podman-4.9.5-150500.3.15.1<>,frp9|e%D5d#H<5ھ5m=j) {6)v;kd`3zg) [9[v*`R9S~lۮjƱYp֥ĠGD^32 jv]|D:%x2bVJ"[-jWy+eM!Bd_S{=PGjY ylzJI\#<[d{]*>O?d   c )NTZ     \ ]aftkLkpoPo|)p )s)(t08t89w,:*=Q<>QD?QL@QTBQ\FQnGQHUdIYDXZ<YZHZZx[Z|\Z]^d^tCbucvdw!ew&fw)lw+uw<v{ wxyh(zSXd|Cpodman4.9.5150500.3.15.1Daemon-less container engine for managing containers, pods and imagesPodman is a container engine for managing pods, containers, and container images. It is a standalone tool and it directly manipulates containers without the need of a container engine daemon. Podman is able to interact with container images create in buildah, cri-o, and skopeo, as they all share the same datastore backend.frs390zp37>SUSE Linux Enterprise 15SUSE LLC Apache-2.0https://www.suse.com/System/Managementhttps://github.com/containers/podmanlinuxs390x if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : for service in podman.service podman.socket podman-auto-update.service podman-restart.service podman-auto-update.timer podman-clean-transient.service ; do sysv_service=${service%.*} if [ ! -e /usr/lib/systemd/system/$service ] && [ ! -e /etc/init.d/$sysv_service ]; then mkdir -p /run/systemd/rpm/needs-preset touch /run/systemd/rpm/needs-preset/$service elif [ -e /etc/init.d/$sysv_service ] && [ ! -e /var/lib/systemd/migrated/$sysv_service ]; then /usr/sbin/systemd-sysv-convert --save $sysv_service || : mkdir -p /run/systemd/rpm/needs-sysv-convert touch /run/systemd/rpm/needs-sysv-convert/$service fi done fi if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : if [ "$YAST_IS_RUNNING" != "instsys" ]; then /usr/bin/systemctl daemon-reload || : fi for service in podman.service podman.socket podman-auto-update.service podman-restart.service podman-auto-update.timer podman-clean-transient.service ; do sysv_service=${service%.*} if [ -e /run/systemd/rpm/needs-preset/$service ]; then /usr/bin/systemctl preset $service || : rm "/run/systemd/rpm/needs-preset/$service" || : elif [ -e /run/systemd/rpm/needs-sysv-convert/$service ]; then /usr/sbin/systemd-sysv-convert --apply $sysv_service || : rm "/run/systemd/rpm/needs-sysv-convert/$service" || : touch /var/lib/systemd/migrated/$sysv_service || : fi done fi [ -z "${TRANSACTIONAL_UPDATE}" -a -x /usr/bin/systemd-tmpfiles ] && /usr/bin/systemd-tmpfiles --create /usr/lib/tmpfiles.d/podman.conf || : if [ -x /usr/bin/systemctl ]; then for service in podman.service podman.socket podman-auto-update.service podman-restart.service podman-auto-update.timer ; do if [ -e "/run/systemd/rpm/needs-user-preset/$service" ]; then /usr/bin/systemctl --global preset "$service" || : rm "/run/systemd/rpm/needs-user-preset/$service" || : fi done fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ "$FIRST_ARG" -eq 0 -a -x /usr/bin/systemctl ]; then # Package removal, not upgrade /usr/bin/systemctl --no-reload disable podman.service podman.socket podman-auto-update.service podman-restart.service podman-auto-update.timer podman-clean-transient.service || : ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_STOP_ON_REMOVAL" && . /etc/sysconfig/services test "$DISABLE_STOP_ON_REMOVAL" = yes -o \ "$DISABLE_STOP_ON_REMOVAL" = 1 && exit 0 /usr/bin/systemctl stop podman.service podman.socket podman-auto-update.service podman-restart.service podman-auto-update.timer podman-clean-transient.service ) || : fi if [ $1 -eq 0 -a -x /usr/bin/systemctl ]; then # Package removal, not upgrade /usr/bin/systemctl --global disable podman.service podman.socket podman-auto-update.service podman-restart.service podman-auto-update.timer || : fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ $1 -eq 0 ]; then # Package removal for service in podman.service podman.socket podman-auto-update.service podman-restart.service podman-auto-update.timer podman-clean-transient.service ; do sysv_service="${service%.*}" rm -f "/var/lib/systemd/migrated/$sysv_service" || : done fi if [ -x /usr/bin/systemctl ]; then /usr/bin/systemctl daemon-reload || : fi if [ "$FIRST_ARG" -ge 1 ]; then # Package upgrade, not uninstall if [ -x /usr/bin/systemctl ]; then ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_RESTART_ON_UPDATE" && . /etc/sysconfig/services test "$DISABLE_RESTART_ON_UPDATE" = yes -o \ "$DISABLE_RESTART_ON_UPDATE" = 1 && exit 0 /usr/bin/systemctl try-restart podman.service podman.socket podman-auto-update.service podman-restart.service podman-auto-update.timer podman-clean-transient.service ) || : fi fi(0",=DD.A&+,_ OCv+ +'+)+))')'**)'+, '(**)(,,,+) { = -2?F$*f,++)+O))()7+(2;* #b*h %; :1{u6*uIz K&n.&6@7 ZEO 3v oYr (E#4)EE+))p _r,!=% 2 k+> z/1A큤AAA큤A큤frfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfXzfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfrfr491c376b9b9303dfeffcb197832d859e29d3899275e879e7f99caee0bf77d0281b224bf6e73057a2614ac43d22de7e2ea05c7f508697f2861f99e3e2656e8017f14bf724e87c2633c605906c8144618650d10e7bcc570eeba7de5731bed14a6dbfdbd25abaa403e166d09d41c89283e25031da5579f4f53e824f38b8b3a36ddf8a1ce38cecc0eb837d1b16e072b771e5cbdbad0398addfa44085ca60955e6c9e60e13a3d58ca5a19e11fc78d5b5159e97b722eb71cdeecd336b6a3407a0cd1e0f01b639f41ebffa8aac92a1dcb281d41410c5df3b235c3c506581e8494d7b9b1b7093d0a542f8b1f9ba9717ceecc904fd913644b3935fd5944496634efc85f4e27dbdee5b45cb8b597efc3315dbe67e05752fd853a90372bd27724f19c1b87a3d499ac5e8fe3a863a79c5857a3d84238a00bb8c8c170786af1605ccbe8e560c43779462f87e25ef6783f1effaaccde711249450b87d33e7da19d8673d7a38da18a1ce38cecc0eb837d1b16e072b771e5cbdbad0398addfa44085ca60955e6c9e60e13a3d58ca5a19e11fc78d5b5159e97b722eb71cdeecd336b6a3407a0cd1e0b7093d0a542f8b1f9ba9717ceecc904fd913644b3935fd5944496634efc85f4e27dbdee5b45cb8b597efc3315dbe67e05752fd853a90372bd27724f19c1b87a3d499ac5e8fe3a863a79c5857a3d84238a00bb8c8c170786af1605ccbe8e560c43779462f87e25ef6783f1effaaccde711249450b87d33e7da19d8673d7a38da106ad12558f98b5d4eff5f71f62399efd4f6fba47414083073b187cb3fe6ade7c83ec9df204e33b1a2fc2505e00e875a71446b5ad0826a78eaac687749b1790e8e75f5d83e8c109b12a9ac874bd1fecf5ae56a79750862ec508475a0e19ac93f562fb8a3a9621dc2388174caaabe9c2317b694bb9a1d46c98bcf5655b68f51be35c36164390bb6385cecb1a2f8d3cae32db633ae342bcc25e4a2357f4d5bf2eca176d063713c208c878af2cd29f95cbeb724f63a0e4ca601a3c156280befa13dfc3e0c48c34e15d63d617eb1ea8854ab3c24d8927a611bbc128bd57c6ab1658e32e1fc029807985dadea45ff23d6a7a5681fd95a34117ed1d096190238c720f0f55f15acdac0c6627ddb5dff0c0dca596b32b16f181300617dec7354bf79bb3a87ca63b0bf61560bac3bc1a6d6d47cfb0c44ab7ec67b09a9e54fd70a40d75cde308fd3f0c6d62a6d4fcc9492786438960e9733297524a2767e79d685d9b4d239b928122392ca77214d088e9f57250e7200f310f42ea3e15a0ac57c43827f29df681c684b29af24e0f8f8e211d9a14180994f6dea305faeedd44bff15f6401a2d8fc12da8ee2b04891fe778e582cb3388ef463542e6b73476b70c3c3be9dc0d5d86f3950e86a73d07be1c4a942160625c9f41a5665ebd1a3d407de1a7c2fe2bd973479ff233e22a6a16364fd9d2658510538a9b44896265018798498623c18000799b7f93695a464cb10683de03b8fd5b49e09288eb154b7b3f284c8f065f702cca666fc43a82008c99439d3ac28c4b18f11fbd85c4a64a0ca6cc7c640f33e58d474632629e19cb511f45c8d3d4e1d7248fdacd1e04ecbf0aa8d2f270d1e2f69f44f60e52aa5fc19719e073c81a7b4903c9a8e19aae69d2907a38e65508445cdadd568eb766f9c8b29429851ef96a33480457c3e8ffc777fcb927f3833a5922e26f711e00a27a1b23575996bfcabc5453f1e0c5b718f966fe47589dc6d9f1e69a9bb0990576e980799c8442ec7680165ec60a22cd4fe3d0aa1db6bf67515e7948171c23950a629bb9d7ed158e034c0a538b8fabf7e91ca2cdd00dec790ea92eb3de5c96aa5ccd161d0b9ad7fce573a522f59bf2231ef73aad79f385d48fa81ec9f15a32ec14b5aa582df37b4b3c3dc0544fdaad0cff582bbdef0cb610715bfc5b9e5c96aa5ccd161d0b9ad7fce573a522f59bf2231ef73aad79f385d48fa81ec9f890d61d27cfba3223b79df23abf7007ac2ab9d3378e025b08c0d713078d3fdfafaf7065f2a4cc851e04a035447903830552061a549d8447a118ef7e3226cefb0dd7e27c041b6ab77ee8a14902e46907a8b18b27bfb6d900fd24d1ea7210e96892fa791bb20d2ffd99bc18d72eed36be67d064e2f8a635f7a1e3400b21fdac283e5c96aa5ccd161d0b9ad7fce573a522f59bf2231ef73aad79f385d48fa81ec9f627ceaab78bdb3208655561333361e56cc076290116f21e0efc27baf4e49379e445ef87ac4cdfdf7fdbcbb491a9b448dd64015ddd6696eac59268b34f75d28473dce302c0ec5f3404c4fbea2ea8de2e8823236554133f9da5c4f31885af41d351300c33d41d74bd0fb10644ff1a519d7509dbef3faab2de33da5426e235ef722cfa3282b2f032cb63ee1b373cba5539d1ecb711bece6274bc5f58b48a64dbe76d4cd6ebece74545302f81b60419d307a7284c4c36f3d96be013831eab90e2d01ac64abdcbbdc7cd29211d17a3ef34c3cebb5cad6be02c3b2117895615aa13235ea29894dfd7961034174e08292e41b684e02be4e95dc2f1ac2986ce1322cc7cde93cb3e59243ba0833d31c6e47221fabcdffea13f3114f4a08e3f1ea989dab819c926b0dda408015df84bb6841e86140907ad5bec8f426e259b342eb882227e2c7f0402903ea253ef11fd451e2d7eff66650e61a869bef47f290da2ce3ca0ab7c7f0402903ea253ef11fd451e2d7eff66650e61a869bef47f290da2ce3ca0ab7c991f8665eed30a7126ffeb5dbf24e8234b237e6233aa79c81b3378cfc017b644704b6c69f2ed8625c93e7de00d09f1dfb3073d009f9c0cd488b875450e4d7d6093952f17ab524df10bfa7c2eb461933c120e69f4de5ee930c6fdc9afc3b4ccea3d3af64eec3b36ad4e29d905461e241faf7f25cb021544ded73ca2f2c62b171905cc61a94d931e324b37e64ea5d7ea7f3e4e30d24efc6d9033233869866fe0c295a506756815b8a3bb6612a2021d7272c1beafc577ab4a1748b5511af6f458558c2faa8585d0ca4ea3efbdaa63c62c50fe7bbac8d2c5f10db47d6cb7569355bc8a39b86e004229747c1348c265011b838f547ce647eb3ce509def5a5e859710e4e9ff4039d4f52a80a9dfa0450ad09d688dea88ba3b7f68b49cbdc7b08e452f1cdd29e74f6021007038d481fb7f06da077e53300d77f50770773662e22e9cce706da45b7799d482d81c191fe291cbd43c3889a472e451e95e257290970363999fa56a54317e12b8f98b5668bfd5cdb003755221a4a072972c33d8ba2abb436f959d0021186752e995e4ce5ed4b2234df97a351169c9b0f8dc93f3a857327ab62efe339a8fdf2d74819cea9060a43541ef955add73db1486160f7aabb5fb4a671fe48dfed65b77caebfe4aa3b417ab284dc49055a54c2b2b7bab8482c906cd41c20d93d05e8f271b2704387eb2103ce6425327f56b4aa7826aafc8d73cdc3bb162bab6db9d0e85d8ad52ceeb3e518775fefbdb4b8ade2bc41a87fe0a129f0829f9df5cd3b6b37cee59f7a0bb6f675dab108189058d73a2d2cd03c676d4f0479e023201ec71de6ff541ec5ea92dc87792f867f113eb73a9af2493ebafc403cb372dfb8f1e355e267fa3e219ae0fd3363e6deeaccef1bc72055b454f90d2110e562b78b5ef31d737998b3dcee97cbfded3524835e12da4001c22e37374b61ec7fc0e3d4ec590c47c8924886049cd7d29ce327dc64312496b9302757cd0770cc50e702a78f7d98374626ac3d95b045a4c4850fe09882071b4545f902e9f3138d2f7dd105153cc8398c8668d3853c3ba68f3499cf933e3e750ea1ff613cd5fc457970d8f09fb5d6e4117955114781ff7091b3b25f811428130a8d18a7169f770da038e892c0f50fd42834cfbedaa856cef1ea3358c4db15c6b4c6cc3d645fb2b96e897c26d0a728714f9da369bb569e8ec1a358a505fec7d41464acaeecd30bdb9d16bc54f603d4498a2e2db5b65d705b7e336b16ca0ce59c582a18331b40d8abd7434ee9573d5cc2141423888b1d53b6dadad90ff537092d40464bde9acffd70e0ee895a187bff26a499fff5fce935ccb3f917eda73385b80ff92744d5faf8596529ea88444acde23cabaeb03e9f4791800dc7ba772faa565389934ae9e593d51f24252746f729aa756a63810571bfcb65dc0f028046de81d4679efe46e184cb5d79ea88444acde23cabaeb03e9f4791800dc7ba772faa565389934ae9e593d51f2c52e574c07133e8e6bf4e22acccadaad964e14b11cc615485b6ab88ec45c57c8fb0ffbfc8fa8105c7a446ae48c74fcf6bbe2cca8c9fb21a939df9e58f18ebd52dff08307fa5fab664ac7e85860ce62cfc099e2c1a7255fac0806402c0417685cfb05c98312d11180d532df7446fc29e50f9f96980fa12742c9e9eaeb275d82fe8f5149f91f71371bdf0e8ffd0fc91842b3659d7222b3b2a13434a7322e1e0d2bd32b8e22658ed7302d136915583cd9a122ebbdc7acaf9753409917b47d1565c463cc1b38ad7c2348648900a790078c93a883028c9dc38d912d040eca5e330ddf1f1d9596eb1afa516493ff914c6597173f4bbae5519df8c3ba6bcba3e99a7e164688cfb771dacd14bbd3ed4bae2d27922bc39bdbb0bec3678ab5b1da5b29371012e3289fe82f567d9ae897ee4e2306b66338110afb302d67c4bc4324b3dfb7b91ca9fe9de00f290842dc2ac82bcdd31b9b97dfbcfc4dfc43e6a4c9408c6fbaf9a326e8b60a8ccc778670f2b434fcb3f3dc9b149a16a4fffbca4f09d786569b7cbae4cfd5baa18a0e2978af29e41a484fcbc189672d3425e189a67b1ff3e4fa299c15d7718e03b93eb1625eea7045619a22d69a4bccd0d8cbc8d7a668acb564e3d20adeaf272d0ae90ae6fb1eba767daaad1e28cfcdbe200cb2a96b208310b90f916598eefb97468ea40488173033ecf7b07e22af9d2adeb18aa5923acce3ec3a39704f70097c31ba7245c0bd5c28709010b196beebba3fb7edfad523e30000b145fb0963c087e164e00b969131e5d8dcfcd03f71fb264c885586938dbd34030721e6d0ebcbe4ea405f084cc538ebdce7e6b8f469b9ee629f097e60761f76120729577e242d075bfc4cf25d29b0d85fdc94f2166672605e32ad6b4b84b618ff8148c3f0095a5744d5fc0a6504b7ddaae325582acdf79b441c71ed6ff96296adc98b05f73eb1bcea82e37520c6f544f508e140a1ee975e4639c83a559faf5a3c87ff4ad76607e859876ebfe469a060ada6760eba7141c495d8adc449520d6d3aa259b2651eb06f64cfcc3901ee2fc62f1159a7d38e2628abfcde1b4c000169a5ac68c8068ea92c344f02e4bdd6d972dba6648a6dac9c0ae173ea24fd4101d68d464d288aa357780223e46178dd6dfc5c3584eeb0d0fb268778edb7996f1e76721825e6f569cab47269fb2c3db1eb4ad0164b2d8310ac528344c4a57ad95bb7461982898f24cfac2dc36d6d990aaf4c7e313e2b5f219b737218c82f8b44e08add410861552ba25d571eff6700f7cb619c5850b375d86f88270e4ebe1bfa60c6f7676e491876794092e0babcb9f6cc58952b5832c7f5f64d8c5ca01f6761ae9d359d2addc3a414fcf0d24d28b9ddb34b704b9d4de93416221e92e5d7ebe906ac3fda5cb33ffb9ecace1c3671740d9af5a5611c887d2a3a678c6dcecafb7dd2ffa7a69048f8d976f376357fcbf658895637d6f8411e3e38c5d4233dc755cfa328117c9187ed7ac3ab28be7c83bbcceed98245d2ba2e54732577a7b536ec3d16cf649e23ef10d14c9528598e3399143a9fad115ba975c70d219bfe44a30e693d25fd38743533b2296d3c9ad29f5eb70a28f6e1fabc0c5986e72b7008cbfe6c98536d8b678324f750f269aacb7f64373a31e0940b2d4319cf8d475cf47a80754102ce9bc3cf1d3df18feca7808b3c44594e93e8a432a2a4a4df584c31d03d9aedd7cfccbf63c7f155f10e7e30de3d1af401281178d20dfb348ba2d7154394134e9748d76b6139a2fbf5f10e311daed970f0206c473c356dda3d3c898e7e3e34e2c12949ee77beac19a2bde6c66582b1346fa98b5745be7a6fc26d0cfef6a1284eb5db1915a5234967c3f0720519fd7266131f46d30598620eb742b9716192d8f71539cfb6e6d99937cf8366edba7525ce399a697e11d8eceab60776335d88790b42f77e70eae379caf8ca1547f4086db307af66692715b88c71ecf1c42c3f3b5f1b258519572c7f847e9eeaf3f5a1b6bcb8112f78f257fbdfb513d365e09ade2a1107bf280e718ea8153c49c6a00417915ddb2eda0beb9224de44308430beb18944b8a7b46f340346a5ff0feb405479a35872abc033db170c37426b53d87dd47a7bf4bd7aa197acee4adec74e561beae6ef1f75ca1b1ab44e76ddcd9b89fdb4081a4d714c81b2072a38bda47148a432919b1b33ba9bb1e036fde51bd11f154fa26aa2c9b7c207eb613c8ce5853b46669718d0ac0552b911a7b101cf0b68e89ce20ce06f31f63b9830cfefc798e0dee784411a8230a7933449780a3bacfbdf7559a6d1c386c800d697d7d4a6302ac73d55757310ade772321e5855088fcd07810dd8f5429e578429e7e43d71e81b2dcb42790679c86b167f7f1ca00f73a6bb7f960c0002b22038d950564de2227c1096d3d6e62dadd5f09382e8d9433361254333892754d84205dfe3996b9ee49c69dfdc3cfa80d040929cfaa131c48cd6bf9a0bff9ebb6ab8bf9c5e8ac5a0e5bfc7c857d8a4607d9d48c29e55c2bc4f578ac2ac567ff5dfddee2959adc690cf65090e27cfe2440a623d6dff47a01ce51992990e94b9451b8c455cb0a18a49130f623d9e3e715e8ec5f948eea25d171ae6f21f1d1660895c386a0d0cc336afd0bb34bbdc930416cca200d929134cc7884385c20716c88f1bad1ff016b27af13fc938c98382d8d09c9a389c7f3f59c0a5b3d002312bc22cc915978e4409d88d469b6d18a2bb8425e2518ae94c6fa3ce8d29200cd7de44bc28525b6ce558c51dbc8dbeba4f87c1722c947a9b1c0ed356a55d0b178212a3ff81e106b855f053d99cd9313301fdf65fc65ba79688b7eef0fd7847864725ded14dcdf8cdb84789ed140d69d8775335a21a1f33d2178810839436733ada6e14d4f1c50c95ce073815cf2067c07a6c6c06c133ac8f25f8545fbcb73e3d233d157aa7f5e7dd50e058fec0d8f726c0385f63c3f08b0143c2401d4f653b3bce40623c426e6f91683df0a6871c7871bf2454c57cb40b9e013506e1d9d4a3636ff994d035b6e786605d62e7ee2d562bcdd389faea94d8e467260feaff22bba8f215022b79e952b76f2d7cb38b54aa4cc4854e684618cc5b60dd3d0009ce852bcdcd61ff9c2a30ac82afc29f4818cd69a12e451eee8247a998750cf5e07ddadfb67301d3c638d51b9cb5e688e5ddb3f9c63c6d0d2bc672304ebeba6e84ce917b820360916cf80aa8910d7b06fc1160a357d1092d4de34b55086a6ef4654ed06702a28f3a89df1d857236b20c38fc937a4b47eabc9a37cbe1e58cd7f38edd0565ab7dba2738d3da4ef29681faa4193cefad9c0fdd5cdb0aa5ea17ae97a6b7fbc04a3213358ef87414955cfdcedb2dc3abb0487e00e70a8f3c58e8f48594d729ddc1a50edaf1735459aa315c12ff458dfb397c8c0abe2404244f837d0312b707b8f88ad6cc3e60452b5cbce3559f31b3b88be66d4b37a6156af7cf603ad03c312c023a7c4473e8efac86c26c23a2317757ff75dc48d4ee0af4c364669f6fb2d4822054bef0916a568e9794fefb86c9870bc3afc08f5ec0eb7775be32a385047f1aee5fde6a8ee662cd4a350463522c3b661693b7382f4f67f8818a8f686fd3c7f96afb325ad5af01aede28e26226391cfc06dc06dc884292b477fa8174dd98634ca0b4d4e530531e095f8692372b004071a5eac98ac3ce5b0c49e047223d0cc4bf2b4e1a6a518d336c42b1015eae09dc184acb193b0da732a3890ce36f428a5aa68f60a5bec86e743858fda328a6dfd11fdec2bddcfe27b0c261ccc3c5adcb6a77cf36cefcec081bbe4d28091378cf6be5db37570d2d0a4f6f0fbfd92a6be493d23f3ab29c073dc0493dc493c06ec087f4483860dc58beb2c2b3441198c7ece26b5ce8de35b6d12c0c389d1fe0e6f90a801c704e62d96a580dea8a4047056061bc3342c27823f56483b5fb55a97513a9a35c97f1addb6635d783097f1cbb00e3971aff71853bc1a793bfa046d2af51f39343fb983879b981d15c34f5ce5310c44a0513cc6bec40599a4796087e75957a292091cdd70132a9297828e6fa9465ffe891d9a488d327eae9a961547a1d570011b2ed4f44f7f0e04e94252510109a317a955ef0e5b4d6d0bce62d64a39a03770c77d1a4abcc5f638890c182ac445c2cb9bc22223327a8df7dd4cf303baa74c467f7ef96fef9089c8b57db80a71c8ec18651257938f14fa1d1c15de1da97581215dfd85eacd6f8fd11f1e637d42c3283050f37222982c613d6c6c854487e54c56348f4a44537c157a438df011613bc347d14de46743af8e186591aeb8926dd9c55e4621093f1f867d1074083884f038ca5e6cfd23afb6ee6bd887464e226862200b3cecba9788baa1ac5839efb459743316be32142964abbe7757e9616f53217014636a2bf15da20774eab0f662d0a2d5034b89c16256c67c5df29a350b1340ebe459de70b652073dfaeb38064498d00e6d098f10e2d61c1bd98ef40a8cce4f377d9d45d27a99ba696d714e543ac48adeea678ebdd622d1bede0372bc76b8724758ea54c92ea80741ca83b730b0d1e7d026ec457c54851c606d68ae4d59c5fa1d2ddd83c9a8ac4fdbd48f02433032317568707d347d397c6af0e38df60349d3840eb863aa0d62d9fd23700eb5c522df39e4744830c6434c78fa02b0713e45cfa27575a16da1c48ef8bc8f2fe4f5271d8c514867079e3f4ccfaf0b8bb828ccd6d897243ae776fb6fcd7b9d569c001b9881560b59a3b34bcfb0da5cc33a80c62a8e5e56bd029d94573d076ffbcfc86ff81d7136d6fa93225c59e9fd22a0505f39d369faced6846b2b6750ddfd629fa006a75a9119d7040d0fafc50cb0356cd0bc856de7beed7a84efa34b55c1ef8a5093e850eef92289b12415111e7ecbf0027beb445bbbd15a5925d4b9554df379f21eaf5a3e0c35a8c6774240059f78a10a4f1461ee00c0846405967aeed422a1d7512aa27a6e075bea616fa59edefde4c472ff921621be9d95f1f0e8f3fd55aeb7d8b40e481bc9f980bbd322412c9b4e7b39ec4a8a91d46d12576e706f6a86ce9e36b5f0cad864f3439ea77236919ac78d37758131ed1302a2ef668960339ad818b4ac9d67504192cc61a3a08197e9e6b25973cd4aef80339e74be49afb502755446dae932518563ea89cf82078d0024e63d4a65b255370b53c1fecc27cebe115028fa2a342a9518c65f35574e019f859c41e95f6f08d4a8e78ae1aca86fa4d0a5fdd695fdc2ffc9b888fda557e6095960e8487b2acc87bd8f299804d639ffe038e65c939054a5d13bb62cc05da086a73d4bbd5f168a8ad3406d76780d8cfc2925a137805dfe39805e81ab043e12c12234f1e678c6cad62963cb34d3e56bf0898578c81f4193b27f917e18f9f3bb72ecebc925e8efcbd538efb4f192036aee6bc5d8a31d0a408c1df8462619c7eb13770dccf7697572208eb1f74fba86c83b731df9717cd6fc723c7f0402903ea253ef11fd451e2d7eff66650e61a869bef47f290da2ce3ca0ab72f7f9591a658fd469b89c9b7abd733983033f881514b0b6cfe012cf301d93fba09ff4dd0d9e74f81a2c379d9eb5bf945faf9abcfb711efc78f210e9f90afcf622bf105c01fb26d9fbca679f7fc408f11d33bd01d30f21746968f00f081b1b146f2f3c02a6b47167ced7a7f8218317e47819a6a7bf18bd1d4dce52969d637059ade78e2270c1a6a9ad2cebe605a2a2018e72511e289eb639be8c0ae3078b49550c0eb1d3cbd99c06c3292cf2cc0e4a3fc153f75beebe4869f5be88a14f6fb99e78e2b8559f24f6c81ff743e75bed25fffab9f484af48f75cf383974c713d5b59d98807250a01cb4db7e69ec377d7ad61dfa4e353a0a5f7d9a42e5ef35f3bf71c78568a4ed076196961d46aaae8040ea2815b0ceef84aab0a014579d5347c807baabe15f57cc51dfd77ab56a53fcc1ce088669ba559bbaccc70a44abdace671d71bb4800e8168f969ad55e9cdbeda6a14997f6a95d5b1839fd038c81ce947b1c6f0ac15c9f80a36d6d39505fb9df9981dfbef6c19682595c92bdc65005a59c0f2a0307054da8e9674d1ff1ba41f5a4a7ee883b4f556aff71e290ad65d6c5e9752f84e6beb14e0156ed2cb86d60889901a0a582f9f12ce8e2b8df8ecc9ec8f3ae89deaded520b40e11d700e4abe22f0ecaa10c91612d855f2b3d4d9452735200d7bd0e68360155f4521cb611867f4e288e3c4880b14e6efce0b02a2475e9d9aa9653bbd88ede868eebddc1edb75179ed0e219059443b0f4d6c71a9c1d4ba8b87de9ba3912680fe8c19e595fb4a66cd4deca98c1657e2bfb4dd7299c188599db59cbd59d90cde6ff6353058d40d8f82bedc08d82ed630888e010a5af6e68d3e0cd5189b36bd05755c1f3f76430e409c87ad6001578f9aa6b5d56fe64076fb2f6a443237cdd27f6d116db2081f076cb2be8a3a445fdd1b55c27fc6d666943a8fa686bc4dc954d9c73c47851f9abbc02c724757280f07520c7347eacbcf2e9705f478c3ead8eed2fff3efb0a3d04289ecd18024d30e88f72d50eb4a57d1bbc205418f1bb0df2fe593484e2827387774e0da2521b3fd3b509481694f99a65dc46e44a1a../../podman/quadlet../../podman/quadlet@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpodman-4.9.5-150500.3.15.1.src.rpmpodmanpodman(s390-64)podman-cni-config@  @@@@@@ @@@@@@@@@@@@@@@      (kmod(br_netfilter.ko) if kernel)(netavark or cni-plugins)/bin/sh/bin/sh/bin/sh/bin/shcatatonitconmonfuse-overlayfsiptableslibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.4)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcontainers-commonlibdl.so.2()(64bit)libdl.so.2(GLIBC_2.2)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libpthread.so.0(GLIBC_2.2.3)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)libresolv.so.2()(64bit)libresolv.so.2(GLIBC_2.2)(64bit)librt.so.1()(64bit)librt.so.1(GLIBC_2.2)(64bit)libseccomp.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rpmlib(RichDependencies)runcslirp4netnstimezone0.1.72.0.24202302143.0.4-14.6.0-14.0.4-14.0-15.2-14.12.0-11.0.10.4.04.14.3f@fb@e~@eeyeveqepb@ee@eKx@eB=e@@e'ee@ejddܺ@d"d˖ds@dr@d@dtd>@d9@@d"dc@cc@cl@c@cۥcƍcGc|c*b@bb@bw@bUibN@bN@bF@b1@aa@aLaapaV@a0a.a#a@a^`@`h@`D`[``}p`pA`a@`6?`6?_T_ǁ_@_ts@_Wr@_O@_D@_;_3_)M_'@_$_ @_ @_@_@^@^˳@^l@^H^%@^}^}^t@^j$@^`^`^Nt^=Q@^*@^[^@]+]]]4@]p]m@]e@]S]@1@]9]0_@]/ ]%@]#0@]^@]@\\Q\t@\9\ޢ@\P\@\@\\@\Y@\\@\}@\v{\u*@\k\Q\N\@n@\?\;(@\4\@\ `[@[[v[G[$@[[ @["@[[z@[qr[l,[h8@[^[U@[L[CN@[:[0@['[d@[o[{@[ @[@Zz@Z?Z@ZZZZUZZlZZ@Z@Z`@ZZZ@ZZ Z}@Zz@ZxG@Zs@Zp^@dcermak@suse.comdanish.prakash@suse.comalexandre.vicenzi@suse.comdanish.prakash@suse.comfvogt@suse.comkastl@b1-systems.dedanish.prakash@suse.comdanish.prakash@suse.comdanish.prakash@suse.comschwab@suse.dedcermak@suse.comguillaume.gardet@opensuse.orgdcermak@suse.comdanish.prakash@suse.comdanish.prakash@suse.comkastl@b1-systems.dedanish.prakash@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdcermak@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdcermak@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdcermak@suse.comfvogt@suse.comdcermak@suse.comdanish.prakash@suse.comdanish.prakash@suse.comdcermak@suse.comasarai@suse.commichael@stroeder.compredivan@mts.rsrbrown@suse.comdfaggioli@suse.comrbrown@suse.comfvogt@suse.comfvogt@suse.commichael@stroeder.comrbrown@suse.comdcermak@suse.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.comalexandre.vicenzi@suse.commichael@stroeder.comalexandre.vicenzi@suse.commichael@stroeder.comidesmi@protonmail.comidesmi@protonmail.comidesmi@protonmail.comfvogt@suse.comalexandre.vicenzi@suse.comalexandre.vicenzi@suse.comfcrozat@suse.comrbrown@suse.comdmacvicar@suse.commichael@stroeder.comrbrown@suse.comadrian@suse.derhafer@suse.comrhafer@suse.commichael@stroeder.commichael@stroeder.comrbrown@suse.comkukuk@suse.comrbrown@suse.comsgrunert@suse.comrhafer@suse.comrhafer@suse.comfvogt@suse.comrhafer@suse.comrhafer@suse.comrhafer@suse.cominfo@paolostivanin.comsgrunert@suse.comsgrunert@suse.comrhafer@suse.comrbrown@suse.comrhafer@suse.comsgrunert@suse.comsgrunert@suse.comrhafer@suse.comrbrown@suse.comrhafer@suse.comsgrunert@suse.comsgrunert@suse.comrhafer@suse.comrhafer@suse.comrbrown@suse.comrbrown@suse.comsgrunert@suse.comsgrunert@suse.commvedovati@suse.comsgrunert@suse.commvedovati@suse.comsgrunert@suse.comsgrunert@suse.comrbrown@suse.comrbrown@suse.comrbrown@suse.commvedovati@suse.commvedovati@suse.comrfrohl@suse.comrfrohl@suse.comsgrunert@suse.comsgrunert@suse.comsgrunert@suse.comsgrunert@suse.comsgrunert@suse.comsgrunert@suse.comrbrown@suse.comfcastelli@suse.comguillaume.gardet@opensuse.orgjengelh@inai.derbrown@suse.comrbrown@suse.comrbrown@suse.comfcastelli@suse.comrbrown@suse.comrbrown@suse.comrbrown@suse.comdmacvicar@suse.derbrown@suse.comjmassaguerpla@suse.comrbrown@suse.comrbrown@suse.comrbrown@suse.commvedovati@suse.comadrian@suse.devrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comdcassany@suse.comvrothberg@suse.comparlt@suse.comparlt@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comparlt@suse.comvrothberg@suse.comvrothberg@suse.comparlt@suse.comasarai@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.comvrothberg@suse.com- Add patch to fix bsc#1227052 / CVE-2024-6104: * 0001-Backport-fix-for-CVE-2024-6104.patch - Add missing BuildRequires man- Remove upstreamed patches: - 0001-CVE-2024-1753-container-escape-fix.patch - Update to version 4.9.5: * Bump to v4.9.5 * Update release notes for v4.9.5 * fix "concurrent map writes" in network ls compat endpoint * [v4.9] Fix for CVE-2024-3727 (bsc#1224122) * Disable failing bud test * CI Maintenance: Disable machine tests * [CI:DOCS] Allow downgrade of WiX * [CI:DOCS] Force WiX 3.11 * [CI:DOCS] Fix windows installer action * Bump to v4.9.5-dev * Bump to v4.9.4 * Update release notes for v4.9.4 * [v4.9] Bump Buildah to v1.33.7, CVE-2024-1753, CVE-2024-24786 (bsc#1226136) * Add farm command to commands list * Bump to FreeBSD 13.3 (13.2 vanished) * Update health-start-periods docs * Don't update health check status during initialDelaySeconds * image scp: don't require port for ssh URL * Ignore docker's end point config when the final network mode isn't bridge. * Fix running container from docker client with rootful in rootless podman. * [skip-ci] Packit: remove koji and bodhi tasks for v4.9 * Bump to v4.9.4-dev * Bump to v4.9.3 * Release notes for v4.9.3 * Remove gitleaks scanning * [v4.9] [skip-ci] packit: update fedora downstream branches * @@option volume.image: be specific that -v only affects RUN * Accept a config blob alongside the "changes" slice when committing * container create: use ParseUserNamespace to parse a user namespace setting * Bump to v4.9.3-dev * Bump to v4.9.2 * Release notes for v4.9.2 * Cirrus: Update operating branch * [v4.9] Bump to c/common v0.57.4, buildkit v0.12.5, c/buidah v1.33.5 * Fix updated runc dep breaking pod devices cgroup * systests: kube with policies test: fix race * Remove go.mod pin of runc and update to latest * systests: kube with policies test: fix race * Bump to v4.9.2-dev * Bump to v4.9.1 * Release notes for v4.9.1 * [v4.9] Bump Buildah to v1.33.4, c/common v0.57.3, c/image v5.29.2 * pkginstaller: bump Qemu version to 8.2.1 * Assign separate ports for each appleHV machine * Fix machine inspect test config * AppleHV: update LastUp time * applehv: return socket path from setupAPIForwarding * applehv: Remove unneeded cmd.ExtraFiles assignment * abi: drop check for IsRootless() * system: enhance check for re-exec into rootless userns * system: enhance check for re-exec into rootless userns * Fix `podman machine set --rootful` for applehv * applehv - fix vm lookup * rpm: use go-rpm-macros on RHEL 10 * Bump to v4.9.1-dev * Bump to v4.9.0 * Fix a small grammar error in RELEASE_NOTES.md * Fix push endpoint stream * Finalized release notes for v4.9.0 * farm build: push built images to registry * Move the --farm flag to farm build command * Clean up farm-build miscommit * [CI:DOCS] Add podman farm build doc * Add release notes for v4.9.0 * gvproxy: Update to 0.7.2 release * [v4.9] Bump Buildah to v1.33.3, c/common to v0.57.2, c/image to v5.29.1 * Add a net health recovery service to Qemu machines * Set up podman machine remote user correctly * Remove Libpod special-init conditions * Fix `podman system reset` with external containers * [v4.8] podman kube play: fix broken annotation parsing * feat: disable pid max in the podman machine * systests: cp: add wait_for_ready * System tests: fixes for RHEL8 gating failures * Add API forwarding support for HyperV * bump to v4.8.4-dev- Add patch for CVE-2024-1753 (bsc#1221677): 0001-CVE-2024-1753-container-escape-fix.patch- Update to version 4.8.3: * Release v4.8.3 * Update RELEASE_NOTES.md for v4.8.3 * update module golang.org/x/crypto to v0.17.0 [security] * Error on HyperV VM start when gvproxy has failed to start * bump release to v4.8.3-dev- Refactor network backend dependencies: * podman requires either netavark or cni-plugins. On ALP, require netavark, otherwise prefer netavark but don't force it. * This fixes missing cni-plugins in some scenarios * Default to netavark everywhere where it's available- Update to version 4.8.2: * v4.8.2 * [CI:DOCS] Update RELEASE_NOTES.md for v4.8.2 * Kube Play - set ReportWriter when building an image * Fix user-mode net init flag on first time install * bump c/common to v0.57.1 * bump version to v4.8.2-dev- Default to the new networking backend, netavark, on openSUSE (bsc#1217828)- Update to version 4.8.1: * v4.8.1 * Update RELEASE_NOTES.md for v4.8.1 * Handle symlinks when checking DB vs runtime configs * libpod: Detect whether we have a private UTS namespace on FreeBSD * pkg/bindings: add new APIVersionError error type * fix podman-remote exec regression with v4.8 * sqlite: fix issue in ValidateDBConfig() * sqlite: fix missing Commit() in RemovePodContainers() * sqlite: set busy timeout to 100s * Fix locking error in WSL machine rm -f * Gating test fixes * If API calls for kube play --replace, then replace pod * Fix wsl.conf generation when user-mode-networking is disabled * Bump to v4.8.1-dev- Update to version 4.8.0: * Bump to v4.8.0 * Update release notes for 4.8.0 * Add notes on upcoming deprecations to release notes * [v4.8] Bump to Buildah v1.33.2 * [CI:DOCS] Update release notes * machine applehv: create better error on start failure * Bump to v4.8.0-dev * Bump to v4.8.0-rc1 * Create release notes for v4.8.0 * Update release notes from v4.7 branch * Cirrus: Update operating branch * rootless_tutorial: modernize * Bump Buildah to v1.33.1 * Bump Buildah to v1.33.0 * Update to libhvee 0.5.0 * vmtypes names cannot be used as machine names * Add support for --compat-auth-file in login/logout * Update tests for a c/common error message change * Update c/image and c/common to latest, c/buildah to main * CI: test overlay and vfs * [CI:DOCS] Add link to podman py docs * Test fixes for debian * pasta tests: remove some skips * VM images: bump to 2023-11-16 * fix(deps): update module k8s.io/kubernetes to v1.28.4 [security] * [CI:DOCS] Machine test timeout env var * Quadlet - add support for UID and GID Mapping * Quadlet - Allow using symlink on the base search paths * [skip-ci] Update dessant/lock-threads action to v5 * Avoid empty SSH keys on applehv * qemu,parseUSB: minor refactor * fix(deps): update module github.com/gorilla/handlers to v1.5.2 * docs: fix relabeling command * Pass secrets from the host down to internal podman containers * (Temporary) Emergency CI fix: quay search is broken * Update podman-stats.1.md.in * [CI:BUILD] packit: handle builds for RC releases * Quadlet test - add case for multi = sign in mount * set RLIMIT_NOFILE soft limit to match the hard limit on mac * rootless: use functionalities from c/storage * CI: e2e: fix a smattering of test bugs that slipped in * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.13.1 * vendor: update c/storage * Improve the documentation of quadlet * Fix socket mapping socket mapping nits * fix(deps): update module golang.org/x/tools to v0.15.0 * fix(deps): update github.com/containers/libhvee digest to 9651e31 * [skip-ci] Update github/issue-labeler action to v3.3 * Document --userns=auto behaviour for rootless users * machine: qemu: add usb host passthrough * fix(deps): update module golang.org/x/net to v0.18.0 * fix(deps): update module github.com/onsi/gomega to v1.30.0 * Refactor Ignition configuration for virt providers * [CI:BUILD] rpm: disable GOPROXY * Automatic code cleanups - JetBrains * Refactor key machine objects * systests: add [NNN] prefix in logs, NNN = filename * systests: add a last-minute check for db backend * applehv: allow virtiofs to mount to / * Run codespell on podman * update completion scripts for cobra v1.8.0 * Fix man page display of podman-kube-generate * Try to fix the broken formatting of man podman‐kube‐apply(1). * fix(deps): update module golang.org/x/text to v0.14.0 * docs: make CNI removal explicit * fix(deps): update module github.com/gorilla/mux to v1.8.1 * fix(deps): update module github.com/spf13/cobra to v1.8.0 * fix(deps): update module golang.org/x/sync to v0.5.0 * fix(deps): update module github.com/mattn/go-sqlite3 to v1.14.18 * Podman push --help should reveal default compression * Update container-device-interface (CDI) to v0.6.2 * fix: adjust helper string in machine_common * fix: adjust helper string in machine_common * remote,test: remove .dockerignore which is a symlink * [CI:DOCS] Update dependency golangci/golangci-lint to v1.55.2 * fix: adjust helper string in machine_common * vendor: update github.com/coreos/go-systemd/v22 to latest main * CI: default to sqlite * vendor: update c/common * check system connections before machine init * Consume OCI images for machine image * freebsd: drop dead code * libpod: make removePodCgroup linux specific * containers: drop special handling for ErrCgroupV1Rootless * compose: fix compose provider debug message * image: replace GetStoreImage with ResolveReference * vendor: bump c/image to 373c52a9466f * Refactor machine socket mapping * AppleHV: Fix machine rm error message * Add status messages to podman --remote commit * End-of-Life policy for github issues * fix(deps): update module github.com/shirou/gopsutil/v3 to v3.23.10 * Support passing of Ulimits as -1 to mean max * fix(deps): update github.com/docker/go-connections digest to 0b8c1f4 * fix(deps): update github.com/crc-org/vfkit digest to f3c783d * Log gvproxy and server9 to file on log-level=debug * Change to using gopsutil for cross-OS process ops * Initial addition of 9p code to Podman * libpod: fix /etc/hostname with --uts=host * systests: stty test: retry once on flake * systests: pasta: avoid hangs * Fix secrets scanning GHA Workflow * [skip-ci] Update dawidd6/action-send-mail action to v3.9.0 * docs: clarify systemd cgroup mount * podman build --remote URI Dockerfile shoud not be treated as file * Small fixes for wacko CI environments * Do not add powercap mask if no paths are masked * compose: try all possible providers before throwing an error * podman kube play --replace should force removal of pods and containers * Sort kube options alphabetically * container.conf: support attributed string slices * CI: podman farm tests cleanup * Mask /sys/devices/virtual/powercap * Update module github.com/google/uuid to v1.4.0 * fix(deps): update module github.com/docker/docker to v24.0.7+incompatible * fix(deps): update module go.etcd.io/bbolt to v1.3.8 * CI: systest: safer random_rfc1918_subnet * CI: e2e: safer GetPort() * Fix broken code block markup in Introduction.rst * chore(deps): update module google.golang.org/grpc to v1.57.1 [security] * chore: remove npipe const and use vmtype const for checking * Update module github.com/onsi/gomega to v1.29.0 * CI: try to fix more networking flakes * fix: check wsl npipe when executing podman compose * [CI:DOCS] Update dependency golangci/golangci-lint to v1.55.1 * Quadlet - explicit support for read-only-tmpfs * compat API: fix image-prune --all * Makefile - allow more control over Ginkgo parameters * Add e2e tests for farm build * vendor c/{buildah,common}: appendable containers.conf strings, Part 1 * Add podman farm build command * Add emulation package * Use buildah default isolation when working with podman play kube * docs(API): Fix compat network (dis-)connect * test/e2e: do not import buildah * pkg/specgen: remove config_unsupported.go * pkg/parallel/ctr: add !remote tag * pkg/domain/filters: add !remote tag * pkg/ps: add !remote tag * pkg/systemd/generate: add !remote tag * libpod: add !remote tag * pkg/autoupdate: add !remote tag * vendor latest c/common * libpod: remove build support non linux/freebsd * Fix typo * test/apiv2: adapt apiv2 test on cgroups v1 environment * ginkgo setup: retry cache pulls * Support size option when creating tmpfs volumes * not mounted layers should be reported as info not error * CI: stop using registry.k8s.io * fix(deps): update module github.com/vbatts/git-validation to v1.2.1 * test fixes for c/common tag chnages * vendor latest c/common * hyperV: Update lastUp time * [CI:DOCS] Update dependency golangci/golangci-lint to v1.55.0 * lint: disable testifylint * lint: fix warnings found by perfsprint * lint: fix warnings found by inamedparam * lint: fix warnings found by protogetter * libpod: skip DBUS_SESSION_BUS_ADDRESS in conmon * Use node hostname in kube play when hostNetwork=true * cirrus setup: special-case perl unicode * network: document ports and macvlan interaction * quadlet: document cgroupv2 requirement * [skip-ci] Update actions/checkout digest to b4ffde6 * Revert "Emergency workaround for CI breakage" * remote: exec: do not leak session IDs on errors * fix(deps): update github.com/containers/storage digest to 79aa304 * fix(deps): update module k8s.io/kubernetes to v1.28.3 * System tests: fix broken silence127 * Add TERM iff TERM not defined in container when podman exec -t * Emergency workaround for CI breakage * Kill gvproxy when machine rm -f * Fix path for omvf vars on Darwin/arm64 * Allow systemd specifiers in User and Group Quadlet keys * libpod: rename confusing import name * use FindInitBinary() for init binary * vendor latest c/common * exec: do not leak session IDs on errors * systests: cp test: lots of cleanup * Define better error message for container name conflicts with external storage. * Quadlet - support ImageName for .image files * test/system: ignore 127 if it is the expected rc * test/apiv2/20-containers.at: fix NanoCPUs tests on cgroups v1 * image history: fix walking layers * fix(api): Ensure compatibality for network connect * [CI:DOCS] Add cross-build target info. * machine set: document --rootful better * libpod: restart+userns cleanup netns correctly * Minor log and doc fixes * Quadlet man page - discuss volume removal explicitly * Quadlet - add support for KubeDownForce * System Test - Quadlet kube oneshot * Fix output of podman --remote top * buildah-bud: test relative TMPDIR * Fix handling of --read-only-tmpfs flag * Vendor common and buildah main * remote,build: wire unsetlabels * test: build with TMPDIR as relative * docs: add unsetlabel * vendor: bump buildah to v1.32.1-0.20231012130144-244170240d85 * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.6.2 * fix: pull error response docker rest api compatibility * Show client info even if remote connection fails * fix(deps): update github.com/containers/libhvee digest to e51be96 * Run codespell * SetLock for all virt providers * Machine: Teardown on init failure * healthcheck: make sure to always show health_status events * Apply suggestions from code review * [CI:DOCS]rtd: implement v2 build file * Quadlet - support oneshot .kube files * libpod: fix deadlock while parallel container create * fix(deps): update module golang.org/x/net to v0.17.0 * api: add `compatMode` paramenter to libpod's pull endpoint * api: break out compat image pull * fix(deps): update module github.com/cpuguy83/go-md2man/v2 to v2.0.3 * use sqlite as default database * vendor latest c/common * fix(deps): update module github.com/nxadm/tail to v1.4.11 * Check for image with /libpod/containers/create * container: always check if mountpoint is mounted * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.13.0 * vendor: update c/storage * api: drop debug statement * Quadlet - add support for global arguments * Add system test * fix(deps): update module golang.org/x/tools to v0.14.0 * Don't ignore containerfiles outside of build context * fix(deps): update github.com/containers/libhvee digest to fcf1cc2 * fix(deps): update module golang.org/x/term to v0.13.0 * Update module golang.org/x/sys to v0.13.0 * [CI:DOCS] Add updating version on podman.io to release process * containers.conf: add `privileged` field to containers table * Implement secrets/credential scanning * Cirrus: Execute Windows podman-machine e2e tests * vendor: bump c/storage * Update module golang.org/x/sync to v0.4.0 * [CI:DOCS] update swagger version on docs.podman.io * Create Qemu command wrapper * Adjust to path name change for resolved unit * Revert "Fix WSL systemd detection" * [CI:BUILD] rpm/copr: gvforwarder recommends for RHEL * [CI:DOCS] update kube play delete endpoint docs * [CI:DOCS] Remove dead link from README * test/system: --env-file test fixes * Revert "feat(env): support multiline in env-file" * Revert "docs(env-file): improve document description" * Revert "fix(env): parsing --env incorrect in cli" * Filter health_check and exec events for logging in console * inspect: ignore ENOENT during device lookup * test, manifest: test push retry * Fix locale issues with WSL version detection * vendor: update module github.com/docker/distribution to v2.8.3+incompatible * vendor: bump c/common to v0.56.1-0.20231002091908-745eaa498509 * Update github.com/containers/libhvee digest to e9b1811 * windows: Use prebuilt gvproxy/win-sshproxy binaries * Volume create - fast exit when ignore is set and volume exists * Update golang.org/x/exp digest to 9212866 * Update github.com/opencontainers/runtime-spec digest to c0e9043 * remove selinux tag as not needed anymore * [skip-ci] Improve podmansh(1) * Build applehv for Intel Macs * Revert "GHA Workflow: Faster discussion-locking" * update vfkit vendored code * Add DefaultMode to kube play * Fix broken podman images filters * Remove `c.ExtraFiles` line in machine * podman: run --replace prints only the new container id * New machines should show Never as LastUp * podman machine: disable zincati update service * Revert "cirrus setup: install en_US.UTF-8 locale" * Cirrus: CI VM images w/ newer automation-library * CI VMs: bump to f39 + f38 * [CI:DOCS] Update podman load doc * Update mac installer to latest gvproxy release * Fix WSL systemd detection * Add documentation for the vrf option on netavark * fix(deps): update github.com/containers/common digest to 9342cdd * fix: typos in links, path and code example * e2e: ExitCleanly(): manual special cases * e2e: ExitCleanly(): the final fron^Wcommit * [CI:DOCS] Add win-sshproxy target to winmake * wsl: enable machine init tests * Update docs/source/markdown/options/rdt-class.md * move IntelRdtClosID to HostConfig * use default when user does not provide rdt-class * Add documentation for Intel RDT support * Add test for Intel RDT support * Add Intel RDT support * [CI:DOCS] Fix podman form update --help examples * Quadlet container mount - support non key=val options * test/e2e: default to netavark * [skip-ci] Update dawidd6/action-send-mail action to v3.9.0 * fix(deps): update module github.com/containers/gvisor-tap-vsock to v0.7.1 * fix(deps): update github.com/containers/common digest to 4619314 * applehv: enable machine tests for start * applehv: machine tests for stop and rm * Update machine tests README * Add podman socket info to machine inspect * Fix podman machine info test for hyperV * libpod: pass entire environment to conmon * e2e: ExitCleanly(): manual fixes to get tests working * e2e: ExitCleanly(): a few more * FCOS+podman-next: correct GHA conditional syntax * pkg/machine/e2e: wsl stop * wsl: machine tests for inspect * wsl: machine tests for ssh * fix(deps): update github.com/containers/common digest to e18cda8 * wsl: machine start test * wsl machine tests: set * wsl: machine tests * Skip proxy test for hyperV * Enable machine e2e test for applehv * hyperV: Respect rootful option on machine init * [CI:BUILD] FCOS image: enable nightly build * e2e: use safe fedora-minimal image * hyperv: machine e2e tests for set command * podman build: correct default pull policy * fix handling of static/volume dir * unbreak CI: useradd not found * hyperv: set more realistic starting state * hyperv: use StopWithForce with remove * Fix all ports exposed by kube play * Fix setting timezone on HyperV * fix(deps): update github.com/containers/gvisor-tap-vsock digest to 97028a6 * Fix farm update to check for connections * Adjust machine CPU tests * Bump version on main * [CI:BUILD] Packit: show SHORT_SHA in `podman --version` for COPR builds * Vendor c/common * pod rm: do not log error if anonymous volume is still used * e2e: ExitCleanly(): manual fixes to get tests passing * e2e: ExitCleanly(): a few more * fixes for pkg/machine/e2e on hyperv * test: fix rootless propagation test * [CI:BUILD] packit: tag @containers/packit-build team on copr build failures * Enable disk resizing for applehv * Various updates for hyperv and machine e2e tests * test: update fedoraMinimal version * specgen, rootless: fix mount of cgroup without a netns * Automatically remove anonymous volumes when removing a container * Use ActiveServiceDestination in ssh remoteConnectionUsername * fix(deps): update github.com/containers/gvisor-tap-vsock digest to 9298405 * e2e: ExitCleanly(): generate_kube_test.go * e2e: generate kube -> kube generate * e2e: ExitCleanly(): generate_kube_test.go * windows cannot "do" extra files * e2e: ExitCleanly(): Fixes for breaking tests * play kube -> kube play * e2e: ExitCleanly(): play_kube_test.go * introduce pkg/strongunits * Makefile equiv Powershell script * pass --syslog to the cleanup process * vendor of containers/common * fix --authfile auto-update test * compat API: speed up network list * Change priority for cli-flags for remotely operating Podman * libpod: remove unused ContainerState() fucntion * [CI:BUILD] Packit: Enable failure notifications for cockpit tests * e2e: ExitCleanly(): more low-hanging fruit * e2e: ExitCleanly(): more low-hanging fruit * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.12.1 * Enable machine e2e tests for WSL * systests: tighter checks for unwanted warnings * GHA Workflow: Faster discussion-locking * [CI:BUILD] FCOS + podman-next image: pull in wasm * [CI:BUILD] rpm: remove gvproxy subpackage * [CI:DOCS] Tweak podman to Podman in a few farm man pages * Docs on sig-proxy are wrong, we support TTY * e2e: ExitCleanly(): low-hanging fruit, part 2 * e2e: ExitCleanly(): low-hanging fruit, part 1 * Buildtag out unix commands for common OS files * systests: clean up after tests; fix missing path in logs * [CI:BUILD] followup PR for fcos with podman-next * Implement gvproxy networking using cmdline wrapper * fix, test: rmi should work with images w/o layers * vendor: bump c/common to v0.56.1-0.20230919073449-d1d9d38d8282 * Quadlet Image test - rearrange test function * e2e: continuing ExitCleanly() work: manual tweaks * e2e: continuing ExitCleanly() work * [CI:DOCS] Improve podman-tag man page * [CI:DOCS] Improve podman-build man page * [CI:DOCS] Include precheck to release process * [CI:DOCS] consistentize filter options in man pages * Quadlet - add support for .image units * --env-host: use default from containers.conf * error when --module is specified on the command level * man page crossrefs: add --filter autocompletes * Fix specification of unix:///run * Add label! filter and tests to containers and pods * Add test for legacy address without two slashes * Use url with scheme and path for the unix address- Use crun only on selected archs- Update to version 4.7.2: * v4.7.2 * Update RELEASE_NOTES.md for v4.7.2 * compose: try all possible providers before throwing an error * Mask /sys/devices/virtual/powercap * fix: check wsl npipe when executing podman compose * rtd: implement v2 build file * Adjust to path name change for resolved unit * Switch version to 4.7.2-dev- crun is not available for armv6 (because of criu), so use runc on armv6- Use crun on Tumbleweed & ALP for WASM support- podman-docker: Provides docker to avoid conflicts when using podman with docker-compose (bsc#1215926) - Update to version 4.7.1: * New version: v4.7.1 * Update RELEASE_NOTES.md for v4.7.1 * compat API: speed up network list * inspect: ignore ENOENT during device lookup * test/system: --env-file test fixes * Revert "feat(env): support multiline in env-file" * Revert "docs(env-file): improve document description" * Revert "fix(env): parsing --env incorrect in cli" * [CI:DOCS] update swagger version on docs.podman.io * Fix locale issues with WSL version detection * switch version to 4.7.1-dev- Build against latest stable Go version (bsc#1215807)- Update to version 4.7.0: * Bump to v4.7.0 * [CI:DOCS] v4.7.0 RELEASE_NOTES update * rpm: remove gvproxy subpackage * packit: tag @containers/packit-build team on copr build failures * specgen, rootless: fix mount of cgroup without a netns * pass --syslog to the cleanup process * fix --authfile auto-update test * version: switch back from -rc1 to -dev * New pre-release: v4.7.0-rc1 * [CI:DOCS] Update release notes for v4.7.0-rc1 * Cirrus: Update operating branch * Move podman build opts to common file * Add ability for machine rm -f for WSL * Plumbing to run machine tests with hyperv * CI: trace setup and runner scripts * Bump to Buildah v1.32.0 * [CI:DOCS] bump release notes on main with the latest release * fix(deps): update module github.com/opencontainers/image-spec to v1.1.0-rc5 * Add --filter pod= autocompletion * e2e: ExitCleanly(): manual test fixes * e2e: continuing ExitCleanly(): just the replacements * Fix some spelling and formatting * Add support for Ulimit in quadlet * Run codespell on code * wire in new buildah build options * make golangci-lint happy * add !remote tag to pkg/specgen/generate * pkg/specgen: do not depend on libimage for remote * bump buildah to latest * [CI:DOCS] restart.md: migrate to container unit * fix(deps): update module k8s.io/kubernetes to v1.28.2 * Add support for PidsLimit in quadlet * Add DNS fields to Container and Network unit groups * [CI:DOCS] update API docs version list * Try to fix broken CI (gvisor-something) * e2e: more ExitCleanly(): manual test fixes * e2e: more ExitCleanly(): dumb string replacements * e2e: create_test: use ExitCleanly() * e2e: diff_test: use ExitCleanly() * The `podman init` command cannot modify containers. * bump c/common to latest main * Podmansh: use podmansh_timeout * e2e: more ExitCleanly(): low-hanging fruit * vendor: update checkpointctl to v1.1.0 * kube: add DaemonSet support for generate * vendor of containers/(common, storage, image) * libpod: move oom_score_adj clamp to init * e2e: commit_test: use ExitCleanly() * e2e: container_clone_test.go: use ExitCleanly() * e2e: use ExitCleanly() in cleanup_test.go * Ensure HC events fire after logs are written * [CI:DOCS] podman-systemd.unit: fix equivalents * Add support for kube TerminationGracePeriodSeconds * Update podman-kube-play.1.md.in * Split up alt binaries to speed up build * Switch installer task to EC2 * pod: fix duplicate volumes from containers.conf * tests: add test for pod cgroups * libpod: create the cgroup pod before containers * cmd, specgen: allow cgroup resources without --infra * specgen: allow --share-parent with --infra=false * libpod: allow cgroup path without infra container * libpod: check if cgroup exists before creating it * libpod: refactor platformMakePod signature * libpod: destroy pod cgroup on pod stop * utils: export MoveUnderCgroup * libpod: refactor code to new function * e2e: use ExitCleanly() in checkpoint tests * [CI:DOCS]Remove use of --latest|-l from tutorial * CI test runner: upgrade tests rely on system tests * run --rmi: "cannot remove" is a warning, not an error * StopContainer: display signal num when name unknown * URGENT: fix broken CI * Add support for kube securityContext\.procMount * podman: don't restart after kill * Tmpfs should not be mounted noexec * sys tests: run_podman: check for unwanted warnings/errors * chore(deps): update dependency setuptools to ~=68.2.0 * e2e: use ExitCleanly() in attach & build tests * Some distros do not default to docker.io for shortname searches * security: accept empty capabilities list * systests: random_free_port: fix EADDRINUSE flake * fix(deps): update module github.com/cyphar/filepath-securejoin to v0.2.4 * Restrict fcos_test to amd64, arm64 * fix(deps): update github.com/containers/libhvee digest to 56fb235 * fix(deps): update module github.com/docker/docker to v24.0.6+incompatible * fix(deps): update module golang.org/x/tools to v0.13.0 * Ignore spurious container-removal errors * fix(deps): update module golang.org/x/net to v0.15.0 * systests: manifest zstd test: lots of tiny cleanups * vendor: update github.com/opencontainers/runc to main * [skip-ci] Update actions/checkout action to v4 * linux, rootless: clamp oom_score_adj if it is too low * machine: increase max number of inotify instances * fix(deps): update module golang.org/x/term to v0.12.0 * Remove redundant nil checks in system connection remove * fix(deps): update module golang.org/x/text to v0.13.0 * fix(deps): update module golang.org/x/sys to v0.12.0 * fix(deps): update github.com/containers/libhvee digest to 2bf7930 * docs(readme): fix a broken link * [CI:BUILD] Podman FCOS image from main * Update golang.org/x/exp digest to d852ddb * Add port forwarding and gvproxy machine test * libpod: do not parse --hostuser in base 8 * fix: default typo * Add Japanese locale and translation of index * remove rh.container.bot@gmail.com * Tweaks and cleanups to prepare hyperv for CI * system tests: housekeeping: various small fixes * CI: e2e: first use of new ExitCleanly() matcher * CI: e2e: new ginkgo matcher, ExitCleanly() * CI: e2e: fetch the standard system-test image * kube play: fix pull policy * Fix gidmap command in example * vendor containers/common@12405381ff45 * manifest,push: support add_compression from containers.conf * hyperv ignition: use gvforwarder instead of vm * Set remote username earlier for hyperv * Added an additional troubleshooting problem and solution * Remove a dependency on libimage from pkg/bindings * Rename parameter in pkg/bindings * Remove a dependency on libimage from pkg/api/handlers * Don't re-inspect an image * Cirrus: Remove multi-arch podman image builds * uid/gid mapping flags * [DOC] Clarify default behaviour on uidmap * Update containers/common to latest * update libhvee * /_ping handler: return OSType http header * e2e: fix race condition (kube play + logs) * Update module github.com/vbauerster/mpb/v8 to v8.6.0 * Kube - support List documents * kube down/play --replace: handle absent objects * push, manifest-push: --force-compression must be true with - -compression-format * oci: print stderr only after checking state * Updated docs to reflect pod spec sysctls support added in v4.6 * [CI:BUILD] Packit: Disable unexpected journal message check for cockpit-podman * [CI:BUILD] Packit: Restrict cockpit tests to recent Fedoras * Update machine init/set tests * Add rootful status to machine inspect * Dedup and refactor image acquisition * Share podman sock bindings with other WSL distros * Fix user-mode validation check * system tests: try to fix sdnotify flakes * Cirrus: Disable only hello multiarch build * Set StopTimeout for service-container started under podman kube play * Set StopTimeout for compat API if not set by client * podman exec should set umask to match container * [CI:BUILD] Packit: run cockpit-podman tests in PRs * Add infra-name annotations to kube gen/play * kube: notifyproxy: close once * system service: unset NOTIFY_SOCKET * Update module k8s.io/kubernetes to v1.28.1 * API attach: return vnd.docker.multiplexed-stream header * test/apiv2/60-auth.at: use `doesnotexists.podman.io` * e2e tests: use registry:2.8.2 (was 2.8) * create apiutils package * api docs: document stream format * Revert "Remove `hello` multi-arch image build" * manifest-push: add support for --force-compression * push: add support for --force-compression * Update module github.com/onsi/ginkgo/v2 to v2.12.0 * Remove `hello` multi-arch image build * hack/perf/system-df.sh: add `df` benchmarks * Expand env variables for cmds/entrypoint with format $(ENV) * vendor c/storage@6902c2d * Ignore the resource limits on cgroups V1 rootless systems * Fixups for stopping gvproxy * Revert "GHA: Closed issue/PR comment-lock test" * GHA: Closed issue/PR comment-lock test * GHA: Add workflow to lock closed issues/PRs * [CI:DOCS] update auto-update docs * chore(deps): update dependency containers/automation_images to v20230816 * fix(deps): update module github.com/google/uuid to v1.3.1 * libpod: sum per-interface network stats for FreeBSD * Set default Umask for `podman kube play` * [CI:BUILD] rpm: spdx compatible license field * chore(deps): update dependency golangci/golangci-lint to v1.54.2 * Implement automatic port reassignment on Windows * Add support for ramfs as well as tmpfs in volume mounts * Validate current generation of WSL2 with user-mode-networking * use container restart policy if user specifies one * Stop gvproxy on hyperv machine stop * [CI:BUILD] rpm: depend on man-db * Update machine list test * Update machine start tests * Update machine rm tests * libpod: improve conmon error handling * cirrus setup: install en_US.UTF-8 locale * fixup "podman logs with non ASCII log tag" tests * libpod: use /var/run instead of /run on FreeBSD * cirrus/lib.sh: extend env to passthrough at start for locale work * libpod: correctly pass env so alternative locales work * cgroups_linux: use SessionBusPrivateNoAutoStartup * podmansh man page UID=$(id -u lockedu) is not allowed * CI: systests: remove pasta ICMP tests * podman.1.md: Fix formatting of exit code 127, clarify wording of `exit code` example. * document available secret drivers * pkg/specgen: add support for read-only root on FreeBSD * add --module flag * Update dependency setuptools to ~=68.1.0 * Add riscv64 architecture to the cross build target * GetFcosArch add `riscv64` arch * Update WSL backend to be compat with FCOS defaults * enabled hyperv image downloads * fix(deps): update module github.com/containers/ocicrypt to v1.1.8 * [CI:DOCS] Fix git build example in build page * CI: e2e manifest_test: use image from quay * Cirrus: Remove EC2 experimental flag * sphinx: skip options include dir * Update rootfs.md: Fix formatting and wording of idmap option * fix: Docker API compatible bool deserialization * Revert "compat,build: pull must accept string" * Add missing verb in machinectl example * [CI:DOCS] Update Release Notes and Release Process * chore(deps): update dependency golangci/golangci-lint to v1.54.1 * fix podman top missing output flake * New partial-line test is flaking * [CI:BUILD] Packit: add back fedora-eln targets * Cirrus: Prune defunct job + fix noop alias * Bump bundled gvproxy to 0.7.0 * systests: tests for --env and --env-file * Update system connection add & remove * Add tests for podman farm * Add podman farm update command * Add podman farm remove command * Add podman farm list command * Add podman farm create command * Add podman farm subcommand * CI: e2e: add delay before podman logs or journalctl * Add completion for Farms * Vendor c/common changes * chore(deps): update dependency golangci/golangci-lint to v1.54.0 * file logger: fix podman logs --tail with partial lines * fix(env): parsing --env incorrect in cli * Update docker.io/library/golang Docker tag to v1.21 * podman stop --cidfile missing --ignore * Skip podman exec cannot be invoked on Debian * Re-enable checkpoint test on Debian SID * Require a non-generic reason for non-Fedora skip * CI FIXME removal/update. * Update dependency containers/automation_images to v20230807 * [skip-ci] Update dawidd6/action-send-mail action to v3.8.0 * [CI:DOCS] fixed couple typos in build docs * Stop timer in function waitPidStop * packit: Build PRs into default packit COPRs * Add support for host-gateway * Ensure volumes-from mounts override image volumes * Minor: Include shasums in GHA workflow artifacts * Minor: Add important comment to windows GHA workflow * Minor: Update/fix dry-run input descriptions * [CI:DOCS] Quadlet - provide more information about network files * man-page xref: check for duplicate entries * cp: close temporary file on error path * Makefile: work around the lack of 'man -l' on FreeBSD * Update module golang.org/x/net to v0.14.0 * libpod: fix a crash in 'kube generate' on FreeBSD * remove temporary files when copy [NO NEW TESTS NEEDED] * Update module golang.org/x/sys to v0.11.0 * [ci] Remove the podman socket in remove_packaged_podman_files() * [ci] Correct the podman systemd file names * Always show RemoteSocket.Exists in json * Fail if ssh key exists * Fix regression for hyperv * [CI:BUILD] Makefile: rpm target generates correct version * Fix nits in #19480 * Add support for passing container stop timeout as -1 (infinite) * pkg/specgen: Add device support for FreeBSD * [CI:DOCS] man: remove duplicate entry .LastUp * CI: e2e: remove useless test * Check tty flag to set default terminal in Env * Run codespell on code * Deprecate podman generate systemd * manifest/push: add support for --add-compression * [CI:DOCS]Update Release Notes * CI: sys: quadlet %T test: do not rely on journal * GHA: Support testing build/sign workflows * Remove unnecessary backslashes * [docs] Use code blocks for commands in podman-completion * Make podman run --rmi automatically set --rm * machine: QEMU: recover from failed start * vendor: bump c/image to v5.26.1-0.20230801083106-fcf7f0e1712a * secret: add support for `--ignore` with rm * Move `writeConfig` logic to shared function * Move some logic of `setRootful` to a common file * move `removeFilesAndConnections` to a common file * Move `waitAPIAndPrintInfo` to common file * Move `addSSHConnectionsToPodmanSocket` code to shared file * Update module golang.org/x/net to v0.13.0 * chore(deps): update dependency containers/automation_images to v20230726 * Skip pasta local forwarder test on debian SID * Skip broken/flaky blkio-weight test * Skip tarball re-inport test in rawhide for CI * Cleanup CIDFile on podman-remote run --rm command * CI: e2e: remove workaround for missing login file * vendor: bump c/image and c/common * Add support for confined users * Cirrus: Temp. disable rawhide validation task * Limit git-validation to 'short-subject' * Fix up man page and add test on globs * Move alternate image acquisition to separate function * Move `getDevNullFiles` into a common file * Update github.com/digitalocean/go-qemu digest to 2e3d018 * Convert QEMU functions to methods with documentation * Update docs/source/markdown/podman-build.1.md.in * do not redefine gobuild for eln * Set default userns from containers.conf file * Mention TimeoutStartSec in quadlet man page * inspect with network=none show SandboxKey netns path * [CI:DOCS] GHA: Use stable go for Mac/Win builds * Breakup AppleHV machine funcs * Codespell fixups * Update docs/source/markdown/podman-stats.1.md.in * CI: e2e: reenable containerized checkpoint tests * docs(env-file): improve document description * Don't log EOF error when using podman --remote build with an empty context directory. * API: kill: return 409 on invalid state * feat(env): support multiline in env-file * Adds documentation to new functions that were added * `startHostNetworking`: get DevNull files * `Remove`: remove network and ready sockets from registry * `Remove`: remove files and connections * `Remove`: collect files to destroy * `Init`: read and split ign file * `Init`: write ign config * `Init`: add network and registry socks to registry * `Init`: add SSH conns to podman sock * Improve the description of fields in podman-stats man page * make /dev & /dev/shm read/only when --read-only - -read-only-tmpfs=false * Mention no comment lines in Containerfile.in podman-build man page * [CI:BUILD] RPM: define gobuild macro for rhel/centos stream * Fix HyperV loadMachineFromJSON function name * machine: QEMU: lock VM on stop/rm/set * libpod: add 'pod top' support on FreeBSD * [CI:DOCS] Build and Sign Mac Pkginstaller * Make sure users changes --authfile before checking * github: add issue type as link to podman github discussions * Break QEMU `config.go` code into its own functions * machine: QEMU: lock VM on start * libpod: fix 'podman kube generate' on FreeBSD * Add glob support to podman run/create --mount * kube: add DaemonSet support * Fix artifacts script after removal of msitools msi build * System tests: quadlet: fix race in %T test * If quadlets have same name, only use first * Add support for mounts listed in containers.conf * Update vendor of containers/common * System tests: add test tags * [CI:DOCS] socket_activation.md: increase socat timeout * go-md2man: use vendored-in version, not system * CI: use different TMPDIR on prior-fedora * system tests: authfile-exists: minor cleanup * start(): don't defer event * Fix: use --all in podman stats to get all containers stats * Verify authfile exists if user specifies it * libpod: don't generate errors for createTimer etc. * add "healthy" sdnotify policy * Remove LICENSE and general doc files that are installed by the main package * Add missing ` * Remove legacy msitools based msi installer * Remove any quotes around distribution id * add a podman-compose command * pkg/specgen: Don't crash for device spec with... * fix(deps): update module github.com/docker/docker to v24.0.5+incompatible * Update vendor of containers/(storage,image) * Clean up /var/tmp/ when using oci-archives when creating containers * [CI:BUILD] RPM: separate out gvproxy for copr and rawhide * Reduce qemu machine function sizes * [CI:DOCS] migrate socket_activation.md to quadlet * [CI:DOCS] Update kube play volume support * Fix language, typos and markdown layout * [CI:DOCS] Add note about QUADLET_UNIT_DIRS to simplify quadlet debug * Add note on debugging quadlet unit files * Remove unnecessary use of the word "please". * libpod: fix FreeBSD 'podman-remote top' default behaviour * fix(deps): update module github.com/onsi/gomega to v1.27.9 * Add support for ShmSize to quadlet * Quadlet system test - force journald log driver for short lived containers * fix(deps): update module github.com/containers/libhvee to v0.4.0 * quadlet recursively scan for unit files * Ensure that we appropriately warn that TCP is insecure * systests: quadlet: fixes for RHEL8 * Quadlet - Allow setting Service WorkingDirectory for Kube units * Quadlet system test - do not rely on journalctl in kube file tests * Fix markdown in docs for podman-network-create * Man pages: check for corrupt tables * quadlet systest: fix broken tmpdir references * Add `since` as valid filter option for `volume` subcommands * Podmansh: Better error, increase timeout to 30s * Fix multiple filter options logic for `podman volume ls ` * Add bash-completion for podman inspect * Fix windows installer * Add missing reserved annotation support to `play` * Avoid progress hang with empty files * Revert the usage of `home.GetConfigHome()` * Fix bug report issue template README link * Replace error check for non-existent file * Emergency gating-test fixes for RHEL8 * Add progress bar for decompress image * refactor: move progressbar to a function * Use pkg/homedir to get the home config directory * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.5.2 * Should be checking tmpfs versus type not source * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.5.1 * Enabled arm64 arch for podman applehv provider * [CI:BUILD] Packit: remove pre-sync action * Add `--podman-only` flag to `podman generate kube` * Update vendor containers/(common, buildah, image, storage) * Use constants for mount types * libpod: use define.TypeBind when resolving container paths * Tests: remove/update obsolete skips * Fix trust not using local policy file * Fix `podman container prune` docs for `--filter` * Add more tests for liveness probes with default hostname & named ports * docs: podman-build --network add slirp and pasta * docs: podman run --network mention comma separted names * Podman machine AppleHV pass number 3 * Makefile: `package` -> `rpm` * network create: document --internal better * pkg/specgen: fix support for --rootfs on FreeBSD * machine start: qemu: wait for SSH readiness * [CI:BUILD] Packit: downstream task action fix * Fix container errors not being sent via pod removal API * Add missing return after utils.InternalServerError() * Update cmd/podman/login.go * [CI:DOCS] Reformat and reorder table with --userns options * Add secret support to podman login * netavark: macvlan networks keep custom nameservers * remote: fix podman-remote play kube --userns * fix(deps): update container-device-interface to v0.6.0 * go mod: no longer use 1.18 * fix(deps): update module github.com/containers/libhvee to v0.3.0 * chore(deps): update module github.com/gin-gonic/gin to v1.9.1 [security] * Run codespell on code * system service: unset listen fds on tcp * add hostname to network alias * libpod: set cid network alias in setupContainer() * AppleHV enablement pass #2 * e2e: Fetch the correct user name * Add `--no-trunc` flag to maintain original annotation length * Fix TCP probes when the optional host field is not given * Add support for using port names in Kubernetes health probes * Fix: cgroup is not set: internal libpod error after os reboot * Allow setting volume and network names in Quadlet * pasta tests: automatically determine test parameters * test/e2e: wait for socket * manifest inspect: support authentication * api: fix slow version endpoint * libpod: don't make a broken symlink for /etc/mtab on FreeBSD * CI: remove build without cgo task * libpod: use io.Writer vs io.WriteCloser for attach streams * top: do not depend on ps(1) in container * make --syslog errors non fatal * api: fix doc for default ps_args * Fixes typo in the path where quadlet looks for files * Add --replace flag to podman secret create * [CI:DOCS] uidmap man pages: fix corrupt italics * [skip-ci] Update github/issue-labeler action to v3.2 * [CI:DOCS] podman-system-service.1.md: document systemd usage * fix(deps): update module github.com/docker/docker to v24.0.4+incompatible * fix(deps): update module github.com/docker/docker to v24.0.3+incompatible * Use bytes size consistently instead of human size * bugfix: do not try to parse empty ranges * [CI:BUILD] Packit: fix pre-sync action for downstream tasks * fix(deps): update module golang.org/x/tools to v0.11.0 * fix(deps): update module golang.org/x/net to v0.12.0 * fix(deps): update module golang.org/x/term to v0.10.0 * e2e: fix two toolbox flakes * test/e2e: use GinkgoT().TempDir() over MkdirTemp() * test/e2e: use random ImageCacheDir * test/e2e: remove RHEL7 workaround * test/e2e: remove unnecessary code in SynchronizedAfterSuite * test/e2e: do not use /tmp for podman commands * test/tools: vendor ginkgo v2.11 * test/e2e: write timings directly to file * machine start: qemu: adjust backoffs * auto update: fix usage of --authfile * system tests: refactor registry code * fix(deps): update module golang.org/x/text to v0.11.0 * pkg/specgen: properly identify image OS on FreeBSD * libpod: use new libcontainer BlockIO constructors * [CI:BUILD] Minor: Don't confuse osx-debugging * [CI:DOCS] Better document the default value of --userns * Cirrus: build FreeBSD binaries in a VM * Makefile: add support for building freebsd release tarballs * [CI:DOCS] uidmap man pages: fix corrupt tables * fix(deps): update github.com/crc-org/vfkit digest to c9a4b08 * fix(deps): update module github.com/containers/buildah to v1.31.0 * fix(deps): update module github.com/opencontainers/image-spec to v1.1.0-rc4 * Use /proc/self/gid_map as intended, not uid_map * fix(command): ignore `--format` in `podman search --list-tags` * podman machine start: fix ready service * Makefile: don't rely on the non-standard -r flag for ln * pasta: Create /etc/hosts entries for pods using pasta networking * fix(deps): update module github.com/containers/libhvee to v0.2.0 * pasta tests: add sanity check for test name vs function * pasta tests: cleanup + 1 new test * cmd/podman, pkg/domain/infra: sockets should live in /var/run on FreeBSD * cmd/podman/system: add API server support on FreeBSD * [CI:DOCS] Document support of pod security context IDs * rootless: use default_rootless_network_cmd config * Revert^3 "pasta: Use two connections instead of three in TCP range forward tests" * pasta: Workaround occasional socat failures in CI * pasta: Remove some leftover code from pasta bats tests * Bump c/image to v5.26.0, c/common 0.54.0 * fix(deps): update module github.com/coreos/stream-metadata-go to v0.4.3 * Display secret to user in inpspect * [CI:BUILD] RPM: Fix koji and ELN issues * e2e: systemd test: major fixes * pkg/specgen: add support for 'podman run --init' on FreeBSD * Bump version after v4.6 branch cut * Remove 'inspecting object' from inspect errors * pasta: Fix pasta tests to work on hosts with multiple interfaces * [CI:DOCS] fix command incorrect in windows * Fix readonly=false failure * pkg/specgen: Add support for Linux emulation on FreeBSD * Fix up podmansh man page * Make Podman/Buildah use same DecryptConfig/EncryptConfig funcs * Fixes for vendoring Buildah * vendor in latest buildah * tests: fix "Storing signatures" check * update c/image and c/storage to latest * Kube quadlets can support autoupdate as well as containers * debug tail 800 lines flake * Pass in correct cwd value for hooks exe * specgen: honor --device-cgroup-rule with a new user namespace * specgen, rootless: raise error with --device-cgroup-rule * make image listing more resilient * Update module google.golang.org/protobuf to v1.31.0 * Trim whitespace from unit files while parsing * Re-organize hypervisor implementations * play.go: remove volumes on down -f- Update to version 4.6.2: * Bump to v4.6.2 * Release notes for v4.6.2 * Packit: Disable unexpected journal message check for cockpit-podman * Packit: Restrict cockpit tests to recent Fedoras * Packit: run cockpit-podman tests in PRs * rpm: spdx compatible license field * vendor c/storage@v1.48.1 * rpm: depend on man-db * use container restart policy if user specifies one * podmansh man page UID=$(id -u lockedu) is not allowed * packit: Build PRs into default packit COPRs * Skip tests that fail in gating * fix: pull parma parsing for the /build compat ep * [CI:DOCS] Update Release Notes * Bumpt to v4.6.2-dev- Fix build error on SLE due to dangling files clause on a discarded file, README.SLE.SUSE - Fix unexpanded RPM macro error- Update to version 4.6.1: * Bump to v4.6.1 * Release notes for v4.6.1 * Vendor buildah v1.31.2 * [4.6] vendor c/common v0.55.3 * [v4.6] Remove zstd:chunked reference * [v4.6] bump golang.org/x/net to v0.13.0 * do not redefine gobuild for eln * [CI:BUILD] RPM: define gobuild macro for rhel/centos stream * [v4.6] [CI:BUILD] RPM: separate out gvproxy for copr and fedora >= 38 * System tests: add test tags * API: kill: return 409 on invalid state * Mention TimeoutStartSec in quadlet man page * If quadlets have same name, only use first * Bump to v4.6.1-dev- Discard outdated README.SUSE.SLES - Recommend gvisor-tap-vsock, required for `podmand machine`- Update to version 4.6.0: * Bump to v4.6.0 * Update release notes for v4.6.0 * Ensure that we appropriately warn that TCP is insecure * CI: remove build without cgo task * libpod: use io.Writer vs io.WriteCloser for attach streams * top: do not depend on ps(1) in container * api: fix doc for default ps_args * Add more tests for liveness probes with default hostname & named ports * Fix TCP probes when the optional host field is not given * Add support for using port names in Kubernetes health probes * [CI:DOCS] fix command incorrect in windows * [CI:DOCS] Reformat and reorder table with --userns options * [CI:DOCS] Better document the default value of --userns * Add missing return after utils.InternalServerError() * Fix markdown in docs for podman-network-create * Fix multiple filter options logic for `podman volume ls ` * Should be checking tmpfs versus type not source * Use constants for mount types * Fix `podman container prune` docs for `--filter` * docs: podman-build --network add slirp and pasta * docs: podman run --network mention comma separted names * network create: document --internal better * pkg/specgen: fix support for --rootfs on FreeBSD * systests: quadlet: fixes for RHEL8 * Fix windows installer * Podmansh: Better error, increase timeout to 30s * Emergency gating-test fixes for RHEL8 * Packit: remove pre-sync action * [CI:DOCS] Update RELEASE_NOTES.md with Makefile change * Bump to v4.6.0-dev * Bump to v4.6.0-rc2 * Makefile: `package` -> `rpm` * Update release notes * system tests: refactor registry code * machine start: qemu: wait for SSH readiness * machine start: qemu: adjust backoffs * auto update: fix usage of --authfile * [CI:BUILD] Packit: downstream task action fix * Fix container errors not being sent via pod removal API * netavark: macvlan networks keep custom nameservers * add hostname to network alias * libpod: set cid network alias in setupContainer() * Fix: cgroup is not set: internal libpod error after os reboot * test/e2e: wait for socket * api: fix slow version endpoint * manifest inspect: support authentication * libpod: don't make a broken symlink for /etc/mtab on FreeBSD * make --syslog errors non fatal * Fixes typo in the path where quadlet looks for files * [CI:DOCS] uidmap man pages: fix corrupt italics * [CI:DOCS] podman-system-service.1.md: document systemd usage * Use bytes size consistently instead of human size * bugfix: do not try to parse empty ranges * pkg/specgen: properly identify image OS on FreeBSD * [CI:DOCS] Document support of pod security context IDs * pkg/specgen: add support for 'podman run --init' on FreeBSD * Remove 'inspecting object' from inspect errors * Fix readonly=false failure * pkg/specgen: Add support for Linux emulation on FreeBSD * Fix up podmansh man page * Pass in correct cwd value for hooks exe * specgen: honor --device-cgroup-rule with a new user namespace * specgen, rootless: raise error with --device-cgroup-rule * make image listing more resilient * Trim whitespace from unit files while parsing * play.go: remove volumes on down -f * Vendor c/common v0.55.2 * system service: unset listen fds on tcp * [CI:DOCS] [Release Notes]: add static routes * [CI:DOCS] tag podmansh as tech preview in RELEASE_NOTES.md * [CI:DOCS] uidmap man pages: fix corrupt tables * libpod: use new libcontainer BlockIO constructors * Bump to v4.6.0-dev * Bump to v4.6.0-rc1 * Bump to v4.6.1-dev * Bump to v4.6.0 * Release notes for v4.6.0 * Update Release Notes for v4.5.1 * rootless: use default_rootless_network_cmd config * tests: fix "Storing signatures" check * Fixes for vendoring Buildah * Make Podman/Buildah use same DecryptConfig/EncryptConfig funcs * Do not use deprecated hook functions from c/common * Bump c/storage to v1.48.0, c/image to v5.26.1, c/common to v0.55.1, buildah to v1.31.0 * pasta: Remove some leftover code from pasta bats tests * pasta: Fix pasta tests to work on hosts with multiple interfaces * fix(command): ignore `--format` in `podman search --list-tags` * Use /proc/self/gid_map as intended, not uid_map * podman machine start: fix ready service * Makefile: don't rely on the non-standard -r flag for ln * cmd/podman, pkg/domain/infra: sockets should live in /var/run on FreeBSD * cmd/podman/system: add API server support on FreeBSD * pasta: Create /etc/hosts entries for pods using pasta networking * RPM: Fix koji and ELN issues * Cirrus: Update operating branch * system tests: add and use _prefetch * pkg/api: BufferedResponseWriter flush correctly * pkg/api: top return error to client * container wait: support health states * [CI:DOCS] Fix example on PublishPort * container wait API: use string slice instead of state slice * podman wait: update man page * StopContainer(): ignore one more conmon warning * run,create: modify `--env-merge` behavior for non-existent vars * use libnetwork/slirp4netns from c/common * update c/common to latest * e2e: use parallel-safe /dev subdirectories * [CI:BUILD] Help Renovate manage the golangci-lint version * systests: test instrumentation * compat API create/pull: fix error handling * compat API push: fix error handling * GetSafeIPAddress(): discourage its use * libpod: write /etc/{hosts,resolv.conf} once * e2e: fix one of the many log flakes * cmd, push: expose --compression-level * vendor: bump containers/common * compat API container create: handle platform parameter * refactor(machine): remove hard code * vendor in latests containers/common * fix(machine): throw `connect: connection refused` after set proxy * [CI:BUILD] Packit: cleanups * Add console mode to podman machine * e2e: kube test: specify expected exit code * e2e --authfile test: fix test condition * chore(deps): update dependency setuptools to v68 * make lint: re-enable revive * make lint: re-enable ginkgolinter * make lint: enable rowserrcheck * make lint: enable wastedassign * make lint: enable mirror * bump golangci-lint to v1.53.3 * auto update: restart instead of stop+start * cmd/podman/root.go: fix help document issue of the image store * vendor: bump c/storage to v1.46.2-0.20230616083707-cc0d208e5e1c * podman: add support for splitting imagestore * network create --ip-range allow for custom range * fix(ssh): start machine failed to start with exit status 255 * remote wait: fix "removed" condition * [CI:DOCS] Fix service_destinations description in podman man page * quadlet should exit non zero on failures * fix(deps): update module golang.org/x/tools to v0.10.0 * e2e: GetSafeIPAddress() replaces GetRandomIPAddress * pasta: use code from c/common * Add support for setting autoupdate in quadlet * New command: podmansh * vendor: update c/common to latest * Add quadlet container support for Mask,Umask options * libpod: make conmon always log to syslog * Document how to get secret mounts working on RHEL8 * Verify podman pull dup image only prints id once * Vendor in latests containers/common * Apply suggestions from code review * Revert "rootlessport: exclude storage drivers via build tags" * filters: use new FilterID function from c/common * logformatter: ignore 'TOP-LEVEL' headings * test/e2e: fix network ID test * update c/{common,image,storage} to latest * [CI:DOCS] clarify supported transports in manifest push * [CI:DOCS] podman-push: rm confusion on supported transports * container wait: indicate timeout in error * network-create: document new bclim option * fix(deps): update module golang.org/x/text to v0.10.0 * libpod: Podman info output more network information * fix(deps): update module golang.org/x/term to v0.9.0 * quadlet: adjust container unit documentation * e2e: GetRandomIPAddress(): parallelize * Makefile: add support for 'make help' on FreeBSD * criu: return error when checking for min version * Update docs/source/markdown/podman-systemd.unit.5.md * 250-systemd.bats: remove outdated comment * github: add issue type as link to podman-desktop * Add WorkingDir support to quadlet * rootlessport: exclude storage drivers via build tags * Add ability to set static routes * test/upgrade: correctly share mounts between host and container * Update common, image, and storage deps * Fix system service manpage name in API Documentation * style(specgen): omit nil check * fix(specgen): index out of range when unmask=[] * Makefile to force a shell when running command * cirrus,ci: default to overlay for debian env * Quadlet: Add support for --sysctl flag * chore(deps): update dependency requests-mock to ~=1.11.0 * Ignore spurious warnings when killing containers * Makefile: don't hard-code the path for bash * fix(deps): update module github.com/burntsushi/toml to v1.3.2 * GHA: Fix bad job-names & links in monitoring emails * podman-registry: simpler, safer invocations * Ensure our mutexes handle recursive locking properly * Fix an expected error message from pod removal * Fix a race removing multiple containers in the same pod * Discard errors when a pod is already removed * Change Inherit to use a pointer to a container * e2e: add ginkgo decorators to address flakes * filters: better handling of id= * fix(deps): update module github.com/onsi/gomega to v1.27.8 * refactor: improve get ssh path duplicate code * logformatter: better recognition of ginkgo test names * Address review feedback and add manpage notes * Add support for SecurityLabelNested flag in quadlet * fix(deps): update module github.com/burntsushi/toml to v1.3.1 * `system locks` now reports held locks * fix(deps): update module github.com/mattn/go-sqlite3 to v1.14.17 * Add a new hidden command, podman system locks * Add number of free locks to `podman info` * Include lock number in pod/container/volume inspect * fix ignition config creation * Makefile binaries target adopted for Mac and Win * fix(deps): update github.com/crc-org/vfkit digest to 3d57f09 * logformatter: proper status color for failed tests * pasta: Test handling of unknown protocols * pasta: Correct handling of unknown protocols * Quadlet - add support for Pull key in .container * fix(deps): update module github.com/sirupsen/logrus to v1.9.3 * Add default ulimit test for gen kube * feat: add insecure registry troubleshooting solution * fix(deps): update module golang.org/x/tools to v0.9.3 * fix(deps): update module github.com/coreos/stream-metadata-go to v0.4.2 * e2e: GetPort(): safer allocation of random ports * The removeContainer function now accepts a struct * Revert "test/e2e: fix "podman run ipcns ipcmk container test"" * Add a test for removing dependencies with rm -fa * Revert "ginkgo-v2 cleanup workaround for #18180" * Fix a deadlock when removing pods * Pods now return what containers were removed with them * Make RemoveContainer return containers and pods removed * Add an API for removing a container and dependencies * systests: fixes for coping with extra systemd image * libpod: fix timezone handling * fix(deps): update github.com/godbus/dbus/v5 digest to 7623695 * fix(deps): update module golang.org/x/tools to v0.9.2 * test/system: quadlet use correct systemd restart policy * systests: minimize race-condition window * systests: fix improper backgrounding of run_podman * set max ulimits for rootless on each start * Fix: display online_cpus in compat REST API * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.9.6 * systests: fix race in quadlet tests * fix(deps): update module github.com/burntsushi/toml to v1.3.0 * e2e: make BuildImage parallel-safe * completion: fix panic in simplePathJoinUnix() * Update module github.com/stretchr/testify to v1.8.4 * authfile.md: add default path of file for Windows/macOS. * Update module github.com/rootless-containers/rootlesskit to v1.1.1 * hack: fix typo in hack/podman-registry * man pages and command help: clean up descriptions * RPM: bump gvisor-tap-vsock subpackage and fix packit scripts * Man pages: fix broken tables * test/e2e: add regression testing for comma-containing labels * fix: volume create filters * fix: move filter flags from StringSliceVar to StringArrayVar * pkg/rootless: correctly handle proxy signals on reexec * [CI:BUILD] Packit: set propose-downstream action type to pre-sync * [CI:DOCS] fix Quadlet man page rendering * Quadlet: kube: use ExecStopPost * Quadlet: kube: add ExitCodePropagation field * kube play: exit-code propagation * prune exit codes only when container doesn't exist * podman: Add pasta to podman info * Revert "test/system/255-auto-update.bats: add debug logs" * Quadlet - add support for PodmanArgs to all groups * [CI:BUILD] Packit: add jobs for downstream Fedora package builds * In a concurrent removal test, don't remove concurrently with builds * Consolidate error handling in Runtime.removeContainer * Consolidate error handling in Container.cleanupStorage * Fix reporting errors on container unmount * TEMPORARY(?) instrumentation for unlinkat-ebusy * pkginstaller: bump Qemu to version 8.0.0 * Support podman --remote when Containerfile is not in context directory * chore(deps): update dependency requests to ~=2.31.0 * fix: podman event --filter volume=vol-name should compare the event name with volume name * fix(deps): update module github.com/docker/docker to v24 * wait: look for exit code in stopped state * network create/update: allow dns servers comma separated * source code comments and docs: fix typos, language, Markdown layout * Increase download progress to 80ch * chore(deps): update dependency setuptools to ~=67.8.0 * podman: Added find slirp4netns binary file from helper_binaries_dir [NO NEW TESTS NEEDED] * fix(deps): update module github.com/sirupsen/logrus to v1.9.2 * stats: get mem limit from the cgroup * quadlet tests: enable device.volume test * quadlet tests: remove unused socketactivated.container * fix(deps): update module github.com/stretchr/testify to v1.8.3 * Correct markdown in docs * fix(deps): update module github.com/onsi/gomega to v1.27.7 * [CI:DOCS] Improve security in mysql examples * Cirrus: Record the buildah version for reference * test/e2e: do not call setenforce * Fix discombobulated kubernetes support table * run: ignore PODMAN_USERNS with --pod * Add --configmap to podman-remote kube play * compat: accept tag in /images/create?fromSrc * fix HTMLSpan warnings * generate systemd: error on init containers * Remove future tense from man pages * compat,build: pull must accept string * Cirrus: Add support for `[CI:NEXT]` * Cirrus: Remove support for `[CI:COPR]` magic * system tests: add precision timestamps * Makefile: add ginkgo FOCUS/FOCUS_FILE options * e2e: refactor and document serialization * machine: fix default connection URL to use 127.0.0.1 * e2e: serialize gpg tests * Document podman-machine-default behavior * e2e: fix more test races (missing "wait") * fix(deps): update module github.com/openshift/imagebuilder to v1.2.5 * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.9.5 * Fix documentation of `--network-cmd-path` CLI option * Skip rhel-release branch unnecessary CI tasks * test/e2e: dedup Before/AfterEach nodes * remote-save: fix permissions and dir formats * Set machine docker.sock according to rootful flag * Fix handling of .containenv on tmpfs * Do not include image annotations when building spec * build(deps): bump github.com/docker/distribution * Kube Play - Support multi-doc YAML files for configmap argument * system tests: instrument, to try to catch unlinkat-ebusy * test: check restart policy of init containers * Update sigstore/rekor after https://github.com/sigstore/rekor/pull/1469 * issue template: mention `su` * e2e: logs test: fix flakes * fix(deps): update module github.com/containernetworking/plugins to v1.3.0 * e2e: stop podman.service test: wait for server * logformatter: handle podman-machine test logs * fix(deps): update module golang.org/x/tools to v0.9.1 * [CI:DOCS] Disable Dependabot in favor of Renovate * Ensure the consistent setting of the HOME env variable on container start * Quadlet system tests - fix socket notification * sqlite: disable WAL mode * system tests: timeoutize quadlet, systemd * test: update README for integration tests * libpod/Container.rootFsSize(): use recorded image sizes * quadlet: support `HostName` * e2e: fix race in a play-kube test * Fix preference of user quadlets directories * fix(deps): update module golang.org/x/tools to v0.9.0 * fix(deps): update module golang.org/x/net to v0.10.0 * Check on client side for Containerfile, if none specified * build(deps): bump github.com/docker/docker * Buildah treadmill: several fixes * fix(deps): update github.com/containers/common digest to 3e93a76 * chore(deps): update dependency docker to ~=6.1.0 * Update docs/source/markdown/podman-systemd.unit.5.md * fix(deps): update github.com/containers/common digest to bc15b04 * fix: initContainer restart policy overridden by pod * fix(deps): update module golang.org/x/sync to v0.2.0 * chore(deps): update dependency requests to ~=2.30.0 * ginkgo json output: only in CI, not on laptop runs * Allow user quadlets to be stored under /etc * fix(deps): update github.com/containers/common digest to ea87b34 * libpod: do not Cleanup() more than once * compat container create: match duplicate mounts correctly * Update podman-completion.1.md * fix(deps): update github.com/containers/buildah digest to e925b58 * Run generate.CompleteSpec() for initContainers as well * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.9.4 * remote: return better connect error * Add missing man page links for Docker man pages * Replace egrep/fgrep with grep -E/-F * remote: exec inspect update exec session status * fix(deps): update github.com/digitalocean/go-qemu digest to f035778 * fix(deps): update github.com/godbus/dbus/v5 digest to 6cc540d * fix(deps): update github.com/containers/buildah digest to f353690 * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.9.3 * MVP for Podman Machine with AppleHV * e2e tests: try writing & preserving ginkgo json artifacts * vendor: bump buildah to v1.30.1-0.20230501124043-3908816d5310 * bindings, build: don't pass invalid platform in case of none * Revert "logformatter: anchors: link to test summary, not name" * More cleanup: volumes: do not export to stdout * e2e test cleanup * Update kube gen & play to use pod restart policy * Add {{.Restarts}} to podman pod ps * Add {{.Restarts}} to podman ps * Add --restart flag to pod create * history: correctly set tags * fix(deps): update module github.com/moby/term to v0.5.0 * Makefile: do not run machine test in parallel * pkg/machine/e2e: switch to GinkgoWriter * api: fix parsing filters * ginkgo-v2 cleanup workaround for #18180 * test/e2e: fix custom timing reporting * logformatter: anchors: link to test summary, not name * WIP: logformatter: handle ginkgo v2 logs * test/e2e: unshare --rootless-netns cleanup slirp4netns * test/e2e: run system reset test serial * test/e2e: fix CleanupVolume/Secrets() * ginkgo v2: fix new Skip() behavior * test/e2e: fix pause tests to unpause before cleanup() * ginkgo v2: drop localbenchmarks * test/e2e: switch to GinkgoWriter * test/e2e: unset CONTAINERS_CONF before Cleanup() * ginkgo: run on all cores * test/e2e: fix Cleanup() * test/e2e: fix "podman run ipcns ipcmk container test" * test/e2e: actually check for cleanup errors * Lower e2e timeout to not waste time when it hangs * test/e2e: containers.conf tests add missing Wait() * ginkgo v2: remove CurrentGinkgoTestDescription() * ginkgo v2: remove deprecated flags * update to ginkgo v2 * test/e2e: do not remove CNI directory * e2e: login_logout: use unique authfile for each test * Fix clashing subuid * [CI:DOCS] troubleshooting: fix subuid example * manifest, push: use source as destination if not specified * Update github.com/moby/term digest to 0564e01 * Add name-generation test * Implement machine provider selection * libpod: improve errors management in cleanupStorage * libpod: report unmount idmapped rootfs errors * test: do not wait 10 seconds before killing myyaml * podman: simplify code with a switch * test: fix typo * build(deps): bump github.com/docker/docker * swagger: fix Info name conflict * Nightly dependency treadmill: remove * Update short description for disconnect cmd * windows: podman save allow the use of stdout * Update c/common and avoid setting umask * Cirrus: Update CI VM Image to F38/37 * Cirrus: Run code validation on rawhide * Fix rand.Seed() deprecation in golang 1.20 * Add sha256: to images history id for docker compatibility * Support systemd optional prefix '-' for devices. * Fix a copy/paste error in an error message * chore(deps): update dependency requests to ~=2.29.0 * Fix simple typo in podman-network-create.md * e2e cleanup: push with auth: add error checks * e2e: remove "-it" from podman run & exec * pkg/machine: rework RemoveConnection() * machine: qemu only remove connection after confirmation * Add file swith for pre-exec * system reset: show graphRoot/runRoot before removal * fix manifest annotate help * Netavark userns test: give aardvark time to come up * sqlite: move first read into a transaction * Recover from failed podman machine start * rootless: support joining contianers that use host ns * auto-update: return errors when checking for updates * [skip-ci] Update dawidd6/action-send-mail action to v3.7.2 * fix(deps): update github.com/containers/common digest to 46c4463 * Add user mode networking feature to Windows * system/reset.go: help: fix typo * e2e create same-IP: try to fix flake * system tests: safer container-stop signaling * Revert "Resolve symlink path for qemu directory if possible" * ps: --format {{.State}} match docker output * test/system/260-sdnotify.bats: fix test flake * [CI:DOCS] Quadlet: clarify overriding user/system services * Eliminate transient container deps from wslkerninst * Wording * fix(deps): update github.com/containers/common digest to 5547996 * cmd/podman/pods: omit superfluous runtime.NumCPU call * support `--digestfile` for remote push * e2e: skip journald test if journald is unavailable * Cirrus: Enable testing on Fedora rawhide * [CI:BUILD] Cirrus: remove copr rpm build task * chore(deps): update dependency setuptools to ~=67.7.0 * Cirrus: Drop benchmarks artifacts * test/e2e: correctly reap service process * test/e2e: add missing options to remote service * test/e2e: fix incorrect usage of CreateTempDirInTempDir() * test/e2e: "podman-remote send correct path to copier" do not leak file * test/e2e: fix network create flake due same subnet * test/e2e: fix SkipIfNotActive() * test/e2e: do not try to use docker as rootless * test/e2e: do not leak "hello" file * podman-remote logs: handle server error correctly * test/e2e: use custom network config v2 * rename ImagePushReport to ImagePushStream * Specify format to buildah before commit * Add eBPF snooper that traces the entire fork/exec graph of podman * libpod: stop containers with --restart=always * test: fix race when listing cgroups * compat: Translate `noprune` into ImageRemoveOptions.NoPrune * [CI:DOCS] Update RELEASE_PROCESS.md * hyperv: add podman socket mapping * e2e networking test: better way to get host IP * Updated system test to be easier to read * bindings tests: bail out early on image errors * libpod: fix TestPostDeleteHooks do not depend on version * chore(deps): update dependency setuptools to v67 * fix(deps): update module github.com/containers/libhvee to v0.0.5 * e2e: quadlet uses PODMAN env for podman binary path * Fixes format inconsistencies with docker for certain history fields * Makefile: do not prefix /etc * libpod: configureNetNS() tear down on errors * libpod: rootlessNetNs.Cleanup() fix error message * HyperV: wait on stop * build(deps): bump github.com/docker/docker * Makefile: include `release-artifacts` target * Enabled network over vsock * fix(deps): update module github.com/microsoft/go-winio to v0.6.1 * fix(deps): update module github.com/opencontainers/runtime-spec to v1.1.0-rc.2 * fix remote start --filter * Update API reference to include v4.5 * Add missing security options to /info response * Add mention of redir to doc `rootless.md` * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.4.0 * docs(readme): add status badges and remove hardcoded release info * Don't use bytes.NewBuffer to read data * Add support for HVSOCK on hyperv * docs: update network tutorial with netavark DHCP support * bump main to v4.6.0-dev * Remove disused test/install * Return title fields as a list * [CI:BUILD] Packit: Initial Enablement * Quadlet - do not set log-driver by default * system tests: address COPY-hardlink flake * chore(deps): update registry.centos.org/centos/centos docker tag to v8 * system tests: fix race in kube-play read-only * chore(deps): update dependency docker to v6 * CI: enable sqlite system tests * test: enable test_wait_next_exit * Update dependency PyYAML to v6 * test/e2e/systemd_activate_test.go: simplify test * Update docker.io/library/golang Docker tag to v1.20 * api: auth: fix nil deref * Update dependency requests-mock to ~=1.10.0 * Update dependency requests to ~=2.28.2 * fix: Document removing anonymous volumes at create * Use a sane polling interval in WaitContainerDocker * podman: added the --out option for capturing formatted output emitted by various commands * Renovate: Ensure release-note-none label is added * Renovate: Update ignore paths * *: migrate image registry to registry.k8s.io * Do not display the resource limits warning message- Don't unconditionally Obsolete podman-cni-config, ensure clean upgrade path.- Prefer Podman's new network stack (netavark) exclusively on ALP - Remove unused podman-cni-config subpackage, add systemd- Update to version 4.5.1: * Release v4.5.1 * [CI:DOCS] Final release notes for v4.5.1 * [CI:BUILD] Packit: set propose-downstream action type to pre-sync * Revert "Resolve symlink path for qemu directory if possible" * no need for podman-next rpm test on maint branch * [CI:BUILD] Packit: add jobs for downstream Fedora package builds * libpod: configureNetNS() tear down on errors * libpod: rootlessNetNs.Cleanup() fix error message * network create/update: allow dns servers comma separated * machine: fix default connection URL to use 127.0.0.1 * compat: accept tag in /images/create?fromSrc * compat container create: match duplicate mounts correctly * machine: qemu only remove connection after confirmation * windows: podman save allow the use of stdout * remote: exec inspect update exec session status * podman-remote logs: handle server error correctly * libpod: stop containers with --restart=always * Do not include image annotations when building spec * [v4.5] system tests: fix race in kube-play read-only * api: fix parsing filters * Support systemd optional prefix '-' for devices. * *: migrate image registry to registry.k8s.io * Makefile: include `release-artifacts` target * [CI:BUILD] Packit: Initial Enablement * Bump to v4.5.1-dev- Update to version 4.5.0: * Release v4.5.0 * [CI:DOCS] Final release notes for v4.5.0 * Quadlet - do not set log-driver by default * Return title fields as a list * Bump to v4.5.0-dev * Bump to v4.5.0-RC2 * Final release notes for v4.5.0-RC2 * test/e2e: remove unnecessary SkipIfNetavark() calls * test/e2e: deduplicated network test * docs: update podman-network-create.1 * network create: add --interface-name * test/system/252-quadlet.bats: fix flake * Read kube_generate_type from containers.conf * Debian setup: workaround for runc /dev/char/10:200 bug * pkg/rootless: use catatonit from /usr/libexec/podman * rootless: make sure we only use a single pause process * Use atomic config writing strategy for podman machine config files * Add remaining release notes for v4.5.0-RC2 * GHA: Use version instead of SHA for actions * chore(deps): update dependency containers/automation_images to v20230405 * build: pass env by reference * test: retrofit error message * test/system: expect 12 char for short id * vendor: bump containers/(storage, common, buildah, image) * [skip-ci] Update actions/upload-artifact action to v3 * [skip-ci] Update actions/stale action to v8 * [skip-ci] Update actions/setup-go action to v4 * [skip-ci] Update github/issue-labeler action to v2.6 * Fix up codespell errors * Capitalize all uid,gid and id words that are not options in docs * build(deps): bump golang.org/x/tools from 0.7.0 to 0.8.0 in /test/tools * Properly remove the service container during kube down * quadlet: add `UserNS` option key * [CI:DOCS] Release notes for 4.5.0 Part 1 * "podman pull by digest and list --all" test: untag instead of rmi * build(deps): bump golang.org/x/text from 0.8.0 to 0.9.0 * Add renovate.json configuration * CI: postbuild step: skip under nightly treadmill * The `--ulimit` option accepts the name with an `RLIMIT_` prefix both upper and lower case * test/e2e: use custom network config dir where needed * chore: replace `github.com/ghodss/yaml` with `sigs.k8s.io/yaml` * update completion scripts for cobra v1.7.0 * libpod.storageService.CreateContainerStorage(): retrieve ID maps * Fix invalid pod name and hostname during kube generate * e2e tests: fix racy flakes * Cirrus: Enable labeling of EC2 VMs * Cirrus: Fix aarch64 clone_script 404 errors * e2e: GinkgoParallelNode() -> ...Process() * build(deps): bump github.com/spf13/cobra from 1.6.1 to 1.7.0 * build(deps): bump golang.org/x/sys from 0.6.0 to 0.7.0 * [CI:DOCS] --creds and registries * Copr: fix build deps for /usr/bin/envsubst * Don't error when removing non-existant env vars * e2e: healthcheck on stopped container: fix flake * test/apiv2/80-kube.at * test/apiv2/80-kube.at * system service: do not close Body * rm `hack/release.sh` * build(deps): bump github.com/onsi/gomega from 1.27.5 to 1.27.6 * add `quadlet -version` flag * add version/rawversion package * quadlet: use `Flag` suffix for variables * quadlet: implement `Tmpfs` option * Bump to v4.5.0-dev * Bump to 4.5.0-rc1 * Update release notes from 4.4 branch * rootless netns: recover from invalid netns * System tests: unverbosify a flake log * Add support for secret exists * Fix Win install task failures with large PR bodies * docs: add `starting` to `HealthCheckResults.Status` * Add support for cgroup_config from containers.conf * libpod: mount safely subpaths * Support Deployment generation with kube generate * Use secret.items to create volume mounts if present * [CI:DOCS] fix typo in --systemd option * rootless: drop preexec hook error message * Edit the docker wrapper to use the install prefix * Update podman-for-windows.md * Quadlet: RemapUsers documentation fixes * speed up image listing * vendor containers/common@e27c30ee9b1b * fix volume-plugin-test flake * Document building Podman remote on Windows hosts * test/e2e: gpg keep stdout/err attached * auto-update: stop+start instead of restart sytemd units * [CI:DOCS] Improve basic tutorial * Update docs/source/markdown/podman-network.1.md * Add debug to --wait test * fix slirp4netns resolv.conf ip with a userns * Quadlet: add support for keep-id with mapping values * Quadlet E2E test - run quadlet as user generator * sqlite: do not `Ping()` after connecting * Quadlet - treat paths starting with systemd specifiers as absolute * Update docs/source/markdown/podman-kube-play.1.md.in * system tests: use CONTAINERS_CONF_OVERRIDE * implement podman machine set for hyperv * [CI:DOCS] Add network subnets info to network man page * CI: retry the golangci install * system tests: fix racey sdnotify test * hyperv: lookup machine on local filesystem first * fix os.IsNotExist() CI check * Ensure that SQLite state handles name-ID collisions * macos pkginstaller: do not fail when podman-mac-helper fails * podman-mac-helper: install: do not error if already installed * build(deps): bump github.com/onsi/gomega from 1.27.4 to 1.27.5 * Fix a race around SQLite DB config validation * add CONTAINERS_CONF_OVERRIDE * vendor containers/common@main * docs: minor grammar fix in `--volume` description * sqlite: do not use shared cache * test: podman checkpoint/restore the latest container * stats compat API: return "id" lowercase * Run make codespell * Drop SQLite max connections * sqlite: set connection attributes on open * Fix database locked errors with SQLite * quadlet tests: skip on RHEL8 rootless * Kube Play Doc: Document the support for K8S Secret * New ulimit test: bump up minimum nfiles * logformatter: hide --db-backend, and friendlyize quadlet * Quadlet - add support for relative path in Volume key in .container file * Add service ctr cleanup to PlayKubeDown * fix --health-on-failure=restart in transient unit * Quadlet Doc: Suggest the kill operation for HealthOnFailure * Quadlet - Add support for health checks configuration in .container files * Makefile: allow specifying /lib dir location * Fix option --opts -> --opt * basic hypverv machine implementation * Fix SQLite DB schema migration code * Add support for oom_score_adj value from containers.conf * Use default_ulimits field in containers.conf * CI: test and confirm DESIRED_DATABASE * build(deps): bump github.com/openshift/imagebuilder * logformatter: futureproof output filename * Vendor in latest containers/(storage, common, image) * build(deps): bump google.golang.org/protobuf from 1.29.0 to 1.30.0 * test/system/255-auto-update.bats: add debug logs * Revert "Revert "pasta: Use two connections instead of three in TCP range forward tests"" * Add information for secret inspect * Add format to podman volume ls * Add format to podman volume inspect * Add format to podman secret ls * Add format to podman system df * Add format to podman machine info * Add format table to podman image inspect man page * Cirrus: Store podman machine benchmark data * Update Cirrus display names, and fix get-ci-vm script * Ensure SQLite places uses the runroot in transient mode * Fix various integration test issues with SQLite state * Remove test for pod/container name global uniqueness * Improve handling of existing container names in SQLite * Add SQLite job to CI * buildah treadmill: also run rootless tests * build(deps): bump github.com/vbatts/git-validation in /test/tools * auto update: return restart error * fix: Document removing anonymous volumes * events: no duplicates when streaming during a log rotation * Add search --cert-dir, --creds * podman-mac-helper: exit 1 on error * system service --log-level=trace: support hijack * test/system: fix wait_for_port() to wait for bind * cgroupns: private cgroupns on cgroupv1 breaks --systemd * libpod: remove error stutter * podman events: unhide --stream * test/system/255-auto-update.bats: multiple services * 255-auto-update.bats: turn off rollback where needed * Use append() to add elements to a slice * Revert "pasta: Use two connections instead of three in TCP range forward tests" * Support running nested SELinux container separation * bud tests: rootless remote: use correct socket path * build(deps): bump github.com/vbauerster/mpb/v8 from 8.2.1 to 8.3.0 * compat: /auth: parse server address correctly * docs: fix cmd `set DOCKER_HOST` suggestion * test: reenable idmap test * Must use mountlabel when creating builtin volumes * podman.spec.rpkg: distro conditionals for modulesloaddir * build(deps): bump google.golang.org/protobuf from 1.28.1 to 1.29.0 * podman inspect list network when using --net=host or none * pasta: Re-enable "Local forwarder, IPv4" test, accept NXDOMAIN as response * build(deps): bump golang.org/x/tools from 0.6.0 to 0.7.0 in /test/tools * CI: Switch to c20230307t192532z-f37f36d12 images * Cirrus: Run system & integration tests in parallel * Update checkpointctl v0.1.0 * Quadlet: add support for setting --ip and --ip6 * build(deps): bump golang.org/x/net from 0.7.0 to 0.8.0 * build(deps): bump golang.org/x/sys from 0.5.0 to 0.6.0 * libpod: avoid nil pointer dereference in (*Container).Cleanup * [CI:DOCS] Add image not found info to troubleshooting * cmd: do not require userns for "version" * cmd: drop special handling for "scp" * cmd: clarify meaning of ParentNSRequired * Fix package restore * [CI:DOCS] Fix docs/version-check always requesting updates * sqlite: add a hidden --db-backend flag * fix: update the default machine value when the previously set default machine is deleted * podman machine: Adjust Chrony makestep config * sqlite: add container short ID to network aliases * sqlite: remove dead code * sqlite: addContainer: add named volume only once * sqlite: implement RewriteVolumeConfig * sqlite: LookupVolume: fix partial name match * sqlite: LookupVolume: wrap error * sqlite: fix type rewriting container config * sqlite: return correct error on pod-name conflict * sqlite: RewritePodConfig: update error message * test/system/255-auto-update.bats: wait 10 for update to finish * auto-update test: wait for service to be ready * Vendor in latest containers/(common, storage, image) * play kube: Add --wait option * Cirrus: Fix git config permission denied * Quadlet: Add support for the Mount key in .container files * build(deps): bump github.com/onsi/gomega from 1.27.1 to 1.27.2 * fix "podman logs --since --follow" flake * Clarify that replicas are ignored in kubernetes deployment * Revert "Skip all pasta tests" * CI: Switch to c20230223t153813z-f37f36d12 images * Fix user socket path * pkginstaller: bump Qemu to version 7.2.0 * Cirrus: Fix bud tests failing to apply patches * build(deps): bump github.com/stretchr/testify from 1.8.1 to 1.8.2 * build(deps): bump github.com/coreos/stream-metadata-go * Vendor in latest containers/storage * buildah-bud tests: don't sudo when rootless is desired * Temporarily disable version-check * CI: new rootless buildah-bud tests (cron only) * sqlite: fix volume lookups with partial names * sqlite: fix container lookups with partial IDs * sqlite: fix LookupPod * sqlite: fix pod create/rm * sqlite: LookupContainer: update error message * sqlite: AddContainerExitCode: allow to replace * system: add warning when running rootless on cgroupv1 * sqlite: fix AllContainers with state * sqlite: fix "UPDATE TABLE" typos * sqlite: SaveVolume: fix syntax error updating the volumes table * sqlite: exit code: allow -1 * sqlite: fix typo when removing exec sessions * sqlite: AllContainers: fix inner join * sqlite: move migration after table creation * sqlite: implement pod methods * Quadlet - use the default runtime * docs: context is not optional for build * Fix an incorrect comment on NewSqliteState * Add support for containers.conf database setting * Add support for volume operations to SQLite state * Implement exec session handling in SQL database * Various fixes from code review * Remove `--namespace` flag from Podman root * Get E2E tests to pass * Implement network disconnect for SQLite state * Implement Network Connect/Modify for SQLite state * Fix various lint issues * Some further work on SQLite state * Remove concept of Namespaces from BoltDB * Add initial SQLite-backed state implementation * Cirrus: Support runc testing on debian VMs * Skip all pasta tests * Skip buildah-bud test * Skip buildx test with VFS podman storage driver * Skip 'podman kube --network' test for rootless CGv1 * Skip tests which fail with CGv1 & runc * Skip rootless CGv1 quadlet tests due to issue * Makefile: Define SHELL * Machine refactor for QEMU/AppleHV * machine refactoring preparations for hyperv * [CI:BUILD] spec.rpkg: trim dependency list * Logs follow-until tests: loosen checks * [CI:DOCS] Windows/Mac docs link update * Doc update for docker network options via CLI * compat API: network create return 409 for duplicate * Apply suggestions to man page * vendor c/common@852ca05a1fbb * Quadlet: Add support for LogDriver key in container and kube units * machine refactoring preparations for hyperv * libpod: always use direct mapping * netavark: only use aardvark ip as nameserver * build(deps): bump github.com/container-orchestrated-devices/container-device-interface * podman logs passthrough driver support --cgroups=split * journald logs: simplify entry parsing * podman logs: read journald with passthrough * make docs: sanity check for broken man pages * build(deps): bump github.com/vbauerster/mpb/v8 from 8.1.6 to 8.2.0 * build(deps): bump github.com/onsi/gomega from 1.27.0 to 1.27.1 * kube: rm secret on down, print secret on play * Fix spacing typo that triggered OCD & indent units in podman-systemd.unit(5) * Update remote_client.md * [CI:DOCS] Add restriction to option README * Revert "CI: Temporarily disable all AWS EC2-based tasks" * build(deps): bump github.com/onsi/gomega from 1.26.0 to 1.27.0 * kube play: only enforce passthrough in Quadlet * journald: remove initializeJournal() * auto-update: support pods * Emergency fix for man pages: check for broken includes * System tests: assert(): friendlier failure messages * Cirrus: Fix version-check to only run on `main` job * CI: Temporarily disable all AWS EC2-based tasks * build(deps): bump github.com/containerd/containerd from 1.6.16 to 1.6.18 * volume,container: chroot to source before exporting content * Support sysctl configs via podman kube play * [CI:BUILD] copr: podman.spec.rpkg cleanups * quadlet system tests: add useful defaults, logging * libpod: support relative positions for idmaps * Experimental workaround for cdn03.quay.io flake * system tests: prevent leading tabs * Introduce podman machine os apply * create: add support for --group-entry * fix != filter in volume prune * Allow specification of podman --remote build -f - * Quadlet use crun specified in containers.conf * build(deps): bump golang.org/x/net from 0.6.0 to 0.7.0 * Vendor c/image after https://github.com/containers/image/pull/1847 * Don't set hostPort when generating a service * man page --format xref: tighten the autocompletion check * add support for limiting tmpfs size for systemd-specific mnts * build(deps): bump golang.org/x/text from 0.6.0 to 0.7.0 * Add ulimit annotation to kube gen & play * man page xref: validate displayed man page names * quadlet: add ExecStop * install sigproxy before start/attach * build(deps): bump golang.org/x/tools from 0.5.0 to 0.6.0 in /test/tools * Fix typos * Cirrus: Make benchmarks .env file easier to load * Cirrus: Omit functions in env. file * kube play: set service container as main PID when possible * Fix typos. Improve language. * events + container inspect test: RHEL fixes * Add ctrName to network alias during kube play * Run codespell on codebase * podman image scp: added identity for ssh.Exec * [CI:DOCS] Clarify nomap constrains * [CI:DOCS] man-page checker: include --format (Go templates) * Vendor c/image after https://github.com/containers/image/pull/1816 * [CI:DOCS] Cleanup some man pages to display options with line breaks * [CI:DOCS] Add tables to podman-systemd.unit man page * github: remove prefix from bugs/features * Quadlet: Add support for the Secret key in Container group * [CI:DOCS] OWNERS: add @ygalblum and @alexlarsson * build(deps): bump golang.org/x/term from 0.4.0 to 0.5.0 * build(deps): bump github.com/vbauerster/mpb/v8 from 8.1.4 to 8.1.6 * Sort quadlet keys to make it easier to read * e2e: fix some tests on remote * kube play: do not teardown unconditionally on error * Fix typos in comments * Resolve symlink path for qemu directory if possible * #17363 Fix contradicting documentation podman-commit * Fix a potential UID/GID collision in unit tests * golangci-lint: show all errors at once * update golangci-lint to version 1.51.1 * [CI:DOCS] events: document journald identifiers * Quadlet: exit 0 when there are no files to process * network ls: handle removed container * e2e: adapt play kube test on remote rootless * docs/podman-systemd.unit: Explicitely mention network & kube units * docs/podman-systemd.unit: Update example to work out of the box * [CI:BUILD] Cirrus: Fix GraphQL ownerRepository:null error * Add missing return after errors * Revert "Cirrus: Emergency fix to un-stuck PRs" * pasta: Fix ICMPv6 Echo test, skip it for the moment * pasta: Fix ICMP Echo Request (IPv4) test * pasta: Use two connections instead of three in TCP range forward tests * Add SELinux label types support to quadlet * Add quadlet support for rootfs= containers * Cirrus: Emergency fix to un-stuck PRs * Move clean-binaries before podman-remote in podman-remote-docs target * oci: bind mount /sys with --userns=(auto|pod:) * Cleanup podman-systemd.unit file * Install podman-systemd.unit man page, make quadlet discoverable * libpod: allow userns=keep-id for root * system-reset: use CleanCacheMount to clear build cache * vendor: bump buildah to v1.29.1-0.20230201192322-e56eb25575c7 * system tests: fix noexistent labels test in the remote * Expose Podman named pipe in Inspect output * libpod: support idmap for --rootfs * test: adapt test to work on cgroupv1 * Bump to v4.5.0-dev * Update main to reflect v4.4.0 release * Update from /github.com/vbauerster/mpb/v7 to /v8 * hack/perf: cleanup after benchmarks * hack/perf/bz-2162111.sh: use custom network * Update bug_report.yaml * Handle filetype field in kubernetes.yaml files * hack/perf/bz-2162111.sh: measure stop * make hack/markdown-preprocess parallel-safe * system tests: fix volume exec/noexec test * system tests: minor fix for RHEL8 incompatibility * Cirrus: Use versionable IMAGE_SUFFIX * utils: new conversion method * libpod: use GraphRoot for overlay upper dir * vendor: update containers/storage * Do not mount /dev/tty into rootless containers * build(deps): bump go.etcd.io/bbolt from 1.3.6 to 1.3.7 * e2e: fix run_staticip_test about no_proxy * docs: specify order preference for FROM * Fixes port collision issue on use of --publish-all * Support for Windows paths in the source position of the volume mounts * e2e tests: fix incorrect os.User.Name * Log data that we failed to unmarshal * [CI:DOCS] hack/perf: add script for BZ 216111 * container rm: save once for exec removal and state change * [DOCS:CI] podman-events: document verbose create events * e2e: Avoid hard-coding included in quadlet test * e2e: Avoid hard-coding ImageCacheDir * Making gvproxy.exe optional for building Windows installer * Add gvproxy to Windows packages * Add comment to clarify error handling intention * fix #17244: use /etc/timezone where `timedatectl` is missing on Linux * Fix usage of absolute windows paths with --image-path * Match VT device paths to be blocked from mounting exactly * Fix default handling of pids-limit * Add (podman {image,manifest} push --sign-by-sigstore=param-file.yaml) * journald: podman logs only show logs for current user * journald: podman events only show events for current user * e2e: Remove the cache with "podman unshare rm" when a rootless user * Clean up more language for inclusiveness * e2e: Remove some directories at SynchronizedAfterSuite * fix: don't output "ago" when container is currently up and running * fix: running check error when podman is default in wsl * fix CI: test fail due to merge * Bump Bulidah to v1.29.0 * e2e: reduce dependency on /tmp for e2e tests * Bump cirrus image with easier dependency management * quadlet: Add device support for .volume files * remote,build: error if containerignore is symlink * DB: make loading container states optional * ps: do not sync container * Set runAsNonRoot=true in gen kube * WSL refactoring * kube-play: add support for HostIPC in pod.Spec * Allow --device-cgroup-rule to be passed in by docker API- Don't build against EoL go versions, fixes bsc#1210299- Update to version 4.4.4: * Bump to v4.4.4 * Release notes for v4.4.4 * libpod: always use direct mapping * macos pkginstaller: do not fail when podman-mac-helper fails * podman-mac-helper: install: do not error if already installed * Bump to v4.4.4-dev - spec: Bump required version for libcontainers-common (bsc#1209495)- Update to version 4.4.3: * Bump to v4.4.3 * Release notes for v4.4.3 * compat: /auth: parse server address correctly * vendor github.com/containers/common@v0.51.1 * pkginstaller: bump Qemu to version 7.2.0 * podman machine: Adjust Chrony makestep config * [v4.4] fix --health-on-failure=restart in transient unit * podman logs passthrough driver support --cgroups=split * journald logs: simplify entry parsing * podman logs: read journald with passthrough * journald: remove initializeJournal() * netavark: only use aardvark ip as nameserver * compat API: network create return 409 for duplicate * fix "podman logs --since --follow" flake * system service --log-level=trace: support hijack * podman-mac-helper: exit 1 on error * bump golang.org/x/net to v0.8.0 * Fix package restore * Quadlet - use the default runtime * Bump to v4.4.3-dev - Remove patch (merged upstream): * Quadlet-use-the-default-runtime.patch (https://github.com/containers/podman/pull/17601)- Add patch to let quadlet use the default runtime Added patch: * Quadlet-use-the-default-runtime.patch => Remove dependency on crun- Update to version 4.4.2: * Bump to v4.4.2 * Release notes for v4.4.2 * Revert "CI: Temporarily disable all AWS EC2-based tasks" * kube play: only enforce passthrough in Quadlet * Emergency fix for man pages: check for broken includes * CI: Temporarily disable all AWS EC2-based tasks * quadlet system tests: add useful defaults, logging * volume,container: chroot to source before exporting content * install sigproxy before start/attach * Update to c/image 5.24.1 * events + container inspect test: RHEL fixes * Bump to v4.4.2-dev - Remove patches (merged upstream): * volume-container-chroot-to-source-before-exporting-content.patch - podman.spec: add `crun` requirement for quadlet (https://github.com/containers/podman/pull/17601)- podman.spec: set PREFIX at build stage (boo#1208510)- Add patch to fix bsc#1208364 aka CVE-2023-0778 Added patch: * volume-container-chroot-to-source-before-exporting-content.patch- Update to version 4.4.1: * Bump to v4.4.1 * Update release notes for Podman 4.4.1 * kube play: do not teardown unconditionally on error * Resolve symlink path for qemu directory if possible * events: document journald identifiers * Quadlet: exit 0 when there are no files to process * Cleanup podman-systemd.unit file * Install podman-systemd.unit man page, make quadlet discoverable * Add missing return after errors * oci: bind mount /sys with --userns=(auto|pod:) * docs: specify order preference for FROM * Cirrus: Fix & remove GraphQL API tests * test: adapt test to work on cgroupv1 * make hack/markdown-preprocess parallel-safe * Fix default handling of pids-limit * system tests: fix volume exec/noexec test * Bump to v4.4.1-dev- Remove patches (merged upstream or resolved otherwise): * 0001-Revert-Default-missing-hostPort-to-containerPort-is-.patch * 0002-Make-the-priority-for-picking-the-storage-driver-con.patch * 0003-Only-override-the-graphdriver-to-vfs-if-the-priority.patch - remove long obsolete update scriptlets - Update to version 4.4.0: * Bump to v4.4.0 * Final release notes for v4.4.0 * Emergency fix for RHEL8 gating tests * Do not mount /dev/tty into rootless containers * Fixes port collision issue on use of --publish-all * Fix usage of absolute windows paths with --image-path * fix #17244: use /etc/timezone where `timedatectl` is missing on Linux * podman-events: document verbose create events * Making gvproxy.exe optional for building Windows installer * Add gvproxy to Windows packages * Match VT device paths to be blocked from mounting exactly * Clean up more language for inclusiveness * Set runAsNonRoot=true in gen kube * quadlet: Add device support for .volume files * fix: running check error when podman is default in wsl * fix: don't output "ago" when container is currently up and running * journald: podman logs only show logs for current user * journald: podman events only show events for current user * Add (podman {image,manifest} push --sign-by-sigstore=param-file.yaml) * DB: make loading container states optional * ps: do not sync container * Allow --device-cgroup-rule to be passed in by docker API * [v4.4] Bump to Buildah v1.29.0 * Bump to v4.4.0-dev * Bump to v4.4.0-RC3 * Create release notes for v4.4.0 * Cirrus: Update operating branch * fix APIv2 python attach test flake * ps: query health check in batch mode * make example volume import, not import volume * Correct output when inspecting containers created with --ipc * Vendor containers/(storage, image, common, buildah) * Get correct username in pod when using --userns=keep-id * ps: get network data in batch mode * build(deps): bump github.com/onsi/gomega from 1.25.0 to 1.26.0 * add hack/perf for comparing two container engines * systems: retrofit dns options test to honor other search domains * ps: do not create copy of container config * libpod: set search domain independently of nameservers * libpod,netavark: correctly populate /etc/resolv.conf with custom dns server * podman: relay custom DNS servers to network stack * (fix) mount_program is in storage.options.overlay * Change example target to default in doc * network create: do not allow `default` as name * kube-play: add support for HostPID in podSpec * build(deps): bump github.com/docker/docker * Let's see if #14653 is fixed or not * Add support for podman build --group-add * vendor in latests containers/(storage, common, build, image) * unskip network update test * do not install swagger by default * pasta: skip "Local forwarder, IPv4" test * add testbindings Makefile target * update CI images to include pasta * [CI:DOCS] Add CNI deprecation notices to documentation * Cirrus: preserve podman-server logs * waitPidStop: reduce sleep time to 10ms * StopContainer: return if cleanup process changed state * StopSignal: add a comment * StopContainer: small refactor * waitPidStop: simplify code * e2e tests: reenable long-skipped build test * Add openssh-clients to podmanimage * Reworks Windows smoke test to tunnel through interactive session. * fix bud-multiple-platform-with-base-as-default-arg flake * Remove ReservedAnnotations from kube generate specification * e2e: update test/README.md * e2e: use isRootless() instead of rootless.IsRootless() * Cleanup documentation on --userns=auto * Bump to v4.4.0-dev * Bump to v4.4.0-rc2 * Vendor in latest c/common * sig-proxy system test: bump timeout * build(deps): bump github.com/containernetworking/plugins * rootless: rename auth-scripts to preexec-hooks * Docs: version-check updates * commit: use libimage code to parse changes * [CI:DOCS] Remove experimental mac tutorial * man: Document the interaction between --systemd and --privileged * Make rootless privileged containers share the same tty devices as rootfull ones * container kill: handle stopped/exited container * Vendor in latest containers/(image,ocicrypt) * add a comment to container removal * Vendor in latest containers/storage * Cirrus: Run machine tests on PR merge * fix flake in kube system test * kube play: complete container spec * E2E Tests: Use inspect instead of actual data to avoid UDP flake * Use containers/storage/pkg/regexp in place of regexp * Vendor in latest containers/storage * Cirrus: Support using updated/latest NV/AV in PRs * Limit replica count to 1 when deploying from kubernetes YAML * Set StoppedByUser earlier in the process of stopping * podman-play system test: refactor * Bump to v4.4.0-dev * Bump to v4.4.0-RC1 * network: add support for podman network update and --network-dns-server * service container: less verbose error logs * Quadlet Kube - add support for PublishPort key * e2e: fix systemd_activate_test * Compile regex on demand not in init * [docker compat] Don't overwrite the NetworkMode if containers.conf overrides netns. * E2E Test: Play Kube set deadline to connection to avoid hangs * Only prevent VTs to be mounted inside privileged systemd containers * e2e: fix play_kube_test * Updated error message for supported VolumeSource types * Introduce pkg retry logic in win installer task * logformatter: include base SHA, with history link * Network tests: ping redhat.com, not podman.io * cobra: move engine shutdown to Execute * Updated options for QEMU on Windows hosts * Update Mac installer to use gvproxy v0.5.0 * podman: podman rm -f doesn't leave processes * oci: check for valid PID before kill(pid, 0) * linux: add /sys/fs/cgroup if /sys is a bind mount * Quadlet: Add support for ConfigMap key in Kube section * remove service container _after_ pods * Kube Play - allow setting and overriding published host ports * oci: terminate all container processes on cleanup * Update win-sshproxy to 0.5.0 gvisor tag * Vendor in latest containers/common * Fix a potential defer logic error around locking * logformatter: nicer formatting for bats failures * logformatter: refactor verbose line-print * e2e tests: stop using UBI images * k8s-file: podman logs --until --follow exit after time * journald: podman logs --until --follow exit after time * journald: seek to time when --since is used * podman logs: journald fix --since and --follow * Preprocess files in UTF-8 mode * Bump golang.org/x/tools from 0.4.0 to 0.5.0 in /test/tools * Vendor in latest containers/(common, image, storage) * Switch to C based msi hooks for win installer * hack/bats: improve usage message * hack/bats: add --remote option * hack/bats: fix root/rootless logic * Describe copy volume options * Support sig-proxy for podman-remote attach and start * libpod: fix race condition rm'ing stopping containers * e2e: fix run_volume_test * Add support for Windows ARM64 * Add shared --compress to man pages * Add container error message to ContainerState * Man page checker: require canonical name in SEE ALSO * system df: improve json output code * kube play: fix the error logic with --quiet * System tests: quadlet network test * Fix: List container with volume filter * adding -dryrun flag * Quadlet Container: Add support for EnvironmentFile and EnvironmentHost * Kube Play: use passthrough as the default log-driver if service-container is set * System tests: add missing cleanup * System tests: fix unquoted question marks * Build and use a newer systemd image * Quadlet Network - Fix the name of the required network service * System Test Quadlet - Volume dependency test did not test the dependency * fix `podman system connection - tcp` flake * vendor: bump c/storage to a747b27 * Fix instructions about setting storage driver on command-line * Test README - point users to hack/bats * System test: quadlet kube basic test * Fixed `podman update --pids-limit` * podman-remote,bindings: trim context path correctly when its emptydir * Quadlet Doc: Add section for .kube files * e2e: fix containers_conf_test * Allow '/' to prefix container names to match Docker * Remove references to qcow2 * Fix typos in man page regarding transient storage mode. * make: Use PYTHON var for .install.pre-commit * Add containers.conf read-only flag support * Explain that relabeling/chowning of volumes can take along time * events: support "die" filter * infra/abi: refactor ContainerRm * When in transient store mode, use rundir for bundlepath * quadlet: Support Type=oneshot container files * hacks/bats: keep QUADLET env var in test env * New system tests for conflicting options * Vendor in latest containers/(buildah, image, common) * Output Size and Reclaimable in human form for json output * podman service: close duplicated /dev/null fd * ginkgo tests: apply ginkgolinter fixes * Add support for hostPath and configMap subpath usage * export: use io.Writer instead of file * rootless: always create userns with euid != 0 * rootless: inhibit copy mapping for euid != 0 * pkg/domain/infra/abi: introduce `type containerWrapper` * vendor: bump to buildah ca578b290144 and use new cache API * quadlet: Handle booleans that have defaults better * quadlet: Rename parser.LookupBoolean to LookupBooleanWithDefault * Add podman-clean-transient.service service * Stop recording annotations set to false * Unify --noheading and -n to be consistent on all commands * pkg/domain/infra/abi: add `getContainers` * Update vendor of containters/(common, image) * specfile: Drop user-add depedency from quadlet subpackage. * quadlet: Default BINDIR to /usr/bin if tag not specified * Quadlet: add network support * Add comment for jsonMarshal command * Always allow pushing from containers-storage * libpod: move NetNS into state db instead of extra bucket * Add initial system tests for quadlets * quadlet: Add --user option * libpod: remove CNI word were no longer applicable * libpod: fix header length in http attach with logs * podman-kube@ template: use `podman kube` * build(deps): bump github.com/docker/docker * wait: add --ignore option * qudlet: Respect $PODMAN env var for podman binary * e2e: Add assert-key-is-regex check to quadlet e2e testsuite * e2e: Add some assert to quadlet test to make sure testcases are sane * remove unmapped ports from inspect port bindings * update podman-network-create for clarity * Vendor in latest containers/common with default capabilities * pkg/rootless: Change error text ... * rootless: add cli validator * rootless: define LIBEXECPODMAN * doc: fix documentation for idmapped mounts * bump golangci-lint to v1.50.1 * build(deps): bump github.com/onsi/gomega from 1.24.1 to 1.24.2 * [CI:DOCS] podman-mount: s/umount/unmount/ * create/pull --help: list pull policies * Network Create: Add --ignore flag to support idempotent script * Make qemu security model none * libpod: use OCI idmappings for mounts * stop reporting errors removing containers that don't exist * test: added test from wait endpoint with to long label * quadlet: Default VolatileTmp to off * build(deps): bump github.com/ulikunitz/xz from 0.5.10 to 0.5.11 * docs/options/ipc: fix list syntax * Docs: Add dedicated DOWNLOAD doc w/ links to bins * Make a consistently-named windows installer * checkpoint restore: fix --ignore-static-ip/mac * add support for subpath in play kube for named volumes * build(deps): bump golang.org/x/net from 0.2.0 to 0.4.0 * golangci-lint: remove three deprecated linters * parse-localbenchmarks: separate standard deviation * build(deps): bump golang.org/x/term from 0.2.0 to 0.3.0 * podman play kube support container startup probe * Add podman buildx version support * Cirrus: Collect benchmarks on machine instances * Cirrus: Remove escape codes from log files * [CI:DOCS] Clarify secret target behavior * Fix typo on network docs * podman-remote build add --volume support * remote: allow --http-proxy for remote clients * Cleanup kube play workloads if error happens * health check: ignore dependencies of transient systemd units/timers * fix: event read from syslog * Fixes secret (un)marshaling for kube play. * Remove 'you' from man pages * build(deps): bump golang.org/x/tools from 0.3.0 to 0.4.0 in /test/tools * [CI:DOCS] test/README.md: run tests with podman-remote * e2e: keeps the http_proxy value * Makefile: Add podman-mac-helper to darwin client zip * test/e2e: enable "podman run with ipam none driver" for nv * [skip-ci] GHA/Cirrus-cron: Fix execution order * kube sdnotify: run proxies for the lifespan of the service * Update containers common package * podman manpage: Use man-page links instead of file names * e2e: fix e2e tests in proxy environment * Fix test * disable healthchecks automatically on non systemd systems * Quadlet Kube: Add support for userns flag * [CI:DOCS] Add warning about --opts,o with mount's -o * Add podman system prune --external * Add some tests for transient store * runtime: In transient_store mode, move bolt_state.db to rundir * runtime: Handle the transient store options * libpod: Move the creation of TmpDir to an earlier time * network create: support "-o parent=XXX" for ipvlan * compat API: allow MacAddress on container config * Quadlet Kube: Add support for relative path for YAML file * notify k8s system test: move sending message into exec * runtime: do not chown idmapped volumes * quadlet: Drop ExecStartPre=rm %t/%N.cid * Quadlet Kube: Set SyslogIdentifier if was not set * Add a FreeBSD cross build to the cirrus alt build task * Add completion for --init-ctr * Fix handling of readonly containers when defined in kube.yaml * Build cross-compilation fixes * libpod: Track healthcheck API changes in healthcheck_unsupported.go * quadlet: Use same default capability set as podman run * quadlet: Drop --pull=never * quadlet: Change default of ReadOnly to no * quadlet: Change RunInit default to no * quadlet: Change NoNewPrivileges default to false * test: podman run with checkpoint image * Enable 'podman run' for checkpoint images * test: Add tests for checkpoint images * CI setup: simplify environment passthrough code * Init containers should not be restarted * Update c/storage after https://github.com/containers/storage/pull/1436 * Set the latest release explicitly * add friendly comment * fix an overriding logic and load config problem * Update the issue templates * Update vendor of containers/(image, buildah) * [CI:DOCS] Skip windows-smoke when not useful * [CI:DOCS] Remove broken gate-container docs * OWNERS: add Jason T. Greene * hack/podmansnoop: print arguments * Improve atomicity of VM state persistence on Windows * [CI:BUILD] copr: enable podman-restart.service on rpm installation * macos: pkg: Use -arm64 suffix instead of -aarch64 * linux: Add -linux suffix to podman-remote-static binaries * linux: Build amd64 and arm64 podman-remote-static binaries * container create: add inspect data to event * Allow manual override of install location * Run codespell on code * Add missing parameters for checkpoint/restore endpoint * Add support for startup healthchecks * Add information on metrics to the `network create` docs * Introduce podman machine os commands * Document that ignoreRootFS depends on export/import * Document ignoreVolumes in checkpoint/restore endpoint * Remove leaveRunning from swagger restore endpoint * libpod: Add checks to avoid nil pointer dereference if network setup fails * Address golangci-lint issues * Bump golang version to 1.18 * Documenting Hyper-V QEMU acceleration settings * Kube Play: fix the handling of the optional field of SecretVolumeSource * Update Vendor of containers/(common, image, buildah) * Fix swapped NetInput/-Output stats * libpod: Use O_CLOEXEC for descriptors returned by (*Container).openDirectory * chore: Fix MD for Troubleshooting Guide link in GitHub Issue Template * test/tools: rebuild when files are changed * ginkgo tests: apply ginkgolinter fixes * ginkgo: restructure install work flow * Fix manpage emphasis * specgen: support CDI devices from containers.conf * vendor: update containers/common * pkg/trust: Take the default policy path from c/common/pkg/config * Add validate-in-container target * Adding encryption decryption feature * container restart: clean up healthcheck state * Add support for podman-remote manifest annotate * Quadlet: Add support for .kube files * Update vendor of containers/(buildah, common, storage, image) * specgen: honor user namespace value * [CI:DOCS] Migrate OSX Cross to M1 * quadlet: Rework uid/gid remapping * GHA: Fix cirrus re-run workflow for other repos. * ssh system test: skip until it becomes a test * shell completion: fix hard coded network drivers * libpod: Report network setup errors properly on FreeBSD * E2E Tests: change the registry for the search test to avoid authentication * pkginstaller: install podman-mac-helper by default * Fix language. Mostly spelling a -> an * podman machine: Propagate SSL_CERT_FILE and SSL_CERT_DIR to systemd environment. * [CI:DOCS] Fix spelling and typos * Modify man page of "--pids-limit" option to correct a default value. * Update docs/source/markdown/podman-remote.1.md * Update pkg/bindings/connection.go * Add more documentation on UID/GID Mappings with --userns=keep-id * support podman-remote to connect tcpURL with proxy * Removing the RawInput from the API output * fix port issues for CONTAINER_HOST * CI: Package versions: run in the 'main' step * build(deps): bump github.com/rootless-containers/rootlesskit * pkg/domain: Make checkExecPreserveFDs platform-specific * e2e tests: fix restart race * Fix podman --noout to suppress all output * remove pod if creation has failed * pkg/rootless: Implement rootless.IsFdInherited on FreeBSD * Fix more podman-logs flakes * healthcheck system tests: try to fix flake * libpod: treat ESRCH from /proc/PID/cgroup as ENOENT * GHA: Configure workflows for reuse * compat,build: handle docker's preconfigured cacheTo,cacheFrom * docs: deprecate pasta network name * utils: Enable cgroup utils for FreeBSD * pkg/specgen: Disable kube play tests on FreeBSD * libpod/lock: Fix build and tests for SHM locks on FreeBSD * podman cp: fix copying with "." suffix * pkginstaller: bump Qemu to version 7.1.0 * specgen,wasm: switch to crun-wasm wherever applicable * vendor: bump c/common to v0.50.2-0.20221111184705-791b83e1cdf1 * libpod: Make unit test for statToPercent Linux only * Update vendor of containers/storage * fix connection usage with containers.conf * Add --quiet and --no-info flags to podman machine start * Add hidden podman manifest inspect -v option * Bump github.com/onsi/gomega from 1.24.0 to 1.24.1 * Add podman volume create -d short option for driver * Vendor in latest containers/(common,image,storage) * Add podman system events alias to podman events * Fix search_test to return correct version of alpine * Bump golang.org/x/tools from 0.1.12 to 0.3.0 in /test/tools * GHA: Fix undefined secret env. var. * Release notes for 4.3.1 * GHA: Fix make_email-body script reference * Add release keys to README * GHA: Fix typo setting output parameter * GHA: Fix typo. * New tool, docs/version-check * Formalize our compare-against-docker mechanism * Add restart-sec for container service files * test/tools: bump module to go 1.17 * contrib/cirrus/check_go_changes.sh: ignore test/tools/vendor * Bump github.com/coreos/go-systemd/v22 from 22.4.0 to 22.5.0 * Bump golang.org/x/term from 0.1.0 to 0.2.0 * Bump golang.org/x/sys from 0.1.0 to 0.2.0 * Bump github.com/container-orchestrated-devices/container-device-interface * build(deps): bump golang.org/x/tools from 0.1.12 to 0.2.0 in /test/tools * libpod: Add FreeBSD support in packageVersion * Allow podman manigest push --purge|-p as alias for --rm * [CI:DOCS] Add performance tutorial * [CI:DOCS] Fix build targets in build_osx.md. * fix --format {{json .}} output to match docker * remote: fix manifest add --annotation * Skip test if `--events-backend` is necessary with podman-remote * kube play: update the handling of PersistentVolumeClaim * system tests: fix a system test in proxy environment * Use single unqualified search registry on Windows * test/system: Add, use tcp_port_probe() to check for listeners rather than binds * test/system: Add tests for pasta(1) connectivity * test/system: Move network-related helpers to helpers.network.bash * test/system: Use procfs to find bound ports, with optional address and protocol * test/system: Use port_is_free() from wait_for_port() * libpod: Add pasta networking mode * More log-flake work * Fix test flakes caused by improper podman-logs * fix incorrect systemd booted check * Cirrus: Add tests for GHA scripts * GHA: Update scripts to pass shellcheck * Cirrus: Shellcheck github-action scripts * Cirrus: shellcheck support for github-action scripts * GHA: Fix cirrus-cron scripts * Makefile: don't install to tmpfiles.d on FreeBSD * Make sure we can build and read each line of docker py's api client * Docker compat build api - make sure only one line appears per flush * Run codespell on code * Update vendor of containers/(image, storage, common) * Allow namespace path network option for pods. * Cirrus: Never skip running Windows Cross task * GHA: Auto. re-run failed cirrus-cron builds once * GHA: Migrate inline script to file * GHA: Simplify script reference * test/e2e: do not use apk in builds * remove container/pod id file along with container/pod * Cirrus: Synchronize windows image * Add --insecure,--tls-verify,--verbose flags to podman manifest inspect * runtime: add check for valid pod systemd cgroup * CI: set and verify DESIRED_NETWORK (netavark, cni) * [CI:DOCS] troubleshooting: document keep-id options * Man pages: refactor common options: --security-opt * Cirrus: Guarantee CNI testing w/o nv/av present * Cirrus: temp. disable all Ubuntu testing * Cirrus: Update to F37beta * buildah bud tests: better handling of remote * quadlet: Warn in generator if using short names * Add Windows Smoke Testing * Add podman kube apply command * docs: offer advice on installing test dependencies * Fix documentation on read-only-tmpfs * version bump to 4.4.0-dev * deps: bump go-criu to v6 * Makefile: Add cross build targets for freebsd * pkg/machine: Make this build on FreeBSD/arm64 * pkg/rctl: Remove unused cgo dependency * man pages: assorted underscore fixes * Upgrade GitHub actions packages from v2 to v3 * vendor github.com/godbus/dbus/v5@4b691ce * [CI:DOCS] fix --tmpdir typos * Do not report that /usr/share/containers/storage.conf has been edited. * Eval symlinks on XDG_RUNTIME_DIR * hack/podmansnoop * rootless: support keep-id with one mapping * rootless: add argument to GetConfiguredMappings * Update vendor containers/(common,storage,buildah,image) * Fix deadlock between 'podman ps' and 'container inspect' commands * Add information about where the libpod/boltdb database lives * Consolidate the dependencies for the IsTerminal() API * Ensure that StartAndAttach locks while sending signals * ginkgo testing: fix podman usernamespace join * Test runners: nuke podman from $PATH before tests * volumes: Fix idmap not working for volumes * FIXME: Temporary workaround for ubi8 CI breakage * System tests: teardown: clean up volumes * update api versions on docs.podman.io * system tests: runlabel: use podman-under-test * system tests: podman network create: use random port * sig-proxy test: bump timeout * play kube: Allow the user to import the contents of a tar file into a volume * Clarify the docs on DropCapability * quadlet tests: Disable kmsg logging while testing * quadlet: Support multiple Network= * quadlet: Add support for Network=... * Fix manpage for podman run --network option * quadlet: Add support for AddDevice= * quadlet: Add support for setting seccomp profile * quadlet: Allow multiple elements on each Add/DropCaps line * quadlet: Embed the correct binary name in the generated comment * quadlet: Drop the SocketActivated key * quadlet: Switch log-driver to passthrough * quadlet: Change ReadOnly to default to enabled * quadlet tests: Run the tests even for (exected) failed tests * quadlet tests: Fix handling of stderr checks * Remove unused script file * notifyproxy: fix container watcher * container/pod id file: truncate instead of throwing an error * quadlet: Use the new podman create volume --ignore * Add podman volume create --ignore * logcollector: include aardvark-dns * build(deps): bump github.com/stretchr/testify from 1.8.0 to 1.8.1 * build(deps): bump github.com/BurntSushi/toml from 1.2.0 to 1.2.1 * docs: generate systemd: point to kube template * docs: kube play: mention restart policy * Fixes: 15858 (podman system reset --force destroy machine) * fix search flake * use cached containers.conf * adding regex support to the ancestor ps filter function * Fix `system df` issues with `-f` and `-v` * markdown-preprocess: cross-reference where opts are used * Default qemu flags for Windows amd64 * build(deps): bump golang.org/x/text from 0.3.8 to 0.4.0 * Update main to reflect v4.3.0 release * build(deps): bump github.com/docker/docker * move quadlet packages into pkg/systemd * system df: fix image-size calculations * Add man page for quadlet * Fix small typo * testimage: add iproute2 & socat, for pasta networking * Set up minikube for k8s testing * Makefile: don't install systemd generator binaries on FreeBSD * [CI:BUILD] copr: podman rpm should depend on containers-common-extra * Podman image: Set default_sysctls to empty for rootless containers * Don't use github.com/docker/distribution * libpod: Add support for 'podman top' on FreeBSD * libpod: Factor out jail name construction from stats_freebsd.go * pkg/util: Add pid information descriptors for FreeBSD * Initial quadlet version integrated in golang * bump golangci-lint to v1.49.0 * Update vendor containers/(common,image,storage) * Allow volume mount dups, iff source and dest dirs * rootless: fix return value handling * Change to correct break statements * vendor containers/psgo@v1.8.0 * Clarify that MacOSX docs are client specific * libpod: Factor out the call to PidFdOpen from (*Container).WaitForExit * Add swagger install + allow version updates in CI * Cirrus: Fix windows clone race * build(deps): bump github.com/docker/docker * kill: wait for the container * generate systemd: set --stop-timeout for stopping containers * hack/tree_status.sh: print diff at the end * Fix markdown header typo * markdown-preprocess: add generic include mechanism * markdown-preprocess: almost complete OO rewrite * Update tests for changed error messages * Update c/image after https://github.com/containers/image/pull/1299 * Man pages: refactor common options (misc) * Man pages: Refactor common options: --detach-keys * vendor containers/storage@main * Man pages: refactor common options: --attach * build(deps): bump github.com/fsnotify/fsnotify from 1.5.4 to 1.6.0 * KillContainer: improve error message * docs: add missing options * Man pages: refactor common options: --annotation (manifest) * build(deps): bump github.com/spf13/cobra from 1.5.0 to 1.6.0 * system tests: health-on-failure: fix broken logic * build(deps): bump golang.org/x/text from 0.3.7 to 0.3.8 * build(deps): bump github.com/onsi/gomega from 1.20.2 to 1.22.1 * ContainerEngine.SetupRootless(): Avoid calling container.Config() * Container filters: Avoid use of ctr.Config() * Avoid unnecessary calls to Container.Spec() * Add and use Container.LinuxResource() helper * play kube: notifyproxy: listen before starting the pod * play kube: add support for configmap binaryData * Add and use libpod/Container.Terminal() helper * Revert "Add checkpoint image tests" * Revert "cmd/podman: add support for checkpoint images" * healthcheck: fix --on-failure=stop * Man pages: Add mention of behavior due to XDG_CONFIG_HOME * build(deps): bump github.com/containers/ocicrypt from 1.1.5 to 1.1.6 * Avoid unnecessary timeout of 250msec when waiting on container shutdown * health checks: make on-failure action retry aware * libpod: Remove 100msec delay during shutdown * libpod: Add support for 'podman pod' on FreeBSD * libpod: Factor out cgroup validation from (*Runtime).NewPod * libpod: Move runtime_pod_linux.go to runtime_pod_common.go * specgen/generate: Avoid a nil dereference in MakePod * libpod: Factor out cgroups handling from (*Pod).refresh * Adds a link to OSX docs in CONTRIBUTING.md * Man pages: refactor common options: --os-version * Create full path to a directory when DirectoryOrCreate is used with play kube * Return error in podman system service if URI scheme is not unix/tcp * Man pages: refactor common options: --time * man pages: document some --format options: images * Clean up when stopping pods * Update vendor of containers/buildah v1.28.0 * Proof of concept: nightly dependency treadmill- add patch: 0003-Only-override-the-graphdriver-to-vfs-if-the-priority.patch (backport of https://github.com/containers/storage/pull/1468)- Make the priority for picking the storage driver configurable (bsc#1197093) (backport of https://github.com/containers/storage/pull/1460) - add patch: 0002-Make-the-priority-for-picking-the-storage-driver-con.patch- switch to building with go 1.17 - use %%make_* macros - drop /usr/share/user-tmpfiles.d/podman-docker.conf on SLE & Leap - remove rpmlintrc (contained only obsolete filters) - remove obsolete with_libostree (we don't build on anything older than SLE 15) - add patch: 0001-Revert-Default-missing-hostPort-to-containerPort-is-.patch (hotfix for https://github.com/containers/podman/issues/16765) - Update to version 4.3.1: 4.3.1: [#]## Bugfixes - Fixed a deadlock between the `podman ps` and `podman container inspect` commands [#]## Misc - Updated the containers/image library to v5.23.1 4.3.0: [#]## Features - A new command, `podman generate spec`, has been added, which creates a JSON struct based on a given container that can be used with the Podman REST API to create containers. - A new command, `podman update`, has been added,which makes changes to the resource limits of existing containers. Please note that these changes do not persist if the container is restarted ([#15067](https://github.com/containers/podman/issues/15067)). - A new command, `podman kube down`, has been added, which removes pods and containers created by the given Kubernetes YAML (functionality is identical to `podman kube play --down`, but it now has its own command). - The `podman kube play` command now supports Kubernetes secrets using Podman's secrets backend. - Systemd-managed pods created by the `podman kube play` command now integrate with sd-notify, using the `io.containers.sdnotify` annotation (or `io.containers.sdnotify/$name` for specific containers). - Systemd-managed pods created by `podman kube play` can now be auto-updated, using the `io.containers.auto-update` annotation (or `io.containers.auto-update/$name` for specific containers). - The `podman kube play` command can now read YAML from URLs, e.g. `podman kube play https://example.com/demo.yml` ([#14955](https://github.com/containers/podman/issues/14955)). - The `podman kube play` command now supports the `emptyDir` volume type ([#13309](https://github.com/containers/podman/issues/13309)). - The `podman kube play` command now supports the `HostUsers` field in the pod spec. - The `podman play kube` command now supports `binaryData` in ConfigMaps. - The `podman pod create` command can now set additional resource limits for pods using the new `--memory-swap`, `--cpuset-mems`, `--device-read-bps`, `--device-write-bps`, `--blkio-weight`, `--blkio-weight-device`, and `--cpu-shares` options. - The `podman machine init` command now supports a new option, `--username`, to set the username that will be used to connect to the VM as a non-root user ([#15402](https://github.com/containers/podman/issues/15402)). - The `podman volume create` command's `-o timeout=` option can now set a timeout of 0, indicating volume plugin operations will never time out. - Added support for a new volume driver, `image`, which allows volumes to be created that are backed by images. - The `podman run` and `podman create` commands support a new option, `--env-merge`, allowing environment variables to be specified relative to other environment variables in the image (e.g. `podman run --env-merge "PATH=$PATH:/my/app" ...`) ([#15288](https://github.com/containers/podman/issues/15288)). - The `podman run` and `podman create` commands support a new option, `--on-failure`, to allow action to be taken when a container fails health checks, with the following supported actions: `none` (take no action, the default), `kill` (kill the container), `restart` (restart the container), and `stop` (stop the container). - The `--keep-id` option to `podman create` and `podman run` now supports new options, `uid` and `gid`, to set the UID and GID of the user in the container that will be mapped to the user running Podman (e.g. `--userns=keep-id:uid=11` will made the user running Podman to UID 11 in the container) ([#15294](https://github.com/containers/podman/issues/15294)). - The `podman generate systemd` command now supports a new option, `--env`/`-e`, to set environment variables in the generated unit file ([#15523](https://github.com/containers/podman/issues/15523)). - The `podman pause` and `podman unpause` commands now support the `--latest`, `--cidfile`, and `--filter` options. - The `podman restart` command now supports the `--cidfile` and `--filter` options. - The `podman rm` command now supports the `--filter` option to select which containers will be removed. - The `podman rmi` command now supports a new option, `--no-prune`, to prevent the removal of dangling parents of removed images. - The `--dns-opt` option to `podman create`, `podman run`, and `podman pod create` has received a new alias, `--dns-option`, to improve Docker compatibility. - The `podman` command now features a new global flag, `--debug`/`-D`, which enables debug-level logging (identical to `--log-level=debug`), improving Docker compatibility. - The `podman` command now features a new global flag, `--config`. This flag is ignored, and is only included for Docker compatibility ([#14767](https://github.com/containers/podman/issues/14767)). - The `podman manifest create` command now accepts a new option, `--amend`/`-a`. - The `podman manifest create`, `podman manifest add` and `podman manifest push` commands now accept a new option, `--insecure` (identical to `--tls-verify=false`), improving Docker compatibility. - The `podman secret create` command's `--driver` and `--format` options now have new aliases, `-d` for `--driver` and `-f` for `--format`. - The `podman secret create` command now supports a new option, `--label`/`-l`, to add labels to created secrets. - The `podman secret ls` command now accepts the `--quiet`/`-q` option. - The `podman secret inspect` command now accepts a new option, `--pretty`, to print output in human-readable format. - The `podman stats` command now accepts the `--no-trunc` option. - The `podman save` command now accepts the `--signature-policy` option ([#15869](https://github.com/containers/podman/issues/15869)). - The `podman pod inspect` command now allows multiple arguments to be passed. If so, it will return a JSON array of the inspected pods ([#15674](https://github.com/containers/podman/issues/15674)). - A series of new hidden commands have been added under `podman context` as aliases to existing `podman system connection` commands, to improve Docker compatibility. - The remote Podman client now supports proxying signals for attach sessions when the `--sig-proxy` option is set ([#14707](https://github.com/containers/podman/issues/14707)). [#]## Changes - Duplicate volume mounts are now allowed with the `-v` option to `podman run`, `podman create`, and `podman pod create`, so long as source, destination, and options all match ([#4217](https://github.com/containers/podman/issues/4217)). - The `podman generate kube` and `podman play kube` commands have been renamed to `podman kube generate` and `podman kube play` to group Kubernetes-related commands. Aliases have been added to ensure the old command names still function. - A number of Podman commands (`podman init`, `podman container checkpoint`, `podman container restore`, `podman container cleanup`) now print the user-inputted name of the container, instead of its full ID, on success. - When an unsupported option (e.g. resource limit) is specified for a rootless container on a cgroups v1 system, a warning message is now printed that the limit will not be honored. - The installer for the Windows Podman client has been improved. - The `--cpu-rt-period` and `--cpu-rt-runtime` options to `podman run` and `podman create` now print a warning and are ignored on cgroups v2 systems (cgroups v2 having dropped support for these controllers) ([#15666](https://github.com/containers/podman/issues/15666)). - Privileged containers running systemd will no longer mount `/dev/tty*` devices other than `/dev/tty` itself into the container ([#15878](https://github.com/containers/podman/issues/15878)). - Events for containers that are part of a pod now include the ID of the pod in the event. - SSH functionality for `podman machine` commands has seen a thorough rework, addressing many issues about authentication. - The `--network` option to `podman kube play` now allows passing `host` to set the pod to use host networking, even if the YAML does not request this. - The `podman inspect` command on containers now includes the digest of the image used to create the container. - Pods created by `podman play kube` are now, by default, placed into a network named `podman-kube`. If the `podman-kube` network does not exist, it will be created. This ensures pods can connect to each other by their names, as the network has DNS enabled. [#]## Bugfixes - Fixed a bug where the `podman network prune` and `podman container prune` commands did not properly support the `--filter label!=` option ([#14182](https://github.com/containers/podman/issues/14182)). - Fixed a bug where the `podman kube generate` command added an unnecessary `Secret: null` line to generated YAML ([#15156](https://github.com/containers/podman/issues/15156)). - Fixed a bug where the `podman kube generate` command did not set `enableServiceLinks` and `automountServiceAccountToken` to false in generated YAML ([#15478](https://github.com/containers/podman/issues/15478) and [#15243](https://github.com/containers/podman/issues/15243)). - Fixed a bug where the `podman kube play` command did not properly handle CPU limits ([#15726](https://github.com/containers/podman/issues/15726)). - Fixed a bug where the `podman kube play` command did not respect default values for liveness probes ([#15855](https://github.com/containers/podman/issues/15855)). - Fixed a bug where the `podman kube play` command did not bind ports if `hostPort` was not specified but `containerPort` was ([#15942](https://github.com/containers/podman/issues/15942)). - Fixed a bug where the `podman kube play` command sometimes did not create directories on the host for `hostPath` volumes. - Fixed a bug where the remote Podman client's `podman manifest push` command did not display progress. - Fixed a bug where the `--filter "{{.Config.Healthcheck}}"` option to `podman image inspect` did not print the image's configured healthcheck ([#14661](https://github.com/containers/podman/issues/14661)). - Fixed a bug where the `podman volume create -o timeout=` option could be specified even when no volume plugin was in use. - Fixed a bug where the `podman rmi` command did not emit `untag` events when removing tagged images ([#15485](https://github.com/containers/podman/issues/15485)). - Fixed a bug where API forwarding with `podman machine` VMs on windows could sometimes fail because the pipe was not created in time ([#14811](https://github.com/containers/podman/issues/14811)). - Fixed a bug where the `podman pod rm` command could error if removal of a container in the pod was interrupted by a reboot. - Fixed a bug where the `exited` and `exec died` events for containers did not include the container's labels ([#15617](https://github.com/containers/podman/issues/15617)). - Fixed a bug where running Systemd containers on a system not using Systemd as PID 1 could fail ([#15647](https://github.com/containers/podman/issues/15647)). - Fixed a bug where Podman did not pass all necessary environment variables (including `$PATH`) to Conmon when starting containers ([#15707](https://github.com/containers/podman/issues/15707)). - Fixed a bug where the `podman events` command could function improperly when no events were present ([#15688](https://github.com/containers/podman/issues/15688)). - Fixed a bug where the `--format` flag to various Podman commands did not properly handle template strings including a newline (`\n`) ([#13446](https://github.com/containers/podman/issues/13446)). - Fixed a bug where Systemd-managed pods would kill every container in a pod when a single container exited ([#14546](https://github.com/containers/podman/issues/14546)). - Fixed a bug where the `podman generate systemd` command would generate incorrect YAML for pods created without the `--name` option. - Fixed a bug where the `podman generate systemd --new` command did not properly set stop timeout ([#16149](https://github.com/containers/podman/issues/16149)). - Fixed a bug where a broken OCI spec resulting from the system rebooting while a container is being started could cause the `podman inspect` command to be unable to inspect the container until it was restarted. - Fixed a bug where creating a container with a working directory on an overlay volume would result in the container being unable to start ([#15789](https://github.com/containers/podman/issues/15789)). - Fixed a bug where attempting to remove a pod with running containers without `--force` would not error and instead would result in the pod, and its remaining containers, being placed in an unusable state ([#15526](https://github.com/containers/podman/issues/15526)). - Fixed a bug where memory limits reported by `podman stats` could exceed the maximum memory available on the system ([#15765](https://github.com/containers/podman/issues/15765)). - Fixed a bug where the `podman container clone` command did not properly handle environment variables whose value contained an `=` character ([#15836](https://github.com/containers/podman/issues/15836)). - Fixed a bug where the remote Podman client would not print the container ID when running the `podman-remote run --attach stdin` command. - Fixed a bug where the `podman machine list --format json` command did not properly show machine starting status. - Fixed a bug where automatic updates would not error when attempting to update a container with a non-fully qualified image name ([#15879](https://github.com/containers/podman/issues/15879)). - Fixed a bug where the `podman pod logs --latest` command could panic ([#15556](https://github.com/containers/podman/issues/15556)). - Fixed a bug where Podman could leave lingering network namespace mounts on the system if cleaning up the network failed. - Fixed a bug where specifying an unsupported URI scheme for `podman system service` to listen at would result in a panic. - Fixed a bug where the `podman kill` command would sometimes not transition containers to the exited state ([#16142](https://github.com/containers/podman/issues/16142)). [#]## API - Fixed a bug where the Compat DF endpoint reported incorrect reference counts for volumes ([#15720](https://github.com/containers/podman/issues/15720)). - Fixed a bug in the Compat Inspect endpoint for Networks where an incorrect network option was displayed, causing issues with `docker-compose` ([#15580](https://github.com/containers/podman/issues/15580)). - The Libpod Restore endpoint for Containers now features a new query parameter, `pod`, to set the pod that the container will be restored into ([#15018](https://github.com/containers/podman/issues/15018)). - Fixed a bug where the REST API could panic while retrieving images. - Fixed a bug where a cancelled connection to several endpoints could induce a memory leak. [#]## Misc - Error messages when attempting to remove an image used by a non-Podman container have been improved ([#15006](https://github.com/containers/podman/issues/15006)). - Podman will no longer print a warning that `/` is not a shared mount when run inside a container ([#15295](https://github.com/containers/podman/issues/15295)). - Work is ongoing to port Podman to FreeBSD. - The output of `podman generate systemd` has been adjusted to improve readability. - A number of performance improvements have been made to `podman create` and `podman run`. - A major reworking of the manpages to ensure duplicated options between commands have the same description text has been performed. - Updated Buildah to v1.28.0 - Updated the containers/image library to v5.23.0 - Updated the containers/storage library to v1.43.0 - Updated the containers/common library to v0.50.1- Update to version 4.2.1: * Bump to v4.2.1 * Add release notes for v4.2.1 * remove SkipIfNotFedora() from events test * fix podman events with custom format * Drop stale config value resulting in asymmetric config * Fix list of default capabilities * Add container GID to additional groups (CVE-2022-2989 / bsc#1202809, removes patch 0001-Add-container-GID-to-additional-groups.patch) * libpod: Ensure that generated container names are random * Fix bind-mount-option annotation in gen/play kube * Improved Windows compatibility for machine command * updated apiv2 tests to reflect hash compat fix * api: return imageID instead of imageName, for "Image" when Podman API is queried * Inhibit SIGTERM during Conmon startup * Fix example sections to follow the same format * Fix template name inconsistency * service: make move to sub-cgroup non fatal * Remove duplicate annotations in generated service yaml * Compat API image remove events now have 'delete' status * [CI:DOCS] Automatically set podman version in pkginstaller * Allow colons in windows file paths * Fixes isRootfull check using qemu machine on Windows * vendor containers/psgo@v1.7.3 * Allow podman to run in an environment with keys containing spaces * Document restrictions on transport in FROM * Improved Windows compatibility * pass environment variables to container clone * podman save: update --compress validation * sort hc.Binds returned from compat api * Cirrus: Update podman-machine comment * podman images and friends can take one image as argument * [CI:DOCS] Add .DS_Store to gitignore * podman-kube@.service.in: Remove Restart=never option with typo * Fix #15499 already connected network * [CI:DOCS] Cirrus: Update meta-task for EC2 image * fix CI: remove hardcodeded alpine version * fix CI: remove hardcodeded alpine version * Preserve all unknown PolicyRequirement fields on (podman image trust set) * Reorganize the types in policy.go a bit * Add support for showing keyPaths in (podman image trust show) * Support (image trust show) for sigstoreSigned entries * BREAKING CHANGE: Change how (podman image trust show) represents multiple requirements * Reorganize descriptionsOfPolicyRequirements a bit * Use the full descriptionsOfPolicyRequirements for the default scope * Rename haveMatchRegistry to registriesDConfigurationForScope * Rename tempTrustShowOutput to entry * Split descriptionsOfPolicyRequirements out of getPolicyShowOutput * Recognize the new lookaside names for simple signing sigstore * Add a unit test for trust.PolicyDescription * Make the output of (podman image trust show) deterministic * Make most of pkg/trust package-private * Move most of ImageEngine.ShowTrust into pkg/trust.PolicyDescription * Add support for sigstoreSigned in (podman image trust set) * Create new policy entries together with validating input * Improve validation of data in ImageEngine.SetTrust * Move most of imageEngine.SetTrust to pkg/trust.AddPolicyEntries * Add a variable for scope * Make trust.CreateTempFile private * Reorganize pkg/trust * Remove an unused trust.ShowOutput type * Remove commented out code * libpod: UpdateContainerStatus: do not wait for container * Skip / update some tests under runc * Bump to v4.2.1-dev * test: update apply-podman-deltas for new tests * build: implement --cache-to,--cache-from and --cache-ttl * vendor: bump buildah to v1.27.0- Update to version 4.2.0: * Features - Podman now supports the Gitlab Runner (using the Docker executor), allowing its use in Gitlab CI/CD pipelines. - A new command has been added, podman pod clone, to create a copy of an existing pod. It supports several options, including --start to start the new pod, --destroy to remove the original pod, and --name to change the name of the new pod (#12843). - A new command has been added, podman volume reload, to sync changes in state between Podman's database and any configured volume plugins (#14207). - A new command has been added, podman machine info, which displays information about the host and the versions of various machine components. - Pods created by podman play kube can now be managed by systemd unit files. This can be done via a new systemd service, podman-kube@.service - e.g. systemctl --user start podman-play-kube@$(systemd-escape my.yaml).service will run the Kubernetes pod or deployment contained in my.yaml under systemd. - The podman play kube command now honors the RunAsUser, RunAsGroup, and SupplementalGroups setting from the Kubernetes pod's security context. - The podman play kube command now supports volumes with the BlockDevice and CharDevice types (#13951). - The podman play kube command now features a new flag, --userns, to set the user namespace of created pods. Two values are allowed at present: host and auto (#7504). - The podman play kube command now supports setting the type of created init containers via the io.podman.annotations.init.container.type annotation. - Pods now have include an exit policy (configurable via the --exit-policy option to podman pod create), which determines what will happen to the pod's infra container when the entire pod stops. The default, continue, acts as Podman currently does, while a new option, stop, stops the infra container after the last container in the pod stops, and is used by default for pods from podman play kube (#13464). - The podman pod create command now allows the pod's name to be specified as an argument, instead of using the --name option - for example, podman pod create mypod instead of the prior podman pod create --name mypod. Please note that the --name option is not deprecated and will continue to work. - The podman pod create command's --share option now supports adding namespaces to the set by prefacing them with + (as opposed to specifying all namespaces that should be shared) (#13422). - The podman pod create command has a new option, --shm-size, to specify the size of the /dev/shm mount that will be shared if the pod shares its UTS namespace (#14609). - The podman pod create command has a new option, --uts, to configure the UTS namespace that will be shared by containers in the pod. - The podman pod create command now supports setting pod-level resource limits via the --cpus, --cpuset-cpus, and --memory options. These will set a limit for all containers in the pod, while individual containers within the pod are allowed to set further limits. Look forward to more options for resource limits in our next release! - The podman create and podman run commands now include the -c short option for the --cpu-shares option. - The podman create and podman run commands can now create containers from a manifest list (and not an image) as long as the --platform option is specified (#14773). - The podman build command now supports a new option, --cpp-flag, to specify options for the C preprocessor when using Containerfile.in files that require preprocessing. - The podman build command now supports a new option, --build-context, allowing the user to specify an additional build context. - The podman machine inspect command now prints the location of the VM's Podman API socket on the host (#14231). - The podman machine init command on Windows now fetches an image with packages pre-installed (#14698). - Unused, cached Podman machine VM images are now cleaned up automatically. Note that because Podman now caches in a different directory, this will not clean up old images pulled before this change (#14697). - The default for the --image-volume option to podman run and podman create can now have its default set through the image_volume_mode setting in containers.conf (#14230). - Overlay volumes now support two new options, workdir and upperdir, to allow multiple overlay volumes from different containers to reuse the same workdir or upperdir (#14427). - The podman volume create command now supports two new options, copy and nocopy, to control whether contents from the overmounted folder in a container will be copied into the newly-created named volume (copy-up). - Volumes created using a volume plugin can now specify a timeout for all operations that contact the volume plugin (replacing the standard 5 second timeout) via the --opt o=timeout= option to podman volume create (BZ 2080458). - The podman volume ls command's --filter name= option now supports regular expression matching for volume names (#14583). - When used with a podman machine VM, volumes now support specification of the 9p security model using the security_model option to podman create -v and podman run -v. - The remote Podman client's podman push command now supports the --remove-signatures option (#14558). - The remote Podman client now supports the podman image scp command. - The podman image scp command now supports tagging the transferred image with a new name. - The podman network ls command supports a new filter, --filter dangling=, to list networks not presently used by any containers (#14595). - The --condition option to podman wait can now be specified multiple times to wait on any one of multiple conditions. - The podman events command now includes the -f short option for the --filter option. - The podman pull command now includes the -a short option for the --all-tags option. - The podman stop command now includes a new flag, --filter, to filter which containers will be stopped (e.g. podman stop --all --filter label=COM.MY.APP). - The Podman global option --url now has two aliases: -H and --host. - The podman network create command now supports a new option with the default bridge driver, --opt isolate=, which isolates the network by blocking any traffic from it to any other network with the isolate option enabled. This option is enabled by default for networks created using the Docker-compatible API. - Added the ability to create sigstore signatures in podman push and podman manifest push. - Added an option to read image signing passphrase from a file. * Changes - Paused containers can now be killed with the podman kill command. - The podman system prune command now removes unused networks. - The --userns=keep-id and --userns=nomap options to the podman run and podman create commands are no longer allowed (instead of simply being ignored) with root Podman. - If the /run directory for a container is part of a volume, Podman will not create the /run/.containerenv file (#14577). - The podman machine stop command on macOS now waits for the machine to be completely stopped to exit (#14148). - All podman machine commands now only support being run as rootless, given that VMs only functioned when run rootless. - The podman unpause --all command will now only attempt to unpause containers that are paused, not all containers. - Init containers created with podman play kube now default to the once type (#14877). - Pods created with no shared namespaces will no longer create an infra container unless one is explicitly requested (#15048). - The podman create, podman run, and podman cp commands can now autocomplete paths in the image or container via the shell completion. - The libpod/common package has been removed as it's not used anywhere. - The --userns option to podman create and podman run is no longer accepted when an explicit UID or GID mapping is specified (#15233). * Bugfixes - Fixed a bug where bind-mounting /dev into a container which used the --init flag would cause the container to fail to start (#14251). - Fixed a bug where the podman image mount command would not pretty-print its output when multiple images were mounted. - Fixed a bug where the podman volume import command would print an unrelated error when attempting to import into a nonexistent volume (#14411). - Fixed a bug where the podman system reset command could race against other Podman commands (#9075). - Fixed a bug where privileged containers were not able to restart if the layout of host devices changed (#13899). - Fixed a bug where the podman cp command would overwrite directories with non-directories and vice versa. A new --overwrite flag to podman cp allows for retaining the old behavior if needed (#14420). - Fixed a bug where the podman machine ssh command would not preserve the exit code from the command run via ssh (#14401). - Fixed a bug where VMs created by podman machine would fail to start when created with more than 3072MB of RAM on Macs with M1 CPUs (#14303). - Fixed a bug where the podman machine init command would fail when run from C:\Windows\System32 on Windows systems (#14416). - Fixed a bug where the podman machine init --now did not respect proxy environment variables (#14640). - Fixed a bug where the podman machine init command would fail if there is no $HOME/.ssh dir (#14572). - Fixed a bug where the podman machine init command would add a connection even if creating the VM failed (#15154). - Fixed a bug where interrupting the podman machine start command could render the VM unable to start. - Fixed a bug where the podman machine list --format command would still print a heading. - Fixed a bug where the podman machine list command did not properly set the Starting field (#14738). - Fixed a bug where the podman machine start command could fail to start QEMU VMs when the machine name started with a number. - Fixed a bug where Podman Machine VMs with proxy variables could not be started more than once (#14636 and #14837). - Fixed a bug where containers created using the Podman API would, when the Podman API service was managed by systemd, be killed when the API service was stopped (BZ 2052697). - Fixed a bug where the podman -h command did not show help output. - Fixed a bug where the podman wait command (and the associated REST API endpoint) could return before a container had fully exited, breaking some tools like the Gitlab Runner. - Fixed a bug where healthchecks generated exec events, instead of health_status events (#13493). - Fixed a bug where the podman pod ps command could return an error when run at the same time as podman pod rm (#14736). - Fixed a bug where the podman systemd df command incorrectly calculated reclaimable storage for volumes (#13516). - Fixed a bug where an exported container checkpoint using a non-default OCI runtime could not be restored. - Fixed a bug where Podman, when used with a recent runc version, could not remove paused containers. - Fixed a bug where the remote Podman client's podman manifest rm command would remove images, not manifests (#14763). - Fixed a bug where Podman did not correctly parse wildcards for device major number in the podman run and podman create commands' --device-cgroup-rule option. - Fixed a bug where the podman play kube command on 32 bit systems where the total memory was calculated incorrectly (#14819). - Fixed a bug where the podman generate kube command could set ports and hostname incorrectly in generated YAML (#13030). - Fixed a bug where the podman system df --format "{{ json . }}" command would not output the Size and Reclaimable fields (#14769). - Fixed a bug where the remote Podman client's podman pull command would display duplicate progress output. - Fixed a bug where the podman system service command could leak memory when a client unexpectedly closed a connection when reading events or logs (#14879). - Fixed a bug where Podman containers could fail to run if the image did not contain an /etc/passwd file (#14966). - Fixed a bug where the remote Podman client's podman push command did not display progress information (#14971). - Fixed a bug where a lock ordering issue could cause podman pod rm to deadlock if it was run at the same time as a command that attempted to lock multiple containers at once (#14929). - Fixed a bug where the podman rm --force command would exit with a non-0 code if the container in question did not exist (#14612). - Fixed a bug where the podman container restore command would fail when attempting to restore a checkpoint for a container with the same name as an image (#15055). - Fixed a bug where the podman manifest push --rm command could remove image, instead of manifest lists (#15033). - Fixed a bug where the podman run --rm command could fail to remove the container if it failed to start (#15049). - Fixed a bug where the podman generate systemd --new command would create incorrect unit files when the container was created with the --sdnotify parameter (#15052). - Fixed a bug where the podman generate systemd --new command would fail when -h was used to create the container (#15124). * API - The Docker-compatible API now supports API version v1.41 (#14204). - Fixed a bug where containers created via the Libpod API had an incorrect umask set (#15036). - Fixed a bug where the remote parameter to the Libpod API's Build endpoint for Images was nonfunctional (#13831). - Fixed a bug where the Libpod List endpoint for Containers did not return the application/json content type header when there were no containers present (#14647). - Fixed a bug where the Compat Stats endpoint for Containers could return incorrect memory limits (#14676). - Fixed a bug where the Compat List and Inspect endpoints for Containers could return incorrect strings for container status. - Fixed a bug where the Compat Create endpoint for Containers did not properly handle disabling healthchecks (#14493). - Fixed a bug where the Compat Create endpoint for Networks did not support the mtu, name, mode, and parent options (#14482). - Fixed a bug where the Compat Create endpoint for Networks did not allow the creation of networks name bridge (#14983). - Fixed a bug where the Compat Inspect endpoint for Networks did not properly set netmasks in the SecondaryIPAddresses and SecondaryIPv6Addresses fields (#14674). - The Libpod Stats endpoint for Pods now supports streaming output via two new parameters, stream and delay (#14674). * Misc - Podman will now check for nameservers in /run/NetworkManager/no-stub-resolv.conf if the /etc/resolv.conf file only contains a localhost server. - The podman build command now supports caching with builds that specify --squash-all by allowing the --layers flag to be used at the same time. - Podman Machine support for QEMU installations at non-default paths has been improved. - The podman machine ssh command no longer prints spurious warnings every time it is run. - When accessing the WSL prompt on Windows, the rootless user will be preferred. - The podman info command now includes a field for information on supported authentication plugins for improved Docker compatibility. Authentication plugins are not presently supported by Podman, so this field is always empty. - The podman system prune command now no longer prints the Deleted Images header if no images were pruned. - The podman system service command now automatically creates and moves to a sub-cgroup when running in the root cgroup (#14573). - Updated Buildah to v1.27.0 (fixes CVE-2022-21698 / bsc#1196338) - Updated the containers/image library to v5.22.0 - Updated the containers/storage library to v1.42.0 (fixes bsc#1196751) - Updated the containers/common library to v0.49.1 - Podman will automatically create a sub-cgroup and move itself into it when it detects that it is running inside a container (#14884). - Fixed an incorrect release note about regexp. - A new MacOS installer (via pkginstaller) is now supported.- Fix build on Leap Use libexec macro to set correct, per-distribution specific, directory.- Update to version 4.1.1: * The output of the podman load command now mirrors that of docker load. * Podman now supports Docker Compose v2.2 and higher. Please note that it may be necessary to disable the use of Buildkit by setting the environment variable DOCKER_BUILDKIT=0. * A new container command has been added, podman container clone. This command makes a copy of an existing container, with the ability to change some settings (e.g. resource limits) while doing so. * Podman now supports sending JSON events related to machines to a Unix socket named machine_events.*\.sock in XDG_RUNTIME_DIR/podman or to a socket whose path is set in the PODMAN_MACHINE_EVENTS_SOCK environment variable. * Two new volume commands have been added, podman volume mount and podman volume unmount. These allow for Podman-managed named volumes to be mounted and accessed from outside containers. * The podman container checkpoint and podman container restore options now support checkpointing to and restoring from OCI images. This allows checkpoints to be distributed via standard image registries. * The podman play kube command now supports environment variables that are specified using the fieldRef and resourceFieldRef sources. * The podman play kube command will now set default resource limits when the provided YAML does not include them. * The podman play kube command now supports a new option, --annotation, to add annotations to created containers. * The podman play kube --build command now supports a new option, --context-dir, which allows the user to specify the context directory to use when building the Containerfile. * The podman container commit command now supports a new option, --squash, which squashes the generated image into a single layer. * The podman pod logs command now supports two new options, --names, which identifies which container generated a log message by name, instead of ID and --color, which colors messages based on what container generated them. * The podman rmi command now supports a new option, --ignore, which will ignore errors caused by missing images. * The podman network create command now features a new option, --ipam-driver, to specify details about how IP addresses are assigned to containers in the network. * The podman machine list command now features a new option, --quiet, to print only the names of configured VMs and no other information. * The --ipc option to the podman create, podman run, and podman pod create commands now supports three new modes: none, private, and shareable. The default IPC mode is now shareable, indicating the the IPC namespace can be shared with other containers. * The --mount option to the podman create and podman run commands can now set options for created named volumes via the volume-opt parameter. * The --mount option to the podman create and podman run commands now allows parameters to be passed in CSV format. * The --userns option to the podman create and podman run commands now supports a new option, nomap, that (only for rootless containers) does not map the UID of the user that started the container into the container, increasing security. * The podman import command now supports three new options, --arch, --os, and --variant, to specify what system the imported image was built for. * The podman inspect command now includes information on the network configuration of containers that joined a pre-configured network namespace with the --net ns: option to podman run, podman create, and podman pod create. * The podman run and podman create commands now support a new option, --chrootdirs, which specifies additional locations where container-specific files managed by Podman (e.g. /etc/hosts, `/etc/resolv.conf, etc) will be mounted inside the container (#12961). * The podman run and podman create commands now support a new option, --passwd-entry, allowing entries to be added to the container's /etc/passwd file. * The podman images --format command now accepts two new format directives: {{.CreatedAt}} and {{.CreatedSince}}. * The podman volume create command's -o option now accepts a new argument, o=noquota, to disable XFS quotas entirely and avoid potential issues when Podman is run on an XFS filesystem with existing quotas defined. * The podman info command now includes additional information on the machine Podman is running on, including disk utilization on the drive Podman is storing containers and images on, and CPU utilization. * Fix CVE-2022-27191 / bsc#1197284 - Drop obsolete patches: * 0001-Adjust-buildah-to-opencontainers-selinux-v1.10.1.patch * 0001-Relabel-relabel-links-instead-of-their-targets.patch * 0002-specgen-do-not-set-OOMScoreAdj-by-default.patch * 0004-fix-Container.cGroupPath-skip-empty-line-to-avoid-fa.patch- Backport upstream commit be5abf03ababc ("fix: Container.cGroupPath() skip empty line to avoid false error logging") for fixing "Error parsing cgroup: expected 3 fields but got 1" (see bsc#1199790, as it applies to Factory/Tumbleweed too) * 0004-fix-Container.cGroupPath-skip-empty-line-to-avoid-fa.patch- Require catatonit >= 0.1.7 for pause functionality needed by pods- Add patch to make buildah happy after selinux change: * 0001-Adjust-buildah-to-opencontainers-selinux-v1.10.1.patch- Add patch to fix starting containers on btrfs with SELinux (gh#opencontainers/selinux#172): * 0001-Relabel-relabel-links-instead-of-their-targets.patch - Add patch to fix starting containers as user service with systemd 250 (boo#1197672, gh#containers/podman#13731): * 0002-specgen-do-not-set-OOMScoreAdj-by-default.patch- Update to version 4.0.3: * Security - This release fixes CVE-2022-27649, where containers run by Podman would have excess inheritable capabilities set. * Changes - The podman machine rm --force command will now remove running machines as well (such machines are shut down first, then removed) (#13448). - When a podman machine VM is started that is using a too-old VM image, it will now start in a reduced functionality mode, and provide instructions on how to recreate it (previously, VMs were effectively unusable) (#13510). * Bugfixes - Fixed a bug where devices added to containers by the --device option to podman run and podman create would not be accessible within the container. - Fixed a bug where Podman would refuse to create containers when the working directory in the container was a symlink (#13346). - Fixed a bug where pods would be created with cgroups even if cgroups were disabled in containers.conf (#13411). - Fixed a bug where the podman play kube command would produce confusing errors if invalid YAML with duplicated container named was passed (#13332). - Fixed a bug where the podman machine rm command would not remove the Podman API socket on the host that was associated with the VM. - Fixed a bug where the remote Podman client was unable to properly resize the TTYs of containers on non-Linux OSes. - Fixed a bug where rootless Podman could hang indefinitely when starting containers on systems with IPv6 disabled (#13388). - Fixed a bug where the podman version command could sometimes print excess blank lines as part of its output. - Fixed a bug where the podman generate systemd command would sometimes generate systemd services with names beginning with a hyphen (#13272). - Fixed a bug where locally building the pause image could fail if the current directory contained a .dockerignore file (#13529). - Fixed a bug where root containers in VMs created by podman machine could not bind ports to specific IPs on the host (#13543). - Fixed a bug where the storage utilization percentages displayed by podman system df were incorrect (#13516). - Fixed a bug where the CPU utilization percentages displayed by podman stats were incorrect (#13597). - Fixed a bug where containers created with the --no-healthcheck option would still display healthcheck status in podman inspect (#13578). - Fixed a bug where the podman pod rm command could print a warning about a missing cgroup (#13382). - Fixed a bug where the podman exec command could sometimes print a timed out waiting for file error after the process in the container exited (#13227). - Fixed a bug where virtual machines created by podman machine were not tolerant of changes to the path to the qemu binary on the host (#13394). - Fixed a bug where the remote Podman client's podman build command did not properly handle the context directory if a Containerfile was manually specified using -f (#13293). - Fixed a bug where Podman would not properly detect the use of systemd as PID 1 in a container when the entrypoint was prefixed with /bin/sh -c (#13324). - Fixed a bug where rootless Podman could, on systems that do not use systemd as init, print a warning message about the rootless network namespace (#13703). - Fixed a bug where the default systemd unit file for podman system service did not delegate all cgroup controllers, resulting in podman info queries against the remote API returning incorrect cgroup controllers (#13710). - Fixed a bug where the slirp4netns port forwarder for rootless Podman would only publish the first port of a range (#13643). * API - Fixed a bug where the Compat Create API for containers did not properly handle permissions for tmpfs mounts (#13108). * Misc - The static binary for Linux is now built with CGo disabled to avoid panics due to a Golang bug (#13557). - Updated Buildah to v1.24.3 - Updated the containers/storage library to v1.38.3 - Updated the containers/image library to v5.19.2 - Updated the containers/common library to v0.47.5- Update to version 4.0.2: * Bump to v4.0.2 * Update release notes for v4.0.2 * Revert "use GetRuntimeDir() from c/common" * Revert "Option --url and --connection should imply --remote." * Option --url and --connection should imply --remote. * Bump to v4.0.2-dev * Bump to v4.0.1 * Update release notes for v4.0.1 * Fix a potential flake in volume plugins tests * Propagate $CONTAINERS_CONF to conmon * tests: Remove inaccurate comment * System tests: show one-line config overview * provide better error on invalid flag * use GetRuntimeDir() from c/common * kube: honor --build=false and make --build=true by default * system tests: cleanup networks on teardown * Remove the runtime lock * Don't log errors on removing volumes inuse, if container --volumes-from * kube: honor mount propagation mode * Load ip_tables modules at boot * Cirrus: Disable F34 aka prior-fedora testing * Cirrus: Update VM Images for 4.0 release * Bump to v4.0.1-dev * Bump to v4.0.0 * Release notes for v4.0.0 final * Fix lint * Fix manifest 4.0 Endpoints Branch forced 4.0 only endpoints * Introduce podman machine init --root=t|f and podman machine set --root=t|f * Initial implementation of mac forwarding using a privileged docker sock claim helper * ignition: propagate proxy settings from a host into a vm * Update to podman4 copr stream * Unify ls --filter docs for networks and pods * e2e: merge after/since image-filter tests * podman network: add documentation for netavark * create: Fix key=value annotation in the flag output * enable netavark specific tests * Fix checkpoint/restore pod tests * Make sure building with relative paths work correctly. * Add 409 response to swagger godoc * Fix images since/after tests * Changes of docker descriptions * Temporarily pull machine images from side repo * Cirrus: TODO: netavark/aardvark release branches * Cirrus: Expand netavark testing to include rootless * Cirrus: Minor - limit release task applicability * Cirrus: Add [CI:BUILD] magic that only builds * CI: fix nightly builds * Cirrus: Log netavark/aardvark binary build info. * Cirrus: Add netavark/aardvark system test task * Cirrus: Also download aardvark-dns binary * Cirrus: Add e2e task w/ upstream netavark * Revert minimum API change * netavark e2e tests * Bump to v4.0.0-dev * Bump to v4.0.0-RC5 * Update release notes for v4.0.0-RC5 * Modify /etc/resolv.conf when connecting/disconnecting * Do not set the network config dir to cni plugin dir * Show API doc for several versions * [NO NEW TEST NEEDED] Add schema for ImageCreate 200 response. * fix: Multiplication of durations * move rootless netns slirp4netns process to systemd user.slice * compat: endpoint /build must set header content type as application/json in reponse * Cleanup: remove obsolete/misleading bug workaround * tests: retrofit healthcheck system tests * healthcheck, libpod: Read healthcheck event output from os pipe * Fix: Do not print error when parsing journald log fails * Bump github.com/buger/goterm from 1.0.1 to 1.0.4 * append podman dns search domain * Podman pod create --share-parent vs --share=cgroup * System tests: revert emergency skip of checkpoint tests * Add version guard to libpod API endpoints * [v4.0] Bump c/common to v0.47.4 * idmap should be able to be specified along with other options * Vendor in containers/buildah v1.24.1 * Bump to v4.0.0-dev * Bump to v4.0.0-RC4 * Disable failing E2E test * Revert "Move each search dns to its own line" * Move each search dns to its own line * Update release notes for v4.0.0-RC4 * Document `schema` values in the `--url` flag * podman image scp syntax correction * system prune: remove all networks * Only change network fields if they were actually changed by the user * docs: clarify rootless net stats * Fix size to match Docker selection * libpod: enforce noexec,nosuid,nodev for /dev/shm * Clarify remote client means Mac and Windows * libpod: report slirp4netns network stats * Add notes to "--oom-kill-disable" not supported on cgroups V2 * Fix use of infra image to clarify default * Adapt podman images ls filters docs to be aligned with prune filters docs * ignition, machine: delegate cpu,io cgroup controllers to machine's default users * pkg/bindings/images.Build(): slashify "dockerfile" values, too * Remove mention of IPv6 portfwd from release notes * Bump to v4.0.0-dev * Bump to v4.0.0-RC3 * Update release notes for v4.0.0-RC3 * Fix Cirrus destination branch * volume: add support for non-volatile upperdir,workdir for overlay volumes * github: label issues based on os fix regex * github: label issues based on os * Cirrus: Fix get_ci_vm.sh initial setup * System tests: emergency skip of checkpoint tests * network create: allow multiple subnets * Update troubleshooting.md * Fix sort ordering of filters * Unify podman prune filter description: volumes, networks, system * Bump Buildah to v1.24.0 * rootless: drop permission check for devices * switch podman image scp from depending on machinectl to just os/exec * Bump github.com/containers/image/v5 from 5.18.0 to 5.19.0 * Bump github.com/containers/storage from 1.38.0 to 1.38.1 * change location of where make outputs podman binary on osx * Github workflow: Fix parsing of GraphQL response JSON * Github-workflow: Fix YAML syntax * Update godoc, swagger using wrong struct * Makefile: install targets independent of build * [CI:DOCS] Fix typos and improve language * CI: enable rootless-remote system tests * pkg/specgen/generate/security: fix error message * Github workflow: Send e-mail on job error * Github workflow: Update Cirrus-cron GraphQL query * remote build: set rootless oci isolation correctly * [CI:DOCS] Fix typos and improve language * Fix handling of duplicate matches on id expansion * Show correct default values or show none * exec: retry rm -rf on ENOTEMPTY and EBUSY * container create: do not check for network dns support * libpod: fix leaking fd * libpod: fix connection leak * [CI:DOCS] fix typo subpordinate * Fix filter description and unify filters docs for containers/images prune * Remove unused param and clean API handlers * Restore machine start logic that was hanging * Bump to v4.0.0-dev * Bump to v4.0.0-RC2 * Final release notes for v4.0.0-rc2 * Run codespell on code * Update release notes for Podman v4.0.0 * Fix #2 for compat commit handling of --changes * Fix nil pointer dereference for configmap optional * Make error message matching in 030-run.bats less fragile * Don't explicitly check for crun|runc in package information * Don't segfault if an image layer has no creation timestamp * compat: remove hardcoded index from load images output report * compat: images/load must be able to load tar with multiple images * System tests: fix for new systemd on rawhide * Remove rootless_networking option from containers.conf * vendor c/psgo@v1.7.2 (fixes CVE-2022-1227 / bsc#1182428) * Engine.Remote from containers.conf * vendor: bump c/common and other vendors * rootless: report correctly the error * Implement API forwarding for podman machine on Windows * Implement env parsing on Windows * Handle changes in docker compat mode * Show package version when running on alpine * Handlers for `generate systemd` with custom dependencies * APIv2 tests: followup to recent log test * Add IndexConfigs to compat /info endpoint * Bump github.com/opencontainers/runc from 1.0.3 to 1.1.0 * apiv2 test: add regression test for #12904 * SECURITY.md: fix the project name * rename --cni-config-dir to --network-config-dir * compat attach: fix write on closed channel * upgrade all dependencies * Revert "Cirrus: Temporarily disable OSX Cross task" * Bump github.com/opencontainers/runc from 1.0.3 to 1.1.0 * bump go module to version 4 * [NO NEW TESTS NEEDED] add builddeps to copr template * CI: rootless user: also create in some root tests * [WIP] Tests for podman image scp (the sudo form) * Revamp Libpod state strings for Docker compat * Cirrus: Temporarily disable OSX Cross task * update c/common to latest * Use PODMAN_USERNS environment variable when running as a service * Unify the method of parsing filters in cmd * fix default branch links * [CI:DOCS] fix default branch links * [CI:DOCS] Unprivileged native overlayfs is now supported * [CI:DOCS] Fix typo in --env * Recursively copy cert files. * Refactor manifest list operations * Add rpkg template for COPR autobuild * Fix cgroup mode handling in api server * Standardize on capatalized Cgroups * test/system: podman run update /etc/hosts * Remove two GetImages functions from API * Use fully-qualified device name in CDI test * Use new CDI API * troubleshooting links to main branch * Podman Build use absolute filepath * Prohibit --uid/gid map and --pod for container create/run * podman container rm: remove pod * Manual fixes for PR #12642: * podman build enable --all-platforms and --unsetenv * use events_logfile_path from containers.conf for events log. * Podman Pod Create --sysctl support * Wait for podman stop to complete * libpod: fix check for systemd session * libpod: refine check for empty pod cgroup * fix buildah-bud test diff * upgrade test: check that network backend is cni * use netns package from c/common * update buildah to latest and use new network stack * podman image scp: implement --quiet * use libnetwork from c/common * Add --noout option to prevent the output of ids * remote events: convert TimeNano properly * Bump github.com/BurntSushi/toml from 0.4.1 to 1.0.0 * vendor latest c/common * add additional fields to podman machine ls --json * buildah bud tests: skip failing tests * Fix permission on secrets directory * Add podman rm --depend * fix host.containers.internal entry for macvlan networks * It takes some time to start a VM * Pretty Print output of podman machine ls --format json * Use the InfraImage defined in containers.conf * Cirrus: Freshen VM images * Revert "Cirrus: Temp. ignore gitlab task failures" * pkg: use PROXY_VARS from c/common * ignition: add support from setting SSL_CERT_FILE * ignition: propogate HTTP proxy variables from host to remote * System tests: fix RHEL8 gating tests * vendor c/common * Remove dead RuntimeOption functions * Update docker cli message for case where user creates directory * Don't add env if optional and not found * Fix type-o in podman.wxs * [CI:DOCS] fixes indentation of example pod yaml * Prevent double decoding of storage options * Emergency system-test fixes * add OCI Runtime name to errors * fix healthcheck timeouts and ut8 coercion * Don't rename pod if container has the same name * Set volume NeedsCopyUp to false iff data was copied up * Fix CI * correct typo words in docs * Change Tests to ignore missing containers when removing --all * test/e2e/pod_initcontainers: fix a flake * test/e2e/run: don't use date +%N on Alpine * Support all volume mounts for rootless containers * Fix wrong 'podman search --format' placeholder * Fix Container List API call to return mount info * fix misleading comment regarding default value of cpu period [NO NEW TESTS NEEDED] * add --ip6 flag to podman create/run * legacy events: also set exitCode * Don't initialize the global RNG with GinkgoRandomSeed() in e2e tests * Avoid collisions on RemoteSocket paths * Refactor remote socket path determination in tests * fix doc * test/system: podman run image with filesystem permission * test/system: podman run with log-opt option * Update swagger documentation * Make it possible to select the volume driver * Check the mount type for future compatibility * Implement virtfs volumes for podman machine * [CI:DOCS] Add example of cpus to init command * prefix imageId with sha256: in containers list test for compat API ImageId * Pod Security Option support * ignition: add certs from current user into the machine while init * docs: sort swagger operations alpabetically * .service file removal on failure * Introduce Windows WSL implementation of podman machine * podman image scp never enter podman user NS * Allow users to add host user accounts to /etc/passwd * container creation: don't apply reserved annotations from image * [CI:DOCS] clarify `io.podman.annotations.seccomp` * Error out early if system does not support pre-copy checkpointing * Update go-criu to v5.3.0 * [CI:DOCS] docs: document rootless userns mappings * Switch to a new installer approach using a path manipulation helper * e2e: Add dev/shm checkpoint/restore test * Enable checkpoint/restore for /dev/shm * Update github.com/checkpoint-restore/checkpointctl * Always run passwd management code when DB value is nil * Warn on use of --kernel-memory * support hosts without /etc/hosts * Podman run --passwd * ci: force scratch build for crun * Use hosts public ip address in rootless containers * compat: image normalization: handle sha256 prefix * specgen: honor userns=auto from containers.conf * [CI:DOCS] Small checkpoint/restore man page fixes * [CI:DOCS] Explicitly mention that checkpointing systemd containers might fail * vendor: update containers/storage * build: fix test for subid 4 * test: add --rm to podman run commands * fix(generate): fix up podman generate kube missing env field bug * legacy events: also set Action="die" * rootless: include the args in the debug message * apiv2 tests: use quay.io/libpod/testimage:20210610 for platform tests * image rm: allow for force-remove infra images * tests: adjust old build test to expect exit code * Test for checkpoint specific inspect fields * Add more checkpoint/restore information to 'inspect' * build: relay exitcode from imagebuildah to registry * Removed .service file for healthchecks * Set machine timezone * MovePauseProcessToScope do not seed everytime * bindings rmi test: clarify behavior * bump cobra to 1.3.0 * .github: revert to the old template * oci: configure the devices cgroup with default devices * kill: fix output * e2e: search flake: skip test on registry.redhat.io * APIv2 tests: fail on syntax/logic errors * Show --external containers even without --all option * apiv2 tests: refactor complicated curls * fix network id handling * Update Windows Install Doc * Fixes #12063 Add docker compatible output after image build. * pause scope: don't use the global math/rand RNG * specgen: check that networks are only set with bridge * container restore/import: store networks from db * play kube add support for multiple networks * support advanced network configuration via cli * Add new networks format to spegecen * fix incorrect swagger doc for network dis/connect * network connect allow ip, ipv6 and mac address * network db: add new strucutre to container create * remove unneeded return value from c.Networks() * network db rewrite: migrate existing settings * network ls: show networks in deterministic order * Bump github.com/docker/docker * pprof flakes: bump timeout to 20 seconds * Add secret list --filter to cli * Cirrus: Temp. ignore gitlab task failures * compat build: adhere to q/quiet * Make XRegistryAuthHeader and XRegistryConfigHeader private * Remove the authfile parameter of MakeXRegistryAuthHeader * Simplify the header decision in pkg/bindings/images.Build a bit * Remove the authfile parameter of MakeXRegistryConfigHeader * Remove no-longer-useful name variables * Consolidate creation of SystemContext with auth.json into a helper * Remove pkg/auth.Header * Call MakeXRegistryAuthHeader instead of Header(..., XRegistryAuthHeader) * Turn headerAuth into MakeXRegistryAuthHeader * Call MakeXRegistryConfigHeader instead of Header(..., XRegistryConfigHeader) * Turn headerConfig into MakeXRegistryConfigHeader * Move the auth file creation to GetCredentials * Consolidate the error handling path in GetCredentials * Only look up HTTP header values once in GetCredentials * Use Header.Values in GetCredentials.has * Beautify GetCredentials.has a bit * Pass a header value directly to parseSingleAuthHeader and parseMultiAuthHeader * Simplify parseSingleAuthHeader * Simplify the interface of parseSingleAuthHeader * Don't return a header name from auth.GetCredentials * Fix normalizeAuthFileKey to use the correct semantics * Rename normalize and a few variables * Add TestHeaderGetCredentialsRoundtrip * Add tests for auth.Header * Improve TestAuthConfigsToAuthFile * Add unit tests for singleAuthHeader * Add unit tests for multiAuthHeader * fix e2e test missing network cleanup * pprof CI flakes: enforce 5 seconds grace period * [NO NEW TESTS NEEDED] rootless: declare TEMP_FAILURE_RETRY before usage (Fixes: #12563) * --hostname should be set when using --pod new:foobar * Cirrus: Use cached swagger binary * inotify: make sure to remove files * System tests: remove rm_pause_image() * specgen: honor empty args for entrypoint * generate systemd: support entrypoint JSON strings * Bump github.com/uber/jaeger-client-go * remove runlabel test for global opts * utils: reintroduce moveToCgroup * autocopr: distro conditionals for containers-common * vendor c/image/v5@main * Update vendor or containers/common moving pkg/cgroups there * volume: apply exact permission of target directory without adding extra 0111 * Cirrus: Remove remnants of nix-based static build * Refactor podman pods to report.Formatter * rootless netns: resolve all path components for resolv.conf * tests: clean up FIXMEs and noise * fix remote run/start flake * e2e: fix pprof flakes * Bump github.com/opencontainers/runc from 1.0.2 to 1.0.3 * vendor c/common@main * Escape trailing slash in install directory location so the closing quote is not escaped * centos 9 stream cannot use %autochangelog * Refactor podman system to report.Formatter [NO NEW TESTS NEEDED] * add spec file for automated copr builds * Add restart-sec option to systemd generate * Fix documentation of (podman image save --compress --uncompressed) * Improve documentation of (podman image save --format) * Add support for configmap volumes to play kube * cmd, push: use the configured compression format * [CI:DOCS] logformatter: fix corner case with links * UPdate vendor of image-spec and containers/storage * vendor: update containers/common * Update doc to explictly mention using ed25519 in ssh keys * Refactor podman image command output * Manual fixes * Same thing, with BeNumerically("==", x) * Use HaveLen(x) instead of Expect(len(y)).To(Equal(x)) * Same thing, for BeNumerically("==", 0) * Use BeEmpty() instead of len(x).To(Equal(0)) * Same as previous, for assertions other than Equal() * e2e tests: a little more minor cleanup * compat API: push: report size of manifest * compat: images/json * Add ashley-cui, lsm5 and floutoc to owners * remove ARTIFACT_DIR and ArtifactPath * Image caches: allow overriding cache dir * Rename CrioRoot as just Root * Fix possible rootless netns cleanup race * [NO NEW TESTS NEEDED] Refactor podman container command output * Hostname in `spec.hostname` should be passed to infra ctr init opt * container, cgroup: detect pid termination * top: parse ps(1) args correctly * podman, push: expose --compression-format * e2e: yet more cleanup of BeTrue/BeFalse * Ensure the generated NodePort values are unique * Allow containerPortsToServicePorts to fail * Don't use the global math/rand RNG for service ports * Move a comment to the relevant place * a few more manual BeTrue cleanups * Convert strings.Contains() to Expect(ContainSubstring) * e2e tests: more cleanup of BeTrue()s * Implement 'podman run --blkio-weight-device' * systemd: replace multi-user with default.target * compat API: allow enforcing short-names resolution to Docker Hub * Fixed the containerfile not found during remote build. * podman-remote: prevent leaking secret into image * podman-remote: copy secret to contextdir is absolute path on host * api: allow build api to accept secrets * Only open save output file with WRONLY * List /etc/containers/certs.d as default for --cert-path * e2e tests: enable golint * fix: parsing of HostConfig.Mounts for container create * Move the chown to after the ADDs * fix: error reporting for archive endpoint * Bindings test: emit GIT_COMMIT, for links in logs * checkpoint do not modify XDG_RUNTIME_DIR * libpod: improve heuristic to detect cgroup * libpod, inspect: export cgroup path * stats: get the memory limit from the spec * compat: Add compatiblity with Docker/Moby API for scenarios where build fails * libpod: leave thread locked on errors * Find and fix empty Expect()s * Unset SocketLabel after system finishes checkpointing * Remove StringInSlice(), part 2 * Remove StringInSlice(), part 1 * e2e test cleanup, continued * Update basic_networking.md * Warn on failing to update container status * oci: ack crun output when container is not there * oci: exit gracefully if container is already dead * Support env variables based on ConfigMaps sent in payload * image lookup: do not match *any* tags * generate systemd: add --start-timeout flag * Oops! Manual edits to broken tests * e2e tests: clean up antihelpful BeTrue()s * Cirrus: Strip out static nix build * Rename pod on generate of container * [CI:DOCS] Update notes on java TZ in man page * Bump github.com/containers/image/v5 from 5.16.1 to 5.17.0 * Fix netavark error handling and teardown issue * swagger: add layers to build api docs * compat: add layer caching compatiblity for non podman clients * Bump github.com/opencontainers/selinux from 1.9.1 to 1.10.0 * Add note about volume with unprivileged container * Add EXPOSE e2e test * Support EXPOSE with port ranges * compat: Add subnet mask behind IP address to match Docker API * [CI:DOCS] Add java TZ note to run manpage * Bump github.com/rootless-containers/rootlesskit from 0.14.5 to 0.14.6 * podman-remote does not support signature-policy * Add tests for restore runtime verification * Use same runtime to restore a container as during checkpointing * Force iptables driver for netavark tests * Make sure netavark output is logged to the syslog * filter: use filepath.Match to maintain consistency with other pattern matching in podman * Semiperiodic cleanup of obsolete Skip()s * [CI:DOCS]upload a translation file * api/handlers: Add checkpoint/restore FileLocks * test: Update error string for --file-locks test * fix duplicated logs command * Bump github.com/docker/docker * Bump k8s.io/api from 0.22.3 to 0.22.4 * Do not store the exit command in container config * Add test for checkpoint/restore with --file-locks * Add --file-locks checkpoint/restore option * Cirrus: Bump Fedora to release 35 * Cirrus: Partially revert catatonit --force install * Revert "Cirrus: Temp. disable prior-fedora testing" * Cirrus: Workaround log_driver=journald setting * Cirrus: Fix bindings test hang b/c logging config mismatch * Cirrus: Timeout bindings test after 30m * Cirrus: Log more things in bindings and unit tests * Minor Makefile fix * rootless netns, one netns per libpod tmp dir * Introduce Address type to be used in secondary IPv4 and IPv6 inspect data structure. * volumes: add new option idmap * remote checkpoint/restore: more fixes * fix CI * fix: take absolute path for dd on apple silicon * System tests: new checkpoint tests * rootless: use catatonit to maintain user+mnt namespace * rootless: drop strerror(errno) calls * rootless: reuse existing open_namespace function * rootless: use auto cleanup functions * utils: use podman-pause-$RANDOM.scope name * hack/bats: deal with new bin helpers * Change error message for compatibility with docker * rename libpod nettypes fields * podman machine start wait for ssh * fix remote checkpoint/restore * Add --unsetenv & --unsetenv-all to remove def environment variables * Set config environment variables early in Podman init * journald logs: keep reading until the journal's end * secret: honor custom target for secrets with run * bindings: reuse context for API requests * podman machine improve port forwarding * Network test: fix podman-remote-rootless corner case * filter: add basic pattern matching for label keys * cirrus: force-install catatonit * infra container: replace pause with catatonit * Revert "add kubernetes pause" * Added test for checkpoint/restore --print-stats * Update man pages for checkpoint/restore --print-stats * Added optional container restore statistics * Added optional container checkpointing statistics * Error logs --follow if events-backend != journald, event-logger=journald * Enable 'podman run --memory-swappiness=0' * Fix network mode in play kube * Always create working directory when using compat API * play kube: don't force-pull infra image * Podman Image SCP transfer patch * --authfile command line argument for image sign command. * Cirrus: Temp. disable prior-fedora testing * Cirrus: Update to Ubuntu 21.10 * Add failing run test for netavark * Add flag to overwrite network backend from config * libpod: create /etc/mtab safely * Add network backend to podman info * Add more netavark tests * select network backend based on config * Fix RUST_LOG envar for netavark * netavark IPAM assignment * netavark network interface * Make networking code reusable * Fix flake in upgrade tests * export adding id-specifier code to setContainerNameForTemplate * VOLUME must be declared after RUN chown command * network reload return error if we cannot reload ports * network reload without ports should not reload ports * Print headers for system connection ls * [CI:DOCS] Add CI check for SEE ALSO in man pages * podman load: support downloading files * Add links to all SEE ALSO sections * pod create: read infra image from containers.conf * rootless: adjust error message * Fix rootless networking with userns and ports * support health checks from image configs * change from run to create in 250-systemd.bats * Exclude already built sources for static build * shm_lock: Handle ENOSPC better in AllocateSemaphore * Fix Zsh completion command documentation * Match .c files in Makefile * Add Static Build download instructions to README * Add links to podman build,run, create see also * Minor test tweaks * pod create: read network mode from config * Bump Catatonit up to v0.1.7 * test connection add * system: Adds support for removing all named destination via --all * pod/container create: resolve conflicts of generated names * podman-generate-kube - remove empty structs from YAML * Add some information about disabling SELinux when using system volumes * Fix swagger definition for the new mac address type * Log Apache access_log-like entries at Info level [NO NEW TESTS NEEDED] * Test to check for presence of 'stats-dump' in exported checkpoints * Add 'stats-dump' file to exported checkpoint * Podman Image SCP rootful to rootless transfer * rename rootless cni ns to rootless netns * mount full XDG_RUNTIME_DIR in rootless cni ns * Bump github.com/checkpoint-restore/go-criu/v5 from 5.1.0 to 5.2.0 * Keep error semantics intact * Fix rootless cni netns cleanup logic * tweak a couple of flag descriptions in help output * Update swagger doc make filed optional * Fix bindings container log test * test: run --cgroups=split in new cgroup * MAC address json unmarshal should allow strings * Make stop message more similar to start * Implement top streaming for containers and pods * Handle HTTP 409 error messages properly for Pod actions * Add tests * Fix swagger definitions * More conforming libpod API and swagger types * More conforming libpod API and swagger types * Better emptiness test for custom JSON serializer * System tests: enhance volume test, add debug prints * add unit test to containers_test * Use correct swagger type in doc-comment * Cirrus: Authorize rootless user self-ssh * Fix libpod API conformance to swagger * Fix help message case for `podman version` * Fix pause usage example * Use systemctl in local system test * Allow label and labels when creating volumes * volumes: be more tolerant and fix infinite loop * Add information on how podman machine is updated * volumes: allow more options for devpts * volumes: do not pass mount opt as formatter string * Bump k8s.io/api from 0.22.2 to 0.22.3 * runtime: change PID existence check * oci: rename sub-cgroup to runtime instead of supervisor * libpod: deduplicate ports in db * Set flags to test 'logs -f' with journald driver * Set Checkpointed state to false after restore * container create: fix --tls-verify parsing * runtime: check for pause pid existence * utils: do not overwrite the err variable * Fix systemd PID1 test * Record the image stream along with the path * cgroups: use SessionBusPrivateNoAutoStartup * vendor: update godbus to v5.0.6 * Slirp4netns with ipv6 set net.ipv6.conf.default.accept_dad=0 * Fix a few problems in 'podman logs --tail' with journald driver * Allow 'container restore' with '--ipc host' * Document to not set K8S envars for CNI * Bump github.com/docker/docker * pod create: remove need for pause image * add kubernetes pause * cirrus: containers: mount directory in /var/tmp to /tmp * overlay root fs: create mount on runtime dir * Update vendor github.com/opencontainers/runtime-tools * If Dockerfile exists in same directory as service, we should not use it. * Fix tests of podman image trust --raw and --json * Tighten the expected output of the "podman image trust show" test * Use INTEGRATION_ROOT instead of current directory * Add support to play kube for --log-opt * [NO NEW TESTS NEEDED] Fix off-by-one index comparision (reported by LGTM) * Fix some typos in documentation and comments (found by codespell) * Replace 'an user' => 'a user' * [CI:DOCS] Fix typo keep_id -> keep-id * Set DOCKER_HOST in the VM * fuse-overlay probably means fuse-overlayfs. * Support template unit files in podman generate systemd * Remove --kernel-memory options * tag: Support tagging manifest list instead of resolving to images * Remove infra ID from DB before removing containers * System tests: confirm that -a and -l clash * systemd: compatible with rootless mode * system tests: CONTAINER_* and --help: cleanup * podman run --memory=0 ... should not set memory limit * Add information on how to discover default log driver * Add test for system connection * Generate Kube should not print default structs * libpod: change mountpoint ownership c.Root when using overlay on top of external rootfs * Change podman connection list to use default field * Allow API to specify size and inode quota * Use exponential backoff when waiting for a journal entry * Pod Rm Infra Improvements * system tests: socket activation: clean up * rootfs-overlay: fix overlaybase path for cleanups * Move CONTAINER_HOST and _CONNECTION to IsRemote Function * We should only be relabeling when on first run * If CONTAINER_HOST env variable is set default podman --remote=true * Set targetPort to the port value in the kube yaml * Do not add TCP to protocol in generated kube yaml * Use CGO_ENABLED=1 when building natively on darwin * Test-hang fix: Wait for ready + timeout on connect. * Checkpoint/Restore test fixes * Don't include ctr.log if not using file logging * Don't use docker/pkg/archive, use containers/storage/pkg/archive * Fix codespell errors * Adjust tests to verify all subcommands show the help message * Fix panic in container create compat api * Don't add image entrypoint to the generate kube yaml * Display help text on empty subcommand by default * podman search: display only name and description by default * codespell code * Add information about .containerignore to podman build man page * CNI: fix network create --ip-range * Kube Gen run as user/group issues * rootlessport: reduce memory usage of the process * No space in kube annotations for bind mounts * Fix CI flake on time of shutdown for API service * Refactor podman search to be more code friendly * Unit files: Use actual installed path for podman * Bump github.com/onsi/ginkgo from 1.16.4 to 1.16.5 * cgroups: use cgroup.controllers to read controllers * builder: Add support for builder prune * Remove a volume with --force if container is running * Use SplitN(2) when copying env variables * podman stats: move cgroup validation to server * fix test * Support readonly rootfs contains colon * [CI:DOCS] oci-hooks.5.md: fixup section in header * Enable /debug/pprof API service endpoints * Not all fields in machine list were set properly * faster image inspection * Warn if podman stop timeout expires that sigkill was sent * [CI:DOCS] introduce --replace flag for play kube * [CI:DOCS] Include manifest example usage * Change podman.1 man page to show corret log-level default * Bump github.com/opencontainers/selinux from 1.8.5 to 1.9.1 * Fixes #11668 * libpod: fix race when closing STDIN * Ensure `podman ps --sync` functions * Allow `podman stop` to be run on Stopping containers * Bump github.com/containers/image/v5 from 5.16.0 to 5.16.1 * Bump github.com/docker/docker * It really should be no **NEW** tests needed * README.md: Point to Podman's channels * Add podman-plugins to upstream image * CNI networks: reload networks if needed * bump c/common to latest and c/storage to 1.37.0 * Add --time out for podman * rm -f commands * Cirrus: Fix defunct package metadata breaking cache * Pod Events Logging Fix * [NO TESTS NEEDED] Ignore removed containers * Pod Volumes From Support * Add note about empty fields and null values for API responses * Bump github.com/containers/buildah from 1.23.0 to 1.23.1 * Add podman play kube --no-hosts options * Gating tests: fix permissions error * pkg/specgen: cache image in generator * cirrus: gitlab: download packages * Add guard for BuildOptions.CommonBuildOpts * System tests: tighten 'is' operator * Update README and release notes for v3.4.0 * sdnotify test: accept MAINPID anywhere * machine: silently cleanup dangling sockets before rm if possible * Add expose type map[uint16]string to description * [NO TESTS NEEDED] Fix typo in storage.conf file exists message * Support selinux options with bind mounts play/gen * kube: fix conversion from milliCPU to period/quota * Bump github.com/mattn/go-isatty from 0.0.12 to 0.0.14 * test: use new helper * test: skip test on rootless cgroupsv1 * machine: Info on successfully stopping qemu machine * Allow a value of -1 to set unlimited pids limit * Vendor in latest containers/storage * Storage can remove ErrNotAContainer as well * libpod: container create: init variable: do not deep copy spec * libpod: add GetConfigNoCopy() * libpod: add execSessionNoCopy * libpod: do not call (*container).Spec() * Pod Device-Read-BPS support * Remind user to check connection or use podman machine * Ensure pod ID bucket is properly updated on rename * Fix contributor make targets on Ubuntu and Debian * Implement PR template to assist review & release * libpod: do not call (*container).Config() * [NO TESTS NEEDED] Add port configuration to first regular container * [CI:DOCS] cmd/podman: no dot for short descriptions * move network alias validation to container create * set --cni-config-dir for exit command * always add short container id as net alias * image prune: support removing external containers * System tests: speed up. They've gotten too slow. * Add dockerfile.5 as man link to containerfile man page * Set MSI to be 64-bit only. * fix podman network prune integration test flakes * Cirrus: Add gitlab podman runner test * CNI: network remove do not error for ENOENT * remote build: EvalSymlinks() the context directory * stop: Do nothing if container was never created in runtime * logging: new mode -l passthrough * Allow machine options to be set from containers.conf * Vendor in containers/common v0.46.0 * podman machine: do not join userns * Disable docker and alias to podman in FCOS ignition * added healthcheck to ps command * Fix english on prune prompt * Document missing /images/search query parameters * rootful: do not set XDG_RUNTIME_DIR for cni plugins * Revert "rootful: unset XDG_RUNTIME_DIR" * Add completion for machine list format * Set context dir for play kube build * Makefile: use -ldflags/-gccgoflags depending on the go implemenatiton * Update docs for --platform in podman-build.1 * shell completion: do not show images without tag * podman inspect add State.Health field for docker compat * podman save: enforce signature removal * Add JSON version of the machine list * Add support for :U flag with --mount option * [CI:DOCS] Add link to running ctrimage on enablesysadm * Ignore mount errors except ErrContainerUnknown when cleaningup container * standardize logrus messages to upper case * podman generate kube should not include images command * Fix machine image * sync container state before reading the healthcheck * Also show the (initial) disk size * Show cpus and memory in machine list * Eighty-six eighty-eighty * net types: remove omitempty from required fields * podman save: add `--uncompressed` * Bump CNI to v1.0.1 * vendor c/psgo@v1.7.1 * [CI:DOCS] Add network alias note in man pages * Add a backoff and retries to retrieving exited event * Cross-build release-archives w/ arch in filename * Fix Error, empty output for info: 'VERSION' * Generate kube should'd add podman default environment vars * volume: Add support for overlay on named volumes * Pod Device Support * Support --format tables in ps output * Remove references to kube being development * Add support for retrieving system service --timeout * Add podman image/container inspect man pages * [CI:DOCS] Add link to skopeo delete in podman rmi * vendor c/common@main * remote untag: support digests * Created MapOptions for PodCreate * Bump k8s.io/api from 0.22.1 to 0.22.2 * compat API: /images/json prefix image id with sha256 * podman machine: use gvproxy for host.containers.internal * utils: return error message from StartTransientUnit * utils: raise warning only on cgroupv2 * Add podman machine init --now option * System tests: cleanup, and remove obsolete skips * Add username flag for machine ssh * Remove unused code from libpod * [CI:DOCS] markdown cleanup * Fix up build the docs site * Use a new markdown converter for sphinx * runtime: move pause process to scope * system: move MovePauseProcessToScope to utils * system: always move pause process when running on systemd * system: avoid reading pause pid file * Only add 127.0.0.1 entry to /etc/hosts with --net=none * Add no-trunc support to podman-events * CNI: add ipvlan driver * CNI: network create support macvlan modes * Do not allow network modes to be used as network names * fix inverted condition * Fix /auth compat endpoint * Add Drivers method to the Network Interface * CI: load ipv6 kernel modules for rootless tests * Drop OCICNI dependency * Wire network interface into libpod * cni network configs set ipv6 enables correctly * default network: do not validate the used subnets * network create: validate the input subnet * Set default storage from containers.conf for temporary images * container runlabel remove image tag from name * build.bats: fix copy tests after containers/buildah#3486 * build: mirror --authfile to filesystem if pointing to FD instead of file * Fix example in podman machine init man page * vendor: Bump github.com/containers/buildah from 1.22.3 to 1.23.0 * api: handle nil pointer dereference in rest endpoints * build: take advantage of --platform lists * Document `all` query parameter for /libpod/images/prune * Show variant and codename of the distribution * Use new aarch64 fcos repos * Enhance bindings for IDE hints * Pod Volumes Support * test: enable --cgroup-parent test * libpod: honor --cgroups=split also with pods * tests: enable --cgroups=disabled test for rootless * tests: simplify --cgroups=disabled test * libpod: rootful close binded ports * Search gvproxy with config.FindHelperBinary() * rootfs: Add support for rootfs-overlay and bump to buildah v1.22.1-0.202108 * fix restart always with rootlessport * Cirrus: NM/CNI workaround + Remove prior-Ubuntu * If container exits with 125 podman should exit with 125 * Bump github.com/json-iterator/go from 1.1.11 to 1.1.12 * bump c/common to v0.44.0 * remove rootlessport socket to prevent EADDRINUSE * Add deprecated fields for 1.22+ clients that still expect them * Use default username for podman machine ssh- Add: Provides: podman:/usr/bin/podman-remote subpackage for a clearer upgrade path from podman < 3.1.2- Update to version 3.4.4: * Bugfixes - Fixed a bug where the podman exec command would, under some circumstances, print a warning message about failing to move conmon to the appropriate cgroup (#12535). - Fixed a bug where named volumes created as part of container creation (e.g. podman run --volume avolume:/a/mountpoint or similar) would be mounted with incorrect permissions (#12523). - Fixed a bug where the podman-remote create and podman-remote run commands did not properly handle the --entrypoint="" option (to clear the container's entrypoint) (#12521).- Update to version 3.4.3: * Security - This release addresses CVE-2021-4024 / bsc#1193166, where the podman machine command opened the gvproxy API (used to forward ports to podman machine VMs) to the public internet on port 7777. - This release addresses CVE-2021-41190 / bsc#1193273, where incomplete specification of behavior regarding image manifests could lead to inconsistent decoding on different clients. * Features - The --secret type=mount option to podman create and podman run supports a new option, target=, which specifies where in the container the secret will be mounted (#12287). * Bugfixes - Fixed a bug where rootless Podman would occasionally print warning messages about failing to move the pause process to a new cgroup (#12065). - Fixed a bug where the podman run and podman create commands would, when pulling images, still require TLS even with registries set to Insecure via config file (#11933). - Fixed a bug where the podman generate systemd command generated units that depended on multi-user.target, which has been removed from some distributions (#12438). - Fixed a bug where Podman could not run containers with images that had /etc/ as a symlink (#12189). - Fixed a bug where the podman logs -f command would, when using the journald logs backend, exit immediately if the container had previously been restarted (#12263). - Fixed a bug where, in containers on VMs created by podman machine, the host.containers.internal name pointed to the VM, not the host system (#11642). - Fixed a bug where containers and pods created by the podman play kube command in VMs managed by podman machine would not automatically forward ports from the host machine (#12248). - Fixed a bug where podman machine init would fail on OS X when GNU Coreutils was installed (#12329). - Fixed a bug where podman machine start would exit before SSH on the started VM was accepting connections (#11532). - Fixed a bug where the podman run command with signal proxying (--sig-proxy) enabled could print an error if it attempted to send a signal to a container that had just exited (#8086). - Fixed a bug where the podman stats command would not return correct information for containers running Systemd as PID1 (#12400). - Fixed a bug where the podman image save command would fail on OS X when writing the image to STDOUT (#12402). - Fixed a bug where the podman ps command did not properly handle PS arguments which contained whitespace (#12452). - Fixed a bug where the podman-remote wait command could fail to detect that the container exited and return an error under some circumstances (#12457). - Fixed a bug where the Windows MSI installer for podman-remote would break the PATH environment variable by adding an extra " (#11416). * API - Updated the containers/image library to v5.17.0 - The Libpod Play Kube endpoint now also accepts ConfigMap YAML as part of its payload, and will use provided any ConfigMap to configure provided pods and services. - Fixed a bug where the Compat Create endpoint for Containers would not always create the container's working directory if it did not exist (#11842). - Fixed a bug where the Compat Create endpoint for Containers returned an incorrect error message with 404 errors when the requested image was not found (#12315). - Fixed a bug where the Compat Create endpoint for Containers did not properly handle the HostConfig.Mounts field (#12419). - Fixed a bug where the Compat Archive endpoint for Containers did not properly report errors when the operation failed (#12420). - Fixed a bug where the Compat Build endpoint for Images ignored the layers query parameter (for caching intermediate layers from the build) (#12378). - Fixed a bug where the Compat Build endpoint for Images did not report errors in a manner compatible with Docker (#12392). - Fixed a bug where the Compat Build endpoint for Images would fail to build if the context directory was a symlink (#12409). - Fixed a bug where the Compat List endpoint for Images included manifest lists (and not just images) in returned results (#12453). * Misc - Podman now builds by default with cgo enabled on OS X, resolving some issues with SSH (#10737).- Update to version 3.4.2: * Fixed a bug where podman tag could not tag manifest lists (#12046). * Fixed a bug where built-in volumes specified by images would not be created correctly under some circumstances. * Fixed a bug where, when using Podman Machine on OS X, containers in pods did not have working port forwarding from the host (#12207). * Fixed a bug where the podman network reload command command on containers using the slirp4netns network mode and the rootlessport port forwarding driver would make an unnecessary attempt to restart rootlessport on containers that did not forward ports. * Fixed a bug where the podman generate kube command would generate YAML including some unnecessary (set to default) fields (e.g. empty SELinux and DNS configuration blocks, and the privileged flag when set to false) (#11995). * Fixed a bug where the podman pod rm command could, if interrupted at the right moment, leave a reference to an already-removed infra container behind (#12034). * Fixed a bug where the podman pod rm command would not remove pods with more than one container if all containers save for the infra container were stopped unless --force was specified (#11713). * Fixed a bug where the --memory flag to podman run and podman create did not accept a limit of 0 (which should specify unlimited memory) (#12002). * Fixed a bug where the remote Podman client's podman build command could attempt to build a Dockerfile in the working directory of the podman system service instance instead of the Dockerfile specified by the user (#12054). * Fixed a bug where the podman logs --tail command could function improperly (printing more output than requested) when the journald log driver was used. * Fixed a bug where containers run using the slirp4netns network mode with IPv6 enabled would not have IPv6 connectivity until several seconds after they started (#11062). * Fixed a bug where some Podman commands could cause an extra dbus-daemon process to be created (#9727). * Fixed a bug where rootless Podman would sometimes print warnings about a failure to move the pause process into a given CGroup (#12065). * Fixed a bug where the checkpointed field in podman inspect on a container was not set to false after a container was restored. * Fixed a bug where the podman system service command would print overly-verbose logs about request IDs (#12181). * Fixed a bug where Podman could, when creating a new container without a name explicitly specified by the user, sometimes use an auto-generated name already in use by another container if multiple containers were being created in parallel (#11735).- Update to version 3.4.1: * Bugfixes - Fixed a bug where podman machine init could, under some circumstances, create invalid machine configurations which could not be started (#11824). - Fixed a bug where the podman machine list command would not properly populate some output fields. - Fixed a bug where podman machine rm could leave dangling sockets from the removed machine (#11393). - Fixed a bug where podman run --pids-limit=-1 was not supported (it now sets the PID limit in the container to unlimited) (#11782). - Fixed a bug where podman run and podman attach could throw errors about a closed network connection when STDIN was closed by the client (#11856). - Fixed a bug where the podman stop command could fail when run on a container that had another podman stop command run on it previously. - Fixed a bug where the --sync flag to podman ps was nonfunctional. - Fixed a bug where the Windows and OS X remote clients' podman stats command would fail (#11909). - Fixed a bug where the podman play kube command did not properly handle environment variables whose values contained an = (#11891). - Fixed a bug where the podman generate kube command could generate invalid annotations when run on containers with volumes that use SELinux relabelling (:z or :Z) (#11929). - Fixed a bug where the podman generate kube command would generate YAML including some unnecessary (set to default) fields (e.g. user and group, entrypoint, default protocol for forwarded ports) (#11914, #11915, and #11965). - Fixed a bug where the podman generate kube command could, under some circumstances, generate YAML including an invalid targetPort field for forwarded ports (#11930). - Fixed a bug where rootless Podman's podman info command could, under some circumstances, not read available CGroup controllers (#11931). - Fixed a bug where podman container checkpoint --export would fail to checkpoint any container created with --log-driver=none (#11974). * API - Fixed a bug where the Compat Create endpoint for Containers could panic when no options were passed to a bind mount of tmpfs (#11961).- Update to version 3.4.0: * Features - Pods now support init containers! Init containers are containers which run before the rest of the pod starts. There are two types of init containers: "always", which always run before the pod is started, and "once", which only run the first time the pod starts and are subsequently removed. They can be added using the podman create command's --init-ctr option. - Support for init containers has also been added to podman play kube and podman generate kube - init containers contained in Kubernetes YAML will be created as Podman init containers, and YAML generated by Podman will include any init containers created. - The podman play kube command now supports building images. If the --build option is given and a directory with the name of the specified image exists in the current working directory and contains a valid Containerfile or Dockerfile, the image will be built and used for the container. - The podman play kube command now supports a new option, --teardown, which removes any pods and containers created by the given Kubernetes YAML. - The podman generate kube command now generates annotations for SELinux mount options on volume (:z and :Z) that are respected by the podman play kube command. - A new command has been added, podman pod logs, to return logs for all containers in a pod at the same time. - Two new commands have been added, podman volume export (to export a volume to a tar file) and podman volume import) (to populate a volume from a given tar file). - The podman auto-update command now supports simple rollbacks. If a container fails to start after an automatic update, it will be rolled back to the previous image and restarted again. - Pods now share their user namespace by default, and the podman pod create command now supports the --userns option. This allows rootless pods to be created with the --userns=keep-id option. - The podman pod ps command now supports a new filter with its --filter option, until, which returns pods created before a given timestamp. - The podman image scp command has been added. This command allows images to be transferred between different hosts. - The podman stats command supports a new option, --interval, to specify the amount of time before the information is refreshed. - The podman inspect command now includes ports exposed (but not published) by containers (e.g. ports from --expose when --publish-all is not specified). - The podman inspect command now has a new boolean value, Checkpointed, which indicates that a container was stopped as a result of a podman container checkpoint operation. - Volumes created by podman volume create now support setting quotas when run atop XFS. The size and inode options allow the maximum size and maximum number of inodes consumed by a volume to be limited. - The podman info command now outputs information on what log drivers, network drivers, and volume plugins are available for use (#11265). - The podman info command now outputs the current log driver in use, and the variant and codename of the distribution in use. - The parameters of the VM created by podman machine init (amount of disk space, memory, CPUs) can now be set in containers.conf. - The podman machine ls command now shows additional information (CPUs, memory, disk size) about VMs managed by podman machine. - The podman ps command now includes healthcheck status in container state for containers that have healthchecks (#11527). * Changes - The podman build command has a new alias, podman buildx, to improve compatibility with Docker. We have already added support for many docker buildx flags to podman build and aim to continue to do so. - Cases where Podman is run without a user session or a writable temporary files directory will now produce better error messages. - The default log driver has been changed from file to journald. The file driver did not properly support log rotation, so this should lead to a better experience. If journald is not available on the system, Podman will automatically revert to the file. - Podman no longer depends on ip for removing networks (#11403). - The deprecated --macvlan flag to podman network create now warns when it is used. It will be removed entirely in the Podman 4.0 release. - The podman machine start command now prints a message when the VM is successfully started. - The podman stats command can now be used on containers that are paused. - The podman unshare command will now return the exit code of the command that was run in the user namespace (assuming the command was successfully run). - Successful healthchecks will no longer add a healthy line to the system log to reduce log spam. - As a temporary workaround for a lack of shortname prompts in the Podman remote client, VMs created by podman machine now default to only using the docker.io registry. * Bugfixes - Fixed a bug where whitespace in the definition of sysctls (particularly default sysctls specified in containers.conf) would cause them to be parsed incorrectly. - Fixed a bug where the Windows remote client improperly validated volume paths (#10900). - Fixed a bug where the first line of logs from a container run with the journald log driver could be skipped. - Fixed a bug where images created by podman commit did not include ports exposed by the container. - Fixed a bug where the podman auto-update command would ignore the io.containers.autoupdate.authfile label when pulling images (#11171). - Fixed a bug where the --workdir option to podman create and podman run could not be set to a directory where a volume was mounted (#11352). - Fixed a bug where systemd socket-activation did not properly work with systemd-managed Podman containers (#10443). - Fixed a bug where environment variable secrets added to a container were not available to exec sessions launched in the container. - Fixed a bug where rootless containers could fail to start the rootlessport port-forwarding service when XDG_RUNTIME_DIR was set to a long path. - Fixed a bug where arguments to the --systemd option to podman create and podman run were case-sensitive (#11387). - Fixed a bug where the podman manifest rm command would also remove images referenced by the manifest, not just the manifest itself (#11344). - Fixed a bug where the Podman remote client on OS X would not function properly if the TMPDIR environment variable was not set (#11418). - Fixed a bug where the /etc/hosts file was not guaranteed to contain an entry for localhost (this is still not guaranteed if --net=host is used; such containers will exactly match the host's /etc/hosts) (#11411). - Fixed a bug where the podman machine start command could print warnings about unsupported CPU features (#11421). - Fixed a bug where the podman info command could segfault when accessing cgroup information. - Fixed a bug where the podman logs -f command could hang when a container exited (#11461). - Fixed a bug where the podman generate systemd command could not be used on containers that specified a restart policy (#11438). - Fixed a bug where the remote Podman client's podman build command would fail to build containers if the UID and GID on the client were higher than 65536 (#11474). - Fixed a bug where the remote Podman client's podman build command would fail to build containers if the context directory was a symlink (#11732). - Fixed a bug where the --network flag to podman play kube was not properly parsed when a non-bridge network configuration was specified. - Fixed a bug where the podman inspect command could error when the container being inspected was removed as it was being inspected (#11392). - Fixed a bug where the podman play kube command ignored the default pod infra image specified in containers.conf. - Fixed a bug where the --format option to podman inspect was nonfunctional under some circumstances (#8785). - Fixed a bug where the remote Podman client's podman run and podman exec commands could skip a byte of output every 8192 bytes (#11496). - Fixed a bug where the podman stats command would print nonsensical results if the container restarted while it was running (#11469). - Fixed a bug where the remote Podman client would error when STDOUT was redirected on a Windows client (#11444). - Fixed a bug where the podman run command could return 0 when the application in the container exited with 125 (#11540). - Fixed a bug where containers with --restart=always set using the rootlessport port-forwarding service could not be restarted automatically. - Fixed a bug where the --cgroups=split option to podman create and podman run was silently discarded if the container was part of a pod. - Fixed a bug where the podman container runlabel command could fail if the image name given included a tag. - Fixed a bug where Podman could add an extra 127.0.0.1 entry to /etc/hosts under some circumstances (#11596). - Fixed a bug where the remote Podman client's podman untag command did not properly handle tags including a digest (#11557). - Fixed a bug where the --format option to podman ps did not properly support the table argument for tabular output. - Fixed a bug where the --filter option to podman ps did not properly handle filtering by healthcheck status (#11687). - Fixed a bug where the podman run and podman start --attach commands could race when retrieving the exit code of a container that had already been removed resulting in an error (e.g. by an external podman rm -f) (#11633). - Fixed a bug where the podman generate kube command would add default environment variables to generated YAML. - Fixed a bug where the podman generate kube command would add the default CMD from the image to generated YAML (#11672). - Fixed a bug where the podman rm --storage command could fail to remove containers under some circumstances (#11207). - Fixed a bug where the podman machine ssh command could fail when run on Linux (#11731). - Fixed a bug where the podman stop command would error when used on a container that was already stopped (#11740). - Fixed a bug where renaming a container in a pod using the podman rename command, then removing the pod using podman pod rm, could cause Podman to believe the new name of the container was permanently in use, despite the container being removed (#11750). * API - The Libpod Pull endpoint for Images now has a new query parameter, quiet, which (when set to true) suppresses image pull progress reports (#10612). - The Compat Events endpoint now includes several deprecated fields from the Docker v1.21 API for improved compatibility with older clients. - The Compat List and Inspect endpoints for Images now prefix image IDs with sha256: for improved Docker compatibility (#11623). - The Compat Create endpoint for Containers now properly sets defaults for healthcheck-related fields (#11225). - The Compat Create endpoint for Containers now supports volume options provided by the Mounts field (#10831). - The Compat List endpoint for Secrets now supports a new query parameter, filter, which allows returned results to be filtered. - The Compat Auth endpoint now returns the correct response code (500 instead of 400) when logging into a registry fails. - The Version endpoint now includes information about the OCI runtime and Conmon in use (#11227). - Fixed a bug where the X-Registry-Config header was not properly handled, leading to errors when pulling images (#11235). - Fixed a bug where invalid query parameters could cause a null pointer dereference when creating error messages. - Logging of API requests and responses at trace level has been greatly improved, including the addition of an X-Reference-Id header to correlate requests and responses (#10053). * Misc - Updated Buildah to v1.23.0 - Updated the containers/storage library to v1.36.0 - Updated the containers/image library to v5.16.0 - Updated the containers/common library to v0.44.0- require runc >= 1.0.1- Update to version 3.3.1: * Bugfixes - Fixed a bug where unit files created by podman generate systemd could not cleanup shut down containers when stopped by systemctl stop (#11304). - Fixed a bug where podman machine commands would not properly locate the gvproxy binary in some circumstances. - Fixed a bug where containers created as part of a pod using the - -pod-id-file option would not join the pod's network namespace (#11303). - Fixed a bug where Podman, when using the systemd cgroups driver, could sometimes leak dbus sessions. - Fixed a bug where the until filter to podman logs and podman events was improperly handled, requiring input to be negated (#11158). - Fixed a bug where rootless containers using CNI networking run on systems using systemd-resolved for DNS would fail to start if resolved symlinked /etc/resolv.conf to an absolute path (#11358). * API - A large number of potential file descriptor leaks from improperly closing client connections have been fixed.- Revert crun change due to crun having exclusive arch targets that would drop podman support in PPC and IBM Z- Update to version 3.3.0: * Fix network aliases with network id * machine: compute sha256 as we read the image file * machine: check for file exists instead of listing directory * pkg/bindings/images.nTar(): slashify hdr.Name values * Volumes: Only remove from DB if plugin removal succeeds * For compatibility, ignore Content-Type * [v3.3] Bump c/image 5.15.2, buildah v1.22.3 * Implement SD-NOTIFY proxy in conmon * Fix rootless cni dns without systemd stub resolver * fix rootlessport flake * Skip stats test in CGv1 container environments * Fix AVC denials in tests of volume mounts * Restore buildah-bud test requiring new images * Revert ".cirrus.yml: use fresh images for all VMs" * Fix device tests using ls test files * Enhance priv. dev. check * Workaround host availability of /dev/kvm * Skip cgroup-parent test due to frequent flakes * Cirrus: Fix not uploading logformatter html- Switch to crun (bsc#1188914)- Update to version 3.2.3: * Bump to v3.2.3 * Update release notes for v3.2.3 * vendor containers/common@v0.38.16 * vendor containers/buildah@v1.21.3 * Fix race conditions in rootless cni setup * CNI-in-slirp4netns: fix bind-mount for /run/systemd/resolve/stub-resolv.conf * Make rootless-cni setup more robust * Support uid,gid,mode options for secrets * vendor containers/common@v0.38.15 * [CI:DOCS] podman search: clarify that results depend on implementation * vendor containers/common@v0.38.14 * vendor containers/common@v0.38.13 * [3.2] vendor containers/common@v0.38.12 * Bump README to v3.2.2 * Bump to v3.2.3-dev- Update to version 3.2.2: * Bump to v3.2.2 * fix systemcontext to use correct TMPDIR * Scrub podman commands to use report package * Fix volumes with uid and gid options * Vendor in c/common v0.38.11 * Initial release notes for v3.2.2 * Fix restoring of privileged containers * Fix handling of podman-remote build --device * Add support for podman remote build -f - . * Fix panic condition in cgroups.getAvailableControllers * Fix permissions on initially created named volumes * Fix building static podman-remote * add correct slirp ip to /etc/hosts * disable tty-size exec checks in system tests * Fix resize race with podman exec -it * Fix documentation of the --format option of podman push * Fix systemd-resolved detection. * Health Check is not handled in the compat LibpodToContainerJSON * Do not use inotify for OCICNI * getContainerNetworkInfo: lock netNsCtr before sync * [NO TESTS NEEDED] Create /etc/mtab with the correct ownership * Create the /etc/mtab file if does not exists * [v3.2] cp: do not allow dir->file copying * create: support images with invalid platform * vendor containers/common@v0.38.10 * logs: k8s-file: restore poll sleep * logs: k8s-file: fix spurious error logs * utils: move message from warning to debug * Bump to v3.2.2-dev- Update to version 3.2.1: * Bump to v3.2.1 * Updated release notes for v3.2.1 * Fix network connect race with docker-compose * Revert "Ensure minimum API version is set correctly in tests" * Fall back to string for dockerfile parameter * remote events: fix --stream=false * [CI:DOCS] fix incorrect network remove api doc * remote: always send resize before the container starts * remote events: support labels * remote pull: cancel pull when connection is closed * Fix network prune api docs * Improve systemd-resolved detection * logs: k8s-file: fix race * Fix image prune --filter cmd behavior * Several shell completion fixes * podman-remote build should handle -f option properly * System tests: deal with crun 0.20.1 * Fix build tags for pkg/machine... * Fix pre-checkpointing * container: ignore named hierarchies * [v3.2] vendor containers/common@v0.38.9 * rootless: fix fast join userns path * [v3.2] vendor containers/common@v0.38.7 * [v3.2] vendor containers/common@v0.38.6 * Correct qemu options for Intel macs * Ensure minimum API version is set correctly in tests * Bump to v3.2.1-dev- Update to version 3.2.0: * Bump to v3.2.0 * Fix network create macvlan with subnet option * Final release notes updates for v3.2.0 * add ipv6 nameservers only when the container has ipv6 enabled * Use request context instead of background * [v.3.2] events: support disjunctive filters * System tests: add :Z to volume mounts * generate systemd: make mounts portable * vendor containers/storage@v1.31.3 * vendor containers/common@v0.38.5 * Bump to v3.2.0-dev * Bump to v3.2.0-RC3 * Update release notes for v3.2.0-RC3 * Fix race on podman start --all * Fix race condition in running ls container in a pod * docs: --cert-dir: point to containers-certs.d(5) * Handle hard links in different directories * Improve OCI Runtime error * Handle hard links in remote builds * Podman info add support for status of cgroup controllers * Drop container does not exist on removal to debugf * Downgrade API service routing table logging * add libimage events * docs: generate systemd: XDG_RUNTIME_DIR * Fix problem copying files when container is in host pid namespace * Bump to v3.2.0-dev * Bump to v3.2.0-RC2 * update c/common * Update Cirrus DEST_BRANCH to v3.2 * Updated vendors of c/image, c/storage, Buildah * Initial release notes for v3.2.0-RC2 * Add script for identifying commits in release branches * Add host.containers.internal entry into container's etc/hosts * image prune: remove unused images only with `--all` * podman network reload add rootless support * Use more recent `stale` release... * network tutorial: update with rootless cni changes * [CI:DOCS] Update first line in intro page * Use updated VM images + updated automation tooling * auto-update service: prune images * make vendor * fix system upgrade tests * Print "extracting" only on compressed file * podman image tree: restore previous behavior * fix network restart always test * fix incorrect log driver in podman container image * Add support for cli network prune --filter flag * Move filter parsing to common utils * Bump github.com/containers/storage from 1.30.2 to 1.30.3 * Update nix pin with `make nixpkgs` * [CI:DOCS] hack/bats - new helper for running system tests * fix restart always with slirp4netns * Bump github.com/opencontainers/runc from 1.0.0-rc93 to 1.0.0-rc94 * Bump github.com/coreos/go-systemd/v22 from 22.3.1 to 22.3.2 * Add host.serviceIsRemote to podman info results * Add client disconnect to build handler loop * Remove obsolete skips * Fix podman-remote build --rm=false ... * fix: improved "containers/{name}/wait" endpoint * Bump github.com/containers/storage from 1.30.1 to 1.30.2 * Add envars to the generated systemd unit * fix: use UTC Time Stamps in response JSON * fix container startup for empty pidfile * Kube like pods should share ipc,net,uts by default * fix: compat API "images/get" for multiple images * Revert escaped double dash man page flag syntax * Report Download complete in Compatibility mode * Add documentation on short-names * Bump github.com/docker/docker * Adds support to preserve auto update labels in generate and play kube * [CI:DOCS] Stop conversion of `--` into en dash * Revert Patch to relabel if selinux not enabled * fix per review request * Add support for environment variable secrets * fix pre review request * Fix infinite loop in isPathOnVolume * Add containers.conf information for changing defaults * CI: run rootless tests under ubuntu * Fix wrong macvlan PNG in networking doc. * Add restart-policy to container filters & --filter to podman start * Fixes docker-compose cannot set static ip when use ipam * channel: simplify implementation * build: improve regex for iidfile * Bump github.com/onsi/gomega from 1.11.0 to 1.12.0 * cgroup: fix rootless --cgroup-parent with pods * fix: docker APIv2 `images/get` * codespell cleanup * Minor podmanimage docs updates. * Fix handling of runlabel IMAGE and NAME * Bump to v3.2.0-dev * Bump to v3.2.0-rc1 * rootless: improve automatic range split * podman: set volatile storage flag for --rm containers * Bump github.com/onsi/ginkgo from 1.16.1 to 1.16.2 * Bump github.com/containers/image/v5 from 5.11.1 to 5.12.0 * migrate Podman to containers/common/libimage * Add filepath glob support to --security-opt unmask * Force log_driver to k8s-file for containers in containers * add --mac-address to podman play kube * compat api: Networks must be empty instead of null * System tests: honor $OCI_RUNTIME (for CI) * is this a bug? * system test image: add arm64v8 image * Fix troubleshooting documentation on handling sublemental groups. * Add --all to podman start * Fix variable reference typo. in multi-arch image action * cgroup: always honor --cgroup-parent with cgroupfs * Bump github.com/uber/jaeger-client-go * Don't require tests for github-actions & metadata * Detect if in podman machine virtual vm * Fix multi-arch image workflow typo * [CI:DOCS] Add titles to remote docs (windows) * Remove unused VolumeList* structs * Cirrus: Update F34beta -> F34 * Update container image docs + fix unstable execution * Bump github.com/containers/storage from 1.30.0 to 1.30.1 * TODO complete * Docker returns 'die' status rather then 'died' status * Check if another VM is running on machine start * [CI:DOCS] Improve titles of command HTML pages * system tests: networking: fix another race condition * Use seccomp_profile as default profile if defined in containers.conf * Bump github.com/json-iterator/go from 1.1.10 to 1.1.11 * Vendored * Autoupdate local label functional * System tests: fix two race conditions * Add more documentation on conmon * Allow docker volume create API to pass without name * Cirrus: Update Ubuntu images to 21.04 * Skip blkio-weight test when no kernel BFQ support * rootless: Tell the user what was led to the error, not just what it is * Add troubleshooting advice about the --userns option. * Fix images prune filter until * Fix logic for pushing stable multi-arch images * Fixes generate kube incorrect when bind-mounting "/" and "/root" * libpod/image: unit tests: don't use system's registries.conf.d * runtime: create userns when CAP_SYS_ADMIN is not present * rootless: attempt to copy current mappings first * [CI:DOCS] Restore missing content to manpages * [CI:DOCS] Fix Markdown layout bugs * Fix podman ps --filter ancestor to match exact ImageName/ImageID * Add machine-enabled to containers.conf for machine * Several multi-arch image build/push fixes * Add podman run --timeout option * Parse slirp4netns net options with compat api * Fix rootlesskit port forwarder with custom slirp cidr * Fix removal race condition in ListContainers * Add github-action workflow to build/push multi-arch * rootless: if root is not sub?id raise a debug message * Bump github.com/containers/common from 0.36.0 to 0.37.0 * Add go template shell completion for --format * Add --group-add keep-groups: suplimentary groups into container * Fixes from make codespell * Typo fix to usage text of --compress option * corrupt-image test: fix an oops * Add --noheading flag to all list commands * Bump github.com/containers/storage from 1.29.0 to 1.30.0 * Bump github.com/containers/image/v5 from 5.11.0 to 5.11.1 * [CI:DOCS] Fix Markdown table layout bugs * podman-remote should show podman.sock info * rmi: don't break when the image is missing a manifest * [CI:DOCS] Rewrite --uidmap doc in podman-create.1.md and podman-run.1.md * Add support for CDI device configuration * [CI:DOCS] Add missing dash to verbose option * Bump github.com/uber/jaeger-client-go * Remove an advanced layer diff function * Ensure mount destination is clean, no trailing slash * add it for inspect pidfile * [CI:DOCS] Fix introduction page typo * support pidfile on container restore * fix start it * skip pidfile test on remote * improve document * set pidfile default value int containerconfig * add pidfile in inspection * add pidfile it for container start * skip pidfile it on remote * Modify according to comments * WIP: drop test requirement * runtime: bump required conmon version * runtime: return findConmon to libpod * oci: drop ExecContainerCleanup * oci: use `--full-path` option for conmon * use AttachSocketPath when removing conmon files * hide conmon-pidfile flag on remote mode * Fix possible panic in libpod/image/prune.go * add --ip to podman play kube * add flag autocomplete * add ut * add flag "--pidfile" for podman create/run * Add network bindings tests: remove and list * Fix build with GO111MODULE=off * system tests: build --pull-never: deal with flakes * compose test: diagnose flakes v3 * podman play kube apply correct log driver * Fixes podman-remote save to directories does not work * Bump github.com/rootless-containers/rootlesskit from 0.14.1 to 0.14.2 * Update documentation of podman-run to reflect volume "U" option * Fix flake on failed podman-remote build : try 2 * compose test: ongoing efforts to diagnose flakes * Test that we don't error out on advertised --log-level values * At trace log level, print error text using %+v instead of %v * pkg/errorhandling.JoinErrors: don't throw away context for lone errors * Recognize --log-level=trace * Fix flake on failed podman-remote build * System tests: fix racy podman-inspect * Fixes invalid expression in save command * Bump github.com/containers/common from 0.35.4 to 0.36.0 * Update nix pin with `make nixpkgs` * compose test: try to get useful data from flakes * Remove in-memory state implementation * Fix message about runtime to show only the actual runtime * System tests: setup: better cleanup of stray images * Bump github.com/containers/ocicrypt from 1.1.0 to 1.1.1 * Reflect current state of prune implementation in docs * Do not delete container twice * [CI:DOCS] Correct status code for /pods/create * vendor in containers/storage v1.29.0 * cgroup: do not set cgroup parent when rootless and cgroupfs * Overhaul Makefile binary and release worflows * Reorganize Makefile with sections and guide * Simplify Makefile help target * Don't shell to obtain current directory * Remove unnecessary/not-needed release.txt target * Fix incorrect version number output * Exclude .gitignore from test req. * Fix handling of $NAME and $IMAGE in runlabel * Update podman image Dockerfile to support Podman in container * Bump github.com/containers/image/v5 from 5.10.5 to 5.11.0 * Fix slashes in socket URLs * Add network prune filters support to bindings * Add support for play/generate kube volumes * Update manifest API endpoints * Fix panic when not giving a machine name for ssh * cgroups: force 64 bits to ParseUint * Bump k8s.io/api from 0.20.5 to 0.21.0 * [CI:DOCS] Fix formatting of podman-build man page * buildah-bud tests: simplify * Add missing return * Bump github.com/onsi/ginkgo from 1.16.0 to 1.16.1 * speed up CI handling of images * Volumes prune endpoint should use only prune filters * Cirrus: Use Fedora 34beta images * Bump go.sum + Makefile for golang 1.16 * Exempt Makefile changes from test requirements * Adjust libpod API Container Wait documentation to the code * [CI:DOCS] Update swagger definition of inspect manifest * use updated ubuntu images * podman unshare: add --rootless-cni to join the ns * Update swagger-check * swagger: remove name wildcards * Update buildah-bud diffs * Handle podman-remote --arch, --platform, --os * buildah-bud tests: handle go pseudoversions, plus... * Fix flaking rootless compose test * rootless cni add /usr/sbin to PATH if not present * System tests: special case for RHEL: require runc * Add --requires flag to podman run/create * [CI:DOCS] swagger-check: compare operations * [CI:DOCS] Polish swagger OpertionIDs * [NO TESTS NEEDED] Update nix pin with `make nixpkgs` * Ensure that `--userns=keep-id` sets user in config * [CI:DOCS] Set all operation id to be compatibile * Move operationIds to swagger:operation line * swagger: add operationIds that match with docker * Cirrus: Make use of shared get_ci_vm container * Don't relabel volumes if running in a privileged container * Allow users to override default storage opts with --storage-opt * Add support for podman --context default * Verify existence of auth file if specified * fix machine naming conventions * Initial network bindings tests * Update release notes to indicate CVE fix * Move socket activation check into init() and set global condition. * Bump github.com/onsi/ginkgo from 1.15.2 to 1.16.0 * Http api tests for network prune with until filter * podman-run.1.md, podman-create.1.md : Adjust Markdown layout for --userns * Fix typos --uidmapping and --gidmapping * Add transport and destination info to manifest doc * Bump github.com/rootless-containers/rootlesskit from 0.14.0 to 0.14.1 * Add default template functions * Fix missing podman-remote build options * Bump github.com/coreos/go-systemd/v22 from 22.3.0 to 22.3.1 * Add ssh connection to root user * Add rootless docker-compose test to the CI * Use the slrip4netns dns in the rootless cni ns * Cleanup the rootless cni namespace * Add new docker-compose test for two networks * Make the docker-compose test work rootless * Remove unused rootless-cni-infra container files * Only use rootless RLK when the container has ports * Fix dnsname test * Enable rootless network connect/disconnect * Move slirp4netns functions into an extra file * Fix pod infra container cni network setup * Add rootless support for cni and --uidmap * rootless cni without infra container * Recreate until container prune tests for bindings * Remove --execute from podman machine ssh * Fixed podman-remote --network flag * Makefile: introduce install.docker-full * Makefile: ensure install.docker creates BINDIR * Fix unmount doc reference in image.rst * Should send the OCI runtime path not just the name to buildah * podman machine shell completion * Fix handling of remove --log-rusage param * Fix bindings prune containers flaky test * [CI:DOCS] Add local html build info to docs/README.md * Add podman machine list * Trim white space from /top endpoint results * Remove semantic version suffices from API calls * podman machine init --ignition-path * Document --volume from podman-remote run/create client * Update main branch to reflect the release of v3.1.0 * Silence podman network reload errors with iptables-nft * Containers prune endpoint should use only prune filters * resolve proper aarch64 image names * APIv2 basic test: relax APIVersion check * Add machine support for qemu-system-aarch64 * podman machine init user input * manpage xref: helpful diagnostic for unescaped dash-dash * Bump to v3.2.0-dev * swagger: update system version response body * buildah-bud tests: reenable pull-never test * [NO TESTS NEEDED] Shrink the size of podman-remote * Add powershell completions * [NO TESTS NEEDED] Drop Warning to Info, if cgroups not mounted * Fix long option format on docs.podman.io * system tests: friendier messages for 2-arg is() * service: use LISTEN_FDS * man pages: correct seccomp-policy label * rootless: use is_fd_inherited * podman generate systemd --new do not duplicate params * play kube: add support for env vars defined from secrets * play kube: support optional/mandatory env var from config map * play kube: prepare supporting other env source than config maps * Add machine support for more Linux distros * [NO TESTS NEEDED] Use same function podman-remote rmi as podman * Podman machine enhancements * Add problematic volume name to kube play error messages * Fix podman build --pull-never * [NO TESTS NEEDED] Fix for kernel without CONFIG_USER_NS * [NO TESTS NEEDED] Turn on podman-remote build --isolation * Fix list pods filter handling in libpod api * Remove resize race condition * [NO TESTS NEEDED] Vendor in containers/buildah v1.20.0 * Use TMPDIR when commiting images * Add RequiresMountsFor= to systemd generate * Bump github.com/vbauerster/mpb/v6 from 6.0.2 to 6.0.3 * Fix swapped dimensions from terminal.GetSize * Rename podman machine create to init and clean up * Correct json field name * system tests: new interactive tests * Improvements for machine * libpod/image: unit tests: use a `registries.conf` for aliases * libpod/image: unit tests: defer cleanup * libpod/image: unit tests: use `require.NoError` * Add --execute flag to podman machine ssh * introduce podman machine * Podman machine CLI and interface stub * Support multi doc yaml for generate/play kube * Fix filters in image http compat/libpod api endpoints * Bump github.com/containers/common from 0.35.3 to 0.35.4 * Bump github.com/containers/storage from 1.28.0 to 1.28.1 * Check if stdin is a term in --interactive --tty mode * [NO TESTS NEEDED] Remove /tmp/containers-users-* files on reboot * [NO TESTS NEEDED] Fix rootless volume plugins * Ensure manually-created volumes have correct ownership * Bump github.com/rootless-containers/rootlesskit * Unification of until filter across list/prune endpoints * Unification of label filter across list/prune endpoints * fixup * fix: build endpoint for compat API * [CI:DOCS] Add note to mappings for user/group userns in build * Bump k8s.io/api from 0.20.1 to 0.20.5 * Validate passed in timezone from tz option * WIP: run buildah bud tests using podman * Fix containers list/prune http api filter behaviour * Generate Kubernetes PersistentVolumeClaims from named volumes- Update to version 3.1.2: * Bump to v3.1.2 * Update release notes for v3.1.2 * Ensure mount destination is clean, no trailing slash * Fixes podman-remote save to directories does not work * [CI:DOCS] Add missing dash to verbose option * [CI:DOCS] Fix Markdown table layout bugs * [CI:DOCS] Rewrite --uidmap doc in podman-create.1.md and podman-run.1.md * rmi: don't break when the image is missing a manifest * Bump containers/image to v5.11.1 * Bump github.com/coreos/go-systemd from 22.2.0 to 22.3.1 * Fix lint * Bump to v3.1.2-dev - Split podman-remote into a subpackage - Add missing scriptlets for systemd units - Escape macros in comments - Drop some obsolete workarounds, including %{go_nostrip}- Update to version 3.1.1: * Bump to v3.1.1 * Update release notes for v3.1.1 * podman play kube apply correct log driver * Fix build with GO111MODULE=off * [CI:DOCS] Set all operation id to be compatibile * Move operationIds to swagger:operation line * swagger: add operationIds that match with docker * Fix missing podman-remote build options * [NO TESTS NEEDED] Shrink the size of podman-remote * Move socket activation check into init() and set global condition. * rootless: use is_fd_inherited * Recreate until container prune tests for bindings * System tests: special case for RHEL: require runc * Document --volume from podman-remote run/create client * Containers prune endpoint should use only prune filters * Trim white space from /top endpoint results * Fix unmount doc reference in image.rst * Fix handling of remove --log-rusage param * Makefile: introduce install.docker-full * Makefile: ensure install.docker creates BINDIR * Should send the OCI runtime path not just the name to buildah * Fixed podman-remote --network flag * podman-run.1.md, podman-create.1.md : Adjust Markdown layout for --userns * Fix typos --uidmapping and --gidmapping * Add default template functions * Don't relabel volumes if running in a privileged container * Allow users to override default storage opts with --storage-opt * Add transport and destination info to manifest doc * Verify existence of auth file if specified * Ensure that `--userns=keep-id` sets user in config * [CI:DOCS] Update swagger definition of inspect manifest * Volumes prune endpoint should use only prune filters * Adjust libpod API Container Wait documentation to the code * Add missing return * [CI:DOCS] Fix formatting of podman-build man page * cgroups: force 64 bits to ParseUint * Fix slashes in socket URLs * [CI:DOCS] Correct status code for /pods/create * cgroup: do not set cgroup parent when rootless and cgroupfs * Reflect current state of prune implementation in docs * Do not delete container twice * Test that we don't error out on advertised --log-level values * At trace log level, print error text using %+v instead of %v * pkg/errorhandling.JoinErrors: don't throw away context for lone errors * Recognize --log-level=trace * Fix message about runtime to show only the actual runtime * Fix handling of $NAME and $IMAGE in runlabel * Fix flake on failed podman-remote build : try 2 * Fix flake on failed podman-remote build * Update documentation of podman-run to reflect volume "U" option * Fixes invalid expression in save command * Fix possible panic in libpod/image/prune.go * Update all containers/ project vendors * Fix tests * Bump to v3.1.1-dev- Update to version 3.1.0: (bsc#1181961, CVE-2021-20206) * Bump to v3.1.0 * Fix test failure * Update release notes for v3.1.0 final release * [NO TESTS NEEDED] Turn on podman-remote build --isolation * Fix long option format on docs.podman.io * Fix containers list/prune http api filter behaviour * [CI:DOCS] Add note to mappings for user/group userns in build * Validate passed in timezone from tz option * Generate Kubernetes PersistentVolumeClaims from named volumes * libpod/image: unit tests: use a `registries.conf` for aliases - Require systemd 241 or newer due to podman dependency go-systemd v22, otherwise build will fail with unknown C name errors- Create docker subpackage to allow replacing docker with corresponding aliases to podman.- Drop obsolete varlink.patch- Update to v3.0.1 * Changes - Several frequently-occurring WARN level log messages have been downgraded to INFO or DEBUG to not clutter terminal output. Bugfixes - Fixed a bug where the Created field of podman ps --format=json was formatted as a string instead of an Unix timestamp (integer) (#9315). - Fixed a bug where failing lookups of individual layers during the podman images command would cause the whole command to fail without printing output. - Fixed a bug where --cgroups=split did not function properly on cgroups v1 systems. - Fixed a bug where mounting a volume over an directory in the container that existed, but was empty, could fail (#9393). - Fixed a bug where mounting a volume over a directory in the container that existed could copy the entirety of the container's rootfs, instead of just the directory mounted over, into the volume (#9415). - Fixed a bug where Podman would treat the --entrypoint=[""] option to podman run and podman create as a literal empty string in the entrypoint, when instead it should have been ignored (#9377). - Fixed a bug where Podman would set the HOME environment variable to "" when the container ran as a user without an assigned home directory (#9378). - Fixed a bug where specifying a pod infra image that had no tags (by using its ID) would cause podman pod create to panic (#9374). - Fixed a bug where the --runtime option was not properly handled by the podman build command (#9365). - Fixed a bug where Podman would incorrectly print an error message related to the remote API when the remote API was not in use and starting Podman failed. - Fixed a bug where Podman would change ownership of a container's working directory, even if it already existed (#9387). - Fixed a bug where the podman generate systemd --new command would incorrectly escape %t when generating the path for the PID file (#9373). - Fixed a bug where Podman could, when run inside a Podman container with the host's containers/storage directory mounted into the container, erroneously detect a reboot and reset container state if the temporary directory was not also mounted in (#9191). - Fixed a bug where some options of the podman build command (including but not limited to --jobs) were nonfunctional (#9247). * API - Fixed a breaking change to the Libpod Wait API for Containers where the Conditions parameter changed type in Podman v3.0 (#9351). - Fixed a bug where the Compat Create endpoint for Containers did not properly handle forwarded ports that did not specify a host port. - Fixed a bug where the Libpod Wait endpoint for Containers could write duplicate headers after an error occurred. - Fixed a bug where the Compat Create endpoint for Images would not pull images that already had a matching tag present locally, even if a more recent version was available at the registry (#9232). - The Compat Create endpoint for Images has had its compatibility with Docker improved, allowing its use with the docker-java library. * Misc - Updated Buildah to v1.19.4 - Updated the containers/storage library to v1.24.6 - Changes from v3.0.0 * Features - Podman now features initial support for Docker Compose. - Added the podman rename command, which allows containers to be renamed after they are created (#1925). - The Podman remote client now supports the podman copy command. - A new command, podman network reload, has been added. This command will re-configure the network of all running containers, and can be used to recreate firewall rules lost when the system firewall was reloaded (e.g. via firewall-cmd --reload). - Podman networks now have IDs. They can be seen in podman network ls and can be used when removing and inspecting networks. Existing networks receive IDs automatically. - Podman networks now also support labels. They can be added via the --label option to network create, and podman network ls can filter labels based on them. - The podman network create command now supports setting bridge MTU and VLAN through the --opt option (#8454). - The podman container checkpoint and podman container restore commands can now checkpoint and restore containers that include volumes. - The podman container checkpoint command now supports the --with-previous and --pre-checkpoint options, and the podman container restore command now support the --import-previous option. These add support for two-step checkpointing with lowered dump times. - The podman push command can now push manifest lists. Podman will first attempt to push as an image, then fall back to pushing as a manifest list if that fails. - The podman generate kube command can now be run on multiple containers at once, and will generate a single pod containing all of them. - The podman generate kube and podman play kube commands now support Kubernetes DNS configuration, and will preserve custom DNS configuration when exporting or importing YAML (#9132). - The podman generate kube command now properly supports generating YAML for containers and pods creating using host networking (--net=host) (#9077). - The podman kill command now supports a --cidfile option to kill containers given a file containing the container's ID (#8443). - The podman pod create command now supports the --net=none option (#9165). - The podman volume create command can now specify volume UID and GID as options with the UID and GID fields passed to the the --opt option. - Initial support has been added for Docker Volume Plugins. Podman can now define available plugins in containers.conf and use them to create volumes with podman volume create --driver. - The podman run and podman create commands now support a new option, --platform, to specify the platform of the image to be used when creating the container. - The --security-opt option to podman run and podman create now supports the systempaths=unconfined option to unrestrict access to all paths in the container, as well as mask and unmask options to allow more granular restriction of container paths. - The podman stats --format command now supports a new format specified, MemUsageBytes, which prints the raw bytes of memory consumed by a container without human-readable formatting #8945. - The podman ps command can now filter containers based on what pod they are joined to via the pod filter (#8512). - The podman pod ps command can now filter pods based on what networks they are joined to via the network filter. The podman pod ps command can now print information on what networks a pod is joined to via the .Networks specifier to the --format option. - The podman system prune command now supports filtering what containers, pods, images, and volumes will be pruned. - The podman volume prune commands now supports filtering what volumes will be pruned. - The podman system prune command now includes information on space reclaimed (#8658). - The podman info command will now properly print information about packages in use on Gentoo and Arch systems. - The containers.conf file now contains an option for disabling creation of a new kernel keyring on container creation (#8384). - The podman image sign command can now sign multi-arch images by producing a signature for each image in a given manifest list. - The podman image sign command, when run as rootless, now supports per-user registry configuration files in $HOME/.config/containers/registries.d. - Configuration options for slirp4netns can now be set system-wide via the NetworkCmdOptions configuration option in containers.conf. - The MTU of slirp4netns can now be configured via the mtu= network command option (e.g. podman run --net slirp4netns:mtu=9000). * Security - A fix for CVE-2021-20199 / bsc#1181640 is included. Podman between v1.8.0 and v2.2.1 used 127.0.0.1 as the source address for all traffic forwarded into rootless containers by a forwarded port; this has been changed to address the issue. * Changes - Shortname aliasing support has now been turned on by default. All Podman commands that must pull an image will, if a TTY is available, prompt the user about what image to pull. - The podman load command no longer accepts a NAME[:TAG] argument. The presence of this argument broke CLI compatibility with Docker by making docker load commands unusable with Podman (#7387). - The Go bindings for the HTTP API have been rewritten with a focus on limiting dependency footprint and improving extensibility. Read more here. - The legacy Varlink API has been completely removed from Podman. - The default log level for Podman has been changed from Error to Warn. - The podman network create command can now create macvlan networks using the --driver macvlan option for Docker compatibility. The existing --macvlan flag has been deprecated and will be removed in Podman 4.0 some time next year. - The podman inspect command has had the LogPath and LogTag fields moved into the LogConfig structure (from the root of the Inspect structure). The maximum size of the log file is also included. - The podman generate systemd command no longer generates unit files using the deprecated KillMode=none option (#8615). - The podman stop command now releases the container lock while waiting for it to stop - as such, commands like podman ps will no longer block until podman stop completes (#8501). - Networks created with podman network create --internal no longer use the dnsname plugin. This configuration never functioned as expected. - Error messages for the remote Podman client have been improved when it cannot connect to a Podman service. - Error messages for podman run when an invalid SELinux is specified have been improved. - Rootless Podman features improved support for containers with a single user mapped into the rootless user namespace. - Pod infra containers now respect default sysctls specified in containers.conf allowing for advanced configuration of the namespaces they will share. - SSH public key handling for remote Podman has been improved. * Bugfixes - Fixed a bug where the podman history --no-trunc command would truncate the Created By field (#9120). - Fixed a bug where root containers that did not explicitly specify a CNI network to join did not generate an entry for the network in use in the Networks field of the output of podman inspect (#6618). - Fixed a bug where, under some circumstances, container working directories specified by the image (via the WORKDIR instruction) but not present in the image, would not be created (#9040). - Fixed a bug where the podman generate systemd command would generate invalid unit files if the container was creating using a command line that included doubled braces ({{ and }}), e.g. --log-opt-tag={{.Name}} (#9034). - Fixed a bug where the podman generate systemd --new command could generate unit files including invalid Podman commands if the container was created using merged short options (e.g. podman run -dt) (#8847). - Fixed a bug where the podman generate systemd --new command could generate unit files that did not handle Podman commands including some special characters (e.g. $) (#9176 - Fixed a bug where rootless containers joining CNI networks could not set a static IP address (#7842). - Fixed a bug where rootless containers joining CNI networks could not set network aliases (#8567). - Fixed a bug where the remote client could, under some circumstances, not include the Containerfile when sending build context to the server (#8374). - Fixed a bug where rootless Podman did not mount /sys as a new sysfs in some circumstances where it was acceptable. - Fixed a bug where rootless containers that both joined a user namespace and a CNI networks would cause a segfault. These options are incompatible and now return an error. - Fixed a bug where the podman play kube command did not properly handle CMD and ARGS from images (#8803). - Fixed a bug where the podman play kube command did not properly handle environment variables from images (#8608). - Fixed a bug where the podman play kube command did not properly print errors that occurred when starting containers. - Fixed a bug where the podman play kube command errored when hostNetwork was used (#8790). - Fixed a bug where the podman play kube command would always pull images when the :latest tag was specified, even if the image was available locally (#7838). - Fixed a bug where the podman play kube command did not properly handle SELinux configuration, rending YAML with custom SELinux configuration unusable (#8710). - Fixed a bug where the podman generate kube command incorrectly populated the args and command fields of generated YAML (#9211). - Fixed a bug where containers in a pod would create a duplicate entry in the pod's shared /etc/hosts file every time the container restarted (#8921). - Fixed a bug where the podman search --list-tags command did not support the --format option (#8740). - Fixed a bug where the http_proxy option in containers.conf was not being respected, and instead was set unconditionally to true (#8843). - Fixed a bug where rootless Podman could, on systems with a recent Conmon and users with a long username, fail to attach to containers (#8798). - Fixed a bug where the podman images command would break and fail to display any images if an empty manifest list was present in storage (#8931). - Fixed a bug where locale environment variables were not properly passed on to Conmon. - Fixed a bug where Podman would not build on the MIPS architecture (#8782). - Fixed a bug where rootless Podman could fail to properly configure user namespaces for rootless containers when the user specified a --uidmap option that included a mapping beginning with UID 0. - Fixed a bug where the podman logs command using the k8s-file backend did not properly handle partial log lines with a length of 1 (#8879). - Fixed a bug where the podman logs command with the --follow option did not properly handle log rotation (#8733). - Fixed a bug where user-specified HOSTNAME environment variables were overwritten by Podman (#8886). - Fixed a bug where Podman would applied default sysctls from containers.conf in too many situations (e.g. applying network sysctls when the container shared its network with a pod). - Fixed a bug where Podman did not properly handle cases where a secondary image store was in use and an image was present in both the secondary and primary stores (#8176). - Fixed a bug where systemd-managed rootless Podman containers where the user in the container was not root could fail as the container's PID file was not accessible to systemd on the host (#8506). - Fixed a bug where the --privileged option to podman run and podman create would, under some circumstances, not disable Seccomp (#8849). - Fixed a bug where the podman exec command did not properly add capabilities when the container or exec session were run with --privileged. - Fixed a bug where rootless Podman would use the --enable-sandbox option to slirp4netns unconditionally, even when pivot_root was disabled, rendering slirp4netns unusable when pivot_root was disabled (#8846). - Fixed a bug where podman build --logfile did not actually write the build's log to the logfile. - Fixed a bug where the podman system service command did not close STDIN, and could display user-interactive prompts (#8700). - Fixed a bug where the podman system reset command could, under some circumstances, remove all the contents of the XDG_RUNTIME_DIR directory (#8680). - Fixed a bug where the podman network create command created CNI configurations that did not include a default gateway (#8748). - Fixed a bug where the podman.service systemd unit provided by default used the wrong service type, and would cause systemd to not correctly register the service as started (#8751). - Fixed a bug where, if the TMPDIR environment variable was set for the container engine in containers.conf, it was being ignored. - Fixed a bug where the podman events command did not properly handle future times given to the --until option (#8694). - Fixed a bug where the podman logs command wrote container STDERR logs to STDOUT instead of STDERR (#8683). - Fixed a bug where containers created from an image with multiple tags would report that they were created from the wrong tag (#8547). - Fixed a bug where container capabilities were not set properly when the --cap-add=all and --user options to podman create and podman run were combined. - Fixed a bug where the --layers option to podman build was nonfunctional (#8643). - Fixed a bug where the podman system prune command did not act recursively, and thus would leave images, containers, pods, and volumes present that would be removed by a subsequent call to podman system prune (#7990). - Fixed a bug where the --publish option to podman run and podman create did not properly handle ports specified as a range of ports with no host port specified (#8650). - Fixed a bug where --format did not support JSON output for individual fields (#8444). - Fixed a bug where the podman stats command would fail when run on root containers using the slirp4netns network mode (#7883). - Fixed a bug where the Podman remote client would ask for a password even if the server's SSH daemon did not support password authentication (#8498). - Fixed a bug where the podman stats command would fail if the system did not support one or more of the cgroup controllers Podman supports (#8588). - Fixed a bug where the --mount option to podman create and podman run did not ignore the consistency mount option. - Fixed a bug where failures during the resizing of a container's TTY would print the wrong error. - Fixed a bug where the podman network disconnect command could cause the podman inspect command to fail for a container until it was restarted (#9234). - Fixed a bug where containers created from a read-only rootfs (using the --rootfs option to podman create and podman run) would fail (#9230). - Fixed a bug where specifying Go templates to the --format option to multiple Podman commands did not support the join function (#8773). - Fixed a bug where the podman rmi command could, when run in parallel on multiple images, return layer not known errors (#6510). - Fixed a bug where the podman inspect command on containers displayed unlimited ulimits incorrectly (#9303). - Fixed a bug where Podman would fail to start when a volume was mounted over a directory in a container that contained symlinks that terminated outside the directory and its subdirectories (#6003). API - Libpod API version has been bumped to v3.0.0. - All Libpod Pod APIs have been modified to properly report errors with individual containers. Cases where the operation as a whole succeeded but individual containers failed now report an HTTP 409 error (#8865). - The Compat API for Containers now supports the Rename and Copy APIs. - Fixed a bug where the Compat Prune APIs (for volumes, containers, and images) did not return the amount of space reclaimed in their responses. - Fixed a bug where the Compat and Libpod Exec APIs for Containers would drop errors that occurred prior to the exec session successfully starting (e.g. a "no such file" error if an invalid executable was passed) (#8281) - Fixed a bug where the Volumes field in the Compat Create API for Containers was being ignored (#8649). - Fixed a bug where the NetworkMode field in the Compat Create API for Containers was not handling some values, e.g. container:, correctly. - Fixed a bug where the Compat Create API for Containers did not set container name properly. - Fixed a bug where containers created using the Compat Create API unconditionally used Kubernetes file logging (the default specified in containers.conf is now used). - Fixed a bug where the Compat Inspect API for Containers could include container states not recognized by Docker. - Fixed a bug where Podman did not properly clean up after calls to the Events API when the journald backend was in use, resulting in a leak of file descriptors (#8864). - Fixed a bug where the Libpod Pull endpoint for Images could fail with an index out of range error under certain circumstances (#8870). - Fixed a bug where the Libpod Exists endpoint for Images could panic. - Fixed a bug where the Compat List API for Containers did not support all filters (#8860). - Fixed a bug where the Compat List API for Containers did not properly populate the Status field. - Fixed a bug where the Compat and Libpod Resize APIs for Containers ignored the height and width parameters (#7102). - Fixed a bug where the Compat Search API for Images returned an incorrectly-formatted JSON response (#8758). - Fixed a bug where the Compat Load API for Images did not properly clean up temporary files. - Fixed a bug where the Compat Create API for Networks could panic when an empty IPAM configuration was specified. - Fixed a bug where the Compat Inspect and List APIs for Networks did not include Scope. - Fixed a bug where the Compat Wait endpoint for Containers did not support the same wait conditions that Docker did. * Misc - Updated Buildah to v1.19.2 - Updated the containers/storage library to v1.24.5 - Updated the containers/image library to v5.10.2 - Updated the containers/common library to v0.33.4- Update to v2.2.1 * Changes - Due to a conflict with a previously-removed field, we were forced to modify the way image volumes (mounting images into containers using - -mount type=image) were handled in the database. As a result, containers created in Podman 2.2.0 with image volume will not have them in v2.2.1, and these containers will need to be re-created. * Bugfixes - Fixed a bug where rootless Podman would, on systems without the XDG_RUNTIME_DIR environment variable defined, use an incorrect path for the PID file of the Podman pause process, causing Podman to fail to start (#8539). - Fixed a bug where containers created using Podman v1.7 and earlier were unusable in Podman due to JSON decode errors (#8613). - Fixed a bug where Podman could retrieve invalid cgroup paths, instead of erroring, for containers that were not running. - Fixed a bug where the podman system reset command would print a warning about a duplicate shutdown handler being registered. - Fixed a bug where rootless Podman would attempt to mount sysfs in circumstances where it was not allowed; some OCI runtimes (notably crun) would fall back to alternatives and not fail, but others (notably runc) would fail to run containers. - Fixed a bug where the podman run and podman create commands would fail to create containers from untagged images (#8558). - Fixed a bug where remote Podman would prompt for a password even when the server did not support password authentication (#8498). - Fixed a bug where the podman exec command did not move the Conmon process for the exec session into the correct cgroup. - Fixed a bug where shell completion for the ancestor option to podman ps --filter did not work correctly. - Fixed a bug where detached containers would not properly clean themselves up (or remove themselves if --rm was set) if the Podman command that created them was invoked with --log-level=debug. * API - Fixed a bug where the Compat Create endpoint for Containers did not properly handle the Binds and Mounts parameters in HostConfig. - Fixed a bug where the Compat Create endpoint for Containers ignored the Name query parameter. - Fixed a bug where the Compat Create endpoint for Containers did not properly handle the "default" value for NetworkMode (this value is used extensively by docker-compose) (#8544). - Fixed a bug where the Compat Build endpoint for Images would sometimes incorrectly use the target query parameter as the image's tag. * Misc - Podman v2.2.0 vendored a non-released, custom version of the github.com/spf13/cobra package; this has been reverted to the latest upstream release to aid in packaging. - Updated the containers/image library to v5.9.0- Update to v2.2.0 * Features - Experimental support for shortname aliasing has been added. This is not enabled by default, but can be turned on by setting the environment variable CONTAINERS_SHORT_NAME_ALIASING to on. Documentation is available here and here. - Initial support has been added for the podman network connect and podman network disconnect commands, which allow existing containers to modify what networks they are connected to. At present, these commands can only be used on running containers that did not specify --network=none when they were created. - The podman run command now supports the --network-alias option to set network aliases (additional names the container can be accessed at from other containers via DNS if the dnsname CNI plugin is in use). Aliases can also be added and removed using the new podman network connect and podman network disconnect commands. Please note that this requires a new release (v1.1.0) of the dnsname plugin, and will only work on newly-created CNI networks. - The podman generate kube command now features support for exporting container's memory and CPU limits (#7855). - The podman play kube command now features support for setting CPU and Memory limits for containers (#7742). - The podman play kube command now supports persistent volumes claims using Podman named volumes. - The podman play kube command now supports Kubernetes configmaps via the --configmap option (#7567). - The podman play kube command now supports a --log-driver option to set the log driver for created containers. - The podman play kube command now supports a --start option, enabled by default, to start the pod after creating it. This allows for podman play kube to be more easily used in systemd unitfiles. - The podman network create command now supports the --ipv6 option to enable dual-stack IPv6 networking for created networks (#7302). - The podman inspect command can now inspect pods, networks, and volumes, in addition to containers and images (#6757). - The --mount option for podman run and podman create now supports a new type, image, to mount the contents of an image into the container at a given location. - The Bash and ZSH completions have been completely reworked and have received significant enhancements! Additionally, support for Fish completions and completions for the podman-remote executable have been added. - The --log-opt option for podman create and podman run now supports the max-size option to set the maximum size for a container's logs (#7434). - The --network option to the podman pod create command now allows pods to be configured to use slirp4netns networking, even when run as root (#6097). - The podman pod stop, podman pod pause, podman pod unpause, and podman pod kill commands now work on multiple containers in parallel and should be significantly faster. - The podman search command now supports a --list-tags option to list all available tags for a single image in a single repository. - The podman search command can now output JSON using the --format=json option. - The podman diff and podman mount commands now work with all containers in the storage library, including those not created by Podman. This allows them to be used with Buildah and CRI-O containers. - The podman container exists command now features a --external option to check if a container exists not just in Podman, but also in the storage library. This will allow Podman to identify Buildah and CRI-O containers. - The --tls-verify and --authfile options have been enabled for use with remote Podman. - The /etc/hosts file now includes the container's name and hostname (both pointing to localhost) when the container is run with --net=none (#8095). - The podman events command now supports filtering events based on the labels of the container they occurred on using the --filter label=key=value option. - The podman volume ls command now supports filtering volumes based on their labels using the --filter label=key=value option. - The --volume and --mount options to podman run and podman create now support two new mount propagation options, unbindable and runbindable. - The name and id filters for podman pod ps now match based on a regular expression, instead of requiring an exact match. - The podman pod ps command now supports a new filter status, that matches pods in a certain state. * Changes - The podman network rm --force command will now also remove pods that are using the network (#7791). - The podman volume rm, podman network rm, and podman pod rm commands now return exit code 1 if the object specified for removal does not exist, and exit code 2 if the object is in use and the --force option was not given. - If /dev/fuse is passed into Podman containers as a device, Podman will open it before starting the container to ensure that the kernel module is loaded on the host and the device is usable in the container. - Global Podman options that were not supported with remote operation have been removed from podman-remote (e.g. --cgroup-manager, --storage-driver). - Many errors have been changed to remove repetition and be more clear as to what has gone wrong. - The --storage option to podman rm is now enabled by default, with slightly changed semantics. If the given container does not exist in Podman but does exist in the storage library, it will be removed even without the --storage option. If the container exists in Podman it will be removed normally. The --storage option for podman rm is now deprecated and will be removed in a future release. - The --storage option to podman ps has been renamed to --external. An alias has been added so the old form of the option will continue to work. - Podman now delays the SIGTERM and SIGINT signals during container creation to ensure that Podman is not stopped midway through creating a container resulting in potential resource leakage (#7941). - The podman save command now strips signatures from images it is exporting, as the formats we export to do not support signatures (#7659). - A new Degraded state has been added to pods. Pods that have some, but not all, of their containers running are now considered to be Degraded instead of Running. - Podman will now print a warning when conflicting network options related to port forwarding (e.g. --publish and --net=host) are specified when creating a container. - The --restart on-failure and --rm options for containers no longer conflict. When both are specified, the container will be restarted if it exits with a non-zero error code, and removed if it exits cleanly (#7906). - Remote Podman will no longer use settings from the client's containers.conf; defaults will instead be provided by the server's containers.conf (#7657). - The podman network rm command now has a new alias, podman network remove (#8402). * Bugfixes - Fixed a bug where podman load on the remote client did not error when attempting to load a directory, which is not yet supported for remote use. - Fixed a bug where rootless Podman could hang when the newuidmap binary was not installed (#7776). - Fixed a bug where the --pull option to podman run, podman create, and podman build did not match Docker's behavior. - Fixed a bug where sysctl settings from the containers.conf configuration file were applied, even if the container did not join the namespace associated with a sysctl. - Fixed a bug where Podman would not return the text of errors encounted when trying to run a healthcheck for a container. - Fixed a bug where Podman was accidentally setting the containers environment variable in addition to the expected container environment variable. - Fixed a bug where rootless Podman using CNI networking did not properly clean up DNS entries for removed containers (#7789). - Fixed a bug where the podman untag --all command was not supported with remote Podman. - Fixed a bug where the podman system service command could time out even if active attach connections were present (#7826). - Fixed a bug where the podman system service command would sometimes never time out despite no active connections being present. - Fixed a bug where Podman's handling of capabilities, specifically inheritable, did not match Docker's. - Fixed a bug where podman run would fail if the image specified was a manifest list and had already been pulled (#7798). - Fixed a bug where Podman did not take search registries into account when looking up images locally (#6381). - Fixed a bug where the podman manifest inspect command would fail for images that had already been pulled (#7726). - Fixed a bug where rootless Podman would not add supplemental GIDs to containers when when a user, but not a group, was set via the --user option to podman create and podman run and sufficient GIDs were available to add the groups (#7782). - Fixed a bug where remote Podman commands did not properly handle cases where the user gave a name that could also be a short ID for a pod or container (#7837). - Fixed a bug where podman image prune could leave images ready to be pruned after podman image prune was run (#7872). - Fixed a bug where the podman logs command with the journald log driver would not read all available logs (#7476). - Fixed a bug where the --rm and --restart options to podman create and podman run did not conflict when a restart policy that is not on-failure was chosen (#7878). - Fixed a bug where the --format "table {{ .Field }}" option to numerous Podman commands ceased to function on Podman v2.0 and up. - Fixed a bug where pods did not properly share an SELinux label between their containers, resulting in containers being unable to see the processes of other containers when the pod shared a PID namespace (#7886). - Fixed a bug where the --namespace option to podman ps did not work with the remote client (#7903). - Fixed a bug where rootless Podman incorrectly calculated the number of UIDs available in the container if multiple different ranges of UIDs were specified. - Fixed a bug where the /etc/hosts file would not be correctly populated for containers in a user namespace (#7490). - Fixed a bug where the podman network create and podman network remove commands could race when run in parallel, with unpredictable results (#7807). - Fixed a bug where the -p option to podman run, podman create, and podman pod create would, when given only a single number (e.g. -p 80), assign the same port for both host and container, instead of generating a random host port (#7947). - Fixed a bug where Podman containers did not properly store the cgroup manager they were created with, causing them to stop functioning after the cgroup manager was changed in containers.conf or with the --cgroup-manager option (#7830). - Fixed a bug where the podman inspect command did not include information on the CNI networks a container was connected to if it was not running. - Fixed a bug where the podman attach command would not print a newline after detaching from the container (#7751). - Fixed a bug where the HOME environment variable was not set properly in containers when the --userns=keep-id option was set (#8004). - Fixed a bug where the podman container restore command could panic when the container in question was in a pod (#8026). - Fixed a bug where the output of the podman image trust show --raw command was not properly formatted. - Fixed a bug where the podman runlabel command could panic if a label to run was not given (#8038). - Fixed a bug where the podman run and podman start --attach commands would exit with an error when the user detached manually using the detach keys on remote Podman (#7979). - Fixed a bug where rootless CNI networking did not use the dnsname CNI plugin if it was not available on the host, despite it always being available in the container used for rootless networking (#8040). - Fixed a bug where Podman did not properly handle cases where an OCI runtime is specified by its full path, and could revert to using another OCI runtime with the same binary path that existed in the system $PATH on subsequent invocations. - Fixed a bug where the --net=host option to podman create and podman run would cause the /etc/hosts file to be incorrectly populated (#8054). - Fixed a bug where the podman inspect command did not include container network information when the container shared its network namespace (IE, joined a pod or another container's network namespace via --net=container:...) (#8073). - Fixed a bug where the podman ps command did not include information on all ports a container was publishing. - Fixed a bug where the podman build command incorrectly forwarded STDIN into build containers from RUN instructions. - Fixed a bug where the podman wait command's --interval option did not work when units were not specified for the duration (#8088). - Fixed a bug where the --detach-keys and --detach options could be passed to podman create despite having no effect (and not making sense in that context). - Fixed a bug where Podman could not start containers if running on a system without a /etc/resolv.conf file (which occurs on some WSL2 images) (#8089). - Fixed a bug where the --extract option to podman cp was nonfunctional. - Fixed a bug where the --cidfile option to podman run would, when the container was not run with --detach, only create the file after the container exited (#8091). - Fixed a bug where the podman images and podman images -a commands could panic and not list any images when certain improperly-formatted images were present in storage (#8148). - Fixed a bug where the podman events command could, when the journald events backend was in use, become nonfunctional when a badly-formatted event or a log message that container certain string was present in the journal (#8125). - Fixed a bug where remote Podman would, when using SSH transport, not authenticate to the server using hostkeys when connecting on a port other than 22 (#8139). - Fixed a bug where the podman attach command would not exit when containers stopped (#8154). - Fixed a bug where Podman did not properly clean paths before verifying them, resulting in Podman refusing to start if the root or temporary directories were specified with extra trailing / characters (#8160). - Fixed a bug where remote Podman did not support hashed hostnames in the known_hosts file on the host for establishing connections (#8159). - Fixed a bug where the podman image exists command would return non-zero (false) when multiple potential matches for the given name existed. - Fixed a bug where the podman manifest inspect command on images that are not manifest lists would error instead of inspecting the image (#8023). - Fixed a bug where the podman system service command would fail if the directory the Unix socket was to be created inside did not exist (#8184). - Fixed a bug where pods that shared the IPC namespace (which is done by default) did not share a /dev/shm filesystem between all containers in the pod (#8181). - Fixed a bug where filters passed to podman volume list were not inclusive (#6765). - Fixed a bug where the podman volume create command would fail when the volume's data directory already existed (as might occur when a volume was not completely removed) (#8253). - Fixed a bug where the podman run and podman create commands would deadlock when trying to create a container that mounted the same named volume at multiple locations (e.g. podman run -v testvol:/test1 -v testvol:/test2) (#8221). - Fixed a bug where the parsing of the --net option to podman build was incorrect (#8322). - Fixed a bug where the podman build command would print the ID of the built image twice when using remote Podman (#8332). - Fixed a bug where the podman stats command did not show memory limits for containers (#8265). - Fixed a bug where the podman pod inspect command printed the static MAC address of the pod in a non-human-readable format (#8386). - Fixed a bug where the --tls-verify option of the podman play kube command had its logic inverted (false would enforce the use of TLS, true would disable it). - Fixed a bug where the podman network rm command would error when trying to remove macvlan networks and rootless CNI networks (#8491). - Fixed a bug where Podman was not setting sane defaults for missing XDG_ environment variables. - Fixed a bug where remote Podman would check if volume paths to be mounted in the container existed on the host, not the server (#8473). - Fixed a bug where the podman manifest create and podman manifest add commands on local images would drop any images in the manifest not pulled by the host. - Fixed a bug where networks made by podman network create did not include the tuning plugin, and as such did not support setting custom MAC addresses (#8385). - Fixed a bug where container healthchecks did not use $PATH when searching for the Podman executable to run the healthcheck. - Fixed a bug where the --ip-range option to podman network create did not properly handle non-classful subnets when calculating the last usable IP for DHCP assignment (#8448). - Fixed a bug where the podman container ps alias for podman ps was missing (#8445). * API - The Compat Create endpoint for Container has received a major refactor to share more code with the Libpod Create endpoint, and should be significantly more stable. - A Compat endpoint for exporting multiple images at once, GET /images/get, has been added (#7950). - The Compat Network Connect and Network Disconnect endpoints have been added. - Endpoints that deal with image registries now support a X-Registry-Config header to specify registry authentication configuration. - The Compat Create endpoint for images now properly supports specifying images by digest. - The Libpod Build endpoint for images now supports an httpproxy query parameter which, if set to true, will forward the server's HTTP proxy settings into the build container for RUN instructions. - The Libpod Untag endpoint for images will now remove all tags for the given image if no repository and tag are specified for removal. - Fixed a bug where the Ping endpoint misspelled a header name (Libpod-Buildha-Version instead of Libpod-Buildah-Version). - Fixed a bug where the Ping endpoint sent an extra newline at the end of its response where Docker did not. - Fixed a bug where the Compat Logs endpoint for containers did not send a newline character after each log line. - Fixed a bug where the Compat Logs endpoint for containers would mangle line endings to change newline characters to add a preceding carriage return (#7942). - Fixed a bug where the Compat Inspect endpoint for Containers did not properly list the container's stop signal (#7917). - Fixed a bug where the Compat Inspect endpoint for Containers formatted the container's create time incorrectly (#7860). - Fixed a bug where the Compat Inspect endpoint for Containers did not include the container's Path, Args, and Restart Count. - Fixed a bug where the Compat Inspect endpoint for Containers prefixed added and dropped capabilities with CAP_ (Docker does not do so). - Fixed a bug where the Compat Info endpoint for the Engine did not include configured registries. - Fixed a bug where the server could panic if a client closed a connection midway through an image pull (#7896). - Fixed a bug where the Compat Create endpoint for volumes returned an error when a volume with the same name already existed, instead of succeeding with a 201 code (#7740). - Fixed a bug where a client disconnecting from the Libpod or Compat events endpoints could result in the server using 100% CPU (#7946). - Fixed a bug where the "no such image" error message sent by the Compat Inspect endpoint for Images returned a 404 status code with an error that was improperly formatted for Docker compatibility. - Fixed a bug where the Compat Create endpoint for networks did not properly set a default for the driver parameter if it was not provided by the client. - Fixed a bug where the Compat Inspect endpoint for images did not populate the RootFS field of the response. - Fixed a bug where the Compat Inspect endpoint for images would omit the ParentId field if the image had no parent, and the Created field if the image did not have a creation time. - Fixed a bug where the Compat Remove endpoint for Networks did not support the Force query parameter.- add dependency to timezone package or podman fails to build a container (bsc#1178122)- Added patch varlink.patch to disable needless varlink code generation. This would cause compile failures in OBS. (https://github.com/containers/podman/pull/7854) - Cleanup %build section a bit and no longer build in GOPATH. This shouldn't be needed anymore. - Path BUILDFLAGS via enviroment variable to allow it being appended to the corresponding Makefile variable instead of completely overriding it. - Install new auto-update system units - Update to v2.1.1 (bsc#1178392): * Changes - The `podman info` command now includes the cgroup manager Podman is using. * API - The REST API now includes a Server header in all responses. - Fixed a bug where the Libpod and Compat Attach endpoints could terminate early, before sending all output from the container. - Fixed a bug where the Compat Create endpoint for containers did not properly handle the Interactive parameter. - Fixed a bug where the Compat Kill endpoint for containers could continue to run after a fatal error. - Fixed a bug where the Limit parameter of the Compat List endpoint for Containers did not properly handle a limit of 0 (returning nothing, instead of all containers) [#7722]. - The Libpod Stats endpoint for containers is being deprecated and will be replaced by a similar endpoint with additional features in a future release. - Changes in v2.1.0 * Features - A new command, `podman image mount`, has been added. This allows for an image to be mounted, read-only, to inspect its contents without creating a container from it [#1433]. - The `podman save` and `podman load` commands can now create and load archives containing multiple images [#2669]. - Rootless Podman now supports all `podman network` commands, and rootless containers can now be joined to networks. - The performance of `podman build` on `ADD` and `COPY` instructions has been greatly improved, especially when a `.dockerignore` is present. - The `podman run` and `podman create` commands now support a new mode for the `--cgroups` option, `--cgroups=split`. Podman will create two cgroups under the cgroup it was launched in, one for the container and one for Conmon. This mode is useful for running Podman in a systemd unit, as it ensures that all processes are retained in systemd's cgroup hierarchy [#6400]. - The `podman run` and `podman create` commands can now specify options to slirp4netns by using the `--network` option as follows: `--net slirp4netns:opt1,opt2`. This allows for, among other things, switching the port forwarder used by slirp4netns away from rootlessport. - The `podman ps` command now features a new option, `--storage`, to show containers from Buildah, CRI-O and other applications. - The `podman run` and `podman create` commands now feature a `--sdnotify` option to control the behavior of systemd's sdnotify with containers, enabling improved support for Podman in `Type=notify` units. - The `podman run` command now features a `--preserve-fds` opton to pass file descriptors from the host into the container [#6458]. - The `podman run` and `podman create` commands can now create overlay volume mounts, by adding the `:O` option to a bind mount (e.g. `-v /test:/test:O`). Overlay volume mounts will mount a directory into a container from the host and allow changes to it, but not write those changes back to the directory on the host. - The `podman play kube` command now supports the Socket HostPath type [#7112]. - The `podman play kube` command now supports read-only mounts. - The `podman play kube` command now supports setting labels on pods from Kubernetes metadata labels. - The `podman play kube` command now supports setting container restart policy [#7656]. - The `podman play kube` command now properly handles `HostAlias` entries. - The `podman generate kube` command now adds entries to `/etc/hosts` from `--host-add` generated YAML as `HostAlias` entries. - The `podman play kube` and `podman generate kube` commands now properly support `shareProcessNamespace` to share the PID namespace in pods. - The `podman volume ls` command now supports the `dangling` filter to identify volumes that are dangling (not attached to any container). - The `podman run` and `podman create` commands now feature a `--umask` option to set the umask of the created container. - The `podman create` and `podman run` commands now feature a `--tz` option to set the timezone within the container [#5128]. - Environment variables for Podman can now be added in the `containers.conf` configuration file. - The `--mount` option of `podman run` and `podman create` now supports a new mount type, `type=devpts`, to add a `devpts` mount to the container. This is useful for containers that want to mount `/dev/` from the host into the container, but still create a terminal. - The `--security-opt` flag to `podman run` and `podman create` now supports a new option, `proc-opts`, to specify options for the container's `/proc` filesystem. - Podman with the `crun` OCI runtime now supports a new option to `podman run` and `podman create`, `--cgroup-conf`, which allows for advanced configuration of cgroups on cgroups v2 systems. - The `podman create` and `podman run` commands now support a `--override-variant` option, to override the architecture variant of the image that will be pulled and ran. - A new global option has been added to Podman, `--runtime-flags`, which allows for setting flags to use when the OCI runtime is called. - The `podman manifest add` command now supports the `--cert-dir`, `--auth-file`, `--creds`, and `--tls-verify` options. * Security - This release resolves CVE-2020-14370, in which environment variables could be leaked between containers created using the Varlink API. * Changes - Podman will now retry pulling an image 3 times if a pull fails due to network errors. - The `podman exec` command would previously print error messages (e.g. `exec session exited with non-zero exit code - 1`) when the command run exited with a non-0 exit code. It no longer does this. The `podman exec` command will still exit with the same exit code as the command run in the container did. - Error messages when creating a container or pod with a name that is already in use have been improved. - For read-only containers running systemd init, Podman creates a tmpfs filesystem at `/run`. This was previously limited to 65k in size and mounted `noexec`, but is now unlimited size and mounted `exec`. - The `podman system reset` command no longer removes configuration files for rootless Podman. * API - The Libpod API version has been bumped to v2.0.0 due to a breaking change in the Image List API. - Docker-compatible Volume Endpoints (Create, Inspect, List, Remove, Prune) are now available! - Added an endpoint for generating systemd unit files for containers. - The `last` parameter to the Libpod container list endpoint now has an alias, `limit` [#6413]. - The Libpod image list API new returns timestamps in Unix format, as integer, as opposed to as strings - The Compat Inspect endpoint for containers now includes port information in NetworkSettings. - The Compat List endpoint for images now features limited support for the (deprecated) `filter` query parameter [#6797]. - Fixed a bug where the Compat Create endpoint for containers was not correctly handling bind mounts. - Fixed a bug where the Compat Create endpoint for containers would not return a 404 when the requested image was not present. - Fixed a bug where the Compat Create endpoint for containers did not properly handle Entrypoint and Command from images. - Fixed a bug where name history information was not properly added in the Libpod Image List endpoint. - Fixed a bug where the Libpod image search endpoint improperly populated the Description field of responses. - Added a `noTrunc` option to the Libpod image search endpoint. - Fixed a bug where the Pod List API would return null, instead of an empty array, when no pods were present [#7392]. - Fixed a bug where endpoints that hijacked would do perform the hijack too early, before being ready to send and receive data [#7195]. - Fixed a bug where Pod endpoints that can operate on multiple containers at once (e.g. Kill, Pause, Unpause, Stop) would not forward errors from individual containers that failed. - The Compat List endpoint for networks now supports filtering results [#7462]. - Fixed a bug where the Top endpoint for pods would return both a 500 and 404 when run on a non-existant pod. - Fixed a bug where Pull endpoints did not stream progress back to the client. - The Version endpoints (Libpod and Compat) now provide version in a format compatible with Docker. - All non-hijacking responses to API requests should not include headers with the version of the server. - Fixed a bug where Libpod and Compat Events endpoints did not send response headers until the first event occurred [#7263]. - Fixed a bug where the Build endpoints (Compat and Libpod) did not stream progress to the client. - Fixed a bug where the Stats endpoints (Compat and Libpod) did not properly handle clients disconnecting. - Fixed a bug where the Ignore parameter to the Libpod Stop endpoint was not performing properly. - Fixed a bug where the Compat Logs endpoint for containers did not stream its output in the correct format [#7196].- Cleanup %install section to use "make install" - install missing systemd units for the new Rest API (bsc#1175957) and a few man-pages that where missing before - Drop varlink API related bits (in favor of the new API) - fix install location for zsh completions- Update to v2.0.6 * Fixed a bug where running systemd in a container on a cgroups v1 system would fail. * Fixed a bug where /etc/passwd could be re-created every time a container is restarted if the container's /etc/passwd did not contain an entry for the user the container was started as. * Fixed a bug where containers without an /etc/passwd file specifying a non-root user would not start. * Fixed a bug where the --remote flag would sometimes not make remote connections and would instead attempt to run Podman locally.- Update to v2.0.5 (bsc#1175821) * Features - Rootless Podman will now add an entry to /etc/passwd for the user who ran Podman if run with --userns=keep-id. - The podman system connection command has been reworked to support multiple connections, and reenabled for use! - Podman now has a new global flag, --connection, to specify a connection to a remote Podman API instance. * Changes - Podman's automatic systemd integration (activated by the --systemd=true flag, set by default) will now activate for containers using /usr/local/sbin/init as their command, instead of just /usr/sbin/init and /sbin/init (and any path ending in systemd). - Seccomp profiles specified by the --security-opt seccomp=... flag to podman create and podman run will now be honored even if the container was created using --privileged. * Bugfixes - Fixed a bug where the podman play kube would not honor the hostIP field for port forwarding (#5964). - Fixed a bug where the podman generate systemd command would panic on an invalid restart policy being specified (#7271). - Fixed a bug where the podman images command could take a very long time (several minutes) to complete when a large number of images were present. - Fixed a bug where the podman logs command with the --tail flag would not work properly when a large amount of output would be printed ((#7230)[https://github.com//issues/7230]). - Fixed a bug where the podman exec command with remote Podman would not return a non-zero exit code when the exec session failed to start (e.g. invoking a non-existent command) (#6893). - Fixed a bug where the podman load command with remote Podman would did not honor user-specified tags (#7124). - Fixed a bug where the podman system service command, when run as a non-root user by Systemd, did not properly handle the Podman pause process and would not restart properly as a result (#7180). - Fixed a bug where the --publish flag to podman create, podman run, and podman pod create did not properly handle a host IP of 0.0.0.0 (attempting to bind to literal 0.0.0.0, instead of all IPs on the system) (#7104). - Fixed a bug where the podman start --attach command would not print the container's exit code when the command exited due to the container exiting. - Fixed a bug where the podman rm command with remote Podman would not remove volumes, even if the --volumes flag was specified (#7128). - Fixed a bug where the podman run command with remote Podman and the --rm flag could exit before the container was fully removed. - Fixed a bug where the --pod new:... flag to podman run and podman create would create a pod that did not share any namespaces. - Fixed a bug where the --preserve-fds flag to podman run and podman exec could close the wrong file descriptors while trying to close user-provided descriptors after passing them into the container. - Fixed a bug where default environment variables ($PATH and $TERM) were not set in containers when not provided by the image. - Fixed a bug where pod infra containers were not properly unmounted after exiting. - Fixed a bug where networks created with podman network create with an IPv6 subnet did not properly set an IPv6 default route. - Fixed a bug where the podman save command would not work properly when its output was piped to another command (#7017). - Fixed a bug where containers using a systemd init on a cgroups v1 system could leak mounts under /sys/fs/cgroup/systemd to the host. - Fixed a bug where podman build would not generate an event on completion (#7022). - Fixed a bug where the podman history command with remote Podman printed incorrect creation times for layers (#7122). - Fixed a bug where Podman would not create working directories specified by the container image if they did not exist. - Fixed a bug where Podman did not clear CMD from the container image if the user overrode ENTRYPOINT (#7115). - Fixed a bug where error parsing image names were not fully reported (part of the error message containing the exact issue was dropped). - Fixed a bug where the podman images command with remote Podman did not support printing image tags in Go templates supplied to the --format flag (#7123). - Fixed a bug where the podman rmi --force command would not attempt to unmount containers it was removing, which could cause a failure to remove the image. - Fixed a bug where the podman generate systemd --new command could incorrectly quote arguments to Podman that contained whitespace, leading to nonfunctional unit files (#7285). - Fixed a bug where the podman version command did not properly include build time and Git commit. - Fixed a bug where running systemd in a Podman container on a system that did not use the systemd cgroup manager would fail (#6734). - Fixed a bug where capabilities from --cap-add were not properly added when a container was started as a non-root user via --user. - Fixed a bug where Pod infra containers were not properly cleaned up when they stopped, causing networking issues (#7103). * API - Fixed a bug where the libpod and compat Build endpoints did not accept the application/tar content type (instead only accepting application/x-tar) (#7185). - Fixed a bug where the libpod Exists endpoint would attempt to write a second header in some error conditions (#7197). - Fixed a bug where compat and libpod Network Inspect and Network Remove endpoints would return a 500 instead of 404 when the requested network was not found. - Added a versioned _ping endpoint (e.g. http://localhost/v1.40/_ping). - Fixed a bug where containers started through a systemd-managed instance of the REST API would be shut down when podman system service shut down due to its idle timeout (#7294). - Added stronger parameter verification for the libpod Network Create endpoint to ensure subnet mask is a valid value. - The Pod URL parameter to the Libpod Container List endpoint has been deprecated; the information previously gated by the Pod boolean will now be included in the response unconditionally. * Misc - Updated Buildah to v1.15.1 - Updated containers/image library to v5.5.2- Correct invalid use of %{_libexecdir} to ensure files should be in /usr/lib- Change hard requires for AppArmor to Recommends. They are not needed for runtime or with SELinux but already installed if AppArmor is used [jsc#SMO-15]- Add BuildRequires for pkg-config(libselinux) to build with SELinux support [jsc#SMO-15]- Update to v2.0.4 * Fixed a bug where the output of podman image search did not populate the Description field as it was mistakenly assigned to the ID field. * Fixed a bug where podman build - and podman build on an HTTP target would fail. * Fixed a bug where rootless Podman would improperly chown the copied-up contents of anonymous volumes (#7130). * Fixed a bug where Podman would sometimes HTML-escape special characters in its CLI output. * Fixed a bug where the podman start --attach --interactive command would print the container ID of the container attached to when exiting (#7068). * Fixed a bug where podman run --ipc=host --pid=host would only set --pid=host and not --ipc=host (#7100). * Fixed a bug where the --publish argument to podman run, podman create and podman pod create would not allow binding the same container port to more than one host port (#7062). * Fixed a bug where incorrect arguments to podman images --format could cause Podman to segfault. * Fixed a bug where podman rmi --force on an image ID with more than one name and at least one container using the image would not completely remove containers using the image (#7153). * Fixed a bug where memory usage in bytes and memory use percentage were swapped in the output of podman stats - -format=json. * Fixed a bug where the libpod and compat events endpoints would fail if no filters were specified (#7078). * Fixed a bug where the CgroupVersion field in responses from the compat Info endpoint was prefixed by "v" (instead of just being "1" or "2", as is documented).- Remove obsolete libpod.conf from Package sources- libpod got renamed to podman on GitHub. Point _service file to the new name. - Remove obsolete old Requires on libcontainers-image and -storage all of that is inside libcontainers-common - Require a new enough libcontainers-common version to have the default containers.conf installed. - Remove deprecated libpod.conf and create an update notice pointing to containers.conf for user that made changes to libpod.conf- Suggest katacontainers instead of recommending it. It's not enabled by default, so it's just bloat- Update to v2.0.3 * Fix handling of entrypoint * log API: add context to allow for cancelling * fix API: Create container with an invalid configuration * Remove all instances of named return "err" from Libpod * Fix: Correct connection counters for hijacked connections * Fix: Hijacking v2 endpoints to follow rfc 7230 semantics * Remove hijacked connections from active connections list * version/info: format: allow more json variants * Correctly print STDOUT on non-terminal remote exec * Fix container and pod create commands for remote create * Mask out /sys/dev to prevent information leak from the host * Ensure sig-proxy default is propagated in start * Add SystemdMode to inspect for containers * When determining systemd mode, use full command * Fix lint * Populate remaining unused fields in `pod inspect` * Include infra container information in `pod inspect` * play-kube: add suport for "IfNotPresent" pull type * docs: user namespace can't be shared in pods * Fix "Error: unrecognized protocol \"TCP\" in port mapping" * Error on rootless mac and ip addresses * Fix & add notes regarding problematic language in codebase * abi: set default umask and rlimits * Used reference package with errors for parsing tag * fix: system df error when an image has no name * Fix Generate API title/description * Add noop function disable-content-trust * fix play kube doesn't override dockerfile ENTRYPOINT * Support default profile for apparmor * Bump github.com/containers/common to v0.14.6 * events endpoint: backwards compat to old type * events endpoint: fix panic and race condition * Switch references from libpod.conf to containers.conf * podman.service: set type to simple * podman.service: set doc to podman-system-service * podman.service: use default registries.conf * podman.service: use default killmode * podman.service: remove stop timeout * systemd: symlink user->system * vendor golang.org/x/text@v0.3.3 * Fix a bug where --pids-limit was parsed incorrectly * search: allow wildcards * [CI:DOCS]Do not copy policy.json into gating image * Fix systemd pid 1 test * Cirrus: Rotate keys post repo. rename - The libpod.conf(5) man page got removed and all references are now pointing towards containers.conf(5), which will be part of the libcontainers-common package.- Update to podman v2.0.2 * fix race condition in `libpod.GetEvents(...)` * Fix bug where `podman mount` didn't error as rootless * remove podman system connection * Fix imports to ensure v2 is used with libpod * Update release notes for v2.0.2 * specgen: fix order for setting rlimits * Ensure umask is set appropriately for 'system service' * generate systemd: improve pod-flags filter * Fix a bug with APIv2 compat network remove to log an ErrNetworkNotFound instead of nil * Fixes --remote flag issues * Pids-limit should only be set if the user set it * Set console mode for windows * Allow empty host port in --publish flag * Add a note on the APIs supported by `system service` * fix: Don't override entrypoint if it's `nil` * Set TMPDIR to /var/tmp by default if not set * test: add tests for --user and volumes * container: move volume chown after spec generation * libpod: volume copyup honors namespace mappings * Fix `system service` panic from early hangup in events * stop podman service in e2e tests * Print errors from individual containers in pods * auto-update: clarify systemd-unit requirements * podman ps truncate the command * move go module to v2 * Vendor containers/common v0.14.4 * Bump to imagebuilder v1.1.6 on v2 branch * Account for non-default port number in image name - Changes since v2.0.1 * Update release notes with further v2.0.1 changes * Fix inspect to display multiple label: changes * Set syslog for exit commands on log-level=debug * Friendly amendment for pr 6751 * podman run/create: support all transports * systemd generate: allow manual restart of container units in pods * Revert sending --remote flag to containers * Print port mappings in `ps` for ctrs sharing network * vendor github.com/containers/common@v0.14.3 * Update release notes for v2.0.1 * utils: drop default mapping when running uid!=0 * Set stop signal to 15 when not explicitly set * podman untag: error if tag doesn't exist * Reformat inspect network settings * APIv2: Return `StatusCreated` from volume creation * APIv2:fix: Remove `/json` from compat network EPs * Fix ssh-agent support * libpod: specify mappings to the storage * APIv2:doc: Fix swagger doc to refer to volumes * Add podman network to bash command completions * Fix typo in manpage for `podman auto update`. * Add JSON output field for ps * V2 podman system connection * image load: no args required * Re-add PODMAN_USERNS environment variable * Fix conflicts between privileged and other flags * Bump required go version to 1.13 * Add explicit command to alpine container in test case. * Use POLL_DURATION for timer * Stop following logs using timers * "pod" was being truncated to "po" in the names of the generated systemd unit files. * rootless_linux: improve error message * Fix podman build handling of --http-proxy flag * correct the absolute path of `rm` executable * Makefile: allow customizable GO_BUILD * Cirrus: Change DEST_BRANCH to v2.0- Update to podman v2.0.0 * The `podman generate systemd` command now supports the `--new` flag when used with pods, allowing portable services for pods to be created. * The `podman play kube` command now supports running Kubernetes Deployment YAML. * The `podman exec` command now supports the `--detach` flag to run commands in the container in the background. * The `-p` flag to `podman run` and `podman create` now supports forwarding ports to IPv6 addresses. * The `podman run`, `podman create` and `podman pod create` command now support a `--replace` flag to remove and replace any existing container (or, for `pod create`, pod) with the same name * The `--restart-policy` flag to `podman run` and `podman create` now supports the `unless-stopped` restart policy. * The `--log-driver` flag to `podman run` and `podman create` now supports the `none` driver, which does not log the container's output. * The `--mount` flag to `podman run` and `podman create` now accepts `readonly` option as an alias to `ro`. * The `podman generate systemd` command now supports the `--container-prefix`, `--pod-prefix`, and `--separator` arguments to control the name of generated unit files. * The `podman network ls` command now supports the `--filter` flag to filter results. * The `podman auto-update` command now supports specifying an authfile to use when pulling new images on a per-container basis using the `io.containers.autoupdate.authfile` label. * Fixed a bug where the `podman exec` command would log to journald when run in containers loggined to journald ([#6555](https://github.com/containers/libpod/issues/6555)). * Fixed a bug where the `podman auto-update` command would not preserve the OS and architecture of the original image when pulling a replacement ([#6613](https://github.com/containers/libpod/issues/6613)). * Fixed a bug where the `podman cp` command could create an extra `merged` directory when copying into an existing directory ([#6596](https://github.com/containers/libpod/issues/6596)). * Fixed a bug where the `podman pod stats` command would crash on pods run with `--network=host` ([#5652](https://github.com/containers/libpod/issues/5652)). * Fixed a bug where containers logs written to journald did not include the name of the container. * Fixed a bug where the `podman network inspect` and `podman network rm` commands did not properly handle non-default CNI configuration paths ([#6212](https://github.com/containers/libpod/issues/6212)). * Fixed a bug where Podman did not properly remove containers when using the Kata containers OCI runtime. * Fixed a bug where `podman inspect` would sometimes incorrectly report the network mode of containers started with `--net=none`. * Podman is now better able to deal with cases where `conmon` is killed before the container it is monitoring. - Requires go 1.13 now- Update to podman v1.9.3: * Fixed a bug where, on FIPS enabled hosts, FIPS mode secrets were not properly mounted into containers * Fixed a bug where builds run over Varlink would hang * Fixed a bug where podman save would fail when the target image was specified by digest * Fixed a bug where rootless containers with ports forwarded to them could panic and dump core due to a concurrency issue (#6018) * Fixed a bug where rootless Podman could race when opening the rootless user namespace, resulting in commands failing to run * Fixed a bug where HTTP proxy environment variables forwarded into the container by the --http-proxy flag could not be overridden by --env or --env-file * Fixed a bug where rootless Podman was setting resource limits on cgroups v2 systems that were not using systemd-managed cgroups (and thus did not support resource limits), resulting in containers failing to start- Update podman to v1.9.1: * Bugfixes - Fixed a bug where healthchecks could become nonfunctional if container log paths were manually set with --log-path and multiple container logs were placed in the same directory - Fixed a bug where rootless Podman could, when using an older libpod.conf, print numerous warning messages about an invalid CGroup manager config - Fixed a bug where rootless Podman would sometimes fail to close the rootless user namespace when joining it * Misc - Updated containers/common to v0.8.2- Switched to simple `make binaries` for building podman - Update podman to v1.9.0: * Features - Experimental support has been added for podman run - -userns=auto, which automatically allocates a unique UID and GID range for the new container's user namespace - The podman play kube command now has a --network flag to place the created pod in one or more CNI networks - The podman commit command now supports an --iidfile flag to write the ID of the committed image to a file - Initial support for the new containers.conf configuration file has been added. containers.conf allows for much more detailed configuration of some Podman functionality * Changes - There has been a major cleanup of the podman info command resulting in breaking changes. Many fields have been renamed to better suit usage with APIv2 - All uses of the --timeout flag have been switched to prefer the alternative --time. The --timeout flag will continue to work, but man pages and --help will use the --time flag instead * Bugfixes - Fixed a bug where some volume mounts from the host would sometimes not properly determine the flags they should use when mounting - Fixed a bug where Podman was not propagating $PATH to Conmon and the OCI runtime, causing issues for some OCI runtimes that required it - Fixed a bug where rootless Podman would print error messages about missing support for systemd cgroups when run in a container with no cgroup support - Fixed a bug where podman play kube would not properly handle container-only port mappings (#5610) - Fixed a bug where the podman container prune command was not pruning containers in the created and configured states - Fixed a bug where Podman was not properly removing CNI IP address allocations after a reboot (#5433) - Fixed a bug where Podman was not properly applying the default Seccomp profile when --security-opt was not given at the command line * HTTP API - Many Libpod API endpoints have been added, including Changes, Checkpoint, Init, and Restore - Resolved issues where the podman system service command would time out and exit while there were still active connections - Stability overall has greatly improved as we prepare the API for a beta release soon with Podman 2.0 * Misc - The default infra image for pods has been upgraded to k8s.gcr.io/pause:3.2 (from 3.1) to address a bug in the architecture metadata for non-AMD64 images - The slirp4netns networking utility in rootless Podman now uses Seccomp filtering where available for improved security - Updated Buildah to v1.14.8 - Updated containers/storage to v1.18.2 - Updated containers/image to v5.4.3 - Updated containers/common to v0.8.1- Add "systemd" BUILDFLAGS to build with support for journald logging (bsc#1162432)- Use infra_image pause:3.2- Fix dependency on slirp4netns. We need at least 0.4.0 now (bsc#1167850)- Update podman to v1.8.2: * Features - Initial support for automatically updating containers managed via Systemd unit files has been merged. This allows containers to automatically upgrade if a newer version of their image becomes available * Bugfixes - Fixed a bug where unit files generated by podman generate systemd --new would not force containers to detach, causing the unit to time out when trying to start - Fixed a bug where podman system reset could delete important system directories if run as rootless on installations created by older Podman (#4831) - Fixed a bug where image built by podman build would not properly set the OS and Architecture they were built with (#5503) - Fixed a bug where attached podman run with --sig-proxy enabled (the default), when built with Go 1.14, would repeatedly send signal 23 to the process in the container and could generate errors when the container stopped (#5483) - Fixed a bug where rootless podman run commands could hang when forwarding ports - Fixed a bug where rootless Podman would not work when /proc was mounted with the hidepid option set - Fixed a bug where the podman system service command would use large amounts of CPU when --timeout was set to 0 (#5531) * HTTP API - Initial support for Libpod endpoints related to creating and operating on image manifest lists has been added - The Libpod Healthcheck and Events API endpoints are now supported - The Swagger endpoint can now handle cases where no Swagger documentation has been generated * Misc - Updated Buildah to v1.14.3 - Updated containers/storage to v1.16.5 - Several performance improvements have been made to creating containers, which should somewhat improve the performance of podman create and podman run- Update podman to v1.8.1: * Features - Many networking-related flags have been added to podman pod create to enable customization of pod networks, including - -add-host, --dns, --dns-opt, --dns-search, --ip, - -mac-address, --network, and --no-hosts - The podman ps --format=json command now includes the ID of the image containers were created with - The podman run and podman create commands now feature an - -rmi flag to remove the image the container was using after it exits (if no other containers are using said image) ([#4628](https://github.com/containers/libpod/issues/4628)) - The podman create and podman run commands now support the - -device-cgroup-rule flag (#4876) - While the HTTP API remains in alpha, many fixes and additions have landed. These are documented in a separate subsection below - The podman create and podman run commands now feature a - -no-healthcheck flag to disable healthchecks for a container (#5299) - Containers now recognize the io.containers.capabilities label, which specifies a list of capabilities required by the image to run. These capabilities will be used as long as they are more restrictive than the default capabilities used - YAML produced by the podman generate kube command now includes SELinux configuration passed into the container via - -security-opt label=... (#4950) * Bugfixes - Fixed CVE-2020-1726, a security issue where volumes manually populated before first being mounted into a container could have those contents overwritten on first being mounted into a container - Fixed a bug where Podman containers with user namespaces in CNI networks with the DNS plugin enabled would not have the DNS plugin's nameserver added to their resolv.conf ([#5256](https://github.com/containers/libpod/issues/5256)) - Fixed a bug where trailing / characters in image volume definitions could cause them to not be overridden by a user-specified mount at the same location ([#5219](https://github.com/containers/libpod/issues/5219)) - Fixed a bug where the label option in libpod.conf, used to disable SELinux by default, was not being respected (#5087) - Fixed a bug where the podman login and podman logout commands required the registry to log into be specified (#5146) - Fixed a bug where detached rootless Podman containers could not forward ports (#5167) - Fixed a bug where rootless Podman could fail to run if the pause process had died - Fixed a bug where Podman ignored labels that were specified with only a key and no value (#3854) - Fixed a bug where Podman would fail to create named volumes when the backing filesystem did not support SELinux labelling (#5200) - Fixed a bug where --detach-keys="" would not disable detaching from a container (#5166) - Fixed a bug where the podman ps command was too aggressive when filtering containers and would force --all on in too many situations - Fixed a bug where the podman play kube command was ignoring image configuration, including volumes, working directory, labels, and stop signal (#5174) - Fixed a bug where the Created and CreatedTime fields in podman images --format=json were misnamed, which also broke Go template output for those fields ([#5110](https://github.com/containers/libpod/issues/5110)) - Fixed a bug where rootless Podman containers with ports forwarded could hang when started (#5182) - Fixed a bug where podman pull could fail to parse registry names including port numbers - Fixed a bug where Podman would incorrectly attempt to validate image OS and architecture when starting containers - Fixed a bug where Bash completion for podman build -f would not list available files that could be built (#3878) - Fixed a bug where podman commit --change would perform incorrect validation, resulting in valid changes being rejected (#5148) - Fixed a bug where podman logs --tail could take large amounts of memory when the log file for a container was large (#5131) - Fixed a bug where Podman would sometimes incorrectly generate firewall rules on systems using firewalld - Fixed a bug where the podman inspect command would not display network information for containers properly if a container joined multiple CNI networks ([#4907](https://github.com/containers/libpod/issues/4907)) - Fixed a bug where the --uts flag to podman create and podman run would only allow specifying containers by full ID (#5289) - Fixed a bug where rootless Podman could segfault when passed a large number of file descriptors - Fixed a bug where the podman port command was incorrectly interpreting additional arguments as container names, instead of port numbers - Fixed a bug where units created by podman generate systemd did not depend on network targets, and so could start before the system network was ready (#4130) - Fixed a bug where exec sessions in containers which did not specify a user would not inherit supplemental groups added to the container via --group-add - Fixed a bug where Podman would not respect the $TMPDIR environment variable for placing large temporary files during some operations (e.g. podman pull) ([#5411](https://github.com/containers/libpod/issues/5411)) * HTTP API - Initial support for secure connections to servers via SSH tunneling has been added - Initial support for the libpod create and logs endpoints for containers has been added - Added a /swagger/ endpoint to serve API documentation - The json endpoint for containers has received many fixes - Filtering images and containers has been greatly improved, with many bugs fixed and documentation improved - Image creation endpoints (commit, pull, etc) have seen many fixes - Server timeout has been fixed so that long operations will no longer trigger the timeout and shut the server down - The stats endpoint for containers has seen major fixes and now provides accurate output - Handling the HTTP 304 status code has been fixed for all endpoints - Many fixes have been made to API documentation to ensure it matches the code * Misc - Updated vendored Buildah to v1.14.2 - Updated vendored containers/storage to v1.16.2 - The Created field to podman images --format=json has been renamed to CreatedSince as part of the fix for (#5110). Go templates using the old name shou ld still work - The CreatedTime field to podman images --format=json has been renamed to CreatedAt as part of the fix for (#5110). Go templates using the old name should still work - The before filter to podman images has been renamed to since for Docker compatibility. Using before will still work, but documentation has been changed to use the new since filter - Using the --password flag to podman login now warns that passwords are being passed in plaintext - Some common cases where Podman would deadlock have been fixed to warn the user that podman system renumber must be run to resolve the deadlock- Added SLE specific README.SUSE about current support status (jsc#SLE-9112, jsc#CAASP-60)- Configure br_netfilter for podman automatically (boo#1165738)- The name of the cni-bridge in the default config changed from "cni0" to "podman-cni0" with podman-1.6.0. Add a %trigger to rename the bridge in the system to the new default if it exists. The trigger is only excuted when updating podman-cni-config from something older than 1.6.0. This is mainly needed for SLE where we're updating from 1.4.4 to 1.8.0 (bsc#1160460).- Remove: 0001-clarify-container-prune-force.patch because it's now included in the release - Update podman to v1.8.0 (bsc#1160460): * Features - The podman system service command has been added, providing a preview of Podman's new Docker-compatible API. This API is still very new, and not yet ready for production use, but is available for early testing - Rootless Podman now uses Rootlesskit for port forwarding, which should greatly improve performance and capabilities - The podman untag command has been added to remove tags from images without deleting them - The podman inspect command on images now displays previous names they used - The podman generate systemd command now supports a --new option to generate service files that create and run new containers instead of managing existing containers - Support for --log-opt tag= to set logging tags has been added to the journald log driver - Added support for using Seccomp profiles embedded in images for podman run and podman create via the new --seccomp-policy CLI flag - The podman play kube command now honors pull policy * Bugfixes - Fixed a bug where the podman cp command would not copy the contents of directories when paths ending in /. were given - Fixed a bug where the podman play kube command did not properly locate Seccomp profiles specified relative to localhost - Fixed a bug where the podman info command for remote Podman did not show registry information - Fixed a bug where the podman exec command did not support having input piped into it - Fixed a bug where the podman cp command with rootless Podman on CGroups v2 systems did not properly determine if the container could be paused while copying - Fixed a bug where the podman container prune --force command could possible remove running containers if they were started while the command was running - Fixed a bug where Podman, when run as root, would not properly configure slirp4netns networking when requested - Fixed a bug where podman run --userns=keep-id did not work when the user had a UID over 65535 - Fixed a bug where rootless podman run and podman create with the --userns=keep-id option could change permissions on /run/user/$UID and break KDE - Fixed a bug where rootless Podman could not be run in a systemd service on systems using CGroups v2 - Fixed a bug where podman inspect would show CPUShares as 0, instead of the default (1024), when it was not explicitly set - Fixed a bug where podman-remote push would segfault - Fixed a bug where image healthchecks were not shown in the output of podman inspect - Fixed a bug where named volumes created with containers from pre-1.6.3 releases of Podman would be autoremoved with their containers if the --rm flag was given, even if they were given names - Fixed a bug where podman history was not computing image sizes correctly - Fixed a bug where Podman would not error on invalid values to the --sort flag to podman images - Fixed a bug where providing a name for the image made by podman commit was mandatory, not optional as it should be - Fixed a bug where the remote Podman client would append an extra " to %PATH - Fixed a bug where the podman build command would sometimes ignore the -f option and build the wrong Containerfile - Fixed a bug where the podman ps --filter command would only filter running containers, instead of all containers, if - -all was not passed - Fixed a bug where the podman load command on compressed images would leave an extra copy on disk - Fixed a bug where the podman restart command would not properly clean up the network, causing it to function differently from podman stop; podman start - Fixed a bug where setting the --memory-swap flag to podman create and podman run to -1 (to indicate unlimited) was not supported * Misc - Initial work on version 2 of the Podman remote API has been merged, but is still in an alpha state and not ready for use. Read more here - Many formatting corrections have been made to the manpages - The changes to address (#5009) may cause anonymous volumes created by Podman versions 1.6.3 to 1.7.0 to not be removed when their container is removed - Updated vendored Buildah to v1.13.1 - Updated vendored containers/storage to v1.15.8 - Updated vendored containers/image to v5.2.0- Add apparmor-abstractions as required runtime dependency to have `tunables/global` available.- Add: 0001-clarify-container-prune-force.patch to fix the --force flag for the "container prune" command. (https://github.com/containers/libpod/issues/4844)- Update podman to v1.7.0 * Features - Added support for setting a static MAC address for containers - Added support for creating macvlan networks with podman network create, allowing Podman containers to be attached directly to networks the host is connected to - The podman image prune and podman container prune commands now support the --filter flag to filter what will be pruned, and now prompts for confirmation when run without --force (#4410 and #4411) - Podman now creates CGroup namespaces by default on systems using CGroups v2 (#4363) - Added the podman system reset command to remove all Podman files and perform a factory reset of the Podman installation - Added the --history flag to podman images to display previous names used by images (#4566) - Added the --ignore flag to podman rm and podman stop to not error when requested containers no longer exist - Added the --cidfile flag to podman rm and podman stop to read the IDs of containers to be removed or stopped from a file - The podman play kube command now honors Seccomp annotations (#3111) - The podman play kube command now honors RunAsUser, RunAsGroup, and selinuxOptions - The output format of the podman version command has been changed to better match docker version when using the - -format flag - Rootless Podman will no longer initialize containers/storage twice, removing a potential deadlock preventing Podman commands from running while an image was being pulled (#4591) - Added tmpcopyup and notmpcopyup options to the --tmpfs and - -mount type=tmpfs flags to podman create and podman run to control whether the content of directories are copied into tmpfs filesystems mounted over them - Added support for disabling detaching from containers by setting empty detach keys via --detach-keys="" - The podman build command now supports the --pull and - -pull-never flags to control when images are pulled during a build - The podman ps -p command now shows the name of the pod as well as its ID (#4703) - The podman inspect command on containers will now display the command used to create the container - The podman info command now displays information on registry mirrors (#4553) * Bugfixes - Fixed a bug where Podman would use an incorrect runtime directory as root, causing state to be deleted after root logged out and making Podman in systemd services not function properly - Fixed a bug where the --change flag to podman import and podman commit was not being parsed properly in many cases - Fixed a bug where detach keys specified in libpod.conf were not used by the podman attach and podman exec commands, which always used the global default ctrl-p,ctrl-q key combination (#4556) - Fixed a bug where rootless Podman was not able to run podman pod stats even on CGroups v2 enabled systems (#4634) - Fixed a bug where rootless Podman would fail on kernels without the renameat2 syscall (#4570) - Fixed a bug where containers with chained network namespace dependencies (IE, container A using --net container=B and container B using --net container=C) would not properly mount /etc/hosts and /etc/resolv.conf into the container (#4626) - Fixed a bug where podman run with the --rm flag and without - d could, when run in the background, throw a 'container does not exist' error when attempting to remove the container after it exited - Fixed a bug where named volume locks were not properly reacquired after a reboot, potentially leading to deadlocks when trying to start containers using the volume (#4605 and [#4621]) - Fixed a bug where Podman could not completely remove containers if sent SIGKILL during removal, leaving the container name unusable without the podman rm --storage command to complete removal (#3906) - Fixed a bug where checkpointing containers started with --rm was allowed when --export was not specified (the container, and checkpoint, would be removed after checkpointing was complete by --rm) (#3774) - Fixed a bug where the podman pod prune command would fail if containers were present in the pods and the --force flag was not passed (#4346) - Fixed a bug where containers could not set a static IP or static MAC address if they joined a non-default CNI network (#4500) - Fixed a bug where podman system renumber would always throw an error if a container was mounted when it was run - Fixed a bug where podman container restore would fail with containers using a user namespace - Fixed a bug where rootless Podman would attempt to use the journald events backend even on systems without systemd installed - Fixed a bug where podman history would sometimes not properly identify the IDs of layers in an image (#3359) - Fixed a bug where containers could not be restarted when Conmon v2.0.3 or later was used - Fixed a bug where Podman did not check image OS and Architecture against the host when starting a container - Fixed a bug where containers in pods did not function properly with the Kata OCI runtime (#4353) - Fixed a bug where `podman info --format '{{ json . }}' would not produce JSON output (#4391) - Fixed a bug where Podman would not verify if files passed to - -authfile existed (#4328) - Fixed a bug where podman images --digest would not always print digests when they were available - Fixed a bug where rootless podman run could hang due to a race with reading and writing events - Fixed a bug where rootless Podman would print warning-level logs despite not be instructed to do so (#4456) - Fixed a bug where podman pull would attempt to fetch from remote registries when pulling an unqualified image using the docker-daemon transport (#4434) - Fixed a bug where podman cp would not work if STDIN was a pipe - Fixed a bug where podman exec could stop accepting input if anything was typed between the command being run and the exec session starting (#4397) - Fixed a bug where podman logs --tail 0 would print all lines of a container's logs, instead of no lines (#4396) - Fixed a bug where the timeout for slirp4netns was incorrectly set, resulting in an extremely long timeout (#4344) - Fixed a bug where the podman stats command would print CPU utilizations figures incorrectly (#4409) - Fixed a bug where the podman inspect --size command would not print the size of the container's read/write layer if the size was 0 (#4744) - Fixed a bug where the podman kill command was not properly validating signals before use (#4746) - Fixed a bug where the --quiet and --format flags to podman ps could not be used at the same time - Fixed a bug where the podman stop command was not stopping exec sessions when a container was created without a PID namespace (--pid=host) - Fixed a bug where the podman pod rm --force command was not removing anonymous volumes for containers that were removed - Fixed a bug where the podman checkpoint command would not export all changes to the root filesystem of the container if performed more than once on the same container (#4606) - Fixed a bug where containers started with --rm would not be automatically removed on being stopped if an exec session was running inside the container (#4666) * Misc - The fixes to runtime directory path as root can cause strange behavior if an upgrade is performed while containers are running - Updated vendored Buildah to v1.12.0 - Updated vendored containers/storage library to v1.15.4 - Updated vendored containers/image library to v5.1.0 - Kata Containers runtimes (kata-runtime, kata-qemu, and kata-fc) are now present in the default libpod.conf, but will not be available unless Kata containers is installed on the system - Podman previously did not allow the creation of containers with a memory limit lower than 4MB. This restriction has been removed, as the crun runtime can create containers with significantly less memory - Remove no longer needed workaround for *.5.md man page sources- Update podman to v1.6.4 - Remove winsz FIFO on container restart to allow use with Conmon 2.03 and higher - Ensure volumes reacquire locks on system restart, preventing deadlocks when starting containers - Suppress spurious log messages when running rootless Podman - Update vendored containers/storage to v1.13.6 - Fix a deadlock related to writing events - Do not use the journald event logger when it is not available - Remove obsolete patch container-start-fix.patch- Add container-start-fix.patch to correct output of container-start to show container_name, not _id.- Update podman to v1.6.2 * Features - Added a --runtime flag to podman system migrate to allow the OCI runtime for all containers to be reset, to ease transition to the crun runtime on CGroups V2 systems until runc gains full support - The podman rm command can now remove containers in broken states which previously could not be removed - The podman info command, when run without root, now shows information on UID and GID mappings in the rootless user namespace - Added podman build --squash-all flag, which squashes all layers (including those of the base image) into one layer - The --systemd flag to podman run and podman create now accepts a string argument and allows a new value, always, which forces systemd support without checking if the the container entrypoint is systemd * Bugfixes - Fixed a bug where the podman top command did not work on systems using CGroups V2 (#4192) - Fixed a bug where rootless Podman could double-close a file, leading to a panic - Fixed a bug where rootless Podman could fail to retrieve some containers while refreshing the state - Fixed a bug where podman start --attach --sig-proxy=false would still proxy signals into the container - Fixed a bug where Podman would unconditionally use a non-default path for authentication credentials (auth.json), breaking podman login integration with skopeo and other tools using the containers/image library - Fixed a bug where podman ps --format=json and podman images - -format=json would display null when no results were returned, instead of valid JSON - Fixed a bug where podman build --squash was incorrectly squashing all layers into one, instead of only new layers - Fixed a bug where rootless Podman would allow volumes with options to be mounted (mounting volumes requires root), creating an inconsistent state where volumes reported as mounted but were not (#4248) - Fixed a bug where volumes which failed to unmount could not be removed (#4247) - Fixed a bug where Podman incorrectly handled some errors relating to unmounted or missing containers in containers/storage - Fixed a bug where podman stats was broken on systems running CGroups V2 when run rootless (#4268) - Fixed a bug where the podman start command would print the short container ID, instead of the full ID - Fixed a bug where containers created with an OCI runtime that is no longer available (uninstalled or removed from the config file) would not appear in podman ps and could not be removed via podman rm - Fixed a bug where containers restored via podman container restore --import would retain the CGroup path of the original container, even if their container ID changed; thus, multiple containers created from the same checkpoint would all share the same CGroup * Misc - The default PID limit for containers is now set to 4096. It can be adjusted back to the old default (unlimited) by passing - -pids-limit 0 to podman create and podman run - The podman start --attach command now automatically attaches STDIN if the container was created with -i - The podman network create command now validates network names using the same regular expression as container and pod names - The --systemd flag to podman run and podman create will now only enable systemd mode when the binary being run inside the container is /sbin/init, /usr/sbin/init, or ends in systemd (previously detected any path ending in init or systemd) - Updated vendored Buildah to 1.11.3 - Updated vendored containers/storage to 1.13.5 - Updated vendored containers/image to 4.0.1- Update podman to v1.6.1 * Features - The podman network create, podman network rm, podman network inspect, and podman network ls commands have been added to manage CNI networks used by Podman - The podman volume create command can now create and mount volumes with options, allowing volumes backed by NFS, tmpfs, and many other filesystems - Podman can now run containers without CGroups for better integration with systemd by using the --cgroups=disabled flag with podman create and podman run. This is presently only supported with the crun OCI runtime - The podman volume rm and podman volume inspect commands can now refer to volumes by an unambiguous partial name, in addition to full name (e.g. podman volume rm myvol to remove a volume named myvolume) (#3891) - The podman run and podman create commands now support the - -pull flag to allow forced re-pulling of images (#3734) - Mounting volumes into a container using --volume, --mount, and - -tmpfs now allows the suid, dev, and exec mount options (the inverse of nosuid, nodev, noexec) (#3819) - Mounting volumes into a container using --mount now allows the relabel=Z and relabel=z options to relabel mounts. - The podman push command now supports the --digestfile option to save a file containing the pushed digest - Pods can now have their hostname set via podman pod create - -hostname or providing Pod YAML with a hostname set to podman play kube (#3732) - The podman image sign command now supports the --cert-dir flag - The podman run and podman create commands now support the - -security-opt label=filetype:$LABEL flag to set the SELinux label for container files - The remote Podman client now supports healthchecks * Bugfixes - Fixed a bug where remote podman pull would panic if a Varlink connection was not available (#4013) - Fixed a bug where podman exec would not properly set terminal size when creating a new exec session (#3903) - Fixed a bug where podman exec would not clean up socket symlinks on the host (#3962) - Fixed a bug where Podman could not run systemd in containers that created a CGroup namespace - Fixed a bug where podman prune -a would attempt to prune images used by Buildah and CRI-O, causing errors (#3983) - Fixed a bug where improper permissions on the ~/.config directory could cause rootless Podman to use an incorrect directory for storing some files - Fixed a bug where the bash completions for podman import threw errors - Fixed a bug where Podman volumes created with podman volume create would not copy the contents of their mountpoint the first time they were mounted into a container (#3945) - Fixed a bug where rootless Podman could not run podman exec when the container was not run inside a CGroup owned by the user (#3937) - Fixed a bug where podman play kube would panic when given Pod YAML without a securityContext (#3956) - Fixed a bug where Podman would place files incorrectly when storage.conf configuration items were set to the empty string (#3952) - Fixed a bug where podman build did not correctly inherit Podman's CGroup configuration, causing crashed on CGroups V2 systems (#3938) - Fixed a bug where podman cp would improperly copy files on the host when copying a symlink in the container that included a glob operator (#3829) - Fixed a bug where remote podman run --rm would exit before the container was completely removed, allowing race conditions when removing container resources (#3870) - Fixed a bug where rootless Podman would not properly handle changes to /etc/subuid and /etc/subgid after a container was launched - Fixed a bug where rootless Podman could not include some devices in a container using the --device flag (#3905) - Fixed a bug where the commit Varlink API would segfault if provided incorrect arguments (#3897) - Fixed a bug where temporary files were not properly cleaned up after a build using remote Podman (#3869) - Fixed a bug where podman remote cp crashed instead of reporting it was not yet supported (#3861) - Fixed a bug where podman exec would run as the wrong user when execing into a container was started from an image with Dockerfile USER (or a user specified via podman run --user) (#3838) - Fixed a bug where images pulled using the oci: transport would be improperly named - Fixed a bug where podman varlink would hang when managed by systemd due to SD_NOTIFY support conflicting with Varlink (#3572) - Fixed a bug where mounts to the same destination would sometimes not trigger a conflict, causing a race as to which was actually mounted - Fixed a bug where podman exec --preserve-fds caused Podman to hang (#4020) - Fixed a bug where removing an unmounted container that was unmounted might sometimes not properly clean up the container (#4033) - Fixed a bug where the Varlink server would freeze when run in a systemd unit file (#4005) - Fixed a bug where Podman would not properly set the $HOME environment variable when the OCI runtime did not set it - Fixed a bug where rootless Podman would incorrectly print warning messages when an OCI runtime was not found (#4012) - Fixed a bug where named volumes would conflict with, instead of overriding, tmpfs filesystems added by the --read-only-tmpfs flag to podman create and podman run - Fixed a bug where podman cp would incorrectly make the target directory when copying to a symlink which pointed to a nonexistent directory (#3894) - Fixed a bug where remote Podman would incorrectly read STDIN when the -i flag was not set (#4095) - Fixed a bug where podman play kube would create an empty pod when given an unsupported YAML type (#4093) - Fixed a bug where podman import --change improperly parsed CMD (#4000) - Fixed a bug where rootless Podman on systems using CGroups V2 would not function with the cgroupfs CGroups manager - Fixed a bug where rootless Podman could not correctly identify the DBus session address, causing containers to fail to start (#4162) - Fixed a bug where rootless Podman with slirp4netns networking would fail to start containers due to mount leaks * Misc - Significant changes were made to Podman volumes in this release. If you have pre-existing volumes, it is strongly recommended to run podman system renumber after upgrading. - Version 0.8.1 or greater of the CNI Plugins is now required for Podman - Version 2.0.1 or greater of Conmon is strongly recommended - Updated vendored Buildah to v1.11.2 - Updated vendored containers/storage library to v1.13.4 - Improved error messages when trying to create a pod with no name via podman play kube - Improved error messages when trying to run podman pause or podman stats on a rootless container on a system without CGroups V2 enabled - TMPDIR has been set to /var/tmp by default to better handle large temporary files - podman wait has been optimized to detect stopped containers more rapidly - Podman containers now include a ContainerManager annotation indicating they were created by libpod - The podman info command now includes information about slirp4netns and fuse-overlayfs if they are available - Podman no longer sets a default size of 65kb for tmpfs filesystems - The default Podman CNI network has been renamed in an attempt to prevent conflicts with CRI-O when both are run on the same system. This should only take effect on system restart - The output of podman volume inspect has been more closely matched to docker volume inspect - Removed CVE-2019-10214.patch as it was merged upstream- Add katacontainers as a recommended package, and include it as an additional OCI runtime in the configuration.- Add patch for CVE-2019-10214. bsc#1144065 + CVE-2019-10214.patch- Update podman to v1.5.1 * Features - The hostname of pods is now set to the pod's name * Bugfixes - Fixed a bug where podman run and podman create did not honor the --authfile option (#3730) - Fixed a bug where containers restored with podman container restore - -import would incorrectly duplicate the Conmon PID file of the original container - Fixed a bug where podman build ignored the default OCI runtime configured in libpod.conf - Fixed a bug where podman run --rm (or force-removing any running container with podman rm --force) were not retrieving the correct exit code (#3795) - Fixed a bug where Podman would exit with an error if any configured hooks directory was not present - Fixed a bug where podman inspect and podman commit would not use the correct CMD for containers run with podman play kube - Fixed a bug created pods when using rootless Podman and CGroups V2 (#3801) - Fixed a bug where the podman events command with the --since or --until options could take a very long time to complete * Misc - Rootless Podman will now inherit OCI runtime configuration from the root configuration (#3781) - Podman now properly sets a user agent while contacting registries (#3788) - Add zsh completion for podman commands- Update podman to v1.5.0 * Features - Podman containers can now join the user namespaces of other containers with --userns=container:$ID, or a user namespace at an arbitary path with --userns=ns:$PATH - Rootless Podman can experimentally squash all UIDs and GIDs in an image to a single UID and GID (which does not require use of the newuidmap and newgidmap executables) by passing - -storage-opt ignore_chown_errors - The podman generate kube command now produces YAML for any bind mounts the container has created (#2303) - The podman container restore command now features a new flag, - -ignore-static-ip, that can be used with --import to import a single container with a static IP multiple times on the same host - Added the ability for podman events to output JSON by specifying --format=json - If the OCI runtime or conmon binary cannot be found at the paths specified in libpod.conf, Podman will now also search for them in the calling user's path - Added the ability to use podman import with URLs (#3609) - The podman ps command now supports filtering names using regular expressions (#3394) - Rootless Podman containers with --privileged set will now mount in all host devices that the user can access - The podman create and podman run commands now support the - -env-host flag to forward all environment variables from the host into the container - Rootless Podman now supports healthchecks (#3523) - The format of the HostConfig portion of the output of podman inspect on containers has been improved and synced with Docker - Podman containers now support CGroup namespaces, and can create them by passing --cgroupns=private to podman run or podman create - The podman create and podman run commands now support the - -ulimit=host flag, which uses any ulimits currently set on the host for the container - The podman rm and podman rmi commands now use different exit codes to indicate 'no such container' and 'container is running' errors - Support for CGroups V2 through the crun OCI runtime has been greatly improved, allowing resource limits to be set for rootless containers when the CGroups V2 hierarchy is in use * Bugfixes - Fixed a bug where a race condition could cause podman restart to fail to start containers with ports - Fixed a bug where containers restored from a checkpoint would not properly report the time they were started at - Fixed a bug where podman search would return at most 25 results, even when the maximum number of results was set higher - Fixed a bug where podman play kube would not honor capabilities set in imported YAML (#3689) - Fixed a bug where podman run --env, when passed a single key (to use the value from the host), would set the environment variable in the container even if it was not set on the host (#3648) - Fixed a bug where podman commit --changes would not properly set environment variables - Fixed a bug where Podman could segfault while working with images with no history - Fixed a bug where podman volume rm could remove arbitrary volumes if given an ambiguous name (#3635) - Fixed a bug where podman exec invocations leaked memory by not cleaning up files in tmpfs - Fixed a bug where the --dns and --net=container flags to podman run and podman create were not mutually exclusive (#3553) - Fixed a bug where rootless Podman would be unable to run containers when less than 5 UIDs were available - Fixed a bug where containers in pods could not be removed without removing the entire pod (#3556) - Fixed a bug where Podman would not properly clean up all CGroup controllers for created cgroups when using the cgroupfs CGroup driver - Fixed a bug where Podman containers did not properly clean up files in tmpfs, resulting in a memory leak as containers stopped - Fixed a bug where healthchecks from images would not use default settings for interval, retries, timeout, and start period when they were not provided by the image (#3525) - Fixed a bug where healthchecks using the HEALTHCHECK CMD format where not properly supported (#3507) - Fixed a bug where volume mounts using relative source paths would not be properly resolved (#3504) - Fixed a bug where podman run did not use authorization credentials when a custom path was specified (#3524) - Fixed a bug where containers checkpointed with podman container checkpoint did not properly set their finished time - Fixed a bug where running podman inspect on any container not created with podman run or podman create (for example, pod infra containers) would result in a segfault (#3500) - Fixed a bug where healthcheck flags for podman create and podman run were incorrectly named (#3455) - Fixed a bug where Podman commands would fail to find targets if a partial ID was specified that was ambiguous between a container and pod (#3487) - Fixed a bug where restored containers would not have the correct SELinux label - Fixed a bug where Varlink endpoints were not working properly if more was not correctly specified - Fixed a bug where the Varlink PullImage endpoint would crash if an error occurred (#3715) - Fixed a bug where the --mount flag to podman create and podman run did not allow boolean arguments for its ro and rw options (#2980) - Fixed a bug where pods did not properly share the UTS namespace, resulting in incorrect behavior from some utilities which rely on hostname (#3547) - Fixed a bug where Podman would unconditionally append ENTRYPOINT to CMD during podman commit (and when reporting CMD in podman inspect) (#3708) - Fixed a bug where podman events with the journald events backend would incorrectly print 6 previous events when only new events were requested (#3616) - Fixed a bug where podman port would exit prematurely when a port number was specified (#3747) - Fixed a bug where passing . as an argument to the --dns-search flag to podman create and podman run was not properly clearing DNS search domains in the container * Misc - Updated vendored Buildah to v1.10.1 - Updated vendored containers/image to v3.0.2 - Updated vendored containers/storage to v1.13.1 - Podman now requires conmon v2.0.0 or higher - The podman info command now displays the events logger being in use - The podman inspect command on containers now includes the ID of the pod a container has joined and the PID of the container's conmon process - The -v short flag for podman --version has been re-added - Error messages from podman pull should be significantly clearer - The podman exec command is now available in the remote client - The podman-v1.5.0.tar.gz file attached is podman packaged for MacOS. It can be installed using Homebrew. - Use new conmon package as direct dependency - Remove internal conmon package - Update libpod.conf to support latest path discovery feature for `runc` and `conmon` binaries. - Re-enable 32bit build- Remove fuse-overlayfs because it's (currently) an unsatisfied dependency on SLE (bsc#1143386)- Update libpod.conf to use correct infra_command- Update libpod.conf to use better versioned pause container- Update libpod.conf to use official kubic pause container- Update libpod.conf to match latest features set: detach_keys, lock_type, runtime_supports_json- Add podman-remote varlink client - Update podman to v1.4.4 * Features - Podman now has greatly improved support for containers using multiple OCI runtimes. Containers now remember if they were created with a different runtime using --runtime and will always use that runtime - The cached and delegated options for volume mounts are now allowed for Docker compatability (#3340) - The podman diff command now supports the --latest flag * Bugfixes - Fixed a bug where rootless Podman would attempt to use the entire root configuration if no rootless configuration was present for the user, breaking rootless Podman for new installations - Fixed a bug where rootless Podman's pause process would block SIGTERM, preventing graceful system shutdown and hanging until the system's init send SIGKILL - Fixed a bug where running Podman as root with sudo -E would not work after running rootless Podman at least once - Fixed a bug where options for tmpfs volumes added with the --tmpfs flag were being ignored - Fixed a bug where images with no layers could not properly be displayed and removed by Podman - Fixed a bug where locks were not properly freed on failure to create a container or pod - Fixed a bug where podman cp on a single file would create a directory at the target and place the file in it (#3384) - Fixed a bug where podman inspect --format '{{.Mounts}}' would print a hexadecimal address instead of a container's mounts - Fixed a bug where rootless Podman would not add an entry to container's /etc/hosts files for their own hostname (#3405) - Fixed a bug where podman ps --sync would segfault (#3411) - Fixed a bug where podman generate kube would produce an invalid ports configuration (#3408) * Misc - Updated containers/storage to v1.12.13 - Podman now performs much better on systems with heavy I/O load - The --cgroup-manager flag to podman now shows the correct default setting in help if the default was overridden by libpod.conf - For backwards compatability, setting --log-driver=json-file in podman run is now supported as an alias for --log-driver=k8s-file. This is considered deprecated, and json-file will be moved to a new implementation in the future ([#3363](https://github.com/containers/libpo\ d/issues/3363)) - Podman's default libpod.conf file now allows the crun OCI runtime to be used if it is installed- Update podman to v1.4.2 - Fixed a bug where Podman could not run containers using an older version of Systemd as init - Updated vendored Buildah to v1.9.0 to resolve a critical bug with Dockerfile RUN instructions - The error message for running podman kill on containers that are not running has been improved - Podman remote client can now log to a file if syslog is not available - The podman exec command now sets its error code differently based on whether the container does not exist, and the command in the container does not exist - The podman inspect command on containers now outputs Mounts JSON that matches that of docker inspect, only including user-specified volumes and differentiating bind mounts and named volumes - The podman inspect command now reports the path to a container's OCI spec with the OCIConfigPath key (only included when the container is initialized or running) - The podman run --mount command now supports the bind-nonrecursive option for bind mounts - Fixed a bug where podman play kube would fail to create containers due to an unspecified log driver - Fixed a bug where Podman would fail to build with musl libc - Fixed a bug where rootless Podman using slirp4netns networking in an environment with no nameservers on the host other than localhost would result in nonfunctional networking - Fixed a bug where podman import would not properly set environment variables, discarding their values and retaining only keys - Fixed a bug where Podman would fail to run when built with Apparmor support but run on systems without the Apparmor kernel module loaded - Remote Podman will now default the username it uses to log in to remote systems to the username of the current user - Podman now uses JSON logging with OCI runtimes that support it, allowing for better error reporting - Updated vendored containers/image to v2.0 - Update conmon to v0.3.0 - Support OOM Monitor under cgroup V2 - Add config binary and make target for configuring conmon with a go library for importing values- update dependency for slirp4netns to 0.3.0 or newer- Update podman to v1.4.0: - The podman checkpoint and podman restore commands can now be used to migrate containers between Podman installations on different systems - The podman cp command now supports a pause flag to pause containers while copying into them - The remote client now supports a configuration file for pre-configuring connections to remote Podman installations - Fixed CVE-2019-10152 - The podman cp command improperly dereferenced symlinks in host context - Fixed a bug where podman commit could improperly set environment variables that contained = characters - Fixed a bug where rootless Podman would sometimes fail to start containers with forwarded ports - Fixed a bug where podman version on the remote client could segfault - Fixed a bug where podman container runlabel would use /proc/self/exe instead of the path of the Podman command when printing the command being executed - Fixed a bug where filtering images by label did not work - Fixed a bug where specifying a bing mount or tmpfs mount over an image volume would cause a container to be unable to start - Fixed a bug where podman generate kube did not work with containers with named volumes - Fixed a bug where rootless Podman would receive permission denied errors accessing conmon.pid - Fixed a bug where podman cp with a folder specified as target would replace the folder, as opposed to copying into it - Fixed a bug where rootless Podman commands could double-unlock a lock, causing a crash - Fixed a bug where Podman incorrectly set tmpcopyup on /dev/ mounts, causing errors when using the Kata containers runtime - Fixed a bug where podman exec would fail on older kernels - The podman commit command is now usable with the Podman remote client - The --signature-policy flag (used with several image-related commands) has been deprecated - The podman unshare command now defines two environment variables in the spawned shell: CONTAINERS_RUNROOT and CONTAINERS_GRAPHROOT, pointing to temporary and permanent storage for rootless containers - Updated vendored containers/storage and containers/image libraries with numerous bugfixes - Updated vendored Buildah to v1.8.3 - Podman now requires Conmon v0.2.0 - The podman cp command is now aliased as podman container cp - Rootless Podman will now default init_path using root Podman's configuration files (/etc/containers/libpod.conf and /usr/share/containers/libpod.conf) if not overridden in the rootless configuration- Add fuse-overlayfs dependency to support overlay based rootless image manipulations- Update podman to v1.3.2: - Fixed a bug where podman would fail to run if a volume was mounted over an image volume- Update podman to v1.3.1: - The podman cp command can now read input redirected to STDIN, and output to STDOUT instead of a file, using - instead of an argument. - The Podman remote client now displays version information from both the client and server in podman version - The podman unshare command has been added, allowing easy entry into the user namespace set up by rootless Podman (allowing the removal of files created by rootless Podman, among other things) - Fixed a bug where Podman containers with the --rm flag were removing created volumes when they were automatically removed - Fixed a bug where container and pod locks were incorrectly marked as released after a system reboot, causing errors on container and pod removal - Fixed a bug where Podman pods could not be removed if any container in the pod encountered an error during removal - Fixed a bug where Podman pods run with the cgroupfs CGroup driver would encounter a race condition during removal, potentially failing to remove the pod CGroup - Fixed a bug where the podman container checkpoint and podman container restore commands were not visible in the remote client - Fixed a bug where podman remote ps --ns would not print the container's namespaces - Fixed a bug where removing stopped containers with healthchecks could cause an error - Fixed a bug where the default libpod.conf file was causing parsing errors - Fixed a bug where pod locks were not being freed when pods were removed, potentially leading to lock exhaustion - Fixed a bug where 'podman run' with SD_NOTIFY set could, on short-running containers, create an inconsistent state rendering the container unusable - The remote Podman client now uses the Varlink bridge to establish remote connections by default - Update conmon to 0.2.0 and switched to containers/conmon upstream project- Update `systemd-devel` to actually be `pkgconfig(libsystemd)` to allow OBS to shortcut through systemd-mini-devel- Update podman to v1.3.0 * Podman now supports container restart policies! The --restart-policy flag on podman create and podman run allows containers to be restarted after they exit. Please note that Podman cannot restart containers after a system reboot - for that, see our next feature * Podman podman generate systemd command was added to generate systemd unit files for managing Podman containers * The podman runlabel command now allows a $GLOBAL_OPTS variable, which will be populated by global options passed to the podman runlabel command, allowing custom storage configurations to be passed into containers run with runlabel * The podman play kube command now allows File and FileOrCreate volumes * The podman pod prune command was added to prune unused pods * Added the podman system migrate command to migrate containers using older configurations to allow their use by newer Libpod versions * Podman containers now forward proxy-related environment variables from the host into the container with the --http-proxy flag (enabled by default) * Read-only Podman containers can now create tmpfs filesystems on /tmp, /var/tmp, and /run with the --read-only-tmpfs flag (enabled by default) * The podman init command was added, performing all container pre-start tasks without starting the container to allow pre-run debugging - Update conmon to cri-o v1.14.1 - Update libpod.conf to match latest feature set- Update to podman 1.2.0 * Podman now supports image healthchecks! The podman healthcheck run command was added to manually run healthchecks, and the status of a running healthcheck can be viewed via podman inspect * The podman events command was added to show a stream of significant events * The podman ps command now supports a --watch flag that will refresh its output on a given interval * The podman image tree command was added to show a tree representation of an image's layers * The podman logs command can now display logs for multiple containers at the same time * The podman exec command can now pass file descriptors to the process being executed in the container via the --preserve-fds option * The podman images command can now filter images by reference * The podman system df command was added to show disk usage by Podman * The --add-host option can now be used by containers sharing a network namespace * The podman cp command now has an --extract option to extract the contents of a Tar archive and copy them into the container, instead of copying the archive itself * Podman now allows manually specifying the path of the slirp4netns binary for rootless networking via the --network-cmd-path flag * Rootless Podman can now be used with a single UID and GID, without requiring a full 65536 UIDs/GIDs to be allocated in /etc/subuid and /etc/subgid * The podman runlabel command now supports the --replace option to replace containers using the name requested * Infrastructure containers for Podman pods will now attempt to use the image's CMD and ENTRYPOINT instead of a fixed command * The podman play kube command now supports the HostPath and VolumeMounts YAML fields * Added support to disable creation of resolv.conf or /etc/hosts in containers by specifying --dns=none and --no-hosts, respectively, to podman run and podman create * The podman version command now supports the {{ json . }} template (which outputs JSON) * Podman can now forward ports using the SCTP protocol - Update conmon to cri-o 1.14.0 - Stop building for i586 (not supported by upstream, does not build)- Change default libpod.conf configuration file: use the runtimes section to allow users to specify different OCI runtimes. This allows user to choose which runtime to use on a per container basis.- Add 'apparmor-parser' to list of requires (boo#1123387)- Scriptlets contain sh-compatible code, so drop -p /bin/bash.- podman-cni-config: remove artificial conflicts with kubelet- Disable build with PIE on ppc64le to avoid boo#1098017- Update to v1.1.2 * Fixed a bug where the podman image list, podman image rm, and podman container list had broken global storage options * Fixed a bug where the --label option to podman create and podman run was missing the -l alias * Fixed a bug where running Podman with the --config flag would not set an appropriate default value for tmp_dir * Fixed a bug where the podman logs command with the --timestamps flag produced unreadable output * Fixed a bug where the podman cp command would automatically extract .tar files copied into the container * The podman container stop command is now usable with the Podman remote client- Update to v1.1.1 * Update release notes for v1.1.1 * Pull image for runlabel if not local * Fix SystemExec completion race * Fix link inconsistencies in man pages * Verify that used OCI runtime supports checkpoint * Should be defaulting to pull not pull-always * podman-commands script: refactor * Move Alias lines to descriptions of commands * Fix usage messages for podman image list, rm * Fix -s to --storage-driver in baseline test * No podman container ps command exists * Allow Exec API user to override streams * fix up a number of misplace commands * rootless, new[ug]idmap: on failure add output * [ci skip] Critical note about merge bot * podman port fix output * Fix ignored --time argument to podman restart * secrets: fix fips-mode with user namespaces * Fix four errors tagged by Cobra macro debugging * Clean up man pages to match commands * Add debugging for errors to Cobra compatibility macros * Command-line input validation: reject unused args * Fix ignored --stop-timeout flag to 'podman create' * fixup! Incorporate review feedback * fixup! missed some more: * fixup! Correction to 'checkpoint' * Followup to #2456: update examples, add trust * podman create: disable interspersed opts * fix up a number of misplace commands * Add a task to Cirrus gating to build w/o Varlink * Skip checkpoint/restore tests on Fedora for now * Fix build for non-Varlink-tagged Podman * Remove restore as podman subcommand * Better usage synopses for subcommands * Bump gitvalidation epoch * Bump to v1.2.0-dev * Centralize setting default volume path * Ensure volume path is set appropriately by default * Move all storage configuration defaults into libpod * rename pod when we have a name collision with a container * podman remote-client readme - Update package to ship varlink required files- Update to v1.1.0 * Added --latest and --all flags to podman mount and podman umount * Rootless Podman can now forward ports into containers (using the same -p and -P flags as root Podman) * Rootless Podman will now pull some configuration options (for example, OCI runtime path) from the default root libpod.conf if they are not explicitly set in the user's own libpod.conf * Added an alias -f for the --format flag of the podman info and podman version commands * Added an alias -s for the --size flag of the podman inspect command * Added the podman system info and podman system prune commands * Added the podman cp command to copy files between containers and the host * Added the --password-stdin flag to podman login * Added the --all-tags flag to podman pull * The --rm and --detach flags can now be used together with podman run * The podman start and podman run commands for containers in pods will now start dependency containers if they are stopped * Added the podman system renumber command to handle lock changes * The --net=host and --dns flags for podman run and podman create no longer conflict * Podman now handles mounting the shared /etc/resolv.conf from network namespaces created by ip netns add when they are passed in via podman run --net=ns: * Various bugfixes - full changelog https://github.com/containers/libpod/releases/tag/v1.1.0 - Removed obsolete patch containers-libpod-pull-2225.diff- Update to conmon from cri-o v1.13.1 * oci: read conmon process status- Upgrade to v1.0.1 * rootless: join both userns and mount namespace with --pod * rootless: create the userns immediately when creating a new pod * Preserve exited state across reboot * podman image prune -- implement all flag * Add varlink support for prune * Make --quiet work in podman create/run * rootless: fix --pid=host without --privileged * podman-inspect: don't ignore errors- Fix rootless mode with AppArmor https://github.com/containers/libpod/pull/2225 Add patch containers-libpod-pull-2225.diff- Stop using conmon from random git commits, use cri-o releases - Update to conmon from cri-o v1.13.0 * Solve gh#containers/libpod#527 - Tidy up .gitignore files from podman-1.0.0.tar.xz- Update requirement to go1.11 to stay in sync with CaaSP4 and use the same version as k8s and cri-o to prevent "weird" issues because of the go version (we had problems mixing go1.5 and go1.6 in the past)- Update libpod.conf to better align with upstream defaults [boo#1122024] - Require catatonit for new --init flag- Upgrade to v1.0.0 * The podman exec command now includes a --workdir option to set working directory for the executed command * The podman create and podman run commands now support the --init flag to use a minimal init process in the container * Added the podman image sign command to GPG sign images * The podman run --device flag now accepts directories, and will added any device nodes in the directory to the container * Added the podman play kube command to create pods and containers from Kubernetes pod YAML * Rootless containers now unconditionally use postrun cleanup processes, ensuring resources are freed when the container stops * Pulling images has been parallelized, allowing individual layers to be pulled in parallel- Update to v0.12.1.2 * Rootless Podman now creates the storage.conf, libpod.conf, and mounts.conf configuration files automatically in ~/.config/containers/ for ease of reconfiguration * The podman pod create command can expose ports in the pod's network namespace, allowing public services to be created in pods * The podman container checkpoint command can now keep containers running after they are checkpointed with the --leave-running flag * The podman container checkpoint and podman container restore commands now support the --tcp-established flag to checkpoint and restore containers with active TCP connections * The podman version command now has a --format flag to produce machine-readable output * Added the podman container exists, podman pod exists, and podman image exists commands to easily check for a container/pod/image, respectively, by name or ID * The podman ps --pod flag now has a short alias, -p * The podman rmi and podman rm commands now have a --prune flag to prune unused images and containers, respectively * The podman ps command now has a --sync flag to force a sync of Podman's state against the OCI runtime, resolving some state desync errors * Added the podman volume set of commands for creating and managing local-only named volumes * Added the podman generate kube command to generate Kubernetes Pod and Service YAML for Podman containers and pods * The podman pod stop flag now accepts a --timeout flag to set the timeout for stopping containers in the pod- Update package summary and description- add dependency to iptables, build fails otherwise- Changelog for v0.11.1.1 (2018-11-15) * Increase pidWaitTimeout to 60s * rootless: call IsRootless just once * Add space between num & unit in images output * Better document rootless containers * info: add rootless field * Do not hide errors when creating container with UserNSRoot * correct assignment of networkStatus * rootless: default to fuse-overlayfs when available- Require golang >= 1.10.- Changelog for v0.11.1 (2018-11-08) * update seccomp.json * Touch up --log* options and daemons in man pages * Don't fail if /etc/passwd or /etc/group does not exists * Properly set Running state when starting containers * If a container ceases to exist in runc, set exit status * rootless: mount /sys/fs/cgroup/systemd from the host * rootless: don't bind mount /sys/fs/cgroup/systemd in systemd mode * Add hostname to /etc/hosts * Remove conmon cgroup before pod cgroup for cgroupfs * Make kill, pause, and unpause parallel. * Fix long image name handling * Make restart parallel and add --all * rootless: do not add an additional /run to runroot * rootless: avoid hang on failed slirp4netns * Fix setting of version information * runtime: do not allow runroot longer than 50 characters * attach: fix attach when cuid is too long * truncate command output in ps by default * make various changes to ps output * Use two spaces to pad PS fields * fix bug in rm -fa parallel deletes * Ensure test container in running state * Add tests for selinux labels * Add --max-workers and heuristics for parallel operations * Increase security and performance when looking up groups * run prepare in parallel * runlabel: run any command * Explain the device format in man pages * Add --all and --latest to checkpoint/restore * Use more reliable check for rootless for firewall init * Make podman ps fast * Support auth file environment variable in podman build * fix environment variable parsing * Use the CRIU version check in checkpoint/restore * Handle http/https in registry given to login/out * correct stats err with non-running containers * Make rm faster * Fix man page to show info on storage - Changelog for v0.10.1.3 (2018-10-17) * Vendor in new new buildah/ci * Fix podman in podman - Changelog for v0.10.1.2 (2018-10-17) * Fix CGroup paths used for systemd CGroup mount- Require slirp4netns to enable networking for unprivileged network namespaces aka networking for rootless podman.- Changelog for v0.10.1.1 (2018-10-16) * Mount proper cgroup for systemd to manage inside of the container. * volume: resolve symlinks in paths * volume: write the correct ID of the container in error messages * Support auth file environment variable & add change to man pages * Generate a passwd file for users not in container- Changelog for v0.10.1 (2018-10-11) * Sort all command flags * rootless: detect when user namespaces are not enabled * Log an otherwise ignored error from joining a net ns * Update manpages for --ip flag * Add --ip flag and plumbing into libpod * Document --net as an alias of --network in podman run & create * rootless: report more error messages from the startup phase * rootless: fix an hang on older versions of setresuid/setresgid * fix runlabel functions based on QA feedback * Stop containers in parallel fashion * runlabel: execute /proc/self/exe and avoid recursion * Ensure resolv.conf has the right label and path * completions: add checkpoint/restore completions * Add support to checkpoint/restore containers * selinux: drop superflous relabel * rootless: always set XDG_RUNTIME_DIR * Address review comments and fix ps output * Disable SELinux labeling if --privileged * Implement pod varlink bindings * Add --all flag to podman kill * Add container runlabel command * run complex image names with short names- Update conmon to 4cd5a7c60349be0678d9f1b0657683324c1a2726 and fetch it from its new home https://github.com/kubernetes-sigs/cri-o. - Changelog for v0.9.3.1 (2018-09-25) * Disable problematic SELinux code causing runc issues - Changelog for v0.9.3 (2018-09-21) * Add --mount option for `create` & `run` command * Don't mount /dev/shm if the user told you --ipc=none * rootless: error out if there are not enough UIDs/GIDs available * Add new field to libpod to indicate whether or not to use labelling * Bind Mounts should be mounted read-only when in read-only mode * report when rootless * Don't crash if an image has no names - Changelog for v0.9.2 (2018-09-14) * Don't mount /dev/* if user mounted /dev * rootless: do not raise an error if the entrypoint is specified * Add a way to disable port reservation * Do not set rlimits if we are rootless * Add --interval flag to podman wait * Add `podman rm --volumes` flag * Explicitly set default CNI network name in libpod.conf - Changelog for v0.9.1.1 (2018-09-10) * Replace existing iptables handler with firewall code * Vendor CNI plugins firewall code * Fix displaying size on size calculation error - Changelog for v0.9.1 (2018-09-07) * Fix pod sharing for utsmode * Respect user-added mounts over default spec mounts * use layer cache when building images * Start pod infra container when pod is created * Fix up libpod.conf man pages and referencese to it. * We should fail Podman with ExitCode 125 by default * Add CRI logs parsing to podman logs * rmi remove all not error when no images are present * rootless, create: support --pod * rootless, run: support --pod- Changelog for v0.8.5 (2018-08-31) * Add proper support for systemd inside of podman * We are mistakenly seeing repos as registries. * Up time between checks for podman wait * Turn on test debugging * Add support for remote commands * fixup A few language changes and subuid(5) * Make the documentation of user namespace options in podman-run clearer * catch command-not-found errors * don't print help message for usage errors * docs: consistent format for example * docs: consistent headings * docs: make HISTORY consistent * docs: fix headers * varlink: fix --timeout usage * run/create: reserve `-h` flag for hostname * podman,varlink: inform user about --timeout 0 * rootless: show an error when stats is used * rootless: show an error when pause/unpause are used * rootless: unexport GetUserNSForPid * rootless, exec: use the new function to join the userns * rootless: fix top * rootless: add new function to join existing namespace * Do not set max open files by default if we are rootless * Set default max open files in spec * Resolve /etc/resolv.conf before reading * document `--rm` semantics * rootless, search: do not create a new userns * rootless, login, logout: do not create a new userns * rootless, kill: do not create a new userns * rootless, stop: do not create a new userns * Fix manpage to note how multiple filters are combined * Fix handling of multiple filters in podman ps * Fix Mount Propagation * docs: add containers-mounts.conf(5) * docs: use "containers-" prefix for registries and storage * rootless: fix --pid=host * rootless: fix --ipc=host * spec: bind mount /sys only when userNS are enabled * rootless, tests: add test for --uts=host * rootless: don't use kill --all * rootless: exec handle processes that create an user namespace * rootless: fix exec- Changelog for v0.8.4 (2018-08-24) * Swap from FFJSON to easyjson * rootless: allow to override policy.json by the user * add completion for --pod in run and create * Fixed formatting and lowered verbosity of pod ps * Do not try to enable AppArmor in rootless mode * Reveal information about container capabilities * Fixing network ns segfault * Change pause container to infra container * Added option to share kernel namespaces in libpod and podman * Add podman pod top * Include pod stats and top in commands/completions * Fix syntax description of --ulimit command * Properly translate users into runc format for exec * rootless: fix --net host --privileged * Fixed segfault in stats where container had netNS none or from container * Enable pod stats with short ID and name * Touch up cert-dir in man pages * Support Attach subcommand in pypodman- Changelog for v0.8.3 (2018-08-17) * Switch from github.com/projectatomic to github.com/containers * Mention that systemd is the default cgroup manager * Fix handling of socket connection refusal. * podman: fix --uts=host * podman pod stats * Added reason to PodContainerError * Add Pod API to varlink. * Revert "spec: bind mount /sys only for rootless containers" * Document STORAGE_DRIVER and STORAGE_OPTS environment variable * Create pod CGroups when using the systemd cgroup driver * Switch systemd default CGroup parent to machine.slice * spec: bind mount /sys only for rootless containers * Add create and pull commands * rootless: not require userns for help/version * pkg/apparmor: use a pipe instead of a tmp file * podman in rootless mode will only work with cgroupfs at this point. * when searching, survive errors for multiple registries- Changelog for v0.8.2.1 (2018-08-11) * Ensure pod inspect is locked and validity-checked * Swap default CGroup manager to systemd - Changelog for v0.8.2 (2018-08-10) * We need to sort mounts so that one mount does not over mount another. * search name should include registry * removeContainer: fix deadlock * Add FFJSON to build container * Add FFJSON generation to makefile * Fixed a bug setting dependencies on the wrong container * Always connect to the stdout and stderr of stream * apparmor: respect "unconfined" setting * oci.go: syslog: fix debug formatting * add podman pod inspect * Fix CGroupFS cgroup manager cgroup creation for pods * Pass newly-added --log-level flag to Conmon * Cleanup man pages * Improve ps handling of container start/stop time * rootless: fix user lookup if USER= is not set * Add dpkg support for returning oci/conmon versions * Have info print conmon/oci runtime information * Better pull error for fully-qualified images * Add Runc and Conmon versions to Podman Version- Add a dedicated conmon for podman as the requirements on the specific version started to differ from the ones of CRI-O. This change implies dropping the requirement on the cri-o package. - Add libpod.conf as a new source to allow tweaking the search paths for openSUSE. This change makes execution slightly faster.- Changelog for v0.8.1 (2018-08-03) * Added ps --pod option * clarify pull error message * Man page fixes found by https://pagure.io/ManualPageScan * rootless: do not segfault if the parent already died * Document the properties of DefaultTransport a bit better. * Add --force to podman umount to force the unmounting of the rootfs * network: add support for rootless network with slirp4netns * Add documentations on how to setup /etc/subuid and /etc/subgid * podman rmi shouldn't delete named referenced images- Changelog for v0.7.4 (2018-07-27) * Add pod pause/unpause * Fix up docker compatibility messages * Fix handling of Linux network namespaces * Cleanup descriptions and help information * Add pod kill * Added pod restart * podman: allow to specify the IPC namespace to join * podman: allow to specify the UTS namespace to join * podman: allow to specify the PID namespace to join * podman: allow to specify the userns to join * spec: allow container:NAME network mode * Add libpod namespace to config * Add missing runtime.go lines to set namespace * Set namespace for new pods/containers based on runtime * Add --namespace flag to Podman * Update documentation for the State interface * Ensure pods are part of the set namespace when added * Enforce namespace checks on container add * Add container and pod namespaces to configs * AppArmor: runtime check if it's enabled on the host * Add format descriptors infor to podman top * docs/podman-top: fix typo and whitespace- Changelog for v0.7.3 (2018-07-20) * Podman load/tag/save prepend localhost when no repository is present * Pod ps now uses pod.Status() * Added pod start and stop * rootless: support a per-user mounts.conf * secrets: parse only one mounts configuration file * rootless: allow a per-user registries.conf file * rootless: allow a per-user storage.conf file * rootless, docs: document the libpod.conf file used in rootless mode * podman-top: use containers/psgo * oci: keep exposed ports busy and leak the fd into conmon * Fix ps filter with key=value labels * rootless: require subids to be present- Changelog for v0.7.2 (2018-07-13) * Only print container size JSON if --size was requested * Don't print rootfs and rw sizes if they're empty * Major fixes to podman ps --format=json output * Ignore running containers in ps exit-code filters * rootless: correctly propagate the exit status from the container * rootless: unshare mount namespace * Need to wait for container to exit before completing run/start completes * If proxy fails then then signal should be sent to the main process * fix pull image that includes a sha * Added full podman pod ps, with tests and man page * Podman pod create/rm commands with man page and tests. * Added created time to pod state * Support multiple networks * podman rmi should only untag image if parent of another * build: enable ostree in containers/storage when available * podman/libpod: add default AppArmor profile * rootless: propagate errors from GetRootlessRuntimeDir() * rootless: resolve the user home directory * rootless: fix when argv[0] is not an absolute path * urfave/cli: fix regression in short-opts parsing * Add --volumes-from flag to podman run and create * Mask /proc/keys to protect information leak about keys on host * Podman stats with no containers listed is the same as podman stats --all - install missing podman (1) manpage - podman-rpmlintrc: ignore missing-call-to-setgroups-before-setuid wari - install bash completion at /usr/share/bash-completion/completions - buildmode=pie: build position independent code- Changelog for v0.7.1 (2018-07-06) * Block use of /proc/acpi from inside containers * Remove per-container CGroup parents * rootless: add /run/user/$UID to the lookup paths * rootless: add function to retrieve the original UID * rootless: always set XDG_RUNTIME_DIR * rootless: set XDG_RUNTIME_DIR also for state and exec * urfave/cli: fix parsing of short opts * docs: Follow man-pages(7) suggestions for SYNOPSIS * Allow multiple mounts - re-enable varlink support (build conditional)- Changelog for v0.6.5 (2018-06-29) * Fix built-in volume issue with podman run/create * Add `podman container cleanup` to CLI * Allow multiple containers and all for umount * Returning joining namespace error should not be fatal * Test to verify overlay quotas work, show container overhead on quota * Remove the --registry flag from podman search * utils: fix endless write of resize event * Start prints UUID or container name that user inputs on success * Fix podman hangs when detecting startup error in container attached mode * podman-build --help: update description * docs: add documentation for rootless containers * Add --authfile to podman search * Add podman-image and podman-container man page links * make varlink optional for podman- Changelog for v0.6.4 (2018-06-22) * Point podman-refresh at the right manpage * Add bash completions for podman refresh * Add manpages for podman refresh * Add podman refresh command * Add information about the configuration files to the install docs * Add unittests and fix bugs * Podman history now prints out intermediate image IDs * Add cap-add and cap-drop to build man page * Fix image volumes access and mount problems on restart * Add carriage return to log message when using --tty flag * Added --sort to ps * Fix podman build -q * Add extra debug so we can tell apart postdelete hooks * TLS verify is skipped per registry. * Add --all,-a flag to podman images * top: make output tabular * Add more network info ipv4/ipv6 and be more compatible with docker * Do not run iptablesDNS workaround on IPv6 addresses * Added --tls-verify functionality to podman search, with tests- Changelog for v0.6.3 (2018-06-15) * podman: use a different store for the rootless case * podman: do not use Chown in rootless mode * network: do not attempt to create a network in rootless mode * oci: do not set resources in rootless mode * oci: do not use hooks in rootless mode * oci: do not set the cgroup path in Rootless mode * spec: change mount options for /dev/pts in rootless mode * container: do not add shm in rootless mode * podman: provide a default UID mapping when non root * podman: accept option --rootfs to use exploded images * When setting a memory limit, also set a swap limit * Fix cleaning up network namespaces on detached ctrs * Implement --latest for ps * Added --sort flag to podman image * add podman container and image command * rmi: remove image if all tags are specified- Changelog for v0.6.2 (2018-06-08) * Vendor in latest buildah code * Update epoch to fix validation problems * Touch up whitespace issue in build man * Add disable-content flag info to man page for build * podman-run: clean up some formatting issues * Remove SELinux transition rule after conmon is started. * Add --all flag even though it is a noop so scripts will work * podman-varlink: log timeouts * bash completion: remove shebang * Vendor in latest containers/storage- Make use of %license macro- Changelog for v0.6.1 (2018-06-01) * Fix lable handling * runtime: add /usr/libexec/podman/conmon to the conmon paths * varlink build * Add OnBuild support for podman build * return all inspect info for varlink containerinspect * hooks/exec: Allow successful reaps for 0s post-kill timeouts * fix panic with podman pull * Remove --net flag and make it an alias for --network * Clear all caps, except the bounding set, when --user is specified. Fix: bsc#1097970 CVE-2018-10856 * do not allow port related args to be used with --network=container: * sort containers and images by create time * Cleanup man pages- Changelog for v0.5.4 (2018-05-25): * Make references to the Process part of Spec conditional * save and load should support multi-tag for docker-archive * Implement python podman create and start * Set Entrypoint from image only if not already set * Update podman build to match buildah bud functionality * Fix handling of command in images * Add support for Zulu timestamp parsing * Clarify using podman build with a URL, Git repo, or archive. * podman create, start, getattachsocket * oci-hooks.5: Discuss directory precedence and monitoring * Tighten the security on the podman varlink socket- Changelog for v0.5.3 (2018-05-18): * troubleshooting: Add console syntax highlighting * Refresh pods when refreshing podman state * Add per-pod CGroups * Add pod state * hooks: Fix monitoring of multiple directories * Add Troubleshooting guide * Add python3 package to podman * libpod: fix panic when using -t and the process fails to start * Allow push/save without image reference * Fix podman inspect bash completions * Support pulling Dockerfile from http * add more bash completions * implement varlink commit * fix segfault for podman push * Add the Podman Logo * hooks: Add package support for extension stages- Changelog for v0.5.2 (2018-05-11): * Fix varlink remove image force * Do not error trying to remove cgroups that don't exist * Remove parent cgroup we create with cgroupfs * Place Conmon and Container in separate CGroups * Add --cgroup-manager flag to Podman binary * Major fixes to systemd cgroup handling * Add validation for CGroup parents. Pass CGroups path into runc * varlink info * Dont eat the pull error message for varlink * podman push should honor registries.conf * alphabetize the varlink methods, types, and errors in the docs * Add missing newline to podman port * Fix calculation of RunningFor in ps json output * Should not error out if container no longer exists in oci * Make invalid state nonfatal when cleaning up in run * podman, userNS: configure an intermediate mount namespace * networking, userNS: configure the network namespace after create * Begin wiring in USERNS Support into podman- Remove runtime dependency on buildah, which isn't required anymore as libpod vendors in buildah's code directly. - Changelog for v0.5.1 (2018-05-04): * Fix pulling from secure registry * Optionally init() during container restart * bashcompletion enhancements * Add directory for systemd socket and service if not present * varlink containers * Make podman commit to localhost rather then docker.io * Do not print unnecessary Buildah details during commit * Fix podman logout --all flag * podman should assign a host port to -p when omitted * libpod.conf: Podman's conmon path on openSUSE * correct varlink command in service file * Make ':' a restricted character for file names- Update podman to v0.4.4: * Use buildah commit and bud in podman * Remove systemd-cat support * Add --default-mounts-file hidden flag * Add isolation note to build man page * Strip transport from image name when looking for local image * Do not eat error messages from pullImage * Modify --user flag for podman create and run * add libpod.conf man page- Update podman to v0.4.3: * podman push without destination image * Add make .git target * Fix tests for podman run --attach * Vendor in latest containers/image and contaners/storage * It is OK to start an already running container (with no attach) * Allow podman start to attach to a running container * regression: tls verify should be set on registries.conf if insecure * ip validation game too strong * reverse host field order (ip goes first) - fix host string split to permit IPv6 * Allow podman to exit exit codes of removed containers * validate dns-search values prior to creation * Add WaitContainerReady for wait for docker registry ready * podman pull should always try to pull * Allow the use of -i/-a on any container * Fix secrets patch- Require golang >= 1.9.- Update podman to v0.4.2: * Allowing attaching stdin to non-interactive containers * Fix terminal attach * Fix locking interaction in batched Exec() on container * Force host UID/GID mapping when creating containers * Do not lock all containers during pod kill * Do not lock all containers during pod start * Make pod stop lock one container at a time * Containers transitioning to stop should not break stats * Add -i to exec for compatibility reasons * Unescape characters in inspect JSON format output * Use buildah commit for podman commit- Update podman to v0.4.1: * Remove image via storage if a buildah container is associated * Add hooks support to podman * Run images with no names * Prevent a potential race when stopping containers * Only allocate tty when -t * Add conmon-pidfile flag to bash completions/manpages * --entrypoint= should delete existing entrypoint * Do not require Init() before Start() * Ensure dependencies are running before initializing containers * Add container dependencies to Inspect output * Vendor in latest containers/image * Change errorf to warnf in warning removing ctr storage- Split out podman's basic CNI configuration to podman-cni-config, to avoid breaking Kubernetes clusters due to misconfigured networking. On openSUSE we still install this configuration so things "just work" there.- Update podman to v0.3.5: * Allow sha256: prefix for input * Add secrets patch to podman * Only start containers that are not running in pod start * Check for duplicate names when generating new container and pod names. * podman: new option --conmon-pidfile= * Remove dependency on kubernetes * Vendor in lots of kubernetes stuff to shrink image size * cmd/podman/run.go: Error nicely when no image found * Update containers/storage to pick up overlay driver fix * First tag, untag THEN reload the image- Update podman to v0.3.4: * Make container env variable conditional * Small manpage reword * Document .containerenv in manpages. Move it to /run. * Add .containerenv file * Removing tagged images change in behavior * Image library stage 4 - create and commit * Add 'podman restart' asciinema- Remove old (redundant) source archive.- Do not compile commit hash into binary. `podman version` will not print the commit number as we are now following official releases. - Change tar naming from commit to version to facilitate updates via the _service file. - Update podman to v0.3.3. This update includes several fixes and a new configuration file, libpod.conf. By default, this config will be installed to /usr/share/containers and /etc/containers, whereas podman will always use the latter if present. The config in /usr/share/containers can be used to check for new config options and will be replaced with each package update. The libpod.conf config can be used to tweak some run-time paths of conmon, runc, etc., which is a more flexible approach than hard-coding those paths in podman. Changelog: * Update containers/image * Add restart to main podman manpage * Add podman restart to podman bash completions and commands * Make manpage more clear * Add 'podman restart' command * Remove ability to specify mount label when mounting * Add signal proxying to podman run, start, and attach * We should not allow a user to mount a container with a different label * We should not have a default workdir * Add additional debug logging * Implement container restarting * sleep does not catch SIGTERM * Include tmpfs in inspect * Add run and search to commands page * Add new default location for conmon * podman-images: return correct image list * Remove crio.conf references from manpages * Fix a potential race around container removal in ps * podman ps command string too long * Podman load can pull in compressed files * Fix Conmon error to display Conmon paths * Add support to load runtime configuration from config file * Add default libpod config file * Change conmon and runtime paths to arrays * Update containers/storage to fix locking bug- Add requirement on cni-plugins to avoid potential issues in the future. feature#crio- Add run-time requirement on buildah to support `podman build`. feature#crio- Fix typo when setting the git commit at compile time.- Update podman to v0.3.1: * allow DNS resolution in containers * Adjust podman logs error message for clarity * Instead of erroring on exit file not being found, warn * podman logs -f: does not detect container stop or rm * Fix issue with podman logs on fresh containers * Replace usage of runc with runtime * Handle removing containers with active exec sessions * Ensure that Cleanup() will not run on active containers * Add tracking for exec session IDs * Add tracking for container exec sessions to DB * Small fixes to container Exec * docs/podman-info.1.md update man page * Update containers/storage * podman info add registries * podman stats add networking * CNIPluginDir: check "/usr/lib/cni" * remove build alias * Restrict top output to container's pids only * ps displays incorrect exit code * podman load dont panic when no repotags * Do not override user mounts * Tagging an image alias by shortname * Add support for --no-new-privs * podman ps json output use batched ops * CreateContainerStorage by image id * Implement --image-volumes for create and run * Add ability to start containers in a pod * Add kill and stop for pods * Add pod status command * Add tests and cleanup * Implement podman run option --cgroup-parent * Inspect output should be in array form * Add --time alias to manpages * Alias --time to --timeout for 'podman stop' * Resolve contention between copr and fedora repos * Ensure we don't repeatedly poll disk for exit codes * Change uptime format in `podman info` to human-readable- Replace macro by the entire URL in the spec file.- Add podman-rpmlintrc to ignore "explicit-lib-dependency" warnings. Those are intentional as we must include the libcontainers-* packages. + podman-rpmlintrc - Update to podman v0.2.1 (change to semantic version scheme): * Run podman inside a podman container * Add FFJSON encoding/decoding for our container structs * images --all developer note * Add podman version * Touch up tutorial location and install reqs * No registries warning * Return imageid from podman pull * Squash logged errors from failed SQL rollbacks * Privileged containers should inherit host devices * Disable default Seccomp profile with privileged containers * Make libpod build on 32-bit systems * Add buckets for all containers and all pods * Containers in a pod can only join namespaces in that pod * Change json to match docker inspect * Honor ENTRYPOINT in image * Fix libpod to use given CGroup parent instead of a hardcoded one * podman logs: fix tailing * Allow removing pods with running containers if --force is given * Match podman inspect output to docker inspect * Touchup podman kill manpage * Change stop signal default to SIGTERM * Add podman search command * sysfs should be mounted rw for privileged * Need to add LISTEN_PID environment variable to conmon command * Add authfile, cert-dir and creds params to build- Add requirement on libcontainers-common, which now provides the /etc/containers/policy.json config. - Use golang-packaging macros. - Set version to +git%{rev_list} scheme as there's no official release yet. - Spec file cleanups via spec-cleaner. - Add requirement on libcontainers-{common,image,storage}, which provide configuration files, manpages and debugging tools useful and required by podman.- Fix typo to provide the correct package. - Replace tabs with spaces.- Fix libostree-devel %if condition for TW, Leap 15+ and SLES 15+.- Use `%fdupes %buildroot/%_prefix` since `fdupes %buildroot` is not allowed because you cannot make hardlinks between certain partitions.- Add podman package: podman is a simple client only tool to help with debugging issues when daemons such as CRI runtime and the kubelet are not responding or failing./bin/sh/bin/sh/bin/sh/bin/shpodman-cni-configs390zp37 1719825102   !"#$%&'()*+,-./0123256782:;<=>?@ABCDDFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdedghijklmnopqrstuvwxyz{|}~D4.9.5-150500.3.15.14.9.5-150500.3.15.14.9.54.5.1 podmanpodmanmodules-load.dpodman.confpodmanquadletrootlessportpodman-system-generatorpodman-auto-update.servicepodman-auto-update.timerpodman-clean-transient.servicepodman-kube@.servicepodman-restart.servicepodman.servicepodman.socketpodman-user-generatorpodman-auto-update.servicepodman-auto-update.timerpodman-kube@.servicepodman-restart.servicepodman.servicepodman.socketpodman.confpodmanfishvendor_completions.dpodman.fishpodmanLICENSEpodman-attach.1.gzpodman-auto-update.1.gzpodman-build.1.gzpodman-commit.1.gzpodman-completion.1.gzpodman-compose.1.gzpodman-container-attach.1.gzpodman-container-checkpoint.1.gzpodman-container-cleanup.1.gzpodman-container-clone.1.gzpodman-container-commit.1.gzpodman-container-cp.1.gzpodman-container-create.1.gzpodman-container-diff.1.gzpodman-container-exec.1.gzpodman-container-exists.1.gzpodman-container-export.1.gzpodman-container-init.1.gzpodman-container-inspect.1.gzpodman-container-kill.1.gzpodman-container-list.1.gzpodman-container-logs.1.gzpodman-container-ls.1.gzpodman-container-mount.1.gzpodman-container-pause.1.gzpodman-container-port.1.gzpodman-container-prune.1.gzpodman-container-ps.1.gzpodman-container-rename.1.gzpodman-container-restart.1.gzpodman-container-restore.1.gzpodman-container-rm.1.gzpodman-container-run.1.gzpodman-container-runlabel.1.gzpodman-container-start.1.gzpodman-container-stats.1.gzpodman-container-stop.1.gzpodman-container-top.1.gzpodman-container-umount.1.gzpodman-container-unmount.1.gzpodman-container-unpause.1.gzpodman-container-update.1.gzpodman-container-wait.1.gzpodman-container.1.gzpodman-cp.1.gzpodman-create.1.gzpodman-diff.1.gzpodman-events.1.gzpodman-exec.1.gzpodman-export.1.gzpodman-farm-build.1.gzpodman-farm-create.1.gzpodman-farm-list.1.gzpodman-farm-remove.1.gzpodman-farm-update.1.gzpodman-farm.1.gzpodman-generate-kube.1.gzpodman-generate-spec.1.gzpodman-generate-systemd.1.gzpodman-generate.1.gzpodman-healthcheck-run.1.gzpodman-healthcheck.1.gzpodman-help.1.gzpodman-history.1.gzpodman-image-build.1.gzpodman-image-diff.1.gzpodman-image-exists.1.gzpodman-image-history.1.gzpodman-image-import.1.gzpodman-image-inspect.1.gzpodman-image-list.1.gzpodman-image-load.1.gzpodman-image-ls.1.gzpodman-image-mount.1.gzpodman-image-prune.1.gzpodman-image-pull.1.gzpodman-image-push.1.gzpodman-image-rm.1.gzpodman-image-save.1.gzpodman-image-scp.1.gzpodman-image-search.1.gzpodman-image-sign.1.gzpodman-image-tag.1.gzpodman-image-tree.1.gzpodman-image-trust.1.gzpodman-image-umount.1.gzpodman-image-unmount.1.gzpodman-image-untag.1.gzpodman-image.1.gzpodman-images.1.gzpodman-import.1.gzpodman-info.1.gzpodman-init.1.gzpodman-inspect.1.gzpodman-kill.1.gzpodman-kube-apply.1.gzpodman-kube-down.1.gzpodman-kube-generate.1.gzpodman-kube-play.1.gzpodman-kube.1.gzpodman-load.1.gzpodman-login.1.gzpodman-logout.1.gzpodman-logs.1.gzpodman-machine-info.1.gzpodman-machine-init.1.gzpodman-machine-inspect.1.gzpodman-machine-list.1.gzpodman-machine-ls.1.gzpodman-machine-os-apply.1.gzpodman-machine-os.1.gzpodman-machine-rm.1.gzpodman-machine-set.1.gzpodman-machine-ssh.1.gzpodman-machine-start.1.gzpodman-machine-stop.1.gzpodman-machine.1.gzpodman-manifest-add.1.gzpodman-manifest-annotate.1.gzpodman-manifest-create.1.gzpodman-manifest-exists.1.gzpodman-manifest-inspect.1.gzpodman-manifest-push.1.gzpodman-manifest-remove.1.gzpodman-manifest-rm.1.gzpodman-manifest.1.gzpodman-mount.1.gzpodman-network-connect.1.gzpodman-network-create.1.gzpodman-network-disconnect.1.gzpodman-network-exists.1.gzpodman-network-inspect.1.gzpodman-network-ls.1.gzpodman-network-prune.1.gzpodman-network-reload.1.gzpodman-network-rm.1.gzpodman-network-update.1.gzpodman-network.1.gzpodman-pause.1.gzpodman-play-kube.1.gzpodman-pod-clone.1.gzpodman-pod-create.1.gzpodman-pod-exists.1.gzpodman-pod-inspect.1.gzpodman-pod-kill.1.gzpodman-pod-logs.1.gzpodman-pod-pause.1.gzpodman-pod-prune.1.gzpodman-pod-ps.1.gzpodman-pod-restart.1.gzpodman-pod-rm.1.gzpodman-pod-start.1.gzpodman-pod-stats.1.gzpodman-pod-stop.1.gzpodman-pod-top.1.gzpodman-pod-unpause.1.gzpodman-pod.1.gzpodman-port.1.gzpodman-ps.1.gzpodman-pull.1.gzpodman-push.1.gzpodman-rename.1.gzpodman-restart.1.gzpodman-rm.1.gzpodman-rmi.1.gzpodman-run.1.gzpodman-save.1.gzpodman-search.1.gzpodman-secret-create.1.gzpodman-secret-exists.1.gzpodman-secret-inspect.1.gzpodman-secret-ls.1.gzpodman-secret-rm.1.gzpodman-secret.1.gzpodman-start.1.gzpodman-stats.1.gzpodman-stop.1.gzpodman-system-connection-add.1.gzpodman-system-connection-default.1.gzpodman-system-connection-list.1.gzpodman-system-connection-remove.1.gzpodman-system-connection-rename.1.gzpodman-system-connection.1.gzpodman-system-df.1.gzpodman-system-events.1.gzpodman-system-info.1.gzpodman-system-migrate.1.gzpodman-system-prune.1.gzpodman-system-renumber.1.gzpodman-system-reset.1.gzpodman-system-service.1.gzpodman-system.1.gzpodman-tag.1.gzpodman-top.1.gzpodman-umount.1.gzpodman-unmount.1.gzpodman-unpause.1.gzpodman-unshare.1.gzpodman-untag.1.gzpodman-update.1.gzpodman-version.1.gzpodman-volume-create.1.gzpodman-volume-exists.1.gzpodman-volume-export.1.gzpodman-volume-import.1.gzpodman-volume-inspect.1.gzpodman-volume-ls.1.gzpodman-volume-mount.1.gzpodman-volume-prune.1.gzpodman-volume-reload.1.gzpodman-volume-rm.1.gzpodman-volume-unmount.1.gzpodman-volume.1.gzpodman-wait.1.gzpodman.1.gzpodmansh.1.gzpodman-systemd.unit.5.gzquadlet.5.gz_podman/run//usr/bin//usr/lib//usr/lib/modules-load.d//usr/lib/podman//usr/lib/systemd/system-generators//usr/lib/systemd/system//usr/lib/systemd/user-generators//usr/lib/systemd/user//usr/lib/tmpfiles.d//usr/share/bash-completion/completions//usr/share//usr/share/fish//usr/share/fish/vendor_completions.d//usr/share/licenses//usr/share/licenses/podman//usr/share/man/man1//usr/share/man/man5//usr/share/zsh/site-functions/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:34521/SUSE_SLE-15-SP5_Update/b3c619bc476c270be6fcb4aff93e1235-podman.SUSE_SLE-15-SP5_Updatedrpmxz5s390x-suse-linux                    cannot open `/home/abuild/rpmbuild/BUILDROOT/podman-4.9.5-150500.3.15.1.s390x/run/podman' (No such file or directory)ELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, BuildID[sha1]=4d24962f88ebf11c40d1397448f03aedae963b09, for GNU/Linux 3.2.0, strippeddirectoryASCII textELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, BuildID[sha1]=37a871d1c472ca80672f456d0899154f6172915d, for GNU/Linux 3.2.0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, BuildID[sha1]=8578b2afe3d6d61c12dbb231257ec7014ae1977f, for GNU/Linux 3.2.0, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix) RRRRRRR R RR RRRRRRRRRRR RRR R RRRRR RR RR RRRRRR 㻁/DmL)Ehtapparmor-abstractionsapparmor-parsergvisor-tap-vsockkatacontainersnetavarkutf-8c7f0f4e17820aaf16740ad646b23be7d80695def7ede5f1538f8f91b2cd6b70f?7zXZ !t/X]"k%w#/A,[VS>RpK :"݀at< [vmV$\o|Jh3e8-kp>T6'jXӉQNWydce"Jn7 %"_@s]c/3uFM ?N' L}]D8㠣WT+_A$@[ sqeQ7a8]1i$ZWq}HݘHh}=nWc+M؈рƯ|OE.8.@'j:=Fg 8ONmdTkΦiP{ ɓai=BߍQ#܄㓳vN\ۯN`![_5Q5BNshTj#Dto'h"o昴^LY]ŸpPpd6 OD6a3y,g,RpRr7MɆ'x~(Ty| 9}ԢЂwmկ1Y? HEooC<>ugOGx bZwz<G5xKs751t?r<+3x({Z#1GܵU%C(v8O`C|f!)Y~#36␌_lʼxJtqg{͋3SA=2w'rZ,ab۞P?{Qc*-s*aC>\ 1sBس$9;D"yI X/WܨIxXJU•9փB%a1gȤ:o\R7oN b*sz0R 1 Dr&ο$4b*=zR:7cV0coU.HXUYú0kbj=xOz^x<`_ו|fR)i& )5F̪d͂[rW@l1{X1ʆ<1;~nH\q!q7](%_5o*\,z$$o|Fǐ/S_.҃σ֨Ȭ+{}a& vmH&2 a熪ٓyh Ú+F߅Uo1heUuUwKfflx} >3_ٌ֌4}N'@N#9' 9L}LG {AܾerG[jN'3|ad~ųRक.H/.Xns?F7Cbz,s(q=w@P }x{ce)8u44>P`OλձPel$ 8b#5h6@BӒ@]%W.ALZ]FjQ Q?E a,Zh=b8;;!Pc%ׄ *1 Ǻ>e\ SX";vijb8|X=̂j&I$SI*mhD#՟l"l{BF|`(+/׸iMflPh9Q.Yy§s؍Mh*k(7 2KEp,Xtku:O5b{3"tNJU_RyF3""^Y2%--:!;?i^pS+#wn/FMCҞt;l@u<\FCA ys^ OZk yw,ϷXi|U\^:WCu/'{OJ,/mG'~&pV ۴m1x8\]+Ŋ 5 @I v& .G I=%zPtfdx}U_ĀIi Ӳ1mC@{lTD: Z~].:wD^^Irt0 B%? n^p:'M!{~r\@QG> |#=ُP#K_xvJhW1f0yGa#eEO,@&"+gCH"8ej}Z{ "V|B$%&W w< /`B2B ӈqnV,G%xS~ ~Cr'0iZq1U~)M5&婤,ok 9r-KN2JS= Oĵ ;=>OVa|qY:"6fY&}oM9ս-E<>lb8+7 EU:@; %Kގ:湺b e۪j&S:f4Zǟ4pS'dRu"y9ȿ>k&\ïC!%2(J~3Uؓq*e߶=F ;֏QB2>asD笈g&\˕ejBҷ&F#[\Vs:ᑦ& [̮Oi\p'᧥Q2Zg} `-%V'g,KR.[@ 7<)_^b Vls$t˹=Su'ҾiS|b5߂g>^4u0%˶BB2j^~jr9Δ8P(y&yRa { hZu?;TƌQ>j?0#*p~KTr:L:$q$ĩ sy3 t (K]Ϋ0x΋ۓSAyڶ;}s]c$ož58Gyέ&Zv,m+}n$GI)2B{鼁VV!I^(jM2Zt0:d}h]oȬ1gGȽǺqJsﻮ5p4d3h8sl580uI= q4a$'o ŕS4Nvh}pjM#`1 "j2%SA n,rkn>N =zʫ_ N+Iyz$YB vэA]tDzI6^g!bB Nw]6UgQtVn!K=F{."_-~#Ah;*5Eh⡍Luj~Zn8Br?}.t"kWYyKXW6)C7hKY]N qvA?:1-&+yrb~5"LW10 dωkQ>^YGMi P lIa۷\B <׾_*%u" Z\bfH>_$#w܏plDʓ]5s[ "+Fe QoJESZF C<{is^-!,'Mt7d*HA@fdbcZwPZt-1 `h0O>^- NyNŔb7AfAí'r5f ($ȃscwov6WU眺UP:$֛<ڒԙL#{5% Tq ($hεDN lQFc=rG/T*bvJ\J?.4ѩ_7:|PN$Up1/ < Ucd#PAGcV71&bsڠ;ւꮙ!13ҕ&BhQe1i=w@bL%3m1٨=pT{~j - ¼ŧ|&c4s6e~¼5QJM.P(IZ G/S0,l`6Bjp*L&;7{ƺe]T3h4du 2#-OI_%[\=&T7:gd&"|yb}Fc]۴T2@uꛏ;k|EP;4_/J-_pI xjzm[mJ#f<<ׅ#9f伇t!gQTl|< O(OE^2<'_kup:ov~ٝsYAbT2ř@,EZ)7]fAC`63h$,n)NJLRg.Y W+ u0y.Ed@=1.I:sDod''(Y*c8PG̱esQD|[.6&>U)Fa{P$FہknJ=0 A hGjp'WfL{ۧ5j2DYJ6|^ RhC$ܲK' i9};eV9k'_/;d3uJegR6+U&B.b[+720U;ys_\ bhz5&H6$4n<5\eXy ĕϛ\m6?0VDLX̀*8JN7U%< ^o_~I 0ϩ0֖vs?ĕϦ*= ,EDkN7 I)CXx`-<*^o (fѪHBJBd.@VN!@ZhȆ"gTVqg1$c%ʦ(uL/",zK7l &s/ uTV18aioErx$ ~OI, hHf]x݈ iғQɼid`T|1'wtYqT h`Hg&j=Ӈ80|*,(RVS:m&E!p:qfaz #m913F 7bOd K]O%h.Ve45C]%g*ǵmG JoWmݽ n/&Gґ_]APZrRbiv;R`ul<߁ЂDKqƓ9.txEj1Lyڍ Y)n;rڰoi҇L}ȏ9q-L b, 67l65uf8)tQPV0CPDOTL<]4Q Sǀ?;tdd#W^Շ?&Ժ 0|ؔWZh۪̄H3Mp'*)[K!ɔr"@.18XS$1_ᬫ=QVL3|ܙkj pnݭ$aNHKtN;: Wj\~Rب^t3AxU-A\ZmoP5 6-PI@:%a-:mjN hFx|ݵuDl)?jPcvFV=wF:<%c )r[j ͽO9}<_ٰn#5i\:𥞞PH4An28cŬ2lws229֖5[(9أjU$/2D \싇;KZS;]na}M9%\~L]y'ihW:(4@Xbm,\Hs "'O*:١_Jo8Rj̀#g]>UmIJ0d0ZtfV8| !4tZ $&}SGUA1\hp#'[vF =tS*#RL Hcy*wD|km9rkrhDjG#@nzt.!D;A&**9}8 E,R,7OeptaG-,pc,дa`WLQ=pcdҨѠx֦4 Ir#r5d' ںG 4:xKY6:|1qI-L 3r?xj?5 KYCxxSM WG)ٽ@mk温7dm:+NAʀhWڤ ;J s+OOԓ.mK r4IoTe5iBчT[`-c] ,| 6*#psG#tJX|/]L9iǎZ_|@o~'W#Ƞ5J{pХk^tيG?4fں Q O}AJ1*C>3W HiY VF] =㌑k5Oʨh`'ErG+X^LT9w)q]rBGUPqv,:aMNЗ!̦<"rzl\[Ga [{y9.ud5Y[mEgRr~[w"]{ y3diOBK.q-po@7Gpk_ 1#⁓<\P*A Bx5kdw;(/_g~t1+So_R;еd2x? %md~we NBr)ͅcH24 |fMQ3#EtXw#,q! P.Q֡0ΐal*VoFdW|.RuIM/I< pYs+FU6d0ooF/LK3cUz>А4;v# Ȉ:q"tĦX02C݉)Ѩ -Y:S1j2frUTȥcI5~we.ğ_{ެ`"nӡ (vY^krmynA>C,!b\A5cskDT͏otEYv|V=z š8njiyJVNm]vu71݃᰸:E +yʱɐN={{&"tBH"ᙖgA<Дbm +D#9?`X@)D]$@:#jZd˝6;gRXj (G( O+-_ϓ܅rmd1ʒWH<%^P*]38^] ddqv1N #D~aًz3;(QI7$Xx6q:Gt 'o'"tc aBXtvߣI\ͽ@ӭR:ǃk8q,#YiEJ8Iٚ{13Л"[3+Uz(]e#z) =sfWѻÈѳͤ 94~nRl%B)08~`Z}}qZSщtcJaH G:\N(( cNQ41 x$s@Ơ *.6P]85avyv~#η)z+VֺNT0q8/A%q4afLo{RcdSEYb[.x9{pxlr_i  V-Bwq/?l5)*%%CZ`aPi) @înXT!:&O)N%Rla+s2AۊE鄱 __3.誑Nj׬ U3HJeyßGab0''Y-yeC%. _Z5#aGc&ٞfDPXgcPC]L u=z7:j uϏbл`4܌AeU`lVq~d̗ъ^vǼA6H ZR OZo4)+`E<0L7^WCNQ#*ͣ b;T ]Fyd}\v` Kgz!GcH \ţ?YV~9\7T"wFGU0TGkKHw-IW,qn<,AJ.ݞF}~ݷy23E*Jj982^k=S@zYXǛ7C":Qrq$f4J̘VxY`RaS#zH`~3uiDVUm2:]V.%׮a:>'x? مɮe[AQ3;:^-w'`pyvx~ط*xzg#q_iʄ$CVU?NNB[Ui*=˖M(^@oLgq;xk>|]CȹfϤCAwҷB ׶5I[ݔWR*55mI*A;+sTWV0wn*md50ꩵ IJn ,9KH)k0.Ёs*Mֶӈ'V'eT$;'(oF7_2Ж. grگ@fE߼/`&1?Un ]v45',g}%(_ Թcݜ6Lu.rC2G9YxZBF Úm:I`omWc[꺊Sq4HM1c7ۑ.9%zXa=[u=o떩 , .QB+rqBlOO-φɆąVyALML7 ě$6ƔlX{O[q3Y!Bo|%a`qbsz @!J4{QZX{ ))&EꑗfzbUBJ,_k+/i?|$ Zo25ـz8T0ڹxKaA%άlQ23?BXwhmFN[ɮQV2< >HTx}Rۥ h\t㫗S;Nn(03Ǿ_{b{}'|E FOVDZ-=\@PqڕR/=cjBw[omKo.DO۫J2Td}"DYu8l͕MtG|GL%`,ͰI!Dh[[b!P$hس%7N*J \97,[ea b!G+v]ٚhv1cXX^|˳ߚ<ߘ|3LrZн@4>%[|,G ,C;hs=*@z^cI~;Bk_쟈x:9QL5@]pSdu*<ҏXE%)&]h!aAj'HGJh›'8o2,Kd yK7x eg3X\CB`Ì<) K0`KA]&;K"U7gFbqA҆ijФD.? Z|b`޹&҈C[dQ#lϑ[R ܲmʰCx%72y47@!eWi=^*18Y\W^<.Y/ *u!'&\v1q<V]iN൳Z8CdH32aw&2%4z D /NpS42燄ǪTzʁ=xJм 7 &GhJdkrԤT6Uղmm 7x9>4zkys̬yG@5{C-j+r~{}Qbk#7<;JO?GQFŤU:FQGhB$??3[)j(^ h 7%\\C~֟l}!>Kqx 梸S EYDc$֛F#<,p{jI HDrD|qT2m й/):/m`ێ p1J(>. QɼWZ|>H0V 9si7 WҖ-ɷXm]sqR鿣ײJ-t鰧z$=4s00Z4^=4&Ԗ ivz_ v$7!Fέ,$G2QZfT-FԱ PC)0\;o9K>pycgZ@X£H"8*6oߧ;N$Gg%(9HA+~41XA3"}yT[~3$*g.*!.N /ኁ[!2$P#̛}W\ 8e;l*DRɠ:5!%I^*JA,报hS1>;g ̼b6HZX$Hّ[3! *+ |ڸebhwM]GR yȞAUfܦcM~f= xYA.QN73A pR x:%o#K(dmMqɿ{:vyHY Yrp*1_~Қv*ѕkP R_ rR$ʞ"n[ oUwF.V@Es>Ss sn|»y#ԻMޣ'1Yz7}'V.9W8 wRb0704/Z\- 9M4 4n%' G48x CGv\%Ѐ M,!4]pE~!J> .舂z3b5n^6Ӕ0'.)C#`[^*z!$Х2[xsc; #`̙1k.7k ҩ Z]>$ܠWStC&Cuw9: P>I_1ߴ&hfzjt[TD:&Z2Żl}]|!q @LNOI  nS'_}cMap=o$)EʁɳG(rCt./f9ubZo0'Ka&! (k p8m9gO\1'LGd /0O+IEw*Sj,25ۗ?/6DDwtQÆ,̳/[Cq(RÁ`0@1q :E۽lidO0icB]RM44PY& ,)Voo@ǀ}t/_;9]5~0]""6сn*=;U結94)2l+taj$C[Z mi'œF4ՔIl9 e;Cb4ڻg$J~>KgpFA> XjGeu!Pj̜ywjށΤr"<{-HX䅪@$+6l5 X[Ql&)tLt8"fYNjqi:vPY w[eezX }2 Z 2)4>;$뜵Uys;bNkxoGR4'vĻ8O~`U!v0!joC~`O Z4lQGe:Btua]Jp`eX _SA]\~%nf)ƱTLn9; $1ngm-L蕉7Ͷ ƑEoFyc3x[؄C%ly.,ˊF;Lȿ5e ϝԋSIĎu":67^x$h(Ƒ\PvD[Xî"aAB 8^tiEl#MhX1s7:U%:82m@icY?3&a]׬m4OOeס*\ kлԑB{xaGLȨP~Uñp,l/KSQB:Vaԩ}zǠ= ihB}0]X!pi;o"Yёy&  qQ7ҁ%\c-s흍ىfnFAg rש)}P<p< iklL3=_[Tbvۿt{2XpIF-"5ޭt cv^d۠vBq6[E{j 6 u]z(\S_NfWh mȇ/i" Ǡ eVJGv*w)"eoJ}Q.MI-eʕ!dgvewUʸa=49RDGc&^Mֺ0lffK?LQ Ih>թ]%0qŰqY]w7\f"e!ܷd0(ILÕtL^V.e](I' ݹF˘ݜcv,H&Q%H_oA{7j__."gK#E\ + +X+s9Q5ͳN߇H>Vt}!:'W% ->2dbӵgFeuי< 97`A\?socI=aL:0 VimVSZoTԩp}ߨovsGrkUS Be7OYjrqEvu< Ds>yRmw<hKaTP2l򯁐` P)'(U ] 1N< Y?DзLse"F8XY|*4 vT xnM_MeINLrotReq`mFn:}2D |&$=U!{S:0˕[,ı+@[1ͼvu*Sc$5]$ѽmgMOqihʚo~@B}_8d*ȼ d/0Ei/S}ûUAﴳl?[6>Fr:]=|Gx1141crOJԮ&fb;vH^1Y "4S)K-M3h ]c:\uEu4͔͘Oaā?|ǯ4u.>dh 5lHa> 'v膮H?<3.Xo~O +4܌̒=u^u)hC HʭƂ]-C,nh=YĄ%Q]L$gڣ$sHް8ZJ 5sԻrc%űޕQvq]i?8 s28bHVԀq;oB/]:lr >v6Z _Go:æ1d) vIbc=m*?́%u9# yy1;añAvssfszq}\p~edQ+hHgEV\A3կB$ Gr]}|H\2XJr=>@v\GuG>`ItЕ0ƌR=jK(U6NگOצLTuHɖdkӈ:U-|N:YL.Gں O( ܀,_G'cz?S96I*CV+g R7tD YeF/O([Y Z:j ITxP~?Y%Ic2ē:..uleC@+χBac\t(ZQX+3o<+_;&9#JR7meqFCO ,υg9^89L׫`Ю7fQ!Sj/e43Y~޾|xEFQ]n 91WN vOL\F'߄Kf1MxY VG5O}TJU-Zv:Q+ vcq'Nw^|>\'?ϻVt{A,Ipgtt "J/!(L^19) ȍ]7U_X~*-I%&S20ʤyҦ& ǃuXW4v}X;PskEj|2ks_ǃlP([k_5أ΀0pkmjF!9pWxh̋X!Wb`Z,Fqn'C "[Θ k%ҮvacdKz%#.gwFAXO&k[Mw$$4ʝlDfcqۧjjHg`3$[ʊ0X`or+OAHi ^ ´w{~@;?vN v YʲДx(adߗSGiEU淕W/@n[7C6(Xd[΍މ6h$ z#E6$6,^+k݆o!ϞQN1~?~Ԑ/עyթIQ_͉3(~ic *0=N_Cns=ͫm„T[)twd!. %Oe+}LvZkqb(NzfV-K"6DqhokRQh|`kM74İK8x8@fz; L΁xar?v XIGI0,e5lH|1JJ!U,Sz/NS´B?yBf%C&i&Pm/ P{E^ԨgG:k LͪQS,!vR -N4,v2vjwSϢȻ%ks}Ф/ËIԙlfS 1vZ潌 6w ]LvEQZҨ#jr5.}=ĺ%XPK7-I<ɶ $7q1فŪ;kK‚mř2Z@" ;ªYA mZ;uʚK.>@AdJ2 `)ƨsRpM#PA meR %L{= j!mxOr)ǗxTK;3lI*a ctOAܔ_ܜ9Bn`HJHXJ3k؛u+^wUz[۰LzAIH0~2lS&$b\q)Ww@&#:`fAnE4oER%%~.I!f$ߴf ̿h$|<:tYȐ!L-:_N?+Eo75a)D{sdcR'ck,sյ,>?d~~*;0hd0&Ru *}-P 3-Ij8ꜗ94jޝN!AB5{زBYȣ Dn0l-Ù^Dxi|-c[s#f=Fz<VJcWsj|"(K:G+\7ǟBPJ'['F[]}5 sرY8JyOrNr&ghp$f#ن- Q p-MoD<2xY016R=#OC zp4c)f*ĺ~·L3"o^b,kAB{w#AS͍;3:^N .Er+vP:RX4;A .ndvX3ed4>gqmgo# 1pK1u_ .a)`Ub\q՞edz|Sƌ9iL}pUMWl n}珐 X(} o-m(:On1m2c+p[WVU0|9 o}N|/>Qh+*9_/Awv0mSwyy%L}:.Zo: ehvH+8lF_M=)< \C}JʮDpCW(98I>]fKx)!~.S/_y6?린rߧNsدje$%at3ꌞGu 7Ry>ćQH͐vr>Nϳd<.wuO>&x# |-r鶟) ,{s[T@ck:v=1"l_)RF?o01$ 0>>$jVv Ƅ[stDkz ͚@?A~؂/V'"6ܯ1*<^o3{vtFTgk\g%}VH݄s얋beHӀzMYV.2Wlt_NUƭOXMqV2 -gH%ZG@@yYbl :ؗֆHV;:AqջD֎X>#!4'Hn ygfԿsH۲x;GX&0vqpȝǃ2yڊu;R3yf։Ygj|%_# Ɏ 4]+}:{ `~/*Q0C@L=H !]nq B o/aN0>a+Tk}VDU)auR2ͯ!߃^Φk$) Knb5ê1Gi$P}7EJ; rDQcV1D`#A͗"RMƜc`S-zK_wIԍr73g-DMpޙ@9|mrC&fMO,RFO}:+TcbIܜC.,{=` Dq= VL2x=|cox*iCxc\[9|!HQ! )LKAbKU#z|Q|HZ$YhURaG>+ *I@8*`}Oe"u0ڍh?qfAۭ۬mE@Ql!"qWC_W#I\U 5?B:<(gQS`$ Nl{b#]^D=QOX$ UE"TXdލch~RЗn嶬LyF:{vaʮ+p^2/0o4{ 1鰔G aZ_m6-_SK i.!{׸R- = /*P/ɬ~7u_q 1ڣ=KQk!LқɀD4:Z_RIE(NM9 ;FEN})o! `7>7m =6<Ɔ OSldY=`szN+R>Ipf:R yހx:GE"$sG=-\&j>ΙZ ȀF/Agѝevcc͋Cz07jM0,M < 3mY6??"#`7̈́Y22AX@`U`hGzanē%+JV֒_&"ɗ(7o8*99qiS璅5V'[o3MPc:Ȓmm"ÆGxT KJлVҧ}AmO}vȗJM|MA0$Z:l`z꺯E1lyz66Y!ShϤy6xBDgndc +5 &xe`1M'xD<m's@sC:/RXwbȧD"&2Hc #ƌG>ӨgFxr CX8BWj6Ȫo )32K:J/h[FXJ(CN ?%ZJ0 j݁6,]yIwǔ @ltrZwx؈C%I3`|@QZ"~c+bmo{+Nk?RB/^)euN65R]͗wNo1y}`ǁoN,Db*LۃB+䤞^UHnc0g@1 z OQbtVY -hĎm;lr)UWjy<4^oP`R{: MQ hsfʺ$"oy/hw#~.Zë \<Ff)C0=+fm.x~=t |V:ʐD=T&c ȴ |X {pC:hԺwQm.״FȒ{3 b$oW5i9^A(,4鱮.oX(? |xٟUwv< e L2 D!8y%NHR-$MrK,p"!$UN< em cUOfaZ{Y`&ʅ,@(m>Ba\/E*.BǬl8Մ@f„)Q2T+&ܭaD0ޝBEق ,NSm ,#0ʊ<v2yH ^Ac5+ *E2pU.V™xs {~1wԶyH[ֵW@Jؙ쌽6yT;-*t ezIWᚑy<>kKԒ\pRG :&p% Uܓe͝sfBbhmn:Ey=?.=FrcbnA H="9`[O')]3b_z1DsqIpds:YZ^vyB:v80J`J#106_{3x~gV |K;_&=[@QLmMD 9ZyJ/YL#sc9N?sW!6AXqX޿b3m-Zlx5&[KsLc dYNP_n>pV1m8Ak4*e6=_f; -toHZ2iݳ[.nt;|zeуrh}"UB z!L(6 %YO-y=T\lo мGCԝ9_:<{2LѸ6ܠ=tFC"}a4֧:+8T~8Y`NU!Y5kU;X7ceԋ^q m7X!Î O#ov0Y26$f 4I jU]BsH]suTb"_s4c ^v8\Sd;6ZnvYAlMBmjR׬648),A]8ANLK"yt>J1@y:"?Eշ٢P;bn| 䮈ZFgFv!L X_d#y4lъܷzxI?nxu(H o&+~󔿆Ys ~_.֦o}!,=3 3ʂ_iX'C[/Sq62PCFčqv,:V2\8 of,\>4? @E&exv3τկyGG(n BbQGN{fhC D cc#λ@:Ek"WfTSDZ3_9} YrǸC,R@Tp"p4 +`+nH&@z0E7ģXґ2ĄݱPYzL3n(cq.pVƚ)̳,c˛@vo܊5깞mY j> ^\5sbB75Qۅ2z#bVյ^ՀYo E4ADj҅o^>I"CʑD;= ;ĊB,ձQzci ErP1;zAG{|`8٘Sdo6Waz~F@?Ӕ0㼚&t 2)?\_T0-e\ U7և2C9XNEx,$ g>}z:p=1&19aē5Bֱ["vVy5ش¿zmDa>!RtcOv4h"R?nl4(Im@4ս6,{_>x.IEˇ4"j%  ~8dKVpayugK_lEK R 70-ۦ!iϽ т^bXSn@FAZL t;Z mܮX \zLJ!Zl5ͽޫM2N{祯#Z '(aqq/PGU`Ղw*+WK{1UUy-Y0ۙc]^溠}n1_*ΎdMQBA+JJ7a3\}К`u͝*Oc4\|]ƙr[ojFOPOd:4R (I4ygs%7+ůK|uAѣbkՌIޠ uk0k Bd$&Ʃxj.eOZwE"/K<U}aU|.<%+z 6g> >2/_vޟ܁]/I5DĵGV]trdM@lvE*]-l\ ;.Jat$@:i>w*7yvaz쫆R0x}sN;ʉ.evcDy>RЏOyy/ati+b!񪞤NjRNkK*6 1 Oz+@Mwo4ޞBucGWnGʏYp>2Om&avC{Tnwp RKПIuN`ҡ8IC"77{⪓i{[K#I q|/S.=aWwt]iE8(Sh"oWw+LOa61 F,l>@mD@ ܰw\wT?tNe?fh!rS]̩z'v5`\N!Z.8`3 64y"~Q-ĚoΟ!{j@HXpF0Z:4%6eE[jJ_}_hqF#yW9N]- ^vi}&0X]5+ؠ=QUy/N臥B?উY}%Dž0Y|/عeY[;7K!^/zjQP Oiy ]m{bhH ?g!8DD6dPb魋SŮ&Y~G=)Cq/AbfO<A 6tƜ(5KM,\q}/-|2zA7ҭ߂]6TkvR3z,!Q7se cb|dQ81+Ja_MXNphu_.Z7kʁ|r+KhŸ% x>wbSdzuSW{Yh6&+Ύ| b!s• \(d`N_읂a= 0{<ꮯЙ_%ݵ-n"- ^Rt?kK#}.q'Xwߓ.`\-i8aq0w[t\:đ b뽥>rZГBuoySmKV?+, 5:?{๮Kvre90Yof^d ̉>OGjăE>z`O }k}|L[oQl"禅tsݚA~Gglru&u5[qF6W/ُ ["8R]Cé d?R{_B$F5O|)4EX0h7`z:9rvwn}̚15:A?ؒ]M9b@օJAx`;ƄiGwc0uNT(|]Oiэ&Nb~$lt NyIl(>(ĥ1f*\=}ln7t $\Z$Ü:ChB1 zZ %1SKVza⡓: lu-+czwheۛ3Pv3\!.ArZyT@q>tFgasPwQ[{$&%TpؼedqIbW@I@NtUz!=-grQ4VM4t ]Ul.BÏCkzIS5Ap/\9R58 ߳><#? aI"i4xQ?;gC8Mynf()SbY,u_.>Za`H89|wKP_f=`lw{|떪ݣ*zԹCj M (b#"ıŁGiBO!Js 8f2P-]ϵVT}}ʈnUgz0Mqaӑe L{l|, y{V͂H@~9O^}<̕2{;/+!sѫ,\)(;o|j_@оO(+``ko?A_=y[q8'Sli$`3wL-D$sBzkIH>@#U; A-C,/w(gȔpC ؏hc/]R_䒹0Kd*א$K5wP̥w oEz<|dm~Ş[@wvwxbޛ+Z )Î H_<,]=fMiiP-!C6Yc)+U`DՓD@+y+QvgGe"M=<4x8 ^'[¤-Y S)e62|4c+8&GPr6Njȱ+2v EVkzqD\Ef%߰8&2V 0n%i=;<4(v2KD^`V8$HК ~!H{<$E]Y5N~ZS$ !:bCBE}xIGPLi3SxItO7sDT/W./$UHBtWZ0h3'؇ZӔ-C#ǙH -4UVV9#`DyFU9d}w³xrO ̎r0}/V7gs;0vcI]Pv9K岏 HX[Ns1^dIPJRXU",Wc_\ {/|Ÿm=qYxu߉ BД_Ry%[-1b)DXmCDuꩄz=~N$$?^=dϘON"$R>##l qpc.2kfvdGʋ$q9cuz*kyxy;F8#S%07b4thxT[׵V3M'̵6Sk8'-7zj>F2ɾo&a3P돶%NBsLQd ] #MtK.o/)tAUk҄ +mkB4RwmhsdZ[A3)a#;pHѡ'h8^CGp,L}PJxWDd)DԄ=I ȱH [pkUc 8b1# fAyPYaⅮ̦)6[-%o6{aXn؝#\Eiͩ%K\=HQ"Fq'V14MJ|9b}ij\zߣ rWQ씥C8P jӡ'YB\ E,g &H苓7 [k%!ץ/4In:i![b&;!h[́RHܪ6sRgZ=fǥ7c(-B[6R{zOJ:(L&=q/ZX`V}\8Ϭ;inU R~[OM&/CkEڥUvI+w+%PmPt23_Hf;s`hJBoHϲڄ)Une8砻 *+D' J"eMv>חGQ'S2yϠ;Fw Bliѡp2;̗;7gA{?,ɸJU7-*g./S{ZqR@,VʸmHNћ،OyOqee8'#$u2dr$¯,'Ը(ECO]#tڈ^##SGGI5,#1/WHf6ϮӮv K+eE59A'o ع{iK!6iLPiK+g߃6TiT:q 4Lӛ֙2 &;Wm q¶'@l{2 BPpb!9uá쮄,oMI].j5TaXV'Y{c}Ra5OkNO_4 "1wo6aTIgRV7Ţ1; ;!?,]U0) pێ_pZii ܡCV rZ<\ ?JM;#_nNic$){>3Yta%lV~D G8OIlhc-Qa[,C\Q% W\|X̏=ڳݑ楤9Y_2T;&hQ~%~܅viL8A@fٮ̅$qXqMVIڟ/XnDk|drs5r"#h>rbgKN1 &G{W?-rײfEڀ2ߚJe>kk(F37&%oh\v&"碤k bOct6"v@Y\d!D755q?Xze&T.#)_b b,T6G鼜.IO'g2SwGzȟ:A!oiyp|`&vrQIIM޲o {2I$3Mn@@1&jR2ޛsNC2VwC9*|ۥ`> 㯞ҊۢdCɫL7U8 v1YYKRΧUeK'rOǾ]Jo60}3.U3HGW/t9h"lp،[#6ۂ9 O`k׮]G2YF پ`qSd di1'B(lb rMqUW wh}&wd3.1nimi^dJJyrsL|X4+~|$ZּB}C]3/ })8ޏy~UwSI'BR=u (A6r3Td 7 Dc H%2qnI (3`v1g̀ˌCτ|yF|I@c脋 <ޣ9*N 0-Bmhg*vl9,nnT*M>Oբm-١ɍ5GULo S9X_v kU/&rdgћ?0]o (ڭDŽO-o24 !R2T#z5nDΘyww0uDAmT25[!J<6oY1s$:wiXwso9 F ~@1B$$RyGja]RfK\8QKD+^}F,;ŖAZrnEB.Us5]H\Y04(O@Q,i3ƈPM/岮L'"lQXX7K.2W4h όe?3ŽZp2EUcq28U{N;BD5IlJy"d(q%2%jtMŊQR"9׻Y )Ԧ?$f@jY-')FUCdqWULBڂ$7!WQl!gqlb) G$['$aؾ*rgQgDUsY))]/<|Ou*m㓷 ))LnE83Z!ձT([)!pQ +gcsl7m;e]ZiCz̑9NYA';0 ٔ5#;3 zyA)兴nA-X)C" ^& IX ʩF'$7#e^Xo߷Dikwlbpǝ$HS1(8fЍ¶=tA11ï"͠Ug4@iZS9 1BP+t֎W߲$si-lp~ĩ-:Zh%`T!x .8^z*.`@`s\?tO p!qՌ$#mMkΗQ*8eg>gtYr\G-Ht/;f9˝R?a87F|ҕL7 n4~6eޑI h⵫Hl'Lɛ#+k#n.$u')QU礷2zĆe*`^x/LAyQV`I濬\S9۸97*rsAS3"00 u+LSr;B98 ҎǞBW1l_!%MwbhTς~BXC[iDo}W8.˃Ö~ЊT$ ɾ;ڮt9kTnЀV_?k/s# sJ7#0իJ,ȶ2B@ 6'6SCL˪._8-UG'ܝJg̔sFT) T]oG{`f!`*< #cd%D3#z6._TGk)m٘Ytte'9}8=P}y?{7?H ,] Y_'~NTrRa~(ߌ^ >s|k>+`sM+ M٢a(׳S>M#k?R(i)XT6ΘsťYbqqeWQA_XO.n~&\nit`|o3N  U~& ^8A%')嚍w9|5 ]xn5_ 3zjiRS9TnQ%9w6タtQx7 A_sw5~C(B]h)0&zM)u|dL I|I͆/p:*äCr4*AD_g ZFI# 6"Nu@젉8 FAj*H˵?omV׎RT#}NWmlGkA"m`iFª&=hF`: 51hcr6L8 A'o{ A6cg%iB+YLѴzx[/0E ӽ9ؤό{GLL*lm#{6hxn=ho嗖NI;L.-*/q>[喽,PBЩfl$Ye@&?Ȏ$Pk }lL߃)6+Z /,3-sҒ{"1Eڻk +ZV 3o4z!0 x͂WG0'CDmLQm*g%p;"pҢ( ?| .&yYVQa5n_ J8UBdZf5ݕ [YIĸ "@<|O零A\4P77g_ [*IzI|s7/KBT pĝ7Niicc=N`@AW6//!e>8T8[j6^Q l7Ag|}W6ޡ q*S]EGX˖5lC(B8͒%C,"Tز-NR7)AҡRNp "ԨwL jH O,w7hy7O F-.ֆ9( V(PEk/SXjvi]b]PL);L /n"YFVTO}GE ^-)ÜwtǸW6T0h>N>ҵ^c⊴4!hАߡ+bxkfdCT&؛`^Xb ȩzݕ8Lk?r깆Y{!e]ۖhVC*"P 8|Ei4$ NBMp:p 'C [;cd/wQ2W8l~"8iS$W㿅O%ЃmfHH7ڵCWpY%|K&$t뾦)>c 9֩Vd4Eat.%oS/CM R{U\Z|tީBzjPKEź<61iS+\|8UT8 b~zeWv(*PrX읊$wBh-;-;"`$ A8hLqmGz΋Lgi ˳U& wLSNR_P̶H~M:vw1-~C\Q`1R)i]( FNxҥ#.sq7zg5&8jSo5RӔ?dU>( mh;.o/%ViW`[bH%x 굹KKab*L3q'%xŗ=Ɗpx>ǃi6cj(4ؚ&<㠔_xps4ee _CN~4q# 2[cjCaQW ꆚO򏤗k#>ŢBc~>ݑZ`L0ƚw.ۭc3s5~ ы\>(ǃJkx\eW"*fؖ,]UEK6~إqP}X#.aox/^,^G&yFAvFw9ZKjϰ#&NO ꠑ):P廬K(X+= Zví-K!"Qvڽ'EkwRu9FcnIB7Hu\,|\ ŏ܋քrἭeCl5nWZLv\jp^&Y ߂[ a0Ŗښ{gQ0Cq>>;4S.ՎB&[>TOcH`+9:/ q-D [4ܽURcPKRb`Cf2t03U4*oB@$un꿨Ey2,pj؂1CCA!&PnH1p {]3vgmq.=$J,{f)R- 29Qfh![:H6BFgx_u΍RӶ@Ԫz ϽYT;2JDʰfuß̗"/T$Uh`?˩$ygllo%zS*T%Zx[r%u#rZ_pF1#>1 WJU$Ϻ<,rl Ӑ8l%aI)|g訆lv $buIޡXD#=N(۾R LN5[?.ٯ2¬6E5 :eb$=y9D;q)޳D{33b7MuD׾'Ʒ qw'<7Ӕ',1D;=qi&3V N~Z#B#ܱ\s[xcy~1~*xEOT;M v3,O*`&ytSPP}C;^tJrT0w0Z e ǵ_ ƣT;q_gAJ|P,Qmb|f ! $OUqo``h4@.Cޓn01I5(mQ`2VS8 w`3s :4!jIoeh SA^3ދp_[#\``9C,(q`$ØنKKZ*t}Nxw98RN-p!QK,fXX8Z5+z/M:2nGV7>cyWC8͘UR'>|s3$xti=R*M1a.d[eܙ:9ĺ4) I9v᱓p慬wWJFş6BWẄ]%>Xxŕ:|8ZX ?y` J9!6ҧ )i|+9vQ(w`Oyg yi>֓T S0gt2J*nֶrhw+ FѻE =IyC#WoξJ|)W )+AZXC^&rtO%QOp 0{xAjf.R!˚p!/vx0ۨ|F%&vDpwKb$ǐTw+vb>ݑ5'H`'ȡ4|`o+ oI*WhfGfNi,k}I5k,)Ww=LVQ:i*Pbz'}p~̱zS[^ןCkBj1F:")E x"g!VfPY1qKˑхq ÆŒxVzQ9~ͿCy9 }a ir; 0V(KEԏ#5(J0YpȤ6Ւs^kT{jIg0\zeKN?Xzzd Ir>RۺX'{z#gئLWXCZ=b.GBd#tbTS/cUdha!׀XF3E%B4Y~[EN@E@Y07qGHnj=gݭα_);3́8?7(jSiZ-Pb^b_?Bԁ3Z-d6d|*v]7q|TئfͰ&tX^IF!}+B3'¼pl)e`;̣䁲}GA:>$[qߵjsΕhx:Zm'Ų_((Q Y6l$`GKes9"{2(Z:3jـ,&Kv<K*] .B,;,[լ1A+Y}ecg 83p}Jr&Kurt<(|3Ao\Y_E$<'į/|t`u; FBʙoxo* |mVt '.pf<٤;%[[ĸ'!蕀5jg*6dTB:n!;RL,s3 ӇB'n4*SqO>8BGө䲫{~{O@͞'ZpPub*4BD?DnO!4j)YF @{L:_9uvXVQPtDC|Ai=s-E=Q֡fGB!zq@ 9 Ci{AƘ< )NB/]9MхlDͿ^R爏N~Sܞ;̥ M5r5* ֶ̧U6_OdT9-vDiy!)~~9{rq&~aV.'[jcn=jz}TG;L)i[82<&!XqtLo^M$@k[Ni꒑v0ENG9^(ojOIL=wuc/KW$R~_BƄHpqFK(LpH@f'(j8n s^1ƉC(˯^A`‹:0< 8cc^Hs H"_rq>^xQ"cUǷWq*19ʚu.x)!iIJ4\AЛ6ŪZmz ha-0ܟA-@k%)FcP5ٷs$C払.@1r5%l#h.F=e| gO=k\7]寧+ +6r)Z[BPj2 (>@)>5aU/BRP"V!N-.PEӟ Iʄ5phiv>";Pñs"*Ve+ EL{}VrØc`u_gJ"( Uá/E{޲-Ŏ2 Czh f}g nNoD7Hj?|EAo\'-d/e5cӇ&HY&}JzE's4iq @'pE]r[yo+" pz">/`[ޫs[h붇N\6sXg'֘Y!HL^lP(LYF7EI@ݘӫEwπѪ4ѵ5m4D*'W *k:/*}!LS(f-ҮQڐmB[ )'^x33}k pQz܊x>AÑ!`rfa9{BH把 ՆLN SDb]YpUm%%vVt1 ŷI BI=pS zJpcћ0yAPƛ'wO ]hH-qjyQR_7!ؔ}M7 ?PNqpŀ-rx=d+k]} QrozIbN^rh}Ka<@Po)Z^݆bG<0pmx[29dtX F6‰%Ճ s/t$7JiǨR(sj_JځhV}e|L@kCA` >1U0KV(8Yℓ]9 Zi-a:!ACѨ Y8rdj[L"Lٕ\jkסe eicFDyNM\Xh{<=XVWC9dR[ )%N ɵ()HB:Kg {9sm JBεƯj56}q[*d).iNlEyWӉ 3Q@SiF &"D޿6yp-ZI(pNԝpik&d?mD]$/Yx89Z2-_@fwj9Y|OXRk_pdWV,p[}%:N]f s{J8 bhvr`w}0@doD"4lZ@7Av'RL;\>g2UAaKnl|5ǁ?0p$JAc{6Sr6 W8换x? z>zD}}F|?ڑgnRӑLNRuIStޮ5X<^M;(Y(suZB+סgPy:!l+!急T sq4 f+lz.wfL@8=$ueg>̻/Mv1@\6/Ctjh~n jsynXWvK*:Ǣ];\9Bv?SY!v+G³][SFDSkHR'&/i@f+c5{^{-mnjNMEXUU7=\,~iѶ5 ho`xUf<D7SSt\[(_s3x^=HqQS3)unp̍{_-)Sˉ՞z$X?˟BD:+,Y6k* Frp#ajI˰JiefkͥWd=nq열}'A=8 JyG^:'Tׅ)i0@QUVdd QGĔKS(Ua 2(&kK26# m*a-ٕCdgL2:ɠap]ؚ} 2כ3YIoA/^*:d6B^H^a">xC(?uÜPuU;w&FsI .y;Lox}+/+X~_uaqLqjNVhPd:X?aXVfHz%Z. Ϡ=VU!4RɥWTI:@BfGpd")061L*Rӻuj@}c?~ R؉sK#>zX6VYuܚ1,/;9isVRG:%cãAF`ޘ0p`%`ahX 0h:d,>ꭋq*~o梶[DFq:^.\fSJw.rn+<׵pӅvW҂=E5/;[y|8[B&!n6A|* M_>1|n _)iZMfS6F[9/ndWLEvCJ\ XnO=JTd1PY63rȠ  #D:Җ]'@^χmK_ <}'sAu,K«txϧBJ 5 z23`dcbh魖⚄DTA#پ9giysz/<u&m@$ u>A'wh;B R(lpR$~l6@2mLr!Tl\(xk=kvI]'ëК).V[#!< i8eAʧ"s4^MVDU +X]Xm 2?.0!wl AQCo;ު6I ^ZpBGH wUA:p{nRgr> Q^ǔHֺ6v޼R Q0 :Lbu[ .'~~9dd1hD6\JIQRCH'  >(GC&^g`-GM @ۡYVa4zFxYw.~]% <䒲QsJͱZhI4" Ph[R824D|fG$0v񩷒?q{́\ Z+e%E:]5,Ti\iJC`+A3l12SwUT_<‹ 6܋ :ԝPu<ڢq3! 27|)Fv+LJ_0 *u^A SR'}Vla0ܨǎJq/l#4vY4c +$(ٖZ:2h 85V5tDYKaRr)`nHb*O)B·Q[w^ч#E V9e|l6QW?4tC]my4Ĭv/N!7J4CJ<-I W(j%(5H'^U%G>.Fw^`nMY@CD35Ít@µ5 /bM9`r#R.4ĥjθsjFo@)˕OdV>j݀AE6z=QzG("?dLS$Z Ǥ/:4k X@ ;0TBR8|3*!Ck|QHQڟ4Ջe><l}t'fL;;wg<3gbQv`Pͱ֔W[UCL۲^`,8UrQڻyxZn/S6Q_`I*tu @l>{\(->fI [C^6IUbZdC&pBT; ]N<_zWUsEY,J@c7QbGh8UuJ Y_8jz]c io,5D!:xheݡ+^U] R1KnVWb\OfncJ4dH{taS1z!B\^ەS=Dp9]i^OyaXǜ {Wڬn21zLK9j^u5Džlz0iZ @ .\Tgas?␭ҋJX.8Ma G^ͯ WTw\L<Gon}eTE,>";I:L&jAR)jù |Xe{Q+63T̗z-y!: C{ԡbƮ[gcEA~c홠{LnS u2qn=9@aBc ߶cs :,V<] A`?J\ "07!]x}~oEX}#4к>ېuy^VG z-.DNahd,3G(ȳBf`YYMNM@/Frg y·igzAcfϗNpR6+HG0QqY;BVS)WRIt:S |Kwfz83bC4û'epg0Hv*4jL^rY+u㞀-e{^a{Vg*W<| 5鼆q.fYblb3zr$`q]P.0T|$%6Cc?. 0+.Vű!z_d ҟPbEb^Ḵ] <'G4YwBiBrʾVC>N>z+IdU|Z5h hmOgT WGK];g8MJ*RB{$S(qX["OǴyav&E2lׄ'g@s6/dΝ$B+Q1\Z]-(IKw8> }}k'o$&!a>Jr]EYim-py6x,1 3oc(Ȱ}Xq|)g6BzB dʊ/_eDs B?A+Hu/$%äx"'4fYDA2].JujWK#Y/G fNnA'?cj)=~@_ɔȱjԂ0Yr"7xg7ܰRB/OIsH&d""I>4n!aDbW2CssAJ9zwνĩmNGw_ɭ'o\ v3y AzкG*&wNrrO>"(ld[]z"DžvKzا7Y[IQz P )eFDj  <ӟ A`1}y)Ǒr5-%'U]o9{3I!-3f-mBlot+D UI@.3]iWEQs '&%YY LFw|BB[šks,@v#7e(L9Ox/pEN ǻL *0tF"_Aoҹ E-]D욱'}ʙ0.֕z0sII`+n5$B0fY|F j&?QU׍פ۸,>%V-Ǿd+L -LT@#.ޙ ]7|j#q IR!Z/oƮ&IM7KBLS%Zbi'%cêJ̣k}"u=Ln{D\c$5rc׃-7xၷDpDH1Y 벿9;E2!+me;/XB3܍ꀰPe}IٝCS6d>,IJg, /XyU2]]}bޏxfi,N6]H5o^ ri7ˬCWb! H p]%sVhv87G>>JTkdmz'՛1wµAIfCɅ6aDL::Zi?酚BzKr'j^6agiw#>4㶵 ln/[QGsMX^.WF wD'#[~G׵oW2ߎqÀlxo4m CcpNGg{$bbTC(a Nz >PYcIٜds9iBQ90 JzDM,=gs~ F&>|O;ZI?3@.KhPyΐ~d?vK`ڡj &[q:D߽>I\ c?\FYAGS#ABٷ%\ *gdos!'L.5gDlj7bi !ɭF/tf(7f=/m-ZӔ"(l ʄOA.l6ƴpu#;Uy>=72Uɐw-~ZرzwE:j3_=bHɏ@E4o-n"gltU^;l:/MaogWTQu-JlxҨoȞHrϕ\>[[K}[fz]b(--zIRPwfrǥ|mP$v 0=dF!jï5t4{up }:ΐvh` ( k $1 ǾJHd屡 $^b!ǡ$FϦwM>O _ʙKZ5Vty_.YbX]h+T?I/X8!\ۋ7ؗ_y]{ S ەZxi8]q{bx0-lX}S|gDGFr`~D` &eι׉s4Cދu%{=׋ I\\S|k[͹,u19=(މ ܱ"|.J[L7T0K|#`"IˣWƚ{axv(b!H2}|?+dzvEVzɯ8,X¤<ȕlxRYs$L\4nSA 2#,hcKQ*Sώt<(ieIX @o8W򵳿\᩠[0dfQDhľ+:)8!jR5h/֫}K-W# Րlot.` ,`#Tl|c"/{A- s3^ kӃ+70^NM>g p,52Y>u{{HnZ mg& 8> ?؃/TNh9DZ\SSTpe!ДBјL*G@yBu9֛؞kLX9 )q i?29ш pI].O<:/bjJ)&*Rm i$}-^QQCC6X,Q2P1&T2%U11LU?}/>~WBSWsD]YY47ۤ=y{/RZ7B@ TK'R( 6DLQLml``$)Zɥ&F1f&QeBkX-I lA-cDڔ2@SVKTc"QQQ &(¦DQ&!AdLBifccd6 H *Z6) R$M~EDF$T"e*$lhK6fVHIH% 6bK62DU4LE$Qf JJƃ (2(C RYSB## ! 34B,`MH mdLM L"1R1FdEd fY! 0ƛLYAB4&LĖC`h"c JdA1 D&Ȧ JJbJ2B3AY+i6Rc&4QZdh"K$E(@dD1"A$$dDK D,hBDXl"JBHFE$SJ(2cHJhHdM"cI $ĆL) j&M2`Բ! &LIJ!L 2RM ?lvTO}W^ӺMu C*tl T5ϯ/?=OZ&m'#yVa:Io>Գ>۔*]L&ߙ?K=HU7;-j2 ms9;_+~1B"=cTEU%IBLLjf M&bF2I0ZMlf5RH "%D$4,!FP4XIM&4i"&i҆d3-6$ D"RQЈMXQRE*IE[DKhJcek0"C "0RF)ѦI4!(c-HMIHi2e6Eh ! [b2(&EF0CXI U15aȰ)!%E&4b$̒MTKSfcHQ bD- B1L 3HFAƠR RT%DSdA bd13b &Q"hF"1@EL PF"PALd$RMf+cFR ,h5-bѣd1DEhiTU UK,[k,heb)fE Lث#(bLX3HLE!XII%d S hFV L[c"4hHY I MDFEJ)BLFaE,d6HmdfM&* A&TUdƒc&IlmV@i$ɤDSe2S")X,3 Ģ $0" QD cc)aM2Ba&fFh-BAA2Y i#L%F dd fSIBBFfF 4PP d#%"2H"L ,#H,D$i LL@ɒH͘a"4ILL%`Ba"XL!B"34 "!f @"h"C i QIl͂d"()$C0D MlLH&H0M AK!FS,&$2D*HbD@!D"RA"&i"1&FX#Ld0X$@$ $Hm'OƫX~_ *q^{RNWfHpX4iib5w7/'qE#a$ʜͺ7f.̓L:woe}Oxf.wAokJQv'.=PMƥp;MVFc20l6&td7ݫ7fLm y|?!RN_=17=b^c 63-Vo/ɶ2גb1MǪg=coqqaw5o9ei ?} fv籪df*Y.{mɬK&'umITfUoby I??Zyzx灳KGuШP! 4cbJ,}XCb5}ǨQ|{1& l翫 @o^1TOaES@aUcKypELܤ! %#&Ɖ ښ{;3ޯ9<ڨ{{p7^!pŹˀ#LDA\#81H""<=ֈ:fhoˠ"Mp}Ov2ǡ>F 1|Rp H8-l rdv;A~Hv{Bl,zޢSqQ"XM@Z(8XM^9甪'~f( kb79'ozZѾ? Xߠ0E1wK!ڣ=4N@YAtE@<%A@qͭ7/Ƈ] L4go\>ǀ]aE% ⛷OHl! `AiL&vSte+NJoTMf8_yc$4!Q #"__?-3 d2 ID( L)HhdL2$ɄI2@dD2B")IIBR`MST"fDCH("$ (K$JD*H ,A(&$&$&2@d" JhҘc!B$a!&&"*!)+aI1*BbQ"#1$34lf0M"f,fL3 R"c3$̌a))"ZlДbI*,XcA3)1XdA5,F '1xe{Ul}N4Z}aѻ?[L$g-"F .9Rwұ*ثKWz:;FsO,:ge ԏ8|ݹx`|aƹ1nt}?Ҽ O}}^jtl3jMN=4ۏ9E'#,(gܸ']γqV3KMycȮ&8 UNٽ*=GQ~ Iq'i_2~rW#x_G#x풱pƒIIpL0h&4F#(PI4cI *&jH$@.?Zd++Ou4{oуX RlhHS$(h$HTE aI4IBb)XfQHRE&$)GYO+1_'ad1~Ek6%yBl̲m,ın}\<[$e{uD ȘXy۰AE%E|\z-"(@G,1&❥ӚLہYK/oo^CȌkek 05* ƣ',EJldH-6;惉r e}]ulC?.@qE|S2_ٜw(N7m^?)eN Wl/1)0:a"I_te)$d"4X64$*Qf%LXS,SHNj_x" AQ040H5% m2Ȅl&l,j2M 6jB)e^K˯=?Ow pdlvG@twvOYdc Ru!Eawyvģp|\G۬`\K!c,`i"bPL( II1R"D"62 ")% B*)fA  KS6 #mfa, #I`LhRF؆6mYőb)S%*%D %!RВ&10b,AC #(h # af HC1Had1&Qf6Y"$Sc3ccj1P4f0ѲTIb3(!hБ`FiDLc F!& 1 i4h*$23&(E#LЬ#3&ٲf1")fƑHքؑbf-$f FLYlahȖɒQHba!QFѲ(P "ْ(43f!iE1XDAddƠʑ`̔ lhɉ44Dd,EAX#bfSFi$Ѳ-&*EF4R" $dMXAK5j(TœATٱF2$1H&($! fY6LhbŊmh4LĬh*LٍBFbD0cBIb1R $eS$Je31$M`)"4"(LII0aR%I4heIQ$h$a H(IBJTi4b I#cM)Q&62jH bLdDf" b2fZdˆLRdLXHX,Rb$$H *4* dC!D3 #4AH)E!d!IfP"4@E "a2*B")"MDE ɐI6$Z00"1c$Tb h") b 34RQIh!1HLRb&YC12Q0F$)EE$a&DJ-Ejb5Q00("!S@#Q$!D!4LL,$eLA"̲ I I3RMZ˜fPH#fpAW~b H#"Oo!)Н_%yidw?%"%W SIǒ].' }yEGT.lwE%)"*.)YW/rR"g9s?3|>7aMOT_ڟ}m<j20x#SQ#:T~'[g38uEIs Y@1rc[z_E&)%e I=|V˿D%V.$~JfEr^vef@w0Ց%O$/zq"ڗY?z9`SD@FDi i{^K*;w!K\ $G@PH82{L];Lo#(Wā#R I)|aң,OMvUVsr 'X 梒I ٗ{}/|/ ŷܑ3̞~K˄EO[8L_K<قzbƧ]˿@/G_|?ms6eHDgb#ڧ5_tNrҠppNTo G! Nr L^PRr' mu]S|g.'sQrCTfj;=wlF_97YM/{wJڕ^G]1]зBDAE{ (g=L% PJ QMB[MJ-(HQRDM&1E+ 1(fFPQkLMIiJ%4&hih-&43dJlj4[F1LQG.} Β9㿉חn).;璢Fb a4ɭcZ6$TFbQ͆XbJ֣CZKP"EchTj*6,k lQScF,$ZKfQZ5h#6 %U)iZ!&+mjaljcb*3m,fR HR4*%ЭՊB,-a,SQMC+2M[ !@Ҕ+JjͩVVaګDZ-j,jbCelSV ĨJLJJ"-BbI4KJ$Ja4hDZ"* VƢ6ALRe `5mfjlY5-E6ѵ)TB @UQl̍i6B@-fZ k&$ыY6Jm)XA1i)6lmdֶEڋRjmTm!C+dVMm+XV2*-ҍ*R%!Jmڈ"TTXƍմUQdFL3Q h1Fj,PVňL c@dȍ2%)2cQ*61U%65 ڍ 1[D QX2ؚQfiJ )fD52,Ԓ-"# BFI-b ,AdM31 J-HRQMS%E*HhI I&)Ib %fc06S$1 FYhZHkcPZY+Fbb)mƵ5-$efŦ"1lY6Ak0 L -$JI"ȚTTdB2i$3l4ȡe"% * 4Hړ,lfMd̥ bIjB-2I+ hd3F6Se5iEZ((&iQ``S,)  TlRj 2 Li2R4XC5L)Uѣm -b-Rjƙ%IQhmcE)ElVeRZMQhĒTj+ŊŰPj*b,VŴkdSm6L)&fSSl̓bYLl0-bSk֋DUشhљPdL1 MZ[m&50BFkb+`kcZƣd3E4YJ@LA"id*`$E*d$i`646-Z"("&b3TfZ4$j%Kb$Z+Y#a1V,R&lծi4Z,DmbFسQcbmōV6lͲdhcZ %i5b4IX6V"mckѪUhb!ZY hѭҕ%F bhQVBT%DFTTV,XZCJ%ڊ[-MMfMfm[V-hhɫ5QV1XElUm[mFƢ0iԣaAU&ţhصE6ƨL$ZQQQ"V)ƪF-U1mEZыceZMbPXB4!*ɐіFeX Z-&Z+Kk$ebB0bTF*PQm) MPFb@cBVE&50 2JRPZ6ͱc`mX5֓ѱQYDimb0R1MQ2j Z4hi$U`ѵ$dڡJh5 M&ڣZj-me+56VQX5FVѢhhj+Ti4jf31h,mfmA(J AHIcAmB),0Alk-bmQ!DYfEFR!ѶRI2Ƣm,5JiZdj*"MZH!DhMDF3M56HbYMj) 6RXH k$!IdbfdEeR` V#hk-mjJȕ,AʀljBҦ֒ زQ 1X6ƃm)&(ґlZ*,Id"1VXUBDA"iZa6*4cm64Y5XY5Tl1F6blIK* Ȧh5"*jbKŦbi6Ŭ"m hd[i6ed6, lIB2&IY$jflC#Y*$Q dFTő43#$Z*Ԫ"H&YL%)!L- j hdcfhZbش"#lLRcifc&L mM3`٩K4 EF6ɚ5dYX[&ب3+Fa5EEX62$)Vƣ!dfcX-JPaf$JM[Ra*2UM5 mLi2,-iB ĊF (M"ؠH1!h L jƚh0b-$E5#$IF(2բ+3Y!Z1b"1EjŦZ6 E$PhɊъ$kc[F+QXڃcAFƙ%F+Qhbƌi-cEbŢ1 &&%ڔlX hd*ZV-2Z-FDF F*L$m$%"Jŋ)AFJ 6R"dTeCQQcQILj1%I, ,A"LHbkXLX6RDD4f&$dR)&6lHahZlTBYT%ص#"hٖ JDLB4bTjf`jML1[F6jK,`$0&ɵfA"lűk41J2kFlU&j A,&*X4DR1hlAdɲEDZ2I%6RDl3 ԄADjX1)cXɃ 5)(&(5#Q`ضe((hPX(PQQTZ,V҈Ō!,J3 6d̦,da(QJi( $Q(آԚda5$LM F*HFTV(4 PԭQDi((S20*(-$ͨ 3($UԔ0,F HFbՍYMM4I(()"MPƒ1QAѤŤՠؓJh4SUQQVi"iHcPQcXт(أ(fQdX%l[,mTҨɱF2a2H4FbMA4Qm6hlQTɍfYhH!e+Llm*Tmh4Z0޿a̬`MZ 1( mmlUmaP =7r㏿_Y(v'ap!O,A98[h؄]mVS(lLh&}cςQm]tae _g=XYޡ^kGpQc,`F8|3 0$ȹwsN  YD˶1}c5]CF$Hii|B5=6roCi?ǍQ[M8춻Uwk׭ez&O*Ta} n*{)'Ffؖ DL㴋[Ch0f8D5+ @2H*`g=̿PtRw϶͕:>q5Ư^{ Ÿ͌?91ߺbXvFȁ0>̳􁟙zsO%qPDѳXM6n,#FRuV?cpӨȾOorcY[g7L 2HsL/Y/AqnN̷e'~2, Ko_VboTѢ60TQ#(3Ҙr+M7%Jd2k$A2뛑Df6$2AJ&ibJEc10`d",RRcP)Dli"# EɌ!̱&TH"J̩ YEs()dI3\wxɐ, 5{T~Թ%XآfFs)J"h!aĖ* Č`45M1F4`31%h dF Q$3R!131MđEhIcdc& 2TRm"l$eIf$E3b*e,QbF&XK)L1dR`!E &ѨLŤ"УKfBc(TJk!)EIeAi2ɱ4f$ S4RDbDlQYbbL)J9W}͵?xT3wJ υnT&v8mj!Բ4Pш2^_$0&yF7L " ;7/Nh*}CFZCrΐG4<@=93$ w b2(asm/~^מ鞶X޾ ڋ 5y,L|' «Q < |]zz C?㙦&}Tk2N{j/aX"쫎THOsKƱvDzl}Y}cjV8W9Oix;OɳW{媱py2 kTډ(r ۴j;ZyѴW#˼25{]&1E L/iSIȄFҮxӣn1'9Ͽ>3d zٚΧap"&!U]QpN1]&\aMp/1jGzOLv?3} gh~L3}I[ hxj|6z%"pWg$Y?*˂+S]2r P]D%--k.&@(mPC)j2M'QZ((E)z2YMNzSǩf i}&~k,QZl𹟑|Ѿ/Xg)̴2\&8r"~nop(Ө } EumiI r22#T \ t>-蔝c>\ mq.R]W}?Sg?޷r44._NQ1 ~hOEnav{΁+,qr&^CHl}>m3UUY{H yh\د:[IE&^79 +3yb)01UqpF"$-wv˵X⋍C؝E_G T jj=ۮ:j(PSR{iۇxSpyWק'J_جcךv}Sʥ74"f ;$&7t&x곶,FfaV_dJzt1X[.P  k!|e"@ rxK9:#zR~Rq%R|gh Yc݀S8yAC빜7Gs[A-Mh6t҄/(ppZLtj.Zֶ7WSp'ɍ}ic3;(hP!A@"zPBwZh6oJ2Go{Q?MX5vi$U v3GQ l#JpK BDid!E:d">n Vʫw ϖg{;P &@D9F8W(f=N5j&)Q] >y#Rv=?qXG *9F;Q~EC<&aJŅ'++U8"yޠoh:ߟRYIQ^Yyn#Yz9Ϣi# {~uxs9̀\.xיM1g\?j$`KʼnL faIV$9Įe{ S#կt;N>wg!z!빝nz?z_!ՙNOwUw/re-8#lp @B Rw3n]'eY7$rryKGo'}0DCvm<7ַUp(SW'<>cg+9:e)͛FRO=(d)I*/.kLܲMv@/;/uSO17یs|ߕtݧb7[/mT:oS{Rw3RE~紇_'RNR $<'_{+tי='wy&Tk'S9UvGl;z=nMoeseGBlOdQzӵšo[H Lw) EB OLR_:^ͮ()Wx|;cz^* $،KhdHcF"*\fq>uP?y'>-pKǯ(O7[l}ȉ= hdLq z8N\IzMS#!I 5?ۆBH]ėO;}E{l~g"r[urqpCx&etyG"m 6AѢz : 4Mvo2JNP_CGԗU)wB)p$䶎ߗuw]I}i4r\^׆TuQ'u:N}|v[-A@k<\ӿ݈A* j$g"XFHᏻX@zrpWGJx]x\}4̦l%]#Ҹ)}|ݾ*U~ȽSI>O4;^?[DcExR2pvߥLOĵڈcn} f4LzOm+ XDD'I!L՘'w~p[gDΖŢO7lE#k(jTJaDf7L_e,t7O _>sX:_+Sn/>$ݓ{폒i\V{EaWN9sGhA9ރoSp/_VQL^&|Ǘ֞8`((9ILX,TPTQQwuCqg^%9eߍ^]C.0㞋F& ?M ]cwc8cD(A*!a=WMP/W tFg?2[#xbD'M0X94p~}@4|H*:־}1{ήݕR5v {|U5֡h9N.3h8~^h-h/'7 '?_ ec͊PF>9dz "s'\=Ub|2܆ښk[3͸Uwo5&͂~B: IѨ03xܖC-1a]G Άch?]/wEgj1mhM.z1Ɛ튙Wi[Zy]>62 P<^ e#'`]6nC#p?> \Q!pΡ7}k21_VKl3yvTD6+(2+PEn?)Y|{z/Eu8I~=򨍹c:V|6;HE5@CE`AmΏ* ᫝T9']T}lAk>zykQ179^F^6r{N.~vz<njs躭PډXS8AavKLJB5EeGB6M0$ԨW f،QQ'D/V!ihMMQorgvJP0I|;adgj7=;s5]S# c/g>?5? Srˢ~D?L1 q'K AV kf5@ov>,nN):":DUO׬jf9T&,}/o/id3(`BBp&am>߯{3\i}X p.Qws~]?xNwuHI* o4ΑEPhL MX>݆56iīwNJ.]tք71Uڐ*lp N@X}}WwxO@ԇU%S9}yv:N7 qėqSE%|K C,sKMx0I4"ㆧeBT DTxѭٽ(=-Gx_!}&SoըݜB 7ŽՈZ\6;""ИX]2jq bsr!Glkoīk%M~S{~}"J 30jKb[#\D&KeԖJSw((bMm14hjZ$}' O(~ߒAĮ: N#6&i O{۽JBMՔO76S__1ېd\窀GaZ!(s0͔ CQf^ch,-{8D> 㫛0J6{AE 8N1rf=V/Ψ qh:| u>"Yp!xnl;,NA {ϔFjo) @ṕ`Z@C{tLƋׄm:G=_stnkOR^W,B=y"ywފ'PBl|hZux]WX]| 5ܜJP]6l dHq &t4Q*|&7EwwVMOc4Nz(83~mڊKѪyT~yx<\HyC(auy9N*둎XDלzKjh ֢!%,x+7ۡ/h^ȫ/Ãgz8Gߵ*osv2[qαi#ù6!}k2`SIcޢ T7|I PҭQ:ήꊘ+\.Bpg PFGb4lҌ(JP  tx47(D1?gZț}y]OGٸ]y~_S~ۖͻΚ -?OA-AD_oτt4;A ; yK8Gg⻶G!z†u?M{^۶jU;cK5'+3T] _1zʫVB,]((2)X L pat=r/L{x2\78_{d\(\CBywZAjK9>r㘜v+Ŀ%Oڢ /dkD4)U~R^jO%EVJ8Yb 3̃ApAs$|Μk|t-.o?/@9yiI'?6mzs>8xe$#aF)wnn7!ѩ穩OtTT@׋1,C= M/\e>iz:F`ID)]Vy1APBs]5[^#5yj9N{(Ty H}. if#/SAF"9t(!(}9M\ʇ̨/ 9 /Ӛ=,W-]빜xGg{~%Yz~q5p[xPy~7'/'%ޜߑvxy.omYpz_wqGj@$e(h&> V0 i.t0(d4y;QA^s`1 0T)߭|B|f8 /٧5ƆC?yߝ.1:*5þP#nGU W?\coOx'7z\ oWɌ !άlv c_.2ik$@I&ܟˏ]q^=yϡ'q"pmjo5?j(saznxwĞpG+4uOHynPD;&@ȑ>Isr1Bl@hB,` ~+ (Nog|sMv_Hg亥_AUGzn=Aj['Yt|!>ae~O38 M Ѕq?Cp6VF;`,<jֽHv]ݭ/JqzOlSLKR ;E% F#clY~ڹڋ66Q!QTT4l*L}v4FGbP&4E{fͣW(+$k1`OXoǯ|0 *"Ǟ{yN<@@" DMDpb$/})}ϳU#XT CT`( 3-;@RClYWt-bffCT'Ec۪H'v/!$@@@%;ꆝn0u@PA@(ATHTe @ Jv@(R:`P47c#ql (4gPI T@ݺQJD(PJ)T*)ʂQ!H$HRBDUR @U vfz'z=UM R< (jªNO ** *{u8* @LJ p@TRJ@;P@X[݂K@*T( ! (ZJ` !9>̹MӡX 9&thñ@,'wO1ǮtQ< Dj4 (빟#K0wt>p{l!p9!=GLf H$liAf{Ð<@Kݽw``6$t.@Ay=32>/d;p<ppu;@: Nݸ E wH%BKCzBU<;9l}@/` ݘҨPH!*=Ñ@D( = ^S7p=P$(Gn@ ޑN& {mPu ܝ@^󷋻A{%NGӬ +TJl6yͽA M2hA&M!@ L24h4h4h LB$I{(=#BSQ~~C'F54&~?PzC# A 4iC#!Iꔒi6HɽCShd&fdКhQ4d MIi@ ѣ@ M4ARDBidL 14Ʉz10&2&CF? 14 hD1=TL&CL5=!m򧚚I& 8%1bD,@,M7K|ֲMJ "Ng2s[W/zmUb$%5/Uѯ>vf*nM2TNg)&t HV[T6SVWݿܫt*;%0R!QW*ʚ;TreU |4I KC 2 m\*NL60ć )fx;&jw}ue[}׸УYX箧=avzkSj3C+o(c^%=l>kA@FM!DH%Kl9Mߢ?'~LM䇋LωF[CL(5e C共Ͷ,{Վ# #%D%K8 ` `Mzέ_32 uAKy_c db lg27ceca^V<]n6Ŀ>CUQ]>@ac^`̅/0+sc`*ۣpn?|ޒj;&pf$rE{3#I.\0xbQk|̊=<.".mJ^6 vD%aΗ,x, ,.]fWbom3ț֢N v!Di3L4hKsyHptiL?rC0ey֙vlwk"WK ܔ};%eeTƖGpgD~}}kō*246 9פ,Dm I&$0Vm5M SE=Ú[(V#pK0\XRptE=F߼M5ll4WvT0R ؗXje[ 8|wHŴ$ŹّɾzKJREC7uD5RCjJdgUjY8[]#&iH*pU p' :lS`u{xJ7D02bohuzlr{Vꎙ$Ül;Hv~ڑGg ՖӬciYH:(³'s愝xSRd/pE>]\`Ҕ+%htehjylsuf7:Umcɡbou8zͩ2:lqts5w'cu{Gy_ hr!kR6P*PR(_kg\`CT8\ #4TC*e!JP5 wt(UikQf łr'jljDI4?VZtn:}I( ̎fvh$e&Lt2cx]Fž3=7Õ 丈f+<3hUv {jfŊMdHTU=Fθ^l6iK:7fhMA5:\g2)-r狹l+èDq%g졐6mA^fueem6"\Tu[|Ngr|n8] ֺ95>q4tNc%Vn"_0Bv+$;&Z$bm2vZ間ntfq9 ז֥+v4=, S*f a%hbgEMNMI3hncX2m£>5<(J%Y%*oXRX,D74 9foUyPYkQb6;T>g]5b"69D2AL3Klc+t&Hm#Uf'Z MF:Tu7lkުʓp :B53"[;fz\N(^Y$hgrMȀkWa ֣JaYzV9NF՝^>{a.]_[pROzK3`,ʍ2!РCXrn iԌ0>Z"Z]\=lg p+'$َ89҉t\2Ai\T[܂PWowrGP%t;M)NNkZ.,P'OCyVvhBС<6;?.3:1tm\^r1rru5/Kev-ݢD@gXUfg>HK[eܡV_;03|ckk-W#cq S fP0&BФ:7]r\%hR4AE ҬE, ]bfY , 6H ZT Kiƌ ~?B BjEf'R.B<5,2z:FTtB%zoW2JQ&+kcsy%>7;t;DQRwC.} u UdqL]J!10wҺ[/wԯaCnysǽq^=aa(Pfzd[\.ƹ^~pv84@eaob1]K7ֳAH7?f+RJž|FiAC'0MYIT^j6$uF%VDK9TAD2M*dF=}9wKTRo4ʥ]j&)aǗ"viݭ${t*c'ʉrž2.uFH#tlM׼P2UМ\<SP 2l `ot"2śbeBֽErx4cH2BΚjWNAX/-3%7T:"]YD1 =jxD8Vl V@K@!l.YZrUqͮh)S!3%`̈;HoT}֣0F6IcMP 7(b 8WR0ar(B#64fZ}Hi'*rP6o b+W;[ i*E1%ׯj^Q? c20孠lHKcP-LX:jaaiZ HF}s+QyK$+@h.ԓ>2:VrBxG,銔x,9&).l bf0#[CLLC64HZde+zv:ԭҖwSVڝ]$sFQ6kÌaK[.@&jL*jMYtR᭺שelJn/!_0~?]̂2Ծo8]n$ȩ+뼍S.?,pƎa[G=K [:beLpc hu?Q3;ڼr3kkK7z J`"ÊR##Ip㉘mZCA 4 J,[2q#$10DsJ{cjwk"tYϞuԿ(>=X~ka닫O_U~9FcrW~r|ݿ/<7穿\єn2 u܍=s憲fV9Ѯ![|yU7WI`LJ_ϺC}m'9*:~ڵD`(,`uǕfJj)ɰu$~6|7lsN|"ߠs29& >6|J˜ "AA{(u_8vz};NھdIf{Zoo^VBBqy͜:ұlϾ{nƺWs^HVM=mSr$p5r".(NX䁝\D±l"R2ȺRݝ,(P̶S6;M].RT#GXё,d9mtLv#b$ZBOƨ^2/IX`͵{ Xqڽ7GVRwkR}lŨԺ*! s蠵lp2'}~'^sAm6kUlxEt+o'ssV0W^sL&О><R5iPbﯴT"&sL,~l.f_gөtux5mJ8J +6cK('`V`PccpOG9ܡ xrWzޙ|(c/iV}/osεֽ& s/M7DVCWz{$'3' Lgrw0| c֍x$0{;ט_u[:owX73o}wߗ1BDΧwyGOr%u۩]cxֈeZ[Zw睽Wp:kJ7Og(לjXqsZ#}jk\|$$_qG,GEJW28bCF,ce!eKкE:(7%PMLT]Of;Yb.)lTTl:u!sJJBW43ְ`x+e=qǪa`_uU};|kV>`n~`OwawV fSy氰us9o>GGٟ]u{ys3Źz]Xᨣ 3_ac+!E9}7ڧ?=t6z}ج'Oˮ;>v3nNB$DbaifS * " r֭a) zxd'ʙAݘa{JY\!Q(Iw<5jUJTdVKbkFtQڊX$$`R" 4#}kg~|hz( {s9e8X)úłTM&m +./s3:z^0>!XR:F\ʼz[ƹv41tzq}zNyuHpg<-lTeiC`gHDkO@#m`tPWz;nYyo'זjF9^ݙˎPdnk/>tzfz: MUwZ ykzOW.9[:cZG?@u1Ԇ1cS;<1>N:%5(o/6y_.w<=UV3<5Vy{lD}keY0kaG$вqe[H,r22Qlwf;v.6j &oo[{ ꧞%KQpo8j-b8ilUQAvi8a&NOS #:U-\wNw}GJIU^׵Oe<`F՗Y/ȡjCmʪoS 'ETO$#HaEQ/DddZJ#O5 .%z1ꍅwKGZNvjIc_eM\"Qf.zQp(j6)h\0mi(J: 0<|.Jzx-b"w+h?%|K#[W"|P5ԣ~zpMFJŊ24:9!_Ƽr+1z'_Mwߏɝ/c4IJ瓢M(* DPJnОDuVSЊ F]8F걳.y&\!{-]tɑτ^Vi39'd1& k%d"'sJ `o {UwyϭQbͻ,mCRAns7Xz *I\٨fh(R ٕ#ufn&΂BŢ*u2B*I3j`bQV cg!K2e!xrMRG@#kOe@\B`{hG35.Qur$Y%#Aܜt!p9+-'b_{FqCO&V-~4yH^ٳp͖!(easE22{../饺I}pW/q q6q-^>f%Eaap@A$!]9-"-/nZE hIF`g`+~H^~ar*3MRYt26ģ%{ Tg֬\Xz 'sӦQy]ce/"sJINAk Z-:[ڕ0 uaCH\"P>[/ȟWPg]#m;E.OQ;ՊCXK3eS_O'@YIJ$YTn14LYmVuu}\;cܛ(В9cNY*TB ۢnERYc\(s,0 :=99BĸY3'~oDvWWH ~yk*A'lѿESIAyȂ- fǨ[ǙA&z)jȞeEkB2լRsR),Q+%_ga$3BCH%eJhs/Tolż GKG_f/87ŕI{k7omx.{ԱoC䛌"jYu= )P϶jkӯ,_fDj,҇~n,N[]=2쭴j䙀l.6yկ./r]AO- 3YMaTWa IZKO4Ȍ壘$@!e!Q8׺12= G,W WRk"HhݟEѯ] 430>3HP9VNԞo K!խf u̧uѓu݃+\ix-WȈ׋'s@5^X7׳bKt^Q^7hšK-m"hq2*8&CN`B D0DE(hX% ]'U^Pu٪w4nR*RVD5[**,ղ5'8xts#q){R_haئ[h%di%!;p1q݋]zLjͳOf#\\Բ7?d)NUBo廙HA405[Tkj2vz5+s{?e˶\\E)m^"]^G^Q܏ [o%G⒠]FoWuƒQGiz~[Hd+@#mGY]CVT c&f&wmԖgKZU8bjƶPrVͦHv =CJ]B)\k=[C3kTpyΓ#ѱL]!xK 'PY v[911RRyY78TdL^Q\^]k{+1t ˹MQTN(iة/0T4 kobj}6ipP5Z%lLѨWyv9KX\*q{1vݜSE55㬁itm9r6u?EJbyzP浖c)U0Ͷ4v XfhekK% ԪI9 TUP G۾37eFHnC ?>raTYy mN PG'*e_Kc[8$fn :J*"(ŕ)Gddq*v!(MGiz1tyLܫ\ ] /iɺQ:*Yar^ AHdY9#\tRgR.t5 /y>T3Eu!P܃l%܅*Ʃ`y`=JXZ!!4tL %Y8=Y5LJX,R~a \CnӠE# Kϲ@˯}jzt`^X8jU^.>Kŧ\esB],F^٣^إ^ؖ6 aT>Wo6q:(k7Pt;}3}k`7\: K@3ʹ-}DAf'ysjtnCԧ|O4MLE Tlj)/__N^u%̴sW#i54S\DkBjK5|N 3,Գ,5+BE'Zk W˻, 4&]#BNZJ1 HHլ,^76g`2ew( %KM0V@-Sw6-ׅ;{[ݰ 4_P:6(^[ .\QYu=nJխ}QD|gLt̫jѤAAvk|3%A[Vr6ЬoU1. LHIkM0e`9ۨK0](/l^`$@5 K"VM-T#lcC4gG=STVŷܪ,Wk6ܳPW`TT̼ *ZN4{m,5cIǰO/vJt x9]oJ0jfڢ'Ԥ? QefF} )@%1x9ӓN ѓJЎZEbbakY\ӵ($Y"N3GE a%y,8 M6.vKn˄0!4LLEq{U,3bɦ #r)b=À3Q2HITOҍ,flN>,wM| R+Uڦ.1{-e5rQpMo t4UpiY^\4^OWz5D=\:Gj&V C})lT<5HWغɬ7f`T04-0=Y2S,B|J),ddҮҌȷyX[8S[]Rf,ko[U%D66Ȕ1N9@AiQT m#>dU&ӚUr)1\dZXBxCјɧyFXK1_S}}+i*IJ6Dz:3w(kP9ݩ4gp^a=)%_JPHx&}?S٧HrkS/[ENԦYˏuu͒TܦmxnL +VfJavG4"s l3F" 3:L[\z{=_i`bQ`rλlτ<X1A>1_AVg{Y2f !t.cXb;[Ru~:gw  Az!J0:"|R3L}iHPs䉂qRA(,09 1xm&@r2Cɽ-[,b~VsN;|\0Eη| GXɺ.r>9ZA߃N[>5CߜsKեY͍;/lxvI֖6u궱⛼ʛKz3uӝ3kUrfW|}yfw-yͥWڼK-ҕ#uɉ}xk/[FU[߬N,wtxzVIãtk :%B7XcM:FR:8Q˝nb96 qfx+jqK"!j"zX0"k4x`z="Y'czd~ǴOz͏nIJw{`yZGo^Ms78%=4J2yܛ1̝ߚgA:׫~Ƶeql-B3AqP;:Q-"j f)s8\$G D m/_2E|(/r;kЮ\LsHKS[+ (i#{t ]3z4P)2HGsmYH2=52xH(EpW@R~+ ֕0 ;[]ui@#(_HrN0-D6,!EkTܾ +|֯# \ Ol |5Xs-ߜ+uo]93rg^'_~plf|a<k+;r/WKS^?'qM ߍaL$'^C^ ~XŒ:coO_V|wX'kYx{|8DM',n¤LMu z^+uxkPq@9޵t,NȽGK:ngs}u L*طky0 )0px G2AJ>}iƳsG D}Hg%cǯzEAXr8˂+BR1OSO(ms [YƱ)I _!c`kE/KY;~ s>FNt!Bΐ![ [.pDpÐN"Z4ϢWXw;9C>1t Zn*Itw'~F0Z6om.rZ'h:|G&SyOfOMSu溥1R 1`e/ϓ2 !ЌEc0Qp-TӜeUdu0J@@;*au8|W(`>D8{f1N-{1!.^f,mHBG8hz9.ˬdYb(̣!6.ӌ_-z"NWlak/Jfض?m<2n񥷈f}{P*y204>~~(m7I%h cflL< #=cQx(H&4ksUG'WozG-7/^Pb{x /\qO]>z{|-ꚨCg'ԣ8:=\)VuA-Ƚk͊র}j@xg9c]wsϕ͟.34[u' ,3/AuִW;R^^_8uv}lsOY(R<ܩdfrjFO;#Cx&ߝUJ)-{p5w} /;x7Lֲ)^ƻqN2{ּ=.gkg=5hfg:\&$vu w\Isx:s{*N,ǙP7>ӬcZ,!S&Zz^wz}V$s:ﺮTI Nx/9 sW{H|3Yv1睋>guSks7κ;W\{},wyגYnx+dx|<5JqoycAV|5+w4sǝQCm1rcpzyz5Z:R󧕌s~m. 5^ebwu}a:uu7fѮK=k=ݎY7}o`\JN zy=ƛ6~:;=>2{ytfrǷZ<גSww돒Fז0/ޟ9~opjp;;{j{#q}q ꯵tpy^et%'Gߋ \ϗ;Riubwrs}y\8|ܾμ[H^xw>_KuO 'zn\\o<)J8;+9Ҏ]9}^gDB^&1v\^lPYν%G25*6:ZT*W': Ua;W1m-)02 UHa.i2(P镸t"칕RtRfO=:›A2h(4ANڙ'2ܑXە*`|iX\24ntSiϷ֏h8438+X׏W0=—B+q>W(aiF~䏪OџnnBΝ9:p㤱WOϯJ:Wj}S ZV~ߵ.wk9}{+{_{z3δ:kl\ܯ͏}mX N7 >B{?]rUZCfJot̴L&]RQpqLq:ZMV4sضثU6S3)u&lT厍*tfrٙsֱ*AJ(dI@@۫.M ԊԤU.SB-#P&9% %hТpbC}Tt'u%&'aZ 6k]HqZLUF , F'^YJZ%(z]!N5iԵb8RLW edQ2hUmZRF6J'4+延Ih.jW H[@zfӣ,MEӯ"gD*Be#Jp=| iQcIan"C\ܷWlmf=|]te"2XꭤT)_4PDWFNPՒJjX+nA!7KJw-5_z_ןmo~߇te"o[9/{r_u~g5?^H^s?Y]ߟry׬o 5ٞVxo/ СRΗ6Ys=wj|bp=z9C;ºsYir=y޻|鬝yy,V P<(JŮk=oxbO\Iz\v(d%jXBKu1muùk =y4'2c>.z>bGyIu痪sAԴ:5N|akÛǃr<8Cuch =cCeiaoYZx1]cwߋ=-`C7?9gi=1;;},52B{?Xut5$AKNqgpjyuqU|&X2i;cFM 2':Y9 cҿNKu)I:{hJϡB^rUé"% f"诬;X+R'ID(s/:!W3xͶY0Hn=}:8+s>fl*[.& qІ.5`+qVE_Y&N&Qdw>y..jقyPBK8##J>&jY9=q̰:mgF  sV~rZikmVRG|b? tiE ס'6" p=T/џK;xkڬNy׾{c=ly횕?~xZ9wgk,??KkOlgα{b}9xpw;yUmgXWcc[5QCB?]wr+}*/ɝ{Rqƹ(c~΋}j]_]bgY~yѿdu푇DƌMN*1ω5XRgLg]֤dl!q̲^D^XNd2Q2tlVXDa:$2\'ߜ3 mju{3"QNGd`&` (ӂ@kٮ/}jO3?WWtzq]/8a1f^QFR9:B8LCdq6S$a5lzNW"źLHI+9&0LvbZA+\:0usL1/^c;u}ة7ֆ>ǜc=qOO{ϙ76WV=JvqֱV/> o<wמ xUCsW MޱLmW}]u}ew:^dטqP&%9:Ѕ;ljr0Ns4Q3R}ɑ pLCw5^p eA(z7p2l 6CB9[%w6\G뫢hBt!V"H,PT/yc)I_/cZ{$ϊ%TϷT%k(8KJ8<&:jX*DߨROE%-RzAzm*J$owRJ:3tp)l[P=6XUR@n]ɺ-^MƚF4]u *xȧdI̞2]􋊙r Y%jFa|3qewZLk㓭,qY](|EwF|P/`Bz#85jPX^1.nz`4T732*GY1vx &yV!*q`]]]wX=f&G_ԗ>eBPͲQN2Aʈۙ3o ]جu}VQטQ\t6нIg^Qި4uzɖ*V:Z ͤH$bBR' w?ww^+n]7+вY;ec[½޻/gq0q;u0`Ƶ,,joL9޽NbȖݘ[&Y1Tm6$ N̽;)[Q(H5v99ѪK WapI#n9kMB*mYYQr2Z>:IA٣$,.Zޫ7jk. T%_[иU-iR2Ifb |+7/P4{hf_:p#毓67;HO-Viخ.➄pc~v [.JD3VeTй)IfՁsife'R,k݈ѯ$J[Ƹk"$V+P}8aRe"o";lͶnp"|c[qz?MŇ5|L3H-]])wt$R{*l-\e(&;ODZ2rLa6J/OOBQ!_PNdk7'8wnfĶwIEJ" >uϪS+Hn$mW~7?W\ᇏs߶hTGf %K_ ODz~rаM35.UOEFuÁ4]s_s'4.000ieߙ;U&zaNF_\vf$8a#I6 (y/ZgXp΋:4!*rl4δ~Cj@nNcwG^4 |t9x3oY}Ɨ+-GK$` !!v;6I@<%#`Ѕf%;ѫkb())) ujE?o:d!hxx"te 4Ôզ ҡחF r2Ǝ%ta2R%SGl,%&I-swcUݑr)\w7yMNrM.˻knwwg+v 뮷XY.E˪*|CC<| ,@6uf6`\W/Nu,5*).],:Qt2* = 1Z6CiLu(:򱱡BhUE1eݍ.TaBYSfS$d^ oCNHJJ)FTj1Gxq4NPd9_89mrBujkRq!,ҚP+5.]MR)ʞrGj-YuZ<*umnxۓ"s2@KwBҚXZܗ?>01YLuJ:ގQ݁lYanݝSG"mteUHi!iK`+bmjNk+ʌ2&)*jRSFv^H׿''Y_{?Oo}H~;c i ɖa6TB`sJue}J*ӛ+x iˍ=a~5>OZ (վTV&6S*L'[3 E!ߋF~DGA-|u?AQ:sϮI˜Q^t1{B4HR(nzф?:tdA"HUL0Hs?$#Eڇ"~*NVǏ]>?<680C+'{pk ]LqA^ΊM#8m4^\š, oZϷ(G_M-GG`:/2kԆ)6@2gĶ F2;?57`݊cfi0(Sj;}J̌?/;Yůj(cHH ;Bdk}Wá9!=x>#Z~wIIӦq!ec)QQjTXsJm00J' ^&o6F!H=te.alf̭$||WOcēSʫz(PYRj%':Fd*Pk޻&L%pòH[^녲{t$O|"ѐ^Q H!ic(di>q'B;ȼ-&@ђ ȴ G_u%z0CR ^@g%=K6:;-!w@7@ %Tfme po흏MП"|[E'(ɸQڊR?wvK?Kd ј" } ;&oJE+ ЕAiC  SjBS5M@cFba [ *RNy 46UB]4:vu50nI+y[9Īm*PMtN|u{)17wC18ՊWKPsN@gHG Z b!hwAQU [i h7F._.*f(X-\4U"U"DEL%6镅ї8Prd4RjRBVjQ^_U_7FsOY6L0r$wms(MY4+1"*qCWہd 2 &z(⡇WQR;綩3d{*FLr_&~5|gt{m׎8f gk(YEԠI}}>ٯYVI"b"`{5q18y?~#OZHiP)KBFuK֌7HW&SRM OPCTj5:^5cnK gq 9}8hZB. ;J,#DC)C0+yqi54(ȩ9@xY}W1'Ѯt H$ɪS)K ^zq([,[rJU_: T(ޯ-#MR l~B״ȏL$l* PʦR{8wj*,|8ɜeYfc~ϑę̷D'指T i *BD)HuњJ *Q2C(0a<:8M"UȠ"Mbd A)p-h(CNUԐ_q#9ke ⃽ae %0YLYְmHRUj.e SbL&Yb"k %SVlH,Yij7N*.ҴHJI.HQ1L7M@-`N>,d0}[HX84ReAXcFh 2fFc3(~?^r܂;JYD[ @bjQJ,hPr`A2"H,I)L"bVFbR2ʦk ÿɃk9S1\9k'rZ k92 ۭQEDAM^՗UD6[rb~=bqTܩ$ jX$L6g,YN  *09QYL[eyYH$IRC~dv}#X#$:4 hgkCA.~QSVDՋpSg!:8 Ra~ 8ʷblS+H"Fp]M%"B>G|Yq1ىşs޲𽴟 K(Ajva҄{,I&y(JA \GlIbs:F 96A;/ ͩ HE4@lGw,bxTJ|Q%$4'v'FҶcC!/*I{6 ""ocY0H(~"38nճFK3j A)2A1h"S AH  If^:G $̪a;nLߦݴ@EY%"6 dnQXb_^g /bFh$&PTHܩQ̘̒P7̨Ye1^wwq+i2C.SQ"@1nzL_"@ W.Y[!c+yYl+6s234#fm̟5$6`Hc~,`9j#T!A@YsRVաy3Q%xBA)^Uj2CV2dxG Lfvf-XhޛHӈ>K!ȴC&0Q2F$^nޛg-A ,cILț^9^d&\ Kĸ[,ǧ9BQR e, 4.%Rii*>rK8@#KY7 rɽe:T*tF[ө1jTzvu-L2dP̞М4I *C̤$a ڭș)+Y$ XEd]iFɑlm:X:2M†]{U]E РKaScHg>z%PT2sDYGlaGϙH6 ƅfYH&e9T`Q!5α:@k7VS꥙T1S͡t2I㧾Se8sȾL,26 4+cbD"U ȩ_Vt0Rma8 /?8CVN8ŭ>~S#;h,J6g*mdw +$^ }YF k׵uF(UWuU=J`%cO D{7J;cR cHޮ|%c۹&uc=< g{C2~gd, i\|^IvuG+=z$љ_5A|{jT>@DsB}'mo@}xI\ح- Ems awBr VT#Cda|k:1C|n芆%>D߿6AV <}'v :L@@B0HKiJ Au8i  WNn٢umT,R(v^]#!p(.ӗ\kUm%`˜'j|.]~JOeLK₉aEXer5 ::ڌ7w-rJ\2a.bTі62D D KdޡrM٭F4 QE(T*O  ҲCUTXD5/M&=tB#$$Id%0=/3XSdYPVtTDJwXGH8cvI䐩zNh*.l& گʂLQh-FPJS(*Ss1ݶNjƣKBS9 )jx޼u:4uea QNSe|>C\$,Kş?nc^=t^i̱1,pk ~tyUU q'Crz=^;x0.|b hIwA?Տ %"nq2B_ƯO:,4D# ZLɤ]|d \}I|+(v1C&7tf'mt6f=C溔ʪ>T8ĝvȕcB$*ʚ(1t `d&"C:JjK/N6J$[rA/(IYb!aWdI fg(Bv/^5[!ut֪ &"tCBR"2B#AF uT@gI":bQ&`[E54D~.qIbP曫Xb;66$ƶu1qR&2Vuؽ:C.E@)wJp#q̐{4MXv:ž\ _lTn`f~IouCX z_ZfsfM+Hu UW@ߒHvdz'}zxb|2jYZ h "$RkQ3 ^3ZdLbP#D)8Hն&2`Q z+3lJAQg$@ `-*2֎iqN\L1)zLBɢFZ>K"JZ(N^S*,aFR俁zFO+6TY:B.H71d?,#1HbC] l3kvYʊ Tf84{oKWFLu1*ZQiXZ韲 qlfג-]t_%$*nLOZ2)B4/a]%C44UPZq3aBHbr\]xa:bܺD$#J>H"78f8: V!JUjeD3Uڰd՞z UEH IIwstJU9RM0]ڡN B/X#}Xc$K ({SE3$pdIP!mPXT/4 8Md\rA *P+ڜkdXrTlsV[Ⱡѐ]]}/Kd`Bŷ L ~1s!/$ÆS¤!@t@e%TSN9$Jǎ@]vFobY71zB;Alia4c1zG#հ'KnTie*aP 8겧=|hLNs3(y*Ex]K2!}pk3qFO2D,%L faH%#9*F>A42k{6P @C?$"(@ lՋ (EZ_&2מ&|[c<LT d9iDz%F2O4QJ YL Ya /h^@uVh/`PK`a̶$>&op"0RBV,N8 "`AE7R/-d>QYbl6= , S55\AD!Bb"R -ɐ? K-q0AHE0H$x}8@~݂Mm&R'D*$LPjJ ITh@l~+Yq"lIL +&2ǝ$ZQH`X(.(zTx5?,tYlBͯg4pP"ꌷe,s-{qz)_w#s X*M.CZ=VeVYĉ1FCəF2$Bĵ2MD&1rIMI0I+Xe@D|֮A! H,ğV*J:iyvQ,2YTI!zc(~sxš%! *Tc|.FaDMgQ4|P01C8F2UĈW `i?}>]a&{HϷ#DIDvt;FH ͡ Qg u:eX1LkY)cJmO-@ne3e:2 %M$h $}s~/A,4)Ժ%°'e$J4i J5TfJu! U "}8ޫR=?LQ}W*1%qWPfQr2ޑ@QH Q5&jP\eKoKs@ZUTu=lw3&utԓ$biPt| :3m.c(S<#N*VS 6TQ*wZ,[1&,fEN, Т L)YPB@C\Cxrb@Ȓk.i4ֳ1(hgŀ&eDApL@O*RUAUvjF Eݖ.屠ZTi~|W+L$22 Β=R8s/)(֦xV8b"D1(O&Lhm@ &3QC5%Ö1P>kԲ0=k;qC!FsFJ7q|:i˧quGm CI>655rImIH4CS4>+]F1H( -z7U% a(QUՕ&1Fq$c9BaS3!|ƫ棳&KBAHػAa o Nf(XP cߌ8!rX[.[I&r9\ {j&&i\}.mwdY\PHjyyq۴ 5]_xd~,t0RTp#@ALɘC!!1p ]Rbf rdg0_ٮXA$WөX ;i4 `"03@u|Zx2gpj0 js&dD F5=ib+Ʀ2ba@2۝:\8wMM[/߉Q'|I!nk*L\ʫzޡ;B Vp6f 㾤$HI*jdߖC@ل".|pl7 Z}rtCS8$ÈkƤXk jIjY!ơScoTc7, +/ z.ETԒҶLE0!=noA!\!%PF'x aG8n,$ PB@ J3Y`DDBpAH*L$:Bm2IVF&(m a@ȡaD&rP)Fwq4*tY!D& "L$c3.c]Th ¦ib$ΝɆ@-I*= Z*PX|dJHAJM][Kb܇4&d8 PBbffItZDDX'HBhq0 V& ]*pFX>eEӔ3a&JeBf˙ ~`Je $L@BP$-( &rTy8Kv\Ļk–H,4CK9b D4P &s0\Q%[eړ :M$aFj[ su{TDE_$1!(ćTa*{!Hc}ig2WJ%&Jg i&aۺiAɄnՁr5-dgcQ4PZ{Rt影 PX(4mLDGr@H2d @J,(MX} DlS ;T`` @ħT0 pI˲꜍MV*[P K2@kі=D4|nbB J1E$Z]5M+B/6.,e&'f Pe^>Ş? 9RhO^K~8FBF̐2_*U9 ,b(r+#%BB]P%RA7M_&bU))Td(t!AC+vRe=D:buIrI։ӽq"BcJ- pIP^XK2 $B"GM{SJ[is Kizan҉MTC aLRJ0RR$--*bE .],`a.T*_h\> tFT|g}p UQTVp[ m T#8\ P( @D@$j5U !F2 P&, FF .{),~m9ԕUd, Qc%9\02XLg,Ġy%(.wb|EJ8Ͽ9 iA %JP(E.rac e%4$!EBfDHZ3,vK*,dX>NA&udD ((Y1 *Lb]eTv.K$Z1FHfɔ,@U*[ hjKBTD 6T/ؚbOe.^BAŁ_>0 3Ig'#p5HQP֐_Lo|2kbPS&%^wf!Փ fr& \ɐ1!nɄ5`U$UEwL6l#l"I9h$ .B.-tpN\юQuF` @9`ᵄzaK̜͒" DCN4E*P!`0TDdLܒ CuoL_J[>]M< 3M=w>Y#LLs(l9ƕDЛZ"ix&dRgYQk0_7/nݽ q1Tdf) K yV+; 07l]JN{4 (NwJ&:8b:] BEy ; D1B+#``C QŀhWCM3Tqmf9_r\/ 珄aG(II 0CSxQ*WYsTPB'U`PDiTqQ|d.%GWxaBUR,Ȣ0fH2*F 7Ivq %3\BF16("Ry&N!;S4aYA'AxC@QDV(4F، (R\=ԡyj}(k#却1]9~R˖f|}*/79&`-*S,Ҵ ma+tȑg IiUȡ2Pq˗/^Ii@R }qwM"Bhz^ny^|ƔxL'&I^^&5D6]j0PUDXلthЕPؼfxwUTVd1 y Vi#eJS I @n8]%z G4ְS:A47ϖ 9II3,}Ld`5uChCsn@HiڊmuvmEGD9EE-%-DH >& -d^k65mQZن]u][4HlD^)`)bf jtP! aVfaM0A̐%]Й*S "XLq. 2EIeFHc PST -5esuR2 !\ܒA-@)n 5rTˉ (b#&dd&6E} PH/ʥy5YX4l 4#߭6xLPz'3e<+_,~w| c+fJ*R ($&J ҬJs<~)& D1R#_>rpNfeDL+I ĶQٓ_ϫ{1jl܆\QJxy3_ed4lr !Y!۷׳:v0eVET5`X ǯOC.#}އ2ZJ]{|CņE@) x=C ӆgB4:&O# eR,-'vBWd/#Ô237vPZVkj(QY\RVKaL[+ J2B >4HK_l; rrR@Iy `D, Y&@'(Ó)~^A1u)آGTզ*,j|s2]C_mNR׽ i*ޭ.\e4*e’ʰ2:q<=@ ʕWXx!&0+Cñ MR@ )3]| YGH#hFF  KT9TPEFT(rIHR)T/.uH1Id> L~xxeҀǯϹv$0(&}!U3SE0k7`Zsz5DE@uFxb0Dkx1-BWe5Zn‚diBˠJSrRLt)Xmc-uaιHL辞7v3=$'4N"@ : --_6Z[0eS4LIxTUkoEMLRp#I29[&9O&~:u<(CVjjz0Tr5I&%`}(dA|c{)A m@D:NZ|ީ^@ӥxqR~C3j 4J͙DUB`ESvgrYB- L R6fLj&Ycxa($|t9vLzB0R_a[/ҀA×KB46o(:Z`> YLU߼mm0g}k%q CE{HdbE˻9&^[IɓnUኅ0m<:*Bd0>ݕD]f^s-#5EqĂmP+kmܵatP4)!Z0,YL Ht=CQ PispdmYCQ-D brV^ >pW0Q} D 4W\5s#a!rA;L\Q((xmV]D ]7NK% >W6;BPVɩBڊZ8YWr\D@EE&b B '9G9ڒGĺVUIޏ,%|s{vu$7Ʀc UhxF p2VqZ&3 ccLn|Вx=dXENZǥU뒎UaD4k52 3!FN8т =>>hr>T Щyֽ+Vn VOQO E/)4=5MjXhnBT!J`Jm|gqb= U!;aL rnNLyI9$IPֹ±ԟGg˩\QRt:T&cꢽqc6ޝ jjK)y7:(rH"gvJRVg5T).aYTֶ@OS&qكP3Q࡬,P y, y!@sBKQ\ dqŖzm\q$F10NuK^]{ F\Q$:o.MCVa,`TuIS1r<ВX̰CDEgZ:R\]|vCKBhΚ)G:5;m۷uc \";у׭A&ik7ǯYv H#xBݷ.vփg/Od>,~U֤K3*4g_}.5b30zz߿wӧ$: ME}~y%*wtx#xIPYb(uhs~+>@/ &RH/bs˾my7|à?-xF,$CexCVl7 pD⩀i0/jL0fڬjm;ܫ9ȝ2h e2,PYVQIkE"b ]tuZtHM6"MG#1 ĚDN*2UTb)ޖe2a%RYTC%6^z gV}=gn[NC_;9_r֊ʿS93j.iFbϤe)aN|h5 m-KD\U*ҳT CFcT)7J Co q̪BS 2 & )8!Zn\Ou;s<|t:2捓w8 xU>z'x0Ava l:$UXA.P)M %Z߳&0v $ . z @=9|6e`ee]kjAJa3uiͭ-:+ s Շ-(,b;Dَ#5KO/5hfϓO&,  Ry@{.| Ta0VhhV[qL(ǒV3aJV@1|GZs hÿ/53ڍUrRlr4UUT5Qe(NIvV(`Jku*!H (v= I 0(e"H &a$ I,S1d-UT5FhBS Ĩh4Ebʹ><j {7X[ڂ)4ޕNVLS*P8rHR RוcclDܸEx aE @ ݨDsZVEM`m[٨{|MR1(2/7zqK4֞#ܝOf|:VWȩ~!#kv9MA 3!h'gS,#p"!M%/;7-j.Wv^*1WaiA6YhrNA]Ɩg5H 'V[ZV?Q(uܧtRL-kehN<7=00:O!~Y0 m׌YD 0ʵ~'6>/ hC, ܏k33az:GᏧAS0z@B : Rh5T{uJIApIxTDM82#cq ynI$(y c^\<0ȋ! (T@7߹#!l1{]:Ա ]q~VDvrpzPi l}3uʻw)*- EjP_)>>tDs_T=NJ=c 6BlWFUQ=vk^. Nj(LU8Iwtw>`/c̿.ѩ*<&oMs͞{.qYaxf#QF!F,A?UVcHIAbc<#@TvARPF3:(|^ @&0,ً wdfk#6F>5 OeSDƨ~(h5Gj;trU\Fz4H!w֋({]$yTw&E eEsKZT$ ҦXMӎ hKx]$ 6W, PS gYUEsyU>/zX##j=F\k(X͘WZ]4dv60dA:z^U):vílIdD997m}@dc",@&¥,܉IUMV8VeG6eH%ᘝMt~s~ާX/ь4!]lQlP2)-4D/}h !mغpId f#gCi}u$:q(Yt-'ps'cӡ=ڜ= |ωGvP!B,,aHoU%-1ӉgN''Mk7MWmBѐa!uӀ*Zwl`đ>IΧ{ ZnU!J]k7pgCX$ԦܣgwrT6B'L!U^Zq.uCݝWKRRSQ)úkƶTHH(mc"ɷs$J1Ćt},V30fWcP/ ,C@%Vi5o{s~\\A!y_mQ^փKpJ 䠪<7wC]0lP h(FmCA$/eX,ttaʎqslku(dZXLufT^*`,!$v@` At=pZ^jGEYnfHt*͚ڰNov dr Nu#:^lh <Hɔ;w}ܻb 6i5ɏrN0+XJ12C Ʀ$\h}XLI&YREE MO I+g&9W-w8ߜw-7Gvx3:85IzAg5l~T1%XB Aе 2@ Sª0{1QF4|Мu"' i#R3^|u,&d-vZ1Ds~@dr0b:їsHTC"Z "nD`sF 1fV f9Ɓeӳ aצ@\AH*̱CŢC ; T_筸N0 tH1aSjII>Td ^(jqdA`E@T)>hsUލJ)7i{UI4|y<<ӻ0gsg$0Teη׏ g_=ާa^( J7鬈d q r>zQ6@$AP|fAԼvFћ É<3G'rLgmpf1D<0rMnF11XCɒ 1g5%dM4^979pK+8 SN5ݫxcLp׎FI6z@Xl͵ sL\ε|5PU9 o #8>d6xyt#"Kݠ:1񿪁LlsHy!.{ R`hu2v ڞzHV8A`hB.X%=Wp5v{H#L6bG}^3`ք#*ɒ~74y + uņ;L |+և6ebBMffk U':mlbS<ǹwz>3Yp~__z2 9B$d`ը*bA"(ݸfN|lOzvX$zql.}pԬ톳׍l뮸$|ty%$5e+ǤS:ә)a7Hh轞0ĻW,ꂈ& uSVN6fsP#N l(ڈBE[Of= K]|0z#XaQxu=;3uZ+].tytNT #΍YfGdAjo]R$/NԀ8d z|Bb=WԁD{" y߿SnG*QXxc">ij:4jP:wHVrƌ $EQZ/ȑIٴBLN1'|y4<6g6sfeB[Jf!,ɰDm$a% ǰZRS#ު0ʹgm!uֻ8%M={:Ḱz@G/ڞ>,:u,ψ÷g;t7 2TyPأb0.wr`+n7% nbH("'n@0RE Po˄ֹjyvz`7اpYf] ־X$!}}*_v@&;E,>I$㠨[=ɁP"H ~6(Hc[NY̨(@-* BIJ"W{s+M7uFywk!-&ZSCmcN]I0G6jR{_wQ$>Oᮺ_$#֛g`ٔ=Y,{uA̡#F@y'6ȈU1ҁz<˄=~~c'#ߡv,gscK A18RcTdnC-?Rڸ{|t)# _&MY۷9῍_,!השVJ%}Tl=i{hل/ [&bL'psOƄc 5a9#·z7}sGh(Q{xȰL.AB_Ej2_ k:5vt^[ wa):$Kzlm`v$0_I h&FwY ٫7O#3kK3uUQg҉yFd P]($vr9LGխuzo6 !\v7lZgI0RՁ6nC4{veOS#=dԡÀyf%)A'Z2VIUe Z C'̈`fC``ͬDsEL r|  H74v; f';^k>9ޠ{:#KzZk}5_f&@*/Z*/WYUT@€({?J55p%vvgXթu:DKLI`Vd1ε#Dg(W:貀szcl@7=;0ڜ!)i`[d/& ȢKËyG]~@g=amfED+pN1賌}Ϲ$dcz B; fN'^)Q}8IĠ k{hmϡb1yҨƋ1Sa@#6,^bK3db$TMdj}݈Ht`mcWRDs 4+$NìMVd8b'uͪ20!kc̜&E!fa=2%"{ݙ٘XkƗsy$VVr#מ vctSEX@X칓cldz }7L/]ds畒Q#`o",@⪳p.8[VBDlH\ 0X^22j/>"BВim31519ԋ4E,B1X:X"HGYnr"ѭbw`.1Šk8٘Ԋ"W&f#XԈh߷HGf|;#s.;WQj@gLfxY#D]0/: 0 @n⢻՘dOvZn`*vl{H("E{t*(NK9<0i6t*"".mhw6ZE}8J4aCs(+F[&|P<|8yL1bnRb"Gd 0tU6i{$ L6,] (X2Eu"5Т#KLVw8?bm01`\ɦkTQy%dNd:*܊'- "'O²YȎ=kQa2UVmӒ GUB`|ojhWԏE@{;Xy(A5?(1S`Y0jH𰓌ߎؓD!U@-昹D*ZKi ȷpt$Hk0@B&f+R419lǾer釢/*ȃ(Las:%4"7z$ t\o EɻRP*qnRB\lM0NU80ɗ1IKDbQɘ/(Yz,έϾМw(b ~~C|g.b>^9Rp1K$r@`d$x^|`Qf;@U 3`˥hf3t!@"S tZg ʉ 40Qvю7 leE 1L)QdNDrB!:l$;"Sl2&A4cC.h(9e!f1j$g (ĘRVh2Bm1e A,bX&!!Y2hqm˕ !`⑕"qT4$' 7e f4bH4Eu,3U 5(7b6BADǎm Z&PZa7i,KJ q !Mh!FdXE:ɔ I͛:[|seC N Yt- yQ(4rIet,Ft`sg 2Θ׊͔lɅ6ι &n dmDلHhR8kJ(T$2\KPݠ(..F0Α]?#Cت@*$Nx|$$L@,^|o 1\󭥥UKش *FZZA iFVBBj[Ei1UFlfh@UAEZ(E!DPU@Db{% #J4 V ŢحUT %PH4("(Ҡ*~ T<QET|7ko JТ"/+DPv\WЈH( 0E'hDCA(`XAU>Tʣ%^?-/I:">[qD~TKt$pGEOKxE'$Sw]OkCPӅTWȃ <"K^yrAΧTpT{$CkǠT|(7KGk6~H$|1^i e%C  AV*PT# qsNYp0$ˡjUͺdK>[T<K1Q7Y#Х~zelC(I%1AHA;(rdR+*,`뛩fGQD %l o1.Le j,0OAAC|_V_yRG~캯Y5jY5 em\uh<+$j̤-5Jtޒ=pM9RrL|v `sIAمn\qgN)0)YpXM&F!d!Q0)JL+FY`-]P0u¥r |Y~&WGUN%0PP,aD?baLLhMAMJ@db)5 kZB@5 (DcEdV6+d,Jю(L#Ha0B ]n0۷JA\{v9t%6QW~WwvH䑅+iSG{yrDڏiv6EfP|ɍ'?^z/ùidE$Y""ld"14wiEo:Aj4D@ /f~18䀉@D@I+$R)bE-G76AzW4?$ "QW`0c3̥!9]P ) =@V IĶOYL0o?hw,ia>YA+RQY #, #0FF !"^Ndfyy% Y E|F@{Oj{&>` _ÈNB1!0,R0bĿ|ZEҖ;d.~K<@tɸ>'c5 t)tNOPImjVMmqJ$#o%8pEicQ{_uZ HkHJUwu蟙kZڿq8kւq?E) yI LlOYwJU~mavtL,_n.Y  " y1 C D0>6&P"#g ?cɁgbHs5ޱ#g10Xfz_6z:Kh3K2,;@Lj(\j4+Lo[I6V6w }C"qJM&1{+",4d2ݕ&bfz,DB س4fPBIy#uۈ-F7#XGBE|fm(n30F֒ve3+x7ãibRrNj=N2剃EXygaٔQ{X~R&<W%oU_׺FE qkJhlA2 ț?c%C k?5v4wAƟAAW$xg돝) -]ˁK7>c}-Wfj6 .`25̪׌69d5?d=Q {.<ySm$Ⱦ1#f4m蜄Lۖ!r9loBG랧^ܩw =ieNAl ]_mFc1 D`rJ > ?56˧|{Q?5Y@Y}h-FLm%QRFLXE> JwRF V ]64P^˃/绌/]tF,f&BY7$WyJ0hѠ%TXU#R}m8!WQƶ ]'j>]T*|Fg:1ww;omCm͟bGd"R2"RD~?7CzF!>(V"cמ$ DEDm}~mh7cֽ }7jE 7l(& j-F#bW|ĥhibTdI@ָv'/:>D傑L|mMAHXVKQQE** Tk$[FFjf6-%QAPY,P6omzFhj/]0a0"yڔy)Ic=F6`cId4']9ٱE&&Z(1_+oĐLO锢=rɓp{j&H /q\8L1URk b!u^t=vy7J&WVZP$ie M!|]zͣ$rkKmb`41/CF*fIi4leӘƨu׊N8$QI5RDG8LoWyaq@޼ XM珔(u |׫`fLȍ y$DPK$T{8U7 QSBU1Tgo ͖2/ZŹr_> +t#Y>*uQ!j8Ͱx~tOI|*#T y ]E*N4@ ++ BH 9*8B"((*@" EVEYg$3tQ~2c.b$ ]R?ʦWc-)"5"Hfrr(bCk[JXFMcGszUz=rxf6+ƿXz* Pbs0f5 I?|;Qm@ň`{8sm8AhI׊nGr7;~t*'&_'0- dSx'tR6 (kFRdʻ$MRzZ,}|Sa=PԚر%Fɨ*,32Ogg2!|i!J1'#~j_LɄǣ'm#X}^u!?p"Nn}^ dlAs^?HM<\o6bf=?z>w#r~WK( _ןQm=7X R@{XE…y%]3hfD CV] 2%ٻ5wV9~vj*wkg-U7 deؠQMY.Z'0A@`2&$ㅮ͛ m.8{ ^pسUp 'LW I("bHCpA ԃf'L0rI뚫P|lA=VT˚[Pa{zmD`OaiΩVw4d"(e%9_cznʋuؕƐĉgJV I!(.DRJ]yRXےh#]̄!/mOWS9K)R ȴrq8L=MAf.Vwxyjas4QͲl/Pe|O6pi͂0D@A,c0͚|J}tAUzF4jlI1\U w1r^<VhƍZfE/PuP̘֗bUVas$:yzDچmWE Gpt8TO_>NKx ɒaA0C*j:~H#G ~ qRl%"9Gݠ[%9^ Bin>}5..6yIvv()Hb8!;(\A$;.x՘#`J@l4x t3ea|ݧ ^䌯zǠa8Q`i{6"+k -[ ˨yly@|:ir'<Ƅؘߘײ2R8ފ(jc9y}i A|uRg|d|Q,,JL]C2$ ~DpĊm)@\2Ӳ ]'~P0:2$pM;&GP>2i H3-}L?<\f{dxe$qQTt&r7pv) 8)8C'/tLe?2 ^(/i`GZK4*?nd10aCT G&^dY`.LR2ί*}D3n bfn.vw$#s*ÄM+zWYX!eNbic%y vS(:1emN1V92plԳw1[Z<ދř(HA,`L JyU:֒ I ! Xl%PY(&,ƭ ,;6W?u)lg,SQ%)hņʵJ7 *2!08@U%'.Zɻӹ,7RPM.o2m\=+ R2c=Ʌ\֓϶5bIs' h"{䞟U<L؛񧀠MHBj&" ERm.,:Z$ۙUԜ!R~4!Y1 ^]\C$Ry 'D25.g E9ºsN}rH,0GTdma&*D8쁽bbMBn j\!< i)F )B@ ڈ=]3#*^lápR܂s S/w("EHZgm쥌b19E2iS{d&_ I /) kkwydFvBǙ#YPhLM^cFRہ K!.. ﰕߣ3Tpec5J|P)Y6v Y9LI }zAz Jn%\.2, t$y,Am"a\crdj̖udq 82nl/&072/gHݸ$4ugӷ,u2ecxcRn| T .G4?}CC{:rdaf$QQ/r |][1`xhWv+وS~X[#D5K )_X;`Sn3,#aVB'J^xU']L,ZS+Yn̜ᬲ$OY#y2P};'s#뒨Tʼ8Tb+T,>\e#U1!/W`֝Ttv {JZpTs lQy&UL2{K?$Y*5HW(i\|fևR?a^>ArR7ҩ$goetkp˜p9-jHWXc4ڮy>V}zzdƕ~Y46[qvtUۗ>x5(@lJ_s'S{j)^i8C\.6q9OtC4Ţm@aUo7@7G X!^sTs< 1IKΏd}@]ɥBޟMO{<0`Ȉ!? @Ծr TfGQ)D0jX2P ZmI&Cu;7~4;Fܡ\04?}bZs2u6ş=/k\$ۘt` M^V -(C~]`.V}Ł3"!_<^ܲTWh-Ᾱ (}gIC旬I,3ɽ,Sz RIK!8yк0h엌5;DЂتțo%Qn $w N0!$@e-,-ڋh"'X!% .4Rm<يNPYe:#6J__V$ H5"6_i(@8 ,WzEȉ/"^b[ `Ez[st.6 'LPXJiN.G'9׫e<70fDDAW-h[X%nd3.t~jKwJ:jtopzhАEu߬c\[ҿ/ʱP+]/1H<LfB P0far`ՏQ?ll X5Z!u 0q %Ji)CG#З?2 FTK; ,4⢶ ᝃulL}T|}Dx3k}Mq :q%vJ[hyWP\p$E qԹȍL Xy!qV7 3+݄p9p<n;产Oʀ}>G]'I5!|ff>d^N9WYVw !)yXmM^5z:?أ#X(6,\-'p>V?wބF::'v};b&XkR-l K z:ؤ7ǡZ$,'1 jf-2D>sBi (3J`!3Z'Q&8'̌0cH!-\ $'7Sqr.=*](`$H%1lJqN0ޛ4m>g,\;TJfWiZ žqz 583AKZ%N:|W=-)% Ma~mg0e`!DK5z0Ƥ,;bD\4lJtJ"jd̥ qHy3 @|˩5v xtqa*SfY6 'Ygi`PV#-ujr^,h-'s`ehC #Λqg֚w.%44(Ԏ\wq(;$U&%[,mB~d>+g4&^'v=8J=K MG9fK͋D`V͒Z"q<Ws49>l\fr:.MQÔ`Ni<]S lAvޣAT<]df[E\"gp}7F"Ւ,:<+lVg'SY>UE c>s薓3*hr!xљdoAxwa >b7?zRm:dހFN/MmxY9&*[" u. X\ڼÀM>R=C$y%$B k9\_MW4F)!J" IDi6\;qp+1rwv}Cy뵡tI XM,>C14<5~7ڜ;S |6xٮ9ZԖV'>zI"WȊC@vxN4O5㲗i1>zMk2ZQesTq(7[ eg5?m {sǣ짖4drO>9<ѫ0tUf~Q .!Ϊ"yyu|,pI;;R*{~Y+iNUjv]v& c/}6+=BV#A|aZ^/c"ugC=VҐcoh"hTeQg:NrmFH!~c,By%W AiWbr(p34 M8px0ߠip{ؠ`k6t-Cdp%gI0!/_}P:ƫLzqe@FR22`[BAd43Ѳϸ;o޹&%Nr+$ !Fs$53c?U2U²S;5%B+ iݻiYBV i dr,j`Q\/rc]OCZY]e m `JڑDL(Q1H0@^0c*i:IDH.x#HM afIEܦ_yEU{l=_ɿv`GYbG[6iMh:Wf5ehZsG ldȱ}tk3⯛e1V:bzEgj\h.23QLm_`a{FnKNF6cN3sVlF/Q2@bK8b61lԫS/ {K<7pJ2~ȔJ:\hSbmb|P,#tnFR쐍4gv `.x0Ҁ.|,ov@r_R _,$;Tg7$~y@z ,E8*bmieֵӚlT~ PO1Le F6>&5qeͽX͜8Pe b ƆF HX듏 AXK%GGvfRcWb,o6q:"MxR_NA8=T@Onv/bQ Ee`!et<iz΢$'0ͼHMC(fp#as3Vk)%I dwhe_pC6NA*pĠwf gw*iA@ɫ07q~jBIe]5 2 t,̷dQpkMiw5?g/\6r;83 Z* YJP3c>jnM_t꽥d*D:yKy{Utl=I\k3,z3􍢆Y;^8oM\Ϸ!XrXz 9C3A;PwQ1rBħ Κ3&zz*LQ)Į0!E=~n"O @\Px Vix}>!=h)=#k랂a.5,F*_ 4^UӤ,;W.GˆEar.${A=G|VRSI˦h}6$ʿ!֮xi)<+q$ GY_|tF|B"a8(Hc& VaFPTp*B$wTOOh6z% ͰEQ '\xP d!w"d<=]q %ޠ@]$ 12vW]`%oeQtʰng8TY(vԱ9}oYJ]gK@RTxhY]J^Lfv,yf**^BZvM,*Ja4E` *q5"b%?8HROh%151$w=iEݹe;n]AʍJPג_q\5v$4WHn;iFՠ" 8죚kG=ڋa,P8Tbf=-U[$=vH5P`PS Jt{SdQ">qꓴ;ZaE#(E9sU~xCNBJ>g r#f5rC~׬2Dy.@ KlC@JU UW >X$R'in%+75j{ҭLS8`cʣcT6?1?Z'J3Hu9g9|v!砽 Ga  W4@v" "::%ǏMB/[SeѬ[-г8[:!wS.@y)L-CeyA\ÉʂZȀUØ̤ V6LUͶufxD E|L}'& z=u3hNlW4k2]Z[%rp_+םHtgN2K`Sw|m 6%}~6qq`9y(Xf2pUÄQ<ߣ|y\P z|@L ̱KetyțΤ5 b( "]etGQ¦|hb޺T"%'>z{D6X!fN˿TSp<$BoY,ԼV.ؽU:Ycg>E-&mF3 ,Z_%Sqc6Æp;S,;̛!^I5o5X YKciu^G6ph^B>ho\[B͠(r@jZ0ߏL H' ."][c! \u*kO8.T9w㾴2a00E;X qX_G a3ûhG?ZFDv=^C Ƽ.J){c&nj4Ӡţ ɹQOihT\%k%dJp GrG8HѴr|xL0;Զ5fxV⾼oC3}EȽry0.R}FI&Log&QáV5, *ɀ%xx1cמTbRl+$qqd|=Fppqd#VsqpsoF_S&5wTlq׏;3yv _dߌWf3uBZܳvxU4OYԽ3oA? 0^ʂ5c`J/'1y촼LJխtօ꡺VM{Z*Fʮ4Zc6;2 Ij7;u[xȺQk\-)JUfZ2ЩAL$JsW!-2+6q47YO.Sro:[^#/ jpGIKqljqFI_^EtJtO+SCNF-r3߷|ePS9xJ/bhi3hƥ6w'> "V;P'٢>qPdWn|suܜAr3k=t.`MX1%Kr {s0QbC+1`E|9p2tؤ)TDٞ9Aȭ)KJe=t/3v/(c11YW@;qG;b%>cf`Fk4 (T-O: yC .t$NcI^ F=üq!$DYbC屮 ځ=j1% ̗[7U#iB`X__j46͸9rfp.֭\G.ALap9+DJ%И0%9gYa׺t@v TeWΞ>@=tUe-.q1ܵBvlk2%ӗ=* o4 jH)Aû%xj_>OFJg0f4Y WƘ@$ˍ p> BD6t@w2 0w8o򬅗;iQi1BE2RhKG0 u9 *P5dH4:1z 1mxB揖FKk(;Iἰ0ljP$Hf_oI‘pK6`}Pa:koCLK2P^bblI_Xh$0xdUuNÃB&cmpG֔Xz+ha|UaBܭtudV5 ȚN ff3jd|x^墁es&&! gH`UW@#k5j;EJU(˿jGQMP %W)Z9:d!),ۙbP^LdV5 Ю@WA (_/>P!O޻L^ !i&` LbIՑ) !ffl*qjzLj˩`\iTIt/M)O110*2Xr~' x]~?GǾPl4'U`)Tpg^.xֶ/% MehXvM5/z%RKi-֗9{=ZK{7,6\ {Em-UHN_Ko#V`swcOR4 QfHQ植ȇR#`dE2hǀB3 PPTcTbr42y+kmj(CGh2T@sNh YM]iOfЛą2hj0Ɔ$dT4$+0DVA @!'v= +]Dl9a* -'_Rمd]11?%GzO%`WUcŶAs  ,0E`7) tGōFmR<.x~`#5AUm\9X A!_eNZHSExYG{F٪5IiO2KUmhofCAJRca^ DI Ba{zTQi&Yk>sj 5|' ,:=cQhgךr<шz=6ˍ8j{R (sʺ3,@*6oB63)`wxpbkp.YJ cOU#bHb AU[\P'0L݄dA @%v#L8LѲeQ%A D (X* 2埜j:9+.:,*6%E蔭gmhqVy6i^RaRH?Z{ msd qRpLJdҖ vR WwTBmZ9WOYB 9Ms @YkfǛ1XҴ620O@i?Xyޏ.+2vfF~hbb@tH 9GZܻc0h+g >1ɧ KFj i <e:XwL"6L5#-k3Q) X8vL,S/Et+J(HA{݁EC@`_!1ͲLF"氷#˩PFq4iQ("?5pRXgoM2`8RȡQ'5\T.Tؐi (\Usn7Q'ql`OB~LҺ?j߳T=h#bȊ0ZJmN'56LSn0DVWb o6ߘ!$G28Jذ.&6LJD%:ު<ֲe"rn*uTr]0***6T@<ԥ&GAFptmC,a;|I#֯Û<ɭ3mP&aGlSN̉6"t4T| @[*ۚwNja̹&iF(9L*&N/r,@*aţ6tk':3DZhyRnԄ(g>ݸ@߯`Tl u'%UcJh 68;*εc 3~! lal)!zFQv9DIK["R^r޷WNSiKR|>QKU]J+G8734mЅ>>ʸ: *#JqXbW+/Ȏdad'6ekhaΥ. 3feD :ӽrg9JRM[lkXWǐ`G/$VT2UY[|s|j ?||Z~#-C_Ѩ =p=WFd19589yb(=`#@W+ߝW亣xG3r1p&h[/?_&kO>*ӓ]ؤ9%H?Be!a첩/OR , `>! OXZhDpq}0J{1*T"xqn%a@JS^A%60fjV39CP1F@%NFŏ7Иh1J%1O=VH( Hy+ #OZ&Wt--w:4)X'y+Ky#hlAl'6U鴱h(|U8F4)Kٕ=/GHLl00=LFh7·!4vҰ9-$46F3?8p$JN;p ,7)ðRi.8`hlAHtVWYGeÛl=KykI`Z$5.o`3pC6τeN&3ڟ$=Z8Y3790he'n̥5M9,7s+Q "nz9C%kE\33R а#ym> ގeAwha=}kbe9 5̙ O=^r):. t0vp&Ub$i(t`S'hTB Z eq|[2zk,+ۚ|+sVh Q*mA_x~.RV p1#"J'm<S{.fG;>ŽDB3x]ɫ(! ?YLd{Zungett@LzP(~p#VNʹ R2gq8,cn$T䇍"hGpwi*ujHftVR-FKz 1k%.& (GNKp:p '4:g[/MG%j^sD!IxmrF /6q$ef, p" cB)0af$YRq:ֺ8Ɋl`bfmkJqՠrfx<Pݣd.I~P](pĻ2$C[- *j0ӉC~|?{~o{|Wo,*c^T-A` /jR@7bhd_cƇ7^]KYZsMKЊj𱶗LJI<=HpX?2=\9?+zy΁\rP@d)ٙg(-hO$0#8-:5x!}RӺŢ+ Ǣ4`t P0qԥ Ȅi0t;; G6,b0'Tze 6mj'NI _IzA8 &r"!W[2[C-XZkZ'l7&5l#YiU rͫ'>T*xit,l\ܚ"զWrjG*KVm,YfR/\ޙad6cP {Q9O\j4+lE|.zB;On2V;U/4c u-˂՜ͦ >=<5+ysd@#nNwq6hz-[^ŞkˉA]5MPQ1 1ZPo?E6B5 q h:YP-" #Z8eZGG#A#FLrР "!Ε'y;}Ge2X=j4 ruÕ 4/%A쬶lRW"I<EҾJ/cN[t} _þE>S;S~@->ݵo1vN-Ѕۨ\,{'@l{w B%%HD# ӱ2>,.j - S{U8ac*kש # H+5tdeasD}޹ri%[Q̿{SJ <2&K>[Z ,ح]Z2y U\WfZ<‹;D(HW f pHX̤Ts"Ȋx;UOD}ڦ{)XXy-6 (lr)(O'oeV0`v5ULHi`̎tEH^`56@ ;[\GV3Y-OO82sDdY'=63tu㭔"˫x)e^D#8';^ͯ˝K˷XcXe>4<7~\Wkf3\1I(;ӗH ip4/[<GӻYo)#8tƠ/#ԥ/vZۍv_&agӢ28g+}%3G2yai'nŅߟV>qg4!喇1l93[vPH-4rtY#=wB=L q qMMkA p5$af,(/}E#\ȏ0h;?b)c?I[y#7Ef\l9]>Lm0H FABPc^VI~`0i޵TR(nh4*-+|NH\;;}t h]ԥudPASSrJM9ͬ/]~[RP@Y˭I3 1Ɗfg^k9.8p)CPSz=Y܅2FwYh]YaA^]37N`@}b4ƭ%Jdw.q@v-=SOBa5vra|Tx'ϒ%~\xk>^y~ގL%Y>C }?3Ok ˧=`xI}nS"1XBV(ahr6 aEgC^֐kg*Jj{d1$."PbQq1I@(`ΥHUKZM4C0 BYɄR/Lb%y@ z`_>ȫnl?EY|H{WFU~wΠKGjˍ`*µ (\?Ir|vw/콾6L=qI "!# De7Q "l5h94Ut ܟŜyn@="Hӏ,_J$-$Ӗh?6~?) 5287|+TckF2ĪD4 J@ P*H +R#eGd"(Jo%@)(P=b^kM@0M( z s DayKuEԔl ~9>km\QAIgPji|k5 e+́OoPv·`.)Z즦qJfgYTNMDr/ѕ%uJ,]%x ><ꕖq:*fmL BPxR8_N3C -@hӈܐ. TxqIZ Y'!HP/dte Q]K J+i[ (|,} 脨-Ӑgk/ Ks!J(T }.)(&֝\ ̣J M0ZqbbST6 B CtZI?$5Op=\LE(sM B&JМ䡶DO2W|Or ulA8 @ .@!E Ri 0dIKE'Ju¥ b $Bh t)PJ!H4m)Lʇ P ;C@t$dU4P:2'喕*9eb JC-c͠d T‘JJvܴXѹU\QI5Z[ujl5EW-KRFZ{`wBBx!JGTHk~PDS$: M8J,j*`9%0 A%C'j+bڮmS5bܤUV\lRVkUe-W-rɴhhIQTZknTj#b֋hk%cEŶ,6ƺ[\ښLqJPK0V*#Xڹ[sXƪ.[1jZKJ f`H1BP8Vb([IRDviԙ |O ӡ'贇5 @êUP@:EtK@P)*+۔Wmr"Th6-ۖQkUwkW4W9ѭFFkH$r$@'$&eXhȰ[Q6-m-E BM\*MK.k'-k(nKj)5&hڍvU͍l[rhn3k5r5$F6,mBXX`6-Fł#V65b,jFصQV) űTTXs\̷ەsvVe\.h5nUFkcjUr[E)Q30Frr kܹlh;v&2n˥rP0h1Lvmn["cl Pd@H&B jr+E櫛W+ŬnչZm-AmEZ-ΔV5rkh֍-hmrh5bZZi! 5cW+\ڊ-cV6QmR@YH!b Cfխ⅛ңsW-H[*ƨkV5Z6b-QFbشmEjZpr͙nj\njZ5b[[QY-ֈ71ڊ-EQFTwv[Z*llb(kflTm6QFj+hV4cmklkAEm!PTEX֨X[QmUƣhT%Vnn55sb(6+ZEձŭlmU-mEmEEbEQm5Z"F5hV1FVHU[Ƣ6׍ȴZh6тB(6آ+Tmch&ƋZ""Иjѭ5ѫֱحFUA֣j"KKcb4S6بѭcEHj5dě"jhZ-mAV4Z-W5ţhe IaB|crz3X(B44,mznmQ"J-bشmMEj4jѵLZITX l[Ʒ6XT܊Imlj6E+TEldƶ1Z*k*&ޜ֊-RXצڋbTjZVi@(QQb(FmTlV5hm1kPѵj!6304f% %67`B qA,1:wTN0P ҴJ!Z-[XcRU%V1ZXkQX+b+l`[8/C($gl)*@!B$K ,H*EjHaW$0(y`b)5QCl( "P >ӫ7"WWl7m|m0)ۭ6}ǑJgu 0o "3qh;VQ(qGg!I'!R); Tiz0$d䛑pfv7u1n&RKCc!IL,~Y-ڃAA6:k89r#>oOQ;n7!C\l5:/7WoN<( gaaDÍ0n]Z` ? _`,FD-j}ԗ՘!O3vd~{C ؒ,u!󷉇oܼ m rV8& tXJ?)¹,ɅN@G51@Ү_3Rק@[~8 0R:!5ڒ dqP7k. ctu,rua3N% jV~Bt Z ْ1w~)i?U;W&Ix`] 5ugo͜3~=N z0VI PQCl[/kg#2,.Ns:%n=;^;]pszZ`Q~4vzs(@(8,4WxYϛx\ 0;jC; Z")նߚ4D~7εվ/CYQ}՘,{}|& M SKIF9 z]!;mׇÎA-~:;z踰r&_jor${\=N/{~`A(9iXF IYp-\@^ȁV,GOlT?#Bϧ1 Ij>̍h7t͂BB0du:>{|pgLvpPB` ')ZMŲwd|np}S{W0ซWWC.Y-uqT(C}8vILsmc.^®ʟPgѮi9:evh`ws13%*i a y_i/b/g,fsi䵚Lw *+if}鬒>xX_xmcxN[ ȨOKLׇi B=f:>^e6gs/k: MH^ܹ`1X!5W]zi&ѝc R_r`ܦY~a/IYl8}xG3Z." T3(V1Denɏ0n8oxQk~p_<ʎ1Pzy}; 8*s0y٘K>aftM,fS?WWs/̷]gpybNCHu y}oDg2o`W([wn+>ǝ9>zַ +vg6X +[Ƈ[gmD,nr Nj] ~}mgڻ[80q8_^g57#߲]e=Nu} pn䭌4NNjG6r9M7MQ_vo)Ӹ.[Abm|ݷ^qz,O&pYں:`_fPNcj>؏뚂i[ʗ{']q}gyO<< {{>:!I!&cV@=%G;9b\5nQԂ&q>/Zw L1 6&׉?o5JKY}A O73qׅN1jmOsP 9@!2?{X!`&p 'eY' P-W{&|@_m(QM#G~_)9`)@‰i8*]ר)R?`} r5Ƙ((3)j $E( "c`J̈́_̶Yb?0/q2TOt L֘ 鮡z=@@<0/3sҨo/m0Wv848]gVVRc{3:oxr }w*0@  8   /vr5oS"$v  QaWrHs,j XnE c{I[y/A=;2G^Ec!/~.'J9jRRЄdD&e^b ͕7h"b}D 7|.Iu=ܪ,B?"Bu|+H+Bယ5[=y74H2u;j4_zm VZ D(:)oSx:LZm)\c^oE51?{OgȂ K%(A鹣msPѽ[*lqzBp|7Ż~t=d[ֹ*1eq+e6a3䠺K+˅ZY?zeo`T^Ni6xTUb,!(bFHV&;#YPe{V P E!4BV~h( EZ@ū?i  yfO?pʱ@\@q p b({RđXOe7.'O _c7nVEOZۿ4>JwjVÜ9 Vyn;>bPA}jץX<6&d$% ӐgLLD. t_/7<.E.HόJ)׭[8Ul=9FݜzJ{JS @J`Y}_'!DL:WU7onHX%W2AįgLohV VHߥU?tk +@laCuY.j^"0[ouyr^.kYsDIIm.@ PŔA 0 UqnH;w#5kɄkF\ eVS {|hX}Ow-˷!3Ѓ ZެMeB0 ! 0Mq'$BdWk~=ko=3Ewc_;/:щ-wӬy\X /wd0~b5hF,ZCFtSѪ~i8kP%5#& jiu.D?D[ipzz^~(f| @ѨLi#ņٮ  C<=^}gqJAo~2N]B\Cul9ZW[4$VWr+~ۊߋ'db'ϲq8\~ـ~> Qf1@616OG0 i1&LnFbΘ;XI?}ii| LVSf(˱2t ߉O:ጄ&sW5 mEzi*hhzKʰ# k?I3瘇F>'V_@@gP f6hm9$3zrWͺfGq"$Y?7>Dt1ɪpoZ8dQ$,aˏk6Q /N" +P)m0`3ct4K '$ T<:V7I'wZHv2jR`q0:Sg'XVt?qC#w @ό_}ї#]ݭL&BԄ&/bW]g3b@D?Sx+KzUYE3jΣjvz}\g LB""1lH B2R?%@>c i#Zxi>&R:՟gTA#; B+haJl"gHQty;Ya F#H023?8]͍ nz"~wg[3ʶPDFay.z$<6=6W<@hԱy~(|%{sC<~&, 6rB!+M?`L%}R6^mhVD^OkD!_X-͇` g3n>Kd5[;N H|}W .ͻlo`X}uw2r=sT#S>BTUUU79-aG2Ӈۡ QT~iZXdff;d#󖉡yi2<ں 4ߊqy1o Wgg\8@Cw6'H>rbҵ|MYD*й0́".9lO\Vr'ٯXPXO, ئaijLE#2Q '0ɍ _$bH^N'sܸMy52:w0uCLhzyҀ"sԆ?OPd#;YԤC_Vʕzԗ6_F$XF KnH5g$|rFhZZNzt418`}Tk#Yj,9ڳXo*g֤dq4WaW}TTl6Jo=;@cyr _2kL"丂ϽwPxь։`G7eْV@ktԝ[v AA>,cvvڍ]QoscƗ{՛lc)'wg5O[ i:we3U;Boc!Ŵm^ gV1^XO~w꾓`앭.fi.Nu&q>MBj!jhKFiA6t 3Ѱ}&ǒPp6]_O`27n]gGc/G|2e#r2wu٢\A to6JTs\(ۦo/_(Ei[?y{ pq?O{wdS`~q&Re)KΠ<6d#QA[m 2^?h# *EH3ɉ4Ql^e$g4.rL  ȠOo_ mYO D}TU}Z %x%q2XDwC X_Ws8a*NWي~?v趉h%fnwڦQ#9V,LLleɋ wob 9Y&G#Y~Ҿ^ mEљ"&1ov5|=me:kCC%,͢ KM[e 27E9usufb,^(LϢ Fu&(mz‘Lcɤ@JۧbtZ]Cd^"JYִ/ Ё( Y8`ՙ .wZf ИjkQ@ŌɛBdCNhg VRwyDp})e $$s [~v#\ڮ_p+'kgVHb"5SŲ&C*İY ^֯}9t"=5<21s I9`\qmIPvsMf7Cƒ&T/vMsxZýV@jtYjտ E7l寱^uKZs8PL({O89 aFBM>Jc6JeQ\3!LHEGƥn&ufNDsZZѥ~z U4* I~o,<jJꮍ7ȁj4;wmX!Pr,b57 #盬.S^ KfڧlzJe羪,Nл\ҼoEN0=klCpl9q>71a{/9k3 !>$n#i*A jPȈFi:lĎ;9qqV*q +%t{HƑ>1"?hrydYDLGOSj PqB?Y!S0x䢗ʊO_i\"<يZo@ blV v[`.صѣ%B94csh{07n~ށ!t,}S+7" } V( gY)Ӻ-r>M9 gTQTń< M]SKUFh @Y2~S@4`R+wkbgZ("jJ`Lg13%e-m|ER׼b9n7)A&/cbqa#NN'fdfMmeK?Y78bH"-̰ %Q(3Nr|(7:F'?8";w@1QA ,`x!#G.J a\sǟKӴlp(i:򽝐?J2yS_h2ae1L9Dx-k׫ͳT-UwD:j(!:-|LjX|(hZ]HdvgwP{`-JO+Y]L !-D+ F5R{BaInTm+5!@X!-Y3W]vё e+ F%eM*-0\_a K1DgW:dF_v)/~J0(EҊivNji_y Qߣ?aT0 *p,(r xZOΟqq Lg~ߖl06oߥ*"z$}5؁vdϷDTܖ(DaRA}jGe'Ioɂ0Z4,T˴kW;# 1X %![2Q4 `qQE<>yL(hDA438B٠sPƖ,E3_R K݌su- IFe-I3v`@,Kc^lJN9csv2J%jɂV > Ya Hb2؈`,ba]BN鶴=D @g&L@A!7_7;:+~n'f4%ۮ\kSMHÒ쮗IHk #%"h(c:_zx#H`KLM9F)d+ZZZ`SzB 1Z,L ] gOk$#|wTaB<(yV#4݉9ٳwI,ƠL^i.Ha|qeo08Gy7a?F<1(36Tt{uɇt MibgҎh[ Yxoe( 1RA5 %[3Gk,u6:-/Ţd]C6ɲ(r͍>t=3;|Kbnҳ|$,a4Z[J" @vDJ !+ɽr BK,rVXdcb+>hk3unRy<0D z.) 0dQ$j͐;ҭ.{ cUW E4s 3!)ׁka"+UR`,s^Qid GZLbRռ1*R$Z{{@u.w7Gx+[)٠GZMNÿxM* ]9}aNFAEU-Xl1\H(!ă_ꡉMF>5?s%K FQҴt;R3V$ ,C/cw 45*_`{c <&cȡEP r#Fk q%+g0YKiaSP. ;y@K<*vѧ%ӷ8l^"m@D_da|2[mYRLNJ~Pc Zsc=Z(i)CB %dr?|yw˂;\06A\.`- 7̵&zD:*?ZOi3RdA x dHG;gm0γq?zN.ò@~9i2bc3J-J-% "PdEsqjXL٩)hC||@B &1J fFI4UH˽ "%TD'?J^C+Va+q}F(HBbIHbs@c_#1/h:tX KIqIMNs|msTӣă&tEz["\Cd=Q[t pKs-UH(D.B%SޖYS$Ү;*¨4+&pdJdҒ"%*!ޠDn-B!eYܶr츺UfX(TJJu(uQed~+%\̭LFj o췜/=w40ɫr,54h2_Y|(_V‚S&]jq-A6b]~S[O"%<;)o8ZzE1z lswM%WdX>UcUC%hC@(JCFR:9k9 (g3f-a6ѴzK_j 'B0lcȦHeKЦF;~>dIt󹈔z &*47 nF`>$aFXΞtdꖯ8T(B,HsIW񡄆b#msJ)\'M -U⮙լU0Q8E u{.uڐ͑UqY5ipE3EU ee"Cz@Bіs`LJ)2̈ "h˚!X (D@*S|, x6 Ek4%,Qn* P0ϥfW}VMR#Ck̸ 8ţ%0ԍ;cqC WlFC(|&L9Mʈa{TҚ1[5HL.|iPoy{YT1:!oyU`᮸', ܠ u֠DgY[0$ 1Lյǥ-"c R!n"-kX-lK-àD 2gSO|l[m yV9ȩ`!@ng]IlB)3&fYBUԐ`)"rێަ' \RYt_AJ)$f2~$%Rʴ q+Y !C{+ȰR˂% 1bg` 1tLO"3G9vҶUGYA H&(9QCMaŒ,bor&,c)6gj ,:w MW0(ŕ2Uq e"mȷv0 ж|cOnD(Vn(qBwnayy$db=t.dչ tNCMDždc;+23}|>kl*iv]njPLA|aO"ɦ™zsiشqʛXIFڗ=Qia2rå iPFhZa&3,Ȉ^c4r&bE$Z^xL h)Jr[g)xDOri;%hWx6Ir`JYdD5ܨU"55kB4[}<],ፒ<#`+p&Jy[{D F .8 4rQ4,lāeQW烼XE-AcnwKDC*N0|K XK Iy*3QB& jMzJ7{2~}1^L$.=l]dmXvuHgݜ]AV(ě>aX-qaefbF>./,5iEQ{=V3 dgSJv+Cx#K3;~Hs݃ZE<cRqXHQI PX+Buw:vi\0̺)Vu,+,*fh؄&@ƍ%&n4NI]r45{Mz;êCz9g, if4+Ҹ>D(tڐ=kY|Gl&ҍoK/9|9Hҗ$n@@nMn_9&UO@6R,;<.Vd&2 w$ėFzk\ӐڍajxM}8+`h3'jlt^ظA0wi,NZbٱNaH1\d,򖎽ƀBSVt SW]711ІdY״[/p 0DCbCj(g V0)7Ouzw2H:ݖ&ҠcVR:гm2%zŸѮ75>r١Q>;N%$hѓ<6#[4(NMO@N@Pչk\e!j5&9%2C@88^YK׾B} ^*Z>u)ed@_lX Tl֮.8/$q;bF( c4I#({EVT=Z{R&63ޜ!dߟm[ u òwekho=j>oUywnjP " PRpcz|H/;׳*1:HX G }_BV,J'5J275,Zu= /oA O?"zZPf~ޞ3lUJ s qɤص:%]zuq$HFOyFXjjGH }PZ ,dG6ޏ$ӯn.ݗ"~=so,a8[ln$fe*?oNfyFADȇ[3mU$ 0! 0 0 j=- {(_D`a٬FCd B+RDͿ!f[u,X5Vˬ?g72~ٶc"lP R/YC7pj(ԥ~XAVIZGe$J=hR8 9(@ژR0{bYlf/ڜ%rE$h:"B!zOt0:~xpky>}'m}~ϭmrH3m? /z0IOշؽV;zg<\3Zg̰!XGz 36x:\ra6H |F0m62!Yl()J.VtN-exʯ8XBP6c} FU#EL z2A*[ 5]GU=/:C]B8p']~] Y_9 Y(8"/cίU@DsWZ 'cz,+=JkG]4er@_NkzBr"t0?it7mf=,eucwGG$ @&a78;6ߒ<%饭K_*QFom;8o 5ׯ+qOx&g%ӥh2=P$a?W8cɫ~UY;Y#rwd.a9sESwmikw_]cCZˇE.8Z3Ož~Hhؘ)5RjL}s}}ke%&x,rPAf\p%%2 O%?@?apWnABieb\%ny=U-5d.9xm*;{Oo/dkCwF'jSM@Vm`瑭C.JRhHͩE Th=a\; qzL` 5{8bnzY39'u:oq"8p4 EjGQ~諹2_.xKݮ(#c& /ɖOd9(p#L.+Tgm۞n/V6jm7ǔhL}&Ub`ݿ+Xg|J}E)APL*0?J ΢+pF=[ܰՃ*zGJ]-t@Da+0?zYm绿Gٍ\NbKQo^1X77䎃kOA*$%.O3Nelo3y|mPgN9?6O ^na@C 1;2h6k14;s>] 7_퉁)p|g]W)CkHjJ6h{Z?nAUOo3)JV@|TP(1Uٵ~Pp:լ@DHgt9.G℮x22|4PSH)G68v@ 8`bv|~u=Ή`y{ćJcMҝ}ug΁v!8ؽֳ|>+ͤo]y3W}u^q&JC_qYb\[`j |VUӡI bq}+#lӟf=^1Vc/#wdb+y1xBt8=Grg#5s<&CvnxLl4Dݐ2<>Haxd gwdfUN^ _Ӱs89o j'rG ǻ5CKEy>rLzqhp=ߗu̻Iu~ͱ|zS[s!o"-&MjM1(F^kS[d׮ym=e\.CşYH=Ǎ%).Os>u!f:WS\Mu%iٹ3y~6/#X7Wis 2;WKh+[eȵ=I*u Q!_q98DPO0LYvv|&řI90q&Ey|xl֊=V O.۪)WL#~ 58!a8| ]hQyL1k׋|O"5؀1@xYG9z&ާ pVW_.8~y{6{n|r.ZW:'x!Yr('[:={N2Z.YTH= o'?+H}lrQQ!F̎ ^r[\y\%' L)o/ߴdEO**E1P~m輯?}ϰg~GCo zvo3m76Qm-/{+.3@H V{oJOo/ fN.?[}7~t4X!n2E \KR^Lsc5/4-S8't(*^ejd{8a]?tI꺴s?]B(993)g@D rKbu|f")J2Y adb?q z>^)Dopg,+%Ӭo𥒽1䫘v2?Xiܬ_}h BcGr|E`ߧ?Fqd\ƉR~dLϬA9Sl :}j{ջ'#2&!/6aAqP{(MAK Bی"ͥ-w %jZbUT9%aA9+cSZœ`z4g30-#SÖ@MԢs+wbWJ5Zc~MϷ'gceNٽQ/WӶcN,Y+Z +yy|ӟe-2s5K ^n` kGN yuM})[no؏N_t% 0)ty (q(•7-ֳAy-^\8p CD&fk:\d`*{sn@q[9(4'FShS٨LiKe[޼/@>S[C}w|*dvڜkv(ۿgw7E"ND4|~}ywDr?$PK~joԚL;/|w [=Ai]:8GNFyR0?#?+d %J %w#dIЂ> AHM T.zӮ&ai պj8cޫX&}mNM䗘Kda˷knX|uФt,㸘H&Wb^.;{IyMZw{+4@!V߾#2jnF3fE}|ˑW(O1ݲ>cwb1Uws'޻}%gO",ne*mJB^۠we߫p݆1/M2ގVQjmQv}v Jΐl!UH(9\;U~5 S1`Cס-?A-͈k*A$=Q_=yB5k0BlghgMH[}R6AX*p0%Bm=7q恱?̱o"fhb Giz?tBG$V(c-l5X s ~x⛙,}?Z$X&b1TK5+,~GX+z C 8i%cJ9zLٯz޼sɓ}%h J\tEP_[e\׋Z~qW.ךwO7;SlU] ?ofv z8}0q)3iےԞo,&B2\% d*=麕m_6`ZྒྷCD~f}A  @kQ5+'ߪ8teg/k;`lƍ1!/#_}v37RWiA1G֥+@ (HK@NJ~54&K"џAm2X;\0-{wÇ˟^Xp2o_.eW"nᘴM:)(Uv8=ҩ~~;Ұj׭cZ=A<`c&00_Z|B# H! 6"|!w[S p܁AB{W,ZGci*BB'bM>S#5ck6TBU[ɰ _`5oG8XZi/60|&xE4[mvst_hɴ-%I#1QŞ^҄o#Nb|Z<]+ h(rڭxYD Px{@0vkX.# /lPJ)4{ێ>z[ِeX<"z% nR5?b( Aϐ Re.bfޥ,Ro/.yH_qS7sA$V/,9 .sk >QT teW#2iXuzJ}?\?~3oC}W)r44o|Z (Ҁ;3=ŋuv$6#S>]+X(@! 9} |Xm-¹9sR+M[UԾ/s=SЖ}=xe ikYϸH o_~3p61HTZKߏGߟE4%"/}k𿽯w"i#Hb0*8170JA";Uԉ 5]%ôװ~=p>/B6yjhqe{o.fJ}F4`hmJwRV~}?lZn"7ˡ( @d8E9LHsO1((7dL|s[8QxjPl^O<-oYUCU=McU}V; c5͐ex{4gz:<۵m05! AO{f򪩰ѼNDYX;\2+6\nG^}uL%~lb iGп|Yv'3둍(Kg_:۷ )h*^ϪݣTvɬ+Xb1P]-Junȳڟ͹ q!,|w~'y9f!Bÿ. wwc1C g鏀j@[Xwlg4Km380EP%CgʎW`x6idK6>uWlmT w6ϯDE 30Fٳ[N8`f+sEU&$wsݮ̔^Aqᴛ@"0A@6xP>?4RSD1<0XƫQkz M|]nv,m8 f!sAMyyz1ȡ5蓒awLa6Ё.tzB݂wP"D_՘y  So Ť/fZHAɫK2PG 0/ m|&1QHAEճZlw׌x[h6Q޴]D8?V7=c SqwU42<CB .q,o yJ#Ky5.:˿qd2ǚ1jeʘ'-8t{w-,BqA(@(`@;yHkz0p”> ,l?OkP{7.}o;ޝw|t0;(^)C7}ٺȸq! ~`@+K3ǹ]/s?ng;}I(^L4kSAȯ5uٮ0w(-1?<#⥗dL\x2%u. 0aTk{e}n&RfώA %ߟ:%%OhS1/YorT R|jVK롁@ ^wm+*E+>j#'L{RWMD@|S` !1K_<7_$3ݲt7ӐoUgظ9=B?;9هB",!^_$L&n()q@ga@*+A -7 9k pǸkuj AzkA9;:uHĨuRkbƳ)( "6ح&lj Pш 6Q% ,0P&goc99)73/}.!D0!CC@ł2sR9_0%>{/e矽rЄQ"h4Q"$,3DSb(U?AEXX1sdsTcM b`}{tQB[] 6|E R~/E% gQ͛kW.:`nmd̾{җf' aWc{=ÞV4ʀWtcn<0djPSzM[1cW2L2}I(CyDդd;Hpdjz_uďGe5ġQ HBXh*`M "dF6ɨclV4h#$PllX`c&5cXS+%F$F PQE%`T&!Vj7kJՉvDD:gw^9yA^;W Խm{2Il%64f1QIA%Wwn.9^E"{ud(FmMEѭ&$TbMlQb%F[f4I((Mc$bQ&Z5iJ,j @m$4#Y(FQIbJMHj I S ĔfcQDɍ`آFdA&bJ cbD1QE"AF4XѨ*A)&IH ("I1Em3QF̊L3,)4%$hfɈcfm,-"Y"E5KQIbFLa4D QXQD65bb`P%FhhLXS !S5 FŃ%d"(F!Bf` fa ŲbY*d@ %(TCIF""#DJe%ibƈDQ1F$kD22I%F ɠ`+Ɣ0B  F&X0h dU&d3J!1&)IACIF*1&! a),jD (h$$#1&jM`B6ih0!hPL lDdBLQ`RBS I$$lELZJdFY(Dd2IP+1(HԒ P Q&@6aRhM*ѡ5!A()bR3*JBH e4 12IQ"HlAfm!V1((c`,LfV4i2mEE1)1JIhIb4 1H""56&QbQY1E1 EF5$&0Hb!#S/թ V">TAW $g&aTb[B+e3JWV>.ޠBeXi()kS?vi1]ʦϓgJ M$oӁGx_xݢS^ijEiH(50;=7ڣP?=[qɋd;7tH)H~ڱ փk<Bb'z?DJ_Q"ɞ7aaf;NQ3g=u B`01 FݏE6jIk= ޓpא=$A(+3WTCAI6@PGއWx}G~sHRjko<{jJIS}?gS|.鲀u!P 5w^`ot5D:n:>L4W6Zx̛ _{PZ6.?;>\t`9)h8Ŀfϝ̷`.WkAOAdD#C}gOFkWbN W;)5ٵ5 29C@^`e2!0+~ՏTC/V\ @s5hZ0cǑ ``*{T(B ~iyMި*;kx[5:=qCʪb$$Fa?6_~Ó!>@P @qd;"nW3=(EB#d3t%=<ݟr0 pa>rΎZa.$߂tng^dF-˷h0浫˔`])"d ~AYE|Cs=[GIMIBl٫*'3s}G\OO D=J '/X-@K|saoV(ce0P_PrEvK5,&ÉǏv$ B"HW6#530 'Y]ǰX(H&P`1 +~78"DH`H}9VPl3lm=wNN~槮p}bTX 3hA4~/S߰>Xܥrvp9fA!ҟlI<ۢb/׻\ -\_Q^|vw|}3f̐ɛ(S~>w%=_|?Y9GLQDX4~[b0T3Acb d1xPcE/&XZh{~{ kA,mp˦=@G%:Xc0/|=]BȾ F*| _=}vDg'cLd))]+ges^3 t:EwmA $ .uoyB Q>م d u\-ecT2MozHMz}>[L#80Kg}s|_p͗hF?J9?KkqN5x~,}Aǚ]])N)(Y1\0xCFd,(AvyW̧<c>$p}R1٭o/ɛYKFgzTI kPzIwKug%;IؐO c[E_qCXn%C"D̙,V`Ԇ""EEcsw]& Z X5Fn= kG'gd h(mD_QD.3%Yɀڼ`Z`Hu{š)(Ftq^>l"f: lv} f|quJÚ栏'! En,484Oo;? ug9#`: y/i t.s7e8 o%VF.>!/ vB cD]B@*v'_ՊB!{<:v, ~̷^>ԭQR2 ZȲn` a~\h^lx0J #{ku?#Ւ>Jzc[ %'3)d/Ct66h9bWy_Bй>oi"qO/f"apSHhқPšS[][>$_+B}S5~c<(~= o ?R4HДL$01Hu#ʤI }D9|uɎ?kHMHFu@DR@l~Et+20&N, ps& OD wzbLe<{!-iw( DXCEGsI,4Zgo [00B F1DhƑ((LiXؐwP4A%(BQ’Dٔ1d4VH(#Xf7s ?W_L9b^x%AΎ=}p=1A a*}|%~}vV0KB(Nin"2]Y2?0g*[}>E!3@^C]I[vM ߉u0wn懄Ϋ[Yٮ4V>^Lj=KzqC:CИD͖yۙ[(g)0%7Cퟰ%s8YGOtFkw+s^gKh6g6~qt #`=ts"( ,$m"a IA1ǥpo^qwZ64haDD @~+O}~,S-4P02L3FKE31X" 4U! #L4@B"$&f64P%5 fT| өt7kIOyjF_}n$ *ݴ7q>a} o~N\ߓ Mxrd?5?񛧼ydY3u/4KÅ5ts0o| *j?q<Y`r u !ӽqPQ"s3b/ @ظ60QFkܦ]aˎ<ǧ+c|s0x Ύ?Ah~DY9uy#WYk߂s$Kos(!8Wjn! d=SIѓ9Kb2V}WɏAXm ѫr%t`UT9sY\ЯC~el<ۇx%s[?#.|mY>Cqi4|5V9v^Ṅ:T\3tx$mz~ЃjމQ%#tq-֬ ,نca^>/ ,±ÐW.?eg# vIFdAO"zmz,IJZ[v#Mv}"f^/~+7E6L$ 29@ ÑD B,lJ>\I[ =2: #x5 7@AcL{w1ph<|,.(=Y14r mFWSWBm̷?Sƅa$`=uJ"UgrFs8 <#dX@8U$)K{gzk9(O/,J ^+R$2&Q1L)C@ )4hR[ !DBTZZQQPثG]hHǢ/]\DDU!&XԱQbLfm`bbJьc5 Ơٍ166[#LEͶbWN3}({mx3~G99?eIzNP3UE%b +/^rb(_5`űJY{oյR L0SOȧ%sFv+\"#'< Y2X5 J`?5hM7J>x SB\ bZ%bI7|}pqe#YW_=5_؝yU$TLq 8`mFɈ0yO|o66;x>wW'[bO|ճU7nljCꡨ0CUjPQL^2>̫"[)/MLޞfJzȹ<$@s쎗) qhZry%oz&۽ZENayKwbB!  !7c{ެ*Hr;t 0!@!cc B `Kp<Ÿe߯>hĀֲ?tjZH3 kor17!սsOGI2Y_ 'Lv$W&Kh%՚CRkyM!f*JoyHߊ.;,(xxP;6<.Dfnm%IuD?+)oнJ(UsKQXU3` ~8ȱ4y#JМ(ct˞#iw?<>PAh`ީ~p a?j?q+P{W{k3vvvwi݌DPCqӱF`w7UE6]fzY!{ ;3wj@{t 2斯2 Tkgr5ڔJлxETb%@k@'NRz<׭2|ڦ()EG:Y@c+`2__41(N>K6z'mq-}fMz@ 4w|W(t>@t"+XbD1 [tlzx d伲~L)}:D.\UNn'ʙ|9}C"xq,1\<K.hgCKIt)%@-΢f{K9bxiJ[aw]22|AZ+Nה"7mz,Ve"gv{-^_Zpvx!Bp520E!C@ $l@&$0H?qJ1E(B4fd@}ZKǝ44ċ*EL7yiD 84\+dmLױZ6s3hivW޶¶.)Dq-L[94tz 12|t`62v:g vsj*rHY< &wuD0T< ,F@S31[ֲnp@{ `M6vo94淸rۋMnQ{C*-}jмZ֯byVsmO&ʃ.GORV͉5T*A4i)Af?/S,ЌMh?}3|_3^Q%ư8;OV{3F&Ԙ_b5+_-K 8sud`$1t  `i9$R0_nfrGk\ 鸖X{CIP2))a+X/ ez\^" H!s=gG)omp^u~_5`j ڬ-ҧOefZl0Gz< N_ߚ*\y?tS邌;,!ى1BZ.ư(7W>ѝ~nM!]q<{ظiR|7LxP>[VrwNZu kHH嵇}J5B &@U- WA}j\~V76 dzM.slw̴c"_6̩E_UxvsCLKP? P;ynMZ}Ys@M^[HzGjX~Ƚ/;w4 X.cj3oDKjjWYي`/Ri}↊ hC&w, ؜K>JtBh^uStڔ:dVgR!1lydnVpeVWGY⽊/^FT. &ߓFkQ0=*9Of7RẸ%Z@&lkm5ŰR $"j,$ARA$HK4XJHȣ0@E&$صFB*+QDk&2&,J0 "LbKIC2A%"i0bDDDLHQD?O}}*UUM|//=LjORgNoDoCs$f*$8 B6㷼'qjTGCwW}U;qy=IN/>3Aw.(ɇ>/Ae~{%Lѣb{sU4O;OD׽=Siyb5_Ӣ5%.yH:Փ3.T:S,o ɛv hMh 8;PX+/uŞGixv4y ;gt|AҔ[5ےD#ۿNG|t(g;Ghʭ\ݦ\%KE똔WPPr_hގçVtpr_֎Oxl֧i8s)-Mǵ}~f !k,9"%xLY42[!'\?RSv8>'L-ZL꽹H|~O9"S/E@8ȧ XZfFԢZw9ؘ3488o֗W|}+j{Un&(;o*~*%nap‰p Z`|sh-&f[Xo0 <]~o&6{;4zYZ&“[=xWla Qّ1e%Ty6wpfZ/_3[*/]M3j #Favvy m!m#\}/(k+<0h ƒS>Ӹ|0Dd~ %$B@0LFݵQ,Hz"4zP`Jf[a TREF@M%5)6e2(3"A"&%%"H @بdȆF&k[Xh&R0bR5`IdRh-20V ,&LRj Db٣PɀBLdIFC(QHEfF%h dI) 3BXP4ABA&&1$B2M,JLY I1i̐I"FhFbX164aIDbh$Qlh)3KLTDLB&R`),$fJK)DF&2)R"$42H#&j(dK$b( ""ʓ&BEe)e2f&!be 1`0$1 D2E!$A ɠ"# "6bP1"DI`1Ld)#10#56dd)DQ*EbLXeXJCMIc $!"L CD&+1B1R )A RM341I`1LT@ɉ 1 f&C%$ &biLfh% 1bJP3DQ4I@( DK*&DIʑ$PbЁEl$A aL6fIȃ2D1E2II6`DTf$PL4 @D 2e"LR!&0&ɨ3dfDMIS4L)(LD E" TH%4%%P",a)RF1$4Ri$$ )f)4R 4 i`2haJ )4I$JSc2"2S""LE( `FF2S(!a!1L(L#&QC2LC2B@Rh+ĥ((kf0"`PH,&ﺾĶ|[JyCWspy-L>_2GF;'Z.x+h/FI-Y/Ү f2"^ 6j*äN.&4Z?tzT#p"q[eB;S؁H` tr7mGF'B1)p]:J_o¢onr\L^#3A^%u +Om *p}ɿ1gCaGwQ9/m׈|Hx)̿?w#"n$ }O̦1{֠})  4GQ XFjĥ ' X 1Vlh@ OӱjPS'F׻sCGv^K!`rz 3 yXY XHSPD>O-Oص0~ +SA9^Jh<Χ p>M{|zRVWPu{^Wwp)^]4핹tip6'NY 2FrV=[F#C-g@0G|<f#2jȾ2Bc _`M~\W9XLr|j0Frt"搖`ixK Nc!j8(;&w`jb\*` I齗{6~~yטU+"l8?]^]yvvd%)jߨ:E2?տ鷉w%AC<{> |ߢpV͊6Ha !1|EWΙ︿['=XzEC97]!/vSN"%(+7ց&S029 QԒ0{w%=“Rw_UAתl~P(9~>7g]h|fs{0լE^h]n9eg'!n?䨉kbKT RmYQndJPR^WlnfԚ6XOYJ-S{3jnS$e#])rYkdJfh U X}R\f'_bËYܸ $V{fv;݄BHl^2 )N⻜,Qdmvh5- nS&R`+zY828L{ KbxLky֭rA8F= .cdt}nMY>MZPr=;25LR7Ԡ_ 0ha}7?MY04 >xc*B>yݸK˚TWk*ˏڽ'tW5{8Jٮ22 {f֖TGH(X<; 0 DFw>T=53 3g?d́HC  t@¼>➫6G؂懖@7]0'jqbʊ!ޠb~me !+Cpp%JtE '&s tB S)c& ɤ'˸#M o56bl޷Wաhf/кU")$‚GJ#nbÁ^cq'KbNy6]L>hZY!Z~fH+Yw:d O^^Y?GyYYCsOmt!ռĀ M<= ZPˎ\ECy|7mOgͮcG} 8>d /w/yNE4})ËZt> ggy&/\sOk+6PLX@e7A:dl^Œ?cSG9p2ꋄPrAYz,v6\#_5ϋ1B M7l*.|gbλpD߃a}Xߌ; J@{={i`V7g @ά|a`v1osgW IC)0 kyq^h[6l9{gYc>?J aґJé4OVRCS̙Mşlڳlp Z) jzۨGd|{O=4`>ϒYw@Ծ1=Ɨ~\ nnx/{Y^8ε׍)3xO)p կtN_h"bhh94p h}2D= [,n)Dkvj7+HMLu>cS5#:xdo5^4[͌h:]5ɾa :ɫ Gݑ^H~D Skby$(,NlsfUM? ƿTO%~~VCff?jB?mewPІ厌 2B/+w5u;_D^V)YUaDvr  8=>}׿ѕml%Ǚ/?ʷkNR쑶[[#_N`([j3Yl끻Sgԡ՞ |^7{gy'nQS%~-F#b&3v3QPN,r_[mne-Ň }$x ,4$:lUiGgtG[p}Qv%С*d#ٞkXzC JŎ6hm6tV+ML4]1)FPR0PH(HDJdQ1"$ ĖW !g7bH#$=΢Q6F2%OwtxIYIi$1JL BKSXLd )II,@R%>QaMZ4jhY"mҴkQb6K$)M(k Q`(5F&T[($-&1&Zɱ`61TbQfk`ITE&&0j)AlU1/N `eaHƍb"Ұmfѣi-MDThIcjmEch5*jM)J(7^MKlٔ`U~݀.+_oU{>>IAY6;a|v 8m^/lGF(,ΠZWYwd ( F6-͛n迥.pMk8(2e[5"[CWa-=!De66فn4糝]7/t:݉%/9ȍw}%|䇮c$KOw*[-_r?GlؒRZORfCpl BpHY)h# /bPOad8!Ga,NiXPϰ.sa旷,sOCEKvƨDtybZ)Ea #[m˘KZGk/P$mimUoźnIIJV\XerX㚪>Hhe9ZWEKū?Qy> \^7(g nr hE/8JLn] #hQhmuh;W0@a]/ ZI9{XO$.'e.7E:;>kJ|r G ,e6VoqŔjgkm%,'Ja` OXS" Y'5gU??:dvQ"hzsfg$:g^?znEMRU q.<~n"~8{0jXT9Fb[GSpmNϕ*@.xftdPi_~EkSTY_ <'㊯c- tާi^OEi7{%.`&q܍MׇCþ+?M~_nzA$Hu.7e&IRE$&^~_^_bbb(D6+!L(2J1A(fFJ dJEA)4 ib$"b<&fKt%[7$/ɐ\~Խ+s=ng*CuzoZRn(VJq'5ȣaDh3ROkkT*xARV ͉ 2,gmƒ#m(~y5|E2Lj2]sPf"Z^1W ٗY!Z[y4rD` gn/'AKCRPR4ee@FCHde%aYUKTh+6͇6VDQrzatbᚆ D Co78V&}i[l'c t%}]xΌZ_f `w;e[_cv^\}r`)9vO5&9EMADw3P_86)@Yۇ-o_mwј=QETA%.Kc`ߘV>0F"/]tcNN$nP*WL4%nI a( Dۿjp {U'DY">6"A BB<6 =pNTܺ^ g^q)TS@iQמf?kt@*a@=/ckW[y\YO:葸^_H"OlHA"+VXלKCCa%tų,#k{^s}D2a X7!E͟,:}:GI@Uw;Wͬ:FX`0d9? 5];DБݘ1LcT֦'>Q+XJmoAj rbca@1T}GK B(Dӻ{_RFEEMY3UfjY]컪C|RchR ^:(@{・ߓ|Q2TƩ S0Ɉ0D$K+H*ѴRQ6V,i4cDdd4d)i ~'O>?iu5DfPFM,!!ױ[mӟ'_eg(j1a` }db|?dyP.)/{+ iʾ_^,*^[ G؂}V^EFb,˙jSo_!hȰw#h+J306zC)}Rr$ ۛ"Y\?8Qs*3U~o::VNp{ !И#v c.-[^GR|3dMv~ǸjJ^{TJqo(`xSv`9daDfm["fT%X1i16aF4aQ%S(fI&( 3aT1 0cE*caAIMC*bh"BDR a$fddČc̔) D%MTl[HhŪ4IR) DRT,DȠdT%)I[M#IZJ)2P4$Kbe  )0JD`!cDP & !)*4ФYB ch$l&Aa($& fII`3dHFHC,DL2e2DA#ad4mhh$30S L"YLdl4ILRIA"DL&fJLI%BF! *!LL 3"H41ꏓш`h1,w^pJ۞F$DQ(M1b2EHe4iK $R3dЦiLL&ĠIi 1Ih1%l&4bfY@hД%u LHR3!""a3e$A24̑&‹)E!0"2@44HcL(Ri adM DII@$ 1IIHI3Llz $FfB32PHș$HL0CdPH 4d $b!2""(RTaH&RBD($X4h$4ىK%lIJ&(e!1biQd&dQ2H3ibLHaF,0!hDH&^˙SH  IJiE(42RabCIH1("0DƆb;dLe4ę4Z2B!A$cM d&#A6d f İ Z( Ic&LQ( D4ɊbJ*HSDM$%`)F(БA$a3LRa&hD܍1"d)BdE PHK$ `)& L1M@QFa!2bEL"d2I!30I6)%J*L4!DF $" TBlѳK2HjJj))2ٶKfŊd5B i"4clEhQZT 5i6bm*Dh$DMLR0D) bBHȉ1D&LY)猃EB6j61# l)iE]wx(e$MbJ4e#FTұZ#C%&3 `PRhHLCE4ƒ ʼnMia$b$eDC(iAF)F(2`FII4$cJRa#($AJLA4ƂPQ4%%MLș&̓QM$؊!h0)CXha AK"d0))"[63$e 24Y`F2 КɔHLi 2 R("I(R4d! 2 H؂"$SR %HfIdʼnP#b#&)#KЌE)H &A FČ@M,&QDM$S"Bm)2ă! %d3D"&b*4̅%!BL,у(I%0R&I%dDM%$0 D2&I$%LY CD%I__GjyR gd:75AF[5q,|fM#A;b_׶ZH+$1/m7sߧ)'HAI/@O{ͅg W6P}NXSWJ1z4ry!B0#C^2ѽ2 ܴg~-1 D%{aEn: v z'[]_06SRB+윃UO糳Ȩ3}!>`(eBt;*?ug% t$W kHO?ZNXE|2~wzr!95:SŘT`sB~yJvCpBH{\}Ե |KYOIMvqkSMTR )IO!v׬!uUe4PQ|QM5_ [a)s>"x4\E__}v9vSӭpG%_{5|c_iǹ~ r咻pA.e=Rвq;DŽP?۷6䛖3sZ lnN.e9.y)<ڽ.@Xi&]l /R*~d;ΝC ?ЀYo}sH$~ ^n[^##'΃aF}.9Ve˜jHY_r O,C6hF-f3z7ubn^.8cha5^nbě(mNW{Ɂax!:oXf u|QQ@ R+ܕ >gjSl0{6)fuXㅽyQ) 9Õ-zg z< d'lNg<LJB cѽ7{/L]2lznN^# Lf|z DLesCbm"_&qmZ=q<(EgLkp[`? ц zhFVQXw_g r,+7v^ 5(> $sކ_q98 k,/0$Վ(w%(s\E̗2@G՟z;kkmwy+ q9>W[?g (E{ ˉ2FLXHy l=Z&66c4S@[sC e_#}S7{*x*R7>H[ܶ5?OE ߪTb'=?TP7&FfxD0"۳Dqqd|ڝO,8,U8,vV;!r˜OjfwxhbRQDX=sCtPr @=hh^Ӎ@q[t5DJx_cy!)fp1=}j7N!{ZZ):>2C?Oo=o^s%Q 5TQPS@?-v\ A7Mɛ}[l7QC|#rJI E4th5/R52B#\qBpWTBj bOqD-ľ3p>f($,@!K_G*#X3HG=zxk76YE$DǨK~#kE?M,PA%/nH8@ #(DӳnpιWۏRѳ0qUuyqO: bZok|iۓ Uqak4x ٺo2B?—4h4I C o1OmgC%} RbQ.b8QtY,b %LxK t.VdʺJT$Q)P_:;L]꒨JF$]vH,5:5 wKII0P#h"J Q+ mըb֣M%&0e0cImhƫTZ`Pq}q'#x g\3 eCX!jG]ӝRKk|cp]/Y{\FIyNý4ZA[l:! D2}nEmJΡ!m( %N~G%w-Π娆4_V_iu~NET>mvgrm-Phh:'wǗEid Rt^=^O!=[PU}+4|&"N䳥AְH*Ӑ~T }Ewgױ',XLBqocHedH#bEwo*d\=Pֿ1# nn 'UHa@ C1-TאPBo0G:}I~B%qh6XMWGB>$"!>z;vЗ7:_3 _  RTGaut=.{9F>g p_eRπ~bG5S?0AC _U1_h7!ܷ+s2*Nxr)xhv湊Ri)}zB;J&;ggT6v2;k~.'i =s^l㐱՞/IxuYvpنbhbMeГ: g#Of4OxsJEP?;+hT?1F?UynkGԯIGU[v)/ڣjx z^f%GSڵkShr8$;%{CoSm/vz0`(2VU8%rܡ ]Bjy+΃B ^i xH\\$G-\R#.B,hQ0}sϧeyDfq֫:Gxf7;YZ&Ov5,VXgK7p3~FC苳(5gX!' rcy z/]GVN XԩokFB_lc52q?m5\םgQ1:$@l_g'V;{ s>̽.A`%F-*<9֞ 2慒ȌȾ _ٌΖs%>ߙڧ^~/Bo?ғ._ÉxmK./gY+¥٢]U\+g̯s~'cUFv؊;.NR:w=aUT$vvAђO^sFkVȝ01&8rHu~pDA.gQB!7?"l{| 46p$  wЮcz_q& 'LV g.o٣BE^8|"ldAZ zKawK.0O`%&{jTO,tD7y15~c<1zz Ss&16dLAr4i1$D5-^s=)xkkŎ޺\j~t%5J|EO? /T![#:e{wg3S& L&&PH # HBA#f4لLRd)EDIɠA"bH(# 4zFIc!AIfBfhI E`BL$Ƃ 0LƀI"(4fFfld@F̉h$BX)-,Euoc!1L@b4kB'ծI{wp,"v^˴v<KK{q!ҫ0g3~ʵ:ȿ'Y$?B4,8Bj 5$b,Q/p( /$?gNy=!Vs6܈骋lko?_1NR ǐjT DY. C&+c0w$ԥ>6v0әhl%v;-9fmX{ \0[[jdr؁XǷ_=b)}ϥ NhᕄJ^4.42?IxG()B|Px-׵mn1.? 1E4@tg^Q~[|&"(|Ñ5SN!K1}ir) L ;vXP~,X7b@^ /I51Sߡߕ _uUxX  %a %&JӼVQ)Ch5,ӥ="* goI`cga&Z\en;C~J {">q[˾c{j@nk3G+&y2 ?AÁ&Mk{F2zgڛ.S${DxQg78Y'<`-Vu5jTHA(F WL<7gN.mJ URW(XA@ŚP15bu~-vO 2VBW*#3L(F}K~xW؋B G.6@dLK5P?즕6&ɰc{zH u/a{t\yʅc3Kݔń._@)AP :y$ (n$J>Խ:_/o* 䓘:4T/|OL(GfoAEfYr+Fky>~v2!0P{;,.3?}~6s$)CI';*|؄^iTPo>׷'wsQ\_^Ċe/OQTRih0gvJ~ &CP|o/ `$"G nY%= _?3 'oڃW,T*{'ίӹwOvj;d.(c,Uk|"%Bk5Brf19Kڴ2Fh!thv 1zh3j\\냩 )w 8pY.)4,<)լ}I͞nWyYn4+qf 8gqggiSĻ́BC 0/0H,E,=yIeKεl(N/7$?mS@@K;kQV]44xs5b EmD©tjZ|v sX(7۫|G!^s䃊gǁH\h>$O!Xp2UYf s`&~e -NHF*$ӵeq8 g/9B `^jIk,{+[+ă=g*C|C[v9b̽,ݏiN0TRF@`F9i(M *ZIُ:= M83263TgDc0sUnBFS2詇v) O6f2s1=aJnuM2ťΩ.Ps<=m#,R;ֹ2*O0k]'4}voAb_c66F( @T% A|OY_tqsL b1 $F!`mc.[ '.v,G,22w yý.;Ww%m%cK&풘h}],/z[A#/}o3N~ lJTzN2#x܏QtQv7T< ?ZC=-UL]-$wtR ֹw(;.F3?NFiE͚dN?Љ}2n7ݽ.hz #: [ɹ-.J $-xτf1mG|yT~O %~l=Q||-wp m䆟 颻Ҽ0 opX-fƑ ۻt]m"ݢ~/+p25bP~\RUkE,;Mo?Tm#_l8? c=7WM\Nu/C~9\X ʄ|w Y~F [_p?Lljglw Zfk!8U g׌[WF ?.dFkz|]1V7uz:QFX&ͪLϝBOSIA_ iVb^e!$J(Jp^,[z{.6ҦE/uT_Ÿ8_>w@ݑ'3S+cz3M T镏-_a?ӽA1aK*݈$,DFbܩ' r4 cƷ͏_-C*nc/sܯ>K÷azIp C΃iHG0p b s(]9!4l|ѱrZiMo߾XE @ tdJeo`߽Y."87a9<ώ󝏦7zc E 5 BEEḓ53( 2S6eLi)(h,4d؉$(RFbQTDbK&4bHXD4D!SLe3LLY$%ɓ)"&V$i-14щ ?I6_YH EEDRLAI fY,R(F &š&PRQXh hh&KJ/zb1(vX)1bŀ0XQMERh̨[6bTX&LɃ&AQXd $2`Ѡd b2$6B0H ) D &1b,@"h&R22)4*ɍ%bҁI&LF2Q1"FLhٕ0MAA%B$Z F$F4%@Db4Q,ŒK& !Fh2cIBFiHb,+y۶erIe-*J(2JC`Hʀ6Ʀ[RmJXƑ Jc$1 BQi6Zm2iPd$Q$F@KP+ 26E%IjfjNѣcH3LQ_f@IHXM&bƤt%lfff$26X(X7eљlͥMH6lF)RDX̱4ŠfI4ۺ鉓dʘfhF>rܤ46acb%$Lأ4lĊ6Y&YkI (ɔ,hE 34!&`ZP4dш$2D"MdJbID ȘiIfdB@3CILMN:^$YCɩ"M1CF&%$Q6 J&ث lRUb(ԵEbL͌A5cdmFmFK(Q Bb1K%4F`*"bhHj bb#06 F&d|aI"FM5!21bd%%4f5i) 0b+$( l4ݻQ1 byz(%F;{&o'&144j-F{\dRrDLhQ&C d3~r62lkyH4m1P("aZ(WfIFQRC Ƣ3$Fe4ޮSje0DR}c̣IBlb3{M ;nFD$J?b `hDC*M{1pbW'4Y(S%LFwNEh(Hݨ$=usJ"1rI_w o ,ddA]`P V Eщ//}UdY$B 1.(̹JH(nuj錱hM榫|Yu ʹe&-/|XZɧ(uSͧ5*dЛT )CX6ԋ# o81[s|j2Ob1ŋ?/QsW ^(n/%AHpĖǧ[ѫ{}i9:ަ67e&bvFۍ 8uHK3!/"3/(OQqoq1𤋮6c?b9aQ{3E֚O)h)VXZ.ە>CWߠIpV&gLyZDZ0lb@!S^"IX .bbBS`XDMEwJ6P3G}:#١M}{Nux~D߫durƾ0{&{-osPc˚u<0PqtiNoplk4^>J[<<bR`y]*ԡ}Iq#pޢ?d=o@ƀtȵ̠&|8c}>Yٲ*}wdžJAi]∙ tp.FWw/Fұv7c94j<(ނ9M.jx8x~ͤpq\ ٻ h8m8xHP@?d8{\@0{{O)va`9&;̀7p>FyޯJvYbI~m=}`((-d$Hڮ,XTELh LDj,F((*HDjJJLQ b&EIbe )4Xb16D[%4c&QPLS1aQ#b5)-)ZLhX$D1bIэЖi$ffMf!%DAĈ4IALF0~zI] B(bBLT}&:I331Z P$#uQ $Pk"Z k$R T0A!% &cQ`3%ITPEQ XADi XH&! ,!#hō1)BJFDih21@Ԁ2 H(І)XD)c1IRh FƉ̰S6 MѰhCTDfTF؋IF0MF(Ԧd)eIe)JHhXF Hf#PY"HlEIEf&@Ve4QM-$i#&BЛM2foS\cRABLD3L2h*"hJJ12%E}T53%L&dA#tqFJTFYVD2Ƥ-VJ5`%@&H4%$ADJcRV5)1*, " Hf b1hѢDb-IJ@i &HdSFc e(2QbM&Eɲj&i*Ƥ 1(S66R&Ѣ"XAI#HY#%! &ij*dسk&HXͩ#T[FhѫEk k,V6ٍ͑kiEkب Rɨj+%)J,Z%-ږ+ci+E*-"Q&Q b"aL f"K0AIBMm4If`&fF- XiII"єH֌-"hŤɶ5fY  0X#Œ" `ƢMA(P¡$-h2cIcY F4 Ȓ3(#`Tƍ6%`#DTPL`ؔ16LL E`T)ɳ$C#EI"M4fh5RLMh̥0ȦiRa2SY2fRbeج-TS*RlL&Y,lɰbLYTF6 2liLfVJeٙa,)i-J2MZRMM"Ei4MSfeƅ6BH̊ž^Z56Ye5M1!^x}:9Y俭,e{yxg{Q>++ IPWzOƓM&Ћ+GAd6YoABtoV5٨WTUu6;eϳ>xdĥy]n,*;+ޘ+ek,۳>3ici`w?Y Pvy_]܃5?QzTm񗾅b7@[( 2$^&'=+7p_Kw@,/)&27?ˌ!)K??)buVb:H<҆O5P: tav?!vXwJbX@YBL"@bXn|yV PA};-S[~ ]Jη%P)՝s`-r[ZS$/+6y.LG=>7k@ 6cYcS%s.e6a89u?>h\:(iѴCF>Q -1>RŮ1D7$|dxD2>)}3`8(vqD ݔ_|+Xm+qc4-m#"CbSH>u004BPOSjMVO04X ]Q_P?p !"ћB3ڸwW^ɍQw}e~^na˫`"T̓}ݥ?U"u wR班@Bʡhي I(5$T='>y^Mۏt"@1W_KZ EtA=vst՞U VE4DjQl- we!ڑj+w< X0Q1k=z=t~, $fJ<*b[ȶrwss+CF!,RO)#=&Ѵa<SSP ;L_=׽p J$3`9#j"3oR:}q0g%h9&b#W1;_L1b==[]^&qX1!!G$xtm:C$gӮՒ5EkH((0nh2Lql:Y-lpVZR2_n |ͤU4aE5@xŵs{:F!\*LG@8mˤhWiӻDE=m' :uO bEJ}[9z5rUu<={?hNknJrP͋1d>S .!ø芒Z[5%5&YamdEx}흎NF8G&]Ӈ;:kR@((2}1u#3b09)<=BLJK.ˍ<B5qS )K;V{Nkz6FWk zwtN]glw֦|Nǎ/є,7ײg;Q9]W\u V͍.x\]ˉM{ g0mHrvuϙ 4j&vpnoV fBhX㲋ĻC]/X$nko52u5Vewljn';h(HxXϡ+Geb ߰~Oםy|&T]GOY8sFm/[:sw!M,& y)i&ԝ_}Pg40/k(bh'! 1YuvfK5jߞW#ѭ'?gRf͝?^L?&s ~Ϫ3c[٣/qe0h2>l-|e7vVkiF[Vhw;Ǭ5<덍꫰>yK|/ &@35ym&g|N!c'q}X;)ҹn3)\^PrnfMB@?Y>W{1I[>aaJ;<k[DP߬ Hm+A| 3Uai[BWYsQVQđ名.Mv~Ηh0)A{BI헶ϴ7 Q %,3ba<ֿhD xbw*fNn3;SMQ#` LѨ&ˁϹPp1/LcZ|94nZ4V1gX?T5ީ@ $NF-PL=cE 8reQw$xhȮ,,[=*+, 7Ig;%GSb[GXXyn&9} JfNG<6p˧ٻB pwѯ~;]Fhd4-[Yd0WDZ_f)Wn<5Qs;$e`) z]}˵#s6yޙu_wm|B3ɞ_0V y,Y1!9bh·[_dɡ,nMÉK3~c2"gNz{$bm='LꚘ+bn35 YkJ$Q/9=hP Fk N9- 2FAe'E{6bhND8X|L4oߛu0}Lkhެ:twꖁR#L? ȪsLyok6lw;ݹe)OZDy.a v^o`JP7$fryȄi{N̨C&۾UX_8C7>yyP1).ݾRӝ f Dz԰_Ԡh[ĔnDC[Ass\n>1rc)h=w>q{';jƯ$(}OV]aUl|~7ʪ6,>.M(87Cnf/ 9p*wuPRg莁a13ZŐ2\G}ߌ>O-XCNzr/b@0$$q>xO10[Dzه^_H}kt)o3Rs&<JU"xD$')6;ģ7;-6'Tj sϿ$SHDGl)<\Ccޡ8ǩp9jHX/?EK*a峻؀N?-T,&U7Myd4pA>0dLbQV N F 1 HA X[GH-YISJ뽪^=uc((l[5Rx.f.khkH_]JT*8 Q. p )$zҿbq c}T',(2Z5VߢzOi|`C-l|E=77o3RtxDls{^ ] 0]f'+ i=-3rH=D> b"Kq[q0O4\D$m}.4T2k/56 c1(i9Na1LKnjr#e6tt2ΕaB1rװ''!= p9:u (xz?J.MNkn|Hk}JX&nblWe'ygZ]I~o3,jTFEf3K~ Ld<ʃgޙӠ:%opp$2DW=1N<2=%B}7YK;bq8[uUEk0A^\OqڵpAgf'7:P|f=$PkN&ˬ`=#G"U!( 5y;N1"4" D%TO- ퟥu3ħE C:%`LcMĕqs? ZD0V 2<'xUj?g5yd_H]֘>*50 ,%ZU~S  {䫮.Pܾ.k*Q.T\]%1v߅9Tz "DD4eI卮ANϑO!R1a.@lЀHWq1K|~:d~DC0]Fۙ_0M1KKTZęcdRu1Z4F&>0)C@uq44n_no\W-{pC~zM ,__':VrEgW¿Uw)Ai}_/nm]^m73N* ϣZ㾖8VN,f_xE˕>"5\ۙSN@vfH6ㅗ`w!rHqE Vڳ:lm -=לQ5֠u9ȫƐR1:Mu]?%lOWnt2upb_EtXVC+.]Nd9:wRXa-ba_H;h32|;gsVzUcG^/Ž֓+F-Y?IŠCP}.wn6.ӢfdY 7J};G"Կ.rRŠ]E/qWvC͢Ʌ)1n/zz}no86bZZTK}eŦ6PPQ !WcTtD8-E5pohh:,ϢT=~˲A|F"y<:q pbUTf0H,xs`,U@_$v2S;C3+#|Y3<8{{q.&w:-e.__Ϝd_^6)܂Qx8zCr2>w/Ζ` A[:8^N[! OgOx_'jV~s`'łQ'sPyv%*nzu;ٞȿg̀7L@E|~/vFv~3bo(ߤ}ۡ9H,aV9$;?[ c32/ĎWm_S=[{Ef晋&O3}Y ٿ6Yo{yt\jbHA@ 5EըSzosiD B S@@ {i\IB}ʆ S5|c٥,jB_/,О ÷O P{D!/Ņl,vEs$|ジ;',O8Lΐ e,pσH!8w R3J8c 2IcJݝ"]#x;ܟ6?^MoT,#Y6YC[C)g68 E-Νu*kfi'|QBn?mGy/m0ǨWǼp6W -_?ĭv?Ecfb:iRF晛lxb٪ $Gqy){8O2?J}(Ox=YF=w'ҷw=',]Qsh&63(a{zZS.g1Ĕ{5 uIG{nK3huAef!~CC%=ű¯g%Y7lfHa4Ȍ_;?S<>~w]B ZZBMXy]( Td0& /鈌 h;mG_$^{}̅ޚ(3EcQ׍ނFf'/$~o01䢶hyzbzP/ui` h`RUT_vivEg[ dwi*rc|V2dk.>}4RLr~? 'tZ?4lF 0WFѡ~>]clQjQ?dqjZ,wİ%/ʯh֎w>̪õkmo["0.2 "&̔΋ {2X/(BdcnY;~d7)h@C:بSDsi(D]Fݦ;3+i{af3TJpmg]gf/WI<嬫vNUڂ9xʁ ]^hVd@0yF$yTu.Őz=UZ/\guwb|J2BO[4LfԞؙ![~j ? ;-MM}6ѩ'mS,lI2 Ĭ]2J7?( rfElJ9m{]_E>+R<"T_}@HW E_LO., rBNxq|2g$OM|jކ@X}=Op~j-vjIgY!0# yf2>[: ĭwU> E ^DRQ6鵫JVvOK&Il =ёH6Sp: /" XrK"++9*ts}.[ceW2=:'5->GCdQ\J` Vl֏ >./rjCfԺhv}7iR 5~F:!Ĕ; cdJQ>k7\|+)ox t^|$vUɽvTDK]6'ФvqKd<2Y] 'XTAu,E7r%Ec`BnL'7h3Vp/?5z[iAُt@mJ C|Ȟ$?ś: eEud~deY~-oĺaRx(W/7M=3di3H+}ۚ,V"4j5u6+m/gs.]EQs1"Ѫ Y$!F/b5B,[{)(&ѰDBZ*6DƃAlb61T[ EAnWtlEYUSikEbJZwpj؍S*-&hlэD6K)fJ-`%_M/|_@tl:( }b@@NqKzQOO|ůk7I慥҂q`qhׅ[Rݯz eXdLIĖ}[=l~[iBj̰`/9@d?IZP/|l|:[bspjKjoYdD-v1X,~Fay>̂ߝ bO],\t8^1UfJ{_?OeW ͩvSh:Qoge@a$Io_#V@qO I,uPdIKY-k #;%2 xHP !)\vȺ8d%$taRВœjޑa"zxTD\70^ YHJ{3[^[s8c ڰ)H]//5SYiåX)ԁ7[HCܷg|p'Sr:dχKRW8ϪmӃm]azJMWq*w1R((m;ܑLL5tIpYXܵ76##_^zP~R{B(&3Q[QGgx^Ez(`%,yHa(@ MG1F~e26f˧5 = }{=A,}QS~[&?7Q Bj c^7^6\ ;πYu1?z O ]WKy^%& s6#"#@000#"yZk !۱zX5RncO*#C(W3500'{ aB.kB1Y!+ Q0[+F"6N0(?1u)=?Szs 6'<%%_Lv[XKX~5(xCʟ5O0zy.t4 M A`+ C.`@Y)c,Zq6`ґo;8 //#/__Up_S-? f~ (,>qZa)ӝ1xϿ^kMg*ͦM`&m 2oosqjZ~I){d8W:>1_Ӭy5^g - ppu-`ݫTPB=w[A00O6`h`_7<$̮˄{T&2 Wa{hWʫx,1 =LSL}ތ_w>Z?܎bd hPZ:kbq |EVg详eu0_ՠW{JQ̛< u4v ë;z\Wڵ ܍x4"w?Uz'r:<}r}M1?}lʾ".!eMq|y~Dي?O*I5V92Y@CP s%ʸ>㢱0Qf_UaQځAg?:x#O3μѲgXe_$5? cS9Mϋ#d~4oE\Σ**Sqߌ&E`$b5Q0jBC7y].WOU՗ȶSmNb9fv B  /,\"Fٰ`Kc6Aa;lZa1gvVSZq19>7`B"#I+la?HݺlsENى.xuۛMٿpWwzW5dޔ8;{=sW⫱5莇 пRP`o9y~ }i:oO6G>[Tk`ݫmzzH]nG &kq?s!wZfu^qrm7*#y>ğ%8w󸞧'o21G6SO(j ׹Ҭ-=1>[0eVOͲ=?/0`N=ɪQ`Z\S{gxӦ;^k[9aa$j"ueQ[0(fD_Y{}7<4 v5>c$o|9r=&~MG_W0"c$-_zoד)oB{|=~cyhNmW2M 7d@0X޾N;CctLw<5\}O3KU@A@*6?jlVU51=7(N>xѹ@Ro=f2Kw J @D#$TFУ _#rlW4d*-GM-ӝRL??` )M-qptzűF9]\v^Q[IZFђMl[cUwp %mt]_-#YwF$kvg -^> @mme[/8ؔ~_Ŝ | уBY#Wu@D L"xFDB!MbbyFai+6i Vp=vz7MxPy|,L&60;*$rW4XG+C.tk]b:8 8=q{!Oq1| 5YS#/rzPEed6Vw,Ƙ,ƗĜM!KxycKp g/6|ʖoM~q@(n6g{57eݪ@Z} M"B TÁ AgX .㎁J5""2/H>S%BH:/ƱX B6y(uiࣼ2 D}2uQ3oꍟ\VFS/jX @!l 6~;}(!(9;#Rǥ[) $ {9eClCݤ"Ⱦ|>3\U\b2` D .Tf>C??\rP~6= F`oCanDa^ HJ}ppķaQ̺&#Y_rXU}pr~sv,8T>~;7(LZneG6&i=ROr^'!SW Nb!"/xfJ ̔E0j!שMǴm0@E?ˉ8q{ʈ <8COJWnAlmn8+\Z[=~qBX5ѾNp/"$WXst3XbZN*QCsCMzԮ@!. dִK$QK.}m}ʇ܄\Wyac'emez`ӏh}ICJnRGp*F6?1fb:0Ht49e !0g?XC$7&I Z7}ƹl"wSlz_Ҿ/B'%eMjA =^斊r}Nʫ"K5C+b/#MP_S_:?_=hvo:rG4D̄I^`Ŋ,0G[˔9Y\@c~)@tu^*3W* ^:߲cQWCqrX~h߶#[{$g66"0}g\̪)~:7Fq,RWXK'>ފaD:([>HPWykղhmMkc-as6i_кKak߹켰/]䛕uݥ`=qbIv{;htv~6o Dܯ H-j6};ft3DBf73IO]\TLOO͏!s.0 Zr#Qў!Dscz' ?˦hog_lOAL?)tdRFԎLy wB0=rJy0#4e)BV5%}oo'k6[z|)mV7z ^RAM 03ýo =~(ET+ ؾtb58ygj /|v+\C xe4;/F19*KCMDה%)fz*1`] aƒB ģ/ cgb1=B'Nԕ`CV87iP=m nHcv. K)4n=X.3,(Zo^zy쿣~quߟEEo>v G9j_Y~uM9|Tz5lh6(PhH4##s(w-):3O|qE_Ew(< "P5XF֍+ wa7f';VJp8AIU2HI"R,nM&GآWx`;u>mi 9T{]ܻNrrHOc8Ӵ>gG𱃞ƽCA}I.,U滞pڡ(D@/1 oH׆MK!ُ/Dm?f\ W6(CPA#!tAn"B2 WW5@¡}b7'o(suouwknmh:ޖ( gD%,@u&cteٝ!b~3w#4ë%隂Ywvf`MPmk.Jf]tp}La \ŅۼIЎw:{HsX(%^5姎A b'ݵ~BH݇j7 ~D #"/8oHD5Mf~=@?0$;@W'L 0jY<u.8GLt}Fl,umfEk3*7N\o1nO]cˌч?c;O#w{!ywnZ&49Yh4H\)R14P#Qxhs.)z)>Io m)JDU uZ=_&  Qp*P)(,JB9+@Kw"EK_%%.ی8yLmfG0 .| Q+`.\0:;Ub&"C/[@Ԣ6?MTǺ,i% kLBOcE!qd1HΑfܕ=!Au|k:2[;,1MWj NSDR2e<Y)'Zȵiae?4d=/bfW̬&'=#"{ψwyͮu%ym?VӨ=K1~R9EZi;j<R; H^ȼ'dp&TmUYixԚ+MfӴU ~,[bH#Z,y!\oN4cK lJsCXRJ< K@d:-5ØD ]!\1$ӄI t=IL Fr4t=byv 5RYVB+a~:?3I(3?`J}/~eP7g 0JH$_EA Wԧܔ12m|RL}FBj`c5t/a$zY'({<_= Ɍ@[M 69yt6_ MM:^r.;VWܺ.@|ߓuy%?u/1Э3LXmwVmɝb>>͢3arx2+ f~O(Zk?+:*ifYL\ƃ~|ZWBw.pI8JY+qu_^*.Ö.Ǎc ڕ辋|ThYpH# mr R8x>o.-u\+6w9yyyΖ Քq_\;a{{a7?n*[qXxJN?-0bG15gi[L>:ViFAQYU9j7tGQ4<~Յ%i0{_͔>t٬o(gn^c}˿Ѳ "ᗕk(uw$urތ!c`W[?m65ֲdvqg|Su |w}Ixn>{d؈nXa #}K& 9.Ν=&1CΆ. гǓ#d~}Fۛ\6ˏ?!lTr{Cn݉L:W|*L~Q_R#dc{+g]^S]>̞-->;e ^\fun89wKl2jeKi3G2Hh) *L zБ`1b>H<ŗS)2?<ϻ-_XL(! ;XJ:^S?TCx\ FG#{Rzj*_\zQJj 2Q(tC \u!αI,JV-zD7S-TeXRV7чgܗr*@FJӭaj3Q)/g,<&ar%βLln/a[+=@C!>8~CXj PPmsJ(?KwߡMWš*,)k9ر_c{ڹزsnޫåӆ/'Wb\b]ƃOX)cpLu>% L !Qosъjg&?9'NQa59ޗt ] {ja7xC>GUiv R-VYOr;)~+WzM9fF+R C`#p$PRhZ7.7(iSon\ c{N6~jD d>WYլ;*-FG$8\a dz&ϣox: 95<1^OsLA98SmxsW..ղxx)p2%4'Jv(evO*Wוܽz^t;/y_l둮Z&p$Xv/L_4O_1 8vGN3P2>#:)ebv^F~S; +=Y^)yi%^ոWl)D@ אVꌑp] M#%>K/Eh Mx E{?սhn%x]f@1bO #UՃllr;4i|W8$q6AlS Kj ѾO(lA>+&(y]R D$bSа,k PE5cn?@n9 V8d? 6$U?+T!W 91lHc `rqƚ y=8"Cx㥪b;ګ8AM/q~ۨs>11ߣ/?{}dV`e+?O߼ycRBYדذ֊aM}O}0cf|ݷQO;3pxz_`s h;6T}/\hg @כAxn&5(EdmC` }ۋuO罬%c94yX8l9P~y b{K[o0  8jdf5eCx_zs]o{Op6h?[%IU+1QV٠ -R)|k(t~Or}a/)~3L#^eׯed*"V8\Wi] B\Lr1߿7>ףS^ 5/Sm#g ןVF|(=zg&Ć=9mPkky0S_ܣnxFپ 7>RIۣx3g)N V[wS?][$[LQ_0ȋ O@HkHk@|Y&F-U6+ddi{huyX)<7H^[AF^_7&{q9Z>vP™kt/КJOwAe̡臹˃Ȯí$k4 oB798d8iVlq#Vy²x,?YUpMFڛS]eHҗ?=/Ӊ"Σkנn{ƻ?`(´h"%4V>^cziǶdR-@ڿ|(x}!dJ" "_㲛h6hS=o7<<?+4z\}z ~kY'd~'[gs@S;ShJZrOmX; D>pH}OW "w{}PCHAwBC M RofOX^x BFq=ljxG59ψi=p"l>>>z<1mxx߻y9\+h.+.B0RڤE d $wcw7Zvsp1Ms<Z$A  bEeiUy8_W|)RsWR{u9MK<ðF6uUd[mk﫻#|O?mg?E Ph?Obmza?PCпAͧhZ q8KDU6-yD<&x,U7b + ")* O ?Cu vj蔬0$PWnc;,ΣZ'\RD]ܖ/澚D|}ѵ$aNs5$_[S X E$y}RbxQ#nmC!n-58G09t @M/&c-ͽ^'.k7Lw0\C\]Zk1p%7^먋L((ʹ+ T,[ u҂ԏ\DbKkRT,-֪֭WgARTI){Wo!%\3,&$~}_ ש,1"$ReBJFiFuĭo7Y(VMۦc77]bM(ryP)?M088rr}כHL! 3Wk2g *[̤ONwF*^m ^f N HU M& KHcyZ#cCRun6uw0TDB:ˬTIvAL"g;'˄j֒pEh@tiiX3lC bXL PQ t5/#B3# cja 6)&%ISAu_PaO[ډ5&W9b$|ni6 2QyeAbR<yšFѱR",X T*_C𿣯p]S£ג+̍6W7O}sP$Hdk2-AckhM6cEZfTV-#TZ6"Z11DZ |Kka)ɩJ *0؋+II3lh d?mvdQ_S꺼Fxw]%!ʿ*^ %6K1Y+H"dPE")"LSF<굞kzougJX߉d/ %HD@^n)Z{"O^;n*sNݵtZG~J$ȊXm3Sa.5!I@"{:K2/ 2LF5R o~oWM|uyhBS .,%@""_J&pPS=eS9Ko?jΤ螑293+Ͽtvbs_CB֋e4hA#k!P9B]ڡ/#t؉8pHیM]w9܉uzXU+JEeC$lH^e8n! /hϱe͛D ߁sDwhu$px-"dAQO(}W@0 97HњP&$ѣ)D&|?%okdC@C-jH*]Ί@~y\֫rPq*s.w3:ͷQIjxo;[%H'#t.ĭ9*{^!"H\R >@v U. $ݬPh uu(&aH0B`h.Ԃ!8&'q З7adiA DU])+j3GP(bӞT}M+dϻʆJn["74',Ve%!͂Y P2n%}ܳN\[=5O,g{qFAD$jh`k~_i/'7>/9󷝽Aʚڪȟb)S IXB! `4Bjա-Y-)]=U;#{ e/&Hl\`DPct_?#?:yv$R,F)#6JH53\6",bMQIIaL(ina f&L4[׈dbIQX~sha硣tm䱳̭7Qզ̬ 5Alta~IXŋI%oZ&';MI&EIѡSQTHji  MouxحF4XWiPq Pd,6Q@X1=XI_i0?ѦuOInUat8M>ubZĢP%(D@B~ޏ/tDU?}A)DB64LKbQCi]53>_?$ĉo-x"1٨ P(($FaKP1,ԙL><1m/ڼ}kh4Y&E#Oe5;X.7%O%3e"PjXL@Ģ((kN eT$B2fQha C" 4$(HD@E$P$nНj nT=Q@Z**Jٶ +J)6cHIVEZ)sI\ T ( R[vuBReQ "4h:jC!H=JѪ""@@ ;bAE+5@P R  ((J$URT( #|M}jWsAU {2ݮ[yBuUmQDIĪ"%$TP`{鐤"{4]*HR]ZZ({43JET :g@ J @X@%ELD Y֚`]eZV.PUP%H@4: XDRD*7ԶZa@HJU{b7U( *(!JPUR@Dw!TU k6 jEk,Nl@J2iP:{W=@^iqy[*B}`UK־䧳Ѭoqs}:n|v5ZFuYn^?6LN9r΂s*k$DZF\fE D@x7^4B=6EEGdM`B1A^ +B:UG$^#چ94 c+bi!hp (ar!VA`,˓!9ʻmnnqNtQSRah1,Z 4QQlFm$ssV[VĘ&biRVQmːIlEL 86ܳ{cn6vLT޵̈́bwFbԅC6*MY$4Xli #A i"B#@L#Q`ĕ3ui`IlbO}QAGtk&s1 'L8( Bu?ÁN 3,(00+Їa di*f2 TFPa'zwNi=)؟N}7q"]eGOl2L"yz ʫqnn\.2&?MYE8zqM N]ً+? N6S@'@Bfa4&ňȘ qO?h97' mQEۆ7e2v% #aۙaeXHhH: d.}?^ca <լx>J 6"h M5Ҩ ӳ4 H'QEC x> xE9֏9CI8-iWTqi?9?k_ytZ-'i큇p&a@ !1Fk~C!rSAI>X7IY Hd0sU\ƌ7X" m Ie4d$XQWMFI@/xaiRc R &0*Sr@6 +=jʥ*lJO;~JjM!Sj68\(U W}i*sq`I|7\E1!/ib$'S6J&6BH2)]vo@ )NRXQ)FBMٴ뚁Ҍ B{dv#4P+naL&j9n^l#)zO]3 jI/mER%BPK;yvd0cm2g^%qѠt(a%Y+\exPJɬ Z[c[c711 ,@|t% d1cZFY0kFSN}qԀbECy阇#txN'(\dMP6 k۫4&! |l~!|a:H1G1n*<@uR :(m$JҴ,^09BLC꺲 &3ݳ‰S(YCresMhc 0sWRC<˻Rl[k\aF3)Mڻ[&fb1eI|Z)hTLTTSć\rlǞMWpLTzʘ@FCNkwhAi|0a%Ɩ3& 86/r+W@7<}@)GyDxrp̈1(2Qh@)6ƮVrV5k[sFsk\:$82TPPP5 H:kI(PcAH% 2R%(6,$/nwD BHc C2VL867ن4 @@hXaCN,8 츅+g o,ELJ1? q%p]W;0\11*tg)RmhFZcnmG*չQn'J 뫝EF"0q)ɣF-D# ihMײаeJڊsnFHaLeF"[nb 3(DѢ&M)b F,`ȚTT: MK?$g, D!Be 9 A$5#K"dj@|͵.P2N1.c -(,;Wou[RR4& srC)0CdEI* -2J 46R#S*2XFEi)C 1Ih3!2b!HQ׹vIGvahW}`84h73مl4V!<@j҅e@ղ 0a8&! 5)AL uQf.DMdme%ɇ20H:%$"]UJ%*%J9 (c̅'3ZU,K@ J]65!h)-t\\1yvgگ=vM^)ڣmBّFu(.yP @hm)ؘw̤ ܶ3{:imQ=uhz%*]&VeE:3zS3X A0pJ2n,tKD 6ە^6LYB*3L&5)Fܪـ.@Vo H)QW6M&MTԊD Q wnd봳gZ(^uv뫚kwK Ei!gya%P(ՁDhkY";2.椬ɹsx/d҉@v(ϰN;<{!=B0ګ6T%˦J&EetzY*Lf5 ,UEnA.\+x*L[YXB̆> ,)62Y bs=R>0OI_]pa#j W 2r ;8Ȫj%Fip4Kۿ5>NNU_ YyjOJ'&f׭d'ߺX Hm;&}Aara?gO y#a֞RTEib@tO:&N i:z7 ~x| >{k===ey%@j@֌Y 4{UT=Jƴ[EILŝԉBDAD F "d8I 0fIJCjK{"mш!D l0aOl2,wad)]2Taf ,ky(aIY+6 3*d0ӈ,Y1fkfEGPCMX1J5ne7k-+8IF(Ȯ1cY4rbMe?$9IdCX\)((_.N Pe ok-Y|MrU^y=Ps53Y =׺_6%/m0d/ LH:nb7d#7xe` xɌ``k M1v*"QDM7Q=%2 n839Ydun h\0ا[\îw9<-sx&Hkwk:TDjR.&Bq)k6s ].U 9uْ4V|`hv\fwl: 梱g&t5EFjջ ĸD<2!nQD[nDEpQ[eR0-5y 8Ŏ yGvmM6n!xbqnCQˢ l@V2,հKef.um4:j8Ė`\jW`>JT[-Lf!:j" :4jЄO:w50X,0nn0U9 !^\0" J,"R +/S<󲊩jAya,1ඉբ*)jΒbR~S @ s%#A@{HbJ)dήҙ%DXT4Yĩd$X7l@fCmf l4]'htz̏@^L9g (,RE -3k Wa¡`Bou@tꙇEPR,咇=Ldh,qL"fҦ05ynJ(b*Cxr!QIR`kZ]&Sv3 XPTC"p#[jcZ*7GRq6wf|oZIxE[2˫%ɴUO "=jU<mey9\ e,ޮk55Bb=ks\q&ڕJd)!< r;3y'+vgA9hMb)4 h8 0p xt2]aJ0Sr3P&Ԍ85n83fp Mv&58p&",fh pD, Z4\^)eiFk9Y o8$ 1385n uL^ӳ[W]sje J3FNI5;M. ҼegN8\dݕ4i8fvm&NWJj4hHVBtMVdeODV0g,WJ3 :ɵzgyNgJ[^:S-qi4ꤸԗ1(RrdPk ^٘tQI^?}b/`UmY\xv݊MܹDmC5G8^jȪW$#]U*qpFaukшEztqmiƱ`Jڲ rr\Ʋo)Ωk)5aú]jQy0;xjv0)2&A!DuDk#Sm ir(ÕZ3=lAN  $pvM!X!hi&i ^Jđ̉؜EAi[,K1x.N6]hE 1eGRfJcAۻJ$v`nm1YjIlmNo?}2}ϘQЙ!u2M- *r2JKD []XVt]eZ2s@ZY jLdE25T1RT؂3+YoFqu& X2|?j T8hEuF͌(t×-uh}})ȡt֮5a 9Lq("t1AQm JɃbqWpѨ|=1 /Ͻ^%c:{'>‚(^D vX"[i)1C20PcE%6d#XRY 85@~Ro&3(HV݁ul@@ ii2:a2T臜*AKhriPz`dDAT1 LDpNP+7X9]XM^<$-+C)3,S-F*EXVcj٬%a,RrH RhD';xImvU=w"QԀVK5qTs8d[҃`01wzA ~~b@+@0@J_g:P aٴ "aFe $3;9a,|q#9n-kN#iLXe=;~tXlq)ײCBamx:^P0@9bD7݀z큩% ,SmJ͹Xw#B&bA‡BAWIu}z8dPI7 2@63A9`-PΜ@TL @%Y⮥bҚجR;B<0P$[Z(Wc|wD zWv-%TiMTUuo<阵cFEI{[QE/|l\^g BPPQ nK5Zb,+ !AI&&B&$XM/i 0\&* EI*-망9]-\arɉ2 b 7 ]ԜŒ7Ewe2m\( H`@R0ZYYo!m*$HOK^s\3u4$Rћnmvt.LE,4o&u':$fכd#i ˵d4Y*Y3J^ go4];dW (-r|os'qY V S}=pqqEr^JTбmYT`wQTHyBɰJ!a:1 N1,+2SvVH;s?'{=(Mh_,7`+v,8EP)#0AaO֒J2ClF6׌XxfP}=%(ى2bP,PS%s c2D LaC_)1%y@*ŔgO "KY.ԈV:kW5&,X;avl2i+3W *̩aћMe JH;3ѵD)!P;NC fVO' 6l ?CyG?\&0>K$֊;v8BMnK%N캽{;Wwō "=<7RPް[W4A) $"4{82Rdёy9Iɧiaͳ }鐲bRZ7h YĸhOMyfsf%0Qpr# tn`x`8.GOT ;x{fyŚg?|1':b(S;>g%a Z yo TDX]C X:2R$`SC.$o$X$!4__ ֽ#l0SVD`(nSBAJ k Z}sN84'$Î88mxdPAuR ;sd7N 4s hmh5b/i[J; R誡&ʢLLW8éAbJ!-.LLum۳54Lwqۂ[mQNIuJ1C5M 9݆g[q6NDYŕ "n YU5;[%H,rh'XCh*GUx]@V9nm)P8(i,tV&RTGXV)8ch# =*~8i}fzCVZ':9Xs=bنCLШQi lQu&lq+M"']wj=0)BOߋ܇ѳAK AS*( s}|`psRhL+Ȑ3Bc4l~zP!RL@60]5qh#t+PWô uARR(`T& HmJ| ("LIYZs(7ԙAD@ l JXVC"# `mhٿbىVq޴]f':ܟHj+,r!)[jNY*&P\ %cQS/\wK j!TDQukKq ʯ#єZ Bm!! %XVQ|~?/ASgt!X)OOd@'RT~w }^aS I>`$d4;?$Qx!G BVB 3Fh eJJ]7rCUSBEo&d lEt lBU1S) [ t(*f T[lE4RWV:-us)RQq@MUQ imFpWۂ@w$Ú)aYQh0YF"˜[WmnT]5M2L [E2c>>p-}WYB б_A}U~ON&$zN@dBi f Ua<}Ә&ۉ81\[DJkQT^at)\t _=k~g'BI}}3A'4¤\@*Ǟ9C!PU 2yBCԏQf5$D'x}VI붝($TJ埃Se"5Qt8ҹ69] /Ѕٺuf OkM7+\& W/dkZhB̕"UX? 0uƵCc6&M2تbm+zs6Zf8]p:HW79L5Nu٪k o nΕ%pM:Й-ȍ3r;ޘx&o֎^8zzd:#9箏3w̑/]_yч?k UXj^wiffb^l5w?|'̅4x`PPo"a M΁Ix;]'rLCLZrkI<$f'c]@:BvWDr (ݯףAgH(,Sb]A!{-18PyNu G|5#B"[U,³i}NvQ!ӎE;5/? x n$Ĝ+qi~y~?~dw< rNMǦ%ݵ=Ey9 R$NEwιZG]o{K7͔S79zn;Հh4V2s-;XO2mj^)gkON3 nI|Sqam޴dutӣgsynͦ!St:z 8;㍝{Q ( {Cա;B1޼x}o!o3>]ٌejV ]11Z4' fjo2흉 sG 54e£3:C>F},'> f(1U)ƺƇk& P+`xfR[uqvʸ:xu)@6@7"q(B+ι=kH9=Oa@5&h>e$8QH+Qq7x_siqeݪ CƠQ |j!m*Cv،j6)&) rR؇ )  [ҌRI`9ꇹ'aa9S}ٞb݆>2|d:7Y{ )̚:w9^=^|&#z )ffV`;@S) *{IM:h\C_{9J7ŕFN !&&Lc' gh[N\izD:S/X·m#A]ͮsΈ`x8ꖔ:nEZ0yowCL>,Ag@b_=4}OO_yLlrrL~d.03J<[ObT8!Y6OeTtvm( i͟:9:i7ݖ6t9gz ;Hnm󉳽Z338μ[zPpЊ'4Ǟs9vڟ,e eD]0R5Z 2ʶJ]'hⴑVL^ YM*Asqmɜ8xc2МIͭS,AFt =xnD`*SO՜xi:@EC<2ߌ IK:zY,XI³<(YvoI鮬E̢t35,R-Vi(m+5B"XzӴۮ)RlԸ 5t]AqL&v-7CCt\ &X턘z.xK܀=@4> ˨~~zؽB)}ӴP*od_m&2ݰ38 AH_!L)40ΩВi6ɒ)|6ݣ0W\ͫLY-C11Ԭ*U_0̵^ [.¬%,&E!\鈮 a . pQXi,p١LFE!VچkKzj1RAY1مib".4WGi%()-"i(ԝ3-xgӔC:[ ZI@0"i&- X@רMLDE& !թ40 !Fթٹ5gtwgE4o/:aN8iٸN08Ec4#LN3J\ys9A;jqs{4/ yJ(xOK1;g:麄";I cw6lA\Ԟ8@'䐩p;`r³Ȃe!E 6 rYLvV@hO:~0 KQ",Cq::xf.b]f$fZ09d$I=ǚ8b(,Rq249ħoV3-k{폃Qjkϻr{y~咜rswb,AK7dْxD@M0Q* z=RzNR}Xz"P:Od!i+ĩTⱕ닸tnϵ;f24.QL|Mbb $ i 3%h4O}2՞yF"Bf'ƦᶇRiX` )2(i6zMO3I :/o\c<)E m(o0=';sEЄ5 ;`g./pS6 -ֲ#khu"md XLW7֬)E:LvCٴ& +;dXMjP d:/^\ٌ[ڝMt0‰ŁН8!# xt<cxdPhE$@IL/ 09BS&i/n~΍FbN`mkca;f2ydbO!gfP icUl$bҀ)϶Y,A`}œs2z} d J' ;>$GSHtu}2P@nAӵ6G <$zBiQgYri PS7_x;?%_z+{;CvIu̲'"'%tv'}`z+fzqΟ! xO.](qXl`Q5b0+s3L<3nIQ yibSƌ+Օ;Kv[Q2rom'x^Zuly@'vu ۙ=JB%!Htyyh{BzB oLZIY=Nn5ZCE;B'įIzOnz=Yj]-CMJ&tjkhJ^ JwN:C3 EH (;Kk%dN_| ɟ|ˬO8dt;Or:f4.e\gΤ9;LC;{u_=pAܙ>)1&p_BT@}P/nv9{oӴ+B!4 2CyC{A+9G *&!NXNi8'5i6aNyx;#Cx=Cx mX,I HZPX) :7*q2S iI>tHÔ2 ~~^Yd-,:;}oO9$ru&0+,tQǍ2ɌHV};g)Y33;{ 1~^6QI'[3NF 'phmQtoƦ+YI\抖Ԋ}5^h yg$%+Xr$X6N91A̷b3N휡gHt&6\9șGQH=n`7v<& _9;YojeE/X[f]iL2qh)'}VC}P̲vˢЅLez4kYlCD5N{"$ qoѡ|483R|ާ?&38G'3Po9%qCgJ`tԆ|lMYDHm<[1)O :l 9󠤣E_!ߑLf$0w0,P t;.V ceg92@?Nߌmx! !S!պO(mC1m(łlAa"40D2LI_L&0Ji`pTMd>eh}<ߚRDDR].^X|!yy=&?cgYیﲊlC̼f 3/V2{P:K$AILU*E8i◪iLTq0N[XqKK4sx͝D9O2~7ơy:՘Xw;q<04 Cb iva5S5{xC4@Lvi6!xt`loLk ݧ.i-ƌV$8,Ρ瀻!ɜYYӘYťVAa7MI$ _hÒQZ|D79Cyg,`o3ݜaݚot1Ӥ3$0N}蜈r}ިZ!ti*CIy p bg轧,9Q:XX! J@tf)I yV{?*NJ}vVwهHyIgĝd'yAqwՋ' \撠,Ћ5S> =q0'Im?7:O9Jd=zv>/z=lOd/7NC̏+,m߽NZvo~Ꞟ8C/PW/1>sgRWt>NOyD LdMY|[;LՄ`mM%gL*vC,!;QQC# u8)Y>umeO͹fyl6h,z9NaA|x4I*wdP׻7id',&/\P(*(yd8f̘Y< X/7cثHnhNW%c:B)%+ၴ%ao(r(+ Z/Lg:4=01blO&m'_Ṅy_|C郗))L8'1#i 7y~>>@O=(B227P*HВެ hM~3Tiݜ!HÇN9L4`eɥNp}9s#6Ijh_(O=$:~׌yK qbx:f`,c6ā*@1'IM߉D1%VND5 :yRsp= vhx8N^nl cBVmuI]&c8gL6pPqtZ:xNY: YWl,H{OL'Z)&׋')Q8R}09c#m (Ƀ@H16qr#~ﯷjYMaXt-æ}> my3Ŝ5v£Շw@&.xBt`.YX6݈A *j3`葑P^A'b"/^''/~ibV(V͕] c{8M3q`kh6粅yf` $)呃oV(@0Y? <]o~Jc*C&EgLf4ɤ'Mꕛbipw:NQ/6vQçiPaS1i0~'6|_P*, RiAmSL d=9I3VxBv2Ic3kgT8QVt1ҧWl`> Ry&Yuv0;Ւm'W;&5,x&kk8 <yˮ I0MZޏ/#97~]}-ÄLXO-ICJ mzT8A$PTᄨc‰I~󿙽;PSovĝ$;f9=qx0`Y4g@KA(= p 2|JTJykI﫮^0a;z=3 {T=|P;  :,7fhLB~hH=umiNJ7uWƨMXRcu0,Ma>Ι"jr=R3>A(_ݓC=8nzkddOHtY+'pƋ ݄!<<)9ANi'/ǎuHLRk% J5vR哞(pngv`N1$􁏤>(dI"{ԝqa(p6 ݤNwö\hTt+ $ۈ,09ݎm2I'Y8w SύLtnϯ=H~2vO$Bz}'L V@Ģt~8OqkBv8bt$96S6C ftƳ }28 c9y{[O i^^S~f:g, yꓴ<ÀjL1P;d*2xdTod8⒧k1p6t!$>,<}'$eʄuӇۙNOL?1:@3ũ!(C {BVuŐ'pb5zAǂqouTVbUuy`NqLps 4]0A)4k hy3ghf=MpjQ x󣠝哴a֬]"r)Q18vv!ԛN׎NWLn1`wMrOi8O,5:HLqO:cBq"Cks*ʀm,,"ca8gH2uJ=PI'I冒wdIzz`plry$q = ܉/uwHCO3JXwCKMYWv8ci:x`V8a*9AFO]!ݖ垞Өy<j@C!9f4-V$^LN\^=gPĒt@8M ~.y  :IzQTnSd-"YZPiT<@6,d !d'CHnF09]YیY &!1$r=jŁײxn&DޡS xBwh`Vv!NYsA*dCp<}γt 0;qNxhvjkzᆏ·^hmwNS] !jOs͝AS|xfEM߽p Hk f!zCx}xd6I'@X/)g9Hxg xn'k&ޓW>6M}P%5*x@䇲TrPo< ^$*wlsa4s`k+ŇM)8v7 0x{!4"@I æmN$4k߾.ҽmSNwP$^cfN2nIuI^2M& 0yBM!'\&stf1|;fη,6Y:uycPNRIXp^v=gL:KhpI!ܔ֜tR~1 T]'nOZiׂɴzC1&$ p] Is3!J3>#c}R{@8dHrÓuBHOO\Okm4a'I<9OL͝0FCCr!i+lx|IuLg^m;toy`va.u`lƧ<Ӎs\&n+NRqd+6_۾,᝞,>FiAda;KcICߌ4$yI8f*ms4͹2E%XP>jL=o㐿V8zO );g8R!9@ﻴyIϯZ4ϳn:M%݇gP6,}Y'֪i!rQOO6풽+4yMut;~ipJytd{kt)*i;uiOH,-\XwLtLQƱC1r6 C4fvpRq1bQE26= ƞd'ʼnq8w3y) "݅>Y 'H; Ͱ nOv]a'(]N8Nu b0zv];݁NSL4qgŖMf;N^h5 xCY3p3w) mC;WLPaƶyrYPIx\Y7N֥8gLP *sC׆%}1JO44ݙp6S:Ġ;#0A' :xi4]=[MPeE (qn,P͌:e8uҦ¬s;07?/L&|E?څErĢNEC?i*(|2 rBR bޟZGoqi׼n2}M'> c?!Q$~c Q|鲄 B "[P'd@2/rgopX~]80|z0B(_tȼ|CS$05_xH<z?<4|"P(~XB֤z̓ؗZl|$gN{̫_M" AϖCA...<+V-ӷ0^E57@eSD7՜̩17mE.N7 5㚛qMN!,L?)TLC1ܒ&怿UZ\Y7lN1{%1"R 2Ú?&dXQ(BN'yi/yVRONN+m}p"Νó+z7O~5D#-_Μ3D-_Wdg="uZ3(<ѣ]8~R0ewR)jUpyAAt.>Im*,~t:PCuz㺠aU3[ @D) G\Y{!eK-MuD3Ͽ*4I U5KozةgFYN %EϥTT[=ꌭ"Ҹ %H@ѭ&$Dž4 -]||_\߁ 2=?G_?{@POHP}[({a+?ع["@]$ % :YAq)#4 8B#,ur\?ހO-~m.}y GjķCCgyӾeW^mį?H5+ @lKzo+rQ䡺_7PY^B< L?$d5UXHpW)n+r,% l>E?M?ÙBv3ʼnVy06901K[XEqo O7C."tK@@,b8 9 OX2E_'9$b9FI$~+꥖h$I^4J^EbM(H 1#ֱ}kVRn&7ܕ_@KJ'eqr7e|\ Q"GHdɌ` `j7wNp>qPDRH ,WRgx)2HSXx!O<  Ol}uρi0B?dqPB uBlJ |O鮑A?!{ɜkG '%D7a cS  bjȽ2Ia {Ԛ<ε3a$MRFd@;]3 1R?ď|Re\T+<Agii)$ ׏oJ=rHpo>}-(rWڜHQR*Dh(4/O~zuh , p@G֠o\b[;^IhڢF\`8;]Rwݔ JCj܌VZ B/f8}rW2lU6T{Ƅ! QTB!:y 㯳j]|D_'~9_鶖{ /KoV Ƈ|LKk j'k nzr"ZF =8ʊըɕ#z-<d=Z$C:.Y; @^ ;W)j՞ˎS޻e<CXCnKN9 #__;XD8;2jл8*(ti{e97Rd%g9~ ح^hX0/,?%=j:_XowTRwIyB.FUB'~jzڼ| ;ٛx=g}:o?5ǚ1Ё݁Agw}z28?\ P)HE (T({mBB;zU6tŠ#a_~iÅqqsylF }!pNXt~L-gi!rP Mf,seQ"?ְ6s!PV 9T**|D1޵EZw =kҒ <]߽0S֑r Ku%)i,uGS=Cb~㾒u!2 ! .I^o4C6!1/z+CLapzFk^{㓋d&p,!@dXU'jD5u1T|ĩAR*FqQgǍ^ePN EQ(r|14 j;>ǓCyODd45 @}EsZny*%))L@"0>!?غ [˺lJhZObXW"u|+I)9 96 :Vtr BBVu3Ja`+G4„n="YAL?jz U+domlEx8+v.$^Lr Ȣ֘+Jɨ7zUHKB \Hse=yF+ %q~tQ/ȗ\WnP@цy$80(?yljŒg=ף׵ZOR\66c+i wi @Xҹn $I~=wiPa4 ?ogGޘY/# i:1PݗK"mץ@ :ß} p\; aQ +]$ ]P͑ާ,[;uģҫg`t[O'h3>(xkcF#_ cOO]7Ƒ 0c@ y@RTO@̆ B-\ioFc 6sWo>8?DCo}H_"a EBB38Ӛ:.#=1]T&%oG]3#cN$LHc{ŒD3Ml|;u>pɒ$(2![2rTMB%@ (6e^(,<*2xWϰþoIg~G_D,}c YJҢU)4ID< =ᾨeCMGi{ztz@axD,U}Ja3dOE_V׸\yVٙk ,#dL $,8xZe,|7ykV DN6LglFG[KF#l&|;xyktNUM US\ŷ2)^$@HiX_nkqۋn^ ho^=~k9NBfXu.$'m`J[k+Z0`GpPKXQ= 0EU@Zdb+Ax]!ޜUZO_ko3ߜjÀW-a}#H|;IS97,?W"0+sIh3ŊT5ktKzEd=Mi_G7 "ь0Nً1 '0%2yc8!Ň&(tѯp1haTD,ffO=fjgKn "\5-RAlo hQ9=]X0Spe,Xhz5<+I."FʽmƝtHR ;'wIuRNða[f.-+^Lv|i9'ܪiF]Bst?GJ$f`.궓;)6*CTWj^7J];G\c xP\Z%f^k <2\{"L깗1}9/gKk9E4R46{ÕŃ2C=$U&4|SOj%'=F_omCCNqu`\|#>e}\~c 4:񖦋!8Xۻso&-̻,"jY9ty gw-վBm*Mҧ@k23d}&F_&-΁zh՗qeרjO7PA_kO3J^Rg i ii>?}Kw%I=uRc ˊd5h&h(e՘Y;y6+l |3305hEqmIbHiY9\`F s]R#${ّz}$A~ c\/ cmQT[0@BB+ ncPNI.I&abbmƟ3 1RwV{BjJAerOQD}ZF%a2Rg| ob4U -[*1Ѭ'A=0r &S÷o/p=DYWV_[+R Yba>#R+[>K1)XZ]s50\YJ2 QZ|h[Rp6h9#ȷMfg[QzQϡ>g(ylQ}ʨ^үfI" <\Dm WyR" = s_͠9 6:8 g GLCDRWeFj*?x?FWЅ1?ء?yQJ%(0d7TZN,$.9uB;6iuTG9ZJy%i߶䆭Q*ds靊Dj5`*![SR[nNRL,rCkxBq4¶%HۈbO;փ"¿9Wmt譻X&>a շmZ0D!L={.  , f\ QJmOe9B:0'NSJci/OfdseBA%!s^7]z{lD} 2y$- I@3B#rRHSzJOCJ"SxՂnu($iDҘH0mhъarLZkڜ֝6< 42q@$ק:$O:TU/ 55qUnýc]͛ uBe&8I 1*AcoT`oO&W?$ʥS{Ïq7$d-T9$)=FB0zp-wj,D-ۗ9&PH>N.yTs9v97;`h^>A\?^Dʹ7Yn (MTOtt *$F$ S [Լ-Zql M3gw+]hYJ; d@%$[E ɦh:10(26cm6d9/ܫ9髗,mחr{s%@ (z;[] 0ԟ6^i39l;1(=/4=ܳP_tGQ? >ME@T/JϚ蛬0n.k(3SqGk[Fqu/|Pz0W!Bj08r :9V"4ȭ(D2L:]}ѯ~<̹ؒm/ѶGKeY\c a)+p}H1(lh4v5GcNUlܲ :!|pۍƞ%d6ޞ: |±:Zz"xb6+7K"&zGHS>knjD<9:O?Ej$8VoI@70e3@S7;o [ 2Ōo@qu#z,90W4aJ1_fR3Ivk̈́Ӻnʯ'QxʛJ {Iʇ8m$$dc #!gXW>y{9e K;7k;ٝUF/'؇{:J!6:rj=dLb{/~=Jǵt;n =mMy/6ՀfEQC}~N<ǘ>"N<!s=[ ?|Aua:n$bAZK=CgpB2g)7Jll~S>FӷG#=6֛Q͛1ʟ1]NѼd&ه/ҲcXJ==$.^:x*:SvyW5sze%$dD5pu=>  %E9 C +RM %:S45"'&QWyN6[GŲ&ZfSj8% $ĻeW`FJc易 LT#Z^1>R]v{Q 1$xmNm'6wCߊ"JN &&LSXb:(qT"8 _ѐDSpv/u6V:$> 7fg18|L4BDʪ Ƞü(<ӐE`&&_`LZR¦hN[#wy h}Wdුƾ.[|='^}^΂M$*Be \]ΒiLL#)Y/ H$!>> x*k{_ao҇s:@`('['fJ'e~ hշ'eu)+IB|\ĕou˶BY !M$QG!±u#痙w AHܝkGSz߾8'lXS#,:Q{cw`h(0))GR{[KRaB9 `z5Mv xT2 QO{s%7SCBbZX= "3?5Rw #Rv$L(OfùU lbh2ߚM &td|S& ڏ&G1d@~?Tm9+S!w>ȽÏ1Ll°}E D8m S˦QDaS H韗n%#|KIP-BP;diXTS,^4IO!"ZT@X(m0)`"f LL@H  JنBklwn-ӷ_SׅDh]!I F,u:tS`Ch~#D] KTIC֕ϯWٌ\I~zxЛO1*v5] ~MAqG5_4UsW_ Q$ځ%m2溄_.B^>3 z}ie19 \ u!-w{L( ۼ;q{C+@=E@:x_3LcDPʩ"r'*2:b.Ziq*k oVHyꏴ 3.@A/_m_13٣޽0_'&AǔWm}HBg@i7egב#arfVX7-,Ml}^ }uPT&_/ dzČ-1 e0=z$t;xhӵoܟC2h]b$e˞̼|4'2pxFs| }y2𶙏Nvn5@> ?@n2ݷG13DKsKeGPA/|i\ĺ!hd6Ur*+9(1L7 ע?&@ȇ2{i*<19X71"E\ۏ:sJ (#hz7C$"$A|-ˤ ]4)P844YhaS%&ޝ_ E0]k\]Ɖ t ii8Pe 1AEyM:@X@DAR=zTA#'?-4 iD!/ܓF3lz}֠. vm u9{pd*AoG^'뵉}ѴI)Zo(dd(9oSw3 s w.(Q@e2-Fo^uLxU 'Bdp(}J mӪ5" q(@JUBQPj0; ^ojTP\e[{;R\8R7Q9BEL1 @f (d*E^Rռu^ec0][$V+Ò[Eum[ϸ»TuQibBX2 `Ŏd8Iձ\K&1ֽm x&Ys)P S·vTb{NJb[{ݎ> 3@S ;8>G* n0X?vCz4 B J9sBا2dj܉:=h`0~0ۺ%( ϳ&*iO6|g0׌vHA9*Xڢt.jl5!DAWa5as_$t#,iON2q2EK+ʐrVV#tVe v+MM}⁖{PK<\25 Oh"(?$ 7NsE^RtJ"ƋAozh߂1%~X)A@H**0MO`Bv6w×r_0-(#_d3 Fe2jH0] ?dE>"!~/^}d"FsLʌRS l15h76npƨ'_{yCBJJ+ Uw6*a?W%bM(hkOKy燘f@8)sb*I!Vh^4vXG5flu 5-nbZBx3}$r50me_/ Dʭ,w?̕5E! $%; 963ý "Aq90j.ɡ\Zz= 7deD.?j]_^>2o*pf`٫|:Uo%<*Ӻ_x⿒bD]ϱ2#V;j~!N'V~m9!@6S,CmR2"^->XdZ!3~,aZ ]~w xY-RM1&vdXּubQԄ^Ae o/%c})J *-ۅ%QSG.FM%|g$B1 TJbrZ4s -?"^1O?gJ2ٿ[Yr3dFu.lH%IB9Uzipuޘ\Ieҽ@IgzAAAEDorPIj43 |[krb(8`?`zϾa (]#8e:#D,Mڿ]N3t'_nVV:e8Vdě+)Le D^oy6hoCuvA56Kx`Ɨƿ۫)( BH Wezd1)jU.|kQ/D}}<ŨJ֩‚Z܍ݰJJf03Õ/&?{tS|9@+$v%|<>N^jx\PZ0t$_p.GfpM\˔L;SK}E*)rJkzf!@0 A@ ˟\;Gv1".jp]CW;Wr@eN&L/(I?ys@ng+ #ߌЂC"B\͇߉R/{++(MqʧF_]Lճ{ k#]1ᕱHߥO"$X̊E@>Lh\xn2.bS:D"jyĘSc̖74LV$B(ڻˡ6rUFu0FH?^4Iڈ0I)ބX>#B~#mxsɔjx];O 2YWp03rO>PMln(r|bv\p',DUH:PʹFHQRDԗ+9m`bOm`j #B; hݻ/? ɯrlʩpZ$ҳ272ymL{pD .LZa8*Cf9+v(4 û֟ݥ&F

)7Η܋OE@$+(vGC2"hi J> >MdrOzuiȍN`m.VʶrBr}ϴ$"m?7\KgGñ)>S%cW6~jW{Z8t[9?ѝwgHBIG2eH=ީ,5s9O'0W%S| Q]8 " F e[r&D/8ݍrlhb8Z|̞WrUr"GGzSԽyޖ(鮚RE Ab1A;c @*.b[ cIM6#.z{|m]zFS&X'w(b-ŋd9]v{o.ii@v-Ӳƻڞ-85)ӄ8ʥl?*r]9)\r uDƑѠW`8Du\ɱ(ΑaG }KMlPɚ8ءQQ~'nH!.j9by&%x16(G.*fT&Lϙaw2CN1@XXJe_173)Pː /ĹM)Ek־chra".؂: M -=A7 _x٥Oi/gWn$!O<:,&CNhYZ`:~t]m\aw7,x ͪ/ yKޏ9B5)ݼg|ξn;ɏ)GF:O PhX Im/%MиYO4tDYP4QrQN{K\vzP0MޭB\͏KG4jњ`a(CE螟oPtʼnCVp%E;HL nS!I/ f`xɼ>t?xt}[ulDHHZI(OweŸ+^uqʍ] 8d&4%"$]ކk^)6`/ܵ%M7oȗnMdU1ox;9F0B0GiA$p;yoʼnQ]/{qep>omns}v(b xsgudƆ"(~QwRUaTt' wc5]'twvV\3/p**bC |LJ+~HT}jd3gfjţ3d#NTaȦѪ bwЧ;sVŵl罫~wԻ ^tqSU J?[yF˳O0tso10_meow'pFƔ)?g~xk7q=i>2VL}_K^)$Ouup#kf2v#;Eb7WpC@A B3vw9$yε=6~\y7~=|rkL~*')w1G bq\V3$x& ;F?Pz?}xwsyc9;->b4sVpuzv&lL`ܰkQ2+ܡzѦFSAQ岃;0P}x`޳rxT!ajtOhtzE{%HXrpگ^qG伛=(֣4!f;YImR~ [ݩ%S Dϸv|D0Zsdc °f}-D)_!Ngu~rf!IN7zՖ*x z:>3:m8rBKD< Abs47jӢ` ~y}CymSŪd?JRJ$ҰuEzB ~ ՍƭYĠA*ta7Rb9ҹ[0V:_ boiRV32 b/Pk/fYT*T $;>K" chȮS'iPYd1ݩ \] J(,]~/*̏XSڱ*!͜%*f _eNA;@vFmUv(5d,EߞpPTh9qp8:/=~う Tr ~9C\WlC ڌpRȫHD69l(BbPW*AЩQÎZ) -͕cmɦYp}RgTlĄ BAMh>K` Ԣ6DY5f4Y)C6ຊfT (X)I1EʝbT,P .B/rj Km'x}%||X2Q 1(g FV&EFp!0(Q U@f"0%^Eܽm4am;NG I=-F kY(u `)Xc;W-\HA}SI#;C9e,*y~ U/Jaqb妭eԠmڽ9t+ ZH!%)T2|GKj%6hDI"9pF 9iWqA|WWmuUi\~<G7h!yB58?+?S~rm%D86"HIOwF>p\Q`@߉Bi3w5O DoF  8)ILqzp$js/em;/JO[rv:$;҈ GN0Fmѐ Riƈosr*qLe mr͝bj8,l7 c^-92C?ITz1?50!)<#aRN>H-7/ u8,o[TS9k(`S1LA78Ιj\eo'kȎwe9B‰&%W"!_u@0$z2wvݑʸoD[]ﷆ1x C7*JD0nu"tgIP$ twɀ^k15? _{Jkr$G$憚ƨꠠb-MiBONVH6Fǂr샒w#*cy9\9'ýGh8QGjs41P|dy]d'y1k)Ly+@F}#E$ ɱ1][&ለlCMUJFFzQ%h+Y8I5S?*;c/uA#@(Fw癃kjP\:V "C6D*hkCG&=ƪ[>Tmd> m) O!cXzǎK݋V޶5&#f?r?Ȑd:! .Z.`ͫA7ͼȫ#)nsm+\J!dD(uM|gwqfPVq]2Jgkޑ@`xp':Vݺ} 9wH=nKEtZGVԧ%rX)LjmlIvabvڜ}X "{Ȃ{r+}fPnZ;{i6CCܻQ*^VlN[1פ]%RI0]-NCதQ)_I"Gx;d/ZVn*qgH` kˑS%fpu3J prK5-\˾Gϴe#{% "î@T?SD~&յiF!.^S\G!,=H|U$ǨIy]ܥ/B( )}cWah/ a!hop.{*ݑJO9 :]wv*$"[FAO ` " Qs"P2>G ]TJzDH~KNtS% *$VLAT Dž bHs ыL*\N,1kY"u,a\ɥT||;$!be^y8ư2&3r/Z!+c/ݞ<̒-bNNVa+S6| "[NIq+ɩ&5<"wfvۧNdQYʳX &v"ͼn$Mh]/KJW#%v)=>WԇC;'+gVnk'2-V ]zpW_v;CG[u9>4btq~\fG`Q/*fh\dx\v3?(a1XJEҮ0iBЁ'bR|(H $ 3>LXv;ۧfrjM_C ⦇:*:iC` i~+C }_];}-ϻoߗ`lH=_Ct}gzlC0s1*a%@HZ5߳^^Bk .ƙKӏ8,lIRe!q$׭MUoGqx-7ؾ{zk}%Z':BSDb_ \S%$FW& 9S*yri\;OKʍ Wg d&z"dȧWIOj0W$iPC% ~X,5=*CghBu 84\Br0 [J$< (5E+ӭ&Zx1;W1/2'J z/}\hJGnuu/+Q/Xz,Tȹ8g{ȝhP{uͬޟ=;z. ͂ 8wܨ#hcV+F%=?hy77;;{WLt3[@7>EVb;}2:.yK$ۯWfJnDn]VnSӄ|~c2Ka|oWr2S:3/2+56;1v$I'PrZ8<>R.;wk/} 7,nS&1PWཡ_zz96:ȵsn,EԷ 2e^D]U61f ( u5;OrĀvȜkpb lӅ=ؖܽYm9sin iޖ@@@NvibT'61,y 2ZSvϰ/:J]a뫷1dˋQ+i+:["KެAнF4Λ-wc͏E]m(Khl)pud ;#Rb9;>5Yq/}skn#4>qt`;pp'Zrρ:bO #ʼnYFTǗHG+,[ΧZ=e!?[NW3zlN-]R~wN?ʫFKǛOvhTk-#xl,|̌t]st=YG&kuQ ;sr["InB:zOm;z}d#u߆5??ΕR|~N=u0r0:>gؒVjPKjpg㡓=AGyC3"DDxX1*kM (6'rZ?٧ڊ$^ r<.FmNf ?7 ~bn<>ozjVͪH*]-<&b}z(iuh R0K΋>EvJف_o=)&gԵ"PԾ>( &ALgFwg|룅?h;K<]=CͧKO qBe)w@ȭTܾ~EOby4g0W"ͽz -~'Vw(G|SuS;Y^NDmt],(k8v73*gUOgb.aQrcj%ws>^}HCCˉV1Ǧ*w$n zwXRLhOxZVܷ1tsS{mSqjW&6Wu߱?VGU.wX]'7Så4 ?e\KٟN_g 䁳k'\_['8[\)C׽,fn9˳,gyi%}EYoqt;0/x?׏rG[ާj/3=gZemrlW[7߉%;ZT2ZaSky* ⢀Z0Kצ% C:Y}i?FNʎb4L$n>Z+jo*%%m:G2iz*Ƽ־bsyLis Rm(YFotf OM;I9N!͒lE/&*}Y:'pU jϋ|~.ݼĎd'h" )ieAUMX""/S+O^WXclhμXBupJ% LkZ"BF}( ^8E_Wv9S'̧B3@N@M1VS^u$6IVd|nطW*x]7/0y/.aUr0赜$(HOH:siNY/^oړetO3.zh' #=<.w6ۚm̖]q2/%\:= ED|_QR 4DbU@z[MIwpc˙ ̧8 ]3:{WbTRl*R2;0x["WB/6zt*lNa_*M :6Zˈ]Ri1+NB=gQ]20@\%T]i3t!'Àt= `.,d]{ Nİ"[Ѽdʲ;Zjl_%m?֏ bsO  ;yr4 x bڼud^W *#HInȭ]trcMߚx 1gAUqulxago2JGWKYfP3ZE(<0'*,+,.ZR(=8r(zm=8"$&;1(kS^Td!3LEEʒAb^KeBlX)nAwZܲ=*iLmtAJE@GΕP!6Ð䟻 G(F"!D6skӜrs悒߅CP %z9._~2?/ek6;R9X3lb/.xdy ʖa&W [YS7dg.1Qqj٘#qb(e6ƅ|fO1842Mty*T1d,Nҏ.+a_ nqbM 2iL9l;oS2Zݍ/vnETq=:}\ t(WHLjAC*J|}ϧ}$RoQV6b{FHzː01,__v41Xݯr"HHʪڲ<2 A ,UPl_Ãw{{e.ϣ"z ٣ P^:\FBd S9GcN3=4K3)yLW=x=K@(|L ]8` <RVZ`2nABb[l]_>6 G5h':ñN'(2c3kRH PBkF,#UO3Qظ_503DLdą"}/7 й*&'#%EdDHh7TE\צq}TK׉ l/šܼd^g0qç#Sк& /iD6 udjϔg%FعAP<8g SSɵW\L\_6ҍ z]}BҦe}jǟZF'ݟ&w aD:cgkI08 ȉ8̫PJƓ]irKy :+g@w5bDۙ*Ct ȕ˜:/0 a- 4(;*9&^VHrם5K+tq\3")ŀ^s3ܳm[wn® FSW^N u/Ǧo7J]%LFD wnjC5 adތF+QwWEm(.5U!~J6$"r z9Ӭ+Hx\+(:k7G"T NM WѶhDjl@QӋ{ֵz\TN?:IM "6ޜ8ϽƋRzL46Qljp%7۽-1*SSMK9~])PQ 9  ۫$pD)֓J@=sgO(bpQ5Xk.;3T|7{}@+W|?wһ{>x~_)_ |LܕpCuհQh ǝL{ G؍N9 Z<qo's[wo.M9Π8 XC|/t/ЇD,ǡy#ZD򃹳|~L3Z Ɠ>[K2eգ4ىFHjo<5;c;ڸ8S/:{B[3%Jy1ry,k.F+*D yz93$@|uIk; OQjT̓Et di\L` 9RD(E NwRfɹlp\aXP}QD\o6%@˹ͰrM~Hkf M%Dӟݎ4xuxOjt䖦-^_Oe:w>/nR/}6 ?3)2>"|@àKDąQ;:vy<{v#BHّs:gwi zĀB16N=j9(X1.!ɾ2LScLmdMNLg؟"g@zՄATjHi(z(KN9*X O /w_=+ b") ­Žj2LօH*\3i"++xpȑvYSM7 %0сqcIZ/$g_hγF>hasU^h0;D M}\OW\HɭJpPbWH ^ʂ:!_%]<8( IASHrznrA,;28QUB.'VC97Pxc>[;s>ՊXFbA_דE>VzQ)-e8rXݚD |D%x'oW?$ @]w|o%yssg>.z7MbDXfhi[|eՖ*lĐ NOc'1Q`ȗ\@, ޣ\M]9 $FsS} 8Axd&>/ E,N]MQ $α3hB\Ф&I-CA#'oQlKhzDR2}Wa*KD>(iݿg~&Vd|"cW3\0"VQAppp9y?mOkYs%v)[s#7"!rv}+`3w2pA#*,#b~*b/]kgHv:dw؂ VqJB@(Pd|1jB MqUG|D4 (( %jJ&iN2((l(9As/)WU?i2U)JP~?wk 7xB(aGeP4]ni@u $J1I*][2~u~gX)3 5K<^Lhwr-I/rʷCs[q} ԞLxf4i?ax &‽aDZd]6*]鯣b@!Vl2(,,q25}&G8*-z=pTy^W^bȓ]\Y]dj;[s|9]۹~#~h@`$Sī؈cMߤѥnX.v=JPs @APB+j_VL3Y_@bR9'|k+ 6דy~_[u42~>OJ3mjRQ4*3Um],=6&R-&-xa_a^R,6"مK-q2E(c0ۑ[yLTh'Y2#Tc,ھxw/! \] >l/K^'3d2\&ff eVZł"%y%. >.CRQ//or\1!fsV,4ÏA&+uP2%u]PnlV,з++زޭ}AX ;d O\dZ(h_eI\xCLKA.^yId2ZDu#57ޭc"#c[)4T4T 2O>cz9罝aqS e%-&BVykᔰPaNZ)ViΧ0ĕ.Y|iBnmF9hXǴ02o"uIhe f_X)(&njEZ!4D̘F b91ҷ41q| pp]ǒKg/?zG ng,2yf'@%*<%x 3Zs5ibDP[2,~ `bڻW%p9D(#v=m:w<{*\zඓafzyӽMH# wMT f]/fsIhک=,,Ʌ7Q5kŃ:[|voU_N(1&Ǡ)U1Mk3Y^CQkl\4p'39HQG*r PGXݠx:}M/F|CגHPL\^DH%@ T=QH$a{3AE04Hnhk7UܑAO+n>kah}8ߥ71qo|PmcB1~?Cֳjx>zg&~B83`aՠBc cКq8+ALy<ƿ?%l:yeq! oKt5jM2q2l-QGIYTy“>-Jӷ7dPsV+%"6Ub'7hPVkzg tduNm'ȆCf&DDSg>kzGq<˩~ N op{XȚ_oQ3(2w7cn 88 H\MP XgTpyE t:-qAĽWjUn99WZ0ΗzDL~SH$QS~O>CMPx ! ]h}9PM]HHX 2*GIL /q2'J"' .WXxB`֞پY,TV̪LI(,4` ӍFo;1y1۶z*Ja[¼˃H<qǵ3ˉ<["Ǣb3OۛlfQx.WUnmrXj-"L8zDLi|eٖC3G:zd>bOݾ$ɵevoc׏y)IsLg(R@oJ,>vb*mki"8׸u#Pp79o^ˇё#0Ug s]#WxpʆDJs+$HŭW^O"Hhuu:rK>BWv]1yȠ>;Ppo3ߣev^iҭEۘ/]Pݻ"%Kld$2R5kb=mau9yΚD~2*=-(kjڭZ4$I`x P8#gF Ե7<=9sW-!wV7;:QT%Zx!?D3$ yJa|WogBAAMz biQuWޢ%њdtN8{EZ: /AH;N2-u [1"lUD[fΥ:"NF 2V,aPRREAec$r OIw LC3[bu\?&@UlC(%6,;?ɸ3UX Sԏ9B eb.Ok;>,•n74.NZlr67G5f7x~9f%1% L.j%/;6((2E *j<2U4b٥J SuCPAr#!}'RQTTh'0P&#˧> lMl,J.pqئ<5ct+U}GTA#a l@L{?s/ ǧdFQ])ಈ*Wi<^][šC?=@N%ASjR@nG-c4X].V\]}Z{̱=kk](%"&'\n1k|F 7egÙUn9\j/hQJa~oy Wtk3QÍW7VGb|!.&!HH >dgI.) &Kqśy~c eH0I0V V|ܲQN1ʺ`߮!ғ%wuGc~MpG& KD|񺰹 nxqm+xH('Zч HG8b(hﯘ0{+N[3C2TgaN 7ooi2>G@H:`KZ$`,PZHtx`IFyx&rup1y6$ p8P$o4Of~(qw@l!{m3~u(@QmLOtDbjinF%D$4O[VZFi\v(e43sm`k\c]g"| cqPBKf :_! x@a!Un ~ס* tDKIkT|\eyB'CעsV(fܽ[(9 )e%CbflW%:q|_k ׬{,hEٸ\oZnLiF.? 50C\b8WHoU@̨`*خjKM5b/M<elxs(EC,Ԅf^ RUݣo.NL3(]މ\<<ޯh'T~Z_2Co?K5hQ 忁dƛWebܐ1!u.QrPe:ޞ:hN8 ؠ :WM&GҺn!hHN@"@yժN(k#U-=ݢwbQ(s]O߷ǽE*y0ƭV*;ZϓN ۆp$صa)czة nƒ=r&=hptxlCy7z]~nҕ &yKoh +6W:s}'q4_S󼘿˫OAĹ\?vosjtSܵKǝUYV/7Ff8#~Nd7BzsTvխo=w(s#;}Yڝ+$9:QfJjϩj>nN~u!K)Pd&&Cf2۴;ֳ0Nz<|q%1Ŏ,>j̼Wisz>Qu; |XJAag[춗E֖z+S"߳0@}[2ked?VK$zU^+c|s1%KYo\6*݉{et~;}: |ϵކ`pڧᏡG;Lfqãr}}5hzkyz|nn_%Ig}d6hx)UvTݞgd" S79<ֱ;CtّzCN$rG[˦F=]}C'kڃ V<+iLJ엇{zx~JtX(F%?@z_rg~wc`^ws`jށ&$]O|;H+G8@{S)lCBLN???}~3Ì|BJP9SRR94jjC@:h &T@Ryԋ\ IĭRo!@D%M0@;`@ʼnbh ? _3}BHLrY:@J)* 9%~$JT@@DO.2WÆ(^/UCV~zRş2ʡ,("QW;@ގkpdM JJ+MHw^ 5ZUz}3!ȗâ݈u)A8u^%jWL̯h;FvQs'|qhVzN;2iUҾ]\3pFUt(Hx6;Ʃt]+ Z A6:ax}h4[LtEAoz>5Zf Q,Ōפ$gijv pjj*;Jr1قtBWuY? #@_a:kh 'Hp0PR>zҴtlӺl{d,2$T^b-u]L7Zʊ6n׿/ĮA+oW]m pXskͅ11PR K$E߅udjKEw *u1T: >Շ !d07]i7%(Z4QYt9#: lMPe)X:Vwe>o5r֌@*_9toVt8Ej4j׃kVS{]65j+cp"r ,ÜNZ,x\w#57zd2L!<2< \R2<ƺ8-b9yMp^R!@\ʵ9H] {dڬy sƉ>K9X!*#iM;Kq]Ƹ;e.$fdfì/ʸ=wAlqbfk۔_fG L١}kRO>Pi)(Z%sxNh3S<~3gLaæI_X@GZ8 ̋ǙϞCOs>ؠɣ.3Qīt# ӉQQxwk+D(썿'K}e*PU:4H r2 VIFfI1Uz쉓06dH홅GK- THxA,rP[؟ƖI';D 7 cg< sjB3mIC"2kv1~kq(K7 sjVy"OA!fN/rN 3#VXZF1" rGs+**_<ɶ9d15Rr:J}6< dXȗ2{)3 eoFVXbV?|NRpdAuӻug8l5gis=;'7>>t2)ȉJTD51נyo\ȸ. ƫe,- +?Ŋ0`B,<~@D${śN7xPJBMvos'% ߩ75A yb\wk-RQ,g =^ctD08*|^W2| 9DJu42njûÔ{}}9B&  rbD%SBao~߷VL5ᾔR\nqOs/}bx?qA/xw<ב:ǍjaHs u^ `!>싼qU.\|w8sɘNDǁ~^:~/6; 3>ǖ4{>Ǚ;wJvzW˿N~GL=E=3.ZBmmML&NʦbWe>x%$I'k V0Ո'* q4#"U\>PhXxIPUwr/ӝlGգq8^,].{TV̈9LUM}>k: 7Ev͂__#B-ƭP:A &[9:?mPD";7nŠLЦz`NwaD&c:4 sk% vf0N]co7hz ,Y6)`~Xx,~ǕBj]5a26Xw4o?c q7~mpM l+qUYMF7Fo]$ NkHlXg ;^gk~ocPp-x$%{_*k}ODx\7.f@U7\j@bkA$ŬOjv*1/ę֥^K^OwK}tDZMPIճJe.Fuxחnm^E_G9Bj&Ǜ]s YW\ܜ콾?cۏx9/ǁȺYvnOsy_r?GD[s|}+hz3#$s9]^8ϤO"ƛ~7zׂkږP'{kOx_+N4\n~Oc^޺;_;}qZĹFǣAz>z}(/eh 2~]a V[Xsv8~8\ksJk_?1v** ]hO³_Wk≙ʷf'/5_=U_WSSn/ͭاUuJtmRP]+WFuOZkG\vfN =DI͓ngy> w=xhG?MPVk;9֐ykw F6LuN;yw4^ƿу'©2#Cnj  LVUJW_F׺PVzrb8}DH\#ؘ7jQD2cb\tD5,&8$J kWZ9wKy-J.WnKo-ĭ۴bJ:$Wt3;!xƥt$)pb*Efy@U: V*7XG3f8G~%vx\M9i2Hp ELCwy6iDL8 d=fHms4?oC]?qO^c؎syMH/7P%;6^}lB?ED; %ݹXT3 9HjU4۸kПrA@ fG Z e 2ZL>wMS~8~xCܵ'v&v՚ZsۻMh' ňą3^P~vws!b5fb؝]kۏ6++MhiPS5yIHK1ZE[ >4[s]Τ!_ohșZ0/gkrC)kN xQ%7"ґyKiffY!aj $QynT̍=5ҎuSN!*ܣp!|̷cS8JSշ># K]_ws ? ÍޤK%=޲pPPo]NQS-=U+x4Ԣ]x.)xi^I yo?<}ﳞ-)n{:$TDT1x\kX*ӆ}U,sy%\H]G/^ڝFnMЮwҪ:г2JL ~LFcsR+E3W~@ o!C@@@xS J 19?vwMRP1((5$7ڜ\~qZ5>'y:SˋVV =;79t7zI݋g8Gp=0sJ TV8&y&4@3|jQ'":.xŕgsT|S|Y}ʃ|')QgFf6Lb yVVbթT7ڗ2 # |d:;tno#e So3yfT fmQwגt_m`|!{>o $\']l))x '4|юgS@9{>E~/N|T%\X&kPLMR ae?fbEQ`YI̭2HMvi_?OKv)PhBV?Vn|Y,zҖ+{f8&NI͌=iśoz~*lG@Ad"nA_M E٧Əc* g3.W.Ĉ״cz4dJw||bԞf~Q9MO] &+Bײ\҉ExAe""L76J&K+aF j*"O~,{lsq^Oѥtt.9./nhBQh+BIK6ChkqX \HЭz) شbQNl4J(͞$翡&7)mEO_LT;UMXSjK(.Q,Gr-g'Iʳ*i8%Lvdi4Ƃz9]/N&$dx͉+eim^G ]+6!w_kjSM{NR*)zm~5#v3~ܜi˓ˌfemVR([2hثe+N$;lm([d9314)k7o2/'.z>uԢK!,(MooO^]a 3l@Z-=85"12"Ov(p> א:FAB" u!]+&6zV!J?nA9bDGWz^\ NػG"뵆T!+$1/GHEJx(€3o>׹h GOIIR>ziN|`K *,OqNJzesVq$s/v*9@HLᙚ"h 1TD1@$qreoOHjrGic\o5J";$6{_=uNKX\ !I}Ln,c2D & }lQB~_ǯ1.?"z: 2L~ X&6H`jVbKԄ(LsZɘnA\uc"źLs2C.:=6hWGJ 2gEe c4&ȚTX"l4t5K/[YbVL)"3|?R~o Ӆ{Ϯl=JnHq"}urH+*LȀ0"yp*." OH1D  ^i~Q(p`ώy2B D`: (~;"}dO O ,B\eG*>̍胗\sS F=NF"]0D@V9!`O0j:C=HBd2K^_G>`T # _}F}P0pż !FQBDˉH2!l 9Xb!@6q1k_*h*\%/2gon{uَY!_J|]yJpa*wJxF G^9CȈ_8mAJ4Іk (3 gTQsv쩘 ֺBiԔXBe]믯fRSHAM㬂sY\@mXm Fu@@AD~ͰFq&Ч.fDM6Hv1@^AqH*Sư," ֔Kޢ]ay- 4׀W EG+hPb7@@ gn?*0Myo~~w"4]B"[R-Hwe+Ӥڟ:;R& rSlnJNYD7tS)x&:FMI.J#ᾜB4u"@B k&3є|cݢPƷກ!AtDI[VFѢQTi! PmMܔ4ZA$"h`3tTof162?Pu]yFЁ:mt],=>~f+ X $Pّސ A«S#a"B$` Gz\%s?eqMS4{fSۡVDNK}&>;3N}9ڇFBrE{i@_ L@$=$i'8?1RWvZO~g:ez]ʔM:ѡ3_P;;T# ݅ `v=iHLmED͆ݗ"Ov2><0MTaԀ7R7U`[)sA!j :sÎ)r  dGR*5ĥtOoZ %yfK8+5_5`r4+7H17iD}_ydžHi/ЀՅI]|_~ ${2=B&uxaНw]qWٜfEpS!"Q'bI->*[fXm#*z)B_*?^ 0@H@]qqrg6fRyS5rjHZ'EHΕ}.f(`ns=UN{Jr2j`ht/Nƣz4KjJPv _WIǃFAG16l9< D$XpULڴt 9lo{F:Ae X$&3HT3zd*m&x|ǖr ALmfm :I4yћ2]DzYt-bD*1/6-7w=OՕq! I$Bae;J')LO#dWۀ߮iS]>O*^R,eJ:ۢ7df/K+HXTyz.!nȍ)8@0ɭVDR<ž(܌kJk+t8Uq/n{դ8 ; NuUC$]l݋ƜpN*@EK4^~%~۷urwp_1BP" CM@ DcKOysqs}T·v\j JCz2&͸jQgwÎǜ\Y]bTAG-kyVw^̾5ߘHc6nNW}]b7֞⑦z~":!̘EMJ)nڕgs/yB|Osq\|",Ս1|~#CX\\[ȟla?tڜrjQ9vO6&q"˜ܖL\ELTc)h]}(V;Feq#]OqY%Uh-|t+6 V˓q|VÁ!Q3@ }ZL[W+˫֟x_|/*%\,&<8zcf .WiGnR3-ڰMR|/g]Z'Cf6uFWd9B+p+Ԯ[ȫ3L%ω&Lg$dEQ9 DBfk*;I i!#(~\/]ʦw}ՠKI86IE5Ʌ3``xNC_=F<Ņ`Zv /Q(&|>[ItxIբ}I+K*B*js{3tPP+~sY*tLȈ, {LCbí4A)WAF1݊D84P3to$R(ׅd9j ;؟", 1˟x-~=3lfѹb<Q̚Ѡ^xfB9V \!U\k{[}^inA$R I ~Γ*B,%,] 6YA᱃(7RTs-AT$̮*fCMt|bt.*6/ԓd&UQOOSkd$g+|;*|1r?;{ՀfHyuB1f,o;"| YHCa菌6q GԵlNRQ81%zyo5y`Xװ'.'yhW3vD>b:>fWyfcdBao ahbNe'1(u(Lr0eL0ôiQ~afnO UyjkfdcajIGKggk&)*) qQ//sʛ,l0}2Rq'lVCFGM!-btHk!D>-4M^c0>-c)`4(@({8huGUEk벶?h uԤY*0.~Y,f]$t'M nK0O1DhNƟȯ]okxjJ=? W fuz6:\;-jTU,sTԿ/JR*y')Hb~@t[0$!p[ʪw^id@|U #4{m:_]?%f?w_n?Kc~ }w&X,PɪjEԷvEKjIH;Cx4 #~Jd[k:O\S8 D4$U$~m)Q !e4ewSdB|kIH ~у$ ^0@H -dqfb'Ǽ0~drQr_`~҈ozp?$E+7ޕ󳿻 gNP1'(>󐋛@BʂN5a fh@:E A,}%_%E8~[[nqe5 XE*b(xi?5Z*\[mgTfAjhaؾ^ژ "c_:>G~?}m yTS ϋ9?QN5Q@-=&+F4SMƩ,H0-I##XJDs0@k?& /` 3.>x okb֣g4]'҈ATU&BPuT >충 6赬 "` 7_vn |^ P7jʃBP P| , xWDD5/xZ$PX׾$$Uz yeAn[Z 𹝼4E˜ h\;ԦH (2 fFTۄQJd(0k,.Y"S@} .Zdwۥ xȺI}eU9?9HIe*=䀕DU,; =]:Z=^Ǭ$V(8w2*kpG%UG(,˻LŽoE aׂ˕BpV$Q .=2K''W<.dbM{H.ݦB#ƹh D*4 %+Yٙ1& "Q w)vrўS/W۲6щD mٜ'WӍjٹ^^R# A Ӱ(k(rt ʒk>s)# TUs]J{c?~ro>jFdoiOⱑ5>1ViuqG*RG L;rC+/YKeH\v \KĤE$.-+YK\@[S'FF^`PM$ժO e);69|0heM[.@'CH1eczdbL8t1_r(f K}9m\Dž+덋g~eee?k8J E_I 45"Cv1;y?ǧBzc=|Zageim!Mc}}[-TvRq"ν)k0H?BhR\BVX;>)t*jGp }iQ @C(D @%^{yGOH i0ܓP2.KT ּ>Xjhۊ6c4S'S7͜%ZFKy&]zL)}9gyzV"刳0tqQ8-gb6'>7ȱNQor!Ċ)hioۑY.[-!q3m`>ȕI]vNԇJTO6~mw3$9"cƇXqa}vnU)J8^g!H\ъPQ9ri=ZA6{A54)밢)NMPle?{ _ #Cl`d敐"c@{o%@ ԊރY,=1P߱2J& 9(Ĕ<n*iw/gyjP*kl/TV3k^/,;_eS$O`e2#lnpkU 47a o7eHJ2WGze ]TA(XY,[IiJObo#/ 캜F^Ky{y[*Nd+:̈$A*$$@Vlȣ v ʖYgD=Grb$&N)%` 9BY%J=+M7//Ύ( ėaQ* EkT8"xO}M]xfXQ$X8` 7|vXbҊ]\v8tqq15 "79UBB+Qh=NZp. h;cHfm`SL'ǃCLv1b1Q(TMXJMu^.޽jZ.~5WJ )UZyr70S7LKYD\icǞ*`,f^qvivUрЊPGB$-^gMyQF;q5XaFg6ٵnocǼƒ`О497'E/]BL(_LFZ뻬=\;/Zj!1ZKNcٜք'JWg0jUE~sO~Uڎٲ* O8Rwdvza L֥¡Ѝ ^9]0e1(CT85vV"]#Ъ.!PǍ$+d 8WX @DM"$\n:)#lCxUjDT>]fHYTV O]@~6Lg5!M0 % h ,J 6 Ie y\WpE{ ?{~lc2 ({EVS%^0?h}O# f@tľIC(oT]UAUXԿ/0b z^* T=>POh:9l7\gAͧOZPdB0`f_>7wzfOj0*I1[o/Y<ӱs_.)In\9sP@'=LiUU>MOzV%e%aKIHfGwnmpZhZ 3th]a}&lHL\T~x)rbj]Λy4-+]+t\s%̸Pg>~Z\k^bh@0nnN0"(I$U͵&,ܿ @xhV BR@9c<xIJdGіrJ9+Q%-śsEK eJ3* bv˧}Viøh_|$ޞw-0Re:/ \4C<xHnpHf~yw4#vItD 1~sZHIG7HGHq$ߝ^K'_*ՋT~Iz_|Xם4@(uER*&H=Lb(Awu#Oc\uF|d`4eWm}-D[m6\IK2䀒,]/ҡ* _>r45UP ˌ5~6CuSU}+y1>o:%whW4 /BωG)b*@Ÿz ?bN03!rXc9uWy(`%D0EI "*A-f6Li*/3Wv^ݫ#H4 5B h9 )>-U{5_$Z""t6Ir T}SX:c?ԇH H)S! HJ¼%0*6!sf>=~2h!\(>!FTA߽}1 U5Un v01&2 $VO^R&oO2y><3_&d@l;KN8 ̻ݹxX;X`P ry{ ʂmxg`0M7qۯ/MlVmXX?X@6B麆:'?D ?hXZMzST5 ?u@㥖Mb M!`Bs -v L)XBg}uut@0*#g;jnQ $kz?>!1P8+S'ֻ A鶩j%ڵt .PU!.'+++o1wPqk_-:ڰZ>>Xҷɞy2SWëCMsc= Rg?%A!f?\AZ7\1tXO|xc6>g c0VI{oc 4Uy`/+|% A}d-$gѮ+`dH9w_aumHku,O}Š@LD >Ӊ/~d ם.SDbBmSԹ~[=沏T, ªT,Z,}ŜƟy G!@#D zj"m5i*s9?n!sp5F_{7݉w1 'b3ͤ?O`ܧNE6(l#uf?uwVd\U$ Uz_6# E *PwP϶b S%P}U sEQ?jyta31UB|#9l˜`9)"w`Va}=SN]JOu־6x3P?m{^hvw>ϧm?rγZao-#m L)69=t<}r9-c̟)||MwN$JhU=4""DSi(V'Y_K' ˎ4]?c H5_LNp:/VbJ0dƢdo ߉$[*=_'!ie]86p@zÜ~y|SVJ|*I^My0eN*;3FʚmB(mClc҂TGrՑ7=e)?6(A,ݦђDllmnIR-W8UAAA@t)M??#⹃]?8ѣv Od"B|ҕs u_T7S$A~_()Ha+)@A? p7wbu'.?#?ۇ@!Q22WHVC|iֻ*-C^IլŬ~]鏮TI 6mr;PỗfSx=nv>A5W(FjTxɵg%9Q=[npq0m4qw|jfnVk0+RM!&L^U*,0%]$hę}"55 X*L;P|F›<͡zlWRf?MRmV:,ɏ#4Ùi~Wˏ[.bQ廞V3 6ЌorjU/oJ.O6e96a5f7dwrݦ?ٜu[ A"A 4E!m푑N-63cM_f=TBHs} 1ڤܞ|*;lWԩV.!*)lli4a=\bf-Dx}:t8 :=Oz1o(z;82PYY2+FzVk:Tw}%$)G"G,M | {(צei8,wMG1CDoK,Ỏ* ^|'^e`X >doeC$5"Þt*}bpdK13;LAؖ} jzN a:z pл]i.pZk>2Сm CaF ~fL2kDbfd`^ ~RҮN~86Ѹ_Rem+:8}*>^U^qoQv$HBPDQ#2S|ݴl}?30"JX@ )bUI A2Q>|;nt9B>ib,[__b{E#BE?c]LӰ}ih|- T1 .jbuaNI/fWXDC+LJ~qL['}1 Oʇ&}@:C|.Şz8"KْHzk>귢ԁŋDn#/z|x31P1sSQ5 >*x; "!FFzojF3E|VAuj;PJqApl2]*";җjwpѷz*smOhIBQK Rq.<YB[*!v^&QH(o+{uՄO+6cAVˋj b$tq"`x\na Ryݯn;쥋^rFt `(qI:q0iDS|ϟ0sn$iu@+M~Cux흂fy+ݛu &R|imMڢi4|`Ҳ bǫ&?qזּ&)UXz cy)1&GwC1;5{˟,a{^Qs"HCg#[S`hHj[%J7fy&݈Q\UxhZ MV:)`!5,MI2>LPeʔB#B(gߊb1 ,R9M}gF2hr_8D"X8l7{lp@HQFBѶ ϒ0ց`ƫ׸\7bp6WSHڔZ Qk..;2᫓|*^](vA\/3^uhC1E$/|_ -5 bՖ Utv2߭Hmԅ_gf)@(3Ij(y8&|[~]zFo% ص2ذY,1[*(ȁ8;>Wv=xoή㓲L2W&)עpE$0&DF?XU-^FcZA) P 7΁P})7D_'G"*Wv$x3l,+F7#[6>t[ՔG#4eTAD\06# k*Q%j"C>OYt޵  [n<(P¡Aaʧ>.4l`1ĵC[Cߡsܢz/1 @a_E %1"X˯;cue z_R^(}v9.nw]cʕiā`rRzaV#M4K9h ?&|vVة!Д"}Ɇ+ Y?C QyiG4|/Սok mn bTZHș YKߒ`HCMo?Ɩ^Nݳk\^,N[sڠf=j(e?']3kkٞ7E Z/ >.t!JPn:Xs pGJzP"ǣCH4U#f]? QCbq&s@Ƃ!m"_i(nX"/4dNU: x DH/R,J~$I[­+UAC54C-,bP8A7GdoeR*/bF,4Qa3dukh@Xc y"O+Jk٤t m c"IHzAp)&}x$k+JkHEwҀh`kj+ |>.yOlnIAާݡUd72"БNf{c@dV=nW[G(避: 2( :h)'6y\ -;f F ȕS v lvh iR]*)91%,2!LTV1ƙ[_qW.Dt}0p(ԏ%%yCȯ$Dq)Z *_ڿR$w @WdIok+6{peDBqN1ZoZfńi׽9%t=8 }4H$ TzWQUXlő䒐B)*R>C& \g.3d8ZZOdad2\Θ"˫:38 E{ )9)'-W7fGoq%2xE ^/%ht>`hR'bnɅ猩pH-g8X9^ƊA$q2:1MEՅn<IŒCy.@le`_'];Q y+6L[ <߹mdQB}Fbny|iíDtG&/MҜ]!8ETQ7Ŋn qz=WU6" 3:sR $$[#Xk^=KכߺyIHmHJM=)-0rpdL r{P2e !"ݯ1UA,jG\dw46hxy??G?({R@'+啴()ycmc6"]_Ԋu[Ч|`{œW=ms!gF@IJ$BE',[|.cOxLʟs }ޏ{l;|7u;r>%+pg?fh/ش9h7eI}_ZF( RgGJ6$"52/^O``h⽱͉8dHN>}Rcf z`ڵ?Q^`!16! HSME81K(pnTY AJ!2hȫh%cu?tl#] V1… JQ|^DQ /UTFݫ) }߻&&{Ma-Oʔy.hv;m>sp'}B9CpC7 [YREH2Jt#ҝwR "(@_%B} >pBW (tW&Oїj/+㯙50.k󚀧t=1fĨ˹aUL @J\Ϥ2)F؏@uKc]k:R0ؗ|(x2W-M 焬Pb4VQ)3_C_lYxn2EU}8|_z{n2~ Fa3LI9UEHT?WjM14 %N.+6%4iKEExhh)T!ɚO:ųM8Pъ1ixC=DDt՞MK/|ņ =Ķ¨ZEŕ^[^^0z]LQg&AK>HHl!uEkNrM٠/|WzeG(As9rߵ65;t̅!Pr_5li]4+rRV)KE6l؄(UʐnXSBP}&؜*ITⲨgGyqC]$堆Nb^wpXx0#wASa>{'RJHIJI)-v.|pQHGڤĦ%P)-14lf4*6tsbsqOAk20nmMwiID(RTd4A3&$ВII>z]؍-w^g2sQҌk*dh3 )@PgzU Xi A@)ATEmQ_K80{vSIP d@(cB4KhS D2hVZ ,Z\?j +e- baEh7sg8b[93KÈt4ʴ&m)Zs+"KEDS&;7/=2SLi;g;`s}+…2M^0H_CTޭ84>twi"S&a3H&ݔ]|W3*FUB?^c{TYqoY.G_&IνGW''ViKRm#|]+I)8㱁L4Yĭ$y3":$L{pKh•R)7œu;l.@'W&lʁ ̋a ocVyĜR7+aD ]攷b ("Jy~^f"xOXz*09D!R܍M?j(+hp7҈(U:4r V)c9{ةb-)k$}Q}t2M('m߃eXuMhCÕ- J"*3)Иh(8E!( JR&vEv~gC-No0Sg9A}ႝ 0IMƋxȸPvLtYf̩lJ0,K54c!E&TЅQeœoSsQb0" (H&or˛Q>3 oѯ[>&,s5JZ( h=k{ȹ4 CR#^WLM̧! X]%t^LO[2z9= SmIEl?1SXדb6KSRͻ َrp-aT$)qEjei'-tdFyWR-צEVaz6q6$76ƠS/Yku?M)sHa:n^YQn/lWbP=쵪)M=Q?WBH"Z2yV\d}8/X 1bE͘)rU,RiSY;ͯU٨^~[ܩYNy̯@iW])E?%Hq(;E-'f3;|Pmkicrr&`893 ,b^W/cΛ=콣{07m1eg8zYr9?A#Hng*.#H-´ 1`DiUX$7VH[Fi)Yf|y:] ,GhOtN3i6puJq39]G\H9abbPiPY)87;0,1m&l*kj'ǽwU[+Ȋ± GM 1j{F^ @S2/Awî[Doq\-ڏ\tӔt O;ƶ"kd~r1Q9{k!/\~0r舡|"VAvȕ`{]u>;s+`|$ƚ("bÒ{}_`x;PO=ߙ+&t-,DRB/DRVU8惍.Qt%K"5.ޯC`#Sʡ!. YĹ*=O:h(:i)>l¼ Fbc#5YPr-ӢCnB2܊:( (\r T sJn(e%$=!hKtޗ-5N7>E7(y4/]Q %fq^o0TuOw 5oGLoNR) CpӶZX)T%Pl!Gp i(\'g>FkSRRj$ Zd79}= 9 )֌FVKP@mK xJ|4H$"EyU?\:)A0^,dOrg1%{zl6qOq4c\B$Y2ԿRypǻDi 6k$RpԂ.y#YCgINJHP6n_e>ɯ,3׊dN˖4KHeIKh[ϵV#uu TFT{%$J73a˜2 `Pkϋ p" {'8)+ѣܻD ԋ#at!enŲkP J}c P1^AAIm*VNS,,#K,O7Z(0ӐӌZ2kә$.6%v^L(^$&ՂO ŠvK}͗ i´ =(WT @Pu1(4*$`3ۆ'sˋ 0$8HCY6i&3(Quj۲u9edBFXE48Ldԩ)!9I1uW%5~*}|UUZHA"f˜+4|]#]+$n>2qX-0[;@kݿMdt xMhr\p.EY"s~YTh*cGF MܵbF1uP@YC8VHSEw?X:_!;xmK ?2RQݕc;R]#FFƢwFct5;Af$$LօO[&*f[aDқ׮ Y\8qnr=߂tt\QU)@e wFvng;cKU!6dy-D`|,MRԻ{Ԫظ֗ÅXëE'p3aLt2k``(3*c IíCƆ٥ųлe@82Ɲ&qd lud C1 qi#"<\i=q:U'b5 +6ZBOY4 Roh8@}R!5JEܲbhnd@hy:X6Qf xrhqa[X}7ZKCڻN+J͘k=HFKCXP -U*RE!K⑂HiQe /S nj #ԘTKApq%DH/=uKѡH-zHBv>dBjw`]-qRTcIwJSNќ01AaQC R0.L`xon\ ȸHJ$A*ަj% j fn|iR{Moq~:f}' /2.C\}m<~1j,j>dԅ([ɓl)VZVpG*xgTL@> Xsr:DAhD9&hG! p6W YYO"*ET,EZ$6{8/OK\*iϓ-NT˫ ogDǚ" # 1![8a:Ur&$5¼&F'V`:ΑãY]7g@eRӼ5ZpB^f1l:5x0v8R%ZːZ,j}n(H(@*Z߹ jP*\` M*,!*|R qU(e.SGK nR ɥPvY8:v76@t7NL8wxWYyq#>ĸ;)l@]=KB(z7;Eq7LN0IPHsM.ZE+``e7OJ1IF0K"#1&Ynj(Q&kś1FeRUZHGw>RUbb:ȥ`^EIXgAV!/Or%VPTWƓ2oVvHckvJn4J2q*6k$zbGiTBeJַ`%a i\sm6&{v5"ikS/{bl[(#3+zD&O7`O NA憻6QIH3FgtV4=@]11UCP阧.aSH{%+8\ 0k*GK^6s5L&S4Q&~llhH7xJZ}d͵c%Tq3o/p"8t &D=c[`&ʀ`T=5h;) "TVR%_,|E  k̗D¨eM/8xwѵ'n..JAI JDɉO5!?w"Hh>h(ݭ=ATE{==8$i&Ta$eDQX"$([8/q.S{YŮ R~+V]k6.kRX sRZDf NXmOעY/ag0_q`@ϋA*S p< @"@ݽS׸V*iSI"> "SЬ*iVhKѠ q:速*PJjԻ[bx@d:`b"⭠@~+;E-XO=:L `O>aP?'?K LE aXWXVۺSV݊Rv^;541עzŷbI^BdDvt'J4ʅe h|5ߑ!i9#Sm5I>$*XL})A'imYoe+9s $1gR*_ԘNrRտyqoy$m"T(1'/ァ$IY0ٶ{*tDp4@NtvM%<H-'wed=d lv*-WB0z("A$<!Əݍ)pEBO*PTؿ';3麜`BA `_s~;ai( 4 ǪMf$nYlrfr `xl#]t@ukvhDw-\``vǥ͌zN7x""]7%(\ZnRg3&y|i>`&wpkS<04C+}4bړ`β/W&Ev뻽W\ROPez1k]0fO0J]u[ZVD=[ %YIc>T沙k\eX,i`RF1GHΐg*T" »t~Qn0Wϵ1eTѺV, 6ecC*h .rK g2QNZhѠaIL+& FOs262?Ĺq`ilX9Eeפ@>W ~G wmEna93WA+`Ip\_v] "%t֕h 4xE94jJ.5M1Ԅ2P#ןޔR[զ Rrn;C :siX(Cg䈁  D݁d4ЫDҥ"#K. ו+Wh V#qQ { (C+s%0Ǿ]nV_֧nz0/A@{|l#$M=$#E&Nw 5I0l#wj@x *¶40MZp[HciyBB]%R%U!O.ÒZZs)qbEeE& UBuK.U}o5hQjƝ =tȑ#,cԨTFϓL_'=4Lk3e7rtqOw?Yy4gkPm0rY gOЖjkt4LF–D>G}" QD M:SkW#@@ 1gRgLX39 Pk>&W{o4΍v6L"@`iђr3L lhKTOCW܀@b'&|tXBҶ]: Jο-իlU8ۥ;unA>VvfD߷ D5)Ja)vÝjT15O)QsmL]gg*QH{bW rO )wY-C:#Hj]t)q73ͼ!Ip\JRpP߆R"6lkfRV-SQ]M`uLں1um ߦ({o?q͑|ՉA0)mE4L]XͥRĩ O G ד1(RA$x^ZS)zZ. tf1"3"|ɩmN)?BVQiABF3 g5Ӡ6۠9cZIJ +='voޞ찿qyv|ºL|aj3)vX9Xp.JbQ hW=8?993K}_d],AU38Cj+uWlBEsJK0PJ6fPE[*3 0̢:)%9[ \S ؊ 903r:ֶ-L)*LJp~I}Qw3Dž[ak+bUO"hD(1BC u.JY* :f{K\m{.ѠAQu ֚O%7 2_PsJъubH`Qkah͓9N.BBJ13wGYd uRX(U&#\DFܨG[ 1T 0cZ&*S;3$DޝY̗ /ދWVM||O)qukbHPUT'*1$s'f"%"grynTwd4+9ns!/Ҧ)6W8T8X@-#PPuGA{=ZN{ dҵJ:|VG⛘ zR:q:RM&8[lY [DbkUX35('QFƟOʉ(Y<{H<(# HNp]!.?;bʋEs #Ho29x.ckԕ(R"1R9iŇ ԽRx9,JAx7֠ 1N`{5*6iESK"7s-B̋MJp%n`Mȴ>M;&4@iqi? j ]L^͆/}w:򘴅ջu/Ƞ-`ȡy0b-]= ZD>(GRzmIs@$)]e +F Q kMc$rʬL<k.\&|]~q95gNi x00>aH<z|6[UZuƭ/Wf(z.ikk6*EFKzZ E0{Sj2^cHc"x9:$*ee+B#"%"xrٝAuуlu y`yY uBnW3T=|IqK$-Er2ILD-Mg$YHr._3?6Tzb8p)äS sF~UmxR'Ɗ`^͍DpaT c=CI]U+^99۹0HJb)I`f lIAUҴߛ<#"Eʞ|qh H{3FzYɇSoL0|FH%L+:5E9\#)UқSqO!űt `hWM!WV3 0f_Atw^hDQ_w|ѿ:Ύ^^ˮM@RRbT:(v|Jİ`IY eP^Yd&1GFa39&9CCa]!bm]@[e#I E%);h Lamv )92Ys5B/$,YU%rJ1=)nNdՅrm~SrY==@#<=Г"qݧr/%^ҀG(Y @$O7ԓQ5 aMACO7PĹ#oiNpX XxEンoօU'9T"]E{L)=l՝ )QJ< `y%u19/i΄ C^{=Iga 0,_M*(q,Gp|#pte0\c].1EFb?-ABd El@1Gb9VjU"p~Y $@xp-v_B^[]7GQ,jsݤd,0#abT* lF{UV 'jG?:+6< 7.D4pje$Q>tP̙ 5}ꮭa;AF$_y1oYƫh%?{D(:(qBT(eH!* ET$+@ARlu5ʮ<UU$#$Q&kӥpi網i7$@bGƿ{Ɓ$4NPj![՜c#^:! eUZ_\Q \mϟVLbeX-3p8ÂSZ] /@Է^h)4ՇֻNqvarYDLUTeخMd'iљ7[@|+R@̧S:+UDFZ;Z;3#Ӷ;U naC߸JW$` ʜ"k9ӕA*P HfIsQ?݂kXu3+a)uN\qT,9x6f+ԅs`\9,PaF8\R.휓W7Cvi+C@,:Ξ` }\ux>re!3d+,"C;ۯH0i0`wTձJ^ wW$]cЉdC2;X~bW#*'"Xn# e7ftd,MyT:S(LEw1f;BH^{9| }WR]1h7d@#% 4 8ōS~Qu$7;,S);1Y9(//)( Ϧ|. ,@QύiCw6jf6Y SMfȚVl*r T zt41c^sW֗&yh|+M]_9+V#݀?Ѐ JDf!Ug0<)' 5DxΥʘttqsETQ^dsES!wvP}׶C"ꘕ3H+BV$ٱԒaZmU/ނ]i=BPn0{4b,(CPidhf+(T], 8:t\FkYA&=}C!7QN^G5\h"O;)W4;.Ÿ"Gvezڽnl!pwa8"* S|Ԯl&r*MCBmm?Ho4(qJç&2G l\f31* 5yӨq*==0#U8X63G t4 Kaur7=6H 'Izd#^ oR֎u lJwʈފۓ9ܟo9Z:3֠y[!Sl݈9RV4WLJ_*TמP#V>8\֪H @P|ē_{UBG9>L!VlCٚ^y6FXJեc(#TQu@,G BH:۱ܘݵ1-Gm yR % { ! RǑ69f(o%]sB2A񬪹e8?"&8vI:g ?Ϙ.*hJ阢]QDcxϤe 2Jѯ1cqLE` oWI1+*S]ƬSV: ֻeB R 1/I*&RfDVȫr>"\zP bD"̧6\U+cUmsWaG%,MKg B(> BҾ",g՜xB66@f ţnh{]ZO^s??04{ѓ?8N9 $c<4i@$!BӵCԃH:SY0 Ū[ĂH4. FiG$TA) (z}$BB4l fҧ6B=KHi^Zv)JbKa!k%жߨO9o)|NjѐV6fWB7 BZE:UEH oA~eK N[*uM ZrtTRPn\)a\rfB$T*M cGQiR=(}*,(E(nϹOz[ۡTH7$`뤣9QqBtPxUib\U͈ rmf_ aT2AT[f9RJ B6K6P*@50B6C5ؿµ]բK_PFhi[jUA3hXr̒֕Ьӧq+o~-%<5^񩴊Reulʃ0¹|HMUB9tyBG9bE>jyU5nWC9V8p ;~4[C-Bqq*@KBc~8<ٵt >@߯0!gobO|{/q AF*,y>s瀥IB{ƥ\*=zTnggn:V$lSA`A*T(O4[7u_0y/l2x4$pmnw\[SfP;s=;fSלN7(Z? ~ܱSP$@() t^ϬtA||/} %it=B1ej@ QGqͧؕM/aq0SI5ҴP.^[ul9M0o{$\#'$b`B50 s*'qbֳ0%q 68Kf[/6elI*`B? Ęt`$B[?5EZV*n~b( M{iߡAء 7~ @"Z;@ pآ[.\ C+S* j;V?+AoH|*&yCm=̃*bTwUKkFpjnSR=,ݮf5PA&Ȍ~i'xJxUr^1q ؓaPPwղpڬpanyx83Y8/ԪT3J{a; z}r /bjR7Պc (':OOV0jHtA #>(0IF+"lliSYkD|阙F~1g XuT3ʢC:WF+*/ww ObV=VK5r`yZ$eeK^otIĪ L36ynSHf1T#h-(Le^ٯR I(9N>D00lPm4㚽-}\RCh=(cdJ*4}L)<Y!,8~adH7Sڍ J\`2x]^ v ۭ0eBD^mvՄk#6^ËQZVPy B\`ĎBe*,]Ha /&"GGIHNtMjV Z'cfҘMOq=EŰ3x3B =''XPA!-UE M ` qI6+ϕDrЇ=A(t.1X,>s[)BAU8HNVsCtMJRR;T0tAu<{qFCff E!hͽtZ^j0zI: #,RJte+N"G 2=> ^UBqvr4WſU~PXqDjI,S밺K2/ȷE "Q 4&iӒ{|%1lF9{N6#\iVUmBL3_b!1.r>M\n57#1|EVۤ )6}>0ȢdPիDaU% 2y\EX'n_׾uh?*S=+Ra#w濄O!كMo70DPK)9{?ޓyܶU(R+|ueS71oA+;Z GBO_'%#Ů Fzi (RPQUYϿo gpg敖q:\]V=o+HQF)J~NVbE]m#F +)aď}B}OJKȃU^OhmEiӄ#s8+ɇ`6eՆBgE 7ut\)0~c)Amgds{ j1rֹ'ˡβ3MMg'no ^q z?u=.jun@y|`AQR;La\)BZ ]SrL$kbJVM"F2X{ ⫚ qa@r"L'TH5Zry@Ƒ~BJUePHR@$o A(Mj8x0`O5_ E2^]%-Z3զ iP|38z7 BƊ S<0hIaY1M =p@VL8v~%M4|I~ V|:wHb|&Z/"fo t蕛qeP'R7(%9\2$ {gkrQS2h^:?MhuYQpUuϡ O7 ڿr9j"FENMk]ͻ}yq']6I8RȟJr`]/l島:;{ .qZ′ ^S Go^٧HG Jo t(!m7[k\LϜ)}YHPsK0|A8<}|qpP#"`B># qR:?{ vRY8ȵ,3U OuVۑfv8!lvJ.XmH.z,Zt;q>Syܑ"1ib緭 -+u݊R JꄙM~Œ$Pİ?!?9S˘oZ)Y}ztQI$f: O^W؂Hљ:U*dk}xolep8H7=m2-׬4P~syYniLW4I|:Ij\FӅjxRhRsRATP|Uuc:aR5I "$xe(fg?"@__m5fs8v>3eEl hb%5\o3;?#GC*ͩN!:cN6;,{yn5fE#PQ\50s!1o5YI zc\4dI( =~]+ Cr{K6\Xxتlkڅ Wҏѐ֍_^x^[ruuAuIB[?E]fm!t@ޏ,ܼ1Sq+i~YXy4'Dɰ0 oպBc[9U$} mʎmvO-9apݬc4Dl_MoF֕h oOޘ[g(~y;D,Ϭ(<8|r95"̘J6({ h@Qe۬lK(9]OU ifc$رQR Nt%WvfZ[:Rz|iPN +qIYftBć|aRuP2.n0D]%cKD9&NzzP-bЋ B0q.eoAoV\tiakFWgT{@U?)lo4uJvdvu02?h"$bȡ[ >xm{X6Et~X3:`S =A~ir~"T"K w$nձWچq|96V/F;2֯}d_A?k\$[<'t2Sa 5:qz涳Q vsK&] %jXqA9^2,i`H3Z 趉%:D(=cVVe!EU-+JÖst7^wX1&U]r b,U"!2ȉb_T WMEF枣uw{Zq$΋˓\(ǜ|@M8 =)Q:Jŧ b']?߆H7C1BbQFj UEg Bݚ^Qrf=љ͊VaJh]ԇ1|AUW ]z/B]U" ܐȁ5qMƦY9o1 ߔ;$s.B,7r̺; '6Psb/%+~dޗC9g#|ҕR@#;j,#P`lY;nUvI1F%bX_Z|t Ae’ ]STut [w<^6Q `ܬv'$/a Afmq vE~t>z$BQPEQas?[TDUx|_ tҮ~+ZC%I}QIGb@)Km]L5wK/6ռJkw>z4%NP}/ &?~qI3ʹ(.1Y!⯂Svsw\WhKDɧ*.LEa3xP BP3"@͌~E5U͋t RkhwDy>Cר &ӨҚOR,-RnUߗ3GC$*7 EJٹmoî+dksݝQ#0 A1`m$(Ƕ `h]m{;:] |ye%؟m=E0d>amm ғwƼ+ӰC6y"Np"]>$v@ =xF"n+)_nC9GM.fR(b➫+IC0i#&M5w>OFzAc: hxmJ54}Mͨlxt2dUSjfYP2)lhw)bwl|gCe,Jd$S0&f(AB>¾بCi*SJqCʜrf-GⅧfC'΀?aOx0 Xi%D3c*򟊒)-jR왊&-)/ ,Ξ3ݽn\'DcJrvZiM"Y"uG%qc`gBC/~}A駣/JSZ=tNx{z BEwHOrYEVSXMl`IEG7iI :r/)U}Z5hۦn)eW&E>agT$꼢,a(r%R&ͫ_2"4rnlU)T*fZJy 'k:>VY1OS@sXW)-&`Y򍻜x o~h/4v`"{h^ua΄jX"+!TP`Uvixh* $ҏRl#tiS|+ű J`X68V8*Q'>d0<[MgPs(q=qb &0B h<i2҇gۂ}%U !(IU7_礹1_&V. ?Blg>b9W#bq) SQH*ӂC V>*9\OۄO^hCvN S@#__s€(e&A{ vkkaz eW=m<Kg5oʦ%iƙD?z {Ql~B) |K6ŸЫV)!-~8q_{3FT dDJ m+]]e|YP?A퐩+m y^0J$b^npr&%ͧH4oR5=,$a#A]V[*ؖ0裆iض"@d*cp]T)&>%A6SCi6ЬR_=?gM0^E_z / }g3uR .!"e*XL4m"yr^o|,;F:̇p YY"K^CN#֯>̂+_f#DzÌY:9r§zq.Ӱ"]1xWm֍͚/o|MJu@eP;>FszPRP(f+I7,mC 1`y!]Ҁ Pa}rp.ӎ_ɲ6Xjbu4H ϔh-$f1o:)*ߍ٘Q|ro00{YLc?N*w YP#Q ᤡϘQA ":p>; #jkj<quehh 4gD?8vߏ&AL@_ݖJUb}<*6̑Ul`TD!p[>)y~~ų*WVH~k# Vj3yRb"馩Oã^[53dM DI3,tz>< 0HJzE Bzg~\HZd_Yl_^^ ȆD/LyXJx}ŪRw789`ǘD::K.o@(V^Z|w:JSqqOc)aJ1O:ktBb |2OߖuhQu_L H'pOEH<6ttjZ[5 I^˔7o<~9' t:OΓޓ@ v3 9>i]#gӒC<}1S:uQ~z_Qzg1_V (srq2[OI4cvۇkV>C; A~I=BBJcK~n[Çx͵ tڕzNk{ǟ1^5mĞ7$ 5bF%q㸸ߡp9za9`߯H}DMz JkB*6_9C$HiM%c[  ϟI3^| J6"Sڸagr"آ,0S>zmIOpr mNZ&#^F|L+j?-wJ" :>!g\3HFĀ"=XyWufDE3KJӮ 0R Ӫ1I6 MuÓx|*4vc(X=Z5CY{rdX꺁O&!㪡5#*tyK6Yez184LƓ&@3zD<dcXۆl^݇Ca)R \Hھ!3c$$)],J8'Ɍ|pAɍcD1A8bі\,zlp7X YtpUƚQ|c艝{ϳ2JvƑ=C(/:ňB8$ȑ=t撋mL@)٭0SBihs[y$JX_SDӒ}4M癏 7uW#r)d9lBg\soeV jRv)#R: )rtM*P1Qߪ8kbNR("w\, _O~Ax\\k4s]s"Ol(R w3[2.^g27Ap ecWc̅ti B`0P3a9ESMDq ?,tŬK;ֻzT9]>B~ܾ{߆w3 7 ՝{2 v ҎljJktA_Gƃ[GF"PcY[nSO=nt#=f\e(TJFg?˜f~̔&‹1F>1#*8xo͊n}g3Ӈf=緱!Z;_ಗMZtG^<Z4F[ 0[F'Dk @bd:ae-Ǵp>Ŏ 'gն?j8运,4hQb6 Cb4FmuN;N>Y/:OEpc=:7~&ͷe"A"A"Iݥ/s2ش1nWҲWއN.o8]kedߵqGhNW4[ԓ46NCH˔)$L$ #hul+KO&ƍ^+*de-#+Ez_ː5O="4;`G*V$sQbW O|_O#c&{6S9c vAlm^S)TQO^K",h1X} |LNA'=OOL43홙0.epyϘIQO*<^3Q[GY3 8Յj$q?uEGnIT#v5{ˊ*7\Pm)~ICpK[7!IN1.Vm*@;+DCs]\ Hʊ<`(3 B¶KC~g/ZT6֎_җgb@#Oߕ.?*>6ap͇Μ$.X`"Bc&:Lu>|c ,=95!BCDA7!l Á;vv7/SLK|(ʊћ@KIq~ͼi.k! ePwuD6RMT˧i8:e%O^]CZDj0k d U{> VlaDnm(tˎdFhT* V>L"4Q9aDQJ{w_O@^m^#ݖ ~T&=i)IWLh' %ä){ ϗ"EP S/g /d__vn§X-(_]BJߔeF[k9 U_* 7RD7jP 0RgUQgQr1R. 2 ]E-[[*T ɬιF%G1\&T͡JA {|ӬD.Q6vuҥ qО83{\l'iAޡ}/ikUɣ4FB"g&JW]u=B=Tkoֆ,-ax [ʿy {1`f`q )0 e%\:%H?B'~{ LbmǢn=BGuTbt3t` /KCCZ|#Yg-&xz YՈ,sIh0BP%JP`v# Hz&t[.׈Tl'.):<9A=_yz2z<ǘ8}Oy7R1ײ-6 &ylQc󞭕LPgZۮ;}bA>wC~䀼}>BU$ ҽJl #iFGgn ^f0o?"Z.9h'J:jA "jU83 "tHPX>RO^M4jyv h8bFzP~YSαU(6ur63 h3u7WpHTO$̗zEƓD5#|k!}ᯔ~/Zճy|~+,j.ʂq:m=`pɤ5YN855. fYd_XAUUp9{VYR=* QuL􏰜VhjGJ嘤5,>v30 s9RT{*G7ݘ Kl" yE:PG"L"* M%$"$a")$ I0M)0bmM,HْfP‰!2dbfa#& Bt\eGR8QboSQ $Q4ƚ4fJEd1d-ckEa61MFkQQ 2 4H!2-20!!i6,Ũd5PhѴfkF"&3MUjj6ٲi0`#B!i @L&PRFe2M%D#,i,PY0(di"LF JBP hhbd3cJESR Pʉ$i`,J2"QZ% Ѭb%Hh"i&feDfd2!c HJL"*(% РRBhQhad5bȍ*4kJeQjBXZmdт-H(aJHHE"F(V̥#VlThT[#"[%AhmF"bED2cIe%%D d dġJl0 XQR,D%M&5"E6*$&I e6-1"lSJ(M(!2b0́ 0$@fٴ@T!ƣFK5S$FjDHM4$DZ+X (b EB4f#(BFE1A)(بɔ6`I,Qc$J51FDHԔE`PPE` )6DIH`C"`#!I &C&DQ))&b AC33PH2Z2 أEfiJ"JLHFddhI`F- %A`13%HII30(,53Lh 1&`@fhVfI23)QRbflR3(,FDIA&RhZ Hc6T&$J$& ,Fe1iI3fI%&`FBXĆ6,bT"XԖ" 1Lэh e$&A152-hA͢"MM& d(Q i#IDlH$͉6Ţ64d icDe,A 2deCe$04Q`F 1KbQZCb!!PF" 2 J3ąfDh6Em2Bhb2d#Ii("X &QYXţ%hج$SbidВ6LIY*JR̲0bSFL%6ŊLb5Ib2IE2DEfTEc̘2Q))62bEd IFB@b4dMFISK$Jl3# 5(Y,0!b$Eт $ @QhPd6$Ri6f43i)PFKF4E`3dJLQ`RUUض,hѶ5Qh*6$j&$E"4la0f!DM@lbcX3S6ъLbMTXj5I`(R!4LA4 3ISha6M 2A&MѐS2dэ%F,cbTEcdI,I1R3PbEl0 E mlI`h4!E 6&2(Ib- 2$llccIicK(#A"6JS1Š% 4@ʚFlLCJi0IhESA (Ib H4i!4 D %KfF$hC1FLdXJ!- MHBɰ531T6MDLl$ B`&MLإ"$5)IA)"E&MX&&AFaDD0 E"L` @I[QTYR$l 2(a1&#(hP*hC#"1QI@IQXRhcTl-R)FBTR Hk$1$&1%`BdIa"HeTlUc c$ RBX@2CD PPbhLDRe!d؀iD 1EDS$m$k  (ň`$ TRQ 1FfJL" Ll1@$B,ĚIiDIBAm ɈMQlY-Q53$i,ĦM2#cD"lEb’lb#TK%Q&435-F42Yl@BM$112JbƁ̙HŦ 4)(32)@Ѥe%#44%24dQȠSLA (II ,D ɨR""FIJfSS K1٤ƔC#1JRl(LTDR)&2hL)0eHk-$l BPaLA !Hi)J$#b$"&dQLJlfRJC)d H dd ЙI"(ShA=(6h3(Q% &"2lbFMɲLIBȐ!$BIH %FRKM di6 SHĒP+P P2%>DbLX4FF̑3Qcm6ł4R,ARImi6R"Xf5b,RjI5a1AL̤ "5lFѨ(HLd, 3#B Q!M( Qƈ-h&HM30%,h1"6(6CI`ZHld 4h ,f`"M%$)TIc!4ГDĆH((Ad6 EPM5QX3 $c"J))(6`LQ&iB2 4ED 66QZ2D#I4ٌF)Mh&4DHLfb1Ah4RZ#TTLر(db"ƘblIh(Ѥ5Db-%i4L4ZM0TZCXXX4[mdƀ(a"&ERh6Ri LBa2l&(lbP*4& MCa6CH3314$4%i4‹%!A*f"$ЀDXJ0bfPeibFXDԕbR5E4dƦQUSEeP$ēJDdm4dQ! Y@E(AQ2FQF4I1CKE0I& 3- " c6M!%&c`h#2b4Ȣ6HJ#"4L"6k2$2aV!CjeDji$b2iFI4$EFJdaEFK X`61[((cF)dbI%(( c2hRJ&ԊUM2#)Q61Jl QM*KFM&R##!dZ1",%BQ$&&4  @cDfFJ b2DEL2L,Y,FKF1&S5`LTh1#@BXƌM QdьXf MPE$1Q1(1X ,KDhI@P22dRc4+QI[DK-l1bٚlFmIQh4h#(hQfj#EDfFZ!f$D(L̡1HPƱ6b`5 a2f (&L `JhE)X d&)$b)"DA0lcE%&JXM I K61DRa64TQ-"Ҳɖ&I2ɢȲ1L0f$ɒQ!5Z"ma)i1`F"1 dDlQ`"T$PhfCFdL$đ"RdɄ1AL(Q%1cB&&cE$EX!Ƀ&2iD-E264hѨ&)4h&% ff4QY,J"HȒDɦ0TMI!ƚTІ)ɢ@DYd F$K(*Hd31FRL4LM&ƚZ4 EDi(0AF$4j#FLi,"E)!&#( H*dƙe lcfb#cQFBI$&1 i1"d(( E*-&BaQHS*&l F 3JXE##%) 3IRjLȑ4"0@QT$ 2-)6 $fL@mEHQa-F&H2E Rɤ&EF(d"&)bYQR4QE %0M AŘ$ KI (b4#Be4)&bRRf@JIdTAE $łJ $$ғ4"Ff! IDf )$؀&@BRJ2Z$"4b$EL$ɉI%,ld *ej %4c&JLl$F3 m3hLTd6lidRHJBѴ`$,V5 &&dĠŌ34J$ ()6M$ŦfQ(3F (CT@K06Mdń5!H 2f(R((EfiH4E"b(H",Q2I)L؊%jM%IdPdih! $̢4 Ě E0Xѥ5$!ؒ2IE0%2,4EY,m$3Qbf5IBh5d3؊!Da4B4ă3& @Bơ HƦL2R"Ph#4RHH b2 *0M3Lc Fl(@ISMT2#J 12-KDH$ij34أe bJ6""0D` )FH$щfh%!&"1dXZ(YLA&T&łL404 DV$ei$QX,LFk43 `ƓleI2IE42 iLReI3F2 h *(SFa)@S1ZJf&C%"E(hF(FC@AZ0TE( B$JZ)#DЛXУB6(3%$ 2ICfɶB4@A4YcbY-5( Pfb(c1$XLi(J "2IFFRhD؋d #4)F٣KF&FIfEbhH) Ba"5$ c,aĀ*fѤJH60I%0A"M26aAbBPcC,QD2QX(dX`e!$diLeF0$bEDh@2Y#&d4DMI Rl Xd,&1@BbYTDD&0PIK8ȢԲXhA17l&% % 5&o6ڗf,QmRiVZi3cHj1dԫ2#Z1DDT6ijS &h5fQڢLlR[JXiS)ImF!լIm4 XdɵB&mEk1I X,d !Q2QQj5%@i6L" Q1L%2Ih{U^jvwU PbD 4`?U">R[46E4ccT$KVK Lm,d2hXj F iFh`5$Z(ɩ*1F+EEAfRRXV4cE2QI%$ j -$*M  5JLIh*1b1QLRF hIQ %F$FBY Ba4lA3bF61+4d#lcb EDbH`mŊō@-2ب QlF-ak#bF *1chB(EF-2$Ed,QSA)m DРPQh#1Aj6-2E05EEE b`6&RdJ2Y5Df4X46B)E#2֤-!X&5F!06I#FMZh6 m 4kFV4jB-Ԛ4PldBj1-&Œ hƃAllI&6D5)ZLQF-&J5QJ"bm1F4DlXL*fLZdűQ#IQI(JĒbF66&,R6-61m bPUi,5cF5EDd+ A&HQfF%E4kMAQ,Qheb X1lX llb!20X ,CDPmiFlRT  4A$F(t((4F@͍)FZ(ѤT6"EDi*1`LRhl͡"* (cEmLQ(@4HQb*05F 2mc&(ъ(i#j 5jHQ$[&э&5PQAfTlcB3fѡ"`c$j&kJ2RŢ+hX JTmDb(h,RQ!("l[QI2XlPF0hMIi1dѵJ$4hLЛ&Ԗƣ<8;T bfS$jb,bE%&ڍ5mbUbXՁdmb% P !H UK63&1$e&h`Ѩ5Rh5Ei4665FEƴV-EV)%*%cQURlBk*(hƱb"ѢbQF35cf %Q-DU%5Eb,YPZ h֤" dR-M`*MImXlL*cLj%(Ѭh֍"@h5@#ZQh֊* IFj5hKƨ- 61d`VXQcb d -cPm4$Ƣ4lZ4h64i4`V44E Xb,VM1bbƉ eqϿug {^.cɌ=*}\\zsW^Iv8qr3| Q!4aEl1 ƱJE8HD;Q)| 7I O tH;ɏ#"|uu9>+m@ |Ƣd9z=Gc^LWvdOkD3#ѵDi?J@zXoADں|QGJlPiQ*d"(Fc$I4q>GQ&gnR* ]p\<`d˷ , "bAe*)pNյR]On H2GHD:O&?ɑFCȕx7xE@RJv:Z7ɝ{eL?[|T!H.o~&_T"4g>OVu s=߫˾Ġ֊?;blQh/@P·2AgE3ԞyPyiPB1*ig 5y H#\R.7.Oy|jå vxu/?Wwʿ0zId-Q1/:k-oEj]ϋ ZQW?Qӌ9ձיhJ: ͎{Z~D8!=U*?J\z.m"uZ$x/ls_>T^s̪vt^y{DEig<oYOw8{f]9iL/H!Cx1ȸ⠮4_9̉1wL"ƄWV O݂ PR\Ӎz-/t~49͏5&WRV~"G P\z8v%6n4Tf^na[oجM )N ]$2SN$GͿF],ւiBLn9@;q_<\_ҕ79JrdKQvY5Kbty@FGn\|evՅ$iBZSvC۠ig?HD52qa* ɓXo8k ĿPq~os_Fe*PsE|SsDAb,Ly$y5̗{op0Ң}/z)TgSԧ-A1$xUieCjFMR^c0EUj'!_µ`~ aoU$yOkb>'It{^M.ɉcޘRt̶̹8{s۵Ť;_l~J#'Lqt܉0ŒHn'cfa\IJn_o9jo?HNĘΝ;]n^kR҇ n}C1g Xv#H<}XeoTw2djn`bLe$ N$~Oo-11Rj/@ZW6~9WjАLO  Bbqi tdUm3Zsha.~Ry=q0Y.'@\/!K }{ߣyb9DȐؼRw*Z9]H,EJli Wv"/ةUo>Ap]>.ёV<*oFy ??2CX3 !Y#ze íŻ.'ϗQ~:7f=>yOud2@_ 6~$wD$~;WVPL8lkNuZƪ4bd`=[dbE3r(+U!W-nԡ{ɋ=1s+b3u: _٨ahoC'VL#ih`MǙ JS=[[]gdtz="n%_[>fK2'Q8RUyy*E/Optu0#o\HOQ?Y]r*|><zX{"k=6]:4f13+fUƦK}vp_`D??k?9w' P.w~V#m3n}s?Q?S'm8B6wE@{ɪ?m~/;=~щR}w?9ަݿE.->&Z+m{?)7J6?.wlWtCSZvʊJ4*@QE)DU+@ӭ.enN뒃CRHRQ@ ldI cml+aι wqMB@hhn.w]ZRě*C JQRR˸:#v]a!-aH`@)*J)JhPjP6L@ Q &6P C--*5%lPDUj:::@[P6Ph $4e 4(RBIQ*55B h6Z)( $H!U|Mj"ԎֺR*"BRPY@n݇uhPI"(* H"̶PQNSK2 @7s'JЕB 5MD *"(D HP"޴.D(fĔ҄i= H%؅JJD)Wwq:ʧs9 kUA]l^₅/%TH#=۶Dej秏w vPeZKmi$a@V( I) TBB{4@(( JRU"UDT*z s'AD(Zҵy{0;UsS@ѡ^ǯ;_lC0>E(zd( A "Q W@^A! ڕiJDG|{ƚ :vJ^{TTD_{{:;iUDvl]; Ѧш 0F@@2i&b06z<4i11~M hd& hhi' h?#QDOM ?JxdSƄiOBTyMM"D&Dɠ=2m)e5=M?J~x''ڃa4h'd@4=MOTjijj`bi Fi FG@&L LL`L 4d &FMLiOfhP6IS)z1L&(A6dPQ =@ѡ $D4PThm @ h@oE}P!$H\Jm9w(fA ̲iKm?x!5JY洔%FIe?`ibP(ݢI%1ET|j|;Mw1ṵͶey&.6z$5 'ECT1R*d@6Dya5,CR$ 1"aUC%1@QJHJ@(j|`)$ͱV_Ԑ6Czp}h&jdM6ڊBHLB/8q"PT=c^:dKdPP>g繒 - Db8=|"~Ne!9[hT[l2BFȩr=$<xbQP΍I.*٩-FǴJt9E!&X Mu؉BlQH6,hɯ|*_K^Īp$ #3M"@\I(E @8=w{fC7$fID ed"$!tm  PU"ENI݊6Ա!0a1!PUeA0a=2퀡W!yx$D?MWizjm2;SyS`֥R"@}K/>n.sN ŋ$IP)? )]c~,)XQTB4E^!mXї݉ͧ2(masyNCg|ߛwiueRQ) a"')8JG b7 _|ǁmQ" s'ςu`dA qn$rwfڞfڼ]٢"5 "PEE<'Z߃b8'r0G$mbKN)ufcX"Iy0^!6AP^ޥdҰ"hcQ-$y\`MYsQl O:΍s9s(l>Zb5}*ޫQbŃ&6QHF(Aj07S~;U |t 9<$ŲZ5#H $);Y| ݠ[4iൄ)$(|BbΞ'ݙSaF ֪H," Shpq " J;RYHITjqfte&ZWEA33sLY%SXn2!. P`N#L'0*6Yer pqHAť:pE{,NcXu&yt40LƭӦsm6tC,E# !phgtM@\a! 0hj()יMA^sXE> XU:m,"Ӕ zOM\1$:`[&חkٯl4dI_T. yƔr"+qBc C"'Sq8Z(|W ^vo$Z-ēGy i(1%iۀ#J%XTWnm4S0rYR ױS9n; ]n\tU@qTY(H)FSrκ R1\뉧\aEo9mJdYDR;RPbeJ0Kj1Lq2EF*ҕiL2ѭ5nLa`ҍ%eT*AP6+o.E5488[3*,V֩OR͢>?; ;y["1>J,~h kH"2I1ćp_tY qVQ[WbZXQҽKq*O1A JEclxE#rV(زaVARe݉θƧ9[ ZVT %VjlKT- fclIZ`ewIfFe,Ykl`wL+QjQiڱ)ck$(F;s;.E<̘ [Tr]#Aue δ;RQmDU`W+q9FLj `#SS :]ΧtrR:T\^u\u*lq-+t(Iվ/m#5&;O絆!U>nETBK$SJ?pƘI/q*S)XD `Xˇ>Jv u;-&$f!2F4%.d& (^b֥Ic,D E[ZRibLED5eUbAPX72f0#(4bo"῅{Uj1s:9nٝ\n{E`KV֫62^7f޻\D/ÀJ`ҕ"uh@™O)lĄ `$nCxPXgtc"{里B43,3H`lxR98iOJp*Y 2¬#V@A,݇"j-4" Pv *i\E'_>E~ `R2)%dښrۙ%!Ȫe.hubMBmai(ۃ+9ǘ5V"j9'cT% (]ę|JxwwMDM/N!%]|>^5xdfMrXegwgt"$\!娉[ݗ~5\!!)^TTA"N8)w4ԈF)"jj5_kQZQIF 0lX-H'|9@2"$$"Q:+CLIY)D}5WɄoǒP8qՌy5N8H܍\ܱI\ZT>.yjQUrF ,*,NߋB QHAh1$ [ a Yݲ $JH+ ;f $F P4Xü aILa1'hVX iPIL 2Ad %A,@0TwlV*^L$H%JAE;T1*1il ,Qa6#Kf|&eF gv ԝ$%mVhThmzYJ$ (T R,X,(kW-7H nlV# `Heσ1bZxz*rUE- &fDز!XfjJR1Quʊ F/-Fe1m2Rĝp j1([mW]p"/V(7( #8QFe)J5(1֒kd&\Yl49mELWs/9ͷi zq-UvX(eX(2W3 [mm9 pk2 P"PM̙R -" I8ZjtX n5uI/^t`j|d7iޅ@*)Ubb,j&Z#KDʙ\Iҝe`Q,mc-11]38Do:)yѸPsn:bRKEJW!a&zP|'L@t!!S٦:kHk`*,|VGk;Q܀:,Dg(C jBKT^yg4mp~vۏN15pbϽmpl(U#K5Bd6f%D>g^Vo!#}l=P`;{5d۳#M(V_uC$,2rQHNcbBU1f3r-j4F穷7*6(ƯirZ%rs\ YU%JlZEJ밑.~'b/_2Bb4|[ƽv{#]>JLBq N15ёA :ZR;F *"E2֍iς3 EEykd;q'"ZĪ=V뛗t 1$)Yܜ`RJ4sH;eA,?JIƷ2TXƐEH65*tH~koǯ%Vtհ9yn4(V@J6 M6=wI3mrkxJS%:]uJ+UciEg#Ωy[TḌbǖ.f)LU³| -̞Љ> zpG@,폇^pF Nw6댬]o]wX6f槍9N:a39ɨf7`}rgYizu׏|x17|Rb"3o'֦ bc q'EfSI%(Vu@[ @JGjX,} Ԅ*D<%]%#®+2"1Qae@1?*2(qՄAr""XTD@*()d3Y:"{k'+!T(%Mn]j*ϞfJ z0%|l0i!Iٵm%!A `('OaeF@-,&Xq-)g{w E&AӖ8O{2(Mh%fMy嶼7u܍'|7  x ``Lhqj6 =ܠtMR bL }x<ν}-YSϲu""$peeYn ,~,PU[G`ϫ%Q1'<( _KUGPbʕ5}~sSLQdi^YCcg(*8,ֈXNpshp P:Mt `:6/p¢U Jx`#L 0Ct1q4^$oFep lq^3ϯa!Yuv.&e˱TEo7);)Xc84-b(EJ,U۸qX9Vd!JKY- ¡*P/}0+/PDyJGa@ Ya3DYUgEFv D;*vs^bp!BǶVH9N$0R! x$! 78\1ȱHl&`X8ӖH=tӯ:J%wjGø*f[o{s9sXb'udGL3.bQX"Em 7n*ǃ Lvsg;o\ /!EgA;ak ;:QBs[H&" _gB+QCp(),bK|饢(JAb4k1-m 1ڲWiLqC2ǝd SSo9]u2RV7HȺwg1ގXs{77C:˩^>4EҽT0Ӌh=s @̩ 7f\#&=lNL^;!^4ΜΙ83avw0논5ΎoGQHs{9˷]U5IN3 3,EqGznǣy5ǴNGvΒ::G-3rwtuy^a<;8{|xӃcbvט$Qf1s4y hR>qD}yM{3(GU㙗1M~s'sզYz-Ϗ$+[{4 17mkX8ڻ|ϥ惵v*tC q韔ҋx*|yTW(k՚Rf*qO?g5c&H!۳ßPSc'M5+CuTxXވby:4CJ+7e+-D@\IXI83 '!۫ 3^ PCw  n d<if d $QCC @F S؉Zf!Sm1,d>A"Q.kA f+Rhfܩf-{P4Zm`2EF1lamlb¶+U1 0i+j3-bH֪uqȫnSBD.2w]˻vؔPs CepŸ̚"7OV9X+ =H$XXLrɅr&t,Ώ+ѥeBaE+<4Nmf Fҧhc"m᛻4z=|rT)=0jTrT*q OY=ɞG=$r"*JREc&#ť,(K׿ƚn[aSO~R9`X ,mր@sUIWQ%(EWQI=*VM6ݤܡR8+"MZau= b)r0b >}~펼{@׵\Sd2Q!H3WނҔ)Rz'>a5_UXKi9<\,LL0XMvɭtyO&7B Pe vDַT蟖@u_U܅ ( pO^2菿n *,fd 9D.Wu 0yd4C%qS3l ȌFb(]`|v]bBB(I,sqfjC "A2&{բ QI9!2xJ>ycil] `ډ=`*Ek8폣ΌThyJZX, Yj,77%OjCQВcݠ,"$:O'ZBNPހo~wj!EA'**.Fu9eP)F@kBF^, q:p7t=St % LH(cb>t)m{b6K"K=Ͳ"A&U "JC',!,]5yuziY¯!Ycqsl$&&/L 䁩Z>0aCǝEdDpƣm/e̱dʡY@aԳbfV, O$a,v5<Ƣqt(花3\YZƶ \fYY2g3p*ֈH*-8^}z4{nb27EsW5@bz&ڑvlNfpxѱM5\K'vFeqFXB{zN`[BQ>5oʽfJ /MK}v9{|E0,8d 3Hu$b4E.竮bZ jATJ:F5 boyИ ҍ, |%w.513W\kp3j EUlkn[V^$bqŴ{C^Kb԰Ia0J2bT(g9AڴQI?T(Z}v8֛;3>zԵaaPZ(VV,|R_+NsE>:f*.munRʳQ5B}mD#FEDsԚ^RI',X˙ߍn,jD;Fݿ< Hv+[A4i u@"\je:Ckw* FEdW0ubN'S-0A< da,hwiMWU^lL2 vyIb$R YrLO|!tݔ O@ҨU}7,VoǨˢAHdnCk$`Mm$"|ڗ@AktKh[M& _dCX{qv r2BScHh(P$ D@zފSۨ,bK/LZT#14ԀxD*(=EyCH|M4XP(}%2Cx Jgޕ{CD"+6Ty xmDHdZe|h<1߅lCӘKCM6S=ꑪjmRj#C멩TZ?gh6YT+VUV.ۭBV9 0^")遡sA =4wiu/cןߐ#|B?HHS $F@0Q@kϪPT[ LkD> n`TTXÎ*>p 䦝f TRӮNn35jIBдzɻ.en\3QƩYchsMSeysZ-.d|B:9REZ%2I> I%Pɘ:ÓWȯiHveX/\wW-.>LW)qŷƗ\DYFh:6N/ 3sNFYD4F5*.Ez̙.V-m4+ZU<>DQTu8rz+(]e>o~8j~tXգ+Gg5nG㥼g&&q۹bWv}!ilѽh Cٮu:vCzS\<::~!UC,h{UZQٷ;Hg&8sG:eޚ:m*QU}i,^Fm񇝱1M酻+ne79-T=x_ Vy-i]Q Om 'Zw@˝NΑelc++Ed{ USNAk +t:6]IwTh&?'O|V5.QOɸvw@pk2_^!ģW3LcE;VyǟKu3}:=y#Z#4is$) %ٞb'Y RHh:!ǒu:m8euCA7`̺Hwd7'([0u)+oNӞTd7:P0* @ȆS@'/5D8yHum$3; IJE8#! EbH57N0aaϓjMC9Δ^a嚧'L-w\b!1!6L2w:nزq:wdny$]uUelL9+MWPqw aԢ}E\fS03COE.)؊)wU{5T;z'ܐ뗈v&sKw u6ATqy` )ӊ,>PE]zL>9]sL|AJAä_,, vȳdSKWCyQWL{Na-{73֙\xf\L &g"sfa fQ$'8ɜZLEzyӺ^>yw9ח9O.r}3ܯ02qq׿c:&S\ܹ1諤s=kXr˚=Pl]S HlerFc _%xw)fPbCTia0Q_I\ɫRoEIN[ٿBkv|IV(0I>&*&P4;J NCo$0H|3Ֆt@ʀ4ɷ;NԌpA@Eimcqx. ĨiM|U{6rs<=%Pvd;0t $@a! 2@(+ܑܸ,H5ʑ*!LWK4NRc5 (hEg *C̉r#K4CJՖ@뻈L+ b+ ,2d<&P^B!C"-)w8dui:2HtyT ABtt}>Q>i&Cb= ;U᫆d'~;UbN45gA9rT+6ER*P]Qb)H^D-_b&QydK\ϑ4]qQ|">VHVEϒ\g{ɳ-%AWo%ZO:T^8vYgl&„M/GN.hД&1m\]BZ)TvS{J,NJbY40ߌ=TDk8eg: Hcݙ@4i:2, ˮ0N ɂe"(GY 3A L x<<2Ԫ%[nY/X:.!RVʊVu%(љKmzaQ;z̧Y3f\8绅1̞/:CK8 o x8g-ȰP|4S?7!吇^A9Sԅi Jӥӽj8`j 93M&r^z@8uhCBN =Fxr L]:31vڊLID՝zmv]dezۍǂb0F2Uc2xZQ,(Zv7rH H: hC; efS.#8NsRYjܱ$.YXS)xKD iEH1"'l+Һ1"]J Uׯ )8+e[r)XwJ0+i+ЩO<0mza4{JM" "a1 ґ[6IXCLsVLf[:q<=̵.޲Z#k6'7$8[ㄤ b=rP̡yZ0{C:ȏra\1dZ/1d5kì1w]ۦdvʞYV#Œ`q+asd&\v0`GTID颼ھ~[@,`@ DSÔ>!@Y # zD!L&!R N$+'V%\)$2F 6f l.0L!S7ĥ>~Pl{E _l8m:$(e'Rʴ0d6p  9 F$0]NpSP<Wq}3'Ӵ04URan7fnI H[ q)r[`֜qF?k Tm.:Kk1]邙4řaGA:]C?HVe2Bu{{ý Lݠd=2~ފCD:D.)>& p}QjgWb4j;YjڙaH'Np1M.Z&qd3"PnW5He)hbeE=NÉQJTU O3XڊdkҀ.t5RLȹO>QJz^ @U i)Rn1fu ^RtjZˏkrPP|gD0 GjU55BtP  t MG|9xJ^{pRԂr㚍&[{2ч^+G=| ØOCP_R@dkd"d 'h^L|M\҂ͧ*Uw"df-G/ʀqԍäKp jMI3|Wf)fE&3D mN6|qDʳL~6Ć3"k)绺Tu;T'F(e$~J5vBB7O'BNkBI% LQm2wV@zD՚Icj]G87?D" jOCʐo7>p'\Г955- 4ҥg>ϊ3Y(;Md4kwxTwiLzn/2HK*}qj [D+AXemHgtP}6L8I0S11(җ}VB}ygj ffMP2Ψ|( ݖeڜ|~$Bw#L)JgO,0:T) 8riӾ9@u'H;Ex*g4'xUxCFAӺ&\PLǴrΗpGsMJ\'lTTɧ[]W9@ސi,0 ,:3_ )IjMz #B@^Y$$ygWٖC4~N*X#HH(&2Z*{p2a(f2I?T=*wgڔ瑘[.]frr#|P u"퐇vt=44,ep7X=g."j :En Q iN4sѓJL!L=URDU5f]xd3C d xM@]H&vx`ā/(l7a5M9ݐ~QZrRK`M.- p{3x0;+|eZhC-0Z֨aӞu S[ܲAI8q''CfhC"g:tF5tҀOHL=Riw:'D)YeU:+2("qD"r BM'S͓ZJx6]gVtX D.K'˿ iuUB&-N<3.V%2NHa${K@ C]|NuHW*m(mG7@d(+ֈ¼ã8NCKʋ*߽xEt4`hjZiA0|Nq9FAr/-*YD V0Qe0R,:3X&FT7]መ=fX;qt;9JtB t [L8IC1P( T 3 0%k]5u*Ds٪QrW[pb"p R/!jِ5",:d+n${C*``т!,ģ!e$Pd) Ұvө'L4x1@}:<in IQ<ٖQ kxd馯5PzĨOd&u1aD$v(b2u\܆-Fwp1MG{v۾ (k㶷SϪYf$4Od9< )-XWBiL:<0*tBI+jP;fBUdaL%Lu3VtȘ Pë2$_p#ޗh2N*P҅;:Xt,=K@uq9@9zRpr[饒xI;=Fx`lD ~x *RF! iJ@z4Cc;Y;.ɖwLJ &UTaPT]IJn.4HH :'y@YTQc07~~*tAJxpc=`hM@(ODgGtrS+܆^ǤI4ۍmvK;J- rUv{U+fN4u҉[$-Q)2K(݆jx:!퇄ds $t g2RI$A,ζK6!%^DZtKHQD>܆:WNj#^S$d"}v=%* .^jГlNq@S%!"jIm1x[Ht4b0h[BZa;8hiISd𖅽ꂮ>2!Rf7he@N"?7GaVL'oL̥t)kAErI0!HuШB +Vv nр\CcQ*\M]P bS2hNN_~f_"x 7 E (C¾EIHp~nRB >(hRyBa/%bbd(be$n&  -h%*Nɖ[8L 4:vpʺƽDl8 w8 2HU l9qS"L8:&ͥE p&nMQsH6^>ԧ^TsH>|d- vS۩׭bKN9`Z?p͐ :S"䶚L^ x" _TEђz|ۆM juI4|3vHKb0 䚹ɲ2NQ I4!R(B:@YBOۊuoЈY r㥁Ube-ӧ4]BqP:ȳ=4\af0ԊTpkۡak4n&0bU;ZQlSԧ; ;EkN:hnÔFu`SZHE2nRMᄩ5gOv puI/x;ʪl-ToN,:qVv%mzFrӴ9d\qEw] [!X>+>$vP]L9l"hM7%[{G@Xh, R ׋3gtЫ(D1ቢqQQx_dޤ?)IڽhRbD{Γ'vvHEeTP >!6^@\ lCDDē }$՞ۅ"HQ4S$2h}ɰnصJpw"JgIfvS.Zcf趾ҹZmROd&N{(1T.hϏnJP$<`vj caRb|@8uaf:*6U@'rR ߚêBva݂6LK F6AdQb3ƕ0[ERBgy*v51@xGP+V(Od= ,OSACTH0x7r[0078@6bC,8x`npУ&֧j6І0oNfS&qԹ3(0?)44|dD j@Y6ay.ڤ7`щvCLڥdPU^6XшDڃ+uM;O2$9b읓w^ AtAP9eM4wa;&ˍ`gt@g xMZ<ܩ7ӈh z"nbkFu,>މAûջ]PN 8e7q{νhjq**,ל]v.xa2`ud3XL5ܠ19QԘ^R |ppD-*^\ LZ`3-}(-SPns5 윰G(>0(Ҍ1 sSDѾtR˜1pYUG'nzh$XY; vC@5AL=e4taJ¶Twf04!3\xSq5 ?eZX{Q 87$[(󒌌5ZU'vtD>D@}HtO#!g3H h]'["NԏNZ iK:BF:J ve&C8l^ >$(bZ"3Y5\w_ot(JN=!0DhWz Vwf\2Ubl؆[*D'ZFyA#UR>quxA[@n݄@ߟ7!ΐJ=I6B)yx8>%Z{^̇Vu$솉'ၢd5'8/J~T2oOJy:lFNYl]%=X^Hwg^6w@']Yk5QL9BӖ⾬*薑g;Eo內Gf(=JRhG?i&(>Torio#n:P[p>Y^saeRxe tᩈ!vA]+ )4`waPIeF qO)q!< Y-R#T\^ ܠ{F83!3N܍G9z)9̒g()ht$&;vVFHzHNA ]S3YDzeP1N9a֪#;7˔Bhq Rݕ5{c\c봙,}%xڼw;2XSe&ѓ5Q"`dHmpWV[فh# $[:AKsQm3ڵD5 [2v=q֨ax )* ClPJH:UBD:&Ěva2 Bq,}o@fpzۙЬL0)5`:ņ]MwIY%j>(: NwAOZC@CBN:BP]BlN 0-!0=jU:h6ig W^DJdA_A˜T/h֓҂IPnq°񣵆vkJi(Bi<]Zbi e AxLE"\sr D*Z͸Ae&R-Y;*Z&V;0{L|6a Nsy(le4| sM,!zZCϚ;H7A/f$QyNCxdﶳ1e  )%`'0{({܆Y, 1i|srd$b Ull׋4ΖQ1-5)Sv%`݃d2͝3n^. v^&R8)A17WhdOng+"v>]]黚Y ןX` / ' 1Y 2#-`WX",<"ךI]%Y\&8E/)CmC[LM]{(`8%^m辇Di}4e{dt]:3 悸EplM1)6Qsp-5F}:}DG'fTQvlA Pݒiަ="T;nYgR]2I<&w|准y͝MV:};[ӵV$li$T\T|,7Ow,=7IӥxH.VZSjm2T P{w1cDZxe6wd4_= !7R!b ނY"A twgu?7 xlE?(?uٽ%"uC:PwOiAfuЬ:$d'tJmZpbaubLٞFt[GMo]ttC>D+fP4tA pvCK >k*xr}= +ibt)\3~;Xقi^w2<5Ԭdm"H2;#h.rP4@|,_XjyVjUbcgz3cI<9DC R@֍kZm[DkFmXFֱm֣jնVգPE@$UdUTUDUEj։ZV!UIQAV1mZ5mFƊȂ $""((~f}흳FK9>ײyl4[M_R 4HYw#sm x{$9;P>LBjR6aJI@{D(| cxH Xbh4Rǔ5˸s'@lL`27=-НYMЂ-w1PdÁo5;rYAdt`@ԅNt֍?Ơt = Ma5ePgz?Mb$0ΡhO&?[(+NS]J#H |] {u@~%b,b*IIcngpWK-UF} g\R#?ZrIyszMk[sjGu{jO դI7jNY}RD`>~FAI_Og,?U;D(G ĭA KW72y}#)GS}JfbQP.}Ř\ ?_:Y~_2 4X68BKqG,6!)`L|X_s}b.G:'(:ROB$GHAb ,/t&eV?$-DGZLdWq?aM eDiL߫Krsj G(M.$P}rXiSU-/p8vmU= 5QS)DA3k8v: :nS),Ws=< 6 "1W9 c*hj(cfէtF=&8?Bfҭ!M̯sERQlddDbVf N=Nrs.nuJu_t6)O3#صc JE:ҝdLKJKTO7g)V. j;m(V2s\AGo;lu`ie+B"{^Fȏ+ ^vtG~Vۯے;ZWdsס_f̳8m<۽MK0":`HIU@Q u;ί.ge>qwߩkGV[NpRmftPJ3 ARvŠ`Lg/_v=7jEy/>w,d90v\;J=vgZ|= Zk(dV['O}GJ.>$GyX|YF>A tBrA)+h#hh0*WkW謃ty*l@!3zMphћ̑ .rJ2DZ t44*߬HM@OZwI`cY:) a( Qzk[Q(<':}o7pu;>-6P5>jH*Cx(52^uV2z R#{u5d,&,uZfh]`[[ NPM^TRМ@@w ɐyYoX> _80> 2z:%r$u!LS頱jKFQcBJWp7~z(3{ Vbdu "3N+-7=9boqȖةP 3<Jfl.Llې3.VR0ȱQ6}Gעxbu Z(`(  Fd`VuFTZ'$7Uq](Ugظxzʎ\+^j==/Ch:"J&]Ry;J09<SX؞CR,ɤbSPе!v[lٹh{k>:4QXF[?yTZZ931FQ6ob$0YM>- cJDVqtflWoXs(D 3P2o'тFuiYUN#8! v^Oq߁ƅa\55!W%b+d:'M5d-d(cYD%T)'^Rl ,:e}'3w] quaᇐ= J#A )L{,e[dJ=d<~&DH2^/.(k(B +rRvl\&bcSyuHK+\D=%9'Mϼ% 5pbpzkjK:3,Q Ib,J aPlWM|T1d?_^єqw‰ q8\׸'JgؿDq9rY~쉪 hlayEpf Zs0w$솄IT (ܺk+ ac05W"ChL)(G :4m%Q-sEɏx\D`Wf)?i䘵yfdQI \㥈o+;1M `bY>Hoq:]6KNcEdaH2;Zn)ŦAc]^1#uIek֞[0Dl8&8ѷΉi$F.8 R?Mu"$SʴrlD^.(M# sz-dHy赽x8Z܋uyq&ÙgsAfۯEPp=i07nS}`DلpRԕ?OSߤMNL @.DGc޲2Cv) .rMVXbȄNBpV<5Σi |lي5j_]8>qJ{+eFt;vAImgCi>C>Nufß>WO@&8&&yNa3Ĉ_I;QJQvO-ckO4F%C rk׺47'}~@L0a9펞9M%U }?b 4 M>1v$䭖թD@ ؚ1qCvڱ D Uކox` ^n\5`;rGP@zց"}?5;nspyeV5O5pʢppso-x'Z-n]J_me\>):uQ!B6L IH a{h Ʈݕcd!sM{ T mh3Zkt3s@~Eǹ4tV#~fT{B+*JUatK%2OWTԭW}m(t3d쓍*]]AZ!rڠEիwz;3©+Z/;{%KQ4yǚWAC|ŃIvݢK_f?Md;[ªB&1 .|>܂rS}zwfly/FlXk/ \O{%!/TSgts涘 ;L>sGl}$ }ޯ9%sICݜљ9ai1T5*9؟B]>72TT9r~2dI?X"R qq9d1G'B#3"e"䭽HI*ly:2Ɩ%)+7wd.|#wz|G<mUb|2KP8{fbRqq.7wg~w.ߗAv6ZofN5w%UKFv,tt)!4[}Ƹ~c^G5WVnT!wboג7A7|d뾃ؼ>pLI7/@!ku1c/n&#}8Fy$&h@EBOꎜt"_ ^uq.US*j:Go6js_H>* `W&#Llk# f?7u Sc(dMOvLk :]$ʄ/1HMQL6V-4KQ Lc ԭ eUl!Fڭm߻;MTChN{a% iKx.,jLD0L =)XCYBD;'Z׼|0% MEǘ%7NOM.N~:Q2/P٣TfV -834y[*6q˔|Ah8%D  Í zuj;΢Bj-k UA> ATUYKa%Lz7Ml;nW N| omѝ ܠ(k# ;wx  aBTNQ#bbt4{V$zmM ʶNK^ hУmOΘ)e ѐ?W\/5ݨܥиš #1 bPT_&/}8KkfjZRW"j8 p >B08\g˥K"n~/u)k,{pxq0LmؑȊ4ȣ.C@+Dc J!*#Dmܻ90A0'҈mZ0}ifG jĉ#:_q$r+ruF%Iqة $nKƘˠ ԫ -8kfO9hSYpמWQ*lw1a.|Na吚sHUj4?BP-껌Mp, )i3k4e#xz3~ u!<;3*rsj-FA)*}*(jfBE^ҌyQخpPlTn4 sEx'H 2η9(B%@gSR$:Yr\ WK2qj]VE1 3`&K+Tyԇhğx,۪⊂hŭ>ބ/cʀְB DBW:'lV8s= Pr39J@lF~/-oE84{H9c1dF+rr>"gfƼԔ̘ik4x_df?d ?@.a6BY R  i?eJhH0tLI6W,]4?5iA#ח[niCЮF֥Iuب7lO>Tuƾ$@])j|6r >RUCC%c:!|?UGi3qD3qsT(Y{NxAS̼HZs1(Ky:Xb&tb^(\yrtR %[R@qf[ϧ&u6*b=4@>O겛{B6X̐4Q]Ck/47TV:rs̟~iafM>Q0J ̨Ϗ 2aPnj)Q93J@m)1/DDpvSYQϮONI` 6E,v )W$[7˼Э Me>_MV95R%ㅡ\ "A~x<)u߶.q}a`Иղ9AuoUC8[۳V6O'2p^]*](;Bj@*$&5}٥]鋃+ttd,_ KqԋN3F uԋOq?oC^%hIu-d+S\DMupa 2ͺ#Una!]@P4JA;O8Tȹ L}$&tKNe#WR䭂;k־K>'KCz|y]W!zFSHXxM95M[c|1%XZ{O|3w>WHr1s\WB@^_k˕2!%>GXf`eIS1w)(cǴH b{]m%9Dž8[ =Eq^ۖ3ڊ&BcgRQ3Lyp0ٷ61Z t _ּazUZfH`H림?]V\n;eGvGPKj1]\*8Te 4,4+/kbg.UoG98[ς2:1l q=h6/ϰbF9w(%zux ]"֨b_.=봅`wc~|yϔnp程(_x< Ϝ5%|P M֗(KIկkr(9.Vܒ,{wH9{Xrt:Lf|i6 ΧPC›X}Ǧ'PWʍE$@N2P%w*P@?S;=RIPOtpTpr3,pô\* h{;1F}NEHtFG~y޺L]&N@bLwgGŶm4:Bdj?>C3.NJͧu]"Nz'{m>YZI ւx o%rgE K5h[7>G5?@K^gn0dsq{r ^Q`M` >xP{MsM  "j#@7[f`eD? cRd>ظJ)3#@#T?{ ElSKnc3d9XN~<;J_1Zo5))Hy?˻<; gX T(.r@k-I&a%{F'@oW-e=zϬ@GH!i0L`mGvJK_yglҌ#oJNƍp^ws7.5i8wQ$|Y)$f\tlhf=EGf@!I6?bbueW~\ts_ĕr^DUku W/A Q4:GJ!&E @Y}I:Uf"jo'_K@iݽܞ9  p_M\>;51jeܾy3$ؿ? ܿO54iEBIUhF2 NH4:1RUI!W5NdC:΢#,GG6)Zk&T){_5@ *,h\ %bPITk|Ri}6`P6ʂ|m;b.B@ ^%Jh[#wi5W%:#fK#P,pAL? cY}^1fm;܃s "iϮ7IO/.a3ډC2N2/ͅ=@UPZP|2TV#T}ؼRPPL gLEzY2lċYӚbAo RbHl3wXq 🳧0s(ZpE!.|G1 Q̋{$S>ڞo_(kA+!g/*kv֛!y |fmr)QF 5”\G͸NjW₡)Yu$ <2a`ʑoЗC#JF9iDu<2_3]⢊f2he`bWŘ.S1pɶUIպkG[GJN[X`$ Q`}7wsxWuV$*A;&`jCl1*./AHvꓯ KZ Q"mױ)u1=2;Ё N*u,T#ggǶ:):( |QHO'Vd@_QR?oRȃkN_XD6}J}p)h@J :d;dv1Wipjͷ,1LZqWoq }1h* '.T0*ίi{L민r%ɍJ#1Ѣ4ʜ?fiM|u &Fb,HEa~ZG8{  uad;&E(E57YE.PD~_m?39]HYS)q mM&"ulŠ@Ͷzpbvb }XXMPr VR.<=&DDr=NUc)*0.pE)<N}/]j,m@h,mڦM5;iǬDU 43mY'Tw*1Wu D $`SՓsRReuCOSQ$"> H`b$uR /An:! P2B=NW.;*4?ֱGqkٶ쿫>'{~{K,F~a߽Q9[ۖ2SW۟gG( JBnuK匬+t~@CA%6.[h3\k-~KZ[ԪnuPNI] 9lȕ+ k6=xƹzׄ xq#S]3f&ǟ#4^D=>e~pbOΟ~4Cc`;-C47ŭ=?3Y!)߯.^txZh@w EgY=E0K?5j'__2WhonK& fâ?pFUU\7d,#\pAQsV4s:sO?%m^kG}! Dߟp*d-P.W"hvjO?Ύ3ͼ m s++5et]LPJI)/l7f)݆~Jk,T^CRXR°l}3pYB)rp9;kC'JZfȞWXshwԣkD:M94LM X~OToѤ7{?qN#LzI٫Ώ^{w00סe,ABb7iޏb#!itBTg$@R|h?oG"6wm0Xh,6JUIQ #~ >U8E xnQ嬒Wtf+!TqBTV<)6tj'%U$1L^mfgdyS+eNpT؜l[Fy/zBZv6Ҳ@+Rwk^}ş%lYENP"VqkZKB+,>%ɣ7b.l4ޯ\H[v Ri&&(| IҳHn5[!{K#9c=uF=HT5 cgf1%?תj_d9JTْCb[S3hG6*.u?%y&,<Ѵ4ܙBc8̊3kT$5RH$/絯=9eKml^Oo+ @AHIRd.O"3<Ew#W{IsiSpQ@],L<@rs]>օ 6a7Ar| -gI~nx5ʎqV.CYֱ#'|| ᑍ#N6k2i7q>plؔe42Nq'dXTJcCݩywwEL'$@T bH>>/dzyq4ݯ5.i`%4jmyY%XftaۗFLk4hXvh^}ӂuGL4bMP] K[]˲R1=pNY;4%B_S& 'N'r)/!T'Ԝn۳NH+=s(Qwwϻñ ~ MnNm".BPa\ ^ ~TFa j|Fs!s^_|255yaᨯf *!k, D{k:`&Y_Qw.+[P؉6bxG7K vwڏKJ~Xp%=/؄$Upb֩Va$Ji,6TND#Az MrmBJP04.u$Ҷ,Mnܲ3﵆"Z(lP]|4ʄ )ʵDp[6!Fr5!!L!Dh䉶s(@Y22JR!Llm*M]jschh_$X4Q\ uWȞ3N[((8n(mϩSBبafdt5z"J}se[%$p\=8m?*߷/>(-ɝ ;ѹCJ_J:e&@@ݪ݈CdXIۃ*Q:mxh ()W(0j?v5d jO*2ڹnjB:dg Srx"JG/(bO(Aʠ8g`H^Y QNi6kl"+j"3JuTtB,"ʼni|k2bY'f_/&(%yx!ЉHC~I ѹ*zr\_Z -S!z_V,5M:܌\azW&x02f*tri~(JBIǧ C9kr;:v3&l!4e$#$?\_}Я EBz&tt6dqC1V4A p>BֺQgǤbWLݛ&uʂn؀94=#o6Nc( jԔyT&4'X7J"},ħ #BR*x,D+Y^SYMK Gtndm8؊IM˙$aNJ*J\g~F0F #: ,-R'@iЃ|p_i#>ϗ5~UPZ9ФZjJݛ,5%䚠DJ0=ȝ}`# *4 KS!<'\v']l򗊈C &BqNX^F 7ǐ?fYZ|!#L@;r(@&H:OO?n`<KOI~_OhiBsݝ+E`$ʶ0HCyo3:Ogr_7c$aEJ4^]BcUÝ'< y\?f>qhBy䠠qwy]Vڬz,@0%b2u,Դy$Ln9a#I Q*qprM1PMXc@n%XPG5UI׍)YΨtѨ@v 86yf%Qd|UjԀbdD-b>7hMf^3@ZEuI$)*|y[У<4Ε*'QW ?<mQX˦+A亘:2i=׆q-s݂p  P(B!¬0Ω[dnɴY*,,#:}Ϥ&*tQ{%aUws(hEP@2tK@Sw?ѳ=@"i22όHRHMӌ7uP$NZ8zKgd=)VhC&ލ 1ǪjcotG?4f ;P\(W< ǔ&8C;xKY(+/ /iE@ţ3CwgTUj4i볪Ѣ8eؗ13E)f[4;P(#3= ~@0 (Mj܇+ZmfF EI!RBzF"QOd׃O{e1OXN@)r?z ōa%;d8CtzrX4 dmtxNjfaFB% "5(b,џ0I$ !3ܤщV#UBXZq@655g Ѩ*Z6TBmPƈeʼU0j|ۥITR9ZF)cj2 d_i I!/FflBtѢ! (]<5 1U/ayz2kÉW-Մ!> 9YYK@UJΡ$'$9QɈ/S8(y*a"DӛEݚ,&E Pw7)>t ^ª~@ \%nj ؠ)lԃ%نMSe  wJߧa_4ռx|nw[ALxCNvv. :|z~IUv~u^)0zu4 AbA h. !$gf~|OiƖA>tG8f U5 D۩ddoe ʬ^g(N$%3h˒sԒ$ FD`V~nU7l|[fD Tl![qx ux FNkeCC8S p j40DD{}%y>\Ȟ_x-u2~\FޏHMp;j^}tZe2f ){ %C Ü]bȩʜADxIwcTGT=8?v#̂:˙2 R|d>c\</ZX}@oR_Î֮8ڗTxajrYLyޮ歡}ȥ3,ǹ+9c΢pchm[:y[`$%Zm B2`.]ynZBK2 ZԗqU%J mgfK;HqQIOQ/a6q[MŸS돿ԑLe):NfooGʽ6^hQmsKJwR7O[?>wyfϔI@=_~c^l_Lz9>5ndWy{فqw{{3 .U72] něe_R1 {uZ1ȠtfUdemck]g"acJjvn.e .tܹ*NovnQgWS"Tϯ7Rf'a]Nn;'I<+OueaĮ՞]6pKrq5::CG_Ľ~u^ɹO{|.<[QkZqfvoz\kf/iɟDω"҃d\ôA==mM?iB7P` 'sO+]GtT) E=&^~ _Kb|(V$=_rs Z$<69 UqAuQcqh{\νۑcA}Χ"VyRgP/ԣӴ8hhL _Np#|e-oa(avPʄ+)2L^XsXw{u/|2l=Xw]>uL}h~7\H9~ =SNcG&W1V偡#1ŭI,Hm` $OO'؏)PRDQa$Ok+vA=!~^J"$媹"aIZd;Μ*1NoUsd;VM^,˸S;mƳBcRpnr?˽Ȱ߯b^lrx)6[m fCrA56S$-m'gWmO>}F88Ŧ=fP8q+ҿuox~ozv>~gֻi"U_KenT@.jD'*2Ι))fM'@P(\ᵂJk%Dt 'Unqt&#K[sҗH $ v " } ^jhϟPA Z vCg}5cY;xnӤSY&CJ[xs``e.)iw=ǚed?5N474֡L0†6Kb5ҀCq!&@M"9R,ڧB瀔'#m@1 f1/ݴ3`'at6:Uh (2v՟ouf9I@OXXػ+?&E5A8. .5OÕ2: i: (XVQbC2%hLZa+E˲*t%% }*A{pfQ2pBnf͝2"C_ DtӤ-zlR WO30rlKG2HGjddY%t74 D ɿHFļ$Ԗ\kl)"흔E=Rʘ_GA(~p9^yMBsgxTh0S#DK 5pvnӳ8s2aMipȑTY18UAx8.pqj+_Fd7Z Gf8qN$jG󇏝AЋӇ`^cNޛ +l4ޭs}ԬK҆(D6r(+ÒzJMM*6 b$ωâeA<ʂCiIrt9! "D )bX1ඇ&3 ˗i;>l+FLpsV)#pj`GD=GH׹`>ҥ C/gߎT^ޅ{K.g\/D̃9vz S;yIVx-WBSh T."rˑjٟ/rз:ו?Ku_-]_(Փ#kKn\L zR>bb̆=DlmܼEw߳B1*.ahzx~Et놏]- DD$!ay& $%6O / NSK+yz<Ma.Ozmmo:ۖB 5ҁ@DYOȽ$`]wOD21y+# 2:Z2C<1w$ZJ L$62q̓kfW̑;HlbX[wt99?r^7MOPbC"nБrt!p (`_Cթ9b"S#ĸ;AjrwH wpa|i'ՑLH-NO}v_tzo"#1bT[73f ҅i.`3hks]~/f:FyY2Q׳xT9+,ֺnOdN/==>O_<.Z(vsV'L}9l !J(A A/SOV/qgyX"[-av)n!'IePEɣBaYle*o>w4_GLe*^.ͻ֧.ƫdTYݦ\qQ+4UӒ@SxJ)qxSC{NȚ   F 7tD76/i#4s^PN()N̷2{7'Z y8' >fZ@ RcjL`"y<0(OJ\-m4cP"e6ZdeHqȺTH)6hn-HvB֥cszsp"b)Ŝ7VA+ =Ȁ as0&H2dh~AFo ƞq`;N>\_?s+pRQrjR 4&<\shQD EBύG7.=V)&R dQWU%A.Ah԰|rlwy3`ݮ+hwfyMKKŮc2#G$eq G!`ʅV$.7'^4P-Hu&9`P҅l7Y%z9 -ֲr²ͪXQɡ)\q4[xl͢7"PNbw9IS6W%|h:Ob.cm)w| QhF "\+^$*:ƧVM?+JvcˁSZ8S>8.QIr/3aFSF^ZdL "$f\2J3JE-$$PxR@f ݀7lQ2@PBY"|w ~Vn1Zի \YFaU[oZVفɧ4x.>N rQ&S(ة% [%uiցDDr+/4$A7"8n:K9QGn}Ux *PޚoۜF=YȼXD9p=_ڛNOǩJs\:8\ݬUhD/d[g(rVŌm.wM)u|1ASe]E|U$ ,4f K޺یkS#kOFNݬSEǞRdρ2HzԸC6<7ɬPĺ)O4jIh[qRj(4p&e0mJJ]qO*5D٠2SR/%QW91< Keڊ ~+Τw_`ͤ#{&LHxSNnX(5Ȏ%~vu3vEA ~ӷ,($G_0!k[hNYҌ!EX<Ў @jI9@Kwx B1ްI L"K'puZ:OtpP1U<޴}>:kmn-kmXPp&C]7̦suܩo>kQn ж:MMgB7dPF),FKטX',W֎.voJRHZBQV3yqMN+8oV#*@@BV *h(DEP]8P>l06}z@vࢸC9QO!d[Ϻw@ t"ERX#sz  ^qlE82g4Yם2K(1I-NB&s^Z"6e0=zh伞9pt}ٷ8X2Nw'#7z>}q]`jW[.t!:\\c?2._:!tj O (h.uBNkHTXs7W")/roӇ B0uu'wb7pi +3g,@U9,d@*ŏ\DIGC;Ϭ"2I){L m8$gNgO >*R"%'V3Xoj((/YR4h\DKY]hg~),1jqYGi 7-ZN Joi`vV<( xX.%nCF/T]Јgv<((bK2_.[9! z1+ZC&Ѧ0@Zcu{ q,wTC 7*ǢϐOS.\[E<|D2E+6Y4Dd6Ip5.JBOw\uGx\9;f'ܜ+ٰŜkrf D-LsD<$lP{zQNs \c="G`F!#6J-3)hHԕx k&#ME9+#ҿ1Eo̖l͑ڭOh -ͬ>Q("wus14!2 &ZL+Z! լeKؾb}% [ؖ9 'Zw rV '̔%wj}dzOeO I YJetJ4.31ޫ9DR J$ nd)Q߷@G:~_"?IVɻF@ʂ" Bw+;w~M枧;-S lt}<+Sd wR Tt,xPik$څsUA5 r)r#Sˈ |D|0CIdUz;z_REϙJE{+Ӟ8t_J;Q?ڶ6 4dK}SП[ao5{9lxww_~ R ]Pow-u0N>Z74 øs%jEF&EAx[n-nؒTՎS/*V"f-)wu'vdC6[@%BQ_bd!G1ʷ㭙Q_rQQAN޶ E!ɰH"d=J HEOXLfh*H!??&0,hŒ;G9% b$if:NmH(<}>zDX H$=$h806wWNN@^>4\fte4ك[jLPWn_hDm^R[ƪ5|^EFم\9schӑ׍7ӾIAPi@(Jic+o|Uv*aqG[e5K1֡, ғ_=K5Kj q +e.}IeG.U-Cߏ  o8 ^D粴ER=4řvR"W2JH+U|fN([ٜw^^*yXE(P/9 UUa܌ҧZE3AW!E)pK*QC2f\&m @@V7H΅6Yn{iL6p-l]vynA`0ym: ?4ćB_郞1`o=OPV0h3-NU\KNΜUY{<aFa!5hY{IlvosxcEu4?$(Ss_|ExD2p , M$ y_V &U\ Pē] }bJIJHbmy<+Od6&"Ec4Y+AC6hLn)MYEͯR8kQ,OTG}RDqo rr\ő$?Ig~MPz[=UwsII# B>ҁ oJ%M9)wJs^tj_DQ?Y)eZ 21Fzi\+3ARfLɪ{PT#K&"NZ9&+](<p9kn GPIFPu=ܩ ] (` ` [(_SF_-1` ^r pЊJ(I?×tt8]U(o^E 瞾a:;S%\p}-i6/m8ⱅC| =Z\HB:-9kRޔ8٦2&{=axF.篼Q=SAQzѐ51V$("IQ7+.;xYxԁc}wa}i 'yCb*"DBQ:YU)]WW`~n6gʞXx='P!n)A{+G8y\nLPu]'y,:A) T ӡBN&Bk}EO{/;#'HȨHQRR|)t#7 H6`BKJCȂի FQ R ¢{X>~uu?>p(ͳͰdئOsa46L5Wq2N~>hUҏq۳L~#xR3&k9ڴ F0b鬜qw4UV6ثvwQi)q,r9_6URߖ6Ra*[U8iLEt!8 . (zܜ&YLy?Sf` z!(lVS:˹ԣMӯXaSw1:2Hx~$5A0 rmC<@oFW:oVD7?Bs1/:#FE60;Y4^ʘ\]F@i7LXlfiU\/ ׭V"tutќUQjN;TM\61e%l KF4h6,HkB'e60HC^l2h3nert2 mN RP/YW&n֓^ CkvEN[~L ? W%ssx!X3('ɄU!1rDv^gEi5ߔFZhԔ4Tj=嘎i%uJ%[76W^ ".SG9н:Seπ̢9) 2]5 TB"0 ܽ.~3C( F@D#:`|K;5[d>υͻsN;DG4v4) u}!~5h%|*m_&N r :.b$R:I/{D)\Gqe:ѐ AE濅"S5u)ּ}fzFAFoLwecEZ@囈e)ѷINZg\%=0 4I 8"Lj6nLp|ʷT&Bd2A ȡJ(<(ٲ#O@T^,f8(rE*42X 0>X|OpCٷۀ}@S9or Μcv&&"a#!M?ڔ/]@rPy T>;)eP ʏ@8v=}uƧY g7?M jkh"'μth?>k\e+j589wzhS;sQ( *!Y\Di)hىcP\BC_l0;7j:dbm:b:t ]?=5PFS|9}׷83JEySX>nB59T ӡ6ψhcS)]7xN7Q#%A>*b DPrx#vS+c%\qQK8Sh26k .i9u%Q<]CMey7Зr랳nYELp|zb}O<c,tB+mOXzVC6VvE\mrWpOQ9yhHJ0's*XsdǙ!@Nα/ϖ "Bm)B|B!'΀}n;<σv8:Kn "(?ls"u$&1|p;DJLH!ݿ.ːAFnBZP;A Ɯw7"ԓ>PI72:b*(*FeHO8V\-^Ŗ4k:Ԏ[ j7ehhybtO5P*^}97WO=_k3*(>Fk2/rÙ{(ԫ*vo9RH9MyY.. a uo3 ԣjAJYె,43r`_x THF.)%q$ H1@YmÃ]"R󁵁@ϭE=JglA@潍6Aa@5wib!3lK)?H/ңģ(pnip7g,͵)$%U͵y_;y@H+4$ /'iHߛћK#.!HF!>UfWj%8ΐ.NlM{mK>c!'19_ko^MytYBV|Y?3}${'Ge%ٺ?SP8rg^ R\NvAR#VeAIeS} GN 4a7q*xM\E&Iť+s[{\k pMҤS񓟖1~Y"|a.95ծx``k?W*KFR9jۆܩJoԘxe^]zT+^7<_dZ;={VasϙʕV_?'USl{SOסw>9]\ J53O[ڒHUqApqa)'RW-; rS9yumM*W9 ҕ7o(|^lկ6|S0V-n^wr=$3^u5Rn\mV=er9uՓ畨V]ƥb*Jgr3VͨTLCA,$ ʙ%_{c)Mկ aRicPDH>4;UOcӶ[M{xrvLƈl5јC.33 .m(ryN昐dlPK'.~q_o1Qz>=p"h\E m>}r}v&[053Rn'9Jwq$ jPXr¡MӈV&iAL RŽR$i59IJ@ ZMM03B91 C$e*vc`"F܋]ۣ!hGLt"+Vw'eD+?s̜D?d圈VGj=wɿ6h$Dl_P IKoР9v6e#OZ>D: lehchX7s/nҨ˚'AU![N>$,W'z+ƀw rg,Вu J]\棂O4H~FK\:Q1-(O'_f^Qo%ʖasTܘ[mY,)9wUτ>Y02Mŕ&w{VOIUP߾8 eySwu `6Mt`ҟyOCe7j$| =&]:v!:Wב6;;>Y)1!ڲy4[uc 2<n̾v/<]xJkMo~]qMOtXM$?-?&; K2/ 4f:P% .]Et[AN=_ZWb[r^(V40;?\t0(ENB\:źA ߿k\+U>r6e{͸m W<ΝzZսy:_..g?=LvSuxɄ}S[Z7Dn~|o-8psO_KK.J}KO4ѥCas:| )"YG(vߔ{gs3cj#">fr$r%QpQ ț#.Dґ4aD*vSK1w`+eJŊd*4R{|;r!5/n:#ffM~DQzέ?Ӝ; 7_$ñZ`ӕ|{^U0qE|2ݰz/^UÁ}U!RƗ'wzm8~wO7˚-엃ߵ΍ ɶ9rB̋Kmrud~KPZzqG"hfprӛ4ew(m[^gI0 "~$P~CPrf|sskWVpSQV׽fO7덭GW.>aR;LwC?Cݻp8`o3hb-c Dzb)O#h Z+ߎ%IEx!fG,=+*/s"ač>?Io}Hߣ1pC#)cOGUB{ν=/|Vq'w%g.=uǙbNooF{F @#kD5s1y6;1A[G6\s#ۥάo0tfnw 2k\[}̫] ` ٹx=:͝*6;= #sO\u"oHsgV jԲǁ{[濟*D'̟ɣ>/u|e_Ϸb'{=jz\e?#}>~(=~BzxsO{B9ؑ,Ju?}jL|Ϯ|>7^ Q+ H?zB# pX6cB"NDX4'jo ivwrڣ~W3MS=Fx3$Z/?W6 9g<[^Hq0A]k#-Vb! Ph:Lc5ɢ}@]}=쾢 <Ӆ)M0W4Q]8j+O&BI'O9)n[ 34[Dqb;2ENaHLwv+$I +5  Qޮ;MXݐ͡4>9V%G83*t bCb EVE +#]Ujp>dABr5֎c"ы+Ia("qf& #D h:k(`Dn*`ӛ4}C;5eѩճΚdo5UP-j\ɷ06z %EϹק6mNOeΓOQqLyˌܫCڛ0UǫJQUhq/2pIIKnj! qq(|De4s:Ø:<}h3?M}VJV { N[ee NCGX9dGA/&.u syR3*inK*p2ݩaǩΥgpP Dߑd4NQ~`{7)7)4:@nj\1ea E}>DAV 7AkA{S$\ܑ)j 0 aGԘ֒} 8vL(K DX2 {M`}SPu=m^4Jes;-^Fܲc][^|WX2Ǥ0(56Rǯ+[X֤ͽ_.Yeih 9L㐽w@rtb:]H9x*OӉ,hЂ ڷlSi81iӭ}`m{?(1b8;Q=\YYH>?Sotr={sq;*y=]du4Q5ߥs`|cR/ZKq"B ""؎B?" @}, }73MO'uq I2gSadzJ?(HSǃOBE-YZ[/#s[t\DPzO?#9|=G#j @#gXzje ܈j$W_g|o;")a{AOһ <0%c( 0c)"xۓ$ogњ>11%a4AZȷѥT\J[k#G.A5nq&#S2;uͅ|^po6?l)nI_{?3_ o<}Mkon=M{i[šk҃~Tk. wpB%RbRO~ovܻ1Ks3` HP┕V*R۳Λ=$"E׉koאriбFV (T'dVE $<Z#N `ϗ"_ƶ)~{^W{ZNZnB2ah%8=x*,T4$N)x#ɎQEr?'4 PўgB6[Ouwf#9NȚD7$dO_ZA&#@6#aD?C C@g.O;!b',k5bא%q!,W9qh?Cձ^h`g FO7w_?(b)x Ytj;}Lb@ ^/[N'ex9>ǯY{E^g@vx.e?ь~MG8_Wh q*ɓVokqyy8`v讳. 巤Z:۸^.iHDa3B Av>3PH  -Z ɇZ!x"& -b,Pd.G,|Ŷ޻h׿ثm'"7t2ZKѶ74R4>44<_7>Nǹ:8wڢ7qWs֘^mOnw +Ew%pw՟{x|v^{ox?+].R,_t<}V @ @D I%[$t)u*]roSQy |V%b0zDE"GG: YcHyA'Vpu9m.UKH[&8Gf=rdљ~8urIJBQbvS>}SwDQV(A[7Xv.5o]m_Ag#4"=*$sLLk]\81}v6|}/-$թ fnR&7ӻ@U8 }uYkݒ%U} 6*|ã Ċl4#}Z8W,/6\lGj^Z+дHksyCX|V#9܌_/~& ;^\un(Q뒛U,+KͯiD$˿?W&qgPaeeG`bApmyԅw> " kްDt"(f@1^q C 1Jz 9>zAsa"I+3 #;ŎXo Ӌ>pTUOg" ke֤2CuK_gs~QmJ0b]2ϣRVZ޸qڬV Tfל(,OԼʊR24K>&" |t"E= ^EŻr'{|C Iv+OL,5g$4Y{z7 O΀LblD}/d8ɆYηnD7@}Ĕ|rԮA|_W>t%dFW|]׹-)y?&ȑ>]̓!4 j ΚߴbS=W.~NGw{bT*U(|?`^(F){vٝeIџn,8y1 eȶ( %R\MIV,J*L^}[rkmāP(!PS]Hjoq5 UѡWźq/VәpS8z [My;*tSţ9wQWkSSAome h 8'46|>+tXNsk$k@ss9&IɨX't Lx_""$vfyׅuu!ՙ6Jh*b$\ڷ:* y|,b &F7 .«[@RrJH>@s{LtΆxw@נyq܈ 02L wb .]toj *ⷀ"IG⧎  T*p\\j h-=R@>E'҄_w;Ɓ@6>mˆκda4Z)X)[/)4M Be9Dq{|;Qn0eisÜ`]1j^ة&L|-!uQA ]ad@%X2s3Z!C8#ғEt3^\ ΄w̧&?m<4z%΁׬NO2д8۱sR)$I4CN4OŒ $`jX~s)&㲗^0fA!+Kev/+^#y,ЧZNXݛNn[He?^ O.1TA$&D89c}N! |FǢ.>u4FvA(h ~z2t}{~s5dxn`J-*TfGcÃ;Ͳ~O{YH|8 ǃX%!ʮR9U'9$p2\=gh<J!)a)"}B@ș@xRtɟVu N.GeI9=#>XrRj{bx׺RPIH) c (XhŎfw҃^`* }9:>ux2u`k.!wr\aDž9U( Z‘yV+-[K0* 5. fԤ T7i.ë [0㣝ZNXiեy("zd !.ۜGB&e.t l4-,q6}%@?-6'd4-IY#/atgVQ^2g[q($ _blOLce3\IIy+!OwO FSH"*%'TI ]K-g; dg`ɪcssYz|o)w%&/`~Fy\9ͣfqr;VQj 5ܢ4RCbii$R[E93a@%z{Vw8\X@ l*F]鍋ӽ PrkLW03Oj푗U[N jkp]3X2܍}Ϙ S+2h}fPMa]̑_@ѩ*FI$s<5Hl&Pcϔc3 ]PY ̓ $9*x-8.&rһ2s$JJ2_2}񧅃lkaNa\<`+-&Nd'Gψt8!_&l׊I^Έ?I֗e`'%i<ҢF-'z9ڵS]=jMſ9sU&qū$Ē:*SMK?]x-DKk%ڻ Ԑ/k*4ƣ פD@8Ank7mLǜ><2lN=XQ8u5ٕՋqJ%M}Z u/Yэ7i2śU:s>{ RTvDH*g0GFǕrͶc~u'M*Lǖ 'r~) yKR_obuBoκtm dniZ @%;s.FbdגYEXvtҸKz$G~[ GDO1Dz~9@Kto|D'<ڂ٥VJ{Lʾ- egHHRe\PH URv3'[?M1@^܊ sp""P"2ȍ* >8qR޹!ߋO8id7R9Ӽ!BhoL٨U~@*6@/ aHw L * '܂@^^w⎤c8tV>#1V2F~>5?HrPKN2xA|TV.XzTD$% J,CrYg? wҿmdӝc|dU(Ae]!*\T^՜iAsjd! nʧn^EBdCMN@׫{ c.._nں㰯ȄRR٬ݴ!LSی̤P fX =~Do‰` ד:ox2Ob Dl@?ڍɥO]/RM|?`4`?XO8y̹Qpsa h1W{!v<|4%Õ6ͯ2.m  t$d%Kd)i. UWZ&")}koy"A;H' 8HAYc}sy\>m=~mحшU,ﲉA)FÔJ~|y١bfUxq.=8o, o󒶋}dTPf@. HMC鍶 9+ wS1R_0-J31$ n;DqQպڡ1N#(N<&u xgipI0,X5s9RH?'/uq˻Ao  $YĞ{|jW弉Ic^'ue>J>Wf~?=aO6W&#s !O+1奨0109%ء7|17_Cvqf@7J u 2k3N-_6%'~0DD[]Qx b4pPExQ}QPZ W˔;7:<+?>ĊD [4H} tRutͪ4QP"%H  o:܅Sh"5`bOfUy 3h*q LVBʨ'yHk@D"W*xؼ|TțԂ`@XH=G݋ hQZ̈@^r$ .u`m(mMQd7J1{E:vH!@,"?De @2:|j?c=k2 "Ogߡڀ~0<:-`eBk7j4\5B ۯ{NWe)VZ߉Bhz* II"ѕ0N썝g_f:<|T#]Z6(_8CDD}(^;.%E> zWcel>_ȯ+`D H />BUo4&[D$.FGky3!o+o [uR$a$W-IA[{=""!&.JG~Դ0` d1h[ȧ[ǑʚWM]M MSG7J ԌeVݮ"b+"~zs3/?G/?W䟋|gp@3ネ&SIԔ]c@/$!Ɋ1숿mzrO?D0 H@4F|_ $?#U/.\u_τ<2_ l'JD hHT_|/O(O2{]}}8H%( H# {oϾ91C%KRA (I 8j} q׍h3&XHl9G~ċ pQfadսyMɽt| ghIOj ك)|QQu@`-cmv[}(NP> xNA 5;<6\n.9Nj?ܡ5qq1y^yLD3;9@ ,#̞ 9YϞ?r\0\P%h60(I "*QAN|@ϏAHV?öLu,gl\*1?jnRĄBBQ 4֬ : ?*^kƅUԈg_@T4Mm2t{XL"hL $ZEVX$ g̘65qiAD@C25`@ ж3f$ܷɺ&`JSr%"?q)>tu= Y9JꡃlДœE+ok:&k.j/6ܽoJ̹֜Yp HP is ىeBЕφVwZs =/[77/T&/CD DС: +@Hkjir52OM'϶#wyT($]ܤubӮ]T0֩UA#F\oiMp#.Pz+pM˛ݱVL1vugLi :KO%T 7`IiiXY ݒ=kDЇ@B3 `h)K*K#sTT8Jhq`&[Of+2w:+ьOCiàI|ئȫŕonjKõw|Nxoӿ$] Aaz|kӥ#nW;]-OɣpNrGe4ЄF`:֩ԪtRޝqZIdu{X980$7g@BNӧFTy,1vll-͟Dn{2.eϯUںXL5/PN 槟$Sp4[w!׳z [ORٙcIo'bᖾv"\0 DD@XȗPh\a}O;-%'ܾw}Obhxrc\wkr5ULvA?&?n!aO#Y_N&++gǤӵ\0i݀$hUe^ˍ 9P"$*)F̡@\;xg}0v1Cdܴ^vb`4mx:жxNI푒t=Ăm¬ g.B=\xmT *P6ੳIJ0!ތ4n{ HR̄$m(۞I |7R֛Mg*)mb;@tEw{ՏR\d ڛ}-|ߣA0!(LgF F fIhKC'֍T*?+tQ8I=?ivHT)Y*I?Wv4 yS6 J#`%ɼ!t؃oZTt7ꧼVO)ˬyR{Vgġ? *meD @[G·eNA{:%@)T}.< axW{;G-* Bl~%>HNЬP6N)AQC@*ls`ej5Fxuki:DC;nvwU4XHd#T=[sf߸oz70l4?c 2Gi?XtW҃?{CYU?OPTORgpPAOG-qܗ?]~9twɟ.Fɬ'MQ W-fmmo^,$C׿-1w|])yibY {aQ>+u % #}9<$>8 Hn>U mO޶H8YY}5&؇gyycFXw]'$6.;OԹ[ɉ*3^d" R$7757ړ=L}sp(MP[!yܯ+7vGFwO9t3-S'|e| 8moZlpī &(<5tXt F!A%IiNfV^R޾pjxfnvqOyf& @eBy{lғe^%FmHmo;L"ԥHoi]zpwiTWsp]JDS{s/ɾ7 B wz͟us)e-Ny:$A𬦕\ÞU⯗W&4Sɗj1EŲOgH49:X1nN彅+_%)(}מ>F߸+oyj/F3BOiR[hLkۍWh0Ml˗{@Z[^(׍3[l$:>cn_W+v!`~:\qb ,^uKOpO!5k?"YTX"$M^f$.Nq86S߷I0T6j|uW3ݑFQ߿BP4^a󖁢ossGfg#r&y2u2ݧY9e,5m4Ϭӣ ׁLiNYsJgd3 U;EL+x|Y*H׬rq BBV+ ;'xފ,o ].D@YAVvj>p\k)_~~uI:ut " HUD$I7 @Tecиeֺzu$z"n,dRFu`^1%-L1?&UiYMKeUNt ~ɨ I$R8o5pe&`-Lɑq@V,{m]6Z qN& txܞR49($%*L #Ih%Qfa$Gi &'(N@A$/Z)Q`%u]&8OriZnU{{Ypt5˶u9&uZ!OՈuk)ES,=;UPJypϜ=8~X[% +_NbZjq>wzzdjmx!|_@&tRBq FiOJD`^}D-3!l4ph$hÜ3׃b]蹮OqO&Ɛ]OYGp鐙F9<&iÉMYu2tST<0e&<?/akY#(t `j:cqQ( w{}>1fvmuc|rם3;9Cr1~l5 ̋E6)VtWg]_=`7})A[vali[iP jRಓU (j>gޙlWy#wZ}1KWR.)?C$Zr*{x'c \kKi},_$>¶.m:6{adeT1}ΒĖSgveta6VOE25 8zZhw;%mByiHI"G,5P:+ؓZ65T4ޖUUKJ"l1=7z??sUDtPJL#} 2㏻~Դ$I͜ǚ>@†K<}"5`F6%6`(a4=M@Ƚy3KE?_ W[X2:=|0ճ>e2!]9]޼_Sxw a}eq"Sve."DyRrϢvʜ:_FEGYC.r 5. ˫`ΛJkPKQ kir $b ҂k-=)z^i /u4Ȼz'|a\-B krC+__\h]!Ϡ(Сcv :Ed9^_.(# PſWf+c϶x, P!Uϼf7;xwg1ʵtK.<cA2${:ReߧDBN(ŏ_'i@}Qϐ䎛 E 7JFalkPnC_BU@\Zs#-)`i8rLrto}=Gγ6t9Naiz`iI-qnL:4Uc2˼QKf9O܉lnFăһޖVe?mHcZMlPzkۙ2ɞQzk͟;FNKP13Փ񯶢!ɟ\F?Rbɏ<-hv'Nbvt[_== PmEx𷮝"(_UjJUCm}h!=A$c0"$PrI2V_f[cS$ @NQg_v{SKD-ݵ|~BڧT!_iV8mZ_[L7`fA$"G)򅋅h(T_g#Q\ɚTᖝdL,`(~q ` Yw$Z+@j~z-/}BW H& Wv䂄$E*H) dUqAg"*2H#?G7)I$~5"9&Ejh&fpV=T1bH"֡I"z+STqh-UPQbp-EwE0dzd\GʰSٝ<;Okck~&GeA&pDA+5AY&I'BPz$6(Hig%jef-)sD ZkuD%- `ʥ >5 Fwb!^qyvgJcMU2E\%v_nE*sϦ4e^qKcKIfRTI ӻqd4IAER 5"HlKT|űl규V씆`9)I H5QjAۥ1ξ+T&:DK̿AB[m)HS0ԑAJ@:H3 :~=}u{k٣ !@<]9LQJUX*2VU4LT}?7u|3U -,ATAaVoe0cioφތp;>MJR"BCS#"x;qq͸t4SUƪS $#XI*P:Ic?h;!E?e\gLQ^lNϟ3,̏])2`W]r.ݬ{q͔1`UJ?ւ#\Ն_: B sowykQ`J*.u@$((x?2CW)ʪc&2eee=QA-h^p@gϿ M$-sr-R"4XۼC}8gXba> ̾BҶmJ6Q v`F IFKO;b?+[ڶ=xV_C_Vr A^+-!wdFQ$6mc)P^{s}9MWEALmmw7)JR@Anvsu܁AOA*%4FGt0s !c0(PȌ3믛uq@Olx2ϪV;ho=| >w=\ ^5=_{" ϳ[@b%|@I#!?HgzM: E Co{i5շ)[ / 'tJ˕d @!X;2w9hbRhAMza:UZaH5 (Bآ>l}ۂĤiuc"ٌh ΕgrH%B #=ΎT]WlZ-}M:+daeXMQһ2F57R(dl`Cyꜯľ%c.Lt/de/Q5ܯmvrFWY/vn7.UV7| mBL)j*F%:wJ%8ޜjQd{j4^â<e4t鑝~3tB#d8 4}~rk:QB㗂!.$iOON%L/W.nVa teܹD޳xcωKqu=gBV37hZT(Fxя^n`tCNFkI2PH1~HBTa)l7M}s?Z/.c6<85q|ZѢVQzVlJЃ=LȠ/84,=Y[KW 3*6h^"V8Uqyo9 ci*tdM7swij02A`]m}Ō3׺*6%r!۴-.h+syl9.pl 14~my mg3t4gԡG3+~*YCŷ=7)O?PW;HX| ~U@<:0~3αYG1WdN:33g(4,![YN_Y/y#=?c%JO]ZEPxo3I Q\B/p&t{sP0EyrQS]WFoEw1̊IT<057$5"Г=w,h꧞Y bD^ש4e4S q̯~*f,5u)\ 7 \"lQp>%& k@MⰒy@*vGqƽ4e0÷dP(dFi,SS+=~?l?XxUG~-;=PVAtB :&:rh_F&2W,%HP ( $X%N';] d?sŵ⣛ŀrpz("h:jV{Dמ @eHPR$fV_Mzjui^3DHw5jy  1t"||Pca2SFi AwY+*ȫtn'kP_!|֘bCe[#=p`" (.IfUER!?ZJ^ԛq5\S9%z萬О b H6ag5A{s$fӬw`O佢:*]h r* _=<ξ*`-&CFd2D$Q'K3b"-qVy,xF93U9[nxVbAԋcQH|nWݢ|jmުECb ҡH+@߅uIL=xefB!7g!!ܞqGvuSX ]\)T%H0D:YxZ)t;NcC%9 0|yB1VuhİT 7T Fu 5:bޖ)7P ˽XZҖ$t2=h%H54av^Cxcnѡس7ocU,Utdp#P{h;Z?ysOʪs#%y.uqd`j`9%̋Po\]v uEmH#NQ,ɟfC_Js÷QqD e=-HugӔU(*Z ,{2q#;cNm[\1.5Ss:̴ӺhWNMdS DFCڕΗ`L)Ǘ{b<:0%٤(2+I.I! x7|EYV;؛[iz;J^|Pufcf?a) BUh!IPன؞ GCjWЬ=f}y-B^$$ (#pՔR(rwfLx}ݾ |nk_905r_NB+,2k"r{Ԝa pRޅq+4Ka`[^wH.Xǁu`5CP42EDEA#e t0He t|mUJu-冺pk )%"I$@*U$6U(J\jD 1op8 DXVREy\sSZT=C(؅)PXKA z{wiTErXO[՟"Lxqre\~+Pސ<=Ê3G"w!?*&|+8^\Uz;j_]A`4 z\~5tJ!:jigQb ,UH*QAcDi AԵaBQc-/,0p~+Xǵ1 *pWDt)q\ηe`D}f*#_WʆwGO^3Xu ~ di *r甌2/gNR[d0E3TpER\MwxRp( KS ~wh~}* {~m%JIo^aޥ#2[PK( RZ-yth'.6qJ| o2k (+:,W~|0M@2Omu4&n}!ʘ6tplDT"z EK{;tF}IhR9nTHf w?Cm,W8#`E& 2(w7X:C˹ur#08mr 璡;4 MK]  u'L9,nɐlpsVhihMh&WUCa 6sؕG=ODC\|>Qo*i-ۗ$.56])+X9 (i#d.kU:S1_CN!Y*2jm͠l4zA9d5pʲ bN׎@:-˘ *mӏ#?`~7zU[~V_l>".`;vIqC b j3;Z 1x_ӭo 038ڲ8GLXC4ZmH(Ed`V٘zx=#YyM/+ [ᇩԫPX!N&^^յУ`R,e>˹[ߌUXZ~B`3 ͻkGh2b*KG Ӣu2P!gZhW Țh9:a5g$4Ԭ׈GF-/oj^T> lq[yj Ҕt%MqYc=fuϒ.d-@vI ~}F@4Xv/)m(zVc 7[cAi{+`~52&Fz ޡE.Kx0Ca Phv+A>9kK9Ƌg^Q[ ТNo)ًAA>[~VoB ʢE=^`".m..;%j dMogy>}{5cن'm՗;}J_.pɅIÅE_iIObuڻY)k|n7MDzu*R%qrz~fs9C..GykpѫB|gHJ;,:,>[*=6zi[Qz@ؾ]AHbTP4o'Q{H|xs UJXQ, Zf`wa e*anYZ"r#}JI6/^ؔA._m4M6 HJWԪ4V9N:fz@TC.i-5͏6$v}TyDvG.k ZAJmnenU/&< 'b9O4~A Fa 42-jT/ZVkc:؊+)\jEym0 Đ6<^ 0j0𔀴bJCFKbAZ@aroFz ˂M6f6_(Ba}-t_ћArڸjU@Z`$ڌfF1g!sF [T’ 7NB 8i=̪-*w^/?ׅδR u]߽5H$(vt>'.hܪ_IX["|PͿr&= b)W-ڠ+Pn|Ϙehg5zj mG;|_Đ},3*miutC=9[hͨ:{ ~4;kW O-.MoKV9A҃r h$B< ŬIUɣ ^ns5(O:X_rM~T$Ogܞ.iѰpHJ SGġm(ßkcs)A,]ބ)W+>PW_͡ .8E]$H'x| +"fc#Ew[; }O{vTXYR n܂C', *OYy"0=_ŀ'\x0B&4m`j<V đ{2L cCscPԒC*{TV'$%5V hHt#P \ׂX8 جͭhP^9 F #k(1tA7 lEsyeؔZJ9%ct+ÉP)?C!Qt0n[ላ H: ң:1H<~Iy<Ɩ:L Cf#*rn|7)Y3Q$g+<wS=\7ul ~0(QP_&bj Me{ K+IҦV!崐\MULIF 9l REP4vj]z36%h 1zP{LF5hJ9O~31ZX麱)ie.gAQ֗=r?fuU`Ng;~|LAl8s)~`KLMQ08Sp8p<1.:KR*$Uawda1bqK! fP)zbG82Sko.\Vj_/YBV> E5\2hSlI m?˥Xx*]j hg ᢙT ֮\1҆i%!-x)!KDvֈ3}*5ynq=RPE׹m41cǼ^9RX&E,v)FşXOm+Ǒ)e5!AArstF9Q-sœ=H 5QLw׻2EZٖ"B I.7;ZY2Ǽ٢5dm#N*9l>ۻ^cmiam,V[^!ql K>X9gGcv}t &iөS`AVBRPz6D L=N)ٗ3)fw ml`(ݢ׭ kF;|dlcu2}iA$qJaW°D:?$PTm7!DL[ͼעLu9tl`' "뛧FGάGE<`1"`0bǪ_ۚwz\ۀ/]ke9䯮5b \HfYX,b͊غ* )? JX#r+VmbfrDz_Jm)KMlʴqiiu% 7+c1O^TQL,{'R썬Issʊ>XpJ:2j(B$Po@9 U"%M~UϟMqe߄I3pc>m=5#Dc`K*JQ`P~r2+0F s?Pb}($vw#TML2 z&umU %ry~?:NDpwn%ABIR\Ԕ+!Ϯrmf*fp`CV)^R^#kJ[ڦ_dlZ%X=gR pj鵂رc '+J פRi5UZ8:+epћKuDT0 wc_xU!:Ki(sE͂Vad͌<w{43MA޶[QJKh|"@o*־ ^QadWl7TVO"պhRǦs=QG9#HÂwV2[wn{6a?\P+R*ԦO"0ײ2U7dVTlP d^ a!KrԱ&}LΫ~G!g}.w2_{rQӀ-C/k$(YCg297y" &ӹJ-l.^5xea )0j#9G֐=,MYAD71|Ǥ -D`8hdd]%zpτ(ߖyy%S!xxuHͯgV?ٵH_,πbLy_gu7c:\Y'Rьl5Z|Aъd^y)9yй282s@+_.sOHF ()f3>2#jO'TUշv=8&7`H,[P/6AG`2^iTDtykJǢamn]//CYٹ>,$$prt( JqfYʹ3A͵돭\kw$?V#SRC(^Yȳ^`_!@*keRoDsG֡K5!w}eap񝦃1 3a>Ok{*ί!,\B>]Z.#I.} כ5sillhhK S.Ipt߇]H T~8m|M]vU_DV%og|NA4嫐OKua|J!qVAR z,2N.ƷG }lu *4_Te3죂2k3Gum&"{h}nH5"1rG9Fs'2l[XcfށnBieӠQDXv<_Yl5+=K)U @_RϿ5`1ܗa;B'nNfIf~ĩMQ _ϴoV9õ[K@ M+(b~,Czp H s iU?'n^YH[:)8(%χn߇pK[w>{`||Y4ZX[ g5IOWfڭ[Ps9+r?:1AOitqe(o.$=YZ; + $ȻOU*wG˼)@H@@$j}yi~Z6Fo+,DŽTΗ<b-1#-R!?Co+KZ72#!.K5lLZEP|0xicB_ SVosq.Xhvc\/ʓO5 28Ĕ5z]k4 w+/H h6Kcru7J [!s^mkou筎^Aa\rQvTn0K 9RJ=:_ZnX16v<#P@qW\X@1iF /PN%/B10 ӯX;|$)io%=}o]"Sbdz U1b^nȗs3Sh2Fn2gnZʩ ;9|_36xj(QXCHJ@lMFbz O~IY `&S9%34 4DFٚq䕝݌ N[APRr"P~0:3kxxS0-"Ϧ85?tj&?Q m=4lA5]mR;ʩG.zClD59^W%n\w;սlز3IoG(( Bz5,Cq_z yhkf&#SB/ WbU⭃4wF[:Awծy3D DĠ6&0CE5\ǛKoi&xPX[G#Q6(h8PWj=g E%."ŤWnApBc,~>8 ԿJOGRl:Tғ]HOloȕݟ&{ >j?CK=j2o&J6{ⶵh_,*؆Z*).FqZZ yĜu"y+Liۥ y<?Nn6]M%ӜfL( s/1_nmǪgipc N5 ^~j84Hxl/Urn?f[۩6yyېiBf_"e^_@oN_wr'^󼛶_-SւYT&kAjpW>PEUyHeKVBӢPO/6TiKZco()yT1egKSd?老_Fp 1!4㼶5/Z.MiRę#>}P! wwNQ:hCLO1JZl:!~&QMtx?ҒixMkhi5lEIנyHOդfCKꝕ0ڡ My>KУWB|jV[)kj&K2BK\0 g @VOarSTÃ\uEQiJk ?UJ\%ewaAPLFGUQQKdE{{}_f8'yoTA؎r:T ȣoT E`P@>jz"(CCx!z;AQrؑS|U{ 8DԖ\fVp3 o<]P9ä }uO]@tcwsR#TY)앆6;>+Q!1RI  @f׿R:w)ȯ!77Jk[mttv9?>GNJr x+n[~`>|t)|qŐ+d+ʂ @؏ɳ/N=7(FުQGwN^IRn]QJVs ;ґ߬%$HFk= BdY\iT+TYE ݚϹ'BֻE= Bl- P<=P!`gb.Meȓ+ҺJ6{ӔSLwimcN6AHu2O?lb^M-pQV"7P|S&LgrzP(`X][gA=<,Ũ&]+-+o zЦ9_r & p9s>mkL4$G.8sR`Z-0siM _KOֱ(Е쪉N%VP@Q@SUģbϻz-?&TMޯ74 qrjʔ ![Z;k(5&K"%Oӻy,{ڗ,j h1بs3 2uy-Idm6JJ*6r>?z}[~p[j)mH/FY47[ B BN%Topy>_ŭrX9J1 Jm+f( !QҥZz1oI(޽n t ax1D:U<^Lz !˃}C?f¯uF$1zi z ,ޗ5-FRWRjk QX4R'ujV,t~Dy9qn_M&m>gK&%,Ik{wY5M-%n(P$c%$G: H\mvs{>S; mdCIKNyW ?dV@|Zԛ@Yv:{?ŌA:n96PAΐnN}0nrԉb k~1 q[$C/2*]@(_wݧm'GHJvj ˜CR7ۊǺ}5]0uIB4Wyi1#a }VHCz[q? 2|6u!ouVI}ǨS*Qj*>Vc_|͙QTáC>ڮ}ªH AmA|:g '.vw+P@$U OL+QvLj}sx_hImMepV}2$(IRnFWIB}y$trI3n` N9Q L2Ve#qP9HTv~_RCj4]~}hT}A_W*Q^HHjwy,nLqm"EiaKOO"? s.cJ*!bA[/]j%Ȩ/aBze[aIN;Acy D{r#!Vq׼¨ =Vw|oF_/2(_ѳѥ}NW^!'_oY>#,LApPWxK׵͕$%K)5XMi "q%ʤuf/7b=)ru#-\tVM$?ч+^`'?#=D aAa o J&RDw-2{/udxZ:dB]2VCWq%oK$M<4c=J:7'6NʟRd!W{eMiY/Tx122ER}Db0im=) >HR5H!ۛղ q"+X ,,ɓQî?VH'/&_71Ёu.ENZw "! .P5Rt?v c<: vz#y2n>k1t sL0u: D|wwx?hiJmM|I9fx=]a%2/}ӚкZ¤z XyߋT 2jӭOZ#qp#P6UO =[ U]WAR$>wOJInj@%CklcZD_l?Ҏ [_KtNq4ad3 @`FW;rV#:.F[E]5>ox &:%}zʃ@cO}MX Y )b@䔝(OSϧzhy}6O4D>>  kT"r_W8B3gs&hdX>m7B=~9yYw|j?e}l_u6-.lme-QjM%J~,a ,ʖk*Xo׵c\[ RbR?_]^ހsQK T0OM7<(@{!TISq@B`;B %oD77by>8re+f3-1R`%BC+c~GԵpl(-PI-3bdEI D=:2JPW 藍!8*Acx8f+E*-uW[G@*Un|ߍ ZD5k$C(,;74)}\l6M]!dPNBgKb֏:Bкtjy:am ;B-*>Y΃&gdZd(|Zh?-@Is((dmm{v;#654+ABҖb  äM]aՇ=\{ڽ&T (X Gz3^&' =g>tId TT$QFk2Wt[w)wf)Hi"f &OF%?+N&m- "oe՞='.OCR",B"\7 ŠHm)yB !Ii]I;^k#ܛ{ւYg윦2II5T)äR/$rwET.95]1`$8fP,f(:=.C#S]֟#'c0%؈.z2` * ASsqY=lwYN00KOyv.C5~蕂?Vz/"T(6E#B$_xg_o"$hK0٤hq`R 0n7`$(},9&Y%Kf1jTY8fæC9)R 6tu0ެ;Łz_a:AU}>3PYߌ0_U0ww27' ){ZIADՌ1`pG]x.עޮS۳"~v^#pʱpG-eEjƗ!R}`ĴԍɬxomG$DE:_˚XP1;!d7n6x=x/M֜F?HH[eMH ]܎?׵;z%”T2O8=>{?~h2Ap̈w3O$i~=_\]z3D;̺vrA|(`*R~-nܗ1TeYYOa -:꾜OyWo&Y*(*Ox~b}szȍ"_"uWL6pT[kqreïk(Cȭ GjW4my|^Kz/L= 0?ż>2 |R@eH 钳?{~}ӤA_46_QXČD2!(JR5';+CFshG)P S#PQ̛ ߄0 dq{=F.f&S?gF=|4tS|z94k}|OC_ ~K5#?>5S43\¹wrhym="T# ROk|j4~>Z80'}iXM$Evڳ@ӔRv,9TdT(i0>Q\SLYKԦք^‰ !OPdS]f Pn/]6}YjY3j1#mq, Y( Sz(jy* 9 ʶ[};\d&Zg&rCTTh"2 j3 9eKh3ZyC@B&g4"rlf VfF6U%+Z'M( vyj 1JvT%đĢV^>RŻ@#؄1LkE/ s%NE;ͦ7x)vՖZ0(dy`hʌ `-u4?gqjl\>& [} KBRndQX!=gd@߯1(İB M AiA@;c ID4ӳeWafQfT~v((KQua"EVUIZ|kښ{v|GH!pxY*LoV߹A圢elP݈uA!D;S .mWIPe1>l9|8җ(S搠!JG>JRO aX|,6[sZ[zI4LAGftxbчr]{@/F ꎇ)qU31zv ̥>av} 34"5gAHA:"Lt*I}TۢS3)& jâCt*ggh;_g{/>6uap1 $H 7A5AD F>>czL*.x8]631ƙYqR$qo۾ +DoPrxyIqK*U␇+{=IhgU"$9VX:lMN. K~)1\_ݗRxq["V. 9$Z6Ń@}4C3bIg7K %0$by~=<:<P NhQ )М" Ww?OVճ0CA| |@||(@ @IR@)mZ& NHIyqRGG3 Y=6z}F-ڈnC6?Gu _U9e> QGb3<)|eҎxgf*`L 4CFD&eSf˅wvSԽȁv-b.!ByU2H}Z^@j~0pJ4ȽvQamX T'd29T]1[YOY#-!?CQ1e1BI)q>mͲ.0M$B0(Zqޢ}J$?J@Z<^Q,+[[ v򻓨\A["S\L^ - 4 0H0_U@1Ei K^ieé~\<){ V#֤J T6 )Du #[84Kz'f^5Ns8= X"]Jщo pF~S˺zT;OI_;|2/b!/ۻ-& ICU@&W?P-iGRh$FX.:,$*TQp/" @ {@" t *7q I(Q\-YT\!A9`1B<nݘcݜ{<H݊ [5yФH$@=_(QȈGTI(HSJJ0 NK3zsXrMfCb|o"dHٟS~C|'?|s((QgƩx(viU n54H(H]Q~ŭisr(((56~n^#b b^M-f^%h`vpR#%8UhʕFS4rH,yVaI9^4t ;Vy5Y>JZ$SS JcObܮ!zWO&ӆ%"6M5Cm6kz1HVjG+*|i}ee[w֦4VJĔ-9#p5ϢWs93Yky^ ,p}wHh>$@U] ) 6 AԊp=?R}3;GԆ] ܈Ww2"($dfR )D*|(PuxƒA;}jd$-JuC꿙 *PP " THQWIRd!@ܾ ;2m8{yЍa.-H&/l::S U/*LsU316KuH3rd$W}Fk 0 H%:<#\;edo%ameW ,EG ܷ_g R"g9CKT*7CymQLk7vy/8ԦMqeJ<ar3d0n;PQ^zEIgw~ ~B$ dqJ$LE<9ll$`P3y P9 Ժm~֗rp_iS!{)lV;A9_zSd1bQ$]Gv2 ݽ̑*DrdM8!{~~oK"խ` ??:0I6fe)ܜnV4SHuGp$)%Mc|apu3CxN!M4~s:3)Tד ݝ8tbnԊR5 IhJo7l N< yt`:U )?2VGA{66LK I 'PЬr$@#?hD\&H""BP ;0}H^sh!kDȲ_kY Svj0řҷԂktg殛htaGZmeO3Q60K$CGܠD¶bu9jz79saIG(:nBuۯ҄98H 5>O0%:3{ l v*yMfQ$zC&xXZ1"EG`\ۼńid\6D !hԚ7.T; E#=}r,:~1"a8Τ3utƱ:e|?ώAdI&[Ckꆁm.@Hvy;͕s}Vݭ,2@% Ah!Oc؃U&2U }cD^.$pnJJXqFrwdBB/߀H~Ab QCfA3$ӶU08#8E%vZ$ri BjEAN77[RKnʭoap_ R B@OW`PwNVؾGb*>YT| R)Ι̲ h @36l$@ Gc5+**ڸ̄~孩F$;ݱQ0sVG›EE$D(JXv<?zqfT<>%rR"WPWPH@VTs1\C6s[Ջk#6J7`Uuaw@1rh(q?09kC\hTI P sYMG7XNM :Ǜ7#hiny4V&-q(5Eif.vaS0H n8E`ܸ RA.5~mP:E$'|'6<`W|=e_V]ǰ T]P 1X4مv'ZNbkʖB\vQBj%%nx#{W)VNJ /֨hw9QDU\ZWSp:} Q5Ri 7 ѥH`$.#4׽CNSoM`Le֎>LSBz{%c 00.0*˝7cYi.yZKp9GC6ceN2䃈t)'OU(qEb&[8x׫eM;Ѐ۪U=׮D}^DtWΤL zYYc{5]@rQA(dtHHT!Zּ0ΡSTKz}]ӛVTS&^3x[7tc^J\j(n(pAz1r֖}o+*Oy0B@pk<[F>0tŗ҄Yp1D`gAflK@* DȅkKIP3R@cMN#ۓ.9XD˒#EUD*?wÒE2#jX VhJ Ur"Xdjv!si J[ PշKgj898$(ש~/ԒOKMՠ"נU]Tk*I*a2tZ,-Bрf(489Kk/euҁH\k`y $Pɣ|߄D ^kf9&Nax5|U- "('+|mjq0kNhm`o*6]WP)= @piGQ$<*1:EX T:ͻ8D~Yq##N`r­҇k֔f"BP1C۟6hM[Š B` -X8|R:Uv7H]V~ͼP)Ũwz(?bk XhR"0uߓLMuEYp=$DTكd`.JW] E ڢ.6~ek*mSӠeO.}+й&-{G9s,SJMWXv0  ġ&̆-TdOIzI9ۏaa 2eCrdr·ZN;۵9WNa% S%E83Nb?xl$ $d/4gʮ)^NflOxءozj.O98bvQ,<, 2"XQOQW60`"`NYl<!XG`x8T+=Fc:y'`GM @ovL#u NxN=kf|cX$ Bad `* K˻v"kl>G׫&GH>'==?iRBҬ]QfzqTWc㏀8Zڥ+(QAvpMZϬ4?Z2fɱx9 *mIL ~X1TFJ# ˔;zr /{lvGpVW`A0`d~S $陋, V64g] 1r}g«<<)"@ln i4"Im4=*nga!T8 rtmdb+^T3?g]:0[s.W֯ag]e^eDC< LYD@kȈiO\zf_GB@#1;3\0BSDg:sUA ݯǹĹUf  B ,=~T:ZGuTa=?SfcϏcρ*BinhK屦8ԴHjmr| }~_X{W==c)x*LU*Uʖ=S3.%FQQhS(/-Ӕz[{jC(uPtSu߮rΓr}Zbj?V2ډ1NQ[QzI=7CyO㛰`̓'8'Uʘn'ȪMu\Ua'p`Yg'5ɟR'wr-?P1ʚ 5 A&GPh%M2ˣ^7CS]ɾ6bp; $Ѐ(+R[I~lf33kj-tsq_VPa5s.24O {#d~4ƑX91҂K ƒP<# ?hڨR9?@oEny_kTXc\:['Loc4tPQILOJpr!Ivw_=٭ Cܲ܍۾:/yha΁R¢!8stV<p$*{6O]Kuv`^aPP:dHDPPcoaX~=/g}'B:rJ` y#Bw -7Ǐoy)x_b_1Q$8XYvƎ,!Z w(%=lts!13{)B:9psF$){'tHwݳlqí&E>qoiG孢)Fnf\ r Ђt>+4gyP a*K6x]OƪOy=e؇بvvetY{m!sYIU6E\qZkZFLPg7$,+aW%޽25ڔ[K.<$H0 n_]oՓO3ϷX>kkJߖE5XD _oUh5R|EV-'./ ڛAm3OVkW}'=&4' t•pMtf9%#:2,ۺ72 ka iȮj~5=>Nm*&KxWʽ)d~m_2%d+6lU6VibqӊX 4Ĺby;p7 GZ4I L| i#kރ}M 5`up# AM{ݨBuMI%(qf]sDn?9QkR 2v[ @8eOEЮvҷ˖he0fA$$4f/DwmeP I:6;ѐ!(s>wҹd= w(3HL&c M*.sI !}2`]9da5S0#y`=NA ϡ-#%LCd}mO$;=—xq h45-" ^&VO@1K_>}d"a:C=Qmu4q=:+Oqm\3_f[ #E@5EAɘV2 뙬U܎LG#:Q+JZ2*U@0?o9rvRz$mwhS^ {Ʊ׹.r>!$>dfG=}59`g2VT0 O]qxL4R.I^x[+#QOID!1ilk61Maɫ&e DQ#a5-QJPE4dmk1FKhQfhlS&J1IZ266L$ f)D3UZ-lX1ldؤHFE4k 5e 3aZi)3IF)"@؉I &MMd#YII$ě`PIT C54Xcb*CHFL S6",eXDɘF$b2X1ɒ`II X,,i a" 2صf!Ȳc&4(( DE"KdS(%D )HM&Z@"L2DhɤXȑ$ȓbAhQ&f%!C0 ThɌ 0P00F32i(#$FMDd24lAI26PD#d-lLfDd)43 hZkXM1l$HX̡[))4-MhAL4J)1Ad4EFD d Z1JdĚM%!$($АLH1(H)$؃Ph҅fL YɀfCD! Dj (٤06L2M-ZXմlmK#5 Cf!eJBHT "$ dcKD FVLLafJB"ƈAQ1ؠE$) !4-XbBR$ЉHD% QM4S)L ( fDXRc21FS&) aR!bA%IB*$L)A)4 Jdb@R"I&F&K%14b,P*fDEY)cIaQ"FDX؄0LE$0Te IRfؕbDX`"f1dГ$3"@MDI(M%,$RJ*)% %R`D 2HAI0(SXf&J1lY6R$h#IdMd` I2@ (0SKJLSl%@) 6 6HAIfأE A&6Hc0 Ē1D¦ $RQ10L%%Lш )LD@H$LXI1(M00щbdhee!!Fl1cI"j3$*kR)(lcIŶLRŖ4fjmEle4LLe5$QQTmb U6CFJ h-hبصFE (ȃIIe),M e`DƣKld@&Xe%Bi$)4#$)dQ4,mQh*!DXb,FHmE ȃ0V"4mFIFME%6M2Qh 4ɲLS23 FiL"C3b,#QITII$LD̄ĈTFY$bdCEERbĔ%hIa mjL&c2dAFѬEfQhJI!"MM 4&%,4"J e I1D6$(&YXi1&I(6 2&LŁC& -&e"iT $J$آcHTBR&hԥ%C1A 0&6&$bJAP&R@5!fi2m 2TkPZ"$Ej43$Efl$lE!B&FL `M#6(H$kFѬZ(ՠDA-E)02 62E PX4J`4@ Xآ4JIEDQ@R2 -&d E(e0dIdK3de$b"(I%bB2 d"$Rd4dTҵe"&PEcD[V)IdTXBMj "1($B &ec)$D1RʹF4*тh$2bRIJLM1c$D&1, c 0EJ fMdȴ ZB4(&B2$QlY!5%*PDɃ`JL&  HDQ6#D)H,F(I$&h%j4T`#QM2P,&14J,hU-։43U!M()eD4 ""Z Y̤)MM(()`$j Bi4цZ-2&hcLb4QIEI&Z 2Q(  S k̥dō$$ɔfI%Hi)d("3&&APHe 2ʘ")DLS)S$SAJ 2REč3&$̈́34K(I& 1I )D I1CI2dHJXi1$P4ID ( f%:]60Mah0bM D10m1 D2jBĘde FJBQ!3I 26QSA- `42FZ,X"jf Fe- i I&C DDDV$"E#),$e2h@# 1hFJ+) CFԕb(-b6hL"BDlIc#"bI5h HMLH)6 2HBRA EM)I,)li)*1L ͉IF1H05i0$#"ҒhL A -RLb1E4̔)LDl"QHČBBhcRX cX3bFKMmѱE(l6i *P)bƤ@K DIPQDY3c%$6$4bb$#dY%%b 4#VIF@Fh(eK!ɍ!)2ELP1(&HLJa"Fi2YA(2S4%H 13#!i%%F"b$-d0i&1#F)XLdI0DDFm2 0iS1cib*jdҤl$3C" E)l,6$A2c#hf#LDLc4YHKAI0DQ)4A ,͐#fH4J$FLdRK (MLF3MI2b JS !JRY 3% &bdɉDRHM%Q4$$ъ"II!Ic HPBK2fRh6$ 1!1"%)fɥ6"KB!eYXГ2EFMFf4VJ-Z6dd2JBM),&lFH 3 DSRffL &RdbQ"LBPĈ ` &1!dd%T2,2#M!bIJ"dhMDR[%(Mb`fdbB$̍Fe“c@Y" AA(hTLUfKD@IBP-$R%HFC0da&(bh1,l,RB(A$͂$b&$ !&@ 0@S c&4Q"l $Bdi4me2$%2&AH#d*"FɐBe@,lRhHJh$dbCFLJdTAF46(Lh*ЄLPɐfITPj6L%jEcEK)HfDc4L2DcFѢ E–&dƑFҌ MH&3&D$D4&lXcd"!P2HDhID0A#IhMlIMi"X"cQL46ō&42TF6ѦlHeԌ6D&XDQF%H$(&4i2LI -"LE`)Q("(ɢimXҙ d&( fM!&K3I#&iȦ$cA$@eJQ2F3iFPl(Y A$&$L( 1`$C2L& ,`5bM0P$) %4Eb)$l!3iM%%MLibFm[Ull Dj,JɁ "imc@FAHĢQI&$*lJ6٦(LdDRRR) fPCI%EIZ1IDH,Hbf65EŊi*@HDCMK,ѩdX4f[)i1$S%MFԖR,h4%JMVR-! *Kh#j ز[EQQ Jb1Ih5!bX*J,İҨѓ E$D3$Y)J"!RjeJhfPfm4l *CEQcRIhA#$ dh$K i%$D0R!e3C2&DhJ#$ )!daH4  $h֚I!XE$T *$T ZeC"*H$jP-% L4)%LBJ)1i3&IfBTI*RccY,RTD!FmfeFF H4E&IH6K2&I@i(D5$eLUF6))* 0[b,3,lIFTI12DDhZ bȢ L && b)"E"Jc@f!YAAA)C4Z1E6haIRT,,e3$(3eIE5IlńіIK-IbA JZ, !)BA%"Hb(RA̚ElEQ)4 4(X6TT,d1Ȃ$ƔɊS&$2"E%53ILD!MI&IP6! YL0lEILM6RR,%2$ ( DdcQ@Y4J033DELDTIl "JM&%b"bf#Dm&DC 5 %FI3`mPh"J2hɋ&$4ab2̓"$3cLF)Im564lZh$ dl4AFi)IaѢd)K4(XLPJA%$DQcDH4jf)FF"$ H%$RŤ 3TEQAY2%%c$Ē,%&e)B&AD&$((iec@)%4j0EœF$)EQ!* &C4dJFc)’a FY(XŃ cL(f2a15FUD0&,Z،Ԇ̬iTHƒTXKF0Q)$fJ!M$(Xf2)a(K6J0QDfDe "bb&4 FMa 1A(c!D&H%EM2 2I4XcE 2ɦZM665j))Ee* 6dě)4Јj$5LIJM(((BlȢ4I6 2 L4R*SS6%4cPă1* $ʢa"`dd"P3DQ4(4`IƒTF3(DE4REMB(Q(5$$RR&"b( R$mA3dɉ&DLT D3 64%,, &4cD#"I4lD 0dhkě25$RIibllc j8X4TRdRihH`0`Q[Uv̄ QcF LFX&X61LFبY)FELVH-EPE$ŃAaD LE Qc-*P&(A%Hc3E KcI,41EX$($$#lZIR[`4F$F#F[EdPM,X1Db,aA *0&6J(J f ,1Pid5(fKH1&mEI`IcdX-la4h0Q(  llIEE&aLhBX lF 2LdF(f,F*-&(SM$IQF*&1" [l(A0Qb&IdZ6"X " cF4]֩+F6#0dQcIFŢ5ƣc hQ%RFm4skS6 %1cRL#`*+6j2FL4(XبZm)ƕfP&h قjБ5E-F2LŴdLQhŨ2@L&d,X6Qh`-$ 0lF6ȑj"*m&I lRd2"Tb1ZL%& AA b"Fc&ERi(64F C`TQ* ,EAK`Bh4cEa-PY"-F1D(؄ɩ*@*$H hm dPi50P`XH4RhmbhABhXQlHCQEa$Z#IhƩs,XJDAQEI(AFF6"5[Vd F"$j5FRb6 uƵFjQ‹)c%#dS&`Z$QEZd%2(j#Y,Tdƣ1(F,X($H6,mȣ&5FTE4EhMjF*4X`Q-TQMIa+-`$ŒƃdVvƢ IlV(m.X**V[[lmEm#Fd f`m`أkbEj*-P CQh4lZ(1TTViU"-%1 $k%jbDAb5Y34ZdFTXeE(,@(b~8E HbX*POɞ u}RC8'[z֏ku6uzOlMJ.M q >g6ѩokqA`DR$kM>,;Ӛe@z"h+J&%Tȋe#!@!HKs_OPT@Rmͨ7YqW6)!sB,k$܍1/K{2cSF,Pad#΅m=H͑z^l+Ok/n`a|Jgk)e wvqjpqfɧ;FEX- |Nə"~ZT}h_O󤵩Zʽba5xiY2Ok'v9}l.?ūF \+YŻ.L m(Q Xr-*͢M/ZIhVla¦-LH~f"?\q}Fr qFu~*hi▟wH㺼9ƽKNi?ݏ[Y3MӃz>6g{pu+ C>N_woJ2ץhTۥtϓ"z5_%WsFэ7UX Wäܤc>U$%U廽z+3JLΚ]_,w/ .97)jxZjq[͎r%!υGJlC+71qcxz?SW6WAe.dױ[pNua'ӽ說"aRqkUK OӇ#w:լi^ u4KJdtt.rKb~ey1ϩٮ95Kʍ? *WUT8me|Mٜv۫M_ v<N^~ent+a5뜶,|ۣ\pu]5* QeSNEQ2{d\#׍TM3|Ro @$!vz3 A%^wȶ YJU\kEJ*UOOX(B.$tIïfuh\:5nI.~]!qDZxf2ۏ:z-2.`aV~g ФJi5Y/+T\W404Γlo?b]22]_Ke |{jWރAUx+IǸޥc#$JrYfLZ'՗vaD]e6ut41#^ʸb]l?VL?5V>ο/Zԍ4d:uh9ea䇇WY/fV;;' ǹefjK˻55%\jVT_CjE2~v$jM=0򼺨*L`[i 6 X8 1A֖ Ӭ8p&NNGˬ!T;֧%J~pTp߫w?|-a:qd?'K@#fXN+-i>-ciҚ]SOR,޵>G>s5s7-tzWT우 \~rEӆ( Q=3*~yJݟ3o|yoTTaX?:epwoJ 5LŸ6 sV)X6R/Oi^K+ Cѓ>2KW7!ddyw*>.v&Ȥ xb_efPH>Q_P]١7R1 O8t1py y랾DAc+B{;=j?gĽ[| w$m9 P_N]f.s( ]l'v+L|ywBNBd٥=nF-=nϥ+wX?3v*_91T֛#ti'|'XyAm*+)sdmʩ|(-#s%i"u$Ԡ@X'*%Np(GH R@PM}trք*B:>W' 9 cv>[Nm,66 ¯q>.}Wps~C9ն, nQacuh2 Rr fq~" 6]8zʐ ;Ꮋ6%YRDV %Wa6)Eݸf E?8GᩁNiVaHƮ1hksP^v752CC(I#/lWiܪ25О)A.ཌx h&ޭy|g \4bvM D7GgwX"u{𪊞\h<@:~޸4NF(C)LC6Xl~P6^)x(2DDNC#j;SX'(}w/t{onI@q wfzmzY26|JUH5]1Z.CD/0 =!^Wڏj1jД4fw-Dd9SƮY= F ]|="u6)qkGa/2Ѡ-1B"vL:ݞzp";GPPׇWyݐE1\jSUA")8#~{듧svcظ)NyE<4MpI ҥ<߅G4@.jh(m{؇’{|oι͕C\_~lr<](zg߆2𐔏:qj|;~ƺdMbb'3+Mwƻv|  Cx́L~n}^lqg*q&@H$'T zbl+(Cצgo\-\ݘOGgfjnYm_r!PR*ٯD:_RzU=oee~BNK,?b(aa?aMܰn3ѹ~yONpygzXt֡7\yc?u3 }YPq)YK( rH ObĐPj;"隞b߃V4P{?NNyW(KJ#Qi`.uL*E=~S}'/ P(U?x<CAfF 6(QtEF1ԧ9Jx;e[t!CkJ ߡAuEA(AD "$y j)YS'EG('B \.-$_< uX:D%$(|GE(|⁘_'r8IӤg4!@ʛoϑB?9!9i2) Ic~rUMޟ<>T#λc<9O{GVY0˥ :U~ R"}̇9Ew83j,CI%,S)}4?}C ~a (3iVuXfg`57HXr >P~*{P>&S&P_@H]3C"^(xy| ,4RL1 +I~lz0,_{ʀ~{< sj+\娬m[Ƶr+FU[nkjڜGsz.@#F8RhZ: Z-V'keŭ܌9ݝ! Ma$}k ) @c8&w5?K99 0́U1P/NVy#' ݽxεxOYr9viiuAkV,, v֎S]+&2~!QY*GmNvQʝ('@9Ȥ\mr`lnZ?I˽CKCK1cJ5Φ!X$<¸9ӏwv-qRT%!z9kΛ$Le5j `"|si ::t+:i,3Š .[VWk2͊u ЮimmwmM%)͙)6ػ-h@ 5s(`LP:FmD($*+%iM:`R:hCPPu fE H҅[AEBO](`t=QOBҀ]0:ձ M#@tӶP CJ(( `( T@@@QHT:Zb>ldʀ; vA*)UA!B*JA (ARZ tE ;1TH@@8m@ e}Ct5$ (&f1{w BURJTh[ R*`*@h>9 4AuEﷇ:zJ*4lI;}BD(j * aOZ#ɦoƶ;xﯟ>SδWž;Fk{-ϛ1=4 2{[p||=ttomz=R@:vҟCi@}=ۡ I @S@G2 EI((  U*e6*BP;>uu`of)*uT W݇:{ׯWל}:DPHU=ͽۡq{m=((r+<=``-h@DAMdd&L @&Ldi!y4&&M4b )" 2 A  02`U?iS x z6EMMѴ=O(zz)"B=$OO Ѫ~SC`-eNmM'+1\ :y._.d;`gCS 3ibEcuanB,ԛXAT\WtZ+!@|Ic̯|J e,XQHI = c1!}Ӿyj d -եqS7{FH}CLUmeI kRWE1fl]Cd&Qm4srU,S[9,+JhvЖDDsF[LCB 9$ Ho[;M-JA\ӌAWUΛe$4̲AP,cTٙ]pa(fL%haI{&C؆IrGphQ~X@0Aٿ}t(;槞]ΐi}c,KXy&ЅËm"d,ɺR iLPp֕ i$Y$m zr=yHP0D˅L$, q3|0s5]M#O\ CȦJbaS@C4 Rʖ[yhEM%l[il5G`*]E&ש 0)$@jTiMHRNmD $"9n(LV@큋rĘށ"Wh[12 aMS%*TR@*i)}&ChV>{yL+PG,88!"MrEcg*#[+5 ۚD4I x5h (ܖ)*heA{s%bn|(2񎡂`1,\FZNlŒdm-$̡ BʕM!S@2G'0tR!1Sl! MH(Z}Db<(z6~6M@w)4΀YJ#O.zwÐ/;sFq8j&a`)@ :戚: s;4?S.o@a%3.~2ϧ!=%h t%3OD" ~/(g\)Exfğ]&Рo=dM(UTlʳgwBV!η.K=o0DP!06Pt&˘hPxឰ>n򍪔[$Fy EʃvDJX)z &=ZaV3OaK,,RRɆXuk`% 9ݱmE j&b>NKCpBN4!J/zDJG TMrA)B2VJS X )$**6Ռhj^H<жxZuMkP#q26ruUt5MBIZ,)eZlv@$&!赶dl!bX+x) bStԤA(Whj*()4Jn2& %4mUƕDDTdࢣkT.ȓ ޏHH!`iS-Cs J2cC@IH,ĊX-Cn.6sQbs(3YRa4D&cJiS@Ϩ)=0٭$6$0(0H"],-ytʞ@a;;ru x%R54VtNJaq E;Ame(ւ@P!Lmsb @4 I aD) -ęKՊ/DPwx2#2+̲`PLZ%囲D86صQn j0 ( l];[JDnCsCGҔ Kqr` `jb~B]LEp9L=&BmW-`(6Yƍ)ێ[lv+A1#:SE""INwb[XURN*EB,Pә ż T"& bi70pSRCVf Ύ뫑"hƽXlI`FJ!TTjƈ {玶cAՑ j% bD9KdH=#ؐ$*XۓI)ib PPVd4;)IGV@Y5eV@URiRBhKjdILkC}v̊գFەҍb%ۣP,Hw-Q75:VEC%a D`v LH`7wu:tSw^y*%Q*ju1'}m݁ZAT Uȵ\VsUrJ"͞뱕"=;cTPDdns[TW.I%^9Si-fJd(PdL*]3\1Q ]kdj0F9CZPfp y<ݽ:`Yղ bF@Ve2ChM%2r0"j*X5!6;0 f*baIrԊ&6ygQbilU6Q-6*9I,X b9hTh2L6$`wsYkۯ#f  % 6+M`c@E\ÖAveTQ4MR#T\EG\R;mB2U#!֨j>MFurxB 6#r.-R- дK!l1ez\tt*7 m 1 Zm$hd&0)X 6LqX"$(\N`T:s.i.]%ݒ^;)-m1us1 &R( \5%e&9eV3ma0NnwЦLlk,Lr5f:rr2Jej e+X1 4x1);5s{vÿ˧;Mk}([sK\Қ!lSZвj)kEeK%d%YMkDZ!R2E2"BIo@eIAKc$ޞY${$sBFq!q @gLdf0V+.pW$iDh iŤ(L H\)H$L2(ʓ%F L.ÓuqdA]#/A5KPiuP9.@9Hޮ'~!ߐ:tvNG'eK 3sûSyF'BTX # -(*&./.ΤH XZi'Q4]wUZ'Y 0̧ D3&Mh6쩩 XVX;bi9 z@6d+6p)mL s0(Tfm/;aR*J( 9mhJܰr͆& a+kZeS)SG.eys\aq\X N3z&hD鉐HV bE̋演FEK$eHJ@-&oX\8Ĵ.IATfW{"s{Ѱ ΒCjۊF8lVt &^&۪ gxoFq%Q {sw\ fsb8)v;!C ,5D9p9' s5h[VX;ɓUW}!fMǹgjqL7(vko.ɼ7Y5 "q\qR_.{޺ `KT3rk܈Z7.2/zsfHdf3Qe$ {)*kHwW+De_D3pK7)XYT R\)r4+=_>!dS^BaJ9rn@d嶹[EAM99u,H-RtJ^[Љ,E c*1C;pxr MYl@1LRтhvi$*iP}95aǰgE8x"SR8!`n C%y˶.tI: wyηx.v.ee+  XZ7dK0#n.nk W7N=BNuBxJ0n#bHzLhq; :!ddy@mѺ m&r@tp7Д>]SLЛc&%ÃL"gH;Jn޲X򖭣g淒s58 fyMs3#!2$[Ͻ`m^8$XZijuy%!Г/UG(|C<6m`G(I?$>%x|Pl}S@ݓ] )H $fĨa49ln1MrC%I# dc4k oo`nB=1jl?t}.~{d)v2~֥ > ×pFL!BJ]NҚ)(I@O99IPCdg 6G,*GMn˛IX4j[ B0$eD:l"k.0DP¹ZYi-j̨ %$>-6#%B Ȫ1EsͯfƼwZ9c)iPRN%qkB#hQP=O@Q oa!&PFY(TLjI ֚v3jBC{ф4H "TX^no$Z]aOtޘ4HdbHVP Otw``Wfnd(]o,S /{FN`/+) ve۰=y0}0M)ׯWkdбփ=dAq fm'^DWK d`)  m+\S*ZQ6KBm&(mo)4$6c]0јJZ8˙3eJHVFāj#08R@9Ad j6@$lbAEʩ]I+ 5 պV!T #HT1Xz-& a*]kVoeȬm4&S|P L1.UP@  nBb RV*v ի%Y t2\h )55"d̎3=R9\ ./%1sD Jb)wAHD &.M)B"*tFdUm.RIRIPUj%YݢPaV uȓgIǘ0$\AF MنSAyH*HL0%ǒ2䘌1@f[n4P\m`ґJr U¦B18M ZTqʸ[)-*Dʄl $Bv rrr)6{x\ZYX"Kː&כ&-r5t$mNvJƒKrû v,A;wy,L "2"֚iqjK K\j]2X5+Q $aDU\*$ +k;̈́,0--E-+q1m\2IY a U-9 ôkE[|SNϧW~{ Y}WNhMb}PWLh 6wAVOϚ̐T *yjLo4`JII-ܖAE٬`{m!4cdg sZI!'Ii9XHst,퓑ѩiTl+IɽG!*StךmN Ph,ߔ^H&y6sG7wXPM{4s(ty 8V(Z ֑Ql@'HIZl.D=h̶#MD'Q@ZS^C[Pij"h|ѷk7 :Rm$̼ `zŒ}N눂AbR~0jaѝǬ޷V,UcQ'M۠UY &=72B}C@YHC5w6N3 wTm \rZS7Bt FEmt&lp~v@ΧI Nz hWp?vqg lt> b5"B2,B6EuIa|Ssj6612e,MLݲ9\g7P:kWLؒ~N|[A ݄d- tVA>&8lodN~Pb%4 ʘs]LyaEIDs4'&hZDW 0&ew1 N'ak0;$V;- n^)`IS()T(rʱ Hl͡܀q" vDZ^ͻ4^.l7YܶOHj]")aЗN>w2mF.--pIrk|s5;r=6-4$3Gז2 Nn^Gm 7o鞺;HxjfArʚWSEy ɶFNy 2[Fa!@L95#QoS/C,8Fd\NX *l-kʱ!e* ۻwbTmO.`3d',@5/ςۮMJ)wAÁDLRCZfk塖M3r]`B߸CWBSW9w7m'D%am8s3yE@|"s9KrSD.Leꙍ["fU)^]Ow9 d<50}O[AwEY9b{7%edP>nQ uodMk|`՛s&Su~r4E XE2`pN kESY22;!.RJm#YYV68X :(G%EGHGc#R,RH *,]3ɶ~akSOms|He)]3Xm#w^b<f]QܨkMR{6~dJusaB"!!>!99Nyn6@{Px> d@{BҢPp6!vA]Ł)\e7a? YE5JvJjxQ_̘!%*y|gI̟d՟fMwMK^}Y]_&jRB P gN%53:ocq.Z ̃dŝ@e%u2dOZ̓Ǘ5f0"jL1&#.t[% m vhLy3xwTL`#ڂ#dfZ9 Ia($Li54mFX-[#2!M&"xdt)6γtjk^l}]{阦; p]uh7aV6@m]Y@4X2 "_^f $fRGt5exzަ񙴉%fVF^ 7}Ds$N;t4.eۘm1m;,(QX,PI4uKsR)6=Jem#==8<֫juXhH׺M "&_] 5(dE2Y>!Ą֬&jʦd޻{}^6dHvt MC,(QD5 3R dC) )Y5q1]-aiB(Μs;f$v\- z: 9[U vܰݤӨu]E/Pp/s~9lCDM^[5,%sUe +g7d#.ZrC nW]7d○88 Mtx˜fgIfjMxfXVxl Ң5|C M1,YYvaH 6(Rlfc[ۇviPjQ1(2ۙrm(J[ &7Nl:=&cfvxŦal3y" <)BH=!E (LE&Q&`M(lKiPıɕclʔ_-ٵKO~C6fcKJ/nuP7`l oIfutuO3 14ޥ8{'۳x@RgM;+ }8 Mlf0%uS5i) qr"8flXa411 eABkE+b}xqs4t㾾~!mf!~;9]7~eWVVKhFjHVJQ*Y tåQ{7p zk!,G Ԏ{zixγZ54f[ х7f !3>2gN:h~i3 91Mo7tގ=f~%κޮI|ö0`T.M0U+`- XV#˔F&޽vCxd2/ C/I֮j)@*TX&jM#PHCRr]HN0e;𱦙ThATv񖦰V%궳(l\6פ-\ +GwByjT;ĆbzoG綮Dcf2knI ![N9*B8QEԓZ.洣)3.#[mU;ɥy΀^TٰVbΦҠTgoF,LgYt7fZso^N ڥT:- q nt|y4/[SCu%&51"Yd6jӚn=j[KY!8fо/i>h C,uA`ŒUxD YX@lLթ2e]m$l X-26g:f*!rAW2NR d'}4% CDbIvQx {S|J[03<}oT&M.֗^1joXvŃ:AwJmٽx[::f}%K-ن3@΋aUݠLc9{bNY!۷8{H&ݬ@||L iO-ѰJttl<=wyίI둤7Jy ^XԱ#W=t.6A[rhTy=ïv \D]N2zE4*y{`^d{|uמRAZ L Вu@CE c*Wǽۆg_dLaâj)y@7fH'l̰^46MCVOTF"XQ>]Vlje.{o%U'JF+0nD\ bwwMۍ1~MSFZLrQ,> OB{lqe$8"SmL?ۨojpI19v2)t9OIrButQw>fI4gH!:L@x$*AO ;@c!'$<I |MgY1Fqcb僝`hC݁醠={,6O oբyu7'Luegv8%vw(M^t;eЏ@ pww-ckIje/N$29\\Ĩa 7eId@R,$;Q<-l 񁱉_'~A:`" &++ ߗєRp{\4z:BM 8:?HYv0! 3Y됣<%vsO:Gt38ɖkqII}iՒ/%(h%HS*:'hL0d JvfHgUz2(=ua((fvDc=wk'd^R}wd8h.# lH!b. !Ow|3!&ؚtβ՞ _6z֩z"Φ4*0ިܐ)mT#2WIۼ|Xx{j|Cz}aOI6o݅y}d Af00AD6 c5ry9mbPpBuC IHv7`VtX+4>Vc'qI4d3Մ" ~>{ԒIbRQjq(%! x Է{H׳LHZ æb C*wMDEN)UMbX, tz@53d& (F13M~{&!5I'TM2e:gzt`zn&!}Xil% ad7;lĞ0taЁѩIТ,keNHo6&&='oOA 5PNIoL mXZ'tt|!,1;BT|'VTMi,QM/MΤ#dr6^R󺊌W.5% Ҋe(Z{F5b;X2!I t0{dW*r~PһIدbB1 2AE$C 1ZNbg1J@uq(dKOtj;\U%FH3)]Mj-$N;)5@wCePX !{C|BhVibȞ]* Lu4[)֬:a+ PY:a49xC {dx文O='תmzݰEVIؘ*OZT;'hv9a.'L @ٜÁ3֦VHV)s(Oel$4>0ݳĞ uT4~ cNÉ\abD~9фɴ;M!l,Ⱦ 7aZ Y@CB{a="Nmδ 1$Lu F,G xVލٖ4HrE'!uBCH]dSIS-C{7tqCF='( ZzF̽׿>:<'i$9zHtMigzwRBP0 &(zJC l=!6ԇE߬4(_/CHf%&(*$:aHT0rE!&wVi'9dYD4zθ'&8 jso^P䏍uS!Η+Cى{A|I<Œ$B>Rxln6=$ t2mN03zh dFʓ֬M:zIH[Vx[&5 8O)> ER*ŀJ8NCY4n4e鑲#>jN!RBh~7bAm-C ؒ{!l+N$@5Tb)='N)|ke(tߏ3C?k E&`%v/(^pOOX z;3uԓ=@aI M1UNbC3\(6ܬVJ>!:D?d%Fe3YϙVn=oێ)Yi5.T]K<2yyXCo{go!= xHÖվCq:@|7=ރ2|R}c7xOHz~D6!JhGd.`G2y\Or] o[CkNWH_Eܷ>jx:!Z5huN?[:<}{$:Obi+B)81+ OHm:7, $/06eܟ^kMH) *#$Ci8Pr_@*vc3CxQX}@1Yt5z5x 13MLa:@5t=rbiP6@=I(d6U˜CY"2߽h}Q3Nʰ$L8ΒOϭ{oVud6gfK+4kmwXJ80R."r*acY (־{}vꞃ}ʧ2:a^mdPCI%Ia:Nh{>_ BaԗxoN3l_ ^Cd?D7 `Ւi"@:I8K&ĕddXx·a YHm!YD}x 2T_О!2*>'hJB5} .s (mv߼YY=iؒvzHy@+d,=r؅E ^rixJ{Oc|TOElE'+4垒L`|&`?TRlDwK 5"h6GI Ϧd|Ni ;Mj|2 Hm?\}dvDzg۝Y!@;BR{Z 'fVNa-hTوY< _(0F} \$'% jTm&q3zyfoYfjOl;O+|gl3W!EtEnoNظϴ(T L1W eaLNOhOV^toDI?}"R(x{!:Z1n0zfRm1l !XY 3\rǥ&yW7O0<] :OltMxY޻&dLեv%M}d4D3:ءyGX&'L<փ!\E8˗J!`!؋ BxCyIxC < ;\i&ά~:1'&Źl6 银0!8u;|f:01PME!PYs[ΗRzS uĘ &Շn *?2b=;WyY$Uى*I4jʐ5$!T:.v$1Vm gO,>֑VM3CH.޽VL>0~}wI<ĊT=8"d׈{tНvoim6J2BBtׄF3æ8 hfN)8!2b}f]}>aCYH5: UF^c_M]3:(bLG>iĆd 6iT]zu;Q0C!SM0*v0JgL<;ɖg,S3'g@GT ꇧq VdbL!){NӴHja1lK3;Cxi R<̄ dkO.QիTP>Xiړlc2 &> alS$ǶC9ow뻧(q5ix톓Pk!xcD"i #t8BY04(bJͳ{%'$raE5טCv6Gg7 w4p~&!aRc:BcP۾:`cYMM0CMPTZ[,hH~38jӫdNm|O!IJ3[f u̕{T=fB(IK) c!18L z>v 冸wE݇t}!N|lgyoHi7:ꆄ u:h9N $lHWxP7wwiq0rğgvԘA%0t#g6t;T9˂M[ O)[!bUmT9YӸv{aֳ>4X{I9VY6MSNS> hd!a]3̤KSM]`u;z-OW'ipëݲXb#zI>h-Y [&ݥL/%'*Y07PJX8Fm%gzxMvFuF?~zoޯӈhW-a=jbm|I _3)`˼;^dg;I]`, \zRm؇ne^id,43M>uHzfwT֌gA^}6ͭՆ(3:OZd;:o5vٓ,5&Sۧhj%d5tt*&lO:˖@@smوi6~!tR>^biCVCWd+4wiKր8g֪Q?]S9X/Ei4 ktΝS6ɺm&nbOLɓxlQɼxlL*_n39_25fOݖ\0KJ5Y&09Xz==&myrzI&6^N%/Ο5O7fi5N3uˇNsroU m<\sLhY5@Ju1Aۼa?/m8s9I 6ÖtCROjxu֙9B&,2#D7hYSmnwn2*x|;՞ ey|@ꐚN rfZM܌F<Y<Ⱦ&ﻸl7#3T G\P; T~A@u" ?:<^--$4=S>/]~nfiա4]z_<&Vh8\ӏ.uy^&%N&w! h@*%"H 4@(R"P" !BB*((*P*=SxMl*T0Ҳ-jd$ nm]Po "*REP@U 4 (liL"7#c+(9 CZ-()BR P J -RK@ P@*% (P QPQ)H@+Wc[kOVl4u_޸B?HF Mu> z:twC!!=X|u(-vfH~<Byʝ+r8!(_w7CB5MMiSkiRI-X7S<Łbm|'! >AWƨA$IF\[s]DĦӖP^ZS}@R̨%|v?"/l'kT (e?q8lĉdPm!- MSiJ|Ϧg+sHH]yf2&? $t. S~" H"BRp1EMl,밂-trHIaY ͑e 1z? D]X1wYwfk'qA X`|[RYuݛ/.r$uT>noW#.~4SYQKO]*Qlę^x`9tl9N3ݘz#G՜B D%j 9m@d*1J_Q CFɁБ͈dpG߷_M< i,o3R ߧEGFYRTeBl/#Y4dB$$]0ZkQeoA|HA`)D2g?Nְ-ݶYݗ@'> (`2\+?p"o@1w"L)ž%k@lW310s1%fʌ"PB?Vg]w5"fTAr KJ%$…tMV;jڑÇpU-g7H#Z %lm6&#->O0M__/L{|I/{,UL#/ p7~rkho,,4eC zƀ\tKJXܤ"! 4/sάkYdOHZLz5]]\hߌ(Jq8DRy$[qb܈S6k~@$Q 9har>jIےսAOϖ|DwjgxCݵ޹UZK9qכ^~7%6.O޼6 qi&Xw;eS𥔆_ ?WV߿;> Keqe(cMOƵ,믆M8?*VN杞BsqhJ#6iN,Hޤ_Oqj-GuƔf)7*}Ɲ6xYns 7 {7O!Mii;#v$ia]fRCt= EZzd{^sxnÂQ0#KRl ȕsb̹޵½'AKTE/w)#o:wB_p0dM^.D;ܽS*Vk($HGa`Wo{T&HZ>R=Ԫ]#ǏaEŜm>*$AY=Kf4~4_\3ʑ#涂 H2dK*%@Kx9НY&!WK| X?gix)8'WO3H#AVT%NHIBL](@@7H9蚟f|-^zj:GS`_k]?Qop^j/ƬJ7x\hRai~Q?6$HT8e"ySopm}؆w [<8* K @f bmz%sQ0 Z`C ,s<ۭ^?Jch Q-%;&t")Hف\NP=^IJug@myO_00K]U)Uo>c>wSt-ެ"u H}IMc2bRe<}_4qUiF@,;U$iBe7S'lr^9G,U6u>۾:Nq%Œzpz9^#?W Q =oի n6mo|DCMM^Y0Ҍ,5jD\xZNn]>;I Fr lG}& JMɴN72޹ e]hd T*@ׯa2?ܷ/z\[21^$!D # KvpvBRv f˃:F20bYȅ2ۮڿ0O`F84){n:ZnD/>I{SaA;D| faٿ%ۓ;޷WcC" , .K/|=i(-0>Kn?f.[{iHצ HB/^*p'Y|d^{¹a"ɓ6@͔/gklG4ױG@HI#xwud,U~9I"ʧB7:8 xFAZ-(!~͹2rTҫQG}M}Tj܀=f`{Ɇ|{H#`Ԉ:`[ak8vDYDH'V}'zf(7"A BY<(dH#((J?Aqʅ?Ϯtg$ F)4d %"!coƍSm2֘6@~8 nԁḛ &߾~WF~8+3;lՇ*ۣB~.X^),og腰$ V2^7OJh, a0$j7 u?.$S #gFց,4(bGd& ;A' "MEI,;ui|/SQD[iM6khFL@݈#+J#=g"բ~B(G C1.$6oF#dpKrG߯VNj.'mR[#ԛӕq^\zmO" ⓹nlI ,$ n8iU3y)ͭH>ո)TKLwPp 58s3AfNV  eYuUi ?D2޵0J, >5Ny4Y bspc\InCndfpHL788!$_}GCO Ûb @#l'22K#O 2GB<]&{׼<9DI0 ǤMP ~>Lnt!h#>.4HśG?@1]$&C=ڀM 'Qy /=ƕx4di}m7S#!b&Exqa\-mhAxݓu 7aHk`5쐹 ժId݊ $yK55Ne=,v3.pfS<ZcNBkvT%6Ҿ^tu bҜmw(pL;8hs u}Wԁ\תQNAeAD\..W yf1eoD~Kq4c90yjl*ۮ)yxz=9_^ }"ejג`[UWP6*pr 猳Av]ȜׯG:t>g3u翇]M4 _8nRT NѪw)#iޟT``Xp@Cq.'ݦVZ꾶]*'zӁ -J÷1AyVv$m|e !a 9`\$WsLf黙,IιFdĚ&fC|P(iOR_6@\}R*0F>I g^ck &CB2?pE?j/8]`{Sr$xh%Y8QY%WJȦ AfWԒ78 mƗj֕r]<9 2]g+\=p$"Lq h"]M}@HV-W[rB;+j&3% nPO1ޗ˯~{]AzߓCxB_ QkwlƧz>dukqjIݍRdA089K^wráKv:yi(v.,rr -3lY8l9+qc9%>%EĔܘGy >htC/7k74ڦb\h <2&85_dPqn'Ѩb $}9<ev\l4V&܏G#4LE`(N~~GaI}W{W-J|SM1@㯻J]d6ҠZ#@K@|2JOܤmA%}9/`֞T .DjaRj^1 =%y QR<ۓUGݝ4@4[ALV"jZ1>D~(d aX_6&%}9r2P2.Jɗ%-`˸㺒2% HR$ @vuZH!Hv>YOkں;WFi'38. GK،ЗM0}&~waԙm!Ҩ!1a>N_#&\gչ}nqKePR1ruS>E Fuy%n@ڐP%֐mpc>F~PXDF$MuӰQ)fcaFQ&BvdZɎ7ͺx?,l>#|UqG e/Sծ8q^|ꆯ@T.Ug?WIMW)XvHHȻ7ʥ@ںLX0:!j,8:uy(lx JU/<M>/HX|֢ =zgGbUU; 1фN҆k'wQDǤHMeuDŽj)%0d4ס$⮇[vH۳%[lQW?RuNe0MMOl=tIoӢާalj, rHޢږ["#ް;?uPJ+̙i&i(\/:TȀr]it[/mV<*+D6qR 9Vz蹴󭇖LrU1RI:܁9ԗ}2@ntXq߁SIrGq-\(/.ձӟ9+]9r^H۲}~[蟻k171䊚ПԈ-ጻT |I-lX׆ʔҡӄ/?:3tE17cyage'4%*gFfG `<݌{GsCl2!qxp1s,R# GN8mJEikĔ!B9 @&[ZDIcX ]9"̃_1FLRvKyˋ쨸uWzEKӧC'}g'Mw FB}1Lb^T<>f]qG66TKr(q\.ik_g9o~i{}Χ>BB/G&Q9v{ﹳ?[+c'H,# D[d(d;dfy0?h,vN.%U{kXH$ݯ!@- )oXO^MlY;]l5HD^yNY6 a0]IA<\d.;_R\-ԢLrLI,ޓ * :=w[̛\{h&90 omJByYL#f9{!U sNOW?.wV3K*Y^nw#{_|̏!Q]b 7_i; ~ݿ~$b8߭ ӧѭLHH  vTj?Bi⎓dRoOvŇCOjGUMƧ)@ PZ_U8gA(f_؊_ QfcA$HwGͯ%:?'kM/`m/P'Νe}JH3PD@I C /͕koUVJ^/ ?F\ZT %)VIta"h.ygdZ1dRy)xjL*M[ʾCJA6/Hn"ZZ^XGãV'u(_` : ?!o;s-v^,r,MX /Ltl5_dkLStUʓv/~ VuA'NygKRwnf@M8d| M5 r!^; &陛ʐ#6~z7:յqA S əĿwB8aQY5ݻKL@yob|op%Po2Z@!,W3xS&R,hHRȗgǍ,TRDV%[zwnNR]BLCp#Ԑ/8tr*2Mx'$]n^2NRNnyr6\Еr ϴCO "O%5P6\jIp_;c∖+h:]n)u v .U>vU+E"G"Ԏ[;e#O0*;71ow -k*Qh}|sj𾻶KӿT˔GMe"EE!E|I6c՜>gȀ]S{J_q+ꫤZ/fb۝7h %}[;[rrʎ\ 2N@L(|[Ϻߣ B"f3i͈gKAA 0*ԂK-aRY1~oބ4D,ƑbJlXZR-h=!T#΂ُ6U˱8E`&`!t(`@Xmە 1 jB@:HH7kc9i kr^9}?n?}xtha#T+D$@"qA}T'*^h-4Nxib*H:HHtJߎBhgx8 y{$eյ&ewk"I,q8s/m iԢ?ʑ SZ+nE0S/a`۳5l] "o@QJ7\XA|+jnb-㴙a*F\>;=z)\kKڬ[Z Sa4'&Q~HOB2]:z9$0H]P.6P:ҹ&K_!iԠǙ jRP+}";;Ÿ38k"h%")dڮ ٵY9UOmP=ztx>7}U:v6Mm}~;v?ҍfjH4  U,?vn 117(td߾a|#161Bb9!$fZd5qB 0F1y2[0tk·[t8J!nd$EyQ1d3 jNF^>T,L`D2]m>f5q*"~HȔ=׻:$6Rz(h&F l'G9gm[=0n2nnmy.bAW ⣻ 1I7j: Z5 |\݄.e$Hr)3) V$iڗV|GR:خܖqݒG>rԀfP&J#m?hb0?.'Zb8 $!hh)SRG\AZHzOHn"1/0y>M!45ZUE:5J($~&u$AIOc.jIя}jcG NMe`8x%FwG˒I2Q~xZ?t?+vQd"@ )UNI$V$":zy~F`}PfN.$ri=Ǎw 8!AW,rL&g9ޜފEu"~[B72Tc#Gf@8;ݼjX.),$Fg8ѩHyV3&0)!Pz8~ H!ř2N#itvxSS8'[-J@~P/xߵ&7.oLW=m,DA>Dz[dUq墥@XI6rmm\ т3 c{y_jE۸ư";&R8OS]}* 5_RT.-HH˱t(ɵ^Sz}jɃ,y7\؄O1A9x/>P` [ b+ EFXwThxf}_wct d TKOj1i ;=]tvėb8e Kbg*ĶGXߧ^]mj,+<ǎ9 H% x) |I <A+ a_AxvP,XX*Lr[%Vi 2A!"P=GB}he3 H#AWr~Y2nHtӇ4](ٺ8êlh}..H$ Ϣ٧IoUyoO\f"=VG!`vr s2.q'$a%B>aA}.1vy\#Lek,gMxX+ٮ&h Qܖ33 ]7rՀeY"D5Jeqm#]?{ 3'[!lZJV\.gs-00pci&V,O5M{4%p&!5qUSF (1L)D5BE6ЪfrVObRe-8kU͌Дr M'3IjVl5oX! Iq8g ^~R(o% $NhS0I gU(ǷL:BPMƻ˺;ldIub ALFXGpOv[yq zC6wlچW4vfn;v: hvumrMnEm?!+{4$ 2!bǗKmGݼwdƲѷ9SLp$X,V0v!bçvO3?kvtWyY#6VBˆOi.y|y+SjFAbr?jIg РM=AƼ7.ru^>hT[Gmix#[ǿ--Sh"Y6*fNrHr ϧtziXכr3')Xk60"sG݃EߴbL H\lh~Ɉl#̶g")e )Ud}oK<JIY16I1˜A C7~c ZD 0A#]( 8SE!nTGM ğ1H#GOc=h."?N}7js #JCq@CH햚H"#:% aޯ./Q-Dzv~=k9|^$c;g$ 0f}G<.\eVzf84[Ԝϻp:LJ9\5iqTv&3Q VD9Bh|>;P}6a a=~F:x|*ev.W/yx雋 \sy<.cJ-?KO;x>txnf._g qӒ '

{=jd dNI-Z'#'І)yq9 \2r ՈĐC*  DPS/tl b-@ &bPtV8<2:WfLd9y_V}\/qyts4B@47ҩ(W-PaIƱ*͚xNG^Uw558 p "a6do;ɘW5ְkOݠd{&Pl>1eBSw+kw?:/^K8yrn7dQ"{q0W):'/wQ=c/K"rj%~_ICIQ?"o {6_,/iB}FdGq^t/W|G=yS% 5#yCˤ|mRF|<wB @^Oo ҖQ1-D}p2H;T~0 7[8VA):ĢNL*6Ɍ6棺Ө _RZUl@ٳR܃2#X|M>} J.Q(HSQq2^&ਔ]eJ!|:>,P43pWQzepȖ^pH 45cdW+>Nf,͛"|'ST;yN/gV,AYC3.efElAc/ >nXK-lFfc $ )Hff]"A'2=|胍kp[Y6I+JzUD ӗO#$%Y8x׿ǟmƩtR_S&S*u&aQ(*AmGy4!<'ɜ&U %`FQ !+,RRɌRWRZ}i{v(bM) -Vxl!2og_W:eKNAeՐ:TRXtdv*7eg(tZF }z2vPǜdn=[VNNݍfk:^rF{qVNi+,4@ݑkF^Jv`b/*l|e*W;&1洯{xZT/'#D155p^܉#Bv~^o1BPv:;̗JU8]kU܄eۘ𼞷^oΉU4A ѦsBe{CTP>Z0I?fS,l>ZK{2T@6K[:宛u2fJ=fF|4Jm-e4fpb| U D 30[Vox &_Uw^^ qvQeI܋,pw-96no@;%I[L,pqVjaNtpl],$G/wFxMә0ֻy:C^_̹όGK Z3 _b<܊mz^;5o]/;w>=ckRޒ;rDX-;a|7@ZOR~sqs ךt4l86I 븳JʟrNԺm]z?kou|~h*[Fbw]ʫcz-)͹L⩜ sFPr]#k`6ikW2RڂV?ss03KS|֦]:VFU.|L2morqIIz~]3^]z_~?CW~>dr߄%|p3fl'֭|A{'LRj5&^conmeK7u^"u/m=Z2$~M_{whTg:{kP~~W;0@xX gqs 0օK>RKL:W~7!L֋kdu̓Zb#(xFM.LQཤK.HJ\^ܯep-skfe`&}}{=$>x\,@*L`+J(5OE}uƗ"E9DH$+30r:kczR4iO%f/?ry~,v?9gX 6eY0:im|w/<͗(lnWv{ u(',n}!9P1emR3#Rj_DyIg4HvD}pcA}|6ж;Zy Fz .8 Yƒ#GIz&BA`wJ~]rLMP™Bzt 9B[iA-OKXnP_W~s%(%;*P/: ]N^p.A"L>*UvoN.٨$&llSiCnEs9+ӌKm~ħs E 6Wg6य़EFgWb wvaSW[vLc¢@BUfK\z}Bz?bZ2} f, ;Id,;d291t`![<\RB̾5 I$қw_Z} V>mw3_v<AۙM[n^+a]K͏B28`7'm*Wv=$~5kZ÷b{CM9ǧGއQFYzZ)ӨdrSWC{y+>c_O=$. ye/+6@;xU,GqCo“ݤfh̟7'꒰!_䖥p*UQ2ӋB k\frSlPP0d9LA44:0Dlŏ;1g^ ȟ䘝< 26d`b oH<[ 1WxsB'kȘ&zy40e$qUb)š3@ ;h|#"݄(ba$#8ATwʩHH`|&D򳹮#9R)gT2!݃J+/zNO84ڣcU/3xos`&G]Qlkn< ı \\u]OZ7o4Wߵ_]{9ag̤,BaRɧfMSJ1]Ai$ gl@YnZbfйeim>#{Y а@ @!S ROWov_U~s66sJr)f`.RQ5Ѿs*W, (vULmPVz_!\ է<˴ηEM,%o>.7 {ɕ_RQ=[bxry.L[6CiqeqD) nhZvs\{#_]ZKl"Pцv{ܽgN)Mk6< Jr,jLJT_eE=z5nA `!nw #F͓;JGġy >T8~fě\נi^轷{ 3o'5Ur@@1@Y"ȇAQ}* $0@s $L|zKv W]G ~g{KG?;Ղ E?\CYI蕠_]/OPn- ~pXNCGA}7f)ks]y'YJBBpHJ$ ^09Sw>/l7{H6^DGFu7' yP~a 0KT#rvGV[Or^G:v?GjwB/6&d^4y~ / }-:GKkkݕkkqxX.hV~'*F^2{f.f}Oc '}}DH@"".1 ޷ȯ| *=(edK8 GEEg8:tI|yjxu! R~DռݷqX |ZvamhHk{rΗamcX/t_qN(蛔iZKTqO>fscx>rlq UYnVUDLP,IZIP)TΜzf NFl!8CEH M@?[ME !3@#kۃdߺ"!pɘRjrMyпB&o#m]=:OV;*ЩG.߿<-7 rF5n4A bc&`1E}m d%,IZ&*>Ci{.1v=["An*>ͩQb/<5+jєCwHG cTeIC`2F3H&ʌ@B{I ˆHxꐚ:d7YUY!,JҊ1+% o;(L#dA/}Go»gP5:CH|龡F(@ [2 `z 1eomἬPčMCQ,3M4e "iD,Irkv`AyHuH_8B?7'b@6rk}T</4"RG 0$u$*ᐷdb\$|Rp,ʋs~!/sc^458#|}t{{Xd|8Q{V(p|Mh2צř63e!bє}5197ۧ.fx>>\~~f,5;נvQ -wc)[`fd)ɱp^Է\:.Ҍ_@[L)*fȞAlC}E(Gxd.>poBYnҍ =@[?~>29H*L"M/ ̌ ya 9yNU0@MSlj{]JS܉\&H_.8p\szyݾ "$SiCihm[83Ǚۚ `rļ>ˍb~{ UtȫSJ]:r[oO>IԹ<0fx 9k!)AMw{i[woߊL{]1FMȂmS\bdkHmUۨiDjvilUuPKr\.F?1q2'i+]^7t(M~9"5/89oDD32hv'% &A>IhơUMx$P%pڞq%iyăJxXr+$h9BjgXJqh6RS0IE}H a$Da $ dϡJԅ$լ=u!QynF]I«|\ 'NME8ۢ@E.wH`\SR{(xz,m=#-X7"1 0 T !C=}J2rmyva=RQ2bl(0Fq3pU_M:PtF-$kGl $ݟتXpxLZL7 f&K E|YS^U(b= Oy]($ͰL9ϥ:Y OxdK+ܞq6v{EG|qAټ$ qH{{ua$JY( ]<[5;<-&R AS zKASY4uQmef,婅/_/C,ng5+; *nlg|u6T ~>bH{{}c5RH3~ng)5P>7 \Kq@həď=ťI*0pMp<ܻ! TMS H/iw\0HK2$!aTI7c{;B avHY:@;8!h/4 kTĻ]|'[ց8-T"Jc 'bNW0O]hqzPw a ,nOhvjg wNē{mc̡.|7>lqYeF> (MF,"ѯS%\L*P>\X&TXMrVdJ ʵf*UIS՟֟Z>$;CapZrDKjR>DVS0\J9Y[shLv:@Ȁ2 噶a+{>[XCǐ{^m8Jh5$.J{K>Z3rQkGk ijw0YiűR\˸nd )>cud6j⦻:3J TJQa׬ 4xtWuo cA# 7QPph[pg-d7*Q.Y{ U TiA`8+o|w"Eg[imUw&XmpRdS0gew4|6 1' A Za$!IAS@yאj)bI)䤈JCD\+mM@ECGU<ыN6pxn+6d".I wA9 U]ϘBkF`i@Ji\ZHJuH եSO-j@pb( $K:[[BЍ8mlV^vU 02~v!!jDgrzODc9jNf4ϒMZw"Ҡ1({d9\ 60N; CdTEvJ.%H|Sf7[`^~@Ev%k8G< C,cΘګ_qt_z,,FY^Xj|O!mɯ}g2FC|m8Q  lqPt,Lru~Jشߏ9_}&luhWeHڔXזI 1#<TmK|DyowέgOĔ]y6JAn3n*|2cgW=iv~PY5pe۵σpͳՄ冰2&".WO̦o ,y'DB2K=f<$$ӑ(/#Y (8z ]ЉX!,, Hbg1&}e|P[Vc }FLmfdI"X$e9aH;fԫ{L"㖣"6Nlt7Mc?&#d;ǶCb4ʷwDo43$;eɺ谒rΎd 3$tOMunn`0y2o0/dCsxMRTf hA$ӳ{Po(uK*D))H-@t#l':ñRKuykJ(?7rOָf 6 *ٕn)a BgAPcBZcte4*/(T6eP}F,Fļ6y~K%ȉLǗX S}99 r08!=8 59pؒQ(%%oְ@wT#⧌jw4,.ݮGY&n #]!LċC 4(M P Zy2͛nͼq٣F]Qi*zXe)8$4YbyAAP#.o^F{r([?xN^=i ѓd<6/B,N y tTCKj7{Qs{|J!A!Ju4Rmm(lOk;#vfR7)F4D E4e{DLU9C=jcNmqd"e;.#;k9oFwںNdۓ1Ԏu]8?zWuzl< 9ұXѩvϡM/;+7'CWxqO|]z_;d~#)y߰fg߁=?_p|ӽg;ػ-ҍ;Ȼ5j]V.`+<ﵾ:f,L#D% ?̚_9gneҞ9SI=X_!O`R\(Xz)U h@!+OO;I"Qxq";%&K$-EjcX'! |0NM>\|IX0D9fm Q]Z9Í+ A"g/umw"J荌/.{x% '382o:F_~m $.$E2[wLyz2Z!x"o$ ]"t zj/;qW-ih~NUW|'PV((ܑr{쥨;%Vnk \5M5&ŁD_?-V+BR؝&~mnE5Z[Xh3\%d4J,ro90.oFѶ3kذOlĢ~̫LrFfRr 4#j=eF;oU"'\&oa\ yx>ٻtp*No^^$SIt['=L 1GH7iޖ"s;ޟO~"~fCEiECfs4 ,Fuy (^vhqe2_Sʑlmইv49_4B{3_XW gѝgxsx4ܯyE^˥rNW{Xy |@"! idEۏ5Odj3e-6%f5JKĺk~X{Ff v7j_U;y<ݧU#^+QV >t'3^9\q{n[4f KCvmqg_j/[r8oxL{vY}Yytp9CίZ;ݱ"y6?䵍꧙#ͬFgٱi;dz @B'ИGoq(~!CLCD-<OܕpȟN\1v(%Eʩ*bkϺd$#FRcN& nClDrwVR"go~#HVPE\ 9݉ur#k:B+R<SCfGds"3@RӠj3!:b_a 6(bk9$L4CáIʩR¯{|<'NP8 :3M9UrZ*Tī 5h#ڄ>9`aeiBL% eK/qb*$Ė?F6dlˋ?+gKRy5(i[ڸfύRyYrU6UMo%?4 &m|cc~o|,eْn<]?w'gTP*u v.FO;7Rx0SĽAK$dF4p\8E5]i4tk쬝h4! _oL3k:ĒNJxH ]TBAh$a2=jiXW$@9~d0-W`8(44 Hx>@VV:A8..{;}|L{w?:;wz{sBۑ)IOƐ׈S7Y'܆}W v{V9K ^u_s00 Y9+m^IPNjJ!yN(?Di~<*.Zբ34<T:7=^ eA;R1 @ XH$hfj6:+Kd_m!Xi;#PIsbS޹G /b? φJײ1pC\rWS8zq3iJqc[`Ty9Gp8av$'- -J @:&ѠH> 3k?f*Ar:,WUaɿB6KQV)eS+wېʱ#ޮ _ r|ubڟMzLT BH@ mX> noَ6.Ç\Z^PuiQd@Cvk3^cr6?ʔn.>@7gwzmε~7KZї/a{R~EC^p8oo^xcH!1k`$NTP'i2/dHEYthFp1h]{K}ǟ;kï\wrG9\W/n/y%5`]ն?Cw_}~֎kF=R%rUEw#9왐"-/j.{EY1 ; bggOZ"r gqn)u9M[]iCqy~:q3l+U!vҗjXѻt%jbCآM59`,Z-;w+U#4v $_ƛ9t. ո8q'$x̹5BG8С*z ˞!5_TamYr=ˮ"ʼnvRh>'lШtyj%z|{! ɝVo pL81'W:NM帉^YXPׅXYKm2)שxD%U#@yԞ.ґv"&B@ "1ӴJHq QEaEXG$wy> 034ʃ,L#$Xy~ĽHȲ \}\hcz=t"{ X.̓6 ^a .%5.p޶s2g_5þC;ozr/jꎦgTr-16ő)P< Nj9ڟ2;a p85{8|ZŸ7+qv7FYcUgj= wOnx“cjTe}_yUVMJ{~N[{ʎ^cm 2~Nw>& nAn!̙=NLnh~$zLġ+nO-ce_<Ԡ@F bV o- 8w B w~/gxCPC|r5I,I4<@-(P4 u<>.I;n^T}M A\p Áb:@;:?;Isu悸~-u3L/>x(rHI=CC+EUL7J?}% f*@( $  w|=$aqg^G!--}ϕ+lGU*IsEgfH"Zn㑇b^BT*9O"fϵdVFKyPNBgqsrJʗZp&AI V#n?s)ld[;]݃3Ӕ$8%ܬy,tF$J&ahߵR!tiThethO Z~y]>bttaVt{z+dz¼5M[CB 8O(9Q-Jgi9Q23oqM!O:`;5]HzJE`#gQœ402-e, ow,̡n:MKԟi܉I/tbv3tLv3pCͲdi}y/6׿lZ qdy [IV2G( ;.e|<ȶRK4NaEEjV(W]b ٸ 3xs}Kb,Ic(QEF2Ȍ1$n)Ƈ ^;:E><.xSf8x/$2KN99]v1(Scg7{A5Ӑweo^moRrN׺k[j3u8׆ ԑ خ>Okb#ޖFg~zAw:] KCCC]^|v Oj&Sh X5&n\d ۬c #9<!eXRgl8ovMyh䄢N 4y 7{/o}W4#dOz[V<O'UR6B5C/gwQ{ˈFQ򌞾tq|W=Ax &g,2m)5N޵W GuLJv:Heb*ˁSK8Eum(AMC`O]^~D)Xd`s/qptZo3X- - s =p_ UKDS^=nq~~L 6s2`P4Bm` @.M)Z,Śfy STETU~O7Ygyo_|~<;yE%8|Oe9QQЙ}{Y3<8I$!T ECNdW*zNšM2)[RvI^BKNax!:#7O,GKOO~i)#T RY~f2f7u?š#9i_-X{t6l5$-@mI1DiXRM$r JJĭ1-|KXAb1ق0>Ξ"Dd\U(߯x"2i~I4'm)=y>j׋34]ewŵeEl=yG:֏S q2mZb:@b_sih! FBd(*d( wS~|Ӷ%;&'.M6op&aIށw;jys;E`K^`Ʌ `;bNNPQL5uI= S}i-d}(F>|C$^_ ƮnHB"z;s<]O93T~d GH9_ %pmW{H[oC#ћLT#֢mMNܗ/~8gaq}0w'ɚYP\.Md&r695N}Q)`1VN<[pK,JCG,"5W.慮c2C7}/Bf`غ7r%l&2KP!bR[rD,W¬yfůqDWX 7L &%BXĊ0ӊP[REU6.ӡ 1,jiH3gB$t(F-3rL*3gi: SN9IxUQ:2*6bD{[}tLߪuuCnUDz"vM(}3( ιk ̀ze<Ŧ5ns8yvpqȐ~yo;"xGQY{i6oG3 = P6AeBG~oߐx\ڥݫ]shH 5tfdH%R?:sx3HleWQݎ =CNW>}aR)!,nVg؉;U!ˎ圫rLz֫timvՃ}kFN~vEfrת/4az°NJ2{ TVj#9Y0qӦ[$?IfLƠǃSFS,b{YlaK:h fb_RFOLej\t&I:J:?sȴZC;=N7.5-~8,OmOi3T=N4D /x9|*ɑUaĿPzRfk3é̸?[?Fc׃rx9?2Hfs_s.?81>Qۑi¼#/5 o'T|V힪[%7½Qj~$ێi#nq1I.M]0i\LMA$R @I7(fЋyю1h_FTU5P,=hkVXOfHGŁ`Kݩ?eΘߗ?@\ mfX$ { c d/Whl$DcE ~ᆰ↡ Y1pJDqѭLQ^b#N9  .1w{<]bq8?ֽ(U.1UA`E| H4XhC"orJt)7uBf\!@&b b`rp1ZZ-`qd/!Oݘ3L,nn w5xWm~Sץ}>NI8h1)HhX]{’nU㘾OW 4PA =sBɸA #ׂ4$ߥ``wM둸HgJ %x@DC33e̓og;qy3bo! :)` /}57={ZQri "LDPRyKƬq1wbruu{9 `{qCˋ*GspwI(n0?U }g!\F*{TșDIZCNQJgfz=Ǟ(㴙IJ|T:"Ht$fZ=~@}2hDv!$L%9@"M@AiL)a#:pȄRWx$o-f.#\<4Қ>)gA}6=d\DȦ!$#)#p?Q gw #_NQqE=w(OOXӝ}YaAoE)Yf],#dꝱhxD5D(we0|렏$ Af4q9R/SKOQL=u籮eU85Uzܤ.Td|zz#!X:٠X=͸ӔczʅaAO<>F?/` % udp_@yoc瞀>|zmɑ~wq?W:=1?WT0BSJ8fgh!z&+;ۨY⩿ Ap)!P~΃t+J8Yj=;{O3&p ͜Ya-3򟒐3 OQ<=䄐"+:C>8_>Ge~C+Qp}-#~{fAJ{y^|_|hv:H|x>$xg Rd! Klq@{,5 8{T>{B#|vktp67cs;ϕrS~40or@:U;-U_'+GXA}ϯw߇?㏚s>cqvzLa)HDPD(9] EG__2tx_˰~c{Kb_)afOFzS143-ۅYP g,y${syѹΔNO0z|?ħb($3;70Ex=b 6RSp)Z4D#^nMmeW,:/`zA7}""?>CU$~mj5wYGX8H!%-$mqW YۘMᜱ#!gAHG'rl>+HlUD9Iy]2NTh/\d\9+֍1E:H%aw54d:L5)-0+V Hm(URޚ 'd kGojσ/or>pa:~l)iXvu&@O^g// ,>Gߗo_^}Ϲ_sCd;RT#sB;^γ OgoO1/Uǒ:}MVk:(3,I"VXM|)LwQQEjHI6l0}-&ل ""H&{ÀG}}ec'k'Ŏw?+>":JNjA#}K#o9CmA|\ YqA($pspkhUo8Q.htz 2Wr ܿ/ϧ7ke B d|~{yT+7|OO92YJ#^`rkn'J !|Eryt (sLc/%EV'E 0VJDf~_#boʕ2N\K3Yҭ988HSXeKV\a6~F^ŒR*7D|a.楏wJ.Fv'<ܭ[ExdHu/d[˛5AMqMwf›DL|Z!N%Co>Q]6Tg;'.jսWOfs֎>pqܖSp:&ry/;rh߽''of n[{o5FjK1:Gm5K A{S%b7ٷT־O:=87ό{ѓ ۟!Xk_̺=%d;GAC6@n1570?O;4͟tO|u OLitg0&BFq>oA`k"gR׌xĐyY/_5I,u1Pʯa"48Շ)ì2jqdb g (;QW; ,NGTЈq ی9O&~xNG?`e6I'?bx}B2{^ֻM ˷x  MQPhs5X _yҜ<6W> )2װ!n侁4rCxҍIKb:1.bCz,B3tO x/:R~5t'hp)Q=WDsǿԥrIgǝWtp;V|9k}>֟˗E7+G.LO?BͭSݻ% 䳿`t lj݊&:bvM65=~4p܀qI~uhhote,˃]5bM#H[!x-FX=JDz+Tض{Ym%WR^FP /wO؎βN91 "3DVYvF~ɗ2BsX?Hs3{WSgz]KQbGK@?3ޓvo*Z0lf۠ߓ%KF@S4osb+Pp[{# 5mj"d":J8vTbU?D8+n?LEG we֏+hbd+Ju麞3p ؕQ.6[O,xq#N*vH$H]!-M"wrO׃ijӎ?JEO_0KttРϋq1&# |ֆS2y6H-c{Vۣ{ni6e5U`SaU!ǯe|OS充{ܰ$^%'I;eoVOʱ]v.7R<z5x{RV앧pȔH+$e{3By 2# A@>b޹]<Al:x\qW/YHgw~DD$WFL.GF5Hm޻DLcbB-?Vdh#?Bnxv7d G'UvxSLr,0JƢ"DdrrڠX3:RZIP ОXu:OE<~pc<۩@-Pkf®TXw.x q7:JS[#yKck,N2xE4Mru%jBw]̮w}˽Ǎ)bGm}_9({U(pe!Mz{Wc}dxTmy]N*6}>kc„^n~<*vO/z7>=xίr葯}F&{g8 ʶ( 8% Bb13-GDϚ|Ib O_7zRF;ԟ5f%$'1x΋/aMd}&ƈKJD(*ܒB*ªHt f.^&VDl Zۙ5 4$A* h3 ].}Kyg^-2ωDM JH7%B (,hq ]錮8zs-\3~)lDvIv?f-j ?#|Ю_3j %_c$d 쿩(Mh{,Lȑ ]8a ?I(,3fs|kD[ ~Lqyч8PHE]c[< j"EAQR'~/c=ָU&) 7B6, 1`ݪXA5(¢MUéZ!S vA`1ҡg;I n/^5Kzrtk  =\p/jHxYZZ=S_4;ܔD[5jc%AB{<9}fvQ5zI)$#c`^÷O5քl<4'z+ cTHSt؋&ܐ*qwB&@4< 'ZTN;3&@*!4SqG q HIU*FׅxIXHY^YaÞ=ie.ӝDQb/(];l?ZU3zkGULE"1rc'-n#]Fi -DdC2 5DEs8E,bָĆ7ۮEkl_B["rV~v?'iiAo7g+H@A` 1w`ou@!T8 P"t*b<>>oy@RXm|G{ ,J"+:3]=sl)ӊGi)O% Շ3}Сfsо6_K\'mﺁ ifB$$`>وPC=.K߻sN>_p$ua(0sg?yN PvxQvvK$?59#hew: 4naZFnKkh?~{<ڨ5e R'ŠD>;|$w;d(RQ1E[ǯZ" moR'HxM%5Rt""Yf5u> NEښ<ڞ>)Y6'fP$J#P ĆB]5akmzb6w7rtgGVC5R7~ˆSiɫ܏r*j#zzrF\wqT7}iG"Ja}ۛEh8`Va1tD B5 xU(ᳱe{5nA$ʄ4D e:ICn{O $DL,;Oe.hw`.yt8UWʫ|;k6os8 $dlc6@%v @GAd;>I ks[f_!߯rzHe%cDȡ$飲E trR{9a;)&.ҡOx~8m;S/'}^!ݙĉ̑[[3c^*M̗iKz2`浨2*J]NFa C)# ,]7JrEzC0;&_C\'sHNCuѧ8u|9ȝ{2gG|/wrlH:=`fv@H#$GU|! n=P3gfJ9S凙!Nma.R8ȓD"" $aS.#ѯӺpڀM[j˧=Rfj6v3Bgh8Iz՞}* GDBt53p:Mj;cj ˢs'-t]g+'6sY^쒭b_ԇ8~U`~I6kbw@t NCvӆGpsp^v ~g7[$t͊`(Si&n}-%UUfxّ!̂L'7ߵWͽ;IbFMWoM]O z\z5q>KlvPG/ <~R)lյr?S+Z_#cw|_0}مAF|~7(Tׂ'H&#Ci:ʄqTP b1hZv2uf()1Uhlj$ghU!E_Ρ/MH js[=Ly`T {ӓ~ӳue4i`YD_}  FM?{ijɃ 秭Ҝ7y"0E(THAr"uPP_#q<ֻ6= ZR^䡒'\@~9]"Lq8;]lbDy<$0gCFv$7olOgvt?syK*1w[r1ljCRaQA\Pe!{涆l bL*<;>" eF[ea4IĜF#A#X}i<:Wgi%JuƮ ]'㍑O}~ݫ@ӣ!N.(!No OLf `#Ķv}]etȱgXv :_6GBY )$Vro&bw h.IqI A=}y0xACN 0gT4#!.nukfiFL!  5۳ܸr .Z!jTPYdKL~t^˽:#`Ge  6ܮA}/7Cp'RjG[֜wU#M>W\N!&uk,Ũonj-ӌ%فb;qŰd1;E]U`$x'{∣쨑6u2Ns712& *+QM3P5*N.|t r9h<̟԰Bt<Q"!=Ngc"QCzɈ8L},J!jAήID|[0[rԄ4\+6mɪL1T97afkFZþg; Y =1fwvkYPحA҆`K"o Et HѹlFRJ'.0|㓬 "rZ1-)cmiˣ)٪ 5$S%ujTmļmF5䘿XWVaL&~kv=hQAݑpXYQZE7_.0Xt sqyBGu_Ż{7FŠI0&"H)f#!/bE5e5̕@}_ VydH3p/EXz[rCXdbKZ:Qɖr$EޝժW"R0[搤):x˒t#be ϓ֚fyqk0}y|"u$i?O}2m*٫Pigy9?o9ba@F@go ){Qe^))JX>bOT}Ck~|pz셃#b9C:eǛ9^FZ<0؀'  yLul ۢNp-fJЮAM :ӱݔ ò ?O]/y}}aqZN&b CL(f̓]9Bb |x• SVrdȣ|%؋%kQe)xY'F&1YpA  ~ifpw#/c,5 g"[I [w3Vt{|-i|@_&2bOz`s\̢Zvȼ!Ș_/NJ&"fSnF(e $TsGR+b}9{Rs,Wsc1H"|>x}ϽtL!$K?0# tE"S&RrLQEk"~͆M]!ryLc&. Ӣb%N:GMz1 $O$>r3'ΗLT\ϓ$ XcG۪$䞙+zwxX cuHo>ztoo4 :yz!_K\4lbcxbyovgvfTqM-9ٳ,o8hl\Kߔ,HCa}iE"I4 )t$،)r^ÄG}"IݘЋo \xbL1cVK4S}UrX<|T-T |R|R^֒{1=2WH Hص N aH-y>r&y0\yrmAO9d]Ye 4Ӂqk9" a@;zG o-X)bo!%adБf[~8cUnƺہᒠ >+7"rM87I okI[.aEu'=vyHtc 1QȽiAn~w>ZB^ɱ6`N P JcۯJG-S ZCS'tc.1GNFPYGSb0ː{4ۘ;~3鹻+ NF>B %7X6Cؼ_bOcUOV.:BQI,VU8XJn5Y@\Qҧ 8PiFx_uJb]ix݋D^/Dy=ܥr H( 9%8/hwmӬFGGճ# 5$.RܖUAJ;C]x5J6Yetmh$bteAB x˓$yVI9;RO{V`m$Z BE0`,rpj}B& NR=iu\eՐNjCbʬ8P$HEv4"Xq$xٍ~31Aj肣IK'wؖض֜@,Jʷ9?$M@՚CJBCVTmi 71|)$V8zOuF<ݓp״eI^1DZarrPC_|Ȝ. C,qo[6⹬_ג(HO0d rE.woWe|d uv|zlْM#^~(m aBd̈́oQԨ8*HO7H9J&kAGǀuvƻHdɲG cǃ(F ,=IM.ݳ6sŦtMq4)!d}&vF!d5|?{{$OG 8}/S,7^)W!Ė'L| f)ĴE*-5SQbxN:hͷ6bB" }^+s%:C/ژE(C~@Ƃrܧv{٬%MAG-D^ZOoϟ=eQ0SJMDNB,\^_߁ڮ |>BCO;saGJ…v(ZSz&S;:7 ʷFXbYk]FvG5܄L׹{/nO';2Vt9Ka=]eӦJf^t\\q߉4 u{`;]/t,:8yw%EϖW(p}#(\%c< fMbNX/,*T,R(փHt| uK%D t=rP_h^v7_V_7A!0T_lD6m+)X,lؕ {aՄZ3.ZL+S4V=g< q?]~5Z )0#D%8b@ ,-m24nɣ &NJ}gͥg?PjU)/)"y.GJ+|ԽV4 ǵ@kǣO* HI ~] 8zioY,pxþ;9,UX)Vc{NIȀ˜q,X4A@ҸNɍN#9yV`KwgN*8i B:.4WPV=Bsυ> D)(7Cg /y=g ݀,^3$3#BS8!qSg$J@"v78bLD"S~MҐ\+@ȡ8[ba WXT܉K'Sz?%Ryx73O r?'Aܜ6h,=D_i fP[,>ra C6}ǗKtTBv}܊Cg#95ӭuaԺNM<-VZ{dJ eBæ`Ve =f) TF` QJ݄E)pW~*Yٝ׽/ݕo*ihC.Qv80C٧ e|S:'f} K!/Osq|iW|^7ҽg`Dj3("*87 :~Ϟˊ[O"'55ˏ/$ 2pRer{>ZM@y% pb1:̋*8@N<@-2iOfBf7ԗ3|M 3F_R^(۠e-5` !I^ %Hc jMzKCOr@TOӖu~utTȘ>~ N!|}QCscZ79M+5򿧚W=lRtnٮ͢q;k'KlMejh6OQB4:jH:kuXk)|",D]n |]]RH̖oD)/wϬG+',vs\[$"8t!<8D_@,$$=$hw Cs~RZNDLŢV?wg{~7< bhCV ?5w?nYyq!Ɯ~=z- dG睒Rs5;huzIWκ&Eabo7k-O+ ][COeNrG-#eP ̍_c8{]BY֬ %ӥ|øA. =t-旋} YZIgc:nrڕr(ܹnЍf]'L2%<9KOzj=䭓@73iuǂY;GH^lc;%A26 qcJɾ$'K/d  J!̣#{@g!0e'[ ORz,K֍MuGѹ!9+Lm{|6N-[sǦ6]M~݀{;3)${Zg(fqmm1i[ KDeTy Z`Iٜ_~/K>)v^k`_ ;<sgSurb( tPς-ʭ́B ѹOe^dH!y "9LH K1"D ^d6Gc#$KmVG$@ HyF/W {Cgo:8"''D#!U{hDJ@}V"HK=vZn=zMO F$?u5a)S αt܀zg,RSrApvi*x@;>c-5Ir9r4]Μ 1YCb&KϸUٱzdB`5I< C("Wc窦œY`.J K.HKL}tR0!NAn~g}vȄ1?1 FmSD?,6 "_J2yQQϓ:9?&'ܺ$ j1Yt_Xmrࣺ!o8uJw:҃)RuԢ(064{4c ݌}@ʹJZ¥ϗ (!Su_Q⚦m}L5x7بR/:P~\m' ؈a3 svmV,Xr o9StV:^+sГyFW٦5?~:)S, A/'s?iS[<XK(r^3~*pCGN p4Z!_^ƒ2Ac~ݹni<%pzhm@B|jo1Mpb|\K_{r#!d;yDHB BD:c4KN%+x[^L{ԝ]C3Tϒa0"LWn}wvd3XAH&ClĄ\@B'cKPLZ[~c~ IgׄÓ7F@"=) U6N\"Bؤ*G;_p˾MذN^׉5~?p*4QK(3CH0M(TU ֣z&9| ^v=O*O"*[mMijI?%aBa&Y eV5D2 `,"GpOb xUyJ/Z*bo=u` L%QޓD)w~O97G?DPU@g"CLJw," aF+Q<{tJ> 4 Z]fY!Μ8]aM4ek^ Ʌx@TpUi%lIcߏzV{Ґvo,y_brH,Ypa.]#-O|f;˴fc7ĝ! "O>ùs]v&6pMFf$%怈VAF u (|cwڕi 3x}h';vH5r)6=c3wurk୉uMeiE/D5(Ɂ :_oekE^); fHi_ᰶw5ˡ% xP)a6a; iU`ԍS^9i.HQOەEI$ HTSB& X4g@{ygI^:E]巿3I$C7%-fA87+|Kt14w^DHvF9%L t]|{6+b ֔F(T_ـFr4Kr*K b"$:tI¼ 76hٴf͒bydL",ts3Z%1n n[ѧ42I UlQ^q3r $B^qO͢8 D/FCr#`=ԍo7^wг\ >"銸ʰKmUgid^!!$nBe^q>_zpܰכ(=ʝ Ŝ\aI`Q!X9E :7 0d8ncG }{k #a{J# I.^6s}~KM%/6 KDNYKG f@G4{J6椞a x7B,|G H;}IׂA٠6$D{f&>5) #|2R^ b$PrGZoۮ۹AY19fMt* Aa~8\ u+~887@2ȝeb6hpk]srU_?H2=OKńɻ j{2˄ ? IN~g݇&_~j (|*9 k`9QYz=x ؈%FgceT:6G׌KQ]X{Љw(OK퀛nco39D6ǾuŚSu$9[;=iVa?Ts٣Ʊqu3^z z$WT_mx~^q5NÓ5rPrnz~|_Ғaj!@:b@Zjb6'(Oqm2O(d:|iٻ;50@1!oI9#MGpLqlO,ttY<!!RRbN5"AJcڜtmmXT)v}q^H Hee:F$H"|ZUkͪIޠqs[yKHEy7x2꪿Ō]?*Y2d|ƷWS,BFg~MnbY%P{c~Cv .妼$'; ZZ[&A#$3S w#@ mGW S[`i.KM1أAsrhhTS%tHi ;QSFg۸xW{ҋ/ɔ 2 g,;O'Hb@PG%SiÖ'2̕z6L& ([EI,/5f1& YZ5$8&} i/ S&-w+XXcl%~|,EJRA'1vg{gt岙:?ޅkZZw<,kM ]oԞёZlbX͐N鸽ze i;ӼO$M'Us`H`,Q8KACLw.N.z(/ҋ=[d`:KCF`A.":]=>7.&5\fvR|$otVԓI*Qw`ItJRؙ*g:8 ZYYvH>Xg:B.D'6%[:qyFnґܔDw'ѯ/Q>o.~C"D$t"Qb6"Ҳa'H -h6Be6?  ӕ^H>wxVjJUipe—#fp-{XG(gVT lpyC0÷ΈhIןz'b>ux< 97GĸT=O b{M2 X t3#15l r?/-R[w7@`&uԴZ?ĻtW 1q}Gs- oW`.G2K" Ot\8" "@ڻ]RDD,W xD~{яњD7p'}.($or.3F'{uosa§tޚUۑȢffDIRcM},&tp z#xd/)j"|qY~J10 SR=/X[1gFC~3J[ scV˵ug=nZ{x종 ^'%"{WbwҖTTVg:gY28A>^:Cjg&~@ NrQ]#y|RArZkPnhӄ&;piۯְm%$܄\zgƓytHa~_N4r@}C*+ޏ.^ge/j[ VμE \w_a簘@@5P$H΋0'VOh{g['=Zb}9)?I l.͋g=ŞC~6^qϏ,^ -p<8w_ W?B^Wm9nV)`>@I5IQ`H[w^fVd'}."E.VVia{rk#+75B',#ý/:b w5 r D$UR%o)kB!v:I<@n5qKNZ $84wz(:%"rp?wG4\%V̺>FprogqR-y.Maf!_j w't_½Hm6M\n}M zdnR{gBRrqC{dQgGh؉\ʓ Ww0rK0IJcl iA Z:~6.ƉCӳ|}/Ph"~Ľ-]nӣ*;ĽMe˃ixR?_حM:ffHh.om-͍|PPC=xYSq/.͢ڶNu caa7.8@Fc(䬞~kIZ'>Z) kV^Ͻus XdI58lǹ*;Yk K1"Ef!0{<=N7JY#У dHC5ߛ: M3;RqI^TאChag>Pq0N=r.Gk/C:ԼzY^Or[q_07囼-rCN`#-/a ueI߆mK/C 7=-d9͢ "+In2 gt%am_5J\͏O[sWVȈ-{"O*Ǟt:9$v@4_=v=CX|5^-$f)Cl`r뗖؄G YX2ٸSGK<B|@+'*ב$ _q>[ag)D2|ҚEvJ?fibTb92P@O+/[L`d~ōx)p1UNL}=!n4.k.!<2UW_Am[u>R;ҩӌj4 &'^p$tNpH#6pA$EY\+JZZ%{m*8j̡/Ĺj1IhkqId=[Ēpy,kfWs;nL.0$}Hg>?ݼK#L{4?/S|i>_]?m'nt.Yθ}M3ZAl6}# UX%FpБɄA: ILVR-jԒoUlm(/jFKz8B֐O_0eGsDMOMw&wD32+73g LcOI8'?_g:v?&;7ʷ %5IbO)SKG8>:rçݺZR &=Ii rhrN}ؤ4N@N+_8:W<|w),~WXL,qd2<  ɗ yDGՒ:E)ol>Yx%a[ :@X $7;eB2^P(#Gh!n{RF;ܐ$FK |Xv͗Ke-ORwR}9dR9Be 6ˤ7"GrHp((\Q Hv39~~7ls]pDH))2brh{UurJ7%,'use$u87"w(t=Yi@'V~>ܩB?zz /AA#MR}ѠzjXrq"G}LזЕ6pue4JM_̤g~}Kq+B@*>Զ _cl,k [ Clݸ^c-'}[A~*rN{ }T{lq2.3Pyy@LO:J TTʧ>۟Z #Vd _S҃1AЪw52ƻ0:ȗ!O! `V-gʾ:vm$37F-o bmas=~dj!߇3IV x$CʷK~] $ԆןMѿ6޾쒟7=#kAQBX Jiy,,љUk j@>o}{~%>^hTz2_>{I,_moX:OWqR^"s(tɑ?]8u3T@{ĢJ_FW\qаsᮑ:I'TNnjQGV>'JԢ^;_?jbNo"{3o)T9Wpof{ RJ52ɢ[J WI/귲16j"[ױA[jrT8-Sz> tPKFﷱ+x؟~m7daQPI81)w9u]/{R' !o2EaOc&q8䤇()![JGDcH($4iZbB2XpپjrjK 9xXd#*DI{^= lm A$vvYpN^ȄK~e.z)GjVOV9NBvSnisp1ވYqcA@>o_L6MJTwm;alutS8g&(_ͭ=6t4l[Cm$gs U;5ydLMslpAnsF|8yp+۹&tryPZwyFԮ̲߰Ewv4=#r('< Ih7Q-/&szF'lZ79/5+ZWqR㞾Wg,y1?uzyh)-obHprɂ&]\XL5V t<)7mW[֙e7"CyvHv9W y7B E:AqА}|}vnc|DJ"-\/ߔEc~/}K|^huq,;7/wiBp_Dr$O-xjغυ7b۳]*\>rzHrn_\G<&},[g-KX9y)?:t8/ňY`>uJ(Pz{Oޮ ,k?]R?;k0_ئ1>IK#<{_UW$ Wr&ҚfC9߫YoJ9>Rv[s v!#Uz E~~ۻb(7@Lj!X׈czUiki7՘}E,t^}f4T0^qek6O[2F p )> vxƯ1j5`גȱ3$cŨRa:x|FbrKr=Y>jk^JŃf%`%$_lS3'!_Y.uߚyKʛJp]Cx(nM\u\c?AX'A=+Д{(H^z܆kk%sMHKd.vJ& )?)xXZǜoى,%Riߑ:u^*;,_i0鸮؜ S(µjqajH5?k-M6v8+:`o-Y>=Yd哖q%S+EIԏRbu ͥqr ݥ $d).ՒܒHbD”$&;QJ bXoET:kK<5^?}weBM,sK9t$o[AͅdXM51  7LXY*(#6k>N 2ʥ̄!\QK! #I#]lD ՙB(e6k#L jYۛruQLtg3[+Iz{) )b\vHh%IDF Cf_kD~7CΦGUg8(c$-i'e V1/[I) SExΦ/e^N_?/ߪ#/q+};`/v>'LM0&\~?o_ML)A8)"±pW_IbIr^J ħ/0]gI8 D:dU  GuW??uUt7ფxv*!܅!ZT$!ˀKG1БiPɐ,M;E9H􍨇I= ~p۸ E{%$CQc eP*e[ue}dpup׍橦K$}&<8s>Dzd "A'~Wj"9;I<8itK/Vb, K*%^э]E4_)|0b>rjb7n>Y3`C"rx)>ەӰ\* LȲc(UX1UI=Р[ zqH$S-OeZz΢Ih7~v5j*x! +H ~cS'}xOŨh2G)͢h~cR6HP $פq,"X^H%xExI':I>.; 2c 'KT;#=H%%9vD.ju;4Lʮl1eR@9qUOOMh<JI 9M!-t=mÊdiCPp$XW]?䥅(RLY\BF7!\63ȥCacqT|ѹ.BGUNdcӳXOs\K}#e(QyEVl&|oA*^Bo&I 5Q$w~T{60+}H L/JܝiI$ĊdxlM<,y &)i/  ?ſI@'"P)"mjU/.O:ҡ*HQEqqJPEAƍFY9֌ *jaMjվb("D dh6LDUI[hEIXhF ƣl&M`,ͱUlZZUd L2bLCEDjm)5bѱAh6KXYmQQ(ڈŴiaD&(kj1QYH[&*mEEcmhI1$I140jhBBL *)FQDȣYY -kR`6a#d Fm5Ѷ RJ%",3"Vi2K() &4IBI1 X 3% HbJdfl!JbD2J1lFJXAbEƒҙFTRF(ccSiCj5EAVRjƬ[,JV(!H2I%"f2lVT4D")dll,Y1,ɲk-2֍FkQe1I2!SLi@ "dIQfcL͐Ɍf@kLBF2J$JP )$ e256IP fcE1@l)IHHdBfE ԢHfЊ$0H A$PE3(L#H)fF&MC&! ad &%C J !P&&Y bleHiLK 2K%QLJID@1IRl I*R4$($(IB"E2,B(JBBf#YhLS()$$C4 &Ȧ%$%&&La$HJ b5"Lf %Se1*HRE lDjH4 4T0Rb&&c)c l2T, )2,iID0,I1*PA̅"X%(HBBLj%Z#!4C"4P&0i" ! Dc)hi#A63aU6 %ljLI"`Db*DL,filQ%R%(J0Y1Fd  F1 *(LQE!  kTAkR$ $ɤE$fMe$a6A2&M` 6@AfDa LCJ2$ѱQCQB,ɌA@HL&R(A $F2i2DR)4( 3dMaQd (S)#b2F S2 %LI016 c2c P0lc14!#F!D"DD1%E2!f4P $iٔ&Hh̤$%F&&TY&S$,Dh4@dhH+ EARe) i2i Qd$Lbca %d- 6MF$$ X"aXe4@@U 2j)FX,+ff րb!@%"%$hbձj5mbѪ lkEdC23AQQ )&I &!h0E&H2QSIŤ1A&SȈ&)Ґ,SH#ʄPRlb$b#i)I1&*Bh(*#Y2QI2d21PB b4Bb ,ƤB͠%4f#,RF &ƍc$`L3RH*&"эM) AJV`b`1fhP16Ci1dJ(H ѦA!)Xd" B%!Җ#46"E4 ƦHiI ̋&ɒAMj"2!"@Ȉ0F"KRbH 1$H HfMEiIŪMhш"( dƀPȣDc$0ј&1& &f&"1 &12# 0HIQ 4M0@ҙ$Dd$Fh4)DRBH%#DafK$1$PٚfFƅFTY"1cIQ-4TPB"lIlh&(LH$Ud(ёHb!$&JD&E H ,`KFR͍cHb#Dh4hM$!2X4IhH$H&P HiX2$JjF%B4I 3F& i%)44Uj4) b$BIfd RM LiR Fb6D`!d b&3" &-)"TZfd"B% H(HY #Cb$AFB% "&Jb$F,l02RI# (i2!K!d fR)B1 Li&fliEJ0e dIJ&RB ($!$0%1&T1fd01HdH"BdJRCE#ii ɓ0(b@0!A3( Ćd,DM!&he %4JaHkVٚ$M^R"l2DTQ*TV m&Q $1F10ш@ bI0)A##Sy=;(+jyzlҔ, &4Ydb0M)l(TC&RYa )([5M!ę5Jj!$2LLDKLeRS,b6%d*(# aQfb2$!%2IBѴ$l!eL$+J21 Q0TidllYQd$Չ)6aj j "lbf(6bRBHbi4Hj-cX2iح3&%I% jJ *5 &@%|3m^]U0w:A"&~U1#BCnd_k̑Or ՓB͇5P0@\zR8w$Zo 4Nmf]HRqEm"|!W:] w@1]!tb}GY +IVc~)^9sa(:Qi;9#N Rɋ'`QY3->AStI҂֯f.ԍK\c-&/=Y0i(PW\&N_B`c_d5R3' 78L~$ޑޢvvwaodZ A5{sf)6<4Gw`p 5N_}E鬵s4MnD*CE*yj*ThI9RֽnZЉКy`0iRDHT%vNz󸼫܃W+0[*[ĸd6n\}HC+ib)塮Egmb&\eMg#]Aφy-A7 p =$2a*L)/V6Z9:yqiޑ|iɯ۔n"a%DV-'^ղ|Ko%KE3( ޞ`Ewbb" YJWfp?9l_o&14(D~}t"0:nC[Z땡]׸T7<6GVxm.@ghi,Ftfya+{0uI0"]hU CvL%H dtUJ\ ^Q0ѨLJWCx+M͉[-ObV#at"(kU SrO2?.)Ch)15M ۣuQD\A;-*%g7trL1*}khu)ҝsVj>176޶Z]jV7$O0)P8SǘE?%LDz897Jce&&Sk5|l  EE!=>?Q!c 7!A>/mXjH<ڙH43G Mdc|V_]DXvQf1>J1ɸ2kcHߴod \ l[E*)3{K^D) >T$S@w3Dїx1^ihgA#/y# e-qm`Xɷ_*g]րXL 80^!T7q؎ &Ltelz/<6ZRF{/ei6"-.zAH{72P$^6FW.Z:'u$Y8dIxFr׳*^#V 8Ch}6# H]h*gUj(TƠgܙm ˹>v_"*$u9fd\c.J7Ab$a!}? W;~mpZ-p j$hGؒF,Z"_%::/qH!ٷ,ȓCOzT4R޾hw0-1[Ճ84!Q5]VT*C#QFN|)la嘂ߍRɀRȂr,xgΣqbBدʹ z 74,?A;;~ jH A ?HM?.1@3A)eEU/J)fډhR @%DG7G9;2-w L*:}ҕu^ L8! qJ XӅ#DDʑ;&#JLҬ'Z9;u,oWj Pw?܋\<;G<0wJ H#i_˸JIzc RDAIWąDa7@BRŕ ca/2ip,Qniw4[LSMBǙ2L&Ovaf|DhziH[x v70(FC9U$ VO{.JZUȇQbF_ifTCr1Iê4Nnj:KTvZ2z\瞿I*wpFg.䠟9دd|Bf$uvo3> ژY$trNy@Rk{WQQ~̑aܢ}_M 7+ 1:@ <),#2{}nG꣓@ ji7pJU)K>܂gjD{ѿA,@lCT#Y8Ǔ훰i.2d2Wk60OEwzvܤMo iL;[~壈WKw54"%'1 ){[E\x^OZGJ IKPPEYB(im(!*^5UO(*LC'.m p=Q&>X6d毘PVJܟU3h5 qo[E|57MJTJ>3KV)^"s p?r&Y$zMe+[J%gV9SeO NIt/.hgH[l+0y⊽6~ f KAf!;89#FNprR.fS:uBߊ'%;]ɿkc}.C xJrJ3 rN-Z[uDfXM+`v/,mJÑl 4^Ԇc)cƛ;c`lo5IKHc; `\ T#3 KS$&p$KQnLht?e,^ C7 3G l\#8L$$B ·}/+B$㦦kO-ظU2a3!NKģF߆$L.LE| ⛼jZZ #ֵsiB 63?qlNxR^ y>0+dUkZNƌتm+QSQ-pnêϻvUIIHMGry{o#ItZ19a"dg9 c eZ߮ƻ[aL}[Z.I"4hJGȆgf^ge@`䧰mdzbYJoBAFѿ6h?o@z23Vf0?!O.-\{{.Cx jlNػ,3\X ܷCf&?kIE~X6uuZ1y`+<ug;b9ٚrֵ=]>)Z91B2UY;>?ИPuIܻ0J $Ad`{,h% a">_KpḉZxk;}?EXP:ju?_b} d[t:,ѐSsY[7ȅG13v7p F#KKB97,<&G.ً6~30Š`JZK+U*@jG,f'dW`cawnac7W*7̩g4c<ND `햊:V.۵wU?5[x(+R:;uA "+,PC[ &K]R+KbCO5u (MשQc}ϋk%cCU:C0ݨu}dj4et"ѻAPHD3J2pľu4О>s`HQ{ů ';D5t;$0XLfY C&6LO[oEMc n?ֳ~t~cl֤aɪy`1y䛪|G v0L{Y2OKX/uU^PyП%[ ԍ&o8K8mإiԼW jϓY OWZ7VX.Z\QvҚ\?%Ij pIq]J|d/,!4|)(X?Cw< ˀ]Rn = Gp(.ƲLGqB l~}!)%CQ-IfERklUԊ5N۹XR,l;*މ7e2uXy@ C%ގ*Zu fFҼ 6ij޿ {m !TK*d(@y 0jd&"I~`.A/SDy}CvJH6RK:ۿ?IҐ,ҏ[eeI#=F)ȅh؂B}l)f  "{>3=G3;[Z.E21<\e;D *r?-# ] ?Fo<.֕I TU 8\gUL~n.6WϤj[O-k4.]B1Ü L< RN3}'@ͼrt@^.[yƃeOX|1-2 f_81p*:, Gı\ӟk|pažqj<7BS ( 2)`"p`UwBh0  Xf6džF.֋pлfy䊨v<#4 sKCn|q%O[Ym15NqW{m-Ug/Qsm12f)P3~AU(.$W^1uZZ tIiBXWu X4I_HZLPܔ\7 2fL-wBhO#hVdKZK{H0Ïh6KjI?r%]nt0*gEtfH}3fSHh9δB`P~(|~i;5Zb+g늧~otAކI=>Y0W0E&DZ$j2K2Y}Ꮆ#Z$Ңk^'_6rеJOxFwI׉GF`Cl6!uEfiV"T0 fVUgeP3FXQW?H ŵQ8,<^*1=[s-fMNm8"IvՄqFM7 9bzV(cxzw R[m#=oXKpr7S'u]Mk63d+>JYVv)n| sznoϓ)=((CS:/-K 7aj>sKn6UX * "zıj{<`yWkoYAR`nl-mB>|Ʀj .lc))&:z   2LZhh*>?hwT;EtsU> jnq/@f1mCa!9$g̴5v a̒;`>mBĊ8M(ax敕 %FY0oEٿׂyEkknR=ig g`cHK3W.Cwi3!lN5Ui~d;&KtPjUOYY+ₛO ZiE:e("S1}?'s?~%r?On~YzEWe%uo功?A,KB>ty#RK}t]2xazYڎ6; Pd*g% >c4?|0,: ̔g^6WC._Ŕ=-Hg>d9$St3Sm+0#s{jJWtd+03uhG,_{p;?I ̵ۊ^paW[8^B#RBƾMq͙0{g 1;ж"cD2Jѭp[[fo2(vo}<K5L)RF.dbMOI4>T8|VRSm5^y,F:gQȁ"8޴*#Rp}j7Y8<ϩ(~;vTMRU}9Q,<Ú=|9D zK$1ZX]̫Q~[y`|&-dz۟o~b5X(9r'[0)QCh"]`W8&!eFV9\3 m\x]G[&3^ft7t~ o9o^jӚ@ r 9-):).^)(u%(?7BGCX@ cQDK )e tcOmOg b:^~_۶mC)=Y-]{ HL2.ʎ5UݑӤsU\lYXn֧Qbm[]S)gKKwlϳ%uLA~ϯL^f6kҋ3М<ƳU6/0}g"8eg- ' XG3/6y=/O@4!k*o]Xcc@&ZYbx:WWbY@oY+Kńg;EѴbze+ˀfPPAU4!8W}w*ЈPoOKP㕐p\ x8U[D|ߠȚT^m\*.qkW"~h*(c"~{4H^1_yE9 ivDAbt&|֭ G:N$%2ɷSDV ]\>%z"558;ho{@R|\|wu(F|SŌ7Å'PCufeOB[]K|Ǽk2\qq]7\?D1~>| wEk N$__+(MN?Q.Mx~msmQ|P:Y H7mL=MSV bNt`ka{LHuB%}\f(?48ɹuͺx+84@ !1{ʤCEVѼ12%^]bhD(@3 L);KDأВοn,{|%bעlpoe3O:'i/(DSs/hb/"|獻S)sj¶ۭRf &1.e irMC/`H9.m쏩@Unַ"KNo[Z1_ۯ&}#c;,k3c+:@dk 9.^2>fZ:l >}j/%R@b3 0>2hN#s}j>AY#]ht X(eN,q|0!Q ɎC7~(+1H%U Gcbר|-ѵ8cDe>>nӤ7#mnISAJ2t ^ v0Hzy!C[r^G&瑸Fz%+-/q릀Aq wQk~8vUù]=ǝ@SrklO,YJ"/آ_$/ K8K_0냰r@^߼{wÉuM(\GԮʏG2}=dO﮷-DOOq׭7gXY5yaFY'E i SLEӭ t#C"^ &xf3Қޫp8u] /Ƿ:ZY ݕ'h tctf엮8i]C% R1i9cL0T~4~ޛ(mn&{(N{cfmp6j*f| oe Qg$A:BqqZH$ֲcIVAZϳz/"F-koxm8X) J|^a\[94l?V'nkzx5FDg eRm2Q 2F큃GؤKYmq4cB1)?\VߘO/ gZ/Tp.#td7_(?.״j](147>T %g}5Z3lKG$rM8ƾMXjJ]`IbC+7FNcEM{YUT O>SZJYgz.#B5]w߶Ad`hx*eMshk\ -p)+5q1*e-5Á/2 ÔB"-e.E nCWœdמ /ŋ|ն!_՗^lΊBz.(_^vא"XV>$t@W)Slg+bσ<% ?ܐ⋜P.x>f~5g7;K$&)Dhj0%7ƸUul!ż]ѵ8~7<ХbSl6PT?vN2`* *@՜'֘Qz G.C_L: @vⱚJJČ},HhCTlO flhDAxqէKS̔f6[b[EsSvL`8ȯCgi|=ل:透߶kCboi\|6uk|5*mi.AqJ h&WY,qW pbۓPPA {/ɖJDKkGsUL ҩo;uɡ\-5LPEIf;. C~>4~)LCiVT7p<͔x+?J5%HXd~є[0H%*kox PwO t}wɉ=Z8G' Vk[ 7%is-l-I$MX7+,8Wv۵-gt{'Ӷrt '`f FNq_r'nz)@{e=U%}L i_դZB*aL?!g E 97orYwGAyj4k3XX֯L[qy֩}ڄ {\RiY+iq e\V_wU2N657o;~8#&`Tjo08JC=AH'EoeS~"i0.D:.Q=QP~&rng!ǃ'd1b)N AvJ8%v~E,dku"TyWdgr2K6{ QεWDL0R v @SuyBadl&υ9 !^\d?Rny.<"^wGJfPPԖ8kçQ gWCZ/IEq8M^sDu/g2.ok<l{D]01XIލA[Xr$I8J~:S˩oO}1 V dpdޮm B.lVO 1{uk)pƫ5ro Wa%-N$Řrg߈٩YtF[ßrY?|r1*iFg1-T W$!Sc!1]NڗЋoN)6G` }+rD̀!q+W{: G7t[ ^e`!6҅}[Ls#. 3|l:KkY=akݚ0KI_<̔ysCP724[հl&$gs Nwu4 \DG?IAGTNΤиYn̎rLzQ#5*F6XїrЈ'] (EBsF4&+V.daYCUhȿ1I;s˴b;14I{V-u*[LX(tI6u@hMcPuhE4C DIMf/0`ۥs^*EVc2D&5רm^?\ӹ42٦#bbO 6*~$t3Ysn"ry9V/@ _(>梕 nhC00\tZy׊4edD2[İc~SП$k-hF2e,D=N{gDވ?cg0P<~I*̷cCi9rGq9TKOJj4n9U+p~{IPZI3v>M)gY. PFyہIdgʰ7f-:1/5㗸| 6_7Z}]dI7'#|sI̩x ^_r8 { *68:E+i3{G]H(P $վR!FțJcmf$Rp7XCP $̆)zL}lzуWA |f 'i5.6ky9Bi 2ftx\ޞ$[ LȢJS /7Kӹ\F(jCHWb=x8*v?1NUǔTO5EnGӪDDeBc{ug@F{Ʌ@fLe{h?]>M!F8Ht4;Њ~آTl)rFW14r\0WJ' Mv<>Jʥg{nys,uwjb~3g(}gw͂dw}; МX>nId+ג*D4;trEO"rfU ׃*RU WM`vFOl ofL5[RrO.i&Isn xJ9xG X0#_"R&(m dVm"Mn{ nPʠ.#*!Ɛ.s de٥;d5-s HAkkI"^a7#n =O?3yB7 w}ّI $G؍G8ncbqtm;$Ox¶wND6 rON#-) w:i)>>&yw+jQ.H(cZjvjgSRSaOh~q)N%TB U2Ŗ;.T!P<ǜ`Br l!bޯ$}7>ZFh[W!` 9KDž=8LKG0pflߪxoʽu_C><XgFz3-%ޞvV`vhn81`zt"8$N 6ȓ/֐zѭyEl9ǃFR[&j^:HL6@s5,bkWLܴ1k+ [nhM)b~)۳j(r7I"$=Q5 Ϥ6BԒ_lʞnOiR,j9 &uuz]s*7Hs춇)AYӽC1ѠC1dnF:sa!LF>V*4M0*`Ԫ=M1#pȣqٲqJ|`Tˡy6bulB:X ԝk?^Vzl> ,)8LϔhPݴ:!Eme|vM▚nz11NX}.ґF9@pAɥWM Iy8B/qh-inpyzq6rH"gCGHM8[V5`ISMQ ^†gH''&ot*%zm'6ZJfj0>v7c3$`$;K2e͂>il1! κ4Op=l!ĸv&SXX8aLƆ5NhcBX ҚK5BaL(KĀ ڲEF!=z{i:1] @V1u5sexv z0Xz A<"u z 56D  eH>ROzKB?TV£:oAWegeg Ѻn*y\@/G\l9tƇTaZ[Jz% S&٬'fxH?^4SҝcBO`|k_偓E_ V7fɨx[AW~&?5#"U#X bJթH#sd7swQY0w4 !_2>SG恈`E::>_ _I {($I͑ΰXKc!I[ώ/{4-y1m+&B6ou8(s;|20鵪8vMxlć07y5ųX~ΐy ;Zh_K'Hv?d=)3Dz09yM:$8K@My *IYLllۃX2cUMjn)$QvmY6=}fR~ߚFցP7,9i.ZMuh~HF#2 XϨݞhPHx'Y[􉰔Sh-‰n`l 4fǰkiH"|hF!ƌhr`=YJ=KokPq qq6؞M41J|/pGNj|ΔoӢt@yfV] ګQ5 pavv5ɵ_VIij8opnH4usWL1،`Dn<w'40h#zk nYi/@MX,Egw W[9~ko;7(׫RDII< 9(9qp 2nٖqz"@o{g|7If.@vC1)uh1!ȼ]TT3zrXߦOtVoH@h,Ƨi@3EF׊Y=Cq+&XUGCW&/tG{.QM^ԡ @E9x0PC+l; ya%[>E4䭄12R:Q yn}`ߦl:; ?.kkaaEk+T;3b>6y ֛ŵbr[^{ } @ &PN2^LdIЌ/ĸZ%yQw爷YN!@U;R)$xu vNYTgcFBNaL QN?m H;EIX~ Щ1uM]13-(nhWӔKDB狯nNTMjMgBWQ4c(7]%23~}D//5jfc(z%zF81N%a<=t*QUɑrbmP]_փM*&5ӄwe~k}D[ ޒ8tv`&6b}fkӞ~ܘx=An!r =fߴvaLM0ro#hEyWZ*>ɗehCO {]a)-T^&mbD`ɑllAu\dKnv?=d@ Mz;ku1k[APMvкD)< 2٠:*c-F̿^.b> F4Xz;=8sx&a;D9k%c?q+ ՛ aҕD]yz5NA+: _ nwN9ER_{Y?g)\ʶ:[*FqtZr'*mKS 9%:,ڜD;h&zVY,TsyG|?Bg~LZtpwr/% J'ԗ#(ttif;yr-BCcw<|IoִmeACМ~of6 (DX""O} M ~N!f5#xRPyp_\{UŲaE1R1ad!<-|mlֹYL(걀";DbF4 &`9o]ō%ќ5bJu,Ek&`e\[Xzu\bфR0}!NkAٹaBe$jժN)Y o$=ƞa:_S{kg0FM+CL'nE*lڸ⹂9Óh?,>v!t\>$oNLx.ʙ9%ᕖg9c?sˀ-Do{}qL=C;HZ SUc]p$<^\>o8 (E \JL@aE]S<+>aʂrm{-4b]gWK`jEia:lY/: &:6lb)$~21|Ja]6 &*K2*OBN9S*`B+h,`hi]W~f9M?@ A:}|آ!!V9D6L]塄%]u?2G3E v( 徹K_LEW>S4&R{la=錡f+vo fG7âd+_LnnɃ`o) vKs#2|kG"'&+cQ:L1cط Ż}q  Th"rI&sUtg[ ZJbaKa"wBW =&+hmCN/wqب^RE]KYeօ.㗊{65p1h;Xj634~8lk[])cTF|JsnPDp JwK!(ݮotocN(kڅQ&9E!> LJMeKu j+yDEmrƛc]0o=.EOk1o8^u/I @hkQ)iw<$1hm^ғN)D=eڡWFÔmt]%&-[meՔUŇ`̻) 6GT5 .=qߒ?gh 3|j>vCL%N'T[{$b& ?66;**5@*],u(@atoy<#¶aIiڗ\&5A`Aҡ"L6L$z~W(*鍂Ou@e=]mY;% ׆S"[7i9YHq3@>׳Y;M}(%r]h೵KY 9,_%4̋" IbO1HEd`&9?˂c,dY3Ψ zԉVvZDRRu4!.ޡ{i'֞vyyxhہxOH~O&4p02s࠽+>!HVI6EI%x~؆)6ޚwfzvt\jn@Ew3VoW<*X3ͱ'Ay6|aH'MBI CLCȥ!8rd^cS'^X&B,Q%_.'ӛK,`Tn C-Y$h|p* !rN (F9U1҂aF\*][ޅӓ\j< \.-8D8Chty=m: `Tω!ӰUD`")S3'b^OvFM -!f84nGJ!gHQ-u6{+wY) i9 2 R ԉR'5I+iuv mSa+s8S:!ƍ(OL%퇛Xe'IF2J쪎$)/dw#K5ѝhțҞ.O$\[g"5֖ q8rLDBO]S_B?%} q5dY ԾGӽo&~~.mO$0cumk⮛ʗ;NaJ) UdQڲ4@n=Z^n|6[+mE@D 0oWTZSzBk"şޓ/r &;Sp[5i$"evi.KvD]W%#d=>w Ҷ[!TF@- _(%kreڷU/]v>v1H))6TB){'CeNH$|>iGqw2@nt6Щ1?pl)қ䨻 NzNw$rE϶?C-۠Z1VCyc=p(8LSH_! e&ȟ697Oj!)Ɩ4nRF1np#k!@>Di>B#7/|i[ЭB!@>t6i$ʂkGB|=@܎G o7wzmd-Q^ymi:e@~CA* QhOTg"6su_cc3AFk˞Cm@H(&Za =oc="]V.Pllr\6d+6zRgxw6}8T!M,s7YRq_}UsHrF.Hc`-àg&3? &vY.0QiC%zO >bq6d?2ʁx[O )e G:+1^JW Okan٥!]&ĒHEE^U<f.)o A8Kw CyO%K H+υ1ʛZxHkkj(! ZBkT,Թc27/N6`Mɧrʰ(;x$9^f_Qݽ_vaC%wE0''[7a1VhެA26-c#*FjѸ<{Q4F1Y 2W_0kx^ڑzdP p#9Ktl514:NމcՂ^ qz=A ѩD>Qϒ3UAXЫ)7kOQ؊ 4.߳K[+a),jq&}Yכ>4zb9se Gt1GĠ vEkO2ڝo R;Tb)j#uu鸝'S}LVu:<"ew-.fp tB!t1cnL<>n*U G o[aM#6^Ly|g{84l(l)͊G[m:Nm'?tH+:\g F gl۫+<~`CI#[1YT? $|مF_j۫fnp6PlRDP_-֤A;OQ⇱rezN\Cݤhȗa<3 m [wdT#a\a>gt(TL%ӝkqմ+s*;W,ixb$-W'U^rڹxVr(g~ DZ3\=TX0)̍S6JḄ2!_7pT%cY+;sdx'Gz"=mt{/Az¾jnNg/,ms5dA'%L $ޟ:sNjeIkm2|N0v`teSyI֑+e-]"/,&UoGBJ<֔&cѵp!3c. pV>ymRјҮ(mF}; u1caόtC&A 0#LjzT\Wa\]}P Cn՜20* YOm2SjXeS=a,qHu`Jt/Gͨ%ãJDZ)&bUR:V)ڝ#8]/R0s[p]}?s3&jjYs&B=Є +C J"[~mwQՃk|x'-4||\ė>~h"@\OT`c*$n1|APgo)eKeCWХ=|lpcR/3R#7һV*?Q4{G0+ÐDR$3;QxӃ\`HKk}o*F.H&h;mAdC8!ꐐSLŸ`Ï4w5wC3O$kB}B xWyxq#Av&뉹 p1ڲ-w7EI>֚ci|e!<ˍ/d?u2ފ}}k0 CI%w!HkF[0f7G{AڮZ_" p C _"%/7g )SNЏy)Fn3W8heO PlǜwY>iNJ/@w@|k8p>Z=>"-L1A:RE27(yXk+{JdGK1AroΟʲwPQ7FmpqV5ֶf3!ADJ DfIU}a5*hZ&Š<r?KlЕ=%P];5 =rf XO&z6ꑤ`y5оq'+gǠwB4sƮHyˢ>)ֶG,՚P(-3ӠIO6ʙǐjoK"FTN _ Q hb>ȷҀݱ5~@ rŃ0K5U^7mV"ˈ$3gQ]V og!5^N@>Bb?]d*an*tȱxX(OC0P! {)an~>0U '*%TW!VGO=/OD0[6Sp$dDڋumCd$Sģ]O {J"|8(pt>` 88}w:&&syNй4j5:)7 Z9}m,T4!]6^M=)3SF"Ј[oGՉMHb)IG`gv&0rӵΘӳ27#xB=ƣ8fmː1 œqk7L‚.b s0;x_DE<1UD,f@Lnc`mޠGD?Ħa|EߴԷ I?w62 vy\%z2#hf1Zu0< ow1ZDk2#t5K鴾lUZ\'ҽyqCp|2&;iV Z퀘_ ߧLhenÈ}$ E^Xd+)| t MjrZlJ3!>djDfi6YkC̖OSJ5Lv$]0;멲H/u9<?Ʒ $g)2Wo(?HЛxx7 L٦v`ɪcUe`BA@Ρr,9\?=7/jRȿRD̿%ѿ/n= Q˯"<\Bsw1MJW2I.g *eh2HfmYR;'t{TaL}gXQy)T:H2nyi(盆a١'͠o,5WxPs4`WLh%Dz&( HZ=pCW&}2>reM*5*M*w,\ ('qՎ~Q8cHA\eocm$=D`P 98tMQX#tOc]ƕ ]3N֖7) X3z7#Iי49f5_.̱X~upB"'̶Yy*vZ2">:䳄Ul;m;L_} d2qҧa**hJ lS 7IKI&퀛JtcyvEON-hC 쉓 ~+w{MT6n\*d]keaؼ"fS[ BՓ"L<\s2 8cjeK%{?5UPd/,(.YFqsr y^=;E$H R@? k3?7 $_*;S>뫫( TJ|ONJIE~$_f>$M|Ĥ$79Mك|uJ/bSN֠ޝ>w7s}`D \*yޤ^!3Bb2f  `Sxɐ@{\)3DŵꞞ#er f3unq6|\xd'Tuk. U3gcL~ ηLmxk V8Ɗ_\k/a=K=C-6ӗ&`cmZ*+(;d)קml?gr?W-l%R{=Tlj4m,A8#tݗȻWFIK*9hF?v 1nBm5dgޣlM[j )o݁)eZ$ApA .c l"tqN( +O /mJ+7wTtYw^ = jLOsLMk:X8qHw /Za+ i-40^?@}XFu!ގUжHIҌE뾞]ۓxNkS} (Za jЬE}BtPH/o3ˎ7B ;Pj2Ư߅$"yMd H fYp8@5Ae,<]Z1g5L܂^VS vf2GXEtnҼB0}BIAyj9]^WWYc7ZBۀQd9kӴ`w X1%RhugX|~nnD=/7&cS:O[Yϓ5>Ӱg0f;K=#TYSɜ4IJNZs^JY<boA*S"^?3) WU"z*2C !cGюW ,>7A/S|bދ6{3Qf(еW^K<3&Q(#13rʍ]'e:v~8Uhl^f\iT,26y:ؓpT}Io$rtPkҟ~<@Zrnyc0jmu8^f]z1[Mg7!vR94ЍP7ĜzE&)c4_Iuch֞vMZrʾ۠Ń?}n9+P!m'7kL<@zOeStpS4N4fNƃ}ӺDʢvȐĚJ  =D xogV(9NtCgX1'H"~MGNQh@C Ż&. rl:kدyըd 4ujf_ JC^I5nLOhuիd/)5-RE(&<^e(8hn Hvt|8$B7Q+<0#8-7lIH0;7i XFMd-4hڧ2D@#S c ])5UxZ`X"GVvn׌L(>C#)vE& `66sy1FbDe6p=YUBECFkeg~.AݮYwWtvNGm GQ>kڷJ^WK&ym{;l /]pd;F_< 6X?lvʨbŇA4.deYqڴnE0Pӥ].BQB ^^R(Lͻۊ}_~#̹ӠALiy:kɷzpVJ&.(PBfš#(d~41_v90f{h:O!Xl :Ƕ_~4C|olu7)Wlux#GH O#4Փ/~QIv,輝HF}ٚEa lI2/ЯԂ\)fvLtR6ƣ9Hi1L{ W ^q=CsyN.-[j !:(̽^k+Rjs_ng_Amoi&"ø6q4,5&{4Qǎ͎3P*1yQ<`tT%g ZzY5.b %;xE]ogpЎdAšRJs(å͸c܄]]X=:8B#hU'm9>Oir_/@# &`mAĒsKx JտŊ/1WTd3 ͔9ItB$1I#5OT=I*6BM(r{b|oh5,Y[7AM`ro߉sE:V]ҶlxV _Rq*+.t-ţFK@Ȳ0$:L?}'?[  ۖgKQ.yA8v$eg9"arᬭo!6~ V Fu`QөVZ&Ghqȝց׋xdه 5M#yTM I<0Twk!^}2f~Z5$OL ?*%dYplj:OlǓ/KS3Kp6,ޤQ vKV|PJ5k&"-D41 >{S"N"Pn.lFހLka8\qY:pɚ>>4p9\~h_tSw*udy؄(V sf슍O8h;ٔgRoEoSzQt5 =$1 ء+6r'(WbǮysjb{'' WD;#ɫ JH!"Mޥ9}j5u1'䃖'5/Q]j 0I,k '$1-S.jK~:m#谈@rQ[W؝Ä3ܣ90Fի 4  :aQi3ZTqjS]h朹M֎? /qK&M;1xi6/ z%؟aCpfǧ`!3aagd٬<,} AdkvN38 u銪q1F}>`[FmPRn\nRԬhuT 颶L`JW^Y|fP% *Y>kS0/R1]vԾ,Bֹ^FOSfo?Sk=Ȓ'膒  yۜ4ѝS@Qћ!.00Ou}3j8-_ju5ZĺVd_N!XOfoa?e 2Hs89qC`'T/<ӥV|j4 lL\iH@{[y$un]Ǣ#(P,"3^w-Arfcs'<4Z\!U2M4R/w` m@4li+N̚&H.;2VyQ 8؛X78E'Ym)y+snCF˿%/ݾ:5rgQrg;a=B"Is7aD,mujx7<+ ߸({垛߹Q2d#zxU+S\Ka72Ӱ!<5;K*F2Ur'߶7Q2Y7:f {8G'7$Hz$.~~Al8e8Lo#N~>ɒÒ"+!:Djeg7B_RtF$fp~hyBZoo ;9vb?>9WZ(H뎾_ Z.~uTR}zgռUJm=Rw3ZSʚZZ0ot,8M)BeE&Bײم=0,~d|N/mzOd;4K͸FDd@22S`(!% v M ,¼hLvz LG.wޮZ5\F;!P<2i#3?ߣj{̺ KJuMtF~Y \ c[ziL!#ò6N\pi4m|sPs&?d4ȯ:S89BiSҧC[ZaiƫsSf)H 4 SlatB{~/Jnf.PTgg2,ͳKTttp;'4#cs'j j=;{F̽;;apFyגG8q, ~8 a_}аvLH' ;;l^"ËaGoMggitu߲۽O_wc,. -)ҷSE*$sPǟd8p!=s;P#}|5g3$Sev T M,7@f֢%cnȮiݩXF2Yv탐wJ*kR ƒoj' t@ӮM zNkh" 2Z b:?\43rڛqhC&Y!L;x"Se5~Փ!s:s)g}>,+hIs"]d} #:6Tٺ _|ǘ .y^$܅+ٻ!O1 X G-*nB̥\X[6^gVDs~ƌED!BAoK܅ZFa"DS)E0q*-oF!ɕ/=c*$ravؓ j"K+TC .2peI_(/,˭ uQޒ$H`PF(C!˻})Oq*ٙ?ʨ_g^Tۂ^=„LYc]֩>!xy1/ l}|ocD6:?scꡝ_bE[,f.d7BNMtWIe*Xnb "<$n)A$<ܭ-֜m=1n` 0K} BM_ƊGO=߭ Wߥ@P($-3kC5_ڳ3U`,_W3WIܥ^]AH zӰWXo){׳TbMVHW|Sœѫ 25&Ed:Jjm7Ӊ?E[h3Ťl=E`Ic"Ũ]U#Sa96k\]N&䰢jSL5}NlNJX2-}U֗C(lQy }6qA fd>RKZKxm'!Rڑ, SSܙFM)z^3]86ID$v wY$SR.2–s_\9@䬙+Vf;J+WN4=F)N;#fmaDBgǻҐ#9+x "*@<5EAbAhS䊫suرG~A$ =H„AT#|9K];TIp FZz* Jg~63ϵ"tjUVǒF^rUt :qҴzHPPwZB[$n15ZutP?ͣu$6@>7Wsݟ}{s&vk~wĝoL6@2W@''sϠDXTba=mgyAfc59Y h?s419_5F uzI>B\Ɏq̉WF"pU(oAjRaW] 3 ٜƀ K|) b}+8G.oz,@L@M) *l$fn+`qRZO4 __LBmC>tdkԊUʇƱHp1J(|EEjMv@(% !qR(\ӥgRT~g(n̬3E1GrXs7.T_K:ʾzIYxS#(ֺQkF ̇tPГD9>*2ۡO yFK(ڳUc{Ҩnsnl*խK6~G.gb[%zaƧﺱwff Kj_:ǓX"ӯN[]QºDXHFljRQaCK/f|e. C 4޹+ARmυ6T^6w*"ljݺJM%_>U `8|b*4%26nagp"/ kSΌk|`:'/{JGj@V~'W$r$jmRM]!E~0hpbg3uc _ 7 cO=uL.&=:DĔ Rt #!q65('b $q<0c9+ ZRE H. aAsk$@vvja@zrd_V':9  OL6K B!kO12t;Ғ;fj-4ut~o+U5 *.% 8ɍUƞs ^A^NDiD!.[?3[\ӽJ#}017@ټ|\&I޾ ڸos*  QMzntԹAgYT"myR2+ I;:NM+ n~%tà̊*AD qfc?? C*ba)sKw[`vjڃ=;V8@MБDB挓roZ a9*g^onaORkjS_'{>E| _]~Rn*%Dk#APxxDAFq~Z,HTZm]˻c"\pes}fX)قtڊ5k1JA:4JNO/;@Ajo.pq=FߑQi(ɲM5CCt.%>ӳOքCgDI݄~mפ{A$K/޹i j ځv Mt+#.rʷ`n{= 7B4ҤS<L: 8N"+҃DeT酃sAf1$c,. ;|ol\YdcwE$.r|͙'-JZ4mG(쒣iDٙ;j4!vfӑLO;|VuTnWCzDG$R_ wTI\u7;j@|]h U"d! km Oй`Vu.{.<#Zw1|肋Ghk7>&$1Xz05p?T*Z,O-D!eJBЗiw5́: gǞ"Vgn{tN] KDt`S1ſ7*dJX9]7Quh끈F?PC!/8Q+uq"e{4&p1Cz;}g`mJtM/F+s_Gg$4eo}?ߚWL<~8}GTŢg}X.ZW-KЫ$k'$R/- omL#Mʙ'ZY ؒj  `N7>x9a7Zn}&}yubLVN}7Kdb rv/C jI'l-;lL8uCNPK#Nj]WW njB}',_lgLjjȭ>l?ܖFO5Yⷓ8%"Μٿu>V}k)K{gQ(0Xýp:MIGb4X֛Wq:8jsIuIY cbknZ; :iV7ٗN5[R^iS4n8tb.Wcd4^3pR:吽 xn̆A)gE1 (vS"8eM)m KvIU۝-'ya'|Sr~c!-0$i?őg$jr=`GH~T*íX@M/ =dqV[7IFi o`j\NfyGAkeSՕ)a tx?:|gF_"eg)p\UOO)@sQ֭&J%>d7ɠgKMy(}01$,ќ8ш J_ґjWf!)b)7xzCl˝ ӾZɗvhH|u&d`XNTYGʎF ָl![8f!N}_^`PA5oYcJ^/x>b9 TIe߼eu\Y*tjK]%ՃIxYU9VvWR q.L536cC*6:$=KZx0Y5(2n9ε@BφnB#"-,+ Wt _:KV((L)2˨ё_+NKغw#إ[45%wRdSVVs\f6r Gw"7uKI>ڧH8 ʵ]21\*A@N >daS{,j 5[9C| tgx,9TD`@ /q_}cD"<>s~hqr10Xo Uv%+q*  M>6&$\%iyNlt'j_Djδ\))8!! w2rR[~~eD΂5^Ōţ-wT3걂 N<3=%9!yҽz++?˲k%Sʋl}낅Ƹ|j1t~{D(B{Mng"›iY_,W# N7]n8fC]FOBn8Jb*H 漒/%@j:O%t8'M>N7uwՖ+\YSSdy(#+*e(ו^<{֮fBۉkl4L,c#ԟokQscsbı"YDSIv<]Iړ.%#L)qu53PkŁ3ʜ8*Un:~F^䫱&/1V pCڀ-哬8?$q櫜sf5Ѭ06 ĔZѬRrO,RRea ~vOC&"ˉoE?rP$aebCND@QrixzCcT̀ 5wL@$y3Iq92  f >xKa1=N"iϿt(!&r'W& SĎ_sPY*P!#d&WX9n lS/zY$זǏE5 6ŚϜ}{L{~ˈbء6$YMҤ ͨJE;E@xHnEN[0^9i?0)T?qkfMA?%7+,>׾ϻ KIw;@ٻT{&7߲| 7PЀa-[UnM/oĂ&NOxkA}tmmV?2l?7fCӌ1Zˡ}[BmˠSHG ?$,?cAHvZK6Hۙ;f=޻L#V@W-'NMHAbLC`exӞMNgR<yEUs;D2{^XC݅W{7TMgYWF}T/CˈL=%G}%sERJgV"*M:cLk2Yr$# &xIo='[ Y>FZQ{׷H5^aCp^zJOv=ހ%$lXT23Wi0]d.I(F;J`u. ր 3vXv?eG/e>{w;p)j>,(2 fUW5IXg7I!V }4_ӝ!#2s,PJDq?O+rC==L Y:@wp7ѿ'徕cΈRx ؛ȺĦ)˥s'u'iN5+pֶSR,gyRUIjrjIFgtcQ!ьJ`}O-awA3Ydуb6|h+İ (R`)oӡ+X=54x$ 6s)F,MJh,NBwW_ڇC2]Ď*PyTZbGGJp&YD:L?ޠbaY!/^*I 0I$D@yTXiZvd{zOۀN R^Ooβ&s lg$V?v'dNYQZ:.> SC ^|RmUDjٻx 2'`փ4A*GZ s~*F N]G)EqIr pr>+Zr)/a/eѳ ]- -4B:I!7;<$8xE\Lj&y҉pJ1/ |Lf~lak3봗+M\謁JǞk(JtZ&-󒈡WӚg.BUiGP2V'Qh R,SG?'pF"|A:;Bla'{, kPi B3 8 1$~~5+œYeZaZE'0BWk:YZWZiVgF/=eüK^Z¼ FĞTĊrsr!GROX13@5VUձ _qS Ш ;vcRSv / y@1Cm ([߻ήM6"./ziEoe|+E*D~ <*%̧T_Axc572GޮKx>7 &mOUrLM֪H،u"sxF\neN>Do_W[wl|6b]x RE.Bۑq:yy?G!]8颇!"{S,sG_5ɾ@f(y;C9_وYW*޽47"BI6\ i5bT}eɪw>;`2> SnO&9G7FP'x2]J RLp?u3"K?DGTA̚~Pv{oކ! O1O5"er$,21h(vp?|XY{"J'jC{qi!A^CĿZ8+D Cۃ_[{#v]fӾs[dL2]HAjbk,Dh7ۢj4Izwڟ8:SK8SU:WV,g#g60lԤRưF]d8M$ %4 Rc 8EU/x ޜ%}xsEIӖLG&u~#78.јv,U_m֛ f@]$t`F*.c]uC;6?Kf`X*csNB~;쪰˫i*y`vz+8P& <l.`Y#q4?66Z;BQkكrٻP+ő/3| *Y^Jr/M<0;g?8kWDY= `/`uQ—'jR%r5N,kW1+RNM֫&}s%nǞ = S`Td: Tr#!3|Pت1q ?qٲ&_(Yaciq>w l7ڹN[~h*)Be}T)D,s:E4†)}ܗ߼fadW2'6W޲ݎTZx%Iݩt,Bھw&;xE7T `ȀxxKd#;z~f8^N{ffw``{fT sKGڙXf . N]Մҕ$.Z}Y&js0JRMZ!MgX궭ҽ3\KRo['eS6UmeW^Sظ"BAߞЍ Dy[M @ڎOYLk8' ?s,_+NF)5e:0.]f̱H){4B/2$ tV:1j#68B=-}ρ?6d Z @{L{h⪟&cp U0Ъp6|jzlԢ' /]#~fFKl2ֵ9}C3Ǝ >2~7-84X&KYKƻc8j͡lz/m2Y9)q ԖDd.J3 t, IU&Uo9G"xX;[r\}?«Zy#k}L>uO8'Y14g w[]/oo#Jk \&ͬ 8CJقtfu%;jwx jPӑ(UE_-0 (xe{SJEw}Tk*ѱ]yf* E|HْS5rJ25(TpqHvvA"0>)S sxCMe_ۇ0@vG1U="1G<glRBt]C5.\HUN@C Hf|g`a:/#=rQF>%z\l5f\v| jX?u|ď幄oNC2r|xkWpG;ѕ}Y@2QsױO{I l"6/+;e Yxrţ鋫cL;|X2'7|՟ABT~+T,;۪?S"_`}dmk1QO`I!?Ǻٴ9p:$"qZqp eV0IsMAeSk֠lLYǮaȚַG,[W3줡I M6T@yUZR)iSz6EpMSf?.,`~sX屃pz]QexMlݾW毪aBFgZO>)1MJxU?<z~TeuOƾ6~JL&%<`T_JZq=GF{ TN/s/umV TZ:u3&C1wk\u(::8erձ|4- .0nCG&Q7Px볚xH^{cMGyrO.X gBs桢u?Ymqj'- 5[)U p^?٦.26J^KsތްGm;nYn* •Ų)0} L n vA pgMj\vf~@/rzm7={b~uNj8h Mt)ً=ғ8y3!wYrXS[̝5P,md$ʦ<'#*EOM٩<$I 44emF.@ܦq.&s BKnEF)Yj곺p 9cΠ^'$."e~B y @%Mu07^$Q3(Jd6x3h{Ək:з'WñA{A[8p鸔(L J{bq 4Ơ0C%$,"||^E7dS*`f4uVAxǀ e_eda?{HSZ4`ŵpC2i>,?963zW bRX+70x8ixR +lZWzKk{ϊN7wP3$ ʺ,[!U]щ&]]L|ngy 1,}7y܃_s?P~#݊FuY$JO:S?X$VQ~f!.Ϧ(x*FX*vcB@zȾRs5%D^h Š5d@|O{i)1 W~=L6Uti$—=Ԙq}|APNPQcq jzs\e--nE%a U)LFݟ'xa\Q:''@6l*+3zY "%cꐈE#d.@ilIfhtOT(3H\ <<(8īJ{ qex B 9vהex:<*.fx>M0pqrq @'8YQD:ud:qpxk؂-*^{dzVGk8'>dJCI2D 'stgyqmSv BoiRږ{&DS%=:PI&{?xd &]⼰'7 v*Z5,P1K;wJDI?A>bA95%/e0a_GSpYa!zg X64E 3ud,uzc= H?t4CA^PSUK94ұ î:v:>9Ae=[u:S[r+j}vyjgxDjN%n` GaIW ݚ,*wOh mR?ĒoBdȓQ] m-ؓZ7S5./35? O*%~8G:*[)l6V@*w>LCԮ 9<:u*w~:֔k*bz 2ЙL>E@[eWl}QJ/ -sk1 tY{Е(]c_{6?TIܕ ^F\Vg# < 5rojj]@qOwmbCn8EPeDW>ltzh2]Ѿ7~˂5";\+KM- HuXy%uTK#Of˵YBhM / ]#aSeJ@7*H͌x<Mk{Z&iD+'{i7놿X7!,(2|2ba=d(b/O#1 '5v,ԔS'?Cݠ Ikr㦬ztvU c`i_vJ2ua<_{*a|e;)z~;$S[NK.{ϧLEGU*B}~^CK& ma$NokӝGԋG_T##nÌjW1 9-#.+3j)W#TyuL 5Fף h![*0Ƨ:I ATbỡx8:٣!h$_1;jsv'/xʫf9 ~2d-O:ʮ+6W|-U~G]~d!n%Bhı)wx'sժ&<@h_A_n\~a܂G}V/.>vd+4[jv~q^2T29Qɀ "z*/mgDX|HCs5p. F<{ =8/l]ɢi3Gf*h7 %bQ-{ :]elpAkу,]fIOyl 3 ]Q*ŧC\ئSeo~&RSVzcdjxJXLN} qF~_11ZT`veo{upE5`/U.ʠ] 6Tmsn_%+W}9|\ lA{ʹ+ftϣrًCr2 /Ӡ<'b3JefhhSuOڅl~M_ӆmEbZTY?/`Lu!WAp&F)=  lR?T*VV$8P!N7"!uHՓ]dCSjb|f威@?cϨZUWT,Ժj jI[(ޡ!t,c+"˦H= X?jԈ6Ka\ztl FvYGy!zZ(ێJ E9J&} l ܮH G޷ ["HhE $: -sil0V0\i{S[W*} #͇* &bN4C&2Lz޹!wt %yUsZ`א_ VOE CZ_F5(ؐtJP%*ļӤ* {1Kax4Ml7N\'7[ŧ)6.,j.,hhvU H-2?w.sЧI=ďwpP#2912V'hiFgnCȖxh0l䨣+zFl(3oˮU8yfc m'}x|5UmyЪd( U+1bRʩ5+CTVw*+t(@»]|H;r-x\}CA'p>}05_bUMsWa+)t8CH-vAF*&V%rW ÑCs3G@ #_R G.W1LjAu`yo;,6kyeL rOIkfeo➷^A j^Frvql4_d-Akȓ/s34/=D,<Н/5Ь=6Y|QtN#>o owp?2$g {X_9=a@<ۈOi`N#ZLxW;<-]ZI*_"!91Q!8!09CWS*r/{:1K ѾOYix玲Dcd$(4Z$@gp)E wZlP3%ԡqS>RMv^ PV? 1+"*@T%"NyrqjO9鈝̡>1̎/П\Σm&X[Q=4Ԣ-I./6ٽ;d4ֵ6vӛP#;H^p2 -"֫4QLx!Ը~ 6U@s#x9LէV}o}"wbq/G_/xx5 ȦQ`T'N$S_yׯ_>J g`,.3>)|ThK^h3fXD2qHB^aG4wj3/ $rl;,Q)ssڱ n֭jEɕcU 0!>x*;`EB>-qVfڐm.̃-I0o,9 jAJ)aQKL K}>_s_sauJ 1,;ӕKwTE䂍1;Cs12C\_ vqOB#Jȓ I\=X; <,S>B\7,N0JFZpuEq7jKw%Xyc]|"?"i@5\Le#i="Đ@@DHe=k:^^bl7W 7}joUy=>e1;DQvc AjFt=xid~~%Uqn" hy2/Z3'԰~Mcjnܰ@6aCJ_D[NpY9,yӌaKv4. s\0Ҿ u?Vzn|W KUhŤ6.Ǽ.u6lpKPq*x $F=u~x%Bi^Si7+cKu)Ys/ *i÷Sq-A/Ж#*xZWD;oͪJbxlkµEyC uQU3~J4{Yz7aHUľ4|[ͽJ_~ID*4ⷎZYEN䏁Ii9KuP <^%i B #mY({F$$u-H>]-4Z0"1W*$?آϫ:1] eZ5?Zeg`)jd2+M_=8+);m9@5-3m`m4dYFl٣D!p'1C^!,$F-6bkY3uti:y{/u QX,Q)-v8lIeW~W"įs;^hI+7́zV 5ohr!șjBgY-pG))H&X4.´?I7DysE /|za2.nds>yپJʸ֝1WM h-m*l5JHV ;j&[<XXkVO>'TLz3ok5n\/Js3Hⵯ3[;Vo%+;}?),dr6?ZM.k>P}/R6囼 s&) )$Zo'tJk'F8M{nĪ"eӔTcw x8#wUi/ 22G%؉Nd {OpT8\tAX`)8Dz EtPBCNLajLrͱb~aYpIf ~$BZ:bf3,1q[\ Sl%4R6m4/^OZKEOf11k.Nr^+Bou޸ ۇfOz=O).SFZ8Xe#ptT&o]L9wnU ¨4nf,!qW mANk0Ǒ&$w<, Ne|FL Ԓ;5{:FwJ?67ZCH[L/ vh]uuF6*0f#.[- 9$kA%]] y("H\;u@QpWZ\N).Fgc$ XFyg(%쉚ҝh%VJE*O$:xڥ^ $K:S.Hg5&â~*K;dOw{[R I@%LJ5&Rl݁ D5%wMi0rt83 'ΈL9P U:P*{~iS`ԠL\5+}i92ZU}bvCLC/@{y~cmeW-69eO ZB%a (&:l\r;߅3!{E}@ kXvk4z@á ])eA,bv8\sYuYKB?mʝ sOib+w}UV0y(6%¡eY#H3 n0B#&E!ϒკTr*O[x:b_)y|[x,;yLssu OuY ޥvr1do z _|3oS;o)Qm~vŦy՘* a#*ƎjZg!Nk%)~R:!$hGEf6\ Ii#,;BmM{\y'wÑC!9CKC m Wq=נw {]8v4L\%|:.~5zo7AɯYto&ҥ~Lo_Tq5(dʺ_X٘)4OKa0 dW;2n,Ns`O!}H ):[t j,?6W4mmMrqG5U;2B 쥂$Opa,d;P B#9""p;0YErn_1r~|?ϳ;oc1z p]t9Bܵ "E֘H(׋e|IjCCw悬xBN~Z廒=g~Xhs2<$u)z2XlVHrcc4d3](ê'%1svQ Q7 /yqT9Ĩ Jy wІ T4PϞ_i92ňVo fF] ֬uFũG`Wb7)ٚuWH{#(m _@4n2W'o:]5AyN#ux;6c wؓRmϷ}Ä>'ML)q2*Y T-N^;ekjJCHTK}'tAҫ)v Jb3$]blXwCA\paH2}CmdOv ^3$OFC/)l,z! #v_HΜ"0 {> oyKL^Yu|<^?5zߩ|6:^c䢏4f$%8ttyĦx_<۩\.vrc@|-l[ߌVo%YϪ^-;[1.]k| |}OP7 ^5lP BZG[1hB@eӲy_ٙ۾A vmaZ}Our%VZEՐsdqN'M IW I,z18W7^l+xWv̊j^U ymJn`q*Xf1|I<$|?9$ FVqGӠS_d'>W]6!+IP \-.54'O2 T].N|#Y ; LәO#$=AU8'x/v<8aGZFI۝0." Մ"Ƴ8ć|.g]Ɲa[z 7v?j<fNۄ?;TfV= Y {76+ֶDlž](DYdԚ=)@o:> ,&K{iiʼaEIC,F󂸅mrBI-M^x؜0lƒ/a[@+tzwh\$H)oJdD'[)6gz(}(SNec9/\화p%;}#L]ofFK;IL)O `v {n3.^琚4R`oeȇ̪喖L@]oiDmlvt,ND0 к )H%UXdBTS:Zbc9yKдc{J8W0Jt)[H.䅟<0q?6EpjJ"˛da\Y6| |^rk N }3uVd9S{U(q#녑Iqq]eP & ,w<$ı/:',%ё1 doQ{\D 5 uԫ;.p.GIC,&ЎF  B(uYZۀ='i8y"n*o*{Pw~9A#^#GDhQDQZݢ<6bi Gp̤>.z5jVt" d{% ySʖms싺Cxԃ _8h3 +'#Iu?N"{ DFKbR nz] s;#⇒1&ĶS Mg75tJc"<3_Oǭ S3kιw+ʔtUvc~vhI:7n}6PS:f==ͤe#og cCH0Yr +BN|[~;,fߪ} eY -WVVz"/hV`^;618E⾪;mhV~vo@÷48Qk?RFVSu"`˿vD5 w&(LB~*4s|:=c%i. vl 3JcWx^F=&'p\AWobE+Tm5ۺNKu9.=-ֵ}“*NJݰ^ :rQ-U:XIit3D!a\P)O!2L &={ؔ9Qʩ4a!__3Ԟ~T>,Cl}؉2r268k!,9Hk@Kx?Ykl-LH.'kN2 %U]DY |D/ _(wši[reMZd* = %axHc>u¸]gx!Rvgq ~R!%hIb8JZK>Xp"`,$*]||PZkq<%YthW.pԃtsU84 ʷ7Yu @PCV&!Zx4>Oqഠ;D1<mY\GtI$28EF?O̳-x\i.ϫ.ǎN(n?ki ߖ3ZGE}|#o9q 0k^3jJFDjNOLC/zU9#E2\u@JR9;WDIJ\m^- gu$]3iDilښRA?ŵ&]u;7,$ɏ VS3S\:$H8󘰧!䯶̏o2-~ed *h|xJ6,UٙӟvLe*D!© &TDދ|앃sT{qzaT5 ɧuI^@VbJ],rvY_(тeGq[xü>0^rH1L]<, #FUiߛv\Dq| `}yƒZ3p%'0/1U?Y/iThP{T8&*O7]aٛ cڔZOc} Mp z=1QT6hDy0헐+zٝC6j4)?RA,U`C'MZVUET')O(CH۳n+2LܔЧUs [p8Ț\80rjhnbA ,҉yjRN󂯪j-͞节1Cu _OfuGZK\@N/][k/T jyH#h4 Ex4]x;[JW=".KccB; ƭBDDAz>B ,{.$@`|;6|^8fZ247 '2ُTe8o&Ԅ".=\ -g.Ssw rDcp*}`aX#K7;d#i<~NfYHkc.U{r+4~{Im$HsFKqcHYp@MM@%xYʡ9i1躿<\ijz6M fz 5BM;6yI@W8mɵֿxݎI5%*mGm8P{lǰ5S~"IXJE[pR1^3<<e9 rY)R*Ұ`f~,)^L'! sul.BR(UڄA+VfMAQot2ݒ9cMa{dxJ.Unvh0F+l :q.Ɉ4x/ O cStiv;Q$ye1@`F!K͔>CMn1A ayw/Zp9vso.k7Hd!"Y9.;<3RJ򥪰 <(O數%Ectx^IqS{/3-@9ïnc?:XS88\lG5С\OǴ>%t0hT.{~`5m&!=1GW?7td3s,Xne5lp`ʬ'p0Q2BBP#ɽ+fjصT0mo=˾Mx5ru:l|xO%l>)T%)jO䰆QSq#-9&S?`Ioϡumf]Sgm&}gXC)9^a辋)9fjO!uUc\+B^P×ӛV#"̣f[EJ,[Bs(}v[5?xbdkmw9lF"~Bެ} ˆ"ՒFRЫH9@n@\m]RbB9lA![>aTp*7%?%"uԈtqp9IlpH$ˡn&Pv<yT08HErHZmx,HR/}u%_ e'[#NKev(BzǕw⁠T.%cj(7W\tox5JP|Hiy֮7 ˛UNa&iɫƹ !di] `K۬@u=T FCx-o&uw@d!][`LJDkT@aoEI KoX܍x&b/ kE_вjtQp&'K_e\,ϼ@ˁ8$B$CUvJ[ [;_E)9'iuD'&6 Pwk˝T N$|&~XnM>Kp ͣJ1p dyr.s :Gw/f4 [dZRj^.IHQ.neɸz05.jOk?T۰N2L{̙VW`Dm@6 w,nyQq|#Y(b 옺8B7t*/\%$_NA@Azc: csO&B!496~՘[ZRQg}]}}ZnIwW1'fզUNHQ\ɿL5BLI~% `)q ]vplB!d)ץ%xIK4y @Ƅށc) ' ߴD{emPyARL"R4Q{ԴL&B0t0@?LؒNKz*n=nkS@'vjfE'(QkWATMϨ zjQ-SzE)M\Fcv<5DEcBgj[n4?)*3rkd\[7&r 0Fg+FҬk!S'bK!RSGv!My(LfI-M=nO*?}|k"\ozW&wQhzQ$Ѭ9^B: h@1t)A٧.gO3 Uc6AVwO6Vfѳm3T-;` l)܄cS.btdK68D#Gj]Ddviz!+T.j6z"{oϵP+u6njz0佚Kں\? P"f)7 1h-3U`) )_ҹmاcnTz/d9._ v2P)\cc匕͒>2~.i8lvewnkᓻO5H-2r"@%^}oRm!ϑBQeI39rìHgR.?Hen(BLD;Js M Qʓ< \~Nl-, Ѹob9t& vSӞ@JW`"3@Q AA`ЗI+Ȟ{JVE+?.=O6jqy`w!j :2wګ'O "kPfI\3whṄ/#PTFWAMBg 쀽e/>Vǟb-@0ތ`M=vN{I:kX4*;j_X@jW&3_te*8ZRZC_w< \$LdgK<랄7 7b) T{V_` -hr>n^W;0PhJ):u;o0&@J}_Cr$Q5[ 3yS `<,$ ZP״\pr+#:ZRp.e,! ?vds}(?ƾ}WW2OCbMqL >4?"TtbB[MxR)IQ򊚈aNc3q~bּ/j]LR/ 7h If s*ftM"~/L)w' }%MI_,{|ln縫R5I37HA< yL*S1_|?Ɍӓ>s.q 6>OR1ٙkjb |W4mC}UxE!T!f&(#BR o?%p>#0CI1!}hW}n텸rl~GAo֚#MXE`M &(7b>{о,tw:yg9@1-u| bghgkǯʥ@_5eQB% ꠅ^t +wT6#q0O96UqnSU6n"(&v-w2O2䶮#e~|wނAҒZ~ٳG w}TMB.z›1F"6[Jşx?)MSezia4ݔG91A.ש6,ԁ^Gxt|s|,f{ӚoܹLVl - wTm\ ;)ݿ Ұy06lF.j}{.jK=B7-oUKV[IؙQvo mO6aETaP~kìF!˂,BrWDt1HNOabR50joݴ9xp1gĜ'~Q?lѧjH)JbNTW(kC6>,A%7,R.\`mPXqޡv4 wl lt)@Uh竬xBRVǹ}1*GǩWuut3aECL ֲ![S^:@ c\L{7R] /,3\u{5_,hjfcZ/jǍ`PEw(z/R6UǨJ} 8F63ܿ'\MKx!mm94&=6I͍"Ti&J  'GU!cHjԙ'!DnYagCK&e3x/?gGIuٲ@ZBC¼F!|Kp4.l}ڒ噼 ]v w&qu 㞭.ڷm/#y1 C2":N\ϟ#eOd4o =]7{~WnuWUZ.>0YDMgFL, >4`.NFlFvEʁ/5FoQ%eUTسkS$ƳFq3x hў=QYgO :aitYݮt˴ +:&4iQ8]/'dŝ7Eoj'}Uaj!I (6Xy&!|ud>:ƕr)? 럏c9 aDwѤB0?N[b9{Quȼ4+CIZۑGrAM;v^чUsu~,1۲.p$s!T:+x66!E h7K@1Щ!dvuSx)`!I>g[v[ 7GΨȉ H@SytԈ[4 q_E`"M !tQ90Y[ QbG |7Mϕj0i#X?/{4 a,nu|:yn˥d'vdaR-Ek &6ph: 6" ^BtrMOoP~a .z\(5YӤ=l!l~~<XF]H]'|(cmq!ͬUx}w=x_K ̪ڷ2LÁ<\|vhsf^KmF/7u{fk?!jCRIb|fى&Xa6Ppʝ;(#BͽEʲSVx'Z? uzu$W3$6Z;R34$ cN%i>C!`,%5$,6!24 /*愂(6Imo zt37 F !W@a&0RņzϐV-U%<Y]hA3m'؝S@'S3f832Ȫ 2jm8%l/y:\kQUS*b-sk0iՐ^m|v ]M8vwvY :| %J6^ߊ-^;BjoQ 헷)w6VҭQޏyZ!UfŹB"C׊t㗱eKBW?Ski-dp(`FȔ~XmuT۰%!s.]qj{kV\3cΖ g ZlEa)/gydPIz[H;{ƽO9N<}Ro?uy!Cm-똺J%0AKBAoVʴ70lOf=요mom1f0sɤjlh~(tp<%I/nd%n_Ag+.֊o -/ XcB=PɅu12a}Q6pP?\hѾKe_M!/ZHϭ8@)BIz%7_lv3=>vv9y,0$R ^`[ϭ$ c۟:B)K>,a:4r:oLtљ sSG{H>-^iWUzy:;4uq\^b`woksE3k)Z3<=h9~/ۉLɈ!'eLGS!& . EaM^OP'~55Մ V~a)8,3C#2W[{P)sozd=3=")(ߏPYԺ'kI䉔v~I~֣)+ qu\$WȀV)UeTMĔ D7gKWUF XY*+k"&ƿ!W"wRRBZ)42/ p B44سzAiqDSa`g2%&U+3?߄MP_3MHCT Ks¿^@Aul^AE ؙaD@7zsߪ?2 42v4S{B[B@ i蝣ya{hO ȉ!~WB )'taA1liWfd k5e(b>$kxزqmCHg+mBDSėGܘ'H&-!. ~k0kIHf\16J I];12.kb.qHk;͜:)FG/l$^Vc@u\!:P#fMM,Jד ia-c<mȴ"Vɳ*1P lG 9Nt!e}򇴇S-gnq7*A nd4ixfdjs/NQ:q>?P`LLx!w]dDcF'Vh-Io<$ZtF@q8#Vec]Lѽ{ck5ZiUcaa5kh9@059RaӢ⼎D$|F&'-לKy6lnuK4Kskf]ݨgM&^,Lra3m79Lrj$L<`xV. @jk k5дV'=l*E;1NYAӗ9XusRuFQ {"l/8N3$'$I<ւ@;fZ1bŜ(8#y}A(%}O⋊t ׄnVgKzKm'8jL^ i{;hXޝʩE_cZ*UdCnmj9p~qy91;UnLå}Ss\ed$oI͈&!lX鴫$'OXBG23&QXL.p!\&kaeCM&$uqLUήqT 1UՔ5e l| k{#[7v{T.BnP&?MxAJ+k?N^St:0*  >vK1KcVy:)/ҝ(=Dg P͗u޼ 4;@B\B(S9v!'űVj1 m2aHmfA\9FEbqFd/Nzs<NHa#ɦO{, &3cs0k"?*7[tNm'}=g8M׻1'"(1C8gJ ݢ߂ӓ_6OSȚʠ1vkETLUGbGיɱq6\O18st-T3ރR ,-ӣx^fM`pLdNeNe&[V vvŲ\F˨x7iB'fs1" L؞vؓRtc-Edz,a}Sѽ\tVZ^,[5=cU)ԫg >lHZ챾Dmm`\ɢeawERQiT01a3/ ywzѝ>lNO'UDN ٷ ͕S)J[O|= hYhǁYd_tJZH՗n1Ҋ"DSӱo?6ܽӱQ9a#{bY>>ki_n<1wr܌|D䙫4C$L.}bG8z+JF򽙱$~vR2)@u1ڃА`ٓכc  1a_v Gs;ۨĮ$~yF{-xlNgy6T}rWHWj|!G" &(֭Tm2C_pe:gck8lnf(gY6Kz$nP'W_ I>5]dPBI6wu rv.|_+ ϝC5J´:eFA~ ҈bn$ pH7]}|RvA+v9][;/WAOҢHg5)6:zW,M#^0 UD\ZȾGi21F) ?h+MJI4P}BM 9l˿V|MID] `4[(j,oET~ѮdɑrUB"a-$]SW78Ҙݬs)wur%MzWvVPSD5;G2Phd+fh'oM#seL,ljp4In(!,!uw݆:`@3<֍t rU i?r  :涗Zqd1z2Q+c;Xvu) Qd2z[J;:hvUf'6>+#~ 9Q}{gavuT"eE);G- gsn KOD")H;qXYyDȼ&˪4f$ Ǜ3b!*doIKta' D+S .|ߢ̸[%.'9{ 󠆇K㔄#^TB>(pilD biS~oV&.Tk ![᪙#L4͋hQS L5tʻ<1n;vs%t9qB* ;O*%fQ9H?+PbyQ=08[dϹAw73~ok>~d#7v[8 -hĭ֟o _Khe\\s"JqJR䘳@vF?@Naد*oiW!g͸Ūp':@JuW*06Z|]-u2[!bI󘘭8/떊#FQPtIT}TҘeʖS^3ODC%O<@oƞDR~SgӤ_j"jΙ,b3O#zW#xČ1 t^qP0iU*jJ%AA i2TՀ;H8^/39RU>{5xʋ!m%*_Q{,hb!P{TO\=0 >sLxSWf ~*)o /X rĆ ayTJ.LR$vJ@ueW"c,.n 15G"͓w0W7AX}T}C4:n^ЀP&T4A:@*&5>ia9Mer2B͆7,̀>;$O'˅s)o V^JO]0ZOqµ#ߗ meRlwc.2d=aӇAz`6(lpCW1`"p[jkaS]`6/Ӯ)Bl]4-,DN*~ TV |r^l~(晅kF'ӯcW|,Na6ToԕfyqxC j(,!ѓd\:0a؄#Qdd:A /?mDZe FآYͷMVb,esTw|Bvpu>Arʕf3;'&y`;ʀJ&ќҥ4GTDk/L8tWrGmPW2hM4UdNgǡC_GSVo~{ w1k8pM$F\O# @TFFzxuK6&F`=N H3wZ=o8Ҷ tv^U̧KO}QXq?OrM1TB"*_,OA5O }BH<(6$HQr/g33mQQ#H,Y{]D5Tk")>8ɞOYX 1NOOVd ߣ_ww.+Sekޓ&har7YpHT俲Z`4^MfEjco}-.t5WϚ f$ Xopvʦd3!,ۢ [مSTfq:k gwʄAjοRY(EwˇS& `jBLVq[ 7f_.Ƒk7$,ȏCQ Ѣq68^9zB|a; 5pņ|1̗W"ļ2k=.23A \UݰziOnͤoon0[dYZ}]EПowjihxNn݁eXOnSl%.xbQtD fzW8<+Go9 ߃vC3 \_#ϯSn'JܙM,-x$n 5 5V8jSR܊B҇W4O߲c7-{WLEP'Cyk@܃*ʵCU-H adN2M{3<$r]JכPW^KD>=m*x [(L Lt _FZI:TӤk ' !("dZ°bf\l?db4-9&}eO~a$G&!Í3E npҥ gR@A2Ir5@.J$9ĠF+\VJ~,"F2@vҫDl9M7bEJ5]}6(A%#e^v ʺf^F"o;^ Q殩_E&0H56qbRDHlhtC _K۰Lbfx&B``D(KktԖ_lK|񺫴)FN*u{E*sjN6ڷ ps(2)!hF[> 8ۺ-(fIi ꞎe4fWZm10 ".%q'K؁[E,P*_PeW'sVGuz]GpL9| ipI/&yQ\&=ﶚh<>ôaD7,9˻RW5_R W>F)jS)N( >0JoZIߠkNA \zEWRpOVlɩ&X$6,8?Gv ˸uet=9DEZ. }GwW^R*>t$5lV3<5gak $H>yCtn+doV<;^$o`gVsåEV*()3d=j㴟Hk*̓ MW+tg;YH8U3U(u[{.IuH5?7T{[lyU ]-ɟ҃x-X$ 0K9L~n%兹isN C֟sf9Ù  x8}GpбJ:n.)0I-D,n ~ijefW YYeVc[zt' ,[~lر)4-gC6nTG_(Py=iC8PN3-$ \W"\a=D#ȋ@ӊߕQq櫫`Qkw>P݈W4]f&ۨؤ`Iq, =:~d%q6ЋpU@Ɵ!ޮ}ͥVϫaZWE!zy}8)gզi#x%R„LM~ojUz9xxf>QO(wH.ޕ4+zfC$WWgCMI%C%F'|$#zW %l"mM<<[Sհ=_jM^c5`hy+-3l0DZ4."1QZy1-#>3 K\2#I٣b揬}}a^8T])qd܀6*7I pY""AGlopnҸMٶ35R49/DhFZH5e(aDEA{7۷x׹dqZ.4PB>WA8\]2ªo0h1yZe~(QWn)A3>K עun[j-c0i;0z34Jn5y!6?a+R~X wapb@\pم7' زI8BBTi?UgEu2&H&O5-J+mg=U1 %R2KMͯ KĘ^J?wޅOP ku;'c3dfpbx瘬Ūe)kIz1CӋT{ĕ^4^s9 )T#V%[T'=gfp %g@ Bb^Pt  2NEi+ťy$KlTZ-}vZj)ƬP-jy"^KM}UV(sJ ~*e-{H1Vq:5ŝ?CMR1xT~=ϣQQ&X.ˏlVs؅xNAk}2ku8z/nx:L5+s6'&aU|j夞i$] yJC^hVDbhBTsF#qf*Sϩ*\_I9GRdfB/q-4"\uE|\r-F;IqD\e9n"Y9!)2Ϝppy'M_[SUyktw>e$)=?bc3LX 'L΍[qm'|B=|駞b[,CȦ4Dp QK;`0# -ʟeB12}1d{ijM>apr?9Ҽ[>]8̿80渤m@Ϗu!U"4V&lxȤS+Da~▮WPQ Wݾ_ .v0GLjtpɧG$Ӟw0G0ܦ9Ѩeh`A =wx $ 0ȷZGLJ#Up~ X]鵿f9!SX ~ -I1'Tz<  dusp@ ՠ4S31D{6qv_7&2xE;])vB1fiȓ}|gx"{EpU Ɓ)#/l{V%68 r54 )Ұm1+4M *d47_hStu{B!g= p$C*^ڵZx[/"]5DMo$d( 6(O o qRGҕմQ룯 sJA uT:W:鴛tҞp7_4ب m.:n9-"9+(_ʠ?^dQˈx̊2rwp>Ac^d@/@/'x(ˌp5v?iho?x:E~$Oijhnrv55us~H8״яcR`AQ dm1hʺաaѽGNÝ~_!\e;n t?]K,d"~#廊v@tX6Y.Mg9;^!Wr⑉$rFHWa+gIө<덦iЖ4,Q8K.RZtDgȹS]A뉀^s%D&[fD}| %i PT\5Eŗ^X,̃-hϞ(@eUу@Uy GZrdc釰N_= I{^Ұy Q$,QJ+S6dq" p½x[d:rr|fV P3xҤ=Qz-t[?:WB,?mgT;`$Z[M~9Q:e?tBVԇӑK;` J֖e8hlW]%F U?"?>j)™a%#Ꞑϙ]qKg[gޤԵұ?Y54?NkǩQ&t@/eI|(z/_w(}|ۿz53{h,3_JaF }GK6{v}_5= b(~KY%Y`Jdݻ 2K)֔}A#C*OZտ ׍%qM7Ms6.%,bel  0_P8|mz 64>`ξw@80W1vf qhi ǝZ^rq4B_~;٩"pJ1be E@o8)ós5dԏ 8HL'õz m 6Ӧ4)fItu<1$CH̱Z@k%(ΐ9`w^HY.a& /~9bEz? ?RP{p9oK=|e.c0aehAkN>i'U[@o+Đ{$u]Pk,ֲ$U# ‚TJeI5@y 5-!Ean6Pۂۇa'#>:zO=fE(dFa߄(L9@ :XvB+kϤJ,dsyص9D0k^VQV>o\sie',Μb_r̲V%Yc/AQ4A&4irU6{ʇ5|ƩEmh:l9xŪҘ t]IAZs,ic;U/*L[v鲻AѶ#Ē H r䣴l0\m:`F "\َwRІ<-(gdΧ+КC0ܕ=tFS]تǼ$C8 SqJ?H8ӭTM焞Uަ=b(~p9ͯ[,Y(sgh!_K/u\M MxW9IJ2֠-Oi x},o}ә5Hk{ E-j4;[wGch2Es4]9޽)xYuiSOũ 02:1 g: Z^V3OEx YQWE0V2.>d,ǣ$ ؚCY=YȬ:e"? 7`@۵"8QVW3R I. >ub:P 4O^E]quf1J |+_:ArHG,,_xg s3Ӊ b:=>wɓ7r¡~5 ˧xz&Ay.煽8b AяfP/odyUnƌpw?x!.Hƞ9hzkr䖴|Vχ ,XDz }/ᰱ$g# ʽ2>LI_ɭFA PfW le_KN|egn($Wo|WڶP6G]ôVPh=W!: ewO X,nHKiw74%ƗAHu-t?LƱr\N 8Gkń]Mʤ ǾGVDt@":)MɽYR3; uѱ~SY@΀4Iٻܧj뚦NWIaR5U4憜X>:2f;oGKQt2G"}A.{u#C܏Hy]u DN.]=}$OѼs1`62'MuIL4R^Ғ?Խ:k1fZ.N"hZQ5 n" Z ,%ig,P9 ^g227|a [=2z߆y$ (˜Y*؏z8tv'-`Ɂ;](߯8˔I~HՇmϯ7˝AMDc ޼m&meD͑Zr#yA=0T|Ij*cU^/bQ$5"=d! 5`@+ƸOz(.^$U{3'}Iה ܑqY$dV$>2|ڣj 4<1gvJkNӀO}% rEa |k301,kB,pjskF$ U"S\VjMd[kV)@˭E-"ΣH$3 ˞%یg٥k&EP-+#K',ٰU =bynF!<|RAoluaxZ3Ki?-lMFZaq\B7He99$V ~aoVI+ZÝ`Z왂fmh󏠵Mld ۓe*f V7XKSNAb9czL(ǘ.EēX&jUj05vNQoUSozp0E#_~:j[9!zŏ?ߧ:{w [NmiQoѨY(7}r ٦١a,txё )ԧĶw5.^o>ş5[8.q&?9l4<վnAN&wl 4GNWŕ]vwVkvۚ{L5Os|5b ɋFkLU-;|Nuw|BOb!(3V_<}Bh5vҞzۏ_Tc̯7j l|-!<p 7N8;;>`-03͝8*WmTL-bȷK7OyEeǁFX}[)W'Qτ0 FbZ: 9:;`%|Դs-^oF{< cCG0gn q.{q*^W!P# ʺC -^`\t~ek`h's0R$ PJ N  _$#2: e{:Urek>!6Gx\X{p4K.W&6l0[.^kU߫viELYGxѮUSJ5ͥDatpJ\<2-FuE=?gz ֧wz4Qtu!gbshhKܠ5g::҉ES6. ?ge#KUuǡڌt2萘Ps M x 7$R]%4z$]iU1$qsHY 3%-Z$}v?jx]U%"2OxIK4k+eOCSR F8e< 6_C*x9@)ECx!a\ԃjfۺN Yb-9$fZ Id[d2Qقې2KcJ6T^u-#=YiOœ۰ѿEW:<(^]qeU>rL ߏ P 3A)rE4}Y"]~ >`~ π bV\7F.$6b:[; >2p W5 0aJ{m"/_u\AnR{Eɀ:̐(a,]fz+I ڐ|mhUv-?Tt} c0Į`79׾L=?TP 4AeqR~( BЁ;w0h 9HD#ȡHO`2=,y ZdxPk:[Lc]5M8M#\j"/eu;IG V3Mf#X(,}v)umTd(uosz dhmbH`$G N[/w&-]9]6:mTʳ]y;bzȐeU 罜F:7_+(A]΀I,,X#O8\ABQu8svr :Wzb@x:j>Qq )P.ٱ.[Q S5ÿf܄@YLB儬gm5 ?KG 7v2ǗJ_N}$mo^T^Wæa^&U?y@;K B{vN^'J]Sln݃\_%K$z͗y{FǝT`o~aM{0|O2){q9)/b˹PJ=>.ws|b\ ɳ" Ў^z)-#)$j'mAKN VK֠zbEmw OF] zH# e&^0Ϸ+Ա; XOSV{,!yVw5/;϶Ug/m Jp=8 -8`I,M(vq'&tc2o5&+!e|A'6_drJh3< }LL3YАF MlIRJi5JnJygQxڗg~\K%qƆ󈞲6٭l(71_5TiD|޺Ŝ {og my&|?Ӳ^aARE"ehd96Cnw}IJqlӈO"*-U}2xЅKN fMX; >eLRlT<#Yk +47CseM?!rh2׼=uJBn/hSKT׻_8A@]!.%^4)R~MF([71 aylrc!Y6V ǽ cs62>֌z'<sp8yЙ<YN.< bB$BFxun:AF)LTw]3=_C-yeԿvLr1ipP(I6'it<V&*0|zaWBzx_$0@i}F' ywo<Į+`@MۼgwYuwe5sOb<@mM T6!?H&^͊&dʲ֔St/&]5EzoiyEL+ic*n\ k&A[*0@x,}|҄l]p6&,'@LHz囀+ܘ @,/f- .+P' ޭ[$&\~0DChERbyK+Ij@[',RВx$?>@NۂQ销pIZ7Iaʮo%nӫ %: =ƘNIրIT/$S%ON,떍K rRil7;^1_83͘d;kln#_?)pX/OژC&:ߟ9@%*xmѬcbز Wk~2ϟwwYdK_Ж. `ˊz"uF)'v'hiA6J k;hD\E>j3_ۯi6}!e~kQ^5Y&mpOR{*jiQq~qwE!LоiQ2j`vyEE{UmΨ`W)(]˗Qƕj6(q.Ջxc^! a՜K?HCrjmڛFr傸FQ2bMErǮ>sWDgycϛqKbwxJ?˾rRpU ce$1\*w Ngk.&7퀇0s$89oF"ppxanN4 Ku(x?F9s˞w`9ЍzSwyS]t-&j#Oo ;X HSx v#+I ջoDPiř7&uTYtg =y+$%,ㄯ2̬e qDK^L=K{ {[i'R8/|2E[<Ve,ř3Q٫6K2[zU-V=>lOvE.NSvdhħts_̛@"&jkʾk| {%7˗k,JJЬ _r0ßtG`.vy)>҇)=~IXI mǥ ׵Z 4SR[ix6SPīQ* \,}~#5ܙ;obuYJU{tuGxGrѼ 9l-4 Ym,^h[0CNq&hQ!M_!oۢ7&VTi!p)vLZ[N$apBoBN>ϥ"$·h S[i@IqWN&X 1imt*?vK>dOȖ1rǚ I97mPHBqKRwV0. Y(pmęMhN#U~f`{Eزɱ!*2,5~Wcy~_4WeΟsu8)t\ m[Ffm̢H|KUUHSZ]uc HSŬڍ:yڗ'{\h\.p 'KP-ɤYV^)fMс~"Vg1ߴXH_kєb ;ޮ_N~B<ʔ)^tݚ͌hD-R{'kPχ"hj=ѧ!rHpSV?7M?&%O':L Xh)7X6;/Εg QT3~&gA]AySlry k؋?a-9~AVS ,$ ,en}׸&Y\8Q>V9B4&Ӕhgb ́HtŬ!7;,H\uܟ0++cHlJ@}7_Z?Ft\ R!p&_ 6H A~%p[+w>{#=S`WpmOBd5Q8ALn$ݠb+yы]5eTun# ڨ^ٷd5y!:BK4,뛣L <͊xeeG&ʹ=c!2E`JOYO34T|tUM7zyG:cd(\o!RV(˸͓ض`T?ˠw>`XO4~5J@Bޫ5eh}:@SeVG0H)P kVj;PNtvπy4*]8(v*ԌAȌjb$,A|#rl$ۓ/J'^,(cC|)"d2aظKҹi݊_`|y1}Y#qE8IdQF0":^#NXU+ەq}萡rޯӬoCDAg5VD2~7gʺ,(D3ޠҚ+IGvx<8V QDBQ^p JjX&W4hg!Tp~9l̰$AaiL23wUta+J2.HmǻrX߇k,(8왩BN]b ) 3AQwȿ^RTy>36+ ~xDW0Sy|dA{ 6&͵#ۡyerLpav\_U@MQd-z?N1S̨;` };d?:1̥Fv>CG)Ʈ⠘{7&Kyt~ƻ[kwZT&X3dL}npt^FR}X{ZOQ%hU 7 3lY<%A5jd{R{ly`nK&8("N= ˢ0-+^Y:Q~Ba΁S,l)mN]'I_6^,& m2j!,5^Q|-ԈҎXMUIL) .B"N=r09G  ]rcg$Bk.G;쏊rRȄјε?h=%p6 3=j;u"dlv}(-5v6*';8`;X|R![1Eź,`-KG`3 (5aQxɳy!bl \U7h3FR $d*9.J|!%|WJbyl՟uL3y]chf _%LkvN0g*6[$/@5qì\ AccsZ{@.'qz-TpG֐pÔ۬SXpD.Nf멏&7?;Er$wQ _DEs9Gw 놑l4P\~{tYC(GBUmi:jcJ:cMMҋ%m ־̯nioFoe% HRDew.5&δeЈdŏxYB`|1hE=YjV ߮ zTYٟ r0 C1 }WsRX(PiI13u96KĆOfe#xCǤ,R$DxEt4;.{ȈXvhVfK˔7%y/Dž,) UxC ?A3^/>:aӔ(РLz)'}ɀayꓙE})|\n$IW Ol[ɡcqA;Kb[)flbsl^lF*;~C<]% ɡ6HI{[<@= rhKsMG,i5(JI0yQafu:oyPȁ ykGw!׺``׈sSG_$-ەF¾ eG/ cz'hBQ9GySdQP54~~UF#PLLYy{@j{GjW%9ۗ?FHpg牊[xYb4d k-tS_o5k b2iQ\q 3[DmvU6cj:,FRjAsu fOHWPr})h wnY>' S3dQb}+RYI#_4^/HoxNgp3Cl!Xmd0{>W(ހ+u\j?eZ*wނ<`N~&_$ڊs5ֿeS)@u_~߮Y4D.3W8%e[rU$o/2?wS&3ܙmaPVylDž`+ _X\ƻ%RϏq4. FwbX;^j(b&Ikܓtt%\Ґ2=}D bRp $v QeO'j{U !4?.3*o4 ޭ㙢`ow(DFA ^3@ؚܰ]{ؔPr Nk 9<9AZ7HT}wu&UB?EQ*&'ϹH03zԦӇt2˿Q s CJcQ HWF_wͽ#[հ(˜0'T]Z<6lT40O*%U^;MXcKtK-%5P-CyKDm%ԦEQaƴ NrbfrLA.[t b&rZdR,Cc-7LY9{\/YD[IAb/#jP)c c{UXwdW@NqȾ4{(Q@=}?CJ490WM;F$#]J2}n$M ^c(N9@#Nh[mV۵ 3׎9]W m+c !>W9AaT, P6󮥉t#@c`|§/=KF%]uc ׌>tˋi |(ġ(pB_@gr@tq|Lbsnc tJh詞*%nc}//c 5&-c]Z V8LKyO.Pn_[ n h-HL/ty+aIJ#R6_|J&\@`?CM%kex;*n:cb6/>TCXjA!gVeP iˤ*s~~˟z*u[E~ZIrO?ozPPP Q.[21kJ]|j2ؠD|O c"(uD]g'6RTP{{$-0- v*e$hZV'2;ԌRx,OO  C wL;7y9F5EZlԽmgɺ(Aci[Š)ny}Jq 2n D ɫxmD;_Ѱlod$_RNGCl[9=/,- 2M ·YǺE7>1S4sk/M*ԬV Z̯Z? foAJ}+Rg(L*:M# n 2椑? aepf4VdlX1>6iaT(u%c~2@e7+&vM?Ao;->Ml~)Lȁ({zۏLK~zqp1;iӆƤ(CGT"姎QBf)ռlg.@ vB+agshҹpc`4/yh\n 1LԸϔ:`l<ژ(f[1ů*E4c֏Ϛ2$ߞF)YKs>| 𻐼юwsQhmOCg1YH-7X.!_CPM;׶hU>t;'!V)yGeyT DtBniNub &#Uh[p؏us*OkK$f M ru-Va̍L,}[]K lqZx/<6G|EiTܐ*f8۬Q$y)A{ؿ$; fO\'Y67\3 OuC &:B?d[ "IhVݿHk&c}iݓD}n\1 3uTI4kLE]!a}'=ߋjךN%.,YsƋw둆lt : U kZ.sQ(FہYV&aD 0Dԣ3\? {pTzgiؚpoJ?+b5w|r7DHwJᾉ,v<@u)R}(~XQ&-mMt:[bX`ƃP="lJ+7#~v8.y[GvX88uj@ǭir]m2yK# :R<=F#F6j/O-Hgsko] &j9'2*%̣gߋ U&U,+mlv6P<Ǔ|{AMk@q04۩mo:WHNiڍ+]_1B&8O-9*78gi$}.XY=k8W4m~Q袿B{|8e_O!vmcۅ}[#9F;%QCTMVk!$QG$dZ%gOk]@qOA$FywFN63W4ּެ >u/"HgLYP${ ԨiO@7*$?F`( 9StAbLop_zt7Dd"~05NWOPaX rK" !k᜹<کAs1óf/k$:$ @& ^x]1,?,)RGQJAG3#}a=˜6~)xO|/B1je9!m w#@?l?fTV(I2Äxl+?@Gv[M0y?D.1 KǠ΂7t}_CW`ζl%p}DX1M^RӮ+iV^PIM){G==B,/Mj/W&+) s2:+-8[A}JwP8 }+Q { $/I2f8"_$M >Ha!رX+ ,Yk脛W^﷦z|ķ&]݊𓻰yo/ȜE ?T,5_@X%ד F>z%0[>"gխ<> CHBD8n~ A'Y;44|+ovl7Vje_Qz!JzB:)i3$:x/x/`L(w4>HGYxBml UJ f&fJaf k !r m՞DH}Q:un,&HSCV@+-"\㰽6mâ*OewWFtƥ"iI"ݸ"H]n:/%߸buYPB' -S|y53Yok Ue4Ir} Qtf[cZ9PxMY4.Y:rO(l 6:O#`n*~&k*~ƙg츜8D~׫|hV8qTU+aPloԎĬk A PԏKQ?UAuhmlh7a.h%`2Ϗ?qYPJ0$Ȭ<Tc9F?OeDAl 81]|f'!#,}mJOB$( T) &`ϟG[ *X%Ɇ<1i0gktyh n} "VX4A0ylJ0wXI~~rylo}GLm5]co@lGWTWA,AU+{0KM;''~aP :k{ԓY+ձVX!S9{  ]-@y' LG83dT ;"w5QW8 |$؉nQ1#X+Oq8(.mqCE\ʚK^\.9Z"Q(S@1KEk7^MB0fz丯'hn}WmK团u˓JԼ-mG{ЩjZ!D#ّ= k. Y nHj6;gwbLjw 1yU5VϛaXJ qPCk̀dßa;Ʃe20 .̖Er`ebnmxOzo0<3(2l' Q[jLAm`ϕ$ʨ9'dSX ^Z<̊*`+jV _!چ<Lߔ',bOT[<M h[߹{ܓ?A(C~MFx+ݼ<)ߢE4;@7ڎ s}O8 +8D(H6= +we]8!M|o;t@ao3V4О xb{qt(RtԺEJ}kEdF 1+IES|Erdش2& mZ HD4D[O֌C+mʽ"r P-n >!9B#Gڲb`?}LB m,61yvS}0Jq"IV-תVH펢:nKdEW:i7Rk^D/rGD-AWP'3׶>G&]GOx'_(6`f|jR>j$TL⼿ƏLrZ tҡ=爳z+gru咅Î!V=Znu&c*&(ڵ@k휋z>m: B>s˥W͠ٷ qY"?hhC4-ؿ#IxLG0!K{luMUbvf[ H0q~.Gl%s%oI7 u15eX0/#bfoJ<a.@(כ>D+P(Em<{ e v8$=oqV ^_-LTy5z,p:m8rg%wAX\v7LI[a0gg[lꭱF-fS{4ϐFP©O*h`2p+J BՂaQ} %->ڱۀ;c`7MPIr .5 x~[! lu;- .5?χi_KJM2vU9, AO-gc{N$V-\ %!@^6AqFD{5ldyeDeH7"no` m}ѣi~)h޶.CgתTkiK!_X( ܬSI^ߌ`]nTi1zѧCaV,w il&U 03 `#vg~6I:wpmXlUwLCNC$`r.I 2ǽfHr-*BUr8dR}']e9_[٤pQ.V]͞JpCх5'в9-J;ٜdjj Hed ]=塀f<3=7J 0:k`a+gfSF-lΨ4xh?ΏWRy>5چܢ!-o A%컿nwg9ZBZ{f8*ʻj! ҂.lˆEeKnBMy*1mK4t t+@5{*NTe1UCԁg%V=H?F< 3jwYkmiCͿv"[wh#bBWǦez{1hzU$6 _bû)AJ7&=^s 3(K嫳 iL# AJ)~s1>mQSe╉P3* F̍[<(  Ɉ4 13s:Z1?jSvgzm iqO8̔#q[Wf",nT{ʧahO>V41?4oٗ ]X!CTX26a298ũHG`^N48V)r1ںbzv^{[ʶgv& ?ZÛn!Memgx{m˾S%7I]ZF';zYViӡdž3ɣ||rt ~\5B9bn"Y!Y!3-S+C9ۅ .ٸιqf_?J#guHy88q'seqmF[1%r@ yЎ6M",53N.1 [[r+SH1<%$aW~R0qڌiZ:z@SA|E.G(pw8"yZi}"Cu%&)GS[ ó~9㉈oY("7s}YY5E=7cn;=W?/e1vCMK0Oc@o!q{pm -Ӣ5E!\ޚxi-&RZ% 1[b&)rQm#jfffG͵HtK&u=m\P6UX`1J"8LbUFX)Ҙ˶ |_g[m˖,ܔhqݩ"WUJ5%^`1xQm_Rف\g" ՚?Yc)]>`:[V-l\c"Y|TV$qA;hZXurnoIZÿ#/j]jD0|[1MT$?lf 01s`tyc=T>ǀnJ%Q~yy>cF)z|tH- l5.$o6Ok R剔miXl\wDprEr;h=fuaHܢk6Јn'Y=f& Hl4e:,F`ôZF&ssu%rj/^,ŊE$G$wCEkZdD7R|Baf(e +5u[!DЇ\`z~zQ:8pRRD,eD &YݺΡ]#Cq"eð}!6;^Nģ*E6& MeΝ/-#n˾"ʠO\catbM3Zfheˊwa"Ru"\ߧ! \s=[WTfUl],xH/? ?7ɡn r/ݶ4Z=7z,yaLש2̩INó_I͛΍W.iR٠.%y[F*N *B{'Klrh !,Wt]׈ZWݞ9SCО3 /1O F}]fvsF&Z?G.$+lS OteP_s9!̕'^'&y4sͅʨ< ^Q;?i {L9!g4:D[­mfA#!DklY}w>!5hDNI\$u1gpg`8wi#ݑ?} +&-NCVȆ'{q ׿gn &|%! ~8G]wA}{ۃ=V 5" {0L5\4W?wT/BvqV|mG[^i1Y]&99Ȩ]ٻ=/^?vJl]]ăGŎrCMluU` >֏8 0WW)M$Q3 qD ;QRh0?5d6e"r5%:jOWS6,K qPت\CP^ЇlB[p^zÃGzgِU7Bı1ZXnG+J5EqOlz3/aHg1WlLn}((Μ!#UUy $o*4f3ζ1<ͳp\ Kk{UU\dJ|NaؐXzx|BX14+D"JSaQ]yp0w4 2lSz'x[>i~2l@g| ׂ~ho4JocEf3L>MÅ0q׷m,@L%O `Dr'Fώ, _esW%~̬2f{۪(Qg U>*tVQP>sUUzXc L쩽͊EN3A҅r[ؗ-'F_^la](ęq:7ad[]ڢw!+Me@)dsyEPFU,p<[?7'lq_OV˰*K~P 2/$I ӄOhSзtK*#~ܑWL按$GSj\i^i=-z|#Go6%^3[qT{HXA|.+ a.m.&WzCjhDY /}obIae7oiכO]+ukKb όrR) YB:k} ʡo7*y|s”Co8O`T8?k=WSJ~FD̀7;ْ嶜g-8* ybpK.?troF6Sf3N=С^!1d~dHCSk$Ho.S*#u{<;ƺ(qpZʭmޠ΄ZSܸlhMOZ"cla`fi WrY,PBlj^_~%QKٶ%:<J"qy9.!lqyUu^rC60_ZFf zAuZ6i#|dCBV|9<{_Xn {]zF&"*5@)O|bjh9H'-a>-t4" j 7_\sԇ#j֖rP8[x8]C$_Z{i5ЇexkI Rtv ٩zF5EߺId+nu&W _4f! z$QQNV#k)T*wfƅPrѤ'Oz`f"oߢxK| ƥu[̃7ú z^O{\[bE&Rz L_ Ѱ@th|ll(7Eʀ}DQFQYK|}<^ZϪO4O0l:Dk53??i.;W,*1_)nHSPWJpib,"sfXԕ[yN`# c%"!c qDF]{Sf4t4.o(j_v˻؅P=X,JUP4v%'GWXq{yS i)Jwe_k>q` DO=l{!Q=~;u? -\V$:yku9 qACJ; A9"nk0YT~*~[WO#ӭLZ ϵO QŽ#V 6gT'YLl懪`H DE!k1+i=ll*;kaOtuV\% ŗQ :$& 68KiwDB2&=I_z'{A旖&9l-(Zcc@,;I'jk VQ|ZGxvWF"XC]];6^d]i$h>wV<lspD^s1?TM}T9G_ WvNDk$*Oejoӿ_ wݎ7ű0K,DL6 wD <50&Ӆ#P4f@8ٚΙ%(R!]f] xb-?Nduyi$CYT1=$ۏܣ"ꦏc6#Աsfo \>fقd1:5ޫh$ ifXd)b]]jZVeʐ!Qm=9 | &%*?V?Sk]5ղqy}Ef ɫ *uc@W^M6"IABX +wVLd h,T'07c1@ɳd9! _H@BÐ8#VuodN_Qb2fT0zB]OP|b05RZZ(Cк|S`{/`3ױm>tR|tFqAUv: S~Mى|=³'YU+kz=c`ʱt%.{qWD|FV :Z~fgV`Ȩr%@ VZYc9,ԓ_gv_j54] B9?8uFO\cJV,{=Sƃ^}ncY#ĭrOm?Xy/W;mr|b֬[V6K LSZN9*l'3^}ٱw MY/RWCh >v!3liڊ.r%(eR?!s^duEQ_y2&o;7{.OϨtBɆ)ȌAAe­n$[$fw>IJ$Vrȱ-"Gqk49ݹ"ls059ߚ-oK pbXJ\̴ۚth[imQYWl^M $8*[xMW4z@đR3vF.|YڒM޲1B!y0u"55|VMwmEfI-*y}OFYf+ 7ruc}xvQ㺓[OKE+b FGo `^9þ B2xr˱!; 5҅2 *֭vn5d־jcT&> 7M䈘 qA68B2Mi b>k: OQ Η4gXwjb6F%RZqM}>[ )H-'ՙ8 EYcgd,SȎN² yw"V&g XCq.ɝ'Q+"S&۹rK\Zv*(H6MYBIJ5[:]+`g3aqrfx=OmD!1$4 ԝկ;ws_*~oC Bָ#C !"S{a1cO9cMݴQ[DH0fslQ:=vBA!41g2ᄦhߌI6Yt|z#mM).(+T'k ߸>BoJdKMt9/~wIOB/w=V'f4Ko`͇t[6 N R->FB%|dXSw M\ #Md" ]qJdHp4GƋtBo 3 irG&IHz\vߣC݅7NJyqǬ 9 fdI0nǴelN`m( 7tvk?qa2vֿkjI("Nstas iWEPq L; &&Ђ_+gB;IFP}f/'IJ\.۹q"#/2ϝl]~1MH[ &v.pt(qnJ}qť@6GQ/P*(v52}=YuQAp~]@S]d݀I8ٿWr[.]h}Juz:⼩v &Z\ZDӱiz%Ң?58yIñd˕y|Bp$[awwDiBV|]o]%eUN&< szƧ9pۑ*)Nf T8Sl c,cT0RaD`P:T7֊-;<'sĐ>4³yY/ &lp^k(Ch ńp,l(u?.9F~„SIQpW\Uxpb.e&S\tI߂5/O[QWJ5z$ĥX^X8-7V-Dl^v;q9˳#FB9-/0\ٽ>pǔ^QicpR4zOA3`,S. -Tr^V4a% 贀2818eX0KYZ,Ԧr|T5BK /O18yW$4#{BqGFLmov'*ဿ(C8i8,Re]rS}<5$3qX6W˘ŢVBsRߕP`Ab̓T)@,zUѨn5iY0[:o"Y! 2a~UNeo&K/J1ߍji$E a)`Ҿ,1  XkKD9M>mzp T#E|;.P'lxg\`aA.CN[29#_|!)ՄIB;ףU'VP2  Vӧ?yɆƾDg>yjJHE8c؅A(4tt`&DF}t,EA%95ġun!!9o^(yqr$BKVU'C zkҬVqt&ݧ~ O|~hjt4D΁CGh\OC\/ X~yA"C[:9v" -tn#1h[Ia[ϟ9ԑ6R&7K▽]8[e4Y1UVIR5qT>b!me",/n Be Lgy9uoa.WS(|k9cgߢOpIg̻xrn ~"W.~~AuІ'֦68 P iߝHG+">鿅|h4bn%]d&X9 $.G$2a3Em7eE?␞B⤢@v>M!CP"[FVWYŬԙ2o:*1Y3fe9ռ4|%n[.<K)UxäD`vwI3Kecjí9T"g򻁋AK!d8r3 2Y)CAq׊יL,4^x4jX*@M/WY;&]0>MW,lp:*q"b u zJsJGTmcH wu%IiCG\__Vw@CΧI/YL>O ,P/dT jF_Q 4",d*,%9wKMN@^29.뭅H7AZG\'p nBӄih\i+s Ha#KwAnHsi.CF湅WANxf\@^D]gt } M;|78&$!Cu1I2e;5H[ow A1MKQx/ࣿhLGqLB.l{J?HvC>,h8a)_{P 2O*pKL3+v'$/4zADrj$8u#W];fZL( lIgԱ4S4Tm@`HFZ]vS(H?B/@чi ` }FhwUƄR-|NSANAuC6*ŗ_=hteEo1bؕէ{ѫQvL[Mnb=CTΐk;1(HA<sߞx{d ᴐ(lWܦq`"\**MHIc^ eWsa5n^ȩd-g+;vnx"笌GKtڅ[B\ځjۍbɬG++uV`_Tg:EK]R|S"Xx9CIz GSap bKٶdN;DNG`Aχe8 &|-^Gx|g#DX뚪#s=&4f󔟁rUa1qαGI06dft)ۖ/! 9I8 @iu۵o,0&wdJuz,A캰[ߔp2VS!xG+&"0>p!{3HL!bNcgUKOe'}Nzz=/ps(\͠<|<+)vs6X /*hb@[}*Gw ^(pсt2!c.ǩq@L^F\YƆ/~D!|/+CV؋*W VyGP$} WUN@xd}ޖ%Oz Hty#QXՕpjw6_ত)wU4Pd`z/Lq0xXҚd1/CѮ6 \\kkg崇XY|W~-ڨY Rp^IԪ.9ކ(q~_MQ[&槵!SAMcSZL԰ FrfQqD7FѰnzԋwe xuAGsۥQ|5ye{A$k30cj oܭ <}|}#c/]:%1@΅7y UNGU$cǂX\Ֆ`&'EC}EƔ䦧P PCL7,/%tk)hֳ`>74=2['yk9E/> dyF4Z^ʛ^}J\+PYbV3;_[W H߰}cy$(1]eu4[2c)rT| ^*~Ut%Vx(--Z Q.zdNt݄N;搵( '#P!\:J BhW&U`jx~ sbSSN7[nDňNlwՋK3= û{s@cJJ`u "M :]94LIg!"zK5WWZj F&b d=OaJ#ݮQ$gm HBiWO@_qms  qλ! ed&q*uMx0|-֯ye/g3vcȰV|%#+9uďϮ>%uNJa9Ӧ $nvU|Xی0(aDa^3dn ]2ZVAiPUurvgV)tٮ8t2p=g+slp7zk 9S"Gc$yo(B\h|l/ocj|G縉OlK4ǁfc7)-^.}`m;>pKv#ѿ p府RS (΄r}d4QrT14hמDFTa`Ȼ4)$C}a]V$Ec+Qv('4Km6z|`]8Vji>( BT(o+k'1zT 0Iv)~Ś0Zr]jO: b2:٪7l$eXB柰yځ-Ve?gs`ܷKh>Mp+KsGȔ2\ۍwx_Mo5ep9hS9A{BԨOV$>8ޥkEH'']gK꿃r>E^S%1Ɂ|^#4؀Y Yo%IRতjM;p輚8L qQ;K@W$`] \."Zr~cv( Dgoq{+1w?o}qZS".[4m7 Õ08,;@ТE`<]nE۱6zq<ʮNuw,D@0LGMj$Z-`kOeB(gԽT8pq"{;لɝ=]\玧JŝmWP:Yj13Yۭń E Ȍ9.YBkT E<"cLw>ę:I_DXAl1F/ktT1pD)E[VZ=eEzS$H)%&b%"AaC.&aB'2.Z2k˜;.c UË{ i_2- LIu56x Ǿ IϽFUw,^6[缘 K$2CO4MVIb*).xcs_PE)t|Y$,y;gF,ag I{羫?,5g!?EV՘buHya7DK[RhEwOT-,V9?ԙҶp>@VHtąYgZg\߂G̓z `WTZ%N s[SZqkJ۞[(ߧRZŴفT W{K sy1by^ޭeڙ{cs2Gx5w(4pp^!аh/g[WĦ֪^'eld# 0m9{C?"lM~7CRwS5a+߯KƌUbcwWcbȮw+̩L"!$AmS=s2vN`jb57=&;Mr@u!F9mA'lF)22H5M5F07s8=Z/1N^ϝY6cּQIEM"t?ߨ$̘vV2;Ty1~:-Buֺκ0;ϊ8Gl~-K)?+eG\c[ғ KdMn+""+l]ܐa]S#ei(\%Е ՝Mwa۵=T$tB_;(: O!2T@^oz~+d 튡U3T*W{`p WzBw1g>=ۭЊZ[0$6 E~J툀q%͐ﯧ흸T%Knt*, a&x꫄7O bNqP7à[TeOߦ ګwfS$Jӑ.0DU ηh{"؏E>l |:xJAG}N2ޥmXq^ج_}y',AK;OV]p>߷[U&a ] 2_@#"z;ᗞvDٛ%nMaFu>yeX+a+~X&h"aPjI&b2<'ֈ8ZfWQ0k ߫E,<1WTTd>JF.03{Üx{G#j+8u[Y>_wGjӤӅ6M4ZXs,K-yk Ƴ-;x$څlGa^I'XOOsg3]l-(v% 0&B}2K;M/X`L,R2tDVwn\^DIx^@#^\۫yi\:B"pYkلlZ4FmNR~Q$!^#f͛nXI ۰ϵkwܧ3i&+IFd5sl $ Pc5P1>KbIAZS ˻Y?ExhL(ڜi.n~*-Яe}>ZH }К0ԍvncsJKX0c n9^3+5ҥ`.|{Muth8J5K<{CF`媑A.S.>LI\C6T9kq5Kĵ8^]PRŴ:ҰV_d@Cf[V]:ukMn}39X*_T(t,5)>|h7 EIqiTmEG[3]/ e|j0- )U&I56n2N 6zX.q!gDDBzCKޞڒS8;L`ylP]BI)'ثџ#;i ^UuԒTXɚzf\WOzE>pQc{~~ǤȔzI0|4M,_Kt`+>>SU6|Tcw!O}.S߈Fnڸ: 0?A*;d+;_/2[ŠK-K׶ȇDeJDTW1Hڍ^|ޘ(ԈហԶ8.DiK5N4Ŗקk7"'—A[ifO7)@Le9b#SBbyrjfȫĥZY I1@Y T3N5[53r Y.QZIXlz?9KȮ<B | ٣$aSt˼**KPs<-'V05p5ZFnEi񱕘Os+H93|~817>0>1i27aE;t3aV܇š6H \y Ik*Noٶ#w>> w2x\ \瞹Ty.fi>VgHuq].A6re Gz/e4-+1*VU}GY! dL7ڗrEo= fk2=mY]\]MEtV!1h >şa`&wZ WFhY&? E}}Sd?I c_)֯fuy4pҟ `x)5tZ :}t1I !\񯋝rcve\2Н7t{V;VA5gЩ ʺza%LSU;ي1OGlд hw6j<?*bݹEF,~ӊ4''x6|cqܸ3 9JCrR칑dwiGj-,ɊSC *CuoZn ʜr6gɜ;t醋#i+e{NuDtblдÝO|QW.9-M8ܕ{Ӧt/ =Ҿh6VX+0L"tyթ zv!/yӁpd=˩3۪ HEOQ= r(%e')b;~"p_/5Ǝ])Zc$(U:apJ B\(@PUe2~)EO l̮=% U^Pj!*S+·]~^Qt+AeC*7r7) Z9S%pnDo?0:1U?r۶]*ףD:{1Bf=hpJ.vK&cQÊ*)=Hl L%s!N_Cʛy}/A9 Jw#rVN1c(iռ''YFFc5L;K(hMb_O"wc:NDA<XG8`*CβzN` 'o;=dUwGs O5|k -DQG>[ 3+$/"ޝz9dn`M*9{+!DG 6w mf:=_z!edMTL ~HZerj2^'j̙L#{]`*GGg ~aRkr(w-FmF|dG;]>J /mcbE+JN5y',$mmF\TPd<LU`H_$_؈#_*lh^{݉_zT{9f~yz}Sر WR|5T":HUiۮozŽ0s go𽲴F’{ g]S+: _E ݝ2$QmxE!Y$k'hċb7\ս_Z & \Muk$%wdW'e#W B[JMYd육CG=Ӿ-8JGlǵCb\ UC5%Iv1<yڦ~Oհsn1$ѻߑ߰ИK /W@-?Me4A>[`МO8svl̥;XSn &? $rtF"yueȚfWG}9qvSDl~Q=VjO*9,]>|'K`ƭ_~9Hx'Q7}1 OЊ1vS4ClI,+o)2GJk;M,E}o u~ƏubQ.v ߗ"usKHʣ$QHPMꑆ6ݬc.lFjF[Ť "#4Ԍ6eCd@rٿ!V^ZX2bWʈ,r_b&]W-}t"qʶx11Qh s tKQ2Q(A8bȍxnroORDWr" {#w f7냂xaam4BY7%H3 8^Mc^n p3TPĊ c{QJ]*oge>+!Sysj1:Zʣn`Uw>{vن#nH=/Ab0c(6Ү>P6*1z\h&WZGQUͭ-^BWNzSAk^-'/0Td=nq?ͮ5؁^XI) 2"z-n1 hxhH# q/14z1ޑpHCjz? skTQ~(|FESZJ-`|P?[WZ'7.jS@Z AϙKܧ,ס`~] W稅,`x F<HS$/*oؘfG $E\{8Gc!n[^n[Y2q&(j`d3D!qi*jRRF:o{YTYWT(Ol"w,Ұ#^47}h`"V Oy r o!,^Y9,Ml$1_t=J EcN H  '- 2tuBʅGx٘ZsԞ7c ct$%|q%3w> ]FP3tBH;ѡ~4[N o?PN/x;"CǗŵin] l/S:Ci9c^sz[Sz4A}@$_h)ΞB;%ީKhM% .!GixZ9;F0pj A+ 6K͞V{8v>>!6nߖ^-&T3+]E!TK+싡0 iڔM;"|>PJ1xaw^ RM%=ɲwC\JKNjZMI/T]&f!* r>A@N$m-1y?Qkь"X9?KeV ^5 v/o}D!m9'M=K^ʳa\K'x(D'ޜڨŽ b.YnC*D%P5#E}'\dĿkkX]i0@# МBæK{XіR\3ӳ#-%:6ſbXw{ >? p#ݾ4Su Dn,۾EZ%84+Ж8j`,iVZ6b yk˘?/`9&;,̝4Z.&x1]o X}mTz{O?z*2# s/l:/ p$d89h֖D s+[Su}+]_qbw~Əɴ_Z9A7jw~|aZ𧄼z3P8XxnsxU*\OD^(~^xkgobVmPPmqD/#Kjm m)ٷ$EeuS"9W."F*I %.\DɤsT(lrDj6d~hD kh;:WNP,cFH2I^Z C;|*1W% u@tq9 ,ZapeC35Ae@𑰊 DsfLFeY@ 3Hz2FMc6Ē9N­/Eɔ͎ۛ*čg ?[>$A 'h8XXԁw pYj hG&q $GTb #9Rz ^8˚xTv֣lؠ)W)B>>:+la/ sȎYS|yL8OV*y  uN94zi`ku[f3,[ V'27^F T__2Kh]@Xl!+aq2q"t䫍4GD/IA>"7:sNYY*ʛC@-$9uKfBy/b)]u")8f$k~w8 7$/s!iYB@` |C MI%抺sT֗LE%W3HaEXYC&-:e)*6qŅ:B.s:!:u cۏωgSVN\X.'rFGj <-t݄z7bQDQ3 xFe ֝=w Eg#< {\hz HZJL1[>8VۋhնBik׊>jU穌^>t\<2j˥ptJ,^O~FbNR~Ұ;|S'D%SGҙy|`T3 #F̧?(-ue=.:CĴP( jwpPiRF@S5&fH~/׵dMؚ'T0\cP8fñP&C懡䍤RD|VfL/C@ShC2G1 Ky뫙 h̷~'Bpә= SV2_];@ҭx?`!>JljB{4G`VdvwۗHj":[k1yʠ[PtZIѕx{GbvBcS9ɢd*̵ŠQfZzIm+bz-OV` ^.e#~$C>܌WX3( 3,uO=ᮛT )حWVԝR{G%k:e \JH58'1áEnTP1W^ jU Hx{-QrO0)LFeAU:MW} W~,<`j#dp>;G##rӎ1ADFÜ38y~S # e@2IÊMzˡz0yS+ gׅW&\Q)D~6_A$-(-';#֦Ny#Qǀ`u657X_o •*#<:d0(ծ}xاbnSŢ*7}ICE& (w&) +,M\ES<){`F >GT( gi[ QփqE]a >aF5D>0ãXp7VJ솑cĨq5ЉHg`#궙N3IEZz4oF>Mww|/O彍`mb!Rsx&e#x7qoWI2fpZcgwJ5`;4R5 +z[ܲLNL4{ڗ0RF:u[D$X3l 9|葾L,^e\rvlv8i~I,sYY#U#w&Of?1zk.,p9zӰ ВZ6 )'^sAWA*fS=)\H-=\{(5p  nG6I#v)]&x,8\~ gܭk⼿yd۴" j<7Ge:Nb%v>!V)\| ԻazC,Ã\n6CxfC 0n#xpw P}%D eu礈fzsMg8 ~h;Hyߖ|=?phf +dOshP@D8- lA]3ﱲ!kU]ɣnݞ*6RG j"'y&$X]$.o b^In3b S.^/` $o\@+ےUz Ǭ ۉc>V$KZ)V]g[fP(8;W+֎뚆&K?1;XQ˩'`#zR$J{-DҬJm,>Tkf,&<ޑ*վ2XjIQ>.I\ز)F}r OI#A4b0"W^}xǶx<4}`B/7vOj>H&xʲ,lIe|m:ñ)g~R qP <5`'dר?kaVY'^@\Asf5Ӿe}%Ƭ2d{ϐ/RQNv$rT&@ҀݭBd\?!9{MG?$U'~48uc@(SFw(C4dqcʡ#@TT5ּMV]G֡̿ybbrIÑW_K9@lcM.A J sy(=nV:ᘀ < `Dh }/3v:0+/2z %_!iJCG~o4O|Z[YH\ptlN9wဌ?|Hξ{G췄RW-/hrNW_V?6S~;dWNGnL[v6F]C^N=o[kZ!'-dD)?{BpDD,dQU1'O?±~K#vT;$*zgbB)Ċkvm39! Ksjr=RƩ 4}[Ӑ|']i@ÇUo-RӪD{!)&g@Ga&Fub#<3w6#bTt]%[$5؝wwa^V/ r_/*APd3ѶHU mYމ轍YF3uv{=nbvK96-s 4ND&$Py$li<b˻cv1e4^2֑8tU4oIGPV-F}g pua|J:9^5YuUf2?` (~ѝn =gЄݛm^i wm~Pot]anzڶ93{ς!DZ8=3yGއ)ٳ]\u\v10M&ax~f6)aK0P5!Şl -GP]sGRpސ,5a;Ršx+@IXGh΋I\Sv=*haăŒ=cLz<[>30'~b{@-=')lm bMdc"ήfQqe'sy=|G˲A~.dz CTK*&sO7 Ml1OW:φSV%ed`&HJ60i4vj|\jQ-#L!6_g0hQeg.*З3YvZ1#T/]D5.rUaȓP ,?7`jQ2 ]nDgz>N.v +J~7K57hZY?|s+Qrpn.dSclk.X`o#  Mݛ-.&?4c@l઱M`~z%JKWEX/S7yJDE*ؗ `PLƼ4hAI=X,OM5!.z-K1R}M#Ο)YGEF0I{~Qx=.lzVS}5g=g}.k1ܩeu0 35 N]bGdʉTTxDUtwbxm TUGGIbxJd a `*M6anS$yo0bFKwfaKkWޮcu1a95vGq yK?ϽZԗ,Z\Um0>PrvHJx IWʹ}yV]؋Rlu2F`!:.cBpȚMKQa>y.;b;ns>fCF "O2MҙP0k7T?:À=F7R֨tu.\&4xcT^jE/ёpuΰŠ겿R4՜TPF.ZY V5oF0j;3+Xϰ9uN!aAI응7{3ÁH̀l_Puo6ē7 X/6 [vTFV1tΓ'/GWi!Fr~'=1uՄl>cRa<4~Q1<6xK0z?R?237v2 j'8~Ohr7z--Is*CxCޞ貛,mDLCDpwd1䂂nّBk2DJ GVQTCEIժw8~ bЊѐ,+4Tlbc+fg?G)f:ƒ| OGh]4fRB EA3`OiAO$̱U7f .; 쀶y_OA"H kd8ڙ$A)jBеRqѓM" \uRpAA)D'CQ5%( }탒Bg\ S*g+ڢ m>y|uuA2 %XKl8S|+`b9]c0$/c5ʗd.[y b$r`"ï䷠GWCܘ9g22I3n~=gF;I`3(:  ("03:y=RUC3ʍ*ǃ6sw3&ALGM=O軭qtn' %ޚ IZ#w!ƨP/t$`Kݶu35C}=:(#QlK9Kž9M慨4:bxn"#~ ENV>,zHa n< Aφ{e`sA[HcVXY>k]"7ɵ2# ҇n~!_U>ܐ e2eRh.Y3P* ]'W&ٯ 7mm*d#Q_%屲2v?P/lZ`N'I XƨfO?2pxE3Q`S95}vejX ,.iTQ46WOB],t$B#]ڟA@2pۜ+me:t+wDe6.%:EqFLw:?ՏaO=9U55'°I4]yZFs)4]],7H 5]9iV|UE8*Z6+弎ͼU1!Dw6TgM˅Z ^܏NRZRg8Y ?N2gXe )Zq1I;0U %Gü߀yҜ& .Ƞ*=Wc؞1WqHBH@l8vm!zfKfR< #. x +spyMf]~;Z.\oƱ>3:=PR,XصkWe6SWuh?IUI8^ ˅XFC}Ͷ#KSljJXVcH*2Fv!Ւ 0<1VLm_PL΁#TȧW',O!yH f `/KR'FH['?h5 ^3Ⱦ<mMx7Ptwq"Crfhr 3U^1LZWD1prWjYŵS x$ OGc4gt_E3&*!_ o~u{9W}7_#|)|6Q8KUqzT\wófgm=blk3pW9n.k`f:?dxg/o"L\%C5r+5lHA)ۻy2p D )7(8(`~WX^Ê@u 4tn=MBB4[hW{ `$zj~\NڠݝmB.{8fS0{%mSKD|\f aJ)`;ĪT$IOEظ@GF4I*fZTJi !  /~m3 / lewT$_USߋ3 !!..D.n16wwCX7⳷Ulibk+JC+yFgk~*Dm3A$OJVV,lc RD:e tbV&yӼ/Q ;3 n3#R8@ zZ4ԧXb|WBQ(ZbIKhmPKʌ E [;Zkpr6D{9ЈZjz55_Θ~ k3~LN}EZ*y׭50MmOR®ȅ396X;5ǒkI2>nNB|k67)xNm#"o#'70K>#!KJnWQAv>bW1eAJ!e;.;x.o5Oi$xseiyvAUSq GwoEh0evNjW"96A ~bWM\b׎|=Y]o<2@@A?ζYo4CO Za&0kF[@eTg2FhJ@V'O@ke;##LZv]wH&89SBTƬąUTF TW;9fd/ <4Ǧ&#-|! nQFx]סF'".)5{ 4W #tR-Te=?BD)^[̙:6˃gkfޕs~"D~u/UT`=0Lx֘i 5oU‡+UyaHy+p\-ȔiQa ¾CŠt K 7?c}7>+,ռAb1ouK;\ 0X/*YN?G=-vCR} +]aR[^8,c\YěnSF&SN~yR2ɜvhדp^_f v%S.w B52YrF%~,Fi6[xQV]W]"q9vw*o!iXzV8Qil#wv,1'acȻ5{MATZ=Y,&y` fpkj2iΑޚ@`6]X 9Xa]2 OVӌ7BIΆSxGpwX}+?Hڙۛ7k]+&n4jNW{µ嬶Ɵ^Fchㄱr%BƮ[/a;հR{0|] b xd* x8IsQX(L:"! ,/ X>^w;O FykռG)fDwCZe@$ ͼfhַٟdš L]!~R%_9U_ Y]uf34L\ w -F~ܱVEnH#}t1X"urW:mhl0<-ד^ĝY(wr]E}kglpӡI=k͆U;E&Tǻp,>njpƝȩ{GW|~) #7w g (zr]Ԏn|_M8]]7NlN*O6@|NTE7;Ywt2r7kadT, [ோ<-O EvL f?: xSK [/j8uhػp:C~xvž8tO}Vz %/4PK4Ѱzy}¬ GG+aRy+FF!OJ3F C("_j5ɅU'0o(!';Zu.yr1e][ZY8#WZ䓻ӕq&?0)DB}.8? {7b'aͅ·1!pq/b2{2` RkI Yk3ï+}<B!3mG^Lyo8 >y1;Q&2W1ujF#RnMm@ |l?iS,"Bַs)u1k0:Ȧᯅ*<3*;6NgfSYsyծKcI3,ep 2Aϲ%r#G9uF8B_>?,ۙ;{^:: &!<hh#L*"C aI:3^D^z },?׬cjaz̀BF¨$_qOS>+V/S#]}c&IQ@f1gMFwp|ٰeI:ypu5znaY8o ,Ox<"6X¨?al5\$\"+D x|G}bC-s-yUĤꜙ=׻~R.'}N}xit^l7IFx0!bobzz6HU*H?UVxd.dR|)uFE ZWu p/AOm^h`ʁ¢yiuVZ`@bVP jez$ZHREͦzUl&͏ϋl q{˔d&Z݅ הon+ؾ tzJj{4>xU/FgI{ T{>YIչK)C }^] W/Hhlu}V3Z@{:=iS0vF@"KӎTTyrD?|tu ٌ ؽɁXޫQ .Z3s iH,!ۂJCJr915"cݑjpsgm)d@{HG+_lM@̓h(-?,8 RR]U~E3",Y-0K63/ O {ئ` AZdY<.ᤡ"DGa$ʓRxEc׏j^ M*s GggEh?,KCG儖R%!P{< 4ـt/|u0(ղ&dK{t mPۙO^ ;GVn=q6hTKl3WUqBQ GP&}= \."GDC=ՔGŶHT*-'>Y8%m(rRGma%䮕N Zb 7{f!e$$WTP b'(+ЊbI_R͍l4(qrpQ8I idM,8 7'm) #D S[&M.k+JO` 2MsjϦ+ݙh쓖\&#uդ,q#,sQzݸ5M(됈C%gdVtE.fd*Bӟ\hs1koIs)4r 24M}p :xv>OdX)bBC,x"i Է7pc1{L?!k ynO+xq'z8Γ n~e)'jeKg=V^fe 2X[ E&$\aQ L4mZe3:][8N '%UUÃxi -]pϣo;"ES` 1&Zj- Ftv! xBழ ]%kOe N?-!|N41jJ<X/#+vS-_ѹSTD#WmZ˂6S1]Fg4@dxE,'%ۚtT3r5JGKׁ,ɪj ^e5 {؟sZO΄"3j9fqq85x,gxF7yn|h3c{E?'eCmi[;fM"yKbH{J2=LsHS9sPleg7Sw,( pY ՊU0p^ "eȘt;+Sjn}xu+]%I€.E?55s=6 b}@p]E6KiS- p"i tp7o(04lQ&I:ZL*#ʟ~9Eހi=y3vv5䉞ZI".9p_#l&Ѫ)1׬]b} N ۴fɴBOoY/`4 %CαV&e"<.-~QP -,mvm}`!R38}s(3=+*ZaʔX"UYٗщJUn8o1m#6,kYZx,qsd 09q[Z9|">=l7i a9M}]jݨ0l=y<_'mbnIݪֺcFgT,538dښ1ەH&ubrN x&$ϚQv2e S%+gzgGiNU)JjTHdYyM[覇;H(-Yv܁ጱ@ڢWFT2(',&O](_vy;@$N4eK=r-5X%MЈ˞[ rInV850SPLgi)UA_DY#}cVk"ޮ"kQaRXBn.Z,/4AI[-Ӹh^nJN!zg]|'k ]?* (H#   k$x_J!W$L ˏqUzl-NoS++9&A0G&:>P l[dcS¸h_:fiV-MH*9L}7>*tV7W'R!4 ' ddVŃ@&UmOdze`Ii868pɄ^eV{3ȭ)"°*PʄYNUw qb?'XL) ?ܻͭȦvyPO1D~};ncB-ypgві5W]CѮ҇/j0$ˑQx2S H ިP _\|!>./,h[J=:!l=v[ EVU/b[u־ "Zc`v53l]ΡPy3v"ι"K!d!hsJ"V'Тp&yl[eT>o[BtM#A( ^YvárB>Ut)D=W&͌^b-EvЉ%$%jn0r@!oGYk;eZԁKcJ(1ߛx2N)AWb/eXŗkBiB&"1怮=g,i֖ q泳꥖ar|owĆE?B&zٸ5Ku\ .bz=њ5B%;=; t7z9|= kGzI>na$[ÎV#6W-IY>Aݦ͉o˒| 3[enﷅy+wBL$QsSvȞigY7ĩx@yAS'G0]340="WLj-'BrҚXE5܋.z?)wڶW =RG<FjY#A^_1粪Y݆7H D(2j ˲/ ^z?bCNqRK; <8B}Rջ6ƄT;kP_DDB_鏔_y_{òy6ErW`^7}ɌW⑕Y -Cos@ltKumJ,YS?hձkxt9W#"j.!с!]D/yqp&%~-ial x0 hU pAE(8ԇL7<% Pf~} D?~"H\Azyirz泚˨so^/iIw*?=jٷ^SZv"FrB-mfVELp Hò}&8݌\ߝ|*`k p26gtA?Cgto:Rl:UIk4HRc8A`R2v]]R&G\EdJTNv[7~u~g;Ƃ`Prr"0>5K11=[E5qgyzq9-4u%<>U)p 'YϏ95>ny2#cZ6РRp&4r.^l});z&TH cQDzIoF>C={2HQjs1Ixg52p5I=>ո8?C>dT?c&ֽ* w?1qQ zbրq|"(SmVDMu|u@=quƎS~U9PV;t#aK$/p?HˉqmS5~}U2 gƇ ݨr8`X T5V{IYԳwfܝP'VFGrh@oZ6mo=YzYʍGrC䋘vR^Δ

aH:wmpWtG<(^f>FHkHe 虚QdBmK*Rˤ&Ig* [܎x$|p]]q_ddEt7BXU.UvvT'->ȰBgbpЧTĘA̳-Z] “ߑ_mx  8AXyzN"( bU4']:}oB^t R˃ۆRNA/(٦ECgRO7-p`5HJGAhiXKW&=-&]fg7 ~E_- ߨXX}ú֟C_Bw?=}8͈:H ƍv:nXڜ߭ [@`%*خC4zj~jo\?{T )3YQ1 JS# NA- ɧ( ãI/3%(;k#^RzL'N$Kcԉ+M-F3=lڍsHY!D@-/Veci†l¬SpOețd.3xZ}#/I.%ofGqл+͓ A ёdxFEN3J`؍?x cƢejcK& ^΢\HJS'&>_F,{X K\X1x5MR\*΀Z$fc.\h"),/sk]f$eQ`H;3)[s{ z[8Du"4yב~Dy].D1kin.jsPkQ ,dpg)2a <]m9ڔ0c| ꑴ=Wԭ9{A<[Yp|cp"_SW:mai)!%)tSqB&W+k&#(wF /0ZWFffͅ}vIB工h2"a;Ƥ01j js;(Lc>P?WLu<8AuC@D}!I ԑhKc4,Z HˁNKxYYÊS)YȻOX~SJY57! axtn0K]vW;I'؍S?gn>h`8n{q+30D"Q!8 j))S;PrC1DZU[iiUԴ.`Mo 4t4Xޘ衽&lK <\a0f ^~Us8q}Dz*>I0w ݋l{&Q L~͊mNb/!?RzK״/>O9zƊeP1 v6[_!SYOXFV"MhU(;Dۭ A ]Rߍ&>3)-VJ~\舭5dT4W3O+{re5`Z~Ah94a e"s}=p6?I! m?*_SD"aXMK}piEn~8&E7=MT&1S8VCߺ.&"Ўn]{x2#R}^/:tS7\ߍ?+bmuƪ=,r&:/[1800@ NHN+U8'鈵[::& |akء7kÊߜ{mrVDEA|p*F%#FY"x綱f̭2]IbEi%<.PEZ.aE.i2g$}m1DUM6eTmL6WEX slڬWƘ^!jSńo= gW+!8 sڱRxߩI&"6Wۛ iq1^Qzՠf.P!S?5c1VQDZ^4<,cZiS&xD8fyqa]cT^Y l+P=iM= 7^6$*Me~kҊ}=4Av, աZ=+̢^>IeoBohwTDb&r'cvG=ISm$nU~%j)2U" mt WEqzR5ECE| ^ zEUʳҬYusl-&ƮFEUC1LO S G]_h_#Q6_-.ϕ6؈\;m( JwF9APu7DyZ m6 /,6G\I־kK$ݠp8OUq+ j'".+|\nJ"TŽ@~Z[^3pea([B5~V Hge(G_]1)RK<|I>j"OwZ[z4 屩sV|𒓰,6 T,!fV#^7iP\ # l҃׽-Q(zdfiBa^5)_2r fˬ*}@*0 7H} 4TOО崺MY7hmO>B؈/R 9;{H(]P)/NȺu"@lE e 0-kU42Da+߉ߏ'4!~]r?ܻzS9Yv`17ckE)D`"% lnK +Ϯ Vn7m[Etfg斚? )AgM{vm}xJ!po+Eĥ+|a_gxNt{leC10-&muOi-4ɭoFiGgOqB6geHsknR!izmJܠpQ &h+2<+49.סG.Mnzl2h*1b`Ff.qqR+~ C!/>>@~? vP?ڨЌuns uas.A^2^+52*Q}ޮ"Bv'P g?}_IM- H#7z%iijJnyuk]SZf* پv"-[x5C6!V. ݒ`w1~+Ӵh⬊6ѕoDɦjҕUK+I?ìw2"Nn4KO)m#HټɱyW!a Mzz pRGޣGΜH)*\R v>P6s& g|0EOD߁L\ՈL,-s˫ h3M=)مG:y\AޝPѠzܸ_\KS9T˚|9@rznr&#,s4!9ˁI?!)=+I,Dy_DZ6i'g߰ү]1ȭ/¬d>"bsd y[Qob8gu7mוLoWfz_:4bm>QBŔCרG>}S@Gu 6~DTAvuՎ"5Wǣ8WV^N[]M"]O7;bO̅N)2K6Jiށ!co$%e^͌mӣ!b`؄3<_L=)#؂;DQ()Q7 J;A1(ׁ赌oy# !mOsp~.ڢCZ gs5(c\eX7gj~(G끣y}&X>T9$xS <~ 8iW~^f*{=EIR5v81zQb hkksfuQ -dgi=CJ!wf aiJ]2Axybήe ~yw;a-yS;t&dP+$(5D:wX j?zap}Nԥ@aܑ=bJZ Ѩ0 --tbxG,V)飂"H{+[Hg1uqXH68TVI5PQf&? 2|[wQ(, zD4 /aE)_ `U@za(6$(&t?s՚g8 fρ۶) Je U8T;K'M˾kr$~f>1Kw nC4QCQXW˜Apū@F OWJpdߘ?RzSb@y*["<~x[5LD™Szßw27Qgf  ggkSRluqn*Yr{ͬ-"LIE7n?,." Q= =FCA!CzJQ'zNw\@|S!4(M\'~G^n2q^#^GM?Kw{"{D; ED{z\l6Knf &  Q zmVW#a3,p y:8ւllرQ^KEU /:QJOԽK]}6‹ni\ͽ3?PC(],N1^&+<~1$T5|eEw %}i]!& ͝zȗ??aRȚE6$`eb L|_!s;E7/6jI%3-VνZn7kw+xK_QG blaWV s'S9'6ZG$7D2yc q>| Wy?@zll9_R#ҽ@-T ƚ<~/[,e@9to&wGKI tP~0D@Ϝ}(8]S,-ʟ.UWe8,J-J8z8-uDs>;/`-6Sѥp{[?OBc#$㫕{B A}%m4)S'[ o| #>Ғݕ7"N7;'zZ) AʹgPYg6w e FR8 >D I,a ϓ4?:mmx/R4DXY PUX; (BǼWg>Ӊ/Q*a }wֻ RHX/[G#b-f39PW8~5EʷQ#q[KHfe;ՓJZщ!5ؑ F&$+k:b1ɷaΏ^;7./Q|:=Ф%L$s"F̧̿۔ceфR;qE-WN:Pe 2| -R M윊C1 &K^ d(֛?'Z gVV1?ַ(l7x3Y6K"LWTOCb) ɚ? Ԯ_,oɯzhp}X%K4ybD8Cyk=#(g}y(+Lh8|"W iZ.2m혩Źg3p}فiu_[sWr&|ЋOJ9aa %.&(:2,4\p&4ɒl(y^n"(qQ+j;nf]w/+dVR[Giןe:WEA4cmaew fȑ#0;I9Og)3|"nU:p39]x"sӬhO:yVR 1U@\YDnt=]b:Zi*YuNJw/p%([4J[A~lל$,譠\אiUmEls. J*~zI.&h܍0mbf:O{HU$~ ['m 7M$EzH$fv͆#Vq\G@]XVj5lIH(l @ALbzfFQqoCݏW]L/*LtI@?b8?Nd3"F(EC XH?*q[tgG4\w6,vv^>a&#]Ddl+O M8U5?'LqѪr}Atrп[I *\@Í^\.vYT$A^6ř ]0@KgmPw1i>>ẑ%'!,E΁@sX`D8I\$#4漣#nJom!ե}=jѤB= S$l6{֔m7sThu5vcgzbkŅ!|j[Ϻ<1aL'KVb<̉ z[>ᵫY%T F?p픝%.U>'>?$a:3Ju]ƒ0b*f?M,,7@ V1EYoZΗ?->;6? ꥍ4sagQk eq=kOjJ/Y⾜{qﳺNx?hIYɿ%EVO ^LHz$[j# D]g٭"|RQ~=IjkpSxze||Y Q6+N%XMϵu \Vyy' UsB&b24v1χqtWhŹZκA <3mv yIik?9ROoGP#O.B n5ȓ֨ SX~qF1=GNa^pT͠ m3Յ:v띷.\oNF/xVV'%uQu)Ѕn1ɒ LCXp4i4w&{9ruS$gdH[JZ~dm`|ieQ{!˂*1 b٭LA_ uUՔ'ϵCJuyHK:fU[@i9[&Bﲼ]_ `䒵f㌾պB!I|.DqV|'"EkrܶT ?~fPixD9MS$|^]rȓ}2.jY-nv^43Pzep83x&Ѓu )Ľ2r `r`x-@뉕pR#\gδeFyM5kl T5H9 Bb:Fy~ΪτʫI䲠yV=Ƶ`jNþqkWʀRqVȇZ%ݗPB'\++ ЄE4Li` Iݦ3DO^ɴe֧RB$L3Mw :pږξ׌3`ڌ/^uCm:o[P^E5!I<y fܗ\z=Ab%ʳЀ<ᖄ"qTZ[7妕Ip䠀"T/=t'=d@(y1c,-[""+J.#{rR+!wE^WkυEts}iD P< z/{ԗ *+=xE+.?;0✗ դZ1a] tųb LRO:\ nKeϊ Ƭ_2w%MɟQQ=rcDH,XC[lg3;KOP\.ٯΩ*~>v n 8CܞV07 g\Rl繫Z\{MQJZ,}&^8#L*]lKȻ:zf$@iaq]r6aX V D}]#2 8 ~\m34NA׽{N~L I!h @pհ QɼY6 a]]NM2B-|W0l~h'#DETP`?q2KjzmaH2(m*iC§뙿 QR% 2nn'$Ց0h$;_B|p$(U߉ NҲ~qOԟsrbZfg]S6̼61z0&ȇ/:osܢl\8ғ1GȓKڠ6|Ⱦ+Ɓ1P(DtYgnM,Qīwtoʶ}mY\EkXh<` rվr( Ry ;n=Ga ${Cm&@f>Ei xO5:D-,Ex.@VA>dž ـ? Ӽ}p{Lj8LIrC #I%;Hۋtydo6~+ԋFlbݰ8s~2dJ[rӳշ0J_y=yiN,p/!Kމ-ԍ@U Z+y*ill.kyemOJN1M]G*F@򠓉-/[->bk=Ccjͷ6bغX-ryI -NOl14syhNͼ$NzMS AZ/ 8aN%QDžH<Փ4 [I9=Vt xhtBny٫34&2m<\C/ Zͣ12@FAWL(v>ݬa 6}ÍQIw8fJZ6 u8J@XQtQ=$i%!(%c(ЕR8V,׌3oUr!oIK#{*;ճ ϦOK!.WۂG^e:zZu?&.vtrDX}Yx =OqLO /_nu,dcx=m{N]+GcS_>2 P-9CmxNxBgq.yX8RK|>]QODs_6,?!bP6pd9+UGċ__Ȼ"ЯTeujآUX +gvi ̲s PoDRi3YȲE ,0'gA;4iU 翀kk@5 %lL(#M H+KT_}<Jbwx4 a"|D6VAw pK*3RN S+S\lE4QŲ ƣͭ`.ks:v2IB%Gq$MXoOV{]OǺ6D0R*r &+1Aq׬W𰏧 L3rBojW=O1k?#(QJg,( ZU9]Y.9'j 7>Nsy[˖-sܼ,U'TjРrqpㅎ2)rcdjk.~QCR!⬣,iN| gu[_\m2P`@r #.|LZQhԈ oLsvڌ>Zn`O/Nsqth$M\,bE=V=8ii]ʧca[RmHwF}\,t3/|f+PVR\ʜ<.}Ϟ\5 u䷙Ls; Y&xB;W*u{>e9l~P[/W7YHΪeP? I ]d BBggkM'1>B[8:R۶9ƣvU6]) 'v/$YC9"}Z%O`?.QCO"/r''}aY@D^:AN0!k6.'ߜ]zIL5'rHsm,޽A0Jat QECOP ٳܽfAb֓7LQޗqQ[j3F;D=b^̈́+4#m*|!@>ΥH+ jW %sTA{+n4(m%GuA]lvVok^ nErUf=$^YeCP1,nNh}F Q/IφlJ9h[C:1idcç8WrmKk2QKuv5DQ[2Er)GDhwƚa:%w?~V;f`W Z . eZHU3k1~3X/RIIX,|{dhk9W|+9L&|hK 1dUhPZ^XvJŧEMqs #Q-(6wzJ/9Uug:s$>uj稞Z:OB,Cqd˙>IED1Dϸm/+Z!>ٸI -\d;ʼn}] kJ . <2aZuȋqB9"gxY߄T?l W@BL}o|0ON , ,py0}ƾ-s1rnڍw4N]!Y>5g;;)X02=~qFiBHLDDXp$y铸|H/xڹ!a8hL!tD[ J\X~UsVqׄߕD;ݎ?~jm}61m@g3HBTV˚5IM%F.T~[&\|v?\myI9$z'dB޻N/gReeu HE *9ك# 4|hu4A%hQB𦙞x5au7Ïgu@hx" vלx MQT yJZj˿{fQ9If]\L܈f;3*Mr?OHk/H x5R^=8 3p{rsr`p[|]po DUױz-jK"E|TvgĝdHS+z䦛E8YI+._ bӥ[#+dF ls!$')aqky UG"]߬ff40A]mնzh9jH*<|?^t?en:a]xm{t/-4A.Ys.6he>dgvRhŘzi^c#/"z^au[wƺ9*-}JHu)JĢ0be)C bː쑓 tޙ|v Ig+!g-?O ̷TV3KmNYVz?+Na%EEBwOa2{ F^|g# i! .U=U.ѥgyR pvkC>KjØOJ?ԩծin1}GzX 849)R_i@kdj`3\-y?ecVF(2qj~s:~3ťRC`uQzng-Խ-h/0bP pĘE%PKq(P[CqHV1wC~FXbV*iLS޶B/r=,ֆM>e,$;~V ?2^@ĚUˣP I]¨z?z(DL&~鿢O?%ވ@Um&Ҝ/cBb+ܺ+[&l"g;KAi%~ ͉C{"\f:RST0q.>U(B(dn:fqt nĦG:2W{ I5ίa(C\ Ls2fa:5V h]Ko`/sZ?4(eD#lnlCn7ubd3omG"4mO20eW-D%L@İ Ħ~hor;k42jl *8ѓ */x+a--X|] "QڛFciwD>%[gJyu!Y"=/`0~$q&^.ؓCx^(Ĉk«W'ȵS:5mNh 0"S,)O{FjJE'.=n;j2xgnhi2c&Ͽ0Jӡ_c="V>G\әO){A;\u ?/%%N.p;vڭw#IysgZبahIk"_Tu*lZHbCtv̪_-%C9$"8˚i{fgx[l(_ɦ^u@o>'}`i:e/*f{uT>,-OrѕMEdCX4֖ %O)nd~:Ľڼԃ2? q9?vgȇ&^3-2@?֪ʚLe=~pޱU ϓ'H;M{Osk-cޔDaH+n<)ef$STWT)Rt)o8q:Q%E\tqs7HKyUVJ\IJ7-C0v.CR2X @@ܳ>{-/ 𒔾s^tΪʃxa(nqEV kmD{9lѱ&?wU>cU_?fٶ0*95O\`x 1] "~7YI NIDž|/ne ^=aHcsJ9)YȆXATX){}!KACٸsNyea"Nhn]W"/|W©‰g9Ha Zj=sS*4B[eaU!.ݧ;` :bL/a!RԎavY0M&TahC*8RՕg?NXlVkEcnp8 lafkygѮK3!cexr'6 ,BnmIӛ' 죹LfOޓ~|*^ԮR¸}^^ [[X~`@ B3u.R,#*dc^sЀS<Bs=$y*8:eM p%wcnܕO͂luո-K(P@OI|Qc (wgD+ `D9Yt{H? !q 6♚rf}ާvdx\9$[Hr\^:9ߕKʿ$ީ|}YR:9"voG\9@v>*= b5 4Qv=vǃjN4 SdiFV ޤ/,#9U#SS`ƶx;c21SUt9GHCW{oL&_~@Yl|1srɉ)L8-z@ J i_K-oisbfҤ"!k (#0Ƙ0mmi6DmM?^2hשE,eŋ?OZfwj+3hEmA=7\ nGSWT0(5n5/9ZB) x2u~צ MȪq;ۜ2az ?w(Yx@7cZ;t"͟sG/x?}rX{PfX ds})vM]܈ꙭlb}DrRg&!!еSWԻ a֊2 &^^Vfrj3p+8+LM?{tgU cNOCk4nGTRDMeUmI?z^p-Ʉi}r0!S$[&췟p*f/mIiM-M۝@i3'淇?=\!YƤ)Em1,B_vC!ypfR),RZ) ٣WzU9/ͤ\CnMbg_f%=k6ּJx@=$spK4զMn( #TY:)oܻJAtǾSj kQJWNTߏCmq?8K05ObspJ+ZkPTƝv]ed:)AŶ׏^ywֈ5,cZROO<څ^yu3Ym!e DeR!hqtinPYm7SӉYxx:Q="RFxI}oRq(*X:y0ِ|⩅0ޢi (i ['y. u+3&??8ER!6]pPtGW${ U+˛0娻hM_R֎q ֐I~@j10SWj/h3!^$^-W /Xk*:IQ >!u1zhar. u'r\P(Ϻ}n'6ҍw;g0i`f; }v{]z `"DJfݟr*c "Vܝ/i9v cw00x!`&<@"\~NBaK%oW70xz=! t?l:-i9)]Hx{h@OdJ/"$̡?!C9*N1"/6yB_Qˍ䁕ZLR%A-M`;F |Aщr=~P!Ʉ-6W:Wo?yAP#t1Zk=W]ƤR5KV#\?aU>{-;4AwAϔFhr23b),FxK47Ԑ,G}$|PΧ^`x.'š[gC"9= @dvFvk/g )e$ c3Pϟ̀f KDd t@ NЖn >mrwib5?S͓Νe(* rrO .v ~hA@;e&GS-FVz N3FRYޥSv"]b\lbVbꞮq [h0f[]m NsW6K:CI:*?ZU&9:W{2E{qQbٟrHx[}3 a|=)#ɶMYW͉eiaڊu,FXoNp-Hׄu1A"|}`1 +鮅'z&L0  d+2ܔ{99<3;6YmO@Xv|5}P݉VS4cy@1C-Sk݌xbC)Z셁As@2Nô--vNJJ=WXF(rImJV &PlîZr|O.803IxCd*8,oU2CGvYDMe()(,9JXw!B|!3Nn]["T +j;MJ,Jo1Ϛ2J$99R%%!<we(3ջ8VLUug37:o'=us$s~GY$?UGwxVI0cq|8qV:ZSӂ"crj-\%[az>}^ܹR]$<[hfBj;$坌i)]tn# lQf; @:<]E!wmtTL]es{ҌFfdb|w$'LC##miaLL_FB)@&;R~2V=(7/שE$+ip'Q5RArzdƱzrS#`BPU@BnogJ~ET̻*4H@-VPmdWZ~!G*E0^<6]ۦz>򦖎6@A?~QA(.8 kE4]qQ'Ȧ(LG: D;P1_:*o2:6Vư^Wﴳb! 0R3PvPZq8a&*yeOb$)WoIXD|h0#M9uc.phJZXgZ~1FO z!IJӄ)#,qnzgt?aKZ=: _MgZ+!yYHpTSƋLY:e>leg: ط0yWXV&@SCNoL ٞWWyEWc' ʗfro>nfzcgSi_fkZí*tDSf6lu`'^V2~Pk}ۻ m 0.>Κ@_9݄ s0>2VWaۗ➪0;}yfEz0DԿHyy=\ER3Z}HeYNX7lE!øjNd&6SCvi2`8xQ`rFUK -WOgzs= ޷' qE\]xsM`Ϸ'A)4ZNb 5Hp%ԡ41TƌpC\q%pBsRMy $v(B "f5_Egj ,SC XDU\w%!99<7j(0'<;c*e)Q(a?1x]`ڌ<Mtg^sLzp$M3 '%QPB#f̬KFfpDNO@ODQϝT){K2j/FHkԭܡ(ψ7l"#/8CR:['VE;Un9/2"Fb$A]>)B"*tQP RF3VL졃w¶B +lZܴAkUq4|*ɼ{Wɏ<}%)I6G eyQ6ȪJ7цd:W1{&fohBN9öU)$FVt[,k{ K=&ݗ4 ;Hnd[MɅ"Nog܃%؋Aib#cő{t(.:ۖӾއF $rjyI_]dlA0aAD 0Ga*.x$:O籏HB բƶfjj* .)xu5,="`:vX\i>/OsԕVSܮjzCH?Cm,oQZ,hNܾKl jtqkp (gnNLQ=0x\?r@t˯|+&gY>MMa HW:Zt=Ҥ]B˒-D*q(([5z`':im[! wHv+2pH x++^Ôg1{v]-[m{3hM]┫^߷! #*WZ绳ڡ̬|J qU})0k>HKqlYgV䇫KL6NZ731)N9^ | Wa0t/(ɟ.r瘝V:[ I8&j8qzn 4$а>%*Nk)ev+Yv^.yeΜxN߉`$ѫP{t㾾 r":PPfO3lO,#QQ,SU UT9#^}*JP6&<v=S}k!9vL݉Ux fqE~L/+Zv*oE¬hdylP ܽ7n9BeE}n% @+2W:b\ iIN̚Lml)F}X;maQ~N岚/=ۦwSs3'd|yI;<0DK?j  çkV Wi݆ s6ه⪼U}{DI۾aaNpʧo]>{NRI VsS 97TNe"t厰넆cI9iɷnL*ؤЛt)Oyd9̀%c &Kڕ +!mJ+h[)zP*-<H]euf%^-FOS=n51h >MOLF7 1hZ.oϷ%O%~v?zo2.*JNh ȖwF%[)Rtaׅk3Fa=!kOr.åd o#':! yu(ʣ }OFn 67hd E B&kl+9#s Ur^ +ߖ?x̉Wa̋=2&VYl"^* nOI1;Oo|qzGL aw3ʠ_۽^$7jUy56v2Sڄ.)fvu)Iψiν=3It鉴JTe|l9c//pq Zub m?\1 LBg!n4p+1Pje˷:)% /|Q 1ivi#7G̍mY9rX6{Xw=ΙmXue^THnzϱai)M +G)1MB`yQwAMJ홲 Xpc]~Y^nU\ɺp [ik?\5@ƪK&ݜs>!6vҏ!?UEfMKi]m@ZӘ ED\2&WgΩU~$U?U}3_T!?&]MG3;9V>=@> k#j>5AD W3VdDRfZ5{!=[S}@dAэ<9)+(oPJau'PN 9 dd8J^pOKl=Zl~3'F/\;$vjz~:ۄ . nU20 Z>Bu;8(WϝU  ]@UBGZck~`MIŠvp-3TBtEq e`:to15j`$߾+0zrsт]LdwH*KQ*PmU:.w.)3NM1v|=va6s\t=ӫc̏캏#t/MLOyxny2O38&_J:IjbJPiAqu Ľk[3#CN߁S)p[>2 5&77K%`64 I h#m6PJx=K~{*N6.ZOyP_mՎ8.EźPtJ'U#StsL$@u㋭PH!vxw[Cl# A^x5syT8$ȇ6,M:J,Rrs +E.fURDlJ~ /1eG\ٲڷ`n7`Pv MF头*h0nҐCL\+&>YxA$wɋZ)e[|4):p yd螜y~vڸ,,D\ I}_6n-T&ɐ5_dozEeھf /vpOOr.>@PKoS+޻[m@r7i)b=r4݇>}9FdرtAZ(zVQK+<*9N,-\} UV{,mkKd~$އ0MB!2 {ZL-mdggV*!6Xt|sǐy}D:n@&?R h &zGǦp(ScNܴOgRA@u?QJd+6:)K%V@ ^9{_2ǟ[-"R3r!QW+t54 ~0eV h(oYؼC[I P_ςC5O؀2'Co"k;d.δU Hv`iˆKVB2eͭbp*|0bg| ;a*[j~L, ra4K JqϠCKK:b"0PGD `39nx mm6 =vV"jdv4#V)@ZS=^@d[9p¹s^Nu%z"n=^}?Cga-^t{ 'B9/ܢ~,[mk7_#fTRMg=B-SԋӇЉaAd!eExz򶒥cyHgFePע=yȰdVʊB)̆7{g{H.n> FNNDQ+zn 2Rpsve盩,(6FR4.6[;Fy_WGAY'V5h#ü# NήCM E)Pv_l->[Pӧ7|Va 3L팡9]?@{y"/^#Xgu'.!)N)80 ْ/v摫QBF";{قan$a8*ن>[K#DEЋ0ywuq= =Q% U)#_OKa u |<؍= yLD2||4)SL{((i93k2BQŨ6517Z_dƶMك7`GOREY_E2C-0oau< 1Fnܴavy$R//92@V?pAw }w# Fc=-A3XLP丐bW;W&AkiB!p,9`#:ߥCzCm\5+ is"C!/kY!1z)/雡ȓ,t G1&]拔`YR!tf,]"=Zv=}WjȭkEZѸ٘Pnq$\=u?1CG򙗸̳ޖ.ƫHO.h4Z*[^JE5 S}:%!IIF-C2U*`qP4$~tg5vo={RI/ 0jWԻU[kGyJ25Zʒpe5@wFȵRv鿚+ D-g~HUUK*Ƭf=fjW<`i$s%c9y(}3`#i}a?5 3Iː̴ >ɔ'Q*Q;Pa]RB z+9J`7 Gi|z(EU(4QH/13 @C{Wc9fyMpx=A`iH$wyLd%/uƃ(> i駣PΨrS'6#ͻJ ؊rCI %˽EvG2Ou;sG!L{㚈ܕ IhLm4Ѓ3zfKTil/)BIOJĕ ֶݰ9`??~}[2E wH_ Mf!1[i_GiDj2``OaYã_rF0Tܫ8'w@"(gl zA6ɯ b7, &DMN@O39-=^p뇤Zq|qhqD"&}EʑG~SoqQ&֐ RV=!3 TAuSk =.SdDV>]_b\H(UܽF񜿐޸?v%+? K4 C:.cՇ*>MLH lqþP$ E 2)M贫,9P_C, f{^ϕnc\`"'"u֠C6۩zڠX3&Z{=`H)(q}Ot@O˷Z #\]3)"Zu,Q˭{]AzbC( _~Ditgۆ- FO1FqdTL1$BA<;wCjq#:*wqO!Ţs6h> WafGo 5OY 8~F:ZMMz udNc̓2 ~zYj೵y#ASbǯޖ=v~]k.(g?I5a*@BdH `|cp"V1(Y Qz㸂e[1I_MY P6J8bБ:y9[m>%&Ӿ꺓CҰ݀iZrؙ΂EUBF21: YgimdL,S;aq:jHbM?C]ɷS ".Q_AK^LqpU&cQU@Ԣ+n͛Eey}Rf OW6N=^63ؐ3HB%O[N^/,`GO ݕD)4{^z>^IFBxyY o}1W1p"HMhMwL iN\➰;H2NPcڏ⟪2^t%b&k2&!sO> 7j˵x2\0ګ- ta5dxK֍Ny5){Aʵ8}=|X{@# s苉딟ne7Rք1\k (CD"O5>bC!'2e2ŋet>d͍ #/I쎳E5*g`eL:풂+%2(z2C,m@Ɩ ѧWbnJfG7FN_ |u$µ-XTu=IaЎQ2Uv[ QHv+I *3TmQ *uv"woYPQ&Bj @?43PR^`LF=d*;xB'x5 8<:ř7>{ {pDN4jSg9QŚtgIU$txͺt@M-Ha̸kj̚ [-@J?^Ůr#; 3-G BXz@RH߯^b<8ĥ ׂt69%'eiEvNr?}cfw]M 99 CgEfvZƮx=-cXĵo% DAxWPš !bX5e#q&%UKkk|*$l04 û14PJw%}XOR:3fOK%#EU{$c7a*v6h+N&݈4zX#Y'\ߗz808uz9OQlSNWY/^JnFEmZQj\:;L*䯘؋IRit=}:t)t[=`V,PXvM'֭tX0Ya @|y^ؙ ԍWrIo_ߊA(|寘A(M?vYO_}D8jm/ U(>v?kʃ'ֿ; Td*D IdTTvjDdѕRImgpͯGi6~*]?Hn xs;cL(CT~`2++kOAh5dx1[=~CO OgO`zClJJE9į>h!&v_ٶQ|fVr #̵iC|]Ry8pD 0mz3Ɏ'8ŁsaSG7g??3:|}ut^R{?ˤqL:_Y(k0ǯg=)w9,SRoe9aoeqr \ V~fhqdqAO_" (t2SL} ִiMi'!֎7 :x"TUiiV*u~}3c=$]%~\'09݄Mc0<4#*"+w<#r!#8z:ѿI~C 1ߓa[F׋{ Jl C7ýLPwl"gebfB{9|lhғ;3xs:1U"AN\N>]O5:DYesix"p֭cM_ ;S[ឥ,>~*g9i `E$n 6Exp{v V_Vb+4%O܆H[&!cZtע{5By-u3%A5(g]q_&w:׮"sy!9)ת]g:ls9SOβKU߳6/{# V|嵛eQǛV>\]o_9/4R2ɉ-x\xd1_D.I&+' J vD%ZG_/G ]Wb!`eF%PޫCXGŭK\\=uhy}ڕgVw_Ӆq$!N0:p`z#֫v0q.^@"IIi3&R& \ EVoN]?ݺI_izg\V44j|,rs2}r/ClPC˜:s.Rod Oa{ jy3j=_ZϟԐ+! 8ϲ/P񀍔㋍+:sPo&x0+,9f$ڮ.+&*iz¼o]k͋\JO­eWa X.G﹞'݆>\8bAP5pL[C$C$<{ivzۍm@B4Z4<Lz5 $x@IMh/D(G4/\1;KKg b b4M+Z UCry#||-U[$vq{+kU&:y 쏮zy(5@ہXyOlJ8lRIP>\$VEB NOwE7dfs1S"q*ڶ>6!*3}O|C/)Ϛ k;;'_H3Mig&<5"<9 ]5EK]'[N!!QzC<y=Lz֢"ujָk y7ۙm6ȴN2n[3/ҨH40ջsSLuXa'QN#!Mp(yHsƓa~&m8asf+5>8HZY*u*(qfӸnҦ}#ek2xb)LGn3r rQ̞$J &fA?r{Ϸ0n2Tތ`Qb3<݇ݺC#zʀ~|e !ijd+-!lyzo_CZ"p G']f݇N}\j*%}ۼO~#H;joHYAu!{F(LU+fBaRT1"kVkMs|H%M&)_+?0R)F2iǙwlK lJ4UÛ!`cۙf?G^zڊ۞cO*wsp6D)&4ܵ'̽Zxa2Dkܻada;9pHM 2 4{/;ܴ\r0^*C1bCHdIDdDdU/XK14t+czsR04>_%Zݼq HOZZPE $bJHJT2fx:Yh2 cјlƀӑVDYn?~enز:+T5JBߓPhIF5J0Ob]A}wkx);اUO2I䶈4.Wy./F$[|ks~u0aYO`V)]oaEUEhXqf:^sd)D+ypKƌu P& )BD9 킕kV9e8Z*&%JJ=8ӓnWi!/ 19='Ь ex\5|=OxAcV+1Ѥ-hH$ =nP7ghb*&.~[4]_7(|5]k.u$Uj ` Z%D3"0컪a8j*iRu3>ɜ(iTOك5qpCO{ޯϳ)x!4*`fd%T_rH搣7jTEX)T6c~'EPTPD4 5HW挞P1:Sx~|71^N4T\j6DDd )8qZG^c)~{A(xRƀ\AE.j *'l%w]Z*HPScXbhw`G"q%hE)T13Tɡ)V%=oԠtT,m]-i!2#E%k } Z @hPbP jGNI(/xdW5d`͠.I"H% JA[Ba&#]vRPjкΗa4SYttRGr;kDA5ZM# VRU*AUPJ2rADr08 @bۊ=K2Jhf(("H@)0Dv"8m;`c{<,?WyQC#R 'vuͽDØE唶cAO%]ÒrmƔ1vJ[VJ5,QyHi-7ӲkK3D1t*'Dޞ?QO2nۧ_t~>F=rB&6er ˚Hlۇh۰bМbL+uvtQ3Z=mSݲ %+f˼U*HQ˛ Fk9&92dpe,*C];ƲaIdIVPD5QIw)NBME'+B;kh wwSFJ;jCnh (kz!ӝAZMdFq~qm4m8Uj UnM2e D eYS%I̸ZI2Hww`w;t]p/K]R([PZRZQGb$mj ))h_vfJZ!Faw̗̋P v)U3DK5&;ј"G~NONSkMi`T[Rӡĺ'uIq2^KAE!DZ&#mlր:t4JNid[!Lad5Pջr܁ "t ݚ";D4u׵{{ͯ4rG7 \7rHCuͭa\I'D1RVk i5cXo,* Qww%jk!w.ɆVi DH@mYfB 0Ґܦ147"Kh!Y,l Jm[  YJ t:M tRCA1jN5Z?dz'(}!:iI|tv]UA[FSld4[D^=]ACAIA@|E%)XEaNzW5R}1s ((APrɌy6r;J+ZЎ <"/TaXad 2phO>ZK@7v7 q'dw&Lf.aYj#ūJ$жASZjm.lۭj&;+dBIrR5j˅:G &.7m[2w bh]K*f*dULM!kD*'a4M1 %/kĚBK&[;CD Ѵ”$.%&AH"Ji,d(x "RS0hh، `ƧR (JhI%3 2i.j4XBș -)@R% M "P@)E*`3ih( VNBi:  4$MqBP 4RҴ%%%(PE B: D&X DƐZBFJZB(@M.`B*"JA)(hb@i "j"jQ@ҴE+JPP4% !KC ҅(Ҵ1D4 B% R @@R T@PJt:QĴP RP(RRRQA@h]P4J4R& ԓHPʼnMCJ@Q@tiIbR hB& H((OrJV Fh (*$h(RJihEbtF,Z0R hiVZ" @(&evi3-#@/: hJ]#J$ dSк]0'XI PHPP%+tJM9*ABh t4!- R(SE#@4P!HR4 %"PD4E)@d@$MP C@ AJДSIMP@QJE @LAEHҔ#AM#IH(RM*SM%R"URBPҥ4!SBT-4 B+C@U !J*)JPQ$@(P+KQ)LSBJR BPD %!IHP,T@1- R5HRQ@P4"P4@P@4QEJPP%  @BET@M HUR%D+H@EдUN\,uN: :a1%B6š 't HGBikt=(ZJJkl#KRx@W=SX:B: x88d^G:ܦ"]%-) RAM E)CJ4D BKBR%DR J!KM-RM LJA%4D-#T4TPPPSTPM$f9Fy0Д%RQ@%DlHܘR[I@tJ2F+P5MIDPRlfj*)(ii*Jjb" he&`&&h ft&(" b")h MJ ZJ*#:MDQBW4P5DIEU 3 Q4P@BcI0DQsR0uM +M#KNHQw!;d$KڂQ4_Ƒ))Z) NI<$F4;N2S `(ul^Sd1Վ{.=+T!BJU-'K҉i 1 4QBS@P/=td&4DPPPR#IidZb)$nRP4{ s<"rh!Ѡj0JbU #*D\jP neWlthš]u;gTkWTBVerҴE 4 m@% IJE hSE!H4QT4Д[ T*:hJhJV(T(*Xii hi  ii@"$Z()V @h`JI$$h {@Qm(H]nw4:$ E%mjJB%-AEST+iC@m)AcE444!Ph @HNB)A@KE ҴH)CIh!isԔE Vͭj:1BF,kl.t!AB4I!)m@jV?MP;*j4T1->sCJ,45PRb B)"d4&Jb&KTj Ѕ& =)4"weOE$CK QlMhXNc0|2IdCMҚ kw|Ґ^yҩkẆKOFX>@H=@JO@kס=AAFAJq^i+,: 6?! E9Z*b Rj ZP*aFh WRTM)@)CC*PP="iX(JE)JV*(DBSlCK_EzMmh`VB &XՌBe+lBKLA5A*5b-f"$)t"JH]Q@PZi9>&eɴx& tCMADUP`=GBh@ TRD)JvA4DѢ iMD*R6i ȄFINs(. ." Z|XZ]TɧOтIiM&BQE BLibJiZD D!PCltA$)eBHZHi Gh $R4@f4:tҴ % ` 4mlD҅PDP4 ܚPi:Pz!TЅ" 45B  QJHM5@*PKAJR@!E5HR@#T*PRMU JM,Jd$RV!%!@ċ@-*4RҦA" A)t) ½tbtСETDHRT҅ K@@QE)H%@B Hfh LCZV v$bHGH( CO@)&/c?`1$ȥ(P~x>c+r'R̢}@wǻ+CFĿ[wyhsF;ucV* WPpN"X""i&a`%IJ*ƭ4lHR &J hjbjj)&*"b*ABijfj*Y(tbJ*""(*!#]F;`ڤb" PI1VZ")5iƇU&('`Z+DDUTU]:3$vAAM-IRD4,KDSDEUU12TTLtF{a%*;V :Y ?Tx2L%EBSy Kfh*mh FhhBD'YTĉCi/̚*x uې>Z[vSvIRVVJ!S VIxoghQh[G,8Jlƞ ҚvQUQE#֍EH@{tQQHfH-sioi-❅udchDœy/C@縎xtC* %D $ 4@0@KTC1U RL4PA DE AETE1@SMM-$5IQHP*PЩ@ҩE 4 B"%#44*%P PRP(PU4"%D-P%D- Cc'y4BIJ)J*,B!MhiC@iPZR( D@) @JB%R tRB4E]T(Ҕ/JHRRQ R!J"iIB QAE *҅ #0+Ć iU)F*i$ :4BihJ(h@PRP , דrźn^9 ZR&B!ǹl8;mמ{\ƍX{zq=kٸ]w&}QZׯguS=j gF=4uwn1{s;޽Fo{'}MJc͈14KjkfZ(Y4@U-@)Z44QZ4ŠDI@BNB)}DAGmml\n*4ΝAQ0jŊƱr^u 4P>DWҔxa: ))iB:]r:JU e$B4BSER!E DBb4 B!y8 CДPh4iCE M#]M"P @BlA()@6i)C@Ll`"bᄀXKBh +PuZWI2QT B9 UW63[&$$"Hװ҄b TQL08x OIhЧ`4k P1S@W@tj^Yzi)C# @@Ij4i(J@)BLBj "HM ZҫHPiI %fJ1*' ΒfvGl^Be U*iJJ퐵R4̥(Zi~B7KhtO]$@BI)Zii)(Z( P(a`ҴEB4HR+BMP 4JJPe4KHЎ'D<>@lX4&Sd|<( `*4 Ҹ1:)Bik D83i ("+s. gO[%جmmDbh %#<9 I:0@|zSh(; RS0R'm$M*-*+JNѡZP)45 DU"Th(]5 +(ߞ T4 'K:Eut] PP1 Xs4JiP1MvS ] hF: tP44PҚ5Z))4.HT%mQ3&jetPP@҅CM%- J%iLV(@ TiT PpA(J)BZ ZRpF( )0P=@CzG bXfA^CҝP)Ї߈zCUt P P#Q(SB#!BöFKng5l5 ǃǛ%d5@^P8.b>TɸH2AK@RRP "6Zv"SvtiT<{i86"Ck Q)&&mݻitV5 q(!qG[Z(N+v㵴PH% PB#BST$7dzrmtPT)8`"h(E .)( Z@) J k ,mTm0tFH4(tD~N*@4 hP4b!5c{' AgPAmp% DlmB"LF )4 *ѶEDḥ t iRV!t Jl*1JҞFbk %(t㶈h;CozAN= zDE(U*( 5(4*}'bCӸ*IBdD ] 9$.DA!&V%fO(tRC@*&4R _}S4CTkA$4EE'hJ,mBbI J4MH iZ)$ h Q[(h:odihkmK!z5@'npAS4!КZz %T`i;/OWj;"zz": 4vTtZ Lz7e(#V>1 MU$U5Mճ5Ӷ3'F&I%((چ4)źmPu;[눻'l[hFMN*W4!5UUb`' 64`"hP2IQT$17Vqm=sGLJG2[E(6CLӣ`3Qݗ$uzET􎈄"lvhv 4b) PQt!ƠbJ4D4()$tO];9_Qv11kREE**!ҙYڵU-QL SQ S=h`5FН;AP:\@k5l8"д-eЍCȚlj2R¦`4 Bҩ,F! J#MRR4UHSH%*YН 2hA)P4%(DE!T4/IMɁ$ *{> /pB P7d1MH袔ҍ4U aOPƍ&(yv[[!0IS>Ph]$ Jv2k䘚ZGBz!r& (JܛLfQN_J `aNJL)Gp҅)pRRq!c&& )t He4`5HP* ",JH4)T-tRt9J-@̪@"iPZZP(@  ZDihxYt 4Y`8$4ń(&l22M$yRFB*nI9Ŵ&屆-_mףk5"  aW,;ޝԷ _Ӟ6 r Tˬd"W٧*[B5W32*khJ6@DU5 u":őK {?aQfK*fQn{:vsn*h`ٍkq!vo/nu۝@U\z7Nk1UٴmnփvEwt];wsխ GF`Dvt @ҔM7i -*yZUM TZlX:Qj`N#A>$ch1DFŶkWWN] .ȃH\ĥ$D^OqԸgp*5ƨ Իnr'Gutk;U%RVrc ӆ\ZQrB AypXG%囦6a$$`i[m[w WwcXJ24¨#mmjUf#Kr"anr$d & [V%wr̻ٻ}tvk:Ni12\ر ˛y7KvY3 iQb I#v+y.0ħ )]6V7!,dԻ@pkC]r`t\(.ktffi﷍$=U0P?2RAq*Ms-һu98*}(Cގޱ]MPMIw,Brnls# )c* ,-EՒ.ILfͥ-" FE˲.Q% 8.VO|axQWX3/E鹦԰DQC̽p/u5 kzlzX^%|ysq"g!)V0 X$q9?tgN9: ?}':%)("AF \s̕┸oWk^(udel*"d8puCGE6!H[1mx-h#TMZN1!XIbݐυ>kswvZiY:(n]Ӟ,k@B,Mt1m728ojGyrc"%ԬB1ehNVoN\UΓǯW1lwb F z`^YOKͬJ݃l:c #wkc&ݏ=/dyM7_OcfDhԩS*qm䛗vB:dݗUجG[a)94!(TupC4{/4U7 ;ԑ^2Y81B s!1aQ x;._M@[Ev(,,Z_89x7uA;8P _+@~]ͳLn>2~q.CAiu0U2J2yk1SI#Յ.5ol`wCNJH=9œe,'5:;2 %s^nE & 3, ! 6gx2𝝹hq &2D4M{%^.3e+L©Aؤg/9f_)qR\qH`wsp|jNv|(]'n: Q]ѻ2&]_:E0λ-e !q)iDS|nYG~f;^Gɥ[i|9-$+Z3x76"6lE<}0eC;{r ]+w7@󯠨w9cd'aKq;-MQ%eP\ΏqnĄʴT.;mߝ0;Gzw2ٻHiFȆs@46s݋|9T||Ա%n deou݌(ʴ@qS\--4|l\L0cmfn=W-hѸP%U*֞'+9vI,![P( -zކ0s rOs8+)Tfg 48T;EQzzewvӜ\p+DGk)]%R c8ֳ-rȴO^!a'.; )d?svIuOpuޢDZ:9}5u(jT_5sOoheY9|rҙ7X&H*_aGyX&}cH 7oC _-^-Æ=By `bT9NC1ʨ+9fwd3i\:E#z;ZniA[󙤆 1Z=ՊD! q@V@_ ۙzMvвO9Vl ,廻!s'.Z;8m x!o55 9$I Jy|B qGάYxD|- pfƲidsHj 4rGYcB?#+9^H%6UHjjIxhNrޭ`sMB 7čquk6v%un#m7 6;,~tv܌e2DnKdUbAsu80{wQ'wp,7:L3H'ϼ׆E6ƦcȤ᜗}Ν=bp҂*h }ܽ 75ac\xWA@-NmiC w;q DMLZ^0v1kHP$*U"G:[Hp8V}yØFY9f H~ܱQ>2)34xr#s#IGöGԉvJA,䲐|{`p5sW &[+cjM~T3 CFiT ua ַ<"+Lfh0rڼLːF4~-AggX@-$T'dI  'lkA-,S|Cg"׼szf<jsK|[q1Ũ7hTnK[kOoE#UN3y2uw N mֈK/sP)Tb b$NLB|Ķqc {CYbرAݓFb-PфIhH'埖Q6A|MHUĬjLTa1D`X*5ydiCX(N'P繐xuPiz-K ŝTv,FFEglR"% ϛN_uH*fB]KŠ(^lX/뇌88ս@oHb 6˃xaPNh+sڣ2Az/_RԦD" \!{y]",DbA&]}y5 5ʃ^g.ޜ1/@[w81 7j2$ίwLj.H-F7x2n߾?xlBVꨀ}ʓ1rUa&dC "DC1b^rɔEfDi s\iVdܝߊZ8_7.b SICg9H.7CK<]miLNe3o3;|jj>F lkQY!d$:O8/=K1?s|X=D9jKw[ƎlXq >0\z[ EmT$b&ILPs9}N{ed#2,$:rƖ×Љ}Go \î&'-8#9v c.ID.Mg:'P+ۀ>:MDjP$yGCSAݤ;up }F[KI:y9u7ImbA?Gn^5J6! Z Zs8DͿ?od9p!~%wTTA)1nC:ZF6仓!\l  |dT/Uk\_)*(^> Ő2pI4M9sܼ{c{asglOoo癿(Wp/>ƇO3ADmCf l,jԨ+eTbJ8P[Hɏ,UILQ8 dI(Gn8/ Lk""EX>u4ME85s`?_&|V]>LHM(dvsIppݒ>}t4=}>oY>g$d~؝h0kӾ$k Cwt<61Ew Lkb0hưLJ-DR弝٘>Zإ ?+>Ϗᆵ;yBx|d>*C)Hu ĵKn@+p[];ůۙ}].0͝koqxgh\`\vu/{2Mv`ݣlnqS{B4Ӣi awHg |܌ÿ5E֣< \wix;mn3a&0q*#$̼DAORs#mo.lL{o/MF_xTڝ q ݀8> ˏReIY:2Fe˳jfɪIP[kyyչۡ0=N!AGM _LHx{qox !D ;ơaMCD b7sp$#oTRP\HɒvLCY/*jcK#Yo"ĈqW;i.X2,OaēQ'V24|u`j&B;Yx/0MR8m<;4Fne~Yl g\re|tCI#y)w̫s{M"mqpt;!W 0;/97[-曾ȢI!:jAq 0|ΕO|UvDzxTF+fY sV=[y Ei.m2 u`ΜmWyk_dގ,+9R}~ye^v<>#oNk}z ay|'ǣFێSCe&~}~SewTO6R/# 9ߥ8R= vnޡ/2KU|@ZX@Zo8+(5W_-NXֹwV!a+ pp3\.ѿ7 94v/A{ha;Ң;܂,X"N w;YHC\/aj`NJ+|GmWb*uaAp2CDK2XfRՏs &v0:$ [^IVފ glra)m^&鬹2\|?ga~fh!H *:O|KtJ@ 3 ρ$+"}mz1p2X90# 5Ȃ]lipI\PNhLBx:KOro%bWx R{۱0˂2Yx:$$gg}<7Rh}2 TVP,g5Zi^PԀ,ńLV@$P\mM4܂EǬy"m} jGXJMiIV-qO JVkDͽ%Ea Ud.7zsӷ}j+( 4zvth{,Y1TN)G!iI9:pBOh i H jT C0hњu]%\ 6'mWO;(Mxz!<*[w%$h}?sڈ--I>AA- J [k,j)fZ 9=oMTX/B7hVp(g،P9v< ZەXGcFOgGlªn 1m0H0rۥ>,"e*lde8@91NK FD"$>*#QBfH%G_[k{y^=>bƬ1 cyІF,ln gdg''Fߒ"tHkyzɢFB[EZf'8nyƷaYrѲ[yޚ䬤Pb0L6x/vDyZhGN^yN} i=bݓlէ):@'1 v-=]3`!`B,"yb ́˃* \Q b))YEZBB)a$H&VeC2R:8l‹RE2ր[.UDҏP% Q+3lYѶ5T6ƈ;Zfbca&%,ʐ,#Te$րX5E|üQ)$(S Ƅf.0bA|hE픭iJ^ouud-VciWWU ]eXTbq ae!J$QxHѤ4SB$LJQJPT)@hMFJI}#ܧDl!턈{}-̄s̛a'C kR(4j Ѕ' * NvZ- &60PIʬ&ƅKh ˳KU=KCEiA@( :C TJ#Ù N0dh&C(dD8rd365Ўf4RL )hoHzh; d˲ v6}j홇࢟Q8ZM`Eq[ 8"%!B$rY$H&$]fU4'$_Id$1q/?i9%ae%a 0b+_,$ Si-J"x~xx=#S2Vӌ Zd" &BZD&!iE C{s|'Ȃ)iG<5JJQ+73z7k>z]&|Lc>\-άh PVIUl p{{-jN0>=>||e퉰h}ސ{{=drA0*h}=g2ѣ6Mk;orvKqzn;hxK"n{<NvjuݞJMxw^] v]RPZH B{H`аM(%himöFr@77v\\.qM}pw|TI4|ޔ =(@(>muܖW.YmOTUK>Dcs@ٽ{gva_o\om}>1@Pyûn:ƀ@@}<O-v\ m}8uNҵvsZ6(á$[ww o7`1@ c@hw.]:iAF=x@}P[`\:=׻vyXkZμ^TTy^xw׫ޗ ;a;[- }mutvZ]}QI^}<_}ϭ[o+w+{wmo}(AJ(|(% T%;꠽֜v^p8w7+|4DM@&dhCA bh 4hbh&L h xS F$4L@hIb2Oڌ2銟u>+ߞ4>.kkf֥ǻTSut|NROoO&^zǏm?x7{a_QyN*pyO-;''}֯kjVG[*ʟ5w+>~eGSrw`Yym~_b3V2׳o?^fE?I]]Os<ϫou0[*:Sp~V=o :ŷe?]Lbj f2{Esi%wv*'5YmTw@b cHks*=.M$sz;ϒZM籟끖ǰCmLH>mbF}ߝW5y <\ep:Lx۞˻ M?7WC%Ҷ֮z_GhmUTrxهϭw9՚J] ?[]E;gΩ7rXZk|%>_6tގ3w|L;7f~ۆr+'Fjfgt~`uh0-zzʃr>+ET[%_roNa5 ;} jam]N{1YϠzѻY\.qt.3>3wE$[w 1(+3< ;*`󏈈\zqHk|_栽H!24I5ݩ_|i8?7춾;=مC/1ژnM= H ̈tӈ"h^! _?B?*|mQ>L7}{~6]ﵟzYT9˔rЫ}9jC @zh7kB+d+C}vC@{|N >" ~ۏSmw `҃ qqڹ j|;5tз ,lYE.B>׼xB !Uc"\rsKjIpLK 1ui0)Y=?c쀥){d)@ t[nOӥMѦj6n+jÌ.juڽpG ,Pr3Fp*q{[o?&>O3[v$sOeQ~WXop/=] [u=CpwL6DJ\tퟝ|/z΃-9`s!t69穢R#dr3Mw]NOl%+[G[m k켈9Mg:}Oq364{}My. s;ywmn5Tp ;|?}"Eu^wW1EvZ&Ӟ=& r||>)Ӻ[qVjV]ƯBX4ixq9 \ϵ@ %Q?#!&dV܈)h rr+ \!WG.,_!a!]/k2iuWoV5k n:VvOxݷGӳGw=  N3wHF**>x$Ihx幹t;#V+9VۃQs\kɢjWتF5a.i1LYmwkjwH].yqIۑlwsc^wmh ңBJЭ J҅4%#5&(9%*QjKh,W]Fw5..Md.JP%I-,ɜ$ch̃3TEZ-h-nVW)rp(BByoDD-hw6RUtؖLصkXܶ&Ue¸崕ֹ[s\QhstMZ9_Nٸ-n;s$մ`PmVL[QeeYRr8ENv&]݃%nnT"J-\26Ym˔,m-&d.I[ b ( su֌J"%j\640`2rkqȋTV.z!yWqͿ;kaD7H5j͹I9Qj5@q1c*YS#MQ@)ƢaW~GضTiP "# cg*VIj""ZRJ6@ rx_zͻuR!ń.&ha Ije.ee<v% ^:D t3‚fYI{Nv:POֱBӔ 6G.g4rmܲAEִӳ[hWw/ݹ6^S(L)%]RRiÅ9U)7$:t8o&c2qyodJ˿=MZ-H:|^R̥nr[7Z,|l>q;kV#ALM^6w wp]Nj5rv9UXc/믳3[JLUnޞK[9[g%QW)UKbͤƑI>E!a!CRHBC!@9#`aH`d#PoK=VxTsD䪱~7{.Ob.l2>=Njo߁⍅_&R!(;bHD- 2Fh5]MhB#cYeDPwvnl.F LZ fRVVY@ +@J9*wtA#mB Z-^]ͻBݪѢJ J5m"hY] +m I]ݣX%\MN.,أmͣFtg]]6RR2JB( ZւHJSѲD2E$d zy@rJIFۗ,6Z0Wm^*\RV;--ΩnrhuV[s'fIeuvwp;rrrFL+dUѵDQ2\`J)1UjQIW5\lF,k5˅vÖ݉wQƚQh…;ssnծW -W"lS%sW*WwhT\mEk24fN)JP$sm^E]- 4xSA5͝ `]d@DH-dY*JNk&2kζ)8[ʟ1*8yn8w ) Hf b$a$*HrL(KYw:ܓcvUGv]7CVxw9^뙙;s`o.M|~-.ѦG\(/l_Di&o&wdbyζ3bX(f& t_i6㛆7nS¹/'/ѥm3[=Z)+l7B} s9ǭruKⴒvJAZp/#YvS %g؜cMC{*Gyv7TQ:lhNgʉ.4[=o8XS/%nyKɝ'-t>Rnzff`]6 )8wM+biO1Cd5$Ҷ &R"ńWk}QJųiMJ6ر%W*-aңm25QXQ2Fi%ff&5(d&A4QHb(F5F"5nnіƋbٱfUͭͶeѡjдlٶ D‚Ě (f2ɱ%666VmEFȖƶ1]:F,VllJlQc) بѣPb `*&ōmrƒ)4&K-JU]Л-TƟTM( T` *R*(q&H $RRB&HͰ ۑR3|?CLˏC҃XF#WAsIiIeϥ`_{t~{Yg'Z |]}^r{k×v1yU9eVamU^(ۉjr{n}ǥmB0@cQE&%C|Zli;3EBȺFUhEы읶q\t}5y$hAS7c2SSf:sa>g;s2$vUM%O!JZ%OiԪfW`gռ]Gs׭;,"?atpJ-lӯ-EYam Df{y\6N魫9ۊ׺,kp[mL9^\vAM-j2MnZ2b C)5IFI 329fPVS],_#usj-tѨrt'VC]?|l99پ|ܕ**б‘a~I2hav;c&G;ͯ=lL(D@2#h:|֮זҿ[VӵILY:`l9R3O(v32B4@&kl/ HR4!ڢԜʰ:hXf5CXTLaICHH|- "C DMsA$oI3^,U膖GE.&zjTp)vZXnO|`E fk5 HvԹ%:[Z|_EϾ_7 x32!"PJl0 fk/06)8XX2×9^n-5SLQw D&% bk鳝d*'\J)a>`S@>Ge:!ӯM?ŠҸw79m[}* wmq3_gδ 9;}=ûlUl.V+H\|%t?s[IM)۷6t}$Lr5v|N :=J4TlskMW;IFyZ0Duk[;ɰ{{ TMː"u@0N:1Zڵy>Jms,=}+X<.ľRF Y"yF "#2tj JkZ%v \DBxM99{GIlߚ҈XK.YO{?hXȈiN:3le Ǚ3eb, 4_3ygkڢvl<c=ӊhRЯYسTG{vn^\apz:E gnf[Q|( Tq i̦qI1(X.q.bฑma-ju(\wC\~ 9s8%b@2\>nΝ_S U:r E$HK| u\jYP^[;_ퟙ, :o;7%P;q (fܖ4&oT& )hĠp73րbۂ4=D81%!J耒B I](_mEIČx^Z"J<۩6 v?B"D@ wꊯ HeTzY"D:{Lz .TE{:ڌ7&,$7;<뼾wdz~V)!6[ d(d4A0%٬X Vid-t"+!8HںVD ^lRw LFsӯݱGɛ ƌkabPu 0hC_/fP:̪éSqE-XD̚^ 18إ fD*'-8J[fg y?[\»}:tܫ֮u5j5}͉lxEŒ[+~SK+cI(&KQ}%%KT,DkҼ w7Tұ٥(3.4ZFsTlx:3۝J׺ep0f>Ym#HtZl#>~LH:'Z0K{EgbbWLtUU㨚 I La{oXjB)Ȣ2bT2塖X 0 5Qª̌#l#-'܆;|{0N#1P>IREj҃vΞ:2 DNd!jYfRDd;Iia,*qm£Vq3# 0YzTDTZk?E2V.4aCSik[m)EkJ㈩QS)z+.[JąMwnayFm[ϨG4lxs ևd}_G"xA!{w@ѥ䨪wUǜד2n~;d@R$itƒĪ" H! ('`m!ņU)x u:iLd!V-hnnԬ'G=ϙ?^.ǃ/l ev#'t'VQB&}fIVIWp JQE Ій%Qa`&(4QG:>t7| Y;$y @B4PPR ׆ytzh'AԧX! )H3j(رm4jV+>:)nc K,B, Gxw).ut4AGh"5f` W7Ott)v[Ң[S!\Jrb&RdKkZ4*pƔ̰ڪ"Xd)+UaYZ& 8d@DD%8ݳ-Rc,A3#Ͱ|qa2osmb jp$0خ$Q2DK& } Oew|yΦ whw1VDg^d' s8&,QH ěi EꄤaMB E(,އٞ|E:q̮&D4ogn}⨾q$ fs(wVL,TJI+}fyAw&802 Hǰ v#R9'+={GT<}2r )( "YZ*6_H=-ܷ/=:]"i])|*5F[Ǟԏr.@aKYP.7ǣNf?^}+X"ܹu)嘹фD<='][i/duzYGWMhL06v=|t19`aKx +]J z>=כFD- g$U;BRDU2:zr]z6JE#9% H; ifLc =T &dW -zGĊ(D'iXkqtT+@o>0]&kĊfC3#Q&s,+lUCnpIB_:G-Yiw,~TˆvWIVcT*ӶYtæxxr1%suγs53v0*poA$'YIt:w/]Ӭ^aӝ1SRŊEn`MJ2 S\G {O yMy[ǔ`~4Q4<|s>#}M4L@^T!DdP@ƕhɧ1MxQϒmeSeݺ$0×iN]6XE$ [_xvS Rk?fdK<}nEM|?ݺßz}o/"f( paɑ_G꾻FW.BY:vs̮q]KzJER!GQ SL9K5>nm*@=_e@9LaUb lQd)%(Qml`u4]嫗h4lYEQdTUkLْ6clhwܯ8䪏754Y1 c~si*AOiG [e[i/'sZOa 'g+@Yals\&_&PRA6@^D6MI;MPP%).\ R7ө -Eå'W^uazK/G=|3RP_*)o2j cW KUrQ|Ŝm&;m ƇQ՟5,$mDTICLh1\2aֶHL QQIn1]qsnҤ?d?C)SCf氦Mo3r՚f:P5v}ef=g2ZgvSytD*3聦q=|:Y8A*Yhh r :/WTh 󡉼CX RR1 Dh4=@N/ VRK^u(6\a Zksw=u^xo@c}g)2]IAeV'M<7ѧeVk ̘"${,Txxrw("7_eb3mƎ7L'Ŏ'=Gc'̃J*2]Yx.t'fvJߟa{Rxxo ~_t=~cf~DvԨ— Uh`64}X&ҲJ_v$BJ=502QQJoWGE*ۙ1 "XbŭThԲ]M4£a 25SI; {ں}! ޥ)iN<~oiLFf{;];F`W m+݇s W]'՝Fj|[5F-6ԬjF\*wwaVaԧ-:8xE8Ug,DbI~fbZZ =iLYKj$I$-u%D2c@Ϻ. 1DYƎO,"+;;Xs9<ሂZsZ]T:zX_>=R"Μu&AD:[1L9wq N"D?k `/0Qb3DG8w^ w~`@tz;!?O1VI(Ɉ -ĩp:@0a8 #$Yjwx$EEET}?_옟_9&0 ¤ݸj{z!;׏9g<7};LłR( zX^; Dy|y;zNQyKmmLaC*Rc+ h0>w}z~oKX(e:mrXTF|!AE8laWl=?? -=\=!qfh7<=!G Wpp1=|_Pﱋ6~}y?/M)VS޿J)~fΊ2}G:eb{멁;=1947"7*8*ta|Vk w09tk{PDA]v"xuӯquJ;8/qO~AZLDT ìZ5Umm-V/sxfC^>q|;$QL6ʋ {ɇnZ)n n (Bʩ Jm]Ss`zyOKK Ep1އs낈Y[8 ќL6o e/xq.N8w"XZfO5c/l.|@i|0Pg]{f:|myj,`f3k1T>9λq o0RwY _^̠Wêt"'~s;`s㯮pK QO=$g>aISG{Gqɹg}hnј)9}SQ s2w AAxxt΍qS{pmGi+{87B}g[`>>NZVwu }||v*voLk%N%IL։,9,sry8q_Pȧ룫=oa_c燯jMZr>sόIme~wBƼǙ,NC,tMkE0NFS5[]5R\?l/g:lɐgrKy2M ܡAA(T?;MfO5~oEuTrq`y-P he-p72Cs'a&Rf)~~b*^^i?|w}Ī;1̦N03" ,猝d.t1X|pO`$"ֻ %nNapWg]>l>4aunp8gW?Ç/Y֜)\8/vͣ*',NNv|xy&Cys+W)m﮹}hsS+-uôg%etpJ漽#Ca[SC[i^}೤)O1s0)">&[J9~1?Y1Fv% ^nL<[NeilCt8Ύ)\s#8uA]/^t+|:2ti疇'VPq ֦h|oAt()fhԭ:-mvhwԚt~[rv'?7m̹,ύޭy_7&k̿g]z;<"㓗lL3p|ϟ]SNH>f'!Lfg4; tyA{g8--G}yKSs lwt8hc ^nlfV 5:%z5rznW6nՋ:Ŭ)%wӗӖÜ>08TXT.};:\/$"}u{M6}S*Ukpq/kwOv~zKTaӆ5/9G 囷?97W!`gRtЪJԆm0ff&&=z}7̐Ng^Lzzꬥ qswif뭿8/H(cR钺׉mmzZq0f:ŧwCm(fBo,*c1*gŧ8[Lgn:*SY))SRۢqӮp3Zsi|yڍI徙sjRCi̤ݮjvԚFXOݿVtCϱkƲQuc1inM/O)3:y6kL2FBv@߉Oǔ ,gͦm=`'?vy8^P)WhT6ՄS<<'f؂D>^ W ON(5ÖwZ} lÃLams@H~?)P ^リY2 q/?/D! 'DAD݈'4 h PG&R>E#UG;30ָ6{Wd슽R B**+%<@")&`tEY~ph_vqɈev&3R3UTv1Nr KjW"_nb}suszԺB Yr L2􅀪z$1 a9zrSA$ii a (l m w\d1UQ_\㉈={g]J%2E]>Z_N1WiE2_J(/[zW16"dP1`\ 4L:uDtNܗ;u'SM) ^|)8I\;fۉ,L]VN%-|xwJʧL=$8{Ys;8]=u0ΆmE0Y6U2($bc빐/Wi ғiE%On䓶ՠby}y;YuoīQ"vՈ*rFt&_bˢ X,y3(XWCr:"1a1IBMO;`opPIOL)&@,=>"סo8CYPpT$jʒ ;@N!Ih/jRusid'l tq$hEwND@Cy]yB x`qzR m+*o0<2 I!׫GCTfV".H[DB,DmmKJ*QSG"맞rQ] 垸̨@)TT B+Rlp5LvXۚI$lZٟ]afu2r++ OS sB;9\cAo' Yx*e?/ )킠y /6Y\>QU6T|h6,޲yٙf9g1 d ^PyNr|BOV#33QAT0qdi4$ֵmE$$Q؄P306C@¢E!" HbJ,* 0H:VmiD3.. qullR Њ (F Z oxa5 ,F/Txg]:LauRBAx)Gx"5* **@'I h^X)5;(6:kBF@D9HDVJ E$$6$F3( lA1$122HLdmm}ն}+'y7Sb8ÃVvjPA_-_]ZnzۂtQ6q9 JR;Cg޲Dm#~_l|XUcQ e(“h!̼&US!ICD:!ӁEU(E5Z-bhֶťEDNQJ*QҌE2j@iTIS?#@"^iUQz DGJwB=6 N 9.>6ֈASRRSw4IBJAME=+٫r1T9>"j@~MlH//7@JtlQ s D@NX@C=/9!MFis)ryXFk0Q@{hk>@qKo;sd\7ܧ7ϚwX|fc{o */o^E5U͹ Xng iMP%FVQo2ෝn}ߡe0͎[9~_.tn$$>Tm@N1i|]"6ʔ~&NEPO!o-tswuɿ]ɹ@RGQJpH?ڶi B-ՀJ,R=-'mG/ySI hXk)q<ܶ]Ya3-zS(l0>i=COOi̞CnJ96t JOYuqa&*tfRfGI'cָ<HAkd 2o[&UStB}%k.OzB1;} D & N 𹤐![¹$4-A֌PsWP-*+ VPd;IQdzW)`55kNOn_\?:Գ]m3:fwT3S[1O'0B 9-33++\7NЃSPB'67Y[}vFS`; a)':-@% d( ߂xx/w KBJU!?E{vO,=k$YOòTN˥A@Jۉ@Κ&; c;Pj)~f쾯|)y{wQ8ا_.g%8WoVҀkS0)d8;~ AdF>6PN/s\'jiF Q%789 "Ш@2@ B@ F!N6?k}d<8DWJ l^m佛+OF,xmRTQH(=` QM;ЪP9 =}IEÞ <\m z6,>E[y>>  rho2Fj&!J(0 r{KSaݗ/>3~wC*poaPο84 Jl!#OA6?99?.9]|0\dmvߠ~y}p8ǍʟsQ?s1s׳:8i̳Yl" `BU "{{ߖc稠kx(dQLRwdo)"ןIwx̑ 2zdVD`8AV[,z^ņs~ v1"e:zN`b}}wF4Vo>Ց4#Xy0b0z TpMeU5~167ۿ4j<Nxg]pŮeK{b2d|l{՜%3/3(񗘵ac): C5<8m"zG3º=Q~s7ۧnLu ^ښgeRYNrPKZtj-raҰKɋ6PW7'%{#x)YkAUR)ѽj8ROV3P&"^Rм{-ʙ>5/m$[`-L Zx>v4x eJUj*y%Åhq&SΫ`Kf?/7q47X5)=71Ia0oROBneԝql{GB_B<;w4VuNH 1g#ӌosfaVeo3@홠VM2iBGT:D4CMNj8[Z PܰZř]|{uշRDt5Y #puG4BɃ!> {̀܉(T^a$ iPY%{l-{:m5y/Ph/tZQA<-9|˜wVknwkvKZi{/-F}ۗt7l@ݾzȮx9cئ'Fo SN `1Q>TgUkbA˧y"_L bk:]HKjyt mSu8l:8^YHg³j9h'8%+ؼiU&Tб˸ k_Wc8X;ن㢘RC֟S2 3CiƐdzڢڱ +[l}ͷIm?_Xqyg̼MC}{+)̇vi!* ?>fb6 5\py)6p@DS\e ]]c>Kc5?}oJ>ھA<)W[ɶ%f d08v4-<4zl|..ݤ?7]}CaŇ~Ѭt:v- DLk.[*Ѯy|~|AKF|ZݏFr͎?nm0 DJEปr Cy1GAS'2c=NعkI=exo+kbn>t㱯UN"p.Ҷ]~F\yGY`N+h),Yik_]OrލMįuf+'"UM0At|&øW|:x:#Hbj-2V5}}tϚ~ [Twnpfry-SKez͆&!:VtfײkGw|o{dF&fgNun2[g6uJ?źޯ7?KR!hP*8gROKyCY5sFެDh uEXi -2xoWOd)%,tϵAJ(M1MiY; ]h8wsßlik&D~ӿv蘺AD[ƆWVwi(tsg{img>= m ;(iL}Ki5ܝ!v޼q Bk7}^@xʛ_2B;HfDCUEd-09nu-M})#̈u0yw2ߓc묺Z)'R{`w5j7(TkwDT%.gCRbqj;{}>cY6alԡRFs훛}OlmG(Iq}5Ü֊uݍ3MjH%6b$򎙐3qZ9\\[m-l*nGg@b%> )8^X&:- qh;iTϧ"S]jUPb.Ѻ.]TTUws[f-ǭS^kwR>8ga74Q6Sht أ6tb ݇KVLtz.*ukj5#O67':X4 1+eP“~j66 *hw 6f% ǏI 9>&,X`-٫&tҧf'9jSݽ=󒜣t2SyϛN yM4(2Qt͹AA?𷗜eaFIf#VFqq:s}fwC>/~eBg`36'/G^E" :cKZϮ| ){G֟}-H 6 GBn=]=;=~W2;k`>פ²PX!ZR<_O%xg+sy֌~bE,B΍gaJ =SI*"::pT$+{[;ӹܾ%5xeAP\CraZ(r/ɧc5?r_P&]ffچR+q_Fɬd REZѧE1 !ԽRł2e?w03^$q=g;z B/Nko3l\#Wdus_(eJnݶճ%@pu_Ɣ9LF8J- 갶M.#*rU{S…Mej7t^Yf3c#",ֶy%ݩ/=)p4 ZXqO`Zm/n원N},m#'ɠk4}tgF`bjXTq4M^ F¡!k;Zmvb7"Y2dpZ롼,)s 9Ųj7Sl*JPB1a-Tef'KH)Ep.e'."={^̱\i.f@~y'RXh!H+e\Ip]?1*44 F^%養>L+ $ݞ|4.y̥3'ȖaE:WiشrJ +T +^ma:@rc m[=;z AJÓTʿq 9zJ %qeF ޛEU)} ӬWT#dwJ̪be~{F?gN4>oxowjT"PS^buދ>,zb., ^Ot)=bYa3Sb~tE~x bc[+4 /=k{q;oV\fxIiv4qdSY/r^T9IZqm2Y`Lfk6Ee_r ZfTcrz84t ôl;f].v]qgo/Jv)صr!Qowco< jgXʹ RNU*L fU.1['F Q}g>yj3"^?bA,4K^JIi^N@f⭾+/g`>g-cUXa}?MCJTFƜc[O [ɤ9hQQi`c-2 ,Z-F {wต:>jz-nn6qO9A)y#JK 07E=#>U=Xג{,E1w '``=0]ϠVHw15h)sOX/j]= 2~ eg2|^~]NzGOy_ 3psm( _ԙYoG6+}2zN =jPkaerdqIǙ|zjnjEZcU|Ӷ;|DeGoP@#r|M!N^T&5[4*íq!`t'b|ŏ`O&<gg%1nfyGL߳0KA;P~JjȝN#ύhו6 o{KҴ/1V Kh~LQ 4 jqIhcy-%ӅɧKGŸ}6'#95k_Sv[xyO%Dg _nT>Ƕx Z89K_%/V[e-4#i3ԺYJi~Hy$_+馵&%2ѶcmNT?&iuYۘi3e$l[)3Kֵ~t݉>|î=dHQn`" mP c rUVn&ɮi]z-\r[H!~v,]|'ɍo,UtyaSǦu ,{,j;G5OD&Qn-4QN@P pg ;>oT?2H9CA?9~uGUn |GhWE?S_Vg5] z8ؽ?Mn+(Wn8 u"eQ-щ \E)30ĂջTt*/RR%Wyݯ|ö?j]D}^*v@3hBᡚX0#SgK$Azmщlз&Z 9TXK*H Y؏!WX 6Z7Lp ~xXAg~ޫW]8z$w?Zj7dBLHX2*Tb/-PV^qT8ݥ4&eqHB!7i!ܽ)|dpܰ9ylӥIH!'!Ż.͙)q򇘃Y#b dF>` 5G֧OsQmZ)B$'}by~SKP ܸ:L#A}ۀƭ+U=QB(#Nfe(dɋNҙ St@a du( 2T&UMqePW`2eL X?UyU c<4{)wZPf(.pwvjm*!o" Jn[tGt͢L4% Ȩ;{:SE,XT쌅yy0ad+8NcݿVf5&dɤ Q=$dJA1\}1Z%)O(gHV~s=9n=V_հLʹK)+^ \5δ)ʝezݣm{Fh-^?%F|TaI:F)89TLg3/@BHg"YqRµ: [VڴOQLhqԄ~E{ڮ}-y qNQ" TԜl~ۉ;(b򦚫 ?P } vaLePJZk0 4M/e^_i.wʾVdk,QgoJ :3mzj3ٖ'*:oF! 6_n"]j#U y/:Dd?cCtVy l+ \-PB/Ŭ#t$]!F޶ea䦴 s=CqT Gg(M41ֻTe{oy?^~I9~5?qE]6 G7Tc5mlRhƎ2p)嬍_]PIyFKN fnݺ"%ւQ@7&)EtX_[{8svZiMtRn>+4P\OCtaܽzZg{~!q͟όExvm7M2mvћ] hc_WfMԹۡՔAo_-++ \i^B cߴ^V25ae]ʝ \edzy̯yq9M 㣇]?V=ӳY_0Ê$B᪦TmfLYdM%kg1`/IrdrCp }x)OMh>w&/n ;MRITU6-G;B{Ɖ?(KcVǔFR2/unC6kBݠr-0?MR"0 +}Ds !ڠȀ[r?^=7zjݣt40yj'9l@&Y43~ vg (D|tTA4 4ȡ$`Q#Hg*x{%?PԄOTo㸖UDq/%r?St֎aHnz+eIП.XkEjݎt64&<^&ړzi}H)Gs {ѧφL M;cZ`Vi co==>5{ʌ{s q5HJ[TX̂b}^[Q+FBBq8@%-PRϑy24Ro$ACKQ*BݕsBA{10Ujo=8uyKH?M߇'2"[a6cYm÷_Fܮyz!iAђ[g\w`:}&=4@ƶOsNɱ7cfhF:xnАR0}G9&@OÀX) 'τ5 CtUy,TDI!ix|9% cg?ۣ_.rZkcX5QZF"W؁׋D\m3aѰ^KP:3hE쟠xZ2‹[pg.:>lL=LѳoG))i2^uM WL~m7 a_zpznma@c4MB:3~GrqpD b+Ja5Rmf2Q0ALpBe3dq {`t 8y*(0P 6A I}$BO4 |_#}N3'oԩfwa}!g&@^ 2=ϡjq:ss~{ẻW+ozQLvI/I㓰$V؋@* ׎KƏp87ӹCF_.o{?qtEZQ} L`D逦T]D!X(e{.+k8>'M~O1"$HZHMex{x? {^|bW.ҪI5-6شQ3IIde(*Ѷ-Z&%))#3imbeFd҅*)b)=u_6Tƅحi636 lcRm6mI&R),J4hd 3Fҵkf0jϝ/e5m9Ztʂ=3/7d|NhN@J7qh` SrN=}>4 I@*b <^8o&6T#/kmx` \!-9O߄n"@L >…>uE8MIG1:4xD}ρ#%Z:5[IUq)DNUGrB NQZbD*0 2[_}ԽƱdUi% 3yUyg$]da]ϻqi^V֧)*O"∜@ec '`-j@fd'n?ǍlT]jD3W،4lFB'Ò9}n]8?W)zxh(hͺ}GW[ \DPP?{ N?9ؿz? SO0@KBRSBt`rP$\ʃZMQ)+J66*(^۳/#7 1hEز68 JZ)2^{ Q1PTt C&. L`,d.= i6ͷ]+4EQEK²G|ANhJZiJF MTOc_qz/p(V7) (ZF}R ]Ha!/'-k=/m!jy߷6-1)?/g;L֎T'/'~q̓hJD=MJЛG=1?l~8i󟹈{/?N9KAITǁ> w02%L$&јd 'ک]P{-U=0@wÉbk`4R'tPJ";(~06cêL c4*eœPI]s׀j4=3!v&IC͐VӯKaJpȠEtk\*AN@5@*AI3liTJ/.IuHR;? Z1Dg@}. RmjijZR (9&pc=2?mPѝ u}.nˆ*7WІ =>9pzdj<͐Wa:zm!B;^K(7qr(|BkAE2& wȟ%JfUdd Su|X<8#vCk0-`%_gV.?oZ^ iw{~ NT@}¢$b@&ou($ a s&//"Y]o(wH(&0Sp5!pG-B 0oQ@!%Eݩ/~5H f6C'عPa80Bhx@J2PNG#0v~t]G?ft3]}A9~&~z[6;>o3Kx~I~\OAt-y (?! @QY?@#Q ެ%FT  0&JnP@uv}ۻ>œے|}Ks߳>p) QP-5HD5m1RdwW92oƢ6(*(l6?@L,VjXj-vEP ' q)׷FIca_:7r̻x 0(|7UT}WPO9Ccv @>D(v?>9 }hDf@c X gߢ-@2ů/c;(( O]:sr2p#q\FW["@kD%AmJF-Fأm{%Xj-lX h lEc2Q5NFiKF!25͖ b4W-ʼUj(FEbjJ66"MQRcdEQ%)&kERj nmIDlF5ʏ6hMYJBbmtRJ[Uwv,b ֊dFh6 QE6E&-A6*6-FűE*2lUD[QbLZ"hة6(c@lZcTbX,F6$lh44U1%% d,2Hؠ4ԛenb+njMFK5 5QkF*(VMhZ6yFrlh&MFt"DF-rQsW+F+]ZKFM&V r*IlQ\%F"F,UHXLEحQFF+1lj1%빳Fshbs[Ehۋ;ƈ;ڮtڹTk]h \JRFcJwd9jskƷEX)LA0$ƈZ5BElR[Ș 6 ȮWn;%η/fnlZ=neEm\B i3sJ5o]0L`,%`XVenPY5bw[yTQo"JRrl&ma- KHTUZ5F5AmF"֔ƌI7-Emт)%FI"!e3&a,aZa&\lTe^hFFWtW"GlSSnV]n&9E[MnmIhԔIh؃Zsnhض6huSBV,Zjm+Y5FWJѵ\skmFV-m%5Qm`-FXcj46DTj1RU&6cUƨQhV1hM#hɋdQŨAZ+b-6lZh֍AjֺV rʨFJ)5ܷ6kѵQ[r1hm$X6WLڋ6 lEumrJ@+&эMX3E&KPUTmEi6i" cmm͋DZ hr&-DT6*imjhƊmƱQZhڷmۭIm&jFڊ6RKF[bDcQi-űlX(*"X[I#Dl Z1lhэFM"ذc*((FQX4mbƋhV*kV5&nֹhT[QQEF6J-Fأ3RBjJŠբmFVMSwbƨ&,[`6)-EQQbѶ5EcTjUj"ڋƶ#UEc ˫.g-F،1lj QXn,XuIvc\F֗,gvf*,QnbQ1FV*W-5rF5h\ֺʶ\"r` ;ן⫤{sGQ|0շT l+tyxu/Fk-ɘgqr[?ߚJߏ;C1lYAhI8]]CU"fx0D^ aZDf:)5uM?aRGKu7|?s_M $~IECm>{뀣U!*G/YVMtk?_8E˒uJ$:2֗wwxNtp]tIwtc'Ӹ}F6H@ɰrRN"FNx øE|I6:9~n-?ȏw@(e*i|=~/3K "f Ħp'̈~ "i'Q@])4/"LASd??^rҵO#fݳY~Ys~[kK9E0cJcZ=J_"RLX;0AP=XJWS֮ѯ7 ""_;%$R/xzaLߺ|oruvc^ľ@Aé-%4ہ!ah,O>0j?_O3^@x` c'"+r"!x/Z\@"$xUVVs  ˠ_=>WZv,p+v!R)vޯ o2M^C՗ +oo7iGpDO@ aCPus SHsӭ%>_rΘµ7o$h}vk_r}8?xp"0)B()KV'"KJ^ DK'/.|@6 ~7) ]}=_o<"1!$I!,YL_%> @@\y8}F@@0@"/GiOv~/_oۮ6& \d`gt(=1\ J%j ^-"pMBdiP|OWg*g((HTDPz~IۅHBH -nP$'}M{3cI~~5#SO}g K^VC7G }U OY1D9R_֧y;|ƞ{<ƕT]SKe뎦EI)-~?4{+?CwK^o_NhFc0gT9T ɫTIffA̓zJ?}O6xOxt޼@ 1(x:zv?P^'?m~7躖O\Btjct ;f?Yh.yR#{b D12z@k kX>{tO>K#Td2#=yuH"6*ʔNJР%d!I'4| @ɺq N >OsiS>5)v7 jYDU~U E@*EAhn$`%|mhW,=߯/*  7;;(C ҩ X6j )WGJu.52iY^?supݷ xv@`ٔhIFf&#&LRJ33fdf`0`)?O֗dݯ eÈo1H$ƠRd&AHЁI$—_o7>~-! SHf &L"RR12I"qWÝ4"fχf"Af@PU|6݆s#fDH_36W@m_OeÝ C*bFX]$җ /$lDkqb(lX>k/LsHN s):%yB0{B z^b62a@T! $ 4K^nyi\=|,< 8D]?"0X&ZbY(f3>_4e)fSa\= sokT(cb7ڷ>2UV5 ox>2b!@O"6fis_փ :f{=]XN@ "IFflnlmSr$=r(]"EZ4DeDDq.ET1BYn&/;&/5K}$557=x.HD]x8Ұ6S~{f $ӈ0Q3,gH  *TxP 2=0!7J|N"4 \dD  Zb\,J#0 ϕ浜L}:*AT0P? \ oߠ<)_O"<wz:n_`&1;_3zu_g$Ģm!HBHH&Cf+-/ǵ$dy`qݸ_}qGQڔͻPP @i@Og|V&$'DG(Ġmw; pS=i_(S>n7{.v\G]/#9ѡԷWm YcCC~~W~QDZP,)N3}z3| k/neCi2D2e=E ?%QPv)MEAs9c;!k 5 Id'G?QI}M |4]| -h<nYCH(P:0"*,>i`(,?md${Z:Gc-bRy`5%-?HUP9<ss +)yd,ȱ>KVxȩ+QCyz⊊e4F{{<3RULPSLH_'_T޺2 7,w>.0IN=N̮}䇂1'PF9bvNq!?ŋ+^ )x 1ALRPA=˹4 Y8 /(zfK3?FQJ#@W^Q֔QB$SL B|3\*< M֝S5x/nPT ZFBt*&3Q(DPA)鏹̠rۻ"K⑀"XcNC'r89bOZ 2g~?҄c"Nķqr9ZSk;8?ϟ|y=O#b$Ĕ9r` EG{{w9:ܖqAt0 9=~սSʽB5 XI@ʼFH! uɇuckbm)rɥ;8=~w܄7 ގr7~ؘ3bfAiA֔y( `#Q^*6r(5NYiS]b!H31!82D`/0r-ip8JAf}%M2A@!_t y@ВLFl,,"!k#g!PBNU:g(H(uW|GœXѐxN|vzXuzhPGE0iUvdQ>x'@1BP7X}R{K{<Pw|3AgQJlnk8y" Ք=7,a!7AT`5DG/eS)O)>6ipG]B7tűo#^0ݖ aO2:|dAO j>?ϔIsxypDDVckRdt;?Ds5@z~i;M?Ih'@Ũ1h`K@1Ap xbn^Y.g@wI?mM|N<2:$^ߠ~4tv80:h̓9\dtAC^-.kx8D>2;8q Y(tJ\Of9Dޓmn_au,Q|zrhy2H"d懯Gfwy<}*saHoT̻RQ'Ge(`K.@8&#YŦV~~}$]^_I;vysy5E4Ak;c @;$c1$.n$ y&586Ayʛ.#qݨt^R@(*e>u 돽89C0d5o@jGnxR7K''̡O_Pf"zqR`#`4rȽָ\I~BrcS)FAE2o4GFcL&=FHsZT'~'7~>rx:5']d<i&07I 0b9Nc !R:D,_@qG!;1S,~2w|@N F >WmU&zw](Qܰ9̉BAeEOFD$}/?q5H|z玾 IN w\MA$wx$GRp2aPL`9jxd}YLGQ7ݮ282L#C\x2 |žk$ϡY<Gd(9G= r`CgL"y~X>xg@ N@<<莡17Ҝ/>M=~y_{ b= &Q/g-:r6[O̼ayD=j@d"NY~e_(L>FC PY1 lӺ\ȋ `c#Y ̱)Pm![I0`b+ȵA'=I]Je 28hq/F PX'u}_փI AKU 6H7:''P eT" 5Cq"t2ć'x~C1خh$_goҖ,-YBֶN 9 Xm$Pa* 7ǩ,R h^¤Yd{I|y3FG|ngZ$$ 萲Oa6$9al-7@@hF* ms?xTP1?8@EL}I>t,Q$r2sAp>n  =g=.X|X'≏]JkR2.HP,Qk#꽞N/}]tYMu{$ d 3`ŶpՍ'{G_LVf#2E*I3JI2$Fa1caLB"J4BHY)5ifLfE4'4 A3hY3f `clxl7^Ә.z-?g~_U6)c|~?ۛ,$1u¨dde;oUz?QJ+dmڮdE!\mwE M$QHM-뻕54HF-(fd`䤒ff2⣿ck6[5Y۾RdԄhs,K\f/lR&ߌ^M/ R35{t* lr.A0fepTq44QRf`#Mb0$_ &k3d7mFDr!)?3"X" M}fy1I%DlmS5h6i [V 2dP'nIU=RxXm-MO(2bV1R%U("bO{%۱",O-e.~OD(.W ̌I%eA˙nJ.J3z"Bh JL=FXZ:30W867d0D&:8XjqDQA( l{;D>''S̏PX%"VtmY>6%]{zl2b$`i0%`2q|6{s@6 fDZD:]1 ؉ $ ԽU-Yیgo^}| |),S/y\D \6%-Vi%e9~ct=2mA _>ʾ* `a-&oܑ$>=uW(Bϳcno<t_X%k&*)ȌŢB"^y;Wj[ "D[:dR?ò"D{{KyOhwq;<s]@Dj{) ͗ ph`d n꛺J|/W1ż2?e~@%DE}w}oڵA-$(]$hToL M?iz7m-ޛ\sC|y( O㡙Y̙$j5bS£ˌ&1. 8ڠ )qaaW{H 2沘Q\W])| ޾ @J<{R Ќ[`2@qAȅP N;aiP00:Wo|cS|y1l! xemA% p1@"p"X8K 6Bs I: ڏc)Z<=o*"!1:UJ8!C}T(Aj܁PSx&-MhHt '42D^I >?-n Q*m&^ h(sU\1ZNr4=݃Z=uBXFdũ& Ut'`d8PAR "teL8r7yt]u wxR{g:{bHx8ŜzTjԊTNU 9 fc Ϋp32;C6nf4驿=:d&cVCP+_i:/2}^:$Je]}"waE>^>Raﻯao|ty`w a,'Y:ό`op{aY|/x>N'ol:߫;}RVJ&=s'OsrqƵQLi|aB,]Юm|nt>G_:Ü}p悋%L8y-xrUouR} zz5rɨ`+oYt{w1z›Oy'#ݧΪNWg,&5L㼵4TǤr|{,U+킞fjt׼γL(ʨTmZΙ1TxNBE}]LWO)w坸eLĩMgqv8pN\gV|$;R2LB׬&D׮P8=>ZQO*wZpzx圵Lpd;eI^b&{LIq)+׏p@BK[M,&3O@o@ N`"~r$󘆐B ȌŮvK"4vila*i>5TwsvDD 8!?zBu ڎvz~yH0%r3w^۪~1 ~-ux:gVX(gF{vIEU)F f:Q]!* TF ER9vHA RA`/ED8z_ok?vnGS^c8#ܘ0J = NI<_%v}wݹSݗk~O[3eģI=׾|Eq}nSY-dv^Șޞc%2~^}˳)1f& bI"S#RRLrW9O.rtA@&bޠ5㚣#ئ:[ ֈ0Y&H\w}Xә^bo+y !"*:Swk4Y`^=C"pi2A(DY:e_(D zz<qL|? M"!ᘔ,:(w"9 .0e>)鎣cXuu+w<C]hzEhWȇ6Sl.1._ڠpjo ߺ-~7V׿_}䉤hD@y Rd1QZi}`3&Z5URd% d(($ VXAu3T`VRH LfJ wx>Vհ٨40TYOCEipbB$x @cy~R!8veLJ) J)41" ( F@ԥ Y fPA$dH3 d6D 0RIFFDPl) d,0QD~׋}qEQRQD c* Q hI,AAL3!Ԥ S0&DI1J4FELX`# 1$>ˢFFJH"i c0QHĉ21DLiіRFH DR ‚B J$VdH &40HC0I%&)2͚*@&J& #%)Q)f`Cd4e J$FA42RēfP ɒ &DQ-0E!cRD! Jdk2QBE$!!E Ia5 )iFS&,D&@,"H"De1&̙ 02B5P2iKLDʌC24ѓP$ȞQ&T"dbYfɉF%$&HBȇM"2"ƂAE @bh@Ih"fla1whRƐiIPM*!feLV CR0icM@m0%(̚i%!wh($4j5 2FFXՌ)I$2j҈X2bj% [(nG[]s#?%|DD$(HJf"!2hA$DI0(Dl(I1LP2BR %(QE!CL#RIbaBIDɟ/pM)~{{)$IRdLdK)  `H@Q2!fQŘX&I%#d dPl%1 EL`"6(2L "M4Ġ͒B I#F e,alI !M$`D"SDb(%" iAQ2@XZD #IQ`bf2 L0LFJ#$3&3Me2mT@DX́300DD4&$12R"(3`E()2%HF3ad )LAECf,ĥ% ,RJ(٦d L)3!) FF!ȣ"`!JI% #!$D (j A&ɤЌh6HHАE$lZK2%%)(6,I)1$A6Hf0%S$F"фѢ($@ii F%ȑ$&ƙF lh1ldb%ɌPC2!ch&KC)BLE()Idf4l$3֊d4H"lh5Q$MHkl$hȔJfDl2A33H_ %W65(S0ae(DFc2f)fii3`"#0PlDD4H3M3-f(FX%D F$A4 ȈE6F$QI3%M$&I(4`C1 dRƀY6A"4H,ņ2E)"CIA&&&҄% d̐ L!&3&Q30L ##HLMbf2Ќ$bI2d#PdXH%"%!&6%!6cLc()AE 31RI1 @# 3DL"4&)3ld !4QHi% LQ)REd I1ђLCbFIE$h #"$LSLTPd J-0XXSFKh-@ b5RI&kFhK#,f3*ԆcfHL,kbHcHMH&4I$ ?N w`FKeEc($edBQI" @#`&h(RC1$ؑ 0P2PI(!IH"i4Ie&D!P1"H$`ЉT@ %$fa#&11& $фk$@P 1b2i1Ĺ$)0 d(Ya2 LQbI0HI4d0R(њHI(d*$1dT0F4``L%I$ #4f J$P$A2CJ`P*X6%(HS2FDb &(d,̦aP(#4$2XF3F0P%Y$DF*S "LjI! D6,ThI4D%c H٘3)%#! &FE-+R,TiD&ƤQh,"c&L#Q(0hœFcFHAHZLRAA6ddf 2 W;@ݧL߳&ڦ)!#@b&KEM&IKHť5E& bf`ȌfdfRJ;U`?v_-؂,Xţ[)!ZF) F,e!%cl-%$cd*"Dfʖ"U,LDdE1DTLfQbU*Ũ5-%h4٨M6ыXY+!iJLZjeb32!a#iHjhL$Rb&&1䁂IV $2dRM34lcRDXɬJb0XI(jKDFPTF6X@jl4&6J"ci(5Q`2 X#%Qцmbch5RjKjJ,FTRc!cQd(m-dd`&ђ%c@d-iY `-m&BKAicHVb1FDD@m@R6k2 dKhR,m؊+&(eLH͔L!Y""b,lbM*5)mF@URkS5Q6*-c&dQiBѭbFVTb2X"6I %m["4F#lMB(`j%4ifM& ؍iL "6FS,-lih61d4ImLS(0I6QD5ŰcIh,P[d4mY+mF0D" Qƨ0lImY,h-FQcQŵ4TbjHMBQT# XRٙeac`5fQdde *4)mmTIiX@,DIA2"Z-6`IIH%h) &4aR( ,Vi UbD[b& QDFMTČZ$E[IFm(TY+H5+ R!ldT&TH6D $doת 2k%j2*j1dքTDBJkFhj616ɀX,h&*+IZ+&bTj64X5cF6-h(1 c!b &,$*-BMj4U Vje%BL5hMh#c,lQ*ai1b&ѤR !i Z-Efdk1T1`5,lT[Z6RcZ(`J5b6,hmm5Ѩk "AlFeY(ƙCd֓XFJ)*LX*&kY(K LhŔ-E%v6VT% m-I!ZٴZRAmmTmmTZmZ+lmb6QdL[DV 6%6,dʊF٨ՍSQcLD+F-E tgeݺ814AY6[!l,JCF52FhQ Q&Qk&XMV2XJlm*)6MmZ($FFcF#4mkaLD2*,-,Qbd(YC(Z5ElѶ(Jj5!M%L-V4l[ڋdXcb ALf`"тMHA5%JZѶbQ-҅SH6Ţ*6#2hhY,*d( FE%)3fh4ATZLlRE("eL"=z6-b4AA](#X(jE!BREQ((JJ)XZ6QEDmZ+(ã:0D`(+bLTTm+E4ZchZ6 UYMRlkl[Vem1m&mQƤPjKV5ZmŤh,J2bIRi+hIFJ#T[2MFZPȚeKb`3S4b&dk6+EC5fE3>yxњLLM2!24RC(2DBFfabXd ld%B$Ć@S6LJAE0M4F"bRB4Lɤ$ "` #7^^EВQ"%)Mƙ0M)he1 td$!0(ʼn"L> H`aI L oD&1 &4%,FPh2RI` JjhyӜz_WSyxf۠uYUY|.Kxǁ~s.q 8-2,r ~ Kյq=LJĉPylV.Ӑ\x;͝zEd UB+5fi?ߞQID{,˗1B BbeVl΅@ky ځ`=J$\\u^[tyy?3dro?ۗP|6C]?a$02ACIL2Q"܏/8*&aRJƀ~Dwk>'}f@[r HKfk>ņ&C)mf UiDB1#0r=_`xg 0}4RHOwcmV+߀˿#_s^SYyx?w) C'i#2zi)XН@U%.B'z_S.V:D c=QE* n Wn5Z k??it@o][{pk3W/OP(Cf7"IX!7xe)>G DNzd彮ݬ:?=LfFo8׫,J̓PzT67sVN=2gњ6\/n L.;U5Dʁ1 36w|#.IX [HpLa?qw}N١oQ?y 3)9* `M( n蹨oz!"xFmBeV$i=%zcwv\gOQh>† ܏}>M39>?_!I%R9 \ yu1{6f7p t\D|oy!+@ytJN>L7s_&1s_}'{>H ƒ>Xa]F:Z/1JnZmEoAH0A!BWb;__u7c)?MG@J9(Ԛ8j"/P.`PcT:x\ት>}͐df_u׃_u|~N% {TH*L]p $54/:c49=9r\pD93n喝?Sc,!?USl28iՑ'sY _#]jjK^A {y4-I 380i|_hk|~eM{ײ|N٤yu չ Mzkczw^e}wyܾ/osK4D4PRr̆g?&ٲD<|X+i]2`&=bϪ\K]'ߍ6R)E3m $ ksu_q!fRe?}?]=\Y_q; KĘ)(VSU?f:~^輔`>|^J!5{.84k\/cguqb$oCPj XraJ_SFU)5=TV!4𷇓==.+YgEonBe$]=F QyNzía~un34HRFBܘ0~1*at c7^6%LrMPEuVe5F (j~a?ϫN/w3x0(9-jr]Zφ*9L5 DgaX2e0`-%N╛8 {F}U.`au`_(U`v4.@9U\'':G-F[oZXz]y!,A$`D:yl3f{t C3hA?>72ېss{ۇr{VU|Sas^n oG}~GG#_;.k_$4 jp ."D6Sd@CsN@W*z\|7}[ :{W 5g1( P/Rq؊-*}ދ~G$>or<<w3=v !::k}_oHt_&!${R#1y,rAPDK2LlҎ` "v4ʛFJ>s#a ^_GFu|ќoBWh]pw]_c.C%&@3#s^RF0FN)WHru[kS]8k{$r9Iq5OO|eyz6 (fU9WL,<5pVN TǞd(AAq[_el|3d V33.9R3!TPW 5y5~;hc.׈ I_+q(uwDъ9e^aJ#/3wd?x_ :>(1<Ǫ,)?)k}dyE?"GUˢr]d/r^"lC T4YM%*&r-Šj{+\oٕI-EQ 9*Iue^y i=gC4˷#7Y\>.4|+9g !CEۚ 2MHsAPMCU Siߥ:϶(~yc/f/.GRɎ02_uM5; *|*SA3h7F*r* b!ɍ`r9oJ@=O5 NbyܿSNL|lniӑlA,^z6oLRE`,vpJfUnoD P&AthB~[ϩ,zj'ƃ`  ^EqIQ8   |^wID:xpL 0dف( ~Z}h(`\k}T`ɍNO&z79!O~'~۵~ޞ/VFdTS PHP1AXƊmopVYB˰/ggKey@?Ix$Ie.ꁊ+/뷎) Ax KۘZ,nk}Z'BmpzlA)?S!i{L_Rܷ4϶r-[DV9W^u֗L˜Y}{y pL3W+--1䨛Ñe1n2rm.YD/=YQTGpιiyN&cv0Ԣ kvLbɋQ\^rU .F(U-j&M N'v3W0nF3.V˴ Z +b+NgUYlw/-γo\ű7Ͷu.]DVYnj;q,Nexe:8ˊm\‰ TL)AcbeJkD3vܥ噅3v(i˗tnT71˔bMN.HrߞdΒ8({q;KP5TrǬ"ָ卩1hՋ%JP.ÖnnXq+kiQ\fQasnnkmb.آ+f3rM2ܦSzŒk'g6{C]/nnh/Et˒8e<O<.QE 3(TMۦsq/-’ڥUDE2Myo2cMN2aL"ZVc-.gM]|cKg{0ʊFЊ9'/q(,oO_~"T,AVE8RU؋?G=!P*-a[|E|vb-mϷ s4MB|29, Fo}_+ Bo5䜔_dܺʈt娿lפ?e=0ꏏ7V95_iAES~ϲz:爥Z(i*3Z s_mt~1ܲ]Q#a}연wHz.lmAeh?<9; Vsql%l"!_ol++8iey _ץ(py4 ,8j1(162E>m#p$Q3Q u,A4KhdѷayB8&zHOfԡv.bϩsƹ\ga2fE  ѐQ}Z^UT l__/l%(- "EYKEIllX2=9|G?S($AQ܍?³@St1s>$J( (ѭF2" &bɵb-hI61$ɭ&1jŶKEDdd1hbɪŨ*6*"Ѩk&j((֒eF&HllDQ5Qjh26*(+Z,i(bTTȬQ$XmDj6lXhHl؍d̶I%HZ5h4ldQ32JM&cFch[|((Z+A("60,FS,4c@m` bfѵ{vj(Elj AElVKESQbbdjL[F1cEF(ƣlX,kDV*F-ƱVf#lX66(KTlF1cEDdjlQX6ŋQbQXXmEѪ4h5HIQ1RT+IhFdQhIѶ- h")Ou| _= P!e='mnWvDKt^.򉰜Y+>zTx,R "{fݲ -~nۢI:![wQbv,jއ1\zAWSh}f1` 8(‡meOT'1MQ}Y _ Ov͎hIK?oG WVٺcU?vW0>/Cp!HCW0.QSoZ=_sJPQ;GvHph<4xwP{b4n1TMdfϚ9UbbFnl(IeŇR>@{gҾTݲ׳mK!|ugܫt痕SY5 ŀ&VNvM!]pXbcS㘴i#WYtY1ɺ1OOl G2\5"9M~Ar}äѺS[E9`PG biD j\$q]J8d & !Xw/:7̥y[sZ/8h!X !0f ÜQ2" @̅[c[FD(Fb+Fj*l[Pm?>ƕ?# cU5 ouC0èrb-䄘QXִlVƶXj4Z*5FѰd(cV11FhXDffff\+x0[/]=z5"$!D*8ֆ!woKY?\0:(uõQz; $nŗ!_aVY2`Qe)ir-\c7w};_ə"ѲSfR4%)7p|8"'f mETT>MLZyh1P1ZmR:ݸ3\u,1ǧㇰ7tIydu'O d4t5eg{HB&uzZshp()CX#P ^R"!((n`;"$ W52hZ4D//Xשƺnbh+pRd -+AZ-V"PlnoMȱF%.y5AORP"ȤQg3;ʶadU*iP rb3̙mIH6+iT22\pq-1ʆ3aK*"Ӻg9tDŧpgκĨ*ne€3 Erp$<^x0+TzxC-;vUܰ)Rzx#_'}W\jkz&"AټaTc9d4fbҴn9+s2RRBB5JRS&FF7x5kTt4 #͖!Sy4+d01Ǒ_RHyE & ;Xb e eg- h2 ȌC0xfzZc.* "w#\n_<>{&i(,E,dfƟb?>䩛KWq; byo?"жJ@Y [cmZЍ52V*ܸl#[ӛrV@*S!g]P8p:oML6!n; -4 ҷw]Y$#T+x`NXb@…P !QRpA}7]zf|ru8Sns`sy+y%:h@$&'!*P^ʻب;ߏ;{c~{UDS217_HpThN]v_,f{'3r`8xhƨRD` kBI ux =ak:1S 1٠:0NĽjEgb@Ԩfũղ8t vlo6Tk.6 ߪ%-,X$%$~ p  !{HA]J_ w>yݼx}6 HHJ3"3 @gճSPB_#秝03?D4sPd?f>HJ۠POGvsFf-?Qs"is KL!ur2 :Xx|47JI lrǒ   #z#xa!#ΠD$%woH~9> Yy3ٴK0JDHl(?_1.(U,(aӄd@9O r#f<P]p/&jeeb5Z+.=L~~'/)璓&KDPAԵnkhZ0 q%&NW^< ֍roӺá*˩_=c:hD㢗ؾ[ւ<UZxx*2 X7>,6+1%]f"Sz^m-0G _{[JjEJm]/[M]v 3a6m\M"3%5O.[:6geUڼhZyXڤ(goոvmKV>.]dw1HXt~#bZYFY|kR€ ʌXbZWຫpa  sgv4mVxsx(~sYj21/WTҝK6֢ n:8R1šݸYR,&Ws8yFkL懄Ib[DBeWi!{-zn:3D|Pp]SE = */AX&{O|G,mb!e,M[d.`fmzoms]ge 3 9 d/q/_|4Y&mj4S9:֖O諂[smg%I4!UW$$v'69A@XrOof?\'{Xu'=D $N%@"*D4V'Xﯿ,adWH 㲡,"p3OӺp۸aS66j* EUwv~UyxC0z}ə:.utF!IAn>f;.L0˺#} o6 H5A)΍M]͏^8YS[)JkO0 $3!A)\}m{G}tˡl-So߼?i>iW9I>C!-cYD$[J\Q :@l۳A-$.M[IUҨ|L3)x ?rGPjQ6G?E|wNd#J6; ^R]0?#{e\s;_@NJP2Fhd9T N *k=tϏE A;4߂ݔ" &P /UW(q39: /iMW};߾RWcs3>"D!0ā+Ⱦ;'a3+=AdG~k޿]X|$  2j.cl[3i6uĥP@D0E/+Kui41iw Xٚ0l;[wUg%u o-/Z<  C] qZ4M޽< ,!ҔXuoma}u7ᷜx;C4?mnd{UCm B;<0iD >nxU t7Dvf[2!X?S)l v]8LpoqW݂x}B uj>#kL&Uul+ 6?鮙ȹ,9]fw׀CmLb(No}-Qtm_9(R@;5K[@O iy~:n!N:'t$6h6BG7EnO&.B ;i RB|vÖWTSeˆф(C% _~} lQrO9<S. 5hss2YƯ}꘏$r @T  n@`<]G K-̋ԶnFR%q_q _{+cJ(JΕEB, mD (lDO6AtHO4إ} ;1b K9iQ[/&ih Qo@T3»Z@Aa]w->D'r#M̻oU arKGoG;| mP0T6/r4{'( X䠀W7woO<7* ٺT HL5zԇy8I9Qz&s+nc)P؋IsYOXm0]3urt8oaE_I_]$j0vtNsHL3PHeJpTϬ*[Yvƒ .y|csn!./769j׶[ʦ;Abz *gSzeY٪.ׄ-aPo}JQn Duu{\܍Kc>N˹aB/MsZ4l27fMN f*嗤i7eaGD""2Jz "׸)AjLM ZY-;Nr~Z@AMzO:DY[N2ɠGj*7+9b 89?-+8 вw0օqtr;mCR!xj81ڏZ u,qVtK-aaKz*9\.K=}CVGY k)x*5W}mT>+^ѽx8ފjw+u.c[{LEuhSOZ82djWI+-s^5;SkNYtGY|ҽe(nW @̪?+ iwuIHuR9qo2y.-DU Z/c 56Qc9ិQrS#E#AO{bq&@I]#-vNr}2'p_8- |eZ^]^„WqR]gU0kl?_OQv[0ÛWNZĄ MTҠ8h'TQY]f+2iI"9XboyT^678Xٻ*hs5UT\i x%Lj=] k}1Ygf㰤:Db*i14h5дGb&/liE)\c% c&Z'pYg~uYW3>j0Qt*)q'kŕ 0$1~Y=~;.ҵ:벫|*{7UgƲ{ldWY?Vlm2ENM}vlϔiy>Frkk,fž{!/S3';/Kd&9)9Vn"m#B[4io84szΞꢈίU:a_A|rMPL"ʏS'\_[v?Xma  ,sI)zq !J,{kÝt-̕ځ"RG(;==$PʼCex9ûQk*UxNf3"Ep0o[9fiF7-tgfcșٻƺ_52)jkS_=u)%Rٓoi=A"n O雯]*Y˗{:J]l_c%7GIBAtՎ5S[aG| 5fЖ16dPlfl3#3O|?v,=ǔզW}LßUtGm/sTgPZD2z}RG+PFI)&tj4O7m`RS/j1\+_<ξ%jj\st->Ӡc4wp[ZӝF bÍ%xZ|>Ҙa&pPX!wؔkU^Fzj5o(}8 ffEuYnm"bYM8 nmY^e\ tY?{*Pc) PFߘ}U|«dD ;Ʋ("2v*E$1O.ܦYzq'u&eueΙ0ʆΙȲz_8ܳ>/+.϶z@I5 Bg Z5n&r1МIGB)-YY}]u>Kq* cMzѣWɝtGM3C_ mS4Yj;H&TIdO,U,9ik}q3G,Ss:=*y[=M/N)sz :aarص1(LkycWV;Nn#P*9ꨘJ?[ fL K~@,yJ0`74 'DeGylrr̃^)a҂Cp\7\$po2*Zʪ0U * !9 +F$(fŚIR<2,"Ҁ`֍*A3iF&!TfZri;ċ0VPE"YTJOI5Y*3`m{kηu=cpH puTzY לsz_(,ke6?Yς?zM볃ћSfn_yTӞ&gE{βzގ}>#B*"X9hfr*U;JSAĤJZIBY¶:gIo2WdSa|9N 96Wu2OQ &&E •Id!bU<LDUR)VhjU`D+P;D9Y^fR U:M 跸-()Y,DI YBDԇiB < 45B;2u3yfU8kh^szKjfxwVEMCCβ="N5USgyN߬޽/i9J_w^\kxͷ7'WzmuêXy4ׯ.L&Z(V2vCN jC9"i:vm)N e)IsdMxZ͕\@fj2 *ҋ+%!7W8ei1U 8& NbBPdgVH@ ͫX.C 5Tx*`ʲiĕ lMKz9E|w<z eǶW#I^uT||Z}Ufy+/ix*|s5'Q7-xkcm6J&6Y TA4FM}GWU#b#ƱUhV5bm2he%mbՍ1լFRE "Hlrh" FdR?pf6̿~Gmhs%ܸRѷAZ;jPMJY Q2 @"#`PS۠E4٨5G!'7 (lQo[TʨWmƠ5eQkVMRT'mMEI@@l'rU0zS:2Ww BJonބ?eC*-)F?Ɨw>9z*&yP1U m/!v`pł@ M>"it,0:=mD %FU&Tzfٸz0}nV+ϻ߬jT|fZ3FZJ1Eyjuh9l11ċl+1]YX :m%Ijan.8ED~xf.<_;G="PEWE;ϸ w/9:*h(Pd7`vS|.QT6;/;|t@vNZn @bhhh b4444 h 4AѦL!iB &iAB  jbdɂ4M1=J~ʞ){TzSjdzDF}PDks;k-Q~r}:&F?v*k{G^edG?>0^@]K0zOmvXEVCLQ2(vPd_v6'cñ #`uu,ps|g.F͆/~ vVUc.>陻[9}{W*ܻj0nu>ӇMM*HlC rK/'P.\* 3yċ}2L{]9jlfKj%SU *f޷kipf_ruk7F߽ɩ{GwW3(V<^HQ(( jC=w*ğv6+$R==mIFZq}\ܪ^|ERMx;wHzk;9a}= J''}H{Bc~~?p9}'dgڳYyKu] 9eYt_๭8s:K64]dfSQ>:}Ѩ4lo^MdZ_'h׌$Q(0JiPГ-Y+^r6+0E\95w`OTb-S5S8u2CaT0eґPq k?z3?O[3UIvjWcn{WcߺU9>ښ54( ju;Q2١<3w7޹uEiHmĎg@X.V[޵{ρ7t?jQܾQp|=0Zs\ŵȀ bzU:2x9g)fRgc/v5ITffkMbHJG}E[+?aH0M,%opq~_4쳧y^nƴp y< O-~kyYU켞'ُ#սg,NwSo+"WZcmK6ku^O}ުg{3q+]e^{g~[cVOsh333ah| d ç[qb]Mز).G֡[6Zmi{ua׷#?jC}-r/rJ*)So2tHyj"O!DDHdf;ۻ_Eٜ]}P+FmEXX%Q {rw` φFAF`\ 947 T!<<|gzGI pBMII+su[rƌ'VjXTD@^ch1F f 0(a7m@|$8|P` @ /L`.*."H4=lA*[:,H?GSCm[KÙGrt=Ml1IGy?*(@HXXlj}+6bs\L!ͦ'qi:>g |PK%3ӶX$TXEAX*Nq6:;'evF(SX95HZA[پ?ׂoߪzm5wT޵Un<)Խw=4s~FlhgFEr`ֳ8Sz .Ծms8Vj[y_}w^NұvGMnaYhr ORZ[Ic"#aeMt^Ð/i!͢2WjxZ3w}vWW\$NwVW\_[1=5fOJy+ _jhAy2y=t'K2[=.M?{]C~>@fp &o޳3l>rSRk@Q^Gm=x_`zƷ3oܵ&/9_ȸx8tEYa{Ҥ "6B &J {nϋyЪ8MCܰH 8ί'XCd@@A2@DjUF_Wg?v?Pv|/z;@,σ!EPBU{Ʀ'bo:5:˵M^Q1 2 .%o~9g;x mvƟ3>>jt/9.?hz^Y4.z~eT=uB3n=#7QlED1X2Nkac]:,8}-[vXq޾>W=O{ű7eGߠ*}uCL[r8YQJn4ʣ1b"QAG~g}O+=Ͷ{y˦=,}Hs9F]s~ƅayDY>v.WbevKͽc`0Q*iuO]Dz\n,n\bU>w|g>Vk[+~5;_gZuhn`zm~]W϶Yt 1|p22.1;*ĀE㙃m9ps$ FE AHd?/_ٝ;]'js :u]~{Ora}h?HQmh:k7CكpnP :1nW`ehYYHݥ~) .BKˀ1y{2pBNQ6C_/-dmUM6A&F26` LJL" Bs")˖ƻbVux35AǗ/y9pҞ^rRJcSl2d7w}l5rˢ{ޫ7]u)FutQPTqh2Ĝ\~3aD;IDAw|=(΀O*m$C _.C۴: d(ЀPF}˦ ^ Ru1O!;\TuTՔra;5x6OrmA?M .߳s<0PRwAP` @ݹ]9V芘7~yi#szͫw_=V=FWÔ;?i1h$mQ݊P.2?<󮩘R+ڟ<>G荭b4rT2"a9a!/C %:ThVM0Є Nꫢ1t2X`P,&  RVc[>Ä!Q p }7 n~01X ),ˆ i'Wrc8]35DCKvYmwUp(2da`) v1îYwwr 孮mXmv&6ZåRlm0]rY.;jtrz]Z5'W]ڒΫNΈ]wk.fI ddB#B% P!:(<`t“wh@d mr9f~s0}ɔk0d!fk&t. . Qxz΀ʘ`a9$#Vrps_. _" H:|qك!ı 1D+ȇ 5`0Fy'w>闗VjWՀm(Dzf {"R !fe3/Mu#F("4[ 4Mb5c6(r lЛ2"li IB+MQQ&KMebV&QDD $DQ !P^ʋDpct_rlOK&4ːpAˇLAPYxl9sn3Ĉ02 `r)i\N XY bxt1=xdpg'7>/s&Q9@TؠGbC4NDOM^/j!#:MY(7E@1ap,Lndu&FPT dAI2R jG1E3 K:QA& kIFUalPu0djIdR &gc0wEeS=8rSomFd^I8ؓ/z~ G,2ƒ,1G >CܷݾČ[Aufhpu8/We2_'4=B/8G_d|_NO PCΐcguDPSzJc#2, 2Ju^W-]ږS9\QZk-4|N p4kB;uZ-w]mȔDj-wn,]նń" Uo[Lh\u:ZqW6QQmlZA@̂t0R) 01 ӑ OB>O1۲4 y03MW͊c[P @J4JLHPnnj-lwC\AN\;ӑَq*S-͎5&@w YE U)??HT\DO~+r]?DKFFeH&qIhc|E`H:FqʄA۞j.RM&=.6 ~)7HdcǃL\%NVκޮE$w\3RbK0LO8&}#2vޔ|>t(HW6U^J%BرYѫ*2VCh6[_ d2o4D{9`ɈRQR4l6m[ P`ɷ8F&LfBR$5lFE 8+ju}S;~TxD01LBZ !Y$> >1iw*ԴLs0, Sbt. g@zV|ʡ` q:6mo9 #1:]{͢i+"I%L%))bB*Öov9Wn 5#B|6RH r  !#QQ,D>(j)2@%$C5rh֪1m մV(beJ"*B ÐӈB0G$i۬4x7Ѭ׌fM p0@Q& aC!zmdLL%p0Ï2wuEk1"fP0;Ȏ" )ɓf*=RQ=ADRaHf KP;^ԇe+Y]l:!wy@τcQ_a`*%UM YXq%pO~Ā zHҍQDI4TI*!8"U/)t9%KEod|퀳m|(V,}c9 N5/FT/fFBFIeQ/Pb[3kbzhʸ ;̠{pnz  CJ61;齜×ЏGf]]ٔP]u$ "#! \DKRa L@aA((y?Wof7o@ѥ9`]" ! 1}?vɋPCxLP+C#zJ zrP%AFov/;&PU7o;?efukċo/ ڰHSQlL0 țL-&I4 1pDA*\3+rYFHF, j]5%t԰dpI2$4af$hhN#MA8Wen@6NcCB1B=q/X ŽB&f޹GyS{.#%n4&Ksm6x{<;3q,N >>s~pw8Jr[ٞO* "DPvv%:6MD%4氍9aW{0-."NA#nV =%T&A7>zhL$y9;_|6 *Nh= @k1ٲ[T{u$;9gvKcT|zJ3}*tG6J2<``#2q5&Na=e\ܾçP6IJXfz_>Ǵg{C\H w@ʍ vM(HcG× v`IR ij0 G ýE@ms"(*4KϤ9uLxCn|;C v޿8'R"ׯUМwldp"\7!4SY ֌):1h L.Ao{ x.έ"Jb ;PtgaG~ïtYVxf97C=瘦 ;EУ:`,bY`@1I&Xd%,!Xi! (L^)8\iNpwoף";=\bN31-:h)쐞3 iWwQ3JY}Oy6:{6Sp#0xMNCE:f'ݹ@؁bDa|%j@(r K4cOY,5!$[ף}FUMA`#RPL^76n6׊> @Q ul;X AcyY wM@U{`و3"bJ6@K6mո)QƊqݞ@N `0Ѓ"Yn[ i,6.g0EɈd=ip;p|0=7:! ۇ;7pK7<7⳧HDHG_+>BLp`}:Q43O훾xpIl׊ddt El Y, G\pyb>i&9DZ˾l#=6=YӡCZ`Dgax( ,) %4-m`,b= Hķ#cpV\yݎCD+hs =w7:(czL7wh釢xZ8IzzDJˈ9|>Z\ֻZbxCv][a3Mx n˜B݄K{f^8  i@,j)cƢgNrr}=:zCcOW VZh2\XKR׹Y69l IEv2ā\5FDrJ5.r{7y[g̳` =8nLuz]r#^<x;x#=Tm9Gm.֍9rOc%e^B=|+@pІ" >\m\e4gBTnm~8 ٸq1Ib\\ȴ9ŝ΃ Q#@H1.J8:3uwfz-W+jM֢HnwО_m{)9(\ -ZHE1Ў+⮆םѧSz5 k(N5j H>A=/Cr ;~OfY9qӓ$=)ehedF@.SO=\2x붝9cQ;nYB ǹ-0"# W\DbT2XC}V.!mHL=^]8!E }׿usvjG>Moo59m"G"(F֢\8ݜ#,NjhwQ&@"E4dX5Ne 8EQ!>d/P3VfM`dF X׶R&z$s+ɓs3s؅FjN넚?UIsc^ꫛ$E{n8*IP ZøL2N`5ED<#Uye @f{AǟX r{xbrj(7Uȵzl|rRW5CM'Z2G!xerRjj5߷"׊6ƌkURt%8gGi©Tp@iQ8e3»VUx8@7")J R0 jEԮHt$!@.@>TE8C"wt:]{ŷ ^v3{_4ppG.s[>c1pTNG1μuFh4# 2@D{yDPMhQ(E ^P|쨂 :8DC-d( r{(F¡fobm*P#FDj V5kFldlh& c" M A Vm%PQcbQmVţQFl`X,1"4ZlT ldj-"A Pb,a!mmZ*42H@1L"m"i10 )4b3Xڢ*̤aIQ hdmQ&,EcCD!VLkjF+hѢ5mtBDl &QRͪ5[m"EI&%vy`vaL!ZC0qhU Pj$UbdڈZjbb6l`"bY@Ƀ(W%\ 0@ aw)#B[kktjYQ+V{L6xv،Tc Ƀ&LQ#di;vfՍnd $0 l/ATo:׵(10EHji L*cbdA(P *zJSCL"#Af  nT =Er`|HBQ":eAH$ $ " LA>UES'~7'N*nv2L]B>>YP? U B`E`CFJK&6ZRIƪS(DzֶJmfd K ,B!# okwwmf |g]QDFJH%M1I!FJ6k(UPEʠ d|IT JJJrPD`UQ|H)%@}܈"d(=8QE a3Ppb |(=$}((dSz{S[i=:VVEfmb "qXw?#tt{:+YHIYjJ"J2Bz:K@%PHIa7Rдg@OT!{!' aMRl^ϴ^rĆ`Ha[gWx =b\x?rw_/0)|>O.nɟK[L7wϢa%bաt}(8LƏӼH$ux7:6RحljJGCramڇ:;X8@ĸl4 '%8ΘqmYH-K.$(+رN %mi0) f +˻ђZmt.y kДIopCHUXT'hb;;ef[QCI)l "vj#" N1kkDm·idA)V*# }]HܳG-V}.sPzbxݫ"3~][Dff< F gY|/re/o/sQAO5R*dվ#ovP8 2n"y@/Z lTT:#?pw/_@=D#I"E A$ξ=/%=wM"e8y@3U<%fs_Rxm|@o}-ۭI=ӱ>gnFXD姤( DAnŹur]P \1["s^I,%gU Aц`[[0ewc0MH/X|R͑!`OXDkfˏ߯a~lYeuHqw:4?ΑD ?tY]sen;ޗ>rj??y÷_ۖG._>^3Oj/egfiM[Gd o~w1mYR\.uN Ѳ[+/[PA>/D-~Gq"F Z!<QRf@l&‰ &Sq>;UM|g4иF,:LK I1;5ϥ h S(gy+, N$~1DuJkno*N(RI)C"UJXiaG,켐|N |A_{Sv C/kRY,&&G!xeulAyjʡ,{5B97 rn c y`}_}J%S$ʘѴ]Ij꤄`F?^GuQo#ʦ\}[O}ץzm^C2DNȷ#B@/6YYn+Kf!( a\H_q8X1񡑩ee++Ѝ`D?<̩ʢ`6PG'+ӄQϖz'Q]S |M6lQ B]%xc;BxQ_eJ0~S@Ȩn-)>)կ'Ĕs_T}EYY%JW?;z|>93uylm9}:‘k(5#Yk{<@DC'KJJ͒`.5ɰtn>=ș1A`͍W(d*+>D %j^,SYRk_99u]}u&8e!U72Ӕ|{rXmd>X׵)ՓVqP}0>SdrNo"~.|EmFzE*B&cHE)4F[/+wQ9tIN )װ@n8=s7lumaO;3 ǾAQ;gaC>& ˮ JK4w'yAohj-xY9}FGMek"nbdֱ1I+C ˓_owB{*so|`̭9ۑꩼҜ<$N@MR0b[CE ن䐅kOgN{*|G|IC OH/,ޕw*%o諗<܏DՠŔy5e>cdB=pD»8ѷ7zn[?q<ŚlcAY6 3SȑҪC͠{[~PȪ;+l D i>Ɩú ҟ0S#/${m,J \m,#NBAhŰ *J'f\qE1eYud Z# 1fEcBSKbcm;l`&Cݖ.G,-|m59 J PYʮo6G\+#ƹ&F8c9)caQ1t!Wpd;A%9)[?Q{3h #]x4Ƨɿ;@'@cM&  KQ&H@QpPȗxeiO~:J,=ӽ a"j5Q[Q$`IImZb:Yy~}":~&] ۩HTBi6'u(09=5F`¶Z1$m8溸`ɋjDj6趮."9 &̲OޒkT,gFݙjȹHΔ!r*ȯuf7.hOicrtL|t&=ɍ D61J ~DfC{ZnCbZT$R _i!fR]8Ii٣ei->يZW*[+qN}¸1~eEpvVcڜP{!Z!DQWIbyo#7y fP_aUɭ0{1rFٯGmʶU[q\“w+m y34۬tUlz\?鋾1O&j*+MEԚv; zQQ*f P+In{[4d &ߥt]bDg%tZ`/SkK®a2ѱ\D5ΉGi]G|3=4'"%N8δF~`LHgʶ\F/՜R/gv$+ǭ}rٔQn3I#kOT?!;ɝ/klXV{Dv)*o˖CA˂ߞjNIvOEz{ !J̙pTrGߘX? mC!1/(ŗ<#ճBwk W}d ~\+6tAg܏-DAb!DouҸ0 {he؅:1jCL_ ~sDeF,g=;{xW>,İ42z2 |yE.@kO.'Ou#& ${h bKez3~  Z0UϬt~mu3!>жm{?w3ݺ$Z>oYtaŗCt[uZNJ[p^{IϤd Z1L-x>@:HX`3zH3 8^z/ pD(Gdu9;9'艅hKȃ*o\t䡐nIZ^]vM^;YJe0)@zC"@@> ^2{%Y&nC|RW6rAFD(z AMۮ`œM1Zj/%US"ɏCNqSwpwWj6J~4D^e($kh+d U@{%0YM^S-[7ĦH*4 ?|7!JHzu xO{-M3A ?!EhcӇZ2EҒe^sW j|ǃK0]%I ː5ߦ[?mJc,`OmHR #]= V'-Kt˭e,@ڒ!Q E,Jb(2]:γ܂&x#RJ=m b 7ѽ"293-LHLusMʶ"^P9daBgPrhΝ7ÁLʣr9(.բ=K?zّ2b/Q 9żxJ 辥igJGrpP}w/ ׄ@?HW7(: dyjv g8fVb@sSMO93D)^Yj)~/ Ļ*ˑI~rylLl{e^gTˈҹ)̳ݕ\Hˆ@ޔB'4)` X8=1 x*s]Uuvyga_N.s+G{6FrӻY4`‡Vpp`eQhm/-c=6:{;HȞ)dH؞].L۩ܛ8 @x{gFH)JV̭. MMNSUzҚOsOk xTSEgMڪPJՕnłKSשׂ8suXuhao ZTV+7*L 6Wqߒ5k4wk!oxyF>2g !@syWOFQvΑU W0(dpyʏG1\b}$PAG!.>L*X3:?$b U2tç:J!XMa $C#uL]p+ II&h~T=DtB`+~l]`0deó1rȉ8撖'`"ˣt㲛d2Ӟ?t(2|Wb󓱄04M^WN(>3t̥"h!dhY7.>>띖֙8A_Z&W Jߕ39 NmL46V tT̢O\s98ȤYjRw(PY,"ش>O Q6mv?DWg8үD1RVg}iΔ v̲Wڲj0܁h$MX \깣NXvr[;\S*2Z +?z戦sMo/–zr56k>080[&G,b'{n&v|r27MZ-&L ]Ot$(pdhd0l@Kɤ:ܙ.R%8Z UwIZRxQIL\(}1">Y ~j-[[zZf8D}[[Tٯ<YG# .niOH* ,b2DHfIa-,É[<Ҫgɯ핐mk@mQW.CУ!m^cLxl"ktJ`6Ϣ`-/3蔃"w-:=`f8BXSWwϻBkݽ -V:t+i(Jp.&;5or@#FAJ7izh?2<` DȎ0@BsOP`}N9yy@ҾḲ:u&I9=?e\{N(qTփf[md9f HKMqT:H(-7CtFgY9lELÔ5Yl'6Fb,r5gFe9%bLxUGNU5 %.i),-d5%Sw\Ce`vf/~Ia -i,n!r8H9ns{c@#hH/t Ж}PworO"R&z*=ڣ)$wO/8(C2"˂*#m1 NǤ0I̴m֗ _Amh_m"+JB |:QPܿhS\krq x9uX̖'4(IxRA⟋w N22qA,f2{Fz ut>dž9c:C**gdCQ3Gk#=z=8JP)Ĕ>םe*MR:Yn(q8&a[׋ie DЩ `7?qTg.X+_b]t)llsO~ S9^8վY;}JFl]!Z&J`Q32KFȂIPaجv|ՋC3u$Ͷ>'ދ≍=8\^"' t#{[f HNJ'HUq̈́o*ohRb zJ2H)]5빖 V<՞>Le^)l>Yg7M;@|aj^?/tƟwX3D: xH;)lb).Ѻ<)bӀ żDCR! 6IF uF&uۆ-Ge`BVOn*VvqUSkmQuNZ|}f2*lhؚq(54;7t"C+|?V( ܆tƗ}so߯j?;%ݺ:6U#̸zw T?c 'Lfo97X+̉vXMCb|đτ~CW/'7RS -/'Vu` rRY8`U]rH6(Ԡw9 0F`kO =RPfԟ~i:釡6Q0? o{ؙ"Rɿ[160OifDͩw>)89 $Ҝ6][ɲӜ+|sħJ-s[cC~?RY@hkZIb(zF biD&عPHp,U3ѱ] EZVnVJuF|mZT!=<`\3vl a`J*.01-# ¬1?#?R$ٙaBAz2ѕ48Qs/AذlGORq^ŷOzRa{!w#m47{4e)bjnȘdJ5X#)|o!J 3A e[S\V z t.Ės Vzd{A893̭'t}SbR˸EBxT[,o%ՐzÄs]Bsw?cJ}P$$%v=.5n?9v5ļ5E'ma>߰ee$'Nj-]]@Bi\z$ow5U;X\]9Ua+cC3lqęUO^-f&'\, "*w-5HA)l1Hcb(o2X̐8nT#i1H9_Icd\mmѥsalC!~f&?{b~rrסyBZx*h-&!Wq4L`oY>tal%&iAɊ#f<]D5*-41E)R6Fg7)C>Y`|$~r%IjrN+Wfe7-#c몡ِd)SѯJG&ks sEyQeU9M3f%q)^=1'Yd LYy8ud8Pe45x6U\rvߊQF**"n&\êUyqFZ~ݝ0E "k?w\O"4>#bFPs z}-1Y.uԂy|A޴ zw/~BoyB0}!.h]T#W?=e#u; \>Obͣ%%_ugGlOSDgGB1&b3`X7J$*? ϪHφרWA6Sҥ-v,jH$Im؛[|; Iռ Ȯ[-~ 6 8SjXTy^0qi(+oP5rf&ϝi X(;?dlO,WI߸kSliOzG}Q[6 !fFAyw}[^yi>.avI|k%6j\ӞHk@]mXK 5֢mv'ZqJV"OIu$.S'Z>"3^,,<,ej'J`!eu,BKK#F!aй״.Ի*!ҷ/".mI)CBZ/Tf'7W}P_Ϸ,jZ]dԮ+v1R[b ~N8;u[ff%8ﴢTm[Jׂ9K-{KZJ۲xcW3?0Y<-,=VV`Dž/^-rm~=+)gWqBF|v( Mmڶ-WQ/$l0]qg(؀iTǒѫ4Zθ'5WHq~]!ts•qur#XF!9Y ܹ^|5أ+sڦ+<;"~<whv! ( vH()ڑlK:Pa+Wi b;q쯱_{-nY%F;0pB@3ll/!QUGhک|@̎u\4&wHCbC­eUCor1"cKC T0¯삐$n_!$o ܷȹ?:1V^\ގ< $p0\I޻@v)9!PHrr  p hp`,0v1ɘ4cuMDM[꼧,h3a__Fg93Fs~y4{\eF؛ӝ`צJ{k^>VQk1K\) D[*^tTl*"4˸ 6ŕIy3Umv|ӾC 1)JȢKqU6O"٤oq#I UBwG5k.yP1:lXYy񐬐>1KoT3h 8QZ $8ɅVBs7RIFszl1u&ds,ZGN8u=_{#dP>g/4HZ:lV L,9C dx  h=s92'okgVXЄ#<,E)k Y"FбSymm 8;9<Pؔ*u肚 3N~)CA# KX$Bp,2.?>f\t#8W2fd~0F$Lu;LFݷA=)|OC:ۨu7/]ԅJ:#njoHA~ߗ%9?aci^kYϠzt֞K]Z|}1K.Kn'9%GCTM4weݿk$wU/ m}ǼTa'D,X 7bc~tB"W.ق#rP@nJSs!a/:'=jK͖D1TR4eq5m;ex 9nUofW2n L`2;/n^,:hp9^Z^t\a#63T?LRYB[YU='YJ߆rJ>5f7q+&7lZrI6*Rk/lΧ#&W)"yK?;f/T@L>U8Q(t셞BI蘄~ {=ZAC GB^wI`BUIK#!a EcrwS67:t/'bl7EJApoKe2d 9ʼjs":׼KSR~1{ A5`PB= wȄG#g*fd2?PϬY,s2 u|vdƀif;ُя5 :We?<ⴳaT|@yt#R#R2*އZ[q95Pwīakz]-2&4 9 IfKS1zNvz^,1 {) ֱ5FRIZ!0k\y] κ87 CM0ܼs+&P@#3aq vxh_2pķM23pwCV#z3J9;W23J?[| Cǵ &I;7~ɒU̳~pϊy^D=Dۏ~N%h0򙤯rq%i*rWk<|}ݙ}XH@/SSFp̕e!!b(2=tR0`.MWjT\ 伈)5}A -k|BGؼsJ}Q9fy}ϲǰם5er/OZ+J3kPS&Ϳ-R :OIF`0GXR.Uy-G(u -U Q~vP.H#xJV%.kaD ꄆ_c~UM !Tp/jj[cjrlFPA%E{ jx.OpjZhE*8*$jr0QѨ",a#j{v=k%u I8p#Ɖ>ȦjAf *HTo]Cf܅-p/!>},*pʗUBQk@޹'ϵCI<<М8D!% EJK5 U:XG2Zy ~Flo?v -U'wBc!FWmdX7Nʁie~DJwOpdIo4"Lȹǜ4#t vLMtBRm?'Bhbʗiz7F#xQC0'G8U(CAPC= /-KMJύԬp:Etr"kj` ) TQNRň1;"dTn̒KE ÌqAnl9];twayT%PU'ɼI?\n *u릾nP VyeZ*̀di }? %qB&:W_ˎ$~Cɩ$TKCNG\zW[Gۍ1Wa+2m(V sݮBik QHTY Z,{o#>ɉ3it!3ж`8wd/R`3;MH(21kNx6@?/SmZse4hb [!]Beh^쟀?#xo3²eH_r⮡L.Z&PefJc(2jYʯaARkk~V B'6VfEVW0*$#kB1.Q=~CJ`߈п!%`?-"G()vRdѡ-ŀ Ix=6!\'qT٩p̀[%점|]I ߣlqoTCydɘ!{hUZIqa1d38a '@לn!Q 5O`Ϊ?HK*#ߪi;3IΈlK/Z/Yژa\+5DuyZVyE)V= E}.TtOabw T\x|d5<{ZK4F]Πjnje\X܍nsձ֕'vgie`i~DQkŭ3[0m=jb/^G/GyDI=)F*2PL0+ l巌m0wXi"_Bw4[NU*M>}db$-U-iמ1>MtycZ o[dz/#hlYl Xx*ι%DJcwQ$x * kͯ|b|`\"WGY+ds6;yźʖFm9i<.BE ~"F8MċF ) 5}ɱK: c[.x;Ѐo%H$gOJɍ4)c8 #qp:4SE5oS![& jn'@˳b_' 0)'a7@@'広dRǚ_;RF 斘P, M}LwV,G 'HGdRm&91R HVN7Q%5_R5jђ_.tچX${n;Z#H%[9gp7IQ`(v8+_ 0T_Ok02^AS%wU,;@V+:>6q5OI|DeS+0v3wqi+ə~OCxD&"WYop*;gsT12I_;6Ljobt=\w N=a?~/\-\ )œ BhjkTc3vśHXG^V>I>_a5jOZֶ7BonHKXmp΁ )qѳD7p=E5v|m 3HG !Ois@pnt?L% pִ 1$m:h)voTld7-naum[ԼaZ<ŦE Oݱ("R%;|[/TkcL-U*}F ptXe dBθ_&U^n&TVHtf6n8c#)FXBx7IFYt ^GV\6$58Nq֦C7ZfcX \A#@`W.ٳAr ף7Ju*!!fZ=!Yc]]B(ljRo}ՉF/LR}ЩI^ J<],/k}#Ć1|g kQ޸1[hP:=;;۱^;ZYZ^eFܙ iFh$o")ApDR@ϳ-XJs"J7' f 1r X>osH^-- N T"GgRwug3?PK!jY>w@: g-U9u"P'3#}_!H(/FYLA-xWsҜ=wO[%쐜J%ݿӃP!:BV`Āld!s K|ȪPq pH*HSM2z(v-Tmm~jH+ nӡ]n]{D L>M$S'rby7#_U>7:fDmb`x*٫g>T ωWS4ȼf@t]W+QuIh.#S>z9LK1DɈ{^5#(onرB輊ܫ'U[ӝZù> yx87ŒC.\B7?R 9@_w4Y2vRv%L'U[ dr!#4\ҁ.lu'b!Kfs$BCaXXY󑂜v]*Al~xə>#{HW ƀ8RglM2h4rB QYu4l8oux/zR' FuV0WC q W|;GBȡ78>tJ5Mr5e~)4_ (R|[9"g<6 @n"J'ܛR-yk.K4OF Eګyw̚_#50- ȆKh8ߓAFI}Gˏ /w Yx'Ũ-ͮj%[\\^awf*v|Icݤ() X=GqXɏlY;MRU+q[ʋjϴV>~e]p3!|V sʿ+~楗S8C;*eXvs&+ 5?ֈMVɢhw = aئK&Ŀ(ݭ&nwWrPfm,1*QV>UoGiY/&zEPz뽟s +_9h$m#I{Kq_x7: glCRdFȉNL:PYHkW4Ifj˓]6{Fr t y`{*FDwj֌4.wʯX&{殮يlSߙݴi)Cc!\ `}Jq K;ֻ'ڌqs ߞMW '9BM{x&6n-CdwĪm8X寳ba"lByT$ܟ,jr..h[Ʈʴ mPtBk'-+u1&WFwf8P}D{*.3c 6](#>ȓ"f$ZٺrM]*rD+Il|L KڟIv/œ;r Ƭ<֨zz¼3g&ThqR6bQ8Kyz=νME*4wiTr:ID3]eBw3= dm}xޥŝOMYȯcːh6xK5`n.u2ٲkXC">W i,MNkҬiX%e 7<8bhQ6cY(vm 53>mSq)>Ȉ|8'8S }Gӎαd֜y*^]e- ,YRc5§"0(D1ٺy‹ԯ Rbmgў ;f`f9Pۜʁ}\R;<+.K2dg&2 TlnTd*Wֽ|1_2}(Q8fճi:'b X)+0Xu!X3!Ս-MwqsqEvB9 M 1H7sJ{]6W]ps\`mQ{_ $#@yYъ(8y ?;ꭼw^]ͭ@d#~a$%:&6Vd%M_w\aQ~JL!k>Q !sυ5f]Fc /聴|v@ ^%P+Y66gzF /f>L5}\MkC퀰~5P Gǻ8p6>Gcz=J<͢kC| Bb`iVĿyǗFFaw.wc4nZv`;=|6k8G^_e2[-f#FH0֝NalM, %8JBW`o^˞K޶Y[E|ц76Xٸ}l9cUHˉ&ʭ?IoY=g7"O.>tt0 T.J8%(a+!kg_ACڴ! zN~FV'To19 xOK&Θffs6K:g5/A#pl폃^bI.˚2C A[{h'tcS|+W~C37ӧBY)l PuZG&[@py)YA/PC~A]X5F8=K5dpe"*0}ŀ˹ڙ XE ^q_:@X5n$8ꏨCd>]oKs@dlNovbQRZ;M9#+z_CH71f}$vߔe;;Ohr\)Iv ֛9^ע6B=5 +k$›k [;='˘VaE{B- 81]ia&+/eXM_<{Q4c'XVa܅NhQ̔s~/hN&z džT<8=@VGdu"A`)T{ ^s=|mP*Jn6Fd+ljq*ʶuWxB{T\U@ "y{Vn~ /Y"ڹ;O QGsù9aTͷ$:@Cf?D%BRfnHiweeڇ:oPF!ٚ p/I*6W#+2GcMw.W8UHk-iۺ?omriÇBNl eTTӨNMVԍn-`HKnQv突_yGJ6t;<5&} ߵ%|}POPX3Q<'";eSz?8rɫق̒H)``忺K4h}&/A1k;;q!p1+Y"ClejCקQ<\ev+W&Xx7Ńߢ)gqHv5"8^B}ÛYdLme0I{YD3!!oDrk\N@ UM)5:ڇ1߆lN=;Ao\SHBl_\69%{fh(/"mSzw4Ѐ0A̽oEz5Ǡr~4*/>eMpR[LliGX>v/hDAw/~2NvVуNNo+Y mAm9cA%bBӾ \ HY%ǎ*]~7 zd[Û|Pss2:c .[9J=b"{X 6dBԏf$!=gJ"g?FccA_~4 O?ĒL]C ͅ.;]xKtVNξ>vcty:.QMW&Z2/ٸS4vgë1\75~lοymy:L.!3ف;Z&nAa 3o XCm_yޘr\T313- =f+D^сgȊ'j/˦zyFŽ2K5کhf|cAeNuAj5ˤG| Vw?@ƞ86t̙Y(i\cF][H0K"G@FWU!.7̦FIR7ͣt+ͬ[O ݻ% {Q?=~w:Qj3~Ffz>kh7|߈HZ!?ל!|\e_r-S_QeA(x?a?rHvd! ]&wM }/D:lxYM)-DO+x< -%IҔn8PkwRG*(n4 qV4gZQnm1D~Y7 >Rjx\b<7Hgw_h-f9Kt?K#lV@\6X}CK H4b7c7vحb.SzםdAj:UBU|1jɣP>g)M"؝I NG0^{ۤntzCT 5.;I+TY B8B8XCvP 劶W@[h,*A S*B4D"±k b$N(P_um~s&;U8%#ک~'8PL3ɭDJNtYa'a;ŶۤL?u:aSb׿ Z5̽/|{ilEj9ڙU()1CAsJK .$=, sx^:+߆ UƟ7WG!!~pX ]vN3\KĖM*Tܩae&_Ayc2l%uF=p+ fQJT7Bn>ߏJ_1&qr(E%:}4,23]F'('0F`SF7\E(t_/iVix*s΋=RgeJCuLr(/~g`ėbwbØ !u'`^ L@RB4 ƅ,6NL%9ߎ Z;7"rn\,m?4jp yeg-ζYx\&ȫLA=š4Vn%*xZy*ѵzWc0/MVu!'~5;upb4 3+ϼ7QB D$~˞]^t6mj®/-F>{;4g_޵o漟9;rĝE[a3cAew?Y1@QD9q$'#lvl=Casyge9Y6,ΣYeXEQ{ k'A|;{|o*m bG/| W \ kf--ҩpsw9/6y(x߲( u2ָ 5I&>} :v餿F=󴫘 $SDg/z͸uzvӰ` : 5XznWlOաDg-Qef5geHmDqr^;a\eu+ 4TC.,7JiXw_Kz_iFl .,S1ڔq0mn삤}#ߵtr K#XMGj6ϋv CQFf^p"Q=M}D7ӹI1\K/;~QM e-i89hXI[[D6Tm{qQZCҤABωF~XX]͈lkgCdJRY,X;@Y&]Wq|52  ~5],V،F-{x$`rVmÌHךE/u{gp8 jH%.pR :$(k+IRb}BlVR2SYk3.q%!,M-J<-@ꂴLUsldaRU)T' =bj2kU/VGVhl 莯n\Cwzv8g;C u7ҭ1; @NI޻T{imXӘβkkb#XN>ki謬 ܈+]X屑~;?F(02F$kz@-uqmLA珺h5uUvtM[VTbJVᑲN%̽3 38cK7>K:C #CЏ0h$:X`^:|V5eW)cYnf-jU5kEXTrb·᳗(r?UE[ʞ4X S渥|{hڷ(&h\?cVB?Kte;z38aQ><#WP8ߚ'v{Gp _qe1XzSYbybُpa+U=?tQ!{gCPڈy/8)Vg% 3kP$,9^|`\^Ia -X 166\q ?5θRL!Na?` El(jA_Zl.1&sCAO|@d Ԁm9RH<49:Y8h YZ