kubernetes1.23-scheduler-1.23.17-150500.3.15.1<>,f'p9|E\=EvF ªA*^AǾ ^E*}/(& $\˳sg~rs_C]\XaD~zAYц67Ge0Rw?hiFgb~bNwt\JliV25Ψ!jVC^ɠv A%Y$.p8T՚dkm 0N 3%_I]92Yڗ+tX!>}R鑱N1t|(f©@@ Hn>AN(?Nd# 1 Z %<BLh v     /R (89D: FHGHHIII$XI,YI8\Il]I^IbJcKUdKeKfKlKuKvLwMxxMyMzMMMMNCkubernetes1.23-scheduler1.23.17150500.3.15.1Kubernetes scheduler for container imageThis subpackage contains the kube-scheduler binary for Kubic imagesf'ibs-power9-15ESUSE Linux Enterprise 15SUSE LLC Apache-2.0https://www.suse.com/System/Managementhttps://kubernetes.io/linuxppc64le( ;,^܁A큤A큤f'f'ccf'cf'ad3c669c8cad3995c7f804459212c7c2b80aebfe26f323c385e6636e6a4bab56639af1c94c39ded3a781d1f82c7075b6af898b7bb6d284ea0313278568c542318b6974720f4fb31199e971a20a4a21cf3987708b6dfa6a0a1f4775e381b970eecfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d305ac951c5acd868dd9de4f935cd6ed733706f40703e283964bef68a145b435f91rootrootrootrootrootrootrootrootrootrootrootrootrootrootkubernetes1.23-1.23.17-150500.3.15.1.src.rpmkubernetes-scheduler-providerkubernetes1.23-schedulerkubernetes1.23-scheduler(ppc-64)@@    libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-1kubernetes-scheduler-provider4.14.3f@f@e}@e7@edd@d6@d!@d!@ddb֜b֜b֜b֜b֜b1@b a@a*@a@priyanka.saggu@suse.compriyanka.saggu@suse.compriyanka.saggu@suse.comdimstar@opensuse.orgbwiedemann@suse.compriyanka.saggu@suse.compriyanka.saggu@suse.compriyanka.saggu@suse.comrombert@apache.orgrombert@apache.orgpriyanka.saggu@suse.compriyanka.saggu@suse.comjkowalczyk@suse.comjkowalczyk@suse.comjkowalczyk@suse.comjkowalczyk@suse.comjkowalczyk@suse.comrbrown@suse.comdmueller@suse.comrbrown@suse.comrbrown@suse.comrbrown@suse.com- add new security patch to escape terminal special characters in kubectl output, bsc#1194400, CVE-2021-25743 * patch file - escape-terminal-special-characters-in-kubectl-112553.patch- add new security patch for bypassing mountable secrets policy imposed by the ServiceAccount admission plugin, bsc#1222539, CVE-2024-3177 * patch file – bypass-mountable-secrets-policy-imposed-by-SA-admission-plugin.patch- add new patch to advance autoscaling v2 as the preferred API version, to fix bsc#1219964, CVE-2024-0793 * autoscaling-advance-v2-as-the-preferred-API-version.patch- Use %patch -P N instead of deprecated %patchN.- Add kubernetes-sort-custom-column-print-flags.patch for reproducible builds- Security Patch Fix for CVE-2023-2431 (bsc#1212493) * added patch: fix-seccomp-localhost-error-handling.patch * this new kubelet component patch returns an error when a Pod or Container's SecurityContext has a localhost seccomp type but an empty localhostProfile field.- Security Patch Fix for CVE-2023-2727 (bsc#1211630) and CVE-2023-2728 (bsc#1211631) * added patch: kube-apiserver-admission-plugin-policy.patch * this new kube-apiserver component patch prevents ephemeral containers: * * from using an image that is restricted by ImagePolicyWebhook (CVE-2023-2727) * * from bypassing the mountable secrets policy enforced by the ServiceAccount admission plugin (CVE-2023-2728)- add kubernetes1.18-client-common as conflicts with kubernetes-client-bash-completion- Stronger conflicts for completion packages- Split individual completions into separate packages- update patch files to reflect upstream registry changes from k8s.gcr.io to registry.k8s.io * kubeadm-opensuse-registry.patch * revert-coredns-image-renaming.patch- Update to version 1.23.17: * Release commit for Kubernetes v1.23.17 * releng: Update images, dependencies and version to Go 1.19.6 * Update golang.org/x/net to v0.7.0 * Pin golang.org/x/net to v0.4.0 * add scale test for probes * use custom dialer for http probes * use custom dialer for tcp probes * add custom dialer optimized for probes * egress_selector: prevent goroutines leak on connect() step. * tls.Dial() validates hostname, no need to do that manually * Fix issue that Audit Server could not correctly encode DeleteOption * Do not include scheduler name in the preemption event message * Do not leak cross namespace pod metadata in preemption events * pkg/controller/job: re-honor exponential backoff * releng: Update images, dependencies and version to Go 1.19.5 * Bump Konnectivity to v0.0.35 * Improve vendor verification works for each staging repo * Update to go1.19 * Adjust for os/exec changes in 1.19 * Update golangci-lint to 1.46.2 and fix errors * Match go1.17 defaults for SHA-1 and GC * update golangci-lint to 1.45.0 * kubelet: make the image pull time more accurate in event * change k8s.gcr.io/pause to registry.k8s.io/pause * use etcd 3.5.6-0 after promotion * changelog: CVE-2022-3294 and CVE-2022-3162 were fixed in v1.23.14 * Add CVE-2021-25749 to CHANGELOG-1.23.md * Add CVE-2022-3294 to CHANGELOG-1.23.md * kubeadm: use registry.k8s.io instead of k8s.gcr.io * etcd: Updated to v3.5.5 * Bump konnectivity network proxy to v0.0.33. Includes a couple bug fixes for better handling of dial failures. [Agent & Server](https://github.com/kubernetes-sigs/apiserver-network-proxy/commits/v0.0.33) include numerous other fixes. * kubeadm: allow RSA and ECDSA format keys in preflight check * Fixes kubelet log compression on Windows * Reduce default gzip compression level from 4 to 1 in apiserver * exec auth: support TLS config caching * Marshal MicroTime to json and proto at the same precision * Windows: ensure runAsNonRoot does case-insensitive comparison on user name * update structured-merge-diff to 4.2.3 * Add rate limiting when calling STS assume role API * Fixing issue in generatePodSandboxWindowsConfig for hostProcess containers by where pod sandbox won't have HostProcess bit set if pod does not have a security context but containers specify HostProcess.- Update to version 1.23.9: * Do not skip job requeue in conflict error * kubeadm: fix the bug that configurable KubernetesVersion not respected during kubeadm join * Bump cAdvisor to v0.43.1 * Fix: filter out unsatisfied nodes when calling AddPod in PodTopologySpread * kubeadm: fix the bug that configurable KubernetesVersion not respected during kubeadm join * GIT-110239: fix activeDeadlineSeconds enforcement bug * fix: --chunk-size with selector returns missing result * Fixed winkernel proxy failing to query v1 endpoints created by dockershim CNIs * Winkernel proxier cache HNS data to improve syncProxyRules performance * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.8 * apiserver: printers should use int64 * add missing error handling steps * add missing error handling steps * fix image pulling failure when IMDS is unavailalbe in kubelet startup * fix: exclude non-ready nodes and deleted nodes from azure load balancers * Avoid updating Services with stale specs Fix the bug that service specs in servicesToUpdate may have been updated by clients. - Require only BuildRequires: golang(API) = 1.17 pinned Go major version. Remove potentially conflicting BuildRequires: go >= x.y.z. The plan for future updates is BuildRequires: golang(API) >= 1.17 minimum Go major version.- Update to version 1.23.8: * Revert "Automated cherry pick of #109124: Winkernel proxier cache HNS data to improve syncProxyRules" * test: update graceful node shutdown e2e with watch * move the ignore logic higher up to the reconciler * Ignore EndpointSlices that are already marked for deletion * kubelet: Mark ready condition as false explicitly for terminal pods * agnhost: bump version 2.39 * Update Go to 1.17.11 * add service e2e tests * kubelet: add e2e test to verify probe readiness * kubelet: only shutdown probes for pods that are terminated * kubelet: Pod probes should be handled by pod worker * Enable resize feature * Reject proxy requests to 0.0.0.0 as well * ipvs: fix prevent concurrent map read and map write for 1.23 * cpu manager policy set to none, no one remove container id from container map, lead memory leak * fix audit union loop variables in closures * Updating e2e test to check EndpointSlices and Endpoints as well * e2e: services with evicted pods doesn't have endpoints * e2e test for evicted pods * endpoints controller: don't consider terminal endpoints * endpointslices: terminal pods doesn't receive enpoints * add pod util to verify pod is terminal * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.7 * Add test for checking ephemeral volume expansion * Fix resizing of ephemeral volumes * untangle fix with healthCheck feature * Winkernel proxier cache HNS data to improve syncProxyRules performance * Skip updating Endpoints and EndpointSlice if no relevant fields change- Update to version 1.23.7: * Fix requests scope classification * Update Go to 1.17.10 * authn: fix cache mutation by AuthenticatedGroupAdder * GCE: skip updating and deleting external loadbalancers if service is managed outside of service controller * Wait for cache to sync in job's TestWatchOrphanPods * Fix OpenAPI loading error caused by empty APIService * Test Foreground deletion in job integration * Fix removing finalizer from finished jobs * Don't mark job as failed until expectations are satisfied * Integration test for backoff limit and finalizers * component-base: replace url in rest client metrics * fix broken find command * Allow KUBE_TEST_REPO_LIST to be a remote url as well * Disable JobTrackingWithFinalizers due to unresolved bug * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.6 * Correct event registration for multiple scheduler plugins. * kubelet: rename closeAllConns to onHeartbeatFailure * kubelet apiserver: be gentle closing connections on heartbeat failures * fix: race detected in TestErrConnKilled * Replace hardcoded kubectl with kubectl.Name() * kubectl: fix hard-coded value in zsh completion * kubeadm: add etcd flag for member data consistency * Fix a bug that out-of-tree plugin is misplaced when using scheduler v1beta3 config * ipvs: remove port opener * iptables: remove port opener * azure_file: try to get secret namespace from ClaimRef * azure_file: add namespace tests for InTree to CSI conversion- Update to version 1.23.6: * Update Go to 1.17.9 * Fix: abort nominating a pod that was already scheduled to a node * Fix the overestimated cost of deletaged API requests in P&F * omit enums from static openapi snapshots used to generate clients * Drop enum tag from certificate request condition * Addresses the issue which caused #109115 * Add test for indexer with multiple values * Reduce number of pods in Job+GC tests * Adjust validation checks to pass for both client-side and server-side validation * Remove finalizer when orphaned * Fix: Clean job tracking finalizer from orphan pods * Add test for Background delete propagation * Add integration test for orphan pods when there is GC * Copy request in timeout handler * kube-up: use registry.k8s.io for containerd-related jobs * kubelet: If the container status is created, we are waiting * e2e: Wait only for the service account * e2e: Wait for kube-root-ca.crt to be created * client-go: update generated * default kubernetes agent for generated clients * Include pod UID in secret/configmap cache key * Move kubelet secret and configmap manager calls to sync_Pod functions * test: Verify that nodes do not transition to Failed while ready * test: Add E2E for job completions with cpu reservation * test: Add E2E for init container pod deletion * kubelet: Delay writing a terminal phase until the pod is terminated * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.5 * generated: make update * polish comments of non-enum values. * unmark non-validated types as enums.- Update to version 1.23.5: * Remove apf_fd from httplog * Update Go to 1.17.8 * cluster/gce: update konnectivity image tags to v0.0.30 * bump sigs.k8s.io/apiserver-network-proxy/konnectivity-client@v0.0.30 * fix dryrun when ca file exists * fix regression introduced by PR 100320 * Add unit tests * Fix nodes volumesAttached status not updated * Fix default config flags * test/e2e/framework: include the new control plane taint * kubelet: Clean up a static pod that has been terminated before starting * Add an e2e test for updating a static pod while it restarts * cronjob_controllerv2: do not filter jobs to be reconciled by labels * kube-proxy: fix duplicate port opening * increase Azure ACR credential provider timeout * Updating EndpointSlice strategy to retain node name in topology until field is set * fix: do not return early in the node informer when there is no change of the topology label. * /test/e2e_kubeadm: adjust label checks for 1.23 * Ignore container notfound error while getPodstatuses * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.4 * Add PDB selector patch integration test * Revert v1beta1 PodDisruptionBudget select patchStrategy * test/e2e_kubeadm: fix matching UnversionedKubeletConfigMap defaults * kubeadm: fix the bug that 'kubeadm init --dry-run --upload-certs' command failed with 'secret not found' error * wrap error from RunCordonOrUncordon- Update to version 1.23.4: * Update Go to 1.17.7 * Use serializable struct for x-kubernetes-validations in openapi * Make JSON schema round tripping test more strict * ignore CRI PodSandboxNetworkStatus for host network pods * set secondary address on host-network pods * Deeply copy JSONSchemaProps.XValidations. * Ensure the execHostnameTest() compares hostnames * Revert "Fix comparison between FQDN and hostname" * service REST: Call Decorator(old) on update path * add namespace in azurefile volumeid * fix: azurefile volumeid conflict in csi migration * Mark device as uncertain if unmount device succeeds * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.3 * kubelet: fix podstatus not containing pod full name * Fix bug with node restriction blocking pvc.status.resizestatus change * Fix regression pruning array fields with x-kubernetes-preserve-unknown-fields: true * Set max results if its not set * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.2 * Update k/utils to v0.0.0-20211116205334-6203023598ed * [go] update to Go 1.17.6 * fix: remove outdated ipv4 route when the corresponding node is deleted * fix: delete non existing disk issue * Revert "Automated cherry pick of #107554: Correct the feature gate string for RBD migration." * fix containers order after applying * generated: ./hack/update-vendor.sh * upgrade sigs.k8s.io/structured-merge-diff/v4 to v4.2.1 * Execute sync before taking the snapshot * Correct the feature gate string for RBD migration. * fix: azuredisk parameter lowercase translation issue * removed unnecessary log line * kubectl: add integration test for result reporting * cli: let kubectl handle error printing * cli: avoid logging command line errors in more cases * Fix header mutation race in timeout filter * clear pod's .status.nominatedNodeName when necessary * use node informer to check volumes attachment status before backoff * When volume is not marked in-use, do not backoff * kubeadm: remove the restriction that the ca.crt can only contain one certificate * flake fix: remove the error handler for cronjob integration test * Fix the leak of vSphere client sessions * fix nil pointer in create secret commands * Fix order of commands in the snapshot tests for persistent volumes * client-go: Clear the ResourceVersionMatch on paged list calls * Improving performance of EndpointSlice controller metrics cache * fix the error when cleaning up jobs for cronjob * Update CHANGELOG to add missing release notes. * apf: ensure exempt request notes the classification * Enabling kube-proxy metrics on windows kernel mode * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.1 * add gce loadbalancer no-op finalizer and existingFwdRule tests * disable gce service handling if has rbs forwarding rule * add ELBRbsFinalizer * add gce elb rbs opt-in annotation * cherry pick of knp 0.0.27 * Remove JSON logging performance regression * Re-introduce removed kubectl --dry-run values. * Point flowcontrol users at v1beta2 * [go1.17] Update to go1.17.5 * dependencies: Update golang.org/x/net to v0.0.0-20211209124913-491a49abca63 * mount-utils: Detect potential stale file handle * Skip creating HNS loadbalancer with empty endpoints * Add regression test for CPUManager distribute NUMA algorithm * Add unit test for CPUManager distribute NUMA algorithm verifying fixes * Fix accounting bug in CPUManager distribute NUMA policy * Fix error handling in CPUManager distribute NUMA tests * Add a sum() helper to the CPUManager cpuassignment logic * Allow the map.Values() function in the CPUManager to take a set of keys * Fix CPUManager algo to calculate min NUMA nodes needed for distribution * Fix unit tests following bug fix in CPUManager for map functions (2/2) * Fix unit tests following bug fix in CPUManager for map functions (1/2) * Fix bug in CPUManager map.Keys() and map.Values() implementations * Ensure we balance across *all* NUMA nodes in NUMA distribution algo * Short-circuit CPUManager distribute NUMA algo for unusable cpuGroupSize * Round the CPUManager mean and stddev calculations to the nearest 1000th * updated deprecation messages from 1.23 to 1.24 * kubelet: set failed phase during graceful shutdown * kubeadm: avoid requiring a CA key during kubeconfig expiration checks * kubeadm: print the CA of kubeconfig files in "check expiration" * kubeadm: validate local etcd certficates during expiration checks * publishing-bot/doc: add component-helpers to the readme * publishing-bot/rules: remove non existing component-helpers branch 1.19 from the rules * Changelog: mention kube-scheduler bits deprication * rbd: initialize ceph monitors slice with an empty value. * Direct v2betaX users to migrate to HPA v2 * DelegateFSGroupToCSIDriver e2e: skip tests with chgrp * Update CHANGELOG/CHANGELOG-1.23.md for v1.23.0 * [go1.17] Update to go1.17.4- avoid bashism in client-common postinstall script (bsc#1195391)- Increase _constraints to 13GB- Restore & rebase revert-coredns-image-renaming.patch from kubernetes1.22. Looks like it's still needed until all supported k8s versions allow us to change how we publish coredns containers- Initial Packageibs-power9-15 17230171701.23.171.23.17-150500.3.15.11.23.17-150500.3.15.1kube-schedulerkubernetes1.23-schedulerCONTRIBUTING.mdREADME.mdkubernetes1.23-schedulerLICENSEkube-scheduler.1.gz/usr/bin//usr/share/doc/packages//usr/share/doc/packages/kubernetes1.23-scheduler//usr/share/licenses//usr/share/licenses/kubernetes1.23-scheduler//usr/share/man/man1/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:35119/SUSE_SLE-15-SP5_Update/c64fbe9b60ff10db1014465886192314-kubernetes1.23.SUSE_SLE-15-SP5_Updatedrpmxz5ppc64le-suse-linuxELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, BuildID[sha1]=c4f40e9077dbbedfb3bf4282b5b7861314c0eb7f, for GNU/Linux 3.10.0, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)RREn[˜Tutf-8bbf56e6bc0ccf2c39e539b41f8dad5a8536eaf0839a5ab0fcb9b38116ead0132?7zXZ !t/=]"k%s]{~mQl-dzͼ년Zzme^ۓlցq-08O2(Uźڥ CLt L0LjFaoG >+jػ q {zjQ :p \sQvn)*P0C,Q& Dcߨ/OJ5m9.q8,*V}7gsځR=KQ@_FP?֒SCekc&m5:ex,}>D-d!E D~iډB3r\e';|P)X8& O=;̮OBz9],0O:H92 ˬ[D~l|Q6cJxa%Z k|? .ca h@rQe4òI.PDg=_ƔҊMh5LG.=4bNqv_%* UkBd(SuY>cC^Xif d r5Ckb"a2L@{d`eV k70,2h&fg K=aq~%9zM*5rL$IFm$.Tk'{q!uեJ^:z#Voo}B*2qvר1v {gfՃ͠r)}Ł}tQ$AtI*sBN7W0TE@z.TG WK23ϔ^`΀iρWKMJ`}R"gVp4?m2شZ냑kxΞ@%" rJjWߖt%aljyw^0u5Sj]gjNFגO෗ |Rs'zF/GSݱ9~%S/W͍=vNଚ (Vrg1]8U͑6qehBm`mbOֽ6e_}`t"]#S7B6܍Tpw/ܙKFe k>]ˌ苓oc:$j8c#2`1e%Q /v;N7CY"S3~9 ˻ JD:Evxj@+?gR*ownNM=+w,PK >27]m*Rzlc¶&<0nq3xe[F`H#NTO䂧_%T|QI=E+4 o|qj $Yrg_..h];gXW]|?p32yZdFΗmWҭ (n}¢eCv[ DŽDj3{f`zgL*^[5y9s"ͦ:j1~x3荝l+LYs%d-R)`Qdv:67Ƀ^kNDh(dږ븑gMc b:ᘇ@)PԚm1"l-/xoQ$> :?d9?ȼֲֵsb\ߐ5!Of祈l_^wB݁Ӊr7/I"ܞ/f扽IU\m\uۨ t;'mW7k=7 _A;}d)it2@ `TrQwI"yat~>otVtQ\L=R"X^i83:4.*i;+\PL眅r[[МςiRەF>tн %e.c9@d%W|yjߨB>''`B_dv )X]دXZjHXV֎X_،mtf^MhP>O<!jaFGA9[h@U s_Ns;0=|'p^UmZ6 "-c*3,CױPHYJ̺pU/ڟB7F\ N9E*d[ WXy7^ЋBk&<#)R-^BWl!cj/ #bO&#voPKvjm#tV__*Xi1ޘ3`7% };~1C֣YeְR媔 )[ "zLjÓaӲ a/{s?%~Uc4*~nͣWu;.n/{wb%?6SIZMn9AַZ"J,D}- -5Ͻ SK w8B0@bfe'-M~֌e4XaH| ?M9$YG4:O&0u4{ՀhVsH- Ui␓AVDv,cGݨ}dT> sh4!zn'KK$& `+6yzI5 x[3[(I/֦ cW @¦ -n;xio161j6& JVsFUj%`*;iKv?";hUBk/g 7Xy|[qnEȲK^PV]T3% *{duI҂tS"_DnJQɲxu]Fmh~#aa)+`[0.z:or lEq.f"flW5 islbFmQ[Kɵb$mB4;+!?adVvStYch_kIP [L('Х"cEOt{|m'禋7;mౘvWUnnAcϠO$B~4n)qTt/%-qhJ"C>VWHpy!*[E:v˦$)>kݵ)7R߭gl $ˋ e7z| yTʯӆ*/['][`+O./b^i+Ğ^}!f=C"6>X~bBI70)lzkPT1i` Ldx?(_)RyU jPmҨH (a.rDoXԩFWN+ھ $8_ޟ|ma?[rH6eȂ MgE{:L||걬3D@Ox2 guHpժ!tG7 V!ŠXS_k%lk;ݭvLc I G͜ V@A\"|@4;s,j'`!h0'-}g=eŨؠ ?7an2r"QX~m >](|i/<<(LbNNJ;5Go7 ! Jg1pLCd=J4g,@Q7lAp@Z9k""0WS9*\BY"6\Hlr_t}}!kI6g9vBă [;V_JZ; Ɏ4 $Dɯ@ h"m]ؾ;m'1%);bsuZH9>S9 >mOi ~j1?^^a;3"+@t}d*gwrY]vvPcܑ^`%/#Ǟ]A/l"% Et"͢3 H84;!w䏨d +.J:y4^`qz|齎1PuT+٪s~zNYXCA*v>\ҌScՏ_qwQI!@-?nJ(amסdPo1Dna;lxǩ, TDKxd/RəS"ZR}س٠W)WhINO<6'utQl`[ٛ,aذm4t*;΁LX*[& ;۵1,%)QVaꉇ<5$o=]0 Xqnzjv95 zkN9BG'baM dz*;ULtcX:/4v9HWha*Ĕ \Q(B1n!wgy|oܿ5ڱKSہ+.Tyu=vedWcĨ[gr#b# uT9jU0P#\zp/nw(hjh6'Ft$W&c1!nF Taj;:a p`}H9r}Hla[}%g cW4YRbԹ 4-`B2-fVx{(2 ڪ2 {Ys5 ެW4?dT&ӍiN_@9OX*is˽68{EgkUVZK`M5 D\)ay"gK[(Pnj򍖝\G= Ȭ }i}q @EyJ@-]/~E #jvJJ:8:.VF f6ǵμ}Wq>끒\jEܸK;՚|-3r|; r,z~*bQ0|XGl1“ 71z`9Am~*Sf-Nz2Ecӏw/pΧ_1Mi*n-I7޼{TgyMYvb.G,ѹ 1kϭ7%Bg<,n]zcoӃ,λL7 [(H? 'b'"~Kػ1L]<^Չ;hCXN`l@B=۰`0&|gn ua#+6DoR_]b#K%o9Jc;*9ϢemڽnKiǰn/`,S7a@׭LjeЃDpZ\΋۴;nKdvoB*'69Ҙ#N}H1/cm GbY?CH?=1c"zkV)ou_C٫I@}0ă5;frf®t%М–$jҊIsIN pǢ !Eږ@J14Vm2\ڋ8n _Oo\ uQ^bJ{G]̣P9s#fB;g ~ ܟh^ E҇xv! s`W>#@%l(|yT bFvJE,r198ǫW{n]m߀^]hP^`Nt?/ >;5㳣M"fucL!)ݚą|}8$X95J[/gϠ6/JI34֨bSi/t&5&̥ ܀pr ]/#$lu.'F_T>lĵQiBۃ4 ޅ3(0\w1mB5DI&ok1@(sz*:| [kPgȷ_PUd&N?<*Q{ho0'J eQRj:0߳bP\QE"ZgA;Wi͒Q -QY;8K`QgT!sj*`yBMg}0KԣBx*aɎ+Bɹ-ArQT6uK^z܂a%%+}:@7NLRh%!l5\P=4o^ 1$wŨi=Q7y-;}MEa{+e 4( |ph$}T_oNϸɅ52Q ę207 WM{Qd죉Ai d$9hXa/ѩ{MLA@v0wOjE:H 5GdarR_} VG(yaM5J&\ƞIh6!P-6]I&oX*k~ҡY(}c?Z_P3krA5VWB4Ks7Te"ޅ?LNلDp[ J72̳XGYJcW{r'9Bw5b oiv)Y.4_co?4лg[k5܆3uW 4(17DRg5ˉ6Me] Sqjz~p@JAϺ%q᪢M/.ֱ9zǙ/WZ }Vm#HzU_X3zG5'HJHr4mB6 =0yw9ۖHƏuм p4\ \فհGFF%8QW5ތn͂gKnsoa>aO72 zȞ9-i!b˕zl7m#"EڂIKh$/[pnx լǵ =*D88UZH\3I<ҭHb" $ ש*̝sP}',~Z^ Uɜ1wT{Zѻ|T9km #.8[ Z cDHtZر\~,R3;Z`Di[Iՙ+JI\FUޓj^⋬;Kȇ?,3rpem#2piMq'fT<=4o`ˠH-y2<_8A (N;`2D}.nE8%t,8z&H)F T# X~ʏӱƉp=NޗTcd}7)ۦ &ᇃͿh Pø?sC>d oAHY*HTLl#~ }ctN5\#ɱ]_I,L68ش5=β}";ByL7SW#|PݟЪ}"UE*]Dm~$=wpI5Xncћ_}:J:ި@ӻT ^ٺ |w@W,qUZ+Rz=U#|$RQ_qCh8,1Sy1  57-<^!v1!.kA!εa~<4B~v{r͜ ױ7E@" X!ÆzteB#(`"PTe6~f KDªGF_. Uʳ?gLUv?c]߲ W*a~ 17 ~޿fz끳!tֹDf:.襢QWo]# {t"MՅnF!^sTg h|E+ѭ o>zcon:({j$%'˗{f_TOz_A͟yI m>5bXAv}kRP+H|؇3$zA|[pFfe[ X֨Z8ĈK8'iܒ~n@"-VHE+u.~e$*{S/*ϏCyI i xD@[.G5&KєJNRJC06U@ #Dk' `䘦GrPB͸( -TIDY72[i7;cbe4ҞZWG:p|)R~AU i$Iea­4:yϹ#M.43Y6tp*~ő}n'(:vIK?O  ^嶋)6QkG`Gy^Bg/KOy]Ijr*JjgJ_ff)j 4ȉζ66br}3˒M}+`kq#>}{{p ehBvo?(kq=r9 Ώ/#Pq7PyS;t=L5R%@Gd n2_Uu;n :"w']lw6xy>=_. k2񣅰LX2ec,$Uô%D;W8'xU+6Ǻ?otSuzhHLc6Y=0ߔJbo|Pɳ&'~1eDvB<'%YPk @1p1z-M[A@.6,c 褆uK ؑUvC1 򐧷Ri'Hf:铒#OTP0^ 4kn+jcu@VxF!3t>vp]Qw}合 W8:RZ~ aj8ds1Aa#[]$ Y+Pnӆ̠`9(I3`rwѻP"@2بQ+:Ny+!ןRF\!w,Te$䱾YcϽU/3U)sKm@o=ܭ&8gK7{q'1 76'>E `^Kƞg~`ɦp_:P_@qɖQ` (" 6!H^OBJ ӋӞIߚKHڥ.j^U08.gWS:(a!}$eE ummz3?Q m Ed8\GR~bTAQjBǍ]iM'Mޒ'}I 4oȔQ^4-+#dKB QLxɖO>9y#~*bT-J䒅cDŽQc.Car/H7̚\E#g Kzpw UHJtyQpn.j₾.zq5uxy4C@f%tP=`.GAk!)~#` oikCĘ2 Zo&$`~ ,JT8IyÞVD*GG6Yq;lC9dѮ V Cga7m@6g*'וQJa0gV MᣬR+B? hC݀j%4V&2&/(Ҡ&糧5[^QuABb]_78_K M9Kq~%*I9Xײ[Mǁm\cyzOsBR91lh@f/"OyMYg^ٶBtU<գ"YQ}O%DhL 7}@KdOdt=dĪmD{/u Ŭ!s\?)8<:Mv/fox|׃D@ϯ˕R}cz^p`ߺuʱzxI$FsGUCrw@1 =fńw=pChWWaNCx}3P `vժy}Gy()c`z5<[~NQ&%'\vqάQXEzOGT$L%w,l.9:lWoRbgjB:Ҿm{&}pۆ q4:M:pCiHISl@z II_n:g z}}rms+)2ɣ+"s)1jCߙ}]PMQt{7A/xyp%"URQsjyVm7p`[>mkhu/kUC.KW(t8ЃVV~.<&jg`,y!yXRi)na40KRs ۄ> ny\?d=.yRƀ;ؙg "'P.~-PeU" Zƍx/#|{z]B7]D\~!\dkY|Q>7ƒiڿ9#ߎ i}H-{sW$9\'Ao R=n ¡*mNH{dЖ),BB xj cӃLNYN 8kz5Q'\Iـ#crO˴<j7}nj,?Q\+oyp=跥-k!iAu mDk.?. wn;*Ϡ_2=jRW6qO ,2ۙJ8->'\_]%TjTWH|Z[-I)8䐎6~ h/b@$ 7vw!M_Qc p$V#-4тe^AKy(0Z~qPkhspuQ@DCwr".'gHj$܋e9kp F`,τ,!EEtj=KM2}1[Ų:?5A vAJשg5 N[$}F;RzCfaF8`g-XE.'Н8H8au],zfۥ,\~a@G$ĀאݶQml,r[sCwgS1ؙYIW!u)Bl=n[C*0z$(s#Km).<M8cY+?C]*Adn0]8j֘@t`rűraUAբaagQ`lBS90pP11HFg MAHQWk-O |Llv BTH,=9Oblmc(ҕP7U-5z21ISFS̵Q" 1(.BT{tl%+-CoA J YGgs b/>NwCpy}nݒ\0:̽q#PELrbKkmŴ/H2Q^X͎M5"j x2©(NM!ԍ62HMiryi9`vh6_/#IG cK|ƴ/W:+f00bY{p,3y?à>MV+yŔS ~dI4;߶Gv+~4PMX7E,]|{)ƬUOgH'qO t%m .j?DTg}*%5nRۏoxcC Sw-&F{W҅M!1hy&D}_K?hqbgDy+ q؞s{y>]**ϸ)=Ԅ\ Ba\i(0o^n^m!/u$qV*%]hT p (k O& L3dC252̒J7(>:zK_bv34\Fj;TpL&Qm%>uMa8CS'6i%.~]4jBR7c''U:)1٪~Q_R+v\@hҩDw5~.bZ_ U:KtH[*=ލdŠъ`.c9O>`Kz㚹ZLﯣeP,[)Ma։k|aXp߱pam@ӎo;Rӣ+GF6lW+b ]V])J"Fi^^mM꠹@.2~ USm&  *:En:' >kFFsf7@M_Zi)؛PHXcUUO _F^d{:m/l2J(-/;bM Fl|ܠN4rU)`OLF8@zZl{Fhfۄ(ZʁYL`TmebdIR(]j S"Y]<"Ƞ%ʋ2اZڿ&āuX~Dl`bCPd7 ہ`|CISLe~*_VXD` ԕgy @[Sd/ j >~L&`OFOc$,6oV՛Q= 煎 7ϭ7M) P`tWG]!~tS-@ƭeB9-!X:rXr;ev(fwv=&jg$F8'ѯd :@/T8_LK(˯L679O?;ZmLmsrw9Ӻ_g^=l Wx}\!$c$_nAb̵7gvއJvv֝%6 MhcC w݄^ɬmE;3ŦĒs(&'𽀟X .AfAUsk{eOqh H[WuJcgΩ$ȾIr= oA1̒笘D0S6)]qduc`%; iI. ? Hs !r̂uUx+nE^ⳬ[{pMc{dQX ١-,äxCqaRoT Ȣ>i:-+p$[c+=mo{HJ ӒL//1I$NUDܠq#ir'ҮW\ٞ+a*]YȣH O4вG˃REznu0Of5_O\a/^ *9U@4d%@2di"qߞTK)ApJpI) s|G?Ʀ,e^$']Z%+ NDkVgX8Qi5c&/@WPP?GA0.~g[ bRu% q=ԇΨki8|ř8gO?L427`!9ϼs,4e|UWA&zO&G{ S#em,@AxF¬qK8{-bN5_ڄ xls*|b"psP!W9 ~>!t)5hA&l2lLSx95a>%+Cu\0pOfy,46r#^^RwK6 rRdK[jAڂePܹ$hBD8_ʀ&R\b#x6meÉSۃG+v_LIFgVǡVxCe63 ̦7db5HVO dh y-x GF 6E[\MZ_np"YΚ;UWD^Qȳ9ㄮAwbeΑʆ[MM~HA.4\N7n4er8c eN<R8W-eU]\vȸ[[\ۘr)Hfǎ}wK%Fߜb 13лvn$FIՂHo`PtحUy]nT+*Mߧs?c᪠OzS7:~w