cryptsetup-doc-2.7.0-150600.3.3.1<>,\fh&p9|7̧A,AD ^$&͋a NVPMw~}ʃ:m"`K:newyJ"3WU)M' CtUGJ,5`7kXku2@.>X--!6["}& - R>=C49=ě0»x(tC6Q icT Wt|嫮/Ki=)G j%6Lt5Z4h]ϫϷA6 4F !'-; W+^6861>>0? d $ =hlx| BHPdd d pd d $d d!d# d%%(d&&&';('W8'`+9( +:+<+FԅGԜdH,dI׼dX Y$\8d]d^GbcFdefludvxzqCcryptsetup-doc2.7.0150600.3.3.1Cryptsetup DocumentationDocumentation and man pages for cryptsetupfh&h01-ch3dSUSE Linux Enterprise 15SUSE LLC LGPL-2.0-or-later AND SUSE-GPL-2.0-with-openssl-exceptionhttps://www.suse.com/Documentation/Manhttps://gitlab.com/cryptsetup/cryptsetup/linuxnoarch,Qӱ i:yb ;!%6C E  [+AhK7".lg.tO .m_-"@E Zf)q)Aj)) *y+ ) 2)%k - ) + A큤fh&dse=RceͫeS|`WO1d`O1d`O1d`O1d`O1d`dd`WO1d``WO1d`dddddsP}ddQNddS$ddddS dddd][`FT`FT`FTdd`FTd`Wdddd`Wdsdsdddsdsdsdddsdddsddsddddddde=Rce=RceӮfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfhfh012a99c581df2f922c8996d25fb19b13eba7776bb7ceb6b79f97c31208845820327439ab28f4a430664927378d68cf15307be855d26a93d0995b4319d3989818f50d65af9485d3c03cda2744be0d49c74481cac69334260f3fed137a070fc008e6c2f4000c45e80e782c03985d607bcf629ebdcf4155fd0cef5d8956da80407a76be8a3fa9546056d4ed8933efe2550b8c0f79014655450b93525821e520138b04505ff6feb42cb3fc27cd79c52b0a8dd446ebac636db57e47b466f2fb6f870e0b3b98db51402d5c6b54a76f049fe834f385bb0a81a195148c217776c29abb2885f985ae4dd6fa76e34b4abff697d973821ac6bb255e00ec8844fbf9fd7d936c0db4517a88ecd842a1ea48360c45563ef051ba71d51d6e5d40e240516536d8b7972e5fc2fc53522a41cf685cde1ed92ab42df50f608dad44b533a20d1468ba2a560ee5ae4db4a1d0ee35e306441e201148b1ea27f18c9e0112d80c802d6778a7f921b65038a98a6281769a64e90528394c11e9f58978945cfbf058bd72d251bbd9f325cc7b69e35a3235b851f6e3d8db5d01d717afac72ba452ddca753be93df085ea8c727c1487e11b032c9357a5187ec8ef86d16f0bbb3d8f357ad4cf780c425b2628be5d85dad2656f925cee0b464f53c3a669223fb6a43dc581a27fbbbc59e6b693606d54c33f2ac9c8502d9fbfcd6c9eabc7040d10ee02832fb5ddf735361231599aa9f0680f7bbf8de421a7a4993cda46cbe2aae886ea19029add9e90a17443d3606ecf579a00565290e63c1f53c0520bf78473014d45cb7c7938a187d758112ba6c3946c2b6fa183d6a3662b3b34c09ebb40140613400e779506f22b7f4077d9fa9709f94e4094178943473d2285bdfd9332cd3f00451f105c8564c730fdac009890d44f3383abd33132f3f6e5e2114b5cc22df9a8b90cff57b06156281698d012f3cdf5f7be29b43f540bc7d2acb5ebd25557b81745c106e255bcc94d198ff7ffb01319f58779842a605461416c316bdf058e6e9091be4a69251bfe372e8e39572c8bc53eb93bf3b51eca71058668732a4a1e6df60cd2980e5d9f66271be98d8aba793d595c7305e65e0bc8027f32d76e22112a7d02ef3836e41f966eefef8259641d4e435288c77eaa861163c2ce048a82cac90d17ddaa9adefe6a0c953fd39abd47985fb74a06277946c50a21503d02cb5f8715084ba7bcb0b24f30087abea8976a6bba02caa7696f1ca6911bdd725f69f716587c6819c208d7dbdff407694c22b8a7f3217e5987a59b232ca2c7ea4cd3014c1c5fd4c941b0b767fd8d3246cbf48031d37564c8e6b56394dfbce815f6977954291049b53e440d880b42705939d9a513836df7abf4ffa7155ff9a1d2b1cf4c132390aaaa81594537ebee834ef41dd79e3430310491ccd9afd39971af54a580151557aaa9b9b8229120d0583bf04536dc5b34fe0c8bb6e88c3b7b4ac19668deb4ecffba426a2e5649026d024e1af8779187808b94aac22d36fd2b16c1be1f9bd7062999e28638cf4bdf3c99841ec78d5688a8a18b644fd8950d7bc46aaea8cdb634e270b8f701d0b07093e92fb88c7c771bc0ba7da4f99386c80e0da2637249fe7fd99a57966d1d1e23a22f841afe99c24bc423a99ca43b0868b476b685469ab4877f1c8150cf14fd8ec749cb281e81781433ecd66aa7ef39ae9e032ae56e8e51920b857ad31e636a79016a7ba548ea78bb8c562a4a1c68753bcab7104110d3df6fa239d54bdd8edc6c165c348ead91ad0e6ceea6aaeea0f71128d8187b4583eef22f3f3eba95a642bb9587909ff0eca1c2951afba46b0197f4b7c5428eb5a85bf730e9f756aa28593e7837b36b249f344f2012523e4f5094d1aeef080cd0481e2689fc2b3ae7e117894a409b6dd3d911af16aae131e5e381ddcd08b58b698344d75f566edb6339f3b506a9645b7138611896178336bb6e116a0d31689723ed8aec4e11e13325b28343fc1552fc80c1896c7d7dd2c722bead9f62e9bfba917cc60cdea64838a6a2ea9fbdeeb8e722fe32e1fa5b94e4a69790c5345f5785c11b4f95d016b5ca503d84325df067f0d6fa1a9a4f9aa405e0bbbe0972abf680102bf1a0e7292ba4dbebf1181301bec574a922d7d9f1900d514f3c36bf07fac6a49684ed56a9d8318539856c49522ac2e9047f37535b313e9c76be539d32fc224cfe78f39a411a2f32aa0a237b3e171deab5857a7701afa16f3f4ebf254cc428023a141556f31cd1110b9ec186cde72e155b5ca5330400489662ef8add809175057a87661ab22029d875615ebc127f67b0d3506bb9058e347d31012676c78096d04ab7caa3644ff1da90435e9180a079b5b327ee052f1d4d5dd6b498dafb59f4f688cc35cb8ffae0ae96b3d550124bed07d062c7efd5c27947019eeb01c7e414ed92efaf0af3f49b6e45db1bf121459eab37fdb69883e28325582c0360ae1c2b97c6c8e507e034fbb56d1d757a86d7f37f147c6f78fe1633cf2509af5aaeb4d41720c896ebfdc9aa9dda8aba185daab56f6a2ee532f742209e81a65000f567afb82d2706af0169621258eb7d3311c5b84bbfbb9a7ab03fcd2d79bdfbcad91fecb152309f6c3a31825bcbcb4f0b3b5faab27ec34c453789e8e7d24c3c360ac9f18c89665a46e85a0339cc3cdd01fd9663f88bb55fd0b16e2a13d8dccfd03e75b44d9f14774f7005dedefd49fead605133db2d44b2b99856c0fa83f5c5a682f0095def1dbbafefd42dbd25f462d25d594b23d2f237f8c2bc8b1a1c90380639eec943536a66bb40b662fc811f12814a47736d663e2ae302536acdcff46c447a51a02c9ce059341050ea93d6f3aec44636c945f82db69c203f8309105fc682b187208ae9c10b099f11771d8c716a9c0df56754c7c2ceb4c32682c0d01028adc08fa8fa58559f5d3c36974f088461e71d5a0f454a66afdfa02a7c0eba831f6c498f3efc49e6c5abea205f7ebca3a2814a47736d663e2ae302536acdcff46c447a51a02c9ce059341050ea93d6f3a302091a858838942b4e0f4d0f74e9b388794467d33599549a66090828b6353e51446546502b2e9a0d1232383536c3f302a26289ad650d5755e3bdd0764365e642814a47736d663e2ae302536acdcff46c447a51a02c9ce059341050ea93d6f3a06e72efa0c18473ae87917c7a25d7928bcf6e24eac69f57b8b5893ff836796c82814a47736d663e2ae302536acdcff46c447a51a02c9ce059341050ea93d6f3a2f4d029b02586e2b12d85763195c184cc647a9d29b2acba12fb217faa3a0b2726edc32a8209dc6356fc90f93d51d89e3802b85df45957450f48b4b851da4ac40387acf66ad0422d7aafcc043585369a757b3e62d70f4930d18d53f1d8029059e8594f55f92fa8945161ce08c4ec0514cf03d219d83190e61fefb3c711991fe5796f743c6fe03ced8478d0718b342bb34974961ad28fc5ea41ab57062e3a50674a866767ecc4c5d0be922f31e180e1939ad462e556b52e747d10f13d0fd8b3ae389115ffafa88d8478a266d685e8129405444de3400a119ac982f0b687ee1df193a38f2bd0cc2af4527e8d58c9cf2a8354088ccdc06654a91bfee51621a418335b0f35c51e68bbdadead74a9c94c5303fc8a61010ec32600529edb3281f91e6822814a47736d663e2ae302536acdcff46c447a51a02c9ce059341050ea93d6f3a26644ead1e3ff82fd84742a04331210e998e0bb09599f569695d94503416fb0c76f47c66c74656a99737c254c91631090f1ee2a142d07890044a062885f4ccdcc8b9c12e1481f26c4c559d48132b910e5934368c120e07c337eb9b708dd10aaaa8424ec36de93d35c0cca1066430f37834cc6ee693312cfa0bde698f1dc3c5169b8bca08cbc150c8178b1347af055f02ef2b92c3c28767196ee9152071e8a7142814a47736d663e2ae302536acdcff46c447a51a02c9ce059341050ea93d6f3a4cbdd9d91407df0cfd31b8bef066f2152d7adef797031e6e8e844cfa147e3f481bfec168805b0bf0fa1cc18718846686327aa1156f504fcd5f39a0cb3d9b9948ba5db14733858258c003fad9dd03c1d8069ef80b527fe89a800394472e007ea6a4db0075d2cb418d1c918f0b9553eb14378265dbad057a69fd139f63d9f0dbf0e55ac503518eb4b195112fc78f6ff88855dfc6d4cb4aca2277baea88596538f529cbee60d523cbae404ac279035ed1ed80327da8523b4f23c3f7be1a40e6f9bd2814a47736d663e2ae302536acdcff46c447a51a02c9ce059341050ea93d6f3ac4d863a886ce4003c9be88a23b608b06a48a076f6d89f743a5f49c1e41df61138b2f0e17c4cdb7c5c7126d88c8e17a2b7b418701bf37d014f6337885b86841b92b1a5a29a5a4d91a5ca53570a1a83a9bdaa68f6ba703107d7174f1741e8b4e7e1949b3875e2421031bec2c9716d3efbc0d8e45775c118d66fa9ae92086e73ce5rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcryptsetup-2.7.0-150600.3.3.1.src.rpmcryptsetup-doc    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3fѴ@e@d@ddcc@cc pcoaea@@aC1a&0a /a@a@`ݮ@`L@`KW_j__R,@^ϧ^^9\]W\f\f[G[G[{Zp^@Z64 bytes) passphrases- Split translations to -lang package - New version to 2.3.1 * Support VeraCrypt 128 bytes passwords. VeraCrypt now allows passwords of maximal length 128 bytes (compared to legacy TrueCrypt where it was limited by 64 bytes). * Strip extra newline from BitLocker recovery keys There might be a trailing newline added by the text editor when the recovery passphrase was passed using the --key-file option. * Detect separate libiconv library. It should fix compilation issues on distributions with iconv implemented in a separate library. * Various fixes and workarounds to build on old Linux distributions. * Split lines with hexadecimal digest printing for large key-sizes. * Do not wipe the device with no integrity profile. With --integrity none we performed useless full device wipe. * Workaround for dm-integrity kernel table bug. Some kernels show an invalid dm-integrity mapping table if superblock contains the "recalculate" bit. This causes integritysetup to not recognize the dm-integrity device. Integritysetup now specifies kernel options such a way that even on unpatched kernels mapping table is correct. * Print error message if LUKS1 keyslot cannot be processed. If the crypto backend is missing support for hash algorithms used in PBKDF2, the error message was not visible. * Properly align LUKS2 keyslots area on conversion. If the LUKS1 payload offset (data offset) is not aligned to 4 KiB boundary, new LUKS2 keyslots area in now aligned properly. * Validate LUKS2 earlier on conversion to not corrupt the device if binary keyslots areas metadata are not correct.- Update to 2.3.0 (include release notes for 2.2.0) * BITLK (Windows BitLocker compatible) device access * Veritysetup now supports activation with additional PKCS7 signature of root hash through --root-hash-signature option. * Integritysetup now calculates hash integrity size according to algorithm instead of requiring an explicit tag size. * Integritysetup now supports fixed padding for dm-integrity devices. * A lot of fixes to online LUKS2 reecryption. * Add crypt_resume_by_volume_key() function to libcryptsetup. If a user has a volume key available, the LUKS device can be resumed directly using the provided volume key. No keyslot derivation is needed, only the key digest is checked. * Implement active device suspend info. Add CRYPT_ACTIVATE_SUSPENDED bit to crypt_get_active_device() flags that informs the caller that device is suspended (luksSuspend). * Allow --test-passphrase for a detached header. Before this fix, we required a data device specified on the command line even though it was not necessary for the passphrase check. * Allow --key-file option in legacy offline encryption. The option was ignored for LUKS1 encryption initialization. * Export memory safe functions. To make developing of some extensions simpler, we now export functions to handle memory with proper wipe on deallocation. * Fail crypt_keyslot_get_pbkdf for inactive LUKS1 keyslot. * Add optional global serialization lock for memory hard PBKDF. * Abort conversion to LUKS1 with incompatible sector size that is not supported in LUKS1. * Report error (-ENOENT) if no LUKS keyslots are available. User can now distinguish between a wrong passphrase and no keyslot available. * Fix a possible segfault in detached header handling (double free). * Add integritysetup support for bitmap mode introduced in Linux kernel 5.2. * The libcryptsetup now keeps all file descriptors to underlying device open during the whole lifetime of crypt device context to avoid excessive scanning in udev (udev run scan on every descriptor close). * The luksDump command now prints more info for reencryption keyslot (when a device is in-reencryption). * New --device-size parameter is supported for LUKS2 reencryption. * New --resume-only parameter is supported for LUKS2 reencryption. * The repair command now tries LUKS2 reencryption recovery if needed. * If reencryption device is a file image, an interactive dialog now asks if reencryption should be run safely in offline mode (if autodetection of active devices failed). * Fix activation through a token where dm-crypt volume key was not set through keyring (but using old device-mapper table parameter mode). * Online reencryption can now retain all keyslots (if all passphrases are provided). Note that keyslot numbers will change in this case. * Allow volume key file to be used if no LUKS2 keyslots are present. * Print a warning if online reencrypt is called over LUKS1 (not supported). * Fix TCRYPT KDF failure in FIPS mode. * Remove FIPS mode restriction for crypt_volume_key_get. * Reduce keyslots area size in luksFormat when the header device is too small. * Make resize action accept --device-size parameter (supports units suffix).- Create a weak dependency cycle between libcryptsetup and libcryptsetup-hmac to make sure they are installed together (bsc#1090768)- Use noun phrase in summary.- New version 2.1.0 * The default size of the LUKS2 header is increased to 16 MB. It includes metadata and the area used for binary keyslots; it means that LUKS header backup is now 16MB in size. * Cryptsetup now doubles LUKS default key size if XTS mode is used (XTS mode uses two internal keys). This does not apply if key size is explicitly specified on the command line and it does not apply for the plain mode. This fixes a confusion with AES and 256bit key in XTS mode where code used AES128 and not AES256 as often expected. * Default cryptographic backend used for LUKS header processing is now OpenSSL. For years, OpenSSL provided better performance for PBKDF. * The Python bindings are no longer supported and the code was removed from cryptsetup distribution. Please use the libblockdev project that already covers most of the libcryptsetup functionality including LUKS2. * Cryptsetup now allows using --offset option also for luksFormat. * Cryptsetup now supports new refresh action (that is the alias for "open --refresh"). * Integritysetup now supports mode with detached data device through new --data-device option. - 2.1.0 would use LUKS2 as default, we stay with LUKS1 for now until someone has time to evaluate the fallout from switching to LUKS2.- Suggest hmac package (boo#1090768) - remove old upgrade hack for upgrades from 12.1 - New version 2.0.5 Changes since version 2.0.4 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Wipe full header areas (including unused) during LUKS format. Since this version, the whole area up to the data offset is zeroed, and subsequently, all keyslots areas are wiped with random data. This ensures that no remaining old data remains in the LUKS header areas, but it could slow down format operation on some devices. Previously only first 4k (or 32k for LUKS2) and the used keyslot was overwritten in the format operation. * Several fixes to error messages that were unintentionally replaced in previous versions with a silent exit code. More descriptive error messages were added, including error messages if - a device is unusable (not a block device, no access, etc.), - a LUKS device is not detected, - LUKS header load code detects unsupported version, - a keyslot decryption fails (also happens in the cipher check), - converting an inactive keyslot. * Device activation fails if data area overlaps with LUKS header. * Code now uses explicit_bzero to wipe memory if available (instead of own implementation). * Additional VeraCrypt modes are now supported, including Camellia and Kuznyechik symmetric ciphers (and cipher chains) and Streebog hash function. These were introduced in a recent VeraCrypt upstream. Note that Kuznyechik requires out-of-tree kernel module and Streebog hash function is available only with the gcrypt cryptographic backend for now. * Fixes static build for integritysetup if the pwquality library is used. * Allows passphrase change for unbound keyslots. * Fixes removed keyslot number in verbose message for luksKillSlot, luksRemoveKey and erase command. * Adds blkid scan when attempting to open a plain device and warn the user about existing device signatures in a ciphertext device. * Remove LUKS header signature if luksFormat fails to add the first keyslot. * Remove O_SYNC from device open and use fsync() to speed up wipe operation considerably. * Create --master-key-file in luksDump and fail if the file already exists. * Fixes a bug when LUKS2 authenticated encryption with a detached header wiped the header device instead of dm-integrity data device area (causing unnecessary LUKS2 header auto recovery).- make parallell installable version for SLE12- New version 2.0.4 Changes since version 2.0.3 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Use the libblkid (blockid) library to detect foreign signatures on a device before LUKS format and LUKS2 auto-recovery. This change fixes an unexpected recovery using the secondary LUKS2 header after a device was already overwritten with another format (filesystem or LVM physical volume). LUKS2 will not recreate a primary header if it detects a valid foreign signature. In this situation, a user must always use cryptsetup repair command for the recovery. Note that libcryptsetup and utilities are now linked to libblkid as a new dependence. To compile code without blockid support (strongly discouraged), use --disable-blkid configure switch. * Add prompt for format and repair actions in cryptsetup and integritysetup if foreign signatures are detected on the device through the blockid library. After the confirmation, all known signatures are then wiped as part of the format or repair procedure. * Print consistent verbose message about keyslot and token numbers. For keyslot actions: Key slot unlocked/created/removed. For token actions: Token created/removed. * Print error, if a non-existent token is tried to be removed. * Add support for LUKS2 token definition export and import. The token command now can export/import customized token JSON file directly from command line. See the man page for more details. * Add support for new dm-integrity superblock version 2. * Add an error message when nothing was read from a key file. * Update cryptsetup man pages, including --type option usage. * Add a snapshot of LUKS2 format specification to documentation and accordingly fix supported secondary header offsets. * Add bundled optimized Argon2 SSE (X86_64 platform) code. If the bundled Argon2 code is used and the new configure switch - -enable-internal-sse-argon2 option is present, and compiler flags support required optimization, the code will try to use optimized and faster variant. Always use the shared library (--enable-libargon2) if possible. This option was added because an enterprise distribution rejected to support the shared Argon2 library and native support in generic cryptographic libraries is not ready yet. * Fix compilation with crypto backend for LibreSSL >= 2.7.0. LibreSSL introduced OpenSSL 1.1.x API functions, so compatibility wrapper must be commented out. * Fix on-disk header size calculation for LUKS2 format if a specific data alignment is requested. Until now, the code used default size that could be wrong for converted devices. Changes since version 2.0.2 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Expose interface to unbound LUKS2 keyslots. Unbound LUKS2 keyslot allows storing a key material that is independent of master volume key (it is not bound to encrypted data segment). * New API extensions for unbound keyslots (LUKS2 only) crypt_keyslot_get_key_size() and crypt_volume_key_get() These functions allow to get key and key size for unbound keyslots. * New enum value CRYPT_SLOT_UNBOUND for keyslot status (LUKS2 only). * Add --unbound keyslot option to the cryptsetup luksAddKey command. * Add crypt_get_active_integrity_failures() call to get integrity failure count for dm-integrity devices. * Add crypt_get_pbkdf_default() function to get per-type PBKDF default setting. * Add new flag to crypt_keyslot_add_by_key() to force update device volume key. This call is mainly intended for a wrapped key change. * Allow volume key store in a file with cryptsetup. The --dump-master-key together with --master-key-file allows cryptsetup to store the binary volume key to a file instead of standard output. * Add support detached header for cryptsetup-reencrypt command. * Fix VeraCrypt PIM handling - use proper iterations count formula for PBKDF2-SHA512 and PBKDF2-Whirlpool used in system volumes. * Fix cryptsetup tcryptDump for VeraCrypt PIM (support --veracrypt-pim). * Add --with-default-luks-format configure time option. (Option to override default LUKS format version.) * Fix LUKS version conversion for detached (and trimmed) LUKS headers. * Add luksConvertKey cryptsetup command that converts specific keyslot from one PBKDF to another. * Do not allow conversion to LUKS2 if LUKSMETA (external tool metadata) header is detected. * More cleanup and hardening of LUKS2 keyslot specific validation options. Add more checks for cipher validity before writing metadata on-disk. * Do not allow LUKS1 version downconversion if the header contains tokens. * Add "paes" family ciphers (AES wrapped key scheme for mainframes) to allowed ciphers. Specific wrapped ley configuration logic must be done by 3rd party tool, LUKS2 stores only keyslot material and allow activation of the device. * Add support for --check-at-most-once option (kernel 4.17) to veritysetup. This flag can be dangerous; if you can control underlying device (you can change its content after it was verified) it will no longer prevent reading tampered data and also it does not prevent silent data corruptions that appear after the block was once read. * Fix return code (EPERM instead of EINVAL) and retry count for bad passphrase on non-tty input. * Enable support for FEC decoding in veritysetup to check dm-verity devices with additional Reed-Solomon code in userspace (verify command). Changes since version 2.0.1 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Fix a regression in early detection of inactive keyslot for luksKillSlot. It tried to ask for passphrase even for already erased keyslot. * Fix a regression in loopaesOpen processing for keyfile on standard input. Use of "-" argument was not working properly. * Add LUKS2 specific options for cryptsetup-reencrypt. Tokens and persistent flags are now transferred during reencryption; change of PBKDF keyslot parameters is now supported and allows to set precalculated values (no benchmarks). * Do not allow LUKS2 --persistent and --test-passphrase cryptsetup flags combination. Persistent flags are now stored only if the device was successfully activated with the specified flags. * Fix integritysetup format after recent Linux kernel changes that requires to setup key for HMAC in all cases. Previously integritysetup allowed HMAC with zero key that behaves like a plain hash. * Fix VeraCrypt PIM handling that modified internal iteration counts even for subsequent activations. The PIM count is no longer printed in debug log as it is sensitive information. Also, the code now skips legacy TrueCrypt algorithms if a PIM is specified (they cannot be used with PIM anyway). * PBKDF values cannot be set (even with force parameters) below hardcoded minimums. For PBKDF2 is it 1000 iterations, for Argon2 it is 4 iterations and 32 KiB of memory cost. * Introduce new crypt_token_is_assigned() API function for reporting the binding between token and keyslots. * Allow crypt_token_json_set() API function to create internal token types. Do not allow unknown fields in internal token objects. * Print message in cryptsetup that about was aborted if a user did not answer YES in a query.- update to 2.0.1: * To store volume key into kernel keyring, kernel 4.15 with dm-crypt 1.18.1 is required * Increase maximum allowed PBKDF memory-cost limit to 4 GiB * Use /run/cryptsetup as default for cryptsetup locking dir * Introduce new 64-bit byte-offset *keyfile_device_offset functions. * New set of fucntions that allows 64-bit offsets even on 32bit systems are now availeble: - crypt_resume_by_keyfile_device_offset - crypt_keyslot_add_by_keyfile_device_offset - crypt_activate_by_keyfile_device_offset - crypt_keyfile_device_read The new functions have added the _device_ in name. Old functions are just internal wrappers around these. * Also cryptsetup --keyfile-offset and --new-keyfile-offset now allows 64-bit offsets as parameters. * Add error hint for wrongly formatted cipher strings in LUKS1 and properly fail in luksFormat if cipher format is missing required IV.- Update to version 2.0.0: * Add support for new on-disk LUKS2 format * Enable to use system libargon2 instead of bundled version * Install tmpfiles.d configuration for LUKS2 locking directory * New command integritysetup: support for the new dm-integrity kernel target * Support for larger sector sizes for crypt devices * Miscellaneous fixes and improvements- Update to version 1.7.5: * Fixes to luksFormat to properly support recent kernel running in FIPS mode (bsc#1031998). * Fixes accesses to unaligned hidden legacy TrueCrypt header. * Fixes to optional dracut ramdisk scripts for offline re-encryption on initial boot.- Update to version 1.7.4: * Allow to specify LUKS1 hash algorithm in Python luksFormat wrapper. * Use LUKS1 compiled-in defaults also in Python wrapper. * OpenSSL backend: Fix OpenSSL 1.1.0 support without backward compatible API. * OpenSSL backend: Fix LibreSSL compatibility. * Check for data device and hash device area overlap in veritysetup. * Fix a possible race while allocating a free loop device. * Fix possible file descriptor leaks if libcryptsetup is run from a forked process. * Fix missing same_cpu_crypt flag in status command. * Various updates to FAQ and man pages. - Changes for version 1.7.3: * Fix device access to hash offsets located beyond the 2GB device boundary in veritysetup. * Set configured (compile-time) default iteration time for devices created directly through libcryptsetup * Fix PBKDF2 benchmark to not double iteration count for specific corner case. * Verify passphrase in cryptsetup-reencrypt when encrypting a new drive. * OpenSSL backend: fix memory leak if hash context was repeatedly reused. * OpenSSL backend: add support for OpenSSL 1.1.0. * Fix several minor spelling errors. * Properly check maximal buffer size when parsing UUID from /dev/disk/.- Update to version 1.7.2: * Update LUKS documentation format. Clarify fixed sector size and keyslots alignment. * Support activation options for error handling modes in Linux kernel dm-verity module: - -ignore-corruption - dm-verity just logs detected corruption - -restart-on-corruption - dm-verity restarts the kernel if corruption is detected If the options above are not specified, default behavior for dm-verity remains. Default is that I/O operation fails with I/O error if corrupted block is detected. - -ignore-zero-blocks - Instructs dm-verity to not verify blocks that are expected to contain zeroes and always return zeroes directly instead. NOTE that these options could have security or functional impacts, do not use them without assessing the risks! * Fix help text for cipher benchmark specification (mention --cipher option). * Fix off-by-one error in maximum keyfile size. Allow keyfiles up to compiled-in default and not that value minus one. * Support resume of interrupted decryption in cryptsetup-reencrypt utility. To resume decryption, LUKS device UUID (--uuid option) option must be used. * Do not use direct-io for LUKS header with unaligned keyslots. Such headers were used only by the first cryptsetup-luks-1.0.0 release (2005). * Fix device block size detection to properly work on particular file-based containers over underlying devices with 4k sectors. - Update to version 1.7.1: * Code now uses kernel crypto API backend according to new changes introduced in mainline kernel While mainline kernel should contain backward compatible changes, some stable series kernels do not contain fully backported compatibility patches. Without these patches most of cryptsetup operations (like unlocking device) fail. This change in cryptsetup ensures that all operations using kernel crypto API works even on these kernels. * The cryptsetup-reencrypt utility now properly detects removal of underlying link to block device and does not remove ongoing re-encryption log. This allows proper recovery (resume) of reencrypt operation later. NOTE: Never use /dev/disk/by-uuid/ path for reencryption utility, this link disappears once the device metadata is temporarily removed from device. * Cryptsetup now allows special "-" (standard input) keyfile handling even for TCRYPT (TrueCrypt and VeraCrypt compatible) devices. * Cryptsetup now fails if there are more keyfiles specified for non-TCRYPT device. * The luksKillSlot command now does not suppress provided password in batch mode (if password is wrong slot is not destroyed). Note that not providing password in batch mode means that keyslot is destroyed unconditionally.- update to 1.7.0: * The cryptsetup 1.7 release changes defaults for LUKS, there are no API changes. * Default hash function is now SHA256 (used in key derivation function and anti-forensic splitter). * Default iteration time for PBKDF2 is now 2 seconds. * Fix PBKDF2 iteration benchmark for longer key sizes. * Remove experimental warning for reencrypt tool. * Add optional libpasswdqc support for new LUKS passwords. * Update FAQ document.- Fix missing dependency on coreutils for initrd macros (boo#958562) - Call missing initrd macro at postun (boo#958562)- Update to 1.6.8 * If the null cipher (no encryption) is used, allow only empty password for LUKS. (Previously cryptsetup accepted any password in this case.) The null cipher can be used only for testing and it is used temporarily during offline encrypting not yet encrypted device (cryptsetup-reencrypt tool). Accepting only empty password prevents situation when someone adds another LUKS device using the same UUID (UUID of existing LUKS device) with faked header containing null cipher. This could force user to use different LUKS device (with no encryption) without noticing. (IOW it prevents situation when attacker intentionally forces user to boot into different system just by LUKS header manipulation.) Properly configured systems should have an additional integrity protection in place here (LUKS here provides only confidentiality) but it is better to not allow this situation in the first place. (For more info see QubesOS Security Bulletin QSB-019-2015.) * Properly support stdin "-" handling for luksAddKey for both new and old keyfile parameters. * If encrypted device is file-backed (it uses underlying loop device), cryptsetup resize will try to resize underlying loop device as well. (It can be used to grow up file-backed device in one step.) * Cryptsetup now allows to use empty password through stdin pipe. (Intended only for testing in scripts.)- Enable verbose build log.- regenerate the initrd if cryptsetup tool changes (wanted by 90crypt dracut module)- Update to 1.6.7 * Cryptsetup TCRYPT mode now supports VeraCrypt devices (TrueCrypt extension) * Support keyfile-offset and keyfile-size options even for plain volumes. * Support keyfile option for luksAddKey if the master key is specified. * For historic reasons, hashing in the plain mode is not used if keyfile is specified (with exception of --key-file=-). Print a warning if these parameters are ignored. * Support permanent device decryption for cryptsetup-reencrypt. To remove LUKS encryption from a device, you can now use - -decrypt option. * Allow to use --header option in all LUKS commands. The - -header always takes precedence over positional device argument. * Allow luksSuspend without need to specify a detached header. * Detect if O_DIRECT is usable on a device allocation. There are some strange storage stack configurations which wrongly allows to open devices with direct-io but fails on all IO operations later. * Add low-level performance options tuning for dmcrypt (for Linux 4.0 and later). * Get rid of libfipscheck library. (Note that this option was used only for Red Hat and derived distributions.) With recent FIPS changes we do not need to link to this FIPS monster anymore. Also drop some no longer needed FIPS mode checks. * Many fixes and clarifications to man pages. * Prevent compiler to optimize-out zeroing of buffers for on-stack variables. * Fix a crash if non-GNU strerror_r is used.h01-ch3d 1725261862  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd2.7.0-150600.3.3.1cryptsetup-docAUTHORSFAQ.mdREADME.mdon-disk-format-luks2.pdfon-disk-format.pdfv1.0.7-ReleaseNotesv1.1.0-ReleaseNotesv1.1.1-ReleaseNotesv1.1.2-ReleaseNotesv1.1.3-ReleaseNotesv1.2.0-ReleaseNotesv1.3.0-ReleaseNotesv1.3.1-ReleaseNotesv1.4.0-ReleaseNotesv1.4.1-ReleaseNotesv1.4.2-ReleaseNotesv1.4.3-ReleaseNotesv1.5.0-ReleaseNotesv1.5.1-ReleaseNotesv1.6.0-ReleaseNotesv1.6.1-ReleaseNotesv1.6.2-ReleaseNotesv1.6.3-ReleaseNotesv1.6.4-ReleaseNotesv1.6.5-ReleaseNotesv1.6.6-ReleaseNotesv1.6.7-ReleaseNotesv1.6.8-ReleaseNotesv1.7.0-ReleaseNotesv1.7.1-ReleaseNotesv1.7.2-ReleaseNotesv1.7.3-ReleaseNotesv1.7.4-ReleaseNotesv1.7.5-ReleaseNotesv2.0.0-ReleaseNotesv2.0.1-ReleaseNotesv2.0.2-ReleaseNotesv2.0.3-ReleaseNotesv2.0.4-ReleaseNotesv2.0.5-ReleaseNotesv2.0.6-ReleaseNotesv2.1.0-ReleaseNotesv2.2.0-ReleaseNotesv2.2.1-ReleaseNotesv2.2.2-ReleaseNotesv2.3.0-ReleaseNotesv2.3.1-ReleaseNotesv2.3.2-ReleaseNotesv2.3.3-ReleaseNotesv2.3.4-ReleaseNotesv2.3.5-ReleaseNotesv2.3.6-ReleaseNotesv2.4.0-ReleaseNotesv2.4.1-ReleaseNotesv2.4.2-ReleaseNotesv2.4.3-ReleaseNotesv2.5.0-ReleaseNotesv2.6.0-ReleaseNotesv2.6.1-ReleaseNotesv2.7.0-ReleaseNotescryptsetup-benchmark.8.gzcryptsetup-bitlkDump.8.gzcryptsetup-bitlkOpen.8.gzcryptsetup-close.8.gzcryptsetup-config.8.gzcryptsetup-convert.8.gzcryptsetup-create.8.gzcryptsetup-erase.8.gzcryptsetup-fvault2Dump.8.gzcryptsetup-fvault2Open.8.gzcryptsetup-isLuks.8.gzcryptsetup-loopaesOpen.8.gzcryptsetup-luksAddKey.8.gzcryptsetup-luksChangeKey.8.gzcryptsetup-luksConvertKey.8.gzcryptsetup-luksDump.8.gzcryptsetup-luksErase.8.gzcryptsetup-luksFormat.8.gzcryptsetup-luksHeaderBackup.8.gzcryptsetup-luksHeaderRestore.8.gzcryptsetup-luksKillSlot.8.gzcryptsetup-luksOpen.8.gzcryptsetup-luksRemoveKey.8.gzcryptsetup-luksResume.8.gzcryptsetup-luksSuspend.8.gzcryptsetup-luksUUID.8.gzcryptsetup-open.8.gzcryptsetup-plainOpen.8.gzcryptsetup-reencrypt.8.gzcryptsetup-refresh.8.gzcryptsetup-repair.8.gzcryptsetup-resize.8.gzcryptsetup-status.8.gzcryptsetup-tcryptDump.8.gzcryptsetup-tcryptOpen.8.gzcryptsetup-token.8.gzcryptsetup.8.gzintegritysetup.8.gzveritysetup.8.gz/usr/share/doc/packages//usr/share/doc/packages/cryptsetup-doc//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:35433/SUSE_SLE-15-SP6_Update/5f8c1318954e33d789e9da31b80cf2ff-cryptsetup.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII textUTF-8 Unicode texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with no line terminators (gzip compressed data, max compression, from Unix)\vFrj(cryptsetup and man)(cryptsetup and patterns-base-documentation)utf-8cf4e1265fb9cdc979121562868ceecb8d0e5c03d7e89052a901d3b837bd8f313? 7zXZ !t//]"k%.Q*7^X?Z(| c-oO݊Jv+E<)ɕ8!4"hZ=lVcCAa9APwR_\X {).`/Ü:GKǷ_rbwsФVnTv4{N!t*PN.ș-T8Rw8LIY\n<9žrsqwm7}BQ;=l+Fgr⪳!-0g[ք~tYYGd]E2.r>?Ž`gNxbj®-3WK) 7 4#[^Me%q̀H"q<o rL(`+,)^)bqbޅ.g±RPmTG5o%0op=gM"aOʗQn-2- >8>le6>O8?FLifuG~y@>[cUutv2"k6 [ #'=| bߺFsJݰ6Y.:[T=Nc<C9P&4S-iyKO0Lzt_Ђ10FTf"Pc .wXk4IZzXV4r fшi.[tX"bij{BpĐEnVRB9[iJ8Zյ/@]1ڕTɛ'pd4AA~^ksI-3sM?W2p5Mr]' X6U\_VUz[%ԱΕy Ϸ>9-WFiݱ;L[RJS,v.|xO(yuRw|^ƿ߰#drEEGBPj.^Iͷ0%r؇:ֆ!8 5fxH|N@&%tnܷz7>̦Ua8̸H†Q>NJuJs9J4GAu֍[ow0/jI;Kx&azopQ\% eaKaI^C-` 㨯NCNz|~6ҸBC1]2І<f\PYu_ԇBP|6Z,PKePlJpyE͍gJbU,jېꓓI[]. Ɠb`xVgAwl&6::dppi*;ToZHo"F@Ъ,ȩo (Mdgt.PݾտRV Gyr'!h~t1U鳔-͚'hKҧ\/!TЯ.[{QmsϟHn:q53 X5af\=*,Q9!_'Ql>Y&T[<_j%EB3 C0 DxC1HuQNق-.&D6CcUAahvaP C_DQj!(,Zm'^+v^M{JI xeFR$5/)h{~pvF_&?C:f~Eizk@nh} g}FX5V#C3$r6\_|@ΜmDXKv3s_:"yΒ;_>@)DfF|CVyZDn(ZS+&Ϥ^D!%A7yk1. P[CaѥE&p DLI!=O9Gz,"k|ct<_kvq^Ӽ{nkIrX_Zolವ2z1l *5ڶ.&zmU$Z~\_> ,%°ێq~ Ā;Z늩 }jݶϻ$־d2D^YNe:{)1G_T&jN(g 'A:ϩ"$aW.Xk *Uys)螃qE9غhzYUa׊oHM\pJe3_F \?٬fB?a3aXN}PA;>/ŏԽ>Pt /50y (sBGAJVOU/-ľdxHmpy+쐚T-?㳫SvND5*@/.dwȡkY0j`(j8fȐUO "o~Ćlʨ٧*r&t=|ќXm)_CȚ݁ .ԩVzs77AGj GkGL""2uÓ(t:!tۘoh{EȮgg'8e)}(3JY|M5"K!g)5g+);U1љZUzVu w'jhCqį5dsAɽ5S"Y9y$n!{xWW* %:Av0|XXH?F`no?ݜNK1ۃ)'¼ԑ&Xe?UcJpo#rVBE3W]soG-`KA*'ZF^*o| jHXODR.ŤO!oG,crXK\Qe+2gf5=}e"9>dbIlţob!ya lU7[a,^V-ABnǫ^C[i<\ OL>]!4 @Tux+m;9d Al~*Ǚ}2n*ןP[)jGL߷Ɩ!PI ,=|i6$~X :$"l5cęiPhL񵪕zpfH4aF,Fت afV9|c4qmfV_/\ŵ*pOrPԬSօ#o@_*Q9Xn9DQ [#P]s`m׀E Jމ^(_ y ia[:783 A3b9ܽJZd'x8bӘo sQ;bF.L[9K )@D..2d#}^̕eշq¸&5翷h\)YX1?xov{kadgO k[,B+A&1}pQXHl 'ȇc{vb{VߪTu#rJHKf& /xH5;>zj?l?TcxCm#^5] 5-q J"빟?cxs餴ӄ7FÛuN{.[*+[=<.-g|:#{`)F$%#ߣs\T1E/od (&ӼW()zk7DΓbR~yMu3 X OMաJxoħһQ Z#^c 0'2ݯI}vcng雪+0(G^;.& _1A|Tr "TƧ!XRt#T+NYYT[ғ¼TTqǼSZ6WZp~sCCv|j R|UZm#=9/IR4 ̎\tA=;Q2ϱ~->ɓ`-:ǫ([ ڋu B@dLADԔ9asasZ`HǍIUbР"Tk6vآ|% CxlG =+Σzz)y_Vdr&;!hck0Opq7*{igw]˲VK"J4>ɹJj&Sq,cI`S%.nmô6 sGG3m-_e=-O>OBE?.p$Wt-,Lm v1 3<֞;a-YЁbim#J '!5.34k[Cs'e )vAA+θBj>cރo=Z{xo[OY/A| /\=@pD ۦIP޸wv(ҩ'lܓ@P^?Z3N_'Qbߞp?gD+ dÊsR}Wlf~7Dg]K:Җ+@P2`تtX A]][@͛=|H[|4OΓW# P,T˼5JiwvbsR?$hg醹y\g ,;Xi4AkZ>MVHa]$f˜uUi2QM œS~ Cq9\ETe;2 v+=kQH#&P+w/fX܍. S Q>]bwɁF, n9Es j5H~IvbޭzV4`.I1-/wbM.02Kqt2 T]8QT2IrF~u\xw8ԨJf_ S\@x)&ӆ#^)3︃tA;lP&cE--)6 |Ȩ7L,_`ȬQ1JyZ&=[HXna|>Nc::U@̇wxTvL!MM!Ite#S]QΠ)<h6dsUĠcM6{`"WvEl!#.nPJ5qY0mS!%;Xs4*tL+יAZ2+@SW< Rnׇ ִ>iLWymK=I Nw $t2d,/ۅfxS`n0EFDlL/ɐDOI,eQ:hNetz;V?|ȳ2X,b[6V9Ym>za6d,J_TSձ2d9Uukl6gկ.YE_ | ]Yk5.Wگ0և 7\L>:oC{T=[s{bә*}%cL1~"F:#NsӔR%gGYaY^$>؋sA%N]wñ!g&%(- PE' 2wDG%g$Y8v w @qL!HZ^w !t繍WϽ)msրStj/“G(坧0ɢXKKL 8SSV|o"w; ;gyn"RpJ-g):./,X*5"TyW2QX\/DK kĩBs@K~\>a :CqꔞwI&=,ho+Px& lu`F#ܹDNʼ!7},} ZN[!dc.2Qq 2 L՘iE3i\{xF84?gKUVGA9 hBZu;)wT)^`|y%)EK? ~N0>+^".a\DDz"2!d!s_ 5h(j,o cih~D5Sd S)@BDhT3␢/y FԤӑ&yWbe%R*/ū QRP?Ewl)pPsg{/ca2!ܵn>>0R'8C8D9?j ox3il\-IBD;Y7P 4aHwh4b{\D8g;ٻOwm;/PWƵw/͔3bh{o+LOr,W-9xXsepeQb H腡B{[EPJXw`CKf] lYȨ @ֹhd4nUl@Y>W|vM+hHDvUM7U ӣ ׮`wb;12IاT+axH KJT3U`-(N?^&D\rϻ"ICWkr ֞-j3{卑q{|˗2?[r͙j$Zr:Qb+-ߔ4Cȶ ^͙P) oB"W3gVRpx&;Mn_/Џii33h0&“IbZ ׏-#MD7c#8҈թ E Au|䄣^-SPqE;t?Θo/DX49w{d`%ipFu(LW+Dfdyތ8Bq6Y_je #  Vy[*dhk=讣*~JS'xAM-ұ\ࡱۻ:u!Xt"|Tйㄶ'Orx1PNy%ʚ7tFE:ץJnS/lI`[wߍ@Ϝ4Xllu0Q4F~|WsA'r 7@4v [+޴2WwlBxti)$[S/_An-Ne OR^Cc1h+$2\q&q :!&KDgv Oy7&ƴ<lR_6TͬrNF- cy+V';:4=.2ú@xHs*JpeJ;E"mLI?vRՠsg]@\XKT(}AEXF(ohA8x]Ÿ|@|>>0処,fw(M*5M@Z+衑Ƿi*G1ݦ.FR@8Q9 X x4o%7fFQAF; Cs =I#I .r]tơec䝞V/ztf. V V,Z?%c^\ޞNbCo#n0b\u ;;;#p2'IxI֠Ȧkn[Ug[XAJ2G@ ) *#:QIwkfQ[y=' *~eW.o5e\:MQ.u(, b\QVbx <~\b#T/)_%Gs_9K޵a#l3wspH4GCFc:I'|!Ǫ`qys/S8Vy#'$y~hR D0Uc\%iaLIʽ/B#8C"R_jh(ħZcI՛[gQFhu?R#ϸaЧy! ci K.7nMfѕaF")?z^nuԕ[wW^e=͌wѶmgYЦb<zۃtӻ]>̮2J눆"cD*`)#P}4{X(Ψ[r,9J*V]IB${(p̞nfr`π Z{9TU ;52t@U b]밈Gn!uK=I~C֤]#1V&d͓`^RNU@:iT^\`zKG"w"nز!!WD\C#wL,Ⅾj ]UC* \h9#pC i{ThX7vwqЛlLa3qEҐt 19_ VsxʿzXY;RGxo$JAޑl! 8!/`%уt$amea#rjyo]H1?‚EԾ1?4uq#ˎű.G t #__۔hq^@D>^ Gpw 꼲-DMNQ5JCaD kq7 wfiQfI][10.{Mv?LqNr/DJ1E\e:V{([gelm-8$HVk̦q^an:/NJnb F/ԻGLH:]|a-d'jTZ {)xMokMƹ-8:eJw(#4]a yf%ۄxL&5(KsXä#Fp2HPE8EU1BuqV(xX7(LJ (_L?9,(2Џ"HoyO4>Y/^ -fEO~O;`,}U Mw`@:BnT*h"/ ~2[`>z-9`\ώ!j=Lv5-x aV)酂l:0luC,wBIkv}K2+_^Sp|=|ؙ ^k a\<< L"Dgl .'fsbK{AʶDKx4{ &ɳVNFguZv?[9}o]KEE6zc Fy3$w[]w{&eS4z|~0Zyp FI|.#O14^|dizq(\sf„hӋ|K+rÉH\U_6EF٬ iCYo*VMZ, |nX\K"}m{/:w:.Ki4q(donF /O Sg[$5(gFKܧN *%һ"87hJމ3&t|!3ڦy5Tۄ#K, 9͵&S6cKQ"5exH>IVI+{ZYp`'g{%eCJ23P 5f+_[ͱa#A4eR <:.pk0lWŊ2PWcn΢I (lB} K!1X0b)DR7>=o*gj6%9^0%mf~^X(7_upJ,MED6gۿ+'f:{{ÁMy= Cr^GNW3ZL uy0bĶm/̜\ ^fW1BuL)#QgR> BH:z4hʶ)2u?wǖL!kˆ嚮*zVzU|ތt0{~)شP>{gh{Aŋ: 4q#>q|[I7$(1(ղ*R`z솁"u6#uOHL@:I[e@ΛSPMbQgw؀6TZpEėNiR>VYM}.*A ئ$CǢpviT^fT)װ=NBI F $Wv'ݏy"}6Tq<ݦ 1)vߎjTTDbnQdLCzK|gRӬykޓkh%%%fx4.xJ!2~"CD,Zk/B„kYK[żL<|c7;2=d&>U}{='4JU2#8]c2zʹ7[gw9e = ̊i'4DįUXjfLAz/j"ZAי[Aү$Cvf0nS`;vC0Ѝ(%=Io 蹻}"lD;}>AkǑuڑAq_ c(T#֮w.YL(?fΪ-6kPe9F$=G,*x`d7󇪣,T}B꭛eC8:̝@aRBȿ` ^ ۛWe[rԃ8{J٢,TYi6"Kvb\&*J4 2B`lOGeͲkW397cܝ]S#P 8`.x%J l4A戰"9 Tk7ydBW4cgRdVKQc~mt ³7v*>R;]?ȭ[/ x\ qۀ̱??JDg/4i_&KW rAG0- ^Ƥrqecr7wh@1Zk)J&&2@r`EQ^JH)YU tyR7}`#|a b%H*6 LA1OQ&&QƏSI0U{ :r[y:m, {YZ!1d9%n^/nSul7;2ZWH ,(y":0 5}~T8N5l-Gp,HDU/mR'F-,B%WX/NrVɩ! ƪr y>DnU޴@m06?ӵ$DwA24tء[CG@~ F2c}n{8DMfU Ú{~xU_VmH>17Eϣgai; 哪P72-/ oddԑh;]O(I $3 pXHq}y ! ixsBB"wj3̗Su @'U HW#NԘ3a(< h#.Nڭ$ Bj~aYܨZ;ꗳBU7>o`lrme҇ &:ݒ|X.W`jrH?B~J҈nM>mj;nRG(.\Ҷe=tղ_Mc#'uYIJ]1iRh_)Xq@"3@GęD2, lXB Gg.DL$@cQJetII+/CɁ^iTY^vЏt`σ{soa8ntoz$H8| Z[PCp,~ѡSTY*6sU^y@hu5MAX ݻQ ԙ?8ߟSpy)*yʈZk)DDsVFz\ibMڋΩhI$O~!GO;H?<9eRs`ZVi$*{[胩s*ؙ)准&0>!`&\bg{ؒI.+j:UzީU5x܏@ZMh!Ea7Yn}u{`>l*7JTɃTbTZ `?+PO ķj փJx7މ4n G|zLbKUCʧ7WdBYg,nd2uUhwxEՒB`?٣nl /}32,dv̄Ҁ6v~gg2<nkW̏zM.;54m`( #ί} ,-FlO#4mF-WEƱpoU:(>~oM,`ٖyԞoU=k 6_4p9=Px:9Φ{k5"\ HG4gF P- dFTYn)shTk 4WBC*2:H _] 2罢 ~jNHQٙ%k@x?!!C'R>6܃r gbίA.a~uvw^hL,ps^NDX}/B\D0\d7JFEQi W@9`'p״ <&옸dqǿE mX Ĥ8^rk?NF#&`MnÆ+"r(L ]Rג$`n0>kBQu ɠx+Hw_Nsgz~6t_hq,\2<] .pSf0N Nw[7XaҒOυ=i$=dg U^ Ţѯb"bf#8hd6N]aQbضME `_<_n*Eb} gȒ' ~[/ࢥ?9AUʪnn [e\eNI|o7-5{Z?HZ}W=:gO1vd6&4R=kM7ߐ}fͼ熻Y&}1aoSEi}c'o$!b0݇nxԏ߷`e`E2"irYJ̠ުÚ$AZv#O1F6lWȷ!4Y"٦'?@5&Q1 !iՁ_mmuW\Qx-]Xp+)n&0b,9Y:]&(ǜAY^exz/#T<$F͝b(EJdQsiF-Tu?GJn@6W,ۃZ5ú7Xz8!YA&wsІ/(XDx3p,:= =N?V9eOUQNB??4_V2alEl[烐 loi|&/7AP Vƞ亀n@U-:> Qhaӝ߂998/{ |8uOσ4#4N,Uܧ&n.l"d>W̌~$!\e8T23Us9nfpCbs_+E }B<}=8 ?:R-Zj!<}fVT/+I@*`wh"h1ޒoпZ PnڬO3'=&(aI!7^o;ʥ!nH }Q{$֣~K<9ț^W^ O s0?XieuPi!`#h >xn yYHR~'{(Sol<56ƞԉ<8#]isSI[vhwTsP!4/ w.'R 'V(mh^TzE,uo7߂Ö{9;ڛ3hź1ۼ8.>C;u0˚Zg 4Kx8j~nKH9ՆR8jj*PuxI. dـc,ES,Ũ #_F'=4#J ˤEnPm7S)K~-@G\z%BT27Ψ( C|2* a ҙs8MjhCn"rAQٰU36x+ܠy/x(JEKFIުK/nYݖpo3CK̨z3#UblE8hy93sx=R!djm-V"փ>>%J^S>nֆ<ڝ^B@.ywOypp<8a?y֍^:V-b?*i}uw0Īw)t {QS^m!3~ 8_O+>$6彎sL9Vlj@D?":B^q>Z\E??IsTSޫ]xrw'h^NkŻ"gMS%ak$-ySEfKwSJAnZ&B4Cp坱/@2U2.,CAӣp<:,uY735]M<:r=ƶ܇Phg} GB@Ȗ镈[n&xF D_]% &`#A{u?,e7|YD ՇSl)R3GSW(5.Cy-oԑks X_XxG1>3t!߬RӦFx[7$wSV  kѵU',wi^z}J8MwkU pc?h?;*R'h_2iBCV'UZMc>ĆxcgtYUMt1 ͆eDŽh%P29]|ǔoVz lOIR/5Z_Q,&@}a/SiR-7nQ[O;6_`e7|\vvwOPx/FaLg7ݱ w#p{nuL Pћ.1;}bߠ9FOlܻԋPn=n9\'g^-.n>j_ݬxuԶF_D\"8kȇh@8+'9f4&j6)[ȦkiԢnF`׾;grg%W]ϝɁ8Z} W=ZSf1Ǎ[wtSK1ɀPNѕ' +4J@'7J*~!fE/Q"=H    .t6t0XPH\i;r͆稩L_#URgs蹐{]tqR`9O"ζ%Iey (5\f3ͱ} ^Ah"AΜ |붣RBxڢӶM mM>+, /LX|2'EXw]8t{ςGC3÷EGO5C/N{Y4[%i2Yl;G}T%.wfE09z^By)]CoPD6ۓ֦^-x gyXnv]RtwmFEQ@<@`ɕH8m?]J Eϸ swlң]5ӦH85O{Q-Xi<_fQճ5V\R"sٗ{ G ]/#yvXEY?(1w<]:(S z>,e IrU v:U r9E TqJ2zMXIzX]J*Vz nPdPAwUwp$y+zq ТSafZL/G{{n?Ќq}ުжmoB%}o-SVUx.5՗aZ8G5t1qޙ'pTŷp0..M3ǐmpY--WT'kSK2>Yk u%.f|Z*Jn?mO2+WЪa@$n$7գPZ;D\`:22gGڄ`rN~{Ю'ki5'{;< 9BM,%}'t@k6#HygTRơͰt1=@nlVCڲ^26.0uM_`+{Uwb͕3wqcbq*D d#ui3p~bf<ԗͤ]j~iZE qwQTZx5j@P< }TǁAI(NĉI1GSj 3<{a_ݻ ,q?\[g1F?m"5wl9s6m}Ӄ(FR:t39q"TWc ?#= ~,Htݪltwv*7-7x`([l'?otQK0AoziZI֜cƞUٹ'z#C@۳#ީW}{9ur ABoDWM:J3Lr ?GXk5^G8Q.ԡ1|[WYYkV',4wߥXXFamk5l`& rLe͚jԲ r ,V/O 5.Rɉ5f#BޞdY$*1?QR_\b=1x7ZNL+Ѡva;tk ]崈j-o;}6 .'_j%鶺z6ϝAL 3>'c:J|eR/"s_ "k5-8w%V3_,QQu%H~%Ֆ0"@"nZaZ} 0єSW۱n}~vF5A4xv| n!t!ׯ_틊XUQŧT∼̢ep(u0| [$O8b.j}腜xwUhhƯmߋ;.Hkf:S<ĉ\F4D!]Cꏬ@g8Ra #%8'56Բ ^/ml#M$(1}q6Pm< /4.-o O!gN8Pb;Mzt=.7lLbe(T#ᰔĊ"X[B,e/7ལq,=zj<@;Hs[LhϣBk|~C vΓǃ_ouήN\=N[>3.0MYY 6-VRp$;5$XBzJ9eXB!H7#}us1)һ@oJb(6SlƳw!IAꃾxÝ'DU 4,ؐOV睺C6Iԏl xưV7'Wh[(A3}>=1yKZ96X(޻ܖcJ=01sg}9"/tXu:qo;Q]S$gP%㷔 D?t*6 #Gݤz)Ѭm@'D=i\Li,yXwaafm ]@k*b8Z]4;]@%85!KȤYkE p7Nulڥ fK“oEOv?c8SsAam?:༗zj j~:0:|$1![UW_I{`s0A ?>CO%hZEf !(+w^]}/Ud0dBV [ϴb!rj]3sQ'zLt2M5,PvK*OI%_?yV{٘%0 %Nl?,gHf6 DK<098"e*4US3ӝg,9 Ou"^YоMȡbn;g?0VlbLUE$S2CwKTD6 6|[+U:$l* ԋ] )@z̭ 9FëCKQ0Jk$x;?9aNŜ[kn;ř&[%`"x4ЁDZ>rIifd/x[U5RT S0,]qmpY07SUB\.!0'=9fˋHjkwMxLx 341qZ d|x]q5pA49fɪ]'֗ztf Bo\p)#x+mnXEB:h/q؊[S1.uDܻA}=KM9̑HgP]Rn'*!U`UB[#(Fc߀bb@V>uT]%Ve&6zWşHl9Lze1.7C~E!ƚ0|۠)iXX8V٢N@4좻dgn: )q،Fq*aLR{M\فy?h}G_+@ԈtDoծ9_9˜#B.dTDWjdpoKKeTV)FANē^ʉ=zԷH/*ΡOX ,:#/(Wԣ?z+c 3D6MA&Aa;=1" D⦏#@u.HD74iЎ/VU>G>Ԝz=_3¨N3pd% aJ w0ߧ8#!ض20W-&`ŜŸCVo)CmT}pqO0XDzx/7\ $sud f;=6/fp4>~vc[E/0]UrvlB]Jg/9YlTy&L; Y'||i\SQW9^ݖ%*I!<1;Gq᫕Tn\ysw>gypL7QG8YTLs4LWѡ_pkYH 4c3ϓ(ȎU w?}I=EI qj[ƢmsU;RWmĈ/ :Su67 ȪFx]sfv41sJ$tY p͒  7CfE ^4gѢ+`P͜j)ftRi( Ph,b6yɔjUL;fFYXֿKEeܒZVYfl*xTY<D>ՋӪ?DvD ~"% tQ;Li,nfCK`feL+  K>aBNߝpQ>;*Al,oEH91Fjn\9joa_{B@fOT7 tA-hg}^Hjۀ-;4@us_ks [YH+-aR*5a޺o5IcC>ŭe%!8`JoWba,NZ#kFK)j- ' Y(ڊ^>=(&:G1@ψo (EĮEEZ++R/“y_?& (轟7Pȩa~[ 2aνj V+1T|ٵy%s)%heH\P3Hկ*ǀ-O?/JTzK/хPOczArb9Lx:igZdli"@h =!9XuB{vROtנ˙%u=S!IŗjnOQa-TCDq˷$*J IV=pMiz/a{ul'chBލDj z6zZ8uk uLb9xL@v=PZB Y5zp#{Ts qP` -P8nh;{/bD㉴~ A{G1 h`rj" Pl lXCBNApǥL-KO7֢B+NİՌw_Ov3`4pU5_q,d諃5+%TY+ՓK5iZ8 *?%z< QyQQ[<nWG׆]pr 3iM|x*!3R3!( LVXs@jxJmM4$2mX-kI+zǨ:gac0@?UxHO%@۸׍EH!x(ribȡ vMbuU#(ukdq/?#ny7MuW:*' :iF O`f4JXF8TB)/܈w tBꎲN2PE?_|HͫÉH'eve zb9@ EзɊ}l8TG(n$6AFHovi;5 Pydݴz_Z,fY ʵUK44i n^WL&Ҝ$}5Ŋ{+ƟT5YV:? > X}3#:uF ʰ XX67<, 3Z96Lf?̂~p2&lhܭ R"x$vXEA1.gZ-m=SuLkV5DNq-iJ6"&ۿʓU#h5𢔈ጓMi4ذoZt;a 'poVxľ)I "G;ѕ'SM)σx`!<.sAςD)GJ~O(GV$ hvߐA0҉sTώ@B(`Tҩt!VX=h os.oOd#=aeۣӨrA1U1 s _F 'oGڋ碧MCܦSd_:y%c"|Ï".Oѩ>˼24["aV-n[$XP-QS*&/_ ;NPMW"0.xNL `Qއ{ zW 5WDĻWQb{v8\6ARXi- %{ْ(k֜_RL {'6X}21"H2md=T,7صw VyE)h2vA_qf "^.Ԧ<ɦ;^=D]Wv279Ԩ%[>FUwl9a [T6XQGs <X~/fCn*S5@M𒎆n90T Z#2i\1,A&WVH: 1E)!@]̂!޻xs5tOG5~9cܺ( 1IpA/<7@aDSLǪ/5X;YAWm#d}ˤ]m5 4ߴ;Y ԈkQCm.Bhדw]5ӄʘ[U@y|c3.@c417. O6h`W!* ޔ ]x˟o´/ Nys\2SBv" m[sg`'_&U:>.Ѭ =|MSmgr?z8/W$_h8wY#svQe hR((d}3f|m(|uD5~x> ]/E[BϦ5JWx202z"s_KMŕ !֩dղ58k:5JK",> T yhw4~_/qE'S*Afgu_<ߪISZ4zLgQT DV7q+F\B"hVq(iv9T;'.ZJH+H^DY)D8AeZߊR,7@#=NW}M-xozW R%^.j|udVNݟ)eA=jZKPMvgMH1bT.=Db L |!]y8ғ}it&߁b cIaw_tu9-]'4WFAg֋= V'_/U8:XcۙR15%YqJ] Frmy0?3 ;3}*>>蔹nZ`*_ө$*KiA"X'KWQ !YO*hDwmn;zCe0710gfsw%Ck҈: !16nr3aCNړI] #j~6(j1E~n4,tFj@kfLVz\e֬L U"U&2d9oB]}D-/S TDGM풵C~94GEO1*b\eP·"`+vKG>LTfk _[OXHђQ!ƒkm5F/X ;(ܽ}Qcy1 `9#gT]]1}qřr\bΡ8w[xw*)- ȯ2厸 G$q"j'wuPBKb)ޱj]L-跙KG8W;!6Cw~@v VLDO#i7CYT%㤽w@=ҪQ)Wܭ!R'ΓQ^2cuJalpF~HŌ~~дC͙O+GFKQ]%9k ڭ$ek(՘qʢ#:MgIU 9X/|ϳDžSxi+ -eVNХÌ@ʵ&*@& n,0Sdl l4Nk9CFR3j=O_zR9  6xvX _ CgkFQG~feL Xc!v9ލqm>&`o,[kX;~C0)#<.DDPø7'.sgO)*]Aiqݕ.zu")69UtQԋozӳ[.[(Qyۇ6g R %jͥcڊ[M[SoPw+ܚl@Sb-|˟JUJ<ٟfڇ*zNՄsz[9NQjEM.oƄZ0?m'uМ*TQDH@*PоK7CIvϮ|&bRH7\ps$nNE@D$ZwUx7V$9< x5 @la)t-5RrN%PNkYX*IOne,!^~"ٯ(~ddU`xErk%Q3`uxYk# U̸J1=x!R[(,a0ɎJWiMsž+$Z藿E WE7ňd5wsUH>OQS厳iwLr,j3<*>cNavTC*MVLAuFZ륇g*Jnz./]n4}0@:oYg!<*0^Љ4"z*xst}*\O(/N6p2Z@<mCG%㌹ʇĪ,vo| OX\{!=jFM4{G,m wH8pv,3 LTeEF?WؑP DUTU0W⮂|h#>|nA85sL&5~ =JX% aY@pu%>A-{fiH&SI* /4%9_ 7[ 4yqHS3:5< EG* <2Hq;ӝ)K[;r&=Aݛ55<ǻ4Ɏ$DktՒdSEW&;ۦ06^@p=(9a ꖏ`nxԹW}Ds&ԔWTd }%awsNiSfT@Gh;Ye9xh ]uDcynh+̭ {vK?ǐ[6r*دv.eox ;l~pN&&H]q/92Mx WJ+Vg4dcl7|lXlkS'G ehs3?Ĺ7ެUoan6{L|b-;1lJ/l#V~|( r+,IFֶL2I3pEith˹<=u݀Rj40^_^;}!6ᣱ1&y$yQZ K-D]ݗ@^IK5&dҕp{|xXo3l%qPrJ<JBpA4t:m}z-RzvƓS~YMz?۸b*[6y`pPKamkW.l#n*v/q`;n`\z8#ye:p 5g^"{6͊-"Rr~vװ_OI''mcfW v%-OEV-ęZ^ECsn^qq#^Mtd!:LtKyMn~"(O!n>P߻*<06aTN AJ\g&9"?!}W_/x]!ʻK!L6>UpVGKp|&xçV >3*gv uequ} sv;3vP]fY"BE{ґ0S,k/+?n&U7H,ܚӘ qi \ H@ CmM 2PB3!}5kH1@=ȚvL1"rHª("w('2dvBѶQnYსF:% ]&= H~eej :I/#CD[!z S?_[WevfE3$41pdww&w5 ~oጄG'ɬ8} ^C^Tak{e:^\G_97)5urRmH*WmuPqclB\j+l0'2OX]ZP7*U;ƘTX_Ɗ{?|olO6rjmUH`64}6em3C2ceKQrwio(' 6GXYwir lrŝvxJig4umW;Y=eGgf3A }g/cnr|~e0U`󼰖:%L7Y5Vۚfbʢ,0)z]󍦃I3cԟ)>芺̈́` ́~C<$/$j59hV&#*3M.9|aI⺯?i}C\f96+POM9[KPgKc}bӥjF w3^8$_r6j?R(s@PןW[N2)wtZ RGo:F*\b\dԳL [aC;*T4΍3:ΰԇGr@Y&sQ>~YV97z*dQ`68 $E̍3jv3m)v '+ ]3 Eb ϗɼٺ]}t @ojVv3`|qє{.+-qJ"qq @ 5_ #3mdƳ]bU*{(gn9|w;}嵟ّyG*9!E(;@= <7v >˛kڠu?籙H&J-UMaDZȴDVit^ u`rr){]!V!+|alR2! ` W%G [$ }s钑UKguTiTĠ'lԭRoh>hr:aa*l:O~[~>UΤÛ-*ןTK!Hb 35%*W?RoU М(>56i0?eX6Q)3B!KU <9QӕO\pxj}ݢP1Z!.,~< Rp&VcTo e$azi{a^>C_DF>_#8z[a!U߶?44Z=Cc@Usf"g4 0fj{N^cѠʚX0p m. 쥹#$BF՛R.CNUtVZ4s2EQZ-p_8<-WJH/!po+qh%" 9~奲}ot>7=Āc(EvyXW}we-mB lK|I_R)iȝ\(NBuFsj E)01k&sbZC` ﻂ MǨ>nѯfW,:?*I"?)P{_TBVyf Pnj z d9aF1teH5Ij>Hd YO݄G:^ҚIH`s%ɷ[!7r?k.pC׎|G5$y܁=^B$h&O˛'e_Xګ*9e@LѸWs]Gq[sF;C||Nyd>U\;P0[Lս19r㭼~Cƫs٢ؾߣzbfZ.LTLizWe|O9cnlqhNh=?TŊP3$0yt\=HAK1= f*i#Dtcph7 7xSPul!_JlġO竇eå{0&~Y0jwp.#KX0w+YJ-wJ 5Zn؈\&9Kth6c=1u>Z=f L WE瘐L"siB֒CzO·r dn_ poJPg:GNAMR0w \?9$V=NN[ə..=l/^}'}#˳V6c8Hq7(;32ۤ0Zy29:rb8)qW*qS{e@P4 haZe3d @<' %9~M 3>i1*oF>1(ϥ\*[tRwhsU6VX'W*E;"[U%wzaHDk2{y4[fY#&B 1 )S0T睳ezbYURqc] / bv+@Jb\F؆`nƚ;:Yߺ:nW'ew֡sīԫYj$bsiaw1u\{ρt_H??pPZS ;\RFy׶Z4m 9% z<9guL p2K2:өihlɥ 3 pM)"KMBzuyʺIp8i\A <1+BEnI^tLK@Q :jJ^Xڔ!@x9I^RF Bqu (~C/ )8iSR&w(;#֊Di_kn SN$3;DAvax#^H8)hp_v>vy(OmkIxܥ ČӆBHeLu7Lg`߻^'93& /nJs`3ה.+CKW'JI7BoYlZ!cJZ̕nY$#v}o7mv!/ah(ë`me]AwK;oJ&J6ݒ& ONƠe%0i L"{ҭk ۰<.Ǐ)c 9CGVz}.q&L_P&i ZUPoEҊKQ91Re5U *ḝ&OSR] aᾑ,?1vV!]{P`9e^g;Od4<-NbT.4_) =-ۻls/XQ:^ 3RuGvv"RHͲm{Sh3 ԘM^܅V TOȕպ 1"mܦ))Y1N%_?zKmb_Nxζ2uiDMESNW+d,+ޕ&|Ol2EH0GOV((̈?mg]u\9D<4ʹfM l\Yb۲I_44D!ct^T;Z>7CTΧmKS[TI:-{eMZrW0< 5[! dӟ'tjJ:}h!LYSG mxMS $dJVeۻ'x|ea(Q:&kXk8AGm.OTmzb4&ɞoWVMBYc=ꨞ(ƞvyo x˙B,P-n FJC8Zyd?1&iqri#Ac&,[Yd#M9kwM3&CH≮gSӈ2tݷ?@a?a One4yL4P U^ɏ{C֡-i/M)[朌6źA̧#1)5!mӉ,aɃő0O8dh+x_LDJT\9{"/@珩s$يm%9hYߗLbZmRˍ?a_#Kj(IJJl*B&HQЮU!֯]EdRNP*[.dOm/u ,A`,g:3;g&ڢZ1,sq"ߖ$\D~(#S_:Q _V60b@f$ 8q !_qfd=`t<=lQ#`& ojE)V| 7l iu 7}qR55D㹧#>ȝbC{ -Ab0|xXjM72ıӵ#m謤 n aq2M^8i2:DבF鐓iH!;1]Hԏ>TZ ?i_v6$.yd1{L@t7j3_r?S(Cg3oFw ZT(TYJ^lO2n&59bd:)#|(?ys+b<s1$bzbX]%[*ԼJ\=sz[^Y}( SY{AUEHU5=oVo|7|ChKZW J"4x8?~7yol\ͭ-[!m֗"YRȦ6(9l$=ǵ%q.'~tP{w-C\NqO'!z ?a[73ax33oN1١v BXq06pHj/s̠FR+dزV| `hFe)UMd%2M/ `w&j>ޜcLcaU1JI6ϙaPXMnsL:\Y*g澇yjZs< MGZ sT/plZ܆ y:t_ >_6YO2*"L p%,]((KGBjhfp=pAȯd6w״UN{y=>Ly?J5j7vG@O M܅Weo^/Y%Xe&oFN:sg/Wmu` *x\)) ˷1A̷jr*6ᶠo:ER[8FE$U.,& spDh0*WmS&ӵ FPSDa'}j[xI"$܎hĬ60k*;8M%r^5e 5&p*#Iˀko~pI="S[K8O.<pમM(vS LX("X"<[$NV܉ܽFYX"q='V$ǢCvC2BNQݭB ~FF4=%߁їz/Bٛ-\.7M:@w:!" U.Sf/*BX_J+P6\ʈrdH-e{tò;t2r-V̞!Ř'b훔gHiR -E7S^FCjSgFe^ܴ x})͉1my1_zpbpD,D4aBT:v[ٶzN\]8'!`df{ sjako+M̳r6;T[zo=qf9iK]S4-pWBΜ<!Y$?#z+hLњ2 ;7 ,8o94΅Fy&G!iN7Y@ h "`<:Y΋a8#:l@ sO\nvf{eIg.1oiΙFdrNuE?U<ݎh /GJ Uq~ 4;T[s#-mv!\cIRg7_7?zSjU'IF`(v3\b-V-e{׆V9[hGScjBm5Ln',X Ω.'&z/MhXFbccRBGХ)G밉H UA&^{}(B>vS?.B")2%m<2~PY'b߮Y`%_L72\:B72BK#4:DGGZh1bB+eR k]?on7o e/ۣ\GΛ]Y"%+5-֚2]CwRCMuYC]8k:13-P+k ?OnJFg3! MO|wށ[FGchm I%ıiK0DP J${nmF ]ߺƕh/ٌ-?%{7L;t(U1NkgB 2W-/Q ,#ӝQWn^B||ߨYo[,6ᏕZת9g2شJvۢn.8.y@r K9t^\C$ɜAUn6vꕯx{ ??gR}h GW!GfnO!Ҩ~UXd^eC oޟ&֚z52qVg,\3>B#ВtY?;T]q0=SLiIPR&ۈ[g U^O"x\|HIWI$!LzrC~0ZM#O!k]fR*LQ@;O% lHr;}ɒsA=uZHwG~`h\߃"h֕4;'tQNKmOkw14)܋6tMOQۤ!M4[|*X&0ly>]N&}Ǧ F.+/":t@$hC>,Hdɫ -Gu1kY[hOj|4*DKx H*Ğ(ߌ%?1s Vzn;ep>BIeDҙds &vVAaph-D3~]W&  (ncEmx!m(9NWs7|gHi$OqCAC=Ӷj%:V{Y'L{/%>٫00y *oxdRD[kd{hF]m: K/l(AO̾vC jF@u|ϳ!QڵrӪ[[`R*|Ժn0=(_9 nFVF# hLn5 X*pZIؤ:O$׼yPBe9@mzK+4\< o00Nª^wv4~f>| bk'(ՂEXel^;'qXru?bմT潳IP~+2!M皩d4䊨 (CvʢV _b J_ &$ CȆGQYJ|;>q;*ďTLg(dmfP2}"QT#//L|Q"yTyo u7!Smѧ6&we)9V+8a-g/5S|={7 S& Wf^%5򆱖HεvޘKҼEO[㿋R^&sY((K8+g}kd|T:]/1]UԞN& ` ]%0Vl)19 Z>ĩ5O>qyW܅'0r+bȰސ]BZ:3Y7sѿ?Қѯڏi:^deVfet~Ta+/z ْm{ K)-E~lMNJđF³>2~UŽʣM]kbnL"7 o=svKU9]8G!f)GUd14 Y0d7T€_Pa &eש6^'ڷU*Ύʄvjitg+BP p;vrLta'Y!o;M`\f"j3I߼:)8o*9と?~st.7[%v&qGK # B|BQ/Dm44iH`aҏZ->M-8tg B{ZSG8ӹ=u }tC9=zÂ~ M9ҽHDf[Ƶyr8JPˋvQ{ NZxyBb%T:>,vӑJiL{]I`R|Uu]-D $eaÀnY-ʌ^Wz&I2E&qzQV瘼M CsL=-fo?_UC_Y09Tk=YɨTI3..CC Z>t9fgjWzgzC8^agJBrۍ- ]No|W6ۜսlapݪڞG &Aí ËiMl@fVt4hœ{-)}w< bps + 2yݶ#4(YLtI}vtwBw8<~He.h'p l lMn lq +L1=$6zLUx$C,M[Գgo}&/`ޝ|<{ʻoK% x_Cnmi;BBC}iˆWQS5I3,:]qߗʏd]B´UUOJ85;_ǩ,u j.cP b4j=$U]W;$\WՐӀԭȐs.?Ymtq1)aI$2HձʻJ>gGCSwX*G%nCpl, )ůZQlXVSʌT8tЋ=kn fФ]=V,SHΐ^*J@[/[ramJ9E޲&DH1 1g2c E<|EX݃Sh@;pdF) xw$7khn0ěJ DQǸ(W|ggݶ$Pb1vP`:M֦)*DEDmNTYk_hszЍ{m3M͓jLc윁̷G'|Fb ň-+E1iMp_&e(} x}F hWLq_9{ $UW_r*ב]y}?ܮ}qjQՂ~QO$-[wlEhLjSGfp\;9wvԌK8#!} 5'0 G7*aݞ OeT0;$azKOʽ0ܾ2yGel!%%Ĕ/s:V ՟N7ŤhaUHGPPV핶}k kbĘ6=z0ʡ4o]/vŰ#)ou6Xt(&Q&o@jJL6׍w<^a/GIƒ3RF1en|@|>OXq3-k,)}C ${O fN\`=S1"4^:BrQ6d=>?f N}-sr1\11`٫pY:;رڣGNޫkC:Iv-o}Yq MY7gk&D 'eBgG/&?&n  QUA*➺VJBV_$rfx0\|S  u PFREe.[z|nŃaJ[QȀ:  +^5;{Lhx1F.\WXUJ۴ߛ6UܢnoI5׈l&n+7,ͽI?­}{36*ȪXB)~H7+z-goo% n~EsZy$ڵSf6(j_'r`^՘ X@֖1`7&:au H*l;eu rׁ}NAD ߬?,oa2[$AU%p*_^!Ckmߴ@!};#Ѷ1g9̮aPD^aEցpZMCgA:uiiEZ9y0VBVPϻ:ͯ XA-_;Ifbh\Ƥ*807- [;KSSO3k[M}ZSQ1;>4{ҲB,/fvL@/zxG"[ I)ӻ|lvxw>J,GXFB?J ‡%;[SWw;`3_5=qz[%00 }iU]n+JUi[(v+`~9]kre Wʪ נʛx%[H(l=N.b bZ3X6`rt?XE-`5]&#_f>3,b43>z,p1ݤzGТ+'d!s-5+\:j8/:޴$kZ'ݠ_ySo&իԪ5KʗnH`1DiP|,#㜖X/}uI6KFDR>V5V:Y_dyzx*څ`".y|u_mI-l{Goœ1R3^ B." >,յx k}-ܛy ߧ*mL`hȟǙ+]YC =CA9^ZɏjqgZyvA7ҊmB鷈>#Æb%Ԃ]SRoZ{BH!]7?ҍ C0 6WX֙Ӓѭ3IRhE8&EN~,hIĄ1fɜ t%{; XN5 nmeו}ز9$mQI_CaJkNccdG hyޠH=t?K5TJ+M ͦ=Ô_bv ]'[ISѵeAF%~N75cT w@5Í`Ȥ䫤\'=P\=bfrbSzre,x 4[J:ّ"q&C &]O!ܶ%g626ʎg⊏>.=*xͲ^8\m8,@^1ӟOKzu$'h"eЧYJyˊ..>Dɿ]ɝbr7ı(t4;$sV lB~.ehMӕ{SեtQz|<x$;AsF:3? c A_ lLB_*Z;IcŌsa*]?z3%34?)[?9"gv S| ֠@N=F̎p:Wb6b2ƪL;7_HʊFLr7ԥ9VU< +=@_c#w@mW}+ mL'`HN+Q eJMԈfpxARۙle)k sd0Pٍݱ;~?\|ǔњevOC,6Sq]= N TUIZ5dq~Q&@&͔ XPg`nOYH Rx V! &XPjrɖi=Mo>kt1Xˍ+4}ZQK\뵭T =ȵQBE,/ϳP`4HZIn}N]|&]M*L$?'Aުn;M'k>۸f`ޛ0XhLа .!]ڑ-oÒ_DQ4E_tθJ b5 ~- ŨRk>%R<^fR\b!5SE `Wǜ$ȳ#yҜdc4RIA!9c/wОZҨ#,zQX5QV 'P>s.Sv[X̟@Q|eIW@ߵ`j$ky9- 9W9C[!S՜q\kzWW?EyA!U~£紿 DtN1AeV]J|M02Z9ce~rº%̐p(my3[U4eʇi;-30l ϓ X>-9Θ2ebGyIVlpp5ϹulQ}w(~OHHa R"5;"eiV?9CC 0ɺk3ugJ^d:C5Nx. Pa%ެY k?dI"f6J"saT%)kn@, ɬf;~%HU AW,6 TnOe8 @4&&kɮ\qh8q=˺A>n(0ѼhC]0mf*-*$ dؐX|qrӅuJ=)DZLT&H?j>gkɏKĎeWl%L多LїVy/ĤZ.CD%.NPE8n :m-rvU>^=KH@O)pW(\~IJ;pr^a~Sntc ss ߡOI;;EO%LGw?^ݥqFqfKJ)#%(>+ a7q~!^PT~N.]E7)p|繺gZ)k^!:.[s{&YB>ͽpRZ:FMr֊h7w3Ka_-[X z`Ւ$TwTtaDE熠!+9no#-,yEkwBP;)^bcjTFՉ8|%&дڽVqᱴ7ƑKEsXhJ|-]ODnkhF/2Gt s2 m3|s Cäc=7+D/Zozs+&4BJ.`]Q 7xF+3]n4{䶲gPKOY4}teqFD' Vk';8a["zAR!OߋK] $Y?ԊǤz >iwiה@!y4FZG F'MuGɾk#[ڍ]E24hh/u猎]<2`SKIP+$FX ǘfTbf[|'rP-NgnUe&3BJQ Qh#{? Ym=#E>R|KkGGq}RjঃF6BD?;e|цjPu''kcε$k,Tv}uνYNtZ]EeSmsyKT MkxPe8|+ϙu_O53Hp`9CA<\V!ⵣ>'vz"#- ~veH,4nHY՜? gIEd *nlX&$S4VO13}(-Dͮܚ;oɤpڂ C"aO6]Z+>`VNQ@SO̒ΆXW_ܕqB|V/ `F¸W'k 1,>gMQTBB&umPpK5gXa s^q^)ڿki%'za՞Ӊo"g3{fp:K\^Kf]yOkBMU6,MQ0н:b9\_s5anU ވděYC˙B{+V&>lACr&ٖ5jd!XD'YURee ɳVko?6 `TqK_萓RP܋LV( y[}(E函8J\)9}C@e"$!kPh'ThеY5b3ve8B ev tv wY|ŶWI>UBU_~qe;* R?Nz'D'KEbz^Ar0.@0vY;-L(֩2ij~ko V6Z_9h%&kG@Ē],j_PrT9)TUC"Y$-e`{e,kR "/iv`= 1v"GGʓ(ּ"i+&=*J3_cZgGX3 TL*o{vdeeHQ QgRL:I 5t7g2T0SQLn?8$ΖQ-LnܽWZC eDP$՚iWIwK$|M| =[٤6簇9G"k{x;>ZY>fm,9}r9#u2䷽*Wo Y,.&IZ%L4Q܄!LX̬0NK^s Z*F&%fttKU2d|2_5[1D*|ak|';!T"c6 [E#^4R];I婧ΐ3h"y_YloE4+R KzjF{k~v֋li l[71Vw-E2m/j_0Y>zSӃO(y&S ([= d]LiQvЇF9mN BP6Yqh.bRrăޫZ3MI2%.ɱ&)T%e<@7= oAmS0/RλJe8fld&>fL,Qk>O=pgcM?,/u}X,B `=uQ\\ 똦XSg4Nծ&Ll&ᑽJ\gyk 6red} q#{] !XhqG÷Hzj1q~ԍ<@I5cט  O7hw.'A@1smU{便تjv z5_QȚhϗL4 ׆& f7;A*K6m] ,YdE4]xE͹Ae_YA.N`Tu7 ӶCiRyٮf}-ʧhzu^x4PC-Dڇ5yʇr(g=ŵ. eWT_ƯNݗTaB2Ѳm-9}5 F$ăozՂuWC_0 !)wUI W35W)sY߹3?`IPq鶛¬zg4KVnV=CP伐1Uv>!R r/a1OO>\Rv+؍\mlU.` Ѩ]=0B#O٣*Lp7^`q3| cD)](Cy/OF*Dg;2 PwaD<9j0G,|>dg>> `mW/ie^N6ă]uAM"3S]dGrY1Gh.I5gUK%hcx5RiCIX=axt_b7Y tNCrӄ*:.7y+ - /@M OoJ *5PzKȤLS !SC40o~D(UJJhse![mk>/XjKF@N>ϯ~ZMvjߵ'J3I@Vi=9?gLYvRvpN\ۖ u0q@pb'`񢚦%N$^Bs KUǵM|_HG|PهSď0)uouUi%^3"j3S5v߲"xї#/`'K1H_XQL2UVBS'T()YX?_eh^G?tw z1U][&mvC.!j1\S?}6R@H.M:BHC֒1V[k%B%% Nݖ}_`u~taƯY{LqTA$Eo1ҫvδ1@Yz$+uJ͠!3 tET~_cSKDYSJK+) FA` iE}RP+[!ZJN5{p\;W{.;"˶9ZY Yc;QPE^$n54̋;t|^II2`yIڟ%3W g3^y,;,a!k:Dh{qךf9xEC|'gCOmKzqnd/0|2W˥rs@tݿW.4u+],lzmvΊُK1YJ)c7V𽆍y@5f4"7 ۞U2o=e֎Xw{;Q kYJ01*310Ձe-ǂXgn+x盬:/\܉7Di_Ny!){N3?a5UH.M=+!0/Q HcwN;to<6֔'8 @n8[`TYɭ@c.{)Pv| >c@(3 V4%'$7_2,WkEFl|@aؤ/ñTg/u.kd*r)Gŭn iwgyv|?آNx98WbrzGM6"gUVx (3i!(@8ug@C wK+j߁ ГE/~KpҮ{ހpE$gt=%*u$cq1zmxnpS>y) Vk">(Gf@E`/M69deX#Wh~Bo_3nvCMD,s[|S*5Q~U H.[&}C"PDӤ,&HR] 3:z_Ҝ=[]|^{{rDS̬Nd7Mހt!T}!E)WwUYioC]57 OB>t=Hhኼi&͙\Ȁx!^.{󄜱_r"Ad>4y Sҧ_$fǎW!I'7OVN4KsbE ;WFB$DCzE~~Q|U #y?FI˕m\Wƭ߽%[\})tWKLRwM(^%2*#43/ i-ԇHܔIWz.r,T@-O\qOca1͖6Uce֫WqeuilĞ<E[҅0?ʛ>_U,ImBw:EҸVJJԔ ( \ =q﨓@;~M.0 TGy[fd;Vr"Y "˴s'v[HўpǞ5, jB6-ʅ^c(۔՝|jB!>Q^2p( Wb ųgyH?ʕp*ih,ЛMȭi!Ol͵_pc+U"G94C$ȨvhVKyW~B QrOVJL4<3Aw Lz"Xe l" [L|+NY rYDP^~[ >k !yAI4G۸hjx,p0 7ލQbOmOq,F^b.?2d̰t#'Z-=aR`84nW2D ޹mXU9'I) /K|Q㍧d-H f(7R-tBzQýp}E K=MoKJjo#YXۨ}E7`Y.tv-* ӸK)L' j0y= ʹʱg5DG\[a`^;m+>:\uU:7cyl*ofUܢN(5r1r8s93|z,1gPFhT /)_E DqkLCzB LLp3 (D̻?0( #ȢM"*$“0רd B*.de11ܮEvarA8+]]!(mǓf0ŢߝY )5ݕU[B1}U):RI '>R n/R/[DbaWPY,;1&&{Xz--sYNc 3d,-" Kvd/"B h6:NS.[@j}hxuVWi:M85#9Wv GU]@kȜ7,V}&mN4HKHniT `)c|eBPV{{1I4 -߈?+RPNR|P]#05vk@u㊼!Iz70ϐRH$ȵs6R=Q;= RaR܊9:SM] , pY5I%24q+ ]F50l:ivi8FkF d!Xޛ,f?JOݼkmH5)*"ĽͻfkUЦ&QJfp5Y\x8AM Plag+O5{fĈdyXJtI)6P K {/ M5v.|@xF[^Tz C8"W:rn*Reh{eD 홽m[rMH7P>rkxgy…CdnRR vG8L:ZiJi] L}%O$d9sTbw]K~ ft E&]RΠR}I%yKF {4@P'7ī\S7J8]74@[`~߉:h^{BPy}C.R oh]GZ5+ZmPY@9x\:ϔMcdLEQ_q ZQ V`؟R8t°= G9Mv+k\K!Pu/sݚ&K-f1{(7$D5$0'p %7 T# pP"7J}XaTس`.@n>cJ!I[|p{'&j͂&'6$iy^Gx+fM  1zliaFT5ճLLϬW<ܢ¤&s"x-/3Kױ3ޟy&]՟ [q<]E~ 0-9r[oK]Fˎj1՞ ׫wRoKX4ήqalͽRDj|یSR7`p&tA23XTpG&{.Dpĭ]N|& 0p.m?Y Ǚ5- ZW; HRǪPD;1ycPD\@([ S@k7X埽5CD]8$ n5:Q9Lڎ˔Jx#cP8:H;<䷠"ފˢ,}#khBYP假Pу`9 fRh=ܔqcJ[,@,Ƒ~q'Ԥ+_a30sk(ad6j2^PBQwݦ Pw8ӨZoD:jwyoː#"W$/lpM?KV"9ڗGOd%XZǐU Fx75BBm9 ,r .qYFwk8&G#RDD W!:-d569Pdgm#~@7)oEhkUvX=8>`ʁ2N&o- {8l" d bp6Ӫԫ@#WX^#gRPAG9ܹ'֪]9RoJ9.'MN72Na  (o'JF6]1ݱ @~ ?"`[)4݊CkREZt+<WڏJ@j1wBkQ)s- l4`F7:jS!RYrsNke{ GϭO ĵD>\KqRqqO^a/k~U|9[y:72~TJ+Q6CQ|vKƬ,UeW6捛WPTj'l 8F3,6gIW7<<a]Rz*)Wv.C-!68b*^EIfGP/ 7vϴ֚Ǣ~:5ʑ+qres2ֶC܌b/H(j])u6"L<}%AI V:LTgfHoR|@mōîj*[+?)52_ˡcC|Yid8K/[.W:hQ,hS+bD&\m1@BczV]w *_.$X!Hrh /_LUE OξT")˻4S7(dͺz}x-i#&K?RC~! ػW@%ՔTMmT<l;T[g擏#qSn^COupjfW)EW75gԱ`KPlW>7=K D\w!˽^ XZ핕QxnoE;Mls3l΂}&ĀΌVRt@7@bZq2]әV*G}1a,$YVĄaT.Y1ذA:NU 亄"&k#` ":Gs5%6 㴢 jƚ&;aY&9vH#PyYH)A4'+j o, _q`N2'N1|z=?z'M*u毞͕9;x]A·'{-Q*T8p"o:DTh6'ᄉ+ٿ<ͮ;h@.B]nIw xBlK⃯oΐuy.WZ g(FTIͷhѕwyxO]{+%\hyw;gh2g*A 9X\`Y3HC3 5O-h!55dTye%ƒN5l@x|~Koq =\;x4pe8ǣm>^$gUBI%4XosePC.SDHQ_EG@^ُzX4ʧtnҏ_ypaミ>;/Gohfi;gQʢi@׷N}*Ӑ7\csfCk_GܰF'X2v}- *uVT8\|mB֮]U>ƢҬ3ѥxKsd# 1̯դK %OsVs(L .56Kkw_4|̓ASgj WG\j Ӂ꩸ڄjCL LwMf8E92p$:͂-/,ܭK' #`<8:"6?9aj\0coXORh ?G{==s2qf^x{jBڰѰkF6{}y@. tm }u9ȔJFP?4;WEՒTWiKd]<͕g =p!Wۯ<Aņ TJnea46yA=1whؠwP|HձmPw0!o.'!UwŠnr h>Qr6b? <~ĵ+yίV5 ʺz|߃bpV"{S-r zIv}L3΄B 0=-ᘦ>ʪۆvhLw@#J6us"""`c5{-`;7e!Iȴ |ho01<|.0i4# ?l) TJ^|p, '/(Pqp[N/?ȜpAX4݄/K{qIG+~iOKLbn;9g/_3Q)9 LШ Id0;%_W JǪjA3,^E[܉\J#R h>J Pj"%H&-tJ!cIJlԬY~I%5&lc] %{OptUGuQ[+3v|yOăs3Xol+ԡB Q`PeB' Ĩ#[X"f`ҡ] c󛙫0˅y4M[@;e*-yD0pVrdV#^(VF ;I{A׀*Me,C 6bf>\.ɗVB?t%]ރ&P[i[]X z'C|#YARQc ?εo xhKܖh_8%X5P{X4_ݰrTVd|% !3H8}Gg.qj>tg9d_u"0;9}gE꿄+."5+w[#.N\D L&T);Wb`57s%/UeDVI؀r83T\ub il<}~ wq@q];!pKz HTԧ5dqѓY6N+Usf(kOi&:)PY ORv|iνT"30d`/Yόߕdj>e֢ohpheKT?[m.H=B}*>(2CMmi (Ԇ WP{BGx=,X.3u=!9?qA3 %唫} 6,%et(ți5sc{,Thxf9RΖI{c$흜@*5/S P?eb(h\iR`֥Ȭv"'ꆣyWvr@{2j_I` 1Ɨ[(fmV=$bb XȿN,*츧 yVF^Qy-3@b`η+kBg{Խr.YƓK[z(ANZ3<(˄Bc*6rSp乖 'Ua!yi=(PP."%Fs/@h+#{ȃYkw'hya>!NY%* N%-5&ܣ%c/%5pdhhRpb|E">]G\pLAr1dq"bF!ӒIEo5n͈^4k^7h`j;T|M9YYkJqIt5.J%Ek|FFor zOni ُmOZݷGG;S2dRGѫGF~}&Sgڿ3qB|dTqG`ŠΔ !恸O讅)BYf Ly aWMOEܦS.|9t e~-76002fj陓[ )tPg6idEK>w?E]̖ FDX*Zq$YAt k;,E MaW@nyy><9)/]W鬬Tl0" KYDWwRrx_ÀKn74Zp44~8Ѱm:!/76>3|۾T=Kނ@47*fVAgp w֜>ޘ2xinF!?+#[*z0~C\a .("8_LY_3*wփhJE^t@_Ʉs]ggd,{^@S_Zgft<#IVJ37mGe6/>/VO)Nal`Zx$/gL~,_PPOdRYY3w4Cp\N\[ zUz˃FU{4 $Q/kuqaAp0 "t_#2q/r{<^K)ގ9aн;-q#BC)+{OCP00]7ήrJpQ?Qi=h$teS+7Qn*cTDNJw?Tˣ8n:N)>m"%ymG ̗&^J?j{{59O Imك&u ,Ӂ$sLT߲׉~@5zr@; BꂈD1W<~;bz7BN-PGm=YY&]ʃ;*O>}Pd8Li~5$ qfpYX 0aOق-jϩob6<5G-FuCS],l榏u 3DΎE 7h۸7cs Ϭr-"e\(voLڇʧxvm}@Yڟ엝6]ZhHL qjG4 tٷꃑtdoUɷf!͞30(uEDz'nuAaoƦw#MA3Ǘ?>jmwib=.&lm$SZg@H(.qMeR4zsa_CGeވR5&L`q$9Kfi~[JZ bMZt% `>V-ԁb}cp+%-|A UWF/2i9 ?yʕzX|P>9@9EH-pf4DL_}L.Նܝ(ۖXѓ*|ēWA'ڿ]vb2]Ux7.cJ^˜38YINP0qkD"n3CAt1JUAW G]hoZtlH|Z [a>ǩYn_YԢh L&K/J6SmGT sӥRCZ䈁>#9~|!\G[Ϊpw GO0\< E\T+B9?‹ŽEİ,wp]Buq c䳄 gA=+U.+w8ˊj_"ܕ [@zK.>H$Xk>6c5g*dYG7}GQ&/`)oMɽA#,6.BѺ5O2UIX#~ɸlץݪooWƚ|ڞMG{fMLS:))'Jݼ3;Jvf~_;!dPQp^rV.):Y5_Ӈ~1n IqďIꧧlo1Mr_5n}FuVciߟDX)Q&f/0+z.6GF)xx*[蔾~>R\7 o(~ in[O"zZYjEXOVtehF<8ŵEzqJɘ?M5,겑 oB_( 3u$k5NTRauZ1oJ73. Vx4O~C߈\jspd 9bjO p)00BysN#d%Xb%67jߵ=:]m|gKXr@:* nHbР%!IIbRC.v)3IC~zw9xӲWa၈X)d>+F%dqdr3~L*MY/G)S`h8P`ZڌPYxVK]u2tҼ[&{=ﷇVI#m!YN˘z! qDU?̦N +ez&:.uf ujp0w fs3GɇO`(ʋ!L!x ?_3C40N8mI~RgݎLޤÉj7kP)ڳ4ZXFK ߐ6*QN7%_-ۭL6'O7K: lu6mA,CyL J]X:۝MAV&*?b(/Ks@$Ʀl'AS3Kd}T8Gm8SBֽq,!!!fÆ%,"*\lvzU7X9̄Kv3 ڋ;&V~?PNm$K(y6 mc:Q J '˵l1YiC |0ir;M7'p=0DbS;ܺ)O1.BVy.hu>hz.Z0=FkWc%{¿F#4oGH#I <"FFmtAJx<_,?:! Ln$mğsѮk7p1@+RM 73삆Φ@W 'H-,zyޱC 퓓xӤ̧Z.nKwcxl<,x]a@abw&t\VFJ7wyT‘Ñ&0@qZl;-4AJwqO4 !],߱e:E>~ILv|[*`W+)%K7=鳎J4ÜuyHCȲtI$?ra>W'-Qþ*؇D(f""E[9Z/†zExBM,~Uc)0[ jA2#8r"HbA_㠆G:NN4 ?cö#nqpIRr"<8Q|;UC ~C$D@ JN͎7?LӉE ?6'q>wk zqBr*DW49S+m!BM~b[MIj䈺mIxǭuKvq 3L&7fyP؇ pѹC) eW,'KGaU_{P,>DyX+y)?(\0z_Z4? nuZbcݲb*Go*.PDYmfe\$CƟM'9m@ּjI$i؃*>Qv{: pvF0$PP,;xg2 >l B.T@)rcO'jk{Y˃/yқѫ7;V^hͳ$doT $)wX>B5űbc3 * kX5h+"`@=B;:<=4Q!LUmᖊ l}kF79*lDXH2k @pV+W4+u瞾d!qb8֬QF|6~Gp΃&%ؾ̀^ $H@xQ'@' ١V6WӖ0ƴ7ؐɇJ3P1Wͧifxf}oyMW ߃oUp枈S/%=tr:҄ sߒ̍Ĺ;g` /ς;,mYS(~.qU|Yj&r2b!~[3œulO~#ڿݸ{ڬ?ҫ ]d$&M1Dݼ~#K,#ϝdh2jBlV"h/_eF~. AU{!8rj nO,eH9L"7kZe/:/Ÿ |nq$LlnTy9xҨ&ͽ6qN-X&/MoX8!UL;FE'N'wI뎖ֺy}dJ F½S>Fz42ȯc[E_1iLzmKQ( ]$"D-xy&6[x.=uF-g*owt.~, VmFv8қr}6)ʡ-^Ne x q&)$Upai>͇NīJO|Jfmzx!}pƻͺ@[Bfl YIG2V!M\UBpĹ|"T::ߘVPfCtrꒊl8]a=z|ꋊ1 凌[shmY(m}]ugK3!3hh*JI1x~\EB݅gln&yei9[-(Qdž߀^=H) *Y ,gN[FEOӘ;,&oKYEUD:8.XQs@Qpj_ho_HT؆!5'}DnLG֧p- *U *=lwDqwpվxB(%7% 0-#G!q WDbTe8~F.;j2AyGJ; u!~ ΐd9 $AVEuj *> BYc) 2aM󮊜bj"Y~U}s %j;):)]<#?s^CIFN&s!Bu5[G IMÝ,y,BjGgϮs8ЄfCLtI163P: 9 rF"z+8.M-wGJ)´\D1,MXJ< TQ*$Qp?1okBMx/. [0)m=Oy l{,3Ѹ: # K5b`)+m4L$Df7Pf@@>ߑZ2([w1a2]ߖxm衬S oQ֘cX)n~ւ IOpw|=V-,Gc`3)]]X[W m,H!z[ z5Wr[{~; ƬRFڎ 2T@<.C2d!$އScTK9Tޘz 3>We)6 ~A܇(AV-nyD ޺+ ;]duqHy^\L^_44},<δtȹk?B@#\/wP)+!P{kL#Oq߫K-T0hWAh p*F'\WJ̴"b]Vf!;Ej3\8g~VaYr } A3hS>MrZ-S^0 P+z?>-AUS[,Q ~w-M'uPB2ǟA'%?S):Fdq4cyv| yEZ! [MG[zt7mר* d,: i$9Xu-Y|uu@TL[Dc\-(:SJT}M :iqZUmM0w(Ke,"?Rchd>Ϣ>e6{[Rfu5}iD:P\"X"M]pJ  fK5[Fw:`T[}HD8W#ߣh Y3ځ \/=REPI1jw~l=-k{MFKMH5.9gBa2m&QOխںN-.*|ZJz5kmawV> 1V-«) }!1?vKtjU͚M*Kkva=̴s9ib3L58a`&Zp j(\m ӄs?'Ϫq^Nc`3u6N̓CՌO:e/TcC4Y!@ ]uG.8IAM0(wlƪQc; M.YԂ@6bL{hsovŘȾǞnx Le<Gkd#qqw r-1c=$ѵtRiri?ߣ=Lɒǫn`e1 CȲrP&^03RfmqO'NsO!Y# ¹U}xN3:_Əsa)z6j,w5 Wa# eClb#<^fmc/pxbZzw{=: #"h4o(xtk1 ^NĖ⒖]ӿiXJ*wn6`/ ނs(;l@3 )5oO}B >OZyO71Sޠ0קٲ$jo Oṳ"!SD ԍy3LFM/Ge70nPVO"f6siz;ȝ5\/o&*ót+)/8VXbI_h-埊gQ" 5O8WYDaICO?߉|mShc?j>T I!| ̹>W&ǔFNG nDIeV'z$xVi2d F.ɳ)(ބ3OKqc2jd6T3p-Zug+Z ۑ֨ՉϥIߚzȰROt? ?2T);Bclߢ8l-/:ȃYŘ_8x4I+wA4hޯ4$SB ŘO>)"0Jn*Ly1N~[|G@n]Lɲ>L<)IЬV7?ZY0c5s"S̔2v,3J+թ0nPPxQ),QhoU>)Afr.oZKo=+|5QW'*BK4,/mlւӷNsYL(íL}E>5V|TǬy`Doe0@p0hӞ&Ya#N/Mo"tJZE lv&8ÓV~qD |Wd?.x<]nC'ھqUn{Vz'``{vpaj|*ӂ1)( n%:.JRtd]7rN"#L8_7`,y-dR\P1%l.Œ!v}~z-LJ񵏌;G!8Xeem:E_t(2Ǐqz=%~ID 3|\}~?τDtY0{" 7{c,~u\rNV|}{K5-"eV[i"?:-g VW^~_s]C4WГ?8nϟ4NRЧx,.^ .V4=]\qmtR=C[]azeP+.I?k# w6~*D?N- XW=D[yMXvsTHdk^OMJ3 _vae@)wR:!# *"GIF.#Ȝ+qu1>K}pMeMQChڿYyQěԪkЄ/ dxa=IҔ[t^ Ɣ*Sgy=^bةarUzh&9\{qj"QqrsYQ?^2ʌA}'Mo:)}1Y'鄯ًًRb9ؓ}hJR4s\D *0a}iOhGWϣb{Ź׭Eͥ? TS~KlLL;lvЋd2,K#\oL Gu#KAC2gJG[.,\8NH[L$CBzpb>0Kc-5kEA8[t&Y-W*SOPp#oN;㞄L5|{*7";u)c W@ +y>LtNɟ#35Q,s$+ћ]%^y yoR9!;6Kۺ[햓:z1Wؐ\*NQ`QQORܳ=>i )=2`+M/L{ taّ/rqUu F7OΉUI%tpw0zZℓ4JN( ʉ8m/ O S8B^FE#POuprDz2iaԧ3{S4M P0,Kc|o?κyHk2tJz@=37]M E4u ܵY<ϔhDRpzռ5s>|g-io!\C_ LC^@gϨ7[S<0:-d>_UQ٫MP|DgqyD"x_J\X  o 4.jº|@:DW(=wk2J%SwDlt"mE=IEjH$Q$ Ȫ0eP`-\!P7Oʂ]0+Ot4U5xQJ5vHhת^'e $ 8aB <נ#C ;Aȗ:m'-Ja}ZanTBIQ*ft F-<+x^+m^1o 9)kX|f1] /vb&.Űle(ql"%o`4%aOrbn3 _6Vՙlx ] .{H{:}(!'ɭ"]M NÝM>)x_ħPĽ Eti<ᲘCtA[W[vnB -^.֊JB.Z[qq|!,޲%NWgRi|L&zC:ΐ_]6%2˼@=pYB6.!8͖CJ3N|_P[VsD*`8iz ҧLȔŐ. .3ەէB:VՌBY䑢0>nkD&TLqW^IL"ڪqȖa;z~TV72C 8Ot*@:6)[u9N7R7s8w,gmKEzv]m_0^ۈH ovP%8<=eЂ3ȥ@čI<n3 НrcYeIiLZľXX@ |[F2\׍ b~\@,<1JNnaY3= ,eSwƶS~zRru(\~ݨ,,){5J) ^V5>Ƚhu[\9|DQ[M™M:1܋9RhJÑݚeVxR6#5mφHրsF_J!";!TmV?{usu9 8ny9[/ ndnM<vEZ;5)'j.V`͹VWk|Cnȕ lS7Af' I0䲥*o9KFz˸ ՀhkY0M7A.f}H?|*%uyeV/}f+:̥DQS}rgC"nGk:NT@3 M ˅{2W` 2&o tyw?]Iϋn(}4ѿ+Hb>薖r?֕"s -[H1LV{imHM_l|:hu%{O)zSoRR,e+g̦+!zRbDe2)3/ܿ7 ߸$5TfJKVV_ t"In #d- c>b4faj |#{&. #n B ڛՕ6=eP)R6 eL/9+>*(of$l2ߠ!pk 9 cŦjC+IA.ZRODt74yNjϱxR`si 4OM4h#c&zi8o]ap}b f:i-|@72̼BzƱ!|poxnjZtKŦb򵫄3C,%-jD_$W#@nh],Q`%`_ зX0JO8sEQӝaw94YHz# ;JSTiK.P\_Kl*|2FzrxWo^2'ߨ%P/q>ځ ]ËK>J&p߇fTIRJ Rע,MDVo`ńuLs<# bC͋`ĭ}}~MҟN4yg9HS{ :h隫]T,l p;\E} ʼn m]϶9"/OE#ply d|ҕuYg^FRױe&eWzwm2}(GLuC7NSPQT|c_J6kIA{ zjd]4Y! _%*@  Bƕk[}o[:<}*< +`md{6d^+-ޛtG;ddNX/$A;\Mg$x n O%ԉjd`8CH|:" dkf(zUU`pzPɺ|ͮbi/)C|b y٥ {Z}R?YkVOz&!_&_Ÿ>;_K]aB<Z-C^,)޼jE 30IJc̤\0͉Jr H7d}d _a*>k GJӰkF1%AF ` ,S3̢G1+HqV9Vd/^ت~m '7VNSNݢF٤>[qϒ䮈~yT!i"} azy$'ff[n1eqNC:y) rxiEhC8qKSJe4gE_Da:03mrIff74#ta@ FOzsL~,&)I)T6)/ 6OPCvbDyD6g6)%tDU~ah\`VY,ñ^3'k#TfJgɄ/E#K}2shcu)d>= xVJ@ *\ OZu'}0؉hxu`-ϔدg~=f`='.cG$ B ͦej/WִUaFH,(TזN[H[:@`T.q~kA!s-tZY\_wi[\j˾fG1SBVڶ,_~`(C|u@DFeBxX^ j_}c%WyhF p9syZ%ZS;Q`檲Ko6xR$Cwh/adl.W|6`ʺ!R`A}ЭgN }XPsoqC)1x.-VT(jJDR&o%XF6Zʜ˅?bS@-߾JZҿ wF?ǶhZTMK1xpckBfLj]a".F?ys=(^Nh\Ģd}[>-WT *#榋 ` +Բl!pXkl ;HI?2ҭ i\ZC"a8z<@D5׎F ` Z s ws'I}*>."0bY(gVeCϓk*# f 2#꩞V )Cڰ[q٬74eˆLD{Su"vWn2ٕ!5͂9F ۷v Bҏ$瘑`dnԎGO{u ^*#(#}22D fDB3bhS%N>7r7_x|b4MQ Hq+2YtB:Y ] [Wz_!CL\ 9Q̊Nh'L< x XZ/׳σ Rfd儏aE21OOfj#0y_g~1d kXFrZ (%O{&5_HSTz.H<01퓰 btWlX=LH$_jpױOq[Sm]0?D tpwdTeQy+1\F_Gn[ eiX&KjŽL9¯ F>nɆ&~"1yXΞDFcreA!HxXFOw ɟqNKM(u͗?n9TA _ɖA{$Dt5Cqr ,oц3Oy ~0zXp.鸂%g[U2ky5D>A$8dp47F(eP3 6J/q;*8I+<{X۟crCn$t,4av= b}y@3-xҬTsTj4xjܮkTLKPs!rh,U1B[~T^o6eY,Qb?]2yʸ xk-'|/RWӡ(1KJ._j'q2'"pxg &x449iKct#LhXU ~;,>FfPbi̮R&-]|a? C7Ȏ 8@?5'?.Y؅b_$^[H}E}n[O;F2Iq'C7~α6N!JP`I8骱Hpk4#Ij^g!ñKV3A%ӗVAVͿn߳ˑn:ŝZ ;9#xbj~BiIFs*. PcDfLoa4T8'*'M""sK`ˊ{3*mй«d[K,?gFT|/2Dݨ-z [ϯෟK|^ISUx 4lBUt٦>feeu0KpgSUP;?&C*njvnHudr !d)vPy1V++=ҢR|=Y ÂM6G^ 7{ @eDόtw|l% Oӡnegu:Ko' 8MDQ_Ac7KfKm6-tׁΣ [Em69`Q0o_XI^ޛj49e_7+W9M^bm 26@(m #Ǩ`(hZ'=쁱OnԏtȌnP΀ ΜX"3M/д da3w>M%{O_qwM" !#R3oRrSY4+9 ,Qsi WYTaϩle&O 1dMٌYgG>r3NV )۹X<!M;'m^FfԦz*O?(I7B%L! ea`kja 9֡'QuY Y G efЌ/(Gi L "#T.<3d0 :C c~0 Z=V"퉳{+.cB=o YdG)8 @(YVQ[tr/(F)"5Q7&4ᢥsÏjʋ4bKj텶7_OdCqGR(R:vR?V(ԍ\Y}.G`-^M6QIl -s{0<\#* m\?-_2UXa_c顚tu9.Xa84D[flD@ཙ5G2(&0ų!z6B9;tEYj'p7VO %W|B7QQ|4` 6ZiDNٱaEp *~uq Jr7- h/˯/#!޶#("w''afLAhKվr}HPzj$/HUQKM%ȾEc(z pu?Ð tڃOP?sf%]5~d(BLE=*lCIAs5_SK& ".2޻UG$(c!u{lpN%txvX^fvB0RXaVwWc\^2 Rǚ3?~0`tYJɜvMUe.`r†o@V^BӤAQɸ=f.-BƭJOXΜv/ ߷WI4xHɕ&!%Oqg+ͫ Q!Q b_b[WxŽy/OlaZ8ST}bFzŮCzI |yL g3$84"i2Y!.k&F m)MYy` PuKB ˑ\t0L[¡?HՏuiYd`^ѪF+0:te*YK}srДЌP)#ԊՋ X-)n M5{Xټeh&~q9kIEMqI-ZpdN)WYܰ)!Ħ]<97]`P&&ˇOA`-~`ԏ 荋мy:6) `Z6[Gkq tU1 Af`Nv7R`t̰.,r;*)=,[=l7):0]5=< r'fڹ1 ?H=qdtQ{f=}-^䘾+3#TTJ4v"(8 Vn{dlWBE\P-ւ%`o,w Pjk:4xW;ސp:4>[GVU-. %q %$g&Åڊjyՙ(z6[@wv;xª0Pb(8K8^Qh- á:&3v֎dq o |.z_/&]k5wE=r:Υs ǜͶN=:c 4XY,\Qz 0dJT09HQe{n7+7SNI(!" xJәkJZ1Jp䗆ɑr^-x=pst ѮƠfzOhRM`bMsaeڀM݉BlO^s>Wum YKJUGrBX %xoK֪T/(BHt knza l,%ZSG`殨uDgVeyC#~V53^,a8ʨ. kN"aV)SqלGG<ƍH(2%h-2qZ'f"wbjr>N̵'hF_UXc QqeZ'DŽ\$%DP1IT.hfMS[c 5/)c5鶕M'QNe!tT7h5¬dƿ!xI"J=HSE,|FXt(6jꑕZ םG-]B{g;E%9XId."fF.SM753tG`مDrFhMTevKoErwRK2߯-F@"huG'J +n+e;&Lޒ5;C;Sq:DR ni~xf9AL:5ʿX<ѰLvJ3-iWßPAGdv8.૰<ҴH_tGǚgR(wy5e}`f"3~WD( I_H Ҏإ\rцDy5_~h)DiS4<#K`i~`''_z&.8zB^'bPM* v1*RFb:8UD1}v2cJFv:4e-dIc:8`o A@_|EX2{)-8lU>ͮnJk$4_7z{&BP;q\`%ypSLN^ߝ+`O҅ˎ|?#-H Il{okvi1m_o~UGE&Fހ"f se 5g?{| }{s8 ya wP݅~঩px 83&JxC0Mx6EN'+aGЋIy r,&׶z4c^1c E{3G/) 9q_H5)(u}C܆vR5x. ۈw3s=.o\٩ v@2x`uMVWwLbCgQ"F:_MaȀz2Hq_LWTz}BiJfvY)9x8aj)րvXҴ_'<жAeX0 I+8[Z]-󨾐25] ?  T"hYs#Efs'>asB Ykw}YѠzU;n#9֙Y˭6ܗrk15@x zVb:<[|pQc[iÈd95>H3deB/+hGoSm3r$?NA|ǍVhL>AT>Hml3&^~-rD?zF’ KjszS%cz& Rt@,I@rOU+Bw B\EF; D{cR.pC\"69NWY<E ]yP^rV(F T5,f~_^ZUm|=S򌍐q g\ 3 =n|F#MҪϾp6Ï>Gc@kp+8+wqsMHAVq?S(EtrQ|rBA3뎼`޵v# ,\J%nGqhbK*&ᶎ(xePr̦r+<{[˻z*0}[<\GTQnu8_٭8Z?v?y;3 Eo*$m{S1?FH*<[w':Tn;*ڥ}#0LFۊx# t",IՋS bBW)%IuoIJaW7d^/^Ś(ڍֈ0A7S)̶ YZ