cryptsetup-2.3.7-150300.3.5.1<>, aeSp9|P:]]n/ BQR(¼WzU Rޭڈ+7SpZhfZˑo=b,w1~}(W ~L)Ae.KaM;PoR' SklLQ4~.%}$b]`U!\T>r4aM*DYW+aKd {XMY[E,GHjzJd ԅ T\&i0z&dZD3N7.y-$ M(TJRfr骖=%2ݱMaа>D?d   Y .:djqMDD ,D D D D `DpDD@DPp( 8 9 :">@FGDH(DI8DX|Y\D]D^} b1cd_edfgliu|Dv w<DxLDy\MzEPTZCcryptsetup2.3.7150300.3.5.1Setup program for dm-crypt Based Encrypted Block Devicescryptsetup is used to conveniently set up dm-crypt based device-mapper targets. It allows to set up targets to read cryptoloop compatible volumes as well as LUKS formatted ones. The package additionally includes support for automatically setting up encrypted volumes at boot time via the config file /etc/crypttab.aeSsheep57 4SUSE Linux Enterprise 15SUSE LLC SUSE-GPL-2.0-with-openssl-exception AND LGPL-2.0-or-laterhttps://www.suse.com/System/Basehttps://gitlab.com/cryptsetup/cryptsetup/linuxx86_64 mkdir -p /run/regenerate-initrd/ touch /run/regenerate-initrd/all [ -z "${TRANSACTIONAL_UPDATE}" -a -x /usr/bin/systemd-tmpfiles ] && /usr/bin/systemd-tmpfiles --create /usr/lib/tmpfiles.d/cryptsetup.conf || : mkdir -p /run/regenerate-initrd/ touch /run/regenerate-initrd/all#$ Xpe N i:y^ 7!%9C E  [+AhG7".lg*tP IrjoZ  @A큤A큤aeRaeQaeQaeQaeQaeQaeQaeR`W`WaaaO1d`O1d`O1d`O1d`O1d`O1d``WO1d``WO1d`OSO&`WP}Pa)QNS$S$S$SS UCVN)][`FT`FT`FT`FT`FT`W`W`W`W`W`W`W`W`W`W`Wa a a a a a a aaeRO1d`PȈaeQaeQaeQaeQd6bb4b689200c2348945700a6b0dad5df92bc2015860d15f36a25590814d77b00a53dab894e3f5c04ad55bbcf94fedb402b2107b94e35d8e9ac792bd8162fd764244969bb2a199154ab911635b33abe0c79324942603aea68254897199e06ba6fd76572684d815b7929d225850ee66c9af510c416819a4c65e2db78de25f8a350aaf9da5c3d8a247cb1b0a0d9499cd0c755665ce68e275937c4cca0342c545e0012a99c581df2f922c8996d25fb19b13eba7776bb7ceb6b79f97c312088458203399dbc567343bbd6a5ff5d73de53bb39b7f8118af6bee31e171f6e6a3de4de00f3e0f44f68cc2a19b62e5b50369c7635b3ab80de75215fd7f43f4e9f0bde86a11c40bc50779d525750af7fcda5d7b7559fe37453d28130ddc7028ac4c6c43f6325800b1569fc977bde2337bffdd20077a5b5dd98f172c944e32b75a19556e3504505ff6feb42cb3fc27cd79c52b0a8dd446ebac636db57e47b466f2fb6f870e0b3b98db51402d5c6b54a76f049fe834f385bb0a81a195148c217776c29abb2885f985ae4dd6fa76e34b4abff697d973821ac6bb255e00ec8844fbf9fd7d936c0db4517a88ecd842a1ea48360c45563ef051ba71d51d6e5d40e240516536d8b7972e5fc2fc53522a41cf685cde1ed92ab42df50f608dad44b533a20d1468ba2ae01c5c98071c7c98d4d62b7af278c2c3c38a89a9f2aea7811e8078f34a6eaa99f921b65038a98a6281769a64e90528394c11e9f58978945cfbf058bd72d251bbd9f325cc7b69e35a3235b851f6e3d8db5d01d717afac72ba452ddca753be93df085ea8c727c1487e11b032c9357a5187ec8ef86d16f0bbb3d8f357ad4cf780c425b2628be5d85dad2656f925cee0b464f53c3a669223fb6a43dc581a27fbbbc5f6e280116a8aa26191a7f768e9dab9d82735c4b48a4aad0824763d081418a034a40f6b268b8cfbabdfe510845bf2de9d20af02dc914a3eebfc7bab6697989cc817443d3606ecf579a00565290e63c1f53c0520bf78473014d45cb7c7938a187d758112ba6c3946c2b6fa183d6a3662b3b34c09ebb40140613400e779506f22b7e005ddf07eb9e34df8ddfb5a6b053e7f1a57b4e44ebebf4c14ad2725bc3c40790fdac009890d44f3383abd33132f3f6e5e2114b5cc22df9a8b90cff57b061562ae48b74ffa53d0870533233fd1052e3f707216cf5f4f5941b0a67a5fc4a061e9d198ff7ffb01319f58779842a605461416c316bdf058e6e9091be4a69251bfe3556c7156ea0bfcd002f24822c0ba3cdd2cebfa9dc6b2463fe259b455c858bd7ebe5988a8fa6a4715c6bd4115489dbbc697f5a5b34058fc475b7c0db7f5faa108eefef8259641d4e435288c77eaa861163c2ce048a82cac90d17ddaa9adefe6a0b0f5fd155f4a31e4b4c3b3a31833d66f425462368041359d6a3165839ba3d51ee8b791da4adbf42e9b8aecd710112cf0a60bc6f9dcfa2f9caf91dcd6559d630eff407694c22b8a7f3217e5987a59b232ca2c7ea4cd3014c1c5fd4c941b0b767fd8d3246cbf48031d37564c8e6b56394dfbce815f6977954291049b53e440d880b42705939d9a513836df7abf4ffa7155ff9a1d2b1cf4c132390aaaa81594537ebee834ef41dd79e3430310491ccd9afd39971af54a580151557aaa9b9b822912260109b314fec98a14b4e525681877a2205703f005ca6aa56ae54a692356508326d024e1af8779187808b94aac22d36fd2b16c1be1f9bd7062999e28638cf4bd50f9c18e06632bc8660889bf0f45d52f09d6491d5291fe8619b329f6495be879093e92fb88c7c771bc0ba7da4f99386c80e0da2637249fe7fd99a57966d1d1e20dfae75a4967bd4676a882e6c13c121806f093d7e9426ce22275f598942b4fb7509951305b214b8b8f847e4ba4b26a3d9654105680cc2e7fdadd4c5c2260b6e19016a7ba548ea78bb8c562a4a1c68753bcab7104110d3df6fa239d54bdd8edc6c165c348ead91ad0e6ceea6aaeea0f71128d8187b4583eef22f3f3eba95a642bb9587909ff0eca1c2951afba46b0197f4b7c5428eb5a85bf730e9f756aa2859375a208dc1bb810cd2e4b073f1f6b5aad915dadbd5f03832a42c2225629c3065194a409b6dd3d911af16aae131e5e381ddcd08b58b698344d75f566edb6339f3b506a9645b7138611896178336bb6e116a0d31689723ed8aec4e11e13325b28343fc1552fc80c1896c7d7dd2c722bead9f62e9bfba917cc60cdea64838a6a2ea98637579ab402ab6e84c2669d86f6871ca6ae66ed9e74cea43ab42c767c2bc67125df067f0d6fa1a9a4f9aa405e0bbbe0972abf680102bf1a0e7292ba4dbebf11c4dce28845a7b2087675fc3c56468dd8ce61fbe1f1f30939ce8d2346c8d7d705c49522ac2e9047f37535b313e9c76be539d32fc224cfe78f39a411a2f32aa0a2cb152e6c7826e492c14a26741c1949e607de2a36d7d61f5e680fd9884baf001f186cde72e155b5ca5330400489662ef8add809175057a87661ab22029d875615ebc127f67b0d3506bb9058e347d31012676c78096d04ab7caa3644ff1da90435d9e77180d0166fb509883e10c6c846b3b7228e8d6ea553ed112c0a19cb8626f145670cce8b6a0ddd66c8016cd8ccef6cd71f35717cbacc7f1e895b3855207b338c33cc37871654ec7ed87e6fbb896c8cf33ef5ef05b1611a5aed857596ffafa55044777c24525ad009139b433028a38af6c032aa3767038fd72924659fb358c6de797e7119c92c22ff9bbce299b2471ab912ac18a77b6e1ea6666ea6c067aa763bccbf6c2ca5ed2a22c5cc474b5373ef0a7cf92b64da818833bf6f41738fd7786eefeec004e51ed4e57026fda94812342c6f4bf75a030840412af0371471c2bc/usr/sbin/cryptsetup@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcryptsetup-2.3.7-150300.3.5.1.src.rpmcryptsetupcryptsetup(x86-64) @@@@@@@@@@@@@@@@@@@@@    /bin/sh/bin/sh/bin/shcoreutilscoreutilslibblkid.so.1()(64bit)libblkid.so.1(BLKID_2.15)(64bit)libblkid.so.1(BLKID_2.17)(64bit)libblkid.so.1(BLKID_2.21)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcryptsetup.so.12()(64bit)libcryptsetup.so.12(CRYPTSETUP_2.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpwquality.so.1()(64bit)libpwquality.so.1(LIBPWQUALITY_1.0)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3aZ@aq@`ݮ@`L@`KW_j__R,@^ϧ^^9\]W\f\f[G[G[{Zp^@Z64 bytes) passphrases- Split translations to -lang package - New version to 2.3.1 * Support VeraCrypt 128 bytes passwords. VeraCrypt now allows passwords of maximal length 128 bytes (compared to legacy TrueCrypt where it was limited by 64 bytes). * Strip extra newline from BitLocker recovery keys There might be a trailing newline added by the text editor when the recovery passphrase was passed using the --key-file option. * Detect separate libiconv library. It should fix compilation issues on distributions with iconv implemented in a separate library. * Various fixes and workarounds to build on old Linux distributions. * Split lines with hexadecimal digest printing for large key-sizes. * Do not wipe the device with no integrity profile. With --integrity none we performed useless full device wipe. * Workaround for dm-integrity kernel table bug. Some kernels show an invalid dm-integrity mapping table if superblock contains the "recalculate" bit. This causes integritysetup to not recognize the dm-integrity device. Integritysetup now specifies kernel options such a way that even on unpatched kernels mapping table is correct. * Print error message if LUKS1 keyslot cannot be processed. If the crypto backend is missing support for hash algorithms used in PBKDF2, the error message was not visible. * Properly align LUKS2 keyslots area on conversion. If the LUKS1 payload offset (data offset) is not aligned to 4 KiB boundary, new LUKS2 keyslots area in now aligned properly. * Validate LUKS2 earlier on conversion to not corrupt the device if binary keyslots areas metadata are not correct.- Update to 2.3.0 (include release notes for 2.2.0) * BITLK (Windows BitLocker compatible) device access * Veritysetup now supports activation with additional PKCS7 signature of root hash through --root-hash-signature option. * Integritysetup now calculates hash integrity size according to algorithm instead of requiring an explicit tag size. * Integritysetup now supports fixed padding for dm-integrity devices. * A lot of fixes to online LUKS2 reecryption. * Add crypt_resume_by_volume_key() function to libcryptsetup. If a user has a volume key available, the LUKS device can be resumed directly using the provided volume key. No keyslot derivation is needed, only the key digest is checked. * Implement active device suspend info. Add CRYPT_ACTIVATE_SUSPENDED bit to crypt_get_active_device() flags that informs the caller that device is suspended (luksSuspend). * Allow --test-passphrase for a detached header. Before this fix, we required a data device specified on the command line even though it was not necessary for the passphrase check. * Allow --key-file option in legacy offline encryption. The option was ignored for LUKS1 encryption initialization. * Export memory safe functions. To make developing of some extensions simpler, we now export functions to handle memory with proper wipe on deallocation. * Fail crypt_keyslot_get_pbkdf for inactive LUKS1 keyslot. * Add optional global serialization lock for memory hard PBKDF. * Abort conversion to LUKS1 with incompatible sector size that is not supported in LUKS1. * Report error (-ENOENT) if no LUKS keyslots are available. User can now distinguish between a wrong passphrase and no keyslot available. * Fix a possible segfault in detached header handling (double free). * Add integritysetup support for bitmap mode introduced in Linux kernel 5.2. * The libcryptsetup now keeps all file descriptors to underlying device open during the whole lifetime of crypt device context to avoid excessive scanning in udev (udev run scan on every descriptor close). * The luksDump command now prints more info for reencryption keyslot (when a device is in-reencryption). * New --device-size parameter is supported for LUKS2 reencryption. * New --resume-only parameter is supported for LUKS2 reencryption. * The repair command now tries LUKS2 reencryption recovery if needed. * If reencryption device is a file image, an interactive dialog now asks if reencryption should be run safely in offline mode (if autodetection of active devices failed). * Fix activation through a token where dm-crypt volume key was not set through keyring (but using old device-mapper table parameter mode). * Online reencryption can now retain all keyslots (if all passphrases are provided). Note that keyslot numbers will change in this case. * Allow volume key file to be used if no LUKS2 keyslots are present. * Print a warning if online reencrypt is called over LUKS1 (not supported). * Fix TCRYPT KDF failure in FIPS mode. * Remove FIPS mode restriction for crypt_volume_key_get. * Reduce keyslots area size in luksFormat when the header device is too small. * Make resize action accept --device-size parameter (supports units suffix).- Create a weak dependency cycle between libcryptsetup and libcryptsetup-hmac to make sure they are installed together (bsc#1090768)- Use noun phrase in summary.- New version 2.1.0 * The default size of the LUKS2 header is increased to 16 MB. It includes metadata and the area used for binary keyslots; it means that LUKS header backup is now 16MB in size. * Cryptsetup now doubles LUKS default key size if XTS mode is used (XTS mode uses two internal keys). This does not apply if key size is explicitly specified on the command line and it does not apply for the plain mode. This fixes a confusion with AES and 256bit key in XTS mode where code used AES128 and not AES256 as often expected. * Default cryptographic backend used for LUKS header processing is now OpenSSL. For years, OpenSSL provided better performance for PBKDF. * The Python bindings are no longer supported and the code was removed from cryptsetup distribution. Please use the libblockdev project that already covers most of the libcryptsetup functionality including LUKS2. * Cryptsetup now allows using --offset option also for luksFormat. * Cryptsetup now supports new refresh action (that is the alias for "open --refresh"). * Integritysetup now supports mode with detached data device through new --data-device option. - 2.1.0 would use LUKS2 as default, we stay with LUKS1 for now until someone has time to evaluate the fallout from switching to LUKS2.- Suggest hmac package (boo#1090768) - remove old upgrade hack for upgrades from 12.1 - New version 2.0.5 Changes since version 2.0.4 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Wipe full header areas (including unused) during LUKS format. Since this version, the whole area up to the data offset is zeroed, and subsequently, all keyslots areas are wiped with random data. This ensures that no remaining old data remains in the LUKS header areas, but it could slow down format operation on some devices. Previously only first 4k (or 32k for LUKS2) and the used keyslot was overwritten in the format operation. * Several fixes to error messages that were unintentionally replaced in previous versions with a silent exit code. More descriptive error messages were added, including error messages if - a device is unusable (not a block device, no access, etc.), - a LUKS device is not detected, - LUKS header load code detects unsupported version, - a keyslot decryption fails (also happens in the cipher check), - converting an inactive keyslot. * Device activation fails if data area overlaps with LUKS header. * Code now uses explicit_bzero to wipe memory if available (instead of own implementation). * Additional VeraCrypt modes are now supported, including Camellia and Kuznyechik symmetric ciphers (and cipher chains) and Streebog hash function. These were introduced in a recent VeraCrypt upstream. Note that Kuznyechik requires out-of-tree kernel module and Streebog hash function is available only with the gcrypt cryptographic backend for now. * Fixes static build for integritysetup if the pwquality library is used. * Allows passphrase change for unbound keyslots. * Fixes removed keyslot number in verbose message for luksKillSlot, luksRemoveKey and erase command. * Adds blkid scan when attempting to open a plain device and warn the user about existing device signatures in a ciphertext device. * Remove LUKS header signature if luksFormat fails to add the first keyslot. * Remove O_SYNC from device open and use fsync() to speed up wipe operation considerably. * Create --master-key-file in luksDump and fail if the file already exists. * Fixes a bug when LUKS2 authenticated encryption with a detached header wiped the header device instead of dm-integrity data device area (causing unnecessary LUKS2 header auto recovery).- make parallell installable version for SLE12- New version 2.0.4 Changes since version 2.0.3 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Use the libblkid (blockid) library to detect foreign signatures on a device before LUKS format and LUKS2 auto-recovery. This change fixes an unexpected recovery using the secondary LUKS2 header after a device was already overwritten with another format (filesystem or LVM physical volume). LUKS2 will not recreate a primary header if it detects a valid foreign signature. In this situation, a user must always use cryptsetup repair command for the recovery. Note that libcryptsetup and utilities are now linked to libblkid as a new dependence. To compile code without blockid support (strongly discouraged), use --disable-blkid configure switch. * Add prompt for format and repair actions in cryptsetup and integritysetup if foreign signatures are detected on the device through the blockid library. After the confirmation, all known signatures are then wiped as part of the format or repair procedure. * Print consistent verbose message about keyslot and token numbers. For keyslot actions: Key slot unlocked/created/removed. For token actions: Token created/removed. * Print error, if a non-existent token is tried to be removed. * Add support for LUKS2 token definition export and import. The token command now can export/import customized token JSON file directly from command line. See the man page for more details. * Add support for new dm-integrity superblock version 2. * Add an error message when nothing was read from a key file. * Update cryptsetup man pages, including --type option usage. * Add a snapshot of LUKS2 format specification to documentation and accordingly fix supported secondary header offsets. * Add bundled optimized Argon2 SSE (X86_64 platform) code. If the bundled Argon2 code is used and the new configure switch - -enable-internal-sse-argon2 option is present, and compiler flags support required optimization, the code will try to use optimized and faster variant. Always use the shared library (--enable-libargon2) if possible. This option was added because an enterprise distribution rejected to support the shared Argon2 library and native support in generic cryptographic libraries is not ready yet. * Fix compilation with crypto backend for LibreSSL >= 2.7.0. LibreSSL introduced OpenSSL 1.1.x API functions, so compatibility wrapper must be commented out. * Fix on-disk header size calculation for LUKS2 format if a specific data alignment is requested. Until now, the code used default size that could be wrong for converted devices. Changes since version 2.0.2 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Expose interface to unbound LUKS2 keyslots. Unbound LUKS2 keyslot allows storing a key material that is independent of master volume key (it is not bound to encrypted data segment). * New API extensions for unbound keyslots (LUKS2 only) crypt_keyslot_get_key_size() and crypt_volume_key_get() These functions allow to get key and key size for unbound keyslots. * New enum value CRYPT_SLOT_UNBOUND for keyslot status (LUKS2 only). * Add --unbound keyslot option to the cryptsetup luksAddKey command. * Add crypt_get_active_integrity_failures() call to get integrity failure count for dm-integrity devices. * Add crypt_get_pbkdf_default() function to get per-type PBKDF default setting. * Add new flag to crypt_keyslot_add_by_key() to force update device volume key. This call is mainly intended for a wrapped key change. * Allow volume key store in a file with cryptsetup. The --dump-master-key together with --master-key-file allows cryptsetup to store the binary volume key to a file instead of standard output. * Add support detached header for cryptsetup-reencrypt command. * Fix VeraCrypt PIM handling - use proper iterations count formula for PBKDF2-SHA512 and PBKDF2-Whirlpool used in system volumes. * Fix cryptsetup tcryptDump for VeraCrypt PIM (support --veracrypt-pim). * Add --with-default-luks-format configure time option. (Option to override default LUKS format version.) * Fix LUKS version conversion for detached (and trimmed) LUKS headers. * Add luksConvertKey cryptsetup command that converts specific keyslot from one PBKDF to another. * Do not allow conversion to LUKS2 if LUKSMETA (external tool metadata) header is detected. * More cleanup and hardening of LUKS2 keyslot specific validation options. Add more checks for cipher validity before writing metadata on-disk. * Do not allow LUKS1 version downconversion if the header contains tokens. * Add "paes" family ciphers (AES wrapped key scheme for mainframes) to allowed ciphers. Specific wrapped ley configuration logic must be done by 3rd party tool, LUKS2 stores only keyslot material and allow activation of the device. * Add support for --check-at-most-once option (kernel 4.17) to veritysetup. This flag can be dangerous; if you can control underlying device (you can change its content after it was verified) it will no longer prevent reading tampered data and also it does not prevent silent data corruptions that appear after the block was once read. * Fix return code (EPERM instead of EINVAL) and retry count for bad passphrase on non-tty input. * Enable support for FEC decoding in veritysetup to check dm-verity devices with additional Reed-Solomon code in userspace (verify command). Changes since version 2.0.1 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Fix a regression in early detection of inactive keyslot for luksKillSlot. It tried to ask for passphrase even for already erased keyslot. * Fix a regression in loopaesOpen processing for keyfile on standard input. Use of "-" argument was not working properly. * Add LUKS2 specific options for cryptsetup-reencrypt. Tokens and persistent flags are now transferred during reencryption; change of PBKDF keyslot parameters is now supported and allows to set precalculated values (no benchmarks). * Do not allow LUKS2 --persistent and --test-passphrase cryptsetup flags combination. Persistent flags are now stored only if the device was successfully activated with the specified flags. * Fix integritysetup format after recent Linux kernel changes that requires to setup key for HMAC in all cases. Previously integritysetup allowed HMAC with zero key that behaves like a plain hash. * Fix VeraCrypt PIM handling that modified internal iteration counts even for subsequent activations. The PIM count is no longer printed in debug log as it is sensitive information. Also, the code now skips legacy TrueCrypt algorithms if a PIM is specified (they cannot be used with PIM anyway). * PBKDF values cannot be set (even with force parameters) below hardcoded minimums. For PBKDF2 is it 1000 iterations, for Argon2 it is 4 iterations and 32 KiB of memory cost. * Introduce new crypt_token_is_assigned() API function for reporting the binding between token and keyslots. * Allow crypt_token_json_set() API function to create internal token types. Do not allow unknown fields in internal token objects. * Print message in cryptsetup that about was aborted if a user did not answer YES in a query.- update to 2.0.1: * To store volume key into kernel keyring, kernel 4.15 with dm-crypt 1.18.1 is required * Increase maximum allowed PBKDF memory-cost limit to 4 GiB * Use /run/cryptsetup as default for cryptsetup locking dir * Introduce new 64-bit byte-offset *keyfile_device_offset functions. * New set of fucntions that allows 64-bit offsets even on 32bit systems are now availeble: - crypt_resume_by_keyfile_device_offset - crypt_keyslot_add_by_keyfile_device_offset - crypt_activate_by_keyfile_device_offset - crypt_keyfile_device_read The new functions have added the _device_ in name. Old functions are just internal wrappers around these. * Also cryptsetup --keyfile-offset and --new-keyfile-offset now allows 64-bit offsets as parameters. * Add error hint for wrongly formatted cipher strings in LUKS1 and properly fail in luksFormat if cipher format is missing required IV.- Update to version 2.0.0: * Add support for new on-disk LUKS2 format * Enable to use system libargon2 instead of bundled version * Install tmpfiles.d configuration for LUKS2 locking directory * New command integritysetup: support for the new dm-integrity kernel target * Support for larger sector sizes for crypt devices * Miscellaneous fixes and improvements- Update to version 1.7.5: * Fixes to luksFormat to properly support recent kernel running in FIPS mode (bsc#1031998). * Fixes accesses to unaligned hidden legacy TrueCrypt header. * Fixes to optional dracut ramdisk scripts for offline re-encryption on initial boot.- Update to version 1.7.4: * Allow to specify LUKS1 hash algorithm in Python luksFormat wrapper. * Use LUKS1 compiled-in defaults also in Python wrapper. * OpenSSL backend: Fix OpenSSL 1.1.0 support without backward compatible API. * OpenSSL backend: Fix LibreSSL compatibility. * Check for data device and hash device area overlap in veritysetup. * Fix a possible race while allocating a free loop device. * Fix possible file descriptor leaks if libcryptsetup is run from a forked process. * Fix missing same_cpu_crypt flag in status command. * Various updates to FAQ and man pages. - Changes for version 1.7.3: * Fix device access to hash offsets located beyond the 2GB device boundary in veritysetup. * Set configured (compile-time) default iteration time for devices created directly through libcryptsetup * Fix PBKDF2 benchmark to not double iteration count for specific corner case. * Verify passphrase in cryptsetup-reencrypt when encrypting a new drive. * OpenSSL backend: fix memory leak if hash context was repeatedly reused. * OpenSSL backend: add support for OpenSSL 1.1.0. * Fix several minor spelling errors. * Properly check maximal buffer size when parsing UUID from /dev/disk/.- Update to version 1.7.2: * Update LUKS documentation format. Clarify fixed sector size and keyslots alignment. * Support activation options for error handling modes in Linux kernel dm-verity module: - -ignore-corruption - dm-verity just logs detected corruption - -restart-on-corruption - dm-verity restarts the kernel if corruption is detected If the options above are not specified, default behavior for dm-verity remains. Default is that I/O operation fails with I/O error if corrupted block is detected. - -ignore-zero-blocks - Instructs dm-verity to not verify blocks that are expected to contain zeroes and always return zeroes directly instead. NOTE that these options could have security or functional impacts, do not use them without assessing the risks! * Fix help text for cipher benchmark specification (mention --cipher option). * Fix off-by-one error in maximum keyfile size. Allow keyfiles up to compiled-in default and not that value minus one. * Support resume of interrupted decryption in cryptsetup-reencrypt utility. To resume decryption, LUKS device UUID (--uuid option) option must be used. * Do not use direct-io for LUKS header with unaligned keyslots. Such headers were used only by the first cryptsetup-luks-1.0.0 release (2005). * Fix device block size detection to properly work on particular file-based containers over underlying devices with 4k sectors. - Update to version 1.7.1: * Code now uses kernel crypto API backend according to new changes introduced in mainline kernel While mainline kernel should contain backward compatible changes, some stable series kernels do not contain fully backported compatibility patches. Without these patches most of cryptsetup operations (like unlocking device) fail. This change in cryptsetup ensures that all operations using kernel crypto API works even on these kernels. * The cryptsetup-reencrypt utility now properly detects removal of underlying link to block device and does not remove ongoing re-encryption log. This allows proper recovery (resume) of reencrypt operation later. NOTE: Never use /dev/disk/by-uuid/ path for reencryption utility, this link disappears once the device metadata is temporarily removed from device. * Cryptsetup now allows special "-" (standard input) keyfile handling even for TCRYPT (TrueCrypt and VeraCrypt compatible) devices. * Cryptsetup now fails if there are more keyfiles specified for non-TCRYPT device. * The luksKillSlot command now does not suppress provided password in batch mode (if password is wrong slot is not destroyed). Note that not providing password in batch mode means that keyslot is destroyed unconditionally.- update to 1.7.0: * The cryptsetup 1.7 release changes defaults for LUKS, there are no API changes. * Default hash function is now SHA256 (used in key derivation function and anti-forensic splitter). * Default iteration time for PBKDF2 is now 2 seconds. * Fix PBKDF2 iteration benchmark for longer key sizes. * Remove experimental warning for reencrypt tool. * Add optional libpasswdqc support for new LUKS passwords. * Update FAQ document.- Fix missing dependency on coreutils for initrd macros (boo#958562) - Call missing initrd macro at postun (boo#958562)- Update to 1.6.8 * If the null cipher (no encryption) is used, allow only empty password for LUKS. (Previously cryptsetup accepted any password in this case.) The null cipher can be used only for testing and it is used temporarily during offline encrypting not yet encrypted device (cryptsetup-reencrypt tool). Accepting only empty password prevents situation when someone adds another LUKS device using the same UUID (UUID of existing LUKS device) with faked header containing null cipher. This could force user to use different LUKS device (with no encryption) without noticing. (IOW it prevents situation when attacker intentionally forces user to boot into different system just by LUKS header manipulation.) Properly configured systems should have an additional integrity protection in place here (LUKS here provides only confidentiality) but it is better to not allow this situation in the first place. (For more info see QubesOS Security Bulletin QSB-019-2015.) * Properly support stdin "-" handling for luksAddKey for both new and old keyfile parameters. * If encrypted device is file-backed (it uses underlying loop device), cryptsetup resize will try to resize underlying loop device as well. (It can be used to grow up file-backed device in one step.) * Cryptsetup now allows to use empty password through stdin pipe. (Intended only for testing in scripts.)- Enable verbose build log.- regenerate the initrd if cryptsetup tool changes (wanted by 90crypt dracut module)- Update to 1.6.7 * Cryptsetup TCRYPT mode now supports VeraCrypt devices (TrueCrypt extension) * Support keyfile-offset and keyfile-size options even for plain volumes. * Support keyfile option for luksAddKey if the master key is specified. * For historic reasons, hashing in the plain mode is not used if keyfile is specified (with exception of --key-file=-). Print a warning if these parameters are ignored. * Support permanent device decryption for cryptsetup-reencrypt. To remove LUKS encryption from a device, you can now use - -decrypt option. * Allow to use --header option in all LUKS commands. The - -header always takes precedence over positional device argument. * Allow luksSuspend without need to specify a detached header. * Detect if O_DIRECT is usable on a device allocation. There are some strange storage stack configurations which wrongly allows to open devices with direct-io but fails on all IO operations later. * Add low-level performance options tuning for dmcrypt (for Linux 4.0 and later). * Get rid of libfipscheck library. (Note that this option was used only for Red Hat and derived distributions.) With recent FIPS changes we do not need to link to this FIPS monster anymore. Also drop some no longer needed FIPS mode checks. * Many fixes and clarifications to man pages. * Prevent compiler to optimize-out zeroing of buffers for on-stack variables. * Fix a crash if non-GNU strerror_r is used./bin/sh/bin/shsheep57 1642423635  !"#$%&'()*+,-./0123456789:;<=>?@ABCD2.3.7-150300.3.5.12.3.7-150300.3.5.1cryptsetupcryptsetupcryptsetup.confcryptsetupcryptsetup-reencryptintegritysetupveritysetupcryptsetupAUTHORSChangeLog.oldFAQREADMETODOv1.0.7-ReleaseNotesv1.1.0-ReleaseNotesv1.1.1-ReleaseNotesv1.1.2-ReleaseNotesv1.1.3-ReleaseNotesv1.2.0-ReleaseNotesv1.3.0-ReleaseNotesv1.3.1-ReleaseNotesv1.4.0-ReleaseNotesv1.4.1-ReleaseNotesv1.4.2-ReleaseNotesv1.4.3-ReleaseNotesv1.5.0-ReleaseNotesv1.5.1-ReleaseNotesv1.6.0-ReleaseNotesv1.6.1-ReleaseNotesv1.6.2-ReleaseNotesv1.6.3-ReleaseNotesv1.6.4-ReleaseNotesv1.6.5-ReleaseNotesv1.6.6-ReleaseNotesv1.6.7-ReleaseNotesv1.6.8-ReleaseNotesv1.7.0-ReleaseNotesv1.7.1-ReleaseNotesv1.7.2-ReleaseNotesv1.7.3-ReleaseNotesv1.7.4-ReleaseNotesv1.7.5-ReleaseNotesv2.0.0-ReleaseNotesv2.0.1-ReleaseNotesv2.0.2-ReleaseNotesv2.0.3-ReleaseNotesv2.0.4-ReleaseNotesv2.0.5-ReleaseNotesv2.0.6-ReleaseNotesv2.1.0-ReleaseNotesv2.2.0-ReleaseNotesv2.2.1-ReleaseNotesv2.2.2-ReleaseNotesv2.3.0-ReleaseNotesv2.3.1-ReleaseNotesv2.3.2-ReleaseNotesv2.3.3-ReleaseNotesv2.3.4-ReleaseNotesv2.3.5-ReleaseNotesv2.3.6-ReleaseNotesv2.3.7-ReleaseNotescryptsetupCOPYINGCOPYING.LGPLcryptsetup-reencrypt.8.gzcryptsetup.8.gzintegritysetup.8.gzveritysetup.8.gz/run//sbin//usr/lib/tmpfiles.d//usr/sbin//usr/share/doc/packages//usr/share/doc/packages/cryptsetup//usr/share/licenses//usr/share/licenses/cryptsetup//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:22378/SUSE_SLE-15-SP3_Update/8485393a1d890a5df93af49682ef6136-cryptsetup.SUSE_SLE-15-SP3_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=9595536490db5ff2ab010b3c0692416e766e66ca, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=6a019d5659ec0c5f88feb2801c380915b2d86398, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=6e9f259a1c13d1a7685260906935d7523f0facf9, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=1abf053cb3b021c9f96b19967e579a67fdcf2573, for GNU/Linux 3.2.0, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix));RRRRRRR RRR RRR R RRRRRRR RRRRRRRR RR RRR R RRRRRR RRRRRRRRR RRR R RRRRR RRRRRRR RR RRR R RRRRR GC`eV if test -x /usr/lib/module-init-tools/regenerate-initrd-posttrans; then /bin/bash -c 'set +e; /usr/lib/module-init-tools/regenerate-initrd-posttrans' fi #/bin/shutf-8c6a3fb5c8bb5e02f0a58ddf906bbe56a7d25def86ea59ac7d263cd47e077b488?7zXZ !t/lR]"k%a+ٙz |2L[OLSLj}ioC h9)TV_BgPm{{b~w7í8(Qy\xGBLk?e?q{J cM}.f箰8 V|Msl`QRBr#&9Š/䷇`cZJC>y327 WJ>/*X>QƞE{ف*g׃JX̑F qJOf+VF\>ε+Xk%ι>%%;)<4%R)}/yxhWTV+~ !` k`LP\?vwyG>j˂zAvSya:5\.ftp@AʩTD]8C$8ܲQ0`x˩lHD 6 I{C$\PrBIDfly -DAj] P%atYUo Ř>⳸9#mo8*lL߾xXm;{,S6R H݆B\rQCBiKw]"ZE;.VP"PIeS9 KS$}8_64fLVUzFufD/lmX}2p#BEHjH/\mS3{#y^́nZZa CxآJVT"tgS.V꽋U+Gi^ JޏM~[-FLB^FJ$sYp _/7cn6;&4.wN?%W<(q]|} t]Ţn*k{z1Qu:iI!] y( oM{-ɼ,mji1s$R|ZQ,;5A%Ѽ8c,$R9^##@޻rnoYl䪑S$;Eq x 5'@TX[<hN:j)0وY3Vb~(Nb9r*x㣠mKS@ԣr^HvɸJ3k;pidLCW"+#.D2IJ1ui \vǤtHQ88(6$79Jg^S 5pn*@c]{>'m?qhB) ÝLIi-bМuxiu3e5?7ujǺfA7 EYue-K7ug"t 4)ƗfvqjiuIID#L)TNztmOuI7:C;6)_YpqYXH&5njqDSFBbUXn0pD~iŅ&/jY/,R\M 'NuAɷPS|E`Tw+Rq ̰*3!ӥ' bx/mPD^eH^,:ే=Y|M#gpv,@ PޏwC6׆Ӗ/!W}NAi7ԩ-]4O9O$y~T*9/@O@}bFT6rk_W5Pa%$Oެqhq 9Ze@\'צiJB#%=PR%m[%eJ؝|vU1Hko:! YkLcNxפQhck/(vjKU3GeyZww dڪ?YdiCnئ̡ TT&ŕ90:MVVQ.0wEb[O[|OYTK~[)@]φp>9] CF jq 1`]gjm5 q=w\:굈 XEq8jRzl(Bؽr,?뗭Q@}ʐݷlA s?Ra?*&zHwP|&,ԟFb]Dy1% b)I:mVL%H('|P[B;R )N>LoO>K%t;.[u)Ǖ@]sjWmk.ʂt2kkiD+Sɯ)A\Qs|Տ:\׾ tw$=OꉽsN; >2c=XM>'aTQ׈~>({J&QA'եC` S- yd`G wz^UMi.=ƐO#k~(BJ5ȋ*>WQhh|FlG?hPn^+kf˙vhr ܽdĪ :`(K/BX!BkWE_ؠ4ju-qv*U7R"hxdL ,p}zܰIhVn(FUhxf㏍nqм[Bچ!G$:=!bUj}s' wX$Ur.nNl=j :YM';-`6o1# adas;`LA-Rd HA#S;("$Jc0yY}}$A*;n.p,f3._JP4pxKyKl PBɪ#B kZOEo< U yjS`s^҇L/L>AH^(eky9hqԶ|SZm?&vBB]>%ThhuLD%JL;~om'<+acj%5hگ [A8 KT""b)Vz!JH& 3;Z&LSln9<k>d0g._!>%3xOËpKcV۳k@^Mz-w|uT%W/- ^-%4 %( =w`$fZ1=ϏΜv(_ _ҍaǶfȶ-dzk)e0YYkwk6 8 bԂC'7}+չ>ȴxZ}IY[?\>J#j?Dp}a[uqb:a!/:42'( S@F!V9~xNHHtZ4 甼ɣW_D bkcL92x~4p4TШһ_h8k8=9/K>谂zgfQ.BSxˍmj%~ŬUS&5#&29ȇ|;Cr~(M)}Zl\vif+҉qt\> XD>TO/4(}[rm >S: UFW{ъA ~ 1[e72Tz\wjASw(7u>6<-ǷHJ1dM./jΞ?pYJ"똖Ͽb+ٺln+pRilAb)b?)>o<攬HYEWuvPzkvμ(pZp7:1^Ar±[]qV$,,,&4h YdHANXnŌ 2",YF-gUp? 7R_XU:9Hdo[8 QLT `?7~~ c /fᗭƣ>DV8vs8[] LPhs܆AHZ\H67m!d-F"<=uGH5<6o@ s?$qZ~k^M .1Jϭs\  Rj'h0d/=Y+]yNMն׋{6w73OAMǪJ+e36/5k܏ MWGyO _F]ʳ&C(40ճ|K)rEH^͏o?Rec5LUy^ Gů&H t"zR I"޼lM oX L4G(#< ˭9ϯk(=[Ը%,Ç't,`q?9a0'jΐaO/< &Ye ?/ݍ6јfNq$EZjF+LDd- "I$qr`.vH+pmm7T/)(d ޝpEyNS0솼njDJ.pQ7vE\@FaЭ7MV*nZӹSHyzqpHPB@وrqu%"~IX^{!ٱ5G#X4 c`Rg<1=գ#sRˍ>71Ϥn`hjR볎L6]kksEQ5i PTyqϩ7ά.%P\+jL,2\!LGYw:woP蕨WtE oeAggs4>PjsȠmK $;)6h${+~V%hHJ Ptٱ:"S"PU^e `<-WdDqWH8zΛVӣ"CkoW X,;^}`FIl┞v',}2%)/=$VE!^T?O(GeoRRKm~j<EzBc\hlP5ӪolWRRWKztNng}YOW#>7Ӝ.mgNԲ,GThban n񵖱h4:}Wh"s>cqE5r:SLf]w_ -6< S8N9%M|UMmlBԇ(F/O~xE(s^HX&3wM-[x+٣Շ=a|+{~+ uFeK;Ob.>v>xr"ku8 ƴėQ/>gZJɖ%zKX=BQtiWcfJ=  nqiOrlXew/mD>_+01&.¥wb*Yh"K궱#&M 9N=}[ܶ۞P 5Xa#ضPv.뼊 ЌK_ZֹH MA H:oO5Wޗ:c4x+M<|N@Q;hamRcsΧ Zz9cBF-#';-FR6rп|JC#`l)FЮpv8=aCyy_W2E"f>l&xyz3sxKwblx 29TRe\O!,"mGD"7U)l{n],phť3ITO|Q g: Vdmܔ!JT 7dʙhJdﮎ}\) b0ɀpfS˘I he-csS< Rj@WiN۱fCT>:BEBl6L2UYR{U75[F Z;'T|}hF ;gиwZ&Z ^Wf/Pv%K_ΌVB}{YG|0Q%pAhӀo?}qd6_X¢mܚk1CL X=)Ų{`rJXݬ 4oހEo7^cn:}6o- 1ׂ)BqX4X%wobɈe3vMUd v.l:+zA ZȪhڔMy%H>ףḶ6`G7)Ҫ -zLNXT~XT&3̄|iSG$ި\Vt)ӣIgCT9r{s/Ƃx˪Z5TDheҕI~mQ E53d=w_bu+Ppὥ2tάJ|W d4 VٕyvAg Ef7־|]ڋ5>lʘ+X5} dbUF>yBA#\9 ʡ;LRBUHؗԻh5 ,zt'8p')Ek޴i'8|+H''1W7֢A"eBCr-rbj^|K'9f ݨ*/J3äNl%|aYG;uduV:~g0EF5DYΏpԁft`Vy")%/0XBwJofw%.~t-uи('oB,yaŶ;6șǑ){LdTSqƝ1WǩVAy0Bх7 HUjqHKS 7"8p F@e&]n矉3l#jn״2-I<4ի1Z:L+T~υ-ytV(Ƙ ݨr|Y~jyШ`iu Gw5?Xn'd9+"c=Y'0µ7.eHFRt{}  dp3 ܦ[F8WKSTz=8CmN{srX7x-5eqe/VzC}i*9ͅ*C ]>OTe͘GDMr$VE$FNR`I菱8Wa= @$4/Ko(iNy%ɗ(',̓d{ hI% !>;6ñJIg+y؟vj)gAOft~Ra|9%scD eXC|yrS\0AŦepgXV]+H(=iy7Q" c=('Amq>eQCephx2PT v|r/C. m 2{ 4N_$+mZ[K% ͤ/oԦ1t®ive b q*i~Yo S," O5dt# uUsa#3r i٘7tfĵ,rA&k[sH)<*m׳aRzg`Z|UDig34)֘ɶ$^_>` 7ҡx_&nX ik*錠]IbI0'IDzQ@Zn"ܲ/RAuk ~nx/ .$&tz-\֝=ΟGYT2E&^~vJMnC \>i=V;)vqIZ;(OE*IzbF 8}PhXWEnr>p!wA1$'.n& -H@)VH"6*Wd\,U.;s)ze=/RWIՀ/B_7Nu '|su%R4E˭Q!Uyω;E.E>~Ta70H`G&xPq`"3_p=k < Im͆rHթm VVg֪V/uy#P0mNߵ(e7@= 2tȴz9WIV>I7J{1<gp*+'e !۹  @X!FQĠVL_(/ǣD۲-C~|+;sE*f; 7\ҏyc=c^ׄ4?H as?w*W^+Rmyaԍ/NUNf[(0۴w ".Ӂ>)o,3VLF]"_}^v-_H\hfA&xsĻeꝹ}a9(&#QotX.X81Fo7B@jܛ@aG } l3}NlޅhN9藦՟h$P*F<*z-lc'.)r9lV 2<@l;%%ziXr?"BE{TtKQ Cޯ5?-eSA1ke-ŌiI!bE d<@%:O?atrm]08^5fouoΞrxΎtƴyUgSdF(QzBjTdO c0ɩT͘7۬jQRNs5C\L:l? S sڛrU*_yY/I+ׇ]}XLkXs[opɌk#~CvE3=tPWun"wI=tA|hAyqt_?uQqmyAʑB(<2d9=|nl\=7;PeWNbv qʍ=F b9BzPV :MaDlh v=/PkΪS=CPڼUm҉YV{O܋u(i߹)M~{5V[h7;'qFGk8}0a;d9E Tl3tmlRzp5AT]vPr{y ̏u`.w D⻊sۿit冀U'[uX ϋ6b1)M`oLp=B{"J"Wŷ)$k :UL8d\ H3emM)\/;;u턨g8̙īp,p28WHx1{r{H(/v/DP ğ/Oi,'7 t[E*4[9ف-{X%\>?P<(0ƒ^vftIӜܱ{Qj0i_QA9B!"WJ Tm>#=yU F\el90}h*)9TP'qu~1( `me"tOAC=VO>>XpO% - ,nhDn|/%е)(nd&cޏeX}riWD0i'N>.f|^ot^%sp޽Ưq4@;0^$&VX[ӒP ͆qWcyjnxWSZ}k]F[i@0=@1?K}NYB-'DmK(w܌Lx%Qڬ<ۼlg%.| ; Q9Za<;ZI1wfAv͍Ohniٵ$4OYP>^qlӝXO"UЊ!I M9ע&9BQ^]COǽOV+R'`N:;C]#[Ecv+'oڈZfS[gxV窟#_^G c!Psa9OAx MjYO!|ZsJ~͚*P+)MD0ںtjݙ[ `y*|W mß%gTlr}ϑ`Kw ʌ' ő~ mXpB-Q` ٔ\W w 4I `G]I8x2rIz0{1~u%@%#XMBb{aK(/%]naHtveL?v޼ z]i3SpB.҂}?4J߈=\~N5< -`8u-4,:tvV H\v]ԎZ0uw  84$BjhZ$=,=hjL &AN s~ ?ʱG[;~u旛HX5-:?{h:8(А.z8O8B9VGu#RF"V6 wԶ 25`ytL岚V6=Ϩ)~nDM8n 9/0V5%嗳Q`:.ޱ(NV>)'÷n*I.-L;\GjErCi '+\YllGUH˲^} a(#+wj3]+Br}uHḊ #GcFS\6BN9#%^ !{?Eg|m1aYV5W1g{&QsDa:lqNU|ée"4PZiLDXPo_\@lp;d >;d"6R0vjiIZ2(,2* ʒUVdWkż+k@r\ovZZ.d7{_GnؤH(K}(0LcIᚌ4i+t !%.]/A,tA!ߋ)VNzPӵz`斮Fum}W SHy\izq*zd+ǻ(C K ]Vxo4\0+1My.y0]5='șFlp!Z?u8UyV{',:=~="<ć=>gF#le;iHbbBSD~^ ڝfW䃹3Mw$rWIf25=B5ʳPz%;y o/8_63(1l3{<>Y=1pfZ6OWI0yOzKq0 P}em2ve(x f^i&@JX!~YC[Yp9!)cjq*|.tPػ,i`t'KMFԙ3 u6ѵI(StE%*}PElW)61LR$sA7i P2Ll(͓4,izg@ ;g!m!zy5!ϕ-cԘRm_x][T= &VCdŸ[.( ܞe {q7G "a۔@lX(s5@ff#[I% DՅnmSϧ*$YSdPJ7xHܟ:eC0PD.r4Ǐlxyed_Ł@J)&fS9G/Е >2:@WPD^н WZL7Dd FG;sVz:U:xVj s?Ku$ހAuse9?~u^Rٕ͘;IrfقmVT(L7ܢ۔s!mq62Y✏PDIqnI3ge^Z7 C&\f#z Z?$z|LϠaIh(:^6vx&Ekif|u&Vf ckld\̃AV\f%z\d>ZSj𰹕LT|0RMţG^`|״!+96 <>u-v4HSR-6-wV&wͤUS!4O庍Rqi xPO gՙt&Rab-Q. ?B2L\1&Bc9cݨs|;u#ΔWSlK{{IXYL7ܺlTu֠:MB!BG`E!oy\ :z gOJZY5dy֏ed{m[~ x%V/:R3u\x#9-Ge+r) (cѰ zBv2i 6nCA<s|g yys`swJp@kϻg{]]ņŢm=͜@hT8Gƴ&N!|p=g}16Uݗ0XɌrjsޒSJ׸% s0Ƹk(  [܃M ï̭P^щ`X92T%ek>nٶ{ _H W!ue stջ ԑ|<oZ!P/t̮E2Kf0WD'i5R,5l$paz{|1!cRm>|2q<^)"uYCgE+e_#aЙ5W)q;%W*Xi],9FlZc.@4ղoOқawflOX0}Gb7ryW kc#̙XA2cJAjOnPsV=Ex(WO+V~ YYb Wᶻ][J;0NWC[ t h2QN.&OAiԢC~rtZO]|ߎwzUɔ*2&tMlYK/eEܣ)N^osBl\`L6y56e:cFZD.%RU|BM vgO-0@||E]0k,Cbϕ:A鬏kS”LX{/.VXR[]yY-ԡr1W}] Lsgq<{ӄT9("5'r eb8BSq5,}$\$I O8\ G\@+Ȃn+xZWaauHKOwU &`}2,Kʟ,U0Z=u ha@,)j'=Z $ZJ'^w "j<#66Zm$ >ئ=o/x%hʒAjz-j)sP5ℯB[z8Xe<ܯB6=h*\a6 VS=Bw)Z~##}Oa7o/fnz,patpVFJ9ZDЈm-$|X=qQ5,BKӐ5i+"N8w)T\ øcI TQ;s  88ŻO!Ȋ }(9G Ć8ev:q=J,|1p)&ׁ R,gMJ ۏA'5Y0fv=r k"AE>F>!2SM{# &*T4)Yl׈T5Revtq&(rDWfR/ '}rB ŴێƠZ䝓T-h0Epܩ'L!d%niP Ϣ)b?aarTyi"/%OČb.aM /+rrSgtߗDu7\|a>Gj4B%֏'B8IpL21XB&ge20tLNy}Qh~QՊPS <ʡiSca`=U:H4!6MEjN9K? S4PGˤq`pp*u'5/.;aI3pRm6ЄTo>n!¥?#0BsFmdR$H4trKϲmMP$|ZE.x2N,kr_q#DtWu r;ߜ+k6܃}^E u]oJ$g@K+Zdž!h.qgOБdL鄅fQn~oY-UڦgxOHw yDIlk>s%K}[UM6 i{=cy&h?onfǑ|1.e 8ῂ6K$y11ijD. `%Ǵ,]'jm/1t ڎ:*>G!P⪜H.K |#ݺO]̡<"͝s Cqd?sguN3/':7n67ڸԱCuQ Ek5,0ǭD%>Ӳ@r)D>L;QJfouFq= mH:QxŠFhPܲ[&`[.}SiKa>+kKŴSdnέv24S_X`aQdͽn0zSpѐnRZ{|VBjQ~B2օ,2nGveD']JRZ'&Sjp$$_/Ñ1o9f=JĊv0j̐xW8J-OQW(G9/)׺8Hqvj9&yKt%c=R v]hm6L˷rpѺ\m,, bAloq9 &jJ<{ו0\wbc=գݵ/0zjb%yV" _&[/ NZGH>'So! ʍ FDkfnc-w V%!+ z̅u1YRF3T.h \IS`1u`}nx?vVi sβ),t5XyP]>\cPN@9r4yʷ H}\.-й nMtTcfV 9eQDžvt7x57S.1\k9͆XYi95$n%oOkKLgfyUlI[`NLg3xeq'JQ5~ >bW{!{rp;ґ!i2e>Ă'o )$)VaIf`'9=LgH|GՔVę{K^-PGiKi͊"4F1 &ɼkmNC1X7n8zХ e2GRÓ^Z+8V2S4sr[HtK?^Z&ave64J-b{X8Ĕ9uIJ>l \pFGK̐AaSYyb׸f1nQd<3s%]"N;gһ X^~0E JeAk>HIp>t3 mzN4(,Z*}[" /.TV;/X'5qJnS/t{X^q⡐ Ȏqfa>tV-! 0`|]i;䦡)k93@JzGQ8}Q}3h\io;J;ED Іp(SwUu@ѵ:ɡ1=r~ySStyBy{DlO CRO$:ڦ>2Q.<էm_B)a,6BaB6a'3 v`~?1WOW-2P=nXOXl}_ 8# vX(]Xlhڥ_5 l0J&WMμi D>..= ?vTUYн,''Djuch:#P‿s2Ҿv4^jZwVv4㩠=2pT<0Uqa{40uݧ}BMg\jI4^uyXB MSY[Lcgj[[+hCy.+q;0 OpΡe6|R>aՋɆ2*dAp(nS;ŷ'J#V|lA+(Q&,| >`JXe=r>Q3X!"Ha]^htFaÛW& tT]b^Jc,焩X2ѣg.W9;nA9ksmЈ =4L,w/~`-9vOb275tUl?yӅ ( \ Oj®,ztCc/lnT_h+`5"TA4OQzm uҤ:ן "G|I7}Z챖<Рby3x%x4U[;0~r=a*yAV=E,ȕ2 m=ׁk Y\Ƀ$cAt8 #Wk[oW(=;"EjdvNYlYxѯ=^eӸc&hΒgE2d"L[vNPzݞ, H +`4wCهMgҴޡ诔 y.JM <-<\C3e%zX뀿asN$8@}45뺻"WB W[a!%ݐI[Bv,z4cw^Ċ&*zM|9՛v"u,whSkr1hR?sm̕}9aUؠղn΍Y*p)?#+!,rwڡ(Yg'&Y&}+"5Mi":ic_TK{&# S&jj3/']DSD0NkE`xKgDlfJ`tC_bvgz)\s̟TcVV{q~Mz;t1yiݖOTnjqgz5xyqUHݳIg.PV1 o񥍼V&)97bM:9eQTO+U>ͦAЌ1sFĦQ\k{Y=b41ܵsc7Umk-L<f5Ӱ*3Gbð&5;\[l ;bΆ5˦`<;cc%!4s–!4$}ni5>Lx8]s~a+WLA ,v=9m8I,I(ZMXlf^U^%J퍣Q|N,T| J~`bDIBf'^_F 3S̽!lqfߠp'E_鱚TP玁zqJ28$e5֘ᾯ#*)xܹS>n0](>ݗ t(L8Ͷbi*eU2i[>Ҁa -ڰP!;*EN7_Jz ;vTb~D_wΌmP, *͗FsɊ #ZJg;iҸ㳍]yX.ܶ"ɒAt :1s>0/i%h^)wMo!0ä{%9p7}2.%/tǀSjޖgu.&b'瑷aW4H~Z-w<{ )j>a9R- $ӎd%qN N5vItevܧwX0Poaqq08C O+%atUtgtM)񺝞!ck 1w _pPQ1հ=R`d4)Hd󅃦oFxbj)/ aMD<1㷚}ֶg/喙qN>q8b*yAsIh#[x`y]?y+`gnsӻ v >/a -b_ z?ߵ4X&pC x\Gؾ=r&v[gH,_XVՀ@J}'v scvH?N9\U?tv<` gYV[#vwUW{-h T3"JgCɣx&d?@t= 8_t/saysD,gFȾڡ},}Xk(޷ia6%哪>BSPvTpZ{eJV9W}A-hC(],;Q_'_Xڗǔ]ͣ~0d" g$ӓB#!9Պ0y>n[Lst ubғI]Dnb+u!2-}N_WQ/VgOZFD~4Lzm̘-Y؃WP*&A,YG6=+\%u##C@V۟fюCEw&8$dLfYcрwv@YnʋD ~oEr[HeM%I-_y/b "Qi=T _>2B/p#/!H9ΘS7#nfnNu(N $@5-uňccLp;X7 (jK3PؿbTp<A t q E=}Y_l`qӵǿ|ѸLx[زkzV7~K(jKUɄ,?" W;y܇ @sվO֘r}#R4S ?)AvہLԣ6p|J~8 ~YS y*RK"|gEYvC&ugNSo[+^>ǭ5zw@/kRGDOe9 6b ?J_W"YKt*wn"?6K) `"TZG5eg $(U[=pH\Cyrdz^Myf^@+P[[ώ@ߗ'gvU:a !k1CъI8T`@I bs)% 돾(22버+Ll<8[O3ڍO.Xvdh[)(c/ěoP !uݘ[3+th50SIu1}J{@Dw92"@רAdJs΍n HyO+ N1WaRGLWC 3}wL?4"hҢlz@Oal҈;4z0ߔ饄S QӪy< Lrѳ\eڧ-l8MDnQӷmg! Dx}^* U j)yTf߮WNܿV۷7m;+jGQu.iouM! 'S.#0~ $W;O>⫮ɴ!d|/Lh-94-ܑZ RY3&! 7ӽNf@ <&oےH. Z#5Ҧ6'JATc1v=у`G-V)ך(?ïP+]72t}ry| y CL~u݀tx UqR?.^`ɛUй6*Bħl̛{^_?/aUzKp (T(Su A KCtVyIZη\*~]&d*26}W| ÜgUղ#ruݟ@&cHyeZkbJblH(`QcyfCY5FhE\"Ւfq^nȾh:põZ-ÄqwN g,%#ALjʃO{ӚRxhʽo UL&$rXJeUOqaX-[bA 6FճJ|fcbɸ.Yc 'h"`@ *^FK 픯hf%GP; G=/U5 R;W@Wlra"v .cIQ–H&/ñNRX\bݘͯ(Rys H_ML%w%pg].8f=~!$:>շPz$r !G: tjt0m :,AalU1^МcS\_=<(nqľ,znW|liwUR}񢏬 }9u; , |Xv-SǷecUpe_ՓϸZ[nC$9q \"gV)9[U:CRYpINrn4ZLx'QK]E'G0 ʧL\Stn.wOp yS)SQ:husobbo.+ձ2 $38bܑmdJhÇi)C%/.'u̱^ QM _1yy\?\`оXώM>{ߦS8/:L"fc_Bvw4~ ײ(P>O^U擋"Z+Q_Cy7+" ~lR$H&S@&ex'ӁH`}?Ahd~;Tdl((o9#iK{Wgf{ t/fЍR36]*SM]lwk|<9T`g9-w|АmT97eXX}GKf̽k$E9"'P'{ZK^m9Rh3E-olҖv}[!cӁD4 e{tn;jBވ E/;U%fӓ;j{܁|%S5_<')ǫ@vi`u,;-ɫLCVc:ꠡccڄ?aC!O,TBO_.lvVZ4V ]ygm"O%P,>G4;ַ4MO\eJ:(4IeUۦEn01o!EYgKhY%0;WBFt .Qx{͟1Ӱb,€NaQ-4w& +K*/T uIQ :}ډZ"7ъ('Cߘ TMu]Ll/_mlh+^*S7!ฆ7^ueoH`ZA،d)~j^n.% G\˟Sfǘ@ {^LTվH4_z,y kȤ(J(`Qf-p\8 d3T&d2;:ɧAy 8SԺL"/S[[(D|Z0LCs$4ìF/N^dj%`MJJpf]Т?Z6Y<׌,*z)E0ˈ)9.첕A7>÷X\R6ML,8ڤVAL݈ӝ[:wXCWpNٽoˠ^2BG;ea:Eh-<.cK* zP%.ToVPZo]#ŕ!6,]hP?Kr!Vcɥݪ^H]I ?k␠^MJMAm]σӉս7=q!K]=|߽2&#S(ӌNu^@6-e#ClGEX37f;]iRH-֕?7xFo_;d~A8{ן*}}<y!<{~6*k H "uA5 .UU6Z [@'ITh?a|i&;=:Icg*οty!B(.D•gG)m˙C'뤜#|DEz='ى@ [qxL|T,`<.W k2͹]_2jFt"ݜk< 'yʸ@FpLΔAL鉗98vH9i6xZFҶ:xn᜝ߣ)x44:b`SB)I>r nUyi.|ɣU[Amkh$f1p  >mÜ~q1uΦʡ LԥCwFzCىrdۢs.RE 0ꨘx<~Y63QC l Ec$F)f݂CqF#r&oJ|{)c1KNhwP֚E[!SNzV'Ձ Z:Mù[dƞ{*ɡUMwĮ(pK0O==Ƴ*SpI\Wso¼9z]0ń8ETsgӦ u9J 7eP<Qv {*] Z?ix`Kٽɱ~}7/*nHߜ %dJAg17Wr`uc|;iCo=Yzze q={Dߒ^.j9ux+. ~h^x8ԽWC8lO^s3HARl7D,dP}Z; /7*NhHe[o{LiP6G9P5x[RkEBQ)x`>> j"Ƥ;uS^@݀ Py#N'iwIS@Nb%乎Sg\!wV L']ːqc.킵Dl=[ѧNF)4˞T.N`..`u|a\&L:R U#ؚaGkLT7':>y qf>sR<<ŧ81鷦l)W}ތÕif1|%Ce%p9Dxa7+0\dR*CtMj9'SRrͧ_`_Ys/Mv-Wm 0,$Ϟ tiawڹZz4DheϳϭP ^Emj~ M_6u?,VNXrv̞1N>gRߺYr*we1YJMUU/ UdqIjao7lO;~c*h* ,! %m,7ۄƕjvWK9:]ݐlnHTggO_(\~y1`1!K:#8+|\~3UYL8=xªiR>&_Z$N_Yx:@rzkdӭ e<ԽQVdgYy&4wb[p[LqZgζq`6S)Y-|ss c J(^^0+L. nQeYmW0~U>TEi%65gL{$FZk[ìA•AI7SD]%SZi6H'~S(#6 ?f g@#`UFLD[}8 U /4)aC5Yٴ56hiCNd|ѳ!# <,c=8.WUk O$:cCa+#2ںma UDgc4;ڥCc?ⵄ$e.[妅wgׄ;ߘB0s>:q]80x 6D54]t5VMݭ'8=Ra$9~K"XF}pZVaVr s !]9.#YM0؞ІZb3'Y+`j\7cC|vt*WqR$uG[MI *QAz]znŞY% Ռez8 %HC? pxetfk]˴a^X+ίAݢc3eI8jyd9}usUo A :vy\?o&շvo3=A!qtL[0S17Y]^BYS-Vf α)K}@gI{.F8<)(E1L!RAP, +]z+mGr#Jc 712=$)MK) eVqep2jCkf*nu%C@/d}'U2LN_VfoiUx[le"AC溑rjώ ,TP5!EPVV,0D&۫7`h,t[9˄u-3HmhGxGDF "_)$ə:04q<29Đ!┴C-! Ge0 LӜ)#ZqfPN, "cPmK>2TUUM$sL AIJAjn G1lI9" 7w6k+U]WڱÑ"ZܜTi( PԨB?4ELR;ws$x (w2 ^+߶Ue 5h$'1ޮNmACQ<|pHr{K~#e"pNvxXVj6БLh_oBO8CuzW%1ʘ $O[( # S;;d:O&)5&@aVԁjWYmP9: v\MG'F>=1@N׊Ld\C+t-(Vx2_ PPN}KTMϐEiR魼3j@ڈ@]SJB}􉧞I@ࣨIE6z6.%X26}jeA3\UJvN_4=qs䊌 4noYe);,4(1Ō,Jx:E M:3yO1 ϴ݉7=reۿ BcwcJGoOH`?#⽡".W,MU 8 ||/bJ*$Y S[&޼#+Gފ[߻6EƥA8+*_S[Uu mWO44%ӲeJz+񐞡e(`~9Fkuv8o.ՀiyENpgQKo@#b}lqVY0$Z$N4 m]ފLq).q1XrbѦ&SMWQ3HY]UU,%3 @a%͡IxMh&a#׽;3O5_~(%*k_7rǹʾ/5]O\U~ 3o#V>H1/E}Q<3_I> r>vk܅m髰OM{@Zl LWқi(OU%sZe#mE%x4ἧ Y!:#8O*SF1?8/eQ縺wpw~L譊rfr8US)4òlYz + &`U6N*3dQ]C|P~PoQԖk럌]9 JNJq8@tۼY:7aGp{3$yi_1![H^ i1 %˧S<'Dyl> p:>7Zmcʟ2Z5a'L [g~WK |[wA&1Ε`.-(LN]lbh>uu0VMn1+n CFYܫk-P(KHןj8*p3u?^TO$vsAHI x5*n/jsC MA7h?rK9o(}.`̹k;68$.k]vˤ/E iD ^ӳ"0_.'Afwυ_31`oR a}ÛXu _P9=cǤFtá$è,z^hS!׾:aa'JŶ%wݘwl&mP+dJKf;qcZ~ݕ6IRjIPALDE͘-z4 ^(Vz*XW J a;9v71-I ^EW[y?r wlXiY\] ZOunkK=Ft "zJD8KEz\#_XJH 95ŭu3d4AC1D͢kcZ(φL/ulU6 hct _ʢO-R4Hq@W3C T]%' ^g_2̙}7,'Wƚ`̀Ҷ9m;/g_*Y(Q4[D4!AJm#  H0FȼM2QH;Oͫ?zXF-N 6Ѕ?h=[.q &,Α-RZR#v+hu@d攌i 7foI|d.x e w#+>-]J՚؈(~{]$ )`WgoѠ*]6 a6Ϗ'ob:xm%WWGaH[[)%i4ng-0w *;V(j\瓪tL|hSj_J,rߛhn!ZKp>1>!CщH~Ƌz5ޠsx}{T9"K3:~J[lI~$,5-vt5QUkm{[ P͒iH-w7=y%$>bt\F3^4LjGj ONb~!ꌠۻ6}n"Jjh0楴^Ը>l!b9ɃM$hiyU@t|]R}ta˟o9fm-=ހ.ZR6c|Wv,u"@׀#(ǹb"*(R[0CË`?e ´n dDA )q_J* =TŖn$wJZ,q fU3Kv|])lv^&QvSs5G)BKn(A)dYZvӞ9V$?hAAȧ0T 46 )eX9ͧR 4:9)z9bT/]<_b@8n8.ݱJיM^d[h8 NJdK"3 q2ne?|>x5Z}R-:ҡOz{pv ʱp 7oJ<g޸`n( Z]ކ>2V<4W&"}35%׃E5jzHvD*]S Mr U@P\~«$zD?uk 4j8t|vNF zQ^Ahby( +BsXaٙx+@^|4d` sP#T{S-ّ!Ń@F/nBEiE4f꺈9.vĚ?l/5^*xSBkp$"͒gIJ`^ի^b[ӑ&bE>CK~lx m^Y|餷J`UKٺQx])BTj1q,CAaRa;d_bshLHjس[ˎ!q>Rk'!$pF .nl|#}߼'}8-S ZT &i Q- 1sqiA. ~RxBu^9@6}-AN1f~Kf#P:Bn*`=2A{T_{Ifz:Sw'Ul)$IGiw VMM}Qd~do:O .'\L; |71P2rw3ƀGzs|XZz՘~;/#|?it5xNRZ:~ՠ 5i~Ɯ?h~fȚ*ά+ &!%Ebeb/K ŻjV}-"HKcgf0Zǐ:o[Hd(,h8%~X\/sȴ *:צN߲E zO@#Y7`^2/-Cib7mKwkK^h8j SMh69p>xe.PYv)Kk]C< Za2ѽbPo.}$ah久 igMuǴl6=A :['ԑ@4Ri2b^P'kѨ p'B; ޺^+յ͟D. !h0E`ci{/Nftus)\4៼C gw<=4x$*E 4eT?E/Ç;0y:rDlmF:Sƙmi'ܴA=-Ef]jIJgȗdW̖D6t ]SLjb݀ZgZ:%c( ,ğ}i82(+-qbl.uT+ץżQNVq )2FMnA% QNxDgzƪf|CLLK$U 8|^kUOncLp믁&=:1'?;p_͏%cV39J;}y@GG/g )-|WަR]W˯>FA4[[I?H<ҬGKc?Jk䏥557%ޠ_nh&J_sm'Nwe,3 ?xT9݇ c LvS ,11sz~Dz1P7ݽ&R%RW|r9S/+ =Jk5,O"zYG_Up5H%* +ɝAnl؊[+z }~`L\H݂4]h=)F*X ͊#oy#إepcTMNl d,%3*lC^><  YY~q]M˔1eL';?5ZWv`arL*T dIU)glmEb]g8BDRd]]+o$AGN3#w$VHeW~b4qn3?q|Xb޹`V1C+#zY:칗C W_|܃ XbmG+Օ"v~fe2 r#-tn@& G~%N@6eLGQsܙ穯j0JױK  l~ѕm8zL,TʜKgU=`@ڜH../E48z]L' gG]je85<%A6E4l9z)fVTJn9WCb[3_蓰l96Fuf.덡Ƃ Ocĉyv69ŬA}=&6嶷 P_=f!E7#YO/V8E 2vj{fLR]9@!&㚄3H:ƋJm19`U&7Ԝ OwtwtFyFQEn:r L]fZcI9ߕRjg;Ya~{gfۂ2F$umX(nЕ̵tnUfb Ӈ2zJDZl$ٞ<&!<-jcVnFlgt# exw!-Ltfű.d" NFG((\tK-KCaׯ ҩ|e%tx&jppE\0߷« I~}$?\qKߛ~Q: #I;k?K>ݾ d64䚑ȷJY@__‘* :`0T|h;L#$9}(bQ;tZ*\o5y&oӘ_ V*.qR7;Y sbI>u{yu*݈*ar0cPOPHD|/D/tm1B57O+v*,mtJHX' ^:H #z`_˯R A5@jM$%H0u&ޅXK[ԟp,zRx g'.UAMګpr|.eLiot R1CyoܫN_-yyckS"JpLMB_;pn䞙2s沅PO!5uJ,CXpRȌa̍T|ZUh*n KXV @CXT.+Jp۔/I? 39Bʹ_(aRkipeGrs`_\M?\iMTSBt%s.Akd/GY_̦C F<w=轣RYcqSJE qRLr:wgBD %-'1NlPP,6-Jj-U$͒H9JT06 DXz=U;"9-{=2ģ2{O-/^ X;Xf@M񉢒Gs3CCE@@([XSgK*NbfD!7ti#t1gFfC tiA,e:-ZzMdn+*hN/XGEB_⯭2LnY:l;:oĨ ?P4-&aC3%'xRHYe䒑6k}.:Sŭ?7$1a\x,d!i ƀrۍ&{࣪iTfRg%a-qd==佅7\mRSe!#݌Xv1,`0s1U}޵Vݒr9:$e3<'tpckqtYJbfاTN?uWFԲ'9i韱*M}ombTRȽm.mfڄړͷ"BG˳,jwC u""䫝*m^s8Q^g6qmV:>)U}ISgT\̱%1B|p#(I[/ M9Sʇ~x(ȄW HrDUGj6#h깟l!met5~C.JM 3񆇒jw &c4r&c(fc.!nP@xXjgV̍,_ *KBJ_i , { 9A@)4׹:}zR/EZM`HfVd 13\Ė/J:ayRwS0 /YyuhokC4^3mŅ3vpaC67^Y1).rXv~_ ;2y쫋Cǟ`V~Rb`THw_b@|AyiDZ:cxFXܓ.7 U Shs0LxdŬbN_%OKS7GzV5h0EdM:cFV8O{jݞʬ#TB9-ثQW C?HzyZI/,Ig$HRX)Uuhbv%+6j9Eb~lsYe8i: nU-%{d cZƒϻo]q;!DFEеD>9]*>n:sk2q)w2BE8*y #^ n۝S$Ct*EYUy4ɓdPz!?ϯී^SN!M2E=o0ꂍ \={$.>$mtF8yBYs.$\laLE &yCc:6|U:/ejC/kYʨf[S]XYɉDF2"Cр"d  1OҒ-Y, 1#CXo1=Ɏ.M43Z "z\ʢH[7+>|qk$-M/pc>|~l,#̇#ZϥB-ISYLqHaʯtjžUcd[8@@ 45 _O=Te *8zo0ɮT3!R%lBqH*zO,=4*=ڱȹ1QvOgc&ڮ⢁-U<7@ezsăڟYVns>{0u:H\ҥ?u$2CB/K~p-[\3׆ ؓSBDjdF$p:';,AGnsڬ'X'AVa(0H|Ⱦ)PKWŤo"lcs;u(sv @ϝ;&ݲ;   g'E#]EDqDz)n03h8VXϨ#KINN7!q½rV)EڏRfs`xOUh(b]߫RG;g31ugD߂wԋ(7M|;W6J~m8F@XYŷ8wi(@m(,"yy F(-h${5mMtgi׼ ^r;]éJƲ!A~P2]=]ҥ.^ul'0ȲD:T#);âsǍD5ˋnۋ/\w3P'\X.{%̞c[eaY?QP6hƤ5yT$ ?yPp_EXs:5m\8놭/3etVkNэnA [e;d}^ *q1XDMzQH W0JZ;c hDa@>VFanlœ]cm/돼~tq͇ e eDtRn2°/2k<˱-RW/+4nPvON-9[i/K (q&g/;_@Nj+JW=)R,mtqKvA.d &?tɿ?VD 5r>̉SD(s%W m3i:Z(?J 2eGFbmRDt#:oCyj#G)ϊZԄ%py?Z-cQZvaD%G]t=Q=jA@ZEB-Gt$a{|Խ\>5J̪V2vf n"ɢC_p$iEj!Lsuމ΄GטW _= ]X͎E0%I H_,]e+ؕ\5S~ c`qHAbV.Utt7CFX%l}B Ef52t{+B*lbΫi"pdT=$_*boIÁ/!c :֎{-:Ca#0$PƙSQD Lr*VD~w <+sٰȢbKj@m]JW} [5?꘱.x%@B~pP㻆Zc{Eͤf+pt.`aiT" ᴆg_s!Bk|A5@-)a|?# r2ܶԉ SU= Tͦ8oq̔.fip./_7~bޛilLh@Z&7HmᑙOw8?FSP&]Lr;U@g0i` 8J0Z31K>v"r?wϜzQozrH\ v 湋Jo"y ji'\J\YyO|7P -psb} )if))&]uiPU]Q#TrJK^?FAeߧ8[t.&d9ɦ59EP_e`4.8ȿ2rZTBb6_:y=7KAr5)R]r ÖGM@Q-Ѭ3QT &u,}qް)bڧ)`XB3e(:+tnGdvXvNJU-,JpYb͝jS(QˍYCq?zVQBcy*1G η"=hpy<Uل̤Jd Y-yѫU6͖E*0nsgb6d%@*DoqKee7lqW튁VZQb]YgX/ Rlc},$'~wA1S|U{hC1`0-^P•茯p%Ǘq_l>Y)\3\x83sd$ TLrrnXf&Լ:Qt\o'T@?T~.Oq"^E8]Y Wr'<g{ץ\ 0Vǘ`AݝَN"En9*aCۨ=E"B% Fv- $}ŗ6qYOZ'64{y/ kK$m/;U~d\Z܆ m}K잆Zdk7sP= E#K M%y'S&(]8ltk܉E2.wƍƞ%ۇ4"?H7!ͪ1+Kn?ݩ#4V 76(Ws5Y{Z+cMprZ9HUU\;iV F*#Ƌ`+Ϙrc-ftB&GftR.|ʘTvϙI;6C[r~AI2B $,ሐbˮߥRP4'~ J||xw좻"h+-֥V{;q޲uE}|@>-^8>]E9g }jt"`ɷ Ŏ4tf K9SOj=F{MZq6Fn0c1F 9LA|^ YǪbNyOM T@xC.g| E)t>zڽ|ڗ,"5f^h߲Fh,aNW@,YSkX*WI/Fhl|G/wQ k(YeYH& (U7aH gah #HB?7&R-y!o=?vM[Q*Q(WU} k;RmpF g-G;V'3>GLNX9,X`21t2{J-]oy ;`䳷p4*1DQc ozr:qH" uLӋoPCܗv(0>8M7J gYM>)XFzg3pw5rTvw)CjN*X2!/ +.c&4HOO+7/(o,aIԳp&OÇ8_Jt/A\ri1! K?@Sr:cJ9xwXpӭ;ᨋ.~$0WyI1NPmCXiD!\rab"Ro8W/=!PLuPd p$9ZQ>'xZYYo`FL^.x H6Rzown#~© =mr M=c}rјSPyL]TCyw[7A7)a Nۼmӱ6cqA2}V[^iS<8-d4_xʴ=HϨP|#2@@.7 nGSUtNāJ9܈wH[]bُX{H;hJL:[mvo<ڻ w~G8L&{V/jfCTy] X`8t %v]7?)9 %Oнe8p& frsҷÿ=lX<_ZĩLB q7a慘^ Flł')@6r@-ȒߟF{`j›0lCG I{✏pYxFTȆɵE,ɍ? vAYTe6>9Z֭tj:3'ņJ q5~jA(ZEaTz RsU+dy&~*{e@ooo3i2W쑭AZd< ?L9̾rc"@rj-#dDÔrЧLI6WšrbRJ{GˆDv ^_J)HIAeX"e]D7UM# A݋b#Cb*R'#ȗ"LXR x:G?z\:|d0sltum"hn;+]y 5Кס YGG)zzՇ}J6! f2yuTo /b}%bXzR*K񪆪ձq@;iXpYCAn5{(C,t_B(/k.V_w#_2Hϩ]^sA"l]6SF4MhQ[,O̶,B{*eIPxb e ^ U<3IFmؘjDr>Dvk:Bі^@ Ik}\P zc]!b~S:낫=ŬwZ$c_B]: aSLϷl ..CHLǠY'^8Fk1ܛӱrXLz:4Z &BK=j!ْ-m)Lܿr6W+rE]<Zc6RgXxͮ A2Mxrn$(h{WaZu {ځV8&[GB6d^4/KsJ Cd(V_+^$z{=`7aKAw+z0ZJh}"hvF봓0[khUV}z(/fK0ۨSJXl3z/]"A I|r N N>?EH>i"+Ci#4MJ9ٮ!%/9 I?p'$Qv8x!c "X,Z$?&g%> C6ୢT:])@hg9}q"<Ɯ_\%I2 zĔ?V 4-=L\&wk&>oA:}-I2?h}S6I{ wHC>AvI_()5vD_wq`fD`{ЬVFT~isQ2 qc W e&?`s9m\?>:J*qKNzN,1XқT 2x8m"hW":-%K,UU6^tTEvmdCMeD+l&m@+\G0o=ܬ6a0D7*$RB;qdTHdc2rٙі$by;QJ%usjp/1(}_tԗ0:oW!i}=ͭ 7?0mHZ1hq,A`*T9뒶e@M;hldD[e|$s׃6עEQ%zt7̟ SETl=S8p%\#ܪ͸nvCe]*h=)ԪT4riuGe],m Lq ׹v?.H =kO ,=<$6s6\ra V>Υ3@9ݓа_nݳBY3m#"TJh+/IrBNgXiIlM|Xw_~[ P/lH^{|[`5A2W⌨b\ Z!LRQ 83'@\̦d>  ~度}|z re[\!F?.Z[$yN # jK©^ީNGc3~<ĄȜkYyrrہt 97"-" jRW =kc:1A=X)t-G E yVd~4_X!'SAfTy!S,#BiY,490ܣ7h U秥x *W?ʌ OT_CX;Mr_p^~  q@ 1(5%iK1wے[Zpd6ژNfU-̸YTIY߱ #L @*i%?~@.).ӥaSJ!+~ w޳"ofocxz}G?IKԵ` .)k-!!gk]q~Gұ rS$!28nHk^Cb'~`2~YTKM,cV\qODfH0UMor10ס'Qdj00\_8AiD(yeA26 PRIuQZ>x~qU_wȅhDq-EK:x#qe%&I:oyeG 9?A (5%d)Oؐ J5ꭞ?kg{V(Ù0n'5b|CDKuZៅQ\:ؿ¤SyvfՔtlTMԈ."E uʓ#_7pʲl-:pnJm`9POܑ_!$ (D~2Sq{Cֹ~c1g[S˥ yL0IV'gv*n d8F-Gi#'d4^^Im;m9J C`.b/-\/ݨ ֶ@S:)xW 5w J7\Tvo1x8ɘl%;|!- aU!gښS|D\LS8# yZpҰn),&^| EGʴK#bX C較n`ߟ}Z8*u׏޴FO(qC Z'hXq`z)؝/`3MiD2q&"UX2F(j]޵E«u`~%67Z"tċaN ǹ^q?:`uTE}A0+b0d-fG-#b9R9ı ,͙I/gjzc&{ ԦƏ7Y@'\|m%}"8Mפb)h |mt0y7`bKc;C FgC'. rqAV|\SfgK)vC.?5[ehܮ.Ơltr%(+.dU I^&6S00]ʌǡC&k-n:K= % +L~ cG+OF>x4lEc"cԕ~֙Ԩ%ީJEU]W}1Lr}2Z:!hș)輻SًcW3i-z3jfV:p +nner̙LaW1$Bm?r޻ޕh>D읶v}u# kت Ξ~E! Fyexh rT \1">X5).oݠ1YB7EwvW$aA͌5F \m8Z'=> ,$2IuYr:%x_i:2I$%Gz]={XMPb5. =4O|hL* yNYM~Q/Ɋ5=b8CF2uCׯ}8^Ѧ&txR8꺑Tѧi0ViM*yۘ]m>HH࢘ Ohsc(e?% 4+{ύ;¯Ģnpʿ \EG2kDZ6{WH \PN<nxz_ OʀtP ɼ1*y2짬LGKIȆ+m5%=imbB4si!>w2-m ?mޘN\)BE%ņyb70ci{W+40FXOGO6Lqh e! 0g0-ᜫWb,朻 _elb6SJ6"rV_V!M+k,J_rF}a@"^ABȓRUxC(51]9rL Q+7zd48 wC@4ZXsW%ZYDn.WBYp܆TSm_%".{匵:Hjo莏s<_t[y1#_7rW3{,ټi6qd{>v,=}TAI{VϘHgHɄ6w<-A,qث*-T.]{Vu:=,%Ϛ6~!h_%23*8>&zoJ𔼮Hqֵ; -n?b8xY䅗8h6%fFqCN(#y+UhA)! Nsr=:|G*$~< gیadx>ڬxFX1"t} HG"/Ŏ" ƧXu 8K a!&\nti;5Fe2/O?[,m%XCE]~ i"a_kt iv1DPbXI*x2QG؍Bm|gWDŽ+x("7jU[bB-}P%D)<` (=:V6rH unJ{΅p8Z Á`>rO@uv RYͥ>_*(RO]u`BhRg_ni#'N=Wb35͙I;w54,.љ -#ED@n7c%|:yRC)ֱ/9PQ(QⷙO9)hJ[a @#V(0ES0n4^**q(M"YлȬب$(7LCXY-mΒf-;DH?tˀmq9~ݡL+"T|G' iu(Rio-NFf7 b\HcSNqGreK @, F UXl+\GZCW|wMar {t =ĉ7 F֏NV[l+C$SnHs4%}(l*~6TCTXHeҿc~&sO_ƀ-*)ENc. 50X17HJCz^&C,n9i/|э+8ObNGCdbҺLNwP!@LG@0zhPbhPu(L}JCIϣ@??K\{ļ"+)At\Oq3U_n qm(~GL6~9qm&jaF\f %Y=|#h'wR1 "k*Lɂ!=x#ࠫ: yBNxpDž\pK,z&)f2&O:K#ں;|P9-{d_C\c"k^n1.fOuNBp*gjt~*~O.HiđH9yv54=Y*$3|LJqfT33;T BovPA Ue칪^XR#L Q<ZX`P͹v!)iUFDHuP6;𶳞`h2\[92nz(hЪ{rn R HE$r-T E݁y0azrdǏp&CV+`UЈuoXkj}.H|)|@<͸5C`&?6YQ>G_1eKj:ytt\Jbs^gDc0#kF9k\nVd҉D*ڠ qYJ ͔ؔ&t`6=mDuDC096eYƬt\V&E뮏=Hv<̵Yi ?ЊTpz űG)aDEiH ).CsDhsԟܶK 2:Qo@/zf'܎85ޕզR (c@;h83HO;)!d3i=s5#K[R,l6O^cRLڮ|fgJ&*~ksRWKT =) AH)ʼno;x\]kr]w|=bye~ݱR3gp{w0)l"eh()uP\FU^Rbv XOYnALyTOJ0^P'J`(gL|:YFW&9}Y=pZ&ח[_LGv.mD3# \)&m_#XԣJuJhT=lt|_lϿ's+;NT1qc>KLb5sn$P\om տ)G¹kRAʹ]ō2P_}6pZ&b1.c*K!"DXt0S(¬[oP~>$;I6U W'P|og'&fMԐ 54~`AS2bcϺ?Y*Q{4|?;G"Q2<]aoK8%?¯-y& #(6Ql Se[hcRPS~LWhDAZ(+NJ% ym-$.NzS eA"{͗ 7շN93Ûټ|vm5GtM Gb :e( !W9fЌM~&o56|Jpb<\̤W[sZm+RDzΧWhlP,)RiHL|'h{< [dUh7\jΗLMKXy&9-Vۡf@ Bk𨪳r$f,85;P/f>o>g'߄ZO@=///~'\p4={|LxaI(v( &ẹK& Fh͈—faȞ܄;s^Ԃ\.~I@ ,^ۇ5@DnQht659ǀ%tߐ %LG>9lTE ӴpɜZߘk(bG Re/07* C2ݜr="wt5irX|z2tR5/c塓 xtW.M-7`2V}Wd9/\рƎD&n7)&7$5[0hK8W}M//< ;EybKNK" uOj`(ɲzO?4UFWUtl ;]}PhoURWA>aD[WKcfօ5fu6}-ntZ[R3b-J4Tȼ6=d9h%=7^[w_A9T/$y SMB.1;TmHr&Dr^"qY sABDIѽBjM*i{4[Ru/0 $|Ԡ͇9lb!~-kf^apB[7&#ZXa4å[x ,{$~Ha4gaHp [{\W_$YsrgA3MXdGmg_q 8CK}ۀi0ezi| OlKC5S]TΗkZKFk̦5 D2wOե1AEj_SzVWh)/&p3l𖉂r.R#F1o>m*R &MtaX@K2D8~1 FtEϜ[-zkR" ];thUgm[(HU&`kRDRC;rYW*yL;X;}I!2$.w-ɇ3o*QAYŔ [ޙ8y-ۀ GvԵZFva b/Hژ۹stũP|鑚v[%[j͠B..*`,Þ5>!ľ,v6~Ol,o"\M\kKVhc-X)5<~[U5tQɎ(WYR'եQ?|Q[C*[T7zM0!P'/ 0܀6Y&ݜGAH*vɣO BXc,S(:^F3Iu;l7Q#XׇrJ)`!7@oo(m{rjQb Alq`?IJ[D@ `=-;&f _d HT]`a"D/B&^}q5GaExqHq;5̣ ˕os\rkֻlb>{7CN [QBEM92zGGO"㻭 Qr\`ι쉽kVݞ;w(o&lehYdu p.>Bsg<.J9Ga(ޙ6xv|㪞'mcl &N\$fl+}&l6sK 5}5B3G 8\N#=}[K`ژP}/2E9oZ"35J//?:;F{~^y P;ݨq AR@_V+"1\b ˥ͼ>}Rvm}o*2c-+z`~umE5[_xl/ u6+K\͑[`{/NOk<<|guZ&$CRG/8ZkEs/w9%tُ"zJ+oXFzUYgZh 2^M$=qSt/vU( C{]^LVjLeҜmY|H$EvOKdUH~%}T"6d捉9N @dKWRUEׇEm@ _V1Nܠ~*:fp}z1ڬU ŕ,R3 to/.#$_rtP˖Y)D a_(| B6gtM񽙸Q%\ R}0-rv-ZO+2!갗N 1ӹl9GB'%b5UB;i cRm+'9@ѓaX5 uIt7b MBwe_/0ԉqsQg_`DŸK|OѲI/FvgݝgB-eSS@:iHPNJ g+i$Ĥcmk,,,/jR>̍Fux?Xj{U"EBTTWuѷ",GbۊbMLWS.ޗz;Cu68&fja)(P4:%hOGDuꈑ X"FQ35j`P8:X24m($$?XeaLq$dT };LOjQTh&fPUF[wp-y~Yذg72N1]:Ƀ:<0c!Oq57cw*aDpLUjlߥ./\fq4bvODZ Su9HTUJ׺5|*)ӫn`OvHD%wuu '8іʫ *:ʁLuc(>$k%؋g'㋃K+vQi!YcJ)#ZCY}ˊx#tsH#+9Kc-V;IRW}ޒ70zӼ~\R=7%1Cc"FPh3hYUT݆\4PTr,1wDp~zao@h1PObx&EL"R>H\GCreA,KAL޹:-^͉jᬀ[}b=DlM<*^Ku Fߑ5%,@7\>(bbs;V|Wmkauƺ1 HxrɟϟW5A: 쑊Dԃ;/־LLj; Qu>#o՞,y;`aTaVwhgdE:DW'@WrOac,˖ vp!;6mnR+7WG>ZXɅ`>`B"J=\2K/h ˋ&;$/[at @\0^| lM;B7 =5ymn-G%0-+5 k-i\T@rtwɫLbl(vZ qYض}84CPɪ1 Q};S$qC te hpi!@dc. U;(dLyh!VAW .clQR e2ז7gSh߂Qӓ?J0Vptwr%!:Ƽ_p|OiϞ=㇃iRAkYN/գ;+Y*P4Bel`bo(3]E(!7G<̘-ܑ} YXBhM K7R8&~-weFShҝ.e%PsW'T{.ѳCJn@WF a z%@io2Nm=9: $t^xI 8N\1s(msrǍ۬#"m'z#}%M<h(&jOkQݎcG#ͷ%|7 a01ʨh B'=^ 9O6%g٧!J2S:UQǡkc*s W+"tyA.V;;Ċ6 =+ yNVBE8m:F6DL^a$,*>xu‹yǐsDAS_LC  ̥;V〄4?3:eTZ3(ĿĻ:V+.ܒ*Xw*2 Rsە}R'$iBx2iG05h9`:ϣ{SMQ*dSjdU*[~:PаLJ?lKaCvʟ쥋 qk/8i":R)0rRӆM'ri1xW{-0r}EN'T>y|Iܗ_ _qPǖ-qkeJ_eO#cߝ.¨^QP@SnUyiB71߈RՆ+* kaDBd!0q24qh#[`8g&|ȑh"I~:' A?{m䧔 N=)mWI!zjO׬ͣ <__\&~t˶>n؉7܇uZ| [0^<*hI"9fK,0!dd_?'҉D!g ;+9S|D} $GRl vf=(dWwŊgLJ4[\}Ջo?yn yX[m!4\]LO/bFIFoԠe[z|&PjknۤT#>p_PZorH1RI$k_jU7\_ڇ @"$'؂x;gQdkh&DC YJ L"ͧ}ͥ TFBq\KKmAť^aJ>ɽ2 +#b,$H>>P@ʢ֫mXד? _C& .4uK}AשRi9L{jkX.__(1pZ9Pw/J|ߌ F><{ݿ8J;g6S`@5>O/? rKY ݓ. K FSvH,18v-Bf\]9l$GU/ L_8-2DZ/Vȗ=;/eq⦵oo"b>.W[MM+l߲k{ oc0te)Cg)Kx3$(\S؎`kawg3mM76fvZnv1~baV\\j EEBP$ 񘶈[ 82SFrnBS/֒P_C95fҨxPY@@i e_!GgƳRQ(/h7m;C+.&77F- ]DPEDe`R>%?{1iNN00#qJr:Jዾ( =`oLȶTQ#2h> JLbxzDKJ _s]:Af/Vbs^^=z[J%>;v  OMxG,f, 7M4#Lg>g[{/=E}Bߊ>5˦a~P% ^ xvS#/#Hzh>a\  -Ȍ.wkI;Ta?Z ~ EXʂ@؉9I8] PHF0ugDnvNɫw@&veN^]? %+M#KpsX^+N=s=bp54[X4ӭ  D_FE%B$oqeb 9~Tب;ZrilKaTT:EE̾(` ~gm!HǀZ/TMvT/T5zvf/킪4\jd^dӃWo(Sx=!9>g;kweK p~n VV+JΕOF:&c\I9|eL%O)d X:)o[d^K4C7dx3J%߼%%_/ ی(k4fCH/56AY0Dm?jvF 7qtp`D&7݃1Ҟyr8Jv4J>7'6XXO9;-9s=3^Ojz^2`cߦ7ϏԀMx:HPLVeL~>'ݫR[OyNZT925գH\)Uwj̈(tHh~ by*ЛO}& SX4nS1ρE4+WeS>(&TMI@ a yo`j f1aqd~ e^H]@?Ki&l~Uj!nFNC0w= <ы<")6Aa$^r^G!|ɠ6>@edffE&HO5O6KCEԮu(`qRĢ׶ u՚$yS|(!eI^΋f;GB]9$~V`ncb՞ZCoԡ߄I-EJ06p\̷8#cL2{ԯ m 4KR v4S2d0hucŅ:0/yZ$-rN<ѣ(bKjL8toniK׈0 Id@-ի }ヲ񇃝 0GC> MC)^rIɁs` [jIHq[t(؊ \cNKpa^9Vp[F-E(PQtvVPK\;[Q=) e:cXa/ִ9 oߴ}.\6Z/4qvQ1Y"scь/[5 _\Ai}ͯ*]Hb)ؕ"}H?ÉϱOL=m֛%Dz2(NӍ, ~a\w}d,[= Bp^Vô+⤫}M]*;xũ7eܣ$& O+%qAqw~ ygDUC'F~}p._&Gg/m [~FS#y2lbL1UY*sKK>_i0Kb GX%/dv(C"v1LZ;9HLO1Tved].1.Hh/52/Z\çE^ȑPͶ u`Sg,uZ3 R\ʼn@}ҏҝVO>|(&8,ba 5mY &APGv,ao #J;iߨLUHQ ҅m仢1ox@7g J Tbnp2Pb>;%}b>OCyxK8Jd6+,+U4 [ ÞɑG+qRh nqU2 }F5/`C~lm϶NdPH <1DCRD7,#LC$-&We 0VnNHF(_C~G.^|bj*iʥ (CP8j+^bH VA39k'(aJ {k ?$1AB[yZDQTYVEbãڜ<`H_ցCWډ7|%GH |gnC]BѮF wb&R]c ٤uF1)X?c;SuLri)c}bv-G%W'@#FB_S0CY! +rP l묈~ea-9D/.+ND=8>J8LczkV.pga$7(_0aeZ5NҾtVOaܜwM:7fKr4nG]zdTR2`K]koj[m0۱ $tblhM#R\wN_'r_M ~ !}@M.-2ZEMMzۼ 9+bm5mq\-eֵYP\2AtqtϮWiGIs>T/g&6w? kcFYo~ vNR2'ȣ|vxT76l̖IevrT* l,z1QWʃ3rJ00 % [bx\~Iz5E ,\ԯkڙmŕzE$q>"&`Wh v8+Nxayֆz, \:VuTs̑ֈc˺/t̆kh^D2$CwI!b/?$H(b8ŵsFrt DSU}H!O$գcC0Y8<I&QNoJ!X fp4j7l[{ N8ה1y25Kkam}# )[|d kga>Pի'EI>>2d QƳn7 bއRY8.6Ro9BgB i]S0bhAc(/]-wUšWvJ2v7{0rda7b3)mfZh.==ezehN{G#> ;)IXk):>;o@F( ԟ7"vΔ\]CM $BDZf*ɤU/lĤb8IK?GY5S8 ␮˥C@|M&iR4ܦQ0̱OLexN -Z97;,Pz"Rb".'wzʻ8:(k bsU&aTސTlK Nk8-oQgU+8(6V[=j!AQFM$wggG?$cu*B(fwQػODм-} _C1#b1Qqĭr;4'Ot%}GY$OTLq]%Ua*M?_eiũ8z66_RgK4YU!%ȤSI`#jR=R!f5Ơ#apnI}/Bj琹*sB#ƀ^`q݉I㇚IY-qyŸ4 GM! *&%R|e;X + XVi->IZ!E+[lqNMy%T&'E\S]O\dw>Rtc01.bʅ6f2dPRʮ|5Q%lꆃU<L5#T..="P lL7lo'2ag5d3j6 ! X#Ê(.[Iֵ2`ͯӿ,+|۩8f"X *ErX%o߯&UrxC-)(W)~0;:;W0g/ hʞWoξ_?ac?ϓ @i3J|hw8r` [ByগWso&grUki㋣Wwӫ?fzuz|yI^.wcqr, \ T kyaOuصޑ,9e9J%y wavm6[VL;Kp; Ԁ9HB.@G;=-!aߵK;?!5bZ=〡"Zmo8_A>bI۽n(q{Il@K$D*!%KNnQ69rK1 L`v;-Ef̷)~ƙU<[lLf}2L+N/Mz4EG@.N5%D"Q*xI*ܦw7t8 bG'Q"d4x`ڟ dz<*VPgxY{B:#8TT*gK nʊuH+u6R23kJ`*B8͸=MWV{Ry*-i\FQL';EH@QyWB2 uM&}6NXh:mI* ]Pq"0߲u\ aFPݞ1L^H В-MwbTD|t3jPC^5P4| 6SS3m⍽ҏ 1ړ6WiX\puIu2}!oȡ〆H9m2IZM(&ԬF POdF,=6`sGd %gNlLbiJF R2c-3\IQD=!7%<"]?K %OZ7ש{PU ٘ O qRc+HDJu'4mԼXIa_bQ$\f EQcS® $qF d#8\񓋟Wyݗ@V0] +_4k .ȴ"kpmzKGD&T(2/y(y5w(si%ҵ XW8CtE+iaiI!ZR>t- &x*¦Hofoon6BMxgE:#O:缞V+&Ä|T, ܃3-BIZޜ*}e\9Ś,v!ǟMrm ;An8+!>{8 6\aRc tOΝeG;ŨQuaQal%h%X%#ҫ/PUm ͞uF'p#k  хgd$:"vƄ#9|O+T0"uPx5Z$]>lHnownPűs <1qX]d&ؔY6[Μ){;g@>U⻩g\~t'䕃] w'w]C玟+/fCfxg0|#b{119rW_%K2XJmB7"}ѷPk>\wڷ;ڝ `;sW eZ\ ^9$E|`+>*;F*Ȝq 8NV*a_Z5'ցiXyA=hg?jK#T٦V/:yD*]@ռw(A6"٨:  G)];ngo ]lW_چY_p7EB,yؑsyh6tZ=tM,\!EɳBӢo:w+7~`׽*7Ws%(?+ڳH𵂱[]NC7/0;h9N/9lN34R^c !yE55  nT8_r] w?fpv׸ګQuZ(4C+ܼ4tQ&ŝ,K,C|Y"[[->G !Dn #h] ZT9Xt}4/dءTH/J㟸vX wOfa A7d0J9,}r ^YʵG%WyQ'ihugT!b 鰩Ju屷~w}*wDz 4~^?vȊB{ݙhzs?A%bաtqN/ǔZ4 ^'&%vG$ޜ|{Co#җO>_\@*m}SGW? ;au"]|<,7=Lԝx4!/SL^ROI~F:DȬtwY1+|EhPx RW6q؍ԧ{afjHW )oSds&E͂6+"%7,#MsCcnghw#N|u2Q}3q2_v~ܩ) 7&/<^=Pק?tr* -0 yt'Y9 A z(Td% Q+{qOj7+sOգrpz0_nf=_1y8Lh"zb܃/oz1GӁ;t0X^EPW͇֮eluH';־R߻*|i 5$ml؜\\Wv4'6"s6_}=#)4qFw2N"! 5_ti[ Aٹ/d$g]vx'ޏfŇhq=o{ײ܉gGyJ]팪-~]JW*yye2OL/߉Q,OZ$`HխJ[XVm֙2,jj2%,y%^ʘ !˵yŋߌt1\E4zFF%*D\+P=o"uc5vJA|mQĶ,nu(LEI)s+An[QQ b%?~ݾQen =Ϧcl؄z!YNMrhۢ6(Q@ovy2LLd%ٍ4+ѹL:'0KMUMK:q$R` F=h/E,sTnD`FfY)Rv+a*tD˝88-? pUQ)+j+nQEe4UIfNnSj򯡘5TrUB%>8+^rF응aݕNRnW[YP&R uMw:MIR בa!us:(n{Yy1@B5l]~607~p}o(XYF}T:g0$r|/Kt ,i׻Opp|r1Z啼C,I: -2I'mݝJwri󍺗 ;K/#0u9Y %=qpU>m AV,! Ke)T=tF*:CG{:]i&rpCrݯ\7ƶlg;y`6?H[ bl7 m$$]ay"/| pb{?D)N lLe-BHҟOL|lz'˄ KrYި]7,} S-MDF)6>NFsP]Mζ,AqRA%Pru XE$\k+ 0Q $ЬŔV^ÎKxMJ dnc7T*]$1Z^4)ALΪFK 1?xou(ylKIwq=u-q!.77ͧy-Uً~S^L]vrՋsI|dtȡJ n?X Lag=klO>`DZ~V\Yװ>x)R,>4¤7x⨦C~bOl2UC;2Rv*1vDNa-nXH=K]N}*[3;0KON7]`2!*g+Wx72Kgꩆ8:|;2j?|׭n6tz s Y*#&ӊ:~t ;.c+S I[-*N*ˢ f!]tMIx6z,jij,y=/ iRo|XbS-y[ˁlSlv5*؞M?1jQwN·!xBh 8ѣYp^4Fu\0I*Wom2ةB%$N0o}yiPX]sF"/IYz91+]W:034@ɉPl-}q0X1uנstVhl!F!enMzdĀ7d*aB>/,~ z R6%O R~LujL3~?69loYj ޖ=5p .AH,6sk'n 7E[glFJ:o̢mZU"dh'6v9WMx;Xc=$`d [?>Ll9`ֽLz`h0KwkGNe6 =I1E]U[8\ @#ٟp>ٰY(}fq2hoٱ ?S>P ',<q|4b0+~`jIn7oͤwޮ\}qu<=ϥ1<~.iM=2:};%x tv@_?G*dՉkK8Glp2|N 6`Ew>-gW|f4-0/!1PN%hJTFrہPF#_D@,ڡ>ڐ|+j);-I)񀝅\jӲ } sG:^Oi|z|oJ@p(~lMk ΁`a3 0QlK;PQo_akyÏ1_f:{u[M?$(sHnyX|q34 iO~?||XlN[6'= -\qf uz4 LBiC1q]͞V=g7]60 S;)Xȁܛdq{Npی?`@l_Vgahth>hkn [*X aRzW05-J6m{#a^E=S+gNn{qϹSK+9M!~URC;JI'Q3 `d6UgT5vCnk~1#Me( (i,t󰹕toI#P摽Rot=`Ds^q^*"er`^'rO;L_S0X|20n]כJ|< qx@kAwԦsl-Ͽ5lpE ݚ;DƁ.G>ײs5Yjae)jZb@xq5L2l&׳d>FG#qv1pLE ~SU[ӵ;Þ .6Ёӻc 6߰;}7]ў*M^#\2﹖;h\PT9{{M YZ