selinux-policy-mls-3.13.1-23.el7_1.18$>/N_ɊɌu;&>A= ?<d ( @lp   @H`H H H H i(H jHoHvH||H H / (89:&=b>jBrGHH HIHXY$Z`[d\hH]H^& b'+d'e'f'l't'Hu-Hv2$w2Hx7H<Cselinux-policy-mls3.13.123.el7_1.18SELinux mls base policySELinux Reference policy mls base module.Uworker1.bsys.centos.orgy&CentOSGPLv2+CentOS BuildSystem System Environment/Basehttp://oss.tresys.com/repos/refpolicy/linuxnoarch if [ $1 -ne 1 ] && [ -s /etc/selinux/config ]; then . /etc/selinux/config; FILE_CONTEXT=/etc/selinux/mls/contexts/files/file_contexts; if [ "${SELINUXTYPE}" = mls -a -f ${FILE_CONTEXT} ]; then [ -f ${FILE_CONTEXT}.pre ] || cp -f ${FILE_CONTEXT} ${FILE_CONTEXT}.pre; fi; touch /etc/selinux/mls/.rebuild; if [ -e /etc/selinux/mls/.policy.sha512 ]; then POLICY_FILE=`ls /etc/selinux/mls/policy/policy.* | sort | head -1` sha512=`sha512sum $POLICY_FILE | cut -d ' ' -f 1`; checksha512=`cat /etc/selinux/mls/.policy.sha512`; if [ "$sha512" == "$checksha512" ] ; then rm /etc/selinux/mls/.rebuild; fi; fi; fi; . /etc/selinux/config; (cd /etc/selinux/mls/modules/active/modules; rm -f vbetool.pp l2tpd.pp shutdown.pp amavis.pp clamav.pp gnomeclock.pp nsplugin.pp matahari.pp xfs.pp kudzu.pp kerneloops.pp execmem.pp openoffice.pp ada.pp tzdata.pp hal.pp hotplug.pp howl.pp java.pp mono.pp moilscanner.pp gamin.pp audio_entropy.pp audioentropy.pp iscsid.pp polkit_auth.pp polkit.pp rtkit_daemon.pp ModemManager.pp telepathysofiasip.pp ethereal.pp passanger.pp qemu.pp qpidd.pp pyzor.pp razor.pp pki-selinux.pp phpfpm.pp consoletype.pp ctdbd.pp fcoemon.pp isnsd.pp rgmanager.pp corosync.pp aisexec.pp pacemaker.pp pkcsslotd.pp smstools.pp ) if [ -e /etc/selinux/mls/.rebuild ]; then rm /etc/selinux/mls/.rebuild; /usr/sbin/semodule -B -n -s mls; fi; [ "${SELINUXTYPE}" == "mls" ] && selinuxenabled && load_policy; if [ $1 -eq 1 ]; then /sbin/restorecon -R /root /var/log /run 2> /dev/null; else . /etc/selinux/config; FILE_CONTEXT=/etc/selinux/mls/contexts/files/file_contexts; /usr/sbin/selinuxenabled; if [ $? = 0 -a "${SELINUXTYPE}" = mls -a -f ${FILE_CONTEXT}.pre ]; then /sbin/fixfiles -C ${FILE_CONTEXT}.pre restore 2> /dev/null; rm -f ${FILE_CONTEXT}.pre; fi; if /sbin/restorecon -e /run/media -R /root /var/log /var/run /etc/passwd* /etc/group* /etc/*shadow* 2> /dev/null;then continue; fi; if /sbin/restorecon -R /home/*/.config 2> /dev/null;then continue; fi;fi; rn.E{+M!w93F h .E-0"!(b D"@'W+-_+-!3>j'#$-#00L--Y]# #/$| o Q.c !?0"!x  &'! >ID>*A%&!,0'-9#i/-,"8'"F7r0,$$S) (E#1)G;&=6`-#o.#@^*&&!mM^#n+8 8HCn2 )j# ''$1"p6/DI/-|$"#, $X6!D> +-%W#r!''Q""L+(&E"%s $5: "=G#'^h:$2"+&1'(I$/Rp*/o%gD!Re,Di\R0 FTiA큤A큤A큤A큤AAAAA큤A큤U}U}UeU}UeUeUdUdUdU}U|U}U|U}U|U}UeUeUeUdUeUeUeUeUeUdUeUeUeUeUeUeUeUeUeUeUeU}U}UmU|U{UmU|UmUmU{U{UmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmUmU{UmU}UmU{UmU{UmUeUeU|U|UeU|U}U}U}U}U}29f5d9edfa4bc035be05f221cc3e3f50f4558c16dcc74d4b0d5086b9415cc01563987940a453030e854f32858c6f53821220b7a83e5d18fb95b65ecd769fadb5db85a973259a48f811edf199b81341d353d89b2aefb08a309125ee481ed4311c33115c8ae83b6d571d45099e1758b571209e2808eed26389ffc50c1d5409cb37395a73444302f482186f17116e4a3d1f0a581812d378ef2ee137645a98b302b58583ca57f622a7ef83c25b1234a40fe8ac5e89cba4e75b8f20da4f206c830a485f8015d0c273021c83e476a651a54a36f573ab304002326a6640e5086ff3854cf546317025e1d452bd4dd475165ad4dc882f8013597263a9cc3b4efcb1e2cc13abdb83c1d154cbff8d4245b51c5d332f935a88c193c2c678007b0d0d80adc28d39894d51570a7817dd76b0d5d675ac59111237d07d9fc2836acec5a90896921d0ec6e51235876750d042e39cc8364c7abcaefaf5f18aff19f122135a5afa728be3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b85574bc7299f98c69bee7529bb0897d3676e63d7c3d848722ca2efc800647ff9801e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855a66ae6451d1f6328fc9b7c28541d5411455ff46b8e6ff94bbd41ba25ebce75f408062b1ce71faab6f7a21a62b6cb71a88b275e7f36fad087d29fd7e0f121d13d971609daa9932c2f0e826de13adcdbaa781480568fdfd1d54bd4210cb021395176afe622fa2ab9e66f67ff50f9e3d9af768587fc9a04f367e370450e8faae0f9e1fa3269417ef83475c62ed5fd9477da3a3f0518b699b35ad6edfb8044ef4f46fff3b43ee849b3fafa25c955c2a41a117a40f1be695c422454a63d34c733f69a8be106a29ae1b25d53472d0462ed303f2371d9ad0f4454176d6e03aafc48fb43b76cc49f30816e6ec08a4bf3f48cab11f3c0c159624e8c3abe52b52f5e6816f0fb1bb1ce512ca5acb0a9503c2c79727397d5dd78ca9af8f301d60e380bda56548a65be07f02462f2662aa12ee06c66b2ef258b55c1e5f67d3d941d5d80b93e57a8d3e1dfff461432348068aab0ccde6d7828b2feb4d9eb5e3b2c6574823032133929be0ce570743da564f9f81c3d6057414a49ec472c1d5c28358ab180182ee1e4ec1d54e40350cf9259f0b2748f93dbb3c788313e5c3db0d059169f73314674eb80ca2251eb053f58a8c2e06fad328746b1fa8b17041d017fc57ff2949bb8dedb7a42138adbfc8d02f049e9b76055ff2b53e777253d5c13eecc746d0182a8e68ea4f8f6c4ba87ef70c525d4ca0df9ba4b0ece20cb8df147a667e0edbd0949c39c1deed896bdc0d0a9bed051729e06c75296cfe6249095f4067cc78f0a2a2d434762fa117dfad29fd5fbd5e51c562e237f9538204ffd1cc717e77c14e5dd6a281cb1366991953983ffe926559b3e61c8fed9992f52cecb45b79d8e2250c7cbe8255cbe0ae3ec01b56845b0d03a121e2f2eef1815b019731507a6f19fa140f148f546317025e1d452bd4dd475165ad4dc882f8013597263a9cc3b4efcb1e2cc13e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b85539894d51570a7817dd76b0d5d675ac59111237d07d9fc2836acec5a90896921de3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855735c7c6602466756912f007f27d5039250281c56b5e57a6abb47fc8251c85daed5e3dd5f68aed9c698ac02541a23e7191e35533c978f352a998a66a8639b13847c7eaf832651e9b0109112cd8ca9868850c8b53ec222b224b8e004b46d84c7bcc99dbcbb72a986f8db3443078ca6cb5668f1ffccf045edd6cade89232dc936a23c24d441bb84c2be0c2f7c9a9250f1c8a90701479d8a70395304d4a0997420c938eee9794076ea3aa8de99d424da2810bc48c58da556651fabedd4585d921e32b6e3468a048c8b58b38822f6b39fee77980b10b72bdf2893838b173ea18adbf238a0bed0ca437b3f0269961ac837ce3e44b08d7871830dbd84dfff6c2d0b9a9307ea5395ee81803f0f0f14a31e2a543a36b96901634528cbcadb228aaea21fa203c97c8ccf50ec20a7647df907811683f52759121eafad6adaed63cc66aa1274d134f772c43486ceb233dcae5d0aecf8a9ec6b414093686b38d23a1f424eac0b6c8cbb4096e4daa7a65c253408ee662534e1be78f9493d66086727c9c5adc4e20ce9cec29cf7e5d1d0e7a408702400ce90a74fefe2ded74504e6a45cf429137e60c35493d8afcb3025fe85af9851c1e3567b60b57e778ffbf90422777d641910cad97e0255655bfdd805b59e2e88b25780cbd050b30621441bcedb7ce322ea882609e27d15954f99b3ae52c0958a0aa8e789e85f99013564e4705b48734e43c55ebb7293555623023112230c37f730c2c1b38018e9fd953d1bef764a0b6c741a7749a0908944fae4509b398c213f7fe905daf3ec3dcd2f51586874b006afa24119a18fdfadbb3a0056d972773a41fe1066fe6aa6b98cb583fc03225f989c714b690c4abc037ee866342d2e404209a9e757a0151b123918a3ad79ef574819a2916fc872324a1a11dde3232f47f52dcd648b9a67ac3653718ba042891e6f1a79243764302169de35dcb5e52897582adc78e8aaa640a74ec66125c4f6eb6313f5ed2ffc682e0b4d713574216793a05d729de7be2c273669747c90d378b8ed6a996aa6c2d1a156f3041913da6e07b54f40511aa67f7dc93f9ed77b6afc7b7a05c9587d78f1901af3a95a2fe0f7bc7cc884f499a466631313cf7789aa5cfa439488ae45c0c5aefa648388e9888426686c1ae761bc537bc6f111fabd615ce5a975c50496e8e78a8a7479f700ce733aa54a29305fd91169a338365d50b871f8f625b6e519414416e5f4d8a889f3349080933517920e98b9f648d6812b3a1d8b823e436bfe6f52dd1d3483df55d51a31fbb18c760549b84b8502044cfc24e39d010db32d3ebc27fcabe7f5553a28879b1fbccce80d70e06c21072d3d6f1bf383a5f8494b2b0eab92c2ff8f8ccb580ff09faf1c02b973d9b4a312d9d3eee1b89ec4c8473dba7c151c9916d3ba2bab5a12a416a3384776c31b592178d1624e77a5b05500004fe0425c14f4e9325f263ad1fc71454f3c8727010610e43067f0508ca0d4a36b355a9d0e91efd569f660357ef93ce3fedcd37f9dc3555bb12abaa01bf0aefe49dc3ebe237705bfb25a6a5c4010b6bad802ec9e9cdaf27c2fba1106063a78c41d8d30abe73f073172abc1719fd59d37d271fc926e4075f1b74cb616868054d2eaa462b22fe4b5cf31422667b6abc5c3c82d8ae6a708d6c44764007ab6273862c7c9172d2af60988d1bbf4eef62843d1ac0a404728533e28259f1adf4083fff86496cb5a973a778f02ab48844dcd9449107ad7d8cfd04d4904f45613041ef9c5252b0b02d0eaf8bb00fa21942a17ec506346c135c593fbc5669fcd2987f937afa383007d596875b44626ef0a6e994be51a4936921737ee3bb432c83ab0700c76046bfd8df38bfc7783fe53c7111988ca4509edbd11eac4420ec4418b61255a3bc74b23c20cac152d34b1ecc9be4a03281d7732f6f8fdfac4aab826e5ae7846c1916710307224dbf4d920df29104d11529e437aadc3febc2f008630c20aa5b485e389a982528a052e2b365fb305312ed6dedde80be908fda8c6f044346b80f303556700fab9566bf991aa51faebbfd1c8bdec8b95f6d419f1a80e0271eeeb60a4249cffb98eadf3cf963b56a4d0d9ef909725aab5a7596c4462f892d5964b8c6b00fa6cd94566789f8c6de037b6b0dcd4c7efa7a11c3571de9f8a11582862242c238b1bf2702dd05b005968d5a119511f0dd1f8209efe5ed757e83325ca2a179f4178129ef2946249f9708d7c66239552c42c4d94f9d5c513475373690202951d28998681860ec7f506c4c2d3228aa2aad85a02185c514e988bb5bca15b119c78e08da3ece4623eb24b34bf87d63329d9e062f8df4e511d6a3b92b47d30e0fdc93ac84bc2b0a4e267700960e68ad63444ecde958c0a0d2a78c356d57af266b05d54a9e15ce9712c01c98900d4a25ee7ee0cbfe9631e0ea06ab276da2206f47c1fe1ec424f34b5f319c2a028940ed29ff1abf9fbc29424592be93605db9a8282a563abe9d6c7b7826f53722191fba584c102afed0416e3237d5f2f356c316df46593d06f6a73bafa3e721c371257d1517c422cef4cc971e4b1ce2e911c9a0455a3d06a3cc5957637a3eb1b07d538515be3f0dbf5c1c31e783396fb44689176a6392f673c94b7ae0daa1c54b3a99472afca7690bddab47e1edfabc68da87835ba71304827e9f9f1315c9e70fbe7500bf3a1393312d560062511e3574143fe9600715176988eff99c1f79029f684c39d0361392c5b0fce743f4817dd675eae3e29db5972ff2efddb45d8b38b7c82a0be69ec510d172916765118dcbaa7572868470eb87eba81a62de3feb10a70e9c81835756d0fbacf8b23fcc4b2a8de9d45e2e21e3099851dec03a5bb0e023b39f8f02640c075a1983b334f71e6ae1d3860712a575cbe0ef81a068c7e007a18263cb9cf9a2a2aabcc11747a38a6535421871f63da7697a2429dac753caf3a94326f5eb12e2be632365ad3d1ee2f0f2314598485795d628d14c8816694a0c613f71607931f5d8dc159fab83954ac8176dd33c7f55829df22d6c5a3ab2c0661d459dea9b76e0a1fbafdbe14731a01e22f57c7d617453ea797865ee99a5a80ffbc4fa8afab89109d68434c0732c943fd0ab70e613d92f9f4a9c7fec68c15b3b462fbab5c89e80580b43054eeb036ff89f2c97fc659c687ac6fd31d1bc1d2fa45fc475aaf2314c13fc59312596fbbfd2bf303b36c7fd7af83f773d183ef1be63aa2d2d4e19dcf1585413d5c7b96a3964c481c3c1c0fa6c7ff43fc5b83dccc5bbc3284de529aadbce9a41aeee202327d73e0418d653930c6cffca5e5f9800fef83f7f3e02d08b38c7830b679c63871828c0cdf3615a053608310f5fc31643ff4a0a5251918d6470a3e713aa2f6cc1b2619872df1457603a0a267e82c9b292210c13ae4d08a9be0f3d49e2fcc3c517fc371abee2c71d5b993e05ac247f3544f869f67637b3f3d40beb563db68bf3275d0a14a8d80211e04ce86b064f6cea2664dab89db06a1b9cbb4e0034f22de353c84b867b0cdd4b1a2fa876fa8683aa357ceb01ab1bf10b1f9e03aab0d033ae07ac11acc2a0ce8f6d6b18d797a882ecf56f43bda402be695d457e7327fb529527c0fc8d294714765187f94f29319dc5e84c41698a4e453a9696640deb0f01a1ccea731a21009ff531b3b4c590842b39ce330f6421b4ef70be0ff6fdf909a0b917844228e056717e38a1c964f04b44337d7a45f38a13b69a4a5d53cfb631ef07341abdeb0f869adb62c5ed8489e90accc2b0b4c80c859be1a851c4db82e7aa42aff4f493da187a6de0ecaf0788d93c9bd3a0b8dd4b4ab5acbb1bf747e6d938aa6c2b58be0feb80e8b26f29bd984b910f92360e2240ddbd339fd39a05c4fcbc1b20b3d343576e0143b5f0ad57b83ad17b79ffe04ca2761edcb74eb60c64d7a81eed3d82eec14c0584801e5ccbf20f9637fca7118bb1e159757cc6baf15fe5fcd542b1643fa6cccacee7df5f7fafeff26ff9039ac45eda7c65b171334324538345638ce8658ab7571d8f9cd64d6b079fafb3c4bb4ca3ef96f5220ea9df6127b6d2fc4948fabce98703378704ce4d16d56abdeb898b2371e9774d25c64aeac580fe47031f2d51f6990d01b9a49a9d0d2b0e5442f4c16172371a9b4f7e4dc0e0a9845c9a1efde1ca2b27cdbb09474e0d6284197a51721da428528ae247be9b1a43358e353ef3a3feaac73818bd1e73f6c132f9f60fcb500244e120e3720bcb82d07e0d9b8ecc3440a40d5f78d37f364a9dd75c18f90972678e6fcd89309191bd5ce2478815be0859be97b393d018cb7963226cdf7b2b2e4535fcf37415cf81854d0a4284555539611ccfc79441dcd4147fe5bc3424cdd5aec8b61a91c7cbbb7002b4036c31d0ba1a979b1b37fbcc7c60be9230d0df25fda0aa6bbc0d447529c4f99f625e781618bb172a37e6dd38b448dfb03582215ac24943c286ebc814162fb2ea86ed9837537aa2e4c939620346244fb7e16fb0858d436985b8f9294f96e17ede2c583ad9dfa275a4e35ee1285dbf40113725cacb0ccd5b314c74beec7d95f9a350ca6dd1a0c0f40d8d792e37bf3bbfa1d834f89c4a08f3d2e0e49b990291d981977e5406f4156a146fc6888ccf2a71c5738c578f3b93fc00586ddf9a160291c0f4394c5254aed39471b148028c97f7659981b9177968fe12aed8d35395efc779149d9bfbc87d0cd7a4094fde46adb5422caad001a5d3795e6a42aa32b875b72180d10d3878f749e986204c8aa226692bb4e9605315c74ef3ca723d0d917289098d98fa07c5fced0a95274f8b62c5881f6b71a4e8df26e4ba4fbd7e02d3df62762619b72912f33285fa27fb34777c59b0b056c871f9199f03d45d568d9cb0ad97447f7885878076f4f0787f9234cd23436189f2909efca5ccdc2287bbda2a273f8ee78e2eff6f8788190daf8701f52e9c200c738154db8c616622b471832a2a53f9980ddeb5c2a6e532924cb2e2a1a27871eb52691536bb1acfad77e2ac0683ae5975736b78d274fffebb448c03ccbe4eef0cfa8c1e9deeed361d446c263e351dff2440911e14646ef29741a50a3c5882a87d10abe38de34ad661c2a3e17b65f839acb115355f4c160f20cd86fa6cf8b7751251c25fbd25f1932a39e1cbf11d66f120a9510dedb4b697f8eaa4240a85edb40b6f52d669d55e0bf4e10a227fd00d8bb763b1b5671da78d2c788beb06228198f3e6c35e6bf3d0137b9a7e23856bade8d98f27b8c41d54ff7197aadf0d51b1dd290a4c5b5b5e0f729bf2e0a6eeed0f8def5a9ba95cdc064a911bf49f45a32aa42e20cd1335d89b5711c8013aa5ec8adebca39b23c4053e228ec7bdf6f0897463f426cbe9fd025d7f3124f207f389faf8dbb4ba5da89af9081065630e049a3a6d6690f05ea8beca5c10c6dedfb930276e0998aa62bce89fa4e5027f2b19049a131cf17baf5f00e8cec3ace4cb67ef98322c7d759e2625957f0b6b829b0d353b179feded9404571ce2ab700ec13b5b218f2a33ee59afcda3a3d74a4dbf19657f1df5859a8d45fada3e1532f4e4162466d919a4a7eb0c051f284bc5e996da4860846013ff4a14a61fba92d04fc65a9d203362fe90ea624fec819d1779a845382acd27cab9a23945733f5e19ecb09426bf7b5c919803a583c6538aaf23187c83ac19b2a5079117b0a4c8fd445d5d3cfea8bc745c203e31ba1e73c07e32ea9e8dc9280d86dfccd3773d666a3d9b483a92a66eabf9b74f81e71b7b9db490a0c3569a9ba72743eceb85b0baf5ce79e872339949a92b974a5527e3a54ef3a812980dde79b210f281432c612c695b319733b35cdb14af0c9ab18c7efe35b8c71db7093e9bb2addeb3439f60cbbcea69bfaa153cb2d6d0f048e7efbb7d6cab90f9a5bfdb0f4ebf27061866be2ee89999af3b8013daad042f5d4f0eeb821d7d00d2007a60148d89b86235d89eb14f48c3cb9f0620c92ea1a094d2eb8e54abc9c80e27d2e43580a5dd5d11cd08a41154a7199c5da8cc6b39b5f9b5e2ccd71634c70291e53f4d6b7a1e9044dc242f4ecd1b1a398e3a2cd9c53e72c88fd31648a5ffc1a1921051f5e8fd49a33e37079766202fd3d19cd0a19e8e685403ea1f72c35903f033d563585ba32577e2e3f9a69ee5589091e8b049e7665584f72a23b83debfb029d78f4ce10c93c9b1248867f11e6c79502cfc25270ad6c56c54423220151b4a2999b95565e2d34f14bc6af274901705b1993c102544557455c2ed55486eda673666fcc24f10dae6c038b6614ff7c0262f001c77d884805cd8a8b3b56bbda94f219cd3d265e8980dbf2860852f3d396dde11df04607d9fc8f61fa45d72a3fa54e8c4625516148e5cce8ac58b442bb38823991b0d3cf39e5ebff1759351504b7a0ca244b3d22b41523eca2a45cbd73580b78acccf9a60abcc5ff527110c05282419683db272ac3cb8c305ee510fc4d4079ea0b5fe479bf174bb0f6199406fe996d8b288fe834d287fdbc0d2ede03b2446fe02bff93fc50982ef93e9d717b2182697cc1ebb2a0153c1bbc241625c1d7f45beeeef649cc7f9d5b1430bb47a45adf8f332d8bdc111e9597b436ad18e5b2e85f173787c8d5fcf848f56e9157da48c9cffce65c8953fb120d0c8e311f6e1cf03f2faeece8383da79b6986bcfa33199d8f09f2d409f6d40a98c1cbb47650a82e7f6836f54a64777e7aa5e00434d54d5bb31138fadd5cada89f41cb7d9d653fc98367d9fb93587a4186b9c296bfa62f3c182eeb5d31aa4b73cc0d240084832279b7c39507dbcff7846320e5c270a2f6220270579f4d18923102ad8cc4ab4fba210c47b9c2dbaa2c1403c33c7ce8c0f857c9d5a169de9355a63c0bd465da61e5f44a0dd83108c5867f2dac49978abc0d4c2a34045313a50e6b99cd72af82b1426f154b1004a7b135525cd77b2161a9dfccd0470613b236bfc31b86ab7adb78c25955417c46e059edad4320a0ca382e9d1211dce484c2599e1e82d3c11db7f168ee522af35d088f8c20d13e44d128fa84e98fe34e6b79ad19fb5f522d35e3babda90130a2cdb1e27560954659d03e4e504401552d81ceebceff54383dc57d7a3ff3af24297d2ab24a7691a40450aa462a82de939388f7c1e1d031b5a77d9c69d20b99758ec7d3b6a9ebd9889b069c97c744cd339d1f766837eb3d68367ef25189a14a92124f1c3f82fd8adc637bf4dd153717c53294da6dbe95346531f3b115f360ac924abdcc7a0688241379614b61f16b1d2db1e1431b4a46c81c5bd60c7d6f7934e051d99bb561d9494af3b729d88fb5ecee56433ac1ede8f880fbdb43eb88e492285efff9a728826ff987d05962e1eaee9cce120650cfb402582fd60c8026cb65f8a2d56e87d5e4600ea5de0e04736b15fc4433f4ac67a6c47f6803e0c45268afb2604dd6787f547357544c4d9f3de33a5530cefc9ed87722652bbbae1121ab98921e47dc73fd2bec919d245a0da05d834d41a29214a3f5bfc933e1e139194e70dcc9abd55da24257dc1ff40438daba803e3ccb9236ce478ba45670d3f0304b7c7415579a5898349222b1aa68d90d417439975a72f03aa5da1c9f47e83cb4b8c9fe672722dc470ec21f21ad3db86989e02bef3da090a1be7c583b4f488df663cb70a10f56e979a8df33deef330c64265bec24bc6700388dc20d8d222a4591683c97442cee0743497c3382ecdee5415f88c3faa94172a27410a899907f64c7f97ab279a65922d03ff67217d2bc51fc2ef06b8dcf22da5af2b8dc2f74dd2fa82bf5831509fa65a48d685f18db0f99992df1a04db9d0ce04c6cb6ebc13087e0cd690ad345c729f2e8a42d73d039fc90b67bcae8f8a75309bbd08a0d9eacf7d54a899cc5c1a20d89704eaa4d5bdc4bfb9f2025a0d1a9cce883e6e6f3f9dfbac5b56b7429cc464ad8a1c39b4803ff0c3208ecc6c75a9ac53681a032ff017e7a798ef21d3e5ff452865164c672ec3f8280313d058d55fe5292064338426f0596524faead0fdbd85f8a092b503eb004a31d7eff502e62020a508f6a49f44bd18c2445028adff2343c70bdb1094abaa60fcd549cbe1aeda5e8a26833495bb9bf54baa529b939dce98382c6f5e38937789d7249a5fd4ede4fcb81b33ea65ddfa9ccf8db50ddc5dce0c469405c06809853f92b31913982b1918988a2c27b37bfced4b9207b3a5bc50d9ef960dbf30740fe4bc4d364323386e38405814879821a5994487d243a2f33e8cc143b7fdb86b310983461ff65610c33ef669a8a54e5b3d2c5d78e2d07285a86c20a1450b32863b9c45b8689ee7e83203938cb336a0ae36bc2a3caba17df8ab92768e486ceb2190d1b65556ae1b75e450c9307486aeed70fc0c953947cb04e8d14ca3eed798260b2e6eb519b7aa929f6ad946a09a6e7505ae3c1ce8dc3cb9cc25729419e49304f6a0419761fb9c7b677f64c6917750e014d1474c7a7bf972c6076a3b838bdb1f161a4000904fac9c45ffe6d81d562f9c2a5ea68a6ff85b718e1581fcced919047ffb70fd9f6a5581463831884c7a4bcaa2b74062b57500a9b3425a98ba7db4bca6bc3259f9725ed4f838ed4972514110597596f64676900118e3fc5f8f39b321cc791a257fcc87af059f04430e49d4ed2f053abf8d542fe9a08f97008c661f3253b518a6330b0e3af79a707d65e9e4398f096d4efa52a57735d0fdc538ac61c3101e1b114b05209607a0d25aa9d28bd3f4f0afc7ae71bb33ccab5eb7d903c34e0e152400fe19f94b76f4319e68859ea687382880989f02d9a853e0fa6a73f430e48cae907291d0b9ce8b73869bf40c2bbc102afe27024db874f8d1b4856d0d89e49795a4cafad5f074a4d9d934ab253fee325c0551d41e83d72f0df1a9dd7b887f0e12949962cdbcc057039cb298a7310465e50da6902e339b49f3ac7dcfc6f288c301f4f6e1073f8c6c6f6930c0458e7ff424ebd3ef160f25f24f5274a558ec7f54fcf149636d63e911bb6eb2ecb408018afc13eea8b0cc82af2cc3716a8e37f380615bb8436526a5d9b3512b5a749cd019e40aae6e4a92d199aaf9a90a431be2a87599375e1a684ce492debc3b42acac80b4110eeffb715cc721e31ad1816e1e3d6c8640b986692a15d48c8e6e626828ed08388e1f4017c8401fbf387dc0d52bacfcf6aa4888d1929032d67a77d6cdca51510c11c74f35bb8d48b95b6c27a05f22e57b9b051f100939791839144241221cb5fd319c2786ac7493cb7c9286b60ab82077f3f6519e4d369f6ecb177e6d0aa49b4dd59c4db6b842d1fa8f82e02c25768f46bd0b05761c00a521ad32a16d2f01aade24448ec4535370c8e9f430c46512ced826351d3f332621972de730a98916c2a228ddf7ca70fb8287dea98f4074caee4ebdc93fca7dd589dd16091599f323c870bfedb2c5131189e345deb93e5afa2911e73ed904bbc868628f5518dfa54d493246d4a9630b3a25f8dd0d54f1c726dd2d445bfd4496aca4d5c69c66dfc70c781aab489067b5dab7da717a9f04661c1d7ef03f344aaa23b9c11b50c1fcdf9fe0fbca938e89a8da8c53a4af46753fcd1f38a537d2d31a70c35cb29e54fd1a5722a0b3a91ef09d12cb78fb413df245a907964e15a8508637af8deaede10c28fd77de0a247426cd4f61858895d00cdefadfa71ca86a973293f6b7ab5f3b4258b87c103bad7b58b92101b3ff3201738a055520c55733becec8708c11cd0187fc6d3e166c1a48669d3773d06024847666bc93232ee71fd22a21763794985fab88b4fa375759bff91bb6e2b372d47653dd3a7029369baf390b0b87f6208cd1bc9d6a3a372d76de214f9263291ea5f060b2770e402e93cde6c5ece392d5315aad2b66b0bf95664c0dd62f8e39684f223aa5b07e2d6ec4d08c20c1fafa5d351fd5d283b6aaed483c0fcdbc660da4119de17cc9ac10b5753f9ed8b7ecd0799cbc24e3d70dc39317c5e938b26ae12f85a24a68d850da2c76481bd8955755fb28cb3773dae72ab1e53be524ab7481103b72bc6db26c5130f13db6cadf0f04e6df8fe6be24ed797c620f4a027be2cfd998338e16c0f06c82f032b454cc32123a1a48b61f0da1781eb25aa44e12377f66b41cfef66932a4ce246b67138e62091e2aef41d490f5aa15596b4e4a8ff214f541d5b62a2c883a216986f4c52cbf8fddd02b965c352cd8a276325968edb44c479f0d27415288c60f27a9492b24896dc2f6f72d69937563d47ef2a783f06be0f354fd55d4d9c09988323a16fc342e75b9d29634229a846e0b6ec8055325ebeed2868895dcbc6ebdefaa424702774b0e24570503322d5037b0d32946a55b8aacf667cc93924e10268a284b6475a65cba1b147ac1083b0bd24e3cfbcfe0dbe801b4e33991b6baacf0d60dc571b02273d459aea9a8500eccdd2f7f927a6b8bf8098b1e399c95c8ac05360999c32c4f7ffd5db7c1a06e14dc4625c7868b65837a54ccfc97a51e17ad261e314f2a330e3258c7ceb8f2754a3fb85c31be2fc86b4821ed8a8dbbaa3e9a19da7a3496e32d45eed9a310caae8431e5b841b8967d0f059ec68ddf04ea9f78b9962205e4a98ccbd149abd0e7595d65bbb3a9440769c6509e3771a510fa6adb11b786e3eca7899bebd37bda2df96bfefd06e92115fab96b2f7192230456a3380a91fe1ec913609b32be4f8c1c73f0ec1e18f69d4a473d0458d0363f66a56eb9eacb96e4719f28f37dad17b0eacfd313558ba088c1f313c2daf319ada9ab3c5e65266137fe9b3888b7386928258aab12ca181db63737e0ef6544c4b5c80aa23314e8816d7bd3dc926c454778529fc2a72b6c5c341ed7cbd5d7e6fc3a0d70d8a39f05a8fbcdf353ae241de01b073d776d2552c4a9840d8360cae97e2fb565880e42358879734c8d9a82661223c57b8ac8a74122efa7485c2ee21bf9228453435b5e2ee00fc6478b5f7cd148fe12f692dfcfe8c918fc69263cc0d3e8f510be88513f5e64d559f7b6191905586a7e157fd48228e5ff9051de358e6452c08923c6081237bf99eec9893c61243e0a250af8c4259dcef41a576a5d4cd0f4cad70fa3d3fef3da658869283e3241301fe80d547a10c80d5fb8c35a77d4aaa39a6c9d498f3408b22eb90a09a7390b292b7c674d0a270b2b4553b2dfb11c0c0d7e3d84bab7fae39c2d6a95822fbb2a0c48156d159f8b08541695c65a870b0433c34236ac763f3325931d4f9428a3f13222fae6e153bf43c115caf088681a268f612d4a8a168b14c60cc295103025cbcc1438bb17564b4d08e2c96ce55275cba1035ee01836c133e5445cfde0f4dabefdce026e3f43c332656ba719dc017019aaaaed9e21140af6d4982dcb0e248a7300d9de7b959a048e25d2d4d29d5d8eeba4874c9333df4819454b679daffe9e2a2b782abcc6258eb6077bad50ff25ccbbfea46b3a548670cfc44e2adb2679f89ced65837c596aed7dc260cb3c9354ff7ad2f2e6c829f1a50d51e7c2e4927075052961dbb211ed17a40e4e1ccaa7dd2237658ef8f0096389a6583f68b48573bffdcf6c71551d5a0e73ed6fd7d1ab9302acd689d08e7c9ac393fbb1e93ff8bc8afa00441e908d7a04df4795899da0351fba82f157e447db255fc32eb92959b2551b3eb5643880a47e53b166a8cda02938060c2abe4f417fe5e312ad32067d6f88e05a8a5d793b7d60eca7b2bdaf8ad8f57ee7337f55a18e4e9332b954b2025e6648597cc89b40bbc77a34fcd5a68249421cf296a1bd068d4f85f04f1a477e3e599a46bf7f8ae066235daa86d05a868ff5f52a4262b3bd826c823c4920bb80a71f35a9f44a44d9bf84acb7b1d9342a30a481bb550d931feaab9ae52021b5ebb026979ccde66304172cb4ccb37c3427de14a9710adf14887e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8556c7f0f051743fc90720f1debfa124e42c4a3cea7f388e87dc69803ba67b781d9e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8557336e4cf97adf5f0114759176842596133e86e735d249d5151f04b5fc35b289ce3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855972bb1d8c688318d411dba94d461c9df5ca52c2ca49621b7977a523f8c3398312ff2b0781a1c48c48e1a8b0bfa06d6081e1e8ef0551f668b52a71119735ea1a36c7f0f051743fc90720f1debfa124e42c4a3cea7f388e87dc69803ba67b781d9c099f1d79f67a324eab7f4e122cac8a93371951f499df7f17a8f2e505450f53db84056f9b9a6ba38237ede153c7a04d6965a46412e7d5eefad759391114eb821f0081e7bf847e82a62ede05ceca13828a5e4a277cb326d6ad73eaa1f873afabfe62b93c8a5dba132edfbfee24fadc34da3a0e159c508869a529e31d74801d072/etc/selinux/mls/policy/policy.29@@@@@@@@@@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootselinux-policy-3.13.1-23.el7_1.18.src.rpmconfig(selinux-policy-mls)selinux-policy-baseselinux-policy-mls     /bin/sh/bin/shconfig(selinux-policy-mls)coreutilspolicycoreutilspolicycoreutils-newrolerpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)selinux-policyselinux-policysetransdrpmlib(PayloadIsXz)3.13.1-23.el7_1.182.1.14-742.1.14-743.0.4-14.6.0-14.0-13.13.1-23.el7_1.183.13.1-23.el7_1.185.2-1seedit4.11.1U6@UM@Uݪ@UoU@UnU4@UU@U@U~@U@U6;U%@U@U@U@U@Tr@T@T@T7TTTC@T@TTT}Tto@TsTk4T`T[bTWn@T?@T>aT6xT6xT@S@SSDSg}@SB@S>S;S:@S9XS5d@S4S2@S0@S,)S*@S)S)S&S&S"@S!S L@SSS@SSc@SSnS @S SK@RRR@RRJ@Ra@RRR&R&RRR=RʚRR@R@R@Rv@Rv@R@RR@R R@R@R|@Rz/@Rz/@RsRpRnQRi RfhR_@R_@R[R[RSRNRNRL RIgRB@RB@R:@R1R-@R-@R(r@R' R%@R7RRNRR@Q@QQdQQ@QQޞ@Q@QکQکQ@QzQQ4Q@@Q@QKQQ@Q@Q@Q@QQ@QQQQ@Q@QQQ@Qzl@Qw@QvwQo@Qo@QnQm=@QkQfQb@Q`@Q^QZ@QQQIQGQ@j@Q9Q8@Q4Q0@Q-@Q& @Q$QQ@QQ@Q @Qh@QsPP@P@PP@P[PP!@P8@PO@P @Pf@PPqP @PP7@P@PPPYP@P@PPPM@PPd@P@PoP{@P{@P@PP5@P@P~P}L@Px@PvPvPuc@Puc@Pr@Pmz@Pmz@Pmz@Pj@Pd?Pd?Pb@PaPaP[@PXb@PWPS@PQPO'PM@PIP@@P>@P8@P7lP2&P2&P,P,P*=P(@P#@P#@P!@P!@P@PkPw@Pw@PP

@NNU@NNl@N@N@NåN@NNNN@NNN@N@NGNGNGN@N@NNS@NS@N^N^N @N @NNj@Nj@NN$@NN@N/N@N@NFNFN@NNN@N@N@N]Ni@Ni@Ni@N|tNyNx@Ns:@NoENoENiNf @N^"@N\N[@NTNS@NS@NC@NBrN:N98@N7N6@N2N.@N*N)f@N(N%qN$ @N@N7@N e@NpNpM@M@Md@Md@MM{@M@M۝M@M@M‘@M@M@M@My@My@M3@M@M@MMM@MMMMTMx@Mx@Mv@MlMbSM[@MRMQ0@MQ0@MJMGMGMA^@M>@M9u@M6@M5M4/@M4/@M0:M,F@M$]@M@M9MMMMM\@M M M@L!L!L@LL@L@L@LOLOL[@L@L@Lr@L L,@L,@Lډ@L7LLLNL@LΫLeL|L@LB@LB@LB@L@LMLL@LdLL{L*@L@L5LLA@LLLL@LcL@L@L@LzL)@L|L|L|L{@LvW@LvW@Ls@Ls@LrbLrbLmLk@LjyLe3Lc@La?@LZLYV@LXLN@LN@LMxLMxLI@LH2LF@LEL=L=L=L;L7@L LT@L@LL@L@L0LLGL@K^K^KKKj@K$@KKK@K@KK@K]K޺K@KtK#@KKՀ@K:@KK͗@KŮ@K\K\K @KKKKK9@KK@KK@K@KKKKrKK~@K,K,K,K@KK8@KKK@KK@KqKqK}+K{@K{@KuBKs@KqN@KjKie@Kf@Ka|@K`*K]KXAKTM@KPXKEKEKEKD{@KC)KA@K;@K2@K0K/c@K+nK*@K(K"4@KK>K>K>JJęJH@JH@JJJ_@J@JjJjJ@Jv@Jv@Jv@Jv@J$J@JJ0@J@J@JG@JG@J@JJ@J@J@JJJ#J@JJJ@J:J@JJQJ@J J J|@JzJyt@Jyt@Jx"JrJrJq@Jn@Jn@JmJhPJeJ\s@JW-@JT@JS8JKOJI@JCfJCfJB@J@J@J?r@J<@J;}J:,@J7@J67J2C@J0J/@J,@J%@JJB@JJMJ J dJ@J@JJ@J*@J*@II@IIA@IIII@I@IIIX@IX@IX@II@I@IcIIo@Io@IzI)@I@IܑI@@II@I@I@IԨIд@I̿In@I3I3I@II@I@IV@IIaIIm@I@I'@II2III@IIIIIIII@III@I1I@III~@I}Iy@Ix_Iw@IuItk@Itk@Io%@Ik0IeIcGIa@I`IVIO@IJ;@IHIAI>]I= @I7@I6tI3I-I@III9@I9@II IP@I@IIg@Ig@HHH@HrH~@H,H@HCHHH @H @Hf@Hf@H@H+H@H׈H׈H7@HBH@HǶH@HH|@HHH@H{@H)HHL@H@H@H@HnH}H|@Ht@HsVHr@Hl@HkmHgy@HcH`H_@H^>HRa@HQHQHO@HFHFH$@DX@DU@DN@DN@DLDH@DGwDGwDDD@@D?D?D;@D;@D:HD:HD2_D1@D1@D-D+@D+@D'D!<@D!<@D!<@DDD@D@D@DDDDDD@D@D@D@D uD $@D D @D @DDDFC@C@C@C@CCCCCR@CCCCC@Ci@CC@C@CtC@C@CC:@CECCC @C @CعCعCعCعCC@C-C-C-C@C@CCǖ@C@CáCáCP@CP@C[C @C @CCg@Cg@CCC!@C~@C,C@CCCCC@CC@C@C@CZCZC @C @CCCf@Cf@Cf@CC@CqCqC @C @C @CCC}@C7@C7@C7@CBCBCYC@C@CC}@CqCqMiroslav Grepl 3.13.1-23.el7_1.18Miroslav Grepl 3.13.1-23.el7_1.17Lukas Vrabec 3.13.1-23.el7_1.16Lukas Vrabec 3.13.1-23.el7_1.15Lukas Vrabec 3.13.1-23.el7_1.14Miroslav Grepl 3.13.1-23.el7_1.13Miroslav Grepl 3.13.1-23.el7_1.12Miroslav Grepl 3.13.1-23.el7_1.11Miroslav Grepl 3.13.1-23.el7_1.10Miroslav Grepl 3.13.1-23.el7_1.9Miroslav Grepl 3.13.1-23.el7_1.8Miroslav Grepl 3.13.1-23.el7_1.7Miroslav Grepl 3.13.1-23.el7_1.6Miroslav Grepl 3.13.1-23.el7_1.5Miroslav Grepl 3.13.1-23.el7_1.4Miroslav Grepl 3.13.1-23.el7_1.3Miroslav Grepl 3.13.1-23.el7_1.2Miroslav Grepl 3.13.1-23.el7_1.1Miroslav Grepl 3.13.1-23Miroslav Grepl 3.13.1-22Miroslav Grepl 3.13.1-21Miroslav Grepl 3.13.1-20Miroslav Grepl 3.13.1-19Miroslav Grepl 3.13.1-18Miroslav Grepl 3.13.1-17Miroslav Grepl 3.13.1-16Miroslav Grepl 3.13.1-15Miroslav Grepl 3.13.1-14Miroslav Grepl 3.13.1-13Miroslav Grepl 3.13.1-12Miroslav Grepl 3.13.1-11Miroslav Grepl 3.13.1-10Miroslav Grepl 3.13.1-9Miroslav Grepl 3.13.1-8Miroslav Grepl 3.13.1-7Miroslav Grepl 3.13.1-6Miroslav Grepl 3.13.1-5Miroslav Grepl 3.13.1-4Miroslav Grepl 3.13.1-3Miroslav Grepl 3.13.1-2Miroslav Grepl 3.13.1-1Miroslav Grepl 3.12.1-156Miroslav Grepl 3.12.1-155Miroslav Grepl 3.12.1-154Miroslav Grepl 3.12.1-153Miroslav Grepl 3.12.1-152Miroslav Grepl 3.12.1-151Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-148Miroslav Grepl 3.12.1-147Miroslav Grepl 3.12.1-146Miroslav Grepl 3.12.1-145Miroslav Grepl 3.12.1-144Lukas Vrabec 3.12.1-143Miroslav Grepl 3.12.1-142Miroslav Grepl 3.12.1-141Miroslav Grepl 3.12.1-140Miroslav Grepl 3.12.1-139Lukas Vrabec 3.12.1-138Miroslav Grepl 3.12.1-137Miroslav Grepl 3.12.1-136Miroslav Grepl 3.12.1-135Miroslav Grepl 3.12.1-134Miroslav Grepl 3.12.1-133Miroslav Grepl 3.12.1-132Miroslav Grepl 3.12.1-131Miroslav Grepl 3.12.1-130Miroslav Grepl 3.12.1-129Miroslav Grepl 3.12.1-128Miroslav Grepl 3.12.1-127Miroslav Grepl 3.12.1-126Miroslav Grepl 3.12.1-125Miroslav Grepl 3.12.1-124Miroslav Grepl 3.12.1-123Miroslav Grepl 3.12.1-122Miroslav Grepl 3.12.1-121Miroslav Grepl 3.12.1-120Miroslav Grepl 3.12.1-119Miroslav Grepl 3.12.1-118Miroslav Grepl 3.12.1-117Miroslav Grepl 3.12.1-116Miroslav Grepl 3.12.1-115Miroslav Grepl 3.12.1-114Miroslav Grepl 3.12.1-113Miroslav Grepl 3.12.1-112Miroslav Grepl 3.12.1-111Miroslav Grepl 3.12.1-110Miroslav Grepl 3.12.1-109Miroslav Grepl 3.12.1-108Miroslav Grepl 3.12.1-107Dan Walsh 3.12.1-106Miroslav Grepl 3.12.1-105Miroslav Grepl 3.12.1-104Miroslav Grepl 3.12.1-103Miroslav Grepl 3.12.1-102Miroslav Grepl 3.12.1-101Miroslav Grepl 3.12.1-100Miroslav Grepl 3.12.1-99Miroslav Grepl 3.12.1-98Miroslav Grepl 3.12.1-97Miroslav Grepl 3.12.1-96Miroslav Grepl 3.12.1-95Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-93Miroslav Grepl 3.12.1-92Miroslav Grepl 3.12.1-91Miroslav Grepl 3.12.1-90Miroslav Grepl 3.12.1-89Miroslav Grepl 3.12.1-88Miroslav Grepl 3.12.1-87Miroslav Grepl 3.12.1-86Miroslav Grepl 3.12.1-85Miroslav Grepl 3.12.1-84Miroslav Grepl 3.12.1-83Miroslav Grepl 3.12.1-82Miroslav Grepl 3.12.1-81Miroslav Grepl 3.12.1-80Miroslav Grepl 3.12.1-79Miroslav Grepl 3.12.1-78Miroslav Grepl 3.12.1-77Miroslav Grepl 3.12.1-76Miroslav Grepl 3.12.1-75Miroslav Grepl 3.12.1-74Miroslav Grepl 3.12.1-73Miroslav Grepl 3.12.1-72Miroslav Grepl 3.12.1-71Miroslav Grepl 3.12.1-70Miroslav Grepl 3.12.1-69Miroslav Grepl 3.12.1-68Miroslav Grepl 3.12.1-67Miroslav Grepl 3.12.1-66Miroslav Grepl 3.12.1-65Miroslav Grepl 3.12.1-64Miroslav Grepl 3.12.1-63Miroslav Grepl 3.12.1-62Miroslav Grepl 3.12.1-61Miroslav Grepl 3.12.1-60Miroslav Grepl 3.12.1-59Miroslav Grepl 3.12.1-58Miroslav Grepl 3.12.1-57Miroslav Grepl 3.12.1-56Miroslav Grepl 3.12.1-55Miroslav Grepl 3.12.1-54Miroslav Grepl 3.12.1-53Miroslav Grepl 3.12.1-52Miroslav Grepl 3.12.1-51Miroslav Grepl 3.12.1-50Miroslav Grepl 3.12.1-49Miroslav Grepl 3.12.1-48Miroslav Grepl 3.12.1-47Miroslav Grepl 3.12.1-46Miroslav Grepl 3.12.1-45Miroslav Grepl 3.12.1-44Miroslav Grepl 3.12.1-43Miroslav Grepl 3.12.1-42Miroslav Grepl 3.12.1-41Miroslav Grepl 3.12.1-40Miroslav Grepl 3.12.1-39Miroslav Grepl 3.12.1-38Miroslav Grepl 3.12.1-37Miroslav Grepl 3.12.1-36Miroslav Grepl 3.12.1-35Miroslav Grepl 3.12.1-34Miroslav Grepl 3.12.1-33Miroslav Grepl 3.12.1-32Miroslav Grepl 3.12.1-31Miroslav Grepl 3.12.1-30Miroslav Grepl 3.12.1-29Dan Walsh 3.12.1-28Dan Walsh 3.12.1-27Miroslav Grepl 3.12.1-26Miroslav Grepl 3.12.1-25Miroslav Grepl 3.12.1-24Miroslav Grepl 3.12.1-23Miroslav Grepl 3.12.1-22Miroslav Grepl 3.12.1-21Miroslav Grepl 3.12.1-20Miroslav Grepl 3.12.1-19Miroslav Grepl 3.12.1-18Miroslav Grepl 3.12.1-17Miroslav Grepl 3.12.1-16Miroslav Grepl 3.12.1-15Miroslav Grepl 3.12.1-14Miroslav Grepl 3.12.1-13Miroslav Grepl 3.12.1-12Miroslav Grepl 3.12.1-11Miroslav Grepl 3.12.1-10Miroslav Grepl 3.12.1-9Miroslav Grepl 3.12.1-8Miroslav Grepl 3.12.1-7Miroslav Grepl 3.12.1-6Miroslav Grepl 3.12.1-5Miroslav Grepl 3.12.1-4Miroslav Grepl 3.12.1-3Miroslav Grepl 3.12.1-2Miroslav Grepl 3.12.1-1Dan Walsh 3.11.1-69.1Miroslav Grepl 3.11.1-69Miroslav Grepl 3.11.1-68Miroslav Grepl 3.11.1-67Miroslav Grepl 3.11.1-66Miroslav Grepl 3.11.1-65Miroslav Grepl 3.11.1-64Miroslav Grepl 3.11.1-63Miroslav Grepl 3.11.1-62Miroslav Grepl 3.11.1-61Miroslav Grepl 3.11.1-60Miroslav Grepl 3.11.1-59Miroslav Grepl 3.11.1-58Miroslav Grepl 3.11.1-57Miroslav Grepl 3.11.1-56Miroslav Grepl 3.11.1-55Miroslav Grepl 3.11.1-54Miroslav Grepl 3.11.1-53Miroslav Grepl 3.11.1-52Miroslav Grepl 3.11.1-51Miroslav Grepl 3.11.1-50Miroslav Grepl 3.11.1-49Miroslav Grepl 3.11.1-48Miroslav Grepl 3.11.1-47Miroslav Grepl 3.11.1-46Miroslav Grepl 3.11.1-45Miroslav Grepl 3.11.1-44Miroslav Grepl 3.11.1-43Miroslav Grepl 3.11.1-42Miroslav Grepl 3.11.1-41Miroslav Grepl 3.11.1-40Miroslav Grepl 3.11.1-39Miroslav Grepl 3.11.1-38Miroslav Grepl 3.11.1-37Miroslav Grepl 3.11.1-36Miroslav Grepl 3.11.1-35Miroslav Grepl 3.11.1-34Miroslav Grepl 3.11.1-33Miroslav Grepl 3.11.1-32Miroslav Grepl 3.11.1-31Miroslav Grepl 3.11.1-30Miroslav Grepl 3.11.1-29Miroslav Grepl 3.11.1-28Miroslav Grepl 3.11.1-27Miroslav Grepl 3.11.1-26Miroslav Grepl 3.11.1-25Miroslav Grepl 3.11.1-24Miroslav Grepl 3.11.1-23Miroslav Grepl 3.11.1-22Miroslav Grepl 3.11.1-21Miroslav Grepl 3.11.1-20Miroslav Grepl 3.11.1-19Miroslav Grepl 3.11.1-18Miroslav Grepl 3.11.1-17Miroslav Grepl 3.11.1-16Dan Walsh 3.11.1-15Miroslav Grepl 3.11.1-14Dan Walsh 3.11.1-13Miroslav Grepl 3.11.1-12Miroslav Grepl 3.11.1-11Miroslav Grepl 3.11.1-10Dan Walsh 3.11.1-9Dan Walsh 3.11.1-8Dan Walsh 3.11.1-7Dan Walsh 3.11.1-6Miroslav Grepl 3.11.1-5Miroslav Grepl 3.11.1-4Miroslav Grepl 3.11.1-3Miroslav Grepl 3.11.1-2Miroslav Grepl 3.11.1-1Miroslav Grepl 3.11.1-0Miroslav Grepl 3.11.0-15Miroslav Grepl 3.11.0-14Miroslav Grepl 3.11.0-13Miroslav Grepl 3.11.0-12Fedora Release Engineering - 3.11.0-11Miroslav Grepl 3.11.0-10Miroslav Grepl 3.11.0-9Miroslav Grepl 3.11.0-8Miroslav Grepl 3.11.0-7Miroslav Grepl 3.11.0-6Miroslav Grepl 3.11.0-5Miroslav Grepl 3.11.0-4Miroslav Grepl 3.11.0-3Miroslav Grepl 3.11.0-2Miroslav Grepl 3.11.0-1Miroslav Grepl 3.10.0-128Miroslav Grepl 3.10.0-127Miroslav Grepl 3.10.0-126Miroslav Grepl 3.10.0-125Miroslav Grepl 3.10.0-124Miroslav Grepl 3.10.0-123Miroslav Grepl 3.10.0-122Miroslav Grepl 3.10.0-121Miroslav Grepl 3.10.0-120Miroslav Grepl 3.10.0-119Miroslav Grepl 3.10.0-118Miroslav Grepl 3.10.0-117Miroslav Grepl 3.10.0-116Miroslav Grepl 3.10.0-115Miroslav Grepl 3.10.0-114Miroslav Grepl 3.10.0-113Miroslav Grepl 3.10.0-112Miroslav Grepl 3.10.0-111Miroslav Grepl 3.10.0-110Miroslav Grepl 3.10.0-109Miroslav Grepl 3.10.0-108Miroslav Grepl 3.10.0-107Miroslav Grepl 3.10.0-106Miroslav Grepl 3.10.0-105Miroslav Grepl 3.10.0-104Miroslav Grepl 3.10.0-103Miroslav Grepl 3.10.0-102Miroslav Grepl 3.10.0-101Miroslav Grepl 3.10.0-100Miroslav Grepl 3.10.0-99Miroslav Grepl 3.10.0-98Miroslav Grepl 3.10.0-97Miroslav Grepl 3.10.0-96Miroslav Grepl 3.10.0-95Miroslav Grepl 3.10.0-94Miroslav Grepl 3.10.0-93Miroslav Grepl 3.10.0-92Miroslav Grepl 3.10.0-91Miroslav Grepl 3.10.0-90Miroslav Grepl 3.10.0-89Miroslav Grepl 3.10.0-88Miroslav Grepl 3.10.0-87Miroslav Grepl 3.10.0-86Miroslav Grepl 3.10.0-85Miroslav Grepl 3.10.0-84Miroslav Grepl 3.10.0-83Miroslav Grepl 3.10.0-82Dan Walsh 3.10.0-81.2Miroslav Grepl 3.10.0-81Miroslav Grepl 3.10.0-80Miroslav Grepl 3.10.0-79Miroslav Grepl 3.10.0-78Miroslav Grepl 3.10.0-77Miroslav Grepl 3.10.0-76Miroslav Grepl 3.10.0-75Dan Walsh 3.10.0-74.2Miroslav Grepl 3.10.0-74Miroslav Grepl 3.10.0-73Miroslav Grepl 3.10.0-72Miroslav Grepl 3.10.0-71Miroslav Grepl 3.10.0-70Miroslav Grepl 3.10.0-69Miroslav Grepl 3.10.0-68Miroslav Grepl 3.10.0-67Miroslav Grepl 3.10.0-66Miroslav Grepl 3.10.0-65Miroslav Grepl 3.10.0-64Miroslav Grepl 3.10.0-63Miroslav Grepl 3.10.0-59Miroslav Grepl 3.10.0-58Dan Walsh 3.10.0-57Dan Walsh 3.10.0-56Dan Walsh 3.10.0-55.2Dan Walsh 3.10.0-55.1Miroslav Grepl 3.10.0-55Dan Walsh 3.10.0-54.1Miroslav Grepl 3.10.0-54Dan Walsh 3.10.0-53.1Miroslav Grepl 3.10.0-53Miroslav Grepl 3.10.0-52Miroslav Grepl 3.10.0-51Dan Walsh 3.10.0-50.2Dan Walsh 3.10.0-50.1Miroslav Grepl 3.10.0-50Miroslav Grepl 3.10.0-49Miroslav Grepl 3.10.0-48Miroslav Grepl 3.10.0-47Dan Walsh 3.10.0-46.1Miroslav Grepl 3.10.0-46Dan Walsh 3.10.0-45.1Miroslav Grepl 3.10.0-45Miroslav Grepl 3.10.0-43Miroslav Grepl 3.10.0-42Miroslav Grepl 3.10.0-41Dan Walsh 3.10.0-40.2Miroslav Grepl 3.10.0-40Dan Walsh 3.10.0-39.3Dan Walsh 3.10.0-39.2Dan Walsh 3.10.0-39.1Miroslav Grepl 3.10.0-39Dan Walsh 3.10.0-38.1Miroslav Grepl 3.10.0-38Miroslav Grepl 3.10.0-37Dan Walsh 3.10.0-36.1Miroslav Grepl 3.10.0-36Dan Walsh 3.10.0-35Dan Walsh 3.10.0-34.7Dan Walsh 3.10.0-34.6Dan Walsh 3.10.0-34.4Miroslav Grepl 3.10.0-34.3Dan Walsh 3.10.0-34.2Dan Walsh 3.10.0-34.1Miroslav Grepl 3.10.0-34Miroslav Grepl 3.10.0-33Dan Walsh 3.10.0-31.1Miroslav Grepl 3.10.0-31Miroslav Grepl 3.10.0-29Miroslav Grepl 3.10.0-28Miroslav Grepl 3.10.0-27Miroslav Grepl 3.10.0-26Miroslav Grepl 3.10.0-25Miroslav Grepl 3.10.0-24Miroslav Grepl 3.10.0-23Miroslav Grepl 3.10.0-22Miroslav Grepl 3.10.0-21Dan Walsh 3.10.0-20Miroslav Grepl 3.10.0-19Miroslav Grepl 3.10.0-18Miroslav Grepl 3.10.0-17Miroslav Grepl 3.10.0-16Miroslav Grepl 3.10.0-14Miroslav Grepl 3.10.0-13Miroslav Grepl 3.10.0-12Miroslav Grepl 3.10.0-11Miroslav Grepl 3.10.0-10Miroslav Grepl 3.10.0-9Miroslav Grepl 3.10.0-8Miroslav Grepl 3.10.0-7Miroslav Grepl 3.10.0-6Miroslav Grepl 3.10.0-5Miroslav Grepl 3.10.0-4Miroslav Grepl 3.10.0-3Miroslav Grepl 3.10.0-2Miroslav Grepl 3.10.0-1Miroslav Grepl 3.9.16-30Dan Walsh 3.9.16-29.1Miroslav Grepl 3.9.16-29Dan Walsh 3.9.16-28.1Miroslav Grepl 3.9.16-27Miroslav Grepl 3.9.16-26Miroslav Grepl 3.9.16-25Miroslav Grepl 3.9.16-24Miroslav Grepl 3.9.16-23Miroslav Grepl 3.9.16-22Miroslav Grepl 3.9.16-21Miroslav Grepl 3.9.16-20Miroslav Grepl 3.9.16-19Miroslav Grepl 3.9.16-18Miroslav Grepl 3.9.16-17Dan Walsh 3.9.16-16.1Miroslav Grepl 3.9.16-16Miroslav Grepl 3.9.16-15Miroslav Grepl 3.9.16-14Miroslav Grepl 3.9.16-13Miroslav Grepl 3.9.16-12Miroslav Grepl 3.9.16-11Miroslav Grepl 3.9.16-10Miroslav Grepl 3.9.16-7Miroslav Grepl 3.9.16-6Miroslav Grepl 3.9.16-5Miroslav Grepl 3.9.16-4Miroslav Grepl 3.9.16-3Miroslav Grepl 3.9.16-2Miroslav Grepl 3.9.16-1Miroslav Grepl 3.9.15-5Miroslav Grepl 3.9.15-2Miroslav Grepl 3.9.15-1Fedora Release Engineering - 3.9.14-2Dan Walsh 3.9.14-1Miroslav Grepl 3.9.13-10Miroslav Grepl 3.9.13-9Dan Walsh 3.9.13-8Miroslav Grepl 3.9.13-7Miroslav Grepl 3.9.13-6Miroslav Grepl 3.9.13-5Miroslav Grepl 3.9.13-4Miroslav Grepl 3.9.13-3Miroslav Grepl 3.9.13-2Miroslav Grepl 3.9.13-1Miroslav Grepl 3.9.12-8Miroslav Grepl 3.9.12-7Miroslav Grepl 3.9.12-6Miroslav Grepl 3.9.12-5Dan Walsh 3.9.12-4Dan Walsh 3.9.12-3Dan Walsh 3.9.12-2Miroslav Grepl 3.9.12-1Dan Walsh 3.9.11-2Miroslav Grepl 3.9.11-1Miroslav Grepl 3.9.10-13Dan Walsh 3.9.10-12Miroslav Grepl 3.9.10-11Miroslav Grepl 3.9.10-10Miroslav Grepl 3.9.10-9Miroslav Grepl 3.9.10-8Miroslav Grepl 3.9.10-7Miroslav Grepl 3.9.10-6Miroslav Grepl 3.9.10-5Dan Walsh 3.9.10-4Miroslav Grepl 3.9.10-3Miroslav Grepl 3.9.10-2Miroslav Grepl 3.9.10-1Miroslav Grepl 3.9.9-4Dan Walsh 3.9.9-3Miroslav Grepl 3.9.9-2Miroslav Grepl 3.9.9-1Miroslav Grepl 3.9.8-7Dan Walsh 3.9.8-6Miroslav Grepl 3.9.8-5Miroslav Grepl 3.9.8-4Dan Walsh 3.9.8-3Dan Walsh 3.9.8-2Dan Walsh 3.9.8-1Dan Walsh 3.9.7-10Dan Walsh 3.9.7-9Dan Walsh 3.9.7-8Dan Walsh 3.9.7-7Dan Walsh 3.9.7-6Dan Walsh 3.9.7-5Dan Walsh 3.9.7-4Dan Walsh 3.9.7-3Dan Walsh 3.9.7-2Dan Walsh 3.9.7-1Dan Walsh 3.9.6-3Dan Walsh 3.9.6-2Dan Walsh 3.9.6-1Dan Walsh 3.9.5-11Dan Walsh 3.9.5-10Dan Walsh 3.9.5-9Dan Walsh 3.9.5-8Dan Walsh 3.9.5-7Dan Walsh 3.9.5-6Dan Walsh 3.9.5-5Dan Walsh 3.9.5-4Dan Walsh 3.9.5-3Dan Walsh 3.9.5-2Dan Walsh 3.9.5-1Dan Walsh 3.9.4-3Dan Walsh 3.9.4-2Dan Walsh 3.9.4-1Dan Walsh 3.9.3-4Dan Walsh 3.9.3-3Dan Walsh 3.9.3-2Dan Walsh 3.9.3-1Dan Walsh 3.9.2-1Dan Walsh 3.9.1-3Dan Walsh 3.9.1-2Dan Walsh 3.9.1-1Dan Walsh 3.9.0-2Dan Walsh 3.9.0-1Dan Walsh 3.8.8-21Dan Walsh 3.8.8-20Dan Walsh 3.8.8-19Dan Walsh 3.8.8-18Dan Walsh 3.8.8-17Dan Walsh 3.8.8-16Dan Walsh 3.8.8-15Dan Walsh 3.8.8-14Dan Walsh 3.8.8-13Dan Walsh 3.8.8-12Dan Walsh 3.8.8-11Dan Walsh 3.8.8-10Dan Walsh 3.8.8-9Dan Walsh 3.8.8-8Dan Walsh 3.8.8-7Dan Walsh 3.8.8-6Dan Walsh 3.8.8-5Dan Walsh 3.8.8-4Dan Walsh 3.8.8-3Dan Walsh 3.8.8-2Dan Walsh 3.8.8-1Dan Walsh 3.8.7-3Dan Walsh 3.8.7-2Dan Walsh 3.8.7-1Dan Walsh 3.8.6-3Miroslav Grepl 3.8.6-2Dan Walsh 3.8.6-1Dan Walsh 3.8.5-1Dan Walsh 3.8.4-1Dan Walsh 3.8.3-4Dan Walsh 3.8.3-3Dan Walsh 3.8.3-2Dan Walsh 3.8.3-1Dan Walsh 3.8.2-1Dan Walsh 3.8.1-5Dan Walsh 3.8.1-4Dan Walsh 3.8.1-3Dan Walsh 3.8.1-2Dan Walsh 3.8.1-1Dan Walsh 3.7.19-22Dan Walsh 3.7.19-21Dan Walsh 3.7.19-20Dan Walsh 3.7.19-19Dan Walsh 3.7.19-17Dan Walsh 3.7.19-16Dan Walsh 3.7.19-15Dan Walsh 3.7.19-14Dan Walsh 3.7.19-13Dan Walsh 3.7.19-12Dan Walsh 3.7.19-11Dan Walsh 3.7.19-10Dan Walsh 3.7.19-9Dan Walsh 3.7.19-8Dan Walsh 3.7.19-7Dan Walsh 3.7.19-6Dan Walsh 3.7.19-5Dan Walsh 3.7.19-4Dan Walsh 3.7.19-3Dan Walsh 3.7.19-2Dan Walsh 3.7.19-1Dan Walsh 3.7.18-3Dan Walsh 3.7.18-2Dan Walsh 3.7.18-1Dan Walsh 3.7.17-6Dan Walsh 3.7.17-5Dan Walsh 3.7.17-4Dan Walsh 3.7.17-3Dan Walsh 3.7.17-2Dan Walsh 3.7.17-1Dan Walsh 3.7.16-2Dan Walsh 3.7.16-1Dan Walsh 3.7.15-4Dan Walsh 3.7.15-3Dan Walsh 3.7.15-2Dan Walsh 3.7.15-1Dan Walsh 3.7.14-5Dan Walsh 3.7.14-4Dan Walsh 3.7.14-3Dan Walsh 3.7.14-2Dan Walsh 3.7.14-1Dan Walsh 3.7.13-4Dan Walsh 3.7.13-3Dan Walsh 3.7.13-2Dan Walsh 3.7.13-1Dan Walsh 3.7.12-1Dan Walsh 3.7.11-1Dan Walsh 3.7.10-5Dan Walsh 3.7.10-4Dan Walsh 3.7.10-3Dan Walsh 3.7.10-2Dan Walsh 3.7.10-1Dan Walsh 3.7.9-4Dan Walsh 3.7.9-3Dan Walsh 3.7.9-2Dan Walsh 3.7.9-1Dan Walsh 3.7.8-11Dan Walsh 3.7.8-9Dan Walsh 3.7.8-8Dan Walsh 3.7.8-7Dan Walsh 3.7.8-6Dan Walsh 3.7.8-5Dan Walsh 3.7.8-4Dan Walsh 3.7.8-3Dan Walsh 3.7.8-2Dan Walsh 3.7.8-1Dan Walsh 3.7.7-3Dan Walsh 3.7.7-2Dan Walsh 3.7.7-1Dan Walsh 3.7.6-1Dan Walsh 3.7.5-8Dan Walsh 3.7.5-7Dan Walsh 3.7.5-6Dan Walsh 3.7.5-5Dan Walsh 3.7.5-4Dan Walsh 3.7.5-3Dan Walsh 3.7.5-2Dan Walsh 3.7.5-1Dan Walsh 3.7.4-4Dan Walsh 3.7.4-3Dan Walsh 3.7.4-2Dan Walsh 3.7.4-1Dan Walsh 3.7.3-1Dan Walsh 3.7.1-1Dan Walsh 3.6.33-2Dan Walsh 3.6.33-1Dan Walsh 3.6.32-17Dan Walsh 3.6.32-16Dan Walsh 3.6.32-15Dan Walsh 3.6.32-13Dan Walsh 3.6.32-12Dan Walsh 3.6.32-11Dan Walsh 3.6.32-10Dan Walsh 3.6.32-9Dan Walsh 3.6.32-8Dan Walsh 3.6.32-7Dan Walsh 3.6.32-6Dan Walsh 3.6.32-5Dan Walsh 3.6.32-4Dan Walsh 3.6.32-3Dan Walsh 3.6.32-2Dan Walsh 3.6.32-1Dan Walsh 3.6.31-5Dan Walsh 3.6.31-4Dan Walsh 3.6.31-3Dan Walsh 3.6.31-2Dan Walsh 3.6.30-6Dan Walsh 3.6.30-5Dan Walsh 3.6.30-4Dan Walsh 3.6.30-3Dan Walsh 3.6.30-2Dan Walsh 3.6.30-1Dan Walsh 3.6.29-2Dan Walsh 3.6.29-1Dan Walsh 3.6.28-9Dan Walsh 3.6.28-8Dan Walsh 3.6.28-7Dan Walsh 3.6.28-6Dan Walsh 3.6.28-5Dan Walsh 3.6.28-4Dan Walsh 3.6.28-3Dan Walsh 3.6.28-2Dan Walsh 3.6.28-1Dan Walsh 3.6.27-1Dan Walsh 3.6.26-11Dan Walsh 3.6.26-10Dan Walsh 3.6.26-9Bill Nottingham 3.6.26-8Dan Walsh 3.6.26-7Dan Walsh 3.6.26-6Dan Walsh 3.6.26-5Dan Walsh 3.6.26-4Dan Walsh 3.6.26-3Dan Walsh 3.6.26-2Dan Walsh 3.6.26-1Dan Walsh 3.6.25-1Dan Walsh 3.6.24-1Dan Walsh 3.6.23-2Dan Walsh 3.6.23-1Dan Walsh 3.6.22-3Dan Walsh 3.6.22-1Dan Walsh 3.6.21-4Dan Walsh 3.6.21-3Tom "spot" Callaway 3.6.21-2Dan Walsh 3.6.21-1Dan Walsh 3.6.20-2Dan Walsh 3.6.20-1Dan Walsh 3.6.19-5Dan Walsh 3.6.19-4Dan Walsh 3.6.19-3Dan Walsh 3.6.19-2Dan Walsh 3.6.19-1Dan Walsh 3.6.18-1Dan Walsh 3.6.17-1Dan Walsh 3.6.16-4Dan Walsh 3.6.16-3Dan Walsh 3.6.16-2Dan Walsh 3.6.16-1Dan Walsh 3.6.14-3Dan Walsh 3.6.14-2Dan Walsh 3.6.14-1Dan Walsh 3.6.13-3Dan Walsh 3.6.13-2Dan Walsh 3.6.13-1Dan Walsh 3.6.12-39Dan Walsh 3.6.12-38Dan Walsh 3.6.12-37Dan Walsh 3.6.12-36Dan Walsh 3.6.12-35Dan Walsh 3.6.12-34Dan Walsh 3.6.12-33Dan Walsh 3.6.12-31Dan Walsh 3.6.12-30Dan Walsh 3.6.12-29Dan Walsh 3.6.12-28Dan Walsh 3.6.12-27Dan Walsh 3.6.12-26Dan Walsh 3.6.12-25Dan Walsh 3.6.12-24Dan Walsh 3.6.12-23Dan Walsh 3.6.12-22Dan Walsh 3.6.12-21Dan Walsh 3.6.12-20Dan Walsh 3.6.12-19Dan Walsh 3.6.12-16Dan Walsh 3.6.12-15Dan Walsh 3.6.12-14Dan Walsh 3.6.12-13Dan Walsh 3.6.12-12Dan Walsh 3.6.12-11Dan Walsh 3.6.12-10Dan Walsh 3.6.12-9Dan Walsh 3.6.12-8Dan Walsh 3.6.12-7Dan Walsh 3.6.12-6Dan Walsh 3.6.12-5Dan Walsh 3.6.12-4Dan Walsh 3.6.12-3Dan Walsh 3.6.12-2Dan Walsh 3.6.12-1Dan Walsh 3.6.11-1Dan Walsh 3.6.10-9Dan Walsh 3.6.10-8Dan Walsh 3.6.10-7Dan Walsh 3.6.10-6Dan Walsh 3.6.10-5Dan Walsh 3.6.10-4Dan Walsh 3.6.10-3Dan Walsh 3.6.10-2Dan Walsh 3.6.10-1Dan Walsh 3.6.9-4Dan Walsh 3.6.9-3Dan Walsh 3.6.9-2Dan Walsh 3.6.9-1Dan Walsh 3.6.8-4Dan Walsh 3.6.8-3Dan Walsh 3.6.8-2Dan Walsh 3.6.8-1Dan Walsh 3.6.7-2Dan Walsh 3.6.7-1Dan Walsh 3.6.6-9Dan Walsh 3.6.6-8Fedora Release Engineering - 3.6.6-7Dan Walsh 3.6.6-6Dan Walsh 3.6.6-5Dan Walsh 3.6.6-4Dan Walsh 3.6.6-3Dan Walsh 3.6.6-2Dan Walsh 3.6.6-1Dan Walsh 3.6.5-3Dan Walsh 3.6.5-1Dan Walsh 3.6.4-6Dan Walsh 3.6.4-5Dan Walsh 3.6.4-4Dan Walsh 3.6.4-3Dan Walsh 3.6.4-2Dan Walsh 3.6.4-1Dan Walsh 3.6.3-13Dan Walsh 3.6.3-12Dan Walsh 3.6.3-11Dan Walsh 3.6.3-10Dan Walsh 3.6.3-9Dan Walsh 3.6.3-8Dan Walsh 3.6.3-7Dan Walsh 3.6.3-6Dan Walsh 3.6.3-3Dan Walsh 3.6.3-2Dan Walsh 3.6.3-1Dan Walsh 3.6.2-5Dan Walsh 3.6.2-4Dan Walsh 3.6.2-3Dan Walsh 3.6.2-2Dan Walsh 3.6.2-1Dan Walsh 3.6.1-15Dan Walsh 3.6.1-14Dan Walsh 3.6.1-13Dan Walsh 3.6.1-12Dan Walsh 3.6.1-11Dan Walsh 3.6.1-10Dan Walsh 3.6.1-9Dan Walsh 3.6.1-8Dan Walsh 3.6.1-7Dan Walsh 3.6.1-4Ignacio Vazquez-Abrams - 3.6.1-2Dan Walsh 3.5.13-19Dan Walsh 3.5.13-18Dan Walsh 3.5.13-17Dan Walsh 3.5.13-16Dan Walsh 3.5.13-15Dan Walsh 3.5.13-14Dan Walsh 3.5.13-13Dan Walsh 3.5.13-12Dan Walsh 3.5.13-11Dan Walsh 3.5.13-9Dan Walsh 3.5.13-8Dan Walsh 3.5.13-7Dan Walsh 3.5.13-6Dan Walsh 3.5.13-5Dan Walsh 3.5.13-4Dan Walsh 3.5.13-3Dan Walsh 3.5.13-2Dan Walsh 3.5.13-1Dan Walsh 3.5.12-3Dan Walsh 3.5.12-2Dan Walsh 3.5.12-1Dan Walsh 3.5.11-1Dan Walsh 3.5.10-3Dan Walsh 3.5.10-2Dan Walsh 3.5.10-1Dan Walsh 3.5.9-4Dan Walsh 3.5.9-3Dan Walsh 3.5.9-2Dan Walsh 3.5.9-1Dan Walsh 3.5.8-7Dan Walsh 3.5.8-6Dan Walsh 3.5.8-5Dan Walsh 3.5.8-4Dan Walsh 3.5.8-3Dan Walsh 3.5.8-1Dan Walsh 3.5.7-2Dan Walsh 3.5.7-1Dan Walsh 3.5.6-2Dan Walsh 3.5.6-1Dan Walsh 3.5.5-4Dan Walsh 3.5.5-3Dan Walsh 3.5.5-2Dan Walsh 3.5.4-2Dan Walsh 3.5.4-1Dan Walsh 3.5.3-1Dan Walsh 3.5.2-2Dan Walsh 3.5.1-5Dan Walsh 3.5.1-4Dan Walsh 3.5.1-3Dan Walsh 3.5.1-2Dan Walsh 3.5.1-1Dan Walsh 3.5.0-1Dan Walsh 3.4.2-14Dan Walsh 3.4.2-13Dan Walsh 3.4.2-12Dan Walsh 3.4.2-11Dan Walsh 3.4.2-10Dan Walsh 3.4.2-9Dan Walsh 3.4.2-8Dan Walsh 3.4.2-7Dan Walsh 3.4.2-6Dan Walsh 3.4.2-5Dan Walsh 3.4.2-4Dan Walsh 3.4.2-3Dan Walsh 3.4.2-2Dan Walsh 3.4.2-1Dan Walsh 3.4.1-5Dan Walsh 3.4.1-3Dan Walsh 3.4.1-2Dan Walsh 3.4.1-1Dan Walsh 3.3.1-48Dan Walsh 3.3.1-47Dan Walsh 3.3.1-46Dan Walsh 3.3.1-45Dan Walsh 3.3.1-44Dan Walsh 3.3.1-43Dan Walsh 3.3.1-42Dan Walsh 3.3.1-41Dan Walsh 3.3.1-39Dan Walsh 3.3.1-37Dan Walsh 3.3.1-36Dan Walsh 3.3.1-33Dan Walsh 3.3.1-32Dan Walsh 3.3.1-31Dan Walsh 3.3.1-30Dan Walsh 3.3.1-29Dan Walsh 3.3.1-28Dan Walsh 3.3.1-27Dan Walsh 3.3.1-26Dan Walsh 3.3.1-25Dan Walsh 3.3.1-24Dan Walsh 3.3.1-23Dan Walsh 3.3.1-22Dan Walsh 3.3.1-21Dan Walsh 3.3.1-20Dan Walsh 3.3.1-19Dan Walsh 3.3.1-18Dan Walsh 3.3.1-17Dan Walsh 3.3.1-16Dan Walsh 3.3.1-15Bill Nottingham 3.3.1-14Dan Walsh 3.3.1-13Dan Walsh 3.3.1-12Dan Walsh 3.3.1-11Dan Walsh 3.3.1-10Dan Walsh 3.3.1-9Dan Walsh 3.3.1-8Dan Walsh 3.3.1-6Dan Walsh 3.3.1-5Dan Walsh 3.3.1-4Dan Walsh 3.3.1-2Dan Walsh 3.3.1-1Dan Walsh 3.3.0-2Dan Walsh 3.3.0-1Dan Walsh 3.2.9-2Dan Walsh 3.2.9-1Dan Walsh 3.2.8-2Dan Walsh 3.2.8-1Dan Walsh 3.2.7-6Dan Walsh 3.2.7-5Dan Walsh 3.2.7-3Dan Walsh 3.2.7-2Dan Walsh 3.2.7-1Dan Walsh 3.2.6-7Dan Walsh 3.2.6-6Dan Walsh 3.2.6-5Dan Walsh 3.2.6-4Dan Walsh 3.2.6-3Dan Walsh 3.2.6-2Dan Walsh 3.2.6-1Dan Walsh 3.2.5-25Dan Walsh 3.2.5-24Dan Walsh 3.2.5-22Dan Walsh 3.2.5-21Dan Walsh 3.2.5-20Dan Walsh 3.2.5-19Dan Walsh 3.2.5-18Dan Walsh 3.2.5-17Dan Walsh 3.2.5-16Dan Walsh 3.2.5-15Dan Walsh 3.2.5-14Dan Walsh 3.2.5-13Dan Walsh 3.2.5-12Dan Walsh 3.2.5-11Dan Walsh 3.2.5-10Dan Walsh 3.2.5-9Dan Walsh 3.2.5-8Dan Walsh 3.2.5-7Dan Walsh 3.2.5-6Dan Walsh 3.2.5-5Dan Walsh 3.2.5-4Dan Walsh 3.2.5-3Dan Walsh 3.2.5-2Dan Walsh 3.2.5-1Dan Walsh 3.2.4-5Dan Walsh 3.2.4-4Dan Walsh 3.2.4-3Dan Walsh 3.2.4-1Dan Walsh 3.2.4-1Dan Walsh 3.2.3-2Dan Walsh 3.2.3-1Dan Walsh 3.2.2-1Dan Walsh 3.2.1-3Dan Walsh 3.2.1-1Dan Walsh 3.1.2-2Dan Walsh 3.1.2-1Dan Walsh 3.1.1-1Dan Walsh 3.1.0-1Dan Walsh 3.0.8-30Dan Walsh 3.0.8-28Dan Walsh 3.0.8-27Dan Walsh 3.0.8-26Dan Walsh 3.0.8-25Dan Walsh 3.0.8-24Dan Walsh 3.0.8-23Dan Walsh 3.0.8-22Dan Walsh 3.0.8-21Dan Walsh 3.0.8-20Dan Walsh 3.0.8-19Dan Walsh 3.0.8-18Dan Walsh 3.0.8-17Dan Walsh 3.0.8-16Dan Walsh 3.0.8-15Dan Walsh 3.0.8-14Dan Walsh 3.0.8-13Dan Walsh 3.0.8-12Dan Walsh 3.0.8-11Dan Walsh 3.0.8-10Dan Walsh 3.0.8-9Dan Walsh 3.0.8-8Dan Walsh 3.0.8-7Dan Walsh 3.0.8-5Dan Walsh 3.0.8-4Dan Walsh 3.0.8-3Dan Walsh 3.0.8-2Dan Walsh 3.0.8-1Dan Walsh 3.0.7-10Dan Walsh 3.0.7-9Dan Walsh 3.0.7-8Dan Walsh 3.0.7-7Dan Walsh 3.0.7-6Dan Walsh 3.0.7-5Dan Walsh 3.0.7-4Dan Walsh 3.0.7-3Dan Walsh 3.0.7-2Dan Walsh 3.0.7-1Dan Walsh 3.0.6-3Dan Walsh 3.0.6-2Dan Walsh 3.0.6-1Dan Walsh 3.0.5-11Dan Walsh 3.0.5-10Dan Walsh 3.0.5-9Dan Walsh 3.0.5-8Dan Walsh 3.0.5-7Dan Walsh 3.0.5-6Dan Walsh 3.0.5-5Dan Walsh 3.0.5-4Dan Walsh 3.0.5-3Dan Walsh 3.0.5-2Dan Walsh 3.0.5-1Dan Walsh 3.0.4-6Dan Walsh 3.0.4-5Dan Walsh 3.0.4-4Dan Walsh 3.0.4-3Dan Walsh 3.0.4-2Dan Walsh 3.0.4-1Dan Walsh 3.0.3-6Dan Walsh 3.0.3-5Dan Walsh 3.0.3-4Dan Walsh 3.0.3-3Dan Walsh 3.0.3-2Dan Walsh 3.0.3-1Dan Walsh 3.0.2-9Dan Walsh 3.0.2-8Dan Walsh 3.0.2-7Dan Walsh 3.0.2-5Dan Walsh 3.0.2-4Dan Walsh 3.0.2-3Dan Walsh 3.0.2-2Dan Walsh 3.0.1-5Dan Walsh 3.0.1-4Dan Walsh 3.0.1-3Dan Walsh 3.0.1-2Dan Walsh 3.0.1-1Dan Walsh 2.6.5-3Dan Walsh 2.6.5-2Dan Walsh 2.6.4-7Dan Walsh 2.6.4-6Dan Walsh 2.6.4-5Dan Walsh 2.6.4-2Dan Walsh 2.6.4-1Dan Walsh 2.6.3-1Dan Walsh 2.6.2-1Dan Walsh 2.6.1-4Dan Walsh 2.6.1-2Dan Walsh 2.6.1-1Dan Walsh 2.5.12-12Dan Walsh 2.5.12-11Dan Walsh 2.5.12-10Dan Walsh 2.5.12-8Dan Walsh 2.5.12-5Dan Walsh 2.5.12-4Dan Walsh 2.5.12-3Dan Walsh 2.5.12-2Dan Walsh 2.5.12-1Dan Walsh 2.5.11-8Dan Walsh 2.5.11-7Dan Walsh 2.5.11-6Dan Walsh 2.5.11-5Dan Walsh 2.5.11-4Dan Walsh 2.5.11-3Dan Walsh 2.5.11-2Dan Walsh 2.5.11-1Dan Walsh 2.5.10-2Dan Walsh 2.5.10-1Dan Walsh 2.5.9-6Dan Walsh 2.5.9-5Dan Walsh 2.5.9-4Dan Walsh 2.5.9-3Dan Walsh 2.5.9-2Dan Walsh 2.5.8-8Dan Walsh 2.5.8-7Dan Walsh 2.5.8-6Dan Walsh 2.5.8-5Dan Walsh 2.5.8-4Dan Walsh 2.5.8-3Dan Walsh 2.5.8-2Dan Walsh 2.5.8-1Dan Walsh 2.5.7-1Dan Walsh 2.5.6-1Dan Walsh 2.5.5-2Dan Walsh 2.5.5-1Dan Walsh 2.5.4-2Dan Walsh 2.5.4-1Dan Walsh 2.5.3-3Dan Walsh 2.5.3-2Dan Walsh 2.5.3-1Dan Walsh 2.5.2-6Dan Walsh 2.5.2-5Dan Walsh 2.5.2-4Dan Walsh 2.5.2-3Dan Walsh 2.5.2-2Dan Walsh 2.5.2-1Dan Walsh 2.5.1-5Dan Walsh 2.5.1-4Dan Walsh 2.5.1-2Dan Walsh 2.5.1-1Dan Walsh 2.4.6-20Dan Walsh 2.4.6-19Dan Walsh 2.4.6-18Dan Walsh 2.4.6-17Dan Walsh 2.4.6-16Dan Walsh 2.4.6-15Dan Walsh 2.4.6-14Dan Walsh 2.4.6-13Dan Walsh 2.4.6-12Dan Walsh 2.4.6-11Dan Walsh 2.4.6-10Dan Walsh 2.4.6-9Dan Walsh 2.4.6-8Dan Walsh 2.4.6-7Dan Walsh 2.4.6-6Dan Walsh 2.4.6-5Dan Walsh 2.4.6-4Dan Walsh 2.4.6-3Dan Walsh 2.4.6-1Dan Walsh 2.4.5-4Dan Walsh 2.4.5-3Dan Walsh 2.4.5-2Dan Walsh 2.4.5-1Dan Walsh 2.4.4-2Dan Walsh 2.4.4-2Dan Walsh 2.4.4-1Dan Walsh 2.4.3-13Dan Walsh 2.4.3-12Dan Walsh 2.4.3-11Dan Walsh 2.4.3-10Dan Walsh 2.4.3-9Dan Walsh 2.4.3-8Dan Walsh 2.4.3-7Dan Walsh 2.4.3-6Dan Walsh 2.4.3-5Dan Walsh 2.4.3-4Dan Walsh 2.4.3-3Dan Walsh 2.4.3-2Dan Walsh 2.4.3-1Dan Walsh 2.4.2-8Dan Walsh 2.4.2-7James Antill 2.4.2-6Dan Walsh 2.4.2-5Dan Walsh 2.4.2-4Dan Walsh 2.4.2-3Dan Walsh 2.4.2-2Dan Walsh 2.4.2-1Dan Walsh 2.4.1-5Dan Walsh 2.4.1-4Dan Walsh 2.4.1-3Dan Walsh 2.4.1-2Dan Walsh 2.4-4Dan Walsh 2.4-3Dan Walsh 2.4-2Dan Walsh 2.4-1Dan Walsh 2.3.19-4Dan Walsh 2.3.19-3Dan Walsh 2.3.19-2Dan Walsh 2.3.19-1James Antill 2.3.18-10James Antill 2.3.18-9Dan Walsh 2.3.18-8Dan Walsh 2.3.18-7Dan Walsh 2.3.18-6Dan Walsh 2.3.18-5Dan Walsh 2.3.18-4Dan Walsh 2.3.18-3Dan Walsh 2.3.18-2Dan Walsh 2.3.18-1Dan Walsh 2.3.17-2Dan Walsh 2.3.17-1Dan Walsh 2.3.16-9Dan Walsh 2.3.16-8Dan Walsh 2.3.16-7Dan Walsh 2.3.16-6Dan Walsh 2.3.16-5Dan Walsh 2.3.16-4Dan Walsh 2.3.16-2Dan Walsh 2.3.16-1Dan Walsh 2.3.15-2Dan Walsh 2.3.15-1Dan Walsh 2.3.14-8Dan Walsh 2.3.14-7Dan Walsh 2.3.14-6Dan Walsh 2.3.14-4Dan Walsh 2.3.14-3Dan Walsh 2.3.14-2Dan Walsh 2.3.14-1Dan Walsh 2.3.13-6Dan Walsh 2.3.13-5Dan Walsh 2.3.13-4Dan Walsh 2.3.13-3Dan Walsh 2.3.13-2Dan Walsh 2.3.13-1Dan Walsh 2.3.12-2Dan Walsh 2.3.12-1Dan Walsh 2.3.11-1Dan Walsh 2.3.10-7Dan Walsh 2.3.10-6Dan Walsh 2.3.10-3Dan Walsh 2.3.10-1Dan Walsh 2.3.9-6Dan Walsh 2.3.9-5Dan Walsh 2.3.9-4Dan Walsh 2.3.9-3Dan Walsh 2.3.9-2Dan Walsh 2.3.9-1Dan Walsh 2.3.8-2Dan Walsh 2.3.7-1Dan Walsh 2.3.6-4Dan Walsh 2.3.6-3Dan Walsh 2.3.6-2Dan Walsh 2.3.6-1Dan Walsh 2.3.5-1Dan Walsh 2.3.4-1Dan Walsh 2.3.3-20Dan Walsh 2.3.3-19Dan Walsh 2.3.3-18Dan Walsh 2.3.3-17Dan Walsh 2.3.3-16Dan Walsh 2.3.3-15Dan Walsh 2.3.3-14Dan Walsh 2.3.3-13Dan Walsh 2.3.3-12Dan Walsh 2.3.3-11Dan Walsh 2.3.3-10Dan Walsh 2.3.3-9Dan Walsh 2.3.3-8Dan Walsh 2.3.3-7Dan Walsh 2.3.3-6Dan Walsh 2.3.3-5Dan Walsh 2.3.3-4Dan Walsh 2.3.3-3Dan Walsh 2.3.3-2Dan Walsh 2.3.3-1Dan Walsh 2.3.2-4Dan Walsh 2.3.2-3Dan Walsh 2.3.2-2Dan Walsh 2.3.2-1Dan Walsh 2.3.1-1Dan Walsh 2.2.49-1Dan Walsh 2.2.48-1Dan Walsh 2.2.47-5Dan Walsh 2.2.47-4Dan Walsh 2.2.47-3Dan Walsh 2.2.47-1Dan Walsh 2.2.46-2Dan Walsh 2.2.46-1Dan Walsh 2.2.45-3Dan Walsh 2.2.45-2Dan Walsh 2.2.45-1Dan Walsh 2.2.44-1Dan Walsh 2.2.43-4Dan Walsh 2.2.43-3Dan Walsh 2.2.43-2Dan Walsh 2.2.43-1Dan Walsh 2.2.42-4Dan Walsh 2.2.42-3Dan Walsh 2.2.42-2Dan Walsh 2.2.42-1Dan Walsh 2.2.41-1Dan Walsh 2.2.40-2Dan Walsh 2.2.40-1Dan Walsh 2.2.39-2Dan Walsh 2.2.39-1Dan Walsh 2.2.38-6Dan Walsh 2.2.38-5Dan Walsh 2.2.38-4Dan Walsh 2.2.38-3Dan Walsh 2.2.38-2Dan Walsh 2.2.38-1Dan Walsh 2.2.37-1Dan Walsh 2.2.36-2Dan Walsh 2.2.36-1James Antill 2.2.35-2Dan Walsh 2.2.35-1Dan Walsh 2.2.34-3Dan Walsh 2.2.34-2Dan Walsh 2.2.34-1Dan Walsh 2.2.33-1Dan Walsh 2.2.32-2Dan Walsh 2.2.32-1Dan Walsh 2.2.31-1Dan Walsh 2.2.30-2Dan Walsh 2.2.30-1Dan Walsh 2.2.29-6Russell Coker 2.2.29-5Dan Walsh 2.2.29-4Dan Walsh 2.2.29-3Dan Walsh 2.2.29-2Dan Walsh 2.2.29-1Dan Walsh 2.2.28-3Dan Walsh 2.2.28-2Dan Walsh 2.2.28-1Dan Walsh 2.2.27-1Dan Walsh 2.2.25-3Dan Walsh 2.2.25-2Dan Walsh 2.2.24-1Dan Walsh 2.2.23-19Dan Walsh 2.2.23-18Dan Walsh 2.2.23-17Karsten Hopp 2.2.23-16Dan Walsh 2.2.23-15Dan Walsh 2.2.23-14Dan Walsh 2.2.23-13Dan Walsh 2.2.23-12Jeremy Katz - 2.2.23-11Jeremy Katz - 2.2.23-10Dan Walsh 2.2.23-9Dan Walsh 2.2.23-8Dan Walsh 2.2.23-7Dan Walsh 2.2.23-5Dan Walsh 2.2.23-4Dan Walsh 2.2.23-3Dan Walsh 2.2.23-2Dan Walsh 2.2.23-1Dan Walsh 2.2.22-2Dan Walsh 2.2.22-1Dan Walsh 2.2.21-9Dan Walsh 2.2.21-8Dan Walsh 2.2.21-7Dan Walsh 2.2.21-6Dan Walsh 2.2.21-5Dan Walsh 2.2.21-4Dan Walsh 2.2.21-3Dan Walsh 2.2.21-2Dan Walsh 2.2.21-1Dan Walsh 2.2.20-1Dan Walsh 2.2.19-2Dan Walsh 2.2.19-1Dan Walsh 2.2.18-2Dan Walsh 2.2.18-1Dan Walsh 2.2.17-2Dan Walsh 2.2.16-1Dan Walsh 2.2.15-4Dan Walsh 2.2.15-3Dan Walsh 2.2.15-1Dan Walsh 2.2.14-2Dan Walsh 2.2.14-1Dan Walsh 2.2.13-1Dan Walsh 2.2.12-1Dan Walsh 2.2.11-2Dan Walsh 2.2.11-1Dan Walsh 2.2.10-1Dan Walsh 2.2.9-2Dan Walsh 2.2.9-1Dan Walsh 2.2.8-2Dan Walsh 2.2.7-1Dan Walsh 2.2.6-3Dan Walsh 2.2.6-2Dan Walsh 2.2.6-1Dan Walsh 2.2.5-1Dan Walsh 2.2.4-1Dan Walsh 2.2.3-1Dan Walsh 2.2.2-1Dan Walsh 2.2.1-1Dan Walsh 2.1.13-1Dan Walsh 2.1.12-3Dan Walsh 2.1.11-1Dan Walsh 2.1.10-1Jeremy Katz - 2.1.9-2Dan Walsh 2.1.9-1Dan Walsh 2.1.8-3Dan Walsh 2.1.8-2Dan Walsh 2.1.8-1Dan Walsh 2.1.7-4Dan Walsh 2.1.7-3Dan Walsh 2.1.7-2Dan Walsh 2.1.7-1Dan Walsh 2.1.6-24Dan Walsh 2.1.6-23Dan Walsh 2.1.6-22Dan Walsh 2.1.6-21Dan Walsh 2.1.6-20Dan Walsh 2.1.6-18Dan Walsh 2.1.6-17Dan Walsh 2.1.6-16Dan Walsh 2.1.6-15Dan Walsh 2.1.6-14Dan Walsh 2.1.6-13Dan Walsh 2.1.6-11Dan Walsh 2.1.6-10Dan Walsh 2.1.6-9Dan Walsh 2.1.6-8Dan Walsh 2.1.6-5Dan Walsh 2.1.6-4Dan Walsh 2.1.6-3Dan Walsh 2.1.6-2Dan Walsh 2.1.6-1Dan Walsh 2.1.4-2Dan Walsh 2.1.4-1Dan Walsh 2.1.3-1Jeremy Katz - 2.1.2-3Dan Walsh 2.1.2-2Dan Walsh 2.1.2-1Dan Walsh 2.1.1-3Dan Walsh 2.1.1-2Dan Walsh 2.1.1-1Dan Walsh 2.1.0-3Dan Walsh 2.1.0-2.Dan Walsh 2.1.0-1.Dan Walsh 2.0.11-2.Dan Walsh 2.0.11-1.Dan Walsh 2.0.9-1.Dan Walsh 2.0.8-1.Dan Walsh 2.0.7-3Dan Walsh 2.0.7-2Dan Walsh 2.0.6-2Dan Walsh 2.0.5-4Dan Walsh 2.0.5-1Dan Walsh 2.0.4-1Dan Walsh 2.0.2-2Dan Walsh 2.0.2-1Dan Walsh 2.0.1-2Dan Walsh 2.0.1-1- Allow qpidd access to /proc//net/psched Resolves: #1254318- Dontaudit chrome to read passwd file. Resolves:#1257816- Revert Allow qpidd access to /proc//net/psched Resolves: #1254318-Allow qpidd access to /proc//net/psched Resolves: #1254318- Allow chrome setcap to itself. Resolves: #1254565- glusterd call pcs utility which calls find for cib.* files and runs pstree under glusterd. Dontaudit access to security files and update gluster boolean to reflect these changes. - Allow glusterd to communicate with cluster domains over stream socket. Resolves:#1238963- Allow iptables to read ctdbd lib files. Resolves:#1238965- Allow glusterd to manage nfsd and rpcd services. - Allow samba_t net_admin capability to make CIFS mount working. Resolves:#1238965 - Dontaudit smbd_t block_suspend capability.- Allow gluster to connect to all ports. It is required by random services executed by gluster. - Allow glusterd to execute showmount in the showmount domain. - Add samba_signull_unconfined_net() - Add samba_signull_winbind() Resolves:#1232755 - Add logging_syslogd_run_nagios_plugins boolean for rsyslog to allow transition to nagios unconfined plugins. Resolves:#1238963 - Label gluster python hooks also as bin_t. Resolves:#1238965 - We allow can_exec() on ssh_keygen on gluster. But there is a transition defined by init_initrc_domain() because we need to allow execute unconfined services by glusterd. So ssh-keygen ends up with ssh_keygen_t and we need to allow to manage /var/lib/glusterd/geo-replication/secret.pem.- S30samba-start gluster hooks wants to search audit logs. Dontaudit it. - Allow glusterd to interact with gluster tools running in a user domain - nrpe needs kill capability to make gluster moniterd nodes working. Resolves:#1238964 - Add cron_system_cronjob_use_shares boolean to allow system cronjob to be executed from shares - NFS, CIFS, FUSE. It requires "entrypoint" permissios on nfs_t, cifs_t and fusefs_t SELinux types. - Allow ctdb_t sending signull to smbd_t, for checking if smbd process exists.- Back port passenger fixes from RHEL-7.2 - Back port httpd fixes related to gluster+nagios. - Back port glusterd changs from RHEL-7.2 related to Gluster. - Back port ctdbd changs from RHEL-7.2 related to Gluster. - Back port nagios changs from RHEL-7.2 related to Gluster. - Back port samba changs from RHEL-7.2 related to Gluster. Resolves:#1230292 Resolves:#1230299 Resolves:#1231649 Resolves:#1231930 Resolves:#1231942- Label /usr/libexec/postgresql-ctl as postgresql_exec_t - Update virt_read_pid_files() interface to allow read also symlinks with virt_var_run_t type. - Add labeling for /usr/libexec/mysqld_safe-scl-helper. - Add support for /usr/libexec/mongodb-scl-helper RHSCL helper script. Resolves:#1209942 - Allow mysqld_t to use pam.It is needed by MariDB if auth_apm.so auth plugin is used Resolves:#1214236 - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. Resolves:#1214235 - Add support for mongod/mongos systemd unit files. Resolves:#1214194- Make mongodb_t as nsswitch domain - ALlow mongod execmem by default Resolves:#1212970- Update policy/mls for sockets related to accept. Resolves:#1207549- Update policy/mls for sockets. Rules were contradictory. Resolves:#1207549- Dontaudit ifconfig writing inhertited /var/log/pluto.log. Resolves:#1205580 - Update init_rw_tcp_sockets() interface to use getopt and setopt.- Use enable_mls instead of enabled_mls in userdomain.if Resolves:#1204778- Allow a user to login with different security level via ssh. Resolves:#1204778- Update seutil_manage_config() interface. Resolves:#1185962 - Allow pki-tomcat relabel pki_tomcat_etc_rw_t. - Turn on docker_transition_unconfined by default- Allow virtd to list all mountpoints. Resolves:#1180713- pkcsslotd_lock_t should be an alias for pkcs_slotd_lock_t. - Allow fowner capability for sssd because of selinux_child handling. - ALlow bind to read/write inherited ipsec pipes - Allow hypervkvp to read /dev/urandom and read addition states/config files. - Allow gluster rpm scripletto create glusterd socket with correct labeling. This is a workaround until we get fix in glusterd. - Add glusterd_filetrans_named_pid() interface - Allow radiusd to connect to radsec ports. - Allow setuid/setgid for selinux_child - Allow lsmd plugin to connect to tcp/5988 by default. - Allow lsmd plugin to connect to tcp/5989 by default. - Update ipsec_manage_pid() interface. Resolves:#1184978- Update ipsec_manage_pid() interface. Resolves:#1184978- Allow ntlm_auth running in winbind_helper_t to access /dev/urandom.- Add auditing support for ipsec. Resolves:#1182524 - Label /ostree/deploy/rhel-atomic-host/deploy directory as system_conf_t - Allow netutils chown capability to make tcpdump working with -w- Allow ipsec to execute _updown.netkey script to run unbound-control. - Allow neutron to read rpm DB. - Add additional fixes for hyperkvp * creates new ifcfg-{name} file * Runs hv_set_ifconfig.sh, which does the following * Copies ifcfg-{name} to /etc/sysconfig/network-scripts - Allow svirt to read symbolic links in /sys/fs/cgroups labeled as tmpfs_t - Add labeling for pacemaker.log. - Allow radius to connect/bind radsec ports. - Allow pm-suspend running as virt_qemu_ga to read /var/log/pm-suspend.log - Allow virt_qemu_ga to dbus chat with rpm. - Update virt_read_content() interface to allow read also char devices. - Allow glance-registry to connect to keystone port. Resolves:#1181818- Allow sssd to send dbus all user domains. Resolves:#1172291 - Allow lsm plugin to read certificates. - Fix labeling for keystone CGI scripts. - Make snapperd back as unconfined domain.- Fix bugs in interfaces discovered by sepolicy. - Allow slapd to read /usr/share/cracklib/pw_dict.hwm. - Allow lsm plugins to connect to tcp/18700 by default. - Allow brltty mknod capability to allow create /var/run/brltty/vcsa. - Fix pcp_domain_template() interface. - Fix conman.te. - Allow mon_fsstatd to read /proc/sys/fs/binfmt_misc - Allow glance-scrubber to connect tcp/9191. - Add missing setuid capability for sblim-sfcbd. - Allow pegasus ioctl() on providers. - Add conman_can_network. - Allow chronyd to read chrony conf files located in /run/timemaster/. - Allow radius to bind on tcp/1813 port. - dontaudit block suspend access for openvpn_t - Allow conman to create files/dirs in /tmp. - Update xserver_rw_xdm_keys() interface to have 'setattr'. Resolves:#1172291 - Allow sulogin to read /dev/urandom and /dev/random. - Update radius port definition to have also tcp/18121 - Label prandom as random_device_t. - Allow charon to manage files in /etc/strongimcv labeled as ipsec_conf_t.- Allow virt_qemu_ga_t to execute kmod. - Add missing files_dontaudit_list_security_dirs() for smbd_t in samba_export_all_ro boolean. - Add additionnal MLS attribute for oddjob_mkhomedir to create homedirs. Resolves:#1113725 - Enable OpenStack cinder policy - Add support for /usr/share/vdsm/daemonAdapter - Add support for /var/run/gluster- Remove old pkcsslotd.pp from minimum package - Allow rlogind to use also rlogin ports. - Add support for /usr/libexec/ntpdate-wrapper. Label it as ntpdate_exec_t. - Allow bacula to connect also to postgresql. - Label /usr/libexec/tomcat/server as tomcat_exec_t - Add support for /usr/sbin/ctdbd_wrapper - Add support for /usr/libexec/ppc64-diag/rtas_errd - Allow rpm_script_roles to access system_mail_t - Allow brltty to create /var/run/brltty - Allow lsmd plugin to access netlink_route_socket - Allow smbcontrol to read passwd - Add support for /usr/libexec/sssd/selinux_child and create sssd_selinux_manager_t domain for it Resolves:#1140106 - Allow osad to execute rhn_check - Allow load_policy to rw inherited sssd pipes because of selinux_child - Allow admin SELinux users mounting / as private within a new mount namespace as root in MLS - Add additional fixes for su_restricted_domain_template to make moving to sysadm_r and trying to su working correctly - Add additional booleans substitions- Add seutil_dontaudit_access_check_semanage_module_store() interface Resolves:#1140106 - Update to have all _systemctl() interface also init_reload_services(). - Dontaudit access check on SELinux module store for sssd. - Add labeling for /sbin/iw. - Allow named_filetrans_domain to create ibus directory with correct labeling.- Allow radius to bind tcp/1812 radius port. - Dontaudit list user_tmp files for system_mail_t. - Label virt-who as virtd_exec_t. - Allow rhsmcertd to send a null signal to virt-who running as virtd_t. - Add missing alias for _content_rw_t. Resolves:#1089177 - Allow spamd to access razor-agent.log. - Add fixes for sfcb from libvirt-cim TestOnly bug. - Allow NetworkManager stream connect on openvpn. - Make /usr/bin/vncserver running as unconfined_service_t. - getty_t should be ranged in MLS. Then also local_login_t runs as ranged domain. - Label /etc/docker/certs.d as cert_t.- Label /etc/strongimcv as ipsec_conf_file_t. - Add support for /usr/bin/start-puppet-ca helper script Resolves:#1160727 - Allow rpm scripts to enable/disable transient systemd units. Resolves:#1154613 - Make kpropdas nsswitch domain Resolves:#1153561 - Make all glance domain as nsswitch domains Resolves:#1113281 - Allow selinux_child running as sssd access check on /etc/selinux/targeted/modules/active - Allow access checks on setfiles/load_policy/semanage_lock for selinux_child running as sssd_t Resolves:#1140106- Dontaudit access check on setfiles/load_policy for sssd_t. Resolves:#1140106 - Add kdump_rw_inherited_kdumpctl_tmp_pipes() Resolves:#1156442 - Make linuxptp services as unconfined. - Added new policy linuxptp. Resolves:#1149693 - Label keystone cgi files as keystone_cgi_script_exec_t. Resolves:#1138424 - Make tuned as unconfined domain- Allow guest to connect to libvirt using unix_stream_socket. - Allow all bus client domains to dbus chat with unconfined_service_t. - Allow inetd service without own policy to run in inetd_child_t which is unconfined domain. - Make opensm as nsswitch domain to make it working with sssd. - Allow brctl to read meminfo. - Allow winbind-helper to execute ntlm_auth in the caller domain. Resolves:#1160339 - Make plymouthd as nsswitch domain to make it working with sssd. Resolves:#1160196 - Make drbd as nsswitch domain to make it working with sssd. - Make conman as nsswitch domain to make ipmitool.exp runing as conman_t working. - Add support for /var/lib/sntp directory. - Add fixes to allow docker to create more content in tmpfs ,and donaudit reading /proc - Allow winbind to read usermodehelper - Allow telepathy domains to execute shells and bin_t - Allow gpgdomains to create netlink_kobject_uevent_sockets - Allow mongodb to bind to the mongo port and mongos to run as mongod_t - Allow abrt to read software raid state. - Allow nslcd to execute netstat. - Allow dovecot to create user's home directory when they log into IMAP. - Allow login domains to create kernel keyring with different level.- Allow modemmanger to connectto itself Resolves:#1120152 - Allow pki_tomcat to create link files in /var/lib/pki-ca. Resolves:#1121744 - varnishd needs to have fsetid capability Resolves:#1125165 - Allow snapperd to dbus chat with system cron jobs. Resolves:#1152447 - Allow dovecot to create user's home directory when they log into IMAP Resolves:#1152773 - Add labeling for /usr/sbin/haproxy-systemd-wrapper wrapper to make haproxy running haproxy_t. - ALlow listen and accept on tcp socket for init_t in MLS. Previously it was for xinetd_t. - Allow nslcd to execute netstat. - Add suppor for keepalived unconfined scripts and allow keepalived to read all domain state and kill capability. - Allow nslcd to read /dev/urandom.- Add back kill permisiion for system class Resolves:#1150011- Add back kill permisiion for service class Resolves:#1150011 - Make rhsmcertd_t also as dbus domain. - Allow named to create DNS_25 with correct labeling. - Add cloudform_dontaudit_write_cloud_log() - Call auth_use_nsswitch to apache to read/write cloud-init keys. - Allow cloud-init to dbus chat with certmonger. - Fix path to mon_statd_initrc_t script. - Allow all RHCS services to read system state. - Allow dnssec_trigger_t to execute unbound-control in own domain. - kernel_read_system_state needs to be called with type. Moved it to antivirus.if. - Added policy for mon_statd and mon_procd services. BZ (1077821) - Allow opensm_t to read/write /dev/infiniband/umad1. - Allow mongodb to manage own log files. - Allow neutron connections to system dbus. - Add support for /var/lib/swiftdirectory. - Allow nova-scheduler to read certs. - Allow openvpn to access /sys/fs/cgroup dir. - Allow openvpn to execute systemd-passwd-agent in systemd_passwd_agent_t to make openvpn working with systemd. - Fix samba_export_all_ro/samba_export_all_rw booleans to dontaudit search/read security files. - Add auth_use_nsswitch for portreserve to make it working with sssd. - automount policy is non-base module so it needs to be called in optional block. - ALlow sensord to getattr on sysfs. - Label /usr/share/corosync/corosync as cluster_exec_t. - Allow lmsd_plugin to read passwd file. BZ(1093733) - Allow read antivirus domain all kernel sysctls. - Allow mandb to getattr on file systems - Allow nova-console to connect to mem_cache port. - Make sosreport as unconfined domain. - Allow mondogdb to 'accept' accesses on the tcp_socket port. - ALlow sanlock to send a signal to virtd_t.- Build also MLS policy Resolves:#1138424- Add back kill permisiion for system class - Allow iptables read fail2ban logs. - Fix radius labeled ports - Add userdom_manage_user_tmpfs_files interface - Allow libreswan to connect to VPN via NM-libreswan. - Label 4101 tcp port as brlp port - fix dev_getattr_generic_usb_dev interface - Allow all domains to read fonts - Make sure /run/systemd/generator and system is labeled correctly on creation. - Dontaudit aicuu to search home config dir. - Make keystone_cgi_script_t domain. Resolves:#1138424 - Fix bug in drbd policy, - Added support for cpuplug. - ALlow sanlock_t to read sysfs_t. - Added sendmail_domtrans_unconfined interface - Fix broken interfaces - radiusd wants to write own log files. - Label /usr/libexec/rhsmd as rhsmcertd_exec_t - Allow rhsmcertd send signull to setroubleshoot. - Allow rhsmcertd manage rpm db. - Added policy for blrtty. - Fix keepalived policy - Allow rhev-agentd dbus chat with systemd-logind. - Allow keepalived manage snmp var lib sock files. - Add support for /var/lib/graphite-web - Allow NetworkManager to create Bluetooth SDP sockets - It's going to do the the discovery for DUN service for modems with Bluez 5. - Allow swift to connect to all ephemeral ports by default. - Allow sssd to read selinux config to add SELinux user mapping. - Allow lsmd to search own plguins. - Allow abrt to read /dev/memto generate an unique machine_id and uses sosuploader's algorithm based off dmidecode[1] fields. - ALlow zebra for user/group look-ups. - Allow nova domains to getattr on all filesystems. - Allow collectd sys_ptrace and dac_override caps because of reading of /proc/%i/io for several processes. - Allow pppd to connect to /run/sstpc/sstpc-nm-sstp-service-28025 over unix stream socket. - Allow rhnsd_t to manage also rhnsd config symlinks. - ALlow user mail domains to create dead.letter. - Allow rabbitmq_t read rabbitmq_var_lib_t lnk files. - Allow pki-tomcat to change SELinux object identity. - Allow radious to connect to apache ports to do OCSP check - Allow git cgi scripts to create content in /tmp - Allow cockpit-session to do GSSAPI logins. - Allow sensord read in /proc - Additional access required by usbmuxd- Allow locate to look at files/directories without labels, and chr_file and blk_file on non dev file systems - Label /usr/lib/erlang/erts.*/bin files as bin_t - Add files_dontaudit_access_check_home_dir() inteface. - Allow udev_t mounton udev_var_run_t dirs #(1128618) - Add systemd_networkd_var_run_t labeling for /var/run/systemd/netif and allow systemd-networkd to manage it. - Add init_dontaudit_read_state() interface. - Add label for ~/.local/share/fonts - Allow unconfined_r to access unconfined_service_t. - Allow init to read all config files - Add new interface to allow creation of file with lib_t type - Assign rabbitmq port. - Allow unconfined_service_t to dbus chat with all dbus domains - Add new interfaces to access users keys. - Allow domains to are allowed to mounton proc to mount on files as well as dirs - Fix labeling for HOME_DIR/tmp and HOME_DIR/.tmp directories. - Add a port definition for shellinaboxd - Label ~/tmp and ~/.tmp directories in user tmp dirs as user_tmp_t - Allow userdomains to stream connect to pcscd for smart cards - Allow programs to use pam to search through user_tmp_t dires (/tmp/.X11-unix) - Update to rawhide-contrib changes Resolves:#1123844- Rebase to 3.13.1 which we have in Fedora21 Resolves:#1128284- Back port fixes from Fedora. Mainly OpenStack and Docker fixes- Add policy-rhel-7.1-{base,contrib} patches- Add support for us_cli ports - Fix labeling for /var/run/user//gvfs - add support for tcp/9697 - Additional rules required by openstack, needs backport to F20 and RHEL7 - Additional access required by docker - ALlow motion to use tcp/8082 port - Allow init_t to setattr/relabelfrom dhcp state files - Dontaudit antivirus domains read access on all security files by default - Add missing alias for old amavis_etc_t type - Allow block_suspend cap for haproxy - Additional fixes for instack overcloud - Allow OpenStack to read mysqld_db links and connect to MySQL - Remove dup filename rules in gnome.te - Allow sys_chroot cap for httpd_t and setattr on httpd_log_t - Allow iscsid to handle own unit files - Add iscsi_systemctl() - Allow mongod to create also sock_files in /run with correct labeling - Allow httpd to send signull to apache script domains and don't audit leaks - Allow rabbitmq_beam to connect to httpd port - Allow aiccu stream connect to pcscd - Allow dmesg to read hwdata and memory dev - Allow all freeipmi domains to read/write ipmi devices - Allow sblim_sfcbd to use also pegasus-https port - Allow rabbitmq_epmd to manage rabbit_var_log_t files - Allow chronyd to read /sys/class/hwmon/hwmon1/device/temp2_input - Allow docker to status any unit file and allow it to start generic unit files- Change hsperfdata_root to have as user_tmp_t Resolves:#1076523- Fix Multiple same specifications for /var/named/chroot/dev/zero - Add labels for /var/named/chroot_sdb/dev devices - Add support for strongimcv - Use kerberos_keytab_domains in auth_use_nsswitch - Update auth_use_nsswitch to make all these types as kerberos_keytab_domain to - Allow net_raw cap for neutron_t and send sigkill to dnsmasq - Fix ntp_filetrans_named_content for sntp-kod file - Add httpd_dbus_sssd boolean - Dontaudit exec insmod in boinc policy - Rename kerberos_keytab_domain to kerberos_keytab_domains - Add kerberos_keytab_domain() - Fix kerberos_keytab_template() - Make all domains which use kerberos as kerberos_keytab_domain Resolves:#1083670 - Allow kill capability to winbind_t- varnishd wants chown capability - update ntp_filetrans_named_content() interface - Add additional fixes for neutron_t. #1083335 - Dontaudit getattr on proc_kcore_t - Allow pki_tomcat_t to read ipa lib files - Allow named_filetrans_domain to create /var/cache/ibus with correct labelign - Allow init_t run /sbin/augenrules - Add dev_unmount_sysfs_fs and sysnet_manage_ifconfig_run interfaces - Allow unpriv SELinux user to use sandbox - Add default label for /tmp/hsperfdata_root- Add file subs also for /var/home- Allow xauth_t to read user_home_dir_t lnk_file - Add labeling for lightdm-data - Allow certmonger to manage ipa lib files - Add support for /var/lib/ipa - Allow pegasus to getattr virt_content - Added some new rules to pcp policy - Allow chrome_sandbox to execute config_home_t - Add support for ABRT FAF- Allow kdm to send signull to remote_login_t process - Add gear policy - Turn on gear_port_t - Allow cgit to read gitosis lib files by default - Allow vdagent to read xdm state - Allow NM and fcoeadm to talk together over unix_dgram_socket- Back port fixes for pegasus_openlmi_admin_t from rawhide Resolves:#1080973 - Add labels for ostree - Add SELinux awareness for NM - Label /usr/sbin/pwhistory_helper as updpwd_exec_t- add gnome_append_home_config() - Allow thumb to append GNOME config home files - Allow rasdaemon to rw /dev/cpu//msr - fix /var/log/pki file spec - make bacula_t as auth_nsswitch domain - Identify pki_tomcat_cert_t as a cert_type - Define speech-dispater_exec_t as an application executable - Add a new file context for /var/named/chroot/run directory - update storage_filetrans_all_named_dev for sg* devices - Allow auditctl_t to getattr on all removeable devices - Allow nsswitch_domains to stream connect to nmbd - Allow unprivusers to connect to memcached - label /var/lib/dirsrv/scripts-INSTANCE as bin_t- Allow also unpriv user to run vmtools - Allow secadm to read /dev/urandom and meminfo Resolves:#1079250 - Add booleans to allow docker processes to use nfs and samba - Add mdadm_tmpfs support - Dontaudit net_amdin for /usr/lib/jvm/java-1.7.0-openjdk-1.7.0.51-2.4.5.1.el7.x86_64/jre-abrt/bin/java running as pki_tomcat_t - Allow vmware-user-sui to use user ttys - Allow talk 2 users logged via console too - Allow ftp services to manage xferlog_t - Make all pcp domanis as unconfined for RHEL7.0 beucause of new policies - allow anaconda to dbus chat with systemd-localed- allow anaconda to dbus chat with systemd-localed - Add fixes for haproxy based on bperkins@redhat.com - Allow cmirrord to make dmsetup working - Allow NM to execute arping - Allow users to send messages through talk - Add userdom_tmp_role for secadm_t- Add additional fixes for rtas_errd - Fix transitions for tmp/tmpfs in rtas.te - Allow rtas_errd to readl all sysctls- Add support for /var/spool/rhsm/debug - Make virt_sandbox_use_audit as True by default - Allow svirt_sandbox_domains to ptrace themselves- Allow docker containers to manage /var/lib/docker content- Allow docker to read tmpfs_t symlinks - Allow sandbox svirt_lxc_net_t to talk to syslog and to sssd over stream sockets- Allow collectd to talk to libvirt - Allow chrome_sandbox to use leaked unix_stream_sockets - Dontaudit leaks of sockets into chrome_sandbox_t - If you create a cups directory in /var/cache then it should be labeled cups_rw_etc_t - Run vmtools as unconfined domains - Allow snort to manage its log files - Allow systemd_cronjob_t to be entered via bin_t - Allow procman to list doveconf_etc_t - allow keyring daemon to create content in tmpfs directories - Add proper labelling for icedtea-web - vpnc is creating content in networkmanager var run directory - Label sddm as xdm_exec_t to make KDE working again - Allow postgresql to read network state - Allow java running as pki_tomcat to read network sysctls - Fix cgroup.te to allow cgred to read cgconfig_etc_t - Allow beam.smp to use ephemeral ports - Allow winbind to use the nis to authenticate passwords- Make rtas_errd_t as unconfined domain for F20.It needs additional fixes. It runs rpm at least. - Allow net_admin cap for fence_virtd running as fenced_t - Make abrt-java-connector working - Make cimtest script 03_defineVS.py of ComputerSystem group working - Fix git_system_enable_homedirs boolean - Allow munin mail plugins to read network systcl- Allow vmtools_helper_t to execute bin_t - Add support for /usr/share/joomla - /var/lib/containers should be labeled as openshift content for now - Allow docker domains to talk to the login programs, to allow a process to login into the container - Allow install_t do dbus chat with NM - Fix interface names in anaconda.if - Add install_t for anaconda. A new type is a part of anaconda policy - sshd to read network sysctls- Allow zabbix to send system log msgs - Allow init_t to stream connect to ipsec Resolves:#1060775- Add docker_connect_any boolean- Allow unpriv SELinux users to dbus chat with firewalld - Add lvm_write_metadata() - Label /etc/yum.reposd dir as system_conf_t. Should be safe because system_conf_t is base_ro_file_type - Allow pegasus_openlmi_storage_t to write lvm metadata - Add hide_broken_symptoms for kdumpgui because of systemd bug - Make kdumpgui_t as unconfined domain Resolves:#1044299 - Allow docker to connect to tcp/5000- Allow numad to write scan_sleep_millisecs - Turn on entropyd_use_audio boolean by default - Allow cgred to read /etc/cgconfig.conf because it contains templates used together with rules from /etc/cgrules.conf. - Allow lscpu running as rhsmcertd_t to read /proc/sysinfo - Fix label on irclogs in the homedir - Allow kerberos_keytab_domain domains to manage keys until we get sssd fix - Allow postgresql to use ldap - Add missing syslog-conn port - Add support for /dev/vmcp and /dev/sclp Resolves:#1069310- Modify xdm_write_home to allow create files/links in /root with xdm_home_ - Allow virt domains to read network state Resolves:#1072019- Added pcp rules - dontaudit openshift_cron_t searching random directories, should be back ported to RHEL6 - clean up ctdb.te - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow certmonger to list home dirs- Change userdom_use_user_inherited_ttys to userdom_use_user_ttys for systemd-tty-ask - Add sysnet_filetrans_named_content_ifconfig() interface - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow kerberos keytab domains to manage sssd/userdomain keys" - Allow to run ip cmd in neutron_t domain- Allow block_suspend cap2 for systemd-logind and rw dri device - Add labeling for /usr/libexec/nm-libreswan-service - Allow locallogin to rw xdm key to make Virtual Terminal login providing smartcard pin working - Add xserver_rw_xdm_keys() - Allow rpm_script_t to dbus chat also with systemd-located - Fix ipa_stream_connect_otpd() - update lpd_manage_spool() interface - Allow krb5kdc to stream connect to ipa-otpd - Add ipa_stream_connect_otpd() interface - Allow vpnc to unlink NM pids - Add networkmanager_delete_pid_files() - Allow munin plugins to access unconfined plugins - update abrt_filetrans_named_content to cover /var/spool/debug - Label /var/spool/debug as abrt_var_cache_t - Allow rhsmcertd to connect to squid port - Make docker_transition_unconfined as optional boolean - Allow certmonger to list home dirs- Make snapperd as unconfined domain and add additional fixes for it - Remove nsplugin.pp module on upgrade- Add snapperd_home_t for HOME_DIR/.snapshots directory - Make sosreport as unconfined domain - Allow sosreport to execute grub2-probe - Allow NM to manage hostname config file - Allow systemd_timedated_t to dbus chat with rpm_script_t - Allow lsmd plugins to connect to http/ssh/http_cache ports by default - Add lsmd_plugin_connect_any boolean - Allow mozilla_plugin to attempt to set capabilities - Allow lsdm_plugins to use tcp_socket - Dontaudit mozilla plugin from getattr on /proc or /sys - Dontaudit use of the keyring by the services in a sandbox - Dontaudit attempts to sys_ptrace caused by running ps for mysqld_safe_t - Allow rabbitmq_beam to connect to jabber_interserver_port - Allow logwatch_mail_t to transition to qmail_inject and queueu - Added new rules to pcp policy - Allow vmtools_helper_t to change role to system_r - Allow NM to dbus chat with vmtools - Fix couchdb_manage_files() to allow manage couchdb conf files - Add support for /var/run/redis.sock - dontaudit gpg trying to use audit - Allow consolekit to create log directories and files - Fix vmtools policy to allow user roles to access vmtools_helper_t - Allow block_suspend cap2 for ipa-otpd - Allow pkcsslotd to read users state - Add ioctl to init_dontaudit_rw_stream_socket - Add systemd_hostnamed_manage_config() interface - Remove transition for temp dirs created by init_t - gdm-simple-slave uses use setsockopt - sddm-greater is a xdm type program- Add lvm_read_metadata() - Allow auditadm to search /var/log/audit dir - Add lvm_read_metadata() interface - Allow confined users to run vmtools helpers - Fix userdom_common_user_template() - Generic systemd unit scripts do write check on / - Allow init_t to create init_tmp_t in /tmp.This is for temporary content created by generic unit files - Add additional fixes needed for init_t and setup script running in generic unit files - Allow general users to create packet_sockets - added connlcli port - Add init_manage_transient_unit() interface - Allow init_t (generic unit files) to manage rpc state date as we had it for initrc_t - Fix userdomain.te to require passwd class - devicekit_power sends out a signal to all processes on the message bus when power is going down - Dontaudit rendom domains listing /proc and hittping system_map_t - Dontauit leaks of var_t into ifconfig_t - Allow domains that transition to ssh_t to manipulate its keyring - Define oracleasm_t as a device node - Change to handle /root as a symbolic link for os-tree - Allow sysadm_t to create packet_socket, also move some rules to attributes - Add label for openvswitch port - Remove general transition for files/dirs created in /etc/mail which got etc_aliases_t label. - Allow postfix_local to read .forward in pcp lib files - Allow pegasus_openlmi_storage_t to read lvm metadata - Add additional fixes for pegasus_openlmi_storage_t - Allow bumblebee to manage debugfs - Make bumblebee as unconfined domain - Allow snmp to read etc_aliases_t - Allow lscpu running in pegasus_openlmi_storage_t to read /dev/mem - Allow pegasus_openlmi_storage_t to read /proc/1/environ - Dontaudit read gconf files for cupsd_config_t - make vmtools as unconfined domain - Add vmtools_helper_t for helper scripts. Allow vmtools shutdonw a host and run ifconfig. - Allow collectd_t to use a mysql database - Allow ipa-otpd to perform DNS name resolution - Added new policy for keepalived - Allow openlmi-service provider to manage transitient units and allow stream connect to sssd - Add additional fixes new pscs-lite+polkit support - Add labeling for /run/krb5kdc - Change w3c_validator_tmp_t to httpd_w3c_validator_tmp_t in F20 - Allow pcscd to read users proc info - Dontaudit smbd_t sending out random signuls - Add boolean to allow openshift domains to use nfs - Allow w3c_validator to create content in /tmp - zabbix_agent uses nsswitch - Allow procmail and dovecot to work together to deliver mail - Allow spamd to execute files in homedir if boolean turned on - Allow openvswitch to listen on port 6634 - Add net_admin capability in collectd policy - Fixed snapperd policy - Fixed bugsfor pcp policy - Allow dbus_system_domains to be started by init - Fixed some interfaces - Add kerberos_keytab_domain attribute - Fix snapperd_conf_t def- Addopt corenet rules for unbound-anchor to rpm_script_t - Allow runuser to send send audit messages. - Allow postfix-local to search .forward in munin lib dirs - Allow udisks to connect to D-Bus - Allow spamd to connect to spamd port - Fix syntax error in snapper.te - Dontaudit osad to search gconf home files - Allow rhsmcertd to manage /etc/sysconf/rhn director - Fix pcp labeling to accept /usr/bin for all daemon binaries - Fix mcelog_read_log() interface - Allow iscsid to manage iscsi lib files - Allow snapper domtrans to lvm_t. Add support for /etc/snapper and allow snapperd to manage it. - Make tuned_t as unconfined domain for RHEL7.0 - Allow ABRT to read puppet certs - Add sys_time capability for virt-ga - Allow gemu-ga to domtrans to hwclock_t - Allow additional access for virt_qemu_ga_t processes to read system clock and send audit messages - Fix some AVCs in pcp policy - Add to bacula capability setgid and setuid and allow to bind to bacula ports - Changed label from rhnsd_rw_conf_t to rhnsd_conf_t - Add access rhnsd and osad to /etc/sysconfig/rhn - drbdadm executes drbdmeta - Fixes needed for docker - Allow epmd to manage /var/log/rabbitmq/startup_err file - Allow beam.smp connect to amqp port - Modify xdm_write_home to allow create also links as xdm_home_t if the boolean is on true - Allow init_t to manage pluto.ctl because of init_t instead of initrc_t - Allow systemd_tmpfiles_t to manage all non security files on the system - Added labels for bacula ports - Fix label on /dev/vfio/vfio - Add kernel_mounton_messages() interface - init wants to manage lock files for iscsi- Added osad policy - Allow postfix to deliver to procmail - Allow bumblebee to seng kill signal to xserver - Allow vmtools to execute /usr/bin/lsb_release - Allow docker to write system net ctrls - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix pcp.te - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl- Turn on bacula, rhnsd policy - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl - Fixes for *_admin interfaces - Add pegasus_openlmi_storage_var_run_t type def - Add support for /var/run/openlmi-storage - Allow tuned to create syslog.conf with correct labeling - Add httpd_dontaudit_search_dirs boolean - Add support for winbind.service - ALlow also fail2ban-client to read apache logs - Allow vmtools to getattr on all fs - Add support for dey_sapi port - Add logging_filetrans_named_conf() - Allow passwd_t to use ipc_lock, so that it can change the password in gnome-keyring- Update snapper policy - Allow domains to append rkhunter lib files - Allow snapperd to getattr on all fs - Allow xdm to create /var/gdm with correct labeling - Add label for snapper.log - Allow fail2ban-client to read apache log files - Allow thumb_t to execute dbus-daemon in thumb_t- Allow gdm to create /var/gdm with correct labeling - Allow domains to append rkhunterl lib files. #1057982 - Allow systemd_tmpfiles_t net_admin to communicate with journald - Add interface to getattr on an isid_type for any type of file - Update libs_filetrans_named_content() to have support for /usr/lib/debug directory - Allow initrc_t domtrans to authconfig if unconfined is enabled - Allow docker and mount on devpts chr_file - Allow docker to transition to unconfined_t if boolean set - init calling needs to be optional in domain.te - Allow uncofined domain types to handle transient unit files - Fix labeling for vfio devices - Allow net_admin capability and send system log msgs - Allow lldpad send dgram to NM - Add networkmanager_dgram_send() - rkhunter_var_lib_t is correct type - Back port pcp policy from rawhide - Allow openlmi-storage to read removable devices - Allow system cron jobs to manage rkhunter lib files - Add rkhunter_manage_lib_files() - Fix ftpd_use_fusefs boolean to allow manage also symlinks - Allow smbcontrob block_suspend cap2 - Allow slpd to read network and system state info - Allow NM domtrans to iscsid_t if iscsiadm is executed - Allow slapd to send a signal itself - Allow sslget running as pki_ra_t to contact port 8443, the secure port of the CA. - Fix plymouthd_create_log() interface - Add rkhunter policy with files type definition for /var/lib/rkhunter until it is fixed in rkhunter package - Add mozilla_plugin_exec_t for /usr/lib/firefox/plugin-container - Allow postfix and cyrus-imapd to work out of box - Allow fcoemon to talk with unpriv user domain using unix_stream_socket - Dontaudit domains that are calling into journald to net_admin - Add rules to allow vmtools to do what it does - snapperd is D-Bus service - Allow OpenLMI PowerManagement to call 'systemctl --force reboot' - Add haproxy_connect_any boolean - Allow haproxy also to use http cache port by default Resolves:#1058248- Allow apache to write to the owncloud data directory in /var/www/html... - Allow consolekit to create log dir - Add support for icinga CGI scripts - Add support for icinga - Allow kdumpctl_t to create kdump lock file Resolves:#1055634 - Allow kdump to create lnk lock file - Allow nscd_t block_suspen capability - Allow unconfined domain types to manage own transient unit file - Allow systemd domains to handle transient init unit files - Add interfaces to handle transient- Add cron unconfined role support for uncofined SELinux user - Call corenet_udp_bind_all_ports() in milter.te - Allow fence_virtd to connect to zented port - Fix header for mirrormanager_admin() - Allow dkim-milter to bind udp ports - Allow milter domains to send signull itself - Allow block_suspend for yum running as mock_t - Allow beam.smp to manage couchdb files - Add couchdb_manage_files() - Add labeling for /var/log/php_errors.log - Allow bumblebee to stream connect to xserver - Allow bumblebee to send a signal to xserver - gnome-thumbnail to stream connect to bumblebee - Allow xkbcomp running as bumblebee_t to execute bin_t - Allow logrotate to read squid.conf - Additional rules to get docker and lxc to play well with SELinux - Allow bumbleed to connect to xserver port - Allow pegasus_openlmi_storage_t to read hwdata- Allow init_t to work on transitient and snapshot unit files - Add logging_manage_syslog_config() - Update sysnet_dns_name_resolve() to allow connect to dnssec por - Allow pegasus_openlmi_storage_t to read hwdata Resolves:#1031721 - Fix rhcs_rw_cluster_tmpfs() - Allow fenced_t to bind on zented udp port - Added policy for vmtools - Fix mirrormanager_read_lib_files() - Allow mirromanager scripts running as httpd_t to manage mirrormanager pid files - Allow ctdb to create sock files in /var/run/ctdb - Add sblim_filetrans_named_content() interface - Allow rpm scritplets to create /run/gather with correct labeling - Allow gnome keyring domains to create gnome config dirs - Dontaudit read/write to init stream socket for lsmd_plugin_t - Allow automount to read nfs link files - Allow lsm plugins to read/write lsmd stream socket - Allow certmonger to connect ldap port to make IPA CA certificate renewal working. - Add also labeling for /var/run/ctdb - Add missing labeling for /var/lib/ctdb - ALlow tuned to manage syslog.conf. Should be fixed in tuned. #1030446 - Dontaudit hypervkvp to search homedirs - Dontaudit hypervkvp to search admin homedirs - Allow hypervkvp to execute bin_t and ifconfig in the caller domain - Dontaudit xguest_t to read ABRT conf files - Add abrt_dontaudit_read_config() - Allow namespace-init to getattr on fs - Add thumb_role() also for xguest - Add filename transitions to create .spamassassin with correct labeling - Allow apache domain to read mirrormanager pid files - Allow domains to read/write shm and sem owned by mozilla_plugin_t - Allow alsactl to send a generic signal to kernel_t- Add back rpm_run() for unconfined user- Add missing files_create_var_lib_dirs() - Fix typo in ipsec.te - Allow passwd to create directory in /var/lib - Add filename trans also for event21 - Allow iptables command to read /dev/rand - Add sigkill capabilityfor ipsec_t - Add filename transitions for bcache devices - Add additional rules to create /var/log/cron by syslogd_t with correct labeling - Add give everyone full access to all key rings - Add default lvm_var_run_t label for /var/run/multipathd - Fix log labeling to have correct default label for them after logrotate - Labeled ~/.nv/GLCache as being gstreamer output - Allow nagios_system_plugin to read mrtg lib files - Add mrtg_read_lib_files() - Call rhcs_rw_cluster_tmpfs for dlm_controld - Make authconfing as named_filetrans domain - Allow virsh to connect to user process using stream socket - Allow rtas_errd to read rand/urand devices and add chown capability - Fix labeling from /var/run/net-snmpd to correct /var/run/net-snmp Resolves:#1051497 - Add also chown cap for abrt_upload_watch_t. It already has dac_override - Allow sosreport to manage rhsmcertd pid files - Add rhsmcertd_manage_pid_files() - Allow also setgid cap for rpc.gssd - Dontaudit access check for abrt on cert_t - Allow pegasus_openlmi_system providers to dbus chat with systemd-logind- Fix semanage import handling in spec file- Add default lvm_var_run_t label for /var/run/multipathd Resolves:#1051430 - Fix log labeling to have correct default label for them after logrotate - Add files_write_root_dirs - Add new openflow port label for 6653/tcp and 6633/tcp - Add xserver_manage_xkb_libs() - Label tcp/8891 as milter por - Allow gnome_manage_generic_cache_files also create cache_home_t files - Fix aide.log labeling - Fix log labeling to have correct default label for them after logrotate - Allow mysqld-safe write access on /root to make mysqld working - Allow sosreport domtrans to prelikn - Allow OpenvSwitch to connec to openflow ports - Allow NM send dgram to lldpad - Allow hyperv domains to execute shell - Allow lsmd plugins stream connect to lsmd/init - Allow sblim domains to create /run/gather with correct labeling - Allow httpd to read ldap certs - Allow cupsd to send dbus msgs to process with different MLS level - Allow bumblebee to stream connect to apmd - Allow bumblebee to run xkbcomp - Additional allow rules to get libvirt-lxc containers working with docker - Additional allow rules to get libvirt-lxc containers working with docker - Allow docker to getattr on itself - Additional rules needed for sandbox apps - Allow mozilla_plugin to set attributes on usb device if use_spice boolean enabled - httpd should be able to send signal/signull to httpd_suexec_t - Add more fixes for neturon. Domtrans to dnsmasq, iptables. Make neutron as filenamtrans domain.- Add neutron fixes- Allow sshd to write to all process levels in order to change passwd when running at a level - Allow updpwd_t to downgrade /etc/passwd file to s0, if it is not running with this range - Allow apcuspd_t to status and start the power unit file - Allow udev to manage kdump unit file - Added new interface modutils_dontaudit_exec_insmod - Allow cobbler to search dhcp_etc_t directory - systemd_systemctl needs sys_admin capability - Allow sytemd_tmpfiles_t to delete all directories - passwd to create gnome-keyring passwd socket - Add missing zabbix_var_lib_t type - Fix filename trans for zabbixsrv in zabbix.te - Allow fprintd_t to send syslog messages - Add zabbix_var_lib_t for /var/lib/zabbixsrv, also allow zabix to connect to smtp port - Allow mozilla plugin to chat with policykit, needed for spice - Allow gssprozy to change user and gid, as well as read user keyrings - Label upgrades directory under /var/www as httpd_sys_rw_content_t, add other filetrans rules to label content correctly - Allow polipo to connect to http_cache_ports - Allow cron jobs to manage apache var lib content - Allow yppassword to manage the passwd_file_t - Allow showall_t to send itself signals - Allow cobbler to restart dhcpc, dnsmasq and bind services - Allow certmonger to manage home cert files - Add userdom filename trans for user mail domains - Allow apcuspd_t to status and start the power unit file - Allow cgroupdrulesengd to create content in cgoups directories - Allow smbd_t to signull cluster - Allow gluster daemon to create fifo files in glusterd_brick_t and sock_file in glusterd_var_lib_t - Add label for /var/spool/cron.aquota.user - Allow sandbox_x domains to use work with the mozilla plugin semaphore - Added new policy for speech-dispatcher - Added dontaudit rule for insmod_exec_t in rasdaemon policy - Updated rasdaemon policy - Allow system_mail_t to transition to postfix_postdrop_t - Clean up mirrormanager policy - Allow virt_domains to read cert files, needs backport to RHEL7 - Allow sssd to read systemd_login_var_run_t - Allow irc_t to execute shell and bin-t files: - Add new access for mythtv - Allow rsync_t to manage all non auth files - allow modemmanger to read /dev/urand - Allow sandbox apps to attempt to set and get capabilties- Add labeling for /var/lib/servicelog/servicelog.db-journal - Add support for freeipmi port - Add sysadm_u_default_contexts - Make new type to texlive files in homedir - Allow subscription-manager running as sosreport_t to manage rhsmcertd - Additional fixes for docker.te - Remove ability to do mount/sys_admin by default in virt_sandbox domains - New rules required to run docker images within libivrt - Add label for ~/.cvsignore - Change mirrormanager to be run by cron - Add mirrormanager policy - Fixed bumblebee_admin() and mip6d_admin() - Add log support for sensord - Fix typo in docker.te - Allow amanda to do backups over UDP - Allow bumblebee to read /etc/group and clean up bumblebee.te - type transitions with a filename not allowed inside conditionals - Don't allow virt-sandbox tools to use netlink out of the box, needs back port to RHEL7 - Make new type to texlive files in homedir- Allow freeipmi_ipmidetectd_t to use freeipmi port - Update freeipmi_domain_template() - Allow journalctl running as ABRT to read /run/log/journal - Allow NM to read dispatcher.d directory - Update freeipmi policy - Type transitions with a filename not allowed inside conditionals - Allow tor to bind to hplip port - Make new type to texlive files in homedir - Allow zabbix_agent to transition to dmidecode - Add rules for docker - Allow sosreport to send signull to unconfined_t - Add virt_noatsecure and virt_rlimitinh interfaces - Fix labeling in thumb.fc to add support for /usr/lib64/tumbler-1/tumblerddd support for freeipmi port - Add sysadm_u_default_contexts - Add logging_read_syslog_pid() - Fix userdom_manage_home_texlive() interface - Make new type to texlive files in homedir - Add filename transitions for /run and /lock links - Allow virtd to inherit rlimit information Resolves:#975358- Change labeling for /usr/libexec/nm-dispatcher.action to NetworkManager_exec_t Resolves:#1039879 - Add labeling for /usr/lib/systemd/system/mariadb.service - Allow hyperv_domain to read sysfs - Fix ldap_read_certs() interface to allow acess also link files - Add support for /usr/libexec/pegasus/cmpiLMI_Journald-cimprovagt - Allow tuned to run modprobe - Allow portreserve to search /var/lib/sss dir - Add SELinux support for the teamd package contains team network device control daemon. - Dontaudit access check on /proc for bumblebee - Bumblebee wants to load nvidia modules - Fix rpm_named_filetrans_log_files and wine.te - Add conman policy for rawhide - DRM master and input event devices are used by the TakeDevice API - Clean up bumblebee policy - Update pegasus_openlmi_storage_t policy - Add freeipmi_stream_connect() interface - Allow logwatch read madm.conf to support RAID setup - Add raid_read_conf_files() interface - Allow up2date running as rpm_t create up2date log file with rpm_log_t labeling - add rpm_named_filetrans_log_files() interface - Allow dkim-milter to create files/dirs in /tmp - update freeipmi policy - Add policy for freeipmi services - Added rdisc_admin and rdisc_systemctl interfaces - opensm policy clean up - openwsman policy clean up - ninfod policy clean up - Added new policy for ninfod - Added new policy for openwsman - Added rdisc_admin and rdisc_systemctl interfaces - Fix kernel_dontaudit_access_check_proc() - Add support for /dev/uhid - Allow sulogin to get the attributes of initctl and sys_admin cap - Add kernel_dontaudit_access_check_proc() - Fix dev_rw_ipmi_dev() - Fix new interface in devices.if - DRM master and input event devices are used by the TakeDevice API - add dev_rw_inherited_dri() and dev_rw_inherited_input_dev() - Added support for default conman port - Add interfaces for ipmi devices- Allow sosreport to send a signal to ABRT - Add proper aliases for pegasus_openlmi_service_exec_t and pegasus_openlmi_service_t - Label /usr/sbin/htcacheclean as httpd_exec_t Resolves:#1037529 - Added support for rdisc unit file - Add antivirus_db_t labeling for /var/lib/clamav-unofficial-sigs - Allow runuser running as logrotate connections to system DBUS - Label bcache devices as fixed_disk_device_t - Allow systemctl running in ipsec_mgmt_t to access /usr/lib/systemd/system/ipsec.service - Label /usr/lib/systemd/system/ipsec.service as ipsec_mgmt_unit_file_t- Add back setpgid/setsched for sosreport_t- Added fix for clout_init to transition to rpm_script_t (dwalsh@redhat.com)- Dontaudit openshift domains trying to use rawip_sockets, this is caused by a bad check in the kernel. - Allow git_system_t to read git_user_content if the git_system_enable_homedirs boolean is turned on - Add lsmd_plugin_t for lsm plugins - Allow dovecot-deliver to search mountpoints - Add labeling for /etc/mdadm.conf - Allow opelmi admin providers to dbus chat with init_t - Allow sblim domain to read /dev/urandom and /dev/random - Allow apmd to request the kernel load modules - Add glusterd_brick_t type - label mate-keyring-daemon with gkeyringd_exec_t - Add plymouthd_create_log() - Dontaudit leaks from openshift domains into mail domains, needs back port to RHEL6 - Allow sssd to request the kernel loads modules - Allow gpg_agent to use ssh-add - Allow gpg_agent to use ssh-add - Dontaudit access check on /root for myslqd_safe_t - Allow ctdb to getattr on al filesystems - Allow abrt to stream connect to syslog - Allow dnsmasq to list dnsmasq.d directory - Watchdog opens the raw socket - Allow watchdog to read network state info - Dontaudit access check on lvm lock dir - Allow sosreport to send signull to setroubleshootd - Add setroubleshoot_signull() interface - Fix ldap_read_certs() interface - Allow sosreport all signal perms - Allow sosreport to run systemctl - Allow sosreport to dbus chat with rpm - Add glusterd_brick_t files type - Allow zabbix_agentd to read all domain state - Clean up rtas.if - Allow smoltclient to execute ldconfig - Allow sosreport to request the kernel to load a module - Fix userdom_confined_admin_template() - Add back exec_content boolean for secadm, logadm, auditadm - Fix files_filetrans_system_db_named_files() interface - Allow sulogin to getattr on /proc/kcore - Add filename transition also for servicelog.db-journal - Add files_dontaudit_access_check_root() - Add lvm_dontaudit_access_check_lock() interface- Allow watchdog to read /etc/passwd - Allow browser plugins to connect to bumblebee - New policy for bumblebee and freqset - Add new policy for mip6d daemon - Add new policy for opensm daemon - Allow condor domains to read/write condor_master udp_socket - Allow openshift_cron_t to append to openshift log files, label /var/log/openshift - Add back file_pid_filetrans for /var/run/dlm_controld - Allow smbd_t to use inherited tmpfs content - Allow mcelog to use the /dev/cpu device - sosreport runs rpcinfo - sosreport runs subscription-manager - Allow staff_t to run frequency command - Allow systemd_tmpfiles to relabel log directories - Allow staff_t to read xserver_log file - Label hsperfdata_root as tmp_t- More sosreport fixes to make ABRT working- Fix files_dontaudit_unmount_all_mountpoints() - Add support for 2608-2609 tcp/udp ports - Should allow domains to lock the terminal device - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - We need to require passwd rootok - Fix zebra.fc - Fix dnsmasq_filetrans_named_content() interface - Allow all sandbox domains create content in svirt_home_t - Allow zebra domains also create zebra_tmp_t files in /tmp - Add support for new zebra services:isisd,babeld. Add systemd support for zebra services. - Fix labeling on neutron and remove transition to iconfig_t - abrt needs to read mcelog log file - Fix labeling on dnsmasq content - Fix labeling on /etc/dnsmasq.d - Allow glusterd to relabel own lib files - Allow sandbox domains to use pam_rootok, and dontaudit attempts to unmount file systems, this is caused by a bug in systemd - Allow ipc_lock for abrt to run journalctl- Fix config.tgz- Fix passenger_stream_connect interface - setroubleshoot_fixit wants to read network state - Allow procmail_t to connect to dovecot stream sockets - Allow cimprovagt service providers to read network states - Add labeling for /var/run/mariadb - pwauth uses lastlog() to update system's lastlog - Allow account provider to read login records - Add support for texlive2013 - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - Allow passwd_t to connect to gnome keyring to change password - Update mls config files to have cronjobs in the user domains - Remove access checks that systemd does not actually do- Add support for yubikey in homedir - Add support for upd/3052 port - Allow apcupsd to use PowerChute Network Shutdown - Allow lsmd to execute various lsmplugins - Add labeling also for /etc/watchdog\.d where are watchdog scripts located too - Update gluster_export_all_rw boolean to allow relabel all base file types - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling- Add files_relabel_base_file_types() interface - Allow netlabel-config to read passwd - update gluster_export_all_rw boolean to allow relabel all base file types caused by lsetxattr() - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling - Allow pegasus to domtrans to mount_t - Add labeling for unconfined scripts in /usr/libexec/watchdog/scripts - Add support for unconfined watchdog scripts - Allow watchdog to manage own log files- Add label only for redhat.repo instead of /etc/yum.repos.d. But probably we will need to switch for the directory. - Label /etc/yum.repos.d as system_conf_t - Use sysnet_filetrans_named_content in udev.te instead of generic transition for net_conf_t - Allow dac_override for sysadm_screen_t - Allow init_t to read ipsec_conf_t as we had it for initrc_t. Needed by ipsec unit file. - Allow netlabel-config to read meminfo - Add interface to allow docker to mounton file_t - Add new interface to exec unlabeled files - Allow lvm to use docker semaphores - Setup transitons for .xsessions-errors.old - Change labels of files in /var/lib/*/.ssh to transition properly - Allow staff_t and user_t to look at logs using journalctl - pluto wants to manage own log file - Allow pluto running as ipsec_t to create pluto.log - Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Allow dmidecode to read/write /run/lock/subsys/rhsmcertd - Allow rhsmcertd to manage redhat.repo which is now labeled as system.conf. Allow rhsmcertd to manage all log files. - Additional access for docker - Added more rules to sblim policy - Fix kdumpgui_run_bootloader boolean - Allow dspam to connect to lmtp port - Included sfcbd service into sblim policy - rhsmcertd wants to manaage /etc/pki/consumer dir - Add kdumpgui_run_bootloader boolean - Add support for /var/cache/watchdog - Remove virt_domain attribute for virt_qemu_ga_unconfined_t - Fixes for handling libvirt containes - Dontaudit attempts by mysql_safe to write content into / - Dontaudit attempts by system_mail to modify network config - Allow dspam to bind to lmtp ports - Add new policy to allow staff_t and user_t to look at logs using journalctl - Allow apache cgi scripts to list sysfs - Dontaudit attempts to write/delete user_tmp_t files - Allow all antivirus domains to manage also own log dirs - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Add missing permission checks for nscd- Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Add file transition rules for content created by f5link - Rename quantum_port information to neutron - Allow all antivirus domains to manage also own log dirs - Rename quantum_port information to neutron - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Allow sysadm_t to read login information - Allow systemd_tmpfiles to setattr on var_log_t directories - Udpdate Makefile to include systemd_contexts - Add systemd_contexts - Add fs_exec_hugetlbfs_files() interface - Add daemons_enable_cluster_mode boolean - Fix rsync_filetrans_named_content() - Add rhcs_read_cluster_pid_files() interface - Update rhcs.if with additional interfaces from RHEL6 - Fix rhcs_domain_template() to not create run dirs with cluster_var_run_t - Allow glusterd_t to mounton glusterd_tmp_t - Allow glusterd to unmout al filesystems - Allow xenstored to read virt config - Add label for swift_server.lock and make add filetrans_named_content to make sure content gets created with the correct label - Allow mozilla_plugin_t to mmap hugepages as an executable- Add back userdom_security_admin_template() interface and use it for sysadm_t if sysadm_secadm.pp- Allow sshd_t to read openshift content, needs backport to RHEL6.5 - Label /usr/lib64/sasl2/libsasldb.so.3.0.0 as textrel_shlib_t - Make sur kdump lock is created with correct label if kdumpctl is executed - gnome interface calls should always be made within an optional_block - Allow syslogd_t to connect to the syslog_tls port - Add labeling for /var/run/charon.ctl socket - Add kdump_filetrans_named_content() - Allo setpgid for fenced_t - Allow setpgid and r/w cluster tmpfs for fenced_t - gnome calls should always be within optional blocks - wicd.pid should be labeled as networkmanager_var_run_t - Allow sys_resource for lldpad- Add rtas policy- Allow mailserver_domains to manage and transition to mailman data - Dontaudit attempts by mozilla plugin to relabel content, caused by using mv and cp commands - Allow mailserver_domains to manage and transition to mailman data - Allow svirt_domains to read sysctl_net_t - Allow thumb_t to use tmpfs inherited from the user - Allow mozilla_plugin to bind to the vnc port if running with spice - Add new attribute to discover confined_admins and assign confined admin to it - Fix zabbix to handle attributes in interfaces - Fix zabbix to read system states for all zabbix domains - Fix piranha_domain_template() - Allow ctdbd to create udp_socket. Allow ndmbd to access ctdbd var files. - Allow lldpad sys_rouserce cap due to #986870 - Allow dovecot-auth to read nologin - Allow openlmi-networking to read /proc/net/dev - Allow smsd_t to execute scripts created on the fly labeled as smsd_spool_t - Add zabbix_domain attribute for zabbix domains to treat them together - Add labels for zabbix-poxy-* (#1018221) - Update openlmi-storage policy to reflect #1015067 - Back port piranha tmpfs fixes from RHEL6 - Update httpd_can_sendmail boolean to allow read/write postfix spool maildrop - Add postfix_rw_spool_maildrop_files interface - Call new userdom_admin_user_templat() also for sysadm_secadm.pp - Fix typo in userdom_admin_user_template() - Allow SELinux users to create coolkeypk11sE-Gate in /var/cache/coolkey - Add new attribute to discover confined_admins - Fix labeling for /etc/strongswan/ipsec.d - systemd_logind seems to pass fd to anyone who dbus communicates with it - Dontaudit leaked write descriptor to dmesg- Activate motion policy- Fix gnome_read_generic_data_home_files() - allow openshift_cgroup_t to read/write inherited openshift file types - Remove httpd_cobbler_content * from cobbler_admin interface - Allow svirt sandbox domains to setattr on chr_file and blk_file svirt_sandbox_file_t, so sshd will work within a container - Allow httpd_t to read also git sys content symlinks - Allow init_t to read gnome home data - Dontaudit setroubleshoot_fixit_t execmem, since it does not seem to really need it. - Allow virsh to execute systemctl - Fix for nagios_services plugins - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - Fix hypervkvp.te - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Fix logging policy - Allow syslog to bind to tls ports - Update labeling for /dev/cdc-wdm - Allow to su_domain to read init states - Allow init_t to read gnome home data - Make sure if systemd_logind creates nologin file with the correct label - Clean up ipsec.te- Add auth_exec_chkpwd interface - Fix port definition for ctdb ports - Allow systemd domains to read /dev/urand - Dontaudit attempts for mozilla_plugin to append to /dev/random - Add label for /var/run/charon.* - Add labeling for /usr/lib/systemd/system/lvm2.*dd policy for motion service - Fix for nagios_services plugins - Fix some bugs in zoneminder policy - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - glusterd binds to random unreserved ports - Additional allow rules found by testing glusterfs - apcupsd needs to send a message to all users on the system so needs to look them up - Fix the label on ~/.juniper_networks - Dontaudit attempts for mozilla_plugin to append to /dev/random - Allow polipo_daemon to connect to flash ports - Allow gssproxy_t to create replay caches - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type- init reload from systemd_localed_t - Allow domains that communicate with systemd_logind_sessions to use systemd_logind_t fd - Allow systemd_localed_t to ask systemd to reload the locale. - Add systemd_runtime_unit_file_t type for unit files that systemd creates in memory - Allow readahead to read /dev/urand - Fix lots of avcs about tuned - Any file names xenstored in /var/log should be treated as xenstored_var_log_t - Allow tuned to inderact with hugepages - Allow condor domains to list etc rw dirs- Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Add additional fixes forpegasus_openlmi_account_t - Allow mdadm to read /dev/urand - Allow pegasus_openlmi_storage_t to create mdadm.conf and write it - Add label/rules for /etc/mdadm.conf - Allow pegasus_openlmi_storage_t to transition to fsadm_t - Fixes for interface definition problems - Dontaudit dovecot-deliver to gettatr on all fs dirs - Allow domains to search data_home_t directories - Allow cobblerd to connect to mysql - Allow mdadm to r/w kdump lock files - Add support for kdump lock files - Label zarafa-search as zarafa-indexer - Openshift cgroup wants to read /etc/passwd - Add new sandbox domains for kvm - Allow mpd to interact with pulseaudio if mpd_enable_homedirs is turned on - Fix labeling for /usr/lib/systemd/system/lvm2.* - Add labeling for /usr/lib/systemd/system/lvm2.* - Fix typos to get a new build. We should not cover filename trans rules to prevent duplicate rules - Add sshd_keygen_t policy for sshd-keygen - Fix alsa_home_filetrans interface name and definition - Allow chown for ssh_keygen_t - Add fs_dontaudit_getattr_all_dirs() - Allow init_t to manage etc_aliases_t and read xserver_var_lib_t and chrony keys - Fix up patch to allow systemd to manage home content - Allow domains to send/recv unlabeled traffic if unlabelednet.pp is enabled - Allow getty to exec hostname to get info - Add systemd_home_t for ~/.local/share/systemd directory- Fix lxc labels in config.tgz- Fix labeling for /usr/libexec/kde4/kcmdatetimehelper - Allow tuned to search all file system directories - Allow alsa_t to sys_nice, to get top performance for sound management - Add support for MySQL/PostgreSQL for amavis - Allow openvpn_t to manage openvpn_var_log_t files. - Allow dirsrv_t to create tmpfs_t directories - Allow dirsrv to create dirs in /dev/shm with dirsrv_tmpfs label - Dontaudit leaked unix_stream_sockets into gnome keyring - Allow telepathy domains to inhibit pipes on telepathy domains - Allow cloud-init to domtrans to rpm - Allow abrt daemon to manage abrt-watch tmp files - Allow abrt-upload-watcher to search /var/spool directory - Allow nsswitch domains to manage own process key - Fix labeling for mgetty.* logs - Allow systemd to dbus chat with upower - Allow ipsec to send signull to itself - Allow setgid cap for ipsec_t - Match upstream labeling- Do not build sanbox pkg on MLS- wine_tmp is no longer needed - Allow setroubleshoot to look at /proc - Allow telepathy domains to dbus with systemd logind - Fix handling of fifo files of rpm - Allow mozilla_plugin to transition to itself - Allow certwatch to write to cert_t directories - New abrt application - Allow NetworkManager to set the kernel scheduler - Make wine_domain shared by all wine domains - Allow mdadm_t to read images labeled svirt_image_t - Allow amanda to read /dev/urand - ALlow my_print_default to read /dev/urand - Allow mdadm to write to kdumpctl fifo files - Allow nslcd to send signull to itself - Allow yppasswd to read /dev/urandom - Fix zarafa_setrlimit - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add additional alias for user_tmp_t because wine_tmp_t is no longer used - More handling of ther kernel keyring required by kerberos - New privs needed for init_t when running without transition to initrc_t over bin_t, and without unconfined domain installed- Dontaudit attempts by sosreport to read shadow_t - Allow browser sandbox plugins to connect to cups to print - Add new label mpd_home_t - Label /srv/www/logs as httpd_log_t - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add labels for apache logs under miq package - Allow irc_t to use tcp sockets - fix labels in puppet.if - Allow tcsd to read utmp file - Allow openshift_cron_t to run ssh-keygen in ssh_keygen_t to access host keys - Define svirt_socket_t as a domain_type - Take away transition from init_t to initrc_t when executing bin_t, allow init_t to run chk_passwd_t - Fix label on pam_krb5 helper apps- Allow ldconfig to write to kdumpctl fifo files - allow neutron to connect to amqp ports - Allow kdump_manage_crash to list the kdump_crash_t directory - Allow glance-api to connect to amqp port - Allow virt_qemu_ga_t to read meminfo - Add antivirus_home_t type for antivirus date in HOMEDIRS - Allow mpd setcap which is needed by pulseaudio - Allow smbcontrol to create content in /var/lib/samba - Allow mozilla_exec_t to be used as a entrypoint to mozilla_domtrans_spec - Add additional labeling for qemu-ga/fsfreeze-hook.d scripts - amanda_exec_t needs to be executable file - Allow block_suspend cap for samba-net - Allow apps that read ipsec_mgmt_var_run_t to search ipsec_var_run_t - Allow init_t to run crash utility - Treat usr_t just like bin_t for transitions and executions - Add port definition of pka_ca to port 829 for openshift - Allow selinux_store to use symlinks- Allow block_suspend cap for samba-net - Allow t-mission-control to manage gabble cache files - Allow nslcd to read /sys/devices/system/cpu - Allow selinux_store to use symlinks- Allow xdm_t to transition to itself - Call neutron interfaces instead of quantum - Allow init to change targed role to make uncofined services (xrdp which now has own systemd unit file) working. We want them to have in unconfined_t - Make sure directories in /run get created with the correct label - Make sure /root/.pki gets created with the right label - try to remove labeling for motion from zoneminder_exec_t to bin_t - Allow inetd_t to execute shell scripts - Allow cloud-init to read all domainstate - Fix to use quantum port - Add interface netowrkmanager_initrc_domtrans - Fix boinc_execmem - Allow t-mission-control to read gabble cache home - Add labeling for ~/.cache/telepathy/avatars/gabble - Allow memcache to read sysfs data - Cleanup antivirus policy and add additional fixes - Add boolean boinc_enable_execstack - Add support for couchdb in rabbitmq policy - Add interface couchdb_search_pid_dirs - Allow firewalld to read NM state - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files()- Split out rlogin ports from inetd - Treat files labeld as usr_t like bin_t when it comes to transitions - Allow staff_t to read login config - Allow ipsec_t to read .google authenticator data - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files() - Call the correct interface - corenet_udp_bind_ktalkd_port() - Allow all domains that can read gnome_config to read kde config - Allow sandbox domain to read/write mozilla_plugin_tmpfs_t so pulseaudio will work - Allow mdadm to getattr any file system - Allow a confined domain to executes mozilla_exec_t via dbus - Allow cupsd_lpd_t to bind to the printer port - Dontaudit attempts to bind to ports < 1024 when nis is turned on - Allow apache domain to connect to gssproxy socket - Allow rlogind to bind to the rlogin_port - Allow telnetd to bind to the telnetd_port - Allow ktalkd to bind to the ktalkd_port - Allow cvs to bind to the cvs_port- Cleanup related to init_domain()+inetd_domain fixes - Use just init_domain instead of init_daemon_domain in inetd_core_service_domain - svirt domains neeed to create kobject_uevint_sockets - Lots of new access required for sosreport - Allow tgtd_t to connect to isns ports - Allow init_t to transition to all inetd domains: - openct needs to be able to create netlink_object_uevent_sockets - Dontaudit leaks into ldconfig_t - Dontaudit su domains getattr on /dev devices, move su domains to attribute based calls - Move kernel_stream_connect into all Xwindow using users - Dontaudit inherited lock files in ifconfig o dhcpc_t- Also sock_file trans rule is needed in lsm - Fix labeling for fetchmail pid files/dirs - Add additional fixes for abrt-upload-watch - Fix polipo.te - Fix transition rules in asterisk policy - Add fowner capability to networkmanager policy - Allow polipo to connect to tor ports - Cleanup lsmd.if - Cleanup openhpid policy - Fix kdump_read_crash() interface - Make more domains as init domain - Fix cupsd.te - Fix requires in rpm_rw_script_inherited_pipes - Fix interfaces in lsm.if - Allow munin service plugins to manage own tmpfs files/dirs - Allow virtd_t also relabel unix stream sockets for virt_image_type - Make ktalk as init domain - Fix to define ktalkd_unit_file_t correctly - Fix ktalk.fc - Add systemd support for talk-server - Allow glusterd to create sock_file in /run - Allow xdm_t to delete gkeyringd_tmp_t files on logout - Add fixes for hypervkvp policy - Add logwatch_can_sendmail boolean - Allow mysqld_safe_t to handle also symlinks in /var/log/mariadb - Allow xdm_t to delete gkeyringd_tmp_t files on logout- Add selinux-policy-sandbox pkg0 - Allow rhsmcertd to read init state - Allow fsetid for pkcsslotd - Fix labeling for /usr/lib/systemd/system/pkcsslotd.service - Allow fetchmail to create own pid with correct labeling - Fix rhcs_domain_template() - Allow roles which can run mock to read mock lib files to view results - Allow rpcbind to use nsswitch - Fix lsm.if summary - Fix collectd_t can read /etc/passwd file - Label systemd unit files under dracut correctly - Add support for pam_mount to mount user's encrypted home When a user logs in and logs out using ssh - Add support for .Xauthority-n - Label umount.crypt as lvm_exec_t - Allow syslogd to search psad lib files - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files- Add policy for lsmd - Add support for /var/log/mariadb dir and allow mysqld_safe to list this directory - Update condor_master rules to allow read system state info and allow logging - Add labeling for /etc/condor and allow condor domain to write it (bug) - Allow condor domains to manage own logs - Allow glusterd to read domains state - Fix initial hypervkvp policy - Add policy for hypervkvpd - Fix redis.if summary- Allow boinc to connect to @/tmp/.X11-unix/X0 - Allow beam.smp to connect to tcp/5984 - Allow named to manage own log files - Add label for /usr/libexec/dcc/start-dccifd and domtrans to dccifd_t - Add virt_transition_userdomain boolean decl - Allow httpd_t to sendto unix_dgram sockets on its children - Allow nova domains to execute ifconfig - bluetooth wants to create fifo_files in /tmp - exim needs to be able to manage mailman data - Allow sysstat to getattr on all file systems - Looks like bluetoothd has moved - Allow collectd to send ping packets - Allow svirt_lxc domains to getpgid - Remove virt-sandbox-service labeling as virsh_exec_t, since it no longer does virsh_t stuff - Allow frpintd_t to read /dev/urandom - Allow asterisk_t to create sock_file in /var/run - Allow usbmuxd to use netlink_kobject - sosreport needs to getattr on lots of devices, and needs access to netlink_kobject_uevent_socket - More cleanup of svirt_lxc policy - virtd_lxc_t now talks to dbus - Dontaudit leaked ptmx_t - Allow processes to use inherited fifo files - Allow openvpn_t to connect to squid ports - Allow prelink_cron_system_t to ask systemd to reloaddd miscfiles_dontaudit_access_check_cert() - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files - Allow user roles to connect to the journal socket- selinux_set_enforce_mode needs to be used with type - Add append to the dontaudit for unix_stream_socket of xdm_t leak - Allow xdm_t to create symlinks in log direcotries - Allow login programs to read afs config - Label 10933 as a pop port, for dovecot - New policy to allow selinux_server.py to run as semanage_t as a dbus service - Add fixes to make netlabelctl working on MLS - AVCs required for running sepolicy gui as staff_t - Dontaudit attempts to read symlinks, sepolicy gui is likely to cause this type of AVC - New dbus server to be used with new gui - After modifying some files in /etc/mail, I saw this needed on the next boot - Loading a vm from /usr/tmp with virt-manager - Clean up oracleasm policy for Fedora - Add oracleasm policy written by rlopez@redhat.com - Make postfix_postdrop_t as mta_agent to allow domtrans to system mail if it is executed by apache - Add label for /var/crash - Allow fenced to domtrans to sanclok_t - Allow nagios to manage nagios spool files - Make tfptd as home_manager - Allow kdump to read kcore on MLS system - Allow mysqld-safe sys_nice/sys_resource caps - Allow apache to search automount tmp dirs if http_use_nfs is enabled - Allow crond to transition to named_t, for use with unbound - Allow crond to look at named_conf_t, for unbound - Allow mozilla_plugin_t to transition its home content - Allow dovecot_domain to read all system and network state - Allow httpd_user_script_t to call getpw - Allow semanage to read pid files - Dontaudit leaked file descriptors from user domain into thumb - Make PAM authentication working if it is enabled in ejabberd - Add fixes for rabbit to fix ##992920,#992931 - Allow glusterd to mount filesystems - Loading a vm from /usr/tmp with virt-manager - Trying to load a VM I got an AVC from devicekit_disk for loopcontrol device - Add fix for pand service - shorewall touches own log - Allow nrpe to list /var - Mozilla_plugin_roles can not be passed into lpd_run_lpr - Allow afs domains to read afs_config files - Allow login programs to read afs config - Allow virt_domain to read virt_var_run_t symlinks - Allow smokeping to send its process signals - Allow fetchmail to setuid - Add kdump_manage_crash() interface - Allow abrt domain to write abrt.socket- Add more aliases in pegasus.te - Add more fixes for *_admin interfaces - Add interface fixes - Allow nscd to stream connect to nmbd - Allow gnupg apps to write to pcscd socket - Add more fixes for openlmi provides. Fix naming and support for additionals - Allow fetchmail to resolve host names - Allow firewalld to interact also with lnk files labeled as firewalld_etc_rw_t - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te - Fix corecmd_exec_chroot() - Fix logging_relabel_syslog_pid_socket interface - Fix typo in unconfineduser.te - Allow system_r to access unconfined_dbusd_t to run hp_chec- Allow xdm_t to act as a dbus client to itsel - Allow fetchmail to resolve host names - Allow gnupg apps to write to pcscd socket - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te -httpd_t does access_check on certs- Add support for cmpiLMI_Service-cimprovagt - Allow pegasus domtrans to rpm_t to make pycmpiLMI_Software-cimprovagt running as rpm_t - Label pycmpiLMI_Software-cimprovagt as rpm_exec_t - Add support for pycmpiLMI_Storage-cimprovagt - Add support for cmpiLMI_Networking-cimprovagt - Allow system_cronjob_t to create user_tmpfs_t to make pulseaudio working - Allow virtual machines and containers to run as user doains, needed for virt-sandbox - Allow buglist.cgi to read cpu info- Allow systemd-tmpfile to handle tmp content in print spool dir - Allow systemd-sysctl to send system log messages - Add support for RTP media ports and fmpro-internal - Make auditd working if audit is configured to perform SINGLE action on disk error - Add interfaces to handle systemd units - Make systemd-notify working if pcsd is used - Add support for netlabel and label /usr/sbin/netlabelctl as iptables_exec_t - Instead of having all unconfined domains get all of the named transition rules, - Only allow unconfined_t, init_t, initrc_t and rpm_script_t by default. - Add definition for the salt ports - Allow xdm_t to create link files in xdm_var_run_t - Dontaudit reads of blk files or chr files leaked into ldconfig_t - Allow sys_chroot for useradd_t - Allow net_raw cap for ipsec_t - Allow sysadm_t to reload services - Add additional fixes to make strongswan working with a simple conf - Allow sysadm_t to enable/disable init_t services - Add additional glusterd perms - Allow apache to read lnk files in the /mnt directory - Allow glusterd to ask the kernel to load a module - Fix description of ftpd_use_fusefs boolean - Allow svirt_lxc_net_t to sys_chroot, modify policy to tighten up svirt_lxc_domain capabilties and process controls, but add them to svirt_lxc_net_t - Allow glusterds to request load a kernel module - Allow boinc to stream connect to xserver_t - Allow sblim domains to read /etc/passwd - Allow mdadm to read usb devices - Allow collectd to use ping plugin - Make foghorn working with SNMP - Allow sssd to read ldap certs - Allow haproxy to connect to RTP media ports - Add additional trans rules for aide_db - Add labeling for /usr/lib/pcsd/pcsd - Add labeling for /var/log/pcsd - Add support for pcs which is a corosync and pacemaker configuration tool- Label /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t - Add labeling for /usr/libexec/kde4/polkit-kde-authentication-agent-1 - Allow all domains that can domtrans to shutdown, to start the power services script to shutdown - consolekit needs to be able to shut down system - Move around interfaces - Remove nfsd_rw_t and nfsd_ro_t, they don't do anything - Add additional fixes for rabbitmq_beam to allow getattr on mountpoints - Allow gconf-defaults-m to read /etc/passwd - Fix pki_rw_tomcat_cert() interface to support lnk_files- Add support for gluster ports - Make sure that all keys located in /etc/ssh/ are labeled correctly - Make sure apcuspd lock files get created with the correct label - Use getcap in gluster.te - Fix gluster policy - add additional fixes to allow beam.smp to interact with couchdb files - Additional fix for #974149 - Allow gluster to user gluster ports - Allow glusterd to transition to rpcd_t and add additional fixes for #980683 - Allow tgtd working when accessing to the passthrough device - Fix labeling for mdadm unit files- Add mdadm fixes- Fix definition of sandbox.disabled to sandbox.pp.disabled- Allow mdamd to execute systemctl - Allow mdadm to read /dev/kvm - Allow ipsec_mgmt_t to read l2tpd pid content- Allow nsd_t to read /dev/urand - Allow mdadm_t to read framebuffer - Allow rabbitmq_beam_t to read process info on rabbitmq_epmd_t - Allow mozilla_plugin_config_t to create tmp files - Cleanup openvswitch policy - Allow mozilla plugin to getattr on all executables - Allow l2tpd_t to create fifo_files in /var/run - Allow samba to touch/manage fifo_files or sock_files in a samba_share_t directory - Allow mdadm to connecto its own unix_stream_socket - FIXME: nagios changed locations to /log/nagios which is wrong. But we need to have this workaround for now. - Allow apache to access smokeping pid files - Allow rabbitmq_beam_t to getattr on all filesystems - Add systemd support for iodined - Allow nup_upsdrvctl_t to execute its entrypoint - Allow fail2ban_client to write to fail2ban_var_run_t, Also allow it to use nsswitch - add labeling for ~/.cache/libvirt-sandbox - Add interface to allow domains transitioned to by confined users to send sigchld to screen program - Allow sysadm_t to check the system status of files labeled etc_t, /etc/fstab - Allow systemd_localed to start /usr/lib/systemd/system/systemd-vconsole-setup.service - Allow an domain that has an entrypoint from a type to be allowed to execute the entrypoint without a transition, I can see no case where this is a bad thing, and elminiates a whole class of AVCs. - Allow staff to getsched all domains, required to run htop - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Add prosody policy written by Michael Scherer - Allow nagios plugins to read /sys info - ntpd needs to manage own log files - Add support for HOME_DIR/.IBMERS - Allow iptables commands to read firewalld config - Allow consolekit_t to read utmp - Fix filename transitions on .razor directory - Add additional fixes to make DSPAM with LDA working - Allow snort to read /etc/passwd - Allow fail2ban to communicate with firewalld over dbus - Dontaudit openshift_cgreoup_file_t read/write leaked dev - Allow nfsd to use mountd port - Call th proper interface - Allow openvswitch to read sys and execute plymouth - Allow tmpwatch to read /var/spool/cups/tmp - Add support for /usr/libexec/telepathy-rakia - Add systemd support for zoneminder - Allow mysql to create files/directories under /var/log/mysql - Allow zoneminder apache scripts to rw zoneminder tmpfs - Allow httpd to manage zoneminder lib files - Add zoneminder_run_sudo boolean to allow to start zoneminder - Allow zoneminder to send mails - gssproxy_t sock_file can be under /var/lib - Allow web domains to connect to whois port. - Allow sandbox_web_type to connect to the same ports as mozilla_plugin_t. - We really need to add an interface to corenet to define what a web_client_domain is and - then define chrome_sandbox_t, mozilla_plugin_t and sandbox_web_type to that domain. - Add labeling for cmpiLMI_LogicalFile-cimprovagt - Also make pegasus_openlmi_logicalfile_t as unconfined to have unconfined_domain attribute for filename trans rules - Update policy rules for pegasus_openlmi_logicalfile_t - Add initial types for logicalfile/unconfined OpenLMI providers - mailmanctl needs to read own log - Allow logwatch manage own lock files - Allow nrpe to read meminfo - Allow httpd to read certs located in pki-ca - Add pki_read_tomcat_cert() interface - Add support for nagios openshift plugins - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Shrink the size of policy by moving to attributes, also add dridomain so that mozilla_plugin can follow selinuxuse_dri boolean. - Allow bootloader to manage generic log files - Allow ftp to bind to port 989 - Fix label of new gear directory - Add support for new directory /var/lib/openshift/gears/ - Add openshift_manage_lib_dirs() - allow virtd domains to manage setrans_var_run_t - Allow useradd to manage all openshift content - Add support so that mozilla_plugin_t can use dri devices - Allow chronyd to change the scheduler - Allow apmd to shut downthe system - Devicekit_disk_t needs to manage /etc/fstab- Make DSPAM to act as a LDA working - Allow ntop to create netlink socket - Allow policykit to send a signal to policykit-auth - Allow stapserver to dbus chat with avahi/systemd-logind - Fix labeling on haproxy unit file - Clean up haproxy policy - A new policy for haproxy and placed it to rhcs.te - Add support for ldirectord and treat it with cluster_t - Make sure anaconda log dir is created with var_log_t- Allow lvm_t to create default targets for filesystem handling - Fix labeling for razor-lightdm binaries - Allow insmod_t to read any file labeled var_lib_t - Add policy for pesign - Activate policy for cmpiLMI_Account-cimprovagt - Allow isnsd syscall=listen - /usr/libexec/pegasus/cimprovagt needs setsched caused by sched_setscheduler - Allow ctdbd to use udp/4379 - gatherd wants sys_nice and setsched - Add support for texlive2012 - Allow NM to read file_t (usb stick with no labels used to transfer keys for example) - Allow cobbler to execute apache with domain transition- condor_collector uses tcp/9000 - Label /usr/sbin/virtlockd as virtd_exec_t for now - Allow cobbler to execute ldconfig - Allow NM to execute ssh - Allow mdadm to read /dev/crash - Allow antivirus domains to connect to snmp port - Make amavisd-snmp working correctly - Allow nfsd_t to mounton nfsd_fs_t - Add initial snapper policy - We still need to have consolekit policy - Dontaudit firefox attempting to connect to the xserver_port_t if run within sandbox_web_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow dirsrv to read network state - Fix pki_read_tomcat_lib_files - Add labeling for /usr/libexec/nm-ssh-service - Add label cert_t for /var/lib/ipa/pki-ca/publish - Lets label /sys/fs/cgroup as cgroup_t for now, to keep labels consistant - Allow nfsd_t to mounton nfsd_fs_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow passwd_t to change role to system_r from unconfined_r- Don't audit access checks by sandbox xserver on xdb var_lib - Allow ntop to read usbmon devices - Add labeling for new polcykit authorizor - Dontaudit access checks from fail2ban_client - Don't audit access checks by sandbox xserver on xdb var_lib - Allow apps that connect to xdm stream to conenct to xdm_dbusd_t stream - Fix labeling for all /usr/bim/razor-lightdm-* binaries - Add filename trans for /dev/md126p1- Make vdagent able to request loading kernel module - Add support for cloud-init make it as unconfined domain - Allow snmpd to run smartctl in fsadm_t domain - remove duplicate openshift_search_lib() interface - Allow mysqld to search openshift lib files - Allow openshift cgroup to interact with passedin file descriptors - Allow colord to list directories inthe users homedir - aide executes prelink to check files - Make sure cupsd_t creates content in /etc/cups with the correct label - Lest dontaudit apache read all domains, so passenger will not cause this avc - Allow gssd to connect to gssproxy - systemd-tmpfiles needs to be able to raise the level to fix labeling on /run/setrans in MLS - Allow systemd-tmpfiles to relabel also lock files - Allow useradd to add homdir in /var/lib/openshift - Allow setfiles and semanage to write output to /run/files- Add labeling for /dev/tgt - Dontaudit leak fd from firewalld for modprobe - Allow runuser running as rpm_script_t to create netlink_audit socket - Allow mdadm to read BIOS non-volatile RAM- accountservice watches when accounts come and go in wtmp - /usr/java/jre1.7.0_21/bin/java needs to create netlink socket - Add httpd_use_sasl boolean - Allow net_admin for tuned_t - iscsid needs sys_module to auto-load kernel modules - Allow blueman to read bluetooth conf - Add nova_manage_lib_files() interface - Fix mplayer_filetrans_home_content() - Add mplayer_filetrans_home_content() - mozilla_plugin_config_roles need to be able to access mozilla_plugin_config_t - Revert "Allow thumb_t to append inherited xdm stream socket" - Add iscsi_filetrans_named_content() interface - Allow to create .mplayer with the correct labeling for unconfined - Allow iscsiadmin to create lock file with the correct labeling- Allow wine to manage wine home content - Make amanda working with socket actiovation - Add labeling for /usr/sbin/iscsiadm - Add support for /var/run/gssproxy.sock - dnsmasq_t needs to read sysctl_net_t- Fix courier_domain_template() interface - Allow blueman to write ip_forward - Allow mongodb to connect to mongodb port - Allow mongodb to connect to mongodb port - Allow java to bind jobss_debug port - Fixes for *_admin interfaces - Allow iscsid auto-load kernel modules needed for proper iSCSI functionality - Need to assign attribute for courier_domain to all courier_domains - Fail2ban reads /etc/passwd - postfix_virtual will create new files in postfix_spool_t - abrt triggers sys_ptrace by running pidof - Label ~/abc as mozilla_home_t, since java apps as plugin want to create it - Add passenger fixes needed by foreman - Remove dup interfaces - Add additional interfaces for quantum - Add new interfaces for dnsmasq - Allow passenger to read localization and send signull to itself - Allow dnsmasq to stream connect to quantum - Add quantum_stream_connect() - Make sure that mcollective starts the service with the correct labeling - Add labels for ~/.manpath - Dontaudit attempts by svirt_t to getpw* calls - sandbox domains are trying to look at parent process data - Allow courior auth to create its pid file in /var/spool/courier subdir - Add fixes for beam to have it working with couchdb - Add labeling for /run/nm-xl2tpd.con - Allow apache to stream connect to thin - Add systemd support for amand - Make public types usable for fs mount points - Call correct mandb interface in domain.te - Allow iptables to r/w quantum inherited pipes and send sigchld - Allow ifconfig domtrans to iptables and execute ldconfig - Add labels for ~/.manpath - Allow systemd to read iscsi lib files - seunshare is trying to look at parent process data- Fix openshift_search_lib - Add support for abrt-uefioops-oops - Allow colord to getattr any file system - Allow chrome processes to look at each other - Allow sys_ptrace for abrt_t - Add new policy for gssproxy - Dontaudit leaked file descriptor writes from firewalld - openshift_net_type is interface not template - Dontaudit pppd to search gnome config - Update openshift_search_lib() interface - Add fs_list_pstorefs() - Fix label on libbcm_host.so since it is built incorrectly on raspberry pi, needs back port to F18 - Better labels for raspberry pi devices - Allow init to create devpts_t directory - Temporarily label rasbery pi devices as memory_device_t, needs back port to f18 - Allow sysadm_t to build kernels - Make sure mount creates /var/run/blkid with the correct label, needs back port to F18 - Allow userdomains to stream connect to gssproxy - Dontaudit leaked file descriptor writes from firewalld - Allow xserver to read /dev/urandom - Add additional fixes for ipsec-mgmt - Make SSHing into an Openshift Enterprise Node working- Add transition rules to unconfined domains and to sysadm_t to create /etc/adjtime - with the proper label. - Update files_filetrans_named_content() interface to get right labeling for pam.d conf files - Allow systemd-timedated to create adjtime - Add clock_create_adjtime() - Additional fix ifconfing for #966106 - Allow kernel_t to create boot.log with correct labeling - Remove unconfined_mplayer for which we don't have rules - Rename interfaces - Add userdom_manage_user_home_files/dirs interfaces - Fix files_dontaudit_read_all_non_security_files - Fix ipsec_manage_key_file() - Fix ipsec_filetrans_key_file() - Label /usr/bin/razor-lightdm-greeter as xdm_exec_t instead of spamc_exec_t - Fix labeling for ipse.secrets - Add interfaces for ipsec and labeling for ipsec.info and ipsec_setup.pid - Add files_dontaudit_read_all_non_security_files() interface - /var/log/syslog-ng should be labeled var_log_t - Make ifconfig_var_run_t a mountpoint - Add transition from ifconfig to dnsmasq - Allow ifconfig to execute bin_t/shell_exec_t - We want to have hwdb.bin labeled as etc_t - update logging_filetrans_named_content() interface - Allow systemd_timedate_t to manage /etc/adjtime - Allow NM to send signals to l2tpd - Update antivirus_can_scan_system boolean - Allow devicekit_disk_t to sys_config_tty - Run abrt-harvest programs as abrt_t, and allow abrt_t to list all filesystem directories - Make printing from vmware working - Allow php-cgi from php54 collection to access /var/lib/net-snmp/mib_indexes - Add virt_qemu_ga_data_t for qemu-ga - Make chrome and mozilla able to connect to same ports, add jboss_management_port_t to both - Fix typo in virt.te - Add virt_qemu_ga_unconfined_t for hook scripts - Make sure NetworkManager files get created with the correct label - Add mozilla_plugin_use_gps boolean - Fix cyrus to have support for net-snmp - Additional fixes for dnsmasq and quantum for #966106 - Add plymouthd_create_log() - remove httpd_use_oddjob for which we don't have rules - Add missing rules for httpd_can_network_connect_cobbler - Add missing cluster_use_execmem boolean - Call userdom_manage_all_user_home_type_files/dirs - Additional fix for ftp_home_dir - Fix ftp_home_dir boolean - Allow squit to recv/send client squid packet - Fix nut.te to have nut_domain attribute - Add support for ejabberd; TODO: revisit jabberd and rabbit policy - Fix amanda policy - Add more fixes for domains which use libusb - Make domains which use libusb working correctly - Allow l2tpd to create ipsec key files with correct labeling and manage them - Fix cobbler_manage_lib_files/cobbler_read_lib_files to cover also lnk files - Allow rabbitmq-beam to bind generic node - Allow l2tpd to read ipse-mgmt pid files - more fixes for l2tpd, NM and pppd from #967072- Dontaudit to getattr on dirs for dovecot-deliver - Allow raiudusd server connect to postgresql socket - Add kerberos support for radiusd - Allow saslauthd to connect to ldap port - Allow postfix to manage postfix_private_t files - Add chronyd support for #965457 - Fix labeling for HOME_DIR/\.icedtea - CHange squid and snmpd to be allowed also write own logs - Fix labeling for /usr/libexec/qemu-ga - Allow virtd_t to use virt_lock_t - Allow also sealert to read the policy from the kernel - qemu-ga needs to execute scripts in /usr/libexec/qemu-ga and to use /tmp content - Dontaudit listing of users homedir by sendmail Seems like a leak - Allow passenger to transition to puppet master - Allow apache to connect to mythtv - Add definition for mythtv ports- Add additional fixes for #948073 bug - Allow sge_execd_t to also connect to sge ports - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow sge_execd to bind sge ports. Allow kill capability and reads cgroup files - Remove pulseaudio filetrans pulseaudio_manage_home_dirs which is a part of pulseaudio_manage_home_files - Add networkmanager_stream_connect() - Make gnome-abrt wokring with staff_t - Fix openshift_manage_lib_files() interface - mdadm runs ps command which seems to getattr on random log files - Allow mozilla_plugin_t to create pulseaudit_home_t directories - Allow qemu-ga to shutdown virtual hosts - Add labelling for cupsd-browsed - Add web browser plugins to connect to aol ports - Allow nm-dhcp-helper to stream connect to NM - Add port definition for sge ports- Make sure users and unconfined domains create .hushlogin with the correct label - Allow pegaus to chat with realmd over DBus - Allow cobblerd to read network state - Allow boicn-client to stat on /dev/input/mice - Allow certwatch to read net_config_t when it executes apache - Allow readahead to create /run/systemd and then create its own directory with the correct label- Transition directories and files when in a user_tmp_t directory - Change certwatch to domtrans to apache instead of just execute - Allow virsh_t to read xen lib files - update policy rules for pegasus_openlmi_account_t - Add support for svnserve_tmp_t - Activate account openlmi policy - pegasus_openlmi_domain_template needs also require pegasus_t - One more fix for policykit.te - Call fs_list_cgroups_dirs() in policykit.te - Allow nagios service plugin to read mysql config files - Add labeling for /var/svn - Fix chrome.te - Fix pegasus_openlmi_domain_template() interfaces - Fix dev_rw_vfio_dev definiton, allow virtd_t to read tmpfs_t symlinks - Fix location of google-chrome data - Add support for chome_sandbox to store content in the homedir - Allow policykit to watch for changes in cgroups file system - Add boolean to allow mozilla_plugin_t to use spice - Allow collectd to bind to udp port - Allow collected_t to read all of /proc - Should use netlink socket_perms - Should use netlink socket_perms - Allow glance domains to connect to apache ports - Allow apcupsd_t to manage its log files - Allow chrome objects to rw_inherited unix_stream_socket from callers - Allow staff_t to execute virtd_exec_t for running vms - nfsd_t needs to bind mountd port to make nfs-mountd.service working - Allow unbound net_admin capability because of setsockopt syscall - Fix fs_list_cgroup_dirs() - Label /usr/lib/nagios/plugins/utils.pm as bin_t - Remove uplicate definition of fs_read_cgroup_files() - Remove duplicate definition of fs_read_cgroup_files() - Add files_mountpoint_filetrans interface to be used by quotadb_t and snapperd - Additional interfaces needed to list and read cgroups config - Add port definition for collectd port - Add labels for /dev/ptp* - Allow staff_t to execute virtd_exec_t for running vms- Allow samba-net to also read realmd tmp files - Allow NUT to use serial ports - realmd can be started by systemctl now- Remove userdom_home_manager for xdm_t and move all rules to xserver.te directly - Add new xdm_write_home boolean to allow xdm_t to create files in HOME dirs with xdm_home_t - Allow postfix-showq to read/write unix.showq in /var/spool/postfix/pid - Allow virsh to read xen lock file - Allow qemu-ga to create files in /run with proper labeling - Allow glusterd to connect to own socket in /tmp - Allow glance-api to connect to http port to make glance image-create working - Allow keystonte_t to execute rpm- Fix realmd cache interfaces- Allow tcpd to execute leafnode - Allow samba-net to read realmd cache files - Dontaudit sys_tty_config for alsactl - Fix allow rules for postfix_var_run - Allow cobblerd to read /etc/passwd - Allow pegasus to read exports - Allow systemd-timedate to read xdm state - Allow mout to stream connect to rpcbind - Add labeling just for /usr/share/pki/ca-trust-source instead of /usr/share/pki- Allow thumbnails to share memory with apps which run thumbnails - Allow postfix-postqueue block_suspend - Add lib interfaces for smsd - Add support for nginx - Allow s2s running as jabberd_t to connect to jabber_interserver_port_t - Allow pki apache domain to create own tmp files and execute httpd_suexec - Allow procmail to manger user tmp files/dirs/lnk_files - Add virt_stream_connect_svirt() interface - Allow dovecot-auth to execute bin_t - Allow iscsid to request that kernel load a kernel module - Add labeling support for /var/lib/mod_security - Allow iw running as tuned_t to create netlink socket - Dontaudit sys_tty_config for thumb_t - Add labeling for nm-l2tp-service - Allow httpd running as certwatch_t to open tcp socket - Allow useradd to manager smsd lib files - Allow useradd_t to add homedirs in /var/lib - Fix typo in userdomain.te - Cleanup userdom_read_home_certs - Implement userdom_home_reader_certs_type to allow read certs also on encrypt /home with ecryptfs_t - Allow staff to stream connect to svirt_t to make gnome-boxes working- Allow lvm to create its own unit files - Label /var/lib/sepolgen as selinux_config_t - Add filetrans rules for tw devices - Add transition from cupsd_config_t to cupsd_t- Add filetrans rules for tw devices - Cleanup bad transition lines- Fix lockdev_manage_files() - Allow setroubleshootd to read var_lib_t to make email_alert working - Add lockdev_manage_files() - Call proper interface in virt.te - Allow gkeyring_domain to create /var/run/UID/config/dbus file - system dbus seems to be blocking suspend - Dontaudit attemps to sys_ptrace, which I believe gpsd does not need - When you enter a container from root, you generate avcs with a leaked file descriptor - Allow mpd getattr on file system directories - Make sure realmd creates content with the correct label - Allow systemd-tty-ask to write kmsg - Allow mgetty to use lockdev library for device locking - Fix selinuxuser_user_share_music boolean name to selinuxuser_share_music - When you enter a container from root, you generate avcs with a leaked file descriptor - Make sure init.fc files are labeled correctly at creation - File name trans vconsole.conf - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow certmonger to dbus communicate with realmd - Make realmd working- Fix mozilla specification of homedir content - Allow certmonger to read network state - Allow tmpwatch to read tmp in /var/spool/{cups,lpd} - Label all nagios plugin as unconfined by default - Add httpd_serve_cobbler_files() - Allow mdadm to read /dev/sr0 and create tmp files - Allow certwatch to send mails - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow realmd to run ipa, really needs to be an unconfined_domain - Allow sandbox domains to use inherted terminals - Allow pscd to use devices labeled svirt_image_t in order to use cat cards. - Add label for new alsa pid - Alsa now uses a pid file and needs to setsched - Fix oracleasmfs_t definition - Add support for sshd_unit_file_t - Add oracleasmfs_t - Allow unlabeled_t files to be stored on unlabeled_t filesystems- Fix description of deny_ptrace boolean - Remove allow for execmod lib_t for now - Allow quantum to connect to keystone port - Allow nova-console to talk with mysql over unix stream socket - Allow dirsrv to stream connect to uuidd - thumb_t needs to be able to create ~/.cache if it does not exist - virtd needs to be able to sys_ptrace when starting and stoping containers- Allow alsa_t signal_perms, we probaly should search for any app that can execute something without transition and give it signal_perms... - Add dontaudit for mozilla_plugin_t looking at the xdm_t sockets - Fix deny_ptrace boolean, certain ptrace leaked into the system - Allow winbind to manage kerberos_rcache_host - Allow spamd to create spamd_var_lib_t directories - Remove transition to mozilla_tmp_t by mozilla_t, to allow it to manage the users tmp dirs - Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Call snmp_manage_var_lib_files(fogorn_t) instead of snmp_manage_var_dirs - Fix vmware_role() interface - Fix cobbler_manage_lib_files() interface - Allow nagios check disk plugins to execute bin_t - Allow quantum to transition to openvswitch_t - Allow postdrop to stream connect to postfix-master - Allow quantum to stream connect to openvswitch - Add xserver_dontaudit_xdm_rw_stream_sockets() interface - Allow daemon to send dgrams to initrc_t - Allow kdm to start the power service to initiate a reboot or poweroff- Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Don't audit attempts to write to stream socket of nscld by thumbnailers - Allow git_system_t to read network state - Allow pegasas to execute mount command - Fix desc for drdb_admin - Fix condor_amin() - Interface fixes for uptime, vdagent, vnstatd - Fix labeling for moodle in /var/www/moodle/data - Add interface fixes - Allow bugzilla to read certs - /var/www/moodle needs to be writable by apache - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Fix namespace_init_t to create content with proper labels, and allow it to manage all user content - Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Fix sys_nice for cups_domain - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Kernel_t needs mac_admin in order to support labeled NFS - Fix systemd_dontaudit_dbus_chat() interface - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Allow consolehelper domain to write Xauth files in /root - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Allow consolehelper more access discovered by Tom London - Allow fsdaemon to send signull to all domain - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Fix file_contexts.subs to label /run/lock correctly- Try to label on controlC devices up to 30 correctly - Add mount_rw_pid_files() interface - Add additional mount/umount interfaces needed by mock - fsadm_t sends audit messages in reads kernel_ipc_info when doing livecd-iso-to-disk - Fix tabs - Allow initrc_domain to search rgmanager lib files - Add more fixes which make mock working together with confined users * Allow mock_t to manage rpm files * Allow mock_t to read rpm log files * Allow mock to setattr on tmpfs, devpts * Allow mount/umount filesystems - Add rpm_read_log() interface - yum-cron runs rpm from within it. - Allow tuned to transition to dmidecode - Allow firewalld to do net_admin - Allow mock to unmont tmpfs_t - Fix virt_sigkill() interface - Add additional fixes for mock. Mainly caused by mount running in mock_t - Allow mock to write sysfs_t and mount pid files - Add mailman_domain to mailman_template() - Allow openvswitch to execute shell - Allow qpidd to use kerberos - Allow mailman to use fusefs, needs back port to RHEL6 - Allow apache and its scripts to use anon_inodefs - Add alias for git_user_content_t and git_sys_content_t so that RHEL6 will update to RHEL7 - Realmd needs to connect to samba ports, needs back port to F18 also - Allow colord to read /run/initial-setup- - Allow sanlock-helper to send sigkill to virtd which is registred to sanlock - Add virt_kill() interface - Add rgmanager_search_lib() interface - Allow wdmd to getattr on all filesystems. Back ported from RHEL6- Allow realmd to create tmp files - FIx ircssi_home_t type to irssi_home_t - Allow adcli running as realmd_t to connect to ldap port - Allow NetworkManager to transition to ipsec_t, for running strongswan - Make openshift_initrc_t an lxc_domain - Allow gssd to manage user_tmp_t files - Fix handling of irclogs in users homedir - Fix labeling for drupal an wp-content in subdirs of /var/www/html - Allow abrt to read utmp_t file - Fix openshift policy to transition lnk_file, sock-file an fifo_file when created in a tmpfs_t, needs back port to RHEL6 - fix labeling for (oo|rhc)-restorer-wrapper.sh - firewalld needs to be able to write to network sysctls - Fix mozilla_plugin_dontaudit_rw_sem() interface - Dontaudit generic ipc read/write to a mozilla_plugin for sandbox_x domains - Add mozilla_plugin_dontaudit_rw_sem() interface - Allow svirt_lxc_t to transition to openshift domains - Allow condor domains block_suspend and dac_override caps - Allow condor_master to read passd - Allow condor_master to read system state - Allow NetworkManager to transition to ipsec_t, for running strongswan - Lots of access required by lvm_t to created encrypted usb device - Allow xdm_t to dbus communicate with systemd_localed_t - Label strongswan content as ipsec_exec_mgmt_t for now - Allow users to dbus chat with systemd_localed - Fix handling of .xsession-errors in xserver.if, so kde will work - Might be a bug but we are seeing avc's about people status on init_t:service - Make sure we label content under /var/run/lock as <> - Allow daemon and systemprocesses to search init_var_run_t directory - Add boolean to allow xdm to write xauth data to the home directory - Allow mount to write keys for the unconfined domain - Add unconfined_write_keys() interface- Add labeling for /usr/share/pki - Allow programs that read var_run_t symlinks also read var_t symlinks - Add additional ports as mongod_port_t for 27018, 27019, 28017, 28018 and 28019 ports - Fix labeling for /etc/dhcp directory - add missing systemd_stub_unit_file() interface - Add files_stub_var() interface - Add lables for cert_t directories - Make localectl set-x11-keymap working at all - Allow abrt to manage mock build environments to catch build problems. - Allow virt_domains to setsched for running gdb on itself - Allow thumb_t to execute user home content - Allow pulseaudio running as mozilla_plugin_t to read /run/systemd/users/1000 - Allow certwatch to execut /usr/bin/httpd - Allow cgred to send signal perms to itself, needs back port to RHEL6 - Allow openshift_cron_t to look at quota - Allow cups_t to read inhered tmpfs_t from the kernel - Allow yppasswdd to use NIS - Tuned wants sys_rawio capability - Add ftpd_use_fusefs boolean - Allow dirsrvadmin_t to signal itself- Allow localectl to read /etc/X11/xorg.conf.d directory - Revert "Revert "Fix filetrans rules for kdm creates .xsession-errors"" - Allow mount to transition to systemd_passwd_agent - Make sure abrt directories are labeled correctly - Allow commands that are going to read mount pid files to search mount_var_run_t - label /usr/bin/repoquery as rpm_exec_t - Allow automount to block suspend - Add abrt_filetrans_named_content so that abrt directories get labeled correctly - Allow virt domains to setrlimit and read file_context- Allow nagios to manage nagios spool files - /var/spool/snmptt is a directory which snmdp needs to write to, needs back port to RHEL6 - Add swift_alias.* policy files which contain typealiases for swift types - Add support for /run/lock/opencryptoki - Allow pkcsslotd chown capability - Allow pkcsslotd to read passwd - Add rsync_stub() interface - Allow systemd_timedate also manage gnome config homedirs - Label /usr/lib64/security/pam_krb5/pam_krb5_cchelper as bin_t - Fix filetrans rules for kdm creates .xsession-errors - Allow sytemd_tmpfiles to create wtmp file - Really should not label content under /var/lock, since it could have labels on it different from var_lock_t - Allow systemd to list all file system directories - Add some basic stub interfaces which will be used in PRODUCT policies- Fix log transition rule for cluster domains - Start to group all cluster log together - Dont use filename transition for POkemon Advanced Adventure until a new checkpolicy update - cups uses usbtty_device_t devices - These fixes were all required to build a MLS virtual Machine with single level desktops - Allow domains to transiton using httpd_exec_t - Allow svirt domains to manage kernel key rings - Allow setroubleshoot to execute ldconfig - Allow firewalld to read generate gnome data - Allow bluetooth to read machine-info - Allow boinc domain to send signal to itself - Fix gnome_filetrans_home_content() interface - Allow mozilla_plugins to list apache modules, for use with gxine - Fix labels for POkemon in the users homedir - Allow xguest to read mdstat - Dontaudit virt_domains getattr on /dev/* - These fixes were all required to build a MLS virtual Machine with single level desktops - Need to back port this to RHEL6 for openshift - Add tcp/8891 as milter port - Allow nsswitch domains to read sssd_var_lib_t files - Allow ping to read network state. - Fix typo - Add labels to /etc/X11/xorg.d and allow systemd-timestampd_t to manage them- Adopt swift changes from lhh@redhat.com - Add rhcs_manage_cluster_pid_files() interface - Allow screen domains to configure tty and setup sock_file in ~/.screen directory - ALlow setroubleshoot to read default_context_t, needed to backport to F18 - Label /etc/owncloud as being an apache writable directory - Allow sshd to stream connect to an lxc domain- Allow postgresql to manage rgmanager pid files - Allow postgresql to read ccs data - Allow systemd_domain to send dbus messages to policykit - Add labels for /etc/hostname and /etc/machine-info and allow systemd-hostnamed to create them - All systemd domains that create content are reading the file_context file and setfscreate - Systemd domains need to search through init_var_run_t - Allow sshd to communicate with libvirt to set containers labels - Add interface to manage pid files - Allow NetworkManger_t to read /etc/hostname - Dontaudit leaked locked files into openshift_domains - Add fixes for oo-cgroup-read - it nows creates tmp files - Allow gluster to manage all directories as well as files - Dontaudit chrome_sandbox_nacl_t using user terminals - Allow sysstat to manage its own log files - Allow virtual machines to setrlimit and send itself signals. - Add labeling for /var/run/hplip- Fix POSTIN scriptlet- Merge rgmanger, corosync,pacemaker,aisexec policies to cluster_t in rhcs.pp- Fix authconfig.py labeling - Make any domains that write homedir content do it correctly - Allow glusterd to read/write anyhwere on the file system by default - Be a little more liberal with the rsync log files - Fix iscsi_admin interface - Allow iscsid_t to read /dev/urand - Fix up iscsi domain for use with unit files - Add filename transition support for spamassassin policy - Allow web plugins to use badly formated libraries - Allow nmbd_t to create samba_var_t directories - Add filename transition support for spamassassin policy - Add filename transition support for tvtime - Fix alsa_home_filetrans_alsa_home() interface - Move all userdom_filetrans_home_content() calling out of booleans - Allow logrotote to getattr on all file sytems - Remove duplicate userdom_filetrans_home_content() calling - Allow kadmind to read /etc/passwd - Dontaudit append .xsession-errors file on ecryptfs for policykit-auth - Allow antivirus domain to manage antivirus db links - Allow logrotate to read /sys - Allow mandb to setattr on man dirs - Remove mozilla_plugin_enable_homedirs boolean - Fix ftp_home_dir boolean - homedir mozilla filetrans has been moved to userdom_home_manager - homedir telepathy filetrans has been moved to userdom_home_manager - Remove gnome_home_dir_filetrans() from gnome_role_gkeyringd() - Might want to eventually write a daemon on fusefsd. - Add policy fixes for sshd [net] child from plautrba@redhat.com - Tor uses a new port - Remove bin_t for authconfig.py - Fix so only one call to userdom_home_file_trans - Allow home_manager_types to create content with the correctl label - Fix all domains that write data into the homedir to do it with the correct label - Change the postgresql to use proper boolean names, which is causing httpd_t to - not get access to postgresql_var_run_t - Hostname needs to send syslog messages - Localectl needs to be able to send dbus signals to users - Make sure userdom_filetrans_type will create files/dirs with user_home_t labeling by default - Allow user_home_manger domains to create spam* homedir content with correct labeling - Allow user_home_manger domains to create HOMEDIR/.tvtime with correct labeling - Add missing miscfiles_setattr_man_pages() interface and for now comment some rules for userdom_filetrans_type to make build process working - Declare userdom_filetrans_type attribute - userdom_manage_home_role() needs to be called withoout usertype attribute because of userdom_filetrans_type attribute - fusefsd is mounding a fuse file system on /run/user/UID/gvfs- Man pages are now generated in the build process - Allow cgred to list inotifyfs filesystem- Allow gluster to get attrs on all fs - New access required for virt-sandbox - Allow dnsmasq to execute bin_t - Allow dnsmasq to create content in /var/run/NetworkManager - Fix openshift_initrc_signal() interface - Dontaudit openshift domains doing getattr on other domains - Allow consolehelper domain to communicate with session bus - Mock should not be transitioning to any other domains, we should keep mock_t as mock_t - Update virt_qemu_ga_t policy - Allow authconfig running from realmd to restart oddjob service - Add systemd support for oddjob - Add initial policy for realmd_consolehelper_t which if for authconfig executed by realmd - Add labeling for gnashpluginrc - Allow chrome_nacl to execute /dev/zero - Allow condor domains to read /proc - mozilla_plugin_t will getattr on /core if firefox crashes - Allow condor domains to read /etc/passwd - Allow dnsmasq to execute shell scripts, openstack requires this access - Fix glusterd labeling - Allow virtd_t to interact with the socket type - Allow nmbd_t to override dac if you turned on sharing all files - Allow tuned to created kobject_uevent socket - Allow guest user to run fusermount - Allow openshift to read /proc and locale - Allow realmd to dbus chat with rpm - Add new interface for virt - Remove depracated interfaces - Allow systemd_domains read access on etc, etc_runtime and usr files, also allow them to connect stream to syslog socket - /usr/share/munin/plugins/plugin.sh should be labeled as bin_t - Remove some more unconfined_t process transitions, that I don't believe are necessary - Stop transitioning uncofnined_t to checkpc - dmraid creates /var/lock/dmraid - Allow systemd_localed to creatre unix_dgram_sockets - Allow systemd_localed to write kernel messages. - Also cleanup systemd definition a little. - Fix userdom_restricted_xwindows_user_template() interface - Label any block devices or char devices under /dev/infiniband as fixed_disk_device_t - User accounts need to dbus chat with accountsd daemon - Gnome requires all users to be able to read /proc/1/- virsh now does a setexeccon call - Additional rules required by openshift domains - Allow svirt_lxc_domains to use inherited terminals, needed to make virt-sandbox-service execute work - Allow spamd_update_t to search spamc_home_t - Avcs discovered by mounting an isci device under /mnt - Allow lspci running as logrotate to read pci.ids - Additional fix for networkmanager_read_pid_files() - Fix networkmanager_read_pid_files() interface - Allow all svirt domains to connect to svirt_socket_t - Allow virsh to set SELinux context for a process. - Allow tuned to create netlink_kobject_uevent_socket - Allow systemd-timestamp to set SELinux context - Add support for /var/lib/systemd/linger - Fix ssh_sysadm_login to be working on MLS as expected- Rename files_rw_inherited_tmp_files to files_rw_inherited_tmp_file - Add missing files_rw_inherited_tmp_files interface - Add additional interface for ecryptfs - ALlow nova-cert to connect to postgresql - Allow keystone to connect to postgresql - Allow all cups domains to getattr on filesystems - Allow pppd to send signull - Allow tuned to execute ldconfig - Allow gpg to read fips_enabled - Add additional fixes for ecryptfs - Allow httpd to work with posgresql - Allow keystone getsched and setsched- Allow gpg to read fips_enabled - Add support for /var/cache/realmd - Add support for /usr/sbin/blazer_usb and systemd support for nut - Add labeling for fenced_sanlock and allow sanclok transition to fenced_t - bitlbee wants to read own log file - Allow glance domain to send a signal itself - Allow xend_t to request that the kernel load a kernel module - Allow pacemaker to execute heartbeat lib files - cleanup new swift policy- Fix smartmontools - Fix userdom_restricted_xwindows_user_template() interface - Add xserver_xdm_ioctl_log() interface - Allow Xusers to ioctl lxdm.log to make lxdm working - Add MLS fixes to make MLS boot/log-in working - Add mls_socket_write_all_levels() also for syslogd - fsck.xfs needs to read passwd - Fix ntp_filetrans_named_content calling in init.te - Allow postgresql to create pg_log dir - Allow sshd to read rsync_data_t to make rsync working - Change ntp.conf to be labeled net_conf_t - Allow useradd to create homedirs in /run. ircd-ratbox does this and we should just allow it - Allow xdm_t to execute gstreamer home content - Allod initrc_t and unconfined domains, and sysadm_t to manage ntp - New policy for openstack swift domains - More access required for openshift_cron_t - Use cupsd_log_t instead of cupsd_var_log_t - rpm_script_roles should be used in rpm_run - Fix rpm_run() interface - Fix openshift_initrc_run() - Fix sssd_dontaudit_stream_connect() interface - Fix sssd_dontaudit_stream_connect() interface - Allow LDA's job to deliver mail to the mailbox - dontaudit block_suspend for mozilla_plugin_t - Allow l2tpd_t to all signal perms - Allow uuidgen to read /dev/random - Allow mozilla-plugin-config to read power_supply info - Implement cups_domain attribute for cups domains - We now need access to user terminals since we start by executing a command outside the tty - We now need access to user terminals since we start by executing a command outside the tty - svirt lxc containers want to execute userhelper apps, need these changes to allow this to happen - Add containment of openshift cron jobs - Allow system cron jobs to create tmp directories - Make userhelp_conf_t a config file - Change rpm to use rpm_script_roles - More fixes for rsync to make rsync wokring - Allow logwatch to domtrans to mdadm - Allow pacemaker to domtrans to ifconfig - Allow pacemaker to setattr on corosync.log - Add pacemaker_use_execmem for memcheck-amd64 command - Allow block_suspend capability - Allow create fifo_file in /tmp with pacemaker_tmp_t - Allow systat to getattr on fixed disk - Relabel /etc/ntp.conf to be net_conf_t - ntp_admin should create files in /etc with the correct label - Add interface to create ntp_conf_t files in /etc - Add additional labeling for quantum - Allow quantum to execute dnsmasq with transition- boinc_cliean wants also execmem as boinc projecs have - Allow sa-update to search admin home for /root/.spamassassin - Allow sa-update to search admin home for /root/.spamassassin - Allow antivirus domain to read net sysctl - Dontaudit attempts from thumb_t to connect to ssd - Dontaudit attempts by readahead to read sock_files - Dontaudit attempts by readahead to read sock_files - Create tmpfs file while running as wine as user_tmpfs_t - Dontaudit attempts by readahead to read sock_files - libmpg ships badly created librarie- Change ssh_use_pts to use macro and only inherited sshd_devpts_t - Allow confined users to read systemd_logind seat information - libmpg ships badly created libraries - Add support for strongswan.service - Add labeling for strongswan - Allow l2tpd_t to read network manager content in /run directory - Allow rsync to getattr any file in rsync_data_t - Add labeling and filename transition for .grl-podcasts- mount.glusterfs executes glusterfsd binary - Allow systemd_hostnamed_t to stream connect to systemd - Dontaudit any user doing a access check - Allow obex-data-server to request the kernel to load a module - Allow gpg-agent to manage gnome content (~/.cache/gpg-agent-info) - Allow gpg-agent to read /proc/sys/crypto/fips_enabled - Add new types for antivirus.pp policy module - Allow gnomesystemmm_t caps because of ioprio_set - Make sure if mozilla_plugin creates files while in permissive mode, they get created with the correct label, user_home_t - Allow gnomesystemmm_t caps because of ioprio_set - Allow NM rawip socket - files_relabel_non_security_files can not be used with boolean - Add interface to thumb_t dbus_chat to allow it to read remote process state - ALlow logrotate to domtrans to mdadm_t - kde gnomeclock wants to write content to /tmp- kde gnomeclock wants to write content to /tmp - /usr/libexec/kde4/kcmdatetimehelper attempts to create /root/.kde - Allow blueman_t to rwx zero_device_t, for some kind of jre - Allow mozilla_plugin_t to rwx zero_device_t, for some kind of jre - Ftp full access should be allowed to create directories as well as files - Add boolean to allow rsync_full_acces, so that an rsync server can write all - over the local machine - logrotate needs to rotate logs in openshift directories, needs back port to RHEL6 - Add missing vpnc_roles type line - Allow stapserver to write content in /tmp - Allow gnome keyring to create keyrings dir in ~/.local/share - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Add interface to colord_t dbus_chat to allow it to read remote process state - Allow colord_t to read cupsd_t state - Add mate-thumbnail-font as thumnailer - Allow sectoolm to sys_ptrace since it is looking at other proceses /proc data. - Allow qpidd to list /tmp. Needed by ssl - Only allow init_t to transition to rsync_t domain, not initrc_t. This should be back ported to F17, F18 - - Added systemd support for ksmtuned - Added booleans ksmtuned_use_nfs ksmtuned_use_cifs - firewalld seems to be creating mmap files which it needs to execute in /run /tmp and /dev/shm. Would like to clean this up but for now we will allow - Looks like qpidd_t needs to read /dev/random - Lots of probing avc's caused by execugting gpg from staff_t - Dontaudit senmail triggering a net_admin avc - Change thumb_role to use thumb_run, not sure why we have a thumb_role, needs back port - Logwatch does access check on mdadm binary - Add raid_access_check_mdadm() iterface- Fix systemd_manage_unit_symlinks() interface - Call systemd_manage_unit_symlinks(() which is correct interface - Add filename transition for opasswd - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow sytstemd-timedated to get status of init_t - Add new systemd policies for hostnamed and rename gnomeclock_t to systemd_timedate_t - colord needs to communicate with systemd and systemd_logind, also remove duplicate rules - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow gpg_t to manage all gnome files - Stop using pcscd_read_pub_files - New rules for xguest, dontaudit attempts to dbus chat - Allow firewalld to create its mmap files in tmpfs and tmp directories - Allow firewalld to create its mmap files in tmpfs and tmp directories - run unbound-chkconf as named_t, so it can read dnssec - Colord is reading xdm process state, probably reads state of any apps that sends dbus message - Allow mdadm_t to change the kernel scheduler - mythtv policy - Update mandb_admin() interface - Allow dsspam to listen on own tpc_socket - seutil_filetrans_named_content needs to be optional - Allow sysadm_t to execute content in his homedir - Add attach_queue to tun_socket, new patch from Paul Moore - Change most of selinux configuration types to security_file_type. - Add filename transition rules for selinux configuration - ssh into a box with -X -Y requires ssh_use_ptys - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Allow all unpriv userdomains to send dbus messages to hostnamed and timedated - New allow rules found by Tom London for systemd_hostnamed- Allow systemd-tmpfiles to relabel lpd spool files - Ad labeling for texlive bash scripts - Add xserver_filetrans_fonts_cache_home_content() interface - Remove duplicate rules from *.te - Add support for /var/lock/man-db.lock - Add support for /var/tmp/abrt(/.*)? - Add additional labeling for munin cgi scripts - Allow httpd_t to read munin conf files - Allow certwatch to read meminfo - Fix nscd_dontaudit_write_sock_file() interfac - Fix gnome_filetrans_home_content() to include also "fontconfig" dir as cache_home_t - llow mozilla_plugin_t to create HOMEDIR/.fontconfig with the proper labeling- Allow gnomeclock to talk to puppet over dbus - Allow numad access discovered by Dominic - Add support for HOME_DIR/.maildir - Fix attribute_role for mozilla_plugin_t domain to allow staff_r to access this domain - Allow udev to relabel udev_var_run_t lnk_files - New bin_t file in mcelog- Remove all mcs overrides and replace with t1 != mcs_constrained_types - Add attribute_role for iptables - mcs_process_set_categories needs to be called for type - Implement additional role_attribute statements - Sodo domain is attempting to get the additributes of proc_kcore_t - Unbound uses port 8953 - Allow svirt_t images to compromise_kernel when using pci-passthrough - Add label for dns lib files - Bluetooth aquires a dbus name - Remove redundant files_read_usr_file calling - Remove redundant files_read_etc_file calling - Fix mozilla_run_plugin() - Add role_attribute support for more domains- Mass merge with upstream- Bump the policy version to 28 to match selinux userspace - Rebuild versus latest libsepol- Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Add labeling for /var/named/chroot/etc/localtim- Allow setroubleshoot_fixit to execute rpm - zoneminder needs to connect to httpd ports where remote cameras are listening - Allow firewalld to execute content created in /run directory - Allow svirt_t to read generic certs - Dontaudit leaked ps content to mozilla plugin - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - init scripts are creating systemd_unit_file_t directories- systemd_logind_t is looking at all files under /run/user/apache - Allow systemd to manage all user tmp files - Add labeling for /var/named/chroot/etc/localtime - Allow netlabel_peer_t type to flow over netif_t and node_t, and only be hindered by MLS, need back port to RHEL6 - Keystone is now using a differnt port - Allow xdm_t to use usbmuxd daemon to control sound - Allow passwd daemon to execute gnome_exec_keyringd - Fix chrome_sandbox policy - Add labeling for /var/run/checkquorum-timer - More fixes for the dspam domain, needs back port to RHEL6 - More fixes for the dspam domain, needs back port to RHEL6 - sssd needs to connect to kerberos password port if a user changes his password - Lots of fixes from RHEL testing of dspam web - Allow chrome and mozilla_plugin to create msgq and semaphores - Fixes for dspam cgi scripts - Fixes for dspam cgi scripts - Allow confine users to ptrace screen - Backport virt_qemu_ga_t changes from RHEL - Fix labeling for dspam.cgi needed for RHEL6 - We need to back port this policy to RHEL6, for lxc domains - Dontaudit attempts to set sys_resource of logrotate - Allow corosync to read/write wdmd's tmpfs files - I see a ptrace of mozilla_plugin_t by staff_t, will allow without deny_ptrace being set - Allow cron jobs to read bind config for unbound - libvirt needs to inhibit systemd - kdumpctl needs to delete boot_t files - Fix duplicate gnome_config_filetrans - virtd_lxc_t is using /dev/fuse - Passenger needs to create a directory in /var/log, needs a backport to RHEL6 for openshift - apcupsd can be setup to listen to snmp trafic - Allow transition from kdumpgui to kdumpctl - Add fixes for munin CGI scripts - Allow deltacloud to connect to openstack at the keystone port - Allow domains that transition to svirt domains to be able to signal them - Fix file context of gstreamer in .cache directory - libvirt is communicating with logind - NetworkManager writes to the systemd inhibit pipe- Allow munin disk plugins to get attributes of all directories - Allow munin disk plugins to get attributes of all directorie - Allow logwatch to get attributes of all directories - Fix networkmanager_manage_lib() interface - Fix gnome_manage_config() to allow to manage sock_file - Fix virtual_domain_context - Add support for dynamic DNS for DHCPv6- Allow svirt to use netlink_route_socket which was a part of auth_use_nsswitch - Add additional labeling for /var/www/openshift/broker - Fix rhev policy - Allow openshift_initrc domain to dbus chat with systemd_logind - Allow httpd to getattr passenger log file if run_stickshift - Allow consolehelper-gtk to connect to xserver - Add labeling for the tmp-inst directory defined in pam_namespace.conf - Add lvm_metadata_t labeling for /etc/multipath- consoletype is no longer used- Add label for efivarfs - Allow certmonger to send signal to itself - Allow plugin-config to read own process status - Add more fixes for pacemaker - apache/drupal can run clamscan on uploaded content - Allow chrome_sandbox_nacl_t to read pid 1 content- Fix MCS Constraints to control ingres and egres controls on the network. - Change name of svirt_nokvm_t to svirt_tcg_t - Allow tuned to request the kernel to load kernel modules- Label /var/lib/pgsql/.ssh as ssh_home_t - Add labeling for /usr/bin/pg_ctl - Allow systemd-logind to manage keyring user tmp dirs - Add support for 7389/tcp port - gems seems to be placed in lots of places - Since xdm is running a full session, it seems to be trying to execute lots of executables via dbus - Add back tcp/8123 port as http_cache port - Add ovirt-guest-agent\.pid labeling - Allow xend to run scsi_id - Allow rhsmcertd-worker to read "physical_package_id" - Allow pki_tomcat to connect to ldap port - Allow lpr to read /usr/share/fonts - Allow open file from CD/DVD drive on domU - Allow munin services plugins to talk to SSSD - Allow all samba domains to create samba directory in var_t directories - Take away svirt_t ability to use nsswitch - Dontaudit attempts by openshift to read apache logs - Allow apache to create as well as append _ra_content_t - Dontaudit sendmail_t reading a leaked file descriptor - Add interface to have admin transition /etc/prelink.cache to the proper label - Add sntp support to ntp policy - Allow firewalld to dbus chat with devicekit_power - Allow tuned to call lsblk - Allow tor to read /proc/sys/kernel/random/uuid - Add tor_can_network_relay boolean- Add openshift_initrc_signal() interface - Fix typos - dspam port is treat as spamd_port_t - Allow setroubleshoot to getattr on all executables - Allow tuned to execute profiles scripts in /etc/tuned - Allow apache to create directories to store its log files - Allow all directories/files in /var/log starting with passenger to be labeled passenger_log_t - Looks like apache is sending sinal to openshift_initrc_t now,needs back port to RHEL6 - Allow Postfix to be configured to listen on TCP port 10026 for email from DSPAM - Add filename transition for /etc/tuned/active_profile - Allow condor_master to send mails - Allow condor_master to read submit.cf - Allow condor_master to create /tmp files/dirs - Allow condor_mater to send sigkill to other condor domains - Allow condor_procd sigkill capability - tuned-adm wants to talk with tuned daemon - Allow kadmind and krb5kdc to also list sssd_public_t - Allow accountsd to dbus chat with init - Fix git_read_generic_system_content_files() interface - pppd wants sys_nice by nmcli because of "syscall=sched_setscheduler" - Fix mozilla_plugin_can_network_connect to allow to connect to all ports - Label all munin plugins which are not covered by munin plugins policy as unconfined_munin_plugin_exec_t - dspam wants to search /var/spool for opendkim data - Revert "Add support for tcp/10026 port as dspam_port_t" - Turning on labeled networking requires additional access for netlabel_peer_t; these allow rules need to be back ported to RHEL6 - Allow all application domains to use fifo_files passed in from userdomains, also allow them to write to tmp_files inherited from userdomain - Allow systemd_tmpfiles_t to setattr on mandb_cache_t- consolekit.pp was not removed from the postinstall script- Add back consolekit policy - Silence bootloader trying to use inherited tty - Silence xdm_dbusd_t trying to execute telepathy apps - Fix shutdown avcs when machine has unconfined.pp disabled - The host and a virtual machine can share the same printer on a usb device - Change oddjob to transition to a ranged openshift_initr_exec_t when run from oddjob - Allow abrt_watch_log_t to execute bin_t - Allow chrome sandbox to write content in ~/.config/chromium - Dontaudit setattr on fontconfig dir for thumb_t - Allow lircd to request the kernel to load module - Make rsync as userdom_home_manager - Allow rsync to search automount filesystem - Add fixes for pacemaker- Add support for 4567/tcp port - Random fixes from Tuomo Soini - xdm wants to get init status - Allow programs to run in fips_mode - Add interface to allow the reading of all blk device nodes - Allow init to relabel rpcbind sock_file - Fix labeling for lastlog and faillog related to logrotate - ALlow aeolus_configserver to use TRAM port - Add fixes for aeolus_configserver - Allow snmpd to connect to snmp port - Allow spamd_update to create spamd_var_lib_t directories - Allow domains that can read sssd_public_t files to also list the directory - Remove miscfiles_read_localization, this is defined for all domains- Allow syslogd to request the kernel to load a module - Allow syslogd_t to read the network state information - Allow xdm_dbusd_t connect to the system DBUS - Add support for 7389/tcp port - Allow domains to read/write all inherited sockets - Allow staff_t to read kmsg - Add awstats_purge_apache_log boolean - Allow ksysguardproces to read /.config/Trolltech.conf - Allow passenger to create and append puppet log files - Add puppet_append_log and puppet_create_log interfaces - Add puppet_manage_log() interface - Allow tomcat domain to search tomcat_var_lib_t - Allow pki_tomcat_t to connect to pki_ca ports - Allow pegasus_t to have net_admin capability - Allow pegasus_t to write /sys/class/net//flags - Allow mailserver_delivery to manage mail_home_rw_t lnk_files - Allow fetchmail to create log files - Allow gnomeclock to manage home config in .kde - Allow bittlebee to read kernel sysctls - Allow logrotate to list /root- Fix userhelper_console_role_template() - Allow enabling Network Access Point service using blueman - Make vmware_host_t as unconfined domain - Allow authenticate users in webaccess via squid, using mysql as backend - Allow gathers to get various metrics on mounted file systems - Allow firewalld to read /etc/hosts - Fix cron_admin_role() to make sysadm cronjobs running in the sysadm_t instead of cronjob_t - Allow kdumpgui to read/write to zipl.conf - Commands needed to get mock to build from staff_t in enforcing mode - Allow mdadm_t to manage cgroup files - Allow all daemons and systemprocesses to use inherited initrc_tmp_t files - dontaudit ifconfig_t looking at fifo_files that are leaked to it - Add lableing for Quest Authentication System- Fix filetrans interface definitions - Dontaudit xdm_t to getattr on BOINC lib files - Add systemd_reload_all_services() interface - Dontaudit write access on /var/lib/net-snmp/mib_indexes - Only stop mcsuntrustedproc from relableing files - Allow accountsd to dbus chat with gdm - Allow realmd to getattr on all fs - Allow logrotate to reload all services - Add systemd unit file for radiusd - Allow winbind to create samba pid dir - Add labeling for /var/nmbd/unexpected - Allow chrome and mozilla plugin to connect to msnp ports- Fix storage_rw_inherited_fixed_disk_dev() to cover also blk_file - Dontaudit setfiles reading /dev/random - On initial boot gnomeclock is going to need to be set buy gdm - Fix tftp_read_content() interface - Random apps looking at kernel file systems - Testing virt with lxc requiers additional access for virsh_t - New allow rules requied for latest libvirt, libvirt talks directly to journald,lxc setup tool needs compromize_kernel,and we need ipc_lock in the container - Allow MPD to read /dev/radnom - Allow sandbox_web_type to read logind files which needs to read pulseaudio - Allow mozilla plugins to read /dev/hpet - Add labeling for /var/lib/zarafa-webap - Allow BOINC client to use an HTTP proxy for all connections - Allow rhsmertd to domain transition to dmidecod - Allow setroubleshootd to send D-Bus msg to ABRT- Define usbtty_device_t as a term_tty - Allow svnserve to accept a connection - Allow xend manage default virt_image_t type - Allow prelink_cron_system_t to overide user componant when executing cp - Add labeling for z-push - Gnomeclock sets the realtime clock - Openshift seems to be storing apache logs in /var/lib/openshift/.log/httpd - Allow lxc domains to use /dev/random and /dev/urandom- Add port defintion for tcp/9000 - Fix labeling for /usr/share/cluster/checkquorum to label also checkquorum.wdmd - Add rules and labeling for $HOME/cache/\.gstreamer-.* directory - Add support for CIM provider openlmi-networking which uses NetworkManager dbus API - Allow shorewall_t to create netlink_socket - Allow krb5admind to block suspend - Fix labels on /var/run/dlm_controld /var/log/dlm_controld - Allow krb5kdc to block suspend - gnomessytemmm_t needs to read /etc/passwd - Allow cgred to read all sysctls- Allow all domains to read /proc/sys/vm/overcommit_memory - Make proc_numa_t an MLS Trusted Object - Add /proc/numactl support for confined users - Allow ssh_t to connect to any port > 1023 - Add openvswitch domain - Pulseaudio tries to create directories in gnome_home_t directories - New ypbind pkg wants to search /var/run which is caused by sd_notify - Allow NM to read certs on NFS/CIFS using use_nfs_*, use_samba_* booleans - Allow sanlock to read /dev/random - Treat php-fpm with httpd_t - Allow domains that can read named_conf_t to be able to list the directories - Allow winbind to create sock files in /var/run/samba- Add smsd policy - Add support for OpenShift sbin labelin - Add boolean to allow virt to use rawip - Allow mozilla_plugin to read all file systems with noxattrs support - Allow kerberos to write on anon_inodefs fs - Additional access required by fenced - Add filename transitions for passwd.lock/group.lock - UPdate man pages - Create coolkey directory in /var/cache with the correct label- Fix label on /etc/group.lock - Allow gnomeclock to create lnk_file in /etc - label /root/.pki as a home_cert_t - Add interface to make sure rpcbind.sock is created with the correct label - Add definition for new directory /var/lib/os-probe and bootloader wants to read udev rules - opendkim should be a part of milter - Allow libvirt to set the kernel sched algorythm - Allow mongod to read sysfs_t - Add authconfig policy - Remove calls to miscfiles_read_localization all domains get this - Allow virsh_t to read /root/.pki/ content - Add label for log directory under /var/www/stickshift- Allow getty to setattr on usb ttys - Allow sshd to search all directories for sshd_home_t content - Allow staff domains to send dbus messages to kdumpgui - Fix labels on /etc/.pwd.lock and friends to be passwd_file_t - Dontaudit setfiles reading urand - Add files_dontaudit_list_tmp() for domains to which we added sys_nice/setsched - Allow staff_gkeyringd_t to read /home/$USER/.local/share/keyrings dir - Allow systemd-timedated to read /dev/urandom - Allow entropyd_t to read proc_t (meminfo) - Add unconfined munin plugin - Fix networkmanager_read_conf() interface - Allow blueman to list /tmp which is needed by sys_nic/setsched - Fix label of /etc/mail/aliasesdb-stamp - numad is searching cgroups - realmd is communicating with networkmanager using dbus - Lots of fixes to try to get kdump to work- Allow loging programs to dbus chat with realmd - Make apache_content_template calling as optional - realmd is using policy kit- Add new selinuxuser_use_ssh_chroot boolean - dbus needs to be able to read/write inherited fixed disk device_t passed through it - Cleanup netutils process allow rule - Dontaudit leaked fifo files from openshift to ping - sanlock needs to read mnt_t lnk files - Fail2ban needs to setsched and sys_nice- Change default label of all files in /var/run/rpcbind - Allow sandbox domains (java) to read hugetlbfs_t - Allow awstats cgi content to create tmp files and read apache log files - Allow setuid/setgid for cupsd-config - Allow setsched/sys_nice pro cupsd-config - Fix /etc/localtime sym link to be labeled locale_t - Allow sshd to search postgresql db t since this is a homedir - Allow xwindows users to chat with realmd - Allow unconfined domains to configure all files and null_device_t service- Adopt pki-selinux policy- pki is leaking which we dontaudit until a pki code fix - Allow setcap for arping - Update man pages - Add labeling for /usr/sbin/mcollectived - pki fixes - Allow smokeping to execute fping in the netutils_t domain- Allow mount to relabelfrom unlabeled file systems - systemd_logind wants to send and receive messages from devicekit disk over dbus to make connected mouse working - Add label to get bin files under libreoffice labeled correctly - Fix interface to allow executing of base_ro_file_type - Add fixes for realmd - Update pki policy - Add tftp_homedir boolean - Allow blueman sched_setscheduler - openshift user domains wants to r/w ssh tcp sockets- Additional requirements for disable unconfined module when booting - Fix label of systemd script files - semanage can use -F /dev/stdin to get input - syslog now uses kerberos keytabs - Allow xserver to compromise_kernel access - Allow nfsd to write to mount_var_run_t when running the mount command - Add filename transition rule for bin_t directories - Allow files to read usr_t lnk_files - dhcpc wants chown - Add support for new openshift labeling - Clean up for tunable+optional statements - Add labeling for /usr/sbin/mkhomedir_helper - Allow antivirus domain to managa amavis spool files - Allow rpcbind_t to read passwd - Allow pyzor running as spamc to manage amavis spool- Add interfaces to read kernel_t proc info - Missed this version of exec_all - Allow anyone who can load a kernel module to compromise kernel - Add oddjob_dbus_chat to openshift apache policy - Allow chrome_sandbox_nacl_t to send signals to itself - Add unit file support to usbmuxd_t - Allow all openshift domains to read sysfs info - Allow openshift domains to getattr on all domains- MLS fixes from Dan - Fix name of capability2 secure_firmware->compromise_kerne- Allow xdm to search all file systems - Add interface to allow the config of all files - Add rngd policy - Remove kgpg as a gpg_exec_t type - Allow plymouthd to block suspend - Allow systemd_dbus to config any file - Allow system_dbus_t to configure all services - Allow freshclam_t to read usr_files - varnishd requires execmem to load modules- Allow semanage to verify types - Allow sudo domain to execute user home files - Allow session_bus_type to transition to user_tmpfs_t - Add dontaudit caused by yum updates - Implement pki policy but not activated- tuned wants to getattr on all filesystems - tuned needs also setsched. The build is needed for test day- Add policy for qemu-qa - Allow razor to write own config files - Add an initial antivirus policy to collect all antivirus program - Allow qdisk to read usr_t - Add additional caps for vmware_host - Allow tmpfiles_t to setattr on mandb_cache_t - Dontaudit leaked files into mozilla_plugin_config_t - Allow wdmd to getattr on tmpfs - Allow realmd to use /dev/random - allow containers to send audit messages - Allow root mount any file via loop device with enforcing mls policy - Allow tmpfiles_t to setattr on mandb_cache_t - Allow tmpfiles_t to setattr on mandb_cache_t - Make userdom_dontaudit_write_all_ not allow open - Allow init scripts to read all unit files - Add support for saphostctrl ports- Add kernel_read_system_state to sandbox_client_t - Add some of the missing access to kdumpgui - Allow systemd_dbusd_t to status the init system - Allow vmnet-natd to request the kernel to load a module - Allow gsf-office-thum to append .cache/gdm/session.log - realmd wants to read .config/dconf/user - Firewalld wants sys_nice/setsched - Allow tmpreaper to delete mandb cache files - Firewalld wants sys_nice/setsched - Allow firewalld to perform a DNS name resolution - Allown winbind to read /usr/share/samba/codepages/lowcase.dat - Add support for HTTPProxy* in /etc/freshclam.conf - Fix authlogin_yubike boolean - Extend smbd_selinux man page to include samba booleans - Allow dhcpc to execute consoletype - Allow ping to use inherited tmp files created in init scripts - On full relabel with unconfined domain disabled, initrc was running some chcon's - Allow people who delete man pages to delete mandb cache files- Add missing permissive domains- Add new mandb policy - ALlow systemd-tmpfiles_t to relabel mandb_cache_t - Allow logrotate to start all unit files- Add fixes for ctbd - Allow nmbd to stream connect to ctbd - Make cglear_t as nsswitch_domain - Fix bogus in interfaces - Allow openshift to read/write postfix public pipe - Add postfix_manage_spool_maildrop_files() interface - stickshift paths have been renamed to openshift - gnome-settings-daemon wants to write to /run/systemd/inhibit/ pipes - Update man pages, adding ENTRYPOINTS- Add mei_device_t - Make sure gpg content in homedir created with correct label - Allow dmesg to write to abrt cache files - automount wants to search virtual memory sysctls - Add support for hplip logs stored in /var/log/hp/tmp - Add labeling for /etc/owncloud/config.php - Allow setroubleshoot to send analysys to syslogd-journal - Allow virsh_t to interact with new fenced daemon - Allow gpg to write to /etc/mail/spamassassiin directories - Make dovecot_deliver_t a mail server delivery type - Add label for /var/tmp/DNS25- Fixes for tomcat_domain template interface- Remove init_systemd and init_upstart boolean, Move init_daemon_domain and init_system_domain to use attributes - Add attribute to all base os types. Allow all domains to read all ro base OS types- Additional unit files to be defined as power unit files - Fix more boolean names- Fix boolean name so subs will continue to work- dbus needs to start getty unit files - Add interface to allow system_dbusd_t to start the poweroff service - xdm wants to exec telepathy apps - Allow users to send messages to systemdlogind - Additional rules needed for systemd and other boot apps - systemd wants to list /home and /boot - Allow gkeyringd to write dbus/conf file - realmd needs to read /dev/urand - Allow readahead to delete /.readahead if labeled root_t, might get created before policy is loaded- Fixes to safe more rules - Re-write tomcat_domain_template() - Fix passenger labeling - Allow all domains to read man pages - Add ephemeral_port_t to the 'generic' port interfaces - Fix the names of postgresql booleans- Stop using attributes form netlabel_peer and syslog, auth_use_nsswitch setsup netlabel_peer - Move netlable_peer check out of booleans - Remove call to recvfrom_netlabel for kerberos call - Remove use of attributes when calling syslog call - Move -miscfiles_read_localization to domain.te to save hundreds of allow rules - Allow all domains to read locale files. This eliminates around 1500 allow rules- Cleanup nis_use_ypbind_uncond interface - Allow rndc to block suspend - tuned needs to modify the schedule of the kernel - Allow svirt_t domains to read alsa configuration files - ighten security on irc domains and make sure they label content in homedir correctly - Add filetrans_home_content for irc files - Dontaudit all getattr access for devices and filesystems for sandbox domains - Allow stapserver to search cgroups directories - Allow all postfix domains to talk to spamd- Add interfaces to ignore setattr until kernel fixes this to be checked after the DAC check - Change pam_t to pam_timestamp_t - Add dovecot_domain attribute and allow this attribute block_suspend capability2 - Add sanlock_use_fusefs boolean - numad wants send/recieve msg - Allow rhnsd to send syslog msgs - Make piranha-pulse as initrc domain - Update openshift instances to dontaudit setattr until the kernel is fixed.- Fix auth_login_pgm_domain() interface to allow domains also managed user tmp dirs because of #856880 related to pam_systemd - Remove pam_selinux.8 which conflicts with man page owned by the pam package - Allow glance-api to talk to mysql - ABRT wants to read Xorg.0.log if if it detects problem with Xorg - Fix gstreamer filename trans. interface- Man page fixes by Dan Walsh- Allow postalias to read postfix config files - Allow man2html to read man pages - Allow rhev-agentd to search all mountpoints - Allow rhsmcertd to read /dev/random - Add tgtd_stream_connect() interface - Add cyrus_write_data() interface - Dontaudit attempts by sandboxX clients connectiing to the xserver_port_t - Add port definition for tcp/81 as http_port_t - Fix /dev/twa labeling - Allow systemd to read modules config- Merge openshift policy - Allow xauth to read /dev/urandom - systemd needs to relabel content in /run/systemd directories - Files unconfined should be able to perform all services on all files - Puppet tmp file can be leaked to all domains - Dontaudit rhsmcertd-worker to search /root/.local - Allow chown capability for zarafa domains - Allow system cronjobs to runcon into openshift domains - Allow virt_bridgehelper_t to manage content in the svirt_home_t labeled directories- nmbd wants to create /var/nmbd - Stop transitioning out of anaconda and firstboot, just causes AVC messages - Allow clamscan to read /etc files - Allow bcfg2 to bind cyphesis port - heartbeat should be run as rgmanager_t instead of corosync_t - Add labeling for /etc/openldap/certs - Add labeling for /opt/sartest directory - Make crontab_t as userdom home reader - Allow tmpreaper to list admin_home dir - Add defition for imap_0 replay cache file - Add support for gitolite3 - Allow virsh_t to send syslog messages - allow domains that can read samba content to be able to list the directories also - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd - Separate out sandbox from sandboxX policy so we can disable it by default - Run dmeventd as lvm_t - Mounting on any directory requires setattr and write permissions - Fix use_nfs_home_dirs() boolean - New labels for pam_krb5 - Allow init and initrc domains to sys_ptrace since this is needed to look at processes not owned by uid 0 - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd- Separate sandbox policy into sandbox and sandboxX, and disable sandbox by default on fresh installs - Allow domains that can read etc_t to read etc_runtime_t - Allow all domains to use inherited tmpfiles- Allow realmd to read resolv.conf - Add pegasus_cache_t type - Label /usr/sbin/fence_virtd as virsh_exec_t - Add policy for pkcsslotd - Add support for cpglockd - Allow polkit-agent-helper to read system-auth-ac - telepathy-idle wants to read gschemas.compiled - Allow plymouthd to getattr on fs_t - Add slpd policy - Allow ksysguardproces to read/write config_usr_t- Fix labeling substitution so rpm will label /lib/systemd content correctly- Add file name transitions for ttyACM0 - spice-vdagent(d)'s are going to log over to syslog - Add sensord policy - Add more fixes for passenger policy related to puppet - Allow wdmd to create wdmd_tmpfs_t - Fix labeling for /var/run/cachefilesd\.pid - Add thumb_tmpfs_t files type- Allow svirt domains to manage the network since this is containerized - Allow svirt_lxc_net_t to send audit messages- Make "snmpwalk -mREDHAT-CLUSTER-MIB ...." working - Allow dlm_controld to execute dlm_stonith labeled as bin_t - Allow GFS2 working on F17 - Abrt needs to execute dmesg - Allow jockey to list the contents of modeprobe.d - Add policy for lightsquid as squid_cron_t - Mailscanner is creating files and directories in /tmp - dmesg is now reading /dev/kmsg - Allow xserver to communicate with secure_firmware - Allow fsadm tools (fsck) to read /run/mount contnet - Allow sysadm types to read /dev/kmsg -- Allow postfix, sssd, rpcd to block_suspend - udev seems to need secure_firmware capability - Allow virtd to send dbus messages to firewalld so it can configure the firewall- Fix labeling of content in /run created by virsh_t - Allow condor domains to read kernel sysctls - Allow condor_master to connect to amqp - Allow thumb drives to create shared memory and semaphores - Allow abrt to read mozilla_plugin config files - Add labels for lightsquid - Default files in /opt and /usr that end in .cgi as httpd_sys_script_t, allow - dovecot_auth_t uses ldap for user auth - Allow domains that can read dhcp_etc_t to read lnk_files - Add more then one watchdog device - Allow useradd_t to manage etc_t files so it can rename it and edit them - Fix invalid class dir should be fifo_file - Move /run/blkid to fsadm and make sure labeling is correct- Fix bogus regex found by eparis - Fix manage run interface since lvm needs more access - syslogd is searching cgroups directory - Fixes to allow virt-sandbox-service to manage lxc var run content- Fix Boolean settings - Add new libjavascriptcoregtk as textrel_shlib_t - Allow xdm_t to create xdm_home_t directories - Additional access required for systemd - Dontaudit mozilla_plugin attempts to ipc_lock - Allow tmpreaper to delete unlabeled files - Eliminate screen_tmp_t and allow it to manage user_tmp_t - Dontaudit mozilla_plugin_config_t to append to leaked file descriptors - Allow web plugins to connect to the asterisk ports - Condor will recreate the lock directory if it does not exist - Oddjob mkhomedir needs to connectto user processes - Make oddjob_mkhomedir_t a userdom home manager- Put placeholder back in place for proper numbering of capabilities - Systemd also configures init scripts- Fix ecryptfs interfaces - Bootloader seems to be trolling around /dev/shm and /dev - init wants to create /etc/systemd/system-update.target.wants - Fix systemd_filetrans call to move it out of tunable - Fix up policy to work with systemd userspace manager - Add secure_firmware capability and remove bogus epolwakeup - Call seutil_*_login_config interfaces where should be needed - Allow rhsmcertd to send signal to itself - Allow thin domains to send signal to itself - Allow Chrome_ChildIO to read dosfs_t- Add role rules for realmd, sambagui- Add new type selinux_login_config_t for /etc/selinux//logins/ - Additional fixes for seutil_manage_module_store() - dbus_system_domain() should be used with optional_policy - Fix svirt to be allowed to use fusefs file system - Allow login programs to read /run/ data created by systemd_login - sssd wants to write /etc/selinux//logins/ for SELinux PAM module - Fix svirt to be allowed to use fusefs file system - Allow piranha domain to use nsswitch - Sanlock needs to send Kill Signals to non root processes - Pulseaudio wants to execute /run/user/PID/.orc- Fix saslauthd when it tries to read /etc/shadow - Label gnome-boxes as a virt homedir - Need to allow svirt_t ability to getattr on nfs_t file systems - Update sanlock policy to solve all AVC's - Change confined users can optionally manage virt content - Handle new directories under ~/.cache - Add block suspend to appropriate domains - More rules required for containers - Allow login programs to read /run/ data created by systemd_logind - Allow staff users to run svirt_t processes- Update to upstream- More fixes for systemd to make rawhide booting from Dan Walsh- Add systemd fixes to make rawhide booting- Add systemd_logind_inhibit_var_run_t attribute - Remove corenet_all_recvfrom_unlabeled() for non-contrib policies because we moved it to domain.if for all domain_type - Add interface for mysqld to dontaudit signull to all processes - Label new /var/run/journal directory correctly - Allow users to inhibit suspend via systemd - Add new type for the /var/run/inhibit directory - Add interface to send signull to systemd_login so avahi can send them - Allow systemd_passwd to send syslog messages - Remove corenet_all_recvfrom_unlabeled() calling fro policy files - Allow editparams.cgi running as httpd_bugzilla_script_t to read /etc/group - Allow smbd to read cluster config - Add additional labeling for passenger - Allow dbus to inhibit suspend via systemd - Allow avahi to send signull to systemd_login- Add interface to dontaudit getattr access on sysctls - Allow sshd to execute /bin/login - Looks like xdm is recreating the xdm directory in ~/.cache/ on login - Allow syslog to use the leaked kernel_t unix_dgram_socket from system-jounald - Fix semanage to work with unconfined domain disabled on F18 - Dontaudit attempts by mozilla plugins to getattr on all kernel sysctls - Virt seems to be using lock files - Dovecot seems to be searching directories of every mountpoint - Allow jockey to read random/urandom, execute shell and install third-party drivers - Add aditional params to allow cachedfiles to manage its content - gpg agent needs to read /dev/random - The kernel hands an svirt domains /SYSxxxxx which is a tmpfs that httpd wants to read and write - Add a bunch of dontaudit rules to quiet svirt_lxc domains - Additional perms needed to run svirt_lxc domains - Allow cgclear to read cgconfig - Allow sys_ptrace capability for snmp - Allow freshclam to read /proc - Allow procmail to manage /home/user/Maildir content - Allow NM to execute wpa_cli - Allow amavis to read clamd system state - Regenerate man pages- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Add realmd and stapserver policies - Allow useradd to manage stap-server lib files - Tighten up capabilities for confined users - Label /etc/security/opasswd as shadow_t - Add label for /dev/ecryptfs - Allow condor_startd_t to start sshd with the ranged - Allow lpstat.cups to read fips_enabled file - Allow pyzor running as spamc_t to create /root/.pyzor directory - Add labelinf for amavisd-snmp init script - Add support for amavisd-snmp - Allow fprintd sigkill self - Allow xend (w/o libvirt) to start virtual machines - Allow aiccu to read /etc/passwd - Allow condor_startd to Make specified domain MCS trusted for setting any category set for the processes it executes - Add condor_startd_ranged_domtrans_to() interface - Add ssd_conf_t for /etc/sssd - accountsd needs to fchown some files/directories - Add ICACLient and zibrauserdata as mozilla_filetrans_home_content - SELinux reports afs_t needs dac_override to read /etc/mtab, even though everything works, adding dontaudit - Allow xend_t to read the /etc/passwd file- Until we figure out how to fix systemd issues, allow all apps that send syslog messages to send them to kernel_t - Add init_access_check() interface - Fix label on /usr/bin/pingus to not be labeled as ping_exec_t - Allow tcpdump to create a netlink_socket - Label newusers like useradd - Change xdm log files to be labeled xdm_log_t - Allow sshd_t with privsep to work in MLS - Allow freshclam to update databases thru HTTP proxy - Allow s-m-config to access check on systemd - Allow abrt to read public files by default - Fix amavis_create_pid_files() interface - Add labeling and filename transition for dbomatic.log - Allow system_dbusd_t to stream connect to bluetooth, and use its socket - Allow amavisd to execute fsav - Allow tuned to use sys_admin and sys_nice capabilities - Add php-fpm policy from Bryan - Add labeling for aeolus-configserver-thinwrapper - Allow thin domains to execute shell - Fix gnome_role_gkeyringd() interface description - Lot of interface fixes - Allow OpenMPI job running as condor_startd_ssh_t to manage condor lib files - Allow OpenMPI job to use kerberos - Make deltacloudd_t as nsswitch_domain - Allow xend_t to run lsscsi - Allow qemu-dm running as xend_t to create tun_socket - Add labeling for /opt/brother/Printers(.*/)?inf - Allow jockey-backend to read pyconfig-64.h labeled as usr_t - Fix clamscan_can_scan_system boolean - Allow lpr to connectto to /run/user/$USER/keyring-22uREb/pkcs11- initrc is calling exportfs which is not confined so it attempts to read nfsd_files - Fixes for passenger running within openshift. - Add labeling for all tomcat6 dirs - Add support for tomcat6 - Allow cobblerd to read /etc/passwd - Allow jockey to read sysfs and and execute binaries with bin_t - Allow thum to use user terminals - Allow cgclear to read cgconfig config files - Fix bcf2g.fc - Remove sysnet_dns_name_resolve() from policies where auth_use_nsswitch() is used for other domains - Allow dbomatic to execute ruby - abrt_watch_log should be abrt_domain - Allow mozilla_plugin to connect to gatekeeper port- add ptrace_child access to process - remove files_read_etc_files() calling from all policies which have auth_use_nsswith() - Allow boinc domains to manage boinc_lib_t lnk_files - Add support for boinc-client.service unit file - Add support for boinc.log - Allow mozilla_plugin execmod on mozilla home files if allow_ex - Allow dovecot_deliver_t to read dovecot_var_run_t - Allow ldconfig and insmod to manage kdumpctl tmp files - Move thin policy out from cloudform.pp and add a new thin poli - pacemaker needs to communicate with corosync streams - abrt is now started on demand by dbus - Allow certmonger to talk directly to Dogtag servers - Change labeling for /var/lib/cobbler/webui_sessions to httpd_c - Allow mozila_plugin to execute gstreamer home files - Allow useradd to delete all file types stored in the users hom - rhsmcertd reads the rpm database - Add support for lightdm- Add tomcat policy - Remove pyzor/razor policy - rhsmcertd reads the rpm database - Dontaudit thumb to setattr on xdm_tmp dir - Allow wicd to execute ldconfig in the networkmanager_t domain - Add /var/run/cherokee\.pid labeling - Allow mozilla_plugin to create mozilla_plugin_tmp_t lnk files too - Allow postfix-master to r/w pipes other postfix domains - Allow snort to create netlink_socket - Add kdumpctl policy - Allow firstboot to create tmp_t files/directories - /usr/bin/paster should not be labeled as piranha_exec_t - remove initrc_domain from tomcat - Allow ddclient to read /etc/passwd - Allow useradd to delete all file types stored in the users homedir - Allow ldconfig and insmod to manage kdumpctl tmp files - Firstboot should be just creating tmp_t dirs and xauth should be allowed to write to those - Transition xauth files within firstboot_tmp_t - Fix labeling of /run/media to match /media - Label all lxdm.log as xserver_log_t - Add port definition for mxi port - Allow local_login_t to execute tmux- apcupsd needs to read /etc/passwd - Sanlock allso sends sigkill - Allow glance_registry to connect to the mysqld port - Dontaudit mozilla_plugin trying to getattr on /dev/gpmctl - Allow firefox plugins/flash to connect to port 1234 - Allow mozilla plugins to delete user_tmp_t files - Add transition name rule for printers.conf.O - Allow virt_lxc_t to read urand - Allow systemd_loigind to list gstreamer_home_dirs - Fix labeling for /usr/bin - Fixes for cloudform services * support FIPS - Allow polipo to work as web caching - Allow chfn to execute tmux- Add support for ecryptfs * ecryptfs does not support xattr * we need labeling for HOMEDIR - Add policy for (u)mount.ecryptfs* - Fix labeling of kerbero host cache files, allow rpc.svcgssd to manage host cache - Allow dovecot to manage Maildir content, fix transitions to Maildir - Allow postfix_local to transition to dovecot_deliver - Dontaudit attempts to setattr on xdm_tmp_t, looks like bogus code - Cleanup interface definitions - Allow apmd to change with the logind daemon - Changes required for sanlock in rhel6 - Label /run/user/apache as httpd_tmp_t - Allow thumb to use lib_t as execmod if boolean turned on - Allow squid to create the squid directory in /var with the correct labe - Add a new policy for glusterd from Bryan Bickford (bbickfor@redhat.com) - Allow virtd to exec xend_exec_t without transition - Allow virtd_lxc_t to unmount all file systems- PolicyKit path has changed - Allow httpd connect to dirsrv socket - Allow tuned to write generic kernel sysctls - Dontaudit logwatch to gettr on /dev/dm-2 - Allow policykit-auth to manage kerberos files - Make condor_startd and rgmanager as initrc domain - Allow virsh to read /etc/passwd - Allow mount to mount on user_tmp_t for /run/user/dwalsh/gvfs - xdm now needs to execute xsession_exec_t - Need labels for /var/lib/gdm - Fix files_filetrans_named_content() interface - Add new attribute - initrc_domain - Allow systemd_logind_t to signal, signull, sigkill all processes - Add filetrans rules for etc_runtime files- Rename boolean names to remove allow_- Mass merge with upstream * new policy topology to include contrib policy modules * we have now two base policy patches- Fix description of authlogin_nsswitch_use_ldap - Fix transition rule for rhsmcertd_t needed for RHEL7 - Allow useradd to list nfs state data - Allow openvpn to manage its log file and directory - We want vdsm to transition to mount_t when executing mount command to make sure /etc/mtab remains labeled correctly - Allow thumb to use nvidia devices - Allow local_login to create user_tmp_t files for kerberos - Pulseaudio needs to read systemd_login /var/run content - virt should only transition named system_conf_t config files - Allow munin to execute its plugins - Allow nagios system plugin to read /etc/passwd - Allow plugin to connect to soundd port - Fix httpd_passwd to be able to ask passwords - Radius servers can use ldap for backing store - Seems to need to mount on /var/lib for xguest polyinstatiation to work. - Allow systemd_logind to list the contents of gnome keyring - VirtualGL need xdm to be able to manage content in /etc/opt/VirtualGL - Add policy for isns-utils- Add policy for subversion daemon - Allow boinc to read passwd - Allow pads to read kernel network state - Fix man2html interface for sepolgen-ifgen - Remove extra /usr/lib/systemd/system/smb - Remove all /lib/systemd and replace with /usr/lib/systemd - Add policy for man2html - Fix the label of kerberos_home_t to krb5_home_t - Allow mozilla plugins to use Citrix - Allow tuned to read /proc/sys/kernel/nmi_watchdog - Allow tune /sys options via systemd's tmpfiles.d "w" type- Dontaudit lpr_t to read/write leaked mozilla tmp files - Add file name transition for .grl-podcasts directory - Allow corosync to read user tmp files - Allow fenced to create snmp lib dirs/files - More fixes for sge policy - Allow mozilla_plugin_t to execute any application - Allow dbus to read/write any open file descriptors to any non security file on the system that it inherits to that it can pass them to another domain - Allow mongod to read system state information - Fix wrong type, we should dontaudit sys_admin for xdm_t not xserver_t - Allow polipo to manage polipo_cache dirs - Add jabbar_client port to mozilla_plugin_t - Cleanup procmail policy - system bus will pass around open file descriptors on files that do not have labels on them - Allow l2tpd_t to read system state - Allow tuned to run ls /dev - Allow sudo domains to read usr_t files - Add label to machine-id - Fix corecmd_read_bin_symlinks cut and paste error- Fix pulseaudio port definition - Add labeling for condor_starter - Allow chfn_t to creat user_tmp_files - Allow chfn_t to execute bin_t - Allow prelink_cron_system_t to getpw calls - Allow sudo domains to manage kerberos rcache files - Allow user_mail_domains to work with courie - Port definitions necessary for running jboss apps within openshift - Add support for openstack-nova-metadata-api - Add support for nova-console* - Add support for openstack-nova-xvpvncproxy - Fixes to make privsep+SELinux working if we try to use chage to change passwd - Fix auth_role() interface - Allow numad to read sysfs - Allow matahari-rpcd to execute shell - Add label for ~/.spicec - xdm is executing lspci as root which is requesting a sys_admin priv but seems to succeed without it - Devicekit_disk wants to read the logind sessions file when writing a cd - Add fixes for condor to make condor jobs working correctly - Change label of /var/log/rpmpkgs to cron_log_t - Access requires to allow systemd-tmpfiles --create to work. - Fix obex to be a user application started by the session bus. - Add additional filename trans rules for kerberos - Fix /var/run/heartbeat labeling - Allow apps that are managing rcache to file trans correctly - Allow openvpn to authenticate against ldap server - Containers need to listen to network starting and stopping events- Make systemd unit files less specific- Fix zarafa labeling - Allow guest_t to fix labeling - corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the user_tcp_server boolean - add lxc_contexts - Allow accountsd to read /proc - Allow restorecond to getattr on all file sytems - tmpwatch now calls getpw - Allow apache daemon to transition to pwauth domain - Label content under /var/run/user/NAME/keyring* as gkeyringd_tmp_t - The obex socket seems to be a stream socket - dd label for /var/run/nologin- Allow jetty running as httpd_t to read hugetlbfs files - Allow sys_nice and setsched for rhsmcertd - Dontaudit attempts by mozilla_plugin_t to bind to ssdp ports - Allow setfiles to append to xdm_tmp_t - Add labeling for /export as a usr_t directory - Add labels for .grl files created by gstreamer- Add labeling for /usr/share/jetty/bin/jetty.sh - Add jetty policy which contains file type definitios - Allow jockey to use its own fifo_file and make this the default for all domains - Allow mozilla_plugins to use spice (vnc_port/couchdb) - asterisk wants to read the network state - Blueman now uses /var/lib/blueman- Add label for nodejs_debug - Allow mozilla_plugin_t to create ~/.pki directory and content- Add clamscan_can_scan_system boolean - Allow mysqld to read kernel network state - Allow sshd to read/write condor lib files - Allow sshd to read/write condor-startd tcp socket - Fix description on httpd_graceful_shutdown - Allow glance_registry to communicate with mysql - dbus_system_domain is using systemd to lauch applications - add interfaces to allow domains to send kill signals to user mail agents - Remove unnessary access for svirt_lxc domains, add privs for virtd_lxc_t - Lots of new access required for secure containers - Corosync needs sys_admin capability - ALlow colord to create shm - .orc should be allowed to be created by any app that can create gstream home content, thumb_t to be specific - Add boolean to control whether or not mozilla plugins can create random content in the users homedir - Add new interface to allow domains to list msyql_db directories, needed for libra - shutdown has to be allowed to delete etc_runtime_t - Fail2ban needs to read /etc/passwd - Allow ldconfig to create /var/cache/ldconfig - Allow tgtd to read hardware state information - Allow collectd to create packet socket - Allow chronyd to send signal to itself - Allow collectd to read /dev/random - Allow collectd to send signal to itself - firewalld needs to execute restorecon - Allow restorecon and other login domains to execute restorecon- Allow logrotate to getattr on systemd unit files - Add support for tor systemd unit file - Allow apmd to create /var/run/pm-utils with the correct label - Allow l2tpd to send sigkill to pppd - Allow pppd to stream connect to l2tpd - Add label for scripts in /etc/gdm/ - Allow systemd_logind_t to ignore mcs constraints on sigkill - Fix files_filetrans_system_conf_named_files() interface - Add labels for /usr/share/wordpress/wp-includes/*.php - Allow cobbler to get SELinux mode and booleans- Add unconfined_execmem_exec_t as an alias to bin_t - Allow fenced to read snmp var lib files, also allow it to read usr_t - ontaudit access checks on all executables from mozilla_plugin - Allow all user domains to setexec, so that sshd will work properly if it call setexec(NULL) while running withing a user mode - Allow systemd_tmpfiles_t to getattr all pipes and sockets - Allow glance-registry to send system log messages - semanage needs to manage mock lib files/dirs- Add policy for abrt-watch-log - Add definitions for jboss_messaging ports - Allow systemd_tmpfiles to manage printer devices - Allow oddjob to use nsswitch - Fix labeling of log files for postgresql - Allow mozilla_plugin_t to execmem and execstack by default - Allow firewalld to execute shell - Fix /etc/wicd content files to get created with the correct label - Allow mcelog to exec shell - Add ~/.orc as a gstreamer_home_t - /var/spool/postfix/lib64 should be labeled lib_t - mpreaper should be able to list all file system labeled directories - Add support for apache to use openstack - Add labeling for /etc/zipl.conf and zipl binary - Turn on allow_execstack and turn off telepathy transition for final release- More access required for virt_qmf_t - Additional assess required for systemd-logind to support multi-seat - Allow mozilla_plugin to setrlimit - Revert changes to fuse file system to stop deadlock- Allow condor domains to connect to ephemeral ports - More fixes for condor policy - Allow keystone to stream connect to mysqld - Allow mozilla_plugin_t to read generic USB device to support GPS devices - Allow thum to file name transition gstreamer home content - Allow thum to read all non security files - Allow glance_api_t to connect to ephemeral ports - Allow nagios plugins to read /dev/urandom - Allow syslogd to search postfix spool to support postfix chroot env - Fix labeling for /var/spool/postfix/dev - Allow wdmd chown - Label .esd_auth as pulseaudio_home_t - Have no idea why keyring tries to write to /run/user/dwalsh/dconf/user, but we can dontaudit for now- Add support for clamd+systemd - Allow fresclam to execute systemctl to handle clamd - Change labeling for /usr/sbin/rpc.ypasswd.env - Allow yppaswd_t to execute yppaswd_exec_t - Allow yppaswd_t to read /etc/passwd - Gnomekeyring socket has been moved to /run/user/USER/ - Allow samba-net to connect to ldap port - Allow signal for vhostmd - allow mozilla_plugin_t to read user_home_t socket - New access required for secure Linux Containers - zfs now supports xattrs - Allow quantum to execute sudo and list sysfs - Allow init to dbus chat with the firewalld - Allow zebra to read /etc/passwd- Allow svirt_t to create content in the users homedir under ~/.libvirt - Fix label on /var/lib/heartbeat - Allow systemd_logind_t to send kill signals to all processes started by a user - Fuse now supports Xattr Support- upowered needs to setsched on the kernel - Allow mpd_t to manage log files - Allow xdm_t to create /var/run/systemd/multi-session-x - Add rules for missedfont.log to be used by thumb.fc - Additional access required for virt_qmf_t - Allow dhclient to dbus chat with the firewalld - Add label for lvmetad - Allow systemd_logind_t to remove userdomain sock_files - Allow cups to execute usr_t files - Fix labeling on nvidia shared libraries - wdmd_t needs access to sssd and /etc/passwd - Add boolean to allow ftp servers to run in passive mode - Allow namepspace_init_t to relabelto/from a different user system_u from the user the namespace_init running with - Fix using httpd_use_fusefs - Allow chrome_sandbox_nacl to write inherited user tmp files as we allow it for chrome_sandbox- Rename rdate port to time port, and allow gnomeclock to connect to it - We no longer need to transition to ldconfig from rpm, rpm_script, or anaconda - /etc/auto.* should be labeled bin_t - Add httpd_use_fusefs boolean - Add fixes for heartbeat - Allow sshd_t to signal processes that it transitions to - Add condor policy - Allow svirt to create monitors in ~/.libvirt - Allow dovecot to domtrans sendmail to handle sieve scripts - Lot of fixes for cfengine- /var/run/postmaster.* labeling is no longer needed - Alllow drbdadmin to read /dev/urandom - l2tpd_t seems to use ptmx - group+ and passwd+ should be labeled as /etc/passwd - Zarafa-indexer is a socket- Ensure lastlog is labeled correctly - Allow accountsd to read /proc data about gdm - Add fixes for tuned - Add bcfg2 fixes which were discovered during RHEL6 testing - More fixes for gnome-keyring socket being moved - Run semanage as a unconfined domain, and allow initrc_t to create tmpfs_t sym links on shutdown - Fix description for files_dontaudit_read_security_files() interface- Add new policy and man page for bcfg2 - cgconfig needs to use getpw calls - Allow domains that communicate with the keyring to use cache_home_t instead of gkeyringd_tmpt - gnome-keyring wants to create a directory in cache_home_t - sanlock calls getpw- Add numad policy and numad man page - Add fixes for interface bugs discovered by SEWatch - Add /tmp support for squid - Add fix for #799102 * change default labeling for /var/run/slapd.* sockets - Make thumb_t as userdom_home_reader - label /var/lib/sss/mc same as pubconf, so getpw domains can read it - Allow smbspool running as cups_t to stream connect to nmbd - accounts needs to be able to execute passwd on behalf of users - Allow systemd_tmpfiles_t to delete boot flags - Allow dnssec_trigger to connect to apache ports - Allow gnome keyring to create sock_files in ~/.cache - google_authenticator is using .google_authenticator - sandbox running from within firefox is exposing more leaks - Dontaudit thumb to read/write /dev/card0 - Dontaudit getattr on init_exec_t for gnomeclock_t - Allow certmonger to do a transition to certmonger_unconfined_t - Allow dhcpc setsched which is caused by nmcli - Add rpm_exec_t for /usr/sbin/bcfg2 - system cronjobs are sending dbus messages to systemd_logind - Thumnailers read /dev/urand- Allow auditctl getcap - Allow vdagent to use libsystemd-login - Allow abrt-dump-oops to search /etc/abrt - Got these avc's while trying to print a boarding pass from firefox - Devicekit is now putting the media directory under /run/media - Allow thumbnailers to create content in ~/.thumbails directory - Add support for proL2TPd by Dominick Grift - Allow all domains to call getcap - wdmd seems to get a random chown capability check that it does not need - Allow vhostmd to read kernel sysctls- Allow chronyd to read unix - Allow hpfax to read /etc/passwd - Add support matahari vios-proxy-* apps and add virtd_exec_t label for them - Allow rpcd to read quota_db_t - Update to man pages to match latest policy - Fix bug in jockey interface for sepolgen-ifgen - Add initial svirt_prot_exec_t policy- More fixes for systemd from Dan Walsh- Add a new type for /etc/firewalld and allow firewalld to write to this directory - Add definition for ~/Maildir, and allow mail deliver domains to write there - Allow polipo to run from a cron job - Allow rtkit to schedule wine processes - Allow mozilla_plugin_t to acquire a bug, and allow it to transition gnome content in the home dir to the proper label - Allow users domains to send signals to consolehelper domains- More fixes for boinc policy - Allow polipo domain to create its own cache dir and pid file - Add systemctl support to httpd domain - Add systemctl support to polipo, allow NetworkManager to manage the service - Add policy for jockey-backend - Add support for motion daemon which is now covered by zoneminder policy - Allow colord to read/write motion tmpfs - Allow vnstat to search through var_lib_t directories - Stop transitioning to quota_t, from init an sysadm_t- Add svirt_lxc_file_t as a customizable type- Add additional fixes for icmp nagios plugin - Allow cron jobs to open fifo_files from cron, since service script opens /dev/stdin - Add certmonger_unconfined_exec_t - Make sure tap22 device is created with the correct label - Allow staff users to read systemd unit files - Merge in previously built policy - Arpwatch needs to be able to start netlink sockets in order to start - Allow cgred_t to sys_ptrace to look at other DAC Processes- Back port some of the access that was allowed in nsplugin_t - Add definitiona for couchdb ports - Allow nagios to use inherited users ttys - Add git support for mock - Allow inetd to use rdate port - Add own type for rdate port - Allow samba to act as a portmapper - Dontaudit chrome_sandbox attempts to getattr on chr_files in /dev - New fixes needed for samba4 - Allow apps that use lib_t to read lib_t symlinks- Add policy for nove-cert - Add labeling for nova-openstack systemd unit files - Add policy for keystoke- Fix man pages fro domains - Add man pages for SELinux users and roles - Add storage_dev_filetrans_named_fixed_disk() and use it for smartmon - Add policy for matahari-rpcd - nfsd executes mount command on restart - Matahari domains execute renice and setsched - Dontaudit leaked tty in mozilla_plugin_config - mailman is changing to a per instance naming - Add 7600 and 4447 as jboss_management ports - Add fixes for nagios event handlers - Label httpd.event as httpd_exec_t, it is an apache daemon- Add labeling for /var/spool/postfix/dev/log - NM reads sysctl.conf - Iscsi log file context specification fix - Allow mozilla plugins to send dbus messages to user domains that transition to it - Allow mysql to read the passwd file - Allow mozilla_plugin_t to create mozilla home dirs in user homedir - Allow deltacloud to read kernel sysctl - Allow postgresql_t to connectto itselfAllow postgresql_t to connectto itself - Allow postgresql_t to connectto itself - Add login_userdomain attribute for users which can log in using terminal- Allow sysadm_u to reach system_r by default #784011 - Allow nagios plugins to use inherited user terminals - Razor labeling is not used no longer - Add systemd support for matahari - Add port_types to man page, move booleans to the top, fix some english - Add support for matahari-sysconfig-console - Clean up matahari.fc - Fix matahari_admin() interfac - Add labels for/etc/ssh/ssh_host_*.pub keys- Allow ksysguardproces to send system log msgs - Allow boinc setpgid and signull - Allow xdm_t to sys_ptrace to run pidof command - Allow smtpd_t to manage spool files/directories and symbolic links - Add labeling for jetty - Needed changes to get unbound/dnssec to work with openswan- Add user_fonts_t alias xfs_tmp_t - Since depmod now runs as insmod_t we need to write to kernel_object_t - Allow firewalld to dbus chat with networkmanager - Allow qpidd to connect to matahari ports - policykit needs to read /proc for uses not owned by it - Allow systemctl apps to connecto the init stream- Turn on deny_ptrace boolean- Remove pam_selinux.8 man page. There was a conflict.- Add proxy class and read access for gssd_proxy - Separate out the sharing public content booleans - Allow certmonger to execute a script and send signals to apache and dirsrv to reload the certificate - Add label transition for gstream-0.10 and 12 - Add booleans to allow rsync to share nfs and cifs file sytems - chrome_sandbox wants to read the /proc/PID/exe file of the program that executed it - Fix filename transitions for cups files - Allow denyhosts to read "unix" - Add file name transition for locale.conf.new - Allow boinc projects to gconf config files - sssd needs to be able to increase the socket limit under certain loads - sge_execd needs to read /etc/passwd - Allow denyhost to check network state - NetworkManager needs to read sessions data - Allow denyhost to check network state - Allow xen to search virt images directories - Add label for /dev/megaraid_sas_ioctl_node - Add autogenerated man pages- Allow boinc project to getattr on fs - Allow init to execute initrc_state_t - rhev-agent package was rename to ovirt-guest-agent - If initrc_t creates /etc/local.conf then we need to make sure it is labeled correctly - sytemd writes content to /run/initramfs and executes it on shutdown - kdump_t needs to read /etc/mtab, should be back ported to F16 - udev needs to load kernel modules in early system boot- Need to add sys_ptrace back in since reading any content in /proc can cause these accesses - Add additional systemd interfaces which are needed fro *_admin interfaces - Fix bind_admin() interface- Allow firewalld to read urand - Alias java, execmem_mono to bin_t to allow third parties - Add label for kmod - /etc/redhat-lsb contains binaries - Add boolean to allow gitosis to send mail - Add filename transition also for "event20" - Allow systemd_tmpfiles_t to delete all file types - Allow collectd to ipc_lock- make consoletype_exec optional, so we can remove consoletype policy - remove unconfined_permisive.patch - Allow openvpn_t to inherit user home content and tmp content - Fix dnssec-trigger labeling - Turn on obex policy for staff_t - Pem files should not be secret - Add lots of rules to fix AVC's when playing with containers - Fix policy for dnssec - Label ask-passwd directories correctly for systemd- sshd fixes seem to be causing unconfined domains to dyntrans to themselves - fuse file system is now being mounted in /run/user - systemd_logind is sending signals to processes that are dbus messaging with it - Add support for winshadow port and allow iscsid to connect to this port - httpd should be allowed to bind to the http_port_t udp socket - zarafa_var_lib_t can be a lnk_file - A couple of new .xsession-errors files - Seems like user space and login programs need to read logind_sessions_files - Devicekit disk seems to be being launched by systemd - Cleanup handling of setfiles so most of rules in te file - Correct port number for dnssec - logcheck has the home dir set to its cache- Add policy for grindengine MPI jobs- Add new sysadm_secadm.pp module * contains secadm definition for sysadm_t - Move user_mail_domain access out of the interface into the te file - Allow httpd_t to create httpd_var_lib_t directories as well as files - Allow snmpd to connect to the ricci_modcluster stream - Allow firewalld to read /etc/passwd - Add auth_use_nsswitch for colord - Allow smartd to read network state - smartdnotify needs to read /etc/group- Allow gpg and gpg_agent to store sock_file in gpg_secret_t directory - lxdm startup scripts should be labeled bin_t, so confined users will work - mcstransd now creates a pid, needs back port to F16 - qpidd should be allowed to connect to the amqp port - Label devices 010-029 as usb devices - ypserv packager says ypserv does not use tmp_t so removing selinux policy types - Remove all ptrace commands that I believe are caused by the kernel/ps avcs - Add initial Obex policy - Add logging_syslogd_use_tty boolean - Add polipo_connect_all_unreserved bolean - Allow zabbix to connect to ftp port - Allow systemd-logind to be able to switch VTs - Allow apache to communicate with memcached through a sock_file- Fix file_context.subs_dist for now to work with pre usrmove- More /usr move fixes- Add zabbix_can_network boolean - Add httpd_can_connect_zabbix boolean - Prepare file context labeling for usrmove functions - Allow system cronjobs to read kernel network state - Add support for selinux_avcstat munin plugin - Treat hearbeat with corosync policy - Allow corosync to read and write to qpidd shared mem - mozilla_plugin is trying to run pulseaudio - Fixes for new sshd patch for running priv sep domains as the users context - Turn off dontaudit rules when turning on allow_ypbind - udev now reads /etc/modules.d directory- Turn on deny_ptrace boolean for the Rawhide run, so we can test this out - Cups exchanges dbus messages with init - udisk2 needs to send syslog messages - certwatch needs to read /etc/passwd- Add labeling for udisks2 - Allow fsadmin to communicate with the systemd process- Treat Bip with bitlbee policy * Bip is an IRC proxy - Add port definition for interwise port - Add support for ipa_memcached socket - systemd_jounald needs to getattr on all processes - mdadmin fixes * uses getpw - amavisd calls getpwnam() - denyhosts calls getpwall()- Setup labeling of /var/rsa and /var/lib/rsa to allow login programs to write there - bluetooth says they do not use /tmp and want to remove the type - Allow init to transition to colord - Mongod needs to read /proc/sys/vm/zone_reclaim_mode - Allow postfix_smtpd_t to connect to spamd - Add boolean to allow ftp to connect to all ports > 1023 - Allow sendmain to write to inherited dovecot tmp files - setroubleshoot needs to be able to execute rpm to see what version of packages- Merge systemd patch - systemd-tmpfiles wants to relabel /sys/devices/system/cpu/online - Allow deltacloudd dac_override, setuid, setgid caps - Allow aisexec to execute shell - Add use_nfs_home_dirs boolean for ssh-keygen- Fixes to make rawhide boot in enforcing mode with latest systemd changes- Add labeling for /var/run/systemd/journal/syslog - libvirt sends signals to ifconfig - Allow domains that read logind session files to list them- Fixed destined form libvirt-sandbox - Allow apps that list sysfs to also read sympolicy links in this filesystem - Add ubac_constrained rules for chrome_sandbox - Need interface to allow domains to use tmpfs_t files created by the kernel, used by libra - Allow postgresql to be executed by the caller - Standardize interfaces of daemons - Add new labeling for mm-handler - Allow all matahari domains to read network state and etc_runtime_t files- New fix for seunshare, requires seunshare_domains to be able to mounton / - Allow systemctl running as logrotate_t to connect to private systemd socket - Allow tmpwatch to read meminfo - Allow rpc.svcgssd to read supported_krb5_enctype - Allow zarafa domains to read /dev/random and /dev/urandom - Allow snmpd to read dev_snmp6 - Allow procmail to talk with cyrus - Add fixes for check_disk and check_nagios plugins- default trans rules for Rawhide policy - Make sure sound_devices controlC* are labeled correctly on creation - sssd now needs sys_admin - Allow snmp to read all proc_type - Allow to setup users homedir with quota.group- Add httpd_can_connect_ldap() interface - apcupsd_t needs to use seriel ports connected to usb devices - Kde puts procmail mail directory under ~/.local/share - nfsd_t can trigger sys_rawio on tests that involve too many mountpoints, dontaudit for now - Add labeling for /sbin/iscsiuio- Add label for /var/lib/iscan/interpreter - Dont audit writes to leaked file descriptors or redirected output for nacl - NetworkManager needs to write to /sys/class/net/ib*/mode- Allow abrt to request the kernel to load a module - Make sure mozilla content is labeled correctly - Allow tgtd to read system state - More fixes for boinc * allow to resolve dns name * re-write boinc policy to use boinc_domain attribute - Allow munin services plugins to use NSCD services- Allow mozilla_plugin_t to manage mozilla_home_t - Allow ssh derived domain to execute ssh-keygen in the ssh_keygen_t domain - Add label for tumblerd- Fixes for xguest package- Fixes related to /bin, /sbin - Allow abrt to getattr on blk files - Add type for rhev-agent log file - Fix labeling for /dev/dmfm - Dontaudit wicd leaking - Allow systemd_logind_t to look at process info of apps that exchange dbus messages with it - Label /etc/locale.conf correctly - Allow user_mail_t to read /dev/random - Allow postfix-smtpd to read MIMEDefang - Add label for /var/log/suphp.log - Allow swat_t to connect and read/write nmbd_t sock_file - Allow systemd-tmpfiles to setattr for /run/user/gdm/dconf - Allow systemd-tmpfiles to change user identity in object contexts - More fixes for rhev_agentd_t consolehelper policy- Use fs_use_xattr for squashf - Fix procs_type interface - Dovecot has a new fifo_file /var/run/dovecot/stats-mail - Dovecot has a new fifo_file /var/run/stats-mail - Colord does not need to connect to network - Allow system_cronjob to dbus chat with NetworkManager - Puppet manages content, want to make sure it labels everything correctly- Change port 9050 to tor_socks_port_t and then allow openvpn to connect to it - Allow all postfix domains to use the fifo_file - Allow sshd_t to getattr on all file systems in order to generate avc on nfs_t - Allow apmd_t to read grub.cfg - Let firewallgui read the selinux config - Allow systemd-tmpfiles to delete content in /root that has been moved to /tmp - Fix devicekit_manage_pid_files() interface - Allow squid to check the network state - Dontaudit colord getattr on file systems - Allow ping domains to read zabbix_tmp_t files- Allow mcelog_t to create dir and file in /var/run and label it correctly - Allow dbus to manage fusefs - Mount needs to read process state when mounting gluster file systems - Allow collectd-web to read collectd lib files - Allow daemons and system processes started by init to read/write the unix_stream_socket passed in from as stdin/stdout/stderr - Allow colord to get the attributes of tmpfs filesystem - Add sanlock_use_nfs and sanlock_use_samba booleans - Add bin_t label for /usr/lib/virtualbox/VBoxManage- Add ssh_dontaudit_search_home_dir - Changes to allow namespace_init_t to work - Add interface to allow exec of mongod, add port definition for mongod port, 27017 - Label .kde/share/apps/networkmanagement/certificates/ as home_cert_t - Allow spamd and clamd to steam connect to each other - Add policy label for passwd.OLD - More fixes for postfix and postfix maildro - Add ftp support for mozilla plugins - Useradd now needs to manage policy since it calls libsemanage - Fix devicekit_manage_log_files() interface - Allow colord to execute ifconfig - Allow accountsd to read /sys - Allow mysqld-safe to execute shell - Allow openct to stream connect to pcscd - Add label for /var/run/nm-dns-dnsmasq\.conf - Allow networkmanager to chat with virtd_t- Pulseaudio changes - Merge patches- Merge patches back into git repository.- Remove allow_execmem boolean and replace with deny_execmem boolean- Turn back on allow_execmem boolean- Add more MCS fixes to make sandbox working - Make faillog MLS trusted to make sudo_$1_t working - Allow sandbox_web_client_t to read passwd_file_t - Add .mailrc file context - Remove execheap from openoffice domain - Allow chrome_sandbox_nacl_t to read cpu_info - Allow virtd to relabel generic usb which is need if USB device - Fixes for virt.if interfaces to consider chr_file as image file type- Remove Open Office policy - Remove execmem policy- MCS fixes - quota fixes- Remove transitions to consoletype- Make nvidia* to be labeled correctly - Fix abrt_manage_cache() interface - Make filetrans rules optional so base policy will build - Dontaudit chkpwd_t access to inherited TTYS - Make sure postfix content gets created with the correct label - Allow gnomeclock to read cgroup - Fixes for cloudform policy- Check in fixed for Chrome nacl support- Begin removing qemu_t domain, we really no longer need this domain. - systemd_passwd needs dac_overide to communicate with users TTY's - Allow svirt_lxc domains to send kill signals within their container- Remove qemu.pp again without causing a crash- Remove qemu.pp, everything should use svirt_t or stay in its current domain- Allow policykit to talk to the systemd via dbus - Move chrome_sandbox_nacl_t to permissive domains - Additional rules for chrome_sandbox_nacl- Change bootstrap name to nacl - Chrome still needs execmem - Missing role for chrome_sandbox_bootstrap - Add boolean to remove execmem and execstack from virtual machines - Dontaudit xdm_t doing an access_check on etc_t directories- Allow named to connect to dirsrv by default - add ldapmap1_0 as a krb5_host_rcache_t file - Google chrome developers asked me to add bootstrap policy for nacl stuff - Allow rhev_agentd_t to getattr on mountpoints - Postfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd_t unix_stream_sockets- Fixes for cloudform policies which need to connect to random ports - Make sure if an admin creates modules content it creates them with the correct label - Add port 8953 as a dns port used by unbound - Fix file name transition for alsa and confined users- Turn on mock_t and thumb_t for unconfined domains- Policy update should not modify local contexts- Remove ada policy- Remove tzdata policy - Add labeling for udev - Add cloudform policy - Fixes for bootloader policy- Add policies for nova openstack- Add fixes for nova-stack policy- Allow svirt_lxc_domain to chr_file and blk_file devices if they are in the domain - Allow init process to setrlimit on itself - Take away transition rules for users executing ssh-keygen - Allow setroubleshoot_fixit_t to read /dev/urand - Allow sshd to relbale tunnel sockets - Allow fail2ban domtrans to shorewall in the same way as with iptables - Add support for lnk files in the /var/lib/sssd directory - Allow system mail to connect to courier-authdaemon over an unix stream socket- Add passwd_file_t for /etc/ptmptmp- Dontaudit access checks for all executables, gnome-shell is doing access(EXEC, X_OK) - Make corosync to be able to relabelto cluster lib fies - Allow samba domains to search /var/run/nmbd - Allow dirsrv to use pam - Allow thumb to call getuid - chrome less likely to get mmap_zero bug so removing dontaudit - gimp help-browser has built in javascript - Best guess is that devices named /dev/bsr4096 should be labeled as cpu_device_t - Re-write glance policy- Move dontaudit sys_ptrace line from permissive.te to domain.te - Remove policy for hal, it no longer exists- Don't check md5 size or mtime on certain config files- Remove allow_ptrace and replace it with deny_ptrace, which will remove all ptrace from the system - Remove 2000 dontaudit rules between confined domains on transition and replace with single dontaudit domain domain:process { noatsecure siginh rlimitinh } ;- Fixes for bootloader policy - $1_gkeyringd_t needs to read $HOME/%USER/.local/share/keystore - Allow nsplugin to read /usr/share/config - Allow sa-update to update rules - Add use_fusefs_home_dirs for chroot ssh option - Fixes for grub2 - Update systemd_exec_systemctl() interface - Allow gpg to read the mail spool - More fixes for sa-update running out of cron job - Allow ipsec_mgmt_t to read hardware state information - Allow pptp_t to connect to unreserved_port_t - Dontaudit getattr on initctl in /dev from chfn - Dontaudit getattr on kernel_core from chfn - Add systemd_list_unit_dirs to systemd_exec_systemctl call - Fixes for collectd policy - CHange sysadm_t to create content as user_tmp_t under /tmp- Shrink size of policy through use of attributes for userdomain and apache- Allow virsh to read xenstored pid file - Backport corenetwork fixes from upstream - Do not audit attempts by thumb to search config_home_t dirs (~/.config) - label ~/.cache/telepathy/logger telepathy_logger_cache_home_t - allow thumb to read generic data home files (mime.type)- Allow nmbd to manage sock file in /var/run/nmbd - ricci_modservice send syslog msgs - Stop transitioning from unconfined_t to ldconfig_t, but make sure /etc/ld.so.cache is labeled correctly - Allow systemd_logind_t to manage /run/USER/dconf/user- Fix missing patch from F16- Allow logrotate setuid and setgid since logrotate is supposed to do it - Fixes for thumb policy by grift - Add new nfsd ports - Added fix to allow confined apps to execmod on chrome - Add labeling for additional vdsm directories - Allow Exim and Dovecot SASL - Add label for /var/run/nmbd - Add fixes to make virsh and xen working together - Colord executes ls - /var/spool/cron is now labeled as user_cron_spool_t- Stop complaining about leaked file descriptors during install- Remove java and mono module and merge into execmem- Fixes for thumb policy and passwd_file_t- Fixes caused by the labeling of /etc/passwd - Add thumb.patch to transition unconfined_t to thumb_t for Rawhide- Add support for Clustered Samba commands - Allow ricci_modrpm_t to send log msgs - move permissive virt_qmf_t from virt.te to permissivedomains.te - Allow ssh_t to use kernel keyrings - Add policy for libvirt-qmf and more fixes for linux containers - Initial Polipo - Sanlock needs to run ranged in order to kill svirt processes - Allow smbcontrol to stream connect to ctdbd- Add label for /etc/passwd- Change unconfined_domains to permissive for Rawhide - Add definition for the ephemeral_ports- Make mta_role() active - Allow asterisk to connect to jabber client port - Allow procmail to read utmp - Add NIS support for systemd_logind_t - Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t - Fix systemd_manage_unit_dirs() interface - Allow ssh_t to manage directories passed into it - init needs to be able to create and delete unit file directories - Fix typo in apache_exec_sys_script - Add ability for logrotate to transition to awstat domain- Change screen to use screen_domain attribute and allow screen_domains to read all process domain state - Add SELinux support for ssh pre-auth net process in F17 - Add logging_syslogd_can_sendmail boolean- Add definition for ephemeral ports - Define user_tty_device_t as a customizable_type- Needs to require a new version of checkpolicy - Interface fixes- Allow sanlock to manage virt lib files - Add virt_use_sanlock booelan - ksmtuned is trying to resolve uids - Make sure .gvfs is labeled user_home_t in the users home directory - Sanlock sends kill signals and needs the kill capability - Allow mockbuild to work on nfs homedirs - Fix kerberos_manage_host_rcache() interface - Allow exim to read system state- Allow systemd-tmpfiles to set the correct labels on /var/run, /tmp and other files - We want any file type that is created in /tmp by a process running as initrc_t to be labeled initrc_tmp_t- Allow collectd to read hardware state information - Add loop_control_device_t - Allow mdadm to request kernel to load module - Allow domains that start other domains via systemctl to search unit dir - systemd_tmpfiles, needs to list any file systems mounted on /tmp - No one can explain why radius is listing the contents of /tmp, so we will dontaudit - If I can manage etc_runtime files, I should be able to read the links - Dontaudit hostname writing to mock library chr_files - Have gdm_t setup labeling correctly in users home dir - Label content unde /var/run/user/NAME/dconf as config_home_t - Allow sa-update to execute shell - Make ssh-keygen working with fips_enabled - Make mock work for staff_t user - Tighten security on mock_t- removing unconfined_notrans_t no longer necessary - Clean up handling of secure_mode_insmod and secure_mode_policyload - Remove unconfined_mount_t- Add exim_exec_t label for /usr/sbin/exim_tidydb - Call init_dontaudit_rw_stream_socket() interface in mta policy - sssd need to search /var/cache/krb5rcache directory - Allow corosync to relabel own tmp files - Allow zarafa domains to send system log messages - Allow ssh to do tunneling - Allow initrc scripts to sendto init_t unix_stream_socket - Changes to make sure dmsmasq and virt directories are labeled correctly - Changes needed to allow sysadm_t to manage systemd unit files - init is passing file descriptors to dbus and on to system daemons - Allow sulogin additional access Reported by dgrift and Jeremy Miller - Steve Grubb believes that wireshark does not need this access - Fix /var/run/initramfs to stop restorecon from looking at - pki needs another port - Add more labels for cluster scripts - Allow apps that manage cgroup_files to manage cgroup link files - Fix label on nfs-utils scripts directories - Allow gatherd to read /dev/rand and /dev/urand- pki needs another port - Add more labels for cluster scripts - Fix label on nfs-utils scripts directories - Fixes for cluster - Allow gatherd to read /dev/rand and /dev/urand - abrt leaks fifo files- Add glance policy - Allow mdadm setsched - /var/run/initramfs should not be relabeled with a restorecon run - memcache can be setup to override sys_resource - Allow httpd_t to read tetex data - Allow systemd_tmpfiles to delete kernel modules left in /tmp directory.- Allow Postfix to deliver to Dovecot LMTP socket - Ignore bogus sys_module for lldpad - Allow chrony and gpsd to send dgrams, gpsd needs to write to the real time clock - systemd_logind_t sets the attributes on usb devices - Allow hddtemp_t to read etc_t files - Add permissivedomains module - Move all permissive domains calls to permissivedomain.te - Allow pegasis to send kill signals to other UIDs- Allow insmod_t to use fds leaked from devicekit - dontaudit getattr between insmod_t and init_t unix_stream_sockets - Change sysctl unit file interfaces to use systemctl - Add support for chronyd unit file - Allow mozilla_plugin to read gnome_usr_config - Add policy for new gpsd - Allow cups to create kerberos rhost cache files - Add authlogin_filetrans_named_content, to unconfined_t to make sure shadow and other log files get labeled correctly- Make users_extra and seusers.final into config(noreplace) so semanage users and login does not get overwritten- Add policy for sa-update being run out of cron jobs - Add create perms to postgresql_manage_db - ntpd using a gps has to be able to read/write generic tty_device_t - If you disable unconfined and unconfineduser, rpm needs more privs to manage /dev - fix spec file - Remove qemu_domtrans_unconfined() interface - Make passenger working together with puppet - Add init_dontaudit_rw_stream_socket interface - Fixes for wordpress- Turn on allow_domain_fd_use boolean on F16 - Allow syslog to manage all log files - Add use_fusefs_home_dirs boolean for chrome - Make vdagent working with confined users - Add abrt_handle_event_t domain for ABRT event scripts - Labeled /usr/sbin/rhnreg_ks as rpm_exec_t and added changes related to this change - Allow httpd_git_script_t to read passwd data - Allow openvpn to set its process priority when the nice parameter is used- livecd fixes - spec file fixes- fetchmail can use kerberos - ksmtuned reads in shell programs - gnome_systemctl_t reads the process state of ntp - dnsmasq_t asks the kernel to load multiple kernel modules - Add rules for domains executing systemctl - Bogus text within fc file- Add cfengine policy- Add abrt_domain attribute - Allow corosync to manage cluster lib files - Allow corosync to connect to the system DBUS- Add sblim, uuidd policies - Allow kernel_t dyntrasition to init_t- init_t need setexec - More fixes of rules which cause an explosion in rules by Dan Walsh- Allow rcsmcertd to perform DNS name resolution - Add dirsrvadmin_unconfined_script_t domain type for 389-ds admin scripts - Allow tmux to run as screen - New policy for collectd - Allow gkeyring_t to interact with all user apps - Add rules to allow firstboot to run on machines with the unconfined.pp module removed- Allow systemd_logind to send dbus messages with users - allow accountsd to read wtmp file - Allow dhcpd to get and set capabilities- Fix oracledb_port definition - Allow mount to mounton the selinux file system - Allow users to list /var directories- systemd fixes- Add initial policy for abrt_dump_oops_t - xtables-multi wants to getattr of the proc fs - Smoltclient is connecting to abrt - Dontaudit leaked file descriptors to postdrop - Allow abrt_dump_oops to look at kernel sysctls - Abrt_dump_oops_t reads kernel ring buffer - Allow mysqld to request the kernel to load modules - systemd-login needs fowner - Allow postfix_cleanup_t to searh maildrop- Initial systemd_logind policy - Add policy for systemd_logger and additional proivs for systemd_logind - More fixes for systemd policies- Allow setsched for virsh - Systemd needs to impersonate cups, which means it needs to create tcp_sockets in cups_t domain, as well as manage spool directories - iptables: the various /sbin/ip6?tables.* are now symlinks for /sbin/xtables-multi- A lot of users are running yum -y update while in /root which is causing ldconfig to list the contents, adding dontaudit - Allow colord to interact with the users through the tmpfs file system - Since we changed the label on deferred, we need to allow postfix_qmgr_t to be able to create maildrop_t files - Add label for /var/log/mcelog - Allow asterisk to read /dev/random if it uses TLS - Allow colord to read ini files which are labeled as bin_t - Allow dirsrvadmin sys_resource and setrlimit to use ulimit - Systemd needs to be able to create sock_files for every label in /var/run directory, cupsd being the first. - Also lists /var and /var/spool directories - Add openl2tpd to l2tpd policy - qpidd is reading the sysfs file- Change usbmuxd_t to dontaudit attempts to read chr_file - Add mysld_safe_exec_t for libra domains to be able to start private mysql domains - Allow pppd to search /var/lock dir - Add rhsmcertd policy- Update to upstream- More fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git- Fix spec file to not report Verify errors- Add dspam policy - Add lldpad policy - dovecot auth wants to search statfs #713555 - Allow systemd passwd apps to read init fifo_file - Allow prelink to use inherited terminals - Run cherokee in the httpd_t domain - Allow mcs constraints on node connections - Implement pyicqt policy - Fixes for zarafa policy - Allow cobblerd to send syslog messages- Add policy.26 to the payload - Remove olpc stuff - Remove policygentool- Fixes for zabbix - init script needs to be able to manage sanlock_var_run_... - Allow sandlock and wdmd to create /var/run directories... - mixclip.so has been compiled correctly - Fix passenger policy module name- Add mailscanner policy from dgrift - Allow chrome to optionally be transitioned to - Zabbix needs these rules when starting the zabbix_server_mysql - Implement a type for freedesktop openicc standard (~/.local/share/icc) - Allow system_dbusd_t to read inherited icc_data_home_t files. - Allow colord_t to read icc_data_home_t content. #706975 - Label stuff under /usr/lib/debug as if it was labeled under /- Fixes for sanlock policy - Fixes for colord policy - Other fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Add rhev policy module to modules-targeted.conf- Lot of fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Allow logrotate to execute systemctl - Allow nsplugin_t to getattr on gpmctl - Fix dev_getattr_all_chr_files() interface - Allow shorewall to use inherited terms - Allow userhelper to getattr all chr_file devices - sandbox domains should be able to getattr and dontaudit search of sysctl_kernel_t - Fix labeling for ABRT Retrace Server- Dontaudit sys_module for ifconfig - Make telepathy and gkeyringd daemon working with confined users - colord wants to read files in users homedir - Remote login should be creating user_tmp_t not its own tmp files- Fix label for /usr/share/munin/plugins/munin_* plugins - Add support for zarafa-indexer - Fix boolean description - Allow colord to getattr on /proc/scsi/scsi - Add label for /lib/upstart/init - Colord needs to list /mnt- Forard port changes from F15 for telepathy - NetworkManager should be allowed to use /dev/rfkill - Fix dontaudit messages to say Domain to not audit - Allow telepathy domains to read/write gnome_cache files - Allow telepathy domains to call getpw - Fixes for colord and vnstatd policy- Allow init_t getcap and setcap - Allow namespace_init_t to use nsswitch - aisexec will execute corosync - colord tries to read files off noxattr file systems - Allow init_t getcap and setcap- Add support for ABRT retrace server - Allow user_t and staff_t access to generic scsi to handle locally plugged in scanners - Allow telepath_msn_t to read /proc/PARENT/cmdline - ftpd needs kill capability - Allow telepath_msn_t to connect to sip port - keyring daemon does not work on nfs homedirs - Allow $1_sudo_t to read default SELinux context - Add label for tgtd sock file in /var/run/ - Add apache_exec_rotatelogs interface - allow all zaraha domains to signal themselves, server writes to /tmp - Allow syslog to read the process state - Add label for /usr/lib/chromium-browser/chrome - Remove the telepathy transition from unconfined_t - Dontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse mounts - Allow initrc_t domain to manage abrt pid files - Add support for AEOLUS project - Virt_admin should be allowed to manage images and processes - Allow plymountd to send signals to init - Change labeling of fping6- Add filename transitions- Fixes for zarafa policy - Add support for AEOLUS project - Change labeling of fping6 - Allow plymountd to send signals to init - Allow initrc_t domain to manage abrt pid files - Virt_admin should be allowed to manage images and processes- xdm_t needs getsession for switch user - Every app that used to exec init is now execing systemdctl - Allow squid to manage krb5_host_rcache_t files - Allow foghorn to connect to agentx port - Fixes for colord policy- Add Dan's patch to remove 64 bit variants - Allow colord to use unix_dgram_socket - Allow apps that search pids to read /var/run if it is a lnk_file - iscsid_t creates its own directory - Allow init to list var_lock_t dir - apm needs to verify user accounts auth_use_nsswitch - Add labeling for systemd unit files - Allow gnomeclok to enable ntpd service using systemctl - systemd_systemctl_t domain was added - Add label for matahari-broker.pid file - We want to remove untrustedmcsprocess from ability to read /proc/pid - Fixes for matahari policy - Allow system_tmpfiles_t to delete user_home_t files in the /tmp dir - Allow sshd to transition to sysadm_t if ssh_sysadm_login is turned on- Fix typo- Add /var/run/lock /var/lock definition to file_contexts.subs - nslcd_t is looking for kerberos cc files - SSH_USE_STRONG_RNG is 1 which requires /dev/random - Fix auth_rw_faillog definition - Allow sysadm_t to set attributes on fixed disks - allow user domains to execute lsof and look at application sockets - prelink_cron job calls telinit -u if init is rewritten - Fixes to run qemu_t from staff_t- Fix label for /var/run/udev to udev_var_run_t - Mock needs to be able to read network state- Add file_contexts.subs to handle /run and /run/lock - Add other fixes relating to /run changes from F15 policy- Allow $1_sudo_t and $1_su_t open access to user terminals - Allow initrc_t to use generic terminals - Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs -systemd is going to be useing /run and /run/lock for early bootup files. - Fix some comments in rlogin.if - Add policy for KDE backlighthelper - sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems - sssd wants to read .k5login file in users homedir - setroubleshoot reads executables to see if they have TEXTREL - Add /var/spool/audit support for new version of audit - Remove kerberos_connect_524() interface calling - Combine kerberos_master_port_t and kerberos_port_t - systemd has setup /dev/kmsg as stderr for apps it executes - Need these access so that init can impersonate sockets on unix_dgram_socket- Remove some unconfined domains - Remove permissive domains - Add policy-term.patch from Dan- Fix multiple specification for boot.log - devicekit leaks file descriptors to setfiles_t - Change all all_nodes to generic_node and all_if to generic_if - Should not use deprecated interface - Switch from using all_nodes to generic_node and from all_if to generic_if - Add support for xfce4-notifyd - Fix file context to show several labels as SystemHigh - seunshare needs to be able to mounton nfs/cifs/fusefs homedirs - Add etc_runtime_t label for /etc/securetty - Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly - login.krb needs to be able to write user_tmp_t - dirsrv needs to bind to port 7390 for dogtag - Fix a bug in gpg policy - gpg sends audit messages - Allow qpid to manage matahari files- Initial policy for matahari - Add dev_read_watchdog - Allow clamd to connect clamd port - Add support for kcmdatetimehelper - Allow shutdown to setrlimit and sys_nice - Allow systemd_passwd to talk to /dev/log before udev or syslog is running - Purge chr_file and blk files on /tmp - Fixes for pads - Fixes for piranha-pulse - gpg_t needs to be able to encyprt anything owned by the user- mozilla_plugin_tmp_t needs to be treated as user tmp files - More dontaudits of writes from readahead - Dontaudit readahead_t file_type:dir write, to cover up kernel bug - systemd_tmpfiles needs to relabel faillog directory as well as the file - Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost- Add policykit fixes from Tim Waugh - dontaudit sandbox domains sandbox_file_t:dir mounton - Add new dontaudit rules for sysadm_dbusd_t - Change label for /var/run/faillock * other fixes which relate with this change- Update to upstream - Fixes for telepathy - Add port defition for ssdp port - add policy for /bin/systemd-notify from Dan - Mount command requires users read mount_var_run_t - colord needs to read konject_uevent_socket - User domains connect to the gkeyring socket - Add colord policy and allow user_t and staff_t to dbus chat with it - Add lvm_exec_t label for kpartx - Dontaudit reading the mail_spool_t link from sandbox -X - systemd is creating sockets in avahi_var_run and system_dbusd_var_run- gpg_t needs to talk to gnome-keyring - nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd - enforce MCS labeling on nodes - Allow arpwatch to read meminfo - Allow gnomeclock to send itself signals - init relabels /dev/.udev files on boot - gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t - nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t - dnsmasq can run as a dbus service, needs acquire service - mysql_admin should be allowed to connect to mysql service - virt creates monitor sockets in the users home dir- Allow usbhid-ups to read hardware state information - systemd-tmpfiles has moved - Allo cgroup to sys_tty_config - For some reason prelink is attempting to read gconf settings - Add allow_daemons_use_tcp_wrapper boolean - Add label for ~/.cache/wocky to make telepathy work in enforcing mode - Add label for char devices /dev/dasd* - Fix for apache_role - Allow amavis to talk to nslcd - allow all sandbox to read selinux poilcy config files - Allow cluster domains to use the system bus and send each other dbus messages- Update to upstream- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Update to ref policy - cgred needs chown capability - Add /dev/crash crash_dev_t - systemd-readahead wants to use fanotify which means readahead_t needs sys_admin capability- New labeling for postfmulti #675654 - dontaudit xdm_t listing noxattr file systems - dovecot-auth needs to be able to connect to mysqld via the network as well as locally - shutdown is passed stdout to a xdm_log_t file - smartd creates a fixed disk device - dovecot_etc_t contains a lnk_file that domains need to read - mount needs to be able to read etc_runtim_t:lnk_file since in rawhide this is a link created at boot- syslog_t needs syslog capability - dirsrv needs to be able to create /var/lib/snmp - Fix labeling for dirsrv - Fix for dirsrv policy missing manage_dirs_pattern - corosync needs to delete clvm_tmpfs_t files - qdiskd needs to list hugetlbfs - Move setsched to sandbox_x_domain, so firefox can run without network access - Allow hddtemp to read removable devices - Adding syslog and read_policy permissions to policy * syslog Allow unconfined, sysadm_t, secadm_t, logadm_t * read_policy allow unconfined, sysadm_t, secadm_t, staff_t on Targeted allow sysadm_t (optionally), secadm_t on MLS - mdadm application will write into /sys/.../uevent whenever arrays are assembled or disassembled.- Add tcsd policy- ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Allow dbus to use setrlimit to increase resoueces - Mozilla_plugin is leaking to sandbox - Allow confined users to connect to lircd over unix domain stream socket which allow to use remote control - Allow awstats to read squid logs - seunshare needs to manage tmp_t - apcupsd cgi scripts have a new directory- Fix xserver_dontaudit_read_xdm_pid - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite - Allow dovecot_deliver_t to read/write postfix_master_t:fifo_file. * These fifo_file is passed from postfix_master_t to postfix_local_t to dovecot_deliver_t - Allow readahead to manage readahead pid dirs - Allow readahead to read all mcs levels - Allow mozilla_plugin_t to use nfs or samba homedirs- Allow nagios plugin to read /proc/meminfo - Fix for mozilla_plugin - Allow samba_net_t to create /etc/keytab - pppd_t setting up vpns needs to run unix_chkpwd, setsched its process and write wtmp_t - nslcd can read user credentials - Allow nsplugin to delete mozilla_plugin_tmpfs_t - abrt tries to create dir in rpm_var_lib_t - virt relabels fifo_files - sshd needs to manage content in fusefs homedir - mock manages link files in cache dir- nslcd needs setsched and to read /usr/tmp - Invalid call in likewise policy ends up creating a bogus role - Cannon puts content into /var/lib/bjlib that cups needs to be able to write - Allow screen to create screen_home_t in /root - dirsrv sends syslog messages - pinentry reads stuff in .kde directory - Add labels for .kde directory in homedir - Treat irpinit, iprupdate, iprdump services with raid policy- NetworkManager wants to read consolekit_var_run_t - Allow readahead to create /dev/.systemd/readahead - Remove permissive domains - Allow newrole to run namespace_init- Add sepgsql_contexts file- Update to upstream- Add oracle ports and allow apache to connect to them if the connect_db boolean is turned on - Add puppetmaster_use_db boolean - Fixes for zarafa policy - Fixes for gnomeclock poliy - Fix systemd-tmpfiles to use auth_use_nsswitch- gnomeclock executes a shell - Update for screen policy to handle pipe in homedir - Fixes for polyinstatiated homedir - Fixes for namespace policy and other fixes related to polyinstantiation - Add namespace policy - Allow dovecot-deliver transition to sendmail which is needed by sieve scripts - Fixes for init, psad policy which relate with confined users - Do not audit bootloader attempts to read devicekit pid files - Allow nagios service plugins to read /proc- Add firewalld policy - Allow vmware_host to read samba config - Kernel wants to read /proc Fix duplicate grub def in cobbler - Chrony sends mail, executes shell, uses fifo_file and reads /proc - devicekitdisk getattr all file systems - sambd daemon writes wtmp file - libvirt transitions to dmidecode- Add initial policy for system-setup-keyboard which is now daemon - Label /var/lock/subsys/shorewall as shorewall_lock_t - Allow users to communicate with the gpg_agent_t - Dontaudit mozilla_plugin_t using the inherited terminal - Allow sambagui to read files in /usr - webalizer manages squid log files - Allow unconfined domains to bind ports to raw_ip_sockets - Allow abrt to manage rpm logs when running yum - Need labels for /var/run/bittlebee - Label .ssh under amanda - Remove unused genrequires for virt_domain_template - Allow virt_domain to use fd inherited from virtd_t - Allow iptables to read shorewall config- Gnome apps list config_home_t - mpd creates lnk files in homedir - apache leaks write to mail apps on tmp files - /var/stockmaniac/templates_cache contains log files - Abrt list the connects of mount_tmp_t dirs - passwd agent reads files under /dev and reads utmp file - squid apache script connects to the squid port - fix name of plymouth log file - teamviewer is a wine app - allow dmesg to read system state - Stop labeling files under /var/lib/mock so restorecon will not go into this - nsplugin needs to read network state for google talk- Allow xdm and syslog to use /var/log/boot.log - Allow users to communicate with mozilla_plugin and kill it - Add labeling for ipv6 and dhcp- New labels for ghc http content - nsplugin_config needs to read urand, lvm now calls setfscreate to create dev - pm-suspend now creates log file for append access so we remove devicekit_wri - Change authlogin_use_sssd to authlogin_nsswitch_use_ldap - Fixes for greylist_milter policy- Update to upstream - Fixes for systemd policy - Fixes for passenger policy - Allow staff users to run mysqld in the staff_t domain, akonadi needs this - Add bin_t label for /usr/share/kde4/apps/kajongg/kajongg.py - auth_use_nsswitch does not need avahi to read passwords,needed for resolving data - Dontaudit (xdm_t) gok attempting to list contents of /var/account - Telepathy domains need to read urand - Need interface to getattr all file classes in a mock library for setroubleshoot- Update selinux policy to handle new /usr/share/sandbox/start script- Update to upstream - Fix version of policy in spec file- Allow sandbox to run on nfs partitions, fixes for systemd_tmpfs - remove per sandbox domains devpts types - Allow dkim-milter sending signal to itself- Allow domains that transition to ping or traceroute, kill them - Allow user_t to conditionally transition to ping_t and traceroute_t - Add fixes to systemd- tools, including new labeling for systemd-fsck, systemd-cryptsetup- Turn on systemd policy - mozilla_plugin needs to read certs in the homedir. - Dontaudit leaked file descriptors from devicekit - Fix ircssi to use auth_use_nsswitch - Change to use interface without param in corenet to disable unlabelednet packets - Allow init to relabel sockets and fifo files in /dev - certmonger needs dac* capabilities to manage cert files not owned by root - dovecot needs fsetid to change group membership on mail - plymouthd removes /var/log/boot.log - systemd is creating symlinks in /dev - Change label on /etc/httpd/alias to be all cert_t- Fixes for clamscan and boinc policy - Add boinc_project_t setpgid - Allow alsa to create tmp files in /tmp- Push fixes to allow disabling of unlabeled_t packet access - Enable unlabelednet policy- Fixes for lvm to work with systemd- Fix the label for wicd log - plymouthd creates force-display-on-active-vt file - Allow avahi to request the kernel to load a module - Dontaudit hal leaks - Fix gnome_manage_data interface - Add new interface corenet_packet to define a type as being an packet_type. - Removed general access to packet_type from icecast and squid. - Allow mpd to read alsa config - Fix the label for wicd log - Add systemd policy- Fix gnome_manage_data interface - Dontaudit sys_ptrace capability for iscsid - Fixes for nagios plugin policy- Fix cron to run ranged when started by init - Fix devicekit to use log files - Dontaudit use of devicekit_var_run_t for fstools - Allow init to setattr on logfile directories - Allow hald to manage files in /var/run/pm-utils/ dir which is now labeled as devicekit_var_run_t- Fix up handling of dnsmasq_t creating /var/run/libvirt/network - Turn on sshd_forward_ports boolean by default - Allow sysadmin to dbus chat with rpm - Add interface for rw_tpm_dev - Allow cron to execute bin - fsadm needs to write sysfs - Dontaudit consoletype reading /var/run/pm-utils - Lots of new privs fro mozilla_plugin_t running java app, make mozilla_plugin - certmonger needs to manage dirsrv data - /var/run/pm-utils should be labeled as devicekit_var_run_t- fixes to allow /var/run and /var/lock as tmpfs - Allow chrome sandbox to connect to web ports - Allow dovecot to listem on lmtp and sieve ports - Allov ddclient to search sysctl_net_t - Transition back to original domain if you execute the shell- Remove duplicate declaration- Update to upstream - Cleanup for sandbox - Add attribute to be able to select sandbox types- Allow ddclient to fix file mode bits of ddclient conf file - init leaks file descriptors to daemons - Add labels for /etc/lirc/ and - Allow amavis_t to exec shell - Add label for gssd_tmp_t for /var/tmp/nfs_0- Put back in lircd_etc_t so policy will install- Turn on allow_postfix_local_write_mail_spool - Allow initrc_t to transition to shutdown_t - Allow logwatch and cron to mls_read_to_clearance for MLS boxes - Allow wm to send signull to all applications and receive them from users - lircd patch from field - Login programs have to read /etc/samba - New programs under /lib/systemd - Abrt needs to read config files- Update to upstream - Dontaudit leaked sockets from userdomains to user domains - Fixes for mcelog to handle scripts - Apply patch from Ruben Kerkhof - Allow syslog to search spool dirs- Allow nagios plugins to read usr files - Allow mysqld-safe to send system log messages - Fixes fpr ddclient policy - Fix sasl_admin interface - Allow apache to search zarafa config - Allow munin plugins to search /var/lib directory - Allow gpsd to read sysfs_t - Fix labels on /etc/mcelog/triggers to bin_t- Remove saslauthd_tmp_t and transition tmp files to krb5_host_rcache_t - Allow saslauthd_t to create krb5_host_rcache_t files in /tmp - Fix xserver interface - Fix definition of /var/run/lxdm- Turn on mediawiki policy - kdump leaks kdump_etc_t to ifconfig, add dontaudit - uux needs to transition to uucpd_t - More init fixes relabels man,faillog - Remove maxima defs in libraries.fc - insmod needs to be able to create tmpfs_t files - ping needs setcap- Allow groupd transition to fenced domain when executes fence_node - Fixes for rchs policy - Allow mpd to be able to read samba/nfs files- Fix up corecommands.fc to match upstream - Make sure /lib/systemd/* is labeled init_exec_t - mount wants to setattr on all mountpoints - dovecot auth wants to read dovecot etc files - nscd daemon looks at the exe file of the comunicating daemon - openvpn wants to read utmp file - postfix apps now set sys_nice and lower limits - remote_login (telnetd/login) wants to use telnetd_devpts_t and user_devpts_t to work correctly - Also resolves nsswitch - Fix labels on /etc/hosts.* - Cleanup to make upsteam patch work - allow abrt to read etc_runtime_t- Add conflicts for dirsrv package- Update to upstream - Add vlock policy- Fix sandbox to work on nfs homedirs - Allow cdrecord to setrlimit - Allow mozilla_plugin to read xauth - Change label on systemd-logger to syslogd_exec_t - Install dirsrv policy from dirsrv package- Add virt_home_t, allow init to setattr on xserver_tmp_t and relabel it - Udev needs to stream connect to init and kernel - Add xdm_exec_bootloader boolean, which allows xdm to execute /sbin/grub and read files in /boot directory- Allow NetworkManager to read openvpn_etc_t - Dontaudit hplip to write of /usr dirs - Allow system_mail_t to create /root/dead.letter as mail_home_t - Add vdagent policy for spice agent daemon- Dontaudit sandbox sending sigkill to all user domains - Add policy for rssh_chroot_helper - Add missing flask definitions - Allow udev to relabelto removable_t - Fix label on /var/log/wicd.log - Transition to initrc_t from init when executing bin_t - Add audit_access permissions to file - Make removable_t a device_node - Fix label on /lib/systemd/*- Fixes for systemd to manage /var/run - Dontaudit leaks by firstboot- Allow chome to create netlink_route_socket - Add additional MATHLAB file context - Define nsplugin as an application_domain - Dontaudit sending signals from sandboxed domains to other domains - systemd requires init to build /tmp /var/auth and /var/lock dirs - mount wants to read devicekit_power /proc/ entries - mpd wants to connect to soundd port - Openoffice causes a setattr on a lib_t file for normal users, add dontaudit - Treat lib_t and textrel_shlib_t directories the same - Allow mount read access on virtual images- Allow sandbox_x_domains to work with nfs/cifs/fusefs home dirs. - Allow devicekit_power to domtrans to mount - Allow dhcp to bind to udp ports > 1024 to do named stuff - Allow ssh_t to exec ssh_exec_t - Remove telepathy_butterfly_rw_tmp_files(), dev_read_printk() interfaces which are nolonger used - Fix clamav_append_log() intefaces - Fix 'psad_rw_fifo_file' interface- Allow cobblerd to list cobler appache content- Fixup for the latest version of upowed - Dontaudit sandbox sending SIGNULL to desktop apps- Update to upstream-Mount command from a confined user generates setattr on /etc/mtab file, need to dontaudit this access - dovecot-auth_t needs ipc_lock - gpm needs to use the user terminal - Allow system_mail_t to append ~/dead.letter - Allow NetworkManager to edit /etc/NetworkManager/NetworkManager.conf - Add pid file to vnstatd - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles- Lots of fixes for systemd - systemd now executes readahead and tmpwatch type scripts - Needs to manage random seed- Allow smbd to use sys_admin - Remove duplicate file context for tcfmgr - Update to upstream- Fix fusefs handling - Do not allow sandbox to manage nsplugin_rw_t - Allow mozilla_plugin_t to connecto its parent - Allow init_t to connect to plymouthd running as kernel_t - Add mediawiki policy - dontaudit sandbox sending signals to itself. This can happen when they are running at different mcs. - Disable transition from dbus_session_domain to telepathy for F14 - Allow boinc_project to use shm - Allow certmonger to search through directories that contain certs - Allow fail2ban the DAC Override so it can read log files owned by non root users- Start adding support for use_fusefs_home_dirs - Add /var/lib/syslog directory file context - Add /etc/localtime as locale file context- Turn off default transition to mozilla_plugin and telepathy domains from unconfined user - Turn off iptables from unconfined user - Allow sudo to send signals to any domains the user could have transitioned to. - Passwd in single user mode needs to talk to console_device_t - Mozilla_plugin_t needs to connect to web ports, needs to write to video device, and read alsa_home_t alsa setsup pulseaudio - locate tried to read a symbolic link, will dontaudit - New labels for telepathy-sunshine content in homedir - Google is storing other binaries under /opt/google/talkplugin - bluetooth/kernel is creating unlabeled_t socket that I will allow it to use until kernel fixes bug - Add boolean for unconfined_t transition to mozilla_plugin_t and telepathy domains, turned off in F14 on in F15 - modemmanger and bluetooth send dbus messages to devicekit_power - Samba needs to getquota on filesystems labeld samba_share_t- Dontaudit attempts by xdm_t to write to bin_t for kdm - Allow initrc_t to manage system_conf_t- Fixes to allow mozilla_plugin_t to create nsplugin_home_t directory. - Allow mozilla_plugin_t to create tcp/udp/netlink_route sockets - Allow confined users to read xdm_etc_t files - Allow xdm_t to transition to xauth_t for lxdm program- Rearrange firewallgui policy to be more easily updated to upstream, dontaudit search of /home - Allow clamd to send signals to itself - Allow mozilla_plugin_t to read user home content. And unlink pulseaudio shm. - Allow haze to connect to yahoo chat and messenger port tcp:5050. Bz #637339 - Allow guest to run ps command on its processes by allowing it to read /proc - Allow firewallgui to sys_rawio which seems to be required to setup masqerading - Allow all domains to search through default_t directories, in order to find differnet labels. For example people serring up /foo/bar to be share via samba. - Add label for /var/log/slim.log- Pull in cleanups from dgrift - Allow mozilla_plugin_t to execute mozilla_home_t - Allow rpc.quota to do quotamod- Cleanup policy via dgrift - Allow dovecot_deliver to append to inherited log files - Lots of fixes for consolehelper- Fix up Xguest policy- Add vnstat policy - allow libvirt to send audit messages - Allow chrome-sandbox to search nfs_t- Update to upstream- Add the ability to send audit messages to confined admin policies - Remove permissive domain from cmirrord and dontaudit sys_tty_config - Split out unconfined_domain() calls from other unconfined_ calls so we can d - virt needs to be able to read processes to clearance for MLS- Allow all domains that can use cgroups to search tmpfs_t directory - Allow init to send audit messages- Update to upstream- Allow mdadm_t to create files and sock files in /dev/md/- Add policy for ajaxterm- Handle /var/db/sudo - Allow pulseaudio to read alsa config - Allow init to send initrc_t dbus messagesAllow iptables to read shorewall tmp files Change chfn and passwd to use auth_use_pam so they can send dbus messages to fpr intd label vlc as an execmem_exec_t Lots of fixes for mozilla_plugin to run google vidio chat Allow telepath_msn to execute ldconfig and its own tmp files Fix labels on hugepages Allow mdadm to read files on /dev Remove permissive domains and change back to unconfined Allow freshclam to execute shell and bin_t Allow devicekit_power to transition to dhcpc Add boolean to allow icecast to connect to any port- Merge upstream fix of mmap_zero - Allow mount to write files in debugfs_t - Allow corosync to communicate with clvmd via tmpfs - Allow certmaster to read usr_t files - Allow dbus system services to search cgroup_t - Define rlogind_t as a login pgm- Allow mdadm_t to read/write hugetlbfs- Dominic Grift Cleanup - Miroslav Grepl policy for jabberd - Various fixes for mount/livecd and prelink- Merge with upstream- More access needed for devicekit - Add dbadm policy- Merge with upstream- Allow seunshare to fowner- Allow cron to look at user_cron_spool links - Lots of fixes for mozilla_plugin_t - Add sysv file system - Turn unconfined domains to permissive to find additional avcs- Update policy for mozilla_plugin_t- Allow clamscan to read proc_t - Allow mount_t to write to debufs_t dir - Dontaudit mount_t trying to write to security_t dir- Allow clamscan_t execmem if clamd_use_jit set - Add policy for firefox plugin-container- Fix /root/.forward definition- label dead.letter as mail_home_t- Allow login programs to search /cgroups- Fix cert handling- Fix devicekit_power bug - Allow policykit_auth_t more access.- Fix nis calls to allow bind to ports 512-1024 - Fix smartmon- Allow pcscd to read sysfs - systemd fixes - Fix wine_mmap_zero_ignore boolean- Apply Miroslav munin patch - Turn back on allow_execmem and allow_execmod booleans- Merge in fixes from dgrift repository- Update boinc policy - Fix sysstat policy to allow sys_admin - Change failsafe_context to unconfined_r:unconfined_t:s0- New paths for upstart- New permissions for syslog - New labels for /lib/upstart- Add mojomojo policy- Allow systemd to setsockcon on sockets to immitate other services- Remove debugfs label- Update to latest policy- Fix eclipse labeling from IBMSupportAssasstant packageing- Make boot with systemd in enforcing mode- Update to upstream- Add boolean to turn off port forwarding in sshd.- Add support for ebtables - Fixes for rhcs and corosync policy-Update to upstream-Update to upstream-Update to upstream- Add Zarafa policy- Cleanup of aiccu policy - initial mock policy- Lots of random fixes- Update to upstream- Update to upstream - Allow prelink script to signal itself - Cobbler fixes- Add xdm_var_run_t to xserver_stream_connect_xdm - Add cmorrord and mpd policy from Miroslav Grepl- Fix sshd creation of krb cc files for users to be user_tmp_t- Fixes for accountsdialog - Fixes for boinc- Fix label on /var/lib/dokwiki - Change permissive domains to enforcing - Fix libvirt policy to allow it to run on mls- Update to upstream- Allow procmail to execute scripts in the users home dir that are labeled home_bin_t - Fix /var/run/abrtd.lock label- Allow login programs to read krb5_home_t Resolves: 594833 - Add obsoletes for cachefilesfd-selinux package Resolves: #575084- Allow mount to r/w abrt fifo file - Allow svirt_t to getattr on hugetlbfs - Allow abrt to create a directory under /var/spool- Add labels for /sys - Allow sshd to getattr on shutdown - Fixes for munin - Allow sssd to use the kernel key ring - Allow tor to send syslog messages - Allow iptabels to read usr files - allow policykit to read all domains state- Fix path for /var/spool/abrt - Allow nfs_t as an entrypoint for http_sys_script_t - Add policy for piranha - Lots of fixes for sosreport- Allow xm_t to read network state and get and set capabilities - Allow policykit to getattr all processes - Allow denyhosts to connect to tcp port 9911 - Allow pyranha to use raw ip sockets and ptrace itself - Allow unconfined_execmem_t and gconfsd mechanism to dbus - Allow staff to kill ping process - Add additional MLS rules- Allow gdm to edit ~/.gconf dir Resolves: #590677 - Allow dovecot to create directories in /var/lib/dovecot Partially resolves 590224 - Allow avahi to dbus chat with NetworkManager - Fix cobbler labels - Dontaudit iceauth_t leaks - fix /var/lib/lxdm file context - Allow aiccu to use tun tap devices - Dontaudit shutdown using xserver.log- Fixes for sandbox_x_net_t to match access for sandbox_web_t ++ - Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory - Add dontaudit interface for bluetooth dbus - Add chronyd_read_keys, append_keys for initrc_t - Add log support for ksmtuned Resolves: #586663- Allow boinc to send mail- Allow initrc_t to remove dhcpc_state_t - Fix label on sa-update.cron - Allow dhcpc to restart chrony initrc - Don't allow sandbox to send signals to its parent processes - Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t Resolves: #589136- Fix location of oddjob_mkhomedir Resolves: #587385 - fix labeling on /root/.shosts and ~/.shosts - Allow ipsec_mgmt_t to manage net_conf_t Resolves: #586760- Dontaudit sandbox trying to connect to netlink sockets Resolves: #587609 - Add policy for piranha- Fixups for xguest policy - Fixes for running sandbox firefox- Allow ksmtuned to use terminals Resolves: #586663 - Allow lircd to write to generic usb devices- Allow sandbox_xserver to connectto unconfined stream Resolves: #585171- Allow initrc_t to read slapd_db_t Resolves: #585476 - Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.conf Resolves: #585963- Allow rlogind_t to search /root for .rhosts Resolves: #582760 - Fix path for cached_var_t - Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri - Allow mls lvm/cryptosetup to work- Allow virtd_t to manage firewall/iptables config Resolves: #573585- Fix label on /root/.rhosts Resolves: #582760 - Add labels for Picasa - Allow openvpn to read home certs - Allow plymouthd_t to use tty_device_t - Run ncftool as iptables_t - Allow mount to unmount unlabeled_t - Dontaudit hal leaks- Allow livecd to transition to mount- Update to upstream - Allow abrt to delete sosreport Resolves: #579998 - Allow snmp to setuid and gid Resolves: #582155 - Allow smartd to use generic scsi devices Resolves: #582145- Allow ipsec_t to create /etc/resolv.conf with the correct label - Fix reserved port destination - Allow autofs to transition to showmount - Stop crashing tuned- Add telepathysofiasip policy- Update to upstream - Fix label for /opt/google/chrome/chrome-sandbox - Allow modemmanager to dbus with policykit- Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t) - Allow accountsd to read shadow file - Allow apache to send audit messages when using pam - Allow asterisk to bind and connect to sip tcp ports - Fixes for dovecot 2.0 - Allow initrc_t to setattr on milter directories - Add procmail_home_t for .procmailrc file- Fixes for labels during install from livecd- Fix /cgroup file context - Fix broken afs use of unlabled_t - Allow getty to use the console for s390- Fix cgroup handling adding policy for /cgroup - Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set- Merge patches from dgrift- Update upstream - Allow abrt to write to the /proc under any process- Fix ~/.fontconfig label - Add /root/.cert label - Allow reading of the fixed_file_disk_t:lnk_file if you can read file - Allow qemu_exec_t as an entrypoint to svirt_t- Update to upstream - Allow tmpreaper to delete sandbox sock files - Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems - Fixes for gitosis - No transition on livecd to passwd or chfn - Fixes for denyhosts- Add label for /var/lib/upower - Allow logrotate to run sssd - dontaudit readahead on tmpfs blk files - Allow tmpreaper to setattr on sandbox files - Allow confined users to execute dos files - Allow sysadm_t to kill processes running within its clearance - Add accountsd policy - Fixes for corosync policy - Fixes from crontab policy - Allow svirt to manage svirt_image_t chr files - Fixes for qdisk policy - Fixes for sssd policy - Fixes for newrole policy- make libvirt work on an MLS platform- Add qpidd policy- Update to upstream- Allow boinc to read kernel sysctl - Fix snmp port definitions - Allow apache to read anon_inodefs- Allow shutdown dac_override- Add device_t as a file system - Fix sysfs association- Dontaudit ipsec_mgmt sys_ptrace - Allow at to mail its spool files - Allow nsplugin to search in .pulse directory- Update to upstream- Allow users to dbus chat with xdm - Allow users to r/w wireless_device_t - Dontaudit reading of process states by ipsec_mgmt- Fix openoffice from unconfined_t- Add shutdown policy so consolekit can shutdown system- Update to upstream- Update to upstream- Update to upstream - These are merges of my patches - Remove 389 labeling conflicts - Add MLS fixes found in RHEL6 testing - Allow pulseaudio to run as a service - Add label for mssql and allow apache to connect to this database port if boolean set - Dontaudit searches of debugfs mount point - Allow policykit_auth to send signals to itself - Allow modcluster to call getpwnam - Allow swat to signal winbind - Allow usbmux to run as a system role - Allow svirt to create and use devpts- Add MLS fixes found in RHEL6 testing - Allow domains to append to rpm_tmp_t - Add cachefilesfd policy - Dontaudit leaks when transitioning- Change allow_execstack and allow_execmem booleans to on - dontaudit acct using console - Add label for fping - Allow tmpreaper to delete sandbox_file_t - Fix wine dontaudit mmap_zero - Allow abrt to read var_t symlinks- Additional policy for rgmanager- Allow sshd to setattr on pseudo terms- Update to upstream- Allow policykit to send itself signals- Fix duplicate cobbler definition- Fix file context of /var/lib/avahi-autoipd- Merge with upstream- Allow sandbox to work with MLS- Make Chrome work with staff user- Add icecast policy - Cleanup spec file- Add mcelog policy- Lots of fixes found in F12- Fix rpm_dontaudit_leaks- Add getsched to hald_t - Add file context for Fedora/Redhat Directory Server- Allow abrt_helper to getattr on all filesystems - Add label for /opt/real/RealPlayer/plugins/oggfformat\.so- Add gstreamer_home_t for ~/.gstreamer- Update to upstream- Fix git- Turn on puppet policy - Update to dgrift git policy- Move users file to selection by spec file. - Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t- Update to upstream- Remove most of the permissive domains from F12.- Add cobbler policy from dgrift- add usbmon device - Add allow rulse for devicekit_disk- Lots of fixes found in F12, fixes from Tom London- Cleanups from dgrift- Add back xserver_manage_home_fonts- Dontaudit sandbox trying to read nscd and sssd- Update to upstream- Rename udisks-daemon back to devicekit_disk_t policy- Fixes for abrt calls- Add tgtd policy- Update to upstream release- Add asterisk policy back in - Update to upstream release 2.20091117- Update to upstream release 2.20091117- Fixup nut policy- Update to upstream- Allow vpnc request the kernel to load modules- Fix minimum policy installs - Allow udev and rpcbind to request the kernel to load modules- Add plymouth policy - Allow local_login to sys_admin- Allow cupsd_config to read user tmp - Allow snmpd_t to signal itself - Allow sysstat_t to makedir in sysstat_log_t- Update rhcs policy- Allow users to exec restorecond- Allow sendmail to request kernel modules load- Fix all kernel_request_load_module domains- Fix all kernel_request_load_module domains- Remove allow_exec* booleans for confined users. Only available for unconfined_t- More fixes for sandbox_web_t- Allow sshd to create .ssh directory and content- Fix request_module line to module_request- Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.- Fixes for sandbox- Update to upstream - Dontaudit nsplugin search /root - Dontaudit nsplugin sys_nice- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service - Remove policycoreutils-python requirement except for minimum- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files - Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)- Add wordpress/wp-content/uploads label - Fixes for sandbox when run from staff_t- Update to upstream - Fixes for devicekit_disk- More fixes- Lots of fixes for initrc and other unconfined domains- Allow xserver to use netlink_kobject_uevent_socket- Fixes for sandbox- Dontaudit setroubleshootfix looking at /root directory- Update to upsteam- Allow gssd to send signals to users - Fix duplicate label for apache content- Update to upstream- Remove polkit_auth on upgrades- Add back in unconfined.pp and unconfineduser.pp - Add Sandbox unshare- Fixes for cdrecord, mdadm, and others- Add capability setting to dhcpc and gpm- Allow cronjobs to read exim_spool_t- Add ABRT policy- Fix system-config-services policy- Allow libvirt to change user componant of virt_domain- Allow cupsd_config_t to be started by dbus - Add smoltclient policy- Add policycoreutils-python to pre install- Make all unconfined_domains permissive so we can see what AVC's happen- Add pt_chown policy- Add kdump policy for Miroslav Grepl - Turn off execstack boolean- Turn on execstack on a temporary basis (#512845)- Allow nsplugin to connecto the session bus - Allow samba_net to write to coolkey data- Allow devicekit_disk to list inotify- Allow svirt images to create sock_file in svirt_var_run_t- Allow exim to getattr on mountpoints - Fixes for pulseaudio- Allow svirt_t to stream_connect to virtd_t- Allod hald_dccm_t to create sock_files in /tmp- More fixes from upstream- Fix polkit label - Remove hidebrokensymptoms for nss_ldap fix - Add modemmanager policy - Lots of merges from upstream - Begin removing textrel_shlib_t labels, from fixed libraries- Update to upstream- Allow certmaster to override dac permissions- Update to upstream- Fix context for VirtualBox- Update to upstream- Allow clamscan read amavis spool files- Fixes for xguest- fix multiple directory ownership of mandirs- Update to upstream- Add rules for rtkit-daemon- Update to upstream - Fix nlscd_stream_connect- Add rtkit policy- Allow rpcd_t to stream connect to rpcbind- Allow kpropd to create tmp files- Fix last duplicate /var/log/rpmpkgs- Update to upstream * add sssd- Update to upstream * cleanup- Update to upstream - Additional mail ports - Add virt_use_usb boolean for svirt- Fix mcs rules to include chr_file and blk_file- Add label for udev-acl- Additional rules for consolekit/udev, privoxy and various other fixes- New version for upstream- Allow NetworkManager to read inotifyfs- Allow setroubleshoot to run mlocate- Update to upstream- Add fish as a shell - Allow fprintd to list usbfs_t - Allow consolekit to search mountpoints - Add proper labeling for shorewall- New log file for vmware - Allow xdm to setattr on user_tmp_t- Upgrade to upstream- Allow fprintd to access sys_ptrace - Add sandbox policy- Add varnishd policy- Fixes for kpropd- Allow brctl to r/w tun_tap_device_t- Add /usr/share/selinux/packages- Allow rpcd_t to send signals to kernel threads- Fix upgrade for F10 to F11- Add policy for /var/lib/fprint-Remove duplicate line- Allow svirt to manage pci and other sysfs device data- Fix package selection handling- Fix /sbin/ip6tables-save context - Allod udev to transition to mount - Fix loading of mls policy file- Add shorewall policy- Additional rules for fprintd and sssd- Allow nsplugin to unix_read unix_write sem for unconfined_java- Fix uml files to be owned by users- Fix Upgrade path to install unconfineduser.pp when unocnfined package is 3.0.0 or less- Allow confined users to manage virt_content_t, since this is home dir content - Allow all domains to read rpm_script_tmp_t which is what shell creates on redirection- Fix labeling on /var/lib/misc/prelink* - Allow xserver to rw_shm_perms with all x_clients - Allow prelink to execute files in the users home directory- Allow initrc_t to delete dev_null - Allow readahead to configure auditing - Fix milter policy - Add /var/lib/readahead- Update to latest milter code from Paul Howarth- Additional perms for readahead- Allow pulseaudio to acquire_svc on session bus - Fix readahead labeling- Allow sysadm_t to run rpm directly - libvirt needs fowner- Allow sshd to read var_lib symlinks for freenx- Allow nsplugin unix_read and write on users shm and sem - Allow sysadm_t to execute su- Dontaudit attempts to getattr user_tmpfs_t by lvm - Allow nfs to share removable media- Add ability to run postdrop from confined users- Fixes for podsleuth- Turn off nsplugin transition - Remove Konsole leaked file descriptors for release- Allow cupsd_t to create link files in print_spool_t - Fix iscsi_stream_connect typo - Fix labeling on /etc/acpi/actions - Don't reinstall unconfine and unconfineuser on upgrade if they are not installed- Allow audioentroy to read etc files- Add fail2ban_var_lib_t - Fixes for devicekit_power_t- Separate out the ucnonfined user from the unconfined.pp package- Make sure unconfined_java_t and unconfined_mono_t create user_tmpfs_t.- Upgrade to latest upstream - Allow devicekit_disk sys_rawio- Dontaudit binds to ports < 1024 for named - Upgrade to latest upstream- Allow podsleuth to use tmpfs files- Add customizable_types for svirt- Allow setroubelshoot exec* privs to prevent crash from bad libraries - add cpufreqselector- Dontaudit listing of /root directory for cron system jobs- Fix missing ld.so.cache label- Add label for ~/.forward and /root/.forward- Fixes for svirt- Fixes to allow svirt read iso files in homedir- Add xenner and wine fixes from mgrepl- Allow mdadm to read/write mls override- Change to svirt to only access svirt_image_t- Fix libvirt policy- Upgrade to latest upstream- Fixes for iscsid and sssd - More cleanups for upgrade from F10 to Rawhide.- Add pulseaudio, sssd policy - Allow networkmanager to exec udevadm- Add pulseaudio context- Upgrade to latest patches- Fixes for libvirt- Update to Latest upstream- Fix setrans.conf to show SystemLow for s0- Further confinement of qemu images via svirt- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- Allow NetworkManager to manage /etc/NetworkManager/system-connections- add virtual_image_context and virtual_domain_context files- Allow rpcd_t to send signal to mount_t - Allow libvirtd to run ranged- Fix sysnet/net_conf_t- Fix squidGuard labeling- Re-add corenet_in_generic_if(unlabeled_t)* Tue Feb 10 2009 Dan Walsh 3.6.5-2 - Add git web policy- Add setrans contains from upstream- Do transitions outside of the booleans- Allow xdm to create user_tmp_t sockets for switch user to work- Fix staff_t domain- Grab remainder of network_peer_controls patch- More fixes for devicekit- Upgrade to latest upstream- Add boolean to disallow unconfined_t login- Add back transition from xguest to mozilla- Add virt_content_ro_t and labeling for isos directory- Fixes for wicd daemon- More mls/rpm fixes- Add policy to make dbus/nm-applet work- Remove polgen-ifgen from post and add trigger to policycoreutils-python- Add wm policy - Make mls work in graphics mode- Fixed for DeviceKit- Add devicekit policy- Update to upstream- Define openoffice as an x_domain- Fixes for reading xserver_tmp_t- Allow cups_pdf_t write to nfs_t- Remove audio_entropy policy- Update to upstream- Allow hal_acl_t to getattr/setattr fixed_disk- Change userdom_read_all_users_state to include reading symbolic links in /proc- Fix dbus reading /proc information- Add missing alias for home directory content- Fixes for IBM java location- Allow unconfined_r unconfined_java_t- Add cron_role back to user domains- Fix sudo setting of user keys- Allow iptables to talk to terminals - Fixes for policy kit - lots of fixes for booting.- Cleanup policy- Rebuild for Python 2.6- Fix labeling on /var/spool/rsyslog- Allow postgresl to bind to udp nodes- Allow lvm to dbus chat with hal - Allow rlogind to read nfs_t- Fix cyphesis file context- Allow hal/pm-utils to look at /var/run/video.rom - Add ulogd policy- Additional fixes for cyphesis - Fix certmaster file context - Add policy for system-config-samba - Allow hal to read /var/run/video.rom- Allow dhcpc to restart ypbind - Fixup labeling in /var/run- Add certmaster policy- Fix confined users - Allow xguest to read/write xguest_dbusd_t- Allow openoffice execstack/execmem privs- Allow mozilla to run with unconfined_execmem_t- Dontaudit domains trying to write to .xsession-errors- Allow nsplugin to look at autofs_t directory- Allow kerneloops to create tmp files- More alias for fastcgi- Remove mod_fcgid-selinux package- Fix dovecot access- Policy cleanup- Remove Multiple spec - Add include - Fix makefile to not call per_role_expansion- Fix labeling of libGL- Update to upstream- Update to upstream policy- Fixes for confined xwindows and xdm_t- Allow confined users and xdm to exec wm - Allow nsplugin to talk to fifo files on nfs- Allow NetworkManager to transition to avahi and iptables - Allow domains to search other domains keys, coverup kernel bug- Fix labeling for oracle- Allow nsplugin to comminicate with xdm_tmp_t sock_file- Change all user tmpfs_t files to be labeled user_tmpfs_t - Allow radiusd to create sock_files- Upgrade to upstream- Allow confined users to login with dbus- Fix transition to nsplugin- Add file context for /dev/mspblk.*- Fix transition to nsplugin '- Fix labeling on new pm*log - Allow ssh to bind to all nodes- Merge upstream changes - Add Xavier Toth patches- Add qemu_cache_t for /var/cache/libvirt- Remove gamin policy- Add tinyxs-max file system support- Update to upstream - New handling of init scripts- Allow pcsd to dbus - Add memcache policy- Allow audit dispatcher to kill his children- Update to upstream - Fix crontab use by unconfined user- Allow ifconfig_t to read dhcpc_state_t- Update to upstream- Update to upstream- Allow system-config-selinux to work with policykit- Fix novel labeling- Consolodate pyzor,spamassassin, razor into one security domain - Fix xdm requiring additional perms.- Fixes for logrotate, alsa- Eliminate vbetool duplicate entry- Fix xguest -> xguest_mozilla_t -> xguest_openiffice_t - Change dhclient to be able to red networkmanager_var_run- Update to latest refpolicy - Fix libsemanage initial install bug- Add inotify support to nscd- Allow unconfined_t to setfcap- Allow amanda to read tape - Allow prewikka cgi to use syslog, allow audisp_t to signal cgi - Add support for netware file systems- Allow ypbind apps to net_bind_service- Allow all system domains and application domains to append to any log file- Allow gdm to read rpm database - Allow nsplugin to read mplayer config files- Allow vpnc to run ifconfig- Allow confined users to use postgres - Allow system_mail_t to exec other mail clients - Label mogrel_rails as an apache server- Apply unconfined_execmem_exec_t to haskell programs- Fix prelude file context- allow hplip to talk dbus - Fix context on ~/.local dir- Prevent applications from reading x_device- Add /var/lib/selinux context- Update to upstream- Add livecd policy- Dontaudit search of admin_home for init_system_domain - Rewrite of xace interfaces - Lots of new fs_list_inotify - Allow livecd to transition to setfiles_mac- Begin XAce integration- Merge Upstream- Allow amanada to create data files- Fix initial install, semanage setup- Allow system_r for httpd_unconfined_script_t- Remove dmesg boolean - Allow user domains to read/write game data- Change unconfined_t to transition to unconfined_mono_t when running mono - Change XXX_mono_t to transition to XXX_t when executing bin_t files, so gnome-do will work- Remove old booleans from targeted-booleans.conf file- Add boolean to mmap_zero - allow tor setgid - Allow gnomeclock to set clock- Don't run crontab from unconfined_t- Change etc files to config files to allow users to read them- Lots of fixes for confined domains on NFS_t homedir- dontaudit mrtg reading /proc - Allow iscsi to signal itself - Allow gnomeclock sys_ptrace- Allow dhcpd to read kernel network state- Label /var/run/gdm correctly - Fix unconfined_u user creation- Allow transition from initrc_t to getty_t- Allow passwd to communicate with user sockets to change gnome-keyring- Fix initial install- Allow radvd to use fifo_file - dontaudit setfiles reading links - allow semanage sys_resource - add allow_httpd_mod_auth_ntlm_winbind boolean - Allow privhome apps including dovecot read on nfs and cifs home dirs if the boolean is set- Allow nsplugin to read /etc/mozpluggerrc, user_fonts - Allow syslog to manage innd logs. - Allow procmail to ioctl spamd_exec_t- Allow initrc_t to dbus chat with consolekit.- Additional access for nsplugin - Allow xdm setcap/getcap until pulseaudio is fixed- Allow mount to mkdir on tmpfs - Allow ifconfig to search debugfs- Fix file context for MATLAB - Fixes for xace- Allow stunnel to transition to inetd children domains - Make unconfined_dbusd_t an unconfined domain- Fixes for qemu/virtd- Fix bug in mozilla policy to allow xguest transition - This will fix the libsemanage.dbase_llist_query: could not find record value libsemanage.dbase_llist_query: could not query record value (No such file or directory) bug in xguest- Allow nsplugin to run acroread- Add cups_pdf policy - Add openoffice policy to run in xguest- prewika needs to contact mysql - Allow syslog to read system_map files- Change init_t to an unconfined_domain- Allow init to transition to initrc_t on shell exec. - Fix init to be able to sendto init_t. - Allow syslog to connect to mysql - Allow lvm to manage its own fifo_files - Allow bugzilla to use ldap - More mls fixes- fixes for init policy (#436988) - fix build- Additional changes for MLS policy- Fix initrc_context generation for MLS- Fixes for libvirt- Allow bitlebee to read locale_t- More xselinux rules- Change httpd_$1_script_r*_t to httpd_$1_content_r*_t- Prepare policy for beta release - Change some of the system domains back to unconfined - Turn on some of the booleans- Allow nsplugin_config execstack/execmem - Allow nsplugin_t to read alsa config - Change apache to use user content- Add cyphesis policy- Fix Makefile.devel to build mls modules - Fix qemu to be more specific on labeling- Update to upstream fixes- Allow staff to mounton user_home_t- Add xace support- Add fusectl file system- Fixes from yum-cron - Update to latest upstream- Fix userdom_list_user_files- Merge with upstream- Allow udev to send audit messages- Add additional login users interfaces - userdom_admin_login_user_template(staff)- More fixes for polkit- Eliminate transition from unconfined_t to qemu by default - Fixes for gpg- Update to upstream- Fixes for staff_t- Add policy for kerneloops - Add policy for gnomeclock- Fixes for libvirt- Fixes for nsplugin- More fixes for qemu- Additional ports for vnc and allow qemu and libvirt to search all directories- Update to upstream - Add libvirt policy - add qemu policy- Allow fail2ban to create a socket in /var/run- Allow allow_httpd_mod_auth_pam to work- Add audisp policy and prelude- Allow all user roles to executae samba net command- Allow usertypes to read/write noxattr file systems- Fix nsplugin to allow flashplugin to work in enforcing mode- Allow pam_selinux_permit to kill all processes- Allow ptrace or user processes by users of same type - Add boolean for transition to nsplugin- Allow nsplugin sys_nice, getsched, setsched- Allow login programs to talk dbus to oddjob- Add procmail_log support - Lots of fixes for munin- Allow setroubleshoot to read policy config and send audit messages- Allow users to execute all files in homedir, if boolean set - Allow mount to read samba config- Fixes for xguest to run java plugin- dontaudit pam_t and dbusd writing to user_home_t- Update gpg to allow reading of inotify- Change user and staff roles to work correctly with varied perms- Fix munin log, - Eliminate duplicate mozilla file context - fix wpa_supplicant spec- Fix role transition from unconfined_r to system_r when running rpm - Allow unconfined_domains to communicate with user dbus instances- Fixes for xguest- Let all uncofined domains communicate with dbus unconfined- Run rpm in system_r- Zero out customizable types- Fix definiton of admin_home_t- Fix munin file context- Allow cron to run unconfined apps- Modify default login to unconfined_u- Dontaudit dbus user client search of /root- Update to upstream- Fixes for polkit - Allow xserver to ptrace- Add polkit policy - Symplify userdom context, remove automatic per_role changes- Update to upstream - Allow httpd_sys_script_t to search users homedirs- Allow rpm_script to transition to unconfined_execmem_t- Remove user based home directory separation- Remove user specific crond_t- Merge with upstream - Allow xsever to read hwdata_t - Allow login programs to setkeycreate- Update to upstream- Update to upstream- Allow XServer to read /proc/self/cmdline - Fix unconfined cron jobs - Allow fetchmail to transition to procmail - Fixes for hald_mac - Allow system_mail to transition to exim - Allow tftpd to upload files - Allow xdm to manage unconfined_tmp - Allow udef to read alsa config - Fix xguest to be able to connect to sound port- Fixes for hald_mac - Treat unconfined_home_dir_t as a home dir - dontaudit rhgb writes to fonts and root- Fix dnsmasq - Allow rshd full login privs- Allow rshd to connect to ports > 1023- Fix vpn to bind to port 4500 - Allow ssh to create shm - Add Kismet policy- Allow rpm to chat with networkmanager- Fixes for ipsec and exim mail - Change default to unconfined user- Pass the UNK_PERMS param to makefile - Fix gdm location- Make alsa work- Fixes for consolekit and startx sessions- Dontaudit consoletype talking to unconfined_t- Remove homedir_template- Check asound.state- Fix exim policy- Allow tmpreadper to read man_t - Allow racoon to bind to all nodes - Fixes for finger print reader- Allow xdm to talk to input device (fingerprint reader) - Allow octave to run as java- Allow login programs to set ioctl on /proc- Allow nsswitch apps to read samba_var_t- Fix maxima- Eliminate rpm_t:fifo_file avcs - Fix dbus path for helper app- Fix service start stop terminal avc's- Allow also to search var_lib - New context for dbus launcher- Allow cupsd_config_t to read/write usb_device_t - Support for finger print reader, - Many fixes for clvmd - dbus starting networkmanager- Fix java and mono to run in xguest account- Fix to add xguest account when inititial install - Allow mono, java, wine to run in userdomains- Allow xserver to search devpts_t - Dontaudit ldconfig output to homedir- Remove hplip_etc_t change back to etc_t.- Allow cron to search nfs and samba homedirs- Allow NetworkManager to dbus chat with yum-updated- Allow xfs to bind to port 7100- Allow newalias/sendmail dac_override - Allow bind to bind to all udp ports- Turn off direct transition- Allow wine to run in system role- Fix java labeling- Define user_home_type as home_type- Allow sendmail to create etc_aliases_t- Allow login programs to read symlinks on homedirs- Update an readd modules- Cleanup spec file- Allow xserver to be started by unconfined process and talk to tty- Upgrade to upstream to grab postgressql changes- Add setransd for mls policy- Add ldconfig_cache_t- Allow sshd to write to proc_t for afs login- Allow xserver access to urand- allow dovecot to search mountpoints- Fix Makefile for building policy modules- Fix dhcpc startup of service- Fix dbus chat to not happen for xguest and guest users- Fix nagios cgi - allow squid to communicate with winbind- Fixes for ldconfig- Update from upstream- Add nasd support- Fix new usb devices and dmfm- Eliminate mount_ntfs_t policy, merge into mount_t- Allow xserver to write to ramfs mounted by rhgb- Add context for dbus machine id- Update with latest changes from upstream- Fix prelink to handle execmod- Add ntpd_key_t to handle secret data- Add anon_inodefs - Allow unpriv user exec pam_exec_t - Fix trigger- Allow cups to use generic usb - fix inetd to be able to run random apps (git)- Add proper contexts for rsyslogd- Fixes for xguest policy- Allow execution of gconf- Fix moilscanner update problem- Begin adding policy to separate setsebool from semanage - Fix xserver.if definition to not break sepolgen.if- Add new devices- Add brctl policy- Fix root login to include system_r- Allow prelink to read kernel sysctls- Default to user_u:system_r:unconfined_t- fix squid - Fix rpm running as uid- Fix syslog declaration- Allow avahi to access inotify - Remove a lot of bogus security_t:filesystem avcs- Remove ifdef strict policy from upstream- Remove ifdef strict to allow user_u to login- Fix for amands - Allow semanage to read pp files - Allow rhgb to read xdm_xserver_tmp- Allow kerberos servers to use ldap for backing store- allow alsactl to read kernel state- More fixes for alsactl - Transition from hal and modutils - Fixes for suspend resume. - insmod domtrans to alsactl - insmod writes to hal log- Allow unconfined_t to transition to NetworkManager_t - Fix netlabel policy- Update to latest from upstream- Update to latest from upstream- Update to latest from upstream- Allow pcscd_t to send itself signals- Fixes for unix_update - Fix logwatch to be able to search all dirs- Upstream bumped the version- Allow consolekit to syslog - Allow ntfs to work with hal- Allow iptables to read etc_runtime_t- MLS Fixes- Fix path of /etc/lvm/cache directory - Fixes for alsactl and pppd_t - Fixes for consolekit- Allow insmod_t to mount kvmfs_t filesystems- Rwho policy - Fixes for consolekit- fixes for fusefs- Fix samba_net to allow it to view samba_var_t- Update to upstream- Fix Sonypic backlight - Allow snmp to look at squid_conf_t- Fixes for pyzor, cyrus, consoletype on everything installs- Fix hald_acl_t to be able to getattr/setattr on usb devices - Dontaudit write to unconfined_pipes for load_policy- Allow bluetooth to read inotifyfs- Fixes for samba domain controller. - Allow ConsoleKit to look at ttys- Fix interface call- Allow syslog-ng to read /var - Allow locate to getattr on all filesystems - nscd needs setcap- Update to upstream- Allow samba to run groupadd- Update to upstream- Allow mdadm to access generic scsi devices- Fix labeling on udev.tbl dirs- Fixes for logwatch- Add fusermount and mount_ntfs policy- Update to upstream - Allow saslauthd to use kerberos keytabs- Fixes for samba_var_t- Allow networkmanager to setpgid - Fixes for hal_acl_t- Remove disable_trans booleans - hald_acl_t needs to talk to nscd- Fix prelink to be able to manage usr dirs.- Allow insmod to launch init scripts- Remove setsebool policy- Fix handling of unlabled_t packets- More of my patches from upstream- Update to latest from upstream - Add fail2ban policy- Update to remove security_t:filesystem getattr problems- Policy for consolekit- Update to latest from upstream- Revert Nemiver change - Set sudo as a corecmd so prelink will work, remove sudoedit mapping, since this will not work, it does not transition. - Allow samba to execute useradd- Upgrade to the latest from upstream- Add sepolgen support - Add bugzilla policy- Fix file context for nemiver- Remove include sym link- Allow mozilla, evolution and thunderbird to read dev_random. Resolves: #227002 - Allow spamd to connect to smtp port Resolves: #227184 - Fixes to make ypxfr work Resolves: #227237- Fix ssh_agent to be marked as an executable - Allow Hal to rw sound device- Fix spamassisin so crond can update spam files - Fixes to allow kpasswd to work - Fixes for bluetooth- Remove some targeted diffs in file context file- Fix squid cachemgr labeling- Add ability to generate webadm_t policy - Lots of new interfaces for httpd - Allow sshd to login as unconfined_t- Continue fixing, additional user domains- Begin adding user confinement to targeted policy- Fixes for prelink, ktalkd, netlabel- Allow prelink when run from rpm to create tmp files Resolves: #221865 - Remove file_context for exportfs Resolves: #221181 - Allow spamassassin to create ~/.spamassissin Resolves: #203290 - Allow ssh access to the krb tickets - Allow sshd to change passwd - Stop newrole -l from working on non securetty Resolves: #200110 - Fixes to run prelink in MLS machine Resolves: #221233 - Allow spamassassin to read var_lib_t dir Resolves: #219234- fix mplayer to work under strict policy - Allow iptables to use nscd Resolves: #220794- Add gconf policy and make it work with strict- Many fixes for strict policy and by extension mls.- Fix to allow ftp to bind to ports > 1024 Resolves: #219349- Allow semanage to exec it self. Label genhomedircon as semanage_exec_t Resolves: #219421 - Allow sysadm_lpr_t to manage other print spool jobs Resolves: #220080- allow automount to setgid Resolves: #219999- Allow cron to polyinstatiate - Fix creation of boot flags Resolves: #207433- Fixes for irqbalance Resolves: #219606- Fix vixie-cron to work on mls Resolves: #207433Resolves: #218978- Allow initrc to create files in /var directories Resolves: #219227- More fixes for MLS Resolves: #181566- More Fixes polyinstatiation Resolves: #216184- More Fixes polyinstatiation - Fix handling of keyrings Resolves: #216184- Fix polyinstatiation - Fix pcscd handling of terminal Resolves: #218149 Resolves: #218350- More fixes for quota Resolves: #212957- ncsd needs to use avahi sockets Resolves: #217640 Resolves: #218014- Allow login programs to polyinstatiate homedirs Resolves: #216184 - Allow quotacheck to create database files Resolves: #212957- Dontaudit appending hal_var_lib files Resolves: #217452 Resolves: #217571 Resolves: #217611 Resolves: #217640 Resolves: #217725- Fix context for helix players file_context #216942- Fix load_policy to be able to mls_write_down so it can talk to the terminal- Fixes for hwclock, clamav, ftp- Move to upstream version which accepted my patches- Fixes for nvidia driver- Allow semanage to signal mcstrans- Update to upstream- Allow modstorage to edit /etc/fstab file- Fix for qemu, /dev/- Fix path to realplayer.bin- Allow xen to connect to xen port- Allow cups to search samba_etc_t directory - Allow xend_t to list auto_mountpoints- Allow xen to search automount- Fix spec of jre files- Fix unconfined access to shadow file- Allow xend to create files in xen_image_t directories- Fixes for /var/lib/hal- Remove ability for sysadm_t to look at audit.log- Fix rpc_port_types - Add aide policy for mls- Merge with upstream- Lots of fixes for ricci- Allow xen to read/write fixed devices with a boolean - Allow apache to search /var/log- Fix policygentool specfile problem. - Allow apache to send signals to it's logging helpers. - Resolves: rhbz#212731- Add perms for swat- Add perms for swat- Allow daemons to dump core files to /- Fixes for ricci- Allow mount.nfs to work- Allow ricci-modstorage to look at lvm_etc_t- Fixes for ricci using saslauthd- Allow mountpoint on home_dir_t and home_t- Update xen to read nfs files- Allow noxattrfs to associate with other noxattrfs- Allow hal to use power_device_t- Allow procemail to look at autofs_t - Allow xen_image_t to work as a fixed device- Refupdate from upstream- Add lots of fixes for mls cups- Lots of fixes for ricci- Fix number of cats- Update to upstream- More iSCSI changes for #209854- Test ISCSI fixes for #209854- allow semodule to rmdir selinux_config_t dir- Fix boot_runtime_t problem on ppc. Should not be creating these files.- Fix context mounts on reboot - Fix ccs creation of directory in /var/log- Update for tallylog- Allow xend to rewrite dhcp conf files - Allow mgetty sys_admin capability- Make xentapctrl work- Don't transition unconfined_t to bootloader_t - Fix label in /dev/xen/blktap- Patch for labeled networking- Fix crond handling for mls- Update to upstream- Remove bluetooth-helper transition - Add selinux_validate for semanage - Require new version of libsemanage- Fix prelink- Fix rhgb- Fix setrans handling on MLS and useradd- Support for fuse - fix vigr- Fix dovecot, amanda - Fix mls- Allow java execheap for itanium- Update with upstream- mls fixes- Update from upstream- More fixes for mls - Revert change on automount transition to mount- Fix cron jobs to run under the correct context- Fixes to make pppd work- Multiple policy fixes - Change max categories to 1023- Fix transition on mcstransd- Add /dev/em8300 defs- Upgrade to upstream- Fix ppp connections from network manager- Add tty access to all domains boolean - Fix gnome-pty-helper context for ia64- Fixed typealias of firstboot_rw_t- Fix location of xel log files - Fix handling of sysadm_r -> rpm_exec_t- Fixes for autofs, lp- Update from upstream- Fixup for test6- Update to upstream- Update to upstream- Fix suspend to disk problems- Lots of fixes for restarting daemons at the console.- Fix audit line - Fix requires line- Upgrade to upstream- Fix install problems- Allow setroubleshoot to getattr on all dirs to gather RPM data- Set /usr/lib/ia32el/ia32x_loader to unconfined_execmem_exec_t for ia32 platform - Fix spec for /dev/adsp- Fix xen tty devices- Fixes for setroubleshoot- Update to upstream- Fixes for stunnel and postgresql - Update from upstream- Update from upstream - More java fixes- Change allow_execstack to default to on, for RHEL5 Beta. This is required because of a Java compiler problem. Hope to turn off for next beta- Misc fixes- More fixes for strict policy- Quiet down anaconda audit messages- Fix setroubleshootd- Update to the latest from upstream- More fixes for xen- Fix anaconda transitions- yet more xen rules- more xen rules- Fixes for Samba- Fixes for xen- Allow setroubleshootd to send mail- Add nagios policy- fixes for setroubleshoot- Added Paul Howarth patch to only load policy packages shipped with this package - Allow pidof from initrc to ptrace higher level domains - Allow firstboot to communicate with hal via dbus- Add policy for /var/run/ldapi- Fix setroubleshoot policy- Fixes for mls use of ssh - named has a new conf file- Fixes to make setroubleshoot work- Cups needs to be able to read domain state off of printer client- add boolean to allow zebra to write config files- setroubleshootd fixes- Allow prelink to read bin_t symlink - allow xfs to read random devices - Change gfs to support xattr- Remove spamassassin_can_network boolean- Update to upstream - Fix lpr domain for mls- Add setroubleshoot policy- Turn off auditallow on setting booleans- Multiple fixes- Update to upstream- Update to upstream - Add new class for kernel key ring- Update to upstream- Update to upstream- Break out selinux-devel package- Add ibmasmfs- Fix policygentool gen_requires- Update from Upstream- Fix spec of realplay- Update to upstream- Fix semanage- Allow useradd to create_home_dir in MLS environment- Update from upstream- Update from upstream- Add oprofilefs- Fix for hplip and Picasus- Update to upstream- Update to upstream- fixes for spamd- fixes for java, openldap and webalizer- Xen fixes- Upgrade to upstream- allow hal to read boot_t files - Upgrade to upstream- allow hal to read boot_t files- Update from upstream- Fixes for amavis- Update from upstream- Allow auditctl to search all directories- Add acquire service for mono.- Turn off allow_execmem boolean - Allow ftp dac_override when allowed to access users homedirs- Clean up spec file - Transition from unconfined_t to prelink_t- Allow execution of cvs command- Update to upstream- Update to upstream- Fix libjvm spec- Update to upstream- Add xm policy - Fix policygentool- Update to upstream - Fix postun to only disable selinux on full removal of the packages- Allow mono to chat with unconfined- Allow procmail to sendmail - Allow nfs to share dosfs- Update to latest from upstream - Allow selinux-policy to be removed and kernel not to crash- Update to latest from upstream - Add James Antill patch for xen - Many fixes for pegasus- Add unconfined_mount_t - Allow privoxy to connect to httpd_cache - fix cups labeleing on /var/cache/cups- Update to latest from upstream- Update to latest from upstream - Allow mono and unconfined to talk to initrc_t dbus objects- Change libraries.fc to stop shlib_t form overriding texrel_shlib_t- Fix samba creating dirs in homedir - Fix NFS so its booleans would work- Allow secadm_t ability to relabel all files - Allow ftp to search xferlog_t directories - Allow mysql to communicate with ldap - Allow rsync to bind to rsync_port_t- Fixed mailman with Postfix #183928 - Allowed semanage to create file_context files. - Allowed amanda_t to access inetd_t TCP sockets and allowed amanda_recover_t to bind to reserved ports. #149030 - Don't allow devpts_t to be associated with tmp_t. - Allow hald_t to stat all mountpoints. - Added boolean samba_share_nfs to allow smbd_t full access to NFS mounts. - Make mount run in mount_t domain from unconfined_t to prevent mislabeling of /etc/mtab. - Changed the file_contexts to not have a regex before the first ^/[a-z]/ whenever possible, makes restorecon slightly faster. - Correct the label of /etc/named.caching-nameserver.conf - Now label /usr/src/kernels/.+/lib(/.*)? as usr_t instead of /usr/src(/.*)?/lib(/.*)? - I don't think we need anything else under /usr/src hit by this. - Granted xen access to /boot, allowed mounting on xend_var_lib_t, and allowed xenstored_t rw access to the xen device node.- More textrel_shlib_t file path fixes - Add ada support- Get auditctl working in MLS policy- Add mono dbus support - Lots of file_context fixes for textrel_shlib_t in FC5 - Turn off execmem auditallow since they are filling log files- Update to upstream- Allow automount and dbus to read cert files- Fix ftp policy - Fix secadm running of auditctl- Update to upstream- Update to upstream- Fix policyhelp- Fix pam_console handling of usb_device - dontaudit logwatch reading /mnt dir- Update to upstream- Get transition rules to create policy.20 at SystemHigh- Allow secadmin to shutdown system - Allow sendmail to exec newalias- MLS Fixes dmidecode needs mls_file_read_up - add ypxfr_t - run init needs access to nscd - udev needs setuid - another xen log file - Dontaudit mount getattr proc_kcore_t- fix buildroot usage (#185391)- Get rid of mount/fsdisk scan of /dev messages - Additional fixes for suspend/resume- Fake make to rebuild enableaudit.pp- Get xen networking running.- Fixes for Xen - enableaudit should not be the same as base.pp - Allow ps to work for all process- more xen policy fixups- more xen fixage (#184393)- Fix blkid specification - Allow postfix to execute mailman_que- Blkid changes - Allow udev access to usb_device_t - Fix post script to create targeted policy config file- Allow lvm tools to create drevice dir- Add Xen support- Fixes for cups - Make cryptosetup work with hal- Load Policy needs translock- Fix cups html interface- Add hal changes suggested by Jeremy - add policyhelp to point at policy html pages- Additional fixes for nvidia and cups- Update to upstream - Merged my latest fixes - Fix cups policy to handle unix domain sockets- NSCD socket is in nscd_var_run_t needs to be able to search dir- Fixes Apache interface file- Fixes for new version of cups- Turn off polyinstatiate util after FC5- Fix problem with privoxy talking to Tor- Turn on polyinstatiation- Don't transition from unconfined_t to fsadm_t- Fix policy update model.- Update to upstream- Fix load_policy to work on MLS - Fix cron_rw_system_pipes for postfix_postdrop_t - Allow audotmount to run showmount- Fix swapon - allow httpd_sys_script_t to be entered via a shell - Allow httpd_sys_script_t to read eventpolfs- Update from upstream- allow cron to read apache files- Fix vpnc policy to work from NetworkManager- Update to upstream - Fix semoudle polcy- Update to upstream - fix sysconfig/selinux link- Add router port for zebra - Add imaze port for spamd - Fixes for amanda and java- Fix bluetooth handling of usb devices - Fix spamd reading of ~/ - fix nvidia spec- Update to upsteam- Add users_extra files- Update to upstream- Add semodule policy- Update from upstream- Fix for spamd to use razor port- Fixes for mcs - Turn on mount and fsadm for unconfined_t- Fixes for the -devel package- Fix for spamd to use ldap- Update to upstream- Update to upstream - Fix rhgb, and other Xorg startups- Update to upstream- Separate out role of secadm for mls- Add inotifyfs handling- Update to upstream - Put back in changes for pup/zen- Many changes for MLS - Turn on strict policy- Update to upstream- Update to upstream - Fixes for booting and logging in on MLS machine- Update to upstream - Turn off execheap execstack for unconfined users - Add mono/wine policy to allow execheap and execstack for them - Add execheap for Xdm policy- Update to upstream - Fixes to fetchmail,- Update to upstream- Fix for procmail/spamassasin - Update to upstream - Add rules to allow rpcd to work with unlabeled_networks.- Update to upstream - Fix ftp Man page- Update to upstream- fix pup transitions (#177262) - fix xen disks (#177599)- Update to upstream- More Fixes for hal and readahead- Fixes for hal and readahead- Update to upstream - Apply- Add wine and fix hal problems- Handle new location of hal scripts- Allow su to read /etc/mtab- Update to upstream- Fix "libsemanage.parse_module_headers: Data did not represent a module." problem- Allow load_policy to read /etc/mtab- Fix dovecot to allow dovecot_auth to look at /tmp- Allow restorecon to read unlabeled_t directories in order to fix labeling.- Add Logwatch policy- Fix /dev/ub[a-z] file context- Fix library specification - Give kudzu execmem privs- Fix hostname in targeted policy- Fix passwd command on mls- Lots of fixes to make mls policy work- Add dri libs to textrel_shlib_t - Add system_r role for java - Add unconfined_exec_t for vncserver - Allow slapd to use kerberos- Add man pages- Add enableaudit.pp- Fix mls policy- Update mls file from old version- Add sids back in - Rebuild with update checkpolicy- Fixes to allow automount to use portmap - Fixes to start kernel in s0-s15:c0.c255- Add java unconfined/execmem policy- Add file context for /var/cvs - Dontaudit webalizer search of homedir- Update from upstream- Clean up spec - range_transition crond to SystemHigh- Fixes for hal - Update to upstream- Turn back on execmem since we need it for java, firefox, ooffice - Allow gpm to stream socket to itself- fix requirements to be on the actual packages so that policy can get created properly at install time- Allow unconfined_t to execmod texrel_shlib_t- Update to upstream - Turn off allow_execmem and allow_execmod booleans - Add tcpd and automount policies- Add two new httpd booleans, turned off by default * httpd_can_network_relay * httpd_can_network_connect_db- Add ghost for policy.20- Update to upstream - Turn off boolean allow_execstack- Change setrans-mls to use new libsetrans - Add default_context rule for xdm- Change Requires to PreReg for requiring of policycoreutils on install- New upstream releaseAdd xdm policyUpdate from upstreamUpdate from upstreamUpdate from upstream- Also trigger to rebuild policy for versions up to 2.0.7.- No longer installing policy.20 file, anaconda handles the building of the app.- Fixes for dovecot and saslauthd- Cleanup pegasus and named - Fix spec file - Fix up passwd changing applications-Update to latest from upstream- Add rules for pegasus and avahi- Start building MLS Policy- Update to upstream- Turn on bash- Initial version/bin/sh/bin/shselinux-policy-mls-sources  !"#$%&'()*+,-./0123456789:;<=>?@ABDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`bcdefghijklmnopqrstuvwxyz{|}~     !"#$%&'()*+-./123456789:;<=>?ABCDEFGHIJKLMNOPQRSTUVW3.13.1-23.el7_1.183.13.1-23.el7_1.183.13.1-23.el7_1.182 mls.policy.sha512booleans.subs_distcontextscustomizable_typesdbus_contextsdefault_contextsdefault_typefailsafe_contextfilesfile_contextsfile_contexts.binfile_contexts.homedirsfile_contexts.homedirs.binfile_contexts.localfile_contexts.local.binfile_contexts.subsfile_contexts.subs_distmediainitrc_contextlxc_contextsremovable_contextsecuretty_typessepgsql_contextssystemd_contextsuserhelper_contextusersguest_urootstaff_uunconfined_uuser_uxguest_uvirtual_domain_contextvirtual_image_contextx_contextsloginsmodulesactivebase.ppcommit_numfile_contextsfile_contexts.binfile_contexts.homedirsfile_contexts.homedirs.binfile_contexts.localfile_contexts.templatehomedir_templatemodulesaccountsd.ppacct.ppafs.ppaide.ppalsa.ppamanda.ppamtu.ppanaconda.ppantivirus.ppapache.ppapcupsd.ppapm.ppapplication.pparpwatch.ppauditadm.ppauthlogin.ppautomount.ppavahi.ppawstats.ppbind.ppbitlbee.ppbluetooth.ppboinc.ppbootloader.ppbrctl.ppbugzilla.ppcachefilesd.ppcalamaris.ppcanna.ppccs.ppcdrecord.ppcertmaster.ppcertmonger.ppcertwatch.ppcgroup.ppchrome.ppchronyd.ppcipe.ppclock.ppclogd.ppcmirrord.ppcolord.ppcomsat.ppcourier.ppcpucontrol.ppcpufreqselector.ppcron.ppcups.ppcvs.ppcyphesis.ppcyrus.ppdaemontools.ppdbadm.ppdbskk.ppdbus.ppdcc.ppdevicekit.ppdhcp.ppdictd.ppdmesg.ppdmidecode.ppdnsmasq.ppdnssec.ppdovecot.ppentropyd.ppexim.ppfail2ban.ppfetchmail.ppfinger.ppfirewalld.ppfirewallgui.ppfirstboot.ppfprintd.ppfstools.ppftp.ppgames.ppgetty.ppgit.ppgitosis.ppglance.ppgnome.ppgpg.ppgpm.ppgpsd.ppgssproxy.ppguest.pphostname.ppinetd.ppinit.ppinn.ppipsec.ppiptables.ppirc.ppirqbalance.ppiscsi.ppjabber.ppkdump.ppkdumpgui.ppkerberos.ppkismet.ppksmtuned.ppktalk.ppldap.pplibraries.pplircd.pploadkeys.pplocallogin.pplockdev.pplogadm.pplogging.pplogrotate.pplogwatch.pplpd.pplvm.ppmailman.ppmandb.ppmcelog.ppmemcached.ppmilter.ppmiscfiles.ppmodemmanager.ppmodutils.ppmojomojo.ppmount.ppmozilla.ppmplayer.ppmrtg.ppmta.ppmunin.ppmysql.ppnagios.ppnamespace.ppncftool.ppnetlabel.ppnetutils.ppnetworkmanager.ppnis.ppnscd.ppnslcd.ppntop.ppntp.ppnx.ppoddjob.ppopenct.ppopenvpn.ppopenvswitch.pppads.pppcmcia.pppcscd.pppegasus.pppingd.pppiranha.ppplymouthd.pppodsleuth.pppolicykit.pppolipo.ppportmap.ppportreserve.pppostfix.pppostgresql.pppostgrey.ppppp.ppprelink.ppprelude.ppprivoxy.ppprocmail.ppprosody.pppsad.ppptchown.pppublicfile.pppulseaudio.ppqmail.ppqpid.ppquota.ppradius.ppradvd.ppraid.pprdisc.ppreadahead.ppremotelogin.pprhcs.pprhgb.ppricci.pprlogin.pproundup.pprpc.pprpcbind.pprpm.pprshd.pprsync.pprtkit.pprwho.ppsamba.ppsambagui.ppsasl.ppscreen.ppsecadm.ppselinuxutil.ppsendmail.ppsetrans.ppsetroubleshoot.ppseunshare.ppshorewall.ppslocate.ppsmartmon.ppsnmp.ppsnort.ppsosreport.ppsoundserver.ppspamassassin.ppsquid.ppssh.ppsssd.ppstaff.ppstunnel.ppsu.ppsudo.ppsysadm.ppsysadm_secadm.ppsysnetwork.ppsysstat.ppsystemd.pptcpd.pptcsd.pptelepathy.pptelnet.pptftp.pptgtd.ppthumb.pptmpreaper.pptor.pptuned.pptvtime.ppudev.ppulogd.ppuml.ppunlabelednet.ppunprivuser.ppupdfstab.ppusbmodules.ppuserdomain.ppuserhelper.ppusermanage.ppusernetctl.ppuucp.ppvirt.ppvmware.ppvpn.ppw3c.ppwebadm.ppwebalizer.ppwine.ppwireshark.ppwm.ppxen.ppxguest.ppxserver.ppzabbix.ppzebra.ppzosremote.ppnetfilter_contextsnodes.localpolicy.kernseusersseusers.finalusers.localusers_extrausers_extra.localsemanage.read.LOCKsemanage.trans.LOCKpolicypolicy.29setrans.confseusersmlsbase.lstmodules-base.lstmodules-contrib.lstnonbasemodules.lst/etc/selinux//etc/selinux/mls//etc/selinux/mls/contexts//etc/selinux/mls/contexts/files//etc/selinux/mls/contexts/users//etc/selinux/mls/modules//etc/selinux/mls/modules/active//etc/selinux/mls/modules/active/modules//etc/selinux/mls/policy//usr/share/selinux//usr/share/selinux/mls/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII textexported SGML document, ASCII textemptyHTML document, ASCII textASCII text, with very long lines, with no line terminators?7zXZ !PH6 p]"k%u1khu[ 9̴x~]|zE\ఌN7V&3id8BpGb0š8~@zLxΔO)[_bI5K(.i& wv>Gm;,p]Ν"D/!RNY5*ޅ n}eqzW[#dn0 w:W/1饡Q,9*QAY JiztlY}sгIU\$L/"cYMԗE>9IC:v;E!|{it2|8D}LUZSB6j@T&̹ne,7ˡɖbCrxsbԄʃ"b-LISOΥ}|į[h|u:$X:r{[{#؞/p@pi {! =v>Vd5m0SͶ?j6YB:gi4aq̠;h$e9('FB23 LI~1|Cϝ+ "B qn UD+~gj=٥gnEyFy5i 5br-Zbfs-Gw D{9Lb֣r^p -d-+W 1 }{YVc?`ZioiGLeޜ6;5$+Cu^NEk"\s fF(8~fCb } +b]̴e!F? 3x҇}$K H3ןVp]ɒg#B0+Vr̒jh9ɎkmCտˣ݋K&k$@8$QNڋ9ܣZMfV7!Y!ߵ 'i( 02rXmK2 EF( Vd!ChGm)O}e,Q^?Z`TZQ3\[ǔž/2f_oam뤕;m̶U]MrL,I,0c`z6”_iԍpʎ-ެ'ZykE q׉vɁJVTCsJ9j)*@T}#sZWltBB]sHYcbz|ͫE m?S =*y#} s0!Un7`u닗~ e5x[ MkjwNA>CSSUyN]:!/KqaYsdq5lk~Dl/=*Uw r2 Xun)OW1VәtR7F p@˓u @w̌|vOQ?zɑ#3?FWXDF}t $%Y~Ph * )v`7d2C&~.GBƇ e.OM>5|I Ъe"-̇ =AP /tlSdb}&7T4'AĬ9(Xk [X=w?TXJCM E/ ̏˿ 1Vs{јBWxѴAYl4OT$g1 d%lΆ[2, iZEIJD`=F +0% e(ASl1G͸& *;ã=j/(lyI/дou Yľ?|m4v3לߙkJ#`ٓXdjriÓa%1"ytYvoE%#^oQ@Ă |??̱0!19S9q&CÞb]oqӞjҖUf}sb߬t&fAZ)˖(?ҀbjNAU_Qy[ՊR~|EtZrǑ<cE7(t:c#LD S9rGTs3YGfR5K#Xa]Gr,ȩp6 ƶchs)dvk@c492ް[5"ݽ[sr@!%f}>h ~BgFׁ;ʌp$NmOxTN|<~7vc!b߽ A 'T`sEP.$P\q fvdQ(ћ%B󐕻DnPCڥS~QD(%}pqCngeQΗ.EziJ7; _RidYt@T9*B,5KO tmp^TTDŽ q)y'qm=䫡zAAVyfvUf<"mϟ\g8)6CU m<ëdSJ %e HfGP}>2({)' <'A+P ٮCuסI74}6]Cg2QO͇;4U-yf=#gZ𤋉I9MZɡ>]W< wbD+eAitوDm5Ea(xjF՛;K V&rPL#H 'iC=&;{k"*ms2g%Ԑk)+$nЗn6IFGI2m$*I#P!ؙH0950b:2܏Z@W\1xدU# Tx1]ph\RGePjkɎAZWh6Ꚋ¬0Ey|;@&agQ,/eR3pN |姑s쯿԰tG9Hm\,|=-svF!$$δz ό|kiX}4+ng;VVDg`i1t`^RR-BR$Ŀ3tNXiɮDy5mE~zXj p\5ͩ<~4A&MƸ"FŢ*ݭ P~ji8o}g0H9Y0WC}nyRM\'SwG-AR] }1jb߀h_FϥPgLieFB8*ոΒL@QK!W.`5B -n=K?m܆bZ*ΨV" Ex)h:?J<۩qJB +ɓ#Bλ0KےFL xґE *|M?c GLA+pPIPyPNȖ-p$XYK(:@toi9yHQnb҅ Wƈ|tW>1U>I?"`{*_bw%k&~`R4/H:Sst5'`%Sv),&io077+C`INQG>.2>+ɷ(FH 79rz2 !'Tԯp:X=>*xVxYM-2 7uV?xxliꁀwӞW5-4b4Qn^j-ISe:q1'sSa* CUܰ (+H\nڻ d޿Ҥ=IS\rO ,}QgNbQ{$Vp~HrZd`! ;T9V߉pz"reUΔ+(d !:9<0CQeS􃦰GdžJ3MN}[iq;̊ `HwP"Ve.&PKv=: @,t fLmB{*@1t Kw*ě1j8 8 NxH9WVaFC&s-To-\*u8* č =J05Jh}z[Lnт1VN vߏ2t,0u,VJ0 i=1K;20}Y;i ҩ8#˚Ye-*'8$yH ܥ9Q0I'd:k^y:Ntؚ=s3_f>޽?ZԙRL|Nʀ7t҄q`oop"ݔ;eW0/>%ULu [-YAC$5={s;mf`33Zs=Osoa OVw"r]2O+_3B^rs]0 ߪ6r>hs Lk^ epv"iS(!X"Jo/pzW%ާLyב*n:zgfS_ţ`S8 Ma!s!.X2l-&WqzA7"%<ÝAMm[)@v1,s.+!iXIP]v dR@G-*J̒%7X%zC7Rtȵ_FUa,, LOp,dwHl-RfD{ayF-ۈmbw Hy)n1k3,QE~x/_?<^ W |58GuC*Jkwp2!2 /bͦO9Xm8P42lLfmpT꛴bQBUZWj%S_dKAږ ;~۝nBQ`:?bR9[,J,ZOke(SrH1LL߬Q*4 { |!3L!z[FTyCQr9K\ f}8\~ 7IY(nR3%A`&C4 [#eSf8P,us0O2OʢfwBu>uowOV$hV4Ca&71^3pXXBڂ?wri?j*"dH/+KϘGW Uva^H6Hn!R= hן6߫(?Q==+\I/O F\m߬paNl|4coo^$y2gofjX-Zɮ 53|tL ~$wves%FDN;:Ar1ě216pLeez c-/ T1zDSaFnpRVgxR;CkVC:e6hBQvүO.1,73p1 (ovq{E@07Ԭ0+6kg/[54E٫T#%k l0T&=L27jZAe.:M4 LUOY;YSE q@ҋrØ ѫb:FsIUq_uCKp398?\b#(7rɮKUȶn>c"3p2ÖmD/!8r3>Zi!cGGQ*݈g37LlhuZ`}Jfi_Gn:=~@a:X*R0Fij= *7ڧא [S؍6xye6xfWM?emtj|*˜*6YL?oXpSßܿv7"+R8mstf RS?U2ܐ̍xZzVAg %(\87: Nin#v՟2_9 @4&ϰ$%%tl:yM#ܢKrJx:]mHY"4Q Բʆ.?x>v ׂ]ƒ&D-mt1PWw.H6l$ZHn>rY+vCBJ\-X wntTPY`B+me;*0J:-6pU6NE@<-9ya4lYL6tv;]| `'5D9D>^6,["k%Ղَuz:Ոwd,@.H{T܀zu {u͟Z#_ /~M-#Y?a)CCˠ"?7,>bRd}ezflNA Hlk5:HyӣgRԾ*"=;g+Q8k"zX{_7kc1.Q Tfoi*FM0-yK-F"apC$scqp^S*+׶DzEc> Y+[޶*֓҈fk:"h7(ndYv1߽vY]hYr団X@8e=5ՕAfl-ޔ**kM:3!G@k$g{(ɒv;CѽCE{BF)YgWKQ/{|jۙY`Z;6HQF 7Y+h H '̎uOPr5jmdԴOgia=s3w$mO$ל&>/;xTKH%zwM-kv>P8"n"e!oG+%> 8_ 1Y pNe|xLmM7eAGDXx@5OGr#oq/WyZ![iS_) 3؝S=w[!JXL6E <sS8t1ǷR r'$t2RK*.H)=b1Avb;Tw\MX {rpAꀚ.4l-0d. 3(i T6EN^7 c(k.,k.Svqn8rCP*J›(ʨ3.ך_F$+j e>:g2BzΜַwXzHy9)O~|kW廿1qBHV\"vhD)ELDGUU&=\TFTҸaNmTD0㘳J 6YR a/tNYWN%)aHJF27/ߘ+Z h&׳5Lʮ\a,[ArH`~Bm93=*e.t4[I9ke2$v _UM@N<tJXtk]w~)k7GM+E('ln̈́]֤@;-|-ΡsyB~ xŞ|sX؏,X*/@h[ѬJKg#@pNXO_/2Xku~Fs` [#@kZ6- dZ 'Jp*"f e2\JU] ,y>6ikB`x@&O\d,! `MFތLHS~sv17d|}dl^#r#hJx .qF2L_VjOYCHt/U>ʤ&8iuUPد t+Vˇ$p@!u-Gnzb2"*_8r@8]D7,2Ok^&8\HhS&NѬLuG1L |nc[L, 'r- `3 `[ '63o6bkj@ (Χ韧ۡ_qAʩ:W)y qUgyH{j-qA6ɝ1lqpʁp {.SnR`opO#/i۰ -2m 3Df9 :aB̷;uNr)Xʀy0Q`ݓwqL۪[?]hsfӨ!Hn T>@a ﳯ]Yy'.L~M_M6 ڌcz./D!Pȩ!jTlx?7!C^"챀Wu8H=GR}cU*%;%JQ*FZY9qz*}T1}6slCsLEP ׺lY7kB3g+V#v"P{HXHl{q*(>suJ퐨0fkPUDUҹ̞v'Ck`KR!|p؅ B9 C}n3_ՏZMk3R=P/*+ZSݭN?ceˏa &EaYJcb +օs[Ą=mlG2p=zp4|4n{k7dkyz=?j1)ٗf-]%\+'kN7ȭ&s\T %!S(#uB3Ƞ,IUވ @.` PDկJOTYzqk7p$MzdrmCX![/-Ra5Toԟ1Ӫg8.M@;sepW!KT30;.K@žz7CnLk pqӴ@o=w:xjI r]aQ3M`QH` Nbk9 ̉et!i{(EbظG딏:?9D]҂wzI|MFb,h`M9Yҧi]xG[j#t6ooMES}DAoW8t>)8^>(õorM*wgsyHo~#K@|}i@g ͅ?Y{DK)gB^Mڜ^`)Ì3/Ɔ{'h׫$p2 'c-o&6`=)Vnʽ3x y,lR0OR,h69~NܠA% {9pg̼Aϼ쬐Bi<]5(|T\S4i_'Nd ke<||hϾJhF A^D'L,ש䖧 OM^'@4ᮻb-m?jv=Q(dTbU١ IHzvq/a60节C*ɨ1)~"cu:w{c =Z÷cd|@T8!aK#t}ݟDYL':?.NH4u4&(ߘH+M%g!/`XHP3t v;n]Oh6aGo{1Ew]PaQ@j/4#Y78J/<4XG`LX3JTCbuHΣ;> !Q?Pe ~nhKȪW-j8y/8TjnOmWo+:IJev(dg+{bj?tn K׊ +fm\i^2(i>{ ?4C `Ȝͼ_y殄NRpڐԭnYL !tоpX)wx86"Ѳ vұ\En(poSV9 LG@}EÉLT4iБ3Ԋ}㛣ݱWtդ }yf^ZޯB.Egت6PXDZ` sy]e;(͢Kc< huϥD`}fAr[G*1 }FoÑSV@Ys+;gw'__*y}d7I*U Hx_FsKsLb5#NY_j%**9$Πg(ZCESJӊZםK@(SBtHΑ䝧f䵵t1`w,'-JхvU=uE[z>0q:.E 7"ȷRg<*tsShrݺ4*-4X]v__P>Ax/p.%]J\XflNXj2;I "629eX c4Єf7 mLJV:- fdɾ%xt Ĩ䑗mjvzhO6',?ug63d4Y5=m'W)RXSOq -[ SDTm(9/ H$.KH  coƮh>bBD 4 "%-zʵ-8 Ȟ}5PHGZUQ {fd;+cK)ӿk,E^h,[zwb},{oҒ Z=lS'9Q&: Ss(ׇgGj7 Jm^T7V;$in:)X '.0VJ2N/Px_ ĝ"]u6h7OY!',?v;~BzP/ݎBþa<@Asa9ܺ`}O&3}\y`{aI-ߊcbtMq,K.f724=Q`wGV0z4c~|$m F Q(+!&&M #t4nc9zjz(6ͬwYA@,&e~s?ρGspj^y]ڨ'+;dl 2sY$2S})"4I ):w"&#R9Qx~+2?Da1$.B}'ߢ aQosJ pяR g$tH䛜 Qu_fE'2;ȴϠH=3 +` ~k^xR^)K}S]VuzԼRњ yh!W+.xd: ɣcx.&ܠ|wW֖AߡsĪeҀ >jقcXO-$&Kԃjy,>C^,tx!`g/+n a4`}zlɔsvlqy&ߑObWE˃BOOt:y׵xTSA.ѿ lD/9$ W`ք`-()=TٽDK:u`COt^KVԨȟ|L }%^FO/bp^Lq%:V*QW2U=H;:TBohzPO\7*ryelk ?o |L1.~QC&w;E~`-܅NYc&Ȍ^7gmCg/i9eYv,$~bŔiȚ!^Q6Wz`M3ﳟ,m!AKD1G7)r1W2YBk7Ew~zH$`hlrCǎ)ԽK5 lg# 84$F #Ur? r0Q(73b~Nw؇:*x{"= ޱ]ZYգ^#8g::G b"raM|LIe>! x ?Xw)~i! *&q-&35}D Ek-f)BڑrpxfU-5FU3**FTբ'h`nPtIX#v>v>H9JUIn 3[$Md?I%8hS>\S0\hHql lل3ώN=,FɔN9Te@[b4AH$%AX-Z=:׊܎ܶt~#O@{+ۜMtXL$Z ݬ,;[dB@2-KѴn`_g>yK眆nԥcçv.h3I5n<`X5tv~oޟ?tqBw:iqaI3ء {`D8Nޡ0CXRp}͗\ .fIR [3? E(mEWa^֓GW62ab"pmG/ ğ EƗJWy/eF@1+~)@O|ĉ5u0 S ySdL@t.v|9o9b|s3Q.]8ݹь+;Z*UAiZ>?)StM&iB=+܆%$HF֏w(kŮح},?')?'-$ANx ?*0_B"9ڮK]t2X!&^ΚVJB!|*) Icyȝ$r1%y<%.ލ EfV }\g#CR;Oo֒ ϡ_FT/?Ffb:fOb[q`6<,;\C q'm)vaKO` %Fڻu)e}vZCL"U-G Ӝﻚ6U]oQQ>MER5 ѭǨ'I0.`q|M=?̉$N(\ l3QzRi7wK,&m>6@`NhH8X))L̢V"ҋ:.|pi['*tV=3zylN߷:(DC*3#mk ʾ$h:AԶio3} +0=ʱfwc +\= նH_ԥCJz=Jx[}\AUV'1Iᄁ{N~s]H>}v" I4{\3鬘A%{K5|A){lIwَNiल6P#,SȈDPNTm=syezu;&#uُ0@_d`uȃz2ؾ57 I*3j}E/⫴òn?%kjdD:5kzNxn' GkBJQnz/֏g9w4/HZOBTBiaQW +T*TFӃd'2$A87e}dꤼնݮ^nY2!E)/(.G봷ՅPReW+̦HWi&dI_vIȳɏF U=*Mjy%: G w:i7.Y:Z7F{V[;! ^Ol Чy"z>s|뎼H|{pivnz/3%|uaҽ,ë|-0#*MVxh@~{Rj '>s3+]߫hMpAVՇ($Ng5]օ%| wTZV)9Rݷm|l=G˯ƉȽ7!8`@Lz"!=8zhm?xI SfO8`Em(dQk܄9@p:j,#&!-s Gc@tYww EGkbuO޶Z$Ou +4u!#Y1kq|U7[ɢr]d׍x̜lW(_v=npUGS\T.hbŏ?gAZ7qY: ÷Pg6 }l&ý((< Hd2:\i{m1#FIZOFh.] X9 wE;VS׫5!נROuJ`5 7MĥFr&,m!&hJf,k=_Jl`e;O8)QeqjįQQU$DTWZ|Q僮G΀SmDyܮ.:41l~1%yY6%c(EQ2VAuhD 5NJ|*ẃɌGB^ _3tYGDM9תFBa&_k Å:j Z%s㝮QC({4J1}b8Q\,^,rZ~qڋ SRgn&$c#6P屗5>g )̆ڸN@ %x[0n\WCbmXd :*(ato! IY\ޡ;Me|ĚbznNZUL֯.d!3m-ME * ;r2 On"y2JZXa* @p1gr9N|A6WͯFyH["FEQ( #0qp`|@1,1_`=Pu`"`4&  V|YЪCW '4,&÷Y}'˒;e nM-f9`\=X,(XKֻ1q KQ]x!Ѯ_/n!x[yVm* NV W4y~;SeN[(&?''\ZZ-+pFA y:ud$<T[C?ɊH/NvnugN66pki%-BT3 b3ʁkZmŃöHx˞aLը\ YLk 6TIz* /^T'o ͻ∢B"؜R(M8HϮn;Ѱ `h^`xK q~3i8,/ExkjrdڙCZzz3i&7kU(9,Kbw?F6}FUҔh#ԃ0^G' o-NގVxPѢH5No=f/VYrWh }GJig%Š'6BGZ(ќ%b]v7vYkZm ĕűnHg ;ޖqo5ڄ-LwkrxhGб)YxV\m(?`/K`B]oO'T\БAk +wfB&˅9Q ?Eː7Ҁ? !{?a$:f"pb_]<~rqms>p{ēC,㱻,գ`WS-*l9!ym86DTRWԶ#?H (ɜA5KdR'.0xw$ƶW .A4jrzrDPKB?ܮp돺 H{A_52eXm¤4JsiJ`F~+]!Xy_a)L68gƒ.+>D 7) ;ӟ7zk""Mnjfe6@=5"D(u7vcZGsٕy&4M[{3lD֚Yn ?_E{Yqco;5SB{^ `[`K ⓬`AZ&hl&PE_(dS,g[ < e{q2envZi}t?xwN 33SDCeNHǻD}ةۼ @$ ˔Bݑ9Osg$,uy&@oVO7 Z`e `6U(=ѩ!֝Ntau1[SZeh6FY$~p:t,Z2aY.EcAџնK;'@i{y*?hj ws|A_4nD~U& t@%~?+k,rوgr\LȄb?0,[%0eܵJxzr)jD:3ɣ|jOEI80:7X €Oenk>uXZnvӻ4SN\thxRFlFCS~ b B_{z:9A#厘'4-Tn<^5)gq`; }Vw= fdu5j1NNп0ď+t(މp1 <̲pCMڧ=lE!l^KoC\xnELh8~w?I(}BOLG $+ÊV+=ԜqJ{KUhzs qMB\:J5T_Ii@ CE/W+豽_) W bD 4[b |3 M6C2$83.2K.Bz~1!g":-3GlE9v”T#ߣU{O e,R #U&ɩ X1QCfF޵URC4JИ-RP$',mp.~5YzC":;{7ǰXд2+([nA&1X@HZ߷Op7&b "OZadeukMC1هoۙ~\q=W'ޤS$){zR\a*a?TY1<*?S.,$v2_IӊcE$*C4O\ʾ!Ucu{jP<=Y< QBD$}'N fR qu/FAS0ռ򚇍; ])܇gַͼsU+f5պZ/r d<G s\,Bb$C&gyy٥jPi?& j]<ʾRes858rҌžj[iҎ0ZĈx~6ز.@Z*Np8qxtR͚%Mkd :UHi:UȰ kj9ew$p?Udj%yl9{4,#V5H囀-xUe^Y|3p*tbo(a;=!9P[fԍ R}0~Ju늨w/'!(3_JiHװp2jL?0]?R4 @7m`T%'NDMYWM_,+g0v̶$dErdGHt{gXEY|,$[e_-y*sg8dr EwdkT;28ׇ_p+7§jX h fq DՄnw wB7bmt!ԯ?9xG ՍcvM4aS" 6Ŏe!vony,?(D^neI-7 ׍RV 9:;rt0U&ǛqH>ZL{Qn;Gu7ؒT-T gG׵ ׮S1ZFnjYKƀ5`?;XEWxtl1n1a)}ۜ-YF⢻I%jmºI?=\u"Էp&N9X QɖR͛q)󔭡Ӂ58_1֖1E{elABR=௉VJ,FV{@s8yhf?v ΖGv]gFlf蹜{fo naNiג[aH%nNHv~1~CK`ARM!ECIaB9@p; "DPC_kFq@2cd9min\i(G{MM@G^` ~͌; ةmmeY>- ,ҳ$X gux'&R z.9"ˌ{g+shTL+xSs!?T\gi yPCc}(|I*BL9^ޫ;|ضVj=~/itZj\zgݰN0V{g)4vrB@ _tΧ.siM '6^](P>w}i {%>?D Z&.@H7L6DißƵX)& y,$Bk$Bj>OTL4KdveV7PL|F#RO?[^PK܅d@h gun)7B{kgc6cRw&J@^jʄY*|s+,g0=劈 EMe[d0q&䠾[/в۠a:6֩usdN|OCk49_k 7y]ஞ*BVTj;Hg c8RZې3T 8 cȅ^ `d2pݹ"HaI^g;UJ+;&>k*EiAk FI/|" kWy+p^]5+xr!Sѝk'"iD̖δρ )`zoڔ.;'qr+v8h&!b# L ggS4Ƃ)t!:^M \ DQ* wuzIڲZr5'2%܈Ts%P7~dQ~7C5?jS^Sׁw7n gF<<`h=fviR @CCg| K%<3M\k~ꑁS霻_vN#U^~ӟBgRxOۈoz"?+V3}}R`ly=$\~řlG|nPqOvE N_S?s]j\@}4C_Ka,%NBlxԱg2Nk1ܓP%堥==6FK+qv17oIl,fM~;7;Aq)õ/! τSRQqLt65 J;<I6")VB;0KЇb;M̟B8ԿP:z *?/>V:x! Ѵ 4ٟJ% 9yoi#I >rrvQ0N(;Idťl  s="vɞE'31 .cmvi᭺ (ygH<<[4΁4Z1Y6I)@O𖵁'y^¬2E[7=X~RG'07/":kҜ%8Ձo| Ԣy.<8_M2r3 7dQL|TsgVyD;B\f!4v )7X2.eجIQ'"MǏJ[79.gp~'.RFޙ> $$OVA#I< $/`&khj[ser>@M_. KJnXQ V FkΠ&A/hMhRvQgĐmeSܨ1h=ydN >;>p>-0ȥyq#4;;׿W˹fk))*YNEX萧E'" :יL6pͩ}WF Yx!qb^:?2a:d%H  ~Չ4]Tw>*!>]pS;/#t7,|Hl_{U b {$l-@a\>Rx.Xlz(kM]霎|9QzdP~J j(P$i:7_d7+LW`ŴS O dKM6fB5v GW{.+r:[k{CC>&g}9+d!-Ļg 7-mo_Km`Mǡݿ`aA հ8XCOT8!)M >́#v,.bnX:]v=?q3|BKqERS=Ӻִ0W5 Xe5(v )3K~L-ލ~$E!<QBhbѽ3qO:| D.qWGvt9-j(/k9.!YG; !r4=JcC9_%d48l8*"'sTZލ55b^,U9r`g.kCFc8*X pW]1r>>ˈΟ0g 5nB.&upAJqS a@Y:%5ԖY(m]>+Syt`3qwJ'#ݐR}k Sɚ}GF,Hnzva^yA/COe4Yp(ZEc6hiLVfkWQֻ88(b0[!/I WOx}&K3mQmc{ A렔CHY%bEbQb0v2:^< %igJ{=Č;ܕ)-tbqw?vGAbn(]ظ5Pk+1!l<>%;0|.}ؖ$6bxGx&GG!NrXvZFeZ,0uB-uML* 0GOzcmwLwݾl'(up>l5)1 xC愒`[idO=Ŭ^r4:Y9{Aгژ}Ćy)m`EsIx/ 8<@5)#~IkEf@c 4pv }~zd̠%/ǧ=`ٗKS,+7dTp3Mp=[#EP\mw=OX)MC \D߆#~SSC@B.Eq+Y(]?FJrɍ&Z4[$5'L*^|iʏynt-[dhDe,}2 2c@=jJAYL9<3{Z( WrbRl=ʝ*:o@i5fT eQ BZ^ f@*gj++%Q: Z;Qw,G}&hfn&[mm\e!u)pmR_WNl< IؾfƱDXЧ<|QJҴgdCY }Y[qlSCi>AB="Y :{r% YTfD٠Md"gҪ rT7BG eGm0l(%ϊYȡ"Dlun[ua@S!]ad9A3F( ^Rc}(bS;%9qϘ,4~[^;0D`žyhM>iR@~N-gd.[lzXOQ`X0ۡdv;Hv@{*>^1gz'a*[N|@n wy F8M`]1;ߵɩ$ĻU͢dgΌ.[F?(in8-wVɹ}gDr{pzkd cVSž@6D0o$'C^ 4T-}"QaJ\ffg~X1.R>ִyoxe?J_!q*'% 0` )^|xs1h 0VI]'BR4>ZL=N+XHM.ߗ)>Vcj`ځg,˜78+a"]末E Y0ftT6M"C~"f>1og𚿼osLF`LQ`ow:OgX$Bޖk9}2B@MMtT|ovJu;6E&MꍧX @%E%ju@l'_ƪ\9}v7as2?;EL˜ ՞tQDs4Xu^t%HS`UX^ t5<~#_[?ݲTrZZO4-ޞ)"_`rm (#2[i7?K6}e _S&Ɵ=\Lt{Up`'~|84edccpZ]2%y5kb1F:2")h/|OoYþxMqņdUAxXuHgqL I=vh5LYۓqz{:L ,lRg.p19}h#hu):vQ283_.AJ Sjc]9y ]4&*.n°uܤ ɦn_Zpo;f|[#}}^D֌B,ye k1suS +FOɪJ-|MC,"XF^z>KYpHG&.`DbcT57=SM҃]Jt<-#h1cflO-v[pFCueңFU`lntafuzqyEo]=7L O3Ic^cG)lK$h'^ @V`o6ˎp}8 /Iw`$#zh) SRS`bc)b6Ԕ,wˇ4| ܣۿlY0w^j+]~У+/lG09l1?"* D\&Zuu[}RqL&[!;Z\[h/tt|;&^pTFy  !4xj&PWsW5ۘ~+{hf}!`̘ᓲlKm1RuINOTETN?~~LE(EɎM}M%Wqu0kƱ'Fʹ#a Tk"ALc"we^g$%aX/ʁ~@aЁw > aI @0SdS$Ѩ@\Q Ĺ(J5aDIj(6Tlw탰n #l \uI~\_̩VAtebj%[h;:\z؈Ek=q@~}q$㪗!q~KA0Ȃe՛mU]J3R4["x8Tn4D5iI-Le25⵱LfiAr> z<2~_v@ [<ӱ.]go^I+k\{t(?(Ϻc4bjNXay2%To caB]wØh8}1U׏;2r;sgeg=k}eqFƺQ1 zHçY!96{dsx rh:+ɮqd12ea8D4OaD~!U? bE"$w9Ҥ]EOC{,$NOJTHf֕LA x[u=VjofvUҾa_'zyh3V-=Gd ' 􁎰^wZGκS6F8;E\/}^0XyQI"Μg)fU*oM+15_-8 T'wPp˙U*H |RE[8ZߍIAJF .hŭrU!tE,'[n;W։ol:c vD\ M1D+]曖,m- ˨òrꥼ@wLYfŝC B j"]p81]Zsy!'Ǯq Uf QWogFMa5j WTN= E)('7!a "^ӜS&//VmfjY ?Ff0EdSPX$,ֲc*Ԟ&4вVᢝU0,irU^Gi$#4e#~3_r%  *о԰>v!O&N:j\<+ zpnCmACb8gar Rk j$]睿Vճ^ F x1;~dt o=d;T$$pxR16ַ@M 8)Չ=J3OC~Jdʘ}e {h1%^Ò&vq⮕&fi9)b㼏No-`* t9|w ,9n-xkM [S7*uS3~{[l%۲("(7y+N%_֡irn<08V՞;NfxϽk0D(WXZn;(a8p2κ(rl0)"$V2ϰnjY+ŠCA4ep-<2x&/MQM'kWvY 'ر?l3%z !ȼ;NشĥF2cBe,gGF g0+sm-_UmȞdE[|cemWr8&3D '1<^epx| '4C/xAdYE?LQ#-Cx2{n4GiD<V>.9:먵VfORFO~wgm$.Sc"4g6TLs^cg5Gys<ˉPz( .ӓe0rjGsV *Q]9v\fШtNo\zD4flVːV~=Q'qЇtSjE4O#;@0wܫ`pZ<@.(^8G&%b9HO zKag!ECCѡY0 $ 'HP,%i}Ջ&Q#X+MP.c|+Q6 }]9MP>]8_eWW5%G7_TF8ىW ;۴%>w~M$П gOPUh,>Onbv.q4t>:TjsA2:k*Ȕ7L{ZOj:sO]180.]k9D" JFL`cBHɻDntn&>`M4D3(H(/+"S'?!8Op|W+~t>22`L? l;0{=W{hTl'[\K !$CǴÏ*r 66WwCS\ KxQLjXx~QuʌQ/^G} &'6Ryt^LJ}'^a?l> exى&πWok;YTR~3l }._:9Q&t/vtM1Zڳ?i8T;Hso!S[D2#̟1p3ߺ84m;f"\G-PSͭhq RRjF4Ŏ ͮɪm1"!-KnU_vc} duDFdqLwzz5 HķǍ!ć OԊ-u΄>qc.b+芉1LV>6|2?Wa t yʪt /U.O3h ~IC?h#gbOK[p*;T{|JOr OS0~?ofG4t-覆+s0 =rqq-nM);I:c)rN:eju4|6uvHv8bنl"aaK9jn/ [v%Mx% ȇjfAd.iDxOsf:x C.4'Dj'lx˅tY ᝹Y~+<:+0TZ2X{hJvދxXhgoܨӈ3x@p***\oP|Qbx.dN٣a5N*NB=B5dq,MڡzB/%C ܱC._L@e5 z( WUn4 蛳!Rǯ_K)y$fP+=AŶR3 M5WgygЦjpZTKLWqd}2ۤ#SSͦ֋N ~Ƈ5gL^vOb? paN&l/&12w/޴Xb49PS%_m\$}s/Za$Y#H5Y dQ|wT]< L,O= ݈L_kZ Gx&STd,R8##\24 u{8UbǼF@qWx{MD$?+,x@H e Dz&b8Lۮ44p/6N|n{Y_y]ȹe0 ?S`ף9XjNNb^qan/kqQb~O?V_°<; 6=)R- .Bftq>Cu[')-;hmY⺭R[֬"<(-Z!h}wb4iIL,jAtZ]{0N>O %yZiqb5ϩJ%x?'5{XNQׇ.P{SNA[6 r{Ib'no&A!VVϲLTrac_\ :SriY'Z?+, )d/k;1Ljsq n晌 "$= GV*۬'M#(&|L&zpan|*>Y=+k´ NHn|Nh04Z5gę3Q Xhקl ݋4wAF9ޒ)Cw}9ӛ0N@`Is4ĕVA)^.t19)y%t٭+6~ۣYKfĂw%Ɇ)y".`=al[?'ˏ9c_ 9=#&&ma 燨Wޥ@^4a4F$UҙGt*EA 3hܞq#ց q%j~V!:V76xW$RtTA?^rR{o*qauNy]ZV! 4}hJP/7Nju!>DBL]S?L{@XG~vSW<Ö;zluǏFs21xc]O,/3i$A}4(r Xg' |@}: \hUrEd('&bn千G3rsr,2ԗpE+{KM,&Uh@8l^v> b(jNl} 4|R[x{M?\5X\J~DWMEYjB[+ ̯ɨ j9҉=6FWtsC> ٝw~^L4Xd bE|i~u=B@Mw*@JCsGn/n| F 0ЂvpJR޺Gm@ߩo Q~)I~}J9?S"IeM\;geB~L'\9C5-C rN)[M5ƟiIBFdo#qcEa&Qd ?ƻ%=/9(! WO rnPr?<]H =c]~CH[ҭI\/D#5!N%~9Z0Id!#>Ѱ<,F*Lyk>i5s~$1@NBzŦ^p$zNW A|sHk, 0O .,BHgo|CuMzK*fHjtᥒ5 CcQ+ !1-\a>}V|\%r .ژ3R)4I:pRLN ӒesgabiP)|`G\ظ٧tC:~dL9Ɉ)f`^$?Ìmh+;QRǙN#DL5] 518][ JE{qhf5K3ԺIfL[BWsKu`pXwyc@V7[r9q?Fl{.3'1 E5]G s"L:K{L蟰6>̑Aq{ae7` .6#unJ;|Cz-T(Qj8]HC/Y՛K2ee.k.E׹>=͋E;ɼNځcNP!k/F+29VBh[ޛ|.c闒WLH$s.x_3q:79I`)lJVLtU1"Vp2*FPN#$D$MXbl4WYY_U"#U.nGk(^/(Pp#?u -[Dߕ6r Nqbh>*1qLι=:!ćQaD7ear5_'ur=`RvʯH[J+N7#wܿT]mcwd%ly2߫vE뙱N]MKG@.w) +'`=9t봑m+O1,I.̋+8^%~N4-GRhjO[t蛯$MTҗq67;Ɛ 7Ypp`:˵%Zc*| %n;}֛X9ԻQ#9)B#o вYyum<;m4H J;@+m_̨ܱ_?q "/+-e`κTi[ݑ;<w,2)c$/0KWÉHg68]Z)8A^p3Qڔ{M Pc̋F_8c#fs_ڊH4EaD83B3;K`&8V ?k/V*gAMuy<^LHƖ &ƖJfWA-\-^{ptp ,W!#7m,XJ\LdeiהߢS5G@D6'гW"v{᪝Ǘ/Cu:h6 !WHhYg#x 3f^څ 6`qO( e,1bR&H [r=`!j2!xgVTڐ3@4 p8/n5ZQ2m?^X%/F; VyȎ6rեȢqPZ!YYNِfhM}uhT1V8;3[u_^Xp烌G!&?8A<]?EXRhfktgl==:3Kwٞkm6"]6*cq^\Մ""6'f̫Dy8, #1aOdOLe!i1[r=i`~CMë|wEnqT!/E& ya1ǙeT0'.1E`dk*F;>i=w]@z"! )H)@N˰- ş9Ηe'oGE)]t8rי0-r |6y充GzҒ%=bDaY4{,$5sf2 ߩ%0ufXU+rqᮗ6e_ p-ñ Ӝ֊uO=;lh)PfKc77gH4&qܩ \M^aq(]4K4bW} "-n v7ϩ#ym}{;V, rQ৆fW|uC.lA߬p_Cln)qJeʂŕCPVD9ěam1zӨ?ۑ6ǢD"DD~]]i" yzLOeczLڥB[^`3PbHSe)M!% h`\9`ݯnQdjZɀ2]Q>(II K|jbbUnS.|߻.Q9!+:wd>`;T-.;l SSdKx9 %Derq1'0I7ėVԵABd_NiS$/D) JvM䁢*D@Y#vr00\gV'??:{ {Al G"nr"hVPH>={D`&tdg'On[,tA[&I 9b){3 _|7~:\GwwX-!bYpT]yP44lRY\BcʙPjwDDq6ml?Hh*eߴⓗPˣ')`? @f>FcSO1kT> & V]*{N+ Ͷ+m#!f`iN2SE% +:ɀ~hc3Vҧ X}!ۘmw¦fO+u oZ-}ϨET%TY E>dU$FSKw:v+f.Ls{Wp>E^2ԯ,)0`m(G.Naa: s8!\MQ3|c>1,nZ[ZV>k2$zYmk dA5 ?6Z׺!"1:uHB(Ҏ># m؊:]j5g4O=_1\ Ql Z:ArF6(iL|e?KS_C"rϿ:^XFG␰^~)a06Cs\\oe@ 3{A~X̋B5AWDL/3.psm-D Zq9OW\<^00>9+. [G-UI!L!SPlUt^lۼjx#׽_pі4_QLK Ek XB(B R"7g]L&BV `c 8|;t6̣zS VVŰϓoˠBG*44~اu2gw( DYmZ+nĺö7m$#mljvKcQ XA^1Q֒<Ùs9MsaŵalHZEy,CJ7IƨMgr:X - ~e>qPpWDBN1N>.+-(+ApIO ;7lDu <#M&D~ <0}5⎣\FbJg'T'c(G$- x͵p|` f&H|(}rOBy&HoR蠹P|m'>1KxSNMWNiWIC1ГEޝ&kO C[e>fFrbc#Q )j@+V8(F6Nz$yk1fwZ#&"m$\]iga0џőOD >brmg'$RhYX-V]Z"Yq:?B5V3[ᶟya>p]+(Iiibø9mpx?πuR1SY29fNbK9l=vKQWT*p{R'd+6>&p,Z4CEc~ˡ.kKnm">Կ@IkQɉ 8:Vji.ݞs/?c|&h_ U_ϪA)\Iv,ɦ6SxzR5eza_(\Ȗft`r,3oKSXVnw&gGJt ((;S0ZH-(l=^#--مR6;Q(8GOipZ\8N^uE[M!p6\D23{'8vK7d@bE6~OZw/P1 v!II8߲jVxyT4ˬ?^@`D(k(<,k0 Àp:vXGfdT0:Vw`uIBnmᦑE."3G^`VjW A_ cWPwEܞ * 1cJ_r"WEw[]fY_HIKE9:AKp̑U:5GlbBek sSl_'F8b5(j>I%xW X2e)9ZgFd"HK{p - ݎI~˫O2v F&69cQ8B΍lɂ~sO)16x$@_ޑ*sZtlnJTHx]ja`B29h}}]Í~{0kXRX@tQ]ЍݎcinADys-,1}/0 j!>\R3=z8V>ڱ堉MNe,*8.$ $'/pwX k?ۥtoHy4`MʽeÏX-~K.y(Ї{T 4F. Ica,vN9S;$D*|ieF±A$ }W#_U8J QĺjEƳ)'\iH(L!ĞCP]|Znb4m3^`XKQƾGKbtg*f6\ZE. ! %\̩K,gh&%N_ K=1j+=kq"CWc(bʍzH/Nȼb'#p=!rgǓwv9Oc~$IY˵8A|kv;60WNEtPr 5H3C| fVf]dcVӺ^͕C`%1:5v\p|iU'o7E{WW*@c,Ǧ?Ux2#{M*e(TnYuʀn"{x{yrbFy4'M;%; /%q'o n7EK._bgT(K+ W ZRGDmwzv#b@I[ÚYmm]i|%չKh)߻%LeewX‰ވg d$nNr HҘ,[# xT [*عrX*QTegE2J(65` Nt Нy (DkU}F@+I_p-":b.O:59ƈF ]fofacv3neu1yD8~n!ʭyae8i|L 𳍋f˯, Z'${SSJtQ_VA]d<V$= 05[ʮ:ђ[^-+P`\3mρ'k "R[@i☽uߞk/aPs >! Vb% B:&fBJt52Љh퐺Q{<4 I{5)ᬘ~>q&GүկwzF55nx*lrD U.)rUD ޡ冂qHچ^' -nF ) *f)CG"uqX[􆴶*-Ͼri:b.P~59=Ċ3~J]t>$i@ /}a]CCke§ bħE/!'Ʃϖ.JEo:_:Lߴ啾[c *lm9{TK5ձ3등_"">}X@d_iYu~#١OC(1eAb׌_wCZr&EYE(yV 6 K`& p>KƭRWZ8øVH[UhtLz-7LrJk1DȖzSXTϒrr/RNaF{lO*vr0d-| u D-b_Ѣ5,KS]",&,@D8KemW/KO]vH.&;EjU@`aFs^{gG,鞔 1AsmY2W(YEBO싎;39Nkd`-/fzk%Asz/ƚFbX)qH62VQO@0@}Sa/Iؘ:X`&;йmS XYyڢqI_ $m -"k 8\'+`lf++*TBë~?UgI5[5>+dSN r HeRHH4Q!2Ȥ 6VJ&Q2v#;0 dkĖL<"/m Y&eb8- ȷ6"dE";j y T?2r\bM^pkX4+wwdNc?z7"1J4,>Ħp1δæL;LhkG Z)+H/ܣ+>`Q$=DqAv<D<&BԯL3Y5h;ύxBS PJ7#YѤPc2,G<)C}M/5U.@G nBe7#: $^1,Tlld2T l=M lql3LgBָ !:DO.Oݰ,瞴֑WX?l8&47Ҏk@ܬƒN|j\N泥 Ao! Qm'fY9l7}["'LV7W(mKb!ime-dP7zw37O)d?0[gc}~ D`1-{`P,CQ¼ć8hGsecY09ez *f-練dH?͙mL[]x*hykkP#q}l Oa\*/Y͐<^oNG;9BhYW}rNx:$n0l/qY\n-Ef303x<5` t"7\k#E~@m1_WS8leS3v_N=̓#TXSV&} Inm\"6ǁ@~o+ ~™Єx`5wpcU'ޭٗ)wï3P؂~X0m 4bɁ 'gӃ؊ayxCs,D*Dkxg^J籒=1:cf/ڏx\mngXc_ֻpFy;1z;OՕ^Ŧ?*9ۋ췤P8[r͎sm+Yx_V̈́!G^~a7KQ_ abhSh?(u5*[9jcs&D}?F^,  BȢTLKZuqԁ#o1 syCfszrRFhT׀t\[3Jm ;Z)Wp_fYO$.tlD*C{ KsʮQcW0 :#&ퟗ1q0oF画44&Dj]@t`nMsv@/ƞ~[شH.ܿ]֐X\On0p0G?ӡV`uđ,rc5?NQtRbC(')+"yY ~v;>S[̥q^U>5[K%咝[K V]CZ6L;Ajx:GxrIliv*rkho:؟{7w͟vUnZ4þBo1 |`m^* *3-}N>*Mh+"H6bnRsl [ѴQ캳02V]ik|<Z8~v,K@AgkEt2[w3Pt .,)EN͘zTL*MNPAtPڵI*Zv1g6؀=cʑ '/[p0ٍ_kť(c=$J_r)GQD |}qe.B` u%/ ="uUGUA%ww_J f~Ksmv2$^*=]]t˟t{^gNjdw!=ꞩӛRCzHyІqe7!u6`?Բw9$acc1;A@ޓ x7׉WÓ hlۆ0 Ċ^w׫\hT|Z3o2eijRu1OdV d,a k:(2K?i,SQ=N0k+9L):CݏzJ'2f:{0]ÑsDRYA:bIu,Rl$,XWbY/׌@5Ւf']$Hp&%d_˙]^Qĉ=X7OdSd1SyW-ophǝarsX 0'ْ$1'uu hrg2GJS'֋ft#Z['O4zN%Ft3ەy,xw)LNTo5YuAiӥMzór{J,cxo1>ҷqG3aj% ?MN<CXrԋ0;:FF JT[; OsA (꾑Xm})=M;nf\Z)!(SB,jU6u&i|Ģ_mkY8]n&'or; `e-A'0˲׹-t=ppKuLD5{RlOv%yVvm!*fs*z 1?`bHk ,QȐwz_8l8ۯ7gQ`IYF7 v ,e T\m=1Ø$_|jЄʞSMX'lħŒGe,A;YCO ܫaĄeB.1\;C5&r*&9#U c3!.mZǂBA 9b,ІxtRMߎ|K顀<5D'oH~m\/_Cq9(eZkzjbo˺JY 坨vF☖[RJ;oc \{B&LDzۀYKh|څ VZ @5%͒ &_,{+yҁ]:v@6{ r>q#$gq8)PV#C_Fo>JE3Pw|2`ig@Bq0{,0"Ash+Y@f`z7s$XjO] qb ΏRzm)YDqA/)xJm3ru.%Q4D9糜!MVcz@ (ȉеڄ]n{2aZ'^[Q 7OJ|i6{`eckg:%jQ`\E зXkՆj} dtJen亍~VfY/@^{X`sMiO&@)^6%O᧗a/I'tJUBi7Pv#{af3nO?/VLgYH$̮JԘ8!oviXz_7]Ahft^ә%fDCifSH5 ʖxMX3  >c7k3凿ѓAptQ(w0vK͏{@h@4sNZyW^w`%b=^G*˜#ƭ^ivYPă GfF4KW` z M+7,ٳK5C8L12s|Ty)1?lκr=ԟ _G@z9&"XN1&rtvQa1 pٙVԘ41QS+R_~ b`io Ch{akAD4W t2VaZXE׌8m~]T]a2j\)I`G#%l 9W+芵_,/@OD6ɆZ "6 &\ַhmLO{lb!džS~Ok(R<<չ*$5KE1rO-F1N؅dm* GbTබm0Pk俹tL8Kƽ*^.DK 2ljj8Ŷc-yJT Ϣ"HO jԖyS1Ihxrxފ>Sܔ\7BYd'_@mn+Wm2в4 wvt6*5v\[jY䚽2Fɗ`@q#`@g:F 7Lj$;s=EVՆӈ}C}d9UM%B )rN)`(~EbNX&ogjo`[qzР,al_ޚ T:Co2Fv7h M@4_nLc˶M6/ny~߆_׋T01hzIpLVw36pufG0F*Y݉^) < y hݧ+rfx.kBK= u;c R*4H"z;'Cʱ?Wl[_j"c6p5& *;Ĥ~thlQ/qE6Aj{6%od(bP2ÐJцl=Y׉u}:3¸Wn3ț$bA\Vp+J; gn@ @Cpd|ukK 7{,dEZ/0?TabdGSӸt+OQ;|7_R/vFj )mi-PRJtw!*;D$ٍ>-#A? *֟yKc rNeS[94>ᔁJ&KuBUIGExxi(Xic1l&?KijQ-m{&, :IIݳ4sj?<8MU[?u?zi?̘cɢY)auV ><}_62BfbhB54pc&`xI,j[]-0H4:W ޲洭jaGC%.7eLlĆA'ms: O!|;{: U춿X! sD&hKkXň)+eJjV*qüZn.͙E] G|kIlC{NA%A#&E#U_ցiEqcV2V+̇8=NՂUʂwuXm; 6ۚ{eFn8:6rzdZ1,Ga4G#trf7>#&]IE)MaWԚoPcw>A2uޛXD)HMUKq:{6hoo?#R7R5AIDRjU?bWr,ZdhBud+FbzxE ̜p]khΚE&Aٓ ƀmc ZA {o{Gz;'V \s@Q.;${#RRPBvf)Lay) C\s q.v<`2ZE''^QΜ:L֞|9t³'teqd.e[SEQˍb+6^Do,{ }VѓLSҞmƥn#m,mPn|:p sCYʂ̵lMv3 GеR3]"{nX.Li$eP$?d]pEg!ͺ!)U(w4=g-X- Yņ~ ʇP=׈7CbדgcC#;sp)+y` ?Iudw8ה:{.253IE-E?6/q#uqi~zL)lEvt>6 sR3AЍB7q(E/jCa д)=M#=BHc3{b0\hºE%aZquڜr{j񘵺Q̈q2̄4ιIL5s&}4f ),v8: HyWdZR*xwd[Z_Hq,$#[cب[TR YLo\h?]yB uC`|g5SVSwT_+Hcb 7rzu:mD-&O D0VZ XqWk:< G}`cջLAVJ|̔,@Nֆ"wɷ.nC9Z"=iۈW|J'{ `>#; A:q_%M]!JL}|E(""H:Zanՙ8(:~٠S:&˯b\ TI>q:ʢŰ7UMhĸ5xPgxױeU2],h;xq9ZE7tDnLqLrif=8Wxoi_aJZg@]:e{áff''ȥ Jҽ_',]:)f2rv9ԝT󃣆?ssV;#zzX1atٟ!BFmy5cF+}U9j2%kjnx}H:bN!0_) ktB_sHYfzIX~){?+>$aOY8g]D7ɗz9τ{c"Z?A>TG oLi@:dTƳ! '2GD\?k^e֖/n] *i3ΨME ""|z6 ja@&/[ )djINULF|iR,j}(xԗO'4iA1w(@>TlĹlH.Vk Z + ૸O{ߕu:3jOl* QNi.fq$Ή0 v ʈ&^Dq p`A󶼮w(ۘ&Z1ތR k"~jÔ#n[)RR_F(a@q/V57$A">=`0b8)?W0LE}ylf !QTdxkxqRyGЕc##Oa8 qZҌ}j,Y<IMdkJ!R6"^qv\XS \4"'gWd;?Yɸ~G>5ájsQ)K7auV6֡yhB/ eza 4\K"@^>9;Z<޽2 $~dM_Wʫ9J[#ɍ'<ϮfI4NͼK J6]VQs<&qZH0m3*1.g 9ȃnlIDT5_Wc%rxսQ+X㲕 }zgK0 p ɁWd$>SJɖonb<1P`dNe?}. |k /:~mktJ1ȁpł?O5Z eg|̍)C 7:(_~-.6, ̓sIN^loۺSUKuD)Iٲ gRIdzfgʮs},s4ͶfwL:'‹XYwS, }/r5oq}c̏\B:P3⒀{M*m }5蟂b~?y;0%nDfts~5 1;+ :Zk_Vѷ1}܎Ǭ!A8!)'"7@Y=fr6alQE7VE!J݂RN(DzZz^o5htu5͊p-:8-:Ѕ!>BYArDRm>$g;դyK> y$2b&&NMnNH;PV@5G94PZ2oNeT} :f6[nݜXchRֱ^` R䀳{|OANu˶ɿC!@y 'EXLdbm.xNS HKT&1& eYмR_o;--}3%,M~;E4lpi~S-5@c޼hfaX7"2![U>/ CB$BQP?TY?$qgUQ{tg__gPWVLt37<~"먎y^L>EE2FRy٪.EE) %)ms8uJgJn=~ +W!&Ȉ` rXpr b{*4+FVKj-{˅Gq:7'"͇|50Yf  2b2ch;^Bd1k#ܫU:NB+'5nj܈>Y|Stר;Uvˇbkhvie`7.Bnؑ59B.z~2\vtLx(g=?`mX9yA7@>5}MβaCB! 8y"wIθ * 1rgNN\0҃ƓG?Ȗ(v!<w#ߗ0+G%RXX{0celUЦjm3` ha7:F/sR@ cJPs{F/S LkYś 'Z+§,-b_GzVMɸ=RI6]H2:98 'q=Ύ@UbkCaӕeD %AH Ҁ Dr ^ɺG+|۪I^0@eQcdfd#lwLp`G!'ri.Є7v&H=s^\GWS|o>HnF1 /PMq3$ksUC"U+w hP[PFc0l@^ҩٵ5^R?ssFsa6jD{[걾`qۤ)l5y'AÒSطh2͹X1FQ֥JØf}3q$gv0\SyɎG:kL%:'A8 4,= >ԅ@Z-|KFEK?b %.ZiO{59uX8xp`NaeuL{WAw|O.Mu<7nُ8D#F_kryלc>f~-Xe+r>FmfTރ=-}}L%LZMJ*`Z|cjf=ⲑi .Һl9?oA`8mn~8B3I“NI-u_Ct ,AZ@%m!H:'ޒybnذTE|:$pJ+hǤ ;\I "t)@xςZ|{j%ݢh[zOe)36Ȥb?~A1JWR/kB,XF[3~?s LPs'"oޥ:'!:>dnď5N!Kt029wn>S=:FA&.~?8WY\$S+ 9&ߍghAG} V]oO=Ș2 `xr&\#Gv!ßp]?@Kb*cwW, ^aZ@ydK/+*qԱBuĮ[RydK LAPp`) 60$A&\mix}*(/4 &W厔9wAxD"l7MBG'Q" \#gMq*e,<4Ʀ*WVūjN6#˒ z&%$(#;P %g'nc*ZE2}^@L)L;ҧ|'*6_k2ꁊljvObȏoy ɾa2ǎƲ#|Sc԰ݬZM?Ȣ*zխ2̼"0gSէlKNRe%;@Uޘ3ud+={sK²w4} :k}@oMGT7C)KbYc󌯵8٦dzLw=$&q]BM2Þo=U89 F*I5O5/cEcjn>c&iT-W;76([{ Ԏ:uy_bXRF zf=R'Btb]=đ¦Z qq>]-Wp  '2 .9 >nF]$?=T34cI\DCEov4M Y[Q^,844ě(NB:q|IܥĹ6:x2q0ЋȎx٤|1"d:2'vTZYQfnTYյR#ȊSq 2XѿܚDoi$*4hې%8!jX$%=Oȭ ϩ[Z6ЋH쮾86 bqFZOM*\bp0'ȇ-@ \IꍜēƼ>  Ln3w~3yZw &hB5kbyxѩ MSL7g;V"'22n?]2NJ3LWZhf( FKX*7}Gn-lڗcĔlJ<%H)gRws4E\=O^/`_$f!W xO R_y"4]cZE`)[(oe{ @wvwP• ;<[U8R#QYcKrZd+DD8z6R׆r{aza8jSN[u}04_A@ x* 13TFr!nT@o=q5ya h+-vK}HMl㙱=xiRı Jgg(QD:@Rʗ6x< @EV@} ߨre|2=gP  &2z4m%rxTՈsq2YBI?2)WPvyTns7"LIٽdKD@a u9ӹCob."MS=qT xPM@O2Q}&r`91}^~}84dPMSwyRmR#?p]la&;"M3O+-VjX*FE5Lz'~ zA픥7sdcI|3Ey89=# mBo($O1I"^Q֊ieBnU$fK>Ja "IVk2]Pv=(R7|4P)m,ޅD&y۫z0XP@ljRc^fŗc:z]|v0¾1 zNZ pB/"IYI$@ JPбN67sghqj+ ǢciQ m8 C˜459o;>> 0eŔi+&2.W*9Q;-) $eMeدYo+G6nٺ&ᤜo2 ~_AJH!)P.V)7$`FVK?v\73ɣ-@wڅ0m&#S?IIS%[DL@:*d;buGf0,1Π2gpf{iVxUT47Yv/T2' sP6.Asdp v\bǛd ax:RMѫaa޶|m ; jqhV[rStC@ќ:vm xQ3 x q@z!T V :*Qs_^NWO%}07Ezw gMUnjKR)p9s%J JMӹV?ZgzVZ γFU9N\ \gPݮKUY.{V>=XC 2gYiHsKr6Q+o?vEʔ|/Tjdy!k@a1!:1Wax1`؆s$(?1| tXc됺z"z^=uX>IFh/)Q|^_Ir+@W|g%fl ~oK,ٲ vC]TGcxu9A`G`;y!yi_a -|eʼxlޞּ [D.؞7ܵ6!ğKfW1_,wU߭O'9'E1!۪tҵf}: # dQ moF=+SJƔ+vʊHum,U?$oU"(cԨAY}Dt;RňЙÚSĜmAoOmV 5Qf[>a-/)yͩ Y2 ,>,wq7$CuVv:Ћ u:ֆ q{O;5d֣v g+=Uȭ!S֜Kz-S<w_.ܑ}bMjj|8g [QMi|It~ﳘIJD=^;.D7%]HG:nu7g\2rF|k]6&*/(=l[aMa@K2d FhЗQ$PgӚSe_I.яzmRߕ=-WQ=UpLuT7Hr*HLs*NǎAZ%P$]F~ ?ᠰJiR"\EKάf1G!J#暕B9 =hzp]0̜dSqʃ!ЮqoaQa2&|-t%V(Th<`+Y*b* _ 'ԛ?BօܑTDퟥ|MQ< 9U^qbANE4t;Y >2.M_V(=~.1W==(Q+Q}ry&p]{ D\TJ'}a$nTNxP#T#Nt~5'4*Hh oXH=mo>O|4,,Sj*bJX1"W? qt?IΊ&G=d_5$ !ilL0g(`յvw6QPf&ۓ}f@Ԉ?Krg]B_dkwK~:04/Sd[zy`Pt۫o\'D] 3Y_qV?L$xCz<ž[lġ8P_w1L0}Ā2J+m5|tOZVEPf+QWwDSSAf{eohVxqiå̻Q8j$&x2 P3SA-?vpEZ"$az fHKǁM -ՂcT Ɂvſw8 XE[O-cΈmӦ͏VzU'3"=NnJp,R1%Q" -H[iQ^෮nm aBKcYǺiH=ÔYV\S{GKO+QŝiLwFGQRT :dlD9RJA_}!!\Tp2A(s 8H0S5WUB+^Ť1]kH'[+G߾N*DRp&|ɉEG:wI[^լm!jXy\<-scBϲM*x }D?{Lm(K:2G~R 'GN?^5H3LI|y2]qquiB*H >VK!ax*Vs [#,(lzN԰J_Õ(˕: ַ@?ohxxwʓ-Jm C[t(}w#\oFM*V2%{3 (G߅?Pӌ"yjdA#?"ŜeT$Ad*FQR qp|p\o,R}]'5X#1D,_kQ݇srD>Ё1lFZ noq'}׈ ϳXwln.8/[e20$X^X{v. uCPfʇwz7[6}#h-96/F""^"B;4tRekVʞl<ivexe 3otwy[r xb?be>޷;(#`d{KrMǕśh[S1H̯D3wfS70*(Sr. n˯K5`H #/aeKſ |#8Ls_G,{){0hB<8Y1Bg_U&j8Y %fSSou<뜮:Ԧ~vw@a3G = gCNy'CѢJGeI{YHSh4 9ale)/7AXX3kѫH_!MsHeE0s'i-Y?5M]uG{$! S'C`54OPs^>Oj)QS7⾸HptÌy5*/?{Q5Fnenk"7a;ݦ6 ?2 >a09S} WY-nufI$8/W{݁J^dcA#bg 規KLA?cYyC91os 3<@%\Bfuk>_NBѭoT`@: &' vs\uK>&f Pٷz/\@)fG:4)ڄH5/6^~Jά6E=+/x3tOSR7Uh}G!crj¹w*8SfsZ沠 uZHu. o3 ˶kRVlNPSFvWѠd-ŝ+T@G ?bA_Z(V=FZvxmWG"EdnS<Lf<@cEnǀׄr.3teאBU{ ,EOa,q6JNl%7_xM;:`H,HDESxS*N7u4c[|_!"ON+pŦ'=siSR3gNſ,J(3S$Xg[㌤L%oeI`=S/(^|G#y|Om`WcN׎Y``  @4R>lk2zDIN֣&S9O|v2Ǥ nIQ5ڰ^oT}@e9"x}f9qh&ԥ[ogYI-\#k1Asfʝ QQ;VuȨQZ,҄!wAfL*<τ<'ukU F]%Tz>/ޑofsQYk : ;mr}@6_n*|22b4LG.v(zvw'C.i%K="k^\,|g\cJPfFByXXǝ;gb Qý'>?[S+Zdk%q_>yqZ]Q{Yc&Kz+F|gݯg/GaWCN Խ[*K#}c>&M$Z$ŶjJypg@vzj.G( JDvR=^g]vaO:CY>xWQda$Kdj*[' i0^Y@k@UkPns %jKo_d_ٖ.}"3_F¤;_x4#lVC|?mqdXeY8 R9; T醂Y8p؊&RXA <{L3{R;͂ hphꉈ>C/i9sֿچC2˹9pK?Pgk5BP;PWd9jĵøH\CMFbԵv_CE@HfT6u dk뒽fR-o ͝0Zri4o:C#Љod͢UZbܻC2%$1So([6%]o %l ;Eߘ9+G>p2mDwwS>/A-PCT&YHh苿9Hq /XMwORdsq} ݆/ i_)Q; 0K[]W;P G'`XMܧU'N!=%J.)xZRbVr`hcr$jⷎŀF5$zg+ԴhA]pl;l1$ EBR#>ť0G2EȻqE׫! ד. WBKJH׉t2lDlUEX?i_TW uG`+ǒ6p #9F4uo>= PGztܐzn'ZT8׆\ۂ[`i]PLk],1{ӱ R`x7S};,_SV5VZh83v%@Lg wŪ2 Ex7UTT|xbͼH<#̨Rv ~:k3~F?u\Lд/H^mA8{F buq)iWOy|Bxr&5+4bň4IM *2x{JIΤOXNE&ryoӁno __tVQpOBG8&s '8ø`_}`fܥLق&t*Aݦl<(G Td4HI<6)?fC,QC.7lٻP+QøVb0PaTDٯtݘQAf=rv {a񦿺o\/}L_%TbOm jT۶d{퀑ֈI4sE@,4 %7 }m l DE镏%rd5^%CiQ_3)@@;eVi|1XY(=ʍ*hm5-xEtN= PD֔Eܘkwk Pc+'Cp!^/s%5QLDƅL ^?!~c~)4OIP^ _SND-h ̍8z!XiVAEc5icH^FG  p>31aV_4LI H" |9:Ks DjHc֊X(ˑ YlþMrI2]t ;5d Kq 7"O#ȇmR+; QIz򴶈=" )7 +CE) jRyvפA`o]B1{A-P29"b`A_7 )gMN{f, خ$IBݛkϸ<%cjve$oh)"/愬G3d;wgG Wת 9AQs0ޙL`~n`DEL2֖>-ٙt01^Pè6dlpNfUf ! [~NƵ"ʽf1rlX)n.# =Zt.Z&vD} Dfs ԭh8Qy:NЊ&i!gC.$ъlJh;e窝L'/8fwjUWs"&OOCϷOi/%l.q6b`zKt/?6x{3 OsJ>Xۇln>  < GkiWuIk2<{R;yYcfZ\5E8e?CosPf&j׊Qc=h*-8UG}\~B(['E Zά8PQ :zܙO:_JyN%+gS:ل 7R"N+R*HHIEڨ$$973LjS8':=7: [O|XW ݝEבmgpW?ɭ`UB`{ǜ͔ծk٤㧈ҒuZ%a]>`zͳ ?%}? i?V%F4V AQ_)p&n R1-hzvcy}1ҲqE-j.1אGfT~>Ϝ+Ƴ3Pp{GhUoA*Q -e| POU+W)M"[6^d<јꖠ '*)}J_ a9FP3@\mgϞj&רqU 3r0sk/M(PZQV ʋ$/J̶ǃlE3 י? 6x1w)B$}|_8>F0`/f͡mV* 伧wJY׶ԛ'{*sthaXd&+Nro#dqo>eFoϳ~aLNI&yEdꋼ.#ȓ7Z٫d,ha?TM ToH@*L1]:+.U]rޤkAe\c/hx/Df͗H kxH_gs`qUwplR0rI56O}N/"q.D뙘τSRӨW-WT(&jΗ7D8:Jy3Q'& X+ŜI$Gg=O[ ۱ :Qg8FX\sSxi@u}8k,og9 Szn4QBt~x{ /?XHQmk[{z"3tZ1CEB1 12mDҦ:A0.Clf-CX%/'FyaLg'JG[$>#0 HfNcq9Da?HlvT3ӁzwO$xg.k9ܧrHZE`ĪB-wgP r~¶t, W`W[]Y*yH]pmt0ͽ]IARPӥ2#^p `U'J(l'+:=lWӄCep'2S3b̔mj\PA[d$ξ&#-a2[:8wUcYkΒc'|5${Kx` ~W?i>J_ڹKpldAh_n,ƍ&vT$g~c7[э7/mh^~z|:Wn7|kI&x49hlg>YH`B 7 sC6{َ&&.įjy3.1\RslDI_P탌`lXK&3|ؠARGSwجWK!zԄ^iBn! ]>6:&oFZԞ#vK`*t7en)m=_Hb6z߀?U}&*5*fP& pHٶUKD{LΫ; h)T'Y5zMђn&ޅԓrAj,M7vxb包xY%H/撍"b6?U8瘘; Qݕ"*I9q.qb |"_;ˆOߪB=3 MeȝC.r?Z7_7e?0 S;> :B$WB #p3Y:[I J2!WUpZDX|qzmVIdIl Gfgl;<5]̮K0B-tv[ft2NJ/L8ԩ ͥ#Q47Ɔq4vcw:L1+unzƂǘ.K[bY`l[w/di nqGp9>]?|5MHF_-F{ J8Hoq81pF{3kfrOBlbtm(bJboQoQObSyyYUktϽPm;v~A#^O8N4b!#nNX0Ver*e Ī5Twj%'wIjCt iJٰ;)9Okԩ[j)xEpoUҴHN Ca_zϗ0J]ٔq{ nl.t_F@N-U6yFT2)mp;K%^t9P>!Vyo6H8 9_^<%*ּ4KmbDz96J۳[otVl=8V#Y-" JLyQgYCh( d=MzrDKi6]ŃA'_zg4w`ciF5jŭ0⠰ip*kt+'z~~V4-QU>tDJB (2cA{;657@~[&8.i5ϛYw 0ޟX1`'&rMEj]t rqRn[{(Q;^h#ZJ(Ye>SV=/Ӟnr+W?L| 1Vh:ݔw8&Q["ō|߼<@^YY^*Wi8yΧ =?PnKiYuyy]€mM)eȢ{ !)e 5:kolsW%STEX()&DQ ;0([ ZȈY- bXcd٫IR0ΌiEUgY5S:9+N=WcL&sjlOo/l lɍϕ$S@t\ǎqxKztEHpT@']]U#^gP78Il@BDZ6Hֺ1c/ O"^Ur 39͞dl1[#_k{iu)}]yMX5B[P~gYG) ('Y/Do(xIӓ$LW@v$ hYLL:0Z/ҕ8f/|{%N xlF%,&~<Łtƭ/b5j?< 6Y*]St*8Q?:A(YR1+!͒i|2[xeﳽY 'x pӛU@K] jm&lPa *?6lQg\wwr&lTۋ C#%kqbOF, %)m7,=oM NSi=нbz7;0FZ{E`w"6#Yappc^ȥǔxFpGgd;kLA{lRT쟪q$g^HiO,!e9Q%ukaLWO_,y+G>R%#-z`)c+]Ӳ(.jrcG/yFW) J uHu@C6mzq#nHcC+8@{*Nл 3{@J ]ݖqrem26Nү?" B$ `HV =Ѳ.}{!6Wg5uEX^W<$Gts*a]O1:yV4@I Y&"֎qm:r~㲉Om~+V&Mo䈰)1߁D #rn@p x* ~rut!thNXBE d5Vl O[_6: vad.74VND`'V=j':YT"#~? rJg0ah!t]T);5A`3Ho huX4u]^Mm׺83e Ɛ0aױ"&$#xjniE[BSWa>,&v0&cB$;ҹĢY#B _i@.؉A۹R̲"]vTpI>Qw[ v뼣Ў5oSgvLǀ/ҤVqBV<+?G2V=QޮѼLrHF2]JFoӍ3oC ={P 6້g\{0Ii4Z 9}T\45rԞ1B-=]Ǟt6@=eie]\X)YW7_ ^2¾VsauLl7*L'iU- ~jW04Kw(8$Yœ׎㉠E2KOn-L\LOȚөBnY5$o@D0RC"T;O'<m+Y}.&4(d`UXoְ$IٛL'zjѱr߆S7r 'J&urD7S?t ϶ N@AK>$tDJQ WwiK֞ɐdo{/zm>)RqӐ3BG0_)f{s$yMIp@VLAMIbW2`}-XBfZ#9->^P]}w4n r`ۺL"Ĩr=^f犭/)AEqfV3:dmsR [7gf\(*œfWS\hK?47\l{FpخLt`JYs ( m}BQ3'Bn:w_lڔ;ygP/K!y=*#09DXJG0R#ŜH֖lުa UQǩ2o.փħfJ)wD$\8$9 +xupEIPe/Fo4;*6nĦvig}:[[@r鱦IJb&ϩkt 9}>GS$#¡%c6Ǿ\[K _[ KFdDNL0, qwS5 ],aw j\aBQኛ"n:.k̤ni),j)J(.#Jh5[ /m:/~w.4S(% t=Tshٮ.+_-ij ]๢i v޵xky2TSLH,Da0'hyFfRr:_=(|C ``{o:ʚϜ% j@MU0C7YB:44yoG DH=C9&Mmr=O5Mm LYmј0㶎h|@"rf!d_Y+ Ad})WPiy.iyɌo U5~F/Ikɬ30DYr8|ӽF um)R7Z,̑ f sdžVo갗C.1,CI ,%=I/WI׊"uh6s$U >=xL&}ޏNԧ<<6vltmHLO֯$)w89ٳ5UI+lfZ VG#`"h#DmU?1pKɦD0u&/RcҪMarZR# 5`3u31KͲ>ssm%RhNf)sd͔X!_V'` c&B5@TW}K)+Ԅ{(R^}I2տ%p7m2,G][ʬ.D(Y`\fTX?8J#5K8f^\cvD?Q¶{Ɠ@_+1(puaJ#̆]Ji%F[?h,T5 NG;[〗:#~[C鸧"ܯޅY˖Hh1fx=VҊÛ'.D%$(N%g%|+GuE;Fs*Ei.I:fz:=p2!K{M>`-~DqS}&Ҟ~逹Iy;~w@69vN]J3WzW;G]k%]&JER->Ͻ[s~dv+*TEuxpim s y W_!|sA 󑩤@ 'w"o.yGlfք'^LlK v#]Σ8d9HFuAn'p%?J?zR?CJ 4 8KU$몛vW#AiZdd䴙c~6:Q~g`=gPEh.y \!k똻X<QtMb9‡c~?JDQ3ŎtJiI+;=9nr8]W tޢRXp; l5߷S UbdF]و/丑R:8JKix`?xEQM5Pó}Gi~-\loZ0z0֒]4*Wmp7@:*=@V!fH#?kte6Җ AFrcCPĹ :p' /v2w 9Ev{@eT3ʼnW_,>äq$bz4s:tE\>2~'@P;C:_", FeB<y橶0lCV:EV u"|IvO{n[XUy 'T}bm#4eUZOWrvv:x& r٢KGמsќŜ 7rVܢ+qkSeWGJpVyP>cy6PFleۀNcD=*NW)B<^iVUYi`\(wt%_AR_4w#V9fz JLGily8d8a{&*R,]f9D]Fr_Ւͫ2dᬥPK g(Mp Ghdg _Gsog=yk6/ T'ZgG%%=QՉ;/yꊑ WJqR"eBߴꋟ;1gт2f LȇV;=%J 'tWBn[=7ydN=)>,&E#Ձv>`/Z5w_M

kRMk=~I#.<,(U [.))AdERlJ/>=aw#G;sC (dElO[P$=d^H."_;{}d'YѮOJC*u>=h2{+q遻 RIXScM̰baW]PrYȳnp{WE$Z*]5wAlʤՎQMfLbƩJim"[[Qogl@?YڢHQRxmdjf{.ճKy[ 2Ai{eyϔCUb`uzeJ2;SOlry+Ϙb_pfUٍp ku{_Of,Hs<,FmڇmN;-#wVq>9X$f]^8_ΓtՃbO&@% U%Hqv6!;^:bi%D| \Uz9+Zh a5ǰ_ŢQC8XOoŞI0|% #r(3)\O`q~D{d-ї=?eE301M3ZV 0_?`򴚉93-}բR m}zbcwE2ycc&wǤ_ފM-q@y^C`2=~ב;.醮H46RW&E'PZ,Jp64wh=WMi_.RbX!D q9؜ٙ*&(AN8%-oS2CcԉK/p9 X0Y0K(+JĹUUv [Y m6ڒ`5s+>iD<&Sq='g`t89jI #T,i'I)%.o 3[%K4.]'T6.4SN9zBr>C"[cɨ{SݷV!l r(Vkg(B93hٌ)t"US]S.-k2Xz;<*a@bPR&k,LؽI{q(a5ro`ps0QLN@tvBH]݃Y<X(ӲaJ'B*8$c׮Y NPЂ4~yƏLjI.G3nn[/ ԟqz)1ri >:=DGO&'\س2zJ r-e>d`V 1oB 0@E-WrZ s`.A~*!4nsVAނV9A-Mx5B57WgPQ{X(ۮLܶ˥Uֿs!! d8Ch'^lŏMCnΏWAǀT>QҺ$x ?wI)Z9]nCHiy _0ɠl|'9J3܊B(8 $]u>L,P >{iAt45:uvfSdܫ []̥C2K[\VfLVl`8 ҕJPB-^5iфvcM_O k+GgD|T)}"No4Cš7 W$씚b墟%R>qr^{ 2\Ŕtz+yP)r$>} A9FH 42JP{s>%g墔165 .dms辂˴+~n͕6W9z=}GlUaF2՝JMu*fE__ N^}O]f铃m'݃1ncdTk{6fxyfM[Adw[xL|ߕtELU~ dҠ=KzG{ï_K6nl0?厢 /1X:0b$P_qʺå:BxVG@!# $*iv4ZUqڸ\ếaDzbkl Ӷ%ۋLyc&/lJ\PDСY ?FELKjJt_lLkiթ!y \.G쳂^ i>}\+ɻLW޿Wst;\_.UCmI&$%VQC9l{E1@hh.uְw;\1Jw_\B^N3{l{<+QQ67;_zA'S/pcj.i礀`1z`pj j i%m7@w3QFz9й2 z,YBs_iJ< Prr\R!I3ۂÄQĪ?OWFA.nh![Qu\<7'cJmxyA0V7VH >Ӆ(R3z' Cڸb4XJEi!q;$yo k#II m2s~|1;5G4_s0 ~6}YԎt Ds$_KtZz_wg}@F"beJv~*ZӚAG88*jp݃3MsD<;)Xot -V*8D5Dmx< YW&AYH6@h*cW©g'/^g ]U,{9G)Ue xPԏgIG毙 9&8%k[ZM9o,2KR{A܉ y2ثHȗ$n;T1ۀovLiGbXr'nٲ]렯fIZKŎL')_>o+I7tC@"*9'o-8fEG.sQF9CcJ-&C\6:hX-=:.p҉"pr ?TgPu`_#.dP<6Q(i"4BύtuWTܝ.DXF}ߝQ-90i gN8<"pdBPm_)TryK)s5tK&vd oqT^Z>wt)VrzqJtvQ6m-@z%!OvuaEtE5??y ȐA@-@}̄lȬ'F1B~+[Dw'wSS銑8(=ŀ}6zHt=G&-4AƝ듺 nʶ ˂Ny>+EP]e_) W2+k_yhs4JR ;7HusAXWh=?OE8/b\?"7X&}rOH:v<\?c8`f\)`Ț c_FΨ%|e nI~l״+TsIe;ڣXRxxtB&rsgVGHk=J*{񀊃 ]c1"WVqd>c- ӘJ_</Q:J{f2TuLT+r)@0F>Dl L`FW䑰pMƂ }9]Q,lQMr^oGݯϗe#S⣝=3Vyo)CRȩؗ)^t") 9!i?^42x21`\󹸪ŤlqS )12܌2~LOJ. qAΔLrŸx-?@#bf_Ká¾Z>쯷VA]%L AOcf`,YdPgj+msn>ocD2ݵ8gg̛, =< I&2ꠦK#{ GIF%nOFZeO]`]9 ˀ= $Kr7nWڈ(eېLq_."%Qt@ФwCo! 펋nyTUBPyǴ71_$܏Hd&yL&=U; S%ƭ .?W@3eѯCBSE<&.ޫPakIbQGt&pF,si2^_@}gUyy Cgi+$Sz$!)~0~*2aD+rd(wO}d <+rՁtIt@AxeiiI7=B?l5BehR'Bli:f2t57,!;}VBY4 ؾ)/I GjL͗@l:CpΎ7o\wIwk-'9s˓W?uܞŠV6\7!5|o]՞T<f{.j1pڝ_gSqӸ!OV޶%=6Ջ@aEbvWF=*GV?)Qiew&%³caqrqg"EB# h6[J~lQU$C‘xJG%HtXMŋqįmcvFG= )Ďݵ6 kJ^:&Y W9 o5[xa5D(nHHXwrPCJgOab;ҿ4t{\HJ9S}vF}nb]9$1+IcvzO@5\r>`3e>\S8-Ri"ߟD}Hsdzpm6w.K:_=d290tcyP!i0Tk9.Sc=ߍvC`Z- 6~Wl"!Ey0+mcpqnn~zz(Z{xS43@"JcN w*'۷-iR3v29?xs!FйtO\;S#:S[Jُ͊8qcx|5wh5FtQ:t@DoxH5'$MդeҞ`lơl>B/ew>y;~7 3񖔆1yx!h2)78qkXq#NpN5鎁\n C6=%1LQ#hWpp-3xO^ U`%v۱NB}Qf#(PLKNqԊQ;wx^@ONު*'3|ja|pqL.0* ٰYteݒ"|`.krl#vч+:-hXU[=mO׷`"yA9rQҷ oƺe1@E%ۜHl]]vA[-24…c^_9͆=,h+nI~CXYSPӯ "8%/rcGa&HQonx^}>(3J[5dWXeo1tQjcMZ;IIwNyAM{cQYz-9,ΐ3ubcv@vn6($n_fϓ\s2d2J9(q,00Ư$OM:¸|$R6z IOπM'.CQE*oٹ4Kl@k!z4چX^ Eáv-İ~WBB2z=CE;;J.zuk o`YtPp(B!v$ue 9S!e ç(eV?R=\0E6 `Z/2Q'G,JF;Fڃ$ 9L֙lU*hM1^K_xW],Lbt㙙}~Ǯo[q8 /]p=_P!A\؛ݷ3HPkɒ+FFUMQgFHgcMZh'z ~\4=/3﭅4cՏִ4ǥC-y ?] 5gp$:eՍL+(z&D ǿ4 ^_H%W7p`%w"Z|&3R*tqd$N#h]PMRy)>d,_UQ?o\B1aX= -#'X}t$+B 97aĩK:zW6sXD4EL|:_`f<~> MtZT=:Xl6bGF4T?8 BH>(x^!鮕?BُUb`)RoЄGpie|5<[@GgQ?gdx蓂0j6Q Ė>Wy%@΄k M#GzrZwT4ґFÒ@y59/{'^w/}ɺ9FRުyZ2ZRomX fklܒ2$o$?k2 M3pQ=R) P)ugpBoa'`ΡOM?c*&ZM*m7l: 4*Pnmh\K/<8ЭeA[=}ϷP+cYt.]x0X˜V Ɓ^n&sQW+ZLM,F~='Oե;qdl8v#Nw?|ZaBr>jYԅU% aF!f^ [@?p>C_0Ղaoxyf!;(grnO3'  B=c(8 Q?ٰs@-k"_ g5%tR `?z_qT+" pP=#"Qи2 e|ȶ v2Def'p+t`q!$黣sJe*q)]էZ=w h_lz[o0ʳ9n R ˆ<)Q|UTaL/{s%u7}I b4{q\EKZZ0d/V SO"^RV-Qy&/MQ>1ML~i(n%P}a}cpVEYe%䭂zN=_}HhlBp:L*2NJ^I#pz +a$rvL_'6E˩/z;Ra; tva$ }|GCɍh\FDmpwy% ;Ͱ-.u}fܝ om_ FrGV¦4 (.u̪qրT$jGĄ Ֆ0O]U^#1j&d"<(ye_7&XU4eTXp,GViE]QPIVѝpgleM^bO(UK`qTbUxӥك^1ދxWak.5d6tEmᤪPa*,%sǢ qյޣiŷ,J驴,Q* `\* 5d.\櫒 v lM`Ds2=EokQjJ; K̥:𣫎D&yt>LQ荝QT* qMtp3-|gdR"nT&Zlf$Ÿ_2J3:p~RXE1.oQd´sj1HyY9~`^$p7nīr;{X8n¿ sJSdk͎Dd-;6y ZREL4/zMyw=1(P6>/~fN'¹"NXAwNYIYD6Uؼh-aSE m`Δ+VLly1I4%Κ+ޜ2 `Kz\!`v.||B>*Mx]gds Bnjx8.}'ڨǰڄV2-,L}K#S_%XgP[&|Ȭ ylOmyvU>=V͸>@vK?Uf=*WR#+dEPE#0) (TDlrAB?C G 锥I 1ŀ{Qu$ټɐ:ޮ\Af.d?Em夫RZq Q2p9k[gps7R $C;/5-ľח0U'rOb.3`|̒5l`2ݯS$ _ xju'y7㌞8zWnN~fb\#N4+mj/(d`ĹC4y8Ж;b~\N*?%[%*4N&;3>|}(qkISMP1=z&X ӃmsW o'ƕ=WařPS#5J Cj=aK5 ijBtF~0ic~F+bxw霿 ˈz=\"QQApU6nu$˨ ((y .k\k9$lґJп\ bo3J_W_4UCp}Y 4DSmǮJ? 53r/ MB)BoVEiZ9QM#g4+V2:g;Yz 83TPm^[hS5QVJ6]tn*$T mXh&X  Fv⹆)R>h;Ʃ4Oh*6BYHu8a'ׄC6] XvUuܪy΁o՞L)uCEseNص!鑤'#2~cQ疪Y/}=a\( 2$B|pVte ;7?5[J1/x_YYpz@NF׋"f*̒"Ȧxvyp^cVӍ99tu2kk);3!zVs )i &D7dC5;/%hbPʜ)BG]PlYF|fj13-#۩GJ'5q ".:I+ףY_ʚ%$ qn*Aq5% /Imy A1Z)ɫ>G+Wv \|_Ds?B/n:K0I51EPԃ:VhX |?-Zlr^C͂*#xQ+?Z:VuԪ8)`>[RC&]ڄTa'#֏TztM%{?w ?paՈ٥Ru'oK;-)I}Sl] y hK$RQG '*5NQLr`P`!Cke$lL %QCwz2 ÇƯj(FÞ0J*.ɦ(> 0>8 ;V2pi䥞cM Xq90 g@'hxުk` aɁu,fVLAzFa&O ;@PơS9g ^ BJ R蠍&ME$=M66~ m ,}!6%K)y)Jv[y[f7>r~Ġ. 52D*K72otL5хM/6]lpt/$^#~>,,c2F0C]z{SU,@R}yΌmrƈFh3JxQTm?^.fzhe= [$3qx[^!q5ہ2je$<Y:m'FC{5&.}B`zLbW:Anϫ¶U+-.FXΡy8B[<俞FV:@$3|0ke`-MF`5 r8PaA$CՃb]~`XoƊx̆o,&ǨW S斎mQxmY-Q,qcc|azN^cR9ǽlGS 21Llq˃u7"ܪ1)Ucf;rddUPY]d`9vM[ԀelC0Gj~B=-Uh;zouÄ5(s~UDپxT}bV59e݉zK~\I٭e;*d\W未Sֽ`f ͧ<1=BQi6@enſT p?"ZOՕ(*[@@w͜zGjӐbjN1kpp8`ʧ DTcjWO[ >*lߵ;Ľ._Va'! Y3<`z6)n]?Rɣ^&O[uY/]#WԒE0'NPO0 ӿ5!Cdcx?Ee Wa]"(12t92Ԃ%?(#)ﲟ29wh#$t2\~}l,(~q -EmKi9ЕF|hc{".W3LUH]}­RCiAss$s:n_fUޙ~ IH4#=S #_-MLo "_o4lF І}vٞJ1ڣDMB6 ""7 QI95"v%l+`*R1NWb9\Fʯ#rjZ6{'Vb%SK.i>HW>)zY\vg"GE%4Һk@ !\oub@)q+}\>ˤOYg@ >nn) a(8hC P VNpcM3.Fd5ћ&HLg/KQMzD46M,й)KOe"}nSvl9^Vr϶ I6#׉I6TDo>wfS%ih% #_pPøj,SZcS+J7 Rտ̑k Ѕ6ؠyoת4rk.c Ѥb,spȅvlGiʚUY.aH,fmS5Gw&a.emQ 5FramZ5plN$kՖ5#5:?kYq=F]{Fk0 [+Y-5Ggws0L(S¾bQA\2Î/g O9` 0O&5'JM]ܧcƊ,lbd)h xںSGq A9A~vF_ۛc[!Eٹ? b+1TeW>OvF^'D"Tk Y=xrypoUxuIE]!1Dx ƺ|A@Nڗ^V!Hk:: 4(CSg"ΐ\|smp&LUGEݒ\}jᬎR*eRLۋM*ed<:^*VJ$ڧ[ }$?Z+rM?S6K5T.|GEǙ\|# D3ZE(rn55}(nԀȃi|~)˨ G~ʕm(nvU#g~RѤuD_B*`~/˛&c>=Lݎ_gйxM'OK α?+ BY$ ,G( eh{3iu>/=I)Kv}Pe_dULi|-f6*?S] 4.G_z Uyܚ"eM*Ɖ#xEHcSDgaC8EM:1ɛȢP::xtLMVB'R{?ҼxmHD~.7}ɭhsf;8b vsB/A/<8ǡi.aqk;,OoQEyN&X)TwA~q\)]SZZIٟwRxa)t}`Gp2[ {K{+Zw~`pe{vm6@CP~^r'p3>.bj1鐚RRFM'A:i:N.eUOSR4xtKR8)H}6*)* xC"@ΑYGZA20U=i%*}=1깿#("0S\]@t{.XErLx@%mqGl,URモsݫƱPzrfvU5R|,xR.W *xb+9C3 NWN |B4v3Ŀ֞P<?צn ]&Y-rց9S=ЀewY/p,!VBwm S#th;Lj=-d^u4W,QـQ耋BA0*X{rŠvqN#}]|{n Uh^Chi>[8=iY xx2FfwСA/ $]WXۉ ܏]P€6 n " LX'> 4 t!nRx$^0Zm5ɀYlMh'hy`GuQY- sfE$NAC%M͝FSr?[XfIHyV[<27NN߿x(jDT0%apu2hy_$!H\{Ppn}F. Ip+)tqƾ"|`9g'd`,+Gu%C_?H,77#v 6lyA'J\ԐksoFrmWDm6`j)(-5Xb([:>ր/m:毼SS8t߂pѽ+*r4TXw?"8̵,^.<^3B#%"3N! dFDgyxee!H[wR\ߘo ) lʨGS/>U wnkXA}_-abk%6:O B CQP\y>$&$ 8ʍI r3nqD Ic܌#Rn0p= 2\TY/md\ӬG`y{aoa(OQ1d 8nU61=+8PsoSjG1] ,.\3ށu.4Dg|CH4X4ܜ<[r/e&g$ϑB,Ӏ0"WC# _& A,ɁDuȑj۾Sd?wM>\&sL)uE0.fOֺՁo/}&ܨaQOMa[XBב z_*ʲ tXUZ?v<+;hBF\f=zW "74_"REb8uQBEl|-\l ,b!Ye-ߑ,N+SmIPaZ!J) @mZ׬uN!Φ%ѺbpҲS]P KubvD]ֆ{;DvwΠxzB;F* _ⰡxerObFQMp ŵW*h.j]mEP{w:}9>0Ԗ;JKU{'ucf UByb{[>Ub J>z~udS,iiMk]Q9s:^rT}E ^rJN :.tnaQj'Ɩ((aE)hj'p֨ j9DE߮F0v#1H"rҧ@*S SsrB\tMhErtP`lDɁ^q5҇oTrbnA*STI86Pr?Cx)r~$p¿& e%H9Q½ A1RBPwCKS6n6*8MCeKY'cUADy ]:!.5rmQ=Rnt"=I(`yBYvgN (^na5WԖ s{kvNJ9D%B>҉k 5UBӺ\ `SA0,ɦHxdhqN_zff}EA 0"p4̱b3.cR&rX>}ab`Q>['9}狶E\ŝ<۰dWu:P62áx}K +?Hh¡@Ncp[80|2fnjc<ï1IܴB![jkbsi.U|L[\C?3!{VĔ{AECp|;Cw&eC*ET(f`Ȝa!x\ěG,zsOg = C TN0cU9 b&{~j”aQX7H孾rB}WVf C>BWƘL<#`~ua%9Y!IH ^ RtLk+q~zҋ+D"KJ0AorlR=p9,'3dmbGHYG/Djg_.E c͗m&"eԻXDx&ď@ U/EiIu!Na?r`&B#Y : xV.T&u$rϧm@^vwΘеQRJ.j:q]!a#]B3LiIx3-WU 2[87l)w ):v5tCN4ˋξ%!"mx ğ># ޹QҦfOWxllH2u?0xM/.?ոol7N5}hD8 i02m=p3preco?ԛ|c1RBYXԹ ŃN*_ճ8U$JY&BXU;4,n[~2bM9[R=wT|yHx~m4%t_M9Wݵ1JHWDZ/Nin'O$*0p}򐀣>Sjo|~ɨq OTnUC(rz3}VPx^~)H/R=C!^?1n߹B^|`(bFfa3BOh,6CLqOwh f˩\ߕub8ZgLZ?W')|xW6gѼ'~1o 4H. vnVm}օKPɄ/-=[ABe"L@#/I&W$r8ý)h"5/W)}.`,F"^6#Zq$J`eA7}pVTәz~-6~ˋOL7yLъS8Ӝ ŁoZuC%Q$D Fou/gUЍ |Nq0qYfAc٦ Ζţ( J;JX%v% EO!b`4oj'N Dڛ4Mu1% Z~€I]d}.TagZZwR^O?M5^V83Í%1.5KSTx$4B]([N޴O~.ywH/MxЫ;RT .D!75؄_U8$ܰ1J7vxHrP4nXΖܐ%T ΕqqĭiZjM=D*ANun𰂯; 216d2f#=' H[̙̍ZבKQwOԅko>VKqàׂҟ`fThȣz`P[:Ly&Jw@u9&> 6t=rz4kѷ1sj"fgD봆9[5C013æZ 2O/}hcXqЭ=JF:uF"6 7RVkL8WLz@S؀l:.Z̶k-S2$u?2m1Lxx%.#flt %G⑷ [̈́"~Fi/X4$Jd)\EI aV)_,="" eD1`Vy=>(rH T3 (Kjw5 4&<]Y;6zk&zDs&yQf%*\\UZF]U"WGMT"}-;HS 8+^.~Ұf\S?Ņ> 0@UCOEt)bڎj)R1VC/&q:zv8hEY`[Ok9xlEobpq~EQ4A:gqz w|c΂}nA~խ V* J/rnCfFN\2Μ"nt%qT'LJaġ-mS!HLRj(j́72elЦ瞅 C>Y4!qy+ڪtzЄ;Z $ܶ nlgƥ . =)o71ytqdM7Q;ٽGGx,4o|"HyM饬DIxU>Ű˔Es߫aYF>ɹO#b32Jȑ ͖>((*hK8x7Tְqؒ PE_{E{ӫX,+P4R]]^2x~H{=yyq!STEuTlH?&e>K3,>CK])N8rsF8dczqBLFG{B=4w='*@$%$wF뉼Ŀ!>JȘ )Ys剟(4g&tG>I"4)} 5 X(. ҂c.`j:f>QDZpFͫFf3yTɞR1!7yla؀ 8W-0<$ŀJ7Chĩ S>=m$U;UQ3׳fKCyėdIMtkjn[s3^e?4V]m+~w"ͷ3VR4غ稦§ӊ( -C6*ȓi j [5aD!l-эnVs:sxe^tV0=D 5 XpSiHH$RVvEhz -^Z91rܝ["נ`v\|{*e ^kV;H  )nFqHud6(Wϝq,Ā=i`x,26;@Fܬ+N18;ܖdu_zcOXL=gc^ I d^d赢q|iۇ]Hu6PxON&yK`ǫNv]Ke :n@߭Ȼ0Eqp<5y8"0ɏ uV H!V`JmXΟ9(Qh…{q:<] ~d#(ᬰD#9٥frsPN`ONmr zeW1 IjF;=O$~nc>3J0 da!ܛx @۔i5rs3yM.{quqRAֻ($A1s$I&Cŗ}%Q9,>, $VŞeᝢA PhzJd/m؊n|=5aQW$íZ<}IrT賰2ρ6SE0/%ƇC 4ͻau7`\_ҮfÏ=8MDo+rFvƘjI1NFm)wBN8^DKB3Pd{Z։D6I5jAٲ8T|#M؜ܠNlFH"BR2ʝD8Er2=мc*d/^I5M:D|ѐ/F8E+g3  uxifNvm}1E,&}HtZYL^?󕣁LzߋQUIU1W"h=DҒ[ivjP_KD*v P롥ʌl l\P'wi'R#1-YSt8<Ќo?De]@g.0(JC?h~B8HPɷ89u?,yf%.ׯ,hu ʿJ|lT.=v/ tSת'^h[ GX_^j;[

Zs"qR$Nˎ{XNd#Yq.x W,Hj)@;1SNm~^eaZGٺ~u|~ W6=7ߗP8$K!vBаИׅ^!](L}R_y gn6mI>/3iA{'>N@?gw{X0@ү:|J]H&a5|2 ,#IKPx `-u-7'$/ʈN6Pr[$ Bm0w!!.V9ɺ: orD +Ȱ#9t-:[I';>}!;(ƭK^k˷sT_pNم([*ѹ d%= +yIZ^>$<}vb]% P1jeZaW=0cheU&7Ɲ+^3ƻ~~FU:Dǖa 4"SGP9A١D+ [#3%oTm0ii3ib_l0/"GO@):c^E|ke.f'1(aMRRծuRZCQo4 d4ztiVk}DYR@btH$9TTJC/}:)'%Dx|䑸 S~8X3lיuX%+]W܅{n/(vL g瘮A$U#aQEb*XtsZ[Jt7ػrԫ!gTy wɁ30~;8tTq8͢l sZ_\;.hsPQ] o3qlnVr|#"|M܈ 5+VgA=M#FV\0$\:M蹬Ή$Ҩul,nO-D:p\j;PׁC@er~T:,z8scŜ )f^CJ(QVNAQb݋z${B{u0#{ѝG'r? ˂Gh3MFC:h)0KV m?œeN/Xp՜I{Ŗ8a8I2yR1}>dƆ3o G!Bk8ڌ  a9+B;D9߇?6[E[:<4DRF1 E ؗ+l;MR񩟜ˎ;DD,\7BtWĐx`u]mc,n\ !BЮ.,"MDVYC]v=H }c8sRUYmܢBx+h2a]Xo_+iҙM3׭?{S^bj—'5QV*m3y]ԕRhO;2".\ Hӯ?;?$.]Rq oqϳ fϒ^dI|RȇhkBe3V│T@z]MeY,*)g:$,0=T,UO}[Ubtw;khݰ`GM}W} zP\ j'ϿTD:IwW\{$*ň"}r5?bFў\6fmXXQs8fId\P wEh)Igٯ1k51*-. Bpve! 1.rSTT.Yx~vܕӅtx1eھ̚/}b](^}gfe;qY2 ]}itI:1$i\)\+8cR*'JRgxXr<RIK`s+$JguBؐAXTJ q-Iu7֯xE/ZWy35a26>)J;5!ƳQAPI}]JmqȻ I Ԛb̒i*Mȑ{sf]蓍{0Lr@W ,/0>R{U0mv3 ]-9ކ, TM/@L֗E7{%qk]v@jv^ufsvFR^_&i5I@ GPiHo7I _1S_ȨXy ʔqfY_뚪BUήTmlg {{[sI'jG7?9AmٜJ~gt$%p%3&/`YRk' cYޏg.1"0}ޚֶ~cK%mq &H_afn3E!$xWnLA^G80!s>QR4̦_HLUv@p|HLp4֜/ֽKoĴ)Wnp0"*V % #=} j-GWf3tck wꔹ{2zjN ˁ Yi/ ?.HIDJf}@˺F-ӢJC>N 0I̓(fvq u r/רG Ac|ʼn*!N#"b]wo؊{:nf\RdtS J-`zqͻקI XB¥`_^`!='|g~t gOr7Gc.|/1' 1-M"g86m}%0dYmdx+ BEU.zuyrF*q!M߼FeZ!py}eVAcg-c8m7߆ + OũnOEPӱvM%+9My5҈V&Avm+,Svf|Pf4djm9&&戴NL# 0ұu)=O;*= q_*KY;2jVn"0Sg%f *@";v153/P]7Z,? ;*͊4r qi\M5wɂp5}zKZt]!'< M*uUnyPV\NxPt*ëj?N=!> .?H ס$v# /!Е6{Tðp?ԶV^%S\EjN*vx=!?p4 ~#yu=40&W)y]XEb;{\sG{%baѽ³6GbSJ2>I P3Ik 7|cpq ؉$)e`]s܇ⅧD9d'׾8Jr5W)_8]j!rfWjBD-H}{&k^t'Sf VwZwyCAs9P1m8wZ45V6=rx)jx~ڤ.軹"#ι#wp'h-`.TFl 0?Mt `1Tɦg-[wˀg=ck085ͧj[9z(slSXiuT(C$yw9Dҏug 1P-O; u[?b9")u5fǥ3XbdNZef":S2 UQ!+N]wSy|7--dC6NΘ{,66J2ihq3:o7vj\L v]xnṠzDCnV+!\t-9G$p|%\>7z%ͯ7fAz,m`+="fX*S 6wGT7~ .nBG[5tHtEhu$Hu9 ƷSe55;C3V1Z\d %`Fx"8)Z{*5\/Q%9 cO{ixkǯjq4a{yK댯XisXIJtc0E3ω^%:ab pWk0K‹VxU 14@;ECcw.o&E'jUo$u>H o}ҝ.ne5s"s֥+cf؞k*YBV&zNJr'#aQ4e^aMk ]`('YnBTTܼyug;̸/ @A?1 bh+`~'X*x6F)`ǥNB5J u׾PJpL `ȇd!iq_l8, sONep5*U#?{)?aȬݵHvt|2w1϶?ܞpZiLh)3k{ս`}m#PGh8#$ Q.4?z!V/N3jŸ:ˠ5Mrtۧ}XC)J%bW5xLTԒ=\T׏`/Sȅ t[AvKȘ>'bRny1ꩢO647K_ ɩ*x2oK`PץJ|b)FW{x J5b.U~tnOלKKx(@}nXMG 7⴪%eaL$ 늓(:b6p_sGp2EY#y{*V")vį>AmRjAWCHbuus[Z G-aǿIEVωS1wyݥN67T8w{Ų=ýÏ kQw{VF"E!nmpS8ѐ_ LPվ׵`崳^ 76EyF߯cfw+!96EYm*Y8BqO EG[$\yW#]J ἋV5R 4 l{fEQ|o4"椷2dHZ0|[bRo#HEZ|t{>GhKV>7v8,ge3Ž4L ҳL9y#pB+ss53:m`f^z] NPGP- 7XZ0x&~E9v`+:V5ivhS3[>> ob= Be3ք0T5t%g?&Hm|˱< RDjUYcq*uW:~ p>B)w9lgU*nhxzȕ Rn7Ēyn*D^Vlqqt6>`2;f!ݗx٧aԉkΰl{M,N;;oNx"o qy"nK]Sz-; ݐ=<?pR_A7s 9RS}xPܿa(QUlN\??lU;$,Ч݁ϰ=!39T6Z8 c~[^l(Ljx&FڣIJ':7 r. M27c ~s9 $)k!P8I 9`G8j8lbd엧Lɘ7ż%$ rU84t p@J%QX VA -z pW9I*b^h˾mП9[L;}f[wM*TAݶMmWrb d6G܌ ]Ef.oq.(@{Bm\KQ)z8uOOH1jp8G"4 & W[YJ{Jp5\!Kg]PhA N-,q(r{1;VB4[Ts^F2c\Ch$u{٩XXJCm)nD ,g;DŽy ׷N~|]R)I&Qg;"KC#Wa0bT?gCF}cD?=-pGG`%iU,6Haz|͗Ip\7!`}$W=(zQ"sf,h՜2,guu@U`Ɔd 2qڻ?M.m8*0q0SXٹy-`p!tbRx_Cιʆْ]__[a vXsfN6*'EkC# 䬭#8EMQqڽC$~'ce::ayYv?zKd&' Uҿ&|1Kc߸\8`Ҧq}~N'(s^ &PL<•-DĠ'r?Iڈb6ư ^ϧUfXF\ XlTnAnL/VASC@TRyco,{dIKٷ5#zu6w`EIӊd\QR"kuU釔>?i_VQ^n֍9/њꦞOxa[ʝi>LX0AWʽEJ0߶C KzdiaLQ:RRVimޠVsn +ni']P WPȰ3m}fɽJ]@wV Ku1w`Au>`Dr%+A;aEsӆtw&dfsa6t$`I:y~YtZanTnH P)*@ yum/d' eLlpb)ݼqf,}p*rS&wBX}f%R ٝ Ə#o7.ͷ7:.AYpkq=UX|kaӽ)yrI0SGy.ۊCIߐ·,]gnEb,STB 23{,8>_/q0.K ԑ%ZE2.!tYˮ|ObHJ,8Qi.W(PVoa$1T-~Br>hPs*Zc^g?m7tZgd&÷ Iha+*kw U} =0&;tJ>v9`&Q8h ;q(2<oYvOsdIy\I ɤ>w+h`_c:Q=k2z6=#']z7|1%)B&ѵ'8_$A.것$"3nUy-¬i}Ruo bKk<|on&sc-#zzۆbz5nuۋ1N7Ũ#g0v{ \'@yX`38D5Q@׻`٪MkddS¾EmkT=W[6ܗ(ju™nc@4wIYK]:.KYZJx}خnf:Fe^ :)E.T q~qC@6驌0"cw?x_%zžf򢕦2W>}kcP#3TqK5:fDSc:'z4z w4ѺMB("^ShR)a$;jd /L[BhXTk)6;HDțIz3TR:Js:F)7N!3mӏ`]c_Ijn&#*"U XG-D)ɖF糦GMy ~E:"9E,'ot)%h[m^X9ϊ.R=A xvy[Fkރ7ǩGf8ET3ᙞ5E|c8 &V ; dr@%6a9pZM,1&4տFT`e(Z2?Yqh}qGU]V]O|-?c>յXz[zv@ڠ156i=#Dt \ AÞ_9vݞ~KǎH&( nupQ`}k QCk8'z~C9W/5/glR; >͂ <9 ev8Au NӍ+%LD5_I$ݞN(b8+8M|E}J\{?լ$fxVAMJol";!KB>. (¨))f't%'nI;`-d4z%Mnn4rYP:-%G Ҩ;򛚉Pzc?#GF̼.Μd?Npmvjj+ W/2V=2Llr t<|5̍@<, 0IF2x{U Vg kx˒"oH.ܒw.ÿCt1 ea +Q g4o?zr5%*g'Uq5}a~zVAݸͨ _KY/ѷdd>&D.5;=Lん7pwHfCJ-Iw8ϘS_v)$0 ،Iu'?g//5ayL\a1>R?L7K1ؒs'0a6[2Yb-I/bNxͫEt`xu2WܚR\3\V 8մy) V c1"˯_# lmdĴ&Ē FW i J(8G|ɩl+'ާ_T%duy@e@H+:&C]Bmb5QЏQQl1` h#X~0EՔ1ϐSl~>/!`鞿Q@|]e7- SrC+sȿzYbb9q0dSh+D(="W@==̏s ErCPTSu.b)$0]JBa7OXS(fY4.e̚m 4 C!-s w^σ:ح a }Z+1 to Dz[Fw4;;WՐ#Je;) {½/1ĭͱe. ?x>[1.JNJ!!Ԗ|Dhle /;$ƽlof Eu ]\;qE 0&y<~J[Ea8ֽ=KKP?ƿI3)۬l!3x5cj,(r2ϣ-=U:7FlT jL2 {D#bztB/Rt)Y|KGliY_)M+80'~ʨy`oӆ乛f{0hH p탧iCNg8݉v2~ orm|4zN0\l/_6$MK!Z}Siv}"%:P37޳5RM[HhPϠOB 't98'Iΐ.)ZW ȌxDcC[w@֣%%K~ MvW)ʍHέO }$͉3r-a ޷O~T猫م2v㪪~⩓#/dT,(tqN<!遑*9$$40.'6jUW~&"'qn6eTuDO\Hn(DE> 4XBʟ#VǙ 6]rQH [:\Pݿisbv2n%"w~D4t"]5O>3,[O{BEtXxz^Bk/?vl!^T pF G][1.E163+@Jd#t=g+LgRER*V?4xd-FWsq.'%g?aonRtj@jh&gjjm+(I\8 rs3/G=/xG8،:5W̷=n44ha;FnWjGhyX2+0[CԚFp[cGk _^C7_ sߺB(ߠWL CסܟmR*teT7 #R9j0L3 J] fnꐆ%k`;̡Vl!PƍGؚQ7fU/,RX# c&L qC埻-`Q֖wm (Ud035DeU , >s mTpR0I^)jTXHL݋ZѶ NOAiӼ CN]gG# OgMqkQ?[x1=cł7V)ZqGmDZ2_-I?&?b-/?=ӷVǀ~ {*z;oqz:B7gU(ŐH'936^vH谏M/I:"!P1E"7 $ ߇"N(~#;:Ţ,c ==<|}scd\?Ž?[S-m'+UTE U/ܿ~O@l# eYb D<-r#%ZH~nh+IeӹW|a' _Oc⩃]Ukv1JxD (?|EaG238 qXEDRAq]{Ȓ!qCU3;GYq4^`ajϘ7TJ=o>!گQe:eow9 =X NfC)[HQ>V n܇Mu砷!tt?` b洏NgxCyx12A Ll6m_mbTthS0\r4wG C'49e7|ÄjTb2 F隓͛&]D8XhZ7*(="⺉Tg$ߠ4SY6)b#>#KJq}waEϫ_B7 rJ/{j) XQwYqC2MhkpV*U.\8}& +\ԛpr@efF `>]p9DT\lRȉH? }c<#-Nĺ 3rW];P[Y;i9o:H#&Laq9W.ֺCz Hu_io,-e2d% ok? _~U$ J㲀@WWT8pC/WhCvT56A 6.x=}o2Cj9z * z1;Eqv?Z1ƕ3I7+_ *PĀȑ.ks-o+ /Z!2K/2-{hY(Mf* p -P.fH5NSsT;P$: dNzh̕ӕi-JE&0YQ/he$e5Him0K/xVgiw`a`$\-"dvcm;-ti}N)/rOo[N/a8l{[W%iZ3T)ZouqHzFY>_wf,@hyR;FF 2O5꺨%b,sž;Jidr #n/՞@{ A[ U]#ݲ0&la߾P嚯=m`BZ$z05~QM^_qǨ}1TI? t٩EJruiݫ#u`F4ncgV+} z'!N,1Da3ĕvJbZE!1P2D]${H*FcUXޢ+S,[yN0shzflΊ˾[]1".T0eSc;j.O+4\$^YӾ;] 79='[.e닲49S DF W/$l`cQ&#,{)uD^\K(< ,daB [Ozʀٿ _B!A[{"wv˞3Yp;]ep!wfOޕa&4;Muǎ^ c޹txˁ\ {?ЩťgbJ<)؄ 7 qPy;74H/o*o(G({2k'Pud8 F`l qrF{Y-:޶Gw/,vS]u`|eΣ1Tp5}o(U/ q;D8Iepj5r!x&G0f| NcaIGow`6?D.\3-~k;K{f^5̈́Tnj 2c 餩 3,m[S6E)cR]1 !Fɴ @Tx ݠzyMAGPn?]X5@xnxuZDjڐ^:̼sQюV$l?OJe8x⢬7*+:j͵ #/Yl7uKF'1 G VcLBs<1bVeIi(AAh[+U$l0) ]ǣ"m<(ZȺ.xGMqb7oQ{Pځ?pvZ> 7Ҟ𽪿NQ9f].줥N\p-b)E|r."!\$v;.lyS`༁Ҧ qs.j>쥇f J)~#{.;{A4#[ȢWdl|&0JY|&,&|$W+D9Xӧ-.Vg<b _%CMͬy9+}KBN㔱/\ƪ4u7@f$Ҿ6ÓΗ~äi5#[}IY1#o` $JE01OAb׊V9AdPEK)DmC४ qC_Q9APfq={V/]saMX1^GIǚՁ9Ei?ŅV]QJ>I& Dɓ)^CLUȶf؜#фaʚ:> ˩E͹{k`Bhzm7lƠ/9޵GyO Z !xwt<>-8ûo: ?"2KMveDݤ$.h'.X 0nkIJ]Ji.i|=۝5)#}j\6ў ]~N߽.BЙ""Qcٙ^s9CJN&AK VhK\,͹d0hmT -/V!Hl"da7?5_/ϥ%$UGBI@UTnv(Iܦ1"I)̳ gL۩']LW,ΡP, 9"SBJALqhQ ].5Ź)& B&xR[CRM2wS}'j2;ڂ&=FjÐ꺸@571/J(]'oOz~"P /TV*%e+wՄ1ߘU[1i>_Nj-d8Ð5 ^Guc_sWSo v@HOjz 6kcQHÞGKVQ^Q*$L:[N08$S@aJ8K894)nXGC0),h  4/IS@$Ժ#GS",O…d%=w}!n>ظ\w C;wb;m X~oD-ZD33;|4tUg[bq n~# O St[i[^ =Nwx3:yk&~yP : arFa?i2rrے}i u.bpi\/sl,wb_g%y*T]d}.(%R֙;`\ /+3~7i m{f[yyF9v8X H<EMӲg&頄IUҒ*Q2خAGLLm~q;uf8Գ5eŻm }%)= @a-RPV6J~;1|= 5g 5͟ʅ@GfĴ#}R%&b! ԍ3si>C{;90ȹ:m+ ^{Nٞ/xIZϮJOeWهv&dDο0,|Lz;]~Ǻ=2Omޔc euDicxJX76P\)&EU5.D4{,‹u1}Aܪ5c|} |-~fztz;̵ 8eܪc3 +_۶V9" KQ>0:*K%>%6 ~dCԛ갫dZXMf; L+r˴B럦2?HЫT! W.PMKkɥ>-̰$ 3?Z"^bŨ;n3>|dh+{g!`f$Ho; K!U0TƫTw36kMAv?U lAvkЂ!!ʳ'sY]m#JlP1Ӟ֏VG%LjB3X]y-hfg1 an#{cܯ"֫rq[TXƙGQ&G6a]44/&(7N.#'պֶ1! R4Q6 ,ZUk%dH;=1cm͚a. /GAVoXr˶7'8lb~;h[?#Va{2n*r 36^.~"imӲ)'9 3].ZO<& {oqvH!Mso_l~  ~C9"Y؍cIf pEQ4Xû/ezVK"T$&.-SLxN~md>A( eݒ۝Bܶ/J ,QҌTܘvUoAzՠ)K)5LB"[C[[%IRxF^+MB*zUw-ܿN?.#v%hcU5ş6Hl߸O63TUEK9^< `f5?0-2%(Hp9IV' Sl&h .ZF c| 8AER9Xl,.ƮL€*%"uӰBV4|q@og5T٧C =XD>p"٨{ֶ0d7!x|ؕI37/PTˣ?G &GeO Fcd0k;a\T֢ U,lA(nC.adItD2O-TčR gn+W%1t^&{`E`]G&>꽠Ux'dpugf1ΐ9dtkvdG~?ru>@|nN :Rj׮t M+5ܐz++%27 ٩9"Q5AH-% 9.M_:gtz8ۿKLS20:>|T iM;L%z3܂l3ey椙&Ni! 7`/3k췱ƮKeslFލ9~|+ قD~cDïXi-R?E_Zk:bhÍ75ɭ| лܲz) /\?q[lW2ϪUrEE~nc2}]xP+XB&vm-)CsjXωmdO^8 RXT^',2 #X3sGa^9&40{ƴFG *5]⩣Mfĺ|"F]zUB8dzODZqc\Z/Mζp_f=OJx:c-:qGgCi\SiA;?,6]wѤM?E+"1Z6 5նN(P dcWk|ӈϸp5:lUn.#cg6 ~+ u{b[2^iO;, |z~pr8|\$.KmYLn@})p^wyyb@`UI :PGk8ӖPr$a"Pg)1hc)I€n%0̶#j ob@^_Xs^DstfT! ISs: /?Ξt[ȖD.Vc2oe8Y]R}YZOkr/q,Cc뮂#i4I7oO[fZlyQ/bVrJDRp2r_[ݤy.HA%1tM9tGKEwmgRi9)9xYj" ooBqBZK7y]Je/"nhgUAP\4> җ <ՓFƍ͹ /|Xh;v2Rqծ1sxԺZPJ`":Bã o˶gEC54 -'b_ytnG{k;661IY&4®RNjv!QY13&ަ1 -X"n42,<_QxXxudǰR\xsn? gjcXZH+Lf*=*!).7d<ڂ+~+;8xaMyAl8F@e)Xbr~ؙ듬$^ EE Y-XVuެRs; 9'id/ngPZ>k>؄uԷ8 p?@UT#5Koio 2މYRDuI*mϺO?){Dؕ';pp;[5KZ>{ؗmBc1C /sbTSdďc[&¤ϔxiBs !]j[UABɘ>_|yoLr8Ü?g_#C'b I=t m.ZNW`r&m$JvtLc%n'Jݔ* prw_4n4Yl"wl47Չ766љGQ#9C3mӓe;sKd<=\$[v^Ԥ1 D,Ss,ջJ)f!pG6cZzM:JJi]^-a>AV ' im.8T9<*b74EyGE'1I o\7s9䯜˶ڮG+$yKLp7F7ڍ\鋯gAsjߗqm%W0EHC (yOAA89u3:EI\r4 G#ڴթu0*G9[]OG1lpKz|x$ ~ Nм]3]iDn0 1E%73- [RDxr1CvS؅1-ogb"} O1؏=W$:&w8|"&lUHQe۾^M_$cHәp'<8yp8Ԉh(jHrJ~6,Jy@(ub6@ql[iA _$uJW+ѕU!$̉Gv6ĎOm:iQt!an]xftlL?iZ] z gM™'jy'AMd*VX-ZuŚߴiD!/fޅZQą+ac/L VҖ+hMg6.zH${#T7NfO~N,SO?}12(txNCY2慶I1 zPy% 2$u!sO! `/yJ*WÂf%|u%"do3~hzq i;bP*L~cB{ZO*2!_X-[>YB#8}A5/#Rߧɪ#9ϜWz_ZsK2r>I?A~jA]"~X[aا'^U iNe0a:uc@!kkZ7C`4HMú_\"Xz/ͭ[w gn'iv͜?/hG I iD^Txx;5c<8YrP5-[Uw3r'@fk]hL WL|3\Ͻn\tA_اݽOۤf͐Ԕ"Z(zX$4i0WV 趓 و~Cgac JŃ@-.b2O[9N6c4N&쓼C:cy=eL$f1ۘf1Iّ]*9p{(9`Qh>̈:2mɹH6jҳɏ=M"I낃Qm3tTj(=̣j6-5f\ )Œ0k'DC]5x)8ߒ)Z z&7?7|\o;C,`")~-W^؜춺b=ORoS|xqnA(H5ƎjZ.,& aɑcijeJQKlE;8lğ[X,D:/4] -wҫU{R~z7Aڿ]Tmvݿq*V(2(}'cJ|vk9=y͌6 cP*ұ:;76rג&j le..}:1!;RM-?GYztxY# k@+v9G:Լ4qO*v7;awT>+fXQ\$t!czc!l2#Am>+uQl7麔芞 ri#i'҆b8$5_}#Xk&|;Ue;pD 3VLoHGa3[6Bji&(!3╳e?Cw!$[-;^Y&^s)p'o з0:Rp$SFVVs/G{kIs&T gli7lEb2dP#miCX6cw?LRS=Y!9=@`Qy^7>i5.+տ` ^:t\oh9J BQVj1_8ys-6jH | ro#r|˯i۞ y*8&ScJLV-+omne,V!Mfy24#/ {ՙ6OyŎ| . @ l;@>X/.Repi|A4ey 'Lh({!wթiP;OE<&DئoeIi9`XX5Vb‚ 5` ,h++,FutٲŦj5I yH->^.8" ϑ{$15l_`u#B)&7I3Mܛt9N-K/˒On]~VYHmVIރ36GEJ|qmEEcvNT(ԁf>]dR \D EB̯㻱6 ,ݏp*X-:*<:4Rw5 ɉ,U* hwJ|64݌x H\#t/HBl P V7 G"g5͏W^Ew6l 5EMF0o =ƚ8/EJԾmz~ #n)7Tĉf7RGPT =sqIT$ .gUuG`Xڙ/Ĉt4?ͳ\b܋fv ##p7 ~!8M4e<"o$Vy0~-E@v}H+ݥ 4ud^q-/}33y>(iݕŨSc֕ʖчɓ̅cZ\KPyR$$$yfjn_aރՂ,j~G:̀Ӵ=(^ !hJ֛5AkEHS$k9KT]l):K64[8<%y5,z/d]j˒ ]<{ѷO؜]QT;yw7a.;,=٭Gȃ"#h',p*l+$*et{eB n=k@ۉ~Wg8cC8X;5]4qԬ;#OkWIWE!av!I溽{~b_;FF.i(]\XʶsF0'tG4ċ,2jrܨeO%Epp/oѯ՞M&ow^zRJ" "?? }8FSC02m?Nށc"vV =| :772~M-&*|_nzZ)g]rȉ%{`1cF(o>mʥ#8 '3 qf1XX"NoZ\rQ.sdqa+2lJqu~te]edBa]=VS%vMVwyHd3hFƽm=ԽGG p!~7,")0H=7'U}0L^h!ITV re}ާ ׃ynjl  hn r27#{>N5Uooof/9=D,w9ٛ?v덼y1o{A)o(yi?kͼ9_ 8W^z g|u 52vFhGZXyޭRH G+G2~Q{Z"%ـ`$E~mIOѤFo`hq[0xD⿾ȕ6Ұ( ȫC T'GG11T?ؼ*̴;Qn%aI >ȥ.r=~oN䆭<8| f2{ȭfųYql 3PSQj;IK&e :+4d%rؓ!G6,"[ $*Ҵ!v1Qi3y3W.H,݄ ֪Ncvu>2]r; 6;פ|ڠ/kՁEعm(\.w^M)ȶx\(iģPrMͅ[aL6d{/ qs)*ֳPp tՉ$^sB&rATV CQ1vi@z%q ]ku)`jQ;v#5,XMZG]uO7`m8ĝ礎 ]c .GK%d#QCgwT?`x.K"R +$o=g@tB7}p4cX%@旟y2˄إ_WBOˊ<ȱu^V’ꈦ^Hf!H#P`ɲ$U| qlvJy~SbN gjbIQ&+#aDm۸y&Hs4FH_soIWc|5,(ދg饵4ddNO5JT% @uXs_`kH'YPd >wCI_D`R\a&\ɸ^5߄k^#@zq}X\ujgN h {H$S$ 9Zwxع76݅fv2؅%Gx)C݇Fw롅'=|0!sh9:.~Hh΋LLh5ӭ?ӅW=ʋ"NZ5=J`0`nb%}HOiY*` ~yeSZ_m@b_9> W"a]^Ftf萨vU-%sƭGuwғ>,r4U`pv$*jC+33CT59jr^+,0mnS@PL>x֛.OVq#IC uqu{BϚeO/VӗL9c.D#!?wʎ\vTm8M<  I#I% BMs! E`'UR!E=}W'c_cEgƿPRތ},6)8f Sޗ_9}흃ktǩ 2 ޳ [+G{ᎃEg~$K`fj |A-qt?8dX=WMNz""O3B|~ t㌎7ot{ cCU+X2)9za7fy%pCC=3};M`/S1r<*s ß OOJ2 CiZťq5{! 4M}Mq_EK4kMkIi@ t F7OO7 ̚k0,֓Vd3@l< W/I܄1 a Fvt>iz* Wz 3\ɻRk -_G(;|`C\}p, lɀ3k났R®9nK&E8؃ص^,/6߽g{}d[zاb=+p0'Qk\mғ֦ .(ܖpovu+J#JiơN٫)DL\m_FǙF܎PO :uyoqq CeXh]YW)\g7/Drz>=1[F0Uv0k;CEנ?D$]̬BWNǶmAzr/r|d='XO25fY~Ѿ֪bۚ:2ފlF`p ̨*{f<#\ ieOǒ7Km U wB!av{{@Nbl9j+ 3:w^p,ƣyiƤ+̼17u5_lPmN쇡J]_NϞRA}[v u5;K8SZjho"Òx@dd)}>ƚRXo|DKLMNPu_M#< =JVpdUuyڞ7ү)-6VW`Onް_+/TDq1$037B2+c&"h'G 1:sR*!V=0O:r;=OUYn*JU)C&Eڠߛ7gBޞ-D#3xNyEGk&mԎH_K3q& X"Cz sBW)k^Mn+_Ĩ ¨VYo8s(Lua*70񟈖a-#ix-7|H.A_f`%/1n.*)j1)wN~Z\&ex2 "&tb5E嗒 F}-P:2.ME'a_tKBLLj\R2mݰrComw,tOY\ \Þ!$<.MmN218ݾM NC%oTCT_`;7~9I}"{g3{DW@l^+W܈MzST^sLb+̗dS-1y8(}4-nb%-8yҏ. 3ǎ8l1C~D_苬 2s,ڑ hJ#buvxk@ SX`'oqOHgHZCq}nxk QzL]ٲ35ww?9rVU =*ݳk+m@eik`96`ءn:WAfB.scު>liHRw*29(&9: d}TYɍH 9W>z_9 o r5Jo[~ ï(נxs&X^&} |{G ɠwb8fRXpXZ !AF;ٍtbBM YF}c<{)VKg:Z+BP,Դ1.dwhIǵʍN&O}F rV@ckE&֊  c#ЙR!'"76۸v HJš2UO|HsRV~VFvX'OFHnk\JO5_6RI@5Hm,<_tyI(ҽ2"K1:IIEGxOӌ Tw/x늛P%y  :N5 W1!3eeCxйm?YKsEuV$1%oÊ+H,Uʥ+Ti:Gv @4tAҨeQhHw;c=u%>4|cȡKBc,zhH#ʧ=[BBX㥳|{ YBZjlD ͪHu΀BVy%C붖l`fU(8 J]_h$&և T6b֧|6/#f+fpl⛃leu3I!"[]AP/c*Qc|q*xhMǡL%KdR_MJ.,LSen<)}X(OTՓzX1(.Ҫg}˘`IYA<'nR@Wz`djn6wFi\a"Xp*1"Ê5jfkpk.(&~~1Iz@ (Y\vGì 5CbHx!QV~mo=6Ԉ"3sO6筵FǍw~d3*ѫ+"exIUEq4\?8d-+)[(XuwGW>פ'+_AxX[j "XP?Ѣ,ñ(BCX`q#k҉- 03T "zN#lS|̔4%Lc%. oZv !ݴ1bY6x!cs`j9)UO8VqrNjyy_/RzD(>V9^A1󪠃3E6dP"1BWk7o /j2iaaX_ԡݍa3~UL%xWlF1Z16h>)n^ 3z[Ǐ4o_k8= b 2= ) C6 EbJHϧ1@|:۪jSkd-PJE.QI~jzrxS9҆^ "G?aI\ .Vݸ:Sݎ,\Tmt'AS0W׸D|?PG [F%f]jVd q `: KR\a-җ߭ 񡮋Q@S걵v3'jf렌0RQ4Hx\8D= rWƹA)i2~b(T45$x0BT9'AbО_)6$[ivW)`KXj c%XljKjYTVjeq7ޝSyE"HSt7M(;`-80wz7н*+zQ8YuC ٤w0pCGiƌwc} v%nP7 ڇ=o> ޾='iAm?23qdLnãdv(n0otdA }9ӈTQKb 8&L$PX>U կhCDa?G env LtC97G@_0>< .gJ̈ 4&@raGƾ.+dYǗ }w(2UG[~(_xIX6.V>dV}ω(^)bR"#Y`4[Gd̝'&@C鏷Xܓh u{<+TbEgU: ^IymfA8Ak=CGj;}彧<\c(qf^U) Y^YɫeNeIsTu-Dkɰs^慒Y,Z%X!{pp9VgBF?0M}z܊NFɽ'0B^>6?+`$8C:tG?x_3@heuuV3t,UI~rrE*?y̼UӊB/dT=H 3@Qy7?aGhYJ?x:{$$^u`.&v z{X}N)goJzɉ=9yRU>»q^m@M҇-IG(;NYCe:|RŻ1Ҷq'?˓G=}0UIa7*$ُ̙ r$ps^Y͚SҎ- K ۝[v}"²NEM?^k6"B/uXV*.]&A kKJ_D5,B69*fM~iP݄VJO_JJ PΝ:+[rwъ/ !*XpJ DGf:8Ks"$Z&݂ ,xr[ ) p0QT 5BT d8V/++) Af=L GUkBLe2bXVDd۞RmACd ԬB9܈zC quJךLDMɳ۴~ qkA d;{ѓ,{jpKIpɷ,7 Rc]+Ip SF?t2LvuoZWtZ}3drN(h[ 9J.SB dÿBo"dωL̦ՋlfֱyJ#ZBZ2Wy [J̦cXG)wbA8B=(֟x9G 8[|e)M͒*\E` N`Ȉ\RطlZ4MX;vDCw9nj4tH{[7ڑ1 .' g)O/ԽZfeeq]:,ykI7=iPYAVOW8);ǝi&v:H/!+G2RT 8LRkEtJt"<$u]a$(fTfVdu.nAuR PYe8B,&8w{{\iDD7+=JGBL>z lBT1^LkwYvUxr3*f8WJ:<)xzVSIh}jˆvvR1=n 09_ًˁ4]ޫ>LtC5 \2$*@cFSԬ*Ta=`O%VdnVz^B"G@4;d{+ <Kg?ܦ*:v: .> -D'7ɳ3\](zyLckT@~I¥E:B8nߔ;Y Q,aXa,xio&鐥"%m#άwAN2Ei~eE=#4mJlla\׹7=xP: D{} [dUSƴ 9;'T{8gz80Cvک\2x[Ϣ цϰv`?I͇hݸ{K#gtnʺ` opCqZ ;uEo"P%&8]FIҠZZ <L pt"eD$O},ԴIELѩPq(Ic&/m7Kl4=h ) 쳮m#Z HI*-4` A0 | 0dpaAh>e&|"b)3>UC0dܣu]לw {;_M UB8_o`]1`F@~RbyQ 5)mԻM̒7D_'K ze-U\![Vxw},i>FE4'F-[ q0]]J9`4 UJG`%{ts6R\ʁF6DC ]F6y>*̀%k;| cŔvK}iU C:sd=uT#U/gnww[ eqs̾e'TUtMۘgD(NI*Þ3.g@wrbI͒A{u gw! ?%Nw9.u 8NV\Է#P1Y3.%hdAY>euv;c@84n*F`plcYfU pV[-3sg"0d БbGegX* x9a1F^: +^[`_J\*zkQ}H/4.8iBNhxٴ~ր4ܵEښ7CDKb^퍏ȠmkV1C$uR..>*9‹x\?YӺ*BDfj Srs] :Y1IVOjZ.湝VV9ìF={Lo{~4)y * f-d'>b౺P ~p 0E8_jrd!Ŭwi9MgM]Do TZlL{ +pij+S5`Jl]("w?{ y9UJm4,;IH yE5'6"%{<>F p C~0Ս E욭55H_CJ0Ud#(u*j q6o<8wwa:'//jyɠNyZ*х;)s/)]r.Z 2Z֊~},+Q?2Js,Lr0tje}c_ mN6 = @5rEaܠ$j9WOcΦLyLrO.90ݵVqamɓ8%0QVE rdh -lQ ih٣ݒzA,@N}J/[nd2RH؃PExfԑ%U$tKv'!)4Pl >)5^wSk,;NRkydP2C!~9E൱SJܔ_FDzwNK0)9=ڂp뼴k,A'>4X̪F]m+*&*0qO_&X>-J% cɝ9iTP¦g ӼΣW!3kgZd͹QX v{ -J?<ΩXP1Y:&~I g tqH]QH5pzw>WAȑV-WRsR2rdFˋ`r%D\ ,6t"~+=VɖZ2ms24cpN[dAWP ]i1BfeN{͟N#*jtfklxLN#~习խ$)ap(+IjԬD0IL~CK{Yd cW-1S-$," q&{ʻ>n+$UiFy%6S`T?"x6oLW.3һ{uJv;A~ oN0)9FVݗDZ_03UK8J@')XqזWϏM}Z{$O^k.'&fӰJ365E~eNA>ֳT (}NUƉ*o@ jWgXL\.TEO;9vfÒܛl=cΞR<_ EoA֌St9 xlg88ڦdK" ֊tZM%At;6@C HJϖxn'ڒS6aSgqWcE(dUpâ1ocWK&sDHrbGmn zk4pJY )\'R6! 4 ѫ, ><{g mg韋QgЌ=2Rd[+ٙ(ط/Xx@D⾠PݷJWC4esțV5n3o틳t1zsb'L%0x tZB̟p4$^d@ E93"UW;Byǜ(u m"_DЯPַkVk«-g-W4h. ׊O6oYz(lGH)FԱ#0M|9!CuxGY`;@L<*/+zN eִ^, j?};)W+(C2Yϫa%ͪ JS|~PkX bF\6Prsaf^N2GWš=b蜿 'r*wUnhjͩ]ױ&. Fn\wc z+m l.׸L-ayj6P;6 0MXb$-2٫zjųg#g``ѳM–r- z9^bÍ-y^(ct09"sgۋъV /FdP7"Ȗ;Dg0Yф9đ;p!zL>l9h|F" tSzx0Wҥآ`gf.{X*W#ʔBIC.'v#vp̣xU#d5h}R_RC!<] [jC*Huro5+^ifOzzKC>'e7HNli}{ީ@$0=BN"Dؗ[7LzD:U(6Ն ǵؒ59  $P#E+"hq ?l=,8Wd3F5G^a{j>֎j3yϫf0LG]q$D-XBkM>Pu/t=4v1HУiߩEOmY)!!q؆k;TJnߦČR"aCV4knF;e'N1!D $%?^9 mmB8('2ڔqm&ca6\ݝ_HZ{#OVG葫opd/%w]1򪒩kI.rR=92h^,Ѵc'SؒѵNe𫱵|!ɒuи:$ɄRi݄‹ljJҍx2xˢE%+$\}]tl?Mh~it&\+⼳EcDCÿߟ~G}S?ߦ![C%\]o9׺$YqlsP/OM)q+$b9IU8G,bcL0` ۧz"\]+ D : 89j`Fa E i8^-@tZkJ\Cw[GgvAH=nUz}t4bbEkxIS(ceM0 ;Zp0wGyʿ/gpTnJ| NwHT\w@@j$?̑(b'rC/NP8!%[WoP˱l k1fy/x4:azeҪGIxn%t $_(ѤVˎu &ձR%_!Vî⋣|o~EBzF3SaF(eT!w N2 3FPמCi6U7OFp{2[n)c=2. <1Ժ9D[^q/~_K2?c/4l@BX68!Eo΅4Oa=j{%dT @js;)y3>i+[ v3.AfDƠ>1{\_;n}\yb0}6ٸ?ӊICFKܮ.m&a2Ȫk7(0gPj!*{RNĒH49s%4<6>+FLwVc~5+Ct0_ه,duVuX(MJ ~X'† q[H o Y'4J`I*Ͱ7f̫G+1r'^X_U e%EO`rqwRӭWٵ!mWDx9Z+V8MuTaadvLDǿ[FƔ*HCt)".G6%S+D1R*$7ú ]KLFp}1HI.Syr)KTr i~!0I76 pɆw;x2+ص {AR/(4B#8HUjde;s ?ZF?|a5w- SP-Eabe}{G?b8Þ;^]ߧgщ-WchЉN-(KNA/&7AmBS R7bʽS>j/%wϡ-a4+M!@tr=eYsQM4نsq!dRY7K=!L|PrM%puX ,u!XpZ75 eE9 ׌p]5?fZ q{4w*fbH^l\%f V$(?/t%e'@#hmPT0 -GlQ#ǽf;ȸXtGDE|6jǏ=C$i1>Lc/ΈVqx`rv ^FjyxظDr ө-&2o.Ďڑg/ [!zݜJdM>9>슪y8`.}s`,3Q9x |1_!giXuUU焪|L`Iߤ[69H~j̓}jչ0븤Zbq͉&bPgJ:AAdyhkD2ۚgif,D<†hlutj~)d\Uv)JR }"[=+dlQ E_Fٌ Kϼ#nMzBߖ(\C'ZxMbLY]_zLtDo*xiJwTW.Aǁ%w QDS)t$W!W d ?5z*O.(u2*,@"!ӭ&+G3mtAԔumZО@J"^ĝ=~Jp񝪮Fkvԛ(C:#Z㝰y4)lmOJ:&F#nSswaް s:,bߓ'c^%XXRz|⛖S L%5|X=[>ܪ܇(#ԈTV$#887?u$#Q,Oڷ m4{ [Jƚ38K " GOEFu"W:E6-?7 1ptfK2~^#GNq3$ـrt?TjO|;,X-~/Gb{dKdn" a!A< ݇C9@ /䀫ͯ\TXRG$93u.α_Wͮl1;஄;23Fgjb9/ʊZY-`y`2 ݏh_ٚ@[;1dsH=@0:ȽJҍ5βig{ y+"_ 4Ȑ;Fِ6qy.1dګ0'< i"0~;oo|BuiOjG(ajck']cUh;[BKӻʅtUғ j(.M[A&pʩ}UJQv.qGLpf\>W2(IY0¾yCo,D"xaoޠm (r~tx[ꄴor8d2:0q3G =o7W}OjJ HH"yq *NqC7^|gy$O砉VLmr&H46tH_3[RMyCq˼2'Hlw i#E/ 0t_9q-\K/H^NB8)C[Wl> +C a9?ebL/{ UO,ouD&{2^s{ړN! #p(H$ {&tT}r PJrF?stѥG%<&L=4n6ӭ%<}_ U.EVsE7[RzM |fӹG YHGozZ[p^ \;{16ï0gVt*[r2\rمNH?>=伒Gr[A,: ddYU+q+?kJ`( ĒA=[Sh4&_X1eLQ_A~8C54bYT ǔF[Lr+TZ?g6mP-?1S`:p?. ];gȼk @Z; I^$dSW[Hi0Ϡ#uN)P!E,'6A@+R@cdJ]"soe/yZg2F,^Le[Րu9Pqِ^J\K'> ١Mq苃s[ $=p>q+jɛ t9`7pW+1iޤ$cF( X.ڰ͚$a0K9op,_ԠĮJ;'&h7ڝe6-B ;l۱zYqTDŽ9VE)V.YA5%"[Ԥ\d}c(~wx{H91N?J2ܚA).S[sh -?V8I#S A^wJn%x6@'ia㇠YdJ:E(iѺXLDekw)y`Lgw"Y)` ޷GZ / e6;W_A{zmWd Y2,[^u Gy)Z >Z3 ƙ4Na5LyhIEFsJC.0d#iNˀnPsVvtm6yD.K9j`XӏpğņDgɆ RhvAABsVܑKMvJZ kBچ0qJO$N {nFĦ1X~z7@A 2F5+iq(j^`/Gnum#ys&4zI;SqzYlxzt4 ,USliQ:*|szt]KG`vK_R'c6ln-z I8{/ͿwK,[a:< XZ)Z,N2Ϩ5YyyDZ6ū_0" Q.li ]EԱآ8s|0^z]g E4sc3 CkPfE4> b]?}X_o^)+1NW68]#y,8Dg S-6'xE3d֟.uM`BEMԾev&$KTZpNTjO gXgh n&~Wg8 J 5M!WG,9g WLR5u8E!SsYϽ$Ռfj{V { _13pIjj.)Un+~Jg4\_0L"NOf~| ,ݶx!ΕwH;~զu껖Kj9E<1tkRM˷Y!4lI} 7"#>Cms0 sıs㷱죺U/ÚSյH,SBQNN$XL#ւo?6uUO O4ZuNx<ʞSeDԮQTST'@%E~_Ε } ?0g1⮾zKίMQ N>aUTJ8A}}DNrCANltY=xSQL au^?x T/.;xTkq^ g3]`E/|F?$# G+aAA˅r09lژf  2G4$~?迫$ GhT֬<|׮;q&]HgMG}+5z]ҥ`}n%L*twH~ϒ6D7КlH8l0R|hA,S{b|ɱ[Wȓ9+}ercw?|4dnӺ\ʇrcER4Mɛ0DZK)՞O:  *rCcF6l<[%n9J;_b4+&}݉R9 O;tze3ʾCR*A)6Rt4yZӤ䪏T2ikg8&KQ_ Kp#@O$O+~qf^- OY_e#m͑)/PM9ȷY@:0DihX8P y^j`Xhb^O@~&>mLD$.;إ J:ZtB o+WS&~{OZMu.aH2`^8Rd.QT YusOż2#$:pGr-D6%Xٌ娳?/Ƈ#cvL:M9PPoJиBIlĬ'jgS" u~Yv9[L!X 28J^L'(M!\u-UvcW&9U̸KUVD}'?cu7Xsֿܔ!RY2 }:,_of iPov@ QˍSmcT/̶ 7EzL' >,B1 J祼0&PSr2ugȺW=:Dkܖw,K_Knx )0C916y^VXB75kUA~9{\6F($:JZ!'杨`bRP-A\\=Q PT[ז/C< Mh{,W&+='Dֽ] 62uΚoD?*H%43ncWγILh쪀b._FW3eAºQy5#e1qUgQP'tNZd0*$M Cnê…knƸWvNKLBKP^gԘI8^f6t"rFmWv/^ ]D;66 2veXstNӃ[|VatER84zy+<4-$~e:[|nl<@L8m&CQ/\Lf9JRH$up*9o okw(}Uבa!z#Je0‚U0} An9՜w5< ȡwEuGqM?Y9s6/wFC#Q]a3I$E#(7kk؞7>A4 lt{(1SutQ< X&j1 5=M 0c^KHҷ&4 wE2P{ŕzMW ^G>PW7g(=9Xr|ub *z c;3=_[ 6'HDo-f~h"C\G6}[. D7ީV_/#v pCʐ9v4˶޽ 32|;hW0>n.S=2|6-N% 'f]%/CluŤX2sEhR^Iv5Yiҳpᜟifh]B߃=ĝMƧ+gk['6k'Y|u*ZC$Oi0/bD-{;}qI#6 5qˤo$^OHi6f/ Mj"R4mmW>D?[c"JʣR} !_?KJQ3K)~@Qڬ'>q^CSuC p.ϤF4D1۟za;gϤ cC<=;;MHIyYi,ՁMY·$2W20vR me&\dI۶;ʤhUI@/ \\f"ev2 VΉ\ 8UV\v^c;->i왯H;c⦜:)~!'Fi.S֚<͜MsO \s2>L|L`8Y,{[0:Kq 3i1s'7&>,"2f@R|NeB\h[n"jS,ecI3ShFFQo I Vi Rn5G^`"-So/7!}vؓK_06ӑxU5Xo"C Z[HArG_'' u? ,AM/'Qy"+:*}$ 3#Y>"T_}i˷g:Br@fnz5u`IkЃR h1h_J:rUbG2M<]kz1MOA`GޜCiP@'{BUXY^s>0O7 W 0HֿB'bImOO]VB"Qx.&,`ptK*J$j\tLh\P}^,"uPofl( DslQV:3eAhMP+;zr\ 8GoUL) QBӝLE&"5Ngg89'¸)%ktg {K&Be<Śtq֖I%w#x(e)!j 6*pOO{duh%pgwbB$c_DDy90ٚԳɫy޿ђ b5 2(T6QJW-SWMu7=2`˴AfY\u (F|'O.. ۿ; fD8#\ U,^:'S^YC 7إf<o!3}c@@3Bb\(h`AK<^_#0x [-KV!'Il,p:6[! \K-@$9`O_G>4'Qj[clc>볟D ^Ȫ6ť;Fjuo=7Ķ3ߢvafS|tGҁÅ)"$%)Tc WEF`TU<]A fNe P9Ct>V6I9o}˚HȀ?\\+ yԗ Y"Ο+HE+ 2c![`xB-O͙(dY*_tdI(s[j<#jjEVmsƟx4Y9T l&܁9yG?]1k7!L (頉? "~cP+N=zW%ݍAr9,Ui97J.c(q5QbTYM0g%U}w*U-)f ƹfofП)ܥI 4dqkI g<ɛgJ9< | O^t(iS'49uNL42.VDTɺ}EwI[ n'oˍx݊ijѐ/3ٖKRz g!!A9b` [ǖJ]s^1Űvqu 1b~wQ*KF*FzplZPmPEQzVW!]FS$q:5S$a_ЈCyO}H- T{>׍%IYT 2z 7VU~_+7ˬ~ ׌QYL mn]͘"rDr Ļ( FE;i -Rj\[/WY6^+ o$cVZ` r*9넶[XEсA o*e1nc<5 IAL+vk!rc*^EwR\P⟺ Cz{ ͏"m^,ͪb5jpG%d)ڳVJkxe !Ju|G^WPá1:bp(IJU/E&_|T\p+U gqh~DoҙoD<I>jF/l@I$Gk+-j!q "7tyYq}09$9Ru.%\<Ƨ0-aUSLx h؛;SBpdWCѠ"NFSxAS Oy(k" {XܫtśV:"Ί8 N XlJKĿlS0c-\.0zwe$(;1vGͫ^ɿGvng9Ttub.SYHE]0؍%hgCn@vD DQ4 S󚒭uE] Ns788mQ܀J-3~q6AIw[x"qXO ;؞p 3,Ȋ%qCI wx 09אoaյURlZvm!U; V-á^0= H嫝U(z{f?ù8QhO Zy]k6&Q_M#fRATq}q.CJ8M#j:;I^_iG}!+VZm[ Kuq^[}hFJV,!YGHc!RTmQ w4 #o;zh3? =Կٵe5qHt쎣Nd5'aVX⒩KLY̪m-b 7+IwjQ>'w 0BM.TX/~@)T2*-'*6;aC_n"lgu512l|!4yЄm?(gi$؈_ H9o4=ןU!F6Wo" \ %\ŽS~@PqsلxD]' T ~e\Q{c4c}-N%:SE:]IA5?Tٸɪ'ʴ<~ bWhCJ#e,/GSl¦#=0 ;"I3F/،q/T^P|_"X_sVr[U=Qtx;=MU9],CkOXCqaRL(6J85r8(]u,]VaLrJx?D0ݏ |aC#8k#(GJuC0h')^es#/#MlWes6Ö1QN4=<麶",`e (w2|,Fx`^SqXYZTS` Эx& h,APsb?.2H~24 >:|2&?ȶoޱF'w'-7 .ؽmԚ?R#hUC{yǕCKu3aj#yߣQ }fļO@(3CJhQxtj/hgՂ߅ 0HhXH4!/ $A hC<~ϊn*RW2U5D5WXcHJUG;HKJJh)XHBc#>T&36Xbߎ]$YXL2g1 ݸ`ŝk؁]:/>"cx<)IAs/yr_d>'i9ӷG{ Scv,6 H+>z4|B>$\=]?|R;R3Y K䣙MiTq-;JkY{64Ҿ]ck3>\# Mڪi=tDտhFch('Eg/v؇I1^t9(2!<ȅfVg\5m1>%}uA2o ~ԏPɡhŶrkCUDB%SH|UI')"qJѾf J,J8R 9 <8.IH‰¦XA ǒ nW霈ub=s&}`0Qn]Ŝ(KW1PM2_Ncw \'#ިXgڎJELH)1RhLAAN'60BbbV] x{ qd') [~,֜M*G7bf(CI~E6,7XCԱEq܋B/-ϡP\(^sGhcSak#iJ7w%r3}TyqV4I|z1RđKC[Hnj }ꊒxB9ve]q^+pDeyAy{r)5;g O;'nA`>piܓ,`|0 .2ZЎ1^Zi7tKKR:ZiH!|, 6w21eU*ϧ HV_{\zMx Rw0/>Ą&jQ])95G¯4Nye;NNTg#֦m$ol֞vv9sYMD4dpǒwbǞwzծ:ږ\m+YrYDYmHp8UKӌ<`Pm(%IUE4f=L`R@SHݘ03;=IÛE'eeT <DoST3KB,q)i.$ &[°s;DZ$&XIhb~1B'zrw z|,W;q%ދNK8^~-O,NRn~#,]nv-~ lYd I$'Fqꄉ:_>{tW?.V¸fމA ,^YD3i|ߵWO(1p,dw&POտH7у@#ߦc^Kj߳O\4PҎ̜ڗ"աQܠC[~5/m٭Z__Q496E2a}MJ{-#k~`G:.lؒrG|B[)؈!] 9[纁B/.[d I:dQ4j M~W8 T1ly}7nxi]"ueV&axۦnviwߝ@@Z5$,Tx|rf#mGJ7?tp7"ݙ>jssHT`2QF薞?tq ;Ios>,6;"ն<:;=҈@ɉlt;vݎ}Ԋ_5q H\ĐD{9up! _V5赵S^m%Ki_mR{u&Wfv>j?n?Oxe8Ψ@y-lйL>IMĮ҄?$(i=L !w7}MjuPa}gu)DSA~tf}Yg.nY7yi*k}(`%9 >mSܒ@;l6eۈe񀋚;b@#SlQNifCaA7:"<}MQ>X8duBӗf)EN๼5W S<ƺ+&_JXN(N'>Nqtv Ɍ"ͩF⟳4X Lwu{(1^ӟ !i!Q BzӐ*˫ BMePe}NJ m+$oNXyw ܞu^l &s;d^%r,_03T)\]>hž@>u8\5. p;=DwD<=y910A囎E,%8y&$BRy|re N?ȧ|H_؄$V5$& 4o 9^RRY$O^ AwD: 9W,/m,rWl{:c 'E}f#@٨o'=vd|80'SF{ut Ѳ4 '5tw9llW\[.s9q # & ƾ/|䵄qnu"|YK{EEi-w*i5~_H$cΝrj A7o[LM巍ܔ`}ex29: 5Ubk&N_LkL?|=pgr&ap&x?b\u+}ҾN ern ^籶"sc\w=@7*YiօU/!9lp H1eá6ϰKv/odSHnNc2l-M}l3Iz^?E q5xG T_.|j9$1@IY)N*?ԓf[3<80]:AJCpf2=2LII~z̩ s:Iv].:N0#j3chħSt9lGgT˂m %t\hufnsDڃfcuSrev29ާtJ2^ 1,%%v/wV2).D ,u-%gNjf ACd[\/l{͈.g辛bF5Ǥސ,~ Lb7<8?o6= ϗ/rα} xx9h=$8]wB_/!\UB:eT)Vl[#ے}}JIT^%S(hBF=)"1B0wd!(aN:F|8Sw Jdߢ-bx^g¥~m`kY#uG9ݨnoR_W!'?18M)B:!;8IsAc |HlDۓiINa .}:}8Yq1m]bO,bOa\&/m-]5:%/ǫm@K MVP>"_ؤ5{Y=zx\ŒZ'yH$3%nѷ'4s p7TX+ǮʱtRsGvC`]I дGm,{YU!oQ3]β5U?*N뉢'\Vӄ$h+AFM}v!97`U]$ؙn^" q<8K@n$*a ɖ#F(VgkfsovNsSrx:3x Y!VM9s߼9l>EoJU#NfpvRȂ0^q2M0}_2uo+L0Kf|#t}+;@˼v0rƬ?'p&'Fpku2 W͓'4P?;"d3IefxKS09`5TN "`@籭[xC\VX֠ k&50Nb5 šs.TDՊ&%-uG*1 Uq8:>-iH2ye f.@7u yV3sB#N9dpuR?odR D$߻ٶBP,uV)sk7W@L'¿y.FݴBb`stNhdCu|Л haJ`rFps4dtK[}Ki7aLTE2?Rr$C0Ssz^\aՕ~N\7O;ƘILR8ihmFJV yGDv's'1&Y͐|ѵ!UI=/p&xngᅾKƣiFTb}vUX q;چl ?z{m9տU'^my\y% ?j#)l6,Lb;8T0da_^+zƎAVnF&C%KGIŜ2vB"XߪNV3s0^B+@g[&%4 D؛֕ QG)"іY+c@Y+|.-D 5V%FC)(-.|}p~$~ora CUlV1@Y$~a [n~sO!gɭزpȉ\Hfr4a ˂ZYT;Q$սS4٬B>tWHkgw767 =>0sj5s#n|O+ }DsYkQ64=V'+ Kહ$zngXaimab+kG] ÕJS{=b(5զf]|cPWH=-6cS|d4%ȥDH bI%xb-܍~3]+:cF#'5:l8*O2V3/{˒F$\ 2fGM8"\A~Jo뤉zP`Ő;ƹ`Afr۵!ZASiP;2mq0Bwu>P齾KK-LW%'8eКltAN!2g "U܁J*bĹm\MJ_ #ϒZԻZ1w@)Taz~ōl&C c;WO٨=s[g:P,ujYol2"?ވ Ҵ]g{UmѯZMZ H.՞`7wxx4rax_5ozikdfķ͠gS݄ٟ>?Vi?2Y,鉟BU(J,*f/@,Q0I\nDN & > w +_< |xX?9st7,gwYe}ރ:Z9W1{ ZГ{tKJl'-fj%KH8!̃+D]\;7ھBHxˠy}"?8`M4Vcٔ9q ok3' ʕ}Y:u^Eq5L''br?NjvQq ˽֩( H=Ѧkât.ۚmqV]5xŰE[ KCZsOY=ԓ-kop R? ,ڄGA3-ym Ýp0g?>%r^lT,u)Ad9?m -ڡ/)r" m-/wZoD֊+s>UԌ.^jR x|4j޲`a4>u `$TW 5A S8ruh_ ~ibĆ ۢeksyx$m,^1C@ W?{lcReMI͘ Tw0E0ڿ+I d޶ٴyܩ\NNbY|e+8*W]7^;|+׍nҢ~PËŊQZt 9>'&Hţ(MLgKMxN}FTs 5U'K,APK~y_Qsn] @ǻ|x^Ʀ!?٢UajlgDFwUqX|ZԱ 1< 8єh6fָu%SCŠ4Dy(Q*o?z4#x:LfwU+ztp@@LwS)2%bNgU |f9q=:`Q7]Gi\{KX %6!JhW[Jy10K3פ_ׯHuIƍBQ u&-2Np6U W) NɍzQNCN]XPEX`H{-&#^mȋ}s ,X’~ca7|k^D$P{a"IuTi_(?ˬ$twB7:=TvBګlXTj>رEcANІ$/ n7v\] \ .'݇LF|DlK#1K${%P2ˬOGk7 us>-X~wv{&%~+d967~a †?rw?49B]୓"Lw~{<Xu.0)*jg*!*HѦoKWdA bX`4ZT1Www⣮"f*NJ,bo[MX$e/}Ifg 7% bGK3$7TEGEc$H\Ie|̭$~ZdG9^삘.3<~e?M.iѲHD1]͓*v&v=c۽gM;u(Qt4%6ig3XۇGLsno!3&d>-`'nzc=>{d5 Њ,%(y1bj[nTeƪvILa$4q'z# ax 1v0H?dUQCx"mh5{w%ܤJaG;+8ia3ϑ $7OCñL>msd㱑ic73_Q>IUN8N)4j| Gc]'t)O6;<^iL߶G6( kqz]w&ÊkeD"ڳh^+ UeEKEFhi5u.mBgϝ~)khBkwUy#\ [סXq84`dZaE@ׄD,fFUݚ&ztɦxUĨЍF*e荜 i\.茰($k\1T붤Xɬ'Tc,*h)Y݃U#8art',r?hT^oɒD.oQE!`:c]diG3"9DlSao&}Y,hytq h/ePN3.HvV~ p؁tTs# cy_"%.C|p%;|=71bxLi@ 2E2h7V "*n&иSY !#Q͐o1.9''{Nތs *\kdWX}(M Dx5Upɺ5\ʎ҉9,1ow!܆>M/('ܰ6xΔv{x΀zR\ *Ƙ,Y+ysIȄr2v4-*Ȝ;s̱$%gM}UjV=LKRg0#oGpxad$C\M^I؊-}82OLlrِ=$5t?Z U+J}?v5Ro d'즩6SC$bk#(ovS2ץ\6I$'At >{}Oj]Q-f{R +h T b8l PSy!E'0dVxğӒMߊR1շK#)T"YR|_-wEAIK'U%ʽBe x;o\S6ݡ )zȗ5]@D$GLEA Nd-.J4Mb?,6 >ID<1` +? )>g${Vnͻئ'5)+Q7po U`r*߰#Pp,[ @`Z#o|n5鷦:}wvwkac$/.Rojݷ/}nI( ۵t TJ NEzvPK_^Qb$Q1w-L+_U`wAHR،ჶx5Ϻf3/L4%zrfFP1ԗʰ&i4Rλ\Cn^y0NSd6*'zT|K8!p#nPϚ93=d<=:Qƹ4K=m̠2g#R;R#CH$$: "?< _tU_#2 lem$eɆ5.z+ %QФ~ͻLȯ6dn \I #$Opq[&`E= %+vY6%;u&^6w%+ @p]t0CpF' ؏(G\1.'9PzrI nb-/hʮ;Wb^ E'GWJ7#ݒFBЈW/5$0onV*s =8=Ft%|{aazIҼ8s G̠!Arz׶ֱEs9n [ ehT]a?>}3}Vkw>+PEu-OXБt_η2=1)hM`g?Lwj5%2OCD+G6a w@R쓂k&q鴉m@b jHЮIo\7UM)+9_Xo6ǎB2ECLa>G&{\.+"gI|\$) CG4 "7}bC՚BZNV wv Tb]*? D:~aT/mMQ$y(n ! B*XWHk8bʠd:<Y;Ai2M*ЬL6k!! o^ T\Q03| on=˹hL~ + N/C45ol@ h9pJ#FFC( $Ba"[bQ(<%}}Ƅ}f?؋(BAo9RezF#b&Ru!<*hC{:(~UblRqa[+=7פ/C}cq}U`>ߖPk&lvI$Y$?SX߹dpĜ7ՕQ'U>~y'CHw {Y0ǭ1G9jɢ]C# 8Hoēo> 7ua6VNR>T4L9PvӨǿtMy5s_PF!~ 9Z`E&> ߍfw jS3~r2nCsh2ml*Nd [Ԯ t409L2oZlF%hG1wm܄Sv0;. ̒FU0'Rz$ć쀗,bPrlx Oiy[ |ɴSo]mϡoC-sq/InMa]#}-&!`@ƜQ~i0dwJ#zzV܌p&īɴf[#'cuAO>"᥿tRdW4j.#D\h(ybX/O~JSTfh WUӏbëZ 9fO5 `jk][wy9f8{$ FG}Yy0ƹ0+dˑ*RWEjRZ-3J} HΓlȸx$G*B)>xQ*䖇$H8{gfvhi6 - yZ[YC KapW[O*Q N 73lIoxjf|"_ iOyjAˣ>³ `1)ެBpWzZ{ɥ'߷C*e}5.=@\bb1*ۯB$$?(]5]%j/iZ#ej;gՁ&&չh ^AJ?KiFN֧}%YazL~58%) Jr.:ϞFOPS*y:egD͎PD$3!j,6̭ɺ+\<xzs窦'6C“qE=}l=b6pEÛK*r/3)zİHؑH*F̓`^qf* |}TrB<kgl_|bi lm|tFrU#)+J%aSUٹb$Ċ+-k4DHuD䖖 ]=E8=-ɌZ5@ a։1MT @M(V&Ee@ {o8#ճ׽Τ\| ΜY31u8vOuQGHPV :zjn81K]$+IDu eNkdμpbӷ+Y~#[div%L&wcV%D EJ"Ե5 _*drcn8jDP(,>آ:5O \i\yNF*Y,yAs1r{HgÒ*aU$ڀ( iYofayT=>36mI@;/VWO}_³@kEyÊ ɮղEJƚYSJ[sP?4ԺB bC?4nh Hlmd|̡d؄Yt;cB! #e@8&Q;37H x&o{# v]@ތamM\\ [=ΘX׺OFՂNi43X@dvK:}i͹N(򻨩U!K $| 10зq $s{0TMۡ%0Czkʯ/0D^Nf^x?Leœd[0 .Y $U/U%bmzwRZEDrW[^ b%?~(1\PZk/\Ž^:K[RyѥPT)[҈ nk`Φ6"ݳ${=2<*4сrX@k2+ M ?B+?p`d%&-?Gm,pu U{mPqAD>q5 yiPE])?ܠHEU!zm:w"|/|TIma]Au_T^Ψ/pNѽB D3?mj5׉^!T, mݰؾ!L4WFcYe(jK^]Ggu\6D& 2'"PBo[Uƶ|lܧԄئ@Z)Wѹ%Ъ%:Z,z@$,rƈKinbc$?qhŦs\] 3 2/@kgJxB3I&55ev:v8)ɱt*˒4 8ȧy.>Eu,GlQ5lhfƊWqfZaGt{}/nF܍gg e U-!QUYnO_0ѭFx9t1kA~&&w*3y+@w#, (ngjY)VsuMR>D*)4EZ%J֭4cNu؂ '8޵BVOXzn&;_i651Vz *Ćy kUO'wt3e6Nx` dpJyJpfJ!plG ۂ@Ȥ+M!sڅ;ZB00Ѽ^'$*zW dQz6r]v]Qkq5,Sy{q S:D; =3)QHh6kgaO9 Is} jG} IݛN 0q%|@y /TgT\0w!:=<:D #Ov43wjCwY.+Sc]d%)\nl`~goKXY#Vk`uQjMl XEDQ65naU$e/۷e!|)8,YXٌ]]ڜOz12' O%sR䔇}-=6q~z9XVn I_کݓ~cCN"9!5ϣ"JҲACnxEN1&^ySjY,2#` $X[Vy ˥c?9J-M{*>Ap g)X>6ݵ.i=h8ӘWoGW ]ǁuq|{ LDEUV/CAKhd߃)uC8-ҘX&-z$%6:Ǔ`.$'֩@!AVzI h"w(%iEe)gAHDVH$>TH=-jQ>nͪlT;lJز-mv R|w=#_y¤AC3>dQr8WP[l6]@# R{=La~?,@8IV+KDJ{_q #6E`%&ޫ&8rhhixj{l-_(|Тk9v%gzH< + j+07 [t;!F2^dYEh$^^$[bą 9Qyo]D~#ȺxSYGQ5v?;L ۧMUN7_n!e88x;R\OLV4̑I2s?CerENʫS&tkP&et7\}9?Tٶl =WpJKDN-Ow.SĨGM80kcJW[k ~觃dg~X|fE5\ձ⮮[弡U LZH}،,&4yH~h>^I"P!NT L,g!u!%1s,z+_5iW-`a%zu>~Fi1WVuNT&0f4'_DP9$>/8`rb 3hȷhO2lq3'@|#Ud?.D*F,6SFϳF?9^&O`+jDSNLF^#4jNdy{"v\;FtY&PBQEgm7aUebR$Q Hh.ɌEG7k ŒA i".wIjJV΀ϣa(Av&Lئ8V-i{x+Ҍ@E'9I*8+zx~HkBeE?r8.a23|M=VXfфVO.'_$SLE,={^Dqx%lI0ˎ [ao7-BmJLbD&Gs1q| 8踺4!IuW,R>L0iDbK8(@(H^LPcf&P'?AWxEqlCQqzd{i@c:ZԩX ߸4㤴Ye%e'f%c=|ӁVhՔk5!j K4^r|!} ddܸtZ) X{|7V2ol]ztf(F).,qO£ T@VAz X=$OPf}!nmMAH&7/;eZs:Z9k1qƳdEzvgT~21094g <;`);"aM}) !LE'}-~XBr Esv'Ar 62i2֤ɯ8c픾#ǖb5-retVsvW+LpB|9t/h~^$N{ādor -~s.Jߓm-$!!7<B):ipdF]x_\8zR.IC@pps{R Gh?£Ns|TD?F@~0ou M}YeTJS)6Z6[GbʖBA*W;"1zIW ICȟ_* `MviH7W\QhW@EA1YHz19!v()CMDLI^}cIL)%F(u.IsU1Ym +; Ly4wO3t$:KLV(dzoU+iҁd„y$4X&˚.x68|1* r=D_4zS *a_db .R.^*~wZ_UZo!|@=7 7AMj㯉ܿ67߳x]O1NN͡Qot^II,BD)swp unUUc슼7xM1BkL^1 +E@5\-HNĂ"[HVdT&ݐeo_JqR3[Wd@B>0olf!ta ؜`aD^@|d--k)<׃TJS:VqAC$RQz5z͍Vn8ricsBÕhy]WګɑNnvވo7xp bUw:G cL֨N'jMK#[ Pj1SLi]B+\~C8B6I763^%/m#g=6Lpa*.;KlG3n|U0?`Ɗ[Ҽ,s5[8Ēq 2.ŧr]n]=(Lo~ QfT1(FhNfNg_,2VÝ z5c a(\'$򸭛tIFW $|5r8r B=!?]S7ҹjTլq3v_evS{$CcE/`U1v@jK!XU^wrdWUlT i'/|o㇇+գꚔAWbʲ!}Q|[(v[+ e KMGGT2Ia4geELQrZ3a`W_}a>7 cI3?Y]bwɷy''҈,hPmǂjlsD\Ay`JmgXC!`wX N^Aҧ>E"@@ bs"A6 cUݱo6@ I)Vd: U>S9&Ш/]yinks_QQ͕>ոf; X;FK]΄ ж΍QD$5!֠b;1v0FLLv\D&,v0Cɡ|+LeޒKYoeET(-9}9ڋͿ{; .IziܵNI:MYRYKF Bhا9&xM}Q/dNQkZ\7|r(Qt788L2c4^R0̀h565_$tKDhqjU?f?_kL ?n5}0/8|}MWLtauf(4LCusųP(o[#wFpo?x5wkԦq}q57vnLlTSvPFI dfIחpX>dJ}3MʑS[j8 9 %Ƿ0Tg5`LdV[Zӑ.߆1q^ѥu~JId,MAٸbcue2 ?cϪ;.XAj+͸ոN:ӯܩd J8*fGU ,Ӻd8c- R+XL}v0b\CAh*Q3"gf>FJa xX,*Zye? HbO yJ8v]MT#D̊|0PqOK1OkDqf) [tC"6>7/PB6m:+0)Ҋ}\_|s s w*"9"f:_ugL?'&, Z'~o'K.}Chiqmoq'ч.IFmӰ':+ 5KUֆM ȚA?̢ejȞݹ& r;Ib)_tfwhG)-T θD›g̰vwgD-cO۬Fk&I_0s& +sAƌS\ Qs9'4Zz43y(ۼ47M y^-1iʽ+Aq|COu/cj;ܒA:qhK?,hQE{gU!s2J>nU@ H6%oC6}Cw&ea&~) 24\yď{qx+TIt!ԫX4fLg1R9GlJ[JPq,3ӳޛTEUWԙܦ!CB_j ܃z@U.~ɛ֎>9rz= !j2moP6R t[13}Z4>?;yy6h~Eܱͼ> vK/7=tߺeܿ gd7.7=d599|yRw,;^=_y亮AAmAPж't0fd"iLLPi~ZQltiҹbDtH2?ʖk }{ҧeJ4-NSpN t޻Nx/i[OU.k 7()/fK ޒLH%m6~2CWT/Qm/Ǹ2VJ}\0A<}w{ 9.(@jh[u GV/KRX2jq>dvAN׉|YRV1;Wf^e_6׈ E89aJx|׾C7gbݲV,#) .ߣHϥ o'ŀ.dfq_W͐kLi(1rqr?e/mx=/=P\jvcı![Ll k~@zȰɎ a]Dwh|udާa˨@0K3o"3 0㳔fΈM KX^u78{Kt yzJrAMO xëU,/5FĂխ_dn0YPJ #nPm늰1k_MRoh5b ylND#2{ L!qZ[O{6/Ix/ [Nx=eu{r,% H]>]Z ĉ[N\ L+9(X,CZB*Q\-LW^XS^$&בѼ°k`r_kGͅ$$h*Ox*ɀ[S)hMY7#VKq^Vs?˂dfW>2 @w[Hfzqj9ԯsJd.{ ԣ0nɧ2yBi̬"dks͟< B{rR/|\ ,3ڶ7D#<ѵi@߶kCs?2Nd,Ė.IHNvejtމà[Uz[Ĕ~*.琛\{͍鹃KqA4i 9ב? . *43د[vFGڞ}_hRDZߤd]iIHpx][o1*LFp(w&OmNB-Trz1U%[B5,ZrcpI5K|'Zga^jJrj%tI'И\d,T@49F+hjD1V5AXAT́\ܒJ}\H*uqZlF%5-V_6@%P8 ֗@b;R?zs 4B$;H% 7Y1-p(fֻJƭ'&^g.TnipWyDm>@'e/BX׬u| A{f06/bm?v95=},VVb78A+Q7(۱[~ Y(#/eIQ)r\ݚgLN{UOխ;٫3a/Ze Ufԙ\=!r}[i/ἽMl5XcXO;0 $ZE[ƒ8hp3ӷ{\]vXA5B/uiə(%_v vɐ[~%"Tˍ0G(/܀mg3ߊ`i[NϪ5,ͨ+۲ӉR5eΑ'FPrF q@-ږf t t&8着DDK(5;1x%w$U#w0ZywOޕBq Arٮu,8+lR/W쌢2S:+|Z #Nm\Zc*1?[\t5W83: 86lV}Gp¸@oin;^ T6eܯBߎl°xNBpI@m˅Bz{K#N_ y]#W?W #`Ҭux,֢J#_'>bI%eAlBPߟCpb2KA6:2(`:s.PӤG`fnDtPq޵}7+iP_rM ݔ (SXQśX8㞽3j(Tp҄Lqd2s`Ank`O]A"hz&(t Aބr8k_zSIӢRzq",}SлC1ЦoRTrZaЁ"a_nPcRfڵuDS%49٪'XM X#4RE5aQTENļ*>s$5)K˯4&e,FoF#TX(|H xns8j Qchs2JOC͐\*Zc'NM]U 9J޲IXiW[186^Ev7Oߴm=֩N K@m8%\P?[] _:qJF'mޅ \)sbV+Ċ}>o&R2B,B?C|ycU{M_Q&"՛;c8a|l&!O!lt0d[gO[ -;|/E-sҬ4hQE \űko.lHܦCbQ-qJ&c:룕>P1E*e6iy*H$[~FWQ=iD *CN|oES҉O8\#M^%9\C&ڬYPiAφ' ԕ(sݑU|`G:g#h/anv!J)fv'*57vnd'PQoFǪ~0W7/*eowR ଢ଼Nj\TG0WL6)&, ť :z(Y3ЛFKUhB@6uf,?bl8֠1%G٢զx-|~[&F㢻 E#@)E( Ղqx^D&Eb hn僩0F(pֳqd N 1 j)ǴQ>iR4מephhgc\gAx%T$qʞ%x=n ZRS mO:4, wsz{. B$G.V|~M<՗vcH&2䟬V2]8Oa-fƲS(\#z.cn`o{#1L/[_\0TtA}5Q;FQetj xfI@'xdʿWkpjQ{R&e!f1JBkc}Ni%j]oSo7&w❠h#LGl@RKNWBe]mR|ݼ<.'h:i|~94^ V}:*~u{L"$H\3a.EGu-Gs:iI "j=^FfΘU -Qvx&֎}χ}NG@KCw2)AMwL=Hqaej.8BGҌY [\97!m9Ƙ7$Pb)U/*cM Y-+sߓ뺃zbKwdۋAc M95fDwwdjv5Ws6:jO? vK!H"Ꮉ!wRƆv V3:; [ >R;0dv=KYݛ^b!H@Ϗ;gұDBUn=!Q~*cTSfġ1[ҍrw^ID#^(%>z)J!d{ib2B ёL!Zu {No+nL-3~1=͟ W+U2eOSZ; |ץ ~H7*7}' sءE s>&CS0VE!Ӌv?#oj Lɺmz%wCQtuUn?V$I8V Am03be)'cH`_rGJujh'X3fw,Y~ tg3aO&2DrC!/,Jɛ`ESΤPڤg.by",mU7AG DacwçJE{ᣅQ6$01(y(!C@qTsXxsP Uv|֋zsX"ey`bԘBG\O~E閾Pz3ĢGWc)C:éLՙF=\lMf73Zj )5W̅)K\{Tm|OG~Dqa;bn 0׊D%G#tv _|o__r0qI%]?ߌmp"{B/ >qث]X}}l%: %@Mq>0(J!Ɇ[9ڢT9Qj]~XہM"?U-U }4I*O TUgoǢ w4"[BӎwRےK,G \7~Zh!i -pݔ@&}~֠q脇m cWbvmKQd ַ@])oGBI{0p&cdI4}ٟu%-mQ|{3#+(z0:]t\u2-hq%lUegRd\!­#)dѺ *Uw@zyk/3,Bc6{LGTAn)F1nK%I Nx)?X~a:$sw5FG2T#Go8O(߫qVwisB#= y{l}}ugİE\(7yh =NCۭ~], W/Q(E_'vbʝpOB'Gl{z(|.=4k)njCp-[;7N+ Ty(Oxa^7jpVt,)8nfkڛ6j; QoqOX]y#Q:[?B +FMcgku_)&qr@Dʦb3 zj&2["C;I!aj! S7Ҳ$_hyu[bڛf2Z~F1R<${auQ "yIIu$D `uZ6% nԱs%ʼnvJ+^! gR\lܢ?s& BVu ppfFQLܲ!QE185न |< s_6_J!,4DrIVJ#ݝ,H&S,6>ab ]"roo]<)[\ "TWwxnCqdxD=%v6S~|HqJ{OEWp: h}HnܳFd 6b'vT=#z:[9瑹I24<&DzRLͶ4bNR f'N ϯXRˍ{+%Lg_bP%9*NXiXb殎Y2f!fL'BtkT/ FTվt!%pHɗrc|eU;KZn%NL@x[I|X8 PJ!@-dTs>g{ؕs0`* d+$+JXj&m6JW{ LbW3OHu]3 zw/9i#䉠e oѳ7(ć{ߵP;\c:B'p7PߩH)qPqЦ4M#z~5<߲3A ߁>u/њE'>mV -@i_z+;%꽼#8ː^aH͵Pc?M6l(NFQ–cUE妤r Lz;dS ӗCҿ4x4#Y2ݯS9dEp]g,Hi;VΈT D<*0`}q5tG·/L܊/+)dEgD@(2ɿl3!$`L셕ySߨ8caRɥc`sBJRl>*LJҌy/SX˕ز2Q>w Ss//;1N ~J1n]jo?ǛweTʟҏ5G9ЩtSo0zѽ~XXS/߽tn}edflǪfR i#@ŗipFiM#t=()UZ"nRz MݷkdDv/|c:, X%~BԢrud(J$xLǾƧN\:=n:߯/6AgբBSSɬW^a͍?ٿp ,mQ|U?A?Z1fv@!HCs:y^?wɒk@GkQ rX)5@7VolM [Ph0oY>!vWarzKmdf7YawKB5*s zIi`Ҫ xI4YMKbFSe*`1?E`@ڶ2 B9R=5nC\gadvNY JauK+ 7ĨK޽!vnY2~ T,Igx:h| Ȅ V>QSsiwC1,qT7ꦵ7[|&IT"1=>3M!rA;vebh>#Sջ,H!W|h^/oҸ6yztlhŲ2פQXۻْ ߅J1vjx3o<ߟ,ĕ1É~ j?0 %zb/DCˊ"GQP,ltF:yp$R2!ħDZ3}=^Dʧ?FIV4T}L1cA%460s4֞(Bc!RʤZfIZcRD;i3fT m,Wq- =#6VuO7Q/d;{<N}f@dB>Z["Edaټ~ L@I  nOx"B AЎX*/\ ,$*Г}VqSm7Z׸h#Z,` e~!WLW 2m/8j2WOˢ+e[l,)$PGsje*gI1(TCr8b \kœ& 0EA0 Gt#/dV5 %.V'#>T3 ՂlxVN3&0ދJo& |Rs-s]8K8X;&KJCPa6(vA~P~YضS N S#qAV3|MQ|:PtT}"tppHy#|x'Ȝa`@ygg&<3zlH q]VH |kBoK*h$e ^Ǯ7]&J*A,5RZGN13ۨgq-= cŌ6eяYjZGI0#"~wDر u6Nbk.ƧY02(j$IV$|qM)`|P 2t66ӚCtD櫭*V^ c+շ*Oo#Oΰ -ALgNvoIE3:S1_k[_l_ #M+nD@pBcCnBs"t ,yF#ys.F˱ d"`jJGky] `ݶ6blE~3Կ-N2߂s{&Wm/cWE0lz`1ȇ)KуU@rlt "5]mX?canQs%/V0z )sj[+ܤě_vd?y_׸6w3R#cwʵ{Y$Ե}|H~_-6WQi1<.GÅMΩD?R.uˁNXôɐA&c} M?gԯP8zXX7FL&u^WzP "ص=p,Aolߵ̓@l:.c 1 B-!O:Nx:9Elzw9bwzO.L}u tե)A0~+F893A^b-~vU?k˯6`ά1Y4s:*|UR;4 왠Z"6b,hI "eQ 'R'X@6rPWq;m Bڥg dd?Z.:ay:Ll%ҫvв &qY4~_[unW1d&6&">=9a y\[D/AMк{ P'!E"N6ZQ? qBR,1pk\ T:x <&P{j5S%êXlO4ejO$Q?n@\ (RƴW1y;oDŽY,k@7p$g*Iܧ4~WLOh-GUȶ^KYWS_yW)ypP+:zprTLk+:Q}I#M; Gm{_YMLj$ r+s=<:9ܝ SetSrGjgMJTYTX{`!2sQ5KgX7ߧt~f#Y$ Xb3Db{VEYE$ 0FyU-eonliČA85W+1ԫ` c?'J%f$!^egWъ{l$I( `*bӈ6% JY^OJl2 Jۏ!xzꂭ" #gK Jl<*6 lziP0=@U$!O&GzLˏX0 @;iM4&̝$^B;!H ' hPٰ})bd2ݠ}}GG`g=NW3\pg,׺˦ q2.~UtJD\$a@#TuR`A*<+s0ߋ>N).ʋ'lDdxaMq'cGL%]]lKQ|BKز}IQYlܼc+,`my&p (RBihdsj)!BuSܤc˫w}ܹMnfu`HZIbYx\\ۉ[۶%(m"#XmNmZ&sU(g_l}V'Ⱦk`ۯa n'Mf&Xˮ:ܻGSݹItΧ<"ІBG.|Es+5l%;M d螔]84L_p y91z@Q1*5KIr G'GӧF0|iEh ᫛!yVO.x1lEXl*PJJ ;yƣl}@[Z/e6+6:SKϼ8B7S <O_ $,暸fK 91^j* s#|۽eÔjƯM][;o37ӭ. dU" c 6ttR7ӊugwaa"!w#G[}8)h h {n\nA+H`%+ v%{|$x!7;oEZf ѲS,j9ÿu9+so۠}˲fr [4?SOZEbA%K +KcLsjʢUg>7@ꛗ- Ȕfc`\ʋ"[>,OiLr-+,KZyOJ9 1cQ3mˠ2:H(Uwx{C]ignysak!ɒ/\t0 :UL@_sX *}HܡgMJ:$oS7VgF[,'2)RVo \zGohf%3KQ/y$0jPŅO> k"no%Gr"*K2[ Σ(Ix,|ir@>RL곱Y6)lADҎV"m b8N yEz:VZg*E ӱ6_!|z9em{5Q [N缨ocG\]L9W2"WpZbGe&3-ݾU(r0!'ƫMG4aM7m k>%W%5^6igj]>| @1SXjh_nPl)bA*V_wss9;!H ʿ1>S|;OdzsumfK8Mgo7%"&]XM5 f%a3_^)mM~^Tx~= R@+Bw,K bY%WdjpCXWijeI2Si?xXqT!-F,!/m3|3B ]]>lդugk4`|Ewq{֝_׀ӥ_)"3MY)]ctx1@8\ o7ohS bkXԮ)rѶ~$;WH-5_*ed-a8ͭc6}J"lⸯ8% 5^Pt_fPc y5B]p?kd׸%G=AȳeHyӣ{z jk}٠˩;$ ww"}ZEUFm% 62}֩͞D5Qn[1'Ja<nu9E9G ,67]eS#2ś}$8.S釂jͻl(1lj pfCӜ%L%:^0zW59D mL*s"hFS|V)XOES,ҮXQ!GǰWQ xdA9-8Z*m,٪噘0c #Dp0VDfY@y˖4y6JfL2NOi]ܣRYxN}g7i(eVI] e?q>W1qBؖ. bkԊ)6PqJ=SGy:F1aRS 4$H6o.z_,tے>3bOAJ/bL~e'f`5j!o{Oƍ0)MڕǺZa-< SґG6?GuoNuFK%ójC[?Z/A"^-- aFe s`_Hя_AZy{pe?,* ݓL>xyɱRx>o((\٩9[ *W.cKjTp~B=uJ -nr/%xoc mmOL7%D&+V͠:7){in[P{ n+ƫX*$Cz RTd~ &3Y[ Heq}B?Bai:ٖ9{i H~(@]cDvnVW2>$B?ʙ grDѣumS^ UO\ UchN_'D )UoK핀X~֧`!8fmõdD| U4 :10rG1J j&ڍ2_~KߏM,IllQq%P' .;A[-B}K,;{*t -~᷾ԠkVo#. %䲵u[f@Vat6 OtC5[sx~kd:.57")5 š`W[ ȷY:$s"\ SPq%g5Z Ub;Q̂L+:.~@FTXҥ!* .DzvAEmĒd2 ¾"V ;]yG 2e_R6"t40XU=]_K0:@fETZ1ްJ%wT;q^={9[ɱ/̷Q9MMkd%~Ij&ӚIW>DꝢc, g(@8 :*A-pY" BV@"Yοs2#Obu[7L$fӆ&諣c453q V,ȗU¥HER:^LdQQ.[@Ԋ)1ywTGh P[\QuΠU ?џCNsKQ#Yol]#a4c+նN?m)i!@]b*Vw4z,ڤ|I/d}zۃm7r0k(^Ր/\|+}v(n!+ F B !,H?HN,lDQ܇ tSiG`"N[ںjMC4/6"(WbO;P TmCD:-2ژO g6jEFo%j8͋a s@oȆ52}!S|[^ hoQ3}N@ˆNNЭCFatOÏq)mlAԍ]DԅP/8Q1) qrFr넲(9٘6 mO($tF8aLa:=ؑg_8jI;?]V"8~zWj$hU ZRX3 ~Y$]{Eed݇&WHhh c-S4ίE ^(߲E݂%ҘYCh>:hT1$nVuD8y= 8l8U2/2$R$֧>>1sط,3Vg"zuX&ʤ[Ǥ& }"6,42[iJ4IU9vWS5(ط#f5}1 riRWwl{`" }pMps9S={U\B+,T%"tJ肶 9UcM@Ug;$wx 3P$ ߙ흢=U 9%MCCo`9ͩ1b>葉:PmPz!!ɺd<m#Ð$\61Lx֓ͪ7jJræq *+J;3XW̄d"B5\ ]Q/ h[WqmlX.SH.`p31//&!aA?:q&p6_E?* !]x6-9.QDUA%:ݗ-UIr,F< 4k-Hc; '0|­갰vHk_i_hTvwk k:q[1B%: Z*8)2F$%ݐ m|b+qrk=11SvPfaݤBS;bez/wW rBUK~px/4ϟ77@s-6xwQ;NY9o˶׾0 dP5\FiX6so弆R1lOH?X!99'@TAd鲓wBD"ng,7^/nH=eЖyƛ|X[(Obs{f(Nzt~&`K_MwݹAT_VM- xYKI4c!қbݿלgk[nj F ŀDyC .#Ю).a\#rD7#b6!? *'(io, f5%}VNu'8hrp&l.K,׸W>4T4} ZؘT.2C/ԪhVyjwd=2 .ѷod[u1Rs;O18L=D׹Is0newZX2Gk mVhSH^ɢ,) bTyz렠9@?[ ωmXiM=p[L2K'<StG%iou2‰)@a/~LV-\9l%Br Z[$$VQߜo @ 38{9fteSIJ[}Q~Ip0Ǧ^MRx躲=w囻gHm?(l(]qÛH*yi{7VZɦ|nJ~eL[yh0 TZ6mzzJ};a2bvyt(GH~]5pEpmC~o-wǷȊesv!QܬkhE-f6K=ou:kuBf>cT̿S &L7pn/<ź VUHOWv~عf "->*NBEܻvjC"c N`ĺJЫkVBO\RᲦ"V{'`37kB\⁾Z.9wiY;08))xzX8CcRx|q.%OѤ۫ڼ%n ۺKP:%g@2DqwU F0L?Ney-q WiH`’W pΥ6 PFWp ˒i͛3 ]dkJXɱZ"ȨYU gM7%Gə j!PEVҺE 1Ly-T( Bs4;@k%/ X8h|sJ6SΏ uKLL[3}|{љ=Q#Ҏc&Xxͱe:WHo`K oJ6%q YSLxO <jT'[oH+pWηZsǘI"oeۻ=A FnC-Atʦ;僀f f +$) 1>b\`Bȇw|@6]8ɂϢ1eIh)-4_Tf:oB`֝r 2t,}vUdҾ1L K:+GcX!q$dgM_u3Nj5pn y( x$cj#bC1(ÖKQN4ZZ@Vin1ُ2{r8XRفnф߀0˷χ"Bh= _zblSPzK,i[x;F6 1mӅjPųNNۉEĎg `£ Ʀi#^=0M/i&ŰE.7}}"bxl؉0./9f {k@xw":iwI}OYIW>!!k`de1ZY7.F@6 AMb|;3=7?0\ELlBP@fruX6f݄t;fu]RX(g_+%H_q *gpP2l4O3 *WtER ,^Â>?x&:dO<Ƒr͠{٦J/Ǵ(utxX$"lI~Ы]=Gz/Ȇ+>]| s^^4:saXw1+cįOmKܹO1eƅ<#S9;TkwQ1IJbgoa=*b36,F瑄z){n9@b<3ȋlc2 h Y0eYc3q: 5Z–'ӀNj6>, WQ­pr`/hfeXWsP/H } -_j'E{ڸ:Y ~9 .PG,%v}%,##Bӥ/MJH?Il]50܎}exA੯vtyzX偓:QI(["PϼCRB`a; Bl-y Q:/J@G(a[shνsLg«a)?»u$O>sbcxՀNq;ZO1 IF\=DՈo:\؅sk?<0a3G߁-WrarU @Jt,kHBҔ0iՉ难˵f0#i.ѮibSm|'J47DZo]hi5zyk sxX-\@[by֮"^J.+lx}9"*)8\?{/ 8kN "eL+5/ޤ?!h.L* v=M\+%´"; p'Ǩ/bR 6^@`@%; 8'td%rC'g5_TP:Lc) 'u d3Z.V)A/ I ǃ}pExTXĈnsJZTnʶ ņViwD,<&륋 \;@ن_j~eq{)̄#e5$=\@7wd=G9Ԫ9G3%4`WMJ%׼]4*VH) R|ß0 > )&U&Ÿ3sxaRyڪ͢rŦMĎEPkt̃v Q2k8tuJ6L O]C|>!6+h|(Ɓ \A՜_=t(2k$P ~ϴ OQ]L݌Qbgd ()mθ Q-r: w?WZƣ!S rD>/n,lXpSw}=m^O6@t3,-? 픻 w[~ 4`'c!+ ;h5|qSpB}1R/ c!I\@FW@-- ٸ}]ӭl+:N˔5AW%NvO-ZpmH:7:;I217ؓ\LgIvd i_24=gMVQbVjK;a8`7 LeG{U2ly+yؖ~EJ=ʣyq~fN iTSg}Li ZV,ږ瓚GzX('r> %\fk1zK0cRb,}K|+v ?JJ{񮧪#AI,ҫ7azq#9ZTӳ3\zC  :}TvXp8v }O>D1p ^5=s ۴'LI W!(.|:Eu>^i GTw/ؿv);ze3_]:#qfKO%, /_C/*ӽ8hsdq%Fǀ-e HUqMW>Y5' #xL 6қR0{Δ|#AѾW9trd -u[IlFeam f&E[)Lwrނy,Ic:[3  )9cu2LاV?-!(Y6rL z!MINjp>\k5Q8iV|lR'2=/H)6 B@~9@٨VBvHqJ|$5_z#$9uiK/s%uȎ6E4ddrk6X}ɼپ o>L\}V7Ց'sJGa @+ UT/H#f_w=?2±yBh/ j9kskFMuք0*Os%e9p`WӔٝ jծ?\n%q b_l~#s9v-,ĺ-"{Bx4ؤem "%-zZyo6S9YezM}+ѧڲn5 H!g*0w[6!?lb0cVBiXKꧩ^4C^?r߮gvR,wDC ؜ xa)5¶%"VAL;$آI:(`~C*5`7uoh&elMѦ&r ._X\rG nye0ܻG_6h]+DƢfCh`\ gOu@{zKU`~kD!w{b=d0ȍ#‚\' z(Mfz=LO6c;d<wvֈEw]|]D[KBTϋ #LT-RbiJ`e p+z`NB0}eP%ta,k@Ck)$I:szs9qH;\g]5}O Ux)W$譋Wu+[ *#ha,zW`˾g\qEXk/i`Wj8Ej?BsLK2 sGqT>0 <[MPaK9ur'ç|{e8Eva!q̉6`Kغ"] 䯈) z԰$-"á88Bx<[؁dٕ'^/L%d'%$pBPUj0׽ /5!z4/Su,l! *:=psP#rQLv x>H [7=mܟCe\僛m3E=;&sYLY.HgCh?3F` z"v'b*RvSw/Wf Q0sH|o.+z.*3&/#:QyBx$-ݐȅ&3Q1 or*ZBlJ{cQptiG-II-f,M1!H"NV0[(Pg@%tL@Nz5|'+l l>Sf@laUk%Rȑ{i@`\!-BF}Oϲ ZGTmP*9mvKĬU?  cxG) SMEj'Uh2%cD\'_M}oH/$ȅ_> )kP+ ѹ̱ afkyR@]vu7L/6!He6 g3ygN>c]4M˽|׷6 QR=VtO&Up*k(L}FYBK^c&^g0kA+Z(G %@N_00=O:|+۸-3bsи4` Sƭ,~| ~}KuԺ5ۏ[8K*@ kyYEX|l/[ zg"]-_33&OJy!yq'dr3Ί.z6t9c#iV}y7]eSř 3ŴAi0o ~&Kۦ?a"Jr]wj&@G̍NjVm9XA/|X>pR׀k .Zh輛m VbJGQtݾI|kdYxoУZ(TA6 +u NjHg|0빈5ޗ*E YSҽL+<5[<ݦ,N+tPE @i| kIz@ ﰋ'c4[+jNf)9 Z_x}~P2=d=dK,"ͽ)_hT7p_ ̆؏M};2;pQ)rլ}M7L`ǔb ]ɦƆwV+3T7v!á'D`1&ش *t؛A}w|瀊0J]oт(ƢTbGƦKG'r]҆vQL|JGcH6ǗgFd m, ux5ʇMG >x/N^B {%~FvnrJӫ6x3$ELC1Xӏ K!<:3P gcȷk 2P>_Zv@2+Ӽ?F6T9r@hz=F(q/:,@6 G)YH03s$Dwڱ ϻ g9uN[oO ]+ѵFvzDHI/ǸM mw9sJ^|4ҧ8 V=xtw 1ݴ~vvNt̎bq /vo3+D;y htA5@XjwW";*Yٷ #kW'~O iEOCYrK|kU I[YAZ3E):M@}e,ƞ0D>?A{ mR4+ rh z)u kWl67ixwz8 {a(v),z+ 86wC$+}@kZK1 4VtT#tB'$bgp%!iO 䬯)չno !}g,$&]p'ȡ5.L!öe-mD䟹<}4JwѬ'#鰒Yz-=[͉xzY `@!& ɿ2,F{$uohl\w,n'愻+dfca=:̯-ՁܧoD;&^:=HJk\z٤*]C!'6 ' ;|3C*wW$ɷ|t28hx.[45l֭ ة7Iۥ_]q;Wպv (/ga)dP\oz̳P9'os2;uaفOq. ґa8 0w[p3'x.Ou/Eꙶl2҈Jo"W$ v.&kɾfeKŎW]!wCx*̆Oos|v"L$j٭Y?qYEJ[PS>wQۍdʄE$t>AH=b`m}ۙ";8T] So~}zhD& $hϏHTs_@QzMϾMlpf۽SAXbI)+V Xyۈ=pLa=r`ɶ|6ZYW6J؆x9TŨ]H%SG_YGdvR}_kp.eΘ.Cu#:e^#j +FڱJ&NFLRd:e{ZnŎ̯7y=a ~哏IMKֲ=UiYk7&üsF|SKz괼Ӟv9ճSԝ抚|ڥ3)P.-zUdV$bݒ ?t6T'A/ T8Qj=-Ԛ//ycvh~\'*7g +!_~$oOj-B@2IKKDyubVU * cPa3s |BG&3~W#+#2,5-mO`] Z^ Q8/ NEgn{%'b8yaN B?$Oy"V0/Ղe-bEYvs/L?> K;B5F!/Ӿ\Xr1S,dQ\N ҷL0󚉓lP} }֥ݥ˿A<0Z=?)Wz5cnP] SCA) Y*<3JAA? :^mS>"Z^Oz~3_'xOw*jwƍuCI86 K+$-?S,mjfBMSD߯l{4s]jw!‹lKp7&`~ Lq)KPeUMo#pqቖfg\X;7z[WhϹKic [Kw-b2?C]X^mܾU f.)?K[T]2~:0+,Cƨ,O5HQtjk#1|κDKLڠIxc)0%+WKubgimH$C0eiH/|ZhtP>&IrYt<)j$s".9((~(SyIyLnB2ػ6®!%&N2.leԼcuh.i WO"E'?i5@keݑ%@Atsr7ϣa99HDž9<]J1V=o '>)o>=_uW\c`fv&qt <Yn,{CA | /I[֞ݖlilce)+TKtLW3`3!+P;eŁff2Z+6TT=;ִm^ߖ#Z [t(#5<!2Wx-ₙ"c %h3d=}7pn"!n32ʏ$i75[t,Y*ャA{`Ji/\.ǬXX/VeP"O=ӄ v|]`2!imDJ<"aPx).PBP5G" ZãAPٕv;C'`BK qnf/F ˳}MK3"s1l Q.u^-mq9$ھ,<1]ij7#Z1d=f(.eRC>p{櫗SôղA.P+.9R=6]s;Dy $mlPcg53Rߋ{;֢xyZw.J-RyyrsZbG#(MTe 0aM>؇pX Jq L]W)r)9KJ7O(\C],(WSK9j1!}N>sJ&D\+wP@g'{`%D Czjΐ-[u<6:fZ+B<֟$2/Pb#3lN~d~xuZ),*㰟,,p0Lpg"crߩqEfCM`'0;D\%Ϯ6QFCf.s ҅.h8޾9*,?mxq̦7Ɉ . 2OHTyP}{RLODY.]_?b_9K8aξ/|Jb-iIcSF|_-} /m"/>Ac WJ-i8Mo_ ڭs8Ne5P(0>o@p&sS2GӼ-7yO/~0VˑS rḀb%cEEq-,{;n$t)qxӫ,m_2'gd$H[X9`&[O\[hɃ&Iy0@%*8M h 5g52#Υ u`Xw@ӪQ)3&p^Q*!Ҫ&xg4M#s =0pN?w:2qhϭ3U3+$%`wr%w'Zmx MC~*S:';!CKجv仑E#BLbǍs=3T),`Lx٘"!w_O Y2ݐ7׹;j+q& wNA5-}_c?t}GZdj5S5żwԀ0"%[,LFWU ci]'[{Z "&;-YYg ^+ާREs+ ɖ_G:r5 +{PA*.7:g+pke?7gF=;P8lPT+1,3 Bd6rzcpNc;C<4~y댛 Kϐ9$}R-5gy`X$61mEĜ{^~R.BҞ-А sptyF,Lbΐqif%HRe1wzL[ޒg*F]W/x!WV!Zf_XKy 0692I.&ݣloo\)) QH4P+u1XOx|(;S܎DRX= нP"IOV-6ﮒimj8!װOTsIOاn)% ;95!h6lXm:"F,iA'?ttCO7Z Ư|Ï|\^oo᷍S3DA!i^͠{mt\3ټWaV~~2-8^U3Kk|l%eɜGI_mcKg .iDq=#2)ud/EGIᇒe!p;tAE}o-un6<.] bHL:2iGQ=TjW$7(xLMeuMO݇t *%lwl,Y(^dqMۍ&.vX4HqCv_Yˠfˆ wdWԛQd\YQ=_Mݍ}NKڍ[`ϱ o2*(ɘTBV߄~48X@J岷.V>m k?mɿ 5;x40u mCHta\a{U8Eq".o\rQ*<e 9꨸j6ϗF n/}9b-GZ/]0tU=%ksww4TQ罣4t4;j E&ngԩϣsDj!i(%iv*_ MT̚[<kkPp哹D0FX*aD^{+Т^qŎrx0-Jᆵ{H91;HU8eYR.xȮܣ#x|p+1I炰8#Tn?buH:N|8O8 V4 vx>ƖB,$me/T+2L=a9ႁhc T~.ȌT-*6y7x2LJ0v*r|r`UC? /{Y^ĥ?#fz5n"ZL.ImZ-Hqس);hNYCGfDDY\^uX3:վԂ@VKtL^^MKkLAaڈ’{vb>/GZW#&Gl~ 6Z8Z`_P=~3M㆑oGʒqAgػ<LGXnگ")X)bD8?M|?:l*GR`R.û9Y/E%.[nK,qtc 5Y/!n8˞ U?Hf =-gx}AO=РjKRJrfY*}Tx,U/€ǧ.%dRL3F]97m)z^&gEtud: jqɆCODC%X7Ua'WdW')t-MBPͬҁk65-#Cg֛Oh 9`rV(ZBܿk{G eǎXޙr<#2=,O3M[:WmubxL }+up28 ?z*S{kOql7Tܥeb Nrd Ƚl˕gvB}\or9"*a˶_f.k3H!/DN!aIs׽utFxF)\0OPue(R5YM'\UecZ'gx4eXqS>.cbWQjrFP;5 GB0 V(R|W'zp8JAaolx[kŮvVQ o:0l!r,'N>]M[ZHZ;E$gUZ],ɴ=sތO`JSsOf&ppxܗE8TCGfm<}Dag2KmS u| a(ᣛké/8knPU4կm{~{M 6PlK\0UPwO_=6Jα_C o)O!bByT %S[[>ܓ{a#Yʼ=?GSH#Z tw~!aT?G$?J4+,xhc=l;ண2K 𹊖$q?`, uE0jyO5B1dtʙfd{x)DR2[(J}?|hn=!7~ֆ^oX~:`lqЗjjvAG%uar^Did;4{_Ҍsg9l T6b EW QhoTބ:4cu|繗 ~bBs`O !Gn_ܠ9-`U.sg띓dBDFS;v-*:BĚvN9^\#M2xS@| $!:ϋro~Ƭ,͙Vf G{NԣI^WDg>Ww>3Ѩ }^p csA1Zqs$B* 7$a:-ծX 2枇gpw0ܞ0I(v.1 A{EXǎQͿ63WgP[a6ھk@XRt"i$dqxAJE]aN?~|Q/QpoyB' )Rec-Fe\ s;<)2˸Iu\y18$_A[㋿Icp bG:ƴQ=Ye/->aRΡa_-jY.ڼmddUݳ4w]^PT_ sa $wZ7¬:+MHau^ R8ߊg. s)mbAǺ?ι`JW:iJzSu^@:ۄ_]F~_pVȞ8XC;"-ܣm!qT{U ϔ㫕랲_L 1k8Jrɏ.Y w3M&1y4:e038"ٍvaG- _›D;ۂ1VH+ʦۓ$bJBv!BK Qπ &p?i \D>94 *ueIٝL'nX)- KJ? AmCGVLG`Ws$. IE@G^? {`-_j-FA9`bU u6)aѮ =oS+ϨM*p[<`O}]}PP hTIuڒc#lw ^4z%  XSUZ<3xAa4aXCږ|rCt淌cGrsdոN1:bueB7+y.ˈ#[b ("biTiH]PBmIm2[:4mLZ=PyctNޣ MUAV[1~#X'tI:zXcqpz{4{WxvZ+jXvqB3aMgKK yr9 gz6nͶU$<\?mA2l."-x,a|4GW)b*sQۓZ'\kĊJM3j#BXie-A.R/|F2>Iڽݨif}?jWTaA})%<6@1Swf(Bd/̯gFC n8f%HsRhHӄ:a$neQYoZ3K]%Of(z!n-O; PY {zI.\7(S8a>敖n]/8t; 慭q6k;\ƾNJΗ {Oɾqg3Ϗ-"|FHN[TإIGuX_/eDNO$䃮Ѐpa LQ+'b1LQ ݥX86FqvQkum9 mq ľ /LPs;.˥c\;p R +Hνƞj|) 4.h&PMҺa-8z5 헷#= k9Z vI OG1OW|wj^Eit?fowpSgvhLly4 "܏iQA5 bMuAGý?W. WsМ,_v+Uب&#>7kYpklLYKڨ wѥ׾_-i2ra[ņuu쾡̜r,3kv׬خҝXgGsſ]q jJ_bZgR4p@bL:Kx~kòY~&Kt'u@U4O`_ԕ\gh% *{IqYC#OW'!%;-9lK_bhGB>[.q!]KfA^r;BF9ʈU6 N0˙9u`KeWP=3[.tЎ0J+5R_0;Oa)S'6Vs6炀̮vXEv|@5#Yh/B'[WƢz\q^ܣN8\+=B]+%Đt1aYN "  A]lO r3TZUQۯ F4,$!%aјhdAe$edtb岣[Y&RnB*,1MAiT}̼ $N|=ȗڬE{kuiO֞L])?.a}='+!.Ws#m(ɖ+ (oEQU<.$U,5Q- Qoٓ*$I3Z2rK)m|/%P\v+OTUomB}c@)ǟ4'hd.9 >04_ps͗erKz73ҪNYk(~*tp#x.8FfD^۽yW3PKLdEH]PYq[=iK)>v lE0]hpSfQb٪_ֵ\ųljZlOݽhQ;mv"2~-&T) Ksd~ ; Mz]  E\= fZ )mc@ǔՖsHص?MU%\zk48I[} va]3Ar܄'Z 6l>"t1]dS#W ,bdNtsc|qjZ ʴ  eGy缯wJ0βj&İ?`K :Ʋ8<;3˨O]6̺ig[&Sꚧo e3o^R8vQIX2rd!ML p-  Q#CP|hva? ?yIBA6<54B7'ɈUcvS}82IWUQxORHZ".SBO8kObWGr3a݂ Yϧ#`Nx5ʙ~6#&re+CRE^B*өܰcYaMDc0,KЯ4U[VڒZeW[c0' bJd?PdݙRUuvgR)2&H[3FP1JrZ"Q vO7PPheMB*sѦ%%˨u)fi'OlM2: ͋aFEKm:n-+]:LdżQV0jVV[*m&]56טէ;b;lZ!dOMEdhH0ۈImu EK-qVac&ipFaR+MG"+H lm$$:>K$-& ;}5!#>I9xGSL'i}fַ0\D^vTᕵD5ȨRiշhWw ɾ{r̞Aj+{{iG᳔9^ b_.^K!4PkGFŽHĭGNj@.|n+ k-Qqy.:O7`6z}Bn:1W\HңfD8JqZ|LjLᡗUxIV}P͑|)Vr/, n]a(&2bp91=jNuLyAHW/x"TtR5`f8TD"6?'ф`SմeO'dGn#^͜ W8a=I+F^K\a6{ͻBRë ![vQaݐDCym=l.|}Xx-I瘗P\ekuCHyE]h?/;w:G/9_ HT~c%؊Up8XHF 5OTs1Ez,b'_W^$nfT^[q6P{BN|uy= p{↑_i|/R,ʪ:P) 5/[I.z]o|2&Csʔ뚴z'C_,,? +J@oz$)β蝼]!s=PߜmwG+xiKQ+DNPم+ ]c? 8ŌWoz~!<^xEی>~^Rcg,pu{"KYfXFrٮ$nYUݖٕ=ۡFh)yQ<-'4J]w]:!8sL@F >zPT܄ce:0j.B=嬝M𸌐 YcQ#]n-U]5)ejpiD@V/Y [ala<@L+jE< ҏ&6-]~U`\B;t8[xZ[@ː&)ĚÑHIW6#[ځLnMHo6 )3ll; Tb6B$#)`L>t Q~4ف|*|c'VUSf(~J^]5ߔ9o@dD,?v8C(n^)P$tETφ4{"QdC5fk槔6ɇe!ϐ\ ıbN:s q(vH/k} i<B2ԷМﳸ.ڻ]`SyG~FYlegњ\C=ă^{T3r`0%ٔ:L#J:<ԿLˈm+0 mmڇйm Y}j%bP%L]#q{w5;g>=un7f%2=[!Fݘ*)NThnƈ8@fRo toWVd6RV*lw&R[/U Hrnюp@}SyQxC;L}xW('eNU, U9r.0i-h٠l|!J˭e.7xP^#N׀]W$\1aTԦ+z˦o0*UT*f{VRQ'Jl{|ŏ=T^!$bEsuL!cmdXCU֝P_ r}"J|\\ǐ"Fod?mJ·{vONʎvÆ8P$8X#<.AcLG_"}mGjv,{mY'.zц{t!T%u>`mp+حIݸc Z ƛ_E-cM{tyD 2ƕMV{q'%IkZ2*MѼN P`, k'ZJ~ "Tɏ7*` Ku+T t)u+PGMƻ١ ()HTT 4yh .χxqh4YZ*Ш`k[S4Q\ؓqO/ a& 6ҁ>F+RByWv`qų\L _߱VT}n̈{;_.oJ1|X*,d{f۴*yBLRQM>i<@Of ϤqKTҪ١O`[)+s/c %#߅l6ȻFI^]-0?K:+ e=rYbUC[n}X!weGy)廗 @={HYz\s+LJ,7y1a@1N/J-&:c33.II0J6JٖQ h{'BS4 j%d9yZT9<2aJ˕}KJ#"]HK){vfewXaI')Mk0Ѷ|YfLnϵu#G(%q,|uzOÍGH `>tMeH.n2!8cc"K߬Ԙ:9]u˺Ҏk+Фr:eQ[:@RAֺ&H&ҰL:+3Iuvp'C uVLthʼn3ˇu.fP7\I|$_]fDa eOƠ`P\.F)_r5rgUv|5j~|ޒ:,t\Ih,NaAډ(;ՓtOVKhm9yDk{)i7E!9 LhT"kŲ-7Ur G~o@k]?Y#%|9ZY+T&1/gUҰis9j',(IHjWM'>=:zє/<,L4Lo?Z/ }ps[pP؄U֮t;tan|3n|;Pp0!/$۬Ye3DYٱ-ncTދ/0 ЗR0 ;~'\4_ޮKB^eEѻy >Mfd)jx(Up)&u c,ӎ`> zf_|D&Le`n![E\~36S~rbxBR[+%^x-2FC+\ ʒڶs.[nbFLs㶩e*ܴɀxP Z3~}5>BxTY-AxcYySPFVӫppO:YoF1$*ۥ̞p ytMp(y$35NI`(*bBMUXԆS$9NX|Vi9(sqSmpf)jX pw}^n]{Q`(ybA#q(s)Fu=tQ4`E1=?RհJ/tDݷ5=[qǘd ۥ3Wf~SjNX.2Z?"xe/>IBtYyV`O>~X`$AGҭ$2#/"4Л{ozcR`Jum#Po㼫ò=pQpKFJuv ɗf ՙc ݞj@g/[,;__&Qh< 1ʌfЏG]lۇ/7Ir8{9mIe-'_{,o:~PSpC5|w˭%ntw_2­wc8x]D9-aԡ FCJP[$!Il2bcXSMAƖ_a*9 nwdQX-&ph?]G?n 2 -VH:"6C~SRn+#q;A·0d &8tQhu2[ZJiS~-@xcW?8Jw;QLtb4RNyU]k9z}08A2(Hks2~wfFR =.o$X+H{nK&5B[. }(" jIZ0tݜcK"Yt֔&kKUƴzO)Sʣ.cT/xs~gf_F`Sdb_ǒqU|# f?9U's3$OQ8s;tL؁?G$3΃0TV Rz9G)l0/}x5:5rԸiJX\ê Ka*>zJl gTudij[ʼ*25nm4uk+Cd>Pg;N>{t˵N D0:g_'dܯB)Xџi Q$1H.΍@cf2Cv v-mXY";D*)xh a(;ssV|<~=#!@`aG9e%C iJ|xm1WŖk^ = [BTsV{0fV+*hU F4A4e^Zq|i.cs鰉wiA6FgnpWgd&ƒ£Iua+D;sZr Yk;oDeHK2ٻ$Y>́ dݽ,vJ$4r'R=m%k&} 9K+3F7=S}YX^t) ! @\ղ+k!H܄zYTT^NZ _ Q@p)?u~( cX'f+9x+Fa:^>GjlH-2$sJ\ox9M'ˇ9w;$!nFOS󶓇уT/X.A٥(#۰x]d7BL4M*FdJ`Y<䌽h{ν3N|cX&h̳lύ-^zuNn;:OЈ=F9!\~…ڑ/} bDžWk7ZcY+ ,E,/3 bM ɔ)1-挍# ~èxտ'e7(RPzTO3"k 3Tl0l4 ܍ŮKs0oZaQae0Kb$BX8`՚:.LU\b!*Aܩ HZ{'#ZtVȢF/~+^kL>z6X'Kaȋy-&c}ԓD[\G ϒx46U_= 8|f{]/s*!: P?7Xh4ngKPѰrK\]au=tҔhSiCX-w1#-%X :|"ۿk޳qG=Ӻ%wmr[ ֋f q*AgJ?#zGwxywQh/ڋyJHH16A[U)y蛍$d qttѮ7m$ꘝgqIC5h+w14Lp\RD\5,f|=Ͷ 7Wo }tyX`;wG޳a/[$1KJީ-*nß_>{ <&e@= ( ]af7t0jf4LN`/ִ̐"ؐXNljc: ڠA{3];%똟!5_ɫȾVU|e]#|W Y?ؘ]io.@j}$Jxx Ikkъi6Bk@xGvK>td-0#7 61[KCP HȦh0h[GU}B/fѝ I('`Ҳ@JiT7LnOyz@B-t.+ԡu>O-KXF1S) tؼg`B R2(Ϗk1b1KܗU$טa&qTȦcd71 y_lQAmv&^qH;dd̏[ "P]}|ԸYlėLF nN*5L ?JRL]1쓼ލXeXeMN.b6jeFVXc D6h]s~}#8?P PB?^knjWG*EVlvݻ1kXʭeAst4 RJW[Hm5qq$@h1Yi=ze鲶,6NW(rq-N6qxXJ\s+PU[֍ w d€QSE[ C٭%M6cpA<8cji.媿a7 M\zJ*dL&?Ψ r*%Wu41ϻq@>ZQ\$k݌T5R1puW?6H}Nv beoh!< )i8ίz*1?#e0~Q}z41$ *˸CE d3O^uI:rxM"?TQdA- ?Yėv+/ٖ8*X+1þXDH/8EX5 C-gϫT:Ɔ_HyN ،;WuLojT/-߸ U?8Gy)$2h_ ɕ$jѐO<`$-)CgAd.pPCD?=W"ZlF鵶p } ATs!"81\e榡4y /KWjOOۈ"e+В)1 \>L0jRU^کFGc( \@jut_ffE%YdI^{BWh`*PR@X.Ø3!9έHg[Wpl)F3t#'2~OdXMRQSR6MSΠ?JddSZVF"2$TnM#%>~MڥS I~,Wn.>نQ@uLJ'fsxdJ"g -3אVnU+Qc*QrqnnMlkq |o_e:( ;b[xRͭ,V9ha^@2Kfqg#Bڪ&fY "~=W9dW @ۗ$BPLN!72ɀ$|ꡕgpAj۔խ;kf!Nzw2͑~ mDC v0Ieeʇޥ(ܬ-u; \bP5ŒYzzƼnA%_Q1bfEb%+i^ r;ܖw_6ҩx:j_#3eʈ4QjJ ON_b靸票ERr,=yFIy$(BpÍ(Ёst *]PNΒS[ĐG ?q&X.U*cO۔!Hc (Ȑ?q,hPk:4x?Nfg`23 12 =Y7+7ok(dY꠽ݔw.nv9bF,腑2sx~{hNɔPX"ǭzzu&Gƻ&BޠhF)1m[j}]˺ko%? DuJ9;WQtU\K: TŦW=at5@9p DF )O.FfTFm]Nu²1:_̂j=1w_׀ 8FlS&-8F :[X(6Co3}V-26"bS8Xl3V%cp) h#\qꝭ)!Jʟ//}>qVVOKV* ;x#gga)߅ep:M|_6yR]e'uTpR{ /8XϘxтB^zC3bl1,ޮHfSipT{o0 0H Da3w3n0++%="+8JkA'Cs{4ϧD֨jx0BӯgI^(o a% -X5cY[c6ڧb` vB )/D84{.BLUG4WOq[UmM 6X|dScD8g|h2t9A9FRUgZn7RaȪح ~1׭T;W[:QYa(:ҍAԛO#F'ԥwW㥈- +>]#;wi!大/=uEήKu0jΘǥmh:k_| .[ʵ&D8.^bU Cp9=FwA1Ͱx`d6r uOd/;m٭!Ŗ6`NUq57d9>q.uIPawxt<[kOf"vko8+h?Mڴ[1#?PMÐIʯr.K&% rY X%.%'f׃RFZKAHtCݼе:Nq5-"SL*$ jr+6^%.=a( _:%B))9@V>@ e"ف܄g`kgHyfn8gY-Q_G$5B8 aRk=ڊuٿJ9+B[b^f꿅3n@!8z+EB9Im-DUu,?pN;4>kHOw doEau#XD\f\c כЦs5V"s̆FW}=6=zLW,ݬB+Ɖ X#? c|/ПXbbv<"$49e:9Q+6TmiVFFW[/8. H7~9UIl,&x`UTќ1UN]kJNdЧmhDU)Z'PpLh>:te>A)3wlq 4_[ zO2T>KuhAh(ggk5U5vpK2.6};hyf1#\h䎹,0̡9FaVk*$_yᱢNp4{ȴs t枳'iotp!L:t -Pbq$NXX@ma]la}VdeעZ{̵TfYw`!E'͋ ѡ]sH+"mq[% Nh|f盨g_Rۄv qr?Ԙ37#I[`R:}ˋrt}n.`~D`~\Ss)2rÌ~W Iy}7, [ȑ=9,2F6. 4{,ҡJO|!lyCm'pHqICD`GȈ~ڂT3}:۷{΃f\֣؜6(l׹9FV4RY:h7F97*6?=8Xf dH<GaUgeZb@?QS*Ci>y ,<֡,vɌ!WJgҬHo_L8"ѕQ?i'Kqq+]S`cPrLg!Z^뽜MԹ[bY$n6VXf?,2ڳj4qҩui*X~(7K!2WaH,Y=_-$gr@iA (当B ˿iQne5 uUtyMWRi~{]ؒ;Cw0k'P2"3qӁgcCOw(yQG/H=;uS ab# 6jEu%ɡ $g =t-5bڪN@Fi(b1ig'xi?*yAc=~4Э:O96)ش^Q(DX _׉y O߉=$ hyΰ$N`_{X7| Z>PҸI7z߿ZP9!*ŠOi3qs.;rIQI:#׌.|;()wt8:B/tjнC Z?;(#pkkf=kjg z`r&W4QS\Pab =N~"OMXevEHq.IKl45&=J㙅Q)x@q&cV-9r`q/eM{b#ܝb-B@0,=?E1$ *SKNj[TmC%cW_dqH2Gm`gsfsTK/|UwJe؄`ıKNR.I.„M> ZW3\N%Lw!2 qRuXRY*pw!T`G8҃[liM}q7.%!gb OKDp}t>?E(Dm#]sQ13;)4_|\)xrVyU: *\ZÝYFo&ˊ31+ߘI'D-` V7Hᐊ)}z q5<x.2IuN#Bi߱ }nKYKt AۿlMDZ_<!Av9iͷSe3$o,a,#C9nMb%m|]ZOB09 \J3hEX hmjЯJnV@2`B׼9BR(pVc"Az!ۯPKmdӅNm8%_zG*U`Rt^tֻ81Γcxbh\R4stD27[(+;_Mrv]g[)#UO$Z4.O(&4:ZIǦ@U~<PH+ᛮBh!ήEAoUoxJ9dk]E_*) Qh;ܥN^Dk?5Y% {%Ÿk+#3fN ]zQSᏩx=Շ˚LN~^$e9~myC En&+ǢqD`2IRpi+xg.e&3[R80.\ Jwr/µ; 9ˠD,&abrcE~3{I4{o瑊T/pl QԕK-$}hܕ}50BhpiNcFpP߫߭A''-(٣ RQC䆠ݠbQ֓gX8oo! +g]ί>;h^h5yeNin.-EtG8!F'S͝4b](U/sCv|ɃL?j<{v @r=]1T2"1(E1RuM8dKM/0Jhbv|B޺$d/**|S84?2 F# 2|=em_ HUjN/+2C)ahT)PG-.wL7rFj:z2:xw%Q[ Ļ 3ᥭY<GsD6֧Ύ{Yӟ[R(aXhz0wCkZW͗9b.@I?$19fnKlDʜk $y4S.Rtqnev@]o7b!=%];VHxW܇yˉ1S6=W7Nta!{)*;"V=@u{ nka`LTw5( \l{b(qb"p}F7f u1uD6S q#*֎XƄ{ X9ba3 ?c!Nb@ ~!nBs!U[FKbW/[dÿIMRsfĊ_e8Wͧ *:޶,;3BNryk f^)F䦍IW]-8pNaJZTv]Dg#Q$AGZ/"mBݍϗmW"n2: "bDC |?YWVG=r3q}e־AAa)K|FY0ճ޽_z*c)=Obfdj挠DfWP] c+O Q-d"AZnFw[k]ZMGoH˚ERj-~*G'u>Ո1HiaEۋ׀b, tk:SIʉDȀs#t&?}({V)n6amX5C?.C;XWf5k^`JArp#W|Of@4ni4 mlUjKaOʫVt9tF~nR1YߍEtUBx2TZDv`u shV}3QNc($"\4rvq8??MA͏xG('sq;zm&8L&U 6>yGEh\F+%ˌ;tgU[hu(NKwZ^qU=%9x(zv""[(M.66r/ Uy%Y%cDBEEd=h5}lcR{R0o*?֋bK V`=Hˁnc$fwl6j>tLwR 2yNv.H(l->DT)\NO^$FE_! D"xaӸF/<ӎ:#ڕ |Bg[[׻b _v͚*Ll !A m"]" ZQΩQ懄4Sf B:*d6u#Hz&mUD:ĄQ+},fsRA rIƀ:~."k-I|]d5BݗܕYLA m5|CiF&BU1wj"sctI :S %zhu3/oǽR1|V tLGxWḛV3Dgvg&SOB;u%[g?9qw 2jۡhbKwSa"1̑V kfƾHeqA0pHRMdJOiӁS"bU낲#FV`Yv䩨~HX#Cjs$ʄ 䠲X5׾Q6wIFj"p˅R=VG0bf^ 7-2tZ?rU77Yq;:%f{\)64(qVM < cMҝ&Ei>R;@}˳L}!rր-Ohv'&5 nY4ƆkƴCOFaC}6AR!#7,:nIG_+ s1J2^lGO:`ZX30//@9q<챘A 2\v ΃E%} r1-yv~5QqkIdJ|}U2ThS:ZѪsL޶⩔)MZK[haQhaJqZ*Yٓ`k g?]l i˛lByT6;ӗi+=RYˡ6HnmsZjA|չ@I9.qAIn{mO*=#<Tj)۵OEPxbdfyl\] 0>tzghSqE%hhS6}Fz>u0}P(|z<"ږBsgkz $|kDWSf;"1,PmphbF +Va>mߊ-@tq0AneMs rvbڿo^OW[}Yo8,%c"P:BKI M'9"6P&)Rb{T)c: 0,>.vY ,ZnR+0bjúqTo۔^풒4c}2V q^_l $ik^[O|ݨr~Zis29OGSZ7osLjӐI?`} 7)4,zX//2tL#?4RȩHĀ9\1,My2|*GIDP Oݾfz:]YRDz!^;Ef}mJl#?cNn|J2I~{+}kګܠ.\f9}.f˰=`(d7<- )ޱ%"i2C #a_ktA N]OJ[}ge 3|D|Stb/B8f[ϭm4WVsev2< jyO+S[Vϩ'UA r]}SsQ 6i"NW dQ [ykdᥝU- lK2vYB%F 9 0[+`u9>wR!*J.Ìb^ĆXjRHu E cBPL7lln6t{bT:LMէɋz_oCȮ7굋 x|~_/'kh6v/B' zI WΗ^q0bD{b\f}efW 7'X ؈6<8#.rH?fC҆FC/fŨG*fK]S;6JskҰɻmaщH`r E*G/)h; s k7]J7ơU={yh2}R蚓2cF$(8ɋVbM(^:;ce6,JMg82<* , `},61 h vX0]09MNNt)<cKg8Juf!`42߬nL')ǰiJwj8a@q ( :9U3(t.=n6ʖa 'mC)`4\[b$-0:kT2)^da2_)^ܤ˨F^?GD \LkМ m;}|x=WYkz&^LMހna[ c;0׺: " &j|jVN'WHkDySMwzg$6"?vL5]p&k1J= hۆjsъy\Ơt] ڄBq,^/HAñj6 cف;^/ǽXK< Usm)ai`>ieϢ[m.D:M??іIQ{槎i}zoms$.K:Nm$b6;M{WdX1t\=ZwQ}wӞ:_í~їZ`ek3^Tv~@-Coľ?4O[rHbqt& zeuϯR"|6$"$P&|'_4JkT"uH @4DNy,j&ťK#6IR]ǐ_걼a;z3w}RE$q"U~%lȜU>H ]^PG4<5x s Z'޺p}o@)?Π4qQz8-~-ثYgVlo5W[ ԿN~NN VtdgwolR v^"mzy;XEoxH<ǒTbшW_S!IbipqP;ZZtgmS-3`go~FȤ;FێcGW{(x͉ɢ.v|:tI)o*kJ yU+#4e/ճ.=A,YJfvtu1p3 9 )mn&n]+ۗb2k},hzĿi[jR׽*xqXʉ&[-5~ YkTҬTV#M{D <SJ&]"K#+ m,2v[F,WyI#UݨwJh[Lg! edj^I^ MMxU jH}0lu .Ϛ]1Dn*BӶ7]zfB} B (uMa,S%)BJp ɺȤz+p?&=3&X,ASGvm#ǫC!M4rZZ 21!ש( MIGPt,xGpVKU6㰅Jj+ģ%äY(m"vgc-m?]e{.%q žI'޺3Eّ6 U1_uF2Bd=-eÅ^X61厼}k8D$*W)v"0ݮW֢=G2F$Gیk*9g27ẜDTM#ݮ|hede"7R# V݂5(Sr1fD:A'`+u; ǐ=q4+SH5֟q2k| b8\^/jЂnwL&oHWW(aj ) jN\tA& 77|WQG U&Auu2M&bH?hN\2ڝemi7/3rt76 +euy-^ x!Kxi=fVbەul3q gdVd«DfODRѮ<59!dK.XSЀF ȫ΍| p(&2FCAsHM]1grs^x!Y8ϊA4z>VvKˬTIT&e}6K6^*Ү^*_K#ȾU/Yf<PccahH4#_7bIc죫<!n+gGS^PKIfWRY' ,8I]GiNHzG/>ÜdB74'z`f]*"̜_z*NķYÝ<)av8U` /%ț#{ɜNߞuZL5- >}`v^vK14Z2g[H$El1߽pr4 wp] >$[ڂRp" ؃Nώښ-q6!L6;@Jqׁ&@Gxjճb bC|N g~2Ax$-ۦ-շx|HYLĤuWbOrpA n3PS·½:( TŋrlNLELsH"Ksy-Dt.g闲@-J + ݀ i vO2I+VnxR+Ԩ+Ӟ]P ؑ#.VcwpLwa KuֹDv1WQ bhTS M?C'oZJ+kaS8b-*=+S"KkOTQqNbc*chf,H#߱-]dc*){ 9'&HzN6"dS Zt1Xa-25p?>P$q `PPFwI;k a9IA'|e0b]g+&jW 3W8|ղ,&K3#DqFSf9K,QȄ coD=,;VaY3G[ \'UzB!WZ-Q9kh_&ܞ~MзS¨)Ƴ%˸)t2]b:@ mgĵo,Y- qg(<413\|' mv]`@~qpGK8G(!].- 7 '\b3{3h:gد]Ƴp&2Jx"&`Q!G O ?:Ag;i`wv"q)NfD \.]tT! iT^(58p5݋7l (o2[XPODJj)I'gMN#\%# ^P;ERv̴/9f~glG̉x4kW-e0TN^Q Y3q۞v^jcqJWXI6:zgiY`JcJSYgM_.1Ͱcrۃѱˡ_4tK1pJm,ޯf/pqe|NY4bX;Zg,f'vSyon۷`Y T{aI{tbvTD_7l Έ=t4 `z)̣|4$N}YEy|Θ/@E 0nq\壶#m8gI}TҞ`7eWnP  L)Rw#f'+dGʘgǑQ h'4/`\8-R:|ۖ/Ɠ/K\O!vw"+Hv>-_ࣖH얛MJ$o20-;:O 5RˋTs4Ū" U_zjmȰ\C" qK ͙ VowyWJz?x鋣!E0CMUG:~͔oЂp]1-8R\ $s,ѨY=\vCC`4`s;DMN!~g)k|zLg}l͖ChUs5-nꢻMu` t ^&b!"%<Ŵbu1Z'V-(%,ܗ.*~Ə0:%] |n?m6\{%ѕZRl$8hvL_khGn[޵WX N͟[4g~%B&zmju.l,Cm0h$%ԉJt-}:Lغc+4|5?H.ÅluKa74>#&-{UwXQ-f`'`35a_ b xR*HfwxZ!RޝAizhzZAugBdVX:;.ԥA?X7\VeLe8cueY8/Ю|I`apbsŃZl;LH\RTRAmEaI&UUxm/HnZdsc@~#%J oD=vDVl{^_,.rIIN y<ydM;L=F5Z[Y9o&Ij v}l!%4=jL~]5E"(9Lמf+X~p.pL(l\ 4ܛ?rufW{3 Zбx礗`&Kw)dQZ&8_3>]6Z,3!xj6?AcSROl@5񿰂E#|H> 8U N-vzB7, DPΌӌ0 [_k0$ I{\Al1zY1B㤢HunZεgL v=  +2y)OzBjro5Qf,XR {e =v93c5eZ{*nس?zBчj2/̀<\ .ױ(Dy.;ۣPOof,3nk}bIA ӢEfQ{wd]*4K7aaݐ>q8Za>eY Þ]%>wo~_4DWX,mZ[Uz— 8QpX\v/7(jaIpMmKpQ =TZx%(:o"^t|˰DteG^:2PDge>l4=8S#Z)_!W*3B򉞝w?Dp) bΌ,ZHě?vptr(Z04jckoPA8 M_FP0F@<$թ(RIܽ!s *(\Ӆ cRI ;,O)cX Qw p?Y=n]~?rg ёq2pe\j@Wn3jgs rh붣|"ehG2cjZ 2!o)ALwDŏ!.`I@Ӯj"hFl)&w36$$@8m;LjtetD0BHc^;,YCq™7$V)qȄv>scI0.Bϓx@:abH:t"e{XNF#'{QpCゅ .Bpcz{,tf LƐLc8Xaj3:{bcSvkUwCqy*nG 1v>'Iy!O;PzC 2I73v`8QFg?WuK|۝+оe$-M 'CDT1'ԚDt7ס} } iWDa+vj{Uc>sςq\LWY-`aDŰ~<΁4?;DPV̘U 8"Bw*,bGPIi( 1Ji4]¶GHdUg GsL|BL[vA>bXh;3YlPPcꜸ9|@ Ж WEC@}} V ȏ܃tiI2͂@ 5L L )ð|#=nqe%-jh;d4 .@Y, @4ho_=˞G+k#<~5,R͡z :"c dH@pGX@TˆJ7Dž|gc(ݠ"҄`̩t2ARoL.6񛭔]_,awBM16LZ'zVLAĆc}Sf4;,b$S8.DHʜoR}#OX&H&}}:eWHҥm:4i, K"D99 &~pd~"œqWmGb-x~k S lvu_1{G9N(u hIgW  >F]ohsz g2<`DhZ E"s MqT?&Bӿ8,RQ)| -y*Ӟπ%WՒkw- Lyp`*R+v:Cui]i߮]å=3FO{\،'),71D3Vwq cB)eR&ʂ'lo?c'!@؂gzMi_& b(7ak x3_ןn6lR 0& LLgҸH4DLf*R}hYL|t$=Z(.M)7ɣ)vmHߺv2M$Ї($7 {2NNXNoE{1L!c&TPvz87nPz$Uꨛ@٭i!i{7S^7ڟ g哪Er~9&YCTP8zg] 6 =c$5)sRM$EQÆ4-Xm'>%FDiҶi)<b\B^֓t'S{/hRrWI(= HJGh\͠yT9OOXlإ@1}.IϖBBn~G'V2j0shb^I~#1zr~uidBcGe{B!p*0+M{ն>|[NYdCSg VtL" z_Q;;F~"{%bYN3bVmpniיuZ [`!ӟ/bDŠK b=_R,LJpu4P{ G92Ms^iir_@wcuFlmv9K|{gaHyH#z˖ "y\ g\~δb`:RKmCBFlPsGno [i(*A|v-ixAuR\ |zxzt;Bi'^Ἃp3mO @bDaVyh'G~dD5ZD-BYXSGJbv =bG[9+0;j>t$;#~ӌ<ܫ+:icG )5v[V k,L]B\@OYwEiIͣrrU[ד+&SfQaͽ&SXQ®*.xݣX/RN4۔3eHOhL!Zs(}Gr/2pD!Venn< ^KǍ q6] <.s-}cqp$X=Db n"D[+G(ScmR-@(%ֳ* @60YG^4G4/c ?(&B2%# 7UդҌv1$y^ϼ_ 4Mhh "0jgsJ %tQ 0h'gi i3iYI:K:7 {dni| NYXZy]n@1%zvWl৪1ش`*G!Gl3DÑcS\Gm{NfY̹B3F[?vJ SI$g3ݲw#L=>XBxpؔФoI/ f1<7)`/ Fa`'WL0+/V3±E-c v*/ DV"M Ac$z6NB.B#:_d߻>{ȭbEmio'c*tAr2N"E?#h}gZ-BBAPevˤjϤn|b!ShypҌ%}Yyyw_nG6p\ejr䙕>aHOIĪFP &7urM--3Q@v\z iATkVUl;C莦| rga(o9Ru{&‡3.<GXls?*]r+OO{7n5m{QQD #3RᡃšAqH NxGY?y^Iq!K)V`]M:ǰ50$V{/bP,&v4Y< EK+h[oB6& ~ [i81dVĝ5 {=F S|$Gi^?~Dž@]).-j6̛1qRhqE\fIbq症,x̟ȸ>P0Z,wXO!= ?;$f50Si[|if5إʀ&~n5@v(tvo} 3o,̖L>U~HAqv4(̠o1#5o:Q2R b4#`DO<g}0H~B̹;B6ˑjԴIvP Jt944mM@@nE^At3 ij?^n:BW/iP)U`qcOs ;0̸sL\oAŔؤIyy9#O?`Kl9@T:ZJ+3\҉_ M8ڲz \>ޘTKSzpՔ^Å%^ j뉿S%d7g M"'϶/8HEܱ*t'`gG?lX0ǧ]mN>~Z1DᖯV$jy A!-/]C,}2,=Hɟ K"+#Ae9 Zu5QԴN+_\f99 ׽v͸U[ 67<;w!-,(PEX88\wWargB#xVIdͱ҉$ckVecUvzVkEA }N:Ժ>lnYUZip>^Ubd#aM~2z'T[I%=55oVhBch'VVbd&Opݿ1-`7{AZ/#Rς*X`J^|]26>҃.^޶g(`  &'7Q;`=oJhm]SLaţNGKaMK%14qwV=Eb>MDoZ(n" :KI ¸i/ kiKJY4)Z^6!c PnG"Q5:噠'IP* )JI?ʆS}$ 0e]h&sBk]1ĠRi%x'v,jT%.Q@jV G-b=_LSDt~Z|h95M ZGŏLLZ,@Q^ gľ&kAG:=XRI>]-lgɡCD tV;`ا_f?v[/-SK N3S^#2?L cu ZoZ:vCs+H/a+eM;,[ Ξ0* SNmJg;H#D8PH_g 0nG/su 񶓼(!!D\L䱭.&Gt%\^[3ľhatIC{(}OA_EVm<1 @rjF60{#S??%GnQuĘ^M^oȧmEȣ>UcESU}K9?(pt<j̐i)w  lÀ`*Hץk @ptv8 )@)2t]>8/ڮajMҷ\,W`A?uG͛I,F$@(1S cťs6 ydڍ0 1o"K_!>ֹDc"1{ k~6ֱ=|Bw!v%(^wL-n/%sE]óxP>c>musvNIH8^:_AVwx-(I )(vbuaO>X+xV)OT<']aǭy:ԗj;on G~l83SP6iӧ7Q d꧄L\j+sw&U6vIAtny,߭PG$men,!n6 su|Ki s&dwQ8?lDi!%7RF B=LQiݪq mGDuqB h2.XSCIIgȹZ'"%D\.+o0}pR>珍 hfqtkA&'5o=_Y"+x+|D3c(sWsunT0㕂p#!8bg1(M{!ÛiUZݤoټ u75,]E.g"7K 4W6÷<4l;u h]=>2{X«QF@6S+u\>?Rn$.^~k"b//Ch-R1+,#1c,"2KP_e[9JlOAG<udAUmD<jڱncS3i1JBmxvdſmW /`. MNaK}f864)pөcrTϫpz*@3 -98Sպ{ijSn  ysj)M>2ܛ \\ (Wø{@MM M vLTXvX޿}NҽAp1SJg!~[y4n"`\JD8o +/U#!JgG̊n 6T': ~.D\ތtwέ65V{fڣޭ^ "̺ DB,]l"@PD`MlsPT7 @'f RlK?7qFȐaze${U8^ xxD HS7lՓuSwqڵc}l(0y8mLIIv:P`>YHCn2qΧ1{O I]}DU/UMmpg s#D*J [O×Ch˝A5Âܔj *bHrf#ULggFOuj)U ; *]%L=]͍|x۷D\f`HQVy2ŔY)L!Իք0i4Cu?dfЇK <@z u}To}4G/]őUXLymmF5(7eM0 &NZg#q`+POU: +i% tا1 \Mg{Ĩ nͱ 8݈X}Sv&󭻂~j[;r|D:iz͐ʃUMjq} HIWq 烈6 ओa3<̙x8;{{@j 9Ddm\U}wx=&hA ^Ui$R{|E&L,\|8@~HG3õ>S(0ذɚQ~x8 `CGHuX!'[\-(p{\S #R#Q7O)K5pU>Z@652:-CYNA4RˮquN<:ڤ'OCB:R fv0 ћX<Æ0ef{W=$$!C6|c5iW@VBwwL7D%>of1=⫥FPAm& V-#DF1MX0pv|}YhC>HH>$Puֈ(Z} q=thM=,ws3-}_p?@YgC،YkQ@rlZPLbpΠ|8&Dh*XЧ^7xWT228q]Laoq g;2t.)sд1AsVP,,GmWzF,"c/W*<Up=_>"gn±>D4lit#G^,bٕQp/75 ,>;7$9;x& k3'^&1šZ ;  zYtd̞(F0(gm}^mlOSڎW rqjb/Q;+sIZZJm5lJNj{8ѐ՞xEUqQ4y#kU9R[ Y \%'w؃KMbܒouJx;"6WL\? di*>w[ 50ڊnN&̛}#h?wM#0kJfMW^Kn> lU ò]w۵Cܖĺdtxs)٫~ YYQ@l>|C *5z֖5G D3虡9Sߑ%{֞Z!I @F)6;H+YN|Pf.w?}VwJgF-b}NMFJOa5)[X'ˡK 6LR&s`۬-)Hf+3-(kpbsdҿ1M!YJh/鲼Ksn˻Z'.覰9m)HJ!;5g  HJ|8a͐mnNA:3cQZVwfGJ R;]ӖI+HuC){?i{2 ( 2YTY_ ].ZBf?jZ-夬Qn!h0Dr>BuD^L sv!vX *̔~7NA*8+0U.wmzÙkvZ,EY9WAm0ôsg*ރCn]Ϝug1Ov)TԼޕMX ZI쥇qPl Fsȋ+7L6 ,hu<a3%; Ùk\MXF#Ύ]^,O|$rj_9ż,YxOCIV#܂L"pI&Pźb{L'3GlV0Ɯu.'-ᯙ!X%nM-[gudOAI`KƤ6oMI=e"o^n 8?Rr'm[ik5I! ~>=D7 e㬡̒ B!-p|*)BX;:T. 6 ӚT1 A7ۚ›$ۼXb؆-J { cY0eoW!ceJɔuŋ1%Ҳbȡ^^+ YRg)ĺzК3ܸ ^ͩ`ℸމcoA.;v %hLVC7)TeB^ܺyKd`EP@A aaZy0xSm{lG|IAlN@"҃ {65NfW Z|DUm[:yrوπe7g?ywݗKQ¦F:1/>TO1soPXY+C&[ $ )Ğ>(F] +т'a #I=J,< hr*4=jK@U´mHYvg$Pw;x\7 r«~=nY.ws>˭$FmhK;/bgZ2#DfhY_0Y#Y` `Pb.%HVȋS~70##u&Jg۝Pa\ [B½>6tq>4_a(#[r^o3LfN `S[ rP+}0pv֓AifntF7Qv>kebHp`9HނEdWRW#i sd3"|ǫp'N`(E~t*93zdIS}hQ}i"vS*fĆ_Ӭ.VuϏ/@)X,cZsľgN!P:Tf9lEwR)0kg |79y _u5| p ME39I(vt'-bf)k[g[ǟzC'$~ Lc4b"Cdprd`"7辇`fގ}dk߬ϯb Pt#2dMi]8эY>p lvzx} zrxU8n֥v#)Ĩ1w;L+-o)#}8GBVC襍:<{ +弈'&0mC (QP6;[kv?J݋S c<rSusԪ򮃑yY 4irWm53xwVC|}[c;R`PyyIJIXP无ξWGBnsx"ʼ{! % a K#1,qrmCQdҌ:ltvtZ"x8}%~n,`3J~1,=~VķV3Zlt &8i %̪y[%Jba@Bj[VV%v~Ԋz?rXa50_6+0ji[g*V߈7t¤VKj|s^Ql鼈eM=Pk7ЭR1.~@sDv˪t3%uصϐk$АR?Z-EmbR$pFd'{辌:;,>K[oXLBf/Ad 07ro wF'T| T7)_9Q񸓶!.Vec> Vl/o_h3"wm*LGj2~t=?X/LpyLuS`QbQը("tyz3%J2FiE4q.[$KS? ]E5 `Lx\8KFYI.t.ܣEGJT;#!ئya1&ÉSC IؘR`YUGFkaJcs+;7lr; ǚq'lCU @ц*:j՚B{a5"T՘du((woС :,M2oBl tMbU>g2Vׇb&`T^ċ $Qf(ݧ:y{nV_dc؀?}q|"o ,8L|iuP鶵brz=yi սY׃Ե"9>vVV(DA)\YfgtUF-~Y4 }:Sh?vJ.*4 / <0_( 6 v&goaFUfV1d\D ~3~| '7d8ve1K۪)g!@ D݃%Aw){〫T/ΨwFhM88eOp(_33yT xe\ ՙ"42*\d|}߿GgwuGR4qȽȐKOeTS*.k8M9 J$z>!d+fGs   T԰^g$;#sh[]π&c48BQ 4-lY%":Y(nI?N|DyE}s9Db͌Ȱ*g4l ȎăuBPaeÃps4ZYn#3 `5'R"05;|)/ !%A`%n=9emֵz+Z*u s_KO.6 +w< jڭ_d^E.ʈ,KG>TZltbD+;]-FlA9FSu>V_UtXa>#XB9\J@7Fv=eH"`yVp~iD_xcB8C#2pL}\dwc" BޱtKis3?)Ќ rep(i  )ޞ&Pổ-x%-  3j hІ(ܟ`[v3/+w..qU[Dswh # tDE-:jL{Zyer.nGlpk1Hnf<mؚnӶ9*a/$@4// <|ϪaO$;-e{.}d7 b `)W;Ad(Kց%C/i~#vP0rAhx9{q ?ľ[P_D+A-J2b"H€ы HR"d=MiIC}[vtNB 9Ð+{|$QpˢtaFVtw}P0Mnt7<;/:&!îbFDH:F:w j3ZկMl  J!)$>kט넅kND[H\_~hCv u2UIJ7B ioөm,m.UTcvpgO5S\+8S<}"2/6h?;УXY>OPY,s>dnI]{\'*fp(C㔌nVp ZM^vrDAڃ3ڴ! WDzɺPYL#Z JtTԚGF6IV^..R]`^N)ֿmj(&pŸNv`roXVR&߅ 4©ϟ(BalsxW4_. Vwl>`/d!m$83'ݹB?VeA.NjE|JfʬKԠ]*`W:6GTC6XTSo mկ(OVT|McK4vXq{moB$aG[M&B@#2MX X0ZY[ kun7{LP3ȫhpG!q?pD^nKI?H.+/8?MB1#Te9a ^y+!K(ZJ,0@\\|S7~;%24(_ $}f9&G*99 5ֆi@fSj޴?e6uGUUNcP,YP ,\$[Ҋzc}#Pzŏ~!dk,ds6w2+YAYThFGqі0FCjLm{ZrpF ܁ch);*x,4_K쳀(ͽckWn#c4y'z௒c?TAio|=}FO<;BapNr9ȓo4eotӼ5!;::uM'=|nl%tDFoMO"88u*z8x ^BWWeAHjnC+Zu J5,ua'375mֻ`m`N1XFU4kqEJ >S~A4JЗ!oKz5&1MƶBc(^t:F+K>Cyשcħvrmz$<}ԙ'F4 r4,+|%$YTAg+z~ hj(;{:g=wG,שk??8۩tf :"y$Cbh{e kKz6[2a`ͱbJy1YWaJP[A5|T뇩aué_29]am>u@}3;Ice_f-zNmvdoq~–*$2qI2#>I+dЏX΋)[R٘ς 9z(YJ&|p_BAkئtqD|^X>t}AeQ>~:1َ{#%p:: X;ْAwEhA+N%?`OA rL֊iqig#1Tx+o{:iVtK}n8$"ܩ/Ù兖4?,] O_Oohe.kfsy#*xe,0lYГ65Z6wh},*Z&l?c 7F969$WW)?`Syfۚ:X+ "b ']PƏFj},ǽ%Qde-`]ДqSIė4G"%*8+׸:ea x\ŪfD5fQ/C: :/YQ9R$}OO%VRh/{nIYϡgG7v'odu sL յs*Y#e`2{=9舒.]]{@闛HDۼ s.bK9ԟ,L^tdvp֝!\[ nG(cV7FQD/-45&lD͖m GIX ]"ZGVs4 ?s 6th|`5fTzp$RVs /]c ) 2>NQtn"6L‹!de29tCMȑo&ǺJz'(Aj[$  '}V"@4_BK\|>nq=]«+}ϝ,ȑNZ+7zs@o7[~Tb@,ߋVYZ$qvft0r 8S8\:i;2 VPb*c۷WSݐnQ@.D=7_ MQ{geM{Z\<>j Y R[@T|U e~7F<^%*0@D$M=}S}yepr@^e%m0mA,X"kXG`_;kGyEXSKi?t睘WǂrPͶ"+^EDI}ɨFz߇l`G`E" $V|G &r71gt4i<-T'8+I.=)-Q9( 11?FSѶ(Y [U+͌WHưV Ee{a z (fga =b|0(JUPyT{[/9l<8ҝX<"dvdDZR,OB fdoT${l\kJ: W8ݗ>"EZTЋ SP4.blbUZmglY/40's` ";l 9'ec51f/(<H+R׋E-UiW*\C8"΋TF8||3cvb[0qC)-Y"h6KHWs8aDN;1\E H *j~xFƥfξv#JeJW%"JkNRjҌ̑E3G'l`kem ھbcwݳu(?Qtac>@-2vgwEe:ac :81U aǪ6UStqG$TI?1/fM3;BY>e*_'J rNMOkdzEMG8kqCUZOoHico^ s*BH2UVC)Em~WTZY|C`FXDCmѫG1vE7u?Xv9͠6'JPxPt2KWY'W:d귳E l+8p'!QjHdK6fnGS5.UodO8$BTJ#,Y3^_!ua,cL͏%9ߒҔŬ́ <:tXݣXy4}{6?Qu 򓜚˭D϶ =pDj5H`Vzut;_vMԗ EĤ,ܿQ=.8o}$5yH;Lɓw6YGchIV gӮxj;eOl(\"6Uj]dV)f Zg;鯶V.:PL\0VS>@+m8q2>䍗dX8h')3)Dd%[.ڝ$ĮݣQ4|7b#|﮶,<(/yҖ|`H gX3g#>l@Yf}p7,0Wɹ=B$ #D۟{Q5"WhTBuq؝蓁ll%>LUF ƱV e4h41GWgaӳ-lc- 7I'A^yOAd̤)T5"4蓥ۻ@;[wƿoa%|7!jv*kl=Ȇx=rRoic4x'/ GrLLɣ] ORc0eӗ GqlV*d{Wʞ~c[t oڽ<Y >W^p_8͆xRT-K"B#]=^X%RUl%v5Bz?q^^NӒ ;尝Yi $e^:'g_K^];363Zi,@}9 @9#At]2Xjuwh ;a?2 { BjH v'5<)$}g8ߕJS臤Hy1AO!+x1pY#ϟ0Bre̓3 -f~f{ydY5R'7ӭƿPUȯ2S5{0 L 2Z9ޞj gul4AU)Pi_]BӺ]%PLk8zeM1 ӟ j?i[{\iUp,#ZN+㱄 ~Aw "+FWap |2hYhX*XRWfL҆.T݋zvjYMy໳q=082[kPe\{ʦkdeg7]ҟ. Tm~nw !@E?V֘8אJVFC#/e %qE2En$À/Le7!aRD@H jCof }=˵֥gID (Vv)4(OA*]8Ӎ7Ez @v/(ǤB=2WzOmMW9P92 :^eEù}˦)0ik{wDK|[ XG?m cw`zAkW0^{qP<-!oQ^Fl7ny.*&^ G\#T|u. lէ -Eɥ"}ZIE흳݁6 Q7qHw &:4ww:j=$Lج -6ݿۂH]baD<-j.r?"%/Q\ T(gSt@caj{/CҥmX?"\ ?QKdKU`0^sd~:y#3ޕm\CӋGe1VW; 1$^#&ljjt_'wEqWX[*g9E=D˽, BeެPqXryӥwt}? oqrw9JIm|*<+C/S5b8%߃]an|c$!#OF܆% љΛCs<[XZN+xI),m?Gs4|ۓz[#8b̳;W% 4G1ׁs̶_x;븶)]ߓva\:S@Ps-^ ɡGHL~0D13us`tKWk^%r;6~HvB|z$Pam-:s&.?S!6 aAvw"QOlÿ?`(?Zh0[;Jt˖}[(gF}X..E, sU[۠#*,å/}{)*|5}SKΨc]&&#b5 ةu`L>+ޖEWٟd$%zw +X"K+M!ZR[ TWS}8n+exeBFi"N a<ƹ$J.c!޼SB/ryOtGNjUx+, $k˜ɠyh䌱ڽ>=Μ%#|<jsҸdQhmCgG*|sGQ~Q\rۥlFsG>]bciw.׀wCHC*C@FGn)Ƅ5:lPՈ=g`9एɿ֚H?\:FMM6]l*`&ll[,Yvr#IFwzo_n=0i8H m<@z>; WXmklljsk~r\;T2`J,_tX4{ĀG>1UB\ɟQP_jT]ѭ(6=1l#hPpNJpf]Bx8X`H*'nkDd!z򍴗#^>ʗ$1޲V,  ͒02KE[GkI28N24F o =1AkS/펊F7e)G΋dܝMo(5w"4K*+i|fܪ":.zѫe^/[pԵᅩLϢ-% X!]~~2P|nC8VZHlu_xI߂-潼W"LlL)Ex_ ŕеz\TK~%@leB?oQK6ERYK BrػͣZ=KubX>)5@3Dlr.Ա>q17}g۫%fP6W#/';W}E56? 5\Y΢:zkwsg*ͤǭ.Խ$ٞgb}\$T,=dX仧%b7|օD 7MEt_amUd';QTt~y[0Vz(&"ξ\c^,Cs}i&Ǻ{?i1.| ࡘM+f+0fQ;:sFKgV/a^ˏ/urˮY1ܖZ1X]f%:(ݾBߑv`@@ۑn Ď1Zmŭæ( PQ~eaDI_lQC-|#>NLuHFƳ\FCy+b3 rVqZ/Q\gBl(M!'21r/>r8q\bY[Gy}sݞMZ %Rb`1& _.k6ۃ@_E۵2g4>րqB6֐(hhJ J\}gmBr46ޕ/.iNrK2sHۣՑH䉚kܘ 3 &tWv-]8cW=SӋڑzol"5;\is&@Q:#US"1>\}c9ʅ&:x鰳+L[QbެI]$PM_pu 0S *G  T.3(3qCvkw?֚tUM1Tbd0ݔ MrqRi"fa螀FWi|KGCR˨fʉD|P5Z00Y8$-w%̺hiFߔ L cE$Do–Z~g=Z?w\N|)#`D]3Y9pmк$,V"#u5nWABYfAUђx)xYAI:6X(O(2ɖnhd-v7ߨ M5.Sć|†ms4d#Z4_Q]'Y 3oMX, }+HJc bə"ś w"XdrWJ$/qP?$[me6oߙ*B)E˾oJtYyE qġuő;S4oBHuMzJz@;?ZqcNW鵌t.!oJ93"QD̙pb.,u$(\gψ(kWUNig?@qU 5?$T0ER!bo<> "~1zt"Gݺt31Xw=*|YF҉X5* $h /+|i֡WQ/J WDTbHP-oAVr,a6,1oѷ͍&B=%I)&?^|5Ff k}u`(iN~mF:[^gO|9 cٶseOV{g|bED¸CxO[}(U󒂵M8NK¡IF4:F^ !3$F[}:RFC$c*`) Hbe7yjvKztJߣ%seP#l'1'ɔC,9^PwWF#g?PkkO´JYku.G;l]WV,*NtP-Cdzq;@iXU 5@[yD!*}zSxR>c}ee%C x؇0 uz;M+pTeՇ:)+ef7 7vt!j e:Wk|C![.% %*n*%VͫZv5+)~7&x~[Xț/mփ͈罛$beoj l(Iy[((!O۹¯B;9\6ϩZW sK 2Pvn{s,Py%~dͽZ]7 Ng`є:{f.Q ͜ן -ׂۆQ<愥9ި[WN,3Z\_:v8ѮO]jƱbOF5{Kyk5&zue9Ns!AK YWr}c'?S|Bjoȓ i>[|(4$WlMℴ"\$q惮X rJ3@:F+2y"AcGV_Xji>T/`pk$DuힰFqɼTyn"y]1"=Kn*ixGtl]_*g8*PAYUfz1fo>Pqq"Ƿ1G)Mq[\)(\dmθ+jJ5N}*YU(Lp/É"s)Yt;CqV#]Q8j>n>`oL=gA~(blKy쵒um* "c“i8d5f-=[#2~"v0PDZ[{P@S޹9S8c|]gȋ q.w1jNA_]R~8 ON|bdJĝ㗧`".D.](z!-`]u L :_m-/(0|[ 82'!lH61Hq ?z&"{<#X0@OQ,|bL"&þ]Ww3]t^LJ~JI *4dp Y6Vn0&'b-Χ*E=[J[Q$ ,(ڛ=Hd0F -$h7E8ryx07Ocz}0kocBf).A.xVN:yYToZv[q(7{G:#PZ]JZ {vS9gQdkC E[)_L (ML^1uP/v88Ǽ.=BDpq۴8έΈlKUN9iEjǤN?3߂k0)D-,+"NY9bO|LEw8 ]F @ ~)P_SA-;#ϣޝQSּcj?bO0v Z.A&O۷4ovrDYR0/}*4_u im 9e>L)[߮K ٜGz^8tc%0:]u3]M$9lx6aƪ|EJŮ/#wdhrn5Ӎ5.Ʒѽ:]֘zKCBazov{9B(~#TBoPk+z@wuQ). [LKiߝ# #F_AhnRdlnT$FZ)|ҜKl=@L.B|S J=2Wvd7P>@mEq_т1$| ? #9VSz5u"d|m=$@Ei헭ǓZ=d3]&qYJ("2ni:_躄/\1d&)Q:g=Q C 8shPj1 N6Sʥ; cPAS`;| 77{(k>x 6"t@#t:MǞg-8Y"I;9U=:Be5Y3ͼHكm~ߝ 6 \hE7Fh{*F$N~);}6a0.b5ɠ= wMz9Xɷ~6#A%%lwDT9Z/$EvZH-Kf [c>tܛ5?]-nK{j+&rqġJ ҾՄ4rjsQo0c|YDgN TUfLBl}O9-A?t[\t>6Ob ".`\b#D-X\V6P0npy8:?)9nAq;ܨ Ar0O]>!N@'@Y-s8j=,{Nq[Ť#G&9S*m⺷T T(5${bYxzW8&@+2ڊL((0VK%Gr>5Og) Ӡ"y߼:He : |- ],rE&+5&]'p&F MLݧg۩ͷ^j_x(./L ?%<z7BƸa-3Fd9] !8̡m!,I*vrjswdΨHh}OFM yIhj6(=N) ~Cœ:Yi!sѽ1WԹpjF}/#㬕M-flSi-͹ңdam˩$CZE#Ӛ[܆g@C]S )g8Ȫe9E%,)]Nt ugr"ip՞,Mk(5*mh"hs[bְ-OtK BM&x-=Vfegn*y[GUY\DXڐ5%_Kfi”Z]ODIxJ2o#EMiq? }87zy8=r7̃zhx@{Ĝ$rU1W;un-As>O )48w%8"JH'ئ˦!mtCVG~6(τr7RYt-G kCVv_Ȫ. I o扦;KVNMGEFfJb)u^)u09یDGe7kHImUԕ-)`8䋱i7~44+gQ,s9K}fX^̎1sʥ-_jP*%:Q WAS jg$Q'CejEf>⠄n0]SNpΣZ9ٰ;?*],V?mj_J?xfws!aa!FpFLUѷ+ܰ3GQ#pG ,g0EBeVdR@|Xo҇$'{iQcPӨ(ӅAhylͅnǷʶB!|t#+>l\`_+q(UԬw\T pXZ. q %F"~I|_Od|A[/f SD\˅/ͯ i 붢a6*bp3vBˈWq@za_cZLA[ĝ tMƣ2J+Vʝ4[- &U+7/zJMZ +|A Yˇ!SЅz M=Ǖ '5?nʄ2q[99?sAZ=6e;%v`]`2eב[ ^ A}!7t:% G>R’L 750`"l~rSۈT]Fa_X"N}:fF--Hqdz!e4rdwU|vbv9دǿ@VxefbI+F`jֽ~gcI c:u!U'∵Bl&8;buׁv8̭?pBCF۵O"NovpM\^వ1;C$#Y2*R͒4f4+/A??-CcU~m=e ăS@T0vUlouI'p"K]'U{@ $vD+def<LP%;"7ex{X4# yW'3$tӀڴ57>LE"kX,|×Ƽ=fYNFjT }Ui̭BfInȳ+k*6{c?-PaGHU)R Y\5ٛz.,5%Ta1ޠ9#Cc(mqZu}$12[4^bX7S:#l>ٸ`D x_X]'v>qpp qa۰- +B7e{g95s1CA.袾iUwCM}B{@  ~vڙkYq~4!rJPgᐆ!Af﹄&Kij6PGBy)=80KZŻiX. ?+RSX`(Z2V!⿳:՝>~CH4CcĊF;}o ^OP+,Ѣxb2_Bjw@O5`㬸,e͎֭mLvQ$~X\"vH/ԿHlx}dq0Q;rjH` 3D$l}pX*6(9VE".{9\ǽg31ʺޛM]*ξ ,@>Wun!-<|PZ̕|Ly5=̉!wXGN#_xsrq")I(Ŗ ~DbBnnjX%ѣ#'"i/ PGM2 > vܛ޹,Kb[!Zk/^&^őr$=&2`r=Yľ\wǔu1Ϭhޗ6!!lo+xYOCN߯a[2w% (ZaKG`wZ.y hߓ;hZ5t¿. ~Ska^wU&Dm"K7VH5cN8"fgr\!L:')lX!ҁk NW}&~3uB ʴfCս"𒇿 eWNLR9@ v)_Y<\$Z6ZJ}9DF M鄊j\-lltP˽љd f/Nxϝ/M[=7kI_f|[Nu>5 nȞ.=!  /[TT@3l|m@n7v/aJs>0pgH·V~)œ5CSYmEv[lAh)dXT@1ò }ޑ́ؐʱ;IQ>sVЪe>'%^@圛pUR&pr 4)r @VJ( &tz|>[ .sGF8g9%ᵰ'F!a!}RcoPp_*\H\!D]l*Xmu6?74ŝ - (G3H@ⷃZo@emv| iCm7KȨo_O;"OU-v䙾AҚgUߢ CO*݀~7I%UC`eĵM@MHq.UeO9 m獬`-8x.xX|>j$.86;g"S[Xn.cQC8m,ZO:.`Y=e_EGXh#?a/jꪼMD\e{Dhqf Mnrz <2/T_d4ITn9ˇ)jiVv co.܁c3$(ޒn(~<:aV NI)n,fT>&`OА؉ַ4*ʦ`h2Hܶ&@"^~>pA,fqOGTgH & w.0,DX))mcRB Ubjhr*q1ԱôwmVi׊Sv'G91Gܙ{6؀AFG/[(]buBIj[ocUuZFnLikyx9NN==,/߾e(oKb #Sǀ5Cߌ;:n1< xZIcQU.* s5ĚGcaB; eus{vaZ4$=`d]_?~L$<qx8 e "zM8Q64u -}tz0 M`X(ZYï,PfΊL 㨶%HɶN,yZʳ"WP C ,I׹lG$aYJ^ť%\s7nKB z0$nCa]b)dBJU&k ИTKƹY^(Yu>d|6hvHRJ_u9Ƅh`l\\q)="f/=q]2IύUSq0 \Zֻ)c'J8KL@Nqφt7)zUD])[|I[/'z[PZ(.d`ڶ/GPH*ՐU ?$_[NB #yHJMԛ|BGȗt5яyK/uuq^ ܜqnzN|1:$Q07 4m5 zвb$v= ~mTGHKGR~bυUTyweBB+_,R/CU:M{6J_4ӳ0Ǖ #<ΖvPxuTlɛ)}"?K8cv͘hZ)|7V[3rkXUS F& ^21kHSI=`\K&R0v\ipo47#J@HOuݛ#$)_XnkHٗEACiD™"i šAo?YVLx 5N( )$<\ߌvuWjbǬtф" Ey2ҎB㨱$qҋ ;a}ǟ5 RAh:IA8hY15qk :y 3kKhRS_,S]?;]?hbIWb9u ~!{8g~GX, d}1NԬܦmcx;XE9 3i0 Gw*t3W/$H7P,AF I1΂-)z"a""r| _7.2PG [Oؑ6 m=*jpXWW^5旯P3"(ʡVO)Ugd>ЎWݠʔ< -RI;9igb3&=JNd18big^^/lȾs7ğ*wΩӁ&8ع^Mg*9 w7b_tFͩtkdWFW~~ u?(2O#βE[d"ԿdW#"j)3svi (BzkJZДBV洩H Le> rMD[\IrLPk?T0QXo§[gIIrt;' ZvqoQ,m}ۯ}~\ Eh'J7NwV `l IS0S9-Q'mChk"$b Ob_;vwKzrb U3$ EEF Jz!c :o25W-6nzlp;F3{ωc8 Eƙrv7+ EN-&߮є9+~ONk)cs!6peyk( .Zf/Do.Of*0G-RUۣkқŸŽz>R" ׊IʘH(i6R3~$j.5/&~E[c_[vvPn!,򐐉zc|7^3W/0p$Չ#>D !kM5UJ~|yXBX?P ﭓmĠ$`v8iɺ159|WV&ʜ Kv>1ާmsAn-hdqGKfOǾ>;<:.${,qĉu2ӴX U}ϕT#A/w̓8HD3vJ0]NdZ(͔?H tGSjA[k$Z'1xj٨ӕ{H_e/,_ڰ ԥ]Ԧ\ħ+c!ñ7O+WF'kFUscO8/wz҄WmՄ<>kg<7!4hz5}?m܆߷ ٶ3r9 p -Q"C*ЍT5 $%Wo5+L&}ӵMYM\qKW#qb9/Q~|M9tYA]Qs`ы٠a/)M;$ 3̚NjW`vuŪ0R¯t9දD#@_H|Ϫ=ɴq*z-dyJxCm>$ƌs},`d"A.M_l,jqѳfH);jIwg/\*nB va#v*<ˇ%o='!?R.~26r^H$-һ.*<F#aɬѡ`5)n'd{SRʬ%vmmvQѼHI,l)Nlsȓfw5[(T<Ӿ&WfzVtƐ%BsȜ'ڜ7K=yR xA̯>{]l,n#9Ǿ"&r!=8،$"E8# m6f 88·]8&x['e烎~xY,- km X&H;#wz AdU#ϖ1o堽xG.&;ubhXå,M HcYk"^nLR~Pٯ=NG+wdj{R2- H/ )j{#,3bj#Ȇ{=} >RF  q?W6LNRu.qxm] Pȍk$ǼQe-=“qO,sR zC=8j'Nv=`G_-xZ2?y9'c-s@-Hi2nl]C94TQsps3õ]۹eX;I"?G[ZS2J{3Ve _ G>lhԚy`hMYzT*fg/]IqԗY=(t TTX.VɗHUOӰ7yex&>P!b&^6ge 2F1,WR 0*Z15*9B7RL<=W,z杬*+뜯zj5־* T,cwoktܽ3Q؏ō~9HRIeELEF[gUPߦRZJ$8\΁\=ULD9`>7Sj1@vWtœ%Rqk0t JX'_Mjnd|IAe*]GZ>iQ'kAP?eSmp1,LY0$u{J=N룈+c\pb#_Vtn@h)͛ TNR DXgN^*ly>]w|\[Q8mla6O3_춛Pn r!|՜D1bm>BKj TLeGb}Cu.mfK\D(z~ӺIl觃⮜X\T'j͋y  JHi].S%{=?S ["]2{N3\ zihaM'pr cwXd̡gb\CdHs^!'|bh:\ja;/Tm19֞; 8uo;ZT~l{\f^dYѨl qC ;kjDF@IC{ = YFW ZU Hv#7QҺxd`E%i_Z:N ńLToEUnK 1cAu܃DVA'3=ɀk!5.ȷFUMHih QC@ Q֧)zJ84g:t7O .KOu1VL8XTit4[ʝ0{Cr $*Y嵏4Z˻{f.#_AD%RcYHal[sNvXD lQ WE1M弭g(PKASu?$OAY]ޫhGn(h(„NLki szfmEҀPEYRD0D*C3k){3_Z.@<݆*mj pq{tK"`R9ps~75niؿ+ȍ=2tҎ(Ы Z]owrWaS#;=0`@W:EjϞr?a{-Q{yvw=Z{^;eokq 4%szEX ic*5H)6gG 2T{j wb- FP'aCG0F'ܘJ')AkaJiї@uE/φJ@]EBc"G_sy6zzBÙS_ ^Q?lhX6iz(~Wc3^`՚Me[sqqkcA=#D Dwcq jM%k=B"uV{F5"B~S9ԱG@ 79A'T1g5\WFm%_slMaU$VW"P± )'+gmx`RIyFGt@Ӡͷh6 \</O3w:w X˕ b J1#T&CasJ .{ =y?g$z~OqH8R?zqXTVob|=~Xy0rO'&PG߿7C9xcUA\51knhQ`[їamiO_TȖ-?J2~[{"2C=^xꦇZC buJ_uִUަ=WlThYs-T Ejc'Sŷ0{ Q|}^1B|G"vG!g loo-*\f{9yGێ%" 6N tG+J?q~(5ȣXonQ![k-97&i+ )(K@5^5&{|DE 2MLYlä?w^y w"ΐe$PIl_S\yCYLGGFĽ[f9C|CJ/%^. fּljӚc~ fR^OL\azo +co9ćtӓLJ4?*y9cM2b<-c|tcn(gǤ3Z\&4{3k!3<щ..KYm#`2 3{T" a捎OA&HM3n\2KaR9 [i0&>SY7]:J2W<7|]P|`,ʼntU {|4V 8e; JԷ{D§/7< &YN_wW'YP,Qo9> !CK1 ]լ/6^(8h4&r0HqpxY0]AANZ/rZ~pU^Hpoe[dtГ!|m]ew#YZYL#XвΣ l؉M/0/,S K7~J֥kN"l#lXE;Xl `℗Ep ]Q@>~Xy'о _3nU_43 |k`ѻm7Ek6(Qd%_±4}WV04{> +E T_/lCC=ShPJ>D(>vG"qWjX; x3VͼcμX MqS}CHi:yaP{ʍdR6ㅩQT)yoEKw*]`$'>~T$rT+ϻ7o(p U[Vu~S{vT/"T*tJ(Dhm! HS6k{ۢ ֚yI-*uHi fFrٕCE/=D~ E84Ü%y䟽\ֺ +PJ!bǶL,H&Je85cS =ywm'ee:xNܛe'/[ʼ]!SV ENUэ_մ 3G`2=#ѧѼDw˲_&$"K1grfCLD6wQ IuN_ڌVx"3lJÛ6|.hz81K*qN .6W_XsS!D/o?RKV!8m¹rry%p.@&kX.=رʭRm]rl1K;;/&Z?}i;ľY2_,YJy+WxgKa HxH8%<Sc#WuPhfF&V&yx:SC +3M7˳) l,#LZ_X״l&aK5Kz3uRK'v$ g ePh/NAVߐ´^9Fr\!x<7:DwCXx.@\'*p:>E )`i|ОC= 0k1B0"5WG< "4B%NF G+{RQ- [ґi0Uq^5>A;A3Mө.|^5wzUZrx6zȩ CoSd[=>Yd&*Eg,a52'ޚ۪+lۣkDH ٩+Iw/h_2FdחU:7X9O =.(7BU;G6-d6⯅ocRaeQE5$' :iQRPnMɼ={pF8_ YRVEp̒~,A1C4Gj6-4b&koغ}9蟛-ȑT0B#DZIn]J[-Է r{\!i~!bǛx(:7F)>EV ("!p_,?z Dp"689U׎(x׿o +>S;\ėS-,\ HZUuuKoSa3~]hmk{CMVSz:vr"kk+X);E2.fv<#˔p[kϗb,hSX)u tu*Tgج?WrSق*ҵ1@N 6*SZG ʑg>>fW:z&`˕ݙ=xVQD Mz>qd킸 ^p3![',N_ɱ7\?z+1Cs 60v+giWgYt:#Ǘ{(ޒՏTX.;w),|qdf^џIUД|pCco `$9‘㥑e[MIXLt)/ȂT gf~ys{YKj/KZVz ;xqRbtI RRh]ю>a( \l)>%ZN>x9 lDjZ-%4I&A:ҤxV"/5Œ s$l}vPyAs oh~/1@x {Z4薒 Y ~:D N'8|#m9.WzզܵN?Ƥ{0sn-$"7USm]wD~/A %sAk}Ʃ BȈQ'[AdBJ=/ $*766笗u7 Hq.qcgd&:ɢDdsܙr$d 4pd),'lY^uepT$ԌP{^huQ"7əȴ9 bk")^}E Qw I[!' ]g0Dahң@ [Um V|sQdu5ORNfɀn"Z:WK%Jq*dRp1v+#9+z܋ ހȓ+Xr7걠@mB"yòȤ^\0#)q?Tu3{$I [y(KYWR~mP>}TDTSPs\-E`÷ij\Qe1l- /C9XkJ~z=!Z(G0٩Y]*;HK8nXa\|nGްݍ0/%cXn7֜/jp}%nNfuLA ^ '7˺b&"=z|kw_7EO?3;D^+FLGЉ=ؽ8\ZGoRKYjj?S&RDEp!0W){nWhml'H7$AdA/Ongzò%@ݱ8s;!~v{m B̬#'Ӝ'p4P(ئMDȋH~v@T~zt̊2Jzv|RujwzY6,_Pn| jhGu߇5Zvo˅y ) әe&DDD6yaEpʑH$XcEk]]QߚuMB{:IҸnv5;?gG0:C,XڝL(K:!:=ӣ$$!˛ )K"W'_'nf @>T(|]|o*j籰G#o] :y')UCe&PY5YjBOcmC@o*?L$d&Br#.tf$O o3w&讼?(9wߐ5^BӓxGvQR`ej@hn[O)([O>"-x9Z2QFv璧H Y$TPQQ>RD~1.OT/*F+ZmeZ7?32 SZ4L_ΒF &1 CsLѵǤkť!=6OU`蕵/Yde$+ңIB{@ ,'*[| [6pjt3yC_@ ߒ[VKa6REK5um`Y npR DCe/C`9uE~Ƴ@L˱|IPDu&9{Z;C׏U sτB֍M- 0?g =M_{X-*v;\MY3mqQ_4+,2'Nߤ-YTSlaV@ !4 H$2 ՅTD_L_EY_RWNqkXbm/8 oˌ&^׶k'Qhj2]Bs'DnڧΥ*P{o.&rZAscᯗe=lJihA55@/Fle\oUmv+A~dzf('' o6eI4tV1ɛ'8'MA-*ӣKj.Z]Pnɂp&[µ%}2UfSsSִ%"BHVEaSXظy$uA}Z'~jAP<ŸiQ+ FVAi}3Cd5^4pTdE>v }"M(4񮼯٠sʸi{ȥj%Yr o?'h֛ةpܫ.k7f i0hɝmTbI&)8{y*wŲ;u5 mA(l\=z)K>|ޮո㊷Q-^єTWy9Rkz^"bu#'O=wRc~RY>$t%A i#<:!21N=;|`DB¬^ɢ|)pvY 6 I?h,R0"'Z-:1(:7tMMSP$I E*֋TĒm,^WU/]2$B[} UML-O WJeZ 9bS%] A=Q2IlFmG"tAC#4/P/!ۄ&[vOzBE(P˕!ysT]ꓣ.CcAA걇?俷Pӭ%RsbgXs,6l>tWZdz^A]lP|cN⭙%ͺ$_dԠVovŠdPD>nbP:U%1/^ -s@sƞ0 {66vob"A89% tu"B~ҀFbIoYUzB޴7a[eѮ`YnպԪ^W? l 1F54X [ hv.%)%Oiw^F`," d©ǐ'a||9 ? u(ޥS o^"x2B$ rENITW1PjB]E~6j03=3\Q?nr.t d^̏:|:#rSq1[)qνG+VuH%1\T kK[eȶ#7wDM6F౺@{:Uc>oT2ߤfҐ gg=MQ3˻.HNB)IA4V? vzҼ#I+|xq B_?m@e9P ~t)|):g?~]78: vvTTr͏O]˱Pw‘? ףtP`Cd骻DEpה M[{N`6yUsNtmq#uNY~|vvQM!2<1uW _sD'N₽eM2w4<o-W$7#3"K;dA"?Urڔ] ܍THxt#G8%#КQrů29)Tb۠DŌZN}9ʸsJ|k*ƫiA6:-,"!N<g׉&ۜϨILF ^svFrJ$Xb82!;yqordW뤬n:q x<6DJq@ҩG5LR_۶>?%XBE̫A O{uiRBDnk4dx q:KOk̓)e~nk则L<%{lTcZI3i.IXWVm\7w \E,gntbNK+^Y]6U6"Ǯ(Ę0`n,D|dke Z~-YuVOrlc%,D٥x(d(Uβ,d{lh^,%ʹukhӈ~ݹ1$EB5܀P[6b^<" #tuSyRXJr:+pϯx޿(OMJȧ>NJtZT(HQuA<4j,U"#xM1 _Vϲb1sQ3V`êC%X/+0G?5, `_W9^mTeℼG U&!OH)vq?Y ԏ_h w(P2ǪЭ 'RoZ]?Yoa(xDQW6,“Ooʖ8Jrm 'n PʗoOQ#gPm߾yL|kC %DL}A섞T| ^LUn(&^#+Zfntђ8wWX[\8n_ṏMԲ /D1;0<5%pH_tQgpt I]0#GZ!%0s3{س‹[%4gugam\3W m@bUB SOP%A9]yX?K r*ꌦz:ž> "%IҤv/* c[-}|"ʓǙQ83 4?XG/WfpHۀ,BD̢]:sEV:O+|qZt3 Q~ K}GH!iHA򭄊 uT[Z$䁃1й #+,)5I\P<ǧ&6dD] G\c7XFny@@1` J2|ZCGUkt@PA`*bRqE/Ur¬eebN+.G| Lt l!*i 8aOij9ɽ>)*O\f~Un ue <~U &8McA*ǖ|Qڰ!9JDfnGcm_z:4!d}ad{Qzp\zЍIkKri/񅑫$ʳKm?yS^.Edxطk@ϴCd⢰5?Dwta2ہܻȓuЙTZɫ3U@2ڈ#**9WD cFTb3qb$ǗĘ/z(jtZ5kn`4: )Ҡ_+wTHI[ƯU1"?9h8 ˇ.{`;U4V;A_%f$R뇦Yz]hY#V\`1Jx5LeԸ^KTEvA ϳם4_ Y opіG! Bߟǟ\64qg&ՖPlтop)XcXҙp`/| hbc2rb)\c>'/K(Q1xU!Cʫ~gy5ӄ͚n&todB+V!ĥ7۔fo)~b!sor4%#(_-T9AFzQpWGgrںuk{ ~l -UZ >}|bsRyQ :TxB1 i [M f٧1ܸE=3ep;h4谗t|X/81z0' /)Ť0#UeG$&}FjQ-93uP#yDzGQi/W ,7xhؿXDnsT WUu·\b,GrC3jx/bꔣ=Ih`]|+,9`])4e6<Ѳy fĔ%Ut}F~|vRZ"ӕ]WYpE8 x@|ǡ-? ,DG= Ya92C +W<B=D J7H_6oK0| zђd L4a؝ɛY%@t+*_C,B{sM 5hҬ4VV,Y|d$cQqo֪YLnIf`kԤQ>P:6#ݭ9 BQo:R=Újע'!9,ETK դY ֍NQiL^pl7{N Q/)KUϧ;Z$Aג :!Eb_<L`~y- DFt-E_4[*&XT5rV.oI8(L/e9 -ѵ(>VB.*3ԘQI(',U[cb!7㎾@mf?؄TA*r>Q*R==^z8ܪ=3K\L&-Jyrui\f6zfu9~fmG)韆umdALKk>Qk8'P۩JF 3tSWF&eo|B* I9E+\&dXHֳoLA.{ Bt]N !TdD6$>%Vw+ P  Ejmm1v)lJ K;uW7S ':c @D,Gfy[,3⍹R!:rD pmq E5E v(GN`1F|ېsz'##=5 \4-a}Ӵ 8W߱I2IĬ[Lq?sPHFp,i#T-PTZ$:`R A.nP"D£;nWGzݽbq!η`!ޣ݅ӹ5%OHjې 2|#џώUһnO5*vfN, MM5QatC1%{4%P9w߷gY3WN~CaԗO5)dnĦq4ыE7~yD@o l#8XܵXkʗtN uEJD lVoKWȩkdZw$1"T:cn`~8֊|g$B ՐM`k[&2cCW^!9_)RX kNx/ѵ*8ŕ%3E=kCpċH2TܢcdΡ.]Y8މ4eja6Zc&~* C Qlӎ"K>NƟNA_|9ACØh;Jg 8&ĺ7i/QgE2嫅ΎHPe?U媗k{YMeY6vԾKty^5APQxD=ٳ4d=J Сq-` gˇsCJi*x90zjhr,}I0yWpiE:L_(/8r,9b;چ#qi-2ZUM5tm x(?>2`J5#2UhQ;lh:u$GDXd]NrAY󢩘EY 7VnFX[:'TvA:zf Қ R)gbE/p`N4YZ!a&:ZaA(\-- Z^}e~S4e4ug j)`d ODlҎ@RWH0P,pBWzƒΟ!Whg/|W]y;@x""+g| JHZ`:F-Iu *<;ԎNڗR&d^b6:]K-ӍNh>JO^{bU> ISي@,ؕzɰaD͟fu@bznXD6Mw(VB Mbpͺ/+l6LԬǪEr~郙)2(90`ݓ9q(IGSͧV8:H#/A=Te2Y=B̸U0 ݾ4Mlҭ7N(=B_o7dO"tQ&VoU,ͭK^5uJƍLO=ȣJ$ԗ6ףRV%=96řj^c~Sؗe "cDMҤ4@=Nc-,'IF&B'v1f \F/J4p' rkU+J7a-fO}yo ^y.:KZP-%@6VLqc M9l׫ XQEm ߗuGhOYkd׶39<ߠ2u0'=t;+B} ~J<)ghd;|mxL_^LE#Ow;94N90Nwep60(El>::Ə܁jܭB#l'4ܘߏ~ܛ|>*SJ^ǒvPU?q;X)uh39D ߦ Fv`L@Q&£9^9!zU\ء%3S/S7W-qP}I_|! V[wڻr 5LX\jxg&)mmxSc'#eK_^&jސll3yPv&$Nнuiju֚@"5rlRLxtqIT(IiZĘ<m_UߟX. A`)?nl>K,-3X, !ђ iV<)n y| j_$BQ$")G}̙Аj[nNZ@vT$y ]zwp-ڄ@\/G\sŒ&7P79А#µ : Uk5^rO7?j\-:p:@.킯Zs`D@'N"2: KZK`wsgqFn-{R'(fۇP|r/ 5{.߯L<BM z'JM={xJ쑞ε:[ 5w  ܑi{~-W`K, ow)Fd# (ӖVC#W|y6z܁mg@bm FȜc2,~g!I =!kgb5>QQcNJ}ȼ%:bt&db}jxpd,F.s$0o|s7ЬCO?[e+rtH3F'j:N[ HS.RK_r҄G;!ⅷ^\R׮WO`rz9uMBs5?;G]e.n͑ N,0dRR"l+T`'[O::^|IVvvہi#h yE\uGÚ_ɖZ|#J 5pnftлW.> o61gl hQ/_CjF''7,0m/H p0+m@r?eN,IܢD_EmHx%U9׮0b՛;ҍ'FX7&RD ukP?\1a yg}#nF*XB/GؖL,!hl~bͰ LaCqᴆF3TWG"gxew_~I&}0 9ۂǭ * |CTW ZC? OA\qta`  cNPF]M0mWT=a@0ΩÞ|FÊ_J'O]eȱ}l^hn1;P]#ǺX}PiskN"%GI zZ[$ 3VՐlGhƿgb;$nitVI`ւ | 'iI\ӁnA]#|S}bL#&,:̳Cz_1RY++~eiO H7]8gb蹝j|bHq<`PIE׎xS8kz>̋p-n2{H)Y֓f2:;L Z{{W-\y]?.#ABۊ{3-Y u-5qj{sV Z9}/ l‘~MA.dWߎ ryO}.pӘٛPklIW\ۀϮ> ku;&Ubpt$#u\jڎ]6@W} 0jwoC`nrW" xnJIe1A?(fP3=0WKuhd:u9"ʹ*d+餯^'/ڳ]:?+Nm<^CLbLA8]c_F`A(+ņ"`)^#.2 1CL xz2]hS; ɱmpޑvk3d͟'wj(k#ן}pdbIX4TH&d~6s/#դKkF;셚uLPo>~u^c\ Z;vt[Oe{şW)pUmYۮFIZo>3JEmO(hX380Qep/k=bu15諹\UZ }4-]߬W`μOY w2V O(ɚ)3@{*  `dka³2JAsY&F]_zGX'[p 9;icvr+#Y#]zTǘUfIlĶSs~t˕I>>U2F(Hg8|[b=!#Q|\i{ 8u!zbk+WaTe;Tm?K۲"Jil?eC0 6B3cz氪ז;),HkǑrNf%(  zqX*BRi( ~0I@;0Cvge*<`hAW`†]EhC)I2n4C_0=!T4 r#ŤA+QPNay82$fw;rk&Y~Z$z#9ހ@#P$P\MlWx"Q)?7G+ʛ'BtHp-҄$9O]9Є4Vy5Yd_/ peJoJ#Т`QMȘ:K|AtyD7B ؒb?vUp)VɰzFAd{SǢ dDeHx3ϟ|x8}*~HΥ2~1Y0W$XwC <6 }qԯt /rG3It C~\\V&=$\Fzre;set3qZN΄t-&_&d@-w/b8/*YB 5zK#+LŐ,xӀ֩p? `!_"6PV,!]盗LM|SeP@N}'65m.#^=]^G g/ .~+hvރI EV]Wlǒb+7.J=wo-;vi̙"OcR\lXS@[^$(&:sGy?QL@ ia;e3.wU$6{ q''@ƫWdU+Z 'dt&Xik%Sʄ0x7y#?َV)dxDoIZBoS2gމ] Ȳ- Ju$Dѵ239/&E^eawZ1KW83fh̪o rκ \f$tLq``Oq51\[PGMj$]sd6ҹʑ}OMvͺ4KAvm& yrR%^+k+Jlge+ÚfO$$ASTrCSYI\OAwT[ b\b0:21FjZ6"Ur\Y|UZ".ѝYIyGn Qa{lmh1RsED}Oe&URgΥ9kt&_nvUP.V]3l 2 p2.e3.w\*C; ّ,O;7Ύ-T u=u",49()1V.f-$9ĺeh+qtעmt,s6+4 8qe)gepv=O\a&I7֬Tڮ\|&8 M).lz_Vb!AY&ۢExw/uֽǝY, Vv\֩S'sQ2œ߆<_cDmVbMǧ˳ڸ/bFC1*?kE/0beD^JzsŰ= D5q Y 7PWΊ8x&̽wވDљf3X O-;B!$o8 ExcC-j`3zOz-@{8xWtf?deY֚}qqwO,V[Vwp{}M6y`XفOD74eDQL(VZ4xD3l +Ri  h}WS$*82Q[uZ +\ m+"W2t30O x?LgU3=TM\vazP癟ҒAz?xat{>3K%! v1Z'F`Ba@z m;;rO{i>Cȇ1 ȑ&&ҜD!-/5evWXFJi6&Ab UFnj`4ԍVj)XkJy@eskk;c cr0A1cB]hQnE'R٤.;G=7ЮZ[e65Td-fR8ę$9:.$ˑ++=TW5p[)9ޠ@ߙ<0(1s\ɗQU5Rl(M-{ɶ6iM5*%?uB%뵙/vAzPc& BpaW:A5bja=.K8)7j EC,֝fieBE8fx결؎+q`Nmd$JBds Ebn<1 ߉UV' C9]sa(ʅ"IYd_5{=Olўh" 9Reovo[Ђ)_o )^ x ?:VŜ( UkV}*pDbC,!{^ eء 肘9 +?e*5TX-% G9 V}n:|ZLS8j>![2"C tS}d!kP=t虶!Z>mF Fo N3>W+B(=aI#h4H' K85;j(dIg 0ǧU\}/5'ٮ\0ֵ߷Xcch`>B[0:zJY'& I yK@+3 Aa{XndTLI;댛i'n E}J+KMm]ݷud>j ^1U*ar9VUcz-<9nhFNk;GXH]+?\{S^kZ "Z˅gk҂((rIB"&XULZCvren~Wݪwmf2S?3[>¦ÔAN-椖.=x`yO5몀^wGƔ[EzSldTh6ϛQOR v[L:fOJj9bkz o)2uPd:b~vU<,0v4B"eZJl[ MF7ȳcBU۽7=OǝrC//FVڤ涌 UmYo_DH45U.ߢ sG;0ljyuvȓ]V 5c;nXN Ltn|I .SLfyqy]1gCq szЄ\8i;ܳԲu xi?c | _,Hrl]?'bǗ.*N/=n*gP{ uш =;hD??AYty?eTF#[r 2wB xӮ+)D*@;7a֝k t5ӹd:>RdLLelN +0;!I&( $ $p&ьg\$k]$LY-}&Kmq[/GbYZ0 D a ~d`R_ƥ*x4Ցk}5 @c\9c >amq&@q6ql')%n&(= P7~urqtiZB4ϰMdGj&O+6Eh; M󎁨XyY Иa498p O+ ybW~q#QyK+ !apT,G}W!M^김]Ӽ56{<@-)Ry`ZHJ, PAe움Ei9ׯ[!$ntkucr}><{" ˁ7ư,Fa`3<_4Ն9~iѩP&LQ={At>ꇳaN \]1]6~X>ȮOC^.A([y77㱙ɔnډCV\"709($aZOvH%}J;nTw?Sn,1 Z>=*N@5MO;[m$ƲjOHsSY֜1ʧ8rP0b[v(mqH-K& spIZ&%Ү%K+q,8B Zyȗqo<ŅMjE+ b'1NZ -N$E\CD}U\bv^D%c_fG"!s(,!<]\(Q"H:c+ګ~(_y?i; ?o x*.jk4rHXz!kF;ͅ+x06s@϶[0K%HxG xAga160TU%"1!E$aX+عLq">ƛZJlfzJ~!>Ɋ xPEә.UiȗpdvE4b!:]!yH :|8i=҃2FoQ-|EIZ*RUR_aZbdgX,7*BZO{]BQ>S`ш#c}\ɰ|2gwtzEFS-ƌς2_RS^tR}zݓVVYho09Zw3G#ǝDǡM +fnTJ. YdǸMdP>ԞX5/d8_|)SD[mvȌ+11m8m"Q%bFqUIA[OL !h]bY_ΨY_Fn`%v=ՁtRNweDxP۸ vxۯ~p'~m (`Ā *q冶 :h{*F#!F f dJ0#K&Vh'f&Y=_whXʺہmמ^Rwש!6޷Ԓp/K(<Ćϸo}Xz 6R؛d{3r+=Y;ȯ4" ld;o M<.x_PڕL KfS} rHiBYQ!Rt+BT f}A2u?vV"xpj&UŊ|bНЙxfˠtA @Oyf 1ROgi~#pLjcxt7T2p> ߀cSMNf͕yzWH*Zjth+qXYiC^rA~ 18 ! ?Çd]ՕVatqg;M yxz)H9[\ohqM_H =}uQbn5o@:viK--fcyg`xU%ѧ>k˥3*M|^ "t"?& Xڣ?Z0EBA ;ZQ!gܪQ H.==@C]iIfc?n&3|o040)W !]!O5S){: (/|\]R/gge;dZ*WY.'JS(qT/MAaLgɮ䧧13ӛ3a=vEF4ŀz{o B-6CĆ@η~kӖdM^頳o6#8)='qFXnwO#obO%N9R!B)n2sh/2фC=> 8a%c}pz+B["]ͺଖNqm8p]kƷa=z6)~P~`Pp$^ /"x)9Lڽ^o}'7>K5==k  |N'Mqz a'?Tfݥ5b}kA]˜H` L!a\Ct^TyB5((jdb/M{WQ\8`IN?V>2;IẨ(d?0[Giۚ3y]" iyhqW_ˤ}*o&U &k3.VQi@7QM )-@TqߌhrFds/j4%dJLcK=>UFCۃv15 ft{)qzy5ZN+ a}57fc_ b j:P n:_\VhTڬ5UIS Q!({Ҵ&#Gfi/B7kuj:p8A͟GHWgXC -"&;`6VJ񭜣.%.0:%#*8d Kg۬ԋ=[Kbki e"*Y]Ő*o\lD3#j&)@̮WjUlXZ.ksh̚]^ʱt= N*+0 |_n ROreڳ rZV[%T暚B#glq,_q،;H3(;Fɜ+Ht\}`VsӉyZ_-AS *qЀʮTP>n%&' g5odVV8Sؘ<\&a$ݰn`]1jބv :=:ROs﹑JH-1WJlRF̭񭃊|Gs6ChR^Ӑ# i. @陥tZFCrg] I3p' :0ˌ?anW( Z%]ٜ𪥔=r֋#[ݮ Q$աYdx7n;*-jZX10nѲ>AxtњtzfOuUrUE\e1 +q=Ifb}>zOR[L,kNVahL䰘wIJr,H|Hw^ew?&يs;)CVDrşf$2BjB_p7F?/b f@sJ|@-$a}QW_Y:/@KgkZV[0YFD  e,8 @O U ޲qxGV!9  ,ZHMt6avFe ~&y"E\ J.սmϞR yzE:BAħmÐå3:҉tWwBSqGٚ]? j~lC2;8ad߰d<2Na=W"5:dqp{ry)eEt=.7 |<+1wBu EI# 5d]BPKF$90>ݗH]<Ũĩ{xo3cDjYs_ԙh%\21h/i,~ƏWt^ e})swB *5BI~Z50ڙɚtoS$woBƻ8Èt)##ci=M$)ET;5166G\f 2\}I@fJ$]dؑ=gd=D5@*:ְA~q)J>:ЪqC'?8ޠ}d|da,EP 3"kM=,r(s]6/Gk'!Ю gYơ5yE (ᩧHBJT$Ŵ\8(j6 [GMK$YX6[h2` F7h{09;WXJg5RrN_WY^@,heȡ~ޭ`3j+Q$?*z}W v=ߧ8%BRlz)k838%WUèq^0wAC=/IܴF&{Z-Ӧ'GDD7ĄLQ>7Ӣ駷b/)98xJEGVQk9aSd$@ ruh.yo2w,(quBvEPy A }jB`epIJ$ny? n/vSxSz'IJ'iM&;jק(+#[&\yvuj\+E4 ,|gJ$-\ƅ nd vv# Kɫgދ c"X"ޢX)61>=6m^3+mH&&8ɰ?q({$Q h_ǠJM&x-]c{\̞Q` ?cE_Nb3r{VHNGlr&]i[FŴ&ߘqV6[`+G> V (fQ]( D܅,j2Y}TQU+ič8^@r>oLH)G7p?4 qa-F- FJ7޹5\Hl!OcVtÃEQ3Cgs΍Q ዲ:RCW_XkDAoy2a[P HrxaT%$57Z'1&oX.R}͆eG$OFsc#ŢFGR Wdټ4'|{2u"ũR*/5)Sǃ[+БClHP u\zdk//eX,!GH*bԩcy q7N<9"Ng:ю 7h{"'5hWEF>h7altuɉh^3|cl^9/  ن+uNJ֯lEilTN^CLWAp"S]5%QnW{zAݬY7وOCNn>y`+\mٝ YW uG=M]Q݇E'WƗ!1BhPONfboh$NÅdsʓfE6_p-(مIwR%P{͋EXh2vj®Cδ^w)MH(7.xmwNwS&6G0oƱe 7Wl J7t 4f߇Yz _BK4yZ>uNًq&$7X.k=Fw߇/f4@ vNMկUK+d?njg)[^Qa| _j͋Hs@49eU'EKf|-ZpwtES?+V$FFP]}އnK|_lfdbYӗyt7$7<.bnҏ_6%BRQL9 YFw'-i%&椈!M?M,8;{=͵wihJuLְoHߎ/qĽGgmkyqT'KyM+H:CbOri1GCu\r}\C{H6žaJy8ȑ+{Og0K՚.;L @M1BoTAc\ǵgLGT3l0Q>lp_$ٞhFdfɰX,dؽ "{(LZ:co)0:f֢a |.UޏeNbe4)eH6 dYBf~"..+hV瞼dm1>#ɘOws%.y1}vV?x'Ź~ڥy r7Fb /6 C`'?Q١kM>uۜ}6/¡ wy8}TEbf>nO|kY(g9d|'KF`#f #K 1Xq.І#8$Ffw–Wa4Yۤb]b^K#)]x,>t*:7>Gi O 3nyJ$PǾvȰ&tKVqݢ4P. DkZ /.nցq*KS3̅eh9WLk2 WO-DPmG䩁- Ool>OsT!ܲ-pLHenV{^Q{h"`|ãMwKZXf1Y꬘>v}.|'FruuYWP!-R8_>@<:~&R˟\2cA.dxl$Z{η%+s kߌ VLu3ߪGęAh/M vo9Dx'˽B&Q5&r +đ\`«%&a1_֨MM5P{m@8i%7k<س.D&V6.Q.4T“ej92'gȖ R@xK4  Jj)ZH{䈔iBѧR%&>?zP-sŁw:()ԁ"̍t@Bٻ20Wb/~0;٦hH^ڿ2WF^Ċ]io !XQe4cx[ ϼqo}Ա\8ZFXȒ07qDθr2.SqjA@!Ĵi0jK,7<}I!.]aQ U >>&7x-iy W5})r!XEri^ BYS~ ^V(d Rq5p7s$".D5u\[Ov'f̊p%_S[I?ÑI7;X Y<'/Wl5Qn<' xqM<0&#  z|͙z8>i}rĖr7T8R[,@4|yx "Nǟ~M,5ѵІRcѤ$fU5 DG$)ՂPDADgρ;%nìSdayj/n]QcC|b)@6 ]l\[?5a{w3ZlAXfy L<41\^j4xГ1x3MBX*a}Q8jFb#L]/φ_o~HGjׇ'ӵv是3URa_ i B(ֻ]E0a]4뉝P9S;_hsG#,9kƸGJh4gka{ǿݲmTn~w<ob 1%l/n9 .G{/+awY(aCL7③鱼Ec#W>oVw@*UKQťN6|DAt6%( ,>Cs% crYE6cQ WHeWeD6|ȑ5DE(pU {HVJYWdvR^.hE`pAOTi6P8k )W c$l=XV!_2jjRFQ8yrvG8MyV6m8:FPCMݓ_; Xc\i33<jͳ@aEpr$wU91a)ۯ g^,B̯ԭ:?@BMpeDRAoub1:)Q4qe#ϸ sIgQ)֩j# FOձ 9#k^2Fu2Ky ]5nJ𣀦^JA )A/d|i0 = R_4Dx:-7c ?ykDI5=)3Q+E%pPտEF~@^`8Ε:jƸB`߆McD&7ܵoo!z:H}[ՀM}mw+I1n}Λ-OLHt6;R"=GSxQEZs.G4Ps7LArXJ̻U9ѿp~hF,3-/?`"R`>Z[DH?g83I [{J`}#vߡPUrj4 L < M 6+#ۦ: rK__Ey1[2wuRI)d2i 1Fy.Af 9I͗W/R@t0GÕGvwAOudx,și>a[6,^>oKƦCL6[A}-{xPh?w_\Dȝ;sg-1BgHk(AVJrWWCj(b6qC e+q"cq ͂5X<)zA^)JA*+zV%,l.'1D7Jns9z_Jg-]Hflu,|A4;KaY!^I{t_`̳N@b|*۴y%;'p,6`Q36ᓚCp_)0,x=^3U2c½pG/ ;3e$O M``-Z3Zߤ$N$ESxdWkh/.yâ0U.!:7魣zvY!j>M"(gjr2ڀwU j6ozŋef%&F *n?@4q`UÜ9W܆{ :RZRf`8Q)g̾$GҖE2쉠, b%|YO7Z׍^>`=XD/85kcAƞfNȗ4l ays+/GYfu=v"3!mtߣf {#z^+XQ.j:f*`ɾ% `x !{zE gRZ>̨@-%z_3%)օ|g N_7I񧶅pƔOw(MTGT.o²h帮C^X2l6ojU6$KyN5.I6a*7W,̥ɄH:u&r.KI|jTi.⿚n+s,CY}_^H Ul}PҊ >ĸI‘"v_Pέtɿ P1ZI(Af;K,2#[Fbivյ +_ qQʣK((N.~ܗ#[ l{hǯkhYpAx?ciޅ"hn?*r`Ձc ZyV$_!nڻnL-ߕͶ?,yC&pi2В0@ 2Q5.iG6@*,ܡ`˴Ȍ$kA g>m+D7\4 TBC$[J.*|";ز_07q\gn*I}ζs) !n= R9<jzD^BQ޼I}2 HĐkƝ;"VU6,<,!7`7b9CzdT$Rux C9sEziz'a}ƒ9^ ̃^kQ|b9yW3BH2SӋtMik XE "pQ|9UW${Mq t 7+>|og_|n"l~83xc.1bI6XX󻡞Ye\!]ɽYl0~07o=G( LfΩ+V!Sln'G)޼w ߳Wn`9E;I7% &9#lݵ+KTDF560X^oҘU\OOsbiSSC#/;]p EpGP^F^_ O1LTT~0O)" Sd(Ic|9oWp)vbWj1ڑ1܋(SzCwB]E'&_~p.ObFEkh\RX?'G&{ۗV]N؏4jN`p$|E׵qԍa@\% YVJ<7 RcxQ 0=GY:>)Á媷vEvb*S]tGB.JPgg]tgciSO D)i a&hhY~eefR(թOeӰJ\Phs},L(\dt]lHc;gjr'l_\DCr1\V o^izDy_`➯X{e^:AdSNB{hQd.?y>V'H;XsqضvV1~+z P~gl;2m>A7 !kVk:ȼj-qwZ#{ACi:LMUU ĞQ\ZЏh@N :~-gTwZ▱ *\ c/Z '.Lp9gH-B| -lv+@ &&-BZCp3]6s4yK.O5VbHQ#j`T,4-M&p!Sk%ASERi'U:7iCǽQtCJD'ZfJLrI2$[z9imz/F }?9o $Y,l?̿kW*(R3G7J?3;1,3|=H[CtCk-]l P`K^{|# S>:#[;zX:}_8%=Vh-nWUT^!3Փ?9&RPPߢUbZϤC4uX L=^r*LRi99h' \]Yl"PV91yI漟ggC Âm )>Et[U#8ΛqYb?]?z(LM6Lخ'F#ЫY{7\LPrGB_3HJõKҕRBe78K'=!ʁq?^a:~#ʒjd0Pv=rd(ss4BQRku7E[4Pei5s4c,}:TňcZ524 ~<7,;pP S'`>aӷ@O[m}g>x)8y E7nC7Fޅ5jOG`P!2%G5'm}:X2л`;Dlp\=$Ҩթuei\n)i\˃@1:c ?Y~QV5׮dy6.OcS7NJAPM[ž?$*}{ڛpY*BUaӚ$t:LgViڏQM`)Q|`)Jӑv O>ȣRH~G =w n{Mk=X͟mݧ{/sK5ċ4o9Dcc!}0µȲ 4v99 je漺50*GCW]Ų"E{ G-*cJ,GF'FMRꬑPUOf{M4 LQ=5n؟%:o>=j~ȶpsT 9N٨eFU^7FXUU{C"9_H(@ߝwTʴEޅ7~([[qʁd?Q;; 4x.5sF"gN?a1w|7l|?ciba8N)40KiKEw0c]/IK\"ZղC ̀^Ϳ4\2G`.;HWm5J+ Dx8'9ҽr[Pk? E`w@D9/CP&yF0|+_e U.Xz"TGM-$K`d8hφPkh4fs8 ɗCv D {` ,{Ga[4"C,4G+݄9.{*.}iuO G  32k˻SyTTߊP).;^ k@KJC1n27ӞQ!bWM8z]]Ÿζ% foRY9E |\gGg1Җ;28]D2n9_Ud;IϕlSgWٹ_]RǕ% ktotm5mqs%NRಷw9n\aس}RP53LƣcH&%k?+L:"ϨбGc B%~{~pG'$$:jJ . 13-c>5)bbґ\48T 9}jX,Uw 2X@D@ }5Kƙ|C.}k)f6E4~p'`5xMgf)C>x%Ðd/qOп6;I#a~cF ]G\o!F VF ҃*܊ቘ~CT%)/Ù_sbG${{^:DTHgc)D?7M{(._bxKhЖ Z2+X]o\jd~Y)3& VwFH3ܯX]~G +ij5= )[fٙK3l ۞FC쿛ΌsV+eaV׷N"'ڬUN%0#g(gB9`r܆M\s9fF?;/A!bEOҰ' .dl(2A$y Z9Bx3\Pg!-B;f#vjhhNJ5Xy"=K7yhTe%vZd9>p&S[zޭRIXpD1a?{Qfr47[  4G-6Z04=V+AF q n`{#jO~4'XPETpdF5>w]0#dj2-p6vT;o]Cc~u+ !TLZ4ȟx  a8gVzpv_BܳQ_J3LbT.2+!g(le`N*6iNrR 8jheTT gOVFɛDv}p/3(س&=j]̄qĄx]a %QTvZSӶ-yR7[ap"ioՄG` k{QP7rlC6Yv쳋S-~ V8T1.1LB*-,d/l>Yg3ͧmkDPf&펦!VYYYLB10/<| Y[Sce7Hـ2oAJfZrXhc)x#\>=qdlN,PN sF}B3 NlgxY\M.]~[DmXHQr$JB[>4bϣuS9sb@ܙS; STf)S~B¬tKE q X4! ,5 pU HyC\V̳ϖP=4Va?f ]#LYx|Ж?z|_?n^ r,[E[r33k qec,ZDئ2+@cϟ;1*)1\%:&Җ`l>^T!rO=+;BV 0iee"Vl&ț$UZIh.;VT\ ^XU0,욵~On!*/N%6,r1W.ʳm(Mr^ڮh LB^}E}hH6ؼP̦E"3+6T3lR7jQBxdL]wV AydGaIrLoɞ璵 kc$zۅ`%ȠTbn l?LCg{0~sP$L7䛎SYӽhN(N撡eb?+2f3FEڎtiD޾Aa, ,NwW<})\bE٫{Ԑsr uV>C6kIʋ5huVυM6ěf뺩[b$'Vh2I$AW؎eϷAZ&t,"j 2GZAh{;UC˖E94Eoӂ)4цߕw"󜤳C;es$$Ƿ{ߒ׳"xI=l8paN3Lf6R BH<":QʅH>j4(qh`רL"!e5ſZv~e`⟔ƹ q ^Em%2S@(Ф7X!~(RgIȉj󊿡bm2nvM¤׾|SR",,aBo5b{2ZjiGyB AGx!rxR?1"η:{#Z[Mmkod%FT|Taɧ!Aؗ,_Q02ЋD4ª }Tk XAXN$=JeacS̚eeȅt4܍wmBb'LI5JTh-H6ag NwRN쥭fZ kc9V+CebcOvߙ#̤>dW_D́DTVZN! pd*E K&o%AQFBꞑ^8o azY`-<װk-Sܨ4I1H]+s֋&!B73J' mհUZ9u?LLt/r Jy\]C-w"oҠU3(6~/SbkE v\6~cM*w Y9;~'֦ϐj'懻7 K+dY1H5p>Ep&Sד"DWo$`#H7jr|SABcS[%Qc(ƞF)! ={\4S3pxGhMɩg+++w#i8xJ 2ko"b7L+R(M&a2zYّt;@a[EADw6!a]:uvcRgYcT=wןjE W Pyer7=EL:z`"y#Aj'Y0Lp9//SخMa/p;LiQb@;/w+қA'l>Y* o [pnfMH uM0ϩz cɎY**\W!g Y\E\ 5ߪ;7M6(y[CI(ݮW1v:9jslX,"_BB~>Y?J Vwie%m͞clP]r}UU E6"C~MmzVw&\N!ǗRF>#9V "r_+5MLI"F;Ⱦ܄ngn+<VZuri4K5bhSUXa:]ЧlD%x<҇\_~A9D;:e _ a{ZW"3Lah8ɮ,$c*7q_X j D6%cd\-kmF)Q]Aa8ݿrI|2#C@4$@=eN0mڑ4y8—nkI0m+B|n"^z :Zqq8uDmSwPF&t:J{^Ƨ$QpZlq~ྀ#2 I?9xeZӓvJMx;u@8 (-~O5wSZZDŽ|ggH!/o8zR(>0svbk1,W|EpOpת])kЖ_S2#?eC>'Uh#2<_7I[ ?; EL(LDoӝBEWZv]O~8d)=2vP*tH.bVp]%qE-ޘ1Ţqד~vu/.iy=e+xOmZ^ޔYEcw^^.v*F!7k /JgHzK"ًqMJ[ZiGyz0zAߘ73`aqu=7w82f!0w /J%jZ!`9Q8[R,e=O]yO2'~SH3?#h]sQKHzcCwRabG y]F+~{Α'jao5zt("˪NKQy~KvQ%)<9}CU 8ny'Ey ,: ՞q!S.c_1mIײ'v#a}PKpT`%E(jD`ya޻$|ES( xE;!J~{budxQ\iF5'G$+vX8lQ™=Ĕ'GKUl86!iq!+h}NLqbt8d24,AQ !{T“\`A S qYUJ~ww&VߖYL҇?; !f/UmA%­m# 9ͳWO RA.}jWU`z!1+8 1c48Ʌl!c boRxcc2S2Ԁm֢++ꦷU +5(JUv;BݸKҒjL5M'Pa 3>t ?>oM2k [?T-r@;fԆ~z0&g@fz-qSJ]xhiJ~Ky*+qQdZ1{}Nwy#%%P/Lw;GEFF0łӐP^1{IA{?i _5<^fYGm 8KR>^Ko1CZB6 9K$-{6"'}}8 e.Ǔ|,p4a\* k1]͸~Bc!3+m-qI'! }8{v#IP^mI fz\sl$k싆j3,N"DMЊs)-|z50YwfMQ&Pm1tyЈ;%FX*k9~ |\;3d]RJl։}bcFc/g_l~.x0S0fn'-ë$r;r)WU+llʥ~Wb$܊^ˁzj3?[T#i;U2eY'ZLԣ ,_GۧpD u`l'7S,mjjArJDNX%rÂqvh= |@R(IKXt" QJHj%WI -U. ~,kZ1Xn!'-54h!4}f aW:~)qppD_¾"niN`ay__KD]C-{LL=A2Et*2XtHvL ' y29@? āz WgC:Q]R/{f9LR )x Ɇ$P|Ŵ|xJ M)u SqZ`f:/ij)G cOtr>Ɇ1Z&Nwf<&ygp#W˧*i3Vi#NPStsVv72(7;pAݝ[4Z"`!Mjsi1 ^B1 nQUu``J Ar5Ww/ @8[7a7`%ڇ@*9Zu> {/e&`_p+뿂]Ĭ3U,(5w_;]<3muwb6Dݐ5 5G,4JF3f7O' Q}(?SI͵b骱ijI%0'7|x%99F< G8ag$AZ`k⹀)1՟RW֬yj魹).\t3t` +\}ϛy9LĕLjI7+\VA`31E($}r.sc*BJP|?ZYvj%%8KһAl؋Ntr{~^RVH#OJ],ԾUVV\qZ4[Sm;e[55D(iZ@ut$Si)eK<RUUȱq8VN ɲc$>wXF~t30ك5̓4G=P8k;3u^?Iኡ3MPV:*xIxxЄOb[4S;.2Ճذejff\ZM#^Դ*9ε+HwAXT*݇6x\G쒒WYkR}/n1mԢzHt@ӥ=ڭVBԵ[%EyS\ˬҥ 22EY&=h­i/.۸_h]qTCXqg U(K2D sv90: c8_.p!iYvF_ί+vVIS vN1wg>kǟ$ruaiD͈tֱwmrSm]V;y=!.&;V ,fȏ Gq߬N{4 oz-J?\"f< 5rx52\A>SԨ嫳W$+~)(ƕq)X .AukXj{h#y[MAR-#w:c-n'9462-ILfDŽ%Q܏ ?ק?|5~8k@,>=y 8΅W|2{u TsX^~J e4i<¬îˇ􀢉}=jwh=qDBŤqu8ԁj 6FN(54B.,#VU5qn`OJuE3RcQj+KHEz?+oZ67*r8 LaQg\j!ǦJfH8~_Z;M C54/NbqxҕuOm|dZ m(1cR+TlOCIi"_ߣo~H\9" ?defӳ W/Up ?{>ׄ#JmW koV[f 2{-]lǾŸʓ~2R½{3(#{+wN+>\1ssqUNj{}3LF]wiJ~yw֟cȀ#d .Gae\g ~gDq M?>87e[=/!VGYAp֔IN5I+M2sAW}/yͲixpr~yv|fүڪߡfi3rBUMQWD#" |CƬI}Œhz[V腤gaEj#Ce܄>M{e>ƥ]P}~C \(y`y&YU 6+\S1%߯"\9Hprw?-+8f̓F.FZ2~Q.9.n|z1lСm3B| 7Kߝ-'˰X ܣ *)B{ Uhލl@[AWN:'彰0 t7r|cb>> Xۺ];Z6 ‹& ]M~ubMܺw綼ttxzUFJ^j -EX By1+Vr4LZ.ގFxKzS,w[qJSy/Rd=}-pL :HWfk#!=$RkLI)Du.튻fr/'@kSNÊ,ٞVTE^Y:L`mA 71/s`1UGLy<6hcV"it0\f7?[m|[Iw*Α;:*ȧsǜEx[+C)U `/nE譢o5Y0.z j3IQLKFd)+DriA}}%˳kzH>bҏ6h\V)^ÕTi,%4Mb)|S[-[@+ɑíog6yp(RdS;;[ȁzZ/&L1xdߎ`6~:-|<2W@~&g5=CxmDuݥkqVba/Q^XP)pZ ^cп5J&hVЕX֠(#?u9Fzl<|ouZL{R]~is?9шqu7sM\hN?(v\|[xFyd'(JPS"źL, i3?>%0W^@ gՅGwNQo^o apzZm_mv9<ZV,kC3A<<{|(AQ_?-Uˢ5`pmEߌ\2Ul $CGb΃Ξ[kׁyODעG`G =2h3sSj 4wʮ+&44Y-p vI\ʁyIy2)# uP۷nay$AުeڰOg'1S[;Yޏx((bzLTefR*G dqΤ>긵\g,r_MaO*~6M=t8 )Lp]lVe!DD=h a1pX¶#| Þ#6BCv2k9Jޑ31 27N>R U1wDbf7vb#MlԲRe7)ǫ)RE! #F:ی%GvL`"~ [ߢ2>ڍT%3FNle#4}&39zbSƜXC@;^Ԯz:)kP_kVIQ1ʼn𬛤Wl(ȃCk;*D=,ᶾ=a8Ae_pIѰ,!RaJ{$&7l1Ј(H%[1gWx"0_YHq-EĤezqWkȌjYX̸"uJc9U}Hd˔ =LgK^@ ԛ&Mber#fa*ҋN #+# 0y`>^0,G zk(q1ϧCmЖL:ZΪrÔtuYLY (MKUmC2vM}}H+{Hb1_Z'݆.e,'n| ٴGN!ЁV{,2T7qRO3`&Nz҇YK _C_L1y&w._K^ /&q'y)I;]XK!\S*hKRݨtH^`r5Yٲq.$>GEHmu9-;IY2>7]LC23,ܝ&XRvaf`f)?Cʶi4aԭXTfN/!/L>##ạU Ntө6DrR )Et )tLY((Lɮ~)ĊsUk>Ӱ5'HO׌fKm2ฆ.!,H!U "lv!Żz`6 KfcGSε DUc V LPژ-]rdp&@Hj8U V{$t#\XGDҶ/UY=ň(n׺hj_L2 om7k%OJ(t.;bfYn4lnS\c/ | u_y !'7Gϊ-KZ8TN䄭ϓŏ-D֭v˼sz"`HlPӡ )Y]Ң9FqKE7O*D2yXmeZ)+U9pO=j ;f/T:rWfzdu׀ꈳ zf35a^XQIt+jjH+>Az uA\)᪖Gs'j(UPӋPG;̡K!;.ٯT Վqcn(3^-OiPWOm 8O]s."٨q ƶ$ &A} rU܂] %iL "1 \>F6"Eq2#ilq%fRt@+ʯ'WKHvڸX]? J7RJar bm+_Q[QC~ۀ'PyϼH zÆ˙D#"r m}"C䥈R@Z8:Q9twA9* MF _v7M(L*p>uR$#ckg t_jRu4|3-k>uPvgckVH 8EK %A-Usv#+ͻ7uChqVj7PҠc[EY|DNs|Djy!%<5/|^ " _6,n ]')hοkC\,2_uĩaH*YtT `H|gm[$$Ik,=Z #Զ xų'_{5wE08PE[\K;lί2߷̅?g9tJʢ4mJGS#5 E*Nآ"Eg{ &8?H[#[9RT-Մ=t pMP>xf%1gڊ!̎-<:Š# &@C-@ݲ>ZN*į?)gfc?Q:U{70 ?OQSA(z4Bhdq'Qe&0QqFjeКڥV{H|lV*ʉqG44^NhYuLCW?W/c|-#AI8E4?tm|Cm"#񡵯@jP/:_a%)Tn|l'& MB]>)iu o]NjkV45Kq8 .eyvc)&>uHD8Ci>;1~8 z]KP,cvIŤ]v ~]H@РF#* tFVwɟmӔTx]n?ň E3N,s֖]JYҰN}Ixފ f%@x?ͮ.^S29_k֞E):_7+u`oiENw["XBk+h&1cOG!ٙ5Qus5 EFvl>L J]Pn$7 u~c#Y3 0@CV̹pHa 3Z]PZz=md`6#>ZQ>G3Q˂$ybxhz|)įf|p@J]5Kz%Ǩl3Ej^/@H5_rLd4/K;y+C - Ft##7pAHwt,#W%K';IV_]nN2]-'aOх9.F__%`Wyj3\NA|.0/ rpbM䀂hh-Iu g{%6k!@?em&#+fd#%l]yjl)(iXY/Cv/ᎹMF0-0`/Gn3)0=*,Xd$px%(uh P6_Ezqg ,%X誅P(27 Xp*8cI `]YV14ocXkה8|Ioy7ߞAWL\ٹޝwpU4m9 g;3'q(4;&UHl:w+ha h2h[n"MUZ OWez!MD;|9K{%g$[Xl˜{̹ҿlt NjZ[C 譻DHy$/Ƞ"fD#el~b5KvrscTDzQ΋%jP\S4(=%bY0GΪ|Xdoz>. ;$B`2nP^u Vg5֌{&'KܠMe(XxQ4Oxa# N1KM4ydʏO?R'NWagq\)3~V-4pKƦi8n$2s{0?q7 =qxځ-`qt7(u؇ nm]5uT鿽[*=?>^ r)" VN6* @ҳŸtt--}'K[fË.PsV544䒝x,F"U0j2mOe݀A) {#tl¾ ~٢8)&"s7(w2'Z#YHL9k//,8Q2v6EjI./:ڂ@+j|N E:kX5DD\u])@z >J?ENUM@AzOi̮"9~Ɍ,#KuU 82S1D>/aHaoD[+&ST B f:>ymPi ^#35(d G2z!KfΒC{. /OvYMͷ {}E3!3QJK!WPZ 80<[A0y[OU ~S Qz]d2+ ҬK-9oPokrW(,eѲAhRq6ODK)#Co<\YzM%-qr$Ui CN9Q]p2t*t\J儵bIU $ƵBvrImpvC77c!o(薞@ #ddYbĞѩ*;ˎ-DPSfrulENK|f$tlWL|E xϩI,g0 >V+A2}u-H[9h}k̀pERq]gẑ+G,)f\$c իeyR^RF0)B`hydKYx5N~|k~ޣǖD*ZQnڶ^2*$ʑ@9!ϔ=FF 9J Gu#~q6uک&,euϱI?ܩt+ kB6|G5nEd4Os ̾\=Yyjسu~⌰أ/6P 4Dw~ķBP]qcX D vVK%¼61ź}sIX/?@^>DvCjOِ`!NR~fQ1UPi@@^CI<ވBE<ٍj_fM(ز . ^bm &5t)efA0|Xf4 +]z^6UE^y68{ssiE Pq uucax悵D2E5Z\sO0G| V`ޣN̛hU!|l/B3 ETJQ$ֳCs/]o7LG痈pz9G;˹fPD}v))>2_`-!]ebQ+Gtx0{-q<-qۇJaWiy452K? \3`9c̩W2?n_^I!fPT4O%mzo2)6ovt".C#qe^;.-zkX<$-#[@W@eMK[X$g_U mIҐyvaB _yA98vdH\J JH'3YL|ǾR ֟|ܸ]F1~Z>K^voA$?,{)Orn˯-׼z xCѳ.R}TFPy./"6Ko`YD7٦FB^xұƗ@A'SPr u>tb/T"0$}zd{$+VQefл9.%5F,YGe·5xJlh3?qZ6k 5㥱wλ) YOQ(?qдnI~YY3JQ ~0r%2}^rٍLRNL޴%hrLhO lvir=eN7?0-vGnCD拉H3*Y"xߔ_ə|`AM7:`Sm bm &rF[r wXEڔqY}| 詹X^%S*|Ѫ({\a@ )I=})m[H)y#ω'ܗxHBsx_88Y.Jʵ_Y3or[iPպY郀X.0?%2}YA-o?yZ>Q[aq~of4k4ۑ00V'c6p|F2MYw&o4_r[^' o7l@OL zPܺ۫ъ #.h(` /h>mˎY#ܿc!8 ۈ)m! ±5 RT |{jwRh[HƔ,DW(MuNEcXAm SRw06qEGv0'ھD ɤO oYlEKG+X `ɂnw~QGc>ŧ2CIg jLIAqr12\/xQvqV}j`) p)NZOVTFk'^E ԁ.f`]V@|W+͉,O.%?6yXED*)4=yuT~vK EHOq"1["|In"ՠw[~DTxA3LbknnRYSD'^_zqwpD"OV|Lg"# 1Rƙ 3!aMw,u+>.3䁴1(ZMl$X]m]ϿO;-&psy?6{2’p7aDB k ս]W5%<&,{]+2o+sFx?Old$hh 0op+?RrA2 *0=x'Y*9m=+.7hCH<}wR !Dm <Åy#<*5m.{IH3[/<<)S2f<:UP0aCԵѢܧ0$MI$3e`<6B?8#82U,hi#]a (UgSe{hvI7aX4j~ϷUUE4#\LGEH볃wC|!O}y57m}k4)+ԂFVd\s.:O:6i06b;;Mms755ŧzg4 'mPp 3e犞S4W07[p$Q ] m*C߮2\Ʊ.*~\ ,zys$JO60F~=0wJF6Js1E.Mzrk(d-3(#4Ni᪉ֽKXIa T - %=4A+*srSR P_Аv- BݸqSfakum[5+#@]8TN4_$I&T]"pb `UxV}vz(OS,!tg*۟50>g[zngr݊^ Z]bli,{aUFQg*U;k_/ì|KQobRV{u8- n{-aMN$;Z|g EzH"X T~ߒ` [/cؽliyV=x[q$FLƺm~x;!LsTcduK(Z nG$c-+Kpљ8Z**RZj:հ"=} Tl"&<wsB` UŧVyghK#,y/m*TUʥ] |ec牓06[ IN2(zuJwL!䉗'x&*K` ~J긠xeft1:d;[ڶxxq^de.ĿsyB"DM%6΃UxެSipY0v;Zc{k`{8c蠕'Qrb^+WOQo/lc1ιjĬNgY6q ^N*NúY>v_~8`Y#0G$lPf%~l4S:C#ؽC(4"`G~L=s=!bTIcs +LDßCL g2rSn_3ȃ ]CsNS;."~ϻV9|&=쵡~:b3Me빴x鷗]ˁMTϟB[cGC&ts9(< o%Y[97fUi1)Fn ]hv/ߩ(pF;D*nZϨ7&QH\5<g3@ ::PY񅧱5R%t.7XږИ e} ,`~*ǣ6%!sOQBF8jnOh[qv8I~z#hxfOk3T=!ԥl5{엋5` ϓ|XqCqs{Ry.Z1iaRN1K*s@  wP(ű q.1[(Zb(ɬ"ng0"r3Ͻh_<ҐrIL)i'Sos&H9C pYN=|B3NQ98-A׿ dAlj^Ņ4fޡyLh}8QEr-#趘d!,7Q<7ImJt66GYiV!l{5{uk~]TV 0[$叢Gщך.`evof!L/s).?8WpEƊbHG.tWzƘ ҂(&IKH/p۝J"OE;ecTD~1"_)bKAaVQu?s ^%+iѣlwB,ytincYvr%ϭ#Yr2yqٛg?)QN[BKEAq9y.ʏ2 mmG%2&/ޙsw:ŴaI*[?ɟ0H>=>ٯ rOC"#e?M M2/KeȬS 7~aBE 8?'~L 5X z pUdعsrA!2g6ӘoJ+\K f|.lI,}Zi[s_acdȣ\V @w&q3L26`O;Zq)ݽ>u`=אGIF C##w_udD>Zj"w&W&-aY՗c*y؆W'u0))"|G`s\mM1|ڀ֜;' FLW 7Eh(k"Eoε [۾>@1% ņ?z%-㓲!:or *&i') g 65gwZ,.}FslF ,T"MhJFOVC V0{[G^ rG!aaT8'T6A{S!' OCMgS~ d&J{͋TKBCbRa|?^ LjvSCp845{@dJ.]ȔRdǯĻڜb> .!,g왜OI|ZJu E2ΟKA?Dݙ%jJe5[yp6tje G]M9.MڐTN[ܼpg[ mˆ1Λk~+܎k+*@͒WrÞIR1=`>1}Ef@b׿p"Znl fͮA<h_^xCS֣)\@PSa-o D~A&#;uO\/,J\pcBV&b)*Qpf CЛvHI½A+=RPкgW/V@" wdǦjlzCs|a8Bn!= MzRE' ۶6,)eYp##2оźiEcsl@aM X.q t@(ˇF^by[ 낲H=pް˟Mwpp#7QLw&Q?as(q],9Q۽0`񂩙:1$2&Q+!Z@[ %c)zt$f^vA@F!˛VICV (:"dVo^@0r!/cFk'xcQ5&7%`4?$Q_"jKu4聾⻡ZbŻ4WY.eGnbge37=Hx}(r/3諷lD7{&$>jЖSa|t/t1׭0\>W:_^nM?9'6ye1S㡹Ȇ':b*HF \Okw9ehCfXeauDJ33 s1L%Ȃ . ^M~+N4|z2udI^ )LMCԩ'LX Z3s}BjV=>'7Vgm&nv7^ݏ!`Xhq~QFjKrsỗ:? 5U3WCy*s J#3ڄ s\>17u9%Cms \mLaz7kW\ zҳ:`;~. {cK`qv~VMl"_@b,oC9L?Sk$$($hr[ < =a|l.w sg+ y~)x@-WdDP.".̆u+ɇF>'bahK TF[_% :v*J Bn> L`g]-=/ę5tdyw9:~Q"x8ٟI:o>ǞY'!mӥܘhJ}Ϧ"4{.cTE.^" zcܩ%I .6dA҈ g岗bEa(!0oZ *zQI57sVʰ qM& Ҝ ?ߔ@QWJ$(XB2Lůn/5o! 4~ eHC7bk3g~>ܹ= Ϩ'׵eQ ,f'd{F9(ͯOA#e:7hnbaQ=aFG#%/f4EZkqMզjԎ݀@%@;ױSAlrLqjaHȇGc˄3V}<ڣ9qlqݢNs珕K^Nlr~ y79O9-)9e'A[0X*;MAJX Pg2Ho f!%B?#e-EPƱB?;y&>_z oK H0M]9UcF4o&Z w.W d_їbRLe͞ 8yIV4ff$p,=`y:SHXMG7.~.+B3]}mű?>mcBĀ ֞3+Șw|IǒpՁv]P4X2+a s+?xO\uyO yf#+;"lc71QwQp?&YhlaE G2D/33'"ɵdVZOߺܵΰ dĤ\KKGa;o'9I}d h&#ixGBYmr&h<1y#:pPmq-Ax.Nqr@`ܽ%FX1p^烤L4NdpBS3f >HU<{#eȮu-`3\ɭ) |CJ^^>Rf=hcTPfKsx8)̨^ I DpaKк?ki$ se̠iti? xHT5H;JԳO(KwSӾh,oBS-f ^VV$ _ET?ǛL|%bo#jژV*8 ׎#nYD?G= ߒLf"|ܾ@uAxk3Z:Yq@o]JtB[̋m (5-clq._)\SX 1ĭ}V_-Od uf?~`}M&aݪ\~u?\F Q|!͘$?4DÊQ<4lOdN)ɚ̍,4r/8ᾍɸL117vx5~ąFsMKߢ8[rWgV<'` "5ErKĐ([ܣ" UyaQkćC7Y$`' 3 T&"S)Qtd.H^ RoW$ndm:sI7?wB;VzotL;[^%R5e"s@(o,q0JKʵ5!/+5]{m :4FZ:2|K ELiIN#6<ٌΪz+u7pECU19yn?_(Sq}sTBy SJ>s^4W_E>hOE Kg_Ȓw ť;>E,4$eÙ,$g*՘*;mJzq{k%'^meHw8} Rh-p6UV=@%S!48nEC8Z2ʺNUy'͑Kȫ)2L_4 qOƆj/t+]*Hꤘ7*U8кf|4vSѲgDed%f(w E@FO/A`VŖ-EL 5yyJӡ:_ Y#D>-k~ "T1O ,VP0EM8 ;p_Zn9̮ύi l̏qȏ;(I]^ *L2hAM. P7\xBX\պFk"@ܦn1݂uP4E}|% u Д Yr'Fm 9)0o՘$p`Ac}[8qT?>} OhL auN@܁R_Kve H6&jq8x=L½K?@GR xWaVQ:ry-9`Xh<>&sGz%gC:z! ;^C$aRsɦ^ȖT[V|3a̚W%nL+=){3#㒻R9D(1/oSU /U%w!&LQ.4'D;q!yM4  Ŵ6hsaj+MA>r4@OnF $m紡]|pId$<}fF8CJU0^Rͩ1EDC.]OaQOR>pmxeci0obf`Sq*Qn 27Di0a bFw-xm`=4?Yj!EfBykY4seKtv5PS,*bzڤU%i8omDV_kh齯.YI] 9icmit: 瀭"eBަUYBP]Q3,S:43ߏNxgTf"d~PZ7i2yH'R: DSKSCۂQC;̮-9e5wdm8ZQ4g#ɝX05_.f⫢+LNrjh!ר.i|re9z`^3M{ 3Lq, . P)+Qp=D3AdҎf5gu- UO#`qy/NaÌ6=bޖ 6Ө5" gMIl3ǘd<U3U ٻ"À\g&7cP4l?l4y~@X?9Hd65J L-X'dIZ_B|ڡom$7y aE6 Op27Lk^evjAi[ ^<0Tɒtf' MRCwh4@0/Ro9.9NZ3V< S#da =RKAAi gT6 3g< Vf6_@750uC4 \^)X# Hd7Go|Dn}-DWxx )]8[Bp,UGX3ƛ?v;ᤗ-j͂5wMIpXe5_+Y6 5ˇMqDgM?$\Eť-68f{OL_ב]4f1 |ͦ1+kD*f}⚙^Tt "7&Fk%ίwDI!*#H TS{`l3~x nOP販)SK(6bs?qMgqY}ert7gPQj*WEf$Sr2px l0q+/Ÿ= eCG$4f&, jm&tàX*P%;*/~&QqBb!R!H \s.-~9K6Ǵ`CCnꊠ0T5"/2G;ѭNOv͢o~]7nlQK<ܭf nExV4k-Y(Bv%So3g+|h21}Hx 1=9\S[ McxhFI}{K/ո)_)':L\7[ 1Ny d ϥq'GXU1{s;![Tc7n IC&س-oE吏r"ӂpaһMүjEC?{OQsu .0WȽ}:D-j.Ny9#%pl^G5YX \fJ#7F[>V|?XWeU#!܍E.]uY}„rDW{ew%oX}ڪ|;IR>z5w5$;+4r 28b:~MXU^nz p{p'`5rzoMW 1~.8H]_B`1;7-3wi Ɛ $Q Hhڑ84+$ vPU}5G%l r ,.ݙM3up- T@|q ~-E˻$"p])ƴٜh=8Dlb*bI!,։x+N=[p }aN%80z`̲H2O0㦯KyK}-B,L8Lb0V[t )Iͨ;]9 15 J /)Cf~' 0B-Ps\L)jdVDLcUFdt2DZXKTh!nvk hŧZ8*+vZl&㬤ʦǁ?rFgS JWH Z_*=<صQӡC +WXZ 8jsrԶ],j6 Tu)]C&q_}^U:a2*hO<By;Oaѓs~q-K̼TzUAr+j$:>0hЋԪ *{O0 }qdfhI,D]*`)[|vZY1ss$'U֑XAJcܺ }ƢJm @Hƛ "k*W,jL)6˘Ґrls'P  s*F8.Hb*/RL\)g:8 6Mߧ/E.iOd%)ؙQe#OR^[ +[g4]e樠^<>JA)5@8\R`3ۍ(J#O$mG+27|a"i$>qhS he y'W S} !"M՜*^r:ծ IQpG>ͩϬ̛AIIRxkz@>^ZႚRp-+ 0: "gaZz ^W i ۟8%w1a`M̎j$rݳ:d+yi'1H/~=r͙b&5_.DcO"!C䳼- 70SRcy!1q4BETrW3M@UIn0A}RnCϡ2JL#(U 'дaI(A&`,8BdFhNQgh|k"W#`{:u jwY#7 ~lXN@ `:8l9b}FeZBxFi{'3xC:]:Fp1tn HM^VXLi&"G> 2zCY+^u5~rstA쾷~YrQ*VnH;nqfw kXhbE{KfܤCȾ g1#jF:Ө2Hܬ(Я`$k>c}yUQPEU"ȲTN0cjwrT7U_{nKZ{d_BKȤWd=5Ffݤs}0鮜ctsG K_!|d)/Y.ḪzK=R9h8Ju3GĿfҊ @VohVNũKd$Ao!i1=L?@wJtˏ F|sg+cIM闉èJ 8%?ϟȢ8lvV /4;A6B%>&V\yY:et/  iWj@KCKͼB@&ʜ4߹N~1.T+wʼkz=Tj_[1?X7oEL@8S=&WAcNDUOM8?Jg+#v%qF1[d,G48_D-p;=IMGH(b +]pf|lǿcԓtu}Q-BwydЂ,vOՋs X{i+5‡ŀc\.6C^l;fMRG|hl:XŚʵAp??S:͆dHr׉w4OEoŪؖ$8:'O >U\ )[L.# <ܢŮrs$f@ϳ>r; T&ťn\b@צp'MMEh{q]ap]wSxD>6j˳vVSȍMpOҩmn!$V `Y6>Zfk l/M]_=-"@} 5MF##nh6Cb.es%'~5BJ[ahWKꯉ}D(0`駈Y"gsCtr}I)a&hبrh(?fF%A)>KBkɽKu{=`lǮJ1-ATɿi xެůZD"$~ Ne.av;Qwo௰41&o3K]%LaŦ>׬),l+#<'j#BfOh=_0_`=>IB"͓fv\4:֪,˸R.Ԧ2]^aEn#@CT2W6o)$T}}sߕ}PmHя=EzډY\ jJnj405c ^[,S! r ==omKʂ$.HrKVx$pPݣx'\bHz|Eu.!d?'lgpupf'ExG84R.ŸlSg2Mvpc DCaR~}giYQ>Sw!0L=]ڸȪTtI3;Cɟ`9r\ @Em$ QNS.52zC "|J0^ٌSxy7%"EE/9/VYHn z`bs%lwOf^)^$*%"`b} B@`G НKgY.);c3La )P E H9:o8g}%SH^Q5$~}L4LX#",dXZ/g.M~l33t׬7dܡ׆Nq$~"<ޑ$}#0#[8<о4 x_`BC / e23xtFw RK\n& '{̵]fZ71` Pp 1s5Ş2I4Q!0*omƳx+YY_,!aځ.ʀmF …˘2}3B`)uBCM-D> FxS8]uS弁 GPR>0U)$OMX.kd"  K{V( 5A Pc]lR `[CN 9duMD?N$lO%Y[:qf/x|05n"g1_ W h\X\Soc+u%%aWjo#:=眱LS=G4$M U2 (ߥ2%eYi!ؕ=JZ;G59"WZ#TFс}'z(ITh2UB\E.ߓn9i{/~vewd  i9a*DN0#T!a]ɩtlGi¨Qx^mZJhc$/G$ vwS1pAN-%nX)7Gó(w9\H@E-W,J'9aMj\ jgˬjʡ'2Ɉ5E.zQ_ ;o{{ ro$>*P2~xyP{r͒{ Li 49 +sL-ɘ>#xʝMh.dc/]}' q~]Wb1nu=6"zkiRK-+"gv].0-ǭN(D۬qǯgGhؘGT^{ʡ?GrC]3<3ܷ=cNw!՛6T8AzJدմm f0t>Erthtw^ l \Ϸn _F |2T([֜Ta8y{R<"cN}gNܾ'UE6;&gcE:7r/{fƫóhj5 e Y8[bQeYK劕A'f0C*>o܏&Kޔ,Nk ~t}'蘩 uH!l.͌˫L^7romxn]>sSh;[icNf5 sYޛo%Scvtm{;YkU5Th~Ԗ:Y} E+gvW_vWv* k3/|nSV3yƒ}UGg.p4Y*8J[ꭄ~ M|DN!Ts6ҥ3!9&H'%na_e`oD0GaJ_@N] 6a1$MF̑;P*? 7vW%okV| *ê; ~J|#mjuw(k}FϦnw]Hpg;"$VS qw4i3.s뼢E(\eCfJEe?Ft\ f:%EƼroB_ aDxl}sԤ-n 8±[R[fTuE}`6pl݈׼G"Q[Xʯ%RP{IqMr~FH)wbj=P +(HSe,_Cx+g?O6[X%'N=-Hc*T:6hrH/.$AD{x)X%S[#a8MvmWMΰ"nN ؾN Qy̭l2zX MhǺT}YM0љ&Kw{(sa4B>}\֖EYa$>E?M9S(JF 45~V"CBSoL#V `(?:lpn6I8 (ʭB#iI?-棴3vM_in)ӜTFWhZ.V` "*LQ69eZL+^|`e Ec/3ub_YG# =ga},DG{v5y@z4S$@$-zY''0 eTt5q } ]Nqm{b(wE*S]vhv0h\Nf^Ӛj`f,ܡ@oZ8*?|e "\4wO(rl Ok*K҄rZjhRp^9 G,D/$}_XJzy-r!VA W3)H[* ?9Rft}rt/1}ε@n@&pb] (\DDBf̀\aD6] Dꭔ9(*gPY(uBv`9ft{s毁l@fq8(x@UbxtvASn%̮exkވmB@AR8t-!i#Zi&S2X=A;#aiS\4 VT׵sE%,g!η<5x޶L3FH‚S˔,k +^ËE'1Z/|ut?%w* uy+O]5(Oٯg0ʨE\|?ycV擝{!cQIG>bDz,]ZPo ɎiQo;/U5KjЋ#xx aŪql# A^8q2HW Kc$hXϊߟ D@KO8~@NW12tBV22qs HM&g OmUr#oS߲$m{ mнWۑ}ـouRnR1I(E/sY1E CIsM'F`D) ~#$J848:hT*&p2\S F1PKf"9 kb ̠tUs1`#? C1aKIϽ-JR}cXPn+t^ՕJw˃k5JAf/ 埭NQ/2;8ű5I~qX~S˥8I,=2pѺfwjX-$r| u&5 `GtP )ʾnW8hLA؊% nCU.245$&_ $[Ͻ鯂eBo"v!7;b)\`ՆH{`!iϽ'2k9"2HjT6ŐRIMPk*AOetu L/pܯc,S_7i/#TU)BM߻$5]!sӗl Bi[l;jꙅ5 :y.zSpbfv}xL^w 7,h XO|6A~@T46W*r[^ev%^KCBƒc:0ɰe b<3Aj-e';px6> _XmMd.9ڸAhBrk^TĀ/A"?PW}։.):4Bd}ӎws!Ew Y3e(j'Dj-RM-=hEN;J8#뭡JD; :(. BMbRr \@xX :%X xy'[ ' <̌$D\=Z4°7&,u /ZrZYTqC2)k4le | ɼ4x#ze09i Քe. IhaB1OkۥWnFE|;W&H&ĩWJ#A"taM['gn` WwjߊԈJzY@pHi {6N0T-P>@ri>!-?iە!E0,/'p9TWaoldǸ?bFgG﹄*/FSYIk߮yltV$~l8iy!Uie- dHIP%%Pb-\a( ߎЯh~E[ti?hr! śƸ 6q<@V\U/rJ#;u?`9KǢz)8#y ՈkHFs V@ipe𙓙}#Tg>ϝ`5\=b#'nq^8A1"webHw6P9xM/z,4%iEЃ#}_C^q'WdyoOY qi>(:_@q Gy"DV_ WK4ilOumxw{Euy٠l!TAFIf ȓm1=])Dyoflh 62:tޭj[#&J@<|[HȎouf3[1&v.N0nOUHh s#/KTE hmX[ Pbx5XEN}o)Vq0X'9Wc'Ns&Dw&>'=V,O`;U:tZZ X?#Jn A,Q1Mj)jڂn ³] =_4X? eE5"f?gA?/c&Mv(fm- k40v~:R~&qG PP+kZ 4ؠ#RvXIl'ВO%wZw ><:дqل'*(T#{*?h{:_wZ/P2uДgmtVE55Y-m$Z:|(S'p{P4\ŸJp(yLˀHئf`ca$.P0*'E޲x8 o%x8J`Oᒚ \Ukh >ܠPٸDML.BSN>&5( edb,V}?}*q@26RH 9a\sogbmOi$yb2lB}"*IRowN5J3ۜU`-WKJM,EYvLaf04Cշ FW1&Ppʽ7W0(?noi1fߍYOim8U"SROItf4mD@fpkYs--ПNwb9!4}h@ItrҬ< k<ъ~8#%lv`&3b3|45-DjW|G5jk%[&:Pε)0:yzۉm;`:}'+F\sG& R>րiW>e[Υ'ֲ΃*b]ɟP1&"<t'-17U@nD*_@:Ӓt˻)0U㏛ 4]ōku ⻲Iac_KVvp4Lv5BUu p]샂gf`36G\T1Uoz4C\8tLuЋ@FfLpw g2DZDLCe I:]0QLYxr{r-r>;!iKob7BQp4OTwyF |>.&PLc<>sz ؽ3+vLDZ̙ Nk)TCXA5Aq?,z-1D AuP#*FU{T<oiUV6fDpÞ5iA gUg`](Xz3V-^&hV 9 ^]jÑ6UỳZa@O1OR{`+7Ӟ#j6nt XZ?PKU ^E*C|hC[. Hώ O3GVBII Q[ ~QX>?UIZwuLu¦y6~KtvRzP7c@7x!pcR.3ǝ8~dS%2>gL;w46qj8Yic2\}ʣ)ը"1W"ҜFOuBVM'čI-6Edkd;18$E@h~ù?IǐJC?Mb hsH CL?o% Lv[5~K}*0Пg?șb,PԐymuy-ZE~,f9w=β_JVgZvkѵz=ct+6It0wzm8GBdJ DQ?,PHK&Ʋ}(FE>@e5;ÅezWv.)&s  'цB996Knծt {|WI7Vyk$YsWiqp}q;؍bWTL1],{ͺM1sCfsEz.ZDgDTl:[M<EB: Rȝ%uu!F.r0>Bk'#iWb7 d \CA <+i,}u#EH7C%ֲP`yyT7}*9}Y9尅¢&bhꃫ¦o_ܷ*$n}'^E';2(U2JT(Tf'g'-LNrHL׻ |#14VU3dә_jU0OϕGoHp9EfzK#n՘|P)_&`75}Pa02󇓺d{,L+NF*.#yΙ'd={ p g*ԇXoEd)5ɒ(i{֖Ԡr$āf\m#M];۪KWnͿzFӲbip(;B否/pSLM8.Xo4[]U\u@80 1ƫCdp0T{dH藄Z߫鿧 WimJ!jg]lAZPal_J|P{y"qi|{߃.JeʯGLF=S!yC*\x8HV@bKżZ>Ik4fI%X,퉇150W=HyRc,Z7ùY":21ܣ2 JuVZ 1sq>ѣ%[Wu!hVVf܁o͆Z40 +]n~S L56Tly2} &}ٚ?I/,+P  czZ-9ܹ18Iu fM*L*{Co/qaYe/JRem܀k7ߣvVLv>Y4Lq KDPSQsbHGlu"oKJy"ѦrOYA0`Ez #[;=BDzcqF묕yՐ7lƂ`.k4x{54^@27> ?_~E&7jydKVРQ~qddF| %wg"0]iDgB<U >p =>r}̪VRqFo&*~6ea0132bG2IJkH_3\3Eku <f.ګ&Gؾ12kr4Mq^k)쫬Z`ɁРX[˜(j-]TR^aZ {W >@f_̔\QQjC]$t!wa}UZ}u]WcjlүnC+)A(t6F2仔PrIgfHӑe9`fjfE$ϱ\s/ב]FV *U@!9y*FNHȓH3sl5ϫˍ q+XqGb:*Pr/M_?*_Z댳e#cवS k6]xHxHP36* itotvWfqTf0%gr¹aՀ q\3 S&=<>7ElLuȦSh^AvX t!ß;C,iSKLY- $\pbOMN<0no vFS)ڕbvxhd1h&G3̍Y\ZfkIXk>GFsIBJ*a]·f]WeUGX$5nq䚵mLqM\a฀M&6fdJ&#3~3ʾSl0U\l HNScjzRe$'oBF/|ky"cZb.x@NafW ( egO5/BoN=;9Dvs}Ht:?,y֥L^a Jt"hQݒs&¦1[Cz @YmjWk|E9/2cګ(Gv|ǝIxߕ㹻 nm`uZPe 55$|N{c%Km ̴Иk\x]/1=k6]&N;r79U;sAW,+ YTSReu;ljMaM;pd8S ,f2iW{##:auH *mV.]݁&xMB?ﰁy?erx`tfP 'DGT,~1.q&5E!I&,ԕ5{KZ]W͛5埦fc0 4 -G.s6/##I^WsVB4TBb«ϾՁ0v\TOW5S,;.RZ )-f:%Cpf7"byYH*i{)-1chn96`a?( om^v'M\)SdR(G`*B%N1 `Yd|NM&Yg\!:&ɧX\hT.߀)?YLҦqFpPv_. ,C: .]>7=8@Y>PBV0#R)_'#}CLs.E|^G T_[ىA#kj l ,(]hؙ0f'ZU,EK_7jYd'joL|UTEWMr"Fe۫;54 e!f8 ww7H P-9.FK81 R B#oRAЊZyefkՍ\!|NEuq,NhF a7Wm, %;|7UeґOZD.dI 5>2hSL324'ɤUډ: ˘/v3;57(M?Rw@_q #(EHVOӦm̃Bp^6wzzpd8x~4[)ij?exv:J+ab\šǁ.5üꏼ`A\G\#IFnn); 4Iup[ O(IOK4Q`>JKfLԼ `Z.CEf8qb(a++\(ŕ]jT1FUHDk+Da"(6v _²,Maqh /C\3`ExV^)o.0[N˘^gz Ƒ+)4?Bn@qZJ DmO,wyIKNϪc_fJ]PBw='u+[[ȎDB +i{P1DCz5Rֶ牸Lzq_xdTk-K[_Q$ܧuqвi.9n&fbf{P*^c؍?얶4F 2eP慘kJ2`0 -oje˩6\aKίCCR;HW?~Ԏ>DT7w`̡@{Rq[҈ ߅[Ⱦn=]p^ _X\Wf UyU xy>)b N FсIؿ>z"7ܤ[+ H;#٨s$UddӨF771O:!ްB7R3Č&:% ;#9`fc۴fJ)$LS ZI 2@jGѥM7ޠCHEM6Kz܆#l}}t0Է3GQ(?VΔ͑lYa'/z0yH:wM*'=iFKӦuF<4n4潊>) t*2V۰JJoOozeϔ-YY ; 2)X|9?Rfr )}{:6 IԵޢvzT.X zvy.h:fQm18kVsWy$1-owP23@8&ֱ}4@h iS4"sY) )1|Pxa9 q2̲x#o54?,"lIhi{٢ȜtaõJmKRrRu%?ipɊO(טܑgIq:0m_d9UՓmieA=sR6!b`Dʻ7 1RXʿ OO/$c)`<)`:/ϝmso^Dv7c,de.*MU02plH S@k}n`i%^{.x(1$:flWۄfx.Ir9@ b 8e 9|sS!xf+NDC$hKғi}20F'0joY B+7 Pg nAyJ2f-̟"jr/ԥHp@v@ R\ڄM9{܅~e $t IͿ[n8GlJgsʔqiˁ!i*VF)ߐVij!CnN3t9jIVԢ؇qն/w $^Dk*@]pQwVצ< H&L棘ц0)߃͆RELdO4VF$qǂttc5t ~8.DFFsDH)2e &,7&0Ơ.BO>붚yC)f#BT% '۵D7S[(+4l褄RX&11pv /ck޳f+VJWlu|#g0~[Ұa3r+ed=o@-19\~0{qh %Rs&i$.|R&ghO3-NOkCDw8M_9v>GoXuNE1d݁@Zrl+ b4Wv&|}e]ߒMoty̸Fæ&ZH2=66^|OiA7pE=mKþFfAФ(WѨݞ1jRvl~գY8~:N Îrod~6(h(dJ"m%T<7x"[1T_Y}f|ypA9f:m0x-C7ǀc)+Q|"9;$XE1 )l:~ WWr46e软nk5RX5iqmz5ˆt+|LہlirQGU tߧŜ{Cp(|W1J͗>I=a[P_+Ө U܅UΔ<_,m %%'sQcbPtj)6 _ҥj&ne(9NjKߝi_ˇ@zG_J H*ȲmžBԀK1"F==yKe5!~T)]ƍ&w3F: 2Mn N{O+#?-/xyɭʝ<^">FyAumTK0;l) q&n @jD^ Y_4$vwYv?4H@ҚL`X?, R6BǺ064PYØ5\%AEqF|?ّMtP_֪)>o^y6p)idHg->lFhWG;<*_4 'ƒ JP赅˞M2v!%Hˊ+_Sc0(|VVwQfxmMϗxQɥ~q_:Rk$%Ο$YpϼkJʑ;gF}^y܌fHt;ԫe.Ii{mJhh5N׶@'2J񱂔m*iiE1Rn Q}ܵpc{=ي1bTD m1=sy|(Y{ bφ&J`|4K+d(}w?*ۥ6t/_T:\fPTFMhTUXHKkb?]Ѳj]h:;[kuf y`3w^wիJÅܸv,G<ރ9l,K%uӲ.K0.2TlG-"P"yشU||;̺{$An8 :,N/+a{+'6)J؛7;E%(;h2638gmDišϜQُo99Cxe^U;)p@ؼb?tR_CbW1w[d\r~)XI3"` Ie Dpib+ϝ Jzms<ݍi,ahqd4_C7s6{n@ߕ1d#Kx *d%y[C!$]d40]\0zK9[`agY9]$x#RbEcDズ! yO,_UȒKE z2Xu*qq諵ޮF7#lƐG׉l8zILpP0-gDh1y!X޺36TS4=ؙgBc ܙ58s0neF:45"ɨ;>{3@=M@ N;_@~z9;?ahUKsa.LxP/}!HI;Ǽ3CI4X5AHYv(Vp 0ު Z MB )}~ d0Y8ĝ d-5}} *cL|H|-33JS,Âб&Dh@5=9RAVxZס6ptG¶qʒC4 ,':igެ+ 8Յ\ y2 Iqy}:0 kB!F.nm cDY  N0߽ܽdN4EVb-G)ŃmK> V99LGzxo$#.Y^Ζ94ݠKijE]5 yѷ5%'CYO(dQ=Rx.7?a+I"Z)w]B|3hJٚiO&q/},ou̪<u!maI=2G.Ӹ1qLf1D+r|f/{;vx~biyG_.4]S@7H6MAQ[2yQQ Ӳ 5D5)zj> l˶3^يaDV_L6dwd4!Ko}J5Zt-D} ѧ c@,w݄j֙3e"; Ɩ$V-H(I@ [>F`Eb:*N*ٕV*mҡEyn6V}zt1Ws__I,Y_vO$\4s? Ɋ?/% ʋl o YJ_?&֥4r1O,ݑ M>rZ, o=zU`DAUڧ%¹jŒ貚#(*UJ "Ҋ%Έ;Zj˕bA2Vfz8B'R 5^mPʅHh0v$b+'YӤh/kOkC]mU,zUVtrHES#|Ñd-+1fikŮiXJnpv$WR AEC*kRg%{Eq2b;bf;-# 3HA,z&b۵Xfo0}Dj.? ߍ~衪޾󺶶-)M}L~`'̩<;3ߢ2JW2)eah5B;Qq#/TPV끈4Bbϔ?gfSɧCv =O?_/Gƞ5v@M*y=̢ t~dA]^d[xQQR01P#$!+ʃxcG]QIr~jے7 >~@xP&ykNxY(p=6iye暖?T9d Kհ%T̸eE`LYjbJjRZ|Jx,6$ܟp6|$$iNcI77ִGGn0oµZqk({ZAF։q$AcƑIMc^cA/\#WPn FZQth ~>ș̴U]Uh./CfϹŔ (9i >\!1e 6 (w lr+#'œWC .}G0RƟ$ĨBh i"K!7TNeao<˗#Kr0VnD^)V Q^yBk X,1D YEMy8=ԙ_D5|N)FH͚>8D'ًM~/}VjY6Rۏ~%%JO+:e3ojmJyɆ* ^|O,;׊ ~༷%="A"Mpam"'-0We;ϣ.ea-BFN;1>[ǝ{SP(}O£Tc REa c9xLy!vyоؤۤJl <]dVP_@yA;QX,4WX^v_\eG\dwަ)9.2,%-@9ʹQ!/X\3P0C`iNrZ*G^kSt+C_?.M NAj2*QGokf.d$NW0iry>'X̶*L ͑XgFm 7gb/;}5 /5~؂^~\Ȋ :_0"a=.J\:BDAⱕv728AG2} {>7N}~^秀@8,qI;XB+/"5Z{$K9߹\=+z`DRU%n/tWTް% _sC-dmȺtY ĉ;BZǣsV8ubr1$]_T(8[ͷ:Gnѡ;w7Wi2t[=aOۙ3̚"kc4]{>2Q=D//9[\6N~Od4~f|Mܑl? ]1FfvQVO憯+V{-uu瘟́V1wnj>i7`فl $C 'XƩM :B:Qp?7lGui(!}ƓÖy8L62ki2ulB3u7f/n !z$3Jǂ:*Iɚzef]L+wB*M/IcM5d7CLjqW:Ҁ3:tGu.u`o )ԭ]d&2CrrAى\jR$lXH^qf54teߚ&Fu GBc͸W\]"?V 59ગHQQkMh;6/)p W\:k8;>sd,Ԅz0UVRtNhAYȥҾR /ww&DdyRJ>SAⷋ!ᯄYh]I5K6S>;u';ӸK/)2`lQNmȺqwH_0]{oYʌce2Fsz@; !8xI+0!r#ʟ`D!yzKrIEc^ @D9Hž*TPFCh{`S#z[=qP""-m;5yڟ"~7\ 7?ގ5 9t%O6]R M4ZE bfbX`,J8${2\ 5ArRV מd5Kj8ÅnU.3^7㙰q ߯S!*F4@=>wq?C2v>rG Zy6 ">fAL8Pv6cDgΏOCEXz C`~MV5W6EB!ć&nُ|&;R 97؏g"8OeIzkV4(k٭auͺbrp/Œ3gthCzP W i}:;~FRw.wD%I R׏2Su>B*~IJJ/u)E=ڒ=F2@8DVs4 #3~,*!Py Qza#4:I:3< $8-5K#їqHĦ-T \ϵv:ހvw;"N7 Z! ah_/#,.%]Y ̄pDs1iKLh+~d8RcD+G U`ᴽRj H >|eS+GW`$<4( ֘U+ӌP!HɇBF7N:YIo=.: F2CD994&H&6<ӄ\bORy1V?d w*33fYuntW]\pDS'ID3[,8E&FE8iBl6VT/?`tEDH 3oJd}:f\=R7xFn_]C656APݕO/`njYS6D-1%roG20Stwӳb\4A*ztJ]NC9s%L'6w}swҁ%?܁R0?H=`V)ZBퟄspfx[0 g2UJ_LG>܌ Y6Aa﹬Dp]HA oO/MxMP٦Eʓs =5wB* e @ E'룓x`M>єbwK+"U, uGe|pő} %3rbG "U(7 :UFvޥ1'̈c6>9ӛlˌv4 I_/j{O!whT1&l5>zo*$;9Fl&Eo(& Vk!]Jg$2ވ"?dMVA֠K0k1FHӮ)v S<3-K `:FtK1Ic(ɉڗNk*9:1Õ+ ,7i]KeГpVCduuHq93V,,i:.wJMsy)|OJz.^[=ώ"$r|G qy:,s3޲uh.P*E0[qH[(*GkUQ ;HNIu4)v=5,{2Rܴh,K~Mzn\zvTqTdzI 30g26.֎9ܺ2J4*0.B96%W93?]G: .hKlҳwZI8{\gLtN}Ɨ`Ȃ\0d 4"vԸؖoԙ ftqh0u.>@6}Do!} ™B/ڴeud屛+dߋ풷[˦A_௅'ye(KݟM8#cQa 1GȦ-9\|OA3 ]d8 ҂IKEᄎFC5%XeTQhBH-gVF4}Ȧhf 䅑5D*BQyJ|AgX4ZRl-{5P`W2 xW_h.~O+t" =?"3}lpVC #y)vr%L{L}.t\: Ġ@?Kj\+T%ce`cDа?q8 ְ7Wscėݤ')݉tε=̞w&&j&4DJ]Q dA$[SYGFVB)]VphO"肀Xpbx%JcJWADG=wƁ4fn0S1⿇N|Ym5y_G =nA]w3Q!E$t"1rU_jW!ot,T%GBQxw)s ;Փ}CPT9T{fh".nO:(S*Зj<=3d UrMga$GMOR=|Y˂mrfh\To'`|xzAA_(5 '5F xG-WDs uO,SƒѸ Frw ;([V*_5>X@L`O2  SP/<v=G־dRai;vT{d33WW;:CgUƚcK~tb}](h#bvɛ0@Y(o}U67bŊAt<.N1_Ago`jPTR.m$ǖ /O L&`f ^@Zdu&v9e94rjc8s;hbBQ/Qbgdkl~;X:N˨]k%,mn+1naЕFCi?v}>1fjnsdT6.z!^WPoeR?ڻ4ھo{=eus&C|<SV"S[rRFed@9%+'ǥ-&0+6";ÌKK93>Khߝ=Aʡ]mR@G͏7e3\і B\Y=JNuP ÔH yHո+y%)"/@b :uh>8pˇO-"gX]1ڗ=zfZ 1 Au*yha&m|(L` ܠrK/'h%pEa<^9&n,GؾK׏Nt鬊{~<0b% |7v ED4?dC̖ן;!N|xkʀTdi]1O$HBOXT~Cp2}"HTU/ֈN &d^~8a/r2%1B)AlpQ /Ȭ]CL>\;uC(W+|bq~m5TVEDLr̷uPna" <4$˪F7I'FEyvd/ GsKh$$O>t+BT1T[.@WzoWGUw(#:rsu&2Cu[$d,odTQ3ieĞmAЅ Q jDtnY.*.j>~\v~H.Ƴe)iru:ks~SBO+#E{ r "IQƷ{HhƯK#?;ljJ,^ |(WC"=QtiUO(7O< AN 89  *_L 3,-bТ⇞ŗI_0u9‰M#nS,Vt*@i٤ʮM0cJ6  hW]P,mvƜ`n.+.: {ڭD^UQۄVXmWRXT|я*yW3Zp`+7|D(Euoe{]3*0r?Ȇ~{@sf=FR4MgK G_PaRK5@Hmj _c|M?}cTN\Yȫ)*iR3oc8|4 le:2s(KE"N dAJf򨥌*g! ZjH;,Zد^1ȸCX.S {|DWT 'oK" b<:%d ^W,2LEBiKsA nr=0Vl"hB,[ym|OEB% ;'O 2c}uM}\ 8^B#@c\*eyz9.Idt_DELnV X7W]cPөH>R nOd_w҇ 1(jW@kp|$Qc࿿(CMDo+3N[X[Ĝc Vԓ/%4,7 m4c}m<jqH"U 1FPRA&p{ ^k'C{ĺ:Pdmf/:8ot":-pH(! JH6^{QF.!xR?pyqD-T$0v l@,͆n'A&"SgfG>]nh3rHsvLWQ(5<^2'Az0#ʫq~QR`=*oo10b2RE2E" 0FzW4Y7E\\GP -Dxdk l qؑ~Rm(zm9a :Þ2ƳQxMwIR3^{'T3XBˮEex$dnEzMpG|cal ױa)ڂ=6iB=6A; %8N6b9LyfV',[ܲ ȃɆ>3mAg附nGnEW1I]v2O˻NF(%^޽} l zr"_=٫wPx1IiEFډ*^"ٮcpPEFql3)A5b*Q 8*^BÅ` ˻}D-=MO~L,cR(b| >U'H`]Rd @$'~1ϧLGwMßZZ#'XI^3#8s7^c}b=5+}ͨN)z},2w5 0Auy;|A3ȡV>$^|lKʟYsV<4X-S%rh2s1܎m>:aJv21rF)-U`\ pF̓@󊖱 ,Qwp10ee B%~ Ϋ%rN`ټɒX/ّr8`_"{\m5{Ǜi*d9aSHݖe"pgN&B+YWO(,pDx ѭ|5Ψ,j*둹 Ԓ5͝kUIʥ݈+0 d4$iGU@@,I9¬PO]lx;TS@Aq-XvF=yzS(G14a-fb Na׿^#GC+YvoRAvXfp /f9/ 'Id9n2|~"Qsiry=_B`]K/m\P`c`(%yW(*`Gmp'dʡhC)za aʤ HhycWo'ɑD#;L|Be_Xlz76f+3(ĹDNBSȉD_+p&ѸJI? h uDFݫܹC :䇆 gT~941; Z&v`4ZʽW vmEZI OTv,=/B|%,s6]*,.)7}w^߅E9`h=Q>җ=MќgP.Sp%@[$X.fuz?JvRsR싋c[yv'֋FO tXp 1py Uh]uScY/./#]엎rܲonnibz9։ѻ84P?;ɉ{xW4DFذWJ+=HAPeȏ-/maEJ.ZPnZ^_ؠffYtHA.V+4; ՙ#ޱΙ.2V\Qf1|DN {{$kXj2T$- h_v"th0DT;gvCLXC2rSvݒՁTs{3R&αASϢQj*(U?4?,/s̻Ұ-!fCѐR]=A~o%ࠑ"։q]7q_TΘ2V_٥l p*ҁi/AϪxxq@S짴ԊDtjXEj6\B'Np^4n_Z'| N, 3|sDJD(h(y9VY;CZB)z̀/DrF\쐤f=O.Y0:{ĎxsD;#/l Q/}>ߠ~!"zEhVNkW8#z=}eI[9 Y)_H3(AYpj ~τ=N`'3 g}wهKiu]ϡ`maB*./D`U à"{fͮ)S+i6*u^`ß\zԤ4,1-ZHjO$mNIf<Ֆ&]ڧvs)o4CbpAhJ,JA7ࡑ=!#JTZ v\[?*2c]9*2ȧ& pU!j,B@FKGL& !XXhͤ<Ǫ29Җ>|m=B/7?!m4۲kK=/~]XCR-p۫[SUJ 8;xnX'mx/6dzw5#"U1cSr^V!69Tg:]CP{ptr{Fi FD[ ^lڭRxIgu^)M^Fk%G9z@t/£͑YBB .'s} 4&dxyH.GqK2 ~paDH;t6,7K.V:CtVIRg-XD]*5[@B?"V28OecO֯WjZ[0asCTeNPbݽݺΨ"$%BX21 M?ӧ.f½tmOd;[a(+Q_2= 0',]6 z(E8Î-8CzŘYj/qs$LĄw:gϱ#Ḇ)qY^Ks;#]%_A.ݙ跃K5@& T x.tʍ'1A1;aćTn{#麧~ mrۓʙϚD,}Sl & RUh8j%o򫸞#X I|ՠʇp#MW;x}|k"e/_.&罐J5~؝Mܔ{,"d6xO?s{`BL$)e@/CSCr/ZonN Nz߰ˠ%+ _Zb"{ Ԙp&fAzT7V]EsK[=9c cI8&c  c:Fzfh82x#e QV^UJ_mk=.ݰ.Σ%<Y=睎ym㏘BA#45C6B³y=|ٶ܍9~õlb01Q(T6Cy25SZg}ܵK%#({3 @!:`a:|DU#B (J(t8[.6-!ym5*xӮ;)N'<ߒ@On7RȮfJ ЀV;$ q9JV)ݮY}vˇ heSkֿE.|E-Ip],19>F;fhKCԆveJiӞYcw*pjp9M[;X3_d'eB]k_yL"ϳfBs)_,Fr*+re- #>PnS5eHd`:龒wgvZys ' Jn g兪pޖEl_<ڷ:U3>?ěתBD+ɺZ5ک~$LRu鴀38Kc?r9^N|Grh_i!~ze_x@5SӓW1Y& f$V 1͇b$\a߀͢ LoxӢ.[EJLRߠ3'⯧ngsx~63;y ss6KPPpBIA45Y1!Z?Dv! gLe-ɡQu-VvTǽIb۳>^6`0U (oWx   6B--*@DstlC+23sA{:v XQ@<و/O3V#e,_Q;;?4 ze8U6oFSÜp,yS9T)/k+bFmJ#UmG=ӂH<73Ϧ4Z\3ˁ}AI~<*yf3n@(!gyH( =b4/0y8aȪ/wq'Wmw? Cjݚ2*'XzW;B$E湉įexXv $TuXU-SDybMgsN}/$k%g@*A6y:LD؏vZ%L2JqS1I)^Y1gPbY< {#mHΥGa8l mL>WiW%Cs< ;j\`_Q u4.ŋGBhfMiG+%.7fW4|8ѵ0i% aV@_["HQ_YoxgVJ;%2ݝm{~b6KCϙ.~;x,y轧%45F h0=\]9&v7lUIc#'\7=;/}aƇegR'^eEa>ڴ٨rVzV t>OC]W G4;#4ƕrP-vD_20LNcBc("S2Kc)<&HNk_9|K;6}#e,$6isc;ʬlF.r[6"+͕VE00,C QcwKBda7OrTJ2P @Z 4 L"9jK-$?jvHZ,w<£&Wyvl<hĔ=2gGeOw'ZlIY`Lbպ-3p#z5ԑv{T^RA!MPiI?F]qt\FwTrFh\L\h&0YM>G%=1)ND5GJcT\A 0óA~$R|4_n1&Xg g_rE*0sf'+ h`LtFo~l8wL mƝ)Wy(-P^WWhWjWBk؎F},XSDJm|Y"S-f <,BDX唳W-6ڬH7:B nNY8! >Aa59ts{7abG[ФsEe5X;SJC}.$ د Q+?y}ypcP8RP4|a6+El5/ 7= J8zDqIa~ '3Tw-6Al`mj4O;~: 4wy lz'&4\`\pҚzH]R/rL L1V\SwLK}z`^085 {"ol3'#2 mr),$)%C9\%_~W2 _=Uߵn^X*NtN#g%@YDt_m=6phv3y ,ġ ^HZH!<2f(c'$ syҬU{I] Xx'\A˛$(3+-lZ~WcoTomx4;u, h+sKtẅ8.1we+pbI MK"J!|p۠%As8{$[8Tk)"EIC:qrQYң7y,9* u;\9pD^Dũ4n=z{_7B WFP:b2h8:wR3)aN %}v׃ɞ?%?,Gxި3GBjO/A0 @ KYilCnK9ROH>xcIwЀ ;Znonj3`|2SKBEfICo"2ĭ_՜FM wmw%9ێ87Q^yYQ#)HQ J?OpmN}Hdfdkl(N:EDLUu{\ Q&ۙBD*YjA)%%2_VO󄒬=QNOϹ_wT|e"f{;5|@tr E M:)-&RZ$v`f82kS{n#vlTqGYt .TݒR#SR38v K0MBjԨgI II_xqtnzW߭JRkLbKܻYRn rR|HOͨ%%#%΄r!"Ē'1n=qy,*ޓ<.˼1y?-ɛy>{{r,kp4wSBUsa; iL_Ϟmc5_ǾKRP!d=F2:^:N14~V'ϚA wIBg?qÍSk ˳-/q)Q*54;#X-fH\}>$|,o$"y\(@/ ޣ+R Qd>>X"B㔙%P-ttt1J`* _=|V2z.ͣ9B*/]%JTLAf8^MfY\Q7ZgVEاPaMx0MN-x&Vھ YSzW>kREj^#^%Khʚ+Qn*&xnyB!R9;h/dQ`iX(HCv?-$$Qƈ+9y-s|(Z F1_|Tp9+tHtHh9׹?J :$6K/#׼)L5CLE "T9,pIړ H:q(jqQ Ei6cP0"rًʹG:j\0xN*bʀCcBZ̶llΖ}%Ml7.Ym-i|N3W3I{ju-_:)!C)=+3 h)2Q#^R.,k4.Mx2`{}Sq+- 8oiaqjn'^gн T{vԔvGx\Hv?A!͓_Uv y%Lð5rM$?U hp@*b`I'n^w8" \ΕeGBȚ#$-a*6<"#L|HHdy~ZWX{VgD䑇yI<"z23ph j#t2/6kst賀nt7ٔ<@L]uhh9O׎AD !D6>i/9P|+\n{֎2V*TvhaiZ7^hˌ\N')^p_9{m4˶G3mHږx\XbO8Z=&.EC@ir6:|) _XN׸z}gsT,J'N;R ^hu}z„vr} |:?Ƒߤ>-q3~>]i/j,\ׯE*=1mޙh͚p.M= ABa݀K"QeԨVŐ#v0(wVbBa/hpWB!ldJğ8 G#Qu= W;q+k1K\3qz8=.7c+GE8IQm^&`eSgsdNm0Fdf}΁M¤}#p`M}uPäxǠc,Sq9T'vvHzHKPxz @T?+,i%*E-mbIT#xاP!zu4}S ô|"ȩKz+{oBcb\CrG6+78c`3455vi7YBh:+hhKrN xz),vohBS$ٓ/XW~twghLtț9S"+zaHKPB~i3.NRN e1%jEZeLu^.{7Bpb |j"%TH^f?_VbFTTJw&A \mvA߃6M|M9hG=wvʙ|ЙPE؊eLt"J|!~H湞)a X ؼž"O {q,nCmLu] #=Uh8ì"MMaPi_.zrJ%/.һ3 n%֟M9*1ς#n^ҧpTk8u/5HɌuۦv19\ɤf"J^{PaeԖ .)䒦Y,O/p"=wP(# YJ.GFsPIOs=]EJ7Tql}F h"xF,B4HR Vc*;W dG*!E2&ZBͷ;#L:ڕ<- lG7D >x%YKMe t,S,hY*/NeC z/ZQnL"iu"cq57hXT_k(ήg=9u-1 DFjcqQdҿ8H?GÆS`u9uB촵`Op)ɾҌ bh-h.0tdeNx^ni݌9rI(D_"Qv_mB MDX:hO~4.fȆ[+NT*OΧL)Ԯ&a >%\A=(_'qt=Qu C-ܵ wz+BRnH^nI8*$bOC2Q#lިs@ U69e T6 tV$`;o"-?b/o8a[M?teIj/X֨90VJJ}y6z '/m#OOZe&D_JhĐnzv1޹n#ZL\\ 7ƻS.>X`PiX_8k*>2ڿ˺߇#xlmkZO&T.by4qh馪Ǹk)6Fj2Ohߌ0UR'꺸\YWME\\ 0/zlOSf/b GC5"ख़aekX:rG4'DS<9mbKj&V}Agv!7^5n|m\gZH*ՏܽED̍Drh,cH+yP|Z"@pyCtyj%!S&CX<칝@%x<$~ifq`T[ښpr,lu >jKE[/)@>5ХA0qP2 kYT: i e2Lb+W'˰ yFDbg$8$. ?#U$#YftQsrD{~ KQMLpqpx|UvԢm݈@Fk;L$%Gr/_Jmn-Z_PjlE&2vo֤^_)y[Xn ,> ?[l.P[sNu%8Gz@ -'Je,>kB((9XCvr"Bl8)7Q8 kuKI~шUq -Q#q'=,P]٠>llaӷ·Bd&V_B.!,9USJ"|9-ǕDv~}7q' +yi_C?~:m 3dxM4X>Ȳ3ѾuU 56?lMQ=Ǝ  )JgjAF DJ?jX{/Qfp(2,̿]{rbj`|_ A'oT.*> j5l?$qhDPrM,<4N]NwUM$8ٍgy!EQ)]y@6w L!Vs#X<7" `CZqE]\pkpA!Q t6)#Z'(-p(Rnxnc[<.3 #qԐ'JP gX']v]Qfɏ+o_uڍَb?u|nE~O'FۯI] H,@IgٕTg'7:="E9-~A٦8@P.h: &^Hvu39"N5:uAY[՟39µuHߝ Iº7;]CIE]!zhа}. eyf;MS:S`/63i[; ]ƚ4ɟ:c0=G1sN|s٫"lW~QyTB}a׫^BTt/k_o |ȫmAiqyDc d? 9ɤ,*ו<ޞ)S[=a)+뒕T/_zZrI.z! wu:_ `-M;Ǯhh48K2~Bv&vsO拾TFe7|k !Q}(+m-]`͛TC]#h4ހK9l2_ /廽UEVꞭ-TZB/`#ԥ}|Nxbsuρ E a')wWp>8z3HR͏I`]7YpE:J:*LމTNHp,ZIɽ[?J]wQO"F+J-qXW0o1? }hyk!F#yo[4-꼇@F=t2ßXՔVvDuO6MCͬK{m2k4$Mb _@A0;vo= imyS??Mpʰ6GN㒏L@әX9IpiÁqؚl3^>5_edMgXD*]&,gL%EeG93FigB6_.1^;ҝRse(ƑmHI&OL)Wpߓ=oa MFHK)5ޚY,t !]D)Dd6$sg!QU`{?_E;47K;W Dy1&0f%Kʵ'x5S}TQ^/&|k?<_*y(wCdʐW~}-69\YVTN/5ѐ6mrM%_<5甯Pt+yAv5,gN %˯+}cv[VV٢`*] wb5dlۦ~{q.1aM,d>P.rPe&13 T/`tA$9 y!/Iqgk%aR<g9VֱN u^ܪe,|B044zZ)b>HM)޲vqd*=d{`3 ^p21, XΣ s} -Y?߷d3$`Qo7}v0?"iٕ6ƉGLx+Hft5v)&kxxOJpO!Nڊ(+_<` *&o̕$7|)n}DcYE iO nV*Yeж җƝSO~=B@MߍIL~ `HEtBA ݕ0li vO"0 Sse*OAdb^ݴ!uǏT ܏G2P3#˳ֈe>*͆#F\<|f jfVFP84MӼON!,XrL p{؞igow.v(nbXMg`Fg7*A#z9y$ =OY>;w8 K7*_Pan|?bE0;AOU #bXF^DfF^fln.i)T3/w98TԖHt>IV]L_CπX,)?uZQxħשEP fө)/ VtU,*=w?c&u(RM0yU  .d W>MLA6 Ha]6P%O{g+uԴȆ{v9d!dw9"//(IP6p;4Ԋ8B8x MEz)c$ Ў6Rm⬊6uPl<)Hٯ ?)uM69& pEOA7 #0o T\|"i40v'@X"Bkd *<ݑʊ>tԓ^Ưyj(HNTƕks]B1XzwO^RrNM TzVM|xbphMDT#җyo&4g)~Ne/^fɕ̀hOBe@f,|ݰ^-n<'6ƎLve85f'B{qDTJ^Ŀ8 h`ke_~]j!&qbDI9=z|0s:luQ1~YoA۱wι17#5Nsꑇ1Zm *"I&%[nR!ڵ9+v?mӿgT"醁0!vcGMѹ ( PZ*.2ZNLE椟+ZE(C"E褅! F=CS+U^ɠnٙ:Őd!'ANuNtNgH' [ۆb;MU Re7{bsi9e=?#x]$9Jy(ycW8#ZZL 1+Y#zlumD#-k5!0,.q 2pJ?}ؼ,B)1D.P kN !;)f /DS n[T~-mCyUO_ɱ́gjYkoҸ#o2 uμw)`e1 ,'(mnUIw&ړj7_QȘn qx>x-i\eyyF8vMex+Dڼ nC8U Jf ?]`CS&nFOX: )6mv H\i-(^@ Ծ9܊]!S{TS |{._fߟb;q i/g8e>MQ! aj7η`alV%Y^q2*Ga|44Lm ܤێXpJ`1ִs,v|$wv'-UMŝy={3?fWʂ}wH>^9$riN"RWM{(NҮtQ2D\E24v3Z^~"~Sҝwȃq"[U;q3&2$H/66sPm4fj~.,#Hcji_o>ZNpL# o0Te}@p\Bet@Pp}!$ o>^KIZP*a/qj(f!y 5./Nw REeוjt45TӉ{ƍsh._Q|% k4u5=b~0,ޖRG`o j Y`$zn:I9ٮR<@PϪ\FG q6Uk&G]ؤ:P<1M2gFSBՔ\p(|8@ 6"7~@vD )䬨_=xchn Ic֨w,np{K7x uVPm.:2arIET֛ T;j~^jڕ_rB6y&j̖DW˶W>3ؓsy3z_x]2 oMoeNp[" MCn7}qq10Oj<2 L~n6r{Ŷ~-J [ꮫ[^9ɸ WfgK.2>{eG}PU77a __+jMy4;ңd 74}@k8cd"9޹L/G 'i1* xHf:-syaa\Ui*f'sP5×pqtuwROGzIWNA#ِXբ_YHџ-aS:3D-={aFMb}1۞gz/3(5JkѤ@0{nz=AdӚhv⛈n^$M%{j5m= WDIF[͉8I၏*x@3Ёyľ*P u0Ժ:VbI5ql~46,AGMdئBYT)Sێ! V7vi\ͤs[ofbyL,R<䮂@/Xts91}ޕ"-\pwK%`gsv`0'\‹ ;|Ĉ!յoH-wJN"W=k̐G1;P'e ̵).ڲ5i;.*exY8AV5CJx W敶)A6PKC1cУ--Ys[>T"} VcM(功<#1 qrޯAiIs4ZxiHfݰ$~MAp~Ws9˸=2Yk+7YD$<Ͽvx,9dC$"QՏ*7$k3l ᛥK%2L>zktqr !~"$Nh/2)ULN* d6TVJBp #n¢⟄B86h]2 O,MG(7Vw}AJFJ7ZbKϯmžKԗ?29FuKȜsPu1E$5Z bZEikPvd䴃U5"O!Qs#i)ι^`u҇t=z 5w:\Upvd{+p(ƍ]WaR>B[z(o[T7Ӓn{K7dӂ/3EYF)F DtG^~ЍI=үSB=GC9t h4? xI4j!S-d-2\زO^/Y}P&cwMU}*m'Q˜Z ѥ3yqR^DT$wB>9I 0puЩTn G A$~%tqIhmr#ϴ0Sѯ)>zr]zWKyP X@Ò'DTv4H٦牊J ,̷+pFNќsvU*z'ߗ) LTt,?_^m{cjy؆]g<59- e$bM| {(6駵b;,X`\cy:},#]f'3ᢥq x3cwMꗜ2vUiGd6/ANzCqޓLp-WKU-q;(™!,/JP&Z'u_bԸj @Ď!aȻ4)7.!gNܚ]'730+ KFyVu,O z?fq̲fR)sa&I\{ڗ՗yV<̥]NI>h9gVߑ|RL<KíT3egsp@PS$Ux 5]h.Ns˃0[TRY1*~҇[Ao0)^ ,`ĝRck{o9l WcL;Z}19 F a]ԛZ{C-T:Sb)Hw :[ҫ44h0`;U=YG۪)<ܚY{Kk\&q8DuV8Pwg^2Bl<%)1+p^h(wZ!|&C1vc,gUcg\@nb=l%a MRjxk|m!JigAfA'uܩ&'!O򌚞^ mнuCÚ}13̛^,t\W[R-(շD lNY8[@lFtVVL:KV24-d13 !́|q} 5Y|&^7jNz><lRy$V#ɏ[m+Ӂ]?eP2e2C( -)ƴ U&F)ٽ̚M1bȵ)d+G]A:)Xp`C/yP6ӊ"h+/AIɖr\"֎1Xͅ%qn3)U- q$V z uMo~Y-&,)٢7ɋD YJj8=*- }L feL_TEjdD;RvrJ{ HAP3<% fLazumwتFGwR~aCD *[D! L?44dj1 Yh }@(t+y. ,QVR_ۛ 4Y0'*ưtC[-d8AV{-tjՎɍYrcaQ1EŨ<#1Miǯm;8(V4xhf%-0x!PX"e']/"QN7>rF=5qqnS3k,U 5KyOu5, /DfeK28:C (Ko%XY jnғI<1h4PaVxx46KxPkfŠ~Q5ݘ!2 ]*0|Ӌ7D{?:FV3MuIj=q`C,ӡs[iS`r7W$<>.AZ;Nc)1F=Uo5kA1kkT,3*׍J+[ knuՈR Vgzqu]8~ )GUߤ7>b "stQ,_H>kؐ://[8>Yf,GOŔkEjzԙ5yM]oCb4ցA57Wїi;˚+u #B ]࿙m!%#HBt+^.; y©.#m ?5ݸDt9wdi;xMCwFYTh%זdGR,Q\JY  47XOYze/xL}=Jy( d7+V4+)ukj ps]HMYrw}P\~Y԰̷Y9 ր[I=c2y%ŷ'!;=U7ŃG7b9*slVPZO.MOtpSl-9U$\)PW 咊PR<"i_=Ve/"$ ^*(tĕŠ7Lfl;4/5vٹ丬e#+BWtj`"crM:&2;7DP#qt >Qnv2q^>YyaF&vmdaf2lKJ ,<:?`#!Ѫ^z(Yhh $~.:a=čj̵{!яUiSUdK_G_  Ћ) c&K&/]8d.;!]ag ]^0+á6Ls6@B NZ2=44gT!ִ5WÞ4aܽ9hg[ѹ) 7(n5*ܚ϶i3:+%co@RO)"j{Y .Nm@夒oWr,jyP \o7]KNč3cw0%2 |*{tJhKM{W“lħFSb"NXkqNGx5{Wj- !_\ >A~K-x3Ur52fgý/q Dv>uY*$0!ELr8P%2JL5 lw3JXyM[C1\ }# O]RN][v(FOF駭x4v#&D:bRڋA)]Ѕ>3kS/>fIf$Md4-цA=C9zʩh> V>x-92_[H)4;]d}u ?c&.ę@$D&HtUg).͕_/lt}@c6p|Y|hOnXλn{c6.P@žDn 2-_GS_}DaZۃJ6 v?>3^%ww'j <]ėƶOahXol=M K qAwoT3ognu + cRmS혹6DI䢯~ԃkεmy1TH2)?aZӲn <_>9~b2CCo0URONcu>Q_ Z/zQ١CR6gqfsnھ5@zZ9#.XpJ{'P] ȕſ$Hn4M&SIJk30w)aq Џ@!wVLݏ,nu*HƯtw{liҢnat(}6Y C~nZ5B.z["N0W#sQ|qm/ز7B VWJ"?X]poJw/=292LV)7Q yp?ˣᒳ'>4 ExZ:'VgЫIz2^#iUFt5 l#Ua%RQrjq?dBR6&W\j 3NQyGzJ @.Y,νh x40;2_ɑqe*=kQ3-la6Gx3״>SDGּԗ>0"mB×) VaQj <)c@ <;effc\M7ٿגآ!A`Rx?@FG""{ EՌ.Viekġ&> wuOA(:҄3|qwZO[άrs£Zm qJI?7/OcQwT] |wtVӍEhQQeO?̙wz?_0<u-Izsδ^FmRkIrO773T0K3NR 2OxT¼Aw7..MCVcZjc}{esĵMI.@Lݻ;! U樂d?=V Rޅ%EHIWP^RTN 3L~ʡ8asԇtH~Zzޓ9@ 8b\B~Ła)ǦRg$~sE| "Mny )yq 0Zk'2#w)/RTդCHb%̓-9!#GoiSq)wng+k@;pxISt)i JtP`͚qV3Bw3ky<7n̞BBԈZcp2~Pz'7`/9Ċ m).4\hpJo#31b*_&;<ܵZ$>cs*Hr* qήmOjɩ5`s{Gio*bX)7bqUbw.º V,y!Z*!:!첳B7NF\ROqø | %be"`bNBbƚ4 NH31~@ъeֈ\ۥy--<օmV /pv<U$oT.oreRҹ& l/g-^ݤ__nP4hFtj7C3:ino2NpP#_X].ugRTlh0vTո2JbHb{XLE*OmDi8pp7z03\ߎ)QOn #/6B&%P2")b zϼYf`)=L[΋1P=JwNz;v$?)B kp`CzBk&P^\rr>>Ds 5ki=AlN,O؞a3b,wߤm E olLyXZ4'4WAV$qy=0J ˡ2]` ^;39ke~.`xUYQ'1@"?3$!3{# s7q7J, N傑d=ɦpyZ÷=f1a0wr+Q>8z j'VL.yia3,,,^Ra"mut(&uEcbI<{x\ꦼ n#'U`i5F0RZw+.-s(dss׽{l{/v23+.Sn>>e ~{hX{mIOWgtr(\WQFЩ'QO7fz;bG(  rLӖu1|PNlUP]bYI#P[KkCbi9Ǒ|D@maUU{?]+ZW2§ۨib ylUZcƉÍnlHF(ilul63gVݲ -DIc;<9Ԫ,ڂa2 h~lk =g2R-HV?`8 m (}Oz`C(BBeAfGj2vi푠Ҙ,78$ҔT4'BN5{n67k 2y85+eY܁SazV|E8n6W!0 fU-D8_xg\q,LGl %M1 aiDv)v ddL4H].]1evh==SZwM~$<MVz)w~w23Cp #yȩE(exUiEPǞ'OSs!uwh_<,d)hֶgyCrZV(%9h'϶aPQ,)sx!Ql><ۄ"Qiˎ VlRDWj`[,+ Ǖ*-qXEzRN_?IbvڀNwX9;`t6ZݔP&lɃh(MHCMo a {v~/z8P8RŤa{UX şafI֤z$[Ws մ˻mH@tdc])37KIJY%R=Wt>bkicsEj̔}Ososl{L+p t~ahtB|~j | X|#5czA qsCHQOIRtP]Y-pGw)y!QRu(&yyXUq̞s?D4R~bLd{ rE`X%v ;>sZD'jM^Ԝ=qP @ yv6D@[gZbg64?/%Ooog 2z,a|5sCX}4lC5Ӆ;_uiXφ'6D`3 ,&9 m'%q0Wspuފ =zk[D(&=  ˝b:g3EE)xY `xVi ^.s Kp"e$1}:?XP9qEнj dAlm718QK6MZ\\c1v{E;z7Ch]70Q5YC) e X|kr*0"rõŹ'{qjAp$aoH{-N-6hӯBúԆ D bV0 ]0F3P/ş=a ̩/yD,-ideB.]vaRJI܌4M4nz%ؙU˻ ox,8Ǎi3Ap)<!9ܶ='UPpe@,en<Ev*WOf_Vq"0S'&%H홯c+$S^|+OH,?gٲ;D<ҽzPfEi j]x:*{ &dO ,߶:/ "ɒ!I8!v(?w^SVFq?`ɮ63Z{83Y1 :["*4).qx:yH2A6լ_1@0n/Op%'2Z'\x u4{)"'a9)gF;=,yHsI xk螃Mf`e=m$c ¾7X稾 KɅL8`z'Wt8!/"p=cy/ {UgzMciPk A畎nz:}iBN`6*y)F|_mųd\_Tj;:>1i ̯ۑntH4W*q PY82׵֫4YqϤ^Ǡ֣doxj-7ϲL@hq^k5oYFv  'N&>t+ۘKDAR{þ' |;љXR:scj[bWeRkN-"(%Z64Aρil@O+;Ww0J)/Z!]Іu]9B_C s[V>&i3ҫǾsbfm!$Ay@칧VܐN"0v}cs6JLOFvFAN]t/W0>r.~z}I΅M/X2(ruF&|Яa{B6YQכKu$ʧH;fL:l. cmȀ&3HyCb (Ga%׊C>S[q_r.W %v%>ꕽx:'zhi~ BQ1(Œhܱc_C7z~I8T!"K1Mf[?r9qpҋ(X?* 0ږW~ # j\To@4nCF+WQ?<㧃at)ģ;Df4PaDK,XJH(TxibZ*>Jo҃94kZ4O [TpNYA-z_PP=(O:qo{8;i3ƕ=Y9/nʬG{c\ŶM6Jn So$]< R#{קeceIr93%钇ݫ7jVTh@-G I36$;šC_0aϔ}/D?E7P^"bHrH."*7r V*:A"^{2WߎIN^ ;bb>N +'ݏNDmU]zq>X&/ Ln%υ&ĂA$"O8%SS}ɜ<0لBQc`{'ɳ|P2i4\ 83߉ Lw.}Vr~c#‹0TieHp+W-2QCpSϜOulI=Bu#M}U:ԗUkb6A,"zѯtxp襞4[QwP-TzwUA4tf{ 2UίѸo%0$K7v!J4;qGB|}vJQ=7:#۟h}iY2:2i N2E8&WEHfW1t h5q6dw]0LhM a)DK{=4*ěu K9efGu<@c 1>P ߈-ߔx DzPp1ճ%f/6XUiMmXؓZOҥ8oUٕpcg:K='rUžxs;-Ss#ڊeG^ %T}0ݪ=YS> LHj˚\yBQY+\ B\d8M$A aĈ#|o{.Mx C).c>ziOυ\y[A1fH0?N AEBq ݃*f/FrNxش5uS[^=ʨ6rI@u|5Plß+V26Нٽ%&~&{mBGN?:B)hW@ х/Kr č"h=ڋ:TNec8յrhxKSU-?@eX=עtk6}U3Y T/Qc=E e/yܻꈪL^i+C&P$w bS8Or!8U'3(ґZH8DB򫸺/ m;#qc%E˘) B`Mfٓqz] O"bOQl#=F鈠_%-<ŭΰ e~EΚꕤ:_Jߖ.^|SySQ?(vJ 6W,ɔ$!/b|_؏H&ejcV `/!"7J{Ր쒯}6&XOz)2_@w/:jFNNʨpє $B~{DK1 đGeiy#JDV6 c)៰]~\ӣ#~$T_O`\ os@:&˓Iz_ u" W/eٓBJC:+t \1܁f<(/H=`cw揝r$Pيԗ}sWt DD?>=y|.턯1%6Q *(;J%[a-2#2gBkjA器2-|+R `k:Y UUXMuRO٤g,ӗ5 C-=X!vae퇻˖( {N!"n여Vjr_bw.kQP”vQ  TtHFbcltkUr͐]ozIxkʇWR~$&ɡ6da@{%~ 9zMZi1MĎ@g*nH_Wmp}jJhratGzqŐi &S9.dya"#Ӽ9-uT$q6HfVgU"{~@c%M}M oXu&=#ki!Q.N[o5 *P{iī+HjdSIL9׭9h|'sp[7C;i^{ "B>L(ȋ|Xl3`a=_[֤Ǵ]w ngXL9] Wx> ռnqhBeIb.R״zްi^]%4d:DQ ](-_ ru%z49 +co9ƹF sG̭6nxAPFGle 02]`娠pXjrK݂$p" UMHZ= G+ݕ7]-Yzi=}-G+ksF{;; N݆ruV_^ÈnLa($lN(h/WkS.>^gL9C9 9NGeȥ>gk6@d~p@6H.5@x _v E:Cb*ɱq*#B|[̠fR)X{Q)(xztN/q7 NX`]S} K8mqy̱ ,"0%zn]df\VDռN[*K_Odι/LV5qX+ΨzLŝN.JcJD)[B' ]Eƥ0Dz1>`a%{Wn?G*r~T|Ҽ5 | 7*<D; 64_qw1M "u@F:hE 6#-1|sw-Hե`n` zLg_9tbCr yѮJĒ^rUyǶ(fʵ]Z_b!8}jAbq_3d,kޔh oCH?9߂&/Vm5cY&ئ^5/&QA*5ԷYjAH*ykuBKDP!CO;t/ۚcuzFW0uUjoɚ{.f+'z{~E8 4"gֆcJ5M9)|a}*Տ뙡C*&{'wD,jUA'Hޓf$9Pw0p+AExX 3}I!k51nv̚[~\\D ,$bB'|?kŤ"oa9 iX_7 [sbM6gcL 1%Gx/nNasEhЫ`'R9GKvG:Xdt@)R6'j/ fvwHÕyH2BMXH<gsNdS%Tb7GΚQ4`AZ erj-K#5pl[uqB(%G?GhGr]"X :j5؟"7E91G}cjVF?M?ݽw,X^EM'jho"+`C`{sX9E^nekRn }+/+"䌈[i&UǽJZih IU㴙HX@Ga~(׃<eg#8s7 }9eK F>I~y쌹H]Wl,g^ŖMHO@VMcࠒ7\c?ȉ Ek q-3-? 'Yј ߃yqE,K+ufyrv_X=UT+wP"%h8ƻ(j3 ouwIՊ $nL"X/bҨ{A&%M1K=j(_GgdU_@Llv*vQZi**:=V+o҇%Rt.ыHh69AuϞ!~K9/-xCkuHL%&y)Wt oĦ׾ڥ6k2~4<]̶-rr2~,@oghf[;wF#M[խ2~ݫ7nth. ,6hBWw79r"&T~mEKTbPr@s<7^#h!$;ycQlXﵪU.b/*u2-oטZwi6Ԋg}tє2Lπy6=o*kSvA%M##w* c*] 2BLf'֖.s*@9467קلVS*2(b@QwbP5[g rhJL <)"OXIo|Z'#5c:Pm3OF Viaݍ]9yhmXH=3 ;H߷$D Q90b=9oDLoq$J0fWZÝ s杛vR[ԐB<+=P_4+[^]W1)CVM9=~ qȍe+띫4#C_ fRIAb'YQ`fdGcXsKHK;-?I;S/ۧ{;=Nq3;(,@,I; [Vz>Q,Wc~0n+Bbɷ@]tdЄ^j9|,>y)5o.=@!k'T@;a6kȁyB,smJi*7/(EѮj&s&OLN|z ]BOtIG=38xNqm)wN0S~%SG:8GП%-my ijkT *^igȾRh܇B$e~_# H7[#:[o^lMFjPbFQ,QLH_6ꞞF45qNCuPEma7A4X@IZ{[,H3҂7Rb9+k ;cs+ Wx{'IOpz-xIF[t zS xHF꘱UhkN.SvstC rLNa 5xH+£5pM큳u1g?H$4fvL8VOe#C$8@'n`R]uڱ?Pb'>.ZSw~'J.DAb`.rs\L?j1x)X'b;"O8-nU5#xr bVj$kHc 0D!beVߤrkk\鹆vc00󠯝(&Dnv!Pr[0ХAʭ*8cꞋ,Q|_^<Ǥ8G`Wz|lcIv\$?1;Ǣk,UIWOde`v=nq#r̘oB_N}M}|K<OfR{n!%)% dmeR%2%77yi SF|>'R@zS=A_J5%XrOQ[]XO2- &/H,3;u[sRDk4k}S^Lز42c#AvDc(~fp{p=ȼ|iDm MKgq$P3%yb_lYkd]UEd/q+D-$ 'k]63> FR7C`д%,WI(QO%7ϋ.f䪄@;]7R#KET(߿S _!}ciJn֙k_.%Eϯ4YHWB{SV~PuP>$iT ⅬBe_ؚRUNQD^>ziT(F|!))~݇v+:h&70"_,;HPhCImcyS^ufuݲ͋hCF~'nۀ ,j#ᆌ%MJ[Tuߠ!TN'ꮀÆ o}8?P6}4CY\;J(U:ѹ#3Q %6z_uő9JM΢UcSEk[\y;Qi[೅M7JaR|Ӽ !cH 6'ClgS+?MS-㧈q1k[jh%)RV+#?ENLI}G8w#wg@xDEg}A1dy M {O'@J'DDpUY]N5!_IRpX-[BBӐ^1XMАK6gv?نkg0m>ݭ5kc[,-r0{H]}a 1͙C2X 24lyMW wX7 <9x@yGb1Q&-ɈP?gT!B"x= ў-^,Zn;E :FkL*&=`lDA qH Cri>?oE')B tl_3DWeHL5\dDRuA! -pv\%..ɍx=m=WFPol6X Mܖb>]G;@̶]D;b$pJ8=(+h72Z%`;*D %[?0OG/~G^Jdڲ0QcEt Z(WK[B`BzqȮYK +۶ $hl1Hm(z@ÆWh-FsVMoDA럤U]Mz;tvadPwb(ma=C6?H^Lk>߲,D iH*"!'`J|9p [ #[ ,m*d=ːUg0ĴnMK`0`Kжg`3jR?hY9cu'|gԠ D$uo/+A_qo梞W&5$ ݌{mmn nN{z ֡772&lx:@EaN2@@e-?sXKVT8 w.`yqvv aKQ'4ڰIl59˥Dju# Rռ7F` [xʖrbXI螦/F\>z{s~@;+"r!#O-SKʨFYȿ*XqϯYi&V\лZ篇^{QәWHTAj-KT,,@JO .Llc|Gy1kد 7<"atxNx e\zmxN/'hw3*1&@-@r-}O1M8TC5`HuJ7k+}z`9^3zȤK°![n">+Uq= 5f[xg_9yJ>+!We:|ÿ*)c0?kXaRR֒jXK!D9YH0tQM'NjxBHHvjo |LIXϋXb0*8_{"y^\D,Z3[Ȩk{%!%0!M2lEMTgjsW0p_k7 tC$ȷ.lYBU~Dc#؉W doFpi;>=t^C{y-Y ^@ي +?xާVk&k9&SmMc+*)0Q';R\g |\gM@$( CJ@7ZҞ>9 0ekSҢU2ި+[ |LDot zeKMf:'[DceHiɂElL,_" l`7MLcuXWO|c,xȖY E9?=\ 3X`m9_wq4:R7  iǐ,T$'05{5`>Zn|nл8omUO->6fex(}Ϳ S菷*fJϴ{Zׁg#N#=+93b#Ŋ[,j_a&;xy#?#Vu˷'X5 PojqZf?SKQ`7$%@)C߸})j_!vjq[E,k z̾VӃ pi [{qsJϾAX5ux\JRZƹԅW{z40YXqÂAlۊYMpg#A g4=dH- |oiy5X--y[>5Zk"* 5 n9w)L\0-NkH$WCG'1:0^OpsH1[Dz>;^ץfYx4V_U}˳L(< yI8<"I X-X:׸'HUi6"lAQ ;,;ۍN$}M0(Gfz᩽JrT Qo]d ( )Aך>yWEljD>aXcOO%P7y`UF|!Fs(rʍҵa؈O_QI:Sx!Ʀ?/@%{LxLɃ28q&Ϭ\/F3қ|n;%C][R|g#.ں#L40=~6ڋ6N{{wU[ vxNɾ!|5n^cOl j3c6*=3#5l[ybYgtc>Lo6.Ԙf+p.~tB@899 mD&0%grJ!Mit&i9`.,yK* bk{/|^~ (p-!UӲ 뎏1i@#17 otsK jv:/,%[Q ˻weSd0\KFK9(68g:6Csn6.kJ"XNMiyo  Y>EqQ&E;) 9h~b)C^>*[QN}IElnTjz ^Fd~D}7!r4i.(qqB0 ai[dMS1d7&ؽa}Vi+M[Xql(0Hv'L%׮.xYY׼-X- ,LUƼ Wd!&-vnRD^()\$A:`<|$ܟ<|4劥KJD0[&516)땡%O)ǃ>!JM]^/C}P? -lГJ(uI<ː ;R%Lʨw fy W^ts*hyqFA|Pt8'b ^پ*vn RH5Fw?8@1d$P[75؉S)Kuub˩/bDKZ jtyS\3;@|P9%\3R@& .5蕫'+錷SE-eG~BƱB5S+ a$4"p- c=?W!6,:rh@,p |>-dTyy~S8<@z\KE/-4 9bϑPƫ4v`@z~nWy@qz XweURaݻƶDj઎_Dm5RtҐ ճXV@G1< 413Ojejڸ{]?,y'!ЦH5 $3݃~^Y)YnbO3ߧuK9hbsi^ cƍAyB=)5^+] g2.5f_zH煔L#̵ Ӆn:R;8&e{;ME~ Ytxe ^p0e护;^`=<ǥ5mx!>kE A@ԩo n#j`_-|YMn'BwQb(i3fՋ'RQSI/p8NI&#Ğ] {Qa+=&.@4+pÚa-xÎ|Z0 涡|IɎ:wy|/!<˝dQYr N1.ߥQ7I'y~-eg<Z3߼ uS蟯X K)X]8";Vhѧcd?ߖNP2Cja* JlUwToP3ߏ ٔ<5cN ifaVgAl-Z1Jz")*PɉGp~/^g-A1A&2GN?|DTP۬/KYms1Nyv7KFHf:]ԛ]=Bk J{)t(ZTJSYgOZ[|KM_?&)kh"z:'aQOcZ[q=sӍi&O q2*;>$՚ѣn`ڈ);7AN̸c G2ieJmPr<ӐY|0e8`b`ң9֫.i)$Re(tr1КЗZ Sj0jj k1%oV3]}tp'aj]#Hed;=^wV@~b4#d-{"<[X@~{ycՒ=2ʸ(>v4mx)Z*z-ADo+sK$%#ƻƨۡGϘs~\ot;Lr-D\Yga@ -q_ ƏwlfIif4 Fq0'}Kp-JHgpF*A#zCg/lJV=򰝮¨jn, q>*G٪A~Àpf?bBp[Q y)l2A 5\&$.R'1/w5Q7Lߢ_Vc{E#(!wiv,LWA>B&u@p=Is' YU~sـ${Sm!V_Zݾ$!S"ķwto+JS[6#8յ'6 7ːO4~ַJ@Y~ ߌ>`,w!8Tgr7ǭ;/8ܜn꟰hL d7Vf /M;#Q }0c /;PYp _Rn!Ԯ$Eg(g985_^);NS]$z{cYIt#渀B-uOݏ2%94QAg?Iؖ#r}U?DhyZ ҡ "!~էUH3LhҠ*`[^n2]Yit:`]`6gOU!~ mڣx V_t!?懳+Ҍ3?zVc4q McU-y{ShJH5m~Ȳ6c;9L[$_<ާn+A4Av T~< .m]HsB%%]BKA6-N`e&)g\[z7=G@w'@Dt'DgKv chwhsrΔF%9=P XCeW,d,<|~];Dϵ0<tO9'@F!b)LA  U+_?3Ċj%7n `g fyGAFUisd[n4lzJac/`x@'Ǥ:LZW(4Bcc:j\F u{DELir7l^yͬQP􀆰΅G{ֳ?Jg: 9 滎uv 7jxc"m+ڑ\T8@Kt4òRwh7U"ET-[N8|En'7N{VG#'Tul\2 C;X,҄$v@[v4 /P9IJᵑ2hmE[JF5nT}[?]0Te` 2)L˨m곳قX cKDVPmU#+wgWbƹz̀yv|YtF@Sϔp5!yχ 6sg @c:ﲥ(KV[ilN?(u! *s[9?a^g8u3xG^@{n'XNYef?x;bs[Ji[йHR`c8*obmF#+GA4ܮꅕ,m꿯)[T.) RFlpAkꀳPb䨖h#8!$_cҸ@QncfT5ͬd<g?80(5foz/@MG 0{<X^T*8lX7u5Mɺ+K耺ǚp$lZNk->V1|6FULo=`KNA1 \4~QxG F4usMf9a.l%o*3naJ4BpN1ٴp\7Z;讠 ׶u|7!h>R2H-B[?1x}}=1~ޅ6H`~xMC*gJrD%yxAuD7%qJ4I5 DK^Lv0 Gs+O;8Q:nO1%&=F_ /]ܺ߃ϴPDWJn_JϷ.cƪ4SL*)tYKxc>l9+Q]Pp@#Ǎl(X6>`MQ5;(]ߤ )4@I:@X̷f:bPr3sm6Wʡ]EpϷ LRE;ƖNMel ,_C.ն Er s<1lT0|#wAQrӬ"t˥镋mFQ(!9aiAE7ҮN(zMnl҆&;c`XTN֒J:NdGFDƏ9*2ȇT20N"Zi8ejݐ`%FZPXgZQvDwռsVO _t5xq4l,ZHf77,~Ro0*2ՠR4Mƒk&bn&|6Y2sR7<B S] {G.TѠs~UD0'!c;%j,;ȕ.ÑK?yFlQR9n qѓ/ɌYi}C./1۫\~D:l7^R aj/&7,m|,Scqmwۿ܇sƇMT(pB dU$+Y]Z_6r(of|Ss.HK i#n.v8%5Ғ<tUo}lĤZbbYbb{ZH/3OUb%zhsV:4 KU;ReTt3Qjz{u'Nڏ -wY$$H ǯ<*'Sſzr;`M_*2̴b g,03hڋ}v~[p&i/vpEˮ0mdv~|Q+IHjw ;/~[^o:O+,Iw8`AOӷu5m+).SDjPy=xH<Ω[3{/,MhRD4N+{PW)Y^>rxw5"n] O' e9R+zlQ\kh.4 B5f^IgE 96&C*'u@n\]G}O 7qY'xr۷@NȻmC)_Y,kZw1C`SU}䋻Y鼨mԎեٳm*FJ":5Dr SCO뱕LMfܪ b\8ƕ|^iYv9^x+B/@c+S6K?Ƃj[† 4MLF1]0Mke,w;;p D kuQ`fHMKpy,*=qͽՎ16W hAڃ`8$1D;YGOKJ54K9x46فBQVO.DFdW7oHxe^Om@RDdL`oOf,E׳?}_ٶD ,"4E4t;IFM&6A@wcp ^>i H$ F X'h(ڙF12]{:bVh4dEfW'${Y\نf3pTb8 1#ͣE:珋y>$be 8UEJ*mW5jؗ`g2̅X h+(GNd#,v#~p)OMROx,;ܞeKYdnY6愰|gLQꦑ A!leH<%r5P) Oh0<=Iz1>9/zW>ji~w%m Bw0c6gqcMcA^GHEQ"Y`/ >-\-wk1߳xTaَ۪0[R`> n|o;Y\{B J"gfiK*~tѩL)(RC2< XXA)1\|*0z:FK=O:OHO+犰GZC4(0ǒPgPK-kN=/:&W(J.aBեZ{sX|oV(|tf i#&VLOO-%NbR6&m^hgZz n0g (4(]M H"'g T~ȉ_P-Zoʟ-[UyZN3=EYWM;h@[j *cGf+)Oz>te=Kφ)l/ôJ8߆,.CY`˲*K5VUa/pI6UmPv2H0V.; 쳇9l}T=͆ 8H Yw/PpyAMt%Nk',ݪτʔM֒5hYSp@/{b2*UQnXvS+M5|o+yB3n #@M_ېMuQq's׎ c4ȏS%-G:%{NACˣ {@ CFLj|w{4W -X1P  v؍@G</3 #R "^Dwǃ)k6'ȿʎ}vrGnsJ?%^M 1MWY{1?uXv~+s4ʂOi9# Ց<@9iw//SbjN=wxfoV&! 8x.6ll@t9"!'U)$}Zh>.5MW%BhL1g/ƜlA):^&Up6γM)  xHF^ vJ/S2D9+C@:K}ǟE[sLVm2b1#J*3. D *톙 ?*L/r]eHoQsuWHTlN`mi|A)ղa=3+ )w[66ϥ_l Ovcl?C ?xMI}y/_J%!Rq!|(l u6zkQ^F9@Ay  U9݁zE;Pqhǻ\{#s/g ˸q&-j+7ۻj*ctLC}Y `+#la=Zu;RQdQg CP?P"G P$o9dyQx;.RaXV+8NU1i $Pt!cS(4\ "F8|ړP,Z\G5|ĩCtwP%y DMk(%}Q4WGRſ{3И^،0)O)rv98}XG󺄵,u ɲ !lk&}vg#xM)-N%*:T&_fʣDO4aOTnȕ^ ibV Ok$EYmzq' *1TcaCqnf<Δ8:N bIpwd;&? ?vwIzfBy\1fBuL4lUL1!jٴ:Hsuq(-8 Lױnk0PھN 7}369ϸMY4ڱ/D0( )k[O\~nj3?Qp* <7Ϫ@^X[F ^G:/@9>BIׇb| W5,>x{lTE_vWS}Mߎq"}^%POR!նxэ`4XM m +C{V6Yw 8\qg o׊:ht(>X]w6c!7ΨUI;%op#X'9N,V"QF?a!.gr3A-9SCݽ lp[sr&EЭקg% !;BNnWj~k:!ؔ{!ɃvƧƞ |lI,Hn&kȹ%A&ן?y*0S&?c<4)\G {E6Զ8[:lx `wѥXwaW8"SjH?4r7 &2>c hFؖ$8 =`Ud|VثޣE\2jf}0UI&J pq؟j )|4yQmG!s]QSΝ o'vӳFQ} D;>8>j`IY]`ږ* Ej/'oh7[L>Q‘Aƣo5&ϏFQJ4עgѽP>x,'0Ǩ f(Qvمc$FeaRJUH'ƽ=0jHE^(t喑9S~WmHʼnYҢCdv7N9W-ס?b㹃 kC[CmA{ Kiq,'{f]hHY2vx%%A@}[ dtؠ7Z @'{#mH+ 7XF T`Ӓ7'Z>楓(4I m^&H@',ȔocqPPe袕+)޴/+rώQzЬWtgA3ot hOm!ũ[5M4%=.+-.Ҽͣ 7 QCQh9 'A%U]T0լtl$=7egj ̝܇TN*攏~>¢ޑcɓVa%W:~Lܬr8gbi6qA`2uMU CSutHd`eH]_|/whB?"y?c4di_$ybF¬E0D,kN8ٱ۪7+nl g3H ZnET1Qa/&hty'`)JDD# YhfD& ey ޖC rAeW `҉ђKsDzE'#_WW2M^4#i)eؚ-F iuLE?vQVk*Fظ60x@N=~\GDAٷ}_tAQq-LGɀ*E<>8eF3S|fڞ 2{^{[ݱ/qmw,Q?O/7Q_"zn GMP,Ж IUΚc\ByI'D49:-`lN p)W."%٪pMme>%#<Ό)yP$_I~rҦ=߃JmK ^W/'܃A *Ӆ7YH0SjVS>WyՄ6=WrWʄȖuHd?si,o usߏ՟Dw#I $?9su NU˿739N t/1yk5}'(*$o.ΓLۡDѩ4Stk̘Hgy5uIPq;#DqN~J USe_  ٧},\ZC?]X3l*Omyy` A X)w(ƶ"N?#*4$Ƴ\ )PeS6]x\h>`H_~f#-@вZyI6+ @7mN d  J>esnJ5$@"hi pFQaMo6m5D U3C\JǾGK}:] X,,= |1Ck̇אEm01]0:{T4ǰuUTyVx<7MfT_AVH1C{^W{<9/7]oԪpuHūjJfh;,ViggY^TnFVS$h:oQYvkO"K([%wGq7k@)~Ktj?"`MQWI?'yvU=6*:L"ϺfYRKK Zk]5ӫO?P:Pԧ* jW Z"u20~7 U#-=}}R{ ?!L͎gSBa>9Q]`ˌW8߉18sg@v|xN0:<W;zs#ыjp,tpabE&ߨ72dzɀ=ōje{X0@΀nlòJ ϬL<Ɣ4067k  H.Zb8|d[~&Y$βldݵ2)N}W`打[&5A\iީ :sp`Z,N%rĒ^,{XG@lv.^ujv.^ÊhOrXwIf2}OfdK{S]k?+<,%ejяS?)1lH9Dυ69)g bJFl0|uhB dg;v-Z3a$S΅r,/v[Ӿ*֥Ln[xE*D(ÅH?t}2(wV ^B9ؖ'PJ3h#F&_S߾x42Q>]c>`'h5YGB\ fD,С g[ojtx;6j.Ͻ4 ,)?&XPъ#?ߐ|;_@v!{|嫣+m ~tNB̚+{a֒REϭrR/k[JX?ev\U`\p.4SZ*լ3 |'R>4'YN#)>P#R&]dNͻ;(0LxAwJ~ PuBJZ'XϙU n/լVIٌB cZgxPrҌycy0{8ڠ̏gyDR~Ri/; ?UaKeBf7ԧihVg'gv,lM?܀0p!k&CT0b$#8MPnA,;ƄRoFW5a)7pahaMT7m|07LǟMҭt 1u7acL -v|OE]<}Zyv9kޓ.k{&T39[W:,PUKXG,ѭej|o.;;dI(.c6hXL J. /I ; .*}حJy~f5|?q'냎BOQBOT?|frl-~&<ӲД=^X.Ǣcfё?f| 2џ( 3έg/kcBnW8]~xĈ\ϥu~ O\ <܊u(O|hGr ZՕ4J$Wb5MZ 4'Td" ySWZ*fbT(+ed]w/Eq0}iY[`FQ  .ļ()Qf8 |e3`UDGpO1nw m_K4%t46*p:7YP($[Fv@.)OK޼ |^]aZ+BƳ` 7k>DzYڳnvh,Fo%,N.gYPP]>k(T|i~NˢnEqUr'-.ΰFָH{Pyx/N^KӕP?,6a3iw5RB/>VY2*4h 5^bG*Xj?U4ŗC,sNӓ` )O+xf^G5I:/jn4VdTpϔUr`좯4`1H(Mu| &Շi$X ʹg'#=Lè2NDrryAh; wRi\v%si Q|m2l7Vʇ]&]vN-PVQVXgS\ AJ=b(9boD)ۑ TXr%]})Yqѣ_;L7{fBTi$VUpPYOĉ)ߖw^_-_ 0sex,`>[Aw3̐ZzA(Kk)DļɢEY Fe%8{o$uDI01rgu\@6B$&P.:.?gkH |¨8:Ut0}X5o283RB` UmW80aj M K _v_Mb1Ϛ'ɝ}/nA*=\ʩk/mKHI PiGxZI뮕 } )=r(}gyywЖLA};úTFPf~_;1> v)u&c Wכ}3^jqDV4''0dF]֩D?5p.)~N9Wpugkh@V~_pBl|g-Nle@ꛔtQW^ФQdk`i$$ZҏfrrEʟ`o(8ygi $#ˈקvGaZ7GbŢzIlw @{HP;dԹ͆A!%fykԋEEbtֿD'C6p];D"/[z8O,w̡tdߞqldxsH ׁ@r=C"/i8CO',&䱪e};~:y6Q_[uёR]8tlMPa` [p7(N~ (xV@w9;\Gf:K'zmj%C?&~_'lkuK.^If^nwcA Y/Y`kƋ0̱gh877 $!AIJ[nOF)y~ٗQoۤ*؆ӈEzaG*Y/TDP^ Y6]3»{uS`)iimG2)V=YqIOpKX]}zSOϨ9Cͣې8ox:B;$}}HG|f~{&SL>רIX<O RH\N4U AҬ| Qj x AX#OkVK`pvYT47dlžcsvrLG̦=s{#v1;J֌Kh& :{|NR Uǧz@1lݛu*T( l`M%&jj*g6`sQ~:1 ƒcJuibTJ=)!Yl֟/ƿ4XtLv*m1K%rܼ; DI7$IAuRϷx<ju*aj%KG(2851 CO CTiqYe sp +92m2ݦ` W{rKk#Oc쇺JZXqDIDmI|]kqbwbUقF;%,r^c" V:/܁u[m$. XϷE)|Ro6_tXJN#%ܩ]6tpP ZƧb-K\Fiu :p#0.O3]E9rtgjL"lWaކ1Xl[snh+ZM&'fkv4?v0p69 v}dMܜ>B 3_7ΞVYA\pvȄar(8c~\e#PF#ST8"B?]T!]ڋ֖DG{j{W&XoTkrfsNd;hsA ݦ90uE?wVOLhbp2c7(_]cB3!T-#Fia㊚Qߕ] $vvbbWy~t>cm֠Q.~DZ|ah0MEňlU,.Q67ljh-AL7#@P=_MV~ '"=hYDu).Q6 |ZP,Q 2zgx*8"g?.Fbb J[( :nҵ< bՍ<̾ a ?F:} pJlc6$H")ӯ=U&Vb8!UҹNK xJ k*mc.RΏ欦,La{[ K.#(FNPDVx9Eab4AJCj}(r@`0 ڢsv iod'V,`e)c.`8'U 񘘠5hc6Y?0i5'Yz{lV2['[~z$@P(dΙ=mc}+k1i|mv:1<3kߑeK+7){MmIv+}R;+u?:e_Z- xc;TH"zt>HS&ܪ$fDrSBK2K2^yQ EBojl†ܓp"1*T+^{k|*̊eXETm.b./5IJ)I )myc cՒ16:_P??`lnWxW򢇁a(}vcݫ2aR& !8\c@xE5sKp ~RJ]L!*_jlWB$>A-5 *6"mAB\Bp\yc xx 8$T/:BǟMtw-y(nLnK.Zhw!,3Kge*΂7"59/7>K5"C'`yG:Gt%V-JrCt[[]%UA '-0fs$gqBȳ`0$6":g!Ƌ)5[@f6cmsNhcTS\wԎƊүRu+EɜaM}0lQijξOg RA)pa} HA_\f2ȵ|Զ-C7p~[M>r]l2Aɸ2qRs7>`wЋMؗWtP>XtcP{k-U`g*jua3[p{,()z%0e,ij_Vf2N:ʀ}v2DE3ծ-ߪ(/kw/9 +yT I-t%NHc0,YHa&a9oDQgf*KǛ&)ɰe'R(UnBpm@]C(kSP gN GjM(/[Ƞ'"%؀'Ũ@ȇiӈ$R6ȃښ"ܽ*-ĵ*w;h=ő n6IZYo%bW μi~hդ{DB>^QF?Vْf.}/m $`mgto,T_,6r I/(v|<Zrx=}ԷHqg~Nr}ja%>rgoE,HXBH/ԿkVlUއEzAbWuY_8.$;4HH 3AѾR'D ^AP,>̤°]&O'y_5 -tGpgNbFÔo -Ol'k³"b%WtJ2_?,lX@B¢?JDdl$qmY V@=}Y,K&mdLmZ6 uMn<HU_X7]yyݗ\],P1r! . ^%%oG;AQq\mdZ dSNvWCDH25x\ byay'bӽuFf,JEqVH=[hp;+fb ŘS>%y˹ (-VJn,SeQ3l >ۤ'V>m%yPL:/{QF5}ԴǶӍBa N2R¢%~;!+ Kts(Ē:aHED(*8U.#ӛwt >X`7 s8B扦쾾3ޟ@4.tc|./04ֳzjz4Vbj%ҸU`dy ϑIm.01`z6atR_3yHԭ$BqzX=u1w'h۪q~+ 4%SuOYUWۤ}ւ^`%I̿Zr,UW s/q27v2ұ)ldEg#|)4zjScw!fI]Hޡ$ҕ4EYIl'pguJpcos=~&|]q0lӣ=t\v\АIkj\R-ikΒQNK=%V/Z/ mL`1E nܺڄG!R@w={vۗ>7_\)k1mHbCŢ5֓IAW gW=$2/8޾ݐJHEeYrd_0/ѻWFdG,Zj4g1|il9N׆ 'OK`=k@^ P6Zo[╽\^Cېzojdp.XP0h',Bp%` ­Vu#gk'Zlg&@egdZ7{¾@;%re| NP'VFV4hat{Uo-vQč /9+fGM32;b<N@ųl: 4>߳!?+; F ={vl9Uh}̈vk,!clkGywO*[P~O3hYn`;<[K^ I+nYnaRNa-^Y:^s2E4m}A{,}ih h$,N4`O1yB0:1 W- ιzR!Ҙ5V{j5L-`<+Cp3O6t{luDϹf[LK`vSNaVTbu2Ӎzs0+&sr*z7umc:&EKC7nEʖ2uRGkv('4X (y G./"$Rj’F3˥#fϩ :{ seΔZS+ؕ# sԷ̻Ni"Ϊhʺą Z[׍Bs% 5T ?|\UOzmЍ Q94{WкT>+$ΉqC*ѾMYMYn1:ir43TS>9H~) وO3+k+ӴԾζ櫏W:ʔ~!czLh-0 YXy;VVWb8LZk`ͯȧl\K>'9h l/>3 5 ꟒hH2f16<*q/~=7gp@!ZG+G]\O3}S.yh[bzޓwMtǮ:`Lt|^^Nn3}w[%UL}X^g8vtkL"`0|0 ?4FaYl`^l=^7܅COqy"% ICl&; w{?pd @K6MEN ˂O[kA9˛f561V ML0ثJa_5>$PXF}WE,s_] >-2#+B|)QS-hvs G fKK2/d^ڃ6gE_k5Z/^I0y|Y$ϏstIqgiۗܘ_)Np45D6^~Do.켃R-ᵆ,o.,rlRͥ؋Z1-j0=uhӉ{tIE7}4-%2K|lT!CeoPFBe"]ߩI˅d8Z:7\w[nP>Zm1!~O)l{p@|oߜa IN y-̕ 49"dRԿRMςA%h۞b?<@}AsY0tom*tlaQ^fkH28^3>T8cxwԶ#n1 h<ӐI "e4kXTd Hj dj!*> HD={ x2?뗻IwY~]DCF#/Ga^Rɸ!si 3`+S'cUJhe:lkǐa2qh}zIAxfҧo%F͎uc4QZw& -1x{6q D}];Wpύ}f<4hA+]Xaq?F(rynx,݅y$] qHG"*9 : np2gºv, K/Z v)`GޯiCX.bѱ_{ 9'|5qmr8xd7HaO9 ]<8.&sF@eнGIrr`[zI$n`of1m˚o9*dݧ\B{E',[y+f aK U`^Kw[*Sz{Kfŧ{r\Wl~zrp8k=ZeǍe%QpYguxp 5ÿ[+^jLNGmF1_+0;i_!UۑuBB)Jޜ{ sɣ>tD,z#.h~Ӣs=0'f%al'dDTWJ^ 57o>kϺiߴ@,oZw\@́Y,X#S22:W\˅ЈR,e*5EG;a)vx ֳI{MXjj.z\|%AEVG֜?v2z;% t&Q`1g/b6R p10,,Řb(l#ʫn'tpYa=UzǞX$ǰ&CLW)Ξ;T  8Ecp-G d5̄VYn4WQ܈ -]٧xh6U=/NA4\8\zZ#I<)V!DєYX 03owW<+Aq#b XB c W\ Lo*ֲr|!O"Hu2b6mcj)flݙXY1rUp#VPD_H0, %NKQmņO&/\f;̤J-&KMUr:F`'/eyu_ߒiOn1Tx3i vVoԷ3 . u$ȧD:)qyhc 52[ ˼ȁ,pAԁ+m`tKˀJE!.kb?}'..|ei*HFZox ༐ le:8R^* l~ s~`GRF\qvW '* eۇQsxq&D\ ;V,Ѷ=RGMZ$c\ 9= ,& ohwKUl-PV:(]N\ᑀR-\<:Da!HV SkgO+P5'??6ԥ>$ `^/EL:*dgu%w`(lBF|+FL}KcS4q:,sThҊ` x}5̺'0xw{W`77~` h[Z% 2k럘]o6Cdkw%x$%+I[Mc"j`_g<;i V` V4pf+k]m9wFF^޶ߙ[5o p8"%P#Ec7X..߄=_V\[OzZ➭gwYW3[/i@6Je4SM," _|mSn9N Q͆Nt!l/[Nt˺>ggQ 8foC ${Ծ䯛P S͹Gn JeZ!b~ȍvꑹi@.OQ'ScNC! ɼT_jK²x9Qr"قǴYN,2joBV*L,~}|w-**QmXyߟ ItہP*+lby7.:;Rޯ3W+k478Bt |nR+?H]XY3׸y<;_^*кSI|"ICx3_ I%j"J~B *R{ʷV6* ` ^ TxB> $':-R(M\qVuJKO7$W5RdBfG閭9oG5Q|d¬bb34D5c *RƺN1v M3qьxpFgcвn ˓HZ./D۵Э È?`);oh33`B&R.Hۀ)/JGNV XdWR)>ۙsȸA^7˚'&bT* O[ٹGM\Hgs. n{F|0BX>)\Q; 3 t@/P y_w\#-4ge.50i~oqFw(f!qu]]y[ewm՘v|wh4SVE4! ;$yUn%Y[u&?]i-R4V\Iy np՟Gb|%mmṁb+k" ~<.'}ok@NX->JsV5|`m͍!F.]' FHUO痋=k iPcD4`i9W"9/ÒNg:=CI!H w`FCZms נ<_ҧgn:Zd fkY)X#ch EZѱ-aF;*1h|^tPle]DKY%7:wD)L M4jJ/Ml;"Zc |-/mvjTN1d(  lKګA 3pi;<.ҥsGZTT#h'И#_)T)׬e`T r-($^m (>dnLғxXiIhTEhV ] G\øc'Ѩ[C%X=>M)8Izxp<)}碘>V Eg@p"rRAŽ˝skRzn {Aieu'oI7oy}L7Og =09m[:m\9u z7_S[ƝR-f= q\pcݻ]UG;AJ/y|XN@i"  #MW48jVSLjw.b>„5=2n{??O1ɝuXKf=F5Ge0G]?53XD1(O:blTRVds!ao81Er%lF2ke.B#DT&߀٤-`ˁ]wF@4=(p*#&eh9qT2xCݾA>$w?m3bF|D""OJ): "mq$޸wLg=Sb&'A&>ASt|<4K|Oe@!"!&AQ=M6%H|јЧ~6MA[O4i? _^U 9^\wA9Rqy_uq#i|pPPyeGwt%Hm# Cek[ 5+*w6@ $rxS9'TPWw},]$5C\=JU'ݪ_ :FV:'od?L)Ln}Qua5<4*V"S {[VB+9g (xr%~MI9WW*49M(Wc2"W5%=~Rlz.Gm|\+y,eH(=%n K_Akp8酿:;xǢkpE,sMAlD#{Wfh8W,]=.[]h Citt vwg P:CiN%DmݥÚZ4 Ao&Ir_U3yiߝYiI-:fh_  "v_UI<)skǢv0ڬ5 b:cs+ Bna<&O{+ebDOVI e2Xxyh,Q󡼀"H@nrC;ܔSU׃WmJwwZJ{|.W L+M/ EV䴗}= zM6둉ZA d.1Z >׎"༟秣-9ghrD')R3%qRy]ț`/1IO+pC?.'g:S#(>Eg2_F1@R+%Inҏ)2ZGUZ^*pdfm@\zC[10j44lFluAJl/bdα@LUuw߰2~#o\-l.ik"YW~b ; @esbR<,YP5Ri#;>!վ 'd9.1)s1e޷4 e,. x"DjO\tCqA^:h;VzH[a٧ã1hF&{[O(* h ߙQ_)-YUP}L}p_( ^yCJVtBwb"f Wt,e79K\^M銧} e#G*0qM!8u);&PUZQmS擓lrHQI,z$5=^P=AΪO-R16kL=qPcw: O&wjT٨?8YY6)yh$hEɡl _ ;oYO74)̯wMG(fHPģ ^Sa?BK5~w^4<́;B+Eݐ6Z:@4Ry uh}-Ѣ~6$;EԨ6+&30%rE!=.#QΗ)fv=Y^*^[b/9繃YL3z2o*9K5{7ue_ 㮋϶'vggͳ`#|?y FOQt5Q ^۱ɕmDeQ%,]h6Uh( sQr]uBUG5@˓DY q挵3y{;J U 1U1q-UM}dpS@ag%|9ik. e"kƒ4M+*r7&S$^Kc%!6|fHnɲ'$Hۡ&YeH'1;h«p%)3Juv:o^M+d!7l oV ^d_ۍ:@b +^y`XC T -@pK'&C7xd'X8@?flb q)L ]IQe:݂Յb؏O^2}5M3~6tXU:6[zg#oNuŌjgD\k4`*i5~IK&l!FoF.W9qXP5Ho8'MBtr?>dbɑ q; ҤqHzFxu:xIǕ/# puԈU-|7z8`X1hTuƼ8~"%=t{1mO2C SOWOTNeR|~a/ׄζ4w!.ܛrNc$4 CgQ7 L# Ku`]9U85҈YT.0<5vz1в,m@AKMR!uŬ+dlbt!>Q^'QIx%2 q ''My n:zQ~Dgl9Qn]Ej]'ct27'rmZ8pVɾvNi>o~SܻBБܫDw4jкAh,2kPaV\>}7 d$/ҿMQm$Dr"X߾LTu+/l1 1 dD<3➟t gߩ F -c +ПWgx!ozsz n~ RzN~[3;U|/Ș8ՙ"KWdaֹ 2Eoq3LSY8 `% Ԁ&Wg>eW nZ*e%:<"=@&cI4vKaʟuD0 ?>Wm5)P H(vp6F?KTrxs(&é*0vXkPa? U]1&0 ,v@*7;H$;O? &5Jp%iӔuh(n~9+i MF{O7 K5hJ%8{Q:H~NPz[ 7esb3K CY( pX" F}aR#׺b4l 3`EƱJHvnD:J%\t?GZG;1W?>Uٟy.1tWc]k"2Cd_ES\w4m]{п>DMV_cNZ(WRw pZƒ\9g;ZΓ?>N<81I]@hQ b\,޹;Q18KB5;x%&xq>b^$<T b!ለC~sW;%}/[ z帼O(]mm]=.Ҽ9Hw3yf˰@p\_")ȽhKVfaf%*QxO(rW&Nmۡ´=.g2SHƌƸ(>KMH_ٳ~d ~ O^`}r%B$Dp?y\Sgu'5cQG 6DS`GSlYcjqayxlQ(o$8*#Ch*0{rOD)a=/g<@L1TlBj84kah2ba\.tiBYV+;dmf@V&ц@=0Rouױ Zq&zPu7W;F掯 `{qMRsWzXLaRktFqj$D=$!&n=f; yyfCd>MMH;~% bXTP!~6bq>tܟ}–_m5‹̡<ƥoE:@'?]QX#'id}+/70myib_֞$vx i_%m =j s+-Bsx˲0E93C6&y"=Q(.;ha{S师0Bn~? q0e:-uHOFy ,_)1D6`@ X8OqBN\J>7v pܾsʦwQD؅pL.(Ȅsq A$'e[ ۶3(X1ڱ7QЃG~uଉMb.ILf3 qk۷F$(L !T.7Eڌ7i+1 6"{AKy BYQр[ޱja] 겣zQ_B* :+ VקU{fKxOFuAτ֢^<) L} CԆ[pw&wo|)}p! Yg;JO[פqN:W>8HNڇfD:֠EKXp1sTT4k%GΘGN= mp! c[2}3D)S`쯨}8umTc%å} wJA|6 (*OK`ַߕ|Z[)<հ` ,91/m0SÝ$@y`hmݘՙQbzcPGe7[\ayeݣp_K^/wr'zG [s)' cTj" Mm PDe9zY16}dQ֖N2Ҏ {_]lFٵ =AbvQ6|/=IRW\34E?ITFIꂦuI(`K vo1 a&,AWOs]W\̱6k ޲GiNU dKx yBbSzrȽ: )6*GN;>¢]7UuXo5nm'L {7 (C%6Qsvc6mkpD~!:Ms O JJ⹞^b17'9oi'(% J0 uW$>0@0w2W3]ޖK;kn$E$ੵ10ָ:+mV:m$}ٰSӞ9]$(@ Q"tnE?s0UR~h\>ea1  cՒdaW@v% $5]؟jl}.kyzv&)oC> N eZr8r|CWlYfkjvӢ)6&#I^m)\(Wld,Tt'4{e^*s:§kъ%H,n-/741>ripA'|C K5 WU+NFf %QDlY >XDCNrz03g KWiIڴpƧ'%8{@4M; ͱH*d'+Hn ļz@vBƑ +U~ a-6xh* n>M{4ׄ Wxz ^Xk l3(t;b /r–&)_')0s; ǀ7yD-K3}(b*l3d-e*U"O~x=@~h-W/C Y=MHx8$Fne/.$Yev5,^؀1_Lͼ+N_!%88'l13sJ$I|?8Fn& T!Ԙ6~Ej|v?-|9Hv\ш *5JsԻQ#B;mD#የ/ݮ\:uwmʾmҎs$^[Q8ރⲐ{NEumE|$n|칲q<ہTC+6$0[o\d܇ }Ff'{v ǵ%E PPmO4E>\}iz$vT <<岝-.s<aiP]\mu!y_ R6?4gp/X2 {lzla?Zf"?^ww6@\1mE]Tt,PvSCg]0PPnW9pbs L&N2sF?Nw p__Wkā@3oD>e7&GE^fޠ@b)ˬkK8?:@lQ|dʇ//ƞJraP/T]*XWS~0EF^`æ}VԆ fjt̟D!x'.֡]H鴡69fɉ= / lUd`{htn&?1ٮnvi1bҢrvȻojܘ<Ʉlfz7pK,E- A~Sv=Zr ˲b2{܅TB\ v(W㟐D Etgzd0k5\mS2ݠj*&RK]hA_Z29\[zqFG waF/"o+c;b }I-`̽~6aJRL b("8Ju?(]d Zݚ{\ |}ԖC LC bƪL9"O)|Im\iC4x rP)K%Ȗ Xdx\,H%XҪ" ӝ߰KZWuy=6 N_|1 ONyO?tϘW2{m]Y3Gm:C6sӚ#%U(UugU7cEoD{/f̜"dY 7gUxsc~ۭT H."[t%Qs$v[k21R;fY5/@yt^6Y1 V0ؚ,Eʮ?/O!Nu*cOˍ8VҮ *od"aK9T7v2 ѯbk}%衭 ]&}Oz@g+J72iC՘*gc=]O?!]æGJ_g^ï4t՟h WN$k̭U`';<2`3fJA4:n)/5X :z&pBBekS|frs:UpwaMDeR]NBNr:VNlQ?' /2r]CcjD^K[,zSh6 qzFo^Hs约#Z!S'h/7T,trY^vb}MӶ_OJo&e{(6 CZ?ӏtѯ*̰j(Vʒ@U$1fQبp@q; +@ǦMAŌ!A2}_φS! J#Ӷء$ 6%pV8Č:KbU 1;N\Yt \`R zXb)1S: IaJ/WZ H"=v{ qԁl!ո/"!cmP`yűVC|)ݢb)A3/"}>}(CBB}x? `.x ,^I7 zqʼp1,f{4UI쮔TS?w]άdeuDO Ȼj]E']k~֪Dnf+AGvb:8j~v}%{h$ECtv徟C-fc6a84V4F,TBlZ9f5C&0lJ⎥`?N|%#`}WW+A^l5)?Ǐ \/ތ] AjyBPG]6 ;ުΣz #7Թ-kr2e$|VZ =hH* k޺Y3?=3ޤj2# Y `[`e&kۏfyV^l5\Ks{Tr;Exbs 5 ^Wf̉,m&ʇ)Op2$JXe#ɵTfR6q' kȀ8&3u4P!979L{X(;R}l"y$0#Dx=qjўeO[:R>``3IʰV *M$a|RBv4( J`QڎK>5OAWofu0 V,-ɚDH`Kf0tMטqs/ bP髗R4˽BVɓs[A;:h^NH,VFV,).et`S6h^KbG`|rih .c>Lٗ9`k U6=؂m3G݉Y9ۣ^\ns*($Rnܚ2F"[QrBG>UL5P{Wq<6 w73Kӧ& i߈/?}^YvhfB5f9ͨu;`E Yp)+9 =E@&ݠz=Hwo`2]!˱+D:H3A) UV2 M%ih95]3 >X¾bIġ֛J](|DÄ'D~ST^-|/YMDY4nֺS 3)ZwE'^^#:wT=" cFBj_贗_;/z.pu=2T fxUTFIb?nZ9({7$~>vKOPUDŽcP$s B yzVah]DN*%h'@s+#xAB ?ՆFm q9GB+(߸·-\ڴ LZ0́"p98Rש{\]uӸlrɸSD,T'ZhnH[FpҕJ %z!667 P=7uvJ1$T$! 24 Г: 1=Wg.C.2c$6-QPX JPƁW /"8pŧА#?ydqcRQRn!ۙT0S8WYO($ho[ ~C|5F#ǁІ|HT)$! /Z:wW.R |9^6d(k{IZ:f/۶lDѶrpˇ2t#< yWE4y a$8056- s^!R οtN*Gfd[XF0T&'&'odD bŨRh`O+!cu <7`T., bfBɲ%%mj,mssdYN"Z%Ii,@@#gOR8]S،"Ѿ_:KQD~:JdqJa'8)"4٨i#/$<:E~T2 +8Gn]:Uo?s{c( k@\H5Fׇ0ݬDBSfU`ؕ'vؙ1@g0&w#ޒ<ʔ9P#?'Bg&9.z!1[p"HmKғ/i pRm!U O tTk#42%-)֞A#t;Bn ZRj.kʫ>״)#IŹjY,paΡh@xF 186J\A, F7W*Ue(:p Ce!@Q:pJ7bHej޶R3oˈk& T&L+(>7((O"Ag +=[_a9A,n)q({췸^:)bC'ЈU/0΃RX"IlɨCX}/ƃZC*XDއp8TR-45㵞3$X(b $H#Ǚx tl?i%W衝@ r9Lk1 x^f2{9QLbϩD+yw͟VFLɄ77LPs]M2ԅ2- K`^rmzTDhz2bjq5`D^~b>p">0O㱮wK(Zn /v4ʫS.-T?͔L:\k*\p&cPT>4&'Po)8&JNÓH.i6hnW?DDhi}u|}))>mPAeF !uGv#@ot\tܺO]S hd_?"H_+l}.qiTw~Ie54@vkNHUhxNex!sg. V,J)+9E@9 DgG&qW}`$a$1?Ry 'WGJ?%N{җA'=z0/#8a-arFDΩZF8 >åP5|zE}أ ,!WfCy!Q._Ҩ2v} MW~1ۈu9=p$#ވ>@vx72ɶ`u~evE.y ݿ[Ӑ cq?hBHs$뿵bړ QA$RU̿9ug1DUdfk& 5 q1Uu>_T:HGM$Vt(-CNU`7 \2 #>"%}:'7߀x썺%gZeJ0 jv:tfۢBk2mA47Cٖ\'by1DPBt,8r!JN8Otm1r:6ӘԺ@d֎>-kCg|nq3uq*O\zTGDq[G<+^nx qL^Fqr`>eu;9Щ=T#+ګJ!iè].+ױV3r:9 OW+I6FuF,"Ip|*:yb!L 1xE*ÛvrB$d<G֘"hq%,$ Ѐu|Tc9_KiJyM;an44NxMeiY!'W:nuǏ\jrm˥Ӟ*Bŗqx{s*aO0p]dbqFJUL`S'ZH*42мRB^yLG~xU"q:Sm 2x4LԡoS)b>6֌B@ܓτ{GEus t$& W~Mfz T 6du@D(=YnܘbAsNcbP"]n̂6 L @~:UzH. ?C D\J{< 8L|O3XaIm1JTjqy*!?\&cs)˕1Dj5rA-ќ-P, #h$1:w|@ ;+pm?2L/ K%RҰnhkEo?i\1&]:E J؅@!tRDvu5{QPɒ]"x/lSPՇ18yc0ػ]-ӓěI݃~뫙`yA^F&X@wrPϮd̼K_0v-~?i8_ҔŞuWi:kHEew[I\x^7 fih79T%f=]j~Mw(ɞFdR*{a]np~EF!IS)B}oL M ,!{S tE<ad={`ykHtoMkvlL>:rA|7mS@q+fQ$0 'T0 0k߰GTC moWП z]3 Udʼnjέ\FkA´y5eDMϳ1>[>J%C(:V/^(YkCZزHB?3v7vST%4gTMPsUf|Qtbݤ Ö߻ц qF~of넗<JP8¾3M}К.":Y·ٺwm}{ #v,`U츭(ڽ@&iZ;8BB8½B]- &pTyl"`,=_XgyP6cSŦBE`s;)@1ŜRrМq#>B4 졢|Q ":ܺ׆PFcG 0J`9T ~`P))?e@l"v7X }RWuA7oJzJz4|nBVЇhGGZ,CRx(کrŹF7nսCjs >ڇ*- yG= ~4oQ:m%o^9TfcE_;l0D OI?D[2~BtH%?B\l="BY8gkC0΄Y2C.p`Kx)v%mTwCv1uQXQ BIBrYFWEyb9 x־lQAЎx=m&st|+)ph}{mz|;wş5yY y v:2Nf-J`AR(0翼zڼV4肎*',SPqBw,%pv YdM`_hۆ'Z0|,t8V|pBe9Y1,`P F}5ΡIb?.M6.+|(e*cz>o)@ZNj"Jy{] ^ª lʨH#_MxH,Ie^ c"5}v_lnsI tAW9op,^??iEC6щخ8/Rϋ} bKyyHS?쪁C!H[Ā pC baL*n4v+UK7.VZQ{~:IM0)_謙\"xߨϧ1֙b_P +,'J7mqW9`lCN-`=D\.r>jQ/3 .2`V5[/3E5fOzhHX}\vzB׍k*j]9z28#['}6r`O.뇧g⠷wnӰ}KzINj؞8u7~]Y&dތ5NK$u%Lb:jf A*2OQzn `ac) 2.5~z8j;v,o-':3z"Tr?#;uG3~.)(eH}Vv:\2=>,9:w.")rlv'c<6}ݙb=\%m7G'Dߣ08U &+--L {ԝbF.pH΢ 2~ڃ $x6OKk-a*˯\0e,hxyJL +-`lܶU7SXU›cV*Pbu?}[*U|u(Ї#{70 J#ad(RP_Y9F8g+ a~+Ҽk|y"BB<ϝa:S(KބW9=(`= 53ie`)A$SXsr{j됼%= 0{Gmo/na5 ڋ98,İVTq~Үm)ΓQ5P_{Lv5u/A:h9n}[,bYT .=ŢNH__l~%K)YZ i _\J@/w{x5d]M5P+/*;6\r?Wި\巶eƸ@s\TW'[ SN3 6]$zJt/Ƴaذm]FkD~Z6~βNk&Da8щnHZfq\ւ\c^Bfd# N־`-h_k3E7J$d׀=WT@Su[=l>bU8u%5)sB\:qH 1_9gTfy9͛d8k  FsUbE؝KoSdbe.0ꥶ|IPK)a}i}9a>r<ʉ5>8sɒ/j@#8 ڧDHHkb8Ȩ558ZҼvC`.]J3_cҡ)vo"j]r^@fZZBCn᪦rNsT0xSMQ#'LTv}HmmLRi[({e{t$\tw>; J H_(t^gћ_D(=z-~]ܩq[.Q2k4g\a/Q8}9p99@Į,z|穖~zyG6Oj?D ِJfƓQ zٲ90˅NC>;Jft:= 0bCS m=ZDiPЇ*>Fgma;?arnBXS!SKZOx]#vFYѥ1fm_O2]SQ xou)4IoHyeT?e٩z#TEڴ=D5wєw$vP6 qH~Z"dzB^A2qqdk4S-gyB8Դδf-!%=Nr55!i|38:Ev&5B?U$d~(*:iYnC*L9qR0$~*.]Y6_R@v$o鞥^fsЅSH@+v) bYڣ]!sW3(FO?f|4Qxczxj+ݽ!<m֕%5UGp#p_h#AGE]@}J־c8H3$ T ť͛(ϔp~GlQ0pGB%AF?MILU ,R{m<옝z/%Z}Vf]onW T$kХUB`*^aYP:3T_i<(98-L[, ?Yj4lwq&^W]jF=!3:hۿ!` eg:u)*>3MA oa\򈾆Fv5֦Btl|?\O*a ')|#"4\< GY}ۘG1uZ ‡*WC fc?&D'T un>yIo8꧷ϐ #?X|: En THrc7'6ٳ_%!A"!+[hػ6-3.$"AeT?:M.^{X?0$aTzzM2O"ZZ 9KgܞF8b.:QAZ܄D^0^C^L~|$t0ZsK(_}YKAFⲃDԱmw8n:mxASպ9MFǙ+Wx f$ ť+k֜ g7"둌m+TW>~ 6y 6%[.?ͣѷLzJ>ΒlsiDGA~FDsp5ތK8GC;)8EFoL(|{#iݡk BS5U(W/cNpCg_]ⴏ$WvaEfvA:;@mج[D nD0ι( 0 y &>7ڴx>u%q﫟>pKa`X5oڧ;<\/ kߛ/a⃷UC#o5'S=O@u.pxCCTeGWdHZH5HK_lf5-fHSb g{r蠁9_ZO͂hМ07=ܙYDurj[eޜ<1$Z%kmd3k##,JZ11imSu{𤩗V)0 "H{sl>/CЄۛ* G*óGC/ɮI K>*`|d(cIF$Y fTL%\Pvԟo!)}=CQ{韅sFK3Y X@^dKdC_(ciB/x坺1Kx|73|~ѱ3dέq ʌ-хGS]Y?7&% m~m̮WTjҘ)ș%nVlD1Z:2~1vѥ %կ0c(WM} mskCtZ:ؔG#)G؎na.)<4yNJD!V )^*qB֋>ZjUX¦ځL-IkG"$[S(Tr7@Pήp<, /lib~]nLG,n͏_I!8TFH1sQ9O™ʬzpĠq(*<<.2\52D}L,%3o*GZ`ȅ5a]~WWs*U)hjVU ~Nl -0' ]݌(z밻*9I-2J /7y:pEՆꉝR+saW䡤Rzed75h$Jߓ3AXָ2LI 뵲;QomB;` {;<#=idu&)?L_ '@1(@:肤$& 2FDWdQd[5գkiid3XzwD`PQ8v[d7?Np}6q%dLMbI6wefK w76Yx*9"I{6WOdd!器ZhUIO"UQN~c/,3#Wԋ:HGfD<$o8T3g[SO-@Qr$,wzMlpH ʨOQa a.d\J*B (\\XC+3}C1'\Nnl+8觖]tClS$EM yuEceV&®@[`*v4f9g|K]Rd!2?$ ksϿԬJEW.q>_,|,؏p*3ae~'% ^oi,tõ |b(HQ`M$gc7F $؇5Lʵ~Wn<5zˏhAqv#v+q=p$~[ (X]Z ;'`.Kw_9f} 6v atT}^Ckή(ؖ|FLQv{ '<%TpƑNIuIZ!)~F0!}  Q_ @ưK {*Nh#?PvG6gueʖd|2ߗ %l) ҠH &_IiV]+ @;^8X+S۷i$%z wpl ^QXl lPh/VKl%2PNΐz 6jGJqɆ) sf$0b8s'_SRKʁ _ sZM^F2Gi]ĢĔuuMZ $c?Y("5v R`~ݠUqGFRZhѮL0\KXr+:IcKfx[l }JqFҒe^iQ8rP&pf2Zl8%! >JIog~/ *3H ENr>v ̈́.]3Ը ?XP2ػ\g:ұ_422(0ɣ k(74ET L='}^tVR Y^뎋KH-;%d(խCVX@s瑶Iɜ{~cL#'9~H?\Cq"܏[5BBN^UhM:1=]1~zJ4Y>cہjhEm%*_&3!0C0?ynEͫns9%[sR7 &4qQQluqlg | H.mS•̛$QX($Of~r)eVa.dn?^k(?2V 03Ea:1;3kC"7U!y!Y^~!hTF;6̦xAV;V96WBF@ZF{U|C iѠii$)]  Na̧,憋LXJSvJ.TD.&ʓț*cԼEop*Ey־S\ |3׻ L7iE J؃7i@$`3e0V܇|EmvS M̢|xPdZ7[oR#WinMqePE'{>Xd9`VƷmɨ+yRY ,=^rXg)K#M@>u4@Hr.l,l.ĩ NSAjפa0W#cP!KtdK0*&LjP1[ D΋ |W I; bul_9`%}7 'Eu+;)ax}q&UݭLZ|m*W%' HUa*pWyEYGB11Vg@J*F)~0Bq)_R?vswV8Y~E%ų0x,]^FV+m %ޢ~ʜ\gzv߽ByPob淳Ze71ێ&$hv*9Gkӵp<\2u2zW?"1%Ȣ塓SN=n+Q|b6ŝt5oMGj^4jkD΢\Ń?%RuV`9"PA_.guߘ7f}&2CeL;&PB4eT!r9W,".A0z1PͿ0RlƏ y' ֱpǼ.:3_bM p6n; QüO;/JJJq7quOzQ0z`M`Sw]H@Qo] cn8^o^C96}Y1F%IKDj’my>F7EyǕoƲTSa, 1tnn0:hryk Bq G3wÿ41m0bIe )^OfB/2@;_][ b$|Or;tׅxD.Ag:R*l[ʾ1`NuϠ+*W*6/]Ū^WBT߳VhjON0Ehd -C:'v6bּTv@x;.gڻjSkV.ֲ+O@S ^3>\{ƫ:Oq+4YMvAC4?$:dk( }_JmoV҆ڿwgyf~+ijt6<_`@3rgX p4ZGKH܉2=8E]{jj/9e7y[Żp(3޹-.Boմ;o;N4tz1VUwB6ʋ(~\ ק- vN\T<^(1b=µ.5vd䟅K/8cMZ*v .N};iS0Xm dT@h0'st[ ZjDv]WlQZvb1@9ń$5DDʦ;)/zKlL& >(~o²vl h:0WL3B sGBbuq$0ZS09r3$ap?$4}n8#Og{/F)U9mmIGB7%MϺ0Y3@yR05b:bchƉW$;JUfv)Q_|1~\]Ϫw.{d:f ?^/4ˏa ( Cw\(A $_BW>U17wD8Ҹҽy=2'J/4H}w-)ҙZ))/ywdO8 0f%h]6er Zq=\ gך+ z!hA/jYzP:ht@1߷ʩ[dJo.^RE-Ѽ# ™|RAُ,૚'n}ZJ-(LSI2 9 n7Ha!nP&,W`6ҧ{"-H4"aڕ995\_$03uteژkF/t.TeP~t;nA{LCq&7[``4Q䰴@B~5o0Z~)RdT!-1KU2)7u"y pZg$ِ\g‡5=Tܾ"BFDPΠn+984IJf*b)*ܘuLceWY5ؖ҄BI^m[E3i7 8^vׯ#TϡQjӳSgg5x )PGȶx%%"V3X`~Hlh5ғ"-Ғxn/?\Rt*5Ȳd+ym{ꢻ&<t}q/zBޜ'L.-𩗲و,ϕJ=qby\*W;9Bx .bHUC? I_?Q$etwa3!^*e{H@I63btuQ?i-j^9g\WEz#+9fT=Dbs{=1,, k\,,M]S(fx5ґntS;=8 +YYUp)X̠TljE)5^@w[&AHɃ:/OAQ|H[k4F7p[a0SnF$P{8E. Iz--yT"cFNZ 7¹c-j@Wg9yb ugDO3}sMC_J(u<5Hb9 4=>ʧy0 w@w0K-Ōrɠ(̜ih;-Wz#0i5B^ؠW}ve Tz0}r?9R>K`?xEE$AYH?jiߤ\f\#`R =RV F~`#j§ yraTUU{ȂYYc[N(_< fi/% b;vո W fUS7 L:[ث`ӻ mA{ŗmf87+%kЪ| p\N,#}sZ+k`OikƩm -Dѹҷ#]u-Ӛ{+ѱE(\P ߇iO'yAYaaԳw41p v3aC$RHd`<`geb-@͉4̔,ڊxYu@.*7CmO[~֣VlHϐ ctl@Ub6?{e g(ε_HL ƶH9ɬ47_MH;sM?cNV4e(ű-)pb P#"B@D0y b"? ʑy1qWĢ'}:g~ L@ (<:UZݬk„d*IHF68mm9F҂ B,-W>)ávONJUkJHD D+5 Ww[ǶLQ rFXEEѲxd!Z@@`]atvR$#n><KQ*$h7~WΔ`MYojcp"XLjܭ{Ub3,@W߽8-ϏLYw/'諓9X]4RxS_ypρD~  \ֻJ,蝻 nh |1ȾqN/WI\!WI\P +~҂ 5P!v}F2xa bwIFqXfM ז@9qRF0 /O #@siZ:-p"zޜ}!FMzx"EN|ƷϠŶsVB}]ڡմ1an]򬜞i*̦O _h~ I,a]Rӡ=R/,kGbl*Fa]%7_k57k&í]ч \>q//'^<@mA+z ᨍ) M{ zu!uhs-A v+X2zV!\rVn6=gkVF"e "t27 #_Y [NPCc.Xy$Sd"3$`15aƓ@R<|MUn-,r\AM?\Ϡ`  `/txg5\}}׉?Ȼu EB}Lb[-0aDB 0<>2"ESꇳQ䟩0f> ԧ9߿*cɐ%V4HR"8D_\ &cYqC_{Xj]./"%%V䶥PG-:2 .ٳ?fUtoLq(xl'VXH){^$V E2_.~9 ]ʀ5aYS-S6hN_%%2j> ˸B9-RnTc_O%tUvsmtr, ^!ܩB+$zgnb#:Abv >!Z>^>h5?݁KaNޱ,s4I+R[Ga"^w,{ձF0?2g.uv~3jrRY%z %?=&Q/4<6 pՕb6R\>3k|vwv\!dPҒe2dVa† ᔢ *tT4n:MMpUjY+!hcՄ׻ɋWBxA-'L=:vdM0~Yu}*i?XI9NuK{'}5ÒT(6fSqepoGw {Tu IF]N!?J@ zi4cx'#u֚sqAI#I^On)K%WV*|LV 6&YܖG\%W?c ?_+]!nywVFO_șŘŴ:lpֈ\*O !k+ܝzE*r? S| hճUUsHʺ0}pD \u=0OsVFC˓ĚLWAR)ZXUR`  $_B(SY{[%H#x !O6'|M +k@yCGt`1A/Y~0^#T67sӇt!%gd聢Yad82*y*K #\M-<ρwW-/E04U,jJ~C&iAn4\4oQ @qǕd}\Z\2,_4g65nVB EgA^ ^ $`8 @Sl]U'Ԗ"M0u /=E $՜āWhGQcL2o#&o"[S"- "wtkˏpM;)Vej!ע)/DqFD}9hOeiUl^ԯYܣnI{@%mɋv Ьm"Ҿ2srQ?n Fj*7x_AOݳ!} P 4{q ?(Scv[C$+fnƖHQ` s'ۣ^;X )#5rƓ5'6I~&n,bvPu(q=}t@*+/h\$|H@S< xTa/܇ $#AmNѱ `#Q_``~baOr}}~jusk?'fr9h`΍.j3ȝϱ$NA_ht5qѕ, WLZ{иPbsE7 ׋ +oD*=՗/}tL:p1'z&U!ǣFOZlr>ʳӬK J@1%ܖyVV|78NpJݝ6!)-1TYR--B[.L.p'rm@p&b @ih%sQ,"j@@O)cauŬX7.QtVjnVvA7yt@O'X$7*FFqMIJȇT T2X'}/CQ~Eh >Zܗgr<@8ӥZ4VW; qUtd+ۓ?/۟d#\u5ߠ|ƙs Ol"`:tb}xTB:Y]_kX#ql%л|zg0rjmGy޽8V"2|ŋ^Y$z3YK)s214}B.* 7TS -*M_6P9tY $,Ёq{juO*l`)R.nkmNQj،YFrR\sm~ GҏN u.fȖ7^A*L )NHPZv|#T>mbbxaoO~ 0Iv4XWY@ .EVihCD4@:cؾ0"B9&b{Aoe3+(=+g/`7n#7*҄qH.h涊Eܜ!f f[[f=]]ە B!!IC"weұn)Hc x ej?NZE?pcL HV:ԪGk"2R DC^9B6\3a&7#D*8 WKU.u d8'2h>#K Q\:1Q}hC,wdG:mb{?3juWN$c&SId.mM51Cfm 0it4#umkw pkԡhc@PV_= Y./0&K儐Y.JQfQkW(FLkRֈo("MI&OT@w;)qAɑ7nk~7AmSbTV5%ߛ/݀}KlmS懗Ұ:֤a?oS1dt\ZAY6q|9(c0ƭ@Kt)Qc+~CEy@ԩ+q;s96XxW>,E:}&kZI3IKbkԕfq:u8Ed8|cE*Kb.y}CTD%x _9cBqь\6}VGr< ~wI~pG5#o!",]X͖\I  b#Hr7ր<꺤u!rl9zx(@8s.zWk2c[F mH&h}cX2ŚG:%굩EH-hc_uċBj# pHdeJS\ZtӅ&3tV* Kc\|{0 ϣ 跼ښ[鬵@FsKADJAkO?H۠構ı#m6,D+bo4 8" لY `=.(Fnc3#:QO*yeҽ sm]_{RM#J0t]mF.C?(PEv8qP;tᱲ3F.DX3.< 0dfM5Bhd.ܬlinWzėpG3d%c z>^}t]/Ť1 sVZCk`18s;RÇalya-zqGԻYc;=S61Rսɲw.^5F$s s񵢦1!9X2< 8L<#d}xizo-4r&a.u8eQ7쏗T$bUW|; oF59 _jwj&DѾIF23|5A*h`RxQ:.wόȟO A ǎNj$bAR赯_Nj] cnLFK 8v,/6[?֠)k:sV6FzBû?25He:$UBXttGb77<u۷>M\%uJإǤAVyyi B}mlWȺn}0mp8Xo@an~fcPN;~p^+!;~H >K\"X"mcƉHw'̜A˄]{9LdKL] r(6]N j1.ꢡhx\=Tؽ;BtE"8ndQQTLjQeڵ"L-yאĜ f=Av,Riuf!g=¦Q#חO[/knjXpLDX:Vy!2 IiƹL{(YEkeMLiŲơk06QOC%]#p~tj,W,25d$EU,1Gtzžv屮j?O>z0 oS_Lwۏu53NAqPR e10;5iJtO.:ڻ!/FE@WxK/.48J +R%ဇI0ϭo[GhIMF M{bc)jbI_p^sU+aci@wTd/쑹ڋެ6 6"@WJP3&̩; ]y ,۹<R3q/3^0_y M9ķ*_ӊ sF$ PTqnYKbtY5g>MՍ bwءRږg %7)]r ـDS*nLT@][Gmrgӄz'a@|Űr0u,= -o[en ⛩;rcE_dDSh5ur9|ITxF̋Ճ-ϜᵈK,Z!:(`Z1*wD *TL:lT DP@w=κ0*l_a#k7󎚃J\ewxhȡHKgGq% /w2) !Gt0;^-N}Vl$/4-hLw̅3?aBwjwk3FS(N]mZĆ?_++,e~`x*PS ̞&iI"]F?5ӝȐcM׫SxJܹJ4[hښth:*fsPL3 $ڭ:;z3{jvCg uR`Ɍ`4ٔ,'\ \y[(~⨍6=$ZҥьT#$@|ϣUBqv<c[$p&&| A4Qp2a {<)7TsG7M?X1`,mN#X<HђȫU4J8 ɶIE"]^qJu\cL ||"x\zXsxp.Yt9xS݋*rmVz4:갯$V;,_z 7DZS kaށ-$\Qԩ}x>O lBVkwBAxt˥l]xyTs'y܁ˎKFZ[&hW[X_q?@rsen}Nc,F#oN6`{X~۱w"|S!ϧ~]p ۼ]j%Ȓ,{z ,G~Hi؏-һka7/~ _=;Z іZHJu0j14ŵDyb6޴̍KTφJCFX~{V[:r>>M B*-0Ly0nH._S[5}pI]y}C:i?4YH->t&;st#{4-O}`$P55kk1vk8GbG #BYd0ȚnPugOEa5/S]gU04nd$92uF4B| mCIk(,x\!^}AE՞]6a3m)n6{![ڙ 'm}U!|#|/l[/&\!B[ajWO r75 ĉ\<+U_KE5uijR~v@|'$fZyT 7iKdhwА81=S+l>@lcԟWЌhv[U([$a Б l+ v[Fd ݓJSR o'[X23 [n!79Ӡgrc_f.#ȁ @[cbiR)l&HGjy旺,CScwz>@ٖQieOF~;zjǞ}l ̫,pӍ1h$3|Su]0c/ÂAՁ\TJ(ϱ;О"c$JGzb(Hx\ ͋{˚'+m(4:gQu b`2b 郖S 1bDL| L_"&Cut&O6t67q!׫vQ7"|7Y{]υdȍ{ dۧ#}`?88)(z5Ei̶Ng:~$V G6sJ{lDD605U@q[N:pԅy{/ӵV|)8W#F<'q;Z\] '>CQr (kl\ A07&τTVW1l|;X+4ݻY4_xpb5P$}kpcm'oGr(WzKjbqd<0fw{?wH^+Q}< T5O5=T~X:| uh\8gVg[Wڞ̉JI䮖[ fK#}8OkP}yg[Ĩ)K⼜Oy0{M,x>˻v )?hN+,o_CE9ww .2$nͷx$0tglbTxتUj2Cr8bPq 2_)6*!QDbN>pfRmh^K mmx͘Ot,T$'c%̮V!刢8 {J'f%Q7`V] )*Otة<+Unc8ii&*Ⱥ\b&-(aSMI ׈wV%j*P/)&\E QŔ"dzoVp$օ+,r;>bȶuME?jZ4ߧ6`?WLwphC9ɲ Hv1uΧx@Z(|Zp63X۸`Q^~^H:Z5xd_1<dPz-=HBEo4pT)V6l>6IgA=96dBCZOmJwڀAO #HRe}/Å2~0]^…g]ц5Kj!-6P!UTAn q %ڣ9GH6 ߝw0KNe0Y&Å3 Z $×/,DP:mN. GȦO,E|.pܹΘHNpKLppSAuB|]ʳx/#?g$~j KLWRiS{7xt޽t)I<#Ej(b+ 8vҠjcpX}k'%3,X>>k$e2ƣΟV-cӴbK2}>LZ-f1 }gF2;YƯ<14mi];p:m3ҌL|E!Rۦ?{*$9@C(,;?EOfOrO+Jx灼LDgSYpꘐw\"ůrbVem1dA|Gdݮy"C蔿ewHG!Q Ǻr;IYa) .] " Rg(u I'kwx_i . qp{Ϛ^UЄ4՚CGzVlu#("%J"`bT. ] f#\h,~}|Ş}.d4,r9G0fR>xUx+$1k Eػ94XoZOqzdn PBȺ\$ J6Y| ^"Y׺m5k1u>5jm b<[/ 7+B@ӗ~CMV83΋,att qڬjg Ə-ܝyc;R3rt/`ÇKKaě2lQ*M=kPTdrA,}Q7˿.|(5PqBf(28z=^w鰢t6sXCzwEVqY s?C\KA)~Lͣ'k3iXЎc8+DLYjc]po0VXщaA5eB1F+ fGxQ*֜ *4qγ^KTT 5Z=P\ CxPKfKi\k'E(=cCa0~6i4cH- M!@ûtGvI*z  ~AkKuE&;T,r$ Lu_+_DVGaptTkD%QJM( lukZ uNTӏ9,epM>໙,ӲzRaDO48OsC|_֍H,@U(']NCK/|w>SN\J9ρ_eLn%zF?r`QN6-ICzmR `Ljk?rA0xa- b+:y|ok_jPe39N獩SaH%s鷱rδJiTL |x6᫽Z𣊉kwLǘǥPMĭxaD” 6Dk?W?y(W`T͇5S 5 p% 6P]ڀ{UvsFъ8]+P3r$s^ED5/19UDao?=‚.ˊ\v)m\FۭY~y=e=;k@$'>͈vC皔O ܷdU/{UDN>Lxodץ%6ǒ(_2!9Kہ#nly1&F c &W-F|e,qhZ8Es iqjJ.i1/Kne^z;6/'jeLmr>1\0ynq~GJ̛!#ƻ }u乌ܞo&i /9}gYll6[Y-n'bvܴnōRL 7ŎB|M>7{<("N4춴Ohq#_SceWķS.{`,[vc(!3{WYaRiV<43m؊ iFV2].QBqHsd@oe޳U'.ut0ʄ;/"òr18AP?p7:-D#lV+SN,VDi!0+:CjKxah,bCm R\{b2g|sP@8'A^,Y)4@ˆz"0„>5vJRԉrpF+S!s7'Q(df?{V= r{ 0#b>tCt##\ZΆK}UuA*Ntrp՞̨[z4(VEtA%C {~k#a)N+ }}۩J>{1x".$Y}lo#Xm<K^;;oU έ.9s/T>x_g;Uhx`+uUy4K%%ꦎp^P갮q1,T5Eׁ<;.VMNTRC<s6ip Y m2GHAf% 5c7}>vCߐv$p8Yе)uG\4= &Cc8ʻe&DZaBNEa΍#F4@j'847h9 L6Dmii)t@(Kd$X^Ip5ge3:E0Y|VY$CƖm:jF<]?ne ^׾tC;,: ͝n:`:kg{I>pIֈT%FH]P~jR8{HDPϯTyJP B#2}i$'KFԛ֘lS][\5Ni񕸭M$X}'Nma C gNڲ'AO,C I ;7nO:J_Iə2Rq酭š TL Ш&>j$UJD-Dێ;/&D26&bOJ5n@n:zc9gțOKP '2S\d*8Q6S15'j˛:sJ$|-A8n(<1Ʌ$.&Ӏ^ DJ"9z# <6Mv.LwI9NKk~E#Is%='Z&՚)//['l |o$rK C;7~ JZ1_&ʉbQ0zZȔZ!VZ>jFizؤR,+ڸki,%H?P9ZY0)-"qF5l>ru 4"Ҥ jCaK-gRIw֠{ 8VM0SepPl]:F"x6qWTRn2~d]B Z'*Mj]MaǰѲ@2y1'Ҽ^eV|mB}utwTϚ` 4t@f PccH#\mQYyZ:_Lge` Cq r@J˙seN@I)&ny$;> :c_5M,3M 7psv7ZξX:7GI25T;jbgF*#=.tw@zsziL/ yʓ#q&Jb#*mB}G~zF-r5j\P<%d%pt%l'3_"yxdǍstGI1^!8 ?:aw 2^&92RBd5iCJ>/`ٛ N?<8D3mƵjUʮWf)ſB2ƊC5($mUxPaC4[!X x7^Cu.3=?cD`;JR`θ4GSdHrۍ?`ౠ3X>mhBF8),z8 &=tjթes3`Kpq "7Lˇj3[%3L\UƹQ6B;C~^$9wr75.>c55(, $C {_A[r#&x[e=aff@>\ I=T]cEJlPym"$+kkWJsȤ_LvG!$'F|[pb"I]՞SjsJϪMs4T tiLɤ&B @9I|ڧiS5nx.F>|YqqBʬt_|JT_VDoi \`f獇QPT+Y骢^Jl(rZT״ _џ8[=i3gkMv`?|tE}2r"=vu;HkX1Mֵ}jU+r&B$UwlN8QAz#7R]#I -Hqd]ؗXRm%Y^Vw(=E#{kaZ>٩";*pi;`Xh;Mc"CNepiE A(#Nb,ix!mT&BCHUqc)LA+%6mHua.vpBIE)[:;9!»~JbmW6Ē\ :f/]CN`<[($]pdiEfy>sO`fl.A´+fo&0apH,1NjdnAo#:c]I&-.wQ6pT:uR*Z?^/l#fb*ւ2rnnZx(i4ݜHt5%  ATO;.x8!eC-Æx>*11ފCjgxGX~<@x7xXJ61VS_KbXv2X5 _7gZX7XHCn nGgġё\6?cjX٢Uԅd*[cnG rc#Pl'!IS1U热gkg%5Mu@@blGb!PTIT!9J&8E@f% I 3Oh{v=wa= U7:{ɥ^Ѭ3E毤;lWM_]6;{'&ۃ{ɟƯh}.ok w 4c}߃ ?M0jZ HmAW#31%+٪O̅<CVviEš޻j_,'Dq'S751$Jek( x.XX9oVX Di0^U7GzsXT-*E,$(:]ccz`x#Jn#p:"?pb7v`W^&AbӰib^ 4SA^q7ׇʴ m3H" N>*bsXWw!Y8 [/ oKǮ CMo ^fE=5M x yn_N 5,yK,F{rύ~ls0G]J\V'b]Mgr`N97& 㖟EݑY$f1i'Jjy$W ;B1력CߕYR@(/0 :њ1 D"y'$C;̄aֽ~"/Ϣ:X!<^Ʃ@HM<~9lbċ̚ ,WrΠڪU,)埿)˳p =1{i}Ah7/&W3]87SӟI{6,ęd ǯ.Y5JUP{kAknit)}!s'm8^>ĐbYgH 1vfp:+U荄 Ug62BR@;MLoǃdv7:~f'A0BNȳ|P+4 mOkRqc0Rׯk|NŖK>}#S xp֖1cy渿`͙XtS8_cMvgW?{M ܣ<טɺɪ:*ģO&T>ʧt K{Ь5w R M/ַy/_>>X&:֬:3Y 4ef)Q&gx*qD֨1ņ~Z-$T~iwNaXD7-pA2y0EV\h .$('Z;yTP}F gcf~xU%6F$!b: ܺjtvX% `qd;P r<}}yǃ+;+CϚ96p_.DZx_xsTwLICؒrt/tIOW)eayG;RL맧ǸͤP*dycc9G9}@.tuioq]!A?HwC/__xIt`p38s/!AB')B7gbXh_;.3`%JEl!X@u-e ;Ts16iXcS%hr#z|GSw|{3Obc>_G\7Rթ õB1m]$qkW niA,Sֶq#]>X_٢BEZiAjqmhg)bHQm"橕§  x?! .i˅}&%J"Q~CZ"Z]-~br)uĵy5SN.xcVE XVU[׈ *>Ug(7ɣT7͈arN4Uo ml] {)y2Y4s"\hԘ#uSOj,>SN^ΛUzxɠa7 {EH4F@v:EWamw5mc:E:w,LS|1Ĩ7K7;;~EZ*պj/wOAv>1,S͇VA} ?@i(u@w""$:XeҏfsPSK/a+V Lep:U*=7ڢC@u/~3;L䋽{zU؍.CVvZ)Vh!zH +pxQU\Jc2J-S:\i*NUIENG~Z|z\{=,A>}1neն@vc%-|&W.BdcuLZDbA2)y2K'Xt2UEUF7U%ҝMz"@ յ-+ g)A]K=$<1@^HwU%ȴJ-9ZNk3BRm4246;}y1Nu#mUxl= є+9Z`i_XQ&%y3CD>2%"^4O99qzi\6hBeg5419q?2m?^SꜨ%ޫNw^;oZ8?|p LON]; :El;G_nEtaFӅ^)ÊJ.La@Zn\Z='st8\,ĝfiҍb1Qcpkc5Tќ̜\jrM:A߷L6=FxE j#7% #Ø19s~*,z⳪/.ijܿ,-lg50^ E:JK|ٶMHadNY~A gJBL.>Itw8KN53`@aGZ3K,D6,egd1M&,PN?x5VLk:W4#/u0/e6~ ^AU_掩˔{"ySf'+a44W;_@kErd98B2{G1]ÉU )hA~2b0J@8׍|묲ת/ bb'i,heϞ:sZ!U ذk)պeunCiepu#hľe'ᱽaSc/#7f\tY܄ON"B,Ut]~n>P&ڑԧI:3l;mx{Tqj΋pʟE&e`fGyKxl ŝ*UCcg#[Ћ0YJ؅~`1i{zZrvRfEOϪXYlCM?oa@R ZE1a #pa~RczPb T5UnAzˊ'S;bYѸ+G}3">?BeOd^jiI)>NK(KtN_ %D 쓎bLU{VYy9셷 }Yps|WA8vA?wV"eח.q2¦s~?܈a}m(Mņ_%eJu])mYט fFEbX^B=B>3W"%kŰ(5(njT]-`C~M8Zi"@`>2zNreǾC-_LT7c)_96!"Ա)TX_ߒ7/ rῈ@^ #KK>#zq4Z=vmTn'<%|1F^(^L.Ns 5؂jzg"uSAe"Y(}.:a8"sfwocFM`RӸA'+mD}{47ZhS}#>M Lnsßf˨3u*V0&1*~VY/b$ YX牴h=`+H瓹c(5DCr}2ɅT$*̳h'ޏ么(e;Ex +ۜ˨PuPa{X[ab?[܀M48Z9B>;٫.iNuS\0Ilw1Ѧкi-tKCSbXu"+@W=ܐƱSwf)o}T*%qVJ㭀;W'u>4E97 K$rМA%SMF]F_"vM䗚 :ճvt4"][^/p-Kl=$Ķ+Bh'Iڇ3j)XςU |Ob>qxY%*0Ac \sX.Ok\NUC|)[j8zRvarW(:3^eR _VĿ5j2nV"`qԏì=Rx_ӓ偷5e@XԾA03hRW+3}ϗ؎5Ԇ@+d_o D(W)σ #+WG^eoua슌P╌gHo8{(6UE1}Yh8!; %P՝}MF:܍6[ >(xWAW&&tL 0w۴,u9Y^Pk Jvm٠V=uAik̻= wBu9A*PUJ3;X;X8ҲmQ` $KBq ֕Kvw#{s\5=w*C:Ӎ~BF`KHO7k04`Mp\=W;)Cy=2|aK*GzOɼ Zbbf|(qJtȮoJB ҨM Mzj}tnT罡&~HYd⳦ d|4Ż;!d v U?T|u4i'n¯u ZSϧy[̞%[~z4y Ҽ,mH[ܦ&@nL [ y듄KˊJҤ50wO j}f(6ksW d#1z^FQlqqw Fwm|(Jo"1BY5 ?Iu Kw*Ddֈ@?7Ugh7CL'5B旎z+k+8#g'A7IXh^z dF Ul1 ֽ!))ؚ8$FՂ`̬ca;BjG. Fp=i`ؾkhn,8G;uÈIgFCC!c1Ip&/6UQS1*T vTHث~V]ߎlB_ͫ2RO;*gfz񳐋T/p_altk͊Z?wE2_DF+2'ʮ<adHLQZcITawy7Vt44\Yf*6xQ0*l1c3D+n<` KR N9U*{~okG}qc;IFF ~O: ۪NSAT=Yřwj 8ci~D5cQʏn EzW_⽝ ͯǦ@?V $O ՙ-0p!UBLrf`BP￉^L1/Fج4|KMeRP'@5J5L|Eԏ®=ca,'{"^ʛε|BV}!T>wPRR"'hQ3j>~Cn4J%u>@ʧ0Tjoףrq#_wwI6Aw!ō?f蠐b 'ĝߗ]$891@9> jM~틞v!YXL(җ-WFȇ*R@ARXn[G]ɽ#HEGvE6(FŴ?3&g ArryJI={zXZ/L c҉+  OKw&^X>e#.5)(Ka#ЌQӠ#E^rf0Y"1Uö"p{+|7 h8ҤvԩQotܣ͛F>'郱W(x }S~6nFcpѶ OyYpmbɫSUL3IWؗqYa&&Ȧz>dںGWu$xgNڹ1cR/TN4/_{WWw7Izwz~JM&[K%T[ Ror/)J(37vlӖ7KJ'[lpyWeY0o9O)NK]ɨ0.)̫t7Lv6Sz(K8_)s჻8& fVGB#^(KF=KR1!v8Ib9@x.~MFjoJj1pRVS~= ;}o>*"{ 1 G}xÎXmʔV-H >BF;^/hK! 6!i=\>mPi|7#BJc쐑@ǡSet#g 3ʹ/0`,}t;&*,%aYZ{+/ޥkYŠk2 lF\YKBEr`7;{Œ1|uQZ[㵿HCT<<1"c Gy6 wSM +=OAV_WS%obl?$+ҕ]B|#<93ܰ3 edrV0PFh@BgܬENC'^5]#&1{NIpW6^F= ↉5O։/^u0Z1\?x~8+|bo36u7) $T_A?DbsL2 rO,nV %N0a#zGw-Eyii/ڱ^S3AL8rNgbh9Mx3$|BʧPٽXu_E>ЊLLZ&|ٮQڦ./qWirFܜ]SMue!ΝL. bx m 6"-R&.ۀ4kM b`mp*$4#rtv\nɣ R>}t-[5 ь˦܁{ (83_|)6 һثvn=*L%$K"MV"Z?Zxݭ/YMK'v0'ZN˵h%U}MIbyOA-dtFYF \XTmZ޷FjCzB0&kz+PjGj"~K/]b4#9 ”Iwxb>lh[,}l;PQ~65syl\2[t%)Q[Grk T[h(31ȃ7e nBmao+%Iqp0Bpma$Kn7~zM۽°:RvA EWϢuLg'y(\`k"h8T`q& Zrlٹnl A4NhSBZȲ󰄚qSpdnJ;ŃlF+Iǧuibo #Qȩ>SQ{.ʩ=,[v=]v^:-?p5ȴ/H[8[n"o57ըM#$ PGctfjtG%gV Lv?֏xPN_b##TdaꫦchYq:iFKLGTc\>ByEnk\eFzM"Gm(G!)1]rP;m`E'\ʅo;>B8Z!:O:\$J?%RBe1Ezcӕ?w/D!bQ$+Q㿷N\#K{!V]?,ڒB^Ͻ/_5Zv+d>ѓgr%hysI ʤh[&Z.cHK-Pc@b~ezF1^lvE)^s\&bȠ)~lZR+Xso,HpaH…fLǴW6FvU5ӻ?Npnȷ`h#zXgV>ӳk jȚ`Lؘ!.+ׁzF2Zm<,Yr!/hRiDK>JKxiMgӂ"e ר.E-S8PX4?i:n'juPNe yk QX(g֑]^:,SVJ\ Wxgj.w>Ŕfj}ZK}E+3mL3: \ᦣV"*!s*S7~g6zm}QUljyuMb/}$ξʴZ+7$q>(8#YKbviʟ{Wc1Tɣj:&[hfU~|~79-pcrf4pk_Eiش'`UP9+ O3Jc$;gGV2 CFջaf*'Hu>aoU:`m /'"Wr`ƬWh#* /=/>BTQ(5: "ypNp}8"ZuwlxҠeSCK}sY鈨 #ȯ.{Bmkɴi/9(8W8#emIdj[V&Ck 9)}_tX\?\㩝OUPKJfDi IŒmɚ#΋] Y^ &TK.C:!Oֳ~hr@)<pK+:Y=}U_6%l9f0+ܭܒ?"H9e=-\Ih% O#&R$f1o,ؒѕժ3O9#ؐ^ZmO-{Sq܏[վYbY=/"ij:% =oQa?7f#gc 4^A5&!P ؕpvRЖ՘6mRk1lF:Iܙ$E{8eHYIp6H8VEC:Z-^Hb.ޚee_$*^lyg V? 8@vy<9b-XIy@RbɴU˔N_+6RB'}̵~|k_Ʃ`Ify(]ySuӣ cABJPhVcg BYFO[5 `QG9@I/Ul }LZ<MCQ9 C]Or/Hmj,OzݰѺk?t2w',̩S84;C$[jς~2.05EC>fNtcG}ڌR"F!{z*>_[,~k<ΘKʮ޾;7AUQVuiك?'rbmCcNK>2u༣q_ApK%vſɝ]ӡ1kVN̠;Fy|` o!&ytܕ$*"J~in3 -:)ΡȩgXO$1 Kxy>B8g}cA-8~fqYK)ud %~h}m .2/7QXwۄӑ-& #/=iս^s;J:6^:aZ¿g{+nnf1Br'bs W⨵D j Ζ9[+%[IQ"|MLjc} 2)#9|BsE7*c)/weC6E `> O ]%!4S2Uvgᐳ 5@v@? !=EuQڧ)Yc4y.(>t _r%X۱ :\&h'h,Rb8!M?tvѣ͜Sc^u{'m men6ߪw ޸8Ϲe;5E)P\d\+{5_$ٺ9L]ůu!²1KOL/%vnZc;}&Q4A_41FT=C]2۟Nk߲հEB91.vx)-P7 R0ԓQ;ىw-F5U:n5c*i>UTU¦y6=Xk%Ϟߎ|Τ VK:P(zb`H9$~h1ѓt/8EC9*6 ӛ75`'E.Ïϑ0)NC 6SZtsz)m %u  R;ւĂ`қ7Kfe?FMy 6 θ&ȸ{_.XS)Ys{%z>R/|&Z boG}-c-iٻU Ӗ5i"FwH k\; z* 5zC7ˈ"6'{z:[~'_%pQ ZwZVjR6;;cO-Qļ =#EʏNYn"K㋉l6GowyT"vn~HPMziN?HRDd__$v(,_lKX+lm8P*>`gHΚQ9CO {g1 N)iBbr*<e3&."].tgQ,1e} 3D:w~0~\pB"z#^ H `(v83#tcmbK{ -L" qeҖ7/ݾ/Pf,>fu(?"ϬH ړ;gWFqm"*FC©oJ> wu*/ZO2 C7ZOs@LH6J`3kqMٰWY0 _J p#O> 74NZ #E~]'vqvtk3ᥟ*LSʀ'  G &`Mcc|PUi̡3i*1躒.:Lsb~S-ٕt)e>]r"pD)bdys!-IXk=uTx?@fTT(v˗8:vNPN6oZ!,CG R?@%w╥s!8ޒ&K&S{N*CTJME`W[9q tR'mIw4k$?dsF90 MP7my? Fmڙ ]T!ih'3K^GE>ɛr8M=퍞lf<ș ϴ#t+^m!5]u~hRm&$)L)\QDD=d+2NQy:jQg`sVaY_|;F79 -jG?!'ҕbs;Q<܇bFˉ&ؓ$+ުGU(1g:Ƌ Ds kˮ+" wTpBxz W(1 3M#idŘn!|#:'3SB[5t͘㪖!eǿb<7Bo;8hGG`[Ɛ8<LjF5t ϛhXrGu򺇫CV8ВC"v(/X( EJj2 :ӯuGAxHMaFR |^|}ixJuxLKEb.CUmVWp#ָ*ddqx劃>#1m}/eS_ܭcˀ^;4|`(InZ>Fè4u=SUP"Zۤ}nyeu|'V,CЃNoFA>Öd;;ь@~Ϯvd >rQƾV 㩫vzoθ_ILPyb G/Ba~ {\bt} : .j8Cb5]&:CGL6Rj;!xk Qs؈V^$b!5?;FIEVÉ^}#it Ԝ Xe! rbG欒-ސ7NtJzURd$ݿ(s1:U5ujAα~ p7Ags~[GBˠVUʎa՛x1 _Y_ zNJ1KBV?RlW_(XbN7v͵핔y#񺦘# N!K>YB~pf]v%$7\ 3-<%8rU$uQ P?[gG/#'ˊv3:8`$E:iHPҲGehQMw{Cc)2FXNډ,O^"8kD7yC>4M U҅PmdpH=go+[rl * |8dlBL [q(߸Lb4 4*^5R;kw"Nn.x=5 /wp:(p+h}dUav5lx`Hq4dޛJq<\RЎh|6٣ r}g9e7} >nc6:~%ÄA] O$b-FPb}蛳ݺ2DU, }GQVlZT$WcƾUO®z]JU,x ׾fo[ 5r<NMn_駁3f ѐs IrIma<2~06j3JTM`0.W@s3w_ T8!Ё ̱W[T =1zb~`RS |+Z| 2J3X'| aGakAtFvZ]9DR@ɟ{˶ۑ=;G* a^2A,ca)̱FrkO+' r<}Qj i2%pl#̐xe J5֞ѭ揮1l¬Ƴ;+,*ƦzӀpjDzǢtIme;U4G d~b]ƻ&5A)ie^R<Aѧ.w4d`&1[bszRBҺW(+ ^sucܮAO|bg%yD.;yV$kKȢUaq,%y2[CEh%KכmJoؕn2]mL&P8MI*j:x1t@1/JvZ0V >c7 ?j]KٖT65bgA%*lN;ǶQœG$FRprs| ˜PjYˠ}!J@Ԑ_LQ1Sϛ9A2"DI7ΙO+ZN yDRI3qSa^lHS"u9c|C\j7B~K8C'H\> \dut ?$V&/='՟ag)sob[rOg7$qF{0 յCb78]!%+ Yml2lGI͗6 e*:w(a@SNx2l)ұHjX'&\ vÃQ >^[A;I~[ՙQȪ$"> =Xk4N*>/I֬-'i,[Z)l՝+蔔NogM!!vZ6A a'ŪAؒCTQWY/}-cW6Lku C5Ν5wA⪈dBWvm n#^!:jףh"4:k+E$t#-?#Ea y9I<GP~h ιgڜ2q>/'`8#񞵑1-8Xi XoP v;4Ú-?@+O ҵ9W @rEG]9sGgZJ  ǡr4UR СFݾkv BR'>UhūfA,ӵ7,H9j.Dz\ظ?ƖU #A@qv2-VE?4f$WjTu7 N/{Fͅy"`ps` CވLpbp1D}/6rhFK!X!lREHp\Bz 9KQ_B4cz<c[ :Kܡ4~Xk0P`O\ 'bV>hXʧb|  i~g*ʫEߊwClDSOth"_L@PaLҸtA{` KHX ˼6 ,>o.6'ąZfEU̢Xc*_zrTF_wǃ[`Gyp-h]9mcjl‰/; k 4}]i}/g;E-#9/Ru՟ {8nF f5(ykz︍ZZ6ha3ErpZuBL a4ư& s@E3IܩIVs6.j:~&uS &o"@ 0vl:^ g"IB-P82@'lzX.]Yjh'GK gWE_A 7d@eV˭fċVN=s~<`;E$$ 8&3vga1B!؞Cn.ȏ!~%8V0^ ]S7Kղ]5OLp '= BL$*o d. kt+TFijYpj|z_2h#ۀCߐ2hiNNtWpsM@6ijBi_ W}cTL,^@.c]Q872K#~ӖcjYql%+mbXG*Zȫַz^ >ɓCMb9 E4O|jsSoh~(gƔ$9\J-\$RHi&ž^hi]u/M'q ]^/E/5ЫGh>o 2Z^ꪓt:Hdj[ aSFNvau ߓ%L y׼|,}GYE"HgN` ͧv]8 A6`pL7ym—cve[1:A6.BeDz8U L9Dt/ bM"+~Q$si?ةXm* m+53L,TG]p:z$8W#5Ye2moSז(WneyC#uߙO `\brcnNE5aOM&~ޞo"= Y7 FŢ+D{f<=uk`ggP/P3SoShIR< }$!EP}%T4PLdzJζcS3s5rڌp[Xق O|B3 }*s jw.C!Yu̺I> Yӽ eV?o?άso_?.䏚;9e7C%MQdDHm5M@ < cTT}όK 4:z̏] ^b E5C1YՔ宱:RѪ 58EkڢO)60v\r{!CQj-a\԰]˨3ygi“ 2nXEXx/p"!AvHiq%a-\6]ttFԦeQQXIf3.$WA閙DM I̚]4,,XuHaЋΎ8tz(`uKtԧ*DE a"W￴O2@;-I^r/>f:F=HUG'.E߆؞Vi%NW6T8;b<$w}le]է/i}#{psXb,;wuT1}L&2F+(`祃V= ,z9FzTNDiɲ3kAY01gM-3Ga!g͖nY=`iھB)9?O~m&5x>@)2%?(66O+bQ.S/Q|3#yy2T8܁F{sZ9՞L9luWG*Ns2d?kWqkH\̸9(zv`Q46rbjƋsn8Y|LexZWZ_Ob|F$ ȗpNxj݇xVofPJ&8y<9o䩒^"Vy< I~VR{ӑ3S1#:.ފ%{Iu!r>3m*@梃Cxt`5X?~͢'SD8&/!o+JW*sϴPB~|ժFLǩ@aW` gl ;7aE Fϰ4bݑxK5rujͻiR&N,X0tԕKIVԴ/@ r &x+Ba+~؂?uBƨڲ4xI˜ID>~T^*MX &kfmۂuK:)*f 6 ^P풬-_N#i#zh`+eae m'?EX@ 23fq9B * 9- G%>yHvhܼ!uܶsuF`tUe!wz q_&sj&Dࠫ-LSH~a>;#0ͣϳEX [پ~go/9/k4hOiݷ;&Hƙ$}`-ļ.}zps } :9yuL $?{I3󧨶C? =SY$;vOݏ|x&<#(7OU@Me< @ucRz.1=L MQ>,_p!tJv&R|\wd{'[܌ٔ@*A1)R1E9lNpYLL琾q(5Ѐ}孙aSv&i E/񴚹kNw2% |ϒc3tPn+S$onM`7|0-qQ[1) Tڂh޲k2 Qr_l3O=ݙtڪnrU:cc]xeQ˞w9z* %kH0<+QU U!È86U [kIJ{NKa0Qr $<)A2&s"R!)趐j[:hOr{/ұ Z/C4&OJ[SzKw8FweA}:vpi?!蓭t_4 MPwSHI{`Q,s5̖Tǡ _\eG| &H/]Ef"yOytP94!3cbT@ޏ,Ziu|$C<-{dHS$p^;؟msbr1GOWx"iAhH;UY0v2\z\g)\SZ4NR&/ЙwUDGXkAK7=;hK/x|W}3P5冃]MI21!H|V\]&5+z\_꣉踶ogd-7}ueJ-\6A Cm*)LQ55t@GuW7E> ]vqt6È'WoBLvs΂}" Ae)M]+AN( kg>s#Ⱦ-aΝ9(&?B-K&F=2[;ouЪCH&&w{wh߇m\{dJzOӑ+>ad$}xN:庘:(&-UΕ ؇6LD&M9#M  'ūeq(e Bo%ɣ60=_V\zXP6wcWLT%ndz{F3" Y.Wz_ |WGоAʜI ˯un bc̭cҚ V%Ifqx#$rH?>70ljjB?Uq"?qcS\ͳQslJ +Xɝ@E5$/yg¼g D% ^G̾UhC.6֨fDڊ@zȭ~=Zr0ؾS!'.7zm?,uu8 ҁ螇lpNvɤ,v:n2 a I-Uas|R#<_~)Ҋ:"YRQ"3LAVQs';mު-P@, ҽ#qg/iMxFuKw-?Xcg8ϱ=ҌlJƚUkcz(ڹN="(ƈ?^-)aָBRKC> TWzǘfdz Tw_Y= h@֕LGbZ6FJC|xY$tSؐy3rE*&g(yíK"% *܏KRZqWuNָqLglPqÊp\ӬAbc/m;z4Sz, m)gY޵9xw%H Fm|GA3RTGގ..p>ICf%K6_pĀ ^j;S'K%v7'ܭUU ~0 D(=Q&GxJڕA5} Xk¼' oR `scJ\uM02|+LKG.1AVo+>%lŪUձn 9FV joJUlbs"BU(^%0% 9%["<9H:DicX6ՖwSxD=2.(L"eŠ(u F{+&r#s&_5P2rU]7 n߄4f*[HgU$~.asN-CӾ|ƛYʭq9 Hw&CE],hY`&>= x}W{ەИ7u\_-~QTa#.PƒeCnL6B9Tt6s_ DNSʉ\7~*洶7*:PS15i^6g_Q /~)oV`Q_Y!ٯrU)̚ǃ# uܾ0 KKř#`) 9bƬf`,MVMBHHT. d`Dlzޢ=JD"zL4)ɍnq8>f^H˸r \1' )rv\&={?J)Ėk!bõ4SӬ~<0,Ѻ{%} m9mvDi `0R:*4|d'A=j u?]cwK]]rbAOw X/#.U-Uo!QJ7K򑫫Xផ6,ZPur$a<Ipq3~ wg_HRScӸX݀"e^źDܷ<&flg$1tm#/*z7j#On!i+r1;A$ 9Lx}pt]LPqtFs7B\O), 7;) #ؓ 恴Z=%VhsieKT)Bʠ#B@yHl훹+Dѧ'n$ ( 4.QpeE\vXSf!2q F" (#h<|KBߙyC42A^7l!jBB!Hwj)ۮ5i']\nO?6_?PZVxyWc?hq})msUjtcQ NEenV繉9|#QRGj{HuY\}:&ذv{/;pW{O`LEPs$fpV?4иjEt)1A ّٞlb[$ͼ .wŇb<-'CE3OJF N}_$4Y A;I>$4 D/Q&̰p뗞S s/9LxpV~#Jo"6iy-ӄ%03ʪ+LIJ[SH+h YЉV"1ttsƬx HF?r MW\W7W_Sӊ#/6vJ/y#ƊXgky_#żi!^l=V6uʿ7R,2c^_Ӡ8ao-AS;8& 7W.c _ `& w3҆e@،^ voۜkqn{~?&sぅb,bRNZ5>iV%i>0fHT@&TK<Ɩ@ե~q/<8$b `M9L}&TM4$4J(<뜦I&kĩL%xC=ԖFyE䦈] 4\52KUc9IDR'hL4{1׮2~hM| RkHhaz"jՒ b #R*th/2 ei:bz?|ſ=C^ nJ hXB Q͵m߁Ež&~iKC'QKJ25D.m/^8Y "/4c$/&L> r =?Goƙh/a`KŚOx۷v\?kqW Ýӏh2vYGgH(]GĚ ,Cvsw=v,fML.gKKy#,Eٸ%ʒ VM qKZoJ~V*rqyclo[n~" vƚc"=8?̍}+i"q"NZOf`6áɢģ˹c tL n=@E%1TEֻ"kɻVuۯ6wڤԻ.O4: * _@|4@~!(n0x8pR6'J5e%&c_@'W&=|Q&r,6")JӺG3;9 89¶C :ZtpO䷺NC!HkSr]u'jž$>dd3n :trNkV9كZ }}wlMu*¤6z3n2o^J:f!ɈS)"`m-~](}~͙.a>oYi% r Y t&M @c@K{`0II_֑TI:/g3P#Nڥ C%ٞ_ `? Q[쏟o%F a\YoNpt vy[+_2yzϩD!*R؂4 !#$؟*CX]FZeY ΅MA&Y`t9at=T5Upp']<]p"s,PS줧s&B? DXJYEm'e\iư .qþMʏAOHF9s|C8U|m l\7Gҭ}+Ҝ5BYV_-#. DɬyU3yv0O,AEl)"@څA ykn~VCA8!,ABD.>n/5DX: ǼK{u[][4YG@RQw,Kʭ2esqt-7/ 3M7 Ԩ!3F,Prh8c 58ZѣJΧMJ/_CVˢm]>?柧Vqݨchf5At;hi-4!3cclgԽBzy>c8?FTz^1QLsu\`mʕ+ 1&Tތ8dD\ݩ$6vO ,V$bf&rEJFC~t}.#/7ru"+x W~KSYq&-LfV/AI_ z+ٜ;Z,{}p&`o$j-G4kt,_֥_ľjD|qoӫ- #{jzX&@=aȶ`r@D|(+bM)TzXڢ ^++16qIFPgLh։> S"WOZ6/*6j)YWT71cϓ]Vd-9NV_66 y1p: W.9g>j0XT#rxφGYee&5B-fz+卬-bJGp<7&(<{ X'K>k4[$0ߧ{XNkM($& CѡFg5[4bY^LL1ιȼ IōHV1U/lgX{@qXF:-8rN䌙9aZ?"5E9 \"2^L][p39+H]1lA ^~2紁4bMԎ-xz稄˧[a%&Hf A@Y!Ghtx·zh;6hh A3Q)AiN.LvnaQhh{]`Ղ<,絈LRT`7[b. bHN FDH)wP H-h*y킟jf>6q;{I/3PiE$EX2"^4g׭vj3yXK: Ti5|~<˯bZsNZNlk[:F 2).wS*_779BVt9,oW offk|{ -5ЄΕrMklmQݬϝ` ЙL1'j.Zw2MziSrx#_+$AElRb'c<%U)ܓAGrǯj2f1/ȕ^-pm b[$NP|㛐܏Mb A_ͫqt9]P֙@m%<ښ9;;_⏒M}* +̚bdZ1vpW\҆0 7{0/)7bV/K7 d9zvR^ /'rp-Nе]&"/3ӗsH8"`\%ǟzd8E=fvB$7!ea66@m.B9a@Sv/3(IoLab 2Ӄ_ܯl4ڇ>$=EQug(}ohhZM I}8/Єl`;\2˸S\u5տdv)֑Cn^ }N[xݬ \XRz(K--yb'أgp"^%U*AG!8+ @viRt pʦsAք#ŵY]Qg۶2O`X)"Q/P^}L]WR VWmmH rGI3 l[]Uooig? *=>(~ %h4b'Z1մdž$BF@5n(f_#:YJIz^$ZɯNx*ڗJtj4>**ymܽ9WXy۸d;b`䥮qXCE T AiI6NÃ?. = |`0¾-[Yb"uU!@noWahpE_z/(S WkMngWm=V?#"4*\ $>ǃqa;V0s1A#ӵr:.9d! hJy_u *γJ?bkXDȝ́n?JQbn& HMʝYu(X5/h#%>5&Рf=ڭreAu[8Qd0ȸ ;F ]xoU13~(=(s5=t2Iug)iwL5Yi[Ws&Ly[X(iAhr}Qdj-7O,V| g@T_jЍ}(Ju0Ҳ}@8#1woAFnK@1  f~M8#S\jўZ+EזqQȻGj:I# ke[7u_} HK SZ%o/JծuwkU> M6 /6fi`1 lnv/OLB\08e==7D ; 8.wnz~a w Њz i=vԹ$O  ?p/.&)hf^s9Mpj o(B5jy<~|(:--ھ{S[KN;Ďa@aկFMMj[1[yV^IeW,DpG -śn3\Ϭ m(,w%©WChRޫ~EWn1hl2R+FYf<G3)S(; xwK*K[?6ff]{$E=Xekyh¦F9c-XN)2V{I8w崼N rx>HUt-7R }zϦ#k0X;4azrLA koloL_W>e>/vApT{84!5}c_ԟjtQ)+-(h0͌ >ip'Q,Y9B\~]POMBQaڪ]A| 8.F!Fa_fN4;9w$ c$k5,~s%2kۡEiua b|əw;>lxԍsFCq q" q8Cvi^QRV;RO\;^<v{](kQ韐_Lbo!0"TfiF"@{ԵPG<0,4+U(0k|t\9R)?>J{R'qT^iN>զ?=KPlA '#OEQDMr!c AAQlbaGpQ%6"Aܲik,c~٫uXɝх}! W#@l61^$brZź"~^Uk>p+hZq]l#cs,%grލ̲fglrubތ6WRI[)2=o{] 5M2l-"BDN|DxpZ^ 関n"J$[a7oҁWtc??+yD -Ћ1Pxm!5H̖D/e{؏Zp\Wׁ !mtPy.Λ>;338wC&(/<|6o1mS6Tvށ'T͚n( z_ PtyKu%1%y:p)d%vnitSvtɩ,'D/Dojkh>'!iTKz3^Se~LxG4"7La`HY4}sxi 96w:a7,Z xsҼNoh^g26fc8rʫC?!G]ZɗЫ2\jQ&=e*@6'e<^;j W->j#`[Ðeu41݀7OcIx~~nA랟Hk^;`퀙>lDMC +oM 3y QX6wL ˛wܽM7%ӈiD6w~<<]}ŝ9L<)pd%kF7L?Y* nZ ANeJj;&Z1E\8V)u|ڜ&3o֥=Og}59,Gm Ǎk/ *s?QQqmy=%Oemà܊?؛\l*!R6 ͏:D_vlt +W0ҕB+:.aQmW6`3ev')V9V762` ##ľ3m~A1 I'Zm^kEʌP9ĂNJle(,qP$f{{ȵiW/$ nu>^]o}(\,7;|9n~p/emJxݳ:i]d9^45ȗ1Vv.CT>nZ'Hq{g[c`-0|&s"b0ndP1g+h7#k0̼2Q) *Kh}:]xkҹ< b@—Ğ6,tz ~䒧ӕ6}+ĝnfOo_ ҅ D'׸{lBH]Uv6 ~*B2펣Z=A?"p1Oscsxj `k`4%\mUS׼9>|aٯv->0`<Pϟ / 9f1-#DЉ3ݸn۶] @ $=&u$[ϩ[zE$j9<%})dʳYU΅enQ,ѐ2Lg/g1n mWsNr4s:Aę]A=#'XVt>|?u&`L*xVIC'\p):E[i_ѩb 55soV}n9 EΫ{GZхk)%**u]#˅Xq'9oK'qͰ. \G((dwks\2blJ;XD#HAF3t7zI5E(3vfgJ?C(LtV_?Ik ClRg$Ø @ֺ2T+__W9#Kئ#{X$ۆ w|`gbMN0 >8ML5.|OgGqǙ)^}Si 63}9uD#˓䈿Pd?{;gu֨E>Pg^V@YNLXעG2 9>QXXsJ{ue=VN, {̱#^ -aK7kKl3ČG vlvL9.D"78APr0Crc)@xVqWdsMlؘx_tyjDa%9Rig.-fc-wDQ?NG^":y` vϨF81'ÍK@Su V<#IVo֖*D<+9h,Fz;`OC}34K4eLFn.0H\o@aaw`V=E2C=*0Xr4>lO +GV2 pr~i" gΦ}*rtY_; 3>,itDg={Ml6 |~@amA*\h"҈vEo (`,lHUC AH, J1-sg/ j\PO^!x!ݲaA=佪+G)y4)MPL_7)/wAYa|+7J:S /VesT]1=HljYoCҬ5bLw}xķުed֒CnG+2y'`jz=ǡ6 {˵h4&v"%<NgCn4V)JbaS$7(G*¹*P ۄbLw0uufp0 y ^ 5 ^.gy`ÆB{L[>[}d9Dp/!$O @\E8ʛQ<,SUͯVV4g8ືlRqvd{eGk3岭kՊүS}k5( bG_εweiiYxx]†˓F?^$^8^Te[AƘb7s|"!ž%@Ȋ>'zu͒0pK `JDz@G  ~g37HId%bR d6p.$$[u'l$Kڙ@"<3FzAS {Syl[㛲Sd:\ZZ$lp*"x?J;c n&n-Se|P@U'˺IYb׿-hZcs,UodìXɚT>XqVo AFBe+/?ɨKF)LG]h6bl ^7 A-1 @Q8@+6^ų' 9yM?K:N<7wqSC"~ R|UD cKJ_(F.85d%i]z4;50Y5dWo.[:CUvY mXpnX('wMf#՜ɱ 4+0s =Mɟ(Բ:I}v-TIdE$&s5z$UB;rKad_5 ĴvvX[@84[/ģFN\] Y(jI`ۖHM?zTqxSȉp]".K! E?h{)Q; j~T +QGz-[7jߦMi"XbN穎x$X|~JX '' _x-F %ͮv q7ZZĝ:Ġ;ag%P|u ZY9f??'A!eo;QJ*󊥢(Pz{ F5V[0پ2YU*(> ,H> A'h}p?)qSeukbcK>\D&tE1:k*ă]} ^8OSdKC$>"!H8#>AkdtN Pc7Fߦ)\gLF4~2ԻwvѕUP?"2F,at2N%jH|-dR*})1%AgY`z W3rwOqRCz,PZ'/##QySv\G)na`4V˭_8ƿ0hjT 46%Ё>L\z) W`Ứ^OjCzˋzaޫ +_qEr8R4,nԄs%[q\+UDz^oĩ6L2p Kn[kS9q[E5lO  piHb4yKGo_չS۾c>f *:R+OJx[:&e.[Jj>` l90F dZѲ:|m â0^(=GyO^UF,Û,VAc#iWă~tWGE0T9N#9òڬjhsP~ =z',mgYMa]D_֫a V ?f9X" e~ 2# #K"O|KW e;+bJ4~y_Q7ˏV#ʼJ}!)ij2>*$=tCB/Pf!⍹0W۲"\Ьq y+WB4sbJɾ񢗴_8Jy@W=>%WS`ѳPvZp^ɲ2bf$wJ!Q\+TH/ ^c[[ dy5a¹˩7n@,85G ,[t2 Q"qҾT?yucbbM.68] oH>/"kvtlp? hWʞć͈.I4#ܹsav+ǨHGl*Cju'y]ȑ_JGWNmH*ט@J{=$uN Ibv6!r*÷..67.?> ܦAr#C@q' AZё;btm||81q7u)aV ]pr"G`6Kq?LQf眖/݀Ns t"+ٳ4@\2x+?vK+hg㹑%x65-BfsL^;::%9gHkg,^.JLiCp<9ѱ:`Z_qECTvpYyAhzEbUB( (r_O@oLN15 tSIU4{ax2vd\X^@ٳub%TҜs``C70yQlT[QZRs|l]f+R>Be-^]V~zwC[FIq{i>搼 Id`Q1Vʾ74M0(5ܮk5Vpgr|F_M~+{ c]ZBNlC&9|S?>vA~ҏ;kyj͵ה@EW |DLr,2MÊIP9lxBbu6. ~5Tߛu?JHl~5Ͼ6Z4oj<&D@(QmTtNj`GA2ԛQ(&ks*뫱BW7/H E65oK: u?_k(FޯdGs-ug&>2y.uU=U7FPfY_q쏛4 DelCч-9\_Rk`w l9$s_bY-JHP/i/fĖ_.9EAZ?14%]?O5-ƘOa+9KG@ 7\!o1h8Xe{ZB11N؇oЂjtXtTZ4mqU1)}mh'ymĞ*q[LgU|3>qGA>Pyšdsifj[߉{ML9)…ƚy` 6/1W͡N0 >kYanlOIF⍛+h$ڝ:mVulszه?ۖ#圯B˔ds oW-(ݴ6V{a%4:V騥FTs6 =c]V#GKM+#ܼ?ZLlPE3E }B}I|;'Nׯm `_Uρz^NxZ)| ڬGZzoqJz}f=LvM;J貤r{P&# +Ij"~:!lCqMvJZS: œ"bd?+NU &Jl( frߩ D!]0̙/UIi1xmE;D?ےޢ./UΠ0Vj*_DRȴ~-D>%E~Rad䅁: -N*b'Kե SbCdΎnf<$,XJZLbC;kl,5|D Yj?OF KxԧDĘKz"A7j-]\m$4Z3ԽdU\7꠬zҰ3p֌tS&y"-y7DpE/11˓d\ܛcQr:vZXQi@%*wq/wKߐz KR\cnAPXDf'I\VC[<,/6`K yGub+Rvf,BTQ?Mη1"lݭ򟞊ZbHb9| 3\4")=ڵ{ rEлCC`"Gj~vk3z p|u:bLC T{Sn;@IwڭL@SB*ͼ"eӱ5w{zN=Uu`GYbwΗb"Qp"^т9B7w 8aJc0 >ģ{Cd&pjKS%e!B8Khyp9ݫg9ю1p("$mtd" @)lVS:wfTHeǮj8%VecmCl?E 2}B&6a|*DVjLUҌ3 +Cۮ^ӡopȵp0TwuC6/OUbmg6>/@L !}BRh"ѯEu#A^au1Łza #?n&.\P4ͤJ.6*´sd}JQia2{K橋Di^A{rE[ 뱚AN 1ĺ),;pSpR 9 Z@7'LA6O?HVeF"{̰+)R5y*^Qa;0Wt`hbHy5`욿н2 [ ʼUQ!5RGƯ&aqˆA5^Bi>'rRIehM:@̯ li#bDNeaA olPvȋ~Q 7HؒnU!R>뮦 %I˺<]{ `"DzL~LNo߃STf- XiQ/7+DZv4لҥsdTb4""1t:@I&2*ay+G%s+~k|Gv3#挅 aW`Aȝ )wTG&U܄?=iJ+ }h8dHΝMlCwi[>d-K<T$Y<<(] +UOv+,F-0"&^ bH. y0=V2ݙJO9Zjp \L;I+=1qHɈf!‡ܰyw`|nlc\3lMաfX.d*JjOޒm݇Ǯ1tϿP eUë5\8=b: ) -kϑf\"jE )LPa0A0)> Uo~@xN$J34T7T&Ҕ`î:33.@{ 9n5ʞ_gpl-Fw?m?QL,8?pȸ _".\n~Q% D 4, V9HTRcǞ{5[y>ZpZL@3Ckc~^z&QM_ "ij=̓۠N{7k9xymaNWĐS-. zc/{H7ݙ]wz}cn,KCMSx ˕i`h<`DWxv26{ovS;bQX'[x YVI\BRq3=h0QjF$V*$x`Nx ɂZU+h,V}Aʏ¬kdlow3!P6cQ.- P7M ZN],8Ch O(ts(P=r6ONhOcn‹ 'y*0"CͮB&[nlIS_oe*lfHb$U3# h.5rkQ2 EgS~jF8!a?a} , RR̓$f Hx矨9r"Jm-/7&uؙN>'`*#n#isʔh%a=> *'L*_4 V;pgӨ? ~M4ynٱeEZ3V,% XI<[_s AURo1J7s2;HfVP0Zʂ}MS\>u>SnԸdulhA;R9~eTRky;pQC&kV8__2k C0s5JAOcGCxH,:G1]a}hOstitZ ʳd=~N N336~VS0klIn9P"c jDٚа Uqǝ/0T25wZsJP&K"6 ~Ŏh5}(+ׯ3.&yQ7䙑}M/DX7SI)&uP+:ШN bb@rV߷5XD#;D>p7P5N |t +jMG3+R'J?eK/\=ܼfBVU:,%ѹnK(p+I(p}ّs< N[VV]k~^R8:V5|8k%0WͪۘKICGn9}>qOgKt^5Zcu" ¼+ܡ|sx訖Yo泣 T'v*tI~^>hfFv[؅Eeez$o.bZflN:SoE؋z[ XڬΔҦvAڻ E& Sǀ0_sD ?NV_b-y e8_&p;{Ft[ #$&\ikVA`:\-.Kg46Taii4iWf( r_jiheJҕۣ gHY𓇌wo٨BL$.U.~Xl!N) OTpZP/ Fb]_ C%W%%:xgt Ӽ B9UP!Q`ReM?#g it=ܡFR:*7Pl.4=6yɉAƽgjx.--2#gq]iH'~wEc奈r!(K`q5tM+;#8y~DXz4߷JHa8^xuhRiPԟG4He̤cosk./ATNLVKWp8<*6BY9 \*Fo 6F!`\GGnH0K+5Cdlt3Y>Ԣ2_/o' \U˨]^)IZ{z^4Rag#h2͢ܝ8ޡ0'VsG: F/$}z*ԟ#퓠F '*h!(G"ǖ a7 fq~zZX+(bqs/N@T6fϼYOqg+s*']I{n\O#@yDy Vn3乗C:oӻ|H#s_?cVd3Nc)KMןu_LhT8K:c3Ji }"39nw]kenMx &X8qh^*ۜP/+2>N]_MpHbê2o[ іXgex$R}W-;L۷jӸZoY.GW"2r^Pi%Qb%s{uÆ0~5&KMKbrBQv7rl|7ދn)#Pz%c)Oo]rU z0fGEXNxg~ϕD _'j+@'پG~gRp@[ sHck,0[R%A~}k.,J@a4m2I #QL,c,2kW ˑqٽŘ6t«ʼn.=G?o]^oD$=cE].rSIdXD: rp~BAH/nzS0Lt8͏KG5W_8q''gg&hxzHhI/q%WpOh#ܢȖɹ4%!~4Fݯ=sorS4|qzXWs&.yY2CD E~A #~UGr>{k1n)('V hT|*l8*_iSL~sݖ$z6c+.k"XKw O6 7{#\ )2ʚC a7RS翋.-]56]ppS\'Ӭ-=,ڨDANOZAt e<ջ%voL^ow$@=J4Ͻ%Ε#}!k!CyI E1~=$B^0nkHHUwcu""U> Ni&d|?r?&j\EMtigaV*kv:ֱVEpdiI[3]FvNXi_~Զ+mPtZ͘[j!5rut3&|ّ᷍#J1^|&F_"M_ñ[n.>XlbB|iZ 勐h~ACZ-yBD~ME(Mu#]k,2FiԠOy]? BBkWxSh}xd^B6m@h]rj˃}?b =2dHOd5H3v%,L`BTy0aaZ*E* ]Pp"\(*Z~'D{O}ݓ0$IO4Fs)HƘu;A@f G lnJ k@!3oypY)s  x-֯D7S7w_jdV [`P)JxYj ARDJ@A&sNLZ@0YOG\UouқN1U -ۻEK~΂Δ=d9S`1f{lMtK18`S,U7qpX a G*V%4UCOeS lq,N6mE~Y6|L_L#8aEmJIlIIa\QsƁajP%uBn} c:ŪdoŲb&J[QV 6aXЪLe\A_ QoC{<SsiOGg \|VAPvgiKa ;gˇ-g۰S(hƥdˌ\-9ޚRVYk15;^O*)t>?**UW0,'MB 0O'V'8wHNЯr`Dv1JDj~7E>L|[RT<> q{v= 9ٙ-*dR PEvW)la \\s2B(G ىJqQ]l٭vBP2a5p#H ꋑu$ӮU7 P%,\G}y7}v3FZb38sИHzM=u]Z?vk!PW<5iOX=!^sÏ5\m;P5=:Pɪ(c_tcoԌMbGۏpv669р6m&wbUԆaF-./^'VatBY˙N#W&R A kMv y[Q}/QmyDO. Eetꂋ{#k2 ZD`>%t%+!$ʗ h=`M!G ضo`5|&3'&%Up<$#p>B^Y~#A.47ɇip~2V3rL/TB`yP4Id2 27<)Yi! CJtE;7<̷;>zfj@zx7ĂY/-(|̧E?Z 2_S yhklڬxb@FPl?pʢݟ3,9yNeHc]8¢<S,gJ( gZve+oƞ Ҩ N\f'&fgUlֹmE?)ґڦin/6E2 7XO2 K%S:7rW$xkTmœ+3'ϳՄEjxh:{\򶭳U )@y3ehga;h(v%zSE5>xhӵYaPWazl1z[3@c>Cl)5(z1:rxs>soFPU%ܯi]NnW2@M`[My%o" ~Ht)^3C{Y1oesKf,lK UIL*EC)}ƪ9[%6Evкח!<4W[l{6\ ^0x1k2GSq6tTe] ` w|>:XsZRw`בto9M^{?bpP vݮ8a-XBN[?5q trQ"J㟑ʸǸ&\f U6D|$=g(~  iVߵ42tni8Xv^iJymVe$͂h@M duvpfab*Aٲѽ9ܱ;$ڸvxˊdYyrTq!:$MOQS,DsO\k$Q O"BHPn̎Ztyۥ`A,i2DzT5[u5,qd'"Y[Ze zi_+֞E@t.Y9{!qH&mVq`I@@L o2WUEiK uכ^'|5AhFԬu1IS5HRNNdU$b:q"bWkڜLX&/D?%.$rR /HADQ븷݂Uz`'o}wo]K.M-/%SUb BȤa#CTGNŘ lnGK-]JH j}}Ci+I_-`e{bRsDxfI^CY9>0ZvMxOXӂUWN>Prl:DiR!AHľ2Al2D7x$Tubg{Ɉ3W,Jlx^̭U[yvnsՅ \_kmB;uozdqOL]]Db Q5Babiw+/LHmf|xnm WU‡sD IU*p0FT%WcZW[wq`1Jy18]0[s<0 mzaB8A`@NpD8N 빊C3)ξ8?~<4'B._Akn 9n~K]B5XJu`!f|}7&^K8Wâ1H, :;H55ѭfJZW9_C=yqL'YcxGT³ni8{՛K\P#1$.sk)a TAc,e9j%"?R4˨%*g2:( +Ͼt֝kX;&=g-jou.[zhvt&EO,8Gu2`.J2UY[K>Q.dapca!N_Q{/N >yKG^q ¶Bβ۹B,uEaѸ7 .? ``JsуmQo_]l<!ob^g6ljAߠ{'ƻ= S=+Ӯ>{t9 A{-Rʷ[?*u p,OVE7RuGL*Ӹf$kjV|*: 37~z:dnʼn< ESD[l^ԎPc~*gfxp2`y:ӹ_Tl[aDR'tXv<~d҉0 vg |4W9sq:^diШ22Xf+ {ԷH^-}6Se:z5GrPk[8#ybsAdP vXWj GdLU_ZԺwZ.̫te2_ &7\VlgoJ@1҄"koX?p>Qª ݤTp<{h{@bͷag'. gEں;D%e"X_hnqىXU4Br :3v?⍉W䆉d`B;ȷ0o@ mK!Я"5Gj6zwiR.-U<]R7qW(bH[*5v>kً}E." 0莚"r=Ѫ! 9`_T Hq6?sK>ٜ?8fP_I^3?6uݨH5kJC{ߤhCG@ɤ_!+`ܒ,9-լ2&R 0;繡"5sH]ŝqmK5<I~P @7=IRMz|#X /h1<$'L>H"!i&OSIxaq{ߤo{`jFޓ<N6އ V#pwDFM`ϐ;= yYs)o]b`Vl[rު86Յ \Մ9z)x6b0‚ I˺՜`W>"XyswIгTRoѬH̰ջ!w(?%KEkO;\AyY5*³*%$5a$$S6 cDuӓSwMt2rbcbZTq?Krd@DKqVm8GTDœXZROQD;ԍ^sf8 !6zkUrB)D1<ܐ7~l?-Hd[RH@a2g,sxTHD|D9WXsS񯻷|U^皏 Q[¢D%[4v,i39gw`ëK_c<٩*f{k19n[:CZI4~&ჽ8M4˕#s7rnt5LjkΠލui S7K?!_]JAB+=3yw+s%[S N=#J\uHšNaJ JS띂mPJ0v}Z60Ŋ> hMb,IFae|Qbi u+WjFKw:46ӂ'ܡ\؅7H\vqPPxOscI[Ƃ1؂GIԳ35=!o|Wisd>I ~q8OUeG,TQss>*sX)0MvkHb@p}J>]nF|:wr~=w }ؐzEdG.N Qℼ^'$ދLjcDaq;cMX>|u/01cjm9[x[e Z[g[_\xPg6p/hC5iF.N)Ma]ϡk83|P)xcc.8 EYDv8]l%qQi Q Ge's%[̼T ˚I녂fr:vW%EP'cÈ/m@Dg2k[(TT.Jf y{dK;xʻZh_nEפs-L*8a%YUl6NWX1Kbtb7%nFDH J'tƷ$i"W!5gEذqL> K0A=! IԻ o\mr> BDyE -|g\Mb.F+Цp` { t̶@S!*6iݓZ qqy&Yqe.a >RwE.}31S ]oQAs.\kmtJHO YsqQ3N?WF5]Be)Q.E̗I&Z|Ongn!1^O؇%ٺtJYI ?skdDDG7DŞn 'b27s>fW՜ SE[⩊$ c+z8J[:,t0gWW?Y؎yNd~څor> -FBgTTp[ėpc<4ƹaN0Y3V.l}*7ʿ3;vBT4V8c҂KG! vSbş<4&"sd`rhԝ)l=vT;hS1i푘Q Z]+\}J3!imYWR2*z|7=^ctBlN1\! @ x_ ۰[(+jGwJ.9 >. _E2͙>ZƢ}JTP`Q^ϗnj-rQ$H,ߐDݯSgAOyJSؿ|_]C>rsնڔI$P.w}qiHdzo7e}cTZYt¨ƩvO S0NmVu{=v T"4 Q0ѵ-`6'|&2_ [oiI, {M׉=$Ui붃wxBnl ޜ4h_کPq>l_05?GqX>HAvV_DB77D cFJwu{E,K(²t$l'wE@{0EKve+)Ʃ'`l"Wz}}9?*gEÿI &0ޣd7*AgAup08XC~ҕcKDܭH'nT1x<bz*j pAd!H-|AuPY)#5.nija:c5G,^ J lDw;͆ MkҹUz'O" td~f芻A!}=סˌn=au#JݿH={m: Fj(E Zn(uAp%%_ ?f1(Dnnoƫ-1=[G7Ix-ƪB@M:ziúӺ9~ V ZJJ?6QV~T[`ba长@i{6ߍOUtSSΖ~nW!yTBT*%~:Է:Y~%̣DU)Z%2ku'FaLMlOrܣɨ/:ԇ)H)υO  ;7U[߆.ĿWX',9pJw(S+xݡ k4Ɗrĉa)FXlŦػs&?MӰgMh^@U k~^U=fڝZɘA|o"R4\:,xZP`WX hCc -bZҢnU0X;76KW,p`&/Ljb(|j.:zb϶[@񮅙a?#`鵸މn)}Uv*?Dz^52"?wr"my#H%g̿}`ݾ=֍;.< 3l>XYKk<+',MwCr:[_esSo3\\b́qX{0+tB$7ѬwyBxad+] 6[DNʇ,/,N \u,"C71DTIzi1s,#\m7Ƙ sZvz%N4) KmrhjBctaÔBWev@ X#&[˳j)?Mxeq曬Yr`7b6)9FgZ]r (<h^|Co.XAbkIO,7T\ƨ8[1{3snfHE!עl:K mEzO<|hvEv+c(~V<;kXwԃMˡJwN2O`MqFzkxKrSpdN|cmAXh[!Jcn%G6DjA|ELzy{wEșxi<(uVIRfFᢞ".wJv,Zl@r,qa/$@mp.DG,|2 ovirr ~ׅwy ]ޢg1xFˠzEmG½r~nKe%&;48+a ;<`o7;:w)1h5*Խ+ cQ| Ti$0=s|R{ί5%) `o5\cW4bնTK)@Vגy*uCoYz7;cZR%<'#yQ̻,ܪL5 ,(:DͅyS4ﲊ Z=|պ_"Ѳ"KY3; w.4M Ip &{bلň h,¡NϫJJxArTua{ ImMGcz),k$J¸J/85orЪއhE~gaP:vPu9¾95Ytkk7P:j"DJIhyL(^/j,:_>,yF؏Jy)azpR7h@.qVsykY+*w?Gp؛RBv: np9~L[VXq$yvi^ =o/۳T((,o%[R}=/b|@UA_V9t̤k?mh Hg$Alގ7fD{^ "7Rn;z3 e/e^5}d䡀\)qwPV|$1q},2ў F?S[#H: 2&Ň]xJ/D)XaVb,Po dfCs[""<G2Ò5<xgP(l|-~; RM8by4nMF'u&Nh1h*W!8E`]IZp+Audb=&z={ g:Ȼ3@ő?$ɓ G.Wu7D38~ն2 Zo>d+FbȜg!.5cq pu%p#2±wzgZ=B+DE.(l$F^$t`ay:A..MkҠiHӃ<8;8D%$Ua5){xhBƜm(~ POڄ8(aSϊpKze:]knt4y @FjRo"e^~O&50 Gԃ.VCb?LeU>V.w_6ˑq;: |MtH]%K@#M3D63QΪEh]~b Գј(`&d˵8?\OGѯ5~S1̂wxx{vcS';3L%aqBS@%"X= E\늘قUi]oFznEt gԉi/<泺t[4sx dBzj.^_$+y ObDv˴V9ۚ [fahwY+k[ L&UnQDȮG98~T+x)|/kc?YZjWgP SA67ԮEysTW}!s`h: 8T鬱M&/;Vy2j8QapsbaL(dϼaj`=~Kߙ'OgBD>ҵXRq58@„'NM̆h&q/:-W;%_f}#ݪ*N>=*WuEYe9ԆDm,)yMNvdŖ+z3Q`d*s#A=_{ Fa9OH\lBZ?\RJ ܷ~#~+q^]GJDpd^6Zwpv}7(:2* ]Yl2Hμ=8E6L0!3 -ԚWjqN{>"7Λ笅=O -cwvdͮQY$ɔsK)O8O흿HV$7>?wzGcSZD@_msxo-QZ%2ƕٰp㴹P(*.[:rOCЋ`w~6g JC?*Љ4LO#WiDkޤR]X6 jKԪ3x(,e5$u$_@*x`mY;r+S}:N7G~u/"2ȯ׸u?Hqi@3mB״P>> ZVek9I=&9=.PT<'Z;Ht2Tv 5e6A!٬dwf4C6Ӑj4nKRe!3dI%V_1}wᒷE.^,I37-u0|38\K:NKd< mתrKNրy*%|Nmo6ș7稥]N\}#1ojr<1c*`Iq4/,T]$͸th^a ,'|Axf#`A<&rX3'9]&zQg%ÖjUYm4Q7*|7V1~$71PےyѦI@B@-&RHDUu(LPۖN:Xmp6Ӥ%\oJi K2MY2otMZ<5<?P8!Kkiѡs+0'ܳlfق/2 ([dKEZOF+zi<7nyF51P6DyriwZnl; r¶ReUL0)4|\K6bZv8Vj,{ԏh6tqp|:cT F{HNWN͹&#JѰPG$!|'TJp=!]X9m[c#_BTKB^mbX`K2LC/*>!yś쮱ξ"Dt?N@LV СDWڪӿxdCԺrӎH'S!͔;ERS' ,\ǁy1xf64wl2D(OFת@10M+Sڋ;G" |O ڢ 4n(]T)͏azʿԃc>xڻJ-!8Ş,*GI,Y܈W'?L)nIf}ږkPrFq4;+r(N½rrR؋mp7QR#"Ylq]G5a7,3 !c/' % {-D uwu/ܾ!N69)@1_zټТ m8Yha#k3DV4?vxQ4 =zQrlɝpըL4:ǝxl~|4-.:ku'@xF4W Aږ&%Kڊ0~Ǟ?_OVod%&Y=rVꇎwNK K?1uz"pz9G̀i1k`Aձ!d)|c'Yc!(AJjdfB锎5~e/_R59,ޗkHĔ3GRsR@Z6wfҺ^qmlB8c`u k@d!wmN\*:mҶ<%f؈.T?`,dg e_59"g߉ yоLD:ؽB9a3oJC 7wS1Jq}/y.QPN?!k^fܕ@0NI#+tSPBy.Y) 0 _w܊sxJ9NģO +:WpזLM=>*2yOoܴEM M9yPb  _<:g=qK1g^9Rn W\Q,\W c  Ypk!N$7ĩ%hL LR<=X6M, 1wYޙ"qb~T~e]:r6z=}2U5lV`w|$,1]Zr3n6%׸~`Ռ_}~o+bps=W=*XS+]&cH 11?o.M1JTD+ۄw[Lz3(8L44dVq'.zJ` c\2%-5&`ze|@괓k#`89IWwq]{MPѺdnR]fF"_f_jrׅE2ή9ږ9$O@lv %2G^嫹3O#w)4&-XIrZ"{`%#Iftҭ 5^ێ&r-8{_7>q}*o*و K^.撻vy Lwan BQ(@b0`iԶʮxHi+aLp+N'y(=rVx`.4֊3wIs SEHJ@eÑ҉[9;;a :32vS&01k'ٺ)?+S*ZrJ ]ߧi?heS?h >dH7}q!ExrZ&ǭ園G(`woB/8~5\t?u$e}# Juj-FmU(x3|@93b-kq$t*VCj܃ 5y57#Z*Ab!3=+pL}9@B>Pnȵǁx87^bK@("+E88`*<k(r2]ܮ_;p@dX?Y:LI -x=&)|:04 L}w"5gLnhקv%D; `HuzKh]Kw!lTJ&pq?tbKzڨ.gelVT|#me.]>H"8;X[>"lVHe(Xz/y贎|p?(\訧3|^l^-<eGpI#TwԈt\;5ݽ9aA_ڐ¢|/#SC6:[z1̍wf, w2cTM:V LS.aYM1=@نE(7~]Ӱ "IH5&ߥ1 v){ڪ 50rk1=b fFSŴΤe/>rTIq2-߽Fn{|ufVmjeEPj!6 2d}[N{%wqx˵^ {_RsjCn9MD$h _`LڧcJٰ?}Ͳa|',y)>F2lWjq_Yhc=CCH- w> .CY=D k><}QQ\<J b P , 3Wy,tυ8#~/֒q]nR^w,~.:ۇ8!"9Lii&,-Z7;0R q;dW_|/~yt*jzac:*&"MC!^(ֳqzY z.w(h.֒p7+ywv x0/!ILi1g}kKt '[^ebt׹j=UǞK*-"8,P!ŗ@%d Lm ei#SRV( Mq ) );kA.qczd:?cۛ=Z}y-`sW݅{ܺ~(NWF%$Os!@AKIQzf*M ۝̀K v,r4$Jkغ^8pml Rn5ۦQ;7[Pg@v|b$_[ Aߪ;oA:~v!+R\S!QW}iPb*޳V &\ZGh9Yи1Z&{A|-(x?U5Dk1?fiM--?ݨ)Ff}Y=A"gDq: j< z_. AzS;2u~}@={@Jt/fiS]ů6ʮc C*`@Mk ̕|VhXfw^"!T,L~(B/tIPz"z7nUf1hZO\-pLC;J%Mr U] d%MXū`g62"~ɧe=YV"[|^m؃1w,Xǂnb;Q=q% UNҢdCz$Puw^ιcՈ}f/e^*k^|EbR4j?_\-t$;vr(9#D I@aT[dŽ!HM!LH̩Cp;3Vvmrf<8L5`EqF}&; byRYx``5>\h(]bs' }͛$Rgmp`BwwjD_Pv3]rFNZ0q.SW:%DL3BRo8eڣvv[3zC%t*~(+"O lΞmd&.):xDц#4~l23DKZ j-L@hg#CEg! 7lT3GNiT-PTvR*g5=x3m6#[cڐF54C2'څI"L\ ַ9x`k.Ag_j_F``ז>1g I6޹PG$ۘ">= `GS `,qs1o &2ҁM~?vAc~f㥔sr *C)%['uuF1@i = h*$հKk/޿9lM4 Zh&;s˙=:clX>by)U/dmg!{j#ƄfK*]^50H%~8{Oڇ6,KmJ5n{|w;ĕ.S)#7m ͊ew{o;뎞h T☦cs;Juݫ]=D& g=$^튖th{DP1X; k}0<\!U@YM~2i5Oiuܪ]QD6w3>Ux(&d"r S M'竪Rɒ醽TX _; #-`"vQǛ/S:1^9H Q>VkÊDŽ;en6?2J>SL ן|rg~"|Iy!nD? H$bg a4oR{*7sIբ!s_)a2&qe8!KюVm1{ DB ˚!\]}ֺUR8 !Ċ3{'.qz26%J\ۏW_n995dMlnPgM I =fS((o >)u1*}v}IeoV3( 99LV[4з*҇Qh +C}ukCr16$1˔>91E|2{rjlBP*3)сl$W&ٮvOJZԣe>$fW+JIC_n@ vބg_ [URu'i)`g"j+6v!q1Z]ɏZp[4`:z|pVԏ5(67$P y:p r'ٲ0P-3-!("y&|~EH]vOGz*r8+2۵#oXGhb\zL)'\iR#MqQ AY: g$x;*L;AI75&dJiOFߋpj s˘ōe(shb_Ә87k2yAn/>:c#TY6~0}co&ƅ.u]+ ' 0<6]zŠZnȗ4L M-Ie(?Tx^ߖEڿ0>_=S[庅jkxQ/e4{k,T8qR 5E Ûᅃܒm`sZHaV4ġw|Tq:ˏZEbP#Td?F%?v2#섬Bnƪa xF&C,:BqT3'ϝm qP(9I u ԩ<娯xf= x̢sʢl_"-xR|p?6bF8gR }cMUO}܂,kϚC7g=&',ݤ'L,i 4l>j!71}csTMv̔pim ݞWwxg]̘ddߝɚo Q!/ {|<>Dk| v5-g-DG;ҶAAXT@l"iR9&)qe;VeNF@gD g"%E(h\K/? a;vmX)R=)kD +mWZgØ"76R8͡GTz\pSpfdgEbìUp[D_XiVBhA#aSt(;W ZiFÞ-w{ yj)mW-,:JЎŌD"ўOc3-QMk_Ռr &BmcaGǹ0l<^B(^,!Q!SICa[b3Ҽ L射^Gb8#W\5I[q';mMixX_^JҤ\Kr<F&R2A'T?*s+~hXQyQEo]&?fڧ?q4a|l/v%Do$4]o{,"'C(AL y[MsʶJIܔjH!aIfۧ}Fr fP{tcg3/JBnRݬ|ʜ8vj#\2iXutߠqK4h /1 K%E%ETQ,rrzJ_t,L>eP`bޞkD?Eng9AG$-Hz"]6AF6`vgSHkg<'t0xx%jӦq[(Vi*F5 ī<=.'Pobw&繅㮷Ih2h6i~67 f ]r'>ۤ'x템g{̌drѐUJkVCGZmҚ9lfhc2ɁBL5Qjv`B5p=)(O/Fy習`f nvvp B:3Gʉٜ,qH*.q#o*X缐m[O:c} = x ܚ qλv1G;fH✃xW36> )5+ӲE6;n0扄7*&GxR=`WzDzP{j6- GBR0NQ}3[GZ V4+ELyg'im`%2Lhwf^7ݥA 6p>ًW 1GF9b Нv, _~}0cBFEd/AEǘ|Rk6ξL<( Yq&2g]yNWk[~`U$?tl[ELlx03ˋE= L`X`=;BaƝM.\rRߨA~G׈ ^& >YC;ϘAG8WPix-}$ޔ\$qrmc}c'N7W钚9Ǫ㘢ђ>ae=࡭"}&!`?y*sF2n'IT2/!bȸ1ϓfLJ#l``|X&8^!/Oəu[ۘ[amND :-AeBiAX2}ٶħߧU(2>?8zH?&bSyd^EJ̱ >Kx1{$TU({(ގhoiP95y5'nZV FS-*; '7 o r!T|LX!驪>JKVf*13xGڤvU3aYx3Ɖh5?zh107Dwe5e.b+o ΝFeN Uu.~Ec~95BN/?ZPj5[wȯ1JV~Ja>Y1 '8>-=42-DO*4SکAZ':i\ ue`ЛHouy:nɐp/ W?Jv/z(`_n>)۫붯 BLG䵽BRh7\?<*K{/B0c=dvӖ, \Ϧ0̩ ϻ7ז4,( 7b3Zq7VC6L󼄀KC@\ `3=X.PzZ%'f3̔@9za⩦枱\rL1(]lnF71BKEE9แ0 v!Mٔ*AKQ7xzGv+W?'W /S T +gC*Zs7It;QmxSJ{& r)ޓ~Dv2Ull15V6~LŝvZ1Bo SKŌ _4*n/~"A@+v_2B7֛vyB;$ŲfYP 'MV\@҅MNPmܿ)ȋxHJ|E!K|O11[L3`6l糷C~0SOqZum?w ~ Vo[VĠ&L%d^b53;ݥQ@A[߷V E\%q/MY vZb ckQ56 הuZR&=\XA|,!2nƭ?a~9xkriƖ`D,=vw^ BZ-\z2mKqgsUf>ɀrG]%(N|ՈM,% ná| "J>1icbZe4.~ܼ`A<2lht@ ˞=cw,0 Sz) vJA/YtuqSEC .luP>nfX?dզA$-,Drwtj2ϬO߅R “"ׁt9 U0!HetP my &85S,`7`z{׌ 8Q=!VQiA3V&8ѻi#$i&?FYY*w΋ ͨZa̿Ķ s鍁!QW d W7z35X z g^̗j$[VJ @/m,N P.jS?=!|,*!&E܌^yًb) ?3ѨA @yd6!%"Mٞ1RtP{!'ľw,9VI+%hE>zVYs%CLݟ2WEç# OyR$o1qV߅<]ȮPW [iZGW'v4~Nv)NE^< {~ WYaF7oS'4R( $CzөȦ@fB\)[Gzw^ڄoÜG0KmoiuDZMh=ÉNt"o04ő`Ԣ--*2GܴOJu>=N$\mPVs XPINeqzp} ߩ  W+lhT5-*ߟUJ!? `,i:ۣJիP$PE,JK!fO4N/HIJ蜎.֟l#˪O{T(qZ",FȍTzZ$4WΛ0aOzJ- Mɚܼ{ hsM\@Y4,k#K,w1P„+ϊuz -hLoV[#EEiRXoxY ufdr v(88|nWRYZڼ-kֱ9\ u: $:ۗ"Q/SGUwU; Q{ z5DBY0=2 Y!*ػ ڱy ˔o ?A@7,:թm!|bZHd'vqL(; ˄#&J&0n m*Qz yĊ|Lv^wSK cN-R $H#@zzp8_5QY=:Z ]>Çj2 /䱷5cUհLȴt}|nxk GfbB MɖGbcGzf&)O1'@ R_9$F9PD;yP&s9'SltNp6w^>s E1;b  k}1]e?x³%/#á4@r8 MX  2Q8f=M9Io:>7yX5hrIm(0Cu;9)TCO {*G88%TkmG1U>6?`eOw-|Nk(q[-D}yϿ ʂm0_8M%k} O\%Ǿb'R <Ŕ6֓w 6vXoՄj^žd}0Ϛ<82rgq]4өci^ڙUy!S34z>ϛ ۄD^Ll\:S[ى~ۂėr`.L: {j@س& +3E7PqP}>IcKq U4u +%2 C8rGF7Ķ>#_p@&d?ͪY1 L6X-盘6A&<3 )tı1Ev4qK٦"ox"(;09T΀q:ِ,dgr`G SvfԒ俣Mr, z̀ͯ\`VX ߆SoU%K⧸ܯ1Q5 tbZpс)6.M $I-+)v˨2d#KI,{\:80:x8"HBHNS2ը9K| zSLXEPB |S }6عOUIfZCC Z5U^l ʢf6Eos{9Pf_F@,U[ 1YbmU<8Xpy߷/ #;׶UjH 'FS)SX?7ꭸNe"$N`&Bu~vMyW,9Hʡ.6q-`'3E]eD27 #?Rql$|i9Mwb&y%ѯ Mk 8eRmPC#M}V.9>rA,rR?n rA)q\3l|-0e"ȎÆ殅~E_! 8s:$TɎkKیK󲞩Cd Emfto#pV@'<.P}Z9۶XEa7 qp.,uę/ݯEX܎W0Q1[e",A%1xKIJ 9`<' i^gʴ,,%o- $uK tH\tBVW-sl@ŅUXny @QFljE\]p{@]Ew )BV#%Z#8KgH_)"lF% [ɄS㒃H}XN'ŽlBŏ_-bJRWs%I/b~즼6N W5{qaѭ~ ?[I`3+ҽV9f|,Yv]Ae H #H9KO t}{*q5)TWa}In9W&E5]+g|ga/܍YIeqZXn nJC{2 `T}<^Y}̿f~_E/Y=FW]flR{*S_h6㮶h//ouspn?\Wg"e"^ )~e6 &ofπ]|p_`Ժʫ܀0un0QZ>&H:TMtS-Ǹ1y^[=,kOS:H5T&4cPAסf2ph:A=Dc!v|j^Q*83Ll݁h9ugMN<\` YvǞu~S_g)beCY1K@06r8Z"AG'X%!D2 DXt/JZ!6Cu9lX*E {C0SG':$!f>gr1^0ywiwhR6󊦔 M(9ERW'oPd.9t:C&9 뢴#4kDP~umC͵Y [8Vh򂼽+/@Z̞6'mq"H{80iA/k_RROG"i4r<(ڄ$HqU"\>'AjFCQߢL2hذqoNHYK V`Ab{I¨"zTQd3HgiG=~\N+̼,-u؉{ 6((E^TV}]xPom'T#~־]и$jQqgX&A#Խ-$+ Ã0Y$AHe· z[/]HIP-۹$`ߖ5=o;u/3D,^>%E"c#mw$|&*\u W9_ >GP塭ISCPz+ƶi}cI ۍڢGãN,ISq2J5icYn?b#_H6dULLiˈ8K˯v'Ũ [DM%Hylkf$j8f)hfߝWd#皦v L€)D:/.,#;Ua*)ib=eup8O XKYpAH 7mz?zF={Pu'_pwBD$z0#VW˳m-u$ua|ܒZx=>GxK!+49 s$`e*Rg5D1`]y; ~=aи[ \xya;:n^G/*B}(Mq4X5cfRT74)-޺Xruя.^?]?Z컗wԷgtM5Aק?0u-7_1Oai'4gF{ +ƙAړ-9UH%Hv vx~̭_i!--@Ք.F;z^:uPެj]g%yIGeY (nui7GSbJߟ@I63B*]GJ[WP@h Ma. Z~iZ11nqas&KKnY^GN{^{Ԑ#1-;JåtUo-n 8^4.;0qnR@0&5m3d=5?XC*way3ٍn0EDR63#s/r8/nl)oE ,ȁ_X$J{xNIWTv P":jtyA)dj4,h@+\:J> 'm*&c'L(^mЫۄ˸m~<0!IpUCm{"!֐'QJx;KN7l:X. 9 3;o `-( fڔNi-+ïM_N0R{G*9u(u q d2=t?M,]’Y«f1OR 4Q7/Ż"|̩ ]Wh-OWtzqg$e_^. ;t?nݨזǑRʊy}RfnJҨehGbj!<G:BPY"=2]}ggK?RL dG gf)aLΓ>tKz0G?"=ghCk7r㸨nlqw]x;ʲL:9݈;0B4ɂ*IB? ˙ S ISLi#Q?^sHjWg1F};bG z]'@CJKeKr@k6"|C KK0] Q,km~Ͼ-$h3}~[#:v}/XtO;c~UA@3?89ic 90q*b:? lҕ{V40_sa"ԍn{5&x%*;-I:Q>:=V3){K;4\~BR5[JAaN[C^^T ZhQm`;DF3E2JoY&F.,{j^:=e=?eRU4JL@,|d:5/Qv^‘VXC[zYZ)pݧURw:)R׵c?'3ªa2$IC.1lԬ-60r>'hEWtCFH_O1Э\lA{%cXOZ%@чQ ԵQC;̙:NF-] .Fr\'iC5E*}|ql a~P~ĥZ%@@Xw-*PRB/t"/S"χmjS&F80)jPTYTFP6=+Z8PZзye>c4wL Q)=KXQl>⑥sn V(%Y}DG-Q|;T=U*pbXw/{!,SMS@K7QiAʚ[%mt| }W@nջи BnOQϥݼr?Զ7y=GOnhOReu/;"18) G VM #u Iz^tKT,{;Y~{؛ExWCVz'yb$g C As)Xm* 6D:.qzP jr2܋A-܆|4n0o$qeL7]?k@1K+jR(̭٥6{S?cсQ} MRo?AI rl/}V[~sR-m@$< Zoh`N߃tbꗛY>fdїoHD I?E{92qM<]KR6Z͔wr~ n9͓4.N j#uٸ(>K[vf8+"6َK[" b5 `MzD<"FBDm1.\Tsxe kbFRFM^qaSRʻ) Hn%e*r ֑"ے_ &0L@=ۮ?ZD#㆒v?ITZU"ߓꭉˆw1J=2?/gA $)KO-g+B^8UNJ]X_y/D>R3O}&MX=U䐠ahgidƵ[Kif:lޅN%3tOMDO=_ ؚq3g<.H#IG sN )˩YdO.h'ͻN; a'[X\f )0fx,iUU#zbl>^aǘP J_%pVNeA: ZAR"Q@3,\ g>44\D8І 1PZ;2Ț6T- 4+j{-֐@i*Y($c.H#IWnH ϗbe 3 fe.`zi3GkJc.靦? ZN| 5u\(=nRߟ39*1ϧ(3<\$:&Zh/d/<]cgMJG~?A;09R0CFw37AN?9tQ`.5Ԟ dЉJ72oDPU냩ʑՒGv]}wFF 1vqm9O JI4 MQqx ?@M(@g2)b|yaڿ"+ ?bP̔tBdc@(ٵ[O];Ϟ~6;W>O`WG{&.n.n0"ܥ:E>=~< pˤ"O?jj>핶D+v-*ݸyZ؏XCon;Lfq܀3`ئw`_΂0 Mܒ A)7F LA.}+j+h>HV$nsߚ㑷n[hjԏIy&Sx;B/b+pv{qq;qXFg0dM G>}T{6ȷ1 9řFP b1Lz6;gI=N!#9ߗp匭aɂ>-$gLoRQh.HҸ I{eT*&)Bߒ:Z\1\kUFQ`fƧd=NH_qc[ lFM]×b$p 鈟nk{aod#MJֶ:j-?w#+F )b# bhj("Q t&"p.Fd밨>m,JBYg?vQ5c/͈Ibːst!O@WG?r_%i-u`$wi::eF8bWi[mufyz6(L,n>"? LkՋ^窺Z L24٘\RM8I]VwC0䰌=IȘ3|7AcT8?݌74udBPnA|􅩼geURֳnsϹ8G" SV8>-UZs[&ORu2_%?5 BΊ:4 IdZٵ)؝ W9l:T8TXScN_WnnG08曻nQSL縫-Ճ~2p 5d[-n/ѓ.pC!l]Wi%hLɏ˞ɞ}\=Fbekn!i5˪^͢-2S,h{1jYf%Ƥ ApM lr,OaAíQ>g 0`}:i{ ÆPcaoPf2pz0U4(Li6M|.]- Ek樲@ " zm  niIڀ}5|q qpXc'-4Zd k]ǖ>2BѦ&0wσ] I-.)I=RۊuZYa P Ya_4\~\D 02o@;53=ւKԪ`l) g8e&ƔwV Te!r= 4aA2k,"0:eiw5"_Ԋ42pµSNyU4'owoQoe$ nu1 QLoB2Ae|1q~L/aВnn/PYh/OԃqNu,ш:O$Wa;, a%oS$V5 Zmyi<T*ٺc*JVxo|D) ‡v뷄 `Oh)$&yܱ%<=AV$o>Dl!ob;p\=(Gf bSF @:~t/s(|i~fS^:xe1K$H?TsVD_`Uy^y=}bl-T{Y.mII'Ȧm 4lz9M iX47of`tGF 'R T5r:ץ[C6>.-2zL~>mRތuB=8 ȼQ1 x#ґ6~OȊ}oE"}\Biw.!"ޓK'BB 7k#6NToM¿%t"!;-ּ}Y`{W~{zeT5O·dٙn_Ӭ:pdLd Z+.y,DWUKtlt _>J3X'{{kTD6TP`!:$CRF@nb:vچ 4w dA3l/.1؊G4j7 $zOK -I<3YG+W~ZǢ X.BM8W"m#j,C牂TWDHHWς5f̭'cl7#!qxA81"t.@>|6uo,M7lOǘZȥqGSUxp ?6|J"13+W2=-Y^R#J2Ddϖ"b \cTS⁁Wq ,\gvʝQ@Pn=0(:MpS67rBk?xuǻGbB,}a$3KƹJA]pMO/QӞ"&k@h (k3 At`Z+%~INH,e}D9`g1X r+Uē!$9(ջ;[ݰ_g_mXs.Iz'+0Lov{ pӋ͔ҟfk=_l[=91h@Ɇ%Tń%@n#tk< wB7oPy)mO  +& OiN׿u33s_g?.qy C75ԫXeyUݢn75?ìq{|x,#A3I0)v:[VxMM= pqg 6Sq@RP$4@S뷎@5ͽ\,mLL|m}4 v[,㢐1zZ:*Q5]m 葔/N {~Eٹ1 wMRoR[С~Q (t-[{}E|XX6O2t2Ãa `;8yv1yh7Rn. dRHA/l:aSR[gHsx`I"/+ >!o!ZrxB]}# v_[ DKʧ=B!C3P79eG_bJnw_fYW\`RB~"&@.~ԥ:CT?ӕz"5lU{Ep(7u('8^&){R,Ł3]F%2{U7%0TO"*89G=QQvTe]l89Cep*;"5|)s*~w^{G8Q? I-va5gV~nyq"58yjY)ܰb雿Y8]:}zk(N:Ӡ9) kq9nzv<^J'J.ưҞ%QMQ'Vnt*/aS35QM藶/!T|Ӷ5H{udі@4?;,M<+pv|w"YR59vρ@}*)-Yϧ?/Qf PG}5^MfLo2rYo<Ŷ@PխޯȊu3 A}-J/\-ߙ]vY_Ef~9[:xuʜ{oXk6m M~*İȈ;*w9F& |-@,@3q~q&:qԸTKrȬsd5s4=-X6-M`V>uXe[ TJʸUC]ܿV~L$^E4e_fW(Gګtކ$؆ 3!bVE4%* OtQvMz8TLk#8Ѥd>f~S6P=*EMӬd1 O!Y 8+s+70pe^SIVAg))+Żߕ7q]4$t%ZWd7RI 4w%+ǣ$kS.3{#(+&J֥k?p?aj LeM'S $*cY1r2a4|8>EUq M`VRf AZ$4QeԤj ¿'w}NTEz?H0w% H-7}cS>fzQn A˭8+_ /n׷2;ALAFv';8D:ֳЖ 3:$eG-ו͋*ۦ@)CGBB<]pBHq+;o/7]f`0x Xd"QzauP$1rzjCOylkr ڋےW16־DvG?c44rX-$k$$Ų Ck Y$V-̉4B虮o-PK : Pvsj˛ANR9+`q,>_FGqJ0_޵J)8Yv?UU q`8Q=A`AҪ%~KdS}CgE6)w eJHsP|n@(fi7"wK1 m4U.;>`, 9_@@fwmߋĒ*fx*;X}s vJ*#0$1UqPjY!#{'cnl^N>޲)Wm  e$nE2?ky8^ҁ˩"@p=d^B5C0;ڋQOJ""SWJevcfZ?[[ Ց{O/L&{x1Oo}[l<@@j#)Ƈ") <$&#QtR6jTG]/7 K#yLe_݃u6`hܭۂ12{,ESܘE HuFF}l18=?i-35E u2yonЎ~q#d|udi'bk jm?Ž)HfGe3O0/_P2L1f':C8>,3k8hs9lӿ؃B`c_\bٟ@cw:`L҈jIj.FiV|t+>\ QȧqD7] )$k))Tۚ LGIs "и-u&Of.vxWXŎ G̫6膮ZKqU^/DeoҨ%2R{9Wk˫7s.@o ݃| , Ȏ6'"~(B|;)jgB71t׈:-@bFjZ{;FcVU`nm\9j}=Y@xrgҌ g'hqy) 0^@+ a++h/$Rc 띋\FUR ^cO< )G- E+gmD\UԲ 6/gL5vnȑYGs[~y D 9+:8>) bWy{֜ `G|;6jQ5w>L'ɣh3eɛp#M/Ј ^B.Y4Rn]g0+m:Z7*Ne>sd6 0Na/>-#[&77Up ihHCOhtHc֣gUϟ?t !7{9H6HP){ybb3d?e-2L_%g㤶_hZ?D%_WɚvnA eM'!e1ʋ9Sp5SEHKMܺiwnw'RV$#*\]3diw9Cq<{M9@N,DpCoCQ\r䲗v5 b$w4APH7,ԝ<8!_ȕ_w]C9q;Mh ;8`NExZ t3EG['&։aT0ȕǻdQ&cIQ;LN .0TjY=>b}N=|V3?]:~ճ(CRsy'#fvMؓ!ÒЌvuR1B`-+ôIJ)+X3j#BLbd]r@_/bw| @r{+dž7 P,v-g`5mWq Y;ǡA"Q&2#}uO.OTU[)GBY֧\D$7}wXS75( 7C@z߇}WÈ4!m9te/Dh_R3/+t-Im(\ʙ;F)׃XЍMVJ>0t*; eqm7~K XPBwAb]6_5C3DMB r sfC$<$0qoqlw%^ӌ W̥(Z:EM;̛5h$3ȢOo0𖸀.جmx_jBB^ȇjKTDJfJ`ko*+sâBv2j_($YhX7y,Csxwf}\э)jMLU꛿ zPC P?q9U>N71=Eʄvuv'_+=>LF 5D0}t0 ɦE. >j]Q}wKϻuiA#V%=Z'rڤza[T9pW<iFRv oS虾Ng}6bexq܏đ"ZT 56z\$YLKa61wSɛ6ͳ$N2 eo ({=YI(aՈ4ӨyÞ:l:lov&4~aMk#|2[gYX+ML24Dd."ɡзIOtZ߫]߁Ŭ)/_faA$eXLߋDm̴vny Yt^S F| Dqq}tK X+ăq+esE# UΚ^P2CMK0,A|ޮXJ g{Գ5?,6G3FkJk0wW;4g|> 멁]Sp?һO[q p61q:{N_|?yX,w't&cϻ?4wh8bc *% !^/cY] Yvh{G9jW\j p33ytxs"VJ,+J9O9onyޣ.:Uמ=7۪a1b8Є35k,;K/ޤKȶѻ^dg6V^>t.P}bpjhw0b=i<81Xij%RaI熍"?qwvL쟨[Gj~2Ů^Z7HSOӆ8puu<#낖ak/-q$#îRClK ϸͦļ; >:HA{Oox`'zæ֫hdB1#X9Rsz_Wjz7y@OO3Z#T#ky} &kF/,.zGdnoAyCQtݙ#W b̟D9^--/r|K<6EUϩ2%t8c0PX%rkvmҞ%RKE"/rj*}^'*wڀ#p-V&LX=Uu6`9ɵ(?<.@>`(n\JDF>a;jNqvOW.-w?.z$Q>Rfto8E!d0榱qƗWH8f%]zY^,̚v2198>RLzZV>ϋˋڅ!$ggr2-d3a)~X7HjZ{9k`ƝܖpYVwƿUpn}\pR[ Vt{ՑpUUa *(E! Y~چ[Qb]3~}1KοJSM^Pb!E+{P?Z5r o._4m; JsD-,?Zb+-ه/u>ۂc8NrA[49eߖA%l $xYc攺b8&C1Sl5l#E|E- {D˃{ ǜ{~JL!a$!>YZͪ:JJFM?ZYMI:ctst~bO}يc6* s?X`O T8Y9iW4}G}g[BCX'iFJck[C=?in=w!?za5ilA9["jgz\`QIb 8PI @դ:}DظUy;/Bu6󨳯UU ?!n.6EӉ/ _ ˤZF?{>NE*AQm{tFf*0dMV +/Lu1D,!:zsQ0*=KjʩAυFV 3L"-ƈ2z.Mȉ:x;hp*ȗwbfoBƵl1#F2Fq.l)4j S]."\-UdWϋЋ~ vZvamnNkڲaHɮ)һFNrWԡ,GϨ }fG yU7D*A)oш˙pxv>MtL!Ԭ ̼FmMx `y35>s?eWC베72H#MY {WU+ .wC&h9FP¾Emr]ୗV=v̸$h=7v| ot%Fv/eU_Ox6N qɩ 傕RE)29''E.pN1P:_՞UBX G}#c+xY:Y#┊(zLX@ן۪%:RMDļ'^=irLFUUnY.ξF(a:9/&kB*E4D m b=K >j ?obơ|TC&"ٞrUv83f\neu#_J]GK꺒F%YY.w`F<`@kbE |-Hq|/Կyר5<+xeIx3 Qa`YQB̭`E$0)c^rPn*_hneu~{0b /XsdHqGz5L:9Է ekP]1^dfݗVk8E6`ƿYqСEV+m? }ځUجI,˜h"prJ R03G!/EкᚋwV:,i/etYL6JА)KQSd> vx9aII,ƁIf >?j L V[7B%>ez{ Ѧ#K4\5p{c+!W鏶*$&?]THe\nt<˚o:t.$7LԙOT.=@+{wt6? k9t(?N7Y !pKbDmf>Ec(b\'<¡ԙOg蒠'}qd=ZJ}IdGjCb"dUAQqwC,)9:T6An/\?KQF&hX=9&V yhvwϰg[EDwA.k-QsԚS%b x+*P0 ʼ/׈w y;Oz$*ńңӟ˄^+%!80$Von72!41 LF+A< 7#vLa0;}Y,.^ܮ(idһ ']ψEZR=P|/@7c:L'"r߉yPp|7m1Ub&'U׈N{*xۋsw9|Y'V{ Ys*yD~<kj1a?"Nۚqzuy;!lqk}y;Hݵu"I3ptPfj܊B:q S_D?u+Kχ10CC=uxEJ^AmfS>v(E2%n8ZH{r pe/dΥ,!1؇o rb| =X5<ڇ/km;\qAx CGȿ RK+&E֘Vx喣yE+fıǜ̓5R:LURyAOkUMMhn]]XÎ6%AX` فwk=1iRp"vOv=JGayQ^A^F-A Fe,$mikms]gg뻗)5)¾7[ nB0nK")DF_ˊY[)U[Pz0wJ]@P8*I<VS[rtџCWU-AlG:쭓dԂ | xNVWq}\#0;%}v).#49` W@"fnwwpG~S&ڰUa1n# l1(2$0_y=ƎA7b/yz&l2 Mt諠̸TSlL:!B81{k@ij?=(tPE*Rffv~2*Y6D,H1e[$v|{n,-3^P M-y3[z % ԑܔ-`,.P}3md#b I6Ϡ+] &[„TC;} ag)ZaQ% /j& g?{ VM'ks;C竜"Zc4W0*ChG+Җ$k/~&hu(є_Y6U `Ix',G7dQFe8~cHc/(ZitmmqNJTZ'FKp"獃Оd]S+{^_Z]qBRK,\fels%{o ҌlgJ@6W2)ìeNJl.搞yj'DE jx$&8\j^Jz^K e{h➏BkT&Wyc a5愽.ˤɒgr5WBVLAEpr, VrH_%pbh1nM:cwܓ,R/^Re?r(VaH|B#w;9Bz!с,XkP;ֽ渍ETBqB_c9p#XQ/QrSOˆb1|],VADbtq{tB|i6J/I2QN:g (hVL\TTrz[M%̜ &Hpq_gX;b_i5P! A'x qUQTboS!,ʫZMϢ~HBp>?^uV5<4sSbNm 3PYzd͊[&9Z/ 6hYT|(qVս1~4'°&[Ҡ\AO ˶;_OFc97<cxh*HL%)*WW'W}7a~m7]sotojn|]ơp`qKd-(k*7}r|#-U{)h,F߶.5j UIB&J$SveDt[g]|"]d.bó:/s-3e4ؓ0/:jY;^yujŘkV)G0s#m q\6r3 4gHB%Gp=C4+h X1/C5֮DG&AwYWr2DLe%-\aacj,kSZ.ИI@[O'@K/4| *tN:)SȆoʔj-f1KNR{Ӱ<܂{ HULm`F#;. iwZJ?3:5{EQ(4A*(<]f<\&7Qx~-.DX6,5HSg9(XA_vy73 dO}:6c![ XRثhRÌ Iv?0[sA'SG`D)"D|XUM^;6uAEWNA_YOT y\ jĦ>j;qNdgaGp[^̉MNN> Kfo{C$P,ë |E9FYa)8'ͪ8kŒ_QSltO9kTŬu Ǜkȧ*I'xKa1w_򰲪Cmqe =$j!RZsxU|Kaj ]c6y| Fz|k.DhoZӱN]2+׋8\pLp];3Ն, ^gU:$խ {_Y0cyK$h_0?T:d'Yh۸5AEuj0)ȾU,]`/֟r *{JT 8_m/ bhTGCdxMR8K2v[ɿ~oI oOtJy f2ΨmyM J"Np|SPt|+:*ouHCl&m1H;}I"+n~btd:;K%t3Wg,܋F2zZJ!#Ӑ:'65ċ iUPz2*ߵy|51с]RKh`nbHYp)7 on4J S (+|cPiF:vz %b>J)=d`"Z7u R *hdf<=|%.qfr <+iiJҺ?tFYxW*~ H$`52XN)ן{<3I*uD gRq$_U>q='z^¯PMgcdvRqSiN AD\Wa~Ytde_"䗦xFzX\+ni^LzEqO''_a҉asNctm4X22ݣ7%OW;shNB:nwqXz ̘(;'c4/WdB[ 2R2ZRK #ۨu[}aTULz4RAvoW%7*QDm]{,gE,=4"ٰ)Ϩe/%G#}Gi͜`[ۻ-#.Ag20 rJt話r>op/8֓׋,C$<qMewXO}h kue+dC)}ϼ e3n*^"9Vد_}17M_Gwǜ'ulg~&1G6$HOܚrL{_puhk Si- h톣hzf.#d5"t{U:V4yCZyGv<;cޅP3HgVZ. 0)wIS`^Y;8<d0%`E\NAEUXnt *5LD>i0ZԽ|*Kh; sX <ɩޭnF{F,pMƴ0fk7[x ܡpfH (gtcOKRۥZ~Io]y7L-uCoVtIF,UP;Kd&v׋ o8f1;pB̪}_"k Y" /6omE9Ne;t湂rqE8)Ԉҧe FhqgӝYE& Yhi2E@K\!*xzgl8,J@x+6JSŅb iAy-C _Em$Y¼qm9p&m=L(sk LE@ d]-]p֏gO ŭS#wKGl/jѺܟW(e6B0+)BA뻿g32.OYFnT]cPk+Gmxx!xH~]p("2q{A^V| g]WUAtjqeqQ izǨ[&Αi;ƣ8aD4ߒZɏ 89n;Wnf6(TU/D ">b<*S$A4ۦ{[բ{ >XDkdo]67kS:lr dbnC`+%Bf&_A߼VydiRF!% n2ESw5X2O`hBQrYN')3؅iŨM JY0:@E v BP&S>oiH|GTEȡwU 8)H")FszZ9>?e ҁ>\oшnW"u'Q)\ :3 Y/\1 &|`j!H?T}Sv37X $"E&@iof>qQ|ެz]s!)ے$03y;B0̱4u $@ x6>H ֓nK߻ M-wJC-\[=*!\&Z 88ZnRGK}mm`9?>++>BRWF{m5ܻ !XjAUĚ"%sQUr)JuT~Ci.tJOD lx/]y(%[P.ZgGi̯}:~g;l͍af>oYT\VC=JUhRz# k_=3{]KTXQEK )ϚQ V:D%ltgrSBkвZЄ_)7W"h|Q(?:ѓg?xёyvR ]2P1ŽiTne^ω k'GHRjR;H4u3V xn&Fȳ) B;Ϟk׃ y+⶜2s{^D (x ޑ کKڋ"1H7mΡ\v|(-0Z8o˓bt