libopenssl3-32bit-3.1.4-150600.5.36.4<>, hWPp9|%/2]Xb&WIz8D,kPxyNcD4bļQ}#9$UIӽ2( X\yDNFA 4{Q[W^yI~lm7L?QQ7PZA5VX1*r/3X*d둅LgӳɯDRL4>(O8 U8 S@c6/7V qMen7U,hs* Ӹ8?vX9P{SHT\0g<>AM?Mpd ( T`dpt  @  X  p        H   ( ( 8 j9 j:j>DNBDVGD HD ID XD YE$ ZEl[Et\E ]E ^FebFcGXdGeGfGlGuG vH( wK xK yL EM M$M*MlClibopenssl3-32bit3.1.4150600.5.36.4Secure Sockets and Transport Layer SecurityOpenSSL is a software library to be used in applications that need to secure communications over computer networks against eavesdropping or need to ascertain the identity of the party at the other end. OpenSSL contains an implementation of the SSL and TLS protocols.hWPh01-ch4aP^SUSE Linux Enterprise 15SUSE LLC Apache-2.0https://www.suse.com/Unspecifiedhttps://www.openssl.org/linuxx86_64/sbin/ldconfigAAxU<B LXAAhWPhWPhWPhWPhWPhWPhWPhWPhWPhWPhWPhWP3eacb28b1fa2dfe28cba34d762d0a354ce5bbabb9bde642adcd7f766c39e14eb1a630eb675805b6b9066398031abd3104eb44371d9ee108f75cac702b05aef572a094e8762ce26a86ac20c28ef2f536b7d4880c1117e9f635e3778670401e1afff87048674ea56b0aa22cfb166c0ede5f4a7b7510526fa6ce8be3041be0ca4bd33af6a78fac178c183a2b5e6e8db1e516a6fba0e2792e022e06676a7d88d09d65084e2becc6fd2bfb90944b4bc57d320ae8d2a629299baa9828d9aa255b5f8a840106b153491cb18a80a5f170f07b432ec8e489c55e0c529006e77d67295b376a6ab4ae709354807cf6b52a6fd2645ac6872bca98dca6122a19f7c25f89b35b1libcrypto.so.3.1.4libssl.so.3.1.4rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootopenssl-3-3.1.4-150600.5.36.4.src.rpmlibcrypto.so.3libcrypto.so.3(OPENSSL_3.0.0)libcrypto.so.3(OPENSSL_3.0.1)libcrypto.so.3(OPENSSL_3.0.3)libcrypto.so.3(OPENSSL_3.0.8)libcrypto.so.3(OPENSSL_3.0.9)libcrypto.so.3(OPENSSL_3.1.0)libcrypto.so.3(OPENSSL_3.1.4)libopenssl3-32bitlibopenssl3-32bit(x86-32)libopenssl3-hmac-32bitlibssl.so.3libssl.so.3(OPENSSL_3.0.0)@@@@@@@@@@@@@@@@@@@@@    /bin/shlibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.15)libc.so.6(GLIBC_2.16)libc.so.6(GLIBC_2.17)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.25)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.33)libc.so.6(GLIBC_2.34)libc.so.6(GLIBC_2.38)libc.so.6(GLIBC_2.4)libcrypto.so.3libcrypto.so.3(OPENSSL_3.0.0)libcrypto.so.3(OPENSSL_3.0.1)libcrypto.so.3(OPENSSL_3.0.3)libjitterentropy.so.3libz.so.1rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3h @hchK@hg=gu@g@f@f(@fIfIf@f@ff@fr@fffb@fafWfU@fK;@f8@e؈eee@eXeoee{@e{@e@eqeRe7e1@e1@e-%e'e @ddd!d~ddu@dtdkY@dbd*d"d!@dd@dadxc=@ck@ccccj@ccca @ca @ca @c!@b?bK@bK@b@b5b4t@b0b@a aa@a@a7T@a@`@`P@` @`B`}p`v@`/@`&m__H@_@_@_@_9_-B@_@_^@^@^@^^@^@pmonreal@suse.commls@suse.deangel.yankov@suse.compmonreal@suse.comlucas.mulling@suse.comlucas.mulling@suse.compmonreal@suse.comangel.yankov@suse.comabergmann@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.combwiedemann@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.comotto.hollmann@suse.compsimons@suse.commwilck@suse.comgiuliano.belinassi@suse.comotto.hollmann@suse.comotto.hollmann@suse.compmonreal@suse.comotto.hollmann@suse.comotto.hollmann@suse.compmonreal@suse.comotto.hollmann@suse.comotto.hollmann@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.comotto.hollmann@suse.comguillaume.gardet@opensuse.orgotto.hollmann@suse.comotto.hollmann@suse.comotto.hollmann@suse.compmonreal@suse.comotto.hollmann@suse.comjengelh@inai.deotto.hollmann@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.comotto.hollmann@suse.comotto.hollmann@suse.compmonreal@suse.comotto.hollmann@suse.comotto.hollmann@suse.comotto.hollmann@suse.compmonreal@suse.comotto.hollmann@suse.comotto.hollmann@suse.comotto.hollmann@suse.comotto.hollmann@suse.commpluskal@suse.comotto.hollmann@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.comotto.hollmann@suse.comotto.hollmann@suse.comotto.hollmann@suse.compmonreal@suse.comotto.hollmann@suse.comotto.hollmann@suse.comotto.hollmann@suse.combrunopitrus@hotmail.compmonreal@suse.compmonreal@suse.compmonreal@suse.comjsikes@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.comdanilo.spinella@suse.comsimonf.lees@suse.comsimonf.lees@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.comjsikes@suse.comjsikes@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.compmonreal@suse.comcallumjfarmer13@gmail.comvcizek@suse.compmonrealgonzalez@suse.comvcizek@suse.comvcizek@suse.comjengelh@inai.devcizek@suse.comvcizek@suse.comvcizek@suse.com- Increase limit for CRL download [bsc#1247148, bsc#1247144] * Add openssl-3-large-CRLs.patch- Backport mdless cms signing support [jsc#PED-12895] * Add openssl-3-support-mdless-cms.patch- Security fix: [bsc#1240366, CVE-2025-27587] * Minerva side channel vulnerability in P-384 on PPC arch * Add openssl-3-p384-minerva-ppc.patch * Add openssl-3-p384-minerva-ppc-p9.patch- Security fix: [bsc#1240607] * Check ssl/ssl3_read_internal null pointer [from commit 38b051a] * Add openssl-check-ssl_read_internal-nullptr.patch- FIPS: Fix EMS in crypto-policies FIPS:NO-ENFORCE-EMS * [bsc#1230959, bsc#1232326, bsc#1231748] * Add patch openssl-FIPS-fix-EMS-support.patch- Security fix: [bsc#1236136, CVE-2024-13176] * Fix timing side-channel in ECDSA signature computation * Add openssl-CVE-2024-13176.patch- Security fix: [bsc#1220262, CVE-2023-50782] * Implicit rejection in PKCS#1 v1.5 * Add openssl-CVE-2023-50782.patch- Security fix: [bsc#1230698, CVE-2024-41996] * Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used. * Added openssl-3-CVE-2024-41996.patch- Security fix: [bsc#1229465, CVE-2024-6119] * possible denial of service in X.509 name checks * openssl-CVE-2024-6119.patch- Build with no-afalgeng [bsc#1226463]- Security fix: [bsc#1227138, CVE-2024-5535] * SSL_select_next_proto buffer overread * Add openssl-CVE-2024-5535.patch- Build with enabled sm2 and sm4 support [bsc#1222899]- Add reproducible.patch to fix bsc#1223336 aes-gcm-avx512.pl: fix non-reproducibility issue- FIPS: Deny SHA-1 signature verification in FIPS provider [bsc#1221365] * SHA-1 is not allowed anymore in FIPS 186-5 for signature verification operations. After 12/31/2030, NIST will disallow SHA-1 for all of its usages. * Add openssl-3-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch- FIPS: RSA keygen PCT requirements. * Skip the rsa_keygen_pairwise_test() PCT in rsa_keygen() as the self-test requirements are covered by do_rsa_pct() for both RSA-OAEP and RSA signatures [bsc#1221760] * Enforce error state if rsa_keygen PCT is run and fails [bsc#1221753] * Add openssl-3-FIPS-PCT_rsa_keygen.patch- FIPS: Check that the fips provider is available before setting it as the default provider in FIPS mode. [bsc#1220523] * Rebase openssl-Force-FIPS.patch- FIPS: Port openssl to use jitterentropy [bsc#1220523] * Set the module in error state if the jitter RNG fails either on initialization or entropy gathering because health tests failed. * Add jitterentropy as a seeding source output also in crypto/info.c * Move the jitter entropy collector and the associated lock out of the header file to avoid redefinitions. * Add the fips_local.cnf symlink to the spec file. This simlink points to the openssl_fips.config file that is provided by the crypto-policies package. * Rebase openssl-3-jitterentropy-3.4.0.patch * Rebase openssl-FIPS-enforce-EMS-support.patch- FIPS: Block non-Approved Elliptic Curves [bsc#1221786] * Add patches - openssl-Add-changes-to-ectest-and-eccurve.patch - openssl-Remove-EC-curves.patch - openssl-Disable-explicit-ec.patch - openssl-skipped-tests-EC-curves.patch - openssl-FIPS-services-minimize.patch - FIPS: Service Level Indicator [bsc#1221365] * Add patches: - openssl-FIPS-Expose-a-FIPS-indicator.patch - openssl-FIPS-Remove-X9.31-padding-from-FIPS-prov.patch - openssl-FIPS-Use-digest_sign-digest_verify-in-self-test.patch - openssl-FIPS-RSA-disable-shake.patch - openssl-FIPS-signature-Add-indicator-for-PSS-salt-length.patch - openssl-FIPS-Add-explicit-indicator-for-key-length.patch - openssl-FIPS-limit-rsa-encrypt.patch - openssl-FIPS-enforce-EMS-support.patch - openssl-3-FIPS-GCM-Implement-explicit-indicator-for-IV-gen.patch - openssl-FIPS-services-minimize.patch - openssl-Add-FIPS-indicator-parameter-to-HKDF.patch - openssl-rand-Forbid-truncated-hashes-SHA-3-in-FIPS-prov.patch - openssl-FIPS-enforce-security-checks-during-initialization.patch - TODO: incomplete - FIPS: Output the FIPS-validation name and module version which uniquely identify the FIPS validated module. [bsc#1221751] * Add openssl-FIPS-release_num_in_version_string.patch - FIPS: Add required selftests: [bsc#1221760] * Add patches - openssl-FIPS-Use-digest_sign-digest_verify-in-self-test.patch - openssl-FIPS-Use-FFDHE2048-in-self-test.patch - openssl-FIPS-early-KATS.patch - openssl-FIPS-Use-OAEP-in-KATs-support-fixed-OAEP-seed.patch - openssl-FIPS-140-3-keychecks.patch - FIPS: DH: Disable FIPS 186-4 Domain Parameters [bsc#1221821] Add openssl-DH-Disable-FIPS-186-4-type-parameters-in-FIPS-mode.patch - FIPS: Recommendation for Password-Based Key Derivation [bsc#1221827] * Add additional check required by FIPS 140-3. Minimum value for PBKDF2 password is 20 characters. * Add patches: - openssl-pbkdf2-Set-minimum-password-length-of-8-bytes.patch - openssl-pbkdf2-Set-indicator-if-pkcs5-param-disabled-checks.patch - FIPS: Zeroization is required [bsc#1221752] * Add openssl-FIPS-140-3-zeroization.patch - FIPS: Reseed DRBG [bsc#1220690, bsc#1220693, bsc#1220696] * Enable prediction resistance for primary DRBG * Add oversampling of the noise source to comply with requirements of NIST SP 800-90C * Change CRNG buf size to align with output size of the Jitter RNG * Add openssl-FIPS-140-3-DRBG.patch - FIPS: NIST SP 800-56Brev2 [bsc#1221824] * Add patches: - openssl-FIPS-limit-rsa-encrypt.patch - openssl-FIPS-RSA-encapsulate.patch - openssl-FIPS-Add-SP800-56Br2-6.4.1.2.1-3.c-check.patch - FIPS: Approved Modulus Sizes for RSA Digital Signature for FIPS 186-4 [bsc#1221787] * Add patches: - openssl-FIPS-services-minimize.patch - openssl-Revert-Improve-FIPS-RSA-keygen-performance.patch - openssl-Allow-disabling-of-SHA1-signatures.patch - openssl-Allow-SHA1-in-seclevel-2-if-rh-allow-sha1-signatures.patch - FIPS: Port openssl to use jitterentropy [bsc#1220523] * Add openssl-3-jitterentropy-3.4.0.patch * Add build dependency on jitterentropy-devel >= 3.4.0 and libjitterentropy3 >= 3.4.0 - FIPS: NIST SP 800-56Arev3 [bsc#1221822] * Add openssl-FIPS-140-3-keychecks.patch - FIPS: Error state has to be enforced [bsc#1221753] * Add patches: - openssl-FIPS-140-3-keychecks.patch - openssl-FIPS-Enforce-error-state.patch- Apply "openssl-CVE-2024-4741.patch" to fix a use-after-free security vulnerability. Calling the function SSL_free_buffers() potentially caused memory to be accessed that was previously freed in some situations and a malicious attacker could attempt to engineer a stituation where this occurs to facilitate a denial-of-service attack. [CVE-2024-4741, bsc#1225551]- Fix HDKF key derivation (bsc#1225291, gh#openssl/openssl#23448, gh#openssl/openssl#23456) * Add openssl-Fix-EVP_PKEY_CTX_add1_hkdf_info-behavior.patch * Add openssl-Handle-empty-param-in-EVP_PKEY_CTX_add1_hkdf_info.patch- Enable livepatching support (bsc#1223428)- Security fix: [bsc#1224388, CVE-2024-4603] * Check DSA parameters for excessive sizes before validating * Add openssl-CVE-2024-4603.patch- Security fix: [bsc#1222548, CVE-2024-2511] * Fix unconstrained session cache growth in TLSv1.3 * Add openssl-CVE-2024-2511.patch- Build the 32bit flavor of libopenssl-3-fips-provider [bsc#1220232] * Update baselibs.conf- Add migration script to move old files (bsc#1219562) /etc/ssl/engines.d/* -> /etc/ssl/engines1.1.d.rpmsave /etc/ssl/engdef.d/* -> /etc/ssl/engdef1.1.d.rpmsave They will be later restored by openssl-1_1 package to engines1.1.d and engdef1.1.d- Security fix: [bsc#1219243, CVE-2024-0727] * Add NULL checks where ContentInfo data can be NULL * Add openssl-CVE-2024-0727.patch- Encapsulate the fips provider into a new package called libopenssl-3-fips-provider.- Added openssl-3-use-include-directive.patch so that the default /etc/ssl/openssl.cnf file will include any configuration files that other packages might place into /etc/ssl/engines3.d/ and /etc/ssl/engdef3.d/. Also create symbolic links /etc/ssl/engines.d/ and /etc/ssl/engdef.d/ to above versioned directories. - Updated spec file to create the two new necessary directores for the above patch and two symbolic links to above directories. [bsc#1194187, bsc#1207472, bsc#1218933]- Security fix: [bsc#1218810, CVE-2023-6237] * Limit the execution time of RSA public key check * Add openssl-CVE-2023-6237.patch- Rename openssl-Override-default-paths-for-the-CA-directory-tree.patch to openssl-crypto-policies-support.patch- Embed the FIPS hmac. Add openssl-FIPS-embed-hmac.patch- Load the FIPS provider and set FIPS properties implicitly. * Add openssl-Force-FIPS.patch [bsc#1217934] - Disable the fipsinstall command-line utility. * Add openssl-disable-fipsinstall.patch - Add instructions to load legacy provider in openssl.cnf. * openssl-load-legacy-provider.patch - Disable the default provider for the test suite. * openssl-Disable-default-provider-for-test-suite.patch- Security fix: [bsc#1218690, CVE-2023-6129] * POLY1305: Fix vector register clobbering on PowerPC * Add openssl-CVE-2023-6129.patch- Add patch to fix BTI enablement on aarch64: * openssl-Enable-BTI-feature-for-md5-on-aarch64.patch- Security fix: [bsc#1216922, CVE-2023-5678] * Fix excessive time spent in DH check / generation with large Q parameter value. * Applications that use the functions DH_generate_key() to generate an X9.42 DH key may experience long delays. Likewise, applications that use DH_check_pub_key(), DH_check_pub_key_ex () or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. * Add openssl-CVE-2023-5678.patch- Update to 3.1.4: * Fix incorrect key and IV resizing issues when calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() with OSSL_PARAM parameters that alter the key or IV length [bsc#1216163, CVE-2023-5363]. * Remove patch fixed upstream openssl-CVE-2023-5363.patch- Performance enhancements for cryptography from OpenSSL 3.2 [jsc#PED-5086, jsc#PED-3514] * Add patches: - openssl-ec-Use-static-linkage-on-nistp521-felem_-square-mul-.patch - openssl-ec-56-bit-Limb-Solinas-Strategy-for-secp384r1.patch - openssl-ec-powerpc64le-Add-asm-implementation-of-felem_-squa.patch - openssl-ecc-Remove-extraneous-parentheses-in-secp384r1.patch - openssl-powerpc-ecc-Fix-stack-allocation-secp384r1-asm.patch - openssl-Improve-performance-for-6x-unrolling-with-vpermxor-i.patch- FIPS: Add the FIPS_mode() compatibility macro and flag support. * Add patches: - openssl-Add-FIPS_mode-compatibility-macro.patch - openssl-Add-Kernel-FIPS-mode-flag-support.patch- Security fix: [bsc#1216163, CVE-2023-5363] * Incorrect cipher key and IV length processing * Add openssl-CVE-2023-5363.patch- As of openssl 3.1.3, the devel package installs at least 5200 manpage files and is the owner of the most files in the man3 directory (in second place after lapack-man); move these manpages off to the -doc subpackage to reduce the walltime to install just openssl-3-devel (because there is also an invocation of mandb that runs at some point).- Update to 3.1.3: * Fix POLY1305 MAC implementation corrupting XMM registers on Windows (CVE-2023-4807)- Update to 3.1.2: * Fix excessive time spent checking DH q parameter value (bsc#1213853, CVE-2023-3817). The function DH_check() performs various checks on DH parameters. After fixing CVE-2023-3446 it was discovered that a large q parameter value can also trigger an overly long computation during some of these checks. A correct q value, if present, cannot be larger than the modulus p parameter, thus it is unnecessary to perform these checks if q is larger than p. If DH_check() is called with such q parameter value, DH_CHECK_INVALID_Q_VALUE return flag is set and the computationally intensive checks are skipped. * Fix DH_check() excessive time with over sized modulus (bsc#1213487, CVE-2023-3446). The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ("p" parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length. However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large. A new limit has been added to DH_check of 32,768 bits. Supplying a key/parameters with a modulus over this size will simply cause DH_check() to fail. * Do not ignore empty associated data entries with AES-SIV (bsc#1213383, CVE-2023-2975). The AES-SIV algorithm allows for authentication of multiple associated data entries along with the encryption. To authenticate empty data the application has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with NULL pointer as the output buffer and 0 as the input buffer length. The AES-SIV implementation in OpenSSL just returns success for such call instead of performing the associated data authentication operation. The empty data thus will not be authenticated. The fix changes the authentication tag value and the ciphertext for applications that use empty associated data entries with AES-SIV. To decrypt data encrypted with previous versions of OpenSSL the application has to skip calls to EVP_DecryptUpdate() for empty associated data entries. * When building with the enable-fips option and using the resulting FIPS provider, TLS 1.2 will, by default, mandate the use of an extended master secret (FIPS 140-3 IG G.Q) and the Hash and HMAC DRBGs will not operate with truncated digests (FIPS 140-3 IG G.R). * Update openssl.keyring with the OTC members that sign releases * Remove openssl-z16-s390x.patch fixed upstream in https://github.com/openssl/openssl/pull/21284 * Remove security patches fixed upstream: - openssl-CVE-2023-2975.patch - openssl-CVE-2023-3446.patch - openssl-CVE-2023-3446-test.patch - openssl-3-CVE-2023-3817.patch- Security fix: [bsc#1213853, CVE-2023-3817] * Excessive time spent checking DH q parameter value: The function DH_check() performs various checks on DH parameters. After fixing CVE-2023-3446 it was discovered that a large q parameter value can also trigger an overly long computation during some of these checks. A correct q value, if present, cannot be larger than the modulus p parameter, thus it is unnecessary to perform these checks if q is larger than p. If DH_check() is called with such q parameter value, DH_CHECK_INVALID_Q_VALUE return flag is set and the computationally intensive checks are skipped. * Add openssl-3-CVE-2023-3817.patch- Security fix: [bsc#1213487, CVE-2023-3446] * Fix DH_check() excessive time with over sized modulus. * The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ("p" parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length. However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large. A new limit has been added to DH_check of 32,768 bits. Supplying a key/parameters with a modulus over this size will simply cause DH_check() to fail. * Add openssl-CVE-2023-3446.patch openssl-CVE-2023-3446-test.patch- Security fix: [bsc#1213383, CVE-2023-2975] * AES-SIV implementation ignores empty associated data entries * Add openssl-CVE-2023-2975.patch- Improve cross-package provides/conflicts [boo#1210313] * Add Provides/Conflicts: ssl-devel * Remove explicit conflicts with other devel-libraries * Remove Provides: openssl(cli) - it's managed by meta package- Update to 3.1.1: * Restrict the size of OBJECT IDENTIFIERs that OBJ_obj2txt will translate (CVE-2023-2650, bsc#1211430) * Multiple algorithm implementation fixes for ARM BE platforms. * Added a -pedantic option to fipsinstall that adjusts the various settings to ensure strict FIPS compliance rather than backwards compatibility. * Fixed buffer overread in AES-XTS decryption on ARM 64 bit platforms which happens if the buffer size is 4 mod 5 in 16 byte AES blocks. This can trigger a crash of an application using AES-XTS decryption if the memory just after the buffer being decrypted is not mapped. Thanks to Anton Romanov (Amazon) for discovering the issue. (CVE-2023-1255, bsc#1210714) * Add FIPS provider configuration option to disallow the use of truncated digests with Hash and HMAC DRBGs (q.v. FIPS 140-3 IG D.R.). The option '-no_drbg_truncated_digests' can optionally be supplied to 'openssl fipsinstall'. * Corrected documentation of X509_VERIFY_PARAM_add0_policy() to mention that it does not enable policy checking. Thanks to David Benjamin for discovering this issue. (CVE-2023-0466, bsc#1209873) * Fixed an issue where invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. (CVE-2023-0465, bsc#1209878) * Limited the number of nodes created in a policy tree to mitigate against CVE-2023-0464. The default limit is set to 1000 nodes, which should be sufficient for most installations. If required, the limit can be adjusted by setting the OPENSSL_POLICY_TREE_NODES_MAX build time define to a desired maximum number of nodes or zero to allow unlimited growth. (CVE-2023-0464, bsc#1209624) * Update openssl.keyring with key A21F AB74 B008 8AA3 6115 2586 B8EF 1A6B A9DA 2D5C (Tomas Mraz) * Rebased patches: - openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch - openssl-Add_support_for_Windows_CA_certificate_store.patch * Removed patches: - openssl-CVE-2023-0464.patch - openssl-Fix-OBJ_nid2obj-regression.patch - openssl-CVE-2023-0465.patch - openssl-CVE-2023-0466.patch - openssl-CVE-2023-1255.patch - openssl-CVE-2023-2650.patch- FIPS: Merge libopenssl3-hmac package into the library [bsc#1185116]- Security Fix: [CVE-2023-1255, bsc#1210714] * Input buffer over-read in AES-XTS implementation on 64 bit ARM * Add openssl-CVE-2023-1255.patch - Security Fix: [CVE-2023-2650, bsc#1211430] * Possible DoS translating ASN.1 object identifiers * Add openssl-CVE-2023-2650.patch- Add support for Windows CA certificate store [bsc#1209430] https://github.com/openssl/openssl/pull/18070 * Add openssl-Add_support_for_Windows_CA_certificate_store.patch- Security Fix: [CVE-2023-0465, bsc#1209878] * Invalid certificate policies in leaf certificates are silently ignored * Add openssl-CVE-2023-0465.patch - Security Fix: [CVE-2023-0466, bsc#1209873] * Certificate policy check not enabled * Add openssl-CVE-2023-0466.patch- Fix regression in the OBJ_nid2obj() function: [bsc#1209430] * Upstream https://github.com/openssl/openssl/issues/20555 * Add openssl-Fix-OBJ_nid2obj-regression.patch- Fix compiler error "initializer element is not constant" on s390 * Add openssl-z16-s390x.patch- Security Fix: [CVE-2023-0464, bsc#1209624] * Excessive Resource Usage Verifying X.509 Policy Constraints * Add openssl-CVE-2023-0464.patch- Pass over with spec-cleaner- Update to 3.1.0: * Add FIPS provider configuration option to enforce the Extended Master Secret (EMS) check during the TLS1_PRF KDF. The option '-ems-check' can optionally be supplied to 'openssl fipsinstall'. * The FIPS provider includes a few non-approved algorithms for backward compatibility purposes and the "fips=yes" property query must be used for all algorithm fetches to ensure FIPS compliance. The algorithms that are included but not approved are Triple DES ECB, Triple DES CBC and EdDSA. * Added support for KMAC in KBKDF. * RNDR and RNDRRS support in provider functions to provide random number generation for Arm CPUs (aarch64). * s_client and s_server apps now explicitly say when the TLS version does not include the renegotiation mechanism. This avoids confusion between that scenario versus when the TLS version includes secure renegotiation but the peer lacks support for it. * AES-GCM enabled with AVX512 vAES and vPCLMULQDQ. * The various OBJ_* functions have been made thread safe. * Parallel dual-prime 1536/2048-bit modular exponentiation for AVX512_IFMA capable processors. * The functions OPENSSL_LH_stats, OPENSSL_LH_node_stats, OPENSSL_LH_node_usage_stats, OPENSSL_LH_stats_bio, OPENSSL_LH_node_stats_bio and OPENSSL_LH_node_usage_stats_bio are now marked deprecated from OpenSSL 3.1 onwards and can be disabled by defining OPENSSL_NO_DEPRECATED_3_1. The macro DEFINE_LHASH_OF is now deprecated in favour of the macro DEFINE_LHASH_OF_EX, which omits the corresponding type-specific function definitions for these functions regardless of whether OPENSSL_NO_DEPRECATED_3_1 is defined. Users of DEFINE_LHASH_OF may start receiving deprecation warnings for these functions regardless of whether they are using them. It is recommended that users transition to the new macro, DEFINE_LHASH_OF_EX. * When generating safe-prime DH parameters set the recommended private key length equivalent to minimum key lengths as in RFC 7919. * Change the default salt length for PKCS#1 RSASSA-PSS signatures to the maximum size that is smaller or equal to the digest length to comply with FIPS 186-4 section 5. This is implemented by a new option OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO_DIGEST_MAX ("auto-digestmax") for the rsa_pss_saltlen parameter, which is now the default. Signature verification is not affected by this change and continues to work as before. * Update openssl.keyring with key 8657 ABB2 60F0 56B1 E519 0839 D9C4 D26D 0E60 4491 (Matt Caswell)- Build AVX2 enabled hwcaps library for x86_64-v3- Update to version 3.0.8 in SLE15-SP5 [jsc#PED-544] * Fixed NULL dereference during PKCS7 data verification. A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check for the return value from the initialization function which later leads to invalid usage of the digest API most likely leading to a crash. ([bsc#1207541, CVE-2023-0401]) PKCS7 data is processed by the SMIME library calls and also by the time stamp (TS) library calls. The TLS implementation in OpenSSL does not call these functions however third party applications would be affected if they call these functions to verify signatures on untrusted data. * Fixed X.400 address type confusion in X.509 GeneralName. There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. ([bsc#1207533, CVE-2023-0286]) * Fixed NULL dereference validating DSA public key. An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted sources which could allow an attacker to cause a denial of service attack. The TLS implementation in OpenSSL does not call this function but applications might call the function if there are additional security requirements imposed by standards such as FIPS 140-3. ([bsc#1207540, CVE-2023-0217]) * Fixed Invalid pointer dereference in d2i_PKCS7 functions. An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applications might call these functions on untrusted data. ([bsc#1207539, CVE-2023-0216]) * Fixed Use-after-free following BIO_new_NDEF. The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter BIO onto the front of it to form a BIO chain, and then returns the new head of the BIO chain to the caller. Under certain conditions, for example if a CMS recipient public key is invalid, the new filter BIO is freed and the function returns a NULL result indicating a failure. However, in this case, the BIO chain is not properly cleaned up and the BIO passed by the caller still retains internal pointers to the previously freed filter BIO. If the caller then goes on to call BIO_pop() on the BIO then a use-after-free will occur. This will most likely result in a crash. ([bsc#1207536, CVE-2023-0215]) * Fixed Double free after calling PEM_read_bio_ex. The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is responsible for freeing those buffers. It is possible to construct a PEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex() will return a failure code but will populate the header argument with a pointer to a buffer that has already been freed. If the caller also frees this buffer then a double free will occur. This will most likely lead to a crash. The functions PEM_read_bio() and PEM_read() are simple wrappers around PEM_read_bio_ex() and therefore these functions are also directly affected. These functions are also called indirectly by a number of other OpenSSL functions including PEM_X509_INFO_read_bio_ex() and SSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal uses of these functions are not vulnerable because the caller does not free the header argument if PEM_read_bio_ex() returns a failure code. ([bsc#1207538, CVE-2022-4450]) * Fixed Timing Oracle in RSA Decryption. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. ([bsc#1207534, CVE-2022-4304]) * Fixed X.509 Name Constraints Read Buffer Overflow. A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. The read buffer overrun might result in a crash which could lead to a denial of service attack. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. ([bsc#1207535, CVE-2022-4203]) * Fixed X.509 Policy Constraints Double Locking security issue. If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. ([CVE-2022-3996]) * Our provider implementations of `OSSL_FUNC_KEYMGMT_EXPORT` and `OSSL_FUNC_KEYMGMT_GET_PARAMS` for EC and SM2 keys now honor `OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT` as set (and default to `POINT_CONVERSION_UNCOMPRESSED`) when exporting `OSSL_PKEY_PARAM_PUB_KEY`, instead of unconditionally using `POINT_CONVERSION_COMPRESSED` as in previous 3.x releases. For symmetry, our implementation of `EVP_PKEY_ASN1_METHOD->export_to` for legacy EC and SM2 keys is also changed similarly to honor the equivalent conversion format flag as specified in the underlying `EC_KEY` object being exported to a provider, when this function is called through `EVP_PKEY_export()`. * Removed openssl-3-Fix-double-locking-problem.patch, contained in upstream. * Rebased openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch * Update openssl.keyring with key 7953 AC1F BC3D C8B3 B292 393E D5E9 E43F 7DF9 EE8C (Richard Levitte)- Relax the crypto-policies requirements for the regression tests- Set OpenSSL 3.0.7 as the default openssl [bsc#1205042] * Rename openssl-1.1.0-no-html.patch to openssl-no-html-docs.patch * Rebase openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch * Package a copy of the original default config file called openssl.cnf and name it as openssl-orig.cnf and warn the user if the files differ. * Add openssl-3-devel as conflicting with libopenssl-1_1-devel * Remove patches: - fix-config-in-tests.patch - openssl-use-versioned-config.patch- Create the openssl ca-certificates directory in case the ca-certificates package is not installed. This directory is required by the nodejs regression tests. [bsc#1207484]- Update openssl.keyring: pub rsa4096 2021-07-16 [SC] [expires: 2031-07-14] A21FAB74B0088AA361152586B8EF1A6BA9DA2D5C uid Tomáš Mráz uid Tomáš Mráz uid Tomáš Mráz - Update to version 3.0.7 in SLE15-SP5 [jsc#PED-544] - Remove patches (already present in 3.0.7): * openssl-3-CVE-2022-1343.patch * openssl-CVE-2022-0778.patch * openssl-CVE-2022-0778-tests.patch * openssl-CVE-2022-1292.patch * openssl-3-Fix-EC-ASM-flag-passing.patch * openssl-update_expired_certificates.patch * openssl-3-CVE-2022-3358.patch * openssl-3-Fix-SHA-SHAKE-and-KECCAK-ASM-flag-passing.patch * openssl-3-CVE-2022-3602_2.patch * openssl-3-CVE-2022-3602_1.patch * openssl-CVE-2022-2097.patch * openssl-3-CVE-2022-1434.patch * openssl-3-CVE-2022-1473.patch * openssl-3-Fix-file-operations-in-c_rehash.patch - Enable tests: test_req test_verify_store test_ca test_ssl_old- Fix X.509 Policy Constraints Double Locking [bsc#1206374, CVE-2022-3996] * Add patch: openssl-3-Fix-double-locking-problem.patch- Compute the hmac files for FIPS 140-3 integrity checking of the openssl shared libraries using the brp-50-generate-fips-hmac script. Also computed for the 32bit package.- Temporary disable tests test_ssl_new and test_sslapi because they are failing in openSUSE_Tumbleweed- Update to 3.0.7: [bsc#1204714, CVE-2022-3602,CVE-2022-3786] * Fixed two buffer overflows in punycode decoding functions. A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. An attacker can craft a malicious email address to overflow an arbitrary number of bytes containing the `.` character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). ([CVE-2022-3786]) An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution depending on stack layout for any given platform/compiler. ([CVE-2022-3602]) * Removed all references to invalid OSSL_PKEY_PARAM_RSA names for CRT parameters in OpenSSL code. Applications should not use the names OSSL_PKEY_PARAM_RSA_FACTOR, OSSL_PKEY_PARAM_RSA_EXPONENT and OSSL_PKEY_PARAM_RSA_COEFFICIENT. Use the numbered names such as OSSL_PKEY_PARAM_RSA_FACTOR1 instead. Using these invalid names may cause algorithms to use slower methods that ignore the CRT parameters. * Fixed a regression introduced in 3.0.6 version raising errors on some stack operations. * Fixed a regression introduced in 3.0.6 version not refreshing the certificate data to be signed before signing the certificate. * Added RIPEMD160 to the default provider. * Ensured that the key share group sent or accepted for the key exchange is allowed for the protocol version.- Update to 3.0.6: [bsc#1204226, CVE-2022-3358] * OpenSSL supports creating a custom cipher via the legacy EVP_CIPHER_meth_new() function and associated function calls. This function was deprecated in OpenSSL 3.0 and application authors are instead encouraged to use the new provider mechanism in order to implement custom ciphers. * OpenSSL versions 3.0.0 to 3.0.5 incorrectly handle legacy custom ciphers passed to the EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() and EVP_CipherInit_ex2() functions (as well as other similarly named encryption and decryption initialisation functions). Instead of using the custom cipher directly it incorrectly tries to fetch an equivalent cipher from the available providers. An equivalent cipher is found based on the NID passed to EVP_CIPHER_meth_new(). This NID is supposed to represent the unique NID for a given cipher. However it is possible for an application to incorrectly pass NID_undef as this value in the call to EVP_CIPHER_meth_new(). When NID_undef is used in this way the OpenSSL encryption/decryption initialisation function will match the NULL cipher as being equivalent and will fetch this from the available providers. This will succeed if the default provider has been loaded (or if a third party provider has been loaded that offers this cipher). Using the NULL cipher means that the plaintext is emitted as the ciphertext. * Applications are only affected by this issue if they call EVP_CIPHER_meth_new() using NID_undef and subsequently use it in a call to an encryption/decryption initialisation function. Applications that only use SSL/TLS are not impacted by this issue. ([CVE-2022-3358]) * Fix LLVM vs Apple LLVM version numbering confusion that caused build failures on MacOS 10.11 * Fixed the linux-mips64 Configure target which was missing the SIXTY_FOUR_BIT bn_ops flag. This was causing heap corruption on that platform. * Fix handling of a ticket key callback that returns 0 in TLSv1.3 to not send a ticket * Correctly handle a retransmitted ClientHello in DTLS * Fixed detection of ktls support in cross-compile environment on Linux * Fixed some regressions and test failures when running the 3.0.0 FIPS provider against 3.0.x * Fixed SSL_pending() and SSL_has_pending() with DTLS which were failing to report correct results in some cases * Fix UWP builds by defining VirtualLock * For known safe primes use the minimum key length according to RFC 7919. Longer private key sizes unnecessarily raise the cycles needed to compute the shared secret without any increase of the real security. This fixes a regression from 1.1.1 where these shorter keys were generated for the known safe primes. * Added the loongarch64 target * Fixed EC ASM flag passing. Flags for ASM implementations of EC curves were only passed to the FIPS provider and not to the default or legacy provider. * Fixed reported performance degradation on aarch64. Restored the implementation prior to commit 2621751 ("aes/asm/aesv8-armx.pl: avoid 32-bit lane assignment in CTR mode") for 64bit targets only, since it is reportedly 2-17% slower and the silicon errata only affects 32bit targets. The new algorithm is still used for 32 bit targets. * Added a missing header for memcmp that caused compilation failure on some platforms- Do not make libopenssl3-32bit obsolete libopenssl1_1-32bit. They are independent libraries and can be installed simultaneously.- Update to 3.0.5: * The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue. [bsc#1201148, CVE-2022-2274] * AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation would not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. [bsc#1201099, CVE-2022-2097] - Rebase patches: * openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch- Update to 3.0.4: [bsc#1199166, bsc#1200550, CVE-2022-1292, CVE-2022-2068] * In addition to the c_rehash shell command injection identified in CVE-2022-1292, further bugs where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection have been fixed. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. * Case insensitive string comparison no longer uses locales. It has instead been directly implemented.- Update to 3.0.3: * Case insensitive string comparison is reimplemented via new locale-agnostic comparison functions OPENSSL_str[n]casecmp always using the POSIX locale for comparison. The previous implementation had problems when the Turkish locale was used. * Fixed a bug in the c_rehash script which was not properly sanitising shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. [bsc#1199166, CVE-2022-1292] * Fixed a bug in the function 'OCSP_basic_verify' that verifies the signer certificate on an OCSP response. The bug caused the function in the case where the (non-default) flag OCSP_NOCHECKS is used to return a postivie response (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of 'OCSP_basic_verify' will not use the OCSP_NOCHECKS flag. In this case the 'OCSP_basic_verify' function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. [bsc#1199167, CVE-2022-1343] * Fixed a bug where the RC4-MD5 ciphersuite incorrectly used the AAD data as the MAC key. This made the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle attack to modify data being sent from one endpoint to an OpenSSL 3.0 recipient such that the modified data would still pass the MAC integrity check. Note that data sent from an OpenSSL 3.0 endpoint to a non-OpenSSL 3.0 endpoint will always be rejected by the recipient and the connection will fail at that point. Many application protocols require data to be sent from the client to the server first. Therefore, in such a case, only an OpenSSL 3.0 server would be impacted when talking to a non-OpenSSL 3.0 client. [bsc#1199168, CVE-2022-1434] * Fix a bug in the OPENSSL_LH_flush() function that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. [bsc#1199169, CVE-2022-1473] * The functions 'OPENSSL_LH_stats' and 'OPENSSL_LH_stats_bio' now only report the 'num_items', 'num_nodes' and 'num_alloc_nodes' statistics. All other statistics are no longer supported. For compatibility, these statistics are still listed in the output but are now always reported as zero.- Added openssl-update_expired_certificates.patch * Openssl failed tests because of expired certificates. * bsc#1185637- Enable zlib compression support [bsc#1195149]- Add crypto-policies support. * Fix some tests that couldn't find the openssl3.cnf location * Rebase patch: openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch- Update to 3.0.2: [bsc#1196877, CVE-2022-0778] * Security fix [CVE-2022-0778]: Infinite loop for non-prime moduli in BN_mod_sqrt() reachable when parsing certificates. * Add ciphersuites based on DHE_PSK (RFC 4279) and ECDHE_PSK (RFC 5489) to the list of ciphersuites providing Perfect Forward Secrecy as required by SECLEVEL >= 3. * Made the AES constant time code for no-asm configurations optional due to the resulting 95% performance degradation. The AES constant time code can be enabled, for no assembly builds, with: ./config no-asm -DOPENSSL_AES_CONST_TIME * Fixed PEM_write_bio_PKCS8PrivateKey() to make it possible to use empty passphrase strings. * The negative return value handling of the certificate verification callback was reverted. The replacement is to set the verification retry state with the SSL_set_retry_verify() function. * Rebase openssl-use-versioned-config.patch- Keep CA_default and tsa_config1 default paths in openssl3.cnf - Rebase patches: * openssl-Override-default-paths-for-the-CA-directory-tree.patch * openssl-use-versioned-config.patch- Fix conflict with openssl and libressl- Remove /etc/pki/CA from the [jsc#SLE-17856, jsc#SLE-19044] openssl-Override-default-paths-for-the-CA-directory-tree.patch - Remove unused patches- Ship openssl-3 as binary names [jsc#SLE-17856, jsc#SLE-19044] - Use openssl3.cnf * openssl-use-versioned-config.patch * fix-config-in-tests.patch - Support crypto policies * openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch * openssl-Override-default-paths-for-the-CA-directory-tree.patch - Remove obsolets, not ready to force an upgrade yet- Update to 3.0.1: [bsc#1193740, CVE-2021-4044] * RNDR and RNDRRS support in provider functions to provide random number generation for Arm CPUs (aarch64). * s_client and s_server apps now explicitly say when the TLS version does not include the renegotiation mechanism. This avoids confusion between that scenario versus when the TLS version includes secure renegotiation but the peer lacks support for it. * The default SSL/TLS security level has been changed from 1 to 2. RSA, DSA and DH keys of 1024 bits and above and less than 2048 bits and ECC keys of 160 bits and above and less than 224 bits were previously accepted by default but are now no longer allowed. By default TLS compression was already disabled in previous OpenSSL versions. At security level 2 it cannot be enabled. * The SSL_CTX_set_cipher_list family functions now accept ciphers using their IANA standard names. * The PVK key derivation function has been moved from b2i_PVK_bio_ex() into the legacy crypto provider as an EVP_KDF. Applications requiring this KDF will need to load the legacy crypto provider. * The various OBJ_* functions have been made thread safe. * CCM8 cipher suites in TLS have been downgraded to security level zero because they use a short authentication tag which lowers their strength. * Subject or issuer names in X.509 objects are now displayed as UTF-8 strings by default. * Parallel dual-prime 1536/2048-bit modular exponentiation for AVX512_IFMA capable processors.- Update to 3.0.0 * The full list of changes since version 1.1.1 can be found in: https://github.com/openssl/openssl/blob/master/CHANGES.md#openssl-30 * OpenSSL 3.0 wiki: https://wiki.openssl.org/index.php/OpenSSL_3.0 * The Migration guide: https://github.com/openssl/openssl/blob/master/doc/man7/migration_guide.pod- Update to 3.0.0 Beta 2 * The ERR_GET_FUNC() function was removed. With the loss of meaningful function codes, this function can only cause problems for calling applications. * While a callback function set via 'SSL_CTX_set_cert_verify_callback()' is not allowed to return a value > 1, this is no more taken as failure. * Deprecated the obsolete X9.31 RSA key generation related functions BN_X931_generate_Xpq(), BN_X931_derive_prime_ex(), and BN_X931_generate_prime_ex(). - Remove openssl-ppc64-fix-build.patch fixed upstream- Update to 3.0.0 Beta 1 * Add a configurable flag to output date formats as ISO 8601. Does not change the default date format. * Version of MSVC earlier than 1300 could get link warnings, which could be suppressed if the undocumented -DI_CAN_LIVE_WITH_LNK4049 was set. Support for this flag has been removed. * Rework and make DEBUG macros consistent. Remove unused - DCONF_DEBUG, -DBN_CTX_DEBUG, and REF_PRINT. Add a new tracing category and use it for printing reference counts. Rename - DDEBUG_UNUSED to -DUNUSED_RESULT_DEBUG. Fix BN_DEBUG_RAND so it compiles and, when set, force DEBUG_RAND to be set also. Rename engine_debug_ref to be ENGINE_REF_PRINT also for consistency. * The public definitions of conf_method_st and conf_st have been deprecated. They will be made opaque in a future release. * Many functions in the EVP_ namespace that are getters of values from implementations or contexts were renamed to include get or get0 in their names. Old names are provided as macro aliases for compatibility and are not deprecated. * PKCS#5 PBKDF1 key derivation has been moved from PKCS5_PBE_keyivgen() into the legacy crypto provider as an EVP_KDF. Applications requiring this KDF will need to load the legacy crypto provider. This includes these PBE algorithms which use this KDF: - NID_pbeWithMD2AndDES_CBC - NID_pbeWithMD5AndDES_CBC - NID_pbeWithSHA1AndRC2_CBC - NID_pbeWithMD2AndRC2_CBC - NID_pbeWithMD5AndRC2_CBC - NID_pbeWithSHA1AndDES_CBC * Deprecated obsolete BIO_set_callback(), BIO_get_callback(), and BIO_debug_callback() functions. - Fix build on ppc and ppc64 * Add openssl-ppc64-fix-build.patch * See https://github.com/openssl/openssl/issues/15923- Update to 3.0.0 Alpha 17 * Added migration guide to man7 * Implemented support for fully "pluggable" TLSv1.3 groups * Added convenience functions for generating asymmetric key pairs. * Added a proper HTTP client supporting GET with optional redirection, POST, arbitrary request and response content types, TLS, persistent connections, connections via HTTP(s) proxies, connections and exchange via user-defined BIOs (allowing implicit connections), and timeout checks.- Update to 3.0.0. Alpha 16 * Mark pop/clear error stack in der2key_decode_p8- Update to 3.0.0 Alpha 15 * The default manual page suffix ($MANSUFFIX) has been changed to "ossl" * Added support for Kernel TLS (KTLS). In order to use KTLS, support for it must be compiled in using the "enable-ktls" compile time option. It must also be enabled at run time using the SSL_OP_ENABLE_KTLS option. * The error return values from some control calls (ctrl) have changed. One significant change is that controls which used to return -2 for invalid inputs, now return -1 indicating a generic error condition instead. * Removed EVP_PKEY_set_alias_type(). * All of these low level RSA functions have been deprecated without replacement: RSA_blinding_off, RSA_blinding_on, RSA_clear_flags, RSA_get_version, RSAPrivateKey_dup, RSAPublicKey_dup, RSA_set_flags, RSA_setup_blinding and RSA_test_flags. * All of these RSA flags have been deprecated without replacement: RSA_FLAG_BLINDING, RSA_FLAG_CACHE_PRIVATE, RSA_FLAG_CACHE_PUBLIC, RSA_FLAG_EXT_PKEY, RSA_FLAG_NO_BLINDING, RSA_FLAG_THREAD_SAFE and RSA_METHOD_FLAG_NO_CHECK. * These low level DH functions have been deprecated without replacement: DH_clear_flags, DH_get_1024_160, DH_get_2048_224, DH_get_2048_256, DH_set_flags and DH_test_flags. The DH_FLAG_CACHE_MONT_P flag has been deprecated without replacement. The DH_FLAG_TYPE_DH and DH_FLAG_TYPE_DHX have been deprecated. Use EVP_PKEY_is_a() to determine the type of a key. There is no replacement for setting these flags. * These low level DSA functions have been deprecated without replacement: DSA_clear_flags, DSA_dup_DH, DSAparams_dup, DSA_set_flags and DSA_test_flags. * The DSA_FLAG_CACHE_MONT_P flag has been deprecated without replacement. * Reworked the treatment of EC EVP_PKEYs with the SM2 curve to automatically become EVP_PKEY_SM2 rather than EVP_PKEY_EC. This is a breaking change from previous OpenSSL versions. Unlike in previous OpenSSL versions, this means that applications must not call 'EVP_PKEY_set_alias_type(pkey, EVP_PKEY_SM2)' to get SM2 computations. The 'EVP_PKEY_set_alias_type' function has now been removed. * Parameter and key generation is also reworked to make it possible to generate EVP_PKEY_SM2 parameters and keys. Applications must now generate SM2 keys directly and must not create an EVP_PKEY_EC key first.- Update to 3.0.0 Alpha 14 * A public key check is now performed during EVP_PKEY_derive_set_peer(). Previously DH was internally doing this during EVP_PKEY_derive(). * The EVP_PKEY_CTRL_PKCS7_ENCRYPT, EVP_PKEY_CTRL_PKCS7_DECRYPT, EVP_PKEY_CTRL_PKCS7_SIGN, EVP_PKEY_CTRL_CMS_ENCRYPT, EVP_PKEY_CTRL_CMS_DECRYPT, and EVP_PKEY_CTRL_CMS_SIGN control operations are deprecated. They are not invoked by the OpenSSL library anymore and are replaced by direct checks of the key operation against the key type when the operation is initialized. * The EVP_PKEY_public_check() and EVP_PKEY_param_check() functions now work for more key types including RSA, DSA, ED25519, X25519, ED448 and X448. Previously (in 1.1.1) they would return -2. For key types that do not have parameters then EVP_PKEY_param_check() will always return 1. * The output from numerous "printing" functions such as X509_signature_print(), X509_print_ex(), X509_CRL_print_ex(), and other similar functions has been amended such that there may be cosmetic differences between the output observed in 1.1.1 and 3.0. This also applies to the "-text" output from the x509 and crl applications. * Improved adherence to Enhanced Security Services (ESS, RFC 2634 and RFC 5035) for the TSP and CMS Advanced Electronic Signatures (CAdES) implementations. As required by RFC 5035 check both ESSCertID and ESSCertIDv2 if both present. Correct the semantics of checking the validation chain in case ESSCertID{,v2} contains more than one certificate identifier: This means that all certificates referenced there MUST be part of the validation chain. * Parallel dual-prime 1024-bit modular exponentiation for AVX512_IFMA capable processors. * Added the AuthEnvelopedData content type structure (RFC 5083) with AES-GCM parameter (RFC 5084) for the Cryptographic Message Syntax (CMS). Its purpose is to support encryption and decryption of a digital envelope that is both authenticated and encrypted using AES GCM mode.- Update to 3.0.0 Alpha 13 * A public key check is now performed during EVP_PKEY_derive_set_peer(). Previously DH was internally doing this during EVP_PKEY_derive(). To disable this check use EVP_PKEY_derive_set_peer_ex(dh, peer, 0). This may mean that an error can occur in EVP_PKEY_derive_set_peer() rather than during EVP_PKEY_derive(). * The EVP_PKEY_CTRL_PKCS7_ENCRYPT, EVP_PKEY_CTRL_PKCS7_DECRYPT, EVP_PKEY_CTRL_PKCS7_SIGN, EVP_PKEY_CTRL_CMS_ENCRYPT, EVP_PKEY_CTRL_CMS_DECRYPT, and EVP_PKEY_CTRL_CMS_SIGN control operations are deprecated. They are not invoked by the OpenSSL library anymore and are replaced by direct checks of the key operation against the key type when the operation is initialized. * The EVP_PKEY_public_check() and EVP_PKEY_param_check() functions now work for more key types including RSA, DSA, ED25519, X25519, ED448 and X448. Previously (in 1.1.1) they would return -2. For key types that do not have parameters then EVP_PKEY_param_check() will always return 1. * The output from numerous "printing" functions such as X509_signature_print(), X509_print_ex(), X509_CRL_print_ex(), and other similar functions has been amended such that there may be cosmetic differences between the output observed in 1.1.1 and 3.0. This also applies to the "-text" output from the x509 and crl applications. * Improved adherence to Enhanced Security Services (ESS, RFC 2634 and RFC 5035) for the TSP and CMS Advanced Electronic Signatures (CAdES) implementations. As required by RFC 5035 check both ESSCertID and ESSCertIDv2 if both present. Correct the semantics of checking the validation chain in case ESSCertID{,v2} contains more than one certificate identifier: This means that all certificates referenced there MUST be part of the validation chain. * Parallel dual-prime 1024-bit modular exponentiation for AVX512_IFMA capable processors. * Added the AuthEnvelopedData content type structure (RFC 5083) with AES-GCM parameter (RFC 5084) for the Cryptographic Message Syntax (CMS). Its purpose is to support encryption and decryption of a digital envelope that is both authenticated and encrypted using AES GCM mode.- Update to 3.0.0 Alpha 12 * The SRP APIs have been deprecated. The old APIs do not work via providers, and there is no EVP interface to them. Unfortunately there is no replacement for these APIs at this time. * Add a compile time option to prevent the caching of provider fetched algorithms. This is enabled by including the no-cached-fetch option at configuration time. * Combining the Configure options no-ec and no-dh no longer disables TLSv1.3. Typically if OpenSSL has no EC or DH algorithms then it cannot support connections with TLSv1.3. However OpenSSL now supports "pluggable" groups through providers. * The undocumented function X509_certificate_type() has been deprecated; applications can use X509_get0_pubkey() and X509_get0_signature() to get the same information. * Deprecated the obsolete BN_pseudo_rand() and BN_pseudo_rand_range() functions. They are identical to BN_rand() and BN_rand_range() respectively. * The default key generation method for the regular 2-prime RSA keys was changed to the FIPS 186-4 B.3.6 method (Generation of Probable Primes with Conditions Based on Auxiliary Probable Primes). This method is slower than the original method. * Deprecated the BN_is_prime_ex() and BN_is_prime_fasttest_ex() functions. They are replaced with the BN_check_prime() function that avoids possible misuse and always uses at least 64 rounds of the Miller-Rabin primality test. * Deprecated EVP_MD_CTX_set_update_fn() and EVP_MD_CTX_update_fn() as they are not useful with non-deprecated functions.- Update to 3.0.0 Alpha 11 * Deprecated the obsolete X9.31 RSA key generation related functions BN_X931_generate_Xpq(), BN_X931_derive_prime_ex(), and BN_X931_generate_prime_ex(). * Deprecated the type OCSP_REQ_CTX and the functions OCSP_REQ_CTX_*(). These were used to collect all necessary data to form a HTTP request, and to perform the HTTP transfer with that request. With OpenSSL 3.0, the type is OSSL_HTTP_REQ_CTX, and the deprecated functions are replaced with OSSL_HTTP_REQ_CTX_*(). * Validation of SM2 keys has been separated from the validation of regular EC keys, allowing to improve the SM2 validation process to reject loaded private keys that are not conforming to the SM2 ISO standard. In particular, a private scalar 'k' outside the range '1 <= k < n-1' is now correctly rejected. * Behavior of the 'pkey' app is changed, when using the '-check' or '-pubcheck' switches: a validation failure triggers an early exit, returning a failure exit status to the parent process. * Changed behavior of SSL_CTX_set_ciphersuites() and SSL_set_ciphersuites() to ignore unknown ciphers. * All of the low level EC_KEY functions have been deprecated. * Functions that read and write EC_KEY objects and that assign or obtain EC_KEY objects from an EVP_PKEY are also deprecated. * Added the '-copy_extensions' option to the 'x509' command for use with '-req' and '-x509toreq'. When given with the 'copy' or 'copyall' argument, all extensions in the request are copied to the certificate or vice versa. * Added the '-copy_extensions' option to the 'req' command for use with '-x509'. When given with the 'copy' or 'copyall' argument, all extensions in the certification request are copied to the certificate. * The 'x509', 'req', and 'ca' commands now make sure that X.509v3 certificates they generate are by default RFC 5280 compliant in the following sense: There is a subjectKeyIdentifier extension with a hash value of the public key and for not self-signed certs there is an authorityKeyIdentifier extension with a keyIdentifier field or issuer information identifying the signing key. This is done unless some configuration overrides the new default behavior, such as 'subjectKeyIdentifier = none' and 'authorityKeyIdentifier = none'.- Update to 3.0.0 Alpha 10 (CVE-2020-1971) * See full changelog: www.openssl.org/news/changelog.html * Fixed NULL pointer deref in the GENERAL_NAME_cmp function This function could crash if both GENERAL_NAMEs contain an EDIPARTYNAME. If an attacker can control both items being compared then this could lead to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) * The -cipher-commands and -digest-commands options of the command line utility list has been deprecated. Instead use the -cipher-algorithms and -digest-algorithms options. * Additionally functions that read and write DH objects such as d2i_DHparams, i2d_DHparams, PEM_read_DHparam, PEM_write_DHparams and other similar functions have also been deprecated. Applications should instead use the OSSL_DECODER and OSSL_ENCODER APIs to read and write DH files.- Update to 3.0.0 Alpha 9 * See also https://www.openssl.org/news/changelog.html * Deprecated all the libcrypto and libssl error string loading functions. Calling these functions is not necessary since OpenSSL 1.1.0, as OpenSSL now loads error strings automatically. * The functions SSL_CTX_set_tmp_dh_callback and SSL_set_tmp_dh_callback, as well as the macros SSL_CTX_set_tmp_dh() and SSL_set_tmp_dh() have been deprecated. These are used to set the Diffie-Hellman (DH) parameters that are to be used by servers requiring ephemeral DH keys. Instead applications should consider using the built-in DH parameters that are available by calling SSL_CTX_set_dh_auto() or SSL_set_dh_auto(). * The -crypt option to the passwd command line tool has been removed. * The -C option to the x509, dhparam, dsaparam, and ecparam commands has been removed. * Added several checks to X509_verify_cert() according to requirements in RFC 5280 in case 'X509_V_FLAG_X509_STRICT' is set (which may be done by using the CLI option '-x509_strict'): - The basicConstraints of CA certificates must be marked critical. - CA certificates must explicitly include the keyUsage extension. - If a pathlenConstraint is given the key usage keyCertSign must be allowed. - The issuer name of any certificate must not be empty. - The subject name of CA certs, certs with keyUsage crlSign, and certs without subjectAlternativeName must not be empty. - If a subjectAlternativeName extension is given it must not be empty. - The signatureAlgorithm field and the cert signature must be consistent. - Any given authorityKeyIdentifier and any given subjectKeyIdentifier must not be marked critical. - The authorityKeyIdentifier must be given for X.509v3 certs unless they are self-signed. - The subjectKeyIdentifier must be given for all X.509v3 CA certs. * Certificate verification using X509_verify_cert() meanwhile rejects EC keys with explicit curve parameters (specifiedCurve) as required by RFC 5480.- Update to 3.0.0 Alpha 8 * Add support for AES Key Wrap inverse ciphers to the EVP layer. The algorithms are: "AES-128-WRAP-INV", "AES-192-WRAP-INV", "AES-256-WRAP-INV", "AES-128-WRAP-PAD-INV", "AES-192-WRAP-PAD-INV" and "AES-256-WRAP-PAD-INV". The inverse ciphers use AES decryption for wrapping, and AES encryption for unwrapping. * Deprecated EVP_PKEY_set1_tls_encodedpoint() and EVP_PKEY_get1_tls_encodedpoint(). These functions were previously used by libssl to set or get an encoded public key in/from an EVP_PKEY object. With OpenSSL 3.0 these are replaced by the more generic functions EVP_PKEY_set1_encoded_public_key() and EVP_PKEY_get1_encoded_public_key(). The old versions have been converted to deprecated macros that just call the new functions. * The security callback, which can be customised by application code, supports the security operation SSL_SECOP_TMP_DH. This is defined to take an EVP_PKEY in the "other" parameter. In most places this is what is passed. All these places occur server side. However there was one client side call of this security operation and it passed a DH object instead. This is incorrect according to the definition of SSL_SECOP_TMP_DH, and is inconsistent with all of the other locations. Therefore this client side call has been changed to pass an EVP_PKEY instead. * Added new option for 'openssl list', '-providers', which will display the list of loaded providers, their names, version and status. It optionally displays their gettable parameters. * Deprecated pthread fork support methods. These were unused so no replacement is required. OPENSSL_fork_prepare(), OPENSSL_fork_parent() and OPENSSL_fork_child(). - Remove openssl-AES_XTS.patch fixed upstream- Fix build on ppc* architectures * Fix tests failing: 30-test_acvp.t and 30-test_evp.t * https://github.com/openssl/openssl/pull/13133 - Add openssl-AES_XTS.patch for ppc64, ppc64le and aarch64- Re-enable test 81-test_cmp_cli.t fixed upstream- Update to 3.0.0 Alpha 7 * Add PKCS7_get_octet_string() and PKCS7_type_is_other() to the public interface. Their functionality remains unchanged. * Deprecated EVP_PKEY_set_alias_type(). This function was previously needed as a workaround to recognise SM2 keys. With OpenSSL 3.0, this key type is internally recognised so the workaround is no longer needed. * Deprecated EVP_PKEY_CTX_set_rsa_keygen_pubexp() & introduced EVP_PKEY_CTX_set1_rsa_keygen_pubexp(), which is now preferred. * Changed all "STACK" functions to be macros instead of inline functions. Macro parameters are still checked for type safety at compile time via helper inline functions. * Remove the RAND_DRBG API: The RAND_DRBG API did not fit well into the new provider concept as implemented by EVP_RAND and EVP_RAND_CTX. The main reason is that the RAND_DRBG API is a mixture of 'front end' and 'back end' API calls and some of its API calls are rather low-level. This holds in particular for the callback mechanism (RAND_DRBG_set_callbacks()). Adding a compatibility layer to continue supporting the RAND_DRBG API as a legacy API for a regular deprecation period turned out to come at the price of complicating the new provider API unnecessarily. Since the RAND_DRBG API exists only since version 1.1.1, it was decided by the OMC to drop it entirely. * Added the options '-crl_lastupdate' and '-crl_nextupdate' to 'openssl ca', allowing the 'lastUpdate' and 'nextUpdate' fields in the generated CRL to be set explicitly. * 'PKCS12_parse' now maintains the order of the parsed certificates when outputting them via '*ca' (rather than reversing it). - Update openssl-DEFAULT_SUSE_cipher.patch- Removed 0001-Fix-typo-for-SSL_get_peer_certificate.patch: contained in upstream. - Update to 3.0.0 Alpha 6 * Added util/check-format.pl for checking adherence to the coding guidelines. * Allow SSL_set1_host() and SSL_add1_host() to take IP literal addresses as well as actual hostnames. * The 'MinProtocol' and 'MaxProtocol' configuration commands now silently ignore TLS protocol version bounds when configuring DTLS-based contexts, and conversely, silently ignore DTLS protocol version bounds when configuring TLS-based contexts. The commands can be repeated to set bounds of both types. The same applies with the corresponding "min_protocol" and "max_protocol" command-line switches, in case some application uses both TLS and DTLS. SSL_CTX instances that are created for a fixed protocol version (e.g. TLSv1_server_method()) also silently ignore version bounds. Previously attempts to apply bounds to these protocol versions would result in an error. Now only the "version-flexible" SSL_CTX instances are subject to limits in configuration files in command-line options.- Fix linking when the deprecated SSL_get_per_certificate() is in use * https://github.com/openssl/openssl/pull/12468 * add 0001-Fix-typo-for-SSL_get_peer_certificate.patch- Update to 3.0.0 Alpha 5 * Deprecated the 'ENGINE' API. Engines should be replaced with providers going forward. * Reworked the recorded ERR codes to make better space for system errors. To distinguish them, the macro 'ERR_SYSTEM_ERROR()' indicates if the given code is a system error (true) or an OpenSSL error (false). * Reworked the test perl framework to better allow parallel testing. * Added ciphertext stealing algorithms AES-128-CBC-CTS, AES-192-CBC-CTS and AES-256-CBC-CTS to the providers. CS1, CS2 and CS3 variants are supported. * 'Configure' has been changed to figure out the configuration target if none is given on the command line. Consequently, the 'config' script is now only a mere wrapper. All documentation is changed to only mention 'Configure'. * Added a library context that applications as well as other libraries can use to form a separate context within which libcrypto operations are performed. - There are two ways this can be used: 1) Directly, by passing a library context to functions that take such an argument, such as 'EVP_CIPHER_fetch' and similar algorithm fetching functions. 2) Indirectly, by creating a new library context and then assigning it as the new default, with 'OPENSSL_CTX_set0_default'. - All public OpenSSL functions that take an 'OPENSSL_CTX' pointer, apart from the functions directly related to 'OPENSSL_CTX', accept NULL to indicate that the default library context should be used. - Library code that changes the default library context using 'OPENSSL_CTX_set0_default' should take care to restore it with a second call before returning to the caller. * The security strength of SHA1 and MD5 based signatures in TLS has been reduced. This results in SSL 3, TLS 1.0, TLS 1.1 and DTLS 1.0 no longer working at the default security level of 1 and instead requires security level 0. The security level can be changed either using the cipher string with @SECLEVEL, or calling SSL_CTX_set_security_level(). * The SSL option SSL_OP_CLEANSE_PLAINTEXT is introduced. If that option is set, openssl cleanses (zeroize) plaintext bytes from internal buffers after delivering them to the application. Note, the application is still responsible for cleansing other copies (e.g.: data received by SSL_read(3)). - Update openssl-ppc64-config.patch- Update to 3.0.0 Alpha 4 * general improvements to the built-in providers, the providers API and the internal plumbing and the provider-aware mechanisms for libssl * general improvements and fixes in the CLI apps * support for Automated Cryptographic Validation Protocol (ACVP) tests * fully pluggable TLS key exchange capability from providers * finalization of the Certificate Management Protocol (CMP) contribution, adding an impressive amount of tests for the new features * default to the newer SP800-56B compliant algorithm for RSA keygen * provider-rand: PRNG functionality backed by providers * refactored naming scheme for dispatched functions (#12222) * fixes for various issues * extended and improved test coverage * additions and improvements to the documentations - Fix license: Apache-2.0 - temporarily disable broken 81-test_cmp_cli.t test * https://github.com/openssl/openssl/issues/12324- Update to 3.0.0 Alpha 3 * general improvements to the built-in providers, the providers API and the internal plumbing and the provider-aware mechanisms for libssl; * general improvements and fixes in the CLI apps; * cleanup of the EC API: EC_METHOD became an internal-only concept, and functions using or returning EC_METHOD arguments have been deprecated; EC_POINT_make_affine() and EC_POINTs_make_affine() have been deprecated in favor of automatic internal handling of conversions when needed; EC_GROUP_precompute_mult(), EC_GROUP_have_precompute_mult(), and EC_KEY_precompute_mult() have been deprecated, as such precomputation data is now rarely used; EC_POINTs_mul() has been deprecated, as for cryptographic applications EC_POINT_mul() is enough. * the CMS API got support for CAdES-BES signature verification; * introduction of a new SSL_OP_IGNORE_UNEXPECTED_EOF option; * improvements to the RSA OAEP support; * FFDH support in the speed app; * CI: added external testing through the GOST engine; * fixes for various issues; * extended and improved test coverage; * additions and improvements to the documentations.- Use find -exec +. Replace 'pwd' by simply $PWD. - Drop Obsoletes on libopenssl1*. libopenssl3 has a new SONAME and does not conflict with anything previously.- Obsolete openssl 1.1 - Update baselibs.conf - Set man page permissions to 644- Update to 3.0.0 Alpha 2 * general improvements to the built-in providers, the providers API and the internal plumbing; * the removal of legacy API functions related to FIPS mode, replaced by new provider-based mechanisms; * the addition of a new cmp app for RFC 4210; * extended and improved test coverage; * improvements to the documentations; * fixes for various issues. - drop obsolete version.patch- Initial packaging 3.0.0 Alpha 1 * Major Release OpenSSL 3.0 is a major release and consequently any application that currently uses an older version of OpenSSL will at the very least need to be recompiled in order to work with the new version. It is the intention that the large majority of applications will work unchanged with OpenSSL 3.0 if those applications previously worked with OpenSSL 1.1.1. However this is not guaranteed and some changes may be required in some cases. * Providers and FIPS support Providers collect together and make available algorithm implementations. With OpenSSL 3.0 it is possible to specify, either programmatically or via a config file, which providers you want to use for any given application * Low Level APIs Use of the low level APIs have been deprecated. * Legacy Algorithms Some cryptographic algorithms that were available via the EVP APIs are now considered legacy and their use is strongly discouraged. These legacy EVP algorithms are still available in OpenSSL 3.0 but not by default. If you want to use them then you must load the legacy provider. * Engines and "METHOD" APIs The ENGINE API and any function that creates or modifies custom "METHODS" are being deprecated in OpenSSL 3.0 Authors and maintainers of external engines are strongly encouraged to refactor their code transforming engines into providers using the new Provider API and avoiding deprecated methods. * Versioning Scheme The OpenSSL versioning scheme has changed with the 3.0 release. The new versioning scheme has this format: MAJOR.MINOR.PATCH The patch level is indicated by the third number instead of a letter at the end of the release version number. A change in the second (MINOR) number indicates that new features may have been added. OpenSSL versions with the same major number are API and ABI compatible. If the major number changes then API and ABI compatibility is not guaranteed. * Other major new features Implementation of the Certificate Management Protocol (CMP, RFC 4210) also covering CRMF (RFC 4211) and HTTP transfer (RFC 6712). A proper HTTP(S) client in libcrypto supporting GET and POST, redirection, plain and ASN.1-encoded contents, proxies, and timeouts EVP_KDF APIs have been introduced for working with Key Derivation Functions EVP_MAC APIs have been introduced for working with MACs Support for Linux Kernel TLS/bin/shlibopenssl1_1_0-32bitlibopenssl3-hmac-32bit 3.1.4-150600.5.36.43.1.4-150600.5.36.43.1.4-150600.5.36.43.1.4-150600.5.36.4.libcrypto.so.3.hmac.libssl.so.3.hmacengines-3capi.soloader_attic.sopadlock.solibcrypto.so.3libcrypto.so.3.1.4libssl.so.3libssl.so.3.1.4ossl-moduleslegacy.so/usr/lib//usr/lib/engines-3//usr/lib/ossl-modules/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:40081/SUSE_SLE-15-SP6_Update/7b2ed0f7cdb3e7607e7348ab64879ff7-openssl-3.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxASCII textdirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=52061ffbb8e75205666efeecbdd7c39acfb468e1, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1cae8ecfc65966809ac566dba04a60dc1efecbd8, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2617f70f2b4d7f808116589f6cc309344fd92f09, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1e2f56604d35a7ec55b14643b3cb545dd6ebd19f, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2985639f6034c25bf779d4ca5eb1f87d80ec03a6, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=c1ad7983680cd1cf6c7a48fb9639d82940f49a6f, stripped /> RRR RR RRRRRRRRRRRPPPPPPPPPPPPPPRRRRR R R R RRRRR RRRRP P RR RR RRR RRRRRRR RRRRRRutf-8c37d9f349aa537e08f59946d1a97970cf4c13e3fc4fb60d1091c4a4a77ccacd3?7zXZ !t/I]"k%+4"c&5Ԑ2L{cf!7d2dVXh5?"B5v1t11Xt{>P-,#oՁە֛-ݨYn6i~,ވAbkL*vKVT]%B&mJVo)raG 64"pyd~*M29q%]}t~+:8K )|e A e;!ڣRLPsWcRuױ1"kE[ށkU,4KODљǯǃ֤Ԛ`iW[82rΠ7HZ1\͞\|_U~wHsO8Mp9[* FpUdvk=96%5u'35!hOӜdqy҈ӷݢQ.wV@Lmg.wOygc9&[MtVXzI :s"]i5fKys9ڟhoIEe2'\U12?oљ]s! ҖY![scs PgiG.*P;ּ~bm\79«&hA຃eԋS߉Ra0+H_[k # H2{!3~ʍF~ϱzַboq=LwU#"F߇5=Z}_?衊sU0HD|1.=Lj.8A2tv (4mR\H# 4g,Mjr%N [ُ% 2-"A%l A>C}S`qa8W;5#mߙcIÈ'.3PFǢJ?s=%\%Q<9]:b"le-u;:תR8IF iIή336TPFxYdEφ rd@ݿaatWYGuI X7/x,۞`kB.JY&Z0G۟t4!pT5.*!3:L ]dmxbf @o}(y&S6BFby!:!,1:)g&t?*R Z7/L@yu2}1)GzKy6 ѭy)̏1JH 2< a14@`Bb@ kPҕNbJ&zңrWʲ9b 2uر|j(;wPRdF5PSGzub6]75w@2OՂ[KWL`h]1 &v K^fi,je8!{'wQN#ËBg /ž jTHRVUR{G qvt ?!bc=#kgZ}5!6tk2C~r)$oU*< QχXM> ¶jUQ*c"tfM ^{lҍᮤX XccAo[(+(_U sˬxnpX̐o뚞Nò#lND9lCz5g$0߄#X$1e&4Hy )MlZٱIIў:Zq'M? {Hf\?CGxFElI $W@7 x;=OwF^ #X dd=sF<jq@!Śg*l|mEZ@.4 IbKE^oviW]ЌM 5׺HZZtdwp@:t0`aarVψ$AVdQ^aVG2? 1|{&e[7\A 9݋E BU|גXtXl.z"\ b}bnϋ?20~I쎆eO1"Ho@>>o:V]"ۺ,YF`ުҘg[^.ҌSfNuHUrX'`gQ}HoYqt}j\MמuF$U19| wOd+[3yM[8=Хiv1p6N5TBW^{cE\JB3+( G^֑jXrt7H~FA:G56umWpp{=n^hfn)xҪ_&^LnAj'" t6p=%!ȫ5GkY!*h)e$ 0; 4h7:ة*^l i+CAM\U WQ#d'g뷐C O]Y<A]W ;ZưĄr)49!]hd(<2y:^Bq?fʢ\wf?д,|1>ź^.M/ljǺC* Ѭ6*4Íp'MAPLZg&zm&U:2/qZ,} U6$3D]\@UI teO]ɍ)P›^2]N3xI{艥R_oW%Ri< k2m>A6 GaXSzQ!mq/Y[8̺jRFt muK(P[ ذsbyso' cTd#@pS%{qvJ =0:/ӭm h(&Xv%:ȋo|߷Bu1}lac(@?fiy`X'yf{јBSR:k$.MVyLZ+:">@]׌=v6-J> ,F#n-%Iqln$YCC[TAjSrsop>asC@!0(7ҥBjf Ox`}(!?Ə{e-B3֡=L+¯ 檷bWud#UygQzf['[|)y ANuz} GkN4vלPEa3T=PMS\_,Q*QZa9<MϖN|MM7ɚ#F<2NjVxϡx bqX=_v;cgT?!Ͳ)" 5oou6.\.!@ƁtYG=bŬ|#RԶ@鿳;;z4) lᤚ9E|0CIagG̛:෡U6)Ȭv…DR&n:SxtU&wsP%́S^}:U1 9'~j A/g -k.KU #TBqb CY", >ra~P\ABPS-HD@{S0a ;9yp]*J`fIXo-,/6QY#Rױao?N}gc]L,pCʝ< EOH'W5}JPE2mTOY_ѩd}uDF@fI3RnZxf;"&!;OL%0~sd%k,O\mh)`VarC!}Cڽ!gSvINH%$xξy7XʍvM9Uqf. fvv8 oD`"&_LTe^5<&m]߃AHPs`j/!զE A Hou fj7捄x>%ޤ%qJy@[^rDwr¶%d=lpM\]9QʌZz&F{&{`>*v 'hrR".(u3.>p <|:TT'#vm)dHa#ÎݤF-t x%+$+'&RbI'7@ԄGOxe{K~RR6쩊 "nj ̞G=7oKH9^qra}ogU &:Y7f9cL<1Y ݓ@3'*ԋ`i;lS=,?l 8n@ysu M {qaQr RjӫWL͈_[)+Ȯi%~9Ĕ#lƪ;9 z vf X`c\Y3[ ՐVɟY)247w8%#R]A#d{Ҷ#)3%#CH &=&ֲ$ln;/Qj~J·: tB@L~Fۍ],+T7J'5AMZ4^TkψV7!Q\1B?0ir?Ou|pg^oC@PF` Dv}Zl}հ|aH!a-,g6/'uW'ajY_gKdCfyUkڢ(X{"bd(ZAF3 b?GrhfN$je9>e"TYA1(z+LIr('̒ pT4lA/RK#3`CvAb!켼(: A8唖z ^?$ ڲ;WlX9vKt kUFY蠙QZSVA:jn(2ޞs:thzfG]RS\̎Yx-O9mzZ`:~$YxG$.(<+S\e·8\Be-}RH5*,,1}~K~l:$`Pq !ڮ6+Z܋)UGV?`:bMNsn5 }k CEg%њG\]$MdLD+!T@V 5p<ԃ"7UD6<~1 qFE@OPbl_6k$u%SۮX?~cHpen#j]GL`{Xӆ6T8`Iߙbr?]; Uk CUEQ٥QRPM';y yL6$u cXQaSc.\;WŞQT \A,ܱf4EАCuTU/ӀIYHJ=9%Av=+:qT.[T4g}BqP[z* 'q-Y#ϑ\oO*;  XSx3m)F{60.>7|⺖Ts ] ̙P JxXU)exٿGLA|cK&;͛brb Cvc FC"gr^ 74v ojZ%iUx".jKIsMk+>Ё| ĕ=س;`8f̞^_ğkcYJ[q" Rըs 3DJSV˺>U oF E0a^(NA4{DhLTvݻ}i\ajdr7}7XCӛOW3>i޾+_2o/ЋQE\k ,|O9$``?HZkpZD2nnW;RZZyw HU [gLBawEun;9CVqjG:.ic S:ISE$AyU/Z)ԛ(͞Sk&:Y@ r!I.Z5" `I~Ϊ7゜Zo۴BqG |&{p|b]Lъ9ܤ1U&؅NO,&/1w/o\mTrw2^w샊U w P  zNW".|8ɘeY  pE[J^ *sx|#n(S Fs fX:c!~gq׌=`تClli3A.ȭ7ӀC0J(LrW7Z Z.I3PP?P`Z}aN4{ [w p$!SUM%qxcRjAIy]kO$T' Da+j _)젥Pj6m?y˶Geeoj߲-w!Ӭ.wA9D<% M_~&R̞I]`m?H]+lMSB=Uz0ϭHӀZ40៻3Nԗ[di_Qwl+"M .#5DL~ pdzzmyU8!#y{3/}pw!И6on@+u4DD!-|di:pT|Tlon|Fw=t \.a'%E&p ~ 6ĻEKWp#VY]H9SZGx0{&GOiKfe-l2ozPln(q<& jY^r%r.|X2俹UP1SlX - O[۱ٸ{!zq8ۨSlko |(+c ?K*4zs. ͢T(']JcYS1|%AiWh_"ւNi)/k~ݶ<›z7`޷R{ Zst >I ,j0{J9$ }-ԾǑPГ?+FNN=c]jWv[)JmvGeF\Im<.bOu 1XaN{/hb|1= hw\ a`m_K+s/V!J  ~m>Zrhkzs1q1RzZ'Fw)j>o^Jd*4#,4P\gV\xRl1D__כW[i5P0 6h"4A:)pVD-IC7;^BKEb4n' ;sL"a5([i ZDgljOWN?-Ǩ+4J=&EnLieElsb@1a`صP~]v2o@E>ANEb셇o .Uw gHA*RE }f`c.A:7';9NY|5ԯ9,{fV*#I쥩d1uq2j\*% :Q$cNvwహ~c-P> Lq)bkq!]J }gi>k6>.zVSWHXLߋFo0h-5ˏ6ө69*?{2/:ʺX沮'2xF_dޙ&}1]jaFB,a}Ea$tz;ž؄Iy֏| b;Wq| `Yg~p΁L]:vs05:ڹN휍~%DH/Y!'B"%X/gʅ<66= 3rDOџܠ*Nޢ7v"-űrl63WujhG:?:T\5H8Əֱ։Gg^'I9ļ}l<^8+LO+bԪIq*ff'7ʒ- XR&?ʴ:X:5e7f}QqEsˇ'6;mUo,.;\4; Ћ_B}WFsE:G }r&d,kY Z{O~j3_ P&A.` V0FTf**ݱ)Rn%s2QSB6d׺R"zC-g?/mmfۜETWG6&]]ֲ Ǽ"^m4ʨ-$+.˲)nS*$`w0| ʱ'䬖.Vj_`\Bk5oYnh>xΨFIa%{(Κj"-, 6##adċ͂g/fr_FSЃaJ -WxV\DS dNpT$O#Tl58Rݛ ^Fg]1q9tiTU:+vUIWq|[ nqT&a3X:tf˨Dӈwz8堳  ێ˗f }Q B÷?RzV S7L "^̈t4``|iJ3˶ rۻV#K>˳&pN-*Sk;H>:ˣa'iomy;틕c~w/.ȫvM4`wr@c^?9>nˇ4i4yU6c0ͮf0iE'F#Z=ܗxRGn3EtEZX!N)Q_8}=)GWnnQ4u$/v |QJB1\ƑYR`wB0:M)2W 3ׄ"7jq/*r冔H" s)0tqP?9^0cbb\'RwǀGA>EDGh Pwpk3\}%e#ŠES8V>utX x]7ouwdٹ d gS2q2Jr2?1;W;`9¿ͣL')AvM/]_ۢ-s!unCz/n;R,ѓ`5@OS̽Ӏh9bvrE }']>n,u{G NG.Hϸ($#(7_| % j ϩNzLFzh`/oЏ@F T63q$v,&1⛲CM.VYw?$=Vүܿ?5&Nc| 铛$yUI;%~@SHj ?G^+ 9rw{0a^n|I XX }6 EUͥޣU3JۻX&u6!]6ؾ9vH 7W $;ͬ2iQt\,Jݽ~&@k+ꞠIAٚ1PQ™ExٱQ&TP~=Qn{dc #s_< +=5 >7ؤgYlsX7b|Úg @$#C\ a8o? Qy~esOȲzV(?]eB?}'y)1< ng7עw{DTl|kuz8_p/T6[{<`])F^ s ?3$7ҊDOF{sO!((,Xa韥d4ږwOVxy~wxya8/8ŭ^qC?Z<gvX`+ .!:qts}([cz 4(\Z5iϐuH:4eY ksP"古 YnuVX|TV>b}(Vc8Qv-AXZ60^Ov{Kv)a:)I|qC hw fB/J}yae?[Q۩4TUY[OL:ŒT(}jܞrܴ&Qѵ]/a;\#:u}B>BSLN=g Q8C`}%6@Ĵcfyh[JbGF 9.PU %l~n0Z1#HX˅:nF[ N\*A~yY,GtU-UI.́v&sҠxf[jBt%yV2Ίp+TL#MX5no|LqcZn2`bZewN>{M,pGaFFr)"e{](nBW{ԺjD쭹P*Tms<5{mpěwFTU%w?O+Hteḽ_Ux(c2St_E7n++BQ D=#E,'-Y'T7uUhYuJ2=Wtd naFjosxjuBY>GؕolBLo:N~0)V $KK 4+N l/.yQ41 yy ^ZE`.1{.E>_ϥU03N`rH-R;\Pj:9]K£$hjk'xOŠE, &e `-dX€'t-%E87 Ƚ帚,{`ב7FKSڱ=p+KSDHn}ưdYW^D"`p#?5h̳moYJG|ۛO'0(]CZC)oFY<}pIU{RpB&CҨhrmđ-2ՈN_7E?@q؎.[n(twۦDAΤr }[?LV!R 4DK*s-( оR[--|hb."gTQcM07{fnC| #XnYEɜKrBI^-^,Л;y'{ G:SDNd U;˓q(OK+3<(|0̐n!j/ 9PŻ>h]h^L4\='*'RZ)8oV_ƶ/.`K`~X3% ⩜| u+ l#0A3k|cUŨ=$斻K.}EJ 'Oe@&?2ufыF I6̮7^KBbJ'HJՁvKP )еD.7"$ҷ@t=c OhMJˮIXK,n E` nyPT!k]Nvtۭ7"!Vr%69LG&JW`9CG971Շiad]!LeUذ†_sȕyN}D 䝵u!#@ 8:* [uwNZ|N,k~ȓ޹E@AĿ~. 'J_A׉{1ըbdz>ߺ@}!F@_۷39 3\<ȼ:iuSWkBpBYa={Be#X1'ltЛ7++@7؛.s`(ԅ$}+w> 坝zylc,}}92Y?8AGՋ6ӹ[65{yDCgFDN#*0%CEhQq'_VtvLS5ixm&.NlJyѝ/>@oٔ;{\lCm n:wEiI$~@MhZ5,2n;*:]IC iTe/:t-!q% j3˲ Qn^CȴB&K̽C|qMlp8=e_myrJhCh&LrEl ct٫߀ԌvųM9[К=ۏ%J ,pnWkNr񾏭kER)4p5s`*2oKb4v(Fmjh&7|69+LqjHƿ)./k~ES}Y 0V4Eo̓)@6k&``6*՗_CxKހk1MøV3Z'sE6χKI?,:Oі2v?))d'8|wHr -N.#}Ζ6kյE4v?[,\}N. vcX TnpcXd\dMt_/QT!d7p+N@J@Wf`2c5np3LGjl-l*i~;A<^l١{xV@3J!worK$1g $_s-$c\[a>|'?.0"3Q䦮MyezU>>8Sκ#= / ,uld⯹;fzywUW@Ps5ߏ38&ŭo7݃(tOdRw赂Db ŔAwgmhe%[ iqӯ{># RxyUIp{GofZk nu.3UÅ:~;s arwwzǹzb\KB]pcl~juwߥZ~dܚTӦuiQL7 fkyQt?8_YS*S#UvD[˫k6D.\ ;}G7Vf7i/"P1\RFBÈ0:04Jo.#Wb%Sw5h32ona%VbLj7whQ>nIn b"|4hZ gZ8YrL/ ;g8!֏66ڌEZ![dbt!8fFZ(G{hp+FW[EhV^Pjnz5D^U}KT gUX5 :X-bXԧ>ޭ(bYW'QޖL2&z<9V8ljn{݅$K\pΩE_1Hs 3NK6KfC_U8hkßn@]ic`3M+4ӌs+,([${d7TPHDN A<4%IB !ue+#.be eH?o ME2%qc_Ƕ哜~kLh6ǠnsPtW&QŞv~S3ڥ60~_\7PYyBkWns&ذV'q׬IeUZ1빃=NN0&Y<~~+VU%Ac|IuHa v:PX*r<"<))!} ׯT9vcf4Iۚ#֌!B))5ݮ 57c!p8&w6xK( ;enL8UY/ݍ؆P48 ?2T[{4[{K֦ .=0#'Mۜ3$@ޯ-8ڇJg0aC"OWŻƊzǏ!XA7x2]Rܙ5 Gx Aώ`~@Wc\nӹG|!a8؝hT*C*T@Uy 72sNλkQ6qO,(˾N%,ׇ`I2秊fQ>Nն*ua$6cGE+Ŝ\jb7[ü?in XFBd]sEu痓~?h}t'ZT}mkcLB=b|@W MԚc9GèV&4%)F;mfqa˾'SOyжȘr^6W)_|6NkŒ"}av4|Ƚ-Ay:P_HZY+Y"`TƓ”gy58,5! Ȕq~cdy*H ͋uXta@N?G{Xb4t1fve(iel`aEUfANfZG@HsE5BAP& T ũ5].p֍e<=*kc\X\A`>Vw: -hП.ODNΐiwA[sI}\4OՕg )dx{֚,'V+hY&XmF"ꘞ+"=Q3&i u$(}"ojBݠR0BFh`L(لShmzb{ IA?dS)]3 )X#ΌQU6g-g78<Yad-\ fQc\p=vՊN s ]DZS{݀^sdߔQF&"@ <0iLLGOh" /oK 1!@JbgX_1_%^+A0fH9 k= s'W* (hrЋd;ε\/2l%RR2d[7Wm9Y>{aV֕e.~^@"Qg]0մ}3̃ŵB|HHKWzljug# hO0r LPৗ& Ag|~{.hosc"Kҹ-Gk]V"sY4lǘ/~da±ʃ3ü5ur"L(NLXvc-Eee'5Sj뽊U`&gdnq ƝUĕ-81Zקr/Y1D"Bb3ETtd&e[(v-N ˵DQtނ $l;hnkf̜ȟ(A@o%o]"4 n-g9* {+ $-lC5PѯJ'TΔM'-߫L5A.ŒqK3'IJ&]#U( z| BF;%WQUyOP9S|ba!ŜqHɭ4>o**9h]d:X%A>*L16sKhևZ!`Ny+Bҵ/<8.۲(|o|qtz  4¥(),7ujGeLڗ tn&V)!T? 5ަ*ٓrF3su\íJb ^P`P;O4& WlvhȖed}XDz:H!at~J]dp ?K..gGJ*= 1R${@]NJݢ/0oQ?՝=LNu=r4\cpʗ҉zGO,}wh8JJot.y9YWyS$BP)sav.1 /Bacz;e3).~όA#D}N:ymJkIߗT->>٧H2: ﮮ&Sk*ɖqB)^'SSƫZ ItˌP wɏϟTYʣufRt50~ BWL>Fޅu4Y{qiKqf?1r:|9Ph+FSd\.g8ytssFZ 92ـ8A6h Qh &mD0G&Jr!(AyTdYfU}G7qkgƴa3/nKpxޙ?."ո+Skb");j\,CNOkoƛK#of7]5Nk1 !oaVZ)VnԵ_n-;r Od1tSnR.hk<ݩv]C\/?bøfZ"s?ﱜ(8+P_xs{HS|o)Q8 {( lKJHQբ{RmK |x.#;Rh>0Ql =GH[?ҏU)T*TT홽H:YS%!J|tU:H';"B+q;a Oī(}}Es@a0s[j* YSե^:I}3W's1NARt Za0A a-8ֹ?p{ 8-|7O!̝~q„1s>dPs/6C"?LhE2S+[=`z?}uڱ.Bѩ? 9Z9Xm2~g۵*S Y_=ixyqz_/sr1pϠsIE(MF $%Z&̗zJ|h6p{߁[4m=k9ʌ䮨&bX2 S?@B9 z̋'B()]ɡb>o_[7U_#/VWfdanҵ))3l 0Ż,=N!S7 Q&rh Ⳣ|jpTmjܷ{ VmR='V,%`9"Տ =ɵ]I I^8 h;BM|iTHLApZ뾵 g54b1eNmṠxW$sF %<-jsDž` T3 vP5N3O`1g"3Z>W-0Ђ\ mvDb{H~TMAs M[WA}|t+`. hĻy␌F(2>j<%AjF2u.RZeu/_T/Ko˜L]in 0MU-XŝLqxmvӮ=Χn QOB4̺% _9GMoMRb#^ES%߭n"x=WSŎ}(+h}\AcL'bR9=frT\WCEϤi=Y᫋gf^2Br 1 :r$0FSgGl)-[)m _X8f-RA >>`{]ڸ./_\I3QAMV},K]ChMetd-= eDUzǞܒB$lA-tc>1~LVy0p-AB4 P@8*^WBs*oVzkg@-P_\ɮm͋i ׺+eW'Ѻo߾&) 7p;3smhNrn̖DMC fOM/Fl'bV_cإPo-ёXm]T^Bq\@-hw(J'g߷Y0pr9l}Z@ L>; \][i#B3Ł=>j 1:I _Pj\AF$7ƥEW5IǹO-mn|_5]5b/'P>KPWVB|C\g,a4hVuZB'vXAպ2yM91OL,gπ*>L18<ʬǼzwsT)k .\>cR͘e{,"&L1p[Gĝ䨌q}o=M!dpUW^=a3-7=jH(d;`#I[9Ik3 *`!$@Q&6q9i/Ospwа4 ~%Z7삉!|E =d ]:UM}*'H߸i,/ g$iWtqE_XK%#njj7׵0T(|=x2dx|ƳS!d ب5, 0)|[M>9\JbBQ /v`sz{' ]]9]"=PwdQ3Ew\ClnK(U>zxfmII*EU%ޖ4ۙA&b8eZZ=":tqUHC-L߻?츻G\ԟCZS I| e鵞3kxĽ;qefmsiBq8ٗ2qi}@!%dSC6TvEQ5T[NM_5 <I[); T2! 1f;`8X_>VVG,mQaJ`d=`4)wl tgQWSQGtA-. tOG 6)59`(* a*+LJI6R@xKp]u6v$~Mpˍ|x)N!hMvnf'?YFZЫwXS$QEyZ W.Y.{ſ eZ.15DzdE-7./qF[z ݍɺ (A.DU(o6E9GqX.CQS:ފq=K1s, *6탤 :>e$UQ9N,;^}aѩ֗=vQ%s vYq qi sdZh=%#s:E`dBVC߅_TBEԦ 0#+<9n<+ {oCξ! (2C)mPQz[BJCWVv6* ug;[l?=h&SHK;πHUi `¡pPM-ޡ=Syʠ%{.>j'8bdR dN 5P,w@LghTlyǭ}p1JocMiQ0}"mK )M,e* 5YEKq P|8n@d2IEc w zϥg1RvH$HHiÄ||k_eiNELd7v3`?߈p]VYMpB|`izng\ \d́&Oq[`F%XxI l܃8ZCA+BiDHQq5` cAdyf)DWﴸ1X@v;C,pd SMO*J$! B5ոU-+q$~8Ju#>mYU XXY@Wd`K&X̣hSNa1K"Բ&g*eB{ JGgG{%O?c?IDEjR`y9pnZf@mAQ}T Ck  )v ("SUvX?7M=b1:}Zɇ) 5^miY $&<0G|E].8~<3*dz32XF[ǃ#Q%˨i3 WD*U 5FtԴ,`mKaM+qwhQcA/&`*s~hYZ7V;i`"7P~tCfLx,$߆ȏLe 2`9֋9?b=DG$/9ߒĘ*qZ^ӭ ,U\ 4 ,0uȔb(*#s*'Uk }B{uJų5X.wzc7ջ pvѳcGE| a rXk:sS4}ٴ]L0H]Q=EqNٵ y2F)m#>_F Ze\EWE+P5[S`x4vK\Yk΂6V_á. LK[?WV/]#2+@RU&a [P8h韑&kbk ^p%SiTc.[/wf3S3 DVc'p8=leuXۖr5U/ߥXBvK.8qI )=x{Eɝ|Vݞw|Eb@O$V3:F~,,{J3{dI4A]Aot ߏZ)QadV>JxT} I zT?7棬Y:% 彺y(&%yJt le+&u~X[BWw Y6,z'xOÙ{Z3 36fnֶ/OĀ{y%/%~\2U%׏=H^.΃fo= b:EHw0B!OR΃3d2Ѱ-̒>#{I7m]M_OzDy,B,]}QځOa7P*Rfg!gR& &{>V[cYRkJ-̓Ex4s'@VDkfH(5bmmYy, ,T>:;>#^)jSsRc"=g؉pk6i>i` ="xYUb,=ȯTڞ>I(0jVb@E Du8uOKGHp,VljD#C0Tҟ},,DOv*p%ͿC& VU}3=G>Fgv%` 7ZrBrϙNVDrY6=,gl-EFDqC\u9 ɀGy j(͕WTBUg+0WwaEB,k_?21)E|D6[gbFYfG@B6aK8dOsmxwgr>!?lE.#!3qmZ)朣UGU _.{ J?VRP>e,p-,4OaQiN1q112';s60 ^E&5?>)޷0_vj?j )2pd˺~<n'p%Lj`S2ҥnS3jpi1 ‚č5{FX<8?Eh@*sS,R lb$fd?uuC;5ϳ]w8_Ar5aG<@6%&W, ^p0W3tB.f҆`(]1)5r/#!'vN]O \f,U0ҷ5L &S:%zN፬ ^slC D5D$f >,]k6Bl1 iL@L3SWov4YӸ6[Ea f1sE_"YmPQZu8B!ܧTn4鹻* Qwڢ  ;,}qs1D%ȣ5yZ7w;)Ɗ5?@6jq=Ɣ|KW"lbLlݔ73xIaw&j-3C^:܄MW߅2`o)JYg@ߍ&"`!JN$@UT7Y qHE` M>&ݧX뻋auV,-Ѿ6UʞȻA3p(=XkN~}Ej;{&91Q BVq9+fSr%/4 K "|"ܙLB.0qNv䲭IXX D,M#v,(j3YPZP̦gkޛ;ZN*HZx" Dw.ZX'ՀWoIE#g4 ס\<ŽKH Iifi`wFvnf=`$JL"9Z,8BPL n\1ªM`wV04;XmM,q 49LB,W|F-&SOg>nHfSe*xҖs2B)e*CTzXw̒f(xYD`x!cqf%b)RP|g}:>tvTdGtzKhӣd2[A(XO}s.K LWBL(:D|2T֛;)fyn H2n9{[ OB E]r*Lʹn:יN>hC@йWO;Re09|1ά+zS#5C2R#eɋN;^ӽ%:@Hj5oJdXmLΠ͉A! ũS~ voHށr2 | ׁ3TJ 7 U%IuwaTAvtuUnM~pvAu )oH f"\3T!$@j)"2{K5%lzu616U4. XU3 'tP;q=ic@a߻#3ߗBJģoϚ}Qc"RSOP;'UjNiepD#r)8lCVFzaDy?/ŪjdMdZR zE3Mlt~U&E1X&h1̠+VD{#ȅ~,/!["THy>6N wP%],.R rXwF8J5ț& xy2f@apy#DkOE~qS*2Ï`+@ ɦKNR'Zfxxگ :$`H*5g9TɨpUO4nϸ$p?ր auu. 9WloD.amZ*O m{y /(v]k_/U+lJVOhk@jgCۅM*(B_:MV?Gn7Y,rox^ Jc.jcN՟'F֊c9DblwDglJwFʗ*̣{f0S $W[8C_-c46+/ئFn`)]~Ϭ93>D|SIu:[om᫾7l܉UQ>E AU g&<6*d6{)fFCL;ն9%Dx蛡 h U Fb= gr ]"r~g9zয়'̩qv xp@ 1VTTL h.XuCUP#Se(܄ m)^!׀{5X)#d[r hpl ,igB$jMn8!yV4X*F2/TtyXš _uo:)By Cy)*)Vz,Sk{n\4qڧd OB4Ў.|*.^A" 6õ'`&npFkm[VӾ;[{avƱ/𐰴-*cTFI.sL2ys#|eA+EVH҉Q"klRށÖρ/x`sx<{PY:,<b7`W - JtaNl`Jr#&I;nVLO0Mho]${1~A@s}3^aEx6NjT޸'{)s[8/t.婒`hk},ap3OJʑ[ _ѭ1uUTO2odTW_OR (\Ҟm zV>^#'GcEXWQ.ᵀπU(avC 4^?dWe庖hb$3>޼9l\D#Py\W$q(Ժ|I72є 4l;pl]zq؝L\\΀}3)lx]`F؇5;~sViNHJP.E5nJG8K0H6 ? ¯29+H@v/aQ<L˰qkSi_S_TT%'J?)vzzL\ '_ܜή_i)==}50LsIn\?{uLD8)hW  dzJ ,ەdi_(~Y溍#`姞(s⣂k`abb[߰>h$]P $x+ݬdN&mR>' Ych'qjvʗ+AF(p(ؕș/T ':ԧiJvѮ,wj6#1fԽ-6q`7W|AxfN %)ẎDq_[h=xj/?tV+l1؍9GI |Hd ] jt4/_сf)^}1_6PRxGWA<4kN6<5"`Øp>1ŏvS^mHMwL0;|g .<Zy |?ٌK`J4E#kS/*$>k>v>'8kS.6趜ƴy-wV܈Z(}rfxbbjqX>3F'$'(N_CELLxiKX8ܳg94Rxv Za50i8&g԰qG- Ң JYFii !Oҏڴ4ZT!q~3%ζq2:;Qzwl3Hmi6a14[U\tPc'Ŗ? =_bA͓Ou57AE~ǡkLzION+>\GBvb t ߩeHXiRl-/0vVm[AOӼ5ѐ7H> =[+yMn;rFIvk)h"p0AN E3#8օ\b0֗ > a4Q6u(m81zsƯgͫUK}1镉 *0n]zsitxX"Z!ew=s;Z1eyܣ grߕֶχJ^gx="(^DbNtn2bT=`sSʀmԓ[*u-$f{vC`GMW[&7j8gHAVW8(PpȋGjLG1Jn&fA?­FE*1].@|UAߞ=gHѿQ% lAEz_ zG0\UǤk'e|i9Thx)Y]uYYʍJ4nn: "\ޜiǴzf}&זJHıBtO=b|}X6C8j 6NT}Iq"t+ n .Hv(bs5fgdˈŇFZ<^M`^{*Νbȕcw`J[%:#娋&gوѹ-E95; 5>?"4VڕgִuvRs|IԜG!̏oj); {Ȧjvr0Y1 4#"@VݞZWmYWϴ1 pƱ7#vFHMn+ gaw;g:xpUHZ/ɼ^c֢/|a&FBSW⁗µw0_Z}8šk5'=s \?":i6eNOGxsL"d(2eQIB-hA7~, 'V_:NCj 1D?d11)Ev |q F AChtt]JE0A@9G7Ϯx.Kxv% 6&|} 0Lsqd|} vIcGhਊs/:b]W a lLŗc<]* -'Z>SJ,A= }'r@etHWp[ZW[=[肦VXb\և}~ iax8oҟ]U5uf-C—M^堡Z5)cy~\4H[¤.'F7+6Y/cSnTWjRPHtdEO( kqh;4>8]aĝS7.)NҺs b{rm?({6}ܐ豠\I#9 WcV^olq1dIgw szn\v?˂ M;ĥ3{q"ϞavwomUX8ɚG.eXƂv係qT*d"D4.*2c\!VIT<͖ˠ -7ty:ws%\gW&˜irK$=@PQA`m'b;av`UpD^ %mDҏ=ʍ0o&_p1ځ {7܎@3.d-CTS<`Xgc㳄ǜH }~$i5ɲ?P*HF7DR JPR=%̩ 6T6fL9.a`,`sՊ} %yT:*NRFEd,gG`}z؆YS NBG=g'籒(BT0v.榍rHnku"= |ArVOvmnuxoa]tMUF#/{:'֊Ni 2A':<ÍSi )P:4鏦z!vOuqiaؠ~֛o& S7&[~0Us}aڐdYu⁖ jj1'YI6,.u(#jZ݊iּR5oTUQͧ(* a]zò>*nΥ LJ2Y϶Քo s/(in EZӘ蹕sii Z"B=S1}5*XD-}J7,p~!(th:ln҄Sgf/cH5I)?zų_15 B5 OI\>j~9߶2[{ a?I H.TdQ8e Ǎo8zYl {|**Bi*r;V s~ډ/Aj?ti>F;Rbl߿+p8Z ݝ;x޾ET:TH^!2'asPR@b"]c2 y_rn%Te>aPJɥ ,ASF {ksX<}v6m:  W?TK|PРzQ@V,u}?q4 LL#ԧ_= on\9iw# .`M^7G aaRaR|l<]m G͟u#W偺Y+;_TҠ4ug۔RV*}f9ch:>T\ܡf W3fq@,!uPomGM7/ tֈ-;FˇVRX6!~Z.}@Oz{8COZψוUuppm=m3sbwþ޿aX^ %řm 1t#.9\ ʵUf2FbkkAeFHPe3/` L/rQ͘,J:h\cGWC&Iƺ0KaQؾϽ%qrk;f*⺼Vt|:ݑ/qW%4sc?ab?.+ٺ;t2 &ϲ4p뗥L4? ʖ~ @rop +<S5qw@A'Al֮DVͲlP$QNbz;qp2SlBFeM!\Hu=H'uoFPX#<"*՜]Ge]w/=ps"4ܢex|z|P_5B`D\dJR>N\ȠZ칚g_-6(M"BTBUYb;(=]I $toՕ1tP8Lwqw~ykTUVTcdC%8K.y*w8mظCG DB军ۤA|V\\F{*KP 15>h,`ɐkSWt u1.مu{/$мmn*c"{SːzJ|SwNH1b.mt{E(XhϠxZݺ͉ qp2tfb0 g*2}5QxAg Ėn|YH9JJ$E+o%ИxU_UYegRP)ʹ4tD:P;l(cdkPROm#q3؟4tM9ф," W4Mdžp3ChukYsRD). a!w(E&|JS+gUQ É ??ޱs%o| y`ɀӡtr=̺d$o8t%wA=`=SV&z5B&?iPq&?19o@e]:xADCsј74 [T`S ۦ~xp}|%}>;rWZ<ɁB{yaQS,Oz^Jh"b6f uӞq}lLYUZ(KB N?ɟdiܑaG $%ȋO7efykfdӥW4 R֛:v{ezIوe_J)8M5Azkߑ``n.3 4=876U-p'0Ea\x =2|J)ʥ,TZz}Av*-s(<jxÓ`lKhH4NEHcc *lŽDhW0IFuQeec{ʘcuww.c4i Z6\n~/]eA. nL8IɣrزSE*ꣷbrB#XCe19X`v@g6J+&&*Ý8qىݐ6.rK jph:ӠL(sąASfy8sA\8{IG#+O悔;em*>+nX=>Hk"1/[nQ Pi{ܐX0P72#ۆT0 2ɲb?pMM[6>L8Y8WEXuҹ RM`mX HM01 4-ݖ~[X8ih(Z`WeQ8crV& t,,۵Z2=cXQѺŠi+> c4!u׏@-v0,&Y}[k4g=dr伇8k =H[$᰷V^8Y"MHK z*fsז{ʕ*xq+޻%ĎJl0);j; }ߺ5 yj+"ެ#*Cl)7"T O8G-)X}zU-Yc]d#?Dsk NMsp˂`j&5i˚/ =-? rԨQ:h([{?]xckX>"yrohO}R}] ៏N"az~W0F|ʘxt\j@'a6Bš] MI T%l=s)d|1sp:J$pS9RG(Px`J HaKpʆsTbwYjٛ:dױ߱_#&Š[&<{qр&۩U$LaZF3~u@rI~ , ']z\Ͽ䬡XCA^5 &^ ++PI+X}uwW%PGdW>I.տvphpb?3d/~QB!`ty"$T:F@3O:IXOSo֛J%>Wx/uAƑ"֨H,,6l}S. O&cV.i׊`qW4 )G mvdJ; ?ñbcտ:niHG~ߡq;Gz%(1&:P%nA| :cO#"=W|E/,2Y\':ybC)>5ΰQݼ$9S0#׎@MUd9ik֤>Vy9M4njZt65;;P?ys\f>CT.vڷ)I%>aMAl_űN~GLpLe1CHLpb戝%`'W "Z^+Bt vE*x {mr &RO(i/7?t75=G(1lỖ̉{):>.?'v;(,^SP]JVe3⃰}#|GHh=nljQΰlHJ2~5Unyfr#57Qhr~>$=quY?*GĈWz56/ҒښQ2n1Q rw>sq\Su,T>\ER% B:];@6@ߪtb-Naoʐ?$ȺK݊Ny5rAcj ,labA/@!ڔF17PH׀?"]NU+Sg*"aMZv"ΌNӺdT][H4h?z  #ю2`y腝\6arb{fҸddMb sU% ުKOkhoj#\mnG1RK=Z1l+b>3&2b+Wtd< OV{vSDՙ'?+Γ|6-GhΛ+X wĝiMahaM JJUWń6E< KU;9"_ NopnLQJXIsռAqo2&'oeWۿaǩ֟e"JĊ˾)xnQϭJڵ}C+Y/:6eUg8`S~V!77"_ Ie& 5arh^2%{"H9LőpTJ`+\ab0WZZJ 4)`e*~nv}iqZl4Jd".LnBa@CYk|a7|%y1!<.Y3/k2OP@ϸ8i:frZ^i Rz_oŰ?~Ю Ý`4'{ߺ]Y8Pyꈰ2 9Ҹ^=R z8R"X i# ,>:z\'xEȞf&ܧXʖCiّ4qUK+عhm 25128Ito  6+Y{݅\&i t 5'rpzy0?֮VUĊ d P"ʚ.kKmWSU<ڨԽ %u':(MHT]wSͻ;<әaIycaV"| :7y0jޥKP?9IШ;@_1KsPOb :ZQI>˧*p6)M#׸ 8d".o~k( jv䶛5D6R?Pp"^2_n!׷V ѳ .Nh0S50l(yO?>۔֥bw~TgƢJUD%|e;hF1>3pw/z xrBCaRHd<^WJ@nV(㢬lGK28Q6It)(V!rgr[578<9 'f*q[뎒y8 +|ZmB1H ?]2W$W {vyx¸W4J.Jb;쟟%)}zU.fѩϏK5lF8d\-I̡FF|)X{$Ѹd,kr6!hcUjAVy@,UvԧjJZ`s~?p "Rw:דE9 A/&Y򩽵 s"6_}/-Tˏ !j!]r2sK\䲮R5(UM>Tĸȼ% eBL7A4y=]ܦۃڨ-tRɃ7BM.% [ 7WVsrq7/ϥނ 5F%Q>3*;,Xk~D!?W 6Xj4w~G(,egqIa8n$Z3yژ۞UCDp*ˆI q]odZX{' sʞa yd $AQ?8&n*ɍzDCuUŠ.uJG- QVMR7q qXK pHtGk[*KQ|ĂK eo[}ٶy'IlR9gQ3u3q>u910W7R1r\$뎎WEV?!ZJO`IvؑI3Ln!N .1f(KzYs&C"* ׮Jvnƒa!M:6fIWH+|˔j~_e2ʀWi 3 Q6jגT}Ci@gՖ]lQzI Wdtq0mZ*xfkN݆ &g- yYP&LZB/l L^th$]ҩK}xAG K9*y\|Sm)'^ 󉍇dSem‰&fu$ k_ce;ODӃ*yWfkǶLy4^P0=}xȽVFd5h).;D>ME>yKnW^LRh~{I k`4krixڲL# QY4o>l#vso8ZtKBf!iecÀK yir`]ۦ+@اVxj[WLLib9@ElZ<oZV l&T4gvyGӭfX(3Z?R::݌*k;p&bN/Tȷ66U!c]6㉸A <"\)yq#"/RY_Ex 6֗^Uo1"Mvsbc2`rIZT9 &8*L7DU\8K˳$A0{D*]O~;sP.Ӓs/zX:rܬܱ`޲E0PƦQ|KmDѰCP@l[;hK& dVX$Eh?;FDsyQ,XQ 'L&\#i}x761ᲛF .k -rtg8!٥]>zeCXGr̓!s@bz?;Wr1Iw!xPX<5(VͪjWЛC8j=.S2 V3| S,څf΂DZkL^#xy{2oB3 !R#ZhZ 2 D^33m'i]>_@g:Z&<ţ8G)ZRv DĘD&H[E? ,V 46ГGwսYX>(%;$<67ZY ڪ P¢UL:DG=%c"ۦO+>nHzgHPuu+[P2F &H֚33eM8y.zY&Ƚ5K_ DZߟX1#D\CH!e/:M`gTD0;p-HdBsP,/rW"ѥNc>5ZT Xg?S]*p~)AO@dSӎ^I\Kں@lF1 RIJTh#Db^ݶN^X3+0ƭdP?{}&;ݮ Y aЇ%[DCcl"Iv쁛$vl,< vCWnحiìMFcNf="Q%dwwoTȳ)84:wbW$.Tkz3I]:Ay5G˰@V2tԧIvQۚEm+ow,u[9Df13Fǿ*SHlYFK&}u=ל } r &[]gg1_rEŦ#E]<ͰU ʱ3E_lader ٺ܃or, 2z13:Pz~űD}X#ϻ-MT%A׀js'&9QPFg`tfONmw䟹1<ŇD>cX7R]B0Il =ZrJHJ҅Llex늍%@Dr+4bݩH;?@[c tmJzws~Cky,\bx4/}+|3%=wOk ~ݫܮ/$MqT2%+ˍV>o􆅹'Wg%{ ߊ_I#Xʳ %݉T^P)`*O;;I%W8+yK`4 4bY;V~mUG=O a͋m [EcRfbdX>!'rg܍u1a`ac5hNHb4/RJSw1m|YDF&إʹ˪;xs76Q+*$_f .؆_Ggl\6EneRy5NtVaCMSg-?/dTQh@^2hܵZXQ ~r:$aFEU^AZ Đ<~^^ _TJ|*'/qr>GJ>]./}YX)d:I>A͂) Q]l.>1mQ@o Ώ`>A' '\Mٍ[3؉?DZ>OD}]ü!oSwS 􌊧|YL.@Yiɝ(Q;5s)HW͹9L"Q^ ] 9-~=¶y+^?=D§A*x_I^Ʊa B~:՛qTJNc櫦R Տ]ԭ3eY>֭93h:Aa@1q0Xr`"z/TV̳X>>{~Yḡ CUז@"dlC%w clֽPa];͘)Oۯ `Y=U ҧD1Pgcid4rY #F ]\鷊Dk@%yC Ģ\dܲyovj͌MK3Zy=j=(Fo5T*1g,Xn0m*Ѓ9!N͚3PC2<.詨:ð9g-EC2T&4`\V'u1#݇z+d%8.E yƮ}.ϫj{سwi])ϊ*_X~& r2np )!2iMNFI/QOBGAq·,v ޟY8pKDr\cC+'йe @r `m- ǕKOK7>E V @ar{1H;{v}uڼvιm!4B["!+HTZ.%XB|mHΧXbO*$<h}쐔9- ZEX "d9&g_M9֜S%dRdֺP3Ļoe+4╃g4 ؂~{MVWC0aXꐥҖ{ it+#PV}rF6 8j[&܍吏VB O)g񮲎U+b#@݇@08z׀/|װꓦ`J̝=K@G/TYshZ~VJb@VGt{$)Ҝ0 Wm+MP]{xVf6B@lB䩛_qSw\N^殈O=+1a<g++`p7DwnQc9&tBgZŎ+{MNv2&<݆ $A o^fuv2>Yjn8o\j J[HŹA0H4MdiJW8CA. nh*CZhEI^&j^'U,MECH8\2 8$@_Jl֣*Aܼ]s;B#`[pj3"VwU ?!F]T]*l[C<&u5 g:CK?;݉HgH Roa(n)gBWtO*qBֹH ܭcɿ]);*/²)hc7tDK*{_({[!lBOe?[~ z9ZB¦$tlE9*ڡp3#rOhRz,x).a00J}L('7^?uc<7nJ+;hn®jt]ҷ 7GY(|[UCB2(a],(qT&20oղo/rNF&wmѺH{٘opgcKz[̓j4%t~Rn!v b\wC*w'm5Q?5mD#Zt.`-c4\E;_wp F.ZpOJ Mq^bc aiǀkrT8[N`fN ,t,kq]{gqO ɣ,-Aɰ/SX7\_6`+;/!l/{ `47=ېd*R_Hd}yup(JV6VL-~esIz( : ᢗ+JِbI݉FMbm2"\wAQ2mehȴK[ e'םQKdMW7.!p:),d7pߡ*qH|h>bqbï_ Ks6ZWRl+(Y ex{kT"iUIR}v &Qb&gT=$J~P};LS[ڴ{yC9\j+hS4(.yA 9!'t Bߑ{Z+^x2Y?.\Јwar''⹠ /HG(oxI؟CP}g DH'JR<lƲV >Nns~ȓw?G _O $zZ]pᛊ4r5<GE<)Bg n1oqTxL#֓H-Df8wn`l$ʙʳLW~VP'L^-VŜ55q8+cΎ-ӳn#F͆Ŋg)UNjIkĄ@t -<`yx۪ck|+\xO>kWȀ|x2VsBX\OU`iJsEmLbyuP.r~zj6"j0 AZOC=~W_$lM̖q̛BPyO%ER:;qbjSMdb@qIq c$2lc?P֜Ọ;NQ^sk]s|:ƾa{Zl( V ף ZȆ:!>@.h;'e|UP_cj6M_!(J 'QǽwRbi@+8v>ο&Ш1᧌c1j݇ <߇EҘ9-hKz=RϞgԵBu.tZ}['ʠc+iu7D8"f`v{)L=eʩ?`@3pcfwtM*]>j,4fs:D hof@c&@EKZj7U ̇ھݵ *mOұX}hiDww[6OG#{_,5DgNRU} &x5w$ȭp*8'G#[s)'{``凓mQ+U JDM٥Hmg+@P1PP t/:B?ԡ(h9Qx A],3B,0o{5n"-^ccHI(劇3HAdŲBٶL CSvT.juD0$Ҕo۾ 8kKHeH.B;Ty@0͐'I Z 'L&fi6'#yER2>%VQ?dY-mʁ)Emvp)T`}2xYf?;'caIU U&I%fA6J@gށ))mAIl.唲NǞR:mؚp񶵮yIȲ`>𾊶WylF|u#99E}5E؋2eH*iJ]F 46ZiʑscfV4*%/)IRڬG0Ww>~iŧr(Pw@zD6q{EgBS`2IXU罛r!o G6#xR! E X }וtS%j@bnڑg`ƴ&-SKfHad@pev>Z;;얎M#oIJ:i 7GP:>w㲱0.MoJp:(9{^hv$jX LJ#\?ŴwM̆ZɚHD8uV1P.ۙG yYPE T\Ƙ/^C͙6 .*/)u`sPiyty|m'a73\͒tB=c,3rUcЀ!6U6zM@AT 91z pn<|G,3%h(W|^ (Axʂ5ź<;ą޾G@D( Ơ5{sh"N8d܅RԖ17 V-̌0?$wJpYڸ$5f!#B@!X_0c%iZ[nEݾOnRU2NozY ԕ39o7Y[8^"F}e98zޛ86i^IL'/\^3/08F"&UK罪Y%|JYga'Zy F{V"X+&~]` %v4Db sr^;&ϝPh&%h4;/#sN-( a!wSd"j54Vc`~Y0jkb}I\9<YŶ/lix$g?2&:ۥjzb:o!H7G\Ab.vd'3j3QG 'R |*JΠ0^_z){b9mnHG'w ')m6QO'u?Oj4I[qL/-[6{08{=\:}}ܞoX(?ti!a1DDXgjû6ZnF2}gּm uTCy!-OO{X6⨘E_KE;a!]k^:յ:+i3`n#]v >zJ׷Vbu˴>f]W)|B5keSlѡU@de wnՃ\Ǡ>WH7qvXzR?D2~/ k4UWSsVX` `:͟LWA# 9>|(+Si9faO!FضPZ%6կQ +8 C|`s6/!~v]略nGwi+ժE^NP/|"py*wCm'1C @[an7U<}Md*eoiX5;f2!N? 5|]6!K#SL.N,Օ:q$.$ĥQ=s]?) vf:(vC>z*!*a2ZAg f{,d1LhXI% b^ʶz0T!:صHCa΋M+ewۉ^d) ʮ#}7̀|z=habvBGleP ppGw@ywz-RBc0tќ0dICW&y8 zo}C!Ꮘa`V]4 P dLF1^(F׋ qDQNl=mDt ?|q&G$W,2rHLZ$IܢcűD T@`8qAق!B'!{{tTDMև$FWgbeO *Ȕ?$:j@x}"ߟCbM ~VMu ڟhN,u*;^NϸǠWA:OVL*\ e?suF#q"LJL'|4fua]W܂M. p~r:"1og!:SQunb1; :_$ Uqy޻E\Hc5^>w'q^Ј2'q lo ފ\4}pѢ ^)G="oaTn#rJY2ؤrF|:cjLgh>bksȍ_𔮳5p 2 ע3Or mXYA }:rsz Xsyw)֠yl%1?à$*)bo.1-o㈄1@eRrun[-@-],6Ekxh@EHB3K{uގ z4>buv._@jƸ% >*$|$- CG8=&WHI╜mSr0Kd:a[5V$ YsJ4j*[٭ G:跣Щ_p: yE} Rk11Vlr${mzyH~{)okibeY9?9[/3S ⨿.Zkq0={0D|}/p(m 'iîtOZ3jHlۿ 6PpǍw Oufz/Q&"砊V T P %BɘE\m5DQ74F%oݺaD[;jЦv4y% jǃf/%E(waYh%pNس)__?޽vc;>t1jG.WRVb:$``28$8I4lx|4%h@dգ1a5M:QE T|L: ]Rxbil;նz9?`H Ju blϒjy\ڍ>c>T[ {vlrM+zHf|l8wO_5 [IWŸ@_ꃾ$ǀnʹth[KLD.1cRu^)0Ș J^+my^sw+ Zc;rORMe(U *0|S))k[T?J3n3r,WHA8&c xiJj>E RsfAq%WȘC(3'8y&wOȈmQTEX gqPEV7WVl G }ij\`$󷌤"/uhSs9,--#Ϻ 2aCKK-dDd5 r5`gA.̊w ?2' q#64[dTQJ;EJPq/i"iuK HaKd-CAS塪}$xy- *P^NB=Ie"F 2jcep½UKt |W:1cɝ᳷E M:n+(NZE[x3eҺvkEnKx'$N?qdÂWfLOZm(=1+%_f'v̔ \.[!aTjImQc2S0pcx_=GH: rc h `YaFD=8=P%]$VxmՌA^fi8z 0,om?=ޛ-  g7X怍6(dgG Kxwjy'H!3rrph$8 b*K=MC&89U ڤpm~_8 pR/^2[pk7R QcTE8'[ʵŐƵ Q@b,vxA};^0^4_@LٖK%9-Ah~ L>u,q~hfcYiiA˒"E9Jh]}ӵ3;^M=& ܈*t~ovaPi&b 4">p ?8X;F EQ}A #Ew7&7tdthLӷA @N%-£<]qmڍ-:74mX~lW^to|kM&M/dTpc;ڴ DO8e 6Jrr=UhHziŵ{Iu=& ^R[> kI9QULhAc'}tC+G渮dz7'EжS!lV;O3M Be:Go^WY$MBq{oާJs J;v4!vGLqbyHa, yJ(^tkx5{'[-4x|aӀV'uIL(xDBS;LlJ )Svm!.Y%> \S [24`ӑ Gʫ7;7Sd?W&sb9r ?TiQo2YRE@ys^|kAl%c:A$UضH.l K?6i!A"e"U|; | u@;Kr Ċ/m2Lqp`v1Dq~= ϳC!بʭU=V_oIʶjcU냂~zMDS?ḆuuXJC(0Pm'6:߶9ASZ?6z.#ѿO 郞ORmR  ds3% :ge7uitim9kt i b>1V*RF74ϧ' PWD 6N9oq+-#-k"8g~VU>Q0hT^{P\vwJ%^];fo\['c/Wql,E=̯d_J$اh0d bM `h-H}ܒ0X_SF"=J~ Uͩ$;`G~Xt&>']WE+a?}B2*XFvt#I1k@Ig3\V_խK-+3v5_Y)3z"mSd{M߅Mjnu)IN< Gq4dD^4~v<ڮO$I )v 3fBa=€&;SR Ꮅi̙9c*3HF͟eX+W/LzʄaT9B6lPHMq``HD6:`l%ŻIF%B@TBiUM[=5:(o9߸-NW}OZE:!@J';puTQo*\ĝa}bH0/:A.X+!x&=Z9h mUEj:DdCaӚ} Q:[~3Teh!Muh_-xCWкDWJAHB0%6XY﫪$dqWޤ6o1![0 u:TyѝP2տr؆55 ;I_%f)ِ!~؀ !Hˏ )mA$ԗLAA1(\w?ߧ@PYiFˇ~M֎#cI,&Hq~εcfT Dxs3<"??&C|zĴ@ !ZяseRmi%ef6gjve dYSNa" cKEޱ@kDl},ZXx"#H6F>Q(rϡ$PȢzqޝ&2EmıD*j"Hԡ|r6\,HIvP`Lf9&>F lSۡcܵ.$ t!de1tJ_vEԋ%D""φ!I>Z p9˦GÈi+.R|`DP9/#)\rrDc$4Fw)O__}( ص.fDR3$sIMc+x[6v7rN.ssNqQ}`36A|DG2~zV%_0/Dp8^N7$f?]T64vu**hMkw#STL/@j`H0`ӡq*%Ҁs~ʹjM^N3/C[~mm,UIDSp;7CvYP4=q a-#W0Tsm `ۑM뇠l(OݤJDTXڬbF z#mKӼ3aGL:vfb2w_oX`EAee[|`텩EbpΙtx{t?ᢀNz^2伻N Q}{*d ǘ+=)^pXi ؏g=l{b]@ (Π!m>j2>VCώ$h3$ T'|6Q/SqwǑq]tS^qh)P}XP21+OaUl9#[$4vr\kWP(ޖPXuK|w'}"IR5x^ cߚb_]Ḯ RaAcK'Z'*1sx.,HJ{1\fxQ.S/Q*j<kzR> ƭ!d<bjaij~[I,asM0E> 9:vSqjŬlyXo^qJzRPٶ\'rg[TZ Ma&aqk1.醼eKNk=vzp&yqw͚}&<:~z9RZM~U&G\fs~(17 βzbUp̷_3Y *_|ߊ_]qaJ{`272o6mZ!$bú2|mEGee 3J:zIhd"^,ZY嶡єt ogzeV/qI1J!ylvK%!*5`+{UI#.3"{BcљY%1T0UQ*ALjqGM,u=f7Z⮗=ԇւ7|y6C:xfk%o80fyaKn۷])3x;%rZREme,0Xb\,3l/iKH˳ARjia2֩Ps9.A7'xg𮀜a͚mn$y[QԻf][ϩ); 7ԈxN'F e@ԬN31nC^ c]S9qK5-ݛuDc3.wFtN,/G= wRI9IsMvq8r/KcaTs DtDaBF}J]"E=k C]{:ɕvNcwד}@dAև9^]ثn'v?BeA+.4.GCѥ` J2/ y(%3LqbE1n=08PO{q5m HBinC1BlB}Fŀ,c٭"J#j,7 Ce%u$s栈fn$?hP *? *fu~:%C<qL41W7ح m\Wb$_0?qWPv})853R%Sm#uu5e91ՙ[5ۜ7~ ^9DS/ʺTέ@"ZZ]dhJ g'W~,|Xkg% >!pDfV ~_+1|Iy>Zɞ9RX,dM^{&h>X(cWUt1HFvK㔂c0Q>4_?qIE:BEҮ,Qfi۸=!8q %D*D۸u`Eƙu@8o-. [_Z` .d_huBDY,Ct܌v4eeU K!-xaK"Kۉr>!u+Z%%߂Fuxܮ}ɟ~hțX4 b~[ {JNboM!tƬ Q`t\1&gosAW"q6w>˲Y^7xLr70Ikt;wf/?^IYVee1IÑYB'cTɪ8 sX j*"U;vLA\̛У@H0} (CTW Z,dy+4 f>34'V#,"8D#Q{c,gHmObLF>tϟ*)ds gSH Fc_H[ƷRQRa"!˖]c.ޔk|5v]T{8\kNi2:|ѵfn!e cxrsjL[-u!AHʛ:EoAmoK6\fFT92T߃eX,pAbGҶ'|8B߄4l11p1 l{OzβZ7H4+ovq\l#ATސ,O&cs:8{'F_sEC=y@MB`K+sGbI hZw7H,Vq!?DV, ba&U.z WA2c'Woe ' 3 '+:e~qD~m y4Bv?dO=RKSek/SFJY쌊XH+=Www0y+ӆXfB盳{JY %3)_׭Pr Ͳ 갌՗wY5QIi 쳫bN#e\HvOܫRӢ+01-넧@ D$dIp%Ŕ9S̷j= mҭ'K!m0Q͘V 9#E?༠ۉ~;w+5X&>ҏ?\5A&#wV-u6K>J-+-thy׻weݠ} QuY{^Mn53h)?+6 I[טCM0i2W*yI5utz$hnPfjy8ZZ}5wm?1uYRl.v 7ώ-800Cz]Kw'YM"3xu-}87SDyξZ{yK֟23=+&duߑGOW$kgsvz[Mi!H67*y /DsHt+!Qk+Q/Nb8.F K!Z@]z T/?FLժFk#$ iPG$k:m1+CA ̏qhͪcWGbe~h8Wi+vt,Vv҈HInzskٹtJ0ms#K,t9Utd2dZ0ZF }A' }j:^zCqv9HmPlA]WuNn_+y1p, .֙ + cL"m74xvТcBײ r@3CIvT],QO@\lj1 >t K_B:y$S#v4֎ajM= #]ήf3*H{Ʋ Y/ME2$'ҲEBmr8, o4v*-]ݝUt;j i9F/yzv(-ٶ:tX vt w=`_[f[#%ϻ<Rn"yz.1]&yt),}v\%jݹ4-jߵ3ŬcU<7+T£ pXB(㋒d(n=TLE<5ɜSh&B-?oѺ zӆ`ݰR ̄ܰmwwϪ6f{K[W v uұםȃdTR~k2'6Q2Q=:]]G#y)Pۦ9+{>.t5|T񎛝]  GQT}1֧v,ܤ׮I:QhZ)HK<*$1SS{ͺZJwKh]YK6ɹ L {G_h(8hap^Wx#Z8 .&OpcR(mY[mDb:W!>G{q$cƩyFN{|>̕Aa8I⊻Ȭh}ʘ<g~kEXFViD7 O47J+?:fI/A2ۨ<(57וbVqjTS I>yh]>sZS աbO$f$ K+{eo՗`+Vt|=F&+?G^d|Z `S5P p^S:'"Uǐv](1[ISHL/?4Ź)'5&yoϑ\9`)K"|hsʟx̌˂} h\{oU.4DdPr|u1TjM%$(jޮ5M`{tqS558̖z1˰fY9̝uOKQR#@>ͦoUNgr\XN%m/x1r KmxW^E73M;\GOow UibDҹ]{e^5v,Rm\ƶhTn@CE,.0'u<++e8>2QL2l3n)=4& H]*9pYF c7J=M!F+ӊgO9|+OWS#Jf;XH_W~d'f~AE;gL㠷NL k\Ae.֢e(.UcL;'#yP3jsh6w k2 uXZբ:>qEVq(E%}f:"A٬ ڵs.of Cᘔ6e+bd ݖ<ɽeҴDq2jr$# ,yĦMTl%?,@ Yqv|Q".Hi>EJǹy\>4lggVAUauzaJfWQz]d2v;v K/n=q_({CM0lI~sO%],䗱) މWrBt,>"j<Eh~  DJ N&qR~oYϕ%] r_a si[کҨoq*v7}ӲH$Tgw]p8^?FT]A^xke i:;K.Р֦a'5LuP%8A"ӛ AQa uDTh8J8yqHy_~Z ]lҩ5mJ: `7T;`׍o]`c%`#0C&p=dl[CL5,[dVY{jy),ˤ!EXL [ɁB;q _9m9&ݎ2@Ug=;%~&_99 7V}kx6/e @.Q99rKânζ7/m;zؒ6έqAWG6pET*ǒk2(v(@{Y'XWxj!Rv;[:\ {J2알Μ޳_Zsq!a[}^*ݬ#ͺ1^Vu8aQ!$"^B|W׾`Ntbn9n>I刺d\a!&E2:hm f @cI6' IhsXnmǵ~V{ȨC#Iu&";<2oX( GNvLwgbbᦱu0niGFdos|LR8Kn~*%" b r&,$F|hqȆN ٮ%ٶ G`lYj@vHIzR "@sHؑ֬tG*ͽ1NSHKrtG-v}dI`JDiGIrE8fZgh~epgf W05!e :2Ŷ+LU5XZ ɨk9[I=W?t|5j8/rI,SQ%S1sj:6GH晐I*t"n6.6+n-8^JH K-0uBkM'Dc^Gٹܵci\ga% V賲]ymaWW||i$Lٰ^NzvL+j>kte>b2kЫ->>y6dp L̂6n[J4x+ Bow¹8ٔ$0>]@tC-y?@eKMSH*S7q;̨)Sj%άG|< -7Y9DnphxA"h8CwU0A{S6BŸJzzIt%l/ibsS(fFrɝ|\au{?27dފ m[nZM'~\amuٰ訢~.ن^^_Yt-=ŹU5)R)# Utq*w7y'nIl덳AZ(sN*sM dj6Vl履_(W1-n2 $1D9}3 w 5^:1D8w8''4.Zl "֝b[\o;cs^ފ)s}^h;W[Sj֜%sDlC$vBCkkZr04aC!Wm&Ixǚ"ݻŸwL:׌ݢn )T2naÖ݉27oEo *tI!`CLE;-T\E vSԭ^ hK80 o!_*hI{4dǻ]@)>Uв~|ֿ 3^ޚС}W!S)pyY@sbjp?DњFgwzi)jm܀}!֔%6K jIG[ҙ?*Ԭ)-ԇ C6= T/鯘iܘrFrc7K]#轞b9֩$bsJf2 =KՅL$3E4W` r:" l΋ds&G7w!;/cr'7Zv}x #d{l-?fĬuOE_!yNRO1VVS6R}-Tsj>j]zlz5O] lF~+>m&6^S=Y ]2x5"7>ӿ9FuiYsIjd@*2Q Q| o $-Җ#n,{At^f5LTa2d7A"e(cxuC$>湠d%{(c@M~FRˆ.NBWreA^%&_k1"Pqq&L8ׯRŽqӂmm1h.7Gi#aypa6ZQCOzܙv31DieH͊WYTY{ :D,0 ^utEUOzC^yrS(Xy $"J Z|N|xס?nL\@["eŠ=xZ(a:4W\8 <+nNuuDz5e.Jbv!D"{ L]hkCwP-0.4cG;}md_aqzof MЈ L B"(Fr5,xUQ.}(#d i0m{4*lE kEcqG5^)o'Nf(t [-$hk#7_N񏕗k: kU EEE>tQ[ekT29a[Ct`f!teRu/y ~1@R!O\yqȚb6:׉l(-I$Xi!oih]kwBp%[I 86:T(~pZ/@d((0ܣE6yxXIX<ن;eM߱ e7[$"X d3%ʲnl4DSRlJ͒[]@_6R)(ZdYώ`)ס8a1x_ƋXLnD0t2LAm;{͌Vog}B]rXSh038ҧ ::c;zi>=6{CM+^o"w?Nix*9Y铋8E[wLK!Ie$Xad>$Ide˧/SCzq!*x|{7984醙:[䡽 /D:r]df_@ٛM d}<$6Ia8.`, @)b(}x(:.TdV@q?B Lh`܉iU)Eyx&<+c0a.Ab37RD]"E@E|](.zx\imDGĂUUĊ lxl{ -X}/ZlQE6, a~ֹ *!0A:9JwÅ'BB}@U\ r_a%ICCe>hCACM@GGt(?΂yy} (cCA[.ÈlavB VT󘯞^ @O]Aq"w$8Q$B*"(S \6y[O# BTCTn)DueW*@-^rh8 sդg .=Cb h*-"`.DS'OtQ.( u2L ?G"tPQ4XZx`MtA$$drԪ"(fc#Żj&Bc<;E5;.w4b(Q"w>Dȁر2f:JWMwe:tRs0у= Ғ BF,F$ Ā2AhU'Q;( Pߦq.Gkhv!w6e$~P?(B <*EH`1 b܂SH$"E$(%I!$8} qpM)oR([de!iV KwI@f lCkBͲ:΅pQ leHBen Vߨ7h tDDTdJ(⊬av@#U,ވfL0@D/ PNJ؅ AE-=|PNjcU稠/f} LU1{IFsݨƂLP@ ~= AY >Ta,qRC}F~@!l=.$IY lfvHneB.px[_I-^nI! NzJf1Q~\B~QCms}3h@؊!`AV@TB#~Z(hAh 'H('kQy!CݎY Qwښ"ڱRUhDn_P2`ܔM!+/D$!`mjO#q+BuG$Pm~Ca0,DVu#*cCiRTCeb `c?J0@Y QJD,$a("v <[k5,HLl0SҘ1I0SHUj!$$)!> I$ӛS*`V"(1#H0*R’E,? ̒ޯ'I,L`܇A~J*:x"9DX&('7V =xqD07@xbd7R4x4wƱ oA>44e!fd|5M_4RMv(O: x*';w)'B"X F'/B䜒m*F?Md&m2јRD;4DtT" Q 1>*K}RT~2'xfjOvBz{HE 1 E4$ AFK+D<}S[gJ- HbU.?" qb I$T}EKۊq.|AWeY|4wx=W ;C9yOY0dX$H 22 ?Y<$kn 7?JuM&ڀ[)y6N^$Dc>= X@FZ#*`"*!$2!#l HQh, gܖr}w|)ibw_T;m }A!u#ǬyB")$Dm|yqQyH; j`Se,4t%Ej 18{X+ ,75fZ .mHa``ɟQa jZذDh}jk,eŒ0ڤŀATX)A'=Zk9tt5uRJV`QGM(wс"k)O]2|;}q lw_f4bvDu D1t `!!#^c/qpB +隆P6 vP@Q|H b HF(, D/P(`Y"d"0Ev2bHoaH͙@" dPESܳY/ 4\]VY9HnWx!'"q.!C+(" lNzHY `|H6_3HW!H+y7l({&<;= fA~åf^-M3$S:M@_$DD}5O)5DX,[5C<C.7>}pE"$@`UC@38~]zmn ٲOОN.)6S5HBwwHyH,R UXz "q% e+Ia@FBK؟u\ fS\!#= !bӫ:N=F}r ȔP(Cx '8yln?*c~O:'zo1 Cܼ:X} s;5%"M( jLnH\S;_Ob͵gCgmH`j~ (Ǒ/4\B, GB & H>Rzo!w@ȂHĄ I%AZmq[0'PҰ9X-DbȰ;.@'hEV 0X VN10"'j0EUX1QAV UYe&2@EQEX,X(1Xcc CbcV+2md%ҩ{z+z fr@"3Q( ,(͹{ih!o{Z$$"j 0ӜFzvtSjSL ͑ =]_2)$]0:T73̈́0@6#f8  6B#Ng)PE[ڦ#i3k &s/B&]REV@tu^tr2ð! `o[A!GIRl1AB(A`Tf c h /[+罄^katܾr"^"e(kx2q}٘NȆ8<,r?溽a`@2FA=(?b7: #m*Qcb*1U'{Q賿w?B"BCgvI7ʄ2BEHI•b5XX.-ko;;2,Yvgƹ(t$3`? cHV#F֣+ ֝[UwRBɄB!2y5 (#dDF *"0M }&zoE;J+$7$6݊⁙8H9jBA j̅DD("+C< jLXHbB7w|o ?C k1b`35/Pb3&R~Z FC VE<7s?)>?~gZ0M~.ԟ>Om<ݫ^/s2( }'^:)%OݥYPfdϛɑ,&$d($2HavmQxrbI*鄓m S +&6#wR0vR5_C[d jb7yg]hԏ^q@a%̆<ɼ?տ nݣ@SCp쭒 q餬4{J;(j\=Ekhc(w'C˵ ~x%aOY#!C-ʢq?7CI" d6VhddCR}(8310<\yvݿEB;BX^ΔQ?I9Ѡ!%>A@UX@Y?Ɩg|j^V?I!փ$ ڳQC~< Uz0cH#b,{ik}#:xIBdu JB G/\LSbу bk"q\t3 Œ{SE 0|avo&:X|3U{:hdxeP@!">>LK3tY6aI[,#.^_uT '/G˭AU.dرX%`I!lSẏ],2 98ƾ,V]#ljsW Ad_%|T+#!*]PH <G!y`)'1TiJ lt 'a-sN$YsU31֢fS]Bsv2O晸acf +,Wu9#FY/H^Pmh `Q7ADD*!? HAd@ EPR,@ Y*EQI `*I E$KdEA@V@PdA@0lB( b,X)"@FXI>D@Y ", BŋF,_YAB$" l;HaAbRBV"(ppE%;KOěWϻ}f5iTd r51ED @D|| VAD$ *mf^b l(UЀx7߇h[1qӅn~w3ܳdv4$0qEU[PR@\Ap/z% FP^bJ@ZdS S D'wBfk(ݥ6p btP@KdI !!AUeUS6 @C* b F8&|)fqp̋"(bwmh-.z/1A4@OAL|**9}*E$\r8FRB^:Y>tsA\IqmϤeXC{$02"]UEJ@]dBz1D(Pt-J46b2  )DT< "bB8;j[F"pw@D .$,E ر2* G(*2S|G@WALJ 2gQ4oQ O/Dɇ'MP@*$=/]677YŝGwEGmQ/5 7[iPv 4FQ@ dEƈ7⡭"B-;u]Q$Aq@MU$E:( "Q2CZbObu)EF坚z GTĐyN$N. 2}MjTO N({waP}70lc}_A4^+H jM .o?Їcoy[=,P{u`O4@] ghȠcOS𽵜ߞoTmo'ă0[}os] 3!/`pQ`,dQkiPl?QR@ӱ{O'o^cs u25|O|kuw4Q> "ϩ)QTUM6; }(z=>'sCh2@;٥qxz:g(~q(_Q>/: yݖOlE{Ҳ>'vSA}IĹh =D]LyNUNY wp=ꂻ4b4+>%)1)A,3B0bPE[ }7EN%X0v(V@'lX7M5]((s QDAER/h`(ݝ˱=ǂeDB$2=u*⨝,U@<r"XA"4X@|) D2h_w<Қ lqPS0j+T@v"f@E_-_5h"~^*dPBHI ,Sv*좩PnDpʚQ?Ty[ƊDDɠ;}ONs"*~nO$< 0M]X yd ‘@щu4AU R$+9e@@^vl`Ly r,d"D&~)PeUf0p#;fAݱ`KOyT&邿g{*1F@~M*g?Ӷ>ӭxҴ,Ϗ-aGW<>m?i;) ^A3='? 4@}.:^ECf|G5 8䶔(*H{:C3t?{>VڸndDCݼˠF]?a<("#!2xsz(\!$@ʂBdWE0>G[6U?[@oL. ql8>i<WÂ%rk>'P?g@DM{* %?/ }1AN,%yyMexP.n+Iy"'} Oq/?z'*|^rSA@:F4sȬfaN"gEL D{cǟó7 0GPַ]y$jp4E,C>*KH-3=4ڔv~\% X.?Jv=:sbn&Ь>A؜ FOۏ?wa FLcM$ns w8ml\ aŇ`,1U%?ewI!#e (|BbcvbU|aj6W1;ـz=K~jwzŸb[S8"Nc; 6 >-t}}ѯmrk]PV5j?W]DN>?HPWmirOUD7< EAKN?ڊ2!Wq^#?ɟN*1W]Cz?vr KU(1s1*rSEC/s4Tt_OP͈(_$ d#EDC8/{ &'悽L9fNGyQ85D_9A[B@N'rr:b}$Qd |[:64E4(4LP8![X-DǠla~3-3 q '5roϨ`? ca_ךs\v>n5 Y'F(n  ?;#q*U??o&7$dcVwl^u2'_BM(" e,N/^c|^lO=̯_sJǩZ@I@}ɓV}-'̱x[=D2 z(=}oEA \T?PAX!\'}rqꭨ\~h~h҉GFYA@=<CG7.]Wd z"J#ch(q8hyfSBE1g)rY@T320 Q  Fg)#qrZۃLV D;W7jmj:Z{Cܸ7bXc\A4^Ne("xY鴹|xo!{1|/Yw5ĸL?;@rA`BAдhc~ ?ERUHzkt; 2ض޳ :cPĩ%!vin\ 2la뽆eoCF".)#%ȨښPID`.LTu bLDk&tBAKc^\vCJvC{md@/E9y?f {lYa&Vk_/L4Ѕ~ !X8ΔmڊM\5?\<1w}pzO\h 1-Bn{\ُے]fG6HJ+F~ }S*F+ y,LBNL_l5?wǛ NTCp@@XIV :XH@R iB1/W3?Owץ"lC`iY섄sÝ?6k)>FlpvvՋ:9G$`P?;.=Zs=j506p$g5kff𸶳?;nPV06(oy)` ?Fw7u[JW%u3vl=66B]OpX`"0>[( I~l^3PnA]@6o%ݼ,cŦsjH ÜYhgCG6}^~|eJtvsw8wociX?XH] d:8,E zRlhŒBt0ɨ%B&0F޲EA@ s\KCC q ?p0ݍ?r#ud(\HVNnTw$܌T`4pxFұ6Xh6h ?vS{G$M~}ns%jiY8b9zX*{hwrRI[q;}-AA^F*hTB}OC[:-lPo ȋ"OȤ, " E aN~&^oĐdPN^gn[ש0bbke@$mqxOŊ(1 |6 lGEȚ@ɀ "'L}EByQbƈeG=|Ʌl Ho`ScEV "' r=/z l(o.F;cRzqoZn_W}V/itKDŽ00{}ne[iy 9g7~n/ ?Dː``!~BF9?~8(N纐}tp9FXl犘r]7 ?yz{ˎLZ C9U챉 ?ɍ+ p,{mja:s ƏϜ!q9P;HB, K`r&HGXy~?{!* QQ@C9gռN9Y4s0N:9rAt ".~zHz*i%۳Fgf>=|}23Dt?.Qj D9i@O~Ub '`ImdƐ|#s.,fY0SFCSk#9Z/{[Kt1`QyM-(> ydC2&IEfW&H'' 3l _(T5u"$i}wrpYvm5'0u$g 7]n c$F?. ;~e7TC|1祍r]}CG:_,8/(v<с 9wb gu- p `&0>\'p4{#JDMFs(Pi 8힋EJKI,1޿CIabrbf`^p0C*Il4sX+=* /_''@a̹dH^Wכ)!uS@a1y3U@ˏ ecUE>ٕ.\3hoW@wA`M#L$h] $c4Q1aQdXd$yETδHuAKd^.6Es{%dx }o[o+ o^2g۰# \;s!~A];+sG `9Dg]%g|9y["B\ `+rDŽ!(OC$e~a~Wet0ܰ..ã(Q.~yoq*JcYX$bAG:+;9$qj!`?27(̅Y4k_wLڼ'ϼ{__9Idwܔ6,KErzu.%(=9ÆeϦ05&3 2,~@~G`2G3+W,fpT]ڔ\4mF/Y1-l׿!E@F>2f PvyVÞ*7T襴4(Q<;m"7~zuMK Lo-=gO(gn)4ƭ(27`L6S Ӏ1e|LjBЙy;%ʹf Y_هmLF_@L԰!A`( so2b$^A cD(CU-S.fPb ,0ģnpM ޿eddE`0ԛ9;1t򃩮} P 7PKhD:L! Hl.]kVEN n5(EENl < ݣ ãWcI$`AO}~J֚A1vZ ͣ]VO-Yn=֩-||ܚoFT!>fy ނ-ZB 2L.iJn2q\YxLF'm=4NgCW7_\5N\u>@y.Ԧz)~ko&/uq;j߻g+v=Q?1;㡽^}"KU`54 c (~i26fGl#2F|.ЍL3i6n mmBZ3h;G7t4a4.Cs^ Tcf=:vZo tgsAdcTR**!ԌX 0?u b1Լi3ń? x`LE0b/Zv.uÄv;+ba=Ԝk8V~vkadFX.ǭzOnBnCuU;^ *boB~xPAחDEY^!/?cigɃ`Ê؛lUx!$p@x?SWi>Ϭ7LAuM->.ޙ 'goMuZ@~k 6r8Fm2SF贤 :Yv)JǙuH4f <{ͽ O<*k8>U&MMHmɘ=?Z> C`|{5TPf,z1$/iPѠ =N.'[O(:!W!7ǐs+FFqv9#8q}O\}}UMwe@O\>|~'ð˦ eu~?[^ykZeFUi }eekPsrU|^}_D/P= wKb7c?y䒾ءG{NHU z`I4ގV{m?UϢ@ OUHʈC+eS=M> e)xC 7T1v Y~|LW/z~T@ʈ ;XeI^ғ'azyaur1`dG4cЩ=6s@K}A ,݄/|F4# 4O6y\RMl N޻X e{0N2>^\Hʾ4KaU7&1+J]B!iXph)!֧pܧ`:Ed}2]3YA"vҐ*J@,J# 0Hl*R ),-r6V4{5C3~wRV<æD<#CD*e 9 l/W*$<׌QPLj"4USA@xA ܠ*?6*d24 Bl靳y+4{dL%xȅ# OORculԺN&<QfYmHʖ@{z0DTvP@>tEM4dS]Ì_a.􉭃q 7O& H  dyif*={_m.e je+nh=\Q.pȈ|Zɐrق'-h״va֦滨" @$[1@F#E,EhzgfPLjmû&cADTC+gEҋTd !"t%OzݓULDQV!}9Zgs6qԹz~37*DOGaq65"lӡʮ Nsp TDW_9BƜ`+W_B.U⪾*8@D9oXW9,9@:mb̈X0 8d;=2%Ķ•?hp».*S&&OL~5bL@4FVMDI73OS.ddl Fzjk,M(:&|[@ Q7:42y 0@maRE1˛tʟqW9t-c_ˆ D7s)T S&)3`*ذ7tї/Q2x=*&!"^mꣿ#/Q o2(,hDٟepTSE8X1 b?eh)z*iYXcDke@ɎDS*&A`hފe " +n[r.QUKhYWEEN2(iI m)L=7yLYRWor&ge}S/w1Ca aJ66l Z~vGSSwNŽWqK yjaDhdl<(\/A@ Mmz\q,Z !X/ΨrBݎ']b oa" 6_Dx]~PLzt8m&%J4mشx@bÕ=u dr?Yt0Y;{vak[E -ZVE"% ʣ-k E%kdFP )$UHJ3kHb,YimZ6 f"RPb"C$ )!0,iWLŐ+[l%+!{Y! m+Y&qa>II apKlX띆X20܅k}pЧxԡ0`I2 D TUIwweޔwkRysd@ BuTA]z 8?!{S+?;y43?)Y@2 96N-sU6_cΦ !dto,bo%Vg|Fv;f@sp2!):h{.}>t rێSY[N!<`$t՛9}ΚW3wMI2!2~,#Ԗa˯-uWbKsJt*mv?78G?(nv%ɖҩO C x8Kdׇc!8Y" P)ՂmƠƊVcK0(2  $`*2:˾*ワj[cDɟx RsqPnByc$~Fi Rm&6BQr]TpL33.n۹lY1jTbpE %a*Jf4E ԌX,+ "X[dP&BC2ZX)$Pډ1"9VB,!F,,dRHbJJ:jV E,ՁR@PD*BU`iJiEI+mt Ұ %iAVsby-cM޼˿vjdm"dL3ךt\^_C*e*Quq;==1a5ød?Q!2#D ZКYK#M| `OI@Q!n}n#{eZ@2 @ D+P'W"|3PNYH3?FH,1]Fy4[Uf0e kqc\ `p GZxz*K4[} @Zۊ:l~Mgb޵2V.vw6^R-d1@( 8+D@֘"&!QJC3ql/  v; 6vʉv zQ"8Nįnϊtǽ'/dc Uq#EŲ|; cE˥4"XkZcߡijdU2bD%b 72Ke@+ O*aP%TR+%QٺA$a YfY D(d[ld!*,$df0E, U ,PRԭZP%V(K=\jԑBH!R 6abJ0mV!1FCL4X {6أ Ad&Dhk˵S!wMN&%=]G @%G?ˬ& LT_a0'5GdT3"S$f˒jΆ,&Ǣw BBDL&9q^, 0q:p/ZCYDƋ~`%r  2L]7 +S(;n&46@LK"!Ĺ>g t12V]FVL=Q 9y)P3猀jŎUhCI&bWqyM6{W]o$]3T"y1H虘vڢEi^'%:@Y0 + )ñ @ʑӒ>Ɉhѧg@^v<Ů@Rjp*w Pc[zV]iMGL&fcUa壩 pf!Cz@FE&\EIXTV[yXQKj-XvQ(M+*M Y%T(TEK`[d*%̸J+ԨiD$ T-,VJV `N d2ՐHT#iEB DD$"Y %,N_}M"( '\Z0% E0*dVybH06[5Sįak-[G#^f6]f"j UGjx[+YmE+a(`0ESI6ZX0`~Σڔ - ~c #IfT3찞*8mncq"u4r@f3Wqy]>δq 4 q\YS/*AFBt{Z!{?K:UvC_{6N.;ܸD[@3qbAeI%Е AaKmJT`*`! )$,1c+Zi XehԪXɦ&uL҉h0)MJ bե TB $ jITeDa T2VYmôf<6yOy˿ @XAaY`^DR R1AC̰fEg$7F`6ʨ*URڥ7PqҲTb؈10k *[ RY!P [Bؕn &!2LĽ'f6HM3M* Xdي>Z-iTA D@"eb2K"ZFJ$KBl*!@{k+1Q@* at:H'y^_sy}AF,it24rBF&L|ziCz2tmB'@nb_{̘[c@ Xm)JbG3e*3s"#DHF bA=5߲ߧ~eTئb"M!mwثѼ!d_esKwT#LxR+ǧ`G DMͧsu|(@zEmF84SA9WOi,[{FmJ5*٭2sP B;T~e:6_<6KMǚk*U $WǴES֙E e§OL6EH-b %d|S-m*bRBbmY !U!YPFDKVեF֐0nRő Z!0Q2M b:e$HԬ+3,L- mJQTdFH%V CZTDf8X,DzT'+*$L̽یڠr0;"quС@}ӛgض_Gx1I{ց%B8ۆr&tddsP68(q`kąjCe\5ͳɕM!6+(FQJʛ[&T26l"edbs'.0_`&"1,H{EllUQr-Tar`bٌ*/a:ŤC nZKIsqn307,nBg_(<xG]PUY5+srZȩ57Pk ^mћvtg+40.xL/*=cr&"ن Ǫ`9Q " sB$1q+`h:CG-2s *FVKnOJN2CHBU4l*HTF" m]@)՗ղ+XT !XM Aa4%Z++jY*hE36FArEU ecX! YP#jqm9 $*!+cZQ]%i |@Wsw֕U⤖-XTdϚ`2ء,?!B2?LF^;SnPgR=d#š9:%$xʧ̎vHbHxHk 4##q1lGB}%ɂ"-C1szղH1T1(ODRS̯R)36g6WRO1525zjpTnJ *\LT(qv[X%Ի.*mFrUEF0@0Y;&lQȠ@.LZŏWƐެrX~FHͦۍ\yKQh-|R 5˽>/#4lkS@C$2k1lfn׾'L&\3O~W8Ɨ-iQp^K3&Xԧ=/GBL (m65LCz6JoN˫!ƯCP .bo2k@RCfS039M{$Whyb% /94y͋[rl_7C5EU+$VUDJbjVdlD\հ1&4Y+!)JdBc(@e2pt嶂YTQGU5u֮@1VTPX8)bĬԬLQ itk *lg{\18A8#",gcc]aVFv6 /HvC̨hꁄȋblqǥ!+jQDy5q=0 f iXZivKjZi2 CK=*jbI5/aff\`3Kd^Z:Ffe(6] һ"S7-QsCoStz n* {Ҳ0TWۻ[ T3Jū̬!FA )ױQiюy@4LRjЮQ5XN{P2i$oLr`'g+T9CQΓm Y9;#ȣ?)"`.M/e 3؆-[Ăى핫ٺ2),=b͕N {lOգMţ'k\Ȩo"<\(;0DKb٦dӕRRN ^l(d nh;l&LÂ=_ 'wGs7:k:Qɂ"R\szW*qi-N)z|$hd4Ub=$īJ,ٲib)*9@b-mRՐ(m[d$-dF .`-cKl e`TPP&ըЅ I CL* V`J5e#M1AUbjXD`F@(ˌ  *-K4YMn6=si{. ̾7gY̛-dԕ|+ tU`N5Bw"9p= E5h]e㶖L)>`"őĴlP `Q/,֓R,>x-(LT1E"4{hH䛸tiq+$Vyju ^)0iN]a͕jfnK(Ia /F%cQ4)⹔F?cOJ/6%#Vcm>|h#[nb"nCN>dS~z'RI 4B@ذ/3wMbC!*Fu oTțö[` QՉVAO?A  6=SzE+I,-UXP,gҀ@gCH">/UD}ƬR>ԅtv$W88D`TrvX1E!j`,Sf@ҥ0X2""pNR{8P"he~T4W)w6q6*koQИ d/Wn@XcbрPЕvT. p@.^\ E 4A~jL暽}&d 3 I9b[LUiZ٪,{5`4kj؏-M{bQO='6NunM f&"A [Mv!j́KD3M6N?*ԉ,\TҜtQL +aK0uuHwlw^Ib_3ʹ7r௅ES ~2g]DnaUHȀ-7?Zc|}=~ih<764Ap.FHW<~ɭZm"/ykLij0DèA]/)qa=`#W|OkkJoaJ^s̀nf\|IC.b`7mw )*w̸"^-[*ΐ";I~kCJ9W8yNw3EŊCO?&ec!+íG۱?vNHh.J2}s#_Uɋa`xn~~_pq >!9лNl up5 ы4Xoȏ{ΧyCϸi4liR@F w{ହfo 0"02PVy9/gO@U҉kL8D7UT}!EnpsX]tb]uKQc.' tª oS{AB <"".n;; :Oz1a#F^`\t,y(#Hv3Aq?G'UyZ"]m] 9Fv5߽z ;-#Fw^9-2χmbfB ?o׺2>tJ Igf{^p]:.'!qR] 0בm]u54CPiyRo50,v4Fݲ!*6Vxޮ_1`aPZCJO~k ?~,M,s]UX=ݱ po+/}1];^uzx@.A\Uŕֿ6|ԏ}X)P۫Ӽf ADp7Jk𭽴fm: +|{?u]]bJf]fsSqqg (Ҝa=Ybӟ}ݚ~@ ̢ax~1J0!: n!ԖF9\xY 9Dޔk{LV-/*j,KewC'.Etj9m݋RD=9mzQKXB䀙5bd|yom Pwu싾Rښ1Ԛ6J>vXl޺-ye|PU>'rsmldΣrHKz^vҋM4Fi6ty+O,֞CݟPkѢxy39M o +ׅoHʳ=Y|^cG_=uv|dg?!j /0tNV>|Ԅ$# j#6:m-2\{=k'8gK(xl LA2<ywP:*%H. yp@`j?ۤ 47;AA/|nx_2gܺsbKS6Ƀugs_S[z0FI3 WcV F]@dl!kuAyaIb1A tT;=8(-{ næ8KzLWt+=qłb ͗H/iʏkx}YΫFnCP !ޫccq4G]SyaӚ:dR`=c}T2$ 9>fjGAW͌+ 4q[6Z5FKEq'u}s,I0nlv1=)̻cCsn3lav7oz{}9Ke6m1D #g_{m"L1/_/"SKxyt-Ƿg|&^#Rq^6k2t}d$&&+_xTt_#eb}k=l,u\"Eli.kTxI:'AQ@_rG#z@/Z[0vsr]vh 2F3 bp"lqācxx67mc Ɣ2 C &ԛLd g1_}ĻtFK(_7 X4{y_V׊e KDq3U[F4 pNNˁs#S 19u<݊@oKݺYoX4I 4@[SQSJ CVvao4fVDerC,bû,ƾY23hQnaɮ#e!ƞژjlp]m~TPfvn˒od0ԯn)Õ#-3Acec$Bbq7RD%c@.Ɔ7u˓Ujj5x c;9*P9v|sN'W 򭙼h_ۺZ}||SLGm?f/dg6uߵ-j$=0dg4#d '^` 5orT>ce]c'bkcf?"nEižzrb[O~pLKN0&ef Makw]Z7x:"F<\Y! E\('Tzx s8>Fх;ޑFϡn_'%PON|&6[w*)!F9e .[&v ;t:.޽!ʲHS1z_d0fFanTc1^e`; s:<_a$5m+#9EFjZ 3@R;iQ֨li6gt}ܛ'_tP!@UCeU!:IWL [--u fľ2ijނ737{+- `\k=c߫nmg7{LNcz =[ӱԎT<7oMKf_PֿE[pei+s9[Fktqs{Rտ0;CX41E8 ` KK/|> 2ɺ1H S&Mx!6Е7=er;}|ӘS8F?',`yOsZArZ k]C={كV=)1R"Z1pU#>VxۜڲbPr eo|%_3@.tp2|`)wLL$w6ew\!DyY1*G{U`6ˆ쁁OPHNƟ)W aǰ8H` GA_.B~?N O1s2.KUL2rWG KVV-t:l=H11ֈ-" |CS}qY]6TYe޶.jBhl; o>:QO[od*_#׵i6ݻʉas"VSbD]r7U_؎YM^sټ(&}M@˭wؾ8z^鿆{2åSWqsLO"XMu{j7h}SlBcHOꡭpTlI5ƌҡi4i9 QӾu9![2 b5, sp9,^J̥Xn^On⣪;.ۙ w@:!ɍ:C?L*cb ~gF왑ùf/+5z5؜r28}2'9 V_lf1ggUh f,Ŵkl١lYҤ1bQLygFfұ"0)6וvzTTr>OE+nc0Ċa>ې3y+,fI605!X̂t}ߝiBl)saFuxu^~{1 oxXeh>"y~{ݎVE*x1~CRVcx\ 2)!`"eaY5剖%û(P0w\ݷ&ÛA!Bj .6m.f fGաJzW8L %(f<7^9Jvq>f|[3-j*>R6z5]mit|tW9.!y$wb7fyotde&la+nofP=s SVC2ةymJgRV+qȯ^ hk^fX* 쒪(d;%tO*e +3xDAZ?͟!l yQnwC;qnUUC n ?w߾}}=qP>8E#L_,cߖfnF⥩(32hy:wTwh[VMxjz7'/ S$hnj泓4ezD+ i܍sz?JFR(=tFcy_%il&vu χbnyɿm=dHԾa6kp^Yo27vӺ&g|3XLg)ُ8<)2(Ɛh* Ci;N:q{{\]b)[nUtWZ7]=YUt ]۩hlTpe%z9I(ZZd#/;óȎwQYXw)^ezzd oG޴Lϸs.UEkee-ZbcR<>sI ^c[xxMv̰||:BX1nj U7ZY~:XBucpunuk3uaK<+73vd!ݶ7e80ԩg9(gߊXܘK5ݍv#9(m֛ x+8PkQTh}LޑتP&mYeV72:,NKcVr:;he\V_w 5 ӣ emUBUve)u?CՓ.Z$w /a؏0©r߷,m`JgAг7rSkYZ'F'#= 6l}u7;ƞ25o5c> mS`mݘn޷?:,gNx { [G˂K Z>4D۵sQ-IjSr\:q8a4NX~[c|&]Mvq qzǎTe2tq]4mR7UwܑpliL m'dž;_uCl39]o?V7kI[wr~45aY*ks:o"MX__ҙ+3JFDltY9e$zL4ԍ'eܐdF2]vwq81 L볞%]xt٬$=8 -:߶Sc튐kGqnRS\o_+ f*sϝ&OmIΧ"Q͞!/ni27;Q-U}3^* M/Wo{ Ap&TdB?rSXxLW<.Dz=N0վo"<3+ pU oʍC!ٰ)emx{ @uf93-TQ<+z B /cH`02ivM]ǁ8b>C)u‰BYT1>㤁$!qwM~!{V6p=ŽB$ebr;2M_:π(S")@Dac 006PTN#|j YL]v11-/ u\uO8rCop Mxy6ݾ~ ',)4hiA4D/  ` Oƅy 7etmt3ӎζC~ntfoU!UIk6D<67`50cro#8CE}bPS:IĦ>c q"F2g8{EOmNh-ЌN`~v84 a߿i?_Kb(HY\> `cß~)?-diA9.VhSizC @n!/dFnCJQSz]+6\ v.lO_LRgSMm(Þ 2Џ+L`o0w?w01_m;uc 60ח;.{19X_j]ȣOo̺{@ÎsxVJ$ЈXGk_?M}V4nsor>/R͗f"]_?m|S_ >*m~i/tv'O/\g/,:i/ߚ\e(7Y[ DW~M"<>YGg ̿\0v_G7ÀwJL6Ǣt|c> >7xMϗ6/nQW~MsEx,omyUnr>=<>g ݉p;c#w'̧X4B6 m;KתIqt,5}3l?z?;ȾWm;ׅblWl29d;!K?k7|>7tZGF_ݧX-cbKF㣯r> =-])إa4qG}h}'8ȏ{Ӹ?n3;9-6v:_ .\gw3im;,ɹצ{E eݸ~ci~kUtv>=慮=(~uW~u"0e||]O>mi]ۼ<ϟrݩ%'i(Y,Ȝ^COy3D 0TQ/[7($WzC! ?{.7ʵf߯ Y q$Ē-װ^Elcif! 02L_B F YOglbfwq#OOv|lq)ү8ߞ,5 Ldz)aqq;"FɅS ooZ(Uo3w,{=EPA`Xxv +8Cm  Ldz\ÌNƌW5r#R 娔!1={_M3oXp2> 3pr_3 x9.3yHvYi`Uɣ5'FMr2B`ܱΐG>tSzP7jnkcڵGvh"} 2l4̞>MO踂q>3u/W9MF%r\ŀJޫdio1&X?+G"یkymxcxZ-백S+7Xj/3e,=)Q% wy^o;fy'J?F42OPTbAQml{ةZ\I!"G#Q ]y0#6HNsq%Uj l \őaÈ3^j]Q et6 ?oz|~`/ZгgVJj@M(s e)rk+) \, 1({uWpݝ8U$+LOL9/Ԓ 0KPҮəJۡ@U h !&$$'"՗_e=,25lQ* nLaYjMRҝD@- 4`T8U,I_ MYYfnû*66 ICS , 9IĞtS$صÝgx'<m"?}&W郬I4ܽoLnOI//p/`~+@ A5FIDC鞪~q$g.EaAŹR⌹.k)ܦgVlNl7V8K6hn  +etOTz4$ָXN( ]{۹Wr֢ :*95@HtS_8e?̽PNzt^@r}sߝܠ~d9\)7m툪P$뽔:YEӉӢQzkD&3FUR\i5 ץ?RbjNAE:Q$`VFf\r\ 'F]xH,Bܘ/i(oŨ-J0j11I:p.$_"W'~2I޴r{lxnrqlJSUOw< O g#WΞbeYu0Y4'G_u'qE5x: pD^?¼vVI|/}{nǗtX-6*[mB͸]3oGyG m2 W[ctuf=o*t'ȧ/}6kh|o=*9)x++>|LqԥRމ9V kF6ݒh}s??ntQ u5>K?Iy?:ji n-xv/;Nmp$D6k`t5Ͽuh mb!*X~7]_|_Ei;r=oqn(+N CQCZT>R4APC.aD|]?y dP|*/ET4 %P@:su.^ZppKYKTqր) VwN3 Vsjr6/:'C#'Ȳp{LeM3 hE#a~v M^ ufvSm/6Gxl]f%g6_8[-E#Q @_9PThڮxc_ekvu,{S[Cƿf4'4(ѶT2箭qܔDʦ9 s-^(} *R@9Fl@?|g-]>4ExOP|7tƠσ2*SCuǥvʰ[%_ gFYeۋ<`3qZ̈VP k+zW1wLo;'?#Wq։tA/{uPf6d+H.JS3/URm8O2[K|}h#X]Ό]z wgqPa=N,~/2> ؕ'%@;j}HʚԳQdLS?k7im7v6*Zf {IpcF^pr(`9`R@?m4f+iZok1H XH"=*bJCg@iFت#~"  "|訥)(^ "h=}P/@8Qb(;"X* E[1dAƂ'n(CR #`8@u0C(e:e *V""ނl!%b? /gAA*lE0:Ĥ@_?1QOOLQ8z^kE_=~ bpb/9NQGE\SWCЈgO7;?EQ8<ի4b`qmZgl(>f`Xw{RQVo>" 2*9r L;^ WzHx^6 ai~Oy& $U<ӭۦ Ӈ ao sC]ɕ~/X;anmN"7D_1r# 9a[O9ڕOt"Z7i _-w~pPz"y>jZA}jvt"*#O'Xcd*d儉05Y%Ln_2m~6?\`g[W?L27i=Ջax3~ki9g*sNlcgfM3Ni(І `SS>20*9e_ʍophԾ*j{YDD Y}[q6Mo?OsE-$Zga[Y/Mq]?Y61 tLX!ZmmxZ(*өl| AQMWA'%\Kh<m+ƒB>k Ĺ:8=mPp ˑs=>:蠁꬯@8z(À y:*k>s":1G#wŅi,4!uZ쇓?u_qs-@_?PP#n#QǸuݽiN:R bR75!#z%Ds~h$N{Ns2hwB}WaFd*`1OhBO~΀,C :,>U$Ҿ%D@r0d?QzwtY4@l;Aw5pj"ղ,>c4(M4,mY.zm4u,g%#y{o$3Zpޞ󿓚&aT2  v]>wѥMתO]c +A̖txIϻߜWܚ^@\_/8=׳ŮLIg4j7xd9gTT礅sS3ᯎ^C :h';&ӰqoI34!0ltm{X=ܳeS$oyn]ebm3 L֠T䪈v$m4rSS(ktE%(9qdvy6A-TDC^$<@e$. 6ϛGȰq0-L脈9cCv%|W$5ztÁlb{)j4貭s>'ߋNK| I,jG> ¾F@v>f>7'wx41QkSԪ )w'۽Yp{n;]\z9<g+|ףjT4@rV #?]dϰ٤h;)ty/^f}[^ڵ_rkh'Ջyrlp\xΖGIscRe ]l;5]篊l*U|A}|xr~?Ymi\~_@rg360o17}&]}6*w\򾇡r{9;H̨ s;x~y#0- а< x!#TZZEQMK+[8T3v1|` ^b"!ir&Edz[(v=.'ӇB 4QO;'}?g3u4UM_SAtD?(&>択Z #" \EkP>T_.O%E|OK ȣE~$DO3E:ȷ-rD7. b/#|_-TysGxQOS:~H*~E^2ᕼ׭^% e>Eؿh9Cż&H2a3AvSƂ ^H}ЖH5P-(l{$@L:ސbVc:s,R\kkб&4,.cHyP,C4_d8/NۯefcA0Yϕ `x>wcXʕG? %^}b-;w,/^fUg:ިrd[$ &6*^ ˳2//'Dd@"`/%[j.KUpfL^`Cߙ@jot)܆x۸oߝeeQ_x] FuRI_??{{,xmZ # +iOD'?Ao$8%f6> @8X[0ܧvw%Q= -cm.OoJ|&2`M̈́sk-.o KCOW{NSˢW^ᄃ~zh[l+/ռܾ'o jm7:m1nϜ\dcfŮg`BδC_~aXFScΈHyY= H/;袇ԃCxB mς"?Z ƃ~*`yȽ=gn(rیQّkgk2EQ 4EP |ho>) ;*`H('P䢼ALxGq h=N2&TYQDɋqVMTGekVڀ[4*Y&NPq&"T*gTPS!`ӻ,Ԇyϒ "D7vЛNmv61?guryj^ P((?ʳIK8CHH_gf {o7I$fldIqz˄>h3 nǰO;l[I"Zʰ_EÕKM&ChxrwVPM{y$DTB ݢucs}x9?(x €`yՀ?O&κQ ܋8kRAjz4k|nXcY.KBtŜЌ֬[46̾'Ί!ˑPXA<6g0:ϬRq9LֹgL._'ԑ<exnlWvXǞ:yў`>a.DzkKAp2Ié[pz,лK``^tÜq*c ~) T|l,*3y.y0>eg-shkRy;,e7Oܙs"Wnd1K!#~Cp.~:Rjn{w|莻+;<̍%PUz4fCU!FFA #QNlDbDAՅb [mmO2) Y{x|v& RF5HMߝcsLy.v]m7+Q;ﲟfJQYt؅ FK's1IJMfgRa =MKaŮ}}M#jSV /'zGi ?7{%%.u׻Zy|nu!8R\.7x; g1/_qSa֡NE,lg4:.ʝ4k븹= q cfҧsmICrLF>[sf7f=2?s /( 2 @N ИyX`(ja*V-Ν4TBNr6uZ!z>/%آ.=y!rQQΞ@+H鮡@aS1}as  [O=UӜاX!G/lbq: fҬ{rajNX>)~^ÉҊCyYlv+ Q'AA'I.&JC:?#&zXU$=ulRpni7P`;fa@$kYZ EH%F>8e3;"Gk θ Hbb?MaaГ8-k-m3SGeOՐz\?^<~&_&5[ң]K@Uopc/,0p7hC=vp[!nxd<> `=<$2~Q~bw.6pAo+F}G| 2 ߾OۇL1 Ve3`H R˜Y0`^XD{W?Ubm2mlE;w?ꯑ-ċz b4hwaL j(8@eת<íV'nْ @(UK$fDf$`r1F⑬$M=η̐{|s[K#hϓuy\.vono~SS+Vx<"U+x|< Ăw'4X'?c@=v7}-o-}<&E8{+4zWn'nd{ +_? =e|>v]=U|{W"u={WR  ЫHR8##3'?Ib?EÁ.EﺈGwMF{Tˀ[TPf"~dnh'9r*>[ov"x!~F;VTA9@>^cAw})DW|}DP!Er)P8O~Tb*^uWS3usU-?ifI {,JK~;~e?or0|;v{3&d5>1um}'%lK4;Ɨ _χUK# ,Y301mθyΑ,t^05jXoM^*)}0X6vg{#F@#OM%uRcJԸA~~wxdpq8SŐϸnx 軛~oùg{S.F I#݉#0!r[_IyWa '~!Β r_pm;l}D0{kp728~Өno 9;hwdo1#o헛\=髟Bd$^2&(:ȡP$N'د|~΂x@Edz mq>Asp]#b>`ա rKd~`4 350aaÞ?+x`ACD?WC?]*Da?ϰΊVcYWδ vB<^QNܒ{$ |I 0_B>8aRDc|De_OKuv'\k=L>'CʇAcR΅wxRK){M/ph)Is5. b1jF/T".>`Lڋ|jx'E331z!D]SR:ڥ;Xr#N [~Nnr`ׇ;DpFըŕlC!!5&{H,쳰x\~w>w`_K{g'a-:MU޽g_Gs7&ZQ\ %a+lq[T P@u+EWEʢeE6/Ὴ>*\+$ٵBy: ݁h$~A~%ĸ3HdSdLI!D2@*oX T6Y8*_0g~,G>SovQ_΃&e,dNl)$ AT] 8N,3^rxGw?t6JPCaO8<8bPuv Hؤtѥuge4THD骰_5z/ ci2 !͌^5g3spQ^9QHgP6 6\gUp8G P^(A 7]TL܃6?9gE0Gwǝh[Ȕvܽ}l+˳Jg;i6wopl7h/*{Sg̟g_at=A?˥inG9L5]6{c69܍mk梲w.+.Ykpwlnԝxe>{L_O9˕2){ziG\]θF}$rfmC][3"BlV$d * vs|WAχ@kD B[}'ۧ }.؀d|F 3%c~h~o߫rJ8fR҇ʏಂ!D7M*/B=_m-m͆CXly܅r?K]~gҧ'1lcl0I_џ?l!߷dPg$wo5?JV @{.뽅,}!bqQ2&%M$D& FWw˨{'6dxDsxX.,s 2vN¤0 ,D@JPT¡ÖWa(eҰg9R1EΒ[|{0Ie;?'Śkk4_Vf݌*`*_&W Xv\Ic~$ mɸeF:#,K]2٬ӿ7꾘A0f`*'!*u~\s>rZ<7 >4φ/]S'9\EO朦XŬ)I(g!@ z"7t K?-Sm{ep L#e5r^{]ba@_4!z'ÁvEMĹѥ}Ɛrk? FC8-|` a"xD뒥PZ* 3mJCVF0/u#O8p9b7@ddq^/zɱf`l3{#Ssי̢đ&Tt)ɜ;ڳ{ ܟ8]Ɔw D ᠼ^IJu: 4]إXc?ǃC 0up2l8 4Jz à&=2+%]NʈjQ^C:J)Ϙ*N+'H"D @ ,#ئNsQ#" OGs;ʦ3d|N' JI "}ewN72ڦ.* H 9r=(a{O_Mq~' s|VKra}quf;| cmtzkHޟI8?km.ⲏ]}+ur2n[-`;xL[qOҤK?Vo|)i?n֙&f{*_~ןK =xut lϜA@`pBM4# Rۇ0:/ٲ O0nmS!sA-{sA .r$4Y6? Ft=ך-6^D %~]oIηp)bt__>M Oڊ ;ޥgA"q~|*`m"1b{ѹi -w3ӝ}7myąa/4ӗnA!66ݏsl1V\_5`*\+ߵ n+?G@RTYIwZ,"VYny?4 P0 7Yn[nM yvv彽vkC[/w3'v#C<3HsC h0|nۨ4(>x O%#P{gd IFNR!HWCN.nǩn1*v9NNpbyVWP<ס|&! !qG͇m-03[d1ɓn7ߪa0|KάfA1*s.dy&sj3ѕջ3Rɕ`6l#8=eGwg;c-wQ'ssӖoe=iwvg0VǤ>܆st?{Ok,d/ `npSڷoY'w6>J'S"N _Rc}넯ǧFO}>[&mYd=Z*|Rv)}w+}_>hض[ް5w3G# "A6U~}~Z:t>ܠ 0$h6γCPGxgFBgTUo1˓+}d.چSp=uʴ=W/q|)s|ʦT|<*'98h~e؏U(-T9鵀.){:ҳe- G5}?zsG S7F6qzjf*U;bL圥u^E0F@N*g\s>K(~Wq# RF]4=j^E:;xTbs6xLP ٯ[Y, 63 Pf%Jm%Gz.a͐g12ํ<>mr˭;b`~䬟i}uw'IΉSb]~  > ]X咱Cf%hMvke5ǣƲOBz&H ,f s#uN!hg2O]q#ʀż [-N !)z9KU\WKFɴD.~Ÿ_9/836$0ثAZʑqWixge5puF5SJpʃgUrVw!Kx/Zΰied.νVIX[,,$=XJɝ&NЏ&n% P+*z^0aJM~[`!u㮾 I:RuR;/Ě&p?+VIZ fTdY^*Z`;jmJ}!'̎bђƝI*Y+]D]XY֭:>Q?MS]2/* W@ XYPƒ$HDrM*Ty9%|lHgb'v7f;IanWoiٽFfMxr=Ǎg0s:f5BynҴl_Y?o?El. ̅cAD1QX9BtLs8$Ͳ4ĖF^oq4.럽Ə=$ }jUv\m76:Ϫu[PbRCi.m?/sqj>J 9DaQ*{ n>\u{>Ky W{No!|;{EFS`橁_k% hRK.o۱{op0q<%6^nY>oǒy)nM75zKϵi+nw|=jzfiboD4%us09#rO)d]ۜėRV$y]ݜF9El<{Qݴl}F_Ɗ2_ߛ(V)G86DRU7x#UwopD 9bʎy!Fbݢ @.OL/c2rjhwPxȈ _V\,=P#X%j2]|btArØk ja8NN%.9(GbrてLHf(Fn cd0@NJ ͗oAK`=P1x T3$n,ԗ"Y#;%+^v [Beis1bw*@9$s0&;uV' 'ׯg-UT9HXs @V02fLoeϷٸPK5蠃dᘓdK74dؙs=C,11W桨09@Hâx6D3Dަ"|8}dZdc-.KZ۲R̷khqEMzw"Ef]dq3'{bVXXz=Kj@‚d8' F¡!{)_?<&~kIn}9&`(g)h2L_/,Hːbx}> aQ,YdEL}54(h$ve/EȖ!a80ЬN.e@-{]_t ӈ8v`ϡXƲJ6gF=*Te4AʄWe!<:-#Kvwä{PcIg?A!*Q=A&b%jn+##cq޵M)1 j~#6 3Qaw#hFΞ1EGY9> 1I⌇G *r>DNjg};ŦzقR"DȞ)o/ىZ9u[?5;CcRZ6i4Qc.nW568 "7Kltw M_3Sq&ے'{Rjve2xZrg,#m4|WK,g.m4j8~=+kt+֥@m PF1^$[/1-Gb-d*=lYyL.C+oo|%j>93~DٕOkں6Ǥ M̿ի͛  {q*ANBFz3 $>"L'C}y7Cu=c> ]T+sn{?&s!CS[|'3r~}oC:X|;ofŧp~ݾW,~'1m1=G]Pqyo`oGt`]CfwX^w1U{H)CkhwࢨiwۊۘT_ÆGt%}w-~"=F#hPedYk(OKSD{ϗa6.6 ^ | 9ke=m/?g=F|vh~`)a-ldsV Gxǜtϧ_5vR I p"p C쥂~lT.=~W{7yrfs]MLn-9jVڝْ{ @c6h4W(mx<_Wmx3]мwP{K|ou~7l|]~A w`}y o3+-[n{~Ϧ~/]4v7y.ܳ'n-hH˰' L;80_zY5/:lp1Ą 'nMMIAE{V S]Z6BաG^xS@QxI ]\9ynVǭjy,XZZ_k>}O@7븰XS gï1s^[0@bsK00 H` #6@_fmXc~:1Y7~m+ ̊V뛕ZK`8`u@Ԃ󓦾r,*b}ݨ[]'M>v.f-NB ~}.!wt~/b}x\yv/ JxefˎɩpG9UdsY*@<ŽD1NezL:"\"G/{~5Vv fp\55D|bĕuBi~v1 рT@*{XQQw@pr <4AsE_ES%QHIax|PO‘U\7˰Haz*v"6P\FLD@kJ̎02d{n z/f5.qdhM6ym& U6j[r;9MRUuΞ}5625k=sY =!\2дDrNG҉9!0zX~%+ϛ#at̺hyCOz@{ٛ+SAFB ~Nκ& ?Q'#h.[WwcJhtBz4R J*Ab<rf-J4OJ}cXYz^:*eEUHJWBV:m*) BXbUEe~֞'w[s,淴*~TJK ws-?-V!xc͔*Mon;{\ko?,n^a/!# ]PI(c2Ncap~Wd -\0mҩ~F5zIb+`zH/梙 >>%vĈB{~ w_H $[ghX_X^ʭ)w޶t?SZnmH:VrL4`ߑH@>G{u@~hLe$}=WߡKm.ZA`*z}uk^tlzrnI!95ܾDd8/snj2"uz1^\_G/I/~yl-L#}Ikz]_IBUePQ(k=@e\=q]{j:SGx<w 7wL cL0wN6q Qw5kZGu~,}x:Ps%5% ~-wx $Gh`3hH`FǺCL'A19œ8͵o:d>&o7sڙXfdȀ'CսceQɵرfr^ɮ2 )2LE1 ``(W_w{࿰\{N_Ś`Ybci;VlcfM#ǔ?$mSqg9j{Zq=~=[s3*w{/Ϻ2V 7 H|>::}Di y `zx4=Wa#G}@Uxo>? bv^7}R Ζ>OH4 AegWRm[^qZ 'OK@~ ,7@b|>uqB>[@-}UmTY*=~Ӟc+TU",L c2e;*|Y'ZMa,HEO}=r;mjI_Xfdt~VL4R$tH%8T: + Β9#57QCz:gAr!TmYu˻i`46ڇƸ-Cӏ(?Ş6ag~ק/5շg'?eLfƱ~rsLdU&ϋm?Jfx~U'jq/#DDs}Gv)}7KF.fG .phzYbo:9oY?#@?ܐ$+pYj[AO}n/Q%J׬OCoV԰zSQD9(K4#]pUǚkirMkݬ!rl12:9%Zz:h&fuaWR 鱿jmt7t7q%}w%q9@c!s9lnϿ]sڜ>3R%nD}yddTf*9с ߣ2kmJwTs{Pr9ígiq #D˻j 5='=C>X*}({a>Q+:F3R5P1Z" w0Cd ?[[֕,wΠu%y)A88q@""p\ɾN…!jMDG`A(D<*LjGaq&gѕ FfTbmtX0f0!0"@) Yoh0f bNG9M)IB ]?>oGKf2Ed*,RR+ q-s-aYPQ[jj m # TYs:P?ㆷX:ְgY߲;}F6O2wY~Έ΁|H'5H&@/^>N≐@7Ҁ Jt& .RS^ط !n~ޯQp nJ7p /]|F7PBrɴ#RRR Nb% =hbB- xC2+I $~QRvz? RScplmi^#;mb{'ųb98N g...e_7)H1. Kإʙa'[=吴ӡEZRqDK\3G*w0S'It,57 p`ŔQo.#{hQ JxKF, jCqrcgOʷ3;2;ʵ弚ry))Ϛ4 uUȒ\Ki"lqnDǨwNw4a,.!l) 1~Z t Sl!^`-ѓ?%/`EEԢWݖ+jWjѹ5O:z[ Ì G81~M*b;w6.WH #jϯ]VrZ7#ZX^=qjԠH`ϖ-GR. ZP7opjDM ` EøH TGpoJdIs[w{7Y 霘Vly G︯6g%R gP V|DcdnOw1hIx2ŸG¿: /'c}ewQ4]A3"B'Fd(to~ٲ‰~JCݻ-!JI7Pau3"@8Tpa~'v=/| ڬ|ߘW&24"!"B#2Hs2%7 TefAtBfȶyQ֦V0vqI8M< Dm.Ps3hrP_:}DRJmADEXVKmBABVb""H*㙙*^_W7Ӎկ/7\ [ c CQ]3+ Gq[GGj>4ft 9 &ZbH{L!.Z\$<<+PG4[8ZSX2SB0_K\ل#iU sHh@D%JS`gf= Λμ0.RiɲO^L+aap ΂yL8]ڋ✭[E vHXps[X\Vc$d8bv/GIFVݵ6=8h1*5??JRU6$57D@;g9{~Ǜ1d%ǐr(ч;4w̎3zçFM{<Ζvi~T#aAbGϗ:vTba{Jۼ8ZTgnp)=71̱L@)?KĄ,]c&9U˱x- 7p5Df9٩=L@鉴k>avAO: Š':hD9AA 3佻hY76kV:90bJ s3hΑ+Gqz}7=1lt.ԿI)}7n풳r=DιrFC(ݍԹ|O-t[Tn/\^Cya6;]-T{`iFרo3/{/1[ V²,UV$Rd61ާ~^| 3]?ޫg3 ۧ9)+Qۻ|v7r xR= EwZj8~z4ڸWnpGuι-컸ӅI&. 4mbiImc`N07 0by3 g~8/y<*kfԷťWAOxy |$7g&t4>jVhrY`IgNndЦ u̥'9rcWᦗ ^j&*F0ĖWPK )89yˈBgiz*af4۸ÛXP%걇amiwL3tz2ͫ\(+p(Cʲ.7Ooeߋ/{mյ FOc/-"@hQv~UA86T[^PyY R rT$BrxSH!50_Es W5k;m%=*|ɓg)RB]1/*Fc6o yx :@h`NMN)}B돬˕;U|Yi6a^.;.:4qٵ yc2'-8QbIGR)a3,_,Xf+3nRWP,ې#+й`J@Ott$xɗ^apah$p踴}S29) $sѝ:Hc&PYY̰ 9io$<&s :AedBNgg%;S  9 PRg"gٯ}%KI"3yL3`p%c%ґ [$5s8:o+gb hqJnGח?hɠ܉{ Pͧ/#'2)@!]ҕ Rʏ -1"s 3`:iۇ_ 4 #gxW!y1F: Xa91c#LH#5W'f%1A[7mTNѸ69䨓rgݱbɌKx} #h+S]˙'Wre᳢Xk8")2uʹmftc m0DC1'"&SV mf&sR)1?_ 1ꛎ˂bziD/gSCQ d{umE4UpǬ(w;Q)usHO֫$U,0'|ZYԍ|{07A2m 䑉z2S#I# #DPiAVihf&kMuR}K~(c!RΈV ˋ觠~-L8xW&T, qr:\5 @ُk\& Ujn4 (vRC(X/:|uS]Ʒ#-DP^x>MDC &s|\eJ-R[>p)S0(`T*S6frb.fO9,N]e Ɛ7qq)20c0Zsx//OgK `-womjYhݔ\zpkXnf9v{Sݺx$:6Uxj!=n%Ȧ6]F5f,YH!!I TD!vB q25W K$>jt2Nw<;0;IC^JNBs;&DWUl5?~̃M`FX-ѐySi/njȲՌ-cل҄s3ڛ߁ʐ+#q"ÕʗR*d?LELZ$b%lS*Z`|T0JYIɗޅo'd6׼Wmb[k'YzĽ4 M jCC ʋ`nvZ=j;%Գ |[W*Qe앫6A-]5UN>BQ3iB)7.zױ+R+<5R̃~`̹/#Gý\|E&Y`Q:!I]iIK9HW4^3]X+(W3v>ev6V*1X\^o#sd AVe16Z'㦭BPhsůb8AS}< w^xM3y\\K.n9Z>k{h/?!ǗeTYX6y-ϵ1GnKPvg֡\-q(gp$@]+&k5t3:V|ɣzNcbIdz20 Z`ϳrҧ;o)ton|ì19XuP͚Cmz6]fQv!~Js@Fw\ؑY-!\'A)Ys{a#'/JY۪XqŊ bQ„qT[vz[B20q_N_*Bmt "HGy `45iv|MkAc1ڙ` Q:d&p55BB^`EJ,2$c╖QtJp bp49>4$*}kQ7\*bG-u=#Z-t;}393o!Cydz8&lؤQW "39XYNF )+JK~Vm4'A]h^<o,V.*HfC.TV<@>.gm#KF`La`Aǹh(3r,1^$u\pL]WתV8sF׊OKͤ'K2h:Z{gxҥ* iݜXdv=gǕ=/K|iWwxvڊLM1p~EcПĹm:5d͟F2)SN̙^Z12X}jLBwo{cRޟES;-VB_*Fybæf30|0/SFz\h@uLp NrFú:ټnko,[qRL'J|/&f{ib^t"/ mO?{P`xLJ1HUFhtZ t_4 Q5%0@^뇅 wt4C.+IWcB約*+?(iSK=_ـ~ػ ĸOg3S-!Ye gr4,שo|[hM$V*NB?UK؁zz\AEɵß1)@mU<́Nu9|pX0vW 5GT q# Clm]a_p,#~[2Ras?UypCv|pG]xv,O6"G$r[#4;Kb\۹kOaRKd1*ڴ; A6*I Ygkj. HchILu  ۣ۴Y@0 9@yE6xmW;Ȧ&.qO&!yo. G8%,-y#˓Q7(e˲Y)C`afAb-R7^>/Kрb 6hD`fKzHHo 5j>Xձk0X\ u>&/ө%gk7-zWY7R; Լ>ueLIe~ҟ+kbGq+csDy{px5i,/98>K6es30p>?VCO SyGMI)[+G2S!@f~?wv#8m!Ʃ 2HxUoh~dPCM7H=ui~^GwUULq9O)u3[GD^MH@h`Ej'*_[`⢾9;oveML1B,8s" o%H SE+?4։8q_ ׽MWD#soÎJ`oyQGZQ8(<~CuG[n C;_)'H{oq='P=Y֍޷qX+c0WRm'>üaI 4= $<3Ek)^­З.Wng`w! QE,~XUP7ifeLMiw i6!( dJc^ r;/1!AgJ0癅@..cMWuޘ>A9#^ϹZk4:\Mj/P|@h ƽ+wB_is?Di+ N'5 B2!*{ZXH1jsl]6r%D̅ȂȌ!Txo Ni,io~NA;Ν#NqHh!V&w4BГA :tmUK .M]P>}ld6pwFy]KoUI[CNJ%g`̭ؒc #߿ Ȫ(J/7)˶^+N[[np`! !F}oྵg9Uxg(I7k+uU傈3 vEY}5$s:u㚸{ms᱙QU>F K Cߝ?|+[^<!b&[X5шcâ/=:7-o:j!,(7YUi8m v9mmܤɇ m("|(Y 6&{jz1Pt5=oُtnܐ ڷyMg&HӃҘ([3?^;Ͽ-,j7Fp]ُٟv+5y,b\H!_P"3ͮJ2MIqZMGt4?ϋ}/Rh}T~Dp Wn~ߍweHsy<R`@i=4W{`^ý 7m^/. 9&~WCk } Q3]3tLn]k}9Rl ;c!{svt2֜8cIj\JSrޖgA-(襸X^9Fe?q}fXTa:;@}Ɗl-j[4іVzvjʔrRf&\l(4ou4S3`ޒz`Ԫ7dǏEV~T} Wߑ2,6%ZbF5VbjL=k4zDۺq)8sfi`d&LlmˠȫKd0n?°jQ )Yhڦl̉dE'Sw=]?Kx1MfR 1E:uMHu=jÖymL$JɃ}JxJ;@ȃXBRzrA3 Ol]jAo:$;"ΗKFLC}"] iof(6V(K{RQj= /u֑@'q6jYkzkcvP6s#L96e*8[nd+a:~u}4A1Uۢ񯖨ӛ[/6֥˖'qlU"ɽNZ#&ͧ VںβRkrHX+3lp57۠=i@Y?b%^wTGAw6VLy)0@\62Z5 $-ޒGAb"z^#"c_", ̱fj턊av%<0._ РԵ@~x@偐euDr݊0,+W ",+[,dB ܵ"q8{ROJP2+HOid1 ,kM EJ$2 72w2`AiXjDyFks= U Br ՓL?I-egri}K"(.T]j_.N 족58cʋ@N;`NYͽ# kp d;o|9.5}jFEMGח. ;]'se5u}ka;t 5edk\_iWCJ٩هgʩgb.6_⛛ޞQCLZ+>$|YJJa~?3]:8ٰAȯEKU[RV_na='/%R]eU*0%2hm9{yDagogCF]gmրOQL8ZQ"wq"@3&7'UьʒR}2*ggsXE7AdVgM_ !Y*" lD &8lR(vMdN0OQ|e,5pŭ6XL!1"$Rī]t:ů6v3]yLk\~W;k=dV)k7Sq}~kӴFRFo}ZLŤk f'َOHM =M|YГkLϳwѻkFQ^W5m9gEInSJcea$9%gn"Q;T f_!4:uo}o8|K=kjerTS;'S_ޗ[yH֥{&p-)3&6nL(n sT )ZS'MJ@'O3#&ai)0'O;-ƲƲəXgpL/l_-E>R"PDU~lwW|. `e=df?T0rOw0ȿ -De댯ª,\82!&F>_z~vvX.ʄa9)f4N5'c'.KocfĂO(CJ\(>g;j9?ꏯJ ZZwaaVѹz=MEG}ۭ.Ey(rU#\Po#D0!99ʖ9P*PwեW9sL2I?5[- 孈F;MNЍ[bWBANđ .=Ln^ ɮYooeOൿ{ ߰.B,.#Ah)䬝_P4aE 0W>s̠l`19Xk̩&@0ѺL9ן Q'V=Б5'Qnb78a2*%X;dtLǢCWfԱ͙ d:݃ fW).9幚… bإ?[0L Z=]g|_ u"␦H >{z&gE-eA=3d5vw]`J60^~hy`k/0}T%Sɐ>ݩ+ ϵ yCisTA{jA1 4/Ri%f~)iM6 _ߏ7zPT$YMn-{9Ϊ| /2hBI:5<;U6؆ c-61CŃaܙ9f@(1h 5>c*w}W]3XGކ<lį<)xc-׶+ ) H[Y+%ʰ4|[\n">}?i)|LPpHwQo:X#^hߏF{+C^mu&fsIqwp-DdN=o'z>)_֞!rotU~O,۾_^ Š F\`A(!Բ_蓖d M H~Hl]`R1 F-Zͭ1~5I@Q}?ZTy?ah^t-MLb0-7F k$w4teT9pʬ o\TR4'<$ w}[8D&hMVzp g<@y0&f,:bfIUQ~N4 VL;)I Ayb4w\UdIea%#>7|1q4Rf+If #c !ᯘ݌GǿDTawqX9.@;(oAOaNZ(R rSذ[7ٺjf w'&4 k7W6!%X6-OV/wZE ՜o4<e6pM3\CghȌGѳvTa>+w̛u?]=^l8O۲䏍Zk1) rtBC?qlRCe1t󾊥AB'kg)O -Ba$>Ys>F88ע&7{t3n[w?EC>M= ʀ0"H>~瑮EL6ߝ7 1CB_dHյ], _xpzL<*Eavr=(kBrlH>Yɇ9Mr?{?+ /# YzEZaO3,) 0e[v4ƾ[}t[Z]0 ̍!=!XnoWHM;TaiPH'~7Df,:|G)9ې7*:E}ߗq~?}ՄSde Ԝ`QAt&N1~oE# 1O4w\fPVa}8~X}6.ͪ#}j )${msGXFM>1&F?b\!YCg= e/*Wʉ^@7!|\=M- L6%$z"#'`y&O9I2ENL13r7W#Adpt98^8swr$BџNê\S&zYs=Rlkz'|?wkV|o*/T%91,W*n60/Ua8CCHÓ>pg.eϡtmVs#Uy2S1$3_aҜ[ uxԭ):$BGRdg`t[/Qx&NƪaGMS8DׯCݡ"m  4^e'rb.2Ym~`^ϋBZ$=kI|{9G8%#񫯹~oI^%<\ LqP{\ഭv=H(i+kJB {V |3Zl )1 $05H 食M֏s DtS*Ȑc5'㙖)e Vy.x?M"{ʯҐb;#U%Zt~g_v!o h<\z#G\0f !ed&NDc h3Av׋}{tKh^*? |AQ9c+XғpȢ*lZ~ei.iD diɸF)it=|d7u|[AI\pwd R}%5XgF/Va ^kY[E?ɧ=6P.jmd> >Gl Q?>l c44eEOx>W3>d?#kz cc%eL׬yPMt3t9fxb a *à "~ryO9Jm¹.L3/!@Õ{BF g %'PoB~+?='Lчpu,bTļO0yj(dz+\\ޝkä !>OC>Jem2aIҠXpGbH"npgD}~ht;~Л-}IGXLܐy-\XgF՗p]njByN^Z3@$*vjT{Ay( zȠvL' ؆Õ}ftלxv)8/oe=gk+թGq= SXkHc-9 L]~ a~: ymKǶ$'EZ(\kE]9 ڌH*r{=wwϖE:Lݮ<䏲Fo;t);CF_n~>wyѝ# KH!ĹC]T8OjpYkNh\kfqmR/T~-T\] c u,,Q"3pBP N} lER}zoݡt]vyt *L*ᬻWgv7է"\/N+2B&CC>Ó'xr\*ob35'KCbq&Au^_+kV!D(Istwmӿ6rj5_ }KӴ_!WM~7mIӞ._ctkTԁW_b,=rPEבv]U}*/%Btykq![;xp i_L~i6K×kxZTM:Ya:ڳ{ "0B0)Ӄd;g[)F5/N~I)4;ţ1UL5j¬ "xoEy ~VwmŖ8վAV_|h`m1gWAe`a/TxR~M?^eT‘Dq2\1ԋh47AL>ټȺjIZз {'v835ڇ~r/eJRqMs&dRL0dx )Lo[fNP&N%BgwzM(ShgH<րFp$`1jue}bM|mj]nw혊7$" %V) |~K+Әrcd1Tpe 08L DśԿ  ̪@b9k3 9=kewG-v-tay,Y& 4lIר 0T7r ]|M&%C1oSJ9iW^4 - -I,ʪIl7pmƊiL6~7:LP wPDD˸Ij#ߤ_[BZ9 -=3g}UŬCG*hŜl;!faܦY/>4!f|b1.z\O+R=RwU4qU@k$^M 4h`5RB33=M /#='14gjƊDy,sCٿkbcیetׇ vF^BD fPXJNf Jie9Y ͩaUWܳшAM dvP`Zo3=D]]z}߫ juݕ{I_1^V@ ,k6ƭThY.ze;(@rVw}t@1M {1wQD X(E9j3lbg-$ݬ>&t=BDQnUNڵXl3^_$g.ʌކ4V,c`d_E1#{?2Fٺ7`qYQ7%U&yq?dX S(cD3ȅf`CfzNu2nZ6wRCڡgN=I*U}VbQˌC1o6.Z Xu=1ڠy*"Y.0 _QKF3#hŃGV5g1Wqz~y!kIs\]tq$ w~^OY,hQַ ڲMzԈW}Z8s07WQ^Uӏfq#gʫ/m7#ɻuʌfYΡ@m_8e%L'5!?i`mǜGNƴQ] G FHSyuX炭uE6#{<9߉"V3 8<rrst诮N%%n3ڈ|]wyux*! KsA3vY##LhYj\ Cn]%gljxK_n*詃~wtb *-4e0 A-CY-#xVYw|gr1xr, ׃}745\dź?@R\ H[ OԈcHsJnKENnћߘn,[DE.E Ob*=#?@*yL1'FM:jM+{l dd̑<𜥁9Ǿjr{iOq&:bÙtc &GU{O/J3OB~U}g"h>Q DG3촮uԥSNI)4e<~0*aKQtnyZN&cZ"frsht98K;AÅ˨u8=1:|Kjփ?wީam\m 86!^Ԏ;oYyB%ӷE7&i0+\"WZܶWlF/HL.& DS]h9'}?&%D>kZ#2N'3g9Kkʔn0yvT/RnSM\OVTq{i/l' *?(ɋǢSݫ6J]`0G|]1S[y$ 9$13(ĥW ~t㮥ET\HgֲR4iX;9MsC?Ol${BG4wMfZuT𜶎v|ϙ?ڔxo"kyb8ی暝o)@c4iŠId,D`Wd'5a_v {=ܘh[-95u0'o[8Gq㸩>w#sY*8W< KkyVyt! 7*U9[ Y*"M5I *̯76f'9u%9Nj8-9 LAQJ?wu͌/hfˢfBa}7@# >+yr\_q4pg_{GdI=$sqhX'`#i)%$MyHjyg([ż}庮d+Mj_(Vk-X4~gF0`]#/eU+4\ZHl\,:wļ4f_%aSak22d 3pwPl|{/%H^K:fG$M=R|VKQ}I¹5y {B8iF+ KaKRsb$˺9^ F ^uzoX+1Z8HoH/XqTT*Rk 2өxhKݠ/$!oq{yV i0p0f[$Xy=;"'~QAe7o!/O}J[VPf[r?Fo!! B2iYGTO(`a [ގ8-²vI%@ NP4 e֡N/ nBT!]NюJ=M„0>qP6БuVlJY5<>IAF}F7qawfX=0E𻐙٪*&mɀ*-!-5!j]o`C6QE_ݝ7Ar6'99MA@t$ J$R!xq/a&Dk*wWOk Ǹa;q֘m"zmRp)aQQ?[o{P/A~oS[O[(VuӬI.x [IJƕ 1h5gS,rGygwTm YL7q3^/ANdzevbɱCAwӾώ{If7oH`m-kD&q`ÈOBcŜ/=+<-fH8pO"vq֨ tjwY?`ma.׽D9k g|[Χs+T͉_wf?gse-iC>x:s2//+1Cwb - clk0ML$şw H 3"<Kabw/a* t|/ ͺLP2rD<,L5iH;< gN@sA^ GgoAfK{~|{-FcV'7Yr*Ӗ3^U M'BCwv2f!0Iv(A=syOoH`lup(Z捳!:sdMdFRhI j\flF)h `(mPwhs~ͳ޷ +b_ \1'zr= Z8wa5qjRxؖei) /w$މʸNc,$p ozzę_X`_*Nl;ޒE7LˬC0Mnbqe10!k5.1EpF(YlnTS_Nod~'ݸv"2"`wlt^u$rQWV.41͵>Ea+.LL0O}k>w9eDŽv*_$NlI1I rdĬ5xn,tMӒ2PmF H|m Q ,ȻBŒHH\H"цA˟v,*z@RU8˒֧᩶|FG{ ɒ$Uکt! %jfdXF[[>cEf)hEC(ꖜ3fvqgg2M38<.Ǒﴰ0#bU(j1dffH@M} 8הӳUbI!rNzQQc]f|urлd6[۰ jq3k7M/Ih^-p0B#˳j{-0 )|s u@%%G(I2Mh VԩȆ.PMq ̣֨ mV ĄHR2.,I)!+BYg?: ͘^l%v=Uʁp:ʘ7SQz2Ï6gKY17U-AF?/sopn`UaQrܿEpϨl;=an^nrņU1[,L7[\ߢd/0B|i˾0~KsWTV V)6&SE[ު3uyHC{ŷI`< c4e&B̏>s?>%NԲ]st*T7=w ( ly&ݔh{,ײs: W;H!E)C `C~>nJe1(PMtRqxYbTD=kK#F"0+`h e5f 7;M+F@徯VZs 3 n4 4 刌f!&(~J 1r^7ܫ/ks%2sSQEVzyr_2w2FSn1r:C!#b^*Z^)qf-gXX=sM"o{[Y"r n evv5.öI|g Y{OVg>DcjҥQ ȃ{k(t\ 㰑a\!ј3`kHl#n-XNR֧% -KPآB|@! <1}=}7Uӭ,Qp|xA \~:{k26£;ZXs*g}` &@%sˇ04Pl,v@5તo&]'_>`dX|;cxk jW@͡ ALc"Gfh12#`|^eRfAjäp"bC!͍9'qjF >z¼#cyEf.-!gZa-1Jͥ- f,B[ +_eqo#3:2]!S w%x`E ٥D=F-Jg6ٞ>Q8~ q&/]S u>/h-{6IQ2s޽=`ecyC ]G'%'! YW \2)4f򲋗D\:#Ã#t}xltcc~lS}fe{JD 18d&pg8\p0yg*'C5 N61D3 O*V./#.3 MC xL i* JHtO~\׸F凱ZxqGpi~[;*#;a>t`uYQyrQ8XͳzZP)qguj+*1(A)" lY2AĚ,*A>3540NZ~6CMw! P#ll\{JAI{]oxg͊QHwzkuqEk"3N$L2I 0a>i$_=ؑ1GpOI?aXN 'rH+|J(t-O9L-ذ@K5ݦ=0| ~g<sXg`Cm;P^ )rb 糹eqbJ!)&kQ{״H-|١?4ST֋"o874|}' 4ϽLzx2u}q) 0&ށ `ƻ%i y:xdb25)k̛p+Wg`-qǻ˗6cm=5lVfӲl~'kuCo\pݸI1pwpaH=4g"PX?ύ7,pTFf5iN5 F֍ {\R^$LD`#-7ZuJPvMo7ą{bW/(77^TƁAی?^&y@*ۜMLjza&;/.]pf[ ܘPۖyjO`ǦI<1'Ώ[څz"D5|Q!"S9MjX bF]rV8~ϷէZsIcÅ0b@c#WDu཮Zw8P%v $!AJDp4D\_*tl7&\ ugP+2f1 EÁOs5彎؛Ig7aãּwx?Ԓ00f}#c?15 ߾:IM.ɩe,P 5gee,T4A|)F*vm2ZDH9myޏގy[3_,&u#]n#a,ȸoxU]91/`ό騦şsOd6,AXb>/. 4>N n8~ŠQZ2|Rgs )^;R3N{6|Ulŗ;Dc=FA~e,`5*f:?q/__~?ڿ=y2)H/H^RDQ/ TpTEeNn"Źd@Z%aǹM==51ZgJ档^EA7|SL NfRܞ0 ぀Gd1^NQj?kxMI8:+nLfa ~c|!YzggZk^ ۩~y~|[^o0hl,%[IzhQ&>|n+~b?3~#q v>r:4P0 <i%-X gy8 4 ZaH)HGacMB'T"rzۯXhXub0z*<$Ω&e2܆1Nhk)6oo_c {#qr NϓJ\JA KsO{"*I J`UY2ABK nfn1wkvp]y#=UE&FDW9 4_ה uΛgtuj2h7% P㼹.՟Cdyp/FV.^R iiS=Z(VnzId0834s6օ}L^4?FLI0VsG1\Gns9,+T8eSNX:n(4sQbHRbzU%IE$ Q@1QRX@50 N& 'E'0"ԦYلH"r8\'@XI3n7)##ByoHdo"F$C'aГkic-c̦۬wލ8k;hCy'a`A6h#y HA=C "H:el̶zJWaR mF.ÃiVg4'N$k3ӻuEO+RM6=1ȝ!nh,ezK-܏r JDvꑱmfJџC2]-]_O?G;zLU 9xJ68[]LhqI/)i eU0 0TQcAQh5 fC  mÜL~"%6 yІHɶb/p W= ՋncYO ޏDcSC0̦LPtҌ1zMNidƅS hC8 y x+JH פD0jnrLp1<Cxd~^˄nR|f8p8}*G۳{(niТY3ԸX׃,̟^bSylk9iV Gdx_y,Vۀ-ڕ*̲Mwӑ[ABY>KEu _k߇+ѩqhMEOҞg7p "P' woZ&<2AU&bmWlxAQ?^?R[hA-k<-j]p4]38]Jh%rY%^.qTa9Mʊ`+9rnNRC<',Rr?Uur^,W+2a1e!9aYblL aN\ VoWu{,Z}R_,$og 1˝1q [&1*nz .e8T/Kj@+ɽnh.) ,~s󠫙tDUkP!'"3>r;P+1L rmٶ^Mj=޵u{#qjbn8sai)JG.1RӅ&(@?) ĂdA^qxйa0470NY)fh~Dd8x3R9z@p-%zͼy=@G&g_UwQ\W1. wY}%7YI0P$ ]2yH(<16VQ%͙)H0:ɣҽo2Y?*f@cZXy*I%A}8[,A Hٶˆo.SD`y64zYTri;"gEz5"$"PsAw&Z{eq5n@cZ|[ic޹e\_!fŲ9a/ߘ+CEdFPUN@bgp'c -a>3RrU]uCӮJٟ&%`9gq^RT a柮oߕtMl/ɞP[(0j4@euEw=Ѯ/YĒ>*lӃh0q s4ׂ< BaFK>4=N+Afk^lIKh:û:20$0OvQ,99e(D+]PIVܚ'G[9q 7k1´@z\I"BQ%:&aDV6T-'F^7AnjgUC 8j4hPVO l8+rRtЄ,;似 #_m#ui&OKTf-zN9H<\4|u&f\$o~_~mҺ]! 358H ~:꛳vIi;7 k/5:$&,Kb.Jrn9oV7QZ<)6ep\ٻL b,>2.555U'AA+D Jd #B . KҙW.A5t$19hl|_Is MSŒP)ZA@g5lWجV cln{b8p!qjeOP T@6#fǖҪ&Ì:ێb8| ]r9B:DžL" k8յtSw*Z!eէ0 fHZ Ere[:MߔT۝J&jQGg1)O ƺd )X"c%)>{m@]_fV<T2:3Q5mo7z~"cuT."sGWD8X[ } x{pLm duxJc@#a  K!F ٟɐÿt^oyd< d?eOˊ8eŪНSቈ ̯QAERM; d#^"RC9BE@S1>suy{½7-_gp/]CJ%4i!ufNhrڟQ{;ٜô>첋 ' 8 \ җ%$Ϋ`y\'>sufs/:~؊=SθJI&z[73{(2NC}֪?iH(>CXo2rT&Jl-M^n:v},$os)CgҜRU>y%] 0s7ExPzmMk8.*}K6,XpJ %^Twy2x4I0' E$ 6kkv^~[zr# < TڀIQoEYm+@CsTds}rDYfR##9U#X߯L$^"6sL&8 +OkH 糗Y3}YdUz9us5&0}:̺c$>̀qXtmBާ5mgZ2^hk?Yjme+ALm؟A 𻮫?d.'2vJ4` Dt:e kEҥdn#hǣ}D3}5󡾷rl=3A=+J fCY#*~?40tzO!!zL>Ͳi4 ;]OK2|W]) ?*KE/$ԫUjP.| (39vOE7SVk{y8;4.VUz qK} c= 7|%:LM06jspML$`H;ޣ=vWh @&I .ċ,#h8= IXL;/4!ߦZ&+!I{c"pJ OY|;ӜÁ3}(E[,RDzirM63=%r. R?~+WllYH@ XyYLdP 43|>%րle:?]4  F,:sZ3ss6K$&=J^؀gG`5&[| }Pn2 մ -t`f;JQ׷/})C=62qբS~P:]ؼ$ ?ϷGXjw |H='MX&ڹ,pc\pu9<:|7r }: pZ$J}mT*ZB^E9JD]>b[C_wZ`Ѡ8;HTΑ:u/"gQb9 9:~J\FKD da CuK<_la0;KH V_\_g"1>Έ~PQ`OE / 2V'AqjH Zxk2KX!!e yvNΫO'PG@7N $)WϾmoNM7Ϣ5C31J@6ئ TN&}(D>=o{߯e_{?Uz {Q_0”َSa8nr2[=L{=8@CpE\N=" o^/xh 5]T,޲wk(>| aelx)Q wIhsrZ&‡fc+qTf@w#-&#Ryj#r__^v=-l_@_`7<aoZ˗yf]9e$boֲ)z/Gc(A> T";ز 0#F,U#]3qRyVG=>Rfp::v~#_Avװ̑|Z8Au}>p1N?MG ,a1%ogg6Y~uRzޛm-#5(ZF:W0~a}?]HԌal2osy\ZKG|4MU#V\~/t;1]qA˽!yA%Us}zrOԒ>?S. 1֐jhZH墣r, cYDjvPl/RD J6FA-tvbS/ͧKh? m`ٸRՁ's[ 1,̍1>~ᾆ`R50O_~ˌHdZ4!3ˆt\^5Tj2]mHJ=㷨"q&6:Q|rMܲ5s,*?aN&>KH>*.ȏHVF֌AS 섽a$\ߥUpoҊgTO`7Jn{PLM>QlxlmǬPYL]3Z6T*2@ۊz#BfhUVG2MYa5Me4tmTxd-C3Es#s@HI='ɹ5TfsYz A!=L_~v7m&ƨolQ&Mɤ3u& &em a`Y(F fb"نGl69P7ᙽ]εArn6smZ!PiIs6/a Z$4i #yűCbGI->?X/s(#jf("a2BW!Y幼{(@zy`i[/.:TߘگkH'2Zo>'hN ; X(p,^_y@_A#uES7KތCCq Q^oq3'_/?v~:p H7 CE3Bމ#NiES*~1exR i,JBqh (Цr|ÏMJGp+ SLYXbrh1+jWg:($0dVĢOE[vƁ c1;N2kF+Կ1JV~拏+{L s͹6'gJze&{{` J/@*a k}7TKoxKWxk+cF4[gCV&ÎݓTXL+cPz=Aώ'${cX ~mZKsj)&KA+W;:Ƙb@` r~qR*QR0TE_PHXQX* UEV+EA`ELjrP`Q ,SJ_Ch *"(EF<1"1F(+DEeUXA* X" "*3Z c(QV ETUX(PU`WMHAUd`zut*,cV1bV/y[X֧pIc(*+TAQX *($UVQ=bbPDQU"(II 2(bH ȃb PE"(+ȣ#҈>(ȳxXD]PQHZX'B"f1E bEh T(TUAU*V b "QETTY"t(E+0 "",$TXF1cDb(SIF"1 AXQ@XAb1OlX,UPV HS( Xb"V(*0AaDdPbAA2"EQU 6Qb# +!> c`DPDF t($`1QdE,ETA$)P|QD`#0Q*#dQd ! DF*V)ADX(F E(@HFAE" ("A`Ab#E2FEX1@RA!$2A TQU(*,m ZQKhS)_)յl44L&%Eݦ٩a֗;p O c`ˋ̋7/Yœ6uLJbpn`6olϜb@f\U:/[2uhmE"ZY18 ƄdvR.NS&fL.Rl- %OĢiVGo K{b-Z7 Z'ՠJXzpwdg7&Sm}!3" /r2n0 (Dƚd6Y3f H;&+UPP ``:bd,$}9)M)T1D4bΧ:UAMK?x1Y/ŵ"prEk%_?Z\0_\L N56𷽧yu=~u'f jdH+&fd K1|>ahDX5# ғi.#vTғGA'EUhʃgmN3a S^6 G@*c/6BEjy,˔^`V3K< d61bZsba ݱNuɭM_ܤH+|XHŶ2o/M>7(?=bŘgHM1SSZ&l7;*dq(5>j5N,eS;}~gّ;LNc oscBܞ?3sg흸X,~<&XI&Nb3xNO"i1LJB` IM^v賙^|xwve *^ j^U\M!V瞽A8SXQDd8!L4W,@;*clfx59k/T'oZĠ)s5*[au101ABk"׶j3:`z f3R{}%Ϛ2*)i1|\B!uFC٦Tp,)?e-4BG{Sw7?<N닆3N6W.sCpJyڙwl ,VXdIJ=`+ڬkRu[I512 s x޷r$q5dro=O BK`aFhS1~h%\rQbs2z_SIH4-Ha”C!^Lld@>&c;[:Om/xNvF'I;J7^X%B0s 5Jm1Ju161tꪉZiVT܊>_O]xMl?9R ك O(8g?rn uQ=9m7+H$ ?@𐜳(.a%2QFTlJN[[TxSuqCkJ,˔Ϭi !CMfV?4["O؟gvO"ϳ5ni^0 M~d@-6 ;`$DSJlYrtSxW(pUݽ?_{F6=oJԹv,\I!Ќ?h-ẴsMYڈDQxU`F:9~dT 5 <>96̳c$xugAKizuHͶϰ/\E_01k@Lrw[#qUnYeX/q$ dMKsƢvNNϟt8+AlN1e 6ڏPS/=q' 0iZ^1x"2(o$EϥMSz[u2cc㎮V^z?FY7|=Z` HOa9]G6K!pQ.P- ڮLh.j[ctjΘle&KKz44}??!B.h[V~is;^O{/#hapx3s+t *&z3L'z?wr$ݏrs='Sz Ya[jx12*fAV蒆h~xr+;^W7 SyArNNPz3T :WO!/6^iVҦq9.ԬWtM&`gf/Z ё .Z9@?/Qp)cRWϳF2mC>CE2:W;ky{i_0a"a{j_\N6r7t]\HP79fO (7b 9j 惩5xumH!TcV旕_xI@;O^|Gp6ykI={ *ɒaĐ )d~y>ȚB0gL?C_K{OiZ*;z{ZCxNF)V[￲|ϠزF#ӆsSs`Kb{Q U+ EU?OHlnS0p?&%Ŵx,̑0^]O\W/E/<栜k\hba+UabR mB"\'@h6۾aZ7/?xp?D~N\o5/>.mI%6+(UE Sa^uW9ORyL^ K0^|89*u2='˯i{|]1]xo%"*j `@An'H,lMcO7c?Zv|2f02!/$ : :IL5v#_K"nL##&D XkH rƆdȆ}&cf2%+1K[Gkz~²'/9kꘇO؅>+JN_ <9J"-h۴r^< 7'=@Ľd7N \jSb+Te'Cg]F*2[`xߒ寴xP=r.pjr^)kSʰ隆#.MBPQrTL?^LX h& C]iyH[W-L^ycU+sVt\ߵqYRi`p+u]PСcSS2_ǬbRpβ@]LaC!ZnOsӺZP=Ǡ^/MðޣRyQRS9p"4ud1&J 4BAʦL%j~}E-ؾ3I3l)/C!:RAߖQǃ[vZw d`ݼuF"3ܭhy"KȹG}TzH.BPs=_:SA~?8ѐ~oիSus%'?c֬1:Hol8Q!@Ȕc UY Z]ѣ>Eg \ DZKwT]e\Zd8q9jݶciX,QOaa~Wn>T|[C #">7ipTʀli߽ ';׺XÚ%$9r,G 66]<|\7~{˒av@Ȟ*A"0Q01@;~ׯOwZ;1Gˇiܳ偂/@d vݦ%2ބ/դ5/B~lj*РI. g3N i7e$o%d"~M/,}qm+9[8*G(%ƯzKHX$HBۢ{o {y@fW;J(D%vBۣ]ߐ[}/ݴ~u/P96h铽K| 8ޖ-91 /D˶Bql|MV>pI|:m47q=KLc4YYZ“p/I_Z*sNc>n=lQdBzM yg穻Zj+Gȍo w3Ս~Eq-Y4Tnw7C!?Yܔsy@JwbݓJuf[YN9#e똛tCIO \i=(r#x2{jX袯lZpvݵDiBVp!6j0R7~i}_;Y6xLy caO\rŸ0b"!},Gz]0K3_lzxyY'[*&bAT/ȪebڼKiդ`ت԰MsZ3,X<~TۡCz68j?v&`XefPÄm(a9!ٻ^-d>pxr-{52i I*ϖJF#ꟽGnTke%1cRg 4Kk:njVeSCYarqe|o;}I/c:uv Ij2I"A|6d2fW>Mc{|U>s'8{5J߅ˏWyn b&cv!@|=+uՎvtL2Ґ&8J"l bu2<_L&CogA6#tt\g +lI“/6=|ImJmM֡& CYͬD`@ [$Bo I fC`'w[c`Ȑ0~S[*`4UT%5TIwrPY٩.)ti/vjLA8+$-I8M޻:_1 mJǫDBC% r_]\ u&uvh_ҭ|/MoӠ\5p "Jńlbt.\χ* Mdݳʛaw 8׮Jڭp2k!Wwmm$|Ư+-">LXe#A_7S3`P#U?{_ӌOv@&IISʉ̓qƘrEP4ĖiZ:wӐqki+NdOL]~*4gŝ>7AuC^)(8VpϨyRe3ւ6Yj(SsaeY|m969Ito9PsOcTgy/q?ذQfuHk=KM|&vc/nT:UKtŠm/ \Tx;@oiUH46<*Yt\C_L%KY9BWq)хP M)n `T0Rq9 L`,lڐ!`7H877&#c S=km"ݔxb9bi:Ss`A = %GoIX9ib$,r9BqraXK0?q|Q*Gm0NQJ 14а3,{7vیRH^ 0Dq &1LC ""F+^~uTa6F)6|lPc Wu3WF}Myw/1a2n DzR[-TR">gcQ DYIڢ4#II-a4c`Ibr[+zf({̱*uo᪒4N&Qz-3}TDܚ9;9h΋ N}QƂڸ AAQ, &_>vP.ͳ܎?qxGBiE܉Fc[IEf iAvqi}ӰPAs)uC-UT$C{_LH{sid+3*̱ϊ-ATM?$V?cmG49^r?nKػ c\CX-&x݋{C,!O\mĦͥ7kxu壓Jcx u,Lcˆ=q"u@8 MEG=Uw1j &fPpz,C`XEݯSf?At|WP[5<;@ꙝR25i͂ޜA,[$b# YdbJdGXC0iζO2tڃ(IhPGֲhW8u%s03CT @&[<^ҿ?J-^e HOS &!H2yR~E}W|WNHU;3}笾_RW!1% uNs1KXTQ!&j ы)hEޤ,!{CwuWܒXhw85v*Uk}$'[` :h2X)dB UybH ek1`.O>gNA(pc U:>7+ Λ`^3a*f$m69[|WzT,_@M{_= -7,',TiUelk咠6G-tZ*HLD[M6G8ӛsܮviUqj/6;üL~##G ==0pS|hfwV7b\Bx^Wz0I˨Y9i܌FHa~pHk]+IftҘ??g..404N2:s`j"d0x\T$HFhE^ N rifB}W?8^];6"32rXn!53l~]V>79%wer)pH#嶰%[5 +;Wq Ix;m@| @ bb>5Rs 핲H[njƬj:i[sm $6[igyUU;BD& -/q`fa*2:& oF䤅j[bTLIÉ*d Oe#ގ~{ϙr 0" PljWV cR,Y1 o{ϭwVK?5?%8ܦ.n}Aa18'%! ~Uچt:wujNސaCGkgx4 :| L)E#^~_T-Wˀ Ƿr V̗s0'\} MS#R^_Hh'R[BەoKHl}ϡtVHLq`JP9ӚfWὠ _-s9v_]3Q\s6iͺHK/񽜕͓b*$! ag=MK.&Ux"ÐWsY%;J^1;B 8F}Vw cu3_4ٖI1ǤchAGqJq3~91SBiÛ:=ſId7/\[ޗJR&GQކJBةIbI"\5HP!5ltz$m/ )ʡBx:ܟ&uQˬ!߄~YY_SxGjƲΨfUǒ=`V4uNk+t7 /i.]6^Ʌ/wugAL^5vPE8ICIG%!*P.+_Vtž@+"]sVV1:diL]DhH gH%*9E|ڞ=w+D ߜ?]E+a~i 3f!%|G%#%%"1Z_`ӶL&[|&{G^=֙_p)[+r9E=ֹ` 9nasTb@9ϱ5m}aUmU m@#漢 >ʿ[:JnS[l9~ԂI0lP4UbYHlD;zBno%^Q*[ 68cc_EAo(6RTWRВ,0'-hyfQQyX7 !l[ˤFIӐ>M[ķ yp Ga[﹏i\;0,8VU\~/]O<^{K(Ho-$\le~of\T>5Wj/וUtA'/b,")E/@Wjb\pA HI5d ށE%7IySL8ނiIg+" by,҄&b[w!@0KBa..3`@ t2(Ger )f**.^'RHqˤ_o߿{<]c+UљpBvA&E%u2zb>w<ޡIBG)zA7$Vi4r>*"_c3^֑c[#DophVfbHnS=段q1q3]Zym}?w9X+o7m9#7X@ujd]dHhC0J }d"j֤0m)ԘC>KW QK?;9o~9`TJgǺi& Q82#F`9oxGkHBH-\G<=. 7ydU$f^'Yod7i8fH"đG!(C1"B*;. =4gB$ҥ DUb Mw=GzTe{}WTdʀv" #LKTz  yc{[zPXX@pv+hh( ^ v+R+0}̓&柿9hF7DMyQ~'qsbs)mT?zGT`@+HH&H("U!( (A5+U;L\-B@`0+X9f%Nsc lHDQ| E}`J (**DR0YeF( { GSyVKTQMVr3TAJL~_LD?sLfd_U鲰j]W1u(}RYg*+S~=44M 4gK-k ߸:ٲb}8;)F+ĒSY*; ߬`%{k(6y:GzSpJ=RJXX̓AAU!JKUل'I3|'*D`Q{ }ktsTWQ*PCGanv+iʐc%A]7ĿY!mJxl++~\.{ ^oЪ-'_i~('c r5r_53t wãF8 e36 1d[P1ѢuIH7C$FLdݖ9@]!Ǹx% x^=Fs!Ʋޞ#? LC,.I$n e1 4.T(Ǧw/Q>i+~p1𥠖H 17&uTܹ25"0W) ljEbOو ͸9RaIEuXEޗm̤at3Թ iH ;lLZׇ{-:a( e v52swBݽI/!yzttNMQOXLclR[TgѩgBp0}ȿ6)jhoVPntB&~[ -T{J!n&jFnHHJ9lI|5r6m-n;Z[=uN @`jFA!}[}9<~_ :c+FaPv[[\:a]Iv̹:0a1QY蕻Uo 6bxOFF25lAg"@hJH2tD"|#fBgjABga5sep [ 3\&2눓7 sG9C!`e˧Qk*<%B02a[s$ƟF:A52|jncCԶw^I{X۱KeU&uqlhb`Djo>\'ט;JN&@YDd,r6j)Q!ѤD\vw?UyAubebɦʇƂ/ LZc,R=@`0(16l9T5E9o@6 kj>jQWƲŭmLC rq")T"*CLU5$ɐb&1_YJZҝ6~R Fр6ex$ͺmho.A IRkX-7d1R7 YոpeXhQ`ztkH/d]ufLչVvͅwy6fl74'sY3Nbh)F\IA@q)>?ު&BgkHX)X)*u_D9-y`HA=5iYH]j[j &\XkWuO}4dy8p=P9hNYly מifVle3u&V}l8@7 3t>co{';m˱цJ+W6%]Fe.Dj<ґUq qkpI橔G2WM\cTKؐK]?|$p:gm_7g02OQ?􇭩TIZQAAQH^^Sòq%Ek O QeX@?u٤ف؝Ck,K\00K^-I c8kmhHe)$"7$6ܞX Hհ`q~ 2IB|G33>CX.">_Vu֯\go.zy.yI?* :%QMhCT1t_˫QrBIa1 EoVx\׏_miz':@Cv,/J6szԸxA}訑8;xFWBo@jW{[%cdz/A_E\\b LmM49wD^"zz~WS@u8vpX$,P8`o8z"_@x8Q_?ݤ:IQmҩ"[USJ쨎ñ |FUDq < ?+^uyv2K @=2_LTj3}MM-y!gnV_ U%K#5 WuIyeW6nb[\%t`_-W ,RRvBkp50J`7v>^2VDYxq4U:/nW1Kpy8._uO ``?֖MKA{%~=CykyLfTjL2™geːpu~ֱH IzfR %BÎ P;{*>hmM:Bs B?iKG?w,ޒ{4ӈ)r=D =I#ھ2@Yn)S^d0n4=/cun/i$AuNf{~}UP<28ͺaJ۶ta  x ,r %t9a'|1c A%!F.@ʲdT{a8!6Ma+%\v9Ɋ{-甆~h| ٳӅ+UKKB%>H5S+Q 6+oԳٗF(9vA'%BWJ&nn}rSmp ^ cM =xapa5^}.Š2Rn~r(LEZ8*`2E=>}Xhqu9Ynw~rtcy/(%bXPK~.̂6iUٜ(EX85˓N)9tԇ'9 }Y͂UrϜ?tFGPtX^a2BJ40B۫5LTp>z{VM;AopXifظoxTVѯ 3-% q›;m2;Af ݼ9~a)U9G 0[K=}l˚Q׭jMjTש H=iAW dz ^!R)HΥ*PMf eڗ>z!p=h$`DDIlL fMĔu۷9ĕçkEٸaz*Ckqje3G~MzQDѩiq{4 :er2;5<$T,KN9[2 )~ک N' iþ g !VHzm-|ClXW(})+gۖq|r@$ЀG@ApDJ}?YKYTMLiND3@H7A?u9엸uuuU |ݢEnX=zdY]gu,Ӷ+௘| 9Ma*gZ'[V"gkLWuzjE&*[6g Y-t~*8B*z5ݰG4fsŒy-fnwtRuWLľs|î=&N YX^>{ϙ>@Fuzz8KSpftU OXpT Yz_zPb\N0s%LafYke#_f?^BHlA867>ȌU 䢧# 09" UUutxUM3/6dI0 t׭QDȌ~^.qbHc}nn>'q,zNW@=kLq2 CaPCWHTݥ#;1GwAG,N@ rW,.5+ݟ r ]d8w\ ?&W![eDi?]hWMrm9Rd86~1wSNCy>ǔ3r9 ěpɍm>pfkw]\y}U|<nOAk7B&97 R $9XiS*iҠ ))DDϜH9 2*ΔhC|fADe)7Jvt &n\[0IKawaN#uB!KX*b RƩ %HSܼX[\f. %K]*Yd D"p=EPS!' bh퉌j 8kU˛= ~6 ncd!8Fwm rL. ؍xGMUˊ&+FdA'"k3ǟz[-G1*1lgc"@_~_ΨzyIg#uM[͜0L#z `>WT(S17&9-35vJi׉sx1ؐ8\ABΉK3Q7Pݿ@-mSOZCܝ2S$lS8nڒn" @4׆0Nmwt}4Ym@hRUc,} OMy}iWsw_1_ȪUo^噬pF0g eoGnp@gTس⟘K7xp>'a6g" !:A0ٕFLhEatj!ݨ~O" z\/sDN;W W6uJ#l& fyk g0@1P P˭KלĒ e@ D 1?8AxΙyk~J엃@1 R"BVی,F,.\ aУ( H$Ç5 2誃zXFb2 8䗕r}d<},%P:': 90FӧgM߽sƗNa<@ :+< 3QPdb$ ԩimzn0 *?oÄc(.e'A60jk~f\ۏ[[x՝3! t^g/J~92C%L*Y&k.6 <%?_yKpzIfurH#%BK#zK\{/Ph}l ?̻jNρ]緆8/C?v䃛'0۷8q'3kTz;6ƺ:q➯ [ggSb|zY }?WaTb*K-~E4GEo ZSx 뇳7sV!@na{WB /l<_B)aSG4g+}/RkcVlV<O_A(U{y7yZj8<\Cd~4cĞOX"Yy6! #,CJQ dhVmh)Hfg@/`\S K)Yaq"9γfpP)֢Qs JpfP8X54{F #`Dg@dN5V4c\ͯYH+ݪV.[V1Pojn;F02֚}븩|:j1ܥzA%JALp2dnɛ ^{E>|I⭤fN&#p{w_=dSBE81h}&֧@hѧ-/SQъcw=vHs|ad*2NjDT31] V&6jBqu-.)=9a04NGyxhŹ,]jniRdfQ@Voi=+[B $%5kASRF@|?MgaBݘ5IGdD'2_6OM g~PC 衵jjm`UIm!?&#1)㽆 Im^$NʢÝ S-7=R'3e ByP2tN%|xfޘ09i%n{) MZ`'M@ɧl})klc"ĽS@"\0a21XJ;5. ʳdeIMǤЄ][r1eSW /؆PÛ2ԥ0L=6.XJZE ~ᒤq3Z2?^w[a+[k BݥG͊@ rɓhtG7(yUM@+?22+KJN`\HuUfG@Ԛ$ATcڜt3L@yMM#oBy뗖:NfmJXe͐{l.ղd,ڰ,KrjFv]N<_p[Qi۰[ʮj,\Noo Lf`@TJtq"pk fflN5KzPWN})~fZ$y"mۜjggFSǑ^&b Dy]V%IKyEQ(Jݘ%1$if.NX5wYcKo@2SX( 4BZ i6q(XPe @!]7 Șa{[pһ_:r(i.ۺ֍Ł{u;~Mko5/OJ͑RW/U׼61zp9UnFsR5[! Pi P1w֜ U! ҄(5poR_@lԓWI 9)oOheZj/̲JdM/R[֭flsɩ268xHmEAȧ#J1$N"*&d^Cd`y @%hg[!C8tWfK/ܚR*5oؗ? K,,װ,i)&^{6<Met%/qps)BλvjANvggY9 z1ɲwbCUw 6{1- UfܓtX|ݢRY!w2 W7NJ̺mi 31bVys%7f1E7%by|sG Č7NI.PЛd˷gJo}f\ #!@ݨ=YE N[pFOޣuLY2pØ]WtwHa-U )ahJ.j K^쯿K6葽^Œ.уvLS+{)Kw>7)L G`Uya 2zvg?eddЊL-ZۿʱT =MWKīNYv+wCy-kê-qv$ϡ:ݫ=+9YCvxu!tNd~]i 5Haժ^|cq 57R6}jj%Y~Ԛ +sO"+r.5,ҩB`OEDb;$|cFS8]X+v7q)E5WYx6ϑIH5 ]2r1ýL Eh_D7"ʉڭT!tioRe#B :W9S;,i6.IӽonC)_&|/C݇ua=n‚rWUJ1ΝMe&1Mod,)!B8-Sm@x]CŘVvW{0{y=4@ݛ4/dV4Z]6KZOlc%79½{! Чq1⺹./AQ/)cÓ8v$Ѝ2Ppa-~Xט9X7n]#[K[YʛiXbC?K/*3 f_ǢlG}˪Kpj?iBĩ0)7IzjL{f=W.KSb{qv;۸K+ϱ"\Cn޾\8p1ڶӸK*M_9wI`c"L Π ְ6c41[l*#jqPϐ`I34gٌŠ\ږ+SzHרk@65Y&x4s4SV^y7i|k j2EXPfQdFFƗeNz)2ڤ(?˥nI?K}bn;{*1T]V/xx${FVHs jFFIStA9~l~ iTS Qvq3qY43hh3ʪޕOÐਲ"PH@-'ڿؽ7sqtgwykFafk4{=W-ƍ:%̶q.Z^U'=csyv_KŽKpm_sCDZګ^i jxe}k7~VY);#߭FjoL9cmɞ9GX]UNl34& wLvVV^{YumQ Eϻ "], lfjK&칮xgl aF5$Hq8ҁ\0tP) qDQkGmOUf36dOHԔ4d-LdV kA1~; q-4mGDŽhLw~lN=^[ BBfxaV!i| TfeH)f0H4Jn-mLYB0'-ff\l1ln^%pp!` WCEZnsZSС(Hrޮ͖?5Z RP75 ;{~JWϼ<:^_7vgӶ1j]qVjDxV>be;:e˥ FD\3:] "C%78\.p-%e2§}ͽgSo;q7ATD`Y͝aa؆NsSOWWvh}أK$; G[1Tk9DEJ^k35)09 [&O7*eWJy7 JqǕ)޼1Q ]d͍؛c{C^0qXX{?0筐.%ޖniuf׀auv[ ;T_c9.J0! ;7-Ϝ$AiGFQR d@ϸODF.La]ꑏ;T؏)eVE!!!H&qBwۨN -:!r5-Yl`H%ؒNP6gnv IU,϶q<:Ry̒5ʱ7ixLAF]}-:x_F@@0X;"7MYw<Dm*zh3*!рeXw1# tإG BSyU%}lNk9ޕIBo4nJʗ¡4MLkf\cf#θчP [Dq$fTNkt*MstZF8+*j>Z *2^Ʊx6t%;&R`YhbmoZ >#ҩwsaQ`bLFֆvAeCjKKav_[ouUt OTǟ Rx2L5ā y=`_^B”7fG3J>5EwNxsv.<@A?=&Ja}X,+Gr&)OƎlvwdoԹJ1q /QZ &DLX*u6?>|I>=hlʍ<.dZ8w&~hРbz :k3 T0kLA>+%arQ5S4ĵ4i| a NL3倫1ƥl{l:glO'?LsU<'|G^ؑy*Qxu:#w%a&YFr#絡e߁jڰC0 Z;nZ}n%)܆-2ѥkger ?s*$"TMX$m":cX &b T<(6"sɊLs,ZMmFvaU?kFR7سͺ_!XՇL2lj!Iza "{(# qu^Q;{KyUzj#6L.1ty$T+U4+Js(ʒw OYG Re[E>x M>|ld#NI& F`UgLT ~kZL Ȍd;VE3Ƨуjv̛@sۢM60 qvs'J!g*b09.̓!  o60+NAFJ(\fAǝvw2,ȉ^ؼƕ\p#dć99U e3K5C/I~N\2⨖ET΂mfKeY̆-tdkgobc̀6n:J91eJTV5Ih z|7x 2,_K+#8QQz̕mv  <IKԹdڣSYdThP$"|X[!\Mg$Mn2(A53k]TPز~vq]dat7k$At0`Q|:0,ݪl5]An6iywśmCu"2q**H})od+XHfV*O[SQ-OHXE9ԑoEyJ5fItLao0>6Ǖ)\Ȟ%[ C\Ǻ#6ru4M鰜x٭OVa&9%2wWAM̻- %u̻.jf'qtѵ-p{U7k/ÝAiu^PŴ1HCP}sf Ky;]YDhRcArgq[tM.'rf3)."c)}P{:$OC0ZCе9jJPMZ3{-/53Zq9I.tӲÉze_ V`'5FYuˮs&bWZOC:5]TDv/1fnM\:Wcu2DF_^ѵ_!٤ R(&Гv>t.#Bp 2ml#1UZ#P{dqȧՖ0昊d Ϗ} \W^ǁ<ϊ̅G}ܺCz}VޱS]?Vld Ը k\%!X}zۍI9ƾbO-dK`vD.eCqr. M0id!"F;ξJpۯ8 Wǭvi"KgT}Ԑy{ߺH4/R!WWN:}.nϬ[5W-Hd2t&CL\\CfA #ǀ9Į8*t F`yW1KUV7+N̫clqϓذ C;8Fr:샄L ^Vd8,2'̳ wbRGeq|m .[~4kLђJ0' "=JԨ 5٣MðUOv"uwygf:PM 8y_fz֤l'*atsRUeK Qtvy3VZ^aNmMpܼEĪPmÜҐIҕٺ'YU&0/.քWd'b˫GVr6v=y;^cEeҖPIy# TUSk~mxidz|4ܵՇ&zk5%ISd׆ nUŨQy~aI\f~y7^vIz4Ƶ KaΑm^(94x΢jOYU]g҇Moba)l&ZRkej|ٱ)xS'[ _eG@0ògaj ̬dD'fRӵSKu|]3DYǐd޷z]}jGA?Ufq/֬2a%,u=|<]kN֝`̼7Jo1hl7m4{:Su)_}rq]K-ä(OBJ!֚q13Qw7tWan֗*d}4X=z.ȣkj"OHIkZxƩ>ոi{wo(}Md?S[!UY|}qT-R1IqַKiw|YTOtKܶ.^9{rX!eS͑8n-$J :'IJ8)o_Jj 00$Du7)FLwhV{Δvﳛ%O;ȏ\Đ"[InLT^}%TeFDk|em T١ۿ_%r'GLv:[6מHl-rU`HPRe\Mͪt߁ÖFKIj0H 2:Yf_vù5=5oX7p@G XZey'_hpgR$ 2xd1#*?psvZy4zw*<{\b֤'<5:$ڟQ#{R?/Y-Wy -89:?`D@Bb3RqK 4Bx9E]tIEc0!_1uEكb@:BPS Z9 ;UfpUd@>?u`͋7䀀%cmMzπTQ%* !z%$@hn}D VJumj*ީa0ZT+wָj0F[60(1w?xUNaL偯dLChsk0ti["o&E47#dS~'W.W&NKr\E-$Zf--ٛeU4N!Y)hMx9ЭiaU_Ci~G}Ng^Yyj H46x_7Oѷ,Ge,Ƴ ̗'Ep{GV'C%;ҤNMa/L)ǢH?:k{]A6@7,,+$\ƍ_}k Rԅ#y*UR[-\+9t! uP"X܋vC1tC8ưt|eaӭz•8=+{eQ*$8塐8Z8sov_O!v8 _WtPVꍫ0``w#/XE9* (r%CD9 R55X!aPCb(܀ fFj8;Xy%:M;z2y(%sgmrz{QPOV%Vsk.*陞+rL%2ɈT,w_*y1'ˈ~Jj^@|b(fhVR- w˳e@ KT?/ݿ~i@tLi~}Q=&][!k-OV7l9yjEjDբo2'&o49Hƚ縦R~%yEؙQ,#Ϻ 4:S8CGj`T]'E瑛JOs+GCf֦Vڜm>fvQ5=쥷s' i:PRt+81Tm<סݾ6z.V ) &5L,Y+/oQ'xpΝ1|'$юa]pEXRܓu.I,͖w]9SH h1LlU2"Bvb)fp-!FVSa4:CN >DJ2q>> v·S2|^&P ~yEc@b>ПÿA'Od^fkzQf ˳oJc;jq#i&gylZ=K+Z8E 2"iq)w2T1h>'v|?guYYRFjg]ajc:"8y2G?hH@Os9"*HJI$bIDD9ŜkŃS9n|trUsNr:3KO(9L~1D |]B0ʜwI"E ͞9 -j3&`!A\9uVYtDP#? Yj_HW1d>I'1JãkUE  1 ^oX3sr;)u] cW\/Lq$KH]zɪl~XlSF]bo3{IO`_Cci<R;u Mh&=8f$*ɅG`_DiiUף}ˍtQg{F$?_C ]x;r~D2||%CՈ[5q ^Qhnk70GT1I8{)cs_N,RɋQXh)(Ha7 Ȇ3А_,MjŽf63l"DI%No`kg!DF{-m{P8F&ȳm; \AB I3B 4koR5Ø?I_% Y_IW#mef3p4\[[yIYK-? |Vɂ>R RƥdڸCďqtQ^nNE=҃7\۠w x2 6CMXBQg#9<i.SEQf P{/u)W-ef{wr-U._{[93_ p]J%w8@5O0g?+ww>wEI}j9~G+m: xKЙV1i]b~ tۃsKYMY)ӷxRp,`qY&jF1_l ) xtq=!UddEYP~~@ZHT Ur O}f#TSGoMB:YִImZ:$3dED*4K'9n/˰ a8!^QOd2aY/>~ 'ZlŘ9!gHfwꣶi[uدf ='0Adr [dVs3$`XxۓUR;v6k8{q$`S Ku }@P%h k+,=5p|tFŘG/R9co_:~_f^;?7]ݴ"p8ձ#"U>J 7|ǃᕅ]v\r$&TU׀IN+|YUXh} ^%KP=@Tfhцqom ):;l ̡)Nc*L W^G?ޙGL_D;.wxH]ygN{mzcd!OpA$ѧ9)CH fը.^z̽B6˶QsLx97Y%-/pvt/ 8>K|K#"ئUx*@xW^$s9%, H j{%"izuXq!( (!BZ yc,s۩M}~sXz:^(Z*ȟW ږþWJIx%ӯ[ {i)r{_̽v4;< H^p\x-ĻcÅ/4CNk0Tϰŕ٫+1XǕQe~axSL*k8sD3g-o>F=lQZyؼB37 d``0vɢzguf}V_O_΍MZ- vh @ʼnN]-塭G<%LL۫oaXW+-HnEMJ9P"w:'*tyRʜ[/+h~b|а>kK;;iqnq=VFfʤdJļtPcʤ߁@>^l]t$-u12۞5Cg[AKj4?l(I*q˷* ]tͫ+U}#X=Α--ص'@F0 .ÓPB$|qq~T͓ dZwYΫt6OmZ/yγT.lc6IGã obn K1k!o$jCHؠXo*Pʠ ؉l 5@&A&,"S:$\snGW<([Z̚0@3  sT/Ik^C끪qp6=V0 $%*41rB \sc ԧ`hP&'Z[`*ŷD7,3a㢏q hp."1CzD9s3]HNaÂ!1xI`iz(QX; lѯH>d3: rV|z4|^WddcHk˟c۬)gzك#V[!i]TJ]#x֬SmL^0zr)GM C7E_R`|&%@w} pS+aѲR]D哓s=7ej[S4M9bRQgK-dpoC:.Q79dUYB`EY>[wN9Ƞܠv:7J%P$‡I4ȷOoS_wAӳc'VeV=ozݰpl|0ȋ-c'X.04Fy;euTDVIIs/<7EPj~˽cO ʴYr[;HxV\ͷat[.{Ѹr=pME7#CoSyq`*v 7'{N{B+Pal8 TaLƺ$0gN1[_źos¼6TkRLg-3/{^%g-,OZK\D\@PH: UKom&/P MdӬ/ 7sk7 Qۦ 9 PuLi$F_!;HϏ_qyJ c>|!:!intPurm>۶sw=tU^ *HwF_.)CT *BTgi#2ZDFjpGڷWچjg6RiSK Td|E@&Mdve)?{)hHb4U6:4A~co;sa2)jWJ@*jewyFʊj};uجUoy%/NsQnbIwC EP u N[`sk,ykCUsm_%_SBBJʢ#hQmlm.[IZfdy pǎecf[)ecn 뵏}+H$ !IQFOƛdm[CcDM,Z^-0Q+r`H𳜓Ʌtrp8P00HŜ"!o(["BG#/]~u{Ңy4epPXAM_]2ųd k3<6rXDoi+$"뭆qП<{?*NIØ20$VhK9ƃk5-ϕuub ;}1% M|M-iES:'Kiɯ=FMɦ ޯ̔Hu"DT HDXB.;`|%W/7YP$csTUMRFq.Mv0(`DEn:YY4XEw{쾣S5*!u%ixœ #7V36fswٽO!3L3Mdԣޜ/M6[3MRݞ9WUy'j[vcu{5*cj~}Eh F2))3Z:%&IPjХ(300^;_ LX&-o6hݿ~8]w3&|j] ǽvL9H/1=6rJ[DKgnSMVI5l-kž.fE+m9)nN$'ZOOW઼lpbyO.Vq: yȂA7wWK?H:Ώgt eq٭]t#lЄ\Qsɓ~9y}ʿpM&ۓ!!(Dǭww~ZuZ4٦nbt-<vf'snm.Cl ۳Uoi2U)u3HZRY,dV6ߝ Z{4m5sd<{߱sIh/J"syO}>{ZضKuw8`AU&O ww~*`-5 %k"{MtU[ƬU: "BQQO ^n(RϤTs2yhGH%AxRyH 2 Aһ/$R绕$a\0oG8z >JjZE-0) K1,=5d;E@})P"Cyo^u[zjQzѠf,IQ!93ЋE;ZIvA׹Bu묃V5 -Jca6ϽFH(Ȃ4MJW6}UA/)fk@% i{OSfH$ŁP[Y'a߇SDL )Ld[9帏zoT>=>IcIG =IrCr]Ec~i]w~s6 6m F+*(D@}g#ZeA)ιϯX[EHf5B%la JŏL't̾{nM;+7?04;Sչ{^>CO־vF&s O99Em 6Ϝ"EH0I2SUQZ]r8K0`E1D{IY//[?az}=l05~@;-0ΠcSYvCJi+ZcUs:tZHA0π0Z!9 Vnn))c9W#Auro!E!U7=fSN&Y͋^]i7MI?|kWGeeeQh(.!f1zy6A!#58n~ 7䥌`q/Dz6TKJ&jߐqpD,Rz+g9}DAy4$IFw_A3 Yѡ|c'HkơGHF`"q6|d"NU3yA̒H5c{t e0܃S\~A0()B$Ŷl@?-@gwJsX,($(A酐LLa8:E.JLJp ITEXtۥM63mVSq/1W>{bkhJJ`㴢?ΡY0bSL$ q^"ı{L>Ngqč&;Pf !@~c|13ae. `_o ^xNO SGdQ(xwlȎNOO4wcl{Y*֖KZ&kL"A8 (wt>"Bɒkİl4whffO;5lsFbrBJq "GSI&R!!r : X0x9tdizf]#[;SJw#D-'|WfW] v'Q*O<.gz.mĂ @r8=WwY,4 UbkJ(_hpOUdo,HW߮8.FUgx$˾7Lv}fO$,v|AH4[$pw>~N9Ԫm;x=TA"$6:*ACʲ Uy6=~YQcg& z7GR4~^4ZRJ3dUzUTzo+~oH/Fe7M+&z5d>'AqmB" mrsm _XMO$bQHmSww'pBwo 6q^We]xFg'L}[s/[{9AFfk}Jʨ;qբz]w 8^{=N++|+ 9Q䄞 T Q6G޷qb7HBv>\M)v1A&CpImr趉 'ԎeoZ寮&r6>D1Goȥ&". Ν1(qm6ҩb=v|KHKE   %C\A9pmH/alI))(Ȩf4ۜsČCD"k"ZVcqFh"Mc&ܐ9_xaﲃShGU3 :]ϥon`Pc?:Ŗm]9 3I m,a~(z>X)H؍BUT4"O+&*%fA? (!Z:EtVO8Ac]YthIY3JPtzqc򃃜86I>}] V;̢L_JI%eUFjbbrpbZk uv"oߥa{7J\Yb)d-[&b#[ɩQ|7C7%|_ue?^MyU~L`||LXY]Y^^A>Gs./RML0~$nh(S1W4m:F1|j; 1V']_ZFsYX}SK]m?A|tpUUP ۻi%vMhFEf0hj\p7~.Fa; 3BQ -YOr,gv1[s3,@+Oplk0Ci;shlzlN-\ź!-]m`xjI\~*N>QM'U<[>-Z6Dz:yҪFn_=moMO >̫Aa%y8r 9~p13G"M7r^rkJ~wAfC )rpS@kx3-8cRb 2qVʘ?٭6?›s*vP˅ޛ{h˼]tP,P)@ !lLFM +obhyo"Bۼ {&e(?"jV2fr2WDitD[1:#= }i/ {JL៹K12Ԍjj>)P")HP@m кSdЫ eӲcghǼ،JŐm BޟpڍbeR\*ttb쥟rVƔ.tL&]! i15Jؓ+:AҒU BA?/\P@1(e_g1x~5 +UIFC[bv}Ģ.xs ӥ2)=3Xji(OjQRm4_ I- s^0Ґә@29@s=}oCo :MgXϱb]h>w '#zVd;#z™!z. SUFPg]\1NBArMDsȚZrLP!H !8Ek,oDf refcǭ vNON>:y& Ǧt !jE}Tx3&0:aVTLOfې$~yf" Ǔ!$nSs3p׿ߨSZF"vPmL"F' |.b4.r=2˜$`s$qF4rO_{F^ûQE: i !+RgK@įQtevk 6L0*K^U<*@|N 0I VrYPTK眹qnf&|)9JfQTG%.PkdCBe H0X8YM^h*BW3xFa AWCFJ١ƔSESDiTҤ&lLDjݍ, e۱P7`n (O.Ey\s wԸ^} hշP q]\K!R؛]ʙxdJ&r TeUc7cۇABa2#z,]+_]u׶f J=%0%u~6ps|3^9.9M,8zSq,eIΡI]t/mٰ|5ByԪ"/#;OK޼⼭jʒ02`--ǟ^ʔ8\9?Lv["ID-P}ІDn?~ﮔMx 7}esHZaWçR -qug8jK;|K筸o"CW I89 ÊcN$0O3ΙI,Sȓ:rpj*×<P QK  ogg`|6Lafs0.pQKc5IMJf;G_.F*"M@5 ݒ4@w \H`@c 0yңG5) 1C %Svv3 jvtySytq .r&&U@HGj>)vb=EQꅑ0‹T!cabщ6Р( vl@1~(CӪbΜd$Lܤ~?Nqɻpp`K;P( \| ~f@ B {AzO JrђˇZaioh@jf1о0>7=; O) I5s&\r߄RՏ @lk0։a2$,ۺ:-mo=lK<si̙=<Q 05hzl̛.ǩ?ǂѝ.ZUN{4/@/E^tJ@k,$Vע:~Pis1ϔ&y3}On;wHȅ)FH0X-* s!DBTd@f~^knW852Y+b,D09Gc\[ *V-vAt -N,ʪ\;=ULMwh(ćO /, F UG>!+./M`V<[FA>$}gȻ#lpis9LSans̐8 cdMe>M'zhM]fVه`R ;(W;X'rYBG*Gj=M~3Ȩ0PIA~l;A-Կ "up/'QSq3@gMJuf#"d5N?{B `Ȋ"_< nץosK`DdW@][lJb=|14g1q؉1Ejv\sB $2sǶ4 CbBG|Qrro#[CSV^zSɪ>;gBC)w 4H;ƒ1K3~w@RAjz Av0@z3[xU$˨÷O(0ow?pߖ9{B8.im?'D( 2If7Z"$2Ow$Gi82/b_g%w1ZiH6ы(ssZM(ǽsn1:IJne.+)oSXoUqGϭcG~+[3Ãsh/Q\)59Lr 3<꧑k>pZ1+c/d6+{ HAc<*:\<Х%AT: 3! };?J/$Ṅm˴peZv l(O$wW0IϥiT?n]RX0n?rN&{_ULN&5L:kG_€FF `6_[f`c hur;㾢}[kOY^2ƾ_.VNɛMٛbF)[u@lޠxZØ֨0H lڠa2NYL/}RV抄 $ ʍgDCïpQC.aJD PCI#wc{zrΝhh [J/4Z1^1\V=*vs4kpqϟ:".ˠjp($deMIC3§zv4A{F ˧ ɐ*ձ8czȉzR5jZ$AJ?D;Qx=uo[m7CD*~ȓ38$ 4r/j#ZXW[۟Euvͼ;]8VR+kb1gKWƿ0,!poWV gF1-8;|uls/y76.OWp%>qatMNj({ߡȘ,P]y?'.a#iT7Y[q>`o; fQ祽qOǺB7]6joÙ)ȟh |޻|b)3q:h9Ǫn7Bxڊ yL>|YUN-43Y`Tǹt;Ϗ<߲~/ve5U"I- J0sœ[q"DbPclv2Zɺ(8{>1>Gܚ B ImJWkyop.A="hkTN|D/J3pүpYDܗ>{ʰ#BH-!+`^KrF!~O!ԓwɬ (, {2Bq$m䦊!/ZؖKg@UwjTMvSH[ -sqLy}opBKA6BM 6n>-{#jKYrZ/-'9I=w钞/*<^Ydyö.+%;J;J IV,0!URT#x.dEq$xPzC'1%gvAn ;wAC;܇qBWDkrX#9w)j8JEmqflJp=.2FNt7`qGL8E&82gKLCA'C*b(EXS*ޗIhs7۽L=GkkpBʞ5tK2YC'1v&Vmd *GG1 $U>4۹d*>?A0츭-N_^ ! ͯ;#i޻z~A m\Ici|wL!t\50xwW<:~<P #C!> -}<"^z)8)؎9  'uJدPrE/@X 6hl=G6=׉}|~Ub~&sבC>[EJ a87.Q#)a5Dp]vgpMUW"A Yr|D!St[NEZ/S+0빯;iؽ" ~O8$ }y(eг8yفR~1T: #cboFHdF}j]wtby @Gu}iq+xR{V GE~Ex\+(XQR.u@2y(@zt115V"r G-Ō~.1XbsI/]ƭ8=Pr$XYҴ)9H\dx#"5ZxET aădt:A$|2G"ѻE c~,0`C6/zOuf I9M l {49CAA*KXR,J2EI#)  Bdj)AG,YXCIsHG1*?yRajrsvVsk_34P:}")'tdȃmޟ(X5do%.G:pINٮy/cmw\sKK]Z0'OpDs^f!V *}{|s5זXD:8zހO:asXX1WNaV>yvni`deTya̙t5⭫"09+,|2ÐiUNnf: u=+)@/1QkDI!(,Z))#SXt h?FCIi"JPD̩@C=A$Y6Ze3lٟ~7jÉvGh&WZigsGu}lj蛛MWe^(P[`S YdO%~]pINPH3:\eVE |CKinK^ֶ&7WnYٻ׽cT>[X~iAēSPfU:L̘3o2EuYtTD03 &vhIoS*]j7yCmҳ/ɱĢ>T|)^* >;@:)vEis?w27tNQF3ʸHGp?`s9t_edA¨ va5Qx(5mmkPhQd'I T!̢\3ox?@Fqq^pTHCf0\cT+v"-*lbhŒḎXAD%_T, سw9 1',Yb* B-GŚA)+΂U49$m ^+bD^LV]mkX 2BfUZ4TbOʕb)~ x6Xn>:qQvx:׊,»l<kT&hRUtW1hjLX}q5wy;u'ewX N1meʡ. [?YhkQwCHUg| I~呚u?[cP7hϰ¥cB pՈKH~2&37/7#TNFfb-GQ akNi#nstg濾-:ajLUVޏ̖3*%!+YfXx/jWޛLͪxpʦ&)$KUOY^"FVބQY~%mZ6>OKm%e+ۗҊ֌c[𒻭5R;!u9G3u:L~<;~!02d\9WĐ;#pSp \Suy]\\!Ujq!_{qxQ?&>+:ܧm3d67h${_$#Ri!yClҩր.wzo(TcB-;iagZg M 9iAhb-~?w.,$u'a&"o=Eޠ:'Ħk*?{)! wrrRc&qE cU L`#0cǢ;B"?sEuԶ"@]"En<0@ X^AƷᲬ_ºCOn;]eUؚ&iG(MbkO=5/jI%vr): C G#M2r'Y -ȷ HqUa)3n|hS.(ݺtbψ]Pe妈_;:{*?YX !n{))`= Qq՛%xN-BI zw0V4Ba Z9+XR`< #@jyWXQb\(Dn۳b5ClhG8G:LWp 3Knd\YeCQj3A`1bC{!.$'kOtp]"WVgǗυ$]? [kB3sJ(ًo@%I = XӋ4 =]CoG")K?+;諛sMK7?4O_I"I@Xѱ"A.rȦk'q rܣĉsMC4:%pc{wOƮۻ$ ʆ] ox;gF +5f'@x zQJEQ>!Z#q9)!D~UO ye~o$

p헝^!hGClZ==k^bɦɘ^saÔT4>de5 M"A@GTMC8,o J& xGBҀ* TQ}]ҷx*Rcc `g{ {:i43ͶԢXk9<:uyi8_DD.JGMCA`KɒKBڳSx:pk|_Q4gfNUfnq*hPPD!pHؿ;㒍o< [fsClJUm$47AC&.]cac٥m #o1~> [RF&ϩUOyX\ZZ(/2rDi"OZПCUFY0,8 Ŝ#0b۔裛NW?kEÔbd5Ҏpu?oϷ!?9LtzM;⧨RK#f㷇ZCݶ:CzybLgKтMc-1LiZO -=+@dűBIh,Zg9dס9[(7 ۄ*id!B<Z"kP"v+l"gRsORTy6h|Pw g31eN` {"Br;4Ef~#VL93p$v瀙A"duHXÅ?ʲl{ $d%㙘2qʜ =O.As-"0 ]|VQ8%;TSʛ:ŭwwpZ !=4Hi,(T:IJL٦b)kNmGh2aY;r~_hvJΏiz0_j&ȢJbO* 4d5P ꝾG]\rIm7㦟˥V<ؔ1-5Omڌj?徸sk銈p\:ʝIt?kXo4jxNMw2y Iiˌg%,*,$ҝ4+بBYQ"IV߾7T?W6aS; "TAeYk5J1,~q]M{>KZZOMLpHoEF+U6gdjRf"f8cVMY ubҶMx1$`Ѡ^Z3 &Bjb>J]!@tDčAS4򞃋pGQ{-9>[`q{k{kEׇL(fUI iQ/?Qa#y{مkG|ˤ?W"H K'ڠ.y l#qi9z\\~}z)OsIb~ -Fy!l$)ph`pgu*2>DkONdy>7XDʎ٨ejT`#!`O@Ll!qHb{p|B7CXpPh;l6'CQ>d^kgoq}ľ67p˦CMuJ e@r32 066P}Osv|TZqƱ,jU9(g[\_5v3q(J%"Ů ?UR, `E$TTV Q`"$F$bŊ XQDADXQUQ*+TUX* R EEUUUdDQUF*(AUdEB,QI$YH"R"*#(#AEPDb V("PdPb",)DR c"0F)aPP#AR Aa , YQ1dQAdU" bł U`D E,TUbb,Db`DFX)"1#b1E`"HV( `` EX,UH`Ȋ($HB D" ( XET"0Ĉ A+1AI"#$$*OH@dL}+"KYCB>bv7pxנ>PCee"$D[NW 'ѻ~y 3|r / n:٠@'> <ŷVTKbJ]l6霓J?X`_LiYV(I H`5}6bX)GSenFZMVć%Úȑs<+l6#{JF<7_ (`Ej|kUd+Ӆc^ ׯwSuoJݤ)_%r{;TK-3 dy\փ溜c1)/Ԩ?fyS)H9 ?Io]-5 \0iru`-7 ^'|ooll5ha&\af._g]cl~0l :[??nӟl&ZGz1'ǃG9v]7՜| "lQ(WW__v`M|;$"d⟗J^{Pbui<^8{[6 M.Nep (F{nx"pY}o#[{\YQt0}za#Z&9_FHULlBr @&}f6je~6>Aa4Ђ CɜykGWp^gբN7,^ZzʳIW5_"lGg /O껭  F4n+֍͚™t=֬0 \zR%S} AX 0OhdUC3th0UaDPV X_5TW?zcx<3>T,ċ3TtЂ"䠅9!82·kr U~w ߩK1p j &n8)9* )\9myy^@irs0k,I)@G$0x05B"R2etO|^RQ5ݲgdV8>'[8{}Q.s$5Mo՞LN>>tH2F)e@:ӷK 3C%swh[殃*l1RHM V7 ]bvSb^=%zS`\RqnK%MYkE˖_(`}nA>EsRqR KU9sky*`.-cRl!w -Y)WĖd9'ȣ_Ssmf'&b`ߩ-miQrB ֭Ym ohK&fV@ޥϦWU *<1FRrXȦq "Idd݄NsRxќKE734 #/U#Xy)Wjn"R 1:cu3vf͐㙶\YNep6bɸe)͐&)™Cv[d0ݳ ۙ1[oVlhMd?7}nv<}SBiosΟJVdh}S:F\K1 U> vNy'+E=-.]"31b`|dXWMcJn)M0DeBލQqW idg\Pf!" >ڽ_i{~O/0KCa( Q'6mV73YlF5 3MMe(Gֳy\bbbefgcM%7ӒjMoX#&^*$*[