knot-libs-2.8.4-1.el7$>9|d} `R><hh?hXd   V 39D p        S     .H t<(8#9#:6#>bL@b[Gbl Hb Ib XbYb\c ]c, ^cbd<ddedfdldte ue< vehwgH xgt yg$h0h4Cknot-libs2.8.41.el7Libraries used by the Knot DNS server and client applicationsThe package contains shared libraries used by the Knot DNS server and utilities.]~buildhw-aarch64-08.arm.fedoraproject.org FFedora ProjectFedora ProjectGPLv3Fedora ProjectUnspecifiedhttps://www.knot-dns.czlinuxaarch64  -A큤A큤]]]]]]]}]y]-f]}]-fba5f5383c236323babde0bf461bfb6aabfbfb4b5dd9c8252c872eb150c3499fe7b93038dd931f822d2c6ccc2c525c602eb27fc462a2b7fba66857270f791373c1bf24e5c76977f5a841de906e75f9154b405915507799d3d6b4cfeb9fba848f7846d8cc92c1ddd0f507546b3d3725eec2fc9f309dfb69966dcc94625b73a34d1d9cff4fdc089e76ecb931ceafdd01de43e59dce46da03fec2530923461ba0184f3a40fa71014a0874cef24c286922ad46e2f564f445444595a93e03203b54b0dlibdnssec.so.7.0.0libknot.so.9.0.0libzscanner.so.3.0.0rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootknot-2.8.4-1.el7.src.rpmknot-libsknot-libs(aarch-64)libdnssec.so.7()(64bit)libknot.so.9()(64bit)libzscanner.so.3()(64bit)@@@@@@@@@@@@@@@@@   @ /sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libdnssec.so.7()(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libgcc_s.so.1(GCC_3.3.1)(64bit)libgnutls.so.28()(64bit)libgnutls.so.28(GNUTLS_1_4)(64bit)libgnutls.so.28(GNUTLS_2_10)(64bit)libgnutls.so.28(GNUTLS_2_12)(64bit)libgnutls.so.28(GNUTLS_3_0_0)(64bit)libgnutls.so.28(GNUTLS_3_1_0)(64bit)liblmdb.so.0.0.0()(64bit)libm.so.6()(64bit)libm.so.6(GLIBC_2.17)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.11.3]@]]2@]'$[ @[H@[E@ZnZZZZ}@Zz@Ze@ZNYYYXƉXX@XAXJX-W#WhWWV&@VUUUUa@UG_@T@T@Tomas Krizek - 2.8.4-1Tomas Krizek - 2.8.3-1Tomas Krizek - 2.8.2-1Tomas Krizek - 2.6.9-1Fedora Release Engineering - 2.6.8-2Tomas Krizek - 2.6.8-1Tomas Krizek - 2.6.7-1Tomas Krizek - 2.6.6-1Iryna Shcherbina - 2.6.5-2Tomas Krizek - 2.6.5-1Igor Gnatenko - 2.6.4-3Fedora Release Engineering - 2.6.4-2Tomas Krizek - 2.6.4-1Petr Špaček - 2.6.1-1Petr Spacek - 2.5.3-1Petr Spacek - 2.5.3-2Petr Spacek - 2.5.3-1Petr Spacek - 2.4.1-2Petr Spacek - 2.4.1-1Fedora Release Engineering - 2.4.0-2Petr Spacek - 2.4.0-1Jan Vcelak - 2.3.3-1Jan Vcelak - 2.3.2-1Jan Vcelak - 2.3.0-3Jan Vcelak - 2.3.0-2Jan Vcelak - 2.3.0-1Jan Vcelak - 1.6.8-1Jan Vcelak 1.6.7-1Jan Vcelak 1.6.6-1Jan Vcelak 1.6.5-1Jan Vcelak 1.6.4-1Fedora Release Engineering - 1.99.1-4Kalev Lember - 1.99.1-3Jan Vcelak 1.99.1-2Jan Vcelak 1.99.1-1- new upstream release 2.8.4- new upstream release 2.8.3- rebase to latest upstream version 2.8.2Knot DNS 2.6.9 (2018-08-14) =========================== Improvements: ------------- - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation Bugfixes: --------- - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_RebuildKnot DNS 2.6.8 (2018-07-10) =========================== Features: --------- - New 'import-pkcs11' command in keymgr Improvements: ------------- - Unixtime serial policy mimics Bind – increment if lower #593 Bugfixes: --------- - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy #589Knot DNS 2.6.7 (2018-05-17) =========================== Features: --------- - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) Improvements: ------------- - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination Bugfixes: --------- - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback modeKnot DNS 2.6.6 (2018-04-11) =========================== Features: --------- - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation Improvements: ------------- - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination Bugfixes: --------- - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)- New upstream release 2.6.5 Knot DNS 2.6.5 (2018-02-12) =========================== Features: --------- - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set Improvements: ------------- - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates Bugfixes: --------- - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations - Failed to generate documentation on OpenBSD- Escape macros in %changelog- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Added PGP signature verification - Added integration test - New upstream release 2.6.4 Knot DNS 2.6.4 (2018-01-02) =========================== Features: --------- - Module synthrecord allows multiple 'network' specification - New CSK handling support in keymgr Improvements: ------------- - Allowed configuration for infinite zsk lifetime - Increased performance and security of the module synthrecord - Signing changeset is stored into journal even if 'zonefile-load' is whole Bugfixes: --------- - Unintentional zone re-sign during reload if empty NSEC3 salt - Inconsistent zone names in journald structured logs - Malformed outgoing transfer for big zone with TSIG - Some minor DNSSEC-related issues Knot DNS 2.6.3 (2017-11-24) =========================== Bugfixes: --------- - Wrong detection of signing scheme rollover Knot DNS 2.6.2 (2017-11-23) =========================== Features: --------- - CSK algorithm rollover and (KSK, ZSK) <-> CSK rollover support Improvements: ------------- - Allowed explicit configuration for infinite ksk lifetime - Proper error messages instead of unclear error codes in server log - Better support for old compilers Bugfixes: --------- - Unexpected reply for DS query with an owner below a delegation point - Old dependencies in the pkg-config file- New upstream release 2.6.1 Knot DNS 2.6.1 (2017-11-02) =========================== Features: --------- - NSEC3 Opt-Out support in the DNSSEC signing - New CDS/CDNSKEY publish configuration option Improvements: ------------- - Simplified DNSSEC log message with DNSKEY details - +tls-hostname in kdig implies +tls-ca if neither +tls-ca nor +tls-pin is given - New documentation sections for DNSSEC key rollovers and shared keys - Keymgr no longer prints useless algorithm number for generated key - Kdig prints unknown RCODE in a numeric format - Better support for LLVM libFuzzer Bugfixes: --------- - Faulty DNAME semantic check if present in the zone apex and NSEC3 is used - Immediate zone flush not scheduled during the zone load event - Server crashes upon dynamic zone addition if a query module is loaded - Kdig fails to connect over TLS due to SNI is set to server IP address - Possible out-of-bounds memory access at the end of the input - TCP Fast Open enabled by default in kdig breaks TLS connection Knot DNS 2.6.0 (2017-09-29) =========================== Features: --------- - On-slave (inline) signing support - Automatic DNSSEC key algorithm rollover - Ed25519 algorithm support in DNSSEC (requires GnuTLS 3.6.0) - New 'journal-content' and 'zonefile-load' configuration options - keymgr tries to run as user/group set in the configuration - Public-only DNSSEC key import into KASP DB via keymgr - NSEC3 resalt and parent DS query events are persistent in timer DB - New processing state for a response suppression within a query module - Enabled server side TCP Fast Open if supported - TCP Fast Open support in kdig Improvements: ------------- - Better record owner compression if related to the previous rdata dname - NSEC(3) chain is no longer recomputed whole on every update - Remove inconsistent and unnecessary quoting in log files - Avoiding of overlapping key rollovers at a time - More DNSSSEC-related semantic checks - Extended timestamp format in keymgr Bugfixes: --------- - Incorrect journal free space computation causing inefficient space handling - Interface-automatic broken on Linux in the presence of asymmetric routing Knot DNS 2.5.5 (2017-09-29) =========================== Improvements: ------------- - Constant time memory comparison in the TSIG processing - Proper use of the ctype functions - Generated RRSIG records have inception time 90 minutes in the past Bugfixes: --------- - Incorrect online signature for NSEC in the case of a CNAME record - Incorrect timestamps in dnstap records - EDNS Subnet Client validation rejects valid payloads - Module configuration semantic checks are not executed - Kzonecheck segfaults with unusual inputs Knot DNS 2.5.4 (2017-08-31) =========================== Improvements: ------------- - New minimum and maximum refresh interval config options (Thanks to Manabu Sonoda) - New warning when unforced flush with disabled zone file synchronization - New 'dnskey' keymgr command - Linking with libatomic on architectures that require it (Thanks to Pierre-Olivier Mercier) - Removed 'OK' from listing keymgr command outputs - Extended journal and keymgr documentation and logging Bugfixes: --------- - Incorrect handling of specific corner-cases with zone-in-journal - The 'share' keymgr command doesn't work - Server crashes if configured with query-size and reply-size statistics options - Malformed big integer configuration values on some 32-bit platforms - Keymgr uses local time when parsing date inputs - Memory leak in kdig upon IXFR query- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble).- disable dnstap on RHEL (depedencies are missing)- new upstream release WARNING: Automatic upgrade from versions 1.y.z is no longer possible. To migrate, upgrade your packages gradually or use contacts listed on https://www.knot-dns.cz/support/ (if you are in trouble). Knot DNS 2.5.3 (2017-07-14) =========================== Features: --------- - CSK rollover support for Single-Type Signing Scheme Improvements: ------------- - Allowed binding to non-local adresses for TCP (Thanks to Julian Brost!) - New documentation section for manual DNSSEC key algorithm rollover - Initial KSK also generated in the submission state - The 'ds' keymgr command with no parameter uses all KSK keys - New debug mode in kjournalprint - Updated keymgr documentation Bugfixes: --------- - Sometimes missing RRSIG by KSK in submission state. - Minor DNSSEC-related issues Knot DNS 2.5.2 (2017-06-23) =========================== Security: --------- - CVE-2017-11104: Improper TSIG validity period check can allow TSIG forgery (Thanks to Synacktiv!) Improvements: ------------- - Extended debug logging for TSIG errors - Better error message for unknown module section in the configuration - Module documentation compilation no longer depends on module configuration - Extended policy section configuration semantic checks - Improved python version compatibility in pykeymgr - Extended migration section in the documentation - Improved DNSSEC event timing on 32-bit systems - New KSK rollover start log info message - NULL qtype support in kdig Bugfixes: --------- - Failed to process included configuration - dnskey_ttl policy option in the configuration has no effect on DNSKEY TTL - Corner case journal fixes (huge changesets, OpenWRT operation) - Confusing event timestamps in knotc zone-status output - NSEC/NSEC3 bitmap not updated for CDS/CDNSKEY - CDS/CDNSKEY RRSIG not updated Knot DNS 2.5.1 (2017-06-07) =========================== Bugfixes: --------- - pykeymgr no longer crash on empty json files in the KASP DB directory - pykeymgr no longer imports keys in the "removed" state - Imported keys in the "removed" state no longer makes knotd to crash - Including an empty configuration directory no longer makes knotd to crash - pykeymgr is distributed and installed to the distribution tarball Knot DNS 2.5.0 (2017-06-05) =========================== Features: --------- - KASP database switched from JSON files to LMDB database - KSK rollover support using CDNSKEY and CDS in the automatic DNSSEC signing - Dynamic module loading support with proper module API - Journal can store full zone contents (not only differences) - Zone freeze/thaw support - Updated knotc zone-status output with optional column filters - New '[no]crypto' option in kdig - New keymgr implementation reflecting KASP database changes - New pykeymgr for JSON-based KASP database migration - Removed obsolete knot1to2 utility Improvements: ------------- - Added libidn2 support to kdig (with libidn fallback) - Maximum timer database switched from configure to the server configuration Knot DNS 2.4.4 (2017-06-05) =========================== Improvements: ------------- - Improved error handling in kjournalprint Bugfixes: --------- - Zone flush not replanned upon unsuccessful flush - Journal inconsistency after deleting deleted zone - Zone events not rescheduled upon server reload (Thanks to Mark Warren) - Unreliable LMDB mapsize detection in kjournalprint - Some minor issues found by AddressSanitizer Knot DNS 2.4.3 (2017-04-11) =========================== Improvements: ------------- - New 'journal-db-mode' optimization configuration option - The default TSIG algorithm for utilities input is HMAC-SHA256 - Implemented sensible default EDNS(0) padding policy (Thanks to D. K. Gillmor) - Added some more semantic checks on the knotc configuration operations Bugfixes: --------- - Missing 'zone' keyword in the YAML output - Missing trailing dot in the keymgr DS owner output - Journal logs 'invalid parameter' in several cases - Some minor journal-related problems Knot DNS 2.4.2 (2017-03-23) =========================== Features: --------- - Zscanner can store record comments placed on the same line - Knotc status extension with version, configure, and workers parameters Improvements: ------------- - Significant incoming XFR speed-up in the case of many zones Bugfixes: --------- - Double OPT RR insertion when a global module returns KNOT_STATE_FAIL - User-driven zscanner parsing logic inconsistency - Lower serial at master doesn't trigger any errors - Queries with too long DNAME substitution do not return YXDOMAIN response - Incorrect elapsed time in the DDNS log - Failed to process forwarded DDNS request with TSIG- configuration checking was fixed to be compatible with Knot 2.4.x- new upstream release 2.4.1 replaces old 1.6.x series which is not supported - configuration should be upgraded automatically using knot1to2 tool - make sure you reviewed the new configuration in /etc/knot directory!- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- new upstream release: + fix: False positive semantic-check warning about invalid bitmap in NSEC + fix: Unnecessary SOA queries upon notify with up to date serial + fix: Timers for expired zones are reset on reload + fix: Zone doesn't expire when the server is down + fix: Failed to handle keys with duplicate keytags + fix: Per zone module and global module insconsistency + fix: Obsolete online signing module configuration + fix: Malformed output from kjournalprint + fix: Redundant SO_REUSEPORT activation on the TCP socket + fix: Failed to use higher number of background workers + improvement: Lower memory consumption with qp-trie + improvement: Zone events and zone timers improvements + improvement: Print all zone names in the FQDN format + improvement: Simplified query module interface + improvement: Shared TCP connection between SOA query and transfer + improvement: Response Rate Limiting as a module with statistics support + improvement: Key filters in keymgr + features: New unified LMDB-based zone journal + features: Server statistics support + features: New statistics module for traffic measuring + features: Automatic deletion of retired DNSSEC keys + features: New control logging category- new upstream release: + fix: double free when failed to apply zone journal + fix: zone bootstrap retry interval not preserved upon zone reload + fix: DNSSEC related records not flushed if not signed + fix: false semantic checks warning about incorrect type in NSEC bitmap + fix: memory leak in kzonecheck + improvement: all zone names are fully-qualified in log + features: new kjournalprint utility- new upstream release: + fix: missing glue in some responses + fix: knsupdate prompt printing on non-terminal + fix: configuration policy item names in documentation + fix: segfault on OS X Sierra + fix: incorrect %s expansion for the root zone + fix: refresh not existing slave zone after restart + fix: immediate zone refresh upon restart if refresh already scheduled + fix: early zone transfer after restart if transfer already scheduled + fix: not ignoring empty non-terminal parents during delegation lookup + fix: CD bit clearing in responses + fix: compilation error on GNU/kFreeBSD + fix: server crash after double zone-commit if journal error + improvement: significant speed-up of conf-commit and conf-diff operations + improvement: new EDNS Client Subnet API + improvement: better semantic-checks error messages + improvement: speed-up of knotc if control operation and known socket + improvement: zone purge operation purges also zone timers + feature: print TLS certificate hierarchy in kdig verbose mode + feature: new +subnet alias for +client + feature: new mod-whoami and mod-noudp modules + feature: new zone-purge control command + feature: new log-queries and log-responses options for mod-dnstap + feature: simple modules don't require empty configuration section + feature: new zone journal path configuration option + feature: new timeout configuration option for module dnsproxy- fix post-installation scriptlet (RHBZ #1370939)- endian independent DNS cookies (fixes build on ppc64 and s390x)- new upstream release: + fix: No wildcard expansion below empty non-terminal for NSEC signed zone + fix: Don't ignore non-existing records to be removed in IXFR + fix: Fix kdig IXFR response processing if the transfer content is empty + fix: Avoid multiple loads of the same PKCS #11 module + improvement: Refactored semantic checks and better error messages + improvement: Set TC flag in delegation only if mandatory glue doesn't fit the response + improvement: Separate EDNS(0) payload size configuration for IPv4 and IPv6 + feature: Zone size limit restriction for DDNS, AXFR, and IXFR (CVE-2016-6171)- new upstream release: + fix: Transfer of a huge rrset goes into an infinite loop + fix: Huge response over TCP contains useless TC bit instead of SERVFAIL + fix: Failed to build utilities with disabled daemon + fix: Memory leaks during keys removal + fix: Rough TSIG packet reservation causes early truncation + fix: Minor out-of-bounds string termination write in rrset dump + fix: Server crash during stop if failed to open timers DB + fix: Failed to compile on OS X older than Sierra + fix: Poor minimum UDP-max-size configuration check + fix: Failed to receive one-record-per-message IXFR-style AXFR + fix: Kdig timeouts when receiving RCODE != NOERROR on subsequent transfer message + improvement: Speed-up of rdata addition into a huge rrset + improvement: Introduce check of minumum timeout for next refresh + improvement: Dnsproxy module can forward all queries without local resolving- new upstream release: + improvement: Log change of the zone serial number after IXFR transfer + improvement: Document operational impact of various RRL settings + improvement: Add support for rate-limit-slip zero + improvement: Add 'timer-db' configuration option- new upstream release: + security fix: out-of-bound read in packet parser for malformed NAPTR record + fix: systemd startup notifications- new upstream release: + fix: don't load expired zones on reload and startup + fix: remove race condition in scheduling causing delaying of events + fix: NSEC proof construction in zones with many delegations + fix: TC flag setting in RRL slipped answers + fix: disable domain name compression for root label + fix: check if executed under systemd before using journald log sink + feature: write persistent timers on server shutdown for better performance + feature: support time unit specification for 'max-conn-idle', 'max-conn-handshake', 'max-conn-reply', and 'notify-timeout' config options + feature: add 'request-edns-config' config option- new upstream release: + fix: lost NOTIFY message if received during zone transfer + fix: kdig, record correct dnstap SocketProtocol when retrying over TCP + fix: kdig, hide TSIG section with +noall + fix: do not set AA flag for AXFR/IXFR queries + feature: new configuration format in YAML, binary store im LMDB + feature: DNSSEC, separate library, switch to GnuTLS, new utilities + feature: DNSSEC, basic KASP support (generate initial keys, ZSK rollover) + feature: zone parser, split long TXT/SPF strings into multiple strings + feature: kdig, add generic dump style option (+generic) + feature: try all master servers on failure in multi-master environment + feature: improved remotes and ACLs (multiple addresses, multiple keys) + feature: basic support for zone file patterns (%s to substitute zone name) + improvement: do not write class for SOA record (unified with other RR types) + improvement: do not write master server address into the zone file + documentation: manual pages also in HTML and PDF format- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Rebuilt for nettle soname bump- fix BuildRequires for systemd integration- new upstream pre-release version: + DNSSEC: switch from OpenSSL to GnuTLS + DNSSEC: initial support for KASP - split package into subpackages - add documentation building - restart daemon on updated/sbin/ldconfig/sbin/ldconfig 2.8.4-1.el72.8.4-1.el7libdnssec.so.7libdnssec.so.7.0.0libknot.so.9libknot.so.9.0.0libzscanner.so.3libzscanner.so.3.0.0knot-libs-2.8.4NEWSREADMEknot-libs-2.8.4COPYING/usr/lib64//usr/share/doc//usr/share/doc/knot-libs-2.8.4//usr/share/licenses//usr/share/licenses/knot-libs-2.8.4/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 drpmxz2aarch64-redhat-linux-gnuELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f584b0a3fff3fc351975510f2d8e23094ec626b8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=90f2079e873a1fb5d61673c5112da46071d379df, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f9fc8537f09719f8a1e19aa42aebb67a1e40622c, strippeddirectoryUTF-8 Unicode textASCII text PRR RRR R RR RR RRRRPRR RRRRRRRRRRPRRRRRRRhttps://bugz.fedoraproject.org/knot?@7zXZ !#,kc]"k%a#d/p=IttAyu$'GPvqFVĀj}Cܣ\QˌX*!7v\3$͙xa0{b擹/Hdf\>d:U8؆C?/#- zL3+ Vne[x! o]lzM$mZV~?aǣ,t-̯L퉈vsJG6_".BUpHžu> X d|~#9)3rʹyelۮtL8쐬JdD+a&OMJ_14Т `I{Nbh#1x5ԠXj 9)YBh E=ݦo&,bf,!6JL\`:+WLi['hJr̒glSqIi{`Vfm}'}Rl<]S?{UեX^q12X ɂ湡('Kc9RH>;nac;;v Ghz T hz!0vVMؕ K}KJ'' ȃ3 w.u1^<PdpaȦ= #KT BQBdp٢ ;>Bc]iRݲW5 @{\Uu/ ;i&1׊:.74'<H=&VF6r]a!Zm t9bxN3'W H%Gz0w(@/-k,0֑skKD&cxV`=55d`?WB$_V(/<$ɐfE/+!;h@kv3_Pr(L=T-v23Vu?gZeL糶-FV ݓ9~ۏLW 7o,gocEnLՉqZ *.ՙqT/v_q\IJVPDwi'\],Or÷HZZen} *wgn)GXbhNhr*l@bShXӁ lOt bK@Ё\AȯjۂY Fj#s.Lߝ@jIhp$!W Zӆa~!O!myJ-psĚx@x{?j̈́3U%fq4ڨޯR?V-?buo^A#yaʍf ^ymUp@]35VڃjF=9CrYʌ +<9P{50ko//"!ߕik(I,'~03|;6iK@Us".p*{(glcJkee l LLlmgVv⿃@&vÿ́רS]1 ߍn7HCLތLSz/@t/0#V9)#Ѣn*Gh'[BVO xҦ~@m}) g0 LqWM{[t 3N.%:i]h$O\`L ]d?ւWQ fQb2\dP󼈥FZaU3೮2Z,H k`|w{2Ɋ\,kq8)7ͣYKJKI+C5u:,?Y"xJR0G߲Ubh[ˌKޝ@.hY1)pcA񰻳M3ebE6/"FcԤ_#Um2I?f$b 2)t~vx+.ud'*\W@N0V,X&-QmԢaV˪Yy.ΥC} lɡY "\AN%y=6ŁI7v36nՋ88uИ"i!Pܤ׊|C2クұy\-24W#+D4f[w.O1@&e&Zx;/}t{AТv7alQ/H3-! C忿E"n?XL!`i(d1-/10!&{]j 4Sj5gTC^lߚ/ jf_͛F:֫hiҪeZ^r %bUoNaz1^×?",ҔG';#ڡևH%/S9Ycگ#W#p GX2 5 ڸTEƾG %"6urr"NPLVuM|'I?͊S TnjY6HQfy |Ѭ>CI-A*j,Q$>X_8u^z1[uL֋(#X{a,jċ2^7쭭r+*qq`-IxcO1d XJ&Qc1#ޤCfzUؐ5y9ѐKh5㬷˿q&iDս)܁*ѕ .Qj:Ad*]XƓћ}y ֋ؔBCswpp82wRd ^5+fi`aÄN+8̨ b|&vF+5Ғ%yt)U3PVV<G WC_@7|{\cz䶬W~)mI2:nHm:S^;}VX&Q{muJ- 8b7>Ms I&<ʨ=6u~ʳ[x I`*WͻV 7KT+0y8k`28ɂZfI 9@:>؛54BE_)ùeJ58nJH{3&:Lҁ6v1ԂO}pr nLYkYքd[*_SS\qhd_9 {BqJٱoC3&݊5!0߹>Fn:5 1/|`q)fKy և71noi#' AGBp=P9ĄO'င&ɬ"ӫra_$SeLUG*lj#B*qbF!ɫ£eýɥ)YEȃ o>76`ha(^ VףR4LX 󄙍(.НEd53̷0Vav-t:JHMŷ(ژ~Rφ`Q^:ZF%#e@{'w&њ++=dRv} .ۄoW4fR6_]U|7-.JPb sCa+q}LlGz8iqӢQAݕ=b?VAE`:|lbi$P⸣!dpADV=8 ]FݑSAUBqωg !_g*Sar(a|8+5V\=Hs+ߔD=0|HsY(#27fbh9Go/.yw]Vd [uArRKL1ݟ}p$A("U!03)Օ"Dĩ?gdGseГqRܸ!;Zj]ҿw[p3~&R8?`3 vJ Uc`?\OKhxi|鋚-H(Db 愕\Z C+)ZCPFF3oi 44Czyqۊ9J]1Bb :䂟ԭ, YID}D08=M_O9՜c*YSmA&2T bk,bLCū`u{ ;vH/ptUWH$lscoy %@,f!AV޲MohD *̏&ՙ^#ơfM_X%Pjd0k.u}Mê sގpY@$_ɬIm*qs.XShԙB#7AW_OБn2t1NzjOc `x <F1gAWӏ5kŒURdSƇCP0xvĖvI܏rg$E#BB/\WN(׍[ .(-mm6eI9g,_6=L 0[֊m<(1nE}VlKmF r chsn:'"lANf5CVZ7QU-`k /NŕO F]q D{,3SVsK;Pٰ>ո9痌ãm2bO AhG %AZ2YMnKt%6G&exMD5r̿-H1:y.~F*5z;X2vIv0Bћ\6 ;$h-V1tMA^ JOi3rMk<$}i+!+{̌!\/Y'~^XՂV–QB:-ϩQԹi_&IQ\^Hw쭰΍@7"TvHMg1ܜQdI#A` ǰ'hxc˜*:XȌodF*0QA{h!ʌUI.?Jif3B^2t~#G~,ViסM ,%,\܊Ut feߥxW8Gn 7J&eNԨAFGN".\b[aiK9>?~~6@=L ׁtӁ*mi|߄isl R4PEA'ze#![MIkVW,j.ߛ]胟LyI}]ĉI&u,E0W-`Ъ,l w<5B}ߎ:Yw5Q:/ jTADz7ܹNt<' jEp6' Źۭ3|Q#e: x RX9C8x9IjW`x#~>1OhL co(qTha{F5fPr 847Q=/'吰|JZuV4PG&f-X?Ѿz%; BzZ ^#`ȔoMB}fa)FqV0+pj> |j[ e!.fWhyyHՈ۔"'"Qx%H4Whs^&)- G>y6C=Ay4bδ4+Jdl#&GѢ2bgxO΃k?[0_s~p_qR62ߤ[i$țW`` {ȷ!'f"J'Nk! 3Kg|J Tp7&zhpZ)J)I;H}m$i2`:_| ٛ:Z:+oc&cR6?~էR`ㄑ5p Xߪ8Bt0h\7 Piyw*x1ɿrޡĶP?ُaLͥ܌ǭ&9 'QD3a㰬=+SD -h B`ThIbu -ImZBi5YC]<*bQQ+z~Iݰt^&RH..8$)O?yNs`G~l=!fӵYMڦeillB \շ ct6,daBLl@RN#v CB E6k^q8Lޟ`<ϘU)]]g&233.Ǿ+O~|r6+zRȴ&`^ Z``(ŵlIH^Sw󯗍>+Jc4e8ĀsU9kcOA6]|>F{?>l*ಾaM3ꘪzNPíjFۛJu$v :4Up׎t๢Ho(ȑ(6R0.W= /8AUbͮRxǹR(/O^D~'LAԛaq-_A٬`MnB =9!gb2zjc aiy{<3}cu}%7X2yyס3Rm:kgxkgrgz(yvm|zJ4Hh‘ߞaZV []3m E垽"_Hp~ :I꺷s^#[ڏhgF$ag,KK%S5CS;}'I$fr ?,&Ύ t=S?BvHHA)pEJ@ɫ,ͮ$QRn`Ox"&Kn*|rF͞HӖUa%+"xc lS"|¶Y),r39 s(Y(Ş2_3\an(mQ5O+A8vtv'"= ) ]zŸf;^pp5q]IT b L$soQ4nZ"#"\Q-Kpg Vq]0(mѐ%;;oMY!reOsmk]\Y@ MkΡ0QJڟG0ɏ5͛1D͟n<֩ \6;pe5] ]jPWBX@?Eyw\ {)mVį;\ (O`M2D\‰S.dLӭVCUa bwV.)@wshK*0v|=WbER%de-PV,R!w0u1A{7oCF҆jyvR3o(} ԧgԫoͰyYzNLA ,St z\EY?d*@5XTϲWE&[ < 3.&^oemYbX^ʅν'Pj^b7)z;/#Um0o 5\vOD0+vQۀH@gScx5w;jNdb>4ܣyM EIwJU)E46bS`x"&Y"mtz b€E&MMۿ[M9XtȔ7.D(|{52pۨ qwcɜG=ęY5Y|`*dPB\J&j}uȠݣM\Z;9p|tqe^M_g-9'[#k3f;7*Jw XLOBGύQJHG /X68|X:P ,tq}[}+9o.zӡA ͱlA!b'YشYS*Vu$ ,$Ҏ8c~ӷt֞Hf0M(ݓN%4(`f sU`Eȟ۫o^?p^VoXKqSa }H >_)ǰO=ߩBl#$s1 ؕT(ԦfgK:#;#̃kuWSsr5e;F| Lݝ[֦zuIL}x,<A-;t~uƇmݥ2@L^l$TDt=?\U"6$10/XqX;k˹ zj<#%>pB Aof\R#eETs3_ˋp4;9ԨA~a[Q+㓽we}q m+VĦZQQCHeI|5̋?TL-<0f4gNId9אzHO0"t"-PԸ"(4DQXRTXhB:%3J`-o xhjytL5L&/j/F`+q'Gʝj#'/p61A-Gw;ֽOnv©Be^\k2V>BxMF (X:}g JhT~2q7"i.eLCmvv4OB$R6CCr̜zYFM$qshMaC(*RatAFKVqqȗvu0 {BrFON`RfɔA>NY5~:MĉyF_kFP={BT)6!W5T&}hm::-p[i栗%QbI#i4m%; R)^⃚o4JRKl^ ccunAR'ӝ/pV`.L2+4ou}4&VR4; ʉs~=V8R'HHI)"c!RlFG^|K -XU:b" OQPEm ᱹl)Q^Y ©2oolL#F.bOEnH#Qɷ\:^[/7}g}u( d>YE.!eE.JÍ~Yz% 4:yo:D ELoA:Y^3*㐃X$ &1BxN00#}k*[]IQrx@G<_c;)0Dm$ /9㾡@/zh*5(lsj²_J0Ry)j9cI]p"<Ɠ1VIu{9>^]WgE+&/ؗKY'^a.}bӵ;e×WMb]BK/$Xܸ=x4Hcb)b LD!00HȠ7mI`Zͥ/jnlN5y2=C ˧tx2pvdN~_S3y>7-%G[PoVwtdt:5\5yI5n8FiϥS:5Wui̓0i `ޡ?t_mͽqW)V A\u]ٚӐB6ȟ:ޢ=KWO 9f _[lw$fT$ m¡Is,HҲ5J#&Vv-6#:CO8U[Z-e>L^Fz2W@{a[/* s(~GF͜=m, 933N$m~rN0Ouqإ1a%3bxS^U|SVYrj~{6A˦OlV_7o=˓)OA9NZI Kn>c6'-&SNjEK 4yHUIn/ y8mf M>9a+ISÖmIBrMgD wO2sYw|#H& aUzoqO{7<{5KK$#oǓ柁\^ ]o\D4<B*vOe~;e7wD̺19Jh'Cl"lSb]HM&Cr e3_(> 6 7Ʉ,T0p^ ɣ UnYJeKwk,R@*)CS 8H rZ!]? jZ4qYUAбJ0 ̒plgJWn/20V2/$(s5v\'ĿqAh#^9f\OtHx !v|) jV$6;trv4Uv+2;E"PfR)=~DZaxSUƍ@c~GN#{ DA& Tzm r@h* C'ɗñ5ލYM6]mv2M,A<](SxBQp>Sþ.j-TCJ("|폩I\6͗eٝ؃SG95btd#u ž0~.8J'k+|f?Js8 P1g̥q fE]~9!oan*L]m,F$9kWQhK}~Z ,c<p3%)]$A8Ҍ/@!"Yޗ-gH$jDH(DzEcíԆq+{FIRV%dnBM* #pZ"8 e_vDy0l]m&臷cS!&64n[uL7_ixf81[f?*s7+i<1D;ɍ] [3ۿ Ne8[vQڤYYr[OܴgxD+/r\0 dKnzvR`-a9iHEMd lvmyY6R;eV]FRx˜ڵ/R{K/<tr׸ͦX8ٲ䆏l> { 狠q%z;=28Pjzh z/\8pPv8XlU}: R𮝕gMiVpId`5!P h؏ȥ֍}WsLz,8sd5gttJJ_NI/[--&{^UoD)y +9e9f! T6 @R&%^} "-,cp[-r $:FxɳMi2e3-R~juOLбz A~4n+9h Y(+Ѓfa^~Y_yS~dZ xWL#zr`OjmZqT9BRMAq Y}, ZTYm&mP9=&* F/} Hn[vcLN>7%{:pazE_铦EOO?k@Ԗ:ģ4껨J #6YżSxLnƙf)юtuSv 4PòA!Ա÷nzss&PRGʆ¬|o5avUF7m+R)n[7(bI@0-#- "N0:Xӷۗ.F~p#^zi]Bn) VbΨ*F>|ojќ_ž>_~ǂVWLpq+h!) !K%[6D򵻼񥄤.#j!&-XG0K"3k< Q~%w 6?(Yp3 Xmѝ o(ɹj/PHS:#e"6.9D(MJ/xv}>^XafO^]UVRei~&oR8M=9{W9(s eEipo -f2.I 3D&(_jO;aM1eI/EIgsܽJ]Kdk?W ٠4oB!2sF3 " 2L^[,@Bk?6Z,CTЄ/`CY<;s7l_F;, , Ge=ѝJHY8{e~8L_> J+|. qsupENvAuD0ΑlBC'faf~4_\rUTrmU?Xd/@#VyspS2TaXjgE=Gt݆tH >XisіR 8{W$K +pC(sIY:%/\@M4|8cm6m,# ~2y@3Z.G$Qyѻ5#{*$ͤ没PZ $W8hPBw|P%?ܫ{9Jjўgq_S!}OQTD)ē&\ Igw3w; X.UpNCV-|#]t2#>tj̀t|^?|1xOy~rt6`Νӯ6OxdGG N-QO 9|mk^7E г-u{ T~<6]݁ah)ɼ1Fviuu Ē~&HAxWfN ~2x%D0%b8Q}k`Y*q>~/4<fjnDx*<]cu9MZM9wi<~S纩U:sj[@%QLL!/ Y0% 7Ѹ/T{ͧ2+0]-O }Y{g[Bt t%ԑ'XzT0!jj˚SFn9[Άmq{jКSawdމL>osWl`ȷZKZ6Ɏ?/m}w $,;H<@Qx%ˍU^m~*T(zU2c7YͶ~MX.pk4ȫ8'Z2OfH$Tz0s{eg1S:D4R y(5G=y' r$H ?Br]eL,W5c˵Uu 7Qu n(IHeqm6tjGӞ rI_:,.yIao\E\QAƕssӺ/92 n=TD|ܮUnHxR۱#OA_dnK>"H D+VMzԞp%̷ΜK3˻^l&vdr8b8$MHqpXY:rXL;/Ksl]?'[۩MQC_l(c4X&X>ꉏ:;T:shlxMAHv%I -ftBt!jqǝ `@oԨdvSOCdeL V(`Zvd"b@xٿfei2[}F x}#Y U*S[rR G#)#tA>*0z =`Y*G>&"L8Z &!OlpרCKeҬ@Tە1wUA=`\+33SFq_}'/B{qPoWFAr#()&:G*&/(N0kBݨt~$UW?-r js**W\Iu]ďL-$:'x-؟`PP.2/Hx (2F1YaTB[!XU*Qpgdr'?ˑ0]*B~Yeq/b3 >dyf,4ؙO'I,V *JT9 [vrDxSYg(}mu9鿍xXzbenJ] I]QlU9C~*ohylzC7jz5\TW)) qZm꾺L_W9ٜX)\Jy) OjL\Pv~%4K̋QUMP5ׯ^ &%oXSA>RXgի9u|eL/q(G{r K|d<i1$%J4f \+ "w4U͜BKKģSFA^sj#W6Gbzӫg6 *`ua`Fu=}FUwUSۏ?7)Ֆ}A*M/iP)&xu$uFU,|2A~5)Z"_2] 1 'MlT0f4S͏jXpt 18D4T)NωyGkÅN (SV}uκrYn5! ͌H!h6鏥57g mSA6\&Ƶ WZe]՝vy9Bdk6-z3*ٗ .`70fS,=af2[;Y{ n 2h(f,_cR`! lHړáx){"N%BVٗئ*4M9OWipL Қ@ >:~Aˢ$qŭ:V H&5[(dTM WͦPgnAa5/?cd?W}[T3ُPF<<`R>.$R9BG=3AF2 QRՕw>]5m5™8ɣ4L(2j1Ǡ7TtdO $g$6d[*1,ԭC\%7.Yu<[ih0eV wF!u. '% Kov;}Ujx5=TR%rā>"[^SG{ˇWxt!@jYusC2 MΡh{6^ۤ`ڸ|r9VLfYnhbٞh - ^p7yTAΛOHImkμ'yK2OL40^u\\a@P1q-9ļ#T V;Ex-N$E1ge\|Qb(%̻  VQJv$U8Ԭ[nȉV#͏WR7OHۢMº ) zŒL:9ˎj%]@2hF$cdҎb' AO550WhcOKih`G &Z4AA`1y%ȿ8cRA?A|ADk˖&{9WY4تbGӞ#xarC8{bYhdŁlfik8N[C;r*ye|"Wb}~,Leo1zt[1ԚpJ rb!͆0 q0/MH K,Ǎ4! ,-yq ϔvU)ھS'f1X9prZehij$\=i+vdW5f? \0FL,% j?0SʞY<`MǭNLjqM" `;I6ٝ7Cy5e݈CGaD5&$K~Ie0g˛FJ ;L}%9{;Ia7/^m%I %KsQjMhu?R8lĺ xhL25sئD|ݵrTH@oG6ؤˌȞ%L *]7#seڸ9̾ҚPp<1!<&Ƅ3l#I=^;Jkr_LR 2)dOP2BdG ֊֌_ :BC5 X۷{vv#9ӌfqV471'˜$LЋ$aټ5;K=7HίVqxc.IrRfja\bpi9;}8ߖ$i}TƩ{zBo2`.^Tq,)EP% r@3A&…6+*SvHu6NF?0Sֱ1.ЩP@t(M(|Hv@@X<%z?f(fP\RGBӦ T2nڊm'$9P\+:1]q3E "AD }W-SǢ$rkqCCϣByөH eTuyz?ɭ})@LF4hHu Qs=uwWʿbQtę-M)txL;8+/ф.*Xoڎ.MTbT}K` gC,RYwar:?v'G D{1P7ʵ]Ci-Dz-Ozo\1j>% g/Lxcf< Mp(D0i㘤 iT.E#RfE5u<w'o -Tty3 [Q ٜKv]PvJNNx:4bUAڻ3wرT=fuU"Rž=|OS >޺HÛNv50dkb|ˁ'%P,WU g@|bayLۘo0E?iY&r cїP$h~ $J8ʕkӶ,xF+VUJLĞkJq=W+szj$Ur?lQ`YP vv}_ ҏ, XcWaGX!?0PX39Nы 8&Ap*PIg*Pc|ENsTw=` K.ܨW]\lg78)[#1ţD2 Uw+6Mn͜%z3ᷩn9>i.7KnY!VyGNDk8`lK XHcYDhK}Θ<- Py|j^_30h)V+'%Ϥh3!Ud'dߕMXfӭ6Kuc̝Ԗc!* 2&&o;UJx>H[&ꡖb6Op9{@dga g}E/n6v:̯bi8Rn,h/K3CIc*D'/7NHvGI0kPy;b#a.sfTfI]4Obx_@ =dر)9n)o3Bc="1!㕟m& #X)H=ci]Q@_xB!X?cygd }AZI2:]*g;17;)G8E|ԝ_-@".-6T_ s GaǾj5 }P5\t?tdlC /O1֦6+_&-a}= dZ 5R]BGDX"g`#^ѡS~X~fUE(P* ?+ri>VwرG VfL$~V[؊bT+嗋PNމh g=g~u$v]y!%RlfIp xZMR5'nT݌b:46 qt"~>,"Ҫ,h!"nhNqO_Eڢ^w ms "LkH4Y\<_] ?`p\UbIњNs:3BGA,w>ZQz9f]- _ :ς a: Nz$G zMΑw+Nk2mg&eb5鮁$ ,&L<.v9.9AokcQT |ۮ:(;UF)UMwdq7푫"l^Ri!p}bHy|o428z'Uע@s~ TURO`.Q[֪j򿇬[f!ud)VP3*4|%!ݛ) g5;QqZ('1)zQSRmKf>+}l[]tiXM$$TED~-zw(&=>~FyMiΣ1?6\ؘ58IHm xTN;a˯-\ڃe$w${~Yp9dw5>FϫQ]˳m0uuI Xh0#wPOkס+ s#&mɅrkD u)}"s|܋upbJ[PO _U^~ ڹA S_dX}eI+CnptTah/X1R 88YdҬ/L|t`[llz;R)rf׏G)+1)EDBw_LtB^2 ̈^/Ha#6D06jYb,^C/Wx3kI6ȕqń}r WiNlvRz';󼕊wރjO =熦vJN Wj%/ &iI )YZN|U/`3;FMx"W{汮&Lo> Qo:Aδ8O?AZq:=hJ ,Eoԑp 'vcR[`}3%,V;,b[ ~ @mup'7a_C oیrS4ܹe^#Lx:d9sOVԞ _ij½س|Ë^VԄ3B꺶v̚ر4JE5EPD{bF"f΢lt\*9?V^Y:#E"T3 7 W.q!8>YSW> Q K E_m,L.qˊJ]x]/o'&"iL"`IxfSbӇrNț *vt*Q az .-]J~\ڨLVwh%0*+mxy|!y0HT.FM/I*VON `qĪ %˃N:XYt؀B쨻ɐ]fLr]{ueD z#a#iUrC/Js+XIAć֏ic+ Бho0Dy;%:$>j[=ERkJu4QV! ]O @[F%t7mk-,%iU'XFb;z:h ֣ ޢ3.X<5R2(HԨu9 gײ$VIlYa1Lօ#hi U[y Ulh9Av N$.z7Op \y'Vdq A .ĥEHW /{Ƣ46F25~Brq{1dOzr 峒GRҴ9)%RO\!y;@voZ*0e`2kGvP<%B :`)jhc6uN. Xvw87yU楰4'j&Z=:@Ǻ~bYFH}ޙJU?%uS-kZK4B:" us>׉j_3l8FGAC^8'e^Cv?JޒV2o0$ *MTܒL|!~c`Fx,?5:هXLpg[cYDkzBW{Ig 3q?\(So#0%^;9KX=-z~1>eHLu"3jh8$W٬ `(hPm0?~Uhb&k{'ak{9jMT3lg0%`旝Zz`ôcT`u5< YZ