From 89e60b8333bbdbee905178fb0d4afaba2d60297e Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Mon, 21 Feb 2011 02:36:56 +0000 Subject: [PATCH] update --- RELEASE-NOTES-BIND-9.8.html | 83 ++++++++++++++++++++++++++++-------- RELEASE-NOTES-BIND-9.8.pdf | Bin 52584 -> 56996 bytes RELEASE-NOTES-BIND-9.8.txt | 42 ++++++++++++++++-- 3 files changed, 105 insertions(+), 20 deletions(-) diff --git a/RELEASE-NOTES-BIND-9.8.html b/RELEASE-NOTES-BIND-9.8.html index 95b7bc01e6..a0fe61fc8c 100644 --- a/RELEASE-NOTES-BIND-9.8.html +++ b/RELEASE-NOTES-BIND-9.8.html @@ -2,10 +2,10 @@

-

Introduction

+

Introduction

- BIND 9.8.0rc1 is the first release candidate of BIND 9.8. + BIND 9.8.0 is the first production release of BIND 9.8.

This document summarizes changes from BIND 9.7 to BIND 9.8. @@ -14,7 +14,7 @@

-

Download

+

Download

The latest development versions of BIND 9 software can always be found @@ -26,7 +26,7 @@

-

Support

+

Support

Product support information is available on http://www.isc.org/services/support @@ -37,9 +37,9 @@

-

New Features

+

New Features

-

9.8.0

+

9.8.0

  • The ADB hash table stores informations about which authoritative @@ -108,13 +108,39 @@ DLZ correctly deals with NULL zone in a query. [RT 22795]
  • TSIG correctly deals with a NULL tkey->creator. [RT 22795]
-
+
  • +A new test has been added to check the apex NSEC3 records after DNSKEY +records have been added via dynamic update. [RT #23229] +
  • +

    +RTT banding (randomized server selection on queries) was introduced in +BIND releases in 2008, due to the Kaminsky cache poisoning bug. Instead +of always picking the authoritative server with the lowest RTT to the +caching resolver, all the authoritative servers within an RTT range were +randomly used by the recursive server. +

    +

    +While this did add an extra bit of randomness that an attacker had to +overcome to poison a recursive server's cache, it also impacts the +resolver's speed in answering end customer queries, since it's no +longer the fastest auth server that gets asked. This means that +performance optimizations, such using topologically close +authoritative servers, are rendered ineffective. +

    +

    +ISC has evaluated the amount of security added versus the performance +hit to end users and has decided that RTT banding is causing more harm +than good. Therefore, with this release, BIND is going back to the server +selection used prior to adding RTT banding. +[RT #23310] +

    +
  • -

    Feature Changes

    +

    Feature Changes

    -

    9.8.0

    +

    9.8.0

    • There is a new option in dig, +onesoa, that allows the final SOA record in an AXFR response to be suppressed. [RT #20929 @@ -132,17 +158,17 @@ will be silently set to 30.
    -

    Security Fixes

    +

    Security Fixes

    -

    9.8.0

    +

    9.8.0

    None.

    -

    Bug Fixes

    +

    Bug Fixes

    -

    9.8.0

    +

    9.8.0

    • BIND now builds with threads disabled in versions of NetBSD earlier @@ -218,14 +244,24 @@ per current Windows OS. [RT #22724]
    • Fixed GSS TSIG test problems for Solaris/MacOSX. [RT #22853]
    • - named failed to preserve the case of domain names in RDATA which is not compressible when writing master files. [RT #22863] -
    • +Prior to this fix, when named was was writing a zone to disk (as slave, +when resigning, etc.), it might not correctly preserve the case of domain +name labels within RDATA, if the RDATA was not compressible. The result is +that when reloading the zone from disk would, named could serve data +that did not match the RRSIG for that data, due to case mismatch. named +now correctly preserves case. After upgrading to fixed code, the +operator should either resign the data (on the master) or delete the +disk file on the slave and reload the zone. [RT #22863] +
    • The man page for dnssec-keyfromlabel incorrectly had "-U" rather than the correct option "-I". [RT #22887]
    • The "rndc" command usage statement was missing the "-b" option. [RT #22937]
    • +Fixed a possible deadlock due to zone re-signing. +[RT #22964] +
    • The TTL for DNS64 synthesized answers was not always set correctly. [RT #23034]
    • @@ -234,11 +270,24 @@ being signed and configured for dynamic updates. A bug in the ACL processing for "allow-update { none; };" resulted in a zone that is supposed to be static being treated as a dynamic zone. Thus, name would try to sign/re-sign that zone erroneously. [RT #23120] +
    • +When using auto-dnssec and updating DNSKEY records, named did correctly +update the zone. [RT #23232] +
    • +After a failed zone transfer of an RPZ (response policy zone), named +would respond with SERVFAIL for subsequent queries in the RPZ zone. +[RT #23246] +
    • +If a slave initiates a TSIG signed AXFR from the master and the master +fails to correctly TSIG sign the final message, the slave would be left +with the zone in an unclean state. named detected this error too late +and named would crash with an INSIST. The order dependancy has been +fixed. [RT #23254]
    -

    Known issues in this release

    +

    Known issues in this release

    • @@ -247,7 +296,7 @@ would try to sign/re-sign that zone erroneously. [RT #23120]

    -

    Thank You

    +

    Thank You

    Thank you to everyone who assisted us in making this release possible. diff --git a/RELEASE-NOTES-BIND-9.8.pdf b/RELEASE-NOTES-BIND-9.8.pdf index 15cb7658bedb12822cacfbfc36ec8b308f9920f3..ced7ae369ba95bacb0c79e0d190a0c8c2f0c171e 100644 GIT binary patch delta 32353 zcmZ^~V{|1@w=EdkwprncQ?YH^ww)8(u9y|0VpeS1wr#!oZr|IlUytrzdyT!u*!Z*N zoC_zJ;Kg0wb?y+rUpf~9_L;Z}rL!gb2ZG576R={IAaxb*=h5*c476}27Qaj1L>;kx zH9K42>75!Q9bLP6w!QSLu*NG3BVdHoaxG@93C*%ea@Cadol{KEs@G09{-SwUS1pPp znRCanevGq`P`uW^O&X`58bz>N0hE(4%MK`{amBo}AQEJN+&BQ7&lj=KAGuD?pmB5b zBDlv!R8q=8fH(mJamwNtGaioL$-(c=LKn6K<#HHMKwYN7bv8OjArs<>{UhFrO&nTq zYpAkoQ(?zWVsEV$)(A@47i1J#5`R1op7IF-O*J)+0B&X|Lr!Djl`iReUaTfuK4{_T z9vA(3bkADgIeNc(P86UrMgvb>G}p32HB>qzIc1epdXC^bo+vy!hk7~EdEyduI9w}R zo`QHRGq{S{8Y+_M`rL@M(l%FZ;%F5My>s z6&c9G+8}-n#i#ioERvJKRocKd z-|R-Tb~NrHptOYHtF5CmXi?+I_ZzS7TNZ}&55ci_Movl^qb zj@1rqAzRva*QvZB2Hk>Ul)ToZYePJ$i)v6SgP|htc3TBeR-b$EfLVBLLg~HaIPH^} z9`txUU(Y&!&db$28MK-U5E@rvXSO$`n{sSO`+;y~wdTGI55Dy`3nrJV>Ya!xY_rIP z?t1%-@p=hg^mm+ zf_Ba1mY6afDuEmygvRDOOxHcA;}uCv6G1puzEOJ#C(hH})Ol!p>Rb+aQWAX)Vv0OX zMeQux+et%dp)@+j;Y)?(M?PdDz2-ziqv(4GoL+YI|}~QJ&E{FUNB)%usF(fx!k6UTF!;IS)cYdTo&iCq5LUw@v<)OUfSo1T1Th5^koZtr;(1@a4~05>2my|NsqOyU#H0ClOfjdTub)t*WmAVYu}bR zXq8dimQj6e;gl3I?#n*jU`CT<+gxLj7i9W3qKF3WD(vs_(B!w~H~tcX1yD@$fNa=o z)|OP1<}Mq115Xb*HH&Gk7^cdgNphY>akGnKeU5hXwyOSv;g}4L=$H&%dND0ay`DFs z*WS+uo0mr>3CaKDi_76Ba6&h;Ew(yTZ$|SK za3`%W6hF*3tQ%#2eDm$27<|^4>vTwJ`8x_6l;{N&r#bMt(*~a*+*~ z;=%G8pPAf>U-jhE!)+Br*1Lk+kzE!C2jIFzuwiKJx`q5%Rt~9T{>idWQMb<lBU5&Xg{4up{@w929hHsq976VbuT ztzh?zD&*CpN|;D;SM{!=7q~jI3&VWNwb;_#)&-Q(+E5Yng1HdIT8i$=erP|&^x?QH z0blRAqXsnAFq@(_pv`$CnOS7&cUrC_{eydXR;Y<^wGa(2QGxdPCVh5DsYeDqvgphj zTDdh3GfP$ZsU@W#+HY_DB*!KFs_mhI7BS2=YQyES0VKhD5Zr27>}XHevuL(WBIi%# zQ_*+%X_lwKw0;bvy+p1)dh&K98nwTIYt)luQen2rYWP{^G^`~-P&6a+=V6eKFrXP- zWWE*@^xD)gRe_1r=9>9_asjA>q8H#qS|M;mU( z<9=2_Z((Y9TK*RKz7?ciC!pHPURDSW8f48?Q!*Y{aLE@0@qRTV+(vRdAWIN7sJ?Gp z)1>#)xbMLc`)XgqP9>T#+**QKk>7uF9T^A3I9`u-Du91@)mR#meIn^SmvT(U_#RDk zwW z=AOtJ`V$gYxziyUewvkz6XARd5Bc%K%PsmsdcnjD+bE@5dtg*U)|7GapZmPyU_acX z6xp?PMt}-c*!h?ann}kBOo-8c^hVZFP}KFki}d<8!qpwP@)WhRiVndls-J0|*eq(_ zP)txN%faTw&>Bu9vpo^Cc+BvH*-&HPZ}9TOw*;z$ULlWpVJ^t818V>hhCdiZaYDgr z)mip@yKqY&#FhKD#EfHBDe{G%n>L=R5ejI9e*b@KyYq&M6@#_2Y>^S2KmS)@nO2ecBvFG{?dFi)TVw6=yP+^IPs7P-8 z4*D=K3q?K#zXO3!!iF)Fk(uN)!lx{sS7aera@Y_=<_006Nf5-PcQ7t3csvuRyr>^Y z$H0LXY$<+YAOTrx2`HnisS zRJ`lj21z{ExNVC$7D{|W>a zghAog1887RZ)|+%-zRhh!u;^q90ONaf!`!UP33&=TY_8J-b>iAdKy7r)=80>1h%FM1a<3!S~y)SX_$bYuM<=}kjUk%QoxqP zm@n70Ok7v`LP7WzRCWo@x*7+pbPWyS=lAgYhA;Z47vTsqecy16+PI%wq(R8-Rl^!N z(@InV5?Zd0yB;qC6B%d*5vK*w;M-Vth9~E9N@o-aKONkTWA=`ak}pED2iIasJ1?wR zo0+-vi{N7_h$;AV14Y!x@KsPFI)Kg{w7)vp-xRcrZj2~$dZ?Xm`Fix07Mz0de&`$S zowqM`6?;R-21KnkahEOaM+cpKuW0?*Hi`|lAZ`Q&sJUg7=ex!_JY_3HIcUSFQOilV z*{#tDtd7_7ZbV;EX47@DKz@OfzOGyQOTm0Z_p(fLlo%1={1FoU6g}0PK>+43Rre6o znijuGi;r<)`l@EncDi=gp8YkvC4OF|wTzgeNU0?`5njtdvs|xqpDHt(T?s21-$qK% z$+5{B!YL2{uzXvHYeQf?1#+e>OG;YoUk2#ZVO*17et7y`_z}8XdZJ%xD_r z)QW~HuYS_~ag-?zU zHc4e#>t8WL(f8B&+6%iMy+r^E^Zrb<`%_ueDdL9S%G+U6oQHRxyC8CK=_G&meY=L`<%~z}lo@6P zWe9I+rv7!!<3w?P|F#GO^{vHoZ4kg$0>fryVP|Az1(2|^axk*8aQxTG!pfd}MZlQ6 zK)3?V#>$#pOT-Du$q3+NOFk#^fMfx%a{dqZ*-TzqwRKJi8!2bOSbrs-zI!O{{F%cJ7@dm^1EEjAMcyqzfj^p9ZYP&runewY%H=Zwgt9^Ck@>A ze;Sb^CQBOYifU}#?uej>8bk!U;b%qhC~I~65Ru*_8Q%=% zn8WuLTo`QObjahOw6?d~ZeDZc^>p*;Xz%Fq8Z44wFjsPdY^R@#m!HhXInNblH`~;> z%ZmK!LA`g8F#W~omaBKg?E%!k7-SZTuC0vH1&@Ka3bT0u!ZQ`|-8+?;xoJ@%tbBP`yaK`YO}s0xI(!$|5l zBS71txYE?d6n0uMF=Wu;mfZaX)nG^B1OFo;IVk%F(G5BOt^{u{GOuOb2X4U%GQa=i zl!k3%CG+Dw+XuM2e=zV0rYATmddEz0nTyC(j!jG2lg#Cye2SqBghrFbbMHQBLS0R^ zD@o4_viW<|R+$*Zbo^kJq>${%zb*z}&|(CV<7vfpZ#>&Lx4Wxr&1T)`+zN|HNJ>ODY99v;1XSGOm$U=y<#OU)P`{~D39|7{ePV+$H@f;-&t+em z#5=HaH4AvJWdTeJ?}tMebxuzvz3BSfoy5QTEX)FsIG^7o=lQ_aWR`3Jclm)kKTGq! zGTtM`ZRB!q9B$?c!I9;N{jwmrDv6I*_wTB0!VZoICP}e8V)lHD2yax5Liu*@z|xlt zWxUQIH=@(XQR26@{(54u$|y!~q?*t*6ArSTfE9Q7-vZ}FtQK40nfwAfiackfcrX0b zLV8OXAMN=)q~y0GI|murp=}zEcf4f9 zS87JHHozGZ69L3m4B6B|0xF&ADtq0}BqT4cCByT94l7$~u|bs-f*zy*rdD`^6U*b9 zay1b#RSbG@G{dUXr!^V~FShkwG{?y{b*J*m!YL2rNOD|m*_i3H))juOSZo4H=D9QP zojizy$=vaa2@yr46y&LdaO5#~8~HnJ{b;cHEMN}>roSLQrD$OW zz6hlXz|Vy@lBG!Bv2trAQc<-uJ4LdU^#VeWeq#!FsTNxacu?|+?TTW_4eFe6!?V{r zwT3|EgmVccJ6NlP$^Jkz)dE+TmE(@6L8lZcG8)rw6`>*S_lybW>Xq@!=mMm_hO(+R z13h|+am`3xi(>?eIOwlQJ0yUCaL`P_bfBAr9&VOmt8FE=P`eA>@||$>R4>?M77n87 zleVqRH+!}*R-k6qgE{prgu2T&BcM=YX(9z+ZZQY2i?QK-5!P^)!OGU*Z(pM<%pOay^|RGAkMfh&wGh*;1+7(&igE%w*(w4(B36GAMUvK4 z=MW0S*^`vd8OUBD$E%JvHuyyvaD(VvDX#M~3$SYp@pr(F28Etes)uW8q!rnif$EEd zn{e1E1w1etJV!OAh>QNSOgKI9dH8RYq&_=VN&dfH(Re87T`iq>IsPD14XMsp=g8++yT= zp34|&Xl~lrQQc};TM7laDk7>WU=TYJtmAQCy3&J->k~AD0{a(A4jR;ik){l?DV1Q+ zM2Pbu^X)!GG>uj)S~tv6!o#3{=CH3V9J>_ApL5Djn}`}tnI0^QwrSl&01LTSq?X`C zVWXq%#|$9oU>Nyt8c6uBya7mE{%6un&xKkh93r6lO)V3Gf|RB6j~Yuoi~dIG%NxRm znRobuFLii4vEWTgY~s$MM-gZno-dA2wU+ID;2`_7qxC5I7$HpBv*4ZU=l-|{IM@o- zjHG;?2f2cQUtJ&C*(9%}qUfM1k5ST#6x^^_{^bTOAh*iP>G?pT1QWj?nTTo=3c$t9 z$jy=rO3eWc;9&k|vL-Xq&?aY~{Y*}z!Gz%CVEw;1Nr~pB%Q^=F@Y-N^oTy@B5$@6I z{b^ykdY%28VRh5}lE^Z$*(+5lwK&ro_z42$oWiy>d>Ba~8UOyc(bH8`A6c$1qQ*MXMtr(95w#B+Y@hX z68=v-$zn9ws(BqbtlqJaE-7Y_1(bJ0b8~JAM~!g*Sa6~bOl7!h#1Q^FO5eAbeD!ZjDnK|>SrWDnOPRclC5Rz z)%tjCV?<12URxwTi_hYO!s~qIQqim74U0_BASyQ)Dg|QoRz52y3Nh788j~alwfSg1 zFaphet}f%m`amVi#j%3m=aFz1yb!Ta^{uO;Kke87x1Zr`k!}YmOT%R<8-FJGRpy=R z&B!0kn^$J5i@(cy2vcHmy|4?B>I&V^b8tscOnWHq7>sr04d(d$bYsaAcy7>2obBfk z^+!d#*(SmsJ8G^ZwlPGpF{gw%Hgm83z*dIJ57gZ!sMxwP*JjDB(J-oR-Pso&bB$(M zBzF>F^y;9<0@Z>+d1E$ZL$uJ1Nc2PS$wt_*L~Q&+DaO|BlG@9ik$7f-^>Kw(2eQ4G z-~1!}<#iCXdwwf`^&D*-d@hMv42wJMEO?9)rjK6ertX)=$9s)y{dkm~otX*}pxbfL zHz-khLzQfF{S+!OsQnz~&VDD&+)t*{8@xGj7+&Z)nQ-t(ucGcBKsxdt_+}9_l(p&; zIp!1H(&^=fakMlh2=pq<+*jR=;(TRUt(A*GC4X_6zZD7wTi^)6kNw-q=Ib>#m9AB* zx;%Ye;an`(BZ)Mt0G?2rO(+@Hff~7DjkQ=hRZDnUl^NqdA(FXi*i5@Gz zF%+Xm*eH;NJZA8A8FrHvfQy7&SkAOw++4$lAl-kvyrt&Y9hQHehCO+<`<8J$u(07& zn~A9vS5e#3a}yYeVq6HY^N%yWyz3SxoNfA&1>UhFWR%Hc>{@jST~@yj_~8)@)Kj`t zG6QK0`&R;l=vW<9aDvgZ`zMz!2cu8MYUfwNyw8d4J4N-Fh*6`Ufc3vqL5s@EhOG4# z(5t|lkr^_ahozzOXusfOX_y(rX%z8Ke-Z4$3@u%mxe7#uEKQ($QOHfZ!>zH>D3ul} zx|sVwcFn*VRNVm|#6I&fXM_jN2YLt3+9B_0b>Ng-?1pPmO&o=nF-u>a)eK^^Nq0MV z(aqSeDhGbC+KD7}0=F_*u?DpOx$#ah)%1bUKgL-b2ol094|>> z8tEDW-Cz4ex=;P>^Rb9`5-5kR=y%*MimM2(u{Z?-hL`II3|9Ax zaL3u5QX(&WfWCT83;ZU$TPO!)=mJgL_X&g0>v^b{))%>Fl=OA_xwegf)H1eLp(fp9 z`mSp7%_@MqrPJpfpIQ}pm6)@y)C>iGpX1ojKHG0TW}(_<$|wRzJhv>!s{*v(N#Rm) z=9>=EMhw-XfoMMTcrY1vN2-xt<~XFV8J8E+LEiOT;H^p2w)l(iDoE~?W#F`9nlK7P zrz2s)%%yKqYi{$2(+1x89%jC20#te6ALj~Z=9C4_NFeb&Spk-|FIm5 zt>KcNnM#uts8K<=lXp-tAh{ViIRMGt)MR+vB+MkrButuG+9Uv0)_>bvB@8d^NdVlO z?Eg0`JFIh{{DWm9Q{?2pwGz|udZJAVhR$XyRG*bFduGeXxX2TDiY~VIbB|#j+Ggyg zp1b1x+x@ub+x?t@9eWa}YlFy!>-EP<&g&%8gt&PvHvB4&U}mg+Ns3^t?3f}cUd`j+ z+TJ`R4CHU^@3~8SU&29Qh-hoB%!$Gspt+kL_bZERk)cz^izshV{n~+~LeTGoUt^KA zbd@e*jm4+HvnX6-pPWmtoRZNB_W?`UO&S&6xskIDxHyOssQX)24&s+zRB++*YyK`9-?CzzbHg>=^SZu}s;CuC zK#O}5t(%*KNn{?4XSa6jQsto!(72wMZ&M2$8UsTzQE!%*3{F~Y=_rwEr9jeN&430& zdT!I@L6!jeoG(m0Wr`LqBMs9J+3@Eg(#6+~GmGsa<2~4XeoFkr>h6cUS=^AA-e&AX zLB-3KV-yRpXgBrG{_)=K#)H#c(vD^iw-lOfcp?l^nGl$e?(DO8TT3M!P+O1_^oXZO zb(m7+mo#RYIc>6|^`lnkzR~k&G^{_vX>_3c9OsAbVU&hPX{rj_%kmGq=gPByr>Y<&Td}q z)XP{8Pq}?Y+nDh=L%R;hKsgosS|%hI6NcYI zzH6kovIjqF{fWSQx$%ln;Ytx=&%hf-2#XLHSd2Jtkznwf5@7HQy&LbaX+Q zWaf5Za*9GeAZ<9<=t%ui!fj9n0p;zsaEBO^#6}nlbz@Buh0Y^qz?6Q(IhsBG0%AuO zN_Yuh;;!l94RxUtT4yAkMri1L)y^J=^d`{x1kj^$i5~7BBaWa|&~OL#9FVGXE$vAW zlZ~BQvjgb7eF1{Ack+4TbtyvVno}cVS0K(``z%O?Y=1S73{*FC7I48SV@U@S1UX}W zF7PFRJ}1cAmxx)$0p|w#X#3OdEWd8AP1s(0-?`vRnd;uuHX#Mf*#iKm zdH$si%^Is+cDtll{=7fBK?%{GdynzKCr^)>YlPa%-40(!Iw}2`hOiMd^k_)&nb>1} zauFrH6+|K!%#kGO zv~VXi+`@E*(@{3OMlR<@(sr7nb@jN|G(MSTLXBswnzyad*VNc^5~p(#^ZWnRCE=BO zh2=MB(5|VCUrJ$NZMqbx#Ht~7Wsl5IWgt*AK6I!rT7Yy9-iZ`-2k{^5`Nsc?)jrmt zf%q#=gU>+_4cJ9d!E`sKof->*k;AC8Zi*M9t~o)uHJ%%I7_Nb7*#m76X&YmWbTelb zK-bTFGXrJ|V?Zx2=%s}c4*hfaDv>J%o+cQj*Wui6M`0@ZwB(Vda>bMgafi+ug!5PE zHtQU6g@Rp!oR=fNd$*ly$)-5&J~{#GCv89bu}6c4IB<01@2Pt%E2BI!Z1I!Yq*IWH z-lc48a=c!wahRg!Q?VaQ)@OI)u_;V2vZbO~Gn@$?SH^Qajn!Rm<>*Is;Tp&bk|9$v zzrRyhX9T*0O{R!aBfR_XBXq*iSZy+drzST)BnJdd?)g}H{bXdBnieZphh{*C?H`^g z#<<9(KA>M>Lg&G$UupMiVb(o%I}%yzV~-?+gtK!NUd3{~TIG?d!D1-e+TT}-hUv;} zpCoUh?`iSV=vf+=#0hMzm&Z_aFio8%`F4nb*XF)pNC|s|X((}?r@C5NM|O`DiNgH5 zE^4^@!c80aNI&oAyhVz|E1YNt%N&aY)dE3Qp#G##mUHVrK%*P z0USJ8$29CI%oZbRL-*3>v5f%`=CyV1my|(VQdSg=G zn&jE6CAgaJA z85})Zi!B=1FhU0)v!k1Ay4wX|8$IFStKs=_8WLC*ACKnmm`G;r2$?_i#OrTMHsuYk z6?k6wv3#!a4VK-M0+YPUf)2`>4BC#FjKqw9{vW(ohGSATb8&EUHZgM{`6tgAm^o3| z{~tU+lthP{HJO-*7VMu>hz2XUnVAXaKUC!ZO%&Leng5$8Xl(vBQ6Md5LQ|x}cr>e3 z&`QV93Nnm{wbPq}*7|Kn%5s{hs^_ut{g;R6a7C&Uf$pQ{oy^VSWAk<*NUSF)-eD#A zadCOSs4 zAvJ+(-nZXTQBkS^bq%FKhKog6%VDlC!&Rr2t&h&8q^ZoVBQ}aRBxB69H5#@PAAC_2|xR>f&#L@q^Bnc4xA z!@$)pO(j)A`yoXJw$eMQB6I^zx@8Q65q_1dYD#*JxrKZQ7@{rG3G_j-(77opmy+hk z58q_tCEsP+%hyV1bK$?-1nbpG`E%3HF14(^SXdkPS(~kDS4ox|o)tI^?>&ap^#RYX zvlA_-;#1@P zBu}(mPOxogbeFPx4(mI<0(>An{0-0Q(duS@dC*L5vL|mDX}B@y3nlhxG*fsy!qVv< zl{3lJI^8~4%yWPuO4=BzS-5)+J6!GO@b!E5t$G-Kwv_Z_mvTQyNuwvISu6q#sStOF zA#vGNEJ8dw8-n|~e}0Rysg}>NPRM0q`@!yPY3)Drr`@44U&GN|8=d&9k9X0BZg-1) zNsI7g>FnZZp6+lEgt;sSWu|#+to9?*R2IZfjuLDIwrx{cb$uQplU->|fy~%Y#*)l8 zS%ZqsY_-Ho1gYI2jR#!ML1Y3Y5C}(+2rmpGROM{hJwDIo66V&MpT&-1s^8t{}WhWY+@Z3)w^vlqVHS zjqO_W0})$Er|h(g(-OK50YFrOlRa`w_eqR*=?7gbMC$-rwtDnFdrNs01B3AW3S>wW zx!IEBm#Rs^w2M1TIM%u}NpfM~QPH4#4BD{~4#2dNpM*;yES;vDF|$(n2L&$(o40X< zRL;lfyP%4=j(&h#-kAe^xpPT=o1n>h#|WpRwi8D$2~Yi4)xa4`OND+`g#lu1h2;H- zGx}NT1sXPMlwj(ViAhkZlVu{A%9_v_qvs)-E7748$JI@@vD{CIv=f1@{a?4U{JzNkmm@PY$G4( z(O9{3!$Q?Ftnl>l+1J7Oe!}*8%f#cxdCSz+7+N!jQ1ASdg?8mhC)v?h1fRt4B%!p4 z5CNqe1AI~-Xrv1v>4C34@7Fo;2db>|=Hta1fAN{a%FC&9vVE;kw~yb3`++`#Cd{=d zm>sF}!hCa%#1#Tp)}azF|7HuWSFa7(OO-73U2|5bZYp!HW z@U~}nVGIzZ)nA|o$?fHUJ~vFEk2g{~l32VDd~TtN&SEB)Z{hRvlji$FaYGA#oFnwI z+qq?QQ22TcafsoPj4?{Z;-&@h8s>sqxR`(Db-qGV?d5_({wK;OwPXEPi2pCq_JlH}gNG z$nsw$<#$$Ubilt@|GyF7KM=w7ABafSV?)K``mclk51IN88vY%}mK?!G2FjIeM2(Ki z#=*$O4j{32v$g#{p1}EE5c4l33=UvsX`p5Q4f@YuZJ6cY087?vM@U|`fomY-Rs?{u zH`rS%fc`gv{qH{jm^qSXY{&??SlC$pN5is`F#nJFPtG!PasTW3qXD+LIGQ`OP!X)V z=N6l+%m2JsIYM7=wp%}0X})y5h`V%6ssSWGRvnt%P`23}P7G3mlDw`(lc$jKMx z%QD#-TR>p6G`Rh?FgM%-9no6BY2%_@T^(6<`p(w?%WMPr8e82R85JW844cAoZ#E8_ z5+n-vIRilg#RgSZ2V$Dh*4DN=0$S+)L==Z*el!L0LygkST3fsQJLSU!jQQ>bdD1|E z8lF`LWN;f>Bflx93vp)Ym1*F+sfYyy#*qUWOqQW45JbrfQjV4z79=$!`-dQyCA=$J zBNR<5j+PD%xW8sHo*h2n1q3q$*D81{!&f`#W^CZoci9QZlb{4XJauXJb+WP@4YJ|! z!G-CCrO`FQ3%;6=Y;vSsHK=nkr#(Fo!R`yGr`rQz=Q;_{2>G$e8bBNX#ENYy*#Dj$ zo*C*}+y6dzG^kz-{FZa#8yOqEwaoNMZS)aZ78>r_+9ENtH-4=* z07upAp#OGo`97B%~an_LEWyObU>gurI;Fn zme|_&WYA}NLEpBJqxx;#ch>rMnfTJw0g&h`5Eb>03$*7ftBWJ(iB@aI_f~f|tW!hX z>xYBz7ktF4z;u1sR2 zh{N5<^+V>a8>?r#;(Pz2whagkwi!6&*sXpM;}y&>-@uZ6UUx74d!P~eEu&XL_+lJS zEeihA=ED1PuHU1r65(qhjG1ln#<$srK5rFBAU#hI`)H)4^7I?577oVuuhKJip}mr; z^BfT*%ULR^d3L3Qj~>(KO5n_%p)$`}ma^&`-6yyh*Zk-ijLWC&|XGHJ$kcGS;GHwYFUtJEN3!_iH29JG818}m z18e62FfnYOh>YYbD=eIuR={>Vt1#mrjcNNQ=-t=Tuv|w@lMI+TpC*7U?k^+^|C@8z zy=bX@RF^QJ;qPu(fwcW98|uBN%wgiT&vxla)04Hwb1~2YSyUH;E#s4KhC-zsdViLy zkapDtR+$l;4uvlLdOWSr?JKa+RF!9AL9~?6t*}8SG;fnMDRU8j^iSS|Oa`Q9yLtaw zsUxN;gJg~%f*UZtQCK^Mutp@A2-&d!W&)tflzi5nZ9kzjBq6a1E1yc5>#eu#JxW;7km}X>{4a`KQ@TRr-NWl*t#P=9 zZF80UTQl$qOVie8wvWie3Ev#-Gp(@>3_EHtj7HYLN9Gf9+YYjV^j2v2(A7l&7;>_) z-$EEk7`}O_aZnv<%`n=e5>3Wn{#0@hy0n z0yhw}p%MC#ihNLv;077Oi{>J^H3Q+TFe7fO6z4T5CLwfD(CjGb65Cl{Fl@EQnUqnW1*`w=?N#i}6rM4rcr@lT4 z_#DY}F*7mBNMGX>_&a5n_&6?te&!;Kbs5leKwRiN?6ad+lA>wrUV8LS$${Av6Afln zSJl8e)IWYrlKNk|9ktirZgKF!<$Ij)H%$%>8eZ5WpJ4v}De{RCR6G_bUu~=T#P~ls^^1Vm zLfIc$(l$xRsmx&WR8#whw>`HZ_@CvKwczIotyY@f)F|KX>5K&iXPw)v1`Dq3=}bH0 ze-ztFM(qUGA_6C^;te4_LZIRzii6qE!As6!2ZU0fYAGHx&r9c$zQ#|O$s?3$6MEat z8X~d>%4*o+^rAQNEKC)DG1APE4<`aEMdT%ihM^?Pr*G!Ut4&vbde+KN5Wrde>#)HI z+D_C%%tYjZ!50Lxp&-jz#O{`t;m0jqz{aM)AIKgg#>@ZLk@)K2%N3~NY@woP zMzP6+I21psIsBuBa}Lgd+-B(IQ<<3WgYi0=`U|88cAA9EgaRaZ9yqx zz(jZA^!_Xj+C6+`PZl&Rblf%@k%cx{X-Fashk;|8(Udx}^h?3c_4yg$Ir2K|ELx+- z)m-y#`woe{OgU>q<(+|qy9w+NLBHQKihPbBh{CQI`R`J3kX`x*Y)@KXxtL(4Fmjf9 z!pUNDL-zXG(apJ{O-IUor`OB~Y|X$TkA`su*ycLfPSmkm_jL?jbm@>vPg?wWDTWAo zF&5J_vTHibSG8F0iDMwz>I+SB0qR|W$=M5g1%*d(HbkZkep5b=7X2>$Oc{^kChn7Q zxoYR6y%!|WLZH>}QLts8D^QVCCW@p*x73AGYXy8#vnTLxnk_oXu236wK$Bgv18Y2Z!?uB zdgP_!AH#C^#=Zc2ro&fb5zMuOo8}b(j*SwK4mZrwLsKoXHO}f<&Sqxgvlb@c7(Iz3 z8P#?PV-@1DAFWk+X`)+XF1CgpTGA+TSf{hC$j%`bjR%X`**a!C_Gcs|>n?^scAGY_ zF9`N*Uw7To4O6e|_VBqMVY#b7qq|$jrXf4z30T>>5&nf^85^k z!tQsLNd)r|wr@RMyudoRXc9f+lhR1#^=md7res6oT6ynsy}kFH5svd;%&9Eak{tik z2QoG~^%`)b_RN%bu@ocalHZ|gJ@1e;Ofj%lk+e&|E~~I|?gU^hDs^sUBNj)p%9INS z-A&$Tgsa6Ritm>{D+HZIR3Fhjd4~B5g{Pyjdp5H$^BXK^?c{MwYAt{2Mt^|uJ}046 zw3xgCv^?o{Y-@26?{JF`DH^oGyq6aWBnZ%VhMo+X@eM57K`f1I)-Ewbu%->Q`5s(f-%~CvgLp$4xhPOfGSaZ60(zS3Q(#4<3S` zF&y%9E_!k({nT(-%_WcavXImS{fgSlcE7Z3T>y>ah=R zykXvph{CrdC{$nXLDilgeNsM!y{`K8qwRxq?rVszJ|P2D20ppKrElg?edv}J14iIeL4%YC*0931vhl$5R z=#!rt_JmyYZjeumYch(2EBZXAwPzRs4+Ykg!yc=2owrGX;8)-KwXdsCvt827TEpI4 zJ%pFSl6VA*Y2ka+(a-9#G1PPIOy~=gdzzmMckVY4|+NfFU|yo zC!+zImYjXXA9?amnM2s&d5CqrJ3R@r+CH#st1u6-_t2bi*|?iR;0N1iRG%~6)%72S zm4lXJVv!pq0xHjy0NQc_6g;HzSDKhkj}C z_+K%_w|0E%a@(%>zlkFfDl)EtzhaiEJRLD9I2q`Km@cW+ZT^HE!(>I(ZQNckKiCWN zdeIYr@^#pyxz57E^O4Q#6|hD5C^|1|KTIH86wvAsX4K5n=@nTG&jNm!mtcm{^)P&D z{gpZcUmM6WdxT}ZrucYWL ze$ZP5Z6S=ab7Q_`?1@-fi_0(p$<*)HefS`(H7`=iNI&w2^aoFo8K7Towv3Alhkx7! zu>=wc-{>Lr7U{@Ed9>kSrh*>pUlYYp(EFQFOWIL?dN;|ZKP{;wNz*H?b6EiLpqW)o zFhx68TIou8)z zHx${UF_q8weGXBW@;-H~N}!4&@o>lThC+F(*!Fe!eG);n!SnX?u6XW>_T{gQrFmM3 zW4x#RyZUB09@-Dv?5%UCUdDhmE^K9AaPhM>tNefLO)6y8&5ev5IK0*dSt{j+X_j9- zmn7qrBuR)ZUs5V0j#DV(-`AR()KerhTEGtW{WfEN5Zqo|iZIm$f7m#2B^RbvES zCrm+RX=^EXh4XxI{xlk&URRABB_p~MX=sXDsFqfT~|6!em_PMRT( zw*aKrd}AcU#lR-t$$e(93fO3b-XMW-zJ?G#7lK~7siMCCgEg+f&bE>!eKVTQJpV#1NG2UUyPBI#v(rST+ccOkOrPwE0Z)h?E;e23NET zn_B2^@Jx#oB;h29Nt#PF=0qVA+afYhxrIqY%kT|wP)M<4yE$(-&d<*TAASQK%FM>I z#BAdjQ7Tt}d0szSAJJt27Q`Xdu}it6Wvm?h$6Q1xHnJhyDJj?rLi#QoWVfTABI-mu z#i|$xMp`+k){$8h0v~OVT7N47^1Ba)NmI(Pw-v9^?pZ!+IgGDg0zR1-}K}#P_ab_p1 zzu3js)@quv+#WU6Wvc1(Bhjj(0{%^u4rSM|0+*4wt(FIT{^k9)Sp~*P;TI7K-3XAc z4{2blB6&HbGg0jf|4kWZs_?tF`dZUHtg~jns<|)v@2)o$PGaJe*w4%kpul*+X)}@b zCcYsJh*`{1VPh=bi9Ot1q z0)zS)&3g)^ImIT=5#VPYB&(i_HxW{(?B&qUn5&m# zwZjfvY7rKJf~thEBAZe=i_;Jdv?vNI}wiLW~u|s8d^ZL5cXh)6$-c z**bEi;K64MQ=*2qE&z=Hgip4ulAOEte-quOQ|&&l%^^%zIjm<-@DgjjVFL%CF<}SP z!_^m1j4L@-tx*@HN?-vS8Vyt!^afc4m}ActP7!=dfjuq094&$cJ#f$J=1-N#z<3B) zzC$}~($K~2&in49Fi_XGxo&tlF78ZU(#l#&j|9;>r22u(|wEVP=eW`9W(~CmEK`Pr|HiY4Q}S zY`tj19!T1!ZDI=ep+$@~sAG5{4`nAph|)eAeR!0!fxSPhz}9r+?@Lr-z z8N_W%JxI=b(xWnp;gu`%c3ZPJ{9PBhGp+T-mj)3E<5t^1wTvkZ93y~hw7|>lbgrOu z3ti}vZP8B{@c4aUu5GH9bD`%J22pd8+O_l7Z&Y@Jfgg8&I)?8XQ zmbkVlW6(nhKyQK|mNI$#Bh|7&B^tKm#UlQ~RVv-rvoV)|8yomgldicYs{JFvTYx!w zd<$Bw>e&yA9xHeX{2F^c>yY4gwFXM1>3k6?rYhGA;Fn07&ij5~){^x{G?<@_KVV|Y zC83(z`1`;SCZ*H{4jjCZY#(o|_;xKyhmc0mKDC*IKo=u#Gb!)myl1!)!vrWP(zySrGZbw1W#x^x-ke}ezQ73F3CN$ zff*8L4j=_T#vrti`;WBNU};N~sAsCv4*pUb)J~TS!RIM9tc$8bs~s{~hu<f9thR)Frm!eaDqDN%%Yc6nt35s&L`vFsZ=Im5B%VUZ9_T9L}Nt zl!3vlYDQD!91LT{MtM^w(MOW(-=7uwlz(BZ-h*@BGJtf+oA4gJFq)7+XH7V(nvru% z$4!O!h31h=Re6z0W6kW>?%JCmkt-`CLwalzUFJ>WEBX)l+LfI0Y1?p(lsshA&LN0z zP{3!o*Ux(Hx^9Lz3sL#X0kRFDc%M@lI=dZToO?Cgn)H_|cxKT|=3~WYKnAJRyu5gW zIigb)UnhBD-m+faKo4ble(fPXrY&h_4cTQVW+^9K9kdJo(S>I*=qg+k;ObIRc&g@| zOvH;7H^AMr?IJx^R#x)lMf>>D+#Da#Z3h;9^P7V}f(RV%+9zA&6Sdiz`+F65#4r0^ zKz_Mks;MCtsW->Rzw$K7wRbQx#D(_$UQ9#FC3`V) z>WW86q~x-hSNs$^;o{@m@VHG#B&Ih?TWZx&#N%J{tVa4{-=yk=Gs=`ExDd`#!?40F$zjLUGy6=OErKrYs z?}e2@_HI`9VUjmn$L6v%-7YB-`$H*p)X@%BchNxM9WhNr!=uR(Zxu*!YH`VE}$tuy5RP$l@_{6gEqP@_ktz1$c1 zK(T7#^GR^@cdYc!np!Oc&0tUFc${%ICLSuwxn6DOa6qWq+LHD2g_zO> z24U6PVDVT-|NhSg=8Rp6DkMfcYad)J&V5QK(eaiUus!fSyOA%n&%T8%=@r#r7G;-><`jRc0iF zLn35e%%JjdGllZ=9t-d)NNkU=Z>JbXx5rOhk1=s!hk+6=qOl}KfQ>tFmd_rp;!8jF z3KQ<>L|QW8iHV3!+|J}SvDw6fy=!a+9iMc3pkgKe9sF2?T(AB2i~6C6(D~9|$`N5R zFlre2u9+N;U$|rV{EI=o&{MHH{P=WJSnccd?1RXC*ah&3F!9Bys?iBm*RQBT_qF4b zA8t*VKXZ{Fn!96>Pl@e<{URL`DeED zubRuF%NiFMv1yE7H@+maGKZg5wqQ1C+?Cv{`_YyU-gaDdx8vyGROYH+6g-+$_4P&} zVaP#WfqxP;>D#*)%9m?*wavB$u*{4n!8$`FpUb`8i;JI`n&gp!bJ9In>!>X1hyfZv z_rxn?1=3t4G2v|f_~`>z%}k-t9QE&-0U5pEqcb9$?<9{|jDW*Nfe&OX ziwZ6?CS4N>au39FZq~L3`Om=Mo|#7W&(IcJ*kFksg2RLx0#htJq{?mGn$P|n5@g1R zuj9f_2RNP%l%3T&5oCunECNE>8nfu z=$|n#qp#=rd3gEMQ=sN@2@5uoJvQNM+$4x5o*SI8(J7FphWNBeCkY+fk>L3kbk*;l zH@ytH4Fwi4!kzSeMdhw_#0oAfcL@47qf;577=8O!!?u&bmQ*gZTFyTnki$dZXd{d% zb!s!MVIyYiLX=bv{bwqB`35;9X@nRyB#~5f!`gUL(acste3q;oj(hk|(s2r8!q)UX zOcm9y^Z_g*D_D3v#ie4NB+2(c8g#)a-6p1`dafvVlEl;xMUM}gt(rW6J&%U?d3l=G zWY!msqiHf=yM^*SH{1!+A!28)UUiy>ue6MUp`F4QFtK}0Fu!!=;bg*3_pe09>)Y!- zrGFQnR1}Ru2PIM{OznJD>CM;>vH}Uql2b!4D%Kr~iwP~%096VX^E=(Vl{8cT-i&Dd zUMw-QFOxDStR>_7LMyhL40kK%!OSI!j!BQ{GQL(|x6l|g*0u73&s2}VpB-AVWVlZ@ zu+};gdk05i?>4Ng_A=_?4p8~U>1WZ>8CN+&OD-zY*N`e(Lo%RBg>(u&Mop8ub*?qZ zpF(yyv81-x2T2ANT<7&Vi#pZhi;#`RioI+NTO(~F1);K9-G6a zty%e8qQ~SrQK`U4yo$M2n%vdw8;d}KpQaopI*7@uq>iUaFCNqc8MnoHf-QUiV;MSH zunTW7Gl)S}UotU=_6vAm^Ft&~MGNfM3ySZBbZguk!&Jjhp`1H^LSuTSp*Y(W;Ft17 zA7k&U8<#?h*6|!u|2IJAG16)IdI~%k6Im&3#KLx4A<{=J%zcR(==Fv>SEmA{V62ei zppXeTVI0@@enJXTJ(La0D5m)ZnQF&`;E4qo;+jj!XHTC3Ni+QB8QW+Hbtu{()8>7+rtVT<^Brkr;$|y7BTCL7=2o5=Y>n$vkD}s>&hgbK(#^Ioe7a9xx9(F{=bmKu z4N%`6M;gxzvc>yjTS`K+YI&78(zq&3g~Z78-%vhd2MkJzjpnf7_=xSdy=}>J0z1{2 zEhm^|ep!7v;VEnj;9?9h&}jxXN#s+xO5|Jk+^|hq2FSPbhGcg!YHIBr=sLf72U^Que>N?7w#8D)0!hp%tF`}NXhz%WGJ5rnsXZf@fMzMvdnN~>@e*W{LJey z?g)EgDiuHz&X~{Ee@d&BdH&e|(t3W-DGcc(w-kV)T4WJj`ozSWv6Hj6 z)+H!;nZi*0c{SR*Fp8VKn0tXP9hNy!*Ov8&ayHA`ffki_=z9wr7bull7i=YscZ;#^ z^qTMK!VpY^!Q-c^*LpUMd%&zz6IxG<)ar>%X@x|n4?3>ds*7b00bg_@T4Cm)IPNUa zJ7G0>OLJl^jf!`2h#31I%7rnrhQqo1fkD;rimvx4dVN@1d`cJ7*v(a=am;#ll@ zw&SCiS^3t^t@KTke$HxHeCGs-Q3&b46^p)T84ceZ{b!lCUh{UU?c3nkz~T>U(YY(M z7UY(n5KnqPXEr1TA`TnM!sFM`*%6E&XJ^}ePV~5b>KAl}@`*in&;CBh;Z8)EFnFv$ zoV4wPd;eHbxe@B4jj-Pk>Ro8u(vABA=axGmUE^1HkN*UfaN9R!`O>1O^p;j96&cd> z?ist>_5sOrr$t7DE?FV-ZkV!sm>8J#+h1!X>=-ZO6??l0wW$N~zP}0s2G3 zeV)VUQ>LWDCR$#N9om+J4Y*WGf2*zdG4?K%sEZCjwz`@p%i1qfQR|iz-v7G|u}cD< zxVR$=v9130@j=jguJe52T)+SLdCLT?oTDU=Q$Ub795%Ka^#B_DVZ;p~3o+S_PCLb7 zCHKq^F7>;@LLU}6A9}AiJDxYC8b z>)7w0eVSHtt>1YVDbQjS2llmtp1rS4JiPj#1aEkLa{bx4%kqrNhU?ugXkj}Ndz6ah zIttP35qy_xX%rPOui{EOSUB@_Z?Cl(#vtrAM0$yk$)GwNRRp_nrvQf-t4#B(jKmhn zjw9jR%Ey|wU2889aYoC7c1YDCu;$AgV@;1=#e5VJzML5X0i({>QIT_HlcX~_AgP-| zp!}WsSg5^U0{)UBoBPnO;jkzP{r4(XTnI27p{~K|@1%Oc%s-}Z@nb8q-XXo`+*=@z zWLIYIq|(iU-Szz<%CDuS5cXlMeQ~eJ@`xh5fiHxw0(2cI<5;sV{`%6*U*$U5vMCo$ z1}sGdkfjaitP(&?MoV8`j|vNNQ9cm;%%tOLT+DMK;~!R;eGuEtZ9{!~W+wM7KXt^X zw22k-vUJ-9Y+$g|drn_dgPiT>J_!$p{Xmzg0VfrY_6Tzx z*BW#y$7TrX>%kLJ8`dr7_u~)tB!C_qYW<9dGjJ>NpwfGVaxz|8wTE=o2v|%tdH!$& zJ#5wWltv4vtq^pY_91lt?)z0m?z*AA&NsZ+vwEQ^j73OkZq>vH6;HK145mpa0a$lm zC!VBcx1ux_`q%la&?&6K)}&d!x}ugifvxP7ylmJ3O9eEvaO)=bZ7Q_k49d&WZ=%C> zUBIc{^itt1C3Xso$Q0&NK2&qJ=)*Y5sV>y;zfYEy+Rndau?!*&dOs%GAMGzAD1_#m z{G$Ex9GB!*-$1WAg;&R$w~BoLKLp}|Eh(fV_n7#Rek}Df9ri1JSyZuDs^n;^Rcf&| z?|bZ92i%26k7wxbtO~A)R#ore>2IBl1xCS%sNR_iq|*|4H9vXGIl7w)+-Te%>z92P z!{mh8(HviSm^)UiKV(vK!C2-B3Xe07b{PmysL&M>#^Q@yV=w4U4m2j80cOJiir;^(d*3(W^# zKQm0%W@?Ijv{X0V7?4S@MhRf|SbS$5zG&F9%dfV%4>91-r%*V1~pz^9!&(c9_axb`o^%!8|_mKSzx7>nFgJxlTB zZ&Yur+S}7D?<}jQF4Oe`&{a60r6xqc=2G=K5eN$s6B7t$h}=6dp%~>>;+;h#Ni?+q zkA(Z=xp&($DPnCY4b;{sGk9NB#gO z7#^y0!iGs=E%Z&sNmpIul=$POuvrs^)vM}9FT_^AUp-X9Q)NF+;f<#9=$8?1!Pz>m zgBUPb$x@(XuNTJeRhHaX_C?90sEj{nC`P#5ycHzERcr{S>!aGgoC-i*baLKFh2t2- zvL}dM8|t}SU-ruud_W@b+Oc zub%-$;kAzhtjf&=H9*HsiVHgL@rDVjtwGL>`2L zdeJ|Oo0U2H-BBkUlyl`wu6I^A|Gw2i_g{G%CdrAfc!~TLJTEZESDT#V5oSN}W{^x- zf#L$@cY2=0L72K$0_f5(FBz=G#OT1@xwSeNPRex?hWTlz?Vc;JsghKeTT?Z=hyd+J zikL6mCPu+K&*b)SB|FDT8n#-#FlviYrU$hUyb#d4ZC{IrRu7!rJM%%Waj&}qfiI*l ziapjzmF&b;x**L@B_p*u`%w%Yw4x|E%CCWdMCqGWmAN_8Op4gFST%5%07CJ1q{Mvg z2Xb{v!oIIM6#5o#dyKfP%lGgWF9_&;Mm1@pj5uSJR+Zg(z$f&X9Uj`73O`qV(`1`# zhe|b%2N}=AA=C%eI^-{oMEM+5lpe>DW50p4@6 z^flAslj9F4ae!%Z3*NK*Pfua5>mua9GI3 z@%hJ$?PvJg&N$dHA=a><^9+Mz?ZeY?(zLO*c(4-+MQHFR$<2on7+h zQHZYEC~J?P^E3?30Q0uJ@%1a+w9qKXU~Dhx&cGa*ulxNLd5ea`GlKb+AQ3g|2g(hK zf2Qv>#~2|HW2n#X(YLbvTL3gR#`jHv;lxzl+E|!LM5G~Hm9vzQW04cuw&yO9_kq&- z!w7l_jSUBho|g^b>)ueRUzj6kI5CjN+A{NrrwzqX%u(belEI_`o<{=jV3I%t{H-=R z8e?5b@bqQELlbQ&aje&;ec%^&a(a(N>hnj1gByygfKFyuyrgVL>z{>@imrLpYM6@d zZEN0z57^xqSCjkMPd{(^a`J}wd%*7ftC*;()}tO32ryd}zc@bQZ{?UH$}gpuA)&kmc#c~EvGXyVdSVjpm>ler&cCSM=B*UE4cIEnw(O$roSsL zixX%?Kv@E;QH3(mKwe~KA2l_tKS>GuL|mU3VW%u$aDgR&7%3V#CO8s5&hPWF* zFIlz7b#RUAZ+Zo;g&}Hg#Ee$P7GhE18mqP0KHbxIJGd8T+)Jp_gWJM82W3n-M=!C8 zl%zo)%Ef73rY|9ctqfKHlU2IfTR1X)^^Apa;Bh+>S&cKmp$Y#$ADEB`UJTe)7I0}EddhYX~Ic|@Yr~ zl>&5LIif+{N+TJmhAhe(joWh-1$k`8w=0U3&pGp|gb7mI!yvUWLyVDCwCv0)RYGPl zPvgVXv>LKix5~-DIue*uK6H4Z>c*V4l0-1pw@Y8EQdYjHpLm5Sadi(!x0exq@~^i@ zPd1kO-xiqOt->P7)=58+bUT5@(j%ltB7I4ggGYV_Y%A@Oct6`;0ie(ge*wFWW-lh3 zhNPRsx<2B?GCPYWhE-3qFEE34veH*Xeo>G1(##eAijSh3V#m8uhvCvg%AoH!NrEFZ%8*WY3Ev3B^uDQsC3C5;d&cZA@^XaKOR1AiK*^q#~hQ&3yn#1>d zgV=w&Y3gM|{Du|PmvBSHz|3+RsUXV913U1_2fPe6`CJ6f0R>a^M^P8=oV}Y)U!%)Y zZuM6;{Lm>NaNbK<=7bnTPOZ=XAuJVKV*jz{`B@OMi|CM~KR(-%vg9gIsS-@<{hH1- zefoNZz2{-)ZbQDy_yujMSGeyftPhH1RJ^a$*Em5&{7|;U!U$K-tpVT`$!^Hsj@_q+#Ph#uD;`jm8i9O0f-T1o1+FvQxu8V$^ZMq#UR;&*7liXzm zLl6-P3f-WXT|DDBIEAh{cO(z(`DQ_>~xvr*n!Sn%w^a>nMm0*g_j;v-%TMx z{&$xw{8r{2vI*gSE^poP?ms>yiC$jtfU_E-Rljhfb9P|2uD8oYt4@h?XB&KC7h!o7 zgly>%YP_%dK443*jL4^8?2kyYF3_La>c4zLOeGzBhj!Gx6ua1&#xJJ=#)!un-^ggy z+{^|X2wFC1kI{zIz^ssrIEDrocH#!XuRrzN*C%N-it~txX2uMR%#S3SQHg#kJH#jd zPO`shgB-(f+*ij9r-mRTG$}wbkm5Kt<6~ZAypt|noi7?_1lO$l;Uh~HvaR&OGXXeO!I`I+_j%GVUu{i>cUMWiw(gjP{o)$&tyt=&cY8Lj`z;BIrXZve_74h%i zm*Etq?x7@1%xin!c`mB1N$fN`3w<>#V$^NGgxSKj_lYExn)(!BOwY>}|J!J($DyYm zg|XQD`XNAX18&~X3-YF`sxM?vmV@3;Fo=nvSr0B^_gOg3wtOao29UV7UPDNLa3*F0-n_n3ztWhaArOLC%FwDbMB*Q^?NKnrJl&bjy_nd1cPxYgEdzj%r^ zI4AvnNc%XU@~s>ZTlZt=5r}5KYn=KvX9sw1L4!KWm$rEOfCX-s;atHFn6{B_$Sa-M z{6f=GU`PKxYiufR!-Hb0=E-*;qdT(?JK&-4Bxf7DP4K0!wpBG?qKdrgx@BzE@V@W7 zKyBOBLUwY7q?dfJx2moc>qkq!QfnZbsCVrKQB4v%PPF7$(m5b$TluH6VW6WEDdBEp3_+uQU3{+hW2{Hd>+Hg0^mHO(*kIk7XiO3T;5EZpoLD zb^5kuL9`FKXa+L@9}fX?Ux@wQ7u$8o7N?eC6DQ0FV{S68shL%}hzv)iIM7f{%xzk| z57mE|6GUi*rGBUPV=@oVrHJk;tKdx#e&qAWuC#3QV*wZpz-@`i@=OBsV~SqDQ&ka= zVE=R}9Wt=u7m93NNI~(FYXp&ewI0~dkYAl?vg*vJW=*xR$|*F_KL=)Ax$q%-YNoR5YEEfZwSmy1VIo{ybU7Yuw`Q8I{@ zshd-?j0n_Xazab`%J~}a(XMY1)H?QMcF^gDa#)R>$}Q_STfV|y=|m_(nT7U+yqNAi zMx92D7;YWk2Mf@r7!vAwaIT~?92_jeNE7Kw;C6|C+lfwi=-`LWMADyypZAGI$-L0v z?ItmA8-nWSXu|as_Q)c|&(ZL)&W< zUTj@#&4kmZLC7$Sr&AG$>#*3h?y384N4dUW6!Q=bW88<;{xUk;XhYc|MV*EP{R)fG zZa$+1&o9=aR<;FBik}+4$=4>AEN?2*+vf>|cXy7SOoqL zFFUv}3hAY81@sE{herHKq`@H~7XfN@6V1DeeqCgbO!H8%+!s2X^doWJ$1a}Rr6c8V z?17sY%JjsU2NALmmrV161h;~B7w}wj&w*;=V^0k$+1YeN-{EqG#4FwxHeDhsw+I#O zfvdgq0=rX3+2RgdSD7QZSDDu~p!iM)e%$_O2s!4`ApW``)*WIIA7@U0a*lQ_94<9r zyLEQMsLASA$FC_;YCVXahpta4(A}MUoO~v(5oju%yXIbif@a-AUveY5D4(lt(-@pi zW6b?NuUIlH+Qf6+a;%PZ^ISXMD%>PI8?10xW=rD65u5wr1n%~;#5ZxPHogA7Jhtv_rhZKh(Z;^{V48^5#D|D@%eB}m9lzU7_1BH z8I5Km2d_qCHWUas0^swZCDNI0vik1HtDtqyC-||)ntT{$(~J^b1WY9Zy;qeND@)Nb zC|?ke(4hYzW@9*#^6Wv)9NVUgMqG^So-21jJ#7M)vN3a~EjBI6<%9Dl80~jUihVfn z;Py4&gdnxG`FcfD#VuGjY3)YXRWO|5AU9|wZY3W$S>rOa_loJodF-hXbKn`K0&PaR&X|6oX%t0jcizVq+V2o%`Yh+S-^pRg?Nh4*7<3OvMj)z5 zyqR9BSf322pK4;`(8OcSc)Sa10AA^$kOfCF^mQ`39_+L@753sc-CYPsfOm3nvfoDO zI($w+zjaBu)FTSxGX!)EMVCh(46<&MLf0b?@jcqyetY1EZjUu3khqMhiuRCY|_emGSiOboZg zO!YI#zztzoj*v^WxH>#d$Ne>3wK#8!I=tj$vBFR0oG+!9-)%DqAN3OQ^H*PJw!C&b zv{?7Ad+g&aYe3iqi2N)+!lXbG=S6`R`EGnIqClE?DIyTA6;%7eiZnq`FV3kl_CELh z>jRyJ;62&MLiOS{Js2AfJ;QJ!Po7r^!Nj!txUyR<#q9*GOdw@0oxoF-EZI(>(t`B* zSd&G&a_NV0Gm?4aJf?Ad#Yw@H-4b<694_jWB3wjASfkSrxnmY@x@e5~z1kRINs_Ri z(G}8Q<9ldxg$h#k1mbnK`?5_FOFb^bs#W)po#p9U=BTkxhTz0%(6TMMrfyeUHk+2d z+qK}0z1GNkyVe4MNn{Vrs|2y*Jp2X3`63mP?(D0Ihu8d=?03Qy^w!_diF0Se=^vl^ zLf2W*9VI5jnFqf=O~B@T4aFFu*xp0-Q!4k4j~0L6fM>G8dRc1bC}iE@6QT@k6d~BG zVxFfDE(V_AV1nAK5*$gO zi=N@oMfY8Rqdm^8aKvOOa@~?8=7(GmsqUrsqIWR{2@oMok@IT!Y5J;pu`A#Vea5-K zNh>OLNC5oVsrVI1T#NCdu7=w6?MN%%18Tb27N<|`vj{<%9Bv+z`Nn$Lvf|jXvxfLC zpIR0AI<9(TTX$O1$4gl#B~y8v?5P56`{-){#Y32s^Lo-Arn74XCOlf-+KVQ4;?l#_ z8el)|J(pfL50ezKL#F~7)2IELp$MC2C<~$mRVZ-U%m^}J1>xr4mJ@xz=HQ3~dONWF z_^Jkmm1=t@aOa;})GKq%En=kELB_oupn|%d(Nnx>h&crL!Ncl3@5g`ov(i5ISa}q8 zX5Qy$Cbf$4F*!p!$Ej>l2#u_(Z#-urvnizHV7P)WhP*XS$b`FFwgsggd&l?`@ilcBJOhPBP>#9Ut~20~-8PO;BFZqBb762`N*gZy ztj-F18OS{OX%%ZXp1o9&F0lR8P=wd$kvZKF&@07nK;G@;`5jt#rnY+c`^|5Z2qec_ zvqI~ngjgJF*M1zbxRv?b*?LJu#2P3>rnTja&Ra+}&yT~}>p zY2~x12U#_c-T?uDQb&H`9W~1cvO%#<)J1OvfiO%%IjwHsv=eMv9852kjS<1qMN7MeCDgg_qZ=N>H6*;6!ZUjVUf{f)^^~5Vy(muZ}Uda{+(`$qk=$xW3or z+y>-a8wR1_4mrYi>GbdMW#H_b&sC3&zb)=lSL?Dv4UWB6lEpi`MG*T+{bu92%?`@E zr+#kYqwH|QsLcVt&(4fjC9;|LmKh0|1)%x$LJ^F$pC&!CM9j!BY3Qvg3&u`Wk;1Kd z+T4qjKy>UsoA_J@*dIsWF*+z9{;34Zt+>?f{g|nF+c}iIIR%Yclb`hd>CSulP4i-ZzIvAKG$b)3&)vb-Sj7Tg=!9NY>xsrQ&jX0>f# z!5>r_$hicfZcJpEH_D;!e7B=?gJQ(zJUo6J4ms%!sNXXc-`pgdJkd56SuBvp>x2Ny zzzRukWS%6i+Kf=t&x;%NbGR~?rkNiI0V1QE)zE54&I+Y!sv5FZ4qzQPlTeL;NtGD% zctuCt=^^&{<*$t+@v$B*^La8y$rfECL8qz@ksvIKAEg6qNm)hX2OCbBzPKX#Q5GEMM6_9O)$*4Nx<^H10gV1*=$qA zz`oE;w}4V-(+m;lS_(_1E%9x*q{b@RZgWj@`=raZh$=QOTbdt_6D~U9rxvl`&0@7dXx|w%P@OM zZjc8#^`I_(?O8$z;oUMw43wb?+n$e^dLu8l@qwfhNO)r^523_P%8P`>6G2c7R)2+`_)(v8~IbtjG^k9@8@bqdC-0z?fg3`*1|7*Xf(zXjeHRqa0LeZ{%s6@2ZIEohYMo5`7_)2_05d-j~6H-*cgpVopVIpI!tJTfYn z`KiTe%xCTbpr{m0Y)JzDGXOwD^ z?=2~~+q+a~Z^4CFF>vjt&5Oc1dw=}rrHq@Q9||nb(I{iS$huA@t9f30!!5S@+eZX( z(EXo#ktiN|olf!`gxZ~@Uu-)OU~Wh*ycuh-&dx4-$@WgB(vrVkylP<=H`S3e^~VVq zD<$xI#yd?#WmZcyWpbea6nQe`K*zkHUn)ewI~-(`5_8klwsM|qi>%ZT?x=hE2cI$% z{VxvbO^lfKOM4+_JRC;c+UGj$R=te*UUtbE48L`vQCts2HDsrQhIbP^ib;~=ERHnu z@Y>TaEd`j~gp?yXm+o34k(xgN z{8aX5_~#ApI;#}a#Y=wg%`!{qVNzWh)zL`}!!Z==vnMx3qO!0YAajk+>eq~MnpH#vqu|2n9d1E&2 zZ@)Nb_W#7pYgdB#!q%5mfCs;oq${C9)hDw3@^Cd(G5#amE`7gJG{M+lNl#A+(1!1X z{WGd6j;TAn3e3{q0pGYb=6}#C3~nO~Q!7%=FFaRpP-=Sf&VA&8D(;H{DP}+Xp2&pG zRBeSfw>huNILu(VFJZz_A5?B*SX2NmTEg+PhrmqIwrS7ZIF#AcYA-3SX!{0pL5kPw zeBMqbw$ca8X9n~#M#8H0{3nZfacTdf?%V=R)Uuo;1B}-@+wcM#uf+Yia`3$I*24aq z#n7f-HnTYk5O{_biuDE&v|o#yq{v?Ifg|h-9COth+56AyT* zmcB+{lDNPrP=R`x3AATk1i`1XL%A#&o~;cCo%&+{~YKenmlSxqRm;k2BK zJN3bwcr_TqslJTA!HC&k!+gTOa4;v&Zk%NO*7u)4<~X!^L@4e!TT5nm<&SFG@*m?O zoAKlH>SNv3t-*)-TR*|gZS*$mkXo!N}oj2sP(O|4BoL$3e2avRWGvYz;S$}c3klDm-jqOY5VHQ&^rD#!iYtzyg_h)RDFyG}T(AFxbpZi9aat`d5Te&a ziwvYBZjFbOm95Q?(xUCJlDhq`a<$zPQfhUmK+5lbmr$K#5W01DCr%uDr!K_djc(Go zvQFGM!XC7^u}(xxdqXo*RxU<}%YR|Ulquq7I`vrfAP_GL8w+PA3LS?3*MPyv)Y#d= z&X$#v@gJT6fe`J)D6Akx3iiLpfg&!r%Q#N73kUD7ItC{fqyO&73S`uatLhqbTeL24)<=V<+HS*BY8;$TcSB`ff+arl4GOIZsOh#x?}e=)g%!2j|S2n7D!3kYO~ z#KcSgpFC|bQzwY)z`wO9|L6PzL2(~?I57VnUSu`}LmLQ(6A0vt^Y7tlC2W{(r=??989NU*cN}LwMD|xE{8J}850EP^pr4xv2mrA|g8oCw#S4s^ zh4cjR{4X*NKpf2g4yKPM2t&B+PLseiWPM#ZPe`&zU`==rhBy;|B76b(G z{23d76Z9`9K#=kIzXtz1vj7m>{D0{K|4+IBcmSY3lLEjE1pcdzlLvC>?jKQc|GN%C z@#Fk6RUl6(&_A33|D}fq_^(j_0wCD?Ka2p`|H9b+(=g=G2_fkJQ3v4uYvKR(`R|B< z>|EUcsspiega3>K2!gEpKRa^({^>PDGvria_CMzq$i)l#ml1A`f9vDoVgJ8&!T;kS zh=cQA&Ts=c{&WW7ALw7h%FXc?_Wz#||8G;m!@=`U2O;Cn0hyFPjc@?}YzP2A*70Aw z$$uCDu>;uuTrnUHcFsRn2P8JYpHl~dqyn$Wp9(p+x&9ml5C<>tA4vmo0mKRTR}w<% z{xwY?P9P6Q+|U>qm>a^+w6k-DJe47i{PjgCZTr~{at8_N?>h+pQh<|}o105Q9P%XO z HN+ACqA6HRk delta 28097 zcmYJab8sb0us$5yw(S$!w(VqN+b8B`gA?1v#x^&$t8b9L9>~)y$lqR2z;%PmVW(t#mGb%0!w0aW#3^_w8@S(9@8@9&rOcHGnBFwyZ;~#! z0lM97h)k}{@h%=+{U*M~wK$X6MbU6#T6xy*? z>?y7!R>@SPx`B>8o{SR0AO99DA6mWWt|oT!!pEhWDO{h3^`s{3?@`!#M(8Lg$UXzY3}A zVP_+ucRFIg?gD5yKQ5;}mC59Tk7IqDdi^gSW`(&spag1Lplb87UvqLKU~NhQG0lb3 zTiu4QnE#}?dF*Y=$avt4(Z3gnvIe9IPt=Wf7g8LU37I8i>_RDxwtm=*U(lmbX2#*P z(7C?a3GWZUsQWWKI}E?2n$I=^<2X2}PXMk6uJ9%0ICzh>IN}2M*2!~@oorWoY;R&N z^k*~&3SD`b+k7YO)$Y4J%uE+}4G?L&wjy8;ST6M$aR;ZQa(*F0cm^^5aOt}2xLHuR zHTr&=+`imQn0>!K@*NBot9Gq0Gpv?2-m@x>WJ6nQ-tGm#bQ=k%3AoaAqR>Qc7b{#o zra(LNHssC*r|v@6A1LGf8`{%G|F@CShhgpyOjW)N<8@MJL*AfCN6`ozUV*GKP{2mg zcbpoKqJY6CYB>#4@DLWi4uHzx3U5%e*ahQMYkfIQYcs9ioiwO-@?^(et6?$trc zCY{GI=Vu7x*Hk*hA(x9IaB~Hl*?D9yunslFA!iHy=d9q!RC3cKR_*fG)Z$`4b}3zgjjpbeWwlw#suu_OW3UG5!N0Wl8u7{WPzLl&IWox&V~SR zgVIn^z}cG^QF|aE+4#6XU-Wdq9=tzpo7@k1^>gh};vCdUp>e}ITkUe&Wh5#!8XzJv zjI=pbD#S$Xi~4H=QO6{K%s+~r`$Ld7H&0UYmRvD3&L&b{?~@11$Jy%v80BWkCvJ^C z8N+fIGk334vsQ(Qjem-=0?__&MiHO4PVQZhj3Iwn_)umA zZl@M^**SbWD!kOu6D5YENgY6rA(*P+h32D(=m(aQxsXn9VH@-W$JKoH@IQ>sZ* zN{toV?sCA8dwiR~h&9@v!Qzl-$vpKxb5|7-dxT^9N6-1MB*}yVqxV1^ih9FK?+3Lz z5E6P+J7jVCkB~w|+j%hbRwd+%s#X!@=%ab^=rcp7(eapLzwXhxp_&Cz$r(pl%Vw2)`a>s|=H*F%{%9X#N%%%3cgfbeC3`LmA(O{2U z)tOeTs5DnUVojcb_Sdmh8yPTI4qChVJNBgGdM9QG>_mJ&#Z|_`mybl~3Dhj%Uu z9nUVPT#?&X&0Jz!3klna|t z^mxGi9BA-BOQC{@GQWe`_Czx*c_e7_qRN>Dp}gc%Id}uyka=rNANW(CT6WzEITb)s z9=xcgMPvh5uf-w$HIv6Y1~&zlLxq`7b^P@p%Z*+=(q+#!jW2x5hW60tSPnSqEv(Z$ zYjhNrPBKJZsXk`RyG?O3#_SeE5*_rPjbL8PIW-9i`)a}^IvjepC5eHiZ6dYInORU7 z`$vrjiMxJmmRek_w9u>35=1*L= zp(;kCu9^K*|1sEuSlv}v4&l+TxQy5_W*4z+O%k)?z$u~mgyxdVf;>jZG7ySJI;UO$ zB0G3{$^&mkSUKd39qD6VVeI=H9e)*?Tw+m_}DWh1pP+iVb%32w`~!L=WA|0+_h$fvk=ra2Ro9 z1?Ke13{Os?+gmU?tE<=E*HMd2PfW2d>Jxg#0a04@`TaCy59nm2KC4xB7lQ#m*3YC*Pe=Kh;wKil+I$!WOT&-=d ztUGivF|D6<7hat*N5I+rbuboH0J z6Dm7y0VHSU-^qCjOqm$8Fw?sPQz}5Wec3&{zbg~$C>gp%(w~uMuLZ;e`TF2|X_ny~ zRFp^A2sqf@`n{e0tDO0O*Mw^aWKKzIhzV;nPVydQ@aBJ}y{5H4a*licn4qE=D4B@F z3yVw0oJ1vHSxNhp8zx}MEw1Yl-@prxu%7lK#?aad3v7}b5_y8lCC8G9+J*wFf>65S z!2I>{VmDi(s?bWB2A|Vi@Hisg2H8Bt;C(*wsOZt2$4}ayr^sV@4`%?Hgey#sDHYJF zfe`A2XReN13r=)^VmpE_VI(1iMDx1p7B{S6zN*wvJkH((i_XReRw8M~JFO)OF}v!( zr987&VC;Sa(e!e9$dpw`Ap$1R12dz#%il03JH zT00T5*#tHeb5j+Y13=4ul0H2q+yPflOcR>*=*Ptr(J$TyBiBgtg76 zGo=g*o*nBp4PwtQwu1~2KOA?UX|>m=o5e4)%O-8WADGLQI=JtJIRZkDJs=TRkt5e` z?DT5{f$lgit{!7-qKt?~h?6%N)4kj5FWW}jY47%Y1%zl_93Emhkctzib`L2L9k%CQ z&AH7L^}y4+)(LQHmJ0+SGMf&!s;Cjnw2HiN?)^n$E#hj^xV+o~b~W6SW~ z45d7dn0b>Y<=bEpkKbzV*6Sbdfe>TA7R~TS{gi~WWl8M%gNCg5W<~@TW%GGI*~0!k zBdXnicxT3;Oc#WDdD~r^9SU00{KC{G4L%aa2k_pC5?AuF6eZd zn$~d%=P2HfmXTszcd*Ln&kHw@g^Yo&S&_Cd7bWadpCXQTr{nc;I^Ph{e9PcX-Gpio zIGg}379JjMG7b)I77li9GER1G7H(dUJuwSNon#G?9RL6^lkz}wv+!{NK(?gbPylXT z_WvaxExHQso7`xSo?kg0n!!eWt zDs>r9XQ?;Wlpz-t&e!nOo~NZB1mcbM;6z>FsS|py5(R*w=6@?Fj4fMH$Pm zH_jP2*b3S+j5uON=OuuqG>Y_H35S}2H%H0Z;}&e04b!3X58l+@P$OGX*TxC%DQpEx zsEKW^xBI-F&x_mTTaU#|(TxZ2|AHJxgNPzmTmh0Wf$<*K_LGOyQD~LS%=m3Trso7m z=NEIh+4Wy|Th|#G4)WYI#1C?JDy48z8uc*z)6ra$e4LwYw1?YRBmjP!cu#D=qm0ST z^?&+ykS)W&pwEMg6KWrBMS7K?DSOV;v_rdtGpCr?{hrcb$zrW4Qr%W~h@a{Vvd|jN z+w@o5MaE&7O~aa2M)7&!Hw-gp$Qh|%ZK!od!7j?N7w?hx>S^0B4i<2ds{f=;Rm&)f z{w?CbR|#ZE7|sEzl`n~@1s5fO-Kb4Bd%U#^9|d_)Tbyv&dnHs}BiU5O9af1RS?%0u zY(e<+zo>{D>W(5G)p0<8<#&=$T3&&Wj2Q0xhP>RASbrNj+ALPssJeC~UKWFsziC zHhFk>INuexbF6Hre*KJm|0Pj*lKCvMcAr9&Gg}9I^$S~TFoFeqz>7}EK^dBpWCjw!X^fk<8UL1ev;1b_aalgS1|8n?%@Vm?35I(F z`Z<(U(G|mP6!K#3$dnLnPB_O!Xl1-yEFWfOMOOl*vBkC3+qtcB!;b1M5?9l6w^z~X zF&G0(kCL7#EhEyV)Kvw6_EtG18$E=axh11em^E*a1VSE_I%|JsY@o$ywWJUSjo=cH zn2K!^L%Cp~gPxwwJW+!?p_g2YTeczm%ZtIY3YYC11uns)Bc%+9{Kl@G8AIum`X-`W z2{dFBFcY*=MH33+({{m*oQWp(Bjrz9tqj6t^=Y{u$xVYv`H$a#m^bzv6v7Y(J?pI> zd<&J{CM$~PdBIoD(dA6~>lC`~?UH{V|&6)Z-KdzmbI_P3AlX zIbUx)5{%8r%@ckW$2=#ea{6)=-!f+*Qa7g(1LRlcN|IQtlX(3Yz@iif;8!E9iU5Xc z9Lx=f1zXCSzx(Zg%k+1UQ!3n3A;ZeU@JcOan`0lnWQs{W@7N}?wmFMdTOD5HSsGXs zDv#QPy?hbRBgd1tfr^@_KO$rFVZ+8DRn@{l5=VcCO{ds0!(F3&s7ZPeT<(AnGw3tn zuxRdxbZiv{r_J&P~-igx(f-XRY3$vfDP)n zG{jj3v)#Kks*wg13pMdlec(75?CuHgj+?u1SIKrxrT&_FvwEgLPLgecj%(6o^Pe6s z72@_L*A21|6O{Jjn-)04602Sf7~e4lYi-mnNAGj}8Z`b2=CT`TFKv6iha2?(N;MMr z<$N(+2KN-;lF?#SPfz?V;X}>}&)|zcH-+wF%Tg9UNqBxm^w2ki$O|^HHAt9?eHcRt zbNx>GJS$q=Nnh-0hUQ9&vjy!^)V=ZAUsA!GAMt7Us<$}Freg!Hwo-?zmI}(Vm~;|h z>Cd1hM3O5h(6`=Jm0Ll-(3#X>VR0=p@?s{Mz%LaT2mvW~7E92Fb-2}ay2rIV7X@Eq zJj){6>9V;G>ba`gzI31?)c-&ZCXVg(KH%JSw>VosmzErOs#{X?I9vH-3s$fH6oS7x z&luMAtbtQHq+K$u5?JNkr=ZR5SlmJiqR;51wA1shQ`kI$`rCf>%y(1hc{~*4l-)9y zAjnL77vPr?n+Oy`sQ0R zL=I3LfC9u!j|t1c!NJ1D#|t|9Kg`DYALawmu>XI0b}n8PK29!>`Tt>d9u{6+UQif4 zJt&!!A9O;G4ap1O{O=)T02;V&wqgX$*3VU-mRd1nK2H`~2=EE>$#Ep{E74y1kYO~k zk%Qv|AGG&wbPI@QQ6@n;!{K?*Cb5@%wbACA-CTdo$!U&kee zCBA%_GV?_f-Oz)B-AqVG>G66~CvsRY`NC6oY`XLPsIIyr$E4-jGf}zyBDW$h2aUFK z$y8Gi((xxY_d*%Y!0_Y>$i;nHTaRK+_`WE!kJRDzn!C9DdevJAq6k~=sma00G$kbg zd{@@;plW>GAxVLNT?RYb*E2~z$zHl8@CTdoJh7gqD5>2wv=>}p zq^6<$U;hk*4EBp1XEN@R9D=!-BCs0W0O{3EUg5WGfZ^ruK_rvrlC_FlhyFDpGCn+k zg8()W)H=n zx6%3En1s(XAT^mON`zBjryyaHS2fXd*dr{UBbY$Ahc{W#U20{I8L5Z-Gl!CRzf^%}`!8A&nKr}Cf zqklp1z~QXDYsqV0G}u{Ebf?l3}2*24!z~Py8jOrd|nsDd1$nQf~{P2Qi_Ob>EX_SW4}T9IsBZ z51hOE+cl|20HdSBbFEYF^d0rDxARqWvE9;Mr@g&)bKata+IjFq?U)e-3y3|({;5}C|Aby}FSf}Q z)t{y*RfDC})Tlp^wZNT9Dz?E)zug20X=m>odjGBq%Fo`swIqwo>>>RQN0GI|*Z~HW zwC>!!HQ}44MbwF0_nKEK>R0s$nX2HT{-vDg!B}{UpObeekE@LOB$2O>E?&5JuXy!? z&n_{;AR>mT=pP~wpDG+Ib|uq(7EzXFmox(o?uEAG|2rE;VGTy6-_;pVq{5Ra81kjyF=me}iMYED3m`eA#!Jfe=7p?MwrWj8<*@m+ zQ~I|6y9D9fVKN6>Lmht|ExjhQ@Y1E78QP_=#B}ZtTSZjEfs2`YYImO?ZVT;VISE_i{tLF%I=qkJl$!ZFV z8cTFpA$~}GIYUT^dNp9R;AgRvFtRy{XHH_lK4H< z+f+fM9KtISLhxktOZ5FHkbz{U{NNLWC3^)I?)6QDO`2D7Ac&_)TGxQko+ITFVmw_n zjIC8b%CgA2%<8&|`Ha3CPvdt@lCW~g!^)1TzxD}I97EdHX_^yJ`AH_|I&#dj8bzms zYYUUFlq{u3^|1b6IWv7W@(r#|O&WNc*4=5}O)f(WdNKb)*R zY{)n{dC2~^qBK$;__axf*7KKbCYB(oQlr)kU*CaXu@WR z{dagOJCnybl6(&i&SxX>Bj}QQbF34*dGH4{-YH6O8g-o%Bvd_sk?-_r51YH9ARO(5 z9ZwQI2Ue3!xuA80G5hjo2WVzI+y+vszC`QP`T4NP7I>-~hSL@rQ(D-swH_J@m9?GADo`p zhc{EALq56>TSQd#4}*%@L-_c2v$jF`)1P}+Vx?RhtPgMBl_3CT*$-&@i8%e7d8o)X z;h*}NX27V~C;?*k52(ZUKq5+na;!E%#Op`CNJ?xoIrc&qYZ#t?Ji~AgS1eB-=bOy^ zcVP7G`zvS%Gu;5TXYG0dYu8noSLc_E-*Uh)OqStynH-C>rQ`tr9&lZ zE>W_N%@YjH$L1ATM7??7ZV3vCMoRYzDxk)Y=|QKD$3fTJ-{4<*`$h;qoGjfv+@0i$kR35Ahz1=Mv?PuP z5)?;+K>gwr}0sffR@HEniPG7!7ZF%J(P@BiIu4l=g?6UhL)+#EchZ+co_O{cp@iE|qb(dHR1_NFp_>tcgZ zgX8AeTI*#=*e}OTFBy~X9q*YOy}#M7)+Zlo_Cn92Ev}dT_2t^wd<{kHJ&7^7=&D;Y zE17wjAu+II&Sn-z2PKx)l+I(!3iVK&?%*G(O+!hbI9>?kT;>Z0DdgM`K`_q(cu_1H zBvUgWIGek>`%n_3ll>j(Jg6KU!F3KRV!F*A8MVb zy?{SqLG8Us^tZjt4>Ghp2Nb9beO*X!3WV4!^*anO26$hsV5m8qQyUv(RS!U8D;vzX zJ|3iFZtxPAhJZ})V;?G*g@6HO98lif{3VWr`Ur{*igz6{p82a2d^AT_->`7FH z5RtaLZx%!vK!4i{BO%tRYPz!zsf(m2;B0GMe^!Irq?Oi7WnxQ|o zIl%P#MdC&`=5D|LTG&{aUETuk-s)G*`hn%|KroOS_s1pz!4z3-^1l}1#?9?@XW#OZrk8%&4;a}hXSnPGruu>K_h@!qE;Y5@Ay zA28|sN)-VXM;BH6uEM+gwi@`FRK2|>c0hKYX7aUz zJun$g0k3y=!`t=N0={_2zoCae@~!zKtYr|rgP(RgGc&%mKEGc+{>nY~^+&H0Y-WCN z@K4M{w$cF0FM$YOYJ^?9{9n|sCWw2^%ipeFt6Myg87#uan?_yunU|~eeb_(=>0W< zbzWbDOO`&NE3&b2bDE<ks!n z##BjD)A6+@R$^zFQdEu(MY(^!%ZKI-M7mEhI0_r`rV$fUnpDlYKczhtkw125fbidS9Z=`a{v8fv zq+zZ;iPRx4gkH$9=u)%awyb;lqxZcRUMTOh!HIq=sc@XU>%aTGWPiDQbtQ*sfhw7U z%a$QbVv|h29&u|!w32es0YwiAIZjBOz5nrE>G>7XY^o`+v?N(h>{-;L5tF`5o|C*z z_@^O#N+A*6r_*X^qu2#oby@{q0?8AY&@7&nKwKpOB7qKEvgWjC6i%(14|W8*@v@UL zv(M)4K9Y%D4<5m3Gz#DWjISc|GLU)oH~t`uAAdBKgW2 zlO+hM>w(Mv6Y8^!&!EO)H^Zq9aEXxGl851JY-#zp*&Zn>1Py^@^dq_NU8V`hY24vo zSKSr6yaIAqNpKY?VCwMWtpCa5=-d(xZ(BN=m~Sc3;LvKr)rB0ZBx;ix6z$&wBA5VG z`zH#)+*^cDRHH>x6hyp>K}uo08lN`GewJoI5wj;RLo7+c8;I~)Uq_K)Wys}yWU)#b zTpnu_K?E8rxC^>gHPkta0pw$# z!^~2{Vxs|V>1!Q<8w9Y-_W4{XG7f=nkMzb}ZEehz4gW!kjkreza7Tp?pae*F4R{qm z^0M0U`JY!BjQjtJLoXLO8a;V&KskP><(>0&|6WUHQpEViX&3CiZYX&ox8yEbSsaL) zpII)j9Z);+^%X;sjSvJ428fa&E_R|`q(2bQTd?`qY7f;H9stpa!D|Wcu3;$Cmi#7} z$tNXx1`;(C$xPkV0xPivNg9%rziiNv{JJWPi8g%*+xbAnUcW*PF}ihINQn{gVWS%M zATV==WnVKdX|>B~285-u4%&W%uJ`i~K^JNUO+f@)Zf>jXfXns;=aZJHQ5F4}#w!hU z;yfLTocXzODg{KN2Bytr9f?sR4K>Hy`}hjF2<}S)&(6;K`Kg@nR{CHMwy)->9~5$* z37_LKl%Il7U)-2foow9*6S>Vz-8V)^VMGc;D5at3RjP=aa+-8Gz6>O1r8~3;V{Wqd`M0FqZA09> zNlkybfj><^!5g6v>{7DSaKcPg+5kqg$M^E60AOv zi7uuuxqd)+K)8lX2Ma>y1OHx3M(=Q=1tSsN{Tae4iQvTyrU(GrJ@EWdSyF7Nc%TY4^A|A50q~pwi%9TD?qkrUWpO>JK@M*2 z`(9;}EQTOY6lbO^FC3?E9~Q0B549sGOXu=Xc1t&e@oJ5Cn{a~2!ZY>n%mgEd&d0yg zPv%YHNwN9mGFPD4k(XsH+Ccqm>Y^%OHECNH0wCjJP9jck0koi7v{E`0;8I zYY#+Eq?sF{!KU_Wxn#2DZsYynU)o?f7IG%xYz$*`d6-GXqxp}Y-gX@LZeI%&2aRbQ zG6ZQvpO<4vVHV)9P9l1w!wIhxnR>K~#yA9|$gRS?&H+3>2-K2AG?gKy8{)GTiCL3f zPMnvB+pm!P8#Ea<%-gylP|x}~7cE2VJAu2bp!D^Izoju;9gtpp07uV=7thQoEtK!( zxorh!8NP8LmW(!o0ib?SZmkn)1Otj`Sk0* zyGjJMMc0^q#{yGGE^r*PLNz1=Wj~P@?aL_e-%lO@RG!E-EVfuV7u6en>b=nxB(Tbe zqJG6kZ1uZW&3v?jdItMAT10ZGpx$5EQy>`r~(JqeeF4Y)0(e`fT$X%1wzyQ*e*juHZm@@kPf z8}_#CXVvn_U}XMvTt}Y>KVLQ71=`_MSq4MwL)H0qeuabh#9OV4^|%#dZEcD>_PV+F zc&sGB(FY%*sD_;UJBTE??50}u?h|RAsH$C&C-+SY43|*kerJ}DN~gm%Y+Rd2)R2y* zZE+mjAy7-({hgoL;a1`bX>W>fLcegEWG@yQ!*;?LTY1DhwTYsxgw;^P>}#Bm z+;zS_AC9SHp0iLRX4r{=+PhCAP6dF@Y%7 zxjZ+5iCtX+L~knc1W^uVm;|I7_|@25zbK@f4rB z1^qciWxmPvnsIL$%B|dv_;25jF|?YW^kit}GDsAQwSKQIfD%|mstmRBgK<3pj~adu7^0o0uT^`=k3Uj} zZR`nmoiI)bJ0EZ+eO!AG9xR;5N3H0rH&=Ud|G|ga#oP(+G%XOs`;7adjQ(7VL^psK zby2IU137pNOu~3`SlZPenjz@euTMMmV!zYlqTE-k9huOBf{u;FU&3fEL+_o4LxA#k zCZJhoxfq{iMg7(Eu+N8MvCY22@|qfBwA>4`|}EkZrHy=y5eUY zzn9ZQH^jA8-bLJ*Mrc<-_tRDLIxZ~6Y>}?lC%-k)a#(bvSHIa8@-D)h!Y_+v4^cDnA^R1&AGdrF>pg;A=u6_(t!(rqnmimLSIuHQ1(_z!}TKINWI*R8 zYH`t?>5Jklb_!0rGaP08Pj9yTL-{;vSnbk=ez{$4oSaqEu2jwZYhU*T=X4B+7j?pX za@bfORl~Fsep!n9KKJDeou6QiryG^f$u-TZSSR&gGI(yS zU8R=cbGuT!09a3!wIzA~3I45H*?-|oBI(Ww`B|*zAybv|e1Zc3%Gj1KX>M6Ej5&(p z`mn@=~p2!y9bm=NQ4Dl`}ha$82=aLl*-M#OHQzp?x+DjqZicV|w7Nr%vh1 zNH+RDXT-=rQO}eerx)LOA`(9w*u&qhn)*O|X(iejd(^Yy5b^140H5nKZqJ59Q?{~K zgW4V-GO@DoNuq`E-Oa|kyV3*KY#5D{xDGRXhH*2^GlEMzi=szk_qs$hQPC9Rm0 z!tavg$$SJIw-5H9VA>(HDg&9?=2rVlOJkw56?MjY`y$C|iUQ`QIyTz>^3Q|BuT8F7l7XX#=P70P zaWSqi8{&~6e?EB#dy3iktN~qV%^eWMOUV3L zco5_&V&~LUyl(x0X@i-FU5k;tH;Qr&aVol!*fhTY9IH9m#P|es!$*IAx@cTQ92Gf; zm2tT>#<+edxYyVxCur2-FMFY> zM0+=iX6u#ep3Oj&7D~jPBrFUtEKY!~H+NL8nCraXTDYXWt(H#qOBHn` zN+7#KlH!gI@J1cHxIU#FlPKou)X`YRq$KuW##c;q2C@cXR0vMwA_kA}6uwXofd)5k zz!FG=lqUVvleK0`BEW6f3HT2?VjFA( z#I7BI|BP&pJ=At0hP{~KG?cnpqyrbds@B6qNGqS7LpV0j!ZJ^2nN`UeJHesD)4kf6 zmd*>Vh`h8dfRwL$dVA$~M=#M@p&K}T!UFPI;z#9m zbzO|n%7v$?_#17o)O8QE?g@zoiXHy2b#L9RIjld!GD(-CiN@Xg7_q{d)I)jnc|&Fd zD>H3lZaod&lydxv-tmk*{MvB1NNVQkI~)besx;p0LXk#MlFLh2nKurp7?U$Dy(Wa_ zfIoqnOG+TrSr3&Da!PM^`T#sg7lRF9w3ziu5-%HHMxvOd3OFk^M*l^=B3TAzDS!wz z?Rj5R38JMdRvhP=ec156NbAUBcNs#lfIG2yk}^3uYCA!?wF&V63Dk73dYf6=_%2_( zuM)VV#EEhgl55|eDf|?=az%5U4J=`KU|(QU{`Wz~v`uS8B>0uy-%#0=;$Xua;=LYe z_T~Mi_DrG?-0C;3+&j)x>!@R>Src|iaLovpAl1L$*f)$UP`df>tmZ+%Z=05|EU|*A7@{|RZRvi3aD)b=D2k=Acln`%1=VELumu9uyl=_;N*n`|1V zOLli=b0>opB zJKbLi5J(HDr+3^mxHY&25WH^Vu5cv!a*TJ`n(7Z>IVH+K>j}&Y<_w(4eI{R8{BaM0 z4bN$;ApZe|*Q&25N*IByrj92s5e(}h6x?04$RmHdN0(5YIy6+*1;hlCu5IncyWucg z{3*mMl`3=jR*@CsQ&SX;k<0qFxp>~1Rq|p}zk&kw8a*g_W;r{9ut!*QA^Gl*0C%NU54L#|efa&BWkBI*x|1S5z2b!> zf(wSq|8Faz7!u0jBY-!;guiYUwXq!2uqKL~mki*kpn$ck1Hk>~%s}>Y*(WSWrqv4l z&DCrsqXLzG5sXN1kyz$l*V1*&W*_(UeffB)!*LOMX-$DR4;a!a)?tqEvuW+yF6w&LHGxHD*#gWF-58VL2f=*rW%O<=EhwOp4?m|8MRTA4!+*jyA8ODQu7|OuM$OMH-+jp z_Jrd`#HhtJavgic1Gt%TOv@r0oYvAXUh|uHTI7ddcW)Wv|^ImF9 zn{28ml4V~1naCzgXP$YvqNzZ??G7H(I%~X0`-pnUx`Y<(v{W0zoU3X-vX=XtB*u35 zReZ@>ypuRA+T8}W7^HLJ{Ba_B47n6MT@=+KJ9RPb{)Kmr@w*?Hg&`MzQdJx|_ZDv` zgo|S6z<|WZ%trAgZU{;olk0pDDi^PRP1F@VVGUAWc_H4QVg^#rv%BWAh;V}PV|xv` z7I&X?E|>tVeP`l(hTG*!ao}-!2^WFZVg6&>W5!Z6B=QflrZJHum?Rl5*1OyI?ItcB zW=b{s{oPAlP|S-{xG$dI8P1AdJ`oXDrIwULg}@v?mgd3AW&$=HKzmwKtTGXWYPeXz zX3D~;mu{Yxr0S$LllaWOR%aIs)@>V{h6r@uV=ew$K0W)tHbK$L*>z=)#gZYF1f>^( zWp9U?^N#?YsKMnnb}I;5ZVaIGAm&x-J+2u#I!gVa;cu(3Ug^(iw16ow_dQI1S8{y` zWZ+a=EeC7*ANK5v4d73k=y0)&suDcjhcUdLuu%n@ai&0laPGC|y#;kxf5L$XTGb~*^M(gSQOoO5_d zXx;-Azy6WcBsIb0H@ zGL?5K`YSYxhFqd{1JK_8u-0iHtazdV-hcG%+(?xR+36(Ip-eebgAV@lf2oupC8Azp za_(U3S&cWbIJ}xA$o)HjEMQ^AhfBVh*&F-87|r5Bm(O>>QGh1l@dSWVSzphgwCTvr zOb8WSXfayg6bl_gN2VaYAWrt^dA{F28%jr;jQwJ5?@cR%;0YH};goo42*zplj!EY) zPK461ZcIkW{8*zu<^$}-nM;g--QR7>!pT)TRqj&8(1TCG>o#TVrG-H}--oG&DO4l- zS|2w$$3QFuXwHvhX0?|%uL_7o$nd+11Vn$*s3-cs$6nfd>0Gns#^0XHdOr{bei-7@ zg?LfzC6BbR8<-Pf$HP@h8j=pOirIMRmLR>ci*fV6KlT&nW&?|bhU%COr_SrD4x{fd zHmF2G9siB)5hTTq<0qB9F8AqHqjMiyiG)H30Bw_sqqu$B=U?KZ@GxzOka7(I>bLSI zps;bdEcGm8&2WC+TY3cugmd|BXzt>V9Yyy>HEGUzsCXw|Di7#V0GPtyOpQmc%v7WBdC;0+^b#)Re$dbPr zdCIDBfC^=RM_r{dHxoiQ94K&5m0#PT!|xvK^#X|&ciLxzJBLS`E)Bl^ zPlQY3(hJ8GG>I3oJnLHmed_rR5rBl-cT-T$9WpSANfP=l5^9@8?p^dg6o|@w*xbS? zsrr>|X&PjIryW8hg779S9V63cvK59~5F4-w>ByWnFbP-5WbD1wj+8*TyXx%-uXD7> z|Njd4%BZ-OrrqF92o~G|!I>Etm_dRDclY2LG`J2TZW*OJXaeFt7vK${7pSBE81Nh!Ip(Kg)LJ{T!gUb)&@+y#h-i+~aa50jDzI z^}$k4+j@ye& z>k5@GgRzWa4YykT%SDtkUi}Z{5e&kvRAE}~i*K4aO-v^_65Y9Kw)w%gyFqd)_$j&=KR1i59Oq^8sWl9TOvl@yDOR67@QGC=B`5#x2gl)}%1dt-u8j7v8Yzc8 zf3%S{S`!ZXGF`6fhj*RL)|A}dr z?1?Kx@0hNSqJI&yK7EZ|nON}=NV*x{-+fVvQSS0yulQ2;l5}uD4>rsbRKhiPAInV=D$gyF5Qc=Ok$Aja37-WV(Av zOJys6Vt>r+McKVnKJhc-nx>eDD`obpoz=<0b5nKOo1It0Z&ciYJH<x1k%94{qvZ-H7-@MP7aR%IB1C z_JICAaQyA6HEYRRy$7PX4@lD1$K^+T58>GbHi{TQ3jt3uF|YTAVIE&KS;9`8?Ka0) zizc=|zJUf*yqPco?+~`#j5aIc5J-Ok>`J;5;P!6&Ha9D@?!HN@So7A}zx%s`F3@445dT1br#C@>y?X_ix4( zq}q-Ef1mnV`#6J8Vt!Npv@r60U~L`qc{sbZi+2;#7+##2(<3!S3E`{cB+z917Z5%w zry8wR1UOd9X%?(n`^J}XXPu?^=T9B9GA=pyWXB3&Wad*>Ga=Ye060X97Fx+3_=IBV;d6f*-lxzMdi%>!!pbJy8m*@aR?h*Z!$JFJz z&q!k8*AM%;F(EKDZ+~K&RAr7F7TzI{Q=5FE-5J`X&m5<9)SQ`jB4C3+0=0~iZr_u8 z@%qu&w|SxnryD={N9hY;T0Xw*SbL(LAzE5vXyn9;%T={#p|@9g5;L6x@D?vN_P!-z z+vCdj7zecCLAzP0NQHZ|-c9q4#xf(rhwX5&n2iJGp~6s=!H!FEhkd z$7d>b+a@dHxz0wW=?!7Ic={Hvjy9BOo=ZN*J-YBXTYV9O_b7>&R@@=Gxk5(eyqHHY zQ0IInf)5$?Vki0GBsfr6;Uk4Y=6#5kPHj5yi@E||81bkL!6vPTpORFRx;vXF z`|sLE;AzbISn@DKpje$9 zK1hghWC*pTH9U0a{tK3Jv>c|pbk`yiuF0Ml!^Ld!X z@bPX549Pgs!Sgg=#w`;-Y(}Q5zQ~fakE|UE(7fO*Bi}@an!bh|%bu&_W0LvyalI~m z9KN3T?2J-6Iij)Lh$}J*88hfb+eJlu zD(bZKxzqPWi?!1zqc0c>#$w+PTq+sj4c~U?D;&EXUGn>kMC|q0$_j{I(|rF6IInoE zX?k+xWNpBohgMuX>s?p9A)Bx~m3ziES5WY}jj>ACq@H7}B^*=-h>?;nh|G9kywl-< zk+Wg9W$HF&9gG;;EPf14Qx>M^P-lL+T(q~_Qj~i75Z)P>3OEkcWyJS>Efx( z`5h8Q2{hCQ3qs4JQ~!nGC|S|Y@l5PPcY3NS`}^n`Z9Qj57@rTLSuWZJL8D9~@E%Y}ITC1Rxc~!Fbj)l|I&@ zu+>Y=$-uj}miWljb^-TSZeC%w#1CVVkO0&*!(fa`1p{uzy6$Eohql838Icbeu+y3-urtM)jcI*@xtr5mFFQzuwoFBaTuj z(19B?KhkDiey04ID$^XK$Q<0`0^@vd&3rT3qkg-r&ea!sJyOhFwg0ux2)1VNGo-AB zFKY8W_rz+s+aq9F?G3UajPF~mhTP@2p_)9!QQr+Yx`D^Xyjo(s3{k6TzCt7aZ<5C9 z7veNu5;e-~Ekxt+Um(fQG0v>*cvnHZG&{ z;4v)wvFBHKVPmsVf3T|pk8ljE0jDmNV|e39-RS)g0pdlK_lvjWA?q*bW}T+t&?}`C zPN_L;{%F7a6)#&kJ>gvIY=<>>rSgJJ?H;qrlVD*U_`!h7(<>2Zwez)WLtkM3m0sjh zsY7N*ffjUHjsB!cVmvA=u(XqDK6|f?nE0^JQV^>k>r90%nvQ7k6pb7$BV5lSJ%>Z5@*0ZtZ6#^F3v69K2uA?P$q_ z#?O2){b|6RNXhz6Vy*V0Tp6j)C_!-ZUKqsH%8OZRFaNXSx%SMs)ai{+s<)i6=~1AU zbL+*10LoS|a|BsDp4X)-EUqeq*+lvsuEql9P=*Mf?K@Pw3|6=7O&6_T#4#om#I~vD zZ~n2UevavpDhHGO+Ly|C->3f2EeH#oEN9xW814P5h@E;8@wp+FqJYn| z#*#evb2nZ*Z&u@L8px|DM!r}-Am;?a(GSXs)!N6mdkZ98_o|KMVcFoy9c9gc*ecZ! z_0ohAco^7Aq6+(=_!TA!&e@@1fu;+O*M%vz6~~G26cmFKfWJrbq~HsF@!|M9278BV z5BN1Y@6FFn)cfUhbJQDQ)DLiz{c^5=t0(XL3BWKVQw~6p?%X@P1aA-YhOh<;sZ^q! zC!|2#=vV5avRsO+u$*u9o>Kky^1QI|pGkLWC|6Xl<_Zk&vJ` zsu&K+zl|r!ulL87Qls4~19$msXn!1d$Jj%kVh`jQif>{GgjI2eIUaKuP`+gsNvYJ< z(HN*?oGC6vd`Em(ZE2v2M@EvroV0ZQRnTqo#Y?rdixs{V{pOQkv^)Kb(CMHQk(9Sg zKd+GErOeWwaJGtLrphIJr=E~;(C6$u*P#wO^*i5b+HlQvn1X#a7@HvcafuOw%fRY~^nUe!9Ok7cu!Yy2dLe zx{fS}{!|?0GzeK}V<)5b+?Pr^9z|#Ru|In!7TyClR|80}axscVD6>o{B|USIW>peo+OvC& z)e)D5m(@#EiFlJ>hX5XieSaZIY4$Z?Lo^qYH1^OWj}-of>9Y)2vng#O$J|zxKAYS) zJpACZ)N>e*rSEG4Tk8zN-DiDysWv%8cM~AGdFlk)AEaaiAxx!c!}6=HDkIl#84l|y z-&{(_L~qC_C9~kXOITG7hIQ4+>o}n0$RvyE-Jaxs4!ZjuofquBDjCtMU@^%`vq^7{ z67{&;vB&7L){a#hwmj)u#!L=5Y_RxnW+W2|vs{CDjR%{Rbe-bs^llT*$-fYhvCf6E zVe>f_!aB)k*{m|n@GUD)MxqJ`my*3HOm(d#I~-fhi>QimNZXd+>O_q6H>Y!B81K8& zmM?znt9{(YbJmI*Fd?kJ6W0d+SO@($^QP=oFOR|2MQ$ZvuN)x z*Ox764&MD3P7bEAmgKK^UO<^*CGIH-e54F$y**4_yKo|Oy_BeN-CT$GwUc?_mE)+J9@)*H`Gqu^@c8SnYq;izuJb9j4| zW_!oSI16OziDndrZkj&ANcY}whR}eV>b_2##nQV3tm=@r(M_2~tD{)GD(_T(_)GzS zEe#78-JKT0qij_sX!XW-1sOn;9p+iyEDq<({@iMKTtS8H}CSWoqz+Iox#Miy3AuFdJ}8BbEyjaLfG7k+O&iPZ`+l-0p5!Nd#opm0r|hg|M5zcB?`v7xj}L0a*2GD9*pI2VXeVJ9{xqylo|w zb-39phCpxYZSq&X8CinH+wua#Bxcu5Erf5#9hV2k%iasHs4Gno20nNA;+(Q!wh=WW z;5gbMNmqE$$H}haaPKwtR^-mIzZy5A{E^i`%wjOzG3?@#-DD^94W}w`*xZsNY_5bR z2Qrm}+4oWI8OkNIdUqmar95`+fv1uvQB{#_LU~6lw$g{<<)p>I>?cF>;lxYgrrKGF zb;Ge@Lx^)(f(3Q2M!ALqUR^^a65H3N8%ow#SRvM-Vd=c$erdOCuIEZ8d17Une%pjk zaZ}r#ep`xs<{5e0%*ty-R$CkJ3ufs2?mD7`a$h*ES+)=Vr2%8a*_Bx;mjq7gbS*8( zw>&l#<85dmg9JNXV3D>sGKzl01tgNZ(H4I4NgPjU_`sH;Gsy4 zG<#V^9(F_zX4HHcAB0tW4I>|gK9Wwx|9ovD=nSkKEVaG;q)CD(GPgC^tkt za6M;qrB{!Rjx%#Pkb3Nw8t2h*Bjpt>u4l84o15Jx$9HnwD7bon8ZZ|R|1*6&HFRW{ zG$8&B?+M^^wKHkq=5S}#VynA=RY8qx@s(_3r|Qp$xl@}uqadr4w;;lyCsj6cNY6P< zh!y#>oIm*cZyYaBvum8cdeL>{JgC23uR!aXyOc{xd8^Dr=*n99Ob#!nXr}d>B|g31 zaSdmJWWEl$vuL7Lpg#;YW5rPePX1|g)3Od4Zy&@U{ADmF;t%O{mG8)S)$hIGzd5E5 zU280l#$UL#`NCIUGjyNg9W#r9cxOiiDQt8)n#)Z)gqZQv^Z3(pys-Q^T7!|bW?urF_t}!dv%A@Y!BX0+ zM(MiC=d^;EudOK8DqS~vPo#9Hj4h_2(Y3Hd^KWLeczXfgLXBMjR=s6+6drAGwPy0)`h)ZM(_r4RCENYVk zneWZxrqjcqDX~!4{1j%{*Tsotg$~y_YIgPW1e=c5X?<3wyuxIuF=_SruG4VIBTRqA zMWGgXJm7J;z)WRQoZLdLJlR?!4yT(zY{IJG0rx_a;EW=3HA-Xv9SwQD3l0s7KjcR| z(d2~59AH4IU{#%o0gyZVLX|J}O<$YC8S!`C<)+sa(GqL0HRH*g)%vlbB;=?Lls8Lb zhnLV%!cRl${J3?Y=_37aLKr*pvn%R**T&=U*4$7BhZLed#9+_4vm139y>vQy zyEWHEMY&NB=&5)Z!!P-XU2f5JA}?2b*3L``OdYP7+74@>-L}jNyTfw%_0V zXzFvs4+in_z;fp5P>no9z9;?QBe-@FhKfq(E?#~_fsDUq2Jf6q*bobC5bCn|CuEWL zCw3fZPF75$MUT^;EixDt#|19m^{s@p^gX6)OF5#}+f{9?fnUG)xgsK0D*bxD@`^VA z^*md+NGw_CbrZ3-XJvvbM3d%)kp3aYQ0vHxWkmn4l&y#2Cz5=Z8Hu}XQ zZui7ZoFH-Sj##EKGz)U3*p(VbUVH5rrjsjQM5tBhi~Z>%GFpyYJek;EXL- zcJ61}y^1SyNGoAE=j@ZXyU!Gm?&=GdD1DkL2Z4niR7m+06)R_VeBr$DDyLNb%pNs6 zC?s;gJC^$P*E8%>&oQi}y(g%ZHr=k#;bTL=IEnxvfmcX&mu`txUt2w2d6_VO_HL)@ z!AO?+RSHhl@1p#?qD++*_x`E?f4K{Np{ylJB-Dm%VB5yQmOCSP>nx{>28*7J#Wr|% zT)_b*Og*suRIS^`qZ7GDqKcx;8PrUvBrTzkR);SD6CEn5e8jwEP%njL->*e0R|AQh zP-obk8GgOp#Ll@9J1{ECjpa8#L_z;`vn=o_CEoh#xaB!FV~#mi<0tIFpzCSew41kN zgX3%In}%UN)1I|{i&n`7Cgg7xp1VKGC{b>L6&X=kxx2Kr6UmkpI#NF^Elmg|v%Fol zt8Mgp#8zm%Z(&pS0&YuG6;(czvtsFLRMRWRRa-hX(ys2^JjXeW{2|d!J2R;ppp52Q z->hS>rHs)8xs?C5rY=#Q((KxeH2BsR9`8y(eVSD$%_L;rs-fd%L%_zIxXjTNc_qcl zX+gzMpyiKM5oj38n_(Hgc)-%04V4<(w7U#TNoUSYbN?1obA~>GgUR-KXRxkK{N=HV zQ&!bN8Q~8F3V)WF&cFahu+|hm-Nn)#ENRz@w(aC&zi37UCREh^MtYp_iH=Tio&1e3 z&FtGJB<-xG0_ecwmnj%`$wSB@uKLm-|DtsfW6)3gJY*Xh_}w zHK(!uLLbo}5a7%@B7c{ydmiRXo#oKze`D5au)j!|9FX*M8gtt&PS~|`AFV^}fTYWD z5<3Nlr7L`_f|x0`Vv@$g1V6kOSo zHjORbX&M*KiT}e@S0gSm7=T=l0(*P6<%|CPl=J2eHMt${;JK;-x@)pdLlWmzGrv9c zD+r95?i(Zjy0E?~>i(;m0R^Wz;5yz1rHM5oR>>RhGM0&nnj36s-)D~=rq=2G?r6Bi zWSs~Cqks0-W7;|%*=)HHNQG62@EeE_RVZ&nr>gezVNjYlR@e^!^M@=*p|BZht7*Uw zxt5URrAyFU-j{wnD3O|eV=z(x1!skg5(5|PvnqR0uIrYA1HX2XAiT0SU^(g|L)e(1 zMPFsfqqED4rmRF;J6@qySCR>Fb43N6LduVCwv2Ul*lq_NaNL~)H9aGdIJ92V3%8^u)J1^(=l(~PB2YyiuKP-($+mJs|NsD0=nA84Qf@VOT)HU&{uExauzMdtq z`s6e4INK)}9?v)b5kcPK+oV35bywekiUj5ommhs5Z z3UOGm!PrIcE$Y*N<`d#_SnlzmG`rzk4!_~Y=019O`Y(4qyRglf;aSJPR9l0p< zAD=Uaf*o}nS|u+YP8vtMaG!KH;#*-)hY7332|+gKHqgH>#C>N?faUvTEAO}rMZY-w z(%BrQ!PnUxz9^$bXz=6J{#(kn8%|;jCDKowk-zM$TUl^(0&03Lz|X@yX(x*-Q>SzT zaeULX4Xi!)(OhVW^g}itaC$HVuH-}X^ji|tbzUlphO7w7WgmRvsKLyK#4Vdn_3>}v z8w=#r$*oaS@$5C%PQq|P=bjHnhE;uzWLzNlq*p$OWHJ9Fb|R50*m0AK>nJ>!JLK-@(_`TZ3iEVDXV1A&e3oQ0l{J{ZY-W5J?hAb%u<`{k zX|iv~GHGq4Pn5L3K6KRle0;}J(iZiwGPIIbJS{C+Q0yQ(^0PA_%KtmC`seP$SG)<6 z7~a*oc~z%7=f|uyUt46-MKxr1 zp@m>D1q0ZiR6OK@xnYhjB}^}vK0Gb?NwMwcuvsr5Zb|D`j`4Wl*dd{DfZ$;W0hW=*^M7sr0vv)>!0I8*lgL2v+mSp{gmgb}v;EsWOaC!UF(> zB~lRRSconc)(}`m+8XtShHR(H0$sYmI=NduU8un8*el_=HOn0(rLfVFKvgBBU_krs zsh9=i_VzN@(yLxgFuscnnGjr^I70-a6j1by8Y6jDsDUC)P*e0xp);Wxtl@mlx_!g6 zA+}U}e&U>1+DQyc<}bCK9^#>ul4RfYCM5V})_YV2tFsDa=2tO2&B!_$vz^!iG11wJ zC!g!F0IhIe86GKGvbbQbAaga4H|L=0kO*kqR%4JJiN;T|%J_c@WBdNYQXJ)afJ)LT z0ITHV0e6q(cB5YcDj!DQO>>K@Rua2wu?5o2swO|sHp{Dx=^5c<+s`T%r5{}OyiO4@ z4%2$Eu!9ncODuR@xCvi;arwx0hbOsk!#a61nhG(_%ypq`!R#}6eIFRRz)quD3s(=htjU>BH6CcIR zs9_j4EklkYF|mWOC(#^Oei>)sW=N4@zRGkA&*)-?rAXrG^aNTd%ewi=zAeGuXd1&Gl_8BO^iV*`PP!03MNPr+gZ!5A5VPG&SE~j0YO8LM z7U7T#Ly0*LgB}5+<^=YKj#jhrvaIB1VaI1Mq!o80Lub!tm?$IYawLP23Q3kxJ&Zgja-ccSDHt~L>rVEELAulCkYbo9c;9!Q8o_kz5lE%fgA#BTPTVJ6-{YL$G zt6I7ueH9E|c|+kODJc%uBGCVS<$e%0N*C#`xj1NGI(cfus2>6568G#& z9SB8fl)LyhjHCO_{oc)BD5T<>a2OX|dXd`<)^@FoGG1ghO4?vkNgtRw_f5Ko*VMcF zsgW~|6QMwlJ(c^5YKtY~`2+`8bWjtM`D13qcOxC&zN2O8xK7whwr=}~j=tKdLG9&! zh)=Kn)K}URTHSuluiV2oc4`$<0#vONQ)PCso@H?}sF$9T4%&Y(or^Y^}aFXb*NP;zO?rS>yZaCt*$92+`f-XM;f=Wyn*nu1%r0H^|4NCARjX2@^ZBz85s z7#nl@;xqi?YhlCqdQ5=v5BdgNB+;c)^N;k+ zv)o^oUE($l@;YrQfTOj z0$=X8fg2C_A%Wn_1FS^+(ErQ+B_j`1$|t z*gptB;)P!gG7r1J~XB&Nyp-1VdiS%=)lFxO2_?= z4-64pPB!*7t}b-?{{ymdfmr{$=f5q3z?H@+;lAT~NOW+TiKl%3ivljb-{aj(|1%jv z;lGtY;kXktaPbKNgpqy|^zgf{c=Yl%<_IG|z<(IE=s-Zef5@#sK*<05g(8+i1>c#V zhG&i8;=QzRLD&oe{^MA<=r}nXGRZ>lk0-GKN+$LQCN2;N2zQ(mfa6Ty!fPk(us|RP zh#SF^#Rq4bqWG_x;#4{!OuJLuB#3bSE_4ob*#BIBp-^5PIB;5!1YyJ<2!xLx9x%=S z6vB(};~y9wlm|YBz@VVNF<|x z|AHad%n4?pWI!O_-ynje3vT=y1abc_AU7|(;vW$DH;AwxVGc2n`)_j~{5VxngQtNkthkc`i@gOqjcll4yfnf0O`}$vPU$5fEO)jK8M<|JTF_m;RX(Kt6u{Kf{9998BhjV2A|#6G7~Rf8_>{|2GN#zn24q z0ue-Wf3)#Kp?|i4xWV8*$AY-IA-`P)XI{jE0ePT*x&@JA&_C}M5Dy6QXIw!%yxf0{ zcITme1Err`TjH-%n#%J z%l%+}zQ5d$*jD~>H6q7(|4X6k8xtEli#OOpLUaIi8*dB5=E;L#HFR`zMO-2J{pL87 zb+B|q)DX-1r-mRTG#29K;p3460-?O(P;ux>UP&oFaS5md1O(-N34-v8i3!vF|GOB{ e2@7MpxSG6i^?YMtiOmZH@$q0YF-a;*VgDb3{y!i9 diff --git a/RELEASE-NOTES-BIND-9.8.txt b/RELEASE-NOTES-BIND-9.8.txt index 2b536ccf59..1d24e545eb 100644 --- a/RELEASE-NOTES-BIND-9.8.txt +++ b/RELEASE-NOTES-BIND-9.8.txt @@ -2,7 +2,7 @@ Introduction - BIND 9.8.0rc1 is the first release candidate of BIND 9.8. + BIND 9.8.0 is the first production release of BIND 9.8. This document summarizes changes from BIND 9.7 to BIND 9.8. Please see the CHANGES file in the source code release for a complete list of all @@ -84,6 +84,24 @@ New Features tkey-gssapi-credential and tkey-domain behavior). [RT 22795] + DLZ correctly deals with NULL zone in a query. [RT 22795] + TSIG correctly deals with a NULL tkey->creator. [RT 22795] + * A new test has been added to check the apex NSEC3 records after + DNSKEY records have been added via dynamic update. [RT #23229] + * RTT banding (randomized server selection on queries) was introduced + in BIND releases in 2008, due to the Kaminsky cache poisoning bug. + Instead of always picking the authoritative server with the lowest + RTT to the caching resolver, all the authoritative servers within + an RTT range were randomly used by the recursive server. + While this did add an extra bit of randomness that an attacker had + to overcome to poison a recursive server's cache, it also impacts + the resolver's speed in answering end customer queries, since it's + no longer the fastest auth server that gets asked. This means that + performance optimizations, such using topologically close + authoritative servers, are rendered ineffective. + ISC has evaluated the amount of security added versus the + performance hit to end users and has decided that RTT banding is + causing more harm than good. Therefore, with this release, BIND is + going back to the server selection used prior to adding RTT + banding. [RT #23310] Feature Changes @@ -165,12 +183,20 @@ Bug Fixes * The Kerberos realm was being truncated when being pulled from the the host prinicipal, make krb5-self updates fail. [RT #22770] * Fixed GSS TSIG test problems for Solaris/MacOSX. [RT #22853] - * named failed to preserve the case of domain names in RDATA which is - not compressible when writing master files. [RT #22863] + * Prior to this fix, when named was was writing a zone to disk (as + slave, when resigning, etc.), it might not correctly preserve the + case of domain name labels within RDATA, if the RDATA was not + compressible. The result is that when reloading the zone from disk + would, named could serve data that did not match the RRSIG for that + data, due to case mismatch. named now correctly preserves case. + After upgrading to fixed code, the operator should either resign + the data (on the master) or delete the disk file on the slave and + reload the zone. [RT #22863] * The man page for dnssec-keyfromlabel incorrectly had "-U" rather than the correct option "-I". [RT #22887] * The "rndc" command usage statement was missing the "-b" option. [RT #22937] + * Fixed a possible deadlock due to zone re-signing. [RT #22964] * The TTL for DNS64 synthesized answers was not always set correctly. [RT #23034] * The secure zone update feature in named is based on the zone being @@ -178,6 +204,16 @@ Bug Fixes processing for "allow-update { none; };" resulted in a zone that is supposed to be static being treated as a dynamic zone. Thus, name would try to sign/re-sign that zone erroneously. [RT #23120] + * When using auto-dnssec and updating DNSKEY records, named did + correctly update the zone. [RT #23232] + * After a failed zone transfer of an RPZ (response policy zone), + named would respond with SERVFAIL for subsequent queries in the RPZ + zone. [RT #23246] + * If a slave initiates a TSIG signed AXFR from the master and the + master fails to correctly TSIG sign the final message, the slave + would be left with the zone in an unclean state. named detected + this error too late and named would crash with an INSIST. The order + dependancy has been fixed. [RT #23254] Known issues in this release