From a9c0c1e61eb7a03edad4f95118e7e589151876e1 Mon Sep 17 00:00:00 2001 From: xpk Date: Thu, 24 Oct 2024 23:06:25 +0800 Subject: [PATCH] HistoryPurge: Clearing out 238 old commits --- .gitignore | 17 + .gitmodules | 3 + LICENSE | 12 + README.md | 6 + examples/awsbackup/.terraform.lock.hcl | 20 + examples/awsbackup/main.tf | 40 + examples/awsbackup/provider.tf | 23 + examples/awsbackup/terraform.tfvars | 11 + examples/awsbackup/variables.tf | 11 + examples/backup.tar | Bin 0 -> 3553280 bytes examples/baseline-resources/README.md | 12 + examples/baseline-resources/main.tf | 51 + examples/baseline-resources/provider.tf | 13 + examples/baseline-resources/terraform.tfvars | 5 + examples/baseline-resources/variables.tf | 19 + examples/bea-adc/.terraform.lock.hcl | 32 + .../bea-adc/.terraform/modules/modules.json | 1 + .../hashicorp/aws/4.46.0/linux_amd64 | 1 + .../hashicorp/random/3.4.3/linux_amd64 | 1 + examples/bea-adc/README.md | 7 + examples/bea-adc/locals.tf | 15 + examples/bea-adc/main.tf | 48 + examples/bea-adc/outputs.tf | 11 + examples/bea-adc/provider.tf | 13 + examples/bea-adc/terraform.tfstate | 784 ++ examples/bea-adc/terraform.tfstate.backup | 790 ++ examples/bea-adc/terraform.tfvars | 15 + examples/bea-adc/variables.tf | 22 + examples/bea-sso-preview/.terraform.lock.hcl | 25 + .../.terraform/modules/modules.json | 1 + .../hashicorp/aws/4.45.0/linux_amd64 | 1 + examples/bea-sso-preview/locals.tf | 15 + examples/bea-sso-preview/main.tf | 28 + examples/bea-sso-preview/provider.tf | 13 + examples/bea-sso-preview/sso-users.tf | 64 + examples/bea-sso-preview/terraform.tfstate | 9 + .../bea-sso-preview/terraform.tfstate.backup | 1033 ++ examples/bea-sso-preview/terraform.tfvars | 7 + examples/bea-sso-preview/variables.tf | 6 + examples/deployer.ec2/main.tf | 39 + examples/deployer.ec2/terraform.tfvars | 8 + examples/deployer.ec2/variables.tf | 25 + examples/eks-lab-ip6/eks/.terraform.lock.hcl | 10 + .../hashicorp/aws/4.55.0/linux_amd64 | 1 + examples/eks-lab-ip6/eks/README.md | 119 + examples/eks-lab-ip6/eks/eks-node-sshkey | 7 + examples/eks-lab-ip6/eks/eks-node-sshkey.pub | 1 + examples/eks-lab-ip6/eks/locals.tf | 18 + examples/eks-lab-ip6/eks/main.tf | 306 + examples/eks-lab-ip6/eks/outputs.tf | 9 + examples/eks-lab-ip6/eks/provider.tf | 13 + examples/eks-lab-ip6/eks/terraform.tfvars | 6 + examples/eks-lab-ip6/eks/variables.tf | 6 + .../eks-lab-ip6/network/.terraform.lock.hcl | 10 + .../hashicorp/aws/4.55.0/linux_amd64 | 1 + examples/eks-lab-ip6/network/README.md | 10 + examples/eks-lab-ip6/network/locals.tf | 18 + examples/eks-lab-ip6/network/main.tf | 133 + examples/eks-lab-ip6/network/outputs.tf | 19 + examples/eks-lab-ip6/network/provider.tf | 13 + examples/eks-lab-ip6/network/terraform.tfvars | 6 + examples/eks-lab-ip6/network/variables.tf | 6 + .../eks-lab/.terraform/modules/modules.json | 1 + .../hashicorp/aws/4.54.0/linux_amd64 | 1 + .../hashicorp/local/2.3.0/linux_amd64 | 1 + .../hashicorp/null/3.2.1/linux_amd64 | 1 + .../hashicorp/template/2.2.0/linux_amd64 | 1 + .../hashicorp/tls/4.0.4/linux_amd64 | 1 + examples/eks-lab/eks/.terraform.lock.hcl | 10 + .../hashicorp/aws/4.55.0/linux_amd64 | 1 + examples/eks-lab/eks/README.md | 94 + examples/eks-lab/eks/eks-node-sshkey | 7 + examples/eks-lab/eks/eks-node-sshkey.pub | 1 + examples/eks-lab/eks/locals.tf | 18 + examples/eks-lab/eks/main.tf | 261 + examples/eks-lab/eks/outputs.tf | 9 + examples/eks-lab/eks/provider.tf | 13 + examples/eks-lab/eks/terraform.tfstate | 9 + examples/eks-lab/eks/terraform.tfstate.backup | 1101 +++ examples/eks-lab/eks/terraform.tfvars | 6 + examples/eks-lab/eks/variables.tf | 6 + examples/eks-lab/network/.terraform.lock.hcl | 25 + .../network/.terraform/modules/modules.json | 1 + .../hashicorp/aws/4.55.0/linux_amd64 | 1 + examples/eks-lab/network/README.md | 8 + examples/eks-lab/network/locals.tf | 18 + examples/eks-lab/network/main.tf | 55 + examples/eks-lab/network/outputs.tf | 15 + examples/eks-lab/network/provider.tf | 13 + examples/eks-lab/network/terraform.tfstate | 16 + .../eks-lab/network/terraform.tfstate.backup | 125 + examples/eks-lab/network/terraform.tfvars | 6 + examples/eks-lab/network/variables.tf | 6 + examples/eks-managed-nodegroup/README.md | 15 + examples/eks-managed-nodegroup/bastion.tf | 78 + examples/eks-managed-nodegroup/locals.tf | 3 + examples/eks-managed-nodegroup/main.tf | 189 + examples/eks-managed-nodegroup/provider.tf | 30 + .../eks-managed-nodegroup/terraform.tfstate | 0 .../terraform.tfstate.backup | 2389 +++++ .../eks-managed-nodegroup/terraform.tfvars | 11 + examples/eks-managed-nodegroup/variables.tf | 11 + examples/emr/main.tf | 227 + examples/emr/outputs.tf | 7 + examples/emr/provider.tf | 22 + examples/emr/terraform.tfvars | 6 + examples/emr/variables.tf | 9 + .../external-data-source/.terraform.lock.hcl | 9 + .../hashicorp/external/2.2.2/linux_amd64 | 1 + .../list-rds-instances.sh | 3 + examples/external-data-source/main.tf | 7 + examples/iam.user/main.tf | 67 + examples/iam.user/terraform.tfvars | 8 + examples/iam.user/variables.tf | 21 + examples/lambda-layers/.terraform.lock.hcl | 37 + .../hashicorp/archive/2.5.0/linux_amd64 | 1 + .../hashicorp/aws/5.64.0/linux_amd64 | 1 + examples/lambda-layers/README.md | 47 + examples/lambda-layers/function.py | 10 + examples/lambda-layers/function1.zip | Bin 0 -> 328 bytes examples/lambda-layers/lambda-layer1.zip | Bin 0 -> 1038174 bytes .../python3.12/site-packages/bin/normalizer | 8 + .../certifi-2024.7.4.dist-info/INSTALLER | 1 + .../certifi-2024.7.4.dist-info/LICENSE | 20 + .../certifi-2024.7.4.dist-info/METADATA | 67 + .../certifi-2024.7.4.dist-info/RECORD | 14 + .../certifi-2024.7.4.dist-info/WHEEL | 5 + .../certifi-2024.7.4.dist-info/top_level.txt | 1 + .../site-packages/certifi/__init__.py | 4 + .../site-packages/certifi/__main__.py | 12 + .../__pycache__/__init__.cpython-312.pyc | Bin 0 -> 279 bytes .../__pycache__/__main__.cpython-312.pyc | Bin 0 -> 594 bytes .../certifi/__pycache__/core.cpython-312.pyc | Bin 0 -> 3164 bytes .../site-packages/certifi/cacert.pem | 4798 +++++++++ .../python3.12/site-packages/certifi/core.py | 114 + .../python3.12/site-packages/certifi/py.typed | 0 .../INSTALLER | 1 + .../LICENSE | 21 + .../METADATA | 683 ++ .../charset_normalizer-3.3.2.dist-info/RECORD | 35 + .../charset_normalizer-3.3.2.dist-info/WHEEL | 6 + .../entry_points.txt | 2 + .../top_level.txt | 1 + .../charset_normalizer/__init__.py | 46 + .../charset_normalizer/__main__.py | 4 + .../__pycache__/__init__.cpython-312.pyc | Bin 0 -> 1698 bytes .../__pycache__/__main__.cpython-312.pyc | Bin 0 -> 268 bytes .../__pycache__/api.cpython-312.pyc | Bin 0 -> 17301 bytes .../__pycache__/cd.cpython-312.pyc | Bin 0 -> 13461 bytes .../__pycache__/constant.cpython-312.pyc | Bin 0 -> 38725 bytes .../__pycache__/legacy.cpython-312.pyc | Bin 0 -> 2469 bytes .../__pycache__/md.cpython-312.pyc | Bin 0 -> 24483 bytes .../__pycache__/models.cpython-312.pyc | Bin 0 -> 16573 bytes .../__pycache__/utils.cpython-312.pyc | Bin 0 -> 14336 bytes .../__pycache__/version.cpython-312.pyc | Bin 0 -> 295 bytes .../site-packages/charset_normalizer/api.py | 626 ++ .../site-packages/charset_normalizer/cd.py | 395 + .../charset_normalizer/cli/__init__.py | 6 + .../charset_normalizer/cli/__main__.py | 296 + .../cli/__pycache__/__init__.cpython-312.pyc | Bin 0 -> 256 bytes .../cli/__pycache__/__main__.cpython-312.pyc | Bin 0 -> 10360 bytes .../charset_normalizer/constant.py | 1995 ++++ .../charset_normalizer/legacy.py | 54 + .../md.cpython-312-x86_64-linux-gnu.so | Bin 0 -> 16064 bytes .../site-packages/charset_normalizer/md.py | 615 ++ .../md__mypyc.cpython-312-x86_64-linux-gnu.so | Bin 0 -> 272640 bytes .../charset_normalizer/models.py | 340 + .../site-packages/charset_normalizer/py.typed | 0 .../site-packages/charset_normalizer/utils.py | 421 + .../charset_normalizer/version.py | 6 + .../idna-3.8.dist-info/INSTALLER | 1 + .../idna-3.8.dist-info/LICENSE.md | 31 + .../site-packages/idna-3.8.dist-info/METADATA | 245 + .../site-packages/idna-3.8.dist-info/RECORD | 22 + .../site-packages/idna-3.8.dist-info/WHEEL | 4 + .../python3.12/site-packages/idna/__init__.py | 44 + .../idna/__pycache__/__init__.cpython-312.pyc | Bin 0 -> 842 bytes .../idna/__pycache__/codec.cpython-312.pyc | Bin 0 -> 4947 bytes .../idna/__pycache__/compat.cpython-312.pyc | Bin 0 -> 848 bytes .../idna/__pycache__/core.cpython-312.pyc | Bin 0 -> 16089 bytes .../idna/__pycache__/idnadata.cpython-312.pyc | Bin 0 -> 99437 bytes .../__pycache__/intranges.cpython-312.pyc | Bin 0 -> 2599 bytes .../__pycache__/package_data.cpython-312.pyc | Bin 0 -> 177 bytes .../__pycache__/uts46data.cpython-312.pyc | Bin 0 -> 158809 bytes .../python3.12/site-packages/idna/codec.py | 118 + .../python3.12/site-packages/idna/compat.py | 13 + .../lib/python3.12/site-packages/idna/core.py | 399 + .../python3.12/site-packages/idna/idnadata.py | 4245 ++++++++ .../site-packages/idna/intranges.py | 54 + .../site-packages/idna/package_data.py | 2 + .../python3.12/site-packages/idna/py.typed | 0 .../site-packages/idna/uts46data.py | 8598 +++++++++++++++++ .../requests-2.32.3.dist-info/INSTALLER | 1 + .../requests-2.32.3.dist-info/LICENSE | 175 + .../requests-2.32.3.dist-info/METADATA | 119 + .../requests-2.32.3.dist-info/RECORD | 43 + .../requests-2.32.3.dist-info/REQUESTED | 0 .../requests-2.32.3.dist-info/WHEEL | 5 + .../requests-2.32.3.dist-info/top_level.txt | 1 + .../site-packages/requests/__init__.py | 184 + .../__pycache__/__init__.cpython-312.pyc | Bin 0 -> 5382 bytes .../__pycache__/__version__.cpython-312.pyc | Bin 0 -> 546 bytes .../_internal_utils.cpython-312.pyc | Bin 0 -> 1986 bytes .../__pycache__/adapters.cpython-312.pyc | Bin 0 -> 28326 bytes .../requests/__pycache__/api.cpython-312.pyc | Bin 0 -> 7166 bytes .../requests/__pycache__/auth.cpython-312.pyc | Bin 0 -> 13885 bytes .../__pycache__/certs.cpython-312.pyc | Bin 0 -> 628 bytes .../__pycache__/compat.cpython-312.pyc | Bin 0 -> 2047 bytes .../__pycache__/cookies.cpython-312.pyc | Bin 0 -> 25238 bytes .../__pycache__/exceptions.cpython-312.pyc | Bin 0 -> 7547 bytes .../requests/__pycache__/help.cpython-312.pyc | Bin 0 -> 4289 bytes .../__pycache__/hooks.cpython-312.pyc | Bin 0 -> 1014 bytes .../__pycache__/models.cpython-312.pyc | Bin 0 -> 35368 bytes .../__pycache__/packages.cpython-312.pyc | Bin 0 -> 1101 bytes .../__pycache__/sessions.cpython-312.pyc | Bin 0 -> 27844 bytes .../__pycache__/status_codes.cpython-312.pyc | Bin 0 -> 5993 bytes .../__pycache__/structures.cpython-312.pyc | Bin 0 -> 5579 bytes .../__pycache__/utils.cpython-312.pyc | Bin 0 -> 36392 bytes .../site-packages/requests/__version__.py | 14 + .../site-packages/requests/_internal_utils.py | 50 + .../site-packages/requests/adapters.py | 719 ++ .../python3.12/site-packages/requests/api.py | 157 + .../python3.12/site-packages/requests/auth.py | 314 + .../site-packages/requests/certs.py | 17 + .../site-packages/requests/compat.py | 94 + .../site-packages/requests/cookies.py | 561 ++ .../site-packages/requests/exceptions.py | 151 + .../python3.12/site-packages/requests/help.py | 134 + .../site-packages/requests/hooks.py | 33 + .../site-packages/requests/models.py | 1037 ++ .../site-packages/requests/packages.py | 23 + .../site-packages/requests/sessions.py | 831 ++ .../site-packages/requests/status_codes.py | 128 + .../site-packages/requests/structures.py | 99 + .../site-packages/requests/utils.py | 1096 +++ .../urllib3-2.2.2.dist-info/INSTALLER | 1 + .../urllib3-2.2.2.dist-info/METADATA | 154 + .../urllib3-2.2.2.dist-info/RECORD | 75 + .../urllib3-2.2.2.dist-info/WHEEL | 4 + .../licenses/LICENSE.txt | 21 + .../site-packages/urllib3/__init__.py | 211 + .../__pycache__/__init__.cpython-312.pyc | Bin 0 -> 7277 bytes .../_base_connection.cpython-312.pyc | Bin 0 -> 6824 bytes .../__pycache__/_collections.cpython-312.pyc | Bin 0 -> 22676 bytes .../_request_methods.cpython-312.pyc | Bin 0 -> 10639 bytes .../__pycache__/_version.cpython-312.pyc | Bin 0 -> 230 bytes .../__pycache__/connection.cpython-312.pyc | Bin 0 -> 32227 bytes .../connectionpool.cpython-312.pyc | Bin 0 -> 39710 bytes .../__pycache__/exceptions.cpython-312.pyc | Bin 0 -> 15799 bytes .../__pycache__/fields.cpython-312.pyc | Bin 0 -> 12039 bytes .../__pycache__/filepost.cpython-312.pyc | Bin 0 -> 3480 bytes .../urllib3/__pycache__/http2.cpython-312.pyc | Bin 0 -> 11002 bytes .../__pycache__/poolmanager.cpython-312.pyc | Bin 0 -> 24041 bytes .../__pycache__/response.cpython-312.pyc | Bin 0 -> 50427 bytes .../site-packages/urllib3/_base_connection.py | 172 + .../site-packages/urllib3/_collections.py | 483 + .../site-packages/urllib3/_request_methods.py | 279 + .../site-packages/urllib3/_version.py | 4 + .../site-packages/urllib3/connection.py | 929 ++ .../site-packages/urllib3/connectionpool.py | 1182 +++ .../site-packages/urllib3/contrib/__init__.py | 0 .../__pycache__/__init__.cpython-312.pyc | Bin 0 -> 160 bytes .../__pycache__/pyopenssl.cpython-312.pyc | Bin 0 -> 26897 bytes .../contrib/__pycache__/socks.cpython-312.pyc | Bin 0 -> 8138 bytes .../urllib3/contrib/emscripten/__init__.py | 16 + .../__pycache__/__init__.cpython-312.pyc | Bin 0 -> 868 bytes .../__pycache__/connection.cpython-312.pyc | Bin 0 -> 10207 bytes .../__pycache__/fetch.cpython-312.pyc | Bin 0 -> 18340 bytes .../__pycache__/request.cpython-312.pyc | Bin 0 -> 1388 bytes .../__pycache__/response.cpython-312.pyc | Bin 0 -> 12673 bytes .../urllib3/contrib/emscripten/connection.py | 254 + .../emscripten/emscripten_fetch_worker.js | 110 + .../urllib3/contrib/emscripten/fetch.py | 418 + .../urllib3/contrib/emscripten/request.py | 22 + .../urllib3/contrib/emscripten/response.py | 285 + .../urllib3/contrib/pyopenssl.py | 548 ++ .../site-packages/urllib3/contrib/socks.py | 228 + .../site-packages/urllib3/exceptions.py | 321 + .../site-packages/urllib3/fields.py | 341 + .../site-packages/urllib3/filepost.py | 89 + .../python3.12/site-packages/urllib3/http2.py | 230 + .../site-packages/urllib3/poolmanager.py | 637 ++ .../python3.12/site-packages/urllib3/py.typed | 2 + .../site-packages/urllib3/response.py | 1265 +++ .../site-packages/urllib3/util/__init__.py | 42 + .../util/__pycache__/__init__.cpython-312.pyc | Bin 0 -> 973 bytes .../__pycache__/connection.cpython-312.pyc | Bin 0 -> 4716 bytes .../util/__pycache__/proxy.cpython-312.pyc | Bin 0 -> 1185 bytes .../util/__pycache__/request.cpython-312.pyc | Bin 0 -> 8004 bytes .../util/__pycache__/response.cpython-312.pyc | Bin 0 -> 2841 bytes .../util/__pycache__/retry.cpython-312.pyc | Bin 0 -> 20254 bytes .../util/__pycache__/ssl_.cpython-312.pyc | Bin 0 -> 16542 bytes .../ssl_match_hostname.cpython-312.pyc | Bin 0 -> 5525 bytes .../__pycache__/ssltransport.cpython-312.pyc | Bin 0 -> 13519 bytes .../util/__pycache__/timeout.cpython-312.pyc | Bin 0 -> 11657 bytes .../util/__pycache__/url.cpython-312.pyc | Bin 0 -> 16197 bytes .../util/__pycache__/util.cpython-312.pyc | Bin 0 -> 1962 bytes .../util/__pycache__/wait.cpython-312.pyc | Bin 0 -> 3408 bytes .../site-packages/urllib3/util/connection.py | 137 + .../site-packages/urllib3/util/proxy.py | 43 + .../site-packages/urllib3/util/request.py | 256 + .../site-packages/urllib3/util/response.py | 101 + .../site-packages/urllib3/util/retry.py | 533 + .../site-packages/urllib3/util/ssl_.py | 509 + .../urllib3/util/ssl_match_hostname.py | 159 + .../urllib3/util/ssltransport.py | 279 + .../site-packages/urllib3/util/timeout.py | 275 + .../site-packages/urllib3/util/url.py | 471 + .../site-packages/urllib3/util/util.py | 42 + .../site-packages/urllib3/util/wait.py | 124 + examples/lambda-layers/main.tf | 51 + examples/lambda-layers/provider.tf | 19 + examples/skel/README.md | 9 + examples/skel/main.tf | 1 + examples/skel/provider.tf | 27 + examples/skel/terraform.tfvars | 5 + examples/skel/variables.tf | 5 + headdesk-aws/all-layers/ec2.tf | 52 + headdesk-aws/all-layers/main.tf | 21 + headdesk-aws/all-layers/provider.tf | 13 + headdesk-aws/all-layers/security.tf | 3 + headdesk-aws/all-layers/terraform.tfvars | 5 + headdesk-aws/all-layers/variables.tf | 19 + .../.terraform.lock.hcl | 36 + .../base-network-experimental/main.tf | 21 + .../base-network/.terraform.lock.hcl | 37 + layers/networking/base-network/main.tf | 17 + layers/networking/base-network/outputs.tf | 11 + layers/networking/base-network/provider.tf | 13 + .../networking/base-network/terraform.tfvars | 6 + layers/networking/base-network/variables.tf | 22 + .../apigw-lambda/README.md | 77 + .../apigw-lambda/examples/main.tf | 111 + .../apigw-lambda/main.tf | 256 + .../apigw-lambda/outputs.tf | 7 + .../apigw-lambda/variables.tf | 90 + .../apigw-lambda/versions.tf | 9 + .../terraform-aws-apigateway-v2 | 1 + modules/FrontendWebMobile/Ses/README.md | 42 + modules/FrontendWebMobile/Ses/main.tf | 63 + modules/FrontendWebMobile/Ses/variables.tf | 16 + modules/FrontendWebMobile/Ses/versions.tf | 9 + .../CwAgentInstallUsingSsm/README.md | 50 + .../CwAgentInstallUsingSsm/main.tf | 135 + .../CwAgentInstallUsingSsm/versions.tf | 9 + .../Cwl-firehose-s3/README.md | 61 + .../Cwl-firehose-s3/main.tf | 161 + .../Cwl-firehose-s3/outputs.tf | 7 + .../Cwl-firehose-s3/variables.tf | 40 + .../Cwl-firehose-s3/versions.tf | 9 + .../Monitoring.ALB/README.md | 22 + .../Monitoring.ALB/list-alb-targetgroups.sh | 6 + .../Monitoring.ALB/main.tf | 110 + .../Monitoring.ALB/outputs.tf | 4 + .../Monitoring.ALB/provider.tf | 9 + .../Monitoring.ALB/variables.tf | 8 + .../Monitoring.ASG/README.md | 24 + .../Monitoring.ASG/main.tf | 41 + .../Monitoring.ASG/provider.tf | 9 + .../Monitoring.ASG/variables.tf | 5 + .../Monitoring.EC2/README.md | 74 + .../Monitoring.EC2/get-cwagent-device.sh | 22 + .../Monitoring.EC2/get-cwagent-dimensions.sh | 25 + .../Monitoring.EC2/get-os-platform.sh | 12 + .../Monitoring.EC2/main.tf | 395 + .../Monitoring.EC2/provider.tf | 9 + .../Monitoring.EC2/variables.tf | 8 + .../Monitoring.EKS/README.md | 27 + .../Monitoring.EKS/main.tf | 69 + .../Monitoring.EKS/provider.tf | 9 + .../Monitoring.EKS/variables.tf | 8 + .../Monitoring.EMR/README.md | 25 + .../Monitoring.EMR/main.tf | 19 + .../Monitoring.EMR/provider.tf | 9 + .../Monitoring.EMR/variables.tf | 4 + .../Monitoring.EventBridge/README.md | 5 + .../Monitoring.EventBridge/main.tf | 46 + .../Monitoring.EventBridge/provider.tf | 9 + .../Monitoring.EventBridge/variables.tf | 3 + .../Monitoring.Kafka/README.md | 24 + .../Monitoring.Kafka/main.tf | 116 + .../Monitoring.Kafka/provider.tf | 9 + .../Monitoring.Kafka/variables.tf | 4 + .../Monitoring.NGW/README.md | 26 + .../Monitoring.NGW/main.tf | 19 + .../Monitoring.NGW/provider.tf | 9 + .../Monitoring.NGW/variables.tf | 4 + .../Monitoring.NLB/README.md | 24 + .../Monitoring.NLB/main.tf | 105 + .../Monitoring.NLB/outputs.tf | 4 + .../Monitoring.NLB/provider.tf | 9 + .../Monitoring.NLB/variables.tf | 8 + .../Monitoring.OpenSearch/README.md | 27 + .../Monitoring.OpenSearch/main.tf | 22 + .../Monitoring.OpenSearch/provider.tf | 9 + .../Monitoring.OpenSearch/variables.tf | 4 + .../Monitoring.RDS/README.md | 31 + .../Monitoring.RDS/main.tf | 19 + .../Monitoring.RDS/provider.tf | 9 + .../Monitoring.RDS/variables.tf | 4 + .../Monitoring.Redis/README.md | 26 + .../Monitoring.Redis/main.tf | 21 + .../Monitoring.Redis/provider.tf | 9 + .../Monitoring.Redis/variables.tf | 4 + .../Monitoring.TGW/README.md | 24 + .../Monitoring.TGW/main.tf | 19 + .../Monitoring.TGW/provider.tf | 9 + .../Monitoring.TGW/variables.tf | 4 + .../SnsTopicEmailSubscription/README.md | 47 + .../SnsTopicEmailSubscription/main.tf | 69 + .../SnsTopicEmailSubscription/outputs.tf | 3 + .../SnsTopicEmailSubscription/variables.tf | 33 + .../SnsTopicEmailSubscription/versions.tf | 9 + .../acm-cert-expiry-notice/README.md | 101 + .../acm-cert-expiry-notice/examples/main.tf | 6 + .../acm-cert-expiry-notice/main.tf | 98 + .../acm-cert-expiry-notice/variables.tf | 22 + .../acm-cert-expiry-notice/versions.tf | 9 + .../ssm-schedule-run-command/README.md | 44 + .../ssm-schedule-run-command/main.tf | 80 + .../ssm-schedule-run-command/variables.tf | 36 + .../ssm-schedule-run-command/versions.tf | 9 + .../ec2-instance-scheduler/Ec2Scheduler.py | 16 + .../compute/ec2-instance-scheduler/README.md | 52 + .../compute/ec2-instance-scheduler/main.tf | 203 + .../ec2-instance-scheduler/variables.tf | 25 + .../ec2-instance-scheduler/versions.tf | 13 + modules/compute/ec2/README.md | 78 + modules/compute/ec2/main.tf | 125 + modules/compute/ec2/outputs.tf | 37 + modules/compute/ec2/provider.tf | 10 + modules/compute/ec2/variable.tf | 107 + modules/compute/security-groups/README.md | 52 + modules/compute/security-groups/main.tf | 45 + modules/compute/security-groups/outputs.tf | 14 + modules/compute/security-groups/variables.tf | 3 + modules/compute/security_group/README.md | 43 + modules/compute/security_group/main.tf | 39 + modules/compute/security_group/outputs.tf | 3 + modules/compute/security_group/variables.tf | 5 + modules/compute/sg_default_tags/README.md | 43 + modules/compute/sg_default_tags/main.tf | 71 + modules/compute/sg_default_tags/outputs.tf | 14 + modules/compute/sg_default_tags/variables.tf | 6 + modules/global-variables/README.md | 27 + modules/global-variables/outputs.tf | 18 + modules/networking/VpcSubnet/README.md | 93 + modules/networking/VpcSubnet/example/main.tf | 12 + modules/networking/VpcSubnet/main.tf | 203 + .../VpcSubnet/modules/RouteTables/README.md | 39 + .../VpcSubnet/modules/RouteTables/main.tf | 17 + .../modules/RouteTables/variables.tf | 19 + modules/networking/VpcSubnet/outputs.tf | 70 + modules/networking/VpcSubnet/variables.tf | 75 + modules/networking/VpcSubnet/versions.tf | 9 + modules/networking/VpcSubnet/vpc-flowlog.tf | 81 + .../networking/delete-default-vpcs/README.md | 13 + .../networking/delete-default-vpcs/exec.sh | 23 + .../networking/delete-default-vpcs/main.tf | 8 + modules/networking/nacl/README.md | 23 + modules/networking/nacl/main.tf | 32 + modules/networking/nacl/provider.tf | 9 + modules/networking/nacl/variables.tf | 19 + modules/networking/r53-record-geo/README.md | 19 + modules/networking/r53-record-geo/main.tf | 60 + .../networking/r53-record-geo/variables.tf | 62 + modules/networking/r53-record/README.md | 30 + modules/networking/r53-record/main.tf | 22 + modules/networking/r53-record/variables.tf | 32 + modules/networking/vpc-endpoints/README.md | 275 + modules/networking/vpc-endpoints/main.tf | 102 + modules/networking/vpc-endpoints/provider.tf | 11 + modules/networking/vpc-endpoints/variables.tf | 18 + .../networking/vpc-subnet-manual-5r/README.md | 52 + .../networking/vpc-subnet-manual-5r/main.tf | 204 + .../vpc-subnet-manual-5r/outputs.tf | 39 + .../vpc-subnet-manual-5r/provider.tf | 15 + .../vpc-subnet-manual-5r/variables.tf | 37 + .../vpc-subnet-manual-5r/vpc-flowlog.tf | 71 + modules/networking/vpc_subnets/README.md | 51 + modules/networking/vpc_subnets/main.tf | 1 + modules/networking/vpc_subnets/outputs.tf | 31 + modules/networking/vpc_subnets/variables.tf | 42 + modules/networking/vpc_subnets/vpc-flowlog.tf | 63 + modules/networking/vpc_subnets/vpc.tf | 166 + .../aws_config/Cis14Level1.yaml | 601 ++ .../aws_config/README.md | 25 + .../aws_config/cis-rules.tf-no | 122 + .../aws_config/main.tf | 154 + .../aws_config/provider.tf | 9 + .../aws_config/variables.tf | 9 + .../cloudtrail_cwlogs/README.md | 21 + .../cloudtrail_cwlogs/cloudtrail.tf | 80 + .../cloudtrail_cwlogs/ct-key.tf | 69 + .../cloudtrail_cwlogs/ct-s3-bucket.tf | 64 + .../cloudtrail_cwlogs/cw-loggroup.tf | 377 + .../cloudtrail_cwlogs/main.tf | 1 + .../cloudtrail_cwlogs/outputs.tf | 0 .../cloudtrail_cwlogs/variables.tf | 19 + .../ds-adconnector/main.tf | 17 + .../ds-adconnector/outputs.tf | 11 + .../ds-adconnector/variables.tf | 8 + .../five-deployer-roles/README.md | 13 + .../five-deployer-roles/locals.tf | 1 + .../five-deployer-roles/main.tf | 639 ++ .../five-deployer-roles/outputs.tf | 9 + .../five-deployer-roles/provider.tf | 9 + .../five-deployer-roles/variables.tf | 12 + .../guardduty/README.md | 17 + .../guardduty/main.tf | 8 + .../guardduty/outputs.tf | 3 + .../guardduty/variables.tf | 1 + .../iam-group/README.md | 24 + .../iam-group/main.tf | 17 + .../iam-group/outputs.tf | 7 + .../iam-group/variables.tf | 4 + .../iam-group/versions.tf | 9 + .../iam-role/LICENSE | 12 + .../iam-role/README.md | 51 + .../iam-role/examples/main.tf | 34 + .../iam-role/main.tf | 40 + .../iam-role/outputs.tf | 19 + .../iam-role/provider.tf | 9 + .../iam-role/variables.tf | 38 + .../iam-user/README.md | 56 + .../iam-user/main.tf | 99 + .../iam-user/outputs.tf | 15 + .../iam-user/variables.tf | 20 + .../iam-user/versions.tf | 9 + .../inspector2/README.md | 2 + .../inspector2/main.tf | 11 + .../other-default-settings/main.tf | 24 + .../roles_iam_resources/README.md | 19 + .../roles_iam_resources/access-analyzer.tf | 4 + .../roles_iam_resources/cloudhealth-role.tf | 168 + .../iam-password-policy.tf | 11 + .../roles_iam_resources/main.tf | 128 + .../roles_iam_resources/variables.tf | 20 + .../secretsmanager-secret/README.md | 29 + .../secretsmanager-secret/main.tf | 48 + .../secretsmanager-secret/outputs.tf | 12 + .../secretsmanager-secret/provider.tf | 9 + .../secretsmanager-secret/variables.tf | 23 + .../security_hub/main.tf | 13 + .../sso-aws-id-store/README.md | 3 + .../sso-aws-id-store/main.tf | 33 + .../sso-aws-id-store/variables.tf | 5 + .../sso-permissionsets/README.md | 33 + .../sso-permissionsets/main.tf | 25 + .../sso-permissionsets/outputs.tf | 7 + .../sso-permissionsets/variables.tf | 6 + .../terraform-user/main.tf | 96 + .../terraform-user/outputs.tf | 6 + .../terraform-user/provider.tf | 9 + .../terraform-user/variables.tf | 7 + modules/storage/aws-backup/README.md | 47 + modules/storage/aws-backup/kms-key.tf | 43 + modules/storage/aws-backup/main.tf | 176 + modules/storage/aws-backup/variables.tf | 57 + modules/storage/infra-s3-bucket/README.md | 19 + modules/storage/infra-s3-bucket/main.tf | 82 + modules/storage/infra-s3-bucket/outputs.tf | 3 + modules/storage/infra-s3-bucket/variables.tf | 30 + .../storage/s3-bucket-replication/README.md | 50 + modules/storage/s3-bucket-replication/main.tf | 152 + .../storage/s3-bucket-replication/outputs.tf | 3 + .../s3-bucket-replication/variables.tf | 20 + .../storage/s3-bucket-replication/versions.tf | 10 + modules/storage/s3_bucket_2023/README.md | 263 + modules/storage/s3_bucket_2023/main.tf | 173 + modules/storage/s3_bucket_2023/outputs.tf | 7 + modules/storage/s3_bucket_2023/variables.tf | 89 + modules/storage/s3_bucket_2023/versions.tf | 10 + modules/syntax-test/main.tf | 11 + modules/syntax-test/variables.tf | 1 + modules/terraform-setup/README.md | 9 + .../examples/.terraform.lock.hcl | 10 + modules/terraform-setup/examples/main.tf | 46 + modules/terraform-setup/main.tf | 131 + modules/terraform-setup/outputs.tf | 27 + modules/terraform-setup/variables.tf | 15 + modules/util/account-list/README.md | 16 + modules/util/account-list/main.tf | 2 + modules/util/account-list/outputs.tf | 3 + modules/util/account-list/provider.tf | 10 + modules/util/assume_role/README.md | 30 + modules/util/assume_role/assumeRole.sh | 26 + modules/util/assume_role/main.tf | 12 + modules/util/assume_role/variables.tf | 13 + modules/util/aws-region-short/README.md | 13 + .../util/aws-region-short/examples/main.tf | 7 + modules/util/aws-region-short/main.tf | 25 + modules/util/aws-region-short/provider.tf | 9 + modules/util/awscli/README.md | 56 + modules/util/awscli/main.tf | 14 + modules/util/awscli/run_awscli.sh | 36 + modules/util/awscli/variables.tf | 18 + modules/util/random/main.tf | 17 + modules/util/resource-list/README.md | 2 + .../resource-list/list-alb-targetgroups.sh | 6 + modules/util/resource-list/list-alb.sh | 4 + modules/util/resource-list/list-asg.sh | 6 + modules/util/resource-list/list-ec2.sh | 4 + modules/util/resource-list/list-emr.sh | 6 + modules/util/resource-list/list-kafka.sh | 8 + modules/util/resource-list/list-ngw.sh | 3 + .../resource-list/list-nlb-targetgroups.sh | 7 + modules/util/resource-list/list-nlb.sh | 3 + modules/util/resource-list/list-opensearch.sh | 8 + modules/util/resource-list/list-rds.sh | 3 + modules/util/resource-list/list-redis.sh | 6 + modules/util/resource-list/list-tgw.sh | 7 + modules/util/resource-list/main.tf | 13 + modules/util/resource-list/variables.tf | 17 + modules/util/terraform-aws-cli/.gitignore | 5 + .../terraform-aws-cli/.pre-commit-config.yaml | 43 + .../util/terraform-aws-cli/.terraform-version | 1 + modules/util/terraform-aws-cli/.tflint.hcl | 32 + modules/util/terraform-aws-cli/.travis.yml | 12 + modules/util/terraform-aws-cli/CHANGELOG.md | 86 + modules/util/terraform-aws-cli/README.md | 131 + modules/util/terraform-aws-cli/main.tf | 42 + .../scripts/awsWithAssumeRole.sh | 65 + .../tests/bad_arn/terraform.tfvars | 3 + .../terraform-aws-cli/tests/bad_arn/test.sh | 20 + .../util/terraform-aws-cli/tests/common.sh | 30 + .../empty_result/expected_variables.json | 24 + .../tests/empty_result/notes.txt | 26 + .../tests/empty_result/terraform.tfvars | 3 + .../tests/empty_result/test.sh | 41 + .../terraform.tfvars | 4 + .../test.sh | 20 + .../expected_variables.json | 23 + .../terraform.tfvars | 3 + .../tests/role_session_name_optional/test.sh | 40 + .../terraform.tfvars | 4 + .../tests/role_session_name_too_long/test.sh | 20 + .../test_with_debug/expected_variables.json | 23 + .../tests/test_with_debug/terraform.tfvars | 5 + .../tests/test_with_debug/test.sh | 40 + .../expected_variables.json | 23 + .../tests/test_without_debug/terraform.tfvars | 4 + .../tests/test_without_debug/test.sh | 40 + modules/util/terraform-aws-cli/tests/tests.sh | 4 + modules/util/terraform-aws-cli/variables.tf | 43 + modules/util/terraform-aws-cli/versions.tf | 13 + rslab-ali/network/main.tf | 38 + rslab-ali/network/outputs.tf | 7 + rslab-ali/network/provider.tf | 14 + 649 files changed, 63886 insertions(+) create mode 100644 .gitignore create mode 100644 .gitmodules create mode 100644 LICENSE create mode 100644 README.md create mode 100644 examples/awsbackup/.terraform.lock.hcl create mode 100644 examples/awsbackup/main.tf create mode 100644 examples/awsbackup/provider.tf create mode 100644 examples/awsbackup/terraform.tfvars create mode 100644 examples/awsbackup/variables.tf create mode 100644 examples/backup.tar create mode 100644 examples/baseline-resources/README.md create mode 100644 examples/baseline-resources/main.tf create mode 100644 examples/baseline-resources/provider.tf create mode 100644 examples/baseline-resources/terraform.tfvars create mode 100644 examples/baseline-resources/variables.tf create mode 100644 examples/bea-adc/.terraform.lock.hcl create mode 100644 examples/bea-adc/.terraform/modules/modules.json create mode 120000 examples/bea-adc/.terraform/providers/registry.terraform.io/hashicorp/aws/4.46.0/linux_amd64 create mode 120000 examples/bea-adc/.terraform/providers/registry.terraform.io/hashicorp/random/3.4.3/linux_amd64 create mode 100644 examples/bea-adc/README.md create mode 100644 examples/bea-adc/locals.tf create mode 100644 examples/bea-adc/main.tf create mode 100644 examples/bea-adc/outputs.tf create mode 100644 examples/bea-adc/provider.tf create mode 100644 examples/bea-adc/terraform.tfstate create mode 100644 examples/bea-adc/terraform.tfstate.backup create mode 100644 examples/bea-adc/terraform.tfvars create mode 100644 examples/bea-adc/variables.tf create mode 100644 examples/bea-sso-preview/.terraform.lock.hcl create mode 100644 examples/bea-sso-preview/.terraform/modules/modules.json create mode 120000 examples/bea-sso-preview/.terraform/providers/registry.terraform.io/hashicorp/aws/4.45.0/linux_amd64 create mode 100644 examples/bea-sso-preview/locals.tf create mode 100644 examples/bea-sso-preview/main.tf create mode 100644 examples/bea-sso-preview/provider.tf create mode 100644 examples/bea-sso-preview/sso-users.tf create mode 100644 examples/bea-sso-preview/terraform.tfstate create mode 100644 examples/bea-sso-preview/terraform.tfstate.backup create mode 100644 examples/bea-sso-preview/terraform.tfvars create mode 100644 examples/bea-sso-preview/variables.tf create mode 100644 examples/deployer.ec2/main.tf create mode 100644 examples/deployer.ec2/terraform.tfvars create mode 100644 examples/deployer.ec2/variables.tf create mode 100644 examples/eks-lab-ip6/eks/.terraform.lock.hcl create mode 120000 examples/eks-lab-ip6/eks/.terraform/providers/registry.terraform.io/hashicorp/aws/4.55.0/linux_amd64 create mode 100644 examples/eks-lab-ip6/eks/README.md create mode 100644 examples/eks-lab-ip6/eks/eks-node-sshkey create mode 100644 examples/eks-lab-ip6/eks/eks-node-sshkey.pub create mode 100644 examples/eks-lab-ip6/eks/locals.tf create mode 100644 examples/eks-lab-ip6/eks/main.tf create mode 100644 examples/eks-lab-ip6/eks/outputs.tf create mode 100644 examples/eks-lab-ip6/eks/provider.tf create mode 100644 examples/eks-lab-ip6/eks/terraform.tfvars create mode 100644 examples/eks-lab-ip6/eks/variables.tf create mode 100644 examples/eks-lab-ip6/network/.terraform.lock.hcl create mode 120000 examples/eks-lab-ip6/network/.terraform/providers/registry.terraform.io/hashicorp/aws/4.55.0/linux_amd64 create mode 100644 examples/eks-lab-ip6/network/README.md create mode 100644 examples/eks-lab-ip6/network/locals.tf create mode 100644 examples/eks-lab-ip6/network/main.tf create mode 100644 examples/eks-lab-ip6/network/outputs.tf create mode 100644 examples/eks-lab-ip6/network/provider.tf create mode 100644 examples/eks-lab-ip6/network/terraform.tfvars create mode 100644 examples/eks-lab-ip6/network/variables.tf create mode 100644 examples/eks-lab/.terraform/modules/modules.json create mode 120000 examples/eks-lab/.terraform/providers/registry.terraform.io/hashicorp/aws/4.54.0/linux_amd64 create mode 120000 examples/eks-lab/.terraform/providers/registry.terraform.io/hashicorp/local/2.3.0/linux_amd64 create mode 120000 examples/eks-lab/.terraform/providers/registry.terraform.io/hashicorp/null/3.2.1/linux_amd64 create mode 120000 examples/eks-lab/.terraform/providers/registry.terraform.io/hashicorp/template/2.2.0/linux_amd64 create mode 120000 examples/eks-lab/.terraform/providers/registry.terraform.io/hashicorp/tls/4.0.4/linux_amd64 create mode 100644 examples/eks-lab/eks/.terraform.lock.hcl create mode 120000 examples/eks-lab/eks/.terraform/providers/registry.terraform.io/hashicorp/aws/4.55.0/linux_amd64 create mode 100644 examples/eks-lab/eks/README.md create mode 100644 examples/eks-lab/eks/eks-node-sshkey create mode 100644 examples/eks-lab/eks/eks-node-sshkey.pub create mode 100644 examples/eks-lab/eks/locals.tf create mode 100644 examples/eks-lab/eks/main.tf create mode 100644 examples/eks-lab/eks/outputs.tf create mode 100644 examples/eks-lab/eks/provider.tf create mode 100644 examples/eks-lab/eks/terraform.tfstate create mode 100644 examples/eks-lab/eks/terraform.tfstate.backup create mode 100644 examples/eks-lab/eks/terraform.tfvars create mode 100644 examples/eks-lab/eks/variables.tf create mode 100644 examples/eks-lab/network/.terraform.lock.hcl create mode 100644 examples/eks-lab/network/.terraform/modules/modules.json create mode 120000 examples/eks-lab/network/.terraform/providers/registry.terraform.io/hashicorp/aws/4.55.0/linux_amd64 create mode 100644 examples/eks-lab/network/README.md create mode 100644 examples/eks-lab/network/locals.tf create mode 100644 examples/eks-lab/network/main.tf create mode 100644 examples/eks-lab/network/outputs.tf create mode 100644 examples/eks-lab/network/provider.tf create mode 100644 examples/eks-lab/network/terraform.tfstate create mode 100644 examples/eks-lab/network/terraform.tfstate.backup create mode 100644 examples/eks-lab/network/terraform.tfvars create mode 100644 examples/eks-lab/network/variables.tf create mode 100644 examples/eks-managed-nodegroup/README.md create mode 100644 examples/eks-managed-nodegroup/bastion.tf create mode 100644 examples/eks-managed-nodegroup/locals.tf create mode 100644 examples/eks-managed-nodegroup/main.tf create mode 100644 examples/eks-managed-nodegroup/provider.tf create mode 100644 examples/eks-managed-nodegroup/terraform.tfstate create mode 100644 examples/eks-managed-nodegroup/terraform.tfstate.backup create mode 100644 examples/eks-managed-nodegroup/terraform.tfvars create mode 100644 examples/eks-managed-nodegroup/variables.tf create mode 100644 examples/emr/main.tf create mode 100644 examples/emr/outputs.tf create mode 100644 examples/emr/provider.tf create mode 100644 examples/emr/terraform.tfvars create mode 100644 examples/emr/variables.tf create mode 100644 examples/external-data-source/.terraform.lock.hcl create mode 120000 examples/external-data-source/.terraform/providers/registry.terraform.io/hashicorp/external/2.2.2/linux_amd64 create mode 100755 examples/external-data-source/list-rds-instances.sh create mode 100644 examples/external-data-source/main.tf create mode 100644 examples/iam.user/main.tf create mode 100644 examples/iam.user/terraform.tfvars create mode 100644 examples/iam.user/variables.tf create mode 100644 examples/lambda-layers/.terraform.lock.hcl create mode 120000 examples/lambda-layers/.terraform/providers/registry.opentofu.org/hashicorp/archive/2.5.0/linux_amd64 create mode 120000 examples/lambda-layers/.terraform/providers/registry.opentofu.org/hashicorp/aws/5.64.0/linux_amd64 create mode 100644 examples/lambda-layers/README.md create mode 100644 examples/lambda-layers/function.py create mode 100644 examples/lambda-layers/function1.zip create mode 100644 examples/lambda-layers/lambda-layer1.zip create mode 100755 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/bin/normalizer create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/INSTALLER create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/LICENSE create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/METADATA create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/RECORD create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/WHEEL create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/top_level.txt create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__main__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/__main__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/core.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/cacert.pem create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/core.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/py.typed create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/INSTALLER create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/LICENSE create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/METADATA create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/RECORD create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/WHEEL create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/entry_points.txt create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/top_level.txt create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__main__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/__main__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/api.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/cd.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/constant.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/legacy.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/md.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/models.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/utils.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/version.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/api.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cd.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__main__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__pycache__/__main__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/constant.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/legacy.py create mode 100755 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md.cpython-312-x86_64-linux-gnu.so create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md.py create mode 100755 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md__mypyc.cpython-312-x86_64-linux-gnu.so create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/models.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/py.typed create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/utils.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/version.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/INSTALLER create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/LICENSE.md create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/METADATA create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/RECORD create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/WHEEL create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/codec.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/compat.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/core.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/idnadata.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/intranges.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/package_data.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/uts46data.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/codec.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/compat.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/core.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/idnadata.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/intranges.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/package_data.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/py.typed create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/uts46data.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/INSTALLER create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/LICENSE create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/METADATA create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/RECORD create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/REQUESTED create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/WHEEL create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/top_level.txt create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/__version__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/_internal_utils.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/adapters.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/api.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/auth.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/certs.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/compat.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/cookies.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/exceptions.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/help.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/hooks.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/models.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/packages.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/sessions.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/status_codes.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/structures.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/utils.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__version__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/_internal_utils.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/adapters.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/api.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/auth.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/certs.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/compat.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/cookies.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/exceptions.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/help.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/hooks.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/models.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/packages.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/sessions.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/status_codes.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/structures.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/utils.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/INSTALLER create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/METADATA create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/RECORD create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/WHEEL create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/licenses/LICENSE.txt create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/_base_connection.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/_collections.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/_request_methods.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/_version.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/connection.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/connectionpool.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/exceptions.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/fields.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/filepost.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/http2.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/poolmanager.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/response.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_base_connection.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_collections.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_request_methods.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_version.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/connection.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/connectionpool.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/pyopenssl.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/socks.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/connection.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/fetch.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/request.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/response.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/connection.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/emscripten_fetch_worker.js create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/fetch.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/request.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/response.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/pyopenssl.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/socks.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/exceptions.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/fields.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/filepost.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/http2.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/poolmanager.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/py.typed create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/response.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__init__.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/__init__.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/connection.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/proxy.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/request.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/response.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/retry.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/ssl_.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/ssl_match_hostname.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/ssltransport.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/timeout.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/url.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/util.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/wait.cpython-312.pyc create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/connection.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/proxy.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/request.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/response.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/retry.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssl_.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssl_match_hostname.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssltransport.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/timeout.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/url.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/util.py create mode 100644 examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/wait.py create mode 100644 examples/lambda-layers/main.tf create mode 100644 examples/lambda-layers/provider.tf create mode 100644 examples/skel/README.md create mode 100644 examples/skel/main.tf create mode 100644 examples/skel/provider.tf create mode 100644 examples/skel/terraform.tfvars create mode 100644 examples/skel/variables.tf create mode 100644 headdesk-aws/all-layers/ec2.tf create mode 100644 headdesk-aws/all-layers/main.tf create mode 100644 headdesk-aws/all-layers/provider.tf create mode 100644 headdesk-aws/all-layers/security.tf create mode 100644 headdesk-aws/all-layers/terraform.tfvars create mode 100644 headdesk-aws/all-layers/variables.tf create mode 100644 layers/networking/base-network-experimental/.terraform.lock.hcl create mode 100644 layers/networking/base-network-experimental/main.tf create mode 100644 layers/networking/base-network/.terraform.lock.hcl create mode 100644 layers/networking/base-network/main.tf create mode 100644 layers/networking/base-network/outputs.tf create mode 100644 layers/networking/base-network/provider.tf create mode 100644 layers/networking/base-network/terraform.tfvars create mode 100644 layers/networking/base-network/variables.tf create mode 100644 modules/ApplicationIntegration/apigw-lambda/README.md create mode 100644 modules/ApplicationIntegration/apigw-lambda/examples/main.tf create mode 100644 modules/ApplicationIntegration/apigw-lambda/main.tf create mode 100644 modules/ApplicationIntegration/apigw-lambda/outputs.tf create mode 100644 modules/ApplicationIntegration/apigw-lambda/variables.tf create mode 100644 modules/ApplicationIntegration/apigw-lambda/versions.tf create mode 160000 modules/ApplicationIntegration/terraform-aws-apigateway-v2 create mode 100644 modules/FrontendWebMobile/Ses/README.md create mode 100644 modules/FrontendWebMobile/Ses/main.tf create mode 100644 modules/FrontendWebMobile/Ses/variables.tf create mode 100644 modules/FrontendWebMobile/Ses/versions.tf create mode 100644 modules/ManagementGovernance/CwAgentInstallUsingSsm/README.md create mode 100644 modules/ManagementGovernance/CwAgentInstallUsingSsm/main.tf create mode 100644 modules/ManagementGovernance/CwAgentInstallUsingSsm/versions.tf create mode 100644 modules/ManagementGovernance/Cwl-firehose-s3/README.md create mode 100644 modules/ManagementGovernance/Cwl-firehose-s3/main.tf create mode 100644 modules/ManagementGovernance/Cwl-firehose-s3/outputs.tf create mode 100644 modules/ManagementGovernance/Cwl-firehose-s3/variables.tf create mode 100644 modules/ManagementGovernance/Cwl-firehose-s3/versions.tf create mode 100644 modules/ManagementGovernance/Monitoring.ALB/README.md create mode 100755 modules/ManagementGovernance/Monitoring.ALB/list-alb-targetgroups.sh create mode 100644 modules/ManagementGovernance/Monitoring.ALB/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.ALB/outputs.tf create mode 100644 modules/ManagementGovernance/Monitoring.ALB/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.ALB/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.ASG/README.md create mode 100644 modules/ManagementGovernance/Monitoring.ASG/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.ASG/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.ASG/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.EC2/README.md create mode 100755 modules/ManagementGovernance/Monitoring.EC2/get-cwagent-device.sh create mode 100755 modules/ManagementGovernance/Monitoring.EC2/get-cwagent-dimensions.sh create mode 100755 modules/ManagementGovernance/Monitoring.EC2/get-os-platform.sh create mode 100644 modules/ManagementGovernance/Monitoring.EC2/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.EC2/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.EC2/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.EKS/README.md create mode 100644 modules/ManagementGovernance/Monitoring.EKS/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.EKS/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.EKS/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.EMR/README.md create mode 100644 modules/ManagementGovernance/Monitoring.EMR/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.EMR/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.EMR/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.EventBridge/README.md create mode 100644 modules/ManagementGovernance/Monitoring.EventBridge/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.EventBridge/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.EventBridge/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.Kafka/README.md create mode 100644 modules/ManagementGovernance/Monitoring.Kafka/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.Kafka/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.Kafka/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.NGW/README.md create mode 100644 modules/ManagementGovernance/Monitoring.NGW/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.NGW/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.NGW/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.NLB/README.md create mode 100644 modules/ManagementGovernance/Monitoring.NLB/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.NLB/outputs.tf create mode 100644 modules/ManagementGovernance/Monitoring.NLB/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.NLB/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.OpenSearch/README.md create mode 100644 modules/ManagementGovernance/Monitoring.OpenSearch/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.OpenSearch/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.OpenSearch/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.RDS/README.md create mode 100644 modules/ManagementGovernance/Monitoring.RDS/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.RDS/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.RDS/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.Redis/README.md create mode 100644 modules/ManagementGovernance/Monitoring.Redis/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.Redis/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.Redis/variables.tf create mode 100644 modules/ManagementGovernance/Monitoring.TGW/README.md create mode 100644 modules/ManagementGovernance/Monitoring.TGW/main.tf create mode 100644 modules/ManagementGovernance/Monitoring.TGW/provider.tf create mode 100644 modules/ManagementGovernance/Monitoring.TGW/variables.tf create mode 100644 modules/ManagementGovernance/SnsTopicEmailSubscription/README.md create mode 100644 modules/ManagementGovernance/SnsTopicEmailSubscription/main.tf create mode 100644 modules/ManagementGovernance/SnsTopicEmailSubscription/outputs.tf create mode 100644 modules/ManagementGovernance/SnsTopicEmailSubscription/variables.tf create mode 100644 modules/ManagementGovernance/SnsTopicEmailSubscription/versions.tf create mode 100644 modules/ManagementGovernance/acm-cert-expiry-notice/README.md create mode 100644 modules/ManagementGovernance/acm-cert-expiry-notice/examples/main.tf create mode 100644 modules/ManagementGovernance/acm-cert-expiry-notice/main.tf create mode 100644 modules/ManagementGovernance/acm-cert-expiry-notice/variables.tf create mode 100644 modules/ManagementGovernance/acm-cert-expiry-notice/versions.tf create mode 100644 modules/ManagementGovernance/ssm-schedule-run-command/README.md create mode 100644 modules/ManagementGovernance/ssm-schedule-run-command/main.tf create mode 100644 modules/ManagementGovernance/ssm-schedule-run-command/variables.tf create mode 100644 modules/ManagementGovernance/ssm-schedule-run-command/versions.tf create mode 100644 modules/compute/ec2-instance-scheduler/Ec2Scheduler.py create mode 100644 modules/compute/ec2-instance-scheduler/README.md create mode 100644 modules/compute/ec2-instance-scheduler/main.tf create mode 100644 modules/compute/ec2-instance-scheduler/variables.tf create mode 100644 modules/compute/ec2-instance-scheduler/versions.tf create mode 100644 modules/compute/ec2/README.md create mode 100644 modules/compute/ec2/main.tf create mode 100644 modules/compute/ec2/outputs.tf create mode 100644 modules/compute/ec2/provider.tf create mode 100644 modules/compute/ec2/variable.tf create mode 100644 modules/compute/security-groups/README.md create mode 100644 modules/compute/security-groups/main.tf create mode 100644 modules/compute/security-groups/outputs.tf create mode 100644 modules/compute/security-groups/variables.tf create mode 100644 modules/compute/security_group/README.md create mode 100644 modules/compute/security_group/main.tf create mode 100644 modules/compute/security_group/outputs.tf create mode 100644 modules/compute/security_group/variables.tf create mode 100644 modules/compute/sg_default_tags/README.md create mode 100644 modules/compute/sg_default_tags/main.tf create mode 100644 modules/compute/sg_default_tags/outputs.tf create mode 100644 modules/compute/sg_default_tags/variables.tf create mode 100644 modules/global-variables/README.md create mode 100644 modules/global-variables/outputs.tf create mode 100644 modules/networking/VpcSubnet/README.md create mode 100644 modules/networking/VpcSubnet/example/main.tf create mode 100644 modules/networking/VpcSubnet/main.tf create mode 100644 modules/networking/VpcSubnet/modules/RouteTables/README.md create mode 100644 modules/networking/VpcSubnet/modules/RouteTables/main.tf create mode 100644 modules/networking/VpcSubnet/modules/RouteTables/variables.tf create mode 100644 modules/networking/VpcSubnet/outputs.tf create mode 100644 modules/networking/VpcSubnet/variables.tf create mode 100644 modules/networking/VpcSubnet/versions.tf create mode 100644 modules/networking/VpcSubnet/vpc-flowlog.tf create mode 100644 modules/networking/delete-default-vpcs/README.md create mode 100755 modules/networking/delete-default-vpcs/exec.sh create mode 100644 modules/networking/delete-default-vpcs/main.tf create mode 100644 modules/networking/nacl/README.md create mode 100644 modules/networking/nacl/main.tf create mode 100644 modules/networking/nacl/provider.tf create mode 100644 modules/networking/nacl/variables.tf create mode 100644 modules/networking/r53-record-geo/README.md create mode 100644 modules/networking/r53-record-geo/main.tf create mode 100644 modules/networking/r53-record-geo/variables.tf create mode 100644 modules/networking/r53-record/README.md create mode 100644 modules/networking/r53-record/main.tf create mode 100644 modules/networking/r53-record/variables.tf create mode 100644 modules/networking/vpc-endpoints/README.md create mode 100644 modules/networking/vpc-endpoints/main.tf create mode 100644 modules/networking/vpc-endpoints/provider.tf create mode 100644 modules/networking/vpc-endpoints/variables.tf create mode 100644 modules/networking/vpc-subnet-manual-5r/README.md create mode 100644 modules/networking/vpc-subnet-manual-5r/main.tf create mode 100644 modules/networking/vpc-subnet-manual-5r/outputs.tf create mode 100644 modules/networking/vpc-subnet-manual-5r/provider.tf create mode 100644 modules/networking/vpc-subnet-manual-5r/variables.tf create mode 100644 modules/networking/vpc-subnet-manual-5r/vpc-flowlog.tf create mode 100644 modules/networking/vpc_subnets/README.md create mode 100644 modules/networking/vpc_subnets/main.tf create mode 100644 modules/networking/vpc_subnets/outputs.tf create mode 100644 modules/networking/vpc_subnets/variables.tf create mode 100644 modules/networking/vpc_subnets/vpc-flowlog.tf create mode 100644 modules/networking/vpc_subnets/vpc.tf create mode 100644 modules/security_identity_compliance/aws_config/Cis14Level1.yaml create mode 100644 modules/security_identity_compliance/aws_config/README.md create mode 100644 modules/security_identity_compliance/aws_config/cis-rules.tf-no create mode 100644 modules/security_identity_compliance/aws_config/main.tf create mode 100644 modules/security_identity_compliance/aws_config/provider.tf create mode 100644 modules/security_identity_compliance/aws_config/variables.tf create mode 100644 modules/security_identity_compliance/cloudtrail_cwlogs/README.md create mode 100644 modules/security_identity_compliance/cloudtrail_cwlogs/cloudtrail.tf create mode 100644 modules/security_identity_compliance/cloudtrail_cwlogs/ct-key.tf create mode 100644 modules/security_identity_compliance/cloudtrail_cwlogs/ct-s3-bucket.tf create mode 100644 modules/security_identity_compliance/cloudtrail_cwlogs/cw-loggroup.tf create mode 100644 modules/security_identity_compliance/cloudtrail_cwlogs/main.tf create mode 100644 modules/security_identity_compliance/cloudtrail_cwlogs/outputs.tf create mode 100644 modules/security_identity_compliance/cloudtrail_cwlogs/variables.tf create mode 100644 modules/security_identity_compliance/ds-adconnector/main.tf create mode 100644 modules/security_identity_compliance/ds-adconnector/outputs.tf create mode 100644 modules/security_identity_compliance/ds-adconnector/variables.tf create mode 100644 modules/security_identity_compliance/five-deployer-roles/README.md create mode 100644 modules/security_identity_compliance/five-deployer-roles/locals.tf create mode 100644 modules/security_identity_compliance/five-deployer-roles/main.tf create mode 100644 modules/security_identity_compliance/five-deployer-roles/outputs.tf create mode 100644 modules/security_identity_compliance/five-deployer-roles/provider.tf create mode 100644 modules/security_identity_compliance/five-deployer-roles/variables.tf create mode 100644 modules/security_identity_compliance/guardduty/README.md create mode 100644 modules/security_identity_compliance/guardduty/main.tf create mode 100644 modules/security_identity_compliance/guardduty/outputs.tf create mode 100644 modules/security_identity_compliance/guardduty/variables.tf create mode 100644 modules/security_identity_compliance/iam-group/README.md create mode 100644 modules/security_identity_compliance/iam-group/main.tf create mode 100644 modules/security_identity_compliance/iam-group/outputs.tf create mode 100644 modules/security_identity_compliance/iam-group/variables.tf create mode 100644 modules/security_identity_compliance/iam-group/versions.tf create mode 100644 modules/security_identity_compliance/iam-role/LICENSE create mode 100644 modules/security_identity_compliance/iam-role/README.md create mode 100644 modules/security_identity_compliance/iam-role/examples/main.tf create mode 100644 modules/security_identity_compliance/iam-role/main.tf create mode 100644 modules/security_identity_compliance/iam-role/outputs.tf create mode 100644 modules/security_identity_compliance/iam-role/provider.tf create mode 100644 modules/security_identity_compliance/iam-role/variables.tf create mode 100644 modules/security_identity_compliance/iam-user/README.md create mode 100644 modules/security_identity_compliance/iam-user/main.tf create mode 100644 modules/security_identity_compliance/iam-user/outputs.tf create mode 100644 modules/security_identity_compliance/iam-user/variables.tf create mode 100644 modules/security_identity_compliance/iam-user/versions.tf create mode 100644 modules/security_identity_compliance/inspector2/README.md create mode 100644 modules/security_identity_compliance/inspector2/main.tf create mode 100644 modules/security_identity_compliance/other-default-settings/main.tf create mode 100644 modules/security_identity_compliance/roles_iam_resources/README.md create mode 100644 modules/security_identity_compliance/roles_iam_resources/access-analyzer.tf create mode 100644 modules/security_identity_compliance/roles_iam_resources/cloudhealth-role.tf create mode 100644 modules/security_identity_compliance/roles_iam_resources/iam-password-policy.tf create mode 100644 modules/security_identity_compliance/roles_iam_resources/main.tf create mode 100644 modules/security_identity_compliance/roles_iam_resources/variables.tf create mode 100644 modules/security_identity_compliance/secretsmanager-secret/README.md create mode 100644 modules/security_identity_compliance/secretsmanager-secret/main.tf create mode 100644 modules/security_identity_compliance/secretsmanager-secret/outputs.tf create mode 100644 modules/security_identity_compliance/secretsmanager-secret/provider.tf create mode 100644 modules/security_identity_compliance/secretsmanager-secret/variables.tf create mode 100644 modules/security_identity_compliance/security_hub/main.tf create mode 100644 modules/security_identity_compliance/sso-aws-id-store/README.md create mode 100644 modules/security_identity_compliance/sso-aws-id-store/main.tf create mode 100644 modules/security_identity_compliance/sso-aws-id-store/variables.tf create mode 100644 modules/security_identity_compliance/sso-permissionsets/README.md create mode 100644 modules/security_identity_compliance/sso-permissionsets/main.tf create mode 100644 modules/security_identity_compliance/sso-permissionsets/outputs.tf create mode 100644 modules/security_identity_compliance/sso-permissionsets/variables.tf create mode 100644 modules/security_identity_compliance/terraform-user/main.tf create mode 100644 modules/security_identity_compliance/terraform-user/outputs.tf create mode 100644 modules/security_identity_compliance/terraform-user/provider.tf create mode 100644 modules/security_identity_compliance/terraform-user/variables.tf create mode 100644 modules/storage/aws-backup/README.md create mode 100644 modules/storage/aws-backup/kms-key.tf create mode 100644 modules/storage/aws-backup/main.tf create mode 100644 modules/storage/aws-backup/variables.tf create mode 100644 modules/storage/infra-s3-bucket/README.md create mode 100644 modules/storage/infra-s3-bucket/main.tf create mode 100644 modules/storage/infra-s3-bucket/outputs.tf create mode 100644 modules/storage/infra-s3-bucket/variables.tf create mode 100644 modules/storage/s3-bucket-replication/README.md create mode 100644 modules/storage/s3-bucket-replication/main.tf create mode 100644 modules/storage/s3-bucket-replication/outputs.tf create mode 100644 modules/storage/s3-bucket-replication/variables.tf create mode 100644 modules/storage/s3-bucket-replication/versions.tf create mode 100644 modules/storage/s3_bucket_2023/README.md create mode 100644 modules/storage/s3_bucket_2023/main.tf create mode 100644 modules/storage/s3_bucket_2023/outputs.tf create mode 100644 modules/storage/s3_bucket_2023/variables.tf create mode 100644 modules/storage/s3_bucket_2023/versions.tf create mode 100644 modules/syntax-test/main.tf create mode 100644 modules/syntax-test/variables.tf create mode 100644 modules/terraform-setup/README.md create mode 100644 modules/terraform-setup/examples/.terraform.lock.hcl create mode 100644 modules/terraform-setup/examples/main.tf create mode 100644 modules/terraform-setup/main.tf create mode 100644 modules/terraform-setup/outputs.tf create mode 100644 modules/terraform-setup/variables.tf create mode 100644 modules/util/account-list/README.md create mode 100644 modules/util/account-list/main.tf create mode 100644 modules/util/account-list/outputs.tf create mode 100644 modules/util/account-list/provider.tf create mode 100644 modules/util/assume_role/README.md create mode 100755 modules/util/assume_role/assumeRole.sh create mode 100644 modules/util/assume_role/main.tf create mode 100644 modules/util/assume_role/variables.tf create mode 100644 modules/util/aws-region-short/README.md create mode 100644 modules/util/aws-region-short/examples/main.tf create mode 100644 modules/util/aws-region-short/main.tf create mode 100644 modules/util/aws-region-short/provider.tf create mode 100644 modules/util/awscli/README.md create mode 100644 modules/util/awscli/main.tf create mode 100755 modules/util/awscli/run_awscli.sh create mode 100644 modules/util/awscli/variables.tf create mode 100644 modules/util/random/main.tf create mode 100644 modules/util/resource-list/README.md create mode 100755 modules/util/resource-list/list-alb-targetgroups.sh create mode 100755 modules/util/resource-list/list-alb.sh create mode 100755 modules/util/resource-list/list-asg.sh create mode 100755 modules/util/resource-list/list-ec2.sh create mode 100755 modules/util/resource-list/list-emr.sh create mode 100755 modules/util/resource-list/list-kafka.sh create mode 100755 modules/util/resource-list/list-ngw.sh create mode 100755 modules/util/resource-list/list-nlb-targetgroups.sh create mode 100755 modules/util/resource-list/list-nlb.sh create mode 100755 modules/util/resource-list/list-opensearch.sh create mode 100755 modules/util/resource-list/list-rds.sh create mode 100644 modules/util/resource-list/list-redis.sh create mode 100755 modules/util/resource-list/list-tgw.sh create mode 100644 modules/util/resource-list/main.tf create mode 100644 modules/util/resource-list/variables.tf create mode 100644 modules/util/terraform-aws-cli/.gitignore create mode 100644 modules/util/terraform-aws-cli/.pre-commit-config.yaml create mode 100644 modules/util/terraform-aws-cli/.terraform-version create mode 100644 modules/util/terraform-aws-cli/.tflint.hcl create mode 100644 modules/util/terraform-aws-cli/.travis.yml create mode 100644 modules/util/terraform-aws-cli/CHANGELOG.md create mode 100644 modules/util/terraform-aws-cli/README.md create mode 100644 modules/util/terraform-aws-cli/main.tf create mode 100755 modules/util/terraform-aws-cli/scripts/awsWithAssumeRole.sh create mode 100644 modules/util/terraform-aws-cli/tests/bad_arn/terraform.tfvars create mode 100755 modules/util/terraform-aws-cli/tests/bad_arn/test.sh create mode 100644 modules/util/terraform-aws-cli/tests/common.sh create mode 100644 modules/util/terraform-aws-cli/tests/empty_result/expected_variables.json create mode 100644 modules/util/terraform-aws-cli/tests/empty_result/notes.txt create mode 100644 modules/util/terraform-aws-cli/tests/empty_result/terraform.tfvars create mode 100755 modules/util/terraform-aws-cli/tests/empty_result/test.sh create mode 100644 modules/util/terraform-aws-cli/tests/role_session_name_invalid_characters/terraform.tfvars create mode 100755 modules/util/terraform-aws-cli/tests/role_session_name_invalid_characters/test.sh create mode 100644 modules/util/terraform-aws-cli/tests/role_session_name_optional/expected_variables.json create mode 100644 modules/util/terraform-aws-cli/tests/role_session_name_optional/terraform.tfvars create mode 100755 modules/util/terraform-aws-cli/tests/role_session_name_optional/test.sh create mode 100644 modules/util/terraform-aws-cli/tests/role_session_name_too_long/terraform.tfvars create mode 100755 modules/util/terraform-aws-cli/tests/role_session_name_too_long/test.sh create mode 100644 modules/util/terraform-aws-cli/tests/test_with_debug/expected_variables.json create mode 100644 modules/util/terraform-aws-cli/tests/test_with_debug/terraform.tfvars create mode 100755 modules/util/terraform-aws-cli/tests/test_with_debug/test.sh create mode 100644 modules/util/terraform-aws-cli/tests/test_without_debug/expected_variables.json create mode 100644 modules/util/terraform-aws-cli/tests/test_without_debug/terraform.tfvars create mode 100755 modules/util/terraform-aws-cli/tests/test_without_debug/test.sh create mode 100755 modules/util/terraform-aws-cli/tests/tests.sh create mode 100644 modules/util/terraform-aws-cli/variables.tf create mode 100644 modules/util/terraform-aws-cli/versions.tf create mode 100644 rslab-ali/network/main.tf create mode 100644 rslab-ali/network/outputs.tf create mode 100644 rslab-ali/network/provider.tf diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..4ea01ad --- /dev/null +++ b/.gitignore @@ -0,0 +1,17 @@ +*.tfstate.backup +*.backup +*.tfstate +*.tfstate.lock +**/*.tfstate +**/*.backup +.terraform/ +.DS_Store +*.iml +.idea +.terraform.lock.hcl +*.log +examples/ +experimental/ +headdesk-aws/ +vsphere-yige/ +anz-sandbox/ diff --git a/.gitmodules b/.gitmodules new file mode 100644 index 0000000..98f9daa --- /dev/null +++ b/.gitmodules @@ -0,0 +1,3 @@ +[submodule "modules/ApplicationIntegration/terraform-aws-apigateway-v2"] + path = modules/ApplicationIntegration/terraform-aws-apigateway-v2 + url = https://github.com/terraform-aws-modules/terraform-aws-apigateway-v2.git diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..f5f404b --- /dev/null +++ b/LICENSE @@ -0,0 +1,12 @@ +BSD Zero Clause License + +Permission to use, copy, modify, and/or distribute this software for any +purpose with or without fee is hereby granted. + +THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH +REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY +AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, +INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM +LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR +OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR +PERFORMANCE OF THIS SOFTWARE. diff --git a/README.md b/README.md new file mode 100644 index 0000000..bb295fc --- /dev/null +++ b/README.md @@ -0,0 +1,6 @@ +# terraform.aws-baseline-infra + +terraform modules for deploying baseline resources. + +## Repo info +URL: https://xpk.headdesk.me/git/xpk/terraform.aws-baseline-infra diff --git a/examples/awsbackup/.terraform.lock.hcl b/examples/awsbackup/.terraform.lock.hcl new file mode 100644 index 0000000..2270d33 --- /dev/null +++ b/examples/awsbackup/.terraform.lock.hcl @@ -0,0 +1,20 @@ +# This file is maintained automatically by "tofu init". +# Manual edits may be lost in future updates. + +provider "registry.opentofu.org/hashicorp/aws" { + version = "5.47.0" + constraints = "~> 5.0" + hashes = [ + "h1:oBap1Z3sKRRzRqKjkILpql/fa0gssLL/iqjDu62105I=", + "zh:0a22081994a733ef564fefdf9660e172af97ea2d2e34bcdaa4868300436248e8", + "zh:4a1be5a820a33baeaf81dc33d37e46a0f813f5395247f6449646fae7c9608a53", + "zh:8e156edfe38e2aed76c02e835eb6ba1fa4444feacdb824500cfdbad76abd0582", + "zh:9062035afc3d592dbbbd7f7cb41d4ce077e06584251aac50d116c04b4e3b4d3b", + "zh:a3abedd6b5640bf20d0d39ecaa938e382cbfe54dfb129c3fc291d9d695d9dffc", + "zh:b8ee3c37f497410a307e102638f8ce1cc1c77099498ff5438e506ce604cdf8dd", + "zh:c64d812bfdff6e7a6729bc035f6f8c86e69a01e9409fe1db551a233e320dc9e5", + "zh:c8df7f2993fdfc1bd15ab48eb280f4d11c5526c632c3beb62f014c0079715160", + "zh:cf413154640dcd5ee7286b43e395495f8f44d72f717cf2a20234c240cba528fa", + "zh:f5186377a986b96150611d891700d49125367b4ad3ab534b429305e8fdaa8dcc", + ] +} diff --git a/examples/awsbackup/main.tf b/examples/awsbackup/main.tf new file mode 100644 index 0000000..0d69f2d --- /dev/null +++ b/examples/awsbackup/main.tf @@ -0,0 +1,40 @@ +module "aws-backup" { + source = "../../modules/storage/aws-backup" + + daily-backup-cron = var.daily-backup-cron + monthly-backup-cron = var.monthly-backup-cron + daily-backup-retention = var.daily-backup-retention + monthly-backup-retention = var.monthly-backup-retention + service-opt-in = { + "Aurora" : { + enabled = false + } + "DynamoDB" : { + enabled = true + } + "EBS" : { + enabled = false + } + "EC2" : { + enabled = true + } + "EFS" : { + enabled = true + } + "FSx" : { + enabled = false + } + "Redshift" : { + enabled = true + } + "RDS" : { + enabled = true + } + "VirtualMachine" : { + enabled = false + } + "S3" : { + enabled = false + } + } +} \ No newline at end of file diff --git a/examples/awsbackup/provider.tf b/examples/awsbackup/provider.tf new file mode 100644 index 0000000..bdfe008 --- /dev/null +++ b/examples/awsbackup/provider.tf @@ -0,0 +1,23 @@ +provider "aws" { + region = var.aws-region + default_tags { + tags = { + ServiceProvider = "RackspaceTechnology" + Environment = var.environment + Project = var.project + Application = var.application + Owner = var.owner + TerraformDir = "${reverse(split("/", path.cwd))[1]}/${reverse(split("/", path.cwd))[0]}" + } + } +} + +terraform { + required_version = ">= 1.3.9" + required_providers { + aws = { + source = "hashicorp/aws" + version = "~> 5.0" + } + } +} diff --git a/examples/awsbackup/terraform.tfvars b/examples/awsbackup/terraform.tfvars new file mode 100644 index 0000000..305150e --- /dev/null +++ b/examples/awsbackup/terraform.tfvars @@ -0,0 +1,11 @@ +aws-region = "ap-east-1" +customer-name = "ken2026" +environment = "dev" +project = "iac" +application = "backup" +owner = "ken2026" +daily-backup-retention = 31 +daily-backup-cron = "cron(0 20 * * ? *)" +monthly-backup-retention = 365 +monthly-backup-cron = "cron(0 20 1 * ? *)" +# cron(Minutes Hours Day-of-month Month Day-of-week Year) \ No newline at end of file diff --git a/examples/awsbackup/variables.tf b/examples/awsbackup/variables.tf new file mode 100644 index 0000000..49c60e5 --- /dev/null +++ b/examples/awsbackup/variables.tf @@ -0,0 +1,11 @@ +variable "aws-region" {} +variable "customer-name" {} +variable "environment" {} +variable "project" {} +variable "application" {} +variable "owner" {} + +variable "daily-backup-retention" {} +variable "daily-backup-cron" {} +variable "monthly-backup-retention" {} +variable "monthly-backup-cron" {} \ No newline at end of file diff --git a/examples/backup.tar b/examples/backup.tar new file mode 100644 index 0000000000000000000000000000000000000000..9085c376b2614b5b098099db2747e460e2038c46 GIT binary patch literal 3553280 zcmeFaYjfi^mOehO^C?{1-;0^8q0BoaSLH?S+q=`*OgcOB-_1^`cmZw35~(36cbu(! z_x}Tsph%FEsB2p`JelscgbN8A0M9u%=RA|!Kb-wX!;fp*f52b5YirHF=~wjU54vTV zn&VogtK)lDGweUy*k^w-bg<3~FT1(l23~0Jda5y z*s-kUymL9AU+Ipa)A=_X-7sy#{e!0KCY^unJde|E^^MOzpZy!f`EJ;!b->kCq7ZQk{daKnU4!ok{aH0w^)#D9*3wO7thL#Qar?YS!$8u+x+JL zKD)UIKC0fr%a-aYBT@Y8&F44D|NFo7YDKa?Vgx4DTm0#FwfSk|t^f49f>uHjdFw@? z7T$f1CTPPqHy=p$6bIyoEPcXLV2{BMn*Y%Y9`ltKke^8Kkfe+B{+Tv$bMwt+Ea|W8 z=kpu-6pj8^Ni<2vmKSQ2te%&Z`eHNIb;+{5#w@UsKani+qBL8+PeW3b#gi_*#JeY9 z`E-Br@&aGSQA|SK+~+s6l2>5V$sd*f#?SlrUw^Iq`KE}M1pDf8^~XQ`iS@v1e)-Jn z(y^ekHG$lTlQp4JHSw~9)%{N@8JlYCU*&r+nPFwVf~0)KBxO^uEVGdzRX`k$J6Ae?{dffZ&-S@|67{v+6MN2!>~=c|DS#)x-D+x zw7GB;Z>16}cvV+EYl&=C2%CdXJms^-##C3wcOiLFKC7g<{+#}UZYutx@>yd8s=ue- zrAb_*S)AOX+j{S>OVrhSmMZ;D`HXD{oAT^m_<}v_XSe_QSr+DMoM2~4u$beJ?$tjl zA0Hld6-CrI2vj_tipN)JNgq4)dZiZF%9KB28yGGbEOSlYRp!|rRmRxS&N5i-Y-hRh zyj=A(U0r*-o}HI9_9$zPE{k{GqwM%+@U?xO!D>B&(L3ATeMShI|KQoDGEmRMnDTkN z8Rs$OoAc6N9x^rJDQKzPebZ9Ad*qU^k>vg-C;l{_Om3H6oSaSdV=uM+{D;zKvh$zm|C&k9f6Z_mdH!EQ zB9>{mUXUB5c`{Nh3CCTDdHHFIV{|gP#eZdu{B~W$i`yC*FJc^$O{iQvuLwPq(J;fc z&5j!9JnQLSs2(vVUhse#MVga>DPPTJqNg=gB}9FVKOX-6{D$du6QKwy)vY&5SO5I{ zrhKqTv$K4H_oDh7o}@Dntu{KN@}B8TR3H8>eIi*xk;d)&8rMvI{Q5&jVQjTnzeZE1 zqyyW8E>siW)cX8}4&CI*TdWC677uv(hjbCDU#-^vg;|P!V+uDae10?2S|z^4nMaL3 z@5wUFsBZT8jjbCu|9XQZXjOl8DtrJ&gJSrBDzUUeyLex%ujBmjuWPa7{QO3nXlASLzh`klnuY2zUO+7hxk?iHGPQn6hX^_rnuR_;9B@5xsMa_)eryGUJ+H@&cgT_rU~E6tA+7jIpqBZ0uw+2 z6Au-7VI6&i1xWraE`EdvHy@|`_vbfMkhchFt4fc=lEA3-mXpdW8g5A|?Pw2K<&!0d zGhTMgmfL!((ek+Wmix_Dc*m^*$X`Q{x#sf;A~z^z9Rcfz%91SS5w_iW&OgUyOMhB> zUH;KqwTktY!e;X*mSX#_rnUcSwase932c3NS-EPvRS4>P0NW~x6lvit*vY`2af=xD zNN%$5RT%P4Dzs>`CA74UJ%pCN$^l4$R;#cAf2q+jOY82raen`oFLy}o<~;f`nHUvD5;@^AwqOc4h+4@I$}_SF@RZ*t=$;myYw2q8&ta4mOF ziko|C+`sXPg6^V?Xfbk zuRH)pL0hh|6j^3!bt<29jicSx8mIk;GbNlljZvllFl(V+<;_>yW2K|x zJ(v17?|u>1WMI=1c%^Wet$|OlQ!2{*ZKW;X*obp zY8gStBSm9xsrcfU26z3Q*(9)3rc^3Ux&@>w zf-}L(f```JqO`nsB-f!4YR|4#6GMbC7yWxp2AEN>O&GeqV(uR zkKS2M6xMP}lFGiu3lm>S<==ct_7N?yg$hr$UwW*tiH+?kdjCO3dg~6;?f`SxdjfHt zyls;b>f+ZyiTs~5{SQLmaq%Ph=Nflym1w=s-xH5wP-ZC_+>V5fYLU8x@$?n+0h8{= z0RZ#+IC%&bCw{N(_J7SXO8dWITaM*g4!!@kaSb5-zfL?4ea-#L%}?;Pxrt(20^o0Y zh!^-jY^dHEUSCv4g9`V2<3GcJihGLO0RI)rr znZO_6=7yGIXUfm`1=sQq`kiKd|8DlHX(b;Y?(ZKylBW;fh50Xe{?BLox8I)L=YPF7 z{`$*m`Ri?>ea>zpQSG;fJALNsj%K;O73nsa`BU4RdWJtU>_{h5eB+q2sYOWWhBH5O zr)27Ckx8cbY-+fk+i1!Rw9wZaZ|3Qiui2jKMrK6xDA0_VXGgwnn~^nhoEc<%rUl-V zxH<^}(=yy}YDRXeDc90mZ)zAbO|yyS`hnqEf$tHAm>w2MU|G61olbSlj{=7T#D@=! z<+#%*)TSP3HWkjC2rUJg=|*1UhbD0&i-dt564Ss3csfgW99xUf_RI*(nLah5z_q*? z(M+$=)HJdp+tLC%a?EgQxq;Ll<-AYf&`Sb?x)PA`xkUW(6}x4=kdSnX5T|WJ2I955H;N%ndc)&>}4&PS|V;QWsg8W|{_s55)ou z6VdPj{w&mVA0w?tct*^OVe6LXxSEYIo$8KDT-VgX##0eIMi^K#pXlM#cSCHrW@rZ( z4f?*8?>d^TYg3y{iR0?FH=WsGfalRn%XhTdw9!;#5ImGWMZJ*duIBqT?rdiUew>iL zk>@x%hT4n_JQ7Avw*%9knOa~(mZJr%DQ1cpzbSA#OJ`>=CivgL#z5R3SIPevKluOt z%{M&g^V=}{OaA}8`~J)2*ZS5^Ho<|}(vV-Qj(X{}d%={TdEATLGre;7I4AYs0 zf#Z3BF^e#I9`QUUa$U$vfZ_8@NE;^HXpXw=z@^6__*}<=&~z{GF~EdC9(8+Wc%d6W zc6ATl)h<@xbZSmbOtp3h;8q)bOWRHIAu4I0C$=9_qx? z9X+y5$kojEt*PlZh24#?p;@7c)nuc5ZokI;iW< z2sSU8zqvQl3Lkn8m zo|#itWdWT5H{c&w(QQt!~~#y+jJy;l03Zr4;oJeY7m z>nyL~=u?%dV<~nJ3mD>WsywT+VtzR5pcJR1}1fg%{Ot#$heGQux1r{@*c* z@Bb?Q*fh?a)i;k!7XW{3wit5Ui!Qy!O08#|eT|#bEcVyXz#C&nzrp)?0b6hglA@0} zMerqnEufUeHLS86Etw^>2>!amVBFtJ~h)`x+Zg^^jlu_@7@`@2sEx{_oCL|Ms6>{g?6g|M}|MyWVc9-GcU0 zZ4PCZ*uE0DOvg`T-Wr^r>77{lLxX#w-r(60EuM+gz`UO>!@v6cu7t`u0 zAGdC}%5PQv2OqVnC76=4XLOvb7YpI5(zz4g@fj_v;Gybo6!Ms>y@4V03mPPXxQ65& ze?SG+LTBo!(A*5wFzJy8y+ehXVG;+{AIH;gwztNDHP9HUYfvjS1GS-T!frED9iKSr z)X-gZ3I&1w;rOmKgPF%2-D+e6dH{QfN_<4PXfxuf77Pa}HM~xtsu9=GZ+iXY>1ARN zl2!R&Ivlf2+tsMw!0$O>=2B*MrhIS88lRmy6QcI-3>gccnY-ymH6IvoZ$&J}T7;Wp6*P%A!nXi>ObV zB)_Wz(%Q!k-S}BBEut@1t28UrHN1upjNA}2Y~#H><6bhz;uVWU#%SWc{cd2?TMx`< z>HU}gp?>|%-|o8g?oKLb_1yEPXdlHvEmcEf#K!sVQ$22wBD^Py^E8>`LO=81J5FWy zyNp29%zk?ClApN0y7;CPjIB~!NKhZdYO&niwBQYdEkvv_&U5&Wq20D1;@dB9i}3+h z7}Q^ddXjxlW7yIEX{V?qZLMt$k3gsbgO{DdO=q4XD0)HWCGNs_P>*8Vz0hY@#P_c% z;??FT8K;P(xVte0S*C|QZtTN3bEwO4U(?rAc|LzC8NhC{j-oh-@v?I|tIbs}F3xIi z~-ALyWb@%In6)EQV9!Su2DIIXFqdl`qkr{09hDaCWa>?O){ zYc9Wl5>8cX;jwA10o3kF{3h(5zI4OAq1^!9Z4))mN+L41Q=})1$g{q zxoK5fS2KqIEmXms(i+ez`M%0D@Fj(Cn>je4+JV<+i3Mo;G(NcV=09X*0t zV*^wb8so*GWVyi$QmPd6l$|f*JZB)B8aJpom%odJ*Yr{!UpKK+OALo0dh_W3OXDXT zceE+;{O`a0xACy>|Ndg%Ae&@XV<(oMA>*xH&t=b--Xwai9!8t*9wl*GA z=(#bNEJS=40CK446CmjctH)L1$p-i~Hu_@}|9w=90~Ng%a+j(G-y-SXQq|aMr#MjH z#MLBN|IV&*oanKyQuR3W-5cAPVDH2#c?BxSq2tm#nlKVl6~V44YDrQRk*bJPML4cd zr1B|jnzgn8R4!E!7&l&%Dl+DFNNOP4F40-;5qa4mrqH7%_A<2>yW1QiXD>(bIOJ)s zT;CY=%5O)_7&RQiK`FHhsa;U3l)UJ`AjpdjIR6MI8iqw`7s93~wTsrFdL7!uq3&W* zlaQLkklWOuG9~P>qO5>cSx=k-tR#gUBB) z-NGIvabWk7@-?|Q$r&Hz)W*G-M#$bWMFNB= zYY%A*3~5dgB(p&F zoyhXpXHz5+@qHJGqL45}XZ=n!n&|~;B}|*34ff1Pa^fJ`2{}=awPHrf&jKAuTQp=I z@C>BgDL;$o%exLiZXG%nv=6-aG(avNbBeqL`c!A11@;U%dyw|Q)o8u~_8F3~OuZR$ zQxIgvFxdMd!Hg9VY)c0jYdu)0VjfeaPMCZx|?)Aa({UVywH zQwubRF493*Gxiz5C^^V3p&_9J(&ad`93jRmKoShY^N?`DWn)F6$VSqhDNPKcBbQFo zle2r?e#+P^x~ptF(-E76HxebWwXnI{BfWav>?+LwUB2`;-|`TG<`%a3_P}lD6p>Wp zcO0-BQa@V!r6Ng&hcrpZpJ9i{W#X1BJ@nite?+wxZ#@(d#E0s(XVmKf;;rU+8pJew zWwrLf-8hd|b0j{2`!V&=?Tzbt^5TW(gLk5Mp8u96%(JA9-`dPx)j^Qa>|yhKMFNlu zR@{)-y+tRbD!269Tg8ZVNmm2CH;W;_Xc;FZ+hqT<5Zp#P1UosndA@TRK3w(v9V(Zr4=JjpXt8YwSZ$l24Yv(2sCIb@s_=@7pz=6c%?|O z3&x=Q-)?AwpwI%)~NA>~$$gN(d^O3~@xNrbV&-WNXV=^xH?feL&Dh5{x+PQEstn)f?^i6( zSF;%&s$YI4ZW?rbrwH*}qLcn5rC`M^JmdnP#mXSU5j%ho*($8#9nZ8v!UlwNEjl}o z`1BBHY%my{o*;JQ#-Fc{bpfY%$YSbHtZz4_wrO#f*e>1($wc-z#CYztpePRn zT&O}8?@Q-`udtpoj+Mo3gl8>zBjyk3YQDfCryEo&OugI{6jq~1k%okxoJ#p*$Y9jd zcs<$mdsMTIK;x3!V$b2IxxdhJ-vUiYL6JC?4c0nRU-EsFB#?S2K31qjNa`6NmD@}- zBeD!ibn#XZ8o~=H;s((pxvK@bqbg6rq2PpGhafWzg0k@Hl+L3)A3TzbHpEuMej-&$5EYVg>!NFlHRUlO z&-%{;DlwJt^;Pw}M(v*IWYy`G$$I1G7KVVW=)KMfK8!Jix{9t%OnYKl6AWQzoJwR~ zjrYK}Wi#TJSqk{}sSvOyZuiyTkA=WULeiEPR{x?9SRz?E=B=OCg=8IMt3x(Snt{`R zji^t(5Rk0iCzQtm*&N4m5_;J)P!$WWg&xj=WJUCVf@|<3K9}2hf01%OME;Xvj^ts% zBlefBuBm{}9%mER?bt6c?;(Myj~v%XtqdDnXE=s5J7t7cC!{0Tq6QtH%_$=^IpzDK zw75}nuk6s?4%6IzZ*POh)K1}F3&V*ekTnJA7pZ*ofP$vNuLN!ZD~I-x26W9i*2cu(W!niA=r1L4`w^mVyD)LRv{=2@jD&+0@!tY!k;VD6+$m z>-D2>P+PW94Jf}j=%#!-u>q4`X4G$8Uzh-OGDdo8oZ@p>XMUoC zatp;*4L%}q3Nnh82Ds6;DSX=bu?7vWG=B7%soNqbu0)_u5D8s$uMrIG&z>*=&tcz^M=wmXB3Uc<-Vfo_D z=31Ae#g|Ac7Ca!Om@uu%D@-9qu_eC~$j_Qg>|mAhbRhZzPL6f{6}1U{3nva_73C15 zo@oiFcV!@^m%Gq9VSZ_$Gw}c~(;o{-h$%oCF$v{{3+{6-Th@1lJiF`mHZFv@{>Sv;fhe^^QHVgG!=dUPGArc3xdaq zcHTG`|L~j_WOHsvD1Lb;E=<7zK)h^W3<^Gh$-4`^#&<74_$5I2`1v?31n(DQ3BY@9 zYDM1_3BY@a`~ZyV7zSw*mo{<8L&MprR~fx9hf2dHE&=#Kd8XbJ0H>~3^C%<7J6=g| zlFfFAXjW#n?y-D#2Ye^KuB%)KQ18{>0D}GtVrS1zeD`h%*SFGfWK8rhHfw&>Gwf~B zu{ZK6KkbNmLhA>(yLGx-dBp?uaZ>@st{fxYLZ0+oKhc zhQM|<{8yllylwA$iB3nMQ>l+wj$v7MNLPeBQ6WqEb6b<8-)3I$h}2Zb&SI#H1?8e_oQ2^@&_>Fy0H8?D*Dj{AsxX7(5@fcH~xIhBa--P~oIVd~|{S6@cvjiuI_K}wfnfDsLW5Dt*blg%mdKt*PAV}BX?C3QcQMp8#pcQft=ius~ z5feg>tVCIN*~`HI{x-50s#t<~d@B+q(PqUw$MiEA{(*es34I!x0KC5pO6?uAQnpTO z?o5^1K0SEFM%8W*i!cvm9YL0PLrSIMFrE*Lcr8plLr?3li`RSw@)bJF{r4Mn+rv6Y zT?F?QG|jZqpYO9S)@LN-Uvl4B{`<|%Ke~gaWTaSU2{%SE3KU_SIwRDbZ)INre)sJk zm-^?QYk%hU)SIRLr=Fp$2&2e$sjeqy9!GN|G@SoNvb3+Yji~P)3QD0MjzsHsp^3Hx z2)&;p&}Pr8EipuvN?4s%R(#yolDtY1cfUO~SKesJ8?AT0d=p21{rvORz6O`^70q#; z1aV2#*V@j{7(m}XcDF^w3`f^Ap7pdhS^_z^q-kdS%oKZ-f!4E-1g5F$!7Q}=aN3e6 z;6A}A3)=h;H7`^Q7AVDNnuSsCv?^(uH?Xz*7gn#NX~t0W(=@xT8=ATuXpZh!t~C<` ziVoornHT#`Op4?`_OyUD+9^r5kb1FJ2eOmysx~55DQkWt!I%D4Xqu-pU-Kge%<{P3 z(PviA6bj^aop={EuE(<5Nt)(YL({zDoZ@F%Wx1l9He+j0{gW9>Bu%rVX|Cl67MhZ7 zy0Sog5}Ia94_!N$dY%zZJvS5&(<`HCHdWnlBuz6t+1O9pE-G5_Hhip91*mA6%?XB3 zI8Bw+i=k=mvc1w5tsX4TKkAWuX*j&#MBSuzlpQtVoQnEDjom&C%_d|DCOeVMZuMEJ*Z$BwZvoOnT$A00|!JYP-WoZ`1sdqJ; zF4>i2X=WDyceu9M&v|W(r}|*3tASB37xNYtxpqC~#3qP~umy;h8=LF{Lw6kPneUp^ zb^CWZ;K_Ee*p!azkvK?=tGKQM@o9bG&dAa%zLjuE35$$mY3>*YNEWA5Mef+m-&EdO ztz!&<7ANDxg%$Lg;>6{QkMg79Vc^&yW`d>TxO}yerI{;h6Mj{YH+6u^yTqIhM1PPh z&0G&<_3%a=H#;>JgK$6JHOvaUraI+yhA5eF=iNca?fEMkJ2G;KQ;YDtT3; z!#Ey^FaG}F7L4R#8)x8=7`dYBSc)BxT(UIR`)ZNjwbN(3okX6mD0QoZT zljH7dT9+)%C1}E*XN36e^Zl?qGUMB*J#OgPc6OF#!7O`b$8~mG_i>p@W#jzHM&G!P z(>WS7#{jxhsUCZFD>abDW=NjmGACy8v?N-huSDMw?3hu`ISzk~asfc&>y=kLQ0?fp z>G5}N&wE4IDCus9++pE7-^Gd+T(DpDTeJYjXEF;Ohh%PRNt|Mpp6&#a1c z2vwyDvP%U41p9<6&4Q*X0<04#9b6>FV8u7AY_x7)#2f&pjl(^aHn7jk9-{^DenjDX zp|=s^7PP#NsHod|RA?D}E9mR5Df(8j7>v^R8qv3srJ0%FUbq6#IKZ#jWod{kRRZ~4 zKz@uD!eE@h(6E=r=Ph|~gooEibW9pUg#dfQNxhjGyTi2@ z`wy7oV^F@(-Iaj-F^gV8eaX_y%ygrGpEUKqVN<_kX@2pB{>Dju%{afNnXC_5iSTzJ z{Bf4OL5$xW@}20uu5uwJ+d}R2cehE(!48Zg%8OA>RzX6H;6@;hq8ts%XKr=BubX%o6ZQGK!7DnGZ!@a zH_e8;e`30E2Vkx5iXpP7E?Ju4uThV^OkM@OSX|pz=))-QFh|5x$s4V^o1a^N;EmpB zS-Kv9*i*BormLHQ+3S-QdWBbGPKCSFHz}nz-*UtRzG4-qnh_IkzJ+1=DGo_SO>q3* zaE{B!eViBB^Q0hI=0$0?oW$wv1Gq!tAk9{{=&JQ#yx|<}Y^Jffc`14DK$hP8iDY@4 zCMefB02Qw&ve;i2jIX;{ksim(m_8r7njnVd>fwxdGlN)DLh4s34{(vlU?fYkIO?5N zPt4NniyZ_R3FBg(uSgI_aR4a5#^~pN2+j@&GVuHbnR}}k@d+vACX2j9PPP=o6fWb0 zx7b&jvbg$-G(A&H{yR z!!QaQD~eRZ3~beM97pw?&{S=g80J)SLpR*4y0RlS5P9OQ@`tpjdZWLpn&!H8=zE$O zg!s2FvWc^b74v0xY$5Znnx@%T*IuDwtrx;NsHX2fKPKgtw1w)6jo=U2R=O`%W{K%o z#`hUWXj$roP|Zn(Z3uG|#rl)2EoaehAMJL?5v|!#v@k6#iaXt~+v|??S8*zr`adJN zbB(EPOszlz?Ow@xv1qS?Mv>WG=?CN7{ zwzLU`P+akEl&$$CAYln;-v*$a`PK}i%~MAwk)=B$0PQ%|<~{LjPJ)z%hds|Xy8}Dj zMc|8q>ntvw=l7J)yT3@f&HxcY=p=JkDuPF7)?K!BC13jqsWmlcqG(2dEt`GIm zGdjxsz_J*l<6RGH^G2srwaySga~h-5DLeGJH%s44oGFZ5kTEUvBhA#>df&#?Mo?On zoFsW%#7{67HSKFZZ))&UxBR41dAUVmTo|pWTC^;K2)|`2K)=b7XCA80aD`+2W-21C zUep#!Y7N}OTFHB9Js5|!ZFPXZIYlMMm@G@}U#;J(L^<@KVTf4b`G0O{>gepH6Elmm z+!jH>R`Q04nZx%^X4Pdem=C6qkAi zd0QF1E2(eA4`Hd;ztaKdwTp$Lh{VjDL27ND;@)%GfbjDXGk4yqxo)sJa6(C9W)aHQ z{xcmDxg=(mq2a;`qKentTP(1Hwoe|cF7blxr6&WEEO4VDgc^=Cl9;)|5LEY?Q16fc zYk_3A6e39hbI7E4h{Y_7&3s9n`c|-suZJh{LRkB_2aveCgm=^?)6ybwULTs4^|%>127?dxEGl_ogo+4y zsVd2+7pW>JiJ99d53=!9nipT;Oe>v+;29tcFp7Nrj6sZpFG^p7@8~@M9n5aQZ<41t zOOqv2p0xIm^VZQHwIu}=@hg()}yh;Nv9MR^ieJIwj?P~}$r zLrmUX=rz833BoS{!pG0YX(4#OAWHx)Eu{H+NkTPC7v%OwPIZ4v?+pO@?^aBD=K$e4Ib?{v+azByaAxRhMz39r0c7Nj0cu+o> zR}J?g*m@sYgKV6t5`dpEuCy@=mv^w@qQH$Kt+3DyhT@7A^HHcJw|2XtQKF2iWm+`4n~agvW3YZLqV=v;t)jia{R<^Rlf=xOmBkJ4Up_aj1-VQcgWkD75&A89M? z(%t8jzW2h|F4J(mAQNi9U)HfKrQ?1xF(fO1)2*Ecl3U7#+o+xYDI8NPt7gOadd(Le z9S&8gg6vX3sQe)FM%a!57yXt8<7Yb~zEk<&H7=xd?9<&FRyGYKtc zhAl%nn+a&M8B`#NnIR$POR^)3{6U8P#z}t7IKSqQtyic-_`4APILqFkslGepJJEez zSuY6Eb;9$n z3+>TzNE5W8WHKdvS~tB5N?ZXk^G-F756J<+E1jy{AQoXB${K4tv_!6ox2owzk>$9d9|kjGnI7p)Ny}1`aeciN zf!}etYlYl*zlCAB&JDr;{i2DPO-t7tZ5GZ9Z|Yf=xVaok%q)z$aC|DBBxY^`BnFZs zF>^U2N-r_ZBIAMdq`Rt(NLI=o z=6fWNrSP?vL6x}-uRJeTjSY#Hu+XXz9Yf;9I{YEK24ZI2_NTgM`L;VXBh7JoURn|} zcc|e7?O2K8MVWcGhYFYyF0Zgje@wHmr91OOvJ$LUL(IJ6yy6FagP3`24XTH-MJ$P# zB{6d?M=-yAdSYfmbldhL-vs=N3_TL|(JLcn*43FNd6~EG%Isq8)eUe+%%H!WCn2@~8Ba$WcsCa_aev4cWF;8r(GD59W_E+g7FLTCJkU6M!iDN%5ILw#^~FRcgT z$hJM^&8t+&%N!@=xu8%2Sz(sj$BS^Zyk%ZyVVqh*2cNoDKIK}ni{};lg0bf<(slUJ zD}sj+Np#z!yPI{yZTS=}^M7B+uHRzRQY0_)m;a%D{mtL*zWK_yYtI&QTNA{kp22GO zKS5%v{W~4-UAtH`N+(mUI7lsz7;*18Z9MoHd6~tx;=4gL^*Eshr^c*BoI@-kNk$@xM?8t3q7!##wf@ysClgXCo{MP&mzUnMWIAXR6; z+QX7G2JB1ReF;jqca?fEW=4*|;KQ;Y3Z59CB7)vl__pL_ZtF=e#kE}mv{3-<6}h&{ z86P#{4M;A=ywuU%+|ns|nOi`t5rbXdSCqL{`JKk3{=8|Be_dc);8Lya+0wS{7?yQM zxkFi`qnfW*t28Ur7tYK4DPVYm2Y5&K5`3BX6Vr@ZvoQVGXK z!7&NIEp}`oTHuW^aZ3Q+0M%yNUGL8nq@<5?FDQ`hsqHSx*J+mQe_u9c%czsZymcOgZuqoJl_~nY(P;9y zw^+a|)^uZL+oBjv{?c_hnGSc9F4sWzl9##Mj422>pTkT0e6I+PUkMqSa5kUW=Y}2E zee9*uyuT~c>KNoOm}hlx+&Pxnu5&bI?2@X-p500fq_G)FUgjQNW?{1vb%vuAk%qvE zZSQs2@Iv*Gx9xo|(dj63D)o^!eAB@65dkhscOL|Klcb1?=SlGp=be*b!;6dqh*2l! zgYG`U*fv~+uAi4#IGxX|igYMcr3$i31);+E>3Eq1@er5M3GO?%NQ}{O-mtRKx_uGt zk*AHrJqs`M4naCb3*ZtY3g-(&|Kk?4ypJ$6!_Z|G`?rVx#YEFEGrv#6IEqR5CFNYC ziKoj;z#_kEAD?g1)2O_U5J0L_0A82^&^W-aIc5MEZX_>ry#Xcpowrhnmlvwu-if-Q z0!Q5?3=R9vs|2Cq7?gbiP=7$L1K9pznQ#PN<_mi>HFk$<=4C!3$`?fHO2Gb@MK7U# z1@)!t(Fpn?Y3hH&rhduG{NjC%8YlTR{?Lipn>dxQQ$-67wJ?&~TS!u5Og zH-PBR5}a@y7V*7??--N#E_B@3q^OLEPR!V3-v}@BPBpJwf*6o@dk3#{s&<1|gn1}y z2(nx^Q{87sUgn$52%SKHB`-4$_r(8dR6O%<_JNir?#su#q=f zBMcjz2pf5$^|GUD8sO!mnywugS`bDv-JXK|XgclnNqfV*%*3!EVAjI_w_t)(k&Aat##t0G>4Fpu(EblDyikU=iIC&G&LXCmm?4M;-wCE6m} zVOr0y^O;r;G?k#Y=_abTg9ljPYtSzUK2Mn81U$UsXmftVV_l& zUYryV&Lr4VpuKe=d6{b&g8A*!^D=vm;kcIRN3QN#KJmr5PS?dM&5L=30mZLH;`Sc8 z#MQzJuoWf6{2qLz6kREuR_Y=vFGGk8PgeS# zilk-6qFVNF(6Z6_3hVbPtUtDzlr5yPtn}Bd9+UKAQqMhqYbDCLfrA%m;V`kUk7@Q8C-?I(<{-RLyj57q zNsCGmEEH?L*Tskt;1PnlErd;usW{=2$RZpQ=IwK%s3lwNIN>26WSITi+y4 zah4|ZOsA_Hr(?IwUtr+mVZgMI3=gNHz)#SvJArhjnZ4nd5lPNm0jTqN(==A!HG}96 zlAM{VU-a)9ZSKWSae79$cNGp4&crSFdUzr)gtd=*0ExRxct=fdx`2kMu_y^i2-l}A z&eG)#c~kp2Zbpv5;KMzO0=-wlCP~iRmJA8WYj-K1bRDXiR`p(GDXo7wNs|TY*9UiDa1-W891dMGYTLAA6?`*@$ByNi7`Y`nYdo`M_yAtvu*x|bmQ z5+HoMIGh%O_Y1NF;5~P>qJxUGiH8K?M?J}!BmnPoUXr&U^q!(`WG<|7H3Cc}06!yh z+baR!jJ`{fGw)^m9+U2H(3_+?;5+ekUFAY{?Y;UNK+tE&f7DoWbkI8F%sXO+X^oxU zCLMbtuhPwH(A#kHg`v>+HDh zBQcc*{#^$C0SM8a0x)?tw4y>4@ZplC|Ltd*DlgW_rL%Wu(LsJiu5fbtY=h?A4xr{$Hgh zF!IdGNQX;RDj~a+ko;2;G>f{b2(V7zM8rixsvC`4lJ1p9>jtJ3aF1#)^G0HynLS1e z;QffgxtF`q z%MhGpz-$4TAT_$me`&fDTyqfb5KpQE^1FciQMU<0!(N(}w_GL&7000L6M*^ydL6h* zxL7tEfuQ-q9!*yW?+=*cV^F@(-Iaj-F^gV8eM!*F%yd<{x~+S`>q@pGFL(BX`jVje z#T)t?tM{65e$6FYAG8wT??U+FEPI0i3f&>!iSFwv7sB;>^*4a%&k~?;9TxGuhVK}# zTrb*6f<#kzW0RsK_?=-{n*RA#2%2}Qd3;C?2w>?{-EphK%L}s1KUS(q8>QE6}Y_aM^#qQI{RoLFyvd-B|j}{+yq6v2_x&Voie=|MGW1?rv^`#G|yJl96Ja zB|Q6kFWFVwAa@c0mITdwme?e~2y}-u*>`)z=Z!l6YgrS+WT}M3;F$`jzzR~$qAu{c zxK(us9%THyjGyO{EVBqFWva1jNLeOtw7^E&Iv`)TOIzbvPpauUQ_ZyPAhcZY{Aj-0 z>y!3|37VtGbOU5a@j@erY+Fo5Nb}0l1C*cOBMF+tQ5Vl&@5BVn9d5xlOVAt%L(T9P zC}OkcRY}1#z;hR;E1JR;0RjS$Vhubl^Euc$D{fLQ4ES`2(gKBV!!QaQD~eQ5=-R5~ zIF9N&p{d#~G0dsvhHfZ|8|$o>pxJe1WM)RXt?QQOMUtcljaPO6A2G6Y0EKzc;pU*7Z$~?nzxq z()InrYEAVz-LOUF3r}3}DwlbI@r$a>JjV{~P&1rxHZ{CnscEw@8+M-Ykv5lS`R`Y-NL@lS-|$Twq?+XgUFX=% z`pe_rsIB)37HQlkz}LP=En?cHqieqI`KD*~Zl`jQzRE>P9Mg_0n-Is+O|U`riTBl= zq`&mN#rQ?~a`jR@m{E3Z!!c(wQ|nc~Cu&{2bY_~G33DTXxzX3AZr{|mPt#Fr zv`;N<8NdW*1cmtdJY9jP9=JLLurbAOQrkMlb7>CfWRNAaRyw|~icv1lvp3JA>SD_HbF>m9ZnEqcnWbCPW< z^N{96X=U!|hc$k2hexD<2;obrn~bY8(VA zQhig-brprxEL{+lJmzWwawN55yHZMfB+?x0y44>4LC=-<^6z z;N`2$s_(t)BF`(<)Y6_dXCz3$2~3&pVRVf=N>JaDXAnuZeit7fPEH=Z+uLtNJru=i z4&u61iif9t^Ci}nXS!P|tSpS#c-DM{HB06X>1w{fDrffXp&CW{2x5EMb~!5ELKr#L zcs<+odsNe|Agf!s>RYeBb2v8cEO$3O)@mgo1s3rm)(sYW1ZS`6!iOXfd(Sp;VH0{d zN4>y_ros~|>AG0a)mz;dieHO6M33mM7U+@^E0=4V4o|0*y2#4QikR+`^JKmBhxVpb z7C&K0&BJoE17YHLLoBx|gmCGGT9?bfyFD%5^(zLF^|{r2tVG zDYq`Vr065fJtpH>|9QYJzm*(^xwsJy%!bNrJYLnN+-De z^P(-bW0lO%oVmW~XoLioJsoqgVr@ajd>`n$`)sW?@hr`87$>2ZJp)XYdtuBx20Bm? z1=m?zJeQkzFRZAx!4Q|$^WcF5kJwha3s%Y3K2D_S3@U$7HJgNn2R8y2*BFs!bUZ%> z)6P|4^40Zk2I+t+j7%V8ny zZ{%qe%-eDZDPp47dUlK!oG3KnOsy$_P-&qbX{Oc&nHzUB;H&1VC^;}3AP6)zuPCzE z2Y@KWz3zm=)3S}KHb2G2B~=r(jXfOLDF1TS1TzXd`l;~6Ia7Qp&?nkm)3)E z=-M80{^oR-R&uQTr8ft_&w=7FkF8xxX$@(!BC3{(m0CY~x$DyxxX-*Ln)>Um3U1b=BY_;w+PbDvlVx2^wzo zCT^VnT$d_L`yJ?8B&8P&O`Rvsa=Xcv*r6tXB-Mp_9N5ce!Z%9tv?N-huSAT7>QT;5 zfnTG1drwpyfF3#zW6Cm2*JI;dTaWdER>SG?oqzSifBjbxFXG=2O8^<=tN+lYf*6RS zS4oRxed{Xm0%k^nD%-LU@t3GpMj1g^mF-(P+}m%j;Ege<3I<~r2S&a1z4umpZEIEltp41tn#u68fJZv7PO%Lb@6G9J@BqZT{YxqvN z{~tH?IHA^26bCW2H!venV-1LVxDYMZp7VNJs06es%=i5cK&GNwhthrV_Yb!?Sj0Bc z$9dy%S`&gfINOq}qp99@qHs8x3KN1sf1ieN6q8W0#8+}oHLba~SoGl#(cQX6QQdKE zdtCRDZw_c%-L}T)Sbu@VkIy9qN-STDobgflVj5vpvld*(`haIQ$sf{1cu11KBrU$o zU{`+Vx%B7@0v-uHo2Lu6;nF!L&;S10e;W@A|L@;M;qq_Kfw6e<<9E)xU%rW>zkdFC zOR}J0^D^LG^lsfSqt z>RstT=shj8&fvMNuZciq5L1tsglbzao9M&W!);s$YajOj5_gyIj_zSCEfSm9p}70F z894@n5BFT}DwROLP&__zMURE#@4a8+<$5W;{8)3i1ZXnTLAhSA8%Rigm6;AsipZC7 zo=Y&kxyN|5VEn^#UXabXA))x?p|~&w2LSQ1g--^<$9FG5_$5I2`1v?31n(DQ3BY@9 zYNdsg+-6?zNHRDMCk7lbB>JJ43vesuWerHpjj5EwhY_+z z89CnZN_vy<{StpytTk{c4YHWUPtkiG+^pYq2fVDdh3BTOav?yySAPQt`Yf5S8%i%7 zH07N@Y_lVK9Idg_+oX9%S9VfW`Ds@G6PiE3->uW%$}1kIu-vwx6X?xsZ&N!r@SI}7bIyDmN7Os?i3>(oGO4& zd$iCCQzR=Ze}s*@E_8_7i!`z$JOM$MIg4t}1)1#Un%~8ZDa=pl-OuPVm-QuQ*#?hX zn9#GWa_4VifNOTTVaIh$L)r7W)HW{XyFNJX)t)l!T_e`Kr0&rWlrh~(6{MU^rmjd8 z1iL3v2Gm>47zsLB6KV9X}DgHUOfVa z_&U`TE5IAsqm9?Bi!8}f>LBMJKO6M+?~M3P?St1C1Kz3(Pdp0okf_;xx_isoM(YCR zI&LKPnc8F20Nzh$lYN=+pPIOkJ|}D%m^ze|O6~3c)^8-lh-hh_?uO#OrT|=BlQTZz z4oXx2q{q=2J&pwJYRgT+um;dLz_0l_0jZS&mL+yxq(vh=ri>QY6)kX7CY+&R-wEf1 ziWfrl2lP4s?k|=M=My_LHMWQD`TjCJjt-dQV_?3}-IbvIF{@r;eU^Gf8vCWOUut*V z-M=>G!`N?&Oo_*3+mUWZr*}JQoaEOG^z)D2N*e1gYOL=L`A&FWSGf?d->bg?NPm_9 zh3hbh?=^hKfaP82xUor5852_y;~4gWAYCIPW|?ABXph!Gq{0e`-m09jxZ>G(5AC`3%BAYnUaF={Z{blgbdk3!2w&~9S0W4+3M%A7` z7GWaFDuOWA?NkvKJc_KArk>fMby$|~I>BhagHzr1uo6-i!OaEBSpNl*V#7o^)N5aw zKHdgTTE~CyTzt?kkk-0bXGx15N*Jfk2z4iXZwY?)?H`x==bvkTu6(@ze6!U5)bo;6 z)^W03tn0~{$I%>F4d=g+EbVJ;BkTWY+ZlU?f^s8>BhmU@Xre6vLht7Yw%PM?OSD>3 z35)Y04th2Q<+Wt6k~bW0PtTQiTJlcoW#yD@pEZX?*ffrw)2h0GZ%t>uKC^Az@upFW zD*?A}j2efgYOhZ;g%epcFW@%ca>PXA?mIqtpYrOebpUQBaahLmQ1q5yGcY|+@42oO zc#aXxOp(fzriEu^v*Zrrafi3Qs~PUv*HnBkZYf8CFzWU2m0(SQcWoNPltiy$cZ%Hz_s}KBqOVm&zt;?%w+KbK%|nqAixnMDX6J~uMpplEna?R3 zXsO$A*FStZBw{Fh8~Mg`Y7`6y;8v^Rdk4GX$yF; zn&zwjxqrygUr508wmyO{)uTP<`QbiFqzi?QbQ;7W;Rq8*9-N?wR_%#L)$$5jY0&ZifLO}*t;GJQeO=JvTq0e%+qz< zGqu1Ch4C0|uJ2LG1l|FmWys4|WlR~Nh;8Ru-mQdfQNVV|b(>9jtl}lyeO)8bvSB%z zt`U6-*)h$idzE+vbj*T^v4@S4hxpcVE$NuqF~I+LNp#G@EVu0m;!50yj=5{(xN16P zVVrtb!|9mh26$ILr6s>bq_y3WFX@DPJtd1_Lv|MKTJ+nqb@j5M{urz?U z+gBu#oR?!2`garN_m0d5+@{0p`k}lHw=kB2YM6%3_(rk&0 ztjy-jPtdJ9!E1^Jmvqdde5D%E;F6BHI?kzo$b`Cs1fV7-*$ERuHCEr{-Cp<>z>m$A z=gS5t@g&4s2q->CI_B0c&V3p7$`Lz~ymc@^(}+o^~I@nV6WgTv=N~phYt22 zckjRa5B2MB{&q*1HI91#iMva9cR@PlGh*;zSrG7zvKL>(7k~e73sDo>I0IkA$Q3;n zl1n<~dS5N_ySDe?+sW7YiZZlHNWL#57j6M%$hHLI6w}qWKJ<>Udu$36s?xUIK07F7 zD2r`W^Yv<#W`#QP;NAm@3sZ0a5O47B?!a7Uf#Ku3mmvHSAbk9M9AgIGxtCOeECINr zV}2_M^CbX(!xRY;fS)lr>MOB^GuAChkhYicdrWe}LAc!=@SXU&u5ux}_FnxBAn3DX zJ8G;sI%u7&Hah}@X^oxUCj5e_oRvlup2cP;Y6(TVRA@Wh-8$X9A~xn7s^2kKzZOx^ zGQJnM@6Qc%js!7dwv5`e{?@qcGG;xcT^!r6Rg$8~mG_feKg^ZqXL{ut!2UD@ax_j36tWksGQsOj4x&e$bYkH!O! z=~ikWjm?lyk6Y?#n>;OvmguXusDbP$Ku0Sgjs9MvKJvD`?hGlX(8+MFoHotQso?zqb9@ZS7rMI=us>$eOQMv--YnUS@s4^_1z)g ziSFwv7sB;>^*4a%&k~$)9TxGuhVK}#Trb*6f<(vs#wJBeh(<$fvTuZnd8e9J4j=~P z-QK|~ovPg+7GWOB8iFj>%~X@f9R_P*5+=JYPYX&W=3d7KIz|GQxMX7Hg2M)>Jf|T|IJiM~id=|JhO4 z8y@q9nV9{^A-Xm5Y{PK_-Rscq2~JtKg&fMN$}cA=6SFw#0;)VY6SGJZtVkwi4!{t~ z-p|C`!;H$nS{eE-QZb8y!HSNju+xoRDzS@l*nJW%=Du|LZ0rUYzy`~YAOd6UZe?WV zT&lXbU}#k!rJ9O)@G*YKUOpSMWk$9agkk79Ze)60z=St#voTw}(s?Y=on&KvC2Y*Q zjx&DrZP=Jc*Pv>uWMeMUc}9X1jP1+|GbE9>UKC9?C%QdtXOV?P%cDSUo~|fgG)+eS zvtSbIF-<-c#cB?ZciJg>E(p24%bj(zS%b)EFsgI7?(k2)}VNtwUK4!z}*&PnTvSAnnjul0!VFtEp zIgX?HPH3vOOAK?WxmbR^bOhLM?sh6nL?eXI%35S5hCG;q5a znfs)Dh?Kdv>VLy~X+0QMf7+0nzd75* z^5B6iy*U7W4s0%NkXzYi%l%TV-;1_~?G`S)_nEisLHP=n)`L(S6(*Bg{8xrs#dlQgNN8Ba?fZHZ$&@E>)Q3%d^Lg zlk#Bbo8@+s!i~N1b~%|vCAuYan8+5RB%g@G>EzmkyR`rvx>OLo(|X`TR*B?fUU=EE zwnaAsg4?r2UDiZ#sb{cSo5EGbAv|&WcRJv=cCknl(b1?gNUiNm+&)BE3MJ{lMg+Y+FS0%#JFzu`o!!VRP3WWEMYX7P+{8Hi7B(e56b0wJ)pZSM-hK0Oo{rr-b| zz9Hci#5=ak`njHDie^=lD53fxOh z=5p_;{(Kpxb(tpfts#3kd|=MF*s6cAdSsXaxy~$*;9ayRzw>8iECo7%Z3-KkGyT~ zdx=g*q0?97>LX`-)QpSzhya)Cn+VCtJSiUHymK;af~;`>G1jzv!o2r+2=k==d`sO; zfOc7Vn37GHA2{=LgS>?Yptzj}W;cwl*X;h^p-+`6$SxIx3TNnLVLJ+3^jjXh@#u{B zPUVBw7=!*#pmglh-5XXm8XJI+dIA?Kr;Wos6=~Z(Gkc5{!29X!(*%h)f;rE*@UysP zTE705L;vFzbRB&=6LU{0Xke4N{tINMKne=+-3JmtNrqme@t|A+BvT(rVyMImi5|{O zVf?VB>RhKj>899fCfVuD|MP)lPjNty4)rMx%V3Eg(JiCM_=yA$NxDeypS!*OM6%3_ z(rgLenpXabt?OTAu%EqQSAWUL%rMOhzl&%r;A=+kL)54e$nOI3M>#GH4f{?sFI2n` zs6U|B0c?Mc8oR@_!21K{_!yKgbSFS3dxNI>?vU?9_jQ#E;rhM$ z8$k4D2~PN3Sh_FMBEHw~9Rrqkq2tCTMP*D(M~qGOjc_vWRP)Luhyi)GckoK5YBz{Q zn1`~4Aj@?#m5M{JEojt!Elk2>*X2jtZ`5UnuN&$j^xA>;+kfLw7h5MWE7rcREWiG} z^S;8J3@wI?*2OwY=Jc3He~gDtsMi^x69};6Wad-ICV}UK*efyJxC5}3H8DiCb+IK# z^=NX3I!C+E00iqrB(KsnktYXFCe>Ww{C-_(uAK4x)LeO^#rER2s_B}cVL0JzI-Qbf zWcj_}F$^8>O{0~M7Py)D^VR!*&2$2GVzv7%49oQ$J^wf8Rx)xQ=SB8BL9WB{N`4Zj zw-4YBiGws--JXKKp>+UmWjXPdF~wf^OVvE^7*5^Dn`yo|H9~Q75wkjtE|Nf{vL-YT9$G?sA!Zyd&1)5DmoP>xrBkp_?RIz0Vn0nGMb*C9^kB3lzK z^X22vKSAM4eNAc_j9dJEn};Gj7Av|3C9~*v#Ohy^#ZF*kroXD%H1t4==7*81Tb?$Z z33AGwa=`nEefPy`wTJ^gXG)*<4lCCNi#@$y;K!yqWetui_zO?B&xj>#pt0A_9IpUw0zA%UFhit{ChpmOFtcgpJy<9Cwn8 z`DKtXf3fs_OOp>D-v5{`$hT?6%`W+0*KzRp0j7bKAnHoV07e;pb{t{+>~HWekF7yf z({u1J$3d2M-e>jX%)KxKvsYe`$h9|p<&iwsyZy(9M_q-Fq6)G<6}uUY7*H35n!tgO z{f@$74@(bh#$YlAso8#X$lh8~F)Otg!5~*sN>}HNQegwZS04@?ts`Hsc_FkNCbKk) zlY4IN5~e#L#m6+Gk(B@(k%vhuMV=%O`Y7~0V`>=D)X*%;5t*s4jEY%T-Pr`kJVD-X zRiDr+1TZNg76)&hcneXGITvx5K-N*I5Oi=Cmn~(TyYK;_hYuat&AY zyhiOFNXSmB2c%J_=Gl4iykgr*yi%E6w1_V|bB0vkc;CL=386@6kr0dP{?6Z(4&@zO?UGhIkjU z{XBSkbjzJ(K3cOHMItd)quRuLbRTGk{JvRM<(JKuEWrCcEQve}xR!+4ir5Ux%lm_lzhnwkKGe(WWeAJzGPvR+qBpp=`*LH)DHi2?SLa1q zfKBX+qISUgc^Ff=oMgRNG>W$hUx+_k7^#-n!P~7BaaPMVe`V_PwxI~%i3ONDQ$14k zDxtRaHXZJ!47ajV)XM*TA&a|YOde!(YtI&QC=skRMpWi8t(<11%2ghD)t?(LrfbMt+pvjC0Di`R z&xYcA&DL=0e8o6UYhWf3_pY==M|JUD`v!()Y~0#R6MJ$C+0Q$=<}nwHv{n z^&)OlBt_Z2wslFFTyFOi1)R_0rM+5S7iF?wmp!wcpB>kI#G+E$IKQ^hH|`Z$8uqRc zXY7)?N8^FVbSqU5z8Ojt#JD>|aF5nR8WQ^&6_U5@e=p(bD0upc{O{$AkDBquT?11{ z1iUOclaW`3Bt={x>7nFI?jdMKkZMnwsWa;$9ePu#gY42l@=wZ{EU2m?z&e2o5f=%m zZ8YvkIu{z7uvJ!-wo`-pue_829A_an;Y3%!jPx1QyFgrOORE)&d;0)wv#{);)F zvBAk3s3CZdD=3*@o|)iY_+3Qf0KaCRC8W3sSSr_fkrs^{mJ-MB!trCg5C-YghK7CT zRf14)49GqKraz$9fs2HTrNR*?lP~Me)Yu%lk$f)`-5)T;$AEmHyDP!^W7fPx`W4cb z{JA5DgoAD#HGIc_;1XK;v2ZV=d~k!zxH!1e=>AOokj(WHr5H9t+PWG$vrf zW<8Iid6E|M-$;iUiH>YFsi^X^kbaeY+vbj@BgOZwXBH|vQ)xAQW*zy1jWZ4pdL}KFWN%hZj8`*UX_+BXMDtrH?&-N zpT&0Jw|bv7HMPL^T}?M4Ez(J^L)sfAOg252c&=*&o?}Ea(-luj;r3=MVX`plomTTa z4Pwwn&R1(6l(X}A#aSJ3T=y`;Dc+M80}#avcwo-Kg2^%$)?|2|*g=qyFfQi#iUe`A zp|t(Eg>ZURm0-1=m$fOBLHPF~Ud9F4leZ9&3pEpRUZj+SuJ5gy#a=UEvU57ZIXgM~_qLb8ncTY^VsELE$6O6o>heBgxx<8&+8|Eeag@QZ29N5R zcb59VkF7yfRCbPK>m;ERx57x*O;;NeCCM5r(nx87qi?rNxr z2rS)j9Z{0fb+H0R@4SMB;@9Hd&?B|01&ErL2&b9fXDLX_dn`1YA}cRL*bT;Ro~)Pt z(5}S!enC-8n*(RCuBoO?|Fb1&axH7yO?-S1o21F$O}0BzT!Qv$tOvd=8xgl{lXPc@m_0isE_l<=#dQjSa~a%{^de(24}RAeM) zLe++-Fk!XN{bm_XL3zDg%7E(r%+qzXXP@FAAX}rHGdV$3Hz{dye%r`s5nHwy);^lEkt48+lp z7b3nyc@Z)w5UB^DINF&^Zt)-3d)Et+-@a$TPZW24m*T0Yu#?;Obw;(xH(wdI&|1~t zBW@Uyq8h&m8g7{l#f#B#M9ji0x0@7h=|>SUCr?YFCHks+cif<2{x!(}Ciu`Z*%}5&NYEhmqDQ)8%K5cY|a5SD7M1PPp z%&lFV+kjsi4YMFs!ZAZZ_OV!dSdzwoeTlnEct;H?!i}UtjW|h2!g&kkiBnkKVKlX$ z<7VU-3_jem_|$u4W|B0_Z9Pds^4ja^8aTmTkt@4|1bvoFM~yW{ z2dzWHydylA*4XK7(y=%4D$NWweKAXDy>em1i8b2Yt<&8rVqxB)dmV%IYY}Z72AG1q zz64{qW4wg$h0KC_W=lsZClAi60?8_`M8h+XS(`^D zwZ9FHGZtFS3h-Y##}jkz?`?wzE==gz#-kw`i07JpZrE|%M^!47jrRF<4rQZn+{fu0 zjhdHKJ@)KYY9RbLml{Yv3G=xXk%qu_HhhA(v0%=luEbQA?L3t)R3CZU-uDunjzXue z$kj*A_^26gc;7R9M1afE-AAe-OxvM1c)hw)MZzqc&Mmhc)H`tuZHF*bsvx^m5USUP zUM3`!6od83`-_m|K^C*@QFPuBq<+^K@tw*CuW=!zW1sHcu(HvxMO+I{+deaU%yk6s z=StB3xCJfmBP0tmJG)1r!B>U8iIy}gwolpI@_C2U(zsBM_;e-CMi=?(AfOBTQqHqB7P_sZ2k4D>TeI z)jT>F^yh%!m9k=^YBz{Qn1`~4Aj@?#RdfZdjLBQ(ra7!#uMb!?NzWCayiNwnYDVRF^!=xVNv(i!#Cn z*Bj#DbamMh^d1gHd7~wqa+}~8d81XI;BQmYooc>ikRT$aO>{>ydVSL9(A1~1(j;}@ z>ip(gj+kihQ1@FHmg@}J{NHen%gBA47a6PyB+I-g&6blmy?p?8NF1cu>h=^lu387+ z_8eEsn0fhVT5?p)*Fju!VHgFD6-BCH2DWNBj-&bx zXp?Q180J)SL${w8Phd=@zk=M9($0o*(s+mkqE4uptn$BK2gxVddIkv_$1m2t*ZcG<)rnl( zzUjIdhM@tLw7v~VuGA}BseR(sU8l3a2&Rr6O)X!yeP`M?{q1#1UCxHL0KQQ3LjQCN zwM+4a1Nhn(s_$5#9{9dBjqK^n5&4$Ots2gtJ!&)iP9CWgMZdr!b<1jM9H z`qVY;$ls(5qmx_y2nXsFEY!GfySes-YC(B59bNNv&o@1@cc$ct`f5*9+j9&pa!Ej} zD4ddB)#vI?)L)KUsL%lVcDYZFeqBA7`Br2Zjyao|TCX}T*Xk9n)vU=vhlMKALrv>@N4Zk3aHaN%TUSqwEYqD?8u;4{ zp9EH~nc{$T+NY+rjAEh%n)vxVMU?e2{*BR16xmv2QU-oqcu#~COOrP9c?s0TYfYw| zwg@a*&j1@&>-Wwxt-zoTBG$#+U!=j~yv~N&NqPh0D6TZ12PNypqOHU$pfsPakj4>I z-{G8HvE1GC*vDA8bq?RlEoC0kyz;*2>4<#^?~8Pu1!R5?yEc$(QSlaiCsIAr^?OuP zu2ff9LT-m$OMT;ujGp^eXF>`r;76<(EcD33q?O`J5-RexW?No_i&bap*;7||VkKP{ zE4p&a)u@PHi@QUQ*sd1nl2Qzm>zWQvr!m-mFRilp3Cn37mZKf7 zR9#a|TQyBp*Nq8on+T*=)hE>FbX|}Md-bFHj*y-`j(I%}1utL~T@tA! zscKh8?0-KAkbsCJD3TJT)&(7ow#x+&B#=NpnaIrNp{xv;gjIL7?Lu$Ga%KVwOTtFu zM*&O$yVjOAPMzfNuMakKQA}ennhZvx0Zd_Ofws;HDyQZ1UGdxOG5D8p6s094gkDpj z{Hm^JD&{lOZ{kE7!q3CRvz3^jxije!Y*Y>%+wsR$HBt6M-;Vd zKFM^fe#qO#U4p)#*JOE-H8#Dwl(QXF%gU|cAgdOkZ9H8~s9RROl#W*{ zSiu7U}z{+#Zznq;}3GDo}y#$z_$J0xv*51&z44d}FchTp;T7sPi61#>E z{8g+#{wolc^6hSKFc`u=S#6GF_ybF(r6}|-)c9bw%kYO?<#4EtHUw+8?|!kLp;2D) zdjJoXM#JYJFC|<2c=ozMn8n8QR92<*NW8}YO;U?U5$G&z_}(^r4Wln1nj@GcKjAun zH`zNDH4DHNU3vj`02G=_FLpuuVV&ni3)$wM%yK|i(boH7r|!!#&yQiH@Wf1sT|$FD zKmPcC|8E+sg0GNg5bb93(9P0C2>@_#K$DD5nLc3Iw0xD3eYe4GUG?n4kQmhfy<}QIt{9`|!)>A*dGojOcY) zcpYg$U=6suCS8{k5=8{>y@)to5SVmbX9De2YHKZ_qJj#E;J7h?qmZD(yvoto-;C5q zuQ=dZlfnzX?(m%m3+!w{g z$2Me6^XnhKNI1L?#ofoP$T1kadSr2`T0w+cp09rVeop&@|6zwqGv>FHe-l%4ZV41ulU*7Lg_X6DKAA znYb@uw2Gc_#0*UO&pd4$3{44vN!Gsve2b_X4)snEd5+NWd7{BMfG)8j=eptP&ZAvc zo1fp4l+Ub zA%HlvARbc#a1FrO4D5oKGypH90cZez-2j{hUoHKZ>@vJH;;uv7M@5sAC%hJ4i!NsZ z)UC#=K+q?tk}V9~e9E2>=}k>#Iq*;LtDYwoNLn9~Q|R*Z`zG^)R3$M%+k+zBinoIF z!+IM#eWBNaL-}$A`&zmUed(%3cq`#K2JVZ2uurHJzW?~k2O2+#pYg2&UKY64Krbm4 z7ybYtp>RKr-}-jE>zY`lLHNT>1-$4LZ?NJo5N!Ptt*G+KSTms}iFUJJIHQiN-_>mP zh|-7ZwmhW2hykwI)6dj(Koi;%ZErkw9x7WIX;V4x&CHI%ik;K?XgRDlLbBCl=7Tmu z9UV4G~>1Q2k+4YyyexNcqZZ@nX_$%yJvetx`eroJBc<+dyE;t z$GH;t-)u*Vi2r-Plh7%d_hta-6>qTO*Z|P?5f^?RQBdI5e4zjZmcS;0YO%{SN(+@T zb^OvvMq3{&YNdz9ml0v!RLHZKx zbJug%e1hVB#Q#Uf&%U6cYFB?jlV3B?Prle2?W{kmv%Wm#weVhaITNsNHC_dzKS`3p zb-2V^P2VwKxpa~ds7~!JMLEjCAw^{j7bXVaWxH;)g{qj!0&cVqlndHGU~FEw8IyIe z7Fpl5l3rnDJA_sZRCdfFci^|UiZgv|`DNK)9@G?vV%!aP2oX(aG6Y>QbsmIhrbBegAK3^Skei|Hz}f|Knk8{<~so zb0R3RU#!LAECYWDl?|6)NgS!3wv+YWWT>y03QB8&XF~cJJ%ZJ-7G-A9=)Du9+qAsg z!d`1CVF3_Ixr&3KF|C8HVx^Pl`T3#?%Z7{{t9NBd^jV&bd>-y9&+4eQ8#i^G*>pi> z)0tt6#tUL8Ytyo-!CXRmMRo^n&kKDg(K(cV3!Y_BrH%hLFt5bq8FWz$ZUtVHZ4gAm z7oZUd+$i1*yC8Cq6yRRM6MG#{r3nA(8MO~&&U0Q+V}9tm%z;GpZ-Z&2#jc7QtrxS+m9Am=GW$tQ~>DxhzXW6xPiN=*qk_0D_zI&y_-i*iZ*ir2CFFpHGOOSSiIQpHq?0o{)RX+^VczJzb;Dto?zG3)*`8F}u3;*kvNipFu zdy$ff1s?}-<f$hPQk07U#`(pT&Lx(s|K1)^q}@9Q&Lo|Y=8+t-k%52FT0b$ z$=H`yX+~BJHE1;h^KCOQFGfD`rry{xiEA46)iW^9=bC^yQ=0Jie$};OTcyZD5HQc@ z_;|{3`33MVD|8Ff;%fYRECDlk3*>{EjdfN4tZ}RmX8s?yg<}`ycxG9yPZnc?*goES zOyXo5YpR4YZ*nk<)f~)Ryx`y8goC-(hHE7EMFs(t?IzPLQ-iaK-G*$oYh+@!##6&I zh&cyx?-5`gq~l=GFQ2a&87M8>mpuDde6?_07Sn;bvO6^Bo{u8E7&n46UvrO#N#ILm zu>T5t&1jWncLd&vP57F_w>2?B6FeJyf%#ciU~K-wPxg;=acs?Ko+P2`o@lOumi5rB z(uI>>;@R5obh0ENb#T*ya|$5c%c@R&3u@TPdRG;*p2=_i!aQuH$R;QEV?k_4 zT+m*iw71j>Iwt45{h$?*Y-dYODX}%lL@dc8TJetvSadr%NCy=;3aYKagrXF^K*Q z_h6c>nOk2wwAreFY(s9>N=)5g5o+;u^)t?dwU2uNjk_~=cSg2mbkHDBbrc4#mIXXY ztIDk(e)&B7^btEvP7&SSa7Q_e10Kr*;v zD&79#e1uC+G}QoH18{u{QZA<_*b!ipYXE-2a!NM>z-j1}E``*t6jGDAhm~-);Qd)G~5kQ zHP@Ja$6$RSqDO&yb=ja(c-Na88N#(*%6Y!4Xct{7_1=)ZUhzgNUZO?NRLv9woG#!+ z*3E}iOl|%Qp15!xax|oyPaJc@)U}GuRJ-@<-1|+C!+v8!HSf)AjzZ6KnjS5O)fPy$ zn(QznZ-L9IJlwMd(o%qqHbe^J-J(5m-_iFPoi;+JHx%llSG>`RV|xTaU2zkkD_UMg zMN70k7sJzhUQ?vRsH#nnIuj)Mraa9^JTSoOAb^OAL=zk5j*SiJ_T{vBxLwh>wOQF? ztN=a^7S2|&{^z@mXttsCeMC;(hSM*=>8P`B5t_KA>|4{&E8Z^qR+qGAF1QQ7izq1Y zYfj*;B1_dkz7EJAb(c^z?X_14sACh9-2tdSVAKk1f3`|Eh^G0>(M*NYp&VA)ZJC{} z;Qaw>d<@D*!(9p3Z?fq%)YmM{wDQ=xk>gjp`tLZaSF-|Kr`YR&P%5G=2L0Q{eyici%~`07mn_FTuF&doC45{PO=K_vRv9xjS>OC-(a zy^u6pliAFeIo{myTzBd#nYv|iyHdUj6NY2i?KDaA&5$(L=qYfULBzC63M9=8{*QE(`7|o2G{^qYdMpf(QL7!CR%@@g+?+ zz*6OHq9A0@oHJGx@irYCGz4o4ylL>R$>z36n#~dM7Q~)7{sc&xeN0Kyi?-<|O44N> zyMw{o1{?=K-{vjpg1|zA+to^*(B5WcyHL$EOqb7bwB68UFFi#x+1POkR#6l#!|mE3 zam6Dut7w_i1_ztIY4k@E`j2U8lIBc`;qU$XNJ-K>8JIXswx>y&#f-w?ph=q1VM`~c z_bGe};wYs1obGU_nT0laHif;v+iRu?zr4JfeTUe6ppxyco!36}=;Z8148iQ}yI&xo zCQPaBg8D3j^3q*JTkngV zx-Yzz0gIq2?-2@1WCq?{8;Bl%3p{41h&Z-i{{`#v93*M{K1fL%+kOJqvi_VJkHx%}89t3i4;2grvD<(278| zv!$k#B9HL6!HoRFj$e-%Fs@})l}9&W#Y;^;W65Trn=^O3@}${i`W&F`vg zttOAWf_I^Kyy1=( z;q5h$T$42O2t^&|z5-7QPQoe$zzN4D+ArW={0MjdAHl_$Ik@1SuH2;JvZUOw$rZ`p z>?Gw?xTq6|CGcxV-WHPM1Q=bl74C*WjNz*2_^Pcp3&s&cu<&QojmZ7n+PCeJezM(c zqB!k0RNR$`*=6K{mVny{Er57|mA3|Sbx@9}>I0fs0UCs#1B5phhi)ObT97pW*KkZH znrZ+J;S@KRT3qmnYXE-29Mc;C;AOT`fwDE?o?7GaBRwNnAp(K8n_OL2!tL^e*Wzo@ zr3s?#08qCYuL41zqz+PH&(TRMku=xj4$~gB(I#?SMxjf&zD=pACTZrB?@c827_2Wu z6nXf1t-$^HXc3wm8N#)$Nt#PLi@Rh0#4`4@Yn|nmFYVP$xYji(T3gq8Mv9UMO949C5Gjmzi}pxOsLuz;PJu{eA z!+p@)W;wzGR;oe-&JBbm1PYB+iDC`-5BPlE^9-J;J)pQfPb@B`0AF+Xe~C|3n;>;2 z2o)yJj=iD?JUrk$!pa+u(u~&{AH2tzjE*+L-LbJD-M*YQ54S58w>B$#j1|DgDV?zd zsw%rnUUT7Byl14`+wf`bwIvJ6hbA8ubTE+G>Nt!P{=BRKCUo*}x zQ-ErOUx)CUdG;zXetF7k(Y@$$CS2cYyb45rlH`Qz@QAmXzGJ{Lf_SCC{K6qcWenE` zfkXCANSbTSyle}?ggmuQUMY1gC$XS)$a)}I7LUnI9A1q}2oqXt(Z0d`hG<)T-5{F4 z>Bfj1)DcIbnTq$4|MGuJ-;3^KXhW!+oNnWg^U3)3Dj}#}X@)uwU`^7@SBWix$npr2 zM|%U*ze(CRyHS8b*09f-N*L744qSTifuy>M&+iJ&T+FTmBCm}eZ1mhzM4Mi52vJ25 zEa(jH70ui%!v>24Pp;>+`U6jSPQ=7cm+Op_nJbZA{xd#QRLV+vF-_7;c@hAMDni-{ zO1WE0*Pl$Mli8Gvr(H=`z_6H}C@&pgnld$zh#UU_m}If_6wQ5{5C@9yx`;3Om|a52*yOaKl(urBA)OG1$N z>Bur2Z|peE%=H$wiP!qNh@Qv&g{g_2nLed|?bljLqUZ5oQIdhnA$qO=rz)uX$D0}t z6tS)XoHNXjgWZuemK8nwrHpmaeqk-T$C;`M>ujhBs9D**E!y0t8Wf)n$D2T*mG5wa zKy+f+-ol*B=bmj%iQfQ-n#NoqTgL)XAij-gV%Ym~x4D(-UuMWvH;J|}=n9};OqcEp zabK0jVK3P_pkQ*9lKs#(CeFllK%1DRJu=)G=2C9#w^vwUN5rM6B(e!Z`F@7x94M7` z!~UJntJwv;=B5~=gB)OnArq{Z0XkO9%L57Cu2S?xy);-8fCE%m6yS6VrXTmL?)&u; z=8H_n>W8!=Z+1*~4!h2>XOr33@TTa6;V_~U&ty6u&xt+t4A1e6ks+IQJ0~TwN~@i` z!uQ10YxazMLb)p{FHQvCsV-9l74sDaM+>(mPYD)ZEnJ$#9ASRQ92%&@N0DBPLs)ih zi0R;8&Jp~|I(~E zbhse$W^5#iIioL&cVZjzW{lO~v;BnoG5+uqS=jMN)GPo~bm;|gz8?!OCN;jG-N2LI z_<9RAbL!{U1P=0u{clUPzWlf~2bS+>?_x*Svtn-B}1Vwen29t@A^S zI&ngeco4$0Czv|(yA-XT<3!>Z3|>7l7Q73^;|+JT2z#%o=&H$^xfQR;n{R?)LPPSl zkX&-0gIOnH<8|o!1(P=;)N*z(jtEx|y#@l`y7cOY+yF_aWbX}7?yFluj2Q%9)6h~y zq{fMS+YJ?WWx{qDxu7M;FRLr{s*R1)8yl*5&(Tt~Pam(?IZcnk3pW{7TOiz4(H6+#A#!`PAyN?7 zTeL@NLVeVwR2!$v?y5n^`W95XT)Rk_4O@{ zugROK3f87bc7pS~>JBr?ySwlx@vLeSq|O9MzA1S#vQ&{~r|ApSUCyIz56PM3BB6~9 zIK%i2N%^`%x_voq9&T6n5p7oX7%PB}gN5@#ZzGy*Xnh}{$(!lX%60GF{eMf@x2B;> z-Rn~KPrrY1%oC`Z_S&li)UgT5?f}#uFlxm`!r3a}AoAujM>FkJ@0S^Fbif)PgYwaE;^4`5 zz=eYSCYxSE{T%9#(4vAttV55u%FgBdwxGUV@pe#OlQ&Y&khGF_++EE)G43iw zF>W;HykqlQ9o_@UGXLLv5qUK(AxsqmvjX4A1{hqZA6cDkA)Z}rgNP<@x@q!eSk0{P z6)7hd!S8^pkkEoVJ+U~;z+Z+@y8KGwNU>1)qC%HnQJq;j?}*2m@|hIi1#Q7|9_fES zJfKI&5`aeUMX$vwx9GXzO1D*Ex@HPc$QrIuLnTa;H}9^~b@8g3C|;#+v<`}B!>5C; zVAWwcS>#nZD7&VhGCH+%7lu1`ZF4-DPo1$jH|YRBZwm~*#xH{{J2rD;Cc8{vbk+d_Q1<@9F_Hl64}p|R$J zO`~NDoOM7GB{7c`6cM$8_S-~oQJC?lw&J3FNz)A!81yy~@S;)!j~5%1&t5uwkF^D2 zYIxUV14KGx`4VlGj8GnWN_7osd)_0BUI}B}>1A(L2(HMQv8F;I#CPQUk>7+5cH}ve z#n_nmWIC~o5|4WCs`y~XR)4DbV0W^%e;@5ABk6W9jlpO#7+ZrW_KWmxmJhaqUN)zL zg{&OK*&x%w^0;~Uzf}+o2(^cv=L5|1{k}DFC;jnsI_*1CZ`7a6h&7rUGjFCQugy;e zo)NNJSvYb&Y&NUF1%FG#BKTG5eeArc&jMu4Dl!2pAKM@ykUjVB_L`}^4}Y^BfRyIp z(+@vA!0{gdSyT4zxNbKAfinA)(QtMt-l;?pI<;Nz;;ndMo#9Mc^BaaphY!- zA$B~m{Kd>NN0y5aIh&unR}y@s(`4;=FsJ!@-dJ*RqdJ9oF)Xpfvw)X#G;?4t*jCAY zsF3z1l72+4t4hKfrMtG4?EO+*%Mg2zG$TpAM%velCUnIXLkm|2r&<-Kf+lpOC!+Xs zL4>Y&mF4pn@3AI?uG{c6jJ||o?fF+1=v;Xd$vDDeT^gk;o+;&i=q{MOg1b>iy3|Fw zGzn|1jB}}&^-PBMP)^DHXv7N^7qlO`NKb7)Xhqn|*#g;dk52~; zYAT_n?iC;>B=w5bX4q3M8#@I-WHOh%RNo$ z8h02FTX2ekxLS}k0N0eRn$ootXLRYM^)&$30Q`b#EZztJFLNVm#9fEDkBTNKPk1f97G0Vk z+71A9tMMuj^hv6w6!sjQv@)gZ{!ByKqc++^4nZh%Dc3kJHQiCV@@TeF6F=dB&6Q1V zht##s_&Wye3n4wqzpgGbati-?lS4x|*EOkYY2)b1it?0bQddptN;zG%mt8X{WhVpA zn`_3Tgmv?Yqi&eGR#6{nbK~^phHBoMSsjI*=QKWA4y$dDY&EG(q-_u-tt&q6u+?z1 zDN+zw{Ond24i{>X+;;@NCi!gSd%mFve7)k0R=f~_uW4PW64u7Z6&NEW21ad!)EObk zx1@Eg18*JNd2o?vV&&Yixgp)a;OzWvb8$~W>slvB$5;Veg02MpH`~zqMncoN(t2q; z;&<=MVUC$fQR5%?KXjkA2AS3Jg$Zoi|fPYAj$2{9#lI1SNbD3X^Gq@=CMLe};Y>USqu*>Q;rp=YOQ95~yQJ)+nVJO#E(E0rfe!C*U3VhG0Y z?Nvhfgh+TfZ!5hAZxDx%@ZygrV705n_~j|*FSD}a^^(&${_v;&)Bp3Qe>_5Ul1I_y zOt`+)com5LBnb-F;Sp~&eaC=hv1xM&!htYi+hxC(_YnPmu#enm8>Tq}4SF7HLH^i4 z1>$^z_Eash67_3L^uT%x0!&rM>~$6Ul6Eb>EPJ3AtbrAU?tSQ|ZUdk7)YiKXCU4nodhrfN;8Rh?DjzAi-?$FB&S zmu(72`B;&ZETeE)J3_Xf$y?wOVaX3+tYPB4ps8j}N$AG!o0NGl_VdS;QkGf&gZSfo z$C}T9FStK-oq2ye2kJO`Y%Kb=GqPsBw=id}p?cXQv^U91#H~g8BXDk*#$rAj`KD(% z3x7OSb*!M`Vqb6=@mv}?#1B@~^&_8g^qH`cD){H>y0xXD`||Q?_8nsP1J~^X^;aL3 zx=;OT>y2$Eebec0!J1OOq2Q#ed#4}c=y&2Wn+!%#KkOhfFFH{QBlHkzI@_6plMjq)K*k_bm-IU6wMo)3~ za)CR!X%A|DG7?FuRyL&*q$eJoA6wyewUW1Rp~?G(J<6R7{s8ywGeP^a7i`|9OWX6P z4=wYBV?_syo-q2*PDz$lg>SBF(2U&$t&Ye9`!BFpG@^y_U8cpE~OvcmEtQ@ui5-Y=46FIk;P#=q8?~h@5 zkMJB|%C+KKRzj{?6RwfmYYt}Y>V*B1JogQ2JT**%m~+z}jYd8O&3UWKW@<*(h7|h( zepY4`P{*!->mo=;Gc|Ml(Q_btNKBCUzk|UL{>hxx$?yl3C=a*(>0crU6=H_Y@CQ*% zc>n=2L$G@L?iUEM3sdTX0q@%Y9xQqGu-WxLTN1x3VhF$@*laUzi^2+(9*LYM5F(Xq zSF|hkAr^|pgl}tNgysfAdyx5E>B>L+M1FZZ(#7#KH`xu{MXky7uR?%CxEl4L>(DjD z&3%(N^~%7tidoOL?Vj8exgQH*L*gPt^R5=$<(%!SD+vJfG@-*YGDtp#6Pczn4B5bSVHSbBmG#@}ef)d2r zslsm63SK~oMVX71=SRGU$-gV zNHr==N`3@zwJEI1)~O$#HBU3QIO)Fy+H92z(va1)5>q!=gj}ApNARfdBGj#Z#+k78 zaW9~8cLwjy$kU7t8iZKro#??Byjm9UC^%UKgI+4?Ebg3|f|{q9ANc&t>V1ro^dmUD zvP?ZC@T`b}LMs7hUxT=(-rvCP1|S;v0gG1av21Ql8rG(=5#l1e`A5Mb^zZ{qcb1$O!kyKnxG+j1~T54fqcw^%QyA6;VEer$-E^ zZp)+ji_!4c9CO3ewTj798ylxLHdOQ8%;qTcJg4c=a#(GFWUEOnB5i@d;kj%nKt~%Q zh4D%UK7nG+?viI+{kk{W=R)m~`;NZX=(G_!y`fMaz2c2l9NQxZE~otWyc~a4Sr{LX zX-w>NxelPzcKEzxnZxuZCHomS-i857Q7z(PDMz%I&??z!@CF6+ie>cWa~Du&@Rk=t zBJY3w`cLa+<^1x!@2&sw?pmuiCwQ7Z{r>63s2kAwWO>GSXNr{QRJ93GXM#|>*0W=; zxa%GsFp{Z^^)JnMt?|KooXO~DGu#~;8`ABIbn1fP(QO{?NjREMcpbqd2sRZj?W#5{HqGkn82>25%rLjw)N|Q(VFuk9^@0-H^dd1rjw`KPc2w-Xh0E)Ci zqEe6odDu&kl$68nE`VPbB-wR>xC#*ee^1|a9?V1gLNW^lDI5c9}-0y%JNS zfxN7HIu2Z_n)X^Wk2;?WM!s$?|kA9)>{(v<;#@COA69-Se z11=QoH;Go%P+xO2Q$vPV+1Ps)+)|+(?dosq>Yo@ot>A=d1;~clF*b`bO)Hi&yCzEv7N=)zT%#d~Po$bDxaH zGi$D_g2iGLxxFscqvd9~(A_C3=d4}vKoH-Na!WzGc`Y&gXve2I$p z*nYEvmF)y8xPx7OjY7swBe)bCJb)V$FG!ckhPY7f(dCTFa_}fj1*9|G7Duy>W`cp> zB1fHKa#@=o+OYbq*eS?tGiXWSFKC(ZEU=A^H&^ElqK9*$sT=@)RPpM)xub?5%GO7eq zZBA;Aj}G?a78?dqYNV5w_J=QQy<=1psrN=Un=qf>c5j&01k2-2inDA8piBf>IA<|) zebb)W#D#NDc^J#|i&Lfal=v4%a>RD&T3_jQ>tugmM8Kq5?+<$FE4D01#Xahdru$3PS*zeL!f3Vu*fsmBTmAY#@E4DRtmhVF(|L^%7)~lR)pk0 zV(zTi6P2FE{qM8^Ko9IktEIDw+}EW@04{-6KUifo(-pk#z$3Wa0K5i%Jx}s_%I8;) zw%aBo-q+>@>a%C;^ooJlFM%&G+QvZJ{v1bJfbfjs{6InwV&5mWZ;mH3Z)BUJDJC56McZ^kH)XcbumbAgjjs^h z%?gI3RHWIKRj9GvuF1xZA?6v}3(Ii3c33Sb)g!YM%%zvjcChK2Mt?Nvk7j*yHV`)Y zfL`HlQ!-#*9+sAar*hKguno~pnlk~SGLoH0)K9}6WiuIvoVUk^@-a`PAeTK=SKBW1 zR;(uLPESHM8aHQP2AG#f+BbEAlP9t+gAH91(-@2C6#UCL ziqevHL2uc@&Z?RawV`EWY0l@~jo&xvPG>5%Gj~l`DkxBIXlW~o&NTh=jjbrv^5sab zU_(vk&dfH+#PH@LXKGK85VP-)ZK&~{2lGAo41C2%()a7NOQEng4aWmk$HfBZ#@*2v zyDNGX(p{p)RQS$N{qNF5H};t|v3YvUePuhc%JM7K_yGV7ZTjorIR=bJPyC+O2apQ@ zr*9a3V7^U^^}_%9Wg^Q03IXV4a7w~N^0CxQgEawVOyPw>BNl=6zF#kaJ)BI(>W92- z+$9L%Hl`l$3||KxLy$<0)r9m?qh0VI@*GrGSrGmCHp!lmPZie^c_}qI)5-uxxcg9G zbLp-F`Y{ZxzJ%ckR6-KO1x&HH8eg45!wUH*(u;9uD9<_na&`_KaS4;1czy9*^m%YX zgK-4HyM_t+}`TH&*j?~N=D*3R0hHVm+3JHG@_JLm1tx1_!%xcCoTsvz;QWg6hPr3W2#FwvzfX!z|~<-nbf+_K4*6!E9` zUG7dZTi#o6pkDDtE6&T=!J(|l=5q`oieJ0-Y6aIq-POA&=;56idM=}~I}rU@lg($M zvICuuUBnT3|EUpo9pY|sbzKR!%M)IUuSJ(L0qR!c zRUqh-)N?EBIc7;dq4LZ%H4wm;!fzR#SWKxRqOt6L;az^NOA&&{i&U>34`-9@4QNu1 zcq=uzA-?$<^XnM6FQgPLndY0ndS9z90o*A3;fBDyUhzgNUhuAKzWEF{!QUrD`Lb?S zr$$^W-#pUICyrfb>RQFhtnH1{+Z(ERZ)SEBdY;qzXgRDlLd0RHjgXJlBR*`Ji0;w0 zNI_&-8v#^plHBoq12ahwV%Ch49Y)}zxm6}=Yis0%mH>(a7a|WKVnwK8 zk#A1pj!Nv%+6t+&LXvMvIggB0v8vpPIX-iii$oKwc+d8RbP0ot0d$*=dlJt18c90F z4B#S!rL$GUk(!gG7ridK&WdlgqeaBO=A4)HFE}0{8Xl^W6Hjx_=jZS(Mf__{mPRID z=}to4B|7ZC%dmemw+C4O1qFW1kxNiuNpsGhzZy=}v~wU{nI(WaHi6lBbyWV5?kd`P zU+mO&sJK3-3jjGXeWn<5fWVlO!oz zhfBQG^c@41>(FuGkfJh%W7px3y%W;;+T@jN3&Mmv)s{?^-9)@&p{pX91uaC@2?;ZQ z63?;Vr5uDbq16`cX+xG|OVOqJhC{TiHbO)bxVg}*^RS#*sw58R*9fBI14rFJUh=XJjbS>iaIrQoymOc z6T_Li1h_7JqD+!e6P{3Z2LR5Dluqn9DG06nTktGj7wi1Uo>5xxv1?B)e=#a?oS_?> zhOF~=*2VN?(4uqJc^eN<#X4UQGx{nDW5wNUmsxLG*A&vg8NDG;7@@BF!4l*zTsoV5 z1qGj)G7ghn(aEF4tb#GF;%PZyoSIu%CXC~kgz$f>ZU=#LbLczPd_EyYf9g8({&?<< z`u5mZ^lfKk&3tcR&RhdY1AEydv^U8MfaeTytD01xLe~AmX0r-hfRs^4#X?oJl(mzK zn<_?ud23qTls&L5iLsKnlt#=tP#kHy>8B(~jdGDnHkK$aqwa3WJEy6MFN2y` zDbc`V+$XO|-vyGn=a>}&LqfZwFs{=^T#e^P0~8f$+=E(~T~ipRqXE=53(B>ZJ76#d z<}!MOY4+mVW-p%EmN_N%7ziuJv$3ZAYMN3(*tp8b|sK%LJLPlYZiP)HUm$;FU;nf+=B!Do-=GZlX z%-0={%6>JFD;Z~kD@k@VG1Gmo zvECHg)$2zy0P=uLAS?}<^cZAkH1c=FD6=gMGnYK~4KkgN=fs|RhUfUk$dFCQo!<{_ z@$*n4W6a;eQ^-k+g}ewaA+2N4&x;CjVL3GTg^wb=7`I(CHFEENwj`!Z;n=Cy3&PC( zKnbw%D$62>Zp-1yG}*4G=c4q?U7^VEZB2~O+?4Nd3#B6e@RR)`T^cbmo+nA@AZvvg zy*$cPNH*7jnizSN5I!q8s>uq8p_3gND+?$T*lrgh-Xl(Vi5z^5Kod z_A`c4jF(HLmGCWv=H${O5CVbAS5vARtj0G}ns*QG00r;J&%}KRqgC|$j?^BQJqPmc z6>_pQF>;O}u8$ZQtHu+9=+AH&wM{<05clqQUmf!#&zGK3z!(1qG{*c;7W$4v>cn!kO0m7TFN4F4MEyx;x zD{gAFPh1lt2Wb=s;WIK=!9A;e;#nY`L&{;5#b77pZNX;}zXdLVm?)9+b|#;=2H+=5 z=e!XB&M1U5F>(@Crqjic5ymPy^povo6UAx&sA!V%gxBJ0(dA5j?N;MeAn23S94hQN zI%z#jj9inZOMBEto5*n)g)Y37OjY6$G(8~Ptu);2up-x)e#c;aA)*MZ@QOV=$`O}% zk?XUlEA*VgyWZr;5U%xmXCNr&-RjyMIPQ(6836MSt$f5Ce3>4BW9Zs!IbD^sQGK3* zYhAM^40Juj1ASiXWOS&9lVZL?3|`Y;f0$Ft1XbiVMwU2 ziQe%wPPn;23#6q09c_pd#=Av(MJUd3k9dWW=W&Uhw#%qla-lGZn?;wDv&2V>YY)H2+ z*dN(#9_}d^k?}c$k@_)K0GA;A%vPaB=evz)wxRWXM9z|i(=Pzr=vv|kk=)jOgkEt- zr$_o8pZL0ZJh<6@m6YNM!;R2(16;gakpV5!wHBE(bp}A;U9UN30FrYxBeKXYJ6qsV z)wI{5dDQVtp#FeSE3p09D&ZhT2;YVM5eRAOV#Z?3vLVQ>tM5XP+t=w!|8FlB0C!Av*-nC*a$*Lae8Z4 z{fS-mOAvO2OAtfJF?J_}$hBr( zHi4jZo?0ibl)9FaSkO9TJ&-Jm$K;F1tKAA=LW?chYd+*{xQ|PX{IP-J*-1{9_VoR~ zt!>Hu^@Z zotdlokeL#{S4(#~BEYTbj||K34c}D8q}?+g^4K({#==`z_S_zi@!>+%2X!ZMEdthj z6PwE`hmf*9OuQE~)vRfA z;$lb;KtPH;;2^p<&-2~s*!TO^$er}Z)9JMDOo6_5G9%V#Zp^%yn%fRB7tW|8OQN@ zW7|pJa{604WlYC?!zvfHVXrE)LR(|&ymSi0~$3O;4t5x^Begd^|NZdCJ zKQP}W#(Lp@{W6g$faq%|%uyO%zN1Vwtx0)APD__jSp)xE-5S_r9@^o!Y|EBG1BG_5BLDlq{$afnjA+f!kCjoAaUv&n6;|Fnp~r^ zxPB|JCO7RtZBgb7kGEl1uFFNsRWsGO%uldzyIRS+pwQ%f!ye^M27f?7^)gqAW=+m^ z>hAB}OPX$=xW2cEf{@X<^FsUbB-0*QTi{Pyf;(q(+pNjH?Jo>>Zj!k@vyG9D&d}a< zu_jx6bF$F1$wKV+>n$a1vNeDy#8PlMyvgm5u#Jy;w!NgTfbSc1lV}^eWa*J4UAmN} z2Vi)a{JfWJosjU$mF$PUaXxnDJqFPM23{kou)o`D2I49io0}PSJLcwn-%w-F-7San zWwSFQ+oFZvlJh1DMXuSI1t?+|U@#cMKUv~MGW>xRMOc$C{YwNcjL;5UGW=neiUFiO zL$GoC?iaXs2-BS1dXT)xjsko<^16kk8z+gK8LhJXNaQSO#Lm18U&H82DAt~Td4Zdm zH<986@K_he&x~eDxgU7YD_4s>&Ch&pI=Ln>>XrHBGUYLn;XNg;PSHkcbndg zRO5+3^k>b_%*`+QZxKY(ilU++n`Ht$xOtu=a5;pmFy(sNr}{LlcpJ z3-7J(2W|ikl_fn#mpKJGAgmJ614>n>mW3<9;|+IoQ%HW}{LC7X-(S&I4awU(MO)R}1omI>a09V-3J{)l};7=eNoQAW%wVV7Vu^!{Vj^xCY?={oQvGgn)#z4aCqx z0Bt~6w4byePMBU=80VV3;bo#zjkxO&cay8@O1NE~@LGH=x-@ZOb^xebjaPx7Pf`M@ zu;=KcmHCt@JcM;n81}O>T&xxyJZA2JH(W zmDB+&LMwQGK2C%thlarRnxVP0adfHG@KbIL1pe};;vY!y-qb-*O z=eJ}aC3AlYhCn@HOr zkIXb^DMCk^B8Bm8(IUC`2z-rC8~C0zN3-T=7Mh4EBVn;DbFWNRD+?cxX-w>NxelOG zarn$4FWC)O_A_q04Fgs!r-+OtOR1NTFbUG&jV$dnjRR+!W>*7J<`dw~;4LqJMBe}U z^`F+u%K7Dc-&_CV-L+P4PVh8+`u$VjU(Ag|b3?-Zk}N@?vFc6CTH!z7x!hyW+_EuJ zqEppINSzTvh3VUIG}ri%JGk@UBGJUkxnpxfx`B~ST{!K#&BZ+lM{|uJ9b*M>2`Zhj z1ay$Q>bhJ^9Y4wc+KJf*<2N}^7?U|Td_-#Z%fnW1= zLKRi22J&@4zDXQHW$;qfv}Xt8o?1AlV-u9!0jNJ<)Cz2WwrV(-qxrlMO@-5;987$f z@cw``J_hBZ;jRSiH`(+W>T8bXJB9lCa;L%N&I^>De~DIix z`K=Y4e^mqzem)R;tq0_--+Y;H8Ja<*^ zN$vaFrV;QRyOjTok(_wMx3{ab-IfD)mCb5-w;Ee>Gt)(jeH#`nlVB2p3?qsd@w0yQ(<@At~g4Bi5T7x}CJ z_`ZpmksxM5eOoxz7&*lD49hkb<^njG6`zc7tf>;p5*u?%7<(~n%*3G#-kRnGc-U7EPIr0d-uM{4G zQ9!q$aHk|{MqkBGgM8_aiHDQd91B&e!nK;HSysvN^~*O3sxho7T2#15;h{I0s5#$3 z)GE6bQVPA|jd%bHxg(mWIo}4S%O5G|;f`}ZWYu_L5dB#bH5YZ%P*-j3GMW2k z!8jsU)p^-jrWqFtDn+GVIh8 zfYSxM$hx_=ht=!~nbBn3eBziJrmj^~rrOvzy|JO1_hvRnq31bGkCww~3nW`jb{LYk zz-1RS_iTZ*6riIGk-~VlXpd-;W*G?p=+M#k@|3VzSGN*=7&x++NWn&4ctM zNJ^R^^0q4?@hB$)X3X$J=>aGvR_$qD-?i}PWSzAs0<5Ua`z|J2X-ObwFy#Z zf>0s+h9u3hr7BjHn=mo0qbaf&4vFLEBGJUgxnpBPx_voq9`0#Kn)eIRF;)PVAS|4% zLX9*@vm{}FvM(b077Bc#W!3m!5qEM^_Yr!<8{9x~d{6VY=v9OcH@fhD4ac3+bXl(`8dYJc`dpZ zUCxB-Ta8zN=ueWIa2+1;R?~M3SVkzOgpLb`6qPZI9pR9@6Ov}9&dkfUAWX

*SSE z*K!gIT8FF$l4bFj{62$Q`9he`VvF{)A%npblB(}FL|Z|etE7CR&3bUUX_97`hnzac zR7`shI0?y$PPbT`W#BKvC|!Ofair>zEh==uWQ1(aWxnb(-V!7+`}tiY2|%OwqSvME zR#7*JD_u>}OqUbQ9Y{eFwg+YLDt)8X$mr2GT6bK$O5bQP#eAoht~;6nLo<+i&Vc51 zywD`gplOngl7gNv&|+})#~MwU%jFfmw&;}D*TXC0}$ zo~=om*`_S~1q>@I0<6_gO%-?**FngMr4^Lb49;aK>f)Ym2tN-K&qq_unv&3s-!~aW zQ`O^gmgXiTb*dqh)XLUuJ_9%SZ03#)*CI+bvI+_=_TIRZk%EScwUeWZ6t4$DUqPs> zZrlKnv4Q`d*HHWEKR^BLVK$gQe0=)+u>R4uKdYZBE(g@VF5C{N*tXb^2QhBZo(fBl z7IKWX&o7%THO5fX2OF)-lxz{-n^>0R_+!I&P34;Ay^`Q7y^BCp9L49R?;Cbo@eFK2 z*cg$6(3O6Lsx3op8{8d4K)quyDI9yh7CQ!VYE&~P^ExWlyN9-ns)^nlbT!zY;?>zV z*c_%cQAkvIdo0|kY5Kl7AI(NnZ!uS`s=Pf)Ia%~`IZ5MggN#ZWMA|UF$#18L#Cw-P zB#zcUclb1bNE}Y(?8;;>*>C*N*;EqdJp?K_k>H+7sfGJ;IUd=vWf#^8G)O0 zk^oYWe#R%uE=>tWR-nmVNK(q~w^R~@`%`o7&WYudnPraVGxWySMG!uk^~YmP5KhI6 z{n;-#DuVFQY%m^U8Ms}7aK(0^6W8O$mvtDD)G#rVKRT7yU_+77)F-AhBlf}r_TX|9 z*$x2aHq=-p7&(sQDq3Yk?LEmag{9jx91r5@77Jihc1L4ukg<$(&^7pCxl|8L;T}MV zN9d%1X>RHkXmm%@!X2=q-!8vXjR^M+aseRo|0YPcW$7;bBzu}liTgs<_7X_l6QFv6w~~&co;0P!j#RBNPWZlf z_3V_U9{`N;Yk1VJVg>SF0Ym!>Y7Wo296IfiV_W(FN$lXgo6u=*!`CqS5|%%DN2bl2 z>>caU2(|G{Nn!{4h{-pPQWmn!bs4RFuuA~vbtm=|1E^rmJ#@3c_|gj>vQH$tZSOwG zLnoFb%U6mCg?mEoks7#`YSb11G& z9t{gs-uQpEBz~vb2tSO9t_XV5gxc8@=YJz)t;}ZW6kICqfSg_M3x zsGaME)8+aU^l)ZE(h<*PRCWiVKWjqmT)VM<9TvCTJ&WH{jsr1#sm9mU3wb82ecTIZ z+UM&k)pf41UH{8)8?WGja!O~rVBn@2Z)ce8yBUo?O_~R=saY|lp zQ6&;R0Q^mI9Gr&a(qUfksw-zkr{0HeK^%o^Fte$cg4?+)VcH0TZFXR>g#sj(T8|?p(R!?1f=t2m z+5qt#gL286TikZALpms(RrLW)AfE=|=K$f&#i3gWj?R)?kTn2r5N4tQxUPN0EemaO zg;|xdYp8an0XP?1__qe&5DK=JU!u%Rs}Xk{;yx;xq&(p{EUCuVqDvD*+X0|%HC_dR zK1t0g$+(8y{e();*5rB99<|XXvVBtM@^hZXS(zk6j~l^f$HUo5k1I#Km73fRr*@t7 zcMRMYQYtxQU=dp3dv%qkQ|Or=fvQmQ9)J0*c-M8A(?;PBH&yYc zoFAfD3nfoBoNU5_4!%3hsV#8+2~obRo7JfiS4w1ub+Z%--hJ#kQ`aiyS#58e-ri8n zdo#16(DR(uN6TTg5h4ylZG^y`7Cvm6i0;w0NI_;XFuw(pq$c1;ntA$)baPG_Cfr zndRLj0hAbUwG|?(ta6-D@-1n#v9XE)RtL8pTqK%c#e23lq)Qm=q3Sjrw=3ekHcNYq z8NkQE(s`lqzuAt~cM_IiS*B(oXaomu>P|xQYHMEY%L@BP)|C=a*WE`H6!2d^FsZp#3JhUSs_n>+5Kg2FUNGu)bdL1}k20_G@Bo8t)5*+6JtQqrF;@ z7-$S2uRKWKFT>Se(B#()^aV4hP_!E2*FpSduDwc-U!L+>crUt~3D~z9uL9DaBuU{q zT;i>!?-;NwHf=6J*cV~t+r?{6&Y3MT!^;SMu=zv$D3x>hUL`E+KY_z_t5KVA#1o;4V5ra%nC_$ zW3GnF4{_2r91X0Vo3eBDiZ@vCf}N|GwVBqvQ&X3ii^{0B1%Qz56XkOu#YSFaH)i%WvRAh-qym{@=j75|d}pMKQP)NF3XK6t4$CG<*RX zk-&}O&9Dn12T1|$Cvqq-YuiA!H=p_T!f-}&%fp8YF7MQkSsTx~n7#}EemiDugpn1- zio4k^-I#bm$~X(RAtN{>Ua>$O{R&<;Is2mD(7i6?FHn+u|!5MLy9dp*-vZY zI^rZtN_n~lf^kYQRo)^!C_A~bf$=M2MwRKU=sPIgDTsdu9clZ|C9(mUEGRv&TH=EQ zpJ0Blf)fc|Tfw_aNsBj-69a5c9xw2zI^HgW-1x)V{u+g!KmYJkv?AX}@l&qTlmFfZ z?(1igZZ}9kcKpY6ii{(G9shCT9@IeXn*TT*4c37hN2Tv+#eR%?uWd?_8``1UQc~@0 z8Ub6d8$q=TN?ilxReXE9O55pDa8+fDz^!%(;~s{}uA2y6o{r78jp8g|ZSRBG*jl(I zaeQI{>?79Hz-t|C(@m75%RF)i{~GUl#o@47*)E(hz=HG~N3gYE>Pt@%O*VE6*KJVD zbQx~fPSttCIeEQ|M>^Q_O`|^o?Qiw1$wX5dXQ~4J-hcS>X$;t+n8si<8H}v~Okrt( zwhpBFE%W)V_-*zW{L46s(vosPI_gv?)i%-F(21c+Hh$lv6*`zTxg40P(I#CG{^vS) zlI_uKHixs+wB4CIF2|vO49aNJlx+3vV|kN<;pV0ABu|KE*xOue3$_#f zs=anoofO|KRWkVG#&ZI~Vt9^kj0_nU?m}Kr7;7~pfY38s5oXWGFG0E5X-1WdfqV#xted58WkrS8$>VuR66W&g@~=RLLtl zUN8Aswx6{ai;Fl5bGXw%YKSZ%G;FPI(26j!vt@?h;ErCeFRLEN#8wjaIx6(W0r6a}061?2UpR-kG82GAg?R z(VsO{awaOd!0;G@B&>`vC<|CNMRpV&9S%~ycr=t6Ht^q{Mz z9-m5mvtS(2n+kun_H9qC@%Zr^P#i4*w-Z_b@f|mAo!|2$FueKj8ibz%gg0N0ZXvi@ zkTn3;a7hbVpkqm{hz0 z1(+AS<+1YQ$Yvhp0)> z!OAK`GAi;esM?KX_gYg{uEjkr7p%xJ0$Jae8Y*HSgK>>1Ae$DtaBS zSQ9|kfiwS*VYLau4?}H&sA-b%X@`*LQPKBUV)3(Y!63Qs_ z5bUFAlBo{Xwn%0&agRiYS>@a*!fi6CB&EBGw%!*zbzgXF83VRL6^mSRTA{K;XsT_H zIvWJSutU#|QNc$Xxmx1_=lhx5?xcjv>_WC2cO~gF~N%AR;04_k{#K|T6 zLcxEt{VZbr7r0bu4<4|qB>w?Q*+Knj{OuKGo31YKM3W@nANRu zK5sZv;cz&0nVqiC{Q*mSOw17)4&&Vm#rjS5yhi#u@<>M>Wr|EA{Zf&&wBYF16v-Fw z<}YaSYlit{{!I<=>i~W;$6lqQzC7i%;9hh&6RdAFUIm~(Npb=X(7jBDc&q6<1}xX1 zLTfGBOQnp| zxfY^rwFx4c&`Sr3Qq}hjqM0fsk^hpHtK&aEJfKTV`U@y&oo?fhr#>ciUncg56dg5;4VNIojRM&E8Upv%3fa5lZ-4OYBhUnr5WVm27E%~I3_UBwW79wwfTrkXV^Qp8m~t_4S&Y6wa=oV)-xURH=C z;~%zW^O-~J8PJ9qu0`&EfB56mXT|J*9dZM-!z0(2PR8EEbEYF>R@!q+(qtky3)PJ* zHaVCGPV)|52JbME^8%@G&EXHOD2PD@vfb>cpu9Fsdr-GQ*QCNOu!Q~r1rf_pk3lP1 z;V&<*W*<(we&D)&sJB3Q(E6*iA4VQwKLfoxo-<87Opk=(pB^JCP9rF!OABK6GE!uF zg=UU+p{ahEAb~S0qfpM{RJmG5LGE<~vg-&cU_~*M%Blb%AxVJ~{B=qBqGKO;fO8Qh zAqeqoIyT3aON`0XozA>5dgILRGh^MxYxDbECRWjf8lQd865Z!R>&qoO;P~->}9&sST8lbJHG; zMm{N)-GsZWLKo?Vs=5fL=)sj$_KdtYztw7($B7Vm3%8kO2hMZ~0940LUP}7rlGuUK zD$61$i5+|m6p7oe=&damCGnjZXrOStMYTjBuJkc@EDEz($=V=>$A;V0s?c0&d_nu6 zyS!$Z`c;UK4w|Y9nraduT^TY}G3%L_@2RgO_hZ3Rcw_NYcmAxHdZPuq(=O-zQMk0_ zFJ#$$G^bt#~1vL$d?t$NlMQr55z?&I~=5QP~}c{tTBz+vMX5 zabLfO-~pf@eaaz-(3~1j%P{jClw_qv;F!1tDH(spnXq=XBsF;fjk_~=cSd&L6Jqdc zSrDhnW#jRNeBVtWxn>8}^|!9YXuwvZe}dF`qR@d}QboGeobTrou6c0~rXfF*c? zSO`lpU~rz_oeaePFS_J!3ydR1PYuP-55>_E900@%bg(s;s{=xTGW2RbyawUt0O8Ho z0}i;Y50Uu+1m>{p%%$zpAbn~il%n)evTBtaXaK%bGYpc!T$b)?an#f<=25<=fD2za z&O{Yo)orMWl0rS39rT1qDvFEatDCA)p!*M`XmK-3VV)DT8SOFCTo@UsEsx$!5!X(7gniE41&iW z6!BIXabu@1G!AH3wDM0K`qEX!&Q`*64BQt39fj}JHET3Ku;vH0kzB#{{xObzCoZc{ zq%?azllU!g2{d~Pyle)4vfbBY136(o6Za*IR?#!g_JimCOybz~qj(J!=vitAzwMR| zJSn~vdeK|~%?~^tKi)4LmqGu?`a`?fV@SUQ_YqWt7^E*jg0^vy;}_IVjhh|K?Rw{; z-(`hnK6?900tukm^CTbsp7HTBgrA@4Hkv35he;6wT(hU2scRKat@iNOdH9dFH&pZ9 z%1a#(GIWUI-nB5i~`;=`ti=pJp06lAt^=94rI+~xmlNldwgN;eq|%4mLb zljOc*@HInlBk!{|Ni;+7P8CrjmET9`pdW3GD9xu||J75}dQxVVbGHb$$}~f;x+o$G znJ)xRNNyz9lp-{>&8-JDZND8u@ae;dIKgWZta#7%h9pebC)sT}ZdZ2_ZI<>JGk}kC zCGfx5jusLBnj@I&9gc7`V=UhPw{<6>YpUy->QBFa3jF{6?mOvBhl~CV3E`Fj0##XP zs-zT87SDBbUZwSFi5`acOMQmF$4Jc#{N6}LW3z9T& z=?vo6ZOYPc=}Gjap>H@E+;H4fP@7)y1}n~k)?o8%o?v#K->a$X`x9ei&ppF*OxK<& z!_w}UC)k=z-PvMHh(i{xHOD!Vhw=oYS;zVp9B!TR1eadBiYFK$9$ZBSP?EdZF0~B+e!EnotkK5Plveo+exsk^oq%E#azCsUr1&1SK185052nP^=3A zEZ^!!tbxL79X!XNJ3YFhUO$0qAtde_h98)36Jx#bzkZn%)BUr-6)sqsRTXWYUp8Cn z1x2na_C`6SYNp)bhrTf}y{R?xT;k6i-}O{)*^`M_M|&QezHgXZK5s1i#{0KuLfnX^ zk-RT=n^jrd6B=$~sNt}DhELt7n?&0f$hJL_q)V6bdB9|pw^J|KI>6AKb8=@tz;rkh z*IC%62{fCAJM++@HLjC+F+{8f3HKhst`q9sK?040xtEgA4qX;s;St}aM3VAh*h_;o z0giMk0F>_${dNnRh}DU$`SlXEIhl^tt==~7QWiH57AA4X-eUx3V;ED*ylz3?IXL^AI7?vp%WbO}c?_?{?8@$FTDz-b=f z-F0&5Q6+9FWo~bkvIl}SIfec;PHk#T12$g)N9lP zt)dFn9VhhNP-v@$=YvRQtB;axoh!?iNrSEx`dmyuiqb zj5~~mP6ET553fP^IY4;x_2?FYs|EQ&9pVl5u?FClVOfw`HbqAXAPikm1Kld!QoTgI z;u?ToP^rWl0pN_vL=&`L5kc$e0kx2cCQj1|1bvd)Cxtynjgk^UYfZW!?NJ+TB5Tk> z7hcn%B9{nSYG$O28HpYzO+@DyurFj3p+H?8kzc-MW;=-Ghs|acxKM9`1-8OXY#5|b z9E8tk>Y(YzC`ms8xuK?K#W}k$IX}jlo;6ASLh~i)jec2r8YIm0{s!ri+)SfSVaA*; zh}jm}XJsQaJu5{4r;B)zv4A>;&<#`9Dh5OC->>uU9~HY^Iqw-d*i%m( z_iO^_I&kJ6GORX11lH3gh?<-gopuPj^p3VfR7YFB#adlATxh-anqZ#~kT(Zqukfti zP93`u`ZPct9K`DC-MO6K(p`f#NDeYc5MI^+KOF}Apt*&(`0a`eXaVz`Lr2>pFPsOM zg}aDTTjZLv`6BD3zVT>vYfa4x+d8u|E-Qn#iXc(nC7kpw zp=#Q5s8gM&i#j#|*&Sf|14gZY_Gc@FgQ!{08_slv=>C8uJ_h8Y;jRShH@QF5NMFaH zFdg5>?R!I6z1q>=XvGVKb~G_7pyJC8IVx!KYcA9yh~W98$Cej#`I9)^^=!8}iEP=y|kHkNmNL z>ce@(=5jzXw8)AxuQ5#r>n#{8Rgd10RiYQAUCS@a9_T?W@sPd^Ei|oe1F!Vd*2<&L zrhg7dUdcKZx|Why6kk{J?TV-5p-jBkt&k)SvNFi(&?fQhY7;~>fx}JH zvI?Qrw5*SZ5|ayA!zF5{glSq@_p7i z?z^jP0y&R~z%jHL11)OqRn9W9YtJDOAZEsUSa=k8jo$(<%c$i44TW!G@(h|LejmWV zvF%6kdJsgz7dv?g+$i1*`501S&hGI=T9G2uygVk8Z5phG0Mi+pQhx;>J*0p2$vPe+ zFEY2tZ*rVP?|-%=rtCcmYMyG^5%HUz{BUfbeTm{%$bwyZL7Wd!0K-z_6Oij9eJ@(u zu%0^^(lW=9{sVRN9K)VdC3DdR3^ZcL?#rn~Psx`>lD=VHv{3G1iQ$N<{s!q#+Ap^N zBbTndS^<$3oPuEroNGIg=f`IH5)?K9KP6#T3Xfld6SE6C8_6K3p|dG^C+6ePY&2So zr`C8ZJ}(nzOj6w?rq2Bv`$lIJW|2tq=L`4YTHxR~K=T`dsSTX5*EjUUA zwG!_3Sba{_Y(;k!ZM`pc>b^VzeI|j@1btKXurp8jV;4hLxT4P$Tk>%gz~TGExIy`+~ouu%xX4F!$p6>qfSg`kmc*_qY>-1(Kt zSM|0~*NURF1Hfxhy#V41-hf7%K8n2m_3J;amzDF&_rACO$GdB--kjiRdNx;@a1&&y zo!luj*g1lVuP*#s1F$rAsCt(ciVU#&k=E?iaIG%n2mQg-E z8pq4PwtRKgBu-QrIPxKVSW)c!5QXFcHqRR9*B_D>JN6#z(0d5d*#O012XWzC%7y&~%z&CCQB4S?FV$}f#5q{yN+GZDqKyE!LK3dpnhG!A%6|ga;2&Th{tXaj=oYSOq9k>O9a z`^plQhg7AOqM~L0Ea090`VwY|Jr22i!mvU-j)w1tm2kNhPyDOxzuG#jjp?O4N1~54 z{fSbH*wmjoyQmoAR*t>?mWgfQ%IU*JcOjc+e|iv)XcMa=O7)jR+zyT5;$uizOS{Kk ze<~$R`l%(32QQEnM0y2q8)thCM1zGc+_P1grMpHX9)=_xzRr`r9i|W+?!NZz&HFa| zpCIf{jhQv|=Z<3xjrrJ|S=QXN7sOkb1meZALIg(->k;4HuG0Q`W5Wl~L_A{*1H0aA zGPGQ0Y>r0r$(R_6#dOl)sP8aT8rXf0{Riv~gDl*|Y-AC8XiUA)oLGi!dj8ZiXQv!? z>MdNuGDl-$=$O8-FfD&>8`Ig;nVxc3+h3TI`P3QDhZEDE%sppL7RF*ab51(RzA+m^ zcF1Dl4vmTByT;gbY}c^I6RXRw-P)<`q_DQ|A1i0o_sMwVlbJbphYMrkJ2QjKVQ_P_ z@H-yX1!yXU9r>fN1)n){hK6bSo;x>PV>B8~4EqGbX5Z?#eaEw>3o^1{+m0sw*!Ab` z#I#0J+wXL3VZ7(4Fv-TuA*M5Rozc*mc(xDUy6|9yX9k3uc6M6OC52r4-6T6??AjyO zAhV%6nM}#pTZ~5|5G>a?!LYeRIsFlgMEv>81d&?!wlTN;scnrxutpsZ8`$gJ*G?_l zGe&b~Y!4S8&%QC5j7O9CY(cu-K+>>tdo~-vsbtQEQ_C8g-rNN-CUg6=!`kzyH#02a zm_u&{yLG-WXU4+ujCt20C4H@LIgSJ0>AJ(|#2!2T1h%c^*rP?)le~7l-P)SoWI>z> z=)yx z)2{a|Ad9}k;KdsLgG{G$-**&dk z2326VqXitzLk~_Yc!dd>f*x=drw}PI$>Yg%F`vyn-yDJ{%?TWj6fgUp*R=+czIHlY z0A%&xq!^OXY&`KTb2gogeNacI6sb9x7~_QlN?e`|+%l)8H-u5AvpJa&Z|YC2)2afP(fQOIS@vk?PHk@vGi|{>0;GJ> z!_oK0i}Bp@JPRzo(ZmBoWNf>RH8s1of#@j(#var3{fTQ@1b~fWfk=%e)9L?X?@OE8 zHnOh&N{Zhp0F7N$`C!MMBs1}B@sre)C#C9DLd0zVP>$xU`S0&-kRZ{d*a9f-ysjBb zu_&V1%k6W{-2yjJG-heKk8`_tY#IgumoXeuC-Q+}CfrMD90J$md$3ZP+v<nNQxULTAPPIbZ<~(|0)5rNEh`+FdY%9Q4x}3& zbc~&EspeyW1XK?usUuR@Q*h_A$Ym^+dtF;F4WXnmO~ghgo# zhiIRVjRoLx5Wzg(@jxwc)0o7Z!%eXBGi!WWxLZS^phh8eC@6luFQimH=#RT~#sH)+ z9t(Gz>w~Y&3mi~$;k%H-7E9wK*tLZ+9xH`}E1jhzc1RM_ln1d&(ll}7UE5>hvA{!U zno=-K4tOz>BnI)1`3y|-uDv4pupx88Nug9k+CAY*farj!67a})L9}a(Y&RqJ`6;Z_B^(32*ja-l_+>{UpJmmr;gpdo@B_KKO z_}m(gq{7$#CS_Zlut{Oq63nJV-N?l5St645-elN@Wd_0|O2;vH31&&4t z2jPx{iy{yJL8$Uma8WHju@1*v?@w?Zl@a7n!W8Ig5{+_s-+Z&$u;9f4X@C9c{pas* zH*SPk_C#;?t93>6x@zsqzk9p81%V}jbJyG$%TgPg0{g0=E~+9QVu%}ZwdzKGf6G7q zXG#a3$DbEL?q;lh74AJ5XApdNSB~$h4*;KewIYqRgIn(>2zq=EzdC~OD?MRbg)|zc zp*j(ttHbrZK3w`;-?p^I?lelb!$R-2D6?^J^}BCTl=%>Q=PkKnuN~UX)gJyTOC6s5 z@u&AI8=<#{GR`fH)}oTLZ!hHhDH~2P)6x)K0v+-4V=YG1#bR7D?4DCDR2_42A; zc>~xw-|5>CN&?Q#)sQ`|zvRO+n8u916GFFqT%4Bm7k(T)W%+mntr)9nuz>v5U-J{h z0M`{A^w_HI-!6&QUs=Bj>psk{smrSSfGggyFWSnrigh1a)qSY5VmelF*1xtin>RpC zrUQAS|Fr=Uij8mDzyezrb~cA_Op>zZ4Dh{qsg?o zppV1)O&Yfflou`J)`q?K$q{&T<2;{U(%;ff?b1keN!vmp=k=7l#=TJqIqUNa?vyy< z5Eu&adl07Yu@K^dI4GwkR6-qRP0*VIT>KnKB ziiorR=9Y72wex4I;dGjU6`Fw(&MUezN;s8-k~^ zDB+-l^Ez>Ov6jdBmA)A=0Xstl2daUrc}fmkpXihooG$z6Gz6UW5pRp@k6pBBPx?)l z0yrq(yl#ir1e~=AhGgjgiaJ12x}&HsA?Jue@>rBc0W)YTDmeR5aJF8M!$~-A8RBVc zIBTEGQg6#R4VBa6H4$g+-EC*>LRFkjbAU3=bTS#|WgjDPzUg&|#EI4qCr09|oTkf) z#K9GBA>5&iQ#)MX>sBS4HT{K%gUvxRD~GHRbF*Yfn}m#xkvPjoHNy;gJCD|%6(4O@ zA>{&?feS@Lpl%6?T@Km#x+*~&r-@;Bks}<4BeY$RBXWceLqv|ysQ7D}w`<`DwmDc@ z!HR>Ss~26pjZ0qN^Bbb|5izzvj2GnU#l}A9>dn+YzWvsOr~-2MA-@$m5me5#FUFmE z_8ejUX=d^J^DyO_E$D!ENC=oES1nQlmNaFjfw*hBpG8?kUvI{y=5_?MvzL;w|-(!_yk+^LjM zYD7RSJgA3fUd#o5kVAU+B=cgH0&GN{^=MholRC%w<#cvqTJ*36G#}n=S?OV2%mdY~)q)&R zJL)jRGt-VN=4NHtVfwrKmn}>hgP8(b)a=Cc|7%lnaK&4#IA#ho zgkX#U8dZK!Ie@yy8Ps>DuhWO+i)8N9mCo03jRiHKl7mW)ANw7nfGiv8RFxbXuC-$O zYf*BP3tfh!NJ9?YnF+Kh4m?J=3vG`GDmky4;ucB{BR;eVqp5J9Z6q{ghDL@iG)eP9 z-{7vO+@}0F@k6a<)=( z%vNEQ%!<`JS5DJqRqwUPL&cEYyFp%e`){ff*g?}bQmIXgr?wOIcwL#5jyN0tiXU3 z7#f$nzUMbo??lAd0x@2cw-;Bu#fl?GXqb<)=LmCza01mk*EodLk+Z46!9sM^rAMnu zGMdFL|FwLcRR1dfC}lpPgXK@^YG(itN;=|DsZJQ z=NovdS@oKmZ0tPH;vwVXeB#v4F#Jx-w{Mn%GYHyRSvt2KNyXo6W$Ca2!!i-1!-hH) zZ|~}mE&BhCs&}qF(T1e0Y~q6b%UtG5|FWUt@r6z5XrEvN z#*kZ>ru}F~#ssG#l}RAe$aMk_CR;I&D-N|gqi``Vl^t9&lSV-(tlmk7)lK*5{a^YY zKK^q1vhH;IqQify1v#vCwCxa2Upq2BnZ?`~r=dC#pI@u_0M_1kciUOBTKn_%FSnk9 z+Gx)ZKlHsSrb=Z{$A47bXGvrn zlvii^-LF48f0d=ab3gv{eq|%{#*fW$8S6MZqkAhkJdt@e)cF+f5q{hR!_~fiH<=7F4!=Jh>EB-V4_J8vc+7YDc7)}bf%PGKTz|=j zXPC>3zY`*tMe%(;o=)_;uD|f(=qby`=wGh3-Dk-kM&rTw{&{_(KG*!`imP{`c7)my zc79pd?!$I|S;aLL)C7zNwIl5O@=DEz4jbx(w4>Iz*1&|<(uZZfrtk&w1Q_o#L8Daq zl(~){ssI93c<2#7qAE0G5ma*e5~}j_z1t*cYRB}+sX{F?}-B2f_6u&kxo&0xX~l$@;=%oN7t94{uvxYI4D36&gFa#|@lZ8y{jDLKZFx5oAtuH?+yu&}-l;*C^E>_G|O zR8cpfDxxHSZY(}3Id4#M786W;yn(9YW6uBhbfSIOzTAct3S zwi)7iC^?HyW-&L$Y3QWnEZ*IA)-GJhX*CC^)~$Z?zx*RY6T`ii#j7 z&f5%ak`k-7L$}+sirIFEr>`9upUh%zjMGptg*MeYjd!=5HLJBh@9Lec=U}OzSM!V7 z5o$*b@(16dcBCf(t9N4c&Uw2*>#b3ucGNH*s2z28Jum&!GIxxYtHzyfK~1O~p?1_t zJ8HY3PDnd4hP*YlzZNAYp>gcHQS8M|M4-l`NI109l?hZOKqY4vN=}@DOcpBv6vgSw->#=jY}TBMQ^X31oZZz zw->#=SQid#LCqF=(5rqrkX4FG_1(>A!1}}SC@aS~WD=5Eat{I4Vuz+ z_b=P#&1&s0$iHlx1JsVtzl{E6^e=1cI{$-eAxy-!Y9acU>usbb@!b8(bA)gj-62gD zYb9wnGhM4vvr3xZ%kn-SPbb9!P-)?-lD+f_E&sKAo>c!T|0rcXqJ!m6Ms!&H1e{AH z9dX%st4X7POZ`0vXSux3iZXw`fw#)38t22CZ0tbN{zJyc`NXN8VZaHExVEAGo^aA{^Io+@xxh$pwUFD~_O4Uj&ezKK_+Ss?w zV>0h~Xq*8XuC)&NT9h0`7-Ntlz_}BJG+-*^u1^^CQ_K|DiIM|Z7f~b`5yVMi!IQ)% z9_5~d${GvPSsjIfKgc1ydy;vPjdiU7uX&2BMvL+iexNr+&VE!MtE%#Cpxs{Pox=7VkCtk(X5lpNa}tQZ800>UVu%JMJ%LSC=$ zL5u>zC?Jdi!YClH1vOzkZWNFOHDMGGDmmSi9Lt6})hHkvuC-$O3s!Q5Tr8`1dLm3E z3#FnCKo{LRZNx2cqT{Xo%Yu?W!~RbUOYGG^)cLNz31;efBAo=GS_XjzO25TexFJb z)<*u_uRl9~m8HIOKmPQ7Wh3;)kIiuz>o_~3Rllx%$j=j*XJajl`>x>&)YiJBC3qn- zuE+l=8)d`kaCP7%^a6n&*KA-mGw{3bCX+$N;rC~H_A)DAj8GLNz9ig{5SjyuPRs(ArVOih9xNtjs|5jocfdX@+Ya%}lpKq>S*M4obF1F zWka2+l4HZQ4STqr5O&E*j+*D84cMTch6Ln=P{hg!A*YIQm$F27X%xAr`NxT!HFXMc5awpx$_D>>Wj85rUjC^^kfW-&L$Y0!wc zRh^vHOKY|EXRhQlXSl7sf%!!x2bG+fdd|LLghpj|>RJz<=Jh4&KxC^8(Gge>gFFDP zUGu+saxn^vOGhVW%e?<6M+BT=LV6$5$tyYI#rU+J zW&V_L2`_uf#O!_kS?7a)mi%Ef9*pmw*Pn_pIjH3PZ+^N@qfU;2Yb>YO)_eJqm7EFfv*Co&VhG>JC`y!Ksc@7R%P{g(9J;QOJV7OATP3GC z!8{g8%2E}jj$n*YrUVz9D-vRzoI};gfz7_$@og6bsO}+Sa<&}e87Mi;Pi8SUFW~E{ zeBUBptFVoPaiBO)wT`?wSk1;t-lhAfSj;Q2x7~+{JITmwcoCZxS z+r{LxU0SQPzaS;2!`?w92bCOs(3XEt$$_~*B?pz9c2QVZCueCouy@tGUx*w~T|aGE z0tfQuHZ>4gzDVZINS4dKJ%)$Mf|^jtK_#cVl4IFWr>f-GaIF>FU$~MZo~N|b*;TG$ z)JvpHxfA+4j-hoGgyTd~aE40G8I1SgWDiJ!QPIXoghVyau%P=Vs5rqau)AyJ8M>JfBs5Nt2w|rIo%rWVZ~$O5`w(G9k0jiDy)-J zD;roRC%=RIwo#dt(3$!nTlTS@&Coo?rRtmwk%X=v6u+qr z_r^DEV1ZdKm45dV%dP?s)#6UKpe9suP|0bnK?cA%0XB54|fROU+G3-x!QmnN}?O3qP~oVE*cL?x%g z5YJ4>v6!13C^@!yYoNFFs%RIaTis~f@#<`3JYU$nmY-5 zSM9QQRg*(lP!lRSsN{54ax5F_RFxbXuC-$OYf*B1Pmqu*1xgNQG9Xaw7z$fMH9AjW zOwKN1asowCkHfsiPQv0)1xYA9s74g7)ceEis{LkHEu^)!3vxsyr^67>Ov$mBn;j@Q zwt2H!`wLQXY;%B04k|gQ*OpT zs|7Wol7mW4cO}QNp-xrFvEf=Pw!a!BCz3Ar(}++<&?Ev?CzO#)e3oLxO;bs1Jj$vlu&37=8`0026sgz=RitM+XXqIlG9;`=ceRrHaEs;&|IT+oty>YvCW&+ z+Fy{8W19n1a!|=ZB?pxpRB{?KP~9}!bt}V|oW?x%&OIh)c{|qnjsA4d;Zevx?jGf{ zR`?(jtaISa#!d|j+!BivJiLL&Vkc!p1~O2IV37P`sf=fkDSM|a{2k?GHXapV4Zr-h^5UT^^Nin(=um27`Gcf` z^5OZ1O^0^=^8ZX_u8r&3+v)eIz?y!ucfbDZ{8g4(m;3nBd&4ZkDI7mG$7QVJ?2J}c zyBHOlDwgTan$@%V1#$%B2*?qd$PT@|U_`LLE%vwl-}1scG)I6oiPYni^Tc7XlCe;P zg(?+M5Ez#sa)eEAgAQmuT!52L@Bh;O@bQ=1m-B*eUngyC7vzW>p~Dc7BQ!XIZQcxQ z*{}x{TD~AZf^80#RuDNtelJHH>+Lt-B7BRPo_Z3tM2uLa4Xd=(#|f*nVU@NPVMz9R z`wKsVzd8B>BSJAEbc=}4%^T`eBSJ0lG2a~AySJw&+OWHozg$byYY;|I6;1albf7C_ zBKnkHzZ*kOH`{~R-6nGPiscIRjb-A$Pv}5 z4nsUMwaQ{{R+e3}MhcQb`F%c~PPE_ibs^F=Z&qu6L28w44p6N^k2ZR=(W6~!DyUD+ zW@1}?5~E(5JL%k`Ugrp5)@5Ms&#Haf^BxEqh78AII*?U2gk@WUFaO>uAhxAiWkF4- zR-szeU9GZgs8dy|Y`E5n?XN}2iK0}bTu7!I>Bm8+h!;n3pwiewC1)2(4pXixsHCyy z5E?Q!3L_Qs$mPN{xGTmT9VqUo?SdRp$>}h}GgERb=EgV;8Xrc6;43PIh-Kt;$A4#W}KF31r%LWdzDM`+|G*yin8ID%~smR4|X{V;#o z*cPif+t@)KYZq4zo>sMsF*gBo6KeK_xe1t?u)Ev@i?WK|Ui9{M_x4&g)Tw%VE!y{< zG6if%+JKF#nad=derJ!sCftR9xc^Cd=Un!cViiOgNSV*bz zR1(B8CLU@>N68duyC6r@jyeqS%(NqmxiOT~O55n1DPWs7tF^x%|FUfkP&-2ZGWwU% zzg#OE@D(eW=t)5TGS1b?JPAF*CG#U6D-Inc zBDC#-9FZe*7$S0n21l^Xn*jzJnt`_Jy$kXq*ydnq1*=bu905C>)u3kf72^Z7HP|vf z5IF*Jg!(ukM?j9?r?d0$de4hg$Ur12V6hX5gvTB zgQXSJw!Mdb1oR^`E_uBr5HW6#7}1Y_euVlsp&tSL2<`m{DhUM-WW;XuBXs((hF9f!|HS0tIt_B)TvgVv()0*Q|AIpcJrQ|Xvq`U(-SRGM|*mr z#fPz{C)ya1l@(q~-9i=-kFvz2p2MMfp$bVtl^`^V2-Yp!McqPIrYuNUl5i(gG*S|# zIf*D&5ylA|MFVWRAV<^yI}Gv6G(d~FF`{NPx9D~5Kw+CVtF^zNd_&tDpazH5+V*6`Ra$tf25kgds=P+NyBoeM9eoEXVMI~n! zN>1cc9&r%MsKb3P(sexIgt|!*34^<$l5-#>r|p6qQOW5r#4}TJEat{I4cjR>wt2H! z`wLQXY;%B04k|gQRK#tHr$XL-4IRZg%FKmJn z_V!woRrL0vx3{~u*Rr8b)!S>)zV}q~!G@%*Y~pJC%P|*BxN(#?VVs7(2&EUvh$=Tg z|MD*U%c18IXeb?p#9?t5qyd9TmYj$PwWFidd}zBMN7Rlw4DsBwqs`{VP*OF!>0a}} zHg8sIe?k6b+Z>>FgxV2mN2ncX>pK5~+7V0y`j^qad`$mxESV=&Bt;5!;W%Z=^Fr>0 z9t(+qiqOA&ApdgP1vw%|=rBa&2o3+TZQibhBiQBuIRbJ7>(Z7uTW;{`j;)*_n!RAHY9Cj6IbJ3W+_jI7kR<~_i_{`GL|Az z5pgB@mv`Y`W{HwXOjRNs=_=oilPC-nPyEP3?dYfXpTEETLDE6_@chGpw4=5QazyQ@ z!w}C+JKAh+jMJdmO?UsYZQiWb{(}6=wmCrU2(_avv?GX+T0fkh#v)Uh6z`vVx8L+= zKB@|87iDpKn*50@|f5_jyj%2Ri zpGms@)4%8A-z6{g&xh=B{pUZ+{3+uSUiOrU+50R8@LBSQ(ReVve_sE+&oa-c8s|g! zjIw%nI->Vd*kN@^?~6M+7{D(y^B*fq_HHs6WSo}ScvQXLc$AgnJR9AwKm0p=4a!kD z8}Eys>%;Si4m18vh+G!M_xX4_(eJwcULQwKSw6-U-gv|$=H0J9JAaj>*5y9_^nL~F^u~|P zaT)74JEJpnIx24I1n_22_B|7(YCKv!t6v~TK*YE&#E2Xrh)59JUJoloj!+W>eM6i( zN0{F%zg1u76_0AR&>N1$bTAVPs_$+_1J)ldxc--aFJzJ~^kLbYOyS%g8de`D# zhGN)BR*2I5mT%7)Y7 z$`0;nkK;=)>)gDJE{Rt@8XQjaFR$!~OY$${inod=K<%iej+!!|cC@da^%m5G+7W6; z-L)gjhB6V+sw}clhz_nD*>J5D+h2>4qZAZJONbD}aYH{89`OUp8HqfKO3p5n953Oa z3_?kjLp-8FrJ_WUBn^of8HrIq2Z{n}yC6qYaykt0%#<99xmhQRos}HhyjiXN1t~eU zIauMIsN|rM)1YFSjbY6Jm;}reKqUv2oJ{@W+i#6axhLdALfrfa;zp}TQR7ZMdnIRi zJ2q+RAuqmsIf0KQr9ljMTqj7U8!vsrP2zeWBydV3oZ z!`X9$`BiX&nF1DN6}`Ra?d|UEwQQ(U_4Zn{?>%J-*pRdV8&}!Hh5MHWY`~xx0_{UZ zeIjGV7&PMY{V;;+2Z^FFOH-^wN8jLIUQBQrr5^W#*rg6-eiFuh7>E%3%QP`W67(}h} zGgERb=EgV;+bKD=dAk-R$2JG3qiT7zNbS1kb(Z!}4}K zP^Q3wr7ACoC=DZ@I02Qh>${SKDsbgWCl%xf2jU2A7vzW>p~Dc7BhY@Uvvw^Up~K$6 zOaaU$Zd~&4EoKwzNx*Dk z-DV0bPMr-&TiL{g`db+9_i@aiTcS@Di+POxBxC|q3xc5AtFbh{Z>nREgYf4-oZ=(^!7F`c@36ctP+NC~#9XE|70XL0DS;8Q_*x0Mc5e~!=+Aaue51Nm(If5^@^lNd; z2ji*uN=yE5OJAmpRg1LSZCj&t-ZL;nWa4 zjce^O%j z%QGi~Czkyf{rLMwj0lCrtl7d*vWXXX&=P%t5uuA+Ua!^c4EAORuD^PSCi(b2r$gBM zUyQpS4kM$*!^+FyUvF+4_}_3WrUO|x(=r=4xh%%hoXh?oD@sTI)gKL5zu_<{Zs4tq z_cx9pyzPIcGJl3qn4^XtWTVNnI_5R)kOOc|Wk5b!^fFq$NaoH+md;~R^u_a(me46` zDW+RClsRg{yuje#lTQbFbZf(2{A59wx{SLqbsL6kiI3TBHu2)rS=9DDJ<*2Ujm@;W zEEgX23fs5JVD87uotx7uLAhoSb>r6DLer-4g@ot=h%6HTF*9Ps~{H6^o@Y~}1 z1_NwT@jZI97k4&I!!(Gv5UHaQ5rko+BFPfpb&(?+GBd98f*g?}wB0i>MC1sx-)d@+WMCl?`}J5R%?I$+EJ@HSP|<{ zJ3{TKCcCq*s2x>yN9H+I<9zsOEUK9CcGZ$mJ3{TKK2E3|ou78Jyd7)BNU!D|{maWc zJB?z`O*|1gQNUe44x~#Z7hxD0s0ca2p*TXz1vw^1Xg@^c2(;hotX&O9Xuo%mBOphp zLCx$das-VEwv0$bj({AYK2FFH&W|IUoPT+NYb?qt`j^qa+}gj~W<#Bre|a%vi~he` z|MK#Q79?$D6Bq4Y&X?i55%*}qd?L9MDo@BD4tN+P)K59)FK?Z{+?ZgWaq1@ovX&h$ zc9kyz*H@l&Q-a#j;c^qUSdc?&N81hY9JHgxC$pFvLrK*byrqA+@$R;>X0`U`?q6;> z2TKLLnqSn8P&=y0?(8dSN0r?{|1yc!%`te}GnGm4UKfd4)Kn_U;@0d^f)%;p?!x@# zv&&6b-i`9%M`*ieV2H>O zS}yIiaD)zf2RQG{32PiR%m;Su+0dqCL!Md#w?qjiX+i~+ zj_@Kkg&}{Inj@qtWQml__Z>fonTTB}LZApjU}w*xaD=uCazu{MVTi~P8XUnk zZ`Z;RY;&;mrfS;`S-RNS)7TcjtxV8F=Gj_&Z;dHp7 zNcT#}T!J4rJ=fK|zne@38He8=SB-<0MZZ_x0G8-G?OcVD+fXN!r`8ymUjQqSc{!aWaj@wUyyYfi8WWnDd{7;&A*Pbf|O zAcas{H}rjj!eE^39^-7cS&#$kV_OdK4D_+)C$pFv<1|z{LaSP@&3Ct*HLJBh^IW{P zbFiZEpgx8^^ajC&Z_$UYCjsj?VVo_-*=Fh=-+pUc$~_?`as(Yhc?MlRZ@>9s+^J{p zL!W<|6X_GwywfeH3H345$J*&*EjQFD>0`|yZ;kCQS;;BsQpq7wx{;(F;ZDkgqD%@d zh@`%kppvt#lGB`EnA$KEP`b);#CS2Ttr|PyC6}KBAyK>4OD^GF1 zm`*0+yzI-N% zciUMrQ0J;{f96U~+c{V<2&m+|Vze;QiMSXW|4px5Y&=%v#){mvFp5=`Fw*I5kxtD! z-GZ7>$=O7TGR=c}{S{c*o8;sBoDN^&Ka3U+D=!BUaC76p|Au2R9mv9&mf668kmB() z=dwS5U}s1F)gM6z+(v4AaRYBiPgGkhjM6*P`V3ER-p8 zgCKDzB_c_fil7--q7*?TXBSFN8WQ2TLekjbK`33xT^e~jA`0tcA4SP&yC6qYaykt0 z%#<99xmmwMTgBuwFDTo*8Q1FS1$9A6j%^N5$>}CPqmqM4j>goe@0|T+;Gxm=y)kvpb#jRqeOgf3LoHI?5`F*CboU zP1Y;qsL0CfN!}Tbzb^)j1TvdF(X#3+E}#GW-+z&Z0sHk&N(_H_=49~1vLB-#fB%Rv zIk4$#!rGfL`D$@0PJg4R`!d`3%fGiGuq}zV1vR0PgGx@jn4Bh1wrr@Tarx#O!@Pi5 zTj(|Q!B|Mwi=S+D5MEbuY`E5n?XN}234%ztG7PwIXzF>wO(PnmJ`ckfm7HBDIRRtL z1*OdO9L4+~U3{h6%k9fT)$Qw6tHTh_Ov$mBn-$y&)8ARivCW&++Fy{8W1E8&CW0|J7?V>Y zvDsJ5u7Y{M>?*8K+D^N}>O&3lf!S4i3!$)}CRB1z$?2}-ST@wDDmgY>YsL20qU3N_ zR$2~89g#xQdN1%<slJm0Eu|ny4 zv&1YYmRfm{-Yk=}U63OxIUR<0W=f95+^j77HcF0d-mKRCf|MNF9H5eeF*#UA8tX_m z`8U>)-d?*yC8xQQ&b^NG@^)+n96+}PA^*60lsXk=;neGr@$x!H5P_!xrd&UAJnE;B z2gNjL5=4{=0~MjS_dwp>whMAZj?iI<$PpUlWNh=#_eO= zeif?Qs5o*~`ry3DziI3S~uf}HTpha!p*Ap$+-O69CCF)g49!e_H)O8X{ zq~|4W5OY6b3Zq_k6ZI-$pGpCKY=_9i3#IQV5hO|I67*>Q^#1erw?9ZaC?B4GIFLs> zY`GvuRI54+@yygJi@7mQL#3v4&R@38o7LK1Qq*hv?Tz`%n7>@R;AUSje;MWh^OrGy z8S|I15}h`QwQu{lmFO&}3Dqi8tGcUImJM~XYLx}oTCx2_D>;)!cSsH?wE>0HbVnqC zj8g6^7Wz>dU?sZkm7K-|OUO&0(j`&gu$WVkgpub3oTMHqIfsio+G0Ttt>kPs#B)$` z8lQ}8HaFWUIgNL>oi(eqKX)ak1#OfW{F^nUhEr2b8)r zh5(Y3Bw!>K08VStRUxq2Sy987Uimz!en7t#cgv#dbx)kCirDg9>T+VbwaUg&4Bd+L zDHAf+!Q1us(0(PC_s~%_f4(VYo>Mi>hd0^Sd4T4u86W2p2S#8F8C=dK9dTK}`+Qjt zxmsn{x6j_HOf+^NOsR+>FOHcL1=17BgMW~Oi4dzy97V}#yC6qYaykt0%#<99xmj3= z8XdOmDbVt)EewEu`_){43sQ1A>>Z5B!I+%-u+6?=Ob*Ng#^hj3P7QOdw+3dAHLV9K zIeSxbET{>U98_|;D>;@8b*f5^4cA(&^tC8CJW5mu-2`0aNFk`ppf{ut!V86O$ReoZ z^d&9IzIU4hjgzyXUTA||3O|x8_ER1?VFHyyNu)yNCp->PgS%qA(0yiCZLuInRC3zx z85rW3DLEE%W1I#J5xXlnwt2H!`wLQXY;#b{?=t|7^+K^;sBtRb$h}x$9wRhbMQC75 z4%Q2;r46hXdVcjn=eF>->g(LsQ~Q07kX_Y)tQORSN)9SH4L&*;*NG%DcSf>w9+P60 zfHN%HZKzXKa%{NPKryRc+N)7=65?{GH5@4?f`lK>qd~|6EJgT~Wz7kdo7OL5`^8bQt2fDLI?Xjd2>bQ*vzc zX0`Sgq~zG<0F@lfuG%8I$|Yt4g6eQ$cGb#hx}@wXT=7=g9cEY6$`yP)`=zv%5n#MlZkUXZsJSG?7VBS&bM59A12`w@gMAl%lcByl1kIB)~S zLlSZ~a*-n(tloYDNVZ*&BXWceLqv|ya%r!HBXrn1$PthuG%k7M2(!t+++NJ>#oS)3 zx38^1?NK;#MCj(|3ycWGh|nz}LN{-yQ;i6<#K-KiS7U=sSk(4CJ<*2Ut^DPJqh802 z74bN@SiK--%poacE)(v@3hJeC#W3h~%b?fh{Q8LpVXgs-6Gw$A5L5;MAt}_MOHivi zkXE(LdK^}&+H!=auT(WZn8nl>M?r(cR;kO)H@BTLtDQgZc-OX5ung#_W*22Dl&SPa zSpGp*Hp~UeR47xSOocL)Hj77-shU^11u~&Zg(_7mm8#`_Iw6s&IpVEx{gvo9L8_Ec zaTL2wDqS~_Ns@ws6Z;WI{bmRHjq4?XhGD=`N2V!JM5Y^Ol`&npm{2Z1Oa3q#561V;FIb(rMG>TA8-0_k zCIr)!Q!G4JOQBeJ4hzrKCBQ7zjyBf`Yob*PWJ3K0^_$N6jb%TbsD5Juwbo1dO7xqE z`mXSO2Kr4Lrks!@h>7oVH^8EEEzIzX?E?%8?1nydV^0Q7AYDa-lrr+700Ny1_=xo+ z_E%40oAo%JeiO9ZF)+gO(r+xL#yAQZ33raavCW#*&RYt{)ks74@6L z=r?WG1E3wvN4?wX%PnA&TRs?1#aCMLhfN(Mpu*qkrXol}Dj-`e3ZcZY!Cf&H zXMeFchDm6F;0U<+O5KIS}*OjC^;SW4i+@Vg2pS97Q-{P=k?f| z7YpLl#|aDKoL@rK($7)rHx&xWMne8^_b8v6aoKV}i!y`g>=s#5F9u&5xJ4*GP_f6{ z)Zq%MiA(NrB9qXI0|ONyM>r5iXuBXs#==~+BC@7Up9qLo*`%p_#`Gjy5qJMc8{$*c6<9KQ8ESE zF360RHbupK7JD$PR)-;;nRa9`H!G5XM)Wklm*w~QcskL`@VZWGn>VYqzo1M3+Z?RO zLFivb|8fm@W?xZBc!QFF{$=zp*T)I{%jjSB=M9Kn$1Ndq1IpsSrH&tkapY2uLbW|k z17V;d^e=C6RqZ;PxaEQzkt4L-GcZKt2o3+TZQibhBiQBuIRg5Z(Z7uTLqLWEJr zT8+Y@{#X=lc{?6D1~qbJ?2`lnQJs(kG=-wkuE%^HcnUefPwzi}fBRZE+m1Ox+XXoy zN9Zs_pKKxp+)Pt{+6M7dYJa;k%IgE_7dprZSj| zw~JgnB|!SOJPcxL*T#oQRDLF4Z3xp=m- zX0`Sgl#6GZ1JuV*A47c%^|7X^fpNC_rolK{jI*61gcI!AV?j-*kD)%+T_3Y-s8iL) zY`E5n?XN}2kwS7o7zF8q&=Av<2eC@hG;!k?m7HBDIT7?i3fxpM=8!mXC8v?_6OqJT zWN=r^m_AU(blU|vqLR~Lh-aqcSj>%a8n#n%Z1ZNd_7|k&*yaG098_{p$w4Itm7K;5 zz_+O6VE^S)?!Rn7O{nCclG9zuv23VQRdQ^&){5<~MafY?N+D3hqXCp}rb!aVGGsoZ z&>4#}*a931v4y5F?U63OxIUR<0W=f95+!&`} zJ0-_9Z&qu6K}wEo4p7NKC1(pI2ReeTAI?u>k*Q3I_eNjRqAYH2lc0euX;DmvQuOoj zKsx`dyWBat-<{0+k8(u%k_zdG)a(~gS%ANN9m!nR#%GeQ58?0m_;<-m{qrGvT>tsc zGJndrgqJ;KV)j0Z0eqJHVKg3$@1NIyZ_5ac3#w~@D^5rBUJ5&{DKTfQp@{X)J!frs zJ080B9ZfvfQ`{xQk#Q>AB%rPmv4FsR!#W{HI1oo@yC6s82pxuq9HCLy!ZvT$!Vzq9 zu(W~|0>j#OSo^MV$-}oVS4&33*a|TsN5I;5^>M=5cUb$beeFBuC7_YSOa)Frk|+%s zAs&qsbxqv_Il_TBLfZv7B1h;jMC1q!j$oU&YvBmCIY5qpegyO*U_@w*WRVrlW&$HZ zF(UMv|1EFFL;DewuR@i2Ay1q*;BgS@KASA|I7N=|*Q3<`X}KUrc7#Cpw9)y8lmT?mFEa!jcUW8j}68eO(1NtDEpon zZCTR%UY7Uycskio|5{1K2u;02I*PG0k-ka@RW6Sh#u^=kBeYx)*!46Y>0np*QdLLi zgYi^+r6qs3r7v%XswL>{r}uy9fB5*z?aLJCc6WOQhKL-Y$q_6|do>)vG6%>J(2szA z1oR^`k==_mLXjgNN66GazWvsOs6tNUNXQY-WC6hFi*cu(Jx7>-niH%MYRTfn$`V*v zqLKaAvMG~gL)lZXa#>6VIs>rjYSY(AZ}F1_UFyUBTv z6D=NveLc~_PmKGd;n%G;*acSz$%pgKX#+Os6Cx-Tx}B2aOE(Op2okOmFNh+n5VB>3 z5MzS<2z>Q|Bp!3(L=X}s(xY*p6vtYxFH2Si3e>vTfab%y5gke`k8LA&ZM7hWRphoE z;^`}L#wW9wo0VmU>Hl2G-QR1uTd(|!x3=-_wzFon_UBz8r1c!2B8Q6H7K)rp;`PIc z6+%`{Q+Ywzf4JhP$e|(!M6ebfdc(1p4k`dT`|f5mVEy5El$GN=8{L2T_f|s0W&y>x z(=Dh86**MoS}AgEH`EC!a>kIi#`f2u4obF1FWka2+ zl4HZQR&0MQN)B}s5^@ry#8E*2_48HiMsX6T5c@CFT_`z$=h8q>FLE6}@xmmcDd8jt zp&_%uU9sBU{;KU6*J9fRIiix&VTfm@VYqzo3{L+Z>>hgE2W6 zlY?1uwcenO?2B1)sNJ>F?y!AOqibywLMKFBP5?p&*Q7OwKNpoJ7!+g(>r;6H_4+h&X{vsiM+sYKcnDfs~xK z3vxsyr^67>P0878Zg!yL*yhb@?Jr2lvCRQ0IjH2Il7mW4lYgU~b9LEO%iFQesnX{JDu)aC$K9he`pmz%mW$zB*LR-*!Qc$PqdW5jjGmoQ!SWu7xAm=3r?B=hm;7DwRQnyHRfQae z^5UT^^NcSFq5L4}pnQ1#VH2^Rzx+Q_nQPDn6ae*M|`t1PuH_wlFq zD`c@Zer%4*SjX8JtqK+wqheE~;+*ow>RJ5)IRbJ7#=TX=gnZ>UrC_FA;>-Bs^2PMr-&8z}Tz zt9LT+Ec?t&VgWTDB$3ihAgbN>5-!lcybJ#_NkkfP3bA*N3IoC^_o9@gQ2W6%ND}&& zH_^}?SMO}QAV<`WIt=m5v?GhTF-}9JZFH{rV4F9qwZ9<$vTY7ll<}fZ46p#vB33ZM_E)7(K{^djYms>8#5jlcvKSbmRP5-iG-mZls zbl5w{5s)L)pawa@VkXeP>|wQPtZ{_-%U}^|ws71I@)l(k{mbZI?(Sck|tr`5h%GY63;^=XG;GhujH7YY_qx9PRTLf-E!8f*8aRR1zOJmDmmE20J|7q7lWmAhdt}{Tx_e| zVbA*JPCECV^~>9_)^Do4v7b(7#+@yrSj8-GUC&`MNCPQ&lqQ^d3@gzcg(I|GkRx)0 z4nsta&=5Rq^L8y9!8Qj=D>%1)*y+sJ7OU;pKuF8R0(!CeuDddKMM=x7C^N1*wSCG) z*>E~sVY$5$@=M{z%^Rnh_ji-YAmi}+^bgF&=0HLHK zE*oz($;VHbm`PUk_h0_q%jG>NX8H3Cyj4!sI3M0*W9NYu4;dfl6Q_QL5u3Jr``d56 zEby5@&Gj|$LGEZU6t}6CW`o2ADiwX>eUP5AoisnBu*TKlyC{t z&A1nk<;9^lAlAOyU+p`?2(?|1BdS#$hInRbmBrjFz>+=<`cJF;<6nqcBf`spXMyDT{bJKRj5`i4pLc1#NG`hFlv66>ByMXIFnwPOIqFy zv!Z~2mb*$#&@nEv|6aKfdsB#fsotb7eycnH7=bb57AXJ+@Mya- z4h8X(P&$61m{ckFvLhyf#6yqvPwzi}f4gxb%s5o9+Cz8s*7@}QFZ~Z6f4O~G>AGzs zsW^|xyc@6)8rgP1j;L037~;99Rh!L?aT@f}caM6t&70NQUyw)JHV3uQo*yjqXro#+ z+Y0sHs8&^W2cup|yl##m1~^lh6z`vP=q1fZw}7~Ai?X=AO`zGM@242`x;RJ}^$Kym zP=GEgA#e8~TW0yrW@z3)xymbsomAXZg<|VW-kT+KU%9e?hScfE%kp=dl9V^TX#)$) zv?)EPBSyW3%2hIeUY?1QK*?7bdnw_H>2yTn7-H1x8d;ogryX;IwhMAZj?iI<$PpSI zZQHyx?1Etr^d`Hcs8`z@tQcJ62*?p;Hn#p7IfAwZ=+Q=xHhQ$L&ZE7&9S(D9K(;$c0rEF5jqSJIYNUY*yin8ID%~smR3-MLX3LFs8{1u zz?Q)70LT#t@sJ}RN4PqUFt>%L81=e2`U0a~G3vG9!ySz4l8-WXMzY)xOOXmavyfE>C&`BXAGo+pfC=Uqpu-0pR@SzOX zEuHiwEy})UMtHm)WEs24ji_+b#1RpdJoeo%^*vClFzWT?$W=qc)0&ZvoZem3Yug3U zPtL3Mf^~q;GN^mgcBqDW`{uyh4nsUMwaQ{{R+e3}#;VNzq95bi&YIQQUr^L*hrNRy zZS-hsu(SNLNv(?34=2Vzu4uoySM41g3?L-5=@HYD+dIF0wYcK+UJ5&PTST_Pl6$MW z0c*Wt)axt?{B_*Ico;y0D+Iebl5#JU3TnM39KJV$&oS!tKvA!47vzW>p~Dc7BQ!nQ zma}#(9HGPBL5_eNVaX3FFuTE{jfk-YVnmLBnQ`@T!tSN#*S&Pf@|qkU;=Y9Z1Quhu-2Ri@Hj?<{dZuU6r z>4`S%ZsjkR7xnt};nC|eN&6Y+{ULko3;ER7MOWdglM+wKFoB+$q3gLmM!a@Zs>=In zIw?#iaf1ZPx<-*y3W~cbt~@_6qK43Uy>sVvr};mK4%Kx;Co4O3vKz)euWm6*=<2Ie zWVO&|8L9f}M@B(uI+={~vM+}+zn3FSqc#o!m@afW!z5s-B@~n}jr!`+sF$~6lP&Mo z>D;)Y`LO60lIHxuAt6nepHL>4hZZl zeA@?KnzD)}q30Mq$9f|y{~*wZxj>+gp5wZ`nDwf_478=?fMav+p5x{1co3iuUBMvV zjL4X}!WBZr2}6Xx=UCDP&w6$G4-M_x4CuNs{fjeXwb17d=3o58OFN~_FIGK8x!yPf zuq9Bghe<%W9_4zJ>rt++ILhASdI)M_N`Yd}r@0gkk44JdkdYwrl$S7+?DyLep#kW- zti++QeaEp~H_U%+vJA9yY4ZJRA0EL!#_EiQ(9jg3w|fvpYg{lDA4Kqv;J<2lfXQE& z{PmA-zcnlbn2d>patR}z$pTEs7vnNT3BN_5={3mdL?MxZACZ(w>arLsLL5%TpTQ;j z3LFRQzd9xa`AV%%l3|Z76Wp(VXaw~L>Jiiz6Uyah$sb1J!TA2!z%3QCK}8=GeN^V+=#-F%)f}*zgRPoFr_FTyN)8Re`(mE?o69IP9$<-H-{oUoimTb>`){D7 zyMM%H$D@@rf>TD>q0eM9X;g@2z4{|qkKSKv5c|J5-e$cMnzwWD(d z;C}r>FU^*|*0EFtmZ~t00c;6`c-uofY-fz^jBC1t?ToQiS&OKiWjkb-8)FfH z3cM6Ibu%1`=|JA-CO%~q>TsWrr;}nq4SMhbStTdak}m(Xe4bSQD*q^DKB9x=PeycD z{RFDfmUP4+EwM%oy-7ZP%7o1I+tuHH`8PDFy3dL-f4+gY%BdRX!<%gEJka7HM-@cjkXt1e*Kgc1ydy;vPjYsfMw;oA_UT9h77}&a1VCzep=_CSMYr<;@ zYuiQ8X8o8AtZw&@Sj2^{`Rxns1@) zuHG-7-v6cl;o~p2FT0s<8&|Kh#VQ<1IqJGQU|i>?9=&8q76xE}&+R?Q+Dw$ya-VBl zXqyjSTi*FW!L|k1wxB*%^DTiY5~@g8^XQvija98z1-30{S`Vyw)UM`HeNnH(am7MJ zZWwq`EL21kH-Ha<{e6P{E-P_pz~6Cf*A4n#n=Gp}KX>5&+J{H*k8z^<*yZ45mEPb&8i8xq&>I#0HY;!( zuy5ZLFeU`~5Er_3bgls0uYYI+^$6+_)FY@zP~VsV1oZ@yy!OD-|9j61`r>rSW>0g5Y{`pUOFQy;p6=#$` zPAC0R7Uee^Uj(Pq^(;SrX0QF2Z2s*bpV)qTIH9!YLt?ZJfwjEL{AHxw%ltMkgHP4& zWvw2{+?Edw^h3?v(9j>Ng*~>N7>-9-InJ}uJ*0_j+%}E9WrR=fHsV|F;tyHz_>ZZa z$`5iZ%7$Gc-3@QKW`v7T+;H8SyF0~#yz4l?$j)#K`@OURFgUtZgu?X}@B;m6TamXA^OMAdV4 z5mkRJ|D{EVCzhX8|1rVFxCP72Y+c7qOY04{0STl*$1V{~u8^3fc zRQ}c>AS7R$u=#S&u{@x#yBW~aU~N~B{H@FN7Chc~_UdQ81TdZ=7;oH%dNcPvjfEz; z;=PeoUzEkIX-jEQOovkR^YK7B|Ext1N1Irg_aEhm^x;O5o=DA7i`7H^_H{I)Axtjo zs?5$34B_wj_;<-Gc=94m`B~;q8JF;~MMagx0I=ukY#I@a>&^VRE~*2&y27ZPlM3A% z*RSE!d}a}j-$5ZG(85ZnTJ(@DYaGqzXXc8zxo$ZAYo3)7@i-J@Ihrd4=Jk3DCT~7`^;07#U&XVikV^#RGe7#uVF7%IK9TdGVGA!W zxNs4a!{*(l3EXvqaz2?ZYyfKGrk=B7ZT!2*^#33fFZ=JzH@!lkH=}X$_l||fcQ6V> zcNzU*#64m9N-!9i{|&TT|f$|+J*IPij`S^u}soj*b9tYD%jv3B{<*t`J8Su-06!TH|7`OmW{|9L|BS{B%5*<3@N z=5HPopuc$>2+?aWqrdj{s+;d*%-8=d2>31J+}C@%bBI`N>vd znSBVuXK!Sg7=U0rhg-IQyDYd>cR0tkGLgck{6byXR|-;U**qZn3N(z!3~LxyYJ14V4>VH^T0_Wk;8~uzVF@ zytom2b^YopBmrxu9IEG!S<7Ov9IxVS^Y;#qxZm`A#N4l7?p-BizG;=-g1WIr3O4tt zn~7a>umRRcx#Dz8tdW9h_o9(v3)nq0>vW*by;q&vUNOR+ez~lwa(Luzj=SUYHz4oR ztcWs;&@p0ISK~M5`I0*d>fROXe$x`Y1$LVcUS*RP5!8)UP%z8{nmSvp0#-r6DkxY5 z1!GM*iQWa)KRILr9}QJ(wIJ*Oy!o3QA@B~uO;*R=aRdm$=kARYsdn;WCcs-^cyos$ z5U>3m71*(p#{&`QX+4cM*~});Tc_1SVc$ z;w2_tE^2;5;w9EOK>*$*5ap#x1&F@)ioRc(@>ijEx!uu>ECO@ZA`d?`|Wb-oE$*$ez8aaBJRB+ z?ic6$Rmk1^t;1vPH#{9d_klq78`kJ8sJr=Cgx&MC#&8o1H<_Ds3^%#-a1(^xu+giDTfPA;a-$)2K1T366`>G_DcU%}kFO1ON}D!m1DW1SPMbAsw;MYHbc zU;tw9|67g4LEwGqz#HqFAnfiEUV?Q_4xMPZtXHxs4Q`I>Hfu>7Uh96-^EV*x6RmS{ z=%DUh!R|LL(OY1*`QX((eGx(3Smy-8Ofbv@!%Pf1WrUe5(ksn_vV2XgfM&Y+PH)vp zmbs+m-7qVPY;=F8yVB@a&HsD##nVw%R&UZ6j!}!NSIAM3mD!WLqh+HD_?O?Bql1u! z?1`3AzmzvG;d^0pVZ#55_%-klhQ5IUw=upD9hAOsN5Ox6G{LSM)@HdPALHK-Iz8K`a zOA!8sMS3d?Z$8>E*>Ktrh@%=hl%k)H2h#Z`<&VXL@{3eMvCj7u*ZE!makq(e!Tv3R z!V!tzln+_4c0Y{8bRchZ%Ne+aN;=}QxT*SM%0Eh(kLciL@$b!wpT8~8|NrLS&HiQ1 zNNS_o8&>aM(VFFxhGXC|;~YrOmw)%ZK0JDTCTTz8ygy`*eIcLvRSO)@8JO9>3{h6%k4iu{CwN^rNiUy?H`Vyd$zLhcke|B z{NQy?c8a(g8{-n;Hr6>YwG7zA2)E5CLAZU@a2pdY_03l4)%0s|#~}ei=64xHsgzmy zjEZ-4`x}krUo299h! z`%TYB%st0pn=tpTV!hwAN^e2kSmy-moGfx@%Hq~kEND?oG0uB38DyO5sK{BwX&q*| zatVNq_-^?fMHpj-Il7JQ~8==@&r! z>iTPbqD5KzF7%6tONi%^X#JJ-tFW&3oK7u5xMAL~&I!V9taG9d##}f)xkSr-*Ev~> zAJ{=$w^_@gBl6#Xyid2z$w7m`(K1ts)p1HAeZK1@ITL z;CVLr|LnbOlcPqmHoTwjUopX_b4MK1LhtH``7j=jeUEo%*X!}xvCr5+ASiX?MxX2Sy?>TUYYqiC`bETIwz-s;CUSj1mWHWRGLgL zcrhbuwf2Z<2OB>&*CezlyUk-FOtLph%{OThgdZ_T$HMUZtNEUiI*B@wU5SE&BEEpl z4!xmbmmuH!rup6+h@;L)XXqy@d)+rs=LB_5c(SD^BvB59+02oVPy_z(quyWQ4{xo` zNz#de#U;q90tmToofG9OIR=Z1(?gzroj~HKb0RDV1mZ>UqZkDTZ&+{;bxyiNL^%fl zS1A>sJN%^Xa8;M5-okPccj-WdkS@<(U>p%jf&T=b zdNCVdm(*3zP`)2A_YTb66xaKxQ91^7qs|HHoS@DL^1N@F=Z!ii2)j||ghHKL)HzWi z-v*GksAaLIue}6$w^QdN=|O?RdRkIFg!m$5Qt~-4kVr+@g$iG8WK;sPCVg29Cc2*LqAztR-{{fLkDHE6C?5xi2~$* zpA?vv^m@8$mnU6{_f=plUTBz!|X6x2h>jP*C@GQVP%dH$e0F;G`28z4$QDN0v$`A&$QyXkWH z{P;#7I4=~iYlB`&e#4RR^D)RgH(}(*b^(^7Zi;Bdfo*|$;bNB{kNl>27<7(0EU3eRIxOfvziIzD>ad{q{QdxVz9Oq2eC1dX5&B6HdbM^%IqzJ&?{Wye zk#>|I^p@(g2#gQG9ndkI7U7FZvH4@*xj1L|PLo=tU0}DMUW+uUNN>TiKv)(i&iT)I zny9p~@@vd=BXk`oBBV*{NsB{b#pcS5BG-Q~X>}cXRr<4h@y2&!_K@6ZC7e}SMEuB& z-DhH2aju&Am*4ZP11RV|TQQ-JBCkJu{rBL}Tm1Un(pmlTY7e~Uh5K>x@sAJg@}F-jwq zfK8fODi-Z*%9q~IpdAa>^Ycd7+Tr^nVE^CTxk{}VOcS*`Nq@jJ(Hl+^<$xV^T{=g5 z8KABUL<;hjpLnEcmK_7WiA>^K3lD^7@82vfFCr2WYGI|JYJrP#|GIeJZm7&=kc^BP z0PT&mqXe?IUe_h*Q~_KGZi_AWCZ-p>n31(wd&IPZjUSt9657O%U5~jO3Jw${Y9B}w zn*144zlCE)u@$>f?ApwYB3+euXg+=OSN+=$zuf=y?dSVOM(r5PE;c}(mz_ZDefb;~ z#s~>8NPs~C%uN$uhVll1u65G|Cw%P2uf6!ujS9y?;A}k73!O-ZvnRHEn?yYtTIkVp zF!U|2$A6zMMesX6q5qTqEBQ@&R%cLBTe0WU6Eyi3d($d_;6xBY6ywWp+RNjUp)ZJ~ zySA;b7EiiEo^{%uRq7i(2T)fjFCYu%q%0U!m+vI0=We}R zWS)C_VgDr%dbQ2}*%090L6lSozJjgeTPqT+Et^FQ-~Iae4onUC8Nrj8+UoQPd}GcQ zQx=17y5IpATW&zz0;uaE8iz1!sOutj3BvN5hUKX1LL-C>Rx{Rz<$2`#1sBf&%$1@G zh|Eul%$0qfp$X3lS0+Uz)TYb(Kl6884x2a73Iyk82Imco*)ixm|9Tl(cfo6p@La^A z2+xt1p4r54bT1yIRupYk#L>gRBX>Vp_7gL{??U(&3H2x951?eALkwp=l=cdkR{wbM zNl4E{aAy`j{V@#wAT}dqgPXJX`DYS7yEcK#p220yp2HjPGqE52zzZI>NqWhF3~&9J zgrT(z!W9^u>{MP^zV)!Pa%_&5j_@4e`C*iF8+BdIRYp`)*pRjlt(?^&-gh}<-bgzT zo7cqVO>xm18MR~3IqJF~tp#Z<=s&+{|2gWqp!Xci%Dpp2QP(B9kD88qCs5lVksZ2g zN|C1)KV<+{Yh08gbn(8+A@oMtQG(Fht?P1j(s@(xypbV02A+!zkgd`#xX)47MH*G~ zpQHaA{pXxm4yQj)6BPqZSX2}_E{~a{4}*VvCuO`&iW@1>9d%tgtLu^gOKDqZAVrkI zuDm|Sfkp#@b!ljnB=jc1dIN)YEL_hwfp17Dy$b<*mbt{k>sZzXbzRbIHEFegA@n|o z;`fkVm(Vqow2p6Ifi3CU?;Iy2QS^NnY}WMPFFxyo|Llf=zk7p>kZm7&=khG)H z9W=j@Zj002TWg>MMzL;4OhU?(zt1z|8)-)gWN*E$OVX)Aa$+}iU6ixu7|bqC8+l%K z0y6SAq29J=5iYG?QZAvETvv0M^~=cwzFUjYf=Z52YV z*0?A~=;D2sL+FjPqXeP1Ti506r1PfWc_Tx13_KSbAnfO0Mt6dAK0(&G!0(W_WmjqZ!+d=~=q7-)J^*IhS8W5~YL(?){ z7v=Oh7Ov;#4FdMer+|c)!Dw`UJ7sN<@N&b17Y^7_*QH~A^+n%6T^H1KIYQSZok21( zY5=s00v)>`dr3P=AbZPoU9vADI1+{6B6t;3@J&oFcrhbuwf2Z<2OB>&p@h5*nZ~Zi z0)w(9T6QBy?9(fu*n9*|nWj=l8yU4@FuT|Qd0uwH#f~0!VPT+$9X;&mVb6QmQP-tw zx-RDd>MG?0%pN^y_Nc1M6DM0m@zLB(2jb!e@cHqLKyY4@p57EVKYqxLLFT!)cM+DO zu8SBQLRgNl9ASALmSf^5ARF|cAHYmkiY_2BKPfU-_W4d|p1akP<9I|iMjt_$kApsow*x}dI09-naMI%bSsXU6DxXe}$U z3c^?J)Iz`cN&V*48W&CJx|AT}26!!E`w#Ttmmu^u>$+q;DsXF0OFC}~o;NaN$G~&3 z0eq)P&MMS(L0$9>>Y}gLo@-k%q@7UNyj1}Dc|iz5d(vtFx6}I|ir+&53klhki>Klx z-@f|R%C+A)4)|}Q@55lTrq>oP{NO*kVc@T5-7twm^UIG*QWGhA7>1L8mcx<5xuKw0t{XR~js0=5Y_5NJm|l zj_SH(z*5>48iMM1eGUZcIqyi*8KO;s^#%s*Sh${V0^g7ju*abE0cSZDGD5(Pfc=gZ z@g|}EMErqHEQc7*d?;-eV6Xh+#ZOF?1+j{s{ul;-5Sv*aE0rnpnS{@-P2jR;fQiiH z`6;U%{xh*3{lE(zw%*HZhu3~4VQ4Lba0NyQ15qo>w;sTPsdV6QFrEkOsO!=>R{8*S zT~OEMC|wsegQV@O2?mTP(6Jk`E89`xUvIsxOY&tZcj#{Dx+q8O7|bqC8+l%$u8T0I z0F)qKxs!Zl6k@z#Ax6}7>0bIMJ1BqCe&;6|gvLaBF7ume@$339e!5C|0a-97Wx=Sr zJoPS?Q($s89f*q?aH=2Q2n6SaNc3q%7mpvZV~~07?R*pKkRu&+U9tm+yB?7SA$AG! z(r=oVj)|kNGoS|@bzQuONE>4d>yB0lU6e!f{9TvB<_)w0!TFiNc>`m13_8!h9^rWk zVNurwbzM>u72_nGjFX_Q%NHRci17RXcy6yZ{K!Oq`APldqQVC6^>mXi$K~REmqX@_ zv;(nuO>Ev27rl{DI|iMjt_$kAU>YI%&u`j)K1cpJ!t(>*IqJGZ_mLmnTWd&8iDKP2 zDMGK-xF|>H;(eDx=#8|a1fjQE*X8V_^QPc=BSUr!JQo`vTcw>KolmfusNg7rNH)@2 zq$n;;3N|gz!^Geyx)CLxoc|nkUDBu_a$KnB(Mx37Ua)aqtk{0cgf|)d8)ylFb?F>WQ%gaD&0Lev4IC=<(Ii-JV9<_*>-i?|4Ji#H zAz(*c7u0n@T^H1KNq0h*>0Qd(WE>JJHdk&Gfjp<_Sg{4igqHp+U%UYwPx^6Qc1BPQ z)*|9ZZtOl2(~9HJU2I}P&z=T9e~SGdns%<>z_>knW5J$UpMzkauLR=>R31Mhj^ zew=*#5)I7Y=CchJ^uT=Ve&iQi2jrQEBQ^j95X1HKA%}V+c#}X7JT_ldwF~^ zbkO_MUE9_{*Heee0y=HaYHeAOzUZF=sH>D0kf(l97L2OPQ}1FqM9F^VR`7^Lwx@}ilck+6t!-V_=37F6l*hB%~&7603+em*D^W>FjtB$ATk&C z6k1#%T3a^Jqs@99gt5K}A84I6ZlqCQEkuc6IwmOFA(0)r>#Uj_1xw04-wDn0cU=yf zH_!?M=Vu1z4UE|_=sf>=gy+dR2gezfFB;w74p>88`VD){5uU@Yhw%IWO1h1@F6YV` z6%{sQpi=HK7w@|qGH;|Eh|Oza^QO4yjf~nc=p1!jP}ha${@k!P6#@DU19a4NL3n;h z#whB#bWztu$sBHgcP?sl9B3(&AoO!aLv{>27aJg3rJW$1 zqpl0mTXq(MM|gh2@Emnr(x@S#^g~d36bGU8K=|Q_^p=y-TPS3y(zYmfrOS672$36t z>iO?*U`r6Ji_j)ZEp3agi_+3N7Ov;#4c~K8dKUurEOUvUXjs;!lVxoXup?kM2B??b zIoitzbzM-`Maw7uiNYAWp)#96GBRoav^Ua@63E_qU6-U&&*)-rDs{AxQ9A~+iw%(H zWhW3j>beLE0~1IwffN%+=Z^#l0nD&+-qubmo*n5SAk>M_8VR<(N1M$OeJ=0l-`-x`4?1q{v*^ z=R2W!{;tbm^9EXh;QY+syn!)02A$_$kMKO@v!JfaV1&9ZbTVj2Z0aPjDd#mucuwbe z*JKyZL2$8A*QIN^E~jF(?5hx>YzJcVn%KOl#L-4Z?HF{9x-O{eg1Rou95X=<8p;@8 z=D}@Ll+6Kj)OA64en`eB>bi7M*F}kp8{nOb8XX7v@JkSSyLDZX9u>H?-PCnaPMu@m zxj1LK=sq8!t_#vzP}e1J+@(vLZ(eC3H8jY!1w)}fP}e1m8X`(R1f`>{3$1|WpUaUh ztFy?UrJQ{(-+3TJZV0O9^*Ih~34(PI+O$pAt*;hOxKl5$&;Bsp z)V*?0`^sUhD+kbodT*y!)_Xg>vhwZF6E(lPaAoD&g)8g5edl-Q&)oUlg)4Wyojz{& zxYK9yD|dc(er3J4)5|Nzoxh!4S?}%i%Ide<>$>Bfzq0!6`77(aefM|Ip1J$G=dT=! zdx;!mc?rTN*MBe_mu|*%N6BqH!o^xd{K$>nXJQH)=9l039sf!HmHZ~XJKKrr`2m|B zye0itkL`B)D)3#9*@Z^H2~c;(F@z%^JDFCN4{E&*-+i_0aAKvsy`H^8sKK#9N1S!?36?l~ z&>pG1FvWovb`U@z&DQD|N$7{-L*F5e39~Q;JmuQ7>GBvSknR*ic1&2eYTobdBl_UM zVs+UgK6nU+m!%2Tjg0IxjEw2yDN-kM*N&<*HZLh%A|+M=@voki#@$~%jO;sV)5 zelz5jY~k|O7Kg-&&6OKP4AD|I1qGYQ&+^3^K%MM#;OJGFh2?lR-#YLFxX%VoP7M_gS-6a+qXg!G>5F|VddK{^E-%J@nJq925`7P zq{q^$GM`D0|2}_0cN4pR3qucX81jj%g7EcU5f}wO67aP6F&6XK=V0H2571}%`BHR7 zRY3WA!;m3w&k9#&W`l|7tnxt@2Ky&!TM7CV%1&Q8J&1mu58ql*@Tgw3Es;3$tUJ?o|vGcY|X!AdD&ascJ_m}eWZ6iH}8K-G`k z7^0_-?lx?jUYt1JQ zDTby6NK+Y_PThDW@vVgiQIGpKOUsK$-a3UBB>22(mtURpyuvc5?EQ4cCbz2%0@eK& zwgZ}N62gCJ8mEDS6O{jB@W0v7I|lWuS|Y(g1p5j6gB>rwm$Lm7rL#IIorPfkhHC<% z7Q=yAUe^&17zmgdxjYH}%}{U>tG@`yuNT*^fcaINhAMcUzppl|AIK=_*rYE844Y|6 z37kKRM8n~({DBzx=`@$8Fnf-{@cBt2&&rlN>g%m}?y5&Fk7%c&ryf1^$mKyUkAUGi z?5ICIcCQx&=U#gB*iWd8erVZG(b|IKvS_nj2Vtxq>9Maj44Kh#axPB+t~CPoE5GF7 zhDZteZ$FpktOkG(_yQbtIGO)M!+4BEP}!s_GZE_SB-}tiE{`<2Xd$45fEGgDLO}OE zy7wWVo9aj$kg8i5GDpi`SITak^Sr{zU)lRL3p3) z49jCsziJ*ya1gmX$mL-k8!L)7w^3ySxje|_;r?;V?d=qCe~4V3axJ+_687uG^($b0 z6{n$bF3(U#NsYkz{8y-LVHBED0_R)K<=G(v)+t?{!jK(<;q#M5o|VYuLGX^?J;icZ zwcPGx>P0T=7Ik^LtjlwH>|QSljvo6Hd+h5CLk-t`<%14K*o}bw6Sb`b{kNaXb5;YO zZCsv4ErQCKb!8?(o!B38d9*=)FfjUqi8Q*%Gzy ziT&sYUhwc*yzl3%#@?s2u3uI?NkFr*=mUa%p?kUt_E|MD_PGt-5D;Aa>$U&lL9RI*YA=w z#$ENO%Omy-dg{?rkDmHGct(S+5 z(?~{1jkx#oQ>V6tQ4ne@f%7fr@|;y-eh5HYH}sW9-t>(%Prv znP7z>JH~ULpEPodTkfc@x8{+{gITw9;i0DuzS5IID&a`tLbu$t&i?7@^p&Jb9(oFWyl;YgA-c@mA#)V>Pm9I>i)yAb|X&zW}8&v{73j7 z_-5irj=*o$9QyBFh}}__hwXRTB@5=(iNIGt`Mt;pRrPZ#A5`0iUw~_k z`0!8Ewi5K;erNt!4S?pH`6n92V=RKoCJBBZ@R+sSM5wcqaI*h!((g-I8bWf$yJr$w z59r>H?r)j?7Dmun(nzOxyB2a_z)@fc^>Cr-Qq@6)lDgZ^X=pENM9r8_$b!Sx%L`c(sz{%j$<%aoU_IBmcai7G8(moQV!1k?hqRMCS4orS3vq~is0k;~IDE{}L@o*cW^ zi-IGV-v#FDMBrP^z~zy?yo6(pu?Q+>mOPhR zZX(p#Nw|T4Tpnq3(LyMC5@;|7Ergp2=;V|;QFgy;(w*WtdU6w?GGvaH!HF${%HB_6 zc8%)th?7e?U7JbZRedFd{{r<9U`(_A|K{L-v!izm>Q}Wyp0Eh^k;^l

k_AGtip z<>@Au=ky|+%Gf%B{9PcwUR=K-0HEym8t^`UUu_Is&_r*+%Rj zVPWa&=E|^py*1BW^~mKB13u`fM^Am|-vdy)={)P4ryjXHUFPzf9=q3zf+LvU z1?KBS;47efy4aAM1#viEBk1giTlYzH*kB!vH>k2E6z zwMCcbba4RHJd)rbig2P#Kg#r{)DBGT?YvAsg8fc|eXOz7Qt{1tas7$_KozGUxeZEK zGQHYQ-~3ho_QNmtKT(a=`}}>iVSPaz@p4?ALQ_iMe9Lut&ML8gVJ=T$$d2*c=jZR0 zVfT7#p1bOi%Ol#U=&46fJ$mZ%o_gf+beYR@dhA{=3XUH86MO9I4MPpredU8L4E9gd zwi5K;elE{h4S=?Bc^b6{DreS}nFz?`fod|+m;vtpn-#^GCMT`tGw2TnMt?9VUYT9> z%`3eQ+!Qy@{l-*XOw~=}Ik1wr`G7UHdhw$hNjr$P3Y?8cdPzMi@KeQ>Zi7kW5-mhU0sP4b89nfr(5dMok(pGbM8b$r8c~scU2^4g+ z&HveukitQ+q$3=LG(r}wEt`eO-u?Rd?t=$F(`6wB`B}k}nU?XUPvU!hwg@wz=|}h0 zS|{)r-DqNS;L!ji?n@(r;Q$N=WUDTY?#0D+J5|+kslCYM=`5Fr7SzQWTgc@(lFP%U zk#vqWBe$8SWz@1Tluapt^DXA`Bws^-gQwNlydalHIb_J?;m)-;Z-koh08lx4M=pva&udYuS-1uehc zFl1gs&k9$jnx|j+pu-V%BgFj^wXFpGx0}mzb_1YIT%N`)g36gC8?Gq3kFxtHyPuvV zScSLiRd~_8kM4aSaJ{ZsxSG`-@Pdu=V#W4j#^z$kl%JCi7kW5 z-mhU0sP4b89nfr(5dMok($;c$8b|%AdBiudbZH>iN3f4zAHja+u)CwKI}++o#2*0P z&LM^~mkEXtW%|d9PeKZTfK4rJDe&o!VekjBWBNJps*9h0CgHPd6S(Zzb&}`&lr`XI zVn6zU7d*Tc@B5jAp|uRc6{Mpuw6?N*>w!3VzPKU)gj}9vey6kCp``on)!3rP=jlZ_ z^MnjOK@sHd0{QhcIw}GH%6?BLbfdaFY#Q;A&E63DbTiBH-fV6lma&pqlkOX!6%`6L zmB9Iyb9v4xv43GMPhrTA%ac2QkjsNvw*V0jgmRd5d&60`$mQuWm*@1@y zd9r^m4v7_;D>sTjD8{4?au&NtewHuZfT9e0NG?51NKVrt;zw@mJ`>Z*=T?eB34k-* zXDeoL4D$NJ*MAQly~VHJEuGabulB%uUbr78AOHB^F8}%VtmW z!by+M(~EE_IVI@+-{tKtD7g6~d3*`1Q&K^v{Fc>qWs4%va83ABsMPE32KxRiLnH^{$ z+^~g!x;&lMN zvQ}%4n0B!7V-wuNHg$1$jJ8-HVYZpeQ-sME8}JlJGA=*smAYub}K#aT==Neg3{(7%c`=AeS=iQI`j?`!Pwk^`hYDu|KiLzTPk-JEB&F?JFO2VX%Lq zww0j&)^d4rp!kdiKufqhxi8OZ^BYM(jqhYg4rJ?wN$3 z(k*uZa(PChdn<}IE8^&3;E_A7f!@W$P2}<*mnXHRz}L-7^kx;7P?v{y4*cUfQgyfI z=*i3QR));cGB~kiP}%!63`Z`%d_3BWF&e_96&XXqWs4%Q~Jp2@bYB9)MsUxjcU0 z1rM*%#6>R8U|=AZr&eJG)a4QIy94Ebd)7;2+FmUDT|DzSfIE>B_hAeSe1{`@XkW877bTpqD! z&{L0|`p~}zpmvYCJRa)u&^@%vT%OZo_j*xq1oOMVd>yA;1(dHh3^lNQ<%2E^_D|Hd z67=7GF3(vFfVOdY8np;2XO`q8MfW~Pa{#*onH{LhgIpfVMlKI>d2+s(Yt!X9y@^m6 zGDpkc#Fjy2@7FL0RQF%l4rsPX2>(SNX;z%e4SZUS%MBa~^_qkK&5qtNaR60I5bUD} z=WRQOk+^@uslBMn)7f|cCG;347vankGWc1FAb%IgzaB0Rn?`(OGXo;@0VDF7C$<-C zoEIy$AMdTTPOK=_4Y3DUDC7RqH-FW?{qW2EPsDMf`~1|YWnn0rQUd2&%;ibGhM+le z+IqPc=+E6pEUBUY`Lapy)}02v8 zy+)#kU3LHASi2EBpxGvsIR6p;w~foAG%Sxn{i=B+!9gVMBXNH+z=FE$pg<8$B<`C? z+)qGL3Y}Jgv++nTq-+Eo4x`xeZ4&hys_jGmj7jKQUXTA?%b69w^MC&*{a5mvG>)Gs z;HD*eSvW8Mu2tZ>aS*!x!kI0LjllY5no@Z6)Zx{m%Te8UStM@-%7@RL-m`GZE_SB-}tiE{`<2Xd$45fEGgDLcmnrPN(Xg z-bAPjnWJTJV#}bi_iGpgs{1c&2Q=Fxg#V(Cw6(fCG$Pq3>Q~Jp2@WEc2e~}RP8+#AoPtAFMas0f7B0`}ML3nQbp-jlKz_ZrenkL4+3z*reg3}Mu)d&)emO2r zp(!PBzU5q=vr6n=n9EZbGUW240E_;GHMaf+I$oaw$6dOFRu0lomj`uu(gmVr^WvLV z+9z=AV2!PiM2`X1*kUuJ%Uqt*WA}Pda0K(azi*k7yMg6LIgkT@RK7xG& z`=fj7W=beOZo>gc-0vK5-(L3(s>?(Fz#3a|9J-55Oo}DqHOr=$Co+j|Ej$)RURqv6 zBy^NG&(mwcBl1Pyb^*JK2N?aRtin`LmcRX69$^~EDCxXhp30__!1)$(dBm?FOry@# z*b=|1w4{*BletsjZ{+eImj_OfpGg>6%OG3*w+a^X?>IzmjoL8DFSuTM7DaCznV3CTBDNgk=P$Disj+9pac^ zhQ@9byEbLY%Hy6WGK*CkPBe_iSOk?#lD|{S%kb9ONl=#u+5TuDWEM192vrsWy7$q& z58@23YqnunFOg|`!Nz&9V*Ald&qC(l=I5lA(Zmy#|H_a#a(TMO93kl z2><0hJf-9i(+ghA$XcyEV%ovRk4->-Ht}QEV-c+aW^Wspr*c9agZfqTh;L#EI6z$< z)a5~4o)jo!jV-LPg}OX~&+Q6ydGg2S=|wp6IxqYzMUcM>`CVYXP6WQ)x;&L|tr4(aIoBFT|Ly1UoYeqm8<(eG#2sT1 zRL-m`GZE_SB-}v28e7unqJ@AK0$K=p3jw)2Xd)n&=W;2#b}eI1`f?(Zw~%9J9@{UepO2(IEY*x|dD6Q+%#P)G?@EHIF1Xh+H1z@*tN7xja8v_EWURg1T5xS2`@)Ur;y8v7{v`vBp+Q zW%=vH^($b06{n#J-skVDg`wFrl2KA4u)dk5l)(8Gb9s^;6&wz7jJ{co%?omQl(Xj; z44F`foRv z=j;YRo47p6DRzuSP&u=%%tWXY`$H}d*4V-tTd9?URe0aXz9Z!F2(C3W5s=G+TplRO zGjAUp0>q>=U^QXtF0LGySh{Bm(FC-Fof0 zHro(rdF55$yKxY@{)6-Yxb%Gx#qXi48wuH!i>Klx-@bw_m}|dtoRCD(_hGPE(`$PgRBX^y44r6NX=*9v-kFeq%1COp06yfZw2q!&0Pp{LjjIE>lUp!30 zj2Wm$oAo*fWBt0gJOxekMqqt@>ePnwg{G9i`Id8e&ML8gVJ=T$$d2*c=O>MX?%K}7 zueav8s~&ZEL^~C;ZZYc?&9%Iz9=SYScGRC9yVr|?BbeU>=Icb@D`@%khT$x_Jj`a4 zVO1kwzw%2qj{e)v6%OG3f(E8uq-T2`yd#$fvHLMexAmgn2!jAeRS>HdJCd zoV|s*JP8g;(U4=sRu9y`M>{@{ww(n{pojlBy08~v7by3P1<-dRYv>r`~UgR|M|-e z{nxvL4ovuny?6%O|U` zcKO~y2fmoHRnzGnUodoXyR`B<4)%GPxa+H)w`(Y2da%i%!8RXkLO46%DPP#6;d2b? zII_7*4;6m?@G(%FRNIR{>yq6n99@_6x$xOY4_nQuEP2Ql92~#UBid{{fYPk zomdVroVgIW6S&o|efg0ayU)ZFItR}FgrgB!&mpe25EyTRR~6+OCk5U%gCcl@UP zzJ1O1@!903UpD(r^xs+pXlP~S_Wb%YDH%hZzm7f+o(PS82(1-gZ^^IOM+<1KbUED6 z>)pZsNw-FK8^~?D%T}%K!I!?Hf6xP>2Y2(~q7P(vF8BQZ*^rP5!TKA|%Q`gqnC=4r z_u#Yqx2KCeejA1%m29}R}aY-mr&bYi@LFFPoFS?FlpcE~zu zn9(=-!|@cfCx;V*f;#xm5Jy2+XwacALHGnR!lvWWNleEgH)z7eCs~#HR>>IFP4y`3 zIi|wm%GUhK@&N=nd|rzuh!<>}7b~_O%~Y#`u}!uYXFCDy_4hyiE0@{1y(ZfRpf~v$ zQ)5ej6HI9EA-e&`CTyt)Tc@~?G|Rriyxe!6zrQc(^>p7z$U)gCefs9F`nMl`xi8*# z-{?f+W1qDmq(GhPTibkA-CJuo{9t=D#CQj5_Wh-rdtu-IyGDn%Mc}xni&2)!= zrhbtR?sRX=mRa?Z++XzPeIfZhc*-|N7)m(70Qn|5@_tmdz=|5cd&LZlSziEJ@KRwc z-+>WMO=}6opqBq=bdOs8Fk7&C1G!ULfZ~dQp8Cg&pIB3X>ZSDrpZ*vIe-N9Mq5y2CY3qZv^9gfXg}p_ihNlU<4LA}qWRxArXo}cqiX^@!X(4HGNUYdg zxlzR80W{7^adh&teDMbA57LkG!3E(=D~}fB_j~Y=yU)OAp^qZ3KYac7;L%(B`rXo5 z{qkxLyyu1caq{tx5AO1xZ{G?{fKr5O>Q(c>WwnhK^I6_0Q>0FG2rZB}bQhbLO$Kq( z!(c~cq;w10>dZ4?5yIJfIm6?S)?T^2QR^!UP(av{yJlw8>W=(r108_Y1zH!-14xyp zo$zzUP67)mVN0d#h{`<#t&4<#cSE5q40L3c1^xRVv81yHIu50ap(TNqL>X=B&^dK_ ztD&iuwbVj5`0G`kXCW<#ICUk7vWFF|>#5cgy8y zGIbV?Jtw1~MdPYVrCNp>CUWu zi^-6X>2f*j5Bjvx^mz+-Biub38T09IYT5L6_HY8f7!Rh?!E`a2v)>WurAePyeKMIX z?B#@BN627qFJ|+BWi7~Z%KC~dm*f7>nmK)AVc6D0L}#+M{*t*_bXO5_v)~)aGf`OB z)%y)i(9M>9anH$bVcSm++;*DCq!Q@<)fu`gmj#~G}tgG%6y$o6(xsF64+n5(`rzDCC8J`iHgfAZK^&Las}&E_r+Y zGRTizxqkLURa?m-G8bL|8X%C{3EXaY=oi7L6;ou>COgC<&>?|u?tBBi1K0%g*=BYI z-oejzkyA{6g-d~Q5WcQs$RWIc6NekAZ`sq_U`@NePd$p+F&s>n&fJ*ViSh$|#r8if@~w6B7{uw@=#Q|m z!wyPsTw2E5SPUo9grc`I3K4t-F_NAsh|3%VdCvrWEC zo|iuL+gIp)*M67GT$Tz34bXPo_Q8L4!@yrrQx`6Wfm3`P_(FeA)5^e|phy{}n;i>; z4{Uv7#p*}!+=N|i%B3klVzT;SD;SBD3%S?HOwt@3Qs^O%2=v{SuJJtXujb3IFJtk5 zpj{;$67*LZNR}b;(((ECn%PZ_Wze_tQOz32KE0WkBNNlbl{RvKShvn2|ZIPZq zuVeZN45_Pk>_=Ei$>=Fw#6HZD@XZI93UB~0Lb&2$*IMy|*n|@nz5yFJ<+^~2^)T=V z%c=Llpa2XYO_Wp|qQ*IuooVST+~*FadIa4EX?MYTUD!crRG(>1nQ6+M>U;A`(wSn$on02j+$M#W_yCzPsW?Ki0{$dv^x zEIWXWf=VaAcDJ;sQo>%-8&WbYI@k7l_hTHdO`zPZ186*bcecXB>C83-b}j5iRJUsl zOO}|A!P@j-k<&YcH1%Xx(AXVu0Qw;GTPRjc_ATLLp3Q= zh@5Q*djr`Bj%DAm!dF05jMENwIAf;E=m9R=gw*n8NKJi7vL8AG4h|-O3HwXY*3_cS z0?wxNG)jH|_ugV`FXonE7#8^83f)m=+10V?wAvP(w!bx})v)A_wBoked4r+qV-r-o$Yi8`$n)AZ#n}jRiA_l9 z7}P-Ts1If$$V(CMv|7XAa4E}OfR#zF0te^_WF;p~-&rjC!@h{c61lcyClb1(JY9r0 zC9~O*XQX#$+j=qcyI}`r7R=zsvzA!^fI6A*7hI`JvCOCt#kK@BkkUY_k%kye0BQ;gi}CKG;zSyj;7?lJnI10 zPn;i`%B!iujC2Acg z>K1Vlj<`JHC!^N+LHrHm^4pKpr7gX+gL(UT^2l*TN0PqEY>Ng>%H}}yXV4JcMDJ-) zl<$DV0ji=I1mPo%fLc`7EsB5A;4WC5;C>M-L-_z#mKvu3sm36r)}dOExcV7q!rJ9u zqD})4cPH?U`eXzv5?lg@;_l-{ZC3J^F9{_T zT<6@)B|QMK2rTkZ3onUJ%aFa zfbja`(JTa4PhhU&(rVxN1q%(C>0Gv{<%wb>4qf}sBfxwAh%TK>qH-`}e=TV**d&AZV8^mRHDnzA3f~)Zdi` z6;>8>~G8y=E_dhw$hNjpha)2<%GmzEsJvur%l zqxWuQU6Rs!d2JSU0i10tox0-v@-wo;g&sZIQZ|1c18fsN&XvZ|9Os4|*Dg)yj?mb+ zkD4yCTWxHp`n{gbk-PJprpKPIMGGV|h|mJLmv@>v^Y&;%BsXCT8$JOoY}@>wO(Hi@ zP<)~(aM2p%38>B2QhVgK+4qP}YoXH)MH+C#YmGSf>;ZqX5C2JU8R)}Pf`U+nUo_@3W#CS*>|U)n?D&mP}irGt7-**H-KcwJSfgUA_uSci*0wi!rVJ%v_9V zu@mxyDfA*%QFFw0<=5nno@QfOQh9JCD@|P(KA#N4&pTf0B%gY;{S+L_&yctj(nBZv zca35vP2}7Q2VivthkT*txkK#X&@k+|Gg>$^{#DqdfojgIdM5qr9vXQM-@2?gFPIoC zRf-jAmU_MLR4mk-^zZghNIJ(t&Cng{Le10Z)EOFMyFW1|qv>caO(@!pWuT6I_HMm~ zdf-`gZB3;%%B~YdNh@k&v8zk;Nq5~=L#>oO{_ph)H5<25sChPD^cTws)Ru?%jxisp zCP7-e4huE&67jMfhlQGRg_?JqQ`wo8dafwTz3v^<{$!MQEYysJn)y5e4^2{VIu+2q zNTKGD;Y`Q&%(4c~%$hp#VR~hSnuoeEm|&r1iWt~`qF+?r{kIiasfm&nY998W3#HRk zTeqfAbFtnl{i3N#6E8o12dYhX5nu!9i?C~<#6|eJj)4oSDj&-(aRXMQ7Tg7*Jb{zs)sIQ&`umGRx{fXuDZD%x}PDlOucrGtJ)@LG+#X8M3v~Cwq zg{3c5nW(VLE?lR%#E8Q>&BDH;-Cmt$$==w*f0+pp@kPOXmw9EP?6BkR$~|3|*;|B$ zWq23sG;5h+h|Dz5ggVXAD2o}o|H;OP9t?2o-f*2}sh@;N*L;pS)@fz|0Ot8WpV(DN zucwng(a6f!g`d9ptN!hWU+!uB2=P8fVw0u|-wCs4iNTF6r?D)?!CroU+)GQCY-h_( zDNv8(P7+RBdGBeK3wOdg&GNUB_E0#XuugNqIY2@;peAyW8ZOXj)U2(t01Vcoz?u}k z8wX*r2rqycG2*5Q%#~SY(r#YQAE99xKgRBX>Vp_7fZKyAb|GLj8&O1D#k7F`T&~h4>#YenRJ55KEdC z0Hl5lgFlGPQdyMH^)m^dU7NsVoEFL(@H4R={lE(zUW?B?5TJD^pSxd(NJDp{T$kj= z;2GNh$s0xFD;Kiy{0C`fYN~`R!9}D+w9ZrPJ`>Z5K{9)>i3y7W2)+ggHn`6zKZ?Bm z@b%w=M{n`#cS~pW%d0)`o)_-N$;UrFxXXXOeJeBpg8pmbLuCltO&*&A$uK`Ck-Nvz zlP%99P1caey{B7XT&k^lXc(vo2D_1;+|>+rJEpb7OyXM$kC8f-mKTxy{V*F6G;Af; z!UB;KKsl>@FW+{}gL@AsE)Br}Ks;BNcZc6o;`1Nk@-9NJ`maY2ehv^`e>|Fn;OdEt z0K5iwrR|xf2*++M(-cR%)`;hP;t0SIfU_z=4Eu4rh10HR$|$RAgms$tLfmz94@=>8 zvBP)bYko@|CuReHdaw7DAn20_A?1u-+G$0>o9g6YddE(-iD(OSt4#HSJ-q=v} zdy1A4D@8?Kmq)A)plizX$ThgmYtaHpMw4xZnaqafKd(sNH`X$D1a{126u+*S7Q~-R zxspA6ytd*;fEC(Zb=FU_%=>|~*;4)?#8n+Ls?tqNa#-`EutVnU(S}HF!gkRf*+KQ` zIQt&aX)ScxA*v6Kc&!o7MH-krBJJRu3X}=*E7i8Om{vhDQ+iLPi>x8t$G5y3_g?B- zG(|E5!^l-$uyJ0j*nZ5WT1CL4P*N35kX){FXBz`@P;*g6U6^o^TyL@x8jQ z3N9CvYf^7_MknKoHl0DTGh8q@8Yy!ty^+2*t*z7UI?cNby`%$k!I{KL++F@ByD@ib zF^xqUhvXh2r#4)tc_F{R4vFK& zX0#@@yWAG&EtooxWLlG+H}JhX$#)H%-5o{W}DeK54g`e-tl=!=On)W=gY7|!}rXX+G{ zFX3g8Z>^)pAWkcr(I54Ge>xpI3#&i09r*V`t|!h~nby86_ANYA&ZSk<^kUBtW#cRA zdaMZ>(4cLBv>E2egs!<+;}AuJ7~XR(902ZS})eFdQrQAq1I47UOjE2*gN1 z@U-7wy2kUkznU+PfW{kppsXlkVmCEIeFzG z>@SZ`h7R(>I;?daWQKJ(u5>Tf{lFpYXSi5eTiVKUeaPrzow3)Xwl*==Yvv;fKGe(C zYn~X^Y&@7-OEMjjd11f5u6oU*zCJMKSg)BL5$wO}vrAR4dDQPg7s@OCM(Z`V0SP0Z zy$wJ+UySBZws|%&$Z}*%Y5>}Lb({CZvk|canjrRSZg+>G#yYjoh`kAcBw;=PdS}(m z3x;(RY(l_G4%j57{YdO5fWF0g>squ~_=H<}><7I+CeFYDOL4jY^U)d7t&JxyS`ADj5^Q2RmlW`J1NLKQ z-!z43v4_httM94Hco)-niJJvX>} zw4z7X4#M?a_7~!(os|U2e|dVHP@1`5KnjnP*VyfrW|sR&m~=3ZY%^`Hs+?Htmro$% ztL@^e9hH+(((825z_KYT3DKSFdE%s9XQyeVCBCYkp@dMrx@aNO0~Ijcx!~7%cN`$M1O{pV-vln zZlCWg7YeDFA5#dz7cc_qU4XjzdT@n7$T0DNrI~jDt_HHd%V$y@u#dR=997}6X;o)L zj=|vNbAj(F>4cUuRAdJY&3eGn%)T23VUdx50FBe7urzbBpy;1v@epb4!G#FP-)N^S z#+`%Yf&(489uv45OyKS;7?;YaA{0MA6qkk|#VzHI?jrWt*5bVg46pxs1mWiZ;q}L( zSqQG4$OynYkX(v|dTYt&cPP0ON4(aEBLLr;g{Q3B))4^CN*Q5k=IbfVdVZ11{wmwKrWDjqWCOX3jBK zpHETA!nm7?Yb1 zK^)zS?h$0Wz&3PkY!@trwlA{B(##y>w_G|#+{x6L6+On;$r2ZO`D}kmF3r3HE6Z{`Hm{g>51CxVielXmzby+X-0!NayX&=Rf#fzrEX^D}nYo?j zEQUz#eO zIGF-x;}Leris!?0-xMiSQAHC(1m#5&gia<<-f*fD%M*SOXlmG@%LL_UW*#J|-xqp3 zfvXjnv)LVWz*_@6{(W9|!^TF=7a>VcfX}hnJluh_-%;O)??9>!OvP>5r@W&jIt+Pp za-WesCLEEyM{dzxRHO4nBkC<^j7JRmgMnf6QPjMKsClRGKaO~f5ts2l^8H&Li^v_| z*Bnd$T_r5d%tPRQROVeT0{Nq4aLT%UCz_XTJQJut;H@Rt{%lG(mt`~Mc86<$_Xmt| z70OrW`=tOrt3)Qf@Jir*on?<;KLz_(sJ906>lE0>5w9`gIj~<02V!P#gPFaO>r1J{ znz-r9UH!SU{F;$|vG6B4>rd>gFLwD(e9vz=6SCjyeI=OwBm{(f3mxY+DLThwL1G9hShgK({7ivedLF$;BY&=GIhjPUSyNq+1O-}Mnt5m13jM0| zzXQ@&k{ffk7SmXyaY*iv<}!bbG{$@~DY~BCgQc1Gn!q2w`>&Pp_HF;a-=u{>->i)P ztLWOaI218dpLy1Tcr^IR2gh`mrVlmizLGFd-H{9`6)Km+sMrvOB;JI6CW4QpnLCg@ zk1?%U45v<+xfs*h&&!Y z8ja-5Ma~5QB4SyXD&r^K(EgY?e8cA;janHGL?*I7kLKrgCt$JR4w{8|gw zqZOgP20p9E!P8OX(nT7UW@d{%`GXdS4PVzuDcxdyECvqUfR)&4LqR%aY37+dax7TG zR)02`ES5!IFW4w0CA--7lXGdiRGN9PE#oCEv~>Kr)@VgtG1f~zUPWnUW4xFd)@U)F z&W6kWWTN=eSehA2Gq3b8@Q6;HqNLbxU$(MyrI~k}SJ~N?R*SE3!tpyO(-liIgAWi( zGt=5^l(GvYE5TE9`O?gU7~}C`xflZcTMmq+w2xj{X=X#8_pvf_a^l0ESwWBF7m_~^ z!f);~h2QR)Iv9<9Z#eFajNZI2&w=(7W>#1Q46`I+O}yUx9sGP3IhMTHvum#l2qT`A zi@YY2S?d~}oehXFT1>{y!ssviBWVq?nfn}gn-wu5_bUYxSedzo^Il=%Nmaor%%QSM z1XZ`xsYy_?GIP$P!^+G_;pUsE%q-a=dw47}=^?&>U}fgy#7O^aQ)Ompl*OD}DQXYJ zvLjmYT(RjLAXO>w1mrip1mP2u>oFZSgx66fb?$QE;xpALm-Gc%tl^3iK z?_;zzX}a(c%${|U%FH`nTEbmBTRuvmGPB&?+!8-^%E$>TGt1v9ziuEp0BdivT)MVP zfQd#UetB_N**=!&QQ}0CCslfJJ+0bzzka?0H3j(@m)5E+lEH-(eXPvP6ZKH5R)s_4 z_!?KDktRAUM6AqAD7MnBq3~ZWT?8vLrx@aN>QK3JxY=|M>1Y%%DI}(__*8Qs`ZHE$ zP7O}>*I`QYS5TQ*npM(HFH?sOk&!K*Np-+J;_h=4h5MMA7j;JD7z|!M7vzc8QaoOB zMe_{q9gzH!^{2bqtmH3W5;VHHVggtu?AEC5IO4TNJO{~9sp*8Q_RfNFshTRLV(&`D zu6b~my0?qSMH+(4Iqg~DiW6D#`j=%-sDrs05LP|r^$5bx0m5^YnRi%a%|dYXL`DFv zh}5Eol-yA%I}++o#2-K*8HX6oyqL+crFUI}hqObvr3kP& z5IGfj3lz2>0FOi0HW~Kg-NtEGv~EMO#3>@~U5LAm(qSpwE_V1%e9dn;6QJJfeI*F` zB+^GYqnE92xia&PbYa*JGI#K{GIKQ`&D~Ozv=J#Bbhp8}Xiyi8S7xs6+M_5he2Vg2 zEnP)>f&25-La4K4aMwCkW-hEOtjsKS3CkvjbDb(M$&zMQ7fiuQX!|02tjwHj_weTl zA-=Ta4$?@i|BNg>;yjg^rL+0OoEvsrtLm4cv2l81L)GsoS}G^6%OiG9(<9g5I!L9TnYNGx1cc|ft8ur*Bc%Jy8%#tz*|cK z31?Hnkt#Evnaz~j9ZoH?GmwrF8u|ndr(*&zjom1AZHhZ&FrCy`J91`Kp?s{&4Bd|8 zBXM#f^egTLG>aR_N2Ad_REh!JTZc*c-~9yXBhlKjJDEt5bM_a*f!q|J%JGzNo@~|f z1|EmRip`Y^l{Be_BZ!ixLa+t%uD=={dhxWoF44dtzTbFD=O@2V(qP7{8ux zuN37MyL>0U=eL{*+3)qf5=?)R^aNphYOPOvukNdY%W@f4E#3Sx8;~#BbOy;(7{TDU z<;u)E4ZWlTVMcx2DV8dp9@&k#TZ?Hd(l{jdNOL)RkUYkGGD(BYucwoNfg*YUtMe`R zwdDZ^ehD=Y>66r)BYv3*JY*k=rAO#*e=l|#XjnJc24h-mFTT;3)_6JS+s<-sjAu~)Xf{(?x;I>znG8l#&_^NGd_YDsLL~er z%d6I`%q;hM;i(N*X13%PU}feU0P8|!=KgdFh0Cn|(02O$>0%}gIQ_OaTbbF|R%V7W zUh-N%||hqB`@`8P6SOJf18DLwmZED@w9&B3832xV!V$#II{6PyVnT z<{j1a64B0-Y)p+TA~RUW?g~og(ONjg!sm4LdDb&wmj!-N+(zj#k*e#+HmmS+p-t;Y zDkf-oSedd>&EO4PERdth~2r%Aj-$8BBYpTw?upo9H_@JQnD($n{%5r@O^0V^7 zbl%sV&{&xnPAEQyz=wMI%FNbeFqw{qi{;dqjuvDgk9Dw#*FhAUDT_z`cnwigDCFj3 z5kLj)V(mc~bwx`dJ%quARRJzMgXT&n$&leKMaE)E}THZ!KFO;9O4nE z84c4QCgIBUfk_nj%9E9T&s3|4>)B#q=4AMjKcy;2yP)5_*--r*VhGgf|MK``=%Bi(ySA;b7Ee0pZRu3RZnd_oNWVomyBIA;OER7jXJ{DC zum+s%c5&v#*j~&n!!WF2-<~@1)>7Ahf6c|2cP)cj7M-@kngcwy)>rOB2mqCuFPfuA zBzy+-+==uYd}TPNS4G@R@$Lc=m}D_XeuXsQ<3V3}Gb%&#ap z)P<;BW!c%p>eBi5N)I@ohr{Gu!Myq+K?@D6m`CYyzzeh}S( zirF=HpLkip9@NmhdmyoHzgQ1&QQCh!c(Cv`*#ggsbmqT2I|5yQykBCMaaDQ2p%akIr60k_{X?m^78a;>u+k8#9k0}l; zVB$Th!e!4m6W0D*TIjn@0}yv7@Q!+A3~ACHny-D_h#Z5#%ikJ(KO=ZDFSMfTLh_E6XGVTI^4q~@i~M$J(t*QRjkwmfsjW-DA$B)kM1 zsrdZ$nRi}r;TMjlz}a|&T_Qh&yZPzamSsfbFwfQ78M(Th}~amDAT5 zz{=fuPUBTYlm-=G2U;W&Jn9w$ zA4hz@XakmLrrSLlBgv+aan_`Dl(6N;z0Ece%9cL!rl0 zXjE=~WOtm&?AYgZH*9X?yb;$Dk=SQskFf%>_eel7D`=1@FBFPe2z>wZ#Utu1XpBf; ziDnv$%rq=2*MGP0KeCMu!2d`&YPkWBTfo;GPLPW4@-r8K{4OA0hlfxKGn#U{!?nQs1ID-t__^M z=-EbRe{nbH7T8B;|9)V<7!JhjUMNZpN}O)|dVF@Txc#)NMDv+_^~D09i1Bw}{Cd8< zQj}lp@}2me-*P5ozt{UpF#SnV6l7JpcCz&M>b@$tT<~T~V0jlh77Pw$)rEa4+)8hx zGgnI_npcMEGtXKOkK%gOhsn2rPh|~f`q(VQN&mh5Pjf&~+@~tiRM<#;4K!)*)RpWF z2c)nRZY`#=NaK*)A(7f@C9wsJ14hsd-%dP2y1IqC@8z6!!~k7s>*e>!bvnyEd()Fc_@Z zrR7CLa-UewmJ2Z7^}sh{ehqxK7eIL-0@Wm;sF(bLn=R42lzM{UFDMclzOIuZOvM_q z>=HLvQ(Fgof)bEopFXW36Y6z>cZ_b_8JvUP-t!?4{TXoao#QO+$!NLMp@{BSA5A6` zeKB!{`glqP!&!goOdWZ;v6n@@wT>R4ykGJ*`lH^TPUd7jTpDA;7+H&@TuPALNZr}c zKKYDipS@eJq10ej?oU&lQS7?+P?PdKxB!zQYFBZ(OV+frq6gh}$Xef6u@2(Wa#<|; zb>INy$M&x80!Q;7#7^o5*|uUD!NcT&Uc%49iA>)uoyx2^;9?Fo506QqB4aQXmpQv6 zt*o4kKK!8f=hkFwkDdNt;>>3QOF3)Add!2dY8t24WaWxf^_b=M6eklDg;dv&RBT)9 z`y`4IauLY~MGx;$OI`K#F271AQ0=u3MFxkC;|wN!rLzWCDV-JKf304ns;O37qsyrU z2*Q|7=cE3(Z*8@Rw%=3}*C++%@^XVcMp~p%Y={~vihbo|i?mqc4H{VgG*x}Q%P-Q! zWaJq3VlkR6$FuolqS}aXk#47L_OA{s(kUVR#b7angS0=g>>@pOyZ$2gE5+DXut;6i z1itn~IwHgIaANcqhP4=4L*;ggi!@uB+rK-oNXcY4UXI3uOhyLP$5Bo1t2;^mP<@N~ zi?qFVsbSA)eeJ2`f)|7!I*t!tOsPTyDaQkUD*Ax%4p8uY$cX(Jq}2hy5YA8wt1@7ya2( zHT2?XT5FA}%u>Mt_Pc1>YGe_a0n{X30j{QA)S@4j8kU~*OxR@!_2i52NEKZLZn730 zdm{5cNjLmQ__@%gHB?L|q2-wiFR-6Xu6M8c|T9>M*Z_GVjlv_BG`mBF(1H@2vLL3ht5=7>{=@mSWm13iwS&x_y#Oy z@bdU%=n%rxUE9{d4NNuKbhua#1CQwBDbjt2H0lN4RZ2jD3edZP8~m+_2Xmi0C~1MU zGTivS>&reujXyfwtW@7S`_7q{b2aXb{)7U253&uRx$Eai7ItC92@Atceg0X_gtFtj zIO#6hk#MoJxWHfRf-9XBzTaDv7tfBMukKBDug#Hyw#ddVpzmaux?!8vN#ljTfmu@-FNHC?@_c(weoyhA9a?%IP_0`V?R);8^)!c+Jq zYbykvHuRn8Z&nKyu2DTQbf0OM(MfvSUF$|)A3`*$ug?cP9=z&NdMQ-sgyKx_&5OeU zbY=b=wjlPKQON|Nb0pci=#rvMGA%a8L6Jjs9;K3xnaeM0QfcvdH{GO9qv**>6(eG02hK0G2g zjH!CiD}bqFFLW7Wpnw_R!c9n78VsP(L#}v9vJE;Av^MQWVm~SOKP}oU;6%!30PF|7 zKPJw=0vf>-!Wc_yP+)$Ptb+p4PeoFz9sJk!5BzH%{AV`|e0sjo{SS5`X@3Mb@%J=8 zRf)9<0e`(;`17BwGU#^Ps_FDFi&jn1Jd zS=n2JhGo!I?DOoK(_LDNVCAnY699h7niqC0P3Y46jc{v%N_GCdl3kyEfrrpq!591@ z4>L@bVk}qd_3q&RL=il?`^3uO()Ia0H9MHqa`$Pg5e_w+@4$xD?H977kO>{}nVlVa)=OmCUa)aqtk{0cO4za-IzE^9 z8lg2@-~afpf5pH#{F)HQ_yb|4aT;^>?=Qb;A$fq5gAkHOGuCp?4elOc?zwgluJ7Re zN3RmWrmS2gX?1ZhWd#pW_9fCqlVlJ!U5WfCg_4q97aGir7?|dtzWJ;E?T26PVR7Dz z_t7jydGq9>oIQ(qk2s-mJ2%RBjjXrsk9%oJD&yJYN#ycLg-*&Xap}l|&7;|5$cZ!? z>0#nK#4#(=car`8xKV%;YO`FrwoCmD%t@461M(g&Wy^^ZO`cTg#o4}JK)-bA@>IHa zzka@hxhp^8(#4C4+5p0Uyo2)*4neuqb+I=;Q>6#M^b#Ssil$qJy^GJPgSh_&{P9c# zoF1D@DiDaK#iwOgeZ#PA#(|FF=w75ggC~5mA`bH>-|-xmE+*M@D6I-doPl3S8dv~$ zusFFs2&|O30N3*$X1FTZrKN?W#UZg`bLB#=EX9@Joo8q@h`)gk>_4)>2K1mWF$sO@<>fSSf>!RoYM z^Q+*^8yTpS>Vec4gbWiytZ>DnetD2p{){tW?c*ANxI0Ofr+b)SMZzX_DDFOPM2^AW z_P6@_8zeX|Ho*M|oMRyJrM`7MNJ=(0-K^W^b5AHpnxHJR@0P*Ar7lYyTUymUC z93Z^@cr**a)e{*3xFS+33sRs@yc5Dx2*445C+GLEE^!3lz{3VYcEnOR1fI$@18`Q7 zeHoH%@DvgEF2sElo21y`JMlHYhk6`rfmx{MBU29B zP07jK^7HGOG1*EJnBdw2_-^@_ApKg}+KL}(Q1DI+tq37TxU5;?%Rp?#!4CMnrp_^7 zpT9`<2&Yr=2>sTyDoQ^Qvk?taP3Db=3j*75C;1@?+9`Q#YT0aIJJ-QMV zVNfhXC;JH*FVX<40%zlq9%W*0b60zmGt{G0?#wn|7i2#aj;HcxWSI*+dbXu>{yYY_ zdNaeNsqB%7)<)!)D%BSK`*n~*sdJyfBvrrHGdgm2p40Z&^R;M#B%{g92Q)!o_k_Ke zZ#8u$?$MS=?tO(FpFlF6ZPw%8x6~lnLH6l5{~k1ir9nl5q?n0AsaZJo;-tjrW=Mf1BrSc2V0_eq$Zd5oNw$XqrU=Sq%1s)9GzpuErel#L?fM0Vs0Yq+W zC~pkGggA(EYNg0sIw^OltlM|OdFjS8q51>fS_1CRCWfCotw~<+a8MN zdpj9N2Mlr*%vWgqr3gNgc#>XN*p@rs?nnNSh+`1#7k2}6_d_kD+p1fibN3emf(Z3N z(-p+qKx!DFJ_z*s%zVuDQSD%Fee`0j(OrL5cYU$TcLIEV%bB44UhgXb^(RSDkX zYe77kZy`06-I#nE_*7PKrk~0R%Jg@D6dlkL2O;jHVv_nAxN7gzmE`I4&Ygm(*`}M_ zlKstZRiv^=1CiV!O=kWaX^{DBQgk7`hiMpdiBUDhi9fqM)4D0N$o3J*QdEAoOc3pmGM(f%+QwY}|OYJxhLp9TLZl&1g+* z7bN+UVjD#pKn4JSlI-=yOzx&l(KbFSy(ov#!I_$yu?6Uvl~XjWwF`v@0$Sxx^{pVc zhgQ;HmqCS(mFs6MRb5RBzFw%Fom>=)Ve9(k>?U%OBfI};6`8aiXky!C0fAI+ShZjJhL-C7I>)1@;vrna&ebL3lVNWHAGLQ9lQSzBdsB}K6> zcAZ#lK$@2H3YcOgrM}b`*C;u_9$H!Gi{?8nKz44k)?+Aeyv^*}BW$t!a z=GkaEa13MEA6fI6Wh~{TaaCoRheLgYWto%XlKxo@TepQ+DfUguG7pEnk?eE0&a%vZ zK0C6ZK)VF0vD@M6ItGkiS~S}YSZUfq%$(hSRve2U^~Gnk*;UaV7|d$`sm{c)=3_8j zrj}zYr(PY=j+g-0P%B1pd z(v$Zv#*VMHyxR!dR$4B$bH}_E>nYbYydX?{{35xN1Yf4S_cTj*J7Ga)`CDb@Tsrh{LSaGX-=$9B&_3$~}Dku$S&Y^e0QmT!_jJbh2=nRu!7MXMy{OS+V)+9ZJaD0Ju=F z&>>j6UXo0}zQx@IygMTybAw16gTd=%0V{cBHiKD#)^Gp*>G6l}6_?ftLf8#=v?(OF zgv>lfEX%Vexl9H`6mB8#fyHt>{=ykHA89Ra2tIlx@t{vU%Lm7ADdZMe>pUl>VQNO6 zk-tFf$WKWC!I;d=+G9nzEF^CW$&nY3M#vR}61FQ1uek=K)k}h+km-F0>jORw;=o+Al!UCx`p6+LAC(=2C_*l95aGrH2> zhA^$$dZ@~-;O5xx-f6OrHLY7d=HWfpL$!R&1!$rm;B)~m@+ov!tr+uX@Wh4l@G+yi z`NV3+In>(rYv;Y#KE3+jb=>ousz*goOop`@NaZjjZ;{XHG{kRf z;>7Oe9yO4b0(7(@QW@_S^^yCIzPEJDMt0{L@-)~LH(K$Er-A7s22^h0maQ~@#x1KN3UR7cL7G&M?5ol-BTW?ptPcDgTqLZrvDe)pd0$SOhdV%L6+MvR zfCNyVbWf%9qBdtW1-s449-{^DajPH^OW~TYrRQW2W8~o_e=;|KAor8&0@^ zbJ2RB(3vdoJ;+GmkEm;43w7%)8?$hM$F&v6)l`9_dU9F<6_c6C;`tgsjqu?0mF{Dm;Bfb}1&V=k+jaP%|Pm-Q+9X9b+)3*;UTQcTiYwZ4eAQ^L`qQ^%#AbmyY zs;04^W2fkWWLZ3>^l0#Uw?df23C&v;f67d}dJhNh(W`ejh$htk14m^~U-45kvs}z{ zlEmUzF6IxlrDbuF>|PIJ4WWtUV)ltGUzI0m6hA8m;boMsvh3Rj#kAqm!D_k}7SvV& zFP-|drfxWKCr;=N;NNi=XcJ`an2UKCPKZ02d*i`m>bssoyoWqEhFr{e*3n_wITtgg z3hr4hW`UstvLZlwoy3bqwrAR>OnzT*&EOG|;UBXA3kGXyPGaW{v}9suWwHAzY|OeU zmu&88DqYsL?}U??v#Gjx!_ZfPwf`^9b65KsKc|<^$2=N_W6uwQU^C5kIgyq7%RfPFvMBvH&PQry;GbrMwD0x>+iYqq&qI8UrR>T*Zi~sk6@7eV=6c_ap|bfG$ui;% z-$P1R1)EMVDJ9$I7q}l_I+4AJH7Ma^k=+76^c^Sk#`D?SA1|Hh)SXY!{;KxMqAwIC zxXw%?ddC9Qi{WG@!N3FYpDtlfcmu4Y7!$#1B>o8Nt!`%+@elmfTQg|)`Q_E^FNxQW ze7_G*>%+0s-=m7{SHqgv#_yJudFlGIxjPF-_7yb4W zwvzkNkTonWVg>oLPQl9DG-yrS+SzhZaGhM`eJhSP1=sevO&2*GE3@)d{4^++{+RGL zS z(SEaF95JaL>IS+W+qU7wU7LrkA{Vp-rD9n;fCpXg$H6-q-X_d-5*ThiyanOs0O98A z(Jchm3$g{^7LH}xH3|A@vLcVac>Zg)@oZjc99?u?sbytun^$T9_z5Z7ZUlfc_ASfG z+^X=AiR-!+ZmSdCh_6K#6SHy$fV$OqH3<47WsfR*j=3&AqB^Dxslwpw;9iE0v{Y8F zIV7jjMJ;C|hj2hsktfi*XHGPFnwUuHF<4)S=uy^neU%`~%3Pms(W}X|K+6Do;o#T@ z%ZX)#^DGP6Xfha$p1kZ{bh(OY-Lf(lpb7qaLWnQl?>EKDjLotq4qRu~wT`>gn)l@( zla84bYUkZd=cufh383pr^=LV))j%qTp=D*xUKcF|=x9ZxG9CiL?V^1yR3EwT=zFV= zSbYRwre$SAaJU+MZ&{h?6>L?JLPU71U#T$_;e8q!>EHfGXMsJjDxwgmS{0;81K$qF~I6T>EI$^qT}4LvLSh2a1DTN^KiSOZELf#$7lh394wrzLXFOc{>?VD2=%{r zqBdMr%%VXx5C67^+U$yZ&%h?N_rzE5zYRCKa0Q^UoY$Pdi?~?Dooj)76OcbDaH($E z8(j&gqY29H0Ms8aY7MqOTP2*Y8_iTX9n|anGU5FJYrGHTTUKT;)!aMSw;a6&(9Z@R z-Er`d>JAjD0B71QDhLZ?Rzie4C0@Q*M_C5!WeY}WL^HpOpK)Uyv7%&j>SZL(qC9#d z3op;pXt~V^tM4fh@Bt`{-bw-k^8O!R{xNu2E&u*w7_9&H?hjUP%jo0efvn7pX)An$1JYNNu4)>Kbg}XFNS66u z^LQp+20#dtIH7sV;!n%UoNVK~WL?tCQIGt-f%4f|Sq10gkN>uIzxl@bBhV<&fByJk z?fya6tpHfW)%|YeEy;>H-NoWqR%Xk}97bT!2cZ}^gMn)~dhai$&HA(q3>!+0O z00mZ2Ao(Fm9$&odCGwMW^Vmg|E6Hu!lT0Z*kgvpY-a4W;2>j7^JYX`MO+#<)EQhl} zfDad1RhG3)<0p8@CsS5tH0xMIAlWbRBQWPIN@BNYv+#m|A}AOw^i~<-SnGLjUIc(B zT1EN$;!6@2#2dWAtHR%8S(!P02m66_hE`L5hq)|E-L0M@U%A8tAel=iBfroL+%=o=x7{H23|Oxj|RkZ$c_-T_y+bJ zCC(I#%iN5hHsM?Qc{8Y*N@&CV_rd)UE~8_;g=S?`>&jH4+EFX3FVrBvcgw3xCbQ9u z057)_EJJ7L$fCZp3!=Ez`UoO%1M*E$Jfn1qa{loGZU$|BN!6~G3v4Z{cm zbRoos`r;OzPx++OC}3*fAP^($3yYOJ8h*Q0dE1sVnO{xpPs^Yi7k=C&@sM1}D(HIo zs{Z~HN#7!$0MZx!U_nsvEAe0AWR*N)TPi&FKnC3#O60Ko5JoXgl?WHhnOx!#7NA07 zOnh&(B3D7vhAw=qQrR7d{$x3mt9RVZawa3GLe~=x>Nx~!*GrPc-FXC73>{c50Xsn3 z#X0EOxVzhAMUKJX^|F8k??UmoA@!mtq@-p}N;;C|Oa^71g$rhuGa1eSZfE9KPtS5D zlSf)1ouvI&5)b;svz*CPIC?g-dKVI2A8%eUitT(t=koBJ5{x6BQ)}C9vTYk)+_hQK zDsn+fP#oEN4Bd54Fu`0Mn7oe}-WtEp0m3Vs$qiarw-8(}$QFQGICd{QTh=Ci$Hk4L zY&eRnxxL&bd>)_hc_RQ^B_Fkjy9se06-}Z}cq6_RUCsokTa8zPpifeisIupnsQ_~( zHze}H5y;KK_0cABNKU28ukRa{aGMVw)|xCMXt|?I=D}>r!_;^;rOC$2U#Q{yaevrd zw}CHRkrcENonyeh80aYT`uS)IOwJ5pTeo#fm0e*etK=!^-4;oKtyFtRK^In5OS%*- z#_uxX1#P(^HlNjO*`=5^6?HLx2G5Xqpm$pt&|k#>*KFr!*R_sX)M^{2*EV$XZl-ip zdY)7FXgRD^L5kJ1DhOmnJ>jFqL~xJRL@E+{iwa3Yu+O)Up$7N`e|b%=_SJ=cSk`2t zXzUyEHP{t5T5;}A0CSaPO=cF!(?#E#>k;(@Ce5F5%esg{aB6jsCLIJqd*i@^`aP1d z;h#vJYD0{a8E@1+cn=fs)7y{KS%}{R@y$$owIE-e@t)_1uT(+Fa#n#yU_dw3% zMm>*@a6tNs(p5=gsoWL3v4Z&cFL32iAxq+b<}HgqEoHK$Oa=~^Yy%uS)RTb3q?f!_ z%iJPKJghRE+5IP6Ti9j|-Rlee-cCT9^=}yHJU124W>?%`#c@CzJ{_#03ruNHp&STk zZ(Pxx4IO{EoI36xbV8SCJz956nLPBS#G6h>zBd_!^WhX<>?kJ7lrkC3y7JVHDU)$c z^PZ(l=J@?0D3d4MQ6`7W!E81rPJiMrXZ_JE81}u9Gw*xL;b0mDb9d@HNZjaD^blpT zu1O6lWZiL=3)}q?JW)ygplaeEASx+gy`x0tYZa4j$WVxea2=?+f zz?nQ4xC3_ppqS`u?WBeop%-5GtdcTA@yExXQq=1~Juwd6tqboA#h8D$}OZZ5#s|mhuk# z(dEIUSqw2cXWyblO-K-J*UH0==T2UFK%A4rQ05kMeL!TP5A6wdFA#1#_aPb#7 z??XqM49v-6ECHMCas{+i*TtIr`&)q31Ud^nbJk?VU(Wi!uCoQDosTFfwlHt$00sJ@(guIqYWtCgCjbDmAeg`tTyj8LdK6|8V;d$`-|4sN<;1H>!LyGXgiXb45@A7b*Z`v4QjXF>QmK)AU$bPK`tf@}e} zL3m0MM|qN}VZIQfASVr2o4906`8iGgMSSWE?`db|6G`79pFp!WNNG!HyI;7w@>k-& z#K|go#sSMP>A#XR^}-}wgLi;gLbzAC0tA%&c?-aYb4$d`<Q>{`An21+I+E@>5M)fm+>jnjdo)Iy$Z;8!F4YP) zx|}6wdO*0FGTaUEFgK`v$6$RSqFA471@6zsd|+~92-CW)g{tfd9uxE3J4MXaw0={_ z-qN16HLWw+GfKm3ZR{7$eITD?`^u{F^oaBDFr&Nq#4$JQy4I1ET4m$(%7$*<&2)}R z&vU9CEr+!lNU@q!wYM4wkk~I;3eeGtNM*cR)JGaZeJl;L)kmy8a@U>)OT$dBV5^E0 z+77RMP-;8O7n%gy6?vdZtUEf1-~OkkDL{2%RYajowJJ!H3Ic(>Uy+6xX{s1tb>Q#d zB4MKA+_ADDd0$SOhdV%K6KWfY0}?Ex7;`KNMNOk>ib$K4Jw^-QCP;Z3UhPM6) z%frm>ZX@gT4Q1cDnu@cQhZ&#vq9{GcNa2q_hqh?IE1MMOGd?5plz91K9c39r8}bsZ zz4B+=cne{PR3@usVx$-AWl+H~%A+^3@bWy3mRl$x3_WDlAi#XlTUpMOy#L3Se+*t$ z%fJ5^2J64Q`-9cnGWt0A_^%(L@V~$LMtTJ>ux;o~6#G%}Sm{!{a0Q_9uGgHvi|ALy z`dA>}1msPk5Nh)T>ZZLgKJN)%LLE&|b_byTfKh9({n;wvARgv3M>ADU2Q`qm+cG;{ z!TST&cpu8wRIDxmJWoGI1B#=k+yfU1_f59F1^Xq~x3s(lghe+6_U(!rtazo=j_MAy zNZ;~PLB12pOycU`;q@+6o==PMn=rnaZLb#Pt5e>H??sn0A^TS2)nNLQq$fy*2yh2p zCTMOoef!|DY*K;mMPRuJ9ZL$w2c=>Dc}ucl<|KYr z6~fLs7GFb6N9aZAZ@G(e*PitWqBS)?C5%Kx-v)+lowmY9IUs#S>8hr&Xg*I-0L5d_ z8Vh04Og)Q%#moOGZXS(%A_LnZ~v)T{gmX}H0I_= z#u$a>3GH^BOtco@k3as~+WqDm=a1Z?`eE(A^nUVA#-t~(Jd3Rjt1iN6=ki5!}_$~BC=Uk^2xu;kcT_Q`n1@Md8a98UdUKJn`jb%@_6I|M+#gLQlm2o7#L43+ z84PF6G??nC@epS+{SoL*Cv!3%hVIyPN8U2j(wB8lQ+cL2xI7Py`1qY11}Zc2jy!DhUKOg`*~OO zDDr*%ORZr!*3okcyO(hfNLmnog!*xz;TR@0CSg=qJ?hSRPhmP_(anvdxOQciE?#Z&uysef^y} z38#<?O^4%fsghXkuHoz1sL?HM)DbAJ!-?xGU2i$`hT4^~8}(*4 z>e!nMoN!8fG75tk(W*XIcccF6xQz-LfbNw0`sjD+`t#)|91SMJ`F!YT)p5I5uW+xL z>Z!}|XcD?)7>*s^8M#_iCGXbD*Hd4Q+pL$lQ^{cNPp8BM3svX_j-&fVyHl@lr|QH_ z)lejxh}qyP-` zd9>X&Bk8_2FG-d|Y^Hu7_Dk>`B-_*{i)Sz{f;WNrEi`Wxd26UERJbY@kOu%?z z8!I&Kr^$-+$!pe+Auh77*t5zI4g;r$7`0Hs+Vr5|GVCqWZ5*q`{Cncj<$!rd{Nq&v_HU&*_0JZL9w3H-Mpt9@vQ&Q-8NMKNT7doiq4 zD~a~Dd9p}}pS+Qjl@AR_=uyIYNtVInEd7in7Gh*P>hEhe_Dh~`7LYKwN#Nx{3Smzc z+e?;ZW;0=J!MF|Ynr&delEq81S*&1(GkbSkk34yWm^1q9VphBrnmP7xvC`r@$|diW zKB}PQbnFNs^p3ZflUe=vUWzOg#C}um_^j)Vv9QTLA zzUvMigj4Z>#+*Xh=>z-pSXmFAd`ch0c0)UnDkO*sNpWsbM;?2W$Amo9Uk0U%fH^HS zT|KYTyUue+&r3EMKMG(9m>W^rI87UgPh&)#rajkr7>*x?!v~l`Wr4QKRpj&euK8{8 z82rmLfpE9(e5vZ?%I33h(~1+VbftP)Oki&Hy#yWA0@y1Au%@aeP@<5LGoOM17ouEd zc;7M6mLcqD4>sn9!ShD-h)M?ozELx{l4)I`cYsqY8-EdP)Kq;y4bX6#()bMq(ezD< zvoIiVY4|V1e}%I}-L$=IyM%kGyorh*`p$Sc_Lpzs}z4oAe5w8zGTTFCm}c70>bVAGEm9TK!K``uWf#1K{!Y) zo>5K}_lKJmT*ED1~;^+2i}VbKa~+85tNp9g;pdL9I*sNJupzHMF8qQFt4_#>wXx%@GV6X8aD|O{CYyV^Ot$m3oP| z0ie=cYJ5Tafzz!C+2)_@ea;p;)=FOLhUM3ZnG(B%)<69I=l}Qra)?L#QiKAE2ZF2# zN;v-iP$4lT&rz1A?+>6x6%23>QS$f#(iizjx_N~0kKQLPe+ee^`}T?FGgA_%w33ym z+8+d>$Sy3~>NXD#3(exJE-W@P@C6SGwbw&#S1fC2Ck-R1v$AN z&2UsU7XElS@^vR0bzjQf`RTYpYtkIgR=Nb!Dk+mx+2ZKZgX!-!QF4M7SN(r1jm#jT1y8$RtK2up3sl})(PU)NDb zuyXA0)X;M&mED2pPjGW=v+t>;=SN8Jfy%%iO9&!l<52DMegHM~)q>vXzstHI1}e3f z+F%h%_)O*`Y>09Izu(%6@(J$Ou z@+-#m75`Y(@>T0vx1ldx5$m)Po@3y? z7zo)&c`b3XfERsT=~EOJHaRr}xS!)%13fVO+)==b#_(;!ALN6Ag*V-fb=|IbJ1U)` z#xT?*u_*t9C?9RPB03*&(Lc~|%?BFH&CTmn7IRnB|@ zeA52ns#TJEkHNP9)c~O0RKSm2af21F1pF|S1R-YOk2oX@-v<52K|g42tu}ISCheN6 ztrpTw3!#x`P;vtmdoqsrS7y9X|KL4Lz*|}EiDx1nk~!OExO>(&D)xwL@kz8<+GErJ zKF*cEf3qEJeG)d{$Oash_7xj&v@hVu@*XlVxp03(UB!!Cf@t{wY$CbLK>b$Jw+}8W6(tc^ zR!%Y$3{yFzsEpxCA&^$#`F^s6x|rG$ZnO^+4B9{);<9!#rt4rWioR_${vEOdqShEE_C9SX+oqgZT>*LS(KjnLoGm|!iBFgzT zjU}Qe)K8fqb-`Op@W&tjZS8*Zjq}G3rA_t2+Wmv(Bg^XJWWQL8#aTq*0%{vBzK}H0 zJ#8oJ%~L@+67Wn&Kch#mO4g##EE@e32{$d>TR4uMN|>lHi(l8)vAQd*=ce>rT-_NC zId1>>j!|XsD2go4o@86{UFx~ktHo~2d-ZB9r;|CEPNt4C9L>oddolOKAe;rj$QQc6K0I?& zCN>nA1z%l9X22)okuoKqSr^k+fVUnTM2Q~(L*-&qFug^(%w}Wa^e6su z)*sD+Vc!GpvA(w)4yIu+cc;FVK{<=PP4)sPw@~@$k9}t{3?1L~m*a5Y1jAs21d6?7 z4X9(k!{sV9#Wh(wnJ{1vYZq(%r*}9FBLCY$a{o+eWa-9g>Sn;+#UB4xpmw0o)AFU# z^Jl&BysSU)`diSZJ%P zzKxyrJpA%`ESEi?uc4?|@Md6aPPWf41#OXZcF`WtKqX)%{$%V01CWDh=#N9K(j>Fj zDK_rvlleLSycytEmUT;fXjlT~n;~FsxTpA?R-Q!$H=F1|^-s2Y>9w)}T5WlM9z?+G zj~`CPzr4x|x@xF9Y&n>3n}c~i3`sBvMgy1luH#)j2lH%ZDVW)vN&mC|>e}(GQeYt{ zm}fJ5Je9b-WW28V?O7O@+u`41DVV`pARp8WF`N|uTO2Edng7pi;n=x5nhpkjNaiDl zcp=_*|EEY;rJ+wJgkByx`BT!ou9B!x_nal{G@AyUB#hrg|IF*{+d`c`%wd zu0z}z(0dO7^PpP{7X9)Wn~{Rj!hFfA5s9xBT(q>j1}{&k z%@FKVmKmGTD$C{wyc10ro8z}Nabg!N8+?KJSy$m~{ymh4C=@$Q@8bBH(L6~)$Bp^C zvNr#4$)3NhY-dYPQ7Y)-_mzS`@Y&OCEZhnCn(xS=dxGq!7sxGlwO zeplsdoxud16o3?Mhy~g~w?qzSSKNr9yHYF4@->$ii6|cH15qMLJ4_&{+{4`_f1s=J z#31?;_`xh+b0ID8-=2uhi?g~&8k%>;B5nKGcC$&+yl+S@Rg0+&7NL~q;t@K0UH=T0 zFoL8C-JtZdsmFnT{Z0?7n*{bEPgQ__+zVLTUBJ6D@-;Vz#4#AWUKX(6m5C1A4x>bX zQBfCR?ce_W)8h}{W24C_qT3C3v?(ONalU2?(2M}u4aK?J6*pS(3M5A^!X1?yw{&XL z?|OMkynIoXYUO!SJzKg}F5P;wU>tF*THCgqF>?+mj+Wp6AYLKpZNOY7f#K%ETM&K@ z5N^I6-9m7^AX@;g=8*SrK7uF-g47o<7|1CJ5T2_xsmVi78yaLD=nE=YIA#RLEC9db zf=U*EpD@StMgTZtHnM!pSsUZ`QPCvogg4@A(dA5b?N;N}An216LaOXJI%!J5n}*zB z+M_YrMD{9Iy6^%wbvaMabjOrt9PXwJcSB^&4XWQUSYL=Jf|Qo5S&8esHe~NQwp6Mu zm1^UgaHOLsh6--$qJ)ekYo;LJbOA5&-Q0tC?(K@)2w5|_n@=2b!>(%`pQ$zPH<|a3 zS2lF>Zl-fodY)7DXgRFaK#J95haq{3d{*V*o;8q`0(7(@QW@_S^^yCIzPI|wy?Gk! ziW{wXCDe!MBM2@FeZ_|RTn2dqTAw}Y49}r{ptzkUW><`_*Bt(@aH?7rq)7$IzA95Q z(o`|P>L7rKi-d`ebH~a?2;XtT1%XaRg2 zES#-Ejr1f2r-=18+t4D^U#Y=*SJ}6&gVQg-=xDQV(GI<(>|49y2jPDkZgkDcc3-(cUWczDb{<;^iaQX0rweLXZ<29iT_Y7*LlrI zU+_!{yPC!LO&H(IwpUx2N1gIUd@s733E8(AuLjefBs~EinwM!4Z#8}U;IdM=rnGkR zT1{fpmJ)=G;gZ6kqdsoUa*IZ!rnJSvMe5h z)>sIWX6k7lnWR_m;SkTRcQ}Y9)c-@vc3GNcIt!Mj`AMyZVRiuuS;JOqDq)tUc~=V{^lF$wuZFT4UMjd{fNi}8SDnX?EIPvcy z0k!MQ8w|s-rD+B%SEXqN=4y9559Z5o>db(@Pm(CwRxYn!#&a5@{00)OdEX0FP(1fqJc^mgvO&@>Om)2TCE2D4@0 z`;$=1)h*N8DJE{VbB^V=voy^&L(|-FPjN$hg{IlG2h~3(Aphe@_e%ZNW4j+n3@8OcWi~q$SX&^Chj-03w@uUR4oNU4-gp^~fu=dcq%^%`n{SdVUzFGngSU;BWkBE- z@S47waEr~#^Pv!VoG+f!WV@lut~^CF*?4Il(N$f<+x3#9&|3G%G$qfOs+ z`ol5(*Bw}zW-7z%pZ)ttOVd1laB*mK&(bvW357pH{79L%?9Q;`_O4l?I8K@ zdS0HV(Q=zJLw2q zVtxgRS^rE`m6!%&J^m!hXFmXY&m*Y4eg8AWRmORlP5l55mP8aQE}R}n{s#ILF(@1K zR*d@246U;KNaVur-7!rwnkPxvl-fjKl>U0ob>32z8wNvMg|}VbGdDwzDOtD3M3_eWl|J zpFQ1%!kv(&8GjX$`(xtaI6k>5hK{a;8 zjaIx;D9X|_mjLQ?Q8kr&`1}zu-GS&&;0Lob&4skUe+5x-D?n{X>ROu(Vz3C3LclEr z)fznY&oF_#D30h5tbN=ISlnH}J8F}05gI`Bh819$ayO@e-!tjOapp8v{NxgTl90ZIF>Bp&pM7Z5j?YjVc_>vPOJ(mn87A<=@v z{O2_J7x9@HPs^Y8iKMiSGcV!AqYtiLQcI{T<)gb7T)IqB3IXY;x;FzwM8Z6aHuD_zw3HcC@V(+spO3rhNK zBB{qJs!%8H!2^zhY5J=K+$8XK7suZ9w~<-obhi`QHWs zRH4ZJTvOZ)%!CHDp?ZJuvYf{d(Ggjsku7k3fA}9)p9A^fa$#f3%IjO;dz!!H(0>rX z6b%;TF<8{e!DnQi5-(q@qb!T!XI{dwSN@C}Z{vt1w^X5sbQSe75@%4n@r^8`l07n~ z5MVx5ype8l^8O!R{xNu2E&u*w7_9&H?hjUP%gC0rr^{UWJlN^0Q#pS7A6>Pe6FUXbL)d(q`g$iCHhHJJV+=?Rh{0&qjOwJE!@iMN`*eQ;SesZe79ff~ua zAOLGZ$CX2h$`}q@hX;DTpKO7%Lu)vqeR|~g4Ym6g6`L`o2WwIEy=a=|Mn#W)2>s`P z^p&DxrK_68g4Utvfn-@c2CcCWCbZb1J=L68c^hg&(t9{W+j<>DG=bBN+5ap}Gc#Sf znrZK?yd|L-zdf-yizr;gNxt|((nQyzSXAhOw=|u1DDRzb)0kUk^K?s)#O!Bykt6_( zegV!cY_+BmW@(x$WdUvZD%cqKa_U`M_Pq6CwpDYjPmA5U7oJ~Jxr(~gbi?svGM-Mz zXfj$(CXUvprRO<;(o+zDPW3Q!U~AD=sU}BLfp~Z8xJN^2(0OfrWwsTh6@l} zoA?oB-7D$fqRql9LO{s2hAxH}ua~FzD>{fDt}@-_Xf<`atm{wzxx+DA};W zumc=cz#ec``nxRlHrWfn=R%dFKlU9mB0yC+9}wbu%i(;9B$d5o_x#VAQDCl2W1!ee z8N@-cc7H87@^Z4?=!X@RNcF$|ITfWyfnHDFW(g%vx0`-R1r#LW*)p>znvFDe9^hi1c>91j0OUAom z)!~P}6VCl0AhX$EIa_*RfKQKVuPpjPzi6ZtU(5GgN2*GBoH3oN?f|@SzGw29^?i`l z=ad!sMbcanhEblahWm~Kh4ScW(}U`T<<xt#jJ z+`|T}E2DZI_2;godS=%p{m*`EtEGA#J`XmOrB!q1Ptzv=Nn73*ql zGKLvSusa-#G)P#+y6EI(-Mhz`x=?#IR1MUuZQmAc?zc480!(O&s!Ue;1G4?~>8865F5^fXM^@ff=#cax~4k|njtL=&vx0$h7CuMaCn6|CK zj_7gStJQAUzZ0s=5IS|NXRe9?9y>q{Lk`7W0q9tv-T)+cyUNl2?&Z;%B-@+{iw2x- zLG|N4seQj*0I(#Jk^Uj==$n_WKZ9L2@TTMG$O$wBh_h#~3`}OD8Sy586D&h#=*ZgW z&Pa*0()z>&VL;;7Yw?V7Lb*&EhUz1QqlHBUz+z`{jznoo6mcF@4-;7pS7D2od+t4>-tOgfwm~r*+_b}T(5>*RWl21ev z`sl6|i+Q=bp*!Ze8lG0MJz8#+E{y-zL2+Rcz+RhvUNh_T)Bx!%x^d@Bm0nKn$70*? zwn8AMgH-hPgVqGNoh@mlv@U$4wtSWhh9{}A#nC2*>F+i~?u7Ks_^Z&;!wt0!!C@2; z2v?(S!77D02E!Oj1{PqO@bSdy=rKyHZ(j6yGNsDPARaibNl~+k6Sx}nApX9J%y&xYxm3#TK=da|-&}}F zDKLWND9)ZlTuW1uh#}WhEv7bD1pay}FI@{uc@$qZ3@XPeX}@MZTvgz@T#qqp6rU} z#42GoLD*e^~CbAWJjap)F;>jn8j4dNDn0~M1da9>|k)mli6ETq;Ze#fK=7J#2H_q5`bzGiDU z4ZUK7tHMlW5qA^fHgR3oTE5i@Z^YN4iwUCb08qCYuLeP%q&`w*&oNE%BPw{>kW&m+ zr;m-%CURUxr3Et3d(=Q$3eeGtNM*cR)JN_+`re{bBXoL0o(8+(Mk|i>5d@blr$dLa_h@dd zD#BBSX{}6um2890UhcneqCkdg#Z@fw%xT1t!nA5tkR}xbg0R0LeKXQj#j0`@CXK1N zoJZU4WT7sZfyu^GHENuTgjF{7x;rHA3$6jsZ60n{{)jd!dyE#q$HBsRq236y4J|_b z@7*7P)1hIPSbqdUB(#Ls?f4_?ihIwv@-#m21-^&t*Ot0xXyn3u5tR%4nnRYLFq99J zO(a|7N$#!0ooj)76OcbDaH($EIS#MQ(?uOkP<97FOb3iw<48DLC7iDt%~UxZt|i>) zfHmHS@-6DE#klzL8!5f_XQz21N`d+2pdJ^su)` zzn;{pyRad_KPgtmV*DnIZ)V%8O;1p#yb<4vE@wjat;Vat^e0JAkd7xfBQDb>-fH^x z!DXeABm&D~)7GG4N#W2^qTLC7b7R^{F@YdaA6uudC|%Vw7PJmU4b@@91R-MhS34X2++*U9e?I~?r1ohEJyCl)h5W?Gkx=D3QVSB;w+ay z`~&njRig_`GVH1MK>&jC*rfEC^WW=uz9jbfwc};qb2UKR+0@`bit%bw_Fmd_GPU(@?NH!smIy^H8s3zwt*4I;w9NE7^OV)MD><;J@Vw0u-EAoZ&nGfDE268 zDkMUD$Jb;FVAvl| z$zV8hromKCUwcE`vfut?@F7gn4?q0$%Lh3ABcN*nTTv3DE4C2c{cM`-82vd-{zZIt zlIs{XS(}5XGHFkZ0hd-_PPWf4a4o=g(Md*0=UP}7;Rhf_b%7&xG#-TW>A)Qhe9gD^ z%3c{jM|kdF&x3i^&huta_3N_tl`c>W@GgcYmIMP}<{VC!uot|6qCeC~yHf4^!gykh zC40YAH*&-tB+W>YuaWrmqA6Xm#?Zpl!C8XDsUTAAX#EIF>DqgEc!YloJ5%=f6AP|d z10mC&ss0dqu}>a<63hn=z`XYe>T2Kr45rFBFX!(edyx-Id^mC{5rtzRs!+P(RhA!# z_m~N#>o$Iklh5kyS0QxeO{B9Ok9BFJu6U-j`=Pramm2m)8|l&%>0%PrS{vt5GwT$I zQ0rxFFuUB3M!aBg5oaNP*6|6d?FX$1dpTPuJC0LOCTZ`9&~4z%=}29buacFm9@t4N zsVly%gy&t2Bb9vbmeiGN=GFy&6J;(fWr0y{L8YvWC3P(^#PyN7;;Zq*Ao>%yrncGl zFT{WS(Tl+0xcFE?5CO+5pl$-xh72^dnA%_wI3}*e*Y(dh6V^WN1uX6^;NAI1UGYI9 z_IoL6$6)Y!S-_)|VbR zNw?O;r~K(1w3x{MHVD8woc$R>i8i#Y`m7(~wgT2nEU9aptdi$+-H4LTcj?|S$vnfr&j0ZN?Hn|;I zSA3QsSaVd+ix5)$&{ptXUuMM8x_(t`Z!0SrAw64JaWol>Mo(UrZPz5|r^$*u{^I$s z*~Wul=@kBtq$~XSk=eUsdCGpTn0%w0E?MAETej@2xRZ+#Jn2QfStuUL742TC5qe?UUD?-@Kr;(^|6 zJR_old9Gg1(2*Znb>sBvhHl=A?XxF*odK*$&vPmtEr+!_NaZjTw63)Z#$D(jEk)=U z#{=Fe%8^g~(_al&40yuUKzjp_&Q zaVE8+&2V?DZd9xhO5K?VD2=}+dt}?W-Xi(k%w-jyUIymXZ zuDE8!6_13xOLhu^rF(kFU!qL89CnzPI}EbIp&*UaHsNrf(lyR;t$^u&mfDP$-O~aA=uK?uFR3NzvmGUI(PGC|%W57PJmU4uIzxl@bV-ZmSf3Dp>Xr|T@yAJ0?0sxKlXEFc%Y`fVcY2G)x0EMjKN;P{; z5T?8hBE&&iyUWO+w;qoBQ**6P%M!agFQE(fz2Fb4N0{&LnI z&44`48#(j7w;T?pVK8^6zN35DEcQ0pOOlt2rSwN&-Ef`xY&s0xV6dErqlvC#4X9&Z zfJ-B33Ldd`a$Tf6SrXuyrG&P!IMTMTWHlv{nz|VjOk$7!tG8xi{`uwA?L%&BA86zH zki$yT3i~uaalP@p45Yum1#L?Eh9Wh#>79N~FQ1&wTTWdvT+V`E;w?u5t@Oy`bc%_a z&1>0)7jbCKPG`xJDarCSBdMfU%L3SYff8fI9@h9{*)O54Sh7uhvUsM&#TG>wK~3Yx zTQ7J7%>sPIuqEsF1vF+^v$$T2_DKTpM9#sEiZ%MC}jdFs} zx*06dcu^i(y6+ZE-Z$(~{`lc{D5d^P&}Q#No3{zSKnbH4Mz)Y1aC(ZXLVKR9@?y5= z`2vmc2x|{Wh=G6@D9jjfxG{^dx3vt)yTt~xTfqcfu6nOT7APhk9Cs36z^l276{`U( zG07><8f+T?6CspRC~s2|gVaxkelQ-wO*#t(^Vtw9lvl=}JnRoFgEGC>ihuSCj+Q}r z_%Kk8$g5;f&H@jA2%QulPB+EB9Wp2%ihnJPEhTyP$Bu^f7GUgb77mC0+;g4rXfm9t z1#LiLWf*zTJJQ`5D zPtXVC4t%tI#|b0%ZS1V);g`>2IV%wP4X=@fc`%wdu0!0J>kWs)5QApeW!ZDzxooax zq@QRDiPG9d0^*+oAC|d=%-$xN5@`5rJc?Ca+%RzmT=J z04dC(BnGLJPPm?zL$!_NHfOp_wIeKAp^EjzcNNzJ{Qwa0H9QL2+ImY5D3$q_@>}JS zxSG)_@85|gT+Q*@nmDn$!O$M2Z&x_x_b}T((#0_~qj{2q4txMiNA50aO{U=$0(9tB z@jhqL3m>ve+^Q7s-6bWp)B;p?uy50IUuV}Y!pFL%p*ku(rDoR4U0%E}Kgp^&1adzX z!iK~}tRR2ZNtl`&2Ca!>J6mpwQacyFuQ;#iEMXMTZ6w?YnVRueRrd|OLo8FX5-!yf zp)`usye9?I+<5AURp{Mk`*)6SqvwC58}nV|@?Y#8*KMhpt8mlXefHKUt>c zLR3nD5e4T?!0TF@3}Ubd{PhlHYDQ9Z0<2yC5hh^Y;_d?8osp@zK_rgB;PtYA1+UC= zFss{YnVMxi2{a`+AWB<6za|O_tpq&F#9;mxi0AvMEYV4g)dOcRfGBr0;L8^B#L78! z94-Kcz_iIGQxra;pXDdEd1FVb;29*wdi7ERxWauD6W2j z_@1Xj0ClVJY7q2E${zgUWw;yS zX>QQHj=}muM6o{E3f$|f23ekF%hS9IUoK8(*xZ$TWUbTT%&fgPgzRl;+_t85%hSxa zrR8ZZoo?L0)?pEv?gH1@bzR|36}PrkHcqc>=;poHK5coL8vtEbsz>F8O*9^>fm9Ad z!P9)t8c0h4I$9B_j3-XEa);f5K62mD_ZFQRp;N1m+_9&@vNY4<{)FBJ*-WS}FWE%W zX8sJGL;XN;J5S867+wJJ!H3X*+Qmgdtd9b6==vQhDnsP2x+0dVR(+^%Tc z+N|s`S^yvCO3=UAh8EekN(t7x%D%M~?e7o&YpRs+6p-)UX%Yx`uV;DoBwwFUNP4>_ z0jv1=_zUNdc%*C+P~hm5!~>`h9S}E|t7W!!)s>*OE;>st&jVG-zAgL_2w>WH{|@8* z(cD5>>~=*^efcH@pmKp+9g4 zjwUF(15d&Mqt-YQ&Q=Kru{57KnyGR+TnoHEV2$^od`-dY(tOX$JD~x^(Q`w_{(A@e z8dPSXA3`6ul-FzBJ4WhV1?;QtK#TM((r27k9oM^5IY2GOZ^HOyw!PYHV0FqH@xADB zCS>1gyc$e@lJo>z{-WF3lwH}xTTS0SxU5i@A+X$pjwOYo6OvmrB9+{-IP+S|!T|Jb zgcc|1={go)1HZ-9o9SbDv?cxj-9NycvL-RDA5DuI>Dy2jOIt;ck8nWxiqf^gufy9T zS>}J;Lu)LANi&1APmgL&j767Dvp(NKJiFfEAezAGW?7nrRFnNuEf!}Hg^L*Y>%NdQ z(JWNCs8rNZ)d;qPGGTR|ZVB4C`w3no2|%NtBGtz10u-`_lVqucMOhyCRABMz)-a)5 zT`?o;(=t+eZYrkD`m`)dvt?<9yR-0}(c@j~Mf>f4dX$HeIJ22IAJ0NE98Cu^Z5=E< z&k3Ym3vx(tfiNIM$D}N&fT|hO;_kO#SbmFwBJYy_KfFjvp5ZP^-yeW8FZIGCT|Y$0 z;|s8dM1GQP9=l+0kS@Ue3=S2RW|#Qhd>Odza6TjB&=;RlKs8*~3BLMCa3jkqET4== z&8#a=wJgmX3iCfZVrdT1R5RpPWvSDUb+9%iO|uD2oo)y%xAI^*n?eM{bn1^Be?aEC zjx|t>y%Vl2X~wOr83j%Y(^{fzV1s(1tleKr9_3&D{fEDNm_E!teE;#&hwuON!_WG6 z5S+>SU;mt5K2vf4hbbA(f-x-Vcm~8cvP*%@icB$wxHzgUIHQz~CmBCi)xv9c3{`D# zcaQ)*tvM!mXYbcy!+;fCI(cb-7)&NM*Ub{zF}fypZxpi$^Z9l6hC3K*1geztf;J3( z=sQ3mKlMY`n|Q>Bb5DC1qursEp0dque+=cKkcwkpXUXbje_%wwq}%Qfja8wLRg+rO zYz}Yf?l9dSQ(z|@3`b->3g+|BGuR)4vF>y=*dLN@3z@@uWSKFp@pbftF_@`024(hL zd2cN#$q^@-^bW9RrJt2|+5mAONxju#xk~)kg(yOVjd?v_sRum*Bv2FR@=Wr@24Yu% zVJ}!Py++T^M%!(Ht#e-;G^f0$hCw!Xx{c!~ey(j;-oCoe;m_g+G}Mxs{|*Ef z&lnH&qRrc6;RONA6hu10nklRKO5PXLwn|Tw&o8fT9}sgN=vMnsordOY^;da61`0y< zGc?BUyY?s*d+f!q49O-hofg>Hp@C1{Hcu8Q@e|<6WWmq@3BBzqSFW19VhfIhf_J{v z*e`j$0S3WflfcWyalAq)lhM zSG-vz!nA0{PGKQP;ycP^2Om&Y5FARM-?WR@yZZO~jTe)gvR}e>fIS>~uxJH-ATfx2 z7!ogZN8@QQ^xWYDy9Ij5Hs8=qS;kdjQNSBtBf6Uv3<=Jyyx6jIdX%S#CL1r!BPvmg zc)MQK9XXu&Jt$^7+VowgKOFam)4n@>5Y~bR>cR!$)d%+Fv9cTx5)i$?)?C1I*oJ5) z&4mC_87WRAx~15oJSO8QC8|`9c_st(T|KYTyH0baCm|b+p9U}kY(uva9RBsuhOUY0 zJPgMV!|8)NRhDPFTtz^kMQk+-coZ=1Y|{ET|f*#WYSmqKFiI?Dj^jOKG79QTJKY_90lNVnq3)Y#4t z1rItcV46*BW+pn1Agph;mF?1})K_Y-16WFWPDw8dcjc%5t3s?^M&n%a2oxQO8U43z z6N?Ua!tfFXLK1`nrdrd0f6}30g?tprJH(+OL+xS$tM{WNn~!3EbQFi^bT%<(^!|~= z4$c+;YE;)y!>dX=Eq&-VevOmQu~>U?kL{@Dd6T_kT^!xK$$sdrYM)GCE@t!4&C-Rl zQqtP?J1c#r(%v=QJQ5eNg2jHoKH5V{h07ws0)QI^tqI6ITaukp035&X-V>qQkY42C z>e1^Y4oI-r8-!M1-k-kv&;Fl&_}kMD-w&SJuL9gr+c1p$h-&oI+_&(G{Q}3QVrfD# zpYmu}sLIBdMsI17`YK`q)eIMDK`h<8Eq}oDC(CU)8a>@*!3#?_Ut)+Wq?<<PXXpA;d?2Ww3ukRaX`KnD3g2#(guQm~H%7{0_INzXt9Rv4;lwuom zD}1l7fOd*9SSF{2u&&#p&&sX<%X1V)B(QuR<%Mxe)^%I-*{J?mrRcL|oG-Qk#Q~>_ zd67>ceSNAXmKXD9@a%>2&^)5M`NUy2?7G(RGFuCOlZD>|IqcUrbn{-`B1K1@w_Xim z#w&JC?W6L-Cc|1KL>z`z34!?gLqzvzU8Ewjx2TfbcMQG-s73(whWrh7#f?@Rt0V~R zS|*wfgMQH5YOCd1ZRBN9S^yce6<4vyH>U-E6@F-|g*0g)*;gff;R&T^5k`bNc1qH%giP8eJapxboZt{8UOEbTFB03QcS=Y@JC%yzW(NerC9z_kn= zMsV<^6adT6VHr9sLkGZtLeroKORICVVCd*BbpWc*TGn|Ec+VHVR5$G$h(qz*wJ3vI zbtj;XCNR5$3h4$@=8?1Q6+^;$Wt+D^YjQy3n{F<|b1#hmnXsx;a#O8W+${PW`=yE1# z-)g)XP=As%h3hbix0=3vaJi{GrP#Ek1Yv7<<&dH+s&$#U%=vz@g}RtUp-uEW+6D>+ zZ74BIL1%!8Fj$MC??uzjH)?vtbX43kA1N7zwq&#HD&`$4U7I{RybBU${@0dwp3ej> zh~0?VC zlVSXf{408#s^~6w=ZD^u5`&L?Z!!qyLxtrG`EU$*=kcr~=+lF%C-EanGPmJ8X`Gx9 z5V3}TtmnOX(aKv!t0;e8d`V)K%PlzVJUoD(k|4?#*@pO#b?S4bwBIUXMggEkS@Ad9 zMbVqpKi$TR;1JkJQP=;Ie*Pzyo&r{K(!zzeiGX|{pm|!1CA0sc-pJ8ip@kT&dIhu}^ zbG$XKi@$i>pF5VnnBJD`pZ&;F%U=w%=ol3BO5}Y3{KYlcQHMl-e+w|yr*qN*iYjhz z*8i+fw5Ezadl6j7Q$rWa+IyL)2T@Aig#+hJBk}(FGkz;Y@r7#?imt%i9_gojK zYaM?Yp!L5#hT{W8)Y2Z)eg3xb7a*D2lp0)~L5bUd|5m2prP2>Av**4u7)=}?#&&0% z_89LI){0DKqZ#ogffFo4XXwZ(yyZsZ$no2nII+8N#p)OP0(QoZ9{Kk$+dtB! zQ6uAdl7tSjNEim_E*qqV1NG3YVyTh24AKL-wzyQytQURvFhi(@>TqvE5+!T*fUwsuu$PhH0*?-=^oj}^VwPT z?cYB=0=F}MM)F!^YL*s+?wmA!g0tkQ^ZYE4r=h5$Jt=U-QX`8cu<tbN=ISlnH}yYo>axzLbM7CzQ>{`An23S9IEU&I%x_uazmOf?a>%*BFAM^y6{>ub%{sNv5yp80-dLpSfm_SqA>j#uoQsz>F8O@_4^ zNaZjjZ&4A+ea{+5O947s5vh!Ki~7iYN8ekD-23B1Q!77NPlKX?VtoWbUEzt~OtnR& zA$&mQDe>~fI)b{^@$-V!7^FII@iT6`jU!ffp_(Nsy;pq_boK23bw+PxNh0$8A7B14 zcv&s~{$m)d|Mu<=R&UGbS}PUNPQJw^*q4wX{BZWU^DK5vBCh8Cgzb6n8p zuCi|}C-VK_f1CghaEbe=zN2nMaoyZAUjWAcHr(jKeG!!l{F+0S>Uc>lkZ%I=NBI)! zroGXXfI6C(^g96c2aH;S?ax*T2XP{wIhv_*I-tsOaQj^*ygy)#_n~}Ci44%@-od^# z{TdJl-B4PAb?+FdcNMU&x&y7L|4t~8u?_9SVMBtwRTzCO#&5#-X12ZBh#_^#8}Ys9 zawcToYP=duf0FbB$rE|8pt;rb?SsooY<+3%rXlv!MkY3GjWJwOIJ7Kd-hEIaH!6C? z1cF3;Y@NQMbXC(>&^i=7kSvSGpfwi4gce)0H^{dTZR;Hlq6wUCEC4`X@l!O@#R>3V z@``o*=MNwLDSO80FQBG%zD;8ukHA>z&^#$K#H-%z9^7jyz?KntH+irK+^O3tJJ0L_ z6tae`)>OhGpnvjpM_3If$<@^twLUE)rRS#9TU!nhy^{mCc{`-7oB?vEyuNq;#30^{+N z42Cmj8cg-rZ>psj#4XR^bfGfvqa-vx~IdwWumL!Z; zDv{O)^SBz`O+QHSN7BEdrEYel$?jmR zj>w7WipXkL+Q73H5+|Go zOFtZHr56)4*F)v}eZvsP^QI-By+3~DJqpnQ3Z7BHtd0~rBc-m_pwK~`ssofcFlac-*?O2>Io1Yo!7A@?S zJnL61faPZ{5K;Nx-owKq{9EKrXOBNI7t)%<`JWRoVNfw9k3R`!!3Utxd;}f0?|%lr zL!6iV)(_c>Y$(7=7Oz~0y~#a^pBb&P{7AgVKqI01N>lZFSFmy$zsAYuSgbw&@(MdM zZzB1@@mLqf(2QnEyB~PPJ$^0r_$>&mri)!hF)w7mf~UkxiCqFV?tTpws|{Og3R^oW zHKk_O3mM*1kU%-hzAJwzla;5RzWdMqpMLn;6PyW8 z?FX%iVLMx1iV}2$Cu#4A&~56-2^pI4SMk%JT>4`|;p8>PLe(lu+%h!ttBL)2DK%@c z0~AaKHe(p=pxdfhYgfEoJdI^&E-#WRWN1cLie+qP`+y*h?wBu^L(p-BEiOx`N=sxSgK z3~xdBIY7AidUOlH(OFVjNGt%?_-b(`g77q>4GW-0PDc1@JZ{!PYG5I?Ii`2ac;8S4c)w(X&sfG=Ttsg4r_Ig zVl}BwWOa}yrW&*qp`%ri%6Q6=Px3VK7d-b$sccJw+p>*UFl(QWr_IESVH)nEub5g_ z`{)WQT3UQ+fKPAA+hAARV8yXUf&jCnZn!Y&2DCmEkHfoSEsxY--|A1LiVl3tHJaqNl~~Cn|Q0~+Xt7GSQZ49o6vFPkfJh%L)RgmsV&JZ z8j(J=WYbw|i`TEbC0RlBVoWH_Iu>68zx@rpDE+PavaC-46~*HWd|$MtxV{a%(#N)n z9(^|b=YSNJqGP42n#!X2JVgN%k3nlJgh?~??2QfLo5Zv09S))ioNkt-Sx7b6FV$jk z7E!o}lYH@oq={ys%Cs3O>i?931lSVFgw=VvB}iiaPx=`>f)%kA5pHPoUh=x|eCjM_ zv{2G>;43XlGcacT8Mx>++C$2S*x@fwI-1vurB4|+gMn*HSlJR*u)nxme8*Ta#BR&8 zCmCgWS+-r1pii0W9)I!tSGJ!YX+0WXSbQb%04kIR#0};eU0TpQE{RG6S)~HeR+IPy zERK;+eom9OC?F}7VDSRK68|MmR>|`_I#%G*ekEz@g-N=GZ)CJHyb`~3#$d!I6j>O@ zvNW?>_ilY!WaP|dvynTW4yT^4ElhjIEX~X1ay(jk!36$0osMQ`2OiAQEYG^~)GSN< z2&gL;B?nxz;lz@#V>N7SJ@3tn0Om)lD1TpkNn&;u2u6h^9>7mY5ao+(L;NU=e6NgS z!??(@G?$3H7bP1C-4w3@LyiZLG>6NXK3S2#AI_br@9RjD>k<{%Lvi}_?U6KVrV_4CacS?NB4ZN-7xTY}&vdfL z_w^4uh|Y^X9bM0CK#7|fg`BVkB_myhnR)Cx1Q74iAB+c6Ps^Nr7&G%gj);X9me2*( zge)`j?JzU%zo&QtFt`OMVvYLFa$?wnS~%DxmF3B1qX;XIbx{kiPZlK;r^ac$Yf@4! z)|D;kMaMHUukt?Qu?F-GngB-PK;;+31rr}xBrGgkr|GMvvYxli6JR{{DFd2B;wNpf zrY#5NDvzSHc4NQf`DQ`lV3WYh(**=7!R1O>3wGSFwwt?PX9h;*;e5G-|M(+!L@>ks zb+I##TwrImDaI7-~ z6I$R5Ja_KSft6YF$q2`~I-x89GH0TE-n4|V7sJO)f`K;)hSTL_6nXn@ zr$cpa_b5RZ!N;r!f|1-;ZLd1r?QUt92cwDOg335^z2R^e5_NjB=e~2{WX-a=(ZYOb z$(l<<^q~jL-Y@FnUlLifyvnjU0$ERbCS=X=+nPAB3s(Y0GZnh#-@|PGNS8;|EYFj6 zH*g0L|8Psy%v9bQv--+Q*PXlWkIGNk&xBiFVOQ=~#IVWYg7yOTZ5+Z|(SFdHK(@0b zr>Mnq(IiQB8GQD1n?G_&s%G?6{4^-_iDTm76^gP{&HRpLeiw7*!>A#8Nev7s)kJHOp7yi9z%y zOVwPx;|`03H6(Ve%?2@8gi@aC@pb((&V;p(djX5P&%qM+u~aWiMB*3>UM~v>y0xQ{ zI3FH2+|eSHLQU4p;9!liJo2ey`^Kr7EkH8@Xg8G3ZCBiA#Ve2;xd<&&T-sqWcf}~y zaU%9t2IGic)#hc(88g>M)hx>sMnfGi%c;<-N)5b!cniYM0m9AKqgx1$&XQ82yikL< z1>lTl1RW4y>DDHiS~z9|$1DK1RL$JlX92hc;8Ye^;RKd^0E}`fQ>{`An23SL8>UdOptNCo8|u8VGw<84*qDEK2_8 zlV%+5raa@8h?@87UdLd4A)*K_wzIC=N~y)!Q~vidqFr1^Q|rS z=Qt{P2!at7Z5BAOzE86Jdjg4+tN_Yaif^(jZludqOzTAn8B5d*2iJv{kwM#beKADM z^4)ymm>YIo>&Q&4vT=H4LpSfmjbBo$(Nc=cXaC)Q_W$(5-<~M98eXw;sveaWHW}7x zAOgi%4df8HJz5c|2rPnFH=&O-g!)*TW?SIU>LbJX9eWy>K7ydGD0#Uk9j-;mB78vR zDe>~fI?A#reqOM`hY&tk{)`)Mdu_~f4s#+DKNd z39D?td~y$o>h6%vI_cDfZr$eLo`$A*zaSl>1#k(%!r3a+=zQJ?vkfgm{goQ5Jt@@x z=JCI#W`*@fV6=Bbkw%up;4ps#776aKunNFK{t{)%<*@Swz}>@YuVxP{eV12CdJuoV zr|(+0_lnNm=WN0IJrD@-;XhQBrfbd_sN+htK)wmc9~HP%H|>qC1k}+4Wp@DT4;Zz^ zk#M$3IEcM#dERKID}?t4tT7yh+YksCA_#h5)}~6WDNV)e62Nm085&SIl?j-f{DoPm zo%6wclWlLoe#u{DgO3bIdv6Nt+Z8uhagOD|n5()2t*O7m%wD8LX)Wh>g7gK?q_}7; z#&5#-X12ZB!aVAfH{yHIIb)u_qI7NW>+tqSmib@vcqXn831LEuE!xwDf}~fk@`$$eI*4dO z9S_u>toJ#HX1X{5{!5vUg#N7*8&EWZn%4O?jd?r*BLGD5s>~2~d-H+7E7q20{Ns=R zwsyby#`z;B3H`8k|Dc)Ll6>6KG(V~JFw8DMA#1ow4V5ra#R^S*9i!hBW?WdGmVwf9 zQ);eVaf21FsJWJ=nO$TT9@JL3lsoll`NIitGy|>Y6o_6&b4$}q(abuc*bDyXJ1+6P z`7&_b;e1BMAtq?WVOijZd=liyvI@)HlaKIJJnQ)W1-^Jo)4ao%^#33vbwz-;I*AvM z#kr1RPA#n=tuEVB-uned@Q;wR{+Id}DmXEB4gp0k?VdTo1*MsRbE$`0;{vm#g(j;DkbBXR0m|Fcq|5|2T z{qpZW{N=;+VfNwskDorQfA+jj`u2h~S^w*w)63^d9*{5?4+eu}IC4VY)vjqtAeTj7 zXg(Su<6skPKrtuVPqlW1x-FBZTY|f@9j4ncm==z`UyB_BW^|-`uqVjOj+*uEp)I3p zVmAk!OZHC_869nO7$F_)sTcv^VG@zJI~Z#uN~IE?`xDmr3i=3s4*E@ig3#7o`xP^)FNYy#31(J#GUywG6>0Z;0|X~ESt$T z-#{&sMHxAUf4u?C0muUbZqU_)`fOG(Bt>qE=QP=FD1K9(BARTxG>0@Z0NwF+y=2u> zbdN03%oagRbI?HI`>xX;j{C!De>Acb;q*3Q|HvkJWRB;_dW(pyiR(NJ#}C8l!)T-| z&vv1ng8JGlmEzAKs0&ex48btUoEeB~hy`02e?7tW0jnLb!a`Ym-JX#aD zj_H-Bxf8b;N%!2s;@1n{NG6k!{vmH0e*tXq+ce7Gi|ZP&0?YG8XLgSgYAdwcQlp*O z7^!phx#XfhzqpELlvBk)omu)bM(5h}XO@V%+o}~0*K14v`UQ96oxQhI*1Bb;Fc?(2*1Do$w{`}Lf9Yj_mCntPW{sEt=yR?6`nGa=O8 z#;}f zfU+xYwBnTjC`+kbUL@B?sg1A36NBha;5gc5-@g$5^+zvS!R7w3gdpPPw23=%)RP*w zY{>sro4I4K2&FvNGmX?g!vt`3khOo@3s~G;gtb$vjEgYop}70F6*&fj*N-etl~SND z6ptJ3XpxH00Ld+-HXJZdP~PS#%d;o>I0g6ac1?nQnykpwt8(M8e9v-<-6k?P#i76 z0YH4mp^TL~bhUJ0@~)F16D`1k@N*29$A z4SC+QM`N^!Y>BRPsnjCUCka7Y5su&E;cUv|)QC5w$?dReH)(&zz3$iQ2{;IZ0Tp$wT^q%>KmumH+1uErgl_%o>Tj1IjmJeiq&LVkyS#p zgzzWVMJh6Tiz-P&z>mJjt#Mkb;Dtg{2TJw#P%7bjD0NUI18T!sOzU15CAj{@%W|%4 zKx|sia&6FA;6DEf98vT0ZYki$b*vJ4KoL@ec5Tp4he1DRZml-LlZPpd;4WK|Q#djk zytq$9zB#2CR5)<07Sg1JWM7k5y9vB?;Pv1lVWQ^Tv%awx0CbyA!d~%T+2eh4*U!EM^rBGYj!9=fhC`0 z8OauTl6xz0=UOD+gyc;k5o+U?>ZZMfI`!$gsG|wY?f}&vFlr6BKU+Z@#H@Yppr*?4 zpc?ot6W<@O$opWvrVwC>;5iQk8c>`)myP#L_Ps^>*4%H+{lz~1(Bp2P?^p>@5%zb- z8Qm4MuQ~*+vH!x1{gu1?nxVc*+-gC76Ua9+?$yG4b;=t7zUXo$Xy0nQ8c=_dGzDC> z_A)_ptLfVZmz&B{HlgFnAw^|OF0V}grZqD$8j(GtDAKvsvKOqpC0S9_qw82efA}p< z1E7ypUzQCPKvnUWR+6U0jr473W=UI3k3O6Jb3htP(XrB1lg@$`qUeHzSv&`6L_(T0 zQ%L(T@2ln3E~HR1M^I{Z1C_MP>f=4jt<43E36DVDZ4z$GZa|^%;y8NfZn?GLOcZl} z$6Al|YTa=fz4dCbv-nQETEv}?Cl2u(GMO#?aH6eFtEW7nQE332A#TdAq}OvBG7Uph ze+!mnQJIhbzX9(F3?;o7fADE2PpaJ7o)>ttY3R+J<#09#aF7Hp@MOrXjb|MprruZM z);ge$qkwhOjS3z4Sm`M&C4J_-rP~U?3cQ~zH$3)K)mH{Jvw$*h6*$#-jR*p7I_*9&U`fN6CyR{tE@F(;A)l*`ERi5+ij z6n$Nd>%L7N|Cs*vA)napCNY7auAu)napEYp!`Ss*;e@bv^~mcIljyzcTAf3hS5!gD zkF%bw>#)7?d9*kFI3~YOC!at6{C6nW`^Rba6w0R^36I)6d|)O~kAF1)*O%ChO&`^;X#2g13cC`4&gv=1y$tq+xH)Bg0Bs5ZH( z6`y#R&dN4W8~C&hXDOK%(}zs3DKuu&y7=`vOM$8aBc&kyo{hbYH}*Dm6Xpmig$rh% za6`L2*B8~>*ms9+5MXoTg$)Yd%|_{L*&@2x+}L;TK!oj8Fgu&>##`*lMUr%_u`Kwv zmGifo8*jPY`IxC_ZPtq!ez=TI$;6AI7<8#aSj7DGv{QHw-P&|oWVL$b>XMz!P3TcO zop6%9KCJfn#-m4={$qOo(t%553N<%Go1J9TW65Z=|mJu+h_5Qp&bbB5t@*p!>+ZtGBy>*X31~z zAVBvj#-w6>SLy%T$lo&7?cUs`x4lMd1-vjS2V26(j+PtJE?>JgUZY0XZy;KW^4w#y zOQ+NA4RJKNYRkh9D zJ=ogs8vxqf3-eB~G8&2m-taKZlHXbq@3FzRuZ8x)TV@&jXTI?NuBDnNk8_<>@bQ<= z)~D~*BG3-d%c0|r?rM@_v*cQ@VvzYJa`5A9HcA=fBTP%qV|?z_a?vF3Ym&Ddde|&E z+hZzqgA`l&gsM=7#c!76c@={+SkzWk1mohTyRvF%z3(6-dxP0@bYr~L;1s#-x3Z!; z9^5@l@zxaVV2H1}YADtpaG5scq;$)%{SWSfFP5Zm~b&+=^}_<+Ybj! z@N7Kik`3^(hZ#0Y?nQogDLS~-++G*>oA!16kt6Ziy`Hzlf<8zUqQ;(6LR+gg^G4#X z`ox>jCVE^(<0DmdnJxK5a3yvrTXZQ?>ZHq3eUGtUuTkwZfJx|O-D9idh4NW`$G&8f zMMpL??N{q!fSu?RWlEo0ng(>uk-=Oe++|U~1zRO6E8uVuFS;$TnKr+x9}mY_Sr?_` z)vJHB7LDm1Rqn!3S|zu6*#qT31x%@u+?&xg?HTK0 z(CvZD-{r9gL8{XlA&9%NQF2?`wYBoQk%(c7T>~Jw?f83ao7;(bzM}YhobgUG-UcKs zdl`Et>@nb{CEJZ5Jcvb}uu-xKmtW@ELaf)XZO*(7OYIZxuYfI-(P$NXY^UpO^?7V- zBD)=ZRG&B!>ge;h+eI7NQfjB>?>7iaIi%oMo8G~14{FS#k4UQuXU1f786LKXN3) zzSr}%nDhrpPtbS>!06{`H1`sp$y{EmT(cy*t7x(|b<^g;8%j#8v8qnNV!f&Fx6&l} zO`KPWWQX*XwU4f)v9zXP@qyM-uJ6*C;(9H$=DNOKD`vDg+oHa9ySt&jM7bRl`?uNS zP+zu*B&`1U-?jJsmu}sv3!$iWG0!Fy8CkZeYkh7_LVH-h*dn=_rE(Gu=&G*QTAQ=h z99ykbU8YmR@@voZ;L?)k(WBJ~^PooyTO?~*A4^#6vxJp??4FrNOF&aN8YeCxRLF>L zOphsDmDO7enq3{%vVZDkCs)!U*%6E+lsk@>#3GQaeNwhELAtg`Zb^OZu6aIXDY$JP zmd)7GS=GT2j^$0wgvkp@M}(%Mw0M1hj+bSF8t8H>NL~z`cE_T@qRH_?J`)Ul{dIN1 zHKYSsD(BwHc!M-bqiS=PIN1_)c_|dt$X;iv&+|s%me=&?61V9Q8#@rYQ5-=AZUl|P zZ03p^=s^74kDoV42XM$0G#>Vt9R@xRI1N2JTHABwD$-lQxh0qO9uLitxQ1A(qp5M-JQtbinx`prw=2VRHaJ7eKSH~wMI*e&Y&r+^Tehs(aB)h; z57jXU-S?(49hJ(rway!Dh2K#A_03jog}Z)2fx3OS6=uPm{~OdMe-vwP)T^=Z*QaM^ z2-b)#U%rW`7dCW&JU=J{&?b<4tD zW1u%xtN9LWyYGZLgVYJxI%nWq+-semKSLJ_^_ai^@ad-y(Ovvu(;_y&n`R+Zu#DD6 zI|dX#P9HO{>=Zs7@FAGCFHpYKwq@$P1ok+QzkdyyapLP?jfI$y341L+FCxi@dID<7OqB#t zRxy;#UHuUd#Y@T;OS$?P#*m4}G%vE(J6Pq5dbxM$)OsTMQ_7~<%&MNE4XiQS#$3YZY7D4Qi0s8~D->T9E%c+Mm3i|`E0ceq>Q)T_Fha_up z9Gk<1t|puVE92i+KVHBwPD^ z13h|w4a#Zdcw6r;UYIG>R!*=VnH9I08eAjDWR?P2Yw@KRej>kXp=Q_ zr}{`$SY>Ns5ZoR+1h+Z_AJE*dSLwU#`^`0L2Gi%g_t@yt=dUhXf>k=#_93$Cx=70K zrU!8HgHxgz%Uo*4%d1#}by>+HWIAX^TszpYX3$~Eu|x2}Zc=u@;bLA|Tdol=v&ss6 zt15r@d(=TU>TIi0A{r~=;(^AdHk!!r>jZa3*mFLEEaG84pUtLOG3;VFEW%{C$XS-o zibW2~;L~^O?NZy;()Re8(!grW*fG&Z&&MJNsg)sukPVBz%hG*M^iO-Mv^QC=n4dF+ zB)1)dk7eXLg@0UCNkxPtJ3x|_wOd1$D!p-$F56a+*dxpx!T|(rSeeMTM&P$(i)f^( z7Dm4253A6TYN?f`ZN1X8xTCdxo`^!;LLq8#o~}pm8$|LR!icIR(ZyE0WxUbgBMzO8 zdyp={Z>*&Ez<_EA)jDT^%KAkd9nbvlwxiJ}QAYe@P4(LY0N5pX2LOOkM`!MjXdK{| z>`-Vm2d&RswB+BiFwkzu^u_>kdIA`}dgPyAQIz zah6}QslVQa5{>+~jQnoo-qx_8b&m}@6(#(dNpm3ulh{seJ#Tpm7F*GIO=8X~w*)>&baY z<-=rJJp3-Q>4u3~I;zxKZ&jr#r%-R2Tx4_6S~36C{@uETz5-fLKSaV!w-c~lYi-_I ztuUxHpE9*z+r#bJr(rrti)ofl9$PnnnLCR*R_N72uNJID%&lsnts2R~=3ivmY`dTe zHo~~J>TE90ibiZ2*p5etYik@m`-Qqv2DV3HZadUrB;45I;f6Z}yHUuZ#212!gt;+k z9dv`152tIV;Fi?a?z-nr!E3|b)+xBL%+xwxx9taPHh)-rS{eU?`DB!iQ`N+%^-;62 z1Q`X#=|J4J(ge*PRCmR3`g_@UNtt;q-3NVxN90A6mn|Sp8yam83v^FQ8C=R*d)u^zKwHie$6 zt;t!OL(q6qys?EUwG5P{TBm(Jp-kg__ggKzyK&0aV96kTf45a=&ZRQqhF{YOpMK4U z*l~4|i-)J_?4eXm%EZwZQF(%2Y{ylHB+}=h@I>N3&%rh{zOas~?$GgVY`LnIWcg)2 zHfLG-0=h|Wx$5452-|w{e0r{~pRnphm$hW-f}0i`dRES{cv~sRe8a(sp{fzhkp$1z~P}AaVBI;CFAQoH{m_>R;-@k##QRg@gt5Mz2Kk&qkM5rRV%RnD^Y{%8K!Byz-^O1it@XMf!`mmsOA=_YXja?xnBQV8Mo3}F7*sn_c}<6);AuyC3xj%5$S8u z2JP`0waN}RB z2Q@O-*cLvF@u&2p%G<|$+X(*8B`^(W|i`JzLakz4ojdOSfLo3E~ z@tY<7uAtRm;ixZ{%aqSY;!d??S{1ka^?x_P4b3KnJCx3#{Tb1pu|?}jmnn;T7lV5L zeW89_+JP70Kh1$(N} z2TRkfref;AD@Dea%|)<9>+zyV)&>5ieO-U#NCtJU=WVf|4^sQ20eY3t)@oe5kuIn{ z@n*D%9+%PhNLABfOD+*yS!a$xUf%O$`gKxoxk@DsWL||fZ@pwjiYMhUv-HT%c4+H< z17G%4_odg;d5^JQKd2?+b1jG7E8GPew65(!EFz$b1RJz^$qkoB#0IU^k%|pkFCplr zJgyskH|tXy`F%ZH^Sm3hzQNw^fy{3&lrE45AxNbR5rVAuB<`|;-i<^yskX(WTm>L` zBiQH4@7APoD2?O9vPqpd&ofI6xr(ZyE0U9_ROUoOKR(Pv`c0|Kh&wAW^@SfkB_ z%g>;C^{x9OuvO=+wQIr|?=a()d9M<IAcZovSnkcYM>`NHGJwKrJ!7fJj9&Gv@p1Q@fKUyiAR?D8_ zhBIBDb-%+Dn~eMoWxbd7dzF6PdfGCoum_X8QJu4YxK zkJv>yD`h%n=Tm~iHOME7Cd99LU%UG^A?Q#XRxo{0| zZ0vS)BduBA#Cf%G^<(e!m9>wqrLnZ8Vex_1Qm*gPn&NsbwdT6MUMnuT*}qX=yB&hm zmwCboGoo3I_ zKK+5G8QexaqG1ec7ayR#PCn$*F@gD9tsz`F{>Xl%N}Yr^*|y8Tp!|MYpd zrH#rd7o%1e`;EnTiQSbx-)|9mwQ)uy8`oV*>q_74kKJ$AQ*Ug=-t{Km@#rm7^s%B# zz8j@rx&K)9<2I-ZI7$Cd+9iJ`g@kW67e)}_x(>w>@-qwTj zNm{yxngFY#@!C9Iz~U==M=Oh2y#DF;f4Wa2`pX|BAOGW(xuX}F{umyON~>vtz5ye7 zqtVhTFuVoC7A#)l9N#@Iy!pKT&~blO{DR5*Ty}Z-yI6JJMmzqk(2*{2q8p>bKNcTG zg5<@A=|p^h%`=7u>>u(clJO6aH~Jwh@(-DqjZ#MP4|T-p!wmAOKuQqmE_mfy)08;u(GefcO(wm=m^YIE)zJ zU>M-j=lg9^e~Zj-eeS5%{O-?2WBwh+{GRCi-DmGTwtVZUEo-4)!N>EoBA*GSwUsvOGDl+AKIspXVpNL$(Ah=J5V!T%>r*DSO-6JG>=>rCDVp$DYYv2d z=oMEno?-;P@D#jpgj0yng0$hu<2{)TRRGw~(fv!Si$rEkL}5M0`H)Nshz@7ZLo$1v zPyUlmhM^s~p^PcDEj#v|$aQ0fB!VZ7fOxS*%*4AN%Y`J6FFG902#i!E;@LhtnDHpE zTtk7XiTJ=T++@4{{|WqQape zqn_mkoJe@rgu@I+HiVn*O7+1u+01p9U@8~Zj1TRg9yV|N}6y> zI*|xMM@E5dOTprO3%U7N!9lQ~k^|350!J|4X2kJi5ZL=PrIdD3Z(A!zTT;%9mYnbV z1k&C%3==R}IcN$?c#$7S*NMW&mv9^%a!JJ^u>FL>Az=9d%xV;XlH%O=o#c>@C6tBS zwf%rtU@QtaiKy=rB4c^bl?6lY3=}1S#{&Tx3(RDD z@8@k($eboDcAe1S7CbeKVi5@*%FsRRQ2-K+L&tN8XR(m*7$oh&J_1YmpvqB7Kk;Li za~BYw7jOU~K4H`ioqb~jLf?$eS=LtwMI0!%pRaN$Qj3&I${$ljM!-T)(jdtAZc-19A9 zFuWk4iDNS`k?`A8}~`ETBB}-I#_+1e@rPkBvCk!W9H?rI~A_?;&87E0>NBh>t+G7ESkR&0Xm@M#O#&HDXAN44x=zV)dvT=jv zgq=bN50!hu6JVl)O%;Pj#__{_+sN8u6ULYbBmuXg0(}u!H<6$o0rq^)8%TRB_(8x* zcEiNAr0)v?Y7)E#u`l;-(CCj%6ip6JKG?T`14lx_9l--wW&761+G8m^(4%%7aS*al zrfW<$ArwE);J?p9mjrUmw=0^eq$Amx!#}P zGO8Slu>cXMY7&iddFu@eHWo_`UOI>ubRX|IHd(WmR1Rp*WQ|Mj`m8IdG+ZAbe z3Uz>Ts63`hj;&?F`~*Rd-=e?d?S^tkd?`0qU83lHQ>(2`t@wW<6$ouuRWxIJ*y4|>yfxxB=&sP$^FsIl%tOOakv_ix+98SmK_t-Ttm^A>x5 zn_8k(Sus7UIIEAX5Yin~SD25)o%(IVNZ8&>ykQIMT-aG30#tTB8A#jq`nArkt50Cl zwhszi9-@KP+S=>d!EMc$PA9W@S#k3;3rdG^Z9}$Ju#4 zjz;6WXM|_X;;g^e_6*V5=2*-*2>*+j#96<&VV@cG{KaxOy+qK08A##0!8;>`Q`TgM zqU`Hi6Dge5Zn`E42WPxfwWo@v0iL!^+hgg@PNh2)@&%~6oo#7tvIbeRf=1gojIF#- z!xT6}3TORD-)=GiI@|X4waP{Yr?Mx(qP#%{r_Xvi4+3X>#Jk${r!LyGQc`>6Z~7F# zK>}w70%uLYkSy&(Q3ps$wEI6JQy7~*+zIBRcasJErWMD(l5U5+?MmB@&d{vbo zijr8L0K^FGw2j62HCVt4)s|W5>z?7vyHCgoF+$fhgBU@t_-m4zrq9|zNLPdrOfpz$ z!O|c^jDQ#cF@kmqm-_-S0%8Qj2seijmKMUo`Mb0bDzu>7rH~L%5(cZ(fb($VpsyD? zKfugXbG3vGDOa;~#J(VUrpOsZ>#t)V6IE|Clc8wIT7P}W2L6AiQV(n4 z*=uaO$&xk-=~n#9hE6BwU*3y<8M;9DP=P6lEvUww2mz%=IMl*}dU%@EiWvfj$q-mm z3BcNQnvfH6M?HpkVg6-izLB+zSWjoSW-xT79x2e~8Uj*vUrpm)%}?1t-N z!Niaj_g<$007%6&fs6MqpD%Z0u$nMWAf>P!*^_GjDQ z3X@}K9*a!QKA0S6jTl3r&OoYmB+$gc3mmA<3r%jQZY&{_b0j9G>x7(;$>}k~3uAH& z>Si4}^v)D8$?aB{9Fq)MNCcT2WOBMNIhg+6DJBFev_j3}(V9OR4w6f&(uyh$;(RRabF*#69W$RuuYWpjS$uY?QnVk7-HqDA*$3it&y0a|ZiP=4!aQziA zIXL5;W*nIuWO9mWmQEfITbR#aH6fFOOiq6$$FQKzmdV-Gw!c;;2RaH9S`7Is{4k=U zp@i<|&Yr{=JoXcAbzTGCA)U;+Zo!?Kd;1o7S|0_}`4lY2V$n*RGYx=_3PVa*)ZHKtt@Z zO&=F8>sxM1^-jH2SV^;Du1#w@UAc60a zNOC)HxPx)~C&36^C**_}p~nyrBQyyQ!(O`;jL>84VB9{&?Kj*t>Oe${ptuRFz~CZA zK#Xu>7-4B4oI&-@H4I^NX6eiv7z> zWGnx&Cq3VV6oH6Zw&O_7Vu#tD=LI%F|MHIhWlg{dPekmCB(yEx0bxt(Fv*~HXBcSo zK4uCWC{qAb!cG%%T<&PsA)Y^Xq`jFz-Dta^bYXSzFKc%Kj;3NE71jVT1?*qmrKB*x?%E+%KE2{|s4 zv+EGgpUKhQ%%Eg}$JKOeG%;Y?ge3e~Ah0ln`Y!O*32twiW#P>Yt z#=>l5a&}~LGyyZ)6_Fi<(zU`6Zs?0h2qN4#b~PIknViEhIXg|rahaT5hj{)>j`n5- zb))Tu&PYZ4AIlKh{@50yt8e8KNn3b{ok%P49H@~a?Jy7yhj!MQ4T((7VVRuX6LNeeXO|&f29s02nL*uX zyP+48Q{UaR*RGt&=_CVWa*)YECI^|EMj#ee)dpegT2&i6>NZyrhZc`_<8 zhm=Fdr?hyzE1uH4b-FL>&fHB#bV#yEeph~2{8or;LPmEGEn1KX6Q+-ir;~Ki&URao z;jK4q*aC}+%IY=#yE+~JU*m!U^v1Zm2m!g$D8ab>V^v_- zX+lnj5xTA!7$RbXj(e@K?KOR%)WhJiiFP_1yaZ7v-nEG>ld=)}#My}jt|?da~ zFKYs}T@t!dh{Um+fW-l&z85DXl$2`59{QIL=U?7wLckgV=2IEv@Sl6&P4C%gI_F=Z zV&v03nGFTWi=lHL`wi7iMkE{G|NQO$4FB-yANQN7vHPMdO8KZve(O12X6@`c#PjEl zv^O)T8*Mizn{?2n4~uqp(_S-b`^)BzI?G_ipqKJR?g+UfwGdWc$Q^+!kUMg0%oM;( z0n8LQVWxm~rW>p# z$O>JkG09^F?Q}&9RSA&E*$0yoB|wu!l7}GR#15DrhRlnEpLnr`U6IK-5|h()LQcr! z^cdoWF*ycxqwNL-F8eb%Cb``TlVg$rGC7zjfH5J5iV49eAU||{|DNRed@T4dn~sF_ zcfy`afm<2;1pUyS#l!_K2!~|J#9P<-fB8CD#6MA?M@g3_!e6uLzXdC{#z%b?*-Od< zT=oKS>SY{NJ%9sL`M@Y3H7m=ni;n_YosLJy6wpvA0YDH&fDWidp%o?tk9y#75!#`z z?GVHWN5TkQC**_}p~nyrBQ!!+Ome#wj9`+%N((Bzj=dTgdV8xAe(_)Q_NsmH1?$40 zw->#==4w$SjmqrMZL3*rY6k1SXEGVvYP3nTbHk;onW^zE1L?|%?v zR6M=@a3t=i>x7(;JL)mS3*(Lq>PFiQ3d;8PFPr3M)b>}DDPWQTa!2T2M*lMUmls4~ z`5oE9@}${~Ekyrvb0uMwi87y5j39+Hg{;yJ@L_e4F|gZUH6eF|+);n-$grT!l{+%o zwMN_iR+t>=Qc595fH5l!h)-p}Y|o{{OE6QQgDQTT$$_kkFcj3~t`$d|#j)o)ggF8# zYiQUNqkxXYF}(ikKXe43Nn|CI^`uWOADL z`zOGiKTmloQ^8dPzH7TK)_fQfi~_j2hWJFds-omjoI+D?O_VtF3MqR3MAkd_fotwU~5WP%hA<2279h5te2CzX{+7yoWw zJcrKD>d#HE_1`8tKgh)-PmAg8W@vvz?hs}CIs}>5j*ORcO2pcFgeXPGpHMFHz?mojCkm=q<7cp$7ur;~N#A1+=3l8R7$tGLzj^2%P( zu>{;s-KPwW0IOi|@t4ompGBe0+)qD!+gb>N>2q^j+C0LIDtjlNzru;`Oe0O7pf-Um)W<1%N?= z=XYh19r0TsvI!a8fsdge69zO?ORSBLji*3tO*3G??i#;sK*H@eZJZ&C2pqK`{=59` znZ)EY&vb*;giH=HIo)D%IxeVlVse^8Hrcg}{S5oKr82IW$(fNM9nT2K$MAy)!&pk1 za7#Lo2tr3jfo)5{Vq|i5WpbJVW)Y7Qn#eG*IHinnH7I-xdzke0exb@lVF{|m7ij}V!X0c%&)4!=vM))NG|q->hatcs)4 zFy-p@%>bEZw8y%8+pdPMcG^ITJZpXs{)RC*6H#n2luc&1(NL})2QeXZR2D9jWR#0)juz&{GE1r9cGvc- z(u>)otiFE;_x2)1ii@0O=}bBPmBdfN6|yx%DStf{qn4DrI4 z9D};ic0;)%dNVmDxoL~N&D&oQlVg%WOCcbWgG|oiY^c6tga$|gnH;QmT$#DXQ=^W% zX&Y;>hU&jnmM~^lRZ2$vSCI>lt%5N*RacdE?<$SSF<4E2c#z3iyS_GM#p@1$AL+3vB z8_{fA;{<8}$HGlwFSaSQSm=6`2GGiikx(*>$vGyI(|baW&*bbf#LHlE>Nhi}o86h5 z`tGK^X4LkV&*XHH0Wvw5U4_|Im|fMt)X3c_UIDYKuujgIWmf@;t+=v zs5!{1%Yr&HCZ`_q&bIxnFgZ@>hMYkoC1H6yOzb#jQ13YOJ%%wk6<-dixZ8p--ez*7 z;Gvr&5m05e@SH&X6gWv7ImqOkgvseTAtz*VdJOTxm>h$;*#nbflH08?IVKq(lY>kS zGC9cPAd}OO05UmP@mMW~GiGuORueKg$mH~AatsUVT$vn`U2C-MZ-vS69PS20N?>vr z6}}6_j-gVz!xKkhOwQYhu5U9rzH}3Zfm|aircogMI1mn0BMK5v!>;Qop;{3=%&vM* z@2aMQqw9p6kjd#W#0z6`4C+SP4a&6YTqmdI?M-qsYWpjS$uY?QnH*$tkjX(NM`_pP z7slj(ATTBedsm$^lVh-&kjX(Nr$3WpSWxH6M8qY~9?W**kZRZ!nVbXmu4*zlT_@y(Oiqs>UK*3L zUEOHALE()4OpZxzMs0sZOpZwg$mAfCgG>%GIZGC&RI=E+3Yi@2LJnJ@Q9G|$aRs_U zAF7sS?SYDT0v=x9p^=qPSNOu0F{h#ML#bIsh!Kv25xP#u2{A&CAtFX-WGb5Eb}Jac zBm=|L5FW=v9 zZM?A9$jd$fRX3Mii`mzpt?PuG5F_*$B4UIFMli|kRxpA|28a<5BOpdVjL@)}pAc_RCRVS%L z*L6Zp$X4|j;)StQ26dxxx5|9%AN6XIn^D_eQPitR2FO++TZL>DvQCt2~QXoR9eD|{6M-+6h^*GA_tkA zeK0vx+BPSGM2_W>fZAaY%7}$F~8UpC1Axg+F`kUK)|sKK0IrT}tBSl2>rh%>HhVX&HzJ3{WLKX+tUQ0K}W zne1AlZGS6F4xudMuI&fJ@)9Wob*S$H-w;cIOwK--9LKh)WRZv?3s@XzUSRWpJ7FT+ zSi`Ou1$3k+pso{gLMErj5HF0$F{m4DHz?DpKa*pUn^D_e5tCz*0Wvwr&n0EESXDfs=wf5LTqqNj|v$@aw-?fMP6)EM*T>Gm*Dik1Q|$ z&s=1$n{KD>QyOdV$HB*6K3jhlh2rHt{q(J-7GW1opPS>-=5et{@5$HvKA+_GWHuBe zFNV&2>^CUTjIihOS;HJL0%8Qj2o*q3<}qdygAl%mEF*H7jenkUp)}H%Ovt0)X4gmY zl!^RlI^ysNr=>3IzdbB9VXCegv~^pN2~s?a(>zZnkEISSpT78a`{MZ|Ey|lTbYLR~ z7TzNllRPcb7x6#}P}g)`h;?N?m}Th;Da!X0uYdaepXlvX8=@h}V|POi9cssp!+C5) zQu-_o9G3~|g&tNMI!Q!m*9lqJA8Jolh4k5II_F00wtKeSl3iYqBF&4GDFyL!I!VX# zar;a!$fG);njtnezf;5sKsb?=SJLP8OaAZ* zcq?TeIR}d+|2~_}XX@JZ3qMU>(rk(t0WpGFh08C*2p|Z=2!--nFJz@d;jQJzzj@^w0ONMp3+>q5tvrv zDW8wT-DE_EK*8pB<%h*@K!!}n=nhV%f=n1ZrFCRAKDMG(?i#->NcJd-N5zzEziDIK z|EhmJp&vnz*d3HW|W!$FxKcuu|{1d;(z5I&%}3av=k(K6es7Le~j7Ax7viM8pUk_u8#s zgdS@LF#=+Q6+TcuAx1!qV7snkyOBmNc4U zZ$2NX(X9=;{>x4qp&`00d%#eO=Rlnc4B5>GdZHmu;6P6_L>(RIi3T6Wfu3kWMA{Z@ zFZNrhTS!CKAvCs$V=<^+C<8YplDi}fU94O9_96bZ?y^Nf{g}ovvl2-{DL~9|NSF*U zPT(XQVAlzO;}}liCfqq%zG06cUKj^xP&ez=*OxLbsLr5z-(E9n`zy*f?6G!`14IsR z0hp@q$N?(!xMO4~#tC4YK)sQW14It+ZTQfU12kAo$N?e;*eJjD{snce9H7arHQM&K z!sMt*M!v^61RIf9Mm+EtVZ@95z(FSGZB_g>y5xbRzVxLRSyGV1j)?8W(hmJtXxJ4q zK8}>}(RD&j$mH}G;)O9e26dzD24xZV??7Ran^D_e5tCz*0cLz)by=(&g_WZ!zCkHj ztS-AdcZbzwn=9$kv%;4a!Wl+$8LTE`a*)aC&*T^u)VVS_CcD;X+usV40|N4S08u%P zMLiz5A-9F=C9WMO$mHyU$q7BeLIz|Rv6$zCs*Xn#6FZJWu3=YXa*o90be)hBGC4hl zcwtPALEUJ(L0O3XnH-bcjN1N+m>iP~kjX(N2bmmXa+>%XnH*$to<>*$yjjnynREns zQe6D@@GP`!)IPaVZ+m;GNQC2g%y+E7W&vZah;4^)H(;7ogc#vS7@_NgoDd`Q7$RbX zM(qxh+-?OUm}Gz$0Wkt%1jGo45gHOG*(mHKiZ#H`*V}7gR?*vw-roM+Uc-VqS8uO@ z`#w<32a_djL=!jTUyc~3+>XN73Zf+Ncp#imghbjt`j_|NUk;#%8Z?v+1J|Na;3qx> zAq(d65V@n1)O_eVAt&UHdJOT>xTEdrMq^TyZQtL&Y?7N%+h37?*(3wxj*vS-?g+V~ z26KX$0>~Y?=wF6K(5U)%Z2xj3s3T-3cmj3d7@^W}0_Fq`4P4DCLjUrS{L5V@AYW)=O*=wIH!zr1}x zovVM@z#q5=pc9W)3;x~zyCpyQStQp!;!e7t`l-X?x@EQFO56eu5Ps5pp3cx{$-Qg zjN1N+{L3a8Aa{h^(GJ`ZL`bb~PV6$-+D*k3^%TGvClm50xEV;*eFLEJkkeibRh7Dj zu_&^XL4|$Qo~X5t21O=F@i0#FJe@o~s9J97s^!1i7tbeY*>JEqs)kn-PRv|P^0Y`_ z!~-edsdQe59B%mQznY_i){5y1DTI2Gc>UAw|3vPnT7dE zB3g`{EJnl#*mtbjN`o3dAV#<=p3+>ib-}b+^m4ybE!&~HYkpUjx)#3`BAbxW9h^)B znJ@r2ts|@PvGEij(=-EYb=UZ9qoC0Cn>K8LMQv&|ZRhM?-p;I|f4N4&O=JfvYyrxL z?G-f3rjHpJE9Bf*25JEeD9N8%m&0%G?kxDe zYY%Rv-Cu+0aNGaPMW)JT>7#}}q?6gaqyk`H+>@{QeV=+-9s7>)?F&jDwMId};NZ>Y zBQ?6UVb_0A-I{xkyCFL3InIatbxw-$tYO<5xbFk`mra(mHnnXb-HLx1iebm03&(Z>~~zua{~KvSNoXMK+$ zUKn>|P&ezR_Lsgr>rHYqYWpklFPmi0GQ^QPLheWz&8x4?+>z}@>zniEDNki8__tc! z*u2Q^?_<9aElKixJ{EkKO-I7|J7LddYJio&Pa+#Wi-|iFgbRl!-ugrS@^vCI0+{A|}Tq17vbAQ(%Wo0mSv4aQziU0pW~ynsH=uRwVF;i)V6Hr(-k3 z;TWCHVo1@?L}{Ie{Zj0L7l6&*T8)rC{w^> zNo$(##xey)bVMPEgAAdfzAGY1DKz5pydZ??2eBj(O%kj`N8aIIt_7TgiNicUvWZ2g z7YC6S_&fmrGKuwrIcHB|OdeiDmZ#H6JNRs%l@_Uvw1wqAAgq9obU_q6Xu}=9Uzb7*Y;DqccN00kd0iI>3=P>W*s#!doi=1WY zOpR6@!^h-~dQZqgAZnOZ+7ug2=lm-v*wZ%gly7h#OyA1I% zxTE^b4C+SP4JEhHHB+FzyJ@d!i@mMwFWttFm$cZ zi=oy%a}p8-lGzM11@^(@a0Xo{ozPCCWs}GO{x$N18$lO`P{Xd6DR9_KfqKPvosbhU zIX#AWVN6c4UEOHAVK*knB)3~(a!fKnCZ`|$JQG)*N zlHmo%GVrU3S%Y~pW>`+{w@W84=qIn9-H=`|l#8osHq511)X zo21h5LqdYkb1k2U$o6dE2GX}htI`c(gd<^ut`l-XjL>684ptl#j zy^TX2e#A@xC4?O<#w+snVx|Ckdofc0bU}p{PLe55+cgGe6}`Ra?d|XFH7uxe_4XRL z@BL;9)Vt1PNgL6`mHU^ArG$oFOl@gH7jrBnXnk z=A2tGOQJY%-I#G`G9WNhU~?#a%QG@qBpHAcrR=i0YZ!j-2{}G@w961LgFC9<%%E;s z)2=XF$4Yed-A#MVsO>L5Q=pR!Rt&nL41hV$=TfGSGdwBEe#y-=qJOn6UbbGYw&4$g zjEbk%AGQ&`%gd{-OM2I2c(%Gv>F86w(2u`-w*D*%b>@Eh>D$&q7)+m=T*LGb98^@jk9XgmJcZB^Ym0nd}*pD)MfIc3RA}wCAALZk=%u;ivKz*hgtS01+ zkUQ$k9d%hyXT}}XL*Ci8zZE8j1ccg->jshKF$$bcm|9$uY@IV*swN z=EE*)2bmm<0$Kpi>N`dODHM)TK*-%;6wu8@0j*pYRqT&aiwDdUsL$+#i9kjW=O8U6 zdEyh_6`mdWJaIIu2r~t?Iga-1?d>`tC&UOnhKLw}3_I<$TfqoD)(&C>#0V8SSo{|; zg0cz_BOpdVjDQ%S)QQKy2%Hg@`C-B%%T6NUf}6%6G^UVVj2PjkZ@+wh|5k9>o-sn# z2{|D~=rKgZ2n~#2lH09d1d|L_Oo>u|7!k@4Bb4W0{S7gK+82ls5F;Q)xH*ilv=Gjx z?^w-!8lo>SA`~M+`$vQt7Sy>$gc@Rm_M1&y?>Yn9exN6sYyjIay4~Fk&8+ zZtTX1MMB??RZ)Fn2P6a`ZI<3Lup9l5|(5ho@L0*Xm2RL(d>w(5v%RqqKo zK3lcR5HEwRs^83@ZnWK?@N?&=*ZS_Jy=K(*m!H4fNe0MPVSQ|@kB#-QYjzTpEY`=~ zou9<|*v*xM^|3d12j1G*wm!2-5+r`eI8Q7Yb3X_|844OhR|dog$IOiDJs~H=2wm3< z3=uH`8Frf5TfqoD)(%F!qDQ-N$SYWm7US*~Bi1;=8b{T3!Wu_dG-pJ=kAjcDS^{mZXQ2@O3rV4?JB99sekWP@Yb z19F4A)WiDN9hCo8?x+@U>?WS;L5b`DdaH5U7cpfnv|ED`R+>i*Go}xlG2MGYj?W$K zGQ`W^j_Nlvs2goJC>y-9f4RQ9X|EZz{pI_YJIMh3%jjQ5|1$cQD~3ZUS!4@$XA9B4 z++0cMU+(E&UY*%V7&&(A@W2XvW_yt@Y$6yBf z&0vJ?YX|+y=wEIe@@O$Ggn=2;*fnX48Pk|C4eFq(!FrPZ%e7r&U{=w;jQ-`${^c$U z>dgGh^^gtx|9<_;t0x*PX(O7rYX5S!3g-=(Lt^T=f?0udxbP#N1z}9Qgkk>j+rdR! z{L2jidz29`b|Guoaw1!L+_ydH2s?3+J33x&!VVL1Z0=~cAzlJ^)Oa(4y3v?ah2lE; zmm7CC?KPvezjXg{M;V}h8U4%XUq=7(f+H)xqkp+PX+)M0InBmDPq|Qy`j9*NbaUL% z>U69aBeg>gR*}1LW(UL%02l-TwIbiKBM}5l@W_XLs+v`V{^djZmv@+u6Jms}YX*jh z7@_0T-U>$Ov3AhEjQ-`)P^`b9#i*-2t9^~7@>g?Ome#wj9`+%iYZa*54-kY*B)(Gz>>hMCBz7> zi!rF^M?gP92@#IsM@VEqVL znl<#_mbH9Eu|_5twB8#12@dEg<=9?MRjkX&UVDFZT*Sx!FuNk%dh4W)wWq|w`=Hg*49_Hdzbf{9Y z7&WmwBZ{?Nn=9$kYrUQqKh`|c4OSEKW5|znz>Mi# zCgjLW&W=O804AsTW(IYm?FMBbc4KmycQ@^|Yi4q~$^e-hWO9(nK_;h(zmds7Cg*8H zfBB>20+{A|}Tq17vcL$w4LunH*$t8WKPz2bmnT92&hPj?uHe z>3!k8BYi4uFSH!uC7}bwG)e4-gmBF<~SpyuDo~or7fJ;3kdoVPU1)49Vg_J7@_+R z5hFA)f% z!-6{3h)_d(%pQ9+Hg}zYZ9mi#4Ys=xzuZdHs}w8{L?nrA#l#hk6We~oypT$adfiXd zD~~)PIQX$GSHw;rJV$arjsx38kM^;;LpGIA&~ZXe$X4|j;)StQ26dzD24z0>&tEpl z&8Y3KDeATR@=hoDT*{QCVp2S)-d+!c73p-65AHww`mYwXH5NsdvWE#73;6Tk2SG-~ z)9Vl0!cdl%|7R|;*G;!m_bF)ub+eDZe76293U%gw`sv%&LKsY+o8!{vaj{45$=Cco zpXB#sHWVZ;hR%KLH%z#Uu;=nw!yMTvWUG*^QrdO-g&u7X#NZ27qQgpb=gU?ZtR`fu zkgaN%I-_X?T193}L}5M0`J#c~xQT%b3+imyDuZ3C*@TVgb#=xKuA0f2HM&DGNU8M+ zq^4Uu_C=U5Ptw2(6CW$lRhuH6JZ=LC1<4*o@t95Lv*xC02v|T~0uibx2^QICI_FeT zI_0qTJlk#&TX{i>G%r%7R_4#?BpuJktrZLl_EC{y&1|^Rw)i-kjZy}mpH9@L$J0q# zOfxuTS~q|x`c5%rK(vXhyplezU-E}nV8v4Qk@HOCdA(cKFZ?ulNwet=OpeoXI+QQ* z^OUDD75rO8)YU37FY|4-b=Y0!e6uLzXdC{O6If3UQ#CDvX_)E?o$uoi(pTa>1g`+y8hH1aXrlT0~w8A zI5^|CG2>6L#amU$W`tYF_-ieeoRh zM0u0OS*GEZK`thFTBI-HffPWz(|IA*Y5Bn{OJ7J)67u5pPrv^Y+$afJavs ztur~@7L-0}O})V2;LYbFHM+H7*MF&Pfj;AIh;9cQtqHn4K~H{c@(Px34`KwR{jC}q7N&mTb*Aev|Zh$^608{ztyV? zC(X+As($|Ue_<6p!k)=q@4&9jh@58QyL4(j!S+kpG@Ds40&U0uR0=X-i?ghr?B)^# zEW^cb56?ogM)$h{L8LqkohYJK=!3y39r%TCDGydcEcHmvp2V0uyofAcnE0A;FwlR^SQE#W{kvbUQ z-84zp2~khZN~l$-)YbAnFq6|`h!@7>7}QN`+CluinH-bcY6YOyR9o9$5tCz*K}#VZ zlY>l-+6}8OjL-mC>>8nQMNE$E>gnxjg$$6pYw6FLtpS5eGuA*@_1`K>7@3@vngRJN zknx=Y0$^U{cPb?GPW%R@{e+C}R;GJP<>>xFJh)YvnV({)0?+&C4J(_@Gi z#^e~(jkX(h zZzl??in~E32UN(QBx6d4E<~n@>;dB7CPi9+=k+PgTcP#2brAy zOpakeohy@LvTKd!^35D^H5^JSgoGc*A%4JoCLCKLle2So$Oioxcup8Q)Dg@I zgD4EV#POUYi5$<@PB&z7j>P12osbhUIX#AWX-v*`b))SD1upwDIVQOowfz+_IVKq( zlY@0~cF3;62#s4~a&X2w%{VeSD-!tfnVi+>*bI3;M%;cJ1wNB3CXVIW92~ul44i~B zD0iV*MTilOgb}(<$O$n*k0ByPXy9>^+-?OUm}Ichf+Yq+Z!da#8;87ttez$T9CfZE3@ZHN&NBitNDSXv0@(jBs4*Rbu; z7Z?$W5urOogl=C@=Nb`eh>zK4ug1o%GqCLkdZNj8H{zEoj(VLoX2fCOVs-q8Qp-&s zbJ=BHB%xj!lN5tqcMN)M%GZk>2y^vm6k9ToJ}1KWT{nR`bg^b7qd)s_{_I`miNr#ckL$=a3dj5LiZ+a{oEG2CNH4eZuF-#Lf{st7{S@1UolL`47b`s5RR4x5D305r#Z+gTQhr z^nr{x;X&ZKE_X2gW)JZL&9U&z>jATWOl<8MCvcWEG; zN130dS1R0YG9iD1{7rxUX8U?NQ~t(e)Ee#jE9P%z)5(y(&Pg$%qhaXUVL<(eON-E$ z^3Zo<8YU4THWD~H5;&TGgM<=0OhP-bq)(aSabRzxPhuY{;2bN1YNrV~E`_t}5YL~( z(ca9UZgwMaw7Z-3no-+dHjC3)21w%|je|4}(l`}|qZkYfyh0iW)2Lu4oEMFwo#_Uv z33(jkaXRrhT^H0D5jonBced?sg~^Gy>x7=5j%PV6itHqEBgVooa${t2_QB+UfP=&( z4rLZexE}|EL$+ENK#5}wyJ9TP;bL(#mC$uUPRQi+7~+L7IR?P%k`_u#Y zBG}VpI+{Mdu77UFPHR}uc%?c%U~gVBgN2`BbvAs|8hc;fXl=WiA6jjJP&F~O3!r} z4bZ>55C5_!pz>*CLv05uc9MX&fpBBnXF;U1tH>Q4i96~#At&UHdJOTxxFdtQ(U{cI z*U+V1uBPoxax-fCE6Nlw$pE<{64*Cz=SjkX=? zG2fBeVTc%Eo4HX2cGkwpy8}GCPRI!{LXROLMrdFJliW1hvY`)3Yx#=&2qqb{%zn&M z!#uTyxu}dKj7S6_>===Vd1{!aR&A$2QRT2bEZLHjD>g(k`CzFPnIOf(IL-5P@>udT z>Z;|x+ZWF#X_=ze3=`8%vOz8;d0M0|;(-)E>Cky0)(M}%EK6TVQBpnP^-sV56ET9C zwuU5+?MIMK;QN8?302F&<4GJRVIl(V2v=JJh!Kv25xP#u2{A&CAtFX-U<8xgZUrNl zWPlg}{RrqsKtDod$-;jT6)GX@hzctl0Cv68(yfRQ9-x}Yq)3a`yW%O$HCq=XKA!UV zNZd_EbO>bt@;l|mz7xL{BAbxW9k5pgnJ@r2EwMH}Hl6}xnr48l?i#;s1omvdX~Py+ zw31O9;*9gu3=!Ixr&c53CbEMSwgBbB_6nM1)5naAVaxv7SO#hV3@FK;T9?Cb@9r%4 z-(rd7*1SkZRwnZ4JY!-wO7p@}--c=-Yikc~rQQEut(9CwSm>ix6h{!q66Ak?S zfu3kW3)=E+FN9mk#iKH`JwLP^-(sEzKLyOQq5Cp4mBC!RedOXv0ZbSPsT7tQyGcSI z5zldi6LF#GV&un;#gBEI5ICw%RmZ98nt>r+7(ZrEH`;C}592Q+dlbd@*>pZro`tv1 zP?Ow@+Wv}s=q4GoOf>YNqYqtewAB}~B_NAk*%I`jqYu5>O6Wt+kRN*+K6Ior3|15J zW5|#7uj6D`Q0K~zne1AlZGS6Fj^KiEmqL&}5DgJYm>b))SDWfAx9+GCQNQQKb; zlVg$rGC3IOgpp1d=~VFzO37mW%kJDAMmjZDQW>m7zUB{%j79>P9P&1N=*Z+4tR`e~ zkjd%KyVhvi-wKl>{e(cEh(mlR-%R2-ibOy?N}xk9GC6On;JmY6~*M>jFSm@6xbx|} zSyRXLr87CJ)3KS5135$oua8Y)$95#MUDpy(!tK~6w&W3qzrC&UOn zhKLxUQP;vGw_CvoCK;@>V2QynZXe_J)k0W(ZT9`4#n{PWM2vuO`_)#$xc$rX_O4FH zV`BvB#17<2Q|Vj28;40iUDqL@BsTWh{PR!We)<0Xt#%xHu8-YyLQaSgdJGXULIWe1 z+6#m#ulUGZkZv$j%r+ zNa~WriG?Nq|MuRsxp5=O8lKPlD-_%>?;EkaffOY%!cRoIyY1;2_cI=MuN@QZ4n`3u zim*U{1Avm{3IF#e3pb)bum}1Jb7|DeYod?*}cYQJ$*El2f)+k ze8DEq-1R~SlO)UDk_souuBld3LVLn(HnoUFH@=xM%i|eH5c=a&<+i0E4k2-EWv#=P z8{E@fa~XTkPGch!9FSAm2*sNS8zF5YDEdvB>`k^26n&7{5MU#~Mu3eVox-9!U?adr zSinZOIvXKE2w_#72qDBkJF58;hJBOjKkEqamtPMm9a2zPLXpJ@WeF%t?5`}Lm{95z ztfW#-yf9+?&`N%D&_dW9Yg6Re)>L0c!P>9sjS3D>O>b006zY1T!ah;jXbn~faTih5 zC~Io9HO*km5apD*1KztGa$|U}&+hxf(Fh752P%X}9XuFOtlrS>`_t~-y`gENd){Yv z!`V!S*6Xo6at95_aXoT}Hu3yDa?+P6wwoNwxIon&>FKJqrrhl>J8ECJ58#o5LdXHk z-kx^1xj3N^l37iH$2}pHOS0NG%#};ya%05dk%LE$ybbY6KDtLvI@1-X2_89krvuh|n8K4&g(qj$XVbwQX}jKa zANsTD!{~w1Fm6Yq0jl=2PU6WaIv^+XJv=$kaf+7{bet|v$LXxNRgx8}Kuz%Ez>~ATCr2@%&efBn z!nI0le=VLI*1Okkb#3&Zb!WpNXU6QVH@dqY&TdhExj+H6Ty~$d3lIA}HZ)j&)awrJ z`?vQa_Mqw7@RkZPOSUT%x$9HpK4?Hr=*cNMXQ+u6=E+fPH_~blh`3PIp29<`-0d60 z$=PG>z>@<{PHcLHf5MX!>^t0b+01bl#5>|aVhlVvv>k(mmGOk5YEOFixOgRv^Y!E? zP!l{k@Z{|8$x%$GbM@q?aIF&CUyUc{fwSI_4+n#8|F%Eq_aBTtH*O7Ws)LhL1t;g; zU=P#Vhv|TK@0elC$cZ!L4{XM`T+|YtoFjR1iVnyLJvn!xTTSaxB~aK1un}M*z(#0z-Gt~UI1f!!$%bItJ*$ZJBHDXEw0HZ2 zI@f5g!uMUBdZ)DNR7hHajalE(wZxaF6j>fjd-rz+X+Cg`^WHtN+6Vo6-9UV~iukg2 zZ#;~2M)us$^reUz;>$;hFBct<6Z($!XyS$WjuhLCv>F26#@?C_ zs(w@M_6>?JtNI}08bN#+@nx~l*8d>BOnrfRI`9^vp3eKLQ}0}#j>nEK^Pcg*d$S&! zb@}bxjLL1YyD7iF?HPuIieMug$wnwTASbjD_Glt(gj9T4)o<5gBdGddy$cFhNbDNK zm!)Ze_%b-Cuo1v0xM{&gxIP;pIttD(zO3-9BEF3H^8WE<#e_Q7__D(HT~mBng`_3e zc&+hey=PE$?mJBzbnmCP1Cqbj^xGj77U-_Z}>e*S*^SI#Vd{`%J=`HqSX$O(N%do=OFd`F7yMp_MlZ)5NHvZ~*dyM2S= z%c?$r?+Dc)Q617-GM#_s`rLLb=kYaX-+>Yx>VewqksE453i-?8n2!HJ{xVy(IrIE> ze|$eo+4H;As`;&UI~Xyt!@5)5n2~_gu*XT~=vL>_?u7XAk!*yb19CzeVUH%lMo7n( z6>IHUY=k}L4&uw;pvEVB_$N51)DPgGf`f|qGUCf(ON`m5r>!8b@T?-fjQDcO9<`jf z#1ePAHut+v_YpppQ**aR2Gwp6mwPMArwR`7!U%B#9h%8+TFkY_?8O^%iwtH{UpL9L zAIAsV(F)&pUGe2Zt%+;NU*`8yDp^0c8{Ktv#;1%NBfZ&Rs&h6%e7TDF^4*|6y`{~6 zs&%!y8J}^Z$L@7nQ<#F3Hee;=5m``t=u6*v%9bcrRtJcyr zpP3)j@Z+z4`{Q5Q+?xLK-OO10{Hkl#^VIw>`tTckM`D%4Ch}>0M+(#g-%&Eloi6=v;TS86d)<|9T3uT9&dSw!+cG`B zEB@8Ct!X<&B=9=)DCzmq5~Roed&S*XYK7ct`h{sPSHUtr#0Rr>)F^#NiU}pRTH0Qy zafyd$quI%CYVsYaaIMtQ*(NvGlkEjU@Mt z`+gsuoC7^MatDuwL)ITY+&vHr=vM39Q4xc|tv~bcCl0mi*`qgMmX(Lj-z=AwsWabnf&*pYkWKEm zWV~-~dT#|8mfJpe#nH2vK5bs|?$u@sQ-5O^1fRX{U1zlv*KS_;-hMV+2fn+ye0T8V z#2bfLHo_0pq457ir&YjR@?Ft1HvQL*KR3P1nBV_@m&D5GIok?dlAKlIFro&#Z-<|T| z!;l;L=;2;x{V9~_@x=fTPsd~12s6$&H>gO^tZVSm{at@J z9gZHfQQrU~^dvSy(E&N3jj%@(VI!n$1XaIXi;bY_gY_;bU?J41b=U}N`yiMS;0MA+ zfLb-ws=){i&&t?ZI65O#iZiImUfaSbiLYHWKJc#xjN=#twEWj)$O?|4H|y(TfBa@R zhuFlmVAbA+nPCYIi)@V3|V zMiq8f+Ar6_dVT2i9w?i3csuG2^ug@5H+#^BciK!FKp#7n5!g3pUz+p%+q>c2fDeZE z-Mi5(({xVVJ=Oa|jU~rJ{>Ch&#I#f!Gt&j1#+z`PO)XM&9N)~C8s6#M2X@)2v=R1b zB5Z_IL|fHw*J2~6`T#b<6XBz2n~T*#+Ry14 zpK_(>*RrRbevUjT-WAR!?zW$}tx@3#gZGVxL8kwxr~dI`hryF6mpy9Y{BHf|I=^u} z(1Xa$Ap6AKXH(~NSrUZ#DfV%phE4>5z+s@71dStT9Hsn*=^gtRHUhgF-4Cd$rZMVj z>_Ip9^lqfx_hz>mGUHAXM<_ZVv~^Gb;UsZ{J(>s`A!Q?|`t4e51XUlvMu3d~Erq(Y z6ri3l9BIShn0el6!Hu@-SiGAUWlgjSp`H;Mn!&#>UOgj12%(-vWHH3n!f9Er3ibtb zP@#ibsD_RdCs9nOb7j3M_%StcP!-9u?z$rr+vD zuct9Kllb&8%|E6C#D-78^bbUy5;4qJt2`h(CZ6h6O#T-VPk-gi^5?IA-3VkJng>8F zkeXZ|1;Dfo{`=&K3;E=P+*rC&m9#PR_}#6c4eoDwcW^(O^4SB$vPV;6c;8R@MV$7C zXm3n}5DGWsh1;EcwXYuFd@|fvbn@6Y5-9uL^!lO&nB(x4ot}s<6A# zez_LbtFF(q{_TB#c-ws-O6D!=8$+fKwP_z(ukpe!rS*E(oApM_=snzbjS=Je-Jo~- zFzA!F3arC!yOQ6<`Cnn7 zl*~G6`7USvWMO(9fy_xzIfnADqW{ibyt2(ev@G4Kl==|8)#J8j`sOpANTmV3d`<8C zlvQRvGe4|K^ZK_x{-wcNMQ|h4lW}HtfI^Ot88_8$hs1CtvTK(!y?@JRr1g5Q)8Fr; zIRMt{kyx)q2jqk{!X8b8jgXFLE7qEFw{MV*u*cj%W*jo(#4))3XB!6+h_L`-gpGjA zxOgeSMsSfCS2#0nc00S9Y4@XtVfWr(4}93u8M`wEng-VEN#Y1a2jqk{!X8b8jgYbt zRQ+}>HiD`T(%vMR-mnp1BgCL4{1Y|;^#jy1sAe3j!U9$yGUHO)2ee-8F$wsM_YvPK zNK#a=FTi>Q>vezDt71Z>gOpNmO)T}6%e|E)f|==1oBW%aR45hvn7TNq+anG&y-|hT zmG(>XSg$Yhr+%BNfVE9sZ&S6ew!xp>^^Ay8Na=!nwq!0es2KA>z<5P|1s!J zM%}6PhW8}vIvVlWjKp1M`m8^=NASAdbnLzQ|0sT_eOq+4Zl}HW4QZYSrQJat3Dh+A3z^KA3#41 z&$j3#A##k!@jt)$MuwaQUvjEcX6q*RD0=ioI!FQZ*E5G!GmYP|p3yUm+1>pV z2)|}7X$s-*?EYgz`yvgxZcLxsL((3U$|4nKT+6b}>+6rbt=vD<&< zuFGbQyC8LxKwlv)60AHU60Hd6NQh2^yM8YePo$>lY(^e?edThatKS(9)86e=8;<(3 z{{2+8pFDle7i{v(UC(sv?0joUsv$Bpuf=qqZt*7EW>br#QN}kjW_dh=1%fiyljzzF z3oS&n0ln3;z3~=v#bx?au(`Iq{m$9&~qT4*t2cd4fA((mU1`0bi}{w<1-5$$zMqR%Ag=PbPtDu5Qu<4M7*3J z5CMURL5@Jg2CVCjZZ$p}jI;;FS#Np=MTldAe)R~P2JG)_6F~lKw%JKn0PZ(G8lZkZ zPs5VCrXzeHgI+Jwcb?CD)ALPT822Ad+gz*`k`sn@1D{|X{aW_0(9hp2mzJs1{h{k( z;gI61oLv z^x@Hup{MY}!i=L%fJYy7%+8{Y*;qH7HH&uQWm3*cM6? zsRc>}>lnWsX>4>ywG;H7WZ57+t&a4xeMf;HGzGYY*;#L#`+#;`p8G3rCz0m7FyB;V z)99Ql(oxEt`%>fEMLs;^%0X-!vF(&c1Wu8#GY)l%AhwOzcD$Sr+eU1AOKdwns53;g zevgm(`mjIMrc|-IhstR6$G8s}iDLu)eP#)@?Ycq#uFh&S@Za_E0RM=ABLpYuAm}3$D zoj%;lq%}w2Lm)-as#KT=bYyJ4NaADltVuRW=Xr$y4r96iz zvQb*?bmw>IQPT6j#$6b-SVSsbQmuF^qcV|` zwQS5}!F|`%CxJ{%vann6?k0Bczj9{z^Vh#__ze!-=%@u!lMC!|Ch52SK6&C|H#lg~ zr}mvLEg6o%#^GULf1i;! zHsIg0ZPyL@cXd{yf&Z?L2lz(_86jkZkYk7{EFFZ94>$L~3r)`?@InjmLS^vZ<-`7f z4Gqq3A4u+$p~^x1$zc18z-hp~dR9=I0P=|!y0LVw0NihWG(bH-JwQD`eHw}Z)C1Jd zttkXg&s*@6fM_0X3cOH1sEI8zEL-4(+T8DMB^l>UrnBIM#^zQ^?l4PhtAex{zb15o zZ{XzWUy<-aH{y0mJLHtSP}lI za(PcAl#~3XmAf;D5uZ{O%GI(>o2q}a^&(oGy}shtuhU(>*0$fh(3h&a7fZ&xHYG+2 z3asKO(Pdh(%LYX*qpvDHr-}^#K&aNo4$j(f*Y*I^Zz1g4MeHw4+^=Mnlr(SH{H!d=NB)Us^ zziUOU*y3sZ-sOx^rasS^{W%E(Wj1XQ5Lr5=?Ryj7iIN${H&P-LeWqb9xGicJ=ho4A z_w9!$m+ON;qiD{|Fomm7hbnPMwJc{X^X(#UjM5{FiBv==JH#QRk10D9jaV5@vwFHm zX(@3A*q7`o5*(z!5hW5r-u&{ZOJ9`zWap{!n$krUc+oOXZ>XR)d*s{U zwllM><%=V6vM@c5%Dhd2lx5lmqyNrcyrOz=VwX%~U@3#L<%v_#H=p@L%43r^T|$56 zGaba@QT+99fBZ{3o!e6~t~&u6BF>)ftc~u}nH(moi#=dZH>G&fxxw?FXzTldM#9$D z+Yqq%_dUy7ln*hci)HPQD#^X{up6`w2y%b=a%mP%|?fc^0153du{4R~by6etGt*0m@VU9kKKQ(ey?_GkB%V-VaB(T0xf*y7CBBgh|=(tH_{MG`N|(a zTmdNGOG!K+((r{tg8p%k1-QIcT>hQQIh$JiqulE|ak+fosc?A(t=NLgf8d@6GP&s( zg1J%^D6e3+%7AkD^~nws&2@lsKs2z)mrKjkLm!PG3p+#$c3k2QXI2YY=5K}mD~0_- z7JV*D{@p8OV3_(F!=S84?|V^9iFT9L=Cj`0&!+1@HKi`qloTkx9gObpdJp|98xbrP zuvnB;egro6XfsG>BLSS(4$eP?UH)mw^o=aA?W}SEb<%g95}=oE2OxR~Q6r#QtKYnm ziBlG&r)NwCEVKaA0n-7~0n;1KGf!YTeCUnwp$C#aP-US~qSIBbq8!r&ImDZATeze} z+2I+pJRXMvB&T$AEnV{^8-`7il#a$USIbmvhw1Wt+d+CTbFxUNWR=T()IDJ`aQ5nRYdTSHmHuP0wYzeqcT5EEbv;ems zkjj~C^0Y$0Ou1NQ$}s?UuKWQIcddv!x6gM%?(|*9$J`~}4$z(K$Mu5l5@S>bb*Eno z*d2{^0K_P~2D%C8CZL-%oNfXI725ScG;vnO3-k4PEG!=|7m^dP75h;I6L?o#gu=H7w1t4hi&HA-brH#Ab9C!SFCpeGJf>uSn5rRXKlNCE7& z_JG|BS*HVj?ppoaYQ>1{yl(lv<0J1<@85#F&r=cQ=%ntdV0Wn@Dg(Ra7iX=>Mv%H8 zO(=6JKr;c&#I?sH#WucXG0GI|PSPvog#xaL3$BU6>Fq)P-WXQFlz+8LSCqAUzg&kq3cINkx`iH73#!DK+Ore+pv$^+uiIcX04YM~0A;~&qbF400=Ok~G%3yKmoIG<$ z*EO=eL@FL=30Ff)fX>MkCtgD5q(MX!aX{7#!1I&}z(%Q+jgr^p(Mi4C6P~(B;RMe^ zR2AUv!(R^29lJvlRl<721rHyhGKf3%)~vbL1O^IpPUJ`l2q+++fPj(+nUGD5giAW# z;PKvr`JF3L0K{D@;?C{!osc_y*YPoTiMIoE9|?4q7^5<%JN;U~?r5w*Hv!!w+R{;y zzUd|D0lR6c19tBLyLITCG)Cv7CNFnk1&zG-19R`d+*Ku9mKvops2e&b&^dw533R;& z*R1OeofE)r=$r_s(+as7XH~yatqHN6Tq56hd|!8|_isVoXR31&*bYY|byo$uOAS#O z*e$=fiSF(JbWT7sp)$$JT><5Et{HYi=Op$n!Rft+)7yj2N#k@*@|@2VP`m}qO6yqc zX#@a-hZ|IWU7adHc!@zO3&Yc|1`tn9B&1hD=Oma6&^dw5i4oUaF%6=Jx3b%$?{el( z7N+N!_T$80J`-0(|DC;fWt)ERkd$R8NdUAwZhNM0KJy9lQ#uu2zNQUoA{U#_%;(}! z{Pk~t{7ai#(_g-u8H=A^bj7wj)u`s zw3^c_w@4F!_gyRRdrPlJP;I+ET)s~Yg*9o(h`4}jikzaONtvhn^cQ2eZQPBgXi>+*F@Hb$uo7MG`IcK$UX@p911>WFzh^G(k;b+NWU zM2UBoYu15=&Ixo*Vj~>o<@p6mev?nLZUCOAQ~>lX15uahPu`O0yzQ-)OUL!wEBBGx zz6{PJ+cM$77~IocbLo@1g*c&wT3}w6?}Xl|n~smW4}Up8_j)JJmHO7w9toN?{C8it z7L17m?6O!kbfTn9qr-=&4B}3`HQU4{z-{Q9$g`8?=SRmdXC^nkeN7wlfZG;z$A2V0 zAaxcJE|GAlQ^gsvRI>XcJl(A(K;ZGvZ zf4ulw3&&Vlfm1*HTSt_0UpN#qa9j#5eEGHYGJoo~r<}D-U2iX@Pi=!gw}YbZM*!Tp zA_YL)wIc4^KHmws({~*obC-BKK=+YAcZo47gSykN%^oX&-N`W#EpULaMuISSxv$vE z4V@F(+!{ssuG`NIofErBIwu>vfeP3q`zUB^ydRi*2j;Gd>s@M;%AjuOoPb^edI@w+ zpmUP!^n^hZ(Qoj(JO14CHvBPxH#+b^CtmF<@^&xy!f{`dPJy4hRzJ5|6Jk5BTfXo3 zzV1@*--5i)SLfuYr0%L^r3I|?|au-Epv#(^sM*x zv*|kaLZl?o!-&ng`LG`-!9M2hi;J|LruBQ;X!FYWDlq(`Ej<^AXY;U=i{J;pG(Y%4 zU)Ekuev32#{Nc6w!?*N$w63?qarwUOU_6*PnH}_)Iw!gB-vY(YR_7%A2#K{Ti8;{$ zciB28xuaADi_6n9JO3Ji#G!K{EeKizfMs$nDu^goO+*<0fH%e!9vqN03k~Ke6##wL zioWx@d?)ly-E@51efY}(x?{Izg4Rj#X0qh2=@>#I^{6^0l_T!d#AqVihR%tMEdjSd zKmh?IacR@`jf6`&-vGGx;GX1)6aaD8inw$8d?(~i-*tSwel4GM@Qg>CbyVMYsf!*?pGj2(wSHj=Dg1>vYv`n4q zorbm4)-^pctA$+rNUyw{2*;e#Tj!1?s^mcDB=#-=eeZ$3Ju2-(p|oTh0L`RUnu&la zDlG^#08ig}8VFvZ1pwiZk##0ICzX4@cg^iaWLJ)mUMZQT;CqAb4Ze4p@0|c~_`#cl z#FvbDZPx3zSInoTt@C9{%IE8{ws8<3rsjX>-G?9##j zUf=%F+yJu{66Y6j|g$_7B`GEfy+Mc$I>yzQ-)OUL!wEB8@|tx9LoS6M?K z5-2ygr@Q7dj#>Wn?$bE0%VP{}F?TT`+1DUJC=HEMH=Pcjmv02X`AsVeP;*`BRe|&J zLskZvr{13Z>L$Q)=%&bf9$-0OIbeAjmP0p%kPSTORIWy(uO=?hSR_7hfhH$oD+Ye9 z;k9$c4}i>TMdrDEz7v|K?>Zeeub>qG=SK$T6^vOKbe?{FvI#}g9q?Q-?&%OiIUkhs zK{=lWDC(s6=78sb=YgwrZ+H%!mFDQIq{A&)9CS>*6;(Tc%?o1lsuDp9>#wLrtqeMc z4hwWxVltiQdt=%2!8{KMp)koBX_BP?I&@gzJ*R55d&6_+u{27LMTM~{KeRaFdu!FGk>x$JRm)7(%Xc$l@$;*$SlBgJ*|BrO>c^DSEAdJo<18dD4!yl)#m_M z4+$F)Z6o56^NHoWOgy$&T705AE87>PICaWdFs)$o+SrP7N$6FA_4LF$aL~%a^>h=m zQxkw41%)862!X{WmXJ#M(-XiBU6;nO(lzM15Qa@#e)5slV!BAf^d{UE;^D#~oiWSf z8QV2P!O^wCe3a}w0h8ktm!mOY)B+dVVY__aZqyabpe!<~z`tHeJGS`O&tBIh>{MwI zNp1_8QPraMs!~TQ8MQK)U2Z^jUN!=;L)S%G7_=6sI;J@@x$*6*@C7D&EeJ5w9rAfb zodp6+(+M!pb!i>}<`_UdPk8~^qcVr`;&ff=!sn^Ua-fj_aK0Jc%yp?(19dJJHmE4lz=UMn)s?emB+vE6%~zUx3( zT!HVrf>r>W9~qoiFlJ@YdHVH$=Mg_DDCiC!D$+*bH76zGhSOXC&jHV&>k^%O;*W^i zeO9a%Sz#j!RJP-C`M%R3^GezQY+ewXSH(rIWYo%_bLhH2*9Ekez#N+}%YsREH6~fg ze-2$2&|0ADk^<;wiO|&=7uylKeBbF1dL`}Hg3!-f*X8J>^Qz!^B|}yQp34o$TBVI3 zokQ0J^cLv4AkRQby;y6ukVTfHiOLIQeGPP7I{w`BHjW3!SXsOy>i5tYv;DEeFQriDYwIF3saI$wTmz09Bb z?I~w%Q`g&z=~LU_&u!73MI_8|42}zQT^g(FQWphXz^=4D$ALxzzYHCab*Vyc_8HF8|L-j}AUM_~_|6qX}S#u1n)|T?Wu~A@4YJUH;yF_x|TG;ghi}jIkRk2Qw&h zh6-r~fqCLk^tw3hm@V6!d49Vulkx+9|M=s#6}MvxWIuadm#|Y4!(GI3nyKrOJA2At zc6s_{=Vc>Y?9g?Q76t(O=H}qDM-K#;;c$FCrL0l}80fk*j{tKFpq{6^fb3Bjs9v0| zOD@8y0H3EO%YjA$z`bl(Ma_3DMWS*KZO@!spb&;b(faQSY@S~^w=tvwD$%0L* zWpoT+o-4WlWL_&W&+YS&RIeyzl)mdgSX==%ub>qG=SK$T6^vOKbe?`a;CZ;tZ=ma< zU6l_NUi0DTx<)+ZH3vKgJcq7Jbn=Nmu36V5*ZWxkGT&DrB)1*F<^{2NRb2E+My(7w zhpr2BU1Bnwcf~5%0O(f?(4p%B?>Tf`QULud5xQFAqB>odTx47ULYLcrpbviwLO*X^ zm#{}AZf(7!^Qz!^B|}yQp34nrqWc_aqM1blek)zkVM0PB)*7|FBn ziRHXZJhoU`e4;xm+n(Ve*`n1=Ft_yTsT8HbYL^CLhj4JT2%K{y{Ap4ef zZ1Jz3xvoq6G14JiuZz8^)X_>ttqf+D8<3rsjX>D~mdIp8_qIp8_qIpDd$m)s_zxo!rm z&M$J0G)s2zIDT_|xk`>qpz>N#xva2}^!iR*F5h=LWL`--fXxeH^Qsa@D;c#i=p4E( z&~<^X3wY>P%|nN-3%uvhbqS%a1b9zT7(8UB7~IocbLpE-P{&i$1yyTYY$vtI_ni)* zSJI9x2>qOOT~0tcuL_=5GGt}ox!i!PRoVpiIdokzqYBnJSm$7!r&;Gony4ITT2o+R zqJwGVi3#{FXZ~bidY)-NPJ|m;TowIyX7ROFw&@2CNja~j1gVzCZO`=0XFidtwtxAW zZXG#m&1dEZLL~h4Z-4wtn_JUgzMC0~pI>#&dY+meMjw8AZ_fVt%{NjLT5zI6*M%^6 zD}vq=ZnLRH@x}4Yj9DH}Pcm_p#oWc@>|nY|+d>W0(|4X0s#nkwfc4CDJu6+8*e=Pm zu`FCq&l_oLr{xO3{-4yjDqIb%H_N4E>MS<&7Y-f3j!P$Xrtj#|w~pt(CDkDA1_$`` zY4ehIuQpql`WwS=x#xZFI;&-Hn#*HM&w6h^o33Lo=yBo#gFkOR><8xgv0{t3Nb6}@ zzo(5huZ*wy_ElU5e>(i>SM5(v06TPD8plf4pzA_Ayzjf_bma#;C;3RbT;Q%2xY!Qc z<@#}>$b_PQ?N$4KBxa$6AO zsaB1#s?^a+W=|Q+E;k@MFB^f_q3a?o3|b2S?6O4!z<$+$9l9>fBfuO3sOKp!fTu14 zRhQ{c-jeCO?X8we$MxGQ_ffc=q%%p19?=06!tERuOkS5uoE>t21!1Q&G)~=gI(%Nf z5dh}}>FHI0^YTMh2AQYc-b7fA#8DZ80+xgL0^&=W_yS!Q5g}|^;^;Aed9LUJka?}h zJh#txLi6-pr^DtIv;yG#$l$z!F)M@4)2|0S57+rk;76rEmK+nLLku(*-W8q@?zW$} ztx-tN;Ccvt@(4hmxchACoGyE&nuh^V=%?5L z^O@^&+p(O-*UjgC=B~?Tj=P}9fK*pd^3r5OYCe1PCd{%h;-0r!aHH)y7Vjn<-oz1~ z6R~XWSb~rXcn)}eSgBDRx-Q-}Vn@aPa#>*`v++l6_B@xleBbGic_r-tHZO?Ht4bWL zWYo%_bLhH2*9AOu&|0pV)&gA@c+W*X&c3SX3%+pNwUYpT^IHApYK@ESymR@!(;@Uq z+OY+ppSP~d(Mji3!ShOntPDJt8<4e18$miBfpsqVjzMn$y#@4^G`%HB6P0;j&~69vow3@s6n9LuZiBY@K_ZfF;9!r{s8>S)JtPX_oQVWIy^d`dj#u zD5@35EL)4<`63-J{9Ev*bz=UPUt2Hpr+%B_b8S=C+Z2auQ~rEgv}dto%xh13$Kbel zq!Yj%dD1(8>9xajm9~W%sHg8dEmW_dB>?N09sA65T|&Dg)5fxJJw0!dJtv}f0kFr1 zN5q2x;e`@@nn-^D;bl0|hQl$tM#4)1*rDsvI9B=qx-QUlX{D1!WnqlnpgovDS!8qq zU6+iOk%hTc$FogHbd7Xcht&Yc6s_{=Vc=hJ3Q>t!hnZ;b8`Sg{o#rM zJ9J%|M}P?q%3oVwlM_vN>7|sF*zwi!UzdmR)AN)U;9jrQy`IF{~^ zMgW`_q^F-m*QIh~o|-VpCKgTgCctv&y2J-iIH-W-faM^*q=_#`9HpHB9`pm4>A9i{ zK<2d~^V~k)3C+`YoerB<&T3TIBmq=R2>Y9a|9kdF#4_wuZ#5t(SCO6+EwG$jZQT zxdBadpAVqx0(uKK(z+6$w}9S~rne+%qVhrkN(V}xPa=kA0RNKnu@x(D3k?|$x-Q3t z=_+jtHBe9Ad0MDmK}!JEGduQ~>AK{`K+3}P^t?$nq|mw4Y62Y{fITy+;G+Yu1F+`; zcIdh^j+H)yt_yTsO6j@;GbnS0wklx2$O0X^jfdQJY=P`&uj>+i%n@DeRi%zrGHPWo zyWD{6ylezwhpvmXFaX#A*a6tnfE~In%}XCW22jsaUO@I}t=Xe_T^@NCw|mx8HywzJ zE5PUF8v$@$ke*%@I4?hBWsrI5?M;N`&~=fcLxAOg<$&dBSdPR|LB1brZ;A3nj%^YV)wCZoi-i!*TgUU?Qh`S921OF5Pn(y#dnHP%slPD{ zmwVp#uCrQ-Yd0@^Z$F!^V=w4&;sPq9xOvSF%=14whB-5dcuyB;Jx%NPw9)33@m1fx zitCUlyyl!!e*m5Xoi7rl~ED}&CV>jGVuWV7|XvF!P{o@$d2Uc6%A#Ru@u;XOY< z6&<=R$4(e!Q;UD(3&(vej?iUojME|XO4_jnp`W*|%h5^ar_yx^KUAhGw93G9dCp|# zd?QHb&~=gL3+OGNw}9S~rnf-XCH9>Hr5}LOJ?Od|8>XwYEw;1I1=va7d0MDmK}!JE zWoT2cFTJAaQx>kL=M4aRa&m$2G8~TKPbcf<&2nj(Iuo&9K^9qn@M7@3@i5427SvP! zc(FsO&y=&x-~Q-2zi~Za?=14DK%cn#Z0ejYdp3>mISI$=GuP*~V>ypmKN`LDGk0A! zbKC`ydZha9Qjk6?%$p0?;a5L*#Lf-VYtxbEGh63gGRbIFhGQ>C_3NMdughRY@ZX7p zW;1L3o0uAr^QdKN0>*#;@@vcGkEZ9luN`_+INv&^)15PKZt9M^?8fi-we@xVn)Tz; zq>(g>vgPS>zF?DQ?t0-4BTd2<^L^Kxu6+8~Ed8=&1}wLB^1ATw5_I@Smo4&mDpP81 z=5ks=olckjM_stGxYu3zrqv}jp0jdw-nQtYyW(GMSM+^{?w8ip*9>I(_llFVdwgTB zEGzRXdgjU!>p%VdqRrH|(QjHW^QV5BwvV={>uuU5+C=mV-`v(0Ua#No^@4x(Z;D>2 z6~1y%=t_;6Q0(pE%3^O9S1R95JyG!6r7M+hm#!@K_MP9JJagx_OIPlEyLjC0aTm`_ zuH5Ef2hZO`=0XFicO%r9S)JN}IR7XBoy(Riv zC)n-UYp_QrK+zqiFC78#$+TcLdn8_RyeYQg!zoAsvz(Rj!hC(F@NaMczGZZ1{MGb- zVm@C#Fg~orSHyoWaB$K4r3N2zW=R1o<(U$baf0FE$h{6X6hz= z$V9;8Ns7;$T?0|1HlEF@dB1m1_q|0^)eIh){d(sq-Kb>iUeEtAZC3l0<|(%3X@E^f z%q55y$kUd<`Nt@u2DviPJQS|M3FU0lbcyjp_#5ghIE#4KrOY_)wx77I(XrGtXVE}j zAnVMjxMV}Pg=e=m-{s7oEKJV}5Up@i2(TIcclP2H< z;;(=E<6qj`n*Q?L%vk*Vs%zHs)ci2|@Y{QH_Rnv=k(xm1bxUzr*>qZL=DQr`BMJac zf-O6N`a$e7=_Ef-pU}<3?(b;m$qf_H0{_<|qu|F7UeMo?QAhy17(0OZvDj0BY}>ZC zS}q;eZ?D`(kqeqyAvZT!7^8sl#fBk99s)>DVl*V9Gv$L$4EAek+ZObHEHU8=F#sf+ zn4rPo20%^2SjHkyHYwS~qUCeuCPI;&Bryd$LQ1`h6D3-Gw{0Dyf+XI0E3L^uFi3~>O6loIE}W}7>ffp|d2pPOrr zX6y_Km^Kl=Ch_~9Ydk=cs4?L3B=em9(gK&KDDya~>T%L`lY=QGfk!U#F zm9NQ>A1OMzhUCrQ@@x!Q84M3DPei?fkXpR^co0&f%@|ys>(I82@i`4SxI9hf^3;#r zi$%fVv6pG-m3!=q4MSvqZqaiHc>2l*753q8z_m)ieobxLg8t8+%X3r%pgL!MO~Y8m zB2YFdYq)~TgIXve>(&!)-Cz97ENdOX2biz~$Ml zB?m4~Q7%tb_)?H~PQ>NeXv!8if971C9Wr2z(&gD0vN9MRTpn8-NH<`;*KXxw`1&7DJW{-WbVTgA8`nfzCaIF%sul&fu@r8}HZ9)I%&*eF)0dQ_y zo{eEFV-YB47To)A?~{Bg*#2Pqd*15m*#6-1G@8p(zlop>nZq)u*)mY}egT6Z@BYKF zb|rQ|wM_#2zaTD8rKmq|9s%qF>;vpWrvI8!HB#XKfc?gT{h%5dxIEzUeEawIyZ1kj zH*0ehg7v{P%A%x7V11gFad=aG_4DdV|MPnztkJoBVm)Yzhe zInS9vqx8@psL)wlJxeeIwVtN+d)jF8%J?d9dBEk7-Dua7XPpA?(B)|=m*+Uxy;u|+ z9(#GKX|gU)E?lbw>?`M5<>>#sxjaWV0M3calRL%ASOm(MmBEmZ-6!R35@H9l<7${4 zkllyue!_l-?7llOsbH^f`mYx*yMG)LK^ZcKWl*zapzQrRxjeZbtr9yR?~?%k>-GOv z2mh-by)vjjuO$Hc;PQaW11=A^JOMTU*l!fruU~{SH?|ItzYF9Si|dC;xCZxh*IfFh z6Nuq#a&od5MwPpp9tS}lQ-8&tdT@D~%;l*cyBCXs1I+IN^F<2Z zE1-O_VJP6bS3c;(V85oeZ9)I%&*eF)0Z^SYzoua-fJoDTO#ijY^h1}Y z(YieKi*V+~)&cT&f&9zj@@%Lho{r12(UdK4{>*iGjw-Q#VlL0dkd?vkx%)S3jrg;*aEz73FQGoJ$cwBW zyBCXs1I+IN^F^F;m&4`RfNPb2edSy$9ADUI+ZObH{#>4;8UWQf^J^N$G8TcdNf|FG zba}w`2irdaMXfi>rDf`r&J!kyEgakQ9oMuUGpmN6(_6>$-;$mQcSW3kF@4&+``Wt)?jbh}@(Wl)5$5H>t!V9BYMdG{ZV zwJWg$s%;YBe`Xq=GnZ$>cq@bY^X5?oY5?p5>;vor?El2{CvVAg-W8JC+-*N`TcZQq z;Ca^N$xhG;^k$WwsRh?T@bW8`lHNCD#o4#NB68=XBXKDL@A1Qqq9WT%QB% z2fp~FYd$kSfTjHPZ-4wtn_JUgzMC0~pI>#&dY+meMjw8AZ_fVt%{S5*kh!=NLKL=c z@=cu9u-smnV7)$t0)l__QDX}=whmHOk*ATgoM=O<1lFf%87d1y-IOhG{`|N+na_}H z#d+RYN%t@xkSZtTk|XEPRy44wWkx!maEazq7vBlEj6Wv+a zzDT##MUfCIaAjme<*k~X`85q=8H+&Kqzf|)Q*Ua_@ zm#1l59vMW`ZXzf{=CBNEwhWZLU%(*9yZ^*?K($Q*{LdWsHN*dEN3RU(&ud8r4uZ=A zE)Tdok#`uxeQz2oD z&-Be_K4E@}eDURL`lur42rdtG_m^K=FY~8az&pS@z=E^7mI=e%4o|nb8H8=jKN8t5S!6 z%L6V?WD(LIknX(n8e8%?3NBADw_8%w=s&426HWO@YiGi3Hnpfq$@m7kJcVLMnbWnJ z1l~Lj#^I(3;D0(mN|XJZxjdD|0rKWicESSe2k?(}Jb6o`c>+nsMyj+RwfBlsdqLc9 zG;zOvo&Ma|I^6%e-2a!w<;e<>RRinOQ>QST-)PDfIDh6`o})_apP0+DF=S;t_vuM< zVc5OcnonHysIev6sbqm5>sIa(cmSw&a4YF5sK_2iGcuJp3LaNLI9V?wZ~LSXzcmk zSU$Fy=dBjpXuFQZyVt_@hkGCHeIjt7#+L1Y%kxK2P4RH7U5Oo#$H6$fNn4!%fd7sy z1Uya05OqkZga6fzUK!M%*OCkzgf0(Kdy(235xK$Mf-Vnqd1RLN!ZB7B?}QpSbQt-} z*16X)NSUa^f2VrVHnTd(&(lKMUy}#@8T~E%Nt8(wQzu*D8-$LL^saR^>w>yG8Wq|? zjjgoIQ{2Vj_I6UjezCZ|A^@P`G=#V1m(We$R|rD~(C2v(em); zF8Ah+WlW--5Sp4v=g?ndJe^?l>&5QHqTt~2$U#9-bUP@&-S$??rQ`bTA`y56lrJ_6 z;Y_Z%##Sy|s|4&TKk{%xWDEK~Z)g6|4S?#L`85q=8H+&Kqzf|^FZdBEiXmq!Y^Usyb#ex3f@*gD+*yWIc9;`)jJKyJSm@b{FUOC}-A%nFvL8lEgp&mnSp2un=G&z(Pn{2;lNGn#)taiJ%Ob!!oGZGEnw@0fQj# z{uA2))iw$6U-prnHJ7JS)SowxGH?)F9&mZUk$VQ7dU)#LsZV?A!R2W(m#2R0UMva@Fux1T7m2_tpnS1mD1hyi4>~c} zuc>WY(Es^!d5&rToEw*?Qj0)2vo_o}+;>fV^6wRQUrD#(OBQ{L{PsX}OXwoM`Q=mh zy~RA=46Nqtvz(_1(|yyiMID1LQpy)$RWgyoYCpC&X3I9G$F%!Z>?DbS04`5vL|`Gn zLWox#YHS(M=!JgJYb&>~RItP3*{im(E~<$<%83-8N<+3boWf&YY#2g+MoZWY(Es^!d5&rTROigE zX&B2`1j;5|n2AtiCrJzh=<;Mn7Zw661Xu`Z3jywZxc4c)>vb8#1KEo=S*Kmbg%<)u zne3#km=)rR)X%muWDd)qX3Id?`vnYwy!%gV2UOc6z<=3CdXBn0^~3@4=25bVMN0!* zo|d3;6Yu*!65pF}GE`c4*Jb(>ciT_g)<`zh;Cyqno6r5sU6;)qcR}nGaCyMxiF+VR z`UKdQcD5$R1M1i5&yB4E=AcDU7n4mY=QG<&gD6( z#Qur7JR3t+#&e&ZzZnR0?wXp#)_mfs2bV{-Q{kzHryidAG2iU!gqrO-a9AJJI zm@g86S3vn=kgrY05~@;Po)-ta%NqaiBM!GNel#Vc`~C5 z3jr1aEQGX$04`6Xxjgl|_mv@YSOzs)2Fl(qU=ZZpe_}hJ+9m=1%RbVx=JHgE`t#;d z1`eKkJOE%H6_>!}A)^g7wx|;hWN*!>#@XDlP-82ALrskb2tI7Tb`j3p*g8P|E|6a= zuCE9HwjZ=EernUCd9$mPkMJ>c?$3pM!n*Niomxaz^>k$VQ7dU)#L zsZV?A!Q}yV2bU)_;+XE6j_pmj&8AjRc6-JwkIP3$q-qmgOZe%Fgu>{AAz(YE^yRT< zd)vyzigYe-$#mZKR?DU1`t2f4IR%v8i;NIHCr+N0i`FV1bYieyQ`@$n|MTYZ9Nhpo zCoWIr7J+hRWer!P>LOKF8xF_J^HvLPv|Y#I-6T^Msk*-7n)YL6)zG>4*75weD zi*r+u-@VeQWa@7WgWSvB_pY;A=6ERRS?}#<({=0xJx*MJfKJ5$9k};X?v=)Jd4hAa zcK5zAWDYm~E;oNk%Rt%t;UrfIb>`iFVmqMPCIS9u4BRMiK&G&W6qt@7q6F2!|7u6C zOdKGuB^lTPE)PkvL6-+$Uz`+BV$vI_#00Q^EnvTXo&Gc-BRNX}@^^v!%i{8E6t+4Y zmuI6XTj2beb9s&`v43JN&&H6I!SK2JO=Q-dxud?=ng^Fh>uFlQr;U>1BtETCE;Y;f z6QHc~y;u|+V15^vFX^!_HVhHQsh`WU0oN)4`^t|j z9ADUI+ZObH{#>4;8UWQf^J^N$G8TcdNf`_Y_deYFBXD`5vjl|};NCYyM(;*SnD27t zPZp-<5wmMzFrSI5qW{kBsVmzINLj5EFI^_g!#T}PFH@AiS|XxV!e<-+-|9e-|m(u3&Yg=4HN-U$m#(W&G!TjyRUcn1HSsBAW~ zI?2z|U;H(B>z~oz!k0$C3ZlyO#=MCATG~_@m2=)=gp&y z&79L=qfh?5;_fSLxbksBo4v@039@p;Zv5t#Pu=$x^L#T1F=U_RJWWoK0+d7pAi|j$ z5gI?LKV{BLZhR|7cb$gidt-TD263M{3t%5$A7DQYC5k^U4D8o0!kHUe2gsKXlg(7# zVsU*%GH-6b7l8Na`wGMQ4RypyV0|@B*#hU!oXc}miTx9Ec{XNG84RDEG#PYv?vDCm zYd%5m(B+ZsRDgHr^2DkcS8T3<%ag+6O?K4RkKKz!!2#xXf%#@}c{bo$C177U*A6#C zwxIv>=kgrY05~@;&&CuhV-YB4)`gh}MRtFy}lssi+`cURyq$P&W(ss@Cjx4i^cU%$>ouzQ5Gdt z0_)SX45fvkY|0ime}-Hh`7@F<9x)rGG$wLMUVM!$`CBsvM;Q#Co;2B630)p!-Ch}# z19-n;@D5#`rg3?sW3zSv{bEsYcm6V@sNMSy)vG*jIjJ<>>!B zxjb?&AJG7)&Y54+FqW|hlugRc;POb_0~4W48D3?`9F{@NmVvVO3m61>_aBb6E3pHrZPFI!Kj8nl)Yy_uo(kgt zdGiQhpJ%%OHMUStH#jJu%YzzQBuOc(h>bl0BAlkzCKuHCiEyTm&-z6;b7SiO`MW^= zWpQ~n)DbIz_35co*uvOo$`&|(=3JhmO6;FNmq*%!vWG_*&wYB*WS@KHj{0J2K1sWU zE{|;bA?tRN^M@K+58(2IPCZ&4i5Gto?S#PYao>nPFF;dMIyS-OxsgZ+EvZ1m84>e~ zMBo*){JqEs_0-ss=3N$6RRZ>vA6Ys2KYwTbQ4IiT8PP^4s)bNd5@SM;)Hg|1UeELK zgr~>HZ~xwY_x|VcPuwuQaZSTm#v)KQDLa?X+(am{lOzTLba^tP3kv}j0(5y2D}eTN zr0O<0RkwckzA|JEH~%g-f06TCVHqfUKQwJyDuW>J{=>0$C3ZlyP1@r82mC)rF3(2j zrVQ%On@1Tq2wfhe_9C@6@_>TN11=A^JTlAw{0r)){j&9oaOTF=0rGc&{90hecI z4kmPYz~zaoHE?;jOV$dvebayK_;b_SI3FBiW$}(HqSEKj!>=E^7mI=e%bR0=Vy*`sCj$?!Hp2`^#4uW446g zmA7O%7v!clzkKSxw@4wx46Kgqvz(_13#EO?EL};LEil*wgakd z65xLZzea-o<~eeCDnk?mA? z>fxz}r#_u^iyB)^70?fkP3ZDKmuEvXTa|{ZWHp=^?AO$`E$IKexjaWV0M3caQ@KT; zoLO1J6}mhv$nHaSKd?XH-iLc1?tRG*2lsx!W)(!%FylcPG6$EZsa&31kXDJ)KW{=E zZkho8%RbW9xpH}OCsdg@K;Aq8*xzs$0PF+o1MKThL4HoxW%?6$+fUrqD7nVqed8fZ zFr+BcKVEF^3J5giEVHH1Z+~>1-?;9J-!G<5o4^0W-DgwhblEc{mIlxHiC!Bt;4|0f z6_-$+yWE>Q7Kr=dEH{|XI+Q{+(V1m6C%0D|pY@Ayrnw=>#0JRU1@en&bSNnMx&0o@ zXCg3J%w0@GilNwXD&X>Ls3TSa>(if57|w4rWec1?b1u(OCH7CK%M)xu$-WTH&oUT3 zJ!!JfJ#$BWu{94akJi()eoq@^h8J8OaCyMx0hcE{M53bv*xi3!1~4x$U@T{4yf9y% z$5qw>D41-d8ApAwC^*3UE->F5U7lRHRteZw&b7+X|M_!yj%om$8<%Iph$~|eC}&o( z^+o5!nVSejc9O(EfG$sFbYUUDLV$&kwh*Ap(^y@e5<8&UCT(&41OA_zE>EsuSqAmz&7%w)gf0(sd7#S^xl2LZ2XP<7{Yxh9*Du1E z8(Rm+-v#oE#r4mH%abK93ITCJ6QVx?9dSL0A#IZr558nv0j+4GDO=$DnR9uLDzSfJ zF3-l0mBH}2`^{xI>Wi)U#8nSn9y#X(o_cud;i*r1>Y>ZiWL=*6v3s#7IKccaFkd7B zuYmH!hM|D#UiqNHKKu>1Rteazscl=(|M@%fk7@v%8<%Heij}bllrszNeWdDAowF;h zxP&UaS6qb`T%JaAdFnS2lp%9i1~pp-%HA(v5aiu|VmqMPCISA-KGL(+<*5|)=glL4 zeSm#{eG(+0*zA8K+5*K+-Yl1vsWYF-?**DNj&1smYub;QRYRA)bv*wqxBXC6CRcst z-785&nED&TAYB;md)HYl#Zxz*_1=CqUB_O~6*;vH(sbpc{8;f{prT^ZkXpey7-lG^J4n* z8-LDkm>!%W-v8VLx+CI|Q~oG6AK$roaonfQe|_h;H~e?DSXz91Gxz5oE=tCp=OEkSDgPtO-tK< zV*GDu1Hk!TsB=qR^q&^F=*XrcXU3QRwEoUtTjLg41dEg(vGvJWxjHF}wK_CgI^B4e z_!xMygbVO{=b5{*i5n-(uqs;je}DM) zz-Ea%*X@zb9eU)J-dg#l)g@Co=*zZcdj6Kz=Uljco3OmA`1<#6NqFg?K@oSZ+Y=kb zb$>Tmx|MwQn@`^#_}${p^>>HmZK@cFpM;m|2P-c-k@eTAE!9v>3bbb%P{Xd{U5bXcLgIMCiE#vQ!*ZW1@<5RyCJ!R;QuKxu0?O%Yy9WTo15gUUG6s%_8b5HUwT@9FrxS`{C`D9@$l;o z9Dnk~7oP+BjX(K+$)kUZ{r~Vm-Q&&@<3H>SMxB0vX>h>!-}MGq|9cGM!IzdFf6KI2 zzfai07!9|yA{hU>yW;Vm;cf4Z*1y)BI}6@@vQsgtj?rCOD~c+%bw*??@~GtjmGwa- zHmYc%<~J1apLP6ijsJIbEB~GDvYAz2_5VeTd*S%cU0wh@9yQA~Jiv2$`Q8ycU_4|Lk>DNa9 z7UQpo|Mq*MApSe(jqZlpAmIO!1&H`>yngEZGah|X{d@6R0Zmk#{fH0)C&}578cy!kv-Q5oF27|%FSX|XzvPIiu zy1|#0^V+5al=h1GA`yZf<59i|y)`IRDjt=95~7@%!8Lypxj6Z0)X;ygOp3%!DEcgJ z7We(1Z*KaXL8m8fae4In_#;Ca?9B~*6kQwV(u5&dakB&);|vY?;e*cIZ6~VO^C!JS z{QrMXMPX>$xM_KVunXyfrYpgw6Hk4aKlR&G47%;TdTq}WAKmt6kD`h+QLTO6kGkNA zzlzI~Z=3|b?fyc{Im=;2S3JVhbI%g!FjUGS`pa;+c=mGQqdH_9u9zYME2haoP p0rUWR06l;nKo6h?&;#fJ^Z item } + + default-tags = local.default-tags + pset-name = each.value.name + pset-desc = each.value.desc + pset-managed-policy-arn = each.value.mpolicy + pset-session-duration = each.value.session + +} + +locals { + csv_data = <<-CSV + name,desc,mpolicy,session + ViewOnly,View only access,arn:aws:iam::aws:policy/job-function/ViewOnlyAccess,PT4H + ReadOnly,Read only access,arn:aws:iam::aws:policy/ReadOnlyAccess,PT4H + FullAccess,Full admin access,arn:aws:iam::aws:policy/AdministratorAccess,PT4H + NetworkAdmin,Network admin access,arn:aws:iam::aws:policy/job-function/NetworkAdministrator,PT4H + DatabaseAdmin,Database admin access,arn:aws:iam::aws:policy/job-function/DatabaseAdministrator,PT4H + BillingAdmin,Billing admin access,arn:aws:iam::aws:policy/job-function/Billing,PT4H + SecurityAudit,Security admin access,arn:aws:iam::aws:policy/SecurityAudit,PT4H + PowerUser,Full access excluding IAM,arn:aws:iam::aws:policy/PowerUserAccess,PT4H + CSV + + items = csvdecode(local.csv_data) +} \ No newline at end of file diff --git a/examples/bea-sso-preview/provider.tf b/examples/bea-sso-preview/provider.tf new file mode 100644 index 0000000..a971ca5 --- /dev/null +++ b/examples/bea-sso-preview/provider.tf @@ -0,0 +1,13 @@ +provider "aws" { + region = var.aws-region +} + +terraform { + required_version = ">= 1.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 3.25" + } + } +} diff --git a/examples/bea-sso-preview/sso-users.tf b/examples/bea-sso-preview/sso-users.tf new file mode 100644 index 0000000..10382b7 --- /dev/null +++ b/examples/bea-sso-preview/sso-users.tf @@ -0,0 +1,64 @@ +data "aws_ssoadmin_instances" "sso1" {} + +locals { + csv_data2 = <<-CSV + username,email,lastName,firstName + user1,user1@acme.local,Doe,John + user2,user2@acme.local,Smith,Jane + CSV + + users = csvdecode(local.csv_data2) +} + +resource "aws_identitystore_user" "sso-user" { + for_each = { for item in local.users : item.username => item } + identity_store_id = tolist(data.aws_ssoadmin_instances.sso1.identity_store_ids)[0] + display_name = "${each.value.firstName} ${each.value.lastName}" + user_name = each.value.username + nickname = each.value.username + emails { + primary = true + value = each.value.email + } + + name { + family_name = each.value.lastName + given_name = each.value.firstName + } +} + +resource "aws_identitystore_group" "sso-group" { + identity_store_id = tolist(data.aws_ssoadmin_instances.sso1.identity_store_ids)[0] + display_name = "Viewers" + description = "Users with view permission" +} + +resource "aws_identitystore_group_membership" "sso-group-membership" { + for_each = aws_identitystore_user.sso-user + identity_store_id = tolist(data.aws_ssoadmin_instances.sso1.identity_store_ids)[0] + group_id = aws_identitystore_group.sso-group.group_id + member_id = each.value.user_id +} + +locals { + csv_data3 = <<-CSV + seq,groupName,permission,accountId + 1,Viewers,ViewOnly,865184416664 + 2,Viewers,ViewOnly,572802010687 + CSV + + accounts = csvdecode(local.csv_data3) +} + +resource "aws_ssoadmin_account_assignment" "pset-assignment" { + for_each = { for item in local.accounts : item.seq => item } + + instance_arn = tolist(data.aws_ssoadmin_instances.sso1.arns)[0] + permission_set_arn = module.sso[each.value.permission].pset-arn + + principal_id = aws_identitystore_group.sso-group.group_id + principal_type = "GROUP" + + target_id = each.value.accountId + target_type = "AWS_ACCOUNT" +} \ No newline at end of file diff --git a/examples/bea-sso-preview/terraform.tfstate b/examples/bea-sso-preview/terraform.tfstate new file mode 100644 index 0000000..708e28d --- /dev/null +++ b/examples/bea-sso-preview/terraform.tfstate @@ -0,0 +1,9 @@ +{ + "version": 4, + "terraform_version": "1.3.5", + "serial": 66, + "lineage": "b72dc65d-13d0-2661-89b8-fa46cc9e8bbd", + "outputs": {}, + "resources": [], + "check_results": null +} diff --git a/examples/bea-sso-preview/terraform.tfstate.backup b/examples/bea-sso-preview/terraform.tfstate.backup new file mode 100644 index 0000000..4bf1878 --- /dev/null +++ b/examples/bea-sso-preview/terraform.tfstate.backup @@ -0,0 +1,1033 @@ +{ + "version": 4, + "terraform_version": "1.3.5", + "serial": 32, + "lineage": "b72dc65d-13d0-2661-89b8-fa46cc9e8bbd", + "outputs": {}, + "resources": [ + { + "mode": "data", + "type": "aws_caller_identity", + "name": "this", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "account_id": "410429265162", + "arn": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "id": "410429265162", + "user_id": "AIDAV7D35SUFD6WRSHFSO" + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "managed", + "type": "aws_identitystore_group", + "name": "sso-group", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "description": "Users with view permission", + "display_name": "Viewers", + "external_ids": [], + "group_id": "2422fcce-a051-7085-107a-afe88b5684fd", + "id": "d-c4673f6b60/2422fcce-a051-7085-107a-afe88b5684fd", + "identity_store_id": "d-c4673f6b60" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "mode": "managed", + "type": "aws_identitystore_group_membership", + "name": "sso-group-membership", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "index_key": "user1", + "schema_version": 0, + "attributes": { + "group_id": "2422fcce-a051-7085-107a-afe88b5684fd", + "id": "d-c4673f6b60/04225cfe-0071-70bd-1845-8ad98e64d0c0", + "identity_store_id": "d-c4673f6b60", + "member_id": "0422fcfe-50b1-708a-a599-aa68e028ef3a", + "membership_id": "04225cfe-0071-70bd-1845-8ad98e64d0c0" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "aws_identitystore_group.sso-group", + "aws_identitystore_user.sso-user", + "data.aws_ssoadmin_instances.sso1" + ] + }, + { + "index_key": "user2", + "schema_version": 0, + "attributes": { + "group_id": "2422fcce-a051-7085-107a-afe88b5684fd", + "id": "d-c4673f6b60/f4028cfe-60b1-7038-df00-d1b5b1724f60", + "identity_store_id": "d-c4673f6b60", + "member_id": "d402ec2e-f001-70bf-63fa-f74aeda77b5f", + "membership_id": "f4028cfe-60b1-7038-df00-d1b5b1724f60" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "aws_identitystore_group.sso-group", + "aws_identitystore_user.sso-user", + "data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "mode": "managed", + "type": "aws_identitystore_user", + "name": "sso-user", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "index_key": "user1", + "schema_version": 0, + "attributes": { + "addresses": [], + "display_name": "John Doe", + "emails": [ + { + "primary": true, + "type": "", + "value": "user1@acme.local" + } + ], + "external_ids": [], + "id": "d-c4673f6b60/0422fcfe-50b1-708a-a599-aa68e028ef3a", + "identity_store_id": "d-c4673f6b60", + "locale": "", + "name": [ + { + "family_name": "Doe", + "formatted": "", + "given_name": "John", + "honorific_prefix": "", + "honorific_suffix": "", + "middle_name": "" + } + ], + "nickname": "user1", + "phone_numbers": [], + "preferred_language": "", + "profile_url": "", + "timezone": "", + "title": "", + "user_id": "0422fcfe-50b1-708a-a599-aa68e028ef3a", + "user_name": "user1", + "user_type": "" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_ssoadmin_instances.sso1" + ] + }, + { + "index_key": "user2", + "schema_version": 0, + "attributes": { + "addresses": [], + "display_name": "Jane Smith", + "emails": [ + { + "primary": true, + "type": "", + "value": "user2@acme.local" + } + ], + "external_ids": [], + "id": "d-c4673f6b60/d402ec2e-f001-70bf-63fa-f74aeda77b5f", + "identity_store_id": "d-c4673f6b60", + "locale": "", + "name": [ + { + "family_name": "Smith", + "formatted": "", + "given_name": "Jane", + "honorific_prefix": "", + "honorific_suffix": "", + "middle_name": "" + } + ], + "nickname": "user2", + "phone_numbers": [], + "preferred_language": "", + "profile_url": "", + "timezone": "", + "title": "", + "user_id": "d402ec2e-f001-70bf-63fa-f74aeda77b5f", + "user_name": "user2", + "user_type": "" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "mode": "managed", + "type": "aws_ssoadmin_account_assignment", + "name": "pset-assignment", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "index_key": "1", + "schema_version": 0, + "attributes": { + "id": "2422fcce-a051-7085-107a-afe88b5684fd,GROUP,865184416664,AWS_ACCOUNT,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-69eea04a59288b4c,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-69eea04a59288b4c", + "principal_id": "2422fcce-a051-7085-107a-afe88b5684fd", + "principal_type": "GROUP", + "target_id": "865184416664", + "target_type": "AWS_ACCOUNT" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "aws_identitystore_group.sso-group", + "data.aws_caller_identity.this", + "data.aws_ssoadmin_instances.sso1", + "module.sso.aws_ssoadmin_managed_policy_attachment.psetatt", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + }, + { + "index_key": "2", + "schema_version": 0, + "attributes": { + "id": "2422fcce-a051-7085-107a-afe88b5684fd,GROUP,572802010687,AWS_ACCOUNT,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-69eea04a59288b4c,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-69eea04a59288b4c", + "principal_id": "2422fcce-a051-7085-107a-afe88b5684fd", + "principal_type": "GROUP", + "target_id": "572802010687", + "target_type": "AWS_ACCOUNT" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "aws_identitystore_group.sso-group", + "data.aws_caller_identity.this", + "data.aws_ssoadmin_instances.sso1", + "module.sso.aws_ssoadmin_managed_policy_attachment.psetatt", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"BillingAdmin\"]", + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "module": "module.sso[\"BillingAdmin\"]", + "mode": "managed", + "type": "aws_ssoadmin_managed_policy_attachment", + "name": "psetatt", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "id": "arn:aws:iam::aws:policy/job-function/Billing,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-741b160413072d1a,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "managed_policy_arn": "arn:aws:iam::aws:policy/job-function/Billing", + "managed_policy_name": "Billing", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-741b160413072d1a" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"BillingAdmin\"]", + "mode": "managed", + "type": "aws_ssoadmin_permission_set", + "name": "pset", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-741b160413072d1a", + "created_date": "2022-12-08T04:05:25Z", + "description": "Billing admin access", + "id": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-741b160413072d1a,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "name": "BillingAdmin", + "relay_state": "", + "session_duration": "PT4H", + "tags": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + }, + "tags_all": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + } + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"DatabaseAdmin\"]", + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "module": "module.sso[\"DatabaseAdmin\"]", + "mode": "managed", + "type": "aws_ssoadmin_managed_policy_attachment", + "name": "psetatt", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "id": "arn:aws:iam::aws:policy/job-function/DatabaseAdministrator,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-3ba41a4ccf37858b,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "managed_policy_arn": "arn:aws:iam::aws:policy/job-function/DatabaseAdministrator", + "managed_policy_name": "DatabaseAdministrator", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-3ba41a4ccf37858b" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"DatabaseAdmin\"]", + "mode": "managed", + "type": "aws_ssoadmin_permission_set", + "name": "pset", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-3ba41a4ccf37858b", + "created_date": "2022-12-08T04:05:25Z", + "description": "Database admin access", + "id": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-3ba41a4ccf37858b,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "name": "DatabaseAdmin", + "relay_state": "", + "session_duration": "PT4H", + "tags": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + }, + "tags_all": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + } + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"FullAccess\"]", + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "module": "module.sso[\"FullAccess\"]", + "mode": "managed", + "type": "aws_ssoadmin_managed_policy_attachment", + "name": "psetatt", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "id": "arn:aws:iam::aws:policy/AdministratorAccess,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-56d8a2c16f68a7d5,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "managed_policy_arn": "arn:aws:iam::aws:policy/AdministratorAccess", + "managed_policy_name": "AdministratorAccess", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-56d8a2c16f68a7d5" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"FullAccess\"]", + "mode": "managed", + "type": "aws_ssoadmin_permission_set", + "name": "pset", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-56d8a2c16f68a7d5", + "created_date": "2022-12-08T04:05:25Z", + "description": "Full admin access", + "id": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-56d8a2c16f68a7d5,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "name": "FullAccess", + "relay_state": "", + "session_duration": "PT4H", + "tags": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + }, + "tags_all": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + } + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"NetworkAdmin\"]", + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "module": "module.sso[\"NetworkAdmin\"]", + "mode": "managed", + "type": "aws_ssoadmin_managed_policy_attachment", + "name": "psetatt", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "id": "arn:aws:iam::aws:policy/job-function/NetworkAdministrator,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-b6d41e12b42a497f,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "managed_policy_arn": "arn:aws:iam::aws:policy/job-function/NetworkAdministrator", + "managed_policy_name": "NetworkAdministrator", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-b6d41e12b42a497f" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"NetworkAdmin\"]", + "mode": "managed", + "type": "aws_ssoadmin_permission_set", + "name": "pset", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-b6d41e12b42a497f", + "created_date": "2022-12-08T04:05:25Z", + "description": "Network admin access", + "id": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-b6d41e12b42a497f,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "name": "NetworkAdmin", + "relay_state": "", + "session_duration": "PT4H", + "tags": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + }, + "tags_all": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + } + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"PowerUser\"]", + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "module": "module.sso[\"PowerUser\"]", + "mode": "managed", + "type": "aws_ssoadmin_managed_policy_attachment", + "name": "psetatt", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "id": "arn:aws:iam::aws:policy/PowerUserAccess,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-385816375bd2af48,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "managed_policy_arn": "arn:aws:iam::aws:policy/PowerUserAccess", + "managed_policy_name": "PowerUserAccess", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-385816375bd2af48" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"PowerUser\"]", + "mode": "managed", + "type": "aws_ssoadmin_permission_set", + "name": "pset", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-385816375bd2af48", + "created_date": "2022-12-08T04:05:25Z", + "description": "Full access excluding IAM", + "id": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-385816375bd2af48,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "name": "PowerUser", + "relay_state": "", + "session_duration": "PT4H", + "tags": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + }, + "tags_all": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + } + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"ReadOnly\"]", + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "module": "module.sso[\"ReadOnly\"]", + "mode": "managed", + "type": "aws_ssoadmin_managed_policy_attachment", + "name": "psetatt", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "id": "arn:aws:iam::aws:policy/ReadOnlyAccess,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-2e81d873215880a2,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "managed_policy_arn": "arn:aws:iam::aws:policy/ReadOnlyAccess", + "managed_policy_name": "ReadOnlyAccess", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-2e81d873215880a2" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"ReadOnly\"]", + "mode": "managed", + "type": "aws_ssoadmin_permission_set", + "name": "pset", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-2e81d873215880a2", + "created_date": "2022-12-08T04:05:25Z", + "description": "Read only access", + "id": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-2e81d873215880a2,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "name": "ReadOnly", + "relay_state": "", + "session_duration": "PT4H", + "tags": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + }, + "tags_all": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + } + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"SecurityAudit\"]", + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "module": "module.sso[\"SecurityAudit\"]", + "mode": "managed", + "type": "aws_ssoadmin_managed_policy_attachment", + "name": "psetatt", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "id": "arn:aws:iam::aws:policy/SecurityAudit,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-8750449339258dae,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "managed_policy_arn": "arn:aws:iam::aws:policy/SecurityAudit", + "managed_policy_name": "SecurityAudit", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-8750449339258dae" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"SecurityAudit\"]", + "mode": "managed", + "type": "aws_ssoadmin_permission_set", + "name": "pset", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-8750449339258dae", + "created_date": "2022-12-08T04:05:25Z", + "description": "Security admin access", + "id": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-8750449339258dae,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "name": "SecurityAudit", + "relay_state": "", + "session_duration": "PT4H", + "tags": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + }, + "tags_all": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + } + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"ViewOnly\"]", + "mode": "data", + "type": "aws_ssoadmin_instances", + "name": "sso1", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arns": [ + "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec" + ], + "id": "ap-east-1", + "identity_store_ids": [ + "d-c4673f6b60" + ] + }, + "sensitive_attributes": [] + } + ] + }, + { + "module": "module.sso[\"ViewOnly\"]", + "mode": "managed", + "type": "aws_ssoadmin_managed_policy_attachment", + "name": "psetatt", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "id": "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess,arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-69eea04a59288b4c,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "managed_policy_arn": "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess", + "managed_policy_name": "ViewOnlyAccess", + "permission_set_arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-69eea04a59288b4c" + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.aws_ssoadmin_permission_set.pset", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + }, + { + "module": "module.sso[\"ViewOnly\"]", + "mode": "managed", + "type": "aws_ssoadmin_permission_set", + "name": "pset", + "provider": "provider[\"registry.terraform.io/hashicorp/aws\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "arn": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-69eea04a59288b4c", + "created_date": "2022-12-08T04:05:25Z", + "description": "View only access", + "id": "arn:aws:sso:::permissionSet/ssoins-7158fc0aa3f872ec/ps-69eea04a59288b4c,arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "instance_arn": "arn:aws:sso:::instance/ssoins-7158fc0aa3f872ec", + "name": "ViewOnly", + "relay_state": "", + "session_duration": "PT4H", + "tags": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + }, + "tags_all": { + "Application": "sso", + "BuildDate": "20221208", + "CreatedBy": "arn:aws:iam::410429265162:user/pam-admin-mgt-msp", + "Environment": "preview", + "Project": "security", + "ServiceProvider": "None", + "TerraformDir": "terraform.aws-baseline-infra/examples/bea-sso-preview", + "TerraformMode": "managed" + } + }, + "sensitive_attributes": [], + "private": "bnVsbA==", + "dependencies": [ + "data.aws_caller_identity.this", + "module.sso.data.aws_ssoadmin_instances.sso1" + ] + } + ] + } + ], + "check_results": null +} diff --git a/examples/bea-sso-preview/terraform.tfvars b/examples/bea-sso-preview/terraform.tfvars new file mode 100644 index 0000000..3593084 --- /dev/null +++ b/examples/bea-sso-preview/terraform.tfvars @@ -0,0 +1,7 @@ +aws-region = "ap-east-1" +aws-region-short = "ape1" +customer-name = "bea" +environment = "preview" +project = "security" +application = "sso" + diff --git a/examples/bea-sso-preview/variables.tf b/examples/bea-sso-preview/variables.tf new file mode 100644 index 0000000..fda8540 --- /dev/null +++ b/examples/bea-sso-preview/variables.tf @@ -0,0 +1,6 @@ +variable "aws-region" {} +variable "aws-region-short" {} +variable "customer-name" {} +variable "environment" {} +variable "project" {} +variable "application" {} diff --git a/examples/deployer.ec2/main.tf b/examples/deployer.ec2/main.tf new file mode 100644 index 0000000..8d40a0a --- /dev/null +++ b/examples/deployer.ec2/main.tf @@ -0,0 +1,39 @@ +module "deployer-ec2" { + source = "../../modules/compute/ec2" + + additional_tags = { "Backup" : "None" } + # ami-id = "ami-072e4595d41025d94" + ami-id = data.aws_ami.ami-lookup.id + default-tags = local.default-tags + ebs-encrypted = true + asso-eip = false + instance-name = "rackspace-deployer-ec2-test" + instance-type = "t3.micro" + key-name = "whk1-ec2-key-555344966285" + asso-public-ip = false + root-volume-size = 15 + security-groups = ["sg-03282995027b7a9fc"] + subnet-id = "subnet-07e4392828a70b1f9" + instance-profile = "TerraformRole" +} + +data "aws_ami" "ami-lookup" { + most_recent = true + + filter { + name = "name" + values = ["CIS Amazon Linux 2 Kernel 5.10*"] + } + + filter { + name = "virtualization-type" + values = ["hvm"] + } + + filter { + name = "architecture" + values = ["x86_64"] + } + + owners = ["211372476111"] # CIS +} \ No newline at end of file diff --git a/examples/deployer.ec2/terraform.tfvars b/examples/deployer.ec2/terraform.tfvars new file mode 100644 index 0000000..eea3d16 --- /dev/null +++ b/examples/deployer.ec2/terraform.tfvars @@ -0,0 +1,8 @@ +aws-region = "ap-southeast-1" +customer-name = "bea" +environment = "dev" +project = "iac" +application = "terraform" +CostCenter = "none" +DynamicAddressGroup = "" +Owner = "Rackspace" \ No newline at end of file diff --git a/examples/deployer.ec2/variables.tf b/examples/deployer.ec2/variables.tf new file mode 100644 index 0000000..53c2652 --- /dev/null +++ b/examples/deployer.ec2/variables.tf @@ -0,0 +1,25 @@ +variable "aws-region" {} +variable "customer-name" {} +variable "environment" {} +variable "project" {} +variable "application" {} +variable "owner" {} +variable "costcenter" {} +variable "DynamicAddressGroup" {} + +locals { + default-tags = { + ServiceProvider = "RackspaceTechnology" + Environment = var.environment + Project = var.project + Application = var.application + TerraformMode = "managed" + BuildDate = formatdate("YYYYMMDD", timestamp()) + Owner = var.owner + CostCenter = var.costcenter + DynamicAddressGroup = var.DynamicAddressGroup + + } + resource-prefix = "${var.environment}-substr(${var.aws-region},0,2)-${var.customer-name}-${var.project}" +} + diff --git a/examples/eks-lab-ip6/eks/.terraform.lock.hcl b/examples/eks-lab-ip6/eks/.terraform.lock.hcl new file mode 100644 index 0000000..5e1c159 --- /dev/null +++ b/examples/eks-lab-ip6/eks/.terraform.lock.hcl @@ -0,0 +1,10 @@ +# This file is maintained automatically by "terraform init". +# Manual edits may be lost in future updates. + +provider "registry.terraform.io/hashicorp/aws" { + version = "4.55.0" + constraints = ">= 3.25.0" + hashes = [ + "h1:VHfmrKCb4oTW/+rWGKKqipoMOPd4tPxlGwMp0/Flx/s=", + ] +} diff --git a/examples/eks-lab-ip6/eks/.terraform/providers/registry.terraform.io/hashicorp/aws/4.55.0/linux_amd64 b/examples/eks-lab-ip6/eks/.terraform/providers/registry.terraform.io/hashicorp/aws/4.55.0/linux_amd64 new file mode 120000 index 0000000..612bb8d --- /dev/null +++ b/examples/eks-lab-ip6/eks/.terraform/providers/registry.terraform.io/hashicorp/aws/4.55.0/linux_amd64 @@ -0,0 +1 @@ +/home/kn/.terraform.d/plugin-cache/registry.terraform.io/hashicorp/aws/4.55.0/linux_amd64 \ No newline at end of file diff --git a/examples/eks-lab-ip6/eks/README.md b/examples/eks-lab-ip6/eks/README.md new file mode 100644 index 0000000..e22ef16 --- /dev/null +++ b/examples/eks-lab-ip6/eks/README.md @@ -0,0 +1,119 @@ +# eks-lab/eks +This layer creates the following resources +- EKS cluster using ipv6 for service network +- EKS nodegroup +- EKS bastion +- Install eksctl, kubectl, awscliv2, helm on EKS bastion with user_data script + +Be patient. EKS cluster takes 12min to provision. Node group will take another 5 min. And the cluster addon takes another ?? min. + +## Worker node instance size +Choose t3.large at the minimum. This is due to AWS's limitation on number of IPs. Smaller instanecs are limited with 6 IP +which is not enough. See https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html#AvailableIpPerENI + +## How to use eksctl and kubectl +By default, AWS EKS are installed with an aws-auth configmap which allows only the cluster creator +to work with the cluster. Therefore, one must first assume to the creator IAM role before running eksctl or kubectl. +For example, to create kube config, run these commands: + +```bash +export AWS_ACCESS_KEY_ID=xxxx AWS_SECRET_ACCESS_KEY="yyyy" AWS_DEFAULT_REGION=ap-northeast-1 +aws eks update-kubeconfig --name lab-apne1-xpk-iac-cluster01 +``` + +## Edit configmap/aws-auth +``` +kubectl edit -n kube-system configmap/aws-auth +``` +Add a group with system:master role +```yaml +apiVersion: v1 +data: + mapRoles: | + - groups: + - system:bootstrappers + - system:nodes + rolearn: arn:aws:iam::040216112220:role/clusterCreator + username: system:node:Template:EC2PrivateDNSName + - groups: + - system:masters + rolearn: arn:aws:iam::040216112220:role/lab-apne1-xpk-iac-bast-role + username: lab-apne1-xpk-iac-bast-role +kind: ConfigMap +metadata: + creationTimestamp: "2022-12-29T11:02:15Z" + name: aws-auth + namespace: kube-system + resourceVersion: "59670" + uid: 7cf9d889-8ed2-4c8d-ac0f-092184cede8a +``` + +## Addon updates +When updating addons, please select advanced options and choose preserve settings. + +## Install ALB ingress controller +AWS provides documentation on how to deploy a sample application with ingress (ALB) +https://docs.aws.amazon.com/eks/latest/userguide/alb-ingress.html + +That depends on the load balancer container, which can be deployed by + +```bash +curl -O https://raw.githubusercontent.com/kubernetes-sigs/aws-load-balancer-controller/v2.4.4/docs/install/iam_policy.json + +aws iam create-policy \ +--policy-name AWSLoadBalancerControllerIAMPolicy \ +--policy-document file://iam_policy.json + +``` +Create an openid provider on iam +https://docs.aws.amazon.com/eks/latest/userguide/enable-iam-roles-for-service-accounts.html + +``` +eksctl create iamserviceaccount \ + --cluster=lab-apne1-xpk-iac-cluster01 \ + --namespace=kube-system \ + --name=aws-load-balancer-controller \ + --role-name AmazonEKSLoadBalancerControllerRole \ + --attach-policy-arn=arn:aws:iam::040216112220:policy/AWSLoadBalancerControllerIAMPolicy \ + --approve + +helm repo add eks https://aws.github.io/eks-charts +helm repo update +helm install aws-load-balancer-controller eks/aws-load-balancer-controller \ +-n kube-system \ +--set clusterName=lab-apne1-xpk-iac-cluster01 \ +--set serviceAccount.create=false \ +--set serviceAccount.name=aws-load-balancer-controller +``` + +## Tag subnets +Reference: https://docs.aws.amazon.com/eks/latest/userguide/alb-ingress.html + +The following tags are set in the network layer: + +On private subnets: +Key – kubernetes.io/role/internal-elb +Value – 1 + +On public subnets: +Key – kubernetes.io/role/elb +Value – 1 + + +## Install sample app the 2048 game +See https://docs.aws.amazon.com/eks/latest/userguide/alb-ingress.html +```bash +curl -O https://raw.githubusercontent.com/kubernetes-sigs/aws-load-balancer-controller/v2.4.4/docs/examples/2048/2048_full.yaml +edit the file +kubectl apply -f 2048_full.yaml +kubectl get ingress/ingress-2048 -n game-2048 +``` + +In a moment, the lb address should be displayed +```bash +root@ip-192-168-123-187:~# kubectl get ingress/ingress-2048 -n game-2048 +NAME CLASS HOSTS ADDRESS PORTS AGE +ingress-2048 alb * internal-k8s-game2048-ingress2-5f196824a1-20502803.ap-northeast-1.elb.amazonaws.com 80 7s +``` + + diff --git a/examples/eks-lab-ip6/eks/eks-node-sshkey b/examples/eks-lab-ip6/eks/eks-node-sshkey new file mode 100644 index 0000000..2cc109d --- /dev/null +++ b/examples/eks-lab-ip6/eks/eks-node-sshkey @@ -0,0 +1,7 @@ +-----BEGIN OPENSSH PRIVATE KEY----- +b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW +QyNTUxOQAAACDQnEGn3cwEav+pMKXYvP3KjDYpB+Po/wpcrmQZnh31wgAAAJDu9hUF7vYV +BQAAAAtzc2gtZWQyNTUxOQAAACDQnEGn3cwEav+pMKXYvP3KjDYpB+Po/wpcrmQZnh31wg +AAAEBcvMSW9eqRM2Kd3obuJfHma+nzrsMiRSHO09wjSg4KF9CcQafdzARq/6kwpdi8/cqM +NikH4+j/ClyuZBmeHfXCAAAADWtuQGlzbS56b28ubG8= +-----END OPENSSH PRIVATE KEY----- diff --git a/examples/eks-lab-ip6/eks/eks-node-sshkey.pub b/examples/eks-lab-ip6/eks/eks-node-sshkey.pub new file mode 100644 index 0000000..ca03027 --- /dev/null +++ b/examples/eks-lab-ip6/eks/eks-node-sshkey.pub @@ -0,0 +1 @@ +ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINCcQafdzARq/6kwpdi8/cqMNikH4+j/ClyuZBmeHfXC kn@ism.zoo.lo diff --git a/examples/eks-lab-ip6/eks/locals.tf b/examples/eks-lab-ip6/eks/locals.tf new file mode 100644 index 0000000..8719f76 --- /dev/null +++ b/examples/eks-lab-ip6/eks/locals.tf @@ -0,0 +1,18 @@ +data "aws_caller_identity" "this" {} + +locals { + default-tags = merge({ + ServiceProvider = "None" + Environment = var.environment + Project = var.project + Application = var.application + TerraformMode = "managed" + TerraformDir = "${local.path-cwd-list[length(local.path-cwd-list) - 2]}/${local.path-cwd-list[length(local.path-cwd-list) - 1]}" + + CreatedBy = data.aws_caller_identity.this.arn + BuildDate = formatdate("YYYYMMDD", timestamp()) + }) + resource-prefix = "${var.environment}-${var.aws-region-short}-${var.customer-name}-${var.project}" + path-cwd-list = split("/", path.cwd) + +} \ No newline at end of file diff --git a/examples/eks-lab-ip6/eks/main.tf b/examples/eks-lab-ip6/eks/main.tf new file mode 100644 index 0000000..5753163 --- /dev/null +++ b/examples/eks-lab-ip6/eks/main.tf @@ -0,0 +1,306 @@ +data "terraform_remote_state" "vpc" { + backend = "local" + config = { + path = "../network/terraform.tfstate" + } +} + +resource "aws_iam_role" "eks-cluster-role" { + name = "${local.resource-prefix}-cluster-role" + assume_role_policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "eks.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) + managed_policy_arns = ["arn:aws:iam::aws:policy/AmazonEKSClusterPolicy", "arn:aws:iam::aws:policy/AmazonEKSVPCResourceController"] + tags = local.default-tags +} + +resource "aws_eks_cluster" "eks-cluster" { + name = "${local.resource-prefix}-cluster01" + role_arn = aws_iam_role.eks-cluster-role.arn + vpc_config { + subnet_ids = data.terraform_remote_state.vpc.outputs.private-subnet-ids + endpoint_private_access = true + endpoint_public_access = false + } + enabled_cluster_log_types = ["api", "audit"] + kubernetes_network_config { + ip_family = "ipv6" + } + tags = local.default-tags +} + + +resource "aws_eks_addon" "eks-addons" { + # for_each = toset(["vpc-cni", "coredns", "kube-proxy", "aws-ebs-csi-driver"]) + # latest version as on 2023-02-17 failed to deploy + for_each = { + "aws-ebs-csi-driver" : { + "version" : "v1.15.0-eksbuild.1" + }, + "vpc-cni" : { + "version" : "v1.12.2-eksbuild.1" + }, + "coredns" : { + "version" : "v1.9.3-eksbuild.2" + }, + "kube-proxy" : { + "version" : "v1.24.9-eksbuild.1" + } + } + cluster_name = aws_eks_cluster.eks-cluster.name + addon_name = each.key + addon_version = each.value["version"] +} + +resource "aws_iam_role" "eks-nodegroup-role" { + name = "${local.resource-prefix}-nodegroup-role" + assume_role_policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "ec2.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) + managed_policy_arns = [ + "arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy", + "arn:aws:iam::aws:policy/AmazonEKS_CNI_Policy", + "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly", + "arn:aws:iam::aws:policy/CloudWatchAgentServerPolicy" + ] + inline_policy { + name = "IP6CniAccess" + policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Action" : [ + "ec2:AssignIpv6Addresses", + "ec2:DescribeInstances", + "ec2:DescribeTags", + "ec2:DescribeNetworkInterfaces", + "ec2:DescribeInstanceTypes" + ], + "Resource" : "*" + }, + { + "Effect" : "Allow", + "Action" : [ + "ec2:CreateTags" + ], + "Resource" : [ + "arn:aws:ec2:*:*:network-interface/*" + ] + } + ] + }) + } + + inline_policy { + name = "AlbIngressAccess" + policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Action" : [ + "elasticloadbalancing:*" + ], + "Resource" : "*" + } + ] + }) + } + + tags = local.default-tags +} + +data "aws_ssm_parameter" "eks_ami_release_version" { + name = "/aws/service/eks/optimized-ami/${aws_eks_cluster.eks-cluster.version}/amazon-linux-2/recommended/release_version" +} + +# manually generate the key: ssh-keygen -ted25519 -f eks-node-sshkey +# file() can only read pre-existing file +resource "aws_key_pair" "eks-node-sshkey" { + key_name = "${local.resource-prefix}-eks-node-sshkey" + public_key = file("${path.module}/eks-node-sshkey.pub") +} + +resource "aws_security_group" "eks-node-sg" { + name = "${local.resource-prefix}-eks-node-sg" + description = "Allow ssh to EKS nodes" + vpc_id = data.terraform_remote_state.vpc.outputs.vpc-id + + ingress { + description = "SSH from VPC" + from_port = 22 + to_port = 22 + protocol = "tcp" + cidr_blocks = [data.terraform_remote_state.vpc.outputs.vpc-cidr] + } + + egress { + from_port = 0 + to_port = 0 + protocol = "-1" + cidr_blocks = ["0.0.0.0/0"] + } + + tags = local.default-tags +} + +resource "aws_eks_node_group" "eks-nodegroup" { + cluster_name = aws_eks_cluster.eks-cluster.name + node_group_name_prefix = "${local.resource-prefix}-eks-ng" + node_role_arn = aws_iam_role.eks-nodegroup-role.arn + subnet_ids = data.terraform_remote_state.vpc.outputs.private-subnet-ids + version = aws_eks_cluster.eks-cluster.version + release_version = nonsensitive(data.aws_ssm_parameter.eks_ami_release_version.value) + instance_types = ["t3.large"] # see README.md + scaling_config { + desired_size = 1 + max_size = 2 + min_size = 1 + } + + update_config { + max_unavailable = 1 + } + remote_access { + ec2_ssh_key = aws_key_pair.eks-node-sshkey.key_name + source_security_group_ids = [aws_security_group.eks-node-sg.id] + } + tags = local.default-tags +} + +# ec2 instance for EKS management +data "aws_ami" "ubuntu" { + most_recent = true + + filter { + name = "name" + values = ["ubuntu/images/hvm-ssd/ubuntu-*-amd64-server-*"] + } + + filter { + name = "virtualization-type" + values = ["hvm"] + } + + owners = ["099720109477"] # Canonical +} + +resource "aws_security_group" "eks-bast-sg" { + name = "${local.resource-prefix}-eks-bast-sg" + description = "Allow ssh to EKS bast" + vpc_id = data.terraform_remote_state.vpc.outputs.vpc-id + + ingress { + description = "SSH from VPC" + from_port = 22 + to_port = 22 + protocol = "tcp" + cidr_blocks = ["223.18.148.85/32"] + } + + egress { + from_port = 0 + to_port = 0 + protocol = "-1" + cidr_blocks = ["0.0.0.0/0"] + } + + tags = local.default-tags +} + + +resource "aws_iam_role" "eks-bast-role" { + name = "${local.resource-prefix}-bast-role" + assume_role_policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "ec2.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + }) + inline_policy { + name = "eks-bast-policy" + + policy = jsonencode({ + Version = "2012-10-17" + Statement = [ + { + Action = ["eks:*", "ecr:*"] + Effect = "Allow" + Resource = "*" + }, + ] + }) + } + + managed_policy_arns = ["arn:aws:iam::aws:policy/ReadOnlyAccess"] + tags = local.default-tags +} + + +resource "aws_iam_instance_profile" "eks-bast-iam-profile" { + name = "eksBastIamProfile" + role = aws_iam_role.eks-bast-role.name +} + +resource "aws_instance" "eks-bast" { + ami = data.aws_ami.ubuntu.id + instance_type = "t3.micro" + associate_public_ip_address = true + ebs_optimized = true + key_name = aws_key_pair.eks-node-sshkey.key_name + vpc_security_group_ids = [aws_security_group.eks-bast-sg.id, aws_eks_cluster.eks-cluster.vpc_config[0].cluster_security_group_id] + subnet_id = data.terraform_remote_state.vpc.outputs.public-subnet-ids[0] + iam_instance_profile = aws_iam_instance_profile.eks-bast-iam-profile.name + root_block_device { + volume_size = 8 + volume_type = "gp3" + tags = local.default-tags + } + tags = merge(local.default-tags, { "Name" : "${local.resource-prefix}-eks-bast" }) + user_data = < +kube-system coredns-5fc8d4cdcf-c75z6 1/1 Running 0 13m 100.64.9.249 ip-192-168-123-245.ap-northeast-1.compute.internal +kube-system coredns-5fc8d4cdcf-h5lnl 1/1 Running 0 13m 100.64.13.41 ip-192-168-123-245.ap-northeast-1.compute.internal +kube-system ebs-csi-controller-d6bff959-8459z 6/6 Running 0 13m 100.64.8.74 ip-192-168-123-245.ap-northeast-1.compute.internal +kube-system ebs-csi-controller-d6bff959-vnwlf 6/6 Running 0 5m28s 100.64.11.124 ip-192-168-123-245.ap-northeast-1.compute.internal +kube-system ebs-csi-node-h7w8r 3/3 Running 0 4m9s 100.64.11.188 ip-192-168-123-245.ap-northeast-1.compute.internal +kube-system kube-proxy-vgmdf 1/1 Running 0 4m9s 192.168.123.245 ip-192-168-123-245.ap-northeast-1.compute.internal + +``` + +## Edit configmap/aws-auth +``` +kubectl edit -n kube-system configmap/aws-auth +``` +Add a group with system:master role +```yaml +apiVersion: v1 +data: + mapRoles: | + - groups: + - system:bootstrappers + - system:nodes + rolearn: arn:aws:iam::040216112220:role/clusterCreator + username: system:node:Template:EC2PrivateDNSName + - groups: + - system:masters + rolearn: arn:aws:iam::040216112220:role/lab-apne1-xpk-iac-bast-role + username: lab-apne1-xpk-iac-bast-role +kind: ConfigMap +metadata: + creationTimestamp: "2022-12-29T11:02:15Z" + name: aws-auth + namespace: kube-system + resourceVersion: "59670" + uid: 7cf9d889-8ed2-4c8d-ac0f-092184cede8a +``` + +## Addon updates +When updating addons, please select advanced options and choose preserve settings. \ No newline at end of file diff --git a/examples/eks-lab/eks/eks-node-sshkey b/examples/eks-lab/eks/eks-node-sshkey new file mode 100644 index 0000000..2cc109d --- /dev/null +++ b/examples/eks-lab/eks/eks-node-sshkey @@ -0,0 +1,7 @@ +-----BEGIN OPENSSH PRIVATE KEY----- +b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW +QyNTUxOQAAACDQnEGn3cwEav+pMKXYvP3KjDYpB+Po/wpcrmQZnh31wgAAAJDu9hUF7vYV +BQAAAAtzc2gtZWQyNTUxOQAAACDQnEGn3cwEav+pMKXYvP3KjDYpB+Po/wpcrmQZnh31wg +AAAEBcvMSW9eqRM2Kd3obuJfHma+nzrsMiRSHO09wjSg4KF9CcQafdzARq/6kwpdi8/cqM +NikH4+j/ClyuZBmeHfXCAAAADWtuQGlzbS56b28ubG8= +-----END OPENSSH PRIVATE KEY----- diff --git a/examples/eks-lab/eks/eks-node-sshkey.pub b/examples/eks-lab/eks/eks-node-sshkey.pub new file mode 100644 index 0000000..ca03027 --- /dev/null +++ b/examples/eks-lab/eks/eks-node-sshkey.pub @@ -0,0 +1 @@ +ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINCcQafdzARq/6kwpdi8/cqMNikH4+j/ClyuZBmeHfXC kn@ism.zoo.lo diff --git a/examples/eks-lab/eks/locals.tf b/examples/eks-lab/eks/locals.tf new file mode 100644 index 0000000..8719f76 --- /dev/null +++ b/examples/eks-lab/eks/locals.tf @@ -0,0 +1,18 @@ +data "aws_caller_identity" "this" {} + +locals { + default-tags = merge({ + ServiceProvider = "None" + Environment = var.environment + Project = var.project + Application = var.application + TerraformMode = "managed" + TerraformDir = "${local.path-cwd-list[length(local.path-cwd-list) - 2]}/${local.path-cwd-list[length(local.path-cwd-list) - 1]}" + + CreatedBy = data.aws_caller_identity.this.arn + BuildDate = formatdate("YYYYMMDD", timestamp()) + }) + resource-prefix = "${var.environment}-${var.aws-region-short}-${var.customer-name}-${var.project}" + path-cwd-list = split("/", path.cwd) + +} \ No newline at end of file diff --git a/examples/eks-lab/eks/main.tf b/examples/eks-lab/eks/main.tf new file mode 100644 index 0000000..9036f17 --- /dev/null +++ b/examples/eks-lab/eks/main.tf @@ -0,0 +1,261 @@ +data "terraform_remote_state" "vpc" { + backend = "local" + config = { + path = "../network/terraform.tfstate" + } +} + +resource "aws_iam_role" "eks-cluster-role" { + name = "${local.resource-prefix}-cluster-role" + assume_role_policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "eks.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) + managed_policy_arns = ["arn:aws:iam::aws:policy/AmazonEKSClusterPolicy", "arn:aws:iam::aws:policy/AmazonEKSVPCResourceController"] + tags = local.default-tags +} + +resource "aws_eks_cluster" "eks-cluster" { + name = "${local.resource-prefix}-cluster01" + role_arn = aws_iam_role.eks-cluster-role.arn + vpc_config { + subnet_ids = data.terraform_remote_state.vpc.outputs.private-subnet-ids + endpoint_private_access = true + endpoint_public_access = false + } + enabled_cluster_log_types = ["api", "audit"] + kubernetes_network_config { + service_ipv4_cidr = "172.16.0.0/16" + ip_family = "ipv4" + } + tags = local.default-tags +} + + +resource "aws_eks_addon" "eks-addons" { + # for_each = toset(["vpc-cni", "coredns", "kube-proxy", "aws-ebs-csi-driver"]) + # latest version as on 2023-02-17 failed to deploy + for_each = { + "aws-ebs-csi-driver" : { + "version" : "v1.15.0-eksbuild.1" + }, + "vpc-cni" : { + "version" : "v1.12.2-eksbuild.1" + }, + "coredns" : { + "version" : "v1.9.3-eksbuild.2" + }, + "kube-proxy" : { + "version" : "v1.24.9-eksbuild.2" + } + } + cluster_name = aws_eks_cluster.eks-cluster.name + addon_name = each.key + # addon_version = each.value["version"] + tags = local.default-tags +} + +resource "aws_iam_role" "eks-nodegroup-role" { + name = "${local.resource-prefix}-nodegroup-role" + assume_role_policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "ec2.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) + managed_policy_arns = [ + "arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy", + "arn:aws:iam::aws:policy/AmazonEKS_CNI_Policy", + "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly", + "arn:aws:iam::aws:policy/CloudWatchAgentServerPolicy" + ] + tags = local.default-tags +} + +data "aws_ssm_parameter" "eks_ami_release_version" { + name = "/aws/service/eks/optimized-ami/${aws_eks_cluster.eks-cluster.version}/amazon-linux-2/recommended/release_version" +} + +# manually generate the key: ssh-keygen -ted25519 -f eks-node-sshkey +# file() can only read pre-existing file +resource "aws_key_pair" "eks-node-sshkey" { + key_name = "${local.resource-prefix}-eks-node-sshkey" + public_key = file("${path.module}/eks-node-sshkey.pub") +} + +resource "aws_security_group" "eks-node-sg" { + name = "${local.resource-prefix}-eks-node-sg" + description = "Allow ssh to EKS nodes" + vpc_id = data.terraform_remote_state.vpc.outputs.vpc-id + + ingress { + description = "SSH from VPC" + from_port = 22 + to_port = 22 + protocol = "tcp" + cidr_blocks = [data.terraform_remote_state.vpc.outputs.vpc-cidr] + } + + egress { + from_port = 0 + to_port = 0 + protocol = "-1" + cidr_blocks = ["0.0.0.0/0"] + } + + tags = local.default-tags +} + +resource "aws_eks_node_group" "eks-nodegroup" { + cluster_name = aws_eks_cluster.eks-cluster.name + node_group_name_prefix = "${local.resource-prefix}-eks-ng" + node_role_arn = aws_iam_role.eks-nodegroup-role.arn + subnet_ids = data.terraform_remote_state.vpc.outputs.private-subnet-ids + version = aws_eks_cluster.eks-cluster.version + release_version = nonsensitive(data.aws_ssm_parameter.eks_ami_release_version.value) + instance_types = ["t3.small"] + scaling_config { + desired_size = 1 + max_size = 2 + min_size = 1 + } + + update_config { + max_unavailable = 1 + } + remote_access { + ec2_ssh_key = aws_key_pair.eks-node-sshkey.key_name + source_security_group_ids = [aws_security_group.eks-node-sg.id] + } + tags = local.default-tags +} + +# ec2 instance for EKS management +data "aws_ami" "ubuntu" { + most_recent = true + + filter { + name = "name" + values = ["ubuntu/images/hvm-ssd/ubuntu-*-amd64-server-*"] + } + + filter { + name = "virtualization-type" + values = ["hvm"] + } + + owners = ["099720109477"] # Canonical +} + +resource "aws_security_group" "eks-bast-sg" { + name = "${local.resource-prefix}-eks-bast-sg" + description = "Allow ssh to EKS bast" + vpc_id = data.terraform_remote_state.vpc.outputs.vpc-id + + ingress { + description = "SSH from VPC" + from_port = 22 + to_port = 22 + protocol = "tcp" + cidr_blocks = ["223.18.148.85/32"] + } + + egress { + from_port = 0 + to_port = 0 + protocol = "-1" + cidr_blocks = ["0.0.0.0/0"] + } + + tags = local.default-tags +} + + +resource "aws_iam_role" "eks-bast-role" { + name = "${local.resource-prefix}-bast-role" + assume_role_policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "ec2.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + }) + inline_policy { + name = "eks-bast-policy" + + policy = jsonencode({ + Version = "2012-10-17" + Statement = [ + { + Action = ["eks:*", "ecr:*"] + Effect = "Allow" + Resource = "*" + }, + ] + }) + } + + managed_policy_arns = ["arn:aws:iam::aws:policy/ReadOnlyAccess"] + tags = local.default-tags +} + + +resource "aws_iam_instance_profile" "eks-bast-iam-profile" { + name = "eksBastIamProfile" + role = aws_iam_role.eks-bast-role.name +} + +resource "aws_instance" "eks-bast" { + ami = data.aws_ami.ubuntu.id + instance_type = "t3.micro" + associate_public_ip_address = true + ebs_optimized = true + key_name = aws_key_pair.eks-node-sshkey.key_name + vpc_security_group_ids = [aws_security_group.eks-bast-sg.id, aws_eks_cluster.eks-cluster.vpc_config[0].cluster_security_group_id] + subnet_id = data.terraform_remote_state.vpc.outputs.public-subnet-ids[0] + iam_instance_profile = aws_iam_instance_profile.eks-bast-iam-profile.name + root_block_device { + volume_size = 8 + volume_type = "gp3" + tags = local.default-tags + } + tags = merge(local.default-tags, { "Name" : "${local.resource-prefix}-eks-bast" }) + user_data = < +## Prepare lambda-layer1 with the following command. +The path is hard-required by AWS. See https://docs.aws.amazon.com/lambda/latest/dg/packaging-layers.html + +```bash +pip install requests -t python/lib/python3.12/site-packages/ +``` + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 4.40 | + +## Providers + +| Name | Version | +|------|---------| +| archive | 2.5.0 | +| aws | 5.64.0 | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_iam_role.lambda-role1](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_lambda_function.myFunction](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function) | resource | +| [aws_lambda_layer_version.libraries](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_layer_version) | resource | +| [archive_file.function1](https://registry.terraform.io/providers/hashicorp/archive/latest/docs/data-sources/file) | data source | +| [archive_file.layer1](https://registry.terraform.io/providers/hashicorp/archive/latest/docs/data-sources/file) | data source | + +## Inputs + +No inputs. + +## Outputs + +No outputs. + +--- +## Authorship +This module was developed by xpk. diff --git a/examples/lambda-layers/function.py b/examples/lambda-layers/function.py new file mode 100644 index 0000000..da29ca6 --- /dev/null +++ b/examples/lambda-layers/function.py @@ -0,0 +1,10 @@ +# reference: https://aws.amazon.com/premiumsupport/knowledge-center/start-stop-lambda-eventbridge/ +import requests + +def lambda_handler(event, context): + r = requests.get('https://ipinfo.io/') + return { + "HttpResponseCode": r.status_code + } + + diff --git a/examples/lambda-layers/function1.zip b/examples/lambda-layers/function1.zip new file mode 100644 index 0000000000000000000000000000000000000000..773597e172fdb17e62dbcdd5ded026c301bcb074 GIT binary patch literal 328 zcmWIWW@Zs#-~d7f2E{HQ0SDYbR$6IZa!F=>o?bzv&AEeKhaCitef({AG=M+%V9I+& z|2Ui9OsTW~PSQ(Dzc#Z|^l16?WiRfq{j>ie=V9o0P?>Gl4s+=wpYYegzVV0tYM7e2 z>Sk}&S8- cufxESMi2`rAOgHu*+4>!Kxhf1e}Xs+05b+~x&QzG literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1.zip b/examples/lambda-layers/lambda-layer1.zip new file mode 100644 index 0000000000000000000000000000000000000000..5edb7ee8b1d46327a13200638941c4e10709a742 GIT binary patch literal 1038174 zcmb@t1B@n7v@ZI$ZJX2f-?nYrwr$(CZBE zCzZ9o^{uSEP>M2O;OGG8e!c9u2r)chz(*g&850HN zsg+SHU6H&jI2*O>(_iS+%bdgRv?bfns^ZT`t)Fzk@Sa~J4B%d!7U+K`!I&(fEgN9i zHzGdYhd7Fyf<#1wI*9h4vIC9wX*K>yrvLx5>~=<0_Wx6M*?6VsFeZ4h@0Mtper-i8 zrrq&NLwDjb@d~E)WKr{XBpJV+2Em!%6Tio`Mv=_~N~qB6l#$3Wr*yPZ}x&@WoM`N!o z585k{M7_HE&mTDZpaJp|qaQ8zB*@>?0nO^4kPZJ<`yaX^zWuwF^Y7{Yzg@rLzuEs2 zI{%mM9KB48Of1a|4E{@xCjapTdLT2)Kb@M$&NN963*tlG-Y`_vA-JIpia}(+{|-|= zBjpc9N*okm^RPoo*8Q2AZo0tXc#q?YNr3+&CO9Q$t}X=}|BZg<)^GU6jTIMk;Qn=E zA98@hedycA-54sZ=i$q;-nS9R$g^w<*>rW;Ci33y>buNwW^3w{fS=u8& zlSmMlJCb6BK3nYRP4J{Gz}D@uL78oVqlAaNMXO__g4}DkNYW16`>UMVh2Pz&N5f%H zV}j>pBv$Sqrq!KBEm~c>2uC03T123vy0S57W`C$xUT+I16j7G|`16geQO@)Q4_7?C z-yRlyJ2`$}ulWH2K>ic=G4h6$w|}T&{d@Djx0(Mt-2WdA{x7)OCjGWS6T%)V$okZm zrG+H%g!L~(S>=n$P)Fv)N=Tk+HZMO5zl6GxPXtF2L#FTbToe$B`i>%muPcquh=#hO zcvwlXZN?<=L%N@S{~|O$HsWW)ip!NhXN=4Va-s>!n`vnCUiU;V5|=Dm3N6IW$0 zqAGp$Kwf3aQ$&NLhO}&hR3#v7R!*paxZvKj1lNSDqzk-aELStIc4^Xv_>uJ%crN4U zEudYknfay+k-}0D^;2Sx$qN_Lq%Fn5$j=K~%qrJZ$+ZK!pbO86L0sfDkbxc* z> zG0@p;Lx?w1^BXH?N7mtHy!^7nJc#6IYde`9}AO6ECJ$hF{3;!`g8T7wn zhwT4_Rhl?Bn=$+^%qUg=?SMCq5zs<(=q%+lilo$9mK|z5u0NiPI{wPEiPSA^&7p24 zq8yV=)wp&UUs^Vy=kBf>Rjquw8{*d-joyYRR3w6gnJW_iiU!LH#q3IAbN~v8OMDww z1rL5(m8r)dmtqUoN@nR^n)Q6#yL0oreQgjCZVCu|AMe+EBZjy|I>o(vy1%7_-sR6! z1Vzizg-A>MK9tVQ0)}k}M~zp~3GFbA=JbOSOURmv(-^ZUN2`{UQGuo`{zzFgp-4FT zF%!FuDSh{(-9?{@>UO>J665wUfziaRDy^QDyl}#}eZ+|Ja(_U;fbc%6N^M5!Qkh(D zE{y}u8KQEe^4Y=sP6klK9mJu_nRqhj#2y*IXT#t%Mm)&P8fwlOYYr%|HMfuXQRe5- zP8**@jL6m>Zw7{DO|PZW*7eanlXx_WF-5OVaIX%51ykM;d4+if%b?vZ^C&G=k#2%T z8;?SlTUJ~IR8V2lrROfSRO+zgWFKXBt2nHn3*ll!=*M!`(Y|z79%J5%;x#x-fbAGyZCR9|f zztuCWQBx8Xz*}{x=`L468+vqc$M8d6cCk^8d7hQASVcU75~ats6CJGpVaV}TiIUm; zM}56vFicGhiujURL8ZlT;;)-gxLIc=_PY}_B;(&vE$?VpxM*1X1$OcutzHiyJQ_p^ z1n-9(?_n-+L!IV(SI28S9_B=p3(xgiy-yQu5>Y?{S`(jz%z#B1_`f6}{m|H=d*WCc zA*!2u)pUq!M*nJNXEazCR87)-uW? zbgES_qBx-qyEz0x0=j>llyb}%bN&VzRI%T`UXk&%6!hOqX04}~gC-|Yer>kn`|w@= zR9SWFVzJp8(Qhrs<9IZiKA&~7M*%~_Ou!lpE9JFbq;w)599WP z<40u=6?#O@XaDK`?4U!e8K|*~;5bhcu?tE3?bkTA6R1||>~iQsN3@NWi`(uO&l{8$ zL4%rB}E~id!qb=LF6%ExZ%Da>ZBxu_DKH5C*dD-&{()I8by5qZw~s9 zs>_fUYF90A1CAzf;uw50P7~lF6xP}!D>a$D8tXE$i@ZT@HW*%(6J{D%KG8)(bIM>z zKa!src6u)_KBR$8`-pGaQd>H`-QErd*JDp*S8?Ue<_g^R-*5#zZw02`Htn1^_SN`C zV=gou4BN#rDL39I8K_f*=apE?tc%R7zYn&$@Kgn8eHriYWOb*S*rxQIdt%kCLa)3_3k~pYBw0I#>{#DZq9&tf4Dy^cqP)0dBlAx zULD@gL5jIKVl9x_LF!xdmt=T#1KAxz7L1XA_M3{5GS=HwV!DZRdVvZ_$`8sF|K2g^fRzM)?y&P4qDXseP2=pe|^S} z8nX|@f5|Q#Y5MQJ=LJ6Mj!jN)1mX|m6a$#y0IabBa-h!5jYR@S^SDQBZ|xt+{Oum! zLemb+cFJdQdG=J591U$NPG#O-1n=ya7;sQkzA*{WVU%Yj^vpDv+9D(WUaf?hUtRQXGYy&C?`96K`DSnO+DH$Oc(zP&dq>fI9N0`-4gEvw)8)?U%i1Tl zS3220%pg&O5~ECF@BGO6z`qW1HlJsImh?OQ5h$yM`8dz6cy zA&wj*hW!}lNE`2qdgY7jZlAgV`$UMcLN8&?3}?bEwS+IG&WtDFCbpz2MhPxQ?t6H84fNTb5SK;byHJ>oGx2;~M zTg(hbegvsC4XSJ-j4dDBA`sThgvjUWe>{`JR2C-|d{Bi7)6&MdxeB(1J(>-v%f=;( zKXOZn8ig5|;SH(kVXA=ug3!#q?SnH|---s$`4ec({`rfQW$LtNR=^L5O1MXGaElpd zoJ(SPa;NRD5hL%LiXGfr8fjTf(27#;j7{rIi0|f}_VvDh$5QM`0zDJsuG`@I94}ME z7vSr98<`xL&8K?L1>g$Vn6D%tQAUO)Frisq|AnF{VS z1PF|=;gs>XO`@->bhS$V%+@@I8vqaHJ5^bt(DX^3WHG;M%R5>3Lmd~3@<9nsSj;47 z#`T*n=Fvd$nboV=;F9rc`GDR{KtfcZ0qb;vhVM+p!$VrqC$JW!F6FJHi^oux$Xe0A zxn(K}XFj$+y{g6&ON6Wj;H%PFnYp7k^aPj2Oq)d>sCD=qg}%@6z3&k{d%lc~ZY5HBog#U;e2?)))Smq{dVMNjicJ1~y!uc%X?dKr%KkzL zaQNeraq->l_L;sjTyFDyN3YrE=JYqg;als-jsIb%dK2mE&fxtU{`&$?RB5S$=!C~k zZ~qia_2YZ*FTdjRcufXF{k_HK7278pVu4=I-VL@#e;{+%KC%2D)eFYU*j;$_FF1ab zOp1L3I+NUZDei&O(6wDoK`Zbwn8@-0#z8DFEAUbwUl9kYV(NW}LF}t>R$)7r&_T#> zbXm0dC!}#p&Oha%g*$f7v;K~qa;hMd^g+gEJ+jTIh?7I_x#H@ntWlA)q->JT0#QTDi=)lD?}RNJU+ zqV(9e(@pfqOMkGpvnuGQGkq0l7$p`~P4UI4#;2(gv%BOiqpD6v; z?*UT=Jym^)1foO-*ck28mUitF^Js@i2NvjC>q7`hHVlKbABt=bQj$9){!%Zp)EKMv=XdNZsvHy)`ivIVOlzs+l#SvvwR ze$AFptI|~T&DMrXNZFa`56qZnef`yu{@pQ{HV#)a3Fm+xowYpPK;X8fPg+&&Cox4@ zg&UGsIeKPeCarX;>Q2uo9 zIrCh%vd*TVYg#y33l^uoPS=XD^s!*jvQji>y}pZiC<}S~B{DT-=+D>3wyD?})%97t zLiI~e7?(|%RpWr*c^j&sPBriML>uuAh8{D0wY>IQ_g0DV2oP6(K`Va|DZV2YJThmd`lwy=f`5U6>A*?&l&qSCdB|er>F%B(+J!Csh3uo8Wv1F(i#j@UZC-UyR z$S*&Bnn6WS20H_95nC?#nEoi~!>J}Q_^ZpB#&lN=9GMiHsDF#oE9wqVL=qWJ#XV$&?zhJ-9)S`E z$r@(MA)i=BdA;a#t3mZ!;({W{qk!snDf~Tazp&Mc#-soKwrMfBY&0l#xucraF<3iB zFXp>sbvQtYW?7L^=zA`ko`^>pL){^=O#evAT$j)jEf?d28+ghyhrOa+O{R9eg?@p+ zxRxQQru8tElk?VQ-iE9g=Rv7vYY%XkoYN`ku{Q5ylb63M-xUD=SZ+2iGJHS+nbnfU z#E)fntc19g9aPoY1KW-l*vi9lPV@2MHCOK?B2vI)ovyorXxsrj$xYnjkLw;8bg(@6 z(RMR!xb^PoZ~Rfh$e(HgvnK4?%k5aoixb-9lQ`IvS6B!Yp1pUf@>AF_>%h+E+#=ll z;aC62>>+_a-F6(^AO`h|aOiY3zwKIqt9YrA*yQ8vII&>+W{-jG!Nj=MItNRml&0Lm z&T4#2c^Q%@Pu}T(OtHiM#nJeIrH;L=p?;|OgnTl82+kvGZ87PpfFE}&fo6epPV-?_ z)D~VS3F3T2HsJ#8=kkZW=g<8wQ*k;~=S0n}HrF8SljQVi*)345=<$|F0g0HwCeDK< zQ-K{w0nMhCGkQUEa2_`IvaU-tyhw13{8srj1n98J= zVe~0v-s=o(Dw^9QKGM3S@@~~sd>{<`flV<@<)Tmk$zqn7o)9ljl8JLJ2!^$Xm1)j% znWvv1fR=cX2P`g>gPy)7wp$2){PbLBZ3MvRa9e&aOCu>DE)4j3^znxaW8$X#OX@pD zK6wkFWy_k$l+ieu2^1ToaEl&-8Fka!jQhIN9&VBv1f->v%a(F;sN2`zXnBG{tXkE3 zrLXBmM3T)W&$XyxV5Pen?KDW(d8q4&Ha>yvmjV@2FWL%36Hl2=)5V)zE6P7F!?Grg zwGyM>H|$Svlm}DbIdq$A+S5S~GhA|y-oq~h1ubtR!MO3eW|)r#?~sq3hESYq3@zf> zrPb( zxb^h*x+`vqdSl1!6$s$%jU9xD5RT7au~TF7A^kJN7xyhVMbT?|1;#H2f8IwsdjGW9 z`m!7G#`3;tTHcAAQ+Ry+_D#9j6Ywt)=s)`GezWBch%E7d!S%S~i!~TRgB1GMP*Cx! zi~NStxQ_vREv9`yS0jg(a3Ut(X6$neaR?%yaL4}(tx6)rjd8)xkc*QdDGZV^q}keWjGrCG+KxWT|5?xMl2)a+Ny+GfIffT@R)RH5JWPwfrSvh~?_eyYi29NXz3ICuy+b z6HO1Zoa#M!(tDE7q8s5%le9whf@&@KK=xjjgfuZya$j!&nK`8hO_lWOM-^z9rG5K9 zX(snClMI0;o@$yK3RvyO!`+GN{(p?WqEYE+W(NeoVfX`plqqNW#SvzzDzDpnz?GXV z^f`~7l`ye6kID+VNJVlp6HN_6TYn4W0R!d86bGcTu`6!}&Xv?y!*K6*k)%^L*~Ssb zxqQif2fX$HhzCzC6rtO56__z)$`^AY?3Ddqz1}-D_WdkNXi`c3lvCoe;L$F;6jXuv zG!(38P9VcBZLPmY2<$kzAt2o%1noB~jw)R#P;&mLD2SQQb|M9FDWGWtUT4RmJJwno zjMZ*PIqrkS-Zg<$bCj*=B}7q$D0$))QL-Npt67kqzV(C%+Rag;jqknN=!7Il`B+J;roi~ag)9;m{W z-V?#4vO91yM~ji^;BXYt^@P#)aBE{%^g&YdnJinJ(iZ?ba2kjQ=Y3L2I2sH(+&n#E z(QAvfr^1GJtIEWiqW@^H$b(k_vMm({bGHdDXYGyeIlXlRIjea#OwoJ9Pj~E?XB6$? zp13EoDs{wg$1*AJ(ys*O7#@G&gng6ftG3naqlKA4Z`WQSx*)8Bkh|tm`?oG0Rh%2| zf;>ZmzIET`h zg{fhu%_d$T(!J9FFgY($FB*IIa(W|Eaf4!ww38%36q14}4XT@|0X5hL1Q) znalrpzsFty(PSDF#fsZ8mVaJ?r;sXy>aD!?T|tkW)d)b(rM*JI{4anEznir zP`ZyZ@kdMf#)|Nt3wyTNIGsh=V(h|ui^eHLms4bow2x*-WTycrB0g+3|aCa}*F?y+Xgp@#X8H_v$F@^#Z*EzBWm=~7?Q?0>jnJm~=2Vo7G zS0$S>h?0At@}p!|vn~Ki(#w_|!){_@c{pRU&>-OcI81e%Nvg3dwqUM7t zn$-DyF4EJj!zI^|3OEb3NNhDt=r^BY6~LMmw`Sv-4_ljO&u)$F+Y?ZVQY4~^Brr}1 zll5slu-CTFu7<9pI*>fF*8dYHqLYk!^}>G%bJQ+Yy(` z7q~SL1X}zf3=c`Zvw5g>)YB$uDsyXvH-{ze*OD$QkTkEd@roCO5wxd51*5@2gqw=& zONOsOfJh&XLSs8PzIu4Nb()9=hj!K=jMObVw&KZR#<|LY5bU-zPM1iuGJewQ33x1ybjRuas zZg5{y7kgA4;tie?J}%yH8c8|q#L6hq(Xo7;A+jrJb*?7k-L~Y_2e{(0x*o}lCsF4xw}&x@MhjzQakJ5kXt*EH*gFaVvTO1jaeEzFRQnIRbG*{3NJN7SMO(DXi5M8KbKm4e=8W^bOA({elYMh<%cYK5#TS2!(xiSz>LC7!+8Y%zK4%y zHD&|vZ7If3E#{l=vDx9)Yg_fP#YS~~b_4861uo=voxvZ*6-F{=s&Thic3sV7k3x5q zkABV`eZRnG`2zMvxx0$051t6D=i}St1X(hd*qPVB()NmIkgODizY-leo)5$xM~7yR zR6BQlY=;}(!ev6g9k)*1#nQXKj7Hp{*hd{Eb3ykPc9UxB&p{?_pBza)m`B4+@?+hx zrn!d7J{uFJ2$5`M|3HD)emJPSTgLuM5<62oMoi5w`ulv8`nY z!%Ie7!7<9vaB@oEhs=tvJhUC457}Z910lK?4nM?4h|-5k&g%UCfau)a9eE?ey>e~w z^0nVP%fc?)cUAz4kTKp{mhLjNM}%4+++&-PXWy^O4{6+Z68McSSAIcf`6|vfwW{W` zoys|f1h>?qDKTCmF(-o$$um6fUO|GG1+Wu8lZ3$TkfEZU6e)-02kbw>xd|u*y=d0o z)^ChenFxpG3E=T?Sw&H?z%gWSp#F;4|yw+YEC@8`Zs@rlGaBE0X=K zi%l}&{f<1z;Hc+)3tZ`3j(i~)LY6KQu)dLR#RHbR!!ya^e zo^?wWB8tlIn88Ax{D*77=IDxqOzR2JT0H49!j|I+gtn;kd2{Kjl9o%^cU?O@_eT^i z4#@A9S{#MXdBM9!{3i#D(MD(phJ2Tik(aRK8l2UW2!y6gAY>!&ovGYU_?^q2W!Y)u zs_77jN&zp15JaVcK4cIX3QxBwZt~B-GfDk0D>c_eQb%yM-}&J=K-!xQx3H z?*R*0x^HDlO4aRKqvkujc|{}}lg8E+r@R$g_s_yt5OZ2$lxL5!Zer`H&h&D!BEOI+ zT~X@kF?SPgDmm2+h?rKf(CWlm9tqc*u91C@2qkVqi2)~u@gWWTUr6Iht|@N4EvIWl zM77J5n4#UJs~Uy!!H@a<=6g;Rw;FgEd{Z6au)Hq-xNB`0pVKf4$x12NWr!u5zQCF8 zSRt?jD+{?U=~SJO-9^V|#Oo@bSY&V0EBsC^5n`T4FTp#i@-FOpgQFPlF{fW+U>WzR zF?dAwwmS0Vu#wQlixrbysY2q%L$lox* zyAyR=q>n9DVs~&a;LPr`#zP0lUfnsDw}J#rRO2@r8=AtGGpd`o-9J1_HKbx0CpEE< zvhv6p2$N{YR;fipvb&=kxv#FTAHlr^Q()2$cV*HMewWFjR81u1oQ!&~;b3T{&#T|s z|FKFZ!^RpU(;z{$sZ;jZ@k!lKf(v}JxJPD?D6>v&87nA)F&~)`)VX(JGJ9DQZ&$rK z(&t<*{hfzBX0Ag(Ht;2d(0zXnX6l;{V{L(+__dpkS7YiiIEg(UgD=nNk&7EV8&Hr= z@(oG<{yTGLf#r}=I~?^equwu)f*IF~nF+RxI(Q6)yU=o{A|-QCxHZTv`Pip%<0eU-n)=swdpo zUu?Fpb;zmi-nZC1_gPSAcEQ+sDK^?#V3jp7fa~zlvB>ghP-xZzyHQa#&xp6vtxwqMiL$YZ%mW1=So=%<^84LG!HP zE|E{N%({hu1(`|tQiCRSLWOLUXH269gKOzSdC*7L)p+VW5G;J}iHkA5e5*CqbI<9s z>gt!_W**}Zvksx6`*2}RYvuEDQ8r=yu8ShwsM%@cgI5foSsQa@X{-l&hPWp08QksA zOT^BH4bM)z@!;fR1bK+5Q8|_=$BB~R+`eM0lv5y6+|ZRpzt;CiQ&cN!z)b^nngvg7 zRHA|fL0tXds9P5t|F0>JaAAC}Qr-=hEIizz1SMK!FAU}R;B!<9yJE+^9^bWg4biB4 zv|nEaD1OQHJ1NCdm0eShBApxglW{Tck9FB*Z0PV2v>!_4C6|%)2HPsnu<}>zxK)FCaR%mwEtwqZ<>^L!$S*lGI;4Z@NbVN!sNP)x99BQ4d%D{3G-@A_|OFer0%i0J|qGjD) z*?+ARUXkxCjM`Zx+s!UA{E3ZIlfWAg68?v?Dof56Yxc=v=?Qy?#Wu!d z%JLd@DC=6!2ga1%*;N&KL6?pODoDZm6yDs}g;HPMriCpL8nsAIX(P=#g?#dBjd$<_ z^pJoBmaMveWnSLBG#!wyOx-=rhu^bF&3^|~jzUT%p;F|g;^iQMV3;zDmZ%Zxs2^2f zc7N&{yULhSW~rD-CF4e|62PY*J)P^V&rfO11zaKRgyc40SCqyL>VbiLn+qnHHZ+rC zGT164k@M@VNrSD)kx|!}-f`60c*QV*3WQ=m0`hgRs23Oiis34nVy(^#?#$C@Ee+UV z1epi~MT%6UTu+Wqm}zZsGga;Wnz7(KOWT5Xc*0&bKHF)1-#E+bKwgAdp&-`HTJ(83 z2f93_P#-%RhZ2mR(F!4RxoPNNby+F6X32Na6fxpCkSmPorQsjX{>!E5;nLE6p>`hw z7SVar5Cme4yWCnN-rIB^$LCybQFhGDAKy%fcJFhS(zF&;F;4_MgLjZBOF>Qc9lcT2 zeY>d0Abg%ol!O93!|69|2Iri3@$a~^iJ(!BuPvaZ>we5!^wLgwc@R0d5B5|&z*#XM z{U#81BkLbyLl#1SMd{|pTRr*BmtsqVjk0MFT*I%Q)b3ERrj>887eDOGKb*HF7?klN zpHp9<$~`)8ODd@1GZfadgtTmd(8#zqw;)zHPEqIl4}rCv1d-jg`r-OG8p{r|%O)MB zgI-OTAqeaGEK4?y#lNyh8k7l|nd(o!BM8YRUbsH+?hkIcx4}og`?WeFimbKH5S#P) z%@0X1Ncf|!?nydr6{c>`;TBj|l^JbJE`p7VEg1Zn8%M@IKJ8{(X`9#qzq$M-30!72 zez2Y?*c64#zqmgXmM9W3KSq!|(^MKGAP@O83s0Q_2%oI5^q!}(x**LQEjkN-K2%4b z2ucx7j#7Wh{Bk$1haWL<{LM7?sCast++&VBkE67rqCXkLdGp7fY*{>yBVt4mqX%kb z_$uoMyX_gW7DE=jGgAmUPp{vhLz(hK67a%98_`q?q#jnT+$zm%UZ%Guo^OXWSUvo=o^JTQP}m0bJu<%u?5Pr8``m>z|RL4wF3lF1`?u|tE<>)cSuvA z3Eo)2?a^_-t$53;A|X>&J7DAnSx*;H9@@B~N`)dRoZjfMq{22<`Nd0+5sFxdsNDhWqm69~G3FA}%Oh4$pV z2mMQxP9)0f^OHkwa{49PCSX#qV$VbO)KSA&{i^VLX@G7o{EI(6{R%a>LO*&6)9xv_ zT`Q!|B7V(q)h8?COqckzU*Bfu#*Z%hVwKR@J1uFc86)C3M}yU5P+y=@7Z*gG8aU~f ze-DGNG!cxKqTQ$`+R@QMglWsDq=&IB=l2@7M9WD~;St}1&0uH;bh&(|UOsC;Op%SC zTT<08P)o^D1LlInSqNI#=+>Pr|I(>xhs{)Ryxj5P-JQ+9x#1*ylT2ogap9>26vjUm$t$YmrG%eBdYHNPaWn@Bu*Jc3ODw9J znFSIEL%nEWs?tfzYCcS~M5TRs3S=svYCISA2O2u7o33ikkki4|w8}Ij{5gjh8NWr1 zy6OR?CwWiBI#2(Ese$|5KrBniO{r@*p_-oNs6%JRAN_){hWgWA5`Vs zmeHhhOly2iR`SM~n&W+#>b*!VTmRSCHg?3SWu_?>uLXVz7<`MP3%*?(vq0pWLZtMo zKr{PXFB>#fS5@PhCf#JZ4GPvL=ym`>b=yzQG4ny`Xy7aoXg55Xy#JBw9*eYrH&LHo zB4nf&B>0g(?HU@n+Tg$?6ZGnIhWS2*6UGP@IY0|j5B;R2p#>u!Y13}3`x{bj$r{6V z2wkaHq*6JX{yukrh0|E?r+|57$M&(v5cUAJC=2&J6H$^+W5b@rQR=G7@F4ne9t#hr zNnwiSgxp43l$T3`_9`VZLsRW;`EM4afnkyLQsND^BU#e~s-w@^!x^@*^d?>^VI=ow z7gXbt^DVhrvigYh0?y$9`^`>ZNea?0$g<@QZefwX{so=8#1-0%9cA{?R0fP)&OMMF zA+BET!`B1xK|4%XT$(!A&nTbHdV%;27MDHuWkE&0H($PvUP0MY()p$b^~$CGh@|jK zmFALngAHuWKfPPZFDeNYb89XJydMvf@Ww3A2_@QUkl7J15&ab zdWgiPII3*&uRPH1EO<0t{k{>t2r|DTzrR<_Kj=K}B1i-Xnm!lwWQG1!Fp1@dv9F-; zBqC3NF9Zm_e&Z3JuryBphZHnq!g|8Ki}gvfV)? zMi^p!h4mS|tI&B(0L1s$W6i;QaJ!)`F2xw^QX!z>AplIcN32Loi!u>KaD5>5=S)K^ z1vYp2ym9hKqQx8QfUmI0MyD5ZGX_49`jDv>Ut1y%Wi6TX{_{rdZLm1EMmKvb%WWJW zw4x<+*jbb~nRKEufoqE%lyyvb{IRVv?$DU(0Nrt_1KKI5AN`TvkBG+d!rN{>FLkcJ!&95sOj)?e zn%)sC%X?gKC~Oc*A2(}`-;NY_!=Rdb zIc+Nefk{Du)NZeJY$w_sBbpXY`*B4EmC?15+9hF*cWV={Ya)0sQfA@*8T8sR3wP_m z&lK?F1=9C6P+B!mIsGsL-PaPdbHLb;E4lC5(+Z`0`WY*h;Svg@&A~C6C}vsIIj`l{y?Q!SNJYASa^79k6ppX?aC?1 zbMVL|gv6@ap&T~ipkfWE=BRC#8TtE)a#8V*_Q^7L#A~=b49m3EG}zNbdp`y?vBi7} zJ`I=yG?L~y05|F>syAli{D%{a=G9Dyh`?{nO?l3}~Lal|d1^-EYah!$Boqn_tf#woo(rs5# zXF2n`yw-RV2ok%td@V!xB=qW7?KxMz<@xg}WS;Ds{YxLJU*_-6=)Nqc%&nYisr#Sb z@tHdf-)yE|fT3@Wici6P#<34JbTX#6H@r;<#uM839^M8Jf{}*Oly7b$w0T9*5>A8w zzq#=M9Q&fga4Bv8M^9`Df`d~cWD)|3QDV3vx9I7q8$2`#yDNO-Y_eK_ta=e^{Cw2+ zq$&xk*c^xy+RMuRfh*_&znBWP+!$-Poi~p-#~@K(vQA&Wk+a|&$%i*-Fa;BCxcZG18)z~hX_Brw43 z%!;NofYbAp+T$@}Gi~RHq4;SOv0sXfmIrJ$`iHPFu26XodBpn|QPkAD0zjG1;?}TB zh(GhFj8TUWOES#TzPn9X5RIE~%TE^N%<1q5QF+{FCo;BT4B|4}LSP|K?=f&#s-fp3 zki7d>&QwGNc6b=$V34RJ63cqkfJaJ_$2-Hd4rz3Xgf|~+YSd951Sp5~u8c;w(fE&d z;_(F(#94@H#t+WsHobAX8!6sqB)cG0E;<}IXc(9u#usTBBs);?m1-I5&K6xVURk?I zJWHD?9@IU0a`c=j{%b-t!K^+f)lpO}kQnYgULHqtBfDFt*Z^lmm2PY1V1$Vu+dSx~ zj-Eki%wXZ(1a7tJg>!T9ulgvs;^&#FyLb=8)qjIjv~KCeZja+SuN_2hbhDxt$QSG7@U(h-W?lyHg-P*E*DeuOCEGd(T7kabC!5$c_%uS3K@F zPPIo|+GtCvL<33}TT8PoTGoTIL`k_NbwL8LdqMqE76DMR0}iyBO!BTm_t5Y%J5OcX z3Jf)9e4t|perVAf$LciWMxudeB;z%>qhE>lI1F3RjiC(BiVIi&0@i6imaETZ9rZ(+ z6{zNB_vaMvCUeO2GUg#i!pLq5{u_ElQ5c0rPsdp~q{YT(`dZP74|5jT0%@G3%UJ9( z`P-sUcW(5VD2; z)%jw`V2C}kHVA8+u?J& zT51drPEZOLsiO^ogy5YOqxW2Qq(P-?F8nm8|IBQsPTb7RT<%h~y|`-8qhS zex%^3Pc#DJ_p*98msIA|0TVbcN`KO-Ofyn|L`N6QMCqY2So)%b8GnD`GncYB^pN9A zJcBOvz)O7Mk{vIwDx5dzAjYT>CBF~tAa)z0B-`@K*Z1ZYa0(z3Tm{MI@+yms8KYc*&F-$65W`-D)4;(AG^~PrAg${zG7nZ$Pt8 z^a!Ut7m=SLyyG=6+;=?aXxPOYRKJ?w!}1xQ<^8OW1=KG=29e(^$~977jT|IA3D(1` zrD0OiygxPRqdJ;=pgBD9U_41#zM>Twa>{ReLo8YnJL&ZiDMIUe4(p}peig@0&oCRE zGHJ_-c=it}shw8dlcXk8{TnMMv2*;aEeC_5Yr@raZY_;9fkK)3pe|G*h=Hr5^&{V}>W)35SbcGpp^P_!Wx!F2(KgE3ChN^t_|;e&^zb^kiYLDcX;7&?b@vD^9S#h?(+I^WnK%tA zZKxT%Ag9Z=ofG|r!|x(*C7Hg^K;t)Q{EWAlTZzZ@Pk>N zGPdsOvkf#QNp22Gh&MqSoI)~Y#hv~Q6?3x28CNKHaMT^37`h<=?AQT9amKXkMY}Ca zKuG=hZOMHZcsw7Xob5)L+Dx0U5;u2u**ZmNRzpGI1R@)GUIMGoU}L)(K|OALNY|Xu zvXjuwrbwS4hd84=Zrx!J*#zXeHRX$pRErP~oAE)HB#WTBbQQohap^tws$>J!kVqCl z#7wkWU^0f=fQ$~?X{4Tesq#-pHF9@SxIlg>!VG=h|BWD$P{)B?WaD81+_Nqn-X+W2 z|I!GR4Qgj2DEBa$E>BrwD#+_UfA=Y?;uk@1Ff&R|=mtT(26ek)G+!vAK;Mz>)N=J; zd>}}yn!b&-kNC7~hN|S``@tD|bKLts06aj$zvk*r2yR7q1w~yN_Dd?%0*EMUuG11jy-G z2sT*tfO{2ONWTs-KlSH^?b_XQ6b-Y5S-Itj8e>mqK;Pbch{Zv;G!w?h%K>|l15JL$Hq6ioz5RgDngdiah1j#QASP}Xv z?hw-$L1Q6}yo6zdyj)ZmO(JxNZHS6vn=1Xy-zC6aG1~Z*21bw#dNFE4GC!iha6`ej zYReI_X-LSYacG0ID5T-vop2yf8i6)APF}I*5ZWX%if@vXAU4bdgKd`hW$Z#<$6AqK zqXYh{C~^dD9en(iktS&JA2Lu;9LwF>%d=9m8AqHBz9 z-j3o7LM>@WL+qUe1jts_Vb7K^a5W>0B6fE3oXJE|fqf)DMJU-f#|NKxTy1hA>_wGp zvdz_sGYIr8rcVK(pV=pjo-8v*ujEI~C9O~;;foRuf3!&fU;3m@!ft{~es`h{OmuaX ztdW@~Re0RUzvprzdD2~#^%>w#JAY9L>8%hF6H2LnL$o*q?&~6ZsVm#d;r}D5 z-)v!c&a0^5IpB9%%n9fLa}a}=C88(H6tfc3)qfDZ?Xq3l<*I)VUc&~osUOp}#PzHv ztd*#KfgQX2HZA3vHLM*_@{vOCkr;-SS={o27{dLtH4OiSHF+iIDzO2%K_(b%;%Sz& zYGiXr8!Fw^Y3O0>Hj_wA3K>jY8oTwR_I-IhqMU%ifntPWM8dTMR4#29r?@nnOTAjf zHF7T7N>Z^*urz3l`E`@^3wzacdzR1A5nWEru`|Wsj8pE^&j@hYuC#M>4mf|g^AGnN z+vr$ZIx9*!wkj953C^o4_m_zu_;990m}eK{;1VexWsS_|z$8A-ybD6>f(xo`> z=TmW0lXeitnd)^gKd4;VAt#d*^PA>o{U8(@t7>#$<|6=F%}XRql;G&&KSo)1zCIqi zd5%1^*&6`=-ybsahxOeXto##-{?mQF6-qx{{{zQFF&d#@94BB3B4`>$s86e>2=<1S zjNa3uFq6S=L@DB3FgV*)j0&cpm^6Ds9F2Yogc-(efV-&YIgOd9Vq ze=&pOd&QL6i?6;YqED#%FW$k+uhtE2kvLUVh|M9x9zp{WGH~sIVcF zn;{tRmyGI9+iFhw8Hxp0_z{YIG#gXY{NlkQN{ZopJgRoO8hOC?m+Bz&UWc+>_Nj{L zYN#szOX>S^=YBk}lfP1A@1XZ8hDRe*+UpjuPpPrVX4KO4US*Z0@#1=;q9EsO0Y7U7 zY+qOZ_CyX8KoYt=a}=+MgVzpJErORJWck{mQhCJe`bfU$_WC>o>8j5`S_qxi3N%Cq z!?+bgPO5Eo1gb-5vR1j7W%UU@v20_>$rm1cx|*} zuvTCS5Q#w@scB;!>kvK;+|wS*DMR2cbiCJ*4)#z zNc7!&Qh3*A9(|rby4|ob%QJ99w99?$)u_lT#I8^k0N_e@w9vr>R_C%KrG{Qol_JV zo}qKRIOOWG_uCk@$N|5f(fHzlmuy?xCb^_FpTtqDYDubG1IxnKW-)+LrO_PWW911V zR8!`{eY64@xnP!jm2VpA8wc@%>knt?G6Ib5+e7@O?{pV<4!He0jm00Bb+`s3(B7QZ zKNFZ$oY-8BazeQGl!g6;S-%&5wib9VcFK?8LV=o39!qj%TUKYA3vF@lf!1sG!IkBm zE8na;yQU84V9y0N z4*m04Xx-CAT;fPMp6sYla7*&Tlo6f$B3^p&RI{Z3U*I|c^2xvX1&dc&9waiB%plbLV-W%C5q?YR$wWn3e_pa4%)zhPWf| zmh&Zs-O9W<6!qfaI0%f%>YmTr^BAuPB&yXlLjfAOm3BAlmO-AgfL)u1UK}^}>Y74e zdu4l$z406!c)PFnCT?Y zD&r>_lR`qj)zj6Q?h`z*Aj?}Dhk(`d3D_ycJ@O7)!vsRsWV3D#L^VwlQr!$m1qaqR zfklP(AB1b}wf$nS^sfT8-|h9+knP7kz7N`P5`s_)g>V#xNt~u}0{zt2X*XnwVJ4*+ zGGo%>{h~-2C}UEH!3l=M_o4vB5C{W*9<$L26UR)Bzk@NHVDg+nU?xo%4BZRp`8!&p zQ6?*xm}H9GDKUc?IAhY}7cpCsGsG^m5F<>Iyu-F6W^kHG2&Q<4j=PM+?$(4M3`Xn; z4(J`i(KLe=dr_lcAmn`)aK_}>`yw*z9aB;;ll?wso8EMp_$JSwdduYNuuJOD<8zsY z?>f4HU8eyme`Ng9pD|f-H)~A-n5=)0&Bp_|gaQXQN{cNTQmL z9yDb%YX1s36yaTS3Fs3xXazmK*s$V-9Dg4*g;34dm+J94yzq0Zq-fM0l`ZODP~DW| z1tp-8xX*N7FR20$tal`lVX0`3eNLU9o}YcBUy;Ti`5f_IhCCQ_B)r-@S+|S+Kw{}g zp5oO71F6cRCy;A~sE;e3c=5OhQlnt8z^`}6v`1_W&L=zJ6vE?+F2SoC8;dWuBFd4x-31^|=UczG|z)=fE*1Kt}Qi@30L!HyzgC0+=*aep& zxe@tU1B`(yANYwq-Y*v(hr!zKS5X`fU>3;w(zyfP_1bMEYhmkz`=W64viXHHM?9s1 ziK76D$2}Zt7)>m6V>zbEtp@Y0c|ou+D~D%((c^KPhTbmZL{{{bzBrKkX!}KSU#{#G zKy6B|2ZvT1Mybl!rD@(8$nlIii&|u+svsna3&!iA=#G=k&T(;}f~-XavsJ<5*~I)&m1P2*P8C-eqa)Suee@4)SU6Sn~p zA((USaL;;7Eb1xs36#!bO;m09m$>b-wZPZKe-pO}e;2m_yTa%HB5ng%4dst^Jxj45UnwAVT72PXu${xhk~fVXkUs1` zJu++Ru)YXUeBxLF=8Tgm%UEdNkr0LxrIFevmO027$U8W?xwlhJlR||xcIUTSZj|&C zh;YW=1L};A@_HjJ5^7)C7@y8s)yT0zmRsm$wgY7B^L8j7!r^EJ0oH@=M09eL&7FmQg_=7U$5jU8(7kA0y;pnu9 zIBSC15iiriXU#eqr<;jK<6W{PDuyM2q?e%R%w?njy?NeriG7{L*e zBq<6d5E3UL7()nxA`l2gKCM6Pj+`m_j;@I89c`j`D56<{c4P5|7orI9&v4RN`kIrQaqr7ybnw-F?9=KH@M}}AS5xL;uoY)SQc2#U?mpIE zgHT&I%tj)cx6f82Zb0~1}213b~B1TuPae9_&te zbX$;7k!yeyVn0?!bkvnzxPn~%I>PCYOhfn5DfW;+aC3O|N6O*d6hp0zCg`&csa+qp z(5vKJfNCbwM;C?PVoB)Yk=N4DlnO4Iaux&OIWTe$sI^}i$(~+b1c&@8i5BMhf zbWu@>RYk7CL{>Cd+xtoH=okGNz|Y}`T^|u?8pK0^XD)gd4n=0z930yOHJj{*N;nVA z$8DdkF9Gdxseh6Q{}`D1 zeea0^M1~*+fi3h2- z2LL^f(>XIz`UI+6*zz|!SXMoMXs`11RF~TURnnKP6kW1VYGB`S>3V&^>3AQBaafuT z5b);3>%w#h`%~u(TAf>czfPK2JEW$Yn5X&Yk-c=vJ!NzM zA>lvV@kcEDbEhA?s7V~APy!}M5``fg#&HZm5g4X13dV4PCMlf$v>78Um|~w$f1?fd zrv6#V5I6%93`W1<@eMWcZV;U_+2>u2X#9paa?f7mI77h<4KZ-BV-@j6BkW5r{w|c0 zVhmm|#a@qsf0fU`5C($w(i8Sxmr`$hgK{QG7<_lTMj(dX6(qlSWFz!0LY};D0Zy6t z3y=~_p1yCbfZtb^?N}VA3_<@E45u9o-EUyX!I$f3)&6y8O`1EY)TzFWpN|3@|My_{ zXV0MFiP8sFx!$;(|{g4m80+%X4DH&2K$SI(hcF2YpLqnwv4qr9uxC2jY zQU$Ng<{6|?umf6@AYqJkr9}BuQ$@OZ*N~zgF>sKSXKW;Pa&sunlwbDa8v3&F!cI7R z7_a>qYF=$_;0EGa%FQVnQ|nK<9vvDP58_k<>Ry$UVagmeSh(akKFlL5G_81iPDAT>y$UGZ8E+2ZjSBR%i%NRDTw+1+H?VoN9D4~A zL1sx}xWtr3!t~t&J)?w+kdABPS=t^6JfzL~e&vtd|goOVZ1NbeaHZ7+gw?v0c-D? z+w89!Ft}PSE4GN8+@E0-QEo3~hIGJpE&{n!)M{B%++ICN=AFmjrB{&vt;;}AV9Z|w zh%-s+t{v?_7*#lIM)BO>XRtq8fCAN4G})BR$8IOj33+v7fy+1lc234fcDAkX5-{y~ zVYFn2B1X7MC5pyR*wl=)(E%zBbpl+C2QdR5Pu{%Z*5T;WLVR|R2%1hDwsq{3!&u@7 zPyg|hv;&Uv7jq&aC1aBda5Y8Z=<(wARPj<)lbey9-DJ51fz(U>4K(edfzRQ^M4MSM zA7dYGQk*VI5UVpyEh$h?y3ldU-K%1jKu0X{!z;_(CV_>6NO07bcEqW~v5$pzQkO%V z9OuHZluSh{C#2Hw9|Iz98J1xEjV#>P1;6s6`i~Cq&6VnJcm8n-07G#IhfxBf5R67p zgvMZ+rf`U&DV#zvjKFa6(*gjVG8pv+$zo5YlgJxn@ZCh3$llpL2 z5(I<7Z%n0kJ1J~`kq~c|m*GrI>^e3vL+r(X41TXkGA1t=@>hTfr3{iX8S#ee;!FEs z!Ne#-({D)6cV-L243X?yF<}adA?e*AV{f#CDW;&`dr`ZR9fZGWCrmO_vTIHM);2>_ z-i&DeRsgWQL3~~Zt;N^}Pu3XBHc5N>rF`5^qRl^9KzYBjfCBa%7vpmasLF6`h&DaQ zIsI$_rEP4>eYIs&8uR4&wCH`N!}@~`%(sz&b$7TD*ctek8CWe(T#fDh&&N%#jSW@i zK6CB*X4=IWyJ;8jJJ&98{?WDTt7(_GNP-8!C%_T^;@Z_4y#KXEk$?9)_;ivP_$JNs z(}2O>%@;r-uU}EUZk!1P{8UT=*1bSPcbN0|c=lcjNWRpqL~DJc~Wd1TW1%zd_lf^hbffEN7vK@f0M_wX2f~s@eB>^VJb!sjH zQc$9+wkUc(j{t~dPdo1@D}h!dRCy|qhf|25y`@gr)4FQIB)_CUxLRU;x}9B3Xm1Yj zVBw>@-P|(>2p-rg$=&l)Q6J6Q!?NhW=WQwSW6u<+XC0$5%!?5;kVh_*77jHP{4zx1 z9TL41w}Ac_sCWI*(SMp!ScWR=KY2~)p%v;&GY2N&us4q%)dW|}b`0PA^VOY)oEKXr~s|K+;^d_NceE0?OT zQ+%iKns&vlLvkcw#$fw<#Q+IUN+d0V}uStfOhX~^A-^Z+-11B&SXf5Cv-bh(2Mi86?Gk$6G)ZeiYoI7{uB1 zj-T$hv-uI8WdO$#Adgv{gju-39m~Zt0xoGxkV>WOb-K6%N|{_x-v@GvJpV7D_Y>^?_Xqh2zyIa{-(xri<0OSpC`FJEMG!PXpcH}= zGy>xkO+qA%QV{)V-zB-5D-^}9QIox)7)KdAX9$YH;x_`56cfk0{dB<~zo_Bwdt*66 z7YvdxSoUF{1r_h(A?cf#Cd4~1Kof?_86?~F;Lu+ufMIek)FTWTzo{#XG5Bu(K+#N` zF=@^qyDSd6yE+v6(TQEJ7L9kug?$(w%NPWHUk8jcS@OOntk`!ae+S|G^$p?WpX2We zlux%#WmAdsJyy;;#EOnJd*sUURyDPCdPn3N&s9Gg)%;ud{?Y{SAHerEBD+X4TTXvaBsQ=wr&#j+ZWHGRs{Dke=@SGWPJPRdw!xbF2cM zF?(oE9K>-JMneOnwewbHxkrF#emqXTa1kHKb-C2i4bp(LaE>%z+0PT9Dl&FRcxvK< zHW`D5Zs7fO-VhB8hX+aO9{1|%9d&-19f#96ja;sy`Ut(*eo?fBqh@&T<^Q0n418Bs z{_&$an*%FwEnAB$Ih#p-ThW{y*C$pN2QrW)wmE_~p#uuLmgOO*d@7aUcvch4q37IM}~?BhSI{}!riw+_$iizsIGN$<4kS2i{BxhihAy5Xx zcd=~j%~0T&Nf3sBKAMy8FOBaQ6Q}Qk?e;gncv|M@`vDju`}lIc4`JtTVn$)_=Oh{L zUGWHm?Q>tr7t3Dk{ZPdcrbzZ7YnXwHUHo(JcE=E=z?nQ}Vwgd)-#smbo51tz$p6`; zej-zB7Eh~RA3p6;7wn(A)Fan$)LH!MzRR{^EVs`*q@nn1ETZ>CX@O%6gZ~<{BY0(S z*clK!7X47kgbmM_&0sHu{k&~9f2xEzt-6RcYXcvpFoXAg4Tgi5=-k$|aYt1s7p}%`44C!{b#x zRf{f%%|u<2u&FWkd8KLeYFoG z?yXRO<;s|trMy|zCVS86SVG4x5PPKU9?N}Io$y*)BfhGEza%rTam6Em593hYE__DT zXMCAZv92ro5rnsx=!r$e=5D1A_KLO`G*t_B_O)ayv1<(>HUOj0D(i->%eO;aQ@(g< zN}*5vr-%5wTA-Rk29J(qNtwDG`QUY|vCCyi+tY@NDwiOD_9)wX862NhR_iCrkXjQw zpB|1})|}HF3-w+v^8kC+|d4sjU7pkmz>6 zQBItJi2dlNk)S!m*uPmUSJu%+zW*4%KgGa*`Y|rchCMvD8er{%=ANj}?Rhy-=0jd~ zSy=|f_lIj&Az``gFZ1tzQi{qp@}^f1`*x@XM9zuBi4_jV7B+7I{*1v`xX?w16`p#Z zAe*XyBp_P9J6YmXPsist5nBO@v#zY$15~>yzPR`SR#Y1Ggi2`^R=&(97~h<7$%9q2U{v%P2@Ffak;qtIGtpOafy+j1kyAUn#0)$k zyPNrhy~F<8*Hd6#hlo2lsWKf-x?UWh6QbCh5{Rxvx&~X_VtddFC;)ZNIv(s92v>y? zBN3V!Wy*2noE6}?P5Ch754RVToL`_9>Hk<5#QJZ(di7;B$A5Tvo2Ntf2S5DR|L+g| zneFP9xy%3k!M@_)Z`XbgkO)QN1Vm8;g^(x?Q#66&5DMW44dEn;BP0P~ z#)vAQ=K@po}SChRoj-g3R9# zOzk$iF~$_wn_Xag+eyB+gb*~75=;U80y0x*m%qgJ3LpB$&NmkBJp7YK-WY&q8K z@a19jFw`)xU8wms@%y`!AF${A1aUQLcHRqYb+*fd{JhPOu%Bc?oU`E?GoacZk4SD5 zVkLM*NQGWp&X2;Sy&&{c70pS%&ZVa~jb4j4ga6N#kGIYZ47)r zCib=47<2s-IiSf^FyV+oo(c*PUWa7RO8FFGLhCG6ab4UhiB$l1jS}8BA8Lf(R?`>g zkQ-}io7I^rJ&Yc^f<*D{;1zc-oZBbX_9ko+5@`yOc zYwK+>5#|T}$Tb)p@lWVHwFeKOvmACSpAQw}5{l1qGSD+1M1yC*C+AYM1e|5q10Obe z=H;z|%~rThH*3NCGk-jDyx_YEDtZu9wPfoW$ho|zFyL|hBPyc%Vuuykq#k@XDh;=7 z{@FAZc>^8JlnntqpUnCUBlnlJ)%B5f&%(V)@Hx|fVoPt}Im0&CdxlV)4H#=R{)vOz zXCdjgVjQ5xfw*WwRqRnm5Ay&eY?j+!2*xck@D7N?|0mz@8=#XN@~~?_f}w) z-+9v56?0~%a?80~kY0M6l}{2S-O?-v-NVZVLInmz&syv$yCz&6ZgV@Fdip_E#OZQF z+6(>A#)Z1tjhH8RcRW1{`~-1Cp71Rj=`PTFkSfK#&AP~D^zqQz$d-?Hl3O@T3=dUJ z<%F>MamL?UMXR_jqpAwL23$8BAIPWxS$9UP2Y9+vX_U{yusL_PT(D|c*TXc?Rjg;d zOg=I1f?5%HZsrStsz`F}BMvsT>j;?F*RdO2yw5k|dRH**(x&14GSwXY%w4zlyIQD( z^EDdaTDS%#>~t&MH|V$?vp^7e;A1TOX2|7_)kzLBXfo=lm+Wd~E6tLR>wS8#o7?q! zfzEHGP0PNB(K;wBYcB>*&APn{_G)jgER+T>mp*H-smz7xjh$JR;~eQ>=nBBM5kipz z*H#>PxGlHP$~k>-==LHn#_im9Nk0#_h`6-CX^zIAKMB_^Qo*(30@Rk*al0L@5{uT$ zoytP^goGX_L|Hu`rp@z;oZlynV(F*QoB-|o9DKzIdUlD5V4&^DZvC<@oplZjrw^t% z3zqxCeMSXz#w_X8D;yH8oOr$*`8$6A%CSI+8YRHj{JgnW--442YQ@+6!P7h!8X2rY z?K4j9rjga1crwqgRFK+8X@%*7tjM~3X+<2x zFClToYUebL$R;=-vH|i4U+)9L6Qi4>L1WJZnqduE8`)VQt$KZ&2v?~tM|s*J>QMI2 zM+Yj2^N2L=KwF*&gmjAD8`VN%J5JD54Gcd_UJ?=WBxc8i5%4#~c~b}Y;LgJ*vX z=YF&DYpnM3TR&>gATWd=B!bZ}j(r+}?MiDY#AF1M(+nCjMamR3lYD6_`cl447zk!C zjDbHl2`S@V$_nF%-p68G{uJjxq(hYXf}IwISa}Ac*(Tu$&b2U*aK4yuewnMUcCi&7Y89{kQITbr zHmV*?gTf;F@x9hBVcBAj`}6CkzRp8a;t%tKn4k|6XxKDYsUv_@>5v4>uFS*<=_ zQZ-M2HmElCGTW9N#91QIb1-3|rQ5H5)Il0US(c5%wXUIY*-rIQ>5hu#yN5G+o3{r< zeZy|v5ZPZ%1pPJ7oBruf3hY2{@kU2KS~oc@g_?wq=BV&AcOT5Y`5ToM5UN%U(Cae= zD(4LE>GpbZR?lc2@TOT54Mn-1({=q!nwhp;*Y@JYmeUudL4;gk5HGHIdI5~yrd%02 z_0Z(g3+Xjj)C5{qr>zhK>48u+gCE98P;t|e+5j084o_03QYdQDlQ{w~tXx2;iA%dz zTOxuML=Z!2IoEd$J~$7a&z@0&9=*6o7dwkpO9z$59SZZJyWu*a0$K)F+G?avPgFP| zhUAf_2gO-@wS7*UR|{DDqT&a*5UjQxO%=+8B(ie%nSxW=m@{xa^g<=f-mNFx4$i#h zFwXNRT1L?&5sZ#)UFB!e+`OR-BAUpvio2>h9>h@~utIAB^oy9o2G<mSy) z9goFxr~ck2%bIJP{m)XM%^&~gM~?s1g7W|VlsfeUX2d zWYO3giZgicc%qq_to`$Ygr9xZ zQ04w--E1}R{>+_o^Q_u^&|J=3o1*sjlf;G~;%z1_(*=2yE)qd{y?bBzUy1%Jkfqm5 zj@wMYQ1-B@q;KzWC^a)_-c`Q(#36bY-hOWgwxcJ)hG2Zn;6J=BfIOM5#=ICrf-)r*->|#Y{#{d$)-wM?X&j2&GPu+GXkh$HYKt>s$wEF z=f9rycYRU7_l;2t@8l_o>xttDL*dme&b^?TlazXUMReO>-0fIU!@LfsS~ZlK7VaL< zN>p4(&*!vpr;0C-exbF=h$DU!R^bpFY|KV4u&n2|U_L10WxEgwnVNEje>Icoqpgzz`|{o zHGv)3+#Mz#^nfl00&WghK8E4#ez;uQ819!&&Gu6awapf*%th9j&vIvWopI%kIg zVu#yn5Io^Dq3~gwkzY1D>Dz)P=_=^o<8 zqL0nlXWhsaD$(mF$XGTs)U`~3#?FJADZX?0gC=5MH#`~El*&a@vd35BE|9bRh*Yt3P;mNZw{D<}5T0F-6 zAD<)b7kjKv2XX$R!~8gw^TQ#2D6@Zt!U?%&(J>}R-e{Fz3I$o;CD2D@A4xk{3feJvCo|D6R>go zrlv5#z`ymN7Lqp#x8a|@S)UgJEjLshE)DYUz^eXPEYkH zuG;Z(=Bng7(@EfaO#ce$-%JFZd6vJanwwuoQa=<&v?)QIH^CN{-@(-PD0MjJx6xT` z&YN^kdu+fJ9(*VE`i4s!6fRuV;T!3I7I*VfjG&hkr{aNnvOIWOmCCNHnX<);+jBZU>^*!3KZ2tfAGLki=e1^gbda>*KT@*XvqI zo)rK_c4y^-{<@5veA&PQ8X32esF0Uq6i*7b>>)gFGOGMu_DU_p4Wq zG~gdmn6qKYgQDf&mY{!lhzO6KBL_aphx^GQ*`=$4*Q!2bXyzSiwAIL87n8lP`Oseh z%1DJUJp}OU+8g&%*NMEmq);yolaW&dDtgQH!lw1<`ec*QW%&?69te#lo3Hw(2M<(~ z4_@t$_FYJwZQ&W@Ru_9FPxx%H5>}CN4~PS zsMBv*sH}3zO+!W|&2{n04iWJac{C4shRbR!D;Y*9ymnhhBbDxqjrVq~LA0B!7NB;lZ?OOK3H&t!~g6Kc2KNslF>}O#5*E@fOqrczr2V}w^7$aeX zBng_2^U93upu zzOz^=jhdY;Pb_wCzV9wiW1Wi~hj^DjT&tf=;*BZEiVxYJh=&;7WidQsHoR&_JmAZu z3;S*3_xJZtZV&jo`}-%i2mIar{gc}RvVSA;ZS`1vFzb7ElaXUl+S7CbnvCeQ=^Blp zIp3q#YpqST2$3+kiI!uLm53w0-5%rV97-9#4nl=^&+3ZS{5ouhX9}cAACo6?D279$ zFUWdRLIu(D3iqZ{=Z`X^8c~t*l~}Do;@=^}$Xm}dUX|Cf*%|YJLS@}f5)?bku|egk z;21r;>QMGJrVwdI7+?X;l0WF|ksX&F?w?EG&(=AgGxdP?Bw%7gvq-(+b6j2DZliqX zMR`c@Gx=J4nP?#UZop>=RERVwPJx$PwPIbT4px@z{!DmaX||TLm52-qYIaThaJs9S zY6TP-+(4x!2o#ozsWe10tfyQ?LKV~`@v?? z(*-Ii?B-;g(iiOVRwehh?s$JdvGB9))SqjCPZlR%c%>*x0_&CzHzr*)*|PskKfYLc zSHXXoc7A`)zvP((4YKiEf1Zs8I)m$BrVleTw2>jM`XS!V9cJUgJnG~`y{HQ4^v#DQ zNTy#nPYT>)INru}lBer59C*~conFJsRJ&eKDLSQDhh`u$VypTaEjEgpnhmbH@KcvZ!UVQc#tFxJXg`#Sc40C zz85t$mp7MFZb&LW4Dn<^{3W~O++-HkP^`y;BvqhK-%UjcFqe)AG6j%RhscOF^BaV$ zzP=jIjJV{9i)`p=J@#5hZ%HV6=VZH11zLLp0mWG|q_Y=M^@2YE#V}##hQVB%AZG!p z$TpeRi+a`1qklsMp>Vaf?D>B_jQT|=VJBwR4?pMv!|@C&CZ_iMg0KyC>Nd`WSK6V^!T3febxW=Yhw{N*7-mx zk8eIKnI!X#K-hP08b7=lA=pO>wV91g#J)O7eTX#d+kkHyYtH!2w@Me6>_b~&`Htaz zfjQmfTw@bGgA+e)p)!s?+(P~3%@0ER(|bQc9`N_Z7IT}89M1LSRhrIhNyg%Oz2*ly zK*ThBUKO1JoKh1O@_6iRr_hYY%LS#fY?8{qJ&e-N=EQ^>D4$^cXq?I#GL8gshRKUx zRUH1>9v)CCxxrhK26f|AU+5ehqXEU5zV)sJ_e{YxeRQD>Z|Gf63HM@^%ULGjmkyOq zxi(z~98b|`9TI)zuMQp|$4ii+cg6Nm#Vf5BzUnKHf;3M~2cKpwQ8vIUe4$(;=+{!?1!kc}HlUFA+sDvzCCzVyoe_sRzKE<|Q;NTD4 zPU>NHQE&kC#&7NoY=fN@Uup7+Ixp(8DD*=rLAT9`^^bROWw(jOBOh@5j%-U-v*UFW zu~9%%Lm+2kB^2lps?;c$!i-6q@DUuyaDid?GF7F8bNM>UM>e|4a)Ut5BJtxOI zC639%r!G&NcOI|EsX==2VmS*>gN1FIU(HlI93Esmx7Kab_#;3RT;>dGfS$+8ksBr@ zBTZJwxEh4TB+I;`mVp$Kib{1pU&k1NXxz{U$Bj^ffPm21L;<2+{1wA@9wY3r5y$&vaCPP@s!{3{UEo_hbHF>CpXQ{kIy4 z=1Kg+{V(=sBKSAUzCz8POMZ|9f=Qe}Ap*x}2&HHQgK-+iQG%cdnuak5A&^gVlQHo| zkTl!Pn4mWw!}n=M6k}qPL1~7D7^HYZ4?!~I=grGV@kSH$i@4riR*cEL+Xa6gfZXMI zko3*c==2ReFwPJKlhX`L{{mmnD2C|7;)IgmN`E6%K0_`ob2nG4MWfS*q7xSoHE=W`NWqJE;5~{-XDz zun>4*Zjb%P?Kw8 z;qTHJc*WMSGfod{^Q6|7#-cy-Cti>)$>=x)TQ-_iHR7~+{VF+u8$-6=*$EGO4zx`V zTL4x*pysoXSO;6v1G{&R^Ms}Db#CC4ZUsdGvVptq zH?((khAh&NNhYBut~?8wDvKzJDJt^8&Xm&UaV6TxvHZkN4^{R5r|!La-Nx1=(0Bfd z^UgaX<^-Gv<{$=9OcLLigD6sB5W}y(5VzfJySLl!IWrfyK*Q+PW>{Njud44`^;JFd zBP2ibm$;e$SDR7SU7DK^6xU`B+?P;yuTGGAdq`sQs+%~;(?cYHuS`8taynmy!DwIi zd}Ak%(t)z7L8xz^82xN!D1C^N5L2gXSb;E^mr)L>+P3DZQ+JO?TctfB!#T2mI(H8O!IUp@q33z%EOv41}{ES~T z5KxQ~J-|~WklDm}aYIE#K#JK-`onTTK@3&d3{{@LmVrf7%taJ%0@6%Cc&FLu@@V3g zYj!t;$l-1-&(*c07^3&}FBka3U#>TE6CCea0Jh66#%7>KeVuh*GsBBk>rMDbWqOSQ zaXcf^mdgGkt2obaS=e+q*{s#V+ls~BIPS~%-p#OX5)#T{5z79cif|Lk4HRCq^%~$! zymHd}f!BL;3j?t*T)WU6b~apg0SulCc4y;zQ|ew?Cg{0|F5Pd-u>jV-{-C>tlF%kP zs`ANEQ%<-pFL)38sXR-c5fR|MX|OhjJ&HMS9<)&jJ-g0CBeh6Ad1WrElzFXVWIH!~ ze|-7$L!$du*-oTkWoi%uO=P#Km-0@#sMgDua@{cMM#6f{bI~ED^SFp^;@aPelR|nb zw-tx$kUy*2Bo%Rl6F@ZIpG(zFk=V3`%HFbC3@m>Hsq;Lc!L0SUy3AM2n&KD!>Zxbx z9$5Qm5JA3#&Ng>|W=@cF2`1rM5qf)KUw))# zyW+Dm$qxnG%z!Rjf_}R~qXChiaO_CX#HxHU&(0RLdI{RxQsNs?-Ks^W29&t#*T>;- zS~KF7>rdVV{PmTU_6d*NTyNX*$;GZ@Tq=!Jo^6@Qc(!fXtHklrAo7I8!@2gR8{aKR zc9yc6d;|2-icJ>3XVAS5wcI`rCf;5&`$|ODV2)@s<=^P^ftxxPJIh3A`MlCPq@`W$?)9+5O)XBZ@3o?498 zoH_t@YenA#z65t{Y^62hw0>=k``l34(*+aolMfZu@<_Yz(drVC=wZiM+~v& ziGFy4q$m?5O!OwEZ|0dszaol1=6G`KUq(WP-Sw*2{%TSTh{DHK%dv&aLDCvs9^^x2LHX;lsoY?DAP12XeR`a9_%^Fk*2{j_V;!pihm#ScR~Gj! zuLg7jBo&EAeN|mtzaE~pC4kQ(Se5=Wr!jpduc5?Vj>KSfoMw~fc3uG?H`uV!)jDWK zvzyPdp1VW26r)fRY`0ku4a*#j9Z%Dk=0-_@B-?w0<6Q5}S+o5TkZ%rG^XtRLuQf`{ zL=kq@G4YaT)}%@wWo^wKt%O`ERUjQ0HH>MMt~aAGSuN0J`3#K0I3H_z8nP;>Scz_F z7e`=oylTinx6d3US|E!X(0|K z@|3E}HVP$=6g~;E8a$nlW=OLMpvOEDsnHb`;&>kA3)m;qagqC*&bGy=?OM2hm^j$u zCOr(8cWGTT)I=J;xtHKFyFE~-R(~(laXbqUq6rG8m@Iiwo9=keNsZ_u?il)1bQ0@M zd+4xuu&=&J$uTY*YtpSd0Fm8IS1|9u>d%%!4;)flko9O=JWSN7f|B$DiDu8NoXtB$5TrzsJgW+aq zf`}pyWPRE7uZI~3 z`H~$K@99-I{9bc{?or-*26q%QY4%=tP49qUR(?g7;kMLp)dl>bKEk@1GUk?F}{-5^% zA^+*f_HV;0@FTwd39r;|!7K11zWxPX9dA~@&QvXno66D}-kTdOATy-|suXLjM?xr8%7Wft3{t9k^54=Uk**;Npcc9o_dIdPGA|Z@p&m+nrQXm_q zGLHH2fYmqPQp^SagxIPaipv+@EZO;@uEI6x`Wol6O;>Oh!sjX3YGw(_73GKx&50hRc zQb+~b;X;~u=nB|_Oidtdx-4xlXtt`rf83A5fjc}5ghmB*$u;GKNz@sXr>Em@=X>a$ zyUDDBxj{xhtT1nc040n)ZM0QRYVA9VS@=j&GdSnBlgR(hKo;;Typ@#MFiNmRT<)+a zaMvNnu1koXgNODFx4`Fk%btV0Yuwp$Vow++s~jTn);hzRrmtf4sN?uJI_6}!?mV0{I*-o%A(TmWy6QG;#fMmR(mMiB%OmKk2}wD(-wwkaTb_gx zUZ6(0hOnC;B=Tgh%(CW6w_>3=;$rFTNTbM!9 z3PDPJ?Oeh;MR1Vk%f=&|OB&;aTO*WlI3(nF1BkoC^+xOYCaCCCQVmsXv~c4^+JSmi z-D{D&B=xvL!aUx0?|MFaKd1%%hZV7;Ejep~Pk>F6`M6bT*O#O7*j6!=g}+k^n9oQ| zkv6rKdmgTa3dA#Bt~ny2(&1`$iivO|r-yWbCP@^T?K$q^vf@uCk;a7$RH0#ZQe|!Z z*P+Z-^TGkIjBw&jgQ$nh>ml+JOs za<>$yMB$Ws*YvQE3YL%um43-!2m9{x#^X?OKG!64h+*>RMC3D&Ds!z6-RTig4R7m( zZvp6upvMb`6ZIBd*C0Ox6>3<^45GntMBpMM)oj(<2XZW5Y&W)o2i<*CiPY1^ISp?D zgHsW|4bg0#SN;8KJkb4~^+^>q|FXXQ!4IhWo40%g($6pdZn~I&C=|zOlB5X?Mk$K? zbi|nYm}!a_JZ7?8eoaMt9KkNL#`j?&3S)ADNeL$YiS@?rFB%hj7Z-m+CY`)X%`Dji z4Dwx>uxH#6*&AOI@?Ck7)F03LYeE9L3)$i?PM`_?CGp@5=h*w^3}GOciJ&*Mli5ew z!uw_KMG$X%j&|&)_Z~M!yN#C6> zFjwiiGRrH5ni6+AYq~ya+Sv`Z!9t(wa$0WU+DJJeKGRs3jwe7_2w9G@=jb5#Wk!zk z6O_!$ZPnu;xz_nQ_~Y@E^k(889(GT7gi&Xpqp6`0H&5!?191dN)T#G*3XJfavmfd} zo(ZoG&<6nu#$mF+umO!?POn{+fF4LT5}BE-v?yMBVs*gC)Ly$kV^_+io@c@7<`Z0Q z(RbwL_bqIx@<}u=SAv^$%{-vW86-REa!r%vvNnVR1FQ1D5%2gsqI7Z?u)9l`_reWc zXZ_(RMaO$GtWq#?gvI8`VERGw0 zGq2Q!C)vZsY<*G(pk1&N9^U;I?;?##{iE*e`+sxb(~(-K8fezGwuChgb5Fy17hKjm zogq~ih^;en5b9p2HutVFaPdxZSz%y8s`uOj-Dez&$H%i*!^9g>!hncLlhU%+Om~r< zRIbW9{kEaQrFjFQN6c4d+i0y&&sn-hy@nY+0f&#t{w&) zs#E~Q1_qh6Ko@|Cqwac#K~urZ7S)hyneyZXJEkW|?Bn`U^kbAjw{q|r1qIJ*5fnbJ?-v40xK^>Ja z7`%(5_eA~_XUNYzsS*0UuOoXalZqK+FP)&>1)3nf*hi=E?jM!D3#*SaNC;w(pH*nk z9+&@ysOXJ=G`UY4!SCB>=v|5B=o>rml)?AM5yTthGUWX-Y6r@AZ&?_k*(-Ugw6E=EOACc3;GN8)aaQyg6MS9QMo&RGX+(OG0V zFX!&Uq9uDcWe9dSDT@l9k{1$OV!Fj`MK<#o@nM4iI|*x5nxr2idlw4!0TA0FQvzJP zHrj^9`EL7iCJ8Ce9nIM%ins)!5o}*m&Gz*(h%`AFIWUDq^RAq*HkE-@K@nOza^?$- z&6Bj|FT;>}1d{#+Vz}kt;P@8JccKDp-I=q7wLQfZR~`C~Am-1&RJFMbWk@^?orcGI zeBWHY)$LUhk@jI8hSxI#LGcvd+}r|2L7hCwi%btkY*Z{r+(g~dpY<*m<}*B^#sq7$ zJ@}*Kc-upS+LO9)gB1FY>h{Wj?F-36lr%ulKno)@KppldKzFDD z=PkQUbzJ0XCN)dvcOy0dT{F@BQsXyCFcYc8G$d74Dl53{K|{`x#@vkvd!Igp(yQoY zkk?MJB<4$3=gK+6C}2UeS9q*k^bkG@Oe?5c!I$U;&yO1?1#B2f&*5g7io_m^Pr{TbRvTVsNW5(c3d6k@Q9 zfp)P=PBSRQzyw2)4E}lXl2UuEgT4!s3}PVkT_waYL*ehDhd>!DXULBk8RCs&$X@0k z6odS%cp>+JRWxVFoIy#3h~L!*v|4;)Zi{uTOO&*QGzU+>x~bO{UYMs&fsT zUmgDDj*|@DJTx!u#g(-#(~jDyKJZm(zjT^!4$$*_C9BX}qi2`leF%Vcot>q`$Mecq z%|^uvD9{!tTUATa;*5AUKDV((<*dlLzP|2NMBf*%JsiOs)tkKo4AiNNv{eI@j`c?p z@j?*VHA%S2+3}k;ecY;%aQi;mt;5+zJ~tV z+*3p>4Lg}M@1DvheWKQJsr7)c>{Lq++e?2OZSD$#zYAt|4Z zB6h!EpdGQd*L12AZn{nP8b3d1v0B(?Yl-DB9NI%3O)}tv76ErYmXZ&FxRnQbtUwik zvKK8Pu~a5hM%-lIj%fSjq*GkhIz$b$sXCypf(qyWPbHLFQEN_5JDcr92yWML((-Mj zgVlGG*EB8$tL3Dmd96VnIvYx5sHj5e&XV_*bO3yUFk+fHrCwD3cGDJUMp=zeg@N0! zfW8wKO)&(_#_d5^!w1jGo75EOa4QC`h7ROXME(^&#I~HRTM!Cy`10zp z{(ULxD$Fp&q4cs@JO+>oKY zAIJOm^GV;!YBZD$iL0TGw>#|x{p0RCqLW|G(Nh1;>@M)a6y2h3ggcvl_mNDd#?yRTZMYoscUJfdSRfF_<~s9_RA7d zlF@Opli^<1(>S*kjWwN70Op8O0&;V!qYs;pLVXNz-Wy~cm=Ss!34#I#$Tq90$bIaz z9{fkXh2410I2OC~InDu;6|BkYAr`gC6FhvS;mEkwAYu1>B1j9U-@W@qGEc0oVfj-u z?+#*49Ab5YGamxM28^R)t?apaChlmaIMINRWl4mi-NBr&Jp$5v}wm@v);gN4Etc6ESo;*`pZ?fCoyM-=N3f% zHKG9d7{O18fC^;kBTsN!dRu0s>8DH@`P^Ne4TtdUgU-sV^uv(9yP}2$?76nRIiDg6 zIFE8FnY|)`w$yZ+sOet3Ew(b;1gyhxuIy(KlBZzhpR9R84&)rws9#H^3xV~4$be(U zBNN+n@_D}6|3nu28L<(0{vVT}&+hpfLiE1=yK)hxVCm=5B#J@yyoq2#-w=x0jbIAut951k@**AQ|y&dM2LuiFWXAtNT;N6;wvy?!!f$URFh zr}ind>|Iu8d(tkQFnGpL*lxItyh#*-{)!ZFhc_v@27h*RwWO(rwdn+t9{8J!^QF9pYts7qGJAXn5(j`rdP; zkR3PMq%0a3257)z}D} z-&jXDQNK3C%!#n+glB^lgy@B{a6|?t;lsxAtIHtgvcen3z9tX<=rH(W>RihT+>Nc- z3!hs`C2>(t)vVpq%H`k>K-9&>!lw`}lrB8`2YGYrr2@CLxKSpKUU0IMsT?V>R^$y) z3rpzac_~Oh^KA_VLIv_Bp<9XOql2gD@ntR^Cp-wiDLg%{_;tuI!~(~wV#f2)$o^3# zXx5L@{a^e3k)>bzb^qeoe_8+b+G@+j?mK11K9%|}%lmrcZ$$h2pT6bW?7L6j@Lkpq zNt4*8z6&Y-E|VyDkBr-svOhGL81XLeD4HSh_l^VQOcXKXPYiR(-NP1n|A|0MOulbL za|Wj0TOqXP=S90+9vZzrj6O7(1VjH!mWd|}PQBMaeVnM_?=lbDH#HL5b)*QBB22tD zEa5#Y^t~tUc1KwB-X$sY{hD+i>P6D`nh0w5%!L>#`_riyrzD(Ne^4}}ehe|p{u>T0;^Y;Fen#js)7 z^L@U21_U(+{xH>RyMkC5Jp0v!F!Tfbk==bLUjHIjDFAQ9IlcZfqMKigZ2xtX_m=*P zd>==h0rji=a%qIG-^a&}d~U*T8lb9Za-TIofuETIVuz9L&?7Ow1Wi(NIGQC33viYr zAEO4t2O1v60qzyR^TGZh9Pig_hQtLZLp94chx!uvSt$!m8r{$MQb=Jh%!^Z(6jZp5 zv(}v|Q6xv`2H;*!F-72~1&;mTnFUqeZ%?H5R4fcNiqbT49pd&VC<3>lAYT!wUZ#o{ zzMN;4ExreE-0Na*_tAH12`ir@Z3wr%E;WN%kTRt3b9%hBFV(3f1hc%uCX_GaAQ&KqWet1-;efO7!s|${!9{2y9CLVq7u~gz9#rT8N?rkE z8`J`@$!S1Kag<;vpCsXYDerBRVv4cWM^C%p57^axHMGxBi#y*pKzC39{(>ss=X|T_ zfa=_Vy3xbMB;(0`Sx3=?LYV&200lnlfPUHlJw{#c=oafD_wGPfkXWS^jIY3;lp;pY zNk6x=3f08R>BY(S#PQ76wUcK&rqz%|W`dC7wm(!u&qubu-V;mkASKrUm3~9v66m1x z5NtGj_EcH;LdZRX?tptJbnHQ_Kf!kgmP)m6?4rG-toov{_Il6m6rj;(rH(uETrTLg zI5$PV-;Bgbj*2aqCu)Xv17{2!?*n}i z^JePwr^uM(44p9)$q@Uj-JA3$42Cesp12aBZv>0bHM@=VjplQw@*06JyqH8e$zG)>l|^7LQfuc*VGk;ojG&?b zNA#lS8aR!qoT^(|Kj?+;D#YQq(Vj08b}C<*UpTrBALBl10wPfkebijbjYo<+y8!2W z4*hNDWALodS|c4wbOE)jt~dx)r1gX;*XG^`SSPuMv&JDRt**;p^<00TK=QBw{RMHZ zg%%%E1MYAuvXOIfiFLwwQ6zVyODf zUc^|1otG<1KF>0CQ@%#f?j_Xc7VEzQZ0DyX4fi@F^x&nPvc?hQb6xX7aG$>L6yPrz zYPQIpOdma^eO|>+MPN%WsyO@B6SM6ixOR60zB+Wa!C#Ji#sh}fYqtaa#EC1LV-0^F zuV>spSvs|?NO2JllV&f%Q_hnu%1c(Wa1}l_)_RzRo=cknxMZq_3^2WfN+N&;fZ#q#-j4{bBUWE5a@?`gFN3l2HBqT#(KdbWKeUd)eyHxuV zQ*5`h#hG;XXF}=SpFL+1f=TwtI|ABcS$8b{2u+D`2HEZYu;~5Uk4quJgznPo!R?B5!Ltr<{?=FDgsy}`>Uw&xBISu>Wpn)Qpk`2+ODxFs# zy_k?HnfSY=iZ4cCL)4^;i+BFco_27R#%!*rzZYk!XujeAhU0rv17EARU2y*fz~3Bs z`_R*~K4AIB#p^9%@$dX1!A@U4gz(Dg%i$Qj%mHcW=pL$TcXy*z7)mhxcrVDXIJD@kqUq9r^nJOU2Cw zN|Sr8btkhzs^AKKaW_yWkPNGiz4U5Ke|RWj9^dEke3LVtjIZaOD0BaKi_C(>!lKD1QJN1wJ>HVor}Vs}4HuS_ttyy+Cj(%e#3Lzer@sTdzqSW|NX!35P;XdI zQ|$Fd8j{S-heGFXdLCL`LN?97>rd^1^hf6rWLZZkOZt$2q|+9m?ww5r+wmyY)8Tq+ zso`?y*84W-4nnQwK~X4nZMj&2whQ7Qp*v~uQX<*uk^tSU$YmF_Zs2PH%Y52AvgSC= zho{R8%?FUXY?b1Z@`GG2E>aM5cANN{h4gTmT<;|Xj0dEyI;ZI6BY2$eih1ImY&^wB z|4JPS7Ts2JpgiI^wr5$quV=D$eNua#amWF0g0up#cjM_oZ)on&=jJ`|qxL|mJ%0D{ zgXwqtvvBpQnUuu2pI?y!Wd%atU;ag%Sw%f32f(S@Gw0p(2YE${$WQBIw_Q51%a19o zfdkuj5c+!<#+(0UlQC+lVJ~;GcKjAEKAMkTFL3_*@!#x!A0QOPDI9@lg8cDV=0AGU zABQ!6`;>3-i$F-2!Z4CVFa#q>2#2Uo5slv6T=(=yXfLJU_zgVyNA0uEqs9A?OHMG+ z=i}rbnIbW|Pnr=79x({DpOQp7#-V#FG27di@f&;+a<}J8m?-%fqTvjUyg`cEk6vhk zL8INW{X@wARnVDa3=}gF#Sr^X^Z32&c$fJ{(Owhg@81r`cZkiIl-#G>eu-$(-nS(F zsLoV>?#>OQix~B}3P0L@5VAPFy$CgHd>L9ZI1hfrvNRcvF@F>A&0W!R8OzP4O2(A% zIHycdMTY|S5!VNLEKjDs@=gbaF=o&1KWc?_6!T^VUL_1(FqCONbiy_?BJ)5gm zXXC4M|NGCrTmF9R^q(yMy?Wq3S^j(Vz(0}BJg8WFIQN@w9U9pPX76ae0MDIrzUj63 zR$%;~CLLEEZgHSY9(zE~aHq_b06S1t9R;k0qf;E-_}haGV4qTBwY>mXv{I^ZTrkx< zSNFzbwJ?g;1AA78T9};k=GPN?dMV1yS5POzc~;IJm6+0=IO@?#T7+}EeMkI<8hQ#vf*{OXI9e}2{H=~SOm7QR0E80Z&Q4G6`k&acwoW2)1J zyogdonccqI?hf|=Lx?=M#ErIFt_7Pe$xiYG>6YSFU{@Q!VHH12WBKYP|MHcIQM4cu?0^*En#Qb=XZ(2!1&kLbWi^%3g zc$L?#Zcp^K9puwXru?TKWGde)lLLvE=faId7fS{lC2%GLTG}Y^bw>_lX_{#8@L#>= zi0wpBv-mtYj}vz0mCEq^(i1Tou?#pD=WsMJ33w5P+)@?1Wp)lPi7Z^6ekyrp#PyWO zja8_@Bc=t#jN6JoLmu8k5=d4#K7u+n#4V6NV#K2Y)|A*TII)hWh!;ce@0n~-w0<1# z>$Dyw5w9hJ;8)&5+ew&ChuZHDRLpK9P@j&=>?7%e9gQP>U*%H(x6mKlqBdmldu}1= z*GlNs7A^1OwcUVhE9b_z@oXL2KehY)P`}n3SIkn!dfr&6)==e{9FIVio1~@i-fFA7 zIkKO7&B}!o{Vi_a-db9LLOZpyoY4RLqP1aTA z8+4;<;4wEme|9PM*z$#9p7eoZk+VcP)`MUN!6nv$)0z^R6K+%Qh}+~4p2x!zJ48IT zt{30}Vfig|i9@y4h;of45m_w}jKLCCugdL?y-xHqS=z>c5%U3(reT_?}L z5xdY2q*kXw?1x~1l(^iQET2XyX(*O6SX~3hV$zk+pWqvIdGr4+!~9 z(@0;xwRm%&jS-6*>!pA<+mUVilHINI;n_}B4$0w*%hqSw5{GDs3WB^S2Tk(;eI3r) z>Y@XVZ_uwJrN%BJ|;P6coNo14~0Gz|axh*CwqA!T2G!aDy& zQz%TJDDoq*`^Ptb<#Io{@w@ZpPp4Xl{YVzsLr(EG>mjf=>58a5)f8grm?0?!!`}ab zeBMyUXas>V1&UShW?rJG9B%40T6@i z@#JK(r^?X`o-#DHI|%GY&`HW*C_~Z=M7`e^6AVV|9h78u|A(1qZ>~fT17%FUr^emvTBSczZ62M2Lyf$vZ!zBJpsP~=NGPN*@5`N;=#%tG?% z)Y2i*Ur((|g@}`?{Y}xLA;5&knA=N9nCF9$f?WVw9-4a%CHV%ff-+CT0DMGbCz<>n zw&mC?WD$eo11R2QzhyQ3$t9P&eU`XR)6V&%8)wRCxNBr`>uMlyqAY;Xu(sPCpz?7V zO4G7l;&iyMlErOkBB@W0f4a})Fz8-ZxZF|`!b|KS-}ZBND{0aW0sEd-mo_iD<}!?9 z^N?td=plD>h9JY0uFWkUhKXL+vOJIGJ{BOvb)QwSU51HjZX6Kxi8-+umv;juZ}pvT zvhb8)C2>5#0vD$hI79Vgekv^MOBmc0v^KX(p>AiXgOjEQya5%@-60wC)73|fj0kO< z(+@6M*V!nYhUmOj`QV&zZk+r4Sb_NqmG0+z6w;a(=@lTI%a*%64sfu-ZftCrtn`_%Ml96`b^?To$;xQaO!= z%3y#b9LML$kn3zUulGUmvy8MARjbOhK4NaLoPh67AATbr!ML+2$W^yahtH2~1EyDM z%rt>@1cd*joAcMrWv@&`)`O`MpyTIkH7c%a$2n#Njij)Goa425kdKFQK4fJ~jfVgM z7cV{$(|uO7RMe$~?3WWpAOpZ6(3CjDYq6}cBOybKGUxz3*KA>Jg-9=Uth4>g9)dJf zM77>jUwjzGqbQ%W{9Moxu$pOZOkBhuQSAn0P|}!o$v8OEtjAOReeHcRMR87n31J~4 z!wRGMgh!km(8bNtI{?gwDoGo9*kJiZI%1EriGWc~^gO)C5-0jXJ62`Vr!Qjg)!R)M zsl(VGTen-gTbPr;F$u{FkKij3AtO=7Vk1kV-GJA&oDa|DdDX9}(B6zg(myqoTW35u zP;J)Rt9o3(2>}Gv;dPbk?Q5sb*3?8a7>dJmgnfb)G^Nmr0&$EBVR0gSSOY=NHR470 zbp0Zl74il^p&ZpCa8wxYQ91;c&LQM=UAcxf^KJCkJBDC3Ava=7}lNIb8A=B<`Lcrnq@jN~8qj7i~ z=n_CrQsf5nszRr!Kh_g@>m1%)(j+;8S>E#{Ql$I=PNHO%A?-o?+U>czw@8j?{dhZV zz!iq0z*1k>g5I8KZ1W?Zz37bNb46R$tJ!Ns;6K^_DOo~)&3ArImVV>r&&d+{+hhq% z88l|#-M9B6_7C69gHxQLsJ(%d?Xy}WlORl%d_JfZF?qz~H)N?UU`zUeEPZ_Te@>Q+{~=jA zULyYC1)gR3R70d`Ey_mwjHxq+Oe`ObzKU$lSs66y3WWL^(XZam(#pQx=1QkA?3BjE z)4CEWdRUq+cxV!mZs*C#VRRXwtdo>WudX-+RG}eqlkJip6R= z%}4eHrH`ttu+$&w&OPV}sBM|0PFClx{p+d^G%#+hAQX~v_aVonM*(cIlFaYvtCSS2 z8QlAEOr`EQo6B-(z00A}uE>jg9XWJ-mB{G=K!Wy!8+Z^-@)p-^6>Z{V*=#GB7&cpT z74tfC};& zi4|Ft1};kV1K~SmDfKuoUk+fwo_(G@KSVT8maY4_rZl0k*Go^C*S2d(Oz050(YdBW zgX&`QoQA?OrFmLHuN*1>D7Hw36w46e^x^BoULH|0Q|@a{ChW0aoQinP?rqL z*I7gF=UN>2L66XXPL{+B+wwybgCsUg^9yhb64zqhI>|5LpOPh(XKTQAJ@IB}?Da0Z zu-Z4^4IHrAv8SW-N?%m*#k3VBj(nMokV2mdxs=jswe)GX+MJLCHalSZ!D)+;ISGl7B%9F}w z&tyJ7+-;S5Q)%8cF)9`|#Rcn>^<{T+&BS?JCmo^Aj$`An-?x0G*w_~`q$Dp|ckIBt$ z#w^dL%XKK($FrwG>wJW9$z`LWsAM9!Kn}hlJZD5)YCNS!w}dC=1dg;$ zRap^!txLUvq*IHg(_Iq+RFR_-!^l{RRO^=;N=!g{H;>tkYi?MMDIIT=Qy{|~WgR4A zxLQSUJwL0{%_KLsDSWwysqS`XgGz9Y>P8qh5xB+b+2ll!7&$>cQ^E~rjRP#w{^88U zlcIMz*{{LLjFasK3ehvt(DCIXmqfJ9vA|#ewM63*PlXq{dS1r8=z#U@c2QkL317xN z^qN%GVd3<0{Rb^T{#Hbd&Qc)V$wZ^S1YjcRCNqz6meZQGJO$w-WSO<8)D1S|k>HPc z%>`pWlGC-lOr->AP~t^p_k`RUQpYEN9SU-y7ZXO@)r-md^EpO@t4v(KY_G+v_{Tw+ z!sPeKlKWq7)?`kW{Ocp=@q@N};V{;}-T(TkW)a(QX9q*}r$MEBkClH}-Zxi$vE9nv z7yqdB{6BruA9B#YdCM=Aph>j%av&z67;HC|rV)mU-V`R!7%F3soJlYSA$L9K=XNYO z&O`)5B5xX$d`zb&yN3(PASgp(3<)tX&CuzWQ$iSKGW5;MQurraEKeB{WzvXA(cOm{ zW3Zgb;WxcPcV{wae?b~CG{KNC1MN`}DZNkjXG{_?WX7QI`^Dt$-ICF}9u#4an2CSM z#e{jEk(mBQ3Hl`o;s?_6|8nXTr$H;FS`5B^d)s(o!j(;(nW>FBTT@9*3m@SpDQ@7x~npYHEJ-QKrS zQ{b;^O&N=$^4MIX=JL8+iK^(6xlEDxq6g@5K6HQ-)Cxx$#qaR+-dVY8?N@3s&CIl& zC2w5T(51Q;S*Lle*Jkq>DpuALgBb?0hx~d5Y;||dK$_ec)L$>AxK2pWrx3C1N7$ntjDq;)(l;u8bnf|-4-u0S{n&6BM8ynfs)1s{8g$lH4(V+m|r zacIBjpd91aV)#|>Pytx*Q`jvUAoPru3Rd;l7#uf8Kb810E1LmMo_M)0+crU= zf5us&CVBfDR2zPL<1fH}A~3&mh5l1#9|SPx95!HyOX}-G63vO(CGT}6jQw{6#u6C6 zMP8jAP;hVTK%nB!+ZB#3Sb1VnY4s`&bqgz1LMtt2{u$nHk4r*jP>m#D-(N^98&M^Z zk;;zwvls)AOwH3yJ&Wb(Rp%F* zAZvht0AAf+glRz78WdxVUp+_;Zm6u~7ZZNwkNd^)!NMO;7LRkz9@&~i)Fvp)_R2s| z8M*)kS*OZH5+`^h^NF;~BArr7R+L+*9vaDNu^LN;*1W1)A+=aCKkbPZZM^h!V7dn4UX$oWsle#655JnqL@ z90UiEUqWL3Y4-aVD3dvj5_FQi;f17VOz9M)5uAoF z8bLlDOP|qHN<--zkYMVKaOFp88Y^iKq)YHOkcd)rLC^_Gqwsq^CHMwp9R4g5eOd)E z^iwa2eQI)W8UyJ9rAw5iiuaHLp;3~~aXR@VH45+z^#%1&$%N<(`YT8jv^OMf-yxCb zBJ=pw`m`p1Kei3tY!T3GZxz;WP0E{~er=Wh1`B^wWNMmxvld^x_#X6!Apwwn@)^wW z@pk5wN^6gq2q(Yqa-iFv&w&*3omTv zYl|F?P+Mj-m39}X7Z~9M0n~5)g@={03Oy7C7Dv8@N5`-tm6r3~Zq0MFSR&R3H*ieD zky~3*IF}to$#ClFuWQU)cR$p4$^fM& zBv!6GOw`;tzYW!_>59s^j`~J*^p~m4h-t=tIgnyJu2eP{l zr|{PTulqJ;h_zZc%MScWGJ_h-Wd>Jw3dxb|8FLW$g_vQ_IJ907a+v`YwwC-$!)lqm zrzukH=eq!rM+ob6cwEZQcfrBh?EdfNdBFG1M)?%N2d^Nwla-E$S2Ayi>}70N$BzVy zom6$ygj4Eimpd%ux~BT8R`d;!WaW|Rb0tQp#h2V^VnnFcuu~7h=LKen-ZZaraVZkL zY5TbBEQxpYMm~Y6gNoD$0t0gP5Q2-C$M#C#dA>OIJ_OKR8bE_+RHE_cz}XvdFkIS9%2 zJPEOTF(i^qgI9DX0aFR?$vWKmf^+W@_blh=)}dn^Vv-S$%B4P1y}{?O;GQ+7zf`wQ|cpxg8Xhlp`bI2MkyLk-zOqJn%5-$hUk=f&kdw# z_|sYfe@ZXX;(eJEe8;QMm!=T(9R`EhXL%!e2f!urCJZP^lYfoa)*G?+9}pY-C1Q)r zKS%6q%M9PJQStr;V%vW78`SnzosWM)ZEpqMJAXB`zdJMFcT@ZQ%>IdG!lmD8-d>;0 z3DK^c@d{VrAh70j>8WZgouV3hplhoORkKFtT#kE$B%*`#Y`MnSenr}`VqW}8O;>R~ zQ89M$o(rjMH+ZN{*R(RZTmu2bHKAyc>%;CxqOMI>Y@TRM1iU!=!BXK*&5B}{Xf@&r zHDPY>>N)PD+3jG`8P0eNJS*rdbm8PDLZv5{2%@b*4=HmU*{#dRgg))o-U2H@ z8y!LsvPNRi0d*DbY+xj?`#22vbwXrml55fAPDTx52lU*M7Y@!|R1L4WFcAKA!)mIP zjewlPR~>T8)k#S}uB?-M~>#IU$s%#A*-J|ZiOP97p$&f{|`5DbE3B*FiL z+>W&ZRV7q^D+jI{UUS0+t(D?(G*D@6iFBq ziLHBTjwNvgjD~#0Qn$x}4yMQjQ}5s4&w8eJA5=lzF#mYaI<5V(hV}+x3*KrVL$pq7 znGb|ppzz+_KPc@-pKXn2FjXKaoBO5`^oIS<<2+jjBmlNcwLdt1gqJSAQ(q+}usI2J zP!p2MzOr0>V~1R}*Y~V*BuCz}1%8+=tnVpDeJ3Cxa(ShQT}GcJK)uu;s*QYd4`Ck; zj}O0i0&m>^z0U*#65*1VSI27%G7&;gRtfWDnnU3^=~SPi5kQ{&25HfaD|+^TymaCD z_^787+evpZu@-{3sIQ$FE?#esZH(wfeM6w@CS>_h%peBz^L1%up(eX=nkbTVyWlks zb|)%#EGOrOmJ;RwBW4OVo_3307$RxIH4!8?lgUaK0nT|!d3cl|+=Yz3JmG7+E4Rgh zz*780naJSJS0^Tao?fEt%)&gfhM zaY`R@lHM9z4#}L-SwP z_I`Q#ua(+SW|trRmTs!({C(p^j`hxE~eiz{R>9`-# z$sk6+2nOOHj8F)IkTCSi3^R<=AoPxX-vCN{^aY5I<~Q~ZSrL+kk~egNpN2{B*Zr9( zM&l4&d_)P7PjzI0zHt;y-$6Q*yzw=`-oY&TS@VAbKSAddP5dsyT)^+>9ZfzGulZ+r zAAI9;iG9!?`Y0KIZ@ACl56~BMUeakwL**yB{@6|62#pl)h?-1jD*qT$kTgip;9n|` ziOCympzo{w7v^$B8~wR9v)KL`08l`$zoeD#NC2q*E`mw;4j1A-TNGV| zbrh0NALE^^)n0o7ntfZvZ=S*%%Ucfn?SL;CRZ;ocniv``_Q3f^gQ(kOfB#rz@K)z{VFUj7aB#WX`-84mB;lFu=q9;L_)Ysqc!RX?_4BWK z1754VVL|zwrU3UP&#PRS;Uh`e45YBQ$^wlW=1p)UY>Q!m8T}H21ccw7WWxx!a6c3tYo7dDN9;bPjL8ieY z-|op)Iz2*a)Q%g-D~TC_t>gM*s=Ca|i0xKNGok<+yx*r>+eYFTutK~;i%Kwr&Bocy znkrO`$b?DmxAmN>&znK&7wS}Yp$Vc+n51l40G3;U`0ygZq7p<&Sga7AHzYT9Nc2t+ z?nvw`1ou|jGZ$Yrqq?h^eI?4kCpWUMOB>kt@KoQ>o7zQMA;1M=U+-5uW8(lLqZ$@! z{rp&^Cp0<_zan*4u(m_Cp1VErw$)AsU`e1PR@ayyVuGb;q?|mhx`VFx zu2;zPY#W?6g0z1=^>~5fgGw%dRYt;X7{+S=O-6n6c?fcuMI5V9Q2W;BeZcMOJ+78X z5Qw?I*V8?TZ`^=w@=|#o4>aev4~mv$Yl%X#6T{r7&XViQhIr+EipnZ{-Rx_f*74LJ z-Q;iQ8*WRnit!h(H0&AZRn0K%qM2LEfqHy@2zLSuhrv?uMy$^z#%HAvn#7G6I}2Cz z(yS!L_l`1U^rz`U!1VArA6a1`+K6zr_&(aO{uhcvzmlqILm2zXc24|>DBOxO?z=cF-^*v@fA)CbVNoP`Fr|krQwdir(SPMVtW== zmG#l11f*ef$E6`)*Y{^z79W;z`0W#`FIp4!1WVNyr#TICOdKcuc0f<g4io2wlsb#7+S0ql9D9zNBj0wB()!{g+Q>!7D}WQEm}t}@f;z7w#SqJ<5fTO!6_Yt6GZY8AYql6i7Pk{ zleQ{egu@st4Q5GW!fI0MlO`?6LOXjV+Ib*=8Fb#in0m0umRwD1AL_(7!4Pl>LNJ(eK`z>73WkORB4SlSsVe+GCkArm?$K3*-KdQKRA^E{CFR1ZL( zIe+|I@Pf`E8vL+56r!QOq(?G%a2%U{&s`|tY#`%JKaU3UOFtB={X^3TVAl0wc{=ZR z7uNBI?I%qm%K_~PhmWcU`X+C_d-ncY2S&BEbYVO?5kPc7qnb_Hy6Wg)NS$gBrC1G z4-p_QjS1TcDF_uDnru5`Y!Y%70^w$`uif@61vVR;wagd2(hw4a&zF<_fcZgn>?jxj z32p|nXhB=rsUcHUhQKwm)|gtSu8zjHN;M6*TlA8!Z=40TeoqQ+ehX{1>2`f&fKE22 zqryUyF<4^+uY;fSNwS4$c()28fENB0y@XxAUZsA(3!J&39q2rsM1u0lR8N4ykn2@+ z{PM&ezO12L&WqC|J1K?HhDPOx} z_HnjtL%^E2I2oKGGZQIJ$&jrHN=k;nJa{R19(}G;>+~@AOECo-R>;5&FQsM}jt*uJ zfyYDhj*eoU)I23ADtj$c{BhfE>SQHq+j*wTME=rFGePbeyq!@3K(9i_g3Yu?9e7?F zvr^AYcMlKZxv7Z?=Z&UqGsthac7_f0nPIwkh73QtBL@zdngQIAz{b?kQS0smmZ2Wh zJ^8Fs_yk=C2fGPK*bSObVPP07g@^TAuQB%c;t`Cc7onSPiC{OF$njS?E!;L^~_-b`fH73PqcEHn{LyI|W%hW^2?VO>iF&mq> zMv8s4U_4edX3VUKiN7%(RN?l6l(4F<;jdC2${>iG+~uEZk8C!6WN3L zMZ!aDBP4ppq4tXJ-3-KmcuRxssehgF+bapAQyuQ>|su^UM7W zn`6J^xRlk3G&W&G{VFepS?YV?0)80>_#k)sylZlMqBKQevoEVo6{{$0(sCRVL~B)v z4O`j1>@Xi?(18EsG$r8sKWtUF_Xi@2bBxU}mc>GhY%%G|?u>L}Vur05$zl|Sy)lya ze&yeXN4DTKB%65!|GST`zq44J`dhgfhePW4ZQigpoQpNy;#n$gD6`wO|Ol-0Hd+LeB z-rqBc*7wvkCb9VAePV@S#rF*2_e^E$eG6YcNIp{+7?t^QBFAE-&n;LC$nX)PG0evB z0;5|D%m^NHwV2N>zHh-|MD2a%?&}qX_nC8sT^W90)RlQLa>nEdBr@x z{1XpmWvgmpt2bYfB!7X|hLBmw%e!b_V-9h@TCEBcetU@TFG zid^a>96z(reCig5%JWO^@7J+L_~lU+1c7Ia%Gy2yE$RC=@ZZoH_#R_ivW*$f{n^ud zN3cAMyUT>P4)Ma7dOqq=nqNB*hG2}ZSO+z>zPHFR9|4{K1)I8`V8R>W@fA;xdkp0o zsa;H{O{C$>B)V<7S8?=7joO+9uaFa0Mw|nt1X+2&W#`6NaL?)zLy!BWM*|Xx>uYG!er_G`D6)wz#R(VHFn9L?f|2mg=?tU`hrW6i|0grze-fF5)n%E z+{EyCMa55zS1L$y@W79$V5{L@8FdUn?K7`=fEw@jA{^y&qS%`nqD zhR$CQgSoiQX}ffDpIgjjlP<{Bs>{B+&%n~-OAlGAQkksWi?{RZhH_&RA(rAzoT;+) zT8uKR^EujEMYF(lfXtkkU-8z3n?MGLqV{b8RwzC`)t3>S%*^m_Hv?+54jOFBy04W` zgAXXhNwVkIQD&=G6+m|k6>Jr&0R=zC(Qz~(;=JH-ZJu85todP&CvX#-y^xahiTYu^ z8k5OK?oA|$ro4uQ?|2e19}G}K8w1a~Z$e?EX9ZfTI2dLSUajIz4COuC;O7#B(q%c{ z*LWJ`>LU01V@Q)OJx-elBEuWrkQiN~)q* z+x>o0*P~jHXJbMGECZwI2iBIvs_ESP$pW8}fb7{Ns@P}M;W8OS$S9Pl&4Y`t3(=!N zBjRtz7$1?=F9o@O>Ztm=0Cm@$f<4x|14E%@Mg_1~({5io&+@v^^3cTsh3yZM|Jemt=&P z;R*?@JxkdI9C@*@e#RSV|Fd)WKjR`BVlDrH15bnc3GVO%609 zB|>0L8DvEf~sm6vak7y1QC$ zqwU3exIsd;t+_xh_YJmf6AG?Z{`5rS$8L@p2esLDTVP5b7zqMMvs-;6*ROMCO z&nkBl)Acg-&lCCDA7ntXRtt)278SdjW&-etoK}0Bp2U3)8{)d1??-)8cI9!&m1C~; z{j5m`L_N6Mb(3ohQBl0YM#W%XtEeo>9Y9^tE?qU_*RRpZuC0pu8wbl@xLpG0vt1&f>L|rkud6(#A<4UMBur zS<9&bmq{oux!R`uFlp^`3~s{RdN|`_?g6zP^(s9Hkjxa5SDwz^BiBy+{>*HV2)5-ZghlL&?2MI%zDZ4>4}h(}E+yIPz{B~K33(&r(5RoQbK$1A)zr@mN^x0k zp7sO1Au)?|YK8ix(_03aW5fyQo35Zp(T>=20awpm4Fkji8y7pr*f!XCC3aP3Zs=Vh z$r~gu)`gJ~*lsV{Vq{iO0}y5<4XEVtfvB3%NI`BS3F+I-Gmz z;{*zU6bOL?g`*UR!XyDh1VQ2?2w~VSbr=!is~oTgGbgJ`s%@sHbdiNE<*iPH%BsW~TT5~h*grDpT|eGr1v zWkJIbU6OPO(gg87BaG0=r`sKdK5tX=@HAHWmh4o0$)A%z zbW<4Xvb*r7{vb^gJG)DzuJ&N+8HbnpO*eqAe51xpqC_d$}r! zc_dEkmm?wqzMa^iiM*7Qaw~aQz){koLtY8aT~|DGvVOJF(n6L~crWGt(W(L0;Fz*J zRtAxL2q3so4@pU;9Jafn(qJF>MZvsP9N9B2X0l^s@ib9lObCdyMvwDCV3Q26?{on@bE$BK1Wul9ImmjVvO?jcWrnfK&B{4FUqqfBeA=HYTFeS-utKH|`HCr|o*(}T5;-+fCfiisK31ezJQ_xJ4n*kEi z7Lq+6B3LmaG#GKNotZOrlqWL8-Q+=?q2_sw66JZqQfem_6(0-GA<8|HuD3goFYDlJ zOeO33S?sfg2u=(I-U)9Fh%jhnNUI^SJzav~g@|D3xu)zi;qBzQaP*Mm0x)XAIf*Eb zYVt)^4!89Xw{w$2hp0Bf=0h}@<#J!#Qn_o|e0dT)STlTo8G^R)6zvJj{4kM6Qcc|X zmclaUSvSla7WbJhJ-lr0GmK+>gm}#1E7QGHwR5o-GCQ6W=&QJm0%MgEl^4ORlIDdQ z%AK`*yaL7;_X#DNB(TD(uKWGa7bJ&Ael67tggz7(B-n3VyGO4 zg7@`r?OW!-P`@j^3*AsgHK7)J1iT(jr~dg6Pn9eDsdEeX!6l#) znAg+Jq8oanm{mESd6$>k+YP)mCTR63u`I}--;YPD@#O*CtF#01&9QL|Vhil{sEzP^ z=43W3`I`(CNS@s5a8>SSs+1{^DBN?4$U@2#H;Pd?1tQt|27uDit13638q4TM2-o74 zp*Y1ACf@HBWZ@MoCAWWMI9&{s*d{wa$CT)#wxq3`pqhXF+D5y;I(XQ ze}90hZD{^WD=tqbtIqkr+?hQZQ9gyKhIP>`Uv;*~fe5aO|e`4ZP#VVs6?(BCK+&&b**gM|t@bC(`h6kT?=UD`&iQ4$vRV__$ z7<5+Imr1C+ofvwz>(RYYQ|6+b2;k+vraVMOPQfK@->`h`#xd&28R4uNNlb9R z64s1U**aI3X0q-Fw91V=A5jiJ>>>ablGJanry*VMk&{cs`OXSiBVkg3aFi==hSw-J z&W3z8S&o;BCboSu%4hpj$JNrZ9+1_u;CCh-!J$QNt0BJpsqSiB(%l;$;a%@PZA6Z4 z9)FguuUEWaI|Myb3ofd-+58P~t}ucxb=>HV_1cmHF79&>h~Ccb_&&>5G`&@>LgF{{ z-VNG*2G21x%0ZC&(LW$Wzi-us|Mwfh|7Pp?f5VmjM(a8Jm#yb;`X)lur?j({X*mDneMlNDKWc{sjYBk1yqORV(+EsM1dV_E zPa%TN$&dKqZ#5Gkx`5vlk03u?c^~hFB7KvlGcmez$(|WG_qt^3BNDXOts*hU{ zCZXvx*sbhHxb`E)%K_%$9CxTcu!p8LXuv7n9%w<#$xv8M<|;3yr3_Mdu-iZ790q3Odo^&Esnx?h%CD%ZJvrw;w4Q60(L~l<=0?2(`W!DO4=zs4bwDFAI7pc2 zPmk$l-_QvkNzp@&h@Y^B}Zej2qkS;8)9?I43$O9!ZakbN?1s?}S}%iLXBFq-j>FSS;Az>dj3 zjC0REb4`CGAbWd0+G9H%29rNseX=_fV4cDcaPhhR6Y*eX8Rl=cu^&u=LFiM$wG8vm z6<+`O(C;N)zdG!PaxWZ3NP<8qf`kwR!cp*-D=ta#aSlS?sD!3;lF>v-V>ylEZ^R>r zH#Vgy4JYqy?AI$Ua7w4p8={bp-4U44(3j$Kh|WK-!J6#g@)(QrYxfzZ`#`Ae%N$?Y2L|t#%Sy8Dp6ZfboDE$7KFm%!YpT{jvJ2B8DByct0 zAl4O^N9SMsGM#-Mo+b7cgyVRu29mDuX>YMtE~}46%RDmpdIFqStanyE@s;+V;Gseo z#piw0PhLk`%@VZ5(2WcBHi#?vLS|{#EOjo6vvrmcJ-S%{dLd>%5fJ5Zm08A{Z3G5o zwQH_HH0)DZ-_F6UV~qG2a^h0N3O+#AS?`NOB4vI7RUjK-Mq?wnbIE~!A!6=PF4Q~8 z!dcI@y4nYliuVok^UH=Rsl2MCp!THdcXd^gqSXM!uzrV+(q)OC5TPHfWK*xvB{B%R zJ9X#ulQ54}R}qU8;vx5Z@pGK&bFHz}m*#SXv22YY-_O1J zDScw3RkbvMv4mgXmL&ZLw<6}AA8y(SjdZ<9xyqx`P2z?2x~jffmCx|yvPXYAwHPtC zkU_*`3%ug;NTB0IydY*=PW25JuJz-1DLRWWDTGp6A6<9>WEtuHtb=6T%M2Ds^I+@t zjNMFtAH^xR(^@Hy=rZT>f~RI6U$%0ZYB%;}gS@}eL;}}hzfhB98fw_Y`q~|Mn&Q}) z0rx}}Ih~-eW%8kJ6nV`-*2(h-!m`gR>Mvyo!DK?=(4!~CsCl?s=WCJwP+_T`VIJu2 zHJ(M%1+`u^UJGf$v|17qbAOWxn^*3|^D1+_K;b7l8Fe+?GDJe|?D<*hrhQRgz;((Z z^O41{wNSI0v)07n5sU2S>SoU-Cl`2;|7|F;o`av{&HOz*4gE_({$>2JUv2KqQsh6u z(mxpX4WfQIaSFyj0>NPd0ucfSaSTIo7zGKEfI$#JAqx8?etoQm zu#`qhx-4kq)5=wTvHAf&kyG-Hb&&ky0+jv|zo7ID9YsQ81Wn;I{ORDzsE;B^LZ>7R zCNv4XcM=~LqYR{}k3K#AyPWtt4#R1@r1MX)G=bA8_6`8CFRn)LM??&x$&a)doYKW7 zuq&vK7ZUuA96^jmp^vX0@#(Wh>9l;$=?%(%iC<#Ga~uOU-|)*T#JW@;;4FEsR$ntn zXSHF8Q!kGHtsv?nhOj#PkBDI1z(2J?4Xz-HPzuF$EOmz>Y-1X9U>sN<82VOi?27)M z4*FwlzS104){gJh1Dob5n|>&W&f9N%1A(7+YC`o>+x12NQ_I*@*jPIcs2~dLG22-U zNCIel!>(qdtNh*F-2d}I-&JK5Ua0It`$rW6)vIHy_Sx^Lz=7;#7oVJpEl)D;g=nOT0nk)9` z%%ltnQ>r@mC4wTWooZ(|srjJjL)kjpW+MT{z$_}IW|iVzhqYT0G3Q4(0$#m1ORQj7 zrCp*4UL!VsjtkhWm3~J`O#nT zf}CcFtCnDDM85cWl*?)pZ{=`%*!L${KW?{xyEathRNEdp3s9G7yrq%~7M`Wupt9K+ z+!Su5hWas|zf>;t`6M)n1Q97xKMSsmNW)GjUD&G`el-C12Hs8(abs0%m++`py)Lrgxy%mk1q(WNuxBOY8ru{(BRk}0A0vufX8ol!H*1zAu_2;5W;O7pm z0V@L%!W+SmCOalc5w=L864ze)rSTaLd{&;=77vh+H2X;oky755vl)__vk7bt@z=*w znnK9-e0!|gu}G|7Yhu?h7VBYffaWI3QS`*dIDwon}ZiPr0Q>4{MYhT); zj;9N<=iLAUWNm`eiMedB@JP+F>Jyx(Z^Mx8#B-5*{l=U8jHEbKvU6`q)@j5oYTWh% zER%IR-vHfVU9xj+1eW-*Qk#q07PYG^VQ*Mo2XUK*QqD=nq{zylri4|2nIJ|7)!3_rre6s^Fhk z6+(d!hJyr!VkCu8Fh-y#{z(B)F#g_8;V=l}B#aU;_M0ZKFXEGJ;u#`m9K9Y(I_~M3JJtUUR@MAFt1@^G(~irJ ztm@m&|HG_G`NyoPo|<51>^Ae!>TEw>*mP1S1(BQkBGz#umcZjd_FmyXr7iW;5VB@b zM_yrtN5-Kt14DI0;|cTK4}5aqf@)*&q&vZNZYc(e(n8U z^3J0BIu~9pr}8SJc%PJsNF{`VUy^R|Zq9sCvFC}}??8r0R+L1%$niUd7HxBdmq9ts zV>NeP6ZT>y`#VuVm9@9VnXl1uOTr9ivH(GyWIh1~@jxMzVNZBC1%xSvcjlob+)F=I zl`)cY_e6drc6camQ^70tV`=R~J%q%sHb>>Fi7`4n^DM%vm{= z7<-=#J}j?-|2%a*Xd2f9)*euB-pnOsaAfzRm|>Vj z&c$A!!oBuX*@knKwl(GLNCyycb98||l;;~n=_h3i80a>$WMXf1XQviUq3U#?f*|-^ zATsC#wtJ990oktljZq~a<4|^TS0DQCVpT+uzw+*Jj*RURkV%&l%P#g(y7AzDU{x2n ztays<p=KiTcw1;vwkd)cLON@f}(6$1}X5)`Z}y>h=`WYaxyUOft#IO(1T% zrG)CGN=AO&HI$EDca*y#-BIYYuZBYDs>W^7WpdYz~-)rnR6ND<8yl z^fmqALhH+6;wZ6a!`yi7DYN$Zj1s0`EA2JtH5Crvdr<6*W`R-y1m`%GqPFm(3h}H3 z4Vj@BK$Y4sSm8;2FBs+KUyN5170T{C7`d3Nw8d(*O$gmWd!Tzkcb#AAtT#8Y+hn%0 zFN{1!!o*w&G^FOVI`ZJ*%B*^iMC>Jp=Zn0XYAs2nJX{3eVD#l4dEyf5zs^+T#fp9btFc$|+0+BQ0^J zX1}=v^Kt}-bKCSaDVHK`e7=Q>sL%k}H}-eX#I~)hnk_oZSN&4>i1)I1S!nK_ zcv2LeeUih4e;jaF8@YShW!7EE<~}4S5I7TTA7I>Y$WRwjK`5S*OyaC-x112F$w1mA zo*knI?mW_;wEsG*LjG&4>i5Hb%c_u{SQU(uAO#XQ1Q8&LLnscTI6_evg~1R;ATR-= zFoX~wNx=w(k-sc3c+;MoPANLcX$+MKZ@rs-j1Izx#u5);S|8tEkUzyA>a|G=vDe`8g<#w+m8tm^yD|HG_G`^T*6*jLnw zQQ{$9ie77mtKY`wL^$LbCUIqRY~Z|g=P`TC#H7Q0IE~HroRULMPu1eO*Rwd8d{ganOkIZmZhR6Ji~q<#XZDMF*Yv(r~?YMZEjrQ`eOn zf;@ANVjy3P_R?6xVR`8YZNMXpjhF*BiIkH#d4v6s3w*d;2+u%SFS*t)Keh=pO;@27 z)Si0e%COfA#$|)6&!-HS5{Sv=+r+dacs>tR5+W{fm!aom_L|Nh3L5W`=Z%io4JlIG z)j>M3AoQ9@La=Sa21J>W+U-=Hlzf~m;(=w>lcMN~4Mi2XH0PLAV~&w8cq|PG zRH&D(if~~<9G7ng`Jrxj=do~wXgqkl0StA1iD42)7%wtCXNQGUj!vFcSg#b9#;pmj zx{$o5!g-XBRyQ%GfP*=KH5Eq9+YDsubD7UfKZ9&_u_q}?=lUwtLpC?q!$YD6&jlOG zt_)hW9vD57t|2)_EyD;$P;+g7(Rx&BinZ)DXHvafkQYgL$?D0aaw$XCKRu=)H74O| z3is=IDyM^T4Z&kW@QWHqY!A3wkumO5bF=!4ki43%DrosGN%e(^uSiBX!c$}%EIgQeY`PYsUOVkx}N4J^sT2MT{^$hjekH@ zyjj9-1PS-lwNtp(Z1MEOjdLWM1BFjVgOW`UOxC95jLp^x@#y-bR0z`)`*Y4sa z%4SVRCc&hjCspDVovy}Yaf;}jqWm5OliG3V>!m(x#@iIFTsp(Xyw?l3FaCo$qILz_ zH;_DAxMUMnDj2rkv^YLclmss4j&X)`%fdxd3)3xMmpr`r>2eCh0(c(TppU(TJ7!m@ zak^O;+1P%Dd}^dEtaTTPfAUG+zGU;-KalCDWAz{=$I$Yx<2||pAX6Wo=fH_4qLB~l zkX>B+83#w4<1z429Rep-N^}*-W4GK-RVAUFELj%WK>Kq$--i$Xw2aQS+kJ*c>G< z&R|Y0R`A}7jL@ejpDd&@@IiLc_^MI|D@M+^F`VF6dI0z`kwCEW!Sl%?84|nJ=Hq-u z0n@D_?*YMt2> zBe3i#7G0`OEL(%QK4mwQvaL$$4?;0qZ}4dlrz5b=QRsPm;GI0Tc5IVEsDq49)Ntn^ z7F^+LzbvkN6RaZ?9Kss>ZB)fqMa5;q^obeA=a8kJB>pq(Iepe${PL~TC7*QX|IYLL zKWSA|Nj6OXlib@Mu-1P)*k97iKOg8j<|c-a7=n@z4w5JcLkNYCIEsJ>g2Nz5p%jRr z5cLuIdIKi%jlSM^2BBe;CSe-Kc8z9&MvymP%Ck2RB6FHbKSW;JMIE$3Zf~5#vmF?X(ay%`XbUde9B@v#`i88gr;(uOlS&y-}!z3 zMWfmKf;^-1h$bi++q-HYbhmqi=^Uj|YX5`La85_NF(jPR2}G0Fuh19Y)Evij_*e90 zaG09tQ-FnszLSU}KVSoBebh3@vkmZr^`q--f~&IXXKqQUs^+QbB1dbI&L}JotG~fP z7hz!$U{`d1U*zoT% z&iYQ}lxCG@zO>#HvuX>_U!T=%^CQ>hkEi|ZtbuE zE8RAGJDl#B>RJrY;gDm*?is#_428b8LeDyj3qQ&Eh!N;WOy~G}m(DiC^FZ52}*C!mdFNV^u!6jdBkJIuBTKT;3 z+KdNJAgJ}HSjdPe4qai~$sRPGSzH|1%aYusygcEQS&ztgxen;DMP|KQAJxI^8vC?& zmjJ(VH~f(4@(mvcU|CzA!3Wm5{`%CW;)OSdmm5LN7In}+Ff`YP>(=^J0t^r9Wjuw1 zj3moCe1Sc3%J?FU!l=5nx2JwuFD)JW9&Xm}dMWxrv6$|G*hgWN zQKU~T*TnhBH45f{KWBmRkUCdq`cvk*HI?vWcMz}_f}32q+$G> z)Y4?%5Fpw4aHv=omfi8B&U;K_B?RrJ1Hjcf080DMu!r~?-y4#m7^vr>`3s8 z!WPA&yw&>EFnDJBoLPYXCLz8v3-I40#CK)^%uW5*3GqE^;NML9+gStuX4>yrr@L55 z@&G=+Rf%N_XDAGVkqWJ17$d}pbu>@@w8h2IyFRti&3cmqMKQm;xFcz#@&O7OIS0ZH z&9QWjP5*Y;)X?U7So4ib_;9<7X$H8l?s{#PN_Fc_FE!wGCe7WnKX4vVPHqUJ^y79W4uSL7OaU6yev@zht@8%^N1JL5O97EQjvU^2@?^y50nUT!$2t8DLr8 zIQ2Zk&XJihPpY#%PGS#c>#DI)=}$FQS`$An(lQ2jM6zp$2pzucJ2he z--Od7NE65#{ew82LUfYsCUE(?T8Pk}1kfaYkC?=>(y%eaAQ1%L{bh?u7|DMc*M6i*{$Wn8xy71yH`;tBUBa0LpB`f;|%R z5pjfavX-;a;n;_bWNi7rRaG$a`LAe{ejAN`R5m&TYW-!ycVp0eDVPABXWB$C&tAA4t>u8`^mb7wV)lS@jv`ML!zp~4oc>S(9yxo8g}er}~?po)WI z053^zxY6vCYq*K5L7835my0D!wy6y>CGtur-{S|-sotWZYG3}aZ3+DDzGeBtwxwOk zj>J|jfIYP*RvhueaI**_@aygN;lAZ=0d!(JMK)jjt*r6woZ@W~08r3SSJk^%-LZd7 z;~-Lp*+(=)sU=$v#Ll=IHFS`LIrbZzFcXRUE%+8rT8>Z-=9D=EF^t8y1Ev{rNhZF>m!%1%=@g)!yGmX+4PQy8TUW(y zj3X(Z1W2BN{H=U7DMZ0Uy=sdHc^-ZV!xrB(J8uAW_=BG6kF(8h0{>slO)?wl~3CW&{ZLUzsYl-j+vNg7FM1f{9$ zC%F%S_HqS(r`>$-mPR2OA?bv8|D7W=mA&VTz`Ml@LL=197>j6#d`}qMwawqv4n-5m zJ8LHto#ix6ywhmV-_LvM z#$>>MllR_f5BP8L-aG99e~|Y!^&HFs6P(}iaH~O%F#-`#P(ffgi4O`!K%zW+q7Rfi zj+cBrTjT{lBu91g%?GLJL$>r!5|n+IR5ybo`qG2M6Oi}l)E#g=m}j40(wRyQ!sW*C zon9Ob4hLw@wt=$p(1L0w&mFn1z>aZUU`51LK&RA>Rl&9@UEbm?mHdi7mh5E?%lhe zj~aefGhqAi0kP9`^W9=0%HOdPPu`K3*uy1}@79$t9mRA`?6nQ}4ysz*}D=YOmj=6B6d{cqI_!hHVA zm8$$Un*G(-`^~0{@h6)u)&JI}%kNM5J>x$ik{q#~-69PqFcDI&JX5Ks+eWBLCtHLp z*~ki1QyI=rq3<^+cpy=oLrtaos9=~jQrSyhq3F{wLDvxc=T9%v3N+z zfu%>?-p3Ce-uPnExXFXM-w>V~haPIZep7qf6a>S#Ob3pfGXd)iBKFVK#h7EF;$2|1 zm^4^#)An34d#vmOCzkDI4{Q=%$TiNC!a{=Lh6*hJEqj+1!*CHyM8}ZOtNwa^zDNLc{5XtBw_^Aa?{fEsdM_C@a-BdDRp5PUIlV#JEAdHIU-*1(Mbcq$>nWWu#!=JFiNj$(Oo ztUJ2Xi0AZzw!h*Tp0+ zzGte)ignjRhPMiu@F4kPL8ktPNOGA<*oXW0g8GXr#4~=X7zwGvQ*m`i3K=>cJBGc| z#+{srv&xId8&(>GopaE)Z6s$Ma0J-Pc6gXJfQw*0a`v5hDiT z@!rQ)H{dlA+g<|X;zNNR658e(S{+Rdte6W@*w0#?&V?^&Gi$8G#)g*%Q6#zSVW)>5 zW3my4krtgF5ir()lNIqQUv9GC@;-Mtp_Ts-Bv|B>%&WIZDvUHYyOSN_Ra91s?b~d- zI)b=dZAt?YPCxO&kQC`fReMX|jY4jge2l9y%BqI)eD%Pyp&x8eKN>=C=w5SUFiylN%Gl|dy1Dp05l)w@K7g$R z3`gB+<7mTL;R@az27{OgW1ntkw&gQimzEHi^Ydu%AjQS%O?l}Uf2jMVPfAUGI1q3Q zn)D^P)!DvScW!csu=nTmg$pVfPUxhZP?DXh%ykYGTzOFZI@OMJs4h+ol`>zN2%M4{7zu+Ef`BB2LI{pv zFiH{#L?O^_L-jY<2E}if74HX1C`co_LJEYwf1vi7Gub7!@|4aJ8X`X?kmPiRy^#@$ z(h>OvN)Sb(FpYq8p3^8nQ~BPsPSO-X$MGB85fM!$bo^7;2JemT(EI5bw#$F*E$r|v z6Z?7dmjGHorN78&kf2fgJ@a^1uP3tipWX*q37___QmY~hx!p(lc& zFBP^YJ_ERH62xqh`m=aFu-~|-X9pI?u%*_J7b2A{zJe&z04dD|&FfB{{f7JdRk;gz z7n#ycyV?#V*eh!}pimg!c#x#0<`q{goBHNGM&v#{-@d>+<_+mE;Em^gzY8KCamts@Kop8+c(2N);i6rq8Y>b} znGRT{J&#&-$7JaS-?SkZN*6e01N%CyaCKDmIvj2-y!35eq887JP=u7cy@ZnnXG|J+FE2~a}7*(Sd9)$4HUxr6^>HBqz!O%P{r4}jC#0FO6K2!ir zlS9uA_se_*hgL`hc6{{GgfBTN_Rli|jrE~>;8%sXQ*B-c$=n2Hi?`j?_GLw8!UCx)&sl^c6~xn7&xGN8WQsOQ0vpBa0# zLWvUZGP9{mxI6=#Fr{Z?FJlv*sYeMBIT{_#1-hEA7a^b&l!NO9u)wfB77S>dd3Gk+ z5{beYEv(Imx4w|ik5FE4)ROo|xIE(-YixKumk_bV4<1V+F9r;~w8tt-t)XMm^`srq zd_{&;C6+v&z}p4P<)_Mw5r4yA!aS2y)_7wF9~T%@Zs^(opvuAL7{%@0svsB}IZ{#b z>%AaJ`-UZ;_E4YZZ4k*aTOsk(wEX?jZ3!V=qR`COGYe?0F0!{i?QoblLDcUvj2%lb zKP$BUGpw`A?9+a&=~(tBEt}^1aQgut{u{U0eu@7+~9Mfd}25_IL z$zb{hgAq)p;2RI(35`K?PS9XRXS?ET8hz<2BY$=*k`Xk8&Cw$E7$*BQZ^&G?maKwV%+SbPT;e!P7UKOb|Ln=_IDpUvjEMq<-VX zZzusdG^y9MUYpbXL@YPHcKFNBaANgCi9i)ZSU&Pi?3+d_MOa)XIyr^wYNFGamg{PcBw$T?PG3noE|;1a|H6r~>)NI( ze^qDwBdqwjPwW?1@t>9n{LVW6X_>(9tn;6i3H;MKe+MrDUjQQ`w2rS81P{;E1}cls z`|-3{xos{$j%bIzwqR9gq6KhLOu9h5=VYBy5pzJHpgzNRxK35Q#^We3ihVLy71V zu%@1{_ARvAO)DtOIyhTqB;a*ZN6iKZ>iIZ!rXD5fP@gy(8SOK#9ZU5=sJCr0GuiE` z14_9sR0U7B>uEl2vK0<0j3DtX$AJXAHhFxZ_Ybl1-(;!t){=d;WHX4JE@DS#A7ni)OF)%ZT4D zWrscsyGxe1m^5`fK=F|x8X&>vT3U3oq6Y6l5#chZSPgcXR zm&2zaLh5jG8fzKVd; zA1?>>5V9Q^!#CCKFqCuM%oDGob>*^i!`0JyyR#ZD!$(mwX32_|cG92sxwLUb2V74v zN%-c%msLVZ>%kq7*F$eEu5~|2C&5DIEjI6_1#Q$LFJ2#{A(JXXqv zuLm8R8Zj_@wt)}#v{SAXI>Q4&YHWfnbr!YpLXCYVR!dqN1tO`WmzY3htcd_FtEL@D z$UoK8P#1icm`(fro|UPve46VHQocAI)$! zm*AsUWVEhdR3gK#aukjmdqA1XWQHX#WPwg#sQbkX?_Cgdf}rI?oJv;UCnq2UY&ANYU*F$ zMSr%AtwAXb;xviS@Xk(wQ96M>J`moynMt%$;$b?)cFpE|_hyP| zoS@P4jW_e%+y6akLQ}gvWe)xXF`_x0qcje_$3o*B1mZi;%->VZ_qI6*rZbR6!QJ&> z*Re$QZ_%Bi8mDiNN#gHo@Q6+mI)&+I$Eig0E5yjv8^z$noG)!#;oZ?O2woyA{)V&Hey`A^FPerKKk zv`pY<>-@^|{|U`M8bmXC<=F1_&2o|2hGI=nVg&*W`^Jl@&dHOST-@s9$JwYlN&V2}{LIWc@11+sqxAo5r7=a%h7?0Zzzp}G- zXLz<@Y6cE*!Q-^;*32w>cJKr0sVuN<&xcWpx4R5Gx*?gFyAbERzdbY5GY0)wjgq|R z+ii3}PBr*mX~lCb%8CV|L2`{fz|_Jg73g^ER+OwYo}~}3MUhWMP(JiqY(BzCTfK7x zx{x20#qU!cKXVGLs^~uH-~Ge+_FwP#`Bhfs|9mpB9|HEj9^`AJ{)el+_Z%ijjG$nU zq9_W)KmvwwoCI--1R)5+K?)@(1cK2IBQ&*#WF&sq${XWamvnyYvbSe(^Mp_Mn-jG?u@sYb4rFa40&8eiEUf{k$mN zPoc<&Mp8NjX)xcs9d*$;Pq*YuI~m-SvCHZsZu&nM(#T$d?H-YD>C{*k3NJG^iMRPKxI-lE1|9ef?Q z>Eh~h5c!YE9WzOy1gWMv3&vM&VSfg`_@3C2mp;Gwl7D~s-FGbN^R}?6wy>z%=a{OB zcOT$wb*DM%HnXX=F>BC$pW5%v4EWj9es^ZTNA$&S*^4IV=*?@Q{P@`GsZbtd@-j^> zaqcDD5^o7Wo}}fHu()zXqaIqfXX-R*_3dBS9{Jd1`!!yG*v;Rx+OYt0}s)UFrS@-FVw761le zsa-tzPMlyRVr01zA3-6_Nvc3Kv_15Lh;o5kJuTEgkBrjYHbQpp>gA`uP$)QCN$ zG5q~pDyB2^9p*BSCSy9u-@rEo_aKh46YElf?*iOaq3mDp!bi=N4?%Wt9(RJv{aV)dX6hwp4r5Wxu(7b zs#Y?~UxUVi$>GU;0-xPHjKYAaDfZkofSYf)(7TZN7XWFzu_CP6#iG{I_8C7KGw|Jq zHLLvTjDR1f^gA>96NX{uuw8b=ZWP38C(@(LAW+tabGU|Rla^Xz1Bfx-;WVF*IPMyV z5*}hV&82}gp2FgsZL=^Satp`u0bZ*?fwHnCHZHj5Uae5~=hFcWS($Lp?bvF{D~WZ` z!6>~v9IV#`8SPD)D`E8gCKnv?0yBN4!Jag{RwEDYNInxq4_IJ>US+MQxC_~)cX(Bm z3gQ-rIVDis=|`ri=UzjaQIXng9188>gyPGmro-WR1$hXF-Mes1P;jm6B<0lDw^dtc z5P`9LSk*wz503@pWYnaO@jaeoE3I;GzHHUgxZQNK0&MWe4(O<-Y<35IMT)vRYb7ga zcHK!N&QZ&vXD{y|DR3JkWWDY69D0vS7a75vfx7^&Ajj%;thq{q^<%Q3$&Df54zut} zVGqmUwzUF#Ooil399U>*#%ME7>b7c`D_cgb0Pc9B4l^0#!AQ*Jm9vARY|kiyn}?Eb zhdii=i)MsoW^Iye*Wlsy>?(Inz^AI|L8t)fd2_uW=dK{C`r-w==BZV@&W}63QI>5) z%2i`4{%#Y`Iy+*w)F*}u&Jyd>Ws8|V+dy*gU#|y0sq+NBDyCRY=}0mKpEVwngQ4C$ za`0ReB{dZ?YHK$IzWQo|=ZAzPc%*y*4YAtot4)NSMYB717SnWn*OlqHTAokwnJ^Y^ z;~XBT8gbmtbFzU{!#x%b6!iNQ(}3#a4w)uF0~75O70O(lY+kx5-LAJD!m&H2pBzT4UzZ9y zIFO=F&3p#%dxf{bWHegF6&h7?24@cj=wKtkl6B@}7dG!MdX*5>l?_#N3&6v8sfk%V zEaY>ZfQ$K33FQ%ucwZFdIO(J=T-{7*N<2y9+E!Jl;3VAuQOqG7sGUU!WI(Pa?(ShO zDFo=4_&!HT;Jb=TBwZ?p*mQVw(|x;xpx6-b6EeunI}+LG*!KAxT%;Eu-=<|l+B!N$DPhITN{^L@I2j9P;ALwHyc*1*eEKr6@3v*)3NMqd(5^9J@dz|61F zPwpGxT_`h2ULLgscZtEU*We#Z)#;xg)d)S8YBrxj&9(*9>D4$WaUAY9`|pq(Iy(J)M>yWJZMzN^J}w~!~IHw4Qd8ct|pFKa1`CUZJP-xET}ccBXZvTzeiZk*{$MJQ%j=O1c>=cs((UR38Zf7`bJs6 z8)kj?Va;lPGArPtY5nf3-bm|bYEnNUEm-PpvKOisE~EqZ8oTsquUGU=0NL$6s@6lT zW3Hb!ad@0lxa1;ukVK9*>cMp@B70S2=p*a>1YaIP-UnTf2^lJh+Gzz$HU{yD$Ilg& z!Q`|V5l%7}R#8B19dv=PNNMUat85Q*q?g3ZU9JYk84!ydl1XhWAWp~gdOtwkk>g45 zc)mowG$c<~QjA3r)4+RL+6j9MT>+|Oao==H!ni(pl8}Zx9a993fql^`j`b`!ieX5y zPG`l|C>x9@>m^wEW2J@yxxCVVkJws`{iKcpGSs$cY1ITV0i?#y0w0&p$ixYlHOBF! z^i5o7_+ijk6_c|93!heyJ?>U3FJX8O4nuyL*BU+X$ZG}!XGHFTIc4PYUZ2k(6nmyN zZnKyK1JVfo7^bSj!%O2fB%9U7blJ;_Yk3*`v-phBN4;8g+rmt8g32D2 z`FTVe(Z1u;nq4iAbk=x+q7i$HE@O+kiD#F)J&U!>&#F>A5XonlNH??fg4QaP zQ}@u+%_Vm+IEcS;;3;5ZV1d5!CZmK$C z>f$66heo~*Gk!Hi<$E_Q;6L5<63YlVju?+w2nBR-pp-f|dIK3@ajVX*v_3+)3%nOD zF^L=WVY^6>Q3DfvPbD#L7*A$JN|j;6zr>AYq&XUOsG!Uf;!|^Hc!=a;EGkDexRL8A z!bWrUhIhe;p z#YA#J0d~YI#>ux5WP>W|rZo03xUSlCnuLeUc3~N-K7o|ahg+Kxbv+9QXq9~`9er&E z&*TYc=2lPwwmj#3c0}~?uIuuXT^2EkGu0<8L>H$PKX$lGL7A`)X8nw|ffP?7q>1+I z0d3hBto&HpmTD?U&aYx2D4frPt+3=nSETVRdPrw4DYI=c)I~EzG*d1GZgXmm@;TsX zB>Ai|54|&Boaq4w8{Ht32j!e5OXZewUWxq4#}{6D^Min_h%#`5N^b$XEnnn2XNwDYLQwmb6VTm%E^f&Hr^rbAV{`#(j9maEYdgydRkCko-2%61wR#Ic`TeKRGr1KcA&{ zzFhnN`y_SA|9sM&|7&I0r+J?LC;R-x|8&`OY_cM1{?C*R?RfnEB>&$}FbGngzQ6PT ze9G^`r|9$WTb6!$j@hSs*Q`Gvx&OD#?JH9J?RkBFOpM|bNg>#WcD!gzXE2>myLc#0 zt|A#t_h+h!KWQ?U3C#_ z#$mt6!Sjy$Og}@aQ4*SGu%e5?GwoMhf-|Hwq4lM|*26&H^T{Um41MDjpWH6+<|#e7 zYwW9wZZpW&8&$5X6^mI_p1~yHKMw)EJf*l;Y#Sp|5%?|`ov1bP`zGXAD1n_KhOsfT zh4;<-)R{%?O%DU#4+ql!?5QM??Lumi3{`(92=zRfy^1?oPU%;Qdu#ess@Fy?qqxS{;(+m3@uVdhg*)d*T z!WG6)H99CEZZm9;#1D0-T*Dk>xD|Epe7PQ95tqf(78rrjTX`@-M;kC5G)bmVS6}j4 z6-T64IwQJs3?n$%sODWeke0h9$sI0U+&!bBcGUgW-_GaUg(Ob{67B?!+oh}Ui(A$= zZj5WoB#GPVbb^lO*#R;smmp^RL~vOw;T+^wj$C+ZsU;Vr^nf{0obf0}7?(xeYWvG` zGuqYTP;%oI!53>e#o2az2;rgUT1?X6V+^rEXuPs3OB^A<0l|?URh) zLw?8N5qz=jW#|_ZBhtg<>WjKwnmD26D?8w5KXudn3IcWHy@K1Kp<*?LykRlN3a&%5 zmKAgP>UI2CV(;%wxorJ2Nu}>3_RL38g*eC(uRKeL$UQr;1m`zaZXX+?0Y4LB%|bG5 z#t6=AvZ{mJE@xE;PW{kUSXlY0IS5yiGOtIVwr|6HRVW+b)Q5F^h@^3GWx_dOQJ`+? zeejfuIY)!%HBYvL4$Gwx>acnVlUc&^Jp{~KzTwBTo*hOs6yKVT7Sz_!@e!18#h5P3 zJ(Ch4BW+s_m&l1=&654`K@B`K!YB9zK)D9@WL(4<(yM5QzxfcbiujgrPg*frKao#8C=@Pzb^y z1VQi*CDdblmv>5c78yw=*nSeYv(k|Goz%0GrpTSvkkWDTac2War{o)mpx_%+Q1KVz zKL~#RfJ8I|(OE?21dUNN8PQoxLns|%H2O2MWe|Qp4t(RGecueF(}+ef8p3HTp)s7s zi8q`gc9I&t>#C;&oyYI5a`1gu6u%dR>^9Ib_`Wj3Xgqt*FaM>4I(M)+j=BHU0jn`e zbjhsSzE$ODoO!VS&QW`Paoh*~DeL}D(gpr0>;7}n71nps{V}!w4ocZnUig}HAHY9l z-Jd31M_s=1GJwyfgaV}2&ZaeYpSM-y>t~w1e>N8}`GMS2FpEsU1D|;pkQjHLx6v-2 z<))shRm^hnRWgOLL(eHvBt}+Hi3#71yrS!M1gj{CfJmQi^IP8juMaOz3KVBO^a zlOmI$(L<34U*|JYzLt{%8oHEbmR3cUl7ev-d*>JP@`))us>d5~JU+U%pQYKuIv*(Q ziqIX1#x}C}KlkokcY{I`Cv!m8(!XgXkE4 z2V8jH^e6U10tDQhE70A2B7WDNBt#?NhY28q>6qNlE#fa!kSKoFitmI1?=~9vJEug+ zP9-L3gxWQ0QJO@4Mhi*yPPAQy3f=P)mc0`IhQ6l-}&Vzyo$I%qsV} z&7Ujg&Vb84ZiT{Zn`hu*b>xZTKSfmFGkf)QgTwYvQEVg2_h{%VH6ucr8`83OMq{!Rng=fex$_q~@U@MO-qoy$5P z0*nSRw%k(}O$5JzqhD0wB8V5?@yuBqWjAtQUG(7mHP7+<TRbRc%mY*5fPd>Ytn0mmlynsDD@^w3-ov_aM>Tv8=>&7sgmx7NUyV}`?%a;z%kTs zuEeU&WLl3ElM#&9p5ozfrSNjSfd$0*_mXSui8x8;;}M5@F6SP%$*>O#X%;;|lwo+` zP5JaFP7q#6V4IEv*o0_YPS+tuNLbm-4G?&yJ zy~Ndb*~SZ~enituZIAp(dO%HZn6o<1yqiNTTU-)wZtAJ-dx%z@oMHmXWj-AcE0Ba{ zBN^X15vSr#BysZpXYN0i97Wr10d&q))SR<7-bVZbybuBjZ)SKSjD#>kSARleWp`C| z_TOD!d^^sWRH#UJL1g6ntjDaijI$aiZHzPx98POnV>JYxD{z)y$JS+v+lCUVvRr_e z!4R>qg$c5^sK!n05(j=i`|?2Zij6#yo+f-Qx|XXVmb779CwO}f`PBfg{_8$WK&;VP z>APgAE6M00lcx{&lRL`_b>@hkmqmZdje>{HRGku>wbqu}UYSAb>|+^sMhQ55sB{v^ zlq8(_>d;o%=@41?)I5@6dL&hW50YxRx9q}!{ZYt7fqK>r5#P)8cz6^ZaM3PPOY6CD z8F0`n&p6Fz8h)|7Zahx+%5^sa*SnM{dj^ItOEr~VIR|3WlnWst)dHkGXS$U@tgdvV zFtvzYG7b@;+;T(PIIwk|0m=a;Gkhb ztN34~BXJ0yAiFUI$|tA$Nm|zU&WD==Zhs-0{n6+EI3ZBxZW$|j$;+nmF9k2%&{;~? zOWxblWv+Q>In>*W$XA7Uy%6j=Gj5H-%Oj}Ii38*fG`Y`Ih$szK8s>T`8$r36Xae%=U!zepgF%Lw-dG-m)xCsf#YY-kdPbWf_v|# z*THlWY&)28C3fC93r}a#?7^}L1D?Wpg|`98E(Z>R78eb)aA7txT}UB?^ID;>iN z=tGf+`BL?gJPDvt`{7FqBDbp!_z}8qz=b%JuM$q^7Z;BST?f|UESoDkxne6l81=8G zbfrhvl-ftB76C7gqTZ^A*e3WbLm1$xJ`BlXob5?&G8GLOGM0$Gs60s_=bAhlRAF-N zBx*sfpQHRzwj=K5{&C=&K0YuRAk-8!!0GuChfV$n`6mvk!N^Rd9D{XjlR9`Wa7VTJ z{woeY5Jw(O)<+eH+3{wCFA+f8V7oz;hC%;9#xm6%R9qfmXT zDWwJ(#5KG`j%rI%W}a?204;=njt}Y!A#=sI6v-HZYm&;Pww=1@$PnZyje-pTG=l}Wq+1dSmvOLUv_5r1&J{!izUsSCAYm0uuvwv9dXZIJ1 zB58slNQ5M48b@#(MG=BQDViZkihwDCBFHa?P~u&5G+|g0VNrVbex+Encqj1*%woiD z-2$@=^G=$PuRYP=;*F+ocvk?W*=$E*WV}= zQ`&^h{?U9tR?M@HWH;l7sAiHyZF4|j|J@yMQ7kg zNoTX>Mbr6kGcZKyo%KHrhg-kf*S^lq=P_y3UvjJ~@DupizSdB6>w7}Cr`cIxdq!)c z9--Uns&b#{b$hWr!?kQ)0TRrcBjq!ZeSc=Q6!oq@luj_%4!q3-gd zQtc%aVY2WS$ATnY?)U8K_b9A6f2xllLK_=|sPxGv|R|Y(2rW>BM;9$=7h2BEBaF%Sr zC{P*$;|k1FCNy1-B8M<5ZfHNtx#s%WhA{RpA3fJR=pr+ZFbUy<*{4u%>&asbnUXgT zjzC-hhH*8yM49NSV?}L$$n%^c7*Cf6KE^t@zqdS)cpb#^tqT>ixMA|+#C5N*qO_N0Bx6|t zsaFR@jAOD!g9Mbvc#olJR7bpa6SG6z;BZ@A`m^ptP6-AFX{y4ri-uI3=Q&5cIh7wJ7I4Au{*h_F&}lGPHEvJz^Ix6MvCaM<+;jD z2(kH*2lNel()0P^8n^y<3t_>eu;;|JJ&ugw;o$TNS@Zh8ui4uXC#%*+DMH}TZ|DEf z#<&^Q_?!Al;&0aQYU}is_x1ab{eQXt`%CcrPpt)noFXZNCK&`r z5elU!495wY!f2AhF^r-Jf<_qQL`1IiBkrlKK|jFL z7W%g(L#5IVZgpt$c7oj=v2Tz-K>G zkMC|idyI3gD`33Lm;U;&HTXREc}$mowKd@NAHtR<^2`ZHJNdppfz*;=C%vOBnJ8_O zcitTP3>MnFbGk~iZk4NCeil6#$G^&o?WrZ;UYUz0yhHQ9>pg#OJ!6YVn0IM00P_@_ z!#wx5(XP;Ptsj>=l4Bv4;p^#zp+ogpJ2yAWOX%uI+cX4Z-jyR3!!h1b^W*^7#Ws=3 z(8ME0uaFbN18!WKF?}Ql=xk8pTq8w!x(bVX&y*E}SNg<9>m|eZIlUz36~Ia^zl+vk zCdLseAMWDB5?aFL0^O30y!xsJ6X6+OvLxwS;ze8*1ay4HIDw!l`XdQog~TMa&%h> zKij+UoGAi(Rr{yjvpLK6R#Q&F>2>iI_o6oeRAmJDTDLC%BkPpe&eDQpf46L_rMqMJxk z!(}a7kGULc+EQ`joSErmAr@=mv75v>;MNHjV7PAhm_pT+gN(5p4?!?vu5oh1V)W!} z33@!Uyz|`R;Bu^Du2sc?Y96?5s7`fJl?}*XLcE1lQFVEB$zwQB6!bDJ;IuXJQ0DWL zj#^_6HboTE+6dRpzL6kg80vG5^p{-%r^UYsFUSq@!=*YxwUQo-dJ4XFa4Lb`~Qdc`J=r5_xJdz z+K)37!@w|%P$-OJGzK#aPGS^^V+2JYD8Z1-*S+8m1vn;WGloTp-Li*fQH&*$J^R90 zDr1p+w~tHM;_FGZccj`0pjiHnS4qL*>F!ZMvvI*9@H?9;;&)<+lJCg)K0jqKm}Stv ziHyl^oLB4};VgbHL{Th}zON*AWxIl8v2-`6*aI-Or@jTg8(r*n;7Ppu0>$q%7{=aF zJ|Wo*erJ#HKQiKF_#GLkKO&>4W{GKE=~kq#n*nY2pwbNTFDiHNhss?k{xvG94Of2l zgcZ-5E|xFg?6|03l^4C?V55;% zT@2T=s1t@0#k#6+zhuXzBmR&DS9%0^K5@%C4^B4TjeKKBI_8m}*)0n6(%lID)JVN9 zxSwfr{>PJk?>_*4+kp7lj&y$?nGcsA>aW^&0C9z6hq zHL0H-pkUp5I|>#J=C13lINU%oIp*LXltNH>_j{kMw=Gu@9-LOk9sM;i{8^KE;Cx&x z@FhbH$QO7bK_ZU(wl4dS(@4rtGp10tnZH`26d$ttZ8IkZx7*gLT|HUMZyS5fW1HkG@c8R z>2my7Hk1~P*)zPO^fsNJ+qGhzN{Zl7*j2Iz+GcsxD052IFc=AxV6bu~)h&br z%kCn*cLhDiZ^uV9a&wG?R}V6tUaX?^5fQ1}sq>YVIDL`eV1v;bcswbSZ^w+eT`nHx zM@(^7lrF;`6zD^ZlP-B?d$a!{0*^vq#p1JP7UySAbk78&o_*jPc~qkEvGX*x=aey8 zaFga%yK0liTjjNcYOS2w$J!*@Q8a=ez0?PH!D5PhTBkC90nS31LUvmzq9MIGno!CM zZ06OT1lQY+_?$}=j^4Jss$ZH1=`oSkcKy5yZ9j^O%-KMkm1qANpU(561MACi8U=p2 zs@(0;_)x>mPv)pFvwzMCYA`}qjQ_*O_Mz6j_Ton6P`;G z^4L8?0)wW1aK`}tI$UR?gJ%-l<6K^FQd=&g3-VhBJHr`r{z}OJc23668G!KzqvD{n z;)A-92@RbM|L8wVAuJ~SX_>((oGvc=I1$xfUmeOMbZ% zF>$$mnbhckpJX;06)Hv|KxoD zKfaLvjn`d@bhg(VB!sIEBsq><7&l z>C*!wFPs_W2n^sh*cTez8>h#uh-UP)_9~I-8l+Zj6qp)z(9=LixQF#}r@_`8S-iw5 zIruRp9AQ!bh9=15i&;R_5ktasxpxF}6pH@&cyz=ZfYF*YsN@=$bBiLU4fC58r45=^ zGO4Ob;{lBDqS1i29jwL|XB}(851Hg*#X4Qe2SN{IsIS2QF+wRanA8$ZS+`7v_8N?U z6Gss!i!#^<6%8__K@V<%hmW4@Z>m`!vSP;5k!a6rz#p*0FG^3hiA2$D8Gf42qG|Mq z1VSP@X%2s`B%)S4oPOPM^A^xNNnjE63=a4(8nYK!m|cVc`oX3;f%enIHR8spa*X-W->}%Yby^ za7DRiG$vg=?(w%XGu*+a63;r_D?YRuXA7s)H(FQ)g2{VqYR*goq0r3%FU~h%ige%0 zwo2r+676JAM5-`Ft?da`ax-l=x(=ad-{}ueR{IZ zzIb=sqemXrM70l&@*4FF((vm=9-dGeL(4D$%n3R&uA97?($tz<%i}YQukE7>V+X=J z|A^ImgBFd|TW&L5jW|DQjD)}(1a29KdO$=J*GKA)3pzBUVY~R%9Kwfn!WS{b>vmLn z9y}_Flf$&A*REmN=Gcyw5|4}~KzR%_wDM3MUQeSm3@^7=h`$zj6o#7=-of+3rVbiR zLFHHsPkU8o$-7*a%WQae$A9>vLCG%{aQ)zfj{maY_fNHJYIUQi#h=&LZ9!4N#NNHf9?Gc%8_dd71?L%Rif zxr+DYdQsw|N<~e7(14t(6?D`tor7o63fodnxpzps$w4R(XR)}~T<)Wa97)3MdQ6Sc zyV!n(9^z66B42}nrDN_l$bFbIyp2g%^&?6DKY_BJ8l3+vDEXhl+5h%){3nq1muL7# zSW6?jCkW0W)b0k1vIW8B$Q#+h8H*!tK#MbPgjwWlUVI5_nSw14mO@xMd!LvQZ!}u$ zp1>5o+sff=lD>f_jk6^E#+ym}M!DqQ!CL%-e?#nI&M}J;Y)-O7%u*Pe#wCd2{nzt z-@kyg;s@RD_aNM_2oCsN2xp1B@QL8gaMc383*kNyoaGv#Djydh!K{ypt0*DgNi&Ep zrmOLiR{fPe^_??guDTe$bn%a4YZ(uFFBAB4m?yJ!b07T_J<~i$Ys6Tn!0$Zvhu!ec#aBRg&DH#@zP=_k@}G~$CvM@!^C2oLFU*^=#@e9+8Z64^S$J**W^I)*4+?*ofq?k5*+mUTFc~<7xO`jF>64; zwdlx6=l--@#RY{xA}z1P_5KSlM);E#Q=H{a#fST|w&MH-w6?=3b)M?Y!mWl+-tz+I zCBvz5!d5dfV{Bi%+=$TLpdfncXVp|!K9>PI3czvKqrhPgn?$bi*7R9Q$WfqH zGX1Dclhh@m#Jkp-I(n>&^C0+wX8r3RquQ48G2$5P+FbpVk9|IUv-5P`35oFp6UYj3XoilL&%-xsSuU(tW|O zIm~7sD$y95Gi;u*G|A!_8xy;fD$M2-i+^37NMkn1_9+d9jrVaAGG;M^El?K8cCIAJ zVg#G+1rR17PD!wI}H$Qyw6+aG#g`V z3ct7h9AS}|rHl7QpXV%0ypJatn-wffv*|yUC*=6Ok0XDSCoE1?%@-xw=GllWNQ!g zM~a^|Itx24S-?GIhjTuohbXmeB)oN(*?#U8z&ekMYS1XBRJJTpPkY(C2 zMHlcqJiAQ>0oc*$`Pv{@&=(J?fuu#My6eK%L-dT@TNicPrD&e(Lc%w-OkRX8cBMwu zHV$H4K)L`&K#oOZbmx|h3zqnJrL_dtXV`6nM&;pY8WvcrjeIp$)tV5x;b?FGXDqul zcktl@4y~OfcLHDQGC-7vofdn`;jwghwG|J7!EIfMd-|2)FA-IBkaRM%Mg)%oDqGln zI{-Z4z#(>coaW==6E%;AZE76aM>f;cRXGyGG+(=#?w%QE;wF`&mT;Dr8Dq!>dxEY2 z@I-wv%Gx796>Ccv%_52td+m9MW}1WABcIhgX8N!;MLZd=e0Fm+k!cDff$hV~T>y>G z9`LQpDQ8S$D!M3)Kf7~45YaTX8olRLn1)g^upoLhOW z09-($znVEO0?>a>Un)q6c`o$xx{nQ}FgVbDc0KKOhgCF_{1!2Pf( zXE+{g;jUtbIL=18i0>|=gwS}t7+363j-ojX5L6_17!wgi3cUkK0up6&VTC+YG9wHnt&;X`>S`C)G=mdq<5jkbs|0kUH6+ z1`~H~xyzgESA}efZ9l$dJ|dIxDCeNkhoDqmk}DZ0CV=sI5>}H;E3pUn&t;tlih4qq zjfv+Yq}(2QJwpKkcFR!n=LJFo=zg^y^}|Zf4Wwy+Ax|NCS^3SgiCIYWdMIDDyH1t3 z2^dKF-s+R5(}F!u#ldN2VQCJk+8eLybP!6-B!IKUy;S_DUyh*iX#Mbz;J0d6>yDu6 z_%#LR;kY{4dVJ#jNhmWTIagWp=$F@hIn0zh0?sw??TPDNXK&le>VAuYMvf2I?Tj5y zGT4F;_|Q0YUZ#wiLF1VdoDZ*AZnXw&teF5b#zksxFRx47JAQQIQmSW1ydGYU=iw%6 zo<`kqki={qF&M%^j3o1`N16!<7;(p!mjc69V?2)ajdM1M?OcF}kmmkVK@!t@5Yb%R z9(vo{akqvcq+Kd-ZG`HAU+>!ah~A%f0JqBfBd)~ITbu*4QcaL-r@S_@j1F{kWn5^Y zHdrnoW~*UE!tp4^M;SdCOokxNg#$WEnS1xZr@b#N<&igArawxx3rCNBDN|@ps!JJI z79QL&DuNq)q)NmtCF!+3IfBZ7yxT6%G7X-Gx$uJ3u zKwwi5!SF!1J|Jp!8goTR|K)(w`F~_Xcm9th=-E47dIxEh#8K8NS% zmh_Q`n5HIjmEv3x_v9T#$B`nP{|;Q%)ihnbbg%Le@N52ullE!a_54mWo9okX+h-JOg0_97R9RUFwZ%nHmF$Ycvnr+op z>S1&*z%Z&bQ6WeCv=HHHo=aTHMXD0C+yV`r3fmRZ|d7?|Kjx ztoCMc(VqWC?wPzz?>O*K#Bh&T$;u_~OGKwqk-3{1Qj#1iMOl1LI*8su|$YEUn^ z7+vg6GqOa4@_J$8)pUjR7;oA2X-LPAx-R#$SiuOuD7-OTH|N?HIK_3+*+CpEdcD4S zgb;=qro-Z?Z1<=2ymO|fotTrn#wC1gk?xkM0-zSxa9R_@xwXq(n{+pCE-v558C?>B z{XAY9ExMl`fsA#l{|LH)wxY;QkrE+qr0AZ2E?KTGTU0uDP|k@rK!Qe6t*>h^b*HIA z1D)cin>+#RWkb-x!=bx9i=ua?bJwP!OabeaIJEZw%?7{GROnVJB=3^m6i}54rYFL< zhqGOPc>BQqXIfe@vZeDbXO9V^rflj^J zSDI&V{#t^P(5_tAg(OO#jyv(x4Fw{5dw4j*FkJ2;xFobK+VF7i$tg;~GwoPXttk`dWs6 zEg1m+x@K_6m}h}WCTeO65#U7u{7~L&>w?k`uX67p{sR zJQU7!Wqwt8xk85QV6EqxUNS7hfKz9*X>ZO^M@*SOwCToNQ^k0lUSIT^ze6jY;57`= z8)p$kpqJ&gBi4Et2E8hbm*!6fR37TP`E0m^mLk&6IvHX(>q1h;TTO-uICUpGxo$2< z^9W!C&sMzDn?ZvQkp_(fx<(8RJr2up?H5s-&mab2A(piZnhecrMAc2b>BhOcpJgS~ zfs<#z9_r>ua>`U(qHccJ9MSaHfHHQ!UW~|-RLYY>XbuT5oeq^|dUOy|w=;P?(^dgc zl=^BbDV*rGU8<%UNGAoWhJdNn>0T{qoJPki7E&LE`?Sr9fOg{fL>YCBpHdAqfaC2n z9~PI_)-ghEd6LY+pja!Zh7bL46($ZWvZ$w!+2#xmtbH&%%81yP1IK3w(R4r&5q(OZ zV{OUDnv_WSOv8(;p6jTNc}b8C0U^hc5xnN*49Yz1JfAZ!of9w%DfQXh0CJ!#$Bhlz zS+4QpPJ-JR>!5qY*=_90!-PYD7Ja!?@Kc}=`7z3#HU9d^(M5f=L;f?R z$=rcO_X)5ZzT1iy(LoJ25ctC5_4U%VO_Xe3=(+%$$Pr&ufi7=E_Pq+Em_AbF9W(3J zb(KF$Pfwmte3=9i6#voh?D=Pv-`$MnPs_4T$1>wj8?*K7d|`L_=kUtl@K<>XgWHlc ze*!G-shgiq^u5PmmU}(@{T}SU16a}rz%t(eOX9iH5ibu1EjNM&NMq(u$~;{7REXde z${gE)LCPw;v~a~q%gCuyHJwWnyPY3*$27))Uj{6(_3|LUA{}7Pq^i;>NWKbWvU=S1 z>lK@FB5TSljL0iAsOT;CG;g+Kyy%&UPsq%;r`^jXPSAY?RGCwf!)TT#tpj7|VLiKx zE0zaL(++2^!RN`pfo|37$7F5~Ri5BoSFuJ;0E5YC(De{`bA|0yYh%md3A0cq zUrnBAntNv%!<9l6iS3{=A!G_Xq^hD+N-KEY%noQudrpp{dM{ytTP2Q*zsqU;%eDc) zg}-0`)eK*%3sa|6Z;$3I$X)uRRMRO3^{adV;P9Pk7Sc@?n~_i{4-a+ivNUS_JkH@T zlOx`0gnAQsNP*UCd{N>oEh>I$cyH;$0XEfmw}fB7@)Z@kKUwv4sA}CgH_SZm|ZXSL5R`7!_!RO%$J2E zZ5FNNF+FzN?X~HVJdmnM1};G84;9>W%LFS?3y$>=w^>j&?o}gkRL9+Q;yrpu(C5(* zGc>B!Q$Ltl9^?uqCfC~rjQ7AQlELhU=%L_u!gnq>N!#YKD8zpnP|$xFP|$x7P|z;| z3XReRz%a>BFiBu2_GQNY4if}RXKb3k6KfoOXV_HCrZ9`f zERnKQ$}%~N?m>tAI-n5oJE6`C7AM$@`aX_H>sBn1iU!d<*VB{U|ioN@tr|-Z)qVK4OXDp4qzetL+)J_9Jn0MS^ z(*2U0jd7OD*yNv?Kzl&hehw(`Ekvptt%;zoOQmMenl{GzJPtvxA8 zWnM&|nKV*w@arLo03U`L=Ughr71O)>%7{m9yiTT~_`<`0Eusn)Ve|$J=Pa9?xD#pXB5K!wvnt=F`WQsUsj`*p*?gRs2cL9kek$(p z*(5Lg(Fqqu1L%GR4b#6#jnmMm1&8&@a8es<7ksl$^8xeSp6ewFy^h#{84YHWy{klD zD2){Gh#3LY4V)R`iwcD4lh`R}1Lf4==#g00jMo@K6?U6IoWB zRX*6|zzY&;FF@#Hcw0`CBfoHS)*#q$E&c%_bh7Xh_>6I?O-ff`Xpic2bUWQrr@#A$hn$+FQyg9DOchXU!_muBF1DRachMoE z2I$a|oH?$#6OoWq6m2vGE%&%sxfFse|<>3WT z`UIOqKqN|Q8;|ssKu?cD)&e9z#sZh#c5_dF$)j4fNBrVdhed%-!);3jK7x>x1i--E z2AC+QGdzS-YoyRgFRiSkQf$PGx!)ch$c@uR3Ycmx_9POosAA~ z|AIQ#KN9Qvz2=&gzz0yM5gqH8s3Oncz;Toih_^HC-y0M-sn4wApn*=JRJ2$kZF1rdT11JI)`RW2g@9-G+PR z>OV*7cuq}>^QFX(&E(|L^9$-G{^iObP`K-*I2?(*?Tz3%oX6vQ>kbA{oE-Rd>TrJD zwoKmeCkm=VB=n3n5(}D=3_o~bMPfit;mpJCmWY&Wx-Ct`(?y-1ab@Vy{)7e`PBucJ zXZ3b?P6l*67)lYDszSCeU!u+uK#^J-s839bvtd={*)+6aI*$geBB%3ljk@YFc&GY! zJwsX+O5kBRUXOYjjxYsT1bzUR#%pheu6YZD$f)(8$g)1Voij}|Co{LOXtDWe%`2SA zg=&chusD-kIrKaoJdsD?0Qlu`43+giPOPziiG#3zfrGHGa1co{49vh3Numr+!7zyt z7>%G9%wRZ0(?!~do zUgy{wL?twv?Smd9{Z5@Rgw5bx2`t%tLt+-CScKRu$_W<6b}R7@5QMSuKjI*MddGin z{s{*mfgKoK2%XnCM)Nw)%FAXqzYg_r#8-}P{~80mArSBb273K22KtLW_wQn$Hv|H9 z4D{k7o!5UFQ2QL%;#TRv!79fKU2vl#zMwgy14~{(5`}KH7MN>vljg=gO$E87L3r=r zBE==@OjP4JSYNl)J68kA$!JwuUdC8*nLS=b8?DV4O=JW7j-rFo{_Z;?e-C3t-oRO@;L9V;6`?bU zUY>PRP)#A_X6V@-w^zILCBW-c#>{3MTi; z8S_3^WGv0>f3G;3e%R|*5BUFgn};F( z!*r{mjdhb<21GZYhoa^1Jmhe63Msw@m>N#dwR)FR=_#dZ$zfw`p}f4>`v zdaUHYN)jk9%_Kjk`1#BPxK+~_e+6_>JRJpQork*8?mPmj${d!7RAvt%sk`;C40E9U zeU%FMvQzbImCCq0p08V*JYE&r$FaA}DUC;y2l_nlSJn5D(-l|H#rsJu6sD+@2|hDn zTSGocAmCMn#}^uT>-K6itz7}(nx1Jfi=>5~y2u=y`gSo~_~n=ClRMuKPQt0Dcz31S z;pj_ordq~!!|Sx3E#01GA3(J26rce4o4T zZ#~;jTk}`jZI-ey{0385x>Ie7U4o|ARZo*$BqrMp*N|OP{%c(~40&TA5@(schLrAN zH+jnDySW**<3PG#;f&4kH@;$!H?YfdHvPMr6}}7Wr`Q{ceF))aJA(q>h2s+Jy}je{ zE=7~=cDs9Bi%wXSd_%fCW)YG_nfGm|e0Sw#-s`+!BgG>BIG`(qFG1ko`A?$7UzBP- z_`~q8mSM8`1pbs^OC1r;+OWU1ssNWZ$~2+xJz__G?-HNeFX0`$Ek;`+vUwr)pEn>0 zj5ZN?G_rX&@~1gLpG(}eqbkW;7#MII9H-FcPg!t8lE5ubHt%}w@#snNNw?t@&^{eI zHtQ7n2%^e=Xwr{iU=Z(3-SOXd^~iYl)R?OGLM{wHjfR7P&%xW1XL;tebxrqC+NeBb zHt#q#@3`>#{yO6?3*X*f)5W|E$b7iezss%aFX^c_?s^tg#BjV=USU{&N$ZctboF5W z7^VPeJ-Tiqg*yKs^vXZ=i-mf1-tFJ_l%Pfx`Oll~s;kL;mt=jlZWbKJIA~iym5#SW zX{QwR9_k@#RoQA|bk_;G$Nr-v#Whvg=AnTcUJI0Hjr?pAd^)3= zrJct_deMhWOewTxUZ8z{ExgB&DvYSc2pHI!t_z89;4^rQ8$6}K#Bq#cY&V0EXuX7H zbB=gd6?jmCXCFgjD? zea3w&z9{PrbWFy(o^@5Ux0i;pS2) zKsVCn&9^I<-;v&mI=1y20s9}`2R`an&AbCxXkKskRx=;Y^ zfL*2q=6Y{%yO9>GOTe!;x(@E@WypVHzCjTM?n6$FbDhICi}V)5f^Z)(-oE-62)z|;Zf}iN%>&1SA0SpW?G{cYtOyMws!pPSSHzdZUDVs67 zMJdi=1WW8(NdkN4F*(Y@^gDOKX%;Ei1pm5-Q|#OvnkAAq#6Wh+WQx6U0=Ac5=$$y3 zGw(Z) zQ*XHSdj_OyZswUTaZn}e;#||xggx7nTE%t^-jm$Y^gP#=7~A%&2v8;Ca;l%YCz-Qu zeK(9UO;O~dgC!aNU*6th=W#4u0^IW{dQZ%V-T`+(CmPX6bRxN<_eP{Bnx`K~X{s_i zv#aX%#Q?bx&CyZf$9Ez=6Ty8`sr$UdbGBiB5r6&4*&sl7#5X~Mbw}R}?<;9@ltXt! z*l-%y^oAd{{PT{1f4b$LcMSaPEh`HDtMl%QQfTox@c7SxSBNYU>32#mp;XRd^3V-) z4M8v8;Xt90vQ+up3%l!3@uaWTfG`po>fC0wJzMM6(|6An_xwD~(7qB`Dfvz<4Uc3I zy^JWzd(|uSb5`36|I(()=W4*|d+`Y`^w1(3)rkCsKt}U%owM6C`^QwDGLXGqAgJ3O zQ^kj*_qgz7d76x%6LJ__fQyUK&yJj@Szc9qS+J8clLUUEv4BqcX&Uoq=sfbN4c5x^ z`%=4A*F)Q_MU>IAF4n*!F`r%Ii8HDBnvP1BOudO0JlU~}dEN>n5A&{4AFJcsRGQ!M zdlx)rE{ppTM|yYc0Ns`I>*;mo7Ak)BSY*{P8cI5e9ZjHsX`fn-mwK6PkO&x+bLU z-75l_ST&T?{iDwnG8Q)iJ4eMVEL|g)Ed(cyJp?D1(Y_q1#YZZh}2kXfJG% zl<`0<$=RYEmWCgsK(iBRJ&`55;a*;2gN0y^fn^;<>*t(8J8_{#+5FB)4|>|-5e*$D zsfSfQKz1jfekryLruogAM>L5qa2lO&50?|plrjKFLfaMmQUcoIuMhUfnqZ;Vp|DyD zj2ddAf-`vQZ&>K-JvoQeqLBXROn!HflA7Z@0HU87De^aJh8K@kE1}=~hLrj^LDGVp zA2@hNO!OQ~Iciz)7Bv~}obM;cy0vgTJ#K(+Vd8P*x%?=*IXF5+nqDWdG*h+Yr@eh? z-6Vr3YK65}9ZJCFT_gyi2E82HUbpE1IMfIx4WuQ?-r3sH4VHs|a4B|{y*!G=i6VAX z-AB9cue9m{`P>(thl(+I_2lwuW`ORb1ng7Il-blNNA-BP4#K5EZ}(M3V~8rp-;e%_AEt4bKKFluXaChg-_`m5<|2OvY7|A{1O_2Af#Vbk zLlE}M3=Tyw#7B)S`53n5Fq3^u1EWu-JH?qeVIus~JPI?&uQNC?$wcuRO+nPhEau~7 zNRmt(F)+qZ(5L$}dc(gsWulLcKK8K>jN{+6vEpw)M??%xFi6H^5EEx_1etwAk`tIo zsWYCNR0JTErJgd#5^YJGS7+GLbB}Tm?mFPc9++P5Jr9U~6 z8$$1iMDJg9csJc)Ute=8`sG9Y@j6DJ?;T3tw26UVyPtBl3w@i(4pzMucil-2)6wxS zf^OpXYryAX%~8L|{hK)De$Eb#SB6uxAqIX2NbsC)r$Q1;&PAK9!y7vN8} zLWogyjZyWBGfypUI!}Gca;)p%!iKJO#tVq;zv+T|R-M}~rkQ}>Hb-5XD;nujp1f|C z7deO6y~B4bUi!SmPWRVn9)#T@7ONhNGgM|}8Q!UH^xNZwthv$}qs7A0i0^fh=~mHIboxK4^1UZA)is_j%{ zLuT%1C~l8^PPr@C+Qkh8h~VDn`-{e&p=ZczIEv%2k(U7?^UDyL3PDN!OF3{kZK{&D zpl!X;(W4m~>X?@Es{~Fh)jnz~*mbe?R4DE^SuoWNyawSs-e|V$SDrqvytCKZ)JwT= zOp1QOEYz(Mhff(Go z(Jg1fBH5WnML;!n_A;EgIJ|+oDX4`jvVBXOa>`Y@ixOy}%Fd_uW%8-!3<7iw&N8Ny z6j2`L)AtgeRAf=>=N5%+N6laM#-DNN53RwguI^RKE1kO$R{ z>f`#VC?NFiG5T_i$_~U6??z+gjXR}2_x`Bv9_UZz>!r;V1#i#r%D;4~?3D(Y`(W#@ zC$s4QP#?Dr1)WoE^`%IJ#A!b=wmA}Q?8ZKRO6YZx9G~i?U45u7^tkbK<6U%Y(OG^ z%PQI*X}8twX7m?RVOt>zL!HGw6}TV9$ID;YvVLu(Qn5jf@$Qr=_uJJkAGFqKW0;UntFo4j=s}l@o4ob9h|0v2O8_}aJB*ZE zZe4dXiXRfm;RuH$iRjeT6BWVG&8xZ;uB&t&-K@X5(f%^sD!Qg*Zxl0dErxREp<~ic z=OS#jR6oN>atG&}t*zWnqthA&I8wh@N0QjNU0_ocNRxF9{7g3133%WZ7OJ&FS9My_ zreKC>v!%$yN zu%4C_ogW%@bz{IfD4_&YImqyZQsw!xZbT{&-_Mv z4&_OJRplDfGjdTy?Rhqzs2V_6SiSIM-n!a`?9c7UqO0jhWv8E3CTX*4;X{e44E@@!caMbl5dDdLLW0g zf`Lf}|K!7{->C1PZ}deb?=_H*gEWqP#=B!C`8ZZ15JTe(88I2cBq#%A42&`m!VteJ z?xCNF?>J^4;xiHjecCjl_lh*ZzzIVmpNe7h>F~%H^ox!$@?IK?m97QRs-@ZZ3~H!1}F7AzD!;dcDG;{*8K z@*#T5!xO}@(viNUhT6)two;oby%BYZ>bz!FiER^g)8QQVl-stNw9r=oGQ<=kDS86y zbQi9tV3ZYzL4?RtY+jT4YG64srBOZbf)no4ZHq&(njy766}h9QZP1h%jnh z5`UUC(yY?gSNw2A2*dd1^=d~$7L}|vzU6O#e>4C8(lb(XT(O=9)-9gWIXQ&hxH(Q; zTx<}$H&Ajb2_5?Up#lG%?D?Je*{LVs#u_Ez8pQlP1EDi$Qx4Fi#}m)DTeO`eYtj?t z##IYR3OHCB9Ny!??U^PuDLx8imC2ppL1k61Pbv;Lj~^QlC|Kyg?@>JyCOM{etzMgX zY+(?4u`(}}PpIFLN*Au$?5 zafHTD6#r%4Z1x$fL16~}SlLC{JJjNzV48mdH4!oJ7wOBCq48gaYZ80M@*HAtgrQ?5 zg%}iJB8bVcckHB4CP|qTdlUPJey>D+JpU7np??>yk#Fs?#3!MEU<~yUMT_H)fJnqp z#5-=2ACVCPW@6~QbCiA)el%u~{LT5(Pi5!L?K37P85Cn^n86SRPyQ-gpNWI#S^B$J zn&M5tcsMqdUH{Ed2Q52Yhj^^Bnz#t-_Z!0YzXvH}uOgIsP!D<m9njw;cd{v0mS?OA(D%(sQq*`$EihCs~bewG1AAv;8GN=;v1}|4-N24e@s1OGV%K z=3@J2h0MZj4Nf^L--ePK z`~J?)1AbS``Bg2aKEn29%6BIb{HNJUNcVaGI+PpEwWafzpfv|w5wtGLhaWCQ>qjQ+ zUmwDa7bOATOHSoZbyE5_)|yDaXX|-ha=^^4*UcrRrh~ezU&xsr`u_Hih(JWSoLm!M zp4aUd148l7D*BR;+$lYmXP=?ECtCzyv5dyYCEwEzX z(m*CTr48Ob7ZmD0#{C9JBUNfLjXe%!eU;CjC#WnDl;q_`L;;|4N2(dGL{dFJoa2+PJnyuhd>c~!V1eHZDd%69yse9G@KkUP9%wHYqg{xe zYM2|?c0{kS)pbMvlN396=SkSSdd4-v0QwfOYLp%b6pjxS`-g=e?hectsqrJM))Uxl zszioma(2TK20`zp$&ZY(9O6Nnm+K3(E&*LvbOk-U8z;nsQ&uM&usc-tU!D&pqbGA0 z&{`>EOX$v^m*t!KoZH&lREkV$2uk`VzKGM(ciz*aAp2R@~woO&)os6bP;F zo>WV=tu8vKb>qin{MXms-DJK6b|!jAHXS2huxT@8WySfwOA;3^c{|t z&lTQl@X~CT76Y@{o%B%P616q$B4B5epGWBY>ij3rwse~c2gy6`lHsd!vgWIwq|d?` z?*g@wSVZyKewnR#l&%*xag0!Wp0UN}ypGSr4!Go`wHmv$w|D|a(#r+7#YV@&6Pep)OO=oHL=$m=-xkO@<;|2? z)9R98k`=Kg8$qcF4fm?m1cP1@ji!@$1J+Y=mS*8Tp;l#cDcW@1EwGNP4LHbCs6f`Q z2TSv(Q8eJP)q|`U7T#Ks9+&B27%IS~MbqW|bYFG-OmzawmZsq%mkLBzcCBdxtUpMx_wNB%gj>iejJ-R>VKE?dfN% z3;R@}a{80IAU|%DUle(%zru}tE4*p`cd>LuGfJ6RxWnVq#T|firAvYixlJl&`1v^@T zA*>%~jw%!x5$_x<(z&>~hNq-mM3eF0;l_>QFc}vgz?ZNvwqt>p9{$J(~AKX8G`ZjL%|NP4$e(s?B-z@OGWAfKe{5aGGlO#b9FiDdr zhG8^CBk!OLp%6^KG>($L)R)TNAr&H-40}`VcYOY2V&RN|J|a;V!er4q+I}ROei@dj zk5xT^F;MmniV?{~@W*Qcen&+3^9?D^&^bfFpQJ1L(W8o)6#iXUPM9cue{Y_BQo+!h z*GI@Z*v20xi+6B`-ccU?h^x~SgU}3)e1t|nQywJxRWTin-v8d)NR=NO z*7`PQ#y9C4BWel6XJZTz>`yoK?>E2R`x;$un_hnt@MPC7lIOP#_~ByB>AKCXa`AQC zVoT*%qO0J(Inh1+KD~B>#6q(<+o(kc&^htjgTgQlGkfu@K*`4Zu4ABmI7?cGrnF3VG$);-|QwvPvd1iq**DaEsj(uiT2ax zn67mzNpVUgc#_~DUmR!fxCL&2uvqLuA4Rk`UFT)?l}}$YNmq7Gy~VEDX%K>Ec4@ff z<01__Dg~mM&-UddS-N6v0uUJqeO0FO+{Ip_K2ZG@pI?jm)QhN-UmZ>mk9yHSu;`2% zbY+7oJv9Q_!^A_$FHdy^wEoqq{0CJUEYCHK!f9u<*zFPV(xIW zS03y^ayXShTr4}U8D&_skNFl5VHk$%m4#19A6*nE5`%OtZjYhs-L$VC5_jV>1QYIR z-X~m$^}yZT5Yu}-!028gihhOiQ?7F|UMAFGU;Rsbzqy(`1`cg#yx5=H`z;Dq9KYuG zqt?d&n8J;>{B{wBB=pbr7RJ%3R$qw-HbzVq3o50{9?aG=xVcrqhKXX}O_*6QH}tO~ z$pF2`gR`Vl7jb|6P#*sedgp&-%e%zvy>7N^H7t1rZ^wN*ai?8Mok94*!2clN_5%Ee zhkvUxQtbYdFl4&*Gy~{oRvgsxh_}bBG{|I%)GHyT7~I{1hqnw@C8gM5vf?SZCt#Sb zXFGs>8(b5#5<}?;C|g0J*?G6r2x>i&%`hU&xKI$`(4UFRVUiw-irhY3u2Xlo;Cw5} zAdJ9zyOY~v!iXoCG1SyFlQwbYB`?*?l2IKWvk278VZlEkukOIX%~FMOsN+w z3Zm6fPpt-CZoo<%#4nYX){(fmDePM1W*~TXC$}Nt&U<&xXbh8k&`)RZ(QMu+9K6T< zRF1D#4kUswt{~1^3(7a^T?Ko%&W_V93C4%@n4#+}NKlu4=O)ydoqD_ISR+QZ zJRZOxr{hM3NseiX{K5liFQ$jIKm876xl|>e;KH6N7d;i1IJ#`SpIjF@ITGs3!B8EJ zKyQX5XV44RbqHDvs(tQc0-fDJ9-Bwk3M4Mej=2Wt{dl=MqIcOjqk08AU`Kh~^BEXf zTDS6(vp8(cLHkwIK&gFp;eE10Z`+$go4v|235|8HxNc`sECz<*>3uvs=?#1Vs_Kf_ zr4Sa7;P70ynL?N_Pyv%W;bz{6GcT zU^(~<7n;v^nZS9II&$pahhwHk z7cwjM=`hV%`V&O^KU?%0Z2OA^e^6k@APPeBw6X7tBAjARh>mk=(4-e`@&7(8Q8?9FTA>`itl z_%nZ!d}=!%ADR^Y6u|R0A&zMV{T+m(aE5^1q!|7fjUm`aP(AvT;h_($&X@>d(wNCm zhWNOk!Jpa>g1*0-#u$oVD4fAQqqI5tX4yE-kT3(&43+*BgySQJ=h+PW2H|dsJ>G>2 z83~ssYsJ(wR1iV@n-Br_d^1ttPgGQ}g+D4Ve5uPG)H5559q?{M!rP7qq#r$ZY+tW+2~oPPl!YQ8f-0)`ey@ zog1bf)|VO8`r9=Z(+?xkCFo}ncSHG8Lf|58%il^@pfJ*Cput$V1N;$wGUM9dph_wF2|n7>tb0cK;vNv_cxCx~Sjqe9#a zFrx2=WDW3bb?YD14}fn%-M>ke|B(N-mBgLQtI&^JVLtOqm5~lG1v}(QpWm)t)_~(! zi8nTv`?4_mQ;tU$B9>jlo3g5NI^OBS18`F7cXron{hDUM8V9tmx}#+}fqF?cVlNbX zR1;3Wcd&Z7bC?LKplv=Iwia3BxD|k2)Tgd#_~%e(=L?<2YP;3eaH{CM80tup*^D>) z&^aZSip*$oR=De(r8W2H=)WC}U7r0G-6Z5ofHVKc?W@m>-%mmIub%xDJOBN;AJ{H} zkt9vfC`6+q2ICk?!!(TH2u@Ns1d#-R!U*|G1xyNh$DSN|lSS-H89Mohq9AXI3MU_m zNih-4;1H8jzl@g%^$u+$^$vS`pOsxW-#&{%MCOgU9F-Us3q|-Eqp$^gCRmG=riHg)kZZ z*;(}ddW>e!zph|gZ~C?q-{Ym9f*aC4YSKf%d*>G6&AgGnQj8Z^`e*SL!KuY>LqH;5 ztcrKXM^9Ga1ifw2!G_-wjAH8vH=C1zZ*k8$lrLFE;cLjN*+X~!@TmBNJVD$)qxs)` zE1;iUGYs=5-wH48S~uyvBNfD0=bCSMK-+T-?j5y&uVG8pzq0gyQV!m-U;<+Fc&UZk z517~>-AQBfF6ieG}x8TyI_nrcMts_j4)ElMyYhoa>76ml z1F4#_ADPN_WrM?-LRXBUR@+tg(iR4L(>Ad5tPnX^@R=bJda?j-C|*+iFidjc#f+0# zgR@KGMV38wRi!7}J68WvP+1GYSLP7r!&!YB1=lV!*W@lF0DtnDmBNLW1aC{KWh%T} z2&0y!F%&ujY!Ah|0taL~GeBJ`H~g@0`$C~{ELXE?Pz9n-e6(4g|Ywe z@h4(7X^lPL#jEV4dDxeAyPpDK;;&qGxnr@+?k}LmO?65adcd)AADWOfKzQAz>HNYm zqdD&JlLgP)emf&`x4fQ&MpBl{6{hCvLQM!QU_@MmH5)AZa%noHlZk>};8&j?iS&+v z7u@s<+q9Iq$qlC(;Yot_d z%!bUWBTFGbO++NpKrNb9m zCNA=v7Yfu19Dp+`=Sax&)D+t1>FJOUB9x=Nh%3=@TfM%66+y~6l$b8kI6S^+56P@5 zc~8#EGj9R-(Hm$+Bb@@V!VJY=VWRcG1wxga+}Gj`^O%K6e=m&(Zus({&fGNxBTl7N z)WioDh|wORpF#=YHUXVe>t!crA(82wQ&zGA4bh&JK6Ts|#+}dVL$QouB__MaK=O6R zG!M8wqi3dSu`e74azTkjdY(2R7@mdVRqbu=HP%ls@@5dadsQosW!I7Omdtj$&8PAj z*eR+H0}MWsslN+Cc=Hzgti{7xfUX{8Zl`Y#g7i!E&){sgV)rl!``!#uaPn~vd~!E_85cu;87>hq{!--n5Q%2l*8A$X2i~G5wsXotJhXsH8{P@VnMI zj!)HfUY>i)qRywqtVq%v=959!r$U!^CD(i&T38WEYnH`r0~_Jk2V4%kfNKn|WxqoI zL_X?`U&QU1^=X#=%Zu9TD^2`sboBS$`ZG@Y-5Wn3CWwF`2q8%vCoqb@5t>8^f~Ikb zq)7@VQ34_%=$CSL5&R}#c+Pxrqd-3*N^d%sGgQKmA9qn4Wuo*=4Kw7Ih$%vu=+k#c zGu(C^o&;H{eeN0{MTl8{p5|`K#R&g;M=|7y#_;%V{92?E8TW zJG@T@e&lb-Ag-6S%edxI;=;Kfk2#cz)FB3N(J@w@=ITBafPlTuvpOFv{E)V`lHf!- zFVIQqMb6kKa*4tSn*wp|`rYQT`Fz1g1=337I>w5ky=-8}8vovj!62oWAiQT!nv zYvlHWc)cZ5c|$~qqY?g0K!tufNdcn-Iib9>WbVB$ zF&^Y9MK+9jrRDXV*7zAvJ0qbhG^y$kU+e%thIFoWs1k`L(OPveCF1Kp8#k; zm%mQ!IKhp-1U#C%`BKPGcY#}{uc_1dDXe%~Dq{_J`kj3)d}gDttUeNsKciNqlKy(A zA~>iQzAN4QC>@sC8&)tH*K4!^yI5IE&gWS>fXfnANHxXxyK+ z>ej^{6(?KV4dsjp$vrogScMh2r#vX*$ejRZ5ndc5$rJKu{ozF(Fu!-L{aUe(xbrBi ztJP-o3Z6HOc(S|Rk^6@8^0?KSyNkgRFmH$#c2~;STXd`#Djn#i_Wn@6J z9YTRJndAVcd1|>{ee7(W;@V9B^8cW@g!nfC7g$=z6C0KBhzqIAP$v|#Zr>9Nz+ZWV zu)!}IiG@!wO^6Jjr8fS2zl{bycbXBCQ|XPGG)K}a&7ZGEcFz5SqIzYCNPVer0@Ve0 z=26xpz&v4H3y4Olbyjgq%xf!{^5fngi57;SD?=^ekLN`7*6HwFmKRT( zDYNlq-s~ITaY-na(%+?;LmC4r@Lc~Pn4&`CI9w_8>oq1;^6 zspt*`2NGg_!1rFsRI$^2wAv0~J8>44Zi*?Mob)`}CmTu0+b<>s(~0uQ?v_UajADfAW3Sp-dYuB#?{t)%g80|l>z8wXNd+gW*|~gdNO}s@sQWHUG|e6%QI29KFI`8cX%?~CzAbt=V~G-t?PE07~81Emc9X@SdghW^-t(VrnW z2xdr(L7-0(>7yx5;qUK3NG8V_4E;T-qS8-W1^PxzY0Tgd6JZQaGa1g{Fhi3J0Wt7L z{+Rr@y3i>@#veyA`VF1%=#2+yoPptw6+ZG_;ZrJLh`;QJlkNx4bK;+D=k;lnuzvGy zx-ozu7bi|VF8|hk@x^xj{*x?})he4d1E0! zuUNQv1yAG!*&zCJSuz<>6TuKW1V|VF<-$2*IHX#rA=6N3cl_ z>jU3&Yu}pL5WM_TlgBTi*q@OY@COtV3`uBPsqHqRyWNFhcU9G+3i^6B?Klxk>h58v zk6iZp)`R@MpvIk^P2jnsPwQ6r^Rqj4I`G|I84wIN`{9A`r!Fhi(MX?Ib@2{+rWNU0 zv-rce>!uBo;ZExSUvbZVH;AVmN1Ay{HDf<62J2AGX0lCJdLp0Ui+dh;MBJ}n5F5f& zl@F2U2sGla3!u>6dUUWAS;8{-6A#(Swhosw^isXFkYfip+Orz3t#j`zGFNM2fT~Qu@5{K=P_(QI3*BFo>|mD}Cj3+aEk4*UxxCT$ zL(dDP1bCc&jRFYv-nBYVWYpv>kjA{cIteOC!2mVF*$p20x}&Cx70q3`t>^jvz>MHB zHbM?$*BIvHZ4@z^f>NpHW{RVcnthxz((I%sr|b?!pcG|1#n|f;+v}D|eS}8MaTyvM zfHGwDI$oss)vn}&kW1W+H~B&9`PGG%dw3#og_M0bPoGUb0mVwl1K(wm}LzpdZ=r70_L z<|^4+xFrR##&9+>!G|1PEGlHe(@~u{bBJYeRXi9bzxr3+jj@o&j{)d4z88) zad1tJ;RR@Dil%6?1b;-GCG3?~;Cs+#hDq`c?cknY+D<4jthq+#!9t7JsjS)o_~r#0 zpz8d^3ieA((7JHfkUu^r?@%TgrPdjHEU??~UL*)6Ad)R85r&tB7<C|t^c6B660%UKOF}TlePbq%LL|3KA zRo0ueSRk_3QI@d!B6=2l>SPmr+=h!P?;JZ`jm#+2LM8x+lXTEJKgb6~udv|MFm+_k zEVCM#VCl{3A!XHQdwE9XM^PzZN*%BMv^OwNT({2B*nw;*XB)s0`*CJZY^Oe?22 z7S9pXo7H%hl9PjICw@rK#0;ao1nPTeM?S7a>>#)kk+%ca}sS(B( z)E!R~B}^a zp;J)W-@xoImihtDqBxDh6hROag~BunQ51|p*e^$c>4d?MPtyp=q$!hp zJR>5KL9#dci&7>gm>m5i3KJ$ue%(79F$wvRPRJP&Wuk<^K4sGwXGr{wCZmrPVE#$y zB{@ST?^{&HP|0rq?E7hgiSm#84Z%b-Lr0&6_yN0CMdS~ZlZVO*Xh9iTmB9B znt)TCKQ-F&n|=xJ@Yil#PO}}c)p`9}LrN05FdRzd9@v}_hbPRpHaHRGb z`BobWf1q7<)15yS{Gt6<2EGZRn*#e8(J%%5kIL)u<27AMegd+s3Fwx-inp&#CF|J6 z-lt=^aK)#p+wQ7-t;&kq);hk|M6y~cXR8g6@*^S-gh<;aJEuo?_yTfkSQd8fgf1=#oNrL-tI78YF1LLvykk&uu2~Dsyn6 zBd-fFdtI$lkIB>?Gc25P|B+lz&tntGR>w`fj2#7HA3#c)uPZCgv5AD5@(P`<3+7jL zy~XUFN%CFrP6GH)*`|b(GZ?Pd+V6)c=Y!=kjY6pdPp5%na1f$=AUvr$$7#H4km1Rr zXb8{RiyrnJvUEz5%Nrp)Y^Y4{xZ_4QZUt-mcmifh^O$0AsR7nUa*+bD95AHOJeJpR zIUJQ6j63yB@k@t4Gzp#3luDFIE^lA(7x1f87zk2EIT9;IBjb{b zYbZ~+kEYl0*be+M$6~DmYo(kb=XHLT?rS)FDdLC3BPg82(3_FyfgsPUR~|;SwGcXC zS8)+;kB4|-YkNy{A_XKPP}sGV$WAEoDHiRUW#v9sye^OZgtmM32-2%ZJwSb`PELnf zWIyFkN>qpw(X)XJ5c#uiFphmD;mp_Ka1?ufka}$d99Q2D(LfhY!}#(hUd}|?V0BiN zE(LKfq#y1@yaU#4xq%O|eBtOmwFxyw#O}RpEp&zPV5dH&A_4f;>dtX~{~|Lu}L9fLnF_rp<0krV}C7z9Hw zPQnmH&=?NmzZ4=*viI3XBA@oi{L?x4F<`ILwy{cuwPF%q7Z|jOdc^< z&g97FP)$DVLnuRis#i$H;M7NKl44?nL31V}m^fyV-}Yb8kH9})tAE`7d-uS9v;Ft(f&XUv@7)9GC;63p{a;o%u5hQ~ zc4L*os95$^kGCDuEDgR~&24_76i&i^RfmBPI3DLR*MFnIZsL4 zhxphDdFS!=`FN)LktT%3J$XqXX$cOn>veS?c-w6te?@ITX|RuBi$jQkbW~dNnQ_aFj`+RZZ55WqqrE&Dnp$?>~QF!1uqf)ficU>)2Xk zUoWFPR^=w&ZI2_1ARekSXM+OIWw*TqFOFFl68hMt^v(gio4-tARXBM|x>$Z%Yi_?6 z>EqEmUD^v_qEEaJxLf~HKuHK|PtrW+Mb`3b3U9ptfNE@5M8#8O=%u>_iY4!H{9gal zc=|`A;{S~Ql|K19q4OWS{adoY|3DTf1jk_rp$P&;QJ8=rjK*;Y|78zB`iX&f%0MuK z!0#|eQg0|8Lrj{#<4=lwVqC=FIYa!q>oWUriyVHxktgpM2+<7k@fXKGia{y^Y>jGdw(DHX&uOscg##EhJY9<|EmZoBnQv4?e{@LjlGapR-44*(6Af%Z$8|g zEVozx!m#d-S;5)iJMZ~*;P7Tc&2|=8`}>d~;u-1P8j?;d0Q-*De-B;j+gJG?Oc#{R z6hurv*cJHdsdxPOqJAE}Z}G2o2>jI+|7wT84_o{P_Cp7_j7u(s0GAxWg+E^?REONa zx{KF);q0r8od&0?^4oE0ajCa**>CXE`GqA4Sv0MN;=GT0$~6S!^s3wk_vFtR!hsmL z>O?dV+x=Dzxate{7wM741DWamnjC48R)g7s`*J%w=_K=^44}e1dZY1}sq@1eA(~Dk z-#i!RYFjM~w4vpUoaNvOW@k#X?nPiGYBT>8hWhAU?_r?U%IKC-1Ht zj|gdE?mEesr{FPiJ+Xzs#Th@xA}4xyPUQ6Kc^StDOn}YSAM~-7v4*^Ah&-Efr>AMJ-W8-{Lf^<{|E<7wd0(TByeg>-*zscSb8zKiQ|cQI-vIAG8UZsv-$E!c&G(<)K7dp@J4MSR!IyMZ{RN>{JNifUsAUK#E!U|EPPDW;d~IYqZa=$mV;Ycdw|ch})np zL?KEcdeov4Ado12{R?4lr|sN6={)B)zAwY!*c%p0Ybi4aW3D;p7z1S7d#8)RJH;{g z>+@zboaJInC*bb-(8e3jc@GJ=T5jXG_5mbag|d#!@N98kB)021on46cj*o_DuQN4s zILVYRcM{E>pJ5*r>p}m!FGF;rxGoCoIm#E0I52f%lZ1idEQh0L;lYp|NNcx4`=w7 z?4J99-D4z7p(Fu;I0|DR4uT*Ep&0mShZU017_vJkBfF(@MyCV~fpkvNDe``UK`9Lp zJN#pG`nl#^yq`&-ySpm2I}Kq7O{8>=@3yY-E-;e6|KK1EVKkWRM^Pk=iw3CpuNL?m)p-F8rcuip!EF|n7vg=;*Y=OzT|eiL|Fd`3pPl!-u%zGKUAAZNz)xpyy#5O%(QnEk zXSlgW7@^*n6pxb<&`+pDDbhB2>e9F^2|`-+z>gT&Cs19565nNh71!A1*%AoFA66!1 z&)Ve2s98m?sRTwvQkgqTIl6yB4|VBts!=oeWDRK;sQ3QS+%$i~0I!y7rosaJM@0z56AN0b1R@C}} zQUP%0$u8gOKBtb4G?_s?MREdXS;(6`j`1izLAjw=JnJ76|H|FHsJnad$GID)Zy5B3 zuOIIG1bV;!)CbW0;)x#`OL2$*NgRVok|H34#4wVCNeDtw2!|Qz44vGFYGTl{x-N(8&?T@2XV_m-B9~xJ?QNrk>#@IB#rVzSxYafFn`QaAma^ z#_qa(oy8A-(HT zYhE#ky{yD2nn0ShP=7c!xO)jPeNHfN$}3l&72a^+C?X&ib*pEc-@tbAILKOW<$>|b zQb4%N6Kxg1@7Uy^f#cZ}bssGWkZ65^e96?*Eh$&FSmUUaCoJpJYo!t9P??X+wIv|y z47G9Z1JuQ}uMEDGUW=9`DT19Xp5*l$iHwt-XKnJ&+T0h(?PO-7hE~1tNLFsl;1(0* zuDt^At7fz!?szTV`q61cO;FBY_8e4A%g?Zz#ZG1 z4Dy0{>8Yx5P;_pf+bs7Syd7enAWf}cI_lY!R->JmOgmLV8Rah`tR;=Oo&Z-k#@#q0 z(m=^K2R;R)1scN49PQE#m$PjgLS<4$Y4KA+x?WFNGBT@wdRZ?LsSZ*F$oG!&PE*A` z6Mu3KuSbZBFw-q%ag^} z&tRfe3fZyx@d{Z)5SB)Q9`RzqGzSlz$-y-VAXt@54POD9+G`X3@l53hB^2`ohwnaO zhC_O8CQ5i-9Q%q$#ZzmwYxJ~dZUqaE<7z zOOvi-)!FXdJJcF0cncDQ8WFvyt8E4kpa}6-r?%5;sM&BFQQ6&cYdM1M1qYwER65EC zbwfogD!`3DcCQ2LV1;I+ZZrgFey;&Z4^YT0b+y_kvaCv?>D7|k^2~+Jd(V(BPdu3u z6jS{GZWY<+GP&lF!Z!w=WP|7cNQ=9bU9?C4GQO^d7#t5T484x)LaH%tyoRgmB?M)3 zffc)@QIO+o4);TS7v^Tr)D|$e>IjF{Ox;hytG)RGbCi;GzC@ueA0MJf#Lv>d3^V-j zPfY3EZ)t{1XefwXGZx%<02;hapaAn-JKN$_V)+-Jijo*2$p$|W=0Zhl}=+7<43 zJrNG8q+Y>+%pJW+H#`B<+}+MTnt`_s8&?>nwlrDB@#a2wr1g^PEfF5i=JI5p4~r$V zWS}^%xd$fL@P{_b&wz#<@98AoPOtIy++=I$DY@5_a=l$~Pt1i2Xxx{JUov3L;@~-i z&t>*V4$F1MMC!ywfToVq62;6Ty2%um>Lvp|C9o#Em)n(!{_wfVBP-vT_!EC^o0?ap zav5C;#h@ynFl+eVKmC(m$SK_D6Sb)}I*V z|7mOc;H|&Ct{)R}6hb06N|6})4%tbZgh?0%5dtMB9K&#&z|qf3Rmfd^G>1L}MhKcn zc8a+N!DO=A?UHZm3FS2T`ROx+?nH98>WA_Dlo@>g5al#R(Kt+F$(wZ&#GB$G7!6aq z-U4%@ z4E$a>LhN02Af4fK4$@He-o@WASjpKqj^)3rwKiJFLJqINtG$3i*c^T?NR&lJN*z15EjY}FJ6%%DWbLhGyT$F_KaH})ZnEFVR6&~yGdGT z)7^SD=C4I18`E9ax&ZWwSqz8$%cm$DScEOLD$+MqQarp^MH(25B2mv+u6MKGk5Xy( zyRZ=Fxf*CFt_UK2&A2MEGax1aa~}_}CBU z_^b_55d!e(AjB>^2LZ8Zlj^pae2^g`bWT(%ph$d#_03InhIwql!4M=)wXuuR`AFGr z#~cv=_fQV#zz|siA0tp-k+cB??T%1VsL9B3S3xsxBQb9y~xKK=+s>@C#(zoWMwLs8ab30h$!N=JC~!IK$YqQet#~ zgC32>$dZ3L2E!;=8KsDq$Bnsn(S61^iD^QI3x)(NGtLA1#%mwY*~~h!UtcAGxBx%7 zUeMz5z3nL5M(n_Tfw(n{SM^Smv3qQ}?VPhn&kUW=-f$FAZcjBf#_*Mp_1Or3Io4m) z1z8W|a652qYIn~qdc|!xX9rD6PNy3cjTIIwhJI5nM&tEDJcg~A1w@OZAOpbuFyQxd z*DDHVWAWjFV%{}6KQwThM`f(iKqVD-Q>d2+LhM3xv+om+$uPImp}nUqa37Yw<`h|m z1-y9>O zEl>TSZDs)vrqtV~;CN*o@Xh8>>_nYkY8tdDsNGh@UTZKoDC?lk4Pc-v-ZETJg6&0q zflWDV2|V4>RKnWvObG}sT$cx?Xj|rG=hAm7>L@^1ddVU1RvQ(Nfc1~63jeU~9QdZH zppxh!UaNV#cbzPbxM=H`S>R(#-T#HCf&*aQsm;*w%$v5<$6;Y9nXU%-^puL{g$$Xr zn)!p?gw)x5Tu0QZVmk_zrJFT&wKmrQr1=GF;@MeyR=c$^IdpnSDPt6`q4JPJgwu{< zD{i3LwOK}*Sja1EPMvwgzfFWDJ%F3&gDGkWDx^Mc^=2Y*(;TT-3i?ANsEw9h9*5}J z28!v{>HQ&roHNuqSkziChv(@Cu!P}ens>Us)XgF>_JoRq)_IpkJbMvDt;#Ujny2}U zx`rRQdtwJf-t-TRXlfU$Pa!(acQ#19Sz;2?c}8a`jep)tNbQxhVhMCh=7_&$s+ylQ0DW&0GM$}2PA7f$(o{)HZ802ze|06g&c@eHK3-TM zBf1!Cj2N%*ZtZ!W&z*_9AC=~LWd?LN`C5PWre6Z8SNd#J7WAe5Oqq>szqS|^174~x z%l>}Vz`wKX?^g}{JIj8r`lIX&_`L4S^I&=D;i4nT1?G$j!$8I65C6L?X$;bI#>BT>wI=TcKb=f7x>f7_6Iv$WyP8`5f%MlMu)Mm zgOl?(TQ`0(-1pw=2U`dNb5#&Pw1jSHVs0ihbbsj?sh(s@pU``=0aMz@@NNAE;L zCp%t#$+jmH4dyiZISLa99bsQ#9EsmEkq8a#k~m-T^GQPE5KTrj1-`)$&FCoG-RRL@ zpm0La=x%WG{?M3)_Yz=|e7_suj3yvDf!+gPn9gz1fntC9E|66cwK{B(WsM`ew* z%z&;FxAkgt%b`6>bM;|Q;W4$@6MnFnCJx5G# zz|_xBN?fI+yQy9RL_Gf@zAJ8!&rm;5r?Hqud!ZaiKG~G0sEC^04lm!% zLM060m)CPRaKV*p=qJt{E-{GpAB}GJN?(Ecfu9b(WLiG28Uh8^r;Rjq`HBWl3_X}0 z>V^F}qbIAF8@oK3q`Xac6`bV2%gl#KhW^n;O%Sn8U^)zV+oH`{ zo*mtifrF^>=F2_#t~ZXSaG2E%BRlyfv=7EkoBK!-M+HBrT;qD8Ru6-bkB8`GsD80# z*MkLIumW3{LYkxH$X6iKe{DDVOuqM^NU&LgL zrT&9@FYvv5?uC#P6#8l8qW86iUKh%+-?XtKr1vuEc{R&@TJ0Q*g*%gw$pM9KoXs(P3huE*m&m@Ir|Bk> zV0wbpp2RVT%JQ4!IIsS4dsvODQ^=Eh_9yR(z5M8j15;>Ak8U}_C)H9feo+WHS`*9X(^MHfcnL_hVc#zt5FiNNmSVfP#0+`Zx+dS}dt6Xqy}l6jNMSPd?{ z0}p8toR(C@f>@jVC^V~VIl}c=hmwn?l-_MA47ib$A0#l7(=$$-U!ZM+Zk!yEOXig- zqC9RdBY1B7qzXuq`w`I*XVj2eb<29~}#R^RzhLfoUB>fWsXR&)%&_Qj;>G1 zEXgl;bqd&H=-oP5W@|WIgy(QBnZ5_4ixVnPOgy;mnP^zMFsncuE*gpH>_Hl=8cwyb zEvxBrI^*s^&#Eco51IbdLz38X3P?>&aW`W{Lko*z(0LH3?%r8af)B>Ho!kVpE^$_Y z)PeI00ycAyMsBs23K<^7LHKR{m;INsmBqdLR&n$LC(DvQv?=}X zpDQ|l^O8q43IEJC~oL=+wEWu3|H zT@2;Fb~=hPItFPle$y!up{e-&CqZa9p%IwQ(7h;$`YNac;yaVuJ(^%>Z*thX%-$h6 zMUyd&?ZhzKEt{a2rvBFHh_l}0EW3P=GoA5mg;-^(fog-Ytkcg9Ub-y&WL#X|{O`n; zWuCcl>BYV!(k{0AXHicv8y~DEyy%51+clt7LZGwWKHzH2reBMmBYKlw>5$1=py?)y zTrtUqrj2;`64K~zS{f8>hkADNqEXWL~FsvFU=j-D-%F_#2%IsjP+%iH}KSMEImBHvH z-k(>vT$cuyLDpB~p|l<`(iV0#J}J=ly{mj_8mYskM|8zanrb+-977WicFkD+p5s0`0aOervvpQjMo z``i}aZncX;M$-XRTqO!RocPpwSJB>to9~JTnN_sY89-HseaY+@>cd zZ868!vJTA@0*5S5^xv-VH2>#)*HI+n4~O}~^!_Kw9@GA-ZJO>ItR(n*`1{TAAJF&b z-LKFm!9O}~A~;B)B#wd*0)i-kLDc72?}W}Fn!w(mknBSBNlsHJ9TV?x5Z~=HN#YGR z6hSAyP#D`a=PBe3mDv|zFp`G%+;>d9e<+d}cJ9 zzaK{Oz4?lyQJjW%gO429{or95+3njg79a#6xr1bMVnL=f0Qj8;9ZtuIl0-=%@gv z^xGu|F#}X);MMTMR2=%!D4yD-zG0MrNCHOHsdowBDQ0v9vt|&!`6tYSy|e6TO+}I- zcpwsnLWs#og*y>?Mpu#q5IT^LAs#GtSw3Ib3eTDT0lwsaZZqTvkh~jPcJ6b3W?Ih;F*N5!c3STfK0_HiW+f{5e`z`L)U z!j{{(U9M#{tOP$t#zq|~OgqE2;)Oa4Ae5Py@OksV2TQuL;hgR4z{P_{{q#%9Uxey%6Vs>|z%uTR(J1 z=$y2}1D)LF$=SXp*jm}$gu6Zn;Mx%%zHNK6@po@G;CEhc-@V;9#ev#o$_kVX9$P)D zKuX%hy|JInXVw^BwXUuP8a>T?y(*f|Y$m(T(TQ|a70;>xsDq=VLs%zSreuOTyUpp0 zF+~<$FE(})%IWBF3W`6UHb%(^HewI3fkH1Li%a`JJr0O*0);C1s3y&6)w9!(wz&hg zvEXN6UF$aTxNg0^1=Yo-ARQ!6+zPgRJh*uv*t*pKL&-5P*Z9~kcMWc@ff3jW1Htxn1OZd!iKiiLNfE0_7O_ikpEx|k$eXU+ z&uPlv$GRqL1xCXhX*ek}QwFP~u9n038XXeASZ8~>o{(WcYeSq?UaF1FZ*%G{z3$A* z=Bf%~%MgEznr)0e7D|V3!Z&gg7pL-P_r-O`F<+bBsLGYcHxn7YWFf`;aKxTd5 zWNlPtojaeR0oIm#%7dPGoIGdAD*!}lD!xqW>J+ASx2@N_g?80hx3RsS4{brn$44Ke z*C>$NV(t*K3)Sd>VVugt%q^^e^D~HC8PyH_js--tokZ#0ug}5B2P1SE6NN{&$DB&@ z#VKPJVWo~4CmqcWb{-&h5dcVQ9A8$6rVR9#bgvuXZs-+OQJYPkqAt{1cne8ijfEmQ!otS@MlyjCuu0z9e{Qd zw)jgM`@MXbxjX3MZ$5}(?_ua}Z~o<15ZpENq5TJ( zCicJMgoYv-j&}vF^f&CyMfgoE$Zrz)I-4ivZR%ALyh7SzSU;s(ills&fc;aDo|zTr zvW(FMdqsco1UI_qV%$QQTmZ%W5^}Iir%U3Onzs}d;m~1~7+&h=g58sK-W&C_O4xN6 zzlywe{+Hr98@UEy^PR2Pzbfqcy4L+_W>FIp9?@Up7o_DU1#zc{)GE6ie5Ei<^L{i1rH0IawUI zD~?wbzHDHy-GOm_zBq;Ai79>b_IVAl-sT6p4DtNh?`m?I*`b-$i8EqlKMcHAT+Ttv(m0D~H(xbLH-gOyrE#GK zu&3?0UGAlOJ;)~k1-Xqli$+TzacH#zgh1^50^bH@70_5kg6mjR%cIlhr!APxmr_pfK`$tF~dR_(P1s*2P=6R3h)lzU5|$P!-bApzJ6No~*g zV#8**l=dsRY05)BSQGQK6SG9H+to_!+(e4->(9bJS>D?!Wx4X?47Mrj0Zp7;v#40x_JVlkdPW43cA`x?oG_(UxdcVjp` zhfWa#%Av})^2-~#s3guJf^~DD3D&lpSI`0)>3BdZM=q%NjM*a;rwWh8j4_d&OA8C|UQHvJ6$B+siafY8x z*R(cPNODgv@WS@dUBSA_Ib-%Kjs;-UL~on0(Tc!Jh!FA7t&FF8GsjUZRtyXfsLZnV zw5lBiHsPzjEQrHX@Ksi)@addgK##cgxK-)4vS-}CUCcJ;!8{7v5XOy1#AxVEcG2i) z^87%Uz*NG(S1+axh5@50IDHW|u)tJW5lSR5?C3 z&||2x6Ck>snN(KuqLnT;z%LUi%KX*3%I;K1YR8dya=#zUiaT1_CSNPucE~)`gOEGq z33)xtZ6)h^Zg(j@+(_VtSDcD$Hysqt8+jy|6H^u{cIsi083j?CR_zoCm1qs8Ct@Qj zDq$w;m&>d&m(yTTfFN*(3RbHEZ0oZs~2-y(Ydk~;opQ~#1f{@t`c zW-2g<0znXkP>Mh?5JyOmA|ME+VC*w8iN$Z)m+gmXSo&s!Us_Hwk_J;6#OM@$Gs1|V zNrcAG&-EryngVGOev>|Qmy?LIJw*`HF+}4yog#Dw(-BI8|7l9qmouAV$M`rwk15>)%CP zBa)8))^CZs?yTZlzqQU^`kdp*F5oe{NvZTNsR~81e->8#kzuj=uZX1kGrbahB~*`G<}e(n1`|GZ`3pYHkREd&2_ z&p&S&`29V9o&y1XNP@@&5u4WvMf8=^`vPms+CT)OH&qNpoJw4E$*MtMK;B%r>JG>>>2v0xvF)(^Ci!@)F0#C`Fss zt1PCu+H4&ikh!=4JfCn12eu5(h_B1brkV{6lU0giGckl)bz|;g6(kWlt_d30#D9p& z2#NlC(E0bM{BKYFuTlA5O#4GSApxQkMNlw~fe48}H~|qPNkTY8e(KkfMQ^Oaci&(n zrsF;70aNd|IofSevR!@$CTI$wQ~Xm@&Imf+WrUJlwGQ8H)IszOmv~Bp*)CrP(+NgX z8I6;B(l_0+yuVbzz}`5Ikna~lvd8oZLT51@lQgl~Os<^{MLPGp3>hgaDD(k56 zo1y;qs0+%)=l^lvtzeD zD^JAkR#R+c*@I|5kyI!G(D`(|@wcWs8N4nCziPZX|4<%g={!4MnV(YFwm)1Q6&!{2 zWmj5!y2|cY-S08Z)qgGEzB4>qGZljXOn3@xTRn7V{qV4BJed&CQ*~Z=U;im5LwWVB;@E!R4y%1TCxBZj{g z?jUhvRvoXs+}k06qBnz_?Dph80q37I(in^{*dM6*FT1eKuVY!yQ4GOx{y1xlE1I^x z*IoY%^#7alexUqs&-p#NQy_%k6igBbL6JCyBM1(|IE*0(L=gyuQy7F}6p5k~OhU+~ zn$9FmWP8EQo|s1BH*kWx-6%x7xj2fy$!?s}DM(ZC=LJK%v|A3-5%qpCpb?!$G=%P@ z)nCYSwp*d@9t6n_z6808nf_AKnS4KnkaU{RIk`Kf?rN%JzAKPI`%!OBXW08L9MKs> zXM3SIxD)YYcS+47I!b8*qKTMB(033(WxGn;-)GOeisKk`_@;Wqgw`w%iiYHYsIS9f zf%bARLd&(lzm!Mrsz;Iglj;$qENaEnA4iz7hp~R`JBpzC9@v<+Z@7xc>XvUyfD5U{ zmwIXDsk_Rof31_|xyH2oQ1nVx{_v9jtT7q*mq)g4F`K-H8vK4@yM4X3>YIldZWHNJ z{j<^hT!GM{h~j14gB}jX`cjF_up|NK>Nsr6iN!}UfRO2cJ7IRY_6T~oDR*AD z94g!%lZV(&@&M%ob zR+$@oC?JUlj0gI#{h`e>$3G|F<}c%khRY4uf+nS(2Os_Ym29IX1nmWBXoZ3C5|a87?8~euBnl zL}nBpB;2F-MfL(HEx0Xz|4 z+A}Lz9*#n{J*d=^E?q6bTdFb2g0CF_X5-<0UQ(&kpC|GOk)V^BLlRuWs7z90Zf?FY zfy+kRnq=|EgO%fBdSM6&KAVhzL;$C<?;Q*fi#*)>iC|+mjijS92TMTbuTCGnNONT*7(yU)=$%6es z0T5g^Gz}RkcVwAR-&8_-T!rzswPb-$#AN@h;^wtep_%E~wIG)2h68J9a>dWbBP@hc%hu9J-hlTd$I@u@~+I28v*o3l79`* zTpOK+B)6%74pBbWtCb^0H!e}^ZR=3q58E6G+>w!Ssl6CUPAI5kntY4e&ctUY%?32qJ@U?NP5Mh5 z6!*CFoa-=%>Jt$i@^OTZYj!h+13KL^1#yQu4o9#yW-oBL<8&AU08=s~Nx2(@Bt9f) z0r}FG)`tK?K)kc#`X7#9`wDN`g7b$XNSSH=i9~2Pr_?x$X$+&|&nX=a@1%>`V{4Gc_Xr(C-f{Lj;6`>K`&}3lPWM=zqBG>p$IxFH z*<;w7Wnu^&LwkMY?!1wvbWH3Qb2`p;dCH6iqc@o&)AtY2-iSwlG)B^S_Kw^m_#O4* zFdgre<1zWBcgf$|bi{8;mw%H1vaYY|8k>QD!nZ_%we-&6Y2*H-O&a|lsbb`kQVSGa&Bui}sCYsEg&>qPIe}UKOiRF|#3bi^em< zN8z*rio7DKtmAjZ$K-$of`teAj$b!|3#p>Fvaao=zE@N3H|1Yfc@r*7-;zy-z6$?- zy#{=}IA{D%?yN@MZebSwIJ{2FV)nKiabpXq2BIUc;710pACRA;Ka%^9JZ%_7p_3ZsZ zA^6V-{2bvvbXL~kl^b>MD47$0opHav*v3oQ>_(>Y=-*c#%wmQ)xi*{jFsRAE7%RBM z;9ziFx3Gb4#<_+y;U1Gy2ay8yA-8--iSwey$*Nt zL~3C|m>I%FL|DbB>OFa9hzlM$Cf0*B2 zy}$lzjD7;!-+t%=TR(Z=2Q0-f7>5X)BvBlvFc3ot3L{CJz#xP|AQB@nhy+m>BR)M6 zP0)8Ri-2#q$s-!aX%wL;^c{ENdj|@P(pXMI)Gqv+e~PCVvIEzy)tf}`a5=?kbZg<7R3fiA8&BH24npv*?Y*II?S0P&Bg3yCr|yQzKs9cnW^2dUAyHL_E`^l2nWd z<{{NmK36Zf{d3^PGaduz!u2ObT~*ZWdKSOg=6yuC%NMb934^u3xP7=}0AFn~ejM~Q zp7bgU{tAhh&g<)L9L?{#=Wj@a-`9ZeF3$E(V(3=w?JmTEDu#$Wo>-o-u4zyd5xjYaXG`^AsJ;N1jXKkb4~f4#^Mbg@_PUcrx?zOm7!S>`*90_zJmXOaZqDL%6@WwXCI_jAJg+(| zJI145%Q&!8>w!vC+SGBOSP!M0U4E2Zk3FdR<;;?)g%SU?(7O zZO4h-E&1u9FPA{jVd=9HFdWZma6(7a*7%$=-M@o%h)vX$u z5v~sf^$LdD-J0Ohddc@3Ik%@mnqS4x;S%3zNs|m72cSQ?q5N%s^3Uzbz(=^tKlo zBX%H4_Eb@OvFgdHVJ;>`)Tmzo>a$ZFlZT#U-bcoXh$?Z}D28N;*3anNQ!vLt4_NC1(HMCAh3kHHx7^{b zr<=6ctcVAiZ~zxu1VsB*s_fZWLBtG{Gi$sQYqD@9j;ovBA5^3dThmKxO~Q;vs}e7m z1*Q0Qd8nsRth5PuTyFlcFL7{lGfHo6^NdSW{S>YyYGj1BUgXyHot3o+1C)_rP(w6@ za7lY65T_MR4TPOxls!WYmi5?dig5wp8@n$UzfPs?u%2gB8(+@1~o!cXXuA}AZE3LQ3UBK1(8XjKN;dNbt0M+5x zOQi${3?xf13a)u171T- z0Rdj!GZ=$naf$PNDs*>iob*xp;U<$%Fjt5rcuU6h_`gk|gnx%Z{qmt-Q7GYa3Pphk zLQ)8f;Rpp`B#OW!jA9gyAp`-TFht;=W*K5^58Ci|%$R00NYW(o4jA8IBTR!3ji5A$ z(@{cW5RHFMp%99WcYlKvdxwJLUe}$)?+M_XMx%Fp3z9T~?Cxeco$lG|G^NR3YR2p% z5_ET%*+WSX-CbpNOUo>x5r~d(n#$j+LaBGSoDzE~1b%;Ng1;9;A@B8r&|a~Q)6lLa zhP?yUzoSqbw{aX3NeTu%^Uxh?6PqE`H23X(Wf_i0)9oGZ1?Z! z)BAVeKcP==_5}O}eG=dF=~w=az!#w{C*dFRc{-GtcTXYXJT&%@P5P}~CnoDva`2w> z=5RM&hP!rd=4BS%<#WfU&+&C~B;x?h9K%9*uWQ+gId{(JlsV)H zRe5=+8y~>LV-L5yky?*;$CTU!c+_i9BkRE1cI3_GADZLFf5>^`y?To3e$krg1xY^ZT(NV~Bq^S@L{jZ&-O{k8hp7=6;WPPTiwSqx6q7`!o5Ol->Og)7wXI z%pZ1CZa<&R{V&e@?X>P!bN-NhrT%}`{-oJW>}wW>=X{Eq>-}HRcM*3$D?s#}fEm3+ zCn0)1{Tsq%|7@52RMqc3ld5x&*xDRNq%!wfD-%a35J4dj1V0Ff{<6;z#y=o}q94_j zQAa-3F%_J^AFxPp8pjS{nA15)Q@`%0!4eujT4gejPE#7fKKI3k9|LqG$zuf_A6YU* z`Vp7#krjy-zxT^35}GXNJUx!{AR0fSAR+K`Gn9Yu4m$Rn9zilGMngvj4{}U04AMB&P^*PFXW>)iM$6`YGr4x4bpR$RZ}ewyBt|7 zqH>Re=PFlB`R5Ka_u?I^y3tLC($*`z&tk2=edl%X)lX|NTn5zK50Gl;?Vjp@w%5y% zF#q*p#j$t(yZ9ShQ|vw5wW>sPS6F`PtPufk7dnmmV#mPUwfxIgMJT&aTYR(c5y#e% z^Fv{{I*hmeoTdi8MAwh3TZe}&gV&0$yb>N7$9(OkiH=1@y$KP2iyYRC0tJo&`MXrg ze=#J(=<_??<~9-?zkG2OkoH!@L~zQXVv&L^{=)a26)>VH=RwHXS6 zA>UU5zk!Ad>?!=@;rEpnajdIzlhj+7E5|Uh(|vNxI$IlR1D{jfji$P?$Pj{atgMgS zV6Bs}*}x03HGk>+tTjda;^jmO_50Fhr*1XhH%31Dam26QkmD`WqwBo_pHfzJSYO{&b+3wQ3sBZYgZ8!m@^TA~7OHXG_O-%aBOB>MI%GGTqAYo<8rxl^ZWKJf|_Ol$WmZ3`gnDHl6z`To>R?qvET!EK3_TuB>Ac0H(wfYNg^5%-*j3wf41V9M$F1lA+K+&BSnx zD>09gUUwQBJ*bEIRyGCnV8VlLD3(XSd4ED??|V+8L=Ma+#EhXrKwS~m#zHlEM~s<> zp?QD430TH5i)89u@3Xae1pDME6aeq#Srs1xE~s~YtXu8u6F|qWj{Z>Hw&h9xD_&RGLtAiFOKGi@*?Wo8`~`nAxL&+R-4g0(yw~5ed@h^ z*-C;CFK<%9n=XB#B}8B=3~1G=vk%n}^C0WShY62_v+`XdqLOI{#k)Z7Vu;KdlYKbXvUCWh_UA#XWKNe$6Oj)57}MmQ}p` za{~F{Zd3b*!2N$m^Yg*)h9OU%fAH}b|KV)In76|p&i`Tl&z}|8&)a{~M)wnm{NG;t zE0O$p-5*3X4#F6SV>nC_BmrR*f>9`e5)cZZFojSUNWm!n%b@W;X(K{YM>{h`&=5?= z(1*~Whs88<_|&BM;m->Fl2jH)?g~L3IjQLpH;&RV{2`ceO5?{=HBQkO{!zU-_F;rb zdbHYQzaf=)LL=};nUmNN6@z@pV;q0va0b!Dq4&QK#w?~m>Z9a|{Ad|GHVi?B11oV% zfrG~^H+Yauga%W(_}j2TF8Z*M{9DktmCIxo$b#cNxQ5l45lLP<^;auw@aGz@}~t5we35d zths<7=uO($P~xznwSl|Ae@`OIMcZXq zu$kXI%I~E7pO)DIaFy}*MI8IN#cCZk>pkDz#$0I6q%_L93+|7$ct-Aq!Yta#BFfgt zMkr6ihdI6@+!hcwG9Dn1yP8befMCskc2n^B0x~(a>XyshHDhX>rOsbll2y& zAxFp}H&UMAeFtu_dnFXc zSpmEY!79rsz2npb*@JvhVdt7kbEAkTSUpoeY#x|BDAM~?$7c~9b?b5aFwDcoYIFk7u1;-$bT`~_$R6zlPP)j zz25$R!OUOa@&EEC{DjIst^T7wHc5a82|^%(!YD*x1c{I!fe<8$LlBJM7zUxgY`?*v z4@RaiofCACe-MpC|BTN958+>+G=_e}c^=a+^-E|@j|0+={ss>S&1tIm;Bo@A0dc8{^O7RrXo+Rl#{NFwj@T;$!fAdJd&(HKv9_jnSHSjma+O`_v#JDGY;^uY-;_hn+>Z_$S z`+egmWQ%|f6fS!XSJS{JoU^lqPQHqIY*ftXAVz#MTNys7N5-Z?4-3IsXGCF89K$?! z(_qd$@PbxUh+TG*{Zz?JcbL*o$b;6HBqLf4XsX~(&-(*%0#?MfqXU1EicKngBd9C;!*3+{xX(l_9{FS1dtei zNAJyQ4g8RKaa@a489&kY%L^A)Mx)_gRCC|r1(d7`V+O-RcxELEYr={_-X#Xw{(`0Fy7%)He*|$IU=x)SH{XnvA>%B zU13e`Y?dZAL|~OG=2;=U`=(KogqTboR1E&Og@QJ`7z#Y;kv)MX(8onyUdFgDbNG@@ zq<=O7Ie2P=GlJ$c$1gY?UCjx*DpayIYR~NRjMsNhQqg4&Sqqqv4cbc{<}Xr&Z5EFj z8e3X81&xSht=IqKQT?AX zUOTNT1k8-;b|5-AdWVIg)32&-o_^)bZG}Idjp?k#@W62(COjUH#i;7YoM(3TN8eVY z=JlowcS8jRLAAxpiB36HHz>1nH!l6xJ=%45ZBXF0wk!#2r-j6l>g>%yDZ;`|4vgCA zO(SE@4HVoVc=2ecqeZ_5sO*sL+lb1r*17o!?Ap7FvrXz!8HA9|29X@?n=Z}mR-bZh&$WvMt5r6lx(#5OtI3piDU8SlNf6Xh9=6|u`YskqV7%S{ zdt1qI4U!$H(3f?4;H3lHV%Z$RE~C zGx(Vy2k2G2_j13>S`m*s!2>2i&Is?+r){|Jx7>8jZiSE583RxF6yIFiUR!CC@JPgF zREj-q7$NFLG}QAfO;=X~dL^PFbEt3ilTR)Kx=tl;VQ<7I+WmTKUBk3^@;wt}J4muF zIuiD(nQjWBaZFwRX#$|^_)mWEtR=Z_bBt|2NkAHdFo6T0h8gki-xa z#7Gc@KSYl}5fTO|9D;EagAtsTKq35~}e zRZrnG7}E&&(drp^SaByb3jHk!9CnUluy6X@6BgA+YgVi4_#(DhHmVabw8QDlYJVvL z9bA@z8=A|cu13&RyAJJ=;9xzN{h9%=V)0L70Wp^s^Z+508cdRk^?$*tMx(a!qyR$O)tDKn!K0e^YPp83Kp>UAQ-Ddt-RK2Lonh5kmc7edd=LLtuV zGtCKyO)`HhG`HvPQ@kfos71i#8Q6_d1Y55++*w0U)^$RPsN2cpSlH0D#FcNQwK=U}OR(e$h+2uLMQ6$1M;jBUI_2D!ZHeIorH%$U*;*9dH z7iQ^O{_Q_*z9S{~rt^R|8IwpTPAoN+;Yz zHWC`W$%{SN*!2;@Kpv8X`>M0yNoxFkKW{$5oFm41y#<6ML0q}u;638brCMv1eoLUC zTK$TQOS!@OTuuP35e9Qsi~JmA`J;}iDUfG3S|1RkEqCzz_8*UZhZZ-Etd`P`y6 zL6FmgGAG$7fofqrvDoaye{@YXza1>>_S^J$hVj4$tB19b7Bwepeq3Uv4o6Hjxl-*+ zXD6P;zOVoxQ~4g8ovR?TP56E^J7~!P0(bT<>Q`w{8T9Hs7RL{m+DvCo z>;9XAp5L0D^`$?JBj|6*X$RH^53_Z?++SJ)qA<2G%(*%H zj)LCTEpREEeAO^C&r$>9GbO!=W_?ZfL?(&W1ovVbtIAg-uA&QK7 z5@_k%(_LT3H$-}!1cf<+z$MdSxP=E-yG6&-i~`~?`oiR1iewfD^8rZ$dWwj%7_8%% zc?Q=z%0yEkIb2TR)(c8*%Q}uDaxWZ8Uksa6`hAyA z>Uq&9pXEtcGj-&pff`%e%v%~S7!ai3b_pl5;#dUQRKXfIL3|BOl0QH{5YL0O?I0p5 zQ%X56#yTTBTuwN-cja>lWg-DOANG0`Dlz!VWX}uF%e$rtk%E@H(_hc;Fpy?!QyzVh zrO{<8#OK=Sk4&VjhM3Qx1#t6aseGHS7zcmu=NYX6=@htSvfC`EQhVg5w*_i4D(m)`Oi-VCB~LH<_}kOzDuNI z{(wOk`os9YQr(m2c8NBT$HWq;WDkjL-z{)gNR<71pY#BKP4V}9a)|I15% zrGo#%vfr~p0w*DYJZAAo2*D_X0C5ySK^O-~45na$LR4yY3kRt8W5)8!xW8#4<7{bh;uH^m}yi$Is8<4Xb5QX@C^=?`f+)Wuci;#C~Oxe=w|c`w%9f z);ReqsY)C{bR17-Wzp8WjdeUw_)j3b6nC$*Y_{i zbm+Mxyr2R<^eaK~Pc-)4B$u^G+NP2Pu?lZ?liZq0zKB!Au}&1|4G;!O6?3eTbUGLZ zHgu53PWv#_RpFV(R~mZ(@2pohyydW-D{9}u^}dgl*|dMt$0N@ihEomDE`HYxwXUe0 z#kVfGPjY?XHlaW=ds{49f8TTB)~qj#s1>UXB2tu=;bezPpn8cZR!Vq7a_NX_z$-C|cVB1Y3h!t66=5*8 zMKJ5n@gp$hO zMzlR2IR`R|<(diB-0^daN2$ifJQce4PMEW{BWoQ=0QE-L7p%P*9z-)RUilV^jWnur#!g>J!KyDdgD4j&-) zLOicS=St{lGat;t%IQ^8l&5H78HOlP;B}oCFwrE!Q?K zT<&JwTDzj zH1)Wo>MDrw_A>$$SOg22e|cq0=|DWFyF*Bces9^M#I_|lEwvnuP2qdj{w*5fTk&st z6TdO$rmb-m0}`&kW?wT`^PFyzej@8lzSr61GHVPKa`tmvdF$mQvdPSC-s)H$@PrrNQ`HxBQnsdf)Wv8(J}U-Bwit zfwPK9ly(7obN4m*{v?KJ+HR(hz45_dt9#Jw=DT`6ynMDFgt=dLP4eXeA641SiI)qo z7n$t}iE&TF-54EJW_g@xik2V+b;Q_9$JVb(U+1Urdc~20D3@D##+UP6N`&kX6cC$_ zgzN)TbML7bzuRWvSp@2v*WUJcXrE2-@-)WQyP@0JUG6KEP0v7go!5*qPcpm#>vDdU z8k$}&Hh8fr*P2X&5ux*tE$(0l;zkK&|BS${>bkl>&NnJS-f=iH%Q&J?<^eboxfdC< zTlK%=eg6rB|L@7!Z+PGT#?rsweLpYzqY(pvK^R417)pX529X3xpdf*wI1EB4hG7JP zP&oc8;uq(1LC|PQ=NOISG=d#23GYV~&8ZLn zqToNhW)YIcj#w%(`!nSa%V<2O^PC1D8YO>2{E*^9)zb7sO3}mZF+HM{i~R6IBtA3` zKTax9;_1I95#nT3 zP=p5jPUP7=-}38u|G8CSXNRAgbpAEz`*1$sza)KMEEB(VJ^z~Ytr{<^+K;5~b8RvF zFQo6o`GEfy()Zzfz<)#fzR$J?{zLkHZM5*sXMr!}^ZQaZqk_M$lwyoLgK8Q9T(9pn zZJ~w{a`|pYxL%ar->E+;FY<^gfn#zD^WrzOS3*M<-;JDkG&gDIu3IWHJv{t}M zAdwKG=`ES?w0dgsVKoA0fNfIM)0w$qf`ZA#T2kkz(8vTH58Xu8=M^tHk_<|>gPavAm zP)f(huXT0uQM)Nj!-sDyN__+@LeX(dXUPY#vGhobM?Q%CXR}K|CpcZ?zkyebI3^si zW5V$m6-?m6nGm6I=%chL>iBO)7buORAB4>dnmDF^Q1r7^B%ukICgabuP|4w04j!@` zrt$di;PoPY;Pw1XSIZZKe}VI9N~B*8)_C8QRDiF;Garup6-o^6?}ticA$p}PbO%yN znWNUQd(ehkp%(Ps&LnN1~&LVod|gb(<*J%4||&IixXkRK!C=3-!5vR@RLh~ z?`odBSYQ1R`R3b5&)10_;4dRR5B3rV$`}UhmcUVy!e44EvY;#WgJtzfhPB;V^s4-K zIr2?A8TecgWGq9dL}~EE^WKdkZeyZ`*y%uF4A)?APn&=kw^W93~GY zHd4u}G#vHp+1N!5v`#=_%hG@}9w;wBO_ri6*56+_Qrg6c&c9P;7{!m^&`Ynx?O3rLM9wgbE{;IvC2M z;JGb8vrTO9Y%@EAJpi4d7Pdmmi}*GuL{603=4PzpJ`rQ(`(6?_Jqk8Pym-YJ%eW&9 zuk5Uc@8KnrvUa`$0Zx{4&%y>B-pYNS1yk5PI_PAq3%J}E3Ws;e8HH#oLCQJQPDm=-Ca zq_YcLWpcgwv%6W>b`;fX@+t_6^kk(yT`6^@y6w^PnJ<#7hD%w+oXUdmZ z1aQ4(AAB7*XjEI7N8FcnI+f?k?3LcUH#($X?D#z0q?>W8sn%z^a*Y)fVXKLGc>WzQ z98*Ut=lMLc7&g4ObU#WF7fwQt?rETeW`@w znak&^lqm&PlP~S@n!^ZXgf3+?EM-()SkcP>nPHYPBo}oFWoF+24Te22&5twvg z8|FeXGQ-x)#ryn!_*|D6mIFR7Bqe)iE+~^MEd1pK24wj3c*C(k$yT2m6Na5X?+Y!a zWO#-#7-j(&USRa!csl(8Q2+F#aHK0Ezq6HUfyd1qE5w@Y`$qI;g>oy*k5%8{!tKfu zMQJ{G6}75FSSs{-6`0eYV|r3k^b9EvDGkyvRg zgmY{5hS&P}c}e(0m0u-KWOKu$xfCY~a4%v?H}6b-k*$>PPlY#NWn5d360y_yUP#Q4 zaprX${|VfF6yEVkY1hC~TY`K;IOX9MFHG60kTE{ATUDyxWr~!JzT`$5M3n#GRLZ_&af+!kR;TI%8hww z>r@5!1HX>X*i0b?f9?}&-+Tayy+P(qUCULIUF_>5my9Y?9Nb8LXLxQbiK2y0IkyR< z11%!L_C+fb@$6jlbbv>I8)oeZ=gC!ag_cTVld;3s^P0WWj7ZKWrkOgly7kmWVX`w= z$F(RU^+u9R19Mq9+5omDl7BAIQ(Wlnrg#KwEaDAvBTK&qbzcsBZa5Yj8G0a5GFwwO z-1pSdF7Ezf2>k*S6fbBU&s>VLVsN0RUJ}r%-PRAnq-6czOmf`|e`5Vuxv9=f(=>VU z{3>)g>B4tF0gstk?vbm!H;Yr@^9{KbCzN1)cX2`&w^@I>y5Qyggl3b7a^A>NYrR?f zR1T#U^7<9HB)t%AsW}TuHaoV*=S!9{QSnlDT$Wb0#|TY9G*Zyeku#XZM}Wca?5`2h(BzQplAf5 zbBxA78ii@{$khLQz|qB%C&!5cau{gGG>OwG_92i&MrX+1aY&9oj48h5<$FonlehTg z&aV=SaMg)%i@;hig~sRdW73DV0QUZq9R!GeXO#7H1-LnSjV<{8N?M_`U~*E06^uA^ zy;My2pBa)MI^HM?K5uQTlfV=x3p)GF?vPJ+&1Dd+3PD}`)9#Q@ci_8=%YU;Q;QQ_T z?QW!S5tvZ=^KbC^S`dLNDhLcG^I^#dk;cymQXR$EZ{8gMe3Cyg#h6lTIC#2u5+TOoV|o z?X6AO@_Og3{Q2U|Q8sf>s&h@j`jxS8%Xj)bKDNrtxBhe)l`BOQS1FN5@=)8rKeaXd z>EEA^8D@zrc>#P3$^2Q8&{K;#KKpLrj!#ZIUpPVSW1ed%qXX{qZm}(?4C%^U^hOd>ytsT%G0UF}pWqDep!9uEW=ovH}`jEHx}!`^NB?TMS^V zKb5y5T!4$>8vhc~{tlS_3TJ?1p&_=p5Rj}yM^BZ3R^gK!CXh*}IGldSzCmT8du4LD0CEPUD`s(PQXGcS$ z_RH?Tp9{ahUn;*Uh+7qk3cy%_Dc4O{a?E%cT>5B4} zBiVrBesNXaTsvwRLU)Nxg!Nk-WW4TdvTAqI=RRH7cnW9y<_h}Bx1AGkd7Dm>UgxZh z{dnt_M#{yYw9N1hRaud}F>*}Wjvvf66-g77IGH!E`XH`%t5ea40!XgN&!_05fmO$? zSO_}l+gq@}X@lT|UzyNcwVC%_=GF)4^E#6@wBX7P5fH&8S|$NS(|dO((hcJMc8$lv zrAo8B;Ean#V~kSqZF-ldnZj&9fVHZ;SJlNL2zJ%5^95HIW4aXZ_6?n($>t-rBS#mp!gwqyw+ZJe?`qn8q83J~8=LG7(n@ zBAnv(P!w<6ZA_{q1q*xml#7a@3ZDn41z{Q8?^nYDyuRO=mtUT&Rg2ATg6vd3Nn$WM zL4D1!CWy~AQ7r)nz4$f0UGRsKqopSyyv+$O=>`~qGr7WrgU{F2(Jy;@*7klj+C}pX zs&KNbHCtu~9}ao(O^B^k(QU?=A+ITQGzS9TD!)HUUN7v}iVSXo1w9PV4$C2phs%41 zA3rq*0^hm=|7FA9HR&BE&PRYW#br4;0jZo`O6I@2$~|HCS4~x~xA&H&-1#&Zt4h^s098P8&rm{y$cI+Ft0seCzZOpK)sev4KuSGB80(z%xDBtI!RniX z;5>}=m;#dGAlzpSxW;dcy9N(^b+1EmZ;7?%Fq22gIK9P5k@Po#?9Sf0oh-&4 zD}+i@&&B>MKW4z?J?UDi*POLSdm9;l>eOq?-J``Q_vc0qlG3fbWWc-ID3)F-!ML`D z%Urgx$OP2^9MX?CCYRqjYUAf zol?-Qcmp!|kfUm#j3B(*vor*of#SH*W`WCEW)a3p@1hU*rM|)Rxe{`w#kCqd%YL8G zK}aYdp`gNRd?=i`;3@5aVS)`p!ezVi=7T8FpdrNZ8ghCsP;xX=RCavYYJxL8R{PV)E?AVttv?hT6F#fOHjrqIF$1m<#k8%4? zDfaSyPOqOh)W5&`E1&xQ&hP0INuU(+QG^sp5+F%I5J(aP4B`|C;W$O&2o6EN)`H04 zc8}6f{*hcr`Vnqfab$NQG;xI2<=}_$v|8J$3Ma`-4`7)>3z5yd`?2F5?P zVn<|Ame3SNr^Mk2cDUllzY8SADVl(fl5tK$7#))|o_|OfM0|uGMjYcA#OGJ&2)@Tr zIzC*a$&`i*I*mU+6wpT|68VSBq1b10>CxRsfPY7#xXVWi#@|c|Ei1cbV4(IypEHZI z4!CoYyuX%f&0nS4zceoWN?A(hhJjI_Oi^H!9_&|HaLlKcUhD7CP257bECCx)<}6@V z(Pi9kWJ+jUuTH;Gm{6;Zn!*?Bd*1qDR>*&e4h4>jZo2B#my4P}{#a9Jd{=YoMfqx- zxUovo*-hGFO~$b<@WtJ$0dwa+CD@o_rL?7>lox!B)xMG|&GB`|{;Cbda{FjQ;Ae68 zy*AvV+3!$}=cYw*X6@!wSh^$mfV8Q|+n_X#%MCa|y(;SSBfas$RNs6dYz@3j3Tk`a zq^pCiskfnwSxQeiG~_w3v+^3ZM9WA8!89TT$YXg;Uaush&daHm1|wUctt};!0 z?6v;mKLq^Bv-hizEQIUrJz}cE&v-pQ@=Bw|2i|Nt=6%zKz|Z0^M;gO!IAN(B$-a+b zYEogF5#Tv?9X}3BHE?gby0TA*Ef^=e0i%j`nHA5%1A|%_AwSyiarTi!cjYL4m)y2b zq5^h0?qVM9+ZfmK(D`9${>XL98v@Qf%EU&lIo1hIpfM2(wfn~yCq2xo{7vcoe}7z{ zKaBs&-KVa+FYzC4-sI`CJw)FhztD;Q{_bxrDu222hx0Fx!f_af5flbt1f>WPBXJD- zTmdokc!45**_eWVX%Ie6qwu3bnv+Km=aH~R;75MuVINQBboT4YDIU|*k-!m?bbh31 z=7({>2VRJeR)nb!I-%4@NmBTq@gNyY^$H%EI*&ER2g zuR(Jad0gf7tbOGn|I3bK^XHCa&)HNZJa0T(D$K_65a(w5+=Um(Fj3O91E;Hb#C1S3pdQr9=ld|+FB&Y2B zjGuhf6VYo!9uw7wDLzdrhCvi%wHB5?LYUgz1#(U}&_tyj^>CnP5yXUi`93>B7%sZh zP~;tpaw|T+@258!6vFgiypzja3HVO-h_75CzS{w7Afm3^_Cd;nNZA?cs!bB+NdsFH znm#ZWCDNXus3MjE>eFarU;BI0CNX=xzshHb=i14VG1=}Tlho*LFh+F08#bt-s z_r^j|^SV;6GtsXVlBOIixzb>4{2SO#SCoozXPAroU6{A$e0AH$H3wIF)*FYCAS@D- zX74qTOpx(`+tFY{uZCPuy9JX7INy*IdhN_8!Oft9XTLq&PeoD-bw#lq>G(wal0hnA zNV80xXEmPlWpF35RgqhJEj1uM$A-}6E%{bLjFA;#-(J(ofnddoWWFN|D-}^urB_h* z=QR#i=IpDNi_mx1%XtcMpcv$HkrSl4S|{uoWZvb3I625Mi@-4P{}}%AqoY09rNODe zpXWKG(#(HOLv!KzDtr^nFY?a)yVpTm?__~QlQ z6tqIFY1|i~b*{t8N)Le8_3P`QWqb)qFkeUsPJ#t^V&mO6@!;BMxq@Qn%xKtqVo8V@ zZ=!dfVn3hf%Qp2X;0Rd2`QZFEon}|8YnlFX3!>V zF`)~(u#}qu!5%%Ms^yzU+CGL#FbX`DZ)ZP!Ca(fkn+7B-MQ52oXCY3;sn|ee2*yZ3 zVlNkDFM)@8&C_QbF}ZQ>z&aYa+sSWllL(uQG@hSlFmL9Q(6XUh4;nXP%OmQUHCLXj z2$}aMpklH4o|LPkEH|FjXG1RFi7deYlX)*_me+Vzsi@KO6f$NpFDwvytB)Z(U0!>o zzC}RKNi42~d`B+N=lgnLp#k4=X*OX`D1~&hCC+y%v5Px95dqm#mH542w@CfuiHXHk5MKh~Ra*O#JIMMD^QSaYnccD$y|0s-1xO z?xS6JW1YtVik%>A6AG=CoBTU26y448fRL|; zVPSoBa-m_tf>jY&Mp@4IH7M{oId3L6CjRv);!_e9i{rULtrYOwxBbPi{zY8xcOLXV zc-0%;_rHB#Km7mxuuj$^`axokR9noTi#=lTpc zoO9V;KWod1wKT_C-eLO{Z9otnFC9&vQ}Yd?5_v+T>Zsu9{AI4{<{~oZ!iA& z+MfsY@~XMQ{?!cs_PMr~3!r^*$zOGzL2ln|?Vs)p_}$k2$3#h}X)L?w z9K$&1+I4OPFAe`9C&R8&26v`*@-TL(Z(D1uz!WCvqbXRQ#JE#u+$q@S&MUz(sxqYu zab7p6xm=wd4uo^BJJ|kQvhQUh@DF`!e~^v7$`WtyhN3ll22RUsIuYo;xm$JDy`O4| zGH)-;Vl#3n*A$q(oAP~@+V0BSSf4Ex2ql1|6+wbP*;PeDM{Mq8C37+tXZ}TJkSZ%Z z?JUCvoRvL_wCYw>;Hvem^-hd4(L_W0&mqcnz954A5pkF2vuyG&Hgbng{3FeWKU9_b z8I%6;UEe_HKX?2UbPyOsK#G8I6e3U%g$NQwK>`3jK)}ELWs@v;gk@yl5h@0K#9EAe z6dsNo9-K#Rc1F?|OlK*L{(1%>KdeHa^virIjU+Teeirzm%Ag~7J4ZekMCLS}&{Rfe z6iq_E4};98WBLF&j7Ty%C;n{RrH&2?_*exymWGm#m?Oc@K68jpi4Q8}hat)re^Zh? z;IcT5!iW#%rN!TYj_B_k$LyycK&OVubzpVnahV?CUtE@#kIa*Pb*S~tFrB+=kquLG z1h0)Oe)SE}o3x8wA?)w6uxi#Wc)(YOd1lpA8~SYTYjD}us$jV2mAw53HvhSHByZfR zFWdQVb_0CBo&RY!zf0Z*eigkfSXWh=jC+O+1frfi^PT%IkRhK1%$)*oW1q@O&9PRT z=O+LYYp=fY;EAs4$(iAy=!`oHuc!1DAkzsWd-FB3S0(84-s@*n-U{`lUeb`7gEk-* zfNO|%d`-Z$c}ctnTG~lB2HU7M_C7eLo#Z0^LtkEsqe;)ibxa2zZ@CP^eP1$a!)N5)N+&W|G{MIp>ntHw~I9Q&Jxu`3%Fk?Cwu>=geKfKwy zRiJL^YOn)t{7WNNr;W*NblP2UdeAYO4NYG)b&5GbMxI@Iy*|t*8a>}65T0xH6jW3W zt;ng1rPH(*gN0#@pM$fL%up%W_!?d(6jjGG5FgF$4dQ!Wd&6sI+ZxawzHyz!#?~2b z@85=#xP6Cg{2;Id1{&`dyj2wfD`oN0Ud7q32Gej(90aR|VW$)fEC$3}&ydR#TnD*> zK7{>)q0sf6t_a>zggGWf?Z^)HCUBTnN#UY-UZCbd7T#(Cd;u|U&PJOIEc$Gb)eL;t zM->Xo9ou4_C3|lB@;>(M+9X^vS>R2`-cllzq-C%t-hbx%$$ghjuHfH?ow4Ga_zM; za~e#4%oYK31IHNElMrU*3!2lHPC63|c1I3j`PlMa%By|G#!?*{TM>Z&Cb;bVHUr+T zGhCxyYAYrhRJ9kEcF)&sqLiDLdDzc`%hbcuzNRU_P{g!43Tk~ zwnPKxGn8wRO2K$-3=9Ro=DG>cJ~ubbo6#TiMKQbMuhrDC|Mp~1a! z*vn(=4zz|fAUX$VPw1)#YH`bI^h&9~xhfTF*(k~wj=Di#uet;aI4ZQzs|bTeUgGR( zj0yiZK-yR+a;Ly#aqFloKV4ZuECIbLbLrslTQ##zD6xaxSE1WrQ`rP7VjV4UgN6xA zlZILn{9c^&CI+b`1kiqFLNig}9u#Qs3;} zxEvie%^}oOy3N0o>ak3744F-XtJDJL+am9Le-|z57!4fLDLjSEkd6xbvEoRyE``+HA=;~TY=F^V*rk5bw{&*!IhAI#g%^b)IYfr z@=vaWVKfH43$^_)oQ5!jq6vil&{Q2R7?fr*Xjl9YdmE5uDCAukWyx-jf$vUk`I~Fx z9~WqJ!eAJK(Ql50B21n#dGTg8Zw8hzW%@3R$drM}-8iFQaDsv8cd11GEUAae8Dt;F zqIZcBo$pi*Vo-dKk=-M+(>>RlL>X-Nlq-5f) z%apPYxzei-4UYGd=OQ-Gf1LRKf5VlO|D(8)@+VwLFwqIQ9}Zi86l{u{&q;c0QOS#P znv(J$d3l>R-frk=;-|*|v}HP9VlM6ci`#DPaX4Vz%LGsPz4FKWFtFizmMQxxpTR@c zmeuJvPB`m=9;#JR?ZyBhG##n>O@SsC{C>wT&Yix-+u>C}2+^7ph*{SaMLDR)wH||x zZ8xYl8stKn8>5LG0i7p!(0Wn>muapUDt9VO6PlRUmn~4n3%Z>y&DqK`PeZ%%elG5L zfz36kK%AMs3i1Xx(WnMxp~;BqUN~)=Z+wJdUFqP`JwLwO!|7OS9FO($9Sho=?XF2& zWa$B2qtP0}3MgskBEZL!B^-2QJkGgM^NA+ov%NjKLIp?Ir}8QtlN+hux@z{$PuiOY z<=(mQU9$ql}|uZy+4eRl^pj!Qt+@#RWOG%5q-Eugt0a^1tF+ex79MEx?iqyp$h|8H`chzEW9yI5ZR4Ln zm65qLEKWAVR%W)%aEUKcbYJoAcFIFfgOicsGcoQ;&<`}}Xjzc2vgUfB&D${lPjRIY z1hx8VmLA?}$U*HMPd`wXtU&Dlz?C>q+Xhqyrl(XQZm#q69NoF&^J-u;-X6p3r4`bR z$Y6Jj)gzK7=s4?`qE0#0IO8*JUvUa{It4&?^)lPuu#LiT%_>iXqxLD8LoN3l*k&`9 z;oW_XFmc3jJ>fXV^E3c-$WagM!>kcPLy(;WInYxYtW}!ifdLh;4wH+AP0`2Ppe36 zZ_-5gIC{A`FEw(WVd`lzY3miRvL`cqk!NB;Rxh(BiKfe9im)q{j=I-1eh{>EXs^ZL zUd)(AXjk+hzr4z2lPf3{6Cke&pMibFKM#2zj+d>ZD~DvksG!o|g+$6Z9{Ax{v|hzK z$coceT&wA|N*>)SpKAhGPGWcC&oM7-*Yf#_tnfhSaiwuZ-ww%9C7;|ekf*zfglC19 zx{lmPNli%qPU&Q9IDlt1XY9&VOQtrrPSdG{ErsqGO>M!a-ocUsgmT@2-bBj6G90;7 zcD-c0E;bX5U~UDd)=>cwhk{Ocb{ypCo}jD@PN&yv#*`|)pN&`2%owO~f%p_DcAfZS z(`hJq*$2xU1Ash5UN~I2d(jAzP`-L{azaVvC?s`j;(;}RUCnSe=KK^uDHbOg-@}P# znd!s1utozA;fakWGWLQn#0J(m+$u;c)`GPC9M|hmj?>e>;7aJf;!3}I>YrQ*{eUac zI0nHmN>DgLLL`NgB!(i;ha&`N!4%}1jNlXl?bcuz!Qh_;wQ;6^b~SafX9JQ9`SA!r zk-zUHVTOVjBxSPQ+ajeIJY}eT{wm+)GX%w;<(nmCIg>zdT80rn6V6~vPBF=zY)~K! zL@_!2=3RNpKsiI>41qHU#L)ZM6;{0IQbD};Od$+TzsV7m?y-sJdp8*JW>^r+K*>J2 z{!6aJ^B&K$G4UN&8kN&av8qNzAo~2zL8-6A1o%^C@*^<;K4vERZ}Fs^EB!Y->Af4^ z*E~u8j}b5c%i5*4nX9=DX$>-jHFyroFgY5gY-H*)%HN%Sh;qWJAohF(6R3e9IlR|A)<&8NzEdx zAe;~Y}MJo z6x*#Jk~b9Ld(vuwFa*lL$bQaFGgPtzExrf0?CD-G`u;E5QL!Kxs(j-aj(?8EE~xkZ z;Pibn`AZwd4-spY>M35HS@z)U4@Nuxwca!fw61as)>iQ}4+wAQ1K6ue#U zW%sDP2*%^f-M6~fX}Ceou2d^$)KyQeV6$kG1IY37zeOyU^^EkDTeNCCtpKrB*y@8P zrP_J@9}tTW1+bzq0ie~xC`Zrs^tw+TmYsm7dW=_3`??80&0djEiHMgjZvdw*37GunFM`(!Ct*zWG_R> zU4QT!;kOaXE1GNawVyvBf0>^z9j|SZwE17=TK@o7zxl}5RDmCE|IR-ap(q-`ARM7d z5+Yy(#bE>?5qekl;VAy$krcFxkdur_k~c@mONPRk6lO|{$+NvbmN8|v%kk*1mR~>4 zr0?FWS^hbL4~O2El3@%+G7$deNOZiB1kI4xK4bnV zGdkV7c_l+r3`OsPWb6%E$evk+V{hof(>EB>Gy}s7N$ryl=sr16GDPxTEu|Rb*OQvL z!1FBp)#Juu!@N}K^iYh}?RCP`a1M(fk7D@QXLZs3F*yIM>P|OH?3a1Sqkj&UN9=M^ z65{=C9VXIvQvdC<59~(!QqU)%_{|I?hkTwxUra$<^!m2wo(~(Iv(KULPGFy}0q=|N zt^C`a0N+{uf4GzX?B)u5FX}tl)?83nJJ|`|Vpy9$aEizutVvaO+)j*E7qACVh^PY}N* zPa0^P+(+b#NZAW|JfEt&sI?Cxc`EA3m=k_$UJ7v$HKWYK05{T<2v1^oGVmqdJi{{u zphd%rf6XtZbv#=!Zeu4Hx6Hh6CcHpwwHXvVgE$dFVFdJ_1;^?Jc=yBeG54dDeRu#V zS=&8A^~BMn`BKj8nE)@R&GGv_z1>suakQE)1w~|TL%eH3jjHR?AZrk78zaOzfRN^s z0!t6oj$W=+=Y94fQugAIWEQ8Qr>Wy{Te_Q66`}Sz30EykaP?%o98QKFzQqHcXf>IT z=tFHp#ls(~rvOD9zs0eIuvI9X+IdKgS#a(ce4_)Ralt|{E@}C2ZBBX;K6qM z=NwFjG>LyU+fWXWkY=gQwPILdnM#(4WC-B3ua4s+J!MTnhr?L`9%9@#=CjN1s(f8I zkAp5zYHF^RCL@zxrxVZu!#xl!Vj|&F=yoEA7A-#Mi z!(}~42yf#*2mn{$W!hVjJdPJIrC%IUz$zxKd~Zx-eUE^Ur?cJ?$`D{NXPRf zg$P=b!;`XgoC~;)2(Gs6&Wk}=+o&}|Pjwuo4a(s6SEm(<1HY0ORp#=wB(M-}&heOc zRUhj?R~$6J^VG?9DbMdTA6{Nup{Wk)4s)7j$)PM}Oe&&a7^pbVRd%g-TQ4@mLb6PH zNt$jR0irk!(!;FK+ZcD9ec+;uYig7nc-CrVg)c731SclpN7qTa4&vD-V9YZqBLOf$L>GE;!_fA_QN@Zlkfli?c?b zvx~c){r=dd@PB!Z?|Of6&R6OK|AjyZ^q2YmyS=!R?y39(xB7#}zVNG`KJtC4GER{Y zg%C7Jp)`V$1c6ZmNmCR~p*W2p7)IgfhZCA9{^nU&y4O)TQ|>wz9A}W7g^>sYB}|Dj zB>v_pUs8~NU|VqcW;ry)l+gR>6n`&6VtaIQ{;t-5-X`-o%Q6_W`fu{lOId-T}Th zAE}aoAO^#J#kP24<9YVZf7Qj5`rXnnFG3HUwT58=L4(o!vrJTeYygUm_qSY*zv#Nd z!=F+oc}`A4Rnc8#Rz7?CiAy7%0>=e{!0;7Ob-&fY=%4&o=g(f>wP*m;6z4_~sA90b0)!lyFwOObkhZ`W@EFW@=ezkV~u zDSWn56+X681-|;J>gj1&Yv+J@@O`BDBQIQRWEk@VrL@@;VL9>CJU^Szu}K#4Ztzbs zw_+FA#>;>c)6Ehw&|$Bq%{ebCd2sKgdxN*d4vw0Ai4Clg^0r%MRq|liP@;kiIeM8_ z2(SYUPseDqpC-@R&|Fob`db;tvgwH01Oh>7Bqe)m;8Y`cje9*8diYog&vVNsSwqPw z(m_`wQWuB{ur!vq)R!)oo!PunQ;e$p>244Cr+@J=y$8?Q)}p&lXX8lmqW zyHf%&axC?L+JEk+yRoJMhj(&OH!3@b;Oi2DmrH!O4wvZS-_9#`+p2?flM|aedv;Z8 zCyZRI?id2I_KHcT7JH3^tf|`UchbRUn8EE(2Nl=Es z_NYB*x8W%n8sAS7@%KvwBlnKRE_FmnCQ09Khcshw;{9TJKMudKJboL-U{C%9iR#(1w4PT=XER@1N0kMR?LHqOH z|F6H4Hv3WR{>Kl0#r*&D;P-(HFhavH0U;Djpa@1&5C+3I2E!zYLo`mpD2|{%G58>1 z2ErI3VK9_|_r7pKyy3g}B8^BACfj?`Kcn~Ln`P$(gYTLA&@PuMXof17l6cc?6k!m8 zA@)Sp4BO>W#rsWC{LC;Mf_G~V^v&Bza(7%q-tPP1f4IA~s{ZVvAa{w=ZfY*>@hm8EJMm@$YgL1RXQ@ zFTk6@f5$9{i{Y`~z`u~km`j$#g20Z4yO6rwI`=rEQ;JYraqzq-6C5g6uZK#J` znHYb10MHh6+heF(%!Thh9Cr!{2WAnhpOwnrLA`!-oPaw&H?ln)UxdOdF2G^DQgX-V zAGMIaNlySi#V1s(F8RD}^J>z;GJe>owDAQb%zO1l2+M@3hqd>nQ%=+;r-AOxBVLT! zT+cRes-#O{Cr;~M!TE*px>yRwXk0o~I=g4Hv*fLFs^oOCl!aB@JnpaRVK% z-w%_>t~uR}YcXigLVy{%cr#a$e$!_pWuW8@w@Ajo`5PRG-2j)^&sVbDw<*aP@|Spb zJl8zWLd4&AXWgMftBG=WJoT+m(RQ=0AI~%!KiYi!9_D#${RQ&?S^OJ*z6lhBbm4}4 zp}x-Mf9inO;;efj{A~vuFogJh5z=cNHa#B?YtHzST>&3$>vwnc2LTEE23ek3I8qLl z%e^W}9WGpoRKx?2)S-ELl`Z-NaSlQ)T}7X~J)Wm@@ zzN&THSqB~x;t?K2koALVgKJKUgarzHy-Em%RZ+5;Q$KGq1QXdKPz1|44tl!r1x0PS zj5`9*`Y@QutN{xz#{jv$Jx}aWHDZ#2Ia3ZPaW;ce2J6Ud10j#DCC6Q#_i47Gbh8Mn z1A1MiN#YTC$tpdTE2L#&FTCj6biL~cs|;H(PgDy|$I{l1$*lF3>o^r9kS6JY_) zuL9jh&?L>Z$+KsV9ga0kUN4+}rHYNtPfmOdMp$u6qCKIvSv`+LvO-|%P2%y8<-lp0 z){RIhY_a?1QC;ej>kv*;RiH9!^Lg`)FgEA(v0$AZD|2@^YH2#kh?n+~s!kE0tuY9? z-ISG4sGe|8KVw!}TrCemY73-bVxZONCRvxMU2?QJNu*mxSCDk7lYPDz1rT+CwGEf~ zDo-YxhG9dOMp+{KL04{b)^VnPFuGp!ZSIhr2Vdv?G^7T>apiMp-mDWaRGnj{PhCW2 zX*iP>@g*SP1IJ|F(=*aLv#+J})C_(kmNo(2RX_BQ_!BFSj|;DFyRyJ{L(UR^f5Af; z&`%YC2K$-Wwc*MjB#HAyl~8LDEHx(835p>k6EEsznE@$MijKO=;Ik3VYD}z0UF2V9 zZloNUHSVRvRb*e0n_+f0nnor?;>X+dQW|5P;|3`MmND37f{>PbF`9NkmS%$Hy!RhT ze~zmxwvUJCmao}DjIeK`_arcaO=xJO_nja*9RU*?)q`LU53X#EhvZy(yrOuep>r8M zS{n6~!^)=T!_^<{*BuftZml~tR!0=6hqbc-M;s(>b86C)aLy#^JN_K;`iRkHcZEUu`53iWD`5eMk zmySzva&t>SoeM3Q{wwxrVLR2s^2nVD04<}%*}_8I_>9GHdU%?ic%B}s@DhUXn%u^t zo7Z)RrBC_*fdNTct*ht@r6?DSOb)<<7$y=2OHZe`QBt4EhPJ$quoBwO58cW+l!B(G zeeb6;N3gdXTlx4|=N1T-3wCX0K=(5+H(38Tb(d>(3a-`N&sTB{-Rr45@-BZrW2R!j z%PB~noGjs)l%Jc(@+o(M(eMa7eZ>pL`I2Lj7gpP|85(tciVF3}$n@Nc67Pt0J9E@9 zH^`BY?k^EXz|hg}FXz$n8qiH;@esqK`mBoj2t7jTazfO{lZEk_>H;ejhwel@e7f5b zeIkVf(?L@|AAXx;y~$2;ZJYHQE&SJOKai?l-TQ?^{o}sxm=i@&D2l=aOu#UP;4q0G zB#NUHgcCT5Q7DDb2>juAGequ(X4swrfG`xvBoI?3Z?=LGd$ERn{$oKhF!C{Vf*2gy z)A&jTq28RR-1%0Dyy+LQJ9FUBo0)y;;bhsn!o!fCdqI-qrvVuz-_6ai>|Mq}I|E9x z-5NV(;9VAm;S52(SBEeL+TFWx_+2D^N^XXb-L(y3GW5+2iG8Xu`K1@+(b;&OUB8x! z4y$0+!5{4`yfixOL9l4!!-4%UX9}>qe->uqK3VtK_+lq0&Ls))zVO6E=c+FgdCt2Q z19Iv3Nbd{&54n6T&W6A)-_oQvOZx6w&C(x{H}_q^eWpq3r|76pAM(vCjvy|_of!df z*o>+C)%nc*qts-BMF5xspJ+1OpftT7))R|5x{?b6id z-NE~5s>o7LiyTOftNWOuhMGHQC~2}AUAfDW={O4$i_62)Skg(60P|#>O*dp2`(Ri@-JIq|NcC&B9-&oyhVl6XpXNS(lzt&;j=BO=GjTqM}EAlcVOK3=Y8yuV0F)JHSlc!rxKAp6){M=J*mttY3! zhb%whK*lXn1j~=rE3*j29|a_rh8R^Q=0RQDX~qLXH%WD|_-1HULnx$ZSRRsqXM`iy z)dpsH5WUx+Vl1u&4~<&MC@-8sz2*4j8oBP%)YnUjo0r5ng<1bvqN|w&p3T<9xi$k8 zAV$v5p0>kXsZ*^V)9Dpn`lB(nr%QEn=yL+z23obXhK%|piiLn18vpgsZ_U{;5{?BB zzD-|^ikK@j+v=!6q8bjTLSYkEHeoZ|5gSB2oz^>oKvDSN!!2N8*b96C?8{~S3PU0sn4_+=^{b! z#0ccjDq8nUr$4e({5(1{2E{aTrzF5kD`ERhwhb>R-5@jV7ht6(hMBzfEvlVWX%p$QUNrjjwR{)-0>n(b`OdFeYT}RwASP?eG zJ4Y66jsZ^(F?LPG~rHB*gZI@ zPuxe)kuell(?KNiRhgm_EggbRxHtwMQLnS;Ewjg(bO7p?SmwYPlSI ziF}0D`hG6XsIw+90c}CYhczW?V0$c$;Y+WV-dX7DWze9@HeAj= z=F5!)_mb@k(j!tIqg?u1(2eaqKdr#Z&)W@G<^>}3v!~l z*Bg{x?O>$|J9<&cBBjrHObEaX4%$6wxX>=_onw{J;!F@5*%iO|ag41${4^?e?)`&SVHvqzt`hh9K!r2vLeL zIK|*4gM6~0-A|{8T@p_bZ<}Z#n1cG@A1zas{^;!dkEqC-i2&bFk>h7u z*j4vfNEgKKOt6jm`)j%Y?X$07UB^bTU>vXx}n$QLYG9y+f92Stl2^J%T(qtIGJNwkcMFRr7?kF0&_Q5ioa#j|6d z>uq#kQFl#cDdbtgbLp77A%JbfkIQ_cZqW;wIK4)L#^jEqwX#Yk9W74J>qIddu`V3s zBjqyiv$4*POv|XXidV#e$?NS&9FS3gD-5_4lcH4F&w`K^_9U6%RS^11bMH! zf?*2&Ffa+u7&>8Kf+@@0g(G`cLs-sG2?Jwqa4NAq{WoV2nn8#U;Vj#gU>WrW9}?T$ zuyKZfnFL|z>FtShU;qd!0B;V&!$lbLK zXE2yS(D&xC{k$DTn4Em0CJw)`FG=17U0E`D!5}4*W(-#D8O8`h|8mmrSia#5DZap& z%9=;YfCO3s@%G14UxD>m{Rn*(F#w-b3=dm({aN|qroSwn;~SRea$hDuydpB7a|myW zXjrG~q6eZq>TWgzs{IAyaPJ$}eIZ5QArJA#mwx-F`p*$;?^|iBhyc0}FUBS!U(6Zx zJtXe)wVKO+sQ)xy5F4HUI;WBWJ`@NZ1XW+gLwvN^aw!%F5Ro@%kxdH+jk zT6`N_0N4mUq){+_8WY&Vhj)CmA#wX1cWmH`JvK%)t6OF>S~b+u=ef`@A#*^8*gkl^ zgg-1H;>l*%Zrsp%yxd1yNSYq@0{FWyjR^F*OvBRk*B(D6{vo?heRT2_ZGoUy6}$rZ zaEaW@=m-Zc7I6PzZngl!qPDR>^D5f1O(<*`Tq(mGdG1BSiefsvQ8{SbXcl>1a2q{sLykCfvW0*GZes;IsWp6v zcoQxnp*W0!^T=b}j*cWiAD+6b)H10|Fyzufb30REJ;WwB5(tmLYW^U+o)%wM>E1qS zO_6YF#IDB>oLEuPNPwDdt#bgKtJesN0T!4qfq|@7%?kI(WceIn-N*bgy{1){T+%xu z*{jKiI64JSb}})bf(a-gajtAKHTNAm$lyc_#S4Fz`Da|yA~_FN7c}C652pSJ7l$Kh zNZCmyV|_vA0+0erdyq%%=yKsvW@!ymdI5(5*)LcJq_Mk=EiZ&R)CWXL9GsMt%J2IV zRn_{~iv0i_P?pS+?p3UDOD!)Rwfbn(1=-AV;t>o=2g$PU+_8c0n$D8# zm(~(zm*mc0Z_qKMo-4UgFXH<8NuZJieB5;YCklOX#}+d7sw>z?UCcf+hBbA8_+hpW z*I2og=VOD4Vb~oKH+0+K=5P2N_dD5o-B-9pcoXM zv@DNaSJqk5LTgYqr-sUkw6C9CE(V7?ZTK)ZLVefa*Hxl#r{i2U^x>HUbd*LD0ICEP7449{}xmJu5}uYV%D)K>40=mvEf7 z+cdSEsM+4_Rb`klv~r*e4_<50BjSp}_5{H>6}guHAO@ecVRVA{zSV8LFh-HiTVDqu z|32ohGx3%j(RF-TI99A6+7!yx5$1S4>grhmK>$8K@1@L+8SGyO0|YDbmRq$_z|S*% zvW|BmnDYl=nbFl>wSyVF_)gwlc2_7dbxM*P@NyN>4fy6eQCeY!0}~*vNu{5$^Fm!jj-d#Y7 zeP94X87yOHib>KpKSOtU2Kg@dK4fVr#Xtpv?Bfq<$>a!=?$Y`UVv3T%2qvTV!*}vs z3YG)|=M0p;Sr+!Qbl!q|ld3e|x!SH3A+UGJNTU1LZn|^5)W9mj@1QS62Fs~ z0{@<&^|SU_^Dl_2`kxuvH%8YsBrcy5dyzL81B{x5bbHonpG;~DBSX{1*+v?p--4v#I`#y-AOtx97wF&eB%Agp?ZE1;*dnH%hZPU=tTLj+H)N~ zT&$wRTRub~D7 zZGnBRkO`y(6nDem5pI+Qc3t`URyvXxR?k80PZ~$crd*sHy}v7|ICY`t2B(;W3WL7= zK4x+%&;Iqv(f^B-;EigWsHln|ef#uZtnbODqj>QTF!?W+_=1cdJ^uZ87m5=INy9Ks z!Wf0pI6}}6g~AvGV<<{eC_)j?hvop-ZjVIoUXvL5xi^XIg)2ld)SeoLP)xaJ_0k`E zd*}EYR;ipJ(>JW9$-8PTF{U8jK$Y!g-bA|F|C0=bGBETmdJ&i*epbYmC_~WGl)S%2NQNMGi|&LWk~a{)i{_F^afVD7vSiR=m(8W`Z-?HcYYDl7f5sr$8&q?g zNs3>=bm5*bb{2yC{f>(=oo&OY{%U5%5-vZUWHKwz2 zf)l8|>z`E{I{J>waY5iHfCsB;aJ((D$EKgbM?Z?HWz=Zh z9=id$7cU0954S>l>OjqIpRdh<@XtKrzb9%tUG~)@;Q9~MyJeLP1#TcVlIt5>Ao`UZ z1imZMt{XUK-GOH5(;Gk#IEQy{2B(N$G7%NoT0dg>$;gm%E9DScxth5#z5o1o`L=$tj=Y1d+%}CrYGt= zFyS&}TRNhs6EBEC<74xXQ5eNum!%A@TQpwO;~LOQHB%-I;8fnKykW)jqo(g?+J(c` zLN7Nryt&PR(}i4DJ3*Pv=~>Q}mMxC*JY80p6RhMRR1S~~q$F8q*}SUUWj#@ga_a)) zsy{qdJ8)UJK4%n+?(NOVF;l${p^2<$zpABeW0EKhOua*r%p;H%QGv2RtsGrcgL_@&~^PWJfml|!8PpW|)7mR*n+x>95I+No{ z{gOKm)lP(0^iVF2-V1hurE(L3n$hZ=3>LHzNl$30T?;YRhIA_? z(^Gkj?1$3JqL-Hy5#IwM=0cP_0HIXL&!QoawCzBcEuWMI%{ti;6J$*>Y>cO6`L4tH zebe#?kOx#p6zHKjI9{^^;8w?i1S-p_`jzb|HiU&RCaoz^R!T`Hh5@ zTF02JFgYJEAa;17tED*f%MP-kM!p1`V6x934*KccfbcWe4srqFj?ciop4pnetsgibwgI9xG@t{4A1bw%N zktFdEI3NN72CbxBdQgF$zACWos@y38vTygkr>7ej6g^=cso^^3Z6Q}U0Yau^95pKT zC<=(k>72hDZ&Hg5>>j#!#amayA7`-C5<_>;Ma? zmMGWNWhL|wu`0rt3us&}@^mWj0z~f7xjH$7pS7~Yuid)fstNmPB$xMxWWN;P@QBRR zHREU1W3Tfg6vBf+c_Mq&#i-Sxvr$KfATTRTn70T&7g&9Ipqoi@x90;|IwSkqstUX5POHt=^xTx=`w0*Ni-=kYNq{}lm4 zeuF*zf`I+b690jKeP_&sQv`$)2tlC)MA9@0!8A_5IEA4wg2E6D;Wz?+Sf1j=ZU{gy z7|Gz}yUv5LH*11n27(zHXV8+t@;ziFWzdiP!at3KQN*59Sup9I4nXgkS3$nMFM z?96G`gF+CKByYl${LBLrC*L1h5)6&*7Um>FK@3X2mmt$GCI&f^eKHd$nGAVX&ndAt zX3^b^e0L9c6ET#b_Ue|}ZJgd^>o0qvy!xgL$@q7SCYLE?Xg_C*I7-Kxw2_WR{8LZl z|JW1#WA62)Uceu4uk}anrF+#1=)sTNt6KHo_qf-adIA3p_j*$=;4Am4Kh~Lk)fcJg zsZu4wM+$fh_=N@Q#&u{8P^$av2Wkvod#I*-*SUDd>q_+(i|W&79Z+^#v#aPYqE45( z*e~MnbbIu1IdC+6)egYn_Hagl*T6z9Bu>%jTY=(B0jk)`xBWG=BtD!=D3G-e^hJiM z0ex@;xk+%U3vH&&;Z=c)0-t#2rz6onj86ma@Ab#CjIa74?n#Aod3ffkFWeqEbVnB3 z*dUvZT=#K1i%r4;G^RtC7nrUDi2|H0y1)*7^32(-PPs~1Sbfqjuyra1s`4Y#p0!IF z=fcq!TKZCw9Dt!U_888m={(By3^s6MhR7T#9!1ww?Kxh!KC8U++I%@7Ljz67l^vZ;tJLf2Hr{NGO`3NtD8H6vbf@ zLogU8NeHD0f`n+8q+x>oc(N9u7zAZXib;`OJCrdf$-uDtkU*y zQe4wus$E?3Iz@olvzJj)CCfcJg4e(uTuzX==>QN*YubeQQ6b_e!$S|t<0)EW?D;@L za_o&693SyFCS|~HIPw2@uGg{xcVla|C7(_LJb8&E{32?Udz16rQ23xSosA;oYVzcC zY|`H`E9Y+>*|`5dup1M+f@REL-peq$_+G6nvzRw3Wd z-e{)WV?W9K4Wwww5IdYwyKMALK#@JUW~Ztp{=O6aS*|FVzBwgEzG*R%Fh#*6+2_nt zWIyps@He#P5CfNQ*i6tjV=kaKaAP==k#F`)qi-UM?=~vMZm?YL(V`IXD?~kB--wF- zo#vj$D19Yxikk)E>4q(q6~pl#$AG)cv;6TG@Q+ay_!&<9228ncm;%1)KmR4F0)MjI zk9G_E$#y@=z5#xs3-zYKNBlO5S=X#&G3VU^uZLH50W&v%{pzK*v+plL0u&|m8dl^6 z|G&)rN3)|?*R6r}`4w+pajx(#;xw=Vg!j-1 zI6Qkh4I(K$GTB+y({)?Ri?D5vI?$%__Qd(+3KxOLEQxYsjYpc@OpV;Ewk{lv+DhPV z6s51XGO65ns7tAS%TSB-SkHQe=vy;I5lTfPS6>SPzV(6EDJd`#;pVveU{vA%OhUP@=3h zP20qCr(&QFz66B=b1UzOXd$i&VVlWQiM_gyX31~#w z@-}%3wA~S7Af123xsRx#v2Bt+B6p~KvQe~aZp2x-_(Y)1h7i3H07p49t83a=8AyTIIg+)(VXYnn?4B!*};W%=bE70P>l{qGzuw@+Nz}XBI=8 zC{$}@sEmbyZ=I5b_|r+pw|DAucTjeBvSg++fh<#Ao>V|en3zpo_=$V6*0VyN(~Ee# zKngX@D+1zS`|cNVy9Ia>1e1#JjdFjZW_O3Kv1B3J0_=Y=7wY$V6e}Ut+#aiNAB3py zZWbHJve*1x*8u-^F7&&xP>#xg&fQ72#kH2hR(z4)S_FfnDETjD+GB;3!X;!g_|_DU zE5<)-ER4M6!RO-RUW0ArTR?Pem2y1aJ2x5y(3X-B@@0OHy0gG*)09|OamNSawt!B@ zj}66 z?((NAs|+!XA;912mpV>}u-vQU)QDpujfr_DU7mELCLFw(t6!Vk7iq6)?#@&7a2G41 zdPh_@iqAXX<_W7<>6kw(hN}s6cY_o)1oREF?(Kf#EPE6D(|wqdMMU48_0s24>`BB0 zPeT6m#DHAtF=<+Je}$xp)LuQBU&hni1r-%Ugny4ND04b#z2K<*dF)Kx3@}_X>}*1! zb;B`0eO+x^lq{bFHC^{*IX$PsS?m-~cfg*x>oZ(#>;}nKsLnd=!mnt*FUo^Y-;iNX zBLIdm4*Gk8fvuwY9+H?$VvNu1`g}ze#hkU#?wAO$ z9`k-pC+3)R7EMXqB5%@>)e~Svd*#Q zIQMHcz~cKUd&&QqYya99>fvhYQGd;55R!oD(+><(NE6mi3p9u(L5%JdKp7TC`J*2g z?6+>5m6-d>f(alrDiBHq-|iXf_X(fkEh)~<#ePnbP1Zx{vKRd)&X^CVB(YGuxQ=+c ztEg|^D4hS$s1_moPj8$Kk$A@V*`-=Bt%orX(p#x%C=;g$Jd~~{flOQhcAo_fpCH)3 zIEjgeID9DvPClUHzI&yUKZhgeC1L;~o{QTEcW>lFJAY)u-Cm3)zsX&c0>w*a^VkD= zb_8BQ(mmE&`MPphd|CV7!Wb%57lNE+&>q#68)~aQ=40+z8f;Rt&>(5mj1OucAnCGT08m^UekW@SQay^D$pSQ`rd5VeCkj4DH|rdlPX0^3lFifC#7nX|JCun-JbCe zG78Q}SmkKC8O1KZ2z??ZsxO2k~?{J_RwKmqH*F?Zr9G0cavkagdNmQrB zTzT{%od)KfF&mDB4$3Icpo0}Z_#C58OL=;Wj(3uWo{1gXxO!oQKOhwZz?yX#q4B1c zIKaPo@8-aqTU`&ANkpU(*inlPo-wq$^+0;XRmRFzupHdWVqZcMjyg&f{lw~#yAIfd zR~x^>&glDXvN^3LdDr6|$!xV4djNL4FVRLj{*v5z%hrUsln_jRs| z6~XLTBmy=Z+1z!B@!&Wui4?i{_xU9oVm zu8k;UXN~(lfN zFBj6qJd;DC{ZDVU*4M*LOY9106NHYaYk?PIk=|08_YMbhU~GMg{?mQJq0>A#*;Ccd z$$dG$u%7`Fxy21Zit3TY%D*Y8Mc)-@#qB8r$KwWuH)l9_c&)bvzDzQ$i1~6Z6k1kI zH|CtzTMaVI)7UM@NRL#%@a5$YDLD|W0=fEVV4@I6YR3&Nx@4?zn4v|bLd3&x;>yqpv%}=!_(iZh z%NWn^I8DH!3Kh0GGHzCj6TA3Ih-xa*{^h+iN(dO&Xd>S#r>uJ0u8U%IX($ty^I98>TZ$RxVXVr)GD zM6fOp_WL{NaHc#8V?6gFw^`d|F3`4G_LoIVW8cujtasFlYO_0kh>f1((0(S2{CyE1vybuBg7Ko6?@!@r^|A7O zT|fh7?Ilv*1W1O@65hS*a0>1&cZZ0XMR3Es7v})8=augn67=sKoGd(h=Na3%FR?>? zyRjmDyU~;8A%zQn9-;Q(KWj(RW)HZDUuet%6Z>c4X1Bk+LGP5{4tws6@uk2%cgMQz z34WFnE%NTb!S5@{7Wi@B-EuCC#{B*E$G%UIzLyifaKROCMR}O-Tq@4LOqJkO7Qr1t zfAx#KigX=pZ&hg(z)3J$T0FAYV38l3=Aj_qkunYSM2dD)K$wo=w-`n|x#$WllE@(> zD~=ecQrHqzL~!k)GVTAN2UoL<=dmy*gdSK|tC4zE>jdlRKqZYhgcd^fp5T`m;uibn zT4s5v7MLTGB;`p;J%K$;_To?TUL(F?$u2S1HLGPk0k}IlVBRFJUrf@asrR%lpblu- zE+G2Tw?Tr`n|rJsVq)s*-DW*R2BbKtj=gxY=@EYWX1joBM0Aqh>-*oUA}WY(V^q%u zpd?jh^ct+(q~d^##28U>+0%+n=rvQdGMmv+3b}X~n;9T6y^e2c8t>G#j!=E>L>tjh z(EDLVli$;kz4t&ai8b=>g9gz*;vcwg!LPs4rTVH2`!!yESokIIBcPBGKnx1t1Q{TZ z5?~0ChX>0e{efqlmpd`KJAh;PIfVekGZr}~W*cHa$SlA&7_TEX1}aL-J&9Ei(-FsM zqV(J(@V^zy8#QWgCgEjafWv=*Ce0=U=K?5D`qeZ|=1S>zPM;le_=3VcPr-k5IwznE z7;yoHm>ZjW67&HSQ53^>6f_&j<5R`U(z^}k3F1BCh{dOfI^+xQKN$p0{t&Z@!c-ev z6;XC#_bha)d=xe9opdYTEz{78 zy6cO*wu||(x*MjcUe_Z6uy}9T%2>7Zp8Cm<3J5qgXNq9pub z^SEStP#a&&XE-FhOFZ6P*TzU!t4U+sIZ>wfl!O`!>kGlsFl6@+pm(Mf;0i%ZjkjYM zMUBvnsvAXdKvQEaC!R2+7K3FYvvf~wn>(x*>CYfS=aw?-^%$t#9!mC2+0KiQBM*Ef5N$5@e;Yh~TS(SYzydnvMZe9**p9^{lq-3cq{xrr!NTI&*#VRw+Y)&lwo@iF^eV1ortNty3(9;o%SoJnuwTk=)0qA=IP zw)bb|pu;1T?2lI`D&0MXWOJklh1RSRc{Q6*p65|*cHG}kIQHbb2z`bn==|sfN%#ZX zkb*GG+ojsMgw&7a5*5F|eJ5%e+%AMmv(r=A1~Eu~I3VWtEp-$lvC-`xZjTwCjV|#3sj|if4DJ&KR{ORH#->=`;a90cc{@8cobN7_uyK|i1kwTOqfpWX&s;mp0kv>Sq9u28o_*S{3j^7JGpOhm@sl_df zxIoBzXhIiO#^4C5!tm6(4aYKHP=A(J9xpHY3P+vW0seQbImr2!$@ZsCDoAe(CFz{)Y@DWVg=Bj3Rl|oTO^W5d%GBpwCLk|>o z;>#_$PGmb`>OuiF;j(QvoCLP=HPqdF#9vOpXXQHN2F5(bwVX>Z!bH2HqtCYw{C!J% zAt*_FHytJ*R378sWf zdxsRykNp#(WpYJ4nBhrfEP5Gn0mKH(+q$vKd418yr*0)sx_*7ByyWSm-Qfy0LkiVZ zyOg3y)@A3N(!&tQj$k0^G|UpRmGMv6dfJvF`*~>&jN6V^`Z7|6TD;XbO zG8O^h=HZf7AIprBWp80HH0~&-rwo47 z6HwR!z9$2AK{L|qeP=MAbAI+>hR+5-k5_W?kC@z~eX$ziM+z*1N2A+%y+8DU_-+sb zzwCh`?+kLeFYNJ7#uBM0*=YDXVF9`0>|CJ^`AM{~wE(DkYn|ZO023CMd7A-xKm$m> z@>cCiID9T-?_8$SQB$Mg1D`3}riKi7`!YVZFOSVE7r7nc0LzBUdEaBV{rJC+@iCLG zLC_}}XE_SkN1V%2cF!ARU;cx5!r$y#?`i?`-S%&iZkZQK)lN!uLNgQSZKgm_V}?eL zF;=5qn{)gzYY*ST;2tNVx5W z%SYviO^h0s^{bk1)>Iic0Q7pI#kFVFl)+YAJg)8~i=>Vs4O>x7Wi;z5?7|b??U!az z2%(}D<%z6g1lXL<11NfEbaATMhS*0#E|Sy(mge5wW>mLh9zFC6qOi*>Zru`0{n{zY zjP|x6m{uyr^=x4z#+Cy6rn~+D z<=(W8f~j5^PP>x{VORaX1MJk9#c(Gzn4GOtJ2O1S0&EX5s-1MX>ssoNsj1zGQiKxQ z#e-#(AkQ1b2YnI3AYQk0Pg{;JiIiOEK07WCKJ5dgNOzcBFpkI;{hGi0-a_8*<20s2 zRc5;U2gGG-Z!j$`cN-BEd6gPG#gm8$tZAqvyMv@(T|}*(t&)c!LpX-GrLH)I9bqmF z&`C+FX2cWLTkP)d&N7Q6#Xn0UoUAwWZ%rb9aKLax5t zZz$*0WI#*UJ){h~H4uf}yH4As9IEz7uC!%!v+b?rde3t;AGaGxXJf&dmk7~PyyY?9EI>t_!67u2dFC9`&t*li!Mer zG_i*#Yil8=jYNHL2-MTO{dzX`uWIcfzrUkT0GeXy^f?qoh_fkrc1>}?p9K4!J#Nkp z&ul)HFEq-)O;0n4^^pe6x7M=#IILR0HJd!`>vrRme@c3p6Gk@-lyK8_0}5KAK1Df2 z*)+_9HYQoAtcmjh*g(T;#FAX-yt`7m(0s0hLdj?^D&))pjZH~n`}YNd(S%WjFMl`w zO?42+9q6>{4`opc+%~*;J08KV7WJCpUt&i0;z`6fB-PBfT`kt&3pfAXh#)tCLgzDw35l9Sly`pi1u*ba4L2FP}V^ z+I+XjS6v3}?5Uam3G5L1*-rXma(jViefM$;^S!v1han<|A|^l}AqWQ` z#2Io31TugUfPe^6KoQo5>W>2_|6Ty#y@cSGfj1^qo#&7s2GzkSR|FLgIva^M(Q~X< zY8UrAzoy>@pusJYxr7LmG-&VT`vXmAfmAXPJuHDmVh-}o{V9l%uaEViBBbrPn@XQG z4F~=523SORX!Kl1T$(Rzf%5ekISJqUN0w~YOsVlRZHaEvAh<{>Ff?%{3i38BKMzjZ z?Ah%)_JQx3_U9{U%4x^*A?c33KRhZ-(s~==ys5?8{0-UI74#e1?1jO#_h)hK>@ziy zZI{bTjmpo}wdr2!f2I2!T=H7^_qe()>(ysr3~&988CQsY@SqkmqV=g4A^O-mUXhly zhlko8*_h`dACXh9m9cg`3`W z@wsI7CNsMRa4));p(piWR7xc3+#zJ7mf8!o2T0}9kUyGc^u&8D#PmWSRAS+?s7GDr zcKQR`#$Kg;!{2RbK?R%e$c2ZEs7!T0RVVp@RB0HH2~-xjCEU))J{gXny-N0>o$%0*nwy5TIY0CkGf& z2c#hcm^X@4TnTd&?lQ@>(j1bwQ;XowGI;HIaX~Wr7_(eMbZPU`lW^`^00d*PFvlFf z$U_+JeK83vZbuQP_+jx3@zZ?(Xfm+@X`qGGT3SoOQzc+z%xp5|zrGcQRe5uTOJG!S zuKR_LBBL|cuMS4{Z@}?>+W-Ra+PbdPAQlO)Rf6#|;6MvjQ zWE4EkTUTHFJLkGYNx}j_f!`X6e#^fCgYq%M9^kywG5VG_>5hRmV@0VMYqs%4#Q%iwNqoA%EqCtY#;l@EGrqkv687>QS}MxA)u|A{YND zfb5#;d6wd#amRt9c4BUOrAQ-`Q9ve zsH3}+@LLav1cM#pqO^6VXOOlaqzZ(G6?w5|VZrpTd(q$fdISuJp~O{6yTAMM;PzgW zImGX@H{8yANS3imsyESm(p3?YXfEuku10H*ObU>5e7#E0-Bp${{MDqhId+abb? zNx}#0|D`k&Rdk3hiH~De99b3hkcS*EgbbzT%@lyhM(l}O{Kh=d#Y0F=_!F0Q%=|T~ z>#9v(s>jdpD&R)P$9D(jER@|Qr;h;;WRQ%1a$DTUsR7pCtgl~VnuED)`%<2jD<)uZg^M-lX>M@2w6v6yf@ z98F9(lg|uE3Qir}7R)%CCB{rSFBEwtOKuU3bdjQq06H#+TI0rs=1SNwv$WE7QT71b z@~U+7E!|Pgyj!u}hNmoS)}t4?=}p5AO15|@mB6p4=+&D6u|x@7!}n{2^3)Zbf*YA$ zZ?lHhc*bO}(V%*XLA1?JwXe3$pB7ll+oO}Sw2`8g*DK|So2qa3fWFrjF$hcfvmfQ) zo_~hNe#Z6$uJ6xv$*Th6YT2TFhBBO{d%BFoZhqf+QD#uWhctm4Ij8^A#gJcN;12cYG_)akxIai>FGy$* zN%S5>NCAQLUzF%y3ZZ_Kz&-kKesYlfTR9J9eFtGKBj*esYvfp*7T7njPl(`Y1*~Dd z6lk)zpHGhkyd1x1B30jtHI(8#VpK8_i+kwv;5>@J;kjRK38ZEvJjiKMY5e}r1#ho3 zS*P}*Sn1D0qwo8yl6l}XMZ9;&ISN@@1k2S(khzM9dg3kzx{rd|B*w}JA&}NbTkV8@KxyqX}KNBj)I)Z>xe}V zNo?jr#O=M(E0xy&`m2PdcFELjn(&}y)rWj+F_V3Fndj4YwzL|aSX zNBtec$Fn!?XrpM%{1I4lW~oslk#+S(m{+2;DV5&7oJ{G=;t>z~#D;t1|$D1z{5u16=B} zKjp4LstwF-vH^lksZC=HW0G!qy$>ZtiaDfAd94;$MAqu7J9_C2F@i=v0sSfmG@t}# zjf%#n%@Xhxw1Q>G}=tl?40Kx zjEW~BP*$*>_*+sx)Ba$T&?ywsW8Ib)gc-Z|1CBB?4;2`JN>ad*GB>BGspybBY9%0b zh_W7<6VptKruKGIipyk28LX8)KGVxGP;4rG0fjOwGz281;5tVZ=aNY^&|-hxJ}|lS zo-F6v&}(PNt(I~Mp_l1A1xb_@s0;B>B-S=9)-@nb2W4Vz^DPRM4iito)$#M@yLM0R z%@651@~edWked!ICy1MlUDt}n5G(gR=szI_WQ*KXx_zKegsAtU?gP(rw@CIv%E2YP z`Eeu7Kf~f})8YYY@kkpnBM8B5Ja+7P;K$7q37smn0yZY*ox_q&b5{{=rpr2l!>3#3 z3s8HzZea1{03 z+*4QV++}3o{ekzZK!CFT!g-WC5C$Kn7%vx@Njz)m^{<}rd(KmppmD@G?UV$yHPJ~q zz+YD{QO+u4%z3vTy}&GO$R+wLOG>6_=FL+t()-oY1yL$B2Pg z#Nqic$JqpM+5yXGRa9ZQ;G(?Qgw$YaGv+?yP0*I@3f-L>5-V`Wu!N1!5>R;2sSPA_ z9)S``@#p%YLYOg!;D=15 z42K6;Js_M3^x62l_t17plzjO62di*M{0{W86Ml9*-mDzh5RpxLBH)Pun1$j!1t`;= zr$1I7Po;v&{(#vlJuP}206&=rtv|3Iq(9IfLp!pl0wgd8ouGrc>?#1xQUt6!HbL|? zBe&eu>0hVHw>lf3K|=I!V2s7=npGRu>IFJ}0VYV6Z@OySx|y^Dvz;cE+&XLp;gBz} zQd>~hZ7is9oR<@&;BG4yN)Zlz+qHe8G=CpSW=>?ma24v&G57r`c9F^4U(;jRqw_6! zs~kX6j%Bk-Wr99-+tg}VF*#}@yJ#h+K+S{1x`IsBww79OTUjt4%JkcOcMZ>E4xCnG zx>c5W;V$lh!27U^1V8&XXkZF&0BCA8wEuk&KTlRcVq?gYW|DMV-p6`^{+X62NMQME zw{W=m*3U6BytMG7a*1k<#Zs|0(A8=~%9ef2%YI%6iDsh_F_?B3x!So)TeiLJ5Yt6HLDSHB)h+{iwc*xcgjLs+C!`oMWsu=(keyb=H`i67|?#m-$tg#NB>Al~C?;6U^Oswa1 zHg4coXGX+C3dJ53R9H`)o+I}(-fO?nc#@b;S?+SRl=Q%J6Em<)>ffP_Ye|+;UiIDa zty|Oc-7wdK4-Thfus!{O7cY@9p04AX#fxB`>pi%!)`Bw|YTJaA(`wsHZ=pvB`+K@Q zWVaP_a*;C0EwrTyv2f%GoqbVgGz=k6D(n$H^!VC)dO7AUj!(4Bl!mESu;OMVC9DJw~;rja9*f* zTtpyWcpI{k)nK7dU2O;=%lZk9qA}@}NX-G&mZtr^`5#0C8J@O|z9DHvyYE8C2Y`1J; z5*P#it*RiG92SEU*QId51N=OOPRcyRx9!I#l;+`8P z+cvjcREHvc;hx<@dzaD<-m*UTGQ(QyIu^NG5B@@=?HtzzqE7kWyshVE9^83H5LqC&|oe#Nh*A}}NEWlrPRe%J{kOY#L9?%E_kccFtpCp=} zJ(hsvc>%E&rXcZ=eOc~T%xI79rTDFnmh%z?2>&H#)gd$EXEDcwKqmoTF4e$U5Vt`W z0d}7mW{yDM1QPad*Z>h<2O5eDF7*qs(Fyu93^6ZQ4flKc!@<_y1W{-#t};Lm$wEjS z5`4Av;#~aEtP*)FDhnKL&a}P(pkwBwS#ePzi0uB6MH@*n5}nU#o`Wi*^PUf%L8)4N zf$FBU&1KHf@Hf@hJvmX$3;fb=(2Xx*^yJFr{_ahEYS>yNM zts4F8NNoBx08Gr*cf3rnI;MoY;&!#DqFgg|KPf``&NsrJHTs z`K%B&F({erOHq)p#tKTP-pE&C>l;hMMlF@I=Oj-I#61)rOp>50F?Hf6Jdnx9xCZ{F z+W#>XC-k}w`~kVJJ-zt~{K!_bUMVK^Y&@qyUsyisARJpGRLZ{Is zXU#{-K_rn3`7@|=h3C92lydUvrR^osb_*Aj=9TWH;+Qj$xCKn_&=L-6{llg4g-Ze+ zM1L9-Hu3nen$fHdHt{Ti+Y1WW^`yijC_>r^f z><|MlpwREv5wSCpQi($dmXD=kAqBk6uFHpc=C87|6Ywlr$#wz@=2GOe(7$pbnMAp4 zK?`v!1S6THXe`p=M2?o> z1|q9$WQdH&btZZN6!%Tm1Yv+h5S zF$76_A}N0wLJl$04XvgO*x-^R7U`0W-YjZ?!RwD4Y(Bg{cQp*bY5y^Sj{)S)vO6A0 zWE-?rGc5IHQQ5{!edjP-vt7$X7nFDKxe{Q6JPqMmD!b+;rTe#O?~#rLCtPZa5<)+y zxg?9;Wz#w`o7?%?5#7feWMo8)^EE%5W4)QfNGx&cUC4PX7HzdD7L zL1Sx$fP2pp;--&?S|oi(?n6j|M%32HN0rWw208G{r9^m5;PT;@MU_ym_muJCs*6Hp z3XBPtA|JU5CA#})E-T|NH3}(;DbdSSZ(C;JjBt+}NCCi_f4A$?Td-Wp%@&pf z7hT*DY&opkNj($R)(d~wowWF${ePYW*4Budt>;!2?8SGJPz3lZ5l7*%)~Z5P)s_iT zs<4oxw)OJHbg&+@wvn4M^ju>>Kii>B`NbMT-CYfW=CqK~1$9Ad+29Q|Nse0cZO4y) zFb@O?W{wr4NJ@awQejq+G34P6peOWlXyrJAb zQV8Z(5!$8kB`k4t?3f#I{HZ9`eQx2-+p*`Tr#A#O3yodPW~v{FE`rq>#cm$@P7nSP z9q}^Xu*sq?>v=qG8|IGm22Sp?H>=ebqjNy_1~cvL1iA!WmOx_PHG9!oG0ma z(0kO(il_`&oB@mr1u{MEusEzms z08ypd>!zvl6ASD^2C*FkV6UOvPhYU4h}5~5zYFJ5H>It8Txx?dLZRZGjSTT*3k`ss z1T+>#&IC-5w)O34hn++Lf*$Q&7+E?qW#w?Wy1GaRIUXPC;fr72a-A3IeA?&cZ)?dI zPYgK&wTdO`a{6V>EhuFvt_CEuXu4i)s7IU{&_WJj#gC8^dqw7b&9T}j8Bj`HebQdnBZ#+|NV61V$`(lk8E#YcJC5p<@eT=LZZ%4Fo7mslO zQt9?g`y{}`l{M-`@F#h-&!Dxuv{jAYu;p7!+H0Ea)U4ev^C_Hs<`5BI;X6ggkDBdlf0r!mA#sXB0I87z;MN!F_*9JgQ17*-~9P2N(N>Uj#f^A5;=V+u_R{$8%!Ty zpAS&WM*1>S(P=&^t87VexN&fX9(dT|S&hi($JTa~O#)Q)oQ%(LUbUJI(QAE#4b|y}`OP~69a`rI2uG529vhM+I*ls-cVoB$*pcmqIx{o( zq*qA7qhnv3PN=+uD}YJpCoq<5ym>gSnGh=0`ZU@zUIJ#|i*M2oDBvsZ&Tr^rk@SE$ zX~-M@z33}$;B)u&J50;F$=$E(Q_CyN2qicXMHYboVvi&OnLt7x0c4*(L=izWA0qU# zu_2cGzCJMs5GGIz3FOs5o4lx99lS+ayq6vN)E|47ov{@XL9;=P6&Q3zHL1g3ZRB)& zf@MZ4rYQ>@=T9ZkQ(p4T(3rJmZzMfk2BPV|otU zXxjORry}14XSYX3^P0l${|E-JT{?dPcVwk7yC|snGGlmk@54rLx@7^^zeq)nylFyf ztBxZ}FWa!t1xuE>Bo{)TMid;M0kT#8|RAgK$bU%Ymc0D z5x-TwcTt1Kwrexkp;eic1cHofxIr|#^ZlxZ$D@3O@V$QhNbZK&-*k4a4@Ne}yCQ{$ zp=Vv0@xgHvjJAOMV-pBT2A4HW&WNa*h~9_V{IpHNvklv6veCzoZE%P3*?O^%qAzC) zdA6v>+7LTpI?{rg(%!Er>)_yk!BjH$1r#LvH%yL_yEniTX6UZrSKj-x0{{T<^CK?> z4nY)Tpx|T<1Tg9d0w6C141xjx@jC+m5Jvv4{?EkpyJzp=Y;I>uXKi6f_n*5=v}#J>2Idpa+=ku8WFKB z)ep@x-&lMau3ocvSQVT>yYXCRJhy-XS~KGqLmAW6?X_DL6qlU$-g@yynyOP*(AFBEjU6zUp?r%=n*@Xtj(0{`*rGY<%4vG~1is>F6S> z+EpeV&Huli>D`pd?yPUy}_YYGS8@Zu71A!#o+<60OC1&Ui zNi$3k$t!rBb05H&co^9WTy0J(3^<6f({^nNGmWhTI9*U<5+@; zbzAuhYUI_GZZ%qfSu#4r&CE2gZx?str9hNO-Nw`KBu%369Wf3nMs;s7vIizm*4tV~ zfwl{yI_?v|R>vq#gTvM_ZVJz*;OJO#tN|&bfd1;G7FnRPeks^m# zbaE9-zp9W+t?=(2CDuB8u}cr7fxEgruq_YrOX1Sc>|^RJ@fkzr^Xhe|R1DfkShL`d z${@OwJ&K6nPO1nHYgD{f#{&%9RkB9FW!X4(gACa%jr4187(`uq?HvJKlkO)tHAOLP z<(nhLsDMm97!Dmu1zhNik8YP~X9Xh{nNhTq<{Jm~5veQ;L8BFUkKU8oWDR`Jx#{W@ zpM`?P{Fzu2=_Ru2*&~NV$(8ia64pOatO38k0~vF62_oqG0;EBW(}DD>e(FoKRt?HI z=1O=k9nCtSB}px-2~@cszl7S!Zg0 z68vUcYvn@pW-KcVhl6tx6ZV;ssn{qeiGj-Qk7mcrKfl~`R8ot~(8cg5BK zn36fdwmF2E-&F4I6Gan`lR2`oF$R3>DVNSwy2E0&Rote@g1CM;B1+`)Cd{SDYJ$xz z;h`XYd-J<5*(W>M?M`l%iRziil!CbvO?DI9arwOSVNd-*(w(yXP!-kOwlluyC_*~W zow0?cx_^t=ADDTEQ^O}RpU>9BY*0GVA^8!%hO>0EUw8JQxi##O>} z2!R(6002oufd2+png1Vg)!u{F*~8w%81R1=^B)Ke`X8&`>A!|=@!#D42l%F8q-SKN zWus-LHMVearm?U!wWE`eRZ3V|T!c(Dk6ktq;s>fjlRPs9&jsTiqglQ6$hA_S~3ProgNdi8A`P>$;YX z+)D>sJ^MI{$!?q5=bXcU`8mpibai*APL3W!Z~|8;ie_lAkJ!2HxFp^CqO4AVvUvNo zwXN^#@@U>OA{7CIMPx6w8c|YmYJk1PPBz&O)h$X-f9BlLISXs#`I93h@sY5ep43Hy zt`^GsoC47m1=2Ku9>c&YYa^&zl3BG(1bx7N#aDn6#kx@nCwO*7_H^iL^{uQ>AZh-?Q+fsj_ zta0h@&#=6tSFLl;QY{NpgR-k+KC$9Fqd%o%0NZs#cr%q^&V+EH`resRL@tC0oCS6q z38*b2No7N^#bMb6L7@l7<}qKd9GNQ+4zvoxMjTih3vxo{e5HqVg?|(_6(<+!)~XC} z6H}%AI?U?75R?gUn+O-a_W4`)Z{Wz zuUGt*{q(1CKpHt_b;D9_83qZdC}pPjj6so(zXcuAT#~X6-tN3-7c*$ygjX!JcAM2v z+)wrO2U_`f+;xr2kh~EZvq&77#@O~{JG2jO=%?NxWO!qsa`ZtoAd;6)h}^w(FE$MG zqwKJ2a(KPndi3aaboTa(w+{hPr$y|$hCpd`%_rX6s^rmb&^hk=AXHj)l8R}ix?VAl zbW~E7w!E~pNOYJW&+6x-8VqMGhA(t2HwtT6Ux&GlIF)=q4U8q=@}cJBOmq8+zhfnPS-91V^QW4(RCWQbhdYX$L}2CFEU~UbyFG4NgPl&s`DJA=pS%5ZeO*U zc7%An#54`F0hS=YvaD+=)qLBB)}ys33lh(V){{3=%V?h@GY#$5n|pPvVf2wm9(Y6g zB{Y%1awAQ&2xR;fSSH1IKl1RqTCia(J=XpUtK9!(n4@!&YPq+iRzdRd$xdf*R#1Do zh3O#8655OXN3Y+mk@!keNL8PLoPl4XA3naXzk^e?e;Q4yuc-uia}sJT!!m6!V@x$k zKZxOePuMM-&%#@CT7SOeP%+yVek?>p+o}dGW95ysvrBJsVQ+tM`IpqS%plekTj}38 z()FdPlez38+O`c3RwCuArkmb5lk&pZSKIrSQuX!p&=FrwOe+WW-NIUU?u@9mP7Zt< zC%$7f-r3D)j$m_Ys{IFpiGz93rQ5P{zc*`_m-;pZ%a&Yk-?$@3n1E`&ygYu-1Fkd- zh`=5ypYo{%a?^EQBwmPRS=RF63_>d`Hzyg{HPS*Eu4RqFJXbLx0)9{@I~}YR6ycs? z(vsDx)If&5SPt7(_(4Who%6WOu0?n7FeoI)BnTEv-Jg2?pYRdNp{Bd($1;_1d{D?r zx-*do6~|&zRtU=&3j5@)_ax2gP;phNU4T}hTCZOR)0`kbu9I2 zOA!M z9f1=fWplz%ysG8DO~%#+$ToTj3`rXsTKWr|bR+DdZv>-ySoe?51*tt0hPNTEsON$Y zp86}lA4d??=T%Qz#M$fYLe7#}jJL_3#_$vMIE-eO^Va4oJ1@1En8M5xKKVYB&!>G| zwtkYvon9TQUK||W1d_b^HL)smP#s-C*ZTDl?n4w4+mC%wxf2|?7Rzbmz{ozP-Egwj z6#yW)tTMS|+zuFrpMMn(STXrL$}B&R4GJv)_9 z!HxrZ>!bFR2@rz;g4O^4sYeu;=bwp!OI!eC@h0#7UY_3W>UGoK-a#$+hrj57*K5=9@49&KNrH>MN7A zTk$?G-g&)@Eimo>(t_S-HIt9t56&HBPo0Fj+~RD2tEg9W7w!{d>%`XxqM8c(bNSw) zf67oeIxgi2Nvxtq{AADp6_~9DE?|dw&~;D>(So_T6<3E_RDd;| z*E%E0`4*MEuW)prQrwD^TS(inoz1`x~x3*pI}+N$xPZmY|-yyJ_O2& z0+H~-ffspIMoIZ&C9(gTJjRuB zP;{c1>P{;q=he3Y6;YT5r60xc^i?t@EYz7}BxWG=KFz28Ox`3AUs>U2vv?Pg*|H$9 zaIY3$eD^)quM^xgwTCKbW(T%s#pqy4dDsgqDGe&vplf4xD39 zvkx+BfTHq$3T~NSe{A@meX3oyFcPYrqL@J@){B^>Sk0@wr`*2o`up#$={l|&BbC7b z44#4K0<6F#pWz|JIblvEnj7hj6pT|Ds5qVGL5+QAMeHQ9-OXg<49u)CzQ3;iZ_k~_ z&uBv6*Mi;tw-!wJf8J)*#6?7;L3;l|0WrXU?efU|RR~L}2%1GlU_+d1>yN`rIuxJZ z+y3sJ!N<4{9Wh*gRi@m^yUjU{0p?g?#_kKVqB&8Fdt{bs3*#;^qTU%kLw-E(8NP5u zWC?NJ3V;5s;D7p(ysQnmdcQ|nzsrC95=#HiZ^+rsUeDUZ)x?_C+1*)EmWFandgAc^ z`m{PD*U!Ix{QnAr{MYpm{Qp}Ia|1^w6K6eJJ4YJ>YYR^kM>;({3tJ0kJ-y!uNuzR~ z?f>#;sY<2^T@5C#u1yS_f!$juSbK*l>Md&f)3Bn1$rTC2WS4~Ip67QY(AAmA+t298 z{gmZPkif^9I4zE+;%{K_JpdZ$%m{SyZQA@p*&5Ush(!zkx>wGE@2`!&LB)KhcfKCY zkTvpn(QzB+a^*1yl4)C-lxze$ITP+N1@266rWSbOW(OoAY9 z?=|zT@ioJmnVIc1Gcz;8nwi;aW@ct)STi#-Gc(7ROLWqge5XjcKYFB*Mm;k<>ZhuD zeqFUq!Cp_IhvqjecW&4bN$+1s)zkL)qj0o;7K2^AD(Rz*Je9kDf<^`P+c(jopi%Cg zf1;r>72uS8Dzmt1YRf@16=wvv`%lj|-bo3Q_G80q2%^*!1Oa^W^Yb&e3mBW96d|<- zn(!uDYCF3>~N`FybOSvy8_ab-xs(pexT$ASfk6H1I3 zIJ)Ry&WC;)d%b=YQT1a|-GWdW9E1bRA~x1tLi{!7A(w*nApM*-mzf9ocZ?Kcjg2lU z_=9ax9dLnnZl&rhXHsnz-izR}+&=DRqN!?Ps?9pd;pp^9D6TgP5!LxSNo9GUv`JT! zvi<+e#9607Wn^iKc>JEoY@=22qdcOOXA~e9EKuq`kxA(=RFhVd1n;v(Y8GX+88<#` zPwy3p$|;UxsvCv3id24+j5;6FzQU#DjG`I+0~B(3hEp%x%M1NtVXnYG-Qz}{(8{HO ze^CPBLtLE8J@4JTgv8e`px$!-a-$W>%4cxQf&!IIW=rI(bRLC7V8;L6|JPZ-4#z>?Tpud1|XA?3oM2_`W8zH#K=oO3v|3ZEm z61#5~0NITu6I^kLpE~~X=abQcL-jIzgWEclqH5gF(K&x?&{A^}nSPC(uTR}QArRwK za`)*YcyC7WEQ%BpC~Uxqr}4NPO@?ywA1wG!GV~OK2oZi`jso((Bg6l%8ELI=Zu5W6 zNU2cH;x6J+W(AlLar6#w|2K}Y6w}_&8A==x3b&(^iUV! zl5LM4zocfWmr49B?r@Sl-JQF?3n}>9d|lG^LSLBNFDT~sPm<<@^*@yL3I^y$s~jC} zTe^3f?@cYo$b!Qzrat&?(t@AFAu@)}-LDH4h$5cF!9^#|~3{yprMm1HLP=_)kvM z?+@!=dYOiAXmL_jR&a{GJZ-HrX@*2v>Tq?dlJ$4uC>G98|16Lw*>;g@)%`ka;bQp5 zssMtmWe%oW;EA4C1Zq-rjfn;SS4rCi7aX6mY*5d@f{pv2cn4S8TH+3h};{vnn`{^s|76Q91+!%9>uqw4C5rB|EM|eXZ74Pb-5| zL2|UNN=n5)$xQQz62ZBUWr&Vh#tN85+Dn~6EI)rOG5_m=``&nEIp=Sx40*Cf3np8k zPVytzFyQsCpI|0j{?6R*y2;tX5w?N8-Qry&sVZ23n&qgD6n?_7R*8b$8)+lL( zi;d%xnrPNaNBorrUrQ%#mq}sr=3>+RappM`>5pEo1uW8lGy$(-#`_Bty+dDc`nAloB+4sq`UkVr=zC)ghk?M zdtyu_D7x-Xt{|hu?jOH1y&0LL|J^!z?Z7V;p5sLfCW zN9RP-4?e1`AVA{v5fdua&+BBEc%9r4``YNzL5Z-U%IS@nV&Q{$p;adjg5h}nE~FK5 zB6O?O`uoBnfgcD49;QVSDium%wsX=nTK)X<%cTElKhgT-Op+(ws58=ZEVvAM;ue=? z0rxTX6o&WQc;U6%5Yk2T(Pn207kujA1E+(V zL$a!Dq~+MMD%GC?tP382F+Sfu<9}kc_k@83<9p>U@4v(%DVtxI7Me`>M)ufKtJb_Fyskv|Z2Ff_*Wq6|a z#s%ly%3!8jB?fDi=4e;W3sXSKyA6T%urG0{6=v07p`9tF3MR}9xXpSR&UM&gUrr!N zUR4>L&*qgHH%_mw7MunLJXSSRf8B@FY90;cGPrDJ+1YM9LT&10#zWJ!X%~;){=}26#c#iDjexY_ zc9N$Tf7Qg~6BCC#x;!B7rqLn|-*`(VcH^)^5+t6e!$5ux4 zAy?g}mL6@)-eHT@nwBOlJ9@#(q?HFPGkTu6Dr?4B%Gt2fq|>aeOA{4(YQ%n?!;IFG zmP?gs7115*zuVv8O4`7=z`6b2Iu8~>TqRmGk90}oqZFzxs`b@4@4 zGn4N1qS?|Wyxr9^**y&PpImJ-V(YLN6<%h_=a~{jetW;)Ka4~TiL;X$d2Vrq_5``G z&;`k917}*M{W#}v1&^Q}za!v`wwQ}2e!g2jFPl1&5Ar{`3=MGVvx{4bx@~+lQzRPK zr|9l6aO%?-b-CK+Ygc}2u5G`MKYDoC8i)IL*o;~x`!V|-u&QY@fOL5+8+N!TBzSa_ z87x-C!onn7j|x1j&TByx!lmE~Fe#Uw`j$&KUG zbw*L2;T0n7YG1jNj^Ch&#O#lEx!>QPh-7`NV~a*-hcX3|g`f@;0Glz+Zy@lf#Jmz!72$%rU*IV0 zi)VTzBg9Ff6$~_l1aV7dvM5W$Av#ramKES2PVx*|gmre~k+Xk`w38Evqs>K#3y%{U zXJjNh1j{PLm3k^5IT$1jiG-98I|Nlwk{+Qe&*yBEQV$1J#3(6IAEvKCDUx;+5bxn+ zqa`Eigb#_hkrak=psMCT8s@7z!WhE@pR%3MW((L4*ezXC25Za9>o9Pmx+)+g$Ly$} z(<=b?EA(oPPVW2aXDtVy_Kc7p{1^hhS}b%R2glv6eQAeAI(DpxH^8xHC% zsu&A6En7hydJ&x8m27DW{X{q9FFt;YIP4lyYL>h8evzXA!n2BQn=%h9YLYD2+lzoZ zKpIYshS2$2EVBrm2`V+(C{W)m%e>|99>6UF;tu;o(=47YD?aW+zm^?>5@;{u5B|msdF~kpxe^%KWCded7&<=K;t4 zSp3hhdbie6XCjY5(iuQ20@4E}8~JwuVE=2W-TrYb!vC`>FW3)8?e*S&A7sBhOfvIc~EPlOC*wfy{40amg6i!2+* zAoy$PjpJj`=0{eT4l>|-*rVg5+o{rNicHiJo-z2LCkUstyycI#G&||d#VE6f#hH&+ zacRrZ+n)a^6&!aS^3kr}5Fka*Gf#7E-TdC2G zuxOHmH?eVL;rgi41x;y1n$Od~mUgnRM%P&%5r|;bw?}Jlq@|JIwyPCAYyGE32R7fw zbq4fkESdI(+2*YjJ#jN|3u-VkjI@2v1)}|vmCiTB{)^w{=iZ>Q7+5`pz|6;6@&FSB z+Vi%c_`uo8JX8(RyHMkv%lj%%;AEDw(9%>@Da;qmtZw-ALk5T-*0qQVvGn*jVACrf zsPV?^N(Rku&+pZ^Nm_<5PXuxZN#=%US+*1`sHrxtScM2d>scd?0*}wk)6$M>)2*# z$3GVjR+}dRewJ4+ox#I>IGO*1OEQqMLv=CcwQL6g^uY)W}}^ zP+xG632Cm-h_}G$C>L(PYWc+q@5!gE42YN%)LPp zbMf6(?o2T!T__*H8sBPh3C`9Zmyd=L-ivp=2GknWrOb9gQuGXnx{@j?B4GgTVK0Tv zBv18-rQ#`XX-lzpe6?NfVlGcp^eJ$miH#y6X7wx5`#Y(xtq^<~cC@AZFY;w(TI){m z>zXD>OslAih7uE!+RR1mh>P$&4W&J^dy9p^2;8_3xe}ic;s{n9csflRD{h8E2AWrl z{=cb3vib`yr%u>ec7nHMBPuVe;G0kVVuPB42s5O%Y&T}`wKPd71$FEIfVT{GD&*BU z5wPI)VbOk~PLY>m0d;2CXlzr~ zd?wRtfm3t!-FX6Y&b^^D_>g(UR%tJEQ9je-`<;-PdA;r!%5zDH9eEO-KdM90EEWxE zD-|O|nkp?qRntg1j|ttY)sn2)Oz;D|p1w4fttWKK>Mvi$l}~);|AkA#Q2;B!M6=aA z9+@Ai!LGa_xgRZX(E~GIqUY!<^JgSsEcLBs1o@7a{+z|55Z|Fz@&zDXTYfM;3iq2mtT^sc<~Z(-_gQZXYrO3J^|yk)L7 zE4(&*=3NWC{i+kO%&b>(P)s89Xr*8QpEqoLweTwEvc`mL`JynHm^>^wqp3M>xp_CX z8+Zk_jKhOG9Joik7O@{(yVrJ`o0fOWYeefC%0?2jStp%TPci;YrF(9{*rBPbJNe50 zG#>ifO|O`os?v!8`J8I-g+hewN?o^OAazW8S$5aF@x06M9?c8!wQTsp*J_l(CW0pn z&pwJc&Q9v;0YnatYuJ1Lcgt zr=ZmeN#R;O6stB_HY>8?b+F2g!YnY~#a%!p?t&^f1kxIY_o!A=CxvgM`uaV?($_=#}M^ zILK(_^=~PSW3T0+j?9)UxE5>L4FB%jub|XlkFPi&=6fc|{#r#tyYn~0Gvx;i{3n!W&DL z>T(O5W1PHEl1b>%`~!0MEbN+^tVDR#kU>dq_ie6+%PHf?>6L@SGk#0|iN8U`gkhXz zl*cv(1%}q7HQi0*TCC0#Plqnb4ZeU*j=`2m$|~u#5hz0lh(zH@$j#R?73Y|hxn${% zk9N>2V_S>8c0nsMgb=jF3A&+;B6Is(?(b)rk{x?&ZHg|$AdiOMr3^*L#l#A>=Mp5A zgf&2;yNVAJS~*7oSk<#BjOyvqg;C_BP%wMv{iPfOhoMp(Mazy*h!RREO&N<;GW#Gn zxf?7!RSFZ3#z#}(2?Hn#2c$smSnTio0dDN&2K`56Qqln^XeFpZiIfDf#lDAdsgdNy z<2rc7uo5HT3XrqCDkoy|?uol3?9t?#ICN;wR?ah4ZTI70RBj0hv2srE{lxPF++}Up zm~-IK4BhM?Om*(iUES@WBaU_V|H4jV72;XPkckIt%viGtlC*|nDIr)gJ%5BND7PaA zXC4|^Y~B=rOj3XBuqqRFidgucrbsB0jF~n)byvyJQymJ;MpTqc^Ug=L6J$?}CdUGP z_NK(C)k*b`c&B@Rdbh~A3uaEV-;xB@k`su@{@XT_icBw(=R+z#q!2;~mBW%q1u83u z3A2~=ORJ)jUHVS_LenSl8>urpDRgj+y;eCm1u$xYCX+fv&?nV{JY^%{wV`4P0XrT+@m;`%)ssZs2mS|LrAEiw2U}v`^$LQjf5ne z4hfe9M`-Mk+p_EFLfgH)s-6KtC#euAaXBa)byPi-_)fj?DG!#xy_&#aHzGRIiv?th z*rZ}tc#e)T=tZ2;E^y}rMR7=mScmYgy>uBWY18$O48k1}npzC~X!!g*UBs!smK@Ao z=}M|%SYhV`^VzE)H;+7vjz5zEY(7q$5--Z@nL~b*t~n-bqH(QwA3sXVq|mN6(7wESS&P zNW%%Bta-dJ&oXUn1nJ^2;20H2mf8>65kwkSP2)R$x{Ddf zJ1Da}#Lvkk2r2K^3t7|&qFQ80(O#q44$3pc$~4ViMvb+43KZTT(3)vrer9<2Xz!B@%dB6@E!#XW5)M+oAsnSu zz$cd^uO;SF_S#*hW7E&Y3uI^6T?^HYXdLDtl0eR-ES_j-JETgU%!(Cngim$)We>K1 zgP=+$?xG!oNJvA;BdwtYey0V&ytkw>URpY$I<;j^D;U;7vxRHvfZuaBQk*1-> zwOE+WnD%LInit^fy5Oo@%}Ria>v&WtHMDd@6HZHF4hI6p9Mi`1*A=|q`;}U0zz|a>p+@t zoPM!i*iIignXX`C(WJ$*Df<@p>tJdsQ?VU1z;|uJabOd~aicQmP_C3Z2t6rIHy%AgGWp+JPkIE6aiA-vn`*df%? zbLj{L$Q^DV$wCbhN$AyJXF*Fe_v;8)+z`MGK5hun4L)8plG_=Hafe$ZS*SIKc%oK3 z?f2d=Aw@ndMv~GdbcBRL;z2>&Uj54JMuj^oLPS~}HdX6jBkcfmQ_I-_y&-7+oF~~4 zoW&o%AwkB8h!s$gHCR-R%0;+$77uZS0LG4otA7q6HJ|cF=IrHgo&n1JQeb|`p2}c6 zeX89wWVgt+;Nvrhrw6%i9LWg`o$Q0Uy93mC_z`uc_jY*zk;m3$FT_rf~)F zA|;a@I>F$5{_&7YLY6v7u;DXFd(|nbdvTbb$P&O?$Pm{IZ7IsK4B4W6{{k$1ZwnEM7PNec=y&m?Pa`D4gOdNexf9Wjif_O9L@j;M(aSb)G$7kYtvF7TrG6QJ6=2|IS9^9>H8eLh>WbAAb07ujPV85Na zuzSbXunL+5Thq$(q`nPn)j#-kdeQCKzJI!5_p+oNTSs*}GM{E?)pzhkZ^v^T<~6b4 zLWiLP+=ekp9K`VjE|99`=|2ifpwqbuGEO!Q1WAHY!oa!?4k(Y2L+##jb0gv-`w~j^hnR zd&+4Fa!sX{zUw2M`e|qUA@$&#lB?mMshtN6$jvtKUg7ZSe2wxn(VKo;UKOTrbkEYX z&e6Go**e%ncz1p!IM~eHq(BZ8a>Z_lV8NNbFjD{9G(b})WKHoVplO?>9q+R1aK*81 zY4dGo_x4G3TJ&nO!;Y-OgJ`{R)}HBcuWRA@m}RQ7cUk&|EUeLsY&3vOqG?#<;Vt## zcH40T__De(H-2)@$)#yx>Qoi*W0i0D!m)$*#K%$Yl>x#JHOsbQzm__e!#!# zG8#@*_Vnf^u5!)OM&`2BT?AiJ%S(8xzT4=mWr?kJHMzz86mQ+d!vw8Msp&z7r<2UZYYMDvoCM>EKl9@yBXa+9cO`}nULFb~HK$T3#edWQ+%mgB1=?w;|HYrtT-W!1=p z*ltAEpZ)9K*Iwx#L6%+Zo0EyEwoeHjI`b>jOZ$6^YX?~YoY<@P&XpO|9#G=5Mjh|F zX_k6Sylyl(Lyzm;#W-9le;$s(-tYlqIi?rWXPnq>W{uoe6s>KPv^^pcJndtf8wUZ^ z$X=hD4_DT9`kC>LRW4)ZcP~_U+i+)_Rf(x}Y$`H1mQ}=7pOpIiF6;UqB3b} z!4mb7xjfnEwZgmajVo~Y8haaUouk%QbuZVoYyIuEMh9do*@}I3X+s8Ci2|}O+h0CU zr@QDB_;5chYf(A!o}xbT*EWIcw*k4@jm}Tv?IH)W)1M0a>YXlDW7hbvv`~}*dY&#L zEHxbO?_hdPE(vNaNXP1K#mx5mU zx~D*OpR?#(*>JkO?;Q>v@5&WJoLI#m=W3BZhr34~`5af@vn-Rs@t+~_0TFb$4j*g_ z$ZVfI7B?i9_7`KOs;xWe$)oE=12F5cZ`67oSnrg;BI`f#XNBiY?|Sr)C+C&hvYQJ`>>`>QQ)J#x#O)9K<2-KuSOXWP;86se5YNVRl^`*A}MS5rk)lU@*5?q(tzulvp6 zc;=%x53^?kMaXX9^tFju3$y#R%yAA97L9b*v+?uf{z&!j*ikUSGsV=o5$gxT}UY_h$!p zH+Z@|<}NT|Xg#Xp5HQPOc|Xd$)w{p*b2Lc){JA;44kLS7>xG}Wg0tTFKB~>?SUvKr zJF_wjxz@z(bmz*!{-@pg?}n&Xj~Cyz0k$FC`+ep@t?H=NROhFuO?UmOPe=cw=f#E1 z;>girYoGCD4Ib9BqptaW&*`+o&&s5x?WB#%JJolBb+-v=Y1e~!+^ZNoOiw^YSLfK{ z-(DVf^1Kk|jSUa0m*;4m&*KAyt9=df8@8qp8Eh8Rrd;R`U3(8okYd{_6~z1VPF&p! z@7(=Ucktm&r%Sz5u9A>o+ruUSI|uyN>NmFKsx;WgrTglyUr4t}3m1<{ZN79Gr)ypw z`^8WaokL^i_6F3yU0RlTSf6)J&WfEbhm+$q`y01h096hFXKF{mW9!$&BP=#wkV`lD zJ)(Zd>)nGq?K8Y~cRiKpW51y!142~Rvb+0uWx2OcSgwwP#UmnLvnI+6+pgR!{v>8Z zJg--Fz_oNN{df;+df&t~UDCE4ibgpIOHK>=XS-6F0I}9Ae>N03iBRRRXKa%J{3a&) z>-G2pQ{m-E^>Y7GS5=~mWanGgVcS(OujM!4lRCr@#nsuL^-O2ya;dn4Sz|Az z#j1}9D_K4zGVYhYm}?oD4w-CgRqgJhRavre-^jF3QaVl3av)*t>@EMUec9_leazYW zJ{R!g_ElH&N<(1ny4Xh!_S_ACb7@y^RAh`Hrw??T5in;2~OWw>5|`LO~IYZ=<9iXK0Eop7`JALy1{y!}@O!bjWeCFy=0aQnULSD4vCe*s)7mdDw%=JFe)sxsTVzq3vmxhSdoes- z%b#!&Tn^tyTW*Kp&xqfTt3ntIPDJSMT!K}^LD@Cu~7IU-(%sqheU zh6p_!AW7p1cS&0S?1Yz+M7oWvWF4%cdTX1<*7|$}YV-8;i$^*BJ8Ak z)K`=2q~yDF=?YEW!Cg&jg^i|btyF-UPe|YRhVUjZlfO75cIWw&Qa}y*vDC7~1Q*H@PeDfmH=UeCKxJC1*?wWNkI;|56U(cM_PBW{#+5Gv3wL?T zo5xXQyFm2|`oaMq)&X)l6tLB!ztU>BJ5QsO0G3Y`9kocu)9OCfnJ9}Zw6FN5R_&9I zCst42uXN{WX?&4oD;@#0e?v6@0eHTfZh2sOW0E1tm?Sfn;z+Y?JDFbP{yO?0{Cwdv z8q|*EGg{b4zciJa_6L`{Z90UGz?FAUPjkgN}1B84G@&Yu#^y?B*p(pn4QBLu=!AuO^&~ZM$Er5Zx>|d6@^aH z;tQ*$q{IO6VkI(|*A~Mh>t+#hj!t*Sp5OC|8*6ppo0VmUvZTBwAwSNeGx~Q38kVrL zf)FwC4mz!v2>N%H4Is^9EuMlS`AE5KM-sO{Y0a_Ny2<6&r8gx}X#4fAIPU=NPvzBg}@F%vNv`rgtz-o zxzB`~9no@SJ(zoq;uX#`*Xx5=83Z@87BR=guI;@GWI=&^Qq$hHAloPL&+A-Ca28pT#V-RaO4VY3WZ zmZE$t(%P!HA&%#m%ne%RvFDh)Zf6?fo_6_bk7$3b`GOOQSLRj?qLl0;%s0Gdr;04S z;ez=fZF00jLV31kV(d>-ZeWo!vhmB3Z+J50Y_%5M{_*F#ZIVBdA<0BmCW# z@7Gbz-BpiYb&sE|we#RD;xgt~Gqv8Po=Wc-AJj}YSbKM43&vP;&w$!xyl5euYg@Hb zReQd%OT#=*nn?d;jaRpMTICpT85qEIn z5k`i%1en+YsX$_5P+|%cd~sZTZ>kQw!F&(UvBiTsD!SyBojNj=+DCdk*v60>rQGk! z6ASSCBQF@iH`W)J+br^sE!S@okCq84RsZkT7gpe=&bl zabH!W1o+`NJqJ_lIfR^%*3xz;;_WO9%X-QfbPB)rsENNH05^4G`dO8n3jE_TB|;C~ zhD2^hhn#_u->Qfqi9*V57@*@-g%ZY!NB8S?xmmY0AM_4wQ$8};yhmT%Utir0pZQB? z-+GAbrmtd(uWzLYLV{M-`WLGJ;98LY1V*F>{FRK5UP1~HF>wSMvyhZrtBBAsAyv;V zHL4|V9vs_Awk1CcMm8aRJMSI*r(eHVRVbSVt32>Q`Z@0t#;3tEk6VL5-tTN#%(%fK z4>oxt_S9@b2!Ymv5Gt<`rE#V$tj+90$g4p=@7F5(x45l;L>igSW50+K(1S|ib|sH8 zp|Da_+~qMZ1P5Ytn7?j%VSdytdT>S>Xq!My7i%RPSNF9S9<3+ShAesahyRBZQY%oI zgl2V}-y**3?n9jAPfmf02&Y|imf29}JkZFs)i6Bv^im!rQ{kg(hIu`o^oPXXI?<|; zkwqzag*hIJJV}cL%Rf&OPbFalSmpByIOW)47cG1OmoXZ~Ro6{v6e_Um`EZ7pSpmIK zbn^Dh&==uUwKbHY2Pw27!3TC)aSH?u+UUC@DNzxZp=t0z1J{u_119pZ4*NaLJ)*u`IJQkJ+-9ml+jZ!_+I&y1XSoc;2cZ)(TF$EwxisV&Vv-gx zBo+Pf8b-7QBz^koa|!Ak1>v>k9MINZLC=vDqqQ}j+Vg!(b-;oPMq#+Hof@3E_&i!k z)^fAl&=M+!c99vu86zQ8!FY!@oH)asmV*AG3wL2S5<}QD*y5uY(vUp{ait@xt0>sD z%1{OdRFwR>iITc3CBvO{i|sK8072}+2avFQ4$cX3xca*qq0wh4_?@f|z=`wg9tifR zg=|08`D9+Z^!`ONrBjMZ>JGY`*5-l#HreQyG%U2JsY#bIILbWi)rnm$pe{gy#x^Kq?qU>o>;}g~f?B>@gHrf(m%TmvZPT8L{fzy`$#`}kehfeg5e3>duV?GPdK_p0t*f93W7@HKNi3A z8mGZYNJIUL`iqF_d=n&l5@GB$E(dVOpLC=K{|(y(s%fD&7!e|=%Jbc%_$t?#nwGoq zR%dElJt?r}OAYN(&bo@IEVPuBniY0=B7D3P0k-qP7r(`hU7v?mF{(`h2)zIZ&LO% ztq~<-7F2$LRF zBh2Z|rzhrvN2^y&#;#W=Q<|;Zg_Z;C*M`$DTcZfb%|V*DKORlu!KQV-xvAAn(4!YK zh_mkq6>ZbQtDAvkLc&gysr9%eB1iHUQ*sR;MFOzE*b5-Yqn6tg6THnM;948>mrS^j zid#K`x+T(CBq%B7wlg|Ew48pAW>u#bmXHoID0GrLdCj~i2w0RKK?a|qMWKY1go?5{ zGNFMLCk5f1ltmr!y8Jz+z`A*BloKRHV&7}^@t=8l*K{Nl7!Fbh^TwYWZE%?@R$XQu zu%i_#mj> z(lM~E)q=97nTiWFdB*NMlx<^gN(hn^LU?xg?<#w@K=6OY2(-13se}Zf0x%$Q6NfVpqw88N+gvN8-=(@bM1POa2rpSN)IS+}AtqpcI`pk3Ab~~>ozwO{+90&5~`jokkJ^n#3{S5(D`}8K8Y7=Y6J^-3l z9a&7?r6ac3Rt`a4!FfvuI+cgsn)>eD-ly}F2rc^ zHE9->c1V<~6_TX*BgYcn`}_KRywkU=L=lYnrZt17z*>|cBggtf=JpnzBC9HuBoq7) zUPA=XIuVi?A}aP{K*!z9xx$1PYpdi-NCEQ*!`~4RkJIQ22lL6{sliikZBNpaKc7-=Nf006dRt$6z^Hi1SC%CE{e0FW0`#q4JrK| z>b!V&oWH$SfpxiR+=uYYT3GxwFK9Zxt#Se6oMbSYV2~KJf#?vb!a&s*AjG2<$LY%ePhK`WbO6QXHc1Bjx4m3pq!?@{9uSnK_WBmgm&#LCc3G?n3=o> z_Fv}X$@$;$_2L72;)`yERK4*uyCxS@sRS_X*|I31h6-0dUvZ==8zaTDZ)$-*ShTkIZAc&K-_EGs(Kq2WlJD@ zX)NB6^y8ZkIMxbB>+8x!*lFO~tP~Y>LYlg8;7b-JWOtDDWKdzbReOHDZDFRpH%f&aKU7qX3l!5p4}FtI->O zvVB4$C-9_cHAHBs;>eAQ@p+$l-%~R1m}V8QGXJLA3aN;p<}rpWWAa=kUFBBTxBEjQ zWa|6Glm?{!La6N^@%ukZRF%|4Zuj04?azv?X6FZ8pD$5c-km9%c%kAUqx3rJk_+{Z zE~o8r!p@PGWV-j06L{UuUN#NSy?|8ZRjbpFjH@wcrRfj4HvSjCgVvvh(S=T5K|xgM zrnDcpE-T!wv-_GVdTBqocWBe+52~BW{GM2z7gW%;tN9TqUTrnjk7QlFQ3@uruiqaD zd_GZ)Rr{62Rg6oGgq^p|{6gIW924q}iA-}fbR`5f@_Mr@>1yx6hUS3u4$V{FACC|j z7|AY-mfh7rVm*!Q=7I66W)kg|{Nm8WUrA1;8d(VMq28`)PdrQ4dJc zI?il{0VoX;5CiAb`)4mU@{^(aw0|mibdB0c9=9&}BJ0;Y5Gb4Q2MkPkk~rwxI~l*Y zBy;cGO&#iwG`~JsU#%5)x@&`{ki~s^sKSk%fMlCXwLDg_5Vy zI!aH%+}N>~8q}?Zq2}95qxTC50+o??=J)(5%j$}tAR@ElYc;(m$ChOq z5nB+sBGZW0&LzFLz&BXvMv@DO<4s07;$p23cEU;_W6=wHzCDkrq^{|xYe1MgXo}Qk z@KZ&zu2KG4?3eW7#cC&gh9%MdzjH4wQ<*$!e_}y5)sQ`mb}J|z_qD1mH+%(yAiN9C z7ur!SBZ>sMz2*$J9~_fSHmdb`{3E6ox#DiHLAz0V%|8?7LlsM`tMWW$QP#RO7psPy zR8C*VGHoRA^nFOrTXCAVlxEEdv-mBlj~#yDu$R=mf&qGl$U$BI_8|G<*L>ppO#Ok# zN?J&B3Sm8sQgaergq(9Ko-_VU%GI#4sju)?RulB6Y~^O-D&!nZb(+#%{bPX1(um_5 zg_29lmFoK5n97&f>$Pya#g-NOgX^q?tF=C=n^)845fN3T$&g&z4gBrXI4ed$IZcz( zOs6O57@%v_ird6~NUmer%hP)Bl(&6`$G|Dtv#g+fi+-ht)Mxp;-RLH{j@S-Lhd!s> z^dWkj$ySrcwm9G_#mX`XWHT75ZlIaxK{ZX8$K*@7{M2IA=Yr`b>}!xz_W)W9h`&q{ zLvf}})jS$y6t~ zaUUn@%kCu;tulIkoW1#DTvW|8@$JF7{=;R3n)IRM#cXL%g!D2T>yv1}sx+nk951$( zeU6Qkb#Y+BK>tZGBfW_22~?JhEX^pIoPCN<0!$S;n>|CeU3mTB!Jor zD)F}6Y-_#9F~s`h2ZRLfjyJ{0rK2Z2xcE$>OH8tz2svzPD$wzzigv&FttRJCL2^iX zusFu{1Z|V@;5dl)*UvbAQZk{1Ul(>)L@pi>Gbc<#RRriv$mvn!t5Vs0r-!az;=<@c zJ9XTpqb`A562x&n&E90Rdb{{9^qt#k44NfouN3cj*bJ@r2x9Q{=z>CvwdtaGXgq(< znCd9Ux0m)?GG+)2+ffmG0_)Qchc?NPyNSwKgLDj->W6*I1w=l6ZF+@& z8N$ua1w`14-?C_E8FD70{=!DcQcIVFnxc7SZFP@_%Skw~>mFIOh0WCTwO>l{++*_T z=CHe*t2h5rE2;wuC~7BxWRgkwY{U6DEsnKV)_M1^rE7^6HE!*vv$Yl_+G?)nN?i|k zo4d`&{m9blFjH|>^CUaXqG9r?G-s{JduROA=iYb;ALy!^gsdAnJLyFa@O`3V;(OS9 z`fR0}fFUJe2VVRE%C6}TYi-7S(Jku_^SF8Mn-m)+x!I7LYS9K{1w){e36W%opBp|4 z(?a_fR=pq2(?9!;GSG#{O+hMy2OrzUFb#995E79)3{el#r{HJzH#*QSm5^C()I{YJ!G>NI6u zOHia2*P*N8V<}q zqcW}(d!N_W%&H8Z_S6j~U;5>IAb^J4*iTm3F+84chlLT%Nz*qM3O!Y-vj)QKX?u4; z%3O`UAMtt@6R~HR=%M z{L@4{7;hXl=kj_hxxG_r@n^?^I^DGj-@%xDzr9^zV;SV^Cs8*RldjiCy-S5^cP8&= z(}54y9^F=vxa|sXqJ>9&_QDt_QrB}~tTPYjGHBhS`!uum%;YjxAnRV`+th!?BIULbp-k5*-C_MQ`6-or)bZoHhLZJU=PDW z0DACoyq6u^8$C~s4NiO0ld4H3V5q>d9WIiN8v0PbYH~3l&C}x&YN9&i2?>LZLtGGc zte7b`CwfC)kB*C>k+RgdiA6K#jJ-``hHJU-^FHDIbdY#;9Jcds(s@NbzW)>f5%3SB zeZE(nxN}Um^CRGv*pMPyj=kZDuHJwv2T@X9dih;zWmh^pT|luVeBFDiKMOx?G_+ib z$~|sg18gF$mW|4jZPl&LAlHm*waXW>>%G*oBQAa9LDXn3I6ASkpE7h@GAHlvQ>`vc ztcQTUm+~#H9DQsy*Ve$TrrXJ()z#_Z#>JWPlP*h>x3lcKrFvrIQN|v+6ss{()mr*+ z5OslTz4ix8)3SxnCr}C}I{8Jh*(+`MJN=fIr8v+MPgxGAmU^MZr@&fGlb0e)1_ysotJ)UgBe}onn z|J8VYM5OYX_+dDF%CgSvbbwEo|Cbl}=XYN}1u{sOtboF|K0?AB0a{$SIF1@Yz$&Wm z1=V#a(`htfD7i*uN_Dmuzae6%qn=5ZV_LyZmr#^A5weTb?wg+J;v>{(U!siyPqJ;u zUc~oeai=wIBI2+E7>z@Ln@80hfof>eIx%Wd)n7hCz>n`fqhLQ$?xJ zSiXgS$7S7Ld=~fkYpIh7N2g<@DDoffwiZd1w^n(hj_Kd|f8cRAxU3zvK|DM*Xh{Np zO#3!(o;zN6%om%@8*AY8$9~RLuW`LxX3_d-jBiNc_vfA8T-HG;%xPdt*qaoZUUSb! zeC7(C%6gy4(be&oog*j?Lso@OVGahGNY(3!d7|yuoU{GhuNo_*LTe;~R@gToGe^Th z4LPA)Gul?aV`uBzhsD^0Zf-5$W0fy;Wkf9Gjg{xAD#NCH-p!>R*n$}TdD3%o8Ew;u z+}kXZ)>ByT&q0+=$8#WDbhY_&qxs9UZGt6>9_dKkA5f>zT|a#;VN1up_-YQUw=Ao? zGUYAq=wfY`S(MPn@49C%40=4g@&`0H9*T4F%$(U3GY@UR%qg)~_>HQ{eM3#H|L`B_lz8*zW@oqgy%YRM912O+H^@baX-phwaQRq0q2 zgM8svebaY-@(BK475j(zB*>sk_b=*Tma0j*q@{-O=t;WWwM%cj&M#6MQc`*Kki;j?>E^rMs)r#*ob!W{ESOJE&pbOjxcl>QLdxF~jS{)07}nQU8PygEOHhQ5V)AkT+N>oe;WdU4pvvZ^++awS@3 zk5=VvqK*o(a=L}RO~Ko#A!`LsyRtdlqYS3C(cTq~|KF6@%D$CxzD-Z1TSxaBVsu+=>29vzlgU zN`zBF8SH9RRvs_IRV9TIKX&U~@MoCDq@|du!2hSu2g!m}`VSC(RXgt|(>ybWXlgET z$wAzNbcQDez_Qra33=Uwy^kr9fEDd*Lmb(zXgrh@Wx(>1X%8Tt5eU?%VKmK%RwS?? zPB${)M$8m9Ury7j(J^g`9>=l)rdyj_A!N#bw6*Cn3^5IeW`(WP%ve_|6^Iu<0BrhF zGf=oRnDS9mA*F~=s_@H{nQ3d~?#G^##AINTTupM}+@L0^rrg5Pl5WpJoD0x3+VEsp z%jQ(Kr%R%$zV-yMJ!Z|&1a=63tufMSXja%e$b?uLOwzJ|l|b{4uFM}m`-|a!jj$V&*IBibPHSsB1J9_0feXyq zn62Z3b_AzD$FS&i#wD^{Hj)#ZQ??mcoJ#db56c5@6?+V**;ki1dkg^8OG~AO)p0w(Th^YKL@nFX)xb_UgZkPF zlw0D5b2DFIs(ZH)S-s^&L_yh&np!?Yub>Vy6MNKKe2<~Q4ZKq_s2lM1F7SoyAv@X! zRC5tev9u(LatjZQ1>Q>byv9Ed5Bjn!#SSamoR$Q>1V1N6chWD3#^)?AG4}XMZ#38D zpx%l^EHAMmM8*3x)q+0WPVQ;}U3F_f@!Y8oylnSGP;0$qKdjTmU6AeRCc={zl!Qc( zdC7hl8F;JLBSP6-UyF$-C?ir=8;kf9?rm&xfcO;ryfG+(cY3$WP4X0Em=o{UT>JLv zbTh)tBnQzrwIYz$N@%HFd9y(v1}?nK_9JTt*M+mQlIHh zV05R3*c5LW=a9ia3vdY>DP|Mr5vFprXQzqDwxZjD1=7ndDt~Iv=9NDa3SBp z>3tmOCE6d0%*gvpyNq=xS+9rysCe@64J@Wsae`JQ_5;#QL2$+yK$?e zuAN2NTAB8FLW&>}z$dZ@r29w+c*2GFf|rLlTJ>tzXjt!HO8)E}lEp1N5jGucE12(~ zB_b07Fqu-q3irfANBSc7u)rQ^M!mQYDzFh+Vl`8WOwk@^=$Vc{UtHpUbz-;R;y!@Y z$#uficY?zs(#TP}R*01~j0gbIV%dyKspeJ)#f8)~pm8c>tFlbWLAcQp4{#wct=UFi zO%tYFFb}=`l{He4r5<{gE|}OV2t(q^O~7-g@Wu?5B9z!F)VIsux2qSqrvZKd_T8do zkC0}=ggu1%;s&@Cl(-ZOv{>xFLQc>U`S2imGf+U^uI&IcrlDh;!$Yg~Ijf-q!tvlW z02Ky5c!iGK;XyD9_ny!a{Zv@q7+Bx_a6IH0Kg2gY#~DFQ2B0|L2hP6TlE}TB!o3o- z#5-KbWZ|B0=m_Hgw5#ElaoY29KcA`d_>W}p->g(PXuj)rO9VZU!Ipsx@Lq9#9fj)#Fi zFz~980No^nfK)<&UzhRqtBmg37{>!>ueJLtpAawt9+Pwf%}Ne^;H|I}j9nc>O?n+6(>q@<7*Gj1Yg zJhM%GWt&a9c(3S7U|Hx7zQr*w?jhnXQK--1=0;b_5HQPlX-EhE*cfA+J++un2vWCD zN;envFem;c%pE;uo*{fiP*5^*3ZijJD>i-07<=XAiUrHvR{xiT3X=?gNs4nvvzTWj z>{xRREe>NBGYWJ8oV=r1%>F0o>xbDSQc$8mm$W8_;>aa$`i`|J@9gQpv_cRLxH#TL zL7mG((Hu(LngYIcvMlbA<@v9A(%k411^-n~Ap`t_X&hEP`dNjbdhmbM%YhZD!X0g6 zn2}I!&84+CEM2_pc8B2Sgx+qD9_Uf@9f{x4Dc6=4B4X7cqiDWF+?oi!t+y%efk}K7 zolO$bP4sAxzU5RLDd0_)vEDT(UcRy{9wF7GK~9%G*J8o^3JHP%W(WhUCS95wW)Pz_ zm-@o67R-)Tm>v2sJLuFGOp7bxhti8pM>EEfc%ihjNeViN>2=abFsX5vl*ND6rZMe?@XfcZ~8tVQkN6@P=8BQTd-Oo3NsI zeu00GPyFYJ+b~ab_^&7;*bULJ8~XlNOSeVF%a>=AlxHsmd9$g67k_ZsnogacsV1zp_Kr%C(z^07ni?v{zUX52LLnP2bJB#bqPxjkEp z%Nl&DW-`)j#)VAm>b~TuQrdL;Z*Heczv?ucrA``d-GDxvHOx(LME7_8c(XQoAOJsT z703G}rfhOV|1u+f_*4Gjr8$51!gK^PU3y|9fr2q5HeFgIKIN(x>IHuIW|<>MaS}urtuAL1yqQCkR5mS zTu#7=EZ)0K`TWKUeh9uBMqPugk3FKMl-F9A!q$MMbJzWWRefa;#kOK@@Plm!i$~0p z+CmN;?CoK%f)sx1jYfN^E@x}cF)e7F%JW8zF{LEp%; ze;_oof7%#se8`J@>KS@bd10{wSt@*;;74ALYq0gkZzf=D$|$s*t#9#(H!j};?o+y) zMGZVV$2}G{lk~d-N7F2^SEALd@pYr-bVC*ZjpGul)Qy!AtAIw=JloV2MTvGDt7eo+ zNh`tNV);sSOY$DgoF~f4#$IxpKyanmKBT zC^_5asoSr%)l;5@3(O6xg|6*W=W#1p67BL#?KzW&)5>xg;gOMT`%E?HP3jM%Yog?(i7iRxM zLi*>p?{}%Ri!a7RT0x({!XUl-B>23mHO<|h7D;>yZVio^)zPtuZV)ZEB(3GfwxlM< zko6`M+lyxxyeTdWa9pPp)?8Y>E| zueN&Ij*KR>M4d2e`G4>FoUJjhGOevMTa#DNRngkC*Fi#sJ85fcb81<}US57;S=Lrt z`8zLv6!PN0w5X0hxjzWaK$pdl@*9=DlwFf0yD`(VK875B9z8xLW**hGCMNN8Vv^_y zCxW&Mi>%KHWA&Yq=~ac54e6K2SpM^-kSOKTS|eb0YyQ&S{v!PcMS6nfr;2?OM@#vw z^iN98uMR|K?Zj*)io_C~I=qTz@A`Of(PmXK=$oBS$ceApP9%fR3qy~pxT&%F(A0Ou zO5Jp&7^Y-{I>hMag#pnjvFETIoXxe;T(7W~Nfi1H9Z$r!t595IO2hJbg13qAgaJ2C zt;b(V-Has~Zvs;IJ$ksf4H3%73xAeZMN5}}PxFQclDX6`b~Or}ii(B`+rofFG;^8o z_+GX?`6}hgi$R}#Qki2yS3XG*p$u^AUHjY3gp(JZv}PMrBS$C+JIf$dqggd+Eo2#a zMU2NwYVDcfno;9YsDn=zg4(qB7|(VnJJ(P=T||p4(JqccONqi=9~jOOkJ;AeXp-`4 zQ3kT20cX?ToEH0e_&Mci{%M*%iW_M#h1QJqjiCztXQ>^J>SLGgje@6}cV|1Eo~Y=L z&fQ9?_!5^5nmI~fif)&=BdSQiKkCYc*}ryT%f0Bro^gWa40=4nDCq_w*bK;d8?_`i zxqQcN_A~HQk&Ye#zr$lg+seXj6?aWCRL){ZG8m9HEzLtEPfJ z=Xp-)FA#B+r6Rd>w-*gv9BiP?cD>(1s#eCFqH@?IMTbu3&=Oa9x%dssuS=|!A{X?i zgjXG8)C(OK1fT!CBdTm`R>wSt8OJgI_&!v2+H|W*Wr_rPg%P79UFvqUIajgEpw1Jb zr7Z)WrMkj{m}j6>uC(rgbhb0Pgk%z{=U*y5>Bwc!vARBkbBOlPhpV_Z&K&Cro>S|`s@ z$}GO(13s?fiL6M0H=WH4070#RTy`U}UnGwQE*!H{y%T+wlpWM>&4XyI0_l*(|6W)^ zLjtA0G+sME#>%x%8@nK=<8R%+jG2F$Q_l%X=|8TS1y7-%Bf5x6)!!4NlxvKp+HL$n zm!9H)A;w62{U!gipTDaUq#?z!*(g*Pa269hK)i^3mc&H1O;^X9UkpYN79MdB8Mq95 zE1wpWY${D-#dojWe*~w-^YA$IwS-#c&T_2JQ*nPPwgFZ|m|H5RLU9?ckO^eRQ4(@@#lZdKK>3Q_hT4aKe@O)>S4$+&gPH`@g`3SyKQ4u^ua{;1XIxK z?7ha7K=cuJaEm2Fj8{1%;Ao7Y^L-_5Bu0_@Ft$`T2^_yffo{JFoH0L=Y<^dorVjQz zV4C+{wq%tqUG$mHj!KjNd5_&SWb^OD8*7K;EQU^N`IOm`g8e|wW^mxsUq`l8w@u^P z?=x9ErCvS_u>@nXY)2zRj!pN+kS|11@=~vc7r8#~Zyc@)BNZFZ&9nZIm)E-xNp#{^ z-Q>ElE8^!`2xO^C{)}6kYxkMksp2tgn^xh#OE9ux-N_N4qn2F$R_+ej2)&`}h$Sg2 z^YYN-pq-)*qYN@GrL~*6ro-{Wb0zF<+(jJP{%CX*M`qo(W(y3r|KfMEpP-~ zlNgO=?+CA(lXR+2UN#iOgcjhEZGnf(vu184LBhVHM^jfds)+e;kp`a5SgtIrNV&2O+r#)sS0gL?O_#m6`VUb`<<)0K*#t#DQ z>9w+(=$ThK20*Q1eOHTIg4PQrccz-1f$|i_0v~pOTIl#(_*6Z6q|^onHImEXiExCE z;^3UTT%>t<@orK1eSM^B6f$;tW*xc{g#Rgu;So?Rc`Ja2Q_%gWrj?}boT2;>J$K^N z{6&#_cb-N%?e--@*;qVNp-nHA@EjPgM=PJ}x0U%--!k_7Bot{Whk+YCEB|dj@hnmx zKNyMo{VcV_aeBb^=$-%eNwn$x{Q69o#KBU_IqtR*_-6-74o(|=otAr>NN^# z3`+=CuArM&?WW)<-F#$@olLRolYGFHM!9khMnYeAPKCtJkCU&I5EqKV8%1(Rcj}mh zE=~nGHiaB{Vq8H2$*mA*?1o#hfrGX<*iEJj{YUqJ9HqW^l_h=IKJrMOvHC@FOy%V# zo}Y(tlz6>}*A<~5%IyPIE0tcoNMIrb6P**$Re3 zu+HR%v?f-q9@&Nj@PyX^=u$Q`pJ$BS_^2R)dlO2ujp1xx z7)k_v^tyLGf$Z)Ko-NCINzI|nt|LjAxED2wtfPhaU{Mqa4*u)0W=$F!>LBDTuuh2XNhR{s0vCOdY%}+ea%_k3 zU^%r~FnjZBpH~JxDXilD_NziLnT~g9eT!2wQD>6MqaA+NXu2e#6b`o03N|#-h#{TQ zSj}o32bSezmLDg0T= zW6j<}`jR2P`f<#< zRQ&U0y$k6b^yok@3>jlRrXpy1&gz(+>v%j8N1ui)KMo~3H)FY`x=4*PtaBn3+%F*s ze=QZFCC=zYRoZhZ(8oN^@~pON)3b{{E*8%$?$y2xexF74c@#DI`Ax8ffvw;IIy4A8 zQguT_Z{s^wjV!+O@0N>H|1RyOu+znMchta4dX|r?I27)xOkk3qNuGmMc%gLQU{D?A zlKt5Z1@R$n>`(Z4S`Ru&eviI)QV+*xc=EIDfurU0j{5o*KIvnq{j>6LB=k0JQzV9rFx89G!tC%e=C1dT?yVylZATXlTDJ%{92Mdb zRv8~XoUaghzI|5?q7weP%(bzAO-`w?k$sMG*XX0ltP`Sou~weeU-esN4Z8DL!L1@N zOC?q;Y1vvlS;(~910;oCaXmkzb)iof&idAl;e1=gD8u&UYdb z+2)R%;hfVobg)5)g4mhla;aU;7hbDg(qAavCNjLZm5bu{JB;C@gK+`4_fPA3F>_u$PMf@g)?O-AwY!vuyN3T?wfeN-b2_M$Y*8dfQer-N`iM_&E`q&wAh zy}g~VbY{#7_?b@6#DxtJf`rc>Ewy)D(W!=87#@kFujeM+^Pt%V!i0I^G&)QV0WOhl zhdvwE%nG7IrEbL;?E04p00V{+&5Ouj*V(H6L9F77S5g|!6q5Sm8}i}aKY_+V_xH$s z3#H`F_S@+ejyYIOkt(onu@gIt_&Fz^HK3kAWlhd?Va5yUM!~F55jaAcS_r*(<1c=; z6k?|{k8iTK8N5{Y7G~C-y>gZr12WETJ<0e_X5D+tBlaHscGE%Rpz!?7%lR7dyS9@8@m_+z>J-qXUwv9HYD^^-qWk;G z{RuBW?m9q*qP8`fBYw# zhb!jy_v{s3y7Ov}+^=Y7OOo#B*6(2a5mP(Dr(Ht4x;+^>$!==&MV_UL_*>|E9>N6g zVeFAc(8ZRdeqJW6!t?>*OXI){9t&QR8Ug1q>oXLm0&pBb+ui+|h-s`r ziJOKOVZpa4@_k|BuU)k{H%@fy^s9Wd<3r z-(abmXa3)bIM_E{M_Y+ZMY$?x=G5EY?!BavU(|(Ep0^%n_Kf=C)2PJxC*4nc$yJ5t zIDYCqOrIY&How(m=;m0Jy7j!>^i=gP=kR=4Pkk+J<5LMH4F@VZQ-1!u7{DN*6MlP% z+N%?;`y4oh;5)LPO8Ra0ndEq#P}zFEb891A>*2n+v2oG0I#c)@63Y|`dCj34-AP;_ zwqhb?F8`bXAqIYHbpFP(kh;k8O#@#sJXThibn&}Hta(_nIhkU7N1Dj$a zXF=+i^%g|DBHn&|vg}WsLi3AP8Qb6hC1w6|F3I?qJ?5RN@bieNA6PLKgyPs6k~Ce^ zq(feP9nyD2P_uZkyE?lSebQ;gYAnWc^sq4lH7mBO*$K0CVJr|si-Knj&G0O~=o#;r znKwB4uxEJYJX@Y<@$p8Ce!7|uBpps~#PB`*)3Kz@ZDJG#EAbLBB+IYi-?#HRR21d! z4xVfG>JJd*XgxcDPlE&=)!RC}X6R;QthS1Z(c_gG$(KSJ7p0aq)|PwctU9g54CtgC z#*J|ht%x4&T5~#rB09SL=1&q*;C+YSxCf?g?@W-v&IJ}`1p^*@qi16cK+YF7PMcXy zemk9qRJXm!S%2tbL<$VOPKdl_Wps&~%zt=l$@WE3%Xll~Uqff+5>K{|e6tIkSyJh= zifycE<-XMoY7WRvlNR|@16B{NovU?W^&q3JLFm^#B(y9~4bp})rVCfQyiZP!%zmRu zdlm08v^^ref(_un>FyYc#!wxU_Dl0bP`IE|6vg)IhcBkMf+*kbmB>ED+TK#=54@S}#E~DI27EN9QL9gi`wE;gkcK&48=x-0R zJnAqH>WAm24_@)Jw{z@sx|?C~&pLIzNfDcP(Xx%oNGG~_f}5HoPrh|zO+#ZK>LPnB zuYIzu6aVug4i7dG3Wz<8YJF6wPp(Sr)?!fMFruwsAA9$9>g+QV(B1D&hnQMP#malb z>tZ%;%%ho9p*=lqb{kU(2D9wTIaH3LOXDsJPGFtG%jS-_#<&dkXOy`uF?6r}o8H>i5?&^wpI3d7w=< zD3PgdA#^bVC$UlwL+~3Iyr!XUFuBKnE*txd5E)y!C>(K-*8*8>HQs~bIV^@cQqA%u z^?|Adm@^hGeW6U6)#onKG=fo!x8_iS3Rb(a1-f5JX?>87FI^v5M#YEODop$@%5xOq%CT zx)H@X(b1Ar-(`c+F>A=t<>&73cQ5VVzNgBy5(j22wpr-WM= z-1X+iu^%oEPsMdZ!Uy&+}1(+HhTIkKosIz0!$lEFxJ=OB9U5#o`AA9fO zsYk@p*74sL<}SZj4qv}dE7w*+oke<>uugL-=SDCu7V|6<-*Vm2h-RVm0hee5pt?s( zdKywjg}_0oY#$TaXFP@=a03ii{Zt*m54X)qwQ+$A+tiU_sS9x%{Zn<2zpV4|D&#9lVz;G`@6qx;-tt9*fyAfEtvhnhEEulcZ1x(qxJ1cK;$sR!|$i9ljwT#eJ{h;tt3?G>2oeh2HONw17n3D3>-pHRhg1YUU^cA1BCO zLo4nCbGscSMi=wCdVCB;1sEWmG%kNBqD26EiT~C*|4jPa**?5dO)0;7yDu}z-9*3f zhCajRZeC$udtGBqU3j67QiR_6I^X-BBI7`xaeUN7n9lyD#%7CP?8Q)oJ)XmN!!k2x zy4izX{I9P9yzDPyZ|U3fRm9z}14)R3 z;M@EDaT$0_$m>}mlzf@|@a`d?B*fQObk6Iw2(I)XuTO3C(n~w$M3%7Gsao{Ii%+_2 z_t!VFR=wL3^tcP!?ML6kMI3rFzwEe4QOq;q(EFEN%Ko7Ti*C3}&&{amT9mwg=dJc< z4ApJ7r_ChnjpueB`l8p+Bz9R3u~7oE)`LQCX($%so&0O$9H!h$yV_gvobuO)nB7?U zhq~Q}yA9^OMLIvtQPq+3BuO<9#KZD~wH9y7USUHdGB;~K^?iZ?M z6!CQ+=$Cd-YKQWuq?)hf3MkG~LWJ6*cQZ&W)psT5-^IF`2<@Jc&N*wDD2vN-&dX*B z7bk|Y`~xo|MdDtpJR{^n5U}TF+FDZh%F2kd!!qRerd6bH&%Kocrz3&|!j#j0wB1}y zpx>xhmV3y4x%-+BA90^>*(8d!SuImPN7O?9f%M0{zc=)O zs!GQ`5wD|$$I1xJ-+w;t?VhIg%&`+h`wD;`&En1z#TVIw8bC^~zODDeXWMQsj?f!O z?rEy{5_?b;NU8X>{|U!8FdQJ!wtV?-10_juYb8|h=%o~w0R z`SJ1z;{pkf4S^Rs*B>cDcGcX^cB||5;(SjbP z;RqWrH~kGCceB1=+~@CZ^4M=(@Z5($Ax&S%D6;*<1nxA_?M3LW()u{!C&&nsUBv$Q zLO&vG$SC)Ix!?6j&xs-Dv)|@TG*zdFKNDr-UTiiEg^tS3CNf+{eE%+bKMEB74d}K|h@hVduMM+DKdV956`yCu*jb-vQtq>T-$vZcC5P8c+-;FR8h`l8Dp7Wo zI@j!DCG|<(UmLBzF78nX|GzUede-Lcez&XVUE?1TELcC@I`}EWOSEPU|3SG!z6I6Q zI`$@nCDSAij5I080WE#&5bJ9kmuhI2L*_oy>E;O4M#e5HM1NJm`~%I(sbF+5;A7R1 zjakVi8UaQYv&g%@JcZ>xERP@+V-W4rethX;;8Cqu3yH{m`irhTE8_l=)l#3o_^Cv# zY$s*zvu`7vw?Q3aue$nWGBVjo0vUGJ_c$AItAXsy(?NCPsDPmK9(Qx-q;0j(;;+DD z?hc6x(m%Up)!WH|qUshAWkF+*7)lGeRk}e(^ZXYFE!$xpcfH_l5ijDD0c8sRFDLc% z>AN*5-kzd1hdCI1(EG3<M{7`kBPGSg7@hRd|w=p>m`&Q8>HTn)lBqyKa`FU&rnVvsB6XQ1Mn5`C zn!N27M*2U2E-WsjjB?LEKJ}}Y;Y;*b?20=!+J%-0Aqu?&GCW)JdkCTrIh25~w#Pat z|MH)Y!F~F{|ZSXx$#f9 zyMol6nO6!*z}#SCCg}F>m(p;7_nDeeMy?Y55yJYXJH}B2?R=ZtMtTHKElZsP8wOcx zQOJfv-8RYunVn1h1LthF*WV`9K-l@4wj*D*#k>{BqVMw~bmB7JA&$rZ=&Xko7vfgF zszbg&Wk~+z9o7p9FlKky>^#CD>|%zBcc91UX0g1<33U!otk@!;o8`2emQ>GO;FoQ3 z?VIc^R+PVdr!3Y#ZV5-iJS#rO}(Uh|_q~9Unsbx%~SZS2{f)B)GmS4baq$(5U zx#zWr3B&s+V*>dRwxvFSkbA^_`V+o~ ztAEr|4sypus1WJ)#O`;Z3>6nb+%Bg?5);DQCZWuJciHG}?lG6McGt~wEmcvn4f@iC zVjDjlnMSb1_8xW-{?N92+Cs7aGu$tJ1gag@-^8nPm^*C$meVa2K_v?tzZUuMEyH;^ zt=N@}Gr`z-AT5GQNgD6Vy$^MZ>Au5l>rfGCGBh|zrpQ}q)I=>i2`a@1iihf{bpiH_ z7;{pgvW(q~dv1l#p-FdNAHtJl3cYnkjTpNDd#Gx@TBA?6-R9*Y3NIL$IoF;{SJ@oD6&QYNM~ipxlY<)5J#~wNc+}cWJq! zFr2z>dh$fINA+y-U&2&Fs^+d1%0hHS*NYMDMc%SqT3v7baE#q-doOC|iF>yMig*rJ z8xB;yNP-Vu7ykSows}9-uln^%y77$WY->%*e1HK-g75`kqt3aY(u_3CriS zC5dZ0wv(yo`X8r&Nz6#R5J2WR?dPe#x!;H}T}mm6 z5{s(w*-Bj6p{U}|o8)^E=Nk@u6TW7G(5kK)xEdr`5KcAs-}f`W>zuCz=@?fW+(OXIbnd^qoam~lyhfdB0C%_M)~k?DoFexXDV3m^VoaU zKqQ)d+Sfm((^8k4lxdib|8SA(Ghn@J#Cp0`qbI*VC%mC(D@vN7Key{&e%Ov(BqkOd zJ+>Ov{jIxQ^<(%aA?^8!>?lelgV;@rFYNAIHzO7Bb5ym zTA*zNuWZeTTq|RsqSVACGPw2pBNXe8i+@02Pc6LTx&Jron1 zPx0`_ZmfWFF5!|O=n(TE6p)W4p=a96BGBvX$rp1g<8_9+F`*-TFBbIMPg1O%({Z27 zibR_?i2#ygzy5LV+bRhXu__q%(C+82D4E~V2U%aESX(Dn;9>oRO~{tj#6Hb%o%&}3 zWMUWJyc`IoZZg#D(~&OA8821f8r0MQmUvTE=mI6^n&{(#8Tgq7Hn#8DRD+~q&@=`C z1p1|LZL*ck_?B6rze4&3r$?tfY9FjCJaf^B9r0rc3zF&g2U0c+dEeX4#LWu-62%o* zAy9VK?xGZ}#Fm)Y9>3 zd-$bRg%IUNuJTHr9Ao>HNohn>2jT5w#NLR~SX;B>r~Je_AxqlLqU|^?1ej z1Ss>Nv7b$5Q*;}}PDuYEo8+>l2;WHvPaz?Xr5wg#W!CjuA*>WG{GgdKN2bLXoNh|< zDw==aFb{V*<=Vgmv<{g^a;}FLK*f+kUJ3neoQVG)&@Pk~(_gnrop^}#oUHV9r?7xiBtfuL_2N%QPS0`q>a)I+nP0xts-4CI4~kU7Pw%5JBlA9A~=d z?oY*E_Ap#XhXvePjxDz=eQh>~%TY@=1AbkF709egmm8y2)xx|~u9HAQtX)HN?cq!9Vt2j;u>3V!i{fsn% zpb2qK_TvCxA>)}X4A{9JThh7XVB=j(4fM!(d$^U1;`?UwL-R&-7>tTI*2gtY{KT2M zHZZ@^iG7q&B zbR+rBl0$K9r>Dt?GZseV+5VqoBcg2PrU(PgjpmTozW(vMC5x!&zPMy?x^ZO!@nwhcztx2@jz=cQ{i&2*gY z#WMHK_m)NKWz8Qg8`Z&mFc7ljysZ809DiS;HcXWDOTv6A8Tj7Tk*TukVH(Q3d(;p3@!ZZm(f&Jvt+m~Ie8gF5R8 zoZPnyLNT|`$;lAZxdYtg+q|Zp-%G&)_%N%B^u=D7(BGlMGMNz?^jN)^Rn*C%IHtl^ zHef#Rv9kvG(4YkSL|Du#%NUdJCq`7~9x%7L-0b3=XNmgmXjp!bG>b*H3oK-@g`~7n z`szn6GW%<`;Z|$GRcb=)-nC5^{d7Q|Qe-PKgAr!V^CSS+lGFu@MQTT|Xgp7>>)+It zRBH*}wp>&p{T~ySE&hbqimmF85;u|^Dju)eA$dm0rxW~dB-Xfa_s5=3M4HO7itQBh zVWa!aIHhkD+wT83fBRq5Ab!76x$pyKgsl#t<(DED7xb-O-~CURm5;djuTh$|V2#q2 z#CyY*dor8s37MhtolPcY^4Bb8t~Eex&}D6hI~;U2JE(-kRaQOJ2Bo4KF_JlA;s9U~ zGmRh3)V{MBD;RF&_riZIq3a5JavaGC*}wwj3@kXR9frW7VnWr}I7Y7ET-TA9;B36p zxa@)K&c%wcwKXe@vt8rw+PL+X^>5M$0y2Kn z_leOQjjsKCzh3!hggMn|^&k0)X%1j66o2SIqv>4vAN^(r7RPEhsk_Y2-+5ZJ`51g} zK|Op#;alex8ES3z;F_gwxN|*XGd?0y7(a zfAzR$zV_0Iga`iQ^Ch;>>Z3uEvsZ>!B3No%kJMG%czJk z{p<15>+n=#l}1f!npgq0(;yL9eC>R!wyY|_&Pt@henGYuYAafmzmAD?$f(~=!0OR#-XfAGonB{Ag{y-zscW_@B=|sjh1Q zv{v11`Te@n=^IbrXJe01)&Jw7Xf^?zL`&GmG1lF^Os)2vQ{bAI6tf_rtay7kTJ|(1 zfs>3P63-7SWou$kQ+4V6Zj`<*K`#_PMEq|iln&9$_!KeT0Os;ESby#KY3A2qN!hzN zdwq}p#z$k7Ut_qoM>)HZvJbG|a$Z2ybP8++KiiRdt;qEC`i&Bt|M6KG&;POQ$6xEH zc>J}EQSv4$n4wyUUxSW8EX^Nf%iY4(R54fnwd@I>o?jbbFtZOgG95V{W9Mb^tB`x4kG&12>DoVtK3G>YTj1aEGc9w{Tm4Xs=;3FPsnXu!B=szJfttpg zz`BQ#eFHK!ynb*uv-y|KeCVXHB3x=n+p2@jWKyugw*N40HnPQJZb)m!?l=sNaR}E^ zmu|I?$OJzfbvzXlor^q~#)aa+SNLe)k+JAJzn?+i>&Tt-2I`=H{b0pB$diPc*>i<5 zVVI+vXPjcmL_0rI6dfI{YtHfd1#W(5piV_Y*88J%eYg3PHmq&n;TkzQ8VT=Dy|j;h&dGw*+*AJ*vqpZk8CV zVk(Wep=6#(+H@|cX)}$mA(cOcAuOm# z+{9{GKbLa%G~}AMO^J4)a5NQu+@dxaMC!AsIf|w^8Qc+2X}L~lSuCeYU^*k5#5-@C z4AqSU9mg?mtgJ84a$pp1&F}SxqtTF~k_PIXc22X3cJ3=rRReG?@W3@O*s1~*Xl}Y+ zn3;9ecpJ*7Fa@)0){=RK)@EVEq?0!{>VA8WNk&@Bh17NBE=rMOa^`3n_Zw=pkqn-e zn??U7{puY2rfZEPha(sYYynIo}|AyAj)>XDs=aB;7iCS7yRYz zvj^aY?BB<@9bfRSZ19Kqrw`{6N8s**8Asc4#_;X7*Ktj&$-@VSoC$4jZfHYk7DleC zi5GA0iPY&28|{nK%46l{?rT@1vDv@T70%Q<(Dca0a5Q`7!};&9sy&dGVUlh} z6qM?n5pIfSkE87l-R!OQVYRr)Ik!`8C5YEl_w|O_Qp!^x--XorQ<#}%)0m^}`Hh88 zp+wqAT^F$-V`yWB0t2XXc}+0E^aA$b~B@-sJ<7 zAm5Ei#%5Z9A<;i^5l#Yb2Hg9EjCL`T9l&!X^<(Lti0ACH#>+9NWfagH4|D~Zcf_gA zhAI589OFLBClCtRnN?nYYw%rx80=amJD}%EfDo4#9kf-f0h`Pf0=#q>#N&3v$0KZj z4P<0`sJSt`m`Tp#Ybf>#%f~Z#6#GRN6L8mgVZE4n)MY1~%x0sKVomrxO`u|>ChgTx zneus<5^p=C5hk;eF&owAa9u5?w&rrye_w6P=W$H1-Q@+}U}94*F{W)Y)oIAta6iyK z4i1pY-fN(Q5>D?97LR>`aH#kEZo*z2ZeDD772b-LEmLgJLRXc}-0N@~HPC6Yz4BLK zO%(>CgnOzhzKzZO0=1y)+c@=1&0Bv6u`s+zP&B*m+tMvS`UlSPqx%aS_}`ip(|`(P zRDu8i!m0nAW`+9y44}Zu*i_%p{l6+!c&SKRVU0fJ9{bpd$16~;H=y|HA%VA~ogMzv zT8`33aMn=wivzUR9iu2CKn!LRv@hLES(vDxq@&`ab3k+}nZqL@px@<#gVV~jrarC} zfNJFNh{gLuL4z~QJ;!ANT^=bibZ(7-M#J&KlM*5b4R zzLL4wJh~n)q8bCz_ho>4SqnTkLUZWq&UqX5&n@}PFnL?{F9596?;m@6_RE}#0h zJZsP6eM(Wzr&B$x%R;7Eh!$?M!X8h?b$D7*c0l}6b*hRnXKK^qeM|v1<9E2XE$1m* z4Ap*b*%|Hh&0zq1h!-;JRx>i={Ufs(0W3v|_Iu>iG4Ge9dV$>b?NBi;7A!@KgiMU~ z7qq|7%97@}H~=CL1kaceMui5Nkn&}X0{4X+qs0!y$gx0>F6gfoIE|W(v|Uvpf-B1M zGcGOdH2?^6XWIwyO8*PiM$;)&~~1>t~aGN8Z%f-aj!^9Rcyx>3-lvgXK?3Wl7c z{}Joa95o2AJDEq@^UX^OCfn~3NIt9 z$+yQVA9XfG8osPWdQ2EY*cPK(BBog|#xN}j9US_?k1q*p!+DRO)~4A(jXRvx;K#~Q z)DZJ>8dgMs#3L(huQ_rB{k?*cxd<~1bK~(B?{l1O`ZrVVI9IIBxQi5+=zvw})Wg+? zi6B}(SOIxoake245$qR5hCIY!5j)74n7SYO)5?l|YP(1>p}`FH)O7z+J7hv`8JTKe zDBt$99)Y{LzHGSpw+Xj^GdvQmkOiH}iz=}G25~~UGAf$X(cH?dCa%6-XoHZpW1v`& z@FK45&Kj;h{RkEPWD_ubKkMI`gnKM(GAkYNPKA(I%{vaBishm?KB+vt~in)l_(P3FTUx~=W*$tHln(h^>|EpU%~H#v~!y_2==R=nd`UR=y|%(vlW*pJ^Cm6Kxak0ZV- zRhQr6n(0zCH;c3Tsej~tmXq(An|Y=7w*2_(c-M*d^7DICS8BQ>qxW0y>wTxv^hVkW z&YISD;l1tYK@t9Rb$7khUt3Lg6SMuLkWOS25BKeJ?Kb9moz8mZW{u8vP4=FwWgz?0 z@_Z@fQ0N5{~9ZnDZPHRcTB$c^&Q4G951w1EUqGyT)?%q=(@WMyX^F2EL7nix&J3}#nAGv zFo6L86hr=Zk?Vg5tz-TFqIJAH<*?Sf6J=G!m?%NJd}6|=);7uSwWd^=ELhNd-o;#*6Z}MplIl~ z3v64zpN=++0lvA$-hPF+WsrdPtowk_p#AAtWAyJZ;P>?nviN6(#!yH{$Lrj;q5xNh z5(p&IFiQtk>@C+=ZT{+?#PLYQF77A%ORzh4Ghbu4f#4d=-f#HVVE5+c-e%B6c!lX2 zOf~we$bYE3fAR0aZrV+{&83S~i%kc;2Co*LEs9MK0DKl`r2#_i!n19m@1F>Yi8e@8 zwB;vmeh98${8t& z$dh;SkneS4#Y?5fW5sl;uh}+eMRjVN**2Jnve_bb;m&!o;k^@jHy>JDO+au04;HY9 z?UjB|G&x^RA#=BHzG$qIw6JtmH6%*pKlfM7KURzlCQ7HBk@EoWvX}kn77yzW?lV01 zs&BRL-uqm0J+u3l#!sJI$N6ylzW;nb!Oz-U-`SYnPqXZM?Ncl_*O9N!Sz_*=Zq_p@ z$<+G-J_HyCL<+Pxc2?`)TS2`5_>#&eQ9e46zw{e?7^nm0WOVO=fbkEzFc4mPghR!@ zvMVPd8#9qUwAjh7ddvY48E`@+1_UU))6o9q{KS4bHXucPu&;vu3iwdsULh>Tt*DWL zVD}5-nWrOt;xl0(04XT*28P=2gqV|B?h14>;O@vpsTry65Fwijg!TsJGqW~woy4gJ zzzeBQ(ShPAXdxVYNS}I`fJAZk`q)PT?6ZbPAkj{xsQcp+NmrW8FxjYXslC|fGDc{s zlAEbBMkr<`kg}|iOv|x(>t^G5H9J0`$RYx>hCqwU>{w7T4~QOqH#h00K?BAc0wEU= zg9IQU!+;9KhlgWNN{N7yPK6T=7Fc;P4@?zA8K6(B;X#$l%L^FQbg{c+@7qXf1sMY& zrtA+k63|Ww6PrZzjti&JlSzxJvsi9mX2JEnvlCdOu~U!=1-QY{;Qtl)-lY(3ihB%O zWx!+g#Z3nEt@|sO7HbE?SH4n+J{7h&uNG!Z%5IWih{3y1Z0d6wIGSZ2Hdbm;)bPdZr%gIhGDU7#K zD<2d87E^)%7yRTVa|&IrS#M_^4t}NZAsm`sMfdTerD=e5K|Q#z)Jp}5IRQD|@$bfQ z2P*IqxZQp-kAVb#g&-0#L@J6#2^QM3aqLeUs+Y22&G=hFtsFu`NG2A=Jk5}QhJt7G z3gH-;8n8$%c3>kpMH5}nZzgo4F0-emhJ>xP?f}9Dz;8CbAm{fbnMukKlU>V-4;*#o zH?EAdhJpm41Hg~qX$7ShN z3)o6YOSaJQ)aoB*++plMp69+v!xCUZA_pxvUET0-Bql}=9G`r-M>I0}1t=dE1j6` zSV2fVT5k~Gqzt{ckvMM}yoPG(dNa)5$v;yA29QnS0PDw@1F*Vij6T+z#^UtL`Lkqx zBO93TboqS?l|K}@f&|XEqx+bn+Je;v_3U?-@n^7;o{J12p!R!Yk8IpYs&l6 z?1@a=h6b+O=Dy$vCDPKIgQ|__59L$Dx{fyquoP!#?sd~HufW|#Z+4UIZD(I_cNlFH zX(Z9Xg7V`&UocyXFh?6QwWFx|ZnR=49SJFa&-9Z625_1I}r=B1<2n1z&! z3$IO&Huc57(tNq&hO=vAyk^H*O~`R!y$drgJ4f2|!Q~QBi9bJRaa3d#`CuB`4PBLf zSQKA^lK6%RK|~C0sufR+lQ>%c+8|qy%ealL_zxTAP5H>*I&|lc#{(AQAmBqp$3bX6 zzv=yvLt;1+so?wv2`PP$v{v9czhQ=ywttKOK)9nL0Fki-JAuPLB9gC}I**!sr$i`( z*~{d|gYhj1E(GaUu`(xuj<_$*e58>3(9q)S5n^rDu2$<9>oZl)WY^Z^5tL&-#+pu% zQms`Dn%88<&xwrQjKW;4X01}4c=2te90Dvxc6j|UiIc@vDr~h{p{4`SMd3YCml_^{%-OfusWW&Q!J)V=*d)C z6eZFQ78vH&-yh~TbK#T|YC*FtCsj10*Nu@fHUe*iLtQ`dHoBm8V@#(!$5f6Pst|mG ztrMKh4NQQN(Ll)(D#VKr-zSk%8evAe=1ih#)z2v$X*lNbypFIP+=&QrluWQu_f{_H z?k&<}1j*Zc_MaX-Vc#Dvc=ahWYecN^B@L}-<_>+WVMwtbBz+lm`~=`;8*7HQ;1jCo zhXByCK>G4=hkH`}doF=f{IqWZvG^eebmE4iaBzj|#+%X9T0&XT!h@rk!@Iudy4$?` zld$!ZaOF-Rz*5p>dfS<>lOI&bA`tyq#U>DK)UW2&51=^OG-*X!a!^F~SKlZypqvJ( zq{V28bOD@US?C?VBtvW$E;_LqLn2!-+F+u{0%g%uxsb9X#``l(XSQ#0p7yPLH)244YfPjFIO)>SG67@?vr9xGc7jfT=27r05C;KrkR0hrtX z<-FC}J!!E@xM51PpygUn3hj(00apHE!f`YR*+0kIOs zx!1~7|>uG3dVM)KgZlCClQwU$~W zx8Il5W2rd^bJxpd{`{n!($URRC&el4_5P@F-ge{^$fgxiPF%^IZtqdrYclXEkI9Q@s^zwg2{hP~z?J7F(zmSYJ5}y54jN@{pBV)wzr%G@gQ* z6Cen6vSI&)GtM{!AcP1w4};2H3SwJP&j= zuRKrMar}R6>Kt{lX59|f67tidq8aTX0zS4 z;7Mqi{$&bze1NG!k$rEE0Mfv{6@p&oT7;o9wLd$j1sDp|swYosl*+G_=yJqS`U>m`Oe%zI z5W+2Rx-khSS2upg)YUwDF^slNz8H<=vQjrwe{>m3u`lHP0@j!uU%X5&+q@H$@v9KqIImpNf7@0!ZE0kXf*1PyuW?HQ#PEtpj~Tf_M{;dHz0 zCzU&3Xgjgi2 zOL3-x2G#N89AHyivNlThpk-LEF7pa93VlUZFkncH*yTgtdFlziH{1;@C&73t4X&3G z7D%0!&yFK;>ePI0fcaWw&ZY68`UQ&p9S)F*CAXg&1%=Ir`Y*H~o?^Sw5B;k@4c`t? zT$~$G?}fA*H7;N=gFdAA=1IElmCPV9F$4Y6JW%;}U;prx??0fA+trh99L#L-Qjf&*~hb1D73OX3= zk)U428dD5ppQs+8zxr9U677IDgxw&+EWl|;d!q}>lP9}fVkTuNJBY=r~!Vcy1 z>W`uY^5kWIaKYC()f}yBh7XZHiZjfqqUPJbnvUibHPIrMSj$RhKMr8S&~^qMIlZ+# z#B^>C*d+-jJ{1oU@wXB9JGH;oa%)`m$=|kczTU5y zvy)HWy`qa*tCyJc`;B3l`^G3b-xvUS@CpL2lvTJ~_kb=Zz*kq`YP;ZSpTJj4Js!gW zpCozJ^S&55JrK;5j41d(pM*dt(1ILY_)qV${wMNanIvAg7L-C^k>nlESa-;xO%>9=@9K&St43{^a-|6gp$CcXa{6@EN zqyI8fgNLQ_%dCrGW=Z|&DA5Pip6@1vNn_i-{T5v8>DVv_$gkK9xx;#YQnDP#0j8?c#k+dGgwY&gTN;bvo z0=2Kl72Fth5M1fvKCsrjphmDna}RIL4}6C>yz%6ot>Ef(fw6HCIY*8EZ{A+45m}u{ zxZA2$7cs%*g|c&bhphEw+m&n+Tme-X>Sq$}cH>`l%!9+I`?@`^KsH~WV11dk5B#RH zcC*}^k!VT39*ZXc(WYtu2Ec9Q60Dp)L6jX$_xvY-p zXv5Al23mZOQhn(}`Qm^xX_>HaY~*Ys?%VB;Ebwcahb~v!`9iC_H!<$eo#92}Z%sjF z#^X?&1#7JSbSzJ6RN*K@5tQX<#6`80bTLhXpRsDF5SqCvsQd#JP;XRU9ql~5`pk?_ zV)D=W*B#-2cCx4Xp=d8^?;$Zfm{%I=%Wluei!aBF!(({AlD;pjzl7uw@dSu@1}MW$ zn#h2>{Px!39oE%SCGbB9Aq|l`v!Lho z>e8=1_8j_a9>ioeCw6fyk5Hg}-(VM)z9_qs46oI=oX$$4$#nOD2WmE3bWPo`i>(mn zldzS73pbL=O2znIt>ZB*EQ=|vy3fy(G2bA|xxu!&<2rcHhkNi&Mn5$!>3*=D44v`T zqalenA>UHO>-kqEmvSzR&R0nXMx7V#;&JE*?}MEY-*@um|2pw{(>pqJA!NW`_aYk` zv+OuLB9Y-*lw^6!ky>(#F;P?p;x>xSv{t=Sn#TElwXxW)hjn|$L<6!Kil`hK&qubB zS&py|L_O)0VQkmgHu%Oxfe3~fuazc*Xs^w}*|qbrT7V7WPQT{G%x3<4rxO}2lk{E2 zWy??;w$_-BJB@aDe^RhVakVBtl?;|AmhN?nHVWFhzErH75vhOO6e6GqZ&r*)u;Kkx zi9!a~%!~B&qS^aR?i%R%hanHFMk!08i9Qd_qKA{jZFt!D!c(Y)+7*R4V~(&8U>H+H zMF(PZ&?_Zts(%kZkRrPE+sqJN(w40_$lV!ATfnOD1bJl@JElYd=Cj63E1``X&kqco z(3p+-&ojQ7_ICAZYnCz1uqkT(DcKx=AFcm72&NLA*s8_pw%2QGMNs&=4sL!2tKKMa zc;!0z!HNi8;QqXQAN%DZ{Dilt^9A0HaU{b>LkY(#^ns&4rXvK9cIv_Z@SpS=2nWGHy}6|wCt5q;{PNgg zUj82+ewNGJzgZvDB~zy9)fTl{*V?tbSyeqv^WHZ-&fOmiNZAeym46{qZO7j&J1vKs zl|5Bzcs%hWSDuMJ7VX#FKXG%Ma%9>uTeYkkDy_GV)jcI#p2$Ps)|cH=leA^?hsY9V z63Ji9*PkAVfas`popPq+_S9|{_Q1B2FL>Z?dCFDjx;hnEq9p@eLlir@&p^{{c8j(t zWWgI;tSWWjX&SnXl@qRUT&p#Cz8qwKJZAg8(zYBqiZg^CpZ*1PE3yS!v1{g4IH)}5 zY~RC;@8rYYHhzfMs4De(UsNkrlC~Epp9?QMJ@T|(d6+CdIYpRj;(lJ-u`Wi~z}^@y zs#a}!Zga%>ikc=|bVZIY%}ZA>4Zk*YqU7-B-L^hP9Ya2H+v0+Fd_X!GyT5hJ7Dzq& zRym%_KB%MqtIOBeQj6M;Gx=P^9F|s*lg2q$5VE|rC)QAuszkc22u5OGKHwO0 zaPR~2o-42lctu$Ysq}O7-Ja-vKbqC&}{wh45?^3`1L+Hu8 z>7{Ay?V#xrYqBW`S>eOg`Jz@&_vbcV)C7d+W8k|aIM*`uC*;_zXWwWPF8B)c&w2&E zWo1BBHAbU215FyrVnFzn-0T=bA`ODVv{7V4nTY}q2WZLi%Ifs<0Af{=`wT`mYIkHEiiLH%Rnc@arP4Kd@l)34RJCB z`@RiZpnjaux$gMlWe2lt9TE$%@o$n@{hoz4fCi`2>=x4P2u3=}n|>ILU=dS!2E-dy zPPa&Ckka%r=4r@`a-P$%I=?X^9AQ+d_oqnndqz&jS!K+aUs+%RO|)U9H&}E;_OPocsZoQ z>j-p^tj671rwdIFU~H~blywC+klk!Xgwc-qO^VUavr~jr@nykMX9U5}XZF|k2ylZW z%*x|QKoy+&98DY9X1vJ`N>-W`DjkVvx)b{wElISllV~p&OWUOFU))d>x-kbLx8n0PN!`TqCo&t`y%lBSYSKp5 zBal@r7+HDN7z0Ml##VhAiDkFaa^2}j#bu&0dezBToQg{04vA8~F45Ab{b{OY@QF&2 z1tyfoo;o*?X1a3Gwe$G-J88R}8;Xp#z7uZUkycqgv0=43DDgR_nXl8Ac%3KXx2ZJ$ zX6Du|6y@x)+vM^c6zyCyPJ%_UmTMNO!iH``>;0a;BIyb)Vho;}8c*Bu>uh>zcP-og z2vOiDM*t~-S<~;rH_Ly}Asx;e?DkmkVuHUGn)<>Q=MgeV)oln_QHdSq1}gg3`S$Q{ zn_9nG7+?a}!he_0R8=9E*ddTLwYA=Hxgh^%B-ox~)$#I&72ZEwiMvV-2vR73g+`6A zg?&6>OhmZu1XL2llm~l7cYq&+$)BC}^Rmj7)N*xkmE)| z^5Dc3KofIx2XL3(GO6Ehf7LFpCyTqz$P~NIxT+AY3%JMMbdsB1*B!eK)k>mzGW3t9p+5uGvk!*d%n`X-vGA!@} zMZtu9$OJ()pa_oc)KJz?cogeI$I>9xyqMu*dC|L1*(IWagNl!p;ttRFL`yuV|A_fO^r1faZH6r6%I+NY1< zH4skA6yz_TeXKbC-JsNE?r2u&u=+YZg|7VqMIeyMrsZ2vjxQgfTV@I&L&OzT!cX|L zYu|xM+qrOmeHHPvmW$D)lIaTgEJInm#T#IXLN!Wp-T{Z!#UvG@4Q#R z6KyCZC6bDb)kz*poA$25=E%+HDa*pmlmz30C$|f;TB$b$mC^fuY;eV#okkO_+w0kR zUbigFBxyOFqsAvgvQ)R*pW=regN?VqTERrk7r3x%JFMu{rG(4#eN>rKQs+Mdx zI25MSnmn2hx ze{I&iZ*IugwoX^zvo$fdU9csXUuw8Ke2=T9ls3mJM4kO8-Q`qL%Wie(F4Y-r6^m^* zdh|T`Q;qGaj?6C3nuTW745Fm%6au1+0bGzBOSeXmq<$Nh%-J9jue5GOnTrW3G~b@7 z!j;_ERB(FBOzp8dr>a*LEja!Biujlg&&d~h86L_vWji}G3@1Rx7Y1w-<`u zrmgkG(_3kjL~l5s=v}<44q0Ak4(~kXt9a9&*48|jW6FF?hw)dRy~zO7ZrN(O&}nTY zm8$Ob{mIpH3snzt*t=fHFO??Z^}5jY!TI*_xhbe+vd#{oG-bv_0tH&{Cdj>urwGoT zUf81c@?QsKGEgnMm+%iOx;hH1ieX-4#z=gPD|<~Oj0DLjC4%O55aoy7A1gBmCsQz* zw?b}s%=wkvSi(5&TIKccOH#BO288j0@z-D54JhdajrIlK>Sao&|3swMf4#Lj{`1Wh z=lVwD!MPR0!UrU+_Hcv060SXhl%v=QznBIJ^!W9-4zdLw0;H_9x{xpzkF11-94g*MMjI&G(M-1OS8(1|o*U5Ww%uC_t*sfL_yyq?8ad z-zGz{B`!OaXk;MOK&q1XIMOAqJC*u4`Z>-|%@5#@wiUi%M2|M)EK8VF6}e1uY4|j5 zM=b?_gbfJP2osbMD`p5-4-w*?>c7{h4?72srN0QX9*~ofkIs6i0ey3+3ntiiv)Q4B z1?v-1AusrH2N|!Lk4fUx$~nr%)j}t6))Xf}TP7cSgPDrvY@rZk$?2#R2vs{CA=6D* zkuj5{H7BHgfXwO5*&OG`=`Dg}e9knG#^&^XBz|*TDB7l|Seuj1$-sc>e9l5h_b+RR zEPsc*LW?nZPRPbXJ`g+UpaEZ^(F30(++N);Ye2G*UdIQZc?Ga3@eBYz3=t?So`wGm zRqPB&D-MZV44T;q+NPg~eh!!-CcNsS6l``@E#*-CCg>LF(n$xdr-&kWuOqDsmDqQCuAk_mMqv#UGqyYU^w$W$ zl+9!eW)I?HJQ)z%oNpeZulHJ{Cm(t{CImgPC?24=5o z zi#!~2v>0om+;Rx$V~(m93gDHLdlRx*U&Rs{_(P?vQ%Y3d%<8ui?fp4# z^m$-Fb*W*^mJS@#d7aP0Pr>orS;sC{e9$Cn}1QtMaj-2Pcp)wF=HE0vrig~C<| z1^|HJd}c2HV@YyZPaAxYe4PpMrXSzVXx`I;?ha{>Vv4x?5(?Zw!8K^BtTgn@kBw<&nI)z z(Tdg0BW?bAQWD?;%-a1Vg3Me~s}Q=R(J(d~%CS@|s$&~t5q}m5pd2R?tv@#xq~F55 zyUAZ789>hzMYj|cfFxv%KHPJ$@aJxbbw}@QuMfpT;9nWtjNTplAmAmf+fyIWrDUIF zOGfc$GY0~|M7f2$J`2Xoqgg?fWYov8+|ywYzHC1$3xSk1hk;;9DhvAZn6-zg9@Mw_ z_}!vZ`1E8xE|e$A!ZXS}=wt6_*`g_|Fl1YAeT6 zH=k2CUhbY7yk0yQT?t(&)6yE8P7i84Y&BD`C{39pM8D0BV_i0C%mSy`=7eYYgIzT3 z)HcAh(!P}3Wx8vo8{(7RMzAV3@(TsHfv5>va3B0H{_gsh#4olNUtfydHa0wLP1BJUo2(Yr@0R>D|F`N+ zfZZ!P(SSt}CcT|*R7wQA_9~Z}uG^IwFbgL(1&afXBn2?)sXs-#;Su8!M`yTj6av_( zF-r3^A-DqFqA*>r0jY3W+;umb_O;bamD-ve9Yzq5n~qr4qAH}Sx)dOTsf_4Mmr|Q5 z*z1IQLE_jCLn}|Feca~|&VOj%YNXZLIv%NnAlU`W44ie5ueDD0X0`vs zx(hYV6(p+0HOG*+#ak%NYPWm3_DDtG4yo#9;YvZJE@tLBIhB9iN~9~H#WLfY7c zUzegXi0fu~E}WvOo};X|DDDMt4>PGs|3t26ur~2f)<@O=j+!RrNe_RFj+RGE{!zh# z%|{23#p2mfd=NE}*%JkpQ?=k?^R&J5K^Jw&`>0@47SWlP^q4_paEHT zhmTc7fxRH;|M0DnDjg&X#v6)AI>E z-(OIBFgd0Th>^zKBNLe=-qRabMadgxgp@si?ramgF$YMIY&C2@|CTI4C!1| zGa9NbnCE?ej&sSWtY*M{#v)LFTGC_$04nV`mFePja%8!cHosz5OvJVE+ddh!F_ISH z!4Y*>qOBW%8X;p4e-i+}%Gfd{)X+G|0ZLdRNR2jtJfrt&NmZ>LSLX5wK2~bHN0oq7 zNSGn*SOp~^m}RHH8U_amfy`t^41r4Use;%W_51|}%P<*IBsJq-)UZkl)R`hAqLaxy zy)J@rIzlc~QuHQav>ee?y%3zb9hN>?@_QhqCgGJk(7KAOAj}?aZSZw}CM41q|Ak1@ zg**r}ZJ0skWk|J|mik-bZ8dw8=N)FJpelhopSr@+3@_zxV>@C^*YvinCqQR1_J*0L z&l?##5Zx-tZ<&gNJgpUhWu#5KBu+Af8Hr){JcP)iJ)|;_bSD}_af@(bzmvv|?Bk;0 z+9VGo&#jy#(F&sa*c);06s-&zcS&qz`d3ntISh22Qm#WJEt}|Y<&{-fGf~4eic8=C?Zk{sw(nneqsLs1XA5hE!wc~AaSN= z%}!~DbK3YwnFk9k6zAC_=1hcT4k=!Fh1ymQ{qc|0xU7?wfW;nFH|eCcRCiRUj!`e+ zq<)k#HocQs>AyB2@rhaIo{Ly5ockgN0Rx4KSt7z?D=_dW>|W|z1^bjcGis6*NV{n4 zfgztvkxhT&C2zZ4WaeQ7rPp_+SGwPRkG&m1QNTWU3?U5)sF;!Eb?cwLgO(lVFAXF&k^Olg^tNFfiZ%F5*xN>QD(8Ae*edisEr z4&)ZtqduK1hgT>!zOkdNMm9e_^p5U-69mm_HDtSUu7_LOdpFJ|FF&c)6b~U@anx6~ z>jK%`5|{W3*)yGW8$SgeWV>n~BD6WSVLKb%u2@806coG?MXnpvmqmm#5lFduiV38p z2aa;|Q4@^9@xObeEGRSil~l?RC_aOGskdP^bKl7>jpTtgWi+KVHnl2@6wqErlUYYx zLON+obG<2{>Wu&ByCK*nkV%QyzM5mFUX0e`nqJm)o$D6bN1xQM>h5?R_igw`<7aMm zZ&x?{{S%w(H|l$^3)d@SQ^~kZ=jYU$kgmg+wmPuUrIwS&X=RF~qn0fgk#D>tC#G;AAbFr^ z|G!xKrr^w?Zrd+5J7&kW-LY-kHafO#+v@NOI!-#aZQIVtty|~i-m3rM)Op!^SFQcD zX02JX##mzvcA<(yUp8+e!`QsgOszq2+h_S1F5UW0v8*n9&#hS3ExB_Yyx}mY#SgH! z4FiuQy3?YfuQ}1nTMREK^*Hn2emh%=B5^dm#6R6V30eFvz5*Q1a`Z2~57d^XIzFA= zCnwd}U*qi0ISs*^Mx!IQ`0f)rI=g=l`xop5N3y?QKJ0ar=P~8pFnvu4%|EAaX-?^T zfSQim74fFd{HiJV;>qZ?-nSaAhn!VC`aw4PWP{-*ZBzr-HS&+` zasK&+N^Jp6Ex?MpV8_^VrW*W?llmR4dags1evZfMkb@dkU?a!tN(sVHr`7{bFEy zC{43<^I0!`Yg3+yZ}yAn(|%3u`Xy5L^#{ZHN$xll#Ztz|*2YQhfXdr3=r7avjR@88Ik_T;zQh=GMNjdgD=HJ-&+_6iVOzPOf@IC`=)Z>1 zzon`FnB}jzgpWrK53m%@mHaTL*ny9e5KCHNDMLcKV#rwqHVq4jCZI1UoRkq&MUI3F z5YtRbH3aG_7ebfUQ^@6-p#$T$_Y^4S?)b=QrKmnI)@C*i^Se;lww)`Yjd6nY(1n=% z{i3-2MiO&Ar%U4|-j-drwqr&n3U1z~pUdjDu(|b)@wGBK&#u~+=JMvczTVBIa=oW= zwe>sc?C!l$*y`ooM3#eZ4r=-)n;$%A-B*(k*H42~qu>sF0iwZ2F*K=(1I|>#xv#s= zjmB?`ED}UXV@@`LYRVpxISDDGXv@8`ZQ?Z~gog6NS}(5h^$p-O^rWkq4bd-8c;3p$ z2@qYPw%Ed$4Q-%rrZ-3W1)DiyXk&0fF=-(*=1Y^l@$1l!c97z?y$LbfwXSBEVpT*Q zlz0j(*EO?U}yPO+ij*^-ZWC|Nojz>z~eKrM5rnsacQ=}$( za}}1Fa+G?k2P}{?GE@D)Qr@tidm49t(tpIhQ;I7%qM_GmsFeLQtj-o2R98d+Q!D%j z&q#+WteT?eI5~TahJY?nPi3$D4!4I!a#^|~$IOV`0^6kE8Uk*BjV8REkpR_8?zQ#N zK194Baz)cFsBQjzvk=~5L$O+rjltrC@>O91iTGm>P`MDec&RhB5G!usa-)g#5f^^G zL;UND>jLGIVNv{85IlN12pXdRDoVIVSDO^ZOTYGt=;yIdoDN3*aq01+%`-~=@nd0L zez%m#Zvv3}uVG!`Cp6rN*qjvt)`mHP6-}4D%(Tnlhr{`^nXn#d_w)(9_M&AQxAVW= zI5FqV;*XgmFzpXe7p;HPVgy#7iy{h7}nn1BbvY z{)wIrpuICjbb_;_5CnA;QLb_q(ZmUXh)P8XV#h~33ApiWMw0m z*0PgQFy!w~D`#3>q?Ex(iR1*G9wYmDqB(G7QsR^#S+(aeR&3`5aFqpAar`)I8zEje zO@bFrILEnA-hg5d5QLwz2as^E~aottn!YIJZyhTE#vQ2q38)d9T2-NL@eTjD_B<$+b*Bk5v7 z(_CIp1voEb5asP*S(NfS zw4!o{SoCYEzQ4=`+XtzuG##i-+Elnxpod|seOvWv}B(CSVjnxrD>MG?t%BAM~X&oV8LgI zefrn$2t(;#`u z$HI||^jO2$_USy%={o#rEvi-JOut3yu@{w2 z7JrveQ-j?HV>NWl!@TcZw1)*%j=w~4q@6vKy!#5SK}xmVx%$#lQ-AwMD-6LEPoEsp z_MIV7QT_Eo39_(QNR)<&{ag&su-j_2mDny6bnM?=Lm*Jz2xY{3+&B47ti>qePUc$a zp!_yFO{w+%IyeE{#-uSB)zm>NkzC!BCpR1t-`SW^xgUlZ$`-76v1^nw1_qaUxsods zmh^;1gCIs-t@p-ZN-B*}MLaqM6&!G?zXGXe-SPzW*&#^cd^l}(?7;8xtXE7Wty}e1 zs{;kQTq@7=9O`pB((Pm-%HH>Ed*iWyr>j6n`d@Qw6+Th`&9qwveQ*{>|KAsfD+DWN z2R~njFENj=3l_hR<~-jEd-AWjw9k(;cEm2V@Fp9v*SmzzY&Q<(`zi_RnLXGhbZmtm zKr|rMvdQY5%}um%@^QDei% z-A51vha=bG=^3c{vu;$$v}s?sY+@G6F9kbX0l#+|v1vnL#SN2z-uJA=wX}JB0$EW_ z;e(iZljR`u=RdAVhadCHX>cb%*q}&S>Ug1I?|)s^Tf&2`D&Dy0Tdh~yM>@wJ6( z@*D@pI`2cd>+25&D96*A1it)R}AfECkf{P#N}n;b~60m z>w+8;dbwj=Irey-;Onf~@QN;L2OQ4LFQqg8{0n1x5cRA=7R+xR#jjK~eWuCc;{(m~ zK#C`DOqVQ4_Cmpu4hlu?63j{@X*>1c~vIG{ccMPBqKK=ha z9v=IieaA<|U1F-*2?mJC33u{J2UXu9sryTacJ_CTML2@7R?L217*+-yIfH4y2bOekBYe{~bl`aXL?`WnRy zJ^s*sq+ualYaz(9l@Xgs@tpw9UgS4BhiKJMoqOAbw2w8RL5iuDFZ?n*f*Zn=>nOeE zkO_(9hrh%h+7fu+kIJ_Vd93}$qO}c*uvYmRggyc-SB7vNw8LKCC?o=>k^;`p8@3LU zV2Tr7cpV>~VHN%&)p#vxtDW?Kc`TSQd_C3{*&3zI_TPi9A#-ba^0 z-~TUbjf1u}W?l5ZJQ{Y~=8q8GVgz&#y#)_+m9fZ!gPJp?yJMH7Wq(F9GpD{QC@I74 zM|+cVG#HT4Nl_o8kACNqB#0-qd8($))*xarugRgbL>&-JT6!2?#Aqk1y>DzwpN&g< z2vZa`t0qn&>yS}}K`d3e!lg);|MC`fT(f?oTBiQT-x4X<6uzbri#}rJb?r~Y}Xn-efYvM zuJU5gcN}mr@o2WNF7h~0 zMS>*g|Co6>1-PJdL%rurKoEdD-ddjjhox!jl|zRnHqNR|Qn$qNugV$55l39q1-5`N zFZXg015?Cu@fW5Tp79=r@d}j8UqSO-=EXC%y(D7pk_eau2chj`W)pT?t$%Nif(1!4 z)-(cds#@ni%6U_^SfHZIhoeTP#YFVU zRdu}fRuy<+G6)6*6F~Esk+RbL!V!aJ^*1wLo_j#og+M!n%2JgGq|<{kZDFn)MP9nhSBO=T3Cf5ri-={C@y#W(Vwa27ImK6H22fmMc_g!9t`(PnG^Yga;(U9# z=bRpnfC{F>VwoC0CYS-E~i0&k)S$fAe??6wHE*# zQxJLwKy4*p$rn)D4p?#o)RqF=vG#0!@e{u_4hR0Wa(37AYy9?i(uw zd3XLo(yX|lXYmD%BVt33p2@~7Dlv$rXAYF6AKhdi%xW^df0@?xdM}>O?5Mk-=i8*y zO$K#po~K_z#x*R7?HGTiI$;!Sb8d0ir|0w4I!&%BDJni1C#AvfkdDiv1FEr%Nd3E- z-K&$JFyVBDJAX@RC#Pb*O1gEdz}+J0m6YRlO~V#A0w~qFXz`QhBvh3&-g=&(zX0zm zbx3lOtc&k%nJUC<6X;FU$=XcPbm#vmoVkY4c;9=kb2n?NRW{)6BcTy12q8IE9PtG!_(6f8BbSy_U$+ zbo4o&&6r-;UISAP3M$y%-mYgO)$>;AETV>MIDwXrl7P2nX4WLNcBaG#h2W6@15o0T zFFO1LLCin!GPil-(1Fr))eTOR4QuVeFK-e2shHtL0*;zvx%BHNQ-&KCIBJ$9rr^&N z7F#?epbT!mM09IW5EKwebuDuFq~ zM?JzbeTM`$d%vxoZ3Bm1Vc!P?@Hg>SaVRm&PPMBZiK~aIG|0ED$#rga#^t5%o}|YG zgR9|d1xPMtMi)(JJv`s4FMiWoXC{ar#xLSHrf;pCCiOmt>IITU`M57R6=* zD+KlyOEVVW+EqUu#BY!@aByB9z1M)LSsY=d8t3yzVQ8K{jBEL-3nQ!xXaBjl6k}ME z<>R^PL;~&zIf_2DBB5Ds(qLR5fbSk27Fz$S2|9~6sPg);os0`FZgNN!!oGf_yb(o| zrQ({EnTo6wf>IhTTQi+D16~bBwIrM#x;z&?Xy4*JHG4&69uZ*C|AtNa_5$oQta`U- zct378E_zQX;o#r#p{m>3eqTdJ&_=HriCko}D%!nP`ZC^hme)OzL+kbd4tB`y)pX@^kph+DEX#04+% zhrDAn&<5_JfeT_KuoVxtnh0j4hMc9oKubi+jtF@>DZ$VfiS&e$$`pF2AVa7|$cmZ} z9W`-}Pzr;L7Vk<3k!iR@7mg^h{n8F}JE||>Oq8L(<`s#aLlIXBe^;}Ve$?DChhI4r zp#T7MHJ*jMP>IQCk7Ol8M5ky5~ zBMR&Q05!&kaS**Ah}zkdEJ(#-%#6Dqm`q1j*8xQ-uOK!hdes(t-KAvG$aNUKo>@bk z`CFxHsoT6{Gwldtq&@H%*Q?89N!{$2aK>fj1IABOVh# z9DiS|Q*+P%D4x5R-}M*40sJ{`y>5Z@^{Vc~n(js)=VBY4LG)WKJP2{|O>k89Cwmy) zZ3pkO*DZh7>z7J8P1iaFm~5``AvgZ$%R4z`eF!-zTS{vqXO|(y6Vfqh_`3fz`Z--N zu*oayo#QhcTttqC(_zA#wo6%=+0x7D1yMD})w#`QaO>@V;~VBkdUrXyKT&&o-e@sU`p+MQvcp;MYy&`>#; zrbD6H6%i5J+s6i!KP+0kG|+XCk1W|-yH*9%4Aq(#FNqnuCtk51Uv8%4CHk;NzYvPO2vCf7xX06m1fgq+k_t<+#6qdi&%MYsD6P*6R)Dc?Xj>+z62fAbX_ z-toM>+2Hya7)kF~Z$Umfp?&9YQyDs`Tm%z}q3=CG?yPxr6R)EAbq(akt9J7&P4A!W zlpu94<@tdukCG&SzhA7Oq0W1#*?1QLUc0x?HQC)@f|*vd?1X4MDBwA1>JNh{jXujW zMv&c$?JB0%`NMXP^rFRg8QJNmDI;xfotHI6Mz3(ZlLR?F*lXeuV!;^@?+NPTh*2q$ z8T;-Jrx+~`4Qk&0GH|Z(Aft=CPo;D5xxfs90N^eIW_EhFHT?1%EIsy5rPUM@v_&Np z_fWhMkz|Jy(RKh&m@hw{u-jkayBpl@d#`XV)Zt%8qaGESq20iqbN8ShP(4yr(>ePz_}V*3w^9X@qCJ~dUbzw0BP?%q&ZWiyKQSvxBpfE z^1Ab^0l~ZWDZ7Y0N(h2NY0X`_WjEE-){uCUv1b=hWdCv8(M~FM#NAABst-jJ;ezXT zh{|_2mL$%+;>C;z8w_8a%Lw|yLJBdSXZS*TK0x(2#@4RV=*qF!x@V{0GyeL8=(=@{ z*6%-2Jh045J=h7Z#nKb?#%H}%srRYy%?v+VM?dZSqYe1iY2MG$;_2iv$I{Xphkd{N z$!YuMDvwDJjD#pU^gF(d< zgB{2J`96+k)q_Y4Ib$@Z;DARAHRuP?8EjzH) zOk&secc2|uth>FS9!RQx&gX!zr zIJw_(LYdLZ8?edyV6t_JLDyG@ig#B_Stmi!`#G*%&93eiwL2N}JZ_MG40)fSUAHM=ZhoWM?Yc`1aM?0Zy{aWvadr!C6xJOaR`T`> zdJ>Cz&*`roE=6uV+m*T8g62<1_Uqj@h8CF9v8ly0^}NZz%-cmA1YM-Rx)qU!6NQJ# ztwYFiHXiaC0`7QCMPwIl%ygE1>`@O?803|{n=dO*W>z&nPVmcfgCJVGuTNAOCYGP{ zC)QkAa(5n!ZrO92a}|;EF*ZqYo>QZfM?3`;A(*P#cR(iw(~7?L3Z;G#<|dt1CcKjN z`<-vm_sfA&!YRR|ngB|YZPGHSU{1|-$i&h0Jz3Q~hY^4AYC1UET8w$3_D5TlE`^i& zRIrNaX$B1sS@T_06bJ@xFgFKEY&rDs9_rr1` zlIf*AQwqlFC|ru$5#L#5SV-Jnk;z)|NM0zNGOkl^6ue8xiV{~C2LRAR`@bIOaJSoH zI>`KMcvJkh0wtb^U&p`_=eZU6zHyf2tvssU?Bv%nb?eH=jIQ@|}i)+5wM`Rey2ZZ}zqUY}!%q|Ie z%A4zhb>-&AOc1IJO`PM7uBQlH&W2EkWggVS_%j4WjMhPtUH>w@x4nBo8^Nkag z>3uyoPuF59(!ofz=!`?W(4N3|5Nabk|Ak=SVNA;>x7`m3(=Ka(EfrQtIU+)3>%Ss& z?Dl)(o~P3at7j118h}FC@q+)sCKv@r`F0x2Svtars@2`TjAJlEXmsD|kO1dj4vG1- zsx(cw`^ZiIZCoorT+z>Gb@UT9k}T$v50H;?H4@!SL9o?YcqO(KW$&q#n47wAt+f<- zLv2jT5Th0;!ev;+%#sbLsc_EEw= zdzG$sRZk{O&zrqD+!S?o-XKU0;6xg&=8y@7W`HiNY0Sl7ST@g;>F>s@MrhYgL4>K_ ziFjPaE>6`V226D36qDZD1K!nQ(Kb?+b9*1X1ItbHUnZlqfJJt z-Ju{d_Wtfpb|xwH8^M1-0eWC)uk?to#L-o^a<$u=F05A|Xy-c5J3_Gr zPzTw|w2iiKO|@oUajVn6CtFK(XqLWMqBx+})L-SW9K%Y-d)o;M8|}nJU}{f4Jvm-w zgB`%t9uD}gTngyP=)XtXJW3CR=2_c}Lb^n4n5P7`faI(?ha{wns*SBw519S_ZvArr z+Euto)W?c<9#gq8eV5GXHd-Nb#LFqh2l||pb2vKy#>#JV%lt;v)}9|`dsvyHn;~6c zQTE%r^z_$5zOOXveVg}lUttT$Bnbo`G&AL8qu&bvs= z#R8;8`ZuAmOE9IvuVy}?vAzsS4q{gfNj0a z0tGgM=U-+Yl8bp}fIZLAz}?Czu=O2(WQ`;Cvnl!qAEm8SOIr?B9G3%Q_YtY3-+LYY zMp|h*MX!gdj;{AXA*Sw;Prhdh?)ti#>)YCkqrMtG-CiF5gp}P*`b_bTolIl0e$0763Dv94M)*sGKVpu${dW5oa zz(gVq~WKPkO+pVET?m|=rDAb7MXr3<_UT!S1p5(`^L^&- zqK3*yWv5?k*t4eXbbT@w5;oL263|Yu*M9F_4BAvVUWTLrFA_?O-|B+EVtBl_H@Hi; z%c}|TmiIdstDz52(j4(|bEEW)Ch=Wm<@5yZQWIN7el{|aBxO_E>BOb-P!p!tcB~{~ zW@g>WYF%Q~c@q=vTiG&7No)mwB5~w<4&XBkObCj###>W}LPoW~FtT1}O@?JKGgebd zLH_9j?asq<%et$iyROih0|$ey)Xbzk;#cpr)EBw#!}8wREh`zHEN*UU$rx4UR^f-_ z>eohO&FG_v>D%f{%xGiQJq^`ro9J6&lfCI_nM+QIdMxdP0t^-N#m$JM>Y~aVc5ZIe z27Ch2;VAj8qKpQUJ-U5_6!;xeS3j|1h`&oy`36_hv7$keKxAPSpgm z8Zcj2pz)GGr*g4YX$Qog0$lgWfcoQUu8jg77ps8%I*gol<>npRg`A9J8|)ZA!}li` z{vh3b*H2L21ylose5sm zSZy9xp4W!Uc#YfWR@g4_eAos(yBy)VGdY;!OX_^*)}OE#3XEZw@jwU)K;mBic+y)> zj2r-ik9(Sr`|E5B|H!h=(X#kegwS&}42MA?zD?&`ck72g%4UzeC2FMK zLzO;+#l0STPvLLiv$Tz;Uh*ia<2?+$jLtheW}L%~v(CG_&O06bCtSpm2$^hHNrsaQ zv+fQTop|zuQgW*qlIy@o~NQId)fWM}VxB5>2=~S08 zA`rIdb=k|W;nk*cxf{+R%#SOb+FA>twzrw%@^^H@+}KB6@~Z&VZHW~1W=F$bKK^GD zT(Zh#AbH?}I{D^vTJAwW^3vBv?Z7(}pLMUvLqgalNd@tjo9o?ami3_Z-qTt1Da%-p z-;piz>Ll;6d<%r~!-aKsQnf(G?kfF{mQk%F)0&FHRr$=xPQRmGmrRhZ77G7c&(t?} z-u!aY8jp(!zrEk{p5A{ydI!YJrzyFc`a$)bNA<1eU2z{aLcivNJZAkK9BubbZ&V#? zc7ETk4vSs<(cQjgBR8mgSoXSk)hv4O?t5@w5RXan5im-ms4L}`<13eRyQhF`4e8ew zQdc_G>V7R^7d~D^7W*;o)@;C<&4e?BwO~#dOrVD3t27r+@A`~0caT5-wV9GLRzI@y z1$9O@Ihdb)f+_q#M` z;K+lwkl0486k&u^*Q#Oly&5%3XgL^pM*Z9d8Ic59Sv&a1*o%%MYQtelsjJi8!IEFgYJeocJ(Q`F@qC6D6^JYQj~~Foobg81~s(oTE;# z15-ehqz)x8eAfsA6B={CuKpv@9SuX?b`Zi-RMz4`9QdrPvn@=+C7Cg9LP~EHto-d| zI}0Y97Ah%1)FM8gMM_<51La9HnA7NF#dmxq84UjGBOdantRS=>WTY=7uK*aC02JMR z_vcamyM1p6ox_e_z+89!#q=YbL0C%;v%y}>?4#^*LW}3mEaeqR)q6_Dk$3m?*|cm?*U^JvhIsA$mKrdO3|IWmSJu1LHs` zFi7^=*$&|7Hr6swS;c>E$BT&zkun-OGZO3Yb{ySj67YH@h zN0fdn1*TJ%yH4f`8I{FD_PgG`PlREp3r79TO){sys|^!wr$Ut);U{mi*wrpISn%~c zVypRhX$m7j0~OH@N|qBCJKxheyLG1RBJG+Ju!SL0@r7Nn~19l*Aa{aF40Z*|uT>KUqYvF(d& zs=;cgDzQ|6Uuka8)!8w8-}h>tfb*%Mv)m5(w)}c%fztiD9RA0@H&C*_GbVpM=)w}b zvFP2gB+uWwfOr&Iq7iPV(Y`8P`LIa=l!D{EuS1o6s7t8{xl-rvop6akY9XIzz3yFn zP*UQ%=Id2`#e&jY?-#^)a)|d)cm!9s6ri+|M1Sj6zVnr>Y_R`#8T>$1#v{vR_`!Z9 z$s(tbXC|mAit|*=)x({~>2Su#Ip3wcits^YubFuo`gt*X%Q}bfVTs`(HRraz`^!;t zH9%WVK{xNvaSVdGa?Wo3);}?_39~iwS4=$pPz|brUK(__A4!b3TpGw?M|JHzS!SA_ zz{tG7gR8KBquH0he=~v_IF7W@xZi{y=YL`Zwf=V)K{rz;XG?p#|5uO6Jux;m*wfR) zsCyujDF6o6Zw&bjc$Ns91*k9kn5a*b`W%OL)dxDNUeI1ajzI8b;$kGfI0`(9XyHb?xCJx=-&IGPy!&ik<+ zJy5tipZMJQUbsGxJzhCa>{H(B1(DLtY2$RKEaj|p5&4S%lB-!GAs}D}jD>_`Pn?`w zEENe4{@n;+odYOR=PaqepP0MjogrP2@HadtAOHmUziXg8k$m|6y~7kB|EUIi|MMCc zI#|*>c%FOP+T(I1e*N}~)Ix|(a5EX4JU{m{5CPloP3i`r$i=0=!h6)VyotTCdUosOZJ~>KlIz z+$yBu$V!Y-{Wyofl(C&;D0Ap-&ge6>1ftRA^`U1{bzfpfB=3`FO@44 zr&F2%vz3Sdwe{|plS2Ed*3b8emuKNGtV`e887}-qZ{@>l3}=6 ze|eBe6?2Hda^i*aE_{Kj659HJZ=AkN+CGrXz-2bkv|%zgN{ZuGXHk06j@p_FmkpB& zt(O0lRlw-oCdsN#rbGs(`3%J^IVN%!cqGFnDw=|uOUn-V`{Sg!`j&P^?1nj?jf?Xc z(s$1jF=QUn$v5f+5(BydO>BfmCA0B;J4>s|jCPFv8u6~Rx`)Zp8J6UgKo-%4Ooh?j zs%~0GVZ|evyM;`sGVtJ?q;h5-Adt+pN36+`a3DBFQxuQ>wUrVF#b%B(F_oIgRF2nu zmTG%*>@eQI_>9d?F~R>@q=D! zWrO!6<6u>w@`61=Zl@R$&@#-V*}$t`f8Vmy4<74#x-vt>h8rVx|B<;>0Dz3#_)+9a z5=uqMnu2Pu2n{z6DOJIyzhB;4g{89UhA0*&lu!U_i#9wcz{ut$c0ZNY@>ggZC%C4x zYW0WOUiM1cccHylaJNiIP?8&uMSsVvr!hXp(m$Fl>6wlq@P$h7=h^ zYhWvRC}FfwMF62e!q~l9kd9VJyg#k(+75G#t?AlyB{^e4^RtyTiw26hl^swnFKXP? zfKW&kG$@g(e~#K5Rw;uh*(RhX6%w77kH4uH)}&o2T~VIJqcs(WNOe7b7d~A`g2vXQ zR{)hIqk!HFYJQI=Q>#XDn@zH}YOImQzK~w zk2&eVlHE|h0XpL{JqYX4+%%DGb|gd4T? zs%w=>=9eAftToj7So)-5<1@s3Tt9Ju%2$cDP9qHz%}u?NK42Kr0D)o+oOsa9?zflY z{VV0y&reHzgb0O6%*YA^6I3=?;i5lQ#Ow+r46@^h%dQ_Sqs~ZO%G=UoBoa%rr{M=k z-0fRl>CcOTnL0JuE1EQ|y9E`0){#xYyLpS1XkRLos?9jYm<^DBcCm2Q3aYQigKGJj z0n71*mBSb$1+BNCP+N#3=NqLm>Z3C7?R!NAZ@pQp{fBBYrH!DMve%=~{vmA38?O6z z_W$O~;LL6y90ZDav{K#3P@P~Fys~h=DHvHX-T{s2CT*ndEy&SbBXjll%B)epz_*($!1b5TyOAFqidBfMI;Fd(HQ=vY-_+yVWaaV8f)-Exuok&@>Puq z)d4%gc<$Y&R5RPS4=&`1@dDPOjvqOAua-$M6UI$;3d{*2Q}uvOL%v6jH`T&wmoSg* zi?0HY z%=S`}Cf@~WI}f*!8<&458+g)RF$F1e&NnL7y-`J*eZ}iUckHFh@Zjiw!9sF}oed=r zl$9JU28U**V(4`&*oQ+Ow)YqDw`I}$X~%!zyd#wR_sF3K+I!Sx0Z!?w96ryG9Pa}4^0FW{x2(g8PqJY$a2CW^<>QNL|q(a)&g*v8qR-U`!2Dj zY^S$?&;iZkM?3krs2}%kbG%|%>8)f81X}W)jo;vqFL4g{%iA!N-If6U2Z$>M75CC~ zWQzv#Kn*tKfdb31LjPa1EgX&fv>%K<1Fm~W4q&i;bwDA5#dC8zxSsMDX`d4-M-dhw z2uyQ%z3hh=yjL3-LiycMWlWo+rLQ-_fnxTV9yS#r!%0c|%QnriQH?IXHg3NUSB<&V zl-1xQ_*U0!*=Fpw=TiACQfn=KOHN;sM(Tg9v+uMt35u^)ut!avqJHH1X;ZS4s??t5 zMU3RzI>oSXXrTvn>)D?x-s`)LNnN5DHV1N!7bgY=tK~#A`5oFWvQ%|9NdKN&M`W9* zLu`pIS^30p<7w91ru8if*7oAlrgx6Kp^OcCbfO#b!!9w32~9@3!;$oDADjPnVy??A zQdM%KeUtT7vl(!V2%HM7dV1LX?832^%q+`xR*x)RD>iB_7q%lYPYZprtOk&|`a0v= z3gXp>ZrXYue|CpPghw06Qp@@3=zc*cW<9QL2<9g&Blg*jwg_&Iu+=bHZ)6*8qk_b^ zmGR+Su}bk0uhf7&@e~F@!iAi(J219P@maicDfpDv{51`SFf%Bwegh@p$ubDDi}XtND52z{(BZfjUt3Sk<&lALWQ(Z;(;agi(HS zUY{Rc5!V)kVB`+&B)&U}C|tqO@6V|@B{lnb$fU@;HCtHjaeGK0MBhZ_o?SGhszs+k%cTt(9}k*r114|aRL*V;3+F9 zba`6@+nU%RmGa~*f1UHTX!sEiySu)gE49297E=z+YVG?`=f)RQDJ;*~d zE=YO>8Z@A2Zs{`XRmS)HNc`x9TQ=^^{M0z_Fs7UQR5(+&7Ye=- z0$Orp@PGUYADfWYEaFz%TG|hbcL~i^^U+>?&WlVU!=itvz%3?0A76WvxUb8JaCQe>Dq)n?b3Z7f+~*@%xbdeQ@JK2%W+ z%q}`fF!DjxoH~6wJ0u_4;raRlBuOd5Lp}lT=yI`fWj~p_cEzT;w_yHk^)SFnm##~Z zu(7{6XX;3mqFkb=&1zU{avZ&$P5~ATJQ_T%dD|(RF5Kg|%gRHuiu+l05qyw@Elp(Y zABh#Qnolms_~R+F9`~1SrrRmHy>gET6c{D`P96QJc|JZ4&8lL&nsB15;ax0B8v@%< zDDi0zFQFh>=iQVwgLaHtk>tBSb8MLy*wRR{oz(tTX|ZhJo4r{C!GpckNP8gB*N_;j zj&T`ct-#lLcDYs={!HOFJ#!eW1+(3d-yhpK4kX}*su%d!;Q-;YNRnTcV8nw_j!xHUZ)7)z*!bj`|db@c?GVTJV`bJ zesM=k!4+4kVWS;-9OrTidboM;nMUbzJWvoq6-H8N{f?zPbU-Luh+F@C7cI$Cfa`#vyr;f1Bs(!p{tDi; zPVQU9A;4t443qbHE!iAaT_BKql8SKu+PH!I{wLew(fG;e^(CU5pbL@aJk1k_(NMwI zeepQ|V$rjD2D`Q$#mae$S;Z8xSA3>b0i1!wg1^2a~ zaYfbLQgXmHF@`#m8cZ9GaLWRL@u?U)S!{&&eMAALLLwBX8~kgdflQl{fom2@j&Ur`NfAe#N`9 zY=0nxN=}dw>q`kKt4)Yk+3|*}1v~NEm$Vf_RoW5H0rvlNU$nN*VbZN{k^AV2GWHP* zdK-y$HdHGK&86wp%B2QF{t##`x4*eSS)X%u+@0Cbx~Uc6@5V|k=?;1+^t?${y#Arc z-SpfQkDY+IpoxhIZ{}3YqvQ`qq{zp@$HgBnH8-~)(d$^`6xG8SN#-&P^jVS9;7kYdGZ_jrJr`SOL0r_XMKiZGs z^lha@0e!tz$!Ko#;U2TiJZG*eh-}YMdN5ad0Hnz}D9`b!889{*VW*kfay6cxSm*Ti zwcPq9;P>$riS7axdmH*G=H#s3?js1M3+*ll6GS$JA~h0nvQF@Lq|}omN3`lPyFjd+ zDecEry5@obKTsv~m4hq?WtMsh{Lyt!?>qQdM4~#`I|`@DQ~8+V{nR}a{2k2>pPwcl|I^Gt zleq0+F|J-p=CY_`PO!9Rd^I%b5&=_Tc)Z(Um+Z&q>e~yMZEMKl?klxoG+hW)^t_SC z+w9n6uFO)g6>p8e7_&|dfn$=BbPI)@PW?j9wjfDRdO#-u6y{0=*ip2N4$7k2`nK`1MCeZ@yc3hQYI-R0cLi*9sp5;u%phTqv zQQ39WqLUcRX4{oW7K2tBF>BPno~0{Lzk93YsdECXt?wcBKo>QrY7yiE4rnTXnwYD3 z2rhN+z`y2JB?X?wvU=V0!JDmyX+vJ6t1rNLTxDqNGW8=9w`e%<)~8rlEL(oy^bKW- z=m$Svu_6P(7kna^FU$FQmp^fH)=AHR zey#PIZVW!Cl|C6*`)ik25F#AC|?=H0B@~zgeZMXBhJGF4cDe-E?S3NAVVGV^6 z8HOVaXYC(ZXMUSj9}V>aYOS?wOtLi4@)VVUHkb5BhPtoa_LmC?;QBVKs=Kq}8%bNM zYL&j*?KnH1Xk6Nut1`Fm@_jl#t2)2vxa#iy+&MfIeSCl2$ijVlIDF;){r0+2rM{va zbuilX^^XHT7D%Rtj;~40vND``n9R|@Ytk^{oSe96NDkdGi0F^0!Hv3B^ec7Gy6~27 z)J?JIxPIs|Y&3eGi+KS#WU%44I;yDVmkL`+;mTt^qj2h7V8hy{c7OR|t|@s^y0aRx zWBu0OI4^fhOo+>T;axECWX41$r5)H}R3=^zE7qn|DH}D&Eu%k-ety3epdm%1a+N1M z#9`pcVUj^WBv))B@?Y48pxD|52ZTl3S>ABdBj_wYd21Z%jC}j~Jz+DI1|EZ$INmk`$MRF%laUNg2k{$S4O| zYtl7e<)0?F>WEyh87hN$pXylfGWQELLDOeA#qkH-Cz(PidwkzNc{9Z>ioktX(Nya= zt&^$vzLJuTJ94T^<@i_+|FzT^@Tnu1OlDH6)To9-s$x300C` zTmr9x0>lk?v2gxsHQ~CN3*w?ACjVtfPC7ctdw#JDeq}|s zTHo6QZ!D>DH_TKYoAVj8#MVG^p*NIRtnGi)ZO+4YH#|I?`({Eg>{EjE%h@Nz!}_2X zaS*>CM<i+e9h{?Orf}1&PAAt zQ(6%itqhaIW*$5<(zC$lAIs`XBcjzGQ{{pO>Pm)-Ai0vZh(By}*MI`u-EfA4QR@O( zcUBmOe3j`p3RQGCjLGs=+KF;R_O}J2p=GL1UDT+4&11zm1$>lvv7%+YwxMQKB<72d zm7yb$81E%hx`;$r3O}wOcxy3x0wXZ?q6uF|irm-x^{?Zz@$VTcn}@5>^kD8Zx`#L9 zT!9vw5m3{w^rfKuq2ZEEskE7EHPwk(keySY7t)4ZvTc3+*NS=`rBxi}c;wA5KgRTUgA6 ztEyXB>Ss2HSWp4rbr(1S9wNRx%Bm!!TsB zi`ttKf7Jl2i>@@!_K)y{mqJTf)?ZTxE=`{>J()UJpAk-6>b?d?@!&&N9g*n6u3va| z=lC72Blp6i8+GSD-N-4e4paCNI7mk8^h1}?WMlxRuHa4z)fxcu7Lk{? zK>ELb%Uwd-lyA&$@X#;lytP>hu3D>tvlcw*>_5jN($;U|$+=riOvXR7)E>1~aev`6 zgVS%!2c}x3^ojX{MbcrZ+ARHK&XEytfi4m`U}q#xhAX%R^~m8Eh^n-4t7!X`H!KY? z&xj5!1R;$csDvM<*u0c14FhJXLSuVfw7iG03@r+k3M*$y%vhurtKEF>b@oL8F2 zND^X+$}Np{O=(%pNPiz%x2K$s>F;|+lr#^7a=-~3C(EC7(-h`T&u&CAz;r2CGQJbV zk8be+m;1C-oo7J+0eL;8Vh66Wt9CMvk`-^!8!a`i&FL>f0c;Q_2@9zf^5?`NevD=_ z_BOC`>;BuOh0j-{zoc_JOU&V3{-WrRDsD0cR?>@#KXr|d=b)Md1=9{VM?}i+O>{4= zocE}o?$8Ln_!W!kKJSNt)v37_e4(4OvdaEfKCe3>STAefE^Q*CUl);}4YRvLQx$CoiqOJH7zgQO* zzGhjj%}*@Qo^=n;Q7c--Lw__R&(mq&?S;V^dB7=z$mJ{?W8--R(|veB@#*O26i&{X zzp$V>lo*eZs?jyl-?;oSp~dly12mcV@_M#s?Ar7?pccru;hbP5@Ert?mTzpoJ(cV< z5ZGJ$KvOEchN)!=!B!v5mS4EorCpJPe8Kx#6yxyR?0hvDeL=D!8u%4ejuMGw1LLQi zVJ+cOM`}yJ{25g|9yZfIlh9+|{S(8Je1PKKhR`kl?t<22O+SYQ2gLjyVF`R^Nm+Z9 z;w&R?H19$ik0TbdU%+)VQ-6s)XH|}o{cD_uJRPS#TrJ6_xK7svg}X&}nVXD}Fp9M7 zSv&)HoaV6h4f@D~0IW%_ek~aEb}0C1WL2xfwG=sh&B^O-E=JO;3hv=ENhf;=_8)CLyzYcjQa8XA_>_06|2u-k-0Y2tycj*;=9sX;{9QM`Sch9sJeM{g#(qj{CDN<~8}$x?$bykbM7KiHCL} z+Zma~ZPam*@W9LH%U?_cAC9_ex^o($rnSB?-u02O)wLl)F54R9kf3h6 zmk@96tVZzNgJaw67^&=9$fM@h7qPp}g{6iJM=~83RWT1sL3_u4`NDUZ3OTKMH1!PY{OjnVJ9d6H zgBNX~aJSzS${Q>p&dIqy)lF}Npm@5(WsG~z@f<^{O>l@5HBIXzaNvEX_rkAX-ESO~ z1O0p}99kR8nCoqbtR->Y50z^W-2>5#N%hi27m~kX`d|TjY%8v*$G(7&6_C7!&Hpxl z5VXIZ*^3NdQ#r}{xkfSvmd>0?)0Af$aD^o+i*c1>-{mPBCbnI7Iv3)IChwzMS zZKBsLU{jAiC35XZ_Ed!blDx7cmiu}kn9S%&_3u=bFm!X`H3xlv0q5CvmU@UPkgm!0$cl$a~38Y6vOeg2P zZvfT!XCB5YxBo~ju_zOE2w!!&Wb{2lZe}l%@!xmB$A22a$v>eMa}hv5elY!aj*$5O zz!9>sWYpKUw6k>4*Z+2jWGDIH{C@rr-S<&oDpH2o>1#wFuK6(*JJLLMO;6YKyUYHz z+JIO_GFg;H;xZ%+m4hw%#BpZ>I#jPpE(n1uQG*E}ksef*!H;{W4q*cw{e{ns|SxP9$6IUBxCRi;Sm!lIj(U3L!)^%ZaPEm}hfyrkyY zft*KR{wX8u+7Z8`Xu@mG+yxM%#uLcf$93&rW67P&I0ZO+sUi!OMnE|>6L2Fb@3&W; zO^jVY39Hq9P(D^r9X7Q{jc?az?pw>$!fQB3Mqsx2>7?D=DZw{`1nK}J1sTcRacv`@ zdaJhOE1xi;(X}A4)Ki6Ral<$UIv{mYWxnNfla1&vh!A zsN2xKL=(}t9N@)rFt}^Upb|vdLYV1GGo9e*s9j5$H%2&aR2J$moMVjRy@Mx-umt8G)WaZQKyp#vMpb@sXPNOks&tcTC5njfW4MF$)} zs}S2Xh2vR(*S0k|N?T%BcKu9)ht`fxd19J8sdKJrI#tNg7;RK|!}a+#FHgj9c3hWie1Rjl11q<&M%Orzb(pB8Xy>TAEckCl(=0vL0; zoo8>rG`2m5J{uRVc<&S#rytc7q-=1e6V{3r9@UbI=f%#?%KBYDMYjdl@JyjC(UHGV z`n$0PDC(%%x>xZwp@f6MVt=!3o-&y>rqUFJP!YEcW}G=c`*WE8=JT=kYq|3f&(oSJ zEUvKEGpr`d+(bF7apQkrrDwF(t;dZ+(MGKZYp)TQb^{9gt8Hz zb5X*Q6;XE`00(Zo3tl^GUSJE?aH9S@SI*=#v+-9F(+UtS0s%eZS z2Tmw=dH%bZ?FA0=acouy9`7jsWFz?3brgcR#{rKj1byltPSK~$+PwK1WMoK+#^6`^ zjrRim&~b#FIkTd#AB|9mLetG8OMiOFZSI(wHxu`eQjank=Q#rC!5ZW1Pz(8I%XpwT zfdoP1%K?yEb{~uDu*G2J#BG8PW?0IYvlm57sqLs8JZ=q0$(|h;Gl~E!*>=n(0KbEH zL^(^C!dFq!<{Y&W;omjt3&`GpbiR^|$n!simgXzg@ zi5JDFYg)@{Ldg{Ygcv z6UT-FT?XE{i5YdA&gbUZ+dlax&gUAz5p~sSs2hDJm2*~Z`F5s@|qz_k{J4PH~`?z1ai!nFz2CHF%XBRcR%dnee7Fwc63A@E6y zu42w#BWz@+ye6fQ0&>U&t|@;RB=T8|I8Bd8z@AMH@RxLuJedwX7f_BX%JMF~q z)X+Of1#8IvQHtr2c_PM1mf558H?M?wv4K<|EDkcYnH3Krs2NH}kL2?8tiPr0^$sTQ z`V(#M(E~Tm-POg2@>mJz@ivtjlK@g!xNHoG+2`*{&z^iP2mWj89b?e%HgfUWDB+Y+ z;Wn_`NNR?y*jfP1s4uEo=UtM&dMF@$`j|7jb$>(JU~kRTQ$_M%+z4?Bz8{8uO8)EAsWVk4*m zzI*6yZg2Y=;+4EQb17c0xO-^XSZ$7e*VDfz#g-ctjs8D!9{J)OWs8b--=yB>kS8818RG{Zx3b0dBB?@9`fT>Pvscq;+p_ zHWWHkc4_0QF6!ScYudFZs4otwp=RPqY%ve13R&9<6@<)f;~MwAkZ zIH^(f8hZkc*_tKF;@hP#;XRlQp?|kArQ_>=2iBJcnppqASy+_A@*vd0|I?_v+GeoS zIqvtPP7Tm*LN&w6E{;!5lsPKal)5i()ECeH_Ej$mmFY?;rNR)E{^l-YjTTCxjur

;Eq{-ZS7T{~^R<8#Qx55~F z%WBxXz~lT!?Sq!=zpyCG9#?!tNc`EaNZQ zt>8=O)bKptgg(UEt>Rb1yOF(790cLIK~LDX9f00(Y~6!+Es!Jc5$vU?V2$cF@|0{h z@x&B0nN3luhxYK&UB9cp;LpYHWoV2>M}Ep2v)k~?ftJvAm}Mz9V{qR+lSmr2@oOIb zDNHo@zNmt}{!RuG zPmP=_t1$curVL!xNn7$Y)??dEFrSt<@`=I)JoC|3_g8$9@P+gCt(<1CO~%v+Kqi5;3vmPXbWzKv@3`^sgMEqLix?V97sAAi;^EiycA<@IJY zB=`Tb&2lesMHKS?M=;r+`wwf>Kw2T`0@W>TVZ^&Z{O^rhVByZ8ET8-ve>Z=pl+l(Y z-c=!n)e7epn8pA=pm>o9I)9%L#WmcDovaPSZ4|@SxU)d9^CNhg8qRLQGMvNo;U@$@1~2Ika~?1mTqZp(|)ch;nto>^oJ`yU}bfe~Fi$Ly#^Y@Go$u$d8=GorHO()_Ap-s zTGb0(OnU}$V@Xm0AvXl!BV zu8_OsED2Nqg zzM5im{7#~UBzQ=&9)YB!>;%G58|6++drer&G2C&8mgV2r2fL-HI4>rh3a43MkYOpF zaq78ivjTGG_2<3})O%my$Uc`L6_T~d;jREx&rMk{vWBLix(CuvZRWCHbAck0c=jt7 zIRqY^MLF!nmXAZUr`11<7DNX;O!c~mxABCQ( zHqg88+|YlFZ7j$9xc6;JkpH$e`~Rx3|F@U%|1)-%7SIM)!YglT?7?Q4)x~fU&aA{=t zlQFcQ8-kOF-b+w!lIxzGdFHIx_efyG?Z%-UjN0sP9o_L?f(A|>?1g)p)@eyL`%YSNV= z+o6=E*tNtM6p00{gCk>%X5w=kN5_qdj>H@kg$162W82J)w5RC5K?z$WCXbTvrPmb# z*jTU*8~H61o8lXs*S`YC=OiUT%3#^{+>QpW$D(;gY{ni%E+r|g#PzO*3APBpKEG0Z- z@`b=vmCU9Q!J$}XJE%BkuM=kq_+@_e)Apy@jHVltxrqouro7Rw91t2~RirdYTr_#ACBM#ROSHsoa_paXSW<>cmm}LM$9D_D)VhQSG8CxXS-d7lOv-o0vn8_7GyP)i47qn6$SfY1F}pM zqmH7g@&}SoxF~Y54x`B~1PI!4)Paa9V`)ZEnFS@80V&Oc#_2xS5M(|eAlBVe+P24P zC0}!}Y1hA+q%>6(hm%ZsuKl{Lqx4WsI0Pz<*8AcNNQ)Pi2-nw@WDyeC1+`I*k)LEm&8xZ`ax8{mG+ zHoBvYxI-R#sWX@!A|~;x9j;*<8-L1#E<#HO`ehseX#Jc9@Rf3W4 ztF;r3zQ4U?eS39_7Ct8>{V5&m(jxo!M+UCXi5;)|-ju(XyZO$xXZ2+;?hR(7T;H-s zD0!!4{PwI%j8ybFpy^NI6>8i8^m=8^lHjbkx|M#(Nt3mUC~X=*9Qu0A z8e^(V3J3wwtbbM+XnP#4XN?ErW)I|cm^a>bPzE8`cEAT7zF;-7znzFs3{w7csGxhE ze9VpTHnP8-KaoVODBt%YSgnxFg5LEP&`W7I`Ofsc^{!eZHt)}$7W|7ED63J^(`1G*|j+gyIHsMx19R= z^iZ}u)L;gz{01)X

-S+T!Uxkme&l2B1EtsKD(Mw|-L@s%u!7DkcC|1^z-hg;a* zCgZ0T1K4b*HBoV`QI?J4=*@XP15K^hR2jXTQ-(^oyOA3r$4GA+>+CiU}$e|1?*q^=2O$;N?+{fI8)0Ti|Ylv+KHT$D;H_6Pp37KyDi0>*o5o4 z0^L`ik^G#W+c=R94#F`&O1{Z9ztbsOncz>a8V}a}Acux6Lx2q!sg2~%E7$mCn>-q= zFXVr!u_q`Jy0M%W zUPJeB1m(1iF%o#Ld0Tg@9{7E$?t9G16G0hGYOo^JZ`ryf1^B}Z_nqY1%B5He;RIAyyqnLeDt2! zjyUPm)Uge=x-h`p4&mY$hSyYofv3i|M{F}(> zK$q=wz8UhMkD)=QF@HA`g`tyhFUUqdq!r1k&r0rDM#50Db}|yK7ITy#=t?d8Rjd3` z(exBevz?O&)yE~#zT+vQ$`xOMf@C(_$gg*dm(gm~%FWpX`}=l6aoFyKE*{%^Zv1oz zM&MwmX@gV(VLK> zDjA+bpvsgQmyMUxcjrl0>7Ymq6)eGK3P2T6+gB+D!f12=mZi{;sKj-0hafIQvDI1A zo%*$OB%&m7v4nI3(R!u#(+Uo#cz?AIP`N7Om#~r7km7xRz2OZ><VHMKd%sr5EQP!Wwa9t;biFOfUZE!HN6AAlmidJ$KP8e2b+G?C6n zMbRuy`-v-WwAfu`X!1fRzxXS|M`St44r`*UfaX`fxay!GAG*>#ncBWTX()0(<_j{S zW2BHOlLafScvBTEpj?kUeTF6--wPwLXrNp9nr^#1rMuPlTkZrym0YeLjA&jFQOWRk*%$uE{f5a0+VZ7CqihqI|;A}IK5rcpwoCO8Vn99 zsU4ZtgT^U1izggyHYP=%&rfAU$1PP*H3E}N{$Ahwwk}YdM~E=>vBjbM=5{kL-Jvb9 zO;KP?Zji<^We?R`9>-p>yuhoUK{&VDWF5V-L9uw@OhAZ`%H4Tke8kDuHK`omFUT3| z$Tt!hEKoaxWfQHX&8eDbd4|P&Eki!Pwo=NPyHWvNKpKaFnWIV(D<}<>eN?4N5*6hy zETbPFWyd-|O;wjme+EQAp_owzdjuIpi|>a}ZT<1UZoPDDW5Q`kh)&j)Zpisv-=G&U zu6%*@ku9D+c0+gSQ$0A$lKfW0GFF2M-L1xd|Kz%27j^tW=UM{kf7B{DOyL zkb(}oNiWCa!&W>I;YQVYTt*RFkrtd6P$!;TFZ<~=Ub~~8c@xfDD26nVt~51(NrMBg z)Pv32_o@Uqa3)xmw|Yx5leXke;p;O=4rtCO!eKaGrRqsVvfxWXOhIjsu8U&+$w0}3 zN9xs}mDLL<$o2jFv#M{-aYdX4%?i;i z=r9d3a%!J-sgpBKvqv_rU{G09i(p$Ab8%{5vvkU*+XSshw@BvwA+7qr!KHaa{0MorWgcEe6`Ak3<@yQCwOl5PyJM~QCu9@RogiF z1!o=Ru}-DUw?0bL6QOC;P%#F@J|&nXre%XR`qz5gshSnPqAI%d*wKdDl#Puz*2pSt zp)7}$k6QLXqmYRJ%S@%YT)`lqnUkFy-P(jDv!*|fIlmZkDlxc zo=v$zI9&!omddwZ@XDr77bzagm(hA&MT1n=Mv$3`>G~b{ah1Y^);O+B%9yEW$db-X z>n~7?QFF37mBw>!;KlKNIn7eRtc_6?s9bUnYmAgcO11)DY^T1+L~ z`{$J{uBiTkK`K})p>-+1i6KjHSG5>DevZw+H5Bf7mLoK3+luXe)(Jvl(0Ro0VY%7w z1e~^q26o>WXsAG*FnZ{H1a>rIc+<<|nAH%_u&?Oa$mBC=+~MmyA)fvol(}gkcYhD) zbROTXM?2F)csc>^j`Wx0|Dg%<#0b@L3ce`-vjxNJXtokNc!GW&bb_P{h zjRkRYBBpM>v&_ZOwRgeA=P-Hm*0^=qj-Ao!KBc|$r{}u6g95pgo{M+2tJBx*=rBH3 zoZpdG+v17I;Q7zhl*0}|h6v^|`~`W|?aq`xkI%}3>Xfb@%2Z{I=;K0c%561p}rN;^dCJOpRf1Z z-(Q3Kv9Z1`AL5UX_G|W#+_QwaeE&{fb}ibD;dGo`>Dx2mdiuq7`@3!p`ga|DEZol2 zv`1f68cP|ZRyPS=g~9wm_tnY**YjR$aGOGAVy9xf*U#=eBB%QnJ?y^HKV^Dy$bCn* z7BNE^5a|C7Li*P2*&ly({B(mA z6vNd(*SuQKyj_3Ctt6lGs%-3>n`hhYX>*eCIZnC6*S6CZDm!d3fo;OT6*L%Te(ve& zt=+rj_qBNbVP8A@zUpiwveTPiH4mq+@~B(Be%QSU?M=_J`Hz=_Qr}*ONuaLH>+;XC zHvBcMJ-DyR`_zuGwuPNZes${)o8GgoJ)MgvhW;Iy=a=oo@d*8JmOJmv+ExC?b zB02_l_S~%r>x%6L{$kY1lGByhA1e+=F3RQhIrv-mn!5$R|C;KG^%*sJOay z=Di5nwbo6%+r58Lfqcy&Jd5W4W9_LHm|lyIiFeyH75lLrf!iP5n;g_vQh?m1J#)?9 z2)sE9s4U&H<8r^7>hI;$VI@oP9+raT-0H$AdVHQC4>cd(ZbIAkXg+=T3q2r^l||Wm zSDk5}W68gJZ#EiWzYTpfm@FXm^|YiQkKUn%u@T^YjS>4&W8%z?whGo-x&{@HecIT# zzS(#F)N{|Op!wx_T9tS_oMDRX=(rhddmEL?*Wh;gCnj4g1q)LbQ)e|W^F)6Vn&Y0V zope1Tqc=$dNk+c3bq#JSXLs8t9`Wk9+4jz=G`=9K>e_z`Jt$6+5$6 zPhZ`u(fQt{s-v^*c*S&ifEshCcAxq$1$FzoWV0T%vMZP0jE{j^VB1!}4n4JM1{HsW z{FdNewDONx11l2lKaPW%fj@eg6KpjD2I9i_18Xs6PnZ*d;g8z*f5HCY6=w3m}rjG zm`9a#?26Gc(kh$}9kZ5IY{oA;YJB44g?jl_RUZ;&ayP806a}s;GC*WE^cW75X=qF> zUZ?cv)b^3YM-B`K>8OvfWB`#j9F71aB8SjrZQqST-%X~$a&6y4X5LG$;9m+2AgWC- zEcgFnbs96tJFgZ-V|2On=FVKH5j^re z`pT91Nhb0|Av6L|*W`Tt@0-Q^pOEW(JLlU88VHC7)qfY?7XBZ^x9#nmT@3A9zGK*1 zzc<}+N7GMvz9P7%xNt3@UFHz;I`ehykr;o7J$67G%Nm{Eq4{IX85QE**o74^^N;3v zD|n~N0ygV;!zp{n9EEw@$72qm*MTQeF^$McX8O#yDyj7^zH2JWAaCz%9Ymb#o@?`w zclkXPHE%bmR(J3=7Xk|P8T#&BBTOsdGqRconc*z{y8!*o<~XkE7D7=QGgr^YqY+2i z)vqG#Ocr!FdU8dfQe(*9&gFnwOW^(B0I==yZjOL%7u>k2@5Zqd+<3qeEQ&Xv%8kVWgYNA$lUu2PKSwFFdgF16-DJf3r|9uB5^NcKx0iaW2{2y)uA zwVYY!w=i|O?jON2uR#@`5_lx1Y|yr`=4cR6(@pzYn7VinH8pi}wKFvJarX53UGF8! zfA0Si&MVeK&}cL^Mj)5}cgFT)4}U+Fabot_R0*3W9kJ;{GnZ!+ACb_#z4gPA=kLoU z&(Epy#}da2@BWOba_C7?s6W+8f#%}$*4f;(t3a4ipth}zrCLv1E-%G=^+EX~!9}}Gjx_pdXnvR{m}?K?(I!K`Yinf2%nOgc41j8t zSDmIAB0g)_K4vHun)cpgIbQkEuPd2Ak3$SLI8Cuap_+ZJq#TA*J0sOX${#JYO{RF( zWlu37(vH&6?&h)(u069K>Sa&AU5}L`{-CGLHP+H2#ItwfaL`FL2osW8^2QMpQmZ#0 z-tTvrYv2o|xHd`}QIF(L`71 zR7TO6-EGprTC0#}TIY|p4q=5gF(qgyN$MKT5|#Sh`1ED5CbW4SNSutAGK@P)5L+6j zy16MS0mfj38bhe2wi*VoI;6SWIw7)fRd|bkx{3$L18Po(8Q@?02~Mt@w+;~rIAN8E z842{rtSo?tH-M-DMd9uw8~YyAChkqS(2ArrbftjT8BKz_usq4~ReD<@@Jj#2%%5UW zM`?QUFfIMsF_}@RknwP@qG0Sct&3;hQwuR|7|&k&*)iKs@3|>k$Z}`v!BCD(Zyt1S z9@GLzP1_Y^uOyf6Gq%Vp(TYE*$QK&tkH)!%1!K^sL|IcjNOTT>mfnDMmlhiuEhD-!;thrw|o(Z!&m^AB$H;hA1^IP39WN(RRrJK#+m4 z3Qvng-MaMf5pGRrA}n?i-cFZaEKhV4S_RZI;&#;!cjL<|1|?y=isE8q(jTA=OU7Ui zdDFe?4Z2e&B3iOX4V;o4_bHRXqYrsT85MBJ$XnCS(=m~ZpoZ4>Y#DonA$UB*}%FYK%*-NS*bL19?pB)crxA&2Y4niD@BY_XCekv8)J3?zZZ z8sWOQ`(`W_MzDqENo;`ZwsN_oV1~?B(bP)(+8I!ZsFSpEatetQ_-~Nr z1>+CM4z9JaPq*$~_^5OU<(PCb6AkOP9DM3J(+`6bK=5SW%$AarMS&%m6}vP{1IEuF zf(&tzH!S*wbFb}iyxl{Fbke4NI?8!@yeh=RR=NTL8Cp~|54S$umX&)erO?P==ru6L zQM!Za%Ip^WpyobHiF^de%Is=_w5f!fZIT>=7F389^-cT*9+?jC$TWYYA;9b59NdDU z#xO~|8OmG7OiQ*u-Ox&bc;Vtk1Gw83vKEA#7Gh-3{-V&{ts;aJCQJS#b8LoNqcU0PShMvF@pmpGf2=pF0FzvrGe4?maUrcRwA|2O6n2kny+lRQMjE6BsPgnP z=D}D-Cx-B6xb%!87fWT_%Z{6eT=p{h7IwfTi)hU!nj}g$<`>Ow8Z^udLKvJAx^mKP z)BSjAtQ*-Ff>PE9!^z_!!=tCQd_tzEQjSByT5%6WT|h~9a?>pscpn&q87NQEN{$~3 z*U1niq>GQ}m^3+{I&eLc7@>VAWv4Wo_ zC7;2HhUd1;BA!Ma-is%aU_a1_J5o*IvyTJh3^IrFA-HLW6T$$yQz=n&G7R;@MNUSI zX1CfVmt72P>E~f&4PzUR;UNr8wT?U3vN8^k34P?$1H#+SxS;kN**KYv#*F)a^^B6w zT(+Z1Dfg4t2+-4}jKg7#2;_LO{5XhSR*F;ST@J`F#3X|x7dR}usP_k=cAvHXVJDPE zDuw@&H|J{fshlP?pLEQ&z;q@EXE2LjbBqUSf5Y-f`Jo-DKTFLeqwGeam{5Hg%hAJ! zLY0@3*pRkmuMEESY<}I5nh*WS@K;0d4)jp2?IL?^xB@CA&NM$XcqKCSpZE#Fwg{rG z4Z*`+`Dii4<^No#B<)a)W00ant^ZfytQLe!dG*+Za<>v^A2;R{V;Jp2mQ8}DWzzq8 z#MJ#ULXMV-MWRIUXRy|+EK)SiBba@IQn}s2tw21QpcMzqmv+*Rl%7go`2|5AZ5FYY4e)f;l7|C5!P>Hp3b*5ltG6D@V}|71PuSbdhxwnRM5(0CbgT4RkM%0Ibaf zlKToi2J^MV0+-5Sz&JRw7>Qx-P_jxw-+j=cMS~S3%m-BL*aLuiR2qs&1mI5ZFf%S5 zHPsP%ioL*{Y(Z=>zB?{XKeXH^JfP9>=343 z#UHA7v63Oz>}Qg;00mm!!`|dbv00IoWEosoH6Zedt_c^4UWhJZxF1gc^hC?3k`fIU zK*}~d>q?U+<3pENbG%Se89^T9slgRF$G>n4k6p{R+N|MPil0ylPqMKdzqcW%OV8oI zH%KiQ?PLO|@Cn|IquccVJj$1{b>FaC+q(25j-aXR5+5f4oGs&RMr!CpV&@nR>yWBu z{)@_gGm%=cMIg_Uh=J0gg1 zsHCG-HhI$H@JA7Ydkhja7pS(*V35ea`#I?pkPD4;5wd*`f2=j>m$r7B6K2(%VVA@_ zFS?sWAsXjTFhq-f(jq2kwHW%dOJ0(ZYcYC%_pd zuy1HBw(>!%P9{~e4wC5}7H@mOky8*!X{KEFVFpafbGq$uZ0X+FmLOmuM4tUK7_gy) z$#y>KQ>*%iVR=H&?ztB_9mc9~+$KmGqfaHid@CwPam~H$qyx=Pr+fieqxFdkr=Qdb z5%a!he#z284Yxb*wv#e~E16w4gy5{FuZsw$pz{cn26JD>K`x-+@1{ZzR0~>E$zTwW zuq0;j9VD49X^!iR$2ZxR_ADSb5eko%uagU2OyH9pEO6_qZbZeejc0CBtGdLPKSb3r zDX`hL=hh3rQm?&}VF#(!)`H9n~? zmq9TJADBuE7z{yW+q_R6NHD_OCQParsJP;jptrdQO8B48b40lIy| zL6;;Kn)_S9J5079mcuS&IevGPw;h%xk8NY4!~&w)CQDKFKj1KpZC1k13akElkkw^5 z&#V(??%Y7&2T%q|C$6}wx2d};ue!?Wa>FNLRQ8PU^$auK`Kc0K-TArX9u6dzCyv!$ z+`d)Q=k5)W6k-D2e0zWpWGIQ1W5a-ajYE9)OOGpvTSZ=KtR}cDrDgx*NXOL7l%UM5 zbtIlSxYS{dL_HR*6QOELAcTatb%|X(Ej#ZKsC~WXZec=c>R|}`_~!}Fj%NNC^;Fw| z>4MP;^DaguAgdrL2+VSw{sF%u%w{DWa$!cpX&|OxnPFUss6DZZu~;w#PKk)Vb3MkK z$Na-@%vzI`(v&<_P`i3EM^N$BssDwx?-Na^u8MQ*ygB{OZ zX$t-Hq0@)% z#6P06J$YvHk%kRrnZxl;-qE$PnNXAd3L~au$|cKNh&OD)@=8H)$*#h8*aRV2+q0Pv zGRkdLi9b!FIbP)xvn^hml&U7Z3uUcaCf&CA2eZ8dZw@02gxM>kth%q_aP5u*x;}p~ z0B$8R72GdLk|UXk88D@U>0)+>muM$~G$v1_+HelXm?Lk6ta(NfuT7&n#3%v(L{c;> zn90alSUsm@C#}hN&-sWexhU_w5N!aJ9=w%QWtOkXTVIojE6GDMHXp}_G07>d7L!pm za_{kAv?CPVR-R)f@?qO!T}iHTh4{(I@@rR$Sx#Hs#oasY@|%C$&&3SrTUay1Cp(r) zB;`z8rSff=e0UjQk9tn-Q?5NbZQ4;MCbl97i*d{EuYbrjhLKEP>Fwzqc|02&D6UF1 z9^_=GQJ@R5xoL(_eXmd;R}#f->Z?YViXGobc4I!AXWRs|{X)mFw7;>O3i>CVj_KAg z?W>@rD6dfNYrAf3qc_f7;wzTY_tSpNQrG66F+`ey)$f0%PM2G zjaQ#|+hf(QMdNSlD;Dp10Gue@EdbI8*e3?TiY6w7xo;qQkbJeFlQHqT9?%AdEqh~R zzhxUQo7lFf1XD8G({y!zvt`x58eh-a?J7xk`Kisn_#AS9eeI5PBY`2wi)zT-I~dqZ zK{9M>u+gEpkJz$xf59re^i(iKKJ*n{gY;r#b{4e;b|xkqVd_7Ek!{RzF*#L%#6a zO#G4f#K~gsYdZN|qg`Q?aP<2pzK;FLmCSGD{ z>6ZZlwc_Jk*O&w;Fs>ZY2|fR&R}}a4x$oqg$_$a}ZnPiJ@Z&8@-F&huyWdC#BYr4JFELBc956?aad49R9_;%Kre8IHi1|PllZZf29t~cjN!Pg*lEws-wnbBI|M7~5`d}2* zS(es%Sm{%&K{jP2HL}6CAlY*CzGjmMsnuqzpdx40g8I%5J`0QPhXNXWlI+`v0%`nm zgIS6wv;K-KAjrJQl?9b$1O?cqr zaP%@V>TYOn(W+*cqElsuw#Q+tnxY@Nt!My_17{_Ujtm~gQe*L7AL{>YPD*^!ty5!{ zGk9UHss7>l{(kyC<8!!J>%MwgZO%&Zr3#@`_WTrdt??;K73jcM0wg z0tENq43gj)+-8sf!2<+$39f`zN+V|`|G_`_x?GxYaiLCx~sZ+ z?_RxD0Yl{zD0&lu$PlLM%M~8pa0&@f!r5FO4XXof#_CT&~rE9P;$ zwH+Oe`RPE@SNh&E;2UZBz>(MN!pksdn*40xrHHQW!CKzvQ37l;Zsbip!=tg*ywA{ zsANK#a$Rb-IgVSxs-!uX#Z4D~BOJ36QSc9;#ZVdbXJ|2W@yOmv0-7BCto&(&dRg^V zN$j$am2qFp!Hi}P```s|kU3bEIx~yTr$*YU#yhPw+b4HOw`8o}Cq){bt4a=I|=s zBZ2^2d=ijQV*}B7m2J}3a@Xh#iNEVX!slI+=XmI54fj7@M8P(!t^FDB{C-HI{^FIY zMB!dgskGE^b5qo%oq;tm3mI z)Q^N8AOA!uC0k(i`0mz(hjm|l`}$O)TBQB!*HksNJF(V!t(UFNZnPYp#s`J$F80vaDULL_Di2waerJc8Yks3_1X!%JiY_a%}AdAnbB$At= zi4DEDGmYe*osMDjy+8w(^lP~aW|?h))-lJhjhmwa!KRx~7EN&(Mj1RX1YtP0`=s{d zeo^&x?Ay|xuf1VFSq2{q3eUbPuB(Ho&6V+g_BWbV>iXpSup-MDF=FRjulM}MQuS_u z*4N;02axBe{c!TccLXK@X;T?q7=T z28s@|!BbYptxWa2q&JSmkpwJTd@A7k?`gSdQ3|xs`cJgGbih%Sg^5E@TmXNAO5fMBm1(bfEiHOs8v! zf4jNqnrVi4O|iGA-@NNpwP;-mD>cQpNEWa+gGa<}pyXS8wtn*QvpSX-%yFD#f+)2Y z;#|QG@nF5yuHXGlP752B9w`~g*ThsOGb6QGDJ)Fy?kQ;!58DGry>~pj=3yBUiMuP@ zpAIaO)!~rHE-A6g@LiGN&)W1?OR3x!@}(}A-Z>*HCA10I9>O?hnCR~VVfNb({!b?k zI4Q?#D#)a@TX$StPw#>D_rsjX8X@0N@X-UYeMzv`3AOT-k<(DTuxHu+70AY*+^}A; ztdQ7gSwy0=ljO^Ei}=N(tdNLmhBT10$cA7B$Zjy+v2pvt5P0<_Dt{5o{p&h9=IW;n zDt{B0?mB30-qWKONHII3GK(=XmmaIU_xY)ZDgL-qZ=pI8>dZXH%O-}d*9DabHb*}c zG2%L!f%;km{Hf>uC`wDtz^rP@>=(qW>Yzf2I3cOV! zS*B4qY1I%+n$1l*cX*R9SY%oD`Mtbyh=+;}>Q2+p4yl$uYm6FEOaAA%noM-p5-jcw zIVyWOYUc8}`6c~nGiNUcm3YseKONYYJT#QExtZ~lu!KJHL_ahoT^WE98SXM=sKd&_ z$%iXb;j(_YIhS@caXy()UsEj!6vB0a`=3?1RG9>{=!XjQcf7j&HBGJeVhrFerdhY2 zw$+@kByE0_3S(JEKf18EFA}P2Pk>53Q+%ACGtlWbhkV=m@#e7)a+EF8f%mT#xefPU z0131Ohj4g&h@h_nfb^2iL6Feoy6J%E|6mv2V)!sTpB{{Y!N}=d=!XYLW+8qXXov2> zvYQB`t&yRGw*=ts^PRJDh4UOQtK8M0mFJB%dbP)0n*4s&w2*I+wP55Th-CDz8Cnn5 zx{20eiiX%O4yk zm+O#jy<*_Gm5xWb8gK53+q}NWA3}P(Xzm)i4pkNFz#VQjUyhtovY=`PVD?A^-l!vO zV7!$Iq`oqoYh8~Qqb+!!50f<+79Vp&ccgguMA0SrYSJ7>wPm&v3r@^{py-MD{zMip9aYpdFqOA`_yui4X%|BO zAn-wh=7Jv$@j4OoeRJje6LqMJ?1f);76Z+@z3m+=AZj9DXv)CtWGN8R z=0ZsnN*QYQLF4ru%?BVwPnXgKO!OX)T0LZv;j4-jpkJFLC5AmC5Ur>5b;mc=&d8$4 zO}4LF+qHyhQTL-*K!P6Eoxd_lga+#?N*5w6v#O#{95h{yC}_Z?306rl4>J|-=3n-# zYjtV`xn-CXLuq_nBt7lcb`e&|H#%h>{$F(;#XaRf>#9et4$15>KYxqaCGwOwIRS*a zv+qHTx^>H=E4~NB?aUohRJsJurx|_ zBT+$wnc&vi&y@Gc^9rc{6fT$K>tg2XW7N(IMGi}F3B>z&C=;Yi{RrZ|i2Sh?j5HG@ zFq<9a!QQ96D$80Xt$3iNEr?O9jL}(D*qKrwg%rN?(%x-9{MTl;b@$`b%cspq8l*gF z%=AiJ{uUP;tg5;bs;i28vEyetDwIDdv_C3rhPd{{}5=qrgc~D*IFc z%hUqs`RwHv`jW=-&6D@+o1*i&lXBswQh`zneZ7WiK=I2pZRWIbLs(wU3kK7`0Len( zln?sNQgx0-x>s1R41=Dg&rKUlZqf>;OCalEL_Br2t3==@67!_VW1HIGoI1>$ff@menJ5zVLM`cnCz zPj)_&rEh0Vq7t}v#s8UTR!W)E`Bm6wo5*fZrvar+)mZPf;z=!YvHlPUvy_znq;qcZ zHSi(eJClqbChl!@8l9rJ{6pHT#P$@YA+!UfxcwQv;~Q9|By*2TOSd|dGt?C|g!#HN ztjDr~Ht1TpibFaS{V)j0wKGu%PjqUWH8|<${d8sbh6zMEroTt!P=HWn?P<^F#}~pv zIxv2ZTLp&C12xgX8xqKU9nTX^-ASb8TV_DS#pYe@Tdr2GSC8!pS5F+i$)08p&*X&P z?6wG1^U66MY1AwU=+sF+Tb66`Fj|6wm3;A?Y36?t08k@JjyKCQueKmsLhF4gfcMWq z!e5}W%dS@C5VtP6hFfR&$XT$&`oYPeUq zu&{oNcJFdHEmlxP5$3Mi?Y*MsjWh-s@F_4FhZ9(5EusjR40cnbA*+C}ltZY?ifFNH z>Hmcgeq76maKk{M@wx}CKJ0N|QGHM{==pnAJRG!o8R3ds2C*%Ra^{RWKPN7BeqpETU~Ftr!v2m9#hdCXOY(= zb^AgNP_bBpN1Kwkj~!{cqY#%(nY^1Ca$4|Pv+qE}ZO*;!hrCXUQrEe1-Z$j}WnE16 z;-$sMO;=^s>+wCRobJ#ao6;=#F*Ej1z zE1qsqy_j8#JokR!Xca@DThEw$s+*gG2FLpZ1-hMryG%ic6!PfoPBTJXy^@%XY3DCf80qNOK4FgAkq?g17H3vW9+ z@LxJWkFLGywiZIFMCenx@cC!GK8DpI#0NqiL}--ikrIM-*oD}2KLef6P84514>4lh z%wydlW$2=~xuaQvL_>W)-T>m{3}3DJ>Wt5y)c!K$^J#8Bv!*2T@~#x7bAT1$Q}ig5 zo&8NuK@yxi{*Ckrh3^s50B?NCXV1)gIyHd9d<0kA$24)D;r?kRB71N=>F9y%Y zX;82F29@^}VH5lt>TUVObx^4;g4|C@o+M`ifU$!9{T0TFcgO#N#?k^N*+(k(Lo+*$ z-^W6mkO{TT0B@S#dyvMm&4Yd@goO^~b6C5g-{I@PkP2r}?P6(UNjH&n_EEpf;pfx( zB2E28UX2n9ZtFwt=fTwC5DoruhE&r>Et_?Qv|WqJM~C?%hYrb%fSyGr7^aW8X@K7y zL@V3tg|wC%2Kn_}dd9s$#S)Pac=*D6qeD}4xj{g6sc85&ve1_L7D(}-ryQTucUEr* zYnAaXRmb(49GcjnAYMgR$YjwJb9xu_S@)mwZ31>#P(_=aWXWrtQkaFqKbp{SBx|9+ zRUo85@nnYkSFG@u58viN{-jQ$dFDY>J)>A~tR92ct4bHxp)zt8+-RVX&Dxh7Ve|Alk-2xf(YRgcW6SXukI^GkZ2*bK$3pUA1Eu8thH?Y zENS4M?#dIBV;%8NhO()3H5k3Y`b}dffw7o@nvtSZ>bdjZM%hBs03R+Qu?pEXP0B!R zSA6l(@$`Sk_dxFnzns5|p4xL|{9c%lHVXHA<3)vY3u=2J3Vng{)5%?^OVa1wUlC)$ z8ACPSwnVC$snsjOTd8-)h1?YBdgg0FI6E*D4=6uQ2)Rwu^}LowIq<@he9`n_$(H>Ljb6)?HF=BLUmnqAt%pRA1)}d`9Vm)E`bOHnHfZ*5klsa* zCoU}E?E@#;)TdLKu+3yFAWqLH`!VkoPGGwj2akH^0)kwzupFlBD}g3*2S(fakVJDR8 zq=#*m?iYz|%%(@H+*>8?naVFrUq5Uz(IH_((|Su&8+o>!?Amd(02uj7m4_Xs$;9Uz z1`%;nIPCJy!K16QqqTEw_1VWG=uaznbno0$DHD=5uTp&7NLPp zKlI{E!czXWlf1J*b$lp}9boPNAp*5@mS*n-Vk~bB4v(h9#qMq?mX9}5B2ohU{Z-`0 z*`j+vU|pU3Ffi8ap|>g8sJ<+gOJwj*kC%9`ICf@MVQtn)wdZ1n5}M-ZT4PEEk5y+5`ng+x^2iCMUhf1k@6pHpI@Pmep31U zNKl@Zk2~LeoPa+osL(f)ns!3#fgaIi#`Hi9$0B=gbqTV7R z?X}-|eGkQ`+RF^9K6ox449Son`LFfoIMBDV@7Y|TF~S>^W1an?I9Hd+GeXbd#ug#T z4y5fQh0T||bmm3H3zNN=8nQbNYPz;mnH%d8B!>{)zX}>whffeQRX&;&yC)#x+OtUg(ZtVcHpYKHBSIJrS zFT8U>(9riWT%VAsGy_h7zQ!A_D5~Tb*=uxC5=Rvs7jA4&!}IBr!F6}=9VI$?z!y(s zG4k|CnzUGQIHUcLs*(I`+t+~Cc%N-d>CpLFpTQA!j$Wkd4C2j-ff*M)ekSrWnqU`O z>}t?9RMcM*Z~CO%H{;!hBKe;hOQ}jHWr=J#jb2t#$BZhP{nG&*6JX5$hKA~KQJiX2 zBqVaI|0y&W{ojWM=gMLbBOLEh zq-DdueUFY_CeZu!{ja@B)Wdu1K%@^$IEjBR>b>IQN8RqB%tCi{iiMh@4w)DEceYagKvMWw z4^$6`QmAI_yW3_PbuzhmpxvsyI#e4#hIjcK91(!K;wZ>-RKhmn`8_=j?vG4CD}}w` zf9PAia}WUXb-KQ%-MAde%7Lxbq#=#YOh5D;QFm8pcTpD9q6c?L-3!2zm$IrM&-;oe zoC^S&h<1xg!M%66Y0}BDwp544VgAw^-Cd<22nr-g+M+C^3;L=sMk*AT{p?Cm=dYT? z$eY)4nmE=JRPkPT;L0OL{C zWkeeWg!@};v4|=ZUpZ}MT*Y5yI)F)v`$$YV4VFwV7mD_Zi0R{xO%TptMptnhPPt|g~!?^LgE-gdmwMb@;q z%rg$Vd!amQYE*K!Eiln&X3pOBTdez zKHHl2cV5v$Q4>Xj8S6d+@?dv(Tl4zM=OGAWvILI_a-8hzX59pD6uTi_&NE)AKC!&n zm8P8ANXH4f$)$BjGYVJegXF<}XVBmyfP#E;^+_$p-9}qrqW1Eg868DK=LV^HZ7rI4 zR)1M!p6lfaXLc6?)>`8SddE^8@++^#P2<|zHuFCw`~PkCGH7Q2@U2yx)kp87K9hrL z%$q1U7fKu+15!@lE1muXgN92eNYzDt0E`XWPOq@*1eEUTFB1w&59$+>+Y+CV&t@s? z1kQ|yph8Dt+`e6%`jUAYn}I5#jZFl9T;PT)ZM-F#eIeX1IAnzNX`!aq76}R5Hr9%W z_sakCobjjnNd838Waa^^)#&pj<9gO?@a=#7`v3hT+~jp`g5HGubjA>!+$<2)Pf9-+ zlb=pDd7@f6S~zFuR5ojZ!KJ|0$+c1koM;*|upX0#lZROoyFw*bHxP+q@mo_x5&~vMohFdKp0@4nzs)pl1YYP~ zIIYuZ$xe@tmyH%o(Z=(`4|a?Ebz67}{XJS}3!xQmYaed)MB&;&UZSqrLF%FiZ7G_X ziJ~dW3eOHLc+BOfYEZ0G`!s%LziQ~`nsl!m%gzny(9Pvo%5^?k z@+FYz3(Kf+oKH8qT%}ZNvstp4_iQyq9c1GC2>xLP{#8}!qM6xbStmwnG z8Q@sz#*h|T7WrC6M?pm^^%n!rQwU@5rQtLYh)pT|G}{C2J1s9L(8P^zxCDnqVlJ)C zXcX`MpjZAS4PwgtH_dkP;jcR^8O_yGBrg!CG@g^W zm$LUt3O+QWH){XRP&B^ue1#awec&sVLo9G^Mumv%0d-1D0`UVcQ-cS9LC*MIs#?p!nM!A*XiF@CSj0Gs>2G$KKzl zsXvqe)$e%-vzq}%_-aINkPyo-9^AfZJFR z@tDOE3Vyb4&BmMSXV*lT_HWkd6OT#LmVXdbl>Mc57=fx&a}OZ&|K>@t%z~^1FF8`T z^#7D6{XeLwyyQtQYATXvU#Ucr5RW85YG&bTpN(}o%70FHRx@x?xmvM*SxQ^JYAxx` zpe33o+(f2Ojh?)BywACk_4~nX0Y<{LiTIg*3XLSfr;IyS^eJke5-8tv{OCc(IU(@M zvvcdc9Lp6O%O$pwjpWWK^OsQv&!}T1uxa572y$(Z@+ncp3n`6CL5y*!3@KwETUjB! zBA82f z-)J{xfT!A%h+kMgGy3sfe{i3YY&GHaZTN2d+88msq^MOw8I4}^h{^RuTk`LlIKR+D zdZ#Gk??u|#ui3YlRUWBH2cu*1eg`TqMP=~OCX9o+n2AETiiwy$X^o9Av;6pq?D&(2 zNFeJg29*F{Vyu6Li!-w2$Hmq7oMX31I2Up+QK##hnnZTPX@X&kIER7cuNCGiPnx0Z z7K&+}iCZ76QfXy77&3`SSm{&Jdy8!AHYGW~H@#Xw2wGdIzd=zS4L^RQH;|kpGNdm~ zNBYu0k1bdBp=I+}L4lv;g(@ET;*ArUQO(FJKH6&nHp)WX{^G1noC!X)ixbk`Of8Ji z1C^QT78XKR{s~f+AFeF}@8vIXShU%+IA=epS?A-rltmltC-$14i;y-if3y!pA&yh# zyp|RtXVZQ&PxWc-mDU&*_ha%p_pc0LJKW1~og-T)`4>Iyq!7IiTk)RcAK-qB4;bNX zjvwa-7k*^hWS3psWnbR17}&8*{Z1Y*H6(O?o!v7Y&DOHh$|h)m&B-9gVEp&?T^cqI z58$MF_yG@Fi?esr?GE5(`S2-}Y`;;@t%WhBr<$GnS?GZGReSrp++Cfg*@v9ob5>^q zKB@9>5(VQM?OkVQ^(3HVLyi&2b#^&%zFH48zEpQ_-fiEk|9P07+nYp=3bXtSZyh>y z*B3=p3zxFn{a+|cygsDtKNUnwnOFyNx~aj88U3*Kw;>$lP1QO^$)XwSle%aFD1eEr zve&QFNBioa3!)u}bRV3tj6xbufjIYHYswq!=99U(qTlU~bKH_Ct1(}#ap>{cp<2yv z6FF(v>aln#&wa+$OQkwO&5|z@H{kx=hE!?2fr7^f`8@W?Z+zyG%pdnUq7w6Ak!J*d zc{O-Xc)q35;FtYEsE4R0v!U_y*4VqiFv;!m@fqcMj4`RXL%m8Q`8bBY9lj98jb8a; zySvcIyzwo!J5mdldW+%P@ly4hHkrKDBSkYl&ae2;6)7>fBA-<~U^%5A{xG!qFrA<*C_P?{Amm*TcrI^V4 zf}K0a#MUP%uoap`DYS0LYR`MbKbsKLh2Q;!E!=QV#%(VZ$JFp{X3F+*V;Tsu@H4D#|jFAGv$*xYgF){=VU$V3g4-K%D?b7vLg$S9$SvLbPYG zi%Ds{Rpl_<#e2Q3Q0=zC7jo~=mO9M^{?Kr)6po5ek^DMrs}~B+(Jn1jKC^=gJY?Y5 zt1#&)C%@DJgkRMJ7f)ZHxs(~py`LdLe}|6VE|7;=diNP~^tx4Kp0NnVKhrP*!!0uT zfSdURsW9yCAPVAFeEq;Sxm!mJAW&hE=za&2^QW+S$#*}^p~Fx=_OuV5LBS?Zw>XU*;J^x-x9VvUgX0oE`)~_n_(*EQoINWXDAT{Lu>Be7 zmL4{-?D+)uuj6tKAt#@2A1kY=^U2U%3xm8Y)E23Z~H))>S2(`Y#w)(KVCO@@oz z2_VT(e7cR$*|P{5po{)}+Q|DM8A7~*ZQ|e+;Z*)9CDC@6MOcS3DHvQfEhl`1*Y_se z*28ytJs+xuYqVlbhfX~K#-_R3xt7W>LOBAW8a?Jj|g|Y${tU4^ql%8<(*7{m+A`d2T7E ze(x^Q^ZFr*IjlQs%~*)VaV)wi|APagKh=8NrY?8s15z2;9Ixk&(=;;4<>OX}>X+_u zdB2Z$r?c(z$#I)8g};qF2s>7r5Jw88!11VG&k?Y|<#)@aB`zEFQ*VtcXmDN^NPYbQ zmr;oelsb;bGI@}nvP(~zc+d!I4)XH#Pmk(`-(@E{7kTw^vnJgrnHji5)`plsOPsWX zNdu{6Xz02hGT_%A5g8{kh+4!`9-KH%Mhq)^;#+|uyoVER5!?F9;|TvF-XiMn)gQBw z_sij{R#{>G%NjENn32R+KfGO&Q_i*`h6|sLsN?b5sX?vlJYS|=)*~E>Z6URQIs&Gm zk(BMMf~S__N9bsCas%lXHh1H@%(pSEufF(J{0Nc#gh5A7x`FhCpB%+HWvyo%+i0qO zFynm*{g&aXU-7J{Z^H+*^dmv0BpaVEJ1i^$E$UUmP+VHGAJ9xDpc!imo%V!CVf^bqsSne0ahMo5&!y`Smn_Qw07FWT`Q@Z@fq6Q z;zf>Brja7Yt9X-QDgXmdQW7Z6 ze~x|cJ?M+D>o@Y(v%Ftwzh~3ie^5P>+s~LmNY8eHP><)#i_hvV%+KftN|8gFC5+=| z7O*IzqAtIZxuos51WB5T3WkZ5oa2bTEEIKZLy_7w95!~h|RBc$%4_O*an6(N*|{cAD=Jn+P~m^~K66#biDYrglFb=<_3T*twlgvPt? zSurmfTsL_k1r_yQjLuM_tikJqij`!#DEt6kwj!rjubAueqX(J7gkCQ&^O#O-cCm9P z&a;g!$a?WDFuqX_Dz%8FuYPqfXiJKo(*mU@!`4u_cUgbHQWb8qi;MJ^ zjYE|e5}mTLrUNc6z4$`-M0CWUc6b^jK@LZ zu`Gy``r!Vl5-C5=JX29uK7~mmiGa-;K-=#|@V4GFl_O4|9>nVsnO=?dwc>9HtK0xt>8B66c3UJkAFvIzo!)0oTdedmg{R8B1i7~) z92%l-)dCZwktXigVOs9_Bj5^?lwy0UR! z)o^F-m|&aN$Tc!SQ=80G0`#&r;Hx?A(rz^BG!!aNK4dvD6Uu!?DSo(pQX{7Bes;5EX z9kqAw25P*mPVdR8a-n7k&8(Y#=?ciEw`J_`F-1`}~beu4)@dT<1*;48zM&#e1FKzsd-dm2m{ixJ_kc z>8v_gv3?^^?Jr09yKN=x6`swy0aOfzFSt-jsmqmHo*}-U7JFLIFe#D-ebc_|l$+N2 zJ5sOme&H}R^>_LHvHgJjkaw5;-!ZrMNkX$}%z><4bbinm-I^pd_9~^`ckKGh4r9ji z7RLu^!0NfZmkvnmtZ~I7b8GSWp-iJ3KDF9*#t=Lyv7=%yCoh8XtA(d;E{>Q06T}bj zKwIPFX4I=J;-^DOV zL*MBZ%7ka=`0;?PV*k7w1jjoQ4Mwgu$JRqAtY!EHdt>W6W9z*;*5#Z)HnGotDPVE@ zcbL|vnuCj$gNv^_YVhrI`VCRw*=+pYNyUw?5XU_H-qHPryixpN{ps3PRSErufT(&n zQOu*bx)qnQl~aEIB7Ic70Mp>aPYMZDE2r=MhVPaM`XGJGgNlT72V0ZmoA-iI_1Z+% zX&+3#SYe%NR^PT_*tMt4|?6dC0QZUpqs$PkCkT#hjz|`vWRa8AI^I&c&MF5#| zZZd`APl^EATO1;5Ugg-%SSWzVTAj$c_GQe&e}{1;atUM6xg(3JuP%FRT#J=)O`{0F z1Of9FA@njJdj7it!l4%emUi?z=HptXL2xPs4BsoOf6+XuK8VN~HX19u6~nU~_SW`OB+ji^`PV|)W9Fvs$#Kl|TxJ?}i+YbA!W zrtDGt)WPIxP6l7nDra?VeaZM-Q}TK_3j%vCw=BZ=)#)`-Ahd2N(UtCYHV46dx=1Zn zf}Nk9Cja;}X< zg2WpFYL90evzq3AY66xK!$aJ8aX~YF*1ZtKVPeokSY-sA@@&_}YiQ%WTKkm$T{vP{ z$V1~$WF~U@?%Sn6lFZZL5i8Ncp2&FigE{0N7x72%p>Jk909p+(Z-vbbOx^`fJlXio zLrHN&%x=&9qEw;MxwdUr3pfk46;c;>RhVRdvi*iobH#8#Z!X>Pt{THYM|m`j2dine zaNob%m9p> zyWJ+P&RJfdK6qUae5e!}kRwvO&zMuEV=IidjO;%Cx3Wpf%{-qTFTBnDDOel zc<0TniOoa@zx!BPvT)b#f-O%FwkTcW?)m> z21^o)tOT7&e0`EgP;c91G|=~(ndt(;CioyfXB1gUZBuJ}=db_Pgj647ixqFD>hq4* z`I!ISi}}OKYvc{O<$R`HT3T~&DG|Dz$KPm7<1wqh*(rp}4+i=i&nLIxnSfOLhHvl0 zWY)!eFM4h~?rac_3s-dDTrl)+6yS7&?|%5s$5ql$Ch(*E^1lS0z?O{(6PxV0oAnbY z^8K0L`VtK6_-Rbyad;lN>sIo%4Mea`20yH+9}qcv?vp-K3^*W;H^27Y2pB!O2fBYY z+OzIV?V1&5zuF^^aB1C3Q8!rt`r5e<{DnUk!;)>%a09Q$_Ixxt{qBOA^GL;#jAYL5 zFnPtR>aHYLIZ{Ok0pyseof_)CqR{r!{%XC1`;~hWMbZwTi#^v$YAuK=; zO%rn546mX7ZFD>-jc2FJkj=j)vNYQNI`r_w7B z``X3m_8&iMowVGvi#X<^5SV7hz4|)%u`f>Mu6;V|O}dqj8XdLh7xN`Y5xS*$@YR0% zApZI7b)Qc=q{H?2&ys5D8mMRPelHGsJQlAY(?ONK3`xtAKJ0jDgWYu(ngsZHZ9NjR zRt3ojIqC;Fs}7wMV3y!LSZvHf{LRJOo=7z%`CZP+kQ<<;ZlVDL{gV;P9ZGjW_ijdr z$Gs(pbX(y5EowEhH)wl3yqY!7@lo`)Vs-@cpp?Y6Hgm_jQPXHH_i(b_A1($B3B5A8 zE3OfB+moq%C|jsC(7dtXT|`{Kxr+v&GdcQ@^}Amyjd#6sQmm7mYeDKg+eVB^rzU5r zY43Ct4>UR_9eAo24Q{PwYT}yzP^&z>6>aC{*LH=RK0XNeNSZA8Uu0BI@?I}MK&_L! zG0Xe-u;PPdDV$~|{m#Vg^^Dg1USZJek5E{2^D1I^65!NPbY0@LB*7!W`h01N-*uYv ze73(du>gcan@iU_&KA-%;m-5%69jO7m*GCuV?YK>uGwG`(6UJ|bDy)HC-cNudXBF2 zX@Bd_ofw1*epf7;^k?_3^0z@}$5tGg84OnB{WK3s-%2jI?t*Vd7L?b>bal?Ty!76O zRcxgJo4l@lOhD#Mk1t%5&4{8esgNuX*cev(%Bw5Zclq$RNt^QWCbMzK_3Qs4jdSj^3RLl1D09A z&u?1p$-2(x%O*=aC{BnYC#haW*eD2UyK=8`V%`Fhv{#JUUatmP;cV}Ff*t|sfTwqkR>VyYhsC(%6K%OU4 zGNs94H(T218t5`lK~5Dpbf8Y@M^!$hNp=@MS(-zWX8@Nk0y)IatOy>1bW{S@YqmgL zid_yfhs`sBgKKG&x2+1+;5N>;U__eW6Yn8uUc$c@A5r=}=ojSys-`r7n(=^1JgJ=( z*M)S=3Lz-MGVbX_=oB!$`G)ejOTKUY*VH5`<*lEh_4-N8mTlNzi_1)UZSKEAR)L$# z$91{O$8yT+Ij%UbEk*gKyXR6x>EyPd16`r3jt@m}SG(N?IYvZO$wOePBI4fR=9)Ur z?+7CfzM)=}>qmJ8Rw`PZ6dbIT>q8L6xqFhwOfts>4L4BkcvdTd0t~EaIp@<4WM&PA zn(Y_6O8I$m=MVEV?ZzVIg`g{9l+U&u5qWLNJJ)(~?s~q!KxwriKu-0P=AhjJpjbOE zS@3DWVfPw{Cu1#m*9>vo<*u6A08cMQR{gWPhf_Wyas{@p{o{a+)59y?ako-ciFufU z%fA$?LGM%<^SCLW?`-3sk%CvL75wXTGsB>d)?kh~yP-6pE67YbD8lifORo>{G483@ zZWmB`ncbqw=!!>q<~Wy*aGkT;h!NZu$y1a%qXY^&jO88J?fSi#ChNsXr4f0#lqaJU zad7LY;Vh%D+Nm&MQO-onzw;Gv)PX znK((V7t4d}#|-u;{XQ-j4zW5mj#^W~I3pFMI0XkGxN&})j&YKhLeOgiW0+#xQ-I*$ z&Kt^W`F6$J(km%BYGC`I$BB3x5LP(ok*sTN=4)aNaM${e7mh($if~N3hsRGv8}SQv zX`DjPJ|G^j$Nus~@mXlOUd5V*YwoaFRda9Wgk--<(NFt^AP}G@^nRs}K$Cm)>G= zttTmy1Z8=VhQlQ0oEO4#2(joqnqk{wwmZDg=R2kWaKZcfE~>}0MIOA-6z`1qCq3f* zt?R`ODFlHNZ-Z6dH^{cJW*>A@bsf(RG$?zsW6&a=sv2MoqNuzONR*hB1XNsPq>H>d zS#mJImJGg=xtD`U4%CTUCDgBC1U|OEG_;*#i&zgy;yiw{T#P^9fCpHaViKnW?&Cam zpu!6FdKSI2!yW;Qiv)deC#XU_h+M|=Dgo|biY=1={4#5zI5>}Z`aE{Pu7W=2E%q!K zTWP+fN$)!7jT=<`puMpH4#K~>S@d?DVZW^^|t>XiE3=3L{eM{P9 zK=dl_?g7fFD;$#~e$I+6I|P{f{VWo7vbV)tOH?Cd8#Jgc51dN7vY=T@KuJJ1HPsh_n@k0Cnp~td8dG&=;tLt)yoE|gUZ*U8r3_b zu#sUrQCC6FzDGRbW-M6L(ca>d+J^uUjc;G1NX~m6=bfX*uS0td5x0v_TfE+ubKMs4 z1RCvwWYcg1#x9hDdVEXTQBi>XJz2pTZ?CtdQT@)LJ6AKQ%uNH)qf`r6a1*lxyM9fx z=dtvcA@UnL5X4WVb^LuRWUHla+4>+4BU|PU<@{RYy7+RI^s9cd0yneQSPVtL;A(xOupXI>7W)8OBPkS{H@b=zPo(JSP1 z+k2<*N?3QCC~$3o^U)9c%*T4&INbZmBVWfQS?e6T@qS@onYRaMob4c1T$`Vfu=t6IXz zM=Y2CFgrb`q6xwjZp)Atbz7fX>E=cAM0~sv^QVaouA8`0M?-bTX1rz~xCtHzDz^d& zH;uZSM(+PzgwF$lG?aB)mhiX>*fG6MA_GHf$DT%Yb;``OLb&62Qp52fr$(B7?CL~D) z$uf3h%{CPpWf@~FgPE}o#>{)__x>|;&pFR|p6Byy_ug~oo{4TtBz&y9hJPi!)Iqx* z4O`WQ*X5ywqHliIwE%xF=Ctcu>O2-jJCXw1wRr&va@m-tu;KOJjZEgLVUqW14i^Mh z>DhQTyIuaSYPe(dT-^r)Wc!bJe&mRq)B}3EVLd(1@>0aqZ+ACS+~dt8q2*lXd+lcM zD3k*}p`TY(85*1q?}u~*Yt2P%n=MSL`f^;HQSLb`^DlR;TKBAXLse==dx$|fCJo{? z+jU(S9<*r5?lASM^tRZW%1x!T{Ve{tTLn+^7G0(=-b90+-bdg;1w3ev+ zxiY>zSH*^TW)Lc$uMT;}SFg9n?vdG-MR9ZbQ;#?OPNE>oQoP92RPc`fW`_Kb5bnxA z__q&8K?*yU&lI+f^Eo^!^J{yJHF;BVLrL4^w3Tb$AhUMcX=Jie$bUl(20yc#{pS;4 zRc@#vJR6-SjCjG!zzE&6b9~2ABPCI(KccW|E0A|55W0bSh1q9!JD4=mhSk;g)+b&u zu#~l?YQIFp``67;9FnJ4{DV?yZ5&Zjx1+8$u5%gFB-aB^`@<>=*}c1herjJj5;URg zIk)-zk10S?;gH{Ot&wPEkS7c8o5Ibhn7xLheDoEfT<91T^L)*hX@weC zfF9q|6k68O81Y?+qQDw`97uvPg(fb~F@hWoJ?lAU{&d{qWv-R*8*wzF-_iUVqOanu z!2*5x0mq{^BZxqM*l^tPK#lgg!yrGsK^##&g3zv-iH%I%7uLF19?iNz)=nLt57gBZ zA|x+cR5J5H?cN-onpmfC)U45@kt((iRf3!+9upkqZ$G88?T-oHKVMf+6I2wkFD#PMlh zKmP+gwu6`F8bwRzHgonP@Ad}i#|d594#R6bRN3sQ2@`ss!oH9rj!RzSM;}&)uRl^7 zv0GQ+iwF`8J+_;%6vSq?9HTc*^LstFtQd*fP73#lrOA}Qr3x!flATNpu%}-f*4l*5 zeCgYN-+undB$FoN^71iisn|A_wkTI@bXGOt~aQjd$;0&o<&b+?g`&QUAlJWeq*)KQU9pwkG7P9d-SJGkS-4M(;G$F z&^*M8HDB|ZXa~~all}Z4m61si?dxNQE;5FF<5e#Ta)h;^jmvU7D^1ZXyL;05Ro8d- zx@w$1Ql{cYnFqU;ZEIg*xPL?A2yOfM+pP5^lW$3uX@e_)!zDHITM?0k>h81qDTLR& zeTn;tJ}ZrSyoYD?i~WM4C_Ix5{D?Bq3vEVlToJ8UI4VM5(7Pk>VZOzL>QE{-q;Y(? z3T$qi=ZDZ?T4VQb-JI_RcNGTykbAxG*%O~3?+b+&B;?(d0WLk2Ny z9d0ba^1t%FMzQYaekhzTDr$nk84heDb}9nXxVpn89yQ;@*i%}f6PkzyTJ?~f>p1Lf zx_we4_lR3^W9sV!>Z$FP)4Q!Jn>Pe{$DbbvL{9gpk8LX09{~l@JE&d$GjVMq#WqsZ zuJ5VKbi*w5zKL=L#%rQ;{BXu42&ytvVH0X`uRCywE3Isr;Py4=-u?X?0kbRTWTBcwXz(P!H7D9iwynbpQ*j99p>^?x@w9L{Hp*N z;A@L&?!Mo!Cu~N3?NSnQwJvMezq`&)PamtDUx@Z{Dx`=l>^(Fro35Bq^I1>Uao>C> zHGl>>WU-`D%9r{gr zbwyIfHT0tZzevxy=abKzLwZ{S7_R+VoISca_c#gjDo= zIXrzVdtj9<;(|*lc3F0KC)7#QLcj2de!L21**|;ujtipCWr+MaAS9vW_9r*PT5AiH zz+cW!Q=a6jBf6}ztvuvveu~7U?lzi{qk14J-V&2CK-3dg+_+*WmRh1%{pFLwDyJ4?JmaBZL`_#>s8d3hz#1obPqaDYTpe2< z%4}LQb^df&71)`~$%6C8n==p6;OAfaJ>ey;CX?)V2W`Y>=wn=K2!9Hi{WN77$x8d&OnbF1r=vS$&KL+jvmlbUBb?rrAE z#U4~K^}RBy~ye*I=Zm zA(Ha@Z2?of<>!Jw92dDx!{$EqY)vWJ>5O!^IV01b=>JBp=)a#zflI#2@CYAQer<27 z?OxbrWj*&gwYFBi+2dYg?U_LxjQ#tOSq%|UL1ve-imTOmE3$PugKQ!fe+s6&P|C}$ zn2Ny5)+H&6%$r}>diQ?!v-wx?we(vu_j807CD+nJE#56>?tMo+gSaZ5`Sa4dRO;0W z_114&3X&N6-j+xvWxw#jhbzji&nn;QH_ggr&pWwzgoKscetiu!Y;W5gS+72~DV>@c zwin%WJ@{#!j{MY(mxR|{W=?^Zz0IA}N_Fz3Ze-05%PABGeDeO}ryyPPe$3`%tE>O8 zClhI6F;KN3JzpPT>a5#8@a|)w{!ad4-at5e|*QMGShX6c%(t(!GPCN+e?=bhFE z{ChN0ht~r`TUJEE)_G){wfK_-%XFvEqUKU7)70{BdbmFd(wd_WN78S$MON7UbbtDS zW94dt<4=R~kTV^FIxe*LSev7WsFFZc#6#z&pUrY-{*3mPd1mtmn4?qG7g`mYljyfj z7Mx(?xWU7B!NhV7!SE1Q=)BN zcB4XV7hkvgyFRxHYXh{0QeU2(;bht4_a;NvTt2bdYJ6XeDmMSw{ylPm?-D_ev9M#U zK0W;kC#;5j2eL4t3^kLP@0$FxU39VY;9dBUt~{5eI({AF*LJHnk4@jWZeP%2UYz1v zI@Cpea~mNOI-D31?K1VBqH+jwc#zld%MAxreu!t5h5FBPUv8{ySl@IL*nanLW6W#b zY0>=~-$G`Xh@`|%e#7{U+ZRj2gFcjuox@yMS9)aK5qcw}HeS9$k#qJ z6yhA#H^plINBFaTF%OewmA$ytWd1OVK~NHsk?Wo%`P?ao&>Nr?ZTzH$tv*AzQ0MmR z<;MHgIn3KGHn7F_TO)qx2c73~%r^PI%FIo~*Z4CHY}TwWX4|cp9C5}N-tNvY@;=}9 znuKO5t7!<4Tf9+aj+)B)j7K4a5nU3&7g8r+t>V^f$wkyZ+w!LFNylnW7Hb|#=1s0C z=JAS%wiNkG%8L*FshiaQnpT4d*^X3iYbxBc?yC_@c^$;|?pOW{(&S7ql|20n>#0!7 z+ZzGj;;y>=p(}QGQ}>!51(Zx3cN68KRw6ElK}M#Yq~W1Y7iV~dYiqRllI9h3MSAB& zA`|Rn3@zn^cY_Vu6^vkexe>{_1o_LAmxp3CElybt4n~fA|J`d*Sr*PUBVNe=)k@gV z{r1<9u#`_FA5rX5B4&Al#xV{@`CzK0Q(C1gGQm|WXCoDd)>A zUg~o_3Qg*AHdIuk#`L=>*fbp8*81VmUUNP;RCwj826AF4DcH~Vv{2dhcN1-g`~`VM z6@R`V<&bO&iDVvj16u0*w5Si;?cY}zGAN%k~0{;dA$4wOe^J?ei^OL(W8!Lp9@5qEm{lR(dr-t0i zH4BudFK2>_`yTXtlK7)LLx6Jds;z`-zWp9Ozd^>ZT;c13ijPI@y$_22%0y%Kp;%h# z%pd!BxNiOV>qi``kT5a-+`A`z@SqCspsnV`Mvt2L`=18m55|!pq7>m%2G71Jr*HN0 z>WKaLBz8(W#_roMTN#RO^4PwwWB%7KS_y>inF7e@_22hoA~TWq1*}@<+pD3-#RO42 zgukEFUbIi{{wLmQ-5K*^=gxhDI}B}NSdrB=M#=gA&AqhRjg+Zx8*PF_&vboys`bY7 z+ReTe=fIH{r*<6#Q>PDHe-T12O=XQb&aTN zq#iXrr4k17kf?Weg7@+n*nJI_ly}4S zBv2LlJ5IbQ_ul28ymy3}E$qpR*GWFO^2oDFGp44+MDE`e7p0UUjkC1n`+4I8MKMn7 z!tN{O2=yWI7h8K8#Zsr#C#TQuP2_x6VNeY#Ct~B|v+_hWgB63m8zZ6at|G2tvl>`6 z%#H6sr(;qhz-0@0gvT_ua_n0WE9P!ygqz{{o7ZOpQS4@o67E;dtC+N8G&v1uh=1b2 z=Ic;?9+hk}3sI~VoYZ%TuX=OUKz)Ock8i@+FKJP)&>4lXpIh6XijxZ0w7IE1u7<&r zb>B6T7nytmJb&i%m==u^>i1TAn5@X7FIIj(k%;t3%i97cHsb9B>@tX=as$~8gjkG3O9kgby}Hrdi+JlE|n_J|ph zUnh&`K9UwcsjVMZO*)l*kNVqMFlFBw`iucLZuKydquhlMJ}h`3m*2ASa|X%vjud6J zLJDsdZ7oUUX{$sF)_z-j`D#?_u30(LR&q|s*jj}m=|hQnxY&BL%C^l*2l&?qDAR&3 z!L7yL^u4wBx%b=g2?wE;ujxNErfMLMEoT4BAFW@OsUJ1y;dVJ`y3rMHyuQtiYun=ckS;O2hGq8@5-eKg z^*Qq}YVsb^ww`bo+xvGeT)1D_oUSrF|Io)*Cu*mrTW4}Dwqz~M1>0|pT%(qmPsB~- z*UYnBO1|3sp3rwgLdC-Yri<5WElxDDTvcep@@@wg2d~&Q%%7riAn0{fymD)|G*{03 ziKg#@w@jh?&>7~SRjG{zbz=$Azps%9YSOx?-*MP-DpDjbjyX= zo?$ka3@NBzh-oIK<;twsN6X8ze|!~M>}UD=9gU&=A*@dAB9qRu0tzMeLW$Z1CDErwzL^&scLy3mx zw6taR7G9Li7QGFf$m9|;rL=GABIZ}mc(B(^ISihzyV%|nmO7lYi21Nt*)bmWQ{GQw zXW2ETV$=8XEUcLB5!2v$cn#aLK^zNnoLz}r6QrcxgDLn0iTd(Wi1#1@p(hD$ZH7^Y z?lB?7@UCt0VHK}-S9@$JO}zSKmCNi(xLW}~bOtaaT)&rniN@s9z5mMRIgHL1BU98$ ze@5A^;%{uC)yDO%e16t+jJ;BB%QOEy%Tf~3-+qNHW zzXs@X#;KEMH&pzBqQ5>E?QicGhsTE110jV~OVNM7eQY*;v48syUyLKuqGKu!UcGb% z^Fk{2RK`HR!WdQX0T8o7E3dl_`t5dYJmSGTmx?7^5unEcy6^wy=ht2SHy&0bo=jzL zxiCx@2H%kdujxAf^lN`uQ1VZJMIhJ>hH2*QQu{41fvbEkn`Cdk(5IXMG|<3AtK%fwSF7Yw}BboyFM$@ zE|1GN>SGKoXTZfreK&~^#(KnP&4qpuZ2X0(Wbo~1A4QqZ@+=h@&5BXGEcvxqh3VJd z!Dcz4<#AZnDZcBEGCC?nP2!nmUL3Yq&3aIq(^uf~kjL990*yZ_Cz_eot9rc%k%b3=MPbb}tu_7u~9-K%#9;(3#e0N2=Ic<|TU!75(a+z7;U| zlH_!IWV)a3Sqe7pamXzhW??$^t9To~#O`r7?sI)V%N{Aef1jHG7LXld99R7E*&;Rf z|L`?J4yyyixD=|Lj~a3vzB=mDLqmxBY3!@9>pzdW8-p!@Bz8E)YICtW6;w?zSoSo^ z8>d9AFwy?ox0lFHoG-mFOIw`aVxo!fvnGU5uIqGE6D?SLah7h|*W4k*TLT?RT@=A7;I1)f(Mlt8fLZ31VY44Eeyanad!SI` zL_IhJ22$w_vR5IUNYN|lux~|M$Iy6@4IW8snf3e}{V-=d%u}vv-&jB$d;@Hzz4GU5R;}46jLsl{T3{Z1; zsx;{mYu~(hXR59!lju!E$kCbVi{JJbJQMky6@FFB-9(Kv3vr$&ESi&BD?WWN`A|j%ti^DmNSHuK*H>)QSRK0tn}$5>6rF+DPG^8hKMCQ z*6q&V2DTQ_u*#0%3OX07Pu-_5p58m&U1cc?+AD#Tw;-b%lx;PYR2YN+4#?mD z@oe#b^8}J$5G&Ov_)sThyXM$Dwhxj7LtFkG>E{qgr)6^US~GZ-bzVf$c$?S>pdWCHJpL>R(0dA~Y~OmK5J1@r+2^DuD0p)ik? z`Kt&)H56MAjkd8JVXU4qaP=|46{X(5!sKcT+tOQu)svL zR7`WiVP#xig25txH%%0s++7#|t$`+x9MBP_Y85j1G(C(LOBp@o5hH#JX9qK-fW2t0 zu3QO|s0rbnFi2 z7Vo%5KVB-6eqb5KT+^Pvqi_>4pqFrnNQ%7nVxuad^(m#u$#Qk`K2(y5mi4$22fNUi zK+<@Q;6wLuA6TPnSuAB*3j8$i$L0`ekvElj4=SFco|4qgV!F8&_qy92*GqhnS+sSf z8{mh#3pZR{>8HJ6K*V%+6dT?H=*Lt;yhc%WwL~E%=Al;@VH|I1nOL5KFWng3ImAY| zYcx0Bi>1Lt&FjpR1w|Ll&gv`K@`@ylE{Ka~X-^)LF`g@J$(_jIfhxt(focme8_wM{ zwK-@)rg@k`&F%^4onM&y%^3l5#4|gH>k&7V7Yn+h3?*P0B~)eCDw#-CeED0$OreBB zTeQ_>xU8l44$ef4aE2zQ#eGmW2E{Wcv}RF?^s^>>WuiX5EzB(AJ&20K^3XH$z)K}@ zj?WDi)oWnA&kgY7am&0G(O>$_DA(tr1rrhh*7ih_z)eell~yI|u?^s}fv3S_H}UPF zDa+M}w8j+eIyf6P6N@9C!&x0N@4sg!rC4`K@^|5yz$c*I9{P9I;&o=rcD3pYS)b+-F}+fGK%yr4IY|=T{4H39eA7pK=YE_ZFqEa(j-|1h zxfJ!ZD?~g>)>3BYN?aZ*=8TgxHCNU{0L}bWA22PnTt!GM*`gydXzyqTi|HMS35RRl z?Rlj3d$cQX*{U-;JO!4&HyQ9zt~dlq^@|2TI%7UiDMPjTwf@#=0DIy9Tm0(W37RgR zz=FH9X$kbaygKXL2Z7=>c-S zQadmn`W-ZH0-XH|*P=)_ZC=)+ATIi1sK%GP#@+E^_qlQp2k+*h=Nu^@d#5j1!?`ut6snz zAnqI!5FY4uY5l8|J9A|yO+%RAbBtF`-*QhU#mR*mQ8w1Iyq`r5yA@mISc;GD-j>-e z>C9s!?=>xw!@N}uRRGOk5IJmMfa26{R#JG{N!tI^eK<>1*|rST=d=pm=$^rqsF9*Y z9@-hD96v#&91^7X)t@VcR`*eHP@_R9s?1#3D-zdp_$w0YSBTE)}qIf~moW=5!EcI^7yQo~2vdJbsbTfCMSttYkPaMLy zF_)CVn!}3a^%2W2++60JDVT6%rROfilSI2`u2JOT>`u&N_(Abo1{am^t11oaAy40 z;YAsI@UIJ1DH|7#5?G-HeiC@k6NSc<+_*dzXd;OZeJ!qx$1slc2z~H!KaUk+w(5?? zNKai1RmbneA&eTcNDBAqGA)o(6FzAA1*-K4nm&16CciDGTq;tVY-LGdL1RxuDdRcf z5Puzwk!eXI8ND^U76-P07eoJv0Dk{-P#}O-ITIDkO=GL^l>)^ep0$h+0F;AYm%-of z=E^(0SiK^iOrcT&!xM_J2=YQu3L$<^^%CnDJK8qeW|cxgOc>rwbki3oG~z&3;Hnb zfTap_FN5mxD16;4REIozUK>ttP9cSLx22KT(0MFXlKRFJ26P@k6Xpoe1cq?8y(HP9 z1-V6~Bh~OCak#6YGI(Q))Csw=K4$@Rwtiac76 z6=zDVK6S&zvbvBo2`pxT*#kjF?7J3+v!K2`(S{)XwHWyku;PvfI$8>N)9ZQbQxYKo zcykNhkVT3}K)9lb5`T5$a=Ab`?4GftIH0{)EsGJ+XY$*aVMf|;-1K>h$1gf7mYbe@ z*0;MY!Eav_SPjbRD@{EDt{-5Rf#x8Kv+CK`=yA}?t9mTauSgbXh*-We?;;mBJsb^@ zTDpXWNa!b!`dGEN+fx3z^We}LjgZ{=6W8!<4?!w>-g=cX8V7uUVD6W3`ipnVAW997 zxuh1zJ98O06a$P8>Ro#_X}i0vkVIsK8By5dv`)~(!KorTfpiHClWs{MMRSXa=SLym zW`>v^6e8Yekr z9Qqt6m-;t^d35Q#ZD|xWD~si5v=%qW0yRY9nMjSA1|AD2=K58NfGbg&s)SZx!I?E8 ze#C>Tusqf(nU>hGXb$|=CO=1=Pdoxe^ESBg_90U(LI z(8@UC8U3rF>>%3cdBAQVJR`{D4PQ_>ETGJ;l95~>M`%aD1p?IwZN)-=4xAdoU1&im z1Lt4dFm0C*-A*IY(kr6I20Obw1qiR4csHb;nG$rSiuZYj7@mOsE_d2}O1WUUuy6ewvULl2aDnSi-1S)K^_3<}u|0q{+VT1ttz0 z%uF;W@P&(5PQu@#)$ex%g^BW9Dqd#1ml(g zhg@K)kyF`uDgYI(4Q8IhN`R3;l%XIXOCoH72799+WR7_aA1(>Tm9c{7snHh>0t*1^ z!Y@ImL7zOf1d#Ef+D-tyvk8fyk>d|n10#Ic9KhPt4=x89ve-XBj|)zopz9z2eyW?R zi5Xk+50Oed0OIh`t;Y?_Wo~R^0K#(!3Su;9(IH9`=p7PRzzU#z*}er74o3C?qiOjU zFoCX)AWgvA06PyDSq2y!nPUcCQt#&4cR~KeSb-{JA;-FmY})|Y?oP|Vnu2}?tpD%; zDuBo849(~(&B+lEYoOXr0|;4!azLEmv<#&51sDKtz)xZSn!cp5@CZ3pv~&9$7%y^K z28uEJ!<7IK6|4pr2frufoMWz>-wy{`7MbYU>a&Bnj|oD6cLYlLF@^qkXZhD(pA6Rl zuB{n_zn)ohngnz6z)xo>7kp=b0SPXcAZ~!*3UV2k3NqJp5^zz$S^%aGkbe>61i~eN z?x(O)U^}!HPYor}eS0(_i2Sh4j zLx6!)=J)@aMixl~l2d2*eL&+n5(`FvbGZKD*##Dg@Pk9Txg7eo4}nZ0_D3H>f#df7 z!_tA-iHrM3p3}ANMI-;Zsu>jpA{lrm{vV(yVE)zwf+=VSHAeA)Mj@dOG(h@*jM*1M zVu9rW2UZ~W0TKb&sVwiyfrdH~0ZgVcyMO9A z$SDLsVfH^{{ug$C zoK9fIPck2H&g&ix*TYUX z`WyvecN8gf-gj0vjS&8ofHF+*g8r648RmLvflT@l=*vCD7}7jpP-VPM0S zzsd2R&hX*|m0@@87t61%AYbIE-zX=c#&rtoFND|M(jkq71Kq4p>%g4=)!%woR*VJ*pz?r(W|Szyzq)-LFbzgx{>7c{DPZv!!krWJw#$;ux^w139GQ}N)EpTN zn5*p@Rh=uGOVWAjuteh|#kJc@6=^JPIzr+DSRS3P`Mi`{$Y1YsVlU}v+eUxI*hQ2O z9l8eHuAw?ny+KPGSUl#ifG^NF<$KD< zIYPt@^_}(_-sY0~ET=C|S=h@VZmcDzv~t@G|2L_hZTZ10V& zAqhsCh~wujOMW`%KX0WgJ^V{C6IZXwlfajJ_P8xg)(Gx!FYt!7fJiAhQk{HB#9U97 zIahc>pxiR+Vu1mfh8gRolm7zPyHv|JJqp!Tm8Z?*kI1Ag+PDqVtI}I%Qb6o`dx0 z{%B)9L|oTj?&;^|vF@VIA=^)`a4LV6RhohL{4tqF3QkV8 zOWORw%?mpmM%?E9gQH2^e{op;ddEA39y{O3*U;)yw8r0Hu=H{duf1tLwIhBwOhs&I z(bFZR5P543do5+E()3TR(arB#Yf1DT>R>00>sQdn{%WYCZ{B~=sFAOp7jItgQ+UVz zd!gf8IY|c7U~$+WMO_lFd9|_Aa8$t6+u-mt-JIx4Dkj4Ba=aYSRc{a9n8W=CCBsIVa?` zW!$njqww>U5Jk+>(N;b3g;=1MZ9tRq=vNs99l0R{Oc}cuzI4nXOM1jrQRdZ4C*BXg zI~88?UcS7uJz_Cga_6WPeHnenjbOm*5VuO*XPqCdj8@lp)LjvD!6E#}+Y6GGl zOqKX?hl&%mX~X;WLL6!1eJRmIx0Cd5i_q$2-z?mg_tm{qTEc<)TOAwNXrlq#>#Y2@ z^YpB&&f8Du@19|(ryqUtz=3oRFWcceeRP{+GTSUW#wC)a7)EnT?fk_vNBz_s`K<<8E`6`JOs;I+b6C%P-b z>!1aDQOAeW-H#di68o^ZLm!lGroa;)yj-{RTwDuKC8rT)@lppm312$5ND;V8;`hZ+ z56pRBn(ChJGcWD`BV^81yf@UkHBj#k9yL~9rMqelU57tb+v#;rivI*{*_pg-%z0NR zkil{B^~<7tiG-T`50&XHN$43{s(G{G?aLIJuiQY{oG3GLY z`++3y(Y5rGgOv&v10M&?Qu=S!I)(J^Of{kJ!hH&SGuq&(Yy7UPclehQWz zstWc9-v0HWVM@<+gY=M|+25p=;6e}DWhY+wXf5U+`7UOHdOxqXW~yZiJZN6HEP1o) zo$IIWTfKVEY`oMwZ_dI+FHVY>sup&b#)z!J{@z$lBFAe!c4!4m_ms6BZ53DIL++*R zCf56MnTng~wW^(Vq?T7naHB@Vznm*_GTMomIv;j(@(sAn^f|*bL*}2_9>QOi)R?cj z+O^RBNxcno_Uc|;|MmLH{_8u2kG90SR+CMhrPgL>aHv?i(x8_xP#gQ2=?WqmjJrNQuzN=gW!&GBX@jbtEK5P}9P+>mwxUwh9v(9m6hNXR9 zM~i-i^Wh-tLsrbbfY0eCS|%%d1{n`_D95SbyuekfUgc}PC&u#yQ94u=;P)gqWNY+E z?}uyYmJn5+6dl}k>5sHlkBgTzLR-H2#^yZrhTYj+8oibS_j?k_Kyzsqpk8}N+rLLK z*Eteh`l8+ZeS0#D29NfXr;QZRe7=)%!Wn2YR!!ZPS9~w)NB8N`_YgnkHao~?3r({& zDeB(`uia;s2pOG!U&xg{FY8XH?mX)6d9pn~I=RK9Y`?Ode~OGHin|}WkSyH~3tNS- zMCk&~A9&=o;2R!i6m+u8DT9mybDZ>RTsXR%A~}325R2&FpJ~x+YRedR;-re(9o|cC zaF^U!QP&*TwMHw%yO7lb7{g^;~d%@qSLS~u|aaO+ejsGN{! zOEgwzoLsoAS;1qXNZ=1~ zo2Y~wTUx&G)rU*pm`1yLRBQK?*@zTz9x*MI7xjHd>kJ0^NCGG6_a(naiG2(l*lu&i z?!6T-TpqnFXDW%ZUa*O{cTVTC|FY3PoYO8J>>%L_ zFZCCl8gKk5E1YgQE_+ym{7#HNgtYsfgGW_RKf!a0|EQf0gKckp&_Ad2NMv8H^j;KV|_RMYrONz2YoVJcRxI6Fw{?)G;lvjg((peEiFE_!qIThL z?V(1)W&#GCO6@KNLW&SEX2EwGzY2@SH2J+I+1XXCv7O&TrjYo7oxqY{^x0@m`d-8YT{IB3yJpc;Rk6qCV==D<T=CaY-S|p7in1N=xDI0p35Xwjf}*_ zkdHasYgvxk(3(H=*o{8t0)CZN5~@LmuZH?QNKObDJvd1;(7V?XNuxTFMJZeDr>oi* zp)YnbDz0N{D8GB zb@BZm)*>7QHLL`_F-KcGNYFlh5CyycAbZFnGkDgOAPoMrBNu3}s&$sN}Q`ujO{T;cg zKNC5%^@Vk~4-?IOK;_!juvS?vjowmLg16mlYOUbHSRGUsE!`=#dS@)8uebRASoEo+ zIQd-(8w=`Dj7-WnE@zbH^B(zJ^QN4)WZU~^6}Uv>UmoY@ccNOnlFcI;t!* zERh`JD+ufNkc~IeLZbpkmuu#u^}gT=h+nDBO`FlW(Z294Tz>n<5PC4Jsoi{YcUezu zFL4^-EM~In`Rw(`tDo+z#hE%im2EOA?HAz^DYc1_)}N3z`3`(qWo9c*vHnRKA;S_X z@|*n{EBYIkL%-{R)OGN8ad=iUQdTpvSX20=r1nyOXku=(a_W*?@=V?k@i06>^1G(& zIyI1V84F)C?T5oe6O7T8qyt0!??I6J-+O<B;z14cs~6SRrxYn_Jt+ zcQvCr=e}YU(>H>)hp#e)@=Gux2CJX_bv@pvy}=D>4cM55pR{c~(-~jahB9}>n?sX~ z!4>c<-@FYdgTLBVKgXhi+%%`9YNo!q%+GBkbegnFKDE0v#>ir{EuBy^^r1l#h0Iw~ zPU!s8yPL7v?jHee+76w02G#DaU1oo3Rlm`!DH3${QNh)elMClHH#yS0g7=j%tdac% zifjWmj_Co6l?$JX3O%(|mFywNxxM2S=066{=?&rt;Rr-QeOc=%oY3RxpbyRm-d|N# zl%w`6SW}98Cf^;KkI)PMw1aJ=togp0_1MetjK}q*b1M zQ4~DLUAG!{*Jya~`VJSqwvo*HLT#s^NiC3=e#;SUQQ9)q;WAS}=v8cu#mYwR3H&zm zZuOtqRL%u=`fFLlejBL3U}yf;thN=YH*uk(cwy_j?I)DuyBnO8^kkIZE1~{t7OZ!r zJjYixthp>^%g@@1GMnFGGH)`$Kv_#frry?4v)!3qPR zLh}?Oe6~YFK_~j=@CBpo7@wBKfQ;mTuQ~aJyu!Yj1m$o9u0WodCw(tD7#1MFEUn{4 zaILQGFQcSya*V@y_lE7i2&{`i6&h7d*4xtTtg^i>F17})PA(*Uyjya|##!9WzH@3p z(J=18jOIsub5}*JuWE86D~s96o$vb}kNbkZ$D6X-@4kJJnP`13@044o{}=mHBF}7y ze@+e#klvlP_4z^m(Wal9g*ZK=SLNXuW{G-mk2kyyO0s#n z6$3W0uQx-Lz`sZvZ8Ij-e0;2;Bd72+Ee~(5sa$@+`_ST)2 zyR4V&tC>Id`0}{L>{e*5Ec%GLy@?lIud&C7oMfxJ*dx5x@I1{Ikc>SNXYR%UWIqGo8b=qc1hMj-P)XW!sS^O?n;Xw zSap(N^40Y4h`js0IUZ9VqmhnRrDCqc;7SezVF6%=UUQ$X4d<>P_lBxJoeZf9H7T^ktIe)zs^-A^*W#_t;* zTwLwqiS8&1`@ysT|B13HE82|1s^YVx70hVcF9B7<+H}- zHTTq-Qf-B=SF+2Kh6AQw9cj4IGNNF6Wk@wF(8t-eOFqFS$PBgP@$=<&MDHb(a*an; zcK}C*QGl}wR{nSxlJlaWszaZ68(4mGxckg0#DB(MMQD1RXey4K`6_x{x3p;Awk`Vc zE~nP+@eO;8yYHje47G>#ybgA>3+kkaev;`00`~`#ZXcAbc@Y`c`s}uncIfdaXsU1V z1A07J!<+F=LFTzL<}Z&VDtbS5l{mxk*6#`UJ^qCwOr0;DFubm=l0MQacHQp8l%0St z%Erg1((%`Kfd$(mzG)^*e0MHBzL-}3(4ZZQ8X3Bq{!XbKvwQ$AT!z%-YGA`)gQ#o` zPdwbw=WEC3#-UXng$2}8UAUXv70${x1;<`*56{00shOR1`hJp^^K(?7QoJg0g2;9@ z;wep~BY)g*B1{>!XnHTOMMB9VR1 zqV|#(znqnm@(J2`i~tfYjanFb|V!}DZ4** z-ES}cKLDgaTfd@jK}!+L%^~TnWhM6ev#b^Nu}<-4drr2vYwQ@j;_M+v)_j5q5|A~*Zu+1&{Cu{1E-DDHrVSQ=!bI4s`kRDRXa zMl`E2VeX>nQy#-oCz{e_P&r~OEv5k^(?owtgF!SH617n#n$C$X!RWM=@@wuiAVf2p z$#e`)Ev9KvFYD1PYmg>>`Gk;VSyqxQo+@<+DfF*WhtP`tE6x;Vy2NS1&LgjTem@h%pOh}ATJhj_vv zxrJVMDm4menlKrp{Xr5!l0#@^D|St-a`E@vpt?9tgg7RFX)6P{+sK(kly$d|fyD;!^nC++YDD~6Ya&8+TbVHZI$RfL3P!OQOZ{A8rF^k~tzPiI&LJcheXIOcqSo!+BBR50 z&a>Yk^%ta>g7NM^(sfs0rZ5|q`UGGa4A&tT16jn;T1!y@8tu08OKx#W{RO%7TbK>`x6`}J z2rsy7e|r96a#6|9K`&NQ@y@5g_hb=$Wr2^GI`7}0HIgzy1qswyDSA`PST6h~#)4tC zf8azRWr@-D6Ce2Y1|bgd1bAqdga*2VR{WY0PE7%DpxO6+4)MMs(4}Ea-vn5UG9Cxg zf63FO9#8BdB(xMhUqYNvT`o2%^{530>_*iUhq_-=a{`x?m=(z8aG=>V=x9Id=!`Ye z(eHU`U`g7=UZcFf#;Lqht_nC92zbS=L%_d2FU`%P32}y+E5k)MaBNJZzE@Y@P|q1C zxymfkLhIlR-oNuI#K=J_Ipn>;;Xv!{J}uw-z{m2vG|2Z9mIAFe_$V(^5?RXE(VBql zqU;j)-$!|xjsxlK*Xo4VyND$PcM+{FVMcKII^#DDEj7|&aBKoXG9Qc?FiC{9G9rH6 zkJkxN#`uM5RmP5hlL|NyK%HPIpqLgBaMn5;r#`m<6=2_GIDAWic={ud!3E3{y(`$bx(=v&`HTQC0? zOA3>#34s!FnlKrQ1?W%SY< z@(PD}$3DAl4-PatPap8v1)Av}c$PBWlL>5mDpV$EIFL^BKbpT&yi}jm{tE~h|6pkG z4aE;%4qdKshs&NOcWNn0)|=7a>!x(0|#0^$p93p*>V-E z2Wx%zvmEqn7x&;mdgdAqxy1d{u8R9G9ZqK&I2EKN5?iwxFbsH>!`m0Dwyw6vt z)Wf?3 z>e=Fq!X>Bh2P|yas`R@9`dV$M^UMGEBb54&k5h?^i-l$vhEcq^GH) zu_zJ7gaZ!2QtA+zrYXOea-_UlB z{old=M>PIMXMhEO4r@A9W<0HHLWOmZm9mAcAULLQc+n;PfyMJKu}m&GQ-eeG`|JNR z{MDnJZ2w75I`-b+JgKy03gnGr5tcG7STwQiWwG#?ekk85Y$d^OHTnJ_R8zAt>w#4J zyrJ6X|2zCwxYJ$YX?fE3HH=hYC9x(eY@Y-qdqvKv4ne>+dD$2A|5C6`Uc5cu0_z5_ z|J>44t=_nrI*J065ZsK zT*Yh(QEGw3#@JTu{<*#u%YF}kqN_hYSI!t1f^DU9dtmhp>rBjD#kRt^ZQ;|{{hw0D zxyy*XyE(Sb7YCAt!1@P2ncpNdV24&W)8>`><}v#pZ>qnNFKg{j8fU`Zt42?AX@nVb z!N@vr?7hl)jFENZR~z%bO`y-s1^QugrzJ zGW?Qjy%~!oxZqSL%w5Fd54hlbCv3am8H&Z-*n5Us@EgvLu&{5Q(aCQQQXo23Z2LSd zv3jcb@+{vT-am~HA~j@_&<(Lz1)NDE%$0}m2F8ZEz5z=kOxRmx^z?T~kD0T%lWdwv zTZ!0AU2V<2J5KlqA-eU~S=N)3KlgXoTcru0(ECRM6;D>Xpq-k6_bQj&?j$a#O0;`V zCSbA98gzQka^cRodA0ICq89#}Ir;6oTmb=va%hN(7J~Duh!BFjzb~Y3KXOj-I)h9( zv{(L`J@sTZcQVuxO2hwu^!vj9r}P^~t$FaxzcGEXzY6Tvd%8Nbe!Et8vgf+}%HGq} z%ud2$!=l{0c+Z(Zgw=V+KSJZSY4oDjx84b>T1$tSwVu+jw8)~aZ-rm_;L>4GCxDC5 z))~nCJ|ZOiZJykd{<}x(U%urdSfr$XCC+*)*8iV|y;}(hEzs7N=UW@Y6v!!J+RLP+?h2!D5PAtdCEJRi74S&66o-E&Ly`?t`) zm&RQWbW`?zbaS-5@7-Ldz3c5EgNbMh6OlzP5Op0E2t_AOww_^8TGWuI_Os?zu%EP= z_LCW-ypC9$p&S7)%#2EgVU9{zv!kOQ5EA}1!q2r2qwOdBAt9mci2RPyzsE%W-b?>} z;D0Vp>BDGwF8Z)edB*dn?hB0Nkm^y7hYTMm^Ak`YiIsBBW>{e{35z8m{Apyp4t@S@ zW7=`wZIKqIw0x+XH#IZA&!JpCb@$xHxqPaj#rqtZXMr?l)O++5*f`sn3N_ScyY?RD zdj)mz?{notq%kI+%JdOWODqi*ED0!d?ET1kH)$}}B>{#0^M365U+g_=icHvX?rtvW zF_Y7Ko%6J$;TU^&nRNL?w*RF2ER9ziL{XzFG zEE#rmh9Wnxlta$aUF#sCXUMtKNZwa|2)~vavmef1;eG^rtBHq?L{)4nb@!ohQ@ny- z#RZ`uxUw3H<+$L?kc|Cq9`oBT;J|2tZPl31Dg?=3$&k*vAO19}vCqFxjUfoV{)#2T z8|*Q^ls*1Y_xNiifAv?mU4W&dF2Y-b*jDOk!VWP}_Cr%2-rCV`>XE}!XEBm=WF>Z+}TuO#ubF(aCa4}#4E2BggRGNi{%Ap zI%n*6H{rKm2#hASYMrh`Mt0+DMs}!1_IE59{$>v!UCbVK(;gN?+rPiUJ(%|0Hp?1h z-Fuok#7I6ZRuzd&VIEADAvAYfM1gZY1l{4la#uN6 z$)!?ln7e|YubZs z_RzR5YaH78cK!NY0QyA;&3!DQ-{+}!fnVn}Qq+`*H1)RpfV$G)=VgSDY=6-6o0KCo z1r_@bxc6bn@C1XgcLBrPm13ri!=F()G5QvD_Gx7=zQA4#oq0=-U&)*IlU%+mSdRJI zOLcz5d%9W9=%G%a)XX@U$wXjz z3m!K+^g4&a-_+=D%4W5{$8NH}Au;`pWBuK#^!LvF-Td68@lvr^G`)d=Obb zU}(gs{dWeV_6TckX#YBg6eJFcqihe&4dyk^<@@ZOms-x>8)S7N7;bS}ppmE0=%mm% z_!`HOfskuUbbQz0y9n|(xddY_->2D^uW@KzTdLVFUgOwRW&EZfpH=7!dKyRYQ2S?n z_EGxW`UdOsk=HmBKB(e-ra|c9hlHr-D|Te>$WO3$<|^;>QE_VVrkppmmN#+q-;Not z(Yz>ScP^jvT`u3}@Z5fo_0TTLc~iG8@ObP#YNfk#`IN)ueBq%6xqQyA<^06Gx%~a# zQKg2SdqZ#El>Tak{-I5^($D2n4$(fo-lXfJoG(1A&>tV6e|r>t$lIuW`Gfq+!8rbd zK0m#&*5|o=*-5ISTs~!AF5l-ry!4%7jpcl@OE8x6$*lxAml&DxqRv_&ttiKpI;Yt$>mdj_1sdT!O3Fr(1Ds+^zL zap^`5sl}2KlKp9r^BMZJ0gJdYoms@R*O*0gh|q*_NHtQVXxxwrz{dWhYWzewU-&20 z$nkQ1;(w?%a{2oURiKSFa)@7PCWM6UiPR6dm|sfWzJiK~)RWbk6rCh#G`g0pNw9v@={!ruLiI$+r zPLDB7Ze*_-?%Tkj$ofKg46}LPRKlF*)D0ZS?x$Qnr**}8%4whdyp+R5BvN)XmruPm zw|Op~O3k*EUsYZWFM}*of1i76IbXP+%jL(V7XyKml3YHgkXi_}gU~KmWs*`9`m$Q9 zduZ44de(I~m+uo=NQ3J1A)V=^mBINoo7 zFS{d5cz-nxv}%BPT#o$}{OV@(cUuV`NTQaxbDTxo$4)w~D71K{@;ifAT9)Ch;@nSp zs}gwMD+nQ}!@tGf;k@cWRWx^LrmVvG2L_+9Xf!F#HM_YW>}d3BPzW#;l~qkF9H zfM*VtMrVlaCluxR4tRReKUTL_&L0SjN}=6&OEbKGWMV$+inogMyuk15a7TCp)Sa_a zaA0(X_XK@-aCQ4|Dd@v@z~iQLaz!A7_A z*_f`zzr*bL#A!+6^;I@2R-@n9VTEDv!AX;{o*OYyKvbO@teuqe+V zn2pLOs1)oc{Mt@Q$_kw?jIj5GWLb}vBnjwi4*m>Ui7UW9bY)rhIKNSkiw^UeKX!;G zoZ?TgbZZMOhj!ychhQv85;#X-O3aDZyl*S@;Be~oeWq`gA%r$(dMrUX;TxL8D(7FD zyj2O`&|2klLQIIyx?s0maETWj{Lm8IqsnF5$3MFsA>`tI@t@DV;wzIr%7px8=sdHa( ziGODCJO9cSFNdSfR|OI-v0N_L081QP+(ou%{5L-Ek+#|;Fq$oQ$`LFoq{B{r`+uF{ zL4N0GOGTl@y#vOIH^>II<3jjD7|%>#sx+(>ioifv_OCSiSLBf;UblO%r}C>l17ki8 zvd9W77O3qy#KnTyB|U9|{Q$7xQeEDj0E?Tir_TMxDOQBr=;r%agS97a=viTWm|W5$ zrfmO7_hFY{*%!K%tb@M+XOi|}?M=#azSGZeXvCLW_U)rSYKAb>Js)b8DZLN@h z-K1{CbUU0ES_N+`EipbA8icL=kJ|7|jo``D z;c-Rq^oZawx!cBc_|o%4*$@4a-Uw*CEHEY@Y#U*8x6FrYJ3}w%*Bjb~8$GA7t9n5~OPaA3AY-bcq-z+-_upQV^PCV%q+A>kD<^9w0hGJM}40WumRD1Io-NlS5H z@W(;|;@da`Bj3XznB+Itu`%5a2i$_mx`$HDS1xy6E!R9ny#5rOwc>by)UPf?~3)QrU+y~Rc>rHL~Iqtjc=xum%! zI{s+j-<_uheisd;PY^=9H&W;BVteewAF-6ChBFhEo`UzVct*}+?_n#$Tza7*nnG@%<@<7 z)zo=i#b3OIMknlg8KmC6;`xg)r=GtiwZVa$rjBoZXKcH$v@>lTrz!Q*T*-nH%4A(t68jc4jybSB&(Vw_sC|cuUazIlZ%gU7 z1vFC91>N^ku4F+-q5Br2J6NGR=Q-`5$~gY|ewA`JO1WEn0tdF#gbtV>*MhK ztdC|f*s1@vCPI_^M_7|HA~XsAQ=PwM{SR0BZ%zAet#XFdb2Yh=1z{{1{=lr9uBY4@*O4BxiLnSOg5Ir>QEoS(w#A=Te`$s6~x*-0&+{W3-L(!n9g4P z70W=bTd-vKmLX125a+D|O@9%+zMzEjv{yzg7F%6V5|-$E)et~Hsm)|YY51ym+JX3| zJF#?x34H&4@cq*Xw#ocjA7DH;f0?pw0!zazE=efEwqkzmIvNu4RNEyCoT-r_{KxauoLhxdN~MOl{hoV9xxx^V3wgdz+4Q(8} z&3JlZj26#ktyDj6tGP=a-d{zbt$7qaT+c9tk7@5uQDhQ%KXoM`G-5hpAUAN@isv;O z8R&nGiYas-&HKGRI#5oA*G2oUi2T?@*lS7-kHyPQ@jBjr132u?F)7}QZSvB4ozh~# zOpV1Q^(v!MhIuc$vP=dJ`>^i8fw3GU$fxDiUPxD0BjsEeZN>q{L-B&GSTgtsY!=VH zPn&eO&#wwc))G4y7jvqi=~X5Fyj^LRWj!~+1s9#zb>qVcC9F+e+!Q1$^K0`#TVZPu z7hFrkTo`+AG~!W>J_GU_dFcv{~IMJAMvxKZJCosIj1;NFgeAE zf+f_25JLUy7YyH1_iC)H@(~hBfO=Iu>ttlqSto-CoOMF2YTL7fgbr%^1FaR-qhTqc zGUzX~vzie3lV@2a8+|?rt;d#5S1Qgd>&eJP0miT?H_z$a1-mx!z)7YheX*2fhJ+Kg zbPqZtXRoBHT6Wld6i1ecDZ*FkkX^>R14)ANt2H(r!uW2C_g9BnENAE2!Fc}qI>==B zMCJRJmk{-HebkW73oY{3*pC6n5>r;j0C!ltw5)B&%lgampYx2OOl1$uH7%Lrl!lu} zO1+NjmTUokSo|H%r|}bF7mJmnXo|F>XuhBitt$x0@}F~mvNY4_yYuWtJ2qTu3Z-)6*OA$Mt@v>r74^zq00t?Pn zq`fRzp?+^ETB}uZw@9jEN)i-zJ4s!?C2wQH*>eg@hSOI#gxTQ+)0PnuK9HNoRCOI( zg;)E5Va8fj7CVn;`r z=&SF;tM1|&hg^?fhg^@>`Di6Cgg%!33DpWE6&P)z)e56H+9==0NFEGtW9K53$;X!v z65b9kz_o-BuXDy=@h32rE&)wL?d(#L5UZmJ_K8J#auXlZ&l#uqYxqzemRet|;!r3_ z(#GEdptb#A2xcsn({wP9-mi56vIawIRx9mjkJ}a7Ys3!MPY_Kt{128|KTqlVR%!IF zR4G>0B(!v)>X$=PSI5pDj#2n}e2KM18`!4Ub1h>*0PWU^RcS>Bz{`x8=zUL_C${Xb_E2y*B z#m?Z`WppqJN9yebRm=gjTLy|eilt#j97ul_%9YV(I^HVOj|cwMgoM9f>o8KVWcay~ z)6I80sLpr1(K2ejWBXEVJ?A)e$|Ex0@wQ)kYQs|0>C){W`AaE+^HNhnooMNWZLvR8kuUcz^U*U?l?KxA_1xAK`g?4 z;%>$AIu6>_F2J4W#Akx1)VId*my}I?>3kiXZ{Y*X} zukb%2`v-G$!cyl2Exi9d`tFX$J170OV9I$|z-25)e;#ytZp)`1ODQtH?R^tr4RQd|LVgcS#WfN-YXYppj0z$&; zawGFir)5lkD%Gv0_MWw1$&h?m8RrABNE6(^;O(XaBwt;mo1`-hP@iI~EU5@jOu{o{2T_ zJYUWsIj3$sV{Zb_#Y?exX7LF~KC-YbJpWly1CRJOhvZ!g>cmq#zZN{|Z5hgFo}^&n zeS4WxJnM#iz{SlI5Qe!sahII2P#aCtDM%xAI~u~s-(euq>nY?>0tPNJa*D`nEdNgf|L-@|^FO~%{+HF{fByen z{@pSByX)eAu4l?^nx-LhbSNC2EW@R0m=8w15VimrX6SzPD65p*SnVLKJLNy zJ2^Z*@_EJ#^+2Nw+BlDV{2Sbl(my{}H`a}@W1Z%ED&5eF5Cmyn@kN=IKQ&*b#vT1$ zPkjQ0rDh^+FIHjOD5HDwSa3dyzj?DU^?wS6f${y{5>1;qSS*!aqZ~_Pk^cZy*clFs zW0Ct->Q&f$g4C9}pGIO^MQ^(MT$m@ida-$^R1XjHm0wtJG`1C|AnTj5SSOPYsYJ-jbmyWyY3ebms!aiGo>PKqW)V0Z62A1NghpxS z?$GR2Ug}n#s!~n~^&+wR9klt0%%VJdj{Pf+?R$e+3c06;7IK`sVV3ozKgjOQbEp## znGg@~Y;_yW@tEllHh&iVJ*XqLU0B-DB{?e1aXtoNu4KWVSTgiyikdci1hEE)ci*<7dc?i;gocdvn8iku&g zrSusqRj8m__V~ROf1nX|LZ47W%*(lTSks%@}$Dh&@zpCfa~ zbDI{xbV|?$yh|(z4V^(qZk|glb&40l`y=z2>WmWhp2ZXoc!M+wFGarR38I~xv=z`V z7E%!JD^&hJ4e`Dsw7|Ojv@+jR9(7S14$Ksck%MAV=MfV5>+P8;+x`RY7L;uh77xm| z$C1W>g@ni}X0u3=29D1X>-cbFdQe#xN^L2j9p0?_#Uo{}rcA8nj8_{oPrc z=VRN5IYOG8sBr9W&RTu;7g%1?5zO+0CkY8%s;;p<0!s!v&;tgI*!G=!P=qpYZ2Q4& zl^U?08nC4$wjbTyH3f%KboI3LKzI+OYpn?X7yc#TWBT|?tzBLZ&h$K%GN;3m#Q8?q zJ(G}0ka@+~5AhgCI&->9LUD$4RC~pCm~)pqO((<&$6B|=-X#dRdt&cE(eVTOvD!l- zx}V5>o@BXH4{hHSoGEdl0lPejenY<`T8@CWMrPmO)VnHg1XGv5Pn@ihmy@NPIyui$>=BbA}ODx7fH+ol7Hn=gNt|J z!QNb8+TBJI(F3z}@v5dit8hWp5Q;EF6P74`x?*qjvUweWtF}6Zj$^S9|8y1GesRx{ zH_p@;ST|G8z$eq<>(o_4r|l`=TQ$I&XX*Bbh-GrsqfC##M=3d?&qI$A65guL$HJE) zI>e@_Z1e;Mx+$A3@%|gI-wE@#m(u@yU(P>Npv8ZA?+lHd;0%==+3(iU*TL$yAp4W- zd+eU$5GgkGW0B%&F5AEI=`>EeO(bG3^vQ;490~_=mHbEVe?FeB*1s|SM_1odf3x#R z)!!V9@i*#yTi8oDcMG82YeJ~xN!`B4iwy6BnGEm9T>btE`6%UIT4bSNNOvAYG`+cc zdT&S5yZUGpJ&DmXN7KuQrq^9h?_NglK84=aXnF$~y^LsjY0>l!&eYN47`>4Sy$7S| zg&{pzlom}dC7Rw!J-ttkMd524O>YyUml91cMjr$8^rjq(l3)I`D0+845lA>eviV}KAPUP$K&aDbTqx;dU|tykCNYaQ={ljVDv^u z)60yeSMh|7UYFma^t&*cUK2(yvrhZ_Ku>S~Z$NLTLhtrydS6bDXMZvFa=)J53P$fv zh2D`zqUg<-eiQc6Ku^!g==D|TJr_;ymgzU4-<^-^=$-f#=-sN&yEB^J-pAtUHwIs> zp5F6}UJHfZnJH297Cm+o_}b{{*%`eAh2F+!dOdFjU&(a6|2rB*Z)7yRqq#SMZ?2x+ z+tKu{PLB3}xi^8YyPn>?(e$=P(;Ij*_zpg%_kWCD`4GkbMbisEdK36o>gj!Q1nB*t z&}$q`Z_}eUfp37G-V{dfh(a&_;b{LC7hlYHJC&>Ve~jJ%h29g<^sY_2iShP|o?gM> zD0=Oq>1~^K6Z{U>)0-1b@4JVh{ok}Gexu8TWFXjtCIyv;ig@MzURvU{n#vLsu~_c$ zpf>4YuaRo;x`~X;Tu61~4HMOsaPV`FTwT5h@(+KW8#mv*9TF=62a@i<;#F)doNrRT zQAFl{#EaNkut1idc|^;rraz)j6Ca$QZk}=vji2mRO{gu|{e1!};_aiyTQH5{4Nt8dZv%?g zJyE_Rf~8j!mU|+yTUsN}o>)WqeYL)`rYZAUpDU*I%tmZ0dFExj{|1INj+ozG3hPD1 zGI{=kI@C?zO~|_^KS)S;qhhyRrxFsHPhuuWl=XVnVAOowUQxpFK34*j&SmWVs~SsLCM*_uk0;`SGl@>|XJ_Sa z*jtt0;?e2YrRS&uE}+ zhY^Z{UwIWaVjr;valx4cT<}Mds=rHiepXV_C4N?p0p;>#g?zH3p&5IFCT!d1`2&lG zu=n`&ilRh!rd?|4>*w+#9BAdIZ;Gx}W*opAw(VWo)h@YOCG~T)P7+5-#qV&Ba^PZR|3rkGfw2VlID)-b6Zw^0 zsn|rBHk7SFXOBZJu`t2}y2Q_F+JH}P%Bh&o!?fJ->zFHY+Jf%BQqJqpBS6l1(~JXS zIG63rl6F##AxX@6vjYx{NpRYJUTTya2BYYB(*nz@3*^Lb8@@A=T&r5)z-Z#%!~6dU z7PJrhgB}@|jxZ@-Wixcw9QK~9_ywnU-RV79?PPn0RMWuXPq^|ZRSD*^jyS!$%wS9Y z9XF^~y66(i?Xb=cV#;&G>V7K_DToBnC=?3jG(*obY8 zPE;%sZYvFpFoPL_K{DHnXOUkf=q>Ue2{9JQ#_uJ5mcsy6*&!*HKU!3qJ@US>)r3%+ z>>Af55A%Wk(7@FyscV#79_9n>s|k@@t&R4su2x{1A)|JGrC1On&kl+_`L%geW(8G) zzEnhN!KJ|)gpkm&YmxPCdmp5#tc3ZG2jSZ>8{%8xhP@J(c$y9B0Edu#*Hnl<)Ghc- z3F>W^>`E@U>Cy++pfX3PZFAt7*FAFWz?!%KDuOrd%rWt#SIF~K#DGR0Ffc3cr z#}lzQ!W0_A_EUq_=3Hl5yBR++gwt!y%Ef3+^B>cw{|N7@U0>I)QK9>hy-8DF93R53 zJ$g;iSCeQz!mlk*o*0`bz9h8$nxd~S6PS;#rg|86Rr!u8{|qU_V!;^t;wnuKBk@XV zCN=s$t^x0$0e|f}A#$?`goIArh|K3fUef}y zf~GVN>vDn3L*{o!2!*PvYUU5o?Hj4>7t{7X)Z5;wwttAWenjgw`L(sq{QCHVOsX085)wYG)*m$3@7CoX`t|K=*_I!-9gD?uBufU@ zUJmx22hvk4P%l`6^7Khsei`X_fHv2t)j`^;|7KH@+KTv4_eokk0^d5z=#S5jCPdkf zhW!=1k8Sm3)e+4T2ys9&Y zWbR&NQ%3lAeSM&;$eTJ&ozjGL401mzv{$fX82TS5mwGDGtD7_`8)&<@c+K_UU74fd zHOIsIOD7J=_l~X$?`QW%AY@cz`7;SGj1$%2M&HB z6nv+(huh-nE2BPr9lTG|S4KR2-9{n2eNSEbN*o)lub=Kw^!3Lcz}i*8I&f6|_LWv2 z-tG~+Y4PyR>%bxTVs>44$K*ug?W*GK%kUOi8D8n0`thdJhj;G18s3z6cuQ~LkZi9L z@4I87@jjES;C*&C;9aEPJ(^uV-g^B_$>_TMO^wTDIjGkNSBRku7EQV1*Vu1g+& z-Wx5C&+b;_QCPz4EsbHl#Z|xl>h-@3M%C?q$F<{-ynkd}c>BfRO;qu=V0dRJcxT*Q zKi<*x;l2MJ4e#i9ct13ANbXW6UK$_tc*l%X@IF!uc$+AAzZ@BbSM%p{7*rh3pWm+Y z=k9d98^;khuHvD7`~$4|@#2UduWZX9d7@M8z7$J_l3gs$q%v%sHEdf|dU55MS)V)` zWNY%wjH`bNWk0S{|D$5`?^N~AFi%i0&v4eS|9a!k{jR#>&xdWO{_Di+y(dQhSk-?K z;7wHUeu-=KH@gdU{^s36@Hf_){-zTJ^U?^tzo{;SKFa#AKE`Q%6zS}B z|4nNS$^E0~zrpAqQ|MQYsN0{_8;?$ntUDgvK_PrHye@gS%#N1#pTiY-mlpt5Nx^#e zi2CiLUjI8_WIg$BE1Lh-iFc|iCjV9O4rO?IDtI>yuODx{{&%Ibp8U5Z&407%!b{^r zRQ{W#=D$I}ySKNJ|7OMaXA4wQxS9O)p>JdJ)0DXR=?}x==Ze|6BbJuSfqTs{f&N>L17G zf2gW|hV>Q&>!zXqC-k3HkN$b8e|w$!9}%N}yQ=@MSiaa((Z9WZy!FcWprda2-bV4h zomm&CCkWvcbxmw@*f1@FL{z+10;yF2QZ@4V);{u@#k-Z8^t>OU24Uxv4(f>+9{ zA8)<#oja^<`Ia`L^~^L88&W^sdgWU(v~KyfrFfset1i5k z95MCZU26UJ1vTfBfNdz{e~2Zo8{)|5$H6*T!CVKKB@faAHth z`WiMYT3;;(EBd;XVJ+&xur3;0zkSs^9&$759uNO+%puuYC*Bu_M&q42NWuH`znQ;L z@a`Q{Ki+!B!_FafkB5d7?}~wS;r-JdQ~wWC>;IiB{wR2FiN>qkmm4_-0k(u$e8%QE`Wwx8IPt>XG~XV}XNQZ#u0`I5mgO?CTyl=U13DF+YP2nqj( zSHAO)wh=|KbaJI$_Ch`cwU85brLNZat1< z_~J7Tg^x%4)u@IXl6Pbf0-F_U?#Bsz8j<&tpD}s2&We_||BhPZ{hv=cl%K{pTV({! z{%pWF3}yf1P<~$q=F0{Erhx)RNT*_)R7CqX+dx_uuw?k_pQ^M@il#~Id`t145qUKG zgvsMyL!;% z>d&EtW=|XCQjyGox~ri)&1e`1^~zxTV^~xu%G2cO3K(Yhh;2p>*wIsWfn@H+l40+5-I&#{pQA!w+Lc3cGRVNNa65o zNd%6cPh=c#@5h85?JpaB%qh#@Y#E-1;h?~utrcW_nsS1$Kj@x=1BQev9D^9ONm3sNU&4snB}MYG8LukjzM7l;vek5!$A7_#!Q=cq{E%g z`tugDtS7Z2lA`wKYg_H@Io3U6mE#j~KUR+`f&&ty`4+kBVAlOSY9W&0`p0aWv}ZUq z6Fji@Pn2u^rCm`L1BZL6+jf_qL6D4c=UBoluFdaDNch`Y{adNtzYXfkuAvDqT@L;zVnMDNzG)$) zzLkx(hkZd$dn_4_eiSDbfSx}22ZzEZwQ)iDZPSHA@|M0}XDujqBN=!9O#tqCaLmp| zSoJYUjUx>?4#_k7!kvbiLTmDuU(6x-<-ss09>J2~iER;^l#q30;FHbZh8w?!Q~_g;Z4jwJg>6{I|e8ZsLgN0lHr+c9Lj&3 zvE7{mwx1(#A5xM)d4D%mc_H+O{yr-#mN9}|)t*9drZu~;L2-NytqiPkztBTOw||WK z%Mo`nf7v-T%3qoW)by9v`_}F+Q+liZGE`0ZX#G+(LUQ{%HGjEkTa3S~?x*?7OI-m=dwQW{AKbsoxdCv*I!P-0mIXmV*KU)-ip6e z9ORS%%tQ5$IwwXl?AfgP$9V?kAKRw=Fa6{2EiwLaw49g`mQZ5anKje^8T7s}Nd%XN^ugF<% zGIR*1*C?m9mAXW?V3xn>2P+V3E-UmSc3iUWA54z__)syIWi=NY!m8tey`TP&W4nai zEn`bNY9G=f3$P`(XIxkq7rOw?FbjP}cU-OZ9_)YaNl54^c0LG``=+Z1$;rLq*x6%F zDI4W4QvBd`5cIRO^}DyTk`ppw-TA51|I$YTdw=qQ!T|3dNC*iz;XGg{-W&8%iucfS z%KbF-z2NQ2(R5({wB7GL)pjY$IWKYY>#z0pI`ek$ZVRwv*z!TdRx@hYYA)@uQ-96h zZF@hyoq~K`X~!Y?;_YCU55CW#{P|2Et*?PV=3HTRxvob%yBu`|A$iB`V3&C{@jv$! zhvdJ~wRm0reoVZ6JY9>|4c?C*uPe+PlJ8~s^55f7{!)f-N7Uev2wy-0hj7#?^Ox1WD5^#Z>B;FXRkaS zd4@6-7H?=&W!A-6@v_q0AW<9mmmwa53gZfbmQR0;8YM+HLi zoqe_VKJVSwdMH)1_b=b6BfcMOL-W5BmjAuOq5L&WA#YcJLRM5TdwR2by!g(&dsFef zZ#X8tU+fkg->p63$M?`%TKz-A0SJh6LBywmOzf?=IP z>;JbnmwcgDEzxYf8qL0CQabjQa)y?l zi7hswm9mKT)>|BM4~Rsr$!Yq?RTzm}Df)xfwRmS{Z{41zkJ>xfTjucQNPL?w5E7cG zk8fXILP)lDt2Ms8#Kb=QG6?n^+PbJKI{--+-x}8Mg+wrck@vT}=+hx=m-$wo`YW}mU7T;cdv)=f2zE@=a;#>DO z;>Wk)6yKb#fbYob9LnFo@O^Lz5L~>-@bS0Ct4A$}#xjo~wjN!kn2?B&65jYeVDMOa z#v+Eje{w9Sy{ZJYw|f!dKg#>}C>838E*x6KYaxyG=TXAIv=m)jJBlSkR|=bL$4Wm~ z4zTZ3V2|&j7Nwu&VR4WkH>93V8YD1O3wpD^uvjdAf2(HNs=rq1-xOW_+miyNe|hfE zV%dwgs>Mwii5qV!o+X@&iDz9pN5`}0`^1lD?KZ0Mth9o~v&XvJbUf45tK+PDB6rDNqR!tX zbz8HMRjzO@mB}eB7DmgshvNJ#9HNoIvWd1ScG;#Id4Cv~j&a~6h&D_=wvj{Dpv!jI zZKkd^XM7w9EFSk@s%~h+~n(6*%dlja{whp&VZ{b;pl>9cqssZ9CK*KR&du_>tN^Dt=hH)QlfZ zJJlXPF0@tS$CVJokM}|}U+kvEk8$f`;>Y=0BlZ8wb;OVEjcNVgp4I;^b0~igQ^fPo z&)_*BrT%XhFMgbO<)-4tBfrJOj}zvY_|ZOo{5brg8b4NDVDaO&TmC2ULpR@f|4TK# z2es@PHQ#ymrI`87qL*%ZzVnc|w)xJMGD5Q0E{-3*151YEFLEgVM<)4qnB*%@>*qW9 zSi&sto^GydzH{Vc7)U{ns{b{dbDif9Cr9=hpW*B>TH+{`0<Ju}>bu37bA9^Oc+Pc= z;#`xuFz5P};#^O*=Fq}7)vr4TJLtTrh$X|z&vPihoH2n<0}~(p#hCc6wd%+wfg>9v z$n!et{b{I6#GejsONcV96zxwP9V7m9x+RW3O>C=nlO5Ne{@F%--n)iBEp1b`KV9FF z`O{;qqWtN;TWb2#ugtak)733hf4b!)_|u$|2+2n}NAmG?vH5sQ&7V%ltHYmGCvixA zyEWKT<2(-KUuCMWLqCJNoMfsP(kgB~zE0;)=f(4<%6xmk@bND?p9;S8^MnLyAhQhK zmK@SPyyx0Qhmc1991Y*$!QsMxGvtl8*76;G%39U$@?qw8x3{j-@77Y^zpeK_AGM6~ zKd-N?*Z(}%D$4)dy|y<0(`8)^|1&p{Lvp)TpoeGIawy*j8G5>d>EYEsm>&M!BA)-5 z_Xk4quPvkfPuzM$osU{^b~O|d-6{eszGTq&lEJEyPdg}8$>Jtdk0n?#tXj()@0-(r(prRF1Jj4E<&a%!$orddNIfsOA!wb*TU*frqy$L+&=_Wt zaO}lJYnveC5}&~?DSc6ZgCb_UQ@Tt3xP^LN5$_w?gcUED(KBV4@}723;W%~EUT}+{ z4>v(5+fR63!zQ52&nao!2qW(=X-wH^7-6R&?`zQ*A=kjcw13|Bz5(7?x`sws!(#y& zTVF0+zQ~Gr-zNryvV4U1Z8j+Po8uL`R@YL0sKTI<*w=y(yI2z2@s>uEUWI#yQ~HYC zmmP2mSbrx7ni5Gx^L(?KXsVI{jVN)5_jhd! z=R3HhXRw_uj83$R4P0WS+%B1_tu$7;-I^+95Nf2K9&K`qetOiBOrOobSR7{7-I+-J z#yc&UI%~|kTd{Gi!x}P4D4@%EO?P}$Wz;7b`ZObBLG3Wa@)c4eOh8Xl_!;urw})ZCqMX4Of6x%D1#trUs(9 z@6{a4>3fly(_Jt@urrxWKa7_vn@2QR%`;6-)@gDwWyK_$+AvL;;%IVzb48Qi(D!S| zXcN!uUsUybJh`TR&oOJ;B2xW++k|OCuLZ^>RYrOnHcL{YqkByXj{Bg4#lmdL%yj+e zbcu_F>GCs7PQdfvmNmirY68UlMRltFkSQKxO_E`%{_<*yxk((%0f#Ufi)C3>0#i3k zlJ_Sw-@O{<)wrP3R>}t+Z$+JIHD&L98tTO&0Jj3Ej7Z9jcM&(^5N69;+eCcsPB5Uv zh-MOb-xZ#n-F1Lx$DGA_-BUb5{-g6d`i}DcajhVua(YV>SXfzvmFMwZAO@CKI z_%1OzG~g<<14rW)rpptWMr^ZT1I^iLwu#v=bGOvIOfc3qk%8JokoT3cC^2~zwZcpz z?_X-5vPBWaBi?s4iCUqd>nf_zH(6TIeI>*dp8n>OR6j_E&R0z$@TMDTb;&=ss2!fI zp#m?3!7Es)!aJ5!6W)l10MECQ!s~N|ss>#0TkySEhbF&4tuA>)9cX@PprBdU0MPW) z(4;p2G_HY$hP3mS3Zrn*_k0K3ji`(Dzfz^)+Dvi1(l~-^NuydEj8Wd6Tstm*BL&xB zaNmYaeihd>ql#;mza}m^CN*5ul^U*pQe4%IBDnf1A#A!1*K~%fZ5_B$n=82fW+5z5 z!}TeIbHfoI1r@YYpB$~qk9iuA&MDX)iD3JjVtYh~t#2~JHd}{nHp8~aR6DkvCIwqL zb7qhERBZn=0k*qp#rBs;kFBJFV%s4End!?V#>nEHPZVtPqw~D^@(I3{&!HbDE1yH> zg1a*8^Qu19k<5H79@zU`uQorTbGLzH3hSf-E46}KEjRS)xP=r-}?KH zT<|^N?w^r@@GG@jW{_sZAU(WGER}yW=;r;K=eJXj?4nDQ!F0!Rme*&};WW<>`R3EFQ7yyig{Cm(V)K+C;1^Hw zzN<_JUP{>J5RAP4TVuQv`-VZ?)NR;u8bHpKLlDL^r_^1kcV2$4K_oqD51y@N6?l>s zHR24+hTn(f?0XT_;{67qu0yM$#zS@d*iWjC4<$wExRt8oCRE4aL`84S^IJ0g9{(@s zchFA=$&(UQ{brQw?0RRSYOJ4CMeO>mL~8%~c5AhE?XFN(0*K}Et=Q1=?}wpv;zxw!1f&kF-_El^Fqw8ydXfDxhW>H; zHTnnb#eviz^H_x%9{iNdHKc|IrRN5;=SsOHf>|@yA`az`WW6_Jy-)p-MamVVS^+Te zJhZjYwocae=sswBhthVe);8@t6Hbv)D^5$WSRxNgqBz=!Mg9X+9cMVF*oODHlW4KS zuioAOArL-&)yNdhd_ms-(G9SFEKL+rT#{Qb zM~&N~4OK;t2Cqy_UBV_TAuN86;T&h~d)^mlh!7kiF1Z8~GZ~Ke^@Uf|{u;4~07o@K zytJnw+%VH@X*Em;?B=~sUjwg`!Yt{o#_TW62dxD=n~_5Odua5vh(GgHS1bPP*xyWm zPghry(D)1gKhoYjK8m7w9PUZ7un=&&qS=ex&iVAWFf`F1B z_hEJ)8OP;R6!E|l@IVwri3kB90p(VZn}8g>1PEsilFYoHs_L1Y-E8#xet!Oe>Dlh8 z>gwvM>h9`ll8<|d>qB-R*Vk`jj32MojerdH0tH|!%wZIOtu$IMPmoyNZPczMwNtmz zXf3HWN9)zIhQXbH$#I_KxDvqDxjl#Twu?6kbn4fU?o-E35CjYB#*yBVP+Xf zVYVwi?*T&m{dPngw+%f6et)$t)~6eF`YR6C%K+`;Ce-gQ;1{)of2^BC9xfL04=8S` zqG~;$@NtP@$iA0=vX#+d`}HO2{@C#n%e#xHxSyzaeJgc;X_ZMuI}68zVgL*Dbc_*# zE5>}XE1nOnOW)%0BqEO2(RDhBhzp!L2MsIC5&Cr-qH4aCF`ibX8^sG0^(gx# zP^lY%rebfV1wiHJO>;3CDxAc&p~mgjXmaC3Pb#(|yk1a!9KhRxd1_B7{={B6^>fHRQoil;!Qudfl4;=|Xc+a(en(Z@BvA=Y@nnpy!GMNHeR z*L1^D^vxY)(bW<~JR&4->V^KuCOA7cGsZ8L>qa1>$}o5zfcT%Qs6BZ{C}dus z=>+yPa9^om@Ie5rVJUs?4TT}4s2HBimRR0@3H%KN{-w>N7-pC2Sp9BGR-QX;7(5UK;$|At4&^4J4^^0Bx}gyP$ZJHL*id02sXk@k6bIuKAG*Fy zh(e#{;jy@EX`T&hgyd4Yi8&Y@W@1p~qo-#Y8hO^KE2hVH=!#(k>Xn8f{MJ$|OMtTS zGTkVCA9#Dd4D79LPLZQ!<`j9j#GIK4h33qhTmBC-^V2e#nN5ga?`=kYl@~C^o0gf3 zxN?$)^c6sRT?wrYmzNtxh(Y$f2Vc}3yem|jT~2Im4~2LkJ)On;CoJ;-%gRz~{+~1q zo`J&%KEw>ky#NXq49Swq1T2++1qu;ZCIB010ZTtgqj{x_X6RWUV^J9q z_)V#91lE_C`uyr9#`uUby=HXCoq*>?!ZU;L9EQsJRTIzt6NIOKscsbSg2~<;fM*JC zD-#NTR8t`Z3PaD=5^wituKm2W>Z)$WV_zKeukqL)L|fMGGi0hODrV*qe8D4|52*f zo^Rm-GvhxtFpU4$z!*PJt();5kBkb7|5$!mx8grW{Zl;l-;D8(E~EU^A0@H8VKgA= zh^Oss8)!ftzf?nh6wR^z#s5=0UH2ct;_2pIWFhf%$4d2x@pS4)Gp^$iuu57A|Ld~; ze~qWBIp5AqvFnSi7j=7l$JLSl8sAaBT(`$}j2Ky4d`J3=HR3x8j)DJh3Hki-NQvc* zBt8!&KCjLvKL2$gk{)?GpD|u_QUAyLMIP<|)SB$a9%YsLN8Esl#9%0>H#W*l)U+fEs{zB}N&qtEu9ltQfA1bNM9=<+7VtmLo-L!|# z4G*)2`>$E{@PET2+rwvozFp^$zDI$+aYSDoqOY5vZ}ho;vWL?WtoygkYu>+20NGo9 zRyXh8#)BQq8K!7s6DSgLo>&xIDpqB-UdlUUwVBD2F< zB=d_kMCRtRc5@bt+Z}TS?O8(bp6#qMn{7%uFParkx8GkNv-Z%Hp#AJy7G^)o&Y1|? z+bp4UCCm~g*s=Y3P7k?fYmPVAzq_vz3yv0t+P_N?>|aUk_OEZivVT95{reg0U#VsP zJ{%fm|JDYA_V4+Buz$}S0{eHC?BDYe%X?MWzn{te{VeQXaU}cKV(9-V-_WJ6!|mT0 z)BY7?xZ6g*1QDwYH>SB>l7r$Soxw4WoHmQ-&I6-(h=V-dUSz^;4`xVX6 z1IYSKs5v6*g`bG5ncP$aEAYNm$_1MrjC!N@W!p@y2$-`!yXO7;s*<4INVpuPH`ZA# zAGPU?EhS-kgI}^?(*mJ-Bhvl+8&4BYK0FN2@_$`lH=BOMl!v=pXb)=Y5RvfgI)Ix9235x19z;LOgAct)hW2PDRomtDpP7 z`OnM3^hdW-q5ku(KxF^fJ%({_sQT=olsF1%6mn1~p8X<&pKHKRcB(EmPyGFR#(4Uv2s{uxk1-`}+d);}j{{qwBE^7e}L z&kxx1)hosN=kJK?pOvuwIidfb^9ju<(Ie**y8BtoC&ZpL^9ij;kr?A$PXyOBCxz(L zNGUX;SdSca^ePikM_&*tpL|xx&*Yj>ovRo|bvA$2Oequ>mRQzy?*H3){r_h^A?M$^ z5qQa-Z=ut7jPdnv%gO7{#%>S?aJ)?^Bko-NkeuxiUKjamY@%y;QzJ7S~blCc# zM}LXsoe=h)$bMmku>VDo*AK1HVA=EZbS}18=8MPvVf}FBbkGloFAnnqemoXw{jmOY zm>*Dd#)d8TSncbFzs?H#e>BwopNe4r{|>ePW`1dP52l#*sM~ufYPCl##P<@H7wO{V z@{1Yj8A>ZHL_N^`sBR3MlinwIX9nk^7~d2{o0iD$$DU70q`BEQhB1#esI{WDPfXWh zT)FvDc1*e&-KhwaOhHZk@jx_%`FkIwxR0BjGDE@QV`>J6^o+*49EYEj zSazGx@SE1*;WrA#r;TWB?(Ntf?ETfFwXNtUF^`t~pC>^ZzLMzH+VKuYbt~rk8j>^K zskCYP;ZqWmeM$J1@_7%;ufw{Lu5PRu^nEglu}t3ydFGmE#?q%(NwT*OhIzk&7fntb z32NGFQKV_(LXC7BmrfxOH90j$yd>>iN2f^_`T?ghow9E#z9Ab<%oyZV%WwNhO!h|O zsqnNEq1o9MXfqOcNI&!iHq|&6dgCxEkzRfAfU6y# zd@IH!uZnSHde3D$z4@}Qvn~R0UrFPKp}L67`!<>wkzfnLO&~p43Vr|u;cf~a-49J} zyhP+4?`v}7k?2U=m_Xe4q%Vx+1`IQKMS(%-b~rfbGX*V)p@WjhN1~04aJgzyw73|N zMPxkH*Sv~x1CmkK)23~!zLp0SJf`mwO(D1Sr$6RmvafZu*xbXro!d^6@pG#iX^!0w z)T@IM0?ul~d`CY1kZ!=t@fB3ziKx;?VtL(AIVVSdjjHh3FG&?nIfxTJrPllq9<_{b zKBya>Hpw&k0EZS=8Af1lm8m!Rmj`ttu)NA12m20uy3V8r?8(6|7~|az>4w|3FX+a7 zL1^&&LERo_+LK7_`xTP5l zqvV-ox?z~A!gofe_<)NCbR%%sw8z#y@C&ExUeZPKFX97BE3G)m?nK{DUm|^t0avm` z-&d8^ILrYAgQ`TiginWZuApB_9@s}>eDW#uH+?@>;$dW#8u0iXFMY|FiKRPXS-y-h ze)P17r9-88K0AFGbUMbxFCEYgj~3&i)7cx%S$G}H!a4_Z!5^T%4?!;f0wMPV$T|B> z$Y=5C;TRW>Iw+W1jr@XPYz$RjKVS{xf2?72V*K-dIs@)Y@ZTZ$SC%ryZ?NFMam_IJ zxc#~j=u<_9_rswuvC52J`3CCWc|eaC?$}nK=tn4$3B_D!^4&fYMT=_$I1T`hucGtg zXefMIWf;5#48!KCTK%h#^}w2amVdRr`@i~Ew;r?ntI8h#;9o5-g!RvURE=NskXT+8 z^=HU3?9cioG&_&}70JK)a0z2PWY|VOr(Hqwn&o#R4)2%S+Rx!0$r4eWvYlKOABoQWEO6sqF4=YT1OLU|# z>1ezLbmuKd$D~Br_ba}R9gNy-({^chTA#???dSoF>&w6XD`+nQ(Vr)< z5zAg|BzqwiA9ZsaJg^tk~3}8RE*Vyu-K^g_JXdwvsZVC zWj_TSvH2qI;HxukwQlw;iaH|E^g$Gx@}+ocgLmDl8^s4qy=L&Vy}A)tq62a3>~h0UjsX zaQlx2abJyMHE#JO6Fr@S^t6dcPfL=9>$*uSCn2btw-?!Ub43j4X16wOJPPcGdx8S{ zk&uSgp#s~Q=N+;MZ0JBA{S&my6sD*ZC=dgYwhWg!$z`t*9f>t^SIG*I8aJND?+FU! zR6$0HO(;`HD3cCZLRk>*#56OV-*(Y8nb-`!bqG?mDOv2w)4oTC)|7wR21I%x>KXbT#85;LASvavlTPDzelHkKb|M$BgCuNZ8hYg4mh? zw$4R5!YC*u{=H$lTwJI#j2tb0=iPury% zfwd$T{6Q$}xA~o?c>;VY5W&mWLt$@KC=LhV7zj9C-AQ9t|BP+~wp5ca9NuY0|EXns zCln4<(J#M3;d;X`veaW9zvHIGL5cY0BZL|YP#-&DQhvAS9}Vl751GaHX;lBVJ8&nH5DwgDmg zpF1pnC#mDV`a9?MTmDXLr+@HwIjUz4O14MxcfR?6 zG2VD*sK4V@ub_(R72@wKKM>;YL}B{C79Gjg5$=oqV)|fLoLl<^5b;0u>DC1--2T%X zOFNp;7@y;Z@LkI^33n}rcLeQ!8Hm+d9&&?^lG9oNdnE7Bt=lhWY6gY?{&;@RUa^7< z)y>ySV*U6n5p#1#bNx6$s%a9gGQ7%v#4WMxk!~#~5%JI74xrZ~{`N7}wgm@*ee=M? zsyjUDDUaH~#oKR#pr@m# zb+aG!sFNakI<$X3Y#Z*M-sT3fe$ox2c$uZ&c&BYTCC3V`M^m=xMxaPH%=@N^P}X(Z z{_cqPVEwnv+TXPe+RfyTKBP!2Zx2af$@?g0o!%oU9KQ7*?Gvm~Vgde)ZIRa~3!yzI zoxKEp4uL?#PC4 zcjTKW5XRlIw+?y{q2h5E{k;D=fd=al#jMn8vhPj&MNrk)#f{&As>T*o-&s^8+NkR3 za>C3=QP8x^|jdzYw~1JX1ljDj6ej16_mqc*@l+rgKP zaSfG6u1C)?FA53o>2k^~GF+|s^xYx!)Yy3%86|d}au8!wkV{dr_rs`~{?|LSUzgUw z+@abLaldYA6z)(-9VC`>N68gv6z*%rhwQZmr(F#&2@eqobKU`d>@`VPfIa}q zQ3DsRw*|mJNo(K=Bv%W+ZkNaJP~KrIuZTbe79yxj05#46)d@lEK=IArOu~bETgZqa zG2aw_@)y*+4m7`eGZ7BV`|_9xiXo`RE->FMg;{Hv&DY z$pP8{g{P`%H)R79a?G9!Lcf0p5ySz4B!M8%-4K+h6~%jL=jgx!#(3Aw*3MCVQ@XQT z+vy!b;MPO!;{_&dg%yUu$8Oe*z^#IohYNM1xFE7Wlh-RG{=LBRXDZtNt3PvOljYB} z`R_mYGpkmC{x3v-=1jW8@^%sZpS_LrOAE-7G%tu4|Na(ZJfo2OnMnD_-0Bt6t?BF0 zS`JUAWMugCXS`dR(v{z}Q#jH8#Vws=JzZo-9^;gK_0ZCXnLU>SZS^nd67!^1%U(P; zwPN!gh9%w2g{_dvW>idowM+jhG2D=jY_gi%{Nn(u+p?w>5O6hz86mM#dQ}+E3 z70Ce{4gE>2mVMvpxY0iPaZu!iviD=%Fg&T{@>?-3=$O0;7M$y&8T01L-qqN_mIodO z?{Y+%?EMoRx+!DCb_EdF+Q#S9?ZG1$+!sMUUye3MIe1B{OAKRKspYay!yTMXX*LhR zof?q6r|??!FNuRt zk1`9TLfPp;9q=^XZ(Fc`FIxS3Fs5ezJ~aC`G%9lcCe|TNQs)%tjS|{JCqJ{*-nmV( zcYK7-u_SZcp3zpiN3p3fm_Ft@O1%er@^lV-iye+b6IZ=@e?Pp&TPwMx$jjNe-~wn^7trIC59(UY8QpclEhKp=}N;WXs@uqk;-74q2_4XMq+{GmF7N3f#Pqg z%@&6~)%o^AAF&tBa_V{1Lf$A}H|8js!`%iJ+%&W?b8%<~%%-88y3Vw*3E~`#A6%y! zfhECphnchE*LCLIz;`P{^TG0^(B!9TvHmLI??AcnHQ_H#N~EL9|NO4o#=bL+M-%UdSy zf6PLDwDuD}I{#wwfiPT(bdrl*qH(NNr zrY2uJBG4@-bj7pDWnQ8&#+&_Oy3F#-Zq?=?b|#a3?S(6R?;70*JX|dfZL@w6oLF2X zzO*sF{8|d@s|fpl9YXg1ezyGOfe-(yzpQTz?*BdV5B~CXUopnJt)czDhb5Lbk9d>w z2J&Xt>%^OqyomdMuQSFQuL(Qv>>*x{nh#W_7G#fuZlxAxkJ9S8)vF@2Qo67lG3jb1 zh9amXyyLIBq5fLa5FV%($u> zeEFJM;*Z*zAbJuA+1J`I41%JB(J?%Pj2Qhec;6s@L(x`t4Wpx5ZFJmV z00np(Eha|J5)`Q%AJ&JAdbo24fW_SG)|Gw!I_1Rs}*LroTS&YU3dT* z8k zx)SdMt0lZ*Z7p)~U@T+lxmAYjJuW2GciL&HjPOALXfPUIuB}BpVjGyyPMgrU6KP6c z0|5P9B}H2~USiC*J3CtKg|xl@6F`fQL^-Abz$lexu8+m++On^Cr6sfD!)3NNfvHK< zidX?=q6uc-HN(hI%hPkONVylJ3}=z--E_^I+S9|Pl>TEatgF*N%!Qq?p;LQ$IB7rs zSPQ?fC4lh9im82*WKQkzVRVeEjgEUvAXn;(Iayv&JDXb7M$3iz0?gMYm~Sh>r}j)C zPG8h!27an<3P4*S0NxRT7`q_N6oT|zZMyeSrwJ!dkmbFj!W^M+&h%eZ3pHQW6X%5m16{F=G3Nu_t!CdlwC(mjhs3)r`Q<58KpK2 z{DB4Mkm#N7SY1?2C_@-aj0?M>PF!4QfuAFpxo5T zOPh3`#PTkaBf5=_*p=y^o^h{3bMgTzbR%$EskIKxhw`c*ycJL$WWhUjuf+073EmWf zS3b=SFAnPOx@y+{7V1|}{Vb}#Ii!BkH@Xq{=qg$1_Rx4sDcSvpp&*rsL}nhflz;yn z7|A9f$@jKPWF*^0(Z=JY@<jk~rp-@SArK0YUL~O>bQyI&vOL*V>5b??aZ`(C?yx$a>ct0!DjlkZ^ z2xxT+Nd$%ToWiUQbRs|nQwY$NpLGLojRLh#02vRJVFB6p@N&VnX0-7264@rJ=V}^Rn-&M+RR>;0TOARCNVi^tinXh!Ccm{wfg1O+p3wA$i$uYXP*`1N7`&MY=gI}z|F}zHdG`^V2?XcL zL_3@Y&~)1cim4h6g;`ff#XJXvcZJsI1%>=8hQWXSR$$myVHm~l0s0j9@kL_5NI-ZG zA#@VL+z^C|zR-<8f05Buhr(H4z+eH^ccWg@{FuIY^OcchON`p35;1BA%M2rMNo0I{ z_X`*`_-hVeYc9kr7YZkd+dtkZvAjegy2m0Udiw-B(WjQ_Mqr5m=!TY;%7|r;K_N>7 zxVM4=rwKX;VBSbD4LTK{7y@%1!0aJlUWGz?!E6qNlFNp{JFgJT9$#e`fhxK_QV$^C zN{~Mz$O$2kQ=ol?$W*on3R{F`odt#HtMtnZD6}CP@`FoadCdrBH-fo!ydCC=rMeOL zOu&2sTAsU1Fdv1&9UvNuzY)}?Uo~hCZ0H=kYN(baThnfNbxs(wY9`} z+aKt9?<_>~m`l-~a9YtKN}INsE{Wx|58v#9pOWu^pT_XYZ*j}3t2aNVhoU(q-(hZh zrQx<$yp<0}SNv`HD~$1e%W&Uo!yOXKqbRWCXXsph|0~qlvL(79F6b$mqp3?`#a{;Z zzdivVjhE?0@#>*-()%Rkr}xfMx2N~YR5!WRor?d4l!c5@MBEjLv0jQ=t;{&fq8M|l zr!hY23nakpk}!NpOW~g{0}UU%_G zp!hr82z%cxxGCVD>~iwq-->udVozv1qPV+IZ9WOiW50&lX~O`QHr}adj`ep)Oeu_} zU53{Dz)~7QaUT@seLIQq>%TKkqqCn<)I$FE54CKK+(b7MvTv^G3U!ef<2S)lWlfZ| zt5+2E&bvbbdbAY&(K6gB{ewHd)D6T}TsVg)8roK3>FP#4^;?Um0>$5xj_~7%EyrQ5 zX&zTRzE+d3Xgx(r+N6Bm`)j?{`)!m39rM?Q1li?a0^6{UU29mJ`?GxKvL|@ddqaB{ za{l$1ZUpx0mY=)%Gq8(d|NUnu*y8iPgt9kSUIdN%8}_)|negdTg2!WpkKmmTu8SH? zn-_sO;{3@L-)Rf&9PLz8;GXZC?0r2(Y;C;-e`q7Y{~hdVo#i_x&-%44!xw-OGm}d3 z1)vOf5Jhdk*N3#*}DLRKHJqA&jtCqB{YnQZgqY5Fm}RjY>~Ym zLx%_tiEwFg;wU2Orf!-II6wmKk9>nk##4XjTl3mCv$LtFrI#sK*t5^8A;{ zGw^*(!#~lC(jASFdwt@yD7X3+6ASAoH7Z@JlcoO9H`;pX4vNF@zD7xw`b$^PIQ%mL zHcJZen%(M)Aa<<;%6T6J`Tf6WV&AP_L_W*d8-;1tXWu0;Ci@=74Oi4Y$-_qzw2dDT zPSA!!-SVhS!H7piYkU3{i4B!U=2P5b`KLk5XK;Lyhv5COLjL|&wP@MFQDT;^W{f3m zN!p!+*Hf~V){-qEBT8h8P?3UgaLG{=JM2-p?U1GBM#bNB>o&V_c!2cxQcdwGVj#8W zia!_o0XIv~wHM|wRPV2TY(=Xbuy!7HdO%s9<3B9cjlc-ZyVr6Vv{Oerp}W2j6yXrh z=YMI6WcDIOYwNvPVo9a^>!m@Fe9+R^FajtGjU_3MS;56 zt-ggq$)nZvmzB>llZ?Ro)rNU*1+>zwiz&7xF7S~RFHi>bI)L7vb;DTQfF{_y(P0zJ z`(c$~tiFzZonGVD8Q=^0lXFH>2zK%k5TBgpik1^^HtIB*F1 zG{r$qoRp+9ABbfsYg&Rnyfuk+YXbR+OV@IG|q z$LMUGh(|nEXOl1`FV+pz6K_W8)Cb7; z0N56K47MS`+J(-aq8{OA7n#wF+1cSP1bVrC}D= zQR`%P!+Qx~QDk$%D#b&kr2Lw3X88WkB3SwIg^P3}Fj#C|y#e1o3yx6Wsf8iyg``ZLjrKW3gH6|iXlfS_|>TfMJD1&y(s~R^>pV^qfJZqmj0Kc ziszc~W&Uo7S^o5trD+~Hb3@=ZBTT+AP0QU2QO6Wrj|&kcccU}V^CQah0>3L-m$;;S zCG}!XJ^0PcKjm%=cIuL%rA%q6_>;fT7)#3MBRzlo-Ft(? zvizgaaq1l>zN4yq87)OCc~vIblR*+@WlP%a&7W{r@crPTY3}tW>MFULB)7DY>W)7H z!oL1^U5~uB2!E;fXZ9>$UQah1BUrxo=)uk*Ih*m!6Uz4SM@4||$hEaiNnz@k8uS$VTUqYPAA=fd`l&1>XZSS(;lcy&Qi@j>}|9 z?j|R9y-WMOM*}|!6!C!KML;pkLeW>CP$dh+Fl^SOxV^~7VZlEqz1-@O92b2_j_c%9 za(|8E`5zOGgMl8pVO)~?uO}FCUissJE(SgLHHKwR0Q6%N|F9Tk5cB0v9q#sLY@%5A zK|`3wKP3jdqL0y%ki!tI)6V6rXplYd6O=(ceKBsW!CtLV?gmNre##hA8!4)%Af6nC zqMSpW{P!&(dUMJ>ZSHgBECvF`GuitwN??X-yyEXmM98ydp*8@VKx4lXgd`am+8rMM zq!@m)Z5cDU8p)X2E#05tk`(_fxy255>e1{B_n^A&+`<^Q_D}&mx*Vm}0aLqnv2Ns+ z8#xC8>D6ZZp`g&6x>5E$Y#2tM7n+_*qVz?iRQ62*`OOc=)ioG79Q}#v!0mYd2zMS7 zfAX(`8S910_NF)KIG~rC-V54OM8cW!)tcW$BNNu3lY&pLwR>Tx+cY8jRB zo&BzAz|m1_T;b8iBq-XjL`7@ZNS2tAT0h6DXyfA*wWlkQH~EBk)(G5@L`984e}L>u zPnUuh0Te&J1ljD_L5%U_56qLYN$=BN@pwgVlOksn^XKs!G}NFWJ|XGL2hUB;xXjhL zq;wNJY5<+a(vDi=1pe_nZw22+E}ti^a^rghHACm^`95Jh@-bPC6io8T=TEN&w7V5aZf_z_C(uaeT{>9{Eq zJ=)~M@u;9Y>S>Rvd$f`J;`xssnqlPGqdhQU=W&N7!{y|jc_M7sdPDYW8b6lvDOjLe z=IKVJ@7#pJmNX_FpibA2=MJl2}T3L4w?A^#!<+)Nac)_6^7g z(9K7Brce~!GylQse0Rr6cyTsMy(>3(|7YbeyzXp2XHU&^&0Rowe8##pa_t{9Beq9*rTRkE%{@a_ius%IbuwJ>2Sg+JU z)*q`YF>y{he=)Lt<#giTjVSw$_-+ydxh1x?aBS`>_(`1ms4jADgZMhH4t_0m;MX(;vXwHfh#Rac4ef$s*p@c0yw=%#_zQC=#~(MYyMg! z`)<2rHz8&}921e*Trj)UYqdx=Zy+Q)E0oc*-U^bnt3eo}FWx0Fe&6g`7#(OJ7`?Co zacBdx7`Cn+o~&wdm@O{X8I6o~<49->-I)31q&dEFBlj-|Hh(Qi%vhO7IcgYjw;~F@ zB}8NWH{8VIDuXd&WjsNCfaB&tvdLjz z{SXc>oEIdkynYym-@8>}{E;_m;c%SE;r#l<;VhlnM>DprE^^rMLN&9wbQuQDgz4xF z<_;qvF3ZH3Fd&+M6jkGxbd3g)9#13Vs)oWCs{dCe@wl)GhpRkOi1dzX@^8e?`)CN} z($@`{660Ub#lH4^67%xh6^ny_M>nT=Bej-6=u_V|2oK?iIC@q`9E9m&5Po>ImO+TG zF9u;&y^uj@JU2K9UBU<9ubU*szk9uwLAbuY7=#;X5E?G6LK45#8HqXY;uZs8&O~lD zT!6!b8bVPWeKSbMH*B6k@?A}E@~dEwR*Fe*sXhGIuu~P58bj3<4XfKrjQ5=rq`iNA z`zmMcYqhL$=G9}tRnGg^U&pShh%B8WSo++IT3Fh{f^|-wITc~8#NyJ2Tkj zWRcq163?e2$tP2ptp%!covtm1RSS{BQDfMQAS>O%1gof+dFO|>qo2lHL=%Bi{$ zC_Ep$C;oF>6k~kwtl&<<802Rr)0lk^L7v(6ym>RCuIy`l-Z1!b0Cv}T+x>mM2tIvp z!RH#3F9yq#pnQKx@IE_~N0iv_t@MRYuU)Y2ohVT5a?!BzZ#AbNoYc5-YAEAIk5Q)S%;Af)fjH z?la-g+ZuDQo<#Ljs`s~tF&<;p>tTfCD}egxRKFk9UkUa9oNU&=qh|dms^5a@=R*BY zt@@Ys8ug<^|2@=ysGn`s|Fvd)2i4y~_3wcC8CL!IHS5=>`U|Q4h)-yLE60cNLQ zoQtA4J}PA_4^Jfh$PFy1 zl|3HCCjT92{GnntRQx%ZhXmk>YP+f0eNZh6s=XNwZ!=X~Mirx>qRXOqY*h_@2>wl= z`hU0?<5wo=Mxc#74@wE|3dmYr!W?mCn@no+A+*VdHg!c7{X3xY)=P9tpa~RWFN<7l z71XpoH6091eG^Rb{uGJzOrbjA##-&5*0X@%^GZUn0Sfgm6E&jpk5su4RDJ+{pCBr~ z1%+LgiJF;Eh`S>2JVzn$ld0)mg)v?>-lV33NsVA>Z>qHdYV8`Y8-aL%;30r1UmS4{_*+mTDlekSSD#>vH-X=u7L_MJ;k~Ow%}6L5yc)`z0n{`PnjU;bHv+d`Bhcda zH2VEr`2A=2JxYMS6`&QF(6&+S|4{9bP}~2C*|$UDHc>IOA6QD%9D%~((oo*)euCs5 z+Gjz9H!DPi09E*wD#SvC`=G+u3L;kkm`lGGcVLV+fZuxv+@qoJMJYuJJqLxof{V<5;#J)!UP$puR(yUH zkoyN6gJxrZ{CAm*@#1W84Ei5*&FIKn@g2Ek z0AX3S74kNmS543j?RrJsN70Mdhq*O#g12<0%ibR?K&=7Lfb5`8H`%0ypBX0tvFy%K zgplJ@4DCLb-K3@qIvRf}&2Aj-<#wQO@a(1(ek`{8>gLq*s0N>rts8UjnonY+JZ)us z`YYyrCW+Z{>G<3J(H@BJ?{f0P6N7I2GSV}hGbk4P<+0FPIzBDn-$M!SKlyvQ;;gtv zblI^=A^&I!MdV_N{?Hpw(`8>Dx>=q^2`Ie=@@4+ z*|$}vTU&F->P8^XdS8dCR)thOFRBh5s~buAfn$0|+-p|=@U?FFL1|F-ia21+G2gtp%^gt6ka*v}`NN*jmc9AmP#F!-z^hWT~vs`z%xUc6hYb&tcsAc-+!w;5qm zhGU!NRJ3Lfz(}Ugxwj`JB1iOnvp~Cqv<_`R(JBGDdu*970>ik zFrGl9PTQ{_5w|WQ$aGM%kyamSZ38%5R$cpDz+9V%4!&vqcLlt>c zA^fvl$vqoSIk($(t|KwIMU0Clzf9)uMnyf9v;~O7MIPouZ7~6dFCOh$pm==f{X^}B z8D|&^#7q_Ou-XkTLHVI6qJLm-6}8MXxfD;EgNtV{vbW@j+^;K{`P#7TUBVbk+O4Ps zAU&^7ifo3T7SlWUbZ#3kAEPLGhtD5l-_8r(C4M*<{w0jH(0`|S*HOAr{BtmVEDg#F zgZl)nN7>`a#CxP9_2%2f>Cc2-xP);V2%?kvgfpiHK6IH?x#if$#BN{MEn$))0H)C<92#8>g-6LBz)MTV>W zI1s1sJ(-ERLD!f>eA3wLTDHiZj1pU9&*9$NgKllAQ%TjchwwS*b>;L|G{+C8nMfuv z_9@2l+K@B)KwES+H?(26>b)?5-isOL!*@aX03W{Z=~y~~F=fU^;AZF(0w@=k#I=MC zqbcWV{V3{}J9lH0BISEhi{#mN8{!snP?XR>oq8XECrNjU|lU)hS$(TI*vnaZjkTMK6@@8cGh7KuY=$cl$k~rW>~SS3sUBB? zJc|O4Cc9dD)Kh%?*q|&dz$=59ao~oEQO?2BL(C1>87R{pRJ8H<-ax7@dn?Dg1NsS8M)8E``M< zg3~`6KC4IhYa?jjN9WRj|2UknKz-EbFz-`d5bryFKzEvkoeYXl$)iZbv{WME{oz(> zR#QJZQla{zR6U=ncNNt~4HvJ=47Js-X9GWn>L-Z$?S>P9O@P4R)duDd-G73K{3h8c z!Ir(L<*5{E+4vP|d1x48fmR{=KnqU<=}VwiD@3d9!-z4xU!~R`KDA{{R z^UL+V8eUMJ>5Uqi)C^Zo*%u$jSUTo_m*T*$%XTHo-Xc7=&UPgt08kuY!Mcsrjr818l3U#* z`;_aT-6l!)CE;=YNLL~Xbf6>U=@nP}9ER=T&2q6y9{;><1d4?p4`Yx9%kiIVKQ)`+p` zlU+_G`yN5&gnOx(beOFlga56-lsuYa`f-L1PGWX&(e=p<7~7xWO5?YI@$hH6#w2a= zs3jN%?)c>xW8&G6!LBiiHhl%2C1kk9^Z$+#S6{;o#@`LZ)z_b!Mmie#u>o2C+egu( z&)*GUOxE;RX054)Hb9z^=M16yl+dM1a-(dQB72h>fKt6b!==ctZ>}&5*|(v>F!+#> zBK=81Q_&wKu&jdSZ&T<)Cz^kYAIACDI+^BQ=OLui_D(f*+M%JQPTM`y)M-CWwdu5< zhmuZPIh3aEqN$XDY5r82!UqR47Pz01xqMi}Se{#)3goTJqGxjPYHg$q2qmYEigTQcjMdIZhriE#lt~26yqFdkFh} z=>h6{!b{k{JNa|y=?!)%=ub~JIWcFj$%+3BHb-=%_%)HgJXpMLt^^F+#LKiYk)E%I zLfmrpb2RbNGLz0-k{gY5DZ;Lg8)LKUh2V{i=TX?5oY9Krxci7{u}*elEUz1l+@}vB z^$!W^pBqCXcVLo9Z_yx=-o1lNde=-c>D@4h1pSLi7Tr&jg3^B?&Z8Pe*Z6Ste~MXC zRl5_sj{G4AK~W3b>PG(RKt0ksVV^_{@}JH`UV=N&PECUmU44+T?9Pgoyy75ZJbDy% zzn$C4fFtE3DVpQv!zM49J`fzqcOF1qBqk9rdXE-2vct^Uto}}Dt>Z2YEMfcubt5oV z+y$LJP`tG0Q4RF``|=kD3g+|;Na8V|C!yBWa>KCODQ{M_A^7^jbGm^KW6^y+-yXah zh0ta{Z$d*|O}4|~J`^0&ok`e_0j;SYQwQiq;BKmR`ypng`l3p0M5TUEsXMt^hY!M( zS-Jw9iWNVRJID``ok$oMJb#}ETHBxP8fJg)ZKP`$Z!=5`WB8Dbp+J*G2+WCtM@rr? z>>!@+E82>D5R26Vf@u60{$MU`B-y*EKCKM*V~2Eu<*g z^vx1ks|5b$u%OM0BQlO1FioGLP2VYMCi0sG;VvtPXsZF_*gI>Y9ax{787Gsyg%qYb z*Mt}6(H8H6p6z&!Hf&*Sz>hyG<`jk`gop9pT0fYX_z#(}u373ak9uZZ9mbfE?TYtk z8Ls%Gd~gitIy8@ZPB)(H7crv7CzA`|40j=Riyvxa11>Nlhp%7=hGWxy3W3n37vZj0 zhRex6dS2W#8S0it6((&Ns>q|b;{VSIYucgm$W8b#z^AS`uuN~^#X9`) zVZjaT5l9LPVL}$hnuqtMmmEnW9F&<@-npL>OR7CGE~%8<@&tL-dGdLx_Mv3wlVo4F zpCr4(GeME-D~E~PT{4N>jORq;M~#3TASkz5lD)Uk$iKZ$(2|$H7)vVkXp1?F|FmJc zbz$wj>+ERaWbc6nVljRRgPfA`dFugUOC?kzs@I9J=|@4ME%xDdiAP%jW5eqY)eSKs zFc^zL>nif73m&yBd{7EtL{^9qfr|X=p}`UPv_Z`g`Co%bBeJDIq!Fp2Y4!SFc8u%RY8WE`>Z92r!UK=KdAb+AwhAU2W$u<-xxCI7Dl7!Jha9@`+y?OOD@;evAcfKOf@cEqWHmCD7p#rAch_q;3T6ybPXv)n#G%ocyf;!t&7# z^CZmDgfFk&!x;bT$>3Sd>yF?eLH12{pboyXS3lDw8!9JmRMZjycUwObZeSH+i)(og zRUPS40-szKr1CvL)woM^n)6OS-3Tlfp$Hlj9uv9yra~c36xM@X-Eh&g>+=A_vWw&@ z_@L1Bs`=YEC_Zu(q;;?>EeqG&ywN~f5Pj4a3CeJ#$=buQR(6@mDESR1^|g}BD5?jR zM7?9N&m&!FL*@HNg0~e{*ILwh`il<7xz$46uD@;Yo z=s+DY8Ajon)6w@&Cf<3x67f-~$#w9Z$EJURTQm8BwZcuP%ObCEGwU*zJK5Ef$=+Kn zK6V5i%b4-Akhg`x=@Rr^(*IyAuM0`#=0udrzIQWpamMx0jllbti1+oN&7~3(-nG8E z5!g>4j_kJUstdbGS0(lh>Z&fths>a^Y9@5mp#HV&myV7#9g^!wS54SWr?}dRa?lxH z47Tmw#nM@4L7#|&@O!MuaDvpzgfyK+k-HL)uK}R*9j+)A#iIM|=-3<9*Dpka{e9AM zZF=^p#ci7sD?IJKxXaVi74K0iJnDJ8Y>||Y@*h!0Pml1j`-Es=x~9+#fKj``-HLeL z@mbxtEKkjFImyRCzoH1#X;B2fVx#aYE(lEub@=ILgPQck=$e|eOLQdhTom!8{w$D% z+zeM-RA4nNn)mNyEbmE@vjKOZoLz8{oL$$86yJhT=E~{4-lPJ(qeumA?a5f6c>pBw zl;Usufr~L7-`hGnU2G!GS&+U~66Yj|y>ugxC<1D3hQhq7hQS-bU;9vLWWxfvjJN7d zOR~Fr>qg-0IcjjGr)~stF&>CCDnV|xzXw9@?@|JT&l63(fu_%O!^rDH@Z$;o z(mNRATY3=iZZDcl>?6R=2C&CZBXvE1I??)o3tPW%2T?b(hi(-A0`mjvJV$j_QJoH= z&R~J$>`3atiIEgvdbTH_asjGWPLsx1(nB`_4%+)TxZT_dD7!rfy)QxMw-fXx19hW# zF&_=>+~r`)=2Qt=mcX}|HYWiEbR2C~>&3qo#ZgS_Q7f_%CgK^`q2KR<$)|Lh3rOCLNwa4ha- zVmNg()(tt__StSId6QjA;N|lK;ZQf-2)u$Dg=fkQ zgFn`na**7L7E?jPpBC6rP6NLjYB#0LyW?Af%k1HVuOfl)-3Zm<5Cixm+Y%V#?Ymp) z_3TQKjsO;H4bt9>V0|rM{oa)}kv{2adMtre=S(-GGxUEK31WAE@x18&ZPb4O<28ce zc(yBJf$vU`V|BbMcr7BjYfo2e-vTJU5h$M9EyDA)cfJ{67GC41we&i-!^52LbT^ z{wDUU>Y^KgdkFTK--2rJB?2r7Vw(%tOT@9whr?)wEa^(HXA9VWb!IGZkAVFoz#c{E z#An%H-$1ZGyOm)7+L>T?60q9~*qsFI2Zxb%bn+Gg%S(V|<8d18E1h*CaN7kcoQ6Wn z3x>fD!(Yn?c_TpHkC+xH5LxHeK!p#e!i6otVS1%GQdd_{cPCWqDb71)Lg9srrcL{; z8Dl)7i)GV-0RtdRi)=t|C!pUoBcMC8bR)3wvSFnEVw%2|0D7@Vr=9?Xc%rQ*fEhqw z4&I7jMhGw}fSDqk@Uu|3bP4AB#w&)wJv~JXS}tNJRs3yZZ)J?X*%{~s|Mp4Y-{!Pa zG)J>6@~ag1Ck;Bg2mro+g^Z@|v5e;HS4hK7g5P)3?=6pbthL0vO8nIJcaNo$rd1k- zaOR)6Vmn9bMy=Z}wyGBU6wNVkb8s5+X4vKNw@{ZCct}`o6^9T_hLVt6H|reMQ4z6omq#}O>(Q@vI5r2B$r}Xw76JQFsJ8kP`NxI9YD1{n)tjl>^&UdCNNn=| z-HEZl!$qcs`Qc{9c&n@k8pfk&j{g+~4MxLeL4)y*0KTdd^{?F!>fggd2-*Dt**HM9 z<)~qpPE!fL+(|bAUg7p2ypU*?J4KSp(R_6=b3H`tmX3@CZaGS*Jb)^Zw59M5QahRcLBJ!_ z=v`22+!e!^)64#}A^888pw0|0Q2ZIL)=+82%c8Z)W!+xzIoll?&S189Us zy5bdUAroijxS9-JiIF{?&+ksF&pSH8a$yr=;+hNinu@P9`vpaFJYT?=lG?#3`%W?p zeQH<0SepE1L7Kd(6jM@E`8$0 zm?U3m&H~&hDE>yo34t_CZps)x))Bpgj++?Edys}@*G(vs1Dn!_Omh=l+k1<$FWInm z6&|c{bJBac)oRL`q~xBB zQ?zN$($|2a&YUkYwLX0JrO!va8yyWyZPHKjoR2 zwqM$i{}!V_kDq*)3$g62EfHB z(hiKB3Dk#yw7r+w)8*u+KnrR;VNS@tA(SL94%26rP@|k)B7dVIZBl%@C&as@jf(G_ ztPV2_BWX+0xxjFdUkX0<5Fb6MMPLHt&KEFA8Rcu-80Yp+ZkRxDn<)aWTbq&?=xNl5 z7gscgdy|OYYLD?-ZA&*uIVmE3D}my-R&}w*Zv~cg3BJD?{Yo4Ve5m*&{vPjPN*ABl^DEyl5kN$QDCutm?(F5ZMvlPv7*G8aZic`^AE2(;RN8Ss6 z%Sk8ke*9s^c$9+TJz@i6d8v$irFay;SDTP{FYaJ}PBfU`DKU#?-GB}uv#wi~ebyD= z8>WHBI);!R;r-Ot4+#3#cSriCg8!P&tfy1k0?He@5z2F!At;Y{>?kt`7Dy^}ll(x{uN)Z(`wTRqn)u>pprFFEuh)QkL$``#=;}sE= zYP?^>-h1iZ|7V}G_GISFnPh02`~1JpkMr=baz1D6wbx#I?Y-B2IcK84OOI&!K3JgY z`@4KiUv5uB-y2SozV6#%`Y!*TPTxPQ()8VHPtfyq@{wFo%>^=eh$YlXfC zHGSWhsOmeP^j({dzW@Dm()a6*n7-#;)#HD|JH1z%So22h;Yh(Hr=Jw}D=npz1q~^u0A5eeZdL^nGqkOyAGFqVFHbf8VG`(D&6k1AYIc zI=O!k`u@FA)pye?z)K&|^c|z=d*3)s-={0m(09p?N#DP(j_JGcxK7_^ZJNGQ6ZJJ4 z>HA;yWc$ts&R1yq{_Anzr4yRIca2x|{hmeB_qVn*^v(St>02?N?>4=@U!*R-&6c3= z-L(e#u1MDRA))WbD^z{|`(@yzK26`Rj8pX;NBZ8FtZzkw{mJ4_nle!R=-J5l>iK8w z>U$mo?~A{zS>e>nLd3*ZRK>?U^pXgl$GrI+p@6CG$%+4XSpXx>sgG~^?s18?y`%;; zH7`qG$}94(dtQ=%DY3sk7ZX^29N;&Z)&F~62F}k|qlLd6mLH7xeMSaEz^Cb2ah!9` z|5QcaN8PZ#?#ZbhRlymnA3YnHn(zS!dZ*&GxOnjK{{y`Gk4)e^7d_VFnR4m*b6O|x z+F0QH(dEJnOY0v0xAR^xS$lHgGoLPsiQ|JO5*Ge{kUbWpTe{;Qq_vzGUG3GvfZQ z@5R0^@%Z1)?-tP4wcn#S|B>>6Bi8i1RY2MYjZx81|75X~0UOqf##NZ2acK>zZtt>F z-v`crN%SF)k0@d4R3~y~{?F?6-ju7IV*1NF!1-(uE7K00_WM!G{^vcB`SQqy$brX-P^?xwV&o5j`hlmI4s4Qjt zFV8{y2L2UA?YeSFfS3>b78HyK=8*`~87Xvl4WN+-;tSC#3k@ zZ611<2rBLt@n;d7&bIBr?M+U1BoYccohVfV6liYud7Mr-o%gl7eIkL=i7oA3U&QMV zqj;Rrk(?xu)uySVpx z+~Ei!t=_QG((Z4HcmsZ!B&@Wxha<`sj}nfAy#B3Wc>NL2R!>N2_HOfry#c=x*yahf z_yYH%%^hh~ngeZauV3+mLV=KmgxvnE9s*i?0e3`c@dW~L0=8^d9`J+$&~i|`{$@{y z5@?Soffg+>eBN-x2oDB=N=qovrg&7l3N{r>A!1(0(-zp~De0KKMCnlc0U=XMw9V~n z_bA?Q0_av$D+(DtkAG{VRau~TI)a|2h^JXIuu(=W?ugsBL}G28wm@imE{elSV9Pz8 zrbtY}Qe|r(q7-is2E~>@z$ePD1VYN1fZrqjMpLUh6!t`%{y?bB?ejk13EkM%JTJH% zPN&!JjX0f%Y!7<7(0@e8wu;oj1O zipnaD*BJr1D!=A9}Y++v@BK``u2R$K_xBJ~&d>$ndP@28rpwGR1Im$KHT#k@u zt2Z18ZKppxA#C+ToRRH8kF(Y5kAxwTxFb!i&L($Lt4DJJwEMjQ|DEdJrHa=dxeHDw zdAFw{7zjm#t9c{NWGgtG&bDR)>&$CwrY3}DPg9`T)9eg;?rZn>n>=W9cX->{+nkZs zkSE+4@HL~^v!#72*6vulc1fEj9Cn7>5pO_fB~m)ox^%jA_gk<;V_UnV#p7wl+9e*J zcdK`c&x0i)PuL?GQ7CXfntXw<2VsxDS@Wzg)OLxcKyW*nd>(g5w68GQgU#-UV2m_- zTHNiv2<{1Z{l-N@MaaFy+q5Da@VO(N=9)mL&Ead`>h+7t@wz0`2|?Dnd=IZg10uV9*n)58UqwNikd6Ti^`0H#K>}VedANvt4jFeS(FOI(_bN z#Od}0TiwpE$K!{ysXY|(_#;ktxXJ5v2K>J5sJiFg75;5*pSO8^BoLIs?+*q1TbJ$!oo4kSc@H(}DYeoo$y#9!26J&@uyT#ke z=Z<*&1NmWtKbBCIu6+Qaqz!?uo?UK{$SB-|%o^aUiiFleKftXileNDK1OOwwX*7}CFP{8T&M?zk; zub_+SToIn;j?i$SlGuWLGb0rvKw&)ejVc(i6>To@y}BsK+2EVa1x zYI9f{atySolyXHJ6bgns5l^$CHVsc$X>$9u0HW0s@7qOtbWpGX z6wg~=wT6qsO2mDyC#+DorW7|T#bN0##ln#uXjZm*w|V?j|GISkfD#OZy`l(iU(CQR5E*SFM*X|8@nx(JK6}|s}N6#wWFe^c?q;v_aN=YyvRGA&C zH~F+B5K>}7RBc4Ws7B5uBIRtgRmu{?TG*`O^|OR=-G0SOOd^Qo>>H10H8Y=p{oxbxNcZKhV4+7J7?LUh(?F z5x2j|Q>qltE3<}`mO#5-G*S_PmCRN`o^ZP_A`GkM7SQ@!#jTJY+BlIu|Ca3$k7|3h zM|X$A-mQMMZVaXn(CSsKuvv265bGz}+`*uhwR%-KwmYjtXj3g_SW1)I=kqkHgO}(7 z)M?i===wo}uuzT>#xdp){i-gWx*}O=$hqQiYp@{J+2ZxPed&u%S8ngz4lZ&6VGWP@|PR5tykXtw+uy zBU%LL_9>C=L5~=K2N@4Z-jE|SO)s{1lxB}lOgwPKa+7MvP$tPuG2j@9OU&k^3n-3J`6hy9(bhki}d9W6@VDza7FUBw6~-(M2axNNJ*n;Cbj>j zEjKy3F%p_$Ff}f0a+H%=&nuLh(vIoNF^Zl(1pU&JnZCT_)my{%nzlTHCE^dI+(yyg z2hmd>1%A-_9$Z#(G?uC#)-UL#)N5#YX}C&Sa?%JmQ&sTLVP7gcBrQy)^7AW~e`R(_ zUv6^Xo7(RUqR;oI=@rQ{2!&JlSL(RbK&(N8oN7G2BDrZ7A8ACFMtzFW{*3WB{J!KH zu7n%=@%xfL-1bSF85oY&?@O-13?YT)hMTnW40g~k82?a84v{W-i!cR$^1h=n-w>Tk z%5vy8NmKI~Z14_ZAH&V$LHJW`Zl~r?v8fJkIBsY6nvupe>3>AfU9l{o98~72D6C=HhJ&20{^S`=WTAwiQ;q zPAMr~Pn_-kaC=bjc$$?!&=V4KXfanV3D2heiuqP+c!{v&eASYILEgmg+j>Lc$iP-d zB%rwDIh2ywt|dzGx_Qcmut)KDBdwm0;EY4UsHSCJW~`G=75JzHnjzP9@R`vr`zx8h&Y`~ zr1(_&2|?~iAQaP3OP5kZr_+7E+Z%B@)lCuM)UuIKtO-O`$O`o|tJ^<$-f*m+pHj7U_3E{2oa-xUs+|?Qi+YMkI=hsX%h# zqPHAxSc{NHdc*2k#Tf0>9VHv-4Tpp7CeN6JlT`pli|ksxA@^3d-#yYBc1Bv=-qAuC zPtdJ8M8>j=9U03r9?B@sn496uJbP?s=GkM9N`D$*5%W8D*yG&h4ta$pLg#Rk*E`Z1 zR+mde$=qsxKPmQC;zFB{lRctdXg{i&N**3n6=>U{p1R0TuHUd`Mb%n+wR3%S)!H@o zigkB5*Hx^kt#+=ezT@__>+CsoQ~)3+XO%nRzSr${XI8CTm0jodZ*BMGRl398CPmF5 zFK)0OAx56C*%>=$BZh{IT(zFZC;Q8&t)57IVCz;-Xhg%himGbCm$5>`9&?*1_)ye? ze$Afdxo*GPw>|6)E8&Pc6q%=}2N&8r&0cqCyR*&X_B#j8zd4)SzNTfWJ+sCsx`)dq zC`rfYmSy?^TgR>!lD+<|Y9FygQPby)srEMyV56K)IzVJvqKpUy+WpNr@)YYRU#ML> z8#qesVFLkQc%(0|b*tCE6B-0tj}uoFm=#X z;u&eIRcqz2=vUn*7%cBkN*QQp zQUK!seCvWm zSYTaL28>XK48O8PXL8TIBA#f~hIMb)c`uFjdifbT%IWLbI=0Tl+ukao+AFBG%~9>X z|GSby6Z1Ec(@)e&>H2TgXdhA77OL0JZ*5Vp)3?6%kCM$#fBzSfujx|_a5Ip2Iw8jxOEz^+rs$88Ne?sjMo(b(Q%CTi09)Ne|-$lH;(Z$V*tx| z#{0(r%6P`J%s_NJ~$3GvJuO_--@MGlB7_8L;Lv{;s&sXWTj#=$^=U>sX+7 zBI7$m1r{*gH5PCcFn)3@piE*M7Qiuy@q7!=If?NS3(z--ahCyQ{sLy2&=nTeP;`t25BNKqW8I13q0QApb{NMxt zMU3}M04zm}zb?`jF@9zOU@c<&!UVup#JFfIjv~hM^8r^8<0bh(u!!;Ud>~rH_-26@ zGv1jG^c6FHCLidU#dwiuTqTU#CIZ0{#y3v{`brq@m*!GJ@XmgF$w5j z!1&QgfOQe$7evEe%=qX+pnEan^@V`#7RGxEfzC?C8?FJmD;aOS2I#M6{K7Rr&uYd? zt_8Z*Fdh+fE#pzqQQgM)mz}3L` zfyqE;1LH4D2D%#c==R7*~GYGDq!2hxNj=p+Qj(osX%lS<3|MFCdQ9X z1v>9!yl*OC+06LmsX*6e#`CWOYtbAV+WjuZ^REXSZpN+G15r2Q_16Q|EsVEb4|Hx}eE0Q0 z?-s_p1>VH?@#}$L6XS0QyovGi0&iygvXIlvc)kJzn;9=vfL;&d4GPfL%6O*&IPPKm zn7H>dZl4C&0*vpN21EmlpPUBt1sLxW14xkZcc%eLka5d&z#3${XgXjEGF~#(1y@Q0`}Z zcM%Z0pYiS@p#OfxqeXzLgYmv1pr?cJcZ&dQXWUW@M7J~EPz*R8V7#*!=zf6l1I0k! zM;Jd}4D>w6c->6E`Viv>W&**781I=0bUwuR>oWnzM;W)w0+de1gR_8OC*y}^0iB(U zADabqbuxZR40a!5JgWq7Jj}SQ1n7F0abF40{V?O5B|!hfj2|cg@Cf5ClmN;jj7Lj= z=p&4eo((8F884d+M0Ya2c{b4hDC0e|fxcagXWakIZw?UL!}!HHfU=kIqEeuDFXIiRK=dibcb5V^ zPcweJ6i`0Scz-Ei{W#-UbAir}GhQ|qz%z_D&IN4GFdm!>M4w^2N8q1e{N!A~@d?J? z7Wh8K3+DmWXBjV@2e_VPylx)Q^(^DAd4Od<;|Jyej{S@un+J66XS{bF(6^uQ3-f^9 zPcpvfMj(2C@!*X>*QXdib|c{UG~*X<1n?Qg%dCLoGmJM_f$q;R-eCp$Kg0MzD_}dw zc+?7X9c28h73e$2c+Pyl`dP+H=L4OeW!y0z=>06?k@n? z<^z_`GoG~oaDATfk_AA|=NYeG0HB-k-~zzW&G^0rKzBFe#})wn-HgAz0I)sBI2Hn3 z&oN%K5a@f3@w$b8^$U#q76P4LV7zM~(EA0(k1hn1=NUh<5a@ZH@%%-A>k#9PMS$gt zjPF?l^nH=>w-y1NhZ)bh39x*LaobHm|5q5_a}%I^mGSPI0LNDuKYA0;`BlbG-UQ%l zj9!gZf&L!G_bdh+UuXP?xc@rirxpX<-(dV*fq#?nA`$2vW!!Ny z&~udW9XA7(Z!v!0W+3`4#$Ue~2)@X8|IL8%ZN{gR0nu+WZYu+V#~AmO0m^q6KTrmA zeuwd+WkBC|81F3ux?W=Zav5NInemcafc}>mZ@2~MI?i~dyGV+r8+9^;3W0Qf%Ry-R?e?=yaR31E4R@xrA*&ufgAF9lq$ zGv2xsu>2e2`<4RHe`7ql6zDs_cwsr<`T^r*<$&WPF`lkt+} zfUB2r*K(k{m+{W!fbFM@cP|I}e#-dSpnx=K(g}j}CQW*R^d36WJE12KNkA&+IapnYCx0|J>?UpuS|D8>x%KgPJDdT!#mj^F-U}afn*t z382J^GifWRSMCYX++v*K6Qb?8I7BH?VCX3NFIDHMMW4P2QNpT3D1>B}AiOD`rfSNy zd7h>U2Z^m1QZ|Re{DFMqgrL4&_0AKDKAnoNYJiwE@YY+H_;CeEAWVG4@RmAZ0Nwi} zAFH&f;oEs7(0AmUkA=li9I38?SrB!kxuAFL{j~o?#6l-%A0x!9jcCpiHl-#rfA z4!Ic*bOvY&kIROmNE=lhRN(y|i4WArMCV9;kc{aZgdLNN9UQ0!4+UuEM(fA}UQ?)3 z%L7aVHgs+ti9si$1civ~B;bGVz4z=5xTMPWdjkKFraI@7lU_r1RSj?V;md!VgRrJ- zzB^VZM11gcOvi-yx?axh?XAZqV~I5+SCu(nW`7oV)wwE6I0sQdaaR$JsR&n5g#Vc# z`UDS7Y=-8d@@B#clTi2>RRr#doW#>{IFA-$ao$W(!+;B@DG0 zj-+q;GZV`_oU|3kR}wuL{h`d?*5Ynjyj-c2Y)7@7MeRKLL)&Ytyq(JH-IuG9A8w*y z9Af#LT!Us5v;af6uvW72|YZ$pW&UF^%b@5DK<_wCCsFMax2W4(hUhz_EK z^e+R+$HhON09cE#22ZVw+Y7o((ltWoN&hfr^pZ_G2rSeLkTuu?TR3F0!>V2Spmx9J zB+Cxm!IY2LGfU?fn0`Cj7FhS|hJDyd+vBsfk|O5d8Kk2e9wfVnw_Re7(j6pg_0EuH z`X`xuaws>FM|sFOh(4366laqA)g7Fv>dm`p?D5ut-`y;|AM$F=DmPS9A{>{a4%y5M z&-@eTNGt&Z9baV%L9n-`)3i z-s#g$nUC(AruW_5Z|CKjb+)M?*#}8jJ(-3YRpxR&B*Nv>ZmD}24wsRRgKxbW{1B{n zKg`E|c&b?2Yuzw2&EC$V;@iI7*Rl5XldsSa z2GuBHeAn&#ej-o^nfnS6D2OcoEu+T_L6a!{M-N^>fX#9Ionaku6m7jd>AAv49?kUL z?>?8#>h9qAFx@C0d(v$M7of~*do7m_nswnC3WxqOHu2rlCr{WOH;RdLQHu99lw$(TJ(qcPzyKVmJ zrEk^zyN?6LA%)yyvQJQl_RhxKgo; zHGHTwW}0q#d+p!L`~aoR{bG+V^QX~Tck|6dE@oe@z5V8J%@aPs6bFtUBeo=mMOx{2 zh7~eBAQ&CaYZ?t_v5v}b1mr%5J&gxbw>5n`!^9CpE|wY;Oy3Sq7cFQulqk!q!qxle zR9Ew!dmNQ1&*quH=RX{2#Zi=ahCyQDz`ELQtvo+UWni2FuXNL;spMX}Z|@ChIyrZm zW{F5p4G6Z^d3Svkjbjv7+^m;;FVk))c{-Ru6QoI8QXN2$Y1kqux|s#>@@O?#)v61n z3>&3WKg|lZ+lyTF-XYmGd_b5`%{+$P)6?7D8@na)Dg?B>M>d{LJq_$fKVu4OEV~M7 z9E~Br&U%+pF)}>D81J#|Z13Dl>7}(TSpNp|wdMDzfW6Lk_H*Kt;T+ULjG-HDOE+r% zWMIH*KIp~aXy6l+Q_A>Hc{)eqo0C*hT`tpZHUd|*DDt4Ho~j8yIem4$!^7h1rQfH3 zN{XZM^7|_IQ6;&yZz;v21oQGm(Mzl+`J;o|KOv{VoUf&_PbjBNsX9b%26FRprf}_! z@(+Q=)E$Q&fj*fMlJzv_?il{Q8ACD7 zdb?Zk+nRku8nJ?TE)O~jKZKq3#^4GdusGr@X35a6`)y>MU&O=C?fV#<3xz)#T9na- z6xVD~aq)lzrAWtQj&x?$g}=3GK$%Fo*T#AH zSXjEkxr|Yextv0kRabJ>Pw(0vU9{_RaAxgd7$kq+%x0K-^PH_#1NWQsvce0S#+$9* z{W)a3?&0}J;IY?}w%7Uccx(UPs&Cb5*IS#RWFZ{^7c-gr|5_qXmg0VSgX2$3oI)&7 zZ}WZ1Jmw=Sb3cUh=&%sH>S*VwIT@#Z1!RNB7c;EkL&WXHjka#tigF5G_ zL%SG1sLJfvAXdF(hy^NhaVT@1IpF;5)~>KaaIXKKd6$;a9Iuj{cjn6J7DU4meX);4 z#b3xjRo#>5n~Cs{5-`kZvDaxdCzFOn-;(xm*hFA|X`XJ}0a?RuvcZ(mI3PY~Y}t2x7rk9s56`%EtX(xfl(xvS2QrZHWGEZjv#h#NfVp*r4&{zTew&`0dx8Yf$ZG0GIy z6Xu$e%Wvlv2M@^QSATxbmuNO$`ogTZ^&ifU-CaT?-W>1IX>l*kZF2v4i$ihwnl%nw4myO(Y=S@|Kf?_%|)4ukP7pNpSAg*e>avi{{yITK zL!bUsCS9-k+a%F4hca`}r7p6p{=#>rn286>%pcPVi+Gk6-E%#}`9FL!>Th4{A}cgv zGG*#D^QUMmL0I~;=@})4DXdSSFPq|ha>qv=iz4GxD<y zrO_Rub8fn1V>Nb5RohO|RmRt|BHrgQ7=n8K$X_(8;Wv!ymyFeg z(Oi~dz;;&EMUPyO22&wKZ zx?uj)Sor!H#5i7?chb1g0(uBlP6^99Z&3MHuq}YQ8s}ZZ1r|3V!qKYJmBJ#k?mJo3 z71PiP4bTfv&GbeZDkW@(yw8t2ph}7{Tg&Nco0&v_?LkeL!fbiqZGiAS^3_iC=QvwH z)i`eY^~`k0r{7x1V1*Px%izS|TLgKe7Wt=bP1hz)dv=&`C5Cg&k-^zO@g z9)G{}{Hgp?!CHR~vGmf?&H3G`)YkG#fwq)>N?}xAyN0;+Q^|vdXB-=i=QYk@ADZaS zGzz#}+sWku6*p^mesWdCjS^4G*nga>t4YZn{MNo`{BSlhGMCnhG*wz6^u4>;qSv{Q zK@*&xs$#6-B^gl#lHeT96E8JZ0Wr{li2vSuo!<1~yj1&%*L-8=L43@?#Q7Y_#EZUu zM*hRC*86fR1I=7l7_6&!jYVdYybOrhBQiscqxpXGzXAV{0=Ivg!G)6DXUw@m)8!wo zE#^q%vmZdERrICvAc{W{-Jk!I+h5m(9bHn|2#yl##;T$i-?R3eeCN6zlizK?T| zcnx*3p|PG0>9)=HVA_N|3^+^+^~=`t3R<~tJ+_RsXcZt8b$O4g{#7UU-j3lUrxmZv zvb(76#WLaBzCToa+jJjwEC!cTC&;q=3l`X{mq^AEC*35O*1r)FviHd=6E`(3`<&VU z&q})r?+^R#1SUy!EyfJ1a`fA-fGhs!&iDFn)R(^2=<|F%7oy%m_lkIBVFWF5=j{5U zUrDbsLmDIEfSb@Zxp@R8VSg22+R!Fg@CIRzV@$>hBz<)IWC<>;o{RAuBzotCGYqm0 zwj0K~JsDSyJ6+AA`j^wq1B~<9o+A#?>&wl83UaFq)xxWi#3yzRhAQ0g zRBI@)z_$T z)k2e_f{Z?Cf{UHGOWS1SlKt38#=WB@b-2`8*K9aM5)w~ESNu1hAJ*{XxR_f;WccKC zOUec)vK!nq$-xVqA<1IHC-8p*F7A=q-AtN<$g`r>0@@zzvVNwJ4Bu2k z-W??yqx)+p%QQguYlq=F!mZeM7BBv{o(~d_?H%{*aw$_PO8DsE=lu96DYFwov4V7c!$V3wG(}|pmXiDvoD3+(e|GO{hlO}#L^sN&J0e7u z0O}#J4{ZG?zc=Qdl>AK0-gy6gp}o&ip4v*9J|enZ?*|dhA`6IE%b7RrBvHm$9{DmJO{0LE~Hq6wXL29WNVY*DnEbQPZY>M|ck)`loUdtRP450mv zs{M(gZ@2OaQ+7J#1e3nyNdiT{sHUu2h|vlG3kY-tas|B-E3Mlb#yMs=n#iryp3meDrMDsRmCmWIv0w|iJnPiEd?QYQ3@!7CvUzesiF zCvN@Y(Oj6L>-5LE{@^!OHg`2xp3K8=TX+lUG_*>&}8aXz!(LQRAZBX~OOpW}UOVvaK zx9?10n$)qYHPM;UFuH>B>V{e5=#BC@4o1=m0r*&PnGvxs>mR(hcjB}BpkjYtX@X@k z-m2mNa;x);esQ()Q?eIaFRkW=p4-5}FM)Ffd0EUPaJpZn`seTQP4sd|!M;Sc!`Lz` zMZq`gX;;gcoia96Y04lfbLAYX+gri>9f7}}lF)|sHFHKjJ>a%Ed)6n*+thNEakS?G z-_Zy=sxNbeeqdO;a{0K(WqGsaesR5M9rrUNHtZB8j@SD-JC-LiZwMZAkNMl>{>1jm zp}M8AZ!NqOh}G>Jgq4^=_c7q?u!Q4jnH4`KcZi}go2DB{aqy$YcHx+VAgxckZeX{$ABB$A-^=^;f_4-zQB{D|7X?7k9s)-^_c4rPei>9aSA%pO$&r z%2KMBv+(sIJ3J+d1@OtX8#%sNVUEux#->jSL3eo)mhV{N7&qNsv5eHrT)s8QDrCv@ zv;Bp1`R3<26gF_Mcg_$y6qW$lqLj08F54e%CWeJOE3&PtH=PelrYBnO4+1F&iIccZzOiX+1P zwPmhiQ|1YaFlB(Y6>~@vQ97sx{Y`4&?=D}M=Mx{RR1spAk~ec2*NjJ29^GHKPA7a!mO_y5Mw~c^ z0C{}6Yfj~IEG?2qstS9vW+b{fB^h_Q0FGXDZh}+ZqByQl=TdSP+P69`u^AxzpG3?uT%-CJG|)>{#IE!?6gaPi$|6zB8( z>BRm)j%~Md$3#glI!4hAIa1#HBLj!xoTB9@36NXmy(%WTAEenZ+Nvp927)lf6-+`! zAx%$c<9+>D+z3c|w(JS)Ec5P@%#Vgdz%xgyZ}kT*8YVxG}Ay4G!ew z+GTj<2J+A6)8C9COz&`wXYC|egja%St14RYAR+fPa2!xJ^ml9VIVjyJab3_h5dNx` z7-En^__`3i_smBP9*U`c*%IceswDzf8NeOZUVm+@4YYJR9{i|3^g@|nL(1wEaH#ZB zC5%+&Ve)WeeYS5sH|*iXzcA&NoJ1KKi3?vo4rFb^qZpNp z^!??h;xHyWkT@0Y1p)B9L-altG2BkGeQ>2^XRUSZbJ-byA9Mq zu;1nqsvt|a?~c!|Y`DmPxGi}LO?QBE(^Qvj$GASTPnk?)T&RBAQ*%9Bip|*Uu%e%44;#ppA`#+Jse!y%leNqL?c>ZIOS z^#cnW_~P67Tc36az!c;k^o5qeXZ2C=C@s6tCeE~2Y9Vg;uGDn31cF#?DbL}QO{H|$ z@Dg;`nOc;Ch{p`kp3lTZc{ch#`*$g<_&Z1tKKv#0z%WM$Uw$li?JS_zVc_sbMdH2b zY~Dx*KSK?Fj$rlR6u2|73b9ZT-e;GS{zlR1HM5)Z2M5~hitt&xoSJ8rBNx$1q(avg z&U02Xoq2XS@V@geQRU&w!=)T6pG>&DA^ZN)<85&QIhsdRW3${9py9G&lIzZS8iQs^bVeP=0q9!ZgdAy>#ZW(LKtUT-otS3gg9)|w zccZ%_=^AE9YGgf*mh1kZJG2blHS&PQnf{kEB=Ms;1RWB$Dw9g-fTNGB8}YLwZY6_3 zKkvH-Ol}HSl8zM*I@gezTTE`!%n~zCZYjT|AZse_52~YW&frJ%D&!aXI9gBSrQPe? zHW>qv%=>B_SZ6u}{rf9GN+P$rjjJAs#F%}_0JnH*8ySx(M%hyd6L8%p z%lc=x4FWo}F98$lr$Ydj)<6RBaZqUavOexPcbe&eRylLQwR&M{^u57`lPR2dtiIk3$@_m`o#t;p#aM{=>C89yWjzSN7hd4Tu+Nb|9stjQ6Q||#IUU4 z4VdUw2l57f-gPQ~M_Y4eT^q*Vr_a^$7N1}(V2k-fzx=|RdE#1~jwvK*m$INFCXXjD z#_<9sWv=SYKhdl19Q}!R;kh^4gq8Xwlk%&Zl?H+6JpRChUA}^Oz?>uTM5a13Q`Mu^ zBuDBAS9L#z8?B2?FvsLQ49wb86&W+GnQBKi|gYwT`lK~xOn}~pyJXRGO$2fv{rrHHA3JrGxdOO$qsR-S$-r z(f}I#@8?y8SEohSZBc_NlX&HBUf{y2%&Uu}iyAh5%p`u|U0q@W2q89@e&NQ>k9~># zzh7MaKk`8T$)or`FW!IvE^rBb?Y|N7;|9YKG$`Yc=V(>>KiO&j34!|jpW5mEt3C0i zDgSWqGY*-ufp>235k7R=ayb!p#Re053Ej5fw>ZM1K?h#_F+x2p-wJ&HxPSkc+WXSb z`*P~*+T3vVIWZ=xRdi-qbb48IZduK*s15SQ=kWye{V6Bb=KRMKg5qN+BgYCh+|+vo zZk*!pjIDpcL2w<&^=>)y{n#ea=3_m%OyFD2!rIKCfWIyfB{)v;F+aMQ^eW>(oW0|q0Nc7bpILNSpXV0|Siz@+N_UkE62&<336uf)z z@|$Qbfs9Z(fj^Ww58$2vw({Jd?+7FWNRI{s)*6%cpHUiw>a)Px63~H&sXWCCR+Q@_ zh~CD*%7>9A-M(AXdai=#JYI;%#zBxLGW4G|#@rAYl83&s4GQSWK$Ng+<;E80dkf48)s-O{K1UUV ze}n`Mb3u`qp^F*mW&(K(?4&__74Zw21ibj=SR)P!vhyF#)DE1>?!z;Wuv&+_vA)9R z;%WqR39%}fyKcF3mYIa}U0e;EjiBh;%!{2D+rAuG!#g}u>F@nV zb{UIiPxj_GWD@j)B)*!0Q`5%?Pq#o5QgFg@kT?EfEe!)~8Y5gmaL^AF6~SBr1>5ke zo;CcO8h$RNOTP$s9(vt90Z2vVTgP*Ecvtk6`cw%L7%TEst=G&+jLEcA)HNMV-qg#w4{j4 z8MdAvKKy4I2cJtY*8LDLeeWT3_v75@!Syc>2ptnR9-VqOc#;b{2>XnU$F#o8OIy%I z)b|Agc_DfqVSjJR+|u9x%eJCq-<-22)9Zg@zaDmj_Ha!pxUz%FM}CubLFRLWqjm|x z3~&}i+k3KZS+{}(VArRy*+w;n_yG6Cq{ue6#H`FqbNBBO2IW8}BE-b< zSdwME_}`^5Fo~+6BS3PSNYvH2NN9{UMi^gUt zHyNgnsMh_MKs5;1ICc0aWAD1xV15!*x^8?Fxa1@b#APEKn&$M_5G>P)S)|`SaywEJtlJ~Y za6GxbNEt;-Fyc>Z0=9wGIF6a^AVwnd`dmDrEh6U+*8u{Sc}?cens+;mF@%>rCI2BY zWn3xg_G1*8yX3v0);?`7IwLd{1#{q6BmEAL9y|jCAN2dKLWSUa>m3S9YW`qa!sGR8 z1>D1R&k$$n^;Pzt^T3H2Y<7<*taj+#X3ZOYj=WsmQ-T14D1W;})Z*=QIGKtD`bAfe zH=4F2|1;^8{ z>|Ihv9m@1ggm`kjf+kvxxZu(eZ}SMJw^4)b@CC806L$eL&{ADo{PM~Q@>oj5?0OU> zVsc%R5;48LDxg$)LmcL}hg9j}P{6rGE_$PbA}xH-83wG?yGX%E3vV=g*UxUZNA0WG z(Q^zp+H>R5IQlYHSj~;|=(1A4Ek<7MBI_fEQ8kRBLq!)w-H87*0m?##a)c(k2YfQv zAfzKjI8=la7s_aXIyWZgJ30E#j@^-$`$$>Jbod%?Xc97?7HTimD9UmC&@!*^JGwBk z%^N-ZpJ>8E%j0YvCAT~Cz$j6^8__{G^dswF0n1}QEu2H-4RTA#dDphD;Gc9d_ZdZC z2T)a<(2dkj=UJ)s^e}4U~_y zdYEr)1JsuP)U}P#jRD+LNMMLJeJ4Z+Ch*P%}f1hS5N`WrNEF`M$Nh> zm)VB!e;R{rPx)`@#?>Uy({kWxy4oz5PBwXg$IL@}*P_OF@!g-7I9nVpsEqEYpNm_` zfjeH*f@wQZz;a^UkpE2pSbwC+x8MhY*b36b09DegOLPYe`Ze+nAs(_T;NEq$DaW8W z1qs73SHbaTd((R;j*WD9!7mjzZAB@8Ap+let^)3IQbhsBkt_-m)(UxX&+)2Z|19&h zYA8NlJ>-+fL#!0vP|d^kARTVVx2*v$e~DG!p}C*KmxVVm(?1jpcy@|iia7=7G#7M3 z)jhW`hM9=V$Ey-n5CDH@!11-*x`SPSRm>?tTh1HZHc30Cz9bcMhH))Wnc{c4daMw# zLk|s3R9pC~5_9P8SAdiL&y`+u-Q$30?0bnAfD@BcZv5@04zi-_a~KQ5Zq zjZa=CH-~9{3dgW+F4#gd%Ozi#Kl z*a7s>0LpYkiVj}Okn)DD*P@I7{o;-Zt=d|B*&GZr8FCY_gy;)mz>h2;rh-5rjKX?| z0-j4-UWzu47k3#sd>OzCTJd2OSv^R?$ufwn-gGg}Hv-?iyhfyXUhtnH9$DtKrQ?7+ zmU%Tla1OuN6&$QyZjZL-ZH))aK0W~oc^TazCP)NtD$QiaCWOA}~ zJx>VgKm!7xauySZIfaXE95ow**gt$js%&x4AA+6!;?OpW`ivz9v&_#RFRJ$VEp<@M zU_ctO#1IL}Lbr9W0$ha(Zo05A8`1TeU*A#uCw^&8o)TsM+)CC6q8kXy>cMm{Kumwi z-7fJff%-%=+y1G;sFY34?oFrvk84H4^QtOqjiie-QZbkn&$yl|xCPL_b)cm16t_VM z$WIFXk3g%%QOI3j12!O%@Z<}wzGw9^fgh}5NQd&S10{Xc7if2Et<9-fP422Ok{?Wu z*s_>&J{^s0qF*7@eGMwL=HzQnxgZAU;u7z%z_IKnm#MbA$V)xub7@MeX=~e%>kn6| zBP^i!>~~M0wqL)e1gF9BgB6*M{z!buS&Uir<*n^d%J@v6+@PzTL|5DFg5}MHGACdZ#Es?TSGmS<(3ihDF&j=z%1(AR5qA%{E4S(swiFLs-M%Azz zi`|&d)G_Wf=;6d&Tt^QgP<|p0r27{vsk3Q%Jb8!{VjY8zNbHE}gxB!N*G060k&3qw zZrX=je;AK5iq}B`xR|@AmrS74g+?Wqm)tE-DjEy<;TWYN2=`+R%{&B~y?^QuOu46j z-AUF}QnUuv$AvTi&=1zrA~nmvsc^E{G{(G25nF}mwuj@u8^oBP zkZsuq@HRa8BL^h~AJll8A(BE1602YnfIs?hGu+uUGNqD-m2@T+b%OFp2prpsArbbn zT=l=egAXrvnIAwUu!_K`_ zr`N4dkB`6W3CSh7ndR5+ZxQ%!5rA*j(hb)>XiF0gCou4aH&5oMgn^h=$AGfhkXZ)k z^UYI*E{od~>!*IgO=+wLs0SySLQL2rha&c_CWg>x_r;zb{DsgPu2T>uD0@{W2@%Qq z0awD?|1*}3@bF}mRRjo!zPvb`o%iaooQ%5fX-}_`=2e4c z`3z6B|AL&Uf_Vn_@ctYAXAjqBOBhc?nLe2n+cl@l+(}@d{pi=*1Nw$kS;pLoPSw&<$hTu6Qu>?Zxg@EPv@X$n=BTNCT0&Smj;6w#o^=)~55|7Ocw z-0H(n&9c5#RdmhmCVbi!Bi^s;*-6Y<3Ja>tdN-#fN53k|EyvA^3WvXop5lepJgl`& zU|i9m(W!>#JXC7d=(Z?bz6N8=p#~)fvUn}r^_JVIUz8W~g9F3gs+)+Pr`p)3{OxXq zH#zHWMocUE_qaE?Mc2QHSYMH?FGFObsN`&rDc)P*}oGfp@xM2!`f1SX$ zosuVke`;R3ZtyKdFs_fJOYw+xTmvUtGG6ix9nlb~0RTkzeKGGi+uz@2*zogjI3*ug z&$DuT`k%Y>zgep(>0G@c)LsayCbMs6@|}Dq(_G?YkCv1B)O*spHvI|~M4w#T1h1{i z)s$4OnA6&tHL|-*Ep9FU^CZa6oY_67gy$23$L}y=Hj=lSV)t)vYW#aZO=10kM9l_C z?)Kr~EFCAmYVC8{-;^%$5~$%yO;g`X5~fGSm!=?m<~bZp5UO{kL9c#LV)otg$15WH z!@$|eFdqSAMe#7EeLPH`6}cdFw)Ja^pxD_I4#tWy64ciEX@c>xyD);O7KjJgL<$Zg z7#~~~Qh~d@-mL&+t*q0r{#se`u{hYrNb5(B(u ze^);P(T38$%kgOn4_ys|at2qn+Pbr%7sJ4rNzDrsIN>$8!!LZr+(IykKgx~~O}`7Z z*}Y^V$3>CjfJRV)?nNx<&qUx~_QS!pQ@r0TG}&E~n+#K;(BrZIfF}t$phup%bCnAB zTv`;oN)Cy>W;n-wNgPc}BuwQ4UjIe`B*qC#VL(Y>0-+?JEQ&delY1p-UFpzEGhyo1 zb$d8Wcx~$Gu2;V*;Uf}&(oBYalU*Uj9RdasTw!@iWVlIyj_M$R8%ezitLYaIwZYNp zSkA};?yGI2BU-ebP|cYZ=6k>+<$JCh9kNaO%@`n>EyJ zbk22ry9!`)dtA1%pKooB7=Z3>U!o;#vKBqZJw|e@F^leO2e6_Aw|bwzLgt2tk7lBt zfhYk+fmBKgwxo-5!06$V%*ubfg#hI~`Mn(u@i>s&QO;Q3@zhpULMbcT~x z$V1tXhKRuf__gdnfZ5ZL;Rtd(Kzfai4Jpcsta-0QvC0i*?(eDum%=*$qD>Xn?~sW# zVR;})=nc_l=pA^4@zOtW@xRZQNBf_x1zXegNqoEm?rNPYz(x-M%P^x&qc z4=qM}^W~pzl&o5gIdp}s`b!>mU!MBb(BKXm>sH}^|8+c@=w2BM$LDtPJbsS68$%F8 zl8!SOn_}AEDXo%SXX;?igSNTR;L$`cRy0eG)4pGgtPn1j(e(UnfqTwWrw5gDt+fg# z*BOO75;dO>5_a!hlg_^hu@6uo?DYpbuKP5;lVKp*V7+yvuN1gN@++>#SI@1HhSGY- zm~i0DA~EXAgNGt>f;iAiRm=gEJ2mE<9Lb6#9f&Ye{^Rs7s; z2moolIEsDy#{J&{rETT@=X0uD9ds8IFsuhD!7U8Gbd>xW)6ex_7wmsK@Vu{`BS;)s zZV^OY2W|eAYkw}?=S*ZMz?cL$R$_dGTLm>oZOVApAA@phw`5sjQ{27%#OA& z3fXb`4j1py`3Nn3laBIdfIpcD8ger^yRBrb^ygN4On?D`<6-e=)Nb%NZK@(}4zdE@j#(`pMphC0_&^mVtEsi98%>D%6-|Hz4ZeqJw z1vflB4~FK$Ma{`U|6K3EYe)cS+L($<#zU4XWxGxU1$Z}dt8iZfT8-ur#R5CIq>wFx z?s|yLk2tyhqWwNl)6+{YnA9mOh|&}N>KUy*keI9I2uO|(USocZxZ*{!tTC0MN)?Wh z-+?P`UF~S{Dkn^t)ku%8(p`CdX}!dT0o8K}G@S%?w739Q6Nm*}MgTXZ5FB?e_h&qD zX5_fuij36=PbJVT+z(?B_}Mj}{HQ_|1bHn>YqA}j+Z()oE@iShj>zsT!359OlvfZ` zkdplm9mYXaXznqAQj{1_97(7q2C)b0{j3g^MLN@*A05zr$dQxP30oz?rRH+MTfBNZ7F!5K-3ztwjG;t5<{$-4t z(b+$+XBc#@lkjL9*n?nqBf*=kF^n0Pqc5DvRT2eNzAwT(=rLxRyrGnv28ix}q%H#i zBP?2$T@VfpP+vez-3kh&L+3opjUom`g~KRl&;p(ChhtS`xLphKE6qFT?yn)GU?Dv9 z8!kwE;NH~Sq@^OZ3CF7kK&!M4nadM;r3VR5L+2_t3NEr5U?$H#jda2ZVKDAf?Q@kJ zKek;ivg`1u)9X+sw8qod_i9u=uA#h0Lv1?P1<2d3!8B)cY{-Sy>531xFiXU^a1uyU z0{nT0={4<%${PGN^Ov?d6*Ao2L$7;hbZmX7TjN}6*Xq4&AlH1*NEoouAOY~<=7@rv z)zVL?;159ZjxX0HKGwS?q=Y}jgzEM7?;0;{BoSnMR!tjk52UnyJT9cA-Yi}{@F#v( z8}hl2Qn(F{o=zD4lw)&|pkH+)X4w=GTCuuJc|F=ZPt87CpUF&~k0MEoFP>C;pf&$9 z?z``+h#)L4gHaFlz@V6~@nY8Ic$jR#rzGse!*3m`aqa#UGdkR`lP>GJ>DXXcElXP5 zNTh}D_|JJZhIqF^>%*1%eWX_DEBEL&`Fi$x#c4A9@6>&0Q!8D3_o_or6(_d)Jw?XL zx9UncD1I&SDCkq{7lYbO^TWf1JTIwlj_vpJev#IH;-+6dI$P+boE|^wIZ4ghmp;7C(lbCv%Z{U$kJVl<; zb^%|x98J3I!gv!)6Gxk`i(*_~p+HNe{>swRo=PhgBPtKS*L-A3`{GpUZypors0$va zmd7-I$P)6Xw@n}otZN4wnDYsruSx1GJr)dT^TwT;7%*xySVp&4kD^rgGv5Sn8vYXM ze#oKm`YL~aCm;EuN=`m>%4#Ms^*8z6uTsNyb*^cp)TK$f#X}|$(rnjDp4NAMWj+OJ znH+w}$_wx@ekYVP+=mCsI4@rD$|y(d<=eYa26msD+-ft}_X8jn9?w@Bv#!7D98-4W zzp2tY!A4!h@tb`MtcULKx#Sx>&(vA;g*l{s^m+5XW1x|x%BaE^6Owq5qTQ&FbS+c+ z9V;UW&Ha7NxxEVC@=Kf$At+??}Pni7(`cPvpP2Xf0UVV4?olVOD;v_RgP^ zBLY%SfU$M!%0Z+s$6^&0)Z54J-jPijh$Q}de;!}_XF2>`Mp=K!NUwWgH0GhYrQA0$ zO{0xTihk4Qsg7cbh}s6+7kjk=A}^pCtDQn>75R~epcko`=s*wS=kZ+?vX0!Y4-?E$ z;*+u0j8)(FEcH?zf0;P`-me!(X+<3|W^XH_IcUfBd&|=$nO9_(_3Jou#KQWBr~@xF z(uaK>U-#9lAwg~Nw4rkPA%D7^O3KNogQwY!q?&S^jV0Dxp~`+JnSK71lJAxBK;X1o zpZN0N?Wx>ys5sj&eL~&IU`=0NNyHQTzz>b>mWbDuj{Nn&p(RycmX&AYz^{IfIr?4} z3ePydednycSa%lC{sa2&ttd<&hCf0@%S7=BwdB=QD&9zVII+boR-VEc@e9FMDFKje z^~y7fIKWlnrQ}=JRo%Q$I{~mW3E2|BoQPrIq51PpYL8Rl zO5&a!c2}8Z<6!$2f7o`Nixq6b>)HjTOZMg`9i{r61M8N;>>ucv&Xfo$AC}2`4diSB zq>YbxBylDD=K{)Sg8^Rl$(sOqSMR+{5&p(2Q|7Pyrt&K@EMD$E-dX3)g3nTn1ilIs z*Ksx4N=2|#txcIT2{fV|jO{u28|uQ?bC3Gg2ZuM0USF#{+X>jK+(P-&CiOO4ln6w`cUECud81f?~ zABbBd=1VP>fbeVB3AhVUn^QM@8#$1ct1%t6Eax^Sb!ZsUKlo#~@KNt0%4Ft=tXn|L z_+8jVM^KqXW<%@GMU*uU%IG*5EXOZX_k9jzQ17f zeysDj(BpkWt{`=x>#eBCTSZyfE-DK@s?BC*w-UV<+cjQh)A$dB-`_TI_#QCwr*_O#xJ(58z(o`jqPOf_MP4T-uvV2&YbDfqtkU}x~J=_ucoR`d)Gd% zz-bc^{9Ph_Gk}CqSBI%Tu~QW3neBbbX*#00`DE7fM4UBuPeY@XS5D6@{PuAU8ERr187shNZ= z%)$Xb4p)k8?X&N(xWB>gPRrsHyvIx7A1b#ooy3@RE_1t&FJ_cW{sMVbw?%7-UcVqjWHnhvo-`!>r?bg8Rx<7mb_($kg z^95FRJ6GZY%krUD^^+qc54%cOVFgWVV0oChADIjRm}F^N-?h-sWNJBvHNG%6c;{?aP{b{#x6*%cui0CfI*U6m z-?M>hNAO|aXKTlwGgQtn%;Yc(+cR&zq3zmh7>fms&TZaD;I^bW$cx zW=`90?$0)6xLz96e#0HG&+`bjzRRBGG`3a zJHW;o>nm;T5f6}y=GMs3wU&z_Cy9hkGvX}U0gRCL&Wk2pXD@Ah7U_^U?sD`-e6gMR z>_bC2#avrPki|9Lqe?`<+NE-LM}sX$VC*1iji_#en2-7rVqAOW%kpAgP-g&d;QP*m zz!jnOY>->B>Xcef0r(4su<#_cqN(~6im=AD&9g?elFEsiSsG-{q|0{6u!W~!_rFM} z{E?(B`S>eU9>EaWZmS(f1=2jG8DXI#v-UX_m1aY$*y&v@`ZA>s=oZpq8QI>F=~p_J z_NRm1GC24GroTjkfxPrgSqAr$E^MVxbF`gWgNc?o3~G%|DK!RwTik~-24Kk+|Fy^~ zCyt}NY*|MQT^Xm1+_-4x)d79k#Ypthmx|!*4`WqfTbl9&-6}TJ$fkh5cdh5L-y*!R zxB$@!;bNcIuq_H*rm(#chpIgiIG}7pmNN?Nr?@U+1Rt$K8!bLuH#P6g~uP zz3~=NV}P9y9;HjZmf@0T+p<3#X7b1{TwH(zA|lqXI+aX<4zN#(wzWrOi=yLRX#o;w zbUR&OaXckJ%aW=xl>f)Wj`5K|dKm|OsDe$Dt4>!-xF#IFGaqpfE~n+#Ik7A}C0>f) z1)tzv^A%4bF&%r_)|Sn;vpMDXf{~Xt5~a~PD<@mQsg*QHJb@ubQ5a_|4(i+)raxap zhaeNuwA*}iuk<1!Oj|GA(|BUD7e|`HO!jgRaQUj|BqsjWA@>kezH^vwBQ5C2B9V!h zo-K}#BgBfh8P%X%NuNkMhwW$o??>tUwfQAYK?=9kV%#cP2;=#t;Sh0)vC?2FS;9>V zn7bbC(G^H!_ZVs&nS}gJ1&^|L77i@k&aRMt$%WAH_kz$4%vL~8Ng9x>p&gE+C4FdJ;(;R)&0~` zuYO3fBG&_jW_3Ei)aRNrrrra1UNhwoXQNO}BW-}p;!q4oruF`fQwCqo3Q+1BY2)&S zd-Xil*ppu(0WEA}m5fFumAW*o>b*+g+3_rYYkRV#JSw+7kK~%TjPu0xZQi9rM5{*6 zg4C3%g#4@k?Zw|)&sa7QSx2I+S&c)9N^`9&tJY0_#&vczLs=VC(2zv4rDEZqF7M{` zhn;>Aq6%by8)a}X^5p^S(Wyx+)j2)hqM9x8!qZs`sTK~_9$GboFFfryT5LJb?2WjJ zp}42@-$DyQ^ItwxWvX}$o&^{SZ93KUFb)x}G+3S{)K7E?1i-PD=YV;tC zxDm&Mtv%(Pql%2CA?FYbW-p2wJk_w#Y}m`BW;2q??xNGmYRXa!Zd$z#@yxd};<|E6 zJY`_y+{77zP1|zy6Xd;ib8x}drF&nBY7&~1`R0@?slAv?dOoCpz&cr}Hp0i;t%8b6 z3qBid8SE{}`31(sn8Ml8Q-RSawnH8*Sl*TKSm_zw{Aq8jmt^;iv zk|{+?-G7Qr#nrdNe`xGGT+XWOJgh9jYaLRU6Hf9%KT+A0YrCA=_~EIQJyf-jo`{CX zO7SBbLRrx6#9H^vmt$}ZR5i@IOo#p|fy#NfVkc(TX2RtnPAMqWt(3r1%qm>OCuhNE zA!$YE6i%-n#l*29v6jVT6iK!YX&UdFIj!MXpStiqm{>+}pv9rxyPxezP3aoXh*ev) z-k&~A`kE)fjFFB`NHtvzweWL^Ww&Cz#MTY(^{`nksPQhslf{%Qo4Qee6(7s8E_3RM zjfYE{Kym%r#);5h_ak_p3gOiy|L3lFrSeZr@6?Jz{RDB)WS*Yp?^FY}ut9%xben7} zQ;;^kl+zg-7pXl!?JKdChqU5Ov}d~-T-^D#5l>}E{np7yQIu-D6JK0^UfN?`dfOa< zPd`+ZdnoQ*duabS78#%5mu!goT1=7`p8JM+5@jFptySf4`TDANI{z?JQ!h{{`kVRh z8rjmS%qvnuUC_eLHNP7-C=Z(M=}3!w?JQi%5v+xe<;Ei;RnJ7NA=RQu>()zIAJ#&d9*mz+I>~1w zGjmm3(zjDIboQ!Qn18*e4>|v`s=(bmFL^N4{_=x?q7qBU=6B(+Uh;2mp0n?$peJaZ zVLg=6D71#3Qf_(CAU2Vy)}tYBbUmWQ9XjLrhQ>pXZS!%_Cia{n6BLwPqn-KnB}oRT zppEWq2rJFqIV7`U+K9E<-;O~wJQ9>@WEe6r!B`AQVJmXC*Visq_%>B|YFX3_MT$7{hDji{k&4{tB-KkNiyr0_`ojx?A$1%}Vr?oK-AKSQ|F00ZG z-SCi($QB$L0fp9d`V4J@J<%Pb8c8g8Fc(PLWOyx&OXblPyl`dGT7Nx|=2Qe7Ws2^Y zwuu?t57c^M8(S#w>?|vEA*Tbdjm`bR_2G@;5hTJ;oQ+G#UzX31J@D+WsZJ2a5P*r& zr)j_N|E(_lre}VwnHoBB*I6w9PF$R-FkgK`x6||2h5puVRl&VBdJ{3p|ChcN-SrLB zGHl2eCW=mK#v2FaaQV1}hIqGb<)CMkIx=KAjnnDIG=RnxbL`w>o9mN8XWZqfDeP@p z$7wW`3vH;eE6+rohZyxcxkq}ISK3%Tr-7D(#2-9hu95DXW~%9iM;-S2Bf7V@K<)HvvCa^$zxTIn<2U?i9`SoYb8IrtU8 za8>!VaQpH2Puz=sQjtF(@G0WP?|bO=JoBXFGGA-apYTBCyDr6Fk-F|5f9t<`u5anW z&jHw18#PbpyP&~G_OK_5FOGoRj}Tg!&Fa2y9n1PJd~3I!G9d%J?@!D6LxG z%yP!w?3bCar;|QUv#WoC^oj---?oLH!y~jVt3T%T2l3BWpf7s-QbJ6PqjFdmMXJ)i zPRCEGzk2l>0r;1F0_N|E#vfIm;w^oVPd~oY4hAVZ2F6!v?@Mjtisc4zC;bn!9hLs6 z1in4<-6wDsy;IM9`yu&zmy*YmHXA-)6s8eW$MDHQ3CEQcZLN|M=piVqlMp{~$%2BR0YUw& zKtRONKgIuDgnnv{Uapo7_Kdbx#*F`2Wo2MyVRW%_HKTVlGO;nTFmquvu{3gaF>^Jr zcW|~dvbFLyb7r)2Fg3GvVQ}=S;jweT?O53P{K-Yk*YLpCL~yc!2f_}M#nr*l-rW+l z{cZ>aYwbaH+eE@iwkn{P@U0Kmp_}w>+$H=;j?A5dJ^K#lQGE!kbl9|OT#i|DC|3;O zUs1v`|H0R&cGSGsA0s_jv~f zRM1avijBEty8fqbK7Z7i*C9atLQ_VAF39q0^;D5Y#Mx(LZ|?ZC70sW4xf7fK(SE$r=9064 zdO!S4;!+|w(*EQ5s_~*tU0F6k@hOi7o4_hO&IzTvH9n^qh<5Xc%cR`D>JT$wOuHPE zDFE`eB*CqZp=B;Ak~VYfzC2N?caf{`YmhOlOk*%=`5Z`tma@1(WJ@c99+Ousb$<}7 z!IBxn%Zh;RZo+i&>wBh<<~DH95LjX`$WLNkWkJ#X$3VkDE}|!$cp8EdG7zEg6gNxS(;TMi5U9|YZ5n)~;uOL91U>`nj=_?-pRxAyb%kS?|3xCMbvywjmhv*Z^ zf4ex4zpD{obv<+6$%Y2heylQGxB_J!U!b%UzRr3u1j+;tNfBqLdW|hksa;jF;;Xt} zBwDRfp}bAx>wAk}J>&i&3Np~9RFpv>Z3Qv+t4G^#{eDs`e8o6#1cR04y288xuGRS3 zJ_nBH4T&1|WmRSZCY2kYza?&2Z-u{>b>0;7eY=l0YiJF=7+Sgx_a!JL)wsD%7l*P@ zK_REvvQc4Xy6Lb^DEVTF)}2Zxz2cjF2(r6j9<4SCJxl|W@;mD|7sUtx6=ZhCluLx8 z!uSbY}dZz;*T~`=onbV?CV=I^?FfL^3AGCMIh|XHodJvzB^0v z^JlwZ<@*AA;Xiea(kG*46-2E^AyYR-IWj|&$*pnGc>`@Ia)|{i(9s5E$FwS;RQ!y$ z4};+?cX~tsAU+O?{I9MGzQw#Y6nDp5Jutnk89fzOOQzOAde)skQ!%Yxa}(c2LFxQg z+e&-wl(;AytmIyQoSOPUA&X=`ZqrYwRd4O`U58Z|5rTQmt}i3-@?V2Am#%C6*`%wU ze!T#5nPs20Tb&)s(L^pJRBy^wVg*h*j6e9!!JKGw;Dhuup&;Y-OLa?y%lMQ(B$z|Q@$ZGet+KpT z<6q7_D^a_*(8xo}UK;LUZ& z5w))F=6=+6tBlMX*BAPdT7il|GI*uluEg%Zoa%0dOzUug32I(cYbx_#XT6E<0-2f{ z(jtznw*9;zqvXeQRrg?v+Jbz3NaPZA$v&sU%|zm5Kgh;ET#oTwaWe{?GQ~}e{5-|; zz6!@oUQ=+GH%T><)~>@e#3}`CwP2qqo{Y~c&f z;>DVT`vvev_am>Mb5CeTYw zD(vd63km5ELJT;r=<#(_`Xo3uuh)~ZOCz+~B^i#|&gz;k zS2vL>k7%(mHWpb6vlFsZT=Uk|6u+CLhuWGiE8T|Y($XPPvy(^m{BN$R&GXnxb>#YJ zWFuuXDlVTNUd?ET@V>g86s#p0BQhLbk2d+O#A?gjvz(GzdeBFC-Wx} zk;Zi=T6B)jkx_Yz5*I4eRbYa5664@=iG#(mx9%F)2qHPE%>^RN!VT`n_h&SB9;?BX zn*c{YD16|`6C`!t70#7Hd=C^$oZBmxp%RYGi?hSt`8$Le{f(d#gvv$!W>4S1TL)bE z;$s@BA+!O&UGT4VGxs&}y?=Kn&EP4owUp?G>t@u;ytQuIIJN`ZD{5EPJa8i603g^4LsPRU4%V@M z`r}Y(;@mHPFz{45+Z{d1WB2GIg@aG3*A=J@`DJhjA@hYDq_vap91>k%(NLK!Wk{*@ z)gc7hTq{2z6%Kj+lTDSPPRFnHx^&h+FX3NLG5MUy7k0xg{v1WSrSvNhTBO!B!zLe@l8Pq3m<8-%MDegQSgY?KfbnHGjn! zJHbz-gx&LIX5$!YYmJzPk~!(wgvC2+BQefl$>tv4}NiLT;V@daAC*Ccg2k~IG!k*F1v%SgueTl^SfOXyN|h%Ey~-kXcK1We_wI? z^R+6OFFkGdJ+zWMsGfPTNfa_RHw9WE!YUL1kfL%@Vgx!0Q6wA^3~%fn6&O8XV^9_S zvCLbljsS&4jU2$Js|#SwbBWu{p*Odi4CePFm`^MD4T!%T3sKvqCeV~i<#@#;X;{(I zK*R?p)*o=xvr5nC&v^?;3+V5G>VtmE&q01--u2LhPCpH%CRD(6fD%Po@5$K<^2dgP z8BCoX(T)k$g@cxT2|i%ciTTn=xO6{F^=96%B$U4?n^ew)nkU}2Su@&{GEH&B-s0w> zw~bw=p@Z%Lsoojqg3nIJ`4%U&5n=I%K^XnQap!@|>t2~p?2RpSi*lzm+Czy@ZD3GG19#0NVvlIkFDoKQO5&>f;3rlbN;; zY!djpzG2ZJ)bL1vp;*H9iURLEIcP3YH#M=QUbI8w?iaxCP{p^!Sqs3@@r}#eeC_*< z{+3bVbOriCS$V2Q3B+t2Q#sHDojhbDB^daxVL<^K0&)8jIqQD%sfh*qkv-Vq7Ei>Tu7FFK4S2N1PO@fed@<1}ePgo~iMj!t2@=dVB`b&^c`Edb?DMN>Q*G-$@ke1pTri`{=hIWH%JlsD$g1qhP z!n^bX`L}&Ot~j_*?b%@nhE@KExpnSwnyfboPm-AZIzq6Am^^`vQ{HQywV(t#F_7`A zATMnR>#@`RODeH)*f^+-J6xRXLMHYuLWMSAnSLNTdQ~_lfMOK$$CLGmKG6Szkz~nt z(ExBjK$i4C{|!bG{GVeaM=u6fFGn-e9~kzZsO&$07x;e^Kg)lO%Kjf(baS=(-=ORd z&$%;h+j5_vz{o2{GBkG?)|9-;FV#*x>6C7Eace1R1ri(g{%ui|6%<3D8q?9o><9HX zIlnN3z@BRr6)d;?Q%G`P$P@n|;4|x)FpziJqGpXIq}!3;Ch<3iY0G|5xG0j^j$PXM zZ*UfFNCH@}x&&$z{NleT7%*D>qLUa+k|Z)@=8#DN^nduwgZB9*-AR$(fuYkZpTWy; zT_#0P#ND;*R#NB}YgJ9DBKM16MQPMAM{UHpNtH3nDmopJ>q##L$%}JZ=|BR|C8K9K zCL8cdGG-T-Au2Bh^!qc_LQB0v++l$XnRsvreTr4Tr*peA-Dk2+;&cPNz5E68bm8JY zD?N_kx1+YR;XdwfUH{=DK>E9{;Nts8UWIWIXcbH)dawx)yr6ox@?^Y89yE(OuyHXs zC_qXcEHv`IE(E_iKnV8YE2k9y2%^D&Q;;HSRM)h$K$_LL-e=EI*t&*9P|_&LA8 zELL?y9MfTIiSdEbz15M^Et%jgk*UEl?*C=Oz-;Rr;hJu3U*#`+(%(*FT=6FEUSQ_V zrtM{TH<+rnkMkBb#NQEDVa>bis$GkMuu!HA<@b}d*$wll@BE@DS&YE|3D8fGTar0> zV{YbzH&zCv7Q9a%tX(v#hl7kI)_>xHql6NKfY0O=6yA4;$D)B%MU$O7)S zOF~Dp1~l8zpyvC#yV{8EeM1poT0)@So^+{T568o(`X_=_j$2dsgnK55S|Vo;A-a4q zKC0SeN@pW&tNp|Rl?FC!2sjSlY*?_N4#&XzM*3a8tpSP2*4^)I()O0FGpRS6QY&AFv za~kl{4}Kg5k=bzvwFI5t2RB|q>|ST{^DL! zttMIF<+S$X?|7dF@*^UEqHB_!B$y_mSYLOM-Y1HyN?zxDxkcQf@tG5lu< zN67L!#82i#;YqVLoW<<;t$Es__yyTe6rNFLpkjB@X@S1v9tlU~))|;(vhHyj>=dL> zo}I<09DK}c)B^e`z*k?&#=93}`k=-Mm_UfC;BIzn@Ele$=G~oP4LV2^4M$Ko)*%o-#0#ZmXilMDP_3;$NtC zYFZ~IGd#_aLN2?is6IHeTcPIoOSW7`>xNuU4fDCLy8eaLRx{Q*Ccsq_ zORVhFw|M!;WpD1KDl74K;!M}3I`t>TM14|t4_INPO2*+~rN`Uj-isWry|6=~88nSz zi`L4#zqSn4(R2IO!Y{F{anN@(&(uE%$pZ8`JRxcE`l(6=Cwqz~BZu}kE37^eC~uBt zU+oN(NIhk*t-k6eT*;a=Bq`m+)>c$*015l3%{pP7m>q`cmaACmqogtAQ(5xUPRm)8 zJfDrCrhWMllN;urQ15U8rFF%7cIREQyu)>01wlMaUUrX4;Y4jZ)_8SvTkS}}^f+V-F2`G%SWF4B`lNY_?x ze(qW1WBA;^M_Lpb zz)x&wFn}DK*FT3NcF~E^GGr(z4Wu{Nv~K$hw%mxDX<@b8?n4vX@!ziseBSW(&`wl- zo#1TvAU84!9du4smpu(BrY|ARj7yFD3MR3_B<&ud>SEL8<9Bdnxhg~GAesF0UQ%ac zYXFFXL(?;o92DG}0tg#NhkXWwsU(5Bmn_*~%N}E^Co}COEov9wWU+5LV+4AmEGwA+ zUXqz)Oz8|WXo5^1c@le6Ll>zOVxeHfdHECSQ-;q|B9ocqlqtrWKJcq+a9#&k%sHjg za~URGrwujE;Y0OK?mNW%@Hrd*$~%iq+xz+nvQRX}u=Xz6rCkBW=?fFp>PbO|up~%*@r`i0qf@!6nMn>KIvDGi%lVEa1yFMuo1zvOJBN zmo2AA#I(z-*<_rSYaP;K9D8hJ@D*@T@HV-4&G>Rzd<@p2g0Xi7VneeOORt%UY2eT> zCFIF`31v&WLMDwa?K|thkWs=_F!O(34XskS5`eUl!5lw;P8*j7*|WREj>VKZF^*n) ztLw1Kng+w_qgz;<#j}58L5WM7;`Jk@aaw&DWHJhs)*1DVtW*^ixK!YR{-Z8N9*s*i zad&Z>pPqE{ruK!>8Op^-67tRWP-=lid)m!rxVUuS27U&geh;A|sXwoh3dp0fjuzyV zP=X%eUr5sT>n3$ zZQRYAU924Je|Q@e6_tJGTB>nI1$8P}dYakkxdRYrr;#zyj@w%p0F2D2_o%mojIL3g z@Ic;||IZPrJMR&2?o4tV8E=^^-N64VvzE(qq4>|9;?MS9gBqouv;Q-h=~)?A8CV!h ztz2B`t?bPm7^M|d)r95b#8qg<>2^WD{?D@;BTOHJ`Dx|nz<(o$!v8-xhCzv%xU;S?DO-9qdX#Kw*+XM~0?8sg`-9V>VO?=vP{bU3nUP2e>uRh{dOJUdH z!5Ly)A~7FK+PXVIxQk$~Gq#hAh4@ZpAqn*t3ghp2V=xaFC`&vi9Jcr8!+`Z<8lUyt zLBrQ}>KG0glK+k71!LPpJVpWgIcZI{Zf77;_z9`4r@SP$?o$`5jN zb)kQgL;mswQqV6}wyK2BnRnL|!X#@M_^;L>g*sl1*sU6sSb^)$wQr?TKV7kXthw){aF$9gC+46t#8EI7llZf z8;L4AS;Od;#*Yt!pU(WB9}e|-z0x2MARvaH-v3_@!v7ee|DOh-yttaMn6R4gMUSit zu521scfEmAIOiK`5CjZjbkTUiAJD{<&<Ts%IT2%_IRjtE<<^Z1hI~+CLivAMqLonbI5OG zEKT-m(b{xz)A|c>LF3ww64iM^?_;MhN@$L?L6Vsp#-nxe=!nfkv?<8qgUHitCT_qr z#fyix!Uu3u@7zbtKY)%`%#RC}GNF0rD2+-MXT9v%+VK0Xsy8|zJ926LfI_?`O|TIE z>LPqLb0}s?Aq4Ja&o^~o1mKX<#GBQ@uTC)?w+%!^wzGWzDMTFXic}lijste|^YHqo zd?C{LR5!9#Ea)pqV<$Sa@Gqsry(UY|G^n(Gdwdg#%xKx3@M$DMhy8P0m(DmEh1j_} z5;Vf4$Eovecs=3znCjh|0>5?o5_|%uFOz<&(PVSyW@4U58vkn!F&F8 z@#^OXL(kmx;`cPe5Sy&0wCUCMh%+nB@7LTBVp4m!I4LYLiw-6YvFxtyRuW{5n!P2@ z%-632v(bayq;DR~tZabJDsZ=FFX~m;_HJahR194Dihx?=8{oGdLjN7_rgUa+)UpT$ zUgf6@+0PpYj~KHkHZi4WBRMYf^R-~-1yY>&g^ICF6b}<@aZk`7Hhp+s8!0>WxDum| zAs=f|#fG=z+@qE>MCkv#8Sq@gdffvRY_aZr0<@bs(Tpjm4a9eDcyEC!uZKO&o-eRN z!=(q97OQxuN#+K$2R$z20L_WpAlQ{UWb4hgoaI@x%IY2yrr`b;w3!U z>mGK!#dIlJSDO)C?I51y*aOH@1ofj5Ugus-K%;Z!O}FMjPc(!kDi7q4OEWydBS|gm zKyzPzsYy;G>158ta0UP;ZoXB|{bS(-)OvLTE_cD`OJGv9CiDBj2)G`MxP~mei9jj{E&Cvdz7&gfqE zzKz)Vd}1`LNq3yw)1?q`=2DHp*Z@L-Xq=?$eI2^?e|I?3-Np9*IEy_Q3_QUqC{wN5 zUSR5|yW`A$HXCmg%u~r=%ceJsQr?YA#J1$ zxnt=s^}bC%OQwzYiUt^&nb(8&07FJz-t7D#$d{q(uYZiYpI`o^ss7>hoyoX$ynkJx zPdMazsV_6!jiNIn)Gx-iA@%zserwD_q$^V`uCpOyTP^VV@CMTlWoFoOXFnvdvT(}$ z=BJ3?#h??jJ(+8J`=r###e9yC_oCCZ>`=>sz@W}{T8irIDc?TR_i!km^H!vcf6l)U z@c&@@yKZzFdO5rucdk4WFiwYNqnX>jx&03f!{I)C#(*Qpm`RoeqBxW_myVb+zjVTr ztc--jC2?9-gP*nl?jubWNj35hy<{=IirKtK$kq*3%AtG;ClX#%1{@%>$+Ey20hOR} z%h5Il!=}jm7?Wuq?{5IJOv#`apLE6{4QD8pL6E^Sqz%{r=T86i_gmi}_^K+Nq(pav zd@knXdKuFmM(ur#HN=m%5md~IN1SIWv)$ASTDNdyf^eM*0*fN0E-s5$kIy-AtlqnC zpfK7|mbmN-P8dc;=9X{b%&&C~+?g6k0tm}E|GM8F56~Yq zqs9qtrDa?6{_a)*_*;mc2=3nvgn{XVW$Rl3FoHH5pOG`>h!$2HG0)>uUE8T%0=^S_ z7uTEIAcR`5c|(wEJ9+_4n|eNX=;a53&vPbA$&5S%f%=zHTghKbJ$JDm9giMWlm?Ch zyNHH%f41Kht;dnU^12B!(Ph*s=FhaGF?*KM1s#xXx1D=J<*4xoZ}q}qcKPz1BEeDE z>z~77=}|}anV|HQh?Y8*%ypgR{RPKF2|c<5%e7(yknX9cP+_r`=#DU=@Dx&ykzA(4 zj2%JtbN*CI+R6eW8HyHVx_&T%y#S*bWEVy5TQ4Bh|f=ALz)LokZUI1 zB@|sSH%~jlBL5f&5-gZ&muQe!WbQIVqt6SxoKP-?NV1#3jPn{wgSai)NVI}s%@$SC zX;vLQZ!t*H8lw;mJ6_A^nq+X9Tv92SE%R82qn2>foOAYcW?7L?RESMZoJ-rP`_(!M z4F!9iPoQgdo!THA!3TvVGYcI9LtGYAq>R92s~+h?FdJqph__aqaMoz0+jDLKx%X%z zIMFrW$sDdV-wt2AaHWlO(o|4bU=CIQIa5esM?XKiV_^zM)j#H_S#3MUyf~MLeedT1 z@Qj(r$ldI=qqlpUj-D*KsZ@zF9l&gZL3^7C<}l8p>u{}wJ8dU|{qIlo{>&dqFRAvZ7>Gs~>xa z3NCq@bZs`Wvnk9)MEl02Od49edu@DPjtzpix%mTKdlS$D1Sm#y^wRrDG9M4W8QT@W zbKM>##_1Rxjk&-p>9Fi|+WRui&q7egqH(Qz<_Gts=`VH1vE}pj4=WQ$%%s0 z`)jnKJFW|%f9-pgzOG;Ha%C;9C$uQa;CH&${~Pd z`9hkp{yYpolg{8Pcg!aw%5)ZZI{u%c<*`Ob_4usIOhp&Scx-Lo07 zjs=sXkzOqfv+D=THn_~p=#o1(J zA=~Z2o8!abL=UCnxniiYV*b^Y!6Si#Z)ex-S+cyM2M7OFy`b2(u>Rw}_(f?`4G-;h zJmj=`rRN-nRHpG`+ri6?-dqx=V3SqJGRRAUO5V8T`dL0+Wfkn`|9@y{_9)>p23wV-P|us&UW-$motcUQ+EimO!#06=cdLwaT+CC%;^qU>Bfxnb zQ3QlPt%tW?8l!cufMOgLctpUnRCabht9%Zp_^9FQ&%RCsBRuZSkh(>oxx~l~Hr>p6 zz(rGzK`@2iQ7|y3r9G2j8S|IO9h+t%RkJZ}{}EH4)d`oWhrj*&IEQFlTLRTiow@2q zCmAxj>4BkQe?o&`lz{a}*^U?Yb`dJhiBugXmK-r4SBZtVnh6tt0w!w7VM0z==v3;} ztfjh=HPgv*LA+|K!3`+Ityyn@Ro8(z>d!Jqg$ESuKGr2hcC?TfLt8SK#A(Dg;;`qN zvwB7(xZDVJjniZ}$x_pS!H|_|gi(p&34{`1?ayM^t_PdDyikQj&C+{)lBj4X2~rB5 zn+I`P11G9L%LlQ3fgrxt2k(v#2v1PkS2Y-A%~a+xWXso!ZgIw>gjd{z8L4Jar@cJd zWwWnx_;g640X}W80`~RurZ&@`QbkpV`es$k~u&2CEg>R#0eq zGcT;2h1R??F+k`K@)~3IN2+5Xv2-yk{w!BgRa1H~&cp=HbYm+$Q%PP!ztdaNM*StJjc; zR1Ryl8MeiS*L)GxDqDNdWl}mF7fZ4P6e+l<&;nQXX1|lO6?fvjh!roTVR9uzJIu}i zHgPnbb|ekNT5O@Zn)ORqI#JgBDMT&SzCJ`9^%!-}%_2v+DgPI7#$blD? z9`!d>o*wS73GK%Nc*v@U*&YbHVR2SVLue^5lXYJP-Ns#sweX&!2RlEnpCg@BjH|)c z9OuRb>*NjM`zZ$mAnA{_xKYI>xMa!2LJ4_PwOsW;F_tqyO^pgke_2#mk|Re>EP~$+ z-beyqccRYaNoVJxI_oaf7{{S>x%puHeh>J9#6t3V;Tt-*M-8zx($q@hN&g9F3B2gp zW%<1CCAek7zX|PuxLZpX;;s(r-5gXZSbSHc-Aswdwy9+Ycou3NGvb8OVB^^-CDR!8 z1eKtcL9DS-Afxhs-`Q;_kRrAaR{9i|iK1O3#^8F)49)5y+nZdyEukw3dKn4BH5Idbs#WJtL104t|VDQ2;J&J4!7B_QM2E8(xcp%op^Jy^EJJs zl9P z*wE8^ihWruBUUnZ(|--Vi(wxx$?tTFGg1omc<|p%UJ+%@h9vu6_!I1y=o2sn23~%= zmL*59@4QJS!DIquM#C(R1_wqsQJiAn%}@J)^6hhghc~>%d>@L(@Y0Tqu=CKK+N5e} z`rqz9zGe6TZtU}#rqubY)qJI5@DO(_S(+pJ_w3vr%HIX>>B~Y?Pf9V>p;(jLcjuBd zrZCI5+-`7^G#CPrCfe<)(rruad+dhg!wI(e48&&8c~J2|RvgI4+EiKD&f{E^SHE34 zPLR#GJpsW}ND|~|{zFcNyo-G93b(G%u*^rl|D|{vILYV*$n6uSOJ_zoC=qB(YONYB1h5MpB{mknsxip}gOmco&6!zOABFP(0T&>YXj_4#dzrbM0 zBdE_MXs}%SupmBBAhtmuwm+W~JTChorGsI*K>Wu@|1`oQI*yO{AZtsQ62qE{sgrG<=hd!P z-d*E1;91tEDZq?;{KQ8LmCf7#U#z`lY~)a|CEUp*6K2KK@!EWlB%Vo=h*u$7Q9~hv z%H+_%-xhRvv*MZ380B=CF-6f-z)Huys(6{ivOZe?8gsC=Fr!W{9%1C)7qM(A3z|4r zJU^?ww|3DZ=`<3mRzgo|Pp*TqzdqcB!lq0fW!sHS;X25MdeISYbGlt(Zt|-e9bWBb?c>in65;?-{BOmmRjd9L zkrAw=?t*YfT_6KDKN5R-wKl(9KHRE3RsQV2NKBzfjK!{WXev*CqFPI@g4UH= z89Lc`g42}__h|oQx(wZ@UGb41$5Q@ixkLtrHd-N7BtbJ&@j0&%vnl5+9scA(Jn6_c z$XGh?h0YB4nG`T?Y|+wUyRfrw>V#030>lfN`Ykx_G1xHormEDF3)<@%lftyfDc?+zudr_+AhvpW&hvl~0i0wEk;vbCQar*m3fy84hZ2FP7K48_oJ(|FfQodXA zG-#I58li;fGVOEj1DV_l_$N-cs^Q*}BhAF9CjW+Wt`nG`?HarZYS+C?vq!JXBF(8T=ea-k7(UEeaJ%% z^)04a0DmDAU{R|MsC`2V6J0`aYf_+jz0j-L@Mp1VjwZBSJn;#$i zt+_@ijczSjk>18!`~AJx)$C}~R2<=|2Iun1Ee89{+qG)-KFLs?|J>vJ1bumq+{RKj zj-#_qhYP%TlvC&;ddma~<(6|cX>V82_26DW>6@d7eA+&$am(z$GS`xW>Z}mUt~L2n zavqk`Ert2edPLb)#zR~@2CXqz`aweC1cs*kh%_M%`lUJ^9;l1|^<@`51s^h$_uG3| zl?+D*@F{)&jn+UORHJ*K zCGCc=|9!V@^Ag)-3!W}3{1U4Y-!(==w+nX2%5CfLx|1~ZLXxspl`^(DP^Qv`cIx_J zk2^V*e!zri>k*H>co=O#clF=sxzsNF?M-U}+e94LH6UXg9SW+pMyW`K4nncNU_!C0 zRpJ(Fm1{OsArTXvuHq~anQ{yu0siyIP8GUvm^IFN(z0PPzekQEiQyqMJTbXPXP8@q zA#%uU9Wk>H^>ia_plQ;QTHHgDJ7F}ZWuhTaoH)i5D#Ylh+egLp4D~7;gWr|MZAe_i z!&%6&?+QV)UBG%S-Le;9J03LNUKV=FwJ+{pxC)RPr?iqTSB=wmVbjSvPb>KDAn&nW zRV1jfl!nl;dy0gTHgCtOl?SX*oo6pYV#I=o=uE+sfeRNNhnl(o&!1g5OcZUzzvA|f z)=M3ggX=2YrR^PcZ;NFklXL}HoHT5wo`t92DC0j}L_CqNu z4^b!_{P}R|tgi2#X)b!we~|qCKQW zCO8ct1|S6Xuxi0b7v+|9hba7d|KVg3a7Ssxa;T%c2m}REzL+>kVnywLt$h{(TX~^Z zv8IBe*0APWH8(NqX+7mh*C(1A-Y3}zX2%s)f3BW`5A1HWWa#k*U4-w!9P_W-lt{Nk zw6HmYBjF9d@tZ((F~a_mcA>VNzYs&*vRcRn=eJccyE`!TW^~q4XX`jzcJ5hwZ!Ap*uee4CU4#6dgQOwMQ|r=_QS}9d$68+&j1&{IgMJxL?F= zHGC&`f^!&K#3V|{pV&=8Zo+U&i0D7Tf27sJjkLy@Ucwf`7r}(?Ab}bK_K4YByei6D z_$YNUUk_{?ojVTVJ>m+p&DSE~$-GHsVl%Jj0=w3SzA{zK6A<0xshl19iP5)eg@AnE zpx9)0yOpoASv-M-`IMTFefq(%wQ2i@>O)p%x1ubL&O%juYtvQ!VVmG-7E^7 zsSNmjaWZt`;^N2s^L92gb4AJF!CjP*>?$8AgZ~7T^xz`Zqd0>Rf#{*0b zs03xrIlD!*ZWa#oK0@7hvo+W|Z}Zo4y9%&#Cax`qp5wGC4#r;#5r^wX3gPxm=3;s5 z0>zZ)Wq8D+@x0LM+UU57=2Lah?W2*?&c_O;vBsg=&AGvj>Qir`Sck62hk%rsL{}%{r0#MdL_{nVK0Ef9 zO%Rcx_hWRs*vTTkJJX2=l)m31s+1!R^)I!8lUb4CX__;xXvN;KxAj$Ow zn#iz^iGJEj#~(xYKQ4Dne>O?QYr;q=7WT{RG9}knT4yi%iu%IsE@QAN*~plL5f*qI zIS zPX8O;n+UrqWA6>us-O>cAVJCGJ(v8DT2T;5%cEyh1uqN*Y33a%Rw#Ac`bD-MPSyU&J2 zOINK-;M!w+x56*y+(Y((dtsw zihs~0N3F4hpz)P%r*D`$l#(2-{*aKhnuffBZol%RPB>?|WtiVsP(|vhS`*)yXmA-} zOOULVq-{(3u^-1ojd&*|yi9fl)iUMDPYvJx2G(_oYh35?zW4iU`G;Q<{JU4_T=J}# zE__WsQyYskt_*^HYBkPhy{OzeI^-yVaC<6Aaiq5Dd{FH!G?i#*9n?FQnKMg0J&V+a z2tC3Ycvr4)+eMI@it|YidYhJD{a@YdUR8-!9Y5csH)RuF|I0ygRDvnf)+MDzbu-@I~|p;+vjs+JvWg z2PjYF$Y-{Ll8Sni?cBi_P=1A*SxTL?fp1oxxKJLI(w~Y{T^VrsSjklB*uJ;!?*lzsr{(eO zbK$JNL%W}Sy02Bv!#bML`^fBuw}~MNgBTr=E2a9!%R5NI zB8%}u3HG8YwkFqIe!WvY6@|EU!C!5tembX{x~^bRgOd$B%r?-17ilSC)zFMe{jolw7pGwY4KaDH`0^Dh;Jmp3Tc6xTJ+9;tgDtZZLQlZuG(FOc|4xV zja2;xp5#{a*_omF#xoMq=*Ay0M};Gst*4Cfv0bvaj9Rv%_iJ%J7jj0jwBL-cC0#GG>o$|u({P$y_P=GIOEEy+9 zeSiPajbUREb?=TL?MLW+>3P_esHB{$Lc*A?P?5+jy-WL3 z?+|I+@!~(+iB45a-cI4gCg~@x)P&?NmjzR2@jqRZQg?wU+&KS~H#Lr{4x!@tqb17G zV#Am zzdEc^=rcLQysb|}dm2!bN^BKjYi%zmU3U$CEv9HQ%Wu{g_sr-lrkg81D#K9!wWqiZ z!b&w}RH$i#?WP>y(u#zS%9@`6Ex0Cntrnz=hkP-2wC(L!X|=p z6G`=GQl1<3Pog6xInC(dN6c*|wh)|=MPcAL8^c#2C#g$n`uTz@yBV26=6U37*M%xd zdXRT}8A<_rrWGvbFiC~iY@U{MWXXe6_tGc&9l0xontO*A+Uakz(Z-vmr_DR*_0Hf$ zc`YJdwL0vYa+70UkKN=;Ie;EcMisf$1mz+Vjv2(r_-LiUA}ewa!O9a#a@gVj7)+Wb zCB=fh9^x9Yq?mVSLYzc(HyZHb`EpleM&eDd9J%-lR4;!jgD%O)km(TL-D*Z;^zpwX zR{{xut$7Dj|ovjxG!e%~wOaKxtKg?X9HOMn2t@jZGichRbNZ^f<*CUpNV?j{V2% z^tzneYsMyuz<5EMt|5NVS=hY&02%GHAyqLS>_bUtTZNie(g1G(yLn%l_aOU{yb|u% zJY9EXnfl~FEd^Z>%cTsW*=_v&+HR*xKksOz%g>Z#^c|RA$jl6AY=KMn)vXhgHDQ?A z@z$0{;YRPvPn0pAa%g*3m$42tGj`$>dOHH)wyJ_Iv16FGunk+Mi$i~t@3rUzy|oZeejhs$aHlO0yreXVGI1ra7)6uPmgyavTwSeT zK4$-cKl+?wv}yy7J#)xcg9GX|L+7{BKCDFP2MSxk^@IcH-I@=mDjSCT(rCXp+t-N`*V^^X_8wiU`G;JgetH1HD*T(mgH^2yD?PFl~3 z`?aGx6RzJDv>x1$8OLGSoit|mz_ud~kGB_7b6|K=62?)U5oS7G&&tcn_4&fV_4&ii z$;}E!;0{)LM&FIwkeLx?2UdFewo1?T#q-1qX(a;u6n$qGZl^DEF#8d?_)rqDy9X?J zU(Z;a5&Oc*(|73vW@h8IxjmP=k4(qpkX;o059>oUh^tN9J>qmb`=0@QH`nj5O%Cq9 zY~NGNC~XG5F5D#DEjaNZT1*{yamat_Nk>H$fF6%e=rq`=>aCR;9B@H6YH~+kNxv>U zyrdt!GdJ7D?vI{<84ls1dkoL~|BJtjtG8u*LJa`G2mEJM#4}nc zxmxH!NA$ZNDA%(A0oVk&{@M2gDE@~O;;YgKU7fkPm$G-Nsc3~xOHGSWbxVm0r$!C0 zfAwD!)nt(l?LpvX3ke08zqs}?cHss=JwK{l#xFW9axzqL0eZV`-hjtN*(j9oPirK9 zlCMu{xxPYh-D`oI{V*M*GO$KG=rOAY!VH;kb<~+>HqF;g2o*K8x`@@hLJ#&!X!JOj zz`?kO;H72o^jC-F6ZSyQ5uq5c8{@F8pX0S%vN;3LNaMvGd-^YsJf8i8GUNKwayPQI z)$W2NG9va71A4a#qTyS&=wCL-zyy{ekHPq9JhcIjo=6@3iXk@DYve^JMC77&5!7F| zkdm|aR&>D>>5;Vl?e|7c1Yx6Y_@g00yONb$BXtz}_U88>OD_SyGs+}R3@=$QzN-j> z1VRqkc4NS3WlBJ+zsXW%YsuT=Zd0L)HPaON91ABm_pr5*HqUWzsO*vjb*LaM-F&eG zel)|qw3@Ce1Sh7zXC1;=+8t8lJ7h05lGJ@9(ly0|6!R>j&nn zXoBCQ=l=StQ(G!tF~gGE_4R+zgmuT$&>6vLDte#$ncOI)4TzmO5m7P&w^_zMgS7*z z-yzg9>2%@)6nHY+S`0XG0)199q6vzRI3ko0!J_va zc-<^ib4ldNPdR-%aleQ^pr4LrtAp)|clYrWRU36RT|yp^;0$i$rgNnPHaiK= zxt|kl0kSY7g9!)iveJnp7tsYoB7HwziGIr5Rr4>Gj2ss3q<>fcT)BDV9 z)@O4Sov?-XJp|8RrF0Mb&Ej0<9B&vXHjDo5f+%w;gd^d;`5gnHCC{fv*t|VT7=qgY z@eHUbn0vi!r^k@b2ONv`)>vFS+Qt(~@?Tb+%XUk*>My@k@5IINl^2rdGczI8C@JrVYf{ zfymuZG1Tq;!%Sisxq&5Qc;tM@dJrOyg2IHJFj$d4t~gh>c`%a2N}Z)moA(I?sf^I= zn~iw+2{S2ErjHx|H0zTAi`M}nruQTtMJvCz7Z#15;~o5s6C55mH@z)!r$4#3zkH1K zl2h`x_i<=mqOc-3bRz__ljC*0y^L$%CqGyY1=+CWhQ*hh^GQRpNe@M zT>)wpuPwM&o8!OQ9kbRaCSKHR-yMV|tWlt(m<<})ov8fx)?Ym)ui~Dzd;4ZO@f(dB zS;t!>113U?FDXT}cp_IjeSZ;&BfBlVR@)%Cemnuc;QuEBqZY9wCg+=dvHZXaDfnYSI~C!}emXh!I3l_aD_Xy`)eAxadd8K#*T z=b2~sp+~3aXC7!4;V5XOCPrkwkC7gylskZylxb3upkrWTnGO2a66%q_nc`7^b|ZEZ ze0YO~ZhB)%<{poQg_+u|;sEkZGx_hN6F4J&0*`NplE1hA*k$$qI+smsogF=Z_I4Jw z&Q5gB?#^M~onWaarz9ik<>*FfC@7;2M#tz!WyeR#rD&C^RV5}RXsG09L&YIaNso-R zzPG`m{KR~+B>VsELmNc$!haLo_-~xL|JVnW|2iL>?d*ZpCaxyd|IGoZ|6$?O|1x{` ze-qk%=P2c2eP0;mKQ)cz|I#!IV_O4yAkf0r!Wjts=Kndz2+H3vzy@D^pv}l_k;|qd zvcofQ*zX_^7<+^+r53m*n4-LU<(pc>Rji*M*#Jd-;RU^%*t2;JrMDS!cYLQ2;kr|L zhp7OvucMaP>7P~+jE5HoA15hzUBTG~+yz}v23oSzl`)Pj<&xJMrjzc>sbz!r}Qnw6AM8Eu0Y1~UXr2N6aG%P{$XwA zdIP@a5)VmAY@(C0rWDLSYe{ERvW)eZ{@dTDJsDY>P<6B~<$`g;T6k0|S*&N#AW!I< zXne8u{a*qxLGG=^zrMkb;`cxQacunG!kzyy0QMe621e#4K;Zu#45R~~i+gp}Aa0#Td_ZRTOwEf=UCnTcC z4`eBc2&>j$7ps7rwLAr zL2@!>_RiLmEo!^N(3%=1-pgIOoV9~vO?)IecLnn~X;mh^gNahb4CT8Il^W80=bFjt z;3o0vI(6&2N?0dCS_@@(T&jk0cmE($vz_oz)}QBj9Nb4$+yaP8_R6? zJ#oM=15YP;YNtx7Nj;NT61S*g)W8JsejEVEYY40)cVd6C9qK1WGv#dO9KC zg_xJ0%l>nhs1uU{v0!%u1A}?2KtfS1t~Ug^KW!!DYx2meE9FC5IvfYEz51t%+)NwL z8Q7YoBg?*Z1gHc7?Jpqg6K#S0b-*m7GW=JOkyw-z9x*zw9ydX=R0OS`n6biCM^Swc z&&7;K5dnfnpR@rZ)mNf*V5P+z2B8Wx76XJ*L+*ja$_`4^pD6}fFx1_ zeb@{ges#KMrDi}|I_oY0y$C46v9d_5aXEP{q&8EpE4KWQnZs)A(fPcKqvheTgHY{0 zh>r&ukw&i~ubpJo)WPhs($u~TZQ0PAlOEuC=Q=5A^W$`?>;06z%Y#~RtF0{6R!&(R z1XdAVFkT#bxB9m`4FO2FMz3S6SzJs^GleLc8vVj)P^+hfVpypMXRg*PwPqkn;@@4< z^;kx{QiBn&G$#>xNSAqnm$q0R)7|jwBGXO8xR)sjnwjIZxVj{xCPU z>r1i19nGgmIcdi7!yq{f#=^y!L){r%ac(4!9n|*sQ;Y}Wc496mYR%CHzWFsy`^9bL zS0N?X#!8rnC#H|b%B+((|4#fj_$u3j43{n!t48$z@>}q%cjvlKnAntzJ$BAf*fd?I z`*6BFhV;%nA|k(GB}QknJ$XT#C4Wf#xR5;9$z$=nJ*ncL`T~WeG7<{V3}zy~cKagF zBfnvDrFZdi={XguG!>eVRrxSp-jJpFkoi(XuK*8r^~RMn;}sM=sdx2!4N=zlN7d!G zGidkM3fVu`Rvi#P^N2Q_w9KP|a6pu^VqKH1q~vgk6Z!~za(9znW>+1j|m zMV9T*fbi>vVu^r(890Uf9vo0r+Qh9!oh$og(m zNh%dhXAdcEBU|b%LW9|&X-D`v+g%MJz(aQ$japufW(*nzO^;$FWenNw58qNh?3xvC zQ8#w|y!ZYgY}%b^+u_hOz-=Nftp+FVJF1(Hcn!^|!Gnc=bfr=}T>>8yxrGM$)a5r$ zU^ntw4wT(Mdu~5_4o?CR4TEnZVUSHJ~I;o;`0yje?=vfUcUzZ!lP3tUv;tSCW8S}Fm&Ewjy zcLz`YHaf-|$26Q?*?yAzSQ2N~&zk>&_(S?jzQ*`q{i0@JX>ucz0?#i`2Bj+RbGB_fptHO%0ixl$ZHlZT7rY7#&tK`v=w0Rkd$!zou`jIHDL*2*urw ztw$M?O`{g5iZBmPSm%NX)t3s!{_I>`jB%?N3?CT4gizwA`hqX}Z_5WuT2&mp%U!y?S5Qe!35g`vsJsq1J+~YU5<_#!9ci`EYhSFYEw2>uSWwgnM{DQ> z(4MbZi)WDcCUWl98b7j{XwW?d*(=GLUW~a_{Cd;Ct+HX$J^#*AM$_QsLOo{N9FjT_ zq(}E)AMIq!fNaGXMea+qso8gOsp@l>^@sWjuU6^IOGoK7UEq+H9nj3Pi#n&-uQvTzw41<2ll%rY{KoVUUce?KDckv;OT z(FT8k=nHRiT*4&3!;7Ai}p zmEhBz{oPNvYx~=W0QO9vpK0y=xN*tXFd6L%B*;-0$ye`_(^l;jGi05`2l@Y;u)+qs z7p;HG;46Pmss3X?Fa7_Hsch^Goc~Wy75|UlZe9v?U`jW-<14oPsoujgG!s-?z(8V| zf&v+wpyIb7=`NXMU51+(n?^0~qPr4Dt^fs|ESJ)(7-Z-b$N*8RA_;VT1F6HST<>ed zclksMbvx4DCgGVnCyI=FE?X(hkL^l(@d$MU&8|tS-W|HCXiPiYTHn0lw+Uv@?YJCn zGq$BF%%U{(!3|mB6l`{Q2qLyjWKUp$aI4s<&iY(ItP0SB{^nE2ZZ8ltD}sDBXMZ

b_NRB=g0qYKvr_BClmgA?CD3;GrR`#gM1N?e!wxZQn+4mpr?ti zLA#TI+Qy`J7b$B-=k6a%_|aKGe;Jl?NKh4TnS_vPK!}}`g|gb!ao=$}ni?v@D`+eG zVEGQZfDO7BkzKbQmh1)S;wKbITdh>8nh(?x^N!B1t?4TshZ?*EH@C*P^6lpoYfgI< zsqm;u2qx=fLj%5bUOkO1|1@K$lW5L0rrW+TEW%z(^f^()k3- z{5m-H*I0e-jwv+biRg1H57ncv92B>+41SEhuH{xej{YkKx-Y7yowWI#ECCM&=N{_M zmBxHe?x8q#?6tsV<}#a>YgV%7o=S&80_?6w6KCdL&!OCnYV^Qnl(OC0926Mkwpo`C zq%3EWWIvS64dFbu4K@{no^{XOh+jbhPo&hJIR6kX417VdY;7+KGI6o_?j4jSMQgo}T{B^P3uph19aQ^(Eo*Vn;tBoyCGsj+WQ&5FprIZ19=h@_R?Z=UZ4k z3}|cYnZEXw&TQxntQAXKWiS*SAqv@%k#dv%Qx{ty3lz7zgAYI2ag?DTq+ErGpey*3 zQUJ}H7*-5AL?=tk;s^`PkU5qRYBK3oQ7_GDB~S&~Thvh#a*ZjMTa-X`Ox>#^BVma- zG>c9-W(5+A2TFZCJ&0?5=hmCmEsOa9j3$9kXSmJH!8WS>;F6c*CJuCr)+nY->79ay z_dD$`FWfNdydn&|l>n)+G(IAZ&lK6vpb|UB;5{*-8jNElj?I06-d^QoaXd?@_%+Yx z>FN*?=XpxJQH}ercEuY7a0AD7eoH|gw^$UuCELOuYIlqtO05ReFnV!9Om-VWN6$ni zgrhYx5}|T_1kTDIm$+bsON2A<@w1%};dSN{7?`Z#MZXBICx+KMXKE8T|;?u?B@ zPcMI}y31@zmq$cVn`)4iTuvl9e5s4~r8;!=_ty|-rP)?UB5!+)T#t zqvRG(Q{G+U#ah&Q?wUvau zLX?87-A+ zlpjMfb=^bUg2wfz#DyjP@#?PU2_F~Cv06oljO}t;fP>m4X#n_hRl-=y8GzK6TcCL- z!;l0X2vFh)EL)SmSkfR73nE{(QW(WK%YXU+{mJwEm^#p}Es z>1C3Bb)DF_yPV?Sml-z-d<3VitRD&oziMrbZHj=*GydAim9kV!O{078Bhd}mt{+K3b%D&!`@M98126<2lXo3b7_b3 zw)K?NX2$)Mfajsc{h15L=EAq9a^1g4K@RyohZh%7uQ8QB4d-r{qw`JGQfleuY3ZgQ z&y(@J&qYF4CjW01`QNNlE`ol{m%i3dgQd|PNM>1xzjGwF{Ae!uz6^BNysV$ZmJHH7 zDeN4yY;}1O?bni(?eZAES% zZ-P`nV{6M7v5cFG@LT$z@I)?$t0+UJQknsljtZxSrt2%5(Oa4iMTC8!{?QX?qP)oT zW#pQB?xyqrRix_kxdw`|MhqY<^g2;F?vul%(VU#ZaFJirOa4!vgY!7H_v-5-2xMhE zF-PsSt`ZbRDwT%d&D$J7N=IjOJAytTvbrUJnmSy4Go3+esg5;a8n-BH^XQNWr+!fV zfdLYyeqm7<0L~?kDN98zy5D_59lqvf+&DjMRo_O{P4Znns&dN3x&4^6r?`Lp#1^5d z6INFan+!p}#g1$S;pYe8m6h^3RlX(9X-Kzc@Ix5;tDP#97pzN69a;Q-dxZ6_5fMWjw&!z{npg-@kcXG zhPr)9FS%mKQI`x2%C|DBx7yhLlyA8$Cs%JJQ*ZMMX0U?&;P02&P-rU756`6yhwR+2 z?6v7tD|mBH;Rl+U%@4&b4;ywLEBvSiaSbq!&2Y0s`$Vjk_y8~ru>{lqn007Pu+2+dq8RWydAz^*Z}1^GP#xNr@H#hFXK`!9vVm0J}Eghzk8mOQz9%A-h~w) z3}PaRa zf^o&E=%r}WERUm04`y(+774M&qvOU7l`&eKIy{ohNf6+JKu4}8`$y9)Y`$qCUSaZn zv6>){QHi16lHd9`cVzURT#1*?Q;q+QuJJx$wOFOaj4{MKgVNYOE@D zDFa2##%+i7M_i|M@9``?&*{yi27u4yF`Q(NT2}xv9&(=Gf+5s*?AbcZ78LLM`OZ5p z?_1?Rq>6uE?T<^bd_8yD<j0 zQkIjr+NxW2O)1oL`IVJaf3fLgDzxv~yzzF+;C}*q!L;hBEZgt$kVWk3VpW{O4%|#g zI_n66PbE9cV+n4>J@)|>q99v_?OU!QbIi(W=D;eM zXE0NtP1V9XMr0N0)%iU!9fY^_Ll#FK-YTJNkInC+66Unf%ibx5Q7EW!dY$Ozs$#4v zY5PkG+K-k{IGwE}&c>MkskxJ%)qeDUDEr3XOrmb<*tRpVlZkEHwr$&(I8V%pIkD|z zV%vF=iEV$mb?bgV->SE}y6g1cQ>)JIz1P}n^I-7qIW7$X-8vy@cI~~UW$pWXqDipg zTtcwno;byxv`4t5&9(L~PU%lFYnrubi+Lwj*Z?3=xfwB9-)hql?0p-sKe1IOc~w`{ zb61K1j<;{`PtToXf$y8hzu#JCEOp*g{s~M5{#Kpj33YScfu7 z2QsTMZ3VDP%Qn*L=;eyVOwEq zuw+#B%satjzC05m%aB!@t7aJI$xq`_iO7=4F?l~7Y(UQ9sk;ZQ1G7EcW!`-dbsMllKyxzI^8hY8w>XC&itU@sT0k z|LgRrhS5Np{X)9)i9F}Y_LyCW`xqjXp|;!qefcK!HuvN0=K?oloGjP>2TRHGQ&uavO5^|~}}A5*<^^=aT)>hkn{%_I*c`cbA} z}|?-P%=awCItB&>FrdW^FFJ} z-Io3AR{@~kK*>u`E5q8ajB0;v{K^_(d(v#|=IWr_4eMYg%cQVyWWNhh&gOY<7wz1@W|o5asV8 zO#bzpZPZsbDq~pDYqQ^@sgBHR2Fif+8M|f!>4`e~<7k)?6H-PTEQwFb0+~njCRDVo ztzmomrS4UqbWAWT;~zAm4~#Jw7+>SVN}h6A?CJ7=+#?JCZ1}#Jqo?QQ-!PHxtt|tY zDHCsqQ;g~I#{+hgXH~h^9**@#7C^a{I-hrHHWnthfF^x-;eZ4xZP&UupEzv~W?l#g z0-4Z9Fe6`QWe=`G+EkvFyE@gF>Gam( zDF*FEGE3$ZT+82o*MbLGc~h!4JD{XQ*SaWdtE93n*IF#-PLs>#F{|%HwL6b`rucm+ zEy)ngrEVXOZ$yU!`d@}!m2~-PQCJR)mE=QuaOe9Fw2O~u$m5vygg8aVu5V6OED%bn zQN;xo!kl_mc^L4w$6Ns>fv7t@mq-fj8smspsNb$vlrjCW+8ksKU1r{q^gHsvF$B}FI#8IcrkHACjbrV1!|ld7VTaswAG?! zKRWQdRl0_*U3K(tIy|=#91p%_e>Kg+E}L-KSG#C`hZJvd{3 z`KMdwZfLEy$#HGFXk>(cB(+n*^)P_2PQ0>lrQcI}(ksVs#>)y-?1h}=l>=+hs#8)-$rRdL4RxsSE#a!HP|MV+C44WgV<4~s^*B2=77N%1swFb}mi8r%U$09k&*r2AlBIKs zH?sECpu2%lcrsyxjfuqxH@=%r2RK{HVZdKqPy}+pWVg|=Y=M=OdILV@;6CQc&Q{x% z0p|ymiK=o^C0JEL^6f*0n4jPsBUzbfY6Wr|j>>V}qq%UVC_y`-6IX(#J+w$G=d&Nt z9cztG7kSxb*a}pHxV~rSv!fiI%j(RIUt$|$6Kz(1+jLffHk1Sv|G~`9r&Mp;mOjOM zIvb58S8TL9`2_q>PGtpGR2LaS%4W|zC8YTlsh$RycW3pps;+fF#ik`Y1yD;S##f%F zm2&>>y?a;jwvatyunm#Z8_yJ8$s^|bdc3=G7<0?ZAeKwnsp(eF=F7VAx?1x*ASid9 zMx>w4euVVh-efN+E&QuB>VEfE7mGP}^gRCo_sWvq`^}XX?-$P^jczQ{yRa z+qE>H|Iuh+4}q0w6!)AnVjBGC2A>O1xrS=PpOS57vE!W}#l9S<^hWJG z%8l4v<7F;g7nyf;#rd}L$I>7OxXL7uOD zyZ7cY$2Z59t4y7Snhue@Rhd*y{X>7tukmTqliX32)X{}fV0mWeY0F32N1QCK=iPb5 zpRwHIx7P`6&C~#kyG|{nXskGD@ZMK#O$3z;lDe95r$kzkx zxz*T@Ov#5l1l9#9J`q7bF_pVN%vnu~!jh1T;}s*SQl0Cco*Hxc_01Ef-}zaqj0P!LA}Bt zUw|4WHw~&GM}Kz@uFfy1taVmiKEVttX%%S?XR8yV=^F01DWpKVJF}{@WJRiSZ{Uo4 zOAcy^`aZ#`FLo6`A2-2sJA<9u!f@K>bS~3gW4eRyZjq{Gd`Qj3Mp>uBsr6RhwX%}Q z^h{CtBjJYPwU!t$%_+ANfnNOQeaG2p>JLnxZe}o0UW?sZa*^?5aQ{vstSi{a(?e}` z(oXB$Y!Ye*~DBf??#yNnA-A*@VRAL@;CagW4nk@RebRR>EjFc z*SAm%{Op4ucyP>-S<_hoVOuoQUxHus&$fMZn}$GSM;6Bh+4b}!01MndaRprQ8vVXQ z%~Su#Qu-rFQ@gU(sFVP{aeS%2x&aYlJuf@l`^82DF?!uX3KMR1l2{j?Y(eIiouYVw zvyY>(lm$Vd5X%C}o-gyX#RTWjck~RT=CEWYhcIQO$Hm9P zDd3G(J=;#-PCH~`5$VD24RAzeb7VniwSD(W%u#YhQ;%5Q{9~bNj-Hh~&`2NO^cTlJ zdHWU&^V@J1zg!`e)3YFk_3}m(&^w-Ihr9qk!f`X{ZZqSm_zu2W@j57?h7sJ#V{6Jx zAHq6|`^hVnaD%eo6&J=!E^QFf4t|H*O4JsST$vtba#JHeWWc~M3D)NeRESNs zpkoae$uv1c4JBb`ZLzy4f@}5fNl_N^c@^&G4P2Eeb?;4Vcy#Yc!mG71M947W%lFqt zS1rq67E>xsewq|V?T)VDV#xOVF#NJfwB&^7h4})riIjoxj;VavIFLT~6V>Bjuhlr0 zx;U5Byl2wVU^x7>;Hb{1yRJd!QOfhWfC&ztrkL}fZRvmOcKfWdv9;XE&JE)0tKs{& z)tz;6qIe+!7HsMM}i7{Vp}7awaelC=wa8G@GA%Tsd?~68Eq_8a#B_FKPcK z%dcYJSa0+?bXeFry2{&G+yptl$gWV!^Y(d3Qaf!>7FXoCBS$BtNM`AvB+6`MsSVRa zXPo>4ZERW?#T=ESG*u>H#58gD^|X5L(0?Y6<(&(AAS*$jc_?o)+EYR-?fJ^K6!;qoo7=PGPgr5v}W9w z)d@0+6c;A7tN0-x>UT~L2Gx}$#unn4rePXX0z;T0rn3u%8a!MPjSFfU_aHB?4liY< zAK?FnwyIVrzbRjya=O!<=U1|R=)#D2)nDVqWzk6+T_LXx3MxphdnY@LTkw^ z>x!!94sAQsfPE+bHKF319Tr|lUVlcxG^Ld5-0^Ws2bx_w`+jT0s zox$G0*Kz_JV8!w;7Aoe>)YrVS(!IpSu)}6Y^6>-tyl)9$<4p_fN@OwYo9kGz4Qk@j zoLFzTZ2X-h*3JqI6UizGz&aA0-1$=0Hsto|?P{pay&o_>Zw7{AcmKRpVIA@~rFFV0 z{%+u0lj^(DEODTVhwNnx4=EbJ%y;yPaCcZG#2ZCU+;58VL{cUzMfbu2OHz_r@{IA4 z1sNtn7b)01&a275K!AHArq`OgSn>S%R1{q(qyMwMz90%{a;6klLw2$kJlRoi1o|?% z_PjU|kfWQ8=#)}lz|!iRYMe@BR!)%bU*4E<@%dN}0voROrH2dB1-(B9hEdhi2D4-Z zA9%ZzI* zF&LyI2(TamSd#aYpCYHMoI%sSL1$)y#J_fezgj;L+OEH*dqJlHp*=pX^4}eWCYa)& zr2L=|zS)~Ch+l?a=;WWt&DL77Fbb zi;vvbmDXaRrH}R3VWIVI)8!=Akk@KQpDVA%6#tg5rR3V2oWOq?$CulOm7x`)ip5n5 zmgTJ9$l*@{TjHk6m#Zc6K9t(;<8N@7S~V%x;{|7kxNOEFbNiF}Ali1+NEP)lTTdwj z*HXisZKQt*3j^~8_eXZHLlG9tRP^Ybpfo8i{+2HHm8BBo7i^e<-}$#^t|wOZPQP)sW!-tl^(FOT@bx9 zccCXd`v^i?bq6bbTlWEhXYFM8cp(JpFT-yOov$w?S!kF!kFJxaZ}$l5`2S?N!~5S` z?s%BHxLP|p7#cDOC4YTrrz zIgdjWq_6U0}C))kH=b3FWj*?NixV(OFEVCPl+pp)(^_7k)acP8n z3cNRTHYdr@MU4*3Uxoevu>ae03OBa^`0vpOjo*)wEI0%P2+a2l0zwk~{rdlx;P=YO z+s(?+fyvI=gz0~mtc=VoOs>{$<_u28rnbhG=B`XG=FaZsu5PYOhSm;l<}MD#c833J za^&P4t0wQbFNM`m(Ql8nPKWmeijf$5vNuPdTCu zMbi{S88)e1t^cs^-hMDm(Qdbqj|pb!%%*jamPBKvCF`7@#@TT zb=0SKuhO#V#jWABP0M4bf9#ipQwQ)m!-#VfR@{)E<|Ib+K>}^$S{@X{4o_HNS8PGK zuWnX3j9C0bN#?K((z#;EglP6Rl<5`pg)M{?YdXHKU_6`Uh}a-`l!WsAZ*L)ZJRS13 zDa%PSh_I)uTeQr6d*Lj&kE}&ATs9Pquvm?zUgX^tVTR3Uh0*VJ!vgmOrWTfN>{*UT zg3bj0;4tA4lZeTzEF6t+}|msEF90z0n)VC(Fy14=+NyiB}lF8Xi1N3C0(F%#U5K2e|hJY7o2}|NE0ho z_X<+rDyS~UXP|gf{l~0!fwX1Fkn;vx1=~q(nNV$B7Zw_{cJNv{&a^Gosu41m+!1FV zPjHL`oaG)%NU zQ|{2cXBv^(XKw3>rNv4rIc7WF+hL~G`~PA8mwNIf`ul4I@;||z>%WD)v6->cH||}( z&zW=oGgo|0z_aHE=5w52hT9xaGQhoc7*3yJVq5}q^ilfOVXH)ioNIv`6%iUC2zAP= zG4M^DlL&kgfnwukS-|0;pYp~EBrc!`)I!^%aQ6tRX^xxeWjbh{D)8bnH%HGg%tBY2 z1G7$KIU+`fwGq?;qxM08cF@n$f@8Bz7CMz3kBt?OT8GA-bKPO4%LoG|Qd#g*WSK{> zzda|4p&!7r-*i7%x_wzAm>DE%feCPeEY{oB_`&_L1apzHQsnFmoIXM-eyIfw0 zHc{*Htkf4jVqCMQO~IaWRs3f<6<{+keXdtCjAdq8el38rV_?`@6cKC7fxL5h=ApcE zE0eMV#?%`xO0b`ZnQ{3>jVDQ7<63zo(qt`A_AoX zzCi_)9Yl(DZa<#+6EX#-GaFEyqunbk;|Wy0EiIjSsC`jfG$l8z-)7Ychp)+K`#Z)^ z+C{qNnx=afRW>=AiXHN{Ywt^40x=!oxVDW)QzMKs+6VltoQ)QZ^OKgBHd|>hoJ42q z0^HYR03bp3M2XoyJy4Yh3b-7b)VFgX5l|qArpm`Vv+Mc9MLqrZ8Sd!mxtk}BgY-XMqFPq zTdrSD7noT!JnOMGN4$`!2NWr;Dewv)b!(_&Kk;_v=tc`)7^v%cCh5u;?x}wSME#H) z#ITFRMRwp><}+eK=B;6O5OAagtXeu;vbmDjw(JN^Z4*vPEY~ELBbMiag^K8|AS3E> z6tdVcO-9(k4*{CFZ#(CJb+Jv@P6v}&L3AOzaAovoO2QWHLxr~E4J9dl0pXhb+=OF6-Lf);M3v=equ0VrO|O!BMU|_ zg*F2xF9#)TSa+OMJKfvKgVI7iXs()0Xw6$%` zo1kig+4IsJMXuO&Ha1?kBsoPjnID9=z^JA)>Tb%BU4P^`MRZh;hPkTU%pd6W3cNAk zbi%p3KOg0teGJOQ3RknbL2)I!n-Eb{;<>H__@=-{cS(1Lg2A4bN#M_8dL$xoiC}R9 zBrSd1{6*2&gU0?WPLwLJDXin21LPyah?f`ntYdFc@MRAXwCM6MGbEO7j+4EXzp*bK z{`yF<;$*Ys5Hm(UQNt;8c+TVXuLhQTb#l$>uDv`wb4C)cQeEt&W37N-M)afYqNspT z_g5Gpl|dg`Ht5c@l#*OVy~YcIwA;Q^Kt!RDNcR5toB(G2Nj9eZg;)c9XGq7QzHi*v zp`ua-f&GWX63^;&&pvrj2HK@gNkVxh+P~5m#>HA*NG2>hSg9yHn`BSn^di(O9imlN9jfk z+^Wvz{!sQ7#D~_jM(TmZz-+LEDrD7($w5;#aR8uCrBBw7)xxk-@pX7$Jjn|2UtOpN zEE^J%=u`*YL#cYxtgA2%5TTl3_aO|n30=J27*eIK&P%mn-bz3P$nQ4H^x3@XUB32k zMn}q0j|R!Pt8uBnw~eBUK_Y9^#Y7WpmXn*?V6K{uxw|6qgk@phZ>3%K5Dc*d%muU- zhM~!)dr81p!A_P-;8Xju?X{5x|0+Hk*QWW)xOXaqzIj3Wijt&DmVhWXkgtWn##&exa9_=hoeNWbN@^Na0iWEmI7nPG7xMy@CA z?xoWah&ED$JD%f7(bz)`+3+e&Q_I<`v|+1@U*m0ESMuz}>vDeko=^hBH9cg`ZJ+jr z2l}l}(V`w;l}H?gty^sr>B=z+e^z3;xHsyDn7AA&V~Xok#OU)gal~hvTIqfY#~AjB ztluJ=Y}k=S%^8vZnzg}ZuZHfVx^8(N)C*P?n;P8JV+W6?$2Drz8Q}rn#96(Ri#H2D zg}jMPNzga9$2A%jhota*_!q6NvdzZJ@0rB8T12n1RdB>E`qLZ9Wgsr|HMD=b*JZ;$f@J(f_k5%<%_`dQIo1qoVCLBymhv z7FA0Lt`m(k8Dv7HmA@^?tEy1{x_@p+bP5X|E`x!un?zFKWD`n|GF($5b)PD z7#;QSysE8gy0xKV>UeJ?W9xn_ITC$j)PS@dWQssvod0(t?ppz7BI;lIhD$i@+94js zOwX5Q!;{roLt!qrVL>Du7lw&^W2_!`$sBi6o!nA~ciyaFnDej!o;s`XMgy;@7Ma`z z80rpk!nTUvLGY8wNF3L^K0GAAVY~w1Y}u7HL1?0CzWO3%DZn{oZS&FwUltbgF|nUm zRLOs1H%gn3=ZSg{5^cY*fXJcK&-Tf^yyUQ7yNNZIW_Gf$ufLr4lN{I7q}^wE0Dn}i z9jXYCbJmkN$McS^VV*6_@DFb=G1b9pytLk~ry7$7VcuIn4D|eo(D5%P@HsE!Roq%) zyp}z)VFu*b^aE1?Igj%K_CG-9RWvxFY(L~p1<6r)x1KTW;noR2qq-`34W$CYM%zCH z3{K2zb2~m_vdm(E(q<*#4U2JWmyOihJiwJ@SOUmc@pL2m(SfnL@hLERALYg(6rIP| zQH1XY`}8Hor2x`GemPAd!5A*Uwm%$uXhvGwh;%57`d{4 z5#}ge6YF{XFQ`Rp3OOlnINP`;z|o+BjUC-DB|8*7PFa=K=|Y6KZf+bJy2ppy?-9R+ zR~MfFrim0#n^!H6WKPpYUebUlCuP|d6_5(!(x4k%#>y09lZnC0>y+HUpV5u@T<0aU zxSD5B^6oM`)Xoy5c3kpso>}45k3pt8hr#+`Ye7&Gl#jc=xU?3}-ohUxC(aU3mPA!} z()b%QJX8a!vl;s58#5vSlm-jFJuwXm7=k;YtFhO|t@nDVg zjm)`etVOItD3IDQy5$UYfuJ5G?sB1lfpr1U#=*qHgGPUMujllPn`Md!RA=k>Yckfg zkF8mJ)a;RXGoTFp>Xaw72T&zu|G{R;@ur-dbne_jzhXru@tXxgrP>ar&iNX16va;0 zH^wW7vE)n9d-H~sXnzp|h$)T!=3(W)=K@g-`pMIaEO~eH`}Z2XT>Z|1y!SuB`|PI4 zKr#C#A202n`P07kkxRb4`s2seANnKh7l#dmDsr6zGdr1VsK-UE6uACres4!Z0nevq zaiVG%un^{YkA3CM!_>)tNAK*Z1u=I68;%0H@NXvtg@vHK_=P{7P-ffg=zc>_Qu!YA zwJkTGV64NB!M8o<!WEPAg&zbt+Lf5fV&0(6nf<>rnoEOI49dZa{3MH6YtEmE{x7wj>T-d_G_ z6ZS1I1`yRqzI8%t$hhHJGj<7NAQFoF>Igz=QfRYhs)X~bAQ9M|w1j~Ox%b8x8}}*+ zO7}RKog+tv>Eu}Sp%edwE^dH$GaZdo8PO1{GM7V-mHDZ|PMGO9s=I0t6Lrv}>;aqh z>a^RjlFZQo5cloaww>pGibNK{=f5Q!{aCAW0^B@CD=@u|4}4WOH2#>;C}ebAkNbJt zgHl^^aA0LN(7+1ucTbvCp_4$epy zK@>iD5*VnqR~SR_xadqCSL^n2t` zl!~@OBr?1=*_*;@XbVZl-F+d+oqDX;ZsME=>*~#{=SVrZ8Pg`(rfIPph1%rq5ETxD z=$5S(UXmAt<*s#`azAgKRHU7qNQd>14z}O~;cK`2%i$R-ZSI_iB4O5K$30* zzTI0tcf2feq_DNh`lB6Afr?C8T>HW8V%k!>NC>8?uHXV>@|ErqB$jV|wb{vM0LtLQ zWaCW`f=#>R;T}Wn01e3aE!!kZ(gUSQ5n0x;0&lKBk_#PMtFUlcnubSh(HvOSm0Jg_ z%4no+cGAyHgE{WzucfJWAQFmSFB{pQmz7@F5!c6H>UzzX2J6_>3qhOLXVeXojtLpi zhh&%Z&tg4a)iav*ufUxUMB_Zwz|6|@|WyA}KXMQX|BZYYa+q0$45f;3# z3g2DN>4(Z@DP9z}IZwnxCU-{b$mB?`b)KgsX_$qmEcg4L^Z0RiYHSUPv#1P;rqd5x zMm2ggI^cX_l)@kSp8(9&86FT9WA#bE{xmPSR>6|RTshU z*o%b!_7RJ9AGLkHDijN`cf#-~z$b{~pf)h=_a`jNBRYX6_E25>eaFPLXUqW;t+?vg z8p-(#ps@PjocTpkMp@EV67u9|o9dZGWc^Yb`0FzH(4G9-ni}BtfD2n48ZvLKq_!Fs zrtP9H(DQ-k)z<7aDDUv)c@9VujQXT5V+;Pf9y9)7s!yfob4We}n5T9yy0ULo49|C7 zi6b9+y52GDArelsVtopPpS9FO$k|xHeY;+Ocw7t^IKF1Ye|qci{ktb0S6~`|U5R{g zqOn!KYk!pcYww4{V-1*DrwRCQobJ$fF^IeKhko1Pl1wE-isZmjX1An}_GMp7A!aI9 z<9m;lJD}`mMwbw-8hC~f01g+i#vX&iIfYpNkVsc?iI zgW@H;E^axM9hyk|BFlj-I0@*gA7#S!zinP-A9wH=Pd|~X_fTT?3eX-Y?vuMahy|kn zeU{532*^1HwirE2R!)~swCz7XW_^{!2|F|1WUNw#ipYch4chTZ7#15PXy6(Z z{r)6&cpq(1VFNYD2n=wX;iXRrv|18Bz8(QY7{61UP7SX$J^O)~kxN2io~t zjt!g(I6yV}GCki>hY7K_Sp7mKT4jAwW>*LGiRZ`m}00l|Ocp|=6YB8;$dJW_fw;qmxgzEJCf8sZ8^g$+)7X!56=8s73N+c)YF z9O)4S1`qPIqcKwQbWsioQm4B36`D;KVtBC*zOuQeHl`C0#<>qiWe6-VY(=-5Y_wcp_&t=esjJ^^;(M<`gWg*GMM@)Q)=G|iM+UPp9X_B< z8e=m7+2%K7^=E2@0Bf95`KrFJQ&AXWs=aj$ZXI!lRxhTdxRxW5?XoQwPaRyOdpoS* zU}sG3Iu#mfI}u?*B1y(Av47-AOigL@|K?heG~Ce&4r$Q!i`oRg=;bU+4>k zn6d(aQ&*{}qZe@cL%WQ`IGlcoiR*T?$BcJnTdguf9cOF5+Si2x{{9v4_gl}1Q`^UO z0l8pxK6z^^`hjBaQ=#7uPP2&@r!lfRhUdK)J`8*7l z4$|eZPU?19uMr}mBn+Fv!mo%nd9mtuw-RAwNd-FsXINc5n>YIOPa84n`FN}(QIRXwFFi&%UGhf1G)F` zoRD91SYpg>q=16t@Oc=OZbz)Urtg=f3K8Srq^t)M8QV_B{Ti=n#+Ik~AkwhaxkRx^ zSs8I+mnGc*OcSO7`xZ$K#&NE%4;Ze-W&R~_n-bIqHgTgCoO4#49X?@pG*IfWG2`G( z{vGlJss0I{woW^LI^cB4wOW~U4{45hx8CEDeYd@lGoHN>_Tj1d)=?)ZBYHdVw6#n1 zzD`4Fa`Q{l(U7+kuS9TokBKl&x{Z#Ve4AIW_a|7%CE(T}|6oNJN=;Jc7;k{$z(l{gy@J zqz+5Gme25(;~$;v`9LJ+BY5BnZ5kHwn^oa8R7z4(TE~BgOH|ViR)q-*#oQqrKBK>; z+4J`&=l>DLn$tLfi+CU)yte;|Ib;2=nKLKr{~^t^3>|@OsDV#qIBm!+*gW3ZkJ77% ziSnEBH8JuiyvL%oTJ!U(`&p#ThN$G>^LzLb%uJ8L;5zfJ)XRfuN8p8xJxWjbT%;NmYU;pkgkJ72J4Hl^>5DPd*_%|26{ z5uW2c7PN;l)#ok1Oh@NJZ#T@+2UF34_JORapwI!U+vINAZSqV{7Yh{euHM08YsOol{xt}>pVE+^gZ28%oxqV zFb*g9(V*6N)GVH+SJEb7TLp|Ck?;G}w}sr*RjW2)*7)go)jUY-`tKbyseWDhIv_E4 z(-`bgZ%7_>=Kp1ZGF99Td}w)Y`^>JF{(CFIqwERBkkpn)+Jc?p`1L zcION3s#nl7H2K3HV*e`w;=YvyDx^|DDoepSn6BV2Bu1JS$gz-YeRG@m;ltbhu$Cd2 zX6HB`5Hjs^QR&{(eW?rYYoE_*y`SW^sH@dIj-Jm6_a~!{kjJ&ardt=6{#!o~BBN=&codS_6 zjA^G~{FAO$9Ni44PJz9G?ZNs*oyYayxi7zRzajcsFa2a$+oIg*W^#TEgj2qxbaLYr z_$vmy`t=8~=`gyafjWc{DmAgzlE1Ql+r?3WD{Q%E%g>)% zT0JB5_+r?^#Kf(ky1u*9_@O(y9|kJC6LA95SYgd>H7#pyGCQ&bD)!3@>>YE(Or)Qu z*8@8V+dUtn^?~QmQabOT0_XYl_L+pr#00_an=ch<)T4+Y_6QP%FU-ks9*oVyA^U4u zt0owuj?L6Uq)*|ar+%T+AvMm5{E*X859^Izc-0Pa@qxgR6|;iA(@IPUw&q{8mnvt7 z&mz+W12Wl!G;6b<@?*xLn|{QOmV0hQSU_0y-eQyFn0W0!G%zcn*~RXeq{yKcu@hzn{In=D{VD z5?xf?4qdJP`pOH9QBMasH=?};ub7Y5d8wu@AOGc_&~SW(SYOniadjl2zoLe*QIHQa zg~mclsSOR9rgf`ZFmh%`<2^ujEF4wrI#Jw`(L{QeA1ArI8d2vQ@$)tvNI3AA3pTWE_}5><0u zIcfuC^m}Rk?8wz5TFB97Bik*}*Hoa%(LWd!9Kiik1FqSYFaNWwRW4>33^t5IqeP$; z_Ey0gaYwW?BP}<6%CIUr7a-zEtqRGCz*#y@AI*=$6Rq$PP91^L*=Dh`+7DG`W0!v5 zW@dR2QHR`E+d`FQNy{Ra%qqY`*bZpxXm9I~cKEylir+3oo*5?Z)C9J-`Mm9I4f93? z&lc{c#wQR_o;~<9B-*gkU_RYi6wB_f>;$y8%L(Ke?r5E>k0H{Pvq&P*6-5C0jS~03 z0NhLT@_%rv86!$sPIdNh;3^+zjLX(tIpr|L;Tu5JJr4DVv2ZAt+%s^d0C$qA%;4~K`F9JgAi8x1dwpq1ljqn;= z*dx8IjpBZwuuAF|NVq3p^059KO-aKm5Yl#ns6@fIm84AbP_-ac=?CkB2%vGSDE*Xu z_@I=$xN%W~(Q!FQ@TkQ!pT03xSlD1!&xE@AX*bQqnt<8!;Fqk63_0z9n(>nd3|q){ zgnN=fl+HT=_b2F%_~@MTfzldS7+W73`npn*iBaq_Hl6EgS$x>v9)#?fX&p@!IXm;%z#`mi^NSctG!2ZR)B6`E^qB|T#>$Vrp z2et;8v!ue*-XOJ~fo$crXmVU3U=<}@Hh%mI<%BE2(16FmTJnlj7>}QK=pId zh)cAOl;~|JxOyAUg#?tzBObg(GWeJ{^mTzBcrWKXbnI9t*q;?jB~7{TkSLh4ydtBiXC5ZG^raYUA=$Jqu_ z+0xk=CK*!zHd1=ZVM@D0_+@pU_t4y9grlusz=->taWIEa|wKKC#&4EKb z&>pMDx+!#gyRuaT zJOlbUsF>;JluQ?AlL){oR{rAD6dzM5uKsh+7VB=w9wHV7fu4uuBhQs@!s>H45$c() zAl;EanVJ4oY!b*Lnk@KZ`_z?Z9oLhB@Zm+7u=TC{V6e!wGami&jvu;b@ab67dwWId z%p>EycKkh_K{>lNnjQHykZ;u{2>Y7V1aw`=l$V`aN&fu=yiJY<+P=7Of@pXsl$?m% zVTLa0jRj$I3syD1Qh8HBp+zVj+li!!p%RmLy?}Xq?RQ2$b~aRr6!UJ4aP>MM#|ArN z<2)`{%Y=N@p_L#BG8D%_?N_7__Yx&)d>IZ5H^k+SWVN&b2PZ!mzNuUdPQ^$N_zDt_ z%p;UyYR$1TUZd%Te1>(jS*z%q%^N%VTWnL1!X^#)5EC^Dxv9h>|otxr9F8NEcov(|5kw1RnQQXOgnW3qB>saMC64e9MV@*ur98Jw zu`5}vfm)oeO^2Nqof0O-2Ydq?T|i1JwJddcDpcXMWLt{azbb*>3kr?%K@ci|T1 zqZbF%icE(kX<>|Zr9)TaPP6x1|24&>zs@intU}(Ib+n*|ap$zh)t~{OY(mt;1<`;jT3ww}dAz8zTq~2BK zD7H0AZglx^pQbb(tmF}9nVmr2b*ZRGMWSqj!6__}KOb+$;Y~n2Lgs|N3**ZCkF5pc z?zl}Oc6_8a$Z6ojjn^NHh$Qo*TXaM<;ftv&!m#1akNc9^7he9x2+{NAZ=l%W2-c|b z?MP90QR;sG82eO!5>j9^@f&g!P**206k`b;^Amy*%+KrSRYpbeHO_dAe4+of_$)EK z5+3N1krOh`?i!HNkW=IMzSI_{xJ>J-w>KB}ki~}e&Y4^_D{=PE&@Jl$y{S$Au*#n zd#pk`2gTz-+0I>0 zjAsZ)a?+;uI&|9zGZN1_6}l){k%^7Lu+WHtMG;WD-K1lByJw$s43wu*nm@DiOEwg< z$|J?oy5dqEW zGts5iW!{RfU!rZ(Vr5T0ltpB+fNS>*8=UemavVJsoAy67eW$k@RooidogCi|^uHUm z8SvKHh49c81llv9K~a?YqddSvi}E*Iw?I1*`!iqV$Y8ZfO1{{wL|c^Fwl_%YzGVZLrIPujLaonJbKC1St9I3b#raC`n_IC8cW_Fn%R=nI zO(o%0zn-drS(}344kgh_v53@A(A6yf7QiDhq5U;piDjmpnP2RcnYD0IFS>okjDT>V z3pRY%N&YmHouSkFQx^_^mO)uNgmQC_IE=f`QT)3N18)}>hv)uL9XCr4m!MNRx^mIm z%1i8n8Q=I0Hy~US2^>lVNQ3ekSd7XNfr9YCsjoBMzsgXO{;8XG8#j(dz zsYe}fW5T=`Yc|UJ+=<4HCoatX9UTnzzR(A>Tq7-GYlfl1|KiVA@+$6`oU+rNi~$*G znb%TA$8h2+tDPEEowMr$VEu>}!ITpu-8qSzGx;hu3t9#-ycrd?^`m>Jy>g;+eYKOG zX(fJsn?wFD({I>`&J2SF0GJ^CZ<#*x|C;F=8ap`sN8POyS8uaPhY;e*Gpy@e4=A_; z?MB9da;D@)I&&b;p~O)kx)7d%2Om#5l?alMjGr|IeEsngyW5*>+43O$IOQ?gm4sjJ zD80yb_>=57Zau2f;Q8i|)d`nCUo0mYVqac@VXQYb54f{+ zLGpilzvnT-h4K4U{a<@ZehIPvt*6A$*4j?r>38$Jl%-=2Szx*!R1wCB0To))+Nlv9 z>lQ&vt}c<&x>17hH>C!usNBWbv0mnOb;Q2Iw)H9`AIC;T(~FXpEkFf!H5T&J&o4$m zUQOEpda~5&pOq~kvGSomRIEcu4=E&39Jbvc*F+urQv^e+HWCE*_c`MSc{}Xx;c(~L zEI?v0c)*b>U^#~a(Ws=}o;u?t^vPE``cMbM=jNI9tY>s?1qv>;!S1m1*o1xz+tFb+ z$onvT+jQ$jVo3>0V2ECY{3rT$x(7ka&ivZrJUsKexG=^m=}j8H0K&p5m;WJkLN!|( z*i_VI{gEZ;m3_MT-;iM%3+sv%|u%tg9DL!^Cah?bWY$)AhBS_J5$ z-tT^hqQv-G;qqElUZHX{oB6bSfOyRu4)%-Ze;uHuzyOx5-UTj@H-G57~P zp3D0c{K3sLr5=lPVL$E>B|iIaJ9fg^klbcel733#J%dGhe%y@b@aitHUV@HUFKY&C z*i0exs0aFofV$t)7~aO_+(wz&?FjuV3C@KFB3yVZ&WwWHP%T2zaJNL`X8+zdS_0!`g?)NxK3&}h4$vtMpG^*F! zsx#c&MVF;19$HtxH?~{c4K=UqFHB|tr?w3!Il|aw;$S4AG&lYasBLjs#$vHM?4GLHZPJN27+q~2 zOBMvjU0!ehPDizc-DQgmw#Ad*CJtvrUME>6gbsPw45Z-6_=+>h+6E3-46R=xihS~k zzbYWBf$=iyiT9-mDQ zp$U;QzfFqq=>$$0CTMMK@6qh~oJSwn*C?*u^q0S{D+6?_+v z;d}f}K`yXySQ>9RbZUm>oS07oEHi zaGi>6P+>M7B(yn~^gW&f zXI{Uk$Yee6TBOX;h?(FO_&`WOYp58g-j&=;jOug|QAt(8BU;eln)@*T;roJEQGtt9 zR?>AY|1yRzx!ibY(TsW4l;-)M)K{0ZKaPnF09f2`qI zkEmKN(d&%{qRT{YdlKPtcU*m%)j)!?VMF3~_805QPHcSj=WYYJIY09O9XU8Vn7v#9 zmN(y7z9x{B)|3lz`ogOF%A7=cZKV=1R&zG>*8ADXeEjwaydtiIF>h93T_#3=rp!lBb(FWaZ}yoC;k8UWQHA4yuaaExBvn-8-DAKnERX>w(-|ej*O}9oAe@?<3b^ex`16yErG4O>ZZ{O?uA^As ztkSqG=Bs>ihH%hbC-rgjJ3^}Hj+dSS_~f_V$nrwJkoOS;$>^LM_S4Z1Hc3QGe}-me zvex!%^aR##SEH>8~c(DpF3GKF9-o z03Zn_4+x!&{al)TZ1|L6ga-M%b<03(xzt#<^ns6ZWfMqgo^f%^V5s9G@6Bayq)!NYlU`Y0wdsed}*wM4x7`zY0z-InB$?Qf&(G@B&3*Pip_B1TtuwU#&s3HsyZP&EQYR{{C{NT@Xok1 zuwHtTT~?VxTU?hatO^X>WVwfSLH2?T*1D!M9@?0L=TSr^NsOaqG;1T$(Whj{r#Tl}buI0X^ z)@P#h2hvD+gyp*wQM0Tix2MUewz3Q~2ASTiXpAdd#4oq5to1@-DXO(o|Foq`nU-bn zO8>sU^%0{D(1pL;ZW1MQSO0(s)C&n)!Wm#inoE53X#C08rYKsPfL!M587qtm%gZLX z3i5XQTxJk>g2xFBHG^O`IYxf3s<77G0_qTvsA+ocobSGnnQx3eY&FEMUQauYA2!) zk8uPs><0sy1t@1-160f_9>d{DMN({oDg4#F!=i~N;XaX}*N%b;A=)b-ej`GTA;rp4 z4=b6(D4panoGW~g5Ne}DAZr52Q7{wl&B7Z`8JG89P-n|!O}$W-E8<_3MADF0AAYN- zp5d(csccGwAZm?vyKb(Kefe)`B^=@k~PGQziifFV$xYK3+YHT3a4|QxyNK1 z{P0kQ%mkmT+zQ*y>5JO;Qu=_v^3r56*P*w<2`Inkm15|B3i5G=p(sOD;~maTuxnc$-MEaM2M<@kV09U#N|Yrw;mw z-9huYgmW|F3}mInzNDq4f(o9{*=XCsKDfv2Ox@m+>zFdyyp%peH|^MANlv z`9-hu?Fvhaw~Jv6`tRwZ^X!c_yWF8rL>wonX2I_^GkV%(Q7nS>NjJs(Ap(!?ksup} zOPye+1d2S6D}PFSV$-Mbt7a&5R`)D~Eeo0`?*JO@lZP?}P#vR=pumA2B4;G|F~s66;dUT_3W%Gl*pTz1O6oFL{F|-IN80Bp^p{m)JK~VOo-BO>UH|q&OAWdz~L?Qsm`)XsJ{U| zf6^N9_`@cDriwvJ?4RV-#xn2oZ(8OxVl3`$%Z0yqWNjY_-m}q)2}e_=Bzdt*mmSl zJfs~}+}Ew0BO5RIng!)EN^%msEeYv+kGDEIoOX;Q2J@N^%Mi$36bz+K_QBpLgf0tQ z!ab)f9v&xza9WlS=8((Z@j#okTCKyH+j}_4n=4nsR4SJz3pz`d8g>)rH!fQ%2Bu4$ z{)OlfM>h@8a4Aw{gR1xZ?$x;J(|2MIRU;)jZ7k)_2z-_+rF3d!eK+%LQ&`@;6WfsU zF26rW_QPj!e3ozrrEZ_LF&XkftqzG*dxb{J!0$gcgk9y9_;i*ID}BT+VRyZPa19N; z<|Zi>?nR6YHrB%2TQ29;&J)3QEm!^v%y;A*Aj-u%XvsNoK|eAK#6s)D8CAi@QxbyL z&+o!_aPxDQNBDhY=>45?@ZMp(;K9A)lvcBP3c}06E!ezB5@Fnd`@(B-3A*xF_(kyO z_E$4HG_Acby?%hhCQBIQteLSPPR#N2YHHls{%g!gZh36Ur<720-qGI?xcP`!s^;gp z^}u5!!T^D<5O>lO-E?iip`o1engER)^!(VB38yA|#~vw)Fo=l)ysf}lol+OeVcy8H zJ*bl#S0h>b%=)QpG{r`&(0EXc!EE>JooSTUA97K0x?rrM4|X59h(X!LA4 z?Ib0Yn3XLJUwM2T-8P7|&VYJPB(&6h(@gCGbiAa9c#KG&;x-6-50^&_P6K;F;y`e@ z8hmf)?`SQcRw;|0nAiwcb_F#~XqLrRd)jnJizd3LKwsR}h@Lr)YdoXZZYdg^xevle z((GB+3Fx4ylzh6vkx7eV#;VURz}#U){NFBnWY3R6nwtm7V91lMm8T-HRJvlC8_@*K zto6!w2Mtr75nCyT(4{nrMV|KG3ec#Jk*PE7Zc)A$ie?LK=5)B~nz42~snL<>h6eQo?GyL8%jVI`<=?u~oJq+y+28@|2;rE6BsfbhL=zm?i zvA7q6Z#GH+H^oL%E)^>`;PtBJD%9$BoBy)hzYY(8_gK*s=mY`ZT)J0BQ=%4SuPe$* z*Xs$#&mP;v&i2gUYLH}BfjP2(E zMoRLa@Up4?6djREy=Bd=r}(~p-F!Dk9-Gp>!q%SM&m?FV@+YoIz8|;qM4Mohn6yam zKc6TKiVZYScW`hTb6%+xE^NBL*l}1W76$@%>gArn&|flsak&YP5h8mV`Wz3%c9Htm zB;=sAT8Wo(Cwg_YUDezj^fXbB4ZU*Y2O(+IP+XZA`^xXEQ=ACH>s~*j-3b?WN*|dL z8*d(@cex=FA7>BmdCcPXLI}0WF9V~C);8~nc_gy=juX%Z&yCP8_x!y3YYlR3!@zjt ztili&-1e~D#?rpQMQo~=gPnp=gXC|4WDj8fNR?dXo{a;nIN2rK?wYL_fuliLCZ zS*7WsrLWcHTC?(c#^M;&Px}mc$J0F-x_9cxB1aW&_5vgsCJp(5UTIUW2D?w8QHi$t zmz6SV=^KKjNbS{oMFxT!`wQSCtoZm3p_t{e?P9-0=Im<QFj zua#|t*IybU_ULv*4p@gj>z-=Bc#jM!E9!48-Z6S^$v;0}5beN(@~i%L7FY(Uvb=R9 z5Y(UiwM01B&7wm2s3C;!b#{SFIS{UlW0%WSsHglgn{d&mU)l(izMkGy^L`Pw-D})U zpKH%sp48i!katW}sk)=!5!RCmOFR-dhVsk8dPhR+R~zD5q6za>zCYhrPE=;ikXL|H za0{Fo=1f2n4ePd*6pP7GZ`+d~Aaxus0eU6r>-`b29>R8OBLM*9i2XOFkmG-43XRWI&QKc^jxT3mW7UCzFhw=M?qNc11`goeA!pARJF1#B=tbIK{T^X?F&YA-L$e@#( zyk;2+k94wq*uS!7Rzo4>KXRxCZE-4$20^C_lGY3yXZvl0zlc1j#%qWW3EuYo|KR${Tba(owcQZ!St-QL`=h;GHKkZKWse6F_|BlEu#p(blID$j@pSvCe-c zhfv6ztP0E?4;+Er+Ql+G`}RScw@JBG2)5Q5m`si3^s)GB-ps=xD5CxVkK+c%DG18d zkzLq_3GlxD&p-X+Teew2($1_y5n~O6IHmPH@+|SJp zfWj7@ZrbD~Bz%u6+^=nxS0wJUK~5eqSh%z~2*)$7l5i)g>t^RhTNWi`Sb0U&P$M*l z0e3sGL4>g|h$7OQ_<75nItT=r#sxY4kCPsf4o%74?yz=GB{=nj7@ldt+sw)#_0^rHxxW)|j z3>oo4YY^TS7>YWPx{)9K1vNl_V?zo_GuA3MKRPI_(<`(7^-@7 zu&Lg2=rL%#c*T1%4tiQ8J@X%t7h7$11THo@TArtLrp=Lh!0V1-x`DnmSap!E2$crq zj&!cBxitQ4s2rj748-q3rU3>%u1MKZ;h0_pRp$wo!tV2Qn?oy8GiuQ6xP2Rn_ztzV z?7mO8hhq+j%{{F?V}Cuwk5QAakB7~$x9$!robRL+nl6EQ5llNZ<;sX9(sQB~?^yND z!(D4`hqh3vY#uCHk|^9rN^wfWK!eIy7C-^XmqM@M4YaVGo9Q7poLpNL^R!?!;(-n` zu3J}-?#gJq9U4#_j0l0eI=_BRxc%O#8jTYgm}dXYS=a#-dkD#WH82yTzOYU#x0Xro z)jP!)=frEl<|EOP0Z|)p}ru+jif%K)wELmkT4gZR+3aaa~%H-!)@`u0Y)v>2C z2Igj1)xrK5)k679oG)7k!K8>AwM`Vl#cNNa(8(peTEqNy`8X%7em-%tjOiH~xZwyK zrSjq{zOzfoW>E+OTEyFz)lBps<-a<_Dr9Z6K@JNSMXZfH!jbQFY+oI*rj0(*uhg?a zNo29b1JHy~BQ?j-Il@xpHlg=TW#r zN)i84EKzZGu2Q1T(|TiY_E5YRHwLEAp2Qj3TX(yZE2BMr2>%dyyj!$pq)T?q)~oNkSuM%8;WHnSNGguBlrsXtr9hA>RAdI*&QZ5%L+*)j)P%d&vt#ZcH(Z#dBWrk(evo0Taz0Bts)wPuBU^+QK zqe*1pHh|!s3OQk&X?eK&i_-sx>e>LlH8#I~Wkm@84b}f=@v51zmEA9%H>qmJ9SiiuAr`DLLc5YUaUoqUxtNd$f4)rUhKmCgR7AKi?`1h& zm)8Cj7*ma3B_2?*lg2Rh0?+gS|3it-d|6*5C$mgN97F`kxwcG7?DndYtb`_jGhkah z@oZVB0X4}EyKAYQV)Z~H4n+inPbd{BKBD+Qmm{d{f9bJ7zn_>Zd4XUaKeo(r++Sd(1yd(|CvbR!NLRwvl(paUlo`%Njx6fq2^gRp36N% z#_w?_lXA5fEV}U?;cRT#@-I;Z!=QiWlk~XDWla_pCE1KoXawAIr1+<;02sX}ZOH|| zGaRFl&@kb|3cV{_3{V&~A<_$^{jctICl8}+#y){)zB%FAw6mu_IzE25 z``vU*(YN&?#Wfn2F0(&|%u$P#4M&{5CkM$$t*l#9{)F@oAygh+>=G68HJK$WE7M@5^ZeN%(c3v9CrCi8$HBzdvk?+Xg-keO1(I=^=`%B(S+65u z@jm1sIa>EyZ_jlxGcCS{l9|hqJW+Tu<6}zDDItwhdSCq89Z1QfS^M+BL&Gdx!cp_n z@mu?jORM}<=<`?iE}7H#7H8e8NrgPBy?gn-PBn(%SIWj}lR81#!D4w%00+=(9;ddX z^0QhjON=Mw^^M)%7#p->^m9``q08G}9$&;CU)T0u=leXJKi^NSouk8>;g6bJJ=)sR z{cz078Zw3h*kVUS>A?7nja)}rJ46l{VmH2o4;$QQCC+s6xQQ8BrU@UbAqfCh$A#0;pen1ZvgjyT;a<7#~;7oKSjw z=r*-Bf#?RYO3Xd=2Ef3&TS@09(ztt1oRWrq^0gu-!cvhP^9b+T*sA!aOGiA9Mvr7& zIq}2C+Uvf-kt_!5dOa*-2W`vF|)O`{7=ei72hB6AJNXu12XSFVs%trK0WwgZe%FfruN{y zsf|OoFv9kPgg+@)jcDU8SxwoIml)HmKc5UEajChcko3saj-!0NxB+I17JcK(r!sS% zuJal|29#xOr>s{@6(CGAr$;Y{Auxh%A!MZiXAi;6hpjRp0}*DuFMm8t1211Ff&8Q? z(;V2sP-f*Vn0B)JklOQ#-X=Z1p1^hLm=y!p5#_02EzDoHh8bqnslc03-JVfz91yWo z*RC7(KEa#E+TaP^gQnk|yEBZ>>M9$zQD!EX1O;d7Egs^AS+(LnjXhT$uEKAdS36k$$UfpzX7Y-UliTyR|B;Dd%*wy-m?F*4#?Wp$k^&X=XvRE z>4?Riu;=;}!9{T(7sToJ>>D1NDVZ?3fH?i|_Uk!P ziVKPlh1lJc;Q9IBGhed`=ntO>!7g94NFngBuVp(+$J$uL>ieE==?@$n&5FRFh>G=e zep0l4!MxrIc8i2n+J?W@_k?8NY?^;{*FF@FTOK&ukpG%hF@qfaVD#E;V4xsdW2~Fv zgalLS+*l?#I^?BB1k{j;W~2hT9k-=P8--Qt(Qq`K<-DIdANy$? zi%F#{4tEE#$u>=-f(?%K)4zDpUBZ0l$*00n-p_CMeY8u}QfPT*m^}o{H!M#7)!7(a z+^VE4zc?RaT&!)IJ6fIYO^4yAxM_durHT&J$x_fCg?nnA)t<#y0DwJWTH|5!YDJG* zk(8w$Zbc5CZyj+$Np;a!9y=B7Fxb@U@SL37Ui)5>b7Yl(Rb}*@_%~*rsm*0CO6NQz z{eW3kYwMvDazW<*$-X&$mwDdnv;Tm>CSok-(8N0xBiW~(^zJM-z@z1e=3 z>I&+R($~_Rm4P{3Ye6*_Z@V_XHh1#Y&USCMpXBoL%-LG0>H5L0KgH<-#H>B@8I2K? z;MTaTIW?On5vsM=H==1A$yaS%gDJ9C=n~EiG>V@uwpf(w)1xz*84V5D?n(pq$V?3ln(2b2@ zqAh)Yjn#{ln?1K2s!!X#uv+%-7>#z^EmfY=>9nSusU>QzfIGLh<(kcEwj7b`7V_{A zp8ZLzrYQ^7wd}i-VWFTp&$TmMBIVo+eKFa44>+~@x==UpO0ltX`i3(CPr!~M++e8~ zsK2XNkfezvOxWtc)GUueFytFLcJyDW6Npzahk?m-AcrLtvAx`$?k@)`7bD-^h9e^x z)7+&9<_rjH-I;}jZy#UnAH9e-M|gezaHpC~CwqP~dDyTigqLq`!Czv2@mMq+TMT0E zq;<_ZYW+;A*6MnBInu*Fcso8%u7ghPo!|AJcebL{?&wVY4)u6_u6=lD^z{X0bn}9N z-@m&{GzB+BtK})W@p1b++S|*kN{6$$dHJC|h%}Qi)9~G(Xg{8~JX0N3tur=>?qXc& z(vh~J{A9(9{@#k{Xm9~zw0wQths^-5J^@Wf?lG>kNb4`1-A<&Q3P2!g6R!Lx{)p2* zt*5z%yI-!xPYBz6S%S!n%Pj#;z2-8RX%SURxYygPbp^rkg%Vf_PJRh7bEYer=zUXW z$`p1`q6`})GF+>`bZF!5D*%Uj9Fo~w1(a|q^JbH7fW<9Romr3}7VM^CH3+LZL$?8? zFQk8BpLI$oM)N+2tyY9+ED$aiMvTAKjbul`t zs?fiTToWFWzBMU+^HV(8v$8lAm5w)WXZq^Cf6?7||5L*}bE)Bb-97xKeYjQgWT#p` z@RBj&MTy0;1qB54NwU5P^RxYp`lF4K5%lnHZ z9P`lP-TKOLwat<`8I(8JQl*frF|ZhV!iBTa7Omp-TctcgFkj5rS$9X%ec~VgxDUL( z2L!G0Lmz-fOW4sJh>@W(j9&OEI)c5OX{E2{Df)adfAY}u=2J>3a4JS-Vh8} zpTGMY->dQOGV#8hZKQa?Pq+bYJXqFEP#Kv4qJaMH9r5E|7-OEwpcGBXvCo0Joat|h6-2Uq@IWP}X73l*| z(O(xkmVbEu`jxfWsPwu`&BO`GY)`9POi5{=V7Z`x5{}BK&d6)dsE}Ciq;guISd%x|1hf!C z&~4&gW4q41!)fCxT`T=i9Vf?dSu~9z_ab9Hjc80zI=Geg)w&y&_{l0%UUIwdJ<&V@ ziBv~y!4p8JM6mMdFa>8{&uvtK%cF1h&uQvJB=0RJ6+GcEY}%oF7vt`Vz>|Dr(P2Ad z4%A^-x;(rK`SEx{%?}7J2F+6Ub$7JDC-~BXBp4lF&imIsn2R_%S@LfveRh^TB#0WV zQ}|FDRT3K9P5hyJeB+BM1eEs7Ld@7?;`|2XR8n-CmNQig?i#&dc2_Hi1s-O-&oDI$ zj&ZdAgxf~mi&`_7o6ZYA{^Y*CYZsg|WAXs3KKWOsl!fn@EjOANd;#d|A>jL?vOv@yYpb7_$5wz6M|7D&4Dcdz*EWJ-&WlNM&f znpzzSv3N=Rv=sw#3SFh<>!7<6%#`x<@zq}$&+$Z-8Z~!B)l2l*VUjc#4SJ~T1+#>& zNAK4jA*|!tEm7NkZKXZ`t#%mXmkkEdX)=MeTv1|HZ5yDsNhW6>N8)r@7$*);=#jURi2aEs&#IS2 zH6|m*-C)0@zesQxdqwyPC#I~u)YSO+XD~2LTqtRSBc*^4oCw~ZH15jl^*&h{Im_#QzBvB) zro}Wcb()>XufYA;km(zeBKK0K?EE~WNqVk$Fn@`G!FEnKnX@iv6nq&^Xu!jiK#$o>3{7=h}2(m`8Gc5!OJ_ZX6-WPjXE6RYp94rXkUAHZlNuDGwpU_K~f1 z9n!#pJ&r)c5zTkn05=_zGnz4wObtzE16#cEpVb6lHv7z3GpUROu*b1k)?9*4oKOxT zV=*ld3WL_7q{P&0nC~K*4%jpo;b^DaU3JFn!&H1DjY=VJi1#P+z+CGrudwF&q@U08 zxe^PDb4Bl@UfqURy@+kliU3Pr#>BLEAe}I_oggV~AOigqi&$9@bCy$hN>T{0+?-oM zsclzZxOr|%-9Ra!&wI*{9G>rcOp)lG-(z;7G9p&djkpykkJzsJ8;YY~3q^wQHtOY$ zj6=>Em?h)ryWE7s#!LI}L@9&mevuN^>U@w}*W0k>(Mut1eiRE&Cel|l70io;O%SFG zfV!iP=~>28|Fy73V%s)?hct!vOB+h}2yBVCM~xQeLLo0v>RL)L&?+f`yS$WK<{fs#)X`NF(IXVJN z7<>&fAP+Y?PtUT$*wJ*pBUVkjh6g1tX^U;9#0SyBNx#swumLbux_`X~erWuL9mu?R zWR+(ruL45ShZ=~XgTD+y^=O9;6Y0ka;C0)U*u8ywM1MUB$52exgWOQjc+XLKO{Oac zp>En};0yA#5F>LJH2({|15%l*I#ej>(oX_qnHwRjHQONaSADX^-X0qR@UXh@0{HNg zJatVKRuU}RsOiJpA~l(vvF!BOPwBKeRKR?MH43F|l-xE+J^~6)FY;=V$zzW$CVu0_ zRDIE}&Fi-VG$rrSF z^Avtpa+7Jgf1AD7_i~gF^lbA!!&FB+uHJa4`J@ISX=x*s5u1(%;jhW zSfUX5CJ5MGFRorc$#h6C>~=iawP@PpkOU{pN(!{otw5KJfXChOm$Wo)>W1AVs$-W_ z;EqWE7z3UF%QmAQcTvu0MQc9Ue@IdpmE8R z(fNylZJTyXSsU8(jw2JAija1LD2twyBSj0O>cw>Rwd)i!T9*Kf=6iE7FQ(v?GgID; ziumqz1+e;5@>iuM5Jh;`;d|GItaO9(t?y}dr!OWnbP}19i zqHq#Zl$Fbj&H|vm>Y4col6I7Ij^7`w-+cMWl0Y+JYAXfh|FWl3J3AIdH^|hQVbj4l zuBV$|Gvnh4Ga76tErFdOU35(;P@+=dafn*{tn?&D5%$dQh|^cJN&mE1Yx8>CADus> zX%=RI<~x&7;vRs~uOn5wD7ea?VldAvkAh45<(p2AHm?cZ_n4eByes|z|MIsKnsUkF zYY>J?23fhZ(n}e$MVXGEpvWN99J6eOixX~Iqm##KPZP;QEki@=ll~nzqS#{ucFyzU1P72Rg>di#!?^F8^1%g^F$EI#_y6X zl4-~#-~eY*_`Z(?;Ym6&>z>r?kBE1OHGF3%*eSPW!;jCEK;)enP;Vi*j z+7jUmMLA5vdX_lT;fR^?h!d9x^HoUJhJQc7_y_unRDS2COt*$IUn)7%@ks%6V^T_Uv=o2As6H^jfq-V*Qk2N9v2 z`jan4BFL*#R*B~!^+T_34=7e_n>1*ovcGw3*E6c?Q+X^&uFmNKq+Xx-H4s$SMQEp` zrlw9h!O2Ddnun3g&0X_Jk&Wa2ZB#fk?f7%WN)f3cB#8am_spHB4a%ThDHGCsqw)w_ z{BiKomX>W#1nSkq9TNu4k$BKaFj|E{dD6zP?jgV0()0?wPdkQSVqNj!D@-nxjgj*? zzg&V+9iKch)h4>8#Jt7om9TbUQ_{cNGvUl8xDK)2B4f;!A)VMkhD90F?%S0UgNTOX zj5yrb()vnK9#7M|%pyWjiY0B#Cn&VuM9Fd6c7h8nE(Z8c7H#Fm=LLOuC`QTQj~v-K z7x$eQQQu4xfL}Hy(-9D05%t~(Dus!)uiu+wI-|Mi_XJ4?mSfubk^gWqw{C9vDuT3y z9$Oe55IAqrqjyp-&o+}D=C&NPH9m7aa}7|Q#6$n`Gyu%whc2H{e!X4!`ds;WNeb`V zCC7%&IbW>kEo(bnnr{6y!t%X;A5WOEB))%i+uA&?x#NUCwuI) zXu)S_C>s)nKqv{K-6Hg0JWp(B{8BuFQv&CUfdObK=-mil!_L>DSPp`Sd=lA$Y{Q@* zMTf{L4*v{K6{OGYFuzgKH|<0`y`UOFHCXX3!9q!K?;J@%l`y}Z?~Jc-SZ)}61*(ZvI*hHv$+O^#7q2j*j!-R$%SPK*3>rsP7* zeq9N7E|XB#-LTEYjMgBuVUk+Q$PW$&8?WCBomNM89-+AF?eGs0C6gIsb4nTE;Dv|L z)AZ5vfXAbkWVsboiB+{fYmr2i3N}4K+MPc@O{xY1 zlKU1p5f~+jg--u~jG2CIc-?7W)JD8NZr!ovP>*3fiyG6l?W_NSI|R^CHIpe>$sCA% zX?y4_Vbo>2tdR{2LE>yk%M z23tpko|V6mru|%kWWNsC${C8PC{MCXoM>_PpS(;T+!g%Kg%uHOd3A!j=4$DsVeWX| zYgJiU2ST@H&IXrQln#axeV>@aEx}VOaL#Re2B_{_&n&#?A6Rt+!K>$7b3aa|r_{pC z%uK=xS(sDkN-5_HCUIkbbrphtMpM7)QFBnw*(zC+olWdAr!fD;gwGS#xm(7nGcN2adp(+xRt1s^12+Vez**CN1Z zleT+to|2T-#oI~gm`3uw`PjWMSP8HqM{1qdi|!hF^z-b+(=4lMdLr82)(vITm|h&pPTPOSngMHBy!hE4I5( z_Zt-5g0nW~sEm~;VV3}ucM-c{c3qUYX2#?#0`yQwl@dQ$xWRH6=0}G;&R|aET5O#V zJ{keenZ@_oQkk+dpt3ZtwzvlJ2Jt~CT26LqpYzgb0x_r>NZi3Q6R~Zn9zQn3J)<^g z4SSTO$hRgBHnz(h>p`>K9C9ezmt|ZF9kZp#{ge)%?YwBX7ubEMV6|zR`mI42Q}zlU4(nqF7pX)KfD+Itl`%d?y6S ziG$#y?8lk;kaYTib;($2{Jni#$m}Aa=>%CMqNz!>xS96?O#Em^k~uGJFlO=`U8jZjYPPHxBngP zUH(Wc@_bfo0;+I}c^Zxw3o5KjEa6|{sxPugzr7ZjuZ9Hcu+xj62NUdj)K`HhmsDuc znwxiWJ<*da$#>~K(zx;{iiO>6;)hRjHZq*$310IL(!(=4u+@#e;B&{TL2jd<~R!2ZZ||I#SLMXH4VeH>~U-o z(lpIoYn^Bad=waPhaa_VIfiscQT;FVjOLKp(bh(qDeUY5yDDi zaf-UD7tUh3C-%|sXj!Mj>p>OEjdr6LOX2uqOHYhrjW$!@lB|SRE-PzpX>g-}{B+EW z-j+=wp4xF!C&HR|V;Cp0bCMNMyK4HdbRelX5hMa05Ij*W8HExS` zQ>^6CpNU?GN*7jw0kUDQvXcy)!=l#^WL8jTvIykYS%YTbcBBHKHP&UTErW|wcoyYW zHde_|84*)C3PRK$M(y6*gjeCu`2PGViki^_r~dBvYpg0OxY7-{kiIAn2y7X`E;ztN z?rN0W{ZK^r1wX&*?@KEi)1r}I$M;2v&iISw%;Pr??1TZdMDk7+evW1uATzV=&kjc31tJqIpQIQ^Xv1QXwle5 zJ9_BQ2I#y=IH257mCEC$cG}{u&*?&&H|x`;l}e%j3Gd)S(d zk=6P5{jI8*ajytM$CCy>9G4S|F($5?pKTBy>3TNxXK1hTmULg|ZvjH3w@4vJBTzz4 z*#VN<<;7avARtLrWa$k)vto!5>7v- zyj)!L@unTobH8>_7BTx$L)O|p7Q|~dd{ja4l_jn$$4!`5dA6HL=%0tJ(Cz#rbEL4%4{`*ImkXm zOIXQJgfXw7VSu`}C9pKf=;<_HMzinz3#N?C`?xNc$ zu`z-!$7y+Z3Plu6N=QVx=Icr+W;@B6*Ym!vc)9~QAYHch9>3rBl#nJ_iZlx8SeVZ@Q>on5!ISDVWz5_@jlprg%mK<9|8787&NALM2q<4-%5=2NY(7H(E;vb-v9m=woF8bADO|9 zT*BIR#X5%?i%Z~)m-|tokvTa?afcJGOKJ|;9;~~Uyaj5GHO$2R8)BeV{jy+s4f9VR zW3M;*5s^b`r5YeV9|vls&7(W^;?z+T5WtYp$KZj#9qZTS`dY${!ER+Y!4X%wG4I<| z*)#R7myLTsm* zTiLnS+f%7g0o#(;ERx%;fkYG8w2v!aI?KJ+ev$4{>ODOp9erV_&XhvkU zxHkR^W;JxB;&Yi;5w3b91 z4Y?FprZJWB*9;L@sUbQv>THKP&;}7pl75I1M`f2LktDDfDYz%f9-($=7QDR%$LU1j zX=Rvgi&=+=3DcnUmn%`D;PUD(Oqjr;1dpp5W~XOQoHai*O&gn_d~!6$ZmG~Qvvp{M z;Q_54hD`$@^E#H?&ppp+hfu03+-vvlUj?S%n7A{gB8Sxs)zo@G z%oSO3!nvyW3DQuOLWkXzN)Ch_`nKolw2283sRG?sxyiu=3!d(lF)20`lnZfs-D6zO zaM7hPc?2mr?&06xsU7WKe0X1>*t@^C=ei&(;Y=9wEMulK7yJi@0)k`!Jl_0(~RPvO97^D6@s4SG*VPn+L(lt{M!_%~upAws&joRIi3d*xnN;^6kG zF4=`0m1cit&1ih@cVjmK9kWkLTGM%PJeym69}~$bWFXIX`;T+?lsG(Jh;1*YX9>W% z@$B{;y-SuY>EC_CB@sDNNdnM>%c#gKRM7asB|^U%S(VG6F*=x#KOg)TfHCz&?S(23 z$%c6Ml6=P5hfLwm@{E!(t zMuHS?D@W?YdI4!%&$iTXcyIIeKSrjDFYN-~tY^tR3IXw6#>mE}4gS=0#vIzw5UO;c zHI|`l{XzvpO9g;Cg`G+&o1fCsnm3}m=?GO&`dk%%--eupdiFMXoSqWSK5}W^2p#ph z4&9(KPQFFC*UgnCg-a&C^i)N{J3go%x-9d5;Tr~e&b%VXrctge{u94TpN7)Fw7F?0 zX{r_9J;GOz%WLx-_$@>z(Qq~OD>$il38qVSEi;NS4a9fi zHQ+2gii$XhVS|I=#;ZUf=!R$5#9OaC5wE-Z2;pnkA9H|B3t6RYW3jRV+~r^FU?!@} z>k#LWrlhA=aWZKci7|PeS6xd7O3m%~?ANp(1Sg>!ap=Ob04x-3Og7*5o?bNGhT(L3 zGZI_io^uGDzSlHI=QmKO+)wK#chPOG57gr!;hm8BzMv=;6OIM1R;_-fHm(u55 z4$G2bh0u3gS$?LZ=nRCQBA4~L{kjWQkcHO(lE_UdjiHa*rk`CjXFy7EW%ls`e`%QPD!PK+| zI+6TV+1mB2=N-MSX5{=$`HSi$8LbicI%E*V<;tpKt~(K@4Weas0S5_!4Q0uhW)wO2 z_YZ3JpGPhI=}J!1Di?y>$qh3-EgyUMsan@w(nAWxnlemb8m_&^y> zkY^x?II1iI2+#d-O&k%bO&-1912=fL!r18ARK%B~Sy`W^l=t!V0&0KK8A>p1#P0<| zG%?7=v#TtwZ;gR-h7yDVu6Q)>;?}o>K!6BgQ5rXR zRPT_VPTyg>Z#v%EJIt+qPdxN%Q1YWR(j;Ago$T#<*E;mQiB_%iUAtP0(m5%W>)!!;iT6iGpyM5# z$@d3)`p=_A{To&h{FA2q3-bTw2a z^H%{~q(D`}Lb05xhyqTQ%2UQb7;Zyo!C694FKAH$dGRkuHx@J1^-_Z_6QKB(xEc_f za&>D=HUw{@keX~tV{1*hG4@A_Sm9o2mg!?o$3u9et6jVt?VdsFoTs2xrNf$<01}T7 z8Dj1k2%e8u!(K^8tz4!MYRIv*+0NN8>lP_!`MNS3LYYB7j{9|>d1$D{bhYu(f1a+E zL8%^;=*1E&n%o1aI~STR5u8W9H|dJ|quyzABt77D_!(eWKBk-0bW0L?Pa5kn?P5dmr$Qk20UPJ~oZNj_0s zY_{cGs{i&mclM*##MlHs`pZ92(XYJ=o z($7R`9TXZ-iUE6F)(%^vPgkHyFU5-Lls4>5CT}zbMBW&qXVJY$!)=~L%yt2xOtd?LjS{T1b1w%U*(X?T}+ZgW0m z#E_*PQ_+00CXJ1KPpi>U{vleZ*a+B^RU#7fs8rmJtice>k_hOtR<^BxG6cyO3Gl?d zC}Y$yZ6IvV!1yReRLAAtnyHaWx-?cA(0h)^Yxl?fjk!qCnoo9UEbwCz<$A0mkGP28 zzX`-NsJ!dxg{yN4{#Gq#nT0r9kY_z|ePPE>{%hkAoyL+=#P)1;13%&5l~RRkH7dN%e2t>TSs(fy3%?q4;V zYU%D^w#&UVGTtDLeyPrO3Jh&I>BpX}Cnk{8jS!Ul5wPd9KZR6h4c04N4^lk&@FDt? z@smJ3;p1_=^(i*S>b17$Z?4(+mphmvPkbTxepAv~;iu#o467SJt!;UcodDp{^C>#irs5`IBwC}rF?ue30| z81LV?1asMk+C_MpXoO4b6BWo{e3;o;$WdQw~@>D4U11G zC?I~@MLb5$*Lwk}xx5XLn#82ust7inpHwwyV=a#^FR0?fimIj;^AUS{OVW}9Q)8C8 zpA7VeSF?q|N|p+YJ(^bnH8<+AnYHF@=%F%YMnJGy4S!G0v!sL>$%R6g@?j07J+Gn= zuNMPSgW#Z+qVcn!h@*tfA4g2rTul%X@7_bD?nCxhXJuY~<{p8_E(Ox)23@L5Oj9h{ zNCJg0>IPH2BG*`)!;y|J}spUf$^zjQ6MYKT7j-SiV z4U}}D(}OoyrQnzA&m6>zG?xJjHdv)$4Phj z@v$J1Mwoy&p{ACbISe608U{w{?$UP*k$Gz;a6?DgMzf(;<5PBwf+%m*w--C0CI zb6(pARq?MB3?aDsHT8Jqfc_lzd_y_WE5e7e0kJ>GXam(d4MHgz^Ch3d!Y4Xcp{QF=+5JuWd} z^YRC9r0#(*MxL1X&>ZuNll76mYo6j}UH@re{>Dlqb+F3ZrR#4SZ)p``Y=rRCj9|~#xX9rh1cHTcgK1!GUYOe) zWrHAgmR_)jz!17t$qF&iR>MSD@SN#}mcvBszI0^)-~!ZSVf#-1@SNO(?ViaFE{=Kr z%jxvYuuRO@=(KRb6Y9?aBu}t@;8l)zomI=xrcIKd`XBQZ3dhw8uZ^TI$h@G-YJj-Z z%`rqrfe38a6hw9Tfo)HVUSjg-kLTw6u6&OhE;wEP8ZoM6_IzCnL3qlZ>41e?!?QMp~D zvQIsrrO?x%D0s8w54J{sW^FpG#YiE#*u@AJ9afXNRP!392?HlC$yavT0^vPCsO6m& zFvl$YTJAE<6T_+4;WOi)a5IunPANZ_wAM? zQ9a6tMtV2tpaR#^-1T3tekAp!d;Lh4%dss_yVodURPl=#{?o}{NYMp-%E_rvyjHwW z9gRaIt;76sYp)yw#dKqCL|C{J=$yH0NS`|4v^c8!*H**L z?s}64$60<$oJlcrf+i-!!Q9%Kxu2bCJD_lDX>M8BIoaIiYlanPN_5ROKfYX-iyiD`K3RU>)-ae@02BF$w7XEqtD|t<}i)ZmhqF!phe9xq= zHapuMJ>5~#8B%uq}Qwc$qBML`@REWjj4si5gu zRc@|9`k)#ue#{%8ZUKbWDv?Xopa{MZ2SG(ncPt|1`>nDk1xs4ec{IzZ#P)}9 zyE2E`8=LADz5f)gm#k9Aeq(Z2ME`3=*kv+RF-`v|(u;uZwjx4%UiZmuYy<0}6V_h} zUv<;_-2~0UyeaRP-ai`BBIbjH>+{b5*eL3aqK)x=4zsXt=UBEE0r#fYKCS{P(2*$+ zzY`uu?i#@*3Q-C4uc#oMrBTTHkduBe?riJ5dLk$&;h0ai*lIl&GuUS~FrG~J5D_ZI zK;GLn-h|*_c4TPoOJSj;;d@M9?w_k}89a2<>%NpcxKm0JR*Lt5EW3RJ_)g6Xkk+V` zMxlhc{U$Gf^X9>?x&vfMI4K$jeI5nftbz19BT~3CJ?|#g{HGzJJdQf{g_Z248bubC6f?!mu>}}@Ury{)(=&BUL;w+nl4vXvC3W(6 zm=iCL&6$w@SvIDL243zQT!`QC*zvf5u~FkNW(uMS!n1lHySs)fIvlEnT^_o;0in1` z!!JYJ&cW+q>s4f6aC^e$ecBMg^t6?~Cf^QunQ_Ov^c|4t#P0v(+Z=T#{jZBrF@rBm zpQ}$)2`KUBm}UtpVdqcuyPaA9@z;es7F@)>x~i<_LzIX;{C-{Nnn$3-OoKr=W!Byk zjmNCF5MKB4#ojkJbQ$N9vIx>#`$K4oVf5_c*?mv5d87xi#>b0#>cF3oCp%kZ6IwrD zFp~4S`OP6Z3Z=1;h`u981DqW|)(B^cdTMm#L$n>b>R}S%h?h~I8mq%B6dZ9PNqsxr zRNoxtXLfv_WgZIKK3(KmG-#2095z`rpI0#6!DP-a+>RrN?hpkeR0)zI*yRkF&4_L% z;mG?o5u?~RY)$6}H7MV0;@|N-a?(`i%TM`oOuK51I{os!sC7-p+(@(c_3IMv9fRfcL}Mp#_MUF7&K{5F zp6@LOh`M3_HRD@ZTZL`M;ARHPRr?~ZV>ouq9#;uolIPZZ|B=pmS&R$<(+mpBbt2O1mvJRG@iUq4hiYQv!tKwN?THodQwl9!ZwGLG(O;dap zM6-D&3oAJ=Ps67L<83O*aK!(HZ%n^I2FpDa8xiGUO$EH32Ty#;M*}qav1P$tNyPB^ z93(|DbscOL7Du;io(aiGzmBh1PK(QD)lqae9K{qf3=N}uR*9UhiP702w@O(XEgXM; z8dfPBEobZ>*h}_xX0-5L6Vn@_p`%8OE~I!&b3A~*|lMZzWLQ-$mbI~2%rrqSiTN}NT9TVLk&kH6}9h9!5#bz{AZ6}#IWPQJG zpwGl4vGmG*lX|9gMOxrY->r_YzA%=J_7R*9XJ)>2bfSuEqAtrLdK!EVp#y~ z3+XUYk?f*&DwGSjeVv&7bTk&RCXi~LdBG7g?T}YL09EwiaL*J$1|H-M_OVhva0_b+ zSvKQdbk&^KB}dk5_fd^l9MZ5?1yfM2rD_CnaURg-;zw@!!H55`W4*s{dpu79h}_oG zc@$&@rUUo-;3l;GG9k!(;W7Ery9;Ms1arQf^Su!ozrEWqo8j%MFX%~NZHn&qfnQIe z7;|zMr1|7X&ECtLsE_>mwlV{;?|(DwYfQGR^W*TcE{aN+C|D-I6Zl?e`)fkG~%(!M)J+vX~7O0b0|lOLNNo*ZAuW zW?Eu{>*$Y)ROUSGvOv~+KTh2CPy~(S0(*8}Wb=^q*~?aJAaAGUI^Fcsp=D`;oZ8p6 zw_B5S3wN1xmE=lUS{R7d2$S1Yz2CIbfjFD9gv7|7qfBUkT{i)c%#M!o06xDr@r-_#eLn%*@K*QB~<_UGDFvjs%Op z<#8&e$|0>&6J|3#Jg?kmG>*ZnBManryzXmN)9)iE##SqhFS!ax!3EgzTJXMqz z@c@I)9qdF;Y^cBhi{#iVY7F|oj7C|1?mj9C@6Ep_O|cBjVNJpVt){m+N|v%&P+XL` zTTz@0t+XNL8_$SNG8?V1;V*-*p;2%s9cKpH6ItnfkB?d}Y{U}Ww$B8O8-7oh|3q0^ z8~dc`sw_{UNoX@`Vlie)M@5M=W+7BHB;x9kv3^w$VO~wG2kwoh#M4+D+o)Gq-Piw4 zPMGU0_jYZ?$Q9~hVgI9%&?#gAFA#9RXfJqt8ci*UBjm81S=2ZfnywV3$(5eo4#g7C zY}5kbSr8a|F;4hYO-Y?N`BrY|#-*C|?_AmT&S@kfUl`-N{}F&Zk;!m?KeMZ&a!sq4 zNxJ`|nA<2TKgBEV5IWiUdoE492;&&lI zD|cm0^cs0YQD0r%lFlIwBGOP4#Z*gWB%@3hX+#egHlUVm05K_wW}AQQbXyh>bU5t) z;E%El$ia4WBLB*juj*rD`YO?lDe-c(q5;l#Fn z9%~7|EU85&q~nUlNtZ(S+JnyRVQH8ZNPruHEypwcF*$@iPq9%_faEo>_vP0D^a z{p@h7Hrg$ZF1)+wIv84EE&k`w+J$TxtJjYEtz}x~lxDqT9ALq|+v%)Yd&BVyXp_`B z4Qhkd&oQ`$m+@aJ)&;bH&Q+ECsd6(=Wx+I^Q3)v}7#?kx4uZf+f5D=r#270G5r_bv zh1!Bc=5tg?)?%NabkuE|iI?re8@XVy2h0aSkg8^VdlD{>t%foqcE1w{*UvA|-Rt?$ z5i5ERoyv^_=XG3irBY~11e$AVRGcif`&=UXt}vmP;VOz%0+%c-mrsEoue-;>=KnX8Mq1Y)v-jY{}m#Zz1=9q*$m z%Kc(YJd5)mVPz~J8)J?bA@eb*f}+yf^zI_qNDGAR48YmNPGV`l)jg^A)#a$WCVx7! zKdWMTaOdbMjZAo8X!YN}gwD%0upzJdpXCi?#dQ{QXEvqFXVNSDjm9@lcG6sOEu!G$ z!^|1*iK1qCxy#s2h!47?T1eN;+Q{jpg*XF@V(&Z#z@d4KE&+eDdH*F!=e#`@%h4(o z%|Ilb73`JA*z5~welciY7$~IkI=f>n(}aLYU04w5stAal z2bxk#Xq3+c#s2tHlPr(})wOAFcE)+Xz0BIP-|Y+J;>-x1A9obFN$e|QHo?h+0nLc4 z&LN=Hym>#*6V#L4SMf^MVq8D^6lo(3i)l53T*HSHvwM@yb$C0`*-_-~6 zrD>HP*wAA`5sw^GY1zijAd|U4i*U0DSDidz%s#+>3Y zCgx&ia$HH1>yz6}t zb(bn5O3JncwIWDl{gS1VMN8!8OqohXW=5aTnoT=0?Ge!D#2Qw4YfE<9^*l6G1mmty~D}ytFvVb#ag}!6RW1ewW;{wy=Tvb#aHj4BOO*6&hus|`lS%W;wFILqWED2Es4mC z6vZvHsMOU3@W9jf1tXXyIU%M~$&`?;@VT#GO8`kEX>;IM6L}zQ7oqC z{ODj#+XB$A=8>AB-rc5>oZ+2sg-^3}vWaam=ykim{xeNt*O%>LE`G_t&8LvGj)VOdY{ATleqiv7+h^^A+il@JK?O2Vyd2Dv`&_|W^6xl zr)1b@{tuB!+el?F`gv7G1C@>e`}kIj@o*HkqG0Wokmo!zq(I}@%X-5X4{J_O|5y!2 zD=y30qv3xUlc$U#Xe)@VUzL0s>C9d?eu$@>`$rB~vOD_K~@!eR1;R%P{!DZj?p zehtXjfZb#&{~}|H+5>lWpK&-dZP5-eZFxyOu$5;H0>C{(H7Pj^^9agHz@KA2jxXP< zcb6Qd(b;HSYMqsK2LRt}?{vC9Up(@a-Kr?tse1+?iIVt&V)}G*`+mw{H8R_&q5oEf zMf9IPgHy^yqe2v^0-<&|@(QC%bbEfzpYU~#8BQVm`abFupvzYtN);K+!#xuS>|DYz ztODFEg!b`pv$iR43#;3;fVe4 zSS89SSfjGj%u{5@1ChSVd1d?P=cdLoxh52mgo1nQb}eU*;axx8L#5b*&A~AvT(4rs z%;_g{@C=Bp<7Cp6jbJA$->bhyWx{ByX81xIav;tc{@v3d--&DY87Avsv(8te4Blz;r&JV_nf&wFE8&8WKEnti`t7UAc* z{=`&MzObpXK6zB%o$iPT;gC@Ab-}HaTQ5#%n4dR`&h0cb7GI=usa?cr&3+RFb;K`i zPh9?Tc`#4)oL{&i(yMn8gsZ#|W)tR8wbpvAG@Kcko0@fz;mg~Szw7#-Bb|8F*m!Lp zQSfi^WWF}0C{$mV{2Ygjv`7T+Cf<2Els7;@jbCdoehGydj(M}vV0u%x}-(DkEflJ zef;}hn22U!wq=WfC2Qxov7B<(>tU#udZH?52xOjA3SKqnPVDFX|XMVNBuaBQC zqnfL!gNFr)c&KA``@liuBQCNR_CcW}L5tw%&&Qy;o>F6^=1i`m1s)U``h(xbAJ$Oy zo}}q1=A=q_ozO0o;z>qlHVMqVk)1MmqtjUlV@uhMutXeyvvCqFw05*)hGKorSE-dP zSr<0GS7JLE^r&{rE-3s5xA@%{#U;FhvOP~g1L)QaLx~khHO4h;bmHHn6yJX}&^-#lCSZLYpk*#>*@O)-u591GBK6K_-=4;tZd5mkh)B zK{~!?dd5mS7luYcx%U+0;Zr`eJeJw)-fM8J4LDu-WqKk@f1R1r~lC`DX;Uq?1d`dHJzv)H;fo^*~1C+r?hC@sLp$%2Hjt;kQ>6iUs7K%<) zm!2hJCekt)IoXv&k$!0CTO@v};5T%D5OQr1d+Ra$0zHyzbTE*yT|)c2%M>K#NWx1$ z1oTV~W+!JF!p-i;<#Po=)o-uzq05I#Qglr3G5C+Dl>)sXd7bdCi6LE3{p1%h;t9U7 znSxPF!w4>AO)5sLD7r~Usy)lRIovKN@mI(Wo-e#nZh3uscE@)TG`nfk$) z=7ExBMd&LVdpRo3Pbjq)fyxcM-We`M~csY8wbs?oP?j zoOQH08t&V&j^#Kmf`NBMSn2pTnavqLN?#EFs}sl#-J+eJOf+OGHJt1fD!8h1o{t6? z=rWRHab4=vuKN>>=Q0vqH;%;wN+m)?=?`ghbn1&V=u&(&ob-4!3m-iwq5$rrPZFqi zmrXZ(iyqEW?i~JY7906hV*V)t^QS%$Z5zt;k9SU1w@lu@9^3(DdUdu3C6(a3K%FY| zemJ`TZL#+!;PCGsq4z)0j`BIHTxUWcAbi*VSG0rsf9mx*IvF@QJL(zzcv=6&WqGMh z*$}rOc0Vg2@L*JCj$&ygn{k7g(v5*ZB9REV*j#{$uvCy%uT|>C|IyO8R62~6%BGX6 z*N>A?Y&P?*O;^E>c+@NWv(fzO0MxwYLecl91;&+6@FXor7t>C(wnHI|9)h z@POr4iCYMgf~S4&LHujzc)d&(#se|tkX;?!?^WhpU+Bg(^|YC%T-o^>6LAMYY7ORf zqp!c~E?<;T&0l||!};n8TY5E5cRJ&wC`Is4S_n#O#? z-uYmCmvZhfbEm(DeM;N74SX4TGzR9roS`BD0CYBM`B$@UCS>L*W)s3aFiy{bxPT4SaxJN4&I5knj4Y-RE zP{Cl)6Zmpfblo0-wA1hcPggj`wvJ|H68i&3^8O9I?Q`1Eu-^uc5#?F?%F&@OQ|DQ! z6QS;g0u_>+Fa!cy%D$bD{K(!ADuY|GN{yg|LRBH!6TYzD4D#=Bj1Y zfO^Bd)N8-;z<6af1}YFIw6{?| z6!01F#Bw!x+hTEPIKg>7TMPz{6;cdz%4USIfT97mq7AX3H*^5=fRZ?Mp({3@L zv3h9Uj+@(VS+U$p zmh=|nht`v1qV|ks1YbIBt_kZQ>~M4KIb;LYel-nk4!TXvvxbUZw06 z>W*bDRuPjT{s5KdPsFl|$)pbnw4l_UwuXNN#FmJoiQ2EMZmpEpQ0C7O&>8$D?sFpP z(KK-iC)I>RBe{{kU zNIkfeVyi&42y}5=?}O&1J*y26=m}?8>BI_8HN|MfO3yXwpxXrqJ;UHaLct(og*|!-R zu$r!Qs7S{LQ4s_gI6}x)D^?R!W5cszKTL5@+^vTDy6)a+2#pI+<_VvXL_d*!UyWoM!m(y!Q<+Vg>C}AJWugWP3#Gd7=4~Oq;(WZq4alV^7X} zplvw95jW5Ft~@o8_T;&|oyPhpoK(Nf!6-l}2HEqsJqxu-Imd)jjQ5iZYt(uc4vKV; zZ>anA2k-pPJFikA*(Cg@+j9T^sTu!|je18X2WKNEXNUiO<3+0O*!~#xJ}Y|mc6c=C z;UV2%_kILdwZMPaU@)H$ev{E=lPsf@#U|<$oPIs+iGS83mpn!g-gVqucjzq|)``>b zI-hn<{A^I{aYfL*-n;@Nw(VyOfchQjr z{%Av78ZUT>=*1Ro_&_;s8t$pcjmWUEcfmqq-XN{KB|53B6MZx}X70l0X$b`gGh zS~T2Hw_wfU?kVjK9GffbsK01fSFPt1S?FV9&FM*b0{5qp4|@H1p~Eo}@cvLW-D{(_ z8q!=i$Gs`R!&_ za-xP|wma8wTdTBt;7-L-y^w|bJ-Wk9KZz#z1%1NI7~$~FjA3`Wa}KbG8!j|c`kL?SWPgo8@7S{x5OAxBs>y~! zK-&CEiNCEKIEeL5k8(m==6*YOe`u(E*X`d3->XDC>GpvcBSCBPCEfs6iN;Gem-gidJ z_0hiRT zYL{8*X)UO*ESfWbnC(wH3=VM}of(A&kpgZ?VM%Qp#;70c4}wXg=Vss6(yt|ElpZ-v zY#SxNestph{D&zZNw;bLc*XiZMdSbX^!@+XD|U9W_;26#hYNJwV68vB`Jy&G>#!;- zI*Tc6(_pb=!=GO6_!IA(`En6bJ~71b0vqFg*G zHW;kI5G-|H-XgnCG&PB0x8HxeLQ12$sH(oyL0ug5W7$rn7DrLz)KW)Ne=J+XO0H6> z45pCrpv)#4YQR>8?)WPz_A8~*it^gmB2Cv(i4RkyXlkL^M*pQ<`){XBvq3q+P(9tZ zjQpM87)v4JOdEDHwQm_?wcC?)p=k`23f0We2OiSWie`fquaS`d9Q}L{g6?r+AxcAP3)~> zvaW6FICG(c4kPg~dqKCB!ffYcETz{9v7a}^VU0EL%ng3do!xvh|--?WOzB zwNWN@qJExW0&IffhtknQ#xGY>w5KMU8<#>mO4hV6m8Ko?VCi9*Jk0R7Xm0p7pSrWA zT1Xe*if(1_%k-!%*gqFV=VHnswpFP{zAj42f3y{#!=~Lw}S>5zqM5q z{=s%=643*Fd`xuAKN|ThI48iHg~?8Xxr)fKvsA&3$v=0WA$S`_!NfNGikfCUofu!< z7g1QR2>(|u?dUl8C>SFdRlHI+Q%9F4i$ zUw0~-FPqo>es49#tU)b?-q(+ERJp$Hf*`5^2m0v47#`DTQ$rHn^k6R#v;!PI@&rAZ7dfXm&6aj2#LT z3dYBJ8!&5rr`)wuJraP7zT{7~htmhM{pHq_upa(tp_|v(5Gl-Lm%{~bO>_h&Adl5U zGv{oITFaDyr!}fyw-9zpdt2Qnqw3P}imM9_OhzMm?k-DJHow~L2){g@o>%ADF)_{P z>C9|(b2y#RzsgRUv{T`gJ}%{mR20X9-Oni=pDc>d=qILy2U?C1kZ)3jt=;yQ=J`77 z8+oWJEB{bc@C0&(L^SYE>wbe4_UldixVzud00hff$A@f7A7o&qv4PSwH6u56zEtg- zKGP1-`8)8PEzpF}9tfgpqPO7JG=Y>zx%$W-0f zMDvGnv*XK!l777_+xz$%dwSvEXmgFBBr5k~&#$CjEire{aC7K#HM_%mz^%V>ZJ4PM zbP4=0lcfZ1nas*m$a#PqZzxhI$9uT#(1KnuwDz^AB^L11<96SbsfL^>BWOsT`3fsz zgT*yu9~0V3xnZl!N}Td-3+#a`e>+qRSFYSUTQnoET0atW#1S=|{hgF2gjbq27?@5E8RSV&!Y^& z0o_Q>DTpn9-Gmx!utjD?KpBQlHSGt19>&fk0{R*X<7P^dEm$6b*J>c7Oe<+)Sq*VC zwK3Z1+^H}E%%a+xBhlX%PDUye&;Z1-x|b9fdf|#=Nnh61 zw1B(Q1|-!;)fzG}iBH$CE!1tcX(nNc_0d7P-{M4merwXVXRZ}lOwAF zU}9q#z|(S72E`OiFhURu>=At}XvNnrtuUf<1L1#5M!9cUWZxT#DWx5BwiXmUQo&+h zG9{G4^ylRi_)%{NQW)PA&!|Y~ZjHxNn^K|=7#Ss|s+ro^Z(O78dmywc7S$W;2wp-B z=5n^!rUH^SdI5wRb}#Z4LXv4__`T-TJ&2+ne_9D6x5&WE>QBW=}z@CfHY(S zF4@L3i(9SQ6;vwzT3jh;C!kt?9Ry~ZR?Ucj`8je21Tc=~2$jBBjT0bAlRBioGL1~s zd1adbi&)YYr&7s|u?g_-o%W{i0IkTQM?(@+t%8~mZyMq{{x{W{Ph20%Zz96}I_>qy zx%FScyTP1JB!j_A2*mBUnXqgE!5=36t+N`E??oH&28OSZ+ji(b=Gr49zmMVY`4>{ngNsZtE7{^uIBfe3 z?dUn9`@(3ggtOOKrEi-$cUNUU3I&NympBr3G4{K^L0mcSt6T!p=Wckm%c>z7o20EO zy4M_zJk=Hkih{%PQ%WknyquTrsb zQ8D9`&>VIy7q%!2(AIXGAwvb9iZ$7%!)uwy{bN?o!C+?{H3u(Ilj4emL2p3|k5r1| zvp?n_r6zRr<5ubtY%dSD)Y^XP*H}upPp(G6G1;Pv^|mL>^<8lb;k%e3|!vXN5%aU6fBxOBw}3;oHHtg-~nMoaf{PXna!~J zCP&qBbix}rb*mM$^>_JbtJvn0s&f?6D?PO=#N6dhPm#v<|0t=vsx>Dh>S=SfUB>cg zphU-ehHR3`{m?U;iGptObP37eG_skrp-t0rM)0ILfuAL1M=Q^$8>93I{U?#~y^cul%Tzi=;MJq2*Xv43Jk&SEEev&{$`=+#h17)IPWw-$JGMrIDmMUxuNJyD_O#7UsW2OX$k+) zJRw3A$qMnvYQ4LIB8-2Yy^CHg_X*vrnEveTrk!l3N>hc}YIxd2(du%;V;>+Bg*}Bx)iDoq^=J1uLflr^bgB3m`$tq(daxFePCvGab7pSam@RyZ5&Ep=CQTWLO ztsuZWSx9SE)4`u))z!XsR`My&+w%3qRVkD}WU^ua)dN#h5nsuD(Oh76<>I?DZzuC( z)i$5T9T1Q&MnUIq{YT+J5TjIQmZahFU)EGnCt1N(Wh-kZhIZaEgryC7N)b}vws6=@ zs-)T;AOY*Olsioe_WXp?%MGH8rX{-_P)5pLXQF!5f*Jel#o(o4CT$#ws|*gVp5=XQ zR@kEmW(1BYhn(K5RSBmq2hpOAY-JVo7t_#h;tfZuq292*G!eay?$jE0x&e0g2^B-o zLJ3r57_pug$O!^XEGA^Pm>p#nbq3f(Q_b?qu&5pQQ1$owx}yaz;nX?;aNBlW%^VhC zp=X@9x?@8_eoZp z(8_=#IIa#6D-5JCi?o(XYvhpvO^;dO1Yp)KGva*-*^r3N{18Lo6eJKHOc7MaLn{>v z&LA(n3!&)ml5*6G0h^5zdF`*;z~egJk@ed$t4Rl~UhG4Omvc65{a<%}-kZDUG8hWY ztu~bm(Zj?iUTPXa$rqWV?Vu;nH`3vKZPWGO?}L29ZUaM3I?Q%-03lK+JbB0>ta|U} zKlLx~0#R+7A8dxH&K@0X5t@eFz}Hle19GfphFih3BfjEvrIZ|J549^=R23C|i17u3 zE3T=OvvN9y>dr z?n^f=uR!fNJUkJ*4dYZgx$|Vtj5Q>fU8|00+N(yDrU0JRGe>C(TGg&~Zgw=Cx zOUrW!nHr5f|8k|iRJC0cblv^AX+!5nK%yZUITH$WEVTD!P&m#&z-dx!@bbQ?&QyA; zV&t?5eRC@E+ki>NikFef@h2a9y1c*GdmA2|RHB=Zem zC^*skCB3k<0tYGWb-A+j@7qz@mtesLD}zb#LNhq@+W4HV*|ov4#h5&`W92{(?tbfME6k(j0B>pF)P%BpXFjm_XxpjTUpfVi z==EkF&_6q#b{P&ij8aPt-wJMl*~K}n-yIxrEVujc(kJ95^SWYphQdDu8{S@`GLMCzL39dA7*fl(nyH?fMIH2OiD=v*8|Wh{{37w~Q$Q8F%~Z6ou_<`U zKO*0a3hTVA0|vLOnzd~(K}4l6;aS*YlJ{^s;W@lBa9)O@mbSM3K)SDeEQ+E^fMf|H zjfnWUkNga#p{ep($pben+5OLmHdfqg&ooPtLGa!EZV0;NO%nUX8Bgr{dyk zMrvuiBw{f?MP2HDaITOK2C%xW4TgnN=eLZ`b(vB&w2?UoluI@_YtB9feL`^M zv(H!z-pR1W$ce0pVr8phY%#DbYB9=r54@zR^Ic1RJC=DRfEdKt?mUE)UnW;@Ps&QtfitahKf+6;=! z`20K(b6vP{l2+g(|4Nt1*SS863V3&dms zl5H_yc}=zzcfCG!8#NU{_Kq|!e@&pu&dln6tmr)VGiTR`VOkga_fm0sJTt-ZpZ5b# zRU^Nu`1|X7Ny!f=ouU5R5;B_*z`x<|i9CgvBr=v@KmTh5+H+WH$l|&=Y2^$AQf8%g484Dxs#kM$Y%i-fF}woziwVi$*xEj;F@GsrufT zIa?}yRk;hhKaQ&b;fJM%Z3S#3qj{=_UcRFZ9iF}P9~QEmHC45dYm^9MPMndi#nB)y z_i{~Y7sch1r`=KfiH>?|11BH^)Qa6OpnSW@4AOX*;)j~+Mmls@Ds%cW|M?4?;m>=^ z{C_W((sZUD%i)LZSN-*Y&fLS7YZ1DE+cLX1g`0Kf8w2g>PHS%EO{0ugedfD9i~81${%*_uP`T}yw!fAeqbjO z|0X~qhWvt&J&<@Is@t@cnk)H7^~dv{ihWkB#1`HWZddZ?`dwvG;^xg}k*=3B-ku&+ zbQa~joo?7*YGdGfNIAGikg|Gw++S{X*?oCCEt8y_j2qRGDNK!`cvhag-`ri18;OoSS1Amx>T_bC-HFsz^Bl(X@ja&);^O80{&ygA1<`kC~gIc{KR;KBukT1=k}--Z~E{ z?(&RgK)yn0Mpwt5i2@2hFon9T8q)*I_{l_p)cpWeqNz!TJ6f`HhfS)TMFqo5Ml`F0wFdwnJ{1A2>5mo$^MiTth>U>3%f@c=urg|^9TI4a z)o6yY5hB2ethq}$z>JQ|BYpv-HJ95TXEPLC7FC_Wl1+=HGH>_O`Mv(C5CN0p;tJ~G zgI)Sffa=TFcovtNGHPG2gIK*DG3D=jnnpSLveSrS6-tl#GS#%2m3mLg-DP7fo2q47 z^nSZRfsOXxN!;`je`3@uAK)h-Yw#8I-1>bBd;rm|GFK%1ytlq|DBO=vKXr2*Lg zYr|auOjK&xdBq?+wHl?vMM)BlZiM7Ml|thhRz9@5zbrRBJv#4-`|5N4Ko=~}WWtiY zfV2hv>Rk&26H#V36dxmNsJyuHYl1{QF3;*A$<5W7hts;TUR^(85vy2f4Kq-Mh-EzD z?`GG4{!Om@U$xsLoUr~#RmMyntQL5y5mf;MQADsqPL^l!D2zDIR!avmyBqt*(_d$J zd#JGDw2W&s%hxjr{rNV$26AchqaAElT}laAOA#l}grEB*qIr+&mp1#>94U%Y^T(;H zRPM&6q-)wH*oPsl)*(HcHZgBvnWo z08+SL$`gMm>~0qmBXewZbO+5iG#bE1tOwFE)X$H;Y`(XBzC!|k5`k*=3r1V!ufLrh zuX3`^>Y1`I2H-XE+7WHULNN&ERn`0cZm_g!-+~0N>ADC_CQCR4l&aDm0ml}j^3dAd zya(E=B^mC|;(JgH+sk=2{w+Hd)$9lU-m{6LLWs;+c&gmDILyodwYE59FaCqI@do{C zmh3Lwx@vdlkBJKnpAmT4q|3=P(axfHw8qQRpWt=OqIgm@)|8oMl+irWk0*ob8ml;mTF0t0Glo|ki5LPPM( zp8iV=UrZDZzuXGK+bW*7rvDt?a3KunVviu#>;Yb?Me7xlr zd-RQ!V#Wz@I&pAzfu;7E05u%%-w)C_0}W}G!4aXsyaX*=B7c2<3x^Olhw!_339@oK zfR)19U;flz`m#??X%sQWBF{r2ia3kTL6FPw>?Lh1zV+(i(-Rx?*STGUy1Y={?t{-j zgwK;)&nwyOH~zJ1m5pSyZB7UOiyT%~?++~G8V$jJ*!^Vc(;b%am#zT`E+-7CcMo@r zdGSa#ir}=cyQA+>(0E%AvjW@0%A^PF=SD_5gm&qv$H)f$-6XB;6*z$2Qdog^N->TS zaaqO=ayf@{ODv#coaEsOD8c&dSOHD`AND4d^FX5heI|JhY6Ey9x2&QDItf+suB=Nd zs%%gthm$^7h_LJ%B-3?$y(US86wf_x0BVQ)?)CM~)@e%PWuDiv6~Zr{4Kc49y1*^r zmdo<#n?5tyAoB;HTMs{EdK*duX{X{b4jRloye!Le`NYyFC+EZYK6IR%3DCah6 zEc&o>8D}0^aviq69d!Bv5CJY*JwTv2pzSwqFIe&yODjnf$=S?x!xMxo8Eo$9UnpSH zJyqfGyC&I_UN2paqXA;2X*HHQMTn=h?%5LMjtw4-i(q4E`b zwTr$Z9A~oL2j~O%UjQ~&Mm&6pXPm+UKQDdDhCL^y*k!ei+0ROZ(2gdDl(jy>_Zvy* zvLNIh``$}9>2-X=Uor~A)Ky$C zr|(P-#ULyJ2q|n7NFA~6H8Qib0w;pmSZKcg4lm553tY`c$bfZJ7${ z|BSPGF@@NjGiopHZ)DjaDYbM@oXqJd_0W8?F zbzW{~2fg*nHtr30T!lu|AOR8Mr@Rg=7vKzN|6~)K)6_3D=@u!IVH45nR`}&1e<0Ir z$=o674&g<8)}x6TMWl9!&kmq@CzJ?%$_9b8Si~_4V?V8{k>^_$zL@U&=&1Sj7M<#& z4w(ID;T|0(Zbk+veZ})Q7Yxcg@S6S#q8ex;r!Z9V5+F*J|$?y?Cv(Y7j!l)JG3Y?W`w5361&<%3?FQ_|#*j^vJ( znAeQZ=s@5bCnBgq(=%Cf=bsDp`dhqRDYshA(MfEgSCYKC6xa1g#Tz{_+0t zfY-uT>bx}i_izJ!?=Z`Rf|nTGH7k{Xsb_pI%{?r~0F&~?WWLVsdLG@0SnfWh)Z=7G zSS@PabnMnVrvut)$Np+)QXytR$Zxl6o>8m#8r00HjNo{c&=LqgQrmp)3=*@hA(A_f zu9whuo?do0l^(Zr^*89o!K z6^uN7|8HG$@N3yCg4>350s-g+Cx3KS0Zi{1IsE$X0@?}z|2E!j{)j8Q%`R}bDf}=f zy@;Rpc-qNgUBfDh9O4?f?jr5lm!O@I+Mh#f{GMf|p4}#O4%PB9{6K{y(cL1efb^(S z6h#|VCeVTEww@)fm7+)Y)~|dO%p|=~6A@Ps)DSe2;5v#BSO)cZV0mrvTf+>GyUiwD zqLP}2(8!86BI}?d){}^o1~p9j@BM4@w#Pnen@QL6%dB+dn->$vw z>raY##OKxA!#(iJS4pV9t`PY?h&npItVGkM!zt7|E-O5w^0_%4@w+kmbN|3uSLo9J zJS@(tWg*rH%b6(5*vo6}rr+Pi9_|4kAI1N4?e2C1i$D%LC}^KwwJmr!e1gMGCA1`Y zJD7}A_IH%~q76NQ5mZG|l8Z^i@31@MhN01joEUCx~j%!m$o85o8Aw|~gN!7&O& zcjktc@51w9+rJHlbJE8^CDsLC+&i}WHo|@4T^tYY^``1iv}s^$SW+K(Se&n2kx$>C1UaI#X;1xG&IL$%7}uEp0wUrsmLf&UUZ4Grec(Q&mjs*r{m} zDTQrqV`2*491*WTU4Y%g365uBWW*e>hr-GpK2ykW|mQ}PH+; z^^gpJ9Nj>+^~?bZRIa2XL#gbj4*aYi`F3_R&>uOAr`1!K91$R9YzBV}UR*8KLL6$f zTsl^)Nv+euI$>V>WHH`%TTnlc&UM5$WP6#(p|+bncCwX9HLVq%$D29883O^71NVoI z_U6j8)mBvxj1%$K^#HTLQi;)+QZ7j?d&)GT90AbS%WtxF=LXmIpjLMAP*3>gXEIkq z=j(^5TOW(}tOCQn(yJ_l7%Jslr`!N(q@k+hthgdB)QB{d{8Tn$+P~fQq*3v2%w%5- zk@vgJBk9%_HLejHZR?1*^O)RF4uI02#y)0WvhFFHr?vif>c^z=rSUR)R1>#!zcQ1i zuTEaAYoFLIm9kD~XEzoN6V)$IJSy)k!1{=;qk81DTXuJ6w;TFn&T4y4WT0JhAHLjah|y=~5F#N*Q59P&;>quE zxH?VT5_0NMy73X)ZSvsUu2nw_nr#CfHD*^@{1o?7L<=XUM|7ch89^^YQ|Y9mPf)x}B9Sy|`s}GJtC}SK{kT z7Mtz~uJX_ESkM9xtoeVmN1d7~b7xlFHKq8_X7fUzUc(P5((N9|4B0lh85g zrhxdluR-ag9>rFiQfIX^E-OLul7H7&vP8tPgIwP+&)cu|YiB&6lEDH-8&c4ywP*7Y znfABVZ8c#}uPSJPpMa&kViP;i(0@UzPtlcM6G`e&HFz5`_-IkiE#K`CJs(vt8A%M< zDKw7~lwCne(y-1iV4Me4;%WTH;f`oRpGhLpVmQI0RG0TVBIn6iu6|1xGf*0i$6@$^ zxYifxZMIPt)o1k@vS<4}+?J5nXOPQ(%CT*BI5k`7%PpHM^^Ww|TQJ^t$V+Mf+(hT- z&m7lh(3=VL*XN_#^wWIv8kTCr(oQ9y*_TSZ5ho#lKK%#A-b>fB`P2#T=O?9OsA(ci zHJlpWCfK3ogJi4Z`3>|yRcqhI>jC7Lz{JFDYuD z9@s89v+{Iax8#wd+KbCqUblZ&vGvfRG8|EG6^t9&CYlT8tSKk7|1_i}=3Kzhoahs8 z$t(MwN?^fcaP3ABDx}~zZ1hhT0Q(CW<0xQ8oHF*G-}WRZfd{h8?)}!OPvS<;d`-v`GSNl z7zzGn6A#}`89R{@SV#pqZuB>16bNk2_HQoaJ~#LSk63`xl_w``q(6pneP+@5+ynA| zj!+dWCgmDRARwi{|Ktc2`~RHeqGh6E{yFH3EgYR_Eo@9}=_O>9lm(=vMHH$2(d>Zy zSWy4hkUBz`(hu`<@t+g_!H_EQU*BF@LP$hbNn}G)&vApp!S}i3B)wc&Lgm5D)-mPa zDf4(FZ!?y_U2WB?BHF^HpM;i6-O7#2nu?F`Z!smK> z^OteRje-OVLC^DtZ^8W-&WruK5coIc1jPmz|JThxPS2|%X8+B6hil2a1-1I*Qu{tP zzRIhs?a9!(7<5J&A9Y{!E z!z9J&K2=!08SY`A(xZ4z;LS{|q*ZSA4z>x}9XV81!+u?0Pk{Arr!gU;!<7Q)V;2oq zgVe@>gM~U+eK`nxbx8977}QWkr=_xQ6K{#BCU!w`5DG*wa%uUae~6^~KZ!^R=5G44 zn4*yYgnvuKP@{_V=*7T!&L~DgA)|kS`O1@*z|5S%`whNC8fMY60DSl|fe3|{o|f^2 z55F>%Px3QM?O+Kjjkp1`@Jj`Hom`MSBjyQ(RxcC;HVf8Xi`g?OGZZ0AvB+bCIn+=X zg;>0EjuMg|sGhw7^pPAy;4u$x3NE9yFtYe}x960a^y)6BX$kpO^$0eJ?NPh8SvcZ~ z6>AKAezNf=89g62^evTBT+-3g0mC~#uWG2*wLfnfWs!ElyjDdKx+__Cr7h@#o!e$- znColQ+Ge~Ic7V@aVN$#vFYz@FY=@ewj0c-3_dMx2^Cr`*4vK>Yv+T)AjND%6a52Yh zZKqb`xHin!dUan@Y36yN;L=Y)>EI7W9$7*z zB1`clT%xCigtR%ZSN;f`5ZPcPxsDhPGgfbZnkvR}0>)d{F2(=n_$$xacqCA3e zns_(qbX&zrbcN;Vp$?FGIH!T;>^C7#A0!kX1lT$;vIERo(QxMkR%x`oTT3xy zv*LAtAy!KD@sm0RFo*IAY1r5bxquh)o9Vtybr2jiWF)YhIUmeHJoS3Z8qy;`DwV`c zg1S-erFf<|7OTg40vw-7uNBxzR_b0BSn-|&Cm+KC?J_A3F!@Ad5FWua(`qhSHL<5q zi9I?e1=PrLErSop6wrAcT+V_O4)7Z$rK$u0vql@HWq~D($ zobV1D7_p4L|51_W!p9Vg%L&j65B|KaxNgqJ?vTV^LSqx4Pb^Mpy6aOj8BZ^Z&GG8p zN&^R_V%laLM6#fLZQVZtMJxmc7Ysa?CU1_CyzvSCjl z^%|}@Hadp+&>2(WioL1hSAxm9ktfEnqlk;^%vSYCCVF^@L6(^*RMli(S*Z@Y!8pY9 zKN+F@$TCMS^X4byXQp-|FmjY>^Kee39IF&IL8}k!7x;suC>J-xNdGb!{VQ}A9!oUO z@hz)zeo_K?nPI8(@So>ne@}N(mYo<*<^_pU>Q*yC9mpYGx4Oh1pV`Uz4>6eg#$fc> zKL5KHkW&l}!eLG7GIGfUfrv6qKJ1wx)$`W`VVbeFs=`-h3}%h)8MmS==H@}5PfO%n zxqv^}l#Wu#ag^JhlY)KsZ3WCN8JvYJ-Zj(G7Vj;O=?_4MpxK?*^-)K)a8r~s zDbU)MtqqnHKN9dvyyX2IJP;)1N6Z5_VBVMmwQ)9VlL4%bmS$bP;|K*t;@l{{;XTx# zAdMWa3gBGj!$wvhL=(gGnLBXkJ&<-AsQJ5mQEL%+ZD3|&BV)HGX=MNeVstGt!(wT7 zESaQu$f%-W#qsec;|^j&5HOX1W6+o$R~9&$Ehn6J)YavF9aE!E8k3xQ@w zw0IZ!wDroH6KFJeiXJO;52m;PGI z)%BQNyiq={;@acNalHYF)u&8E+yjKlAcDa(NguOHgx*~3<@-K&z2aYRTV^X8=$wX! zCIyQuqVr#Q>74P3VjH@c63Oj79)djrS~-g($fB;qTp&a_Ehp<|E*PLp$|o`+kh4ob znRW20<$0*JQS$R)wAzi5>N|+ktzzAjRAQmu$omy-POa?0?T4}*#e>luBTmvxYVD&; z1i5nyjN-YChT3Xb=)~c^K5{KfSX;m}9Y5xG#PYT-2oXD;5pkhja8|aJT_hkCt_0;Y zbil#1%MxLy9XeqY+#k?(7n)Vw7n z$bkK5>`_XG$v?C^SKu?l>w`6^N^)f7l{AB?10#l3> zWM`tSj`OKWT$^s)p=3iJI(?H_Qa{)pxDK4^NuuS}-0u=jw&C_{2vZ^qiVX||oy>ly z9=c8K!HiKMyrN^$oSC5;NjMX0*>YOZN;g0n$5Hd|bbyZw%XK2QhWKbPIpSxWWNH3$ z*I(7Lf%`;;LNpoXr?lp3CNfZ|%x?#dX~ro0%oHp^J$kY&Re`8D$ktn)?|h?fXIuM4 zk#Xg|#-xpx-O8C~+Doy9zG-s)GF)A7N2eJ^9afw4K6m{?edY+5I3_p$vI+_{V z-Jgt9UPyR7$g0Bp+Z0j^OcDwDtnWw>jPXjtsK?1g6%=K;%3H5E)G}Qio1Aa{0*!nP zE7Ldz1>wSKnQrgM>uc-Wl%sXrEBdA=A?&2fxDoEZ#8&BqkWK`+k(dI?5F+C7`Tywl z0$6sKQ1J1G2XhpIZ-fCg6tJOYJ6ZU9Hx$~PYFs(Ib2_~}*1NILq2%f`ZcawnoI-^g zLs3Yad^)8fZ}Ew^vjy~6Q6>H}T@+!lK1~RU2qPhmbEXlF#WY6c1HO?|n*<6%&r5bv z$Fb3TE4r;=RSFO|4|8Q)!9=6s8EX-rR@KFLEer6~jeaL(zT5p>cRXBq1tr~3Vm@g{ zM5!`WB^P=uYi`{zCUB9&y{%Lm{+Hvz&1?WLOW6*5BSYKru zJa_u%TxYvZueRyAgy<3Q6Yh*}&d+at)q1)CMoR89zivS{E`0;P*DkNA|DfCY=|PHx zWXk1Zsihmrv@0WBONb1YLCemn@F2BGg*MURxrD?ZqF)d`+q%9Z%5{8h6Z&|s5K_H7 z?w)?qyS@)>PIts~4A^E061s$Z4mf_i_3Fgmo?e~SdVas|Z=!m=eLS4rzW#Puchf3W zn6Es7wCvo|g6vKUQ`+Uy8D!w#<`8+vMBM2A*P%Go18yJTZLz`T!T-clVce>k9k;1f zcErdT;L&b&Xl>;_>%loOyzw4G>y@b^N$;(kubNIj?YiI&tViKG8ci{vKGS&thp)+w zUXkpTfL;lEIM%zPP(h3n*0Sieu2ZGjc7Js2djCm=0*(m(SA{vxXg_+&gMVAgI0-li zF57mbW?4*lTIIbK;S7(dO5J`9%FbMbKKdM=uPdturPhnH7m;GI-dIVr91v>VDftTo z)wNyngocH<@dB(33LgsddZH|1x@#?lD-*H(V$yy%mC+|(8phPWqD>haq}!7`yDHzv z5*PK!+}csGeFNVIobZAnlvs5FT9m01T{4Ewg*b10mgWGEv6EyQAin;b*jdD%Z}`xH ze*7Ex;a)^Lo{@fDE%jIxn@QlX&I#5pIoU;xSp$5p@!>69I!y9eH}t9t9_NW@~JH{@l&0DIUlfOc9O4^h|ME$R~dP=IfUzb4^ri#{sW>hcg*B2QsPcnhD>15rr z8k^c0S+L8@C?*cPp7xZ-vu%gXG}h6<&nKl`b0|&i8@S6#M7ZPrWOu!L^Jx<~;Z`)} z`&Q#mli%R~w_A)q${Fu~2Lj6ei4*#Nk1vY;*Skd-5oG~k0cC+q^>c@Lag48;5)Nq> z22+|>6q|y+)yYBVLa3eaNyUyb%8lgcqTwo=*%U0sCY4UmcQd^h@>MQcJya&;7lAmZ zobl!3yR3pv;c-P%jTgBE05!G{{TW1!x<8}&$Igs8s@3M@bN;9PL3qF^6~Ms6k#zUf zjVCB=?q&mBI-SC;8U{`(*#NGssVHpyGO13SSjsxOOj3GK#qPwa+6j(cUb2xhlei@( zx#TxSWCRw>$4F=Qk`pdv7PuLYfCU3!AfA*H&{c{G*W?is2EUz|GsGYtMlG*t+7@4R zy|*%pPg#PxL1D6SWP?LmZk}S=+>DF|Z3>rTzrYB0gAz&m^F*_94OpbBc+NQEKP?Yih36RQEh^25-gK3jWgMudxQyf0KTOoGyGHUmGMA{x$~KFCWCB@oBsaICU?_a1deMg~r4hSUsJ+t(d(XKJmlF z6^duJo&hMH20(v7v+{V)aGg9?!`vy?AF4duoE6Or-u$E(Zrb8MbSTu|I@fRtTE9jP z2=pwU@~#A1xp?sl@A%P<{P!nUyC9ZjBMQxoFIQd zh-=PV3k^`SRj)ciY|oA>HC`ursj0qihf9THWb^%1Sm0K$9l3G_jrz3`c#qxz@qAt5 z)9p*x3Jd{I!fwhHgr#6GnrlA0CH5MwpnxJvkkC*&>FWc&$yZ*pF~!cZIH^I*hr8?= z4nH~lrc7ZmSW_}}Lt!$zZ)PrCCuJ_41>ri`CcbH(4FK?4vsre;-41@!DNsUm$(p&R z6H6&%M2OZ`vS=l(ybzn$)}!&<;?MfnCVp6}NP3%@$>B&jCx%J3O#}cM8tlBKgK=2C zKEit_}W*W`Sg{h^8trL@45<{}dYr;*tW6w>jpOCO(@u`bF4 zupgThgGkFnKX&_v)m=>BS7A=9++a`+U($XMvYt(3m7y^m&@msF1AS z83@v6|M6#2JI$(cwFi|XDow+rPOST*Lx)yS)=p9pPwJTbyH84EF<=f_pmUg%p(<0_ zpnluEO_gN^0KVrXn5!O7A=8#$!n6O>meH)g?!DJ2Y9RuSIS!o`K%Mllzvb!@)hyg0 z@3EzesCxfQI_JuB+2ihVm;ESv&?A<0RUsFGs2dZ*-#zBDMflOlZ{FV+AkngT>U6SA zk2<4HHBdzah}_W|6X>Iwri+wP5ID8M_o|?*)()72?v!MN35ejv3|!o2Z!LRpM@dpw zjT<7dmD5Pyh49TQoXo&|jndbs(Y2f+|2zg&g@8sEIWn*1LSnM!;#Eg1;zL*wh>UjF7DJ=G@KU_haf95?CDBT0g z_WRkRRF%rvJ?cgKJ|jZiemYntxrWSGYZL`>v{l+6T%m9Udj+ z?DY-E!$DklmX6Z-3oK^TZpvz_8uFhobkAdl?^k!Ow*~RCs~$G zBEW+t<=sAR&0C~`+B%~6z1ptr+AmsuNKT`0{a1Z1@&T1bIski(B*v61O-w0SQJ0T0 z%sX46$R32b?<3J5CA_4UBzH*?G=s{_zb~;UwlseS;|hClr=OXFeR%g7dMqN%<$AUz ztJtL@M8Z!%p^I$976yX7kn$^gU{`pt8DKCw7G!kmOu8U$7JHM-^u+IVK| z(CP7>67}yGn2e@)V&?4y4uda@L2Kd%8(-<|V)p>U!(rn+W*8xTNn5v~tlD?tY|u}U zOZn*dPG`!e^74MP9?wlw{{X%*6nJ6I1k6n*cfNnp=Kfb#{yT~)+WeD52ZHjSItAhX zx>HaT5t36BPFxy|ui(Id*zp!w$oPYCUwZ=1rhoI#T-+AQ-=sHEwBIkMyWo6FI)Oc( zIrH6-k7VXm1k#pQ7%Of9cf7OC_88BAsfK=%|7hzm@lw?hDiIif`E`HtPT(N2DQ!7N zNJA}M1nbqhXTKV3*`Y*p3;g_Pw|tqn^YwN9J+9?gcBykYpwr*kMM!qYLZ`|%hnu?% zFg)PYUpx{WNP>IGJ{?fNMG{bA8Syf^W|31smwWA%yEfc^0o_=tbJO|Tgz+zp;Mc6x zrJHXhdT>R8i+rp8EK=qlrR~+|W*!bI0WUqH_w;j%vk?#ug~f{}Dr{KH*f=v);L)0t z+Lk;ecIK%$qn7-Fxwmgtn}tjc{NL9F_GGtlHU-gfRHFFwy#?FAXBbCwo0po znYeHE{A)oUm#_mexJfq%}R&${Exo*6g7@`BDR+gZQsZg=}H>qZM8`HG)~suZ3RJP7HlL+S!@7T#rj@o1|l~} z<8JfIL_d;1g@?ohmwpYU1e(dtCMBkC9AB0VgOI!8F9|taqm{+nNRP~vlS4i`2wK1< zBF@^!;~Ie(JtleWKn*>yMLEU}VIsQ-g5L3NYA?pI%%_JG#Q4+WUNNO^NyQPI?~ROB zEZVQnJ{x4=6ERN_tQ`Uo3CFKdCA($v)@z@cyD<%)sWC@~$9+=Td8MY7^RrEub)keZ zKKj$nqY-5HN*zQBq_#$qVz7}r$LknQkMzf>?DFVwq;aV1cfg@9_AK`yE!YoJ?d5A7a5b&r2ucv+E=Ri`2& `Dwb$P3thM^USCe!x zf+I`$sN43|!A>Zm>%w~@GrC)$_eC! zdiIo_=C(WqJE|Jr-504QozNBz>B_}Y3qGCKx+D*OH}e8GAb6~i`Jda;6ax6Dv+Rq8 zl#eq|h0%KZg;VFgBa&0C@dI<)mK%F8Z8|B~q|;xPLB1e!S1n~KUTBm{d8u~B>?%Uk z{8&NeSU44965j!pEV~0cKKujrJezE}Rq#o2(|5(H^ZDDEgn* zeW(l76x8iLWSXCaa=jvJNmHvmAZVd+0d9B_{T=0~OYPb#nO-iJ)v}Htoq+JR8dDUU zNe2C)S#K}TVode*TR~{LanMQLN4^<35Xy2#_cpF>bSy}uUS%BID=4wjlkGgsaTU!{>|Ho5iIz}dX zCktm2+W%!7OYdmn;9}zB?DYRGU8+lnips#uO2|&n!%Ndr%}mWUDKRWD?>fp)OVdix zjMFzNNl1;;&_&QgRw&Lf%rP^rFwY&rOw7{HKhmtgQ_xCHkIOVFQBYFJ9>GY;v?@`Q zv#d-{&Pp%KPE{T5|5q{e1Hnt$;HSGfKl}fAK+^x?0Xf^*>sy<+npo30yE{`!(bCA$ z(or7&S3k)2`{;fogMgs_+kUYBf9!{gqxH`R&rGkcZ((cUtgrtg?76AwWw*&;|E-^A zM0K#c{99w*G>Un8KABxD!Hgoh15nz(Y zJm?YMn^CaHB75cKrGT<+*ZNHGBFDTn_^TDN9x|qyi@92iA|+WvtCr-i6g1s4b$Pph zc}jypM~mu4Z9a2(!3vHE=^Gk@reF~Z*y@;qoz_m}j~>aX%{X}ux?O3-^2G9*OL zz2a&GJ%=SR!Exo&DoWX7_X3PpVul$oUfk82)TC;*S9|V`e`bHgD=d(~l^HGn6SRMXjW>bp!fj++-`hiPCpi)98$07bDN=7Wg7mf+7?KL5fLrHhQgSu)im zgA%^UP2;U!Fpj%L9Z=J`CPhnc;}FEBv7a#SgPdwIk~Fu(3*%VQYqhrX&mai3`HMk4 zNoC8BF9I~7+`_OaR2LlsQhK@EXeYwLu-$XIXY{^}9YI!E*FXm<823@JR9!#ELT$$Ci zs4pe8Ol1NG40g)}sYVmFw)D67cs38eJsxlO-mch~Q!T8<%0;niq|&VXf3*!^mF&d{ zLVaS>5q>sel>XD-upoT7!ok~d4+1eyCpN3ezxco57vet|p&Y)00pii`XJ)pKps&0O z36(ehw$PyF8qHqs_LHZ%%SI(u`k=(YH0;F!509_2=_+T|UyOR+7i#MUgMJ?G;u9tB z@ZfcM_qM)1?^g(4Xus>!1-^U#sZY1{TVQ*onr*nf+A~^f9=PB(3YBXRPn)f#b$##RA`4fv( zcx;iAL*5KO*DT$Ci-9$ut0Fkuz+r|^5eIB7LRd|;y#dWKM>!V@oHyvep<+MuhA>W@ zdB*S80C7Jm`@tqo#ep@@CI^q$nR5zF5(&wQb==d)zn(FtajdC(laWd)lJ#MdJ-XCM z5=pA+J?c)MAuzr|4bZe7_fZG4G6xpzE3ml52Lzk-}|&^ z7}U2O@%fHSp+S6Hdj6K1^>W4YxpyoNO4koE>h5gE(_;+8E=A z5ZEf(&xif?Y17E;zNbET7IVZ(kO&RT4acxPQVp#MC%X3O`|3*zleiVhIK2=hiJq2Ae{S!A&)wplM9#-a(h4L2$F zDXpcbF@~99ewuVjN=SP6k9zxn(&^1|LE|;NG%{T}axOV}#Wm9w>$&ZC9D19U!@_0> z`brpTgWb3dr{%IT{Xs-B-TqDAOCp?zUzMnhG(oK(8Ns#Fi7>-m*)npwLgDGm71=H2 z@LlFy#`+4ynt(!*6fVj+j8j#&N@Nx$L2zKp$xTB8x;r07kmGzVMMceqLDn{VK8MPb zHr^8db36nY^($}XnyVQVv+_cQhD=Gh{QkQ>680EvcAb2hiv4~vCp6D>3)}bj3psd( z+aXU-FYwA*!_`p`KIzcFzME3CQyZP)TtZ#hrqhHqRR+JNWn8+7;KWdh8$AYT4OUxy z%Ep%jtTfyWauI0Y#3`8QLXa!vnUJm%j!WrWCbfml@HA6-}Gp`msvU0PtOIoe*GDlwYIpj3eL!hYO}2oCuc(1 z8e!@*9|Kw+zY<=HgPmMsOIDa+sK*`AUf<-ll;Kh!j#`Ju( zj~}p~sF0NAtT{$ztcx}KE`523(Np@tX41E9GLDWt;k$9d6$P%@!D~ZD{_me3O&N9% zNYw^2WE^83VGE{?_5d^}O>&r-SAnaHfTB#SxFS&62$N>$MFVgCh?Yf|00dkeQhja1 zUlkqKLZWnLNHNXu6fI0pG_JWMQgKi$QF+L0&+2%B)?0W3IvL_7C^!;6A7%1qJVEo( znk->8c*_wPZAz9}OrsL3oM2BFJjzIPdM;X(D5mcZ71SHdck&Wy1J4~+iW=y4-z}!; zOn2(d;H8#^ z>TJ3m-mU*a-)850#%><+(v=&{rOql4u)f9lxhndA9VH(+Dx*>IkZy>Kh0wBs>qun) z)tfOmBT*jQSyL3R6nCblZr=Pf*L$C}$BiJ@T@#9a|5Px5Sa=SgKdOA75=Kr3rW@K9 z^Cw?*&Y;Nodx}mRikO0V*hpa2s5MKjmhi%b(U@V72^BRHnkg>5*Cm{ zAgm=kZ-}7v4o4S8f>G~^bcBPna7z$KAcu>6!02h3)P+k;O33cn(C zB5lIMeJbwjJ?<}vsDUj$&Y?t$XtQF+HKBJz#sa!=-fop3nr#*h2UEodOdY5qHO3SU z_Msx6CWb{;?5jTW^w9wOmaylUaIl_&KB`=`MsFI59{fc#jwIgG4uPpz9~!n&TPE7n zu49cFonqE9Z7ItU^w$>}Dac`$0;$+jVyd5Pw+^>oELrXkD zY7g>vdtQP*z%3hPeCYoKtN)Q1@?L=rbN`_n3S<9wLAJvG@8H(n!`RT++(cjhzXDz3 z{{S1b%#2JwL9cN($BrGgxM$O0;=Y|`s)^(m=bij~0R^`lUBpZpHz3gutg%?jF^d5{ zm3Ssz$HO&@o%yef8f7w(d96S|>8UUb3uN)BG-5k{A$Vkqz&ny2PIzlY!e3GRyOAX~ zfrK(6Q#ZknUKf#QBxq~kFupF4c9FY=&mX5$$#o$rJ< z1@Fi}FMCh~=sm_^4S8b12;W0}VbZgEw@LwUX`#0w7Gxk2&IgFk2MOy)W}uhfSipZy z4-D`IFe4Ym?n7uEHv?UTFAkZL1%Yz~Unm8W$!xD*ePC=_BR$DMIndd^~&s_cMK`8G;77_YS77Qbl|is& zBq%atAPyRVvI6Zjj@TR+ZO{lD8J#i6E9y|mJqD$TS4~hTxr`*c=~*eeLv&=Izb9@C zl@1LflvO3-_>VWX}*@bDFEwSGj|SP zJc=!EoGnImqG+nl;8cxU@a>y?T-t8xX=Lj^l0|46rfbM0Np%La{jH4V#*j>o^Ry5> zL2y)zv8QhuSRYh-Nwq3(?RG}g5e}r_yF!^as3p)dz1H5oVM6GTukJ{dg~scYCb2t$ zw=sdWa-Z)R&3pycmvY=-1_a_`H+5dT*z|=1sX167_btt(p7Z!xc-FI(*LPtgr)?7=F+<#CS*RNh_5DmJFJc4Gbch^xpXLCp zUO{!1QF9f9wcrOWIr2jlS)(iV7=Ze)1u?XRj0W08HEYB;X3HNz*M6JlpjiEKSar1u zJVBiyWR0fqCzSKuBoVp`0`iY+AU{jaR#crKgHxUP^9>ODqaO@n5!%GC+--BwAAUUw z74&>LruK)p{res7V(F`H4eEJawnlqI%$5I8?GKRA3no$!i`bL!?ik+d8>ty}Bh20W zQ(h@S@XhZ6_!JC`Fn-&Ol=r{j$RjPwA(I|W zYfL+vjih>aNE^p>3lz_Q!BtW$AI1TV<-k9-opQvA2`$2RAh|iEhrk7NFxxmpV3i47 z=IFIXG7KVf&%dX`3YB+EX3cC6a?xIk*-?Sq$FUNk-lEd#X++l>yDt2#^~8`of*c?v zCELkow1tWI~j?Q>ySAY ze@D08MtP@hoHxPeY`+7WX|`BNPg1dIc?)rNV5zL5SKiqK>ElAQH{@JI$UO~(A@Wbl z+3mc?PvxXB~K%cyf%gltXArC`6^54SB$)tJQA!(qi5 z8s0`CQ(Y={B-or{*rW^G!LeOi+c*fXk>K0txwEl7H3PbgNFHFQ34QHz!=txd)fpLA z;@c-3kk=DilM70$lqKE!nVKr`B&;LaLX42Ff0eHOaBQk$@f})m02{62IyD;0eLX&i zxAHNYx#I!dq%fV#Cg!%!*iS~O+Xyw>ga!ug!n1P}z!_Ez=t%1PJ7Sn`ru3G#544e^ zQZk_(w;}2x{HKmEyNNVa6I`kEN`g)GkXbj^bH`Trj@AL*5?wQ<<~+F>X*1j!+Jd4z zUb8eC6Sw&FtQsGe|C|V9?xL$YJpj7DF;o)|l3dMLgo^<&j>;vnf=M?3PX#dITMt^NK0!1ldJ%-i6dC_%uu5=3B>k3S)R+x)2>`8uR9Yf&e-peno8sRmwsWuZ_k@{-jA=2)I2%TY&j ze~TSlPB`YYt9Gs&_B3vmHp#W!r2{EY{!*M^+v||Ci6_=REnF%?>iEQmWUXxTlA_uc zM0_+f3~(Bmtp6r8pi(exug0m-30)KnnSQ@Buh=sw|B<>A5QL&hW9{Dm7>KEQ{=GVJ zM5H4qLr!Oj)YdMvoe43WD~&w?E`kcS@?7f5W($Cc7eWHY{U&Sz?Kx!7Ija7QG=3> zP!m3dvG1FrntEfbr%um<1ld9OCB*;BevAGWj%QV3*L8Joh%Br^)CIY&O}Jn$;#*7r z#&39~hAOsxa2pHTDhgF=2t5oU3-JUOZGqz}(>Mb3bJKo7T2in;)rt7v#THob3I_Bj z@4SM1s-`nOd0Zqa4y826b#>hZyIK^9zE!ofv=8R{?q+OXBjOz;J|WA>uGGo0TF7zx znq`8ri6a8ECwP)@x$2`k$|ZA!&O$pWQ#AdbcD|ZY=?J9G%*Rjn#ovNaL-e3PcgXZs z;K0^3H1za$#Fng=!=GaPQEZ$?^yLtbqO9KX@bo|55NlUqC?~78KD@fhcjgl!jt}7U z_p<~C3))zfZ`8Xd*dH>th5Dq>Es@$R3AZNVt-Xe;fZMB~*Q=NHtFhute2i;TanAz+ z=0~tUOt*MrL;D?=PfA0`XtwMm4)>w#mYq~-8kN490fhHt{8a=+E!5p@*Xx(e{T|gE z_IIAjEm)QgF+9nwX*&~HA1FZiIjUFR$M`SspW5Dfip;99Q}Q?XmJ33TU&N$4@T?TN z&El@tMZ3RM=Cph+=eyCx_s~lgpT-TIxyuW3?O?`X6(qjYph}XzWVO1kjq1uA+aQ-^;AYd0dF4}t?i8}fYhkm>8n!ioaChwF| zRc$87$Ww=xGyL)IRToh7Hp%Ln2GGfUMY&?+Kf;8>pg{{6tS-vFVYw zHym8BZXG)*enL9GrXqTm2T@s}M>lvf67`ecKGFvzX!!^1hhDY558bjvQ{GxsKDdV_ zf!4?Rr#K68Em^w{Hi|&MNJze~D5$_5L(|lMr>d!=*X-!Gb$WVvj7vjDw4qXgyO(mI zcoIv?K&06PhtN8KIq&*8bg0J%l#Yn2d>3k~$nm z4J=o_muy7N)@y&cE&F{~J2S9-Lsh}jPOH6Fd(f&|kU9nbD7xtHn7L5L@|6!TI zxm$!7=n3KM&bkiW4K%)rd4JX)K?e7Jhots}yhYtZH?IL0>6r-Vp)m9ZGe=+?*Zu0_ z_#{Dy-kTLXbBh1Of#ZiD|Av&|fmnR=JA=LPgzWkPf9Xfx)q>P{2kE-O$o7JZ<%dx2 zUJ6fm+njntAzK;?M654 z=Xh(1h|wBtB}R`muE*@@5RbbvF5||u*ef@ZSfK||+{is%A?J8j1n8BR`Cwvy-2%%M znch=DOvhqw6zD!_>=xgT->#^)~&Sm`~1Uf_u13I-oe()wSc+vhS~sYxX#Joa82K& zwW%A2!=uCNOvmlX@%h1nl@p@#HN)1h)N6lfHK`6;tSbxiN_6>f@=qzca*`fMaol5~ zXC{c|n)JB^#G$FDChv5>pmMh%FE7xDft`pvV&EQew<0eunB$3;v8N}-A>G5sqqETb za@JF<|H~e^_~U~hSi11FuE)v5ySgtj@9UcPKmO_4*{ShuB!<23M=Hj6j8A<7jB)); z=p(styI`0-KblN-J>c&Tsf$wNPjrJ#mcnoR|AowB=}UESe(Fv(IR70o*Z7|xb0b41 zlOKCITU!%jXA3)9y8jKK7i;KRW2?LN3}SvM6N%o+FU5%`(?m7OuFr35$GCM$;&>g9 zC2Xa1bsDm9W8LaS5+jy%e0)*tFoWht3Nw{25q&Pm@uQHrwc%QeOW^%qUu%!ut=jwicH)T*0JaDr- zM7Zk@^w;{&)gg&#%qeP@!-DL_<5h;$hm-1BOS?!4Xbc(hZpJPVUz+ny_=!JgaO=gv zh6lSkolb?3NSe2@1mbVd<{im-5Hk}WCVA6rCGU3TLKol@;B1L=hzWJ3G~MNeZ@ckM zk{-N6k>?U~N(yyOnvMQriWBL{9fcx)ROnQozsV?jFzQsHhYr`q0EoM1qk`BdXJ>7T za|oA8?ESLnqkk6aR&d!zyeXpMkX&Yvk#1&LG&uJ|;xUz5_dfZuF*(?-VYjoRdcLyT z?r!Z-gy+OOdIY%X`P{6OHhMf?0-o`#xr}oUcg1Sj z@Cay-ki&YSkOqj58-^6q!#M^NlfyY6%F*k{vJZVMeb+iouw-pcD1OqOfHn8?R11wm zVd*akJ$Cqg63oSv&{3yio5iIZr8MLciv>iLNLFLW{DsD91n$Z{;yZDsrt*&j>qoB4 z24yelCMeZMx9f5);%iQe6hYl-Li{~myPPW8fL&htYTnK%N)EArx8gQ!XX2{Z}3L))VGC1UiE*{Xxx59 z^jr1PDLWEqTt~2RdbR4g-8%jvu_Q$MKYkU!k#`|cst0mnuY`uUiw1{!Ve+fU8KOB3 zQrp)krj#~D%`z7xpF6shi;ThXNmmMmSyWGIOZC|fGFW6}{nsFjnPfI#aH8ZRvCCRz zNeqk}ciX6haLyy-3}aM0OtxT0(moaD@`rCqGc)p!C6wIiXVRozVqY;NUU9ST;zX`_ znW^gxkCnTB^pr6@jGgX#_?v$rN53LpK`Oc zLiGfnJe7DR-_sp9X&n3A<4eyrA&a+#Qoql8!qx4E_*CGHrrqrKsL02Y^aRdcOXtA_ zYRNmyEFhUhJN=k4jChrtsgj@9&D88#;~YUiex%kiJrSq$RAH`o$-yL*ZYy9>DZ(QF1Rc_iab zJVYRkV`-Xv$i2v@ zAw4XZ-72+iW+8JcUng8T3n-M`AT=0?ZexDjb= zb`km%s1Zxwyke5xCS$rDkmG9L;|g@BpY++z!bBc6aE4^_f+Bo4p~skP%|(`u8Mho< zz(a;guYTs~sC1ma#zd?mBd(6bQFD`e0Q`X^KqiTTK`upO6H!vbQcxG>o~QEdc6KD9bs>Icksu=6D1nYyE1G zd+@Ks*Lqx*z+*n9bRUyFAhi~-+G9LB1EBYtO+~+4Zl=Gha6h(SyABm32qZJ}nI8zu z0!tQZvbw^^cTmZ6UG!%%e*#>A<IV#_LXt3mRj=^kRghV~XWZ5!J*G#Eh44ZiE1^PHVM*VZ< zxo1 <-=s$#N^QsC9Onk16Z6(7DH_N#63#>||GWi1L>*ciqkbQ4u?-qBD0g>wB^0 z%H=GFx}6df+0Fd5{tYjAI~5R)qKO`#wa-IX3k6Enr<|w{bf@O|@8Pj!*9RJMwfFUi zMp7gj#@!eg>x4p9Bzw<1Fq{KBe_X(c&YcK9U&#NX3UCoo1xWj$erJ1ayPThY?{Qvp ztx>DaawhqnaE{LKYi!|W8>kxP8r?&)$n^1VsL{|Wm6_ar)1b8L3zeYpSoo%rP7)WW#0 z^|UJN^U?ajw_R1&oN#o7jjCq1BE{g+gZBFIs^*PBfCt?}x$NJHOMr(lMz81GraldH z3C5RvrKAj)_Wmn?sGZ=1>(rE0bjem%=XEc{SvcW+7)lagYtCL z^x~u4_aa-pdlM>C`)ZVKtqI-#c=p-&L~u}tpUuk5OrV3{+4wHMF(r&zo3z~eNov~n zGS=sn%D-wg--xCLsP_rwL%)NGf*767*P)rGT=poREhPv`1HsaOvpnD^A0qWXUSyzW zEHrA<+!HZBNAAj{c%)?Xp30^D9JF1{fTs)YD!mZmqa*LHyff0K?+QDC%#l%ZA^!$b zrES9crvj@2*W}+tdLhq|s#Lb60WS+oQsq;dzjeVXJLwA@tPeIf>PHzAR4&R1DQ4{m7$DwXC-N<1HkNDxw&q)v1k20u38>plJA&7RN_T$4^OzUs%p?eH@?sB17}ls_{|7^40Eq^}H}q z@Ru@}x%X?FFz{NK_wVl+Z!Wi^ytHq`nh<7N`ru-e=kK`xBq#z~{vMEq0|F|?`tJaZ z%Krq=7~5G}{|AsmRrU6>Tu2}z3GNwMRV=u-TNgilzfa!I+Z}3Z>Yv)9=gBw5 zG$PPVT>j~7iJyWr41Avp5O8rJfmjFyOz)y1mxwS>2E{L9VH!%~BAqE@$DwRO^4A$r zT}HPtSzwX8$Dl_35@e9m@C8QsG2spFqHPV6@B-;me_(!UXLtNB`1a$agx zesRmvLRQdI9g;ww;e4GtrL(JjgPDx-`OETWDot4d%d=;Txy7I{y~B0DRM*I)k}D## zMAByjU%pBK5`s4hB-P-jJYE`7LwD8bbB91FC%N2&VYA@nUFVphD~I(s@CqKTP@>|4 z!^R75kj+b>>-Ypng#=LZ@gYkj*hU19|0LOl$TIwi^}mbD@kBGpVnycTOGSzs4k#)@ zD@@E8FmR;%Nc(LpZ`j&ok2KLl#Z@&7c=y1 zrld-7M^pm_vR#C^$}wZW*$g{L!P4194rVMCWkLNFtkU_pCMtWzAaK{$>2t%D<3=GN zO`$YVM|yy4QT?1AimI5Dg03pd>6E34HC|s?Njl175{$8Im8`YdGd|=GCvjZuJ{5)tlQ#WfDP zs^VfYP>S2A2|RNZ#_~}r9Sj?Rq%4I5R8%5TDygb6ilHpV>fbg7IkqSuVnf+=7@*UB z>oK z_NU&R+aAvndVE z*&k`_b9vfsXdw3*b7g)+0yHCn7>%)uL8}3x-;RgV0UD9V;r!wm|2l zeH7r-WYoeq55lt~*p7Xkr#XLw<<@|x$=Bmy*#;^l*$zWx=h(+XsSKE_bN>kAtqGxa zyTNqHgiwVE$dUhIv#&*e_BH03Ahyvy4RjGD=(>LBrFZ_g-v>txs*1Uxj%;kh0ohG=c_9@L11izsv!^G|lTNYMwzLNo-JO6ByNvnbm{ z)WEH>pq~5QQigYk0ep@bQDUkaG=wCc3kL2jfxB7H3(*zwA*2a(&fel7^EGX5@%|8Y zQq07jlVNFi7^d=D*-u6WnD~!pF7 zU!%k6$i!m8nVoJf{mb=pVTrGi%kaVx*xUjX1}*@h9<6){Og3QA9|Tn*FfC)zAaLQ| zEK(&3(Md)d4kANvPsh>lK5iism#9miQA(nvenft11-U^c0urWQZ{zXVzsWLw$mmW= z^;P%JzK4L2j+ph1n5HxDt>X&e_So7AVRiW*#YyJ)$Gi59A94NetC|B-zx(YJJJ3A?G&4?Z2WI?u_Qe0ePMsC&%RRB&OPOt~NGM<}PPv%_ z(bc23v2dJI+a(-NIoulU`QZvQ$rQ`w^9Tnln<=lQKh?;*SlG7|c0FwpT3gl$lug_* zNp#C=(@bPTsOx1hXjpTe>$VrBL8kW;uU$q)R{pj}<51ufh>km;@X%2FLpm#xATlJl zjhS|k-ZbWl_%lV4i3>TdS%cgBwT~zX^(}tKdoC9+GwL69l!LFDkovY{MjQFg{M%MG zK2K&hV{&PJr)VBiQ^hO!t?PfC&iimR?j}d)%$IuUeF19PsgNw8gIHDUws6K)lt_^? z5VJso$Ve`b;!QRC4{LikFi(+F;y(=A4U*|C_xosdYhEZcpZ{}-x=DD5ghL`tkod)qVO09)`Dy^Nd z(ml3Srtt582vEI4Ar5fDND@Jb8qJ9C;qhP{s7z7oWngM`SOQuec; zsrStpr4Ef2gCZeS{Xb_%OeBZn;m(fIHdro)EUB0^ClwFWhb&+|58TETBURj(N@_lN=?v?za9 z_0!|<%SLqtzl}zK4eereQwvqIkiMITW`Ez`^=&pTNsAr{ToALfaAdF<&k60~D7Lp0 z&lTUMXEf&GAcjA=F=8sR?EW|%wPQ|u6euZ)(|!}K_tdk-PUXwK!%*>6ZBa@SHPM~- z?2psTIqdJY543-+$6Ks3?AF=zdwtF%X0&5y3&8EXRsg=MfB@Nonc>JlFmt_UAcd44 z{#ex$y-KTD6~K($TW#x;Q&<(kIbgS+_Xa6cU~Q*2>(!jyEnZKMKp6+DD% zR<7o)-0H5J|HX5&VT6P|y{63DgFu*=O_-}ttQBV5Xj2i%o?s5BG-(i_F)qOQ9o!|4 z6ghAlD8NI?Yw&>To81>D_~E{C=p=OIU9x8xqR2u8)k=8;?WEXKLJwod_vRpq`mX8+ z!B@tcZPft2^f1-bucJDRm^-t4m2KvBOy$kb(Q^tSOWW?VqvhPu-tx}+B|0(traQUVccrB!Kp=$YE$uo+rHm3gk`$fz@{6cPpNz4x=q_bxuBzjtY& zCy~Nhvu^}`{U^xnhZ#$_iGt*kco~MxNwOYGaR#TlhcD^hF~*AQMiTtBuR0RmoV;>g zNmxKOM8Qu*-8F{Y(DD;jLf=)EX73TB)Wt+$;m^M~C>}LKXT*&oRdn%45kw+UNvOu0 zjx;Fxg4{9`=GTWV#|Wv+U@TO-kBEq1pNR6&QE8E6heyKDM=+ueZB_dRhlj;V7=w{S zXq+l5OrMHtEX9*pLfxGt6rz-{PejdARIG*^;`s=@KVP5hMd|Kb%{N?Oq8gW9$8MFbTOY$G9QYIpb6@wzC<__#}E%&zYbB72E0Je!)@()M&L_|6fzLSB;>EQ;o%Po zQ;ZYIyppF*SHF9mzpq~Jt=j40AFkpL*%dW*eF^2ym8b{Td-?F!?zHe}FoiX$K{`|+ zD{AVO_it2SKcPHyf_lD2scBSpR`pVkx!J(q0XjhX3-^QC+*ML-q{KyrX?Tl@Tq_Nx zf=w(`)Qm`KLo1LHSc;<~4Tq>tOGHEjVQU5U%l>}7L|D73OK#mh*phrp9D1`LTM9fam6fuHg zJ~kIoWaT5OkmzUdlCJBN%qT=vOsnwh8uwSu{$41O zKEE&tMALhVGgUiAApkC6r&4cN6#5Z{_{QH@{lEb!wIyYHLGleJ@eEB1itm;gL`ZyD zkHkO;`VihU%dt&(v-ImS4(-Qpa(3m@BDS?u?2M5y=Pl_ac-<|U1$wMaZV03R|6wdX*@hk$@1paB_Mw;b6hdo*NV9FSpA*hX*DXJFW`gIaiiHG7F}G>leo3_&bDkkO(K?$h@zcr{JB)*LxI| zKvYc)F8QP?YLB0~h*>5rualr9PJGI*z?)$<>dau5gu@NsEy3A{;I_5>a^ z(oLB=4OM&4apTu~M73VoeuC-@=io|1#Ofaiz*_!vG2-YO(p_(x*qnI$g{Ji==qFkA z*3^HeR-~f1Z3A1KcPQlBhQ=n-SRi(Y$V%u}j`=D~JBDu=0x&rE$q57j3>QhTwLn`3 zjwRXt{=V|3O|mw}-2~PqUq?c88)%VaTS9Q_XZ>m9^@gkcxg_q5Lz`_Pyvx8SA^&(N zTRhIz2qDs%Y`Sc8Q|OlYpBgw)WeJT(>5f{Q2&_y5QA5Oae{Y>=3QPKLXQ5?x$(5;M zG<<21W(l6ihmoN-Wm@;41?b6!ws0474HZSim8?Xpd7=|V7R^i%ZgxT{?UJE^eHRadjc#$6wwuC0 z31u)3#lR}Vpp(F=B4kAvVk2cF^I2TXU3@@`k2Jl0_}S1j4P}d}b5tPE-#)|lAa&%# zF`WdA6+>G56otX`$9pOB9BGT9i(cIM%7C*v`-L*q8!JUzZzgq8T zh-%5NS@IB-=DJhf-c26W=wA#($C1>KM;0^Mbe+R}gY7(OsC#r443^1+hbo)M5RPf@ zPI|#(%*kW?*a$&y)XFN}WO)aa6&N#hHI?Kq}j0Gs)sFv}h;6PE(7N*NrKSP|RV{Q-LH$Mw1495ZxWZ zLt`k3c_x=(;hD>AIi!H~!c0sFjwvS?qW!zsqxU_pdP$0ntwokm-HT)H2Is7n^|14& z^|$U$i%xUip+|O}s@qQ8lm4@emuc*F&DBRr8QDoqkLSnTE#|1%wo4S;&B~dpWka|1 zdPS1{s9cStvg>-f5X}cjO6kG_hD~0Oq;ge==QHvSl>j22qnIcy(W5oIeP{z`;!=F3 zn*eGm;ev33j!Le;#O1y zZ>9fanafVBI!hrOx3cWur%OxMs(L1SFpo>$L*Hp<%W7vFlk%7)q17GK7M3ipq?&T) z8c7{9Ls`IRMYpy5F}+0~Uw8Hc0nsx#ltyZ~Da46)-His$NxYoZ#XQ2m`L-)L*_9hr zcP1WW-pr1~cRyA6Hp)1f1Zl#ahJz0cV_a_X7P`0lv(`+vw)SUH>%Xnlry18Cz_Z+r z&ejU&wc27{13FL+HH=MH3G7V%KZR>TA_Y+_ks>3a%8bG|Ytb@AbMkk+K@3*6u}j!bDVE6uJfkPE=eu34m$V zG%GJyZKHZS!!KaNHyKc%6-Id1W(MiZPBDE8Bf<3cK3#*wDgI}ula5=a5Q~WyKE=D* zj|{y1bt$lr)aW8_@FxNz2~6R5`$7kAqS^5c4y8L6#vi3Vm@u~ShFMc3@^H&_nyj=bFrR*x!6HV@u_4F#Mj-BpHpQn|I zXR6~C{ETZpu9Gc${<-^mm)6y3$S0bYr=EknnvBa?h1HzJ8LO*|n#FC8o$bxgPgv|& z6Ly@e9s3X1(68UBw^gi{%(F8}%Ae|SdVFt##u;gJc^X7$KUPLsv+=&1*MRpUl)exW z?kDydNX}95oEk`8Ixo!D`D6!`*E>{saLkCcD7{k*=k9Mw8(MQll z$YUQ|r~iwza|qHT>ehAHw!3WGwrzFUwr$(Cy4+=S*|zPkY@Iq0_nyhU|L6=dBB!}C zVq@)hJx?9NJC)lml^-sU1D@gz<)}MUj^jlcWJx`QZ*qsc(r#2ZxYW(cBp7-DB)axU z1fg>krOkv84>tzCEbK!-lXr__#>8g)jbrLP7!l~mE|WW@+IF;yb?b4U zT)>>teIi}-qkFwOvQdLQdvw1|2&bfy;-N`by;#105sec*$*_p@U5X0SZJhWz1euMN zy57bz=FX1SH;;CTc=Ww&VC%h8XJAh0JVtJRzM(z<@(0wJmQ`vW zO9qVd#4d)E3RD>Jewgk*XX7MPM|Qy0*cm1@IT~dnNQ)Fmu~?+klbQIpUxT}bNqQCgHZ*0m@}OCWbg z0#zJim=GT$<%J|QV}kN_Lz)%JT7s77vSbM4*4POX$8Udf`76k(+|nCtiDx#(khDU*>1*E(o{-dYOv#Huz*dExvR9@-=;H z^n~eNbZET|A2i(z2kMBdEz@DM-*3k2mW}Y=XtDL4g6ePcKc5VsJV7-j1;SD}k^ikU z+!kK1+tLAI_U}hSsH+9K-~po4%?dgss1y|ffT*MtG|JF{FHBn1eG)m8HH>C_N>j-N z(oE5gDxy$guXH$=y4$U1O&qg2w+@$WzkHZECw|$5W-g{Zx0(^7xx{RJ9xWB3EwQgI zvZwZ<>yb4jxnpLqssuF{i^bqiF!EQlXt%&MTczre9m!YwsAO?}FViTSmhyd;AKb z_@L!V0nxF?k@_`x&msX(ck8Mj? z%dC1-CI)F?+l$?W>{E@o@pYA+pM^8Jc+$0`@uT%IF|#lmFxMyGVPr?H~IAf zW!6OGO$2_1;gr?lz}ALJS*tpRjKHHn4vgjo7jm{>7@@oQFTV^E%TSr=(}SXQo{9hH z8f_Ps;fuq zAX9g$GF}3gQWBp(K+&wZY1@d&Hf-A1+4`IYT8hf z<&&lMy`GnAb%H(;zBUj)mUFv#U|?u=W!19BdIyv>hd*J+C`2u3iQ)>2P`G4uyHi$Z z`?HAD)UpI8c@V^g6RJw76(XvZ@0;OBijl!UQD*NtkCZpv37`DQow0bG-o!4YI-$u6-BA?XfWQ zMucwp8f>MQr{234n-;P}~=Xy8iVwXCTeu|U86Dns-z7?wF4WqrUcb>dC(Y8UW%q?2 zs4q3QCN;}6LXawgR0Sec8*{=W!7AOClGMrG80CsxxJC{U=*rK=icn+2quad0JT3Fj zRSwQ5_`BUz_kyGKA5R)J1uEb3tFN5mt@u=ycrvX#(!(O#wGkKxrKhOU*(4ClDx_lH zEz$893#Yvb+CmicNuvj4*NKGT&~KdLPJM~L9Y-TJ$BQjd*4tF{Csn!*Y^Hj0EMJ{< zEnNBjhn(J5*16c@iO&n;t2 zlF0Y;*dJdSk{0&nDyZ~|k)bPv_=!V{p@~UqQ3rU*lL}W{bY37QmR7TA>XFz(ROBWq zEb$XRab@RG)g#*KZh;Lq@l`xfcYS8Sj}J@L6Q*3Qf%}9#&(rBBycP4o>h6 z0E|YXozKc-u)D07yN~nWtM}y$K#^YS0P!xo1iHh*TCuf}AW|8O5Sc5j-$ILozeL70 zU!`xdc*Uo8pU9}>za?ew4UAP_; zHw#m1>-xIt`N-uQ(=OX^n^2Pon?-hWO%f+MLC!7xp7u!B=XnfL!WT<^Rr!TI+u;2! zTEe08GgkC7r5|7<`wSAKWquKk6|BruxMq7@_V+o~_tY2{EX$6M_kvmqfPmn;-ap5{ zl0vgZ6xC-yERq=e5j{e1rT`{pzty(M_ZkBqCVG{0TC_ajD(CjW79PqECex4Ee`E>w ztdlNgeAdpc7v_7NcRY8w&ajiL5@&rka@(r0E zvU>fS07z3q&#b)9tp-F~Zv(!d9bg+65k*{p^pBWa64G&>YS z9I9_iH#triFf{e z4{P7450;+|0-%3dCR-k-R%{w7QUcxeYQc#!RbWAZ2wJ)c#YyTJPZM$!|Bb!`V)Jz^ zK)`U|Y{-&T^`gtq{0;ioGCWV+q}nQdAnJ206DXhhWV7I{PjxMYa89FH2d>+i-0{1G zcCx?l11-6I8)E|`>!_(!TE*_7-sH85XG%TZN1cX$3N~CmwMFi==9mA1&Z+SihoRo7 z>ZaKBkc+0iwqr8R7wNian3_(Ex}O4SikoR<;n~%iRt0UbG6+!@ zgXnZJ=(HM5r{LZQ9|+CPS27Y6uDU#7CpSIhUBtWvRMVYMeeUK{pq?-p ziFC~<+=82C0-Y+uwzpE4xC_lHqxL*9h9PihVi|P#>0Z@~eVm?~&Nc{QHjtV|@RXae zorC$uR~R8IISXiT=%9a^6Bkr({nB>>@}3w{kr_du)nBOLcAw^`#Pb{q3bc77Ry&p@h<9qG!2V7RTr+S)avV=k?kU@=o`>t@-{ePrN55i3 z(9VTm0>r|KDhz@jzoDr8;kmysEk4;Sx@X!jGlms1hj+MuM!xOc4n)!ps?7Befk)IB z)Ise>bWh^iqjJ-8qUm>QdRgDH9->k_{kG@4BHOQT{(N;?Uddg<+s8egtVXRs7+_D@ z^SZl?17sqtNp8@>% zl=?QC%K1H+J1<_tfjGP~io7e{GBNGK>_Y6g`~clo-7F76Bf0kGozLbgcpgw*6>s4K zi}$ok37)?T{Zv~0l7SojMy`SA$yvYr|0h?s+M`&!Ob!H;^3x0SpE-H|t45*!LjyFh zHT@w6n*2Z6x=U?)8(ayu{3HLw6w$~=(}_sFG~`#%XlH^^4&shO$kJq2A{B|~nz2CjJ$mhYXAsSH#fcIX(G)4Hd{D>$Ao)sx3vXdlkg}Ad4 zQFx0cTVAvVq;v4Twn;a zlW%V=(S5Xa{dK$JFE4bexeZC|ms#__lULR6^9}id8EG{cH5Vxpx}_Zr328OJ$(EuF zN}(UJjXI+DGWPnp6TOX`?`GPKVf1u#dflQXq4ioVgA4pLcD=nGo`CU7HtXIkE(12U zx@D8$d(-i%sL7*d6Egiocn}zU67kq`h=wqIk{!0l{uAgwibIsH2xIpClJQ^I%s|K~ z$!IC}RLau^LQ&Tcu$I_qQRE}gGJQ=W_JCMCap9v@(_>-Zb zydNR#&}2S58POg)z2o7?WKKL8xE1dU#k65aN&c4-lu=B>m=!(JE~%$vLDlDSY9prO z4pPbR!B`%(!VTKBmL<|Iai+W~WL?ZEjG5xrq71uL5k?TWW|hQ?V-R`Bxnd-8ba~^# zFAR!$6l59q)hSlsv=>np+gljh(-R$CvYJG==yG+;9aYqWePYUq8fxPq!D_EzRSX9x zwd$2|p55YbvJ+S~zs+Xq4|4XfRV1Y-wW}*iqfSBfHkVCPEnqOlz_Pf8%7pNK)h$U% z(N&XaEu3S&C!$8yEbv{M6pl56sKf6S3%L}ITM`#pB5foDnu>=IcNPb!;ormbuNZU& z#fxwfrTm$uGrcKozi-0k<#9K)v!u`cRK5_aTJ-0-rw|;1j)3)XHa5m782w>;Fn6`K zvV+6gj_dTeCGhR^hgL_gq%psoySC*TbU2(r1H6CYH`EudJ|au0ac5(OsRwLo3-#h> z@HWeR0z3y+Y~t3ksa%#b1Rmth8J-zpvab6GQuOm`L9aNE^T8_h)-)Gb%?IbEdPh|? zl@}pNZ$lwT+`4`{nb6#GwHVAbgGmXO)kImcEG@^-xIi-J0@5S2JVakPx$ZIPJA+ zi=!bI>~4tn2PyS;N7+FTq%-}r=|WPfZox<6Mi!-Wj8a-$JyS+6-|H8Gp3n3?N@yYW;+gyaV12B_~q9O{L4r|>baKLK&8hUjH96D#l9om6n9 zgx|MAbLa=C68koOM*?ogGa1h>b<#y=-%}qu$=KQ2{;+TLnD;IBT%w=(drti3$^*0( z%&Wx)4E@)$&3yz-t*G|~dk{@zm2$AL$Whr8CQH4$H5e|Q8%P0Yy$TO5 zux>NN6_7i+xV2`WE8L4bc7Iq?q<3GhIuZA>R3ui|^EM{ zKF;rYYry(*<@N>MGeT>Bwz3UP_W-6Yo< zr++5zt-ynKkOC+rrgLJm!RUVgE zB}v@y`!u`eWzEOR&thL6TYxT^PlBA*g*zeRm;p3%V&(0^HIAa@M#|1fCDO< zyI0nwhbJt3LIqZpLgk*BLG3c8FMR?l&(tAS*%tEz2^MdA#ipnBQhk_akWfDyB@{ma zwKfjB($XmsY8pbiyvy{M6@Y&qCG_}*1F5LI}~J7=)V$O&?GWNGn|iXS~Rya=e8^s&H%~LQ#N#Iu)kAp zt}FSb(32udhvX^P8Jo10WrcM~j~-*#;3>2h zk#-utMtCGLpZL<4<4ZH6E%VXYpjLNNu+?);!^R}_*`=#G2v|Km&&8h5&^GyLO#Z+N zsn3h3&(8L@8faH$zn-DqnXi1;tmIUGuK5Xr;p41hE6rl zZ7`w{iH=M@Aai|g+_}*_gTNy|M$MGG#8m>Hk=mFs+A?Zxq394d*tSR4{?_y;?^M z5_JDKkJ*f@SRyW%$}Su`8`b;lo82T;v1d*KpTB>QR~okC+llZEiM)OTU50jEEX7EM z&L)f?aW~O>@E*#g3<+r!98(Ufogq8nH8{d5xwbfX4&b*#>Qq!XvID*OE{Xk0-(vh$ z0Jzp604v3pI-do=s}nVqjpi^`Bw<11z`GA*hud7jJwzmA=Zpba@3GfFs~YbFv^cg2 z6uI`D{{n97CXyalwnS5~%d-aLwiS05+xEQe9-h5VY*0+wiDxAaK8N>m_;9>Q9gg-6 ziD%vJ)v5?=`d`1sKZAB$4l3B_docPKCj0l^b`NhwKhs~r<@kfs}{6H9I;| z@9(N=e!T~Ni{~`1ov(mb0Z2ORa=bvJN`wpF!48hd%#wtGe`!c+v9sk(2VAw1bb8!W zUZT#N!p6l*ybh6e~a$c_JAEGL)LM9zS}-3q-Omv-P6eG_ z9|_g16}FYL#4sqbHc4f46xL3?Xd8|28OXhCC3e-)csycHiBe+7*W=o_?J2C*3<&?yR)g^8iZQ+yYYn>ZJook?<_O(l%CdIzSCg1xBY@ix01QE z5<7=_oHq6BUcE=CZ)g#YA3;uN`YxL{wV%rTZb$)Px>~g(9zon>YC$PQD;z;{d1M2A zUQ68M$fF}41FL?%&`hs_s;Z-W*z?%(Ol`hYxpsWQ#H&<1?ftD*B?D{Zux_q(XSMJu zYEvB3A%jh`dtcUI(tmi(X+uE}pC2JvM?JIO-CXme2#qTdkmI4t%4Jp}TCG+@!ybYL z-dCyCviQ{;2<$7bx#)FH^#5MQ;(Oplg>-=&BI*UtzH96_uIU(O9%qiT+PW=Vr0 zs{yTJOno9cBBq>_OIDqLGlxFFr=oJ+0k_ShrD1{IS>8L1a`&(X{u`1V1ildB7OCfg zBCE#GLr;1m`p4FWxUw!l83EE}Y<P*!BFj=7(@p5V$fz7>p8jFz=4N!EgWqh7B&pZto%b{!y|Kae= zVE|FC)-;vEltNhkiJ~uJh$CNS@H@MW$HzPYlFR`&9Skbrt`XVu#aGESSx7>6gs=Ve zB~AU0yf7m^AW+<{^5aR2e~C2GSvp!yct~4_0r9^ z?6|(4N?uNglx(1%)wlbNVU^t5Xq_D0led3p|Iq7waBy<+SAo_>oFGimrIC_oy%a&+o^mG79dUqx+&o)lZ=9ljtZ145zsl1UB%}v~s7}^z=$KQ|J z)w$zU*jhpyfkt!-F=Rip`}ySyp4;-Q+lE>W_x*7GSdrBGueJQH2dR(w;5e&OnF#`R z7@_9q&XI7B?y~cVHP3d4{9ZeUG~mfk_)VnfRT!p!a%DQeFKGz0w6t_3sBV`EUZ@W9 zvG)gwPrv#&aV{gdPNw6~DV3`txxDb$IGuIyQ4sO$r!QQe=uVN*>*#4|eKLQl#Mxl+ z$+`Xp3m1Ks8T*N?$bUm6)41ANYTqz0=5Kr0`{&<;Hs&|~g$}K?e>|?#@y?xM|1s9_ z{O*t7?TOelc`_QNC*-I#&o5!J61(#>Bz^5dpE{{lWnxP>c>Qpf({kPpx%UiByYqa) zbJ>i}Asfn*khi5*?}r?fM{A%p0>ESB-hx6GZk!g{6Jx!;MxXYzU-i9U0#kW3vxUT! zWR>e%5b&?dDzt<_2G2o8n$U1!#k2}rSd^ecPz8lKS_73(;`r8~gHpvI;90>3v4-Ty zN9NUn;cV~V09&GoQ4o*`aYI1F?<=)^kt} z5?K(w{YA0(aIhAQXeA;_^F76#;ZW$Fjlze{LuQWyo8crEj4DVxTLzMRq7;lOzKvWa zloTnjz$#fGP2pZcPQI3m<3_^s6^;qW2NiB+gPB8!LAn}+Vge2m4}qfhPXtqv)$kIK z^;tV4Cwb+)C!yHWQqS36)v_Prk&(tVMSU%@N$?qa7oosFNyubSl55K6G(SRi*Z7Tm z2-Jf9dwQolk~ah{nT;<0Z_tWs>bd$M4q=5pvAP4aMg6D_4W%D&(?5hu%>xBZIk%@z z>dmegA3V>oX+RS#g**civmYYS;+;&=16S4u70x>*>&wpzqRWS~%ZI_-M1HX`q7h_k zu|hY#A7kLoL|3*YL{V?2hqdFyelE?mZhLx{#+UPzLd$!(A4-=%lk?@}(_Ryg@rfJA zPLLVwUyN4yE%>NuBey5M&RiciiW}Vt25<$whj+x6*0~q|VFs`g76Azd z%$_fe|KYb54fQ~|BLe}&|48fqbMfbY#cy>pb#ngy&|zfbn4|{bBF^;ZO| zEj396$eH{|Wun_neO%+RsCzSF)^o4LAUx~WdVQYPNOFhSZx@meEP`BgP~75dn%h6= ze!6k?JmnAzKY8Oxu-OwJKV{;#e?uc@ug=2~Kz^YAm$?H>1#CV0Gq%S+&wn0G<^M&C z>VKx~bbUg*;GOsqM))tO`R+gl*cAlQZ(88NZ$pYIlL99MK?Sk`ORG<~RL`mb;aq~& zQ6qur-psOpe+Sr~MKtG-b+;N@N!XLsvSCjT{}6fJ*;|t{ZznIk7vvPrlrz1eZE{R< zGEJn3o1ISA4tx#p^+1`fzEuG-<1>( zyan&YC|5GQDn_E~;ieQv(3FBbR8Y6l5xp_`GV9yd^)ym%3mW{|a- zER?)Cd`Uc6yivQ7>?u5HJ{bK|Yl;AmI}d>9ohZQM&cu$DD+^a9uCOib(gUD+rwVYn zWA%zR%b$=VrC{vi&G*UUO6D~Nf$Q-oZ~gI|3G^-U%g@!i;Nrj6QF$(dVJ+-$tuL}l z{asl8wQChOlL=(3@6#mTfzZ8ZiE3zuMYHt^nvCPr4<--Vae-6NiJh*Wh8p^$3+lpf zuqa|6TIjn1gl}#W?XReloOgHcBEWZ}H;Lf4;s2oTb(2N*+K4~47`uo7{Isfg>Y2l`;w9gmqwKRu``+cVmg@lk|78xB{BSN5#SLZMP!Cg1nK z?CV@c-}lBOn4P3oLAt{x_@3Fe-ISN!FLyZ{iS7XIk6mMUn`qFt%Sp~v>C@Av;!~Dz zQnsIQ=xJwmylFv{Z$8gR8z*Il#q38mMOz8na}W1db<}xMHBewi@!^~&!{msCtE_(V z8$^DMC*v?Ev)RQ_7N*=xpPwU-n}gqvpN-qkkKEPIhn$U_i5qo{?fqU5(E=#V4aL^+0{p;e?&yR097oJ`N+>PsamCb_vX3o1iQem5gYdumj( z#zoA09VfZgi*VF|)@m_2^+5SCj7^j&CAY0E%z4xRK_}rbD4e7bt7MjXLz|RSZV9KE zmzPtHDeR>xUb;=CYTh_gWy+yssS~&t7wm5h>c>)3>gvHRP=bNGJUoJ9XPE(+%u=E} zqZ4dDi&&a^>jytK&g@KleeEMmnAbg1_Ux%i0KWXiK)$B7DJ~I4Fk-|OCkxOn4w5Z> zs~Bv&agxZ{<5-h1!vGiG2u58^9LAkKB!xXi6BEd^Sm6#j(?7CQawjW+;6h4k`J&6SOHEcynGk z$@ef90C8K)nIwC)yJ<26$H2m*;@9t6!2nOpjGJ zsd^&em4z*+B4g1>nc8J6K1(PqmNE}f&;dJ4wDYh5!%3VXvt>}5cV;-|w5*O`#1

(q*5O=d`4!s)v#*1FEi5+$^O&THwAO_jB?Cn@MX~hpFp9Y;D+H90C!-sU4KV$h zTRZ?t$X~e`u7O?lav98-+nEojzlqW8MXoYDZL7SS-bc}2U2g|l3$yRbtxP|-9M9>p zjUMyTO-`r21Mk1DtXSTch-k z{vWESAhM|Bd>{2nB8AfYT)d4EACB)dfvJQ)D1`Hr0`f^t#X=3;KXsSj^EDFsW=} zmET01c-fMZV3>c9lOefHppy&7L74k(mj9ZJVpj_hB!jB@b9O5V7?YiK2WRQO;GW8Z zaDzwv=xGH6Qq{aVwJMwv6s&_HTIc4eoRSngf)l9VNa^O!*8sqZa^`89MZQ_vyhah* zn);xu{?hl*thws;;hl_e+q(Lo4gS&XOOcF17oaG`7~c7jZV^bQ=*a>B3iPS{Tr=Ea z3q~al(qiTs`k;|#me``eKX!AVDCWqnFb}!v=5z^-G}V7hl?v~c>$}0UV6WamQI_+& zVD2%A>**LkGTWPwLK&hT!O5nzwj-q3F`Bglqrlmw#Yk?$TnyhZE2O14Y`%?3gW=tA zaHV7T6BSu+Jg$wA+>LG!y^Yb)%Qi!9P0s5+MAQ4~y(k70IerzQ-y)8?+XB z0>xRTI{(nK9B-0ZZs`8`URUq8<JirC|Q@Dq1LNN ziFqSDftHAh8b2uNL4ukPudmT+2M!p91#HL8FR&W@0JOK>u_sl%?*YGV_&=BAfe2U_ zK!bxns^p753H$-50>6>3eIH7;^pXJfoyk)ofk zV1$o_l$#S1lctX*eQ&Pb#KgM6igoZJ-Ag^ zk>oNxQ&gis(m#Yo8vuaWhM!9_p&3>!_spGHyP1v(4yxw+F?Bs870|^&DD`fx0ZGi5 z?+1e)YBv!W!$B$)HVzRpEUg%n6d{1G2C^9b9aF=P+yPd>oB5w4Y zhf)_(tXBxAf>@MiAerLj+OaIC2RYUwLE@>1`b@EFM)HnKltrszJs4u*EA}bZ;xo{1 z7XKz9X}c9Ss@tY_*;$7hz&?*US{Y+_nBMC0rPJei(5CqE8g$CGXw`b(V z!bnjrAJFL5y3&ft_~`i^Q{ zaISKm0VPeOm9sgh1?-|)#c6@Qu^5TgP7&fDGo0SPn`)2D@$y4lN>*GbQUBVAReRdR zJ4nDb)37EFb>d-t!HXEh%HxRpVC{jU-J*5qgI>!&Czf&!wgS8~zPvbbKT|zd>xq^$ zrHK&cOJd5k7#g!SZ+~z636c;6cP%Kaqqck1pG!VyL7N&$qfpuMoHb#wtb$q@5VA?E3!r7_h!xhOf`s$ZXR+V`B>skX4B8(Hr?W+>F! zk3~)AT`q(j2P?2{90RzE;*bZd(ouBqw#-=R&}2JeHQ*Y!n~2xS0jVaQVyOea<`Gy? zdMs|pM6_!#lPd`dUGgP@TLFMI`-X6dlmqK4ewT-m=MvZ^$^mO4f1fNB&~g%0kJ(Ta zr$ncyY4?woRXPj@GER!4akJU|2+2P!Ho zX4Jo-LL0`!0L;Df7XZwxM00ftc9S0#fQi`&#mYq_#ZI`|AxFXvl8Q9DBq0(%m;mJr z093cp04H_O)}BI~Zt~POC%7zY(}k0!3bXY&{2v7WR_fN0GB)`XB~yvS14t6(*&vV}vw(FRozV9(Fg`f*dAM%Qw zROCQ0I{T93X0zsMhvjZ9+L&<2V+~*w=RV#CEXjjhV}p0|@J_|MIK+bB_);kgiK&@@ zrxNU$4(OC)BukzRszIw;0yEiKm%Bg^H2-t}jNLEt^;3%~GYo!9jnqS%a9DXp=m;<@ z;W*$(o3#KCX_F6SXI&G}%0<+)e&3OmY!EmsASAf^_<}>*Z_@ns7;~GndIz#pkvZ#_ zfM0@&!2RU3N!V98iBu{n*QbwIr%6#&E9Ub90NN#vZqfqAud^*JP??|_^Fq7u$2dbMEiN3UHYAXOk&luBTxA!^Z_#=oD?Yc7<>bE^wJeW;WA&4>Ny*gd0zN<)>vLf zNJ!VRT9?K)WaEbC63Q$cRpDm2R%^3XmDQ=emI!NR+2%yMrp&!LUJs`1($fw#&rHQlD41E*R`=zmdp4J?zTE0cq{R$#dQ#^RNPUSU_{2MH}>Bu-CwPG8;Qt6sa~pUksxgNr1)O z;y@><3yQcsYcW$ zrw<=l>TrX_^3T$qw`Y`fa(vW<1=c3@thUf>>-&6i(;{+_&}=;fmtH_xO@yy*Z9H5&!xmdj^ zZlZA+rlyH*Y9J(O{J~fb<}7;t{aLB~XtXUfisYe&pOT){ni$n5<@7VYpli20N$oi0 zSG5p$aiR`68sc7eGaVfKDUGWg-`*f6IPNgvVNLv+*V29)EfXUu-Sz$Xs`=dXx9b zNpbt&AuC4F&e6Q5ldf)F{9U}%iLVbXQIi(S=Gv&*>S`k>uR6GZ4>)!8c~NWuv>Dc) zjH0nenVJfHWSN0tJAU^MG{7O&fKq;HIVg^A++(DPRlXtBNB}J`pfx%Cpw)RPQ&U-6 ziA*@9L4!?97w{J;*#jFC>PzrvaXqZr3N&#)4{kwht%`~E^THRsn9jp8Qr+ucRZqxc zN@1l0WR6~kvn$tz@!GobEjG-?8vr6M(c$Gaz%%3gXJ0?ttUiCubFV8tpbOkZpX;2{ zs(~1zmx2RL=hxhf2C~QE55mWhVm(nA^hkURw0Z=baIy_l=o7D@`{AH(;4oi&>;V_d zx|XU|7@L!4W#3?ng0|}sNAZ38pw#vtYn&b7-MoRlP9NLyn;qV}l`BYFS&U0t2c>(J zPw@K^&&SJ#Z?x`pcXK_kTX7EOy1u99v3u5yjW?AWczKR=KpnaBPQExy*+vr`ye&ZZ z0>;?{YhxA5r5yXEp2d2S?fTQ$^hFf?4$$UfK&7yT-<9mlyq%ETi?5}A|9G71thVxS zYBeq=%jP5Z3jO0HROPI*-U_&={j2DbqvLD){!kaa>`D;MzO^p1wV`7Zl9Zb-WxV;l zYt6S#&TbPd{W6(V{znr1nf*YyNA$qySeqneN>RZt4tY&+*-g;&O(Dc=)OUmg^a95H z$D!ySB3cD7ei{170D<92vkb-aQgg-d&NTr?KC>|6Y<6osCKR<5+JAwU%N^<}pI*AN~G*&AJqMEhSm0V!IrHGKKt4nisor#*OOJ&00j@sVw*Q-QC#2-HtB=`NSFFJXC6g98XBrR`rl zr%CX{`!Zc zeELFR@ZbD^6zsf)h5J2-FP`hp*FFl0=sOIWog())Pof?3vq%@94}G1+|4yHJAc6@# z6riL~mkv+WbN3v|hZNsymkNLkaflrn`Cx9Ko|8H3 z4xeug5%JM%)ddpKKm6dHjtx8`= zF&7K<$iPlUDe10EQ=R`fSm|`VfZA`YjCs=>09so7!|t*2v-sC``b6AR+aW<}-<5@r zneA+oAE1w3|HDMO#*|sWE1QsjPQ#afRtGHUSiM{HxCw5uhIv$DN%^&f!p+)JE9D^c ztt2JWujFZb#CKxW&DH*Sd91JKurVVnm=x*8ZVJV$h?D|!C^k1&+22~z z0Zqi5?Q&CO5k~?EHs)PJBmUHWEC~*Xj6tZCD+b>a-``~{#v77|CWeh?W)~YAD?xEb z_Pu*xc22K8{s!$prr?j-&Sqfj8O=dPEOolr&QuUO0Pw^x;WyVLSx3F;khfR&s`Bw@ zau-!T_ZD-}N_zu=WhNd$n>o>8f3TtBV$+*hvKd=z-7>Unw9BL%XT)=3G$tb)Wg&5{ zZK`$Up^eOpWj91+Un^cL1U9=Do`-xidfV~_A zgbX3iqG}qs!pSi#MM>Rc*@=#f&g(~Ez~&$E5*~ohJd`C`S4O|)6J`2h<{)e3+&r(F zcIn4J!lU}^MHLN%n3A2GG3d^`2PImDTvnEz7={wY0&MD3eOH`AS6XdHn%w~NojtQY zUQJ3B)>RV%Z+77Uj=&1Sp?8|nI}UYw^5KAvtdHSYh*_L)c%}T5&y3&L+slb6cH^fx zTK8&z2S69%j>UxkS)vgH@Oe1R{KNLtZX+aWZDsVPD1_wG*ysG^seL9lBse2-L!DhSZ5_t4>GGCz%TH{Jh0Af}E)EQ>te%Or+Qc z#EKT{c7m8AtaA~SC=g-TWi3-DO`K6N0e+4q0p<~EyvXzNHAOKT=$#^RA9klhL)b-2 zhyof;5!SP7*;dcW0s!NL{<+)ulm;`O$X}wB;;|4+ofnLBW+hP_9o81(oLX^fNqF2& zmxC&EQ4wv_CTF8u*h-1Pc1}8X?10)wZglO;;PQ_dVHEug2iKIFgY|bael4CPiz~@C zFS@MGAy)E9dMD4nj#h=MS+&nsj-9A`aX0&VCo2e_v#ZiGUwFNGVU^y}A*CV>W>glATp#1Y?y|pV1HF^NJz_jrMxT=P5<67h3 zcs~;l@Q=%!%THHq_v)W<+3o3YRCgSc!WwwgbIDS5syF>OplH?#jO6cftB4QKn4qEu zRuCpeR?Grykg$17>dVix0msqRpqE~Bm{{Stl#1J4ZNs^nJ<^JwFTJFgdJ%y`eR(mx zCQOn$L%Gbc0-&bHtmD}g)8)8*TZpaVYYaJg?tz--+f8|Hj7ei0FN|{4r@5GNe@$!M z-NdxeI8pvFiaVpB`bgEn0eg%ab4^h)eC;+O5$>zPLJ`g=E3P8b+37YB`MpRN);q>8 zMwKHP_|~dVw$7j3#cvG@bKXu*ywQqn!W`T-Ca5nT>)UwuE}Ol%tX!*-)8-Bjab{~< zsL!lE%0HMX=Njo38u<^n5%(@Ru>X1@n5_3vuGuHvRoG8hRB|$A?lh7prmi(&YVEqB zq!MGf*^MrGP3?we=`~(!iuZ-(v0j+Vx|-syDJ9x?1e-RQWkga>HrChCdNAy*V;PNg z|2s%en(}_DhT&MN?o!LDTOeCD(Ux9Re%egok=8u>I@v+jFYD{B&FBu|SC)OA{kQQc zF^DhJyI=<4H+OM*7f^NH*-3k^j)z#}YqwQbZ;G6&+*2J`1pNPqdk?6lwykYgdM_4= zh9cMn1VjkZiyi45qzMKD3?PKwtBMFVigZ*;XhK9FbdaD@f|^i-P>g_v7K9Kw--_pW z?k&l(W6(w zcNVgy(l4H3Y<Kvw|{P_-j>)$4n>ZdVE=WBhjUwDQPL z-xZ%HNHad(uLNo(p8Y%aadM7yY(Cv_d!Q*Ab73UPR($p15_ehfZtoXQv&$;p%YSsS z;Mcx``L=rDjL=8zB`f^Ji@eg`G(H#G7eL1k-b%aqRVj39#}U!bUkakVea@w287>K` zM|G5%I=Ji;3k`>f9ngFq|Ky@s0?}yWZp9kn8mMp~8U+8SHvb)tPoI z*$WPxx1R}YtDDn zh&rwhxv6JIXB_%c(XZ}E)uJaR;7cdry7M-}zCNzzf!lQ>lV`|l#T60m+B!2nJ>&P( zDGyfD@ZrsBs`f{|A%XRkZ6Urg{D6F>J+h)^jR@b_4{hofH zfbQNh<#wO2^(2O#SdSeyR3CX)U(1X$&tSMdrP1>(K_8Y;`Znuqe*sJ5*QSZ}jjrQd zHZ11X-+3S9Il7*!qHE3bEt!%nd~NM0NrGfBDkr(M=ctg;spQK(x8z;UyoIefuMiZB zPlvnPcvqVpjggs*xFl95>+}4>abuJ00M4Wt#Z+h!Z>_0}C4K()^59@~kL3Dm?PX`I z&3Xe+uICPO-Xgx>6_-fI9geDUI&o!(JqOvDzYDvguDEA=rJO|Tbww(*_&KP`-QdvI0 z{z#ccq$QIPD>As08sA9R)#kclD8~I%d9Qz(~!2mYRnI3hX4) zwO?OeGrp?(_T&8*d8f~_izl)go)ys)UvM~O>=|hFh%q7UZtS6(VtpQm{GPtg9{+;v zk0cmBW7{>6b}KLK)}zYMv;IUrDFU+XE$_J#`fqn|jF2V0y94gLy4RNRarbOq6t5>qHPPA(ion)OV zX3~9br7>GYAj(hCx^FUcyS5m6$g1g;Ji!}!IIFX!`nmhiccD&rm_0-Clal9aA?v0= zDlgryzp-+kw=TCLTAxf_>ufk(c4)!uX2;3?8>edD=x%z5&K-EQ@AcDm=A2Zo#OLmg z0sB%^#K*QHO3QZ#lLvUz+Us)gyO~tj>JfU0o=SF_4Q}mS~@4nmc2B3Cest zz=!#+?8OsR;t6!9%Sg5~laG#GZ=Mm8x;`I?)VS+tyf>zY_GZFdvs_XOvc1)fDS% zc@gA&5A35PP~foAK9<4{%L3Onxwhz z)>Fs*ZSwi47!Ofj25XMx)a6|i!o#Aui%TwZu7%DqxFPNyy> zBO^0b;8m%+ZSh*NfsTDL@0^&S+%eQghwDNPXU`qJ8I!X#e<$#bztE9^I(%2|SDcTc zILYp$?Hc+EOiK3B+c3xXshZYad@fxsr}l}ll%mxMOm|`>*diP>jyPOXwbd2xKNzd4 z_2J<6%PO8Teh;}c?Npu4-jFU0uiBPhe)Ik1mh@e0Uek#U$MlU8Od46Syj!Z|&3yx5 zT*FPwecNoGwnW?;hI&)!t1Qh46Qq)Y(~VP4qxyOBt+-(-aYoInNx3=l@F3QsE+G~% z+4}pkoIA0%WdeH4D|)lYU+6eyFJh1Pe8=;OL@Z>fGzUEBTRaPU{3T#_bntK#$7-}d z%EGgw3TN(o)(*TM6WbG=s`6^!p~_?Uw;qOlN**%Jk;ajS@RvRi&AiI|%(%}`gQx6V;Lj9K3`@=V^8sBiAk z8O86?kyoX$UhaA!nLXj53QzM+WcG2jCXI$OrJtu*&O01%x5DP{RB%v8c)^Cc9<3YA z)$=%>$4ig@>o(WVZ_6*kDHhctJ9Z4J{imOG{I7qfP5a@tlY@`LU%xTGJnR>2V!AJG z!S6xZ#izGfb7MvrqDA&=d~Fc;MjyK?kgb7oxw9SOK3#6V3YBMUS zd%j}SYSe1HaV+A|SfqxZ9rF2^XJ;BoI=8>yUB0`}^*IeMm+tI~70OEVpIi#Y$)!v= zX4R@L`eUvlpMRm0eGizVN{(6f%JraYbUece2>B9;-+MnJtu%EW1%?XD;j+?31jjt@R644bum)N?8ci>43vQeN^|c z!CusTXGiSeEM3*~00pZ1_~7@ZMBKYN`0OACRqCvaUCt6#Q4aL|J~K1ezUYN5%Oa@M z1uc_jR!7g1CTyt7!L6u7XFF_YmVRKq|1wo*>~ybpk~4D39xIlmts1vUy&oIYe?aAY z;Jxocv!^j~-QFcrir9s$-6}@{^}c7!oNo6Q$b>zeB^}s93I5iU_-NdwX=e4#RB_g#irr!`VUY{Fn&lDLII;R_iXQ8y zA`sX(UHi2uaVg8MVPG)?dnilP{{&^D*E?YNY)g3_e7|zh)b8C0Ea7X&Gu07_?Yz`- zz+$L}+E_PB!)nr$1NK0cU7!eMWHNQi3%fh(NQ0f~M8Lj=L?29@+H^qAq6Bs^%Pz>4 zyn$J?#?Grq=Lc^ir6(Rh?Uw652jCZ7{* z{VesMto%%j=+tM5}lij#WuGgyWSecgQ zo0+>6-geckO184ry)?KmYDM~LYg3i=q@>RrQpklr=jvE>`;*CydvU4p z%l8ehT$QUDK4}IG8un-6deEb1L$1sseU0miRdHFa(p7$Mtg?C=)Yb$;5Cr{xedICp zsGV>QH!chsg)>3CP&y-wkums>fN=HwT!j; zwaAgsduw@0<{=k7QgWwLv_+np`^=jnveurgq1R%S>_Uv^7o}{PN~f97q38QK5SwM_ z3)In%Q;mvFb|d`_he#|WBZ@X64SmHXx6H)6NVKRJpNN+y9U)mEY~EP)O^+}mo}w=j zO5ldo$ZX`$Qb1@vHmGi`7OlOhMJSpx@{3bB7v$qnj@BoXCwgh97K(f*7d1;Pv_qc9 zJCeL8(Sb&)&$GBKJNFWli?fWIjIeH8cEtid+YpL1MVXQ}G8bfH_knVaa%axYv^=I{ zf~BDwL5Uri%wKyNsMAn7VmME#Ko@L1+bY@08!-xNeM2{tDHjUk_15Z@ zifwQmlyx+cfSYsWsVW%JFHfpk>T5WHQ**Ve%3gc+ByZWArH}!y>55dc5YFQ^jVo#c zp0N`RH4=V)&#dDs_UaQQGvNZPN4=6}W}%)D&Dpl{UAOa#K5B2xp!SwoKa0#}=BDr?MLU&KT4)wpUr6G?e3|M21fj+l+#s>0Tu=HaCh4g1n!(nl= zq$v_Ng#%H5mT;1)LwF>j%?Sl_<~)Tgcx{pc<<{EsKoiw`5p(^*BY0ymx6`FT&Nvk5 zG)00^zg88fxp{8WY*VkHFtps(NV?b@S1jgMn;)cJ*pG*hbSdX4$${1lPe)AWi`0wM zi<=6mcsu;4R^Ru!IaPyggKd*-BT-~n@pj={K%A%QJa5)#<2IZpzML7CvkwqQtFbsj z`ci_KBTmxQOg{aIO?R$Z-lU1BsdrIgQ7vA@)%}gtcap7|e3O-iR3WA)2G{Dkv#QYQ zvQ$~Jfe!LH?t^PuQq?1T!%f$EtAC;?vo}_*)3y(+e!7Y)Lsjml3pYv>4AYU_xJg%z zs%vkotiIX0RV92fyHW7U{D+6QI#d!!8N+7Q!dJ% zoh|1!U_t(yoH#5yJqeK9dnV_Lp5kR)fB42d^CN}3@fS%>h&xKAnf#T>-_R*#JqFH5 z{UQ`@ko1uxM?#UjNsA;7k`U!AqHN9Rjnzq?`D+wD%Ae>bL?^`BCa3Y~36oJ%0TAA* z1nZK<@)L&Y1}R8UWG8Nd#Ey85zO;G4rZlvq%ut=pveSxST~KBYErj58Niak_+H})| zkRO^4H&-|JE3_+A*6yp+q52jF;TlM4h^9aq=NR!6pT|k#pOR!LHGx{Hdn=QT(SBB{ zPqR$1MRr9~_;Nf42}-Ia`H{|2f+!CHEgN=KCKsdqbT>5{%0>)4km|^4+z?5aQWmJc zd2!Qn^K3);*1pQ*QJ;A~O2k^+TESY%n!%>^=6QrOOH&VbXr}OnlJW||mpnZ))<4)X zpXEpH`>cPP+&HrE8&Zw}{~0q&6Tqhf{_98Gl<>=B3qoh{r14@g6E4yw6%H)%1b2F&|Oz{Ms-Sw=zX6Z9Cv*JQiysImsD)vcXAE%{`6rs5E za1jEBc2$+PEG<_sfFKia7}woZMV~I;D0{_fsiQ-1d;ZF7sPG2f*EOgr>XYH@Gheg1 z!o*@5Jlxf<>iiq4K$5L=RrOl*r}MML%f{Iz#<;CDIW-O8!u6jX0}SJUhF%f=XOEG0 zlKSZ5fqwFLkNK26h1iTNn<|t>dT+1S_00G1?ER}Xf4AM=&HVcXWn~wsc%OMyM8#So z`pl+=4KlRwgmFr-1nx2EIOPC>Ml6S&q_V$`SRpdewuBtG3A893FGVt=7$efx($F@W zR|vVGJ1dhj(bYPH(m6vaavirxqNC&lUQjI&F>EqPM0Vhaq}xeV8Mp>x(sjz+Kr_{X z(C1m^O=i-CqlKf$(INr-JYI)1kyLf%eM2!xp29*w2WmGIZ556fc@+EM>PV`TBNS(f z044N|RVcn;6gP@zA&HW*Np>V{iU&m$pD9eQq|E5!%ldVOw|7u12c_MdDO_L0xHPQY ztV&JV`5UI;92efhO$QjLckw@eQ0t@m9-OCM#n-$3BkgGQ8Cg-^6<)*tBkhQ}6%_?l z;Xb+kBkhQ}UC#}osiS|S9Ue;^9>R3dvQZF?cIv&oG_cByOZD16KYsN{wAG(9p~e=q z;dhcQARZ}M2|vv*a>RR){1K5#hMCXw%nG7Qt|8}ijSGsuk^YsT)JoN!suimhsFgS7 z^cdQ4T6SI`1YPVlursqWv@@M5DlaN8_9*;Aaw4@RRn-><#p9^BcG5a&7li>)w3ds$ zY*SWdV2&)tCF1a;4ly^&r$O0;Zg>PK5D|qoBs_zgRTo<0_3<}I&Lm%oHv&XTV{bzy z=>(!0eV$M}XG|?-!9|h8C@%ufY#ON|MT`^UN+zP`GEMZ03QVb++;kyL+8U$aHByxs zhp7rM#$i7wjB)AD7mQ9IM~hRol!I7?sjA?rDi2)P^4GC* zNGdKHmyNg6>bq%24W&sXbJ4=E!Z2i55f8ozA7%oUp$V2@0G5FR%bzzu&hd>6a_`FJooC{D;;5Ov;>$-@a8X#b?g^O_0k)weA37%#IGpw z_oUhmWIw(k1;+`*G2dpwB2q~|L^s4Hq;0(?#{OL}MVBH)ncd#PSmh|s7jkT`Z{4wf zSBI{?5TZXH@*6RZHBr$feri8eSHqMkdW)84g({!O2M+1K6aelWIP|;lYVtspReudE zE>p)-6ex0ty3kFUlQ%KieZApJ>h~?GLxd%kQAvT>Xgey;*R`Kii5n6%P28+*>(Dmy z)@u5p_RX+`&UkNsgc(#4u7Ebilb z3-F`(ml@t%ly)?@prm}JWYXfX&Zoj1X z(v!2%db~T8G|zlx+&QktYo!AxbpBRTx`tMTTN#KR(35(`->0_cJ;Jam)#{2=Znebf zXc&HHAVIvf0e=5qv)H0;^}6x@w_D`yJ`)|(t>tzRH(ylL_aV@&_@b-uW}uBtzwtvv zQ{yKMDujf-|HfI}@<$Q}ZQ%w9nHawkKOY`gI zC53zVHCvkmQ26`y~IK zX-5$e&qg|fc%XFJNy^yA1F58&S(aZchf5Kf6uSP2EkKkesdD zt)i{xY9`xe+lGW<{`-M=aiempGbGda3shuGb@GLVn>&l<18?E}d`)$mw`fXKoU)<) zEGz65ZjtAH;Fg#XR{acVHSR*Dh&UqfmQMjo>4YqyvvktX@t+bjkY^VO63>&(I{zs_ zgT%^3&@pjC{$qlUEqR_cC;$8Q#V->y&}Iam^14sjvp*B`U+V%~QWa-kgBZyGk*f3$ zDo@NUtt7}8S48?}3Iko91_70a|DD2qQ5W!5Cj0q#c987 ze&eJBV~(O2ytpfkkW`$c4*8VR3WCyP!%pM`&cCYOO0%@^aN%RzJ6FCcq?MGD6dqAd zD+o;7imLDjtL|Bumlhl@rr^OQLluo{0LA8``)LJ%fii#NmV}h23kQ7_sMwn`LbEI!Fpi`K9uy(_0A{S=9URdOvxcrDs!6FOn5$L zMlB4&hmb-k;eiIK&qQb&R%BjiN!~74@t);F9Xl1{4z0gf55%A>qH`_i`dR-b;rt-fOZ z_keV)XxB~SUBF#S!Cfgx(4p!V7iYJ!`K>yiqEmE2E_eTxTIObWOHtY{d$`|&+*pT- z>NC1Ry;OJzZ{&Kt>aNu~O*d6_IB}v+WuzzF4{LS{?J5zs``&w_T4wFU>A}W>6W+L@|Dfa~`lcx~# zOo-n%KYuCr!Cua*IVpotLjmMG^4D@7xai}#kY{CP>Sq0gzn1%AZmXB6uZpvam2uLz zU&{T1PEvNH5kpF9;1$)}ESlWM%aJT88EcONZ8xnNazdYmLMoHzedhDl8Uimil-L@U zBl~fpxM>m><=?xU!2Po3HvhQI`B&{;uYEUYq{Uk2ZdTB(_tX5cfg@t)u*$E$2E+-1 z>hS55@KsP^-Ocj5^?s52A1(%sXu7>E3Q9!Q;yQ4{t|Ibg-GAG202w58j?Y}@pFJhI zbUg9Y_T;eYTHZc7~jLeQV~(f{Hp;UEj)8veM4`8Q9gPM&kvD|>AB z$*V?(VXvQEes}9)TK)d|Apdh+ua7-1z@+N3n<33|jbfrtw#UV$TUyl&-YXeV6dRs- z1SyC~xAAiftQpjX_HaWx?{`D8*`VVDqW zL(;t0J@g55S;8e*p$`)0*`J`y{zO%1DxsDmZE%mrT?wbYjs#uywC8mdx?-qSV-Hzh zDW_x=eBDq(lI0yp5dTRC2{RJY^mQW$rV5M^J#~eQQh=dCi@Vw6S)<6o zcBgE@=d0)4k7olrTig#s|3J^zHum@V*&ri0u zKcJKA96#ZTXHDhv@3MJ)h`B59+f}dh@aNR`?Nn|0S5M90e(!_)n|)2Xh-!Mn&%!OU zRp!jC)b^c1S@>1tTl7A#?yyQb>QPN)>Do83EV3ZV0DBuS+_qC@D7hm@U;gmAi??dzI$F(#s0-{ac?G-UbVpy`2fwR#h__ zbU$yr`L5}4_XBHEo*SQ>+w=JQA43$vkoG80bILE~$&FJ7te17Cm7jrAsM<*sB(qBr-`Z^y!pl597Po^@j9y%f zJx`3eQp4;G^Pm`u3jOJE!#7Ncn(#La6-ff$HA9c?U=rhI*K{~ae>PWePuwnpU6(Yk zA7!|fEA(1Bpl}CYgp_V6g5P*+uh5urlsz`%P2>k zGdx0u)yP4HlWr?sSD3lYfl*}ws*}lt8o%z(oE0-QHW6+~k{}=Nis~Oj_%lqlrIY#V zxj4pzEm-GU#r=8s+tyz&s)au%i%CXJyr4I0J-)(f*4FWYSuLXK1$SQ?^8jnQy_|bQ zDfyUt6n4yeh2FOnKESZP|9sLm{r)3lb0^mm{+u_pMQ+8^C-JarjOPp{oZIlTd{o3> zEE}4u_$d5=0sAHGy+=7F_KUpJW-4T5GhjQe%~!~d&r!mKpDARk%27C|DO|`w*`M}Y z-sw7})_n(8?#@%OhkN%t(e!qqlgj0L8LQCC55DmGxT|vZ7B6yjM6-L;ovN z!#JBD_W}EZcO&1+Fk@O31$lPci(ig>E5nrEdMcIsn+yZ2)mVlD*7lLisltJ6StQeU zMF=>YsAt?uK3Pv+-m2oyWg7>zSF309Xc>9|ev=$SJ|P)NwU@2u(HUc~U>9vYX~8XF zf2brf(Oy27(`{_G1;@0#s(U#2QG!An{{VY-tHKKBtG1~Z42|KLFF1VLLEr{$kwcy= zbFJBA0hQ=5u^`4Uj^+bNyG3HIkOjZQs_=3Ih>3oQqc`CFoWr{(R@`9E9Zj#Jbcb^H zJc>PO!2eEDF7eQ zo4fZ^9RE)z%VqG1*6ZDiZYK8fp*8)!(y8VOEX5wl;aQ3aB_DjI5hl2U!GZT#tGyt- zwu2yN+)kNY=UQ9@8LrFlV_N)EckFi9bvgE!3}1eW&o7L%UnsK8ld&=SsVC>XHa11J zg0WK>5hzdY#>hpo{FQKzG3yoX6RlKFwi9i9HSGOkEH&KFvBMjz)nf|75p|wCp^@3+ z0xP?>Vu$Z<6wuMaO`Gm0tCs;QyY|kb?Cm*>kD`qXnBQrgz7_ZVKgQDE9y26IRE6zW zuPAft{tGcJ|NKxF;`Yky&Wf~@fn>!_jRpAAO*Y5N2>cHM$%0F?ZQlxGU#pS@55)d} zdt~6FSyjAX33{#!lmtx%tR7iuq?N#4e+px^9sctARiKnar6|@Yrd$+R4~q& z5#vqf%ZMuI4XP0d4*}Nt(*+m z;N}_Q0S1eVBSSYBwj<9jv>%Apl)4bP*1Kb$)&Unz-JD~mqWXG8lr+wNWz5XwP~qMj zyO>HhG{!N&R%Z_tiqP@gyS30K(7m>wjik-s!rq;8=w&1raIW>JAcvg&VfUzit-K{v zkv?VY@9qh(8gvG zMKWO6m3tT$ncvI#M4Q8ftu#meWrY4;f)W^Y?5Fz;%xt(Z;d7XA(S|bnFdF;r#(2qy z9Bw|7%J|TM{c_CpByR9vDom&`z?!zvwd7q+&7EZSdiKRJd4J)NaOk*{KZL(o`33Jt z%vrLCWGvNzEqI5{xV8mzrvp<-v?+OKNo=A6S1`SsgK$Y4*NdGBEwBN4>v7`&=AhhQ zZoQYZ&^&1pfi&PkYID&@j~f?L*30#S%YP52-87C8uV-iwnGkN?og~NO9QuX{WDTG2 zdtlAYfdf1Kz{K{_f9IEAhMg6#qW8QEmir}~;#v(D?`X*$+}3$cH4lF43rD=i5Zt{XX0FQb-w>6EnoXQ?P6 zSB5jTja88Csr{+D5vK$>i1sR%!w1QyR2Z>rn~P<5Y@_#V)Y#HW2zRM^KH9Ub|kmPz2Ho4V?Uaaq8@0l2V~YlPWfDZT&&9K ziUgnofj?wMZPBkRn+`iTqcxM*qa0W{V`P(<9UX-3#<9ulJlx`xO8@cK?VNP-xiSFf*eF=;ut)6xmz3*>FpvXrm|gFqdY;%%4I&NrCZ2!v3Eyovw*@OHAAWCV}>Udgz}FWA*0-8_Zi%{OW|sAETNNjHz4`h(%MxfGc@#u+mrKYB9v zw4PpJ?`iAzq-%`u7+0=g1>tlhqS%uwG<@0`g86f_S>tYK~HWa-y?Cha7E%E^^{6y<-E zhwo<=Xtw{!{{K53$EJTy8#|I}o5jQUzggBJ-LZ&BupZzcGFOjYi5p|Peezqgiq95FGHY~^j9u@ z4biV0fDbQ3Y{~5SJu@)Iw#xjJ7@b}4mnXN_Ki}l}nY}&v%3646?^<_dC%olG4TImf z$OhxK*4v4VPVVQqoR4B|^72gN9y=BF=WzPLI3-cPiwNfI7E_PC5*EzAn|+r_ERc%( zv?NmL-Rz}Gq9`=20erME+}aZo8dWSYs8_?~6}F(iq`tA6%Ym0WlvRUQeE+Vz{rj%& z=WvQ~PZIt;LHTbp-T5>MjQorRm=1*G6ErA;XPnV@zdz zXn*o@M3D?vzBY*UH1eLV$iWxP|H|#LQZM+_Vs4Q4y2oM1e@~?0K>r1w9&rAn#QlRu z-j`wiV6XJ7jnjf<+JV768qDAusoIL%&-t@>_>-c;Xn_0vMRL+9vc`?c2vO9W^wbWT zL?UU$g-s#PXv?)4dh_vp8$0^PnTHvJ9$|%CwRatC+absrwV#iV@(4OCQYP*GqcOm1yiy=U#Rg0BG1A%?5#}v7o z$0TWbM||b`g58ejC{cReXx3ZNM{mXcThsnlIOYFa!2F2btT+LC?s``5@k4LIQ^xuH z`6gT3$Vy#tP_f({%4|Px_d_&%0x~2=*qS^Tx*M@ZVHP%e~6m z|8J_+3*nax_98V*3z>f=J(?r~-o^6PKy;smwhLoIE*qyxPt&y|cE|l(|4?}SG1mEB z>@sUP-#fjy=(eM;T*sS@%SJHrVxBoR1&6u#%;&`_tMEltYbku|u9LbAi+{PoBAE z8%1A&a}iB1L>qhV>j@{=_wWC|;m3b6-G7yWk=RO0SBInYzuw~zqdTto(>s6j`Jb$E zP&>qB$N$HY{wqUB?(gMUvxXpJk&NJ91lQjbyo_*H%KytfoB#ix=Ys=tS9F0re^+e5 z_+Eehtf;ARrc?&$)+_#OC&#Y&Gug%jkoVPddo&08?;eS)cA%?g;25{DV4QEc>Mxqy z%<^K7TJ*ISLT1gEESN-FTvr79nvcBT?`r{t1jJ#t`yW%514}TSvV*`(tm+GaWl+?C z4F5kXM?tMv)@)kCtlo^Mp@WW}uVJbl=N_h9Lw#`DgpF+9u8K@6^>dVx8yd&Fg(-AS zB{ZcEKJui76)vaQ_&BCwyXL9qny`}bkSI0O75LqyG(Jzqm)MdT2x_J4Ga zIv92l-t|q+?F;6L8p;gbH7hs$1!IwIsSll8OnY8a5sq~)gb;&a*Wr>ga_OHjd1@$2 zxa6E%IuY|g4HW>FoRza4!&IuF4#DqI(@JkTGGz}2LJzNWy{fIK#JX2Qir2gJYAf=w zGm#Lt^{%qIihJ0ZEXed~mq<-TE>`m7SVBSw?DX&e&Y6E2GpUAZg}b*e*H&;1O<{c9 zvmweaLf|v60l)!(G62+}0Pq$7Pyna_V7(#)e%WDtSTTIoo4EfKHX&+I4a$8D02u(d z0Dz|e$Y1T^uJaO7{)SECiE!IGy02)Ik|zm4rqFkcxS_D=vO{WRoZ$3Q~0KRAig|Cpe@AXv8m z714!my`7rG#HpdI;TtrZAGX|^;NSq;y5O-Cmv+s|QKm~W1#+ORi@ioxsf+gVqtn{! zWUW&zO`(&laymC1dt^}O;9Y#MzIO?=ZCy&WvI<=#1(3xU+S}Ji9W;Pqz-euTXDZml z=jW13pTK-}fO!vFoa}PXg6PDhNqIUB%FtdvkDT=chTQ=+O-SX1z3NVQ+}7n=S7DYq z=m70wldGG;tj(lBAhBs@(V~{UcL`pO9KIb1r31pyR}Ox|HL(OQB3O#V`w@TfE=dIp z#3L@P)Qd=vL3P6~$4bsI#HF7_XAiws7?$iyIMA@&*#y1E4IP@ry!1r1ZEuV17ued? z)_~V8TnkNK-zjpwt-G&g;Yy9AKJ}wYPh9%*ngy*I@Gzkec=9ABejH{z?0;<7JsDCS zo!;$5tnviDTrUED)tmrr>rSp&Fsm6n4jo~GTF+yG#$iLl{@K{pgs|vz8z16mFh6{T z2pziL23cS2hN*r|I2MXJ4Hp`NrcYrsLs3j{p&6+4XH0G=$`md%N1Nh)DC!1WXqL9z zQ%%4g_ZHJLZxR`s2AQCG-_vcph$JV^yo}3#CffI<8;G{Ryw?b9xZtYnOg4-L@!7+fv;TzJok7JwVEuSKm=C1 z^J~0hL695*L6TA#0>6S;uJvL9fGGgXK^R?WTdut?*9(W1Ij;}b+y~JD1JPm)q6O{< zfJ^{z1E6jLc0VzYDAHuf4V_y|Z$~eLkCwcE@T_)Us#~}rdcS82&dFYHMt zVdUJA5Nt&eTm=gNdH{F~nm}!xjDb(FQT!-9KdB*rjb!!5m_Ft${h zZ#M%=c{6rB7*3V52bQX(2bM}zw(onJP(g>vf_DkX=y*9sgwtG`34A|gp=htro^X}{ zh8ng|u~+CwIK%*39JWxh2hMPf0j4u7C@MqqY&sMLewj7(hPR_%A2}7Owp&KWkLXQ@ zYOQVXs-vP@>%CZjac$hQ*DK_M7yzf$WUF?{DHVT44iD0tPO{jCCC(8^+Lkp zWl&lpEBeucAyBhhPC*S7M;v#02<^I_Jcn^U(Cu5Z@caVm^Vx<4qi2?)P~U`;>Be0U zkM#h;x1hLMo$NKi)!LASbtJc&()FrMMBi3*D;%a~Lb zkYj=mev*8fa4oOfscPc?{`2tYFwe;?qnXWco}x!P~LT1;qk)7r9}U za~JyRwnDt0W1I^hp&7m#fc=Ph-IH}*{PB|03Eq~^Aa)M-;a7UZ2`g;zKEy!&ZujGH4XhdRB83oa-psO@b9@H$kJiRa>F>pq_gyPKvy0zqL?CvFlC$bzVm z-0cV$?(x;G^Ex>2?IRZyHCJP8c@g&B* z5pupGb=H?yB8Ym!KC(hD;Z5w61>PR4iYZBhjNX&g@ggeA!VVB>j$+&+A?mkeL1ug` zOUn!L81Qoa+EZ0Mi4lURfje+x$1V^t{&y`aA=vg*iVs-r9Hzu_CFt!9JATv|X!6^u zAm3C~rb>A`5+#4EE8f!mP_>~YZQOz+EOU6^Ks zS-Hwjdk1L~HD0HIRRWWVm{LoSe7$(UqUp@c+GiQSiKW>jX5Qi+r2K^t2)Wbn`s{X) zrBUC_T}`W%ExUIS1{8}e<)8{!SAOem$Pi3kVir?o+5M?j_E0g%0Qb6F6-E=jS$3Dz zd6}8Xg&{nG4-{LTfR=T;D!fS;s(d2sOI$92Q3*APkMU%TcCbA(tH(9@3kGG`jYcnA zHAAVv>pS)h`>Pj&cVPAwHmSda`7{VpX2lH!x#DjL1XS9gx`ksSuacoXJ+S1q1ZgKZ z@KyB#caV^;Jn05Gr~evFa?A#^Lg&V{alYBS^DPPIQE7a>!~nGy5NViP`q();Upbxc z7|FqIAatbbfXR}(;lS9W!EU`;S=lKIsB~3NN7M}LG|As_dIr``7!a$o z%!7zx;lNu|S6$$j!N5t3!(exEt=DB=6ag-jPMArBI6Fb><}ibU-Qv@M#Nxs3s{}>$ zI!k3}<3oaEdqO-aUDuNsH`qN{<7MiLItw3uKyYt>s1vnoyhP`#v!JiuwCrq#2u#Z8 zl+7oE$toykrTQ0eq?3nDb00~hq^|4ARoQcZ%j`ncz9RWLAO$eBnb&&UlfK2Z6PmJRC-4& zq!Phf_x%i)riL!2KCkmK5uqjIPRCcH3DW^XBP0ID69HdjbvpJfvUzMMBo1DHj(o|i zm9;CeyeaCDA?OCo{77Z24Dp}R@lluc(b5FjJGd@qkPm8=k(NNkyikl_E`4CH@dqUOz;YGfh+xX`;$C1BeK-L^(iUuN6@o z@De^};LI1jVAaDG&>rAO4~ZaER?w|0zlT67n&9rOTj+|t>(dzinR19V4QK;^FaWp# zpbUT+S`P^T%mE;%5&+!*-~m7=0E`FhpxpLh1jSpM2%`ORe}eWP0Gt8v001rkxDI-C zfO#^Sx6od@z_4QgC;-4^TCazjnO_o6U=lSj>w+cdk41sLU=dy?KwnM(l)nH#2e>K) z8XUx~b7-%fAf2|;#0#hauDk={WiJ5uXyOG({wv)8pj8P~0O$v5X7~*Nf|v@>n{yjo8U4JkV7h6%e4zSK;Lu>s6n&r*N6S@0Ku~t08=Z(Z-*7>cL|Q{ zX|sOB0WDa^uwr8ph%nF<#Q8&xG#fu6P75T5nq1ZP2Wix|%H5iyh6hc`bR~Kp^CEx9`EPd3N=KC6~~Gf*uOei{kPl z?uL`?N&cv7X##DZyZfAM@7{wBWd_J9jLdjWwmW_Na6@PXCW_(hbALWrIp!2zV(#clx+HN`N#z40nucrPI*~; zVrRP4yZV9G^Ka`{>gxyFyW&HFd-tIgtwu_K=?A~V-lhqRKAw_rv$0@8Ep^35v%`jV zA$G2+=WnT;`@YdQzusipKs`}=B=L}6t;EgKD3-(tu`Hd+SQ|gnemve3{9{86@ij#t z2&(E)>T&EY=Xn{m4PDY?qQm)x&d4&J_sVb*(uw_iH2f;-z2>8_S6^4`+TBwrb)Fsd zB9hd0Bo(1!_Y+~$s3KC+rYtRG|IQJYevZk}-dE~Ktsu#sZBUL9Jx9JctRb3p|w zEwSCGTsE|A5gM;g@H(Bv6Xh}Lb(*JvwchVak1_MMaLQt&n19Day%Q_I%lGC1xPY@l z`NULw>}zoGo*1HI!k_D#@`)p^Z-%{2U)P?y*LiH;cfTuo1cQ3w&9&G?sQbv?4t}oLfc-{fg{#)`(9@NmMpLw zx3ZI*xhb}9>+=>b*C;_WZ~Vt0XkGi%#st7aL&I*x+6@3)fEwqrB0Sx-h zG{|ngCL?Bi63j<7B$I4XjDy+gefz;WJg3S!SI@RhgFh2N1h61HEH8EgtP#3r9-YxRzEReh zw)Y*F3}etReY4TAaK8L?@37tN+=ixI+J0e&Vz;&~akgzf7R0Pe$V!4CqbEziQC-0u z9R0YcROcHj9P6kp!Ihq^60R_>u)f&rq3o)0X#(Q32PAY0tpCoq!157SV7T4#e=*!+ znt5LUGun*;^P1Ca$wNDg)6Dw{;N|m)@5t3uo<4H=I*Z$iGVM@DJ4n+od+=hm1H*2W zhmU>&J%8$!pUmrV_cb zLkSZbYsL1<=uWRt=8Y&-HMrd@B89jb9a7bA(-YDbR9=@M3Q=2(?Offhy~dRSe%nB% zj(8Hbgo+zKK~79%){S9DJx^1)>_R^x))&jGZ_O?+ziIk*Qzf<-N}FIb?Bm2n#dvo8 zx0`Do5q{K8&ak!o&Q;;IryjK#acWFip`8=;u$5lx6CG|f>&cz99xF4}C#G0pTfs3R z7i9-)s_Ja=@0?J~X4?KPm9jV;n?2W*IBt$A8_HH~Y?qTrS$wR}6xZP`kwTOYwx76} z7i(^Q!r5_U<=sSZ2l?&e&eg2(Zg6ZIe_YjRIWT|o`*P33uwD3I&&0;uE|rOy?HhMT zqbAFUzKt#`XrgbZ{YpO3cSQcRQ1xQg_^_9q{)vlXsE1`3C(~gY$W7&msg`M;(a&;j|>ukOA zfZDk4Toc_EX$!k}cqLPHgnoMi40|%JqdyW#N@5r!ezaeEHUwU8%;p!l{Y#IAyhdJq z93*m#QK*Da&-)Ak*+T*LD^=7w;VHK<^}wc~)%4gVN@(?BGx_^R_>_Jl@XYJgi<^EL z-@!*SS%A92yfUlW$hNg~9Xyxye)8QRFBSW(yF;tbgT~auFkn$D>)4vi4(^ui<-0=* zf}v}7X}1`3_D~Od+oC@0yVcAa+&8O2WI#C+?sa%p*}+z3HwDO1+jExHi&i@}60zva za`1xTk5$e2Yq;Dq5t_*7i1wA#FHXa~7! z3cPAaFt#pJ6ru%=DfcvH0;(5}X@3u>Cdz)v@>4#my%|s~C&vj+o1AKbM`l%I&e(b? z>(PI)^Hk0{SlBq`%O4x|!Y-MVsZrfK7DqBoU!I3qSI z<;WDCI^hD&Evl;P*n0s2pyMO9KFa0z77l52W;K^+;QQHUTz262h|4bI{p?0=%X;3> zYK7Q#-q6CSW*$2qWor5u4;Z3;YU85-L9dQ!YcL)@1z0`g^{nCz-i=#B0Ywa*{ z_F!n$wC$<%XejK7chDd$BEEORr;KCEn`V5s2FTqhgr2(CF#xG*Z(XY<)-uwN5bddJ z)r%o*P1MREkp2ahN1eI1Hd6?CII`QiwEfCQ5Gdn3!Fn%K_Wm?KMfc`tbgmOXE{>Jt94a;3}iyR znsz}1^{}^^wpXZe)M)ICmi+FnVo<>3s&KD3qi%+c|)B&^fCf-j~S zdSvbp=>O48jIOz1f`{L?s^SbC&vS2IpnY#Fx~*uj>dE?fSUq5SEsp++?rZ*Ja@XwJ zyuiL5v+ffI*!zuilbC0&rDr#RxAeq~9!ylE*Pf`9bY@6+BZcYSp6$N`wR!Dan%dZ- z74D(PaK6wh7R~Qva`q0q;^Q|BeBto?1@-kU{v!v;%Cq^a<;c2TdSQZKV>AMI9?z(UURaG9ZxalJtF7a} zts`308L&{VYa_uXSZxxud;nSyyRWSTjxIrWNPwmp35e@Sj+~8#piB=CULQ~!n}GvD zzHfYyzP%`|1H=Jqb8jL+n#UM&AOYAuj&F%GQk)mQ_b^nZ)*0#BilWyhpy?$+KK}sR zeSbsBQM@@DZrTk+g>cavJ_=GKwnoV_8CvCSv-38x?nS@57n2?kS@7(Ammata6}cG_zkq&Bvh*I}rBOM0)p zb@FwJbRcavl~j1Dd7hH<;LumLftR)`bwBvFXUB-ic}DrbLGg zvZ=g^{S?%Wel4@_4EZE!y&EJ(xq6{`u3{={k<7t2JHuKUuPK)DKGEfKF)fr)k+?~u z8Ymr=W|GUG5>se;gqIFsBuYg*l(iU-!<1~OMbs`#wS1CzR7K2`Vz)(-ChV#(aT`iD z4e?SqIB}ZBFdR}zs_n>SkJK7#wC$gnhmBVod0zC+Qr~V4pd@vWHBGXXi)v!Nj6GwD zaiNt|oO}Q!*Nu3c6#U$jj=Y6QoTS&}I%ji)PKaPJl-iV}yyePD*q!o8k|P!HG+}hh z*7LQb3wCEp z2E2D7I4a47968pIWs6f8cIy(^es~fw1tr-+{}|v4S74QQP~L!uo^Xr;K==I^iadd z^ygKR&)xoBE+BIJ;b5()K{|K6e>HOa?q1EifPXCkk%LWZT_WdKBF7&lKdpM5lRy6_ zA@RG&@q3&X&s&}J(b_xW+~fFHR{1T||BA_v7KXd!{s*oc+ABNeqxR*v3O#2?PEk=c|2nA>4)L>cO?Qb>dSF0R821Y z>9{UVz*~3+!YD%&O!3~fVyZ-3^5o2&`e!q=Yhc?={()_LXNEJ%dxqb_#vkrA{VtBu zjOtgz#_#UczN;{uwDh;(5Hz+9{yX<-Nqw4R>itV{75yoJ!B^E=&ky`&^WVuu61pe( z;^$_#F)!E6`|dx;%)gnT<&pMu(9)kXb731)aEcN~!MvV}U z7BRbwY@_7&d-~QQ4j@ z7t;B;el=|TuELSivPG}BBfp!!&gx%?EmDZAxU=-1Bh>G#zQ7HalRe4oBQgi5JdeiT zftx=M1|kw=HCq8p!QO@dG0@> z`oE@?7~7*g$%3O3;s1ktxj-^qr@r{b%l`LE%Pp$Cqm(rYx(LHXk`rDA?AFv+N(-v5 z7_qT3Dd75Lte92-aUy7earn>xs(1}o!9o9)EE4l27fD=zbhU72P#YIv32U7i}hVa)SAk_k!F4U-eka`+tr zeAh|o*`+ppXs!HjO@|*NY~P5ZlSki7a9ULwj}QM__4Ui1^==n%Eo=3^fi{1bV8%R5 zD*t=Cm{ygG;*nAG#{&+Pa1*LS`Q)OtJ< zq%BMX|J?rit0k5vVSkXsysD_yHtMfRsQA7{tB}HutcN2-E}{i zy(6qO?Z0oe{f#M>8<8xlP@8T+dYaY!gm&zI+0$;;?#X`ziqj9&xB2nEZzcX!mw&X1 z_KvFtYkmjZe^+DrYbH*oEq$#e{t#2D>*VzHpA6-HGi@48!y5k5CpCJ{43y8R4$&=? zk^j?eS>NQNlQ(}7?aw~&Kb<;_reF>K&?)^ND>MOITKKJW`Cl$Hw**fzz1D53Ckve# ze$?Imfl1!16(Q+O{)g`NU)>vM+1s7zZTsFC@G%rNtmkg%MD-vfCzm9_Y@8orm@zFe}K3@qVZ1~ zish3;H7Y;u^8LAnKDe-Vr22nUYSy=&z?6Sfi(Qy#X~i7)=VsVndza<@jA}{0{Vd`y zRSR8ABxJYJwV51>YY34Hnv@M7EG1-ubIIY{gebt1LWCJj7_Tc5*+=7A>pRJ|>$DR) zldIu+L9k@|o6b*-$%fx3zrlE$YY@i`f-gHD8`)Rh$LPwnjpGLaHT5-x@s>NvBdhX7nL}wqQ*-0oMQG&recw0NalSmOdJ^qqwI(*oUqJM zE=)I!gqS=Y{wTyu_EQrsqTn2P7EaFo{>LFdBd&@aAV$7zQv1{ucetyuN* zP5njoW{k@1y27lpxI%#NTK^4u9UWpV@*(&G+CD&dGJt(nUCh;q(2%P^!$C2~3PJ`< zE;x<}gh+OQzfWj|`&#?gcb%8tth_m%cB zm2$b_+<{2QPBsPbmhv)1aTyR^AkT#-hbT9VHIbQ^m|WM<)gie;UJic}VjI-fg+9Ku zDOtNKiSv__*A>3-lq-#pkNgchEkr|hLN@S5spB=_iW^LixB%v2nN(T!98~b!5b~^h zSyvbJ7KskYvEf-EL?(7qLA=GhtlgXj#Pj3@I1q?(Q)g33QE?IL3a0^yxMY(A{d#i~ zW218A2GMajlQfPV4p9?16Z}O8vuw9)T5M4)%TrDolK13lIOid{vOP_g7#*^tFX{<1 zr|DlL>Lh1}zX}1EXUSN7LNCL)r{DiWyCdhub%AKZLqb?h%uQ5BbVi8X$qR7l8tMq7 zzH+y1R6yzD5C*|h2^sA;{u}OkRz#o3Md1asHvqFE``+q*%soAzE(Yy8?&PxYq7WQL zrAiT|7CZU>MD}moL+G*`Or$A4p+CSe(|7vK=l+I!W?c-!kGR`Rg%Oqzva#R@U6<|D z`X$Z(g}WXl(OYtE91^iiz~wl8sQL8Rx){Qrapz>gy##543rx+!V~fdtdhUP29iq|H z-Nb5Q4|W9{KH|G`PcN#A;r#{fr6DA;Z)G3HGLNMZZors z^MA9t^su@Zod1A(iK9}x{zbwFcq)HWRsQ!j|7+YiU*l3k^qYF1iz&$PPe);!lAJWe zwdB5-4IyZZR*Z5u`eB6GEWqBq|@5RfkDt^`((oi%Ly6fxM+w>$*1A)5Ee%B zsifF)$Dbw{u}thNYYshlc?dMiHcMeqpOWxC`89ZP2&Ac{=@D;<w9xc@7`ie;jk zSaJNL>?|vOEWgYCjr+gSJLS{`HN}yLU()@FK}qwEIrAeR7+DuhdRR5rA)tdDt{3lHZigt=*?3CqOPL@7zPlBJu=fQX#@ zF+3qe(8LT}%DQ6LD%kk2d@t@l<^C^Jm*%L!^yr@af5Y8Gc|^DJf~T5rrVm?f42cgt zW+Cvs4i1d}O?Icf0l+%4pQ6fds{cN_r{hf-0^fcIU`p08K=b-U{|T=83#MER0D?{a zB4IVTH@rRs@Hi7WO8rU(6;2ggeh2_*LpYk6nt*dJ`W;iM4^1dM{ti+$sRF@tZy1 z251TG0XU!kb4>YjKB0d)#uK< zb=6e0qi!REmH0nWyh$vd6i+iurE8z3YQ@gC%5ZU(`~^OBnEyHb=zeytA={qVPo7oE z@1SNkpHY>eWNh$mOXEMP>JP;r^}gvKva6FRp{Nx=49SrwrI;M)d~R^N`}M_}s-j@1 z<%G|q&(_4=#3^fX6bS8j?bs+%DjfZo#QU*R<+>CJm9#NB4pT%VIiZZ4Tf&>_%*SO| z_~`vFly;oZ7(_q3P>afDQj>qsl5PXRUdj<&dM?`k(ojJ0_+>dEGp^Uri^^pi0`U*z zhl=r^?-o&nE|xY}#b!PKBwL%C)a)*W5jN>4nMGG#yo^b6B){UB_V^;?O{E=4L>`%w zNZq2gRq^L)L6TA7i=zdRbv6e?=CYp;4RK3eQM8;eaqk;SLp0ZXWqpdy!K!Y}k&Y(y zpUXktseDH}Niy#nH=W(vxv{hqFdEfsae1fxb#iO}LAJP&fD?Bjzsvq)qMX_unr4Wwww2sDK+vZ(Pk*|kahzj4%%iH_QK`yL;m`HTwe7a- z>SGerjRvFqN`b+U1Tw0qP4+EktU--Wl4v*NtwZB3a!JL1m?8*0)4qwTMHZx`S>XQ6 zKeAiy%>WtfVbUkZS<|%r&>X z6MVd8cZPPk#8-nHHyBOIwX+-drYX&Q6|tA^==v>>GmGjFNpZ>$HimIRUxmnbQ{01P zBZ=omC~}gxN3qt1c#XC}5s5x4Ovd2eJB?kQYE5E64~0=(q+(T-m^Ez8k(sqY>KBRB zacBx>>0C~DmBfWYw>o=sQp`ocI$2DWB$R(l*>=kCs;@%>B z#l0ijTyXn^Leo>Ss#2z8?l_fT+#q;(dmr(6=!1)qCSzqFdkGWhb4KT;yIGx-JD!+? zVO8+C!_S*|JlYoQYI7JBy5XA;j=)~6cJnJUqA?cig7u3&{Lqb+^KCP6ZUwg>0}5<; z?Z(1vn zvae7#zcT&gX;w`A`TK!`7V{+>VxLCpk+v_ovP0N+6lIpIA%(H;D9!o&eRfMXjfDY1VW%l+C7++qh@OAPJ^CKWw6-9V@+ z8sgE74w|!^mDn9Q{oI-1d; z6Kzz!_deXbBl2EznO!EP5WVO+-E#kpoVY6!{NAuvVMJB0hRZ}rADPc>Sfk|*yNOUH zq(o#E>_(M540hROITS)tVF*!W36|w1A9g0#KGM)~7ms+t1iN@^laS)xFuvUI(a4_F zo*20xe7{{h>Qu73W6gpo{b*SA&Mig(IuUd(6fe>0W93K#@(}#6!`38*NEIKecC`xG zvT1PE1=6ceM4rjhF>!>^x^0*|(P&fEMM>C;(ea}rYqEzL9+jPHZ@SLh;x9`~)2lgU zmprc6PafY-ej7X=T<7V&YSR`_-*Px^B;l2iY-8v!r?0G^Xf!s_WiY1r+IG403FW8S zZFAG?jn%~PaCh(0oF=r#S9<4#_%r;r`L68R+|9NY2&M?Hi(9#7cSpbCS%2Zer=@;( zQ=RvnD)7r)Ot8i`BUOuWWf3z8Nk|CEZCuTb*zTJkRYg9@O+W2=h4%)s9hUwdgtT|B ze|R=&DROWR17`?5GlvO&n!l(xN{=b9Par(n|K6&$F;!ct(2e22TYY-_g@zjylap_D zTZ^}@$dWv81rw%N&Cd;Wu1DsZF+3ViqtO2NHuRmZ^1b@ADpt9VYLkRYf(7ozIM4K+ z>ox9v7}^|yi^H7G9*o?5`p3J}ea(uLg0a!i*v_H-B>mm|Z`0qu5~ImVY47`o=Ld`+~$4CD|h)epADbpW$I1`8kujvH4sTpA%2UD|%hsl^dI z-A%o1e3eYEXB*1Q@jz3@jvu{GyIsR{<;8d_!*f4li@SGg8`;L%@3b@_5MT2D+1U+c zFwW?cV%jfIp&0o8e*ql0xw;5k`H^bU>O6cOwH}_;Rawg1z+Az{B2AD9WN{^Hogk_y zcmTcXaS5Y5mXl@M@al`K`*cb;j3W?s(>-GmoUj7#o{f>{owNnFcPl+7RowMFFm)us z6EFYy6j-m|!||%U2PEp^lEmS17DC=73lWjGXN@sWKPaA@wT-Gp%2_B>D^y!TJ34UP?;_ynxn9mYqtu!uKYyENp?gj~* zuUNB-sWjibNDq5!qt!8835@zCaN4kB7n8iYdy}8&!G~AztsCK1D=qB0X|cdV+8xvCnuoQ zphUiKA-fnGc!-DSf#BCU=)zmB7rjn(AH~qT>*7DvyYl@+JWV`UfqpL2z#ri)xji2^q>sj6$#9!RwCyD zW~8#~mMY1a-OIb%FACfQWJm>g=_YV~0%Yg{M!AU|+_}jb*#+=C0(b(4Q1Cjwl?>SY zD_|p!h3jk@v8fgoV_y7s4IIhDQxeSo1 z00}%iZonEz4Uk*_2^`8ea44w&c@H3gLm3ASMIYE|8@uk<wLxByfrX zdlUndr2w$cQzCyt+&?l7%mGYd960Y3Y`x1?7)DiKJv&Y{U1%nGE$?mcu;n5J_EcQ77NfkUPFjB&FJ-PO-r+ zcdSArrQFg>zTqNQn;w?IF})D(=||+iFpV#N>`T-j-9jC{AHoES3p3)JejslU=}AJ= zAlJe}wvo#;q0*8X>6sg58SYsgRzbM&m}x?(ML*J$n#h4;dR6Y2kEp?*rI2uAmkIVP z%!qZGR_@q_sNq^mA=$>V+_5)NgG`G9=|-yDu?10se2W9w#;Dw}JJI^ZX^${ZHlhZN zmUZHd8u?>7q6Y1jb&`!E`D65`#JiP_oL8nL{ruyD^j0G$EU*baYOkhe1t0E=Xs=G7 zTOb4CK9uMQcG*0xD)g>xi_O|VA7?`Ggvl|n6Nevr`mzuw(=L%Mr5Cfztc5{EKd*^~ zJ*?%)34zAn)~m%PBW3~NaNsB~8sIm5VDzPd+e%knfX9TQa0v^rrbrkKsGHmv3@Dn| zWcKgkWME8bF#1x#)k9I|2_;FIEM@lXa56ws-h`4AO$#!Wl5lG2N=A5ZC<=?v9&-x9 z=t~6Wx$kI(V~Zmch+-wICv8$)?XFY@cUZ{ji+!TGbr+*I$ngqXU%HYNt}jz52p^TM zI!q?^%jeAsvW(eW*Upb0zTa=J$65%< z881^Zq`&54l~BtVwL8e}Wk$LBOmj1r_mh6!>^qY|V4O8-x1Zh1mU1;ubF-ZHlX~9l zs!3^sR!6jnYk*dVSkt0(e*BZBMTY!%kNf>?Wl9rd*Jkus*P%JVz%|LWP+$q6DCh@v zFC$9YT+Pi>-b1)n2e@g`F+ZN*em{{OtC@-GQ)oOvaR_pagIL^T5ODg`+redherXaC$>f;y4tt zo|5oLhFY{Hh@TEC#WRKJy(nx^Meb;La5ZL=GNS?BlsTaxbc#&!bv(y_Jl?bCuNqUa zL=_7#{M=Z|5G@WaZ&_pesc;I*_~$HWS%w1-4qbPpYF0=@746aT9>lt9v=o|u)MHil z>$n6i(VZ1k%A0-c3jBjWlM#)q;90G981-GF3wqVEd9%Ak?VS1XbM@^LJuvWy_S4p^ zQim>4UiSW5d9yvt7eCa+_mf|_7dwVkCDF!yI?a?H-|JGUlQ#>Y;p%5UU{X*nQ>t&d zS*+EOD53|L0$KE9+XUZ)95Q!RkF(+!W{J?3=As;QcjcJeU#7$kot^P?vma3L*gVtf z7#7icrs*uCkO!>Lcr#q9Lr6p~M{|=addMbWthrw_KiF#3vBf^TTf13lKs zIje_S9ecv;AJ`8h6;jKTV2FP5{CIljQcZA2jIpV2_Z(k-y#I_ zk5y{!1t6&<&FUcgfrvta9_yJsefaV&Rxo&(p-PHa@}`mWJ{p`rcApU507seN_+w2K zGN!>%LWHN}O_MVF^n|Bu@H4Ebb;e@{oHMj3dd6cCxc_|=58){R+&={6KzK^qG)tHa3)((SvVF__DHphT2AEbdl``MspI8X#SOJzWp z2ht#!ov9Kx1kYo}+B$h%qK)cBpDi)ldLAw(ej9OFPuZP^zOU_H~=&BOs9S-OyGf-PZ z7=Sl-4Crz|E}(WH=PGIN{DoKti=B^mE=zN`C}Z~&C0eUilBw9wh`dj66l8h%g6Ny@}=NO9fH@$)Q9R1q&V`l?>Qw8!H;BM0bQjR#BrRXzIc{jxNRiW_Tw3nO4#vdT_~xnRpQ`J%}LNp7O52}P3jI&nRkiY z(Mx8EzOsbiM2ieDn8;4hZRyICH@mFEImK6IcB#G9AXnb(e0!I!SB*<4A4g@Y5^Yj~ zadCuxpYI*~O)7g;NUL7#u+uU|ez&)Mu?*M(q+>TrK2yqY+JQdS{{{n+Lnl=RXY z6*`X#)!qkw1nJhlo4X{+>mvgT?b4T4j zxO)czKY};e4AKihTbJ51T#|j~CuJsj%~MW|0(=9y1WpKoe8Yf`2FwHA#12as*5y;`oO;XaQY{1P^$gIER{!+i+Q>}Tn^t4)JZ|pI}g$6zijxGA= z_N|jn{w&=S>bsj_i5`oHWAx1ogWT(96zykoo7}WXXMrjZ=Zg&%1PGanV1sh7G2r%J z{?2pxNEaYe&}i<1hJE14JqqG&FRK*axM=v&Jgxi!>-o0%1Pm7@QvFm4TY@3L_1{S7 z1pD$Ot~OH5YE;<)Lm55hK1J9ED%_*Ng6)>TYOiGq+P)5ne;vY4I_|^}1t!7t%54v9 zca8C#nbWJjtU~m4mAAk)Yymg_GO_+q*De~KGym6ZBpc+ax{|kl{PF>b<=NtUR}Z32 z?7#FlbwqLY>3qS-W`^v|H2IS&-jrJl#~L{_%oh&4c9;$5lGzP~GSYR_6A| zgZDFj%(FfuiAx*x=V$dR?RwuZOujYud5l%XoVcn>K8tTHLg!-4oOin1W!*eIApZIN zBX3?r;Jez`)l$nTt57Wqj;l2a{X?w_0%LQx=NmPMd`?H82`9ox`iv;XbuOKHEsG4} z(&a-r-cM&RcAa#sdH%*1HBzCXD|=*5N%FMjAq3Ucq+oH%S%eJ1HBrYf56pZ+BUvI^ z(oTo>;x#GEo07v9lK_E(Kf2M$(c}%?ziMxQGW;tBGt`5xp1B z&M(fnUb7H{rG82URk6N*ITK1l`2<@^+a<%{Q!!<8n<@Sizw>YWbvTeOhu#w<<+!>AzJO&n#M8FdgPQ^jW}} zKV_(kI6dNVqaZKHFtg|+XJ-Yk#;_J=dQ`mTqh4}dePmm8oL5_L2efv%(EvQLWgG=s z_bEaI5{M@)AVTT7UCRz}Y<4aelC2(|VsA=v4-~AE#7fPb$kf#LN}s0bkD4*GA641K z1TxSg-$-D8anfB%oJ|w%FE@+;D+kG(-v2t}VNl*C9edVc?t_PU;3LJLF@|$88mtRF zM#|VQo#4z%UAlZ7wrd=ud;)oTN>Her4DBvtID4ynYu+P$BAtTq#7G4eNgi?Ld^;=Q zfL@{Wwp@1DL~?dQ2hxiD38hGiJE_sIX#GWIVy{g~zbAYV6!N3N7ZvzR`95R|H&15q zd%8tiSer-B+~2kvM!uZ4GPl{h?XvW!lW4U~9r+>_nn&|)xHGN&Ceafv5xvZWm(3i- zvC&C*tK*poBH_%=25c^J(aWUK?M_cRi9`wpgqhmhL=|Q$dyru?!^t#pGoq1#Ry_AI zd*@%ayFF9wBxFVx=bn-e>{*$IR4j0b^Zpk0%jZzQM!#M8P;ZRycB6}bmCPg&a4oxGkyy9XGg zn&<9_^7aO$HP3ojYYUy5bu!2uAMlK2b4>18`C{?rDYg$~(urF;w$}i}^O8Y*W(Yt$ zxxwPWU9S6SxSO2Zy+eV?_?tA`qcKs^>22npa(uU3X zt8JPLg)>9IDA)^>xb$%xXY)e3h(ygZ28Ve*i5h+BiB4ck z-tyTOXDm!&O27f^R?=ifj62AMJK8%ZZQt_saSCAP++b(3-^QB0jwOCw;!AGpovWou z>bA+^?>4TKKp`*oQhxr>&B;as?H-%J}XH>t!Wacl9gftB6Hw zS(|guSe0qbJ4Y*(@@YGkUgH=@&neSO<`B_)o=_E$1E41;&Aq-(gLnPc^1B6T?!E6c z=(_n*YhE<^imiFUf>or}Ja%-sjk*1-RjStfg)b3W$ffiShYLgjh|l^WpRy9F9^{WEzzQ{`d`~D3c@;QZ*c5U~`8=E+I|MNzwyJ>%pEL0_z#=8(hAeZ-b}gkQxE%Sf^B|Iz$83DGyQ#RA?wM zyYnjacuYVlV!(!C@*z?9Bf6Y{TNYMsD`7F(#}DSGd9ly5jHgJf6{&;U*$&8|3zynX z?(x$$Wl3bn_(*~ck1At_CAeoRFdAt0FCcr-&p`V|h|~`_UKS5xjj(D#sL(*EbH|sF zPXhO_BysldB3%OL(O^Z_go)^1B(EVp$0^?R-{?MR-5!*JU2X2L9)U@TOvBAcUW}S<5xn1pfXrc z&>1}{YUV1PgyigpfDE)+DC%KA28IF10Ye<(xw|pNV(%nw+u5mlqs za6Y~waQ0r-U{`<g6YL}VBpprioF~S<74l(# zI<_SKzAG{>pb)#B2vBiqpaZ%gv=(EZ17UF{QYpmGMW_b{w0JU>H?x9z!KzuTT6!evgu=Qq!32K`Tcx^7)ArdK8OuY z@V=R?=u(x%#;M>C8*VM!(U>lThCZ042DFarD~vKg;v#bbW5ANQ`?rw;0lgTK6rPNz z14Lv14_ZCW{w-uzKq00fhA%D38JU1E!aO~P8V+2?t_SZMBG=KroCSgabO!Q#O5VMq z$5@De%z|VC4I@&Y9`tKiuuJ3&;dK3`ppjTd?5gDGK3NKAH2Z`DU8$es0Pp^!7(AK z8PNbfbwEm?$E4wq?8+q-A=EKoe5mEXNwi}NWChwf<}n>|Ja7*)9pp=j!bJ5WEI}FI zujWOD@W3ddx&qBNWhkLBQcs?NcIW0@cwB@qEvt<`CM_8cJRo?kZzOYN{X8 z)SOG_E{mPYTw~c>z04DnaO3$xW&sb#A8S7kVFWt80{HKqS3&pl+9z|YM_mi=!#^w5 zCaK+y?Si#S++tg)(sO&CJJ@nUHnW5dKKUfdx%{N+h@)Z&VW7>{eV8k1G9(ndwA$nv z#J`GjeU12fZZ(U?)%YX%cwO!eQ0%Np+|xc*FU)w#I2KF)Ida-0$-b!5zNofF*CO8W zN`JO@`HZo57vrw4WJCxTjFmR`bC8W#hPcm}zgZFDNq2Chne-j1dCGF1o}$1e*zJkMB2P>YX(BG%CXBlkyw0;Hhg zP+uGr%@@DNIu${kAb{_hlt4`eD)iua?eJfP(V$3r@CxZZ+!t^Q7!KLCyqbcIP(bTN z2mBC(G73=WIp=j!!r+fg#OTF@VF61QV#8=r=m;=6{W)>)J{6KW0B}(XK*3UA!}XQe z3=j8qdeFrA{Q*Pn>uKWf^iDD7ZA!!Zb%Dt0gtX#^cjHUl7;S%|49gY%}B6Gduxgf6R_nsSb09_3% z{g(;4tRw9C-8PL{w&qHh99e#O#$a6rHJoS5~TbNhX%I}P%B4!PhBn7SOn^? zgdj~Db9dbGNcV`HCi&$u@1l_}0djWC@p8@f*lpNaYgMPf4$>bgu$7s^?*N@oHmvOm z>(ci^6@l_46vw$8NGv`}>l54(dOhmZHy+p}zL>1{ zIqST(XK@8+Rl>9B!=VzvA@G%LUa{54iN@eckhTwROQ5Z|;`rSLE%#G5YvTsmL(%-w zVHY{bD*nP7ks=Xo4i{#6R&)D!W|tD0WPS0)=}(@vBjM1ow_WLl2~|&G42?x)g(et7 zpFN}r5tH!jBXdezIjE8FoIRVmqu;s*KyZrNQd;ZYF^ktWdG^j-JDrmh+1~4lgGonk z2QyJ`QeMtzugsO2ZREAwDJsf#J0{Aw=yqxMCc#?~R1$cGc5y}KbEho@!8zK+&oZCU zm*-_{_&gH1J~MKRYG}Pqe68aE=s@_vYaM#SV#Ibxhrn25YML-cOOwmT?x*>0eKYDG zDr?Nv4CH2UwPIw<3up(2&>fEl%F~T4IO}%1FlN-lDb&_{E-45&w@N;r;9fST+jce< z5n@WL4pI-~5^I+)xm#n+oj;wx6k464Z%?ZVO<^5Xbu()2Vi~S_Yz4nJ4 zaeS}$_%w0MHDQjalgAlfGv9Ct(Y-? zzSgK;whZ^pDljw6$W$Z0eJzJ)Mn7@wLuS1oj=GOC+!=T1RNPB;s$7~sQi;T9=6AzD zC$%>S;PyuNSl+i6cWb6IwJEAk-Uu%W!tEQlpobf>6-E@`y2pL1d#y5sT&_nUPJPSg z#$jeO+YdwR8~C7yFJ&tx&x21~vqpIy1jBOsRx94hNa-)`+RkJSlT@Ef2rn++j>DX2 zwy}W+X}~AGS)+x~&v$aF5JMYxud(o*CfzY+zFBl~OZ4^%Q`V@%v)~CGVD?g`5K;As zq3B{F!0j^awgoU-1uUVlxSMb@(-JaX&wpf@3+nBVHR=NpMAdaVP;aTM(bTz20>bJ#J?J4r)@aRKW?P6oPhzm7+~Tgg$YL|x zz7QY`7I$GHi_E~Cq~Oy>eXIB`eHp+4rciI_aMvoWOP@=K{bU`Ux9sBXTvuick*LJk zf%S=1^h?#_nkdEDHZyk>tZZXFowu^BZ*j*b(!qW~eXBcOeQW@c0rrdNTgCG3dkzqp zV88o)t7P7N3zzG<)|5mCp6VX!SA?VyU_;(#k6&r9T7Mo~tN6&0=S6Tmu*3VJi>vLuzWPCykTn7kHExHISv-d&9KYCfriqVs9n*y!|X^hNlU~$#MF~mM0 z%NmeHu`d?lK1m-QmYL*o^){SDJ5kLV*g7O%^nt7OE{|relU3JsK@V$y{d|=1H(K1i zBDP3>Zrsokd}5Y0dbEU#|8n z(DXTXMTx_u));8OlVElYbPf`8W+jN+Eb7-w{uK0}zjKf%iae`&XTS}=dugY+SEGm2 z`ni>P53wCP?Fm+DZi0wH(UM-WchI}O&NL26E~@Gb?!{Qj~6d||zwHQUHF(eZNt?r^Cxe&*Uq zW>=z>TW74lSjsV?mEWxy)W6k_{`MG~ax2yI(-Q%02lA--&s;(M26dXeDR~vR*Iaho z8{2QX!!NI6y7{1e-pwpx29tqK7_%M*dsA*Jz|~wE=E;mxfJQQPXpxwcgp zV=QoXcn-M8_;LZcw&f52Twntu4upd{8>Mu;PSjJvVZn7t%Pouy&>hoslF-0?I0cCs z4RjiZC)#~lkuYO>nvzWtYkI)2+hdxams7;LzkYZxG9pc4w2UtYlh)k2AhYW6JZ_4m zwQL{!Sq>KMy(LPSHk}k6tJCyVg{|b(=>~H-CLX$+-rKo|z4r~{^xbXVs9?~H_j2_*avd9>065REh z(f=F@v*4Jmd9a{g^}*ui{L4G$937Dk6j8OFB9>y8#-Wo@G(u+V;=+xBu9kkM9Briv zueQT)6%I`#sF4=Vy-v^Toya~V_nKIcP_8>1dru)}bg%rLcii5GD-fe;zp|d)4_$rQ zh0;cKom=B`f*+LS+{elNv{k2QG<|jVUnWdM# z^xs!FyBY7w?o4jEW$w85lF}yaWj&*peIMiH=Ftz`cL?f-dS+OWuU1QL97K1}SHf_>X27fLam7~W`jY}O4u9apRaBSr}$bVi% zPU2qulzDu0un18;pJ7eqKa_l$SMT58Z%Lc9o+Sl)(fiycZ&b^$IA4EYw$pkxMK&=v6lo++@YvcMwk09_$*p;v>1K%5 zJVD0AN!G)GV9~Yn`+4>IRl#RN3k{iu8kk-d=LhE2|BdA!X4WqwQ zMh&miu8+PYj_^RycFJMn;@7GATd4MNC zqOcp)PyNm(yBaGhjPE65kc5_AZ7Stj3M0IxZ*6`*q<_fu8cxo=QoiP9D}7NGc)z<| zavc6~iX-k5;`gssKY_3YO8L}7u74WPWsJHq)G1DK4d{yLPDZ5{d={Zg`%L%rCY|r{ ztyynW2*`_W(2-%P(V9D^pDt|;K}pc#$S@hqPkRxCIcFUx8m1@~dqz?5H*^(LIG}Sl$P}(ZN@;vYD-+v?@m!)@LV9WGMK^)|~3FlInd~@%^qqWeG(;t}5%RSEeuq@HTDNS_k=`%r*LPySXs0Tq-%Xl_f#uD z%i35<;3Ui)kw4IGFC>+X??@eO_0hfyf5~y6fHCzv(1&4%c?nZW)ZnpEtZ4MQlH}Ea zUpllIvTC@ZJ~*zKy@Gasxbb#pf?+3QjoRE{ye02N_d7cA&!2rEv%?*U3N?t=pd8}a zjWzM0_~$iU1D`LY$iw#5n29U;I>(x=+#@D@o|J z#CQXpu6rU+>s`i~Rd}QDyzh(Pm56L_GKhB1eWc!e8gA{Ie(CuLn+k6l-r;>OXobl3 z7WpNLk;&jky_CRDiY%ajDcyy}`)yQ$RnxX&d>q3;!4j2&fsAj2?tAwQKBJtM;RmOq zGOIw%678fW)d2#wcL|BtDw4v6A;`zj?}(jiE9cS$2HDs{vm-Q5jx zbayu=(%u2mAPPu#cOTsizU%k*&-(|n&-2Xe-Y~m6^Tg+wjoT)GZE%DrZN{5=L~0Dg z1t@r2z*>uuk|($q(KiLKJYPma)ng0^1Owq88IOC?fYrBE_6 z7YZzGWKky*WLWHUuXD!CP%-O5Q~$i`+1FAAfA7>aPEa<#oEk znQ)*AKw(Cib71Ead&l3LNtBI{3)q5Do;Bm^zAO+6mVf4hr;Am<6wL6<2VWPXKq&b0 zGe{@zGyj+DXrt+!7|$MGRw9q)cd|Z1dRd9eo$wYtNE&(inO9Dy{xjzn`_Hf#YpFZ& zUQj&4VyMOM|yuD=d zY8?evD?6M-LMivV5isf_fpejgV|zrnT8b4q5=w?nzC)ptg%9qyTIqKlz6s4Qu7ODn zyDyu%<$|?!|2`%B^(JUoF6a3Hs~aMcI!A`YRkb&_jRqx+p)W zsYm+TDO;IKCemG(Q#Ork_W5%v9v!=EUJWGP%fu}{7jZ$`>Z3}cyDp_{>UP;|2dH|= zrV`2~M{(h)$ELjng|&cE?c|i*r&n3a1Wkrxk!nA`$YzzK`?$}UAO3Ol!Gl9@YPqHF zuMXY8dC&GW{CVK1VwzeP7C=DNQtju^aDvKDwb5D?8A;5W1C^hYbm?WTaOfyD1)P^G z#D20LIRprYFn1}}^S9`q zf?W|#Z)Slo3_}Rfc%pLct>Sq-$3{GAVjo5Cfo*ow&nP(W5HjekqCgk%UZf2!N6$PvD2^&_UuinCc`1&n<7n)t&VJ{`^R}ANncdC{ zq_#l)_`sv57ebw(HI$^gU6wdlXRAT?9}pV}#s+{%M-eRfaTjF$4)u{G-@AW9@=&_p zUSh+w0LM3WI@^-WCpRsd(rB2`m*r*uAHckNh5XOl)WX{}{o=rd5^O}{=Ie=e;VjeW z>G?MQf6Tl8F>n5>vHl-J`yZnx)7TM+en(lj@VXP(KX3Gq3mhT|m}yMh(#F8KBrh-I zf#$()je&Ck<}+X!zb)V*X>P+rzEl2>sUiN4A^#r(SaU!P>VJ$Q!GDa!{}`aBn8-ev zqlbnxqXU3}_afK`=mK!f|6N9^_fqR0NAl%g)l<@c?Tqn#p2iHcE4*fC2SGO$8@l{`Tlu%aShn%WWi5`qyJh< z0sRCTNdDI#5HNXx1|$D9Xb1k^B>Y`8VEBO6Ril4s1JUlJzO<{OZRZ#K1x8_}XFvEB zF@B5OnVy5NZ*U;;gXwA@TKnsp;vt#53HHtNAQC~$UKbO-gO2Wf zgq{KNUA(G>_PD`AIhkL5p|^5l;Dgjh1&aKbZ7bKWb_}_|+u>SD5OekZecp=4e7DX9 zq92j-DHqBHJs);{v-Cz38s+BpRQYGzKeNCke#h>DR}{*-z@<3x)I_Wy1R0KI!ceeG zn-58}ry4#h4{-M;yLCgAiiENiNJ?ZvDHJW!J^-IpbX%58g`vBZiK=mnBIRYyQD5m)Ff9-M2feK)zb^HL$XoZ2!O@z%c@tb%wp zs7Fi1xPJ~AF;+qY=Q*%ogJp-K$^o560qp`4xmenYeilRY*||%4>iF{vC`bkEI9ddx zNLa*Uxo`bUz>;E@X5~wIU6+v=A)@a}E6-s=R1|vVMjkqseQuj$fkhAPcI|EbJO|>T z(|u&XW;fs><)9IA63iwpr|>3&S^GJzBQS&jjMO$_`-86|eoRhR)uIP>sxyV9t##h= zu>FkIqv)C2{@3Hyl!jLnh{z_2u*24qU_TYDzPZA;^JS>ar6+7ZW^b9I$joBOy5rr%AzZ1})7 z5f1Z)S6>pv+%>(n3`?n&vcxRcKm)u1ZUta|CNyVlRomH(91f_v5GQGsPN)b--qrr) z@dUwMdZD->y2R^l;RPjk?+}<4tEaH#RnqaxVGs4G{+P|mq=$v%R?gJP5e=RzcN}}_ zJc|b79aZ6Zg+jH5IU0iZOqBZyYh>?9)siexiii8w>|S9%F%P>Sp7(9B=L_O`hm3XS z;>Glna_EL>TVPqDz)gopVi*tKa2t zl&STYNq&tkAO3(`9FW;>pFT#P*E7KZMHkD3f}~CPLt&{Ok5q>bnABmyu>8uwZSz?T zyzL0LNi5{2u!zaLNjXgIMyNH-jb2N?hAnFg&Nr zW_Ww-h1MHV4kcS*wvwFyyMqy3d6F~kelAywo3cAIvzL-lGQRa5;b7#1sX z!*g%+e>6BXeA#PFg_ZKBEg%NktA^y81+b=Sm#sSFtQM~GCJUkcniIDzvwKzz9rf&j z8Lwt4cw&Gdw|=(=rh@A(cHRn3R-j{)+h*nRdgbRNZHsuY8;uu;d;aUumib4`+?6$i z$2jb7H5fkK)@#pJPIZi_Ffxs{*x-@~062%%YB)2?x#&u`9L&uif#1=2KlF51@=pZ6 zr>P(Q<%heiIuUG*HPFQ^wsU+U=D4{?q5<0LFfLCQ+P$HgVh)3A(-^45gUpD~hG56?9CiWT2F;R!Ol! z$+pXC%a+a#QEtOVitQlQr7#f`{m^G>$Vp0dT!R;*opu#67Uf$ChPSmTbL-2CMl_FN zxYdI<53BJ9se@69i+9~a#@;{qboCW4(~wFG31KKuZ!>oF4J@;hN~|@$RHzuL3K;{E z7`w_w@pZZNw?r`%*aoP8$EU%aAf|OEH)QPS5V&FkB@-j{7Vq9`MxN@^o2AdIJ7HSCW4O5kLra zHSBh}jbO|KQ(OCgrRXMeyC913fVBw^K%168+*u0>+*#57$i?0>I^1V2kI30-ipE`5 z2uhkg#XOq=B}K7)X`ok|&L%2|^^mbR$6D~Fb2u}95P1ftIVBcssTJoJ7ir}y$|e`#fKz{$i+Ob8AxLtt9LE4VBWyfif*E^ zA*Rng|0xbXrbj#<#flT4gueiebq>LBY>KPMflv!8AoprE*TrBV03WhVQ?r$)=zEOqKCR&*_?x?c#A_+eSUfq+8BL9e$Jb2KloTB- z8o>Np+b83VPywF5WC4gANzp3#2va@o)eJX0@<|=8CJ!UFdRi`_-*;J*@R(?4`r!6b5}3t ziEgCf#!i}PwoX`aG_&FLUZh|8JaPWMHMYvmtH8!S?b}wmFM+QZ;W(;~2cz$VR=ufN zVf8l5R!vn?x4c!krX)_vxb50yiGy8NKrYzfZoM2=((SzE`sd7sFIJ|B9=`bRImXo~ z<>Bbi@STMwCv>QB?DtzE)^Ueg)9H`f;NC_u=pR3^k?d&EL1QKU51ZV+WMk~oBvp)A z94fHK1)0glA4yg!@8?q@`{Q~2?e&JAITVLbPxP{cB_EL|q7Uj6Q-1k&wYzHyT`rEdOyX1+E?T44P z3>*wThJvm*e25bl3CjhxU7A#jQ`%v=r9J}xdWY{ggKBeyu-%mD>vCyXpHb)Ep)_Lq z%nLEZnWt@l$I!dVbje~71;u>g7H$2CSK=3Fya^y)0K|kh+PeL2CDLhw+iMhKHM|G4%Dy8IA?uo`Q5vw zL)Rx!K)Bi^|9IAa{8Tw+19hcyK|Go*)$V?mDB7KO?Q-xFwVf0AS+?b-R4Q2?skeqX zsOsgGwPFL1O^a|1+qmPa zNo}tbwDKyaYP1@W1mJs~IP|(?o9L-zxfTvmHX~Q2Ud`XdMYC@PeOd-FyowIp`Y87a zOP@+ahC@woVy?j@NQB~~Yn^hq0Jj$>{?zU?j3{BiXKywtv|Xf~X6rcn8=Xa$VkG z9D5KMZFf=NuwSpLp=sAj-n%TgR1GQ*A8<|7tbfX=m1Tov!Q9CEGnjyKWIZ0tsUgp58rRzteK zpd2(TO7&Lcc4LAJn*g*028= z^XHLZxN-n1Y1ME(xq*OH{~0JT5J7GN0jXH)LV7#Gljo+0JP&=;~$*kiD6cz zYVbN_ta@i9B(d>9nmY?B1*~2dOkGxaPwb>a6UNANJ2$Vptd5>oNr#qJkc)>lk3+`% zo@BYRMgq&`G<*Bzo)~}?@Gr)KnttZrTQ@j`IK22~z?%Ock=WW`Kz)D#?YxY7u)^t_ zWkacM6TCba+B8|-mG~La)#~j)q-j){Nz7(&U;MN32E6R`eXz9WBca7_K@A`FZv?l~-ghltHoTqpnZiS zU}QoMb#DkQPe_)>o~9lIZQD9U;myp|4Lh%w7k#aFh|6Pa&O7N^#BP|H`~dZR+|(Qa z9c-s(<5)fz>upwDw|SIVsb$>i{p2m3%~6SOsQMEpq@CD@&P2W6uxs&rl>>=5!>u>p}uE2U!u6VUQ$=Pjk`tbuo{zbeyQHSp8i)(s* zVy_%mCH)l9KO?z}GMRSa5tMrjt+tCvXdF!+b(3RJHT$u;mE%wl>tRgtw8<@kjH!rkgRg5s-|H(viO}~?GE9K6Uw`f|x*{*iV zY$Qm{v34z+hZCo{e!XjIc^F?-nDoe7xP=pu4Z|=A4)N#F&Es;8rWQuPZgg%7w>Swoe*i zE-l)V_R@FwWu=>%Bars!t)^?W6q7B z-=z^W*1yOSrGH3_Yw3~x_1>m&q6M_6EfZhio_rm#sBDLA(X@C()KukMapGTulpDw; zoYC@U>LlR3{x13J6AUU$zK-wly`fkZBBZ839#%N1-P&q5R)gCKJ}OA$hB>r~$}gr% z5XZx!wkp(+)NTi?gS(VDJ?4;8Hb0p=@v+#)Da+=QhWdx0z2DZ~4BJH11O@?#-fQ&_ zYCuBIH~UA@A@%wyDQI~E_A38WLojfjV8q171!|26|8Lg?ocftR(4;-1aB(&aAvWfa zFQ|qszv_8qyOEI)CsOP&xO-)(-Y<9$YEsFlEk@e{8-PT*5Mm%ARTx(ICjUa9#z6|i zDq+A4%s{WY!*?p((Ndw_d+S8uGn^9hoHg>TrBQOIug^J;$==7l3l|z2d(w-yZIZeP z(Brw){4IV>vP8K{x3~G;#P8W}*ESxaR%nQ>QAU~6Z$gt+uHTBXtrdU~SpxM6AU&2p z4XIsdaYsN?$@Zn;HFO&VSrR}VUSZa&e420X?25o`aNgts)>rvhpGt31xR-rPv@L9O z>)VM{F{J}B%fbuNQTSxIe}!ZgQBUUSY2rqWK+4~pifD30jbLv`SnmyoUVUiQOp&&e zOp!h<;$Dtj$1K2#;`&lH*K2|w6O9s0s~E)~qlnY-ox09U})Z1ciN}pD}!Tr2IgBz9J6{O|Y za-7Rq?b%j69{txuR*xC0u7#noXc(mAWyt-jTGE^+2ew^t3me&&)% ztB_i#5RIe~+qng)5E7i%QM%>c#{BBWV`XjrQIMXrD0Pma=YDMC66Y67x2M0sC54jh zh;IV;hxWF=@z1SlAbB_X38Ec_`y7k@1Ru-Ekt!p;Q1*$Kk(xh(6^=`geE&cngIjh3 z#e*U)^hg6kd@fw2US5>oh-q>syF7{&8)~_AK#yE8eO>P{QDL|vMjrgfv%F96C^<aL^90$Q&SPULOErk`yh1~ z)nnYm$BL&e>u-90H~FWk1D&&MX0LO~^sgL&cjZ19cqanP_{F9g@`csv4=vR{*x!c% zvZrp~CF*d=vRQBhUY#p3;6-`_u3;bePh<>)&gu_4{#A7FFF}2PhZBj=nk+!a{WFhW zV&3V%=&ykk2y(2;B{IbIBXfU5Ha<*h+V(?-sj*tI-}&3wQQA z7hm3~$v_1jEk+&R?VoBaRp2|KoC=zV0~xL!qhc8TfMQHl;HkVXCFT#r0CNjg7!IJo zS=e_HGWq35u3Wp<=>82jgO3GLG#5b53vLKCp-&;splpE@`^6io48^wq+6vPhOpVkA z8$HAnl0Ig=C>7;idV9=yVJ^xo@%EVIf=HCR?d>tg#V1j2)C)-&uCZVQCV;rAnF>bW z0>G)AIUVhgJT|xce&ta@nZ}w*WdE4aLpC;PF5Thn8S#JOUUc7o2d0-x?cWJ50C)Dk zMgUrhjcwv?tktZ-t2#=qy2`)O$R&$;wjGm@RZw>K$}po~grM1; zf~QG{q*PTe+XpGbgDzKxOuf|)XxlSeYog?O_}eZ|7~1`QKH{9u+7d?*r$6v6qP1%g zJo&(O=F*Pr2Z+;A01+oDL7g5HP!7~vVfgSB{+BK7(=e*y4%QD^*4hQRf%Suz^>-KC z!1F=N+Pe$x;Q8Qy%uyhR)BxxIA>!Iq(6(7e#hlvu?j%QR@S89F3jl=H{{7ny>D}q; z;DF@Os$--_;=+kDC$`;2^rdDg;AZ_-{zo4ZG`j~DtkAjbKfUeH*qwe1ehM0`x<`^= z{3i+2{ZI1sp9Huq|H_L0%9j61=znG7e`WlCW&Xd?|E<2~z6!p?3X=5elRY_ zx@W0FM9oVtgYxkHm68g(fauPvP-8SW^BM3-Rf6!G`%L8ZS0;9C!n+e+9CA5!VL-|9 z?=}JD`Tt4)`NxiZ_o8rtL?yIcY4_^)cmWrFvwt1`KcpL18mfO2fCem;Hf90vg4Uxt z_g!QNK}?2!Ku`f{N;j}Q`464Znz8=MbL)0D*;eYP+0}}-2v4q2z^%q?%m({o={!sH zq2IRMqgmSmW)j z?}!OJftjd}42gdM9P>c?M!N^qHHON??`c5c)sgQ(5#_Ft?y14_&%qgVs6pF~C0Z-@ zsZp{uMqpX57~&r>uOK~1p5PW7;K~PF5e*jvvb)`5SoV3oo;*ZbAuE6VbUPM0Idb=~ zDZSV05N(lF}!}q^9sn*TBc4piC3C5^EX3kotYf#4vKim`l z&TFI&%c;Nj@|+y=zk0tZZKjC!Zd<=NpZ!+b3DuGQ9en&8NIUQc5aLf#tBF&zjxcgj zEFjAzH>fvA3hP0BHUHUP+>@B3gx5L*XIcMCI3eq#c-BGcWx6^PY?=0D;$SW5qEh*X zl)04F&+V-&dpP1eQnY0OH~v)47RXa~gBYlxgRHCxm(W-zYUuskQ0pq&GvL6){{tLd z&+GgT_=bwv@R5yAuJ&`)pk^1KjX}^GfVJeyKg4!73h3Rva2JrCrGU|pb>$k8YGs~B z5c4oQ5mHs^p9|iH^NwINa&n?RJI@&e|U6dDD1woe77qBB+`hT^kpTG1im`MejWDkY1Q%B-}B;8 zT7`h_W93oKy+rFw@`n*`@b3oY;X>!>rbal>;Er@afZJ zVbI&B4YT32q+^k=Iy25H6X;oUWl8-b|FUZ~VooY|h9Q1BmQOfab!U*zyXiyU>)hW1 z^^Uw^*)XC_=*U{}2X*)I-h0P4w=1sRkJAbHBJnf7+u44!@3Q$Ilb^T@d>zL2CIeYf zN#&>4MN`8ty#io=bokfp$T+Y`Toz6@i#gX3XVx6;88CUcn}Ef}X{ogLd3j$Oj-B}BCq^z$(Mx|~ONPyX@4vk? z^BYzx6ViUBSrZ5LNXS+FDtN!855u|f;S|Xe6kigY$7|S%&DDta6dRt_Y90_?P{1AB zs*I^g8{J;TFj_Oe56p=d+Vsg=VV=KT>YRvWVDhB1RIyH5`em!)xDiECid$#| zL|X|k!tRwUc?>O{y z5)JoWPngC1NDb-QD^;^Fp0``p{0f9%UrOIc+#U{M)*h!G{~Y%hh#D<4#bD7XF#|Nfg#KWos&p|QEkTd-eO$8YjY0MDM=7tMIN3WCl^S(UR2Nep6q3M z$mY!Gy1=s;1$D9rl(S{EoUp>q?a@QYg_NDE*VWABcg^wNYby?GCnRU4S~!r+DqLm{ zE$~DE9|<33-K7^uhavc7cTRDJ3h#(q1QYvnNA635P>UmA&Sot^Fl)HKVc&wuF&4+V zyPh(iW8LdMZwEueHx|_H{aV8wWBi=kx#Ee_t>!sZ#XX!mM0FiUZ6SOuQbvDf3#s5t zhQ9|mN-q8CYfjj8)(G;f*fcIU|lKw%itQ0LhK? z?&r*{e48BtHHR&ZQivOhsI3Tjcb93BIXVj_`&i>zMkBCp1TC|zd6otiOs2Vxm{)GCQN%PnbOO{6x6Gop;`( zvAmiQ#EDESz4QMwXXla}F0$~hVoj&@JWVUNgE%H{q~ti|h0ynv6Lpr77wy1=@)md9 zv-Rgyui#%=(Qm+dt6|jSm-YGYx*a)(!peF7P}##12Wo`hJZ_GCN#bK7%th4f>DPW^ z(D);}1=&!Zu~*YAKk47o+_RMZ6l3qO!}!_9o;k+(y~p7>ulb0FuFOZ1C@Jqk+j69* z&j+J8-ygX&go3rN|DLLI7Q{t8mTiC1yph*=61hIfjZ_gYP5H)hCwR`Qk+n zszc@q=Y=6S=f@p8YH!E}>HYkZg>o!^biDE-N)m(e{OfO`%S`<$05kI$ZK{FT@``GY z$wg315v}a%cr84`-TRn54~pbUu*<~vc(OR8xbV#EcY3)}$pxv@%-is zH|@+C#?fz{sFq=HH1T9y5YKHnOcAMy@Y3N`1zVn3#{J#olcsFCPZZP(=f0yEN;e$PX3%cTMbP^1+bKJ5+pE?#?@kTS)SsEtfC?*?y z4+P(qX-S(#)LUH!cHg&6kT{JJIgtn%s81X@bXn0Ktz}jfu{d*SG-fsAU7xz`vn)Nf zkG^Rv_6eex&zJQ|fE}jj#lUj;A8_klv=0~3`el^fiw0I{Z{rUi3~0XIX!!7F&T|_P zRld`F;&ydC-|W%=*_%=0zPCZoGiLEFrWRkaAg{|4H)OayFlsNJ{t>q~gq3_1TL6KD z!3Xxb=ia!K`RhFoR~(~l%C{U-qCfLL^}0_kYh^@nbpxY5;H=D=+!gZ9(~1vcJd8gH ze#j}kAD5gAZL()j3#WZU6}zfA+@slS(i(FL2YJhI&re}pw`uSB*dveFZL3xdDmhr; ze$hB{^O*ALw`}-GbqR9dfNl5!^V#sb-tDzi@2vFpFF39vP7N``%p({I`<6JC6<@cD zg+a1Q`2%w}^M2dt3KEH{c1%>33a;AL#!Z7eDgJ1tlKXSr#n$!AtB3;)``Al~mMQEB z;XEt;!?fOexdnqFbn(PT(;m6u104rOXTh+z)?|@v<*NLjbE-aY=$%ZoVc~>$#(JmQ za?fp;ekPeXQww1h0z15A%RLP(j1xLX&F%rl8L>b!mq;gR48@^2Z#4gRz?=Qse z^UJq_s(k$A^4I41AwRKG_X{5n5@1_kD^GZzWy4SNh71bzrLU=aKd~)G(>|Aj;p9ZF zg5eExfC70w>tejCth0-e*Y~74tZamTe;M%!n63Hs_n(Q4AaV80p3YUSJdhskG|fz>>+Jx|HiozF7aTC<^cFVIkq z(~?c2F~(p*a5!z^N6M{?v0IqKPNa4+8_RX1vOy6QFfOSGjQm}ObSo$tAJx~*OZLJk z({zmsmpxo3@i9?y*p7dZjzJNLR}seiK}X+S3Z*u*3NtZviHc+HN}{?7O^ ztbGr|e<*Ycr**jM;21EYB8~3<&bA!yvPKC7Jop}Oj}MeyGtyKRjkg3{;Ebb`L}R^K zFV(I6vixqB3iwEd%rW>FWs*J!8yWf6&)*m?ABJHtZ;w3B;qc?@&776jE3OZg8dvo& zG1$4d7+>}#WAkWlQMnGm*9yrsnb&(V`Ta5=mhpUN+G8C@$(_B$NS`5_y)42A{*&C4 zAJdQKOYUYys|x9P;_lTJJYEQ0dcnh}8JQ5+)A#;5 z3)ohSb1qGQHWcQiY2LoIqRBe===Cc=CU=qdVP*Sh9kx17@nKRSPB5s;Ko0-Z@q#HlwA z{(Yq9&aL=zU)f;qvqa>8K_!=S69`ePP>O99oazt^Q3zJ}{x-ySu9v>rW5mWTXG)G( zcRz3H54Sk-pXw09u`P3xiUF9BE z1yL!w{ux1k{dz&E=yuio9bC{`ji7BmHl06u`2+pfy#06j>qA+BHb2#LIoB1{cdok( zG6ZcXL#c8qwP8uSZT98#QKS9*E>i7Y5K&R-G?(<>A?;-^?GxlewTr|PWm*i=isa>z zO1#xI51Y;XWDse8WBgdScAqejy#-NL;q(|2Gf7`y?%kIl&Rk#ke!93P~V ziU9Y-JNU03>^`R#a9_2pDLNhdf#$5P@QlAfN4(mmS+$M|%Y`HwUyuu+ zs*IiS(K{!D-Z9F3qvu=q=+)MHwv+{XGmdQ`TQUz*QFXH&30A7#kt>;ZecoKZqfj#6 z9r4jOFHqjC;Ya;WDnsLsnZa)0dUER?jb`uX zZVnyfe;1Va`Z!0nEKR7;j3XHE%ac`}H_xzhIM?|4kiBi(^e4D(s!x|MnHZqeI^24` zWV_7e+~Mnk^0v`TJ`&Bqjh@;q`{G#v=uA2?d@(8Y*-{cNy12wJ$1V4p`g44_=AnMz zmn&$rra#G-R8}xLw}RfgzrD^9z(ZsS;3Kl?>D8SShvy^Qvfc5@ubP455{US-= z?DujumPo*#Y$V|lqkv2aqXa}r%?4|CdKo#<#xY8%UMN}kPgR@9o2lg&fB+q+V8vGS zRjO|U#$%yxf~lpxQ68Xxjvqc>nir$dI;6rczv^XBceXu7-Zg^3>>gfSXBh%rG2B8- zEZKUZNJezMy z>}L2$?jLNQe5c2umU(5V_Qs=n)mKQlhcF@Ov>SG}{EWZpd ziV`7-wmw^@{3)Vpm}RsE{h)ki$X7_=8C=aFc7#SNw)au)9hNZD*&0vqqa8Cr% zArO-QWoQ3aM&`_gYXXpQawALTV%oGdN$d^MqZ#hJ!Vm~L7LkCenG?V2 zXD_90Gf23As)?6e_s205C{vT`BtPdTwe&1b6*Z50FVr`er>c_mX_D^5DK7V3g6ZF? zRDSbJj^T}re(a|7&P6y7ZoknY+&(SGzAQg4Oj-DXV(=}Ivp!*s2RoWH;4*;m_enN{ zfj3a_2hy$<=axjv!1$`h@m#4;!Ir^Z^EDj{WJRFT>_)bm74;ZjErDct)5uF8{Z27m zzuQT+TOX25KF#B$vF_u&CU^al;z!E$g`L^UU7Uqqc$2l6UDFADc*Q1|vP#|B5LNO9 z9<%A%T-s;|6_%a=J&)N$Z8B{O#E{p?cd7GmTT8^PTmnl(;K01E)a13S1NJ@HPjVdY z%`vA0+I)yC)~x`g1#`jLOIc}bMKTO);T}!l?PaOF8Zv7#Q@wCLaqQPSSy8*+R=~{P z*3=-M$(KJfm#^7Fw8)oDm@C!{Aui<0rpz^K{-};W9)h|kIHk>Xv6U>= z2@ORhJ*6(?&CQc65Fc{&0pF~3PPJjD^1J5A8LW7l8%SX=#F4Dke3zN58l z<&{>LDS1d4DpdK{IcktDJhB?AK|-p(OF%-_T8B_{PKGx8uy6WR+UmUa-RiV_$)TK$ z;Q9yVYCc~1=BM_&^iU~2FOeI}&~(j?&v=2RR#j`{9=0ikv5No%iH&J=HCk~qA30&VW za$zxP+WsvoS;CJg4l=otq=sLI4u44Hu3Lf#uA3S7Xtn+f0y7W;j7IBECD1KLmpMFy z8mHKsAxn{Q?s0V{b#-=mm9GW_o-G*^pVGSST#3fz3ebW6k_$6eP<6VG>BO*ex!^ zk~PM@=DE0+QXQ&)BWucDVb>m`K4jih_SC%Rf`!DNVoCaSEdU}-&dM!bTKI-Bv71}B z8wpFp)+@mz0-}ti+$}pB7hXpd4;EuJ75l~wpVCY%Y=hWfc?*2BJV{FuAZ;x*Q$uxR z(ZdAkQ-Ji*K>8#VRlTcKH+#_Fyd1&2yfx%cp$kvPjBcAR_$~64FWOfgg}*<=dG5F! zq#cD+cBC&6&E7*mjTZ+2(aaJpEA&aNQ*28g&IFHr?b^oqV!hiKj;|bc-kCiT21z1j z+mwvKH4Kjve1^VnMLq7#5;ohQ4NW9uIX!_kSISZxD#xdHAliKvGv?Zv(C+a%-^8_~ zYww9!*FMp-5tZfRrH4M?hpAKZ%7cry45=@Y>|@ydM_c-$5t-ySNt?1pi1Z1*Pa=X6 z6Y@s*em*&#={1q4dDO>CTl?QHylVP&^?Zs*a-F|l$T_lbOGm%yH#Y-pg0m<^sKGa0}A4j40w}g$8DnD-%`O|~_U&R&Ii5XdIQ4PSk zB$AaMx3ov1ly|T+|MNmMxAmpoN_WzQYH9il-*Py+#0SJy64V#lfQ8U8xzP*6ATs9b zMmP=(fB>*VP8QH^=7sN}QF>nah0h;Q+c-r~8}(vFJO3%;pO&^XyR_Dsfm*pg{5ebK z6u0$sbf4L66(H#>AT$5_RtvjS{OsM|V2auq+6CJ7WqA*p{b>5q5!ChEgmdcSB=O~q zB?K(POM_eyvOnj~)$K}t^@l=o*U+(}bs0Gxx8yY68gVRnf>u~%G)|RN%H%ULYVwD$ z^+M{W8bx`wM+$Axn(m!ku}z%H^7iFE#VqrXqcZi*(j4gQO?Ino$B;c~>B0$4H;jDQ zoV0AM?E+n0$LBSj+z|RVTnCCk!rO+w*-}gn_uVT3-oM*`S*Anm)$fm^ez_viTb!$m zJ}cyRRJf`q0o!Nc!UbrLAH;Sg4D#x(FXWEVb^`w(iD?{4N=!YP9Iu>pc1;krIo3bW z?PvJdG+x7IDG(0o9hocY_q3nLw#Ti7K8POvERDrnTIX}wKehO5J^y1z6Z0udFi;{H zM?~6vVb^0n&Rl-jE1#o%!|=qS06-}&zf%ESU&Bm$MWj=&<4&`G1)Mftyvb~!@K*a9 z_38OvFEXFl3r~u16|?y%#r+Ddl51es8g)&gCesHsgjhf~8wE%C8~r=k13#bV_%nC3 z9@K52B?4=z1zc@TPSGlR#*0;dG?isJI)+RU?%gZ?sYZeYpKaTrVJyCg#2QPVn07Z->4e&+f4VHa>52JDp>=VA{+V z{LJ@@Ya!dH>0!y`;@j47ny1}mOvgeW`ZtpvcZCuv7ryEX>;BW73H|a8F6#Zy$QZ+J zAvT*-QUZ!yr+Vs|v4X7RNWCme#+^|wjlYCAUucD)pc_L%F0A5zhaCNV0I1fEC_oe% z!r$E%hk|ZO#)70?RW`%=&USa{-MGGwV-h@WIg`E$dd={TVpo7Ec5%hkJy4K}$(pdO zq>oT&B0GXTRq2>0sX@3wpEh#YPFtm@bjIi1g+5%5Ky4F5&oDOsiJ%I}Lup>VLi1gV zH9CtmZq;A4vgqdQUP-~k1|^6=g&Y_UcnM(J zwWrG2rnx3raX7ypH|y2bp&yG{CwcdQ3iOz!keGil;#2e;Yse(fMd8=3IS<43N<>PQ z5Z+Q?ebkS{X>QL4^R6W^Yuk*1??-p>zN?(7$XzYss7pJu{o5Oam#3rm zj1pQ{;2(^*s_% z9%HgiBvpkQ*40>JL6gg$&HiDLwL|atQ9b5DfXHN zKBJk|bzdXCMJj5|JTfW|?5(~0_prQkR903Vl1EMnSth3j?-s8~LjuTId9X%L@VaTR zarv;OPhNK8VW*NoeArx3kEO6anUhu*l6Swvo+5igZo?fju9<8S1JTFgviUl6@*N_I zRb%ya;3Ny;L)m}2Jc2@MVdIrz5&}W>ye;3C9dMC6s&b>?**r_z%Aktn5z7L5@c%xr zg3OIk!irHW6jcV}v@@uxc*N$x9&n%{d~S>yR*Yn!s5ltc%OfUg;^EeFup2TrMg%LS zuu$|IjHAw=(g1s0{5shEU8w5&`o#1vMjQ5t^YLXteBgtC4~bGsK>)?lTUQ4u?ku-^ z*Wb&1l0mfE#$Ght!q}k?_fsb+KaOtE!>y@C!dSgJezIc5Lbo>XxUX@Wg2ujx1F0_| zBSB-|9ZC7WR9~}`8afJ-8Xk*q>-Wbz6O#dU{xfZK3zsK-n&M7cYk<7R^5l=P_)%ek z6oCY|j(v|>fw<@4^_f-OFH#?wq_kE*Hqs@jmW6cS~ zSoS#|cMyFjRyNa!F>lLVn{$3Klk!1FB9S&7@(!y>K-J=j7#W6bgeh|oZC>G5Aj$hT|DZW@wF$K>I`%o4vW;%1rgFCo zpzag%q>R;O0P4O9X}^tbzovROFXW6ojc>8WM4sFWm$>b+GG+Uzy!R7WCAUEN$3E8& zo%66A1e!H=w;#4G8L^daZ>?sx4@90^kehwFHqj&!qK2g+U}vFQMw@8T1mVD9sHZ5n#4kKv1|nnKI=kFgt~pOeMtqaW(R8DcS}Ol$glY9rk#Rl z-*-zxILL8$?53PDOtK+#SPKG_=Cg%sq_SG0{+FT-W|>sTsT0X=Ny7~^h1l1pU60Kdy;x}cem|WwyP;U&{C+)7y4^ciif*w?G2|Vqp^EMZ zF0wf5o2a!P5HpAne+hSMIc@41hv5cGaSxy0iM`>SEyR=GuluB0@)5Lg0kcM1(m8M3 z<#@=U&ngT|fKSy;-L_a)WIJA_a`y33P=X9o$A6 zNmC%fU#41-xT@-qA$Pk=zFF~J?G7bShEok$t<9!WjJbp^O)=kU&G+x}d^rVoht+>$ zF$OSBMz~x?XYzLVTSL}}uxl*6{JSYgmq$;ofPS^cuhl_Tco#8l9MJqm?7ZB&ZON!D zy;|4Uur#>+>eraCI!wLnMt`V}{)k&+!j`hV>41P5j<@VqUh}rbu2EsXw)Lu9W5YH! zzY&83g1s?*>)p$B;a+WdeCrr? zh!U6LZ+s@v2G(Gu<6H)O#BbQE^;f;xrT9=l7AibcH{~BOK?O>c&sm%OM!BxqtG$J9 zDbmpV+PT5B0wcniU%iKP#59ISk~EKWL(21=Q=)gYbsa>BZP_qF#d-|#BZk-^V!-+o z@*{-UDT2)!Km11&kfeqV&yY3nuVJau-?WM`9~wAG@px%l{HfbSPG5*p+CZ^FK~A59 zQnuu>+xb^)T-Ea1lILe?a^y5CG5}%!kB|lk!+(UV+h1(dH`ocUX~v)3(*7f80fGl0 z^8ZO#{t^EqA^^dJXB{LSsf4si62bpAAku3V{aelF2ehM)F+8W_4q<*Zq-Sm4*Fv!Z zHHO{^m>{L~Z|5y(?m#T1sGpZio=(2ko5P$W`U2+R3YuHz%>vO<;Orwo3Ds%sAM zWeL5;9Ca~$zK+lIl^F7%X!^b{&}^Etefq=@axD0euojLjW%DET&$WK0zhlbWwFBgu z&o5%FF7r{*%U~OxT{O3C>I0?ViZntnmb~Armb5QoKF60BO8%jG90VHL91I9oPuxNj zX729=Oe~OV^r29LZ+RW~Hkawll6QEUm2! zt?qGw3mbKFut1Ofsw#s}A^%6(R|mxreBF`+31NX?VetTg;O-i1Nq`{1CAbE6hXh${ zfh@rxNN@-i++}fhcMUE97UvDWuj*C3Ki*gMy%%z3Pv6;{o$Be^J$>%&S=Sg#Ev?}^ zPw}O>*Zm{0^>}+(bQknuz-sL3A#+cfCapKu#M8EOH1<%)X>kn0RZZ{V90YHUEduXg zr3iOgQwe|juIxwG+|Q&t3;Tpd2s!Hyy5d}!KX3XPn_?Ksk(gfT`cW71zcjO+#r*C3 z``Rt{Mt&A(*k}DVFc0lpJQmeg%N5|X$zvPnG*4svsw=3}{xS>b0UJ|R7a#ir2;v6_ z=r4|-4@Q>;Kp)fSp|LD)cHUI7ij8e=3iKKnAaUbMOhgNZ2z|;?rcJX2pGe5+6*jw} zhY=zItUrD{2c70_%v>!79a&xy0M}Hc?U*0bVtT2Lc;H*;JG^Sz`c4YxH({|hY=aF_ zOQ>@<7#RKBhx{U0LL9@PEtZ#hhy-wR`|%+3Es5PGhme45@;nn?hzHHO`#6CZ4m|DT zB=js+>0RnOYc%O(GJ5K<3~>@T^474 z8rFaDG-LAfT+%wREV9|^JujrataQWPW96!co{hzSea~)Ngl8qD8~C1kPDffNv_vX9 zc*aXwC&KPswv{(6&Bw8nmsUf|u=f$I(!j%9Y$dW~rZuF!yyv0s?d|9Btdgpp!Izd| zUhW*&zFkuU&h+pXe! zcM`w(yj5CIx}8VNYC70&>bM2FroFia_hza0m=oG!cd3GiCb_SE91@H# ztBxN!Q#H6x-C$ zki89X*;PU5UoLqNd1PYq#{vjV(&j$kWPX5JzFhJm>`Co5|B2G4A5jA{+O+v&5$HDe z0_W`$L=jkj@^}|I&Cyu0dJeKT_rOBvk}P%oXAHY_L^O~Am;5a@mFcA+BAwSKXf+G? z(wimW7DrzM2AIolIC{RrOpz)##clGYzYL4fWWXt1v*^UyrTv zV!~gQ3gcOw)MEjp;gMhf#QTxp0^|lDUMK*;cqGpO67on;0V4ZIKmh5+(;R)KIphD@ zk9}X9!5w>8uLJp8#%I{v0|!{VrQdoi2_@!h%w4Slm6~{nB6Pt^qsM8`x8UYp-~uR- z_;npeKy_t&?X@TJr;n=upYcOD6eW(@cY@dty{FciEw}+Uufn#s^N{_oNP%CA(V(QV@n+^-YgrXrH>MM^|Z zf<0?>Nd`6Gzb#pn?&=C(Av3jbrWf%xF&6htIZ^#<4=1A>FNE`?5x$`b$LZWVyO(3)OMGvYj!k671vWAI@?TAIJTG+QHEjwU;oWxq+DI8 zLn^A+i<;8SW|HhA)THPwUbIm4ZlK3Nxw=8e`k4q0@}JwR!@8&E5Rz~BYN_qG0I2gc z!%J-hJE`B`@g7u{*5|<@d{xy~Daq=RWw~OAtE2^i6nDG4&s%*U^%EXE;#HXl^8uS^ zyRE_$3Ed-K6u)VqHgmt$cg;JR1bSo-3q%9y(%`WK6qgflxQ9coIp+?fMHG1RvBtCz zd5@R)6C!~u?VW))6`g@aY`GY+U*xv#C=T1+2xvmfoC`um3QymH#CN=de>4m4SMNG= z9WeGvD)okch$tyels2(45Gk7x9*M@?;K0$-= z+5p2{P~tq+F@-jAp4@t2%cwS`7o({`FaQI`6C+A8?izH&7rojh)z!BCu&1ya$bUbb zB%GSzHD3FpsOzVe!R68|*77pPEi=$x-G{7BB{aJ~j3ND?Egg2ud(5TfR#dDw93H@i z3)obXG)BMb{!ft;C=PY3_*M#V2O>w;SU^j%5fzW`8R~j83O^cw$+~QW^M8z;k4FAS zBS#>zf!Gra9BA9@SWG81y6wi&(GUG7s}t?fNNfri^+F$wMvq3B{}?-ah!8zQ-92%w zJ#ig9aqT^ET|IGaJ&Pf5<_I|RTN?N1oqY4no^H|;>U5)6&lK^b;jmH8C57$f1&3}e^dz5NyM+>q}w%= zn*er%Fse|guBj-5q0`U-LRLo)Z+nj@5MqMCtpniJ;c#n!N5QSX!L7sK*1>S=NVs(% z+&Tho9RjzGhVOla?}fs>$!VuCX{SkOr)3~)`SpIA!@$yM%SBF0Q4UKb!x1mz5ig?= zFO!k9j*RoRjPuTnb412@cLsKA26jgVc6)|suml-Q!kaXZ4>d5C!%~XVa@cSLYBZA8 znSq@kQ8DQZT3Y9ON{bYMum!-$!r)}VaI#1^Ss>i|2`!Qaa!3bT=m*!8gX=UooJx&1 z^btKxQSgY)o=8MbWOvWU)}D_YJs;b9K6dqdZ0q?*1aFvb)TBGL0!Fr^RZn};+zuCo zFp@-kZcaLLBe{XD*ib}lXm@O4AR{NSsxf75hmS%SS|UCcC*3O}IhL+itpLVyLRDju z+zzKCe2Jb17vyaL#mSt*}JZlt3-zvvLV^ntVRe9Db98x5f$fZEVX- z4I=r~B-8UzO-;|dg)zOo-(Fm>?H?@8%zKyBAdT&hel*z@0dmVT50r-6*KSwT>&-a- z+U%}Z@YYvU#Qus>bb}l7)&N6!_*UjPZ zsL*3VKOjUu;6XnCp&wX-=J>&t_GTkC=M;fRAKz%Wa0Fa91b*{`)}4~p9oXX0B55Iq z_>e;`$RUt?{T8;M4qF%o*BNj)wHR;s5damPt-*Wh2{W5yjv4)MK$H9E4uI!+n zAV$0&0OVdV;;ALY+^H}-bD2uToAy9|_nPwwRQJWR1iVt4jojN*fF5ti0Z@b<2mPQH z@r(fgyj}sXS3hJt0t&y5<_7e>Op*l94uA&0FL07EIBAWGOG3TfQt|^xjuEKgIP>GQ zaV~Ju4F{JQC)cK_sf~JCn|JD=#W7{x3vg*Tm>pyN9Hnbd0;Wj^o0bBXhL|CR;NmVXeZ4AF22>(_y= z)UYG>c-uWhp(kHpCtm_izA&v5sSUzjB=;+$sbj4hTEiZ_L>DF@4EPF60s|%?OA?sj zwO}dvcK?3p&yDS5aGSS7y)mdh47^}1R`f~`2sB!Ai=?}DuUvd@tC}PLEfLHT&@N!n zE|AgQzJb(6!^(=Uxjd9i#YxO{&n=GAdY%Ap5&YifO@m>?ClWl%0j^lJ8h}zKV!x;` z${#@26-BIw0)Z;Jw9Z&?6yphbZpU*tepGQ!vxK07rEM*PVdtFu`?U;JOdsx?XS{Be<>rTxSKY+X2^+ zfa{XLb=u&%S#X^IOiu)2hXb)=gV<3*?8G2;Pat;G5Ia1G9Vf&N6Jo~*u_J-l2}119 zAa-;RJ0b|%6WSV5+8T7)npdiyCIq2@8Xziis=%K&|TJeUa=&2dZ%#1yGwD$<;TJaRZ zvJ&yTIq0HH;k8dFS2B!s+y2xM2tUH{P%_+PLrRS?uar1V)+89&N^#b?;tC zvn4)-SE#;r;slDyKv5NdGXQx2)&O(?cmt3HU;#iAfIEQHr||wC08#)X07!odXZ{WV zI2>~<0AN3J41jPrGZfAo1!w*SXJ({vFYPUbyb?F!}M@r z3k2Z0G;p0hxNZqt_m5kLs8Hdv|PNzT)Cnci|bd!y=t{&{R9!A)L zGHihxTxSHXv*2_>a5@beZ9oh+{-1n^#tE5x`vvmJgk^6Jq~u4yK}T;ar_dgo2xH_# zQ#EGF?ch-e+X03)4mxvVxdC8DBqLr3BVIHkCx)sq&{9Pd!mfa!jf3u$u^dZ#tQL&1 z997jAXsBEYVVjS41jVgA#T`Ax?LBmc8yY4XQ-&K;#v4;P-)=DGmS%TmzBFavUI61A zb?1X%D}8f^+MVV$AGgBz_a2VLn<94*H=yk%K5DxxfVOLHJ=6Ab`>tFVT2AW5)nPr; z$svodgHoM0?HeT)$?uyb<{41|s__k=8Vj@nspx}Zzcg{ZX%QVO2ubI(lPQn%w`G?kp8v^Ge_JO7r&Xotl!^PHx zhOj#Kh}FvbWtRtIxrMIS+CWA}V%2uJ;MnKcl5(i3gFqKymM7`okuA9)S@5z>0l)wN z7688i*Z|lEKn@_a;AQ>-00$;iCM5v&01N>5GocouAV?_k17>=I%doIaqKVqv2s=}l zp*02~L}QuKOxaSsYVSin6@16ZDbF$Epg2UhFhn3f;f!aBEG^t6;t+9AFc}L8B;w#2 z3Ww2LjTxk74N@Zmsp*2$gh6WFc=_HR{ikCEeL=nP(c&Ypour22~*GnA!tGkG{FPZM_SZRk!KAK^cOQMHr+Ojbpnld z9tt6Xi8#)j6kA3@1Ksg#tu9)jJ7v$0%s6uq_>FZri8%cn6!9iPzkwZLJ7q6!XrFl7 z@K(EEZ*}VoM7t(Z?Qyb^aftI7``NVL&J3)G_Jo1!SiyD0;5u7y-2u3c0$le7wxGBl z{TW=h_@C}#SGqa6{I^dhx6su=TkK2(V>zy>v3PC=FnI>nTf(Z-V*DWe+V^FZ@nX0Rr+*ikL}lm z@z47qIc~L(%`sp#75W3D&EwOi+~!l{UJEX%mOAJVtV-n(5h;hkxdiG<^=v*2}E&4vxV56_p3+A za^Uy|#BS~3i8$iFZL7F{{^`m_2g7D${UZ@HlC+S^W=uKKr~^mo@gVyzmYv7(&?(URnSbIJKoVse zjW;TWx`Fn1DlIOxq%fekJT3~)kRkd8U86-@2`5hF1c3<=KS>((_S;uBjWyBPi5oaQ z>Slf#6+tOM`h6m8D>({E=yasQ0-K9J*H ziIaSs15B`H1w@!YZGV}dyrfXB-_yq+#0@EwvtyUsD}EL6Rroo!_#UpJqs3htJjeGe?U|M8w9As)`)pBK%Tm!@>xC!JhBJ-jUP8ab+>)R9orcE+mICrJ}oZ2$bRU9 z%_TeZ!5okdk4Wu4U)(MBH@Db(?3($P)s$q5Iv*Ou>ebmrniQd|>2zyIbO0H^HXY|t z#l|oB1*%_A+W~-3P73YF-&C>stc557q(`YFdj2x1@YV$tnCW% z1*uH5x4A|5H{0i8$aOa%k1;D)ZGX8sWyc~AnW8y#w28xYEHx>*4ZR`PC3?4TG*kF` z?Mb&r@Jn1E&II%5DObnqKtvUX(@;9vsDn=OO^Vh+yUBIq-iaK}6uw!x)&gQuFS`Y+ znIZ+2%GF6aFe~Hh*TjWvOE06(sf7{f*n(ib zFFn0wAEelzW~5Hszo%ZBYZX!BB3=NiGN-J1y33@c{GgkpFE|Fy{bIX0l%%Mk!K5#M z0arQ5C(vT3WP5Z(_YHRMV|wrg;>zDrDwT28Nn5sF~M5M+mq z3o0==DKJBkHHi?oM1>UPIhGMaifSB>KZyMmOO%-G7MMxE)gQCC;KsSw4qW;tfbvXy zgh4bE*K2rPwW}@9Ok?KD^FV$k<|NW;(!Mf%gCml4FT`aAQba7`ic@a`(D}Aa!M3~s zZQhjW-C7Wic-lyMSWJ24q$T>1Cpj>0ie@(qGT!5i=%RGg#{@6?()1Pv=< zaLVHt#glij2)3&{FSKsC#zF#;V} z&GMap|LvyXrrg=w%8_QK@BDJ9+zscwAMYIQ)y<@p_>UHYzzgo18(u5%h!%s0i;C-; zDl74n7K6MP0=3yJtAlEFfdj4V@_RQQN+><)DHqS=_vp+d=q+fFm(b8MGxN2SJa#Zx z$BJQKL`Mn_%10W`1teC&GJitXKnJ|BhJQ0M-vFtfIY8>Cax#$m$pxf-E_9E`NNGb$ zNc%Wl#+B1D8=yBNUY7Z-$3f6=kSMPJsEJ49Y_6(19ahKOTVxkQ2AY068(S-(;pK63{Q}cz}D} zt+80ZB+vc$zQIRhrQxG7=F!OfXe_?V$03nAV$sWJ!SU8@X?+g_WE{VJS&DvH`&HB! z_4BVl|1PX&I|nqoZ~K%VW-6Xh=!%-`k57h>+yHUfG~S^|WHdJEF6v}zr3o@QvQYLO zR{q7RZSo>tJodqor>p*u*W88PtE`JcOxzAVayO>?NKD+1AN$aX9CJtW)lI!P zLD1F8dwZA72xSBturBo3@51_nN_6FDiv>Zm#Wx*utOe|kp@#7F$*9ro;(4KC-A<(S+>fG4MYW$5H}=ZK*R)5LzZTG$%ZHAbh$tJ9zsqgvN~q-Tv!y8UH$&Fz~O zH)dP%6Tc6PeJgh{W3K2&39)__J-=3QAKAU>vEPRs_Ww}xM@scb?KnJIvR%e&$#(B6 z8w4Au|K32B_YRRwqkhZsl*dhHPnM^Bw!FtIn$sJ0Z>ox#kypGuO_p~AJkVe)jHt0) zw0#uT&)F2&R&D0a{xk_3j@V5ZeF3sowlC!>dia`fdfs4B2rJkZwzGAOHU5;D6G-;> zBS+Q}w4_rPa8Mtx|7Ro!NI($``kCG^R<5pC8{DZT#nwEB<6E_G`sIgZ7jEEaJp=BH zpH8_1_P>Pj80=)p{_tCeQ;1HLqx}8o@;`>>n!4|b1|?4ifFIi0)ffAlt@HYddGEQ|XAte>Rv9 zEIHA%X^QsGDu!kFt>5o?e{rc8=nIfAubSzlbRg|svS8TM7sH7jjH?d1>khd;BfqUG z_0}aD8WSuTq>D~uTP;b{NMLD0OorW7oak2NVeMK{gpE8=Qx&|My^fXjztJF^h1kRk zkRx>0jFne9vEL4|Ws)jAcJr>s7DA3x7-ZKKo>@6tYR|s3Azmvr$zxNQP;H9S)Dw7+Nkng86WKho{%2(FAgWmCgD&rUxw-{M zy%w<*=2`W$`kWl;cD;n47voyx zkUj}!7)}o%tsYClV|X99`rhip58%UQ3uBfgwn1sNT|Hu2AFNY|H)Pz#xVB`(PCR|r zvska{+iBsEvi!*IJ)u@%dMk)Qo!m)Q@ENG z7xF<+!cC$bNW3D*B>yP(Bby>);U@^Pnfu=Pq2fwSyZcL_dvfC{?~elFTq%iqILT>1 zh$UAFCPbSH3kKbtC9e_qsqgq_s$^^vFEXbA)_LPWHCk&>#>!V(G^HM~CAEYw$!5@(%wDrP7I#=ljpUr8Twk0a z&u!_`ELW?5GOF%ziqiP=`WD$*bl6m#b)6D&H_ZUUw;mQhwr7TY$j`z5K1CYQ3mHX< zEB-p)qc2$v@;ySX>EJP&YX6isbHOW1vIc&fhNp>YGVFY{7 z=TwDfdkKbT;TLf>Jx%@+l#ugiN_=F(Ihnu&T z<`idO?2`d`<^EW{l(GevKO66CClZ$Xe`t<=chH!V>#KJj(@^EVYh@M7*7c$M@>7c6 zUm~pzIyFI@LpOr85Ir_Es_GqPeW^d~p#93pfABiI5<6B-{KNeFi1DH^{GG5n5}n3a z#e11o3z8vxq7 zY=*kvn3ded?D=M0Wd~yHpohMI21^NV-8s9$ zYaG4rLR%%3qGwYUi{Bw8YOe=rLe8-B%9|eYX=m%KUl!aLy8Pr0dBPwattT-X zal;_^qSxtgm=r5;6!sYvMql=8Yyn=E*ccIX1*8oSC7``kiHiM>HvKW{+plaE0na)D zwH&+4Bio$KlLDT#*j3#Jx#er$KO;OkNwL9mug3S)6zLnsAKEAQyGO?RRpvEVz9R9!!a=Gl+3*QG*9> zeIhKBOOahIrDqnEEKvO%pQ1$Ii~aZ88?VtqOf;*q0yH%DQ9aF+lo~Dm(kPZHb1v)w z*UimWsw{hLn^B`YDpc_LU6ruC?vKENg?CF!j-*axKy#Cy9StQ*{6%&N*0X&YDH(}p z6>jxZ06z8hBi_!L`RRT9_`4Bu*mWiyKfOACE)hZ-yLeOk(7k`IXP#6xOIFuv-Rh+! z#>a>}I%{vwwn-jx*A<=ZT^(Vr)YE2626pjpX}gLJSDj?!x~^N?(L3A??+S9xrsjwo zNa$?&#at`Isv2x|Azti<)MQ-n-1xVb9qZQ}X{Q~7vG+}_Yvj7;Q1jn;*`D|uj#&h1 zzChZVy7(+Al0E(+fs? zt6wZ0u&rMS*%Wy{47Mu$RP)ZYYUf0}V)dV-DwTVx>m8m7$c0a5tVr(mPiGneOGmY| z9S&GX3%YvkLbD*z32&qGIGqA2!_LHbRno|mOlICN$Wm}?&vZ&BN9VmO(i}r@62avZ z1I>qXkqtYcJi$XNQB7Gb%iOAb=1hZcE3zrFsC}v%;eu!1yL+9+t=ho25PlI1Sl3$J zDKu|laqI#ZdMXYaCw$zI9UN zY$cx_&i1D|BIPKZnom09GEPMN8?1}pQS)O1YDpEdSADQ&fYe*-HioIam5as60k3z+ zlzlQ3chzwFSiE#4H2&T%TPi_(fhs}xIfHqOo)N!Iv%J}L&Dzi^U(BNy3rbq|9{l0O zVvrMVwVaGaeM^-^e;8Ewc4WUCYbf_-o;9T+=#_=HfTFWY>V+iri!Ct@ubKsRTgKTZ z96Iq7vDK;ZbRpTSy6ZE$9Q+%Vc0G6ka7b0wn8wIwiXYWZe+bmN?Jp~?$xbhscDwn3 zevl9uzh5qMmV8moQj-jwcdyM{KgXq53ch!5*cbKOnv(%?dNH!#+t0N3j7g8hf}D6P zeBSKeE&vjc7&Lr(q+$2%*FCG>mugdgV$nB;vstqk@0_)rX%>$#o0qwTINp)~S*~aZ z=|x%tNisK;{pOhIC7E*h`0A9k?=-f!O+(po^9>J_Sb=kKv`LcjytGnSfz`kx2qgBR zM?RfZb_Ag&%MJCIALQ+WvISk4)PTXHnOp$V2}6hT%SLe%4>x zcjPqKE8?O3pGlMwgxLY#eNCMGF}vW9M$bWzZaP}|yRq|!IW;eM1B)%X*#l8oXH>CY z3}2+sUSXwx7mk1YD<#@X_K{YKv&35_EVk^>Tl)QWbfGKK*!iOwrWeEu@*bbl8sTZV z%bUIZmW*d1Wf3=)y=QqWHK|*}Ev9rSi$}$`*aC4={trFL{HhPjC|QC>xxdYbL@R1m z0#10y?wFMnv+0+h0nS!z4G0os@sPk?Za&SouItv1p1C&-ixS!ntl0b2Wmvja=#lWv z1@R9AG1YB%fqY|pW6Th94$}TVJwk3HZ+;Mw*2bmP+gO3G6qj|}Jga`5<;F_Q+3Bor z#PaUvk~)1GrA^RHYe+bxVbP5d_@+4Y?CrS858@Y!*&96=0&zn_xPMC&v5p4^N7fxA zw7d0@WTASNxkxL#*)_yOx=c1jrW+wz7INR%P))+I#4x@j1GUoC@i&1QojqyGd+XWT zh!We=+502!?SG;LzmGItClCp)-^H-_-uYkN?arywXiLVQdt3FBCiVaMt+nS>_W8AJ zuC+$PJBA;+jZNcw3b`umk;;hlsF7mn`~vvP&$Qml%_eE#FtuUqqj@B(7#b~P5=~AN zHjweO?W>tg{iyj%Tgdnp(cGJnt1?56=BT#0Bjy;k7b9C7wozkS0=7%pgY%W134BN6 zTT*jA3Moof{{(Fn$F}6>-i*`7@fnP7>CX8mr8rj#Dy8&SUWM`bk8RQ0-seOT{X!X` zhw|}kHyDW#kn(zUl;sVXQiy&rJx>n2j^4%9cI1}7vq&f7@tRS^rm2&PCn{sHHZ8x6 zcOAq*ed=#f{uG&B*=Nviie~wvLD}ZQx~=WoyWGpf%aRD|HyiTcL}iZ;h>wFYee{tc zBX4#xf5eggWSIJE`mI|LO7>u<(rZm|@Su3Uhn2T(E=Njw-eEiq_TrbrN zS*j5Oajn;cQ5s_g;%Xd(QDVPa{IZo9$culslzb8Z?2`tX%=j;4i}p&b39*B-c+aP+ z!h_pK=dSmJI;B=EKi|1F;RAj z=$_vr^LRrTb@A`w8iOgMee}uFQtP`oWdWg{d2c3VUcxAxi;FZIHLTz)sYX$ve99NH zAzt3Ys9%EGM~#-2D!wIWI=Ix*N}wR|a(_``=FX8HRUH&fHQ^ zsj?Pxm+UGGP3C|KseaCvxfs7>S7fLNvp!4MuhM6q`_JU)5HaNDpb_?=sTt>|VD@xYFP^6;Q6kMUffYT*HthJvDP z^Atr{{uwGE%5&fk1%)~s*!=H*oB(t1bg{IzW4Ey~X8$kB&Bn>a?rh~^#_C{XVr^t$ z=FDzoYG=f5VsC0@!sg()p}A~*!}ro3Y2et8YI(8Nn8s(YW{?n=!Ku zk&1`C88$RX6AVD? zfyECR)Pxxv%x2?UQ6CzYTs)gQJ|fN1*!e$y-nL9P_$=1(CR|Rj3VLL7+L7?Rj`&YF z4a(OSdn59{;M0t16C*^HS)bnNwz#n?zxy3&oD+uWbKgZ=w?qNjB~0YNWezbH|BdtQ zScYmM;?w>*y_>?rt9NB)V182Ca>ZQ)ae_U+ZQIi5w88a8iO2>lz7#z4=3Ey8!JJ3QS+Ow(M7XV8Xy0S zOR}ox$A`_TQPO4EM*Na%{QLIsLywCR%e7}F+qTS;gwch*|y@Xx>t{LwbW6lOS`Sq5FfSN+WO>IeT=9P)eILttTJL%z#Hcz#d> z1thU1J~BH5St#)<%kI{OaBNGn6I9p{`O7LXvLcgl0UG~B6!Q+#>Rch8KT@iA#xlEb z!G2FM)-7KV)pq1VgzAs=>?X>g?wVimtF7}=a%3(s?MxC0p7-bP)Fk`eKN<3PqzBOD zp&QVzP85(SH)reK#f}U{s*KKKcZyTbWazJLnVZEAllSoPd@^cN6${an2a%=T*BsU?YliT+3S=e-5Z|6NNmc^Eid zKuO}se^*N!|Fc?hG6U*pLdP?Dp6}Jea{3zGozyF1vNYQ9gV$`|6=Q7c$3MUo!i^~q z8FYQ-vh-DN;*w^6E&H}f;eYrb7Et~7Md;gKJxIT!jdi$Vbui|4+qPQNm`|}ZVdxjW zGN_8C=Ng}4$_N`M1Sle?W@Zd+eb=uo4PF)k2px?J zhn62bx$P*I(L7ORP)WjvsGzSTKHOTr$cr7CSp zPind~A-PGd zhnFp#A!30PK4=n`l*~F!#p#D&QBn;VZksxBIc9ovroR09beA^-aDda zzQz8r_DN75v~E9X@N9*9K<_ARA`sdO#r;7O<;ovZkj9;utWy1f+8IN&vh%z)H_uCe z<|$&Bfju%1J1hDu>W}w}UUbLU_XBYrI8{9kTUzm{?H0_0c=B+EPw!cyzWbnVeQvRw z)qrg#9L{J|Vv{Hlb*WHX5J*W63@*#q%o5T0s(ppFXFf2LAA>`~a8N~Hh4(5l8QBVj zZE7wZ zQ=IC1bO^5DXW7=9`MoZS;M{B!u$205mkPN!sTeWXYewVE#l(2s0eA=c!E;4&$2|pN z>Fk7Oantp9e?iF-gjbwMA|H+!XQz;VvhQbJVU4KbKMgi+u;!QR)9QT)*mdSi(?+HZa5O~C3iDiUcO z@|B)WkP7dktLi#lrZXZ{&iUTg{p{v*^h#6mfxf=`EOS(3jDlUO+VC|SgN~hMBKxLEX5n`- zNcmX4SJUtQ%(_0X{};>J`wlb8E-8~0)uRa4)Sr|B0e`Em?lSyJ&yMzV&uEaf>IB{M@ITsQq+ayE2UYT8cgKZANGMWWJV{$rL9I28@PNPK5wD>Gz zn78ERWJb-#69vl+p+xBxVxD;WXD;ejw=zybt}Te$I<^vT z?WzWfi|jM&pDmmp(H02mp2Tc>L^{d(`$KEv9SU653vN6V|PwL>AXH0#8z|jaIYH`wY`$4(5dE-`2J0Bm=2#$*z466=` zUCX;sx*Yz5n#fdI$mY_{2FGQ4&3v|2RGp1tFx#2@TV`nN!}atZyB6C+A4pc1c(Pxu z=Ci_-meAi`njYvItiND0NR7(ED@pB;krL_cQRM>9_+wsCDf{R1kE_8Nt61Ig-EUcK-55$~Jm7yZ`;Sfrj!riF zY~&p-&j0m~Jn=arjjo|^86z1Uf}}_LppJ?QcDXCod4sFBXOohZb&I!IJ6IDIgRN{h ze4{nVm#MIJZIX-Gnm}=c=Q>Shf3rtiJMunZ@8$Ce6FkS{`$(kGK1!-W*eOT7I_*y# zcIegO7j3C|DAaD2i%U$b>cMHPc4C}M)*`4!Fdh=2FkVJh2kkhcxydC?7AL99-G8Ao zg~lq3Gbck_8Nm*ng6HnL#Xns+8rW4ZtFf4*>JaqOtL%SA^PC8OG<(UO1e&#gse*i> z`%3YX4PS$NQsl!bVe3b=o407iyC>(>-=j0Ed%ncstCg0IgVnAN^MC|Px&mb43;OGe zMDnWuJqnvY)x)@j_d`!4n?T&Egs=Yn%}Y1XZ}BB!4e+oEF1To7H*-2a+`2etuMw}D zd4E51Az(kdL%iVy-Ft3p$ui@dPjuHBdpeo?8Lw1B@nEyDf@q-^BD&R)9V0rGua>!W zBvVg2;If~}>WZrK_uKiZYQ@#}`*3^(y7#$zthB=?T;w4S(HwUT@jDH_2i$Z$ql5S2 zvtT~I+1g1f$<)5mzia)2vIe(I-5*P3R>#ub$XSSbCc*yKr6%WIXM1Qj<7HUT%RD^> ziaztugaA_KWXi*W)PtphdWTLnlEBna*9K+B_d7~_g@y7@Dw|11jyXdHmG}Db+P))+ zUM?7WY^9deTis|`A?1bs;*HN#p4rs9lNRGTuny5$jA>|yb$!4o!#vZ?^3wYVR`vci z{ls#_=;OBSuQeF%-A|625B8>E-ZcDD%lAgEqcR>Pa^Vg$G%zfS)->=X-X;_A3ZZ^f zaXCX^`fuVw(?Z_fWKYrW*b)g05Rv4WwEv6Qn^bX6jWv z(S33LR8PJCn&~Mo_me*1sV&#PV!qdBqLlV3MkV7DAy<=VWZoOmF+q+^uIwZ}jdu=y zPtYtdUj>YuXV*KKlz3Q`efd>V;xUO`Prz)ZB9|yZ$lF;^@R2|Crn3M(S*)lXo?zZw zalV6oQY)TgIhDGI_$|Td9-5zH`tRbYV!DB)(!bEJVrIkwaDsmpN$UzY)&aC&K559y zJK=DXCh$f6^Dt9Jrq`*9!+|*D#Da2XKTDoPMHY3J@G<@JYIB^bYIX{neyOP20VNtD zkrtP2^@xb|TF@{3b#3=;&-H}bWH`Azl6jAwm;+CTVzv1V&(fJqZd3QoZ>+wrFyn0A zBCXnYej@KD6l*aszr<}YTILDh99OHwAO9ecwik92FEr-t#HD{ywKcdkFJWdLfgsjs zV->1?S)A1!`|B7~Xgp#5b%y=38|5OHLc_I?^>xRg7i4*bChSagvj9F_oGgxx=8F(uhjbzufu{6{na$Dd|vL^e*Ho}G_{?ozU!DB!Pm?Mf{UB)?Km*% zBnZF9cU`3N=u$yUo)K3Fdt++)Hn)Q?kC+w)8cyl^^mqq}iP)_xl9ST7s^aN?^@Nc_ zehlqq9un)5RwJbM=Xx$ma5!B>hG~y*RFNf7CyOguY7s2Sya)3On>fzo0~<$&LqZ0TuynG zU2i^JPP4cd`{`TVgzut>w8dr$1#*e7kGVrV?BneX}`=Qdm1sG zB{duB;Q~sjt9%>f-ff|zTodpR9kmWk44)Eb5ASbrCY1FPsA|9T2j&L22L4I+N)Ko3%lD2Cjt{dB_0u&cK;b%1{BGRfzQ|yT>aIoa zUh`q`=>9n5!TsTiz2$Z%+W!(!)ADfP?R{T-H@}B$x#_?C$Nq3T-Qsg|WB+jCzTE74 zb8+)%wS7GouviyI<)qL%B=SNLeQIqd2-Ihm&xO{Xzx`fK+AH{G6_s_9gvRVFf< zQ0ee8|Q^|#|HwWIQA)}Q;1KHk7Tpt&~{6$VsK-pcX!t5$*D8_2KNSYk&kbJ zR65Z$`SBIL>GsOi+cf8)=u=bs2YPwqFJgVfj$+}bKC=m(b7luC0o`c)S|dcS&YJq~ zx9&|_yr#leSzryqSl&B;mKhapaCx3TS&rnJ|t>R7Rz1geoSEK2N zb%zwTDFrzX9er;QQ@dplzl#G_2GDm~_ar163EoJ}Z`*eTPcQWeavkf(lrnqHp6(Ks zzRz0f+sVIb8gYT;j5epmZ)r@!x1#jH^OfF9qdzaER^i6r?Dgv?;fbb$q1}OfKX10h z^?=HS*O!% zLp_+M!W$m;Y^Ar#td?9QQ7!>;WOOuelyLNLtdX$YJ|-|Ao@a z=DM}HUK*IBIq_D9$l*T|l9#96dBx3XME(ufH>jXU5 z$g6y=EAnr^zIJWwod1Q*Y%fsjk-(HHMlSNdP*nm`Szb|d!jXRs0wt?VlZ}&OC88t> zC6XmboBIFU4+>PnOT9}2OMOd2xz`S`IU232k;4q7Lgt3GC0sC-DGARy-Txw*&611|W(8E)I zyTpDfh_ih5&v29?(Zu=hH_RRqdnBgCyrUITY2bBo`1i8zyUjXlFS1?5T1E`t{v09pCdIpqo-mD`uwl{@tBb}A<8CaWi#f^yLA&+f(9 z>09}(CxbS#({?|De)0@Sa50r6N2$)0X^`P?u1zzsax`lIt;+nYIbcPOUY60``v$#3c$@lLw1KD+XW0u=XL& zp-`t`Fp|T_RbUo*JNFma{WEpV_Xli1&V0AFFE59qJt5|~trePhLdtI^r zZKmCiUd}|_q&CX+pMfw*qLNHJYD6q*1UBU?gOE%`C2Q_z@E;oJ38jvjBFqKOcUBbS zX7#)FzqamQ{=5vE5IZ&cE5T%(WH_qGd5=T=@nn1WtT$=SF|z9NR4L^Hd~sss!6RLq zn*%i29;XrAkdKiR59qosF?rLm+ItMPU9r4m*WcBjo1CX1sg>-MCZVw*{x```*HxSW z5D#_Ay*0|c9p5`rR#J5>iT``5%(RyOSq_-|ksJlhe_8=f{&QXmPW=S-WxB#11+AKu zBl(QrL92xBNp<8#j@y3U7vG1DD|#iPwYmS1J{^yD(yGJnG~tjm;b3~wiS&JbLvDV< zCx#3gl4O-+jqI*mgiZe=;1N=zVq=e49VMbA0D4_uD%&e|PBwD?pTJz{iz@}O@}-d*E^Cr1#}ce)Y|JsPf5gn|c-MQf$5nI~FyzLTV}^1GR2 ze%)Nb&P$=5DLu8E$#@ULF{qtq&Sd4Mb|B?74a+@Q=LQ7FWJ&h8JFF(gNtL*Q;vAb) zJo0>$>-or&W_=@b-V=r87|T>_NA$Xi!Dc8qq!fK!eyAsJW#w-;*gN9%YIW%+b!W9S zU|R0-y2btlm0B9ATH=KKHb{J7zM00Ny`Z7)mn3@}P-f3No^tqr%9k%(KPuI}Ox@1H z-bURM^k%O~N7NL6U61n#%PORIMp-|6nV=wkQylbD1lYqBs^+b5^P$CE>&)y3t` zxKBT0pDt|5KG-zcWtFkB8@v8!HebXB5i$kC~Ie8QyaOQn;W!{pLXbyu-_ zvT2uZ;rB^h5HR7zm!|1sb+D}4psv%LKw96(#`{(%#&$o<<8z!E`!P1aG?=B~@2sCH zG~nX+Yh4wTUhm5#(X$Px=*B%tJwP;VWrr;0<+D=RhnIq(m3<$#vmYW=zjw#JNd*am zAtoLH6>GRh1q=Tr0kvhev)z|eSAWC~C4!1YA=Rlc7%7lG80gJ(w*5N2um8cW8|8MkLz8t;s2c=+ws zUv=Gf@Tnh4;`~tQf$=VI?*As_VB+&o!=bdu4ihh4T>mk5(Qv4O@XdsTQ?|@fL;XY1 zaw3(3N$^7rEk~pN8&@1m!X659I8J|spCVG>B+-8ZY-f7Drayz6f}bH!;#jbv=>H%f zUx_D(r*JgrzX41$B3~_@Hk^Q;B#_`pu@vb4AdY*|;#mU;oRmP0W55alU8{N%L90~} zIxR`y#EGMazgnDvQ~d&Da1NY1dbrWzH+a@?3Qk6##&KZ5XwR9=uhY-|^JOutGqiIr z!o8UOV@Zg@P^C^swE@v+I9Aa})o+w;)4Hm?I(PR+rTI6rex9Y!Bk^*(nB8aA{xc?% zRs^&+{d&l!Hs6@tV28b4Gp&_mCY0&Zs#`=7JjISkZ^JEk3o>RGxW49x&`x1*sX_xe zUho*`K%yc3PqmYM)X<$hVR; z^%rpF4hW@2^!QUaD_U!0^2X!)qhGOX%y7kqx0cx_8UjR{RY*Y{T9ic%WNrJ8u>Q@P z91Whhsm8n|%ws8RGwuevpA^;wU52n=>zVc+EOr1S@Y5q^yWvb@PAXlu7w|ENs|;3-iY>(3;xO7&J((OjWWC(Ct5#i6%LP5mEQ2wi3^OdA1&|&xtdQX- z4zHqWGByM2DGm#Ww-XLyVflZkVG;r5tEB^Ij1&HnpcWA3lJO+m+!X|-pvM_G%zxw@?^<-$88PM0*a#sHn zptV7SMGWD|PC|AAJAScR&TZH)vu256(ixR~px`O|&@=5>BO%fn(pmTi4386*~AWpTY;>K5&ElLIW6PA5U6HneH=n4|y&Agf#G!Vxnl% zDC;z!C7VVM)42fv2Ea4`Fo;o;2KP@x&Z+*uuL_?xPUFsD>CyZ%T3^$jLQcX-2!AF5 zcBhdjp9OYkY)TNW_u=ic&~q#et0j>5+K)>N$+^SP(Eio7Ps<^q?jZTBncSJojCzSU+r5Ol0Hsik7SZCF)d)Hsh5|%1O)t4ax%1g4=9lwL4lp=SEkCm$qrBp*>N;^ zRvQ;6$=|=#y{@Y2pLz<1sA$k6S>gEAFh$^9b$SI*7oP_3uKiVsP7<3gG_)dGmupQ zN)e@TovM7GM86CkyiB6sgPrxx_&^o;yswv;FWe<(BuyqsYIf7Ug{7H=1QYMa$i$}@ z$W?4*#?ur-WOp*3N*LH#$Nv{Wd0LYjbaOF8G!G=7dxCnAvi{+V1^HKGYMeX=Lb8`g zp2)~-x{!A)U(B<{@Grn#=&J14Hu0ycRkel_u9-vPmac^blY3Z>K45wy1mU=aTRxoy z6;S&`A^sG?p@Um~odq@88p#0#V$Z(6EJ(55r`MzU;&^Om_3A(UY@J>mh9$ayMh=F~ z3`(N5ml+WW!UyUUXgTZNzkud{+tPKf!Rd_*sb*uweeDmIPvm*%?j{#Z>v6;f+X(oJ zTTiq4c8|EVIem~1Jaf)Ul?D9m%sB<^iqVVKLC-bnA8rZ9IVbv2*biPQV>@5N1qd}w zftiY6a!qyEnFvK$;gx3v*VL0sTUkf@aygTIGQ@tIw{O0ZDfPoC=6y2vO0HY&GP|>n z3~n8-XIX#?bwUYTK+vF`#Is#6pabRWG5u`vdOis2*ckW*joH#)Q)Ja0^&!NxFn z=vk`%5@SY{%8j`vW(2z{jWr}m69dCYRvPbT-FW++l20%wqD{KMHO4+An^iGHh0UR& z>>olbUnOqNSZ;L(mKsys@8~`dWU4Cv*kT(Z zX-Go?@5pCo=$^RJUGKgJeDg^4UtKeGT6tS8lnPzm0d?26RT6l0;+@1Y_pP0&deQCcCb`G*cPHwl^^sIj8<`+#@y}K3QG!*8QkeF z<4dk+QWIL}R-+MJw&d%2(szZw>&X+7WFGHV3u>?U)zWyp_wJl*#JBkHf7WzK zosntW)i{ZeIT{+R(v(Z_lR9wOnq6q_45Jqgida_qj*0r;8uCAbF&6)1DleGK52Em zT_UBT==wbL#(mhsuc&WN5%DLpg>Hf^&O9$ci}}x<(Qo9xQ9Q$)2zsV{qLum;G-!Kb z=BA`nF_or6Q2*FWg~akbK8|lUjZXh?!|y!5+xX{@cVE}#;(rNoe~Njx7r0->D#@Kc z_)jonOGDk@>w>imY8GK*4;Y(4kDo#EjU_)iI5?$=h|}F!xF9R7+~Y>Su2HeC^=R}+ z(iajJdsptpLB|63F?jJB8ajc!vCx*lC0YM@y`0i`^&z&S=i|3w10Zfx?&b~4{EE)U zP5sI^G{-n}W35ZXL1{ev6P+XXm`X+TBQ}K0COUoNBFJdA=yaUPIljvCckQKZ%3Ae? ztOOmd$5+1nW^(tTaPCJ&UE`?yqF?lJ`QgGJY4I=P{U4nX;m5P}Gx+}vkUaR@*{&hy zwB;HXo9s8SFwgfU*~rQ2OT;4Io4Z#MjZpVes9WJr1QLy;RIiuSpr?2IPOpvssPFpK z8^_%;&jq46@akw+l;hmOyoe3+yZPU!>=&^La^wdB3%|jA%H~+ss{w;9nDWr5X>l{$ zhuOIViUdjfv4iK`wy-B-op$_rn&hb$WG=%5m-HspGUF8ZLo~@*;8OE6wz%2nkco33 zmLY$xiIJku<4jG_$LL>G^$1f|ls{MX2=+#g>aRur?DW6AK#10QV9i9Z{(kXgX(%P1 zy-H_x>5bBr2&3~y5@pUW-N%aZ#{V^i8vC=^?518b_h>>^cr@)-c#J{tr;To;zdU&U z!}fvPDPjmp_5KAOawqcRP&6~Y3JJhv-tzQhpB&{-_4H^*q)xiRZ2#}G(f@r}|6`a{ z{;Q+^+4cWrghBr~=>MSpaPtotqgdzr5Rz))D~}}V3ovv*R3J%w3VHTQKBIhD72W@z z=Om}|gfOwcqQV=AD>Sg)Bgvr`t5tFT%ZuY3tQS9e+PI$ z@qT(++MTL@2^z^_6#Y-D9G@v()J5OBC-DA)82PUiUgv|r$b}bwcbfHkJla5Q*k)!p z^E{0;&hk0rIVS8n;oAQnNc;u3*cPHgl^Yc8_c!2Q7t=ph)jxqhR>U|Oe$c-yk^dkl zx2|`zUjzmD{SCOgb-lBl2NdV`H{i-vSx5UNP?X=_fX7>9o$Y*}WWT=z)B9M$uIILv z193Y&;9%Z@c#YUe+)BVFIKzqSkbp_-5pf+(EF~roF%5Y9wEvN$#rl4`9n^x@M;Hga z+ZU>JB5Iqg#SdY!VX1~bE3tk3^}!xc$es0%wEPUyT-|~J3TAp{iW7Phife+LTxo*l zTvLJph`0Guj6TULj+s?|4Lo(~bWy2#n-_fe2f-mzYP*`5|3*=E4fI|KnW|dx5Bn(s zs|3Bm0zD1O!hT!HWKolCO??1C;L+% zT7e(C=_%#D%>ZJoRSSm6hT?*!Vps6Lh4L=7vz7Ah)l5(AI&~COZ}Yql(_l^T)W1`P zgEgU3`nx5Wp89nTD5(A>tIsjjS`b#r%4j-h6y}U)oRbWJ~k&#?N|3gTt zMCAx$l2}eb`^9CM+demIR?B^NG>4r~C-a2ZY3iW|dr#-d+vnp;N_UPykh7u2P0A*Q z#j{pn=fO=3l{P)%bzSUvUxm2rq!h13gkjo0#eTdRcg}^EI(@e*29i=<}OS<*z zUDnGv%)I~0>c86Hi7KY^iyYy%TZ`N9@?b32qC4V=_Sd0)ZLGa?D{(iTZh?pDiOy+h zwV;#>@|wU-P_;Hmkx%NcUJ+*4y!C})af*x4_HfmN|GUuU3Ahjze5n?^s+i^#eul#H zG)2`PQi-%mh18RSYe?KA))4sb?r{rrl_tx6q^*em-U^ooL%Yzh9)`Tk{`?fdz!@G^ z)i5|dJ-hC_yXWb3WLk&k_)A)@VE-IxtRS=c*bxjkN-VP}b@?~e-KB7!a+Nyitf?Yx z=a~1B4gNP7Cq-TI z3P+=hQ-NBPp@jd#C`0>!WYgM@t3tlNg^)fSw{7%GH=2TKLFP=ijXU}@b>dmwvO60E zo-}pP-I!Zohm2J2-fq@M$g>sYXU0Yqoek?`cRU8i6`i9S+*+oM=Qr0ftGcPYgQpaC zIWza~)v2On^)~5zXa>PcsW*?218q8Yc+byLy*gWROz|B1oN6m?i+-zc3lzAbD07a* zYFEGPTZcM>nS4=qi8pDPdIVH{O~=Z5s#9ij;jQP#Zm{%HYSFf4j5q&kZQTEcruP92 zf^)Nr`n6-k)rQ2?#Xx%x#z#K-uhOp*IB05`BQqs^0!)a77;n$=+)y@69l!c z=yO5~ZkFl&e_o&@fk8Z;+m`vXYBx8U)^STV>6wp}hyOsk+^jWdx2)%R&EPRi&rkU= z^FWaQrK9&JseXPHjN8KKw4_>O=Ok~4ks%9jLlqMhy}GyTll&X!UWdPqte!ewQdN{Q zXV~~Lr19hQm(2J3myryH922`oX9AE(z;`?|VHQ{!p7>I3=#K(WpO6=@3il;H=*2 zya|KW@1CWvu@UrrAXu}+d32krUZ0)Zex$E`To$Sr#c4Aw9*S}cHez18p6Qv|%kAy! zo(esp)_`fQ@{1vqbs^xEtvj*j+T8gtZ`E+Df&mfk^aVF3s`=%YmwAVr>y9*!4_G=t zCD33R4s8`}QEwHwGyEe^)uh!uu7evsmn480*>j!T!|5`negvQKV=_awTq@}a{?Dk3Acikoqzg_Ffl#psV6Xv8BbL~@R zn?%z{DC>AQv>B+{(mi!=UkV_q+vzr3ACX&DJk36~Rb>+l@O6AY%wBd<9L6AP_2p)@ z+&eOUs4u_YNUu94oD}Wy@Y<)>p{wQ1MWL))%v?ja9<&rVyRL3#yI69i2S;p}$Mvj}Uy7#MKNf9Q95~MV6-1hb zheaBO?{Zyt)B0s6W=-d>QQ62MA?3c5W*MaG=n_h$xf>*ko6!rCY@XGqjANm8Ub!H9 zsz(o;Xvwd;{y^oXl)J5So1o9tM5r|et^pYTux;|QdMV>B&ick%xUzu3pmLzVz-Ukh zY;4J|zWyL2^@_%qQe-rJf=mvBrk!0+De53cw!y01-)_vMwdM1`MFZxR6@|4G3@uft z;e(7fHW3Dt^EpCqM{d`>;qx+pVfyZNCq2{IhZ(LdUtK?7@U2#-=M}2#}ileMDsuHNNq@A%<4jxlqKK(iZUW7qP5Qt`J0OV7mKN-|kMDV2ca39wm0{+MIa4 zn_-#u<{nFedAjomC!ttDd%da8f%y&RO=JWzgHKp_U0uOn*WMLEo)S>(uC%V@lOXyA z25#&->mSOv@lGH?jlL%llM;da;YA$@>sv*v4@C@aBxu)Y`}mkn5HlFJIHWzYr9>Dj zJUlxZ67;gp^EJc;F>u%$Osy*k$uyYQxi+XQF>()m3&pkIs}EQ^hrbJ=ha}zYcZZVl znCA_&8I7Ac1$RoFFLm4Nr#WbFwYvpY$y|hs-Y{TVa9(qA&!k0Dkric?tPH<`=t;NY z?5LDmW^;=42QdC3oBe}Pt!Lhg?>G;z8c9|nEhvch*4d;_u1YRAhud;gzA2lugQk`$ zS9i+@?pQVVSKFMp;&HQh^@0QEA-Eu4c4wbVIn0tK=9N0UDzS?#4Mb=JFF3!pEIG<# zWJ_OSwRs!sB}YyO5SASn?YCmEJjGBwKe zXPUA>L$m{>rdgGe-!fgg^pW()c#|r!$FE_|0ArKgS-&p>@gzc&8x~{yZTX z^KrA67)tO&rDwva@uE9Dneb48^iEGNB#gjvhy+?;0|-?f4{Ulg)&+oJJbUzq^RHV1 zfL+i}9i79wYFa@uA=G!)_;+tor(~@(8x9^QO^)>)qpkD@bku^h22!ZObsu$$i>XZo&A_(ua%RD^J9&Kd8!w9lF zo4pNTgmBxvWSOdH_vsCcdAqOdR8&9P_Wg2rq*n(1A8-FnR#T+;cQi8 z&QfD#vOAz&crfAAVJvVk0%s;bL{hwUYGqmXn9xqUk7a2u zT%O2qXbt^ji0U~d0^UJJByb#VcYLSDdoMiZU^tq7`sB+tS>wr8T||=qxnE|o0IlAyg6FK zc{g{p@xf+{!VQh_++hxLJNt?FB{t8Td{@IHXTNxx{1;U(JUe6;PHnL~kuA94aC|Ya zbM0%J5JIW!yL?y8B;mAvbP8h+;xljS8`~t-s&@x%!oWdZEwNPrUKIt&AfCmO?SL|gPYK+=yyAGY)5+RxP>@XG zzYOuuQ9mw&D-c-@MNkcZ+q)zS{d4Glj`A@N48I|&A%jScm)rrSXD9)@GmW+erjuQ}OYpv?b6vZHOTz5c&&#Rp7$%4%^z?!!by8kwe!uL@ zHGCk@4Spx?LJU75+lY;eet-V9LmQrczw|SFmcXztGC{ZP$x! zRF_uWLJ^j0Za9bZ`rD~3_}3le9O=kyuI~2i=Xj4D`QXw1?kS5qUfqp&{;9(F9M8uO zrm%z#4z@E@8XeQn1Gc=%>@#!UC~W=ehna1JxwZt-JyJe|>x6v&9&)Hb@nwlicBQ@U zk$Ly`@kZ)p){^X{m&GV`h06sE54-rn0!%*8~Iiva8#unqB33^4z)v{-vH6Y|aI zJN+S~mv{~jLIG2UW(Vj_vO}P&PvO&hiO&dHD2ojEx#KHUGU3k%yvG-;1QSRP6M*Yh zi02QPP!wE63_m`E~GVA?elEJPC|H z-2^@$nDA$Z0q^|uDrdE@glJ>~p(U!@!F<}Ev9y|IZg+AMU2w!d?m6`U|m`?A% zxXI<&q1wT}aO{!^L?1;Wc&9cK$>Edrw0)i#6(Z2l^QvrQ?)kQ0sn&FZ}y`fn;w5shad4%nVQ z*ZT9Z9ge#$%%WI)XV@=lSaNz!e_Pmm+AqqmtICTCVm2G*fSo0Wm^ITFVrN+cJ~z<} zqnj(`dl(Nd%H=ypmm6XSSpzDYN{7&ee?BtM>UD$&2fi;zGAxbLM`mZIx4$u&%=up@ zn*W&{77XqgGS-XmbzAi&2x+-;HsB1FrLpG(gnK8k*Y*sA9`|F$HZa}Of7ZPzz-Hti zIJMM^(6nuM6Fz$&gf*VAC52Gnie_w|rAvZPyEBA+ShnPkpmpJn?KcC2Z1hO-hPuyy zhIjL`cUXmBNff;*X{~(v9-mR2UBLKw^0nO<@4X|ILTWhYuJ%-ATJKS^mdk*=x855W ztr2Da*GEu&&YS2R<12a-*F}^jU;DPYHG!(r;I43{uNxFSG_v00-=|yZYLIcfh zN!qe>Ig))r_tE%@3lo=KS{XJ~5$d0aSujalZDAa8&kkLw?myZBZ!=j;S0Ccs&CWiR z{1jaR-2Gxq^bf0+lz3C>TVF9fGF$g#M|CMX>vRezx=g4PODaJI7rxW3O0^a#n7%5X z_+!_vmES}5z1HWn(p!xsw&*5oK%=*13+c}N$E4=Fp}cKVQz7>!N=7DXXuHN3YJ3e_ zt7J6f=kl)Lm!tJQjFpu8Y{3jyWLxR=4df2Q(lB zXu5^ZPd#^TO+_>5nB7vF7@S|^sAM)I%Dl5PRHbWWP+q?Ilt6dWHFK-!dpsN55<_v} zo;g8Z-tMLefv)27HLuy6Nzp;7G2>c4?~9%?iJo!?xEuq~im?;SN6o_-)!fg0dYP?| zSk{rb`nmTl;`fqa%EDKBqQ}G)C)I=^CYKx#CzZZ*R6e2vn|G6BtrlNA#E}|m8@rbA zpvGp$V`rK8>$oFZ&lq0NHbXYL#MnoyX85f|ehgnlNsHBJQnEh|Zs&KpS}wHRG#qjJ z$cx1cYZ8?NwVr7j=8Er`W@9p_RcsKm!iewoSUlVx?#XBCwtYKUYH%j|(|*)=dIJ?O zxEB;o`O>)i5lFmKLarzK9XPDp9Qqf<-fv(+@0$8jv_asQsP`geEh23V77F6(@2{1? z8a8hyHk@_WEv)UGQ$Ui&QY14?m1v|g`Ix!L*|&Umy~r;&K{$viiAFa&NvYRZ*xKz^ zdd>Pv(}<38m`$EDnOr9In#Q%J&XHIIw10OlIEq&jtHJPk)->q&q&N6^69^P9m=Uig zX)1l@wBMhPoHqnz=T%>q+Egg9uRTR7&q#Xbji`*EV3}~X*yz?aD|@}N9j4N!{Q0F@ z-^<%bXTt3tHzOy0%o(N0z7MOgt^IT~b1_9$=xRn&_oe3_15tx_yh58epR+y^QZiR4 zywO|fEZ&V23DBNj9Q^83Sw;5pS{0TPhZF(D&y#RGX>l34hGiJT3Yhq$OV<@P119Om{yIXJu;J@?j# zZNx8IF1cb)ptn-(ysbYJbmzTX;OAQ&({o(q5mxmU#Hg3bH71+(O^oaIQ0H`!Iisrf zkVXp8tB=jSqJ7FBSrx;KFI9yzh1oqm=-Zp2YH3ZxnH6838dtbtUpVdhES7v6diLUa zvC;MM=N+0Ke5EEie8DR(3h6UXYL1z{P7ff=EzPf4qQ$N@VREMtB1-B za-N&Uya#U+oxC9@(23fWkN`YHm)y+a+^`{g{kz%&RiT^d##Yg~Da2M)_6q`X*eDhz zK6u$2iG7xO$~l36fdt&)bU3AvZ$zsW%f+&mvZqaMNe}%TVa6;{y*h2f=i+-V<7A=VLx6RXNt`>x9~>yOouVuF`M~5ef_gY+DIhtmc(Sz z;cUm%9;bSTr#%+P5Duo-uRxl0TMF#kb1NHFZV9#MfW(>Ysx5^miZ~_%v#;M9(i;nz zE5T-MPDY=J9<0>qog=dTRLDv1fSuuO$CVe>0kyA~^ggyB1N&~>N^fK9%|oC;(Jcw< zeG^v*0lK&CXf!7Cq*~)8VnW*Vd?(W@^UT7`1a;{T&NbDdyMES-Q|%79yQ{a(vEtV+?g zZxSxRb&MXby#4G;p|<~V&76^uvo2&taF2(v<5fCO!>13R02VckHMF_!qbm+elA^$U zx%QRc2yY;_6>q5_ExTWg^@kJ*T@R1B7LB{H*>xMKmLE$(;zWB#UaL9c%Cum%$cH$O zMCoktF>SE-L6A)m@JOG9b0lw6)MF}uyQsT1>iJWmIX>R>G&izHxHvhe9N`r}j?5#` z*Jofb_vtpQk^I=Wd!%$V!@#*|mg8Ky8b?WVJX3xMIVquxq~Xn}*=e&xbpq|y)kr~W z;TzJ=+k8^qWe?ffI-J4AYOhfAbwT2EZjev4_;5cN-v5L?zH}VNfUp=s+hhd*o* z>Q=bi&VDL;d0Y2QsJ4A=Tl;V%S)#Oj=b0lg{;h!(ee!iy&IK%K!JJk$YEAdlx6=`A zG+x{lHaZ-dr==+e)MnNEZ|(5NXsRiNz4L$6J7{>wna^vc(mdWJE6?t%xyX_{e%g(b zx2SffHq29lVwpo_erUJstq8sEb!nCGjqk;`sr<|AE_2>r6A=Pyi@19h3Ke(?3oUX~ zNm8x*lXfwU5_$Ihf8bYB`VT}h*&hIoG|DNPf`90(u$?1PIAXmt2K!x+>;gP6u5olF2oj!w;3AgaeSG*>iGBPABx1Ms}cIEu)eMbKL3I6Ai0vhj{7+d8T zx$0<7&~!^zu+OIV%J-UC1SFnFM+cr=sM;TOc)0W}UPyG<1YWgbF>SU@C>S2D#g7$; zZ-rxN1ObE-V}_ z4OreZ@c&@5u4Pb196M~SvM}BM1}-fz-fz=_*AaH%?@JFm)kW$EQ(y?FLBXwqzg^Q33(47`$<(riNWzRcQr zcqM`Am%^OI6t`e`{I9G4*J^F&Ad;P(; z=~t3y9RinBGY;q;1)Mg4kQ9TSEvdfW<@Wm)OC&UdN)Ko4)ppZ$;avHRZYx5sSmpBS z1@i}y1H(L(dnt$2?^Js7op0OYrFS*dqSJMUZ`*IB9IC5nr0Y(<8d#IwbyVvD*gN)^ zlxj_#@5lkq)0HOPn*N459B?>qeoVurTEYD0(W@0~jrlPp3{ark0Oiaxh}o|K_#?2I zI}Ts>&Yr6HUy~hG@iLuhKldjU?mdWk)8p0Rwa2FYZ!&U)u4r4cl?kI;>JbW&e&fSH)ZQ6Ewo4XGeE(W>O75fJ)_Ix>1b9)u~Zue@R zk0Jb9Y`R)t-nn|d(@C`U3i|Z+NwjtfPIEBZa}VLd#UWN* zvHwT7kO)1*6o5)z>B&Ai{~zg9wZjk4ArCY*mB-lLN2@|!4M=G>P!>G$Y_H!b(N~ko z4tnqoUb!>5fK)F?#x1d&6vRXQEIW~uS+G(?Vn6eM_X7MBUU9%7a+f>1Yp~eYJYYhA zpUJCKI0nO_=0V-o9+UTkb+s?!@Djf!*x$}{Jv7L!` zv=cMWrRJf4!@lAHlVRq+2c{^-81k?@VFwU$rFYpxa%ApBwi(8M7P+-VBmxxlt8Zmul(U znMr=Uk|b{DYftJg1^uODe<}Z8>eMf#_)DG4Vhiw@L23i)a0co6OR4=*cE6PIFXjD9 zT|`8r_c@$37;-@Sb=ZZQ++SEw)J%wQTDTx3U3_qg>LI=D4hjEz@dh55mM76Dl`AJ( zo&*8vS#k!1g}?e!iTMm4Qj0I5q_~LbbHqWMU6zBxDrq;~`v{Vsc~&A|ObsS`;B{6! zU`zuhd(Qi;SU~kll+TSVS{qzNEXqe`i}nG|>Iuh5%?JoDHydmAQ-S%s2M-jpABSHL zxT7K=_AT`6F;S>8OlyIA{rvGDGpQ02U}`Ep7B({Xv*d`@_;*PQ!_N|2QD8byB{W?h z9S77vm!AoE^-`Qpwe(mQvjhx%)w=PKPX{&lQ(OJkPkw9Q`!&Fa^1b@4vrx)2$ZH5H z2shg8H7Ycn4y!hVP-3k+i{r_*z7%5~tly=oc(IyL!CxY&Boh97ViT0=7DPK72AdUAu8R~nEWbF`pMD0o{l#| z(Za>x+^H#bSYAO@XUYJF17!RTta+?j_eW1B&j1IvbKF5hs?QXkH9a^WV2=yYRdk`o zc=;1W%k5ZRGs{?Bk0;d{HvAG#BDwf)(3QpYue&LED$a;5y}W+8O!PvP9kyMw%sG~J zQow`KyO&lo<)$3>wu4oHIY}3v+}n|Ygj?mExFqJn1gRK*ggoq#gzJ^-NvU7eGca$M z-Cjy@2B@@2TyK+bmBEun7q(!~qAW67cPj?fQzhVKiKv(`ix;bbpI2=SBb;sux0pd{ zG-300IRM=oekar2T1nC*EPTaQS4omx@x-?Nrw?cE)N2qV=ANy--MDbLy{;rl9*v$t zf_Y>mn{GYYbhA=&x=YdIlOC7Z70pcBca%bD@6_@FOzl^nj#7!I>pj9HXTK%ZJDZtao4Z2mxNu!Z(79*IYHn%OV=-f!qsZd<=g&q97yK zm8U2FwC$t&$>=o0Kv8-n$&|~DEH_T_O(5fED68(cwW*G54xPzz(AcKis~J>=72C-* z1ylj^|H}&ZnrC4G%B0^f81LkGsd_0d_QQ0su+lJY2QXbUc-QBhUsAL^m+X=i>oQjy zki{m=mEz^VkBCm8)vT?ILaAt;<)0c;gmLo+(>t$oSHGlhim0Ndo$NR_+hQ6P?z9jL zR67m?mr}e|1pvpT)5NWv{i$o+UjZHrRF~0!HERLYQ+car`GM-)^pj|Mpn4DxMwEb- z(;l1e)wm}fn;%WG@&RU90aYpyPFR-DoLyA(igZ~u;=tTqJUol=_jrLK4LGDcnQMC% zF}cB0y=UYXjFMZuSlu5b(&52%Z@<+b%X(SC;JVn@v&gUGxbG@p+PoSK14PTRU(2$S zGj}zD8qjgOH(X^P?qe9fmyIUpNp5aioFB#P%U-h9kWzuQPmR+nwabL%*1|foZh@{I zZiYWLN{Ld4j6U6R;&z5N$$in2m!G^*SXSkzg12fBjx zw}#=O7_0)Gd7l))w^XiV)_lH6tk47$$)KCAs6j0BuALSP_O{@CTo-NUXl zL@1DkD@<}FJ7?XKKNrpGtAEuRbO&zdaGxAO(o$xG{QmGtdA>RYZF_ZdLk4%YJc~%b zAo@*FNrW|NPI(o4fuDn)czf>)jBzHmPcAGRIyos1YwxK6M{Hodhg;Kf;1`OE;1>*1 z9)78b8k>FR?kR~#t=QP$s%AUqxqp7Lb8SN|s|MrZ2|=VTY;azzj+>YaQt}+aZE$7P zl)3I-L!_E*0u#1#cY`hq{ADWsjet_oYN3#l=M%jBTa;#rMKtXshFGYb1t!4V<54k0 z3nIL^F%iHBm|l+C3SkH0-7lUY$~t7g1t6N9!)_*>fJ+)55j#WFw8g zIxRwRU~z(jr#eko;TT-{&D7n6$eAIS^5LerRJXMd8F(|O7~{1q8FQp zw*|=_Rv~_|D!P*u^g;{1VlgYZsRCYKRMX@ik402sWRq&Fxjl;_HxWgScXSkr!Zs0p z9Bf~#dHrH->~)`?x1#ckT|$kZ=?kZQ#lY9-7b{|SaI!x?^pdCTy=x5qYicYlHN%~~zfn=k7` z!E}njQvgs0Vys7l>fTjxoYGf3=P0wl^B*R0|0@#-ve59Z z34XAhl_-~$=zgbW5^FZCxXLlm2;wS;+K5XP8&u}Xx^c|BzZ<@ib@YH=!(BUE3TRba zZuR@fvt2<{z*1UtNn-nJF++~X`O+d09dUhieWiz-JG9X6`H@~fg3PlVr1j|{ygx*s zOf>ad?sGoos(z!(fJh)44=-8NQ=V9qha4}ruHGNwfaNy4^5%##uwE(|bFOg#3*np) z%^n>PdtSzqk%a@X=k2$kDXME(+pT{Z8Px2_A|KR(un5wR}T+QBT|QV z#W5_tR1I>Flr1yOb`kqtmv!y+BlLx?73`p(mon6u_u=AS39DL?8 zepfjQoWADpiiAA9zFrB&6m^*N;F(}_X(=rS4#X#eg($$#@YkprqJCBoaX6fsV8Jhg zg$DtI20&OVkrCS?s0mttbvh4VtqfQvp=KIVbPGpjv3b-$>>)b&+ohUy=%RH z-nBBx&bH)CGC9fKd(L^KN?DxooBU(hLXrmiND~~UZ*noa#oG{V8a6`;BlPJv5@_70 zIH@Ua7{oYOUjPdw+o21NU9j|GY_*z(eYN1NGoUjpZ!k_RpH>+)sQ(o`2%}ezp~Gwd z(QCVc3R|q{zmFUz?|8zojIP~%_ZWYfn(;+lsJzZ8wM(4)(sF!RcAK36BuBTEEIBU8As-H;n$yQU2<^u-4eNPV(Ab8)apzD!QjJn__=GQwr#ZqSr<#CINZ&DIU zxEYAO#TAUkg1ETxX&UcQKesi=(78BfuoX(vxtLcSL1H_t?z&I;Lf-Kl zdDD(zydu9VN1dI?Fmf?KS(ez@=l|}gD8NkpJW6Ol5Tjm~v4}$g;tts22E`|Rvr1@tTaPE3V z+kgSkA_MOOH?{qT%m6S^8t7k24j*R>PSdSV%_iqf|1arYB&f%xtNdRQi%RTMQU=mX zv96+imBRl|+UZTNFJqe5f$EXPOSCA+zsKC&+rWrjr~<#4#*To$QW&KUtapUIEtj?f z(yZ?r6Ls`bmv35bw6b<_bu5!1-DHKz9FULoUoDmhm2|B@#c|B<=f3k^F`djr|`Y`iIuFTXlq{jSzI zv#}%kad37t)o*P6(qFirr~j80(vrd2AHoa+|5wMDw|-TTW-x<3K*{kD{PIKkrJgOe zB9KUbcO|F0mW-57@>ntaFKr52_qz|mjS|33w7elaypB?~vu5ew$=IYYil_& z+MAZSxq3cdzaZ1+s$H2>EUfi06Ddt}MmQz&mtju&706_i_pRWWiU^sv-Jo`I(T=H|#7(qhZ|+9Gof-)m(;JY04zg zEw?Gnx_Kq`9K`*7tRonfvY+{Dxwc(oKbw?y6ZezMmp#6=T*`OZAkNK~Njk!$aW({n zaloa?`X!%|+;1#xgI8$?1{Q5a^m9aVbV$~lA@Tiq_$fplSzK=!uz2y6tQ?f5aYZwh zr2`vLo)db+7YWm-uF|UPn}O~0s`%vblNF-GG8W6;YkC&T(C<%9t6kO$)z|fgiN_aR z?G-naDAl~q5H83S$SR>DUocAl$RPoJy4p7!<7iT3$^#m(P#J<7L#oBsHjCGN_PNcPf?cgCl~1zT*D zdYvrICWP#yCCD%Sqj(wLiHaW5xWJF{n)c3|HA)#D9p4}^R6(w5aqsalhP7g)C64K& zu`4qR22`FA1tjaxMB+ha2!w-1f zU;uaRM(jZaN}^(#cVa31$>%bU*7m`;zk^>%O|2ap&OZ;n_P0K&0Lp+#RvqhLT2t$B zfmoH=*%%d-t{BYxtiQ z++LLqzE<;(nkrLmoBOh)ZNKl4)}KOD19Nb4SR%RiN&nqf^s_JK*?scN43zJVWJv^l zBg5jI1FK;h^oKnsXX8UO(GtgS)%@0M+q^JIjk~{PUGf>B_R#k89RKfklu=X-QT!`W z3zEN|?_j>|`V`Qu1tG6! zeLIkO>>rKrF2NRC=)|s zKrYoY?dV2rfY(>Zqor;5U9r$H0hNf!Ebj{U-#Hb}k-s=oA%!H!A|{UKR2cJnuD(pq zK;?QO;HZ>YmIDt9lx{~dU0N5`6GYT3lI=_jR~KQfRgb`5;$O0&4t#~KTB@&rXKdMH zT(z7~SqZr!mlMq&1dI3#9vZDDX|z)=y|%47qavPH;PrKV{+)GhD#V~bB=yCdko|r_MqWr; z+p!Jd!_47*s{glId7$Mss8`J4=pPNugHdX^cQ_GxYuF(RneFg2NxL8`Y+ENs%U)0c z5)*jj=W=&s%{vrKLI7vgE8~Wl1>^Fq%O%)UCd*knSCe~@E7rAZ0@oM!4IcLe)%aZ@ z=U#JL-X36x)0p?3EfD#M_eO5lF#&Nt{|dikf?=51N&0bFtspO1#~QDhUf(WNLS19` zK&?+0C-R`4#X?LjmKl12Q%|j@1X%|@ty!c^)q4&`>AVal>Kk|$J*4X6D-6nL0J zI7SlPIgNm=6DX1iL^P1PcI|=wpaqW$0{y{7&K>x#VEV5p{;!a*>^%eT4=->FJmhWj zlBU*KIo!M)hLyj74a}cJq>Ni?3iXGtIvAZ|mNPw}GS4`wIxSs2;5gsfv0FNY|3NsL zWKcefe>lRH5=`;B^`<6ivR7R&frl&0U(zqm`sYuUTJvJc)_5rbe8t{rlK9#7I5|af zlm(AF+#Eii4AY;Ctyyn+g(~~%BpuMq+ERk?q$NyHR`nl(>mS0u(Nm6$zYEqlezo}P zGvm$3)xu9olWFAK1@WclMw&!^w)YOl@f>!5*4#sqAF>SpIOt7e{vl-lU&QnOA>99m zs5FmJI7vUO6Kb1fqkq!A^I%vN`A;jhLy+)T%#AMvJJ@i9={8kUf<&^0xPE0rP=edXnLDzB9?evA73kJJ3X17t=_@`%T=`TNxF%R8}uL30c+;D zw^$7c%p=&urY`0Oo9ok1DlhMtpo`b}n{G%SO9O*^PUz`F_B0(*zs|Pe0~4mLcl2l2 z8t>BXbB=3{r!nVr`Q}LnOdRi0whol1nPt=wqjj>d0CP>&y#X0iab=peeq)!oo==B)DCA`ki|9dXr}Y+2=IhV1O3hhW~1r2$<&m@c+c(u&$H{ zUgsQ`BP)&#;lMxrPRfRNu4WuqB8#OR*djMDCyBv7L6RuIQtaOuMu`g9893f9c(HVM zB#D3s+J6p3{<@5SN17g6%3SyeLO##=wYS6U6qSw4jHAEqZgI=W-~sn#ALn3#$&e&? zBy|?Rx5fvNc7%ZlTp_;tiyObRLMfT5xaeD;Bay#0&>^2=^5KyjrZzI~PRW7F9GJj_ zAx3lY`w>rl84FUNwkWNp7LQ2ZGp%04VlT$3e8u|IQsyw>?3|cGFrbMhTqL#R%y~ui|B~w}C6*?p1 z))29-Q6g5!s=f!iYU<@|R^%UpNtVr98@9v-&8Jg)Gf82@&j zT49D@-6X1aB9%;6TVraD6Cl6jA+^}Njd!)mR?d2it^DCi#Y5DwU2f^iCEU|CDpyEJ z0h!;ri?@Aj+W#Q+_i>sVpCR=Z0>u?l|29yZBK3b%=5Zt->Z%^HA}5M=F}9NCR(q|& z+^-mm(FZN$&I1+mGZJsY`$H|WX7nFX9%IZVzHOmADg(s<%HuFlY@j@{r5@*^|5p9| zCyM7U%ZdcSO6HG8qQXDgE$`_k1Pkw(zCRYf`ztfzq;#!LY^<98X9f_v0hE|de7gXY z0L25K1Sni@|199>6{4f7nM}r8iBrrbB#oq!@mn{JfAsLRWnsN9uG%*X1QjiOA!&G= zI+%&3T~GF5lGO$erW~8bE!{1AlOELgrp0mn-E!>&d?xQ9M)oY?y>GF)l{A;$Op~+G zT&f@+a+mRs1QNKAPCuJVM)!gIVq=W+1~Dgxu)@56`LP| z{QvgR=J(9sj~6%-=N}fu5H?l4A5vcJL#MBspv2$)NKbx~=tFaNPatwj&kXJRQb_4% zdCb{V8NhKO;K*gwSl-&K zVb%>#np5dd_@ckHMOiSTxYaQSlKw{g+F9nPBJOG^RV=J6+?>f)C3m&D9P_|gsQEsZ zp9E>?F6QyIVSxuWj?sq-x+f)W&r;JT2=Wi1Zw(D&hMvDz3Y9dlF4S?6Q|eRyyRgnP zPHpQ`*7)=OW8a|hp9@XK{la)N?i&7Y!C2k9!X8|oQxgJgYW|!#iGgfnsxBX*t11%B zxVPU2^v%_ve%nY@_FR!kd%zTUJL(P}affq(cwReGv0t&3lw|II6_|60?TVBNF`|AU zS47%+X7&f`neg7e9#S5)82ndBl^I4h!=Kw+aEVCZx33^SpIPF|a8sZAk9OA3;&j;9 z;VIjU%~m5Q!{VdK3s1{ZPF=3j;`;PcwvvNVV1Ii`UUYxOlw}yI;>qC)Y=oKYR6JFp z(~e$fWd9!f)2pJMQ+Ifregq#kUX6f5EACjPvVVK0|5mFD=zX^fuY&magBc;h8{8|Z zT;fwJzp&Ff;K+N!3ZMQjh0_0l9C_pmK+%kxQ89CU`Nb?Mb$Mb}58wNSeX2&}7s9i+ zdncY1m%qTS`{>)~yMf0BmH5O0)Xezg8`Bp&fn`6p; zlcQ&%6()9|Z!j>zO`+?DcRS>nesp)sR@55MF>ulSz<2er?OO^WOl0<3e|GQDhs!;Z zY|m@41H@agsaTqA3$(#(Rc!rmT7t5GS!@No+wrEfBd?3oH>g<^Hz-r*g=m@IkhQbL z6IU*sI}!Hn%|&tXOj*xCxUBX#aill4XwTv*Ru8N@aT=V&tvk7|Gfl92mE*%Zy+Wu7 ztE#I0utW4w-MQ9olrsbU@rGVqqBi=BT)M1|=;E#RT>aHcr)FnoE3j^^QyBd7;dctg zJpKCU+h1{@a|Tl09p#ZPTp$H5^AVN^rUa%)BQvZBG1MiWbo~*T zk|t_O%c|Qh*q$kx$nCh%DzDTrygRtod^q%8g9&SjMFg)CoF4U}{Jg{?KP`{vklZ-oYkc_CggG4QcLBcJog~$7Tf( zBX)>;9Xld-AjLojOPN&iyYmO(`GOZr*8Gl%{P$UCWJPkYTNX~ljognQO z70+k2{qF>+Aw{i|`mh#?XznR)-&Y`KhfAG!Zl_WX5t1{V-0VBAvMI+wud=zcFJG6c zW2vtx`X@KzdZ0ebZu4@vz8$YAa{E}?Xt*~>eK_wiU9j3ypM`xj-x|)7Hs(9qE|WHf zo^59U@XodZUFpj`OqbKNRI4yr`ps9wItV|EnGsn8rr83CY4)gT`y%`B7glNeqGV%k z1QlvNbMzK?X+~s;_Q8dbw^Mz<=A%Rl@?a?TL{b|7g*f?-*esa<1y4*9TNcf4bZ!Myhx(Pd9PrNrH6y zphTB2?u!}Z_frpjt1c&z`0Tbpnl=}Y7$C_3B&R1HH2^p!*iC5!>Jh`4wD=tGhT<>K61I$jV&$X z3;r&*X~}e(<@Wz=E}z!C@YkeB1b7PXZ?)=U?iGwHf1p+gYau$QN#&dIeBRiHFM;1|nYa!cz#iP5`)>2Pz6#-^*rDm@fy#2wQ z!eu7hPq?Eza3)QhT-{;u1-wt;=x6EQwp@cBnWY2`Y=H#-Z zPc~2;yr74q`_G>~2*e{ICpn&P1)KkPORbL1xUwT^y}$JbJ8$1Mg(%6Qb;`5VC6K-9Hc2b}Jig2#8k zHGXQq!6i9!Gs@2eXJ~m4|35YxfK3}XgO~1j(VHzpfonniL8-nK^FJ|<~JIYo9-6>fSp&?tO*=-mmv}_v+Nv`alQ#% z502v(WKh`jIE{&&@ye9!$N{G(fb|90)4>YB)fqn>te*H>=_LP?9sYO3`p5KSKKRG< zWE^;6k~y#d)W(Wh1II?-(0!DcO9CA7ZbqBs19XAo-@4!~H86BcK+mxZ^~vf3mn3|m z2$Impl_s$pV|Fg6C3poFZ_|a02gd!0B8J}nHg^<^-`aT%`@8T~`XSjQLbNp}I5${N z%rn+HF*6_Zu)IvSx4YA;A`!3ZD&8dfeZ0~{Lp>d3u#OGqhNUiS_PvKipbzkep62-Z zCbZN0=H{u@@ln;D07pl~3pXQy?9BVf$K_@DgWcvw_PWh+&Jjhr01IVxOgEweGyUAk zPTcdbVQXnDwi2YJ-Nh++Ft?p4z1f)_}lf?fI>Yig1bDF;n~6=H8L%a5Xc znMMYOqJ0i9#l5+x*}~^{Z~zQdN$OU^Ac&fHYz1H)MiLrSz!_AP%km>%65!H8b4>$Q ziOloqAsoYXEMz~I8(k|AEQ0mHeh*!jPzc4NKV0(UkqI2MhIeR%94w(?)gS|{b@}iS z1z=%uNQ>jaSmC+!|2HGeUb^#174#+@E@M*DgioD4Gi$(9E^Vh3r@3Z zFu~w%^d0{o?1u1ZW#R%d9BQseaskKcHkGyRJVEa-1VD9eEtKwlQcuAb z2Uc$Jqexiyz}>;be0_oh_^L>8c~_l-m%1%-x?O-mb_R(lH;j(j4chhALg5nathx6G zZrEn`S=Z07u;Esq>m28=dpp8VY*?z_Sgb!?Zp75b=K?SI1cAr=d4$=nqR7$HmPgH( zO&nyJGoW@uKug3KnLvYzdCgHP&mA;hJ8CThW9Zm12#lVauOQ?(zTsu6LJ*(lsZ8vT zrJYJ%IP{j!^BBf}(0xv+MK`)qp3mI%_Q*C?p1{$K)1KtR^U-!19;91J^C3Fe4^b}Q zCgGN_OIVsV4;-oRBMk1zf#t;ep)J6WFe1M{f1sMRNiChzcFIR@Sn6+SPRD)ffKuv_f1rz&gv&-+{b({c}T91Rc-Jw@?-5-c z)Zrc*D}1I~v0v^4O|9Y|JCnLABuBBdkXuk@`=}!D*M`LXjQ+K_H zwon3Doe}RP;vZYF$1Bk#lZ@liLRx3RTd2C~^adv3qP%x9Eyk?4a4-5+KBLA~_u_yT zeJ4uEAhj;_U|4pXBfLxx#N{c_Hj+ZoKK6sH`t8~x zsdmtpByZeK-g1Du(Q~p5&v_YtV>_&&T(QWk+qQ~;PJ_PetksGKxX9|B zTx6!e?#oe^$i?06+64fQRDnfoCG%;E)eUU1bb&2aBd{TR_p~AVee{(5>_Xp~YEL2< zEWUpU2vG0DeYI}bMTR7(k1GQ89Bn{BvI16b7hRng3|J$5#(-b?MV1vHDl`s=_CWNF zNu^5LBq>RGmVnAKc=8D~u;>;A=-lN26ye2dyM)L*u0KAm80527- z%<|5nZ!&?!{Ip1SHI;=7sL=|J-qZh#kML|Ak+st6aEFcr1E|X{Uo4LHKnTNQBO<<@ zG-O7|GhkET;kg{!3*yBqfCO~iT^{YP-Q{{a*A-2TOD20Vm@B7#S@;vBzPUK#BG!9z z;kwi-ODZ`N<4<5cJsE1A=GZ;@vNo6Vf{a zrtrokB!f9vyU|yU&JXrT8)wuc?y|ed*_h+$VYKNJmsR`FmiHGv4~nQ>+{`@Sq%EI? zzKbLvE?c%%N3v)b5cH0uEx)>9ya%Cw;rFbor7Q23<@=8rb11O7DW=+RlbGUJ=nQ#; zcTup@_%?qKjLNsFI!WnG&RGqDpLb*HraasmXC;ySgcTw!*wMZ#(>8Y2nn?c=ROZa3{W3A2R?uEFE`u^7ydhmO^$e-%hH4Epk6`?xAg8?<%( zIR7dP5dN(tdQSW8o5L&DYoIuodQL6CK)iQ{e&SGX=K4Zvv(v1IzLA)RLM115xAb% zY&(3E1T(8&aNt|mp?l0sSlv`C3*6ku z=4T+k1_@oiUnbrqyF+{y=Mpd&xS45Y(^)fG#l7}*M;;rRI#I>DCMqpq+bI+(6^6Kr zhf4iyj0#(4JX;V{k|P4+(h&3PFz*y2lfuGnzoUQMWuaq+%noJPi}{3tCjOYAPvK-O zQyyzzV{>3h1Q|wod{}gqk}&J#fY$HE%%enH`4P0PP2_M|l2I<6%N_*3^cA-xQ?Fz; z6*+xqPMXaHYQWrxCSb~yz^f*ZJlGhA-2*$sTi%a9Q2^Sir>S-C(C)q13b3c}dmq{y zGT(QtHwNsV&VjiB+<5-{=v$UL*x)oWD2g{KkKht}QDo&4W{2P1|$>mJtum7d{gPXXPGdwsi!Jm5?D=fNDZ86WXl*pq* zf6tnVHAPrcZvjiTG@*DDY8U4BOllt0bpsb?3)z%EfyjGQQcWN+DC^xGs_R)4&KASg zE9{-nErS54kar55nvPRPS0K@h{V_}L&|U)`$hp?X_wh^UC&$+v=g1Ih{3|j|LB7?Y zeq{HT=h+T9|5d1;DxwWm5s!XM6gpWC&{gmBMBxMrIZIjxjhfYfj&pJd3x3W?^GEokX|WIv>@wkZ^9&=F$E8zvA|(!0nboIydnJ?tm=-gEs&l zkdq~-&k+E_z~OFn1fHp}>o-^M>M+O{P{xtFmyvZ$nRT48B_G<*Ry{w#-A~lb^zjOf#6k#- z?A|r#RAs|tcek|#uHouq{kmg6_)TGT2^krU<^eMX&8tn}lTbV3j9q8hHE%*cR*pYk znfNRLt_#A$bELbduG>o7a|MNOJiX>0yKcwWV%jWCefckS=1yV4l_V1}7a^&sYpqQ6 zRzu@`sAdl-R$@Z4Y<>_Gd@t#94vFnIyIY?FSjGx3rYGoMHl9MHQ6k9X5x;z8x^Q}@ z>6HoQM9R!Ht6|jddmd7&S(5o(&t_Ejx>78KGn-J88X=IDEY;udEUtG!YZ>od!3! z1vxk4CmuL{n<)oZmDDg{;@&Y4SHy{jBYC5f{tv;XGz)6Z_;hrtGz%`Lfabb1 z7493-aFW}5_4ipeV4sUx3&&sf#*ZBnVUTfEB8mwvo%mnsI?w;;tlWXC2*gWB?W8~i z;w`Ti$1=h(WubS=AHK+2-bT9ec87NDTIpZPmh`wBqK1M)l+$XsQsZ9;U4~0jsj;tr z2rKNreJq=Z79R2cM8p5$BRBi}4 z`R$y3Ov&AjuT+z4A8h=lur$2>E9i%$8iwC9Ix9Qc(C^q=TPFMoNp8SW(VG~aAW}gw zh#?@5KvV*o4|*tt-2`Em!9c;3WiV*)i!zvguxJ^~D_ErrmPYR=Q)eu-HByU`$U98N zB(!?g7d6)8=TdvlZkBc8*F$El>)%7RrMv3q$q!NUsbcMna=fepJGR;J#YIhQUXmyvJ4|HO7Grbes&CX^ zrw9*50563-E|L98UZj;=xb3dNiXHkhkc9T?j6;%84}(Hz*&Wl_@MOC{I*YvgRiJiA z6Y*O8T7?{Y%7|)QRp*g% zvmV(_?YrSXDNLe~RwIri*Eq#OGhiv37u9JcBRm{lwvS20#2eZjYq8L=W z8@M!}d+hSiJGVyIqRd}S_&X0R>>g;*>#46s!V?%a2%t z<2?MU|1mD-^8{;?F9c?(!DxdOe>U{6&F8Ck1Kal4$}I-VI(X)q(|90GDS80v@{ob8BV!pw2vW)dHFWr8F;$sb`x+V zKH}D4U`#i?9}Xmn$mmWKH)#!LLM~9B>&V9!6#nU-6x5PP_@n5!<4a3KP}fi9+M;8& zPQ^`sYOBHYKXR92ikpC^M{Mt2jrI$UZX`J}#~dc6W(Y#$!*`O77G`uz&E-#-kZ1}% zhX30qhJugrf1e$`t~yGW?`sArQ2&z`>RIAm;VcSMKH+Q%(>~$s3Nt?8oC>pdKsNW3 z%|B%ePub#Aw)B)O-=%P($Le=LZ*NmL^(~D$J{2vWq1bGvaH<73opjS1kF0%nU0^Ua zrg?xX*s{GQ%rIcW7`;7Ke9Mg@sXl`r=K*+wIkfHw|DH28hr8BjWu>qz1y%nptn20@8Lf*3Ml3qp^MPI1^x0uEY?}wFQWb zH-0Jq5xxH-h5!oYkaHt|2r@a9-61IflpXP=f^g@tq!0(p5r0QToS-Zwv<2d{`{fVh zmQZ!vS{APB=I8vOPC1m;+U7@Y%68~WqC$g3oy)r^)A%*st_i9^&ExE)bUNo-w3$e5 zxkg$sK$W7B&D+VwJ_ou~dd@y{0JSfng zwf=G1l1{Rbdq*p=AbetMWfc4CoBJbORLpZop(ztXVs<`+__?T%-v@%8VRRC7bzI=$ zPI#pIx{`WeVD2`!hV{wTiMJd!Cxnm9cC;hQAsV5Z-K$yt; za^RYBEad%4Zc76)^w|~j-dYa)atf<|Mdp9COv`_@`$ℜq?|A2lL+feTA=%&z>R# zvF6@>iU7j@0Q?1yyBp!*m|EXPr{-@SF$=;;tsTU5e z75k(Zb8iDxE8SP<0fFkFhDsv_<0eFb=KmV%WSnbpOq^#F>11rOy`_AW;yZ7wktH)2 zCJqL{7;5l}y}Ujoj))%=tuNR+xI!i=8iU)ilPL>GI>cC_LPh*SN58m7K-O_-EY9s# z))l_?$j`SKdO``0P6!05W~t&5-ut;)vq5wb21S4FNNEZNXfXKALL8orQuQh_7!Lzb zg*_O<=@dPaf1h2h+eozAcGM>(@q{$K+Mw>IC9>1$5P^XG4*EQUH15ei&~TkW33-3M zJl#GliJ73>s?N5OMD4T8F9PKWW40`rC?H^s->t%#@HyZYm>p^8Rt)X^dB}?mecR@r zhB$Dr6b;cBiou4)t#)(<+CW{s%qT57`y{@tC5BS|BzxgoaFT;v!&n@AeGr}TB|M3l zqz$GwZOoq~Q@SR$BDcCoLUS#B3UHepdrpKWE(gB%v>%16pJ3j`meQ_sM|X(|CvI0WR#Z zeHG8M2a>5TuLs=a?24!qko>xfu)%@q-d|JXtld|UXZLra7YnGsWUqySsty zw9Ir=0$6#q->&d9J64*hZrFWYPT%jsG}}z-oz;tn^t8=;Kur&*By1|1)hw6Rp@I%k zWJ!z{I+hS_Me{S-C=xxw43Fop?saDB*-FVdSqBousnp2L&R zRRK~f$a!QR|C8c$mv*NtYNKMYx5T-a_aXWt-9VXEGJ!<1R|vt#eh7AQnzsZ)f$cZ= z;v#1ww|Tg~A+J!i4y8xiBM9(^Yy$oeH7-H~p&UD&$@X>)WD`__iqSu&7XCch_Z~B!7@D{Mnv)G+mxING7w$Uz z^>{ilM!zWnBJOd4-gp2e!k#NZz!KO8^w06h*$Q;FE)_5u`U4#~fC0`{1fW-FPjUFY z0E-2{f(jxybNQm~I<9-8l*OPLy2e7DSR{QST2uJ{r%YV5#%A^-3*0^<<7Hn`JzwP; z+pP5m1HWG|8Kpz*qIb;i8#A_xl@0|ya>r%9#<}L+sJCCA04xO_r?KHSaNg&J`G7ad zgMH$ywGI3w1NADUMeiHEkc&#Vi!<`-{;Pf{#%C8p|AF85H2He{(8oNfh=CODG5^R%8~dtmBESBRXUzk@~CmfFDbGe-H{u=pM?1Ls{xY?!iICW9~c~ z1=Y@%_z*SB(aL84p6@=MYop)Get;P8c)e|TD1y6aN#7rE0k!ynS6}FI-_8M}#^J#W zj7(`xN(}fS%ts0v3=dVgG2rKQ_z=m_ZEN@45GToPVnQDu4_~VJ z7Vd*8PpF_aaLkx~MF9jT%O~#gmL248&T$baYH0djT@nbGZo(9Ebe$$ z^yb<`4;1)#k-}ZZNp2)=jT~O5-M)#u`fFP%-2YFkscyiuCEs|dC+*FC`3vTu*O%uE zVN{QY&qPV`c=Fv#Lx8U=jD2LXECG)V)a_g$H6y^3J0Lg!3R-U)LB-i7$D$gsKiG0| zgcYN|q8Js^19f#Se@{Y-7R+E`0tMX*jus*EQ^vmWD5&=Td#aivsrkKz>-!HmFBc2E zR^^gkuT8f#gWulcL|Z0vV~UUuc(Zn=JnmTJ&}*ztE)IngEnOOsdD+S8xUCaXxXbY0 zMxXG=>9|>hX6wrElQmW!(UvVNc2^2~&cIq)D4;J}SkC_m_#`>Gkp}W3Y@$nS^HZBc zN_M(2c9=hBjB3u>%kUdz&eO|UK2-NZ$`+2cCqWnkAp?MXY__Nx!ORwK(J)AJw7*vt zSP1;vBqf1{At{uAtaiCbq+R26tw>A>5XJ0+7B>KmH<#gGB0Bg^SGF)eg3Ax|A!43| zaQ745XZPMvqy z0B|*`4F@th=cmY=YrR6hB7m1~?SA^QV2~9OkX<1GTn5!aEAYL_jD5^g)@!r|Wh}w@cUElg?X~Efv1eZQru+$`Ha)ab z{@cx+Q&3%O#%Wqz`prLKfYReq@NPcZ!sxvfnn?Kk^eV`f3}kdic6E+KA#z8C>Sb-Q z`q&-i2Jhsie6bRvddhbx?YW{?1ORdED8tVjjyWE0cPOkhzx`vPZ>~yCZ8_l$TX0)Qv^$Q0(Mru?x!l zotZ7#So5)izW^E?c@%ob|H7~7tSwgcB3Ar^ba0zaepM>45S{YE%^w^V`p_w_C)?qj z9VUAgGS)J2TuApGC#;a}4ppw;Q#U_02)%QCECF)dn1coKCQSO0_z&WWfGOjkK0n~L zBis9kL8ukGi3Xm0WoHwtGTn_hfafZtchixjUMhs^fj@KKl!BYPKK4GqK1y?s8|(4Hw31Ge+8vmIkrMBarSWWzWBRSHv% zVUSHMr=u6WTw~5au3GeP{S@A&72@WFai)aRa#*dBpl9c>G=$!r?~4WsA{%Kg0krlb z?oga5#cn!K0n{vwJ5q?SlO-MF4jVMfB8_)K`W&MJ;PsA7RaWv)YLA6 zZ0yx$$+T7V&I#VJZNS?ba-IX^ul+5M%7XSGMq=;6FvS@p{cP$d<)a-^a^~(HC1yn4 z5;HXAT52_KrS6KoGu(-P=Q7SoGtfV}Wjs{L6ueifbANdkQFX^gRPY{%40xb@oD%Kv z3A|807q#d7Au)kH>rTJRj=ZDRdM5qvrJ0yOj9m_$^9!v zg$>b;A!@b{&{*I{s4znBfRotkEeaey7}WA3E-@6d`sFThZ4=oKV2~)_Hr>&zuu+mO z&){+e_&n>-2R;$H?A6u|Br4PjVJQV{W17urF>cWA66G(0kP+29d4pv~-sJp{@%Sa` zscId;QR`*n5&6jPqI`s0hrf{5KkY3?d-FzsVGx)7T@5Nkq<*5umUJO6%#pf(5cfBW z;qr$iH#h;dD8F~i0e(avk&CjUgfb$)KotQFy011e^hNDU ztOz`Aq-!amTRhT4~lU@4E1g)UrP08|A) z@6eSE{p6LJQlf>t(KZB04+YNU1S-2Dz+rpT>kdK4DjFr>@A&f zC?B9cLvRMQm=Jf2575PCrPMD+iV3}MaB82+6UvKN17aLCx^z+bR6L2j>05sW8E}{E z6MGj1d5Jzi4^fI{T;5eP5XI5#GXt8Q%Mcd(!?!~i;yg$bd*7H@ zQ^^v_e=J~9*m$_?bs>FL3wCb2>fJ!`(hMbgZo-9C09Z zZq=5yQ@vDAns$$BAmw@madFGH^2D9Ga0O~yRI>H=Zf|Z5jEV9tBd;tF73@m*=wtZT zoZ%4?g7!v{9;SJiQDo#KWRWj2sorN;qa!Vr(nbDyi6f=Z%7@H-IE#NwQWx{-G)N!|WlgGEO=QjBZ@H+wteLhAr;W!VR|+eFb0=ejJx1mkD`-lEtpx}7 ze$_-pP8?6SKwX|lOE>R4b+XMsoLg`b0Xeg0=8;%NudQGUf+icmwm98Zt2vgP{+mXa zCQ)@n9f!66yu^We5*v%XMnN1*c>nj?N`K(gh*J|!V7wEo^Y=oNKlZ0r_h9G6vqLr1 z31iI0$itIWQ(J@zavKC17<-r9tr01EO7CjzojJ}ul|2S&+3Kl7(8ukja%X+a0D1As z`RE6#@wS*4;heM4L{=Nj;|rrJ&NY>Q0ZfF5QxRP-@r~cWh78HLXFKmf>L>WFi0ifX z^q${bPax4R&rA?P-GU(Sx(c{&NLxQiM|r-AruF&BNKf5z8uo;zFNhUklnYH0e0~Ba zM8h=8BmQYH%>+a+Ge&2iV{qFz2-@UTenrA(0tv!2YubDZ{3u=t*T@>;04l@J5^2J^77xG_dC8>-!EYE&g<1h0S!hnmG6E;+vYKrgeNOu-H8VFgW7?IR3YF`)a1$)F zG3*L6->XQLnl=P#w_@BY@s~1LC_T_?7<~D$+j3oCyo@ZqG&$XQQu@=fO`{HGRdD9! zb9UL4K9zW9b5+UGP{4>hbAUwY z*}T@l?Bc1=eS>Mu#{2cs@I4qBO~v4)A^$yYLG?bK&-!l2U)XpvJuxjoI^%tJc6ws( zP#0ll-ihyG%{(5VnaDDtpCC`#86Oi4%ea5EsU6y}`h-%eY91ZR7tm4rVgPxnf}45< zEB3)RuTrlm*wuw=8aSQEli=Of;;}h6Q01i0_Np68vK?g{kLk0%Xup|YR{^DfR${M9 z9LkS9yh%g^$^cOTF|ex=gNUunaAIvt+y$<3jx84|6LogkdvOQB8bOxLW+*CDSX)H$ zh^lF>35j9J3J+=gyAQO$*xTnFBxv#e#Q0-wJoiO;lFm(a&%q`}A@Bn!ZxEfP6{Bm? zU>Z7wIX!Pso@@6&T?BXf1yKR7O-otyrpB4FTKtwFR~>n>^ThgbZ=(kBc;2lPw>Zl} zasQ^q3GmKyPK=Q7M$=}b50)OFB@a42k5wRzO;1%<0AEMM|CDGv&%uwaP+`Hx9D6dK z4AZxmaZ+zahQFknmMo7v7o#{8Vvg;}3lpCh#5q+Ll=&g!{P2DR_Hc;}{TP)yFP=HJ z&OensK>6a@h%iu*n{r|fF9v9-y7+By<4KD3JDDtm%R${AD~ZGV-A+=B;y!jquh;*C zSd`loBO?#RrWk%jcuT+uR@R2u{=VDU-!{7y4-4*YvO@Ys^`u z^cC-ND_c*TrlC`R5w{tQK91Bs{?ORN_F7}n((hi<*?^D*3Qi2fWm9bVr@1pT^LS5F-FIwNCmrsdj zo49YD*Z(yI%a=;oi;fzI5lYuo?Ux6q2}0=u1^+rO!ddNY@JsGgZM(U5(LS4aRIP?Y+ewz?{vb>mABT&*G6zG%<*tN~uE2UX1z{in-NBKNkF&E3)Ptm5P7!jv1c4 zlz5t~fjTxLoMZk1napY>H}&AUzFvEUzcy}&W#SIpTTOJkBl{{1jEyxG|S?NCJYb0|b>ElbxrU%!jyur#Ku_=&7ZG9(FdQ@Bs) zSr4h`<5G&hoh1tzV6zG%lCsfF4rabojY=;*&{suYb2Co1eiVjIAUwL1^ft9NNr%No z-DOJb{zc}KBtHz6#i*VBFX1wmwgstXi%DA_*Y)YVC95hJnMl}^$p)`3ZQI^&+dRa( zfN#r((+bDGIF;kuI?03t%@e{8NO(J>*2KDZhNsZi%4Nr{_+1!LN*@-Wl;#pLWA#JQ zzjIL}HauE*C&F;W{~NcrjF2?eneG{U{I|c42J;scYhDt>W5lKj{g~OtteF^M=s8FIePJJH;?%)!CqpbXyQm zl$9xyWj4u^!ZrUaVThrA=cuGX{#esUJA^jTNh&JVA)$0C=|-{O%S4CZy1mlPrx<(k zN{;Y~+rpa9uO;)*73KJ!6u7W(`Hp5@M3ZTc1gbyA8>OHdR*`Rb41IB!(e$TrM;iq7J5y3q6m9+KE#Y}0 ziS~$0JiZs^!9Hfe zZFa#aduT*D6QBMkUwF6jucukJ!z%G3X$H}|kd90ukpEG`ES~#6MekW1b z^Sj02#eFMmI_3n*7%NFHoO#W8o_o^S;YdtmDNriRFE&tkzpI3olB{%< zp_UeHY2c;ZlQv~XE8K?k%@Osm)S26;z6q?yk(Ybeq|9B)k041$`$EWii#cXUR6i6S zF8gI$Ao)+)Ka~9rL5|4Cv6f6i!V84{Y;1Yj;ufNsV zmhEn~Defz}_+4Xi{9(o1h3ik#I&q6F(>jlpfmUao;+t)+QOE1;=NSzF3q$0Xca4)T zHcjhx@6K*L=Wg%1S{LKhVnilonIy9vLeSp|j?e94D|q(dZL8KauS_CYc)^*;Fv^q!LzylWWt}O2wjeTxATb+H2axbTM zKOEWKdXno=pHDlP-ORT-i!Ph`Ojmg?%iJ|O-I-oaJ6+xNwK~t;(IM>ko9)`0fL+AU z$PxC^U;hxo|97YX`xSHFE?p2E-d4X;cCxy88?Ych6>wHDhqRya)z}7kIpBOc6sZ^X z-)$q(NOlmU8XP18G$eMEK%)DSnD^d=BK;>FOg-8bf1Z2m`SI><-L&rVZV9o=OgUeV z4`A6&1?*Cf{V-x-q+myan4H}#4YGGs_<=ihJpH? zgk|*8`~KbK=V<4oOdvFVuOp@O*QB71iUvDsQ`jj(F;gf2v_mYPa(P(ZI2lo;@U` zaB7JGWhSm?7vPe!SQOC6QiHjiT&A{j07r?S{y0PYS!7)hQ=sdUTFga6_uctm@GjR! zE&tDEoC8}hiTh@B16!T2_$0||Zc0P5=S9v}(8ry7)>R7Do_*9#D|cmT7oBF_eWiEF zi&#_3rFUPGv92_qGx_y7gj2V^Ev587y+AuZkVqPx#FFr@Y=aqP&+LJn-M)8-23_{p;dOq{B(@`_pS|BC<|z7iu_LUXEwlk5ExN&k!Io5=UHA_=kmqEdGu=Gwpn^{- zwtBZe1d9MN6k;#WvAw!Vek;$hTpDxJ-mUzlywFT(k>=D!kRZ%18rr+zf<-I%t9ch2Po z9G{@L+{Cw_9BllW=38|M$+r$Ce%ku<5B9yv->o@^A%qpa{^IMXtc$1Dulul{H}71W zOni#hoAnpB{YAE@?OrD_Ke0kNRv~fX+n#boFu8r=quW2luh!*kym}*9I;~vaRaZ`E z-r#f;(dR_2U{oHPv|46eI^9pZ{&G$DWxf$E^K|Hm7Til?ZWEm&HGI8RRh%VNzK;+> zT^ciAxAt3GTt}|YX*jpo2p>f5Cd&R`h@2M$&A$DL(J9}Ec#9>r#v=o^o67k9c8qO} zJ@z-vAl*9caAt~mQ@(X^YYlaYsl>#a#)ZkNb)M#vrdK;NgzZTo?D#1{Gdk^>s7>;E z8)nn!<5*rHT&re+=>3#CMCPF(3yhy$R*J%Ou)I<$f3!VE+ZLS>Zzn@-dZxE+hK;sO zvGYEjIki;*)^IJ(IIzBlZq5<#4Bg|xS3a$O$)nxq)&ytc@J!eoD}dJ*&Eq_CRynO> zX@CS_ufl|{2UT!3_62zr5hMYEyz*mnJI_pK99VI&kw6frh%8|!A^_4(achHx4-!0J zT;Z+hd9ctMb)wDbYN$kxQ-xBA(QeK3j$(V(X@Xv@$$5yfb2c;@x-ZR9UYG!;co-N;(zTff#_EscYbeH># z8En@;HvNEoe1jI)E^hA(E`?zaTQrYjG4B)v{Ph>+AYd-;#_w0oe<3j%CexIN_e-%l z$+W!H24$GANKTUqfWocuW1;&K*1J z*3ym%Uz=qkD7RYE=sF+%AofZ-*hp%+HqS3JY!?gors~{r7X21BvwYJ|t>g~-({C-! zwrQ&FOXJvD4~<~BiGC$5c}WVmyK32pT^rLJhEC192Y2xWx9cbnvs)G*WI#k9zb%Hv zS4H)sZryLuq~85zgk&Fu+};=N5k}$MJWH@y5Ib{>;!+-$kf2536Q}7MJMNN^W>amY z|5kn6g)i-1*1)BUKz5|)IO zhl=)*BIb3vNLD@p{9gI*&;`FyOk$$0+N<96(n=$;i?0#Brup!tXe<7xW#l5m>GlUu zT+%>H$_5v3yEuwP)7j8So8xC6v9XXnORZ`8FL(H*=SpY3_R9To?Ukbxd!bQgx?N41 z6^|r1x`KW<{@ZG-izgxTdsAQNpXi>nhgyEwP4j4Q4c0knzk1Gc=nGmKQ(;|svUx*< z+DE>LH-z6?bl_g))#}4K^qHEQ(1u>wDhz@1;>97`^Ae+kx`jrft&M(C$&6MX`f#krqd7TJ5{LQZhWfMJ^iZ-(LJ8ev0nYv z;QV9Mnj8WX{`e`4vY=p zxdO%C`WBoavuQyHA2>sTqx3>l8H5OfkRfo`{1WvX5>yt5FB<@ccMyn=2J!6R-02+& zjDCax4!t^AkV6P^QouTzlz_nxjB-Ry2nfprVHa`6OR7a>^N5o%7Fd-xI%W^t-|F42 z0^@7Zp8TuzjEK*RvRNmLJV7t$@Po47q7)lh-Jg~pix=H%_GsYBo}B{aAmr@i`U$?} z3IDZAJKS{SfRo%$w;ly;fZlish-xAs4VM&qEaF)Yd1TJwFGM5YGN8m^kfE)pqthR9LT; z6jBQ1wJA7EkR*Hxfb$B?|;e#rp;1r7dOTU-7h<+D;XV*QDVvoZ%@kPSwT@s_t)cy7gH#2zh%&cxV*wU%nZlJPPR2~C3lmajJtxaXFcc` zXr}_#@m&Tsw@Pks9VcgE^Qc5`uL)7bv!QT|s+?~-#eFU`!)IO)vdi?zz4AA1=j+tg zqbkqw9}SyQrRqy9f3s~SG5(+EHH_! zHLh@&wkQ~M2C>&=Lwt|+zVNk2c_%bxaN z3dXE7Df{EquWegxjxm2x=SQiSOth+LAGB4^eZpY^yl za1D7sCFlU3w8&f33o`aYStenmgkO$kF*%4ET=FICXfcNcUb<_ON7iwCNad(TnisB) z?UOs-y&mR%g`Z)3TNtc~tE?jTiDNRfiBy}I^jjkbeIX`lB|Uq{6(gKbJ271nN0G=2 ze2sc}Z(=V7%cwrr2!rvH%6v@JpL`ax1^TXm^-7;zJxnq}nY-8y!GE?NEUWo}~ z!197uPP7rB^;7KNng3|xzz2l~2Zfh{#!9h+0Sb>D|G6;ukm-Q7ODbXhO91lsFs?|F|XUHYo9*7H zsy~@DNL#&qWq*FPVO0DH$FFImF3j2T7n1sTwSrQ;INL9^UW>d%{o8=1(VxElO4N2x zvteX$*Lx+uY$?>}v}u1Pi1EYwLSi+q3~0t@jg7 z#FuN|aeD5hEG+{jp!pVc{tHEK z{WchhbsGB(l7jPfB2s@(1zM$_pKRdzs^xt)>Q=^YhX>>czyN?K0x$u9dY?rqQb;2t zDPolm8Y!d_C`+K!A|T&~`?J$VL=A zjKq2I2oFL;L@)h`5en0jPC%=2rosIQ^TUH+^)li9^aCKS2Y{Cd1_2xqOg8{l2nGR+ z{I;;%GBB8N6-pBD+~NQTF9skOfSw`%yZ}H&00%@&Apj--*si?AbF)Ci6aeNqA_jni zMIvTgPA53tK{o&uF90Y*+TE zU=x5B2(StOCITz~@X;86X#kWFU=)CDBLMmVh(>@e09X;A6@Y$2`h$JdKE@7m!+huF za=9(6!E?rrTBR+;4t7!1u$x4BddC!ch|c?6xH&Ps;sZk(MV6UDsAe0LT%r=8J(r^j zeX^M@Z3&7Yo+86cJd~x)MphHui#AcI@-bXHSUe&h&ruSDoIyNcGp|8ji%gYoqO04FSZsC>q*UTiL6UuFr^loi<^lmHK5?ckX`P3(xLc{U-#8uVVGS^T~p|*JK z@YSp0koMU(^x_or3S%852rvu4D+HJVKoJ4P6~7@oZ*>y?N< ztN4E~mSwkc{y$`Y?Y;aN3clw5BJFFLf6xW;{zIMz4;Ckz@j5Wf#25e?Vd~huuxAhg zCKfO|ij$YQ9R4R$M~HMviHrCP-hf;-+QtVp6b}ui;D%!SHlvA1GY$uO8GqTpWv(q* zR}xQJp%@Wd3i)g_tUNW8a1ho3!ptWk|LJA{ZbIP30PY9j8b!dZ1>7aTtqrpO>85P? zGxuAYi`bJTEn0*StP}&RG(=o0b_m5(!#230n72)LB7K>4O9ebjJok6V<89NNSSinu zw+$8qK62oD415ng8GS-T@SCN|9=NE7?`a4cVAj5y3T7|M2M zjJ)hYtH$<-%QY(vp#Qh1f10r%iEbwN2U_hr0no?4H`f%PKjrrye!*>)`c?C4ixEx@ zVb}=v_)Wp{Oi9)smXwCs^1-84j2ZU=SCjUTF2B>rl`{KiO);`zSww`X?=9Xx5>9?o z&_7dRL)jh`md;7iLz~L;@DXFK!uh1|YsN>@0-_f`6m*c^DP2jGo%d5Q5^9-%huIeJ zQZ0&!fhZV#GYc1yj6Wt!36e1w^F25~GJy*8mla567J@etWI>HF)bcqVFlnX+l}+{wVL1l$ZD8xLfotL6VYH|TsCWWNB}UqH42$YuxG zL?9azWdGB>jW{gAo8G+k&wJ7KbK;Ac+m=D4kSDudRwI#s;Z_UC{C}1;Spje~fkTT< z7#{mCV<&PV)=EJjk#ZL5Wkoj&kF8|V6l~9dEC%&9t)AB=>dz|KShJ=lm;J-Q z@TK)+6;3Hz)2mIioK=dm{+IFBHJegqW$2aYG^u6*c5 zk)ZJWZv1^ddGzv9MHJmh`t~^Gw`fxUznG*C{^EewX22g=xjIH4j12HS{>bIP3|Uu6 zRa&8UjJOo)Z_%)d6;V(p5N=K2E&*Mh(XB9c=R&=^e6b25aJeJSJXo?(LY@+Nd1ibfU`&o3RP-jK`V#Q}GAig8X(8 zS=zC`^(Rx6>fIJRo@V!GiyKmVU@8vjtiAnM1e@6iIElfTyRFEg7XcE1~eu=5Sj34qCaXFuACj$I&&Mc(BgL(FEz_M9i9kY?^D%AZ`)F zeFbrEK-?{eL&1tBAf-s5<>6Yc14fPXS)rZw!)lx++vi0~Vn9=Ak^ydlvP zP!V(&P+>_FxR&hw;rh0g_Hh{rQO%jj|^<(O$=8>I$ z2*q`?^0N3ZP0i|X_=MqvPQPUpyBEsUKQNoF`^j#GCw22mR ze7K6-3ONz^X>=O0ngeiVTILNX;QJGrvts^tP_83{Xy;gWjmrn2q&tQiJ{>*|B^1jnSNx~y76 zK}0^-SpE0!I5|80A4Nh6$UlJ&$DH`6tQ;Xz*O6M{kv~P-#p%?`cQ= zmnM9#Q$kmf)>Bi7UX!Un_WuCNeZ#GK}ooMuk(S9Id9SjAs4i3wLfJzj%e zj=ZJ&CG#vU30qv42SJ4H`&Fu3$KN)pfJ5bj12E&Z0AXEA-1FW@$DlmkqQkl&``d?e}m$OfUHM zWxs-%<=w>-NQ6q1{>%);=gKN!8*@vKf%fi=w9wc=ZcOs46J%)|Ndg1lsWG$kuxsny z7#XubvgZy2R@%4j4YR=5!8RoF%#eEm0;tH2j#v*tM~^D2mMCaCq2~9=ub%P32olT9 zEn9`9z<362!DZz3Wh}U&n5wxEvPlKdUN~RP@VyK*eedMEqFXxGi~7XyOZH)b`wA+L zVRG1+&dPM3;g^NCt_=cgMIDz6D+XXlvmaH9|OmziVq7$0o$TIfrSdF=;FXn1Z!zm5NF~K$meU$4t^@_x~I(DhRvG{Uz zDgt@l;NpUtDEG(d^Dn^AZG{IvtKbqDz00 zZq1u+cyzzL5npzl$&Z4SV|A;nCi;L`rTzt0dr9HDBV%+h#^^zm4F=_qS|y zsv180_yz{6T4c0Paoo#W8?)e}|1T}yg72RVF7T{N2>PFmE-T*x1y+<@=fvV5@mS%V z0Df|+oB;&?OOo7HcBDZRoBt0LZ4Ik6M_vsHeOZacW7oRYZ)3ITPX>Co$|gV1e|e%v z36Y6Td?Zo#qt+lPD^9&g?z>zeQyCFM5#5A+Ro*0=IfAHZrWd7{--7ss?E6gU99dN~ zKfIRTLXX7lhk55RmxaO$Y0(yhyAy{S5ybGzf;cn!^^lzSFSx)k&s zNlx_J7$faB9BMp=BXSNNZm;3ti*kk$T8GjT{t$;&oT9Z*l6#>-+?<_}uORZ!e>B|9 z5Dd5TC!J`_|Jl0GnE%vlF^Xg< zmnGEw5XGv|r6b#wT>Mi>+l`^L{vRGW!s!oDFEqNo6#q2Pc4IHCC(<#BW+|s*IV}un zx(Q0DE$iAZ{@c)6-~Fh?&1>2Xo(~|N^%yxxTs~_wN$dUn+8T$?xFRYE6Cc~S0_(b< zd>Xs(g>eNn^R#RqI4ntr=c$$=GcF5+}zgPrO?b-?FEEG=4|!?QXzA8djau~ zIfuP~T*#c`-d!MM&Ux=H0W#;hcNYPfbKkp5gUr3$yMsaIy!P&r-v5x6uq<|Yk4@sh zcI**mfO!-Aen^@cFDbCXln157zYFL5G6J%H!Y#ABJ^d)CVu=fo{eYwd#2FwYxU75! zzlirp7|eMDo6ULpry_}3-9{maTKJ#&!e(%f>H=u!d*NOfwc~Z@l``wzXi!+A1vSAW zTKD)FdS%BNHdYdL`W~xVM~iorI*^J&aaq#*K>GSj-K^#%y1PQh z%}Z+f_=kc|8G0A3T#s?21oWo5&v30etZ&foQXi+a6^x_ICXlkT<0P%Nrl7O9Rw$#) zek0AvV(Mjav;28q>UmU0gBFTDJJu;RW3T-1@&k$L$GL3;ce>%e3#SmP_o(B)(5n5M z=Bep=55Krw^9Hk-<~2=(^|C)EswZ3Cp0NZ(hiwmfwclgxESla!@Iq|D`iq-Us$dq$ zE5Lr8^9`igKXHY>dnn-(LbLCgWP$a)cm*;hR`?+AY9cI+<5k(Y(?KeMg=d-_5v02Nt6LHerVfm6N-MzLl11U`=)ORu*}O#mARTL zc7>mc`DWV&qlaC9+L)%^#m1y}2H#86e!oP^%$4^LGhNHfa>q?ivMG69f}Du!4`)E=U#YXj+Rna?|JG4#MP1)XI*Y5Cz zaN|+TfC_cEyLrYJR@(88v;$+FaKlc*chfrowC>P4Ph8LQq3zo&B&Vr*tS32QH*4KDjp zsay;ejg>}}kV=k@SJq#5Ni-Y$6RLL{n$4%_zIn+;A*uk?IO68=vOCh|K{IT7cz2wO3PC@fmo6S)^2f;^-m&)g-uT*dtYu-*!4F$VJ zIqW%_J6#J~-VnCDz5hrGDEnX>i*Q{(H0AC#^DP3K0yYk;P(mrOeapq;w)?)h-BsQ+n)Dp?R~eiiwwLc5kYE37 z<0hkDCc(BTM3` zUIk|{W1-nKLz;L_T#z%XL5bvv;fIH9A3uk%+Jbq~wYv;TwMA8C0@KwWjnXzKEc1b< z`Fyc4Y^G7om_(B?WSbMMeg0=V-W@qwgB(8E4l?EZPp12jx?;*o{FkoL?GoPS^=hpV zgYQBN`Qlc-^|U!9Y7NP^P4VNnWp)PNynFG>K0Wa9`w-C@f^Tl|A)=kQ0%2IsPjOJ5 z{?UAC`QrCRXgGn}424MjGr#4Lo&ZM^k)NmtKsZn#soA3RSzUPq)aB2qMkyE;^MVMSWNccqi#w%6h#9LHtNC4iK%72Dej&ulJjZ34Qit* zn1*KIT70@~R5K9HwJLNkAvtj(uQsf+Q5NJmv+%3mCNrp_^9tPYv6UV68BLZSae2kOCZ?bg7E{^|$N~##Wc0XrqbBJNmZ5lxq5XiM zD$=cdx4^Z1d|G@aD3-0AbSxeHbc%g-6fb=^Q}2ULNMZ;6wP{M_V5m6X^>V*W$Fq{p zT}6Xow#DN;b%S9=y;yCKq!-inq>+|S!i((TVIfbZeM+PAo=lg+MO;bN&7#88C=`U# zXz4IeHL-@r_^=c-v7Tw|#mX=%SPG(5!^)@&6uR4zWK61m+V!pIZ=tvft?#p`_PC0z z?^Aec3B7aoiKDnjq0!Lbn)Cs?NV|N2hQm#5eV=zL!%cI2Urdf7XzHl>i6$z`1V(6`6s3mK7YOz*lTk;D*W-hmv>-#(nL_*E(_0X!|Rn~Cj zn$ymEDIFgtn0})54~C9kN267}pvTU#Z1Bn?dM@WBE!V-GcavPEAh9HFMW1RB`v%~zD5 z&sY5j6_0k`7Ml@Wy4HGS@l`w5S-p2W2*@);fecVB(WAYn^<@Pxhl(BzCjN!j&ZWJn z-!yHuv1oktY4-a|Nepaid=zG}B3thvYy%&)$Gch7HTyr&%yBw?fh!B=ELAC*rVF|6 zxlJ$Qj<5{QR01~idvCMTj<_VwY2xl1HFfj|**`mz`S)hU1?+Cmt=m752rw%44V6fx zo^s;Y2+yU7DC4vqC%qgpmm(k6MQaxr+`K|DpIf@ML^1bie(9dU#eSB2}g;dJi@C$W4Dbp4uG zg-*A3Na;#{gYa8k%M1HY*U4#f23WkzkX{AQ-Eo}Uh>ZS?% z#rIw^$Jyfm=W!Tx!m0UP$zwcE^4ud%1OAv(S1p;x(Vr*2(rDB*_++gGsw~)XG808M z4t5C_7I(Cc1{w=#-E{CJ(dg9qCsC1?G>(!y_J&TzGIpcif6-%?BvtCnCsnqWzg0fA zR^e~Vii4fbSJEQLiZUaOtgWUF%B{8*(}GKZ5-trlualj|N1V7Vz%*wbc+FA zMo#%ohceMK4|yUEIu(mGQW-5{`ViHwbS3|wcaIa^P5$8S!4TGn1qNx$s1%uJ_M@er zo@9XuE98{<7s7acc{0~#Xf+)KT+sd4xRJic=q;m=TTUD=81(?2fQVACOt1^zDtRRX zi0q&jq(7IhVJ(*pc6pg(BZkOGl+Q+4qJ4JGTI7gkEoVtlB6Z+HCzOvjqV{k5N>+SLJQ(o#U+L ze-Fq7@7*;TqC)PT;>GjQ$eNBOtX;bG(p`B+H6pxnw!2%9r%R92Fq za(Xedenx?9jf!lTi-&(sAvN?MmTJuL z9&^hmGFcS-C%JgOaNgUWnYL}TU4pNboT)VZ@@&^uX}aoOt!r(m!B^*+51E-CD7JXl z3>U~I?kxy;F7_UL&3u@crB2Asmb1-um49=2*DZj@T;g#B2E8n z(~az-M8CZ_&5BUqwHi(hk#(- z8h6P=m;Jygazt;+H{6MSnf*K8MD<(N?G1t<{dFxWv>@P3I-@Qa&sB_wC{s_JUrZz4 z+WAz)VO~(p`ZK!>a8sh`Rc;MNdb9TtxHP1%H=x2GX+#`&R_Xe!Ez&r_n|Mo)2G}@o zVR{B+bZAvI$H6rF?%QZmzmZZamKYy(8r{KYP{y;xQ6Op0bMRqpuA$pOZLaGNr36wI z7m7Aq@tk#gHi_Y`hNiD%aU9b>;=hHN3pI-jN<=cW>lhe5hcN~ez z&(`nK&jSi?bJOpNPVe|`a~tk#SMKyR`Rfg|Ipqkow0Y%pw6q1~lC`u&frBsB1YganBK>OcQU0_6JYrJaj2r=z_E=RY7X2R9F=hy6=yc2{%D z7v{Fs9-Q`8&gSgA96}sc_8u?U?VW90I2F~jw53#3lp|NDAX6lLVpwB$IPtZEX6J?5TJbnRUey1aI<(RRt)vG;Aqt4&W1B~mw{Cd8Z` z&}&B)O20l6HM3oH9ukklU83H5wZe$6hYpZ^+c&ojqh)RUpqJbv^tui)AAz zc8q&qR_Wc7=UX*COz%=z!ko{@lW|TAS+Y6T(F~kxwV!QhGZPC(bFpwK5~~bwAKu*R zgCV6E)re}*P&s}Z4NJ3`FV76SvnO?&q4X6clb~C>&3h=iAnh~mdgv^)H?Wrw6y3yU zY_oPF0$j}*Te`scS!Z>|0MFgk=Udn{Dj1y!73^D`oFA z=PH?0$&WYElv*DVxjab8^crnUSD;!B@o3(pacmxPL*1X9Q1xa1(mA4vw?X8l6A{ce~uq|s6Mt47hxdN1KCWkak@|2woluA+O}=mwr$(CjjwInc27^- zxHA)P;@)_1-;b)wtca?pjM!_h+G}U-1pQB>4(w&zaQ*baA^tn0^8L?|DlM$|SLm(~)M9rg?4_ zLSb-0vyyxu8bY(oZ(g1?W6`XdC_ICKBF?}WLr}!mHX%rSI>Y1~C&beR2-YUprPyF{_Ol1WOtV%>0S?C9Z4%jEI+%J2_06I=>& z!1Hg>q@MNe;TD&yDP?5HLVM|Y$9%Wb{2YsUjj0n~ZXR||#e(e~ekOx)p4y#N-;bh) zX$4)*Czw$zG<*F37`)tUiMFhcyiRXn9>Rq25=U*Wv6(MVgVD6>cx(5n(cp<;G|Fuh z+}r+kz)r;~uvsoS4Oiv_YpH=wR5om(zR{2ty zh^@3$&idh~?gb_HD?*u&o6~@+Snjn|w^r$X>w+15@rd!UN>6lUqP!@h%7SDixOaEk zW2A(Zsl9F%|KtdzCeuYWteB1(1so!o@V!lYhxcUiC+RX#hfVu~jp4fiY+9aSAt zwX@doj(^#;+|+pD{rc+Mw*q=q=&M#DJct<7l^|WA?2AFp8MFAuKp5Dt=2j7_?#CjX zNg|EmfOft<-w85yN|9(jU6PK3YvHUn-QVBvx4OSdT6Df{FVB5we%c*B?UD6mA0G>@ z%IvN7*?oraq53rpJ`C{B#~@YDzH^PP#wCf%7XL|@g30TRM!X?yAJPI_=WHsp%HiRF z@A!QUTJ*uTKtBgsC0m|04FuNy$@E~?=L76}skVv&r!SPXo$C&I>)a%(WMr$M71)vE z(fQLHltN{iJ{-ujp<27{|GH9B}4PP3oyexYBnyG4tun|mJfZjy}e$K_wHo3zb+4beBL{3 zdOAN+Cirx|PVasO{zn{W&ZOJ0QOhYK!Wuow)+UDT?9@C@=W3>U?V6{;1E9@w=#gY_ z(K?a<+Q%Y=%x*+d>Fco**cnO%1J6-QnrMXKO)g2FoJ2C?Q&mS}k{d^!iCyx%o(6|o zWV!j4Q{(g8^ZgNnL%#m5zv}7wZY7Mb-LdC`dyuUoc!DYbq4731%1U4jvTS`?bgAsXGB`QEon@gzym}?RhFr-B z!K&9;b6Srdf+E3Wz`p$n3Vn^5#dd_fsGd}PcdDXBWYDMIl#Hqnj8_ZX$Lj1<+Lnb} zkRlBMU$R`qSQE)d-b`8ixCmYR(RLa5-ICm)3HO8wxByv`%v|hjXt4dj@Owql_*0b@ zEIP`0_-8LwaL?rGmxN?!qFC>$KSd#Bw=A}`?ANF*)aRTywVe2g=0x+RVG=`x0~*y? zkJgu^QS08Rn^}O!0`5>{JvDI`F zQX^-A{$ifz5a(cF1aYaoe>u50py1-=`2P_F?_FB<1xvIR)8uIp$MU_&KzG^MY;zCdeS3-a2vvbs;fmv zL_)CC!VfV$fjtjYnOo&gdVL3By`gl#?V4aimk3u~4oz_V|XS?c6c33A;T{4a9C=_0LY>z|&;wG3z#VRWtID_ncfF#mw z{3`N{1yi$Tu>ohQm(4)6%r!IMeK?JkBj}gEG??;vQ&p~!qN~X zpEt;XRylTD$;SP<*d~42EtT+m3Phv6m(X3wI#OCwim+v|W7$5_&>vehwE`_MMO~ahEn)2qAoEb{EgwseNNBFG$aU`K3pS>))yfBoF zceoWz;(($t)|iup`a(j?w0|3MY&n=6$=&FQNTN*}s0z+RQva|Tl3)0h8O4nzu!*7q zC*tf-gRz1k%E;}>@mLkGLc|lfP^UjuGU}4k~?Pc-=kkY~L};_Pd@sZ|v>jVlKJbJbzDw z#5GY7Og~i1X7^$0`Q$@kIdXeHJzUIfXYv#%vwMA6uwHr&Ls*@(g5cmQrvusQ(-0br zbU8AGDb-D_1jv+kXL*vpYT_Ih+2Z^PsQ`p1YR@Gr4q2j(>dJ{b&Nhia9-(N4$$)E; z8=z}V^ygA86@-Dcq31n_=I_5yQFQt#gpbm8hTd?bthohCOgorSS3a1M%$S+;V4pOU zdpv`o2kEmA0O_R%pPN?_D?RMO!;CXBi|Z{(C{9i=vVlAZR_+_02um-II8=Z3&NS-b zS+sSR=x>VKT!h0z;>*46w87M0+S~o1GA}Zw!qnv17#FF(ZxRlim1Zdxa2Z{Z@i+d5 zgWcU*7Y}fRd@%}N#jSntnycQ!3;}NHPPBioG03y4(r8fQ60oP8Nk|1t{9C5jE5fP0 z1d%+y=toY25uqyeAh>*Bmup>jP2E7kgjIb^vP!qbKj1Wyr2hB-rU+aUR5>yTO1eQm zz$N0FrYP3v8f6uL9GqO#Od)kV58OwY#mBQgor{pSr)SKm zRTRg2CZSF53n^UMsNmv5cCy()8NlsUdRZ*d&dFMMI5r0$f;hM9wQr*)Ugma8v|H+Q zlP$kPvDgdV8QcAkGQ#YhrG3Ia*sC0t>gj5Lg=by>~r44ge=zHps*& zK`z(zvZzpzX(5-<<%YwK`z#=xSEuE}>jRJgQ4sgZVn5leIy-4+5B*Xhrh{mu?40Nk z=rFK$Z$gRHO|69WU#So~Q^^sF8uVccp!0=?$f3X^ibD0>1DNeCDqy^nPvKouiO6NN zBPbKV*v`e|mrBs@u)`~IN{4|@3$C7QJxGJj&NBP|)-Nx>WF`0Uq`LvQv^MtPvb<=4pnzK%6$uhBI%g9!C>CdQn45|hChmS)4OA8Xm_|t2HD5z zf>j7uj|BhZ3gnCtSfoO;?M&)hj`uppSbaSXB3br@~}>CDhtM;P~T%K<6SC zC8mP~?-Cv{T5ADFxT3@DpBWv&-~Lq7Nw+~289XE~d5}Cy58lea!iksh`Re5Y=jPv8 zbR(a+Cs_uXV!;JHq9{1%OJqd0vcYlC7Fu*JX%=tMK^ zeEAW9m$-^F$=-!}()hnfbEZWvS zOTRA>muN=5DmCq@f_(=<8v1Wut_SYh^-nUGP_IR%=QCf(N|)EQ_p4iORxtLQ1m|2E z^UFuiPhk8XQd{vM{l5(aAfOG>|1OZ``JV^U^1_0$@b89#o*ZPpszV1IPMo|dp z>IZWZmE5J`pSxG1!Eq+WjK<9|u&30@%l1Sb+^ZqbT{DozzFE%+6PHgb9G=);oblZy#{@PgO8dZ|UOfDDx^vLY&fg=oJckr#hkCRc9v?tU~e8-C2@p&0R{1iI?B-Vm5Drg?o>D?J5Db5fcrLT*zV@8@xUi@c zX-s4~-jCM19Zy$yKGQ${EtaGS5pwEWVC`61_Yk3id@ z%$L`HpOexQYkQEu&(63bX7#*a&foz7o0zpJ9{&CtU4MWu|LSfe&B@#9;X)YJHyy4VRn<2@UAD|o4ZSIUABGlWnn+(c^j#*4nY zkYt5BA^RE;BKCh}K?SSZqrTsd=m7sGdgL6HxBwtPK>FbS9eTL`=jc%p6Bd>N z>t%ouV1R?z;VBsfm(T7T)8yX}5;}(IQ6~>8Je^(dxqbv~=SD7QqsSQ-!NANf4!J97 zIq1rq5OH}*FSdYP) zuiucsIIGz^_Rf(#=osKWlH)f(^K2A52U?LL5}f&`f|ri10A_#gB*Mz z_J8BvwRs4e(1(Bl#hb)Ver_|_ZaDaIJN0ie#pJU`7g&5W{WXB^?CSc2x_(tw@CyCn zc@zR=V&gYLLjFq}06A4946WHe5u*T-?-b4IY%(n$wJ}0|VuF)gnhxc;!i0ZUg{HW50VS%k{PD@ zw`}KOK0>_tfw4Ep*NN48PNI;ZS!TD`d%BvLQDn-WgOmslbgOgzI{7EfLjRhD@btCw zXwaDWS^Uk+F*pow;NS>9HatWvzL@;jqL6wO=M>3lnl#5o^K5qW?>jJN#nNcv%KDM2 zX~j{iV3qKhw^N+q#pC+T>poyD5pQG@QLLbsM=!65)nT=BnOlQXSZE{y(bNpL(x0!j zySm%mE}81&vHkLjG%@!Q_{h`_xppae;Z2v=CIM1md#cM-7u*SypsU7o_&ajV@5Zwk1{9%p7`Wt6`oBgfsg%VQUj~|2pW#E|c3MbWLR;V&vN*LS86UK?L8>K0ADIS!dag zfx`C5Wqk8<1STgpvEhIOT6c(j@m60F4zig~#U8m<6LaVl-<@IM2AS5zRbl`+$2|IF zZP>@bG)4i>AP=@xfzd+BdEz|mOXK7YcffHD{tz51k`Gelb?cccyx7-Eynry`zu92| z%)H;J?yvhuT5&a*ni( zV9w=i6D;H@qCc6IHE}YC7$Ws}xg~6Cc119`3I_E#B0ZB8(jr{V7rr(t=-?|x&120q zJQMdH(y6XwN>bD!s+VB7G zz3V)SBuOgQSzPKG%>+rOEW1@9%JBBz&1O?68bYuORg;5C6p~GVr;F7YlOMW^LA7P$N%-;ZF4<)xkDK?I&O=~Yc>Og_>A?-O)o6m-4>)UVGAzPtNk@09{bB&$z>3n`3{WhgD zNJ_-z(bnPqbpFrVx2}Xk>{VacBFyluvKVZO^0+3>H!px!s=9bURq9`ZVbhJkx{ihS zm}sk)vJ#WW0CICc!o^&-$~(^)@eD~7{fvSDmW2WfR*_Zwn>okd`Ce_mwaZ+Q?ZgfV zLRmBeuIu(gaVY}L6V{gYKIS*sA4>fX3NB%AYr}&C0-F8x-%;@YP0;^4$?pFT1>3qA z=oy$A>FE5wbZqb+ub^RKVEmzGgH9D`%b(av*kaBbrYP zAnZyM3cr(2B$`ue-OX*`(87JH^)arnkctt42yfuWB zUSRZS-pxJ=(3c6z5QpAcs zB@un#bpSTY;B~+n5-@@-s>3P-`;9JE#Ph3t#%gGyiluS}M=wq5YAB|?(lrU3p-`1_ zhqRU8q_M`+!rzGJJad|xl1=o5XkACptJat^NBAY=_fmJ}*}RL@faFLK&j(%=wtxoC zMHx^mY2^|xO`ho9ov75ucs!MT=aeY=?$Ij05Q zg6z7Pa+6C2r%B$D?1q_&<4f2x@OPs}BM(iy79BYq=;0Q1j7w;z{%l3EOO-_xP_>Ll z8V`xAdb+X{|1Z7sdN1KF6ro(E_pLstoiy{odOr5jLm>Pb5f8rlZ!6~YTeX7y0HSxD zj^0O*WEmj6xE;k?=@lU#Z+*0_-R(f72ly=96Pe{xY&!so3&^Oc(a;O5a$@}^WYPCM z$6(%P&F@OCXMvn_(9Qnq6M-ZSA|1@pJI@3r^7Sc*(@W&MK~PLe{Lvlz6(+>@?+S89H(| z*_jK+G4kXq!#j6~XNG5S%1cgEuEZ$~0ypZ3 zGDQiyu)DV?4cK?y;|Kr4vtY(NOyl&Ynw|bpq3!kdq!A)7&~X^rNagkdr>jL9@?&== zF8ym^rj=tXoI-N%5Qu&*I8>4(i6k5zN!mJ(;R<`=@RXT4x)6Ayf4B6? z-5Tpz*-Skd^2T?`MVQu{HU=SQ3yyec!a0-}74Oy31gdN&jI0}tDU6$AiPSMAo0@*9 zX-1sY4NKI9v$D6XVjB^Xn9D8;pRJ+nZL#BmiJS6-yc(5$va4bq6<( zj|C@tShHlUzHWI&a!Py-J?Rvm9yDRtN5Nu&7x;0lfi9WWOSB9wV2n5pf3dNJ;Z|yS zu8~<7#5JLML$mUP5=75DB7gca z0gks{)2z3QMnH?Juah@VVl; zr3plgGkw_O{e31rB@mc9ltaAr|DuvI}RFU-#fE%tD}P$Gswpf~-KbYO6>wZq_F zcHh@uV{|uk?z4Q@W$L5jwmS^irkCg|Gf&`RtkZm=6gg}+>$0gUq62|=S!5wtwaW2i zmZW;>D9~WCf$6?fF`*yPJK`re{_8f~yC)Io%B2<5Y0-Hnr_9rH{E6C2VcEs0^botu z`*r#Yt@#g3U49gj@s+1~dJU+I2TfsC#3E_ zkSvgo6y# z|E4G5<+BXw@j5Tt4w@N6f~g(sN>OS%9)OQ*~0B z*nJ@S>F_>qFk6hLwO<{VB`xc+Jw9$FUN2WsT_<%_AIe7wrumo>s0CqkV6pi)HCLfo z8r$zeicf{nS`^(hLoJ;l@;2hW(+cZ((H#IBgN(45=&r^fAICGY)8}7&(_fX(f*$~d zjIgM>4nRyn2y4j}4qY&UP2_bLe8$Pm_MYe}qWkv9v+O7JC&4Y?f^=)tCJ=ul+Oo^e z=Iyg??=~)^E)2283nhbG;@7&;2lIRfMh^8b-Ni6j%YFi4XV%MMj?UZbHQK()_w%q1 z5#HP1{T$Y0_67EbjNri(eR4uR14Xgr5|y%aPd)=a1SDW}z*UJ7c6l>`Ky zuq)csKq=kIy-!RCQEC10fR>+b_DmKb6R5vIzY3^H zo`zX=kkN0odz{ma`ICNv`VfpZn_ezLV(m|5$UP`E}c;#X%1Ekpa`}MPw(m3f###C4+ z5ze$OJ&=8Iiopy=<_7ouU z-!?r+d3m1{xwaPyWo3f}wij*7a6s3jCG9%})uRh$Uj+)LXUsnDTuIyt2&yDLb&A7p zf{+SQZkfCKGp7aNQz#Mn%SnHeavk6IE*5Ammp+=(i0_En{4)lkkJZEv*zn02J^Lov zY5OWyQfD-lDz7lnNyVpA?A_gkXLM%}kIT&5#8*>Tq-Ov|DW>T@rAx!j*6Qg;qRdtd zHtNB}ukpo2k7$)<-UY>rloZnU2Ii+_Y>)&?q1Eyq0psp zI^51ijHO_8T;MgML<1Mo4(sZctv6G9{M9&g(1mRDH%q6v6)84~xAjz%Y%wj$!I!(L zxq>oQ=%Hm4W@5VS9HOJxpjm%}TaT=rOqp7_y4{GyV8>q`9Lu-1@%KX-D^xl5H5+1t ze3PBGo^!pD?pyh=;zBFC64UjeSk~$Qkh2&4L(5mj>bGNX#XAjz-<1TTg#l&-%l_MW zciuzee#DnjGuG+8BHn<+V?B9T%G2t&rjRnXnFddWfHE11vd!YY8h8c_ah+Z{z}O!1 zqEtw``r>l14Sh4)O*3bQHO{Bh+)kSFbiZV=FvG3z#FU{FnV<{@oZ%`GX|{Fz17X=^G*@ zMUboGot$Yk@onk7+{uQ5+TS|>7OL=mkt-^6PB7rp;NWnhJK#=g8x=gLt60?3#Q5Rq|Uxly2Igyu1J{lqwHt z8lT|?i~Ps)`M7a+WIp1$MZ%dbVW1bu-Es1dBzpK87b}4D4PqV^7O#I^8qrOJ-0e8n zcSOX=&sh?wq~L?jXt37IQsjUS9Z66vlVj3nV{!)9FJ>Ld0v};bw4Z77V+1Ds^yr)F zKSP@Jml|3{I3OShwEr%oQT#s(X`GGh9n5U3e?-RrC8|-3leJjj#~j|iXzq9gSYlAo zhUy}~&^rBE-75+w*M{*&JvF1HGc#_-N;lk_6k6dJLfl!E?6c^C_J-qeh2vPFtDV)5 zt#{T~Ynz-HxbNit*wX2~1_AQ)dU!u60l&ep=C*ju;nU*u1pzikj&K$WaTZUhj$>(; zSu%@xFwJ==leRoVGP#QGT1vh!7)n$&Zsc1oBlqtL2>9F)8`Z5D-xmlv(kpi=b1pa; z$Cf}>$YP{KL9^F$2iTfmU)@|af)4wPg!`W|zx1}U8dI6n#L%I&p$hyl8TL{b79S@C z+@xW3p&e@8sg(z4jG2Q1P0Ppx47Jel`8Om0o()=@kXV+n1TEQ+DHOsEijMO6E#E_v zCXqA{Z+|76$vYt-Qf12xE(u3cWx<54Ak>&7k9a1HyY|C0XK;4p;6VC}iE z>-cxOBA<3fN@&YCQkzK0MxxBm9y5-==qY|dxH^Bl$ zR2!+mVtmM5GP^XNPYrKYzfbLGU$Wr1Sd`r2FIYD`9w5SH^nI>b1n;lebdKa$aRB-H z{6Bj7bloI+%TJH+M^pc=zpvxe!dn(v4y_|Bm7v_+w8ijeP5d3@HjB+@r^88tcWOzWbGe&q>aQvx_cMZcw zW3=Xt_@*;B8WvMn<_{7-3LYD zIHPPCq`2OwOCGvhv0t+k>~DJ*8WPV&!t}3*%3hQ4a7IL`TGSw`W`TCiCONEm&$l`+ zSS|B^w5gX{h1zD&(zmomt^nQSfJ}uNDdB=(M$)s%!-ZTp3pkGU{#e|9HI;G_>r#$y zE3{~6h1Gv9G*;l7*K;l0lO5rg^U<9%4`CSL)>};pk0C6i=7Ykg%KAvEGG(TG*qH>+ zt=SWAa3kFF{Vi9I*s;)!7x)|6F75SNNg3PP3DAH0VzGoag+QTf-h(byz|y8jQh43| zRaUfEP1oY0gmeBiG)MZZ3gDcskJcJr!p`4oTdme^s5y12UxEq_ENQ8!XpzG&<<`8nP2B4lCv%;Q7^{8`4;fFmas#a+5pQ=P4a<9VLlo{ihd)Ip)f zIEH@bE}{B{D6un6?fLi3dDd?c0PGih=Yv#dO$skXVhfIa#<-ze)5|y}^t1S|fM2;u ztI#=ZNlU}JkqmR$Y*a-Svw8h+v=VcY9-NW4ENJq;9D=F5K5&U^eXMIs%ypqM_jQbz zN9Wi-xfT|RODw_Nj_2>O0OJXRdjPC+!IW3DxZR=Y*nK8Fk`TQ0+Ec%18dSnEtRk%{ z671NB?sAdywdctZ*1c*lSlE@VW_3t?VI|I4WZt?aqDK8D5dEK&OpAL?s85gI%H47~ zBmi&XOELhC1Tp8l1RRgprfk)44v8t%V~>xwWb`*UG3T9y`E#&DJ`r8(!br-%uN$jv zhDS(ysVOAV9>lafg6i{RlQZ{RdN}<{#D5wycBd-{5C(6DWe!Y$x7CjY$L?I6RL-1b zShvr~q##fFx1)^@fj=wH=4W>cZIX27!_H#k{X81^OaKK~4A^@;&ug4Ly#~{=Kd}ve zI390UrC#gVjd_9vVyyMu_9xK}eN>=m!WdVKs0kSL&jO9zh46{T4nfvk$INuLZ zfsKiX3IB>yu-Gs0!nC-|QRTUJeVVKEc^O>$O5lxbM!;30;n8+)JTQ@|#$!Jm=w6yA z-&lKr#vfi9*}9L>c@RDJTmh`PZ20u-#7w={y70^&lOZ+{+Vx!Th$!O8d17u|EQ^^t zROUnm{`$uGPXf*%dn4`tS;f--qbvT`e)RuHQ`9rmv;A?T|33$M;pJhAJK|L42(aV5LzD0RLx={qE7}C)7BaCDvbonke`WG8$rqtmUER< zF`O-H!Ax3r)(1;kPjp^U&z<t)UI(ys%@`2k?X41*1Kaz%56{k?gA;3LT5uZJIkL5Efi87 z?KWJI{}MF`;ZD{4@&>;1Z8MP7hyf*MfXK1dRYcz?4oXgqr(yHn_pr@-+4#&N34LFKl$l? z@d3+9^=L{=K z(ezd16&00>ShBFdq@zzwpb3(j~^=R>4m{6MTW`Lqss|l zOb2LJ1n*w>u7dGQa1f8{%hzy9lx;bPbylKEjoL3cm-^lROGgHvFvGNpipb!s zdbR#CSz+daj#Fm{pdcZQO_eZ=MJiHEk%4wG4i-jP*vBi3lar_tCmbCoR^J(UCb^j% zn7EU@{Ropcr)QX!@MP>WJ}3($-pB6RuLL8(x;+(N%=!!RCxW7Hf>A%go{%CO!;PH8 zkbz+;zf=X@8qYs`Z&ySH$QS#^Q$`L4-Iq)Oootyy7 z2Tvxr`Itc42H~h=#mx_i6Px1bMO3Rsgk|Gi|CBi~K~48Er^MR6>-p!1 z75+IOD0w3x?=8$E(2;~UjP31%9+c6a{~0$f2bZmRAY8zgUcypP^s*t+{VnI@sh<=U zG_FzQTaAL;`iMtt2{EU-=xO8T0Vs%B-e~O`DpZphAR&inaGy7;;sPUOFMeOVtWn+J{H(%6lsSu_G zvn_kNx934JHgvf&XiSqbU{4{8rakIlffUPD*mb&=@OwmJU{9{m+^blb;C&*{|J^BU zXx^~6_f@Z;jRabO2?-9EEBPIh84JmYX=W;U#S>#zO2fm!W#LO_;=4cfkKGFfj3^;qcMv`fFgtX@K$VcQ^gu?c39%xwyvikFVG1m1F9?tc_`!k(?F`oY4M67%vX*rNX`plXg$II9BZe*MgFKqnLl8>Uc}P~ETU zGK(u7jO-<0M3J(!^`H7Fv5UtOeXQqe`)2}i$kxb-R39sfL4qd)99{E{J_t)@3$cGu zMfR|qP({{isin%XyXihE%i^(4$wQiUwjFsT4*p^V%FzUL)533Mai2ryKDdVG+@gom zbsHXgO&MFoU}TG{S=k2!!*si6&YOJQ`(*Q|>FHO+(-PNJGMe?`=gRxl?xNQ~1uT}hxc9K?fJCl&C87JoB7*ih$Ws$ zs{Wxw|gM_(564U&|oXAi-(^Gyy zM_Qwxk}Ap)#-XZ;OAs^rc1Rrkat8*Y$FF0iGfwoJ1FF&a0sU34lgg6TvtP$woZnR5 z|3tW`m~~lyb;}4-IQv5Af)#Uwt@=Ahvh%_x*hg|89>PgTM*eBWgx0QMczhqtH+;a_ z9@zoDAnH2BS(kVmO%DBHFvit4jpzet!7as zguQ%DO6blZP){0zCg-l6X#~c=6DB@Y-zjB?Bqim460Z#^<)D2|d90ddG`t%aO29Ox z(+@v0>Bv+$SUVX=P;bvhL>O%JhLm}Nb3X6ZE$8KeOarDiEf&To`ao9Z6ZvOyejd`z z8UnqY|EzB@)>6Zx{B|xs8sXM(P}Nuy6@0X~1B-WRQs#Dyf;8-yqb3Rm1w1TmF~kM^ zEHOM?6EjOD42y@SUzc@C_C{Pe*nNftxl;1cI>dR3;1*@(Z!{Jbhm{pFDRVSSQzWrqwV{kIM@oo1vNX5TqigU! zw0eVSG_$R-2mxa9sWQPUYf*5B@T;M@h%ZHI@}Ckj0on(&&d3>EOI!1MC8tvz6!?8r zuD_fq+GPinJK@3P&fJj4g39Q=2HO1-+meRM@0SEC-DlQ-WZp-$lrPV9plmplgfs?4 zRgrW*ac);Qx`9MgLF%|baeQJaDVqeMFto*235x=;g=aevHnYX7aMl888?I=?7z9Mo z&D3kX9a&;U8^S!Z#jwCLS>o<=J#e0(Br#ik#yEmbMCm=>kt7I5gtS2aSg}s&yui8g z5@zk!PGrpyXz5fIZBQSB>sFf*+$c9T%%X0w%>pXC%kSEOBU3UOqSc7r!PwzzuM)Ua zDUj(WFG}kWgcDzxll0nOu6Z?Xd)6S7zo+fs2fJoj{@P7jC~l0jRr|H(IOu@h0v)$O z?4fC*9e0Tg1!$(;YZdJMsSdx_DcDQW+`$f2u|r$t=bi+w@pBD?)dIaWN8BOQJY=EN z76htr1{11K+6EL996!XF=+uMy9$&f!V;pFCruT(G7$O%JPY`oX@RrbEOxBa?VG}B^ z6jjYN!p(tY1Qte`jl|{>-|DBYFouE?Q&_Ona@q{i5w#+OVdWUO8bIrAg)U1#hoe)5 zGYobL@KP~Nz=GtZ#4%P9Ozsv{r~$J}sWkhJhb|Exg?`QQ6$3^KImBGq|0JT)=_SdY zH`SfgZJ09jn3^U{7Y_f?AA~k2rAEh=7dq$3$edrTPf`!>qQ1TVSCFVrcV8woE-)vL z<%jx&^4okKU$Zk*JG?8C|DQ-8O%hoN8B^>~=VGCiJ)yL#k*Zp785YMdTtq6%gli@P z?11o4ty$?hrZCb% zuYGuulsQE*(Z5^=Ie2mX$vO^^l!gviK=iM?!9w9QM^_mei#F$>)P!G?nW=j7NcNM& z`T#6HVTgQ&JrXOC9jNGKcY)$Camj!(wbJE5?9G#52do(lFBwOP$ra4H<4CM~c*HR{ zDl~U7DPL6#e`*y@g<)_8x4IgFe$%S@X{P=AxJ*Ml^fVagAy^bH==V3c*NUE=ZPQYQ zuVmCPxBkfJ(}^M~^RZrarc`4TSfA5+sd2I=wFrs2#8mMKtt^FlZoo1CusT(%?!J)s zMm?lxA}=L-lVEP7fBvQb3Vlu}?-kZBMuLYvY?-e9l|pMxNvJ+yYw&hqxPT-hctFx^CARtq0=_BrgLfiG`k_u!95li#pWlvkY z#jE6Pb}h_ZFPRTA2*F1fH>JRj`Svfcr2EEHfP5}3c&^{`Gpg{YX0|$Ox7uy&Za{qi zSxeE&HJ$E0OJTDMF2%X}diVl2?geW{ za9OE(G2EY`f?Dy$;DS0-S_E<(PiDA=g>yZGGbyTnK*x|6BM&9T5kKUE5_<-8%>6yf zI)63NuW2qCKVFI)Jr30T{<`|*0(^Md>HU+xGtt@-sM~w#?IDs?$e!-}*^ztgcH@@?Df!!8RdJ2B%swZC}Owg?f`6NKoqPiK0cS?_Jo z-w(5$+RQlCuX148-)b7|9;JL?Bfni(dEqdP-qgUt3M5nPmSzI(ojsZ#d|TNJyni0pY-wkH9D%7qAJI?k2s&5Y{`vlplDnpQh@sDkaV&Z=C7d zMq7j4D5SO0=t+JwDi~MqQ@KEXR}qme73cawC7F(H-_C9yIf`vaJx|EwM?j7Kj%2tZ zNljO~FJP8H?YzQkd{Q5&dPJC+frdO%Yswga23(IezKec)1W6XvuanNe*YuZNq9WUo zRG2_iUJD}g0~<*9#R|#EQq6}vG{C`?gtIZ}q@nS*9#2}L@bPWGJ?2e89-{Wlz4TI1 zE868<>w=sWN3-vf7H6R236emv$!69tp4*P;-I4j4ecZ67(xoV^Xad_cL|2d3H?=BUJ}Le5%FYGJ%`oEXn^>A#Cn zk31Xn57M3XQeP-dID}2zfNqw}iZL|NFjeX?>i8lx?QDT{zizy)q&hE1$UmA3MG=^5 z)1BL#>ZyOtQ9fF1pKNfzCE>%8gh71t1%&RWl&4kVFN%O-x!0_f@NQIS;jM*!cE;hV z@5XCO4~|N&wv=9;I9<*ZM>9@K%Kq1@s3(H(p0nO zJTV=jwC8YHG5T&t0{j7{S(Kz0C&7$vZB*neNYE{a3xvAG26@lLMWKO9EL?^(eh#@9MR$MZzs*HQ-5Z#42FMhpXAG0T1o@cDlzdC z6Z%;%ExZQ-ITA_VS-`b34NI--7vy4eXbjI)5(#)J}3GhS9fo z@L@+fPT&8d1>XK;t-iZCdD?Z`*j|5})tv#pn$3N<`O<4L;Zr+M=hw%4@^{_Gt z36?m;A-?$Hdwg3)2;^_K0nop*hp<$lZKpxfxt4{+FlJ~K@A{n4wMmS1B6U?k#8kf10&zg^WL!rN0wrcjgO3W! zeZi$N9=_&g>$56mNIG6I*D{-rX@xic2oVI$V;7|xafoSu#!Vu(Q>)(rK^yERnW#-m z43tZ&Paol7c^WO}Taa0i?4cRvX%&OwTl|YH{HB9b~GhVR7bZ{*>}@b?qG29H03&(po+0xZ6CY=wid$?)b3cUj}!v(`0NOS4{UJ@;vJ6IX^CA<{672iZ2%0F|0w9dP$gSOEHL|3tgEa$j79cf5DyFAqV5T z0)r?pD_}55Gmt1`@)L+)fX3IBxPB8T`C!-Bsj+$I+p?q$vh>N^>!5@WS|uB~vK3+F zMNgx{3nCVXcKsve1O+3$OZc>;1wo@_q74esCmU)UlxC8d=*J}y6Nv5}H-bqq$m^`Ctd}2I00A*$?hPzwA zG)pixE~Eq*8E#Lnt8M`kRkXQAfD!e#?k?J`BtovBd-x!JI`eDBhw{@t$Unhp(5J zi0vzb+LCR`f!|j|Tfhn4SHzKibezAa?&K4Dnwfr{Ia-wHYg~XjP~a5J5gg~rOsr;T z<_V>BF6+Qk|Iao*)coJlbfTiwGMBwu%{ne0ZAs>!hG9x};=|YA&t&QE{-zx)iDUV{ zf7~g543q`~Xa-P;Y+L8GDWwaV7UI(d6@n~R>!U^Xf`dF_C+Q1N zn?i-~JAOzdVi~1&t(fDAy08_;TVxYZ#{_xgg%i}woDi@jBF4%=2ZcSP1EWdDx;&SG z2^*`h6DE`*tcFgOzjzu0MVjR4e@qxfyYpjj6G#We#N^Hw{9#k68>1(w6?2H0i(RJo z$>SQ*W+E+Z1BC_8`*8bg@ijFI2+y||O>!(c1<fw#dwIh$|D6;!rZ zU_Ypb1BfGs!UFGx1CW7YH9#Uqc@oa)9es(#1tTqLu{@!RP4&2UM_uabq8Qnhri#Sm z<3!;06T`5@j$y+%vj0R{{_$085cbeKH~vLtgq1sKW}SG0+YNbKU~&-olk`d?_X}7? zeq4ES%jiCSaV2lDG?AE5Gzl`57WQx5Z^fizi+ny$HQGEPguj^SJ19H}kk2D<7P-h| zQM5!&7|RsIQ@yN;D}RQZz;flFv0`aqos3E|8R0K2s3AG?f78$unAJ*0^ah{u(#ib- z>sCahm?YPH^0Ph2if+!fW_XdqfF;x(+=rJ1rRUTJJ4OZrviEZ@oBg;!W>9K}xK(xV zj|R@K&aBpEy%yU_X3yct^u4>#y4fgy*EzKdpsMgoT%)c?NmN2x5Vq~x1(I5o)tUmC zoK+r6sdVo9%Q5SW?z`QmNr`sR4o1Vv39KR3lIjy$=maMFex3weJn*-T?xB+{&tt-J zCo2&m@?JL5nUX%oEAfrIX-C?jQZ+lD?!hd!uWj7H8FG>iiM` z5Hx|H@3Jh`+8=038ht+wC%3>~d zJR$|EM5U1lrv&5NT+M0~5+)zQPy-##$8=3IEM(|oT(uaXI~cp&u0o8DVpbZNWJ!>aAJ5PGL(Bid!V)8YI@>)>W@)=YPO z{HdwEdML5YVIk(rf1yXSf!DsU903(;I&+;Z8;^(PbF0tdH$KXG<#S8tkQZt`tjW`m(yB?I+0;(`mS;xwOIl_)fp;qHwBfXHdHWe63I*}Dw3vF$hfz}KShCgT~YHbx92M{cLJdFT{ zi-(7OVN5Tffw#EJ6xyVwX)?@b8i~O|KG{|)WJ5@rRI6h-Gz7bg6joOJ9nn?i>uu~! zXYm5LBk!R^)ty;{k9W-PU*SXb(`wTg)45A{f9J6+{EG+T#Hae!$;O<4H;4yt04Z~e z9!3?Ep_O#8stCQIuRZH`rz2@pYDU9EGR(MHg1;n_K>4O*YEwn_w%*E|$%bJq#9+=T zwT`09Jc8HQL?UxV!U{B*%rWtbNg=W7HXnGmkEskL z(8rxrM{I1p24ba~7*p5N;K`{d@2ERJ)UA1-g+J(T0^fNs8|b>8x85a*3T_GB71cjQ zLb#XscE@)b+&8pqMy0+?V;ErLCC4qFZUz>H zOH^AM8VD;iNWN{0i7v?~yui-G#JJq=vQqTJxQc!yY@$DgNK9gbW#Lpz#nbTRnwj9o zu8rxa;7J12hfi`Zmf5PEm}`z!HsYHSmG~UfMB!pM*t)U-iYNm7EW;>jcdIAb&)GKU zG~FlKGsjey?N!{(D!AFpjaScBv>xqff3eWQAATe=WVidB;h6IkP{|9Qnsrg3eGHo` zFIA0Rd3fl7z)ax%(ypa>Foou%%v<3+Gh!Ham~P%tv1r^DO7+8xaXL1neFkY8Zwp2% ziUcbWN=_6+--zt6kzDu{K%6D)nCc99AhXcx-uG++V>k2@Z(pKf+XZuy&rZ~a_WVQW ztWwwlvhXNUi^kTDY77&|U($^jup@gx<4QUs_>VTY%hKzW6cSb>!*^GVc9Tou)6%ny zG%g{Tkv5v9+9RR~5jO^Zkzz!@wI87xPh)$dZ)$)n4gm)}gwf?tMr+er4PKsq=MC*R zr%-+&T|N9Fi!0PVfSH=7G}PVn7%U7(W-|I>ZxSt2S&KgiLc;Y$065@w1+7L@l^h$F zQ=HXNMqvJGIuDd7p<9gM$7|!9qLN_RGgm+*DH|yOLyu3=Nl=-PhN_~_0hWdw_T{%C zLlQD=6U^?OHQkK4|ebmOl(vzuaVs%k&~9>!R+*=S~Z*rZ^`em22*wqbcP z!|`6mCeY`}Hg0E6+oD}~ueOfyv|8Nu=_v3jEFjaKtCu+TL1TE-zt+Ffcy2l(UX&ig zSzwT_3DHMVuW+wabESv>7+lWT^fYNGcO806xrW=;Qhna*y);-XXnDAS`32vz0<~mh zV(fSw>x7MY8jBt6#+mI15-`+RWXs5$`ZVljeKH)8l6})iDZfj_VaKV>mqR254kTyc z-gUC>nHi&%pH#?mm9&pNf{Tx5RALc}mX?;k7z=FT48v817gOX1j zf@ZD6^0S!O+X!7ot*WB(Wv#YS*$`jMQa{2(*JRN~B1-%B!7+cN3df~Dtk%;SAZxrBZF(TX z1vf^^wl<8xwhS>1kAMIdjZT;bIOX3bGvvGo0YmxJwro{7$+wg8NOOwj_xSmnqC|Kv z&qec)5&Pv>geYdZ{VFYXs8tju*h@6ad0h3%L!zO-fBZY*_3-KfFaOfD7Ge+BJri9v zbG|S$t9lh!+N?d%J9~>@=xjS5?a=qRzFVtyj-pT_nXCM+Tkpf(zlc(egTl1lN5J*4 zjmM*{U^A@*ma3zX8@h!z^)RJtO{&NKv!_(*lv5F@>xgL@5vKao7`(><<`M@yuIo|e z9leV7d(UU&3q-fJxYk1J319%OQ(OcM?EoK2eGKLe_0ku#y!S1IQQgeqt4o5PHygtL zg8or&X{YQH`JF8kb?PFGl&zGjNsU*VRE)N!wFZK^+<1De^+KhhIioKBil2H-c0Bi` zEU;QZZ#ncH`wa1hp$SQ8@Me;(lZ5U}T?DeTW(F72??)hk~~GM-eV|Wnzn?}#f#iV zJ?a&>btoG`*PbB$Vm1i#86C_XFO;ON*i#{CIcUEtrSY2CHFP=k+=?7c!wfO+BE6f^ zy{e=qfaI1P7^Ejq;H%u78=OZ*zOB@JeoGUk`!A&mFojBQVSb)De!|$|1< zEO2DmUaovEE(`m;A%&Js)en7i91wsy#KSBhK~#RplP>!V1+WddXOqL5D`uX}n`31R zoDzL1c^P;Ay0?ku6t|-_j(%N{J<|I(DMX%doBZ-n1bCDbO9{Bzw49VLEJ4nk*IhOq zDdbx$^DMOzC%)JxW*0wDU5v>)qOT0okPMQL+X*u1(SdIdiisjD(sCR2R4=7{(A27JP!e+8rSJ`17*U7Y6e|AH_;fjH;rT>$!I zdt9}f-tFI@nS-SG+dHS%LNxXjiT21u-IIx;|T`d12x{Rm) znBWFZX73DE?j&8AHNAFt*sd(Rz26tW(6MzUi_*!QjuSzWnBOvuIG=O}5-jGGa5+ zF*8mM4G^0SQGT=TGns{?bT>3aP-^eKr0*~CBk zdpGf2mvG(*V+BMtlU1hLY-IcbIv3*Km9q-I!s3ilitn#A{L;6BFFl3TyR{3eT9ibd zM$N_M`pcsWFV*Yvp65jFzTytT1I|{gN_{);uJgs}$JnjMoqX;lTN+z?*RHvyt<4_2 z_X9KG<*9LPiY1)bO0n1t#`tPEVsQvu`U4f1=ZWUJlP733AmC#_m>H zDLq~d&Ru5LRunKM=Dcp8rcF9&k9U@iAMM=2V6|N7#AJWZF&dma2VMPEPNU-Pu{yfWX1qbW4z<=hp zbNu-z4D=>1+@}opklPF%)_%%=`Lus54Dzt>`;?zQTK}sbjRPzHn^-6ZYkMsFLI0w% ze?}g+id$9o+q7w41*B?wpN%KF_*NLNJscxFAQ%08sQ##5Ae5chych}e5xO|$C%cIbkD$S;bB|I|*Iv z&1MN@4~aty)kW!)d!n_Mznr{sY}XoEmqZ6o=na46JmM0&encpmSl=CJ;jaNB?1Bak zzf2zXff5SiLd>ad(y>w;bI*K^W6r#7oWESG2 zmUq0WseY58xZi5oYpUht$`g@akm71sc1Sl)$jEg<#HD%p&`Uvc@(uzk-~J%r-AE5a zX~G6j!7y)(@Q?wBki-Dz%vLB&SB>hrdAl)aq!;D{W+sL_Dcosd!SNKw{8?)o32kN|kbEs$w$@P3|c`0>J13s;IAt zv(l3{kpS2?I_T(k-#0usA1DMr=qG;*C*?ZtPM!__J;>QDLGTws-xopf071|uLC_O| z;K*--@9p4bg5YX|zUka`pQOvl@h2qsJ0u9#ptsqr%o>2(HMs6O zpYD5p7xOjfB3wlt6GpWjSiX+xi`6gn^;T$N&yrNDZ*A`(`Hbf(RsxMC_Ja#JoTp9A z_p2U9_A0h(ZRhJA`E}fBA653nKQN64r*`H0%{{EwC&gTMate!??zo|Ax8CKsK{mciyy|aTKcjWsogR^(UAFul0-^72?6x`Z>t#8Z1UFCnf z|44-X!(OA0L+mb^9snq|`>(db%lvmFMTQQR|5-+Kp*drZGxC_LtCS#0z4V+pC^uhp z)krU7EA%G`f>vj1v+IuHhYK*9Q4oV>r8HUS&dLf3}cZdgO>0>DV8AAMRVN?uQhM9#=+Oi9v^mDIhx>_>1?`8?bmzi z{fs=>mcF-QE;J3mvOwj54V!FXIzed-0%Jd|&d6q)vsm8VIRG%UhzTt`RD{sKP)U1% zi8bzgNJYkC9D>aYqBvXP#{?h^sYGyD4HHMf2mYRDlN9X0OT6bnVbq^--I_qPUxhji zx!(T>Flp6)C?PFIe)^PSjH$)DU6&7Aa(QYbtDf+pQxj;AFpJ zXlBtLHtxd-Hu|d4)zY?Ut(K?2N+q5CeqPAni1)khCXru1|4upS>^^FbrJ|tIpGS0r zlH6ger2Gf%8|FYHS$}@Tf80JR3{;66zC+~<(|)BQS2Zhlw+2;F&3$$;x#1#-f5d|> zfjr8(3MD!1xan)=7`~(Y{cqp%q$$K?s)=%$E66R_!PLN`>|Ch4JeHFsLRrR&MFFw2 zQ3OHYQ9!1SYm+qasU|A*9NybSH=M9I=bvXdN;NEzF@~XxEWWW2c{iDI!`Q1TUs!m6 zRz0JSnpPw~Ho+Jn)PtcXJk%K)hGjOSrp|01mQlr`@Dr&m@=}5@IYT|0O+g+A*lk+* zL_!~10aJt&Vz;D+kfEx00-TDZY*R7UCJX7fa1mkkE9_Y3n0Z8^)>!tP2I5JgfzYV1 z+^nB!)D_o_j0@S3PQwhPUv@mHkF9?CvUC{Yz3-CVKB#ha?7*yCuJI%VC1r2@a8-EO z?29g?dZc0;WqGlJPPZ1-nVJF%U0!Jhcyx>sI_eH_S$+z`j~Tc2E?vR{6y8}rM|t$C z@MS=Qy1fctf%2A!VJRUTXX2!B_g!H^K9~HUv}rzb(w1z$WfikYy^LvaDT~U~(S3P% zGtNJ20R$-EvV3auZiNvs2D`*jr3C!!f)Hp0+q}}R}hS;l=x!5 z5DB)hDW>q9exAx^U>l81kq}zM_v3b1Uwts4 zOxYl+gu!cp$+bXgKTw2a_x?k{dzv}$Mf!(8M7{@~a@vZ+VhI^Ep?MeR8zne3RNi|B z>Jl?&&$M;I>?{yr5zm9DACa!0WgdYDQf@@ekr68rZ{CS&P=r8CDpsG1Y91F=G859E zv$L~QArpNf1h^T8Cm3IcJymzi zha&G|FSqS>@l}ds`>7K3E`1H47*YlVe62*zRe#ovRwW*h004aDX5#E?;me}_v}&zV zDb&Ha)2OD*v|%h+DdEczSzE}__Pd&T50*`sR;vopEh-{JbRl?r)vy)2lmG!*V89l@ z-**l;-J2iNzm)xJ_IjA$3sZySe#!2AU<`%d>igl5pl2(ar$ycS+Qj~D<9){b4u+}i6y1s4eL@v)*@rXR<{-ON(dCvF4>k6__oV;h_ib7>o;B_>+~pa`u6>y;vn zWJscMlnYb6@vpq|d96z&V1}aWqfvxJy!E2-a~48ww`(+C4n?*_bR3!aopD)mCh{Z> zM|iD~fg&g694lWg*kvD?M1+&8;2t|Xkd@)J;&9B7)_Og)x|!H@aoVND?)}y^r}yN- z?)%n0UT3};4i&c%4~1%@jRbR16-NvW`s+;0Jq^NL5q}sK4eXmA(97LC7687zw1abT z9R=|i%MklhP+jr2UOqRy_uf7=z29`n`TjQV_mdmwwyi>#Ca1#miAXLx@H-Q*nzu0C z2@o^d+0MoCC`-YWdk)x{)nYeLDhrW~gqp74!)@Uge4vs1N4tx0Fj!=IT=;5I_b--fH#|JM~ zPf!&1I6u-p;%raw?%Vz{a?xea*Tuas!Q~zIR4>PViHZFe9Fqxq;RJ`Br)zzwIp(tE z;!;Ivj31XUaz4R5jq*E~;r4rN^+iY{9X>ric2mBBWw`TzPNQB1*ULp+w1&X<$Wo2r*)3-Y{`^VkbF4x^3^B~(R>MOys<@}7^ zXiFlzXnExr|9g$7+m{#L&m-Qx#2v$Hb(MExYPwtZ+|<0|bT!kWMLT}dKQ_YbtMCY( z`I0`!7ZoK}!ibQc)KhMFUv<}9tZ+OM=U&(p2rqO}*6@w002JN%6Lxy;LMsaSb@KL=Y)A3pehB;Wsm*q%np zhd7`BfUh4pNk<4lT6id8K&(^Q}Irl}pp=9q!LA=n~>Li?8rzIu zt|_LhwROiRwJ0ZJc6C=}c_-=pQn10G`!KF+b>~1eRf?9oW^Yfl~HCB#6?4FfbkNRgHamiUWO~g#!Gsvhgk)% zDkvf?P>liH3+OsAqzX>2B;g81;Lgiv9vy>1u;H{QVe4Q<+$iwBxcnRU`D}@1OT8m^CU%m$Ajm{IA0B)v+UjSk=Zy`W=ON6jOS#_gW>})rY*~>5g{!wsR|Cr(lG5HaB7uQ_zoV_%V0A`(TMu}}v<4W`D1?+da56eD)ijXP1H znF^si!{$`lC|<`rXxFN`enClwDEg@-rL`%L_KO(HkfLX!6ETx9DG}qx32LIIDKvUS zrUmo*{v4AuNPkjqs5*&-un78BR5W16Cw*w={6tOmI!P^y@c1nPVQ5K4FuQBP$-&dh zJT;SCG89nb5YaqGb!0}ND2*Oy>f(C`4Q;52r=@sl^XCQi&`XRR{6@%URh$_qKUi&q zSVcWJQ7`2)SjKpS?zktpRIDYSMak0Rz(vESBcx_-e_=<;NtYw>mXVuacxYB(qwFjE ziyqsyqMVI}jK1^HQIX9M4LtcLh&(V*r=aq8wtSzqY`%R`Rm(ifN(@{jAwL8XGt84| zg=S{hdq3Z!Wpcn$@k&mLF%31$z@C(45hpj*+-Od3Q|+1fEa#>3Y_E8>nByV#g3<;Q zKzNvp4**mLkMJ4P{1D~6?S|Yp0dCtaw4BYbMTJlDy2Kl+UvJ@?VoXMi9>HI zP(ELW74~sOCk!@=9VnlPS$vPvO*XdjVErTH0_t?`9}Bl|%!$uz8(xNop%3|$Ei|J3 zhEFOX_FUF%XDbkm=53eg9sSjM68gIK7ZYla=BI(UzLdfQ{)BlgsQ;Lw>GHRU zf^> z9KC~-u>nd_?3i>^ocKdUM5JVr8$VJ0JTbB#3exx{R*+T7=%7GKU@RaRl+A$dkV9nL zQ8KPO86VFDT5>Cb?7Mfhe(TL>iL+fUuAlrM>{=ll{gh~=Of7a{gKMPBEw&?Tha?oA zc?7DCaHP){5Wo#s*h@ET*vb-ESOEZ{cAWR;#KnTR#4J3fI-vg=W8^~~5JM^iIU<3| z05?GbA9ctEEVP)MXy zj^#zg^jRxGf;kMy4dnr%iZpD2p9=e(KeaWwc+jpawZarr=^AENoN_4Wk|Ef+v|pm#Nhg#ObD4?Q3k zd0HT!1#lm|MFz)IO^6fuCBP~l#l$e7aL#D3RH`DAgXDfz8L>Y&ft&ikJB13GE#S>l zPE}Q5wQ$*SsNv|dqhHZ&-Nl|_i#63MexDqmje6?9M@-e?3ZsB-%?T3ap!o+0G}3yC>Y z;Jr``9~V4C+F%FL7-&5cn27FEKqmOjEp`FZ3|5lSw4xDIC4Y&T``{G1C^NoIbigLd z^$vb5=XZD1)A_o(GBfk_VB@y^it4yfZ=!iMHCyGG$}MUg7WUVW8yg+ZbF`osh4r)4 z6Q5Q5L6Q~9Mmx=}%M)u#OTG422>~{o%7pNmh$cZhRQchbF#%7O@~i73&{|hdu;J=y z<8!9^h4!6T=%vu@q2`b6B(M1>_4O{{ryJ41%o-$T$8%9eeUZ_37DfUNANv~$lHAyj zf=l(yo{MSx*1QPMu5w;s_oPv*s~@4uzE|)du_g>L&+Dj0((0|Q>C+zbJ7ixYBygjF z9w<)8UW3~$OnJCA5uO7RMe=e^hw+-Y61#;ybM`k7r;m*p!z+-*M4&Az?Z@Hu?cA-%hZOXgxNAqls#R_>6LcX+nZ7tZ$>>+xj*^a{^{Z43azY>=$h@zrwg2hPPvdWE zX!*GBb$~mZBm@A)4lE=)`37FZiVJG3^UrzC-?1Pm*_>alg(cauhyF3)UNH{EOPEiFimrOp~z=9nvc+~ z&}e28<``#>x7C0XhG^xg8FH2##wi%rP|q_dF^VJEj#GMdo*JS3YKk(b+#+6&X)_ls zP_Z&!2uQl?HS{wy=0?g#p$em6MCAK6Jx0S5y`e^sv%y)mp*9dH!44&ci-C^SA4Gpg z|MwB*|LMmUqxDGgB8HB@K=b`j!i6i zdFG)+^hEkRNw_}LVQEq!#K0wg(5{rcVs|K&xz-AmtMbwc^xxHP*sAUbJlH$m@0wh% z=UPr1`L!qL}WHTt_V%!j5 z;l7)kS4gLBK!gX9J#7}aSlRfW=~gRIy5lgJZep^!o1N&U%s=rszXgW*;~x>KJ0PSr zc>nR=e1lZ{euHo`e^mJHbvJI3^MHuKonr>$W+G3TuHpUhy%OI52Cp?yh_4}1ka?nS z%MLez+m{a?;Mng?pe8B{$+#H|p zuw`~??DHAk=1KH{}Qf5QWA$dLb~+SyS4;Pv~E z6R8aN!jb{W3O^i{`HaS9H^voZw4AyQY)jesDqR`iFfpw}_-LXbV?{|^OJAWz@+#fv zqizLz4CMzal2+;UB?;^Kg(02TA#ts_B8!6^$TRpe<}?^h#AdB`txtTt??%cB6=Hl0 zqN3Zq{Z5`jrBoE+tnF!uUguIz(~^6}@%*2@7W6WLn5g0me5Xjn7NrU+R~R;OYDk3- zHD*(oLd!N4c_$;IFa{dkyNo!$U2p_!r6(>6@E3C)vK0anG*<}bvo?f%#Q9oGvqCPc zN6b(=<@kLL1nPn39`jTYHV2fQELe=du!#4hoW z40(ZRSDdK6czP~yQ|Uxgp;>*KI&+7Ub<7?dZ#D(XIm_x`-M5=+TW7v{Vs#$gOf9&x z(&w1)Sl;4Rl@8wVZ@bjF#cId%9~rkJvD~o_2+Mdge_=h{WzWv;4pq0y zEjQ<~m_D{n^;thG*hKxR`EAxVCXBh3->}FI6CRGSJy?r*_DNX$h-05&!>mE%ucs0H4r}?t#5Vo@?*7PNiJl7Ju z9*=OO?JJwj@v5-e(So-!Ix750{{I{E*@5{qfEmdWnOY~)Pb4_Kki|_8c*O&Y<3ZF zGJA*JKTcJAvHY=}qs7xw`4+JoJlc(+RZt)4mWd^)>!NSELM zYxAdf?p`Bc|2I;(eI=YLQ^{H*@cV5Hk!fB7@{<5zxmN!9=7xf<3z1y>w z?0W_$um7@_{fpj+Io)}8U9>MPYx8N@(A$ocUP&g+HqmOc^8&Qu=>(J-)FAs`_G7qv z@D!Q)V^PVZbUZ44@Dfnb(ZK>()KEm!;QD{Ty5k(u<<0Sfrv_6R@&*v4x+2YnByN_m zzZd4GJ0w!ol2nUiuRO<*c^AKXT!h{6Y}PK=#qFXGyx*mqy-91AlbuH^ohgk5(VRt0 z@xkEK;Zn~Wmqs1N00Am^WZ|2M-J)qiG8YN)RY}U<%QG}0e<{n9rl~F{fAhY}c&P{x zW|!Vn>9k2m=0$Gr6&Wav*0$hE$E{Wem;#f#Ybu6nlk`Quw9EAN)W|p|mr97DJIRVh zUM7?|$b$K3(I18OHywTwXh(9h*d4o}8n>3=s^_695%M>mVa#yJyU#@=AU8?9;?YKQ z9p1!Az0;fycROh?I!lcWUBn56a*s38#FZiLPCJ!$%LB(O>Tc>~7upg+f28 zhQKEYN3ln#kY%IUh}VuOhu;`@+IzI(7As&xAS%ETAbzK4{Guwp$%l6FR}PG&Tt)kv z)?DL&x-iJB1-6tEjmFHE_(7&f-PX5YY!(&=9Stj7paL1wp(wC16hhDR6RatcKcbZ) zNv$@R!vL!^2uX(m2*F1Q4d6e`$;>>brwT>e)wGFiD(hz1i4)03v_zqHW$c%iJ^|A9 zc>%89_g2Xyy>}AYb3oIa>m9h~C{fmkw#tfxx-VBm9+GxIb=4o}b0KA;5LyI?F5*T{ z4GSYFHs$bf`dxiQ>=&X? zX_}GIDJf2H)KiPG0AB1B9P7l>wvL_9a*zr3{Tyo_=d-S@`KCFj{z@0PvZ{b??V9+g zT1{Ss!^niUYh6KJZZfL3II1PmLRE2Y?y zc>cBDZQcj+leroE%sx-^Z?6&FM;G~H7hmeqb{owWozpla_iiIoiP99?T-ncWcDy}z zA611k;tg9}WpxlwOAkB0Nv`8IY+pk@F`l-b{qD|6YV20x_FaEraVI|ct~~fHgmt+$ zR4^>Frkr9=bojQ|&@?ZOJ=1S=--NTca4Q?L>+5-WHgOu8D?)a=uLc`UWR46}dYYZeOm8LCu~*&UxRL8GCviP3rOVp8o;@4|R$rFZ6zSwSr4Ra3 zG|p%JQuN!9hJ9w{7W7a6O0MpAV_iT44of?k%@dJR3)ZvDKB`ic~@eb0z4RmqRG zpQhnhyOg@9$**AeZNG47Wft`=Wah@O;`U+-cnjaOAC2Pn#Oq|`g{V%b3FZu9jWrf7 znQxaJZccRVlO(NS9t!D~gDJ#n^IuYeF(NHU7d|ef9hg-SLU)WQIt$oykw_37ofv1Pmp6#(FQ>H(? zoT{`Ij0tkQzc;{n(@N;LNSECx7u+m@{rGzJF>MQsAC5;Bd%KQ_@@TWQ)oOjczj3_J zQ)22}`2Ljt1X|b{#C7z}=sb>ejOOAI#=8IcwpT;z50)UNoTjAd8&EYGJ7eOENad_1 z;M^X_QzDjU&gIqrfr0?7(Q2MOVc<-==79Pgd#VRi%1N*wPWA zIipdL%J#HiQR+gtWMO@o#UP?Q+QlK2eB^I*Q_A^`5l%gRUpw$KU2lUb7sY{v>szvx z?rUon{r5rfFH2~OKM(wvSXQ}{6du7!^o*W9gpaGxCq#NQKRo1oSrsLc*aHh=(0Y}( z9g)Mr5D<$-83Ta8h#8rQk8mi9RwR{J-YVzL&Tl_5W-iGOhpj--KIcA{xk5?B@l+!z@i%Z9Ds(LxAX>m zZ}xySZv!u13+#V`ZhnKfm4A5&S2EUDT>3;=+a?Z4s^ z449+-?rborL{CLptI+d^P3Xj z*UOJ4`}y%y3xpjj2!oeY038bggnD*kf)P*yCZGsF&5{dHuDb$mFO52CcnSo>%gAe4 z`Jk8&cK>1cqM?dQDefCTZ6-Cjqgx06OsF**k4R^+8duf!>hwo|fKJSm@$471c9mqr zr;C7+CCR4ac1gK;pKvD`y2);+7|w-?Y#NtS5v)r>aK6xqinPSW*528dyu?@18T3x$ z77LAww#_YMi!pDo=yF6K@%&p!Eg@Ym567+j=h2(QvY6IP+7t#GVL1uMdZ`sR7cSEM z_+;|{6OB!UMlEMtP7eCfz=Mg(AO4vOvfCEJ6g(rlEp2lOEZ4hteKY`*3d21S2D_OnOHYH&ER{>aD+d{g87HN^YpO`tZ6V z)n6@rxbE%iuWy-OVELnF?&z=XoL_MH<7P+*F>XYifb<9XNogyl2HC~w7 z8Ut^V|11J2X@l+N@k~=!Z-w!?VqC4Z?9!i2UwjRr9qcDbka-WJQ3N{qKR-Ea#x<8d zc;FUCdqfa&v&fO*cxnrxG9h~7n)-35v%YC(drM})oJfD@tIY(bDF5lt^?4#)W8J-*-PM%#%;Od3;|^S+_t z?d#F{BnqgNC9xG;k~jehSz>*;WDI~f;qwW4l0s8BiFt2+w0qwW&y`&!=-qMxx*DK6 z3GiAdsDUtrH5t1*C7=wiB+EpVA$|vrJi69mh-5)h}Ap{nTxTtcc zyTnY5r`%)`K|U0(+W{)<5OJ~99ZQ@z5mfexFkA^Rb7`oT% z*;eN{rC@0*1+J6)AEbR#kSD>H^>5ntG^TCawr$(CHEr9rZQC}cZQJhcefaj_+lc?m zMr2e*-Kxl_r(1dRoO{mVkTyod<_-6psne`%J<`K=Vt3AQM@r;_KW%8_Ke*eeppO90 z2ns+WfbRWn6h`2z3^k!=ug<;wm&3uwR z)^?r|CmndA&7c6%vT(bXB;+4!ot}Tr&bRwaDncFq4oInz*2D`o)H32Xw8TN7$ATeP z7$pcCIWG(Stw)&V50z>Ml^6{f^p(t6e^W&hTB+y&Zi`jMp{j<&0pc`(29*D=AXd-Um% znMB@K{#xK~*E2wJ43?QN_|s`p*`*~(Z>vK6C&I<$Scy&qyo-u>FO=Q9uQ&hKeQ^Xa z@CXbRYpvBzpx^I?9{NpQYq#CBqy#V-j1zRVDaWF~YB+^)lqfI4@PIf1g^mEe^sM3z zt3Tx08+!J+PTUggh)yRJ@&bj`3u1B71P-sHZpK?s`d`^PDZa73?Yt=v0?l;8_{%=JaYBQ?8cx85Ng3>Tr-aF$OvRK<28py~^n#|;RVD}ZrE?+}B^>s%%7 zks7Pl08)LM4^lk=!>oCD=~Kbj>N@3of6vG8>DCk8m(k_f^cXkcN2GQ$cAoU{nxscW zF543lVv38BNt%zbrilDGM^csZM!3YG$<}vHQ1$)k`+xWdd+(2Rq z`fV-EjsMpUVxtq*4pY?!{p$&M8xIh_(;`$w=EI*)ramvuLOm8oJdu;{ooqGI>DWvB z6sKiT2i>C`3j}*)6p|3jt}XO=kAG&XD@1G~y_Av}@1#(YAf6@3D7{_?451JzxERJM zzh1bIrjQtaU$$U=-1XTDq&D7tP@F(MqC>sq`To?k{k*d7tE+kp4){B<>C5p|G4tz2 zwfE_m<*N%fAJ7T|LI(sQkxOh5Nbo&R$n=_mp${UWN6hl$AtukK2a<9i;~~N&ejUns zig`=?N%&=?N5uClheyzkNbIM*cqbd&|JYE&cSt-^^k=!`S^1B8LnWd{&M!b8^FYavWG3Qdim= zv&0OzNFJg}z?aOgl9H7rj4q`eWjwA9u4gm%_&;6$EHa-pl#;{Ve=UiVcbk&E|$g3_` zVJ9)3?Y$h1`wJWeV2j67xE>7>~xgZulSm&*BoVz_^kL7BDbhe6e zD4GYKE!h`X?66i?>X2W_&ooUsDhP#y*KaF92GJKtVm#U@{@=guMK>s#A~6Gjz%u|T zTz}s$nZJL8#N~rGCW#hF@b}yt&HPj7x0Fj^?U47F64|Yh;>kgY$0F*-$@g2wh)AMS zK<_ktx0JqFM0bA% zZG9BQ6T}t8F!o0ZVOR$y(s{DF(F}*>VQTEcBRxsr0N1IN+7w`Y(9rWDi> zS~!GbLG8ysirOYSs8WHNd=;r1 z+>)LeD6VGEBn35mf>a@3-g!VDhISpkkAt&TK&{V2J)O( zcOh*zew|$U5dpG)v{da@2_0U}_q?C$g1%_+dcIvoO0=FyguHUW-iZFo1uKUgCtLap zV3#Ej^|JXQ567%;=SE*lk3x}R(fqW(%kN#bI~C%(E`IPE}qL$qAg8PuF^rd5w2h3605xl*+SKz%B{+! z3akngWcRG$rpnVvdAzCIA-=X@lmcm2?ox)UO7qGQ)V#N(LR*VSE1Uvr53;?y(q83J zr3?&qON0-N;TYk#{UI{FuHKCvJ;W%$66j{+Moh!9iI;ESfDGNMhy5;-&42=So z$mbhEFP+RT0iD{V`*SoLer#4XZ8b5kn70YG~`bpz@7)ODg%M!PvZ_luWUe)D>90y&oU>DGk~Xt4PTEbe3|Z73~bTkT_5qm>f(N`u{vva?}z)!}uvNH8U*^TCK_)t$A|I_PuM zaq3?FMdKxya|ZjZ@ml322=qzDd)?uAshiSU)m8hSa_P0U-8O8CH>!EJmTOrxdKfC< zR0?nkkZ?oZtHX@~!Z&g^icZb_V$c<1cc?G+i`SQi1UN}iLm(;RqO-@#p&VjPv$P~+Zi?WR`+;!>5#$3FM`_cU5p{>@N2+f8kqnB6H zyU6oe_x`K*h$Cmrap%ZbbO>^!wKk69#5K3TKQHw#0ha6Dri{oUX?49XO%-rsgvV4n z1~$MYDHn0CJrA{c64nl>NAEAa!zVQQ-Y1Rx=J+T0N|6-_1MDC532oZkhevg$0ftYa0Km3By(2+Z_jma%Lst0+Xpwn!EU z;WtDh&_JXX8|XP~6Jh&WBI1tw`BZk{FyN*!C&3NI#N`PR8c3lHL=bYb-WWOvd*&GY z{DUftD3P1bBL+%k_G)w4vc*K9hfpZl{9^pYZu-;xQekOFMHIbzubBW%8{FZ))_8xr zFxPZoy4`Z}2ELs6GBz$DI0X0Sr=3!Y;E+3J7Fz?gFN}85kBXQowJaw{JaabXyX->v zO~*UPTpp=wEw`FGTddpOi(NIVBH!d;n4K2KG$2&fpOfY*%I~9~DD|l)4+pfSCqCUS z($IsRII8H>@UavfK8APb{@Ep(B!CZd_#$=8)Uq z`?oC%okkCCd-nX|gZmJe6cEVyHYrGEushKF=fAwz18GwWX6e1yWne5Wm;?%q5mcg2 z)E$S+;Jag&Vzoggp=}iE2-)DT=6F(E3)1Yln|DjJtTAoIng7zRvuwc9e2efNhVSK& zmcHAJKQc7!nrMGT;T@ihRIRUU_F}h-Dpqg3!`Ou^-)1c}FIcRbH(3)}AIRvU>&OTT z4GG2hHHwNVF;u5^pe)`BY&fvJkEk>nDl90(v$4Evq%qcH`j?N(@|FArM2R9{gza+mh*ZGayNn{Mh=0;Og8vF9xzB|0@P7Nv3uh6O(WcG)EQ3_C%+Y6IZ z2A8wyPXbjUz~DaL=h|}8+SlhgqxbmGQ1a3cyU)%^6e{tjsY^;xOle@1@C%b5xV$X{ zKl&I;ZA*wY+uDp(q7l-r)jgP|#|CpT3> zjVp!G|LL+=<2Io((q$gi8NstGQ?qe@Vdvr~r(MJBRBKUdIXb-4u_5+YU$4lBpojOs znYjn**1L!7GBWTlmAvz}u)nQ$Ps6(^!lzM7aV0!)u*bw7Z~6@##Pb=KQgI2q3^H%4 z5`t~!$517VGC41kTqa>`rinEUw2oEaK7P-()(D44c5coBT@2Lpsm@~g+K4hbOKchm3h}%FS%U%YyBQ#+}4H zX@x1!XMP@^7MYQ;OeV2k4m<%dM#-=miE)S!h1g>(vv?5ig{8Z6(2=lSz;y7a{CGbd zX=ElQJ`@OW1|3+98_1{ablRqM+^yO7nd7#C!|Q#2yC7_PQr%;2p1*U=<@-_H<9@oK zG12Wc(cP3B@R}R|`ki+_5>aUyWj)qFJu!KAx_g9{Zp0zh} z?b#%W<`5sW^1r!-yjdm!I969q{5xm!ga8O>n@!GNi_|+U9}-bU(sQdHZHgt2wP$Af z7*6I>Lw_cmK}PHsRa)N9|5}QwQOYiSfFUdRmKBTKxu|76UzCS+J7r2TS7wKmGZLm zhEY5_^k6MaCGMt5y6$bfah0Zg>?o3xK@8oyT!)n2A96ar_*aqy<<8*o)jK?i) zU0=0#pASFuxE;4_jWyx+Tyodp4BywV{3T#Ph}boLhUy^L zc)DsIk)sL7yi9GN+7OEhicpp5Kt|EJ5#2#I*$2EuMFQpXg}GG?iT zBp@h@FCQRwz|IVcyw?f=DwAma2ZoXe+rFkOc7Oz=?>*OIBh*1a0(uq?DuRR!N4oTP zS||M|@o$i+XCf&JJ?yDSiVgvK+HV-c8NrKi*mM{7M|uh7&PuHFYhZv+^%|)e+KKy_ zG1nh5g<6v@t(duextasY z9gdM|%4H2?_F0>7z*_4XP1uOtGV%UcY)EuzxXZ{7De6;@t>ZAJs^KkDv*i8723sh^ z8&%CK4-c8AT(8 z5+92o;wd4OnS_U0n`}EVbt8s)7?y_*#4aD_o>6lc*b-A}DfF=3>xXq^Sd`PYPe*5SvZ_Z=^RBxx|&UcG;=-}^v89Q;qf{C@QS>ZmAd6dlI=#5$DYVF>1NPyi9=rr zPY<%qKLE;=_4n(pbMT!r7m>}aC#>{N3NUA?Zh;Hk?`a&D_F8)P9wU%|8ThsPN%V6W zl19C>*^CFx;W<~ehWs!fjPavC^XW;IWSmLO4T0QCvnI zSd-73y!F2xDv~dC`BQoMVR{=F-Aafl>uc|%cpUT|AH5EG`|I*q#UdHcl3Tjaqp94opov}d2z-9%UIe-2;lxr3 zY`?a`0d%6qkVKtX>61r=n>&y{8A-I}{lElsw485mQ2VR=YpbR|db{B$$>2?`x|jq36q@2Vv`p!%ww(Z^R_ z1>@m-V$Sm^{@Mmbz%8njv5A2#G&Qr&Endtd{Rzg?3Zw+1 z^nvAo&jgAANt|lR9lZR8g|}hAJ{EI29XwP_k@?)42(ojXUjOus(eZ7I*QxsC2{(A; z|3-*srhEGFROGb|M}LU25O_>U;piAjQ+nKrnhJBykf{Vt0fXw3k*Zwx3Eip+ev1i^ zJDxz;0%=DrTLwId<}XR)swh&tVZe;%I1?zf{2E`@kUQi4UVwp0341)0q(#f;4zjbI z4&~%jJU>B`KTn=2W0qtWRv9)A2cApRT(TNSF#3dhI_f3}tR zp*nOmU{5DXabQ3JoM+==!KunRxV)J?i8Cx$l_9SBQMhjelR~%s`fz(*KG&f_Ir%yS zzEl8fX{B}W#gnDMy3OmAEVc zVEYQ4p^LPA!cFMR|4xpxR!55p>V^=b#F@pC(#Q%K=WdF21sXjYIy-`jbHGH%64wI5 zz{Gae=!N5pipi7OXJdOjfC)nkhw`k%XsPi-1?9{lYE=^}3hu^b6o%|P<# zBx*1ZWG`mN9H_;{3}Kd~W5d}T5oG_czL|1b>YHEN_TzEqlOAH`LuYeNU2>?-cJ~D( z4B0IVwGFi;nc4=s{wAbO5lj)7SWrE#p4^PS&~csX?sH}hZKMkPsuT3NM&rv4bhxx* z9g?YmbZyWW6%OX$+my|f@W?{3XmhQA-HQtbO@ZCxbPnxlc$t=%nX=QRpLb$+BX9k9 zTdL81UAq*65%eMrc3Tj*K}7gYqV<14&Jg_A94$@-gbsHfY$Kz|)_dgJy(tT}XYrel zh7n;Ifml>{GjQ@y-RkrB#HT2YlE0i{$Ok=9b;b2yD58v6a5*A<0*M?B{pl2*T+zT< zP>$$2qvu8snaP+|HB5-IMMsYKIk9N7`#wA0_C9~p%#k{9<-Pw*jy9;h-MiVV#i8iI zj;!)T-=21+4P{zFjZ}a6h}}^HahxQ1@d_`rD03xLU&e4XeXmRHniY!YtTe0-Vi|rg zRxfcFrb;l*QWy&P1wf0g!<#_hc@JRxP%m}hqW|s26elB~KJc8;@lvm+=tdsa((xYO z+oe$EXO$jXir0~+in!52!hdtw7%H}#bH+!kf`|S+q{U*sZmEv7`b5{|qDfPX1-m%J zpL8vA_H>I*sychI9s+slOxO*Qu8H=6ieJ|)2u&IhcT_YhaV^?WbJ=ZQJNpRYauYy# z6$7*aRH5Ow{{3&dYa6?jr}jXX$L(>9Qg$oyq3T_2JI|RnwDGvpx(QM%qC6W6@WJ4W z@$%Q?N0vwZhB}2iO_CrQwaW>3P;N&$HgD35@DEXa-GRaad8kC68&}@wACow@%t8_h z2{rFqwy?(GeK7d!6<|AD03Z`3$-CJQU4ipg@9;Xu)QiS7Q?m|7qV0vIF?3XiW8Y@Z zHl(Y*VfEvC6!kgGq2-dH9WSy4;5(-#;gw}+jIE@;16TgaBt$4O{d3zmff^_0@1JIg zz1y!;`^GX7B^^Y3UdFJ*wE8HR8Dc#Nct;g6eo%g?@p^6_VUmGH-cfGa^T6yKWi~x& zli{bag&QpiB;K&wl{&-{ zG~(*|pqr~q*Jr{5y>G%>C7P<@he4aZXv!t8_ZUdU{P9~P|IS!)(r9s;fE9@Bi}nej zG-h1>O%gIiY*nSp{t~eki2ag? z@ef)01T+3!%yR>zdt6`Zu-B}PZy5rbe4`Hooje~@()Bg;3KRR=$ala!aG#u*5+Vl9 z_AXH|Nb0rhGK1?-4h^3U$g-MV@}CT|M&7qD3v~BVxF=~T)u-j6ZR-?MuQ`GvY|2OZ zFroC2)^H*sZ{_giO*0V@{riKf71K(K!~L~LlC}zF1L}%?dcRWm?Jllc`AEg6*Wz?c z)I$ZSg@BXyeAVaiCTYMD+w%_F)27uXS72nee+-&-6H*k-^ltZ(va9W8_RKG1HxCp1 zem5`EwKQ3(5-1ZhH(6@@m2)H^fTRt^s0?|hN~a)m{MY7TX4F2uLIk=MiyJRAL*fzZ z2o;0+O;vL_h2-S$h>j#=Cs@?Lm?9U0P$75j@WkL#^Wo@kp-6H9`w&AMrl^)(e2eWr zLbIv{$PyHSv$_r?V-*IKyV`N$koYI7rp_0bquJY#GkAB4yG54Z$`w>A7zR6Vw(8PQX4a+C0_Eci zN=_hdVeE*^CvMH87Grfr(o&Vgl)=dR7)d!`@sDG-nP#>O!ksZEUcb)?m+7(Ab=2HdVPtI^`eZdHUT75ATQ$+kih+#0iz>pTrn2 zXc&FxA3=z_KVVTRbse9s~M6XX~wsn5YVyutJX$;vvdEI@Z=Y7PhTPP`8vXtx?`Ia z)o|^ZPw@xYPWG#cXABR~V~*SwmugS`=jj+YT~4o|j;({|%dQnD|2YH0k^Tu+fhk=w z$BVDB-^MR*F>X&oQW#U#NcO+2R4~IF7U1F4oNYXa*HS1PDVNkkAc=_WS%wok?UB;M zN9Jr}|0E{HGr(JQD8cUcU73Q0A>d!$wmKq|Z1^VCPuuvShUrvyD7B!Tj*GTK#a)4} zm~OR4bpKfAWovF#8?adnw_+Qz@O~2tEZFQrWn|jt6w7(GDU9DL!VLHP;5vmq!PB$! zVBY@Xug{~q_-Jn_#dR8Y<_QpY{$#R=S~cB;MAPx~C(jjKOL+D(xR65*-@HR|T)BdC zTtE8k*PHbpYt+}#2D#ov?**GHF2}&0S617vbIq3PQ0vdsnXT9tTBdw<*Mvym4azRo zppYEDmgYRGrkxG$oPIo_%OO(JFINshAaM&BJoto_EMs0_hSeTe!ukwaV!WWq3vvQi zt|2d?fSrk3egLnqvT$I7)Y`0Zi5trvL3LtZ*Yggj$4%&~d{(3E@b32G@oa(jYRxUb zeAYnz9-@sq7nA{MXy5MyS9*))l~wn)i}BFvgcFt57keRnvtcpxgD2BDz8WyZCEQNH?6K0 z(+QEmON+Ho5H0EF^>eLDcn)>dbCKEoKO1ItZ5*rum6pc=xg(DU0bnf^=RSpfj|9#= zJp+#fP4ov2%)4KonEWXfuh#;NlDq(MRAqh`6{VeOewgDjsUT!?XjEYwZ4tXaW-2uW zQ5rn`En!b|ruhK&KZPS0SpOcNw;IJW`B%gSK$7TH;K2|Z!%5zv3KWRpO=ie(*b9{i z?I&YQKHy_s83Dbdsp0OQAH^fSUs(pNx7DPLxindwho>)88+NxFdu_JUN1fKLg0N^q z!uDye#a>_k2rysT6tA<>ecM)N8-J0l;2oXaq_=QiTYvBLE|FGq)!ljI8SXT@K641R zf$>5!W#U#Z@!~hwxN3c0;U|HrOXPxz=z*s2LEHGDn)MOR5)ik7T!TCRX6J-fX=bS~ za9yqehm(`U*z=!JX|r5f?uMu61Rj=eU4vWySMG_?w{0?@oQwz*LTMnbE&`zvRmy2) z>B<2|5olE~z20l6L3O za@ZYFSzJI`N+8KiMsCNgI^tmPLD&^T93`;K9NilP;3js-?p}Q0Ewi9NJE1_LqIxGK zSQs8|MG0&21JYYHH);ljG5Hh2bEP05DoNt-D zvu+04hMqa8o2v3j8@T%z6%_B9e#JX%DuUvm9Tj&XS>eVdSvb+x*(@C2z$hSrI~AjeafB{K^xlX;MSLW zV*iy-Hrlx~Fg$hb*faPby`Y{im)rR&IK-~2^X*A;8Pv1^`Qmg zihT{W$tBc$bql-llG(K0TWHK92DLfrZbx3j+c|<=9_twyY4`NsTm@KLIFT$71fuZ2l(!mlYxg1Y9Eggx{HaO6`burat zl_Jk$gDkGS^P*$A=hGs_!!h7*LUS!& zbn9nAda{BM`H#*#bqp=KZ5;;#PSx&&wO%mP4X4upZRLpT0s6-^0 zB{8bxM*O!k)rj-yZOXwEq>g`mZ$UgJe5zP-XL+!~iw+ui&hA7kyKy9W+v7c^5n>Ss z7hQFqkwpJ=^(GNN+MH_u4TA^pq?$PsbJ5*J%88aZT51yKml=jNtnrcgmBO7*-4B6=vGU zmSGMKxs!L(?9G|~u}p3gy1CBy0pa?!kY-ATs@H3CR?tbcL17uXjYj%pNXt(RKh!=P zK^Q^!GZiI7@G4hU&<1Oyc&e`5UjnzaZw`qqWZCV{j~$NO7i!g`hwCJw5<6~X#BC+j z@SH$^Zl2>EIQV|y0SGQJ|Mqj5pQxd#ZdRmueIvJZ=WWbFw^7rg{?Qo+)zvV)`5SV8 zOcVh;Vtym~ki4JOB$^ev^QygXNp<`gjYH!0oJQpgq-BKk03tSP8w5x-tdC4UXcy8A zt<{UpG7P<46ZLOuJR5JXry@sx;Kb}|w$*Q~$CC^cZz9X<4NA4?CNYB|I$<{f8zlQ; z8;eObmN+a-$%Y>AaE#GOQlfz>|7Z@JZMo=Pk`drZ z(2p>}p={YVcjGU8feI;Bn#_|DWC{?1Rhhi~Xw{Kt&D9jF&$kyzZzf?eU*=Av#ENXi z&+MBYVv{glR#nHuuL|C-zIPv9oTO)E(V%+CB{x7)gI>Dt$9I4rj{b$iDm%QA>22GH zmj_R@un7!!F#{~NI3I2UIv?3(&$G;A@z+{*-X|Ag@10QLv0m?+3o5!Mx>Q}edMH<1 zobVGZIW;0})&Y&zC{1>I@4L%~j1^g|EjSb+Ys&;v*%dce0&wC+@c{ z2Sv_kI2~7@eZ^RqpSvP}Mqc5II9)5Q<;mqlB!p%*DP>aR9<5+C*wu%i%X81)Z6>yl ziew7*#j@XAWqs9-coE!^@AtYE#AFgOH5^&sjU!}z=6Bz4x$3CCtbCeed<>gWBE=nB z`luPSj(K6Aw(;&%(xcN`TqF=I4lQ+p#?Jak`H*B*PmdUwj{oA<+9f^>ni<TD1=0t z|3Mm=PtT))70sl}99b18o8A$YAC6QxjbDjNN<}n$00!`pnpB;e$otf~i+|KwTfh5# zJOQ@=>9!$TOf_NC1V$fpie7n~rM&U5*-Z>=hCNkz@VFB^k6X6n*U-K!6LJi2K>+(Y zovKq>Uwc|*nRtVT_Z2toBzxIS++nu(bD#To-}EE1v%I|m?*O9; zoToQSyadxiZ zMK8iE?e@&|J6m5>7j?F_)3JE|Jc3}p$xX@YoB)Og2)g5fs z7xp(HG4I(XY1j0N3sm>M|HI@&X(v;VA_oAH4gOOnh~oc+$!Y9nXl&Br-Lwq6&`@nu}k8H=_JAorI1%!$iG^>P84KfSu z5$TgcjirIX4$V%45@`$lG28EIWwjPjofknv%sR_+N{F{{Kop;oZrs)BPa#e6YKRb1 z6yhu{oT4G1Ml_cY*VGnTGowhfQJJTvA zB$$`Z5WG|&-n=5HCp0LK7WdQ=auF%iOms?#5Tji>U7mI5h<|Pi-BG@SBffS;#84x? zR=P9&d8sDeR`HITh9IDkQL9N(JVZZ&d_{}sN6L4 zIg`DX*-R0GYMzAFAR7zDG4jOdm9>w@8IXvdRqhiNJM|!}=&Vpos~p1_6F@M?4``1@_T9fp@N^?vBqXwX6$fv7I+YyF(xk;3&y-+5%=<&F4JGUUL zBaHR*DU=C@>sqN;#56H1w24koe5HS12NBU=YR$bQ2!XS#wgtY8wmpnbeXAk&uCBah zGaK``&ik5S&*`|%m+gwLx%G+NoS(VpZT}s@v9_tPx$4MxDLi$R_C0wse9npfyj)!p z<@WAjzdc8W_k`QHX16QX$k?{-ta0^i?I11-k)Zgks95Dymnf zWo`JUp~&(sGFJN;H*A&6X2MdTle>J;F;v)`HC4>q{o76uB75(0=XUrnQy(DGXFs3T zu&(e6w~M~*8hSBxV}ui^NLl>HAaI|BZCRzriXDvHBYKn0DuQpXBC*B_bEH=fN-H(2 zAca@vMn=s5GnNK#6Cy7ruBEpBA2PzrGkWu?a1+QAlLt#+vm-1MlH;6||DZNg0u|}J zI9xLYFtW@TiItc^zC>cVQ~Xxqs=<8UeZT&Bia(~sFO2A_6t4)f5^9T{C7OWEhH382Qe~?WVpod&_hR6u84klQ07K};SMQP_+sM`)k21?9h40-kI1f^JpaCKpL)(nd9plnbL0>^D3bTSdPW9he@i}p+>$3Q!w~-YwcsA!pe`dm zR``#KMlQ`2f(3S6Wdz%})humg$sAnfshoi(ad4bu+9U3oZu|T^XnspQ6uxN%L;rU; zOVG%}I0+PbF>8d}J^pCo?|@?o(DA}vM}0PliNEi#VSC86fHFLvjGCpfE=8)ht;#8l7D6477uvV%B%+(bub?Yjv-IE4lS-2t(Y@-dy5!z@LRJyN*ZBy-bg@3%s1 zEbNMb9|*gxBEuD*2j$92Ys0`P1eX-k@NB-l12g=B@7mq@@>sFWY=&AS9~UcW(v1KXkS@?1|<9O9p zBq`$;@NO!-L2~oXi3B+?4viA|jj1~nFTS~eQMSTNU4gIa(_S6&ku7*ve;31{uCF2& zz(&o6#6jf)d=}G>`=GA#tZ)FQgpA}|-A9f(oLO#^DWUVFOPdWjS}}(f15TS=_B_NY zilxiWoCQB?Xn?4^3~CI5Ss59I4{Jq#O;>9zD$$CFl8L1FNyKIz0PtbKs}Yr)aF^Zx z*N&*0)d?Zf#73Oty|1<@f4ejmVOO;C1^9vEv`SVX-uoWwu%Slb^M#LMOYBQ^tgIKJ z9mn(z#U-fVMof#m*M1RIM!Msz1IFV18Wo7Sxc?D76Q1`PL+UqZBWIL_79j@agyuo& zRqRZOJ`%Cl87FXQeWRS;>G5Z^1P&DiHW0zbxo3)AhMl{n^$H!y{;PH{4I3c`R9i}X zk79$pWx|P-l1lbF0xktJd8+R3LB1X-S5%!xU$IxMDk-hX6Ns2#D0FadKlyBD1H#`8 zz|!qst(g4rAA`?x;oq${zbz2PDGLBpHQD&o5)a?}ZVY%bD7*5q`$k<5n%;qD51_}e z0Fmnl?Lz@cFYs!`Ux;%Q3>W5^qJ0Vak5VgI*#X@8?vLt<_Ona+%iosMHJmr z>^t=t45l`nO2XahcOh(H;oV3`DL{x2wsKYY*d3DWsrQ0qJBzskqv=45a>}ooaz#Nu z_S?YTblKRM)M*)yNCvMd43$m6F|qVIlH*;A-d;R0(JVzBR~j!!!sY$SzTbC)tF}Zi zl8Iv=W0-s=Q?i4=R&mGTNRtzH?^DoF*inzb=!~=;cVOuG^+oyXRT$;FvBbVe=cBJh z!ag09oG>x%a7S7uiqYzK=K@@U9XfId6bq3(|K{XU2-;GUqQ9*iP42=T*o3tcttT~J zkAKKC2PwIjiY5{JQ^Utssgf=Ptz@L_Sevt;ynA;*?NBjbO)KG-x-n@k#t${ ztuJ&>UK|7yny;Vw87$_XsGlt~e48xIFw8Z+>$l3V%WN?ftRR1B@KIV0Z(ddUNEb1>u2sD z*)x_)*`K{xs>q_{-0#<4bXeT#n|0S$?0T|5oNAl%@RN9SrcGzl`a9DW0PmSgEILoU zlX92!GB|ADuW|-Yeoc!{jjoinm~XKE*IXRsBu<0|0|0np|EId-|DxummNu9_;srRHA`p2EK zcc~)=>2fXZezBEtXMh9EuB#*Uiui(UPEOn;;-}P$*IRHXJD-08?$r>aS{MV7fynCy|2~uZYPKc!0 zio_0=7W>m`__hwD0nL(Mo6^b8{gngRyvAOnUj)1I^dF8Xv-V=ziHITNv{KLjId|cy z-%9n{O7Xf3x<}nYfLy!^>a6ZkBt^ytCk_7O9ytc6a+~zFi)nOEz+Y2(pJ+q+;!$n2 zL%o@qOF${Xs$?mxK72RE(N=~8`^IJDRW6-;H_YJM*%s;EZQqGAjcQr3>GCt zSvk$9P9ua@Vo^W-gN4CaY-jOTqd3$s3d=X)rNXs(WM#)8vZLD0((%<f&p@6Agu@ zX_=tOEB5p8&DxD#HK%A!`|;Iw$-VvNuNsI-YgBX0`od5wt{%_w8hxm3#0Ksdj=>t8 z>I_xW0%dY*K#bD53{XzBG1j4j z06hr6r0=g@4z3HoY&C8M^#~~&5xAO}%}3$tC+nBstHC4>uX5C!wa6YdWJ6frhqE|X z-%do_iV^tbJ@9J~fk(bh)X){+Fb%xhsReKzeX;WJx)7wFI7{0y$;$e$rS(2*0j9NL zlqoW9=hxPG)bya}Zo5NgF;)#F?Mh-w1$G0x+f|z$HQnNa|Dva}#Q^UINKdr&3vx`{ z^{{A#!G+DUoU=jkvP(ThrdKbXp{l>REAr&b1<3w)GWpTEAF{|wE0o;#{sUA$*QWm> zX%QT(GMfsPS!sWZho22G%zV)6<-e8D`$j`F-x0+ZP%1t6C!Ku?oOaMlBQMX7L6nxR zwJulZCR1A2cOP0d6*}2>EsD*SCK`j7j727;+p9f~Bg~ zZ2g#E3ZG<#aUTlXQR|NRGMHPtwqqMSw68FXM|cjwi27q~ag&7)H`YS7^tI*{js& zZ}hr{W(-6h9LCSD4Q`VeR%1M~YrMFxJWb=}WNfLW%iv+XAMZbXZF|_TH1%P+4?omY zF%MP{fLnD+Y{tw~$YZPFJWc7s$=!FTej6~OB1?>@i%O`!RzST5r zAhjpuP>Uh4m>V=vYCGP2FPyl9@5u9Ya@f)6SsB~XYp`y z$hQE!*%kHW=ZVuj(!uj=i#RxoHmAnTp%D?ig`vQM?rHl2Q0KEa?a}g94a;uc-~4<@ zUops6wQIBvr;Fjv%!bL!yL9&Xy-JXnqSHx8^$%U2Wgy`v@=%@QLnfeFxW%q=j-}~a zhL~hqtsIlxmfaqO+S5zV&eu*mX6A%gJD$?z@sj9`7h1Jp^liG_T7drh7)b&QH_i zBP4?iHdMyfiZ9AyYbztF8^I5=S^5&;bOIBT|D_>w2 zuH|Y5lT>4d-Mrf|=+^r$(yl2;lc-q^cWm3(v8^53=8kRK){br4HoviL+xFbKaUcJP z|K+}P^oi(x=!mX!s1%9pW+uLaI6`USWxX1wgeOe8q2m4Nn+m8COc*s)o zb-m*1;`|JEI=Jpv(3(J=Hz!Y!rA8W0ku@aAkVSD($)fNLW8J*kchYTdeB40ju-&rY z&N6*D_6vXm%3GqAuAi37r(LsMb3dML7#4+Z242@Wf~Yu~Gk1uXZEk)L=Sgnimy1o{ zWCybkJAxQ{ES7UwSoddl`FURJN_~gAfaZea>4JueCy4@Qx zGY~cWHJ_-tU`Mj@xb#~TwnG^Ik&UZ;S<G=ez`a_e85fh9K61AT0st2136bg%7dV z@FvdH1J=g*t@!;_>mAY3u>17$qYBL6Qhoga=A-I2%O}Wp&kth!f8GVc`Hm5CKi&m> zi2p5<`+sQ-nc3P}{s*{hr1ZxUM-0`6xx;dmy3IygD|e<>V80kA4D8oCqGTT7Y&$T- zUM83c>lR*Bv95Uwvtbc(MZOTcgC%wn{u#lHkd*8v-X#%y5v3G#@E0&EA8QGdfFL+(koe3YM4bI>P2J(WRb0B?l1N788Kq(a4`=#2q)9#Q z^PF)G>#0KNMide!kUB6>*)vm6%C+~6*cRs|=HhS$fP4CWih2I^*?lXH90+$^WS+U2 zLmSAi(}iOKm;6MElo13TG%d*rGi8f@|2(jZoRIBv3`-%o84oE)9wut zn!mJ+Oi{C^JBc$TDRrKH`^9v~7>fZKPz2Y_C(TU{^m2DMyAMO94D@pL1@3iJm#s@^ z6GmJA_{W*s`NPxoYxL;b<1IzOno-pQbX1X6!CB;7w33hN+K2gjWh3XCRlOpY)@o|! z`qv_FF+mypH<9z1%TikKGAU)%{8{5z{;nu9W+^fg!KqSFq9OaZx zMJF(j5-8CFLUSA^Z9o?r6>OCn4CE%CFLmrv!}0h3s&IVEOF=+FO)H^Y{PcC6K>u5u z{lDaxtZj{qt^Om>7P?@ZaF)}^-E7gIZ4n6}5xp8-kijE@vXjZq^rZ?ZN8`;z@-H## zaA@)(NGW+v$^%H5L|QJEiu;6PN?R%N*JLB7T9=jA8&pjia2{o+nlB4ca?)0@W(rg6 zemLFrRhz4so0q|qMf<8AvQHaY2&m%nvL45oTfs3ADlImfp67gD-|u=YUs>bEKe`;2 zRo_08A2L8+=$JkxkJsMGKs(rf|6tbsBimzuz11U@uK!22Ukrv;OxSK3k%5w2OQsK} zh0pGhU9dM5M19eJeB`FlkLR-QD7BG5iI5`HtEr*2kx>e%M(U+c(A^C9 z3?H*2<8vJZ4KKG-$>-9}Dur4mwHRm$Z@1IQ=hMzHgJj>~nQ|kX#Vo#UqsA9!3C=*C z+&vPOY6UMz8qz|s-fbQXxd{>WY{e^S+s8ravtyV=x)Qg7wv}`W;YQKftrn)l?SJOI zjSfG%G4ayH-%edY-U^uRx{ZbsbED>~3A2^9g0USq?tXb1jJbjLx{BpbUcuT5pQhfA zrEm#$-Mts^a?R)7$XY?!N?5_!%2>hJN?9S;%5fw95Z)WTNeBns1q~0}4Ghn=Ljc>D znuS%r-*<`eX)roFj4#`!OXKQda}I+hFs|sAt6SVPw32z@0EP!`enS3xzD1UZyNkk6 z^@aQw=b_OjbIA>=mSy>yuB@0ZS}B7LxH*lx@3F^Hab9lkAz8}LdQs|Sj04Fk1GDjd zL&{thF<72>$icqv%i(s~h5$1h%87WWcpn!}hD?M!8P&`_r~vSy9&Bl~?jZ8gDa85b?4l?}@~CdqnMHF(ym?`n@_kE}}%^8g{JIdBK|< zv4=x}r7J(LP4SwT8d1DAR&`3su3oa%GyE{UX!F-6hJ@FZ0EzeZ9Oiq+zqi3a(oGbS3xI-{zwh-w09DOiZ z+68-ZyvWEp(sJQuVKL0?L*Z3)nWCxTR<{dj#Ia%pq9oY(dfG`qlIy=Jb3VGLA;Wwt zx%*ou* z+3dp=q0$I-2X*tt4vHjc2L%>H$$%P)B-FOTux;sS6QR%Cn6cRdPI7$1*>mdOF06-X zN`SzB^kSbd#>?TUgoE(|B?Tnf0Z@Wl<%MdQ=JXXhezpN#g}?#|@2F_fEeNBa(| zcIhZVBl0v;WNBa}It9A1g+oNENGP0q#Dj(kvj4iqgcTyA0r95btN!S+lEU*8qj(?Gb8Lg+zIF-E&&H`N}@R(q7m4B8o-5oB=7$@WVB;=RwtW<=kFF9d0@f^M)2&WKMcYfL7VAnnezaO)%M2l!Gec>6g~x!EJb>n08B>geKjLpkd#1;uYsE(|}8+%6`L>g?@FlQt?9P9~v);iIF+ zRh4Pe0Vt0}A*_X)KEG4|z(8~XooKD&%m+FpwjMicYBfI2eXIZcT{p6+kBg^_rE}V- z9ng}}wzyRRXzz*M9)SF&vzU^P^uuy8A@8G`gUl;xIT>D7T5TUqZW(&6^Xt~}n#>$7 zep)Z7F-^cB7PVG`fGp1&X|-_$6G<4v8&Ml#n5 zn&BnDXY0A{djz*Zf)#$I$eAOzAb3)9u)OH|`M6ow`A7(GtCx*$o^8707F;Fbi zL??Z9PSRz#MW+a72s5U0#FICs2E@}h`yTFfM213`*#$_L;eaSwsM9uMlxfCFt7u^c zj4+lG7v=hJ5 z7Aw`az#2i^*m#)}G$ZC|sMA);fd(df*?+rjAl5qwxg}%7RDOL`804CgbkBRz1!l!x z5S=FkZvG7p>E8Db>(hj%?^Y-&ALpd)X-*)fYx`BopymPIkwqD|{$Nd_b6xk^yBkzG4@$&W~eB<9Wqgof$ z=@3c1YW(*X8!v>M0B+@)Dw2>EoPT?2)rTQEa z63RdS5?pVg1`|oTA?2iYKmez(+HUt2xuf~ddc3ijM%s96nQur@luBs<-!z;730o=wf3k12Y6>P z9xKHv$B9&k>|Vo;FVe`zU-?c(Ghs3Q6+FR()m$n$vdJ<>*(As)tx@VoA~dfnM(`We zL#uLrD&(Q=SYnj%RGJOPBqXp2`)z@74RYy&WrzJ#S}}f~xRWPR5-H<>i6&mDUaI-o zD&3FcG+w)a)>10I@_IEANHe^Rqz%^asSGO2`VG&U#U3F=roD)1lvg^>=@*Pcnm>{(HC4%6jQ2 zS=LLiqN!+L*2B}|wTr=Mrc}hfp|*St;m|y{Pm3wnshK9C5|qjyQb4e(EZCb}3i(_> z*c!)h$<&Z~44lluL;erCGK$&_n2GSi*?a%DFir47b3>k7(#s#6CJ?NgCe4s%e(@RH zs%-x-p0x<6SF%yZhz@=XpeL9JnITbfll*8n{G+_v zGP57OdrYP}Pc%dWYPI$^S>V4X`sbb;};4i}Wtgyz>%HW!&`ZDncNxqViA zIu4%(_nJ!_{L{^C(kEUkRQ<+PIN==8x+~tVmYOG-u3s@M*?-ipr~297Om^_}2I6b1 zx0auJVNYV(nhD-8a0sRoa=TxLZ_fe8Ad${m*DTiRTkXeB{sb_QTAn8G8ypUwBNvX5 z&N>7s$JWZulQrUzJ$KpThvgGmJk4WX)HlnOe%M;~%C<)WM@8I+UlV<}T)8G}U87yR z4EKBap7RbOhYwOU*O{+lu1^PNIMq)w1f8-p?-eFvdcH14Mb}=m%L`tQWv7A6gO7o( zYi!z=VkOKF+r(FIS|$iIFYI1>+bqj0G6x??^Mg9BkJ9%U{p+DyKaRag*&ebb^jt!mrbY1#jz>zSN?&z9UlXX4yL+pJ0`mxQT*Zo|MD7F7Vf++a z+DvR>(6RtLN+U;-ldKmM>(Wd@9d)tLpL zh$+(eV#_R(0_~9Z2Je*t_>1v=%|xvs0JVZSB%b5%7M)!s^lB%InZ8E%UUZ2qD5_9S zX8f#dGF=cACpi>2RU$;e(SNhEOgQ(Hi?{XlOA$)f50W9WMJN18(5{yKBq>|a_%o~d zFT{Wn4h)3GKvEv0;P2%%?!hKF`h*}c9XxFv|Hr&@kJUx(6%P&r;yjf8CH+%*iD+UtmM=@5AukjM^ zD1IZD(dT=xnKgl^u!~$3Ipk?rNr9a10^xM}K>o0l``h(qNaRN1e6+2KzuC9;v4kY& z%H!>_W}+qg1EMd2+^+{|N*!C@cZOI=eS5?gj#bJQ=ZG$Kf5hY}V1#TngY+BBgsFAe z2*oEtS-f3xC=#1}_JyqKJGQheAitUs)bus#G~~10duukT)MYtct)Q^<@yBxz@lW9Iv6lyrR7*PT1R(DaW0Wz!j zs?4X76V!SX0v-jgVPo-cvC=v4tc|=tQ1pUkwT8vh6%6GU47JS-41))+_m<@*oYk|_ zukR9EDXr;!Phuu)ORdsi6W ze@0d*xx&99kwXwJB8I4rfe3}7l?Gbc-O(mQG#}~EJJ{W$x)_j#-(f6%tCOz z^w0y6ViajpZq|e&^rlV~e)(5O(_vJML0s#zcbOGvqpHt=j!L#%F)EcxT*%3TCfguF zN;s^(gOES`cRG>?IahvHCpp`!Sg7)@P(|u;Nvaw3vDu*-DsU|N%fi#a#NO-o&)m}@1p+ww%f^?=V z%mhP8je<$)`PCBX?dSXRd>vQ-s-{lBF8p+t@b$cH(85rA-RDi7|C4OHw=gOo=xQ=! zcAL4*h;j(Q7XN7Q>90K!Q4+q@!rV{N|7IDA0N2?{uzeYe9nHhVaiP*n$lK?Me7obZl&TQ zag0QXGPVF0>9J?~B51%kD>*Cujq*8sbjXVOxRYu#`JrzdCv817wgR#d-}i z=Jwgm z^Hs&9-b?$>3Yd!6c!44x^6C0TmT<@%WN1(0Oulg;yr5#$aa*t4*M~i;nY+$3FdEu8FNI^cZv(oN3_R(ZuZ|YVSpX-!F{6K zewZKaLqjineyZP9r39a?1dfMI%w6m;I{a)6wlO2^?8a3YOKkIHtPK`P;qq#Rf>6oA zDY=P58XyHn@nvLIJvCFi8$i`>yT0fX{0-CvS0l?@vKva4O?JSgfF+tKtL!q)*)qwEd@|)0Te4brk4Q?e4vi1>uBqVv}#DL&BtfinE=;G zkHz$R6&-G$N4F_0_o{shvFZ)qsyB1HNAMM22J1 z@dnySsm>O{jPkxDeUS38cS8o1+So)T%#ofB=n-15q=fjjzD!E)uOp3nGQ{TEWGOlA^NzBPLP+5}otyp+EyLtOO!c39`eIzRW5$v^uc!g)7X|KYw-ZNN7j zkRKE>5NwoPV}7Yzp~#VR=DT-sEl4CcW1yPO4C0AkX-r42un2aBE*b<&(BKL4#+zcV z!lFe5?S+K2mQsE=>eCeYv2ws{zavi=k5FN*+oul<7MIcx z1qJ0tcgF0?miZ_?EH_)P=7Y2n9|@RE>}K{4ARf)x){8*G>LH1!8OaO_YZb~RMzThyyK7oog>NzN<$(??hSU{OMpjIy5I z9q$SVe6%|z><1XPnG{yiGN1w2PAe6CqhGqk4jF7cJUDyXu-sNF4aR<69bIIjTMRj}6vApXs~T(LrK+cKFrRb2 zLY}GA01r{~kmy8aX-!U?P>4{hQ5DBL#|ll=WJ6bw3Z}w#D$e^NEQ^YUf%!VEV~jyS z20v3_fo?EE#a=29k_=Ze<7qCRkc+d&yQ20ielo(F9B0LIB*ZzK_BcRZS;Q(l1O%wV;@gCV^}h}xd18o14C6dNNfe( z2@ax=b5kR@Ir!)Cz7*s_G!;DBCB)A7*XrDC{s_-6+bT476mv^uwf-oM z7DJC|!J*`$2*5Elevh?AsTkH)!tMkkLBL_R7pPs(bZ-6*X|VU7IT4F=wnhOCbr zaw+O^F8NvkyrWSV%4W8QDyM10LC217J_m)WwyPSy@)hl8_aEg7r+W2iU&pv+Sg>Yp z94l;Xsf&>aJ=pm@+Q&tq4U|hAt~fo>sp3!@WaIA?`YY`{mWo|7)j%SyUC(x8*Nb z@67h67M=y7yGqk&Ywma}+u?f!;A#ybgFm}Cjm}v-# zwqha?MMgp_f++sE0V9x7}=xw z8Vy$3=956dd;v zj?0FJOP#(goqWP+mlx^r!_j1+^}yZN071exIp_68!fD1;mU$NIWW8gk&1JhOc=njF zt>M%<1IYyJG4RGr()k*b>xrs+cF-aBRf3U-2L8Y5dQX>~TUyU^lft&_HbBF=N5f+% zdZ)LB={6|E%}hhFh^tmMq0YOb|5{OR^J{Oj7B@ObM|Jw0iTqI)a$3Yh5QYv;UBhZM z`1Mt#qw5xIXVP|A+O5e%4(FJo?6s5AnQ$?^DQ$*L7L`!=RpvZ5sHvtYRf*VfmQ(RH z{vHzt&0+NbKkq~F%~M|5OTHmWzm^cpSGDvup6_G4?|!H6zV=~&uhj5Y+Q4_(dP+r+ z>6+=dX@@CygGxq?qHB42Nm+;SqOHpW{3P6_f$g);%#*!J^W}ozLZ1@&1HZZ@>mhH_SWRBMg&H*Iw748hA^wAjGL6W0!fXR=5X&+Ucx&8wR-cme~ZaLZuR6fTqSmEYi; zAt-)`!d2gI3y0=5a|9;VV>8CHQ_I~<>wkn@R#xm0xGhj~A?h^bFJOP8SN%vh_Xc7q zTWdl(nMkK(<#2Ykr5EGqEO%_Jbb?4%d(R(rWH+zoiO8u{=RKAiuCYuW;%{?Xw;y$$ zX;)sS8)BTb`0lORPn$Sg3f0yN`X`BE$pGlKDbUn8%?)-*$^Pi)2zS?ql9B(;&_|T| z(NdD?Hl1r-FC3jYB+I-Gb{JKT7sAMVlgYnI)9W0D{4-NSyCfFUo>DrF9C} z1(9nKNB`=C!$cGVw$&ixFh_RIrb$z$hGFHMqE2EXOcQmk)_TDrZ^tJjMCuf}n5&Mk z3r#8+n)Kka{NsbQ39|H|{;r#wF6jLHW6lU3qhKC{TA_6Qit1@K~*xRG(!b{M%msY)*;{ET~4kz^g1HHBRb)Ib0U`* z7+xBsg0hYuPKCbJi)uhE#TbMe`EOWzuau+X=*@YG^r*>>8RxH$SGo(Id_YJ8O8UH4 z3J2e?3`Z08uVFyz->!?WVq`=6A9R8>&0s#9aj~Ng%Zx4tGhRQ(Jw61z zL(G+HK4v=vLPe#9BtH%xMohq+fUbhzjl4b(!ifaY_sN}mW^6P*Uy=kd5rHLAeIgew zrci-6qiEReo-@TBkDZu64Kt=pMn@Ra0Y~iQqMK3bv!kT)ITg zZ1%Y7&2j&uqTb=x-k<)4^|!%JxcNLN^$qJptu29O<;e)RMUD68*|I5t9;8(|+vX$q zl?MoOaoQ}noZad&14%dU+rScm5Z(7utJqQ(vu)8>%Q2VWHH7W2?M;@=juXqCV=(-0 z2V;g~Zm%3tkS!j-6WKJG@@KEXFRA@s>cqlcj6(glF>+ zd#URcD{w6Ta<_Sz_p{gg)w(so3;Npo5pUIecf}k%6-fJ(rL1=8CgWxYu35UZ_jEVr z%Gbbs%Me1gj@O6VPdqyxXFZjeWV&W%lbODEHh51po?Hm-)YvrdCcluJLdp$O>G5zN_}2gv)o+d`;h4PsY}eGT#=ISfx{jA$lc3lyI9p!s_KtGR z`51>5BPz>1Hlpk}KKHrE%ByX}%G2>P+|WN3 z20iWCCk7G4f`8s%N$hB{B+uB;7uS*F#2a(pUVUpgyc2$qk&$AOQ22*2JE?#D!ovbE z-NB=C3>3f6Vl9om$166SU&$JSmPT36jZbBx_8;3>T$3-TbUr3;uhkJMcCB4o4Lp5T5ojjYoI+poznVaW?B3^ zc3ZZ;dbUF`71Ifqcs-iX+w_WLv$Vbd6cSn0bKeY8*mo@rIOidXlNb!h1A9$WU{#%w zJoC$+`wKZ^N-VXLDpo-hg6e}KEeJwg2t!!h_$ODnvebwwX&y*LpzLI3j*dCFhnTD1IOMd|-k$0N!S?Ej(IeNL-k$1fVW@aMP){5>3_J zS)5`Zb8kNs1@XGrKc2%MUyvIbQy}pY(aaw>pRn2yr9S+w!d`(6vd$!yjFVyN+QsSa zyj-;;eNB&hW&DHkpRX_Edk%Q69}l{^Zio2RecR+ZCr=WKI!wckea?f{tTRL0nXpL7 zNoT1$%-zd+G=F5Jw^*QOWpU^f)L*aLtnoS9jH`i`93vHnt^f6Awf>ErH%%+TT0Z?) z2!Ql}X|%>GP?lh))3G8Z-9w8NPGr+XD^>nyR0#%jE`vD4)8Ro6+POa~&lQeml=Kf1 ze87B)7-VuLFfan)YA09pvKBO)qyO}f63u+8&73G1xA>9QN6^VOy=98s@j*MINPBSu2z9I4CpnHryAgLE352fM;6$5La;>1`ajWkPg*nYx1 zF&w}c7vs<#=)%Jm^z6paJ#l?mjgpT*3NR<~78PKRC$5&DFZN5x$FCL$SRiV zh?^xnD~;;hd4@MHQIcRUD?ePTar$A>#o-KFJMBp94BuyOLpkI~5_J?3>+@N!;m%;D zknBSy+R)D4WS}6N53N^YPY`|Vg=6fDW}T}%;r(?;;*54iolOMY9wE6?nThY?=v8LF z?zP`60(jEak@_i|P+ZU1w(DsYF2^2p`RrS$IF{dhmM5#%yMxO=vDBs%lAIfl)|!7` z7#E+Rm^x;IO*J>csH@T9Dd>mh*AWb-U+9vVMXCdEg8t~9u-}(1LeQD!Ze~?#XeRNmgxscfZQOx@2OmsFb$gmi-ePNR8!7g_<#wc{DOtn^i zl`IPPKt9UiNSzaWT~L>TIn=tv_gDUF>{qMsex-&Vs{A+xBaGGb$ah)LT=P?aUp}*I zQa15-cdRMNle9g5`$U)QF#HX_9;gi`vk!}f@&s30p`P)A3aVORNA&zveFy2J4Wf^s zHp~Ub7id!*<&0I$tBs{)(n@zcrrxr_HgZ>V;qq2pWZ76 z_%z4g^b3xM?TCmfE$Inm;_)4XcfO$>ddr&Qq|=#d(xUE8FFmun_%m*x_~6t5AqF&k zqijw_ZLK3W)F*7%$#XuwhigG|cwgOtkelqNfC8$E)fCIMe~h%6I1b|d-B!~XfAFG_ z%kfuW+Allt{z3>?ZfSEU@POXC$g32*K^v6(fl!T@w$_3SlD`8*D9uj+>3bEhtCpai zf-XOk3`G*KmP}K*{c-IaS0MhCKNyKW)Ni$+C>}sF^Ke{)lF~(vNJhSEjz~tx z$6eFi74GXd8X&4_6$eQY(TNy-1Eb!p+Mg)HF}p%NCH@0LAR+A$$3gYvnL>~9i*?Oc z4Uu|!NnJI|ZE){SdwqaMlXNvBdgafD=Pi|P z(R>@uKKI;O36+<5U#OG5c3Q7*09m&xlgq-nBW-NruLa34T}!Njow`(Sw9#m8FOiww znCLB8I{GHINrVr?VSCDf6%58se#m8^BN%dafa;Pa{v!sS@Hr{XTK1^*&yte)?hzbd-~r7$eDx6M<-f zYxRxZe#>3gXsCxB!t#St!@xlB*Aw!@@P$=YW(CtmUnZHzc+nxw3q7Zq~a4HkBO$rc&Vj*firei6oS0Va&)25e&L z2@hgy$rLpoqog0lBOqbE`vZuXu~PiH9uF~t^>JlT-tlKeI{svp+=b{?y89wo^p znv{*lmdvy&P3wC7QnT0#+Y>sQi5p7>sU~c-%G(hPcnWcR+l`#ISw)Nb%lBse`*&~o zISwRpeWINPSPz~gV9x%Yb#Bs=D#7I zL!i)Zk~S>6Wk5CS*rWV`(MG4G8Qo$`agIA62VHh}c+Nlm>arR#zM3mVB;+$Cumh7b z$8B!787!Qt327^s(;^~d#nch|m7=MR;LZzJEV_nXRAaw0I*W#s1CR_ADofVgOfs)z z?e@f=a~vgx$@46fvU34cGp?Lb}QCs_NQmuGWgvgCb*OlQ44 z+@E^=%Ypw%8*=nAxP>P&FS<{mb|Lpy&8EjdHvFvm~=O=$Y;&AThXi3M}{O0 z_=2f=r`C))gDlu+cnO3kM>>|!re9b~`NheC>uTA<7IkES_AR9 znR<0;Tl4qX*Xoih*Y=rq>5A7lpI#ls`9?wuNDgxNvYOG^yht_$5s)wJ7p5*KRw}R% z7!17z#b{aleTXe>7_Ac7d-I@;@lz93rrIv5mvKQJje7rjW%=Jb!|(vT)kOHHEg%|= z1J7!lcgYrOXmp-UNW!@GXWpi%b>w&`+Zp|2$gSV#JpB_&;QO%}OgX>)pxlE4_bMo` zjus+z(C@XaR0_>cN83qg-hQu?%rN?+bHvG#MZ)5q#VcX)JJO*Uf~Oy2s=~0UGU82! zMKqBnqbfNCNENzux|Zq6XYPi=R3QqE$>yv8LeULST75ca=EIqBw|YgO^kTv-gzNGo zU@a@j3;U^@g)&J)TL}gLdt*!ruQ+tki^8uno_`$NfR3}{T{ zkP*MgD8ph9#t@ZeFatYRMjirgz;4#)bSwjLs0olwqrLWR2j!GH55}RvF$elJXkl{9 zu4PI0?7zI62V_jmFtX77GfeFE(-XuhpW8p5GoVz!tZLg@DhOg~cXj1xh+QvOvWPG$ znT7^0FvMJFG#ql6$4+^U5eu*6)@t3paKJAZLG|={{?c-BMUYMUVxRx4vv`WUqDvqR zD;J1*18Ne0yiz(vy#n)rz-Smn&>vd&|8CZUTFw_k8ny=iZK(P!vn^ydzrS-=jShNi z3EpXnoVfP>tuhiIal^!6OXzN4vrOWcQZ=UYHL|g#()JlURyC^o9l?VTSnRV}IRWq| zOdMa3D4NR4mAV~%_nd(J=M<@%W-9=}a>El1kM3k93;}jvWUYt(=ba;_e)bYnMDGP@ z$$0maW*sI{XZ2V_!CdEuVf&R{=APdLR0B(FqYn_F-A5m!{H6fv#c%_NTqL<%_AkOT zs6<}H@aR(`9AazPXt(<84io5p5445HYMFl7<=vi=ZO?0L&%c_~=8??5mo;!+gZQs$ z<9Y9oJd&`>YV$KL*U3MxJmgJVoNB9hZ&jKW2+)3J8M@;@E*ydO`XYY~IOIBm_ug5L zv*xv>pj$MXcx(AK;F{6JEyc{WCtC(M%D}K@Y3Lo>CWA&((l%<(GqyPA6;q#|zsdYy zw0XX$xoS2^hzeD+rq_TVXRBRL>hE2=-v_D0bw;bD0B?-GB6 zN&n@&u1osSV9O1~M_=L;GnXl6+76&csVg2F+Y{%ndtr<cV23kdQPE@v}pm?Vb-w#d z_{?b~^8=vNtDu=STPqWZQ3=Z`Cez zo+ljXsGZwVFdgY}l&5^I+dghy>D&;EJZ##(Gt)T(z(`#F9E)3YT>Gz)m(UDe$&xM5 zASZ@BKbSS?-Vg`QL>qYo$4eu#`q#w>-|2=^VY!tXmPt6yktoDMUkS8^ZWE?yAnTiT zOXRCvCM13ZW3)NhRzAGie12tqhH+J{t?~&6a0Xn= z2A9vMoXM(uDlQJcmPf;=;GHzv4)YIun?GuuYJF*aAe7tMzW@1zuqHqu_{G2KL8CVB zM&ic%GF)7d%*_fnpUmywPG-8<*+92_P`7xjg(mU)xaw;uoChj1+8w&}i~u@Jt=r@8 z`yb|y8%DPoqc6LX_gt*%RSQfhDc#m?<;i}QolvO?J~y#G-nke3*vAdy+44U0PUP}` zk*Z5ZEX5QZ>g5OBq-6WSFam;>!B1+@`9%@1k4O2rHII!@$>Ao8mo824O(;YLG|EA5 zLxo0P=@_;(HhW)22XgBWb=nA2_t&u6-Irczs9$+ zOWq;i9}$E-VtD3#X&m0nUS_cI$dQLBc;2j3*V+7w@7($@?#8;yyqQCf@MP3Uww}T} ztlR22*Y7q257ip7YxV|*-Cg%DmgF|79E+c;*sE5fI~<(O8&CCGuV!dpV3@m${yuxv zdfHEi2mk#B`Fx;wXjq+}md*GYbS^1_(^^F%8#!1oTGDJ$h02%fqgRI8IN?aZEHq`65w6Ga3b2eUR!Jf#%t2{!>XO@Hd8D$a;%HF$B|G@Zt^69U5A#41WI`j%1jpw{(R{>L}WkRZ*Z4D!SbwzO;Cu;R9P(4J(s|m?5qK|%4b#{(nKKlzkK;K>3i0;<=Dc9 zJj9(|u{AI0E!VAytCK1qwbxyp^@cqFI`$%O#fcR+$CFfeBV1;<<{PX8Cu6vy8P?5L zhht}HOE_7}+{cwI6&Tc>OriIDJ5WYr-EQ*0W9M65eCIZL!01}fflP>{3Jo#zs#n=u zUI3l6-{WfPR+|Xmq_dx{Di9kxLeC+f9is@YeV`qYRYYMbgo3`l6t|Fo*oO1k+^{~O z@3`&{8lH6+Am5j9)pAD7gCttEz|M{-ljI`OYsC!XQ&_Kr zu0FD+*qfgzJ#4{S)B)(gz*Iu0;KQwG+Gs)j8on#R!~rs>Je8c9OHrq)um~!Jgx~N& z#$Dn+PFN&W7oh$)@-uvVk^CBpCWI6mTlpw>U!ba@JHu4#+ir`zwyBvpF^1l9A6kJxiZ<_YvVbOb+UV4_^5?jqyuQpRJH_NIq%ffRz zer?Ilsaf&19Pk?YX^1{!AbjMO8-mLpEUH6+)PfLFb()-46%#al=3ctI>b-u? zeFJ}RJ`y#_&!;>->U$6AzhpqT?3il<7hZ-#n8?pEE;`r>?{J*F%K zxcV-&eY3m6n0xN!)uI61nI= zbAp{8P(f~q%Ttg-UpvkigCP6!gLjO#8r(woY0!=V`2x3sAu1+US_wWI#~<&l1S>cE z{)XcUk`K_(PvIXBHCbeuEZ;^ez9IO+1erh3u+e5XXUb#Je31$ktQeLb9>Tfb%ORT7DV{>pe zBLDO_OBmCUe3-3jcEu?f-3W;}t;gC$k(0_M*3P(7-7z20JSXr^FfQFappVq2zQr5% zSoioiizE2XB8@+9)saQ!h^YhHjzGo;YhVSsL6yq-sm?PJz`#a_=i0Ufh_P;e{iQA1 zkKO{>E+E%;pg`X5E@Y#wu7X-#s>&<_kOKe}W7Xo#&aZ8@u9P!R6MEg(|Do>A+v# zY+_}D0}kUAXjqYXru5;aYDlX!1V;09CwWo`VX)#*BRP&puDCev&cGMQh z(=T|z)`Ge!0q2exljL)t_wBI7BZk~24AuSSTd211cCK<6d)1p2e3wgq?JTBKYQDIU zYgnGr<$ZrLjEwoaCEMQaxcJC!@jtYkQ*drUl(u8rC$??##I}Ce_v*FQ`@A*F^s2TQHCwE%Zh0Ofsz1dsYRhWx%d=%> zZ&zHC`6}tHBX`^Te53t~Q+Yg`YZb5*YONz0t@^E{)smkGYt6ai9rWp#gdoNXY1%_> zi^RWz-4@*B@IMPlOYZvT`4vWLFAIyeWQa#|fzOq_nhh5}?OHu-wP6AuDHQ$v> zZqNDXw-L#L0AXJrK(7r%o3akT2#oCyRk`na_OO1Z0(e`U3N?Oyj+_{msEm?x07;ae zcQlNYIGG*-UxHjcE&+jf!r~6$41i!E|96By1lFQgQb@YSKcExtH)Y~w*&O-{;wp)@ zTYK&?D*b+{!DD;O;k`O@nW)%MZWteFIX(9VD33CqMPwbtu@4e%tc{*m;8qK1v7~`s ziCR!T0}#QLl1W>$_?GARG7|N-k~hpOXID^omc3}$Wrj(%jVC&=Co=$-IN`bZ>!jwR zmOzG9RhkeOG(K`o_aE=E6&j!>pvusbo18iS-eJ1ZAtSE2bewXVL|#OdZ;oylytCOn zV2cE*CH}Tp1YB+t6~4<5?5*Ev3ahvvObVUT$^2UA-H*N&p^;!fAmGV2bOH6%KPk4O zNO5(G_R{ub0l&Drsx+cQeWuK^eY+u}Vl6e^xV2`(W+i`g0)C{0kWTcpi7R9|GN%gK z*y%fG&Z*zt;N{^btk;8OXeR2YRO8tU1AoC(3yP6dqP6ma%T?!R(_JxD(*+=fWN(_k z_m|#{NmLUBpzOsERclNi6dqsI087H)3ym1mwRdP%h1s+9sfzGtRm|lE!PP}i8`mxh z5gf2rsXJ6AK)%t?<;7k|!asdpqwJqrLPEwZajSYp{Jg|U*h)6PYAQ;-mrp?E$Z)XLd{+W3zNG%p4`7#7^a7oiD zW@t(CVj`SF`>#-_i22hl`~`b%1A8vGv<=XjIJRo6wvc^N15J*P#67^TAjw$Dov*VF zBj)cm7^^#s_8Zc)3VYu=$bzo+4TZ7^OvlF9f&z7xu?aOJ$DM&&}kmf7lhG`^QOm0qBQb(*CbfZ)OxP%E-}E2|}1CRJff~ zh9KaLs}1swNv;kKS{$aC4Xdb{R0cxBWGBcgzUy>J7MnpenRgIT%-@0KT^8@WSYXMs zB(){Bn~p9$|GHOUourYBFg+vq$!)48x7pr; z8AS_6%RkM}03|DKQ);ObbGT1)+qFhB(%S~1n8NU8kzz~xScPC4Qysn5&|J@AEwG6w zKr?75UJ$4wOno-U0SUt=hx)gF@|2{O$(qZ=9Q*C(iJ$2P|MW+QNS}z}wh3H#N z^THGHDEm4pW$f%Fy;{+e6|JhsrNCcOb^x+#+wcph`@bP00sMth**}mGS+M_ai^I{x z(eeKUi@)fCwZk2A$J$`wdEXl1uhrm%0s#dfttG_wBG{(D?_0)$Rw6CEuexf)y9rPz^X zDN;zTqgEI4oRR+(?@xRX>mt3BQ6ckI)c;5DNC7%0$czP_;H93={VO6Qfo(3sm=jxW zNz78Rn@2IVGIogqCm()Hc20I|*qmhSnUtL(GhcS>$ehLfnS8}qx{<7ntetEX+gi3+ zbX~$n)zH#G+X+YV9p!Q?#vD@e9W~zAtdXUSubpod{Zh(Byd#lsF5B3)k)w^IourMW zou!SYou-YaJrg7j9}n2X*K5ZD5@-~buAtzsXwI7ou`z0mI$7`>X$Z1LdCp9t{EZuZ zQ$A4H4^bD=YpSDB?;29n1l6g~=Z>HQ>B9>`s(yh)ND^f* z>A=HzKWBoCkyye?>3{`#v^buV{6@i$>nUL=2pv+~K*!W1Ue5MZ)yrrghDw3`>3QaZwO>x zGI5lJz(~=&u!V-R1tDpW&|zwj1G6!sO5{oTr8187|&#oM$Fue}$c%hO~V3#di%tIyw^mEK>AuE2e)p@cQQ zH5SXL$Wl$iqWDtCQdRuZk~cC^0aTK`EOHn_MIO;i^ne~tJITj%LZO&Y2_?`0g(dQw zNp%Ra1q%SUvJnW1GL!e}A~hgAfcamFl(W%qWD~3jLZL?@%J6U|^CcG&PWr-^mE2MJ zQnnw@WXYSlzHn9wNmINW+TrT{@D;4oFfuSnwW@t#i|6XrB4dW#%iwJS4y67fg_=2- zRxq?1>?(y+Kbc?X=u*Yejdgu-J%zYQsnUfE*p!V{bWiuyTf;9|^^_@!Je2P=e?i%s z^ZX2dIj6L^tAAgDwxnqR z3JqpTGkoOR8XDhF)gdo5jz8S9XG%=arJbn1gEHQ2auN=MB@g~Hghmr<=TOH+PSRSe zC?s)O6Lj%VYZjsr<7B4Rs{(y3AtYmOo)4>@^JgUZcK}`x?P?S+P2_+AzJJ)1MC%l~ zjsS+dU4m1v6GmM*y%360!er4N(ypf1IuKAfUE&efuW~h^5J{@NUJXgY=+pfQemqu| z0o4ngs(-^A6Qvc@Y{lHlhA@V#$ttiu+(1B;U(a)2dR*yOvaqK%=^_IPSJ_FwS;wwL zyPyqfIrxZT!^-pmbDyx$Iw|-J6!5)i8!>_Gz>E%-fq`oLRT1qLjxJ=u^_8dR9%k{` z=PeO-Dzkl_&P!5ob$jORu0L|RTO051M3f%7GLCBAuih|L<>{7iJ*#?p!BW%Tc$L4^ zu7$4+2l~j4X3IgXR_iwEIkxLv>kiXRzQfb&xGZdryRx=?8V2qDfulbb_jVyd0)S-gODJ4Jx-S`YX0ydw%@Q=7UtT(HhushU% z*Q!62B=W?{?ml}nJFKygOe?Oh7=qDmpwEq{|HM=Q1uK~cChLJ9d)#HgO2~*LrOn<* z8$yb@2eGx`4jXtIXb2a1>VQo^Nu!gpgYPROaI*Fx^mC@h6Y}sYZ3tl-n8o56^vuTO zCSfR}SP6{!JS9^FtQS%+)AEE7x~ej3)-NFx8w2+Z{zfb-<&L5!ZnXFn!YmXSCi+;7 zBm0Q0A)}{=IE)h+l46dy1!V)@*0?7E>)-!@b`y;+?qt2hMDMv0q?(NED{T+uMKWjMQ}V z;EZGf$bE@*y_s~Twm7U>7FrlyuMRBDYSD*O90?-ZQxSP{`o;SQu#=S-I!(C60-ZO; zo2Qnr0CJ{Upw!KtQGQJ8o`>PHs8W#1#Pv&&eXE)69NHmB?FB=vljCdT2&JMIQ>EyeH7(Q}5qvTEIB2wDo zf#BphvP^_g97kALh=;I+o1lr9F&AE*uN&|=Rylf)B(l~EAB^8u;wLgrKS10$Dl7r8 zm!Qxjsqqy;orn=1#lC;pO<;=%$sJC!HUuUgq~!?{lNbbhj07K`uFI(`@3}{!0|N`x zO42m$HsA4#<-kI(O95`)LH8pg(U_7%g?4w)9_mt4yN+}#K_8WS_nA6s+a1cV)?AKA zr*5@O*_3s6o%cGvOX+&0^CW0}#wfQ`=j+w(xL5@|TV*2(+%#f-z&CXN+WzS4?CIFC z)p%+-_@ujM;J_7x##Erk#4ubN`qHTQI>l zbL5#lwJeZXrB$}xu7f$YEQ-OM%7b{wgSd&KQR#W*qhI|bvvkkrn>cs7+u75?S_Qvn z>$P*9?a6k0LT;QZpht~h1lWu@?Tvug zkX%%~f^?@omf!ujy7NNS--xhnEa}uSJj@bnzuOq=m~uenH@Ym|pmHs`qjDXK%4mz= zFm(_DkGcXk@r_W=i|VF=o9VvezVjhr^SCK13Z0M+Jz;`zzRjlU*}DdKdbn@*3jtsPAkRrdcp=<=s{w zrX=)r9#r;)wZG!t+GX>WlvZk{EfmUtw`wXKOE;%>;)E# zpN|&VPpLLkyy6af?K@G-*(3J}!X}zrDLK?Opnvng_Ua~=r+^(4fipM%F!jwZBtKgv z_=Mwpn41pstBgn*N04@v09}lrieYA-?wV<6)g4-9p2L?Hp;}W9WPd@RB}zHI_rQ^$ z03U7u?KgmySPhq%MnXf8u`-hns)FK^f+R_6NTd>Ya4$pD;h+1S7OpV<-9_PgQbA!h zRB$#hkj%fXE&@eJRir$X5v0A4L`E`kS_0Kmh^eavMmE}58IP!E|8Uk1N=CodBvvrR z76S-X>kNPNt^nx6<61WpW$T0}!c>*Z`nVuNF*R!=Bxn&-YSd5(waeo4SZUHhd*z-u zV%-zgycP|sdSeBUt|(<09U1vjcKWOkD!ryys07-4=*4PZDwrL1w<(pGAsLw1vUCHw zFq{!?q>+jgFqyI~Qr9X@tbWT1t$k?4fO6>sE>h|J0N#A&g8Vq*2(&W_5EHmQr+`S2 zMfRvv^1L-A1-UT$AQRw5@Z~aLJ4O=H7Y&qg65^V6vh+k2rKl6*w6O}IU*z+|d$Ye4 zJzH1 zutl~M3^HKY?b2wO8Zc!q(%(UbP7!diJI8bAALF|tgg$?C@ox{bDZtWpj6$-0SM9Mz zdS9GzhK7(O_rV5*gq>uH*~uWWC`}47E!G5Dx#YI9QSpR~E}Rj&s&b3S*cAIzkTss# z|0OrJVFWHx2=CN=E1B2|d0f?bq8QyWdE6R~@<;{uBk&{Wfl$No7f3U~R|8M2Xg;iH zo|=eM)zzGkGFtyA;$hhGv9GK1Y_r$zw%4CltWg7pnbO|sej0A#pm59{R)xHQu<5ef z59Tr*YiO%2bI;BwIes#Gx5?Huq21yG_cdR-Z#SC){#cy%G)0`j)qAMB_nxqRzq5YF ze|f43YC-Rxx}Rk3pqaTEXS?q9q{Q@iTDP{uXlHMQIT5s53>J6$8ouY4F+6R5TdLsD z%i2%%s-lryKRV=Dw$azNT4TDT4>~s!Hx)}+!E@!HyXMW_cK3?E>>!w76X?P6F<7fN z1>G%fds)^S%cgy?u<^bf#yoD}y=gimfrNdWvgPQR1FSoHRlC=9+YYNiEljibZ0VSv zcRGGOy#jiQkSa4TvroUYY@c4rVS}(uV>^9}$vWL*d_51MbwLt zn77-pw%Dy-ea^2sMliLXk9nh|@t^WWdM^G>duBLZ#B^9oXPe!G2BmmUx$ECY^q8)0 z$3MHKg{xK+6`YCuxmB-f?@dW9JuMejUM3L)&(7l4gleJ-ZNJN_KAes5G9THz>6(Si zE2zMrzPT8PsRrce-r0I%Z8hUwjfHyFm%wCO)U(IDHj~M}XTZ8?J63h1Y9k(NBW_1- zZ{JsaUSI3q0d#K{jRFwAssc8gPlf6{!)(s@2Ca*d+=4_xN~6+Q|bj{|-U^qfv0cm!Fo>U$ERKZiW~KLpRxfrHM9f+RtldwEY-f_M4DO!)cxIKSkuL z-!@1D|E8U%*-v_yb;72WbWMD1{>023$F`)jn?A1^6K(WopX@WMT|1w63<}5Xr2?C> z`^Q^&$HXZD>lR$gqMw?O!Sl#~YAg63ty+|;a?1E{2USQ3+60y$GPnx!HkA|E-|l+& zFYRMH4BQPcbc+S;EvY(;Lr~hl-?WJWUiM(cD?*fo zA+p)3Xk~RT&$4Up4DH>3tt28oW0j8A3p>b)fbQ3`!77yqgJHx;I%}^D1=EF%w z_d|4q&*myuv6l^lli*OH4X}z227_$E;wQga(PoH8i{_z$rD@N_2?+e5>i;Sx1oeT@ z#%SV3%7!H@7(EqxEU)^%k+=x2LvIT*pwOE!LX|`@qj0(WrVE->jsbEW0%FSrR{IKI|s^1tlb zK6!o2*5~EkZdd8L#Lsa?+gRjsWg()7@1&@oz4bSHE(dp8abPKP_xUHvXKm!Abl91% zHGw7@22(UEB`T6nWGAorI8|(mL=h*eqFxE3tj~Zv(+zo3Z?WnBunB(X7(^=0MFUt;oU)Mq^C+RO!O6fw2YC@ZXh{<>7nK8|F;I5=1UQDd1^=mt>KW#Q_BYIby zeijei1XsT2Wo8K^yV^3mSUNgya{10s8`-;5HD0uPo@{COJdX{fD7(umKRrB*mP5V_ zOz^W`8y#Dwdd0hnb+`Ezz29`@bog4=y$e67(4&ocaud8^JH&(#)PVc-Tp{NIbc0ha z3j>$M)##EM&Pkvv)UG=~XXbVgPs)$W>3oq2vn!e_Nu(QvQcg+|$bzc}O-vF6Re2## zfq+(TQz*{dHf@Us8^6^*_eQ06OSuEoUdKi3(<*M<>;<^fKsqMo$ zPdjHeAOitl?rJi18i7YaXf#CzfHV+@cusnuL4=|s z2KWb~O&uIagX-eH#d6U7X~W*j%0dzz0**YnA+vmvyfr z)@{w-uxp?`x(WXnuUryK?IvJ(^VLm&D~GT5b(Wc}z)*!WfO_Ey10H3}%>`^_6oKFNoU5k6W1-CzgsW(=-kg+GZY!9UcV`~i_ z86aO70Rk#Fs+gU?fKqEO9X=sV4nFJ#uqsb{XRBr#4=+~ZXmf9T@4eGkTPse!SgjCX z`EP1;6Ss+$94A)N~$~N zS*IjluRHr$uOwg9i%;JB5r29zy0s)#tI+)oW1E*EZxrR;C+gAOPYb%Tb^vP)TXa~?ax z!6?^>#Bi-eP6{>4^YbD;zFOvXrh^4c9aM%NeTLPh%XJp~q|L0Mt%WL$Z>0#Ey(E9x ziTX7}qjHN})RY-NH$v_`_gQ}fGqJ>u*peTj-(-%-M)aFWN}sp4lm8TD!3Sj^;j+~P zCksD};Tmf4$<%?Fp4%~w+O%(3qf@Dr#C1|3KTFCd4vM$U((M`gJPhO_vCLL=s&HmysQLRiy2uHJM z%;R-+a&*sry+j{TE1fHjXtNsHpgU|6O(;+(SRbE2SD;d7N4(lDfQ#&H&*q+3r_5EV zt}`X8N*||DYy=rS+U*cl29cs3aAYoFE=WlG_p;eRKA*|_ zqFX2@Eq*f~I@VLcTcVsu(ADmq?cPYwU~E_K zPJ1*tWvC3L6X;WyTT)05Uzv+CDlQ2luhnWFuCsQpa$nym>fjTQ0rZn=PC3R zau-v7!sTWAQWtDvXHuc2+pF&>-IiyZ9pZ`rz=9pw87Ktd#dbN9>*WuJN%HI)8^oUQjFdl=)dv538ud}%{3%hC&-PJ z?K%Nczr3wZhyzg|!^s{>{#H_nLarh($qK8WAUDrMsS%l`K^ux=5@aC`3sX|oZ zk<{pD=MQHQf{7jZUdq58)@d>nfR6>FGG~(wt)cAcC2B|>=`;R}M19)A640{}d&<>a zgH7xF9%m+!@_?J)54l=)Bb5+4a5Qbzxxlc}401OvjF5*m>aYHCQMzIX3NZyL>G4V+ z6arr7zr4)QsNIgG$6&${95Upm+U$g%4}6q+fK&TN=>v=z0Y5~ACUfy|TKc^E1%>p5 z*^fC65Aeqs@irPX`H_(_BAj`=01uZJ+Brc>khYpU(w@n`k8OS5k?-(Of-`$=YOhJ#0z_P|THK9&w1bfkc=i^Mazb z5gK|3BYCvZ&$_7Z){Z}1*&kW?u^wJ_aS{u_5x^=qOs3(Z<;stPDz82t1SC`&vf@Gy z9qies4S#qWl8mN(8#T9l89RQ4T0m(3i)RG%J^Xy-Q_WZ-+@sIJ>sV3xfI*|*|d^vq{0p7CJwc&bA zfA|wr<`LKf8v4cF@TXF_)8Fg{d7$t1O&J0NBBIY}!O^VL5kHo+^haU;8z& zy>C*#yd4$mbZ0F&$0>^wlQ+zAEy5E{M%BG4%u9dp+1u&>OK6Wv<4z5I5IcH6Q?TIF zIlN<^aBi`J?)TenTO_Bb)RM&pzxq%M#Gbw9E@hW4IObQ zvD)jgI$*^2{2_XNe!$V_-U#;22o}%51g`>LVOhug>UGwl%-LkK0$~S^jtBcLCZz3C zI;J_GhMs0Sqm_vXbNs#inB&lUQ}f7Rj$G5?eZT{Ji5UOcl3lXhq0zdGgl~?T8n^Hc zBN#g$Ja<;3rWK5M@<3mY*aLVZo15v+AN?6r)j*1K&~NenkBKY>R|{C5IKG-|o)nRR zUr|X37~?*N5eS>fG?kOO!SW6IN!IuQQJ^QOz(Cit<MC~DlalN5`CSctT(?>r4Yapf zSdLd-8}v2^up>Rc`g_ywKU2TD8EP$-1<<@Iq~*gpozIy(*tbz$G{x^=lm=&hlp`R=TSQLYH3B?NYz0!wc0C>srTPg~4`=P<|my)!|2HA;SN zK%bk6i{HzaXaw8)+x+BT5#*xjN=rOwyI9DU@kU8ue|!UO7c3-bxQmNLCFu>ReMGR7 zwb^9gL4A#onH;<4VL!SQwp`zQIInrK90AoA_EI+u$EZ6L@-&TtR2Zl{EJZ8suLN=T zW+77Lhy91Z@alJ1@oCXm4-_WTI^|?p@sWn&+$6rpMsl#Th!`@HL`uWE!Tx~jo6VU6 z?@-5>f$x@E(@r$o7!HDDzg{Fh-ixt1CRxwH;|x}^YJ zfr);1e@!!~$1yU|FqHBw5EwBzh@%Ijx@hkCU={x3Fsa$1dOfcnFnt8|Zpc z7DPlY2xMJVq6#ps6pC27Cf>p#lU&$%^aTt1F>69h3TdJWdu1JbuPej4L zMZ^=k!w>!&DGnfI`qj>HA>abt!$&lAQCpBlT3C98TVoxDi16fcQnKZ%4{i2jvJdH#d>|- zWX5S7v(P<7+`4?!LeaG|usfFF_j#ftzE0g-)>3J;l|lC4c;25EIz&WMzhxr#op_)E^uQTGcorP)BQ+u$Y zXs5zQX1ngSo;7+onov-&gD{mf+0jy2+vR%sEZnpGGBx~u*P`eBy(s#`vYI##d6zx) z)3N|9kJ!W3ePE*x&3?o#(1OLAeUGc()Jh+zTSR~->_mwdQJmoVTNOheI&;K z(QIlB?t5A3I-J>5y(ajx8{0|qx0?8TOk>*k5@BxCV{OQGT7q2U_XMllE}6-1a(nJy z=vZ$xcz+phHSkGStqMM-4E;IhorG*LyQImRx*w3v%cganZ!-nm3Tc~mZ@oF~Jnr4J zcAxR5{mDqnOpE*7Wfv5uqkps0>8Zo=FYP4=+~nvs?cA~9*s;%y z+0xij!ZK_f`e1&M>p0+k%|h^I;zRHhucrj!z5W>y{>D4n4>#f|pS30hP)$`5~N zPW_Ah`em5N{vqhDiZ20B+Y9Ma#slQbEUC&SD0B0lD-~PNAZSlj+AoGmEmh4giGOW< zVTjOYz5^t`V`FGilM$Fa#HNXqo1Pz*66G|=PL={pzxMw#G1&YRUo zCb7HO3zygDxBt7Nbn#NR;+XpWKAo*l5u@Mj*8GBRz?xEM-4s^@uh<^MH)!&?9?+uP^p zb@eO#OXr*=GVe1MNO!(bNn3!2i-qg`Y_g)w`W?eE$K5#3G6R3fMz1MQ@KOuC)b#ig zHqVx|d%hKGBekgpEaPbS$V8?a6SU)}lhsv!f1~#!n+MW{K;wsNoY_nZx7l(?4|m|5 z>KHSTtg0sL`-Q}t{>3|0Qj6GGFJFSgdaGKq!(zTrbwZ?Z>!QSBJQ!A7Y;&bZs{zpg zmX>gXT`AQg`OU1mphf&}P(fafv&OO|RMaAd30kM2OUc+|B5U5^b$c-n#zvA>ddwvk z@MdytdO2qOX&8)5N~f3pn<8P3SPdmZm_5ouHf&!3@oH#IBZ!Lc$3!E^4*v7_Ze=JG zYrR5RZWZp=q$RN68`r*)PV?nu8AowSrt4v*D;@i_JD9oIef0g$mQw=Ly;BvAgR1}8 zUvF!<)#B`PBDd$Vx2#0)@`PcLsaK=b^l$oz4fBTWDC6x)zulL5+0CWyOlR7@niplz zaOdBSe5|w(P;qIA5i+<<2o|Hiy2tx%5T#J~AxiijtI^%4WMxu#>`4rcvBMh)1|8Zc zdq}WG8SB^Y0&*v&k03M*I+25bA_(4sOJgwt2n$n=87n;mt0~B4dWbaw;PGG6_yhfY zWjG~1Uz4F2kWW)gJwjcR`lvuCJ}w_*1lWXT z!Q>|b`?tB9PUB-d7EE*@HI#U`@V@v^CEVh$j@&S}u$4aOF1k!YS08j)rQ!MlG#{B1 z&W4&@$StLyywdCnyMT{nXi0mx{7oz(_N~@iob$MV-$`sng;;Dh%jTz}%q^W9o%15@ zBS*rP?^z@*v0f!lleo`3BiD*O-go-C?F3(4GxS$npYoIr6Xw-VlLKd_QM~UBBd~PZ z*H+zK?rkRO-6qSMn~`)g#_u*+9riZWkNzdlBnw|Ty!8R?$5j1~K1H`Ha!1c;Mm*`x zKj4c$8V^+3wTK(}dyRhfqczqokLpqP#Z)_%4^xDJ&^$%6#V|6_=R`V98RcXHkL3LFwCr#uN=T8iArW)BLmP6u6&;OGH6$ZG-;UcK8?GN_ z*9bD9KK5R6*#sIZ4H_LJ1S|3PIa6AWUk%{;l;^KwB(P9`0x0iJ)%m_kBgZ4(##!5q zq5C94wrIFtwAPy&vk^suD*LI8p<&BB#JlpfEJ|T_m_XH@n($LEn4PBdVR_ruDI*^_KLq@yY|u zMeBKYgp%ITo9C>4qeA zzWrM?-FdFKiA>nh72jMl@i>qLWOyE+%P@NDi>1I)lz6l!)7tu zP#$q&fHlBgF65&x@M1a}kB^61-1GX6(jiWX4-P8a?2t%9IC{zO%?S*{Un8~nu7D)pUwe!^IKwo2C$`rit&Ch57?lmD zccVjKOU>M4i~lV_x-4K(9Y89`Ei)_;!7C%7rQn1&Yt+m7o>g)nB`(>)HBb~hY>bp7 zagb`U*zK>wCMR5%>7Tb2Ut3StTZ`1ZJEHdI1ClJpDIhWQcajR<->?wFgKuqrC~rip zT@%vms10VJlrb$iWPS(SrRqA)h;k~rD9wIW^F?9Bh0w-mLwt4M@kh+wpYf?X`=&el zked76k$d9;&qx86}+fL$=E4Y$zXgG0#9#Ro-n z2D~ZGw+2UeLESjYHs>@cU$&LgSpreu`&N&OEXFZ>=>NBpC=d&iyP6RQXwd3^6HBQ6 zUz9|SP6kfSj`~JF#;pHCP2`lS?SwmGU)y2E0E8jEA%v177~=*htK-&SoFGsIDT9V4w1%wG=y_VvujDR{}BMC;bn(q)pOqC%2f!}j*7dI$JEOr+@ zjmvjH$*Bh%$h!LBsUW#~r>)->PkR68eZT08vX8;`ygwuojwKS_aw5zY1l5eTAM0 zt`{ME*RodG5G#l%+yG0AG(@*n+i(TclPtvh#yNafuT|dg1>zzV3!zsieD}MLD10~5 zu4nKDh?kOy7pwqfz<`tZcHN>R)Ii424GcdSE2iHFWq=7Q6)R={I(*mOP1ukVx`Z@@ zVwWm>_ph6np&N#rG~7(zukc-3UIr#kMk1zGMk*#ZAQVvlfI&v^A!7=dd6WUT7Zed_ zkZ^w?O+!vd9YZJ~2{`n$WUQl|&OwD>_wZeCjW{g&-WJjj+X2z=U7j1=@LkWF{J|UV zmv58-#GQn}82to{Ku$u1JZaF zHHxQUzmZ^nICQ409IE_^APg&E-sKuui%xN0lI~8Wv1g@?@MWEHiQGz_ zohTWpfgGbY8uX!y0u{0x-*QXSc2@JbJ1N|0p}du_XuRDzytO)%90g545c@nxZgwuM zojaR2I90Gn+s5v_P1!}_=er}D08kO95ajGG%UJmAWs^xbK6|Jd zikb^>GhElS?le2ts?lI24bwIiwtT*7zoya6F&GH1*(4!p+mKWvJ}PvX%OZ0r+k@45 z3YT1vTZiw>HqJL!A2;cTWP7)Yxe=Oy59gD1lh8z3tBgY(GETm9Fzo1N4kUVq+Gl4f zThXjoLdr}}(CjJ)&L=~c+wy=S0IueglZq)qV6PyF9tB11-MTlrou>>iMBDDweR&Uc+uFm>EqG< z6AY484)?8*=uBrW@Yl%TkiJ8g!|O}iZ}>xfCaHAADwX=Bmd-AUks1E)%t>+S(K~eN z_tepRRfer{RG-%w98Ps1l5kEJQR>(9#rlE$9t?=IZw{^$o2e$Wk4e4;UTv>EP5vk+ zdUbBYV4je_=%;JSeL@Ad%jxo19mr8BYrG)sXP|v+L}FZ62J5)F&YO6F6+?%P!g5VT zCQ9Ew0jfZ!q~)rEG;Yz$rr~mEt<*(Uiw;@oRDM<_=T?3S`cm!OD|r8+nFO8L1Z8OG z*{l_;rDac1F+P-kLPZjyS!C?ey;P`r4xlJdJ=i9V5=Cxt2_P4(h^|< z3$n4yZ-Fsb4PL!L%7%ilNkE$>L3GJ+rR3cDMIERt^E%;nvCxH=;VoQ~Hve>lK1?9nKKy_jfo>V00sDrJ70@j@fgNENn35+ z()2OJ7!(A-HIOR50nm$*)UZ{9|DJJQ2$}{Y}WVQtd z{8laLP!c{5tV9kR*IOahc6j~J_0}B)x(kLI`^rBT`}FfeqP0}K9~%6>G#$dJ52>y| z{0qyUXcMHhpE89rhC{&RVM`c(Nza0;o%Eq?}wkqcihSugaaQo;B z`=-kT`f(jWV<%AJm5O~!7mV2xyDg>{?DwO)Ew2XS30>ZX_Uw;!QUuD-V03!#N7P;DXl+*l}IzAtOX&YtNHF?|6! zKbB;G2ix^O=ONl{2;vEH94_!8nJNicO+V;!5B_3rn=bb)%Sf^)M$Y{-BLs#D_6$ga86f8mH>XXYQ1~(y#_?qEX(!eOXB;<%59WB_HCfP2`X%Ek3Xr?N2 zD3CB4%Lx{zqrwbtQVD|kC zxDB2QVB4(!$FQ^30X~x2vb8$lbUyCfO~q&pCdt1tM^+#CfsZ4iKipAN5n$! zJI6-<^j@jlkLc5|;iOVB#Zf8Jp|RUhHvgk-wcKN5N^MTi)T_5WcxI!20N>`O3Sp`0 zA79J^EK|140=X}>ox!3x@Z+Za04$agtT`}d7fdg74Ov)pm2P_xDy&^Ljio zPc&0|Fy_o^jzKKu%{lapqH4`9Eq2lPD_g~0{@r#WAaZ-8 z!0Acb+}(cKxgV4O)yLj~&)3M$-x-%9^}V#u_FlQoJ7$8u1K~@p*N#i-g)W!J@c|NX zsKLtBr>>fDiR%Z}BS@>7U(3@o zVr`DO`F0HQ+uVV}{tBb_)|!ia=Y8Bc-iX{)_wr&4l+H^f4Ia*?KR$bySXs*nRna}x zp~$W?O4jd0|JB$me5j0Lt`CeR2D~$Bo<657IHiv3hYg7Py~1dV<@(moPU6WbEd zsVN#>uXiMGu9t6|_nP-LEt_Je6I2v9@`43xeXeByN20R~D-S4RbG4IuOUtB$x z$yZI^b6uz2&!sk!0rUKKRwG%QEHSB^hOKY?=U7`|+pZUFvnkfAcz@?IyEyMPEJm>G zsJ1_i&)*nT%1ZVRCmEaQpE_4Pny!oDOndY`IahnMzHf)?65fWZITJRefN}y;h0Q;r zDXQdSO%#!RFzv6jXdWzBgIlq%@!4`S^R+C%{mp zmq#`cCsOx#3>t7x+Q+j0ygU2Iie^3`mC-Mi>d8(qd);w2%z8kr+ z#;!68miEjF*Y1oTuiX%h>*TmV2&5Y_C^=<(8!84%E(U9YEUiJO{3F`JR&b_$|4Bo! zTMhtLI(u8>9tgdX*lhtOU7@EG9ENhIz71ocr=&upyGHwnT6P}0o%LFK5u=Ku;%8;# z43%^R2Y>N$hZG6$RGKo8%j^U$MT_;G?Q}3$SOl6odkULPUVen4!uSuH+Y#L)MMXIZ zt!U=iNtzX!O&T60s_rfYs#w!MRCf56Fm@6SX|f~@igc;L(K2IQU%hbcn05)^bRZRN zyXd?-iSncI0@Eny=e$0f@Xp(*D1$Jg$(PIjV#5^0nD9%Croiu>0 z&SEzYyW+Apb_;(2XD1RBW)t|IA*Y=rdoo*=6ug>K-`%I<^;$8WgH~6Afb?XfVr?-V zq_j?H(OD_pm-mgaYiv$k+6jp{*nvn|eU5$Ui{2tJNB$tN8H}L)GT3T#r_R*Am`h2Y zlu|0@;#m^U&LAO{BAIPpY$_Rztk8lbJnvu?Kc|JBwSG~J0FU?cjxD3Pp1e3+u7R#9 zj@fnnRPjs){Q?j3?xJ<~9+UK;5cVTjXi8bVXu_W#G^6|!ztCcC&XpB|J7205#BAXo zOGDbM_~PhYN(EVBWUP8b?o&89YN#@=X(k8x)d5)OY|0p0$eO)al{U+7dMBAy%t5vJ z6uNSbx{SOz`9&t@L3cU{b_c;$cp05iS&o>X`#M_*RRUOafEreP1(26Jsc{Y`^|aZ% zeSDD$f^TR)&|;MlyCNuyNWh$`UNC;; zL~jofV$cd?<2GRAm-1K-_0$&Er`Uy16CYHXhA8l`X3Vli;HQ?9xllRi($(;fLn8QD zFeSSj(Yef^o%XeV4YRaG|3}qc&KsQ+&P@4oSb<|U+MdG(>>dR_7|@Jut)&U+1q<{v^&8}wCFRwE=Ecq(=n5Z zUDydkq0W(gQO|k3LV3l>Q5zSgVY z>9udUa)rsnX3d8!F}cGOd*x)@=%Jsfm8pfXji86L0iC+`uJ`N|g2etjvdIFCbq%&F z3>dcg_O!^t44kpQl7yBgnlN=02%LF_2xZun6#@B%Hypt3!np(Dzs0qN>LV7FX`z^i zV&EtcBDCVkRA$02X5oCO8QTt&H8A zeSBPWGYGYIjp^UvczlyNx667sz_@{^_}@4h(&$_-M-Y9%s|1Tijqc(Xb-IQ!kOX(( z0I>39XWv2{Ei5no@7n5;{Tke^j?l@C;p1d+*Jfm!#{f~VjY04=z*tSd9g$`zT;zA) zgc(77F|SLf!U4}nCAz_u?d`}hiep(~U~U{Z9W<_Hx;9W|h=Fj-xWGhhhlTYY^q{ht zk5}odbFb7l=p=o`FeXdAK&aB!sm82r8HX;D6MFDR91q%GSttqnU#~k&l^q&LHJ4rf z5AMs|DxU2!|MGI#Wn_H&O9#VoHEgPI5g?}*wO?Cq9r@*$)IUeo2+FsvnIBL&KI6B21j2HJCLt#yl;#iX`ti1n5(tO= zfj!-{AE^cQK0};f#~JWJ=Q)izYd+A6GyA}v04_lwwPN671hHBpnn-XFH&!Mqv zYX}1Gsl|V8j2{bYH#G_0cQ3hHzh%3o(|mfg5ec=^6WI1|eLVBF!$->hN$diZ*ns7c z%>ye;036#e2@P}!RwQKSmS=M8=JEMKk8n-DYseZXhsN}d=hT7s<-SASXN1yX=cf>;Jd!N+^KgJp8mE&vAifuO$GI!xu0fle?t~M{z87#u0Lk(Eh2Idj{(R0^b>32? z#oNEtp*vBApEmm{-Q3l}*ne2QQ$l>RWDR90!4LXnjSAAfY)r#usSVyXo4cZn98#m( zRf11zFNtt~^-T&wR@rCLjH84IK6N8CGPDz63J!JJO2|}oR146GfP8W(Q9?Y)(0h6W z)@qXRW&>j*I(4X6SBg>t3&{``n=wi%uF^MWf{nX7uADFRci3zGyxg(0uQ%ANK3nYM zZPd+aBzb&_Z+!;3+?AhkufC;p2C?m8?V(3UC%^Veu~Q^=B6H&mZOmVO9EPqO0moNb zk9W;opA$DL2b4Cef9d(S@o)4nJae9RTpP=*Yy9;Dv0>lLzcY|Ff(uNdkr9_u{#!nA zs5gDRvG*fw6+{~L>1>Iw&ZAA&VAzC7R>}C!t;Xu`rqAuQ0Ipy*_Zvh=cm*;r*UD&A z!GPP!Rbvu&YH9u(LTGk1kVHHe=jN+!tx~+`y4;zonPCLCk)+qCrygx4C-jIr!Tm~O zd%sHMv`mFf8bMUKFeCRV!*T4u6BE!pt~Iwi==b!B{7Lp|weS69XJkjl3wvnl<=vh54K8u0_>MPu(z zgTuUcpNO?y6Q1lGe=*0BR@P0UeE9n-ob-oi`g9BFuee?OKff^iNEYcp3tli4_hw(g z0l-~NRa;mHo3Q^OHsk`eE!7*YXzNU(ZJqT%*gRQst)8c9lP3M=d|qmG&42}~VOpH7 zuvmJv?5{68@jG*>>&oM&07D>o3D=|tv6K7J1o!W$oY(2^ukU+7ZhQ>@pmp<3)0FfZ zH1Hb%{WG&^d)k)_&;kPI8yH515-boI07DoQAWaw*Kus7HfFJ<&#r_uivV6e0YuGRy z8$d4r_to_F-^=n*L){;8(WlyhRfwNV`RS3TpFX#@}(qc~#4)(OqzF1+^^yE| zay@+74!Gu+TtmHaVT0K6qSL?bw?0tSz2ul(L%(rlGvanZ?BE&U043lN>K@MPOR%e8 z_`7v{8RP27ZQuE~rDp5MG8oAD-6aJ;lY<+Q3n^>T^mXF337LRBuz1#bD0eA zJL7;ey#WJ!N6+?Mwr|M?e0o(JtbDZl1i#0qbV99l^iJHRnAJ zyv7Gl;vdc5;_*qfAFXP|n8~GdsI)rZWL-}H@^8Xx<+T?}uRTMPId5<1`h3^PJ ze91Fctb;l#xaNM^!M}N3p<=*M&|CI^WT~jYf`CTZMKXOOv z6XX-b|LZ4R)wC6BrDmr=x!D2n1=RK%|EBJu7yriT;^(5cI#HKi&MCxckZo`u6U3L` z`Os&%5BAF5F6@0V>5FLTzCV_JUYq%g-cBS`bGy)Za89mjk#Z2)3dPEc1#I#OLob2o zu{R|2@=U0c(D(#s+-cpIDHOqce!}N#Sv}*SgU}T$m~gYEC_zWnvN^r1#5~BmLt0$X zJm>Xapj}(sjB2*W5NT*!?o8N!Izvs6ST(u7!AELyh-lKNNF#FuDMI~&EC%5)L<7;t zZtcoeKE9|GkV8Gvl94wd&G4aql6`Bwn7ndQo{W=gUsc^hH zekm_N-W|Yaq>d+IblT6^NiQwRISGrF^(%pqj(!srR=&$Z=e6d#B+QLxDJ)w+H>^4z zzcHaBae}3m2{wtoJxk@L2z5-4W~T@>;S&hJqd5$cICszTkkx>3*9-2991t`2Dpf4G_B776x>NiU6@R;7_QAqY!x%-1IO#^u*Bm z!9n%Z?p%C{`XOI$TQz3Nv8cj-GCZfR0CYMe5&%F{nIu9`Sp>wc8!{;C45%5G)kiS%3YgouyC3+YWOH(|7>qE|DJoTz5i=g&LWKyx&Tsl!8Bdy>{5Q zCPgie5yJUvl{G~UA(%E9FoA6bW;4fBtqrNFL`0O)JR1IQ43$4y+ol_7fb?ud>m6&! zsrE>Opj?MB|G!l|O^#8aim~Ogb-jHgsYlIFPKwzTY9@I$u&9~q7C=zw4mXp$9@z4~ z<6ia^c(M+EP3N=Urh`XW2FKhWZfy91e5g3d)y$wCueMA?VuPa@uCJLy(-PHD=};!Y zy|;7oG%Rht(UK?8$tNfZNx>hjWh;4NaL$pEl|oKCG54xDMBv(2#C-Ui1Tf;DawjXI zD{jmRdRHnt@m#Y_`^0=#ZZyL-!Uj9T80+PZY$Q^iAk?Mz%JG7e^0ax$eoCq3%pUE=mq~OP5lez99NcgIjh`T~ zqRm;OMpctgCxx@v7!=~EE3|gezS*mjMmCh)4mX+kIBI!KSDkXbh$(P;J}R01MkZ(g zS4j7}J9IDIC`xh3)9u9ziu!-wi(S zW98D<$keyQ2k7;%>l*mIk5-Y!9PE|Iy-vOMNg5hXq+DkZ>bZH@8yL3c6(?Qjer^+f zZ0$%gT#qb1awn|L{hjUH z^e&eNx!+jl+w1^doI1>n7+?4KkqMAmA?XhyEVwL*mv^OAMv^}xk)Tw*@}?S~IieQE z5BMbTK$3uJkxm4zj5(+ z7j|!_5?8nrT(F5T07LT#=>!r1`G&t1%xAv7%B#uuc+RM_lhXY9wYbx-oJ4giwcf)o z+`w(ooaK}=t zIRqsSrSw!Q#hk2KmKmI!fzBIdh^;R&mJFs}I+Zinb~c;Feqn)8{KMO@-wMz>e$s@u zxXc0CVDmL3wq9S(VB@jDSLe8=`}b(qFWc{_n5px&1mR8g+c1=-W>N@q3VDdpuy^fM z`ew8Mo!ugeFBL4Qd`2|r7u*wxw_ZWxp8zlYPd;^Ye3py_^RdDnoKcr^odfFnn;eLr z1DjI;Br47)=E+l&k7g=_%f&wTn>eGm=1khnuT$vgXC-{*x&N){g|JI|Syv=rfsVhm zjj0;%;(So7b37*ppqc2)%66OA!2d?tTbj()ZK&;K?q&1_rQ3{<(~BSpIY;`MDYa~atRf=!UIXwVx=<8Az%5_-(q1RzePx^f5lQ^q-tmR82d&)|!)tBIq_wnjPQZ*ye1l^gCh|K)Gu zJk^tN!;p=uQF)%kzn!O38(`u@$rlAQm(_1>KXSj&kYnU&vt3Oht)Mqw9jjQM-uf|^ z>3-dXQka=}IqKtu!ir#h! zQ&4|+JzkYp55-QyZK=<(coZo!{&b=7Hd)TAT4N~btBK>NNogS0%+S$HAFfi>#XYvS z>fcj%_jFUWYo?gwbt%`}cKH6@)AId{L@~2ZQ#q5X_BrMA*pX(SSAFtRxQ)cTVp?N) zVqLHf*m5CdcP^d&XlC1?x^Oj3=!on&rnzBf<+08iN4?y~E~L$upA|Ha+@ORxT|>wR zCp@{t4&YyJn56IVppX=qeliqXLEKoh>9t%jEw)aKBI9*8HY@ejW62qFaMzzxM>zh)z9H| zM`?OTdFUXAxjZ*6li0}znnP^1hap2TyaWG_SIZeu%4^oOHu6OaAX^uXjKMLXWNZxy zWHK41N)Fi>Lk6%?$lg+2WdDMu(9a$>Q}stbVzkunZj<9UuM+n(72=r2Cf*^2Fx#ig zp@1c;iZs&I+K+7_A{#SeHAdsBcdP$p`(_Gf+BBA?LT2QAe#EkxrKzu?bMZYE{Z=n$hOx%v)@M@|JPJR z>ae;_p;VSR2d~}JcxQux+87Dc{^4LA5WFq~sY#a+0m9--;G6z}*oi>gYFyOI_Q83; zenP%CIKFwj1!*8c-0n{8C`ZPGImmSbJRId3aak_vuX|~BQc%GV@n>sgP}jpua67Ct zLlz=tIQa(8pAPnMi%2uN>nD+mcEFcgCV0b;s4?{LBBB^H5OK;C?c)CjUC02xe9Y$7mO?#(zfs*e<%L`76B)*6aPQ*Od7R)J1BEe(_s;);aLJyGX2fQ7`SCW*|b zfaX8hkrZ{NF_VL)b`OGy&dC?ujEPpyB@<)8NcWB}g{3vTJ-Oj}w6-khC!^5#xq&#e zz+{*QL>aYqfs}2(1yOuBq*IWJ=RT?P>#qv!@!K@%2OOZ+5Qua~w-6dyAHD9@a%RuD zWv$0%&Ue|MXeOVRVkO(`?^Ey6_junfdd=6P=V7^(TEv48|82D8)>H4k<-ILh1Cm{0 z-OVV8O|V$0&fYTO5Lctt^tW;?oiDQ@7v?Sqt##bqK)2QX{xB>(IVeF-ewE&}|E;cr zMboZ9?GQJxi^hCCsVUuWuS^cS+s!<0G*ei7veRo(BNMu_?)PdlyKdLx)3Uvv-K|b( zyU&-|(qS8S7n9$;4V_^`?24^q=j(r&fgNY}P(DK91GokFi#8TJ zJl8-emUA>|`>bcHdDCHGzKkXKRw#VULGDpq>xs;N#Wu%;5<$DR!v88Uvg1+0j z)jU#Q->s4_2;hcvxd5wE(T;!(`I^&#;2{`E3XNy&?IOhBWmImf*s4Z@Q zMks1-`u?R|GMr93hWTO<3;=z}VutXt7FpARd7@37_+N1aI%W#|eCS*LGWxcgGPE;^ ziS&qR4%HEkVIIt}mnp`ixCCWe;6jPgN!oDz0BO(5q=Wx`cEnA_a#_X??F??*^RT^k zB@~fF2mDA`VldYmCM-5q0d`x6wg4JPt-uH9`EuNa%uBo^+_5Qr!id@ z;C-q4_msun_FUC&?lH0%-7$ew`D1!DF#HS|p!4+gZy}kKFvrl%3wfuewYgMZ7ppwh z#%HXPUox236J^Uzu8r5CWD?cW;Mgzd<5KGns5T}vPOPsoQt705*e?b&Xe|q99N77u zA*s83-G@)iqCh+e;jv=qS3kO(#*{Mou|Y27L0{pZFUmOVts7}CWQHLgj79b1Hl>af zOkgjz${p!{pggKv5KWBfzo#f@f9d-S-#}bzTQ|eAC|gg#UC_#+>xTZ0?HSTL(q?uF zK(WbS+=Q}_tGB9e7L%<&FQPi`u@@fcO*-izxeRjx|F(hT7Ybd5PE}SNXCID^4)7FS zES&cZ9U08qC&xw6nS8;C7OS2E?)>mf^Q?4shPgn-$6Yhv5}ZLrq~QsWBbyL-F>nl-PL)PQjK8d)jJjdcZ|V(Rk}PF=G^fk>seS z)S>o&y|#XjYqZM-ey^$NXczV6U)`0yTTi|46*eeX&b+>~om?5^ciqnZPlF%xgu46= zY+bAFe=jGidG%!%$KCiV-4I^d?-h=ds8w5R`q&+0)ch_gCUAm^=+4Vq^<63{+5(&c zD(oeP8(g+t%E4B~qIqA-s*i*4R>n1Lb?2Jt|J|DF+F-`*qG@6rDO8*5*)>o$P)P2r zrj9MSn%k7t^V?aExc$Nos`4FbC%4;7s4OTFH968BM}eo^BJj{Vy#p$NQE3I+u94h6No9;(c)GiqjUe6;)L~I04w>UP0zMc`ncQxiI zWI|iVr}F~aJC%&6WQ>DA(Uiwvby1NHm+yG->iCVR>lNg5WE;id<2a)I0Ll^9f26!u zBhjM0sl$d~+N7R&o7B&jty#-d5A=HXr8s!3D1jD^4tBFG1Ms8QrZWOjJQz;yINV z3NnHET;dYJPpLONmYVk^SsHRI|DKG`31Z^<7T$;%90mKFyiu%t1M%FpJ6V_QHe8LI zdhY$Qc=<9A-BzA|kC6KW_ySJ+vpxbT-m`akW;jpfGD2T1aVGk$wAP?i0B@jzbce6I zb-}0o8b-*l;fXZ^!MDb_F!5$`-~g=5N_D0g_Zp@?lUk0v;3-&kf1Ma|NhLw>S^CGRU5- zt>E43l{!cOehFMS-*@#h|FSYBrFeC9&z!Wt1;ufFpd>?WY#_SQDVZ)Scp-=6mo!+BTr*HEu=sf)}iO zO@F*JPyM%ig*(?iUm{EX%b-STq`9rG%0k+th=RZ0k4;d3AI5VQCE)y`g`BMn;=SsC zy3w#jKrrxIux46Sya~?ckAxveL)^>0fIEatB4fuF$Cj5ZXF~8vfEwlZs^(=oMtFEJ z1O09f2*8sbFD>>4%$4dtY_az`5Ch;%MQg{_u8@$vrf$Eb%8eNGlSB$MWJ<3W{WxX`b3y zS;A;WMCHAcqYozMObd0dAD=PG)ePPv7=ooSuz!M$-~bGWJwCfql60vCqHqFAHxnwm`Yx?i+foc0ND!cnV`7bFRA}SJN8f_{UsS4@+LKWJ@Hl98WPb z109A{1-b8oZ8BCmC(!T*w>@tlnk|YgQ*XsYsgAC&T;s*u2kT-ivo9r~w3=#UEK?yf z09gqVBLHQUXPu=Qfp+D>ObS*Wbb}nQWa5*B!cHu5W1Rj0uA#(ni)f5#t~XpzI`)iW zL!%%o24;Tr0(7Lct`0yc~2RH*MAvhYeo?w=N`KRt<} zQT({`9+Uc!>WD>l2DPMAs6M=;Q>mBBo=X|R1fc+WqLwGz7zl14e|_9N7dIPQ8TX&6 zLFQ(d6wU3b!4q#L2<4>yeH{pyc&{!sbKN9X*)?_AMd^53OKa6zj6F{vSxio4$3sX4 ze~#+qvnGaz=isc2TTBZ;(tfsJ(?Sr&r7Dob_KRd@1P3RQn^B=j0sx%&EXreb(P0p) zh_cZK@PC4$fo8ob&@C9dYy&(w8V8rdNp$L=^MUYYRLL*@6fIlFM}1SZ5;{msAJpyJ zMRh@yDX4sLe8YcK^KzwJAiP$gr$hbwgJh(HVoN8Dbyh~Haf1NQq^o&uW$i>g245p1^2R)UwhS^F69rc7ZL7mV8l3cKMBTV9yx7zM_vj9Z!<5|z0|DEQ=XfQ_w zJl~QHUZuS8ZF6f)FIQR^1ktNNyB$wbqX(+~hnFSpQwZu3k^~8;neqa}C zl?)qYPefDG2!fGf7W;4#ta!)PG1e(cLXP%xiwTbzM2Ty3tpXEOM!jL@D8?W{20P%k z)kr`~XA}%g-yb}rU>w9HX9Ug>>(&}k(l!H){|rS4ir0>qth_HEOvHS3SDoZ4nn{ zEWy@w{a?Kt8U zK;l`K0j?xU1-|HPyTNuotom(>!fpHC+9NmKDGZS#F~7D7q|Kekb#Wv~a2|Z&4QxS7 zl>QayRbffd9GY#X_EchIG;!PfgVO@4VXk(s=c~{6juUse5;i1V{wdP_h`V~zP$WnF zt(Rs}V+E6TcYGu{qC8QaH{bcgW?J604);s0L6gR_W4E1h zrRTV2f}VgsKmOU8lU~3vs$X{K@$6fB?2_6l5f%p5;#Nf%4{SsoGZ`|BWC*bWS9HyA zFyDBnhymdRqc5(%86u zVjjm<@x{5ke`N%fd<6}dF$qx3>;0#KVE9VAx2^h3+H}Fq`#xCFanbyk#;zV<{aT)w z`j??3zrFFo-}`ByV!&;_Wk+@qf10bCg*S&4RQ5Hxjlr&3_Sa}ecEi#ghK=8vPCj2^ zU9+!@$oSK{#`9!#ShbnkaQmeyn6cGZVoKi&cDpBPg=-xdubQJ~Ad4DK{m4+;sM3!y z!6*(1v<1}?lWDKOf5rfd*!tT#W)_K6s(w86`b74rjNfwgb;ZB!`V<#PbhTJ5p4`VI z(vs-i$VVu!{)9_&jA5q5nifBVHBHuQmzt?kL&5k>Xeq@i2~n6?$6|vR$bJ}}mWdb^ zM2ZANxbkUdm64)Jo>VN6>Hav!39-G4iTW%MlyB zBl)tiD6`j2V)_kF@C(va2%zCDk(I+lWF?tHNtU_#Y}8}3D*7Wa*b7aTC4#{6F-ZN> z%2pN(dtKUgY{jY|w(NM+Dc_=09Agte#_Kr`3 zr?x=>(4c_Z5t{Wq$f@Y;bSwtSY}WYU)m_`q<{>)|#4fLosarX}k-3%4zgGrYS#ph2 zdH>SXC-SB=mZtMMuFDO;EJTkxfl`+hD;uk8KbV9vx8NT;TYs0ksRNbQ^TgMCZOwg? zd45gV<_dwunZ$>`6+D_1PsNo_8~o|zxKe*sv*`bg>Sx$rNV8u_FJ9=EpUN*kboRz)-eS>K~Nvb%$!7{xj31#XLm zb{RnDiY|Nyd88T4l_r+{9uK&C;hjsgwCK50VU;wH?5Z8TB@dT-+v{ehTQry7i4!d@ zJea2MBoCdm(@_JX%~0$n0U-TilN!fiWs2q>4y%d6*%BXAO-}(sBR-@1K>#TD)wd7F zgQu^Y@N#@Go_SZj$|~5R{#*Yrf8n|VZ)^dnxIAl>HEQXd!o!5iu425M2Cc6##=xnm zRKF^wF1C`@{HoKznGAQXlwMo&(@)jz&Ux*i>$+kLC(ujMY8Ch0?nAV1x}&&^)h4+Q z*=Sdm46sdXkJe+#1b{9j27wJ^mA13jY;OrZUg0%MtOCFX)4F9i(4IPJL{?`5&16D3 zE6io?MI3}qnu^nLhj6!;F(t>~AiEaXa>Ai{5fFWJGWH%xlX{trbso1giWtcijEW;? z+z`hb97Ko8+Aa1oJ0rc)iKdAx`f?N%jKn6v3RQmaSYZJoBU&&tl@5$h8)ysoXzgp= zpkR|Zdz$cGvDlsp$5jt=^WH|H`<2$&tMK)D7tZmQN67e8asy?3-Wt0Q zF3mB5w&c)c4TCQ`cZw6+BwF-jB7Nn{(!ZQ2HnpRP-m|vV)|m`4tmi3C3%bjOPr__E z?Z5B3NBA%kOM2Y3Y)ZmyFe*0-$xx#T;O8NO%mO7Lej=2r8`36X|#3hOJDpdWD3CPgP%7 zom|bL(JYzK;T;Rl7XC8dW&9WriQp$6kz*94p$x{KpBbB&v5{1dz;HZ#ep*NL*8l*b zC;R+G0iEv}>lZ>xYI!V+l!ql)*LIstI{N7w-@3V5cI*5$eoNYk*wR

IUg%R_>;l(u;TCk-XRt&AA!FwP6DCCRNU80&%CIZ~KcMzqbi-JV#mS7HhA4YPh= z;8?KuqDYhI!iu2Ag}BIzgPNy|LBuhkcFP0WgeH&=^uuyIXOss8xy{LTpLIt~3AOmM zog965;(zt-$@yZ^w?#(kkOdUqlOLFRyh4Dx)5&8iPkmk9*@&@cXI*l&5el@q>)Mlr z-UzomVJj;l?$Esi}HMo7&SX+`!6_LVuV>$~Q~hQz34n8XnkQwfg9G`ePKmT8*losXRBk9P901O^6T1?C_vgH=?d1P6fv zD6KiC9Gkr}YiuT2dKiq0N#YpR3n7dk1p2=gsPI zlWZ}iGWUu|1B3Yt+!l>9Y1(1YhCMl7!#bnrxJi~lLV4{KBzq6j$>i6_4IUSZ7d@M+ zn~l%i;DiH)+sN3F4+ettV_PzIT#hLQvu9Sx?tFV=l{}+V9(6sbbLcpoX{HeK&xIsL z+E^;wU!Z8?yG5I{z|;hDEVD@7#3@~~QCR{6K5a}!J7Kq~0H{73d*ND(%f5h1}A!rsT@AregD9a|kIuN>?+V zkIl%jNX!w)v8~&F>FH?gA#<(L{zd9`;UmvgD$|e5s_De0>IxnQtv6Y#)mWvVri=5_`np(k$O8)#%3tQ_v-u-jSR*PU!#*`F0e?~Gd@ga4zDfsUkDz&>DYyR{bPcbjy`&6mTTqPE`r!qypN&R3aeI zGl!mIamS$(HB1UPuScb{_b?+(!K5~gX-g{IG%H^G#hGC~!{X9%mEch_m6_N$C}b5% z)^a?Rblr1Q>anvhp8LBV>d|hcFGoIkW5g)?ktE3{)<(OAG6Yw#G7OAd$C$gEK#s7m zl^||-{Nj5DXh4F@#TZibrp;(z>FQh{gY7!NK%AsxUwA+_-mA8K7b6F*oj^UmAq4xt zQ04!2+sk61$sGBtKWjV%)3}lqN9Do74;t|R+Qmt{)@Kmef?l| z8nKFkiEG@5x=OOqXXHLgfP}kFNU*Lw7)W0&Seogpsg|gAPXP>UK=0V9e2<|e1WgE_eznJ#WNS3G!tC3rl!oS%a|wW8oOl9y}d z5Ib!gA!%VD*`z~w%$Zbg^!aX`C=7;0y-Y3mrd)q_(}}&48%&EoBvP^?p_thdrPUB= zj_l(fbGZD5TFb|TD!a(QGJQiRnTLEbO=@ul=>n|m8;VHsB5&%LGp`hO^x|7JK@(Ir z=I*UN*TU{xqVdB%XIN+s95+58c%QD8(R>$knI%MCINN8))EpG+I-}bRx_ZV09FHd7 zBn`IT?-5Q%ldP$mOxD!U#~3-eq^9)=%irU>8aUZ|FJN53 z$E*X-PA24#$gy6R`a!A?w55G!$1Dk#Ap@eyHov(PNQCV(jZ^fo#t$)J@I=a};`UO^ zXvlEim(!&fBZW-OQf`BbtDfMLx$zLs=nx)-7&4^qCsZ-!1R%7dq?^FwRH$0f%hF9p zJyl5!2)W1=NT|b1G8yPt@MbCxfj+#0$o9#{@`~>9xXVakCvI)b&hTS=p^He{a;3oi zg;?7#HUoPN^EeEJM+@}9ogi;Q_20)I|D<&5k=d_ooypmESwz!N4x99$k;4yxp`iss z6P8NU896R!YuO((2XV1xy{T!QRG)+FYrsdpl7*FU+G%YlTga;h0_TvL+MnswI)Kk4 zB(#i~nT^3AGWF;eD1%H^s#aZo!6`VwB_Bw(VZnN)QU;^n!NSRyu{6;RnPH8Bn>2-@ zC+SSzq$1}>8DG-ecrXuORaCP-=v_iu`Cee{l!Z11`*cFAm;!1+ zXc<&-ReDRc@v)HVEoY%U;xSYd9Db5^%dV)u7Ps@&lMUw&{{)>`ldm`1y+v7qAK=0t z!PREJNRmOut}tBi1dyM{AGrhBe&uN;V{0re)Rdlq*bH<;+AnQ`3+jL^xc5EFKHi-% z8*OO+)*Ycv8IM=pOXQVvf>St#Wlb(sCxV+19}N8`R`X{cIc+a}?E{KysAe%uMeE8j zS(rgc+0trCMQa9$rM4w0fxLL^A9Ft8`{GB5bUD6n(9nvPyi#V(ziF1Rw3AG95m%B! z?ODnkMdN+o)?Wa|UTU5i6G2=D3aM}?o9KDWF?I!0tTeiMoAg!^vS-#P6|yQ?-IAoo zOV%We#;u#FWG}#=i`CoF*3tkc+u!fqwVn*jm{2oJqIsLYg+I?>2Ce0ecP5>^_AUe?I>ekB_`5AWmc9s%wT285mRZ`S*f%<#IC)~nKd!U_S z_!2P*QpdJk&?4|YFU`EJqu}855k`Y4bJKOf>>pD-5sL2Wp?Zp9Q2&Eh{tZY` zfot&2{P=)sUuKd#PUFhUF_k0_o{raVOYt5Hf^qD2MAfcJQd3HEa1?gxfynYz+O9yqJlV5qw2+M&FF-S_CgH&_EZsyj%u|7hCiV`XQH*&= z&-si8QDSn~-9GY;9y(|eGr*B6fRnYGX%#y%&bq$rl-c3YYi1K@#z)@h;E%qdw6Y0j zQvX~4s{xTbYj{*(Y>ga_Q6UKs^R}g~<%PSE7a8Y1Nt;I1NY^^K{B66md0q8yWI88m zV^xNczt}mud~VQ+<+)~BF)tuKdI>GVM2%@x`yftAdElEw)*pBeiV3ZU&(+$BWwAwQ zvp!nhehu4qH^vSg&OV0E<#7yS_oOwrsFFqvW&6`Qv!rp7NPZpz$frW%bgF3?+Nbhm_@&;2<8_n!F%eeapRwDCN)3C|OM6|(n8Z;RZKgs@~gzTjh&jvlR{sO9(+}h3fpDAL1{uIzDyOf9DQ6+zZHWE~)RIyn|5JVhB)pFXYrA|WjANTKaieY-sf zmf*gZUVhTacm#P2{qdIP?2E@Ip@_7~lEg&csYFI!Nxp*au(98w&CqHj7A|7~evgY} zhdvgww&k})CSD)6DX4w0?6O1djVUXmwd*J~m%O4IW>n2e475|< zua!3fw%{NA$ue;b0#}pe={p6rT8?a?o!Lci(H7I7(rh`WmmU6mo{*ldexX0`nSAO@?Ysi&n`kr!SD1Dh!KOx?~fcl>3Nj~$l`-`uIU#t@i{glKT!w*S;vwh>b@DKK(%giTl|C z(6@;_#V7S%c~gbfGs>JXL4`mi7JD0}W1vIV%p>v6H|$n%EDuq6RWm(Udt`4AYVK|f zMGrGQh?vu-HMvX3HunrO>kTY=h08ac{ffzY}S$7o9T0USf<@VXxNO zsySEp#kX6^ZLZqR@O5BiPsx3Awl6^Ayf0Qk1T`n{nki^1JhbX&(QqLH==+^Y^EyG= z=XLOTTHifZ%DJBm1pX}O$cdMp6R%Fv}HtuRj$ zSno+d7}-_}v+V12g%EIuBNmXCpwSD{uFhYS2nsoSK>NJPkq&9qW6GvtgjYEdxg2dVt>Z5`)1FOpmlD zk~^#+lX`ZYFexnHkDro5d|)&KXgvV)1J7+h8Ce?EkH6+bX~Og~$iJbfRd&7n53N8+ zDp>uh9z|;Y^^#%#pJ>bv=Q6fv$Dy5!iu~RrNKg)aq5wlPP=!h=MXAUT+^X}dYZiq%uTbGeBvhVGWT;c)>yy5vro2Bk;c^ULAoE*L$| zlDSaH2n-G)90Vn2N7Q#7K{gQ0`+M5dlVdD(h2G=*xuD?|;vUdsFI8UdlHEBK7D>W5 zVREI>EaOb$RU)grv3u({SS0>H!+T}{4wr~vQq5=dzs26mSAya5^nVAgBEpe^gG~am zVnI=?M_BnK8fO|p*~n*@c#Bxpglb=t#F)BLd6zf|avjIp*HW^~J+>l1*cn4{C^K1j zlMhHClgnEc?jWd9;K4|c@si8Qcqa}IfI}OEi(3PyPkw5gQ6@WJAZVO3)i-E(w%A@8MLzPLyRR$FPE!`nvp|nT@ zPLxBLNX{L3+wQ-Ku8F1T9&XL*%yASU>P225ovxC!Hb?JaFmV&M4h~HZY{<)mgRbe0 z^6$df@zSt|amWi;#iSY)KO^$T#M-gP*>Mi7)_I#pHJC@YR$y86I9Fmt*{_OaU$9-f zG7wKhMOh5h(h0{Tg`<--E@qo7+);a!>!*!o^^kSBbl1 z5PP!s;BN-fP<(Lf;#0f>VEPtrFmaNl9|w*cN#XF~Huv*{k_;`(I7 z!Ysbp$^Upd+>pzj+u|76L1d3Eyt#_hL3M`_fZOi837>jqKy!~xTNmGfjkT?0n)EKD zZ|~m&d@;g|NMufDuRZJL{%qrfLJuk@h!`%BG?q}+=OCQ$q!4IuKosK{mfQ5QJXUm> z>a|-2Ypo4djua>wc?XWE2-aNCRAI+;>k?L6UaR<~3aZ}1dE%-YF$3OZ8wM1|_?1Oe zqC#y0DX8LT53y0S*3Vv-?G|_Ns9G|5I5YPov$TvdS%+9yso}BpCz-1(5#`M8I=(*d z@&*BebzoeHCmvx%iF2Z#IBzJCg9Xd$#VnW1s0tq-2roS3V-Ocv4E5DX!3UKOrL@kO zW7C6?7sms#sc=I=-K~%ZA`g^UxK(jTi0FGWixDN_WZCd z&my4aJPei{Bx^ErnXt?VUu~?wS znon^}bU?G5ZvW8%zlnX4?p$`{VYJw~^&+hge7OF2NO_dZ$5Gy~0kJs91ovquXYUSR zcv=d(1NGu9sBM<}3(|)PX{`dgYE)!*TE|`37C;B6%=R+aQf&M=b-yF3`Yv^d)e~An zZV?v>HxtJ<249E{MHLW4%At12lfo)gD*R<4w7Bm~gQ0m~E@*Jwrx}cWPB92R3JeA* zvoaP8nPh#}8e+v?vm)AHFLup0syFCfAOwsZs`-pI%4Sh;J zr>#u_LxpHy(PnhbG#eQ^pJ(y7=*rpz+WmzB8b^$R#d6wR^8 z5tWz_t%Y$S$kN(#sA!#25j5tLU{&*`nI8z-7hnGYn?Z@5WGa%Xr_VS z7F8P@fmU3^YY)8gSpUV^H$`{yL|ezn#I|i~V%xTDI}_WsZQGvM<}bE2;g|o*_i!KX z(|zdPRjYdST2;Ne`|MNaoE>_oG~*e%8q~uGHtYCcLqR-ju9l|q&CH{no>qNMMHWK1 zni9C#Z&3zPWlr>LvKtV`9}-7Egzc6KpvpC0&s$QOEkAP1BHnizNVPaVD^Ez2Z*g0E zrvbo7M>~0a{hoUyXoUu^iR}3z%Wgf!6VENE`$plpjx~;?FGgzjF*WxdU)OUPB>?AQ z2h|l-PqP6ASaevHFR?ZQ7GRT1ad?2QRs!|#DXH|LbibtuIbtA>e}tG&h|i05&5(aHVroN(W7VQJv9$U*)VXjH7)3hMrfV&LY@7aXTQ-ac~e zIVhO@d2k)dgz)Md=gt%S?RhcRj`5wQ_uv7gu5svZv<{5LI?{a*-Aby-KS!H6>Tg!@ z2e}+VPTs4Ou!bT&4?r4#nk$csp)oBCn$gbx3-d#P%^V^skb)GXx5wCszydA`C7etd zJ3@#9?HFrNeyfrr`aB>)UY6)3xxL74c5mMYSs71BFF$p!ZXbH^uKE~ykbYUMjP0)i z+rsInY?<5$9`tgUlg;UzdJ8M`$v+#{2Ri7c2&F$=dM~A=`vILtLbOlA`ga%0S~2W9 z`am&gVo$#6VZCL-efni=Pu~8w1yHPsuM7e?zXaL|=6Dp0e;pzQazIv&i;XG+b)W+ml#?W3hf)IeqJ2gbZ14K~cgU!Fe%1E8%G7FMjAhr0RSbH374Uzf|{M)~GR9%^ntVRbh4RO{N; z-5Pdy^eyna4;Z%IrduxXO{fvaMlSbEj2U!|pduT!xgA&=q(3{sr)Lbva2$QzlEZD? z0d?{b1z)m-`mixJ$Rye|S6L!mYsqV*$VP;nk|N9I<+e!{NqB@(6D#GO8gBlvy!+Rm zM#Z)?Oypvcjs~worRAO;lLu+ji~-;tBw7msGHybD!HI_&afI*@trB|>?+p_K*AWU3 zZ`mf{5Us#u9kEi$!vcmL9KnRd{YM@W#?7z&qCum?L*uu=X=8UikE-f?Od2zd8Mhcn zDCex;$Bi+=6Zdz5jEq&>I;XbFP3fK6HkhH-1q|A3!s0<+g(*`m1KB!tkFUoR>pTUn z1(uDD-CDG!w&=ALFzxuNLjlJ_jl!}VEM7bY@NhCU`EgJMsPi2a7wokQe;D< zQ99Z+vImray`NEqHd19mG#}1Gay?c6^0G6Pdydi@=@fL@wviwJ7|}8%2nsgf*$yj( zngb;4#1RD~Z>)v=bvg;N5&^`@7fR(^IA4hX#84f-3u(={A9tsb!^eov0NxJ@K7D8c z57gmP-7~-H66E=n{8P2wPy?miy>xF{^8#!|3Th&SHbLk_Sf|HyzJjNE{EwV z&kXgEP=1=eOnM>6x{M^j&J1{6l0>4;5WAm94xD&%w*%I2aWaPD&Qcna)r}jX%r|iA zzDiG49Ne^oVu=RFg{`^-oLl6PirRT@%IC8)NtIlwj@jD8-=PyE=4S~d%LyGvK3<2* z)Vx=*FsOQ}crpl}K&82_sOsWDG{w4o@c}skr~I-7+}NDs6+%>8Lwvu=ha(c5-BQds z$4e;kJ*1qlYaIoW15ksBI%N2gv}evRcqjvw(2NPW!P34^d7gywuE)o|*tjm5X{1!@ zD3kT?sbMSeE1M;HVgo;M(%wRO)@jp03F0YmL??w z%k4B4Fdzqu``o@EE1%z4)VcLiNl0XFm7Jg*Gm6vKbRj4J`)ckU3^IuX9 zm{)aRWj_rl?4L&8e4H{A<|ilkELwDoA%x{{A$>^s$8wUm3ThOHgsMu-&TczTT>+1- zD$Ofc{QZUfbJhEWce77R&7W5zb=$R0-Fg_plF14+LD6k-9Fvih(?Wyb)~$tHtC2Lq z2V7JG*hkEHAKv?(y-eH<50IbaCx;9lRG!Dfhc-jcol?iULB;!?@21(yFBM_w*`U;u z-R*~2gkI-*9*1UDhsUpy>41|Iqa`a-7zZ}g9L0GYT5n@A`|49X#3Ga5TpE$^)E^hJ zT{gheIXJ@{Je!;rvfZ-wVlO+*MbFlH#-l0KT@oLB&)QVnw^b2uYIpj!l>~b7vE8vJ zIS@^7g+@*xJm55I6%#Xh{Z;iSiXl0)s%zs~AvsfhOzcdnBXX@jPexn!(uBjPOqJM9 z@4cH|IV*so=UlZ$>LVVoL@QicVS}yTn%6%@uMh(Dtu=;=w$ubiKrl4+ ztr_LF4-a0mOtWuaIXVBJ;{8_TMV!TM(&8Zz^&8}F&R3LeskACo<~qO@#^Ms?$9U$Z za|^?Lo3i~g`Soxb-`UnSSd1ik)vv3F z84Ufi+*5&bPCTdaPyHjXB|xhEV@oa=5Jp~=tTpFlH20`-R$|Pu`$QMEhZW7EZ%gG`w`i#x(U*%@2Lx5Aj$wFr z3}B#DNKnly_EH&PqUG~0*s0y>MRiK4Xxnp(*QTH=s?szEZ}GGgvb zQP%aQ*uy=(oy(N=_bYAM#G$fJDhn>R!{$gA9A9uah`1arL%$BNtUK5PRj(#Q9EMtz zP~$x6Y=5jYSTHGzetw1OxaS`q7auEfHa8=)Er%(g+K^9>snv{)ffo|#>T_>ozaYCJ zlJ12`);W_N38(6J{fZqlso8mjPv|>JEO_0kBWBBLUA^twNVsVn zc!`|%i5ZJ=EIO|DcxfH+@l8kfuK;(8s;0KB-%97W9ep?Q2;X-Ag88f*^T=KnjtKkp zo9Kv|t2W%izJkje>VI83tvt6B!yfzOcXO*G+Wq7~TQiK&&nKoq@M>#YeXO_Ax2VvR`UrVTN;^>aqRl z$5It^jO5URcuq9YmY_9PN2j%r^SVy3y-EI;)MM~G;dt?zpEa?Cbj0ofq4=W8P!yVO z1(H`jdzT_#8aEw<+6}r#YY9r1Q1>&H2NE=!3b{LwGdpc#6G0TxK@?Fzvr*fS6WbKh z+Z1fO8wD&H^XpX#Dq=3W9x>@J!G2?Bx_GeYp1q?>HAyjbR^$BCI z$`fXmaJBuQ=C25>b{YV!oBF*^M;v(_;>qqglvi90>n=`1WbAIqI4C8f!=Vp~kDBvG zNq7E{iFQXL4$ZjNG$HRIja4%E)CpnK0>X#SBia}=RKzt$5`I(*3}Riw4(203gzO5j zcr+uiwruQCa7auG)a;`C=dhH23m{!C>DmZrS_qWs)gKZ~?d``mwVSDMG!+*q{s^=2 zzTX6p3(}kyX@P7+f9hnVQ{bs0JFD{ZWdMF6NO}W(G8m|nIDnf=SPG`+k|1Iy$xF*9 z#8XPj&x*dqQ_mfHs5#w_oMC9^Ji)OnAq_xE>SWRbA$usje9CnMrF*>K>aC zdlnd*DX-F7ne#R@dW2f5X*F?5Wg)d{ZY(2Kw$3#u-Mfdg+)hWjbE{B9?QN1yk+hA}^ENfMNR5oN$Cg<*vN$5(8{GHKO_=6dBw@pKebr}CKYz$V z-rAx*Y34PnJ@ThmJ+~ey_6;X{M0;f6qwEV zh}Z=vpf*2G)F4`cPXD|_LZlYB@tZ_Tz=1VR6v3SWBvkIg<&deXFa>;bD->fyO9%zP zP;h~xKh>Uuej!>Vg%LHwr2bG8Zvo{lSa0$hQ25!gcOp^)|I5J7>oW{)Z^N4uBq2}| zj>pUc?SOKdYql{{7}^DBBAm-eJRx|EViX~IjhG*bv&PF1>{IXk2MXK(G7u4Z0KVTz zb=$G-_tz^AdqjqKgM6=n6%);iTfV7E$^9~EYn*rG^@uuZZ*v5Z1#X4$uTX{Lo~qP# z)yQH!qlyx;P`-pReHAK8)5&TojJ?YFOlqWYC=5)O2HBWXB-6Q5$HdHoWszG}-TZsj zHUV8F+V#~!)y*VSi31D>)L7uVUtDMZ_!edqRZ})|pf+|8WYP}hOHSb`v%k!Ah5Hiv zj_kGV{dMmT@hnwB!RIO$F} zt3+$Rl^h&w1LI=u(R4HNR&J<`eFOV)QCw4^wt)wF))cZrTTcTEfNaq~(tvT0L7F9@ zmR#|dMkJ;Ucnutcm+-bVk`OiA)pcOO2{pi)4A5)>bseDW1{gecTRsKwvYztspnhx( zha#=|+$O@9KI>KST~mjIVsJm+!Y*RWDscrpE+|ds0sXk*<6J?Ohz7`uHj%b`gkOB< zWercE-F?IgC?Cy1qpUSkXwfW&4yx>!xbVV(%D*tSgoH)?hQ^*y2WBso@d`Fe_*C*x zKtJNq$=e@Yua-t(H7hPa+Ufft7&(u-tfi}~bL&*EUmX;^8G*=Q9x_-vm88`%$~g>i z%CSwf5OYE)1Wf;L9hp#})wEj#NIDOfyv1+EdDE!uj|Ib5-8(`%4H3L2NZyXno# zCt@nWQ(1lHgwSZG=}yp8{_2c7@F;~$F)07+abT4$RIY>c`D;YLc53C3r`*Ii9Dgl28*X@KRynNX30(0>v#pb zh~-B87P|N$K1_Q44T#LAV&``h;cx?_CpP5r4OJB#AX!OTF5|GBsA)fr2AR_)8pou- zaU$e6agBB^jdnuRY50XZSi-F1h_j`RwAoyoyv*F(WUX9orkqS{KgSOrtH+MJd6tU# zCWdYYH)=N5{Se3TAgc-uYYhxa_;uNzwIXHdyij3oa?aqHh981{Cd^7yxe}L%*L*=9 zs;_@Qo^jM1kL~qladorG{&bIYJ%m@pQ(dji z&Iu0+j>{WpdbmLg8`sSbp+%N0WK(EnkFv!R)t)R8*e$y4-!x|*3KMavleqR>T6=Hx zZE~D#-Ntp%X`8@DwArlx>h|2bikLnIRhQ={&E#_d@}7L3Ii@pzz$-nx+)@*@Ldc#M z-!WL{{^;lKUfyXk^tG^lp99~5yLs2zc@f=pAHnYkiE&tlS@cA$M9(;;!Ln6)d@lIQ8uj6BYbsDA> zRoELr@SCXq<+al|M>|_{ACF5RtBaAdg^Tf}FyyUkWJC|yZhtE{tH@0@y<6VL{HxjN zKgfc!JZ5J2kDyKVz1Ya!_|quf+pCWE>QkJxR^*>h9hldBqk2);u?awclEm;%1jEnGZY`qT3il8(u%!KdAI6{P|<=Y3J>SIdpVeyLB68 z?_38vp#D5jd3+u;kZC*gmjT!CAya~S8?T~+*>CHuh)TxL4-V{gU(+R+PQGxz(qr^NL01|d%Ky{^F!{5YZgf{MSW!VM7bW3txq!+AfT z$&F5-)qWK?1b3!J1EN~!qikT63G&8(_t2ZGf=E7(ZXKw2eB#z%Z+?7pan(OFelKVd zkA_FHMapo<DGXtNdh6#31; z1+)u*Ykje}@F@cGCEkD%^BRXUO`&z0DIGFLy$%9>q+_3=q9(SD zvnLZuBj}Q{P^L##+$x~&O^%HrlSZ_?-wz~P&KLl^0Sj==ZdK7GF+y`#p*CoSqw<#p zNf@(u|1V5XNOZ~y-QR#+qcXiraEs{)jAWIz&L;s|tE(Md%Mj+)M{Npa{KLsE)o|5k z@}IP)L^y2&cyBzt$*K@-5`BI1TT1qC>LgvWj23>$cm|AAP1V0p8T3*OrE~N(YCa>Z z6#Ar2IHaC#DKZQS|2!qIs@3lGIr)D*%ushAAF>Wb=W91~Bp6=NnEgsEu=o>D0Aop? zKn2V44?sJ@g3B*6pH|_MSrC@`+bUO*_O`=@VuB}Fia@Bcfe5n@teQ<

CQ!{;j4D zyo5?ZJd9pCQhR+@IMs@lB%`CmCRCl2V>d7kKmU(ofYveQ;|NQ(q2|>jX5?((p)gt* zETk^wP)TEkw2YhT9hq`(8B%#a)ilv$rn#CD?Bq47q12xcW)&qGcQ69~E?B$z%?XI6 z0Efvdnzq_*ORvf2(5tIkgqNLzuiH5SymyQ-_Lo?@MB^;k15x5;Q)?QxOR9}$A269` z(88vcwcf7NtxqJoMuIh`R*bF}jGT8<8b)yw47-~oM+3VJH(+}a7nh#h-tVtHd2fPf zpV~tky52{p`GjQ0sV{Jw$zvZIvhLKXGE>NK5rE+aAs4868R}D@Blqd5d+1V+dILj< zwI}wltg^M}cGe*SM#>8?>81J)c z1c3!@L|x{7`yrn8%#j)#`m8X9%BE>10N_=3dD{52UD4# z4)B)tO1ht)2okDJMDr=prRMBwdPSyN9Wi>3X{*KIV@QOke5LI6 zcy-m0l?P+dL@!VaFQ-#0BJPWR6{oGePVj$$oNm;1!sZ`ZmzH@8OQiRXx>j(r zUs`d^y79#I>aP*o8Y#ng`%=$DbIHi)&sZ84a%onEWpKI7o+(E0^1D@uBq^EN$7!16 zDS?~__1_pq@XIAd>1%L?nfL^WxYgjjJK_^wL%dfKr1YN3%U1@|0uL>sUdRx4(iZ-R z-W*J>T6apKz142pI03Fiht)j~oepy`8lykiRMXUK4u6Z(oQjH{_lOLYr_4xc6D zQOcLV2_}4i~eA|lu9hW$xu+a(Du@NDP{ja~{`sfCBlkd)%PQ!G`*`n?nBbd2s#m@`qD zeRBa6Fb@x~Rr%H;FeGe~-*5!C>HfIZc2r5GYjs2Uj5Y^63JGzC>4i?PyiMK7s%y3( zG@>R9Tq*POU`!oL#p6}(^v=Q2l?b5}tt1nx`f&}CGQX?a?K6Sm9bt#~fbjglyZJ$L z^MJYEZoaS_^2=U89bQ2l_CV)efHBtwuS~nofOj5&=O2I@UOkMCOzwxqZ1Cj{* zR}ci!WY!p8W}#-)>hGQtw8d-X{#=4;e1JNff~FUKq9mcQ_=4;WLDnnUpoBjA0>%0n zH5!!01%R{o?gOt;U4kMe&=IaVF4I74)Onf0)Q8s1q|wQeNiX7UmX>@{_b%i1Os0H* zsuP`@#n{nyr*`FbvADH;UZ1e@_NeD*&*ySe^nHJ{SGE*(M+b+MkAI*kB*R zW680?{B3~wlv;`BAVBaM@dDuIw#c}VP6P9C0`T{&Q+uEue?B|UB#b~m%nLDq2y?@~ zUkovPLKX@($e;~Z(168)hqR555t=y1i3VizhnS5aN(2hjZN>J(@7c#IS|8CHMDSjV z?Ky%BqcpbsdM2VjkWDwQs?cQTD5!OL%*R}Zpp6}SCZBrn&?iCn>4qGF;A=2kD?kAD zS@WN!Vt3Q$rO_6U_CsPFXLrEG88X?5?D3C?{e!mVECSp*)oRNE_J^vj8OZze7$a(> zHV!DDLp1E<{FFT)W1C}@A2@xTPW#u?C)l>j6UrVp8_3tP#HkC=_v)X^pR?cpPuq@T z?qcKM1p+$o{om5I)&5V?wjJ#4ZT_dW@MRB-3+`9~Vfr%v<2Qm!(H#vU(2wuIAC;e& zD3Mw6mIkpHN`ZMZ6(^+DCV$|ZzPvJ%a4%5C`b=|99AUh{ULucec4@5*WURC0_J2ndd+(JItG%kK(GsLd#-E4eYVZLOBPAbyJG#RXR5lgRt!VJ^7(qZrw907WmDrl z3RVUd78X**9Rm+O1rX4d&A0x7elKW$A4n%Z&c6bDK4xGClzRUX&iE2!)Q~~)nPf(Q zzVl$TAKfpQuNLy^*VWW|z;31p+*b?5C9T19Hpzudy8{;bOwJQ252`^;b$A)2VLM!SC+|kzh~7(<2=hj76mLhJ@XfUCytO=E_B+}?2+r?~d6KyO04+QHXM=r0 z_*KWS#?Od9&;pyo>VnI8h{LbEiJXHV?1OmI_|mvT{|d7?ym=gXyontHLCAroQTnuV zaNvF7hzo`#EwVhO2}krip!tR}7gD{F&zpbYg4=wW_K)_OD>?BY$fE4B{k6<|6<=;R zC>>^`F9I+d-~b*NA9-Q^C2~d`WYL4RVIYDV}5Tp4K7Ya=rVZ4PTMA2r};zBL|s zPiXJ6Toj+1Xg^h~(Yp{EvV4*{QW}r?S@q+5l2rF{^Dsjw3J9sX9CnOmxCQiwR6 zHE&uBd)0w2MZ_$Y+3teuA?QsHOnO}o(+hLi)hz@6BBmzH!J>gkR0d(m$QDtQ45t=g zl)Vp3#?6t7tZ+;Zag?8T4?ht7n|tgTD*)il&PgtvyvZf;jHT&&i@PgyvB(~e5lkIk z!kdj?Ou@)s*ulUeN*j+s3j+0lE_whDourX{%r>FV4M=2^)e8!8sD$lHJZ$cl_K~WY zjo2(+@`Yf&WIRJhHeRhiTNxXxC?o)26P?1MQvAz?I#6j~Cm~nXa+Oruqo5$dDT}1* z)Bx_yo`q77iIrY3QJOe$ijT^QEO4@?kk7;B;`8}fGGHPUqRN}+zMb847bkH4Mh?^8mIB24`x34l!ekZ9Y#90q3NRP*X7DP?& zVoX*%dIq5&#b1~;kB7Il^#^hO`I5hYbug19rKn@G6 zvLth7sAJ*8Imh6c0M5>>fJf3;@e`5d0RE z%s2IlpB*TSQSeXJTs1~txLO)&b4;5|K24;2B9X438Lvt%K1!s*lKC+nceBV{pW+1@ zvo}bCic__mEbruLO$U`fRZE_kC05EE7YXg~vwy+gvu0v9bN*7!aDiy#b*D7MDBN@d zrgI)de-uCxg^|)|CR9Q1Nnxq7IC`a`MBRqQB3zu-X%3H~7Ft5^F*y z(j-O-K``ZJX!0YNp!+3*a_HW<>?oBo@gm8ZTHOk}z)G>B7uL1XigwFeD6LQ>3&S{V z#==N952lpiwQ9iv7+CdYK)K?)kXRi^GjB#P#wu3uA!wAqvvIt%-QKN^v!0`#>+VZP zl_I#x8Xe}d<$0`SsXmzk>oE`GlNbw7BNs8fQRS4Gh*@$_Gb_AfB0k+kz5@tc2pcAb z90-uvp!MFU$6sI|d}5V9SO$zC2jQ4&x8c;8qLTeX=LsxHNvzOR0#po#k?4=;9KRR} zZOj$f$+}bKk_1&OVFAz17KRJ2O=-!2!OEDGk@n|hi?7Py-W7j@RHv4t7LzizG-d_F z0zrm+uc3w_ZcDhKf$~IwJVJ)b;bu&jC!0Ls$&*Cgng2QE0{#{Yq68f&kCPI)_nIh; zo&F45OnRn=iH-@7PxHqGxqUc?qlC=nYsD6hIiKEjM;ZtEMvF(k;GG{Jp2w#F0qFxH z$hcMYph7epON$@NZ8fo?`2ei-JMT-R$JFTPFC@(7mZHzA_B6I8a6Kp$MsZ=9$!)5!RuF4L zT7J?W!*E1a&o~mIUn3+~$Jh0eDy?*|D zdaVIZdaa~Bs$^`9y+5C(yndi7Ok)1G7t6hQDQhFpw3-N@%_#^5ZDhgL5IEgdQXwgv z&uW4VM~Mout3OH+^5t=6Lq8YYHnZ($!Kyu|%lxf%upK%8Fif3~g77T&yo zXp)CdY#OEoVHGZ)6PAcAZ|>9#rR)<+=EH1)=$>KBg28N)JO41n`^ab|5IJrs8Y7fh zu!uV=5$-;HNXiKjVizKcRzPZ0S-m3S0Q3tQtP$aIWkQI@D|Y5kBx1aTaJsCelzK`* zUT?yIcVfm|q{4*O88|W=xU{JosAX^=19yv=oG}AelZiCo!~&mbRH}zs!3e>ZkWLUp zBXTw(FTOf|5ur`BH{9qepQ`U=#WC50AL?((=xDJ$np9@&odekztgVM~*po0P8 zVO^0jfAlZ3+w20>0bg;vU;#bIpCDaS7r`B7u>e?xni?O4DQD)qa*?ALX$>+VB-R$) z(0RE+o2gM~2&+t)AvA(dO}nI6JaYxl7}UixDlZ#6c(`Ovt7NtjlkHtU?goBC49=W2`LS#?FAXJLt0+L`88RI4GJTPY!(X6o@jHX}V+b(=# zf{MkSmblBsCW7Ij&W$o8dn1zcNfQ!VE~Ygg$-%Ho%aLTn<-g9RH1zt*6|{M{WSbbL z4}V7h6@mnea_7bc-z{Run`m(8YW|+Qml%E zK~5G5f90@9eb2L&Do3o3UV_pxfzn+k4GQ5^K4qI##~Lyv0zlNYX*Gi5VXgG%wIzI$ zbeSbWTR0ezs;J?if|%1!D`WH4bnwP9M+G`CVkTMWW7uxUb~E`M;iD3VfEb$aEu*k= zPbAj2{}zMO{829NWDG1Z3#Y}X@!&-pRfsMNq=!DBoS|myVA5cf zKQ1X`NSi$`zA>7QAy#qHuU0%&pQjR%)I^G8Q;z@5(C;#zJ9AjCQ;R9N|LKFgT*p9v zJrWq(7%mZ@rO6+H`$xIpU@j{r{=Tp+u^59_lJ^))gga72>2Kk`OVwbqBmPEEF^?R} z@|`b>!Y+Q1jy6Rg9gwP+ek9G-HrfqsJ8iqBhfnEeTbgGsIy0N`ori+DFSQf*JiU8c zy$Wls+6%4fi_EyKs!ewH$6gxFmrE(#q3O$*%dPqMgyY|ns_p?FTf03kkh%PK-7IeQ zFNCSUE2GD>>NzjgICJs^mJi#dwhx2ZrsMcDtfTYxpOrs}Ijd#8J0D2-xQ|-_ft!9; zuPFzsa(cf#t3G|*rN?D{pC;nX)lhmG7c~4bSEh0KSNr7KQfC60+ussE13G!#D(b!| z^d8$LmbT@6-R9ooxc`LW{CT=q^S7|8rM|=6^I>OX+B>EFSkzs89PR^Py{KM#LR;mw zcgwI@6!m;sbE`C2+eUY@`Jx(?Vx`is03R7XOs|Bp%mP`z6b+YCE~y!h>Dw-C!Sv+FVC(s@&_OXz z7&Cz{q9x8{o3wVSCE0(?N&sJFN$L)U)FigL;4l$;bmP$acZ#mDD%#)TCHLtUi}34J z68>wJ!)wp;K) zmX^22{41?&7x5D>P-!^2EYP3Yn@(efsWJil5DuC^Qd|8hn{bQ9u9>@w8~+F|XQe%g zcQLQKjFwZ$^A1b@}O33%Um0L zq@KU>M(JP>OoYa0SgY3*`P2*;-qbb7Vu(sAEkNiE1+(Q_6ZfziytIda@Yrm)nO8ZQ z5QCY(tB5SdHvfp(sfI;s>wGMkdlyV8rVhF8iXZv}Z+mf%*n+njsg-@CxyB-#7eJiM zIIcpA;9^Q>g!N*CFAQZ|$O%C<*zAEIkrQ0keq}7{KUce^|~)>3kOA)PnK@6fEQZO0^-}(5PgB#3mp#D>-cV z4H73J(x7+2g9+h>&L@Bunfc8Vn2ScLVa)zV+mJmv{47m-g{(>JT{e;}MUoo4lqv%m zgqaOcDOa_6DXVNNu;3DOCBUe>hugkEY40uAwvfI9R$|ZWPTOn4}d{u&scNK*_6oqg| zZt;v~?56~b4W1=AtF&rbDW;$~h)~=hY7zz!FSwqhSvqF#{-3bL>jk)P5Pqo!_!EY z)}2Ua9fKhbQi|nD=0-B9jPS%!XIIkhb{?6DCsSxIO}-peG(R^&%J2EfRj}q&h2qZ= zD`rq=UxzsGIB+?5Ie6OE{>5J8l6|iP_FW792r{D)zqbS=Vzqzv>1~4y;_!ix%U{iY z0#Xzn&30pYgBwPB z?5+#xhS!+>y(NR!sDi9tzv545=jEb?gBpej-ykJqW}{=wj42D3jC4jjG-#JO-z*@a z5GYPM@1dfJs^S{L;TZs6rX>+vAgB@hR7@}l2NA%8hz$H_m?koVx>(_%>X#Jr7r`~u zaTZOSEd&^h3;}w#b#;5pcArv>c2&`%jsp;r;6`%9-h-LzYEb-?miOhm4|({$4@QbI zr`Hj~m05hp2st9U5))L&@Cv$#r+M_sFx!6VZiFsm?!V%qGE*9%c*!7E!N(|8o|KA%se1cfwp5U* zn-if5+bpc+={neJv;;YTO1gPp>Xn-hY%AL$7Bi9h)vpLeQBQI-<3pu}tTV^U(voHM zfom+@WGs`ZicPlHVra%NA#s^ZgcnfWWYGHz-j~rWrnb8t_d6D{jjsGxpZkFc^e#d|oiY18Nbilyi z6``v|C1XXABqU)@B!#Lg;P6vAT2A7uD$kV7DEJ9#@eH8xN~WIEnH^#iQ{EvB)x;qU zRc;|3=foywI52EHhrI5*s91fb>)59mfCKk?^|C5B%V?AD{k-(9fq?@>m@bWf`BPqN z!sba_CASB!yZfigY+Q5~-|JxO;v_Yft9{M!HUdl9to{zMWv}qgA6xG1ic0r9oXhs} zre1$_;R?WtdnVK z#$OYC+5Ic|3x05;>OfTMTxFA&6FFF)?&ylr}ORoh`j|A05zDI&?vpIPu{BL$NS9+B=msd%%}Q^c2cYd zev-`O@N=O(EFr^7HUu5MXTw-5&-a12=GMTa+c`&tg2aQ6+F1Gh?@XdpG**D_<0gqI zBsJ5CVXPdCPwMdlS5lIEdr8e2T9T5}8e-HejH)?B<;3JZicAXGIbBaOm`j?|aUh?U zM|&2ZuN4&UEWG=og4EM+Rpc~`j%miwK|G(g8BkUWrH0U@5SIM1EZ))j*@Vy=R>Xjr z8siu;Nutv)N>>gzmbF^ZBMebV%(Impu`)8sa~a$@f~2B`&nrrG!|qV#=i2cw+wD`A z&>-#hDNhYcYBBy%M#vyNc0$0S3pImOcdC+YqFa3kAB~XVWWbMJ4Rrx;?hf5LlS?iNRt=N+CMo$XPijg}^OVx_-%6$pYRN zR(h8xrzPSN@>)CR6ir0gV7fKRa1GBB)}r5JOjhhWomKDLqBhki8jD;5cR!x_gGdr{ zlICYoNWz$!aFGOjEI|uwEWu^yHH(O~aM=e>Eq|)?4gt6HLkUfU@kcO)TRt$1l^_7- zymU%*H5N_eP-=_~c}}RtJ?W3rP%$ho_nh58S=y$yqEOj7+OE_XUx!q?g7#cwI6X2Y zhd(pz6t^xtz>+N~TWZrhzrX0-IbOq{P>pL9c8uCIXrnFi@2_bZ;#WZji_ai5gmClP zhS2ow5JrSN)EJ6E~kd8YEm2&V)mMcA})q#IC#z38d*c!>!e% z${iBWj+AT_WdOPs^Z0r+o( zfnpQ~>TyP958?j=FKk3THAMW&=ZV0lfRzXX8gSr3B!MFtDO95kiC_8;U1M5C@R}TO z8t&_g#%@4?AP!m!!2uHK0}HUGgQ&jNogJq&m*GY^Onmi38MkzgoM1rd1>D2EJ9;*K zg7&9~XYfv)1#QAx0tc%eX@rGKyTc&pibi0PEu+LMCP=`MJnq2cXhJ1e_8*|KIRD@t zUwON!gyL@YQnRs%wPqktL)e=@HcFr@7Dd3^*4C=+vgc!+gxRU?M1ZIX;d8T{D-}<3 z{aZssCJuOf-li%5%0nk|1oT`81YB&K9>=$H06?L(KWx>Yx{Ha3kHrX9V8~Js?Qydvs-k=SEPw$P2c-h#RQw1SbA$Jg}wnBkpJ@E_wIU)T#zrA3$59U#zq zZlinKw0r5hiA!@6$8`m7``+kJ2?*?~-9tdLx`3HSf6Tk4Yqp_sxuya4FZ+YW$+NSd zOt{gCd!`%xIMZ?SF0`um@0^B=tAi0Ud5&cl(>BhT{GW%?E97aj`yE}qb1=c zDr8zE+ z{pmdU*OJ}q^-jp#N}RuBSeU1ko=@55*!GPZ!|P`1M;Y|jMx3--QrY!^D#LBC`qnhf zHRacC`#yXc58Iy;al)Uq`S7>P;qKnA>RW!pZd>YcFRELpkwJ~;7f_a&JF0MQN>m$HgS-n*6 zLL=5zE84d6Vw3gz{-x|%=F@V_X*XhoPsL+E|2^wl;eHL*m7wk#D4=w86x|1hAB0>S z5$8uxwNu-UAbt0Xy=~7<(}`c*0aD=tZ$O;55c-B4{4Eds#;%5c1?1~e^ZTx6FKqS= zp5OEz;=2_qC+D~Sc$^12_M72mu z2AUI5cx~aU>F`_jm#~OMWBe8`-QFIw}+4AlZYrMKcv@_T}uk^Z?;-5=Gg(@L>zEhQq@- z3}N$vPT$c>`lOJ^ioo!HiZ$76$a&0dcj4!F=t|)Oh;9dq)1nl5nxGgF#20!=*_DwYwFZ1BJ-tm|Btk<3d$ttmi%xAXK;tX-CYL;cX#K*-QC^Y z-QC?8+}#}pcXzn_cVqWqH{!l*cXaoO?ub71R8e&@PbP1;JuNXAa^|x+gwR1cU!M+( zb&t?c6-uku@}usmPleU!q87BUidAlb3Ex9jAB4wQ<^`9N*KpOfRXI}V27Kez8mkF) zt0!!AaMDchI`>vRZBTah8U5<@%-3nQ4MI(z23nKmtB&b-lDB2s3-?1y;Z=A2Mw>~U z!}L1Nl@osJx_vHE_{78Z)ADBhh5?4B)m`#c$7Sml_UFEXkLxAgcnsbZ7dn?L&8rN} zifrs^zN(n(A~WUJT$_lUDt?Ujs!d^F7W_!Er1d^5x-l)+L)PLB+*mMqq+x|6Gky)Q z@32zYS%+yfTfIb!n5Cw`bXJ4N-4QZhfNfMI>u_+0J1r$^bD05`tO5!R;e`m z_QZOhUohpLV`l2+Y!uukLh;5NQ~_Z_r?_XCr_iRZ(Bt}c4VG!9RWe1CW;FGK$Bhwi zkptI2>}iFDrb=M540$s9xOLQ4Tb)0(j<&z$@)}kg{B-+BG<%gsdM<9-F`F2QRC1kF zXa@bfy_#uqfJnX@QE1+}&WA8UvL*$$a02dxJPoU6%;eq^c2NrDY9iY>a%HT;s7jm8 zakl{wbNrN{Kfe>nt zcMfC021UxreTi1{Kx4IWXuzkDi_|R>e!a*DMwMnkcD?R={e~K@LmR(=>yS_3m2u&ZK zU4`6y#a&FwJE)XHB%m!>6v^rigv2vSkJn!IXEM^zoWowG;UR_!;gaSi7N@xg2UTt5O}j5$v=>FQhi)t2sA;rWUdxM|Z&3Q1TmcPMy_wFX&Y1bV5Jt z!L+coyX2h8xN3-5oPGYAxBD%X@3`sdWb@Ga>SIir4%!|!UPig*R|_)zspVu%bWKuz zLltXCInT*(|6G4?%JfMG9JWZSc_whU4m!?bW!ATpsX85UKzlv7#e;MI%`hzcE!@KC z3S$2+JcNaQM*Way_N%ldcIKDtcW1v$bb&)`rU$u1l3DuhSUVfdn{lxzx`b5lyaoOE z)8|Q0CwW+$9ozWPbrGmSiP$&149ZVwg!!X<8D|Gl*S8IBq9`|?d>NyF$^k9G7UDRL zT!lY>|WcBTO73<5JQ7=ygdF>y+%)LvvMH1r91GjmHtt1Ir;cxFfrNretU z(Ao60n;-fMjZvDJ#=p9x7M7_aQZKUtP!ccJvBD`?Mo`K7@yJB1Nn0$lc8%n(Cue9M zn~-bWPCU@16l$)1I-ttnC^)&q`$c#;zAiEolmGa+eDrBdy z;Af^bX`KTmSd7Q)Ya+c8oZ$ zLT8OC)H(Cdr1twreA*S2ETJmEA$v>}FokE`)YTu|s79M?zwM1>eHf(MQs6YduI3{N z6EjLstwA4DNPh^H*^P^e+_OeUnl4|IL1hwYyIH4A6`tVsINKga-z8035l4&b5@3P{I9VKO55o0*8rGLIr(M6NMP zmBPx3K%G}^FvQpvp7JDtmJ;d$gT$^n+W5HhksgyHen|vAav>6SPCP*UA1Nx=0U8APSKoR2~zPqct z!Y(#LR@RKM*;`JYC^)Zo zAb!{JEWDDHJ&s&t&&Z-dGAci(cH;rL`ZxC@W{=y~AeQW1^;n*b<&9uw-^I_|^l=+x z@$&q8FM;5`6Twp3mWIfS?Pu-~Ts56O1EyK{VR#Sy3xNB);emcwn6I9RJ_>)9rj<^w zA&l@>-2VLyQts-oHCXy@qHw7iH)K&E7hyu?9;L7=PLX47BIAXrO*%$=AewkFLkY!z zoIik5Hk3D+Vt;KkUm6D=RhR%0)MTgu8K(q|Hndnj%WF0pc{C+omO8BV{Khzc;ENpl za#^h)@Aoen^JA~`R*H6(fTlY|Ve&R}_B4!EgV><_#L?Yg>QB>9A}s;D%}}n`r9h`C zH6=t^n&vPXE=61;`)6zSU0M06FVxa`w3wGKbxM2q@`!Fbk>3J8r-kZPXQ*VpM5Qde z!>>HpYn9|)A0vMNZjMwu8yyzlPBpB~e3wIMsa%D_dVu zw4GTU#nX2yEZZ`>5WBn$w$OEBd{zwgm}-@K=wBXtsT%byDwwXYuwVB=ZbY@brL4Qq zHD7sBH!WH^di`gU8eu(H=WV3HqTycYXFJe~c9YT4=^+pAA^LYu&bm8p53ER&WSh{d&6OmIHe~ z+^sK7`|#S?T!Gh1(Feh_5%8MH8@$hg6`T&E2&dSGnHA1Rm#w@!J#RXu!5~|O8ZHBBW@VI z$R31GDkgNYIgh-}_h8n?i~VPl1@DXv7@i6J`9y!0zWnYYKh5G+$^TvHb~zA0FGslX z-uvUP{KaR0pwRfkr=Z8Of6v1aU%L^M-&)2N&X(rf+vj7>n;=2E*UI6v&v6#Uwj?cF z*Y|eHt&J_Za9W+C}t~yK(}`JYhh9CTDaQlWGuzHW%I#lqsFG&x`V*1 z)mlBwX;SoZu$guk65SB&$sl0aLIOP_gl<41X^P`^DbJ-HeX6q-Y2B0laql5L9>di< ztY|a7qiF{r4(G#~K-1o4*81!uTb9=HO4pu%E>OcU%7QeCniHu}W}*0XN$`wqp;&gI zbulV8?_g>0AbD#rdFvqgB7$~(o6D`{V5e&(k5jh~P0N{;rXAZFug&W`O0g!#ox1HG zmll&(`_hgDd`I$zm4s$>PEVKD=%)H=^o)-&x5Py_n#mT-DR(#bz^3t+b1FefuecGpvp^4u4cr9*2 zfoM1E+f=fJQnBh)?Afcu6{m+ z{ai!rho|0+qSkjO-Dv%3P1|Paw^P2j`@{$BZ+kzAp37cI?H8;W(&KSInS#EStqyap z9p+49>3Mk3u)=lkt&PG6O80zbon~|8Iey#UOyJV9{&B<$JDsD>!=c0!Ahs-|7w&o# zoov~QBJxe_R~m&B+}-B8w>#ljyoC07*SnsV9*YNi*5udW74ow^6Ybs0gUws9FMYEv z?Le|7*{ns4#`yaXBsPBaEP)Ua^6C1(oK(iX3IE-h^gt{R3V3I5?&WU9d8feVz=GmG zUFZ0YgBqM$(cdGw*BXqkQ*N$zWbSk?*ZEo(-xI2q`mzpl&RGyIA^BG~*%!<|D@qWW z5Lwf&7FUDU`np8UkfD;PQhei6BX2dA>OA7Qv>CW5@n=+?ea)WLfOxkizZnK zJWLo6wbZnQ4Tv56geVEqWGJ~V?S9=m4sXnX0BjJMiLU}%C<{Rs-_reQZ@o}fVF)h` zj0?7a1hn&GH{cq@)bvTN+Go+*qA_1x_4TO;fj;>~G)KSR7YhVd`!m-w{avg=v)_Q60ivOFzMFuo7njGZd`{boC*}d$+UG7fP+Ze)4{53$O1rt*}PN3dBt3 z4IlZnquhW#gwLkTfNjGET#0B1lE6D zf)DjJVCPT)5adrdBL|Zwhq-V?x0o-77i#^NH8KBt2CV(WI{OS^R+_=qxiD{W=Ecq3 zTY3$lmou(-%bPcP;A!Np>MAnr#csP=)v1T9jEjeN1^aJ0rK!t*(<$%y9P?&WW|qRR z|FrA_8^wRLG@@~_r(pj{V0GV?OsS-htM?OVRSF1jRw@O9%IXzO(c(B3iMrj%#Q@Kc zu$H;vuE>pA1Bo_jYN45KX21bX0OFxD?dw79QO ztsIU~-IDi)BPDKA4K^%7zR>LKB?dR|?icFfIJ$@kYM%sGK=Vz4AQ^cS1()~5ItRT3 zCmF10sL5CyGAbie{!9N3L~^Mty#P_d(wQvU;Mq;1zCMGlx)-(JpK=ATcJI6^q<^YaxD4G zJqYwBRBqwj;xLPFsr1Y7TT6m5k%1PpbmYn;G{P*EB((4wsi1i1#ZbJRc<$}m0Zx8S zG6tGiHl^^ari@)VJE>@VY;3uFR2#Glhfq~aX$={MU?BCjzLXWikz@5LbZpa5=;`B`G0|F~B1}^^Kj!6eAu?9W9 z-<>_JzUFUCV9(!}KLU{A7n#1emDf1Pb8k^{mo*U{;VO*$KOj2&(JxL{D7hN#3czPm zDcc{sbQ>!QN{;8E((@(R4Z?};<0t1Rv zX;I37pT`aRtcl^oB4?>~z^L@&rIgf%bzzpAOt&Zdt~D}sYsu*hZyvW}oZ)1KxhcB% z^+@qfz0g2hFFJE0M*L(R0}j|x%)v>MB%wh)4ny$qvsH71aet!?&oj0$*H_303V{&Y z%A6D?*Nj)#zix*_)3bghqGFZS%1RC!w$&>nxUVxO7r3LkQN~rNY`jIPucg5U?^o_g zjAFwA_KuRy;Oc5ZG%vQd?kAte zj^|OZKILwWw8dz%P6@1jW=SleKrc|tXOHLG-}|lw^*tLOqw@wFk#pF8o2$QIadaMg z|J1&&bESyjxFW_zAwpLkO&ui=ynv!K>R0yBnhim97%|k%GAunWbxAMQRX(uRz(pch z#0g>Cq^E&M_qRo3#E^U3X`HPP>l~~YipdV&XY)>QJ6q;(Izn%I*O2_SL?3l{obW9k z5S~CcC<_hI7??b86+fCJywvW%=AT2~>{&$D?%dh~Hg%3wt9#dJ#z8w%8#t1Jt=@Rl zYMi<{$77J#uMVWDT=73omugYzw&*&>txJdD*gZfftBD8u!0LC7#==#w2QL%Bc!s*i zXT+B*J1Ne2R;V~A{?vJF+Inc(!q>TUb+6k$;rDW`+aHjqE!*LbpogUeNf_3w4-k1> z_vmgjnNlu|*qqoHnP`IvebhbCv~Ail-cEJ(+Jpae^48z?6RgCdh1|aUFuvMwK%;;1 zsshGPc=t3Qng02D$d;4aZNq63wECD#vF=nVwb7{FZdB_rlXh&h<6LXPyr5#48;{b& zz-d9(SWDJ)rfoi_^2uLMIoXW3x2C<$9ldf%PFE(Uragv##+w?>)a$9SKUyoHCi|WV zG~5t$izBC^cP*kV%J-d0#Ng=X&|F3nkTFM| z@G}>-t>*OM2qaSdn9<^98ZS)UI85-M31)4S;n9SR)1#h`e;Xrq-LcUXbVYMqKFM_( zqjkFR3M`i83@^AoLDZ9sS6BJj8$JkAB@2Q&AL*mfvrg*S0p^cz1^Rv+J$uR#>(Ph_ z%yX=idaaCsFwI2C`N6(c#b;KzL3_0-U7@_yWaI?%h;Wd-E=dBQDlCPDTqsgt=@d64 z`m_ecBzN%NC?7*Fy0X2oE0bAVX=nDl;%K-2y=&%PI$oH3eu;GRbh&iEf@m@+&&2gHOO2P6Nn7zQV%;ZF!uF6TJGAB*zfke4=@ioN@y8(po{Zch%Y{=2f8t zb+p5BKjnVCA)@bT!r-tavps3J82qrSaVq&mBtrB*TzOnb=2XIR6fl1$i`>7bRa=iT zkRa^eg-r{Af|C^5urRZ^)`n$hL2SN<7e#ES=AwBBsB6#$9+FuU3lQmCl6I(T;HRb= z;R@{KhOjUXfRd+_uCAplL{Z8Z*4x^)`P27BEGo+fK7c;;Du>=bm2>>c@{xlM3mY-0 zm@fOkbk@YQ={TGQ3~`Srj`7@HqfJWd(EF!_(f<5eK(0-1eWOerlXd zKihPr9~8A9YeHOgr$brn+(s+ykltUUGw!2pWtsCsoezRPZPE4>x_oSl^4jM;ff1ul z8mmG%q)W}vJ!3b5b1;pkGg=}pu`-N%XDZrdjw#yULX<^~|E`6}xJQ*UU)Otl_z&w( zytur1!laLHL6;Z9R93sUwivSs_Vr}Lryre%sF`3TrtpDHSEoGRES83hOC=No@d0|7 z0?r@^6jS9e&9D!hmwF7T8Ie&SeGTzXQ!f68uuJzJSiZCiihxev_xoGFdyjF^G0BSjZk*qjk@r=I5|$ zwr*p#rkSv$J^W+->CKNZM*2h( z;0WO=CxzCTrWqC9v?{N_-Merg8{ax@IvHLlC0V3*_Qr8W+VG#}0$PJ#3li=_@V@cE z)r=#X%$yd_ZM)%{<^!l`e!ET+b^9zWXWpJ;ckjMi&!!n!oVgl<4en4$sB&yYng`>T zArgsiS3ZV;@wb`^Jojlck*)%F#SAu!qh(rV*#}rDNbVFjPQ+0Vu&j1?LyYYbvbk@b z=)5PwBQA1xFhmQwAWdCbFUHJ%1y`UqkQT44l+PRE>Twia6+L57@fs5Ly9Tw%?!0~3 z+Wn?eYEk`F(k<6V(0$Um`ySk(1m>BiOY8|%&FgTG76Sl2yf0kRrBPNK#T`QeI@{}D zCqf=Gz9^fvE0HYgfuRa$mJNb4H-P6#HhgD)7|6Bab^FQ}ZH z(HKm*$>ln2?q*{f$nqfWX7}OZxvEk%0+pOo-!)(A{p&WrwxEE`>;UcA72Vpr1j2a^rqXsAMlHOb$fvJwXjBuUd;pyciZj z4hDsL?cz+HVF)6xi|4iJEKRr;qd+^$4|)j(asy8*h;q&)#nwbd3ixY7Lpeem!SnJ- zceW6ES5o}hx{o;o9()7>4)>jBy;-N{K}8d&S44zNuKUbut6Yr_y+>#}R$*=*5E$I) z+El)HP8~Dy`;qRH&_7SGP?Ud407wa_08(aQc>-VfFPK&z$WDGC*`sOSBa_}I=A93K z#H-%I>g4!uV?49=k`C-T2~NvCVhc@y72j`KE1lR=y6GQij&tzBqr zR=QjD-vmvEL9c7pWL!&+s}5fdm3;*(!d7y_Zs`WvRY72QaGM57d5ie;>c9Gv>03OF z@+sbgm>D1>D3t1PhWQ)cD16L_IYi*)NE?El@@f5v{6+2QIb3s(?E^%1w()#8x?`moFdB`W##CzB-^5&W<${d`Oca(&vt63^y z7*@DEp4F7}e11MHcYSH7s(uS|*ff8vFKjo1Tx%jd!$u%JA6LTkW&pt8q+^3okm^ka zmB>&(vC^S$WSs;D0U=Vfc-hbnxQmq%qGaVngn4Judi?}eeb@*Y>vK&gO-Oq1s%cIq zuVL<=xQs0&IAqw*4oz*un;f&yexQ&b)s%qFsB=$pk}am$fxIRN-?I@qf;B0@WkZ}J zlDxBFc0oH{vn&M-VV@%Ts#cx*2|&qJzw@P>KX@S69e0EFzJbjQbKVPp z=%Knw;)LMS06ZxGyc2mb7yxVHkkKs{B}DJQenboapCH29$_4J44xlxlF@cPrBcQ(k z!Z#)!fq;7~Zx{yP0@>=ADAWN17zUj h+{Ji7wcM)SzOdxA-{{ay@kKmUO2kc&?Y zUmngVLiox;<$k9v1MQWCTJrK2nnnd&5>4{mlY~5?1NbCmUT4TT?$bbfk3eV0Iqz4$ z1F#uIT=zV{wFAhp8NvlMz>|?-T@iOp7vSnkICoHUX@)@XJ$6cg8!QAoD!@CB*{?-D z=fHk?3;;e|z?1E>7|4$64s93it02e@^*4PUVD?(ay(2_zs@?4BbrZ|E}k;pv7lCs--z_WafpNt zic3S2yK-8zs+z=q<=<&POtn#-^WQ7FRnGj06&RgSJ4lB(#42*_1SLSNIVlp%>PzT^lC?1zIVa@4%G zCjby`AJ;IEZ96~%u0vUUI^k8)H4Ya$7JI@LHp^ZK=jvVUZtfNK=XU1O4wkABi5aJ! zNZ=|};wm<$oAeO0pm4qzG8Kjdl)^-lT;KT$p#io83Ty-V^g@{e#s3m_EaORjz7!K? z{d5n6UjYHM!t-r)-$h+*yiDzF+&&tPBj+K_GMGR_)gA&o3`gwD7^T88id5vI*3sK) zW}KHAm>EBts6WDHKOU58?)gzr?86`9Yg-%@J>K3x>ZX5oR=aw-jDyh z^Y5dr*LUDPhw!2Cjagv!kwdF`n-9%*g6XnSw~_e5XsW^^-5&cnjF$f92r>DCV1KZ85)h9uoH$#dS)5bTU0B z52;GkS0X6oK{1d>h$A_=3#%KtOie z$6R~(0~>2Gyd*mc4_9K4A3WQ?SM7}(iw*Nc){0%WLu$P##nzd0kXdH9To~%TOX>Z2 z7?kpzGneYB*_IqwxF<$^{_fp#9j^BZvEi}L;iE-FVvj<4?fF)nB_8c!kJ<3<`c~dJ zXe0fwK*G+3_;5bbZ(4WA%K(2j44;B*O>kfJ$5-Cvo04*4bBMs~S|AKhld|%ra~z44 zRA8h>0Mk-Kb=HzLaTtS;KILfPl)Dw|!)mf5O^XFj%FTi+iWe_=hF@;?BW$FDCTa5} zOp`V@C3CF9Z+kp$X|;C7sCx9aG$QfCCPjBLAsVP6_zmHp>62m||Mnk)7)E!V3~B8o z40M$xYDuU$)kuluAPC9 z`V(=%INl%%yRzT7MjSke$WpeI#laAv*^x32EYt1oGp=oAOt}K~Y3JZFh=?n^%ia4$ zopnthJWkZpAL^x@=$RvSlw%4ubTN}OMheWK!eN&y$pT{e9aTtzbKcq)HLTP<|)EGcyt2t`C{j^ zS)!4&^nj#fw$)vJHD1>dEZMyOSmbDtuD7d@O?&5y{)-)c7-&9r4vrU4Go1o;Ce4 z{wph(QSpnIvL~v7KV2yJ0P<&BpF}wu2~Kh~m+UC6wJ9qc0L9vjiqKrN9kKLzCHLWJHHNS(xD!PIH^Mx@reH8@K?bAAbPy@*)C!6symne%b1a#tb8*7P0dF*pi=(H-X+j@f z^aJ|^A7HA(uk_yHgH*4W+f}H_Y(9jt*Ui+r5WvsYzsA7nA=bCg=Qp^s+(gOMtu5VN z3RSe_tBTf?kZOW~+S@xhLK45T-Kb|n9{pEH$+I=}L`xIyKDa#V=%V6OBMR}`pD@fW zmrP`7c7+#M{;P+};S45M(21?G%< z$`V=mW7*+R7+q~}>$ei+{zYdNNFJ{6`JmKTFZ_BVA#U({E^)!^rtm$cz;=om{=H}3q4QAQ#N{fUUW~{O% zSRkh3P7BfSPJ+|Sc7Es|OdOvyO+dS+aa}Vx5v)$fs(GW9<}fy`bLQd{i-kQ$GJ`iA z30;&1JT?p{uf|4VD2o)tE@O-iJ*lWQ*x2(M_eYQ9+rIHSnH_GebWC1}Yz2%*@dCqQ zbsZyuDIb-Mq^(>Ly0xG8R~oHD^MwZ!MN=kqlai`rJj%ktI>`A!Wa?>yNLwnuUHZZjK7JWgmk~&;u$laN!k*;RVgKulv z;e*EcYzLdJs#}AiBaOyfUD2g_uiI?-**)O{?_FNL))ykMhya7N?t_5Eu7!t(FIg;> zuGM6%_E?$3uWqg1ecg(6f@_Rm8Gh?P4=fE^d;JoN=}sRD&@yL4azYe*^HN9 z?o@GhF)*N{Z!9oe2t`9C%6yQ^txRC$c(6jsTS{XhtD{{XnJSzyxrG@miDOD_9?7gY zdhE>n1%0_$UZchS6O%C{fq(DGGvi{hLFSj4p}hsK4v$71ok}IndCXG`!UO56sHiR` z?NW^P$rTQE?Dld;TSom0#!%K4IrhT&mKxT$V8b_qzg+N++Ja6~5HLoO{6XVI+}-LXVVD=W1m%-AH%XQA^U ztPc1%I3mT2;!f!mQaj`IFBD=sD4_cXv?v_O4qEZXIG^EyF0Sm`7k9^*PMwB7myJD` z@C&HtU&1Z%YeO`>kEk_C?OGC_&=g(LASDDt`~%5;09B%fLWbL4^2)5FvF6ps`q94q zp|lI9kAur()4^AHxF2*{!>Br`GQME!-KF$8+ZTc7tzt|Ae+ML950m~mmF-YD!k$!1 z&S9m*WiBz&zhapcBLr~dC_lJMvwcm{D5!J^)}KDC zsbDNqbXjdUzbUAnLH51q{18GXTDf5%qjXR6XreTxq+Aa^!Nj6-nC|pwNa(v7J@i@W zZ}2{PYL>7bcVL?uw0ep^GnO)}pO!IkTux;X|74wFS&GU`%wlCMP|v0=(qc!EOoy!7 zP`mzaiZH@vhbCAhqVrQTrRpaUj~cC%oUt4eD~@fY+b1lac0Y@}MH)!XxqhBQ{-CMb zOq!(fNPXhI@-}WeXP&xVO&H7hrAA$ff?Ykd>(7Ner7Ubgq4@IN0tc%|{^rU7<9tt-u%xu}ytJ}}vbfFd^EU@*CU4X;ObC#Aph4g3l16*6JKzg4qWk&a*|@J}T!`!3kW|* zn`XyPv9xh2$GqEhc1)FSAH|o)$;5cXJFd*1(=I9Vb9O5N37jb$nO0fHwM5Ow@rv@V zV6}CEDv=~V6OBxN$?IF?6T@|}+_I^ydV3c&??&x%_n#a7n;I!cZ-=(P_m>lzq=Hsn zzCNh83}e1|i%-}yyGWd^h{s#K-vj5RR+sTn>&sRs;R(XJQDcT7|aOulMi9pL)tsx$@H)A zB5CpHfs!SX5jlnU86v$<)48qY9{iVx zxE7tA=DDSpvt|=MQx9XEF3n;1BkN5GJ>A=bmFb(PL}#h>>cn0BF)P!_!hHE4dX3}9 zSBX1BcHK^fg2P-aZM{c_mnqRigelc_4X8kGIq{_ z0F)V8A&zz~kW{QGRWL(bk+r-B@KwGefO#u1cC^F=Cu%iQ~1R$q+fRHw_ouH*yQSNpqv?>ib@d;KH7)dR-r z)68*GtXumP+U##oR&fLS#)Pj*;><5*gygF5ewIHZRF!)jAhR_wMgc=k_7pC$ z9R3BvWLHzjmL}Bxt$0Tk7)H(nT7e>Mtj#h$ooE8>wEF3*x-IR&MdowWTO(Yk{!<O?B{0>3ciV&G*1Zh?9t$o zw%rmTC*1Gxf@w|1V6{eN#9BQ4m;nV z_8`PW6D(U)XA!)KGVYK7?qgR*xyL~U(!Us!oEj2IezK5+m%lewVLCftC2x5KfLN$E z8x9R1s#Dw<4qExaBTQpNOj6b@OC^#I4|07vgmp`Pc%_8w1q`M)^^3B{;z|i-bu!G(wK74>W0!9{4#k$2{+^Mv8~W@ooM?i#1TQOr%g`yn%)FZpqq4 zKT-{S;oX3JzrAS}vawT-(Jk1+h5B)d>@F*S-qLB!O2`{nkTSR>K}jY zM4gaK@01yVwe1`kq!#Oh?jJ|3~ZpppmU;SDq@Fhm_NEr1e!j9Jsg9vJ__*O3h=6x z`!O`jX@epSNgzXWW2~(@9GQckZ#@;id`+S?9X4U;cgAR;`_RdgW=jadV+&S@5v`eh!=%~#aT%YsWVrfQGoi_oFz|GwaQTnVd%|Iu3) zwD|EyPqPf`FGwpAkQXdgnjah^c%_A?RRhd9e|=rDDXP{&zZD!?U-iTk9A7QfPzbR$ z&jf>W(?k*(US!1x`&$%%&=Z+%g4Qd*sS8@N2}vh7BI|q|s20xByL7NLCgFF9CS1`e=RJYW&KBM&GQd1N} z;v+(T_(Q3Hh)8>>8=Xz*=k8kS2>n;m*3SPydry+9ab*nMu5@AGUo*!&6dixH_ZQCp zMpaH_p2C+f0f3forEfV&FmO}=^!Et>5QTr={?8%v9of1$n%Y>?Tbdcr|F4jlj**Gp z!ORgzYpZW)p>G0opm(yj{Qk~Nud8e8W~gsy3e?r5H#P%W8vQ?r%7BK2rRK61|I=WL z*y(P`zhkv{X~kp;O>dT1f-1{VJL6RuT2AXk*MDeNd5#C;9;*)Y7okNO7|ckNta=bD z=xAngR+x}DqjF&DA=bUMO}a3aZvuk|6ZKfRReiO3n7x07mQLnvr@UfODTk%~qWtL) zr}uq6k21Hv+%EaqSYH5uoy}|?iLNc!-kRTw!&csmXJ5kZfFEL!pmP%>{jp3HwF$T% zhvaUrv{Eo)sqnt-i1x&?;hPYE)O+jMfQ1%T+!Iz&>&@s5%IJHBoCI(BSWg|jFLCd% z4q_?DLf?VyUGj`VUy_Yo@&E+^`^{Z)q3_4{%YGWyA7a_u0=M41>5b$WM=PfDCWV+l z32%92Rv{K6=|y_dRVsXryBu|Xp%zL++mODMs0K^kdADo7MLNd719q$|pg=ZO$(KCa zlMNpYEKG+?VzL9}1r486AN4-t{Ob>nPgc6Yy+&!C(LMu9@7Rzs%s78t3h z#BEouB-7B(y~Rck^W3*Pyo7ETX-~fYJaTf5ItiyIgRy5G*9|dakB0nqM|RI2U$+`M zPS4P>Mu9auR>4y^gm>N3U6V9S`?)xn`W-d11}O@bh`qRAI$$m#)_&}5%e}N@Yb2j& zuz;Xxw?ZSN;Ihhe5(RNU@|>*(OKz#e^}70`fLtK>5{y5ySRzs|>d1(|%HIyg01Dd8 z-h98}BWMjEnz)?GZjyt^?#@nJe{y2iF9RVNV>D!H2Zo9QB^9E(Mfs)ODlAS;u=(5j zNRS^3f7FXmm835S@cG|v$FGY^jpDYT&|ZQm^I~(gV*0|c)I%txs#*vLozKY^Zxti=y_XJURyjh{kr{V6r zznub;^Vj;+B?(pqz!I_qZH(pS1b(g_Qi4x9nU*uD7W_K?YyM-t95Rtvt%Fih%s(Fi zC9I4S>?90)fkEmRQf4I`ikLV;xl7PK6<>;6H{lq?kob-^N>-FkoA_k$BN~^)fKG`89r{+y39!RCFr)(s%X7If>8V6;ln30!ot8QbK-O$yhrOjww9gON>6=o$^)Y2`yW``Sul+^1GV$-ZnmyeU z=e(>MzPN%U)LkLj!SbriRB_Zna-h6Y=8QBuQG%9uX=ps%ebSQZ#YkJlNk}Q7lteBv zS?lL7IcmFnE>(M?q)*c}b5PsFPuxMZewj_^@`WE1v||$DBiQx%DgKA19!c`u11O9G zf2#JJ0Rp2zaWWJ5>IhN-VlGt+pOIC6y8ym2^_)JEY)5Qr{D8n_R=(?{!7E*whRUaF zMU3la49)d1Z^A|%2)e!p7C0VS$v5xDi@J^m%&kZ3ovhy5Ced9l*uN#8I|VzvV-_(1 zU@;$HgUwlz!zr4{qA5Mi^(`|S4Lei~{w^+zGxk?|dxHlf`vR(~U~A6wTJJ0~o>zbO zg2??oD*QgESKsDiK!b7~TASX9tJfblKb>Bc4 zwhnb6{{o|L*ldmmP~R&HUM6I&@3QikyEdi^Cen1Ohc4SKJKnTUJ(Y25cnmo{sFs+g zCtz|fi5Z)Nh}E*4*pK@pG6y98# zr?E)pdpa@Dbk~ovtmA(~P8Z#0C!|D*EE&czo1p=NfRD|?V|)DEyDQ|yK#M(!rJhyn zI5I=YLcEp8D#bkFHc<&9<^i!)G-`%$xR}$R>Sb{A!A?K-M7P&ED0*xIqdLQ%7#@?W^PeBJG=k zGl|-6-`JSg<^&TP6HV;A!Nj)hiEZ1qZQHhO`{b{4>RkL6-_3W`H(g!T)%)4Kp0(Fn zPhXV@Dsb-o0rd_FmG$woiOnxp`d>0%>(HYN5F2NV%gPkhk~BjMIZ@VeW@OlPJvIWH zi*zI)kEl3l>wm zcMcurhZsXZ1B(L+bt7VcwDJlu08aoHp0Us&jfN?*qNU z-N=%QC)IH7=L$7YK5#&@)L?qv&DdO=`pIoA981G`Tf2*^;o8Sc(8@xjViai6_p&_4Yo&|8fe!R<1w{JtxZ%K0ZjmFeqR#N};|S$}Gdr6CvG?2wM26X=94-mXPLp z=##M82Wo_AB5#D1EA{J4s7G{o&t#*siESI93mV`OcF!+E;P6z+-oJ`q^nrA8Nz5=J zrW2cxEIuir<4Q9^OIdP|Cr(EIqeb+>-T*=N8L1QW7DrzaLeai1;~q`X$)gZV(b*nh z9McdA z;1~ocz23h)K${bEPE^H4NsgmON3OuE^H;rBNc!p(ZKWEv0siJ$q#*WZUHQFrPoV3r zn|^C-I?JnRah3E$Zoa^=IvBK!A&|{Lp0N(r0SO_si8PL{N}i>I3C`I`RVqDHqBqah z;6%=a;@-4MQd|Yy3cuv5CFQ~3mgth@u!SdBMZ=a2X*Y5(T7aM*e^4S~^f%XHCWdQ0Sn z=AFS4h<~@uwt(iKlt4*9*&H@xzxFLzGg3kQ$RRZ&9o4P&d;;}eQdw{Kb~)hEHeP6K zU%7?V2*JH?bpQIG%c^&-Y~JE-V6bzxnAp;~7WG0m(T1y!NvUvY6ojIhg@I%I&u-I}b^IH3nlC24P$W>tK%zgUQ<`oULD(f2z6UHHw}XXolZC{SK~EEO8Zc-UD$E`+B&L*p zqexPTQ)L+KmOV?1(D9o-%L=#&owoes8t>!4E>WCP?hZQqNR+}-AeZm!~6mec8 zQf-8gfHCJJ{Q7fEcxoloCb+kDN+jsy&z}enKGL7}3h}H9Bh{`j7{#5OA+RjT)G+r{ zlIgxmZYc_|g#)<7yG|m!TziR6`u$CJQ%E!?HyI$h;onJ6g zN9ngWKKtkDPETByRj%)O9z8ti=H;&)l1Ix|pAIYy8@F1C(+zQ`kSL~)W_xK9)EY| zVRb*n%#XKws?ueB)DM-muQFA98d?%Y{Y?#m8R9Y&_6-bssq`g4f~Jt0mGvG{k%^Fp z#2TCihc8MSDuB|mBg6QGo)>_fM#`Mb1-Yrw{tx{q!63NIz6agJHOLu$Ib>-+*T*tL z?u%)iOvM!*=Bb00A2z(O|12@@dMytt*{9e>{SF0$+J=rG+!sSX+T5d|6#CXiLn8>F z;ST!9?#*tC5dh!z|O}JvAjih)`>kPB&3HlD9}mrBTx%&PPZ5pt5`gA4vhVETYBvC1Ux-gzaV5SsrXXAsv|JH zxUWB=uc+0E;F1f(8b0&1m2=qYkrY<)z*QC4&c4ZHYW$yK(b1@-` zYvhUgceVjk7(ZG`3!hwnID*J%!Cm)d&a|VjNcAQ}YHX%1xwR(m%%RsQHBcYUup@E} zAn6$=UlTNiY;*kKEplXsTY=zjLn`+%I`U`vleI9V$@$3c9C^G(y0iE@j{>sdn2rcGp#wNto>e8SXHfQ;gpQl(XpmGVmTJcVt#P#t@1XBhL}lrj{U;HBO$zvr}+49b6J*)z=0 z0B#I_VEQuQSTx74U~y7!tV`LJQ&RFMW(r*n>s5oK+7DW`XuihKB|hgMrVOOKow z$w)KeuRTF@?upyS`_VBV@cQa>?R^sXAR@YCWO`gG!v;KRVB6y94P~tR z@F-z2?>Jjn=ChK>oWaAxtI^uByRE%{rK?@2Cu?^Z^e~u-pj-{j*1H&B4qjbrfY3G8 znLN9W>Jk^;x`i+$V-_c$$fm6;TFRs5=FTQ+0HfVDQ-^nmMD z=6p5;z5mOri0gt+>2~N|n8^v)j)~$5BHVm_3(;_r5mtWi?dlWYc6Z<&{uoC zIY%;vTg!d&zAAd(g81T6<#<-exp?OqVrzMs%%HC|lv@zbs907os@|Uv(lJbNbWhh0s$$vZx4xjtYtHKAT zI(WF)P`n*o&QGZ}h7q!?bdrOTSkPxKMjdhNzaf64CK~hpo8v~eryTpWV;iRJBzvS< z$7E=z;CtfIgqLHSMiu^=AlCghoPoNrg=|rMo|US{?kSCap3%NrpBsPQupT919Vm%W%U zJ!6QcacoMqG}V{B^%io*PvV+2nUTh<}Wep6m zoO4iORj0XJsQOE4checDzlcd6^;m$5Duy!$r5BNHGy1n~4*LjdclQ8Z^NO`G!K&(_ zbI={J6=?~A*$lQs&+euVIPa=z;|$V0RfSg!R5Zvjn<&5-eW9s8b(=UNz(e{>+8w;v zt5xmz=aa7=*ubS2qh0m+1)5CdMM!*r%#Ohdgwr`)oA?OW>eCF{_b9-UE=3O0%Rc0Z z(tW4UlyH(XCcbQP1cUoC$Uk~qr%Vm7yrfZnbVnLB643S0_7a8>w0~|m4v&4Nm%{b# z=}6n7?$N0JN=qg9m;Ib!iWe?In2%);Kn_G#*ddM5($Qp}RTpxLG0gmXA#UX&lS;)I zVL#6Z{`<=w@H<5x>o7}TsY+n1>i4rswrPbWyCcV6mFdyTg~m=$6Z*?Q{>wLA?U*g) zeNXEMPj8EohH72~lgRR0s8aLGCXCcK<(JReZdkA^dk=1P0QacwGK?pfu0$vB?K8~{@hQjDRJ@JFuXx4WKT+-r3Zuk4&wBb2&$ z!m(h1n8>ON9E7QQR;hiJB|IWJ<>*J`lym2m$I;u}+a&+mDh~j_4*8Y9cLn*3ks7Fj zdN`sBxeYl?#Qf7Bg`;npv#i#3F;^qKj*9Sz?q@#)wtvoiB zP1jBId4lHBvrEx=+{X7M33s23eg13TX~kYT*co%V`s)V}*+{A?-;^sRIM;m8BAGG6 z8WWnSaMN4(3eRXFvp+@Kiy?)Bm6ek@hQrzJ@Z4Z`dE~10cqlCZ<0yqiV{M`a7A6w6Ae92pXX>FM)>nfn(luaHI81D`HY0nQqceSRQR_ zO8g1>_uIG9ip(YBY}RWlHO^d+mi#k9C$2HbHve^(h|4NWrH-(BC%)w9VY2WvYktLbV$^2BBCHbl=n8%k_D>6`ZJq%udb2Z~kpnHk@464nJH2_W{ zWaHaWRoL$V!t_Soqx9SzKfObd z^+kAbvvU_;V)oKpgHy<$Q}C>^;QbmGq^qvGN_}eYZ!xUV0b@6bS*J;(FUm?gvplqFNJ!sg`~01I=?QRt^fGqRe-^t`mj6?rg6$jOZE ze#+aSP}I~%*8NZ;iFI*1y(b%ZC>J(6;LMDxj;|o@YibHNjtSsK6DE}Q0qtfSN zQ=jvYo_|PPuS0fNohcaTW5B3}JT&J@$IACb`Zrg)o8hbd@1*m}#H{(?C&gDX1|dZVbRj%=R%rbb{RbsK zS_q?bC8?>WVTq4-hJjBYqABuw3)Dx`|1y8t^tukHB-Bh_c6g@sDd`+(b6RkVyF3}17TgUeA@+48EB|CLqwjWXu zwtg?LS4(t0B3Qj}DHkRcjTvk#bpg3QhnFflFL*BmzZ#)^-{MZn<_>gTHg2C!TSC2U z`uH^-khU`Z-VtgYMOipTcs^XJ>?KTx45ZLic^^FA-kkAkXOy@+sXTuy>XVG8B8H0* zm_JkAQ(CvJFWt+f_w@nf*7e!Dj+H91GOQ&`S}Y-2>f(v$R?SlGk&d4RchL40|dv>{!-O+O+yeBnk~wX`L*syxzO zQERK&cR2->v_8>uH98@zKW^Py-)71hRZhmYS>JmvcBPh{<9^3IsDN32Jmg8}l#a^s zA1-S(f@-cI9v^E_(1R2)(0im zTu_A*Y#s(CUl&>@NkipfY@oDe!3s$&w=R6+&i`k$GbKK3?58BZxRoM=@fj+g~Cjx{Fg3LdiWE7BHYwHX|Cd~23n3=iyE$@ans z(g-Wer0Pl~RaV4AOvsT zIR67h`-wnN!XdK5lu@|HGLpg}WXCocn;v#Y=DgCfHW|-?GjZhaA8K61c)Sqg+kSq2gm6O^!tjBq|YR^79<0fsZ- z8c2^})#eznc+&n!>4~dFoYLxi9~CJ!W==))7E(j_NOr*(g%u_>>kXDS0w~gFjGEv` zZGSS3!dsJe#E#@kpW5Z7qOOh>KN#0M1Hf%1Ky3f!?1uN!+~Z*cO6ndib5Q>KjuUL^ zovg9t8yWzgqs*8hs}wlsT|kqwK~NPYQPE+aASu7Bxo&3F-B zIMmbTRAlD-Bo}m<;#87RJ+8QBwtZqSjm&>~Or%8vFu~cyr@1jd>Zt5BfkXrX8RLaH zE<%$l4q#EFlqhnPbcPcIY2hLiveCR4j;?rx_PfB~p=1f%T1aL^H!fr6z)+4zrZ|#H zg&VX%aNpWoq#cNu9;JzYsi5e#5FIi2>bUu&lcYy8*#ezGo2P zzNsKFWE1rkM-!FDLz-ML_T)`Z(mRROr&ctrYs%~R1;3vs)+;o6HbPSwgBH$8Y@W}v zCUhqc0~%cg7!VBc2UU9mPXgy)MurV@PI?Q@>{j<-PD&?HY{S^%ti*li9uACWYKj&} z{Re6>p*y81ymu~%$|D9$&>#UsKD5L8ba2(54tZ1nokIMo1J-i{Sy@UQ4EH)3JuSR3 z6J*C7$QU|D8K84P6`uq42#gC*Mx!l#Ot7d2aU3ixj1lutB#ttNEQLTkb(~7kRO3-% zHmPX8UUM&&j65!yZ2mi^J`(ju7$LIqaAr0nrRhLBAsArXN3=f7zKVTT!X`QIPh;};`%H1KO z!hRm%PA6TVm{U7lzP(ZL=?4z;Q3GDv?$+fdL^e2@6Qbx&cJD-uZPKpdGbh`nvS6rr zWCUEkblz^J{vLrlkM1O{bu!eP(z-iLf3LFAY8SRI%7VlQ2mprxZVMFPkwy}#VLAL* zHEIepOQ55tg(=lc7CcBf`)!Plb5z`e{F5~tb+=0f8v*eFBMr*B9z|3vYVPMS^HyG` zfG%oCjXp(^NXkk233*EVu*sg8UEvdYe2TIyypY_QVeqRGTbjVKEb3Qe3c)6!eTtU2 zAA5etM{|}@D-Agk{RyP+ZT`x?F;uenGb0yT{q(*VeH3@-0~SGS1G`rx43b=1#>rY) zCz3o|iZDvn7jt%l`1zVH;vLaghsnm7v_!$(Oy-I;VfmYCsG3Br@7Tac3aYzoy4F=3 zn#RFI^{4SVxK4$yOIIgiIj;9}p0-^pO>+|sykBe%n-AX0+Gtsx%gZXq{9WtMc0F&m z-p!s(8Y0eT3I-!otwEPs+D=Gnon?QE)A!ms4F}33L^@m&cFjy-ANVeUZ4;R^5IfAs zoGq)Agy`sGJGAAYDZBgwys(98g#QMl5}%ZU>c@|$$41>y@YWFW1{orAggM)5NXroW zE(b@XW(peyNnfp$enid)JLFg4Gt-^G>zz0(iWN!NYjtZPsxva6byYU5khixx!+{aSZk_95K#Y#@^I)t=B>rU*F;RGZl0Ql^>OyUmR!4KW52@4 zfU>sn=D;EVty9XBXfZQyynoLViMd@+$cVw)i3S6c>vl&pgW#M7dj!d76;Rv;{{At_ za`&@YKy7Ct;4$vn2o6G*);h3ev#b`R;HO#*S0Fn*zFBCxOq!Mmo59GiSTeFcZJGVb z?Qc~KE+GSxwBY!x_D+uLvOY_d@G!-jNYOuc??eVm(ePx@P zB3G5@*5&&MovxRQEkNt~;|O|km9|IBw#Q%2_!>6^ZsRk(J44N5r0F~}H%4Ah$01gS zLmTTMAS$`5df=ktgz{a4lz5a?x>GV13Z~G=r=wyX zLn(u3vwg9=JhheNV3@=oF67`{JP?jTse-0;%rFSzesh6j+DQxb9;^r#&txUAID!xU(1X=^4IC4sI&BXX2dlKkK)Wi=rZO(nXJKhQFp z8UgX;fBQn^JT*j+S>Pto&lFQwn3!o`p+t&5xKdGLRV##Zay$l9$=^P&_oHA&g zGBhr6QV7+Wt1(P8lrD>#7WA^)<`+DZJXM-0X*~}X64YCr_#M8sp{96UE|1(lmqev>pK1h;ZbWn^a5WyBFgh~IHZyaZjOl9I z=I1?|UN(+9j<*~zN!}!+xvw(SFL+hYd7IbWn~^yc%tGl;uEyJ0@0>c3SJW|@<@O-= zZeIw4{CvL{wI2WHOV@mM+TI?Q5Zy%yTq>oRkM&F$eiSWs8RLT<|FAhA2NOt@Mb4#-c3v}u&7kqJ^+{vz`ArR~st4^`V3@)7?lQMH96}0Dg7`Nf z$Bbwv%_+*UbJA?NJtNmD1}<0?Rz%vV0$~>;>K3ufO7;}Hp+8^d3M!ar0{&hKTZ<-H z(FQqH1VV=8^c+lI2TAjvzY83RjvRRA1#G8GVXYo{_cQo@QSa2h$KNI6Gn|FwSpA#u zL(`TdKOQ3R>jgzKTjL-}Ei^Knm)}xZgllqrow}7BUp~OnhedbR{SMqe^GVffi%A}H z;^xTYvRSgDRYjksPEYS15kCu-uAU86G=x$gqWLXd6IA>Fo93tr+iE1f8PY(%gU!7d zDpI9tcI9ULT(P5Ieq?s`yT&nlen!&?WGfP(`}N%r3E8>AiIB>PQ1y~e2^ueT3KKL) zqGuR?r?DDmT^|0jxy_lJrn#fXWz zmnzVm*ruBtZ&BT&;o2{U9?w?g2^yPS<8a3qZb?h}b@^5`yvMWOFG4zr^2KUwQ}hb2 z7M=-JN7mmOdKtyKb&`OAvg>~&Wo*D1PhN9#c zy9L)gkK|$M#--{V5v%H2-6_1tM!q(($-WN?C`} zUN2^5lV-EIh0@2y6`vwQqShtg?15orn6N zDD`X@g9Mgf*3bwhP0d7Gh+A2G%%gW)Af8fq?!U&lkh=E2ege zF^xc#5Jz)7ZG+=PmkC>#c?Z~4W}EZnMvc2ZA;I5E&q`!3s~Z=_cMa;*Hk=KW@XI$F z8_w6>T@%xxO2_GCmim6)^W!$St*&6*o73%--R+cw$U3AqB>E>pEiT1X=jWgqLScRg zkNU67D|+uNnuq?&A@5E5{he)Q4Bywa%7Y%v%ZSQ{OV_6Y_g@K+fqd7z*Ph851kdaI zHvA8t%WqTK8eThhS&Rx(J^U-LNV2A<%dKX8 zX_-Zd0MOyC>>i2c9!dLz{1}DaJC#6E;XJv)*MxII^XK)lP=y3)5$RtdepCzMj?N1f zvWK;sl`BTOxlf^>j%ZIu9`f=H!?YS~QvwM-IDda=MNLr7p~zkuJ}xNceLM)I3qe+{ zjW?|iCD&q7lMH*hsqtsY*LI52VbR5U3W16z8K)qyQn*RIC4wA6j!;^;EwU(MkLI`< zakLy)C(9S{&hf@zAwnSF54{zQZl=b%^5pZMJjK?5{T|$!iYs*9?&9rbt$$eO{TMP^ z)$%40=I%AGIK@4nSps_Vz$U&mog(V*DXYU38t8l*QKCn$eAB+%@5AyZP}qdw}NvDwNmz-g$mV%tQ>Oih~?nUNnB2qPVkuAfl1tt=)G?k zNEp3ujin{EC@XiW+X01k`V$?N?wBo27s0Xa>UNy&V^4p!n{bJdL%d+AwCAdPW0-_q zQZsq1x`noZJTu<}#8$Qp8*|u@Z0m7WvwxiKC8fZt0rOqlAK0WmczSkw$~Mi#!`6|7 ze1VH9=s6-)uo&DO%UB210+oAG8^)_8WPN8BYxPA z2f5i`gQ3ksoxeFs>Shj&d<~9#^^ANCgoMYLiqc7Cc}i#fJE|02(5eUw9UdyEN}8eK+@Kw}UBA#6cH+sDQ<$L>|cKAoUqf`?EyblQ${O|RI z#(1l)JTVI6oW$$^1u}3-L!e?qzUM$AXU;;F$=O-At#F!($wCzWgu0E?!O4+m^N{Tr zwk5dFHYE~=vYdJtOA?pc_mOWwq-se+5gw%A8ss%}rX911RhBU(54r6S&l{X`{bRlu zCyI&pXh85?x=fC1`($Iq)RBKx%3#IWAnu(tqCqRnBIpjgvDF0Hx@ChTU=l^O7W}OP z_o9?JVI|%_&_6quB$*-KfkI%@-pH*{MyqLti6FG@5({+aYmuqE_{Sy}bqID>d20U! zd0c<-O!AUKfP)C(bEv{TO)4W$KFZQ-`q3oc3j@{P&1%BISe^ndCZ;Y>-3BAHGc+!3 z%_C`tjK3d!`d0IR2>ETa6S^tRB?r0*bx*10yqBEa#EJ&4c^||_tOX>gJ)2HqHR+>! z?~C@Iq&vvfSA1dfqa)7;6mf3xlqR5F~ugaO71=u8Y*qo6$OYM^L~cJS>f2H5hQ*eod#L6G`88Qfg>+n z$|vfPHg=p=i_6Y!fFkCkb}dWUEuAm6GAo`kIgpttmU*_x76D_r`k|1+#vs5_P4|sp zFf)U@Zj=pkbU5Q-|%5k-oi8Zc_IbW#U!Sh(7kRq@kXmP3VvI{I=-P7yw^^AO^5S|QFsyg ztbZ9@kUdd8Px{-W0mDN?&*syQj3yu8@Sl`e&*0~;;P6!q_n5y8A}rfEUtgEM$IT(p z*3q$-Aao|2YT$J+e~$^i?9|J*2CG-dzzvd}Ryxx&0^9c3qoq;k6wG%93y!z;jNdKJ zi6D~1Cp&wq`X*feZxWgoHSsOQ_X+Ro&;LZwD*hJ)t&O#{g{7|5x2MPMf77((?dCS? z%dSLj{~%wbo#HGywWGzvEn+Mpi;rybXO8Jy$;?O;GE*8UrK@eldrBya4yY0D3#A!vDGE;KmJ;4P-j%93*xOV?6sgsb6i+do)V*XKU!Mk zg!-LFh%;0Y4Lq(wntYk;>2dCSTKX!;A^x@~IYWJ&ttV}PZ)g2Giy|kSpEJVw*Y+C# zO6~)nkWU3Zhmw(hQ$%^vlO+|~lVuT${%<>`9b0=g=#43sA5{#Jim2LG1=dJ#M2;dI ze(#E}gm^C5qQ6=@)F5|+DiBOTv5<2m-Bi5MKyL)g3QnRTrO`mWkas2XM9j&6D=wp% zm(0=-Y#+Y(Vm$rd2k5||HS=dWXaCo ze$2m3I$-?ShG{1kBVRIya2N>y2i`fdCS4tm%=D zYV1axV}KU$NSer@=Z`T2l&$%bG|_#xpUfF?j`nfK2${A<&ffYjImL7)p>|ptuBx!m za_K?pI^Dkqb2f>x+9_IUzP6+HhCoyK9|zjm2qAMudn+d=OOt|H|4zjjE7B^GbZ|yn z>+RJ1dSOHsUF8GK(wT67_53o(Db)V=>Puo`Qn{pbusRAOl8Jh>M^J~Y%at?CB$aof zt%x>aAz-NpjEIm7EiE!qQTXcyVx*JKm^MXY+I~27tALTI02E=xrN3UH7tqus)=s-I zP;}`xd9C&qwLs)z50`uatR}y5Ea(s z(b8f}W{858<{|i;qqgp`cOIn)2CbTp3R@UY$%zsPNF>;_PZ}F?R!WI!`23vGHUV@m z0p<@=zJN|sqh((O(5gElvAO(tCM8z+m1~;5Ccs*=>;CGhX#4V=JlfeY=4}yP=?H8A#h!L53+2AdM!Wp*f5%f%;4E!^&Rw1x; zhg)!mrmcpd`zG;75m`>hV}4JMs=hX^h=y#}8O3)QAnaAPVcih$swRz@ z(3DxaIf?sb%{kNqYd;e=3b22vjFg%t??MO! zq&|wv%>m!|_=qQMBUZQ4ndkm>CLr0q(C`hr)O#kYq`_>ipyQjdeHNEN@$Hw%-^GXUCmD4VS0(oly#U9+mEn6 zQz?toVuo)D+hhA>$GbNcz>70WVdjEm;RP6)@nZ%Qj_0%L+rWiOp-O2|!frP;nlp+r>o@Ql~FT^IhmshCp!?{T)%oBHt$Gb}>7%R6UzSzd=LR5}mBsD8P=t^1t* zPb;jHN)4&J4$8n`Cg_}^#U3oYip2>XL&xHR8R1U`p@Btw2qV!N=l1S!^`*s6&^c|3 zf#uXzI4S2Em?lw}Lrl2wuz^PxpAby$M~vhSWl74*t-8AI^Y2y!UYA$}0HPJm7!`|!$r@yKyC8=@2yP<`y`^=tl!;U)hI-P3gZftRvJofM$) zghk+|1&Q;}xRs57gyZe!)+TT4!|Yp6|C$-KpsXja?f-EB4hHYWD90_RbJ4kk?e}7r zM^Jl(C50W#_9>79p>yT<&GcP*wtgQPA9>&*1C1 z@VuG!`C+9zgIOI+MiRAW=p$sDwFew7a7Bm=t%Wp{o*yt2+uy$jRoY3DSMgnA^5UErW@gpr5yJvcqrugf5OS@9 zns2whWP73Xw(=Pa=ej?G0qd})=0Cd&dkr5N7%QBL5d}`8nKl7Dxo*4u9%o=Zo2${F z7TD%-3U>VhGc$CYvM6cFv`Qk;(O+FwyR#qVmURW{F9MM*$2v+VRlj9YH2qCC7RRe2 z{8fzR5WMgw-EFFJ-B7|;SH;m!)qt7Xku4Y|6Fp-l>a{p%99nxWNjOJxHLMY#hbh|} zl3iq6DN70iSoMmwQ73iaWh<)GCKH1ax*Vo#%HmRxWonqnQyGGg2EzukqqCtS5~IN4 zR1i@Z1~vI0?1}qvQY`+k5wYAteYDgQHHAbe?a zO$P2P4_F5jfCt}OvRO^BTm51|+~iO^Kkho3a_(p69=yfZ4~XPtpWL53Oj*=Zzj|HA zH>|Vd*kaQ#!R@f6aDE-bl+;4zePzsENwUk-E4H;Pqqw9eu)gndNo4dU#XZ z`g}i(^n1aFg5%brb&%bkEYEm8eL<0|`<2j}U2t}Jov{i96p!M@e_h-5_UF?(n7gp$j(1*FoUCt*$Az|1CRQ(8%{ffa1u#5o(`&NKg zS`P58i_gqB0!=Xd7m_679+uW1BqsQSmd>h55&&I;mz)Q_H4&IEYl8mHo|4~HD+++N z6x^nWg9raNt>yU(;Ezb`5+@BAAVcgBCmvY7SjolP7H}=ihV9h(1dYI+Vjv`vrIm9- z5ob}JE_sYf!oFhA|FZc@*qUjixEn_L`vye-^xElolcq`M2t}IxHco;?3g`_;100~+ zdr@D!Tt7BnV*y%4-dIHQU;#ZX&SZT7;>Qh4LQ(^{)<7rjC9J<>a!;wpD{RrYE(?>C zkhG9~*)o(sN3H>lYis&M{`CbDP5QWzQBJ78Ap$I!&htHJJwzgrndxS10$g+)QPl|| z!GayrkHkP^B^k?`yxabMp#b9=X$4v&7jZi$J^!&$lzA4J8O&_6y>2EKEselhKX@(m z*#7!rNt%Q@FRv%7BvI&!pN<##Tyw+KWvls-COslT{WTzVdl1*aTt684p(0mU0=?C%E`b$HKaPDvJEV>O-t zT8To%bL%xxYIv0rAF&c*M?q;?i>a^n;rD={E+QgX^4puay+JqO6F!C1)VPYIB;v> z1e{FHzu=JiE3vd+&hg|aoK3vcePvyAby){7`*H>rbdff}&QYp=_Mw@q(#2g|1NJm; zhZJ6EGzUVMD0$e2CdQRc#+jMZi#ZYZf5^;lY{lrx`_1$mJ+h(ZA&&5j*^F&RBMTbA z3G!7KyNds~$bxn3YQ zyjf<;7KqG(ju@I4(}sv)(Iq8!B`UHVFRufVltsH<9)V-Y^G!2`KL}OAw#-WXJ7-lY z&Af(Gckt-R`pUi`ku7oCOV&(@*KZkCD3ralJmb4OWAF7uLQlG*UxBS`f@@)(YwT~2 zM{keTkJ9^Z6tJE__L!1h$d{Y&4+lb?XWF#>f$W0rS@47-ni}4$gakhW1ZZy zPzP+DjGFlgFT0Lf*gxv7FJpsX;gi~l*4rOfL~|}FE!X%Vm4x&n=>NR2=YhQ(cX#YP zrDTbSN)nV3-^5@Fb1$Yi5)*RT$c~62T0A4o*BS-M5`az_vu7Qekha@D@N@mTRWcIS z-ia?CHRVzeO5h9|by3>}mnV1P9@m-pQDPCBE3nkl1MUfoCzDZjh|Ee80uy$1kU=@Z zbZ~w*@K2l2)1W!{teY+v3`cSIlnMG-s0^b#qmi!M6&$>aG<`smpa9KY$=0&PlZZeJ z3!wY6>6SMz#{Plt>OC~|uG#ROUc=rj#+E!Q*m?&FE{gvGYdF7gSle{XW$scbk0TA@ z!={R|!)#)yvf|frT)~`)9;{Lq2{q*v0IGktepc^eqd%1;fSt%`@~^dh^~OfVr#b2? zGL1CLhim97O^tEa-pVN)I;eWz>@)OIzwqbPY)FVt%Fn_;wP6@J^rW0_;!og3^Qc)a z&y`M^>m~^e=>an{jJsZW|IKN8;E^+RcfvR?*n%rnyryxZZH?rfk&#(LZwfZl98*>3 zd%3Vj3h)u3*WX_gosw{;pHn6#$6bKQ9~5nrrE8U^1bL~r5qxep9XbH~urgWxbC)$p zo+J_bsWc)OovrBFK3^lMf{g>7BOrr&;kGx{)%KTepCMxSA)}C$Qt;8dOPJmQ^h~Zw zOX!_yktjU=6wrf*e-$yehH}CW_Zuj%$XfVQHnx6uFOU0ek34wv4jt)XXi(1lIP1>d z^q6W-M;~jOQT05gD~&6)q+7LnnYT8?U3bTalZr1HMX=mc@69dKc6`pY&7Q{ewU-lb zZ)4NS`G(9)=~3`oU8=!&o7aRCQr#8toKi&L30yu*#fI64N!S9s=rY-kqIq;QB9K58 z$2^Tkq=&SqcgIygSkLNP7(#=k;o52I(6tFMuY&s#4O+xG{V4i9z|jviT%hBu8aIEm z;`7Q|v{D|O&!#5KtyPtx>;$h0bxJG%cV&RmCR!6Cy_=6SRRJS*XIUlkHP}v*vcrBm z<4%Jwv`}RZ$XHPYI|moNCenHSvyBb;D;ix!Vc)g*FBCTKiTUzD_XWO8vwy*87|t#_ zo)S<*WUPiQTAe`lT)aKH`{)uR07;!k=e6p#ly>wkb%bcxf)6H1Ni6oC7G+blLV#?O z+XmOzfE}Mj#cT*jA+0>CEbdLh)r;`?CvBU#qHE1X`6&l_m@L&?S`J3g2eRf@GyvFVRq)bbU93z zN2=O-y*jW6ROXcONW@CNVDPMZaOZLKQ^8vTdw&QoY-PrnAC$t%rixs!@F7XfXme&| z2VWvVi9MsGBSg$0c!R8Z=sTp&Q#Dpt_vt{a>Zbl)8JX3roH({;Q_6|W%Bk$UM+Cch zz3iG7r(5M)r&HxqQe;H(ABbnA5Cmy$>kDj1$r1*v;IJ&Hf3|hqhL)te5XV!$>#F`SYi9i;kU!e6)Y z4?QecL+caf!{!l0X^g_d+N;d{DW;$PORTI!vK0bnzH%#zBCpfS1e<=!qB15~`IMqL zp%}%5{brPt)>dAh{xjDuqYs0qESbs<2cD zr7(1G^J~?9%KLQBoSb7W7meF&f#4LQ7h2~cMDLN6E6(@4a|uD*5zi*yxqu3BQnA;; zF`AXGJf21+fT)C)NpEe{Z>EGFYVAl^g*5AS?4(Z!R6Vqv!JvR6gzXoIIIJSX;IeYU zl|VVt$m2#J=1tNl&`ya;Q=-Z=y@iv>uH#U&kf}*c;>j*`qdU&|LC02IB#HSm1x|Ol zfqxU111Xn{i5M?|(4CleWv25EQ5?2DOrT=z7kUi~OJN5PPi=^J=+s4 zK9wSYKV3t4iEpYec>hwIl8 zuKtW*(@ckCojOwzi=8t0u`GR{tycK6w9{w=>j0wSq$n2C^YXUz4ol)M%%H679+lH! zSd%DPqIet)f0|#AODK#DI?#)+Jc`fB$@z96>Vz$3nqt;yUPLB9bhy%-h% z>D162h?62|nncQApPl--NAYE$PCGPX9i6ghY^|WoUR8{_aG%}YqyICYlm$l0L2)B% z1?B-umsijhmpQyxI$z6zi*N5G{`n(nYIopecR*3V6~U<+?(xXq%YYhWOzi}@X@YNL zNfqdD@7o@rP%x2*)py5anhf@!SG#V~W^ZGuC3gG3Vzvm0Gs#ve ziBO00htQ5iwD%UaW#RAHGsL0>9?sT~R<2-*NP00~+0S{q{N404iZ|z1DWu(>}uJ9~H7*``Tbn9xzC{(zd zp54Vsmofh8@9SQ!DHgP~4=f@QCFDJ!dll-e2d`&!v-QO*Q-_@s%)&b^=)j$Q@tqkc zd0ksaOZs;JgDqvVj@Z+Mbm4Jcu1ipLadd7wd+CPO*$f?cMoQk)cJ%UbRtt3mbe42< za<~v6S3^bLm;fQSyfO#bT{pBqFrN*dx$eeyLRbz&Wx*)~?Ey`YKYKOy8Qh!GVGzZb zmwpj{#WJkCP)7=#Jyu&NH|^o`2Y}pzKX!=}*q48sr&JP_bA6QI_JAQ6X8EK40F}D2 z+M}jFhZh6~7&L}>w{RKg(x#18CN)3+8`k0$k*ZiI|IlS|MQ;w%H3jn|u`!p`2ZsP7 zpv*;Fs{R#gt24X}VPe8lnNK&wC4R7}7OHE@h&~FW6HneWY3KNd&NrMu7Tw&jjW9F* z9#5jX_10eda6gR5-Oe;n;-LRQ+n&-SBPa~&`0~#S(IGlX!o4Teil0K%K0Ozskv_gL z5n>|sC$9d?&CJb)p2ke&uf}oV*{zicU>Rn-p@w+S=&{Z=0kk<{9FQ_<0Dj)pU~!C( zo;gBQ?H18b#xb3Q*%4PFOaV5r!b+Q`4*(D;>i(5Gq%Gh+7yJ?BV{N+69N%*dpQXn1 zI!8WDe;SRu;40`R5j>$3J#UVG)P&o7%FZDOUhlJYzkVO0sxin4w<>I*AfG*1O;(*D zSQSj8@H@b6sz}Ezlu9nRzFrOsstJ*g!~WjfJ_73~vNTM-)}d%3zhEMNslMB>a`Gwh zaktTO3t@G7x0){N&z+LuYSj-J4dasN!M2k{SA!YrN@TwiS;pUvQJVFKiDV+z7-KiX zm$>XS)-7+Ec0)RxE&s%|xjQ1e?T2E{~^Tacnw4*#pl-X3=^UNo8Z2G4lKgF zZiT{DnfNLxc_}N9CUFZSu{p36@s|${h-2O*g;fRwDHRE5I22EOMF>b)#=hpmZe_vvd->lY*&ByL(^I%bF?V06X3hiV|4o+FBQfqweAl; za1a*fy@)JJ*LNJHBX)lWHSCeYk(53?CvSGhYecsJ>`$65LeIIxT{i>VTx4Qlqh|4| zYc1?j4x!$6pWP-FhVj$#8`c|eLrV!qVtzwJm%2yWfPB6@-M?h6b!FR}mpD%f+d_#BLf4M`+x|OCtBjg=^;d?Tj-=b4<38!P7qth|_74bxrvQ&0 zQ+9tUVj&*FtgrHBDX8Wq6DIbEsc`2^AR7M%{~ z@>X6Sml2nVR>8Xxi>Hs9x4jVZusm#TpRzlF`LMhh9eCUL%}p^+xFY+-By1>SX_&KSj+E? zOcnCu183LEAzj3wX*;twq5BB?H-{JQEcZ=^RcQjh^8oV+;>~-HqmRvmkFFtU4}~7P z4Ynmk2ZYNRDWsm|oRP#PL!mQ>xvd0H^kZ7dH7;_o1TwK9OK2H)Pl8S5*cL3^_HWJ> zh7p)RzU351An}XNj6Jx}7MCm2`HM^>FZSc$i6I0iNU~GUE9JQps(HV!;K{OPnz)ys zQ;?x(J}?+ib%~%mmJjjAVB`REUe4AlS)_Hp=@n)U@XvqG|KUsYV5_v2p>Kxph|}{_ z2X8OO4|<(=@4X}1=kX6gx4JT&{kEuTb&HM-5A&%KuyiK(kP@*wEctj(r2jtro8)s| z*PahHLH#b1KvL#*8wecnnh=P}A8G`J-5gRL5&q;m4xZYS>*ey$oCQA30kP`z?kH*@V)7k8CV(~m z*joN*3?VGZ9Qf5aQyeKJYNw#3TXinV2Bg(Z6W#BC_M3DJke*NQYt+q|SGf_|*;Su? zHT$C8dkhc6ZJwSvel4SLIse&3)eWDzgP6LA7M(R&+fV_u+u%ciw$cOWj~f*b5fK#I zcXOJ4BJcKG6I06Ce7j9+BHDWY7R-lj?OW1OP(5=b~7+ARZ=h`DH=3$ ziE`i?1m=+K_bXUUQ&lxl6bZD7s<+uoh4FLgd*1J;BdObKADqp)2d{U%rNp)%BzIRh zxu6Nnn3FK;ivRr6_D; z&9T)8x0L{JxqGYxm(!vqI+4%`JT5t>Uw=oS#;eV^xc~ix;pX&;r}*5p#v{^g*L=a8 zGH~$PPI2C3^dfY`9S=1a=cBaFA+dh1R{Jv2{Ad!Uq+I_qO&?atG;Q3&pXG;Jxwio~ zGIMuK835!chJtJL)uVur1>rQLtJz@Axi+@)gce9aRuP-hQQ^tl22&dNru#Lt20 znP|`N1^Ml~i7lp5C1Dh(_7bHHUXtS&L+{#)XE0##Yqmn^Pm0I4q|=6XKW6Q`(AqK3nQGC?OAk+zxigO>}rPT z6g4C+^s2G}yhASF93VR2646Jz!fkf)zMXbg`?KBObkv_;THOJ*#aCewc@amSKW}TP zxF7SL`|^l8Uy8RscCYMna<-2D`kwV`%*1bmQO`|3%!#_vjM#@2wIXlxcFui?3f}i8 zANKjA_q@G01a!~xccT(*M-ST9`nxsflp^%d`{{ancFsDpcr@Ugb@F*x+zK{wX-CE# zD%dr<12bAfhPE~nybargvQ3HJI-=Ky=Pb69^Yn)t9a#Cb5FF^kq4S|uwn*CNw5=h; z$hY-B9#6x2Y(A8>gtQ3OI{@F3*zUFi+s$(VIZp`~==<4G#V>=(3qZ>)q4&a`pappM zExzO@;%yv0jcelCKcS8dbwt|cIpI_fcLnT`||Pt>_b4Y;|h z{AavhbRK+`WYTK%^f%alR~|HdusZ4Kxl{)bE*yR>OvQYwZQ^6TTw_6!iC3-D(bO4y zzIlnqkCs7{88+> z+`fM*wU`{VGH67kZ})@?uFS?~ zXkivr&MvkEN=iHLMmexrF+Q(XW?Lr9*Nf}G*B%rZHLCTDDO$wS)E?r7HN&wYYhGWX z#E}X22Njzu-VICK$rmBpQ=RR%hwiDe+?TRkz|~t}naNlD#%lA-;efywjx|%bX$HwO zKN2z)`NdypyLbqjD*7HM&eLdmxgs*VZ>zOQm&%OOTs1zns*B%-@^ng273qw-G;rT| zoK>p`zClMq->>bQf4L^%x`N=ocC*u_D3$}{DhlS677v(wd(l6V3V(Zk(40l01FPfh zs3PCrZ1z@%8n_SZP^fFeOTPB!)fqwu-Fu##cm0e%1dfl%+;k^eh zlA{rF4Ku2)biRmtAMN+m{x(Rp1u_YVrT0jsS1l@>-pbY;b?LgjjGh?41i_AFbDB06DI1V1 z&VG**VOtIwi;owa&kM;|xKnyTt?iZm5^cwuNPXC-bj$K;IR>PU^0DolksYM?UmZ(%hpKU*<&s<+A zJyV$b8>Ae`GZ*R*$Z%_O{3#=|w+oNTCkeWHk^aG-BTJuTws^2N%JX6uV>upQsr#^N z4FWwhp#$FnH#t1MfnX9s(h_%p$PRO1lo=j_>a>!*LLN!IZ^?-?pOIM2)Q%2Z#NsDv zMVp}3uvaRqsrgmmi^HuYp>2V=Sb4EUoRUnHhQ{F6J z_@{o$chrIVsm<);zR=~3#7S49&0C%NkjUfuZ8)DA^{P`~Rp>5KxRY-dic zvofYre7weS$|v1r*5`Y>If#xtLH{zo1y5t%KQ$9C&|!xZ9ureufHry)3Ob$<*`E;^ zm=QSupZx;e`Gh3+0EzVlf%*jf0qk3-wM;9@2TLmoz=c|T|eEx@MI0o-a$bHD&b>Zdk*50$T={}%pf>(4O=NJWUw~1fy zlIij5bYjYm>+uNxEk8)4vX(>UqPWeZr2If6-<1012n*kT{Ia<1A155gJ#gAC+~;n0 zE3W$kxfZKmDhAQ-FE=;->o?|s{{g*qhlywK68SKAjEKSr+1L9SSDb#EtBPN6k@Us?(pIfwK;0?ucZ5v)#q1}4NNI=mj`lN116L-K%#07q*Q>rvk$fc0~lZjmk zimo7og+(r_q>1J@)^wrz#n>vnZl#huX+f3iz+h*=JFd{+ROUnF^zUTsa`F-^m_L-2 zw^26X?cU6Nn!(npjL>5G=S){?r4mVW%DKYfBr!M<7L)zv)7jJKW`MTFPe_o!)Rq8F z5nt@U0B8liGB4lcd1 z-Hf2{uPsp3$Lm;iPJzW_kCxg62&pns`E4kM{`&?`s-A+;Retij!!D+FhS!MYP6e9>oq1#;{2Xz0LM?BX*aqz-?{nyUfIvhyLbeRiOcSmA1kH(}k8u_E10@C>0HP{3vCl^J$4hHA z@y*8dPfIH<5MN9AfOpMx3lm3IMV?1qBAmxQLcbPwfOQmgfOi!8fcX^pfcq4`fxQ*I zfxi`l2L&Am^@65!vpKVP(>T(2^El#sxJ$%~6T|bj0CC#MrHV(uMqq@&wmf&Q(#!TD z7Kn(b`}PB?bRhJa|Go9HMBg!h)r1p&qRYnn5ezLcfz>F;dw~skVS{Sc%6KK!`izBd zaeOyXzB|O|k?(cL!U7$!+~N;1$;JjvmR)a<{_$IaA{R1uD8hz&!nmtqAlw0Kmj5( zeihDn)pBRh?H8P+x&pSY1Q(Iizx+V2m6$NPx}wFvRIkEAgf8VPUc--(AoFfcJ3hQ3 zV-QHI5F01p6^pD{AJUUxh;%c5T|Sdl1;9Ewl-&CVE0Yx;Is&~v zXQcs`AoZMM7l}LsAWAnCd2vjnHZAmYjhUSEMuWbF!lJ`KLyxN`LER z5=7{x(fg=G%H1gO2g^D3`0dk-gc$m~j>)v)~z#>n9-C-%}96O^^~@15(zC?fDDvdx0W@K|q61NVyD>5f<=( zOELWe^^U*AbpeJr_M4&+A&`pO(?kRV)ry@dMD=@apC$(7O%A9MUE&5ylO0Eke1Gf# z7OJw%;;~*v#p4gPqA-oM5$?ve3}|^b`3Una6Sa(!(!CFd+E`{Tu)N84Z?;YVR&+#X zxu|4`*Pa2jY*3#ke{)jzcdKDKX{ML4T2~D{Ar)uexIlVicI>@e$~rmC?Yoe_b>#*1 zdqS~1&6>eL?9uw&K>}gWSw*2iNGviUCnHtwE)l1M>&uP06`qg5Kw>va!rW8LeHHeG za+G&UaY?D}`+{YRp?^RR2#QS;APle25F;E`_Ze|aPl+3?5Fz-RhsW)32P2m~4Rp47 zE)WDM6Ajemx`XtRwJD;7w?Iqw&xWJ-FTdK9{PB##Ip8!Iv zkE}zht;XDB6^Iz$kA#4!WCpN-23uQ?6@)V3h>S^PhCsmllieV=Rwg&Cp#JUzUJeX= z5k^Yr-yBjHP0jecgwPQe^RO@!;+|i{AvZVhqBG%R?9d^*T3T>WM*>5eH}uTY{R9X) z;;Ze$6n=||e=24EY5wupJ|Ni00^%`m{4AV(1L8{{&X*HWp63V?&S(+u&-xr@NS>q@q#9tD?OyIDs9KQ^-C{8DZy(|zS=uAg^+{zOn?!`yi*x&+i-?dc5IT+DNC z-Y#IT$xG=v%3JlHdX09AlFL3bXgrkZD5X5J^S1eV_&D3zYHEGL%DuT%$n)RcooZ=f zo^#-BK%A1h&t9soqBVDTeXbdBv-=!>m+G~&8sloAim1u!(pBv-n9r;^d7qy3kg|{8 z;7R%o_(jm}&8Dbg&ZwQ>0Sp6TFO{?&^#Jm3&O4#ybnE>)d0WH-re0;bCoQdB#5bTo zJk!qw*WkA<1Y{9gl!Y#8@$Y{L(X%6e*YC8Ta0g~^yzAor328nSxJU$0>leuGr?{A5 z6g0k5MOh%`<>AjjU;wVRSYD5LBAPcnb{l(l+qpcBD|3yH%$`bO-Zd5W0u7QzMKVteIR%K0UY*69w!a@d|PbvMJ)pf^Jcam%+_ zZz$5GV%iK66dAyanseKC7`f?+P53_%|<$yCc8ZDCLc+T z1Y5-C1Ki*BYR=DBqV|st42uD8$JpOXo!=vTUtzJS6u0{kED)96mHN!N$CLN0#{1^S z643vIL*Zla3XElyL!VwppsB$di(A;cOEr<4g3~vM$xo;jAksuVv~*+y2C z!Dl83Zms>y(|W)0VL($AF8e^lE1~{TH<+iK|XROGb zhTz_5SjFG;xF#wvJ&VFWn$8pYq4`goTQXN-M_pjz=+B{u|A1zv^veCcwF>INh@Xk{ zG>qg3&(pcq{tg-Yz-=}`e^*jk&3op`C`0cu;c}K&(^P&otTfz6ez8$64x|t2fD+q`Z>k~(+;>m7 zEUWhLz7G42ulizRbujC5hX*~B$?hb?mRAgRtrRTr$#v|k?-R2{qZ5Xg;B8ZqV zUrz}joE-PjuNrKioEpeUj-mbZXgVC(2*wlMCl5&6VY=dhfNN>tcJ zx4;Tid5)I0EzRGI0$in4$<#rC>ZIIHIqiPk_-hliYy(GcTD(er^7Jg)4I<~`y zx4dF|8MW$shk*-?z6(t5b#3lOu+X(8TtHw3Inf6NQ-MG-gs8V{^6{nLZonGFAEYdj z&X;2=Y#Ky~S`SIuD_13+DYf5Du(!d*9KdoMVp&{bVD<__>lTd{QP&Ze(}R3`o09UY zWQAm8W>ng@$+-&wZyXvoM68&6}YpcyLVQC6W~>ppMbtUuo{IAPN6ZFq9~_* zCBZ!vtB#mwa_@`S1xYWjx|~UO`8n;X-JxqbzvgcH7n@s$N^?hYc|+f zjhI9J`{CF_%SY?_qXoY17Mvk+E%#$N{#&}O$64mXE8)p2Vdm@S!)x)$YjNglALXmO z+>&8U_i6RV(Fg*xm#lZX4}0pLF_Fy0M(5)PF^{Tj zRmKGK%7n5Usm7Y`WC$s#TB?+hb)Ea@I)2Fw?kq+^ zIq)M?5FNVtWVNrbp^fsL zXr$w|GdZMqN1m)w;xT`7VX8H(G{fLD1CTV$u?@bUiQaC4hzXygG62_uJv9P;F&~mo zYnoemABX3}GhLdk`|cMf6dyV-wGPX9k|Vp>lcYMtzj@k*#`;j3kxRYplgK0056Q!{ z>nO1_wHGLx@&iEU7k?uR9@X;qjF%BkwwwB_)eGz&OK0-6?DX^BNz>REU`feA-~|h_)Gx?TUG{AXO(_NDh+)#K1@9=8tOBHmW1(a$Z#pSqppU!5 zm4rb3vqm5QAkO<7^!y9$e>Ca@YD^@EPJ|)uAVz>d`U1F%DlYEpJzn|taeJ%N%9q5~ zZrrj+k;02VQuPeVu9mqhJ-X!WtP;bOav9&q;RbIM09q-jz3Fa7{FdX)m$lrvF0B(St zaLg{#DWyLe>9n3Fq_hn|@B%}RWEh5j!tEJ{YnZhNBVIfs%98>uU!oUexzB}qhR9SR z5Ab?0X8$wI!i0Z@m4Oa>IVe!aEG-v3Rfi=M6+)1L)s{mLJvrkU!am*5eojrxii})g z$byW3eVQG8S32}41DBN`+f3A!f~>!x+@b`Dc-q}v(x~Vh=;%r{F0R~@iJO>vK&mrv zgT^dAz?x?|e58avm`PKO4LNYfkDiayJH(RvotIDb-UhmfvqqXR8g7astS~7~W|@+L zz{1uKm)uFiTKGG2MFK&^!s{niye^HP05r5~k|sVM*ARQ76KGk)K6Usr4t?l;-5&<< z4xC*lnN7OEAzF)=3)sXXvHP`02H9BE-E1&CkylYmHlOESqjD z^KLxf;hXtcr_3v-4Q-k{&1Tg)m*kzg!f zgTUWYC7aR5sZOwB6lnAp6j2RBLcwFeNF zI${7LHXo>Wv}Lmpj_{w3@7`f$rDWw$qtaSGD8y*-iJ>Y)QZIcJLPc?DDaxLty`rGGY6H zt7h8QkHm}jtU_DBbA2xF;=IeeOFjFP|9V>W+j=)SXrVB1kvgqfyWD1|!B+dCbAKbv ztzFZ0qQ&j#vB~9a&BY_-wEp5E6T!zS2Bk*<8XQgZl@&Q~9ctP{^;uF6nXmm#6b11j&`{-h z^~NbUMI7&o{*qiT+QLA^*+WPqlA z!3prv;o;vdZB-4nrPvd~iHcZ>^jxW>+EM@^SpoqO{CwKk$L_mmM{kW>6mTHy_V?Ue zPp#p*u@P_k643|WZ8TDfL5VR(P}`sHC+^Fqj|7jNj+W*bjsb-94pVvUomRZ$J zi~pW69(KSnxmqGEyKcL?pH-doLBL-889m(3f`48A{%*WTdN{M#c)VlYlKICvfdF!kwi0$Wm_9PVi#1Z^tr72BH9^c;v)rLk>83RJy z`Gs>VY;&WBx4%jL>)qg9#>XQjXu_}CfHkKr`iIfC_dzYgnEHs30YPxXNG5!9FDIF| zS0PiM#N(%2&D z<#>d5%P!xQjz5^(CSlw$4$xz_(B^;||BE%LHNKK(8*TvGL(vy0*55UQ~=-X^BBUmGvJr35UAV1O3HZCF7 zOa67bHCszG-E0Z7P*7)xzCH058!>1t>6xjYoSaI~)mLLK!6wv`QG4 zJl?1j4A^+G^N!&v&+XsC2zy3JlEIVQVlEw_8MX*py=p{+n^*e_f{RMwS~Q{meZ~$< zW7kUsLG5An3K_gIon_*g*f`UWL58@Mg2{uV!B@~E})~R48S35`h z?fvaMy`gLevZ>Omv%Wx3hCe_RMmIC|B?n-mg)kx>6&L0STEx@;ggS~rsgZ^1QYP0) z624!r_m==BIte6Vgyy;$W}h{io<?;h&8UQMjLNA zU-a;UHQTI_R1jq34y$O2cmc%c;okvwUXSUWMHk~(;j%)&&cmkVjHkzcz}mFNGWlUt zIqUakZ-L*Dd{5Y@8Kv&u^0MRM(o#(9zdZi?%Ij3QEV?rF75MrPedsFTQfdCgNUF+O zXKW<9HMi)tm(r|U!J)mnSn zc3V`^+ZaAPO0dii7G_J{y%EV^%BmXWP?~rs3saluJ=SF0G0g%Z58l+@Jl6DQxo40? z$unwImNQ5r*AVE>9~p^dhj6$%4H4zcA=sqod4WLrVM>aVWc1xso5e{Ua7~O##7y(w zL(iFaM^byNpYL8;|H8qPUbQ+a2<(Q9xyZ%=rrwCcsjrLYfW{=R6{%v#+$tUq-{XV7 z`yr-%bM?ihig855Lsf*khWIZQ>L}>yl`wSXQx449eeEaRKPsH}JJDBimyz@Ub!#mK z%jq>|a_g@ocs`CVJMC4R7uNcGsZJtvoM(>dOjNh?I8v$CRO^XmwIyQ&^!3*WsdkNm zO16zHS`+*ENiQQ-gSxu9I97I6z7%iRB|j07Z^)QKSEW7kMyk(lc(}{2yNuIuhG^o9 zCBn_~#IbCC_`ZV?C%uPZ3bvRp9mmqJ?l%zV0Oy1_xi%VW@zeOG;H_njW)P9t-rTP? zW@1gaSQ}@0LI6CJGV^=F4p-;r)rJ``57&BH(eR&bEUWZCLU+Epb32||qj?l(1i#`3 zjzZR;hBI+jV5vCBWp8L)tnbew8D>#3tTYC@M$9nJ2SMm%`g>oJv<1G?$p|^H^HEd4 zQX5E)ceNE%AI730Vr{j=@sUz{+@Ugt6zed$D zqlb>5iQ+shsm4c2?8D8c4N>-4g<`iVyG4m-ZWtmkaiAdlO?LQs!IAq#F(SR5I}M+N z-xq8YXic|R$mQ?PlVyf;P!)xzQ9_$VQ6`;DXz#MZ9o*a*V&nVRO9}I7?RrnTzp+{S z&AAkJjz5`f@$nRX%e&o=8>vSc9##k@{vHuB@mZ*3cb7?JQ!t4_Bp@iC9%1euO_Ei3 z`wH58N7IrQIegMLinXV;SehRlXMZ@=>M|bF7W6z{P7e`D1XFRSEs(}j*lHmz@(yy%WFg?*YMIY;!TsU?=7F>aI_5EA;!C+0}lTVR^3)@jm<$vW#5g z)A4VsM(t@g{}=AnPWzMDnh)E)ADMa0*c!nyl0G1%fmK^-ey!$V$?s&z&uXN*Jc2mjmf#@ej+ z`lsvqXOl(17D#2KCXu24yAAan#-`F=voY}R#$xo2+#7ahau+;VR(vfS_s#5HaBcXv z<^})Kxj}vIYK7S55mU+Z)~+7!iPxpDMM&HX<#+rfqMKiR0y^o z)?IR*T*vZhVxf_U=WEJ5dL_9=W2@-Zwp!>6I}>j9Z{uZjTb|(NQ73^PTDJ+$)%_iH zliaCx@y#+{uu43sVPXYn_G`B!cp$02tr#q)#z&Rre0GHfu%#s?D%cn?KWK9#p@Ave zCA(=~hI46Ovq(8{+7ULJb584XPOa^fifHQ4SE?!HY{(VSwaUTC7EyESzA1t zXGn%?yKgW!jOwdpORZ?j=x6d>CuLh|+x7Vb6C48FTdq`_u2l1`T;{bsx~spaqoNIF|X3BgC&EAriO z;~$h?Z3_>uzFAU7^S#?(W^+@GkU#Q95S03*rVZ7w-&k^fW?Ge;LxfS{B}g1*I2jnU zpg>rukYW!1;sEzZ)>-30Zk>v)(1I>7{};B{0AHo@?H0UT7bah7Q(;N?Ddb3dF+4i} zcRpxgdM>7lF2{gc~wLh<@HkN@4Ks3t*8=?uqnVCZ) z&Se@Np1K}{9VuyxpA`0bu;H<7gUL-^@Kz`W{aZ{mqc$``~-`^FO5cdCF=FW1{jy`NVk+fvSz% z#ebJ$ujyd2E?P!9URNRtQ9t%N{W&sWI@3a%6f0gn8h{t>oGRw*(|@yqeNFFspY{te zEdKcWl1}lv(s+xLuQpYmb|P7PReLX_^0B)7P)HX6%VrBH=h7yMJ}PBZSN7yLJHBsq&HolhP>2?AQ*RF>CKH?NjAbP!@jz_N)C2JeJIAD7v^Zot{;Her>06mi25M zJKB=f473N%shcI*H@Z`P5N0_^)#47z7<_N0yn00MMNnKrWn949)Cn2raKh9I!+e6Y z!?J;TnJ-*-JpTZhlu&!glu(OIh{jz^HumG;C8%poXXnt+X6cvX{NJP$Eq6>LIB z`^{~KBzz(6wo}iL!A1|`BMjEL#2YE?|Kh+AujB*B38&Pl%2ba&GNX3pVeQR#l1%L) zZ9%au3tC`&i%vn3!XKDZy<_^4aO^nj>zuI~|;RxAP4J61iGS zCprIS5z@AwZuQRPpTA;*Um=w|CX^hnrFbZY6Dd1$SK9@2yk&3N$XmG>j&EGcX^9T# ztgnAMysA#|%^&9e2gtxlMlqwjIL~%o3{?IUv)F>6%cr=d!r=&k^Vk9t(@@e*ZSDI- zxUh6IVN^k&=6Q#N;~cye?hA>a9&Al@6->%qVLMq2Ru$Cz-d(;r>lKhuhgW&a*{k)5 zDueT#4Be}hCq-I3F`IM6;Frh^Rt&5PN(Zypd3p~x%C zTNoXJN!crYOI_V+7`bhHcNhO?JR89oDD9^ z{S5K4x`Rux@2W=N`R#`Kzi+(wiFNh)eHD!Dv|n-I;azHGAv_?{$%k*f+4n1b^-AMd zU(3F4Ndo0?KS(b5WI(#x`=srQ$qY`2HH)gBRzKUyC^ATRoa-5cU1DvMMvRjAw+1;~ zpyHB>GP#`?bCl6dcXa^sWQ29jb~#>&NGol2Ip*KR3!6Qk#bOCVD@aXlqtl}UO4b@* zTZ4pZZ~a)u?RP=@b!%toL4Bmf0YRtKCWpQ~1^9*(WZ`$bIqLmuOy*D=o&M+n$p{@? z5RP<8z|}jy@q-N=&L1^#Ro}Nn@gkK;oO<*ssntN75<2aX2Qqb;t8kqUz0D$0rJ3wD z!Rad6+8~EEN0b!bHbT8FF3eVRS~V`pK6A3(STMsLkVK`&^rq^^K#EB?xWbi-n_z}q z!QpVG=>{5K#!e?~56B35lPMlikSm%Du@`^$GP zs@P@^GN-g;Cyk*rHlnlL=Zb3X&^Y3me5q)tBV6F%2!;#H-?@9!J1N_GX#7wE$w8jR z`mQ<}ZPyxar^wI|NR12|?93p`9DE+)_dtmI-iuLLJH@Kiq zgJ!Kzbqf(l&9>2iK)6uA?kJsaBiS~bX+OfYJ_r2;nFfzi1r&gLhIIqsUmx6%X%WRF z$-=0inlfvELOGEd75)FA>>PqKi`p$5+fK*s*jC53ZQHhO+jhR#wr!_ltD~F0{<_m! zbw_(woijO;vudw*J!=bCYArBqDCa~ws0usj9svq`NG5A_o_plAJ+z_ZLXE72T~c() zzhT|af}<#vOjY&E$`}Vl9NzjEQ3ZJ>>f;zjEYI9qIy35*=mz@RheqQo>e0*w8sv>d zuk#o9SOB>Ee9Yt0vrvl;37DT#5*6L~eHdw_?gnf$_i(PEYFly|JKBG@u`+qkG^|Z= z3`8WZMjx2QPxBH6kV%_!A4r_vy$w_bW@)I2`I4A6-7N@nCJ$V18zS0}6wS0+08}g& z9KLm)gMBv{b7%w|P>i}KSlJHMKg?dFh;G{utU3M(-cd3TYp>o`v_o2cD)<+{P&9<0*6WZ{qgp$56(Sh5o*RAS&1rA{gRi9r-<_}S?Q#Da8C27w(}h_(#}uW-8K{6vf$iQLjhj9CvQ=09RpGHqNk0@0e+3 zg;Q_3j2jTGjH$PT|27!(WwR1*;*hApY9zg$a1aB^4ZDVjZA84PZfk zZ=oSX)EY!vK0FkPGIUg?a#8_}hzUU9-|TFIo^!x7$7<3RPBJT3(;b%kix)w_b@W<` znJ!)r=zWUsKQ$;CJ6T1_rCKmP5Zt_m$v?fGU(ab0E;tvGcj<>p#20HCwX z@Gp&RG^BGlTvRlR!J(E3{5 zkiMEfnzJgqM>Bt*h_fyLdk@o+;J*AvwN1?ULTUU<%PX1aHY2}9rXjivj9(kA+kK_X zjI_B@N*MVYnNgi>nZg4>_PI8Y-(T%yb?ai9+m`)itb=DP><#^*qn*#DRu50h?ym&< z;}+w4(@rVrXKs6`^O7<)nCqkYx-d*ZwmeumiKak5R#_h)WofZvFVG~=78FFpzpOud zgzV$vyCRUL_%4EBy&fyDjSMGfPIjjq=aBz^_7KqsT1k!#Wk#CHvq%}F$3~c2Co~b8q;TRX zEQ^G?1sXNl6byq-$mVkYJ4I*4z!PfEK<*2&VC&A@A__r-wfX?VIW5PLtjNRInXX%N zF&-_Y(^Br7YEG#EEMod3%nNyqzbzc|Xe3bLU~BRE zIY-jdOpscv_$M5E5HAPq`vRsnGhck7M?%uQy}P}Ov)S3v!^kDo zN>Nkif1I7O6LJhOGwhO^jr0%0cUudrL#Rg?=QG05a$|3&q~Q{#>Zw?= zi5DAW9>-&0{GNXLw zX&%%+D)ai9DX91=tv+l)Kn%eqFSA6(mdLzMU^o*F`a8>)Tgq1$hd#9B+wKiJe% z56AhXd~#~ZfTOGYn_JHt{SLQVilB@g)bEb#BlvTi&#D9dt+Yz+c4NuqoUV&X-Atdu zJ#=8o&v;_XIOG?~39TGRWfhklxbw{2d)*h`ZiDf3c2KwN^Z8ZC zpIq$Zpa)5LtrWuPbn>uMYo+Nje3D6J3t8BMs(zg|OtFoO)hBz)uEn-f)wk?LuG>d1 zRu8W|ot8=tZqMn@bnWwBQFotL(_|@p8bk|@_15B zrLPGVu~e?y5HFCw8}w>EY}Z9CE=}3)_BDZXKpvY4d`m!H3J!$Mo*CVyKJycEsQ)b6 z=AP`i8FzSpjxzN57R>Bf9OaMgPJ)3nnoaT@u1Pe9Pk|Eb&Q;)50)C%Ti`ttq&8`?; zPVW;pu@K>BuHkugzEi9tQ{o`0AsE7UAtb~Re_N+A_{S1dP$&T=sb|+OQE6EKW(u+?yV9LhVcFEjzVD!R$? zwM{TRM#7MND5_!A7%(KL0A&#~Oh!J?gxS!OsEW^ko|~QcP`_vZZ{v;8LP6s~9egFa z;O4~S=5D+b0Od-F8xnpWeUw)x5bWxmiCGWc@z1hHV_32964$aEE)KnVnEz(MJT4mc zF3Q{5ANxV&XhQU`AgYU04}z+XbEq0sSb^l4kW>_mz0l=#a?xA-pgr3n6P<8?)ZJgu zoglEi14_gISiwmQI%B*r{g=8Ba&8RxemSAcA?`3t63!IdL{PW@K3qTcNr;CXBN(0M zo1XyIhaL3#nQ#w^vRBdyPxt0RD#gWQF5y>96O|v<5-Yi!k2%D(Xt7Jz^?BFT`BaD1 z%C?S$+iHiG*hcqZY$v~+2)&kFr{?@*OLM2q_I8G=+m3_V>2!Gfn(t=A=Sb~StwXetqaY+b<}2lcFI|lH2CPi&NVx$t(Vp z3SZ)TulcnmHlwSZwwL1Vo&4oHJrW}) zasDOM-?^QZ$4mDW$(_tvO7E%19b_ttph7DbD}cH#-k0fi0Boz(zw2c@P5dskU9YG% z#-z&4ZWi~}4i}qSQIXP)3ssSc_6K%?wyfT6_T%$F`A_HrTNf+K_b<21-3mzn-kXF- zspl;wI^}7_?jP}Qu)8co>hI0iV?Xquc!mOe0>U0i0;eFg@x$&tfKllvWO!Z&?PzC3 z9@`S`rp%{v>!&;W6SE=Y5Rq%)?S4_|A;kG<=)~dn(k$=H;nmXYCOpHI4Bibm{|&FH zuQ&Y@{qsO#m>r7vr)UWxbWK`zFEM)=Vgmt3ta?65u)a7FG|Ym!p-`avogJIO-w&Km z_iUwCH7&hlvW}LX`4|#p7guHh;$7?#=*K#mA{cAL=_dm&d&Lqki&#wt((p7m=)fZS zYw$l%D>;hen7NUT^x=UiyB^3@28;>Jr`vBgdPI8Z&OFf0YX%(Jh}6`{H4TrW)tT{0XRw;>EMI|pvlLZOKdTN2m`WE z5&4*QG}Dav`9+2htT+t9t6_C-w$Lr|C?pK0F(VcnA)49lkCq_j@ zWnP4u15WlJp2k&W2Ok>3F4E-*5zU$^1T0DCXI@Tipib+c95M~M;DXdUlYcylE%PgRGhbm zWA3UO99?aQwde=>u!|os{f!kX(f`{EyEBY7sxhsB%qc!bk~8X;u(soTH8RG8_U;d_ zgoG1m$6(k$KaB=-06m4X_8;RhO|L!MnUvma8(w0PellCCsOnu0amT46)f$TLpKYfP zN4)F1ZFbky&S$_N;9B37JKYYkw)IM~^{Ru_tMlsi9l>qoP^Z1i+vE7{_;hsuTTX9c z-K}*ZD2InU>_=D&$UMlkGyqG0lMVszD)Jxk-M4pnFeF)SsRi;_(B%06F7849iC+b0pvt z;281Cj#(xMT;T6yRir&|O^yIum5aweb*Af4o&s4SewV)#GUC>7*702XeTaBrH2V<< zQJP4Bb0NS8`fi}HQu?mDT5cwKlBcs=JoxM<9qRxUTA|Tiatn@i)rQ^C5^0PXjj4zNMI~>a0sSR9 z?(e%CJ6$CCOvJM`gro#EqjXBUHf^*^~E&h z;!2VAefhQ~a+8&tAQ`moCe&-&jp2&>6`|GFoyEtUMTtGtG4AJ9-JBZxpCQ1icN07c zQCvwU{(Drv-W)%-N9Tp~j;{9dF1}?mi{C32@a0VPcDt=zhmGAo*YC{7(f7sY>z7NJ zu^9mEmAMq>KP2F$s}`qCH*NNjuVS{Vt+!k!t(ASrjjw0Yd2@@I!D~aJd&F2gF56;X zTNYfm^v9UV&!v-*$jre2ZwFMBC~zhLs1q{_B(SpEE&-^~L62)S+QB zpy$Dtu@eIk_wrb2DWeuy3aHq0;56v@NK$@M9#uNjpW`K%4J2$R80`wLr4}d3WXztZ zG!i`<`D244mjF53d4U|o@BZMfL=3cDeP8RPI;SouHh8tT70DTSKLXt%hopwB#Al+u zqS(Mox$g`xS}=TrkMDO2#*}>U1IxXp>Spj?u|2bWu?m`bar@>R1BF^v#_dn0|C-bd zV`y&}bC_|=)MH_#_T8gn%E>UC3n9}VPNP_(e|$K_mY*FiTn_zxacGLldO3@H@ZY@f zS*H1nx#R;inFMx82Vp%THHQNh0vNeqkJ_vNbi(f>ViH|AIXSCv9Ec1vqfBBNB4?fz zx_ul|Vf;h~Mcm_4?2M=~)e(%^K}srF^t-f2BW8H3lbdRjX`aARKq-+3NskJ*@G}bi z1?xB$yttc0uu+^iFPQ&&`MEX&jV%@|84kT{7@2Ojv$!EFzo{WEz3|B%oJ_C^xVK+F z+Ml=J1jmOVX|RQ2r#o!Z)EJ3Il>omY4dConcWIbW(>Wa>Ou)-`KjO1AERe<m+YJ;$T8miv;g<;c~SovP{{rgT~-@}Tv9Cr25GxG7Sd zD>_#eYF;Dr4o0^vMeG-M2U*J|X=utLP1MI*E^1ocK+Cu--sd2dw{38+(_R+i}3uRXGM zxZFSY;QxtU=9rIoae4eQpp@R2sovaNcy0lhU9Y+M%4-0IYSi3HtGJm{bl3%3solKe zgvbaLnUe3E>E;_xqj7{djN#Sdim9xZoNssN+>2^)wo2^4U( zwhadTaRXUrEMA?zl#qvJ5~zybsh2=}BgXrhPeg}23M*-MXdV#&}a3YXIe(l{;zT%ab@5!xR`VCRBOQJC8*eY;OCHmY49 zfU-ZCG;&E#B9a8Jo<>JvBa$p$zkMb6+C`+n;`^_)WZW(@r|QiO+s%y~H`YmnWCV2F z-@FWH7Gi&PX42^ zEjU{X`_WbWoXPZ{2x>dfmk40U=zH^7u1}`gf3K;;HCs#ZYA#}*n~OdnQXHJirnXDw zf>l|9iG}w)!E}xC`S@4PiSUW z`P;C8rXGA8K*1garRjPIl9CU`C9r>ij}M?Fb^yF6wS=~L8pdXmyaZN37pF7`m^v#r z=tRR-3LFY+$1B)615>h1-7$;Ji>APHlibaTn39u+kYqj}6_uoOtG4OkPzsh$F~taq zX!nt!fb zkq<-}3Y?)Pm=$C|QJeGF^~;fZC#VI}-G5e89E2E;IQfq5Cz5lTjL~{Q^J!9B}wv{WHqQaN><& zQAD_l`%qh$g!@iKR|brfmhvupZ}TI{uD2;cNQb*wwYy$r_<8Mk7ILHTtK53B9$ZYh zixm0ByV-Q71?@7Kz1et8|N%{>>wo~sekyW@Je-P>+I-fis^?QBg<&te-( z+FiDKq2JlP@x?Da{--_=o*Ir*FEY;E3+^O#|3>B^3PWCD_xHFfV&6Zwn-bsjVi`uA z;d!1vaudhZ5(Q;rOhL?&Eh-A>6dZ?(J?JYeX^n>#bPumcPu7u?iak1}YYEE?_l~jg zeDEw||IYRKS~J9&)!r;2pU`+lqPapl<0p3}-rm)qfZ2#`Qc;&%B2HGR9& z;(>frE4O*EdPQsDHHqhiQ|zqgejL*Id~Zcjm)+(1Jh8r9@Nzlr0mI=EZLO@6G1`); zqt~A=vpRfMbpIJ?%e;yjOEjOiLN1`DB+ANKyE!y`hCwGS)-NH-V{S0rx_yET+$i=3rFu^Sq(BGItSnp5=Wd%=)^ zmuXkY_=;m#&=dS&qnLwvTnaAAw_ltHe;WHP?ybp)Nvaldz;ReWtU@Zh{x^vN?jX!v z29}yK_-GUn5fAM!I6(|%KamSrxF@v$jSh61fRH^|_K;b~G|}Ys4`on#E^A69S8`d# zmLo@V_nqI!CWnIV^W%uAWhgoUQ`iylrP|1_07rR7eJjh<<6td!l>4vINU%xt-Ms-Cq@txj8Axn<|L0f-m5 zuX$gN?)bXAISwsl*0mlW?3NQTC8m|Z0#4dUv8 zV~v-wKhTl7LUsi4eweonJV|}iTC{}m8c3X0i{F50%*G}h7t2Z*r=#J9*g^YB6A(Jx z0PnJ9G|{j`hqgyfepKOT zwdg0HJmc%Vs_>4?pdpKj^uXvuA?6zh9gO)CL?pR21BJwkU$Z1txHAp|r z=ZRCEqIy71`J-&7b3dRuJn@3D~$c ze5{DJH|jwFYM>pRlR9*{LcNbJx&#J7zr^Z%g2Z*ohQJu@z=y92F~yf!rZ?t*9Xe*W zLKndDT(^>+c^x$nGv;^Kt^bW7AKk2q8NmOxk~gMscb+SRuUWRANTJS#@7fJ+jUU9Z zPVEqwub|-=9%&2jVm`fybgOyJ0cx#+)$7&UjHj6;ZpiI4Js!G;zAX8I_|zGd5gX~I z_u$!_OT*oiFcbkZu{dgyf8Phe%#bLsp-;Ww}Pe} zt3o#l_DgH$-@y~TA;J^w3u0E!YO)1KhlpBZEW}Sp@v68IBU`VS98JreZ2IW#i9r2edN@o z*G<(y3mRMHx?Exww5033Tf!rhQIxGq?o=r981=>~@^A0R@?VJ4B0@!ec)!P4J>gn-5%2X;j#+EbNTP-5+3e)xX7Q6ieCz7) zTSL>bfdWdre-rdo&~M^Xir-*ktr)2qKIrPzk=NU`D&iEtwSLvD(bZxXD#}_S;~}Se zpap02C?dY~r%=56G$1$R8VTa*tEh8dki4^c;2;dp2JifeSCZH@lJmTmv-`FtTDhcD z@i*WZ$3!@6uBCW6Zn)cS)Z7Mv6aeVz{4T|!x69T?qEV4eJMNa)=X5XWSGm^aC z#V7D$*Tr1dmO5^)g_&ILnVss<_g0MF5_&|ZeQN$pPEF`~2~wPLn416|k9AW99oPy#ua|udZOU1J@;U;lg{?kt?lplX&K% zh9_$PMmH-t>L^y}*lB2Vzjg1V4wG~DNXVV!b-htN+0^m!M55tl(<42TP`i~|r)(oE z6?R~kNA{80(<|Z=68BAoAK3R%Zq=6L-g-V~Px7=VIcZOEr&I?S>Q;CgVDvc{vo!0~ zipZ|$rvYB{)i}?vW&3YZb@AsN>`#WzkPfZcac*GS&$5}Ek;>qv`v#H`v*7q@Tr3RM zu-KD72{67g4kv-IYlYJ1w7a+U!ap-u6%xa7#$XlPVD0{JQt9-X!8;R|2j1`;V>?Y46 z(>m3>hY$vt-b!eOh&sxpel`HzQfOZjE~x?sm4GhDKn7TaRH{7qR%p=^E4XrvX(aQ~ z1SXRMnz!MZci=&Eb_K$Ud4GEJ^OXt?yi)ocvW22x($Ejh?^I8rHi{Bl`-ZGRm|iP8 zM<@Vw9R@&J<$yc^8X*uJi7!TPP^bpyMxByxj|wUM+W|6!6EPqrY$WHX!s{D@g?kh} zi9<=_#DJCRPJ~6{(hyPj4I_L1g4S=@k|6P`Nd-Wyr}?!&>v<-XQMpY3oMobQ@4m9H z%c||cr?vT-`qJTcRUvJ&n#ic7)5!$j0eDg>b$^OJ(H@xEbap4KtpnzNGC*(Ym5e&|*Vf7R=#;_GYf!)t#@D@1Y(@OtTVd0QFI*P(0e=3e>8eUNo2F?TaMjD8tfg3og{M z*%B16wApt{LMk}-k3tjfLKb$@i@2x!4p!LUABL@$C-gifVo_@xTTSDs{cY+E%~q8~ z$&;s23r(pld(WPK)Ph`q@byR>4953suPAdZzTs6h>1`!(;`qXX1@LYz^Cjq_lIf*C zM`PCoDOw&vnaQrJdrutyxok-XXF-kz&U%E8836_fyvfzaxyIrUM&Tjlg%bsnoaMBCfuLv*L<(W8;w^w z>oz^slh4(yl)YE^`&bTjUF3HDz{ifrXd|sr`Gh^XVBmM3#J|Jou>=Gt%B`l<^7YBe zZN@s~=itv@PO9YVe{pc#Q1)kWvk)s*^v9apG z2G{z-nq()^&nB-DrIovjP<{N}jt6l=0TmR`u4l`rd{i|rLt+}F)nhSaZGXCbe?=1g zbJL#F4^7{)%l-?#<|W4qZu!ju1Z$fhLF~4M?3xGeI80*CW&-E=m*`%+`#FDeA7KZQ zaI90u!*AIhV=!=f$5ITv()#q>C~t`D_q0V2dG*rQgmG8cTU60qwPS8(H%di@@%Iru%g^7hf9 zAnfqLJ3Hg~N%GaO^Taiccrb)qBCcXVrCcDdkU39U?CrHo7Jxyd#9U>n7-qAT$-mT2sX{%I`Rz?xW@+;ia>E~ntNhfBk z8#8&QiUsGnYKaNG8we@$3koSSyJ8bdvD4(}7hcHchiCF^gr41P@uBslv#a{HL;9Lq zy`H}J5&gb^kH#{KR?NuB6+~PE*SjQG_AfdvqFZZhVtK!^FQu~fcJiW}GT9|BX=5W@ z_dygovC$az5`@}NcEyY}m--8)8UFA4f00Vvjfyojy6?fK*??)^~0hu9^4g?!ILZ zz_n%5d!T*u+MC@r{+2wqorg|dNJrnpmIS2%4K>~)wJhgJwFx`65ihXlh>H?Et`X@B z`|gPPv#eeiJxiUE8+WH91yVrKSKg9P;+VAEh?`80L`*rz{%b&PuGFNp&K}Ylf;eQr ze5SbgjYb%(qpC)VOH%kCPghKkcQIAS zeT?iGC$vQN9TDsninxQ}8}TowI9wmrA5pGxU}-o)ZvSN1C_3-GfkxOH{G=hGhFqjc z6*~9G$PP@BW{x?GE@uoWP!rE|(1)cw&2wJ>_xdt{3}5!8T=&a+$Y9C&m*NxQ_nkpc zOI{t`5kK!-?Hj3SWoMz`($saF+(DCA$O7n9n?CQ{7x;F_B3zsLC)LCJ(_x}|}zE#XfEBp@SYYp$<=oGro4oLM^3K<4IeXN?^^l^c+w zgpk-?X<9_;mrUZWdAd;jZ-eX(^@{Ba^weJwgCBa;CIvP;VZ@{SEK0@VG4cpTpUV8p z31p6L)(>vx^1LL()x9e8?4A!#g|j@8S+8}FZBCk6!k2vGh7bcN6 z19gEz?8J8?Hy?`CL=7;Lo>9(n#JnQ9p#HbBb8e{1j7g?nP0s^x4a5lHI zrMI>)r2p@hnU0Z(-pRt*gx21`$jZRX#EIU;(fa2(GrgXnfs=`zk)5rriIKB~oh_Zc z$B~+i-6jXh*R>v_IKQ@HG2f#n$0OXUeNB>XP^rTlhZ>py;o`y=v2+rZ+0jtc*DH7h zrc~o)8!*hJ;R6}Q+ti@P;S@uQDYO8RS+)ioNc`lIIz$1$pnt*q{3()Ew@h)?i=^u1WQc|a!~s#o+3i_E16d0oW~1aVDB@;Z(opp%GK4OM4|}TqIK_RbGZs}hf?(pV zy2)Y1+4)jc%d+sayRx(qFui!iBIwbIxWBSdx_!ppZ1{bc+L`De6p4QcNjX3dX2%$G$~eIJKndWa+|y;V=nAFlvd ztp!Jwf&Zn9gP(L0I`dI(=NLU;C3_W}kKm>yhdekP8YWO8;BMzHxg9}$(O>2)dG~^o zq0+^JCWX0bm0t+%yiom0bHZu$T77RSIk7BhYf{m~SL42>R~5Ccr=Vk`V`-Qp5;Tr~ z+{Fry8IGOonF==u)lZ1lG+3&0H=PKEP3$#LLTAc|Y6vHeI;wVA_Y$*~!@KP9y>WD3 z7i0 zdVK#(CD;JIS~{%QvxUy-tNMN|5eO>Vy1 zV~}_zqEZpMCl>#Fb!NWC5F9bBIaUj?1HH96*9wL(-OA~>-ooy&VY?-F+|J~3Mj`uY zXDJhzx(bgV5l|Mv#xqk(K07}@zY4}Fa8aa_)uQlEMS`J8P%QrrI66caX$lDdJ1UtO zy~MTJg1#HYL2xa(jGORK#x2_UA*0XbLUlr6$dVJtZOSDhY{ROL`r62u(~{V~C|O)N z_?~>$TEjggb!;%}luU|5G>Oh7m#j>86`~u|;7G@c>xGm3t-i*2KMtJf^1koE)lsg1 z5h{*mR#{VSJmICZ=!J^OAC;{k)9xlPk}ne*;_WyK^=>c4scFh&>8Dq3o^hJD5i>|{mn|jnYg^ur5}<85nZH(r$S;%a&I7f&v1@*n%rUrB z7-hQ@-jP_oKH3cBOFh@1ymsafUi)HK8aM_xIWg)M{&0c(Uj6obc+T?+9Vd9!dzSrR zru*W{#S_W*>JaM`)Z+d}`H=)(yh(zmVnk4{Bk*kGrks=maY;$kY2uoel*801B}Ft( z#pv=j!?oa{s3x-xeOXD*|KRz_`@fn&*>wm%3JwH>hVg%C2KWD0GmPx4t^X?*PCt6F z#jRt9!vqPDCQ|y`1^RYBN5T#g^ykN5s`mZ) zFnRQLkv6;AGC~pef z@EKVvl=B?Ur6VtJ4*RE%!X1g5C`FwLY`-64W0H2pT|z(S?IMxD85rf`QlYanm`iJwn2+EA2z)SPO_^mi3UD z29QX}gvcru<+O^NC&j#YH17M5W=MagCmfBSS{BUo)A$W8$w7KAecr!;?%>1(bZG}T zD{|92M;^k=qHWw;mY0j@sp}*iVV1`dTTZqG`~}lRmrQYmJcC%&YGiK$=@k%LYwz(vrAG!hcHix> z5y!>mHypMlD0A@hRdN8d$>Y$ZD|BhcwI^zn2P%2pmF_u0mWz%{3WQ-7SZ|*vt~W_l ziEZ^iod&#qu8=TkN0xQB%L>Fz9L1GgYkKLneI48{AZF*}HXRDf=HU4wEUL2ZSqDk$ z_62I$%+xKrqbo!7=I)}TCDGq3)m;fhyg9fZ|NU(}Eo&;?PdBuxM4<|Gge05N1wYY8 zx^GLe2yY#71c?xd+hsr+HLU9Gdhe!9!*POCUKrGJ68k8*6~UWVCAj}l5yQ*_74f)3v@-R)P2xt%Ne&}#f1*K_+}(Zm9tDhX^z0yP01_Il3>DlHb-3L&}VBh&U;;w8IR9h zQx*A=K*gzi5+lpHobcs6tQLc~Gd*>BKFpX5r+&bokU3m!49CP`+__U!x#YB^rX_^> zx{b@eyT(u_v|n7|mN|LsN=tMCiC9xXW4~7hJ~fo?pCjE;yt^#9{vx_l0fZz|*~cu| zLu%F?e%}@MKVrG4dYY+w%++q|;IC-L1Opfk?JjCKASgUhbO0CgYBLnzrw{%bCXL0qVAe`ZY! zQZYy#Msa^mM&Mi-U7LFcdAp@I9--&^!7C*GooeZDCKH;+Mu{sKG+EP4jFFwh2gZ}e zSu94V-6O0BZy)nGRqFOj`sIyi_ixgU!It4UM7oI5aSh1P)< zaD5ad;N+?1qFgJs`FC0!`t-Ce*pUO9W$SQwq6j={h<4t1X8i7#j>dAc^9hmBwwgc| znVJ)snvJR9-AsR2u@@5g24t#q)v*BCDXnvuZF35Gb81VWNa(qHv-$h@55hIRsNiHf zu^&)_-{?2iB8aD9Dq8X!cgQRn%NJxphL3N9>NiEWlZDvTlfVLdhO~q8ZJHG}gvjj5 zeTcDcVD25?OKOJTD|CikwzeQpK)DI8vVdYlCtY!Ct!`jZpGJk&a&mPS<_t0`(-XEO zel_nHDrp;8av^Dz!a0h%7JBq~n~XOlAaU9Wk{!}|INr_ZgVFX)9+D42|2ustAxy~b zxqhXYTM>aXqnp!gwQ-g*PTR`pE>m`F0?rPfY^huU0TFxvj3TKr(~_NJ$9>B;*C?6u5jDU*@kjZ=kA4T_XPfy2q! zO|8`#$_&W>XjtJtbk%7V1;OC7Eky9;k+1^AQt$`oB=viey*V&(n)Ow}7i(;))$uA@ zE~fznWpa6fuDt*17V9q-Uksy)?0HD8M{{I^^sXg7zFQU4UpKb)5w4PxFJn=)sd*r9 z&^k!Q5)P-^J#ok>lF%iuh*&pEq9Y1+^Qk$5OY+xDSis$S1+)Zb>Z}9oDJGa`z`jk0 z(91xS`)mbkq)0D&8kExAIB@*1b>U_W+}W}RZn1qdv6(-(D$=HeQ)9v~AHT-!HxBlJ z&ank(fBHG>)^eM$?Rr`EE+nT%i=yVyM9q}knKGqu;_~JXQy6*W(gsrH>;_h9E%VZT zbu+nMOuz(v&Px_UVeq3b7(z_SH@9*_+uvP!l-~rcP?_n|wrf)cYFZ4^R!XnY8q$@Mvsa~qgigu-;;o`d^xI}*KSxD-Z3=Z>Xzi*hYN51=|%S~K>+In2UPY$9A@4f4w00|biV4)b%v!G%~ zl-~G0`BVQ~{>!Zs7W-V~gtU3uJn7LMsBir^jJkL$=NhK{u)yxQQ7JuNV zav5q>KpaR8W&WhyeDKGbAPqYE#f7gBq?67x}!D)~k2P+DX7wBn81!RCY$Z$l`e%3Y|)3b*34C)GeIS*M~odi)d<+?)O{Wo(Yyg2wn2u z@JtVp1PE=NN}8ClCwlE#8jP6SF+*V6y6#u)R#a`IQrG}aTgY1_FNdG8Hd?8t@yeW; zJulbgzK!jc?I6T05lj0kmxtp-%?Pp18MfrBANIvkX{6a4PioLLs{@n`+6b z7kj%8SJaOHZ$PJ~i;8hXn7WZ61m<(U@)Y^KGn}_N`t`<&@x_B0Mvdopj|WHO4m&Z8 zSLf}v+kBlf?o-h8wyE6nq#6~LXz?A%LSQ^{_DFPr=5Mv-2zIJZS*vDrbK+NC=1DrG zH$DxGCR(+Yi`r-VGC(rL=lVWVJC}XeHtYW9QGYEp!Jcfnr|#~~7j$?|0ydQTHE%~R zmt9d*d@M=}uW|aXndG!KCJci^pW36wacd!WTt;jaG2J8X_GJ#EU=Dn${SrQ29DLp* zt3cJ0Sm(gY!_0)6;0}-a=^ZalqGIe98+sWCSj~Z=~4*B|boPI%^aA9Es^htH*2k^#I zjvot&^uCqC`sIb4Vo+KQdWJrA0Zk=uBy~It*Qs|;21&J}4$WXHd^{}frSVX1f4H}3 z`{TFcyvEozm=jjgHt)e^4MrozuFzbUEfj0pL^?;TdEO+~U(#C8@wL2@hcQNAR##6r zExaE&hh^e%5GF7YIPnEQPf4gLU#_|bN!0RW_b6(fO;E--LmM1vjaCD)V6UXPTnDw| z$W&Z1d2ZACrfp2iSY-eso_HK_GrLI7{YOby~IQnH3Xpuj@ZXBU?#Ccxb z5HOM)JBn~TR4UPIy;Ne_iO#$c%_c@TIHRSBL1Em$tgU3)lf89fi6~V}Ys3b>z33>3 zatx|HQy{j9bk@DjV3JY9wHVT4{gT4SIDHk?agzI!KQ3aj!2{&C<1LuWTWfV+Tre6{ zXll&8e!Z6?HzBS?>E}i6iuvTU@eAZ;*0NP`0Rs-h zrqX+7PFh$LV4{p*?b*?I2LE(7qmQxZym383UCXL#aaYQ1f1+O2Q(-`4*U0)`9^ach(2pV6`E0R4=^-BT1GrL zNOb5s4F+nX?6<8yN(!IRR~*AUnXHLwT(TDN(-#dVpt!PU_M-tnTtXe8Zu($|XqDN= zB8Rn1-KGSu;trB@&Dv^BTiyP@I5|A2Uvv?^#+STmdjy3h{LW|0%Q*aJTnB!$7)MM8>A z&4OiFb26}{lOz(rum^^~!g#46b-vs3I<~QVgt0VMQ_&G2GS>n32hpdT8dzS$*7J7K z5VEy^pK~?#M`V1)T%%Kudd)e4O^m9e_8pE=HTz>oSWb4zq~i*KXUp>Og<~YE$=8j& zaYD;ne^y33DKvovcY`1xEQ-3#{l#|0?F8@~ns6^8LtYQRX@ovmw^{{#H3dN~d{&+jNDMKkUo>*DI`RjWsc19kx&+VZ^nT{2HO1nv4r@pCEkP+{Nm>KJWIx!&uo; zU{USd_@4;P%(mrrnLjiUr@y?P>>6~3NhJP^DHw_RY@$ro{*~Y)?H zM&NCyNIw(XRbqX0qM04$wA~$N<<$NDkY)e%AdxthJXm>Kuj&cFxdn2YUttI*h}C`a z0vYVnUsdUO;qf;kDFTXblmG3}mL&P+ox4dzuzX@QCPAsyjU;IkEXSc(^ZxV6^4^~# z{WH^Ve8yoQB@FGph>$%S(~#D(=HR`#yLcnDiI_zW{kli?%Kg@d~j~OLZpCb zs5vzX$>8D?`0n2k;vV&8a^f)={5mi;$nm z*dISt(jrkv{3;`HP$Fs!tp~DO5x?YsKGZT+v`KaK+r z5?Z?}OXu;QAeo7Nq<66wUf{;ToCz!BpF$@m1=pisa-WrXG1}@y$&jsc*V!sPcanO; zA^&a(YYXCjOo`$E|mTWd2q|ZxfR!^LSvx%b>_g z-3E{th|zp}GZ09&{=?8jocEv0wLk0|gZn<5InR4_@a(Icqu_Tj|3>{!a<7HM7Q^Z1 zZcXIBOYZ%T3qk-B2WJyUCp{aJpDL2^ecO2tn znX~YuDf$K-*&~Q*e@t;qMH1J@&_}vHo}V5a(FdgYl<^7d`mTuen60X6#p7JeJC?7TmxpJWnUUA!{$(iru}q7(h!cmGkjB_&u-R*jjK?6b zCe~{6?-diVn6Ah#i)tN;>bi_JYHjl!Q5qPgR;L_P(r|RcS~S=(IaN zAK2fT`E|?YEz~Ugp>v}(F0ZGXQ$vSm6UVUz2I^qTgL-6YcRpZ1i&;D<$~$G)8SFQNvBKUMi57~^|)j&Z|7-vZ`BB| zRf;6Q6f7K_0x8+LEMx4YiEalW8fWSdUK3$F5?>lO5`+ac;zdb1 zl%3&Ib9rtBgRuKzp`JM4;yLI$RF)l-3yj^LVPGV8O`z%N(iXqjz55^uh@6N`otV)0 z*gLaI#`jsjv->@Wdk6bj?xlo-qHIShkMs2YiG5kz;F0J_x!j%z)57680cG1Wn{$8I zfk^qUMg>8^Ir=M{-o6ml)AKC$`6)I_9G;fwt#*K%Zq?pT;dx7Ch9=HdB`xR7=5i%3J^Q&bKX_;r)+v0GeoY@puAjZ2qiWJM& zv#k(uoan8yO-Fars~z{77v`NfbTLB8R;{8;C|;t8T%vAR{S!!_kMi!Q-+OZB!gnKe z*eL;3ZJ5@wAt{7VYXSl&-KALUk-={2ud20eisr+WeD$=}P(g(@%axkuqV&abELUYR zO08cJz1Bd+TfJ)0WEwxGnA{)l`y&Uva{xW!SNOe256~3w7wq)%uw}}crl08sk(c6A zd4TC8eUobYEv3%BEAY_mDg^C`D#%K5Hvqzm(6wZp4ghb-KwO606Y$ZB&12P%19&Gy zQ;jvgm!10FRPuX~zsbeB==&g_&yl4@i54GnWAR@3VtFv z>J-AbW04J<8ipc;L9{JbIXjP`P00E@%T(BSy&z+XU^X=$`mW!tQ&~Tgcm>fyxnI;> zLavqt80wj0^yxdDWL#Q4lQbc(0I;d0LEn#jlB?5RI!%>KYchnF@U>Ll6WT9-IjXmK zOD=Y_$XaM_txG7I(|A8sa-iCHBDW{6%)WOJuDW@0a$Wiv)KMGIy3{RBe(sF^5LAF;eloMbYdrOCr zfOP)2TMLWIatYO#>IL*}tbb<5xJk|D0~H@pv&R=1t4`-EAk~1_-}3U|mJ84=eW&ib zWll@zrY+{R*>Tj=kQhV2tQY}BCns3Yd=)JkSiFs^d4~)Upe#4Ot{geM3Empr0_Vtc zvVIWZS!DaJlA1|R*6vjHf60U>XONenAn52a$&6Hyd;wJVDG#`mefUn9FH`=-2A4YO(I2I=H;8UksCk0dH z)QV;-kJ}mu_fy)YL(}nF#4pBo-Rm{yS1`_;7w#U7I+~Bu z({gv(|4S8tl^(GOqsp2bt`@B|w5*JQ)_0bX-Iw4^JGEx_v}m(!(8nQ|l$~n5E?xko z)lcKlY0_cE>?TGrJFI3@dc*M-0(7aY(H8HAxjlRFMgkT6VyjO3!==}0*1tph#N|u& zuV`xK>%C~U^RE;{H~-Q&3oK3)-9GU2lrch>VU`_uA~i9Q-ztLMGmy$9(*}msTf|1s)lMi8NHDh z*^&GWk_8E!57*l>dOZS{Dj&PEjiSM(ALRi|TZhf!w14&HqGe**s2lV8x-gJ=pE2=9 zxPeEJ42|E?L02s(1-??UN@M1fdsaU>jci@;ZYrL|ffjaK%9ej2%II0Y5U3s@ zg%$`GS6&-{vjw(36bH{+tls^eF}YPJ|7^R%0yGnPSqJ_m_fL~(b|@4&+P`u0zbaBd zbDP5RI!FCl5u!@LxAOtJJ5d*b<3JA}DMphBM`;6)tJX2H0s;q9oqW+V04QBRfB93p$s{n{_eb9e>{k@rPP zu+`22UBs7)3woSGZ>jK*1lMRn%oyTW>iZ(QkmMuPJOD+7Ow!uj-tBbt*PpO?JO9d5 zgfB=``EBS%*P_=<+)p6K72DJ8zRr)3r{y%`KvL$2QG~tK@uz#fk&6EUCNsh2rnV*yu_4Db%-PnXjXKcx-jtnitKI~bNrnkubMEZ z0I!4sqJJb0PjMNzSGeh1T2zJn5B03;XemF4t(ew&6%IBjy)2`4Rfu_BmLLne|D{&a=bZ_e zR94blBAYDW`7nrz-L5g?dp=Ip*A;k2uh_BNA_1@-9eLCIZIY>)O-UkJ>cLZahGHw9 zZ;HWEV<4d(+pPR;fl{JX1jpX7H)C(eId^3#i}aP1ab7VX7X)0Bjq8Tc?JBC3KV$`o zzPC6`-nrKKa314tTx;GIH(}%4vw5A#(LM!`SGwTpo zz9gFr5ouscFxT{Hwc;3{)Q+!aV4wERX2a4xTmx9YjYE3C(>=84nRD}!POd|&6T*#w zU9i1wvih)YCDr8x`z}|y*arE}Oj*;%HlYjVr^@|ffGjTs3Wf#*^|J#35l8%-{?Eqo zbM-$$r(8?`j{h5(0_&}V>1RZO*x{4AReDBP&1$RwN5}IG(7owB8b8c9e&*SIU5qIg z@OQbeCBBYB48hP|IJKt|;VP0HPEX+ItM^h$EC7F+{ zS>bwk>sB3!sppq@#3%{1#X#UdRjS-wIiI@dKqx@JR>w^2wl}N3PcVdXfzZx4V0MJZ z*v9U~Y%GWF{@y%_Q;U=$&C3rI%?A3@(3Ba3)TH}X9{|RN<^?1#eang?Qie!brWUHp z3|%sFPgAJ-h7=L)S!s;eH542uq6nuso}W3)6rogm$Tdxmlla2bN>=;%g-H{^KI^ zzQK;6`imVONf=6aJn5VWuj!h#R25g(L{n{w`4H;%=;MQ3fTyQx#%|{Nei_s3na?IF zU)YFr`RVHFZYvf3BC5VKPQ`?&e4x&2zH%hku*)aT$-iTeW;oM5j2{J2SVG|aZ`FT31n0-Ecw!1B?gmpdg;GHW{^qqtxuK(D!m+53goSG6W8aVXHEs^Pxvw6Yi%tC2 z-3E(4_VUb9Cmy>kAwX!^w8cQFKUJ9eDaCRs)o?1v-OQ7gy4?BSH537kCcYdGV-T-G zrE#Py6wnvD^0`n$hGV&gZlf2f!jxW(-uH|25H9)l^>m^74f(9|&5Jf-wp$HHN{XLR zA~WJ%_%D3+M{xHmOU79L5Hbl)y^+tD-xtg~uu@eVDPIA1H0`D>(i7zn=DV=XHe!F| zV^9&YuU*z^*_>VilhqUZIEi{f8oIk$$9lK~yuE#R`a&}odUUfp5;~wQZrOlg#*DJx z%1qmd_u6P(+v45p%7+RFE|5WEZZWiJ)7Plz<>3xD_q>5XeSTk8w3qA}nmA(Dd)Z55XVuR^H0j+76cv%vF~CQhk-QBt2=5 zr#6$u?%n}+u4E&2==#lFYKpv7YRSk+qBf5t8N?f(3B6ixGz3K_MV~TQ*-9af(qIU- za{^C?HJ4y70z*Bz5$l({N<@svO!{YRr$&;W*B7LfK z^c@~V-0^-N5clM9hc+fnv#GH-Kb#OTe91w@3gHpxN=s{f^5g_YU1!w)g zgNcqC-8K|e&QQ~c*}SG{Y+VZTd5TB>rqdY(jFuZm$Sa`qHA}~5W@-G%W2s=3ok$SL zX(WlYZb>c=QYp4FO`8v*7PrJ|iJyHBV6e*dttn$g0rG7m`qgU1h?d*fz>qYA*Z}6|IAT8O|D~A>vEAh z{_1o2%23UC43uC$JuMuRy;%3w!Pju#wd_-`vM$H*Q?&#ks}O4GEbpaoa|3ex+U@J_ zdvbT(=}|A(Ui)%+8CA;oh8rY_VhbmM<|hBqyuYYow-k=MphZ(-)7>^(THqLJevLTm zOvgw|-MJ7rg0ex`1dk9v7JulvYuiB^+zpCmt7s z5U^EXRB4-g*hJ2E z>kJ$*CL#L?=Ff{au^vX-zP#hIg#4;EH6>RdqiIf&i;}M+71!7fN}Bhx%nPws$WOCF zi*_cTgZqBV(bF@bt7ZVxVD3Y!qByv^Vpc}UNK(YZwYws&t!3GU*TjME71L4aNX)U+ z)L>JVys4dS`ir=7WfIjVIX>dCzvDCvg3~ILgtj;hiCas**~>EooK-td zCt{~2&Gg_0`hrz)c`C?K4zu1dY(G=?WP*pYE}t~mO_)Ntm)py+Q~SaD4HxI9Ocq`&rop%Zy?j89^MExkTOaE%w4~cjEU}6=8oU_J@^4bTmQ539?5hBQF$w zz=}xb@=kUPecfgEVP>FIhX-ws7M~e*y-nRn3uPT1tSb%*AGJihND^J(w$#x@Xl8wo zwbsMC$6JtlX|-|$BW%6VG;p2JUaFz+uYqWsWxrt~)i~QZtkim0OG7pidowU>$`gtW z`{iW;rRtWLo3-hC&k*B^J4=F>`S24md~(dVmJ|Q7>v3q^ zV)){9I+O-nPjTx4Dzum+*g8ZKCpqED$S#W!4@rsh7`(=xSM$K%R4^x~hv;`anDmSi z-ILvKMhh_vzwwf!R}4#7q9kKN3^?cDZBLf@i6JIHE_XUVl820Fs99O2ncw*~sXCgL zLomAwa9_6Dh1W{Es^!h`r>(I(TbGM=VATk#(C9};*=}yH9S9A)5bFVmLbM^6AU1Tz zH#|3`!bpF#X-f_Q>Apn0|He62!MDCg6(9+O#KeX>^*r3#BVK#DQuX%ev@IRps{d{K zM)f6SFYVjzCA^&HzB6|g+>3J;0+&J7FJK!+j^ObTVkM7?Q%}qlLN0A*D-iC$R45f) z8ke9K;hb?}eJ)3MnRM~;{e1I~>^{2InXy$WPLd9s)2@e4qfi7>S}caX9K`Qn!*YGr zi&mf{*Rt;$cO@>-)0fsZ=$wv^j2DENvu=SK0?PQf%%t^m?AgP)(3`C{oq!b=S44}N zZFAO>1o@HP(%8?Q5-z7xX=MS=0u+O)_d>D_vt4@WGt~!KKjpj8o0y=(q<|$95O6FT9#GtPT6es&7Gg^$*D4SzM#fEi1S zffhil6wcY^nB+u1do*{gctL|a(GGUUWGtG8o9Qv+xw}|-f-Qk6&;2CU1pi%QCZqOK zPrWHD?L!tG97#`!t_)5@8N!bm=g6OHCdp2(saEN0`BkV~Dr&e)_`&~raV7eN(ez9P zk9DL80UNqDVOL80cxS5!T7+ zBKo!`F{9f5`Fu>xc1BkmAY=2lqix2vE+Wcnu#d$pq@d$o3WR5;Qa)cXBAy7Ky>6=sqE zte6q2GGT9U$0-6`rLp(&0I_*l?wS9N&EY7$qYbbS_=2 z2V_Kx-=-kS%ofl_OCK2zC_Hj}DbCqm|+GGR#>K&h46+Kzef=-{|~GPK%pb#lh+u#T~_o!%hSbs|{LQnM}(Pd%oi{vukp!4u7n z$@P-9d520`$06!JQkf?dnqt5q z3R)G$!L+L^$!Y4pRal$uBEpL_9+j`=C?pP|XO=-Mk)+#Z=jv?hBQ6OVW5u?C&B9JrzGqC_~(rdul+FI{Gv91Aeu zSX0-vuF1I9hXG$Tm5gAVLMGFMolWojr9f>&uy17ORLYWQ1uC;xMoZ{=wT5cSQI#5X z`2pw77zo#p;;Ij0`K(xFQl{(7ihgw`3rwJ(_oWI~n$=7NGV5mn=7G3SjUM?@A^T^t z)&`iy6X>KD;n2NZkK{r_>nlv^1^T#Hs+R%Hr}LyVMY{U2VyRaLBf>Ml6Ljy>f6Fhb z6e}zts98PI8Rux-V`xS?StAMe%Rlkh&KVFm>_p0+#*3FBt=Z;6W5ZX*2v-qwX_G$E zp{FKCEqX>&Z~eJFz$7n196T-{W?h?41~K8+hgbAAwlvm6UVMFJoRD;_A3FzoPub$$ zW<5o3UV4Sg*%Zm;3rwu3p*W<8nI^#J>8i@-UcjWZsU2Yt%Bb%1`_(1V82AE4pu_+0tb9m3u*L3!QKt{>G#DQ+LAzK< z)R3+=2y0jGlWEtaX~mcz!?I!VjG>&SdutgvS~H$cnO8LO&awn3z|#|!=6yu zih~FPQg&{(0=b@l7D*@E_#q*ArezhMYxIXpMV1Qn@=ox0vrvW`F*RrfzZnac;1)QV zq>0F(YAuZoTNa!3M{TfIZ}#f?4ildu0eiIsppEe&SdkN?;GmGdAF!YfInVW3LQ?7t zFr$5lya_mP=Dg4E0lD6N^XEvoQmf`zLojW+py%#0_nZbX4$Qk(h6!fHqIgWhQL{AG z17|56Pixq_dd$z>i$0{UZ#`e>&%iO{^GI}a3cTMAWTZ6*ODHwRAT`eRsAcT@;GR;h zwSJ}heRsW+z{W(&M26o6Rq5P$QWTT-A6e78@Qr*!&8P_s=@xetK$bD`68l7jOD{UM ziTv^&*c{eX5@lA{&sc1-E<9;e_@#54;r$(6UC^?ydbX+ z4jcf9M7%NKq+1tYF!MYh}m{e1NyEdh$-YhbT0 zfasyjimEDFBxl(g`fw&DDf~OTd0mp*(?%*fwQ3k;ZvX__fI09nC59@@8M%k6%{i_F zV=b|9o8GFMiBG?;`aqCX0T(~vOfI(Gx`Ou7iCw#84hcWTUg zLvPYFpH2hH=a@yc?Xp4h+^b)@3|enD78BE`1I%;z#faoYjKqx6g;+Suoo2*Scw74Z zWkKur1o`1sdsmbqwiNQ!XBo8om-m#w6pm-GrD0mYnM7K$5S$21qn=}^OlP}19r}J> zaU$77UCGAT%ebl@64$MYWSRgOPlV~ShYRtT-UIzrJ3v|9yY1qzMKw*t%Vl^Y zbN>TV4a4hsCVRR!-<;;wX9Fc9_gTLOF1k0*gPSyf(zY2V-wnQSb|LWmV}33PY-ZJU zaR46UF(>#NRDP72F?*ELBPTb@ry?K zc2O^6pOsU}SueKv!@iPT^H2}9H5!K?V(;zX*;IR`axlBp?%%c}vHpCt<#WQlW8RfF z@2r_oTeSJ&@3Nh!R~`G&j~(p$>(UkXR7Ots=#a*#(c9w@CXZTR?0B(b8YPt1xB{^mA>8S=X<=Xz&XY3s88!9ypRLzKa8}Qc9=Xj(|je%hpZ#JO_Wj8LM-A=F3v=%6|t|x9^K>w;MxX&ndZk9!nWKh$xEvPtu&bi;mUx--+d=&M}n_k8z?=%j>vK_ zF!OxLVL^Snp6;dotxX!*XXSTCyqn<`f8ur7C=-Z&oy?om&6!+`t-p~ja-;_+oxZ%_ z*Fmc@N8N@}=3LHY_5^L1Kqlf%o|$En-iZM4{vEyLtpMWrYZbg^ipZW*T`9HyZs=_} z11j=kJ`Hj;90yE7mt(?W6$d&u$0*PyQ_SMgE{fVWwc5C6pXjAZVo#{LX$d+`VdgBI z=93sN&u5K2k0KUxxGYbJ4~t8O|IoQBoAt4K4Lp}(ScamG>rn90fK48PWr2(r<0Yl`5sB$N~D-9?f+tL3U(y2BiLV{;u4Q+?r(bEZQ#6mx6P;#~OkAHm@WUKAu<4Si$;vkPF5K@}3A)dGs zw8rQ@FHOEl102H^>z0y*kdLO6y+EJA4#jXo6+u)FEf4YBxNG-qdqVj|j%N3{0Y%Y! zvxbBezDtg)B!hz_Os~TK9p~B7(6EVmpkSZAZ6OQaraIA{5~Z_yv+lsOWJx)qpq-30 z?oE%)Md8_5zmjaE67_s{d4gq|xAmlQ=IW$1xA_aYSghMh5pYL{wrQ>IPCb5&4@9#g zE=#RF$3}DglO9j_z+0X@Ueq^kZHwcDmNE)74RJEiCXb7!p_c5*kFE5N5ujbMpmiQ& zxDCyKI&Gu$X2i;E^(}KdjemA&)8_t7s*ueP!*zn^g_#*%)jJid?WorS&oU` zi=zSVP&Sry`;uyqdQi|NKDe8S^1bEqd9IxcxOda)7(A+`S`E9iO4nN`Ll2w;d}Ex> z#vzA*?)G23*8`1bl%8K;=-pgh6E)L40zFNH_LDQ!J?~d<)IHpv(-43WeC7!xF#{m3 zk2L5uwG&&lgp`A~X%@Emwq`Sd;K$BeFl&f3SQk}Bz!kq8TXW>@PQGY$Q@mCEs{4gY zv!Sz_M0!umR#iA?(CUuv(oU`T6~s*#;5Mp!p@fdDy}`qud-FR62dC>I-fqrQz|Jl; z(ZIFzYQu7-{6S`-W~^f0Z&dcSt1|I=ECgw$2M1lM@da7zm*i3u1O z9XgNtfuj0^D@`=i-~`G;xFza@>A}C#S0PO1t3X4RqhLX!rf#Gltz}AwBe!ws%~OuV zcb6FOKp|_7*%>7yg_L`%xz^sCo|?<#WQ1ULN(wDYh-Ds|o4wMleSl z8ID4W^pIQi5^|KGthnLVIyEGHqEDrdau>(iOzDSbZ)d!gvrr|v*jr_51-H4*m5;+Z z-=6Ky3tce)p0LwZ1DPJ8^Y56^WPzQL)P5g#ktOO^ThsFnNw^ro^~ANEPXeB)RC4{y zEK}Sm&@}xfj;9{@Gk38DlPUk#@erk0WQGxF<(e>C7Y?5K{Bqu3#$$~=5Ri|)uBHx^)oEJ;StQ(20#Sdxn2oOEcMWFak~YqGA`Rcgs8k_vMRU$*FUo%WJX~Ss&ecbQ zFn?vIkarKUHa+2f=95LN2EJ;dJd^v#L!V><{5b-^^%&Xd&?f3#UGqX(;qrvmxV>Wo?Ym)Z1%qmkzGN8!|!>GY7iK8)k_KLBSTQ={V zguT(MS@&6Wak9>I90R&vXLc|`0gGr%TEI@Z;j1^Ud$cQ~Fj?~#3|d2^z@<=Kp$=@c z1LI%jx>QRbq78Fq6H?>-Ewb;E8k1%QI*myl3%wrGEzC6mdyV<4s94{4qUHkmgsQ0y zxPA=MH1v~ufH|i>iWVc>4bciltN$bjh}~Q*RyXoxa0wRk5DlCrRr69Pfs>~DCOLAi z#;8T^_9mv*g&JH;tN_Gb)_Y#^3jUCv#!C?+HU|Re0C0JNW3{3iGVmvDRjO z<-8cjBeo$rAH9wkGzdMm>(;nlGWk*Ld<|zkxwx7r7K*Dv=;aGkd`O%yZ>Zq3(hN4b z=mq?i!5t#e+`c^R`KnMr1#e5zhE6F?lMxWK&*LTm_HGQ0l zHW_4Hs_}@Q6cf*nhhVoEEkN|)$97>F)S*DnDY`*cTlvcs&%8xGdO`ra{7&!EuI2m# z5>9&@;BlIPW|)BBV;w$w^obz6=T=Z2AI#bCt-%9it-4zudy7TEzdi#6OkjF5!&#xi z_M!*;AC3wgl4fR?3N>~<*4lK?5zK*Yr@;g5tpO>#Pt(~R^?ZG zH=4=FyRy!a_J}IV;#;247-iF;bNmk6Z$mabMj&xkj?DLUJ7*3*U`7#*Ew#gJRG+v} z?9MqmCyo?Nn-%M3YwLm`>)`{_ibj*p>f}S!@-;mCHZ$RK%~!%?%_`%rI{{yFQPK~@ z29B?aO}hd`o@y(Nn*Q~yofb{nSbHRK^p^fNVD&cS^13KomuLpt6X4{g_bSHjljx&h z^_#sX(;jpQWqoEXds5Tjaw~;iRuP)8OBP>Gru?R8vUy~T`>A#i? zN%iICDXa5uK$%VpbJWJe?j*~oGxml|t)5pK>@v#73A{_9yt|JcC6neBCf368=lZKY zpTX1~u8OFU?7t(`WIBs$UPfB_&%7T_npT=%(fNAj$ID5uA?fuW-m7+sK*vrj+M7;2 zdpb4Ks>-8ptiXtXJ)f5NT!(OIDzdBMC_v6M$`)N{##>=*%NX#{!B3Jk(^l8kE+^TY z>B?KP1Fz__C#$!#^|rLT-T6$#S5_5O4VzWOg)1yTRj;)QYdr{i*orf3TIrS=nwXo9 zG8w;*g|*s}z*`!%9O&f0KXP@oz3wkICo)&34l5!#u5E{H)2?pQ$VCG(%$*J^dKMPb zrbKm06(?zzX&g!qDpfrOXkOL)2f)MRa_~x94%fmo3KElp1^g?^((B$%e$(Sy{M`Y| z_I17eh)u2O;ge{+HU6h8@v@%Ct5IXRSAgCW?r@>0JW;wKG=98GO9H>EA<7UFL)~Pk zB)3CJW1v^QD0#AL4YAIi866X2zPd?YTb47?p;`XcwI0Nzr5dq5P0*#<^kVPig_-&oM%c!VPktb9Wu)pF~1*jhHq3KIy= z)753sE&SC|y*i79y3t^LS(sfFCduOQ zr25oXNJnq+3*z<{CF9L;vVqdxVPYzv?1p%eekftev_8d!9T!J|ZUpWIC=-{IhtsUS z*DY5T_>R)i3^vx%$#5(Z@ zc1O5e9g#O-QIi8-31@iorjbiSN{CI<8jQ_zEmugEF@BWn3R1CS!ZR;7wiunp&`VYV z`GR4=m2sEhQD}%&9|lo7)^L;MS;9}h$!E%K{l9*!-DU=yar{c?-f(0#c@%cJT@R3h z^dAi@*3e{nHbm6GF_F#BA>jJB0ybma0Li7wb#Rt?UmQN<2zM2O)u;?pnug~N! z3)Zj>)F$*lp@PCZd>MjjI#sby?_(rU0}QuyX?;L53hds9jntzigm|ijMb~c5(+PmC zp^H7^>JxLnYnl0Y}8dCnhB^@e$aO_e3cXTqSQlP9B4w9Us=X~qbG?p~( zLz;Q?dPJ40)ku#>ORQp^as%m@knvuiQy3ueGf>Ii`9lCdV-tWTI(PC$G$A_>j@DeY-THo$C z^a!RflBsRu#{!B$3vVPo*xTHmE*mD6jgEZ0zmGO2F!g%8?muD$@bS5Z7fqN39*#Mc z(8PZ^c4%1jO(+edk{nxxB?u}5_u{K@Zv&<{u(824uuss4>w?)xq;1!6BgQQIA(E-x zz>^^hnAQQH&c-$>=Hrgy>WhCA{wSyD zMWZSli%-eXj}xS`jaucOOKuNvi98@0|0lgPeAkX7O*f#7tD^$AO)C6NsWPQQN#jll zHwtZC&rW3C@u9=#}IkZfvYn{N@3VY~*A z?x2F-UyQki-@oX6`JF5EY&al*^ST^H&}qvKn`cnZbf+~0*8@6ujIo5fqyg(!0PR`C z+FiPusHz$v7-W+%E*WV~CTUt|GwQ=+kSfKVLkgHV9uz?S7v~eb@E9r4kf;JqO4Ycd znq)nvu3p901=QSw#JQF5YlX|r6+k(^IM7FFM+{YysT6 zU(X^9wZca`Y-~Zl`_NgMTa*R=9;?8J+IG+Y_Qzj10wphoFfh)mDu(C^9{FcJ1wSPj zDQUlfAs613svAuUjyh39g>)n0s8wA>n-Osy$TQ?(l?R^CP9$~BIR_r6nUK~0=unX; z?Lfmi7O7fSh2biwo|3Fc9>ECxD2f^z4n@W1mr+k&UW{fJBIu>H%9z-uNzN0TPa~pK?O(D1j8vN?D}8Xzts!D%GDmWe|BDb%Cn-OQ zXH+I-rmScLvNv`*_*R!Um#Jx0M)?C!6p^wd9gNoH$nQ`v2BBq4eA^vlf@tCzw<$H@ z8BdQKXVoWc8uBZ|WzP&4_)+vuUwPz|mcaKYq0iTuSOVanNn6*suyGU_tWHC9N%fxS zl{OWGYv9ny_64m$0%m$v{#I*^tlztTA>X!Zn(BVx0_~G({|P)vM}R(< zIZ*j`4_V1;xF8*HI`<~bQFgFi?oU_!ToGskJd>$m`5UT;CnQ^b!4bvUdpx_*F08s9 z{I|4{#KyW1x8Fnk9Zh%e_qBp2o2oA-t72>wg4DP8<@aUx7#E!JwUe`N{OUFzwOWq( zu)FmppK`$v(DrJ>n!!@3Sj1%WT)|DE3tL2(8tp$9%ULi|=grgac{e{oO*?u3${aFFxMPUo

FDld@M!QcLc?nZ`0c zh_Xc@>oOu2=PN zM2rMaj5TS4F-rML^{;{4l`emWYCCl8(8Sr_CNZOw&Q*qi@H>eFIp>Y@p(Z0YZd%+k zuQk&-jQMHa3O7Ar*EI6S#)&Lla$*|(DUS#%ccmkiB?k-mD+B37s<(g-A@@PegTXA) zF%S0^8SfND8deq7v|`}D1h$wQ^aigujWW!lP-CQXQn4;2__dtG2Te}hltBcILy^nd z+MJ8LNTV8wpAJDHWA!4&#cigScF!=Wzai#dIgpJqTJb(wDxNsB^Bh~?LRuK4%BN2T zFy;1O?I1XTnySfbdB`#JkN3?Ax0?wUKum7sLBKj-4_L{sr6d{D0U8Yys>Wn>$Mhc%L^Xk;soC>J<-s z;}y^OCF6FMpwE7z%OMap1j;2g9*%!`n${G3-NAw{qb97AO$#sah-jcHA)>8+VJ(L8 z)Zu%hfr5;5o)NevZ?my0+kN{)d=inU092Rv9}FTWqKnSsXps5SbSE0#23)l^8=1)I zT;d|OTx>ifI7VEc{SDa73tR7ABTd(QK%Lo=Wt;hi{|lG=;xyWqKXzOn9x~8NzIw#k zD38MyHsqh$R_9aE&kWP%N+-_K6hxjPb&2FC0fQA_RxAlcY=4)&bJRx6(yCISdW*O@ zcOL%rQblQq&8GtN-@h%bC{06U*;H{A8c~+?n<}wVTBio6*;P8;Rk2 z8boQ-VGPk#<}_Lt(b5z-)EEVFq>DMscOejpxFv;;(dA%wqKm5^&{cb}g6&WTI!us> z<3k~siTy9u&N)VuAllPo+rDEPcWhgCY}>YN+qP}nwrzW6C;RgDC7ZlWUb3Au{^)d7 zpYBxEIrXdWc%h)Bf-hUW{RR?Rqy?PzF5KYFoE~40!G%?%CCo9Q%w4f&@nDZoU^}Fa zQJgM75N%@Vu&VR|Mn?*0mZ$IJM-(*|`SMF9k5$K9e#%nr;&_1#Inyk19pBz+!~6;dgp& z3DT_xb7h5W871WpaI7TD5Ufpqkt)nFKLNoie58%LM$lN6ht)$d=>MjuACXUCL?jM) zb|QP+t_Bn@)FY{x_)1MGM=P^lkd5QKdPX=EFF}Y+=^hT7^j`R~ht_%$+@Xbpdfzb>kDQ}A5rB!8={iF1-}(~|FeP0eNwPbuUb7U`OKW|fQ~ zzK^y#Bf8qv83^i~4@$Qj$YQ@>iP6u~TgvNv2BDuD4!Ck@!+uPh1;iJZHDU2n3O={( zK1FBM!`wIg^$C%)@!vXmGxNX7oxm*`#cSC)rE&8SaS0WgF5ic zhwKcb>ptRSrkeLx!}>@-dH#At&10|7z2I7CjM6&j8vB3@cD1!a?4iFq*jeG6w2?

ACt~n*qZV#&Oqg;FZdFy z1Qq#9#;EAH%~W5>%7!a}3pTm}EYXBA+D61ewWb>@Q`c_QYnWzu zixN@SO67BRRE{_|jVF8zW(?0e_Moe??3up{vaE+M&!<>Ey1G)oz7)Y`*_U`L0dAXvCrqRPrab!+$RHtY*1$wqLv=)UYk}m^o}W1 zfQwCoM34;+fKNKhLh`&N|HKJ%YZRDMz+90w%dbBNvN<4l*rFYP&(h^9CCOx z!Z;F)=~7C35lU))-Sx)j+y=t<*hHLyUX!*-5zHz(k=E_2r^}Xk0Y3bFnZi06v6##u)m1puFkIYrqrkYhnuMG#p%}9 zKB(&aAB8`&)G>^XlAwwG zJ|b8c{OW?#JAh%RT$GVYf&`q(*Ac zv9#~qbqnmimR18evUOIyl-jwERV|m*_OIyn>Xt6KtqOoATl|rYhqG9X5{p1I%roXm zh#3p)O>UJewJD2+NfZc}dqBkCF2LSR@rPJa`M9P|+BTWJvAbu*{j1vO3`h_D3JZS= z%Rej;M+t>v7J6oMmF5)TOkcYIE1k4ddt9Plr~1V?(->a*3rNa!EN?xhMv&L?P_xx5S$ zxO6g~#crx>cA6!evA~3y^P8Yace%Yd7#Jh2eW@+A$WUD5}wJ~#A*E6 z_ULsK0+@#xeEXH5iOe&4>CNcGw0Z5i@jh*CZMi#N%EQ$^hjKbeoa1tJU;d?HOf)@> zP{qvwz$#>qH%6PNV<>Hfr4zs|HRizn4 zZu&Uw`q_TPyyIRSBQru~g~6H&FQ!YWuF=CbCYPl~a+DiF zIPz73jdjht1q1M%04`8s)8X{~T!z+>#%5wAww73ANX%3pxkisEXM#{5kB(4_{1;Xb z%NU$yBNdTsVbYsb6D1BEm} zCTNl&RP+^=Al;MpY|&T7h0Fpk+Dw?eA^fuMrBaLRr++r8?J5tsa@@ZSd}6pXpsDlA zC{WufcqmUH=5vDq4$FDOthPRS{jOeyn*VN`d}Tj)2TJa7RW4%R`tUWeAz2nKq216m zizUy`5gyMs-w_WeB{N@P!|kZCwhW%~6vdWtdGYH8ZIn3J?72gO;OK4P(WJ$d*ChLy zSEhojgnlPspkggA8zNskStJlvt8#zoXlW=E^9(4F3q6I@yb6iR>52RxW_5cy6P1w(tVEI#~T*N~UT4}r)O~g>`K5w7IO*H6<@OL0f8&q}p zZ%OI4_?Fg>%ecn%?)d$(s4^pFEhD0$#m0Jj^YiQ+DDGqbEn}r-M_W^8b60=Gal6{Q z*$=J0-Phvy^HR!GZF7B0V%@1BRm`cmbn*OhVno*4>-lhOErB=l?p|iGd9FWm{GIug zH0OQ+!NH?^a%4dx&q6+nHhoELdC5UZ@f3=RoB=9}t+zNVs`0Lsh(>;Ci6?!Jn5?89 zGt-CVNw50M+;Jzwy8U1E!1^2!=nJpXHUi#tFeV8kDj=b86+RlY`d!5#48g3S*{Dn7 zB*AWd(?|mXuvEMopnp}%MnMKP?pE%S6L_a-O?oAJ#Y;6g-3GE8ae@Yk#cDc&Kx<4` zJv7Et`h!QXg(-%K&cpq>{YGj^Jz5-1h*on)#KH8|UG$kF=_rt?HGT0K{=M>2Ub2@6 zfcEj!oIUoK$Yt_mf7u6Ub?bZf`hbKTJo^5j<&x0q?H3#puZkP?l zg*ot-FF3wTbG;CE(ISoCb?`ne9HzM(N}nM~r4LGuF$W+^(i%?FMFKdlj&V%M3XyxE zsLt}q2wwvU9?=It`%t!FMkK4|hBY|$A?*ym2Is$l?M?qDUfy%H78wu8l! z8AWnE+EGY$F=5Y(>>_Lu{HsllC*UC-cjMYF^gwqm!b=0)r0?ELf}IPQSpJ2ZT}+4b zd#kMS`KY*Fw~Ii=VIYm01;Pt_Co!gB@lf!@-!?Q!5=2p4ucBwZ+npqsejgv-1Ufht z|84YYy=W|P93MoevhvJ0GRY0s!)?y#Pj4O~$Na1zzt`Zr8%}%JSYzYYVG>oyM>u#< zyCif1BcutHHIFQTAIHnTIjrsZuCCL6`*Zm5tM;+`Jh!Q0_XIfC>el+YOdW-XQGv~0 zY;FIZzO1*-N!NR`+GuyOo6L;Q3zOVY9&!R{AEZ7(+4imu;Vp!MCMcPX=wW6I5kwd~ zn+_LS1y}18RLCoX{!Qs7#|7VPSKEvKrL%gm!=oS ztP3L*<{i^KT3|oUGZTS3_+iq{$Y*rGdo4OhEB=#-mB=UpySB({89w@O48DAQqv2$6Q-^YLYSwy8Ogik^8H{v`ylJg z8v|%56OLWpVrt&|S-5|ICT%B0YU2K|*((^*SZB~B%T~YFvQMC7rwg;AvjJ4NAYuot1xTVkBbM7s~iQ4%F51%>NT6$GVPF*Q2ofKUm*Ax>lI0(|QOu{vDb#oQH!e27vUy6As4-`(qWXD`4<&5X|%sF=Cl}|BAeM&&bqC z1FqMsXAdHFk%tid<(0|7QG%)38$FI6G+?@ne02Pmd_1~+cKsNIPWw()Ev zZ7C}V+RhVv%<19&Ahx*pdGPFfwGE(f?19!KN@0r z;-3V=*gfuir0!?3o8jZ7Qh$?BhMWuWPLhE+&uiJH{=j1gTpTL~^D_rDo_Kr`w-IDD zsA`o5PqpKRL}A_IS;qSZiv^0u{`Vh%6cM$J<;mDa*Q0AT{5&1qV0<-Eb5OVmc?t=p zvgB-ylk3QA0@>9m?~6jP!Uj&IoK*lNXup4J6$N+p#8ZB+cI`?V#R5*80Dx-{ce(95 zeO`@vdHUuOmvw~zy8+6gFs5mw>JL2sz9TT)CJTiPEE8QNM%5sVV9qy-6EA_P& z?Be@i3(gF!Hq^cAN~$mpeY59nTm9XZThUzLv+#vTirF{BqXB0(;q*l}1!?1v2_pC0d1d04a2h0TIpZ{nXLT^H#4W1Qm(=CK^qMWr?+J`q zYneE^|BQIvvr!D1s-{9))1=PZlUQgA8}^LgG>4j;3us9;RcJ)-lX{3k`i>-848CiC zsXI+rHgIW;$WN>Qt@fCKaDHFeWY@mP^5mLgT!wl%<<9;*Uo%e27RzNYiC*^mSgvG# zJ+sPoLp6O#>FIFc4L8{E6SW^1qh0?^6`5>)5y*TDO_9OjtHKc7F-cUn-V`JgyaIvL zf$XxUl+1i^?%!Tq!c&xaZNR-~-E^7zf<}J!>P$HVtWnKtcI>?_v!H<9D84larW0;* z!4pUfp5u5`B(;u}z-UG&RHLObVFR5qhYtWw6mB!^$T<}1ut|fL_xa6fW6I{fJLk1H zSjb<9BcieQ5aEnvVP1BwXnHSLj~Z2%*gQj;%>do$Ge9||8f)E7#tc)U&LJ%O+ zicoF^RAuH`g|o1leukPHDwxAAnN)Kv%!qMoWl?1Qt?{O?b#Pt z9`@2V<)00|Na*EO$+}URC*gZuOVf3r>dI93Tr_RgX0w8f;l;`p;Lx!{$mPj)Zw5

jY-_MOH}3VQ#H)d>FxF7V?sZfpndoZn9`{cu)E&e6_wn1~Qm zd(d~0%&kmZs=HTt311_@!l6pbZO?iU4|{>EPK-TUsJ-`C3yw;&)94eHqz7!DR#xsH&y?f+&Sa zh2E*dTR3Od6BESJr(E*#=>zZORcMs&hca9CA9k4N?*({)e=b02hy!ZwSniD6}dtH*AT4ohRfT>q?eAwvmif3%Yq5uNHn z|GN88jKG2T`HpTK4U1JaHJ;uKSo0exOe9xEZjISOaunXrBbz>oeR-q{9z-g4WE$V$ z?tDaqtVaZ;DqTEg6sUt|kh1_xcCbg2Z8`!ntCvAzK*^#q!_%F5Z<~zeA=uYl)pZ`)JGp~`uqC++>of(|TgGr_7m<#b zJsPCJ5UAnGk=AE|&km9-*dqJHyfSuwm8!TazGdWMo+LXfiKRr23MzAC`6zOOsbiN` zj`%{_f|F~82gdv<5Tm)O+Zl~9JA&rnd>_PPM-dkAh4+xh(%zo)H;~JJ8}b#w?VO7j zL&aS#orj$GrOVa?E{nD8>nEY!Cx#wZ4GF11V24e8$`tG8m6I9B#ystvj#q`@C)F#Z zeZMgo=EqREjVd^9h}{PJ9?LF{&Q~C79+5@hJ+AB8Hkx`gSi0o$?4ZQUFnHP_Hk7Rd zS{o(YzDIp%+xsE&Yi}%J#K8F~_GHY4v?u$sJz}@|IT7}k6mtgFgxg@^GzKKfw}4j{ zZOb>|dbLPIWKLAoc`>FRi3*Rf`}_06Lur+~2%tHi!ZuZDnUp<7if|DjJ5KL;TnWB} zk%ckuukeWEsYkr~%@5>aCus2xV{88~gsq5>I3`|ELMQ^GJ$#D{NB4D_)(^ z8FGDpMvS^bsBQ!;J`&GtJmYDF0OX;SnyH$K+z+E6{{XefQ)E;$lS8di2QL zuwgsba8Fpf_8eowNZ(s`C0IwjVQ78Uxt)|JC(2kyT1C?H6kT~<=ju^hB+Y8jSa7-k zGVkF6h)=QV^N6~+@PvRrxV1{Ep2h1UUk4^nu(9>wj%w0+U?&WBWGq)#J0dkRUyHz2 zdN-h1^7Np3a7|~;j9Bu}na+;M(s@IBJ4}RXTOuN8x-3E z)Aobrm$KuLMoBn#O7C&X<7^D~og)e0)oY7hK%C>u!odGNhCXwLi-@>P8+Xii5)-DX z0e?yZu@upCbbF^2N^;oF)tq&mz3h^7%j|Z4AAN882>4$0?0sv;fV5tN2N-Z$d$yzG zM()&lj1RZk`4qt2UDKfCZ3Djt&tt1iNH>^SU@A&mYis|Ye|5J|YOUV4DKVKJog6%0 zkcglt-yp8SSu3YB@)%zE3TKM)m_Kr7JpDyV&hx^t(@k9CYOXco%WUN9Mfq!0S6l*-8%77T)3N1xX{+^? zqox7JnM?7~)B@nkrvc_&G(-rZzkrd|KEya_H`GwVy`)fiw=`d3)&yg)$~=;{y^m<$ z$dVs|$jRYpAT!*rPJQ~yn@RlEM9HrJUN<#7EEy6|i{VrXP6aB3X2UzMagF z|8C=GDQJx-wwRC3N~}6F2ibu5Mws=JBf`+ zsKF-&ChuA>UW~L|R@?Q5wZpzRi)o9I8Ct+1lrk)UMw1}Lo3!#6P-uo5i>R=N_du38 z`SAYEkv;@0kieg(l1X&Q9C2~KGMxxKYEMifc?C2 zz}~|h6c6_ainl=_`b!46ds72!^@jOm+H5RxPWt0j&n7B#P8!~J2&PX%o0lbxe3mAy z?yXtmIlshs{H!4TEJBmGz=;DtYKlTHtI0ulgnnYFt0uVO3E4F$MzihgyL3yUeiFf$tfcu;r7UwCH6*=kv0qyI>#w-?|0 z1g@5$FviX2p7|m}mNKM@ovvC$B^wIg-QYPEJaPtG%Htl3TLVLhC3*i(l#_Ml=DZQw zuTElE_@pD!`4Wn)iJ1UaZ~ZmrCz9&VdJmAh4F(+r9a9ZPGV<~fjQziWYdCp=8T~{? zDrP6sbmZq~fprFW!lT=KGl0!H36ZsOE^PR9FS#8CL`3PMeWD%93gV_^6&E zYmi#-(0GLk34D1DOp>Ig8SM+)L)qW%gB`O0S!Z@&*TmSglb6#VaT(zzi7PSFcGCMN zbshNark3NxHh*Sx2hRCid1$n$!rR3IE=;Ys1g!+#tHZR9JFWig#Kb1}{!mNr6 zzx&KcS?l#WElPvwgt5bibrKB|pN8S{)+G<@yOpTzh2)R4_=c5kZi$C@qp3nm;?#BN z^`-A>teZtRsOW?bhlNdNDd=bo!Mt*^znZug>#jok z4@8A?$iec%(a+TBNokf02oCv=;f1+$K0g^HKDVJ=&v8$qCHtjMFW2@;o&@Lf+}{Y` z4V-emJ~ug;IXna~&TJ9pS-=M(DnghozU|R)W#^sXb!$8CrempAZCWp?zpL36F=4=L zwz4Ldg>Mb0!+Lm_>V@Ru5oQuuHG>`K9>a!hk5Fm(i*D!rbieG8Jxi!WsqUCvk(eyp z<7dg0;gbqRn>p&}{7QxY zk2LvLbNq`{{EzLwM?9+j-ta#GRsL6rwr&P`2BtAh#UZB0r^knk_jiRFBoF}U1I}&q&$s$pjNJ0}Z=35UWUdFD*hY%!Azkj=m5-!?Ho1<-x-C?nmFRR;O=U;P1eAvPWRGl3tzwk$ z&q&PHAnn3X@#n>HW~p;|O+u-3J}2g9=VRpKrsv{k=V$q>5fGsF=(s2I^^+ao8|v`W zp`3U1Jx3j&6-EXCE)o##;FkVxM9dz>B(k1<%m@eBeS;*=wZ~@t)w8Q1BQEx?1%Ubufce%bEwI>_oniy`82&Pb z@9zD21O^cYyly`#zo}hcn?qd9GZ(ui<;^e&7>$EYj(-cl@7UzD2WHz0UbU@UB`@_O z=Utz1UA!uq!R~)3X?F?~>{kH>TCWPgVx!Lvz>0=n|M%4iti+!`I~ey=Lq-wj?Jl>t z3v}o!-mDKB;IzKbs<9A$_}}%QzCOOdwIIp07-+yf0XZ#k_+r$0lDd`1;GfChl?tFC zUMX@9@P7A3d1zArkyb~PZ(!BtGXr(y4XOqk2qIHN^yUuq?Fb@UMD%|TbuC3Po??1) z9q66$BZFaFf+F%th=z&AARY`d|bzEamtP6D+Lq2+fg-$yd8s{s1>Fr0v(& z;o;mqpB?REb-#3|f)&SH9R8(EF!<6WYcWg1!QSO)OE$8w!*Z{UJ5nmAnDBcB6twO~Tn zN)5MB2g^)rIr~_;Cu|kVzR?CK2}AD#LL01$jMM=5rhWE_1z3fH-t;e!x!3zf!Hzq#^AVpH@EM=y#+h-+Nd+h`u8R90d)D+$_d4<*`}U2uUT3> zif74@VYVwBldu&9#c~PTY+mShGRE`A+ zXFx5R(SzJLMn#wv_#~#v6Q)ZriD|I?0--=ob9?V_5A+Dw8Z6McrzI5sVoNVLGI5vC zYL8HJqo*%yES|-&(qSPD8)KuI{v{8QsbiD{caw*c4)iDI9RfEIh#Pa}7!4k1)H;@BX%6{5KlcBjP{m5W<|-=yx=d^ zz&It6--s`JM@SQ5?8dQ?BG%yGpvTq`iy+UL%&75rC~h@Kwqdn53nME?%ZlGDp_{Z> zkFgcRc&lTIb`=jEFADBS2-N(Ji08vGIy3f&e_o)20?M#)heIW9ni;u0PwOs`d{U^D zl?4qA&5jGPPYg79Ml!BBK5^h<#HDly^#Dw3dAF*aEQY`*q|Bi!x781`e}3V*YU0|J2g zfE?N)tYvoHwNn=MaYc=ZrK-9gsLgu-;_PTbv3nWTcJ7wLgNAKn!By ziisu=jC_2Qvqy=*P8ZU@LLc-w{##Ef?SLnx@z;g=Q7|JgYm_R-xuGEcd&#`eO_>nF z`w0oi1WdewFry)d$Je+yqAt;#(;8zYqlo#X(SzI(iCeKEL=%fI}bRqesVR`8+Cw%OH0=>Ttz`z9q z-U$j*nfe0+(MfJ1ORk>882co~$tkEY(c4r)hNBrI002YDG;(5MYC{Zc{WxBCqjTST zad8B5U@lISoLyF`!Fbl`HF1&aB#_;X|q|IWoZm;s}z$*01(a1jrw8&eTa|7rz@hug%b zU}}G4q#+2AVi=Q{x!zIHw3RmsHzb(|#us7*mEVa9X8XR!!-gE1`WA~0k#qC1Qq<#s zB!Ir7Fq-G7A@8BPGTlo+e)yxX5n~B=;_7!hMn!{hfjF>JE8T%5v@JW!Neo!z(?@Q|q7Hwbe`mOK`+*@RB1 z5W~Zl<^@Y3E2->#B3rODI~V?+a9BzIZCyDM+(~mHE>!(9yTcZ_yY1yjcU-~p_s#<#Mo(g`AI$Ok>RX40v^T;6J^6t3*R_&I1d zq>=i27sv*n=u==iczisN1tEr)A={`A;!96AY8CYh794HZWImXjzvu@hZLGnVOC~OT zgqxylU?Ko-VylR=AbK#=>1MyPNlXZkFr5(jt!O%TiV-dlPDAfYPWoe^$w1_7ObJkq{cUCYiRIb7!;-qCoWlnkmC8I4!alrt*B8wH2 zC}AzNmyJ6z)vl_vHq;bvZliw4c45yRPQw&UZnw6P9z7Rdb{BdH_IK}%_osJ}$TXu+ z5hql~+P1zK^omWL8lxBoX+YBjrxu4#7;d?;tVgapv#cjdwrUm}9jVix50qR)=sCFO zMOZXxH`-eMY2^dE8=KslL&7AQiN`@CBDBGi+kg=U0kZ9*_leO~R$wSUpSDqJmH}#}C1>Dg_^q}IjiPdRDlu?{ z3_(QsudA|ohPg&zjD6DTy6u^HhG_zLo8N)N^Ue?|4T{t^J6JE);6ha>5|m;v^@*t~ zSfQp*VNqdu#n8s$M`W8%F5gcp_Acx{*?VI6^OE9-a&DRP%!p5MKZPK=0I0FH|0m58$rbzC> z9oP#1F-RRGL4Ll}PGEpddx#?peTS;{e!k{g-I8w&*b&l+4|q#)K~(8z_5o|erpDP4 zE5?eo*=#Y5iM}p4>~{|tp9=9oFrHkCcRp|DX9t>>&oUn zD(&@OF8Qp~ur3gtgO4pp%(XkWN_yTk`^iC_`U4N03i%zJ z1O8n2lcH=zjW*h_dH3$PP+=5H>~`HIZxD3#daH}3j?pSOm>E(|D516VWvS?@3`pTp zl!MfqAt2@ZL5+O4lA{^%1m$hAEQ+Ye=>R3F;4#Ldm#h@a?Ahp;tlv0e(v2_P>n{a)F~Q60F;z*p zKRGC8%v;W`3eGN@+6l$JQ(keN6KSMkC1+ATSg|sS>tN&?8Gi_r=uDk(1vw zlGiopcj9XsH|rCNsuBkr(OXOBJ@9m$G;4DjO6)e<=&XQbR=BB*nu>6H72lmM=;obh z%O7v9!Nf|$?|}in^;Z0}b_=eiyG8B~w2r)<2FXaS=(jE|DoA-~2HwxZWGl+L-3jSp zV;SU|Y@^VYj%peDq1a^m?ld4n=oAfzRmKq~4l#z@*zMDBnCy&jnxvxB+U%zrrJ~hZ zp{6^3Pwan8)JR7xHAzggNJlO+QyORz4B)0G)>6h8$WD%MCJs|4pjykN;FmHT(y$yH zSTZfra2|xVzSW1`{6_^iJwZTi(R0q&IaU!-j89bAneqJbn7Vuc1~-8lEC=&cLWNup zwO#OMcoB#lAaX}4vIRkWy@?A{hHo)+>+^#`kA(B}+wKG)(xMpsEC%Tr|A2oc>O-Fs zA>@H6jPIfadITV@jfrO)xatWgP)mvF3V91COiIyHi*cQhp(^YTAnRj<1BFsf3p|rC zX$WtTqXk0>3os5)D<2|K<|d^G_AQ26<~9N^T51x^bSR=WQ60K@l(%^Vb?TXkDJfUQ zo@7zzTtU4#iPnu3D4LOtrgG)J=EU_BP~0Ng!eT!koPSCq=h6Q`tk&Ddu@BsJT$Brd z!A+_EG%M|ewM9BIMVf{2dfKcIcMshygNh;xw4J5K>Hls`pRhEf{f_9s$C@55R|&WmqWUsPRPbG^{|Q$g?#Q0z7RT zgP?~Bbwr#<^PiBZMj(6zIv_aexSBY5O=k-y_+I?nH_{ZtJSdu7jNj-=bF(kEJ{nlE z0TV*bFrHA`{XS!q8Qz?tupMSPI~?umgs8ElLO$CjLC z@x}w@xCETq3%0!g_8~Ugw{KPQ5tX5Qff6QQOdAJSw+IsgD|Os&dg29jm;rf)`;6C{ zgSLYO_eDYc;ysJk8Sl3Vop1X&Cm^gqPlWZUFHx{XMF6&>kEYpaRJY`UAa?D4@U2I) z)H8Gaot`^>=CPQa5zi?^Wi_#cf4GWLna-sMboVjBB)TlwB4Jnxkx=4M$w-Dg4TWd| zoU8Wn4utpE>}!+~rv0SK%iPkC(Fi5R?!LFb`%XSSQsV;1L_VTB=_}cEbcycmvX2&( zXY=A6{9wmM=K}^5L0hfjQ?xnCKNWg7^mn;U zZQXh8e6Z|Ph+E^zSpE_lxIf!!-kVD_MJ=RTH3-(5HMDi+I~ex1T$4VgCp(x{T6%gu zJUSAz0>Y~MnyLj^I|W-P&-byPE0r$4Y%MkyTsA~?66r+gglqnecxkAxl6Y#^xHo_A zXN%{cW!Wyc02*&OR5X6te-u4eG*w)lhq-#KsGmK(8^@t&-I?Z^UVV+to&hMIU z`6j%suz&;H$!jeD@_E9zkAr6plJTg1k3DDKd$ZmFQ~li~_TDYlTUTSzCGa-Q1IrAo zQ!f4TFbnDl5y8hRMGO@+2ia#KlqJG2*agM%BcF!=i3b>s`1#Q!LimAa@t1KCyBS%A zFpoUCQ$FFx@^cLo!8Z`f78%_Ov6S;v^;AOs+DDSo4hYr}sny7{6f~LK$5eGeBegO8 z%Y&4@&nT5kjqU?XI-7{P6F3IN$f0L1;{vqhS*zo80>NoK9gCBvm8un5MFxGHw)tUzTfTJeyctT@@2Rp!Qz^46G^Tsd{Zs8NzD^l z@hRj~ z$Y_esQmfx6=h+2@HU0o6_)$$7tz0Z;Ps}?{-t_(gtGd0yTV)t2=@lX+Nhur}D}pYR zAZ?}&O{=}B6~F?DWC6SV-$y#>`e)#{E4t%YqD$?8-ft#LPa(JJ*Cot{Vc`4;xQjn4I!;|;7A%dh+7miPN>$&Q5W=)jf(TKr6< z7Ecy&9gY5#=Jv0ytrcefbaP4klM(|T-^`QX*EUjT93&F%7M#wx}4+3utPrHclqlE6r zrC9N5*0sn>xf&XVy6wI0n({j6o{HV%#r4&BOJ8a7`HP?#{)I`A5b-2NAFQ3UMO?FW zt?QJV&D}@PTo^b{Pgbd1Rj3}fang$Gd3!XeK1M;gt%9_%7*}+*yENa3ng$LV2DX#E z;qXgoQ+}T(-F?(DlVST?$(7O!)JOnabd00bz$fX%g2G)tQ2F+s*?mbLVMTDZJ5$LErA>|7#(s2jrBx9o!S)Pp(d_2!c8cyFn}19GHcM9o-!K~qbb^lUYPC91 zb$Obxw-`J?`l+j55btUc6L@}lyVFCq((F+Ha07YfOmfTXuaSulAUuB3y6o1P)36yf zdqlAfs2XyqS*U~qm(({Ss1C;{N_OJ!Vc6yMh1L#?M5(aMvh?uI@cK!wV#13NsX zx~Qzzf{Yn2M?}8R7Vo~GuHK11ds=oiM~Z{@(sWhFg^q?n38>-nFKZF@YW7ay>)-%# zkA6rplOfjxU##pMX;IQ(9)&+4uFPBjEL&Ic zQHRiy3)ig!ioi`N;4dpt^MlH^Q-Bq*pB3Uuym-LycuWK`g*WeiGa!vuBQFC-BBLd@P_;$=gNQ2^ixAA7ZT#R9Apfxo4eY zik%rdnTM+_qp@m|cWRkfpHGY`m(1W3mtKc)K$F`EJfHuo>rk~}^>53aM1-YAL#*6< zYp;NEr6ozxV;LA@sm;1xVe0~wwA_0uKvDVv&A(iyB`%Tm3P`%jtY3Idf#vD+rP=9$ z<0#+q#WZrg3Xb8QtAhrwt=1qEyykDPm@dJ9SoU}HUMFSV$!okXEpi`4bu!9DF2NnT zBuU*lgizzpbR=NcJ!xlEPlNVlWQ z;yt1k6YZvz36J~GJ~z6>Zg78#HxRdwNd^zKpLCd*cuNxO3ae>G`)~2w28C6y`&+e3 zN}{2Gx#AB|fq}kbYUQ@tqV;YjS6bVh&pk0sqzNsJz`wYZE~}Q@jtNTG-AV4Bbq19;iXgrJ^dn z<+fr0`%U$RZ~tJ(@e)*MqRG4!`*3LPCc|P7agp$2E~K{tL82KGyuV2}csO`mp8NDn z_WP%EL?fafA1JbO7bWon+&UCs<34~zL;ByH^k@%Ij0Dhseon!^c7`86-dZTXDyqW9 zt5NSeAC%Rmjs#QSNG8;gjA$wjJ*F+Do9eTE-HHn5%bq;5U&o@Xt*P#bQ^)J2Vl3(_ zEb6PausZj!xTspS#Q|x% zrFLVdP$-M;E6p4mbN0Fzf-F@z7aoi`kxHMB3akd z8Z&AM$?Jhd&mvpX7Y||WU98W4+RWJBE#O3R)l~Y`96muf|17JxM<_e>Ec8JALmG%w&0H{0lvKUEQ^H8@lE4A= z{vD>FwcUl&5a+qP#^Kjww{ig^J89rEAf#vP3xi?xVBS@xE-_N1V54}TsWR?{XRh-K zmr#~BHmB%hekMB(Y$ukNcHp$3w7vJM3y+L9a8O_)B?ni~u+mtS3&y(yNc%vumA^l) zs);dFx?a1X49p~R?Rxz~gKFXN8x7M_i@^nE*uNYe8JX%Pn`AeiQY#@h1**qOVhBg$ z+QoVeCSmkg<-DQ@-n$)XUFR>=tZ%jB>5mR^GmQ=cO)fC9!}Izi9N9>5p7XYVyGaz} zvnmM$eJTKphk%Xmca?wcmFZ&5OZC4LBA*=4X&u?U0j87v6lLp{7QQrI{m2m<{_wiu z$t_^Eu8~Yy(e!?spHRtBr`qXcjIB>WNh-1%cL$PW=RyaYfhEPwK#rcO0A2yNW^*pt zJhF2U{O$eM+{e-%9Z9*ec36FM-wj@*XPC@@T(NpS^XV;}fF^LVhp@qTJdXr?<6ym z++^+~ll!NVs@jFr+S%Frt+k#v!=ZxPO_uYewCjow=C-csjF0Hnp2#^j_|Fz#w#XyV zt-e;TnvYF1b2G;~&N+r$g-BtHySH5ag{HBee<<1v8XR(?N$7bDtw}!r;YR zs=p5Shy7u+`AKi^46z~Nw=UG{um0Sp%iu-!`==%_Y~%kR^P zr}{^vZn7?+5kD-GQhcWL`I^SF|Kfse_*()F&|7uZ*(`@SKvQ>JWcQ&?BdHC z$(L6XWNQ5rATo7W%a=HYV#ecpbqCIi>Xbt7N^fkZQvxlK}4!A5y{wO*rQ)sZ%Bt&T-%23S|GhE zevzjY^+pjtu05h@01*X+?^*vwn&TymZ!wDg6>meycw$FPX>C>vAb_g=n9rc0`j z(Tx3*=D@L&E;ZVyi)9JJVrsbAzGQe?vDLG^dK3IB4Tg#KX@<^$;GsVSsvh934G+Jy zv{W$C7+tX@YtmHVlmAP?Xms|nz$FhH_PU=xHxP1T(Rk}7|k^8_e>vu0wa zyv#E|!{-@77J;h2Swuz=H!#$&vH8z&s@B-$t!pB*w+07{_(W2oi-|){^IZ#Y4Mj$w z?zs)6uHzC3HC`<=K)8Y{MXFK={c+G(Bt!o!OTKEN4!h7gLi6`uPEdRYOCkYmf^{4N zT}8k!9-Aao9|cvso}IYrcs&oDA7ogLK--UiVl(^Jesaq8ygSvOo(j#+<2h}ad0eG* zoJkzxxoq0G7XNA?{oR2Qy@~g-^vjdBT@l{(-(030ldkd4h_TVUviLFzC;4gph%8E% za_5$a%dwkh>-KA&c8B`2U)$68z~VlmgT%)C^-c$hyh8rku#v3uauo*WD`=)?%`3}m z`;+^5EhYQ+&lI!#_g?h+a=EKlEwfHD*)^r8WBUmhRTvTUnR&)|_>* zC6(M`D2({9C1}OgbHTQ0uuL1h-s`WX3j@mpAf1mKjw1p0i|E^j(pc3#ZiDZ3AMB{+{k(qcZ!Q^MRPSgx-3mbS!R- z=HT2QKOIg&5(d6#$QO(ul=6hwEC%C{JmQdwG(6QD!wDR?hKYhYrM@uq%0cx@v@nwG15RJkUZ-&k@;TO(9jrmfH8 zh3fSloAAJ0J=0_n4b}>f6a;QBzLR*u9SJ#JC1=PP<-EmGkUY*gX~0^hi$7d+S$l|* zx8mAav5Z~|_o6wp2}8*qxg`*ZvxW1K7Phe_zc)(1qx?wSdePy}$$zAB8h=>|D#6^& z7tUaDC#&b#nz%24oukW^o)$!WDQjsiD+@GiJ1FOsa27LI{3Fg9v5u&7?G@Lc9a-eI zlbQ!IL6lmEUK(Lmyw0yU%ALLOgjfGn!=kaA39Uey%Vif@AS*@7G^}}La6`YrPnMm7 zt5T(%7n}eOjWw7Vn{;cPFo!7T(I%H#Q5s|LHVwa}RAmViu%A%aO9p0V3TI6ju{}-n30UquNA(pcG zAD_WM@ev$@(fQ#$>-qYWG8+%o1p8;%=i0NYV-EXkPJNb`I&+_z1=^%kHEyv4~r+D7ZZ|X z%P&igAU!8}&=7)(Ur?q2 zgjKI?&^1?tmfUdZySunQ>|>GTnch%lc4$TG14x;mdMB@ul@JT`;zT;(2)^fGSUG_)cZ{v@;6-9LxSV zThaQp`NCT9f=}o8MdbLUbu$9 zT>glwkd2;E&2&4STndh@;e@Z@Q2fhRVIm$4sgU(HeeUQ;l=eiH_Eacj7gr%3ji5Sm zy|7(ROx8qB*8FGUK!giHg7I7hf;@1|1~At>jqvo1P8bRws1-b2Ny!w9O8s4j07YU#ecxkpJ;5Y z;MzfTbuoczq}sqXwt5jaI*5^Yed2h?&7U8|7!ezlhJmj^6ER+ zw8~%`YgyO;?!vQvuMsN2@a4iT!Ad4>>Q=f#u~7Z9gMnXVxPtSsXE$KPvPB0^Vu8m{ z?Pa%H=(4UeBdO@BoJikX*PBLv^*xVDAFI1cd0;D|VqV7+0~g{^m9-LtGo+;AUL>`C zp~wo&6>{>d!@8nVaCfP^5o)F4DhdLx;up@a>)sH( zOq-$sXGccLp84gUQTO1bFTWM(V&+@{QuBg^SocMhkLLYRuQuyi=HpSX{~-bvPW>?j z!nOUM!<=86;A^IAesMHdEv_c4SC^?wuY9D z|2ZeTQq9}yx2Q|bCt<4OtspVU`NUE-4V8|1e!|Lh=nmU$Dss+DJu(HJ$(d$VE0N>j zAuVG^Bej3KBXAR0iL3NgEFpA)pjR)NG$Lx(*J3Uo5Ro~8tC_#TEtF)E0~=pC04YMOM5Vojt*T~Ies4R#e_07!a&aee|qa> zSN<6AI3-W42nl5XsV1&K2es`Jf^3Qh8^^lVRr>Vusgv0!XNsdU8FS>vBLcjL% znP8uXans1e3aZo|vr66*vdI~$6lw*;5U(EBn>CLt)h{EUs%iD-xHVMi2nT`b_+Vy$w$&GwVEC3dzl8u3^zsa64b#wx{P; zM~czY@>f>3Xxf8Qx*+jW(PY;N3%5w=-xDe>Pq9z69(48Q@DM@@I%`Tv>jzFx2p96+ z0_Lu285p=SWlBnl3)cpV@0+DL_pVU;I?V-d7gmHCj71$dtLCRF^RHVg?HBLSg+dZS z(Vx=PjAAF61&3YJjCJnlx7CpWg@i zFi1!4m4**?hSz3dp&W*%@y`XwO|H81{ldb1Lg5XFusF`OFsW)ZffqDXQ?)W%9fTmHCaf{S|P`FD1uJONQ-(LhM?BVomsyX6jD>rUq>_c+2{9LeTs7Cx3qgMOE=bH-) zZ_o5gK!`@E}$dY?$=6s@d18^g8+atR>H$J`Wop`qJoY8PY zgp0Mq#7n!zSh8`(qH)I08A-+^!YR5Gl1O=g0U^%T9xL4NK1Q&HO8$+f`t^}c`ndWZ0vQbefF&^g4tX7p-u)$b;4|^%#4fYHKz*ZSRt1h#1hwUC>#9l#_LNbBA1V-fs7yg6O1Na5U z(5Q&LGtlYz>eG37!zpRSO{GITHD5dGy`EV#4>=dbp7d{f5#5QjD%3NJ|a`pzSMoNXJTW?PbqD-Ae zR&Jg?OIms3eXak{E3Ug%HhF457tF%FAwB}0UTfqvTcwCx6G=Qi+`R!!Gz{A=+EreW zG}vV6VBa#D%?wqRDl$q!Ak)kyWSOzeJGV~OStw1DgyRD0^2(qzFtH7(d6#5pNxkTU z*#g$BeNUntc7fKkV4qYY*>nrlgwzp}F8R2qceaGKS{<>SU@trZFH*EZvMff*idri) z25PwxCUY{85S`NDxJqt&xFpdu53!UPS1E{gqC`<)3b1enO`)|q*y5QomgxLLAr9Wz z0|}lBTo5T*yeiNX>3U!Cz|*<(epx1}=o)E`vS6&K zbm3JvJ#nu&yiDn+5}?$O_A`3kER2hw%_;8|@^`af|9Bj>haPnGg<6qYza0FM;8GS3 zV^#27f1Q~Ay?fVZ>ht$4HhcT=gGIwz_qyi|;q5?c!Y@PKta9B&#kcX;a zmu`SjX~QqT?Gmd*O)4c$)=QJELrY?Z>P`*q7mxc-QLbE3LCHVoozI1BSD)EepH?rk z&X0?G%NZRl?@M|A_p(k?tE{|^ z^$I^5%k7;$+OmW*^5@Lf*V!rW!|FNbkgep_hKhpmxvH#fs~i08bIIPF=tt$fGKZ16 zSe;jLO&i|2>DjT9ETi)Ax%g(=a#$3L4pVMWz)J}V4Vn856yC2(V;*yEyF2@%#F2GT z&vf5#96TQHsMlpfnu4xL+n^USjQhW|HjSzAZmc0tYaD*^fAwZCnD!OkTIpknrMUe; zX#8@ug+c}l_$cO1hF&AV)cpZK(GEWji|ojv)YyH>m|cDfUKx$FXCU_;gNW6 zoU7^Qx7m>mA8Ad30e`ju3&cIjUD9OfyLXq!&q8Gv(L4*H4_~dPZ-ihK;+lJn+WtU3 zkCHt_F0Jk4+@Fkr9%Q8eq{B)kttcxRI94%`+G{?pNJ?qsxG1zVpSdjAeu1B(J2^{U zdOl`y9$&aFRu`m)yU4|^970ILvK+DEF;P1As#;i8C{)%gsG$H5)JMx6I-E%5LT@zr zyF`y68%Nc_z!&-ZqAQ~+i2TGP3A&W2BHmKpDE)D z`?03{&Yn0`@^R3Y$KXZF53PvqVB1U6G;)eJ345z|50M}9mUUrMPAo+wC!69GYO%V# znKv_eCag=!oXa|K9?D3zO3EJ&K>+yGgWp(iy@Xw(NdZ%}3FC3@;vFH;e|Kkw;>KyA zL%ITCuQbOYsiB7*IY%LF66ZjB+&#Ej17W{3$9p}5E|=EY<-!Rery4dbQ7Lu>czRGN z!Tu6#{5&v(W{#woxU|2+f5?tP3%XQat6{@X$?>)Eno7&$1Ud~hEZ!Qf`xzg_iRHas$O@D=&eJN?d_vZlRWuUNJ61zCfWD^}MP z4+y_X9&p<(fDVeuV(QMJ%} zce-9T_*eAHLH}@d*;i|oxAxceJ86$YF0zgHe)zd;CD*-q>$S_w^O6UA)f2V`kE*zf z7O!$R@ph}*=U&8<`GLQ5r}mG((7f2UtNOEhe#r)>hvV1L;oa4-4GHNu4T>wrGi?L! zkeu~QpG4}*R$q%{EIiV83CER4Kvus);V%dT9{Hn=@l6QT*S?w08Q3h=Y@I{dq|jL3 z@tl{=@42S0y2Y{zq^>evqt0(!-O>kwsAkqqE=hkk&UY6?lFA-TYMc& zTy9z0*1NAATtYp9e}H-k6RN^7a48kD%=>{qjsAk`_{sh{wvifHbo|_+N$aN!jd=P= z!^IhP`DNKCI`DnzWSyg5&n)zyM<>)cyt#-~;4!SivmX zZUNh%AOf0nmI_#gI~NPY8Fg3}9P)ihaP5c&RGgh<5L%k5%inuXjlUDis*u+!Fu?$cHWZ^u0bT3 zB{S}FUqjHjD8IdEpY?xfMS4OR&6q!kg-zi9DjtUa9r5^o^A(~J>22rvP)D}eWA+OR z`G}f~glQr|mjs7Gws|X!7ieN&B^gt9am<21y zDsmAL@iZ5W*hz|Hc9=qkqe#gMa2t)kl(2+sl-g8AC8ULi;81~Cb6kVq=B2;sti&5UF2nxfFK}Ek2x%#XHsQs`PhB4Bl&e@$dgHn zyrv=48P=#Mbj4dQX={y?wdvo3UW4j9?aL8iLv*9ITtNt>1`bfvgK*jT{2Ld>$4ip5qA+XXmu31^x#$IlUpRcZL zVXb>6s=V(Fxq7}+jd`M6zwT|bz9Vhra04I=xrNLxsuSv3^er-T;2#kUr{lMhRx@0= z)D-vxtXNV7ijzjoj}B^OG-cRI#8rnp8|7s;2zjm&m4pS6c!x;6e=&{113oC}hiP|r z(U^Su=Mdby_m$K_4~KdGH{0X#a#{T8XU_=azv_m@|GnMt2mN7VZ0KZeYxAEa%uEkU zE9_Os|N!U=qez7F@}ez~;Q5qoMYN_(1nXY_2XL zlJNy(h-P7ET)9Rm^Ouv8utt?O1k?$e^A1Ityy`I+fB#>6{5X{96TzZ$Ax)XW85N%ZWI3Ep7o(jY8~69JysWMYcWF?s zH}M4!vN$=Z$2mSvqmCs9a@)e@Pf+`^JQdv@8KSjn<+4bJ(ih6J`FvnE1BXu`!T zq3I^f(j|p*DpaP}?StvsqT?Fz<;+=1YkS18?6u-v63dp;8@jo{8qso$tE(kl)UoMK zDQk6_oA8$hq;)Iq8$jEr@Dxmvb|<`eCe0co zVj23sM0`hmmoWL|aFvFC8X_6TGWev=h$dqh?=j@W#<$k1rgu*EtZ&_T1;`h3kZVT~ zI?E+QM>Wn&I+^t?86KuObu}ma`_0_sU~(i^mTUgq!>6l2^)_K5L=YM5A)b0`QyH~A z)sT4AV^y3bqtWyNJ$FdiQM4vuRINc^pr}Qy4AXwPYz@cSl_4YTQ&xUjtXg$K8f%!| z7p&0q5>Z?o7u~2+lRPS!A%ll#uVSDmByJ*Av1A@U3MQNIV)i)#@e2(2N-H@1H%K{0Ct8ZnnQBv%p9cSHvg_XF!3K{X3(}e z)m%B&8oHE~oL1REKOJYWfW3Egq1vJtwd4Rx$9-yA_|r7yDq2EI#|dh#^=n!nwG6ZJ z$8a=(i}i0{m54w9^u9__3y9Qyg8&!{Ei8oRVUh{y!HQ+Aj-_&}JEVJlz6x{xEVm}h z?AC&~tEuVS3%IlnQPGg}=`$}VTq+sI%Of@e1En zUa1HQbhQq7VU40MApb@8Aypo2xXNf9`XY^P4DXY-Tg>^SA>TI8f7h~v$tyVGh? z>iczepI+MAdfO57Zm0?WER8P}GY=KOPQIusoy~k;vB}R8GDpOvSd~rK>}~tLYdw2; zNRP1XOZh_du$z&p+7QdZ$~n* zZZg6w&TsbC7_@bM2a$#425q7N!%B{j(9JJ$Jwfb()bgW_J-k=1}IMCc7B`sF1+XzBqwe0bfCN6AhcYhbhRW1 zF1NJ=*n(@0oj$iUjb`(z>Cm>i3J%PFEkl^Xhu@&kySeqhqfmICKwZmbhhb;md@*J6 za9wtJrbW(`|hPB z)YvDO%G_mWTL_aiDv-C?q*wXmO~w9zfigDEOHuZ7Tctd1s;?zpVCQi7sSKYN+Tp87 zCD_b-b^Gm=TAOZOs;(fSndhrBv!gm1`s`Q1W;Q;A67_sU`Q3#U2GJ^(L1%EN46^5-p`~Fk%HHB!-WrPs zPi8{w-Wr1hGC4YwPIAUwl#Jis59X>)nuQWfby~|#_Wog_FeK4d@U-?%JlkDE{Md2Q zPR0k>>lb$)%ug|^GV-9vWwxxkmepVmIhVhGzUbi#ceB#spn$yU4AKUpX>z^}8ccGC zTG1I+6QN8U+P=&>d@a+=N2T>dxYO14_=~sdL9KVm!2CTw;p0fv(ekqzoJD{N9eQ{% z&61=mo%rJFtFD<<_9WLCD2Ydw3e)?7kh6THk~Pl;P7~o0GXqifKPv+0IVhS6G{Wqb zS_NbP|eG8~;NQ+Et zd8;7QJ`Jwx2lQMiomOe==m3el4)ArzGPEunF~(&*!_us5w`RG4maIRsPG`ihRx`m+ z#ahJ+O(97fiHnRxzJ_xZi(6O zsxa!@!r853rV8kY;CP`L0hfB=S0f)~uOruvLDbPs#F7K-=b#Cp^Ilv=jMmQhlR~=rD=_52 z>p@h|&-l>Qze zDbVU76nICB@_2IH(y(tee(u?PgFxI&d78N22kepX1e>y}%5K#_4wk&EH32GK*PC*Y z@w;7?Fir_Dg0&A0e7!F}YRK>m?)EP=)Wi{U{w-Dut4)nTzptt5%kqpHJvKJ!8ry$=@RGDZM`k9pVb8c;&aQo{f3AChNIccY$yWD+(QbPq z7xFW9EPl8W-%0C>FI%o{i1f2mWXNn%8^_CO7avqMBc0(xM1WywGBIw5)aU<;HsYN4 zNmF5R%1=j1&CA7DyF*_@rvFiNL!t@8EWo5Wb&JMDRM(U6Dw#5O`!iJP=SeY~Ivir; zq^nfO`8k)Olj=3(Cm!qP|B<58Iw7-)G)vWT&)O@KHOhH}dmrku?1M=Uh|?-F!Az@4CKdvg#bMeqU-kU zVWS_{wa%u44zqC_wDQ{80k#jT{jV%;EW4y%QUJ3D8QH}xW30i&HK(@VTl-tiJ|%VY zowy~U4JA-_Cip35Qjo0kSx~zsjf?~vQBI^mfAgk;>=-*q2sXM%YW^*zBifL1qV!L# zfW^Sun z6My5ys~4lC$X?KcRp}5deA)3{;C``-f>>p}o}mxbGY=_a&nqrUb*s##P9nC+Q7I+0 zi=1qF3_B$r_AbH0W zo_9Hbn|DdOV= zGu#fF3Zpzr(vM~Ae{FLXj*!|-i-Vi7gK?y5Cvi0{-?RJ%?$2Z52=)t)Pl2aRk7i&o zRUEAUcFogyae^T~2~=GD(sjo0K*tU?4l}nN*oZ0Ksa<+1t1i5*)^_%1N^1c&! zekj^MCqhZh)`>)DdVwNhbvi9uJVfU;f{oGQaA~R;ip5Oq_|uAMdD{`?);weytyVl_ z8fD}gdCl4`5@&36_OGs~dKaD7SW2qqw#)WGzifi*OC3zNqp6k~X>@%AM#r17_Zr>OSY5QZhFM1~q9Em;kNHT3)v{4Ao4pcI z%Sc44_d!M`dW2Tl1r3RBf~YX{3lw&P{Kqh#x*SX%4s#-6Bx(}&hv8k@R>~jYj_C-{17As*H7NaZD|`rALk-yI-5Q9_dB+Rm#mVFu9B;n-*W#hayWo(G}!yS`r4~g zOgM;z)w84I*T32OyWQ-U(&x?_g;1!0I>a9K5<+-OUolB}Lds(Gx5;k4c|tbG?8?DPctXNucOuWXcBE~u zXS%v_Zbp2LIWKlSc)+NyCvSC+T2C@w+Bp4s+joF?j2e6zpVM6a`rs_ss~D=9e-wR(iHI>J2iW4(|# zF?W4D+a+l`1u*d3!(}nKL$6xm%{#Ei0kU$u=t3o9LPfo$c|n!DOXu&)tA$EaM$W{^ zLJLTLTEZ?V;Rbn&k#D`kRiiEh+s*Y8a527SQx{)qt@aC^=egrd&*`?~Y|rZN;macc zU`OO!b|l*e+)p&o0A6%fHd(5RwcM8cBoF z91S^7OY;tZt9w~Rca*Xtu<6HgIC^Unpbd|^pnnb`J4n9?=|t&{v(2Yg5&@(KvV_O2 zsJ#a99+3GR#I>po4K~lRd|X5+%P0kxL+$_)sFY~h1ep`al&IVVfyOY(iTo$WAGgV1 zFACoI=VU1xED%zDvS5x`&jq=lVt~sGaK+XSimw&f%@{*era{UiY?^avFg3Ul3NwJs zDi&xKr|0unw0@^SC}c?q%cA=(pUwGeF8%xn-hDTMU!r&vi@tXvCw~uGu7&uZb*r4@*!!4l*?s&KCqN1 zUQ$qzb@sxG0Uu66zeifl=An6MBNJeieUxG-<~u1ZJ=tT9-MWv_iN| zlhla08d6nBz=qH{F%7lR+M;P2FZuB0Z4upyfKM?%;Idt(h@V6vm$kW7pMs|6t?9_n%j zx_=q1n2bgWA_8fNeW$l#Zkeg5)cg)W#%f!LwgYm**aDd`qK#pg`$Q;WksYsd6jS)v zRO94lv;qazYDfJNT7eR<(fV-&l411jN}jKR2Gqknqy{uX!GDVR`uh3#I5_9Ayx^P% ztXbCKq6~fl-(AZpTSYjQCPIEs_%JJb+#x|EP4g9w@Lk0;2K2@lOI)Qt)j01B~)e{M$W z8R`$n6>=ayxJm(Y12`aeoy605K-K zoD!0953@cnm6v<1L|W=eT7=Y-2`M|ZDO+9Hzu}+F3Pxnqlk~LNzC@=j^sqtvT*-Sa zt+2?C4bP&f*!Kaf6#y`)VzZ}T6Fx`Km}UzB_;_L%_26?hOz7SlSGpH}i{MmT^xIle zdk)|pQlV4cDDO~zCRp!|ISBzGHf50-qb{+Clf4O)&>B{nQo#_&AP!` za%loXX1=n31We)!nR!1vqXLLT17xxy2bueB9Gs3%qDcSJQEOZTiwjS24;{2#!BgF~ zVvA7aBgQ-Zt)o3vBCbAlnUVwA#FYzrL0!!U7;+iyna$FTubnRMS@8Hu4anbS1f2;^vE&yZG0_!!K{PnEf$5EN?z*1vQpZ=@E} zY2y!v-A)Hkx)~uzRWFjH4>a?A{JP~Y$hrXoy$^a3JVoPo!F#glv%(9I^U z8Xcf-W9Sl9OLyhMNn0>tJGkb<2i@UoNp@buX98q^NKh}~hNWS0)eYJ++K}X7seC3$ z@2MJ;9lWB>hg8)qy58<$%%`ChGQP&<)}d#|%oNN)cC-1j$zPNEd+>buv&YAypcL{e zmbV6U=Aby%frZ{9JW(mX@`BF)c+sGzLxLr;+K2H43ot2Ka+T z3GVSE@c6tJCcWSwH*0Lld3z?zt=H?rSkUw6p}GkTjN9@yl-Lzpp;l*+MO5`V?`PWd<433dO$Pv{E^ zWV>l)FIgwthAf$7$s5MkT2arMg)f$ci)od_vCc@3qCjW1{SVgODM*wk*b?p2wr$(C zZQDL=+qP}nwvE%aZQHN!yEE^;n20++GanUEJ8FMaRP4yiTDfv9^!QR|)oe@@`_;%f zWCI7%v3(Owv%3_2jOglODd@jOEl4&h&GU}LoXL<+F(qyJ47q!n{Z#_*n(jz;! z5F$w|Hmm$97Y(%}N+@l2Bh73!y*U+-q_HMlDpE4Gq>NrCgx*`(dzq+bty}308LmO0 zCR^$6q)}sQ%HBJKFKs<{%PY1%-pxI9Dm$q)JN08GfYz1%*UEVx|Hdq4zLjUbmvV&4 zbA<37ed#l=F(ko4(AJtKTBMI+KC)jdQ>mU!&R@02Y;&d-*{oO3D(q&9A`aSdMrOcD;T2IoIFZcRV&eoG)+~iZG@;fD|*JNoY``(r4 zI7^egx#?p0JM-h_QU=7OR>>ITMUVYPaO1|+7-N@wa-IK1t;R0WbKYueeyw=Tqy_3q zY}2+Q)k4W?QtO(=c00qQ1+?>zKx#gE)e+}@DO#Oh%rLS76S809=dh1d@N9*1>Y}yi zm}V(ha+_Cb5WMABS;0^Mb5vf4xmG}bo8xRF$z$M4{4F}Atp1;@pot>rW(>FaMHn|! z6n0)mSQJRgSxP{zR^g84wBZ%`VQJcVkrbvG-U@Kzbcf@$Dj4Nuv#Zl^kRufhFpqtH z4d>LIOjq#IC5K!m*2fLu831D&MEqsjnsASyaW&-dZm8Ti6U~nEgb0`PnrSc z>aF=MWv|iIndK}6;+`!dDh{UU>a`olH3_HMk3kFtWK7DlC83svo`P6 zXb?ogLS zj>-Zzio9Cx5b6+@NJ$*~f&x}YP`@0ht7Pmb*F z*7y5R@=R{)Cd2o+sOST?&({9da4i0U1bm6uctn483Iz$nsJJor73^euv{OYNb%CiI z4?(DlN+x`9I2%MPD2Sp^+eCG%v98rPw;v7kRMNgE5IesV#+eOtmbhfH@Q{osq8TXK|nEHK`lOI zl(j{NTjl4>uZ{FPquIi5t%t2#R`^14dIf}tpgzw`ZuKPQw;nB1>>f0*PA?^JdpO(Z z+x9J{o18Ib@H#SJ&aFT*vVt#AIk)U!(|j<#1f?;82|cQiL&QQr-{o-dxGA%^cpmrr z;_OZz_x@bQpDjuWkvZ4eKU)NiBlt1N)`^V}RoHNaVt}30ce;+`3D-8TTYxvl5iy8k z!J;MrU1~%Va`!|Fk&~K3jwl-|>TO^{ReLj%`3Ai{{a_${m({aK)Ydu2R$ACd>t*)b zb*}ihPH#0_T72n#ey`s9?`Uj$({6p=bBd@sO03jsgc^N_l9W}nGq_k=H8*gnta+bU zo=tR1oM_4baKKlx@RVodEM?%7XW+cFmRiCRpHbyB$LxAK-u$a}xs-Cg)VgxxUAp^p z_*rurl~4GNv!;Rl(>7g9Jcv&4s3=Mzi844#;)0v zMi5b@<7ip`J4>fAB`P6uw#6__SZfkfYqoQdQK`T+pxJ{9(nAfcm3m9du<9tC>Qs-g z48EE!gajM0Tw|lni~I;m)Pgc3KVDjz^@$FJmRtk^!I~xnHEKau+tS)i%BuV%3j+R% zGDOTX!XN_$SiBCxY=CraJ6|%$mp7M;E5abNJ+m&;00(eoF^^8GnH~IKJQRu8Ga#;y zrv<;w^m(nhe8v?KcHBRZxdsrr7cj!7xXmUQWD~-*yiOn>l2;8nc`T@s9RFahig@7E zf1ej3c4@xyNlTt^FPS~adw`0A!8x>wQ!Ie0y1CelbuU?)B_uPwk@jVibTsqyhnJ~F*StCw+qVx7I*)#WqrI`I-5`4Su zECw;F=%4P06Ij6b>?6u`Wpa4ww_?6Zejgw_=k0mnFLN!>@=pK!`zTSv!mYd@^= zsv=vpfSwU%b{AZljDdN?!$rqL6_te=jfKs@#iSP%&cu3UrH|$OplL0vBA=PP6=*xK zzdFkn1w?#NB(AyYpSi6pBU`r`P-6(U7m19T?qfqRhOjk@hYD6oKD8&0HJ~fP&wF%^ zizGbD*-M4R!9>SJg-+VDEHgz$F}Q>iQ6Z^eVh~AE4ohJ)s*U_~!CrxUk9xqG659`u z)t+LKKZ$Z8IqX8u^wd*EQI;-uuZr4y4Ina;Q$~T5%kEZCffrLDVJ#jX`|(Gc-DOag z-aTV}hy^xbu6TzWkjxyEYN8x1UYjtKgXniYB>5r;pMkm1vV~v^UV6_if6qR9*Xhj{ z=X+_iW{EUQ4FemJ{Fxo(5gPwKynqUAEF=BqIDo_CTfMUz-MgTPoS)}-j8-;zk#wJl)k=JB=Kr$DqeD5> zg5l1FnVzIgG#Rj#i4!Z3SM)R@3QW2@x^*q*Ez{PSKj(3?R;^irnuy7 zx$!D3qEu4Ap@h(8|Gs`EE%FrIZyA^l`RyW9v0pANqQ7NbOTA;)M#-(Q>)_eYj2aLP zwc8y4j5^aJENdkg|Hj!bgpod;GPe9+&iLZy+I(pc1!dP)n5p_R1jN3ZXV% z5cU$-Ez4^O+KE}7Gk`Awb>46yrlnX|r3CrA#YtUNjL@#Q7E6T zYC0SSTyJh0$@%8An)mrE`7A(N~L{f5o19BvIov#66(_cBB7F~!tVn@ zbfg7-{3!?y03bVTpFd~+sN%Y*@g)CY^<%n{E4J7LSF0q}8`it`%i&Q(Qc853s7dfI z$J5bAGA}eOdgVc+o3=#|xfXQdX%;eLV23v%rGbWuGgp#PL)io;4jP$!xwu0dMOub$ zWQ1>M1Ro89L>5768QLck06$wsO6}fX_bHFs#K_SFt3fh9hsT=s&lSBk`~CIsjhLp& z3#15#M_yKeN|dYeh-a>rrpgU`@FhJ80cc`U-bGI{d=8h%x%ay>+ z+Ud07tutE`ZBppz_QJdng^2A8nTQWCWUqX`CKN=hEJmzfo7dew9>oRL(^}5XHU>6l z+UpxFQ!PBESZb@JOecrp3cRGI!;@O-`7M$`;KUBskxiw_>YhsUPN3rhW0yIOpzfaT z3&XKxUfOeRmdoxWHrnVD>1UhO`S{gpkb|SLxme7xa>0&YLV=@TvBxo*j%>6}m<;sd zyIE&~*Vatv*;4AvYtTQK0Ct!RwJ=OKYX3^4l{OeR;wbpin@+T;F5g%AjNhto4hN!( z*Iv-H*3cSO)rb`+69EueEd}(dZcTX>zh>@WH7$2M4`fyu^CJU zSjFJ+1(LYw);Lu*cgL(Y2)rt(T)lj(j1Q&13uLZAS9EhSt&iTA_TAUA#JW}=tvYat zr8X~Ja`*xh&+bH$Hjk>s$J38Z;ci8hlhyEleoL_Ms^axB-jmQC9|LP}ghL_XV1 zx5&v6o{T#5$g3l+s7a=FPr&Z~xIoxWqdWm~9Xmm9;sb#{8QurampC-&z-3R0aH=;} zb^4DP@D@jS_T-?sw9EjbghI6O-^5H21OaQ0fqO_6=If{K)9A!YoQiiEjaD!+{99M;LGF61#2_@!&`r@{1(_&W=$x(wy zqhf)|+T>Z2eN{@pOnhEC1j~z8M<)n(NYb!VB`q-k{C6jYsR84c#EauJw_OOL6!GPR zw16RID#SGW0?)_|(o^6>fETN`Rb!~x=k(@kfS8#z#1=&c@1b=t9kjB5bz(a4A&Y zonia2G)5YsSFyH6O3QXRoIwV4BGg^x_?5q2Mxi4HgA&3W6$0KH?iv@d!&4syqH-uZ zc!3A2)$>Vn7&5BPSUn!(Sabb+!XWotQCHBi%7ap}#r6k4OcSUo!BPkCY;)<6hE^5$ zmlaBkK_V->PG~OnGNaFE0Dcfn%3A{*1{w{~9CfP4dNh`@$t<-g&7~9T3ntkT8%DM# z5v^1Uo2lFl`xaAfRQBiUN*7m-HxM_FFU`suj%Ov_ku9w}zr55DUh{Tm{b6U~6{kVa ziFGwEoLKc4m6HI+yVL*3rme9(FZ-Qz+dC}-yonIZJDhG0yB53U%Dd%G`X^+5PM5lF z4DN3AGzU+5**a-oUqh0UHKE%&7<$F=Rz9IUM82mR$tL2X*VIthy3Dsv{>3p`TWp;R zC^%GBCkOWv7ihhX6lkgy+Ay$10YGQFb52Y3PH%TbJYvbc$0PlgU}|646uxHbJI&`i z>GwC%AFedmKE|pbO5eNLIZeKD_qQ3X6iQomlimy7X7BxDvAJt`;&`bbMS&kzAuw$f zynkGd`A5#$JIoAb_StYbH}cAU5QS`~YI*P8hbo^`z4_l}A~La$>ACSb5` zA2J1gcrKcmz<5>Mi^4+BV;}wT?n1f6-uv{PIb!Y>^{&rsIZ*R_u=Qi^l;^fMyDs^f zoqvu#yukEV*Ja{CI?HJkYB?HTfr$B0j{liYYc-!=iMw;9ti_0#etYljny-DL4p_hg z+!Erm8mT_KrFs8imaY^4-+o;JUq8@+U4IQjyg;?>0aPZ7#Y z7xrX2L>DwBf{r|&`kKM@7#$%LrOh84z|}LOW_pLXCy|M%L?EfbeDinDs52NOg~pJ1 zmAk7uUK{H>BYMpP$@M&y6-YxKL>qc&z(2K84j&>DvDS9o^|Uu9@P{f(ADn<;wHerF z*0+MU2Msq8&*JrY2T@3lCPKlE8s6r5KKOx7^WjE>+@b;pVOs_HV|%rymk&q-a$DN> zxF7$Q*%&)~1XbWYY0FIej0b>koFe0$`wxE#A^1L0Lq?u&HxfKeFL2Bca26j}G#{9C zFM##$awiU2pav)epYIu<nL?A z{XSxHJJ#B7FJWWB>4*;f<)*vq@=TIx!?)kf=O&rt<4A2DdYuDF1q+vKuHMZHh&?Ap z?ZXX@=i!qcZ;OplSVR@vA}ej6bdu%awPUXQ2OvlHE&rhe}C%f9$y?B!5*T26S6w2gV~Ul2)|4}ABUqxh+h$km4DR}KMSa`?^jvYNvd11@)K|Y zm4SsW2I=YyKYSs@gmPdZ2hZcL#icC1&|LuPL50^vKbY&A*2^;9>jLmu+AbQ0z;Bm% zSMx;xULx2TD{ss^hanY0OK~qtxrJPUazb4LA4lW8#erYeJViuBQDIVSc`L$PoYM5( zV!1kkDIuc0i<9j5B~1$nYX1_~@q%YrliAU=a8XS_ZSqyD+^9>HOf>#*rz!*uEp@zTnaAy7BMrfHJ9_Ie2VtTDC=<(Y97?@-1-bInFp&6< z`b6m@(QyggQr?XTJ!FGcPtzF{=wA6}bQajpEUt0NxnhDnNnw%);1%1adWP4>SGkYm?=^cA%mQ?x1pPX=db==rkG4> zwL&kAjGbzWM!Ti3ayKG?q4sAt4pGp@e~C~3%C*hq)KBGO!y>L&$ULr?2vYS*j@mKL z_y6P80jI#VhyM=bT7mrU0>l61*>DFFM>|^^N0a|GG8}q%+F^~lzh3j)65iqeLEQZ? zPaq_S2cVE@85(OKQIzu}|Dj&TAZp1cvXKbj#E$C@G@s2gG<(dH{~nJw{y`j1bSi2| zFK2Nfvms-W`LRfJTbJJd3lUEn7s+fumi~9ESAPzJOOk70jRzYboSvlgFBuaLES%?# z&&O5k&b3eNRxW2YEC4{;;>Wj>D<42FunL^*XP+}1@GfGUAFxTB9|E{UdVD&#ly5t@ znD4KZ-=FYg8VJiFNqhFSlsd7?rm4voVV$Cw6dDKb0StRmZ3Hyn1eJ#I>magy31(r; z(^efDX*VKWO_#AAVWlDnz;fA&)J&xBFg(Da8JIvAxE2Z3af()AO`_`X7I7?KX#UO3 zn&`B$18egn!tAksenR{X*?$r~tVjHMbOs`w<~V0C@LBM0Hmo2hjnniGLW|IYJhIEk zC1e)&B}B5p1-DS7C^0=0q{1TD1MT3?T_hHV(x@ve;LraJCML?^x-o<(7Ky~oRevyH zD#l_j(1^ucp{YC)oRN&3{v(>8P>7KVjVC9lT9F$;B2Qn2)z2ap<^fKf^?)odFDfX& zUwkW#3t_?&46F|Uf?x?bpn#!}%cm=iuK>a5p0i?2QAS24;y%?ya_It$Qi-f&wrTr@ z*PsIM2T$S;a>o>huSabBCG6FQC9`YpBT#9Wk4LDFi%Md6&gQeJJ{a9rHQI|TTqw&d z&Ra02B+Uj$MT|Dlm1E)}E5q>BYMGtAE`g*H;1Wa3COmJ z6h@@+&y`(=i6Ti*&?Gu|Gru1-k*8X0&Y3S2i4?B%aboOT6&ldQLzeEB6UYoPiDPNX zC%Or&hYvb+$QA|7T91`hP1Uv2>63Lt=DiO!6g1$|1OBnSU6R6+1t)LMR%0gp8J4$EBkSxeP zq7wbjrpmW%8|qgfme_+Hsvx;Pk#aC>*dt{! zV1*OBm;-M0)_70b2!@=90g=ic@h9fUy7EsTKGboB#clwH4Utn#J1BJ>f~mzcbr`1% zI!^fH=Y(IL^FBT)qk0{DHlmL*SfT(GDbFdYQR#(qF$|WBkw$BdpgM`impwB2@uI2+g#sWa&&5qQPBDsQ1ZAa8jY0;FazcrdB_~LO z0{neR?MP7yskAZiS~h-0Mbjn??7S+{IM&Q0r`SJHhDq=TkOr0cz~Pm1=mQz(Y5`sU z%Efb*vGyZE>If%LV$=uX3M245nI)|Sm@5+A(0~QpFkBH-MZ;!WtU8#5NFR#)J$@}i z&nENK;WD&R+ZJAJowVTnv*knd;_(3i2x)+h5F8VQXj7iTqodu@{1da# z)@y+|dXpmx*d~_)8{gubR9XPi1TM8{DH}-A5uB=%$E)Tr!^#2hU_Gg;7qKkF5q# zOMzf{r>==wpVc0ih0Pa!7)8$)iA+#El8ix+B3(qUs6sqvBN*iE1i2?L!6jML6s3<& zGjWEqh#WvJosWprT;y2l-KiumRuU|cB^nq4E-XXTjlh5rO%5~!38_SAKv%xWz;$>= zH-{rANlh`FobJyJ+(S*xI`Lq_^&E|Dtl!NvFNqy^o`Z`D51FI=lHEVl=&= z>;%~Q!qzle>jHTjvt`TR`ZIakn7n}9i9jl_5UpX{Fhw=9CXkYTV7bdcy3Ni$Gm@qO zZtV6}KDx!h61v|rJ_ya%#zQ+utv zg1h9WW6aDwoNpY!&mDsL9#UvqLw-^wiMrHpomRtgWh4zPJ+V3|CVEz>8ZrnUisWPb z4*)&UT~X};{s=$35$c-zEKpNJ;0hGIT)?Zyw}#zyz56ZU2X$Jg!01rGq_$azuM-xm z;k<>xiaNwMaPUGk?Fb4nM0iuxuo5HUyrkfwVWaU+7UB`JVz56ii+J}K{=?n}fZr=U z@U9R9!0le_nIgBB{*K$MOcPRy3SSYZ7G2{5xCpm`jg^&{lD_6btZh;W@|0Sg!-8ok*u@p z-o;nbEw;ZdyvWvlD<1AU7lpww*O6e6sQbLQ)a!nYd!Gkpc)i>il{ZvvSajm4vbx;u z=hwZQE$7#CZCo|1daf_EEG%?5+Ky~A9KMd0z)d*8xjvVGJ^!=-IJux`aB8(8sGVH4 zRewdJwC}Fr0(-4Cdy_x@psnM9@@-Bey0+Q;5M9E(^nJzFxdv&fI*Qqz@Og?=%9-|K zHzIsbw5e_nHZvSkV;N*jQ>TZZyYBd2aEywghhU_EWL_O+0|e~A)t)zIYy@rbWmn+W zNGlNLTWHw+J?gu2&DX3HQ9*~+dmE)rT1}k!(!KB?Nop{BLdJzv|L zRBvghEKy%okA^L5nVC?NqJp{zIZ*$>LhB!;T!z5T&KJlld`T0;fi6vL={ zBFZg8FQxGhTP-Rc;Ek!5fc=}}xNF%f=?W#)q@HEcM4+j^>LWKjS97&k!~7$v-P5kI z{X-}-7ndGTnSF-;mf8;>AnI@68w6&Yv|^__{c6~tu~p#EJjcF;wgQVnIKgFUxx;y9 zG9yt9IbjO}CXpz*0k;IbOWca=J)s8%Uj8yOK~LF3Q?kt*V|g26p(BIBl2eW-f*V$S z&F7X+Art9{>Et&JucUHn`Ug3Nf}qcyzo&>{!Q+qkhE`mN0j*(Oj@wgsz=r4dpk#K?iwk=e-J%onUfRHX@5qghUZoJA?H#J;fLo z`n-AjqruDD&iMKme5ayUw+nUXtyTNc(o=jic+h_P8oT#&8~3#Pi{`-ZH26kxfJE{>^uEFww zJ{8D5Tw|j&VmQ}w+20DMm)8+qjb2dv)kb$HrvR7$`Bo$gY>9&H(x}fn0|}(P<~j}Y zJsJcH>(`nb5G7t5AS&&9<;<)-xpeu;`sBK=HtllFjSVSZ)g-*X+|zp{fjASDWf#m6gbm{wfDtc?}E z?cCKv5^x7icp0GV3X+k8eJ(_Zk!QZmIH=pJa31EV8``q__?>@xE}rC4-5h9;S#2BSa13R$P1sjLYnHUr_;7mY z3HW<{ykmCJ-Vt3FfiM=JIeN%kFAvniL1Q62i7oDmV{gnKm!1Z#2_yI8zOYr>_8Njw z;chByf$DK>Zz|0FD zN_GQr%-ydt(*nq&*KvJK>E`7g8}|V2K9iDVHd$eoH@hIWY3{$eeYcWB&goz3eSlb( zcD-3zb@op}-q1MCFOt5Wnh{?7lF$+i@kJ(u-3C#vr=coiZh|9?I_=l|T5ejr5gR8Z zb@=tGHRr)PsJuJ3@Qd`0Sx1#7bIGi2XCbWhH*;wcjljGdCw)HoQ7=H*O%ke&m#$1? zt1%uTwvJ^V9~+>itS@=@xR|zdocJESr-AjBBK)-0#=5_oO`-4rH&cI#t+_>qYg(z6 zoze)%>cAS&5cDfvhv%tJd^ z&y$Z(yXMu)Ml>P|2NLQlH&(1cxAKTXG^LNMzH{cT*!WK^4&dqTUAI@&ijhEkWu5Uqd{9u zfwStxUF|vk%?92adOKh}--K|QxYP}Ke`iXEt@{@2q4+(2qDTJOR;r2hI9n9kPda?1 z?4WL50rT1w)?aX4E_wS}X#Bm@tGW5Hjt_qJ-|;zo4a6Mnt^5d6t>R*a?6twT0NX*g z~7WHb{>qm1#KHm2DBNBBN61lp_7)a*ecBQC+9h$mE3;IxNSwsIf&Xt@0 zLH$@EtQ7|5=HJBygo9@vMww_6#8_4cafVNOu%zp{AD{_gu=5sCq~z=qa6?921K82N zbwTfiyD9CpeC~JV?PIIGIo->QM2frZHL=WZEH&R5fve^C67j*}({A!h*)B*@Hbeuet9N9yf5VOA!=;U{E@ z>R}U)QOdw@S3x>G%+`+V#2H?9d`_3wzSRRUQrNSc)1>qRCS*|3Z%~`O@F9#Mp7^YE zfizl|?BqnI5XFMY>cFlt^fAOP>kXq#sGZ0iavcYyL;ycRD1t5s+*gv@FYGoS*eo`I z9hq5gB<@G3**7}<6B&9tB&RK4tz~u3oF_fAuijl;y~bC)oN=vBj>w+|>*4t?My)1* zl53=pKpm03{u*agdS{XQxB3ezYHaoEtvgG8$fW$={^|di2#0VWSRz3M0Ptt{-=Wsh z|L5(j|DSxMo%^PSUMyBCg6~Qx`YA4DdxI65Ks@AX!T6gtmW0({iY0JJz1Y=1$)V~o zm{3pGimMx4==Pts&iQN@U=Rnm1o7|J13Px6tUVLa8-kd|`4rFt^uwOnkpOu~ErViJ z=5%H6jB~wbdGY3K>3?~|LD|j2jN>GfonAenV3Sng z?B&AagGE^E0iDP#AOuMTx?$OYiha?j+@8M<$iyVJ@liApdKRByA|C1Q#*Q2?Y=I53 z%!}#mgO;M)zBVo*UrW{Gd@b{Y;3FNjA8B`+=UPL5<;>f40EqUd2}+DZJ+0L1P_r#k znl}q+uYwuYndy}zv;%z*gSxc46G7EA(__Pqk9RziE6vHE;}?th-3 z(fxF1003;7&^^65P3K>GZn(&jCK96w>%0YM_%tIkDIBw!o~zI-amanf(&H61;1Qf- ztcFr-d_5Y`=Q=qAvo3G%hDaN!-rMh!Q$DEoOI5@34pL7x*E#aFEf}luFSn(nDpFo( zW@?kE5&uM5qn*tYqen8ch*OJd9KQNjY4~kSnzf39z>wf3){T4&ubrq`h3H_eOpYdv zUsYVB_G?Srv0$c4NUPP&afX8DglBbN3q_gvl?frQ9JgZDSLu%5eK|H)W&Z(hJ`XCi;F>PkP)SVavn8 zI%3=J>jy$Oy1mM+XoF_6H5o0Qh@m$2b{#p{Sx^ax%=JNQMK zU&AiDT=vmkXj+Aivn%F(*Fhi+CMi!&{T)}eD>2Gu^pNJ%zy-^i9u?qLwn-$+MGE4h z99S#Xn^ChPEy|D&whm1rIh@}uLh%KEfzE0Rc5QE%jHeZH@5pYJEn_Kl3YLa^V!3G3l0xp48%`1^w zOeEqA{V9_zpfu~P16e6BXEE3~nbVn#_qfP|5ImdA!NmiY>ICrPInZV)`TBIzsKk<> zCWRr(g^0jwZtV(X-e>cxL6wy;*>>8YQ3wTAd@U7sG?6{m&ujElR3FE z2FSHn1BHprg6k(bVZ&ERNTn!&T8*Rv{-cq8B8@(Ea>x*1^)Ic>0J7|5j^P7O|%Qe`|uO3&2|!iZn9by2}h~lor(zmY{Ts|1TH) zet!qh`rW0Es`t!CXqk|sQ5r0VdkDgtgvCEqaN_CU!&GJ z_7U{NGJ+you+S^2b$2D}@yled%8Ggj&3+1y?_qCCM#R7cBw($<3f6*EZ(Hs(S1MU(yOG+-N~w;`t6uON2&SjGYP@oN z6O}!&jar6m>5Z$oEA7_6zmPx07sw9&ibQFDVJ0TL= zfScK+2RwI4katSB+PaMAJ}uI8bph$@-P@6}w^z?sO`K9wVVp%M;`Q|sjy4vzkS4EV zIQOR3RMfIdnN{dMpC%H33G44MHLzG<^dAW7rp?Ykh-11Xi<`aq};@Eh>wEI=uiftQ}dls zU`2oj>cp{Kyps$Nc(iC?vp~`-c1*@O4ys(pYda-N$>h2vJH&EXIN|Ubjo@$}_992) zTVX12+5Yh#wzGM=Us4~xx<92YULsMdcO&Q1NFtRxWhaLcBeL604q7zSip?Gif;C+?B zdXKSSCTM1>f&jfJj(fM?$e{;EY<%#8Al#%c@Q}1ILn14Oe?~T$3xD@xtc_lGNmtNh z42YYIKJK(V(g?u5xPM-eod3rBQ9Y=iIyH>8RJ4{=+qxtp?9%Fz zLRID!b55z8fgGpiy??P_DSuAIoiO^dVHxu4Tt6J(d`pEwUpoUP0)$?bsG&&*3^CV* z`4(YR(IZ0(^Xga80Y(`I5|nn|9MD22@ z9i4etIgk6~JIxPy#Xu={qC28dm#HuZ&7?DA2ln2B@GW4efSJKy6g*FbV%`C$ayr%$ zi=TLF{%okip>j4+p#|o^Z$ojwKLyT`cOmJlV`Tr!KTNJvPEe~Rs5+@f`7O#BX`D7a zG*>scGAKFk#uxe8O=p{^gSKeyTHq;ZAf~Hub7L9pPAw#~FPPzkViX{#Iq<2^-MKR_mG+YN6}==OSASAO;ezJ+L~3Tv+t8`rI}FxnJ{R`?wB4%@^` z%H12%=eo4eNY~M&t$f(OevZ>70_ad9I7S>0ESw7-md5xp0#j%0%vrN(ckjG{;zh}K za(2DAh`;oHOQ-)7-@z^}t-bp-+hh7=5B>MdA&vj@QtQ8T{q_D|?HxT=TL()M2U-iq zEHypb4OaNyx~uI-LKKJO?~A;;yg%zx9kjI$I|V&HIHV}2hLs5;iJU~#;*R$&UU*Xj z^Y*7|Q9WC%(D=`1G=9c&B%7U;Z{sCk|~YNfOi%(*}22Wp3#Bzc_Jb zWp#%F%H9_x2_of@n*>8b!n=W?xyd=UCd%Fu&#f+FR93vvK)&~}0E?Acz9RBs}wu&z&59$*>a>NmMp+b0ZmvWev%Kn=G zxj^ndspKaLSdBYkM(!@<*a=oDw?>>OBca2OYXuux`s&^RA%Pn0YpK7XBuF=J>p zRtWJm5MypzSR$YABcBW5@pNAeuERjDjSd4*zL@; zJXh|538zSPn@-UJ+l@*diy1Tm3k}1fma&_{gx^Ir1AuEkxrndUcf^0vtQ^O=V1urP zf6+fQHEBjJZoha&d|dW@Te2YI@wYB@R86V!@c!`JVlk069JaCT`#9H*E5r25kTc6% z3bIi@eghoPUgfcK!;5TJw%k2l;E!)M9j{3SG8&cAVIWUnbN>Wc7<1W1KQL_cED<73 zvllUY**i-hE>3@jx0rtX&Nw@KA?jv$lc$F8U02G|NY`S@Gk$i^7;MT^!RVSDrgpl> zg`Lfr6=-%@-7#P#xe*W4)b6Xo2(`%zMBVbUqfhKy{fDnU_}N33>5Yl?h2|VLv${-~ zA7+gKi2@Ldq)R1en)Me}`M8`SIm~s863}-y7PBV1rIvfCb?O%V@H(p22c@t~j7zQu z@aGCy-;XE2CC7Iz-ghtUCQrl5;;t{RcZhz=xJyE3uLda>UUudgkX=7SB}UvieALu` znH@;Qw5`_x|LQsXvWfotu=&fz1h8{=GPkv%v-)dD_n)^+vPSDgCvrB2o=v?(uV}D z3dp{~VWt#x;vD6zfNKeIc(nm{r--K*sq4$SK>C~47q?5k1X<)wTneBgd1{x;S$8My zUIKU$+@Q=3#C-@5j^Uh`*8iFt>lEY*>&HStg)v4KXib6WVZuITP_9xa^Rw@w(QL%= zzarYK2=Ct)Cmr5es3DUJKoP|l4Xxh_tXHxRk?j?aL(Gbd1lQ3?!de8X($wG=RA8yM z{KPEg{O(Nza6=gQhXGXm^ud#Wlu{V2R@E)*JSNbP1FHdtFUQb7&(|-lnyGBC`q0e7 z$f{+{0!&kvD**lAZTz{vd&lm0TmJMs8`VoFs*W7bWS_M%K zg$*paLXeKF5Tg-1ur_P|_JkDIp$5^6S9N1-9V1qUM3rzXCDG?;9Sj?(Up66aa!w57 zA)V-q6IO$g4OGqe~&{FG-iZOy^_(V1N(X@*dUStt4U@|T{ zlFwc4%TIr!GDJ%&H_9fO49ngSo2IM5!T$?xA+0DF<0~w9Z&3)~lHNp|m`@N7ZW!>k z^=)^437Zq4R0z+WQc%$cF)71N;!Rq{-5l8Ze^@)G_R7L`S$AyPNyqHi>e#kzvt!$~ zZDYo^?U{6JTf6tc`p(w6u8sFEjFTGmRMiax&NfB0-ADE6>3yZ`>L(*u8h;yqk&iBf(tq!Eqw9ZEVy=tD z6e*(5|2*)rTGd`KeGw&97c0ULX0Q;8-D`fLXydHAM!61UOQ(TQ=LA1i`{`Bh-hxBj zFwFh6u24m;Tca=#t6ZD#%Mk`^m7`5TiVj=1#+3kX;RF)}T6q9s7{+sdV*YLM)fV;o-Z^SHj^;Oo*@pEIrRorNbVZ1T%;MpWZlf5x+F($u@%rj?b8X;Hn z*Yw9>yJABaTThPVM4shH`CdCHr?h<8GMg-Az zOp2K`)vnuG43L`=SO+syW(4w6)7!ed@dl39sp>d*wet*ygyGuS%s1-XKqccI+7vBV z<0UBz8_%>9mxI2ONK@(yiFyh@rLES54_q@6Pq-e{9$I3rOqn~*{qa`i;gc;e2s}9g zIEPwdLrqg+WgFYk@fJxtSDcn<9M$Wxc@I{Ti$E{^B{H+M>=2Vk)ucwB+VwUFA-S#t zZ|tK>rU!onj7`x}=sZZd2$9YHdwZi&O{7VfYCn1hxQLZ4d}@l|QkdQhybt8AxUF$i zHD`i_1`qHCI=&v0!xcR2Cd*UDx<)k@+5L0C8by*4gt?thqoxg7$>*023fbRhFhvYk zEb2-X@3$2+q5DheqZ$a85*iE5ohl+RO;w2S0UM%pYknyU$@p&y%0ArVp}mUeg+$75 z^!{+$gLXf5i`V-lokM<)Lfb%uZX01!)Mxco=M!ysY0v$vpHdKkCLpB`S-93&ljFX9 zu(t6CF9VZ%wq?cLX>|;n+bM9h1Yfa~o1t1(k%+_ZUKWXIPE!#88E;TDrXG5~9%Y8l zWS%gJ(Pc!7nqE2%cO#m3L~*t*^v*|=EFajxSXZ|8Ca>J6sZf+rT%#~7T{jA!1Gb4-w8!M>a!p~pe$id0my5KSAPC3#+z0i zwul{nZ6_ZPO!h8Z&5}o1RfRceLHDxT+QH;ge$irjw(UFK8}~&j^C1HLhVm-3+Lhu8 zdVS1dLPy>H&6z^AX?sWV=%*M7!V9KYtn@AP>u zKSZ`hp_BsEjkyKsfzfg^9Z>tQp(31284wg5KqBATj&XM*=$NO%F;s2}V%6rrYSt}7 zT(gqsYf$BFz2(><(DJ9UL97B()5C(=AiP5UcoFisX>T+s?kzcnRL)Genfn5M;7?1N z+FQvUp7GrBA$GE?6=xccvu!gU14WHnTLkm6D0TZe*40G(rrdWOdkOADJ0L<0?%%Ao zRF{#F;h?Ysb6)5scHZcA;e&NGQVGD(NGUb?sMYeh`V@Nvm|29&=8esktYlL$@NazS z0>rdYarwD=S2hCb2|%r~83*;CW=r?N(;{`lq`+C*q9+F{=Z@e7(^?#md80E?hGI9F zygP>fW=$7Qn=}t9{%#kLOz!lqMOmf@bY`zSLx9<7X0CoH3)p63cK&#ZF{aFDib3M& zEvpT?#DyTT^OfJgWQ`1!zDhpyKZm&N(zAV8rIN55ea!76cnO(gU-}7?J zbJBjAnl6~F-%8-VNzWPKHy(`H4ck-mU(4YmY$Grtd7tai59}BccFhWnkws7S=Ur{u zgS9^kJ;j3PqK~n~i#pgBv?|(d?{GQh;&1SHDb()_brpCVG?(2wO;BGSAG5!FU!VQ( zS`vaPU5XZ@owqfICjJIqf^F67u(8Vnd>!#U;D3qP#+{lxfpC=Fy9r1V{B3xzIOo{x$rKgR4AnsE12T#^ut-1@=tSr z2iFPuvq;RR(>C4#Ev?w|<5@)DYuxfg>m5!aop;VcO|H7obJnfh_%P#*CRNLGZsYwA ziYb4_d5KHWNwocoto`0CJ$(cWRiL`UD|@jIk&Mn=&f4=psSWP( zK3XmqhqvLyEQRxmDe;tI!4=zvxt7=5e%%*cFH9O^Lil!6|jaRtg9MZ zi@dKFneuv82>A?R=@gahXzm+!@hf1XPnGWyYYK&D88hid_4H`jTFp@2JLi|(MW4F+ z@sB_NoB8D`QII1wJjAG=)`WoOh?@EVqXKrfygERxtMu9V)l)*uLIO!;2zdEGxk>n4 z97JgA=AEbiWxc&0aT!C|#_mZ$BnB)xp0icr&8S2A$i;KZ?rs0_?}Y?I9AqK18sI&v zro2v|;tukTdF=*}Jlm=CO$TwA1+!{89{^Vra_NiLXp`4d6>kcr1@=&o%g{^O&vT->cKu%yf zkIF7ojM=RUb`0W+_MGZ6!8h@bj#F7}bwZrH#8ob^r$06#rhB_*oTuzd%oi4zwO>ys zKI;8c-L0T+;d7<*#m;AL!FpN!;hEv@=>l|gz15tW0ZySi zD|*?p=m%4yh_vx{>QOiG7a9NUAsf>{)D)J&q4~MM%N9s2RWt@$WwChVMmsR-)=Q~x=^aH=07V-o!N5dmlDdzD+*T=C@+UhhkQo$wz<1sXRRyb zvB~fCdK6*LPC9ZR)Qvx19(TUdI zJ`nqCgo>nniS|x&nJQT#|8Ak!x9(R$yfL9w+L_PX4gY{~n0m@J5!*)wA zsY{F|KB8HAw5u+q6{oo2CA9yD<3UVq{voQKjS1zoFQ#bn-7^tWLC{S(xL_A=?2fex zPvil%X4*DG3KilAbMyV5wkP+k9tQM304vKs1n7TnK1lw*n-Blh@cd_7#Q)>3G9nLM zdq(n6?9O_d2T4;;x6qTPAxExB(EgkwQrE&zdb<&AOlobu?QbmxT9}O%pZu0mZYN7b ztO=lXx{2M095X*wj(;Tc3a{JB&6t|4H`a4~2*M(XAxy0Li;MQa?YTL@J?@!@ zWav`#*9IOtf0YSk>5WWX2s0Ask3KY_B0^$ktMkOIRilAmex&@GzdlDx%Sl)-{$beA zBTtsQBxj2^^nFBQ2@1+@KI@!uZ3`y#oT-o)qb|6#t#(qaxkh^+(NSZJ1K+JRlA_z5 z2C%$+Bw|pcHp(OoKOmVKvUAikvQLTg%h(N|>`x{>dPDs<=ufvKeQ36SWjw1c(Pq;X zHC;Drt**&_Emo}5zvx&VWGW9E+R)tM{FkLZrL<{5^$&!}{;!4i-+!L}4}9GJ^z0lw z{@u_2cXr|Xn}1j^tWPOlJ8xF*96A;6*l2VWvcXXQO%VA)v6GbEm;pczpsbSZ^ z?%z(i4rCXkCBBW|`EcaC&RABfLS1mt-qbSA1pP%@LeEH@Vwy^8DJM6uF)Jo%0IBp= zq=|0Tw(qp+-4Yhr!?h$M8AVjHn+3^Moh;KxU?rczGRfQ@{d+OKMLM^zzEz63UvVS! z@8jd+W*QMob-3_fYOR~icB}GUehpT2`&5U=BWtspAp!YB@GOGMdG)(gnA~2m)FQnB zwqJ_NPbDi-ZJn%{Qj$URyetyOy>RFBhPD6+RxKY33E+I%jm|#Mn)Nb8FO_1ktC0%$ z3Pnljjdzft^L=?a`Ed6*IVqs)^L=>+{v)4@Y@0F2vb1<;O47J*+4S9Hy|()rQ(i83 zqrYR`xKa2$XX8>~c2T7fb~nD4E6atT-(ojHl<-|g<@JImUefcV|YMvv6}ce z<8xl48{GI&{%T$9Ficee{sR&6cmL)U7n7P{gKqPH^PQM56(O7{ zLxj5Y6XDh322o};c$cRp!iLmf%E|Dp&0TQUSWSv>aNiI~R3b?R^+B(;5V+)ihnf$HwpUWD|3;;6y$3mCHJNe@V z%&fV@WDB?yc`&CWvvT_V#^unW_sWGzAzP%Hwk550FieN1F7u-tCadO_)Epo1e66UV z{FZWYg~@_h&I@c;3p?@lbD0|BJ9X~$gsg|?m$7y9O|Hx<11z9G4DJ*7*o`e!8UIb= zYir~#C7Bzny`7?UF6kQRyBb2*aBv`wK|a$lE{oJ|#^n7t71^IVHW7R@_Yo_TL*hT6 zv^8+Ax(6LE|B$1-+KAOY5O|UDihrCXu7pT{K2fM_O;X<{r~?a7zn{PJI^Ji@nx3w) z>aCypcFcdQ(GY<5-@Sr%agg1BGE;zG0FdiZXx@LcG}S(2B4@Y0@^-5jTmu~_XQ6eToh-4fO~1FNukgq?`1aX2Ht+tK%> zdWzcLa|T--*@ur@Vn^)gAf2T{QeQ!zd@*-{ZUIl?EZn6gqn*1PXz3Wf3;yl@_s2UZ z`BJEnV(ElbQ9-=iDA^GIj?$q>m$BwL*vpSo&X_qelmSREH01>x4Y}q|D>w!_PZUP$ zQ&!X@-~qM+Ox#%!esXlPa2^!MGrVc36N5XFP^lyZy^X#@z|~Yb3MCLZIj5vyp;pr} zEVMVamqG3)dXK9h6RQs*en^_#19V6~)2$fk`yAI9l{npI{%(#TdLYmDW#8vlkNtB@ z_EjP~nIg&o87edDa>~6Xse?TKd4#_`l!i&T(mDw3L&Fzmn%$f?;meOia*=? z2aZl4r32CS)bS}T^miz!-k{0dAAT8bVK;Nk zN#4vm!Oj{lTi~-^vQ!U&@2r77=HfkEo!5yoZn=w&Lsz5h;eL&m5!bz%n=u8=LSki!XyBt@K5Bg>N|sc5$Q{&?M1eVax z?s{t#Gnq*Ly%{s0$Z>Z0KuK0^r(=BIohqbOh~dyvF4sD^1L4x7IKvMB#BayJHrVM( z+?w*Pul|cfjiVCg2}G2Xv+{Bagqfd*f8pq4=OLZ`b$~u+o6_s`zLhmck6L~ppY6nJ zm0VgE!t>T;u!#5z>8wLLOt8QGZvctfj51{epFO={gV?5d18>Q&6NKXFVlE^(+H@G1 zb?K|1zZiXYB6pd98#-o7Av?&17w?A9A2!DOM{hYu@#|goU6&)>&A$K!rZZ1f|X%W@P5<-QqnO zYL2hv<*O$RYmQJY6(?uYqbfC;EE%q%_y`{^BWs>-13P17sT*EYl6_qHfkn)McdTWj z3DNQ5>`ZoQ#Pl%g45dc~k)r)M{XW>LLl5yR>4l`2_#=6{!;Q^WK5L#btdokqlC+>- zI;b<&L;DuJ&)_2D#~d?Z+I(`*>}VTOEiL=@FZ*IRe#o?!bnK^wx6A@PXHSfpH5hr`=Hz|uVUM7B?nJB%$u6@Qi z!DU@uT(*!w41Bo(GnNW1ekOB43D3&<8^~CG3qfm35wUzKcR7ic;A-xZy0`mz*%x00 ztc{+POH<3*+u(1#D!acmF7_oHPH{7EnK9B!h-8vg8*cxo_K?a;e|EO_P`&|XI=+cs zQ1cpj+5|{g<4YZ%`<2yElu7Crgl+Pp2ts)))SQvVc8uFiPkFL_W4JQ6As0Eoyfp71 zNH+7pZ&KEFhKG=bmGkrSww%q5g|o|kOsT+)kLZlc>A+e6KudK@iQe|K10#}i1yQYj z4xcWn-Ez}?mU|t;-YFKA{=j=aplqDIpigsSN$=ho6K+(_cg3EqkVt=2MddT^)6MRec=F200 z<)Z?1evF}qOH(DC>;?mGHx`Ym^|j=&O#oDUV@MIxu-vM(gI$82g)VMbJm&bEFKDxD z>KJq=wW;kt$#U$)cVLmLi+QbX-E1mrVxR-pcd{QvJHwgsj;HS$1XAX|LQ+1d_Ix7o zM0%0+vRC6r~NFjxdn>-VOJYgFNb8 zv!e~dd-fvMhp2f;0-U4RX%o-p{4_7RP+4;mE|p#?T9Cc(vF$RBWVD*Vi$2DL%Re*v zw9)w?G+$o3esB>NlPWYC@5Jq ze@3bIB})AfV6#fkZ^|C40+En)5;RUf`im^jKnhuu$~gu6i^l>s*nDah?^6h9@QjTb zhOYQEQ6w>6r!JKE#&1<%K6so`0J(AVbr{iEB^9wzlw_UcX#3G4(4F=k>lRvBqfRT&+J|=RG3a>B zrfVJDR*tk11K4cK3W~KlV-s2=+vYf7%>&A~f0K73kiA|1CmrL$WA{@T?#B-j%Ku5q z3;tjJX*qb>Q4wY#?*gyKqXnEV=rQ&w!=NXMutMr+aI zp;?B`woI%K?E~+NH!=b?=@$gN9w;o-I;#S>J8Te`V!p(RIzc*C&mo9R6U(5TD~MNh z=!iG<%&1BioeglYx3c98NB%;gOG0x<*BTz0*`z~;P}gQKG7bV%u+zx{*=5LN$m8!a zjI7|EpS8-KpNDyK%rjIV(bDx~LK!C!paCFFCXnneo-y%M8K&vrgo%GTH!@4m9q_++ z>RD@`-*4Gyrc34^+@kQB;di>2*ir$IBqS+D0kG&JPAx(S26soY*x+PYf-bVaZhS9xgIoie8sx>M5;YAC7!yVyK(qa50(=oJJpr=z@Uj>N-zk^S;v4v1gXC7Qlw=;~*lClf&n+6P!!3PqV zATpta&{UVI$(@wWR9j`#N5Tq+n+8HPsf-{Mp-iRgL4y3~>lHeRcCQbNHYcA^B0>Q4 z(NI9!k=3u=u(3ch(F`8*mL8LjAnDMBA~&%jh~4W96}^AYsAk@+Z!)G1Q1Qb_Z;@aL z7}@+}h>qr6>TViUJ1XhbTmd`Ya>F-k-vw2hN({8Ox2u)lDvx=J8l*7~jh6`MgJ3-W z+%m|vCRP8i|Kmr*X^tPL(g)Aj0AZP0-gko`Bq|Lu*|;P%TH+AgqF?y@3^DpVNPLI{ z{jbxRe2IRsWV_@hg7h?~-YoT0SqA>`6XFSq6^Y1r3SK6BBtuC_HJGK8?G`5`U96s! zVzJ1+XWfRK4OEF9y8a3R!^Vg8Ad$ExN(C9tF7=fz`tU3(j3~)|%+F>BZfru4byl{P zF%s64k))W!_MG^}*ta3Xt-qg^aT8v=4@-!q%as@kP+v5jBfRON8Fp~X5%!G&Uh?I> zD+H(T!w=QepVy0(%0^?8WI9?A3T6gSAN+j!uFAn&Yq+=F)PH$B>VQue62{6Qm$8y_ z|86c4E6s#`$w+Y!FaUn+P9KEzCUa=iKV0}?#WyXGX=|n*@6=A$d^=k6n-AbJs5OFQ z5vl%#xA;XJsk{wgo|ZBd!{LRU+GGC*7u@@bI*da=Cr7jln49zE;dEP;SptjY&_QG7 zXD|DdEe`%0y@566C-$IiopJv|=-i-qk%rAr>1zC5xIp!r1k+du0a&pCRh(~Qz(o39 z6FP};WX)VYw?-4II00mWzKCK2Q!Mdb1K@A~J^;=c%J_w6++rD7YwYIi?e6IA;f}Y1 zD=+pe*Zy0Vs5gc`ciY?R)%PWu<4PPiCs%%k!OoY&4iEQCV^v%>m{nyL&X)r1S4M02 zn^u|d37fgNcsB@RLb4#6iSUUBc3eG&LvBM6a8tLnkhJPhcLi2w*4ga?bSAbpv}xaN zCRTbTP$G-$uxV_JTZkW+8f!eCo2v^H!Aiq2mqqh-cjJ4#0qe$QH~dv+N0Ej_d7N{j zZf?Fx|8m~+{l*I5_v*#U?eklHd>R}-;LY?7XJCL~Y<#H}NWR0?gw~X7CF}<~%t8{@ z*n|eCBav{lFMRgTx|QtEp;VLlA=!a|DofzZOId-rg~_$KJS;z;EQ_SAKHRvOq_IXD29yrUTd{ZwbK>{OlM`Fo z6E(-kh4tqXpQdfxCqu_mv6YJb%ENb+74Ut1*pEH^rIZNex|o$)xHwjJFg&q=r&RO2 zlP%xtY_K;vK76oW7B~N}xV(J$7~^^*M~m1=;Z@_e7i@MeBwh(^CEG>BN@ z5OhRzhLB+{dvX|5RUi^v+YlWgkXXV2F{gwW|AUaBSTHU1fnVy@e={gLDy*k(VL2e1h80w|l{=^y- zvv5!~3!wq$CKacmy&g45U{DQmT6;;doP_dktR?+^aaQS!AJV8YHb$!!?=hp|d-I=u z3p%Z4yr!)t`=BP7`7}If!IhnC$VQ4@=Y=11RgRZ*6UU}{%H6m^_5l<$=Hkv3KWQ$! zgctt)Xs@kU^hMvtJ+BF-X-}G}JKySNz^xKh(sqIEf6L!fs!z_cg`TrE0w`*aHH8>O z&)2tHX`Tf(PsV#WJrh{A5Y=w>ij+?hkg?cb+?eGc`E9u!xi->)%p!~T5srd2!D?d6} zxJ!&XF5VelPwIQt0->h>a~uj)fxz}ShKgOdfQAoahJdlls%JLZ>Gca zjncKKWlF35+_+(lsF~IBh!h5GP367qR4qNA8&+MTPDc85by9RtvoqF4gm=vx;{0XN zma@5%RnHNux7KML7yu`hnxKGJ8r^!T4xGln7}!9}0@ zJ59ge`QZz}){+na^?UTb~7TjRd{t1dgrK@B|?QF86!Zex5=wT zsD|2Hfmy#Dj4lcZ-x33JzLVojvpZ23k{;D|8?9jlU7JTzNhM|~)=V(ZEd^k2qnK6dS{6gNeCz167P}Cb zcQP&9v8qMf2wgE;-GW5&`-0jSb~aEIeBRmVvrg#4mZ}vZ#S`cGbSnFft~U$>1!luV zax(G({FxJA_Cy3&)0z_ErMO`ZAm6sSRtVR#ErTX%*+43iGp@S<@w?Rv8VU@(cLOA|KhNhtqOhxgJMY6cynyRpIcb$7Yv_>LAf~(cQ{ar z)(4Rp}T!a$U+q(kJfBICZBu$968%jAeSd=JW zP`c%{RncNWVytLX5HY+9##p06Cb_YzqBk{fPwDoYdOt;ol)33_35^~(cV?bF`1}^h zwO`a|)}mPXmVFM5Ib}&EjQY)QTvJwWV8aF?Bb&TP%ae}pq9tpZ5D>5Un00KlPj?m48-Oru(C`)_j>C43< z7`siBdLvCgjtZiUKH>hE9AkxImQ8rwe6Q{28KrEcBfjSga|CC~`V+CS3vJX-XB3P9pnobLa$fg} z`a~3F1ok*Vc(kNeg2Q$Em_EZ7DQxGjP3Uc56YXN}X?!!)>-d3kXsTvx;l$+{gD!sYbTbn| z5XrT|aYGIB9Vn%THXW-}6kk^=G%=J0kUS83fKqGZZar^WY#Mhrzb-m$%d^|j_w9KR zhkil-H$cOxnEpDJKUeXpZRff!SoDf;Vt_ghKewnYN)#uD< zz)}{$Sk_~wRh?6J~~UtzlA3o6HZFCLQ~-Ol&qpZUv?@8sV_I@cWw+1fW>o6tuUCZ(i& zrxGz%5+6Vf!)3aqlIQZu;pLg{rrmf=MKm*eRAN%Z&Sh6*ap3 zRgG^owb=0nE}N0KTeW+-6hiLqJYf=FL#@{G3|`AUor`ssnEZun>p5Cp7ahbqDJvc( zt`!|OY)H9-WcsEED_YkAGBdL$V(;S*e=Q`oc&!`qMenW=_&s}Ofq1`rf!D)MEs1{v zYwC~Z!iHhMM@j{t<$pm6zt18nT4#aTIk>Jye37vQyDT{t{#H`?jL)NWzb)%Yv9>Pi zcphqvNMU78J#@7cKk-n7i0M&kH$viUQ*_cf-%=@(2U`8oQoW24lk@-kVFGFcQGKBd zpmwhKfH8MebN0J72Lgk#UrFV7R10Q`=h(|p_%kch=cpg~VGyt&m$Qd8Ty}YUr_^uN zm59BU@Z^+j6PA3-<{YQApC-3F8Ds>pT%JXTL7_(oIJTnF+%F}p2(_QL_>MmzXMS5} zKHU12X^N&bRhhZ*U8pp<+re~NkIrsC*ce;t6JL%j^a!3Le}u`bZ>`%%r+6jk&B@Ug zKc|0iOpqwL{>AH%zLw9dD_uNOsrIb83}lLfP(d+wKXh=vE=rNPvDAFpx$C9Z9c)Rn zhKAw?|0-Z#!|a+Cr0!~g-xl8VO@_GwZcP`7o}NBEe|7Dq&g~!+?9SEJ;6xEY#{4Cg za+tYmP9`-r1GG7>ALKim!Ff$Jkyri;({7e`#VBsgtXal8$qF2yGd+EhNhxTr7y3c$ z|E=g^Qoy%$cfQIe?QFq1vGy)YBo9$=A(J6o7F4yKX2Hu7Z#kD{EERA?uF5nQwDNGp zQfN!XzkOSmlopt>r@ktv$uYk!NHwYcA)iq2Z2WzrYU1WJI$^Z^y7h z=GW{ml0843HTQN%dAEk%a)((6-MwO3C_0cLCvMYnBCxBvlL&P<++pdFVZBiiQ>oSJ zP$Gx->OnJ^^B9$Jz5KL;uM{Wem`9Pt1_DinH;5#jBU+6=8~*$uwGdH8J9BB}+p6vn zK05rqDT|nSW-cVjlIXK<)Y{XikoJX&lIAzTiOiw`(tdq4i?MAO5)hq{ZzcRM6{kVd zc>^pAxi-|IbkiakZ)a+RrQ)?#m7=emh-uXQhVX4m8U^3jIP*ik?7??OSlbF<43&~8 z7`Wr&hQX1)w|^b;=A~dUZ;-9$9b9S~JYD7*tEpJ4Bpku8pHIS)B`B^FMi+;BE6zJ& zOGE3s*=ZN)7N^J5xLqqCp@0t$N9hK=ju!4rsEuLi4 zZEkcc`Hl*!k*F2O?&0x%MlAh`2fW#$0!7C}lw1!^ut0RgdGA;6-so@Ch%L;p>DOvy zz}!@&$^DE??4Lm7G7i!ymR~F^Vrelpvmt+bMY_jIWU0aJMQxO0YHwe@$$s?|CLqak z+?#&vdhbu-74XGSj~oG7`MiHyKfLBz&^H|x5& z&f~O-=hX^o_c7YZ+xPdjQ`lNwigH`XQM=6HZ_odR$}#kMz#(7_s6o`q=B)zzMyoMX zJnQ1ZjFZ=QC^Vzi6>|eBR!B$~0dOT4n-0~uj?l5z=PtyzKQXBn6%qPKgKn`AgT7(@ zD@QR%GC7Zg@#Dw(zo^82pQGUYzcgQ+?TxLS{~52%n%nkx02Du9uMx38w#nG}(+n4S z6qQ9h5-Sx06V360Fmm_2e6FMU?)zLD4;Vc)gmJH3{tWs%1sDRZ5*!}XJs@Chks$kI)2G&NNrdSiQ+a@qP zH)^dBbKI%LkvD5NPPU5`m1yEmlNqv%n?6PQye|pQ0jtoc9ne=3P?(zGO5^CI1LmY% z2+0s*D%AJrSk*WSsls6@ZC5CUwt#9AQNM{(xOpkjW9EpyoxHX-{G8IqCp9S{SH^dX z(Sn?x(Iu?Z)_@6X(z;?{^v5^=rl^o42~~)oy~`RL{EjS=fm{E=?O@JW%evvU-_m_J zadMI~*1c0znp2vC#Op8pa=SX_-r?pY{$|o0dY%Ff8s)#y&}#&%@h1x^BLya7M5*Hu z(+FF>GvY$3*xxi!lBgi@W$hp_85`G%N9jST3R&!|a-G|;Ki8)?-7nk>8c`*GrUg5z zuqifcUAch=FD&8qr%rM6u;P+iVaeMOtE2jCB*yMY2b(GYImUzO%Am~yi<+@QkDMCkqzyqW2ZzzEA3Ho{BWaSo$nyKHN$ds+EQ9P)WC!r6rT^$nlG+#V{X>${O{GGAFOT9oUf*~#Lf^HZbqX>SU^#x6 zbF0QF`giRGrk8mmO%7{gC2`)Nk9 zr*b&SPZw(8p%79e*{70z8)z;QzR!&h#nfkAVpzxe@3?nOaE1&27rVB(m3jQolyjW5 zaVs^wYHCPFx3CL+s<0uAuGgG-@S~9Z0&#!gYB&RKK-8Jht*^@U-SsbLZ?lsh+dgDb z`E3KA+JOcZ7^oOtm;EcD>ZOwVIi}r*ND`MLK08th&+J`WR@OPz<;BM5jvJcth!i!` ztanXv`j0si7iL}D4l&s@SL;7fVX?qzh#!gF=84;iOi$3k-%)w6DlLaUYh9~Mhns(I zII(06h9^bXNBbjmm5>^Cd8IRb$StVuDx-^L7>o#d-fuouEtNRDUA-MmceZVo#Hn~Y zS2OyJvvgX;Q{ydoEvamv?Jhh?fn7d>M=#&lQ+Bn9z{;fxou=QhhL|+wJ6oc*m-K-j z=4|9FrVaM7TPed7&K@hkj2wmx|Kf+pPgA=xvGv7kKc-8zuovF?3HZf@8DFa7lvS$B z#7GrsXI{Lc>zkEjGBZzb%eClEVc9D2p+o2;eVm7MUq##g=V&VlUL`y%(U3){gtV4+ zX;O7d>u%{=F*%`<(`+IcXFno~o8NZsWim8k+3kde8*MvvK){eN@bKVZK8GfE z*g<{c;hrQQ+x)4h!E^h5m~yRe&{%p3?i#$vD#vi*PN#@zJf8}(FD{B?Ik4WWy$HvJ z8Gvvl`M|GA)GYukXxrq4zr$qWQa8uV7;e7by}>TrD@0pV)A5pQe)L@ChVT7V!ER&5 zJVLv3^)Otf{No_k!@rgy`-oz@XGHeA3?TfOE)HF#pRkjhfriUkRrXqeJAJ<}fv@j8 z;Zb@tntb-bdob%@i}CmrRP_;5lsF@YPZ7uCa~xY~xdTtDjy?QWv`&!bk44k@JWf(j zr7ip<1*tX|(HkazEhee(2R%IH(+gcM#WgpZxeWKc4`&%g&bDKKh;kvab$boHgEU8e zH;JkJJO&o|Fbd*@gz^_R^H3E6X3Gz<0PqqfLWLVp#tZc&?hMXx#{n}zHj=*(4*LxL z%!A}_?*qiXRn*Mh`tXD4ai-YcdFi3^BW_*(1G`-z<~O{v6|@^3D+Cww>2s=PXM}8> z!i-jNCEV5hRJ%`5U{zC{K`h#t|EF)|G#eII1!!1!;6P5%qn_k<}Iz2p2O5H;N<%e?ZKADmHrvN zw+m)R*Q8uVJ9h^vXxqPN$Dd|Jdv!qkBv z!8{<8Y}H2LDS0!@vr$;GaX)^w`k1Tp_J_{%s!I*uQHGp@5ZSqp6hC7vNeIHntNgZ61fBSHi(GGgB)<=w zVfB{_?BhpQRCtj4+N2=yvCOHd0Qyx%^otbcK&6?h*JNsX^ zJN=W4Ny}I$t9-4ux8u!QP2f^j3%jWDaC%{OqW^n6p>9KAac{l|0*6?ihTl+}8v5i4`9)1G?&1fm_C~1u9Px3Lq&RlCXwJe z!?6ObIFJ5^U5n9psQc`|`zLh0PsB7aV`TYnl+$2Y;}Q5wEYkot7w(FX>ageL-A(i> z(pme##a3p_Mdto;#Hh3W_Jj}69UQn289R&|6~&DKPM0Ll08xD{0#+RcoXJBcc+!o& z^fpH=W8P7}loM}%0OW^a`nf8iHwCYWQ511DO9VQha(k|RJ5gU}b7X@r;av&&uJk+f zmFPS6ca*>S8=+9Ih7Nwq6(HVb5XVXj3P$VKDl-b9A$_rvU}?>I0oL45Wo(;Y>yh0z z9SZ*-CfZHtR%m%p{Sm8vpK7Q<^_B#^$_-~cVz3kBkebAkYvjTt`TL#|jzOhFstmI& z=(ZxQrFK6y;`rOe-?<+@!z8>n*z#+I7~!I=j+*LNrDs&vpryVD2o zTgI45f-b{@RZo9Yjh`jj*NHfFqOrRQ0#yG15~bcgP3Hcbdkj?#h7a{YM7rujzEfRs zPKM~VlFm3i>QQ7!!+V_3jmxll`7j_SyCyP^WnR(>3N#+Ehbe4^-0OY#(9)FnH z)qai#c^Rh>3i=J}P)yh?TOe_?2hUf`3^$VR1+MssF-SjlZ%6EDVq&+wG@rnwnMdT$ zi;qMr2UCTdy_%&qm=C!#Yl;4!y*w;rxIO&ebgUBH7*eIX;hYB;L~H+mL&-OEM?c*N zF!IuaWD=8ChW#BVyaxgjt5)j`C{qH1_4+1W;7k9c$=H`WTS&Xhd~fdU1MLM*SQmzz zuj2dd`Q-h2GgujPR<(6!ik{+_cn3p~o{8KLJ7s7hDPSh(ZTT?tf=h+{g*!#@nm}|= zsB|Bcf)JZ4thi|Q1poX>gje1Hh{+J-tK|e z8cg@M1};f&5s+0X#{D$@Gce*tqMn5AqF0^lf&)F*Zk?v(a4A)=L^w0cud6pR3)KBJ z1LW6wLA`y*KlIiENGCHILyr1*^L3R$_{5BSW3HfEeD%gK1_vB%!CtnkhvwcBUO$s8VI5dTMoE{=!t9bi%EQ1+w(OlXV7HWyGrmB^Gg^*so;e!PY zQ7!zR?G8-%V;G3@EnCh^v3hi#FixiQu*}*Q$vwwCM(264MTO*F=5^hE>9hxzqpn^hvS*Hh?Q{ctMxBOkT` zgL=w}z{;Wa7%Pfw5WnuRhMnir#zLgYn%}*kV5yc4)|i@@+w6^s&`?sai0B_GvcORC z4isT4Y?i3+Cv&=}T#XgEOQJY!ll2DIWs=SeT*Z7Sjn?SIPdB9Ex z4{k*3NYOOr>2KZjLS4M9q#}R>9Iwn@r+@T{)+C>~E_h>2^>MEF&0n-wZ4KcJkC-(& zXx@f9XoGU2dB0-5Rr2-d7<#0oP6q@Fn97I$f+p)|8a~^8MRnh&|LYOzeh?%%@{I;m zx;Q%QA*e#&*S;aYR|iv;_eyI7rrIFaGGNwuSeZR&*-7Dj=!BxSWhmjusVFKyO|@y{ z%PCUEWkLG2VjyQum`%aSFE}MQ%_?u_4{>>h&j8?M6Zd>|%CV6Obu?qJI=hAIccu4d z86MtYIbewjOR z7uWxyxuHbypOmRkO4OL<_+PA@Q*bZQyQae(+qP}nwryj_+_9Y<+jf4jlO5Z(ZEG@h z>P*eeoT`7-T=YfX^-ZsS`&;jN9&HWYzfWYNaFm`n=S4x23xw1QIJv(EiWGPcHWZiUTdgp26jX>;d&JA=oc5Q%di(ovmwxwfy|c4)wV1RKZfj++z(^o=~?v*Kgw3zHW9745T$L`M7_X!7`XpiqJfjig-Y6ikDWOyzFL1 zHq2Wts1NTWJS`cbY@2u{aIbipd1eXHJYULt<$r5dh|NzGA8;~f{o>5w%(KGPS_I*v zX5;pqbHvX>#ax^p&M;6kw_?Ib475#c@7A-UY=A!Cx8iMx}aM(p<2x_(*xXs6LpjfE4o^`W=YH+xd2yQulp~yVf3pCs6hq zCqVW?$+Et0$&ykXQg?0nP`3ksy;Mi2SwDJuFF>f*m}VpN2fcCUCo2fv)o zbly_JShsnTN`{@_NDnc)QK&=xt7!ERcSS?#aaU${ICh^_bUQij&&SDHhZRZ9ld3;V zvG*|XHaYO4JUMji8vagtYP*eCur}?x02>&!Y(0g|4!|7V1q^qSA1Bt9Gftt~$H3*C+fmTkA>xr`*r>ALf2@D>GZu|DE|S zwC$YNTW|ep73v2vza`%^3J4P2nA^`v>}|Kr$h)^lr_8vUC4wat`_n-@fGi~@i*vgg zfgt&5NcdVY+|4boSL*#^#wFd)j#vY+B zvoXt(%#!}%>FxNu!2LnZnj*}nqGGm#NJWh2oz}GV@gy~td(^d(8l}gSGy1}t(#8Z3 zLQZU7|7M%ff$o#(IQa0&od*(y{#S(+JMm9Uo^(}BJ5A_A*P)yMoUZB%G(5!E2Q(^M z5lFYEZayf@~!r@Y~|2MKf>M z3nqp%&j{yIc$AMWwsNl$)`)ACH^Iika=h%=v5x`NeQ6Z@`H0;p8mW2es}ymWcMe&~ zP;X>Z?(7~&YFt3@%_r$rL6`b3yM~_OzRSz%&cl5xzGht4XF8To%g( zHeqWH$ZRiQgO+AYH%wJ-8M)T8)}?%ZHvl&J+mk0WSrWYUS;Jo+%RihL9p00)<>Scs+QT68O zJPn2S{Fgc;iDysx3tD%@hXaPwivyxx7!^FPj*B}(~S$?s1?UD^w^z)Y6!t( z1sU8%x?bONF{s9}=WCyQwY#e0rxFCU5cs_scudTTcl7Uj<;Gwrh?7LR59iHBD7o8| zRVKrT4|HCtqmd}bCT*eQ38YoHze~`H)FjmnFCotI99GUfhSm|HCNDN}SmnmxF)d zs2?1|*ZMc$GabgiD5~~aizIt0fLb@WH zUTa_PCkE{$TUxHFS9_;N2Qk-IlZM03GCdHO?9AIQlW1m|J)7AV)h)E4ogi^Pkeoj~ zr@8I5H`?^z#%__;1z^>;=D$HFiR;Xk&*stWA6C%!FV>@O4sb+5KaY4n<&F<^IV`@@ zjj>@P@@}+x#TuzNq!8?mUAKurXka@jaLH^2)oT2}9m_c^%@iA-b{VN=OQqw{e-Peu zzCrxgCu^7eiSakjUDZKskAu8bZ|4Zp0QPI5QrN{^}mf(_h4ASY940$4m7ajN%Qa809Q+dy$zRz0n6v9c1zg*}^F z1;0gAS%vhR zXUpE;_6%$NGTWYDLS>q?j-{eWzq?xS_jN6)vQh(I2uFA`dMV@-EjZ=2?!uetXnPh{ zGQVkV?M8PRI{O&z@dIV~b=4F`W+M0RQX+j=${%W1P4$$P`va#sYT0)Tc=v-Gbu>fe z7Bj7HrfQq38Z{fvrW!frtH|)2v{1P27expmJlUTqOac~i0lpZ~*9AkfquVxS1W;r5#zntc)y>9m^ zzXdf$WIn%%W3^~l9-IQlhug0)F4*O)jp>~}HW27?QJ;=L;D|G4>2(}OQ6U$<23UOg zK!@Eg7cAbaU)#c%p-O&OCK=MU*FHVZV{p7oK96vl=S4StiX_B1stVacxcQg0Ughj`w!rmxDv zr}w5hi@Kef-8W>E&#POW*jfUM0l3A#PG_+6QYC9KaU6NDqS!vPWc+kHCU{pRK90{+ zY3x?Jkn?3%IizsOxClI6%ZRWRp)t1552|T*^UambU>WKVmY56iF!qOZ2qk!5=|JG{Y1xoB=^kn6dzi-?u%5dF|BO>}Q5_J0F$`mx@c2N2kF{0+NWCQPfc5`1)<^Z4z+@DL_WlAPJZyU?wYdpL_u6*}c zU?Ml|lur9B%xZFFqsge4pEUm+>?`P6cieu0y$<#N6zqSxpjfY3`nSTmvU=hCQYs;_!{%?6>Sc9rZ+t5gdsA3Z+49%Z7<*ma zs;xs$-OxVAw8Iu`lRBKK)}~S^)3`rJ^&FV2v{-a&A~|HJJ9z3uQdZo#vYKYb@8S}_ zg%;f{aQO5}q+2-!OZuNem9MrlYBCl_W9GJieWN?Z`gqG~X)c39%j)Fi@VFgF&u%Ur zwwFa=(2kU|FkB{)D|M3B$r|NFnf@o@P{;B+VVaPh#qzp=L(8?_YQMQ*vc8U>)*d~O z|LtM*f%H}ApxiR_2G-oD4B$yd|J|@>#7pw%w_eF#Kq6NJ&C=TOw<-LS5TdH4h-Yn5 zUzK8ZRoYb{rn*1?QI}hq5oY^wm^>&u_ES`h1O7L1=M{ zFqV6SP#lc#By>PW$kOX;gTv;DzNx*vBmG(I;Xdn)Vn#e((NjvI9n(LQCX~@ptd0*vemIQwhR>V!f#T%{n%ieu%?d_JxJ$CEv9O7Rx zcxy5V^N227=U;VLAv?h_5ylt+{X6NJxwC6O<&*J&82Hj06m9nY=$Ow(__0B`>r`HN zCFisS`S1x0>bIqA0=wY3c4`}Lp-!`m2JO=lk>O~ z$JWX#z{x9VB!BJnlntjCb)`zYZOV9`Pw#NK*R=(oAyFEyX&aM^e`#Q7=v3MbSUOI& zn`N+(Y)Zwpz9NgD2y_Pc=Ov?3}JZsfa6>Uh4A=UH@uHIL2QYL2Bkmn*6v zWZu%SwB{^_0XAAA2_O}CGLIV{LjG`a_3d$)E|y-Ape^oNKR!dgOj~?vg_gTJphAo5 z*64@a#t(mel+rao-a_tL=P9X|HF}$(S)&Zzy8KJGIoVmD55&-3ydvu*!(%%EGL-Cy z$K1j37#ItqD4_u@w$>K!+zC|i!(WT%59I%im%2AWm=||c^{c7 zjVwJ@=CFwftMG6c_g91+VrM3opeK<18*i@AuAWjJy|vHp2RQRzME4^=%1PFb@?Gbr zNcI1&O|kxm3xK7IizD;T+h3)%8Moewl-sX`~WI#z~=;X<+Zs|s@nkp*U_;li|Bt4~!x(|&V`wd6w#j~rs?eU&P0>3of zaDu2ZbZN#{JhAXYlI0Q#)C#o0fuKDG?v$En1#1n5XvLPCbh9{!BR<;E!bY;QYwxkV z-w&B9ZfVw-J<}|j68sb+VbkPK*Jo^cj`vs(iG);R$D?_D1~8DQlBwVJfKp(Tbr`RO&RG*qHyJ;Wg z@`&?9zB*(9ke>2kNYR*sEqKNTNmAfpXs|V>vK~l)tYZvUlU*}X|6>pZjF)1;(VRHHJmR)^0ZOEQUAL@|8bf z{{(|?M%bj|di*u~0v^FUWE-|^sG0m-oLoluCLlTv@uwQ_c12R!J=pxNWf^_FM(UWq z+5*0NHTvomd+ zdcW5>QgfqYLaAoc+}2?`5wV|@$%jzyvKZMNJe&)pD#Wahj`P9Ps>#0e3+IlJNAX>$ zoG^4RP3cw*#W&}vU5#4V)K~+yAyqgD8C~<|sP1IbP`Sl;@`o)b$A6B0%xPoaXg5G* zup3sRaIsw~mf{k)NW%v+H<+DRDQAQ&ff6Lp;QU6Pj@%+)L@0NqB3-1A%nQHz+D!ba z*J=ykvw?)_`FeYbD;tiJ-8BgZ-XYxrZ1BJTdoirI_5loe3{BY=CXY#Pm;i$9RIT;O zE$ew@&T%QUy$~X+XMcCM_Rc|L(D4Z6_G=>PiOZOr$}D_Zo=ODFM+gA51~5=EAOtU# zU6eUb&3bC$DoSVUm*^ECBGcCXMn-U2B|M7futJoW89`rc_jo+EL}K~P3T1ve6IMGN z8O8fd1JAsS66_^T%dTXWC{MDd+05RXD5M*EdCZiUzcrL(E*562^6iut;V23N*+^2= z?lLo-v9F1HydF=Y*b44gV@9c7Ga?{%Z8644*PGQtr|FD!H;n&vgZS;t-#vmLk0=2n1yUlYRT_zJ5j+D*wd`!MgzNk0 zfoj;!tH5XHHcg@Y-ZpIE(~}!s7Cl!s`4DtUkqRG^|x&6&`8_HTZ z-o3w>ZThT>i*>{!>%H~WI<_GVjv@hCTxU6r@tae1a7FTwXske(VO|YoQ zz?FW-s{aTPiOk!?7$EoiTbS@dQXZO_95oP~ogwAG@S6c@8cTRa+Bq9tMS4%aKaS4N zLz?_&XH+gp$t=Kobj#qM7kGh#!*Et>?jI}%dCWNvuBwG{3WmSA;9)UvCr$!v!-THa%!=*oi;v~$%;|UHq{8CJRTskHOz6AIts0~*c+mwE_7<35fF)V<;})?B zuUEUt4U*Z~z)28YCs*6(-e}mLCtdF?#Y{cawkJF~uM3}%ubV6Nw9^MMTI+c`(jdrZ z_7&0Lvuh9&Y%TM=ep<~WsB|}eV6@|!tnNU7yimNzF_Om~g}?0{70L9aI*P9R9XkVt zr%e6?%LBg{btl>->-2;Z7|3xVva|3EQ+^cWQ*e6p;$m~iin-H6eidJKlrRY40;cZE zrzTT+>fDorXd9j({am7oM$LT)JHB5wJ;Dx+6ySJ1tM=VLGo=2lK*_NtyVDev)T6Gf zO8Hpss-WYrPHM4fj^?2?6V-eU@Znh~|Cc2_;W8$Agzae2P&{0JyFsiwQA>Y40gHD? zzNS3ZB>5Ru`08)6Hz2nGCs22kh3)b}yZtht#`{@JVTh|2`lM>ckHq%dMGuv7SFGIi zaXj;75=I3lb|g&(i(Jc6bxpIR!i)@+`WY*jTE|!6x5H0$tMTPCHM90~^78TRZQwE0 zfgDu)Pz`V!*$+V{RWdIe`59+veHOJmzsUC5brCp~LteaW3P}I_`KkG@2tw!*B7=+ znzeQwLr_jrd19^_G7|vF5YxCSxsPoGH6PaZd@S#T9gr*mk0Sd9$)$HOHSJ5y9E}(| z)&nk-j;^_s-&Dzm>XcUGDBo4qrbfvXavqA6lj0+CFV=DI2kQYgR0l({mf+qSK~TN5 zYz&5zQS0aX_#5xy%T1aV-ZgN+Mlm(t6~S4pNLu=3?V*8BsG%PozMoGLJ7g!d8n$JkKu{&kG3jNlEtAj2G4F1aTPB>c%XX zjT#m5EiOpgooW?1^Np2XBDmSLacxx1b@!GdJ0`&IQ%DvlLzv#h&;>&To}0Zt+`j44 z*XfUap1QX*-hvo?q?zYC^@<>u>FplxMQ^Vwj77sI>E`h7Se#zEp8M&~x}iufFs9eX z+-?0M4F~!^?VVHGon3!kj~>;yP2%36g4Rz(;q&_rbZnm6?23Z9vrBJv=@P2=OB||K z0<3LKsh-*JW=|ylK4ag;bS87O=g5j4rn41x8GLwn-p-FN`)MNPeBhd#LHQzl&>WD5 z#i18TjXHz7vZWtz)t>WO$UGTEE_|lTbOZBcH&P{#yvm=9AW>eKd9kF+S~nSu6Uwdr zx}a%V_0KtMJK!0)zaKp~J5&3bKg|7pINE&HusuyT_JSGiL}ru43n>M+8 z;o?8{o0hTn^e~sr-VPWtDT#9vj?`iJ0X#HZR>PS+tqWSBf>+f<|W+vXobopBtN1v0#(MK>r+29#A3btZ_k z`QiahXmko%6OdJ7Of5M`&5tjE_pdemsGfB{p8kns@X7oZG6MK?we}Y96T|tx}J_~*&5UX;ZrRc}> zGByno@$aiop9bnSB=u4(-uekaeKB%>J7Knr0xT_L9_fO>Hl_>rjlrYcNlFW@SgH+al|Kn^R7H&)O ztzaOMBZ+a3;9#2GPrI-1ou9k75*|Mzu`FU%gp7M2puOG8b+`LD?CM2A^;e;86PZ9C ztz!N+$ejOYJmRXRFH4@2{Fqn3lgYH1+uXvO zXpM7~*(x!thmQig}uXh*Ftvl}desXtiR(F#bTPPPFG8;u?h_*2V=eW_7 z45|r1bKhY-dqihdl^)nQ)pP1m@*yUV2JI+OY9%vqRngSm$PD+VZb;GPR$$E{HesM~ zQ-$M!Y#jVV*P-XwNzoZd*@jv?@vP$mi&{nph(4fp*1Wd=3S!ZqnG0`lwbY=AO900@ z2-bgC$c^XnwnDRkts6i;xWR34oLFJI8pSDPoBPF8L7EeL1K&^L*#zxPC|au?ezpir zl#aCCB>3yhQ5B(8KsdL4ub%;#-$OS_$I$vygVMHc7d3ol3S=9Rix_WCFWRYgxailq zWt$;GBHSBWt0;i=m-Gr^24(zWB4#)b3<$O`aEO}(VqhKqMA*ZQpv z;mtcqWiWfnQHTlM`}(xw&IK>tgV9+yOPA63Zex`?#LOp_WY3kyGimHoN6%Iua3WP= zbn9>6P)?!1`@E&zs-rno>1&`ayh?4kQ(dYeMCjOfTlPn5{Lkl_y;2IiWF9_;S7B9P zQ9(p|;;dctSPofC@?^5=cd3i`Z63P)O zb!(V7?9oaIxV1L3VHIX2S)o>r&vzDkF?zbYIof{m8Yq#ZH{yAEaI$UskMmn^k`Y=_N(#-^3h z5#*vd2PfhLh~}E|W<`EJk9Km8!#j`R!HVoyftlu(1rpB3eFx#h)GoN_BQtR6nJCx zd4v};fq({)>Qx075n3ybLs`@ZXF3?^4 zg*tnX+zCk-Us`L$h-`f?YTiS2`*6!pS!)W*F$U3grb-l};wyILp?#BoYl~ z9y!IG7^j^+Zv0Y`rcVm1bHx?Bkrwj;y7~&BehfK3_OhmOBASJ(2#!Icvqpxr_Wgn@ zIlr%&2a;`SH1t>%D&DL`LJQV(dDkuBuSmX3(b0@nsID}gmE4!RoRv0{O3KiQ5LEVQ zi{E0Pu55AJ+7SgW&Z9YhHoK!|yW(*Cj=VqCf6Z>Htw$8fW{T$8lZxf(y_;w7y)|lW zG;jBNTD-3!wmVaMAy8~;ePtDjB_aw;O8|~1Au*eA!{!_8`#}wqK0)AOfY(bHx{xXS zl57i<^p!{(1b?vw6kQ40>?;4||8ss}yTBUVb0Uw=7gS zO&TaN6_!se#C*Q*%L_#iwE=FGwE7Z@(+caF-|MtF>)xqfH`O|8x?DIilU?%jHaNYq3$$^9yg6+5{mbT|VBc98Uq7o8N_V@bW`4YD8|DwGsA zJW4*Fa+Hx`4_kTSvM|jghl1vhyqBeH1C)@+tz|t*Cujy@pa)Uaefx2ze8IfU=FbB^9#*ysG1JAxWBvZdk6w*|XaN~I+ zTg_BtZvlg@=COlUp>0bwEPQ7wU21E$HLVW8Do8$^dPFP?89)t!BxLQfO_Z{GBC|f# zg^-ADggNwEKPHKAblxc$@fHS6t5GS?3lI4&hQvCN?pj5JU?W#OJ+fjtYQQ554vW2t zS@jw3@gH~J8U~oPG{u%CNTh0uu|;cNBcj#wJl`|!l$gh}xI0PdC*x-)<@DvPm|aW7 zsx41jGaU!)l_0?-`tK9xHd%)3c zlLk2?%`(p4dI38jX8P5r76y?wHOwIx)g=BcFi<|6R`Gw=3wWWCyH*qihmBSzSyU$F z7gYc`6&2g?v-p@a6g6aaWHrc;)Nw>0H=x-y2wm=K75CvR-5W;D>Gfbj$3|5cey;`4 zL`@Tm)B>`rJ9X-@)Q&Db=0(d;FmTwMtSO=XWZ{klx(mt_A^P&<0MVF4FP`xB5?bh5 z>MX*8{R;FOtmL_E&sh)ugN&XhEFwqlv-&&sNEf?npY%1LTz<1tl9x9iE>6tzFG4{4(RebD)5~Q`W1@aC%!AdoB^jOZKN1cNw*hlz>Ut`TrNXCmS1L~Fe zF`CuHMLad&<(RyG7<5Z$sd3-b(;HMJTTMlf^JLMKU=Pw%@J8jY4s;YCllH0 zKA;-APdAjVE^8S>^!HpF)%HQX1qw~X>y1u^l69haK3Gf=! zrE$JJt3fiQZ4O(@6(IL3saK-F{i-<8zoF?mkQs+ zWOqaEE86a7sTlgP#wl9i2j)$}F_m5yjh&GD?&1CrObA&o@3++^B1QF{79$2Z1#L+qa5Y8}Ow)0Oc@vXaK`@TQ=EA|*RUm!yi>3yB&j@Nh;xYa`LSgAQ zV_hIcW!YR#mHQgv%l)MDr=)OQY0y~YW+6A&>X%0GLl7sTDe5} zOj=3hhDozKE@A1vuLGC`6hQe;jsnvy6a3uPS=)X?O;`#rZxz;2cn3D^1vljf1`K>i zmJ@CjsEfCzn~-hWL|Y!{eRKeTH&I*-=YIBHYq4o*&DA-cv076X4VBJIv>Fc0`v{v| zKJEal_FWPs!m+@B>@2Y(sX+*R)OvmVZ(YkWY-|#xkXaM0@tf(h{TCQ?G>&Mw%f+l%S{^i{gJ>r<-tcm z7i^D-3&Sfg;@w#Yf67i5PHA2Ieg4vRc-+4|9uB$&AJJ20!>(uTx@u$(&98lOYuuq~ zD6DA3ZA71)b-Oir-f_9R-l86B)y}1tb%-yYOiWTP%Por6CrA&35yEirT^>VIZ-H9+ z0>japoZ$?mUTAYLTEyYI%4}7uUl=g(>;m23G1?37QlyRNfB&fB0B#8j2|eq|mSz(s zcf0-KTGi|Ygo6@3hJq>NO|Ee`bi|ARni0dT$|Bw^>&4mT?sT$FnZV05+?zlqixR5l zDN^Urmp`>XpcZ=_Xy0@{#E!1!u@~i(x?DRCm0$4W&RM<$((Ijn&tr&NY9{MbZRtR6 z=xZWVQ{@b$52HZW9x-HS;>d^~LGbQU$*(qKk_rB#Zq=AQDg`dc{IZ;k@xPAm+RXvW z32bGn^X^_laweUk+cz>pTfhvf@>b!?`N2$Zv_m_C&DcgQlNs11AAj}@GHi2r-#;5` zCGN<>i(}@74@IC*KP+e&>}^_uyk4tv^&<=t(#0<<&W(IyRg!x<_gVhzi-M1m$4LH70Wc zwcyxV_TaN-^1PrJm8!Qpoc(;g#lvx6PpES}7){#jV0GwM?`w0P@3Am;y`Y1)K(>19 z?%zuldU6_R3>rM%a#uN4IW{MPbK6W8x|eizLuj?CqjgNG$4K&Lskey{GJc|YTN|`5Oj?d(&vlk1=OhPctcA*w_#N>a z8h=sxpD=jIVM=;X+WP__+3O!1P=*-WDSq>wvL_lMNN+2jvzNOjEX_#qhgdx>U1a@4 z@|8KWh@oI_)No~=E`I6mpjFTCpe&{{HeN)x25)w04TjE^WxXy5|D4u;Equ~aoWZW) zz{p>x5+V~2{PzAT^`kel;lo{U5iS~u9w*WJN)io9V<#Qc`473V7vqx5jfeF@S&I#} zEBWyup?H$(YP&*Vw2HJ>CYo@~L*6hB^)UHoBLGo`76RgA+fV1vzRV)5d2Pg=| zLbji!Z}ggcBJt0RKFODR-J!eTioxuBNu_&Vfc#OFE>5WP!~B}=6%Mr5tX z&Q;)xiXsv=3alhf$33F{kiK-gCH8Ll7gHx7$`%t-P`o0)k(-oa3BRR z2V^(6gg<4ka)W=gUho|BAth1(pdK=c!!0UTai5Hl>@?9{54_o_M;~df$AwJvCrTZ8+^BmiO9yO1 z@%OJ|c|V*e6OV;Ih8U?$a@a!XdXeA1+ft>rmR#b+InFCJ>v~c|Yc9`}0O>s76Yxde z!0XKP#%z<@@1q+!80&rKKO!eZ@YoZXTpa2g`K=jE(JtdS@=;mN9bcS1jyGGxd895w z{9!ffq1#gR4qHnAWxS&JW5p!4+yHB^ydSvPW3jz^aKoC23P3|E{^$6}GgH9L+`TJ# z;GI{hanA!o%Ft~Z<2Mz95!QGxCR4F*(ix4OUlN;ttdQ&bZp!ThI#kX&jbPvbe)QG$ z;!bB;@^JKz4V}YJpmq2T&@p*z(5}k;nh8O%9#n_^z_)BCe>p!-(ro2BMVG!*2WrYP4vwcwj=a ziH4uoZfHGs-2Q5!+I-J&EkDnL)$M`Q9pdbrRRXWz5Zo<7PR44!QCUq`hU|T7(xURkOC6F0vLuW{mB^CiX#j zjsCU=fK^e=PwQ>3ri^b1I(X$?y!xa6kdri}l$Xwlk^4;s*(`f~G#NT9-RIJnTpH}i z4^l+o^$aUzT7kDH6YWNJ8uVQp#=g2Tcz%lY`ZJ~V{NO^wMSlm{m=8Yt91m2&n-03m zjuuM49z1WJ*tvfg1?~C!)CZc0z3_=m zmEzi9oHg5gph zn)OMbhTI>#fa<+Z9Z0nS(6IC+WsCvl(>H^GVtV5PX<2jWD~ZeD&G=&t#n87@fr)y+ z{LFi(`&=|$V-$lhPax7Ys32%6(SPGrZ!yYPL-yTc(#E+Ee*1WF=F>^f z8|S+EhmHNcs)p2Ilb~W+Kru0Hu8mXVEi(7jPN0o66jI^Ochr&&``D5Ke^_j(~9nKUl;1iu2 zsU~Rk#48;Y<@^8a#RRoz=aBxmkpi^-f7VePJ?ULM9nDNh$C#i&7-7L@x=LSWx_0t7 z935#q0uc+~=%lRnb}sQY3e3SHYMoKTi#$_jCQfn>7DvmG1wtHeLAIxc@-kPuxEv zwa+e)%vAUihunsA=SO)>%#L??5^FiqC&>EjCt2RZe?PA) zBx(qf%04n&8I7jOsMBrc2DWb>Oa&=+$jz9_hz?d1`@K7l9!Z3oOwou5lqF8~?FT6= z6%or&%T^{UXVNlYRVUdzZB9-;*On!jN+I=KC#@yf;`45;Khh=R=#R=9Ja4$9@b(mU z=Nj9L*%Wu^?nmL=@0^6wT?98~3iy5dyghUrD}3LdJrWH6*wG=WGN&Sn=Cd@CwQM0C zpb}IOJ{EeoxRs49+TRQw;w~96bdzZfXw$_1eSkYwA?2AEjz_}0O#%2STe)>^+Nrll zP~V73alkcR?%EJ_9|Q$}^a*HT3_)r=#e&LPvr{8g!I475zbwk3AuL}ssrrtZ3LtG! zh4K5o$<6HavtrqtrcVOZf9NuxA05NX^F6xTyg^W%gvCV?fTX8Irj05}Tge|p$l<>@ zKae6yOJHlU-Qc@HC|j^?#e6qHG$d)2+S6(3R-S2ke6!;^y?P&T9q7QXYV*LrJwX~R z7-%r3?yV$MB|6zl=L4(?RJ{8T~b8d{EGib(xbM78PDcKoL zA-A#D7zZ%5m-8|OYN;jM9jK@_SV%idE8E+Br7DZH#il1OCJL{?HF%HBfRqO6v*^66 zG52k15b2vtUfDRgo9-8I5}<|+Hj{}= zUJYlw`i=$qz!+YC+ywmJR9WZ4^n^NsgUMEh1bYpNYEjSzxJ^1OB?%WNO7M<&)|RCb z<*$GEnMB$&@ao`DwR=qoUg|J(MDa}G<2MpQ72MWWt7kLUj8;XZo2ytqI~C|n{X_j6 z7_2swv0>mH37wwfhp_m)A76S(1o+$9+hR3J8%Ji=deGU@!NZMcHO0o5fsgmqFJ=bT z$m!=hxyt=M((NwVI@Lv28=v>iE*~c!7Vk9_a(Y6bvi1i!IJWuxYzXuR!02yIALHT- zx_$2VA6EA>hZzILQ4b8pfV|w#_h?>l-`pl1lD*U!Pi0wQj$ckc1Qm-tr{$H1!B*iE z1{w*B;suGcdFY><(Q!Q}%dA6JYBZ%1$YK!+R3_QrO~IbCSU($)9%65`-^k!g)~$SC zH6;IW3J}7GfsbW-XaY-|a3OW!VAklDGU&M6$oPj#w)2Px{v${w+YUqyPOj4KPYma> z_HNTBVrD2upKQ}s0v^v@{S}=;@ptC!d9Gz<+2&!PA=rHXtRe-FCjLS2v?=F!J@QQJ z3XmrlkpBzuka|zw>5^MG8(P zL;0*d@}Ss6HLgY0PS7@D?Z-Rewv;Vq)fd$5UfpO^PY@7aJFUr`HVYo{9Mwoi#_B{-tg*viW*BCahBC+ zTXq0-=qMC~Wme7;qVf}p#bO=s%j|J)IGt2OO>2RPA`Lm4GnwKoOSjae3jjERPJ)lA z4hI&(?^c~d*M~2V0|z$I8BNtQ;7(1i;uF``aP&N6X<)nC*n38vMmcQ-(Zw=HIlGL`bLs097JK? zX(<)8{fPVVb*2mfe*%Zq26Rm3~Cv)F8$qQOTx9m==CeaU%&ezBO85Db9UY|?Hh zogpK3>)~0IkmzxHNcIO4@02q=E14yT@B1E=kMHl_@N?Q=1ZD=N7^?$6>vSXBSRSE9 zCw(>+=W()Wh7*5QexCHVdLxgrHHZqXnMPO+zS=$q?n!A760B_MO(b9?)H+9ul`5Mk zOuY3k6zq}lOaN+>EgY?bV+^4s{YD6qej$3G?>w^<8}`c>ZlW(fL5>jU`gn> zo}M2FpRkw}@X;BQ2_X)3iz&q>Whe!tkTbaH=i;KsXSR^RgM;=(@2wfS6uN!08!_k0x?`k+M*CMWxOFSPN>i*QQhV>M6LMa$FU9 zRg3OzRYEFUe{#U~IdUVx88rI63FdGCELtc?T zPLJj*?DMVi+k%TZj~R8+xf4*Tjz`$yb`yPRqU(*jnThnOGIRe@GNe=ym#8LrmAjQ?cohk z{FWYT&^T%+B`v5ZMCYcG4Np=nbG-X|Ln`=2+6azZ2<%bOp$nJ}sFDGcc)j6=LbP;= zc+2AkXKFM=jv2kr;&+5atRJj=imIaRsPB&LbpPq%v z#~-}jKUNplj};tBmO0`a{N=C}55uQk2GB#p=cy}0umuTeOE zRFKtWyZo~vI3P&A+$z=EZ2&%#R7A!k?uZp(_?6z4U^^AdN~27tU2wkNHKi)@w#ucQ zu$5qom6Y$xs;JUXly<;!jWRSU$8J`dj!Q5pR_Cr>Joc*Tf5>+SHFWSz_8jJFf#ZK4 zX9U~{oWNSpvc(M>9;C@9M}N`3ZQRH&P6+(Q&FU6mCNoYNlry zeeoLYO~3Y93X#oI#JTIk#b)}0bEt7Z`2K*=bI_U`#1y8@TroLl;~b!(zc4S1HYdz0 z&AxWRr-TamAT=B5tY@e4Nz!VO%7S%XXDrEmL!k)75A!*7; zh$01A>p4Kqt|y&YeyUc1+RN8=q0Ww2<1o{3z0|9gCa>^?!_x?jt(eFr^LvNHG&p^;Ccc!Z7&Qa+yK_ITY+8|G#gmh zK7sS_XMNLMU$%sulTT~s>3(oJs!5U*-V^nA$G;W%+<_uS#@=vSN14tbN4>K{kIv~K z62T&HRXsC3I>O)LwLiXYZ^x^nE1w>JsXAXhIN*_wlw_mFs!I-RUl*UVR#Wd`)~t+` zitI~ddxDsiWuh$$+|tjdGlFf#97k>Ufq1muC5nro!h3YKni@5XM4-+FG`1KOnivGt zOl?kq>BSj)m$BCqxeaOzL)GM4weYXCN2U>2FtEMH!`UekEHDk@mA-&%9SUg2;@ zxbQ>zI=eHCWSnnSnXXJCEC}0@@1DM+2#_s0+58u|!f^VtG76DY)m6R(|4RDLm1Op~ z;8Nifnfk*!^jI^bqu=Tnom(>77GRytKuYGhfR}8gs4ote$7J>1tj0YoU*eq4FEo zJ30DYvpg>^%1h20q|xWcOu+~AC@e=>c4NCkQugQ>8!KOsR|r#EV2H1l~mlvH0Eq6Jar5?suM#ecNc!~ z|N9mSgdS3Vkrvu7^=JszuZ5cJ+5o9SW~Az_;TVtG?jWS60vlPuR;Gf|AZuthibKld z(PLSs2E5S?QskvT#&4QZoMINaJ)eM4IY)YWN7(h4yb&red8>WI(B;x+eZzR3 zT~Z1r$h;cEfIr&#b^dgf`NE#v%yAhY;6k5OWF%glj{6Itru$`XER2W^rzv3d?%%Z> zt&XvT*Bz<^dz;Sp3-c-bvH**EG6%b#jjia(Ccxm+A>KZz>Z)nPEscF2OqStmkD8h} z61{HL>l50*rc41Sfr2R!gG0wN9wHsYjnu{`lG}otT2{wwyJy@gk3=T-OpLj0*4q=i zFrA?dbhwAh^3Ui6`f=7;zLi}b2Rte?ee0tw3r~=mmb#@tXd7GERV+q~Mw7YC^8T6W zt0#AecMXa!uNIOl8g^(W%`D!t+Fd`&XW zRglx8@-CvBdqVTiBgkwlAWwzE9tvMlZM@f>ubcxSt9XKeoDM==5zw(2AP2bHg11E2 zyituc1r7cikLyUvS5Q{*ZqmmY-{b<(p<}72K>X~^?6|_NA$YAcIHHjHuKpf}tlUQE zYhk*7I;R*KAK_}Fw;@@Pi=!XLyFmxf0*@JRhsspqI*&{^y)7Dyy58rf$Q-E9#~o#T zBqztsA4^3Yi4}P-YKx+vh;31E%NQ@fD`b~laJ}ex&0k+%Q@&F$J5t%&C&q@Jw?3N{ z0w1vg$#ATBy1``5vO%^p9(Z4B0l{-k~{0 zaL) zh-N30lnPIaLu$%at1nbnV6UMShX2ClMPrsQG~IPm9&SDO#T$`Naj5MCG4TE(G=ve#4#c=M-rqEU)>v3iZ-H7VdRB zV|++n!9Q}D68WAvk@B2NC%%@UDW6r#9?47RHo(Q#Vdq237ndik&MKg4*@7^~^mLU8WoReoJPsPLnV{pW z3Ls^+pkZm>u?l9mB!ILk_d5s)DNGAjqddubO(7o#d~v=lEL@U(vpU#Fd6;|y3|pc} z@AK@b0z%vhDGNGHX=-VN1OV%jl zG(jcZyj{Vui7T)#yU3%30B%=Zpi%w9ahBEx^bU38U_d6GnvmfVm@{8r)#x&^8o$fB zad1UPaV@p%cED16DS%;rJGo?3Kp-|(x45coM_<3br2Pg;;v%E6tAGy?(w^n=m?_>! z@iK15qH*l}^5+A_Z0nNp_8Tb3ZMQ@AOn3k<=B&jJKZ5u4>Y3g&p7K%{ObCb{5pWN5 zfQw|oB|#%CnVzy1Kk%N+ivu{6fx{Oy)M4CIFPI!LkTMcV1Z=O!n;!zygyejGS2t8& z9g`5A14p57C0N+s12}3ZYS`~%IfWX}OEsqd5NCVTySd>QNE%zd@a~9&;y?uF6Ic{J z1*vrsH4!6RJGE;kIIQNQfJJ>O5i>&biqX;a1sXhju2|Z3lu_m2+U9S^gPf4{g6lfK zuhMcC#V&Ue2NPlKU{rm~VD5)-uKrDP5N9G(+cu%VCDE4~8WsPAKL}g%w?)mas8)qU zM&egnLAIsg9>n_T{QMa&NCGk2_^DhJYjWEzp}R2y#}|?_J!xByvzA-*WSy$G7YZpM z27;?0l^oaUU+~~kZ0m_s@XkW=S&pFkf%Q3hi9SL!cvcY-TL-Cd#}gevQJtEL=j_Pv z3P@Nr{dF^IY`1ekC>wY=c)YE8DiiCD~Von@`2*L%B@CqYjUQhN+e zM-EudEh2F-)Jw}Jm(bOCi%Dd*l46C$G6tP5seGuX`a6R}4w-UAI*+Q&_0!ZU0yZUo z`t{8PtN8bxNI6|AC2gQ~(rU8DM#}spz@0Exo$qq$18F~AS&o}j#)MVRz-07ZpScW{L5_+e_kHm^d>PSlD%r0P-p( zD!?-ZTu8;7a++)oQR?kj0d+YW9lYk9XxdZ22b64j-}o<6=ak$&1^kOs_EpD*oV#u{ zd1S+t5&uo-aqGPRA!6-97VxK z`+JGD@9az#iIv!F5pO2RA(lqVsmm7uC{=ji7Ia^88clr*1Y8~mMr-8ReSu9f@V8Rd zjTARh*dsOR7Q#ytKW;?Yw}s$dFuSd)Fxzp=_2TZ5ifI16f_cVpV<`01I zI|Y;?s@y~F8Qd=Du~uFvuN(_|JF-=gh7<*r9Sp_^7yh6+cw(KrTqa(DXO)@jBw{^X zQ1BooQ~LMayP#q3+x@dZ#-_QwHOMgU6yLejo`2L0aJFQU&ip3^<-S${8|4Dn^7&@GtWvH{y z*DUXXV|vjiOcRq9D*sp3si%8ZN&1)<*Z!#hP`YEWb_s( zXT)lF+ilf40$$Ir)C^tsWEdQEeZ@;bxuPhQ+WrwQ@$XW#f!_ixPa#hV4dBI&-kI}= zxS5yYFv)3Vs%-jZGag=AwupW#!K}OOiv^a90IdNr#$@!=RkMgt9p<6!N@#B`|1?e} z%+S7XCd|)N4bxZ0cgKUkj{2!s3G?*`F*?aPQSb!uiF+-_6rSt#f+Z^7`YU{V_(pWc zKb!f{L+d=y~nX1*`zZX!}3i3K4!NCl=J|?&Q@D?8ZSb8E>LH^=}DBVFrUH1?mJ8S$C4 zY80c_@dM41N>{31lM9q4ShrLj6LEI7^3hrioo4|)KUStSVAPzzqqfbLSvTb;qbm$& zr>2Gb)?u>!?d9doF}kb#K;rc^fKN)r##F@ZP1T0Jt057$kmwxTfmt!P)k*cXB83f6 zh2Gyr@p^&qn8t_K8icJ~m9Zjj!E$_?1zZJ_YFleHg;I~~XRy#B;7u?C6D8R4&;v>~ zNdE&zU=i2M^0WjoCzQM)#+`G%s zZE6aJ37sMPB4zz!BwkA9jkm)xL~*g4Z$ZP1z+8HD;q(5Lx9j)w*+LP>AaqmA*fLNF z9^q*8>I8;)YX2hG#GM7rP2oXkM$yt_3FwMyZ*yB_<|{}z;7**q8VN^Diy31FV{Nf9rWb6&myaG^z0}Kdz zED}egByDYe|2!x!4X9ngj%h3cz8`masNsyD23zHMMYa^V&N9{C#bQkC7Am|uBI+0= zSM-q!3?Jgc;Uq7bV_nMV;1OSlTHAIw$*Qh`%K~&Y7<1y(l~jqBehUy;DW9ToByWwh zNS}88ef#~gUNVr5jGD5^#LDViyf~^|Ct_0Ne7|Ww$h@KJ3b%?SUz!|}qb7Qu?)$r)#WP#=C|HDm?1Vr$qpr?{h}c84c=tA_J=6=zQWrYr?6wZTBa$p zXvPsH%(^x$&T<47+v^&yV~z7KVGGdKA;gQ{z$8LZogm;NYj=uPRVHIeicv<>lnkv;@(rUFEwOuRZ3%9P; z=8ap{i;q-i5BR;`YG1<)E~;^)5XYOPEpNubnuT+~+`PO9qf;=9gdVExTbWpS#pYcN z7ZoW(CO!;l(kOKaU&B#bYWT!c zWUZ^?QygrCx}|EjAXv7Oi7Ngf+6|20o6H4DSXb)NP@v&oF!TH;f>nt3wg^g4B$b62 z4NucZwzzPo@6--ofxZbnd}H)6=t2~UW(!iC2!yK(2Dwi#9|aji9+)>D2l*B;lp+?y@!OEibyR8E;UQY}%!gj;U-Lk>kOP-2oqhxE&HKr|Nwb8}Jclh_f1oTL> z0jD^+Y<~mD=!h_*$MG_pR1TZ?63#&Ge9FjbBO`Vw&0ORL!ez%#%tgJs zJ%2Z?XX*6=O*7zIW3Olr`F^1_XfPCC8I3M)=$Z&2`Zn@+#YNP#G)BHwE zj2(O`Nc)rs80R_Ae6%McT$}eA0llV~-OrAguI1)qMy!Hr&=joGYyb6}8(-igBW;`+mcR5(c=3E$jr);sVVogmz= z_Dptlvz&E@3-b;MOss8ePHui!8x!5|w;Du-#ym+b!lSZ_0RR;#aFLg|t%6x-+S_=p zs^FYneJ^Xhb>9?r^GJ@f2&Gekn~CB+GV)l*=(G3cWLSBxfbY93tto{!TVv-d&79O9 zkN6kG_}uxZt45dU+cmFl+eslhU-3lT7UXN}gZW7O#vvUq#2iv(;p`@0s*o*B?6Cm& zlJSKw_Hjybt;6BP>^G+&az~qpw-(hvM`@POlt*m0Z{`z2dYXSh<#n4h5ElO`8)A&(Z(5Wz;ccu{ ze=tx?l+9YgMFdJ~5zAX}Z!Dojn^}My%6>>n^8vp(^o=1F+Jb#$KNAgjBtmZ_E^gSQ zK;z&(vrQll2eb3ydknH=q7_pb%JH6-lP2 zusOq;gfns*;!*0#=sK^SQ99pw_l~~_(^+*fL5X_6jPvrXL8v^Y3-W>9% z(vUkkXB*n@H_(gz8*-5bXEgpH+XA~=>RPH<&6oPg8T zxZ2o#a8#9;E6;XJyML2eI^%8D6y%_Sj#{NIyP&*IE$jlM@545|8!K;pLgri;w;5Nr@gcwmRMbiPw1-H;lL}So=X7 zQB{MS3(nP}@2%x_z?O2*m|Ehcg@jj>hrUj~Q71E#d34aZNINJhF`BpFMZ$1&3=%4- z=;?K@bSw2H*e=36ep0TiGC$ZC5J)@8c(&1HV?5hE!MZ880{U;x zH`5sV-m9#a$vDrA8-2&#+(!r7PxB!>#x$zDu;t-%o>)xIt_oyVhugl6;5G`Da*ieJ z4!Cs&R~)$jf!`+s#I~lklId_s7=2&y0n4P1jE!c0X>6vS34RT@GS2@1*9pwdIhw{@ zgo|9m2S)nw6G$CCzKy>6d^vDh9Mz#|aSQB7#GaxNqq*nwwa%`rk zFr{qT3d2&pB_1a*t*()2047Xov4XV+SM~Vq2|-?1q1cDQ!mn-P~Z5>>lh(5<5Z zt7Z(E3Gcw0=#!ez^hK=BKc@xKs5h+JuGNf$B|ROpttkK7m&cqBlG|n6JES<|Jujo3Rf)|eUje`d5sZckQb@`Wihz3X$#a~$?daxss!3QOwG=b zAvE7Un1mfNmxYK4%akzE!01$RJuVyj+vui2wr$Hl>9y+PhLYPoO2(&kCBQz@4a#bl zA7W(VnpGjerDxZ_7gp9A3lmV4zc1LC24qHw!DZwH9>@~kh9;ofbS&e4A`~N3>f$X^ zS)5vFMZS(t@2TX})mgcnN_JM;Eqy(k-m(c91${18Blvt|-v3=90MYf?H6&a$u+tof z9#}KdW5;64tn4a;hqz8S*t^P;m{|#t!oeFP?Y?IVlSobD5079&Dzqnd=$~j1@dVt& zf#A<{3cBrEf9ut%aVu$4wC^V#_XDNUKF7w#_4NMsx(UYXH-I^C7$)l~YU>y1^|26^ z>R59`?M?53OE+Ui6+L8W-ZI5=+IEYRB(Z#>LXezJCGArE}_DbBaVckK*;j?YAO zkMwQ(#%YPMJ6ZCF@joYv`%XUmpZ_5{f$RRe$>RUpXj6ALYdc0mLu&_XH$%gJh#I>j zVb?4sq+hq6k@znQGfeGITcVjAi*gz1%;N=R_}HmBro_~p0}kK*knupH?e{%xA;;Gj zsGn|dkm`91k+{Jd?grrga}p74czm5r4p45V_>jR)YQR1P5Fw$U{R!zejj8&OzwHTq zD2BA)Cv-5?=4NC#mbaE?bSfc}Bb)a?8jMf**&8y?TPUF`n%}>)4(hJI;;sb<#l3&J z*CbSq=PFS56VycM9&v|wX`A15E*m%$Gzg(TQ$N3m3W-fl4BxVWfwnM@QByy*A8(8` z)!xPkXz6~gCazW0(NQZZ5Bk@Ieg=wDpq%?OHhYJ1TVlE_RD$a*O`rBJ;|E;ArL(zF zR|cg^HQPr-Z7ogaXB0+&7^?Xqs}#{5u4F#}`MfS)c>9lJMe9w{Bd}R`T_)JLk>BFy zZ%230HKt}N@;zg)mqOa%<bwNR`mbWf|IwYv8k20q2d2m7p6|$ZdQ&C^sLPP!E-cK zOX^jml|&k~ytT^<#QgySAw!Xlq#Z+7E=HqD6r}?n9>9={v}@w=v*l{=^}MZpN)_7SG`$OEA64ZrHLY3#n! z2fs5UzcWDJ6Ta$&+vW}F>4oX(jrj7=#d7%wOmO7!tL72DtDp1U;zn~F(+}41-o7h_ zsCqv~eA}K6tASymg(wyky_^bg45~Booaajg~(h8iz`TrC-bKy?Z|M zv=uxBy0g&CLIKK$+WkdTN=Bl#JYE^)GS#_OJRT)uilN*k!9#&WAxW-1wKWh^PIEzM z>=R;jA?A`u#Vi+!#0u%+MDj&PEV4si84_rosT@09lB5HIKeSYMGT%yx`3yH1eg$p= z0zWjkze9Mu4>*YQMOL5OEVn{VNhAy&sG~zi$v}fQ#K1zWa=E>$hXIymkt~(1R}1r( zwlIS-<`iCPq9%UzQb4U7uMKx$7puKx2>s^eX~~qF#zBjyR38@c&p?v572`+lK}DLx zc`nQlwz@AT3o_?E;(+OVMH<7BH;QlF#}f-Wb6h-CEE@4{NmSZ{fZ{;(eBMyo2`VVi z8z~Uq22_FXT6aV@FIG?RKK<3sz(|w2@CvJ1{Il6zEu_^cLQe75ym�jk@G>KA{egn ze(aGp+z~vN6dG!$Si2`Z(0gPkB1R!O*n;hx5px+J02%{)PW(_7iDh4|0ZI(S)%8Go+ue|P_Dcv z__>w>zo*13Opdnun@%aOq$~~w){L%GWP9ne%)CrY?E2>16OVlw%lp;8=^n7IPnE%7 zPdpZYjj)=wb&a(Vnl+ev{umVW^lyi`xn71 z*$2sF;);suh*Y_6e?RZ{R8wSG?5ZW$Wb%C3%&MC6&ocPI;4Zq7P3qxOn?XqU~9>!s}77&=g` zrBg>A8l3P^cLD91&#ds6)I#HqZ-Ng%$si?0)M_wkB#~N?5IEOio)`5X8gnq)Rqxu7 zjb{E7Hh>qf7wq6)TKv0FzbUHE^fnnb=2U;^`h~C8!O7Y33tc}vgvD}6xJEVDXo;{O zq3LeXnSoMYXiTozn-8iA>IyM~-)s-{g;1fi%3~k376gM1z9bvMHHWGO`20u=g1i~p zdxaZ|(3(uP9#a0G=kNmY2DDg_{^?uA`e5_;>haB!RCIq>Ufod%cuNFQnx>k9+oGq1 zAunCOCZly%*&Mf895W!P&UI24fya6`FRT)qMaibUaH!-OTv}4QXuCG%qsS_)oaJ(r2-ZzxmlWnyeH@}{bhuhV8h{#ptSmK7VuIAq z869DbRNpph%q5SFwN7NE>Sr+}Gc=0DF47qEVImke-nL>Y&RnCzfXS3e9@HxL0 zHHW7qqr_y_XtO~%p>oqFg~>JO^UtpCq4p%_XAM*TRmq|nE3iByZa|3txLvATtese~ zIG)zmZNz2BhRs;U;<3)|vR1NMvNE5-YE^VQ)wft#YqUPZ;=z7cd4hxP{iYIg9sZ9J zd%4QIIt!1_69#{=)<4QbnrXpT2*4+ue^zu|Yo zvVCBiXF3fCrZo!>W*5!VzRD(!W|UiYl}Hgro%BJksGyJ?zRn*vo0#%Wncg5sQf@Kg z9M80vLM3MQ-(8rcq@I6huN-~skHu#nAG-_#_Z`kRCA8NEhuS}r?mZ1_gAYA5TrBY~Z? zYWukr_n=}&*_b>Q&4%argbuW4K9?;v)35?A?_2vh?BY{Wbp`9+>h>?+y#07nGnU+u zu9jivd?OlPD`BGl?4j?FNbKIC*wwq71d#ipv`*NAtOLJ|xAAc6dllhz8LD+EQSDlD zS?k96;@A$^J&4;qnAMOFF?V2Xh&(A7YyaA*8J4pD&&B=f6yZ+QOP~=^&Hws1%H1q; z$kDOY`Pg%CX7zR<|5}4Z?xLtU*WFLrY*?v@&5hAgV4B zd9oW;J$CvW$yjFf%xoR_Xv@;kgqRp_?F}efSU<3?dkPY4?ovZ87Se66FgHJPMlz|n ztf_O9_*nV!@8u&9LJHU?CYtp<`=B!5?cr$PXx_;&xW(IwM(|HEc!^UN6L`BkbokxI z55_!a;2={Amux!zyawD8xmUBd`z!EAc9;@kBd~@|w9(#u58w?4^v%!ggx7O%8OV%} z-gASpP}jdY`cf)-@MT5hzu?+i!|gxi`jZ|Z*h^8ei`FC}I-h2b-on7PEFecLZT!}$tQd^*^TAXM^jMFx!XGQsL&1nXG zc&CR+@j!6?9_&MSq|Mi`X&K#a#F99wtzAcu?!&I(&~k%~Uzi;MNM40c3Dn?Vwb^&6 zyRL(%Nqd-;=4E=7PURXG<9#d3l=?|V9cha086R9q*YhA!T@+Px1%o`w=5mNInLKx? z_V#}L@lTjdtz}Rj$Q3Ho!TG6pjsndiT$3X(lzvp^~C12+2 z#Q(Is)%(f7)?7xj1@x|JP>QOij^o zOAIa0^wy{QhGD&y#vN7!uK2fBv$pzgP;{CIbt~jCv3UqUx7Li0$7+8r^Q>ub5&u)4 zXTD+ZEC}Qnc~pr^0u4gDHcVOWT(qhQ^RmRPnSIy@A}>(69am2Us)*`G+X~o+t&823S@~Mwacd|eRFEij38dV~7%R_k_Pmww zapZjaUiNf~L*&&cpGfL_(4ytyxj>HJrMGVqbqX!on@h=C1&!(I{2M_TFa$I|-)m|3 z7vACMMp10Ya3S{6Z|i^QmL9c&wS(-TD^{@`O>V&?1rJr@i8Zhg|fvy5$+d#1Q8nRg(9bb;defrCz!l9D84Hnwx3_?9LEoujUQ^o((Um`hMK*SS{k_JQL*nCCIULaCEBBm}2Lj zb+x|&?E|>}X4Y3#bP9K*Hd@1bNHLXVUCy`3Z&qS7U*|y~@#ri${D{&!8S^7lmz9yl zupUY)$uNz!|MgV1dwctqWa*n!*ZYv0I^({)rtDi+`3dh-egzEF)hehcmOgp~-BT2R zR0&J~q((t}MDBM7^ZwJ9X<)9x!bP}K zw~-7-1AAj{t7sm2{JB|TmVf*4|2_^@fgIO8{d2hmVE>)w)c&WMb1`>zH~*LD^It4( zwYR+;?zs2Q)XjtW8wnthN_z!Xvk^bj6QzXr18?}AJJot)B}bH-QXggf2e$hlx;Q1R zbLwiL@wE&`|AGz0M<_XMr9&^&bwf1kKxHrJuV^pY@52D9xx#o7%u>#tCGoAow~?k_ zeaby(tdr!_w;-*lQecJM;U^Uscq08G zNI)Bt?;E8X&QR=Y{&;_Yln&*CGV4!8dj<}H1eksv0^U?1m7zQfPgH^C&=GFS`nF&D z;8umLeNTXF-dMTN3v8Xg=lb8ykFY8 zcRhVf6AYD&nXTT;Ob$W;Q*FrNDX0lzYQ^G z1g7*5C^=^+h5IPI=(fxS)TFee^GDL6w8T@2#54xvjyN^B`mXb4ihm)^_HPU4)v*sW z_K*wbbtmR6EC(#lwpt&ucgYiLZ&&#l)9@$BTS3%G+I9$Na5-pmv}Q``rI4;sC)u^| zCxA+t#ZidI(n183&t*Q2DKCcvHkHpsT{IvgFCZXJVQM5lUg?1use+uGwUlnzfXRo| z?i>$LAi8f6mjRTs1f5y{rv!@hq(6fK?0fr!X_jNVlYrSlQTmwLdbpHnZ|k#jNE?Ayqf8lgt+Z7`vdwZVwt z+Mwa9;2|T+H^YHQPa*ExdX_KV5XgfdEYK^NbmGXVn~B9kDe?4~SmrPeMPr3klL|QJ z0$wUIg~ZnAnBs{UiDii`*6BiHrQRr|HfOhlWpR}zr4)f-_XguQ6t)UmkuA=QQk1}W zDO^4EJk0DioxQCb?~2x8Ry?~kj%*`a%_U80OMtXGT$AAfz${&C-r`VQMY6{XMVqyJ z9w)IvcHW0Ic4S?p!DPmmB*Rtf9~L|Fth7?Eo94VYHf=jABcp(no7+`BcR0~RD$*jo zvC^bD%lU^5u(011j9k>uQb~WEXp+7VQdqe_$5G;~KhKm{idhn!J3YbP=-f)0<%F}@ zWhOd-{M8Y{wBc{Iq*{_u#?zh#+|L~XU(Kw(AivU;*<5~F0Nkz`iH(?07# z1R4v99hrBwN$#w}ku0Y(ljZ9EKCiBi%fwW|#B7pSe#?`Q1aB%#Szbs1QBRdqg<3+i zS#AVZ;>AZ$^H78~D=rm##)+}m`+oRnCK zSf9&}5#L2@=}IGD-8+1U0`CL5See`I@lb4bIi!hRWai4lToM^;^Tl0gbuusGnf?Cl zrO^|?M}=y;`+l`q$3dSEHU%K~=dEZUdtg^aJ|2AdF`=q^?zIQgc(J-#_)deNVX}4cBWN z=4L>+;Fx=l$_u|6J){#2=TS#s*yu)R(kO~k&IEdiTN{MksmhrwLCPRkic%HO;967x z8#Y2WX-~ue<;pImA`7Uu;64Q4|i|Sj2I#?nKN}Jmf7qlap$hTFT=V26&M3t_j20I;qSE=b<9j@fo zCq5>g^J6EHvb-W8tJqQzu<#H!j^RP%)+XfT-CbAm5+w)%TDuMmOh1WcSm|uR6zBn` z_$fRz!uD!`wme9}WOb+?FsDN4mCKv7Uy7K^6eqEo7+{n{<)w%r z-M%_->McGDTIm8W`~Ji?lg^PG;};vwE6T#u)9Tw%s9cQ8j*y0rmBm9^rYLS&YRtHb zV&z%M#8N1oKA^t9n!!hmB@OGURdv-N@L>*VU-eDQw0IRJ>f(4|43=7l^qb!8Y^0V! z#6?Kq#^U=a!V zAmosgl|NMUt}WSDmbG0U1|RIDf9%5AVLoFBJi~_$xD)d>e7cKA$XL^uMyXrvTq?jdDvh#6%&QlXKk=B7}%)h);#0DbZx%F zVrMR(`ZLhO*+q_Cl3Z&%nPa>NBM>T~T{%B;U*8JibQ3J(N1{aQgW2TV6$mEhm<$yEJgtX|a~{|)57 zzN){@H5N4&?3Sz&VV$-Y7&tw?ZvNdJK^F5L30~7*3M0#v=fbk5IFDOXgBnW)c#-qu zOzVrcD2Xm>RM#rMRAKHhy2X@nR%)Xw<;7Jsuewv@IIHfARYf?3294BNnU}*IHu0MGg{XQFl;cY}< zw@*Lly+EdVm3yji{zhJ}DYI~0Xs+u9d8%%coWcK=VN5N}L6f4EGz!^}QP&1h66_}6 z$WyhzVPQegEqlA{PA%cD@D`u^sN`VsOoIED7CE#I%GCHtt47XW9Xbq^6zV{Ma=$3O zTHy#HNZWoPmi~}@3|?uxzD~TUxawBO`UF00&u>m>tj=Y==Ihh6c<@=BQ%N^`EX=4Jok@^IkG!O4=M?DgZ$ zNXL@bm&(KEOHrz)EXMnv%zJSG6_W`3l?{R1Lx;)k{$rGC} zP~NkryZsyzs$-0he_r)4)L?0niWgdJtbp3>0{eUCeA#s_um<9{N{D|3&prY;Q_2z%iA+E_mOwsT0pe$!UxDF2jp%0Nnwo00B`Z_7}w#GZC z^Lo4dd^~WhF@_?76JM+Fu3|>yK+NY>JY>F3ZXZ9T*wn-uj%92FlcW!{c7|Cv8{cOj>gnY%_vV5KPWJ#{ajyL+U~%!OITc#H7==fCU#6*L zNAIk+tb6FOv^~|$lnU0n(2=r*-jOmqmIWv7$JnLuINK8{n{V!EvxZ>UpV5v$Y(wqc zH?#9Lqt01a%lO6_6yDlf8N1qHSH7iYPqg-vyUWqSqw#_jFYiDS?6(h$UBF}mmMCJf z-iu6mXX+ASkl`QfgGs3J!!Ci1!0yfRfZD_07ngg-LD)CVR zlMqsMVbp{zkn)IQEKs0rYkCc_kvWMqpH*n)v!aY>C#{A2y%#7S67` zr~GNrod5u$uG=H8V!*XKwnx%)XpUYyp+R6MzC}Jo$i9|iQc6dWnDv5W^F2j(vYr%K z9UI+&iPlOnJt&>^31@S0R&wJkXEQ}VOBGPomS#(B>}8n611A*HQCA+>(3?@8nr>(Q zpckb@KCSJz2H6Zvz01~HZr>qhv7F{#zdD5BZWUG=rr`yIypIT@@t!dSqIQR1gxCtk zzqSjGN!CMVG=z0IFo5djW$esF!*t+*koQ;nlD~fF9&wV%6NUk8kbCcf+D^wSVpRcj z?Zu!!NmdV*dAct ze4}8;v|6OyXO}(#MGsWc>OJ4d@H4Q2R+eW!EgL@wJ%whE8z1*)G~gl^jh%0v*p+PgVq%C+Q2Zk>b^s^4da!2mkG^3px1x`H@^48;jo4Qp+vSfY`*=Qi~D0$JGwM*_U> zO3wkeZP#hNHNH1v4=N2H*H3XymgGJ1WO*JV87?YHol$vGGMF;{@H+G}KQvsOy7BA+ zeCqcE&9JYS>alC$t73o6`9(vg?cVOC;oB0)pWTl0g`0^b%465uj3BL<75q-MliU+> zI}cESUl?2{vug7zo*K~WZ4RnY&`OLUT$yW(SOe^qX_w*9(cfz2D}yatSM(VcZ)~Xk zbm>3xXYvY86I=FB=wudFgKiZLg6dI5JCfeXO#6$t$I5?fFkvKi!Op=b#3Eq_wtHbnG4K8~rP zw+KFpo=-YAg0YC;bx+M0`EdC>_MDi&Ug8;yo%++(*-BcZ_q2=EIi+g(sb#mM{LTJ! zZ$1BfVE(FWw9H!PcY0qu*aXK8!-=qe`M3D@r(Igj$(u%u<0i^-&hG^hp8kmpXwO%> z<1MYKhXH8dNrrF{(>`W|Si32ai^)%Q#cT>sol=L(i3)w9{TE_cMd_{`0to=% z!2NH(!T&R2>168S^#351U0vP|c*E($o2=MfAfVtv$UaCkN~F|1RljUzQcR^tDF#_6 zr2k}3-yq=|;qEK+!q2iIi+QBwW~)||4YZbIbtg8sjR9>>Noy0MD;d=f-p;Z*Dp$`p zRT+q_qDDl^jjViKkNzUI_@wH7xi0WA1q39SB=Xf+m3Vu-o?X`dHTU1T{tFq*4*;~W zUvJH3n}a+zF@OXW35)Ju*Y74^wY6y*!@klyL}?P>r&8vMbX*)Oa~a=9x#CjqxuMEv7x8 zpk0|yCIu^tFKV!YPh-$!Z~4$j9`+>+c)77?X+1LDEyg{;NgwHxHcLKO5EcLey2OWW z!zu41y^O2kKAc{t8Zdt74Z5lMzi&DH9*wbGD=q}r`A-&mngR$00z@47eV_aMja#_c z7N6Kys7Z%MqKZmC#o|OgIfN|rLOVg#Q$yip6to-=9ckJ|ife$?2iwEgF8`{Vvl2v6 zN|Lxp;EKCgqT@oEwz+O-Q&FB9zVD*FW z_2EuYlbjQ%MU+0$W~olaksX8nln&~IrMm>pX8ehOPVi7nV1bc>%iTBeaI?ECfFV_l zW&+cl2m3Rw4G8j#gu1&=1;`6Q$qPUP=sCrqf)R8jCh1J~bylk(F;;t`@mHUqzH1SV zjcE$0kvBcI%c~(*HZ&$cv#Vp$j-%Fc-BRCqdc11E9$xcKm{AQ_zpYdKj$9B?`$@rM zJpp|S8bm{p9 zJC_Jgy`lXkD-KWfXA^kxOb~rOs6TqNdC1_+dPW0%#GYr;D0Ec#@Lgma&M%L%At!6< zNElrGR{+3?39y}+hyUA_wZ5VCK%Oz_BYRDz^d_(Rif}Icb%Kz+3@Nkh%h`(Q^oW2h z0EoJM;xDb)bj6m#_3aw}V=lA6%6XObbj^6o&N0&OJt1(s-`$1enF$_0JJRBn)G4Vnvw;sB?;?=Xd#}9VN*(lEel8(maeJ{u z|J<`tVu@rmHc~Jsh6&Bq6HLOSUo>MMdR*vd%ewkl6_M zQOn1~_FL<4qy`$((C}>LPM3Os)N}n7k7hidK5dB8GAph`CJ78@8Pc3sbtI_ezu{r} z%4KdvL9-rq&En&Tmtfl@6*|OZjWfquTE?du4{94=qz5|S;4sp^|4k>s0j3dr3+>4j zM8)Zf=`cchsv)n8s)QvTjE2_Y?b^d;n=i+|!I zAV@lTHn_l*u|pJ$$-L$O9e*qcUflUS)OB>#hu$Ev$fpnBOAAChG23V?z3rXg9RXrRW zxU!_AjMln^OWCiSzJDCAlTwv7DQHVTOd-@?C_rQ!aMuiCYGNm;s*Lq@mL!rDy*+l{ zzsq82DRDiml;*H3bRrGTLwi+4f@)#Mw4!8~g4sXRNXAE<_~BMe<;=t+4Kc{+8HB(+ zXEm=vg%0A9f*N%AX0KvxWtdHjlbi9YeqmucBRCX8Yia~z-4+D?=Elc)?ki()7%0a0 zZKcpOwy--Qh)9=ch0%XjYu?W8mfi`gskyyFEmLZEnk!=c*Y$y$i@i5sMYJw1n3^H~ z9NSxO1U3>x(Wt#LA%H?c3mF1JOPAgNM{-P6-fPSYLK%M8h-?AVQIyB2$_@mzeuOZ` z!zP4}*AZGDac_LD%7k@$CxYtpC${02sfMEd=#{8$6uy48?h(wE@5YIPd)$d+YaheOR?DV%C-rC4kO zkftc+Ae3ap1#hrLK?5co`^V1W?sPyhMoJ2X_SZX#M>60YYgg@^C)ErK^S7FgMsHSd zJh6yr2u2cET5Jk=ggFGE6Lt%{Eo3&aP6lblSWp;4aTj#$fkEUkzz+u1mH~~scF&Tx z)=HeC0g}u>82h=-=3+oB}eYKP{^-s*O;X(<67Y+i}Q0@lLJ$l+#S4= z{6y=Lc+MdGBvB(=JQtHcmdBVfBpQKmT{Uv#ZZn&Vf#EAzMccjvV~4DfapM}=jAygq zHXNzn3QA-u#0i?zw`zqDQC%Ss2$Vz1mMWidH(NE2sms?=I%n0hf33wm5=y@iVS?{Y`6wn ztHfv)MXjh-7x7(mqcO=77nX@)bQo1KpoQTBW&;-&{Vi6018lyayoWMkfdUu>YsWW%v)?v>_c2N7d3kpTbkOsEQs)M96JW)AzaFKJJxX=XlIX7 zN-A5Q?Jc_IM1Aw{m3)!&>mNM#k+z&i$X&D&o-6ZYXC+%f{;wwc%%s*be7~#1LqmEkk1M^C z*gSNaY(jNNwQ4wDQE?LzyQn1Ka!raU2Q_?uG-M4H?zv6qB^L+#L<>^PuqbHy7d7z{ z&!fhX>7?L<7AE5@TVPr)!bm+V3oED41uVns=ztbh%)#pb+A zTxv^(;kCN`Yu(^P?7sc@Moe&;B>f~Da9k)nVWP~745*zWhiR3sPL&HGJ&-exw4

zX7)Tp!mH@)%f;Shc{8a(14)*4hJ$*|R|-uxnw>fnvFu|Fe#qPr(TI%&bZ*)@!trG$ z1x3%ir~?$&rKBdgk-+WaY2dsi^go?kf9dHz%d#C!HHJz$rwVb+hrgpU{n#r?;O-kB&PlJL`93@w)EZ-ycA9y%iMk zs;Hha_ApDghh78pw1QUH+SXPhOG>!RdgW{uH}qoTs@Q#Vcv7a$k1BMJ0C z0;mU)nzM)*qqG01+<=Dbk@8$O9CB1;#`*#RG)2Jxho9k|1KCzJ+*fAz4qy-4G)|k< zO0*JM(X`b;_y8RqrZ@PnxaxG01(@CTfF!K-JC(QupT z_k=VtFTemkm%dgoMy()xy2o?v%;^J=hAdov6XUXy)04FNIwttYn4~7ry zFv$8k&u+NEzC0ly7IM3ER)mQH zY~k=23|;DO*7*lM0~6XkWxJ|IHQX|(QmT22^me# zM~_?N3p9;Q(j*IwJ+!HA4kUfJVwgNupzW!>Aob<8$I*MT22z!uopAL_ZcHKdCwIrW z{@j^07<>DffU(E6>xY)Ce!OX~-v|HzdJxHm$Y<*YdQZt~UL0vlUro8$euSfFV|zQZk)DAe6H$O*St1$woa+~5p#!P5!Z?M-(m8zH;r=*Gduyu z!ThsIj)9vq2!~gE+2pHg{pgH<03y~w0o1-i4O^c^fQJ+WoeQ6_Px!7SM%51lZG2h{ zM|K-SmAYNakiFGzNA&GEhvFkcjbqS`7e zMx%+51`%`H>~sQB9R?3qe$1Uy`yX)bifN%&oUMMa8Q%+q+|BxVVkfeYYj-Vr$UfWu z&S!81|3+1Z7`1cZ)69D?+L{pgtnJ}8lS#d+?GS9{xteOrr(t)v8DL>a_9Lim5xnEg zt%LH?O;$y?jS!OWgJ&cB(v7HsZO;qbrJg6-*qvvXmZ6Oh;$nm6CcpD0Uy80~Sn#SR zJBQ5OJ4R*IfzPhrdiVixdR5MBCBj&TKRd{tkaL*Bnr0rsMkPZ{=t&g=0cp&+9_yCmXPU64~z51}$<$zp-T z2ysO^08ptq$RR^L7-U+KMXXiK2sX&UY>~)Os|bw;GtVsxhJhz?A8XOL#9gStVlv3W zdQNnuK$Fa@tV^B8k}4ELgU>%&TvO%rJN1{c62~yjzk)cFBz8J%T2mWNNS>W67LLq3 z=yJ?gImuns-{=;9g=6w4SA+&)_$LqxLg1o}mF{2~h{s^5N{Ii-lrk^FP2=NON;=;< zF#k<*u!>O;UtEVIX9+sw(9xe@`nOOtL(U@$VMiUwx0P-QF_gG$~~uNjiqbQ-op>Y z`mgWyQX3;TPT}-loz1@mnR)>y_tZstAFY{IBla>-7B}t-lI<18AKbry6nB-Pj%=4c7;G zBjlJLMCrv?x^E*LFeo4PhRF$uE#!3NIm;DEcDkkM25_0$k(jO-8hWQd^Zc*eJY+0 zxIXf_N0Z!O;?Zm7w05XbDpsb!VL)bPPu^bn%A@j)V6=#g&Cxz!KIaq@^$2}n9_PQB zSM&!>mi?KiiKZ7zJgFzvEVT_&v)nX1A<-(XH%n(=`|#IK4%g4X=6k&Ds~zhH3uPp0 zuJ0q6B$xipvomJ_&Q1lxYlSGJ!bSyj5*Bwp#P}vR1mcH}W-1#f(GYhDPh@rnozRt| zvq54h;DR}wl3&z1wXn513RZYwtT-@KDMa_4bh9hSN<9=t(YyO^@^smC|=ci0af z?(sio%Ap?|;+XV7x7^U__-MZRW8da3QXgI7CG3_K(q({66D_(HS@?;gFV;o-LE9Ym z5Z3s~w|8YLg#ZnnNCj^8<9Fde9=w zKU?awQ!>hGn)2Eu3p&wg=g5pwCL{dwB}e3l3sJ-*Qm7WP2n6>PqLuxg2Nf>l_A8jK zoz9&#pLK3Ri?+M**dG`QGQ|oiwj=7^WkFhnxOd4B;xY&@89b684(XzW6~?k^j~2GG z;l!Cjs;E9JQ`1~zI6DDAMtT*;t$#rT=`-omL4y%pDBxr-3F4@gI0?N*OT6Y`yb)jV zBX#j+aUu#~q>}7){mdT1o~)kIjX8v1$NEkG0GS$ z&HXctFyWVMf5VuTZ1JG0Gx1ZDtsl!n|-2r;WeW#{vXBh6Q|<1l}*3o!ENN z2x!H^F9%u+!#PU)Q6f|N>viP~hUYYIT|T=@-%!lLCKX!J^OYhWa%{EARLBlBORZkp zA0Ip6QC0E{N*owP;&nrzkWJ>Y0$8l8vZ!D@vy_r+{@sGgw;=bSqf2-h>z=|&TB4w{ zR+tqLYD+?M%%Z_(^v^w^F(${=k^j~a=VU{94BTX2UIjs^Fg&qPic54m&EG7ZHvHih z+)~A`%YPRjXv6yOxX<_X=~U!O#i9@iZm(`u(u+hskP00F}zeg9Y@$KcZRVs)Pw(r%F69EO?(; zrD_9vtui*&9wVz0XbDN>y{=xpTh07DKHrYMj2?pnvqx8E_iZct@;Wc>B1IKbVP`V1 z{Y5eBSDqIh&(g7tPXrKJ6CJ>aS9&IyFMfeH{#sON-8q)CC_~5XK%RXy$tF9J`ZbvhIhCxv$`9L|HB?@nb)-};@qd&maD_hADc=6aCcwusVkAdr~8CfD2saL92e}|bV99JZH zm|PJ{A$NSU7xLCB%8*h4EGOTb3+UN+ZAENmlopIjRHKw3F|uucIPdgWqwrnx&1-*1 zxhko}kJ*G>hu_Y8D#6+c;tYO1{ChIYxh1PlaU8?`K~ySmxrV^$j|#bSD6cJ8SH62a z?28u&`(5S^2(?wNqkd7NulQK;4A}9h!6KmZfqmUu)(TuE-sHRkFLH5BlrCv?yeBS* z%m^JtB@RF$D`lE%)hXC;==7$_81Do>@#aN>AnX=CGL&8KVubO^*~wE~<&A?hpExMf zUG?{z*IfPgws*V&%ol@syEg~s&PbAl!d2^Lb-r@CIp%Ano3d zJq5bUun@f))07Tzd{V_Jx62r5s} zxeKOOOS^F1=GOkLvhR_SZe!H!62?_-3E~xh7y1Oc=y@F1Wta|3=0pza`NDMzT=)~q zKV|Hc^r^+M#CsgC>+1}*fqD->dYBfA%PtSGB(*_d(fA_1EmjKZ`|K?-jBnNnEZ9*+ zi|W>WQ^;~Y?-;(o4{9O_nTBBMnUY}Go$=6LpdTDP?{q$WZt05^M2?p)^8|*vwGdM> zQ*!#;?zCLKC$pi_T5|_cbET6L8m_5?Qwzaj`*086uQi^2U4h7Qgb34avbe1`qG7uj zqLc!UV@Lv*{fGOmmSSY=ib4gnl{6n+hXd#v44xepZfu+-` zeOTZU8&*&jeS}k!VoQRlp$9_=ZOCI$??E27=OmCj0x3?^7&XNPJ14*grdn7=yLbl1!KxAh=%C2rIzZWm+IHlCltxoB5q z`{N*`MSIwuaO*m0joZH4=`J~1aOD)wZp$GhQ=3!gfU)J+@~c^(i>q~xTg{4~Gx6_| zmkTF)C!YrF!)C1O-wAsH-?Opo!YiWn7(QKi0bRQotW2n}otCxO4fu7JFK+A=6}Qze zY1@AHm`!VM8_xNL^uP5z2dh?Ixmz#)LT9lU(V2Q2uHcwBz!$V^F6qJxTgx*yGl8|i z@f!+F*hb?!i)#~{zMR?L=WN3e{LMgj%;<)KHgnVW2V*Oz184m{sZa!O?qI-} zCxW$jApK&X-N@jJNjT!RcW%%@zrFcQ?bhse2x!j#E%k{;z$7-z`E3bUb^1PL!}VZy&zA-SlNY$1A;$$i0s$y^rR4e=^>4<{Q0_UOcCAW*pWpm@DZ4He1p>tzxsKl!@%$7#^X@4oA>6M3+NbZ-Kp^qw0^5@cU~@&BIXp50k~YomKft2d%8a6R_kj;nQ_ zhjlH!pJ*U55RE9^@r#Oo`KfP}Z>oJmq3bwei3bv7j^+Ji6OC*<-F6?ntC%X0-2r|R zlsvsEu=xpd6wTJ;svAOrMH4LQia{`86!&<)6>#;cxBb2UGl#n**?lHtdKL%D@5f-R z52e0C_%D>cLwvjDya>Otq{!DhrcWVD{FeoND5yzAD@YGAsM1A$gjdYLJb1-H3i<^u ze-MRg{pa?-4(*gF^fgNMt%dNf^FCGLmE0zdr~g6!vA+99)meWDY#yV+j1!yR+4_WY zru=4)lleAP;Z@A$$w%+oPOm=E`$`{Dr~jlXzRI;{#jXRkpKd{}%)^~oLR?M5;}`Ob z`IaF=e!teRzE(q9Kk7))Jv`>ahFMQzGTUcDRbHxW85QAe3^DB@54jmqVEUz)6!}q9 z+h%Dssv?6gxz~%5ZA=O2f4Fl@KUjh`l;pbsJjkSZO@_yXRYDACe!C4+@jshtn`&;E!zKRe2euqD!Jc zztDhBoD{^KnsoZ_Xk{`VE+dhbF5B92qsdt>zP>zrltIH4dQ}4)U9eBp3xj!?f65C1 zvS8%91d``wzOwu~6!5~tUJN^=QY-eW3h#*|N;KGF z_aPCIrxO=3`r!>Ex~~nitbgb6@x;QWN%2~RhuMJ7z_OVgPh6;2( z#T|N{1_occVx&*X`vl0on_jtH)sxOWM8LrlE%GKJ;osL)j-1y%3!2NvTUNFS&h>IM z*6xCUy^ZsI987NBe(pHA>$gWS5Or$g_;dgtlRK%#KHkR91z(QqZ~JZ{;lPK-&wIuK zgC}P;khL8NU1HR9h-XzD_Y$B&R_XL~ZUa*SBZ*Q$^V%Cx2Z||?FUvw4XyCaCYuWac zz+LziE&Gb8Ew0L&c9q}r>BB4TM7a|>&s~riN!nbA65jt!ec;44Xa-N^B+Y;9N?4O*BgqvE3 zmL^2zl31nX--h!&MdINh`spBmn+lncU0Me9CNkLq^+9;F1ErYS_#l+#=;n)Q;q=IB zpgT#{=9S=u?7&r+44syrQ%oCEHm4rbeD;(d{Q7Z{xZiVz!0#ZQ-2+87G1)iv2?q=bOnLNlS<-fPOUo`=}U_*A1wGhe#wzIGAA4r;O&#A>_M4Xgk!(R=%KI-I8FyS z>$m^R=5=*@oo_rco3faAHITdwESA|0l{_DgNj01!U@?X$eEB%ikqP z$v$pMA`t!%eMyU4gIjCfI>je{@}+iWd7m5c1sCwAy>&N_`cysdi%4)gHSZ*q_*r`U zgW~!N72F@f>pzcv59(LWUXhvH?eVV|K!x$r&W2;thHKMDy3@EE1Y#6sDQw} zsBP43VZd_>VVGcC2skJ*R#J7dYj|)rq+9Pwy6Y6ZU~m6aoWN=r+CsBSwYQl5+2JgP zdL-=&rOZNg60Iafq<%bIc?Vn&W7V(={1L5Wxl*}SqRXh*SG>v-uiJIpH{VS%#cfYU zKe&Uf<4rS(&U4Hpy;!0G+D_b%Xv81NUOhRFCcpYU@Tt~Ya=1vx-al33o98g`Cw zH1Q_xuS*!Ee>V=(%h~wzh`#@j{3j#}2ncl3ziv^_=NFUX6 zu?Bxm#E~@%J32BbDA~dxTDoWtqw+71zQl4Y-gHQkG)wfLbV`yYLDP(Ue@E=|mp;tf zT8tLp8zKO}V*3N0><4YgRskziu)&c435}?o2kS-WUG^=R@O>EP9LPsh?&ccSDRKaE zBKMtcIwPs3&h1er>xO6$ZaLLf+(~f&R2I~CYF=V;gI45sy$v3{M%TkQXck{#K3;k@ zUKqgTx0}ekL>VAlIG-+WmhdtpWBe&`DA6M@mrFDPzaMKBbEurI;`f6!&7bs6)Q_4q zsdj4qD4ew)J)j&2Z6nI$0XPo;yQaQpIDCxpa&)vOyl0SlJNyj12ra1$2N6U$)=qj# z8B5ys95$b=2)C$zq4#(J0MeC(wn47h@WVIINe5VRP@N6}*a5Y|3~*)cGaxYjLXAxlr1{)SC$QQb24%aQ6GB*&od8mcV1 zC}|tGlZ*ZsC{FfSC;a@IP=vtEgwNS!6+^`G{$23W>@fm{o@T< z^yuhCLVX6aC!>xb==UV1YBq;C-E7<({9HM5&SIo(M+jL~@TpZr6*xB{(X z`)t)eekS2c%@Q>L0+5jQz_ruqFJ{?nKXbi)FTG?6LV=34WXL~3=TzoG5l7!yBrMe` z2dQ5-2b?v@!3@0XKAkpg4;L>{?-vGKVt}?SuuD}J2FSqyV;b^Q56MhP62GK=;_UcK zfH=TdiIF!pmO-z0Lev|x(rL-Xuf)%n&!2pPxRJYZv(HY^{w9z_;G3DcZRnk>0#?;g zDU+2ef1EoZl42Warl{tB!zrMda`G`W4Un~#7gk|02`zo71E5iMV97aP)NIiUi=d55m-!!k3ru0&N0; zJLpCuq~Z_DeeBz}d31#^R1XV(keEY$K5a(ysJucUHLd#$lDTngFjV^~Lw8Dqt(6|g#^s`{O`*^!Mp!a4ZxcjaAa z#B5%LlukvR(Y#~9*aQape-d&9d zAb+pWUh;4_D=vGrkzw5GeFfj`yAN^^LAV;zx~{YQ`$-LS)1V9$gdG9tCT#Lmr*qBx z>T*h}(>os2+Yj_1CfR$VRQa&x@8y#3619pn$cBHkQX%>@er3M5i`G+*v2UqRLXMVc z37mplDV64py_JVHZS|=8rppo_0%j_u<>WKF& zaFmvq()!aO*#!#00_VyW|H789N9W9Ds->LD5W%T*cUHWOBWXQ1p7m?MG>U)vi6@|J z+w|10t$Uu?$GqX*#*39#`(}n;;FPUf=veIcz)NyeB%q!tO_xS+rz&kBAqhpYl*$~1 zsd9PNe1p55GS%y+AUc##7^>iqGY&L*5d_i@EhvIzpENa55rjaA8mQ!u#i5yg2F{V$ z&@hvu@m{J~yYyb;`btFo%7R+8M%?xhP-S5nP-%610K$ByKn z>InUY$r30Udt8>SGer9@Y=u~ zz3T`6BQGb1@6GN#Iw!lA<9b; zoU0upC;X|lCk$lyC689Z#ux{uei?SlKyk}&J;?kh}hE&gP8VsEZ#xxfCEJ8Qyq zjs})0gCFwj%@xSeeJ3_bP31!kFI)n1(Q@y>vKHu>aLrXSKVn$CsxEzVF~?L{WS0^k zEJmL8jgs}&URnQ(0Dj2iqbjLZX7bH{8Mul;QR$DoI}d6DH+9oX!Xl<6R$P>k0Z~;O z7sBk9k_-XO43$7T8l||h42yEo?kVVE4l_fA}>;g^-b#aj>!6BC`7#yiBSCOJ91h2?cx5(05f}pwl zE~XLutrT0%3aN47;9df3Ea)1LF6fm~(3^HLUtSQYfu*JU4Ju@6VyATe+zbk|QZVRL zORoWO6Pj7B8CFqe2@(eHCf101rf2i{CTzwFNh@%WVu{aTP3q?0?lHzpV&8+#BO`Vr z2qZN|0ucTZGYYD*cD3{7vKwhq=x?L!SLtv=)lz(fVMUpS=+2poPT*#7IR%g2SlRVZ zn@4M@GsIZ@gWfyDlwP=M6PSCW@K7BbtT8(_1@v;>?7r2X9G!xoY0g~@<4Vg8a~e}g z0V6I3`l>~*#0#F(9v`pGNSl*?w#5HzN&i{@`2O))lDRYSn$sNhv{$Wt6BF$*TzzcD z+w8VuzQYaN>n(TJ-il7in6w?5OijCsecu*bs{X95F~-v!=IE5O;mD=;#PdtGX!ktN zEUy;b5-+f4jo0!140iCLTkk=!`};CD+pGNaPkt+wJ;iwV(&ut=@F`>K>MOG^7v7Hl zseN|fNIKWQ9sQ*+yorji0wDiGC0}SC$LO)q&S0-Mr&g=Ze4>^s)RHp^Bx7mCWU)mw zyb`j^%EiIJL?q`dNv?X~LS6d$*kEB0ZfO7n9a8e$zZ5`x_JXQ{VL7@Q$E!tcq!1O1 zoRb{o`FnsK291r-n}M~h&P@`;TE&1p^tx{%6-9qrg~A)die8U=IS}zMKSdebjgZFE zd9D)G+Dp$_Bs=uZM{!nV{Rk&;>6uksMOEtJ+E*P|fz~3lb8$guRaMr|Re^bDLhYf` zhKAZheHYRaJ{8IG$$=oIhaw@MURA%{D>1K;F-wch%MF143OS@oj`H7L!2d;;#e-$M$1>k3T@ zWpPJaxqcZP@n2-M7YBSVQwv?UQKPBNRhDAqC7O*!HwkE+r(?p4INb)V*!afF8N{nm zt_CV|1NE3M+~%}zE1?4_)toOYSh<;`6v*^rA^Ss05c<^bGC*0%w*i0uPrVS2nSZ5Y z_UwmF<%et=S0nv!NZgyZ`35m@G1P_q1x{&>K6Ix}xAR5AGyU@2nmqEx5`7;-i7(H%*U4MGpJHimn6K#~6p%m7}9P{dLXvo1Cr3oG)sPlI^_YHdZy zubMEolBNF1;DD{~r}b@v)GzML%RyhU@T>md&kU{tsGVl>Z zw16RHfuNH@Nk^4J1p!@dUo)3lRBWRtq=_nP5LGJ^3i)USz(MaW3p#9r^uIt0GsOJN#fAKorNND=nltDVWv68eEbl6aSGEiV&@v2pGY_EnZKO}J1+DEJexCBbvtkW+^^Wr9TjT)6)JWOC-y!24&y$G-!iC3 z|8#JKF}Ap~YRQz3M`^6{=@sHYePtNforQqzfZi%tO}l&V57zmx!hr}Ac@*8?9hTYQxUTFMBo?@ zn!JFa8vIfriHiTJ7G9;XktR}}Kd4CPZohDZ z`4N`SL7VWS%j&tRA98Lr{Y*V1s2VmZxkV|!TqjyawAIV$PwE>RhqMhtOZ8i$Y9uaW zmAGUjPGdfSx52n+2I^V}GJ&RYOKo&tpX?TYX2*Z9c1|&(MBkck8>el%PusR_+qP}v zv~AnAZQHipJ^jz*zRbojR~`U^m}CHWe#;AlzOz zxfaj-0FoIN!*;Ycuqa8Qvv@&=3sgUjqZ)@U-y2GdW3!ZwE*;IGkBoYyQJ-U< zkFJGcp4M;!8BWlH(Qkx}{NjqR0LkqnCKMI{Mf5}0f58#2#k@T`=1!-G zly8acuA0r5-BfbZ4JjV`2 z7p}0|`=zE>_7*&~T7>9Wwhu0~HD$PC-NE{5Rc35OM5l5WC?-nbRhWoLT|~1j+o;T? zbVdI3ulT|Mg-_Hl)`IV4K~uW`OS|AGeYu4}6I|97o9pY}v(tz~T#V?qELF6>*#Ikz z&ljNyhqSj{ZqMfWb4G5gT{K>+tDYXCi__JoOKuS|o6-aT2PLBxy5-sB$b+L1xd6)Y)?t0Q1ZFuP8P9iH`&%fZ3L-t&LxaZ=AUdZV4p{sgU03zK9sR!D;lJGzKYr!iTG+I?7HMp@bIldh zvvKtqk@74&QHJn2cS9$$4UOHlvw5GAXB+&@@LaW8MQhEHqZRv2wW-C!RPXbxQ|QT= zsh076RRH$K+#P^i_t8|UP(ZQ!)DT5fg_i?~%@y(U)##Q>`o|OAIlH)_BaaS}rt45l z542NSI__^qOF@XLa=mJFuX1YuT3X-kQzXTsa%X=kmF&LFQdq|I=o;VYU$+%+SXDx- zUY$n$3Q)4J(J-yxzgqsPOU9s(B7+qB%-ay=@#EnPCF13n&eYZ`?=gnM)q$9gCjfrz zP=29+j0~p!vGj&#vdCy(^tgZ93f{rCQ9oQoTN4V!0R6hHbPjt3{tq z(=WaSUM?DOU$aNpX~WNTmMXxNV{t`b`Ex~II;`iqJmlb2i8R}^O_$fp=Q?mv%*de1 z=L$Zy%2r$8*uaFRJj|-*yd4ch`N_4oI}kdnA3)$aDnpmgA5VQ;soG0CL<9lfkSxyf z%8`ZEy=`=vPMC5rSuJI}%7MAdMV)fK=&n7qViU-x*so3jOP@U^oo|pEe(V3Vo*?HQ zmp_rzic2H>8eJ7d7&}=G`@gsu1fKl586q=EA_RxX>496>v($Fe|`L_Xbu6F zy9Vj0=-^2zGy|sYBuPnC#vTwxCzdY|sKHg$`1Mm9W$!Syd%zqQ)snhxTXH@h*=7ET~(aVXl#fHXie-F>zi^UH%%i`H7seN1%F59{vH5<9 zB=Wt1y%^}t?32g2pgf?8z|WUAH>SSuy?D;rxodh}7_OzqQWPX}?V@%-CafLj>Glmw z@C_)90R%n6kw#BZ(d{KtL$i#!iA;6)d*nb53;2?Bg8&m1aIB&@mzxndM2}^cb9Hk- zHAk!N;ktTNksVaB^;#)-OQn`85eZ!WO0gEp;)*|&MEck*_YSn?jgmW zfDOC2PD=(#pW-s1Y!DDotP4sKnv!KQV{yG_r{r@L_k99@<+8Mb=7Po@I>7cU>J~A zW^QHpj?d}|7K0*Wrp0U@wUpM2(iH1KUoJ3Eq(HX2F8Y8nlW2uTupY4R`_7r4kTP@@ z{5ykVSZwxuQ16PFpBOURgJaT}UeIJe0MLB=fqgi7+ZIzcZnbCxm5KnRKMNoPjL2av zm07fgg>R$q=kYC?H(@udTaul%xUb6i-|r>ejB) zNvEWq>4NSb*(p+N@~^ts3bos6w|3nwjD}mkyx@H499BZITTkzJzvD7~h5<5nwV2rE zbUti)-c7wut_M4`+E~B;1|UA^1zd);ubyW8N;t0{A-l?u?{CJqI=ZjGTHD`aer>zTz;Av|=4JjHU)d*FNC`&* z@?7>CHS9^niklCpp(j+h*6Tv-%|`U~jpBEPL(C!;x!j0&p0?&MR@nILr5_Je3%ZK3 zRc%dEtJ?FC$-ioGneeicR5$}BzaE`uAQR9)0p-qx43uS1f7QG;hvb-JWf@lar8AXX z+cc`)zaL>d`>qug)!d?IA{jRA^&E%2axBvnO@p3SFKNIl(VC{`{*4XZ-dU(1CjdGO zn7mG^!uSBjqakgx3&+VNCjJY>AUEJSHn{Xr;xa`|j}4tXhxoo&)yc|T^X;dQ(?G|~RyaOB1I4RmLG_P9K5no1vVwKTbb&D_FtvoYLl zdy%z>#8+%UyI<9p<$c}NU;QHy+$D4Y5-9>R}KLR0RO1~+D2K2 z4)ApB+R}q4U91Nel!!Q7&2@MR>*5=9PbOP-jm2xw!7Pc|eO+8FN-;4RnUR^wmQ)B) zrQl;1$BMF6fVJ4ZmB@!tUT>5xW`B>#`ZOJHQ~kzA*Pi(rc!s)tU$=ovy1>E(;8<<` z)f;R(D7IqVP_j1pAV0pZiv{a?p6YFgGJQw+iCu}xXLv|O?N;OgzDry9eZw*H`Odg< z{d;OBU0v((HP~kKoE3XoR&d_YP^iuj6@`to(OIs+ERy3yE>`5w_U@+ zF7b%XEG+ru4`fLh{>1#K;Z6hQO=lGHC?~yF1`ZMnZ;H%EzTYhxFd97C9qJgmB&Ne7O~) z&}zxZC4VoIdZUi<;7rqoX-lHk=VfitW0sl9!7817#lutE;B;|ts8-`Y*V8}NGYn~dC7J^WP$@DQYEJ6=s9r)}ZRTcgG9L-TRf+l8 zcV0zD6|Ip~IF)1t72FMP z_3!D05b7PUwr`aOSd(IDpG(Zd`#_UYkE$phzQmX>MdFGkfdo-MRiU3k?!4}d*`RhD3sos~uO_(P;UjCkKN{DDOD zqj-oTI^lxtjplB=VJHA(3P&P{kdUvx8S^{~FMBx7S z!eZ_y+44Gb9iSq$=2tpj*5cO6$pL)?5-w@s}$d&c9<56aYZ+dD8!~j56BZjT5L-q z;&HO^JTjS3T;qoM6~#sguxNt^fRdhH`UBGbjT+<&7r+ZXmlOC${GbQmst2SCEBB?x zf1wA2Xk%`@Nse8o1(l-3HHFWTU8e_?f^1#KQZv$;wXyr{ZH3pj;v?C^^HOFj%c|_+ zQDh(uQB3JGH}CEEvZ^TB&4OCtu0;X%2-q5>J;`EK=26M3N=a}CK0TBYP>Q}6&jWpM zF~K>pXLD97?}GftMN@Q0RrKwz&VlOiAxyN6AsbISUx?;jsdt^o6Uaa-}jO%&n zp4;Z1{)un2n}yiU#+sw$GtPq^z{Z*)MBqR{l39<3Se8B{lpB2K+mr28(d^QhAB5V3 zP`0whz~bwsGhIf%v+Yyal(b@o1s#)qO{od6h58{UD>|IR2KPX78rNql=NK!e7%S)O z^;52=>$Z-pnd$}2$-a)szL&1p{%=5E60mnL2`SfLz$RHP03Y3f_LluSP%IyoG@6yh zO|FlB&sv2BMPfS}{+y3lNiXL+4=FJ@J6v9SHb(jT4L`qwQ~zPHiwfn*YAGda47IN6#j#?aXwmK zhKdfqdi9ThM?&EZV^#$UGNQvEHiBq;RO%0k(u;4b9`x(^*3bOcptGyry?iGjIs~t= zF;R7O)C`yD@|3*6IYA9RF$O5*^o z4s4llBy_RN+W7xeUlgioTVbiXbU%nr!~76yCL7sO?TEQhotq+G{F*;p zRilI_Cln=D6SZh5b<4y*Y0%MN7`kgPYh_!99sy3NdRpGyAoHI$!{1^5yCcfXod~@h8pOMav{Zffwh47SH{bg|@smCcs@L z)YxUfixuOu^bpBcht@&em;S5eB&+Y>gV0wg5g!>Yyg(R|F1#h5I*uitp8+PN&j@X* zI+}0ZOJH0GPdFg}Hn#+$r6B}1so8FiFg?{(^_k3pY@F$5flex4*367!oYlK{DLU|5 z1c@_lwE8u<*aJ{|S`$e3j7hc?ov{6|ex7FoXpM&8^y0l+F~eFkf(E#p+O6fAvk5w|e}t zVAZWzS}!dEZIbiwJ!qX;x`C&b`bo$lOy-#_m5(%4t}lA*6X~A1ybdudtbGM%Dl#*c zPY_44Oe7@ba`b?~yMp(#KT6-##yYz6JzqaW7~ z)uo$?A~KpJ3Bt)qpCAx)G>R-uRg>gUcT$VO#;cFFfMfTGa=>5?$M&6{Jbr|6cx^1h zis53W=XNAzVc|e?1ZhDRHV$2a5v^PzCQDRKLE^k)^O7M+COSN2ib>_Ch-aqW7ehBz z-kSa6QpmA~tU}9yt(-UY=b9^(G!03{EaWIz-qm6g8o;c?oNeGg;sE_WFg4M>SP)4> z)F=o+ge#;gWRVX!QZ+;4amo9f7Zbn#$zpHerdGMcFF;*XZ_)b-(T_tWV2bU*zvIi}%^L^h{-d`=jRo+Cr z1G-f{Z5r{0mWD@suj`f8NTdCgfy$1@&d7AU7M4A z$la^Mh;B%0?1^iDE`z%)1~k3=xVgL<*D2J4DJ&A9fSPbw&(VWE*zLy#I8g^s@viXM zPz~nEVrfAo<@`7HydfnG-2kJuXZ7uFz4N@n{OGe$@>a$i*~Vey=!;Dn$Kkp8v%am4 zyGrFValBk?wVm$9@3n8^^?SoyX!${VyS$e&@}hFxKD5D6`d!~sWnTDdxD`RPj2e69 zwcsYGHO&Kaz>K#jXa7mZTvYRoymiaODPHJq9>ec|oh@tH)D)kAlP$J^PA2`PW%X$a#5Arz0U&74Y@=Ah;k2Vl7) zR5QV4u{rmahcJO0t@pgZ)a8aCiYH-$=``@PMiWXXJ11DA1pKkb5oTK6Av@u2FWaJ% zg(}Zc=kd9N$~{P9)RA&Z7h*cL*tkf9HFHQ6q@~VhC}l3!%4zFQu)$m8G4{wUp^S9llSml`+=c zkxj;#lYKhn4Lj*_ZoWQh@n@$8HzC#aP#%qnGiETuswM`^1vDOL=<_a08DWT4WHlZK zr3HXC!=n<;)M^W9qSHy09y_c~>SyIIo4$)kh+<3yNREE_xC=&xV83Bovs|O~elh(; zIdAY&Y|mrg6c*BQ3N^28ecIk*7`>J0z`35OOdnvH$&Vjc7#hxUdi87)LmU%M>@*_j zl-n|7FTUzWs6d~0V3TCVzDCrr2Wfd=&rH&-E%ew`AIg&T<>dkd5S#seV5PbKti}P! zzzy2?ONDjrJ9&ppeIKtCCn%sv0uc~r@bV6i*NEG`v)-_@?szeHe7krxR1-xT&FNTl zpqSBRo2;>;k@GrL%~$69IxZv(ChfUQIw9)m+y0qwG^HxLbw-5~T@|hDm3!4ogb$^C zagTC6zUF|h#dUAGLo2FL$S0{0oSaRp`NoAwgv5yEGRwHB1xbY z(`X~YafAESRTEs3a*dniCQ><11*N^y1YGwkvz?0lv1#jUxf%|?AY&=E*`MFe7Ulcr zQ4^KKspA9kDtF`DHi|Nn{L*amnDpFzpL;bb?R2r#VLg)d9OEz{$!bzPvl+EzdG;o= zFW7}5^UtGYfDcBC{f?|+2)^g8<%e?f?#6qdrK#qT_9@4a7w<>d^=xr->)-(;1~SVK z*AZJ=SSG$j7(cYS^JAgg47RV11I@^@p4@~L; z44UyKQ&_~SaeIbweSCpBw?(B}MnnU|ur^H**5IA{nJ$}BlB4Xu8%+>hKbA}uSP*M5 zcujdc9+8&|;xEw`9ev*|P?SdfEm#zv1gNI=6{V5_LLT8E_^#9Ta*o)GEK{Gx;%iI? zxA7Pj&TkN9ab_0JE=e=T)nV z(zKgJ>+nh8wgxYM2%G#9#E zc_)$gItOYHIHTf5^wBnXrew%V4anOndI*-769=$$;l#|9WeMlMY|0yw4HBs$Zoin6!F>vdbJ%tP9D69 zaTjkn@)E+@1x>qm{gK~G;!F%o9lrPW9*D%|VJ?g3-Jt+#@FDs~gQyaD5lsFiGJ%LA z9a=`{Q?9q_orYJ`Q;1`1E zk<0+1h?g=2iSYyxc#JD3CNZjnNTDoXp&^EGuO@+#NZ&7;U`(FMp|6S@c$*;t@xWq_GBsivnCt*GYL7?_(Xf4tu~7f|EyPnAd2EG z8@HBdC39M_E+cvYLU$-jz<>s_RVJ?T=KatydQXxR9nw=%Cl-3{ic zeB8`7{?*DBs;r#Bqmb2@(xOJcwAfL=BmPXQgpIlkDp5+E%8)kZOpHlcP>Jc2-m~;m z@5u`x9_|vo0}x=PZvdjyR>Q;ns0}`_>qXG>foaLkDnY;B*}WI!{2r#1w>6yGguE}Q z4fmvVTc>>fiPT)~=|l(~I&7#!H#PsX6V(zhj@qYy3LllE{&cKY<(CW`Uj^yB+W{1*1HW2`uW*gkxyZqyD(yLo8XW6=qXZOHROD#7_oN2!oA| z=Xxt4gID0dFDSCWfJo*vuvkdpPJTQ^ACh;>g?31RQzQ$oGkF)0JX?Zn%{6jC;ixsz z0Ks!0#sY&NesI8mZ0tQb+GYj#XPM!I0Y(`wYw|5zl%l=#+=JmHw4IH>d^Yu8^*BAv z2xdJ;$hsXzup-rBSg6XSnOjC!DntguNMwFKMKSp_iwcJgpclk~6#Mkr{I|;PQ!iE@ z=(EVKkE7<=5a)8i2g97Vy6@K%bR=4GY`63MQ^L*5F~;m- z7vw1^?eMs#KUwW`i_vTH(e&@a@J7d$JJX!|6TufG7!UwuFUi4cQ@FnZG^CGnah7uz z2kNT#HzT&GI7ARuXEY{`XqcnsK-rx!fMS)W#DbxHEl(L3>5WdgprT?Gw{|X`@5|-G z%*}E++(Rt48KqAbODYfwBz>mA)a+JSSY>&|ZX>j6bNi9L$$#;Ex111>x(g!GY%mZ!A63EHem-Sclx^+3AtHR5+X)=oF0YlRSQ$aNc1mI1guKp9K#R79P zA3I9_k739k729U49fJmj`CxiwOjZzSS|fp1gO#A5!g96+gnyZ-F>~y+6i{G)<`K^O zL?}`LEMu#B5onY}#H3U)2~<)7 zW|}437iq2!eVeNKy<(J4FN`5&$1oimK}jcU>A(Y4a4VV`3=~unXJdbI6|uWQ2X@>oRHP6AaR6WBU4Wy4f;FrUa=xXI$KfO8_#~1J~TGr<_W5fj)(d?PTrs$ibJYXj4P&Fq? z|4|I=P0kySqqGbd(zon~$rP`z0FN>GZ$B)3)p?Z4nN zsfoAzB5urUp|OF$m<1Jgh4}!XHX*bPbwC&wRopOFZ_zdF0SB){2=Z^_<9>}H`o*XOOU1hHs(#leF|Q2jD*_8;nTBX;P(7G_Q&wRuGEw z${1vBg=dB*Dz8ju{gXkJkZj@oPcscfL@DD?J_G-T#dRT|80!~Y>^Ud`3{)C1kp<;o z2#TW5My1T-DJsnQ5fMEYq|u2<1`7K00` z%}BEoovm^M4ui^yC4<)}LJkiL*rAR})7Jd*HL`Hq|O?v3ggA&mD z&uH5HLLX9b@x6k5?$1hcd@M%tV-i&wll2MJ(;0%w68Y2V3L;4JoF;P&Vb&T4{*1M` zcff{B@M#SYxKEDGMPx(gV6bhxe7+&vJwBMuz-gg|f*%04wJ(4^r|7m4QG9*)=GOqy{rxCnYEp^VU+EBP)(?c4WOF*We0+qwl;dt+Qgs0tx zb=iS$qMg~oXnVLkpL49(n63$?seGrk3c^ewlH7v6uH zWL}N44x?(2w1%#>BCp@=K7ls=+9NTvH``0QfBR}5mG+j`4f#7$xpbwgXP0-R`B?RE z<@)xFLOI~-HP~Y69jC18+1%!=Pj?YX<^9o=@RFgqlHtiP#SKy~)#Y-o(|Y8iq;|#D zfQqA5g*O^f06pV<3B8rxwzJx}y_#fxsX>4J*t1f<{Mt0s@B$R)aJ#EX?aio1V%B&d>FGUqQiv)HKubt^ws#eVeY)F;W!}ml-XU*f)AwYoh-FO zC8%)dPs}4P6PK1E+*(9x*C6@ZUw^$GU$Bz@nHy3EZyXT%t?)gkhAjC(<$YVk*3r<+ za}?B5nK#`h_51#BZz+9WD^yFSQ~&*g5#FGWqU0{F!?jNGP?Gz!h6Oc9)3c&p?HYIW zeS&&Ld`C8KT;XU~DG!v!c(1VtiwTr=4=gbW$S$~G<@n(NQ==u1&1)v#tmrtzxoKun95!9tI@Y%uG zw`JMKUGbUS!*~DB@=snS-+ihX8fJvf)z1&CWo=jeNKcYkm54?i=fKVP=v=;5@xH9r zk5uFB=bAf?c?+5fI#`FFdgX!T(oq%wPL?5+$-L%QWmLTgw+!W7$U5&F!L=|zANB)O zLa`3@q)BO-z{w5H`t{S`t3tncdKUIki&+X;IxK5dC@16IbW&W7w)@BU`?X=( z*2p&FHg5;&weHi)&z%pQ(}G4LF2FL<6xfCBG}Uxxn`KuM=fb)->*^P7hmYOuZ+rSf zdJ5|)`X~9NHv5z){!h<33h+(P2OI-$?2|Ji-etk<>eLgCQMZ}Ri4c$rRS^j#5Mc9; zm1I%8aSyJIUS`Emr1yoo+onVC^P1~eIwB^o(i-na=C2n`+o=kg_h!D8xqRbkrI*`8 zvCs7Uk47^83JT+CdXM8Keif_ORNcSq11i)nsCh>k_}bG8oyfN71vUw^uwyoA1Ns&2 zM(@^A!bX6)R0Ge@2EM8Sr3=>wLf3El9>50*=D7I@uNizJi!$e*uTLhk;047x@j8`s~Z({(tT;_ zT4hO{(242=BD0quW_r`sZI+-jGtGu;3z&IMQQ5_RtlM;pEFQ8QyCCqnPke^Dgto#~ z8x-WC>KaOD#=;U~0tz7myU;){=le^orbp{Z*=SK7Ic|{uO>2}foMoCPZ2RcH6nz838mQ573nrg5UZ%0&#w4^Z3^NY~Jd50Wcqc z&-}ANI%|%s=Sg-y|41Sy4X+wyjnlx^?X+N4^5xS$cBVX`1wHe5>YJ7TL(o|h3&`vX3kv&#zLX zi-&g&6j!`KW|QRxpjIh*_?*y^{dpGmq&>pe5%bgO`!y(bJUDtjeZshR!m6>6oIS?U z(s|^w^#u&4%MZARP?oKW^xn}&+dcpc^AM>xGLvcG;~s&fmx?aAP2jF%if$o$)>V-S z9haiwc=@k-jNZeH_?U!;9*ewHW3LJ29%%drEVxAu*BurKGTASDlqAbg)LC1Yw-=)2 z$}(zF+og3UlHJ3)=j?1@UO9|iWNs4u3leT!kUqtG?dK1&&F5MOVp#)avB#kzlVUB% zy`o)|h^-z_yiM!u9AT*85Qh4bG?&-Nw73|@9-8>X(sfUMNtg$VZoM4In-v5ws3f^= zngi+=hxoo^k5me^XGf6#b~yoRS{%%h?TahMfY2#a$TvEC;YbHerU-2sw`wNB92`oe zQ+i`D7%fz?oZo7fQJ=$p=t8SYb2xDB`Dab#dmyluKb3u4~ZK zfG%v@IBG5txpDnHGBAhRvIbDZM~^vluQX`tl;Z|#6Uwr2RT!izw9#C%V@bFIAeqo| z^y4IrFxn&`FN~XdU#TUMhRr-muNQ025lZbld2Uo40kQI1p?zig+x+$31P+;Xw4zdF)$2J9U%nl?71Hb z2k%I7Zl*)K?Y7^Vv+Rsd-sh7`hWZ^9+eew%vC8(L&mV_Qa*O#ystEQPa+x!_qWv~q z?LbqVT0^wH@eltN8^+mDoUO~e*3sg~eaySrw^?C(aJ+W(YEE7F=9@_tkq2B_ zw2e~R8AlzOWLN)?=1!~`H#t1gnR}gG>zzmUw$%ZXY)emc{nmpwkJ&oT8=gtwdmVfy zlNM*AmYYxSTROD0Qp-_C^xv=P3QojLb34@3XOi2`)ER#S$93o?3`;b7lo94+rWuDg2P?Y^o-O3T@PO&qJmle|3v>~jNjXR{6YsAF zGUJBybZr^|p*Wm4JaA=p2+o^-2yw#7!<^AVL??YqcgY9D0q$ACAj;p^O`Hf55 zNgs}TY$U`vEYEFQ#3DK>XqIOKPRB#GOtopjwO;ncp$DD4=ytRz3w^e`KkNJK%GlGY zOprDi>X4`bm2vSust5>GT{952H1)>QUY$1$0hxHTl`-h~Hh}PfuNk<<94u@PQq@*M z;kR@OOE7-NxX84{Ubb99__nO<6=dy(op1tspsd~*A0f4nXU;U2< zn#@|MD__6ib_Lki?x{{`2G~!u{=EnM zzd8i?c@q^Gzs2zxrvIr!p!EORA#gIcHnw&CZ_R;84_hlNQI}V$wnVWAM2hnooVB#k z80z05IA@$=UR4KM{iUN%-K8#xu055*Vmv3Zs?Ie-gW#Bvv%jM=U8rgKGO>P+i-(cqZn_YTZ1o!LJY07|NO1Ro5^+t>rI#Y zPl)fv7LEu+9_#bBwvRbX9__yqB)T7nj2Atyc0VIxXi7>bbACV9oO8*KS6$zATB5a@ zh#@|X-Vvdug4MKZ0p(^~nWxwvt^yJU&r_}M`WEm2gPU_G7 zZ&>~IU?ErzOp78#5hqoIH)Rmkrm48a9W&CQlq_dP)O#1s_x5Aa_pgbOt~D^vFHD4E z2&X}GskJz5q?Db9R34K_q^!)fL^3Wfmv|lvXHZ;(v=kjv2o4Cp6@?cVg&+v3&J_Va zkLhL*^t`IG;N97_Ww!q`;5O+oIiAVPVt3W=HvjSQ{Nc4-{{aO-#5dr;{}2nk1P7fU zLc+lVcSet0?6-!VR<0c3)>#!P59-k-#34QcuUS+ce8!eV?-g4A9nWvs8V z{Dh`hVRbQ$9SpBXZJuHv8BV*kNR-PMo`k!JT0$9_?RmU7h8p#s0Da25u_kY3T6U2Pt5fSw=c<+ z`KiaR%{W>!^xR6lMWLA)3QvN#VWv)BSSewYS)~_9S8Nukrl6c48!jQ-55Y{gaM#~o zSsfP~9BQbwz*rs8Vu1poZV|jP_%my>#f+q%5Qn@2WWtfKm{>6J7GSWOsWVBLUPKT{ zPi4+vIzei#Cv3>E%~^AN*+sDi8vDvufDpQ(o{)kitTNC%Qx;!)?0F)UU$82=gt zW*3U6PKr5DiBF%oqz)(v7eXzmC&%y-NFq@yPsmPE^T!?gApsJmIkOHNA5c|M)l6;7g!~hZlgeB&ooQ8fHQOa^YxQVES1%gH*CDEWQ ztSDb+8GZSo7-R$)7K^yVvOdm_S(SLmg&!3|cm-P^SxG-X2v&gqQEEhlJ%va}X5UeG zsPTq$gQdk1Prinwd3<}mN}e8_VjcaURp_ZQQTeYMpa_~W_h0r$4JAOVc}Fxz5IWOa zwpC{fgZ$c5CRurfl1L=>zn@1aNmAI{k4DcF?)PbAIoY4ngU}K#{dx7GSzZqJ9nfio zf^b4M*HBan^R@X$DAM|adqBUr)GTV|T%nAn>`tj1U7Kyq6qWwpAhX&`eh1@XDx}z+ zWTVQIFpOdt$%mK(yO^Z1i!0FGWr?cjsI7lQzBb=f2+BMkwiIC#hZ7MK>8^k5!3wH6bv*;dtuWg?Pb!7QBPWYNLctUW4~YxwfX|Z>Qbum=wg8;WyV_ODTTFALni{u z&R)?Jr3Rwhgy|9)w98am1jBTcwaJHZj%o7^mI-wI4&#RHfbr|God!Roee+Vz@PFLBN$S7lUS0$cC$asGvE|TYslxW zz{y9bnBawaq`+{@31!2TzqnYz2)d6Ch`fnX1b$8zYZ$VXkOWqhZ>C0`&rRjKlC2hS z7b_U9I+okP=mgf6DtInO5ATztcL5Xga}e)g*EiHT+nPST?!sqfr0zi5#@%gYydt3f>7 zNM4&LnV67DyQI2#zzx!0 z$~o4iN&iIc4vtrk>kCe&^XuSxH&RQ!8#jjr^t4aA0`zn`=bfj^e(DII|Ba9vNh>AO z)o=^tB!R1F1(0J@KaXo;r1Lu6nrX(8Y|tMA0<@VBXmXH}=7W8iAhXTDwYGCl&3}Ov z{Tl(;@9Mph;BKpdYOC23*bfsQ&xGr=`0zNqB}5J!fGIIlpMxy{G;h9PDj>8~wt+bi zlD<^6 z(IZmu?H%QzK}ZGI8n+aJC*fo}yoE(Be?l&k5O5JP78GT>HM!56s@w(=Qi|CsE-2%yrtdI9B8>;I7r5T4 z1#8wBcM4l90BXd*s;}`z)Wz7lA#?iY%AT|7BuOOkg7z#1HTjiFq#bmGJG3-mfzJ2? z214V*;jSId^@rq`0>w3A7KK-Bxi2XTad$tL1Rs*(m&Tt~zSx&a!P%bLAw*1Hr$&cy zP;mUIFYP+7m(kym>_mNS!CLr{&$>9Cjwh=|$W}y1ZC_w@z4ubIfmcR3A6nW)ZU#j$ zdGcJn7H)1X%<+9)Wr{JPgZ| z(POS*x&|xn5s~4f3qs}~KM*iUhY$85GS?fhwob+?^;4=RIwYCM?%h#T=>+B6S_Qjy zDUoDQ-I-*rWia%*uP!)OX-67R(c3gtJ4_fta?Z3QSWc83vJKezD6%UvL@fpkJq2Vm znWRiA$QoR~N09!Vh|qdYCQzyCtkvU3MV*XhOO%M$XQu|UJekm#Ua%O>Ud|NnbyB-J zI@U|ICdJaPI1%#~m8NdABqM7n9E7&PxcuXaT|#Y613kl5nZ2�*N<6;;xeR=M>=c zZcY#YGcfSzfb6%L(XU5_G40B1^KjbF6Y$pciNB4O*FeVFV#%p~f4QxW(|1qgQPfW05whPSd_c3Q;1xyoTk)pNY&O6N+8 zX~%C(3RUmksUmaV&p>DcwU!J$JJ62b6OdbCRk~`n@%Q`Ul<{0t`C%x{>H0Wm@%4Tv zlUKqo;mi7&cr-uLo_lE8eN!{O-56GAitJFU%2#jSJXAp2EQ|)Vw%|6dMLtkXbTGI& z3#wE3@rL`gUISOm#|Xla3|TMUf6qAg-8hzE>8&MWH6-Ilpe&6P64OFAbmUc8 zWX(EDkGGoha8s7l!mV}L0r|!j@LZ>3A+C$A-m=o|u+jy;9(-AR&en~cSte?5bB*n; z=qjqZk<&x91I2H{z1j$isTO=tYP5O2V0#*t7FIBmpLb^iz}Rf3%C zQ)tAg^JJi!2~-m8hbjvpOQUJz?qNoQtOzl0(TS%uPw`s*K|RnSfq_YXS+B%%X~?qt z&}`^yB}-0EHgKM^nP5#=H>&O2GeykXu{=?HM-L~ijgl?rGQ!sEn9~OcPqegRjIFxr zK;CiUe(o>c0oTl~={WHPk9g{NzOSIK5y$W9b~AQ%wE4XbM)kt#`CHdeQZW%UKUuLGC9amH>FYI?Q)*@A0 zIhG}>P!Xp0#feHP7;Gr^c`lH+Y+9@+(^{$C@Da9? z>Ect3-0jevTPfDdDtFnt`0c14+iThh%vN6J20Txm+b{5)ZodMJ zS~Q+l|LG0gJ;1pKxAlQEV+GTI?nS;S&ydDY_PyyQ`QcYZ%OLI(%e7IUi~5}nr?!aX zcI~|8A29hXU(^qT)=)$2GoA;8`L&y)*NywNLCHp!YqpQt$EkxkyI%`#vlp&`E{si2 zd(r_4^zZ=KEvkuD<7VPCmxo!;?>xSTM4O@bwaFb%Xv!o4?c#{RFs(a1grhpaMeq5} z5Ji|<)`P0khyYV1qI4OS4mIZ*YaF9YD>7XYti?<`-z?q%Pn+kx!Q9H1=5P#|@$v{o zf_n~?ltU%DrrY}gk!8>gSgyuNuN+sp3vfNR4LwD=X*KfY;>{12{hu`NkKjT|-F2l_IaKfY=F^wa-i*d$01uw@bVA zs)q177TDddirk(%DSJ8|m*=BP*s?j=o(IRC$mOc8_)MFRR@|nmUZz%v9$GrQ^rd^! zt6gr|2)_+qgKn!9AFPaLoIcrKy1jO*fLGRrzs*;k`8&FQ+M2Rvs$OJQh!)&F{<6K3 zEx(i5M&tzZ!_~atR*1$psM|>YnQd#wbf%(nuW(CERziQ1kMMpZK`-pH5IRI{<;2g` z7nLc{IAV)C%?-`kBfjM@l|QUSbM9!i^N{!42Isvg+4Je`#0P8<^YU++mJwTaN{cG{ zAjCsr#+ym{8?h!X2e0Dl z6v_czW#KWp-R((=+Q`_8#dW2=b(^d4ZV)0^9etneE=ZZt^>Wb7v<5-k_WGzBXmKOQ z&QsXE-8z*ZMu5VxbzX;U7aV@d?1D!#f*PA`nC$Vc`4C3;* z`5+1`nYysx-!e=QdIg1ZQmfyW(WYEo7vRZ}FqWd37BBNxXi7L|Pi&BiR8+e%QiK}4 zY*f&UJ9-CTX`s4*VWP{{_l4{0EA8yZ&Fq;a1gHPgkZO=bxyiisamIm0vI?BeBBI*C zn9=4>t}3!VXlzDL&KKQRz>}BG0g+JY9y-Wg&fF<_=|zsh%ZbIVQ{#*NTtLV7>|eiA z{4e30Na7dnPoc;4v5!%D5o|=~-LvSyyQaZAtca!kkL9_$j=Dbf{2K8Zw@!QyddGwQ zsfMN?^5t76tGcs^t)FehC+LwILU%{AZ|eVm@*K6}MkJ8|0K$L8W&eM&ufqQn%5!nF z{!c>24l8@?l_YZC4^S385Q$saxIf(@Y@&gQ5@Se@xs-A7rK5?Hp+*bwxn%84@f50c*)l7IAg4G<-rfrvI>q_#gq?Z2hS2ZXnNnTy50sdtQ^h%^Ej{n-V z3p=cuqEOAK^1=oXj7!YYlyLdro92A^b&%e6dW&VtzyttL)BgT={A2|1g^uur`x54f zWCW-LLJSMWpF~ao3D_^p$t1Z;NiP(UD*SrnVID&eFcAsbVX(_&K@wn*t0(z4+Qw9S zMP8qS&W}VB<8kVM!Wl z^7ETCtxLvP$Tas&>^RQ}EHV-sKIT~GTrWg}oaLm;ZJz=k*wHIJ4M6X)1R;P@D&Qyv z15o+zCc|Qvw18lz1L9nq6N{t#Zpn=MS{8 zdJDB|mdVKdb8f9b&k5_SdIxq+rGp+%Qr0+uKWG_HE-kyxPJ~-jO%hdM!q#b|vu=(#jq=v0 zFH`XxOJq&qHlAa&M)f}NoRl&iqL!X!%j|9g{P+-mxBu27>9u-TG0r>f8rbdR4b^5s)7wTd|8zRWEZM~o~ph^)8{vY$59o;)Qf%_mZgZuN_D5p(Vq%z+CG~>+_+(@ ztE~F2TwuK*$JhI$VW4K1tlQ|09puM2T~y?9OXlS^Cd+76_Rn3Y-6Qf0C3HfRWq;pUrm8ebx?Hm=3}PuS-p;bIGv3Illa&oF?zh#oI;@Mhv}mxHo@ z{^k+vbSTIW`_aQkq9`0JBl=(8PCVUBw<5O2V{g6ihYwqcOeSgyx@`Yw0DpOi=w#BL z#;EdR18gQe8mwD?271v-3xIn{&}acj00OXjuw9Ctj@HIhlM2I+$gbS`u2fG+dRs&$ zNr1R8B&t;6mXsYjWyrYAHW=EaFj!jABn)64)IIRx!(9GK2^=l_O#0oY(5EdXY6tha z+^lQp$<|w=;3Nytc!aD@gGjucSWmf-JbAJ^sQJ)-prV$6_)7QwS@gPsIf`)&5#ae0 ze1wjNYP+!)QAy!^b~zi3OSdiQ>%t;N<0kqSvT^?MF7*sYwvx)Jy9Mm$`qnqn0oOg! zf#wZ+QOTrE*>aI6l`+O#q?Z7R(nFtH!jNZ!L;lnUFC&7=Niae!Qi~}NU?l-TE{Viq zA3(`N?|?whJx^V5UC{13&74eZ4awvFdJvz0GlG?vW{RCOWgEaa;f+O8y4p9L`C^#I z38(G|j?J)k1(=DavfbHHY@qmkcux{2N0wk0;1p544%aCj?55t_TM;o^y{DJokOAarm^K*r!^23@* zb*sNJz`i*d)2nj3p_b2Oth(jV`^IgOGCXwpDA$uzNOIYn&yRB5Huk<#OpQWC0VkwSqK`cBJXDaPc$ zp%NI0s)>p)VhG|1ri!s59ygeKf&D+AT!!+Jpa4)vDxCR)O!{09PC(ggkBepYF$W3nqDIEkyU&&-n3>ff1I?#8a_PbF)EOo|w%$y{)7Ai5p_^|W6;}B6g1eI3G z@B~{(y`i2`V0^$nJQzEMGZ)S2fn#s!T7KQoiq$^Ps z$dbv>`}P~4w&V05w!1^qTaRyFo0YW$4z_So4}GALhmo$mv$TeMhbfyGoOI|Xun|ft ziTtNsd#+AgVhnb3hTR@C+@aXb$+Gt3_n>qj6l@*K+rcwE*Vor+2KK}BZJm8@*B*T* zH@5pN;}C-S0+u=UA$d7FO0$z!bjIX}+S*Kt7Q)KpE5RsKOc&Sx2qxHr6s*rTi40rx zk>|-uw~OVjCFIFh7Nf1{;(veAh(ia>g%+gI0$xed*Vn_YU{*vhAlb-MJb8-sKpx0!Z1(g}|4^ysl|d^3w4EgSdO)p?7grR$`9l}g zG2Z#b+Aql4ueo4io=R5L_y3xDYRbS=H&rrUv@nsza3rw;SYZZ6t9{(>4bF~_B{nho zav9f=)4EX9(9d=5%V}P;9MbxfaIAe0n;U)lPD%NVuQvjx0aMCE2~(-X6jj1f%%nA5 zE+VTiZgrhJP0ygiaS({Jh*Dyo=8RE#bP{q^1Mdn)_GWgbH`=cqC6hMrt#s8AZF3J ziQGx~_KXZ5+w1!#>Mg0ux$w0HL$Nr|w*ve2gqp2Z0<*A~oKWVP zQRAUMDC*8S@6JjG6js|uzKg8Hj0#X?hWvTzPwCm&0F>B5@D3G=A^^3008Inos~-cB zpRiT)OSp)7cQpkZIQQDiunIL-ut$^CR+QBsfy>SvbyKL7H2@6Nko0jHl0c0LAUagI zr4k8H+RZfXZO)O{7F^^^rzY7CBhs+k3`j;g<1tMXB7fmrfK!p_zQ(=+5V0JJr>EQm zWr(N}uu-^tYn3|Ud}x9RtZ)Me!}=AWm4YD>r)wdwQWb&X8RwN$N(qaxM!=M-S1W18 zbqVH!7GRxZ8f?(-U?ph)%;qwcBN~$)`?QQts#=$zWBzh0)St*@(bhe)7dCcqF!T@f5epnRJQl3m;ZjVPFNg+Lp{O614HPVndquf}>CAm-Iy+A)G=i4*QHy@z6;EI!D_ju1Ik$XqD>Y#4d zOw6B0Ct+Jfp32a0|@ylG=$@$|GX*<|J_oO5)i%Ef#%vy5WLfTKva{G%8L0udq_9Ux>NHc!!m zGFwW3!Wu+js1)QZ9S4+ujbcEwz}JIM^fjHa%c*j}Fit-;^>5oo-#~0x#_;rk;H_Tm zIDuCif<%#eN|YyqD)!cr#b{Oo#WPT06EYjcdERbrl@qe^qSBvM7OR5!`J6=ii(CBY z-e`Re1N(a&Mynm4{iQhFtH*?U#b<`1e&}C*+p7Kiw5g_o*2ijJ5zeO8lBe7HUJR`H zAFgE|epp{5Z;E2w5@pts1m~lK^Wl$V65Ts)?X~-Wo@cUGcpyvd3uObNZt1~rSTC1+ zmb-VYv##*ME>1aq2Q@lse4OY8eJ$+e_vH^?ZysY>{bWCecm+PslWp#o0(k4PE^@ZY zC#xe$E30{}oVsN5)$|dX6r;AL`$K>eYWB^ z=-9V86#n$%5#?y)9wU15tWwN1DT69MYfCxJ^o8VQlC5@J;5iRgpYT_<4kD>Zf+gwS zItH%`ED}K~W0L5!Q=*J(zk>p(l_7Oo=glZj0Jw3YqC~!7uQ-&0;_sP(xb?+{bya)} zVe7+63XYPBV3{{+ea=$hqh<0)k|jt>#PIEirSnn78~#Hq<`ZFtAVf$>@JEFLBe3bUcoh8~X{kje3c}Nd zsVChj^exLUA{MpuD+YnpUjq%u5Y(yEnLH6*^E(&60Spb5a zkzWGbbtkrF1WEeOeb;JR)D#|f!(OEq)TE5;W~(8k_Vf3y$*@+8(LVe;^KyMh4Q*Gl z#Ya-pSs7qrVnNh{^vTb;P;>v}qR9)u^843|ZBGjgKhv_0w};POz-_`1jJD%Svxznu zl4Qne1~{)3{8%t_IbSXR!)cp-Zb?dLIEMPCQ*bSe}X9HE>9(vxK5Z@`mZ(^5Quo$TNa5fH$78yYil2m{JU@w0+ z4iahrxf1DKk0K1{IqtGAB5RS7y;zZ}&Q}O-2q7A-sY>oVm2zZnv|&jT9ojNiV<}kN zU{`@Q4 zU6H>q<;+Q!H_1_e>@5isw;+*=I7MR_D_Ebd@wEd|pru$*cdw?uKlR~<>!(85KVr0O zlicp8fK6b~1KHjN;?=+6rOQE~-TAd-mP26MpgybDQ1vS(2Ul7l=7;;IR>0_g$-(7x zG47+X_}CxUXH(VoF}t1LYRwJo?VabDxj^(+u6_=O;s|GM3F?2qG?8-M)C!LNA@pj2 zV=GoIGBYx9v9PgtdRWXly>IrOVpI-rflFQr*Z-6ID~OV7++gBC_IabGZ46c6^XusR*u&r6$ zDYKq4ob%LguP66?mi9VYp((ZW(AkPB7fV~>otR9SK9@P@?y34}b@kcZS*gj?$CG+A z!%AO2u>Z@8)1hwA^38UddQ~-eI;qEPy;n_`3~m zj-Q1g$*!Zr7b$|Hhb{Gr&;D45CMg?XA+sUsgVos9pnC1LG(66ZCd+tpEJo^_7D~#|!Zz zp^N{%v>l|+q9c{klTBIUHLS2?swt3^Y^rJCGT8kB)qs)&;DkDJZsz%6N7S#z7hg3Fm`WcyDXP3J@$Ais2WyZYvIM57W zLF}*etM{Z52iYOE3)EiB*d?2b(z4m2YXa?^r`?Q-NDSK({zFb_(UF&hah47Nq3j#3 z9Ej6>a7ZRbk1|a%UOCv5*R(x+wnA~hQ-)~*`raAwyC2uB01x;|#$bpAdxTp>E;c#v zVd@h@%s(6@l&u0B#464Mt15D-{6u zcY@q>TZDY~c-sToWW+voP(*%R-xVF)+>bMX3J~Mm{;|lw_fNu{v6$nB>zn;B6MK3v6P;-@q29t<2cU-8dv!$tRy`+ z^%IMmj)yf@O(wKi(u`nI{bAGw!Z~u=(e-Q*P*cmIkjIFJ6;FVBas7MZND8nU`Y6Dv zVS~c~;H#(0xts6n>(Bk0JOZQfgWWuwA?74L+GhC*k@Qa*#jN3wj}i$VO>N-?BFTLX z5;H@DNs2P0sUkk2O(2QgxKV1Wnl3*N<$?`Msz_96>#=T@DjHX>XWN%*y3K@hYiMRn z@N!Q~8bPY<1Wo6fVl1zqa95Rt;^O5fC3o=%7EA=+HChIou*BLS`PD>MBZICpIs<+J zDzvHL+Q#C-c4202V1cVh{>9xLbc-Erm*)Vuz&v!8Q|Uzv;ya^1e=@{C0mh3|ZueGE z10AW%%K`n6o1KxXvZE?G-9wqE8O{C53e3BI*{*)}%*Eg{(>9)^;^ZkjZ;t&5WyS)m zi=NAFuUeLR44>-BC~a&56Bjl4Q2vPX+7BGyHaFS{*e;*^5$5z)7bEy^Vl1Smv2GkpC+fG2jG>fn?bOHDtRid-|4EBQq6&gJ%&*w zY5asNev$t8yY3C(nlo9O=6gi9weSx$4@)y8r<3S5d^wwq(?2^%sUOsPJOJ4s@0Air zd24ruZ_n)Rd3G{qoH`DMgdS{`xB9_%Jza36jd*^XL%p<#o|}tON43=uBD2WTqbs^ z0EKQ(RiT1b`mm9yT16B+GfWm2r3DNYH`W9@R=a(z1O=hogtnL{%Tmfl?-ALl2o2B} zDfXCTl?ZgbnVE2d2(rqlPg2lKbZMzLCR9OFj<{UGQmOomHV#dj&dC@(^rPJh=)J~i^gKd}<1j^MlTuQxz3}XeKm-d(8cNch3*w|sm?M@F zckM*EWK7oG#LPKFcL~7=>;uiA2yaKqim$B^UrAr>i6#{&HfMNlhv+)YCfPMcu7)`aWH+tIWyAzuy4wU(pm_u|a3%1_#B zr|eSQvcbiN3)Ad!KC>d%NT}JyMxcpU-{B?VW^z!$^v6Ub^r)Nv3o;Us|mSa0M!1D-9rX;XK0auL;!Svbn2MX&B1!p>1>~3nCRqbq9D93Z*DJ+ z8QtkL=pGaWH|xN-JSxyHGEg<^bMmxzZRM}nu+!o3L?D0V4{m@OQ!d3UJF40vi`~e# z$`lRwz-%PA){WWC^R#926n7=VYMb9R4 zL;s_Y$>p}#>Iwd>=EsY;|I#mTQR{_NMyv};_?O)tVFFTySEcq6ahg~rzy^z~vaX62xHM?)$SFXek!DckbWebb#{$^A5ded|p035)(rvqex9nU8|3}lW{rr(B ztByNm51uHkydBlk*v@Ud9XyWo6!tTBS5nm`|0ZbYwe1(&&wp3+7+D`gKf;x#+E~dt z8?P=bpq37Z_!2#fE^mKr+gZa#8eczZ>|&Pt8CLSK`wVYz^5MDS!NB+4x7Mfsxy)*O z(D1&MmVW9ACqMf1yqI||oRA+5RT#!Db+G%q>~daO`+Z9aV1=;XMC~wHTX$50k){2B zCMy1CRuPGD&FHGsogWURgPD|7cXNZ9Fj{TY9=!evp!QO%RD5!CiNC=+0$r7CiZh>u zOnsN%q!P%&i;h^v9=Y&t6yj&U1^F~lgRO}08kB%!{+ zunQN40*Jmqpxqc$r`BVtz{#w|CkbF(?~H;!3 zi3LeIl?$I{mTc=$gwR~`J{KakuG~X4z%?8;nK47(H$ibB&S7O_^7=T`M>xgc?%=)K z5Bf^D9ska|Q54`1{gjFA2|NM=p$ZXUcCUkR!5h|q5sUNdDidig=+E~BpZYIyGI85nzUs@>9@F5B=>nRGRlP$RI2aEMdZtwnvK`HDe&!p*O@wE3W z4_esRn0}La_|bT&7*5oYPbe*shVqtPVR8>MgX0Jjr=8(b>pIW@7KK{j)%X`QK`_D) z4-+(|-_Jw+e6RG*%t4KYrTfL%QAD<&!%!L3#$NG2a8GLW4j`jjLvR~-Jw__w%;oz1 zCV9c*?Gyn_C<6(6Vbgt~Wqx3+e~>SKSWBntbBoC#scwN2Ul+I9irP%3zMUn_C*$i> zhs1B>=wyExm&G>Mshq}ivFuw{8t0?&EC-Y6fX1KSZyP5m6KYm!f0UfBm^0>thNIS) z3@#$ln3CTyGU}Rnny=+GU-%91>By=+7MAx?DGy5Z4wS9UqdcUzu1qH5uK=dm!&7;U zX?6L!JZ+CQgWCPd`Rn-pAuMa%d~}!c$Ic(0HIS`J8cI4&!r;DXR8QQsLbT zn4(52rZ}rga(6V5mHY))E(zCn^|O{p)s@L?CULQbbEVVjSVdBNGT!piTc9dbIod~Z z7QJD3=VRSIf~1_;S@d$!xSdE;-9%&KZxhG%mb;<}qP&it6w1m0}qw?q=CN{~LYwXBDnx~AZRv<<;V{ta{TKRvc- zWDo;AJU$~JSaSOlmp@u|ynd6Pe!%}hqgX(epc*3p01)N>uV@ti<2Y^?XUqS@qc~KZ zvcew0_BB`kD0*6-UXS^53Zva1G+BkJ^w7)e0q428PlQ3;mJK zybk3Dv3R{%U1PX;%H%T18{94&Ml}t~&!G!6-!ZxsI8El*f=fCj$a)tnp-}*hA*(W! zuZ+7zviTCNK`@%`U9VYa+_c4=T075{6R$WBOS#N$#N(eYz-~k+9e_7zjfujP-7ua{ zXNivG^J8_zOmyGKX{ff>@ae;K-|+1r^2wRi2K0wAGq*Bx^q3pA@XeL$j%BHvud-*i zPr=&4M{T>JPbDAr`_J*^g4c{*&&$KUr%Q`@bKW%DQ+4P9_JV%TmIN%0Bkj*clE^E! zHq>4jVir6P;rtM|?>}c?fCSu0=zvF84*7SZ;CELENK7FA?gzB#E6SgX+S})B#%DV% z39xCcR4JNIl4gY<2-++^zp!8^q7440Z#=R1=Tq%;9wG9OI}bp~XMyGC26zQWzVsU`phiO?@*G&yAtq}Vgh3)92Y%6|IvI#TQ-tBR!oWJS;_69v5YmTx49R4S$N!V}revxk z!IES)Hk&$(PgPGVq6_!1$)3o1C*Kl+11(pi>lh?x)_xv#qWDJ*M%KIsQl>dT77`x` zy~;F6u;rOG#8wv}giWX<0k!^tPCO{CH-5sCl#5}IUp4xTAS)!B8k~Mg>^+WN?7{K; zico;~io1GKQrRs+Yh{Wn64!KPh>(kTR1zo zSN-_k2;nU<<2&xC!vVOuc{$!(SA=S#^h3L#^9U19eut^Fn>3fH?IT^aRuGqQ^cpAQ z?6u0oV0K-1Y+WSqSgA^7efU{D&{zXbg#^&AcU_ha69P|*J3qoIW*ChGfwFpw6c8kO zN#*{RKsu~fwF(@GOx{BP3-*&!~*nRPGqwyQ(~@x-3G^Z*{5%LG{*NA!&H$0JJ`Hz+8NQPEG)gU_Yx|Q$OnK zVz2YAmga?)i}5Qlss@hX^ppB^g?V^o>M~U)@iQMftE-w1EE0L%bFCZgi;YA)Y5Ah7 z!Q1_p>=)hDL_fEiwAluZ-yu>(w?M1AcRR1%BaJh_B1jH*AdjFEVSFPBPZiFHwdfap5vrvYFW+?# zy|rk=tWZ5o(!Vi!OV+qTBN*^*_tGP_q=JG0N&jYu&Ua4HWp<|F-a}SI~FGG_{(a4u=&@gbxNtxZ=oAw zAY0)9;2Pr(utZ*-99pbFk(wn?Q_#6^H;7*(n)WqbE}1YFub4c3zA~dMlZ}&1x30A9 zdcKz32^PMWV{i7I9xDQ?BsYlBhOx3lh7+wbi)H_^X+j~H!QAk53+&7+h)z_AeAu@B z>IK=N^nv_u6gshO?+d*Zn}*mm%PnFHpBA;w)8<=fYEAO+=dI4n$KOm1*%#h!gOcEV zRkc3_g=fF1ocWNs)Tg3)3cHFgm%JPYHEVuV!s&QWwLWC~ zRNRG42gE_ossMQMrQ?ApA%+r0YcVq~rV>xz-)6d9ulNE+Cl4~>3F1a40pg~& zdyzZABWWwI{CO*{33h^^4(_7{lW58C)FFLI9bubBMXJa$C?}lB688u`?gMYT#5oUd zuV}`Wqod=J))g{Zg2!RIKpx|_FhcgD7i$bwatMv&B0y%r`+cpHvvq{SyT0fYyxfjA zwlhgdleR=3rB(-*az+L%CrL+>)$0uoHVwuN@9vJ;K23C;SP@maB31F;-w=w8&#$NO zn`k@hSUtB7Zm=2do?}CoTul=RTnbABY}!Hf?GrHseA6UGR|G+%Q{2D$(Udr83#i76ym?Z%ZHHYNTU|U zLv%#4Q5iY&am<94P!?U-D{NCG>~4#3?F{#RB!9o@U%A39!@-pUcGY9<35TXO9r#8U z+}sxD+8MCa9DS{=c~VR|@e1=r#Yq$9YMKVio5+e@K(1qZj#}BUqfZKN|5bm}yHiP^ zK^0Mz{mSin6ZcN#!jQ-n%abDqU2y3?L&?yg{vMz}(S&N$|Hfypa(T2bkoP_hJp1KF zO}3gX)!FV|RFVO?`+@tD#Ui|8fboSa?hrgNKKkT8FV4U&C#0Ys9lLOBZT;`7gdI7{ zqBic*_CCwvHo>Hw(lx)Y7(}a?Qdv5{8Ge8zfq?Wy<&Un_!?h6bWCt`X!wnq^f`>Bo zW3k%lRtVU0HJPILgSU1V43-%olSOLCXzm^bNK-$;B9ySn?CrNGV6<;C+AOTt!2eqd zls222it4*k!(oqS1deBF-aLf{ zq(qSMwZJf*vG{+7zumF&7_^4ibG{Zl#_03f*c zo|QQjT}q0EBJ=clW^y;>$kBJlS2DhE5UTa;YFfJL9BYD+*3>+h>~?RaR!zzT0G$DS zQcdcHFBJ<~@2=m22`hT@fqGp`8d!RZ;MWN}xZ4;kkkz0bq(L>B!Z2C^!n9TzsS5~;ux(UHq!O?PnvuOVp-Cr!sTLTLDh zFIbF4uSK#p|M(1{D@9{Ty`THmuoDBg;e9x%5HUTi)p}mfH4HxFO+2NMe?r6!K625x znUyrGSP20xC~RunP(5;6EB{#67`S(zS^PF#3$SzzzIn55>D^V3_Lh0`CGeXpPAP6; z4sm=2B;Uo+D3Ml$3G_hOt8o~CZE*g`6_TbPcd0wZ#w*LU>=xO+scfb8mB7=nXjBbr zn^wYyFge$2$$oe6`g1Z5<36JGjZ6hA+oSGw{~DrNC=PI=1HovuaHBD@Dom0xwg{9M zM<>lgOloZ|vE5SQctYJO1gP)|Z~9xFYuVG36fT^tLNu8HNmXhPTU#yVxcdLz>*i9>Tw)oQIWx%PD4@E#^EP%1P;JF-QKhi= z!u)dICC(s*V!A{dy^4k@I}!xm$7YX6DXuPi;SCfa4oI@mO!65|w}tF=1s(mI>H2M0 zt`Dj=TNX8nt2|Czx$(N9$g(RHk!%mhrY`PIk6aFcMXP}Kx{{#XZ8aOr^9A*1QxVQ_ zC%gyT_3CiZL+?nIn}sAJcXZsb8xJv4l7Ir1L6Tq%>BIJJv>UY-QLZ}X?F6=!Xy1Y= z*s-9Cq?wzt|rs2qLM-?Cxi&hQ~2pDESPUdRg z8G;!_HA|63i1nn<2%QfAd8FlXHd$sNEr(&V)6j>PPVaLH?{-p@5v-$uC=%dMDpjF^ z<1^+4gLbmu=9CHu4?A?i!d@hJVEbeb*vg&XjNV*aU%X;5D(|r`^M)xGwKQ2n0wqaF zH}+6qg0$;bpk|LHQd-%1OIs`zI7iH7K%)+3K#OdumaTHN;? z6W|sP!EE?wUW`4n@SgmMFBZ@DFU@o|_^){f2na#a+Z~TUM)o*4)w~yLrZ4i|neeVN zGkdX0QtJ#8h;MzDN4EibmIBc?BY+uZHS%1$iaAh#z=66tZ|FmPg_^m%f%Ss(`RRQY0WDZlWl=Bs2;#DXq?)0#DCQQ;LOg{|hMtLxf*?Te|cJqL;LWm#S(>*(IL@32|6 z%yV7YOJ3!>5DUA=h{d0gsLF_zv_f|+e>_gdUf7+&|9Lzp$?4WFn|>Z7EVG?X^jbj? z(*H4J+MMMU&lmlmRk_goEE$@OOUGp9xGR{99m3#h7Za9@7wK1Svh&~`ua7N|ywCZa zga0ROjjXdmaT4s;eIN0^nwy;eow;f6Xy@+nJ2JhMCu}zu5IP^I!Ors_ch7-g3eg8_ z0?}gPC_=L#mh~h-Oq6uvRbd|wpq1d6V~5ePD%RH0H0#a00uxjEI7-zt2Rvp-X4ozeA%W|nu>NhQEjATdBsGvq`SUJ_t556oj6g4=eO_iKhP8(wJJ9pIYx$q=TBt|PoN}OtU%bv4r)LM$D za~&Bd3^9Oa9Lr!B z2n!AWO6T#`c#oJqnZR+P&twm6F+}h9sqfiz|GkP$5f7$zZJDU0=PYw7vp2}FxV7J?TMceJze`6IjoT4yvk?uX^Eef0G7>5DpjQ=P&d+2J;L z^M*V#!f2~(Hv1CA#nH3^|5)ZNB$;q;(Q#DxSc?!c%rR-AQ;5+n><`U^CKtdDU3NQ{ zCl}0;P(>s134%^=SYr)k*W>lH?r2X30u621bp&(5AAP|Y!@00Npi=O$wzBLu(~EDX zA}w9yp3`VZWJbkDxJPbd^!l)h%(?T>NkO^;Z`0e^rL#G0r}nV1K{#|=+L*hU=a1QW z&r<`+&xJzK5Jb zpnzZn1PscLRskEk!T@Oz0yAA?80%R=kpv9v);Ig}NkwM>j9ASgSm-i%GxD7c4u|bj*I#keI(}AQjIIy( zQjrkmIt9K$aBMe2BmcX&(`$_2w!ddu{U(JSes9YWb^6DFzekVudRx=D7l!ZS=9n7F zc^u}^hq))K=J>Jk{p^07kLG5~0RGXvtFt3Rzvh!Z`(&s!B!-z6{NHZs8i~n!15ezrgWycmiz>qef=>GKh|HaukLAEox#a*4m0!L8L{IFy0t`cwo#zxNQQK}e2~=YxUWxLBucU%afR-;92*_b zoe$h-+7io4Vg*VvEJ*))06Qd_0ZP)(E=4;tvI||{{-kgp{b_2Ne-Qq z=s(2}$~%Koi1a_B^;|<`AE+RFS!ad`hS{sjtsYx8wLx=JDvaZKwkQlrZXY zT*3bi6djjmF+AS}{}L}+=id}73Fy2|q;o^V>03iI$VYvxzV z1Qn3YS@-BI`j$^i%7vn~UsHr$u;CvpfJ*eciDu^lcEZeic!3oXqWm$gD&|szV;?9_8`;R^r*5E@PVT^kI1>`FxLXwB6r7Tx#fhM#@&tqA zo@KG5T8}7$+ZHnqU7}E&Y!=Ezx=}*@9?Hw?DNU;M$poivdPO;LG5BN zy!rDX$r-gInA5e|so zp)2DMEeF0KGb#_-++Z8^S@&2aR(7D%R_R$$GqRqCHZd~Xgcs?Kr9rpHj^EJjbSac# zb)eyPrD#AxA1aGEEOZ5P4fYalB6;_?%kjrPwj5p=!yzbc&Uq?tmLj^VdUZQ*c~B#J zpX7)Wr0p%p81JI;NL(mDc++XFjh-dk9O@;hVBHPD<#8&=>ASi?{YW)bZRhRO>c}(6 zfOVJFrg6m_wMKl;Al~8;Ri~~D9gwoPOX>F8$n6W>Us@w<{YTPDy+xx zRRufaq7Z@8i*nyyV=ozXfFbopHTbT4RDtG;vVK=;6hsC*D3MFNIXC8qCrE!~G-Vri*t;ia@;BK*p!iY{}`G~3o zw#sbbPlOfuLX~3LP|LqRevrFITVrt7aEBa=+Wv893KOOwWV00d!fC&&4?u-lvJH(r zMCY)WDI+KL(7^Je0Hd(PtaRiM(qqfSJkBem+=G$qTFR%Z5d`|4O1LD9Q9Sb50B8%_#@5npqS zm^GARs>6i1aWZgLyfFux?UGyjY;tu2HHxdd&)(X`URI*IqRz#^8BB zZ+@h-KStzn*^2D~4sknVc4$tzO0FiKDrcqP*XfN2#AmI>bl3t~L!A@m$BQ~nYo4yr zZKY0+s5&E`Xk`8h=xO?Ip)BSN9DU_)u$la!4}f7TgZqQ?LWh;E>om1^9(xdW{38m- zMjm0kl0lrPUI8+fkQ>Ziw!$*FVieT=uM9A{gS*yi+?NDnQ47jJtq}WSgX8^+QISft z>^uUzmI51RV+$eUM_wlyGBO>oylzl#z0((*j;PT1tg@=icOJL2)BvVBP2!4czUB&d zT`IltEZ1d~Rp=Qh^qzNS7Dmeii&4b=xOI;TTlaCO4Yp>UoI|HR-D7KUCdqgQa;u%7wGvE1?#P{5-!)KET13kR%~`G zrkR7&7yM2qO=O!q=k-r2v=F?Th-S=7aAe%_PuI+tp}ah3IIB_vWup<53CmA2 zP=-$d|8ean@8RJGKOh|em890PS6FG3weB4oBGE+*g#-gaj#E zD*J`O_{<>{?I&)c2g+`8<4yTep`39uT5XVAxxePHkYMJU$cKVpt+Y`3)#_E8x7(gl z?hg|lcB&A-Y5mQ@qjHdCxIsMo@C%47>b=UbKv&#_?cZysaB$08b-X32j<@HHry^3e znW!+7Iz_od{n?r2?b|%FQ?ndZO5f&-%k?8)m#&&CBf1J4rw~*-~0?zi;1f`c8bn zXx%fH1^-!!qXat5s?JO%8!qUU&?e_4Lz~S>P-ts(K*zC{i7VwEMgqe^bbLPtfbbfZtz_*_)!MM&qnkxKabMyLF-bs@cOo8`4FDOtkq<)a z+C3m%Dlm~|WS0rL>4vp!y$y)u=$XpIZq!3tcqp#3Mr7xtPY#p=-M5&jp2-3GNfsY& zYpp^NqSe(EDzNUYaZz#1Uo>Szj?)ta5^>jWhF~yV_mt)@v5CGT%UOzaa`5g@m2GfQ zUtV)19o$xYevO^f=yYFVz8QKw4LV~-chswI1jsOf){Aqd%uF$Uk%`f5lzFN6H zz36@(iro~Y!;D~g&0W(KEt?0+?4R*^BpX#i0Rk{Xl|Ch;y34xSh*%kuAI5p zLDllOW#EU*YDZw#{hMs~9yp6)(|q@_;EKvReo1E2)GNrZj5~M=wRLj4b53*S_OW}K z22Ul%9gyekfm?`G&@htid`?K{D}6ecN_+7+{^8_Xjazhf6#FN8(s8k~ty8@Vi>0Gf z1bRn0?JUy7{fm9D(g1{6>2z6OYZA%J3$P@*ga@SKu~EgT4B@J8JYu7Id%BsCGTY|R zH?~@c&6v{b3NDke0GL!(|4m3~^p2+0mMS6B@9lrzGwQWzPHaz}1XSI5S zBetFMjWZOt1awuI^0UD`Vqh=vw*cwb|)lF@*E(ZJi|`L!i3a|n?8q0 zWPxaX4>X~_|3NBd{4Am7Wmu_oUg`CoT*q)ZLz`87(jvGUF)`5+{XJG_=pl+5lE6K# zV%a0Yvtem2zh}&tBS{9oix~$JcqmmY2o5#ucMw<5t3K}zfA1@sN78ma0=4_95Wo)= z3!a~gAVul7%;!suMv_oT!r$9=_UsQe_PRCM|Cp|rs>3pZbOKfgb>w$MEd=lhRHGL4 zZZ|No&8P^Y*0(+;u}Ve~7o`eVW%QbAAkA)UuTU>(@sH`OkW}fOQ()SWW2uM0!0F!$ z>`DRBKq>PWoN)qQ;ov#NUT`w0Ax@Yef$Tw48qDhTO=_93o9}Tdau~a2LjAuwfWAk| zdtaB>I4oxfe-zbiz!70xYZV1#Ih1ONXwa&^;6%Qq_=0`asX}~X6XP)ANTaIJ2D$u*4_m5-wLo{FJ+i;wsZhXectDJd%F0X!|*3saa7ImLp*>m60h2|BUL#nuvE%(!DQ};*?^*vY*fSDykpafe6fAaxmeR^cNRV}gc+t=*J%dSM zAd+PyA&%O1=QNY>Z%&u)RuSnJD`Hk=5F1yD=qq}MbW*sA#f~sQONJ3utIq(T8$*R+ zv!A3N;SiuD>OBNxH>@lx66GpHFID!vQl|WJuIP5CTy4rvhAKMax6eN%aDoGsYmC2y zQnfO+B*)5eGb^Trpk1O5;{VqcJ5BN|qFN@)OOx#Gq>ekmxoXWUkF9K@Zq*3*D1ojr)rKJC``r#vM#*@XqN(xQo3f*f$7}`2R#gHlVvOqIL=!dHhB;( z2IBX*-e&mp*WWIHFVK`K5ExOG5i(xkD3pFBV2XlyDXsw~2twukWKJ2W0JB0rhDURJ z5>~eeC=&vGYYu2`V06DAw;m&opD2c)o$#+P8VFZzy z+ZAru)7Cmo|H9D$D3=zG+z*%1&nIB2N^i*o?>9?mZ;vpl70NyPd=s%->s@!K*;;*Y z4G}w59MfnR=q66=uUIK$=*%}K-LRFuEY;^4Op01h`t}q0+jU_@z-uuu%=YqlCUwik z#LdyF*pt*%8$3Bk!NU(Yj0BQcNyT-xD48sn0y!!&v+PHbpJZ7DGxPvUU|-O7upK`bcuB^0R*pz@)) zE=$5izCZW@gbqPZsPM3&Dmp3N}+x3hgSv)ldYc;u;J>g8er-6mTL<`nzRE|dpe zkRzYzx0)2nQ>8$~uLu>)LtSE%n6)j&_&=(sGO6@&@#nouLra5 zGnn8W>1u405oyKATE9eNQq_TS)ALEnY%+_AzI#T_+1)J$wQx|H1oHQtKTkbADA1zu zhh7sV5z@aOVQOS7uTD7sA6)*i^DZv~yj6K9G3)PN(d;&pu%NLQWg~DGU9rThha-rM`UC8CSIj;*vHbB5O{Sqg@S0u zg5Y6GfecD?YswM4TU?76lTNKQiWqx(%IYL2j!pQ3)vmTd^$x?U!u#L__Zv5%$GtWh zR61%SK9vn0jI&~=;ktfxYh>=W{MB_yX7&R&g4{lPAk}2%OoQyy!X!+JI{5-MK(d>o zc>ud|YtBJ=6e`zM)1KP7XIqEaHU`m1N0$Tx4)&$v1;>!(Ftw7y1@$YzI1_Fi zo$Mbchxbo=ukN;1uCC8LeTV1cwRioBRvkw6bE+xC9eGM3D=5!Sd_Nh?m1maeaVKQESF=3Z^eJKLRI zo^QubLGSKv-tNuW-75hn+zbc31rioI&`+;_wM7=YKkn}qKt10MWuRZp-yXeu&V1wU z$`6p{053ehzA}0$S)n4I-iD5+E~ehz*CrmG){Zc&O(M1A6l*hC?t9t3)J~$9gEP0b zvj$^EWGhB#tJ2GzaL!SZ1Pi@9+@DWaXL4+Q6LL19dv^&%S-{<-YfG?uzvl)Al9)?l z;r%tQFT}qWaS%0PrNm2^1m!Q&>!glxHU%jk!q2Sb-WTH_9OzX`MYh(p*DPonXd62z ztQplv9e>5ne8;nnwm_v#fv*;bN8iJo(_PJjS$n&k?<2mN2=(1rvpI9AX->j7 z4_;5fr*=cozR%vo#^jq3igUqcmTf7$wHx_3jU65W3Bc;FRRQ44eo`CT+#Fz+T9pf| zrV>wdPAu%;CsxSNs}R5AK$n6W;J{(nfB5>ydtjQPH2BB1_c`u16{1#1 zRkX2KRbd&G!F=bAq}I!6V~Q7|o4Qrj=0eogOpvLI$Bi2->Vk9WAe(_+L|rc1Ub;hSLG z)b<-|TL4g9Cd2~jXwKP#TUv=}@2&{~=wWuS^R+R|&g7U2<$5}$JRyRB(*ppdQ^nE5XF86NvHK2Kp+1|{Pb^R6I4#bBT)6W=c~6}@MFHXH zF=0u>xU;!?->7X;9axR6JNAVGM7`y8E*0 zwzaBd3i>%{X!VNcpi^Mfgi0>fO-}KBT`{5J{(+b43ZmA?4f-)h`bbw)v}UCak{}g< zONUa27CVR0S{v%OG}_jXvRi&md(>4@POP&(_MUNCFQ`hE%fYf?$v&+_@g7o!UEjMZ zjlW93ahdXF;Wl_;whzN&$vV;QyJ_9;y=kpcRt>CpI%G6`81{~_KM2&xijD-R2y@y* zt$SuaP*Ome5+B+urZt&wi)){P^~hD;6z$2T$*lPL2JjYaB|I)4-Qr56hGKRQ3+%2& zN@b4MZc&l#H^MUh)1?2_xV3q*6<~+WXsw_ROPQ!T(k-rb{2KP&*yPd>uh@~iE{yw7lBV{4G`K(79QYPv}Bzrfmp%O6yo_>^9EU zFK?}7PvTZEr3^N#X)4`?^bzpWH5X|p&af3og}4x!5jnhG6k~^%W3=3JFyazkCYuf) zLIdNT$t~U!GowLphh*mU(dU~CuUq4{nC|Q5hYauggDJn(z>P*Lmg<2M`lD&fb{8YB zo${ygZ`$JGV)41UM4V}+iX`1QxHeJO)-Xvkpi7f>Og6dluMZ$T(|uOW~L|wI&CJ<+XqU zn)vQ{A*3b#qCYW;uNLp#c#51_zU-Y!UG6D>*4=NTWCv4bcC&#|6@FV4P;u@6Amp}L z!;Bt{VB;RM7)mJtFwO|<+o6stZx<-Z0+D9;pc-`s?W;aWcWkZLxt<(Z+NadLxBfM> zYf;ozrM9fUHOn(vng|+z_d&i_EC>@<%Q_)W(i2qi46HHYto9o0m-AKTJ9KR^ZQYJb zD|aj)jYrGSx!c7S{#Y(&PKM0O@$vI|S&r93bsjlVpfspTcpu-^O|Bp>i((M^g?>3~ z^{XF@6Ai1wNv?^~k?rS8Dj+S{Sj@V;QEZ^Xbu{tOeBek;dHM$x1X2KcpfGN#5Fr^m@ypEjXl>S#Cc12NpR4E;9E7aSb&YOERcYBD!rmMyALiKN?Kyh7#?pt59_&Kt#3QM9gZlx`XGO-C+@ij&sw)Y)GJ zI}061j;p{$3A-6PqP$Tf2dao#a*}RWX@fVw8qN^3ougQOak+%u0$64^qIoa+2t7kD zT5)iBZ#ZX7GSuob{do?r>qf#%Cz@R|tFRtFR&Co|W+zi^eI83Qkd1zABPYe|P3dWc;Z9O<1=HujSl?!~VbuU#EzQjSW)&0y4AK&$-1w^N4g z)02l2mUmh>H?Vd)=#X!^hNMf!pZr}Zwd;gh!&dPR4qbO%OW8viPu$ z8fzElKcTjNEvqxL!YjjzX$D?Wm5mFa=s>%WIu3qAGc*}_e^>B7`CstjePut%} zf=0ageIoGF+xQTlXuT~C{exLF@YC3BkTXL}&3$UaZNj#UdRm;aY35H?pi88@lo~SJ z*V9(0v}15`c%?br(9~7WEWY-3+n~Xxso^u*=&|0V7ER|TomA84ljlDyokIlbB2_Sq zX+bI@F)K&lFS*#LU~km2*o9dti-;-*ZiAlH)ufgVc(LXCYyc7qEOAJ;3}EubG< z^bjH+w>y&07;055hWjG}rFxw}+*o=sD%=ew?}8X!`gA?a&ij*?@)5%h&J{2Jbs=BYt| zbZArfE~Zfe$bpV zL)!6a+>pv2(7M@`3|v+%V2m6g`n%vi-^Ma4P3ZpDu=v1r0+;br zf&hy3Z#xI|G?sR;&Zo5JU!AmgfG+ipsqZZ14V1zI7MvK*hC35YLSR+{@L_p5N#57? zl)*2;#27|mT71vT7rQyA@eq2?k5*qZ6Jc6L{B^c#16j&DLa1FHj=wE4Q!z0QW}{DI zz+b|P(@RBzpj-3Sc~;h4sfxia^fi_$7<+_e?^ zceb=&@GLdt2udHYZ#}cs&kJV+IHY`h!X)?3WSR|+30X3vZk_6-M~b>=T`-$=VtXRS zNbgEeES73E^b`|%+qvUr!%{lwcZ2MA0@4`p`FV{Mb8ZXhOv-nS2$@6nAEgmXwi9** z$P@1l2Aw^HVRQ}7PJQ#FyEc5S5*=8+s@1Z$pUa9GPG@zLJq7=uzWJH1xP3ED3FX$| zmo_SB_s}x{@qqRG$j*N=^eiMu6NmI!jz9#34IPA`v-m{(^mfcFn4PtI${ z-+LwEEIjAw{mVwC@P2H@p9-LV^D{*(Wwx6s1B>s^zn+3u^ z;iu%8nT^FoGs;E~%8MnUMb7^7ucp(<*H^B2eKhxlpd&C>Yt@NRf|eR{DX z;3DJW#F2%9j^Kbg1C7|j^K*VlqkT&*>46K7OFe2E)n?ShW@3SZbvbnkR+K-&r4vec zDc?6u)jY)Vy{P!QpgEVj5R$Ufrx|K#issU>rLkBvxhI_r0Zq7fZ(N~56!LJIaXJ+N zm?>hD|A0S%-a?{eL`L^Yh>-`v%t6DZ6uvpe2UuBARPMkujBs>9?44z7Q z(ESQde2{eoK8By?*W1IZNguS_+PVC>xDo<~rO*#8cr?YoaKHp#c^Z9R&>| zr%?zg_K1KQk06WfWR~_3YAL&o|yX>aDNr${9#+Rf5&&Qn&A- zI*}tY`+k`R=KMMTjOr1dkcsf30WCmuG&5S!=J>+#+LJCZu_56#XQCN|c0to9pen#MDga-}LmoPXAIEb)9k`)LTS|gdb>#`F#XL z=duwZIVU}qfZxxUePeP>?#P=PZo9GjGQ17KVm(y4%&Itc)KKZ(r|CGj%S@hdtx({? zylw3K+V-(=nq_pKjH|SiC5PCpW!3*dAJHVI+Of>cW~-y5QYXDdKrc#JkW5cJ;T+AD zF8;t+If0;uGYxPy2Q?%#Joq7sg<&!Tm5uaDw(UEF85*EPniQIod?O>nLW)nJbLnBB za@lv;`wC@S^~uAY>Y4*U-8q1CP&8aFy^XC|ND!lPa`cx<&54?kHRWr0Y+V33^w(^- zV0gwr6C$F0hM~mav)qG=l+^URZ)EuWHE38<$~-Wrfk$UWb~PM7Z4*S%P#2-HimNNK zmu39+z1>hDx5)r!Bqq2f|Vs)vIc$X#meEv!JX$bmcNs4V3|7%R@#)+k?7PZPILsQ^{uPa zfSkIkEh=aMd%G#TL_+woe#;H?*L1W`H)ZGQ?mbI7t zgw2S{-Nx9FR?WHMB*d7)9rJQ1uBB z_wDEAW9;hnD%brpaz;z0y*sRAg~`!@GkZ>LUBD$_B4@;9PvIcKDw<0@kp$bZogZ@bIp8rLsJ8eu3@UXMSnAn>|qKCon=;vX;VLNvG+T zSaKK?Zv){_(Ueu~Xd88L$#vp4$9l*iV54o``kkgJc5m`gsH|Q-dq1(?X2E!$@dr`|1T*XJNv6$w&);;=94 zqM$ICxY&zBsE34Z1covl8z+t-1gR!YquhZev1na3*tDwZVcY;NJcKi#UT75D;RjTe z{~9h^BGh%gwPfkAj_dn{0FFP?-e)H|py)F@!zg|}fW&Myt3ZX_o3CN_h5z_iW1X{@ zoU;G`C8ft;%0jlNT|ULp8?+ohBN0VbXFIA_lp}bUenRRUXXGwT$pJ%VoVK;?yDjI) z2iLbY_Ir^hS(ZXh)vx6AjGJQCPLGVCUmBxmMje<`dT7`6K}_@D3syzxft2X*cFdaS zVO8^G1-s=q#QB`!*`v1ur`j;HFOf{+Ywh+Y@|PX_o{SXGV-8!yFP^3+?*st;b_N?# zvU~zcPy?UcOi&q26Y)0m@F{Drcve`VNkVaUk^{26L3acGV$CeT%)mO!3!@tKt&j($ zf_vo%Q|5Q@fJl;v&xSUGK+3O)_oOT40FV=6Kew6%ilE~5@h2#ehDqDGjP473tAHwi zpr;}X)wSdIPwfhb*)tS)9G-p@1=Wo4gh9f4I&p(U29VF~0`p>9-icu%iQE-HmSi-} zXN`!4sW1LR&hz1AOZk(?82?fkB9cozU;(^*=orkrm--xN+X;n+fLy!vFlDstZ6JI= zQa_L2-9dVY4hzr!$_R#cbuZluCh2>4Kf7d{5DsWs&P4jrPR|su#OZsy6mV!^XLH`y zZWRlDuO4BFERDg0ybynMuG}z5_ZUMCDS;-ODnA2J1ZZi#gF`OO_Cy@`numX)H{`^H zLk!D+l3^*FvV^hv7R}Cn5%UqM?6E9`avf1FurXCa z`5=W1yHAJ<^UX$%qy-u z$ReOa>a0^GS0i}NUz+5!QZ?7i`i+KOIoX)c9YVQa=_*qvFaX%oqCl>_M*nAhbCgV> zTvH_*)Jk6yyN*7G`~48~Gzs=J*di|7>$(e=ki@picj^R*b(2HX*xZIpms;GxTuHYd zU8A)I0XUmFil%7l8h&^3sm>p#O*=2pqdm)Gbd33~#8uD*#3x&lNTTJL;|M_DHEhy9r?zhr7GpY(_e0Hre}zyN zu5J3o5(0=umL^2^pgPI(pO69xV)Y!2+NMt^b-{K0Mf?d-pd$0d0%-A#?VTN{{Ndpe zl6kTG5rT$1(!@y$RFRtRaVD6B$`u|L03M!Z6@!zPI4S%N`mXYB)ZLnKm^ICRoATOh z*9>fzh4VIZnMhW{<=2so)8w`aqrEC`#_O*mpJ_Dx*s0AE2X`sakj9)OsDq@LIJO;X zM&vS-uOe(_Ct;Nfk)VtdOyUVYssi&*0*Q>fe z?B(O;3o#~@T3Czn+EU+6LCzw8NIy#UW-=J<=h*iVr^JMM?8H^v@lf+$cqND3bzLfi zOYv!WXfjm7j*O=0iWs4x0eB!SFE0Vh%l|+;e0WW{V1R6~i2NWztRlDim#G_l6^D!H zWBw&&HbQG@C8zCMl3E`tGlmaiWoJBCFDjd9u27XtpLM{Fl`_TK{sBv-#v99_L#6yH zo0?cphF}+`>I!jnVhdu^R=;w?37dY3kP`%TKa&i^0mp|(ZUxdZOmz^Z+_Y_r z(b7mEmmbSX7Uwuq9SmL4*oo{w*@K|;JZSQGP(8-^XsG#&Gh^rE;_{|F!RLy1^Y5`0 zGIs}(Vqvq&E;b9AKfefb|>Z0{jKFyRuQ&{w4!u1^ck+ z+;amDyewZ}t-4~j)tSGLsE@cqb>M+LGcRtz;(f$;5{_o%Hv@&Owb`;07k6~gex`5V{?jul~LHA!aJhME5ScwgMT3n`op; z-1#L@>-LO%am+0b=7`NpSQ=avZw4 z#2Wtj=SxY7WQ|gMx7-%Yo?be4g;04E zK~HAK|3?bGZ48RKh5hTvS3@X8J$JHsP7i6Ftqj?GnqEv z63{QnJ*dt3uCPs+0lZ|c&C2%Uj+~9->;2OSgq2qd;Kj;-o$Qcnv`Q^5lP)JXDz+O(J z`q%G^MLPn;Dt*$?@--M4+-#~*7}Ct_y#Q5Xcfx4Qu)IGY!5)I7MJy?|tgdY!lpZh8 zG_rVQ;jZE$qhsvpaerKAttN?@&);nmNPnF?TI;OxcQ6Cz*Ka0Wvt=3dV{}7RFfaFg zd>^U$4qdNZJon1+e(CzNX93cIjwbI8GF9o!R^!IxQ&NlEg_CLHA;#n4!B{sp73b-_ z5+`)Q$nghD>T_pZn`9;6k&NS~1C!L4Yr_{B@>f6 z8zIL$xkR$q_bpgL&mBy6pzw_M-jhB<>x=9A>->ELpG@W8z)vL&+OXIo`0+aUZqjnI zLWkdVE=Kpc7rNIeuZ0Dn6gLi4f%dOYuN7JHoxh3bBQ&R3;`k*6Y(GR`I8Hwq#RUuf zCCfQnRMAxHvW~um!9~tuL^>#F%F3DJcS{9NDD1do?cyT(C^U??adj<0d`O|RNuQZ38U;i|cc!~NaHfS@?{k}jnvFc6V8y$S?7 zj4QUIdxT!_&Edi482)1Lv4cMPsq*sltn&}R@-_~IzcU6|WqCDJT6R*>o8ZKQ_+N*$ zi42S?W^PpB`9FJMKiyn^(TO-Gfo@Nv|2U7L{?L)7vW&;(WZrsa-2>n+B4?WfniW8_ z*twN2rX(LV2`|+s&W*2bS=f+)lUm*LCfl8%F!y>HL^6OReST&gWqc#<-Sx6 zDN=ZG**zA1x0#grJOhga`!d|M#!HKk{Glw@Hk4`%V;MykvgXK-Cw2=)D+l0Jp?C!R zo}At8yRu5GI|}s;%6|Q4g=VOn1#fvs%Ysl6Ef$&F4w>58Ra|s7KqT7;wU%93FSZR( z=IaX=Du<#?3j{Wt$K_EJn+lt^V>JecN2edI4|E^Jw-NRqzjf5YKfbI?xAk0YDdBtwyqS|B) zeWrA(-rD{5x;bVJ*VeC~m>keNYxDW69O6XJ~1gmf8vO8Jm{f zU@c)sml2X~ZwgU*FWW4i0j?hR%1xadT0T_+2;TP|=76t*%UmPEEz`5!S3wP%sKI!w zJx9G=uPRTVSC91IS=CJwTh?>D{$m@Inw^uYIE?6+u~zM=TGC{{h741ViJu;%eAKr= zV!qo{u0=Or@kT3qdqDQjGFpa1)$CszY`pjCl;=(F+a;inC1K5>s1Tc+KfahzbqDZm zHYcH6pi@ENKo3xkIg^w5#kgh@ktfGfok9weF}vcS;2A54L~dsJB(B^TGJkA*ddylR zZ$TX^;^_Q{Yo$VE6B?)QZ$6HLy7Wzg9%LoIB_rE;c|Jes-=X(K_FuX2vOEw;H5ZDT zyiTUq36YiF*MDooteVeN1L}V)!k!(CQniCN4KuQs%lvE4NsDi}Cjz1*_b~HUJ4pny z)%d<$2@N$B^3Y+f8bd>7GqtTi7CGM=t7H?lTo(t-=y0!m-+g{#;s2-WqvCYB+M@#i z6o~&PU0?XW)%C6P91To$Ol=$-t@W(_H@Q-%`eAdxa{sgCGo;u@k=IZBjxkUK14p^+hcX zZQX5%8b^kpM(ManIaWif?`<7jy${fX6VwqdDWx+|$q&k$e2G?5+gn#GK2li2ww!x< zw>%ckUX4f;ya~y)4;|tpWk-OLQ4!9sqc+j(pATv~MZ~gXEbBVZi4bK93;@*4l%118&RAbi`=c>hOUBAkaDKuI(iL&~rWj<(%6YkIC1P70FKGT3$UR*DZd>)P;0c%`S1KdC)Cl zvU-Y~XFSOsz`rn)v}XV8&ftifnBA>!R-2Mt`u#gxj{!JgzjD98m3BwT{25>(2yhRU znNZ7$y!9x>sM6!%?LM4poBoW+e`Yc-Fg1@2rxq2v9@-p{_szSS8ZkugWd66hD^*D+ z@D0a;VQn>y4+^Vws&<&Myx@7Mj75(I9aGKZQ9vxFvo@qOVH&i^sUr$2H3i86(RKzt z&d5#|lkgAGnMUo(-kFz7mPR~m&s)SbPA}X3K@QCQ%ilj;KhIAvzYCZ^AXH-#;2hu~ z&)UWi6U?fU2A?YH`@R8xT7m5CC-7m^M`?SiWZl4QA*!2STFJamxqg4_Q7OP^BI%5p z!L-j(wJD&)N$xRHcA>iX0q2o_?Fmml%Q()e*LuNGC|X9tE{!(FS0yi_%tg z_)Ah$LvBQz9BuwcUyyFFh~em_8l*+^W zb@DZ{(d6_wF8@}mofvc=(kWZrDY=zvXVMcA-y7uf?`_`>)@1Ob_Z}~yT3=MtbXQ`5 zeFN%5)p9OrDLzh+XwwXpMk`HI<@T>XvrsqhCku)qu&Hr5c4hBLlXJZg#{pIRf_K}o zck!ClEMj?}j$uzEw>St>Hglu_k4ZLT5IL!fKXMPj0 z!oF5QHNM8@6arT!Q-DAbG!+3=@7lK9t;NpBTT}o}0+@G%*ON9I5&Booq#?H~n6_#vyAH0`6#J^4CFu(j(tzbsg z#S{=PU7}!SJn#(41NV_4yTvO0ItDzGUQ29nhJ$u8JIXh*e+BV&^YWtO((5w-x4MBz z5~3(In?GLruSQ1%uOq@>wDDfEe3b#Ju=uZX#L>C|g+$}rgn@18X_HyxF07+fS^#S< zW6YsYHON0#J3QB>kR4d~n;r{k##ZCVtzL=n_olv5E8S&%CE+D79Add)2`DY7+=t%{ z$Hf%p6i7+Uu1{P>AJzBS*8KnxR7FcVE($Rkv#;6Sm&x4xeziL%Uj}fSHkvVJD3u~b zj6>e|x+^ecOE%mIkH(h0{=BEMs0TDRW^Bg}OqC5hsA|EmKFYv?)N$C!j{wQ^MmI}@ z5t^V{Oc@qmY^ZFe$=gdfA&r}P>!P5$f-%xsf{ID)%ajZ-N33XT=Xz`jGi6=plX=y) z1=sLJf457hlDYv>V=b7^NabS-Dr-Dv(HL9|i6x@sc!44AD4x4?3f(ri#*`F%Iw$9l z?5%v((B#mO1hEie`xoho4Y-K7$ElW&9WaCzP}1~TI!ZD1K+Tjz+)zpyiyp*iy$pA_ zY$H?8MJoz|;EMy{uv=_(3P2_td$naW%uGsKr{o~a5EQGC5kC=Jv4X)~7Ta}4o<1Y3 z_(&;r-XbpZ8GYInv_w4N-bX|XK0>JSpD{9a&>-k$GQ3COHBfxdQV(B-NAj3Zpup+r z8Z?uV5d6^UzQrDIbTE5n;1!JIpNRyLK-IrMnSyC2f zyTr*@y>hzOY(8P9rK*O(p|SzxL$rB|PUQni1MYO8PLocBAZMm(=V-^1$&yu>d!cD#2 zof*}eF{in-#L`W_Bqrf`NkBw?)PN^Q;msC>M;$GrSS_HW!f><6TH3)$QGOMAqrh}U z$9&}a{SRsX6eK#hb>YHoo2zZxwpQD=ZQHhO+jjSA+qP}%?_In8bME%Vcao}9DoF(u zyd(3S^BF1S%(_KJ?2Vwk_-4vA1Slx0*S*5li3anwTz&M_5qWb^t(lu%copGFt+0i# z%=Kh%SxBQibjB-v@FLEROJwJo2tQdw2P5%rBir~ve^lu<*4%(S5uGxJJ;C&!?#sQw z;jW%!b8;-Fzpdk%drd!Azj=>l=s_y%J&k~N`o9n6pVDujwSzsLil*gSNco22Ysy79 zLse=0RcDWKDQ5p6h5AQi){7XHX0IoX-711SHeSeGy?xT1X1{cN&+&R2{{%_1{Ft@t z^!B`sf2VV^O?Kns%VV}Ns9;fXpmtBiu%)U&fm6XuNmUCoVtmp4{{`2vF)_dw1OPx2 z+W!(<{QpP6<>a7m^IIkC@E2L2{Co{;idEq9 zOb_c15Dm`S=6q2~(WM*L*A27|aePXWc%;i0f+o_8YYjI#WiX28--UwtxydSoLN#&s?ve6G77oAPUK^ZVm}@$S+uZ(LqVq!YqlQ0EIf0 zjY_gb=Zf9~N=#e=Gzgeip_pRFqZVL~BX8bluxveFyFqK4pOk%MlAXwY zxdTZ{l2A4ebTj)=<`#Xq1mM`$y__NI0qxqJt`45s5c-VS-8L5o;7a(j28A>f%meFk!Ld3b@8U34rb zO^_6eBE`|MB@%ZBeShxn1*%?qK+*lc@j=8)yXON>o#ejw^7xCg31m`kIim$Jt1UVS>GN}UAx=qb8^XLPhCe4Uh-~CHb$|TccUO`PlnJm$;Wsp-qz6fd+q(>i`T=h90`|mJW zxM0pSoV6Q)f-+}Cvs{6+A7;p89@;7@Q7$LEJ3m`9`Ntgj z7*>Afib=3^tczC1R2CIE)0gWyT0>e%1QGF!C2}Y?o6F9}WeXqF!yC$#9Gc)oZ$AZHic~e-rK5M_5Qn9Vn+u{#XXK~EeM*!i+R=p8s#@$;k(y=O z7p5!MGjj|EvyKQ~Z-1H-lv(JL%hgkw%fs#2g$i*erFW&z!^}V+C#|9{R9=E&1apvw zy&eyR6QOS{JqJk94rc0tQpxIsNGZt#97mWn1p>Jk6lDF$=~bCN*v7)<6Yq{zx7nbI zk6oyV*F4QE2Rx>jH5@nPLv%uFc|@WNc)=4>tV{TFTIJwVt_^su5ZL=>PVB<8@1*#I z)6Zud24`Dv#&5+Mp|dXq{I14k%#coINw*_6pAb$yGVZSuGhZ5?$?l~NUA~aJAuxf< z$WraN8OK94F)clFXXq%%?w!1$@iP3O@S3}yj|QfQS6aWMrI}_fn`oItr5`lYmpfV0 zvJq8vf6T}Q2l7^FvCE0?q_g_I(!uJDrw5idB3ae4gC%dSdTiBU>Z8Rk2aVyXa0R!8%dOs-YJzO(E-?UAh`1%y^?e^#JM`^;9(ROFvy3gT+!C3 zKAOOW9%s-ERbcDv?wxLqJ-NMi=G$92ai=3LAbfMVd!FjdRQ7ngzS)%(momAQe)EPII#q*-dO5KL4WJSkgD?g_^!pY=9|1?1R2h>lk@mKE7PY z!~vtMNkwI&vG0O^hG76!Sz8DTRg2}CGjRXGni1J^CqM>Ao{oRjzJTT&PR^9{UX|p@ zRcgX(74SUF9$FXL8bqNrh@J3H8GveX_N|1jqdF_({LR5zD=WFm&RWFo>H)vkl>fsJ zrgAS%1^A)JQ9TR~-<7Sf(A%Bf++=IqmA|}fw>oyCdLJC;Z-E=;~$IKW^uU3bb7LV!Zds zXX?)E{E!?(Pfx2yPi&ld(Ukd&Yk4JSwT-?GzW_*u)(yNd48S0g9MMiv;Z}Zvd%u5h zZ1`~S;SQ6;Xyuy1!5%Ui7f4S^?PV0^Z$o6rl$^WfvMw1bG&4M_bHGcdXOlKYb(b4= z-6gKJwdaKz8~$nT=v+K7q~s*%CH;4i3qxODSKb|M-j`BmMB-TLQjnyy%3@ZmddSn?B~W0Wv4<^P-s)>{J)% zJJw;1(RD7Ziyb7c5$Q{N)pVViYh#ZSzFS^V(*pq11q36UN;q}O<6V(KtlF7&M z|1|FP&YQtC0Oh;Hyff^C_X1_Efl}4a^BUi=7%uuQVjP}E!i~F_&T^vG2oBiv|3JRm zz0b?Smv2xq^gY~D{%c>F3{M&)mZ`hh`PAd=XWN<1JL&)UxL7h+r#mS{n8loELE$F` z;!SB$PWPWJv8-cjpB3+2c2O9r$?h8LMk_SyFQGh7oZ>{;a(A$*X=AbjAJ42v8`c|E zN?FS@JdkUNcD_Vg)^mbVH>{+!$_qxH@1YO>p2^4Jzt+p!VWITuKduN=eD&J1LwV*; z^WZwe?s)$+hHn~lGPt;Qdi;NBkxvzWKq;XB0C0)^moEK3(ITD9t&MG+|078kIW28B zL|b;AsAN!4k^w?oGBY?5@GRCTH29k*|oYLcw}8v&ZDxZ`xR^;)sw!diksT+O{2G zTdS@S9(7!tA%Se=`_b}^H4Gs|J>(st{ojU=nt~)KXR8Dq{kVc;i0Iuu-LDzo{jj49 zvFVl!xxJlFJ&lXMy5O&Iwf%|6 z(8O*`_dFHYBP_d5R_3bQdEc=GN!_dB zO8jnbh1CjDbvJd(_9R6MMgf9$yc6-s@fTFl@k-C7^Ste5um<|j7=ITdU4>g3FzmVY zMaB=#@PlAgeYFf-r#_~mtv$h*Jj?%0e%Qsf& zP>SW@RNK6AuLpOJl(<7;N#lV_66+QBo(MgQg^y~buRg9|QL?~&#O<#DE^I0x;k`z2APh650?$%l4LQODwhqhY+e=?- zb{m1PqGgoxjddmbx*jqiZ!vtYZIK^LlRf}~YuQ!&rr}Imz-U)4# zBZaGJsF$y*eU_ZBm$$?#-(=aJm$6jYpOZ_Hog5MB*z;1^9G^z@6GWWyO>q(2F%Ua> z`+ita+P}fwK!N*@eOdi7c+BMOn|Q6qXj3=^_zswnF;JEXwd#-!BB~`#tzJ?{3{_dx zvKVfEO2hNP=RWZ-M3sc7emvD(^+YVQ7Dy)@5$1O-mPTGq4n93ym^Bk;deNc2O6BxhR>sUQd%Y~oIH@h8^b`wAV+U;R z6PTzdI8W*$W}{5|$^6n4FDafp1gvDFi|Z4DDy)xo3(7hhTJLgho^L;&u*yiNm|hfj z>X%8TRK~KOzGWaZnPBP5j&N9@6zm=SFm3CnJ)TkiPRygdT&74CBP(k`>KTuXO*L+_ zP}p*b8ge8Q@bU*rxk7zN90Z;k?ZPM_6YYRY$U9bWrl`S`_v!!|Vmpd0G;}3a%pf$`_Ja7zU)&!5CNPO*dB3665i&+Kqg$>kF<_ zF52(JshCvpp!Zz6dIknvPYl_5)L0NsT$;6;!)PjIGg~GJe)GDy|$ljP>c%Bm7+NiH{xDlZy-^r(@})ds6~g|a9-kyzkwZwu*UlXKNRsm z(6QDxhv(q~8QWWrq6$p<;9T~A{{2Ez={^P%V#3%|jWPMv`sNTc0JbUa=8@T-^&Lf^ zt&|Nsg*h6u0WtM)fi<-HMaTXQ78TSW>mL|R$)mxiE%B2 zIwgrD!HUI&y-#Dr=~%rP_$_RKs7B>tGWalT3T70Isv+aZ?Y6aEV$IV+xC!q?SdG&Q#&#q;SbIrdkI8P&ss;E--{A53In{D*5ld0^YHN{ zaIswzRVrAsNoSpDeNnbH_L|?4@6 zSdG9Cbge&T^A!O|vi)asVFESy=MQRf(^PVDu12k#S(y-%S>tyd=!9bB&`sApbGu7C zwepW%gF5Ez?$?s>BMQNamf4`NKlBG*Lw4tJt2Isc+*=zs;dV&y;2-xsxZ8v^XDj>i+7x zQT^nnMs-_rrW;pa(C`j=-~gkPyQ}e1{kmHX8)Ej2skL_GV>|g94PB>`@O|K?$w96a zt9Yzr?sr8W!c_&bNCQ}?k@cS@83~S>R){?nJwUyzJ5?n})l9?6Ypll~ zW^3p8F0%8=g$~J!$d|s0A~x8{d+JrICN8pAY72@wTilzc4#AdCd#YXa>#s>ZThyuY zkiT=%}(#;sc+(OOB(OHw{zTt-=ojd z7wB}lUptMdiS6K<*20^lh|*WIPWxGDj|{PS!pJT>*`lZ+L!U`6Aifw;pgyFhVgdB< zj|cqwYJmhLuJl;!z%TFVaBwj4iw$jKS^<yVaHi#0Vz(E6*oCdY}Ilc-CZ zftQ46e|eR7Y1nG|Ri+IN4KzE^^M0LimWjXijB;I#BA~So>=69bc1gWx4b&a85Rh}O z{n9_b&k$)hV~XMhF)7^Y)ncrDKq^}I;SL6!&u&m}n2sak`ok&prZgA}jtlsEBg=oo z7X<@t>o8?DF~R4>V)~nubX7X{;%OQ>-z2p4Lcjtpy_L8g;38jrqpJ)xT^ydr2@o5f?fvuG*$d;G z)$)}JW76wlcwIMwl9Hp5`Hz&Et^7cJ2h#(G&Ti?nej%|c=>t>mHFWYxK{5I%fjgv@8 z6Gm+EvPjl)$H3B#%*q~Mc;i~*u{~rHxf*d~1ykR@o(KO;N@x}279)ZI0I(qcU;iR( z|CboKvxC)tvJgByRX5sNUVq+DJSX?iJBi_rSa5zwQ|A+8+EeFop_opRN<_m^3lvB0 z|1!n_UYqt>O5Ri1`_+tPun^DtNUpELI}^VCV(SyirDo|tSS8!#_!EMt3jW9%RT__g zO!bz#k0(^BND_VUcH=B44IZD4cvZ#oArhSNL(o!Nm8fL_Q{YOFXjHSj1_H_Mb8N zehDI56zU*?QY=>JMa}Wz{<5?4dOX^ly2JnceE!-U++}*~cedL;^ZTaChBMPjy2H=0 zFZcV$a0^*Rk&L2HfPxwxghfd%tW;-->A$QbZEgv>Zos(xeYB*5Wx_pffNA#4c=}Y6 zmSIBVJ89bOR8zuzCUZi8$`d&Y#Rn_111B>*umJcdAQvR1E~UL!r5ksBnD=4R_%U&7 zbJ2gNp%MtTYJ2TtC(z-GaQ=2Shol1y(1+g%yXxcmIso0} zJu=Y#Ay9jwz6&VCPHYB*fx>*MhFe6R;_ zeK)c<(inJfATwdvJWwdxdlQrkH!Wu*+&$~!wzlT;dhY4E0e@s$irRzsIWfS=?lbEx z)`9%XK3zMQ+0cAz>crcWKD!Eh`}x9=taZiZ9?9L+QMyjres;9L=^OJQ2w#CRW=)t4 zs$)51wVHUh1Oz+r|2am3?$KrO_crx&Kgv;&^jEm0`9e`9@sFefL z)!7~Dj9$uZF5MPUfD8h6$*KqwfH}2goPiF#7&ksUyXh_=Ve9MvEra}pPFLwf`PiyD zUyHP*J7m=vzqSlzqB&#W(z>?hp*Cb!8Nc@o6|$TX^Zov3@QQNKs~~(~+Ct{&gh7Vu z7s`O`k~^sX?qG`=xCN$M@%WN)R!i8bN^;_)F{nbt&BuY`g`4%w%TBE|+@IMR8tB^F z&G&xu!|`qROY7m2<;%_f`5x*0{tAv7M$FcdUi0l4X$&g$g(`2j$lQ3-&7^B>admm| z@p+2G^SS!2E$p7v8FFT?1Dx(Y_z7+N*WDKEOi!yn0J;ezndfjCiVNf^L-l!oXM})@ zqjFkhd$nEbdAbz0U+{{x3v+|M+1nZ~>1gNX_FgRaP?;|`+OFSKj9Ya-WN-U(F>4-N z8n`o%7ziKu>-GHnw0~j8!#~sW?>%?{Y6ecm7mHb2ac48<>D#$Bc6-~`zo+N+IC6Bl zRqHuh%QlF0yb5ev6O5JB9j3TRBj)w^arbK1?e^^fKCx{TszY-yK+fivM61;uwFfR* zdfWHY3(e=<&BFwJz`3XW;$G(`bQp$J_pHgXfu!(wuhkC9fl#9#`SEKCY1Ii-%k6`z(TzzQX4>w-c zcW02dtHScCPg@N|4XnQHGtK2w@=;;RL*ndr1(;`;hL_V|{ z%6J!?q>Ij+9O1E?xMX+1N(QISXnEo#B{RX<4&^z}k^0`i)RIcT)b2enz9veOxzOB* zhZdrVrVu>Ly4@-0Y29aOokwxxKnmejQR4B>djTZ@5*g$vT1Vv&C0M*!l9+(;{QPps z;UG2QS?0vjRB1+I>}^sEh)_(3y6?9kl@!O|?mmJE5G9L z2`=h{=7i}6D=4FGlOjO|6mX?C+dw7oKKZfVNOO=u`hvCtvqPQAQ;L`Xof2(%=#V!i zkTJqrVKO1XzpO24X=7p7SxURwM8eYxJ`xC<3Nb*r5ivl!50E~jW+XrEenHzLF@pQ8 zdZf{7(9gQ?<1%#eJ&B*&VnRW2DMszm6Qw*yz&p~L{J;@BWeu11^u>R1hB#}}FAtxr z$81V%I)H{RsgnxW&kvwO&JE-^-4Hm|XECg%Vv=(VA!jJ-o+i3oGN7{Mat{Wn_$GoT zi^0Db%LksfpsLZR%yJD~I# z??OtWyvKyes0k9m@H(~vY<#Ea?q*A;H-Qx(F^Ypql45J2^k1l@CJB4sy`gHpF4kIF zGw5Cb$IM0>putq-$4fJ$%b`Bl^BVgoSKFSXGlQo@CS>7M)&{XW0uf+Nn6!mErY?B8 zd7IYZW+_`59q0D)lPPW4-QgH$qE=pxD~s}G^ktdG$zh&lOa4r*vV_~4zx_+;_VVso zN1~;R7EVpgu4rc2KQgW_q@^QJ1yv(NC5hi5x9!L?pg;%+1a^2%z!E$+iM>1$2Y0;0lE!Xt|TnwjwDL6&u3GUDhBCqBtEC?S2$R@ zbiV%ex^ASLxKnotbKuy`5i4?F2Iv&!7l~o`U9_@ZzK&N1;!S zYSQLUe5_h1^>&pB8! zFA5+T=Xqg5^lT1iQIjqV7uHUA5CnrcnM2$~{Zk}7jzvpYimPAqe)<>VjT6VMIo#bJ z);{vK8Adu+WLAhL6>g~d?IZqhzj-4 zAU*e=uFxlT7r}mbWqFtqA&jcq?Kw`~oJOrR?nrHU7)Q89288r1UNCh#DMRGIT@r-( z{ShI|ynqk*->Cd1P{{kLTN+sueMnSJ8Y|R*-58!f;v}Q1)HydFzOoS6TAzL>>!Vcv z+;~?QDc=ycBkQ9M*mKMNEC@Tps!lr1$i`CEn{3-5Cl#4jh*Kbso$ zod}6$k;&iNpe4$`GPYRs0aeSA4%uHDR^ax)K5WQT0(T+<;|82J(#FB*ehPMXof>4%baHX52~(B4`sbq z#HHsKxwG|t+B){P$Wy}kxr4Aa$m=4fisIvFM&F;_PCO{ z@+^1lZRgTU)YDkM)|cmIy`2}fZ(JTPMF}Q|H-x^@l%}BGns?%cB~JBXouEm0-Tu{d zr&WX|3S=f6750AV5=@(o=t9EW5@`m*fCL@a;L!#VyrN{5*hTZ@p`ui5t;OM$*@?9_ zXDvITKZRe4q#%N#QnU5@e@et{CcOHTz#G9yr2);6Ot}-6v@;&gUi$B{ckjCE!NA9~ zLT!e{{WB6k)_ZoYm5@+yW<@v~=YTYpFw?$+q|n+szF zh-sy+(S8(ExnR%AxvIycw>8#NS)3Ds8PHbrWbL1Ipy`b2V6Ghj>JjbW9M=+Pxs^+P zwMLC6)X|i#M9W&^CN9e+&qN`aeH|_D$xMe)_vjA26RKW0yPy|U9&`=opFL@ptp>e>-D9SmT#6IiL`Q=_spzIX}tnLt0;7 zD)M5N{hn-Nynck1J)P4>#>hYtKtbmxCU%l4CMIp5+6TZ9v1H}S%;XEien=9vdmPgx zES(Birqt~0DH3L0hl=W!+HGbI#PdGn&Qg2NafY=n-+nI*<- z!R-G%&9e5Gr)upBZU>K3FZ(9-zh(9l>8}$#_M=>^y zSL2vPE!ufBjFX#76RhRr#A~QD&ECs{+15jwM44{!uq>k=hHN2M8P{Rr$L|%Gq`0lbEV1 z##NQFB4#CnM+36?$Lu#ufH*4!5mMIqYOcqWRvT3EWK&0W#NLaXo9avgBE=DwOXi82M{F+k)wW zi1s4Mmfy@l*U=!KWLv2x;t(P6nDS26BL4BE@Nr*f4Vrz?Am z^0Tb}Hs~ju5JZD0f!GdynK!~phNDBRhR#N>X8&Bh+_UYLHeub>WQgLE9#SrCZC8yZCK&q6%2kmINC$b10x{jYsD@)|o+K?ecI8@q3^B^q5-~ znaSGKRc`ithGCVr^tgAaXoz#x;=_y~$K7zzmFfwILZ6h?l!B>ZI=brErYNAOCKFDH zr4o@|jX5>baVl8TSXxBN9JVg%uyX6ZDK``?6|B5ewC3#wj|%PP3gx9mJW5xo4YWUK znNrrZ87VoDt1S9%xXs^Gn5oM z)*2WvtMGR>((F5UhONAixdQQlg6@~`?aKW3 zQc=xCC0}YJ%HNgY+#xfBap+Ni(mIU*F~W^hV-W z`bp{duuiGC{AY6|VzQ!{8m9`@U*_5>FQ1ouSoP?C)~nloEripIArHh;$w|iLdMEv^ z7BUNxT@7|z7x4tDCrzoyIA^>s5a%mYm6f|3?kvhmKru6>uq=G%==8ngk@B6Q_Bd;C zY$2C`3K_|kLXq@VcCtX2O`hhgNoZ!NeP`?B&a5(AEm4K&N-nb$wqtl;G(l z9{bHl@u~w@o>CRdegTc&xV85`>kd5IqEqlNk9Ys5ndS4jzpqI@*XiZ$o6V zj8u)CwTN2c9g16VjQzfW192$xl8lJTcm4V|GLn)P`tl+n;&gPnZ)hIqu^3Cr-iAC1gk(om++y}hzruE;WE5{}ccB*YGN!6a%$!{X z%!Go3CTC7)@A>0df+}Qg>9M)D9A~(P*JCIyM(%z=)7NKnWu)K_BSYlc*pS{Y8fMka zW8Csf_c#3Z-*DZbS}D5(G5~<}Z+3v3BrpgH0L1SI06-A&JNbWx{}UU`*~$Dr@wzU> zev3_dgzgKfkgK7Pshmgx9u$YE{6n;WxNag1k4EwQ*#w>{z2ojV zPg&fVJDBBnc~MbIf~?R{pcwLqL<9Wd!kNnlLFm{WlQ zYtw!u3;@4!e_|LueoIgO^L++6-SL-r1e>Q-U`8>S+9oMjHoW^V(Gf6s0#J$lvO$aW z6P@hLiCB42(zGVO(p~=oE&GI9lEL7hxjxn=&RrOubn#D zlr<}r{9H4Hfb&a7Ur!aFc(UUU&)5Xk@14JX6GZ-d&r`}!bYp(2$UOe1x#<7tp1bOs z|0h@EP*pefpbggdrS!K%SQ^UK<(*T+V-<+!advQe-v$1m?hipIN}_ z+$m-nf)RAwOz99_gmHaPEe;q6GJ+f7?tvd-S#WHwZ-iYDqQ!xJ6a)>ZvfkIX;0TXh z=q#o#UL?umqTVgS8huNlq(l}E{x1KtH~XjOKSW9T9(fK2*pQ|z{iu_#Ax7XwfkRe< z!(9R2gz%CT&BQTpAmA=J6#C{R*%e7L^;Mew|qASg?s?Wr75qxz~) zdw_eE=@L>Hqhht`2!HEXdthHI^;wde7{3{EdiRt@lP*}{ix;>?9KAnLQ0S6NJ8`}v zWaX-8q_vV^MSj`>B=~6=Vh36QKS;5#Uim0bMXK0;^JULAeV)no=;ZhJOLT>qJ>q&91Y*E^VMk9Z}d-vN(}OTwq7-5G@XK?8!)fV|4!o zbPdU81CP?fC_pA6=eMjvHo{)OZ6B1QeBNRb-!$**8!p~^`_K=5={IAlibdQ?d0 z4@sC%p6Ld}M~PktpisTi0ZpxBnWzfYwusy7NxG+#{U&6WdcH$C7Z&ImTmC0B%=BvH zUuhILM2!oE_Q&9Bx@p8-y0bV&g*MNuMO`Pv6KM<#H(`3(1a_mWKnaL(C*FCFvMKXk zezbBi0%g=wKOMo14f66jiim=K)`@GGVydH&3IKqq7uh|ins?j)_U5NT@TFs|WjFi@0aWChc&eic><<>A4@Nin zwcfHK^BF-{6#hL6_WaSTQxNcSr7ONob zP8CSnQ`g=2^jUPaq+3$Ja-7|$AK6cjgAyKNG54~TpzQuE1LHGd!IosqNPSK5v(iXa zDVsoX6Lax8DQnvJ-Z5ja*`}-UG7{Zl8IV;2>x3R5^=-9LNKLaZN=If}VcbAfg_?x8!)YfE$$*P2 z;RIXXQ!HpsTt zcm}hUeNJ3ty@Xa;MqRpV1@z zdu$i&AQx|EXP3#={)*s+$sDz#v3s(buMb;WTO91+K4hiy?Q5};HaS+~huIkIi6za6 zXhvT?saswm@g!c@V92wLT%>Zx3W=tz&`}F%_(B3n?+D_g70j6qX;kt#w$!P9DjuxN zL>8VIo}_Qf*CTm`ZN&065`t;DoG-t5?}xTV*k@vUF3IrJ9j5DTN^qna|62n&N9(5Fw!}iI~mj1=^I+=n;JXP z{q`dMu4kfQr2WrmWbWuhV{T(&OD8U)s3agI^;=mrO1%s8+cf_7;3Igc1HUaN!0&?p zA&`XsKOS6KL`gtcKuMrUP19rJx9;bJQf5oC$_L4OqP-#kN!1>+S*Eaj^SOU2HQ*32 zoB;x#JY9lvjB|1HXBCqY+V4JOZbubxgSg`Qdp84dqa0TKxnI2_<5c z{upXTXPwxly_}uKx>hO zB)f2G4_4M81ZX;)fJFbV*+YR2vd@{waap#&0qtkCuz7n>x;}-*AD^;bU9%q?H1_KO zC5Y)=HWH--M>wJDoZW3Dd6G(}HZ7NzjfRlx>wV8*;S)GktvMQDFBIeujU8a7} z(H}(a=iWu@hv2_X7fB8nOVtOcQXoY8&@mdV~qDHRuG zZeT4E)sodceUUtU3&${gulwOXYbGI`O*19=jVy|Z$ynIu> zdDKgS(b}$wZH(_z;VxRT)LAxo!l8@Z_sxq%i0Y@Wc6?*CMz&-*RG~W!z&4_6sP;Eo zO=D0#1Mnnl;yjuufd9m9x=%-G+@qAcx>&a(%?h6gjI??<&3}2&ocH^{jv4fi6c*l^yFI$o=xz#3NWa{FOAopG zzLs&}@_gDva^3746DMoUNt=oXMyRO2=b{PKLxoPH*bVQ2MxJ#m7(B{H$DxG9$+2Sg1j_o&OiG@0;Rct{LsF#KZjLe-_7zmrQ5J-Nn^4XvJuy46nvUQ225vm@CYXh&1&P5}Tq<1`#6f!wnaZ-&2gFH;T{J z_6Mg4)4ABaObYGH!>Q#RZdgdis4oZyXR=}q1@qD#z$gKhi>@KgA%@UdaYHgPR{uS)splUltT@<7PWj=^?}evv-m(*P0_GDDA?lzWuOb8O52A9ujH(1 zGO^7OKzQ12Q-SSTfi;5#;7MC)vwfC4SBP>5Cr?i1hTgDK%w7Y?dcv@yJ1hCigAFK_ zQr8MlQY=lV^Q4s4M?Inkw9&oFU^Emt9ASOPxWPCEXFjp}9lNp<~7&pfPS)ncJ z{*?h$ZeqX%?9TB0RLL)k)8oeaqw7d}4mwMMi4Q`s!j6AV^&7c-C2fw|-yC)$d4bp(cmylQS9R)Tu zLGXGbks?ti)yiUnBb5@2>bszkxbc#Q{S%`()wRN@trKIQqtDzO()DA*))F zRgzCi*sxG#37ja}GS7!4ZWqchAbMwIK7ZBFb2_q^E-k{koDRj87pzlbd2z^v9X~e1 zm!HSPO;y2w+AEgF+#m0ht_r{omb<<2{d&Nw?uUJnX*rUzq@~mo4_KcUEm6c9kisVd z5p+_cX_IORx(s=Aw2zb%b+!=M5FFSJwyC5&U5`(gjSZN9&MDZ1?$ozassCs5SqB?Fvyf7S z3}(5EiVlQSEHzHjs6$Wv>b%9f0>*0X_SGX2O_zyI=ODCuAMCqPq1*h7wzlj84tH@< zU+0c-;Re~^e!D)gZR4_Q_mW+8{B)z&eWbH&QVSf~S!>EtIu+l}D&Xn9(uu>~H5%Vf zwYSc;)Wvb2YCLQlVnX-wpFQ~s6Q-R=ITl*@$m=i|c&cAi!(q!LmG62cL4yxjvhJ(* zr)(xI`nK^cYl2K$9}`rdnI#8>Gg1^5G35IUZPE?dI`7(@U^F3vWL9KZl89rBx5EXT z{X+UwSA$&;h(yDoZOTEBverY-odwAxIQjK<6D-7Q%-V|ax4QB+3z@M9lv0fo%WIST znOvclLy*DxC(A$+0ym{DqwcM%T8y;n)bQzn;Q1^Nz%It2kBz&00Nq^OKWRbKQdNdi z|MFis&ZaQw#iQ2Da0ZdoWh+7(18HXvo8r2^xxSV3ZMIIuXEt})XeWAX#7-^&(HG3q zr{jZK-iEATMw6%=LDdv#0JiS-S);482WkdYA^at#+?_XQ*($rsNVIKJq1dDRxqsaP zcy>*zwiAA*e0WLJL7qP;rrBPpiD_BswZ8x@>7o|(S;ip!)EI!8aw8SHE`x^o{tcV` zS0fVZypT3P0ss(V{4b3t`2SHODu@WlDhL;)il-Kgt_;6;%lIOfnc$+`00GLQpa6=n zVh60KlnPXIQw;=+9}9;uHIyabq1^%#Ts0diPBuIVVrKw(nUk$e}7-NYDu?% zh}Q+FQs>Y(wiB_MY-w&~NvO`S4y%zJWWlMQckA2P_k&yC^V?UV#C2nk07|mK?teSt%U^C4`x|kF9fn`ossz zaRmoIS{$z97teZCk?9xO^wIXc!`cO{Bj=wbt$S^v^;3Tqn)lLB46Fc_zBtN@)_--^ zhCe@sHvM?FzK%c|xNM}P2h00Z0I7i-<@LR>Oz=lyy)s=HvDQS&)&6vt+ob!1Sj7IPRV}uI;cZC zBk4f|13K=0sC{F1_)%3=U7m>NGJ$AuQ#$7iQ`jxH7!SYh!z0`RaN@{&p%xi&I zlR!m4EpjA-;NJ-2Fw?FZNFUSrl`jvLO7u>WMpcAIcB_$xAZ#y{wtx#o(TSJ5NCy!JU6s}n6=ZnEECC>dB}hR&jk_gy7>Nm zF=f_Bk`A5FguaAS4}P_KaW&umAKSZE*nP*RJNP&%v%purQ(w$mKE!XWm>m2Zjf-PC zfVmuvXYRXh8#?$%BC3o;B`w3du5C)g^*gKyX%0tz_LLI7&AsoH4_p#kzbDwmo%v(u z|6glo0v6Ny2Jj;-wh|R7mC#DjD#a~np@pJs$uy=>qiM>_l%ir35wg1oQKLd+Y0-MK zq<{8Yib#csR1!)q{_m)%&N*eaj(f~~?sK2>d*APS&%1r!Imf~^=lI{MQye}%jI~Lc zSi^qF&@K6K!sGKu=}0qp5tPnN?v#k0UtMpJ<1 zp&QZcdqiYzYtxeG8?2B;TO@AYo<^(b*tofVs#hRcS2^h5AvvQUseP4Wi{1^1E=)1nRrF0E4&LB;>U8wB1|t2+E1A9V zOyYX4`uFtbOXBE$c8x1bWq#(EUn=yURher)W$lkaH5*Rfuq=+Th^d#O4wrc_iEO?V zzPjP{q0B$ynSq~n?utWgI~7foNDHK|8pO75{=%pWxuQilJt|fzXK!QM1>G|7E!Nq= z7H7-DrQh0>S8hM;w<6fkdiQ^`Gk+eM(>Ss9{Z<9>IETpbCmV;nn4eL5!oJ4sbl^N! zN&V%X7b10U$R3Oct0-Pmdv8LXo;urJXOrY2y-zJgH5M;YG?klt4|w~$diYhfVnDg9 z?567G==BHx%?j3?)fRIp{Nl4I;q;=Xn>OU8Yo7~z^J4g=2NgQ`6|a_O&-XtN%QpI? z_+4vEYTOb}>F7L_dFSd3V%==_o>{MAvv4|L?As9*hRPS0l4nP`$Vbm)FDuu4dYQIq zQQ?gp$i#fh)}f&j-Z{E1N!&3`@?`ox9mjfgKiU_ksReN_Rhs>zUmvSu=)F3Ynp$HP zKDT*W=0}^Bw{{Gy8+h zhb8waw;xkYe$jMCZF)$tiP!y;lKEcxLnl9~AjT)WEew(#S--e4)12v>d(-XjEBB-~ zy^?R0Y%Nez@@r)tmww|!IaM*|#W_msr<}jusa)53P-cEOJ4xNWXuWjJ)GZsN!WLVt zo4smIK_va?%kaauYMzuHE{Jt6O|SI$-$D0-PyMJhjp9)gm%dkN*2rkO;utg1CpX9Y zm1+HSKZVlrHHxrKtz)0Z-cz3{J!hAk1JSpI;Qdnlw0Pe(R#=^*)gn)k)8dt9R^FeAbv& zoZx(PtHzLFH6g0&XNQ|Sx-KPi;bZNHE9dXtq(&SJ%oraWE0a<`h<5Tt@kj5f=jW&I z7u!UdSd^z;@T7tGdTE2qni8Va)x)VyOR7>==N`S=zUs2>-0X*SC(hk_P;o6^-OPDL z=0&yi(MErTY3+SlR9XEl!a;HydooSsG$UkhW#Z-qhB05>W*qq#JcL=JalPtzL+-*R z`20OX*=C7nms>sGw)K2sSkmUbb2Km4 zHH0@w4vSF#+NhcSXkqp>*(0jf&MnXEvUVQKS@C|EYGX;(u_k-3&%0c1vOYa>uA6qB zO7qHC`m^gjh@lOSi8Uq@LPIG75&Rb}!&kSKMcb&iMm8SeZ zEjkfL{yqPCo;~BtIudncqPZ9G5+yd)`KFu9606|-0fZXw;M|!@-{ewt)^L`bUpcV(bCALqXG^*I-9GUX!k!p^ z^Ru36AYtJhD^@1m5_CuPuj0%3Pok~2q@AJ;oBkSiBvdn!kh*Qj<)6%~M(=t@edC$BG2d!QpZ+H7dot%%Q?vrEXc!?wF6B&jJ@IR3}isDvb8XYcPp= zY87Wl9-T-6Zoo1LLCwCLi=Q zVzrfTt(DNtN%Y7}V4pucKD41xCi+Nia;m+A@9Av$>2^As7o|UvNOx#vyy__s8X3v%NVu*r&w()!*CaWc+Nh_!=pzkSIO+nSLbW#{F8KPXS=w9o2~I z`yVNL#1O>x_ww!lG5LYri~3gDMIM*o|9l6hA)MT!fyMbZe%j|NDYPlH0J=YsN?Avy zyEvk+Z$x}KiE|sSfRpo#5BFfR|mnL;2?XcQ)a^K~&SWZcJ3PvYRp zEpVbC_XURd6DhP_AvY(cm9+z4G+dJ7I=Ba$bsxr7FiiqONkoz_nLy~)iqvrhJtG4{ z(2#^xaczEC)CnLj02Z2V53?#fy;EHt^cy2;#CF1h%W`;*%ZaNv{IXeO_^-m!Nda`S zJ`eKvNTMslR}A?dT^un*k*V-GJ3+`W;$TVofnEt^2dRoZifOSyWKFrNZdmBd4W!$%K+%r? z<}5364>oIVq{z^YHVzi~m+9qr&aNyEI5~@n+=I>fu~}r~?<@>U^ek@tDgzkKZZGsr zes7D&L}oxBfl3Z0Q#n}@mRy)Tz-BxQtqwR7Yp$a3%VsT#=9BD8q%+7&LU$nQ_N@5( z5#Gv^$+6eDaH4s2F(UB#3>{bB8JH-7gGm7WIP=Lp*sSB*Mc@e@Mci`k*}nz)Fo+~* zK`eLolOX&BlsoE7 zR{bMFfH#@S;58CUl-5k%p$sztyDpcYCWP(TFJf>uY54fsYLuKP3N+hcs8#06}J;P^qy( zqrem3Nta!=rz`}5H=LYk#68%oj5y&*)IU~Ao@$d5Lt*!ltR|Kjc2q=WpV5!xY}iuG zQ4WlVlhJSwHj9!hBD34ycU6Zx>WR{9v-UU8;R?~l3R9NSkHYX51p_A?y82TK_SPTA z<{@(ngcpYE^6?gT?ylL;bC73^h7`|=I}Py5W@Wt*n%C*s@w6Qp##$$VRQMO#lQys( zz89K?cHnv;W~KyFV?8Q`78IiALkrSp1YncP+T=l|4HVWwf5;)O?)nr?XI+ zWo!{zGj80&<9b%|=td7ET3DQ(k-kyyTU)U=i~9r5Q!FtA(T8ef9!lBf{-gI%*^gaO z<^66Fg2+U63^o_fW;Mq2o92C0_?Ki)?>PxdKY`%r%q7Dwo8^|(Z}8qLeQA>AxKKbH zf)ibL2j=w~y4Q+7SL)DX&i%tNYfh7vd$3ug{C*>oX-s-3AuxbKV={Ux{x_ankOM3H?9Qm%Vud6^qUZWY(H!c$w^TIx9tj{5o*D%gU!0ervwyl8u3pJhiS^jWHGp{ z9DsnfuGxkB>DWmSJmDD@`CsyLh{6kDd>y(};|y=%H6hU?2m+{Z)LX-P_2<)xQ$b}H zP}vd1mA@l2*FTWRvy^qBeOZ#FiXcxR?cg+cxCfh+e@|#I??(0h)CA3kLGavU)BwyB z*Ea}><;=M^kxA?s`Fk7cFwzBwNGRU5z;~gYwwbpiUy&YXU2wC)$4B7l2wv=G$1bYG z!w_GD)0I2a@XKaR^AnQY`CtZtAJxq=p8pyK+4EAW7)Et>s*v~~Cd1g2AGU(W_w$?^ zdL=AGK(W|$uvwKur1&59j=Kq;2-qe|$=rmC&H~TWb7hXr+9D&+<$vEa`0J-_9{u_O zBvEc~@u^+Hb7n4exIowMb;%=XWLv121$4{}24H+@g|Yxw@45x>@{b+6aiJy*|57Og zF+s`CTr3Eo%hK_PowI*#(>hc`w$LG*8K^Gh1KZVBim4>=9-7WrwsJRjh0^R6xmL9~n zPr;02?`h{En29bX~k%R%leOX=buPXtoO6r4JwlLElDBBlsiH$!mhh3?}1G zIo7kbG<`RycO~I&MMt9hiULyv&$I4byfZ2bT=jUEJ#-qIpdk{zvs8pV2|QX`@mlSg z*Pw*C21AW*89&n!MFPkL$aET!O5m$yeAUeE(+;T1lW5p!n4l+u6p#o7f*3sWk*~#P zip*dU<0trSbTOsBTogR-_ZKRB0CW2aff#LaM{kOP4hZn$srFmbU(;_}A&7Pi*5t%*iNN;f zYhiBFUu=itptv)5T6CCk8akM-2;C!?b%z=5)9Ad$JyLPB`FTj!Z&0y#ii`+&*v86P zhvPZ)3$((cO2OnQ;ON}B_71;n)`DpSM^90r-lp8cb%yQ1JAZ;e_g{>tM5{#0$*s&MfdL z{r|M@yo0?kNIAH6bk>`ALQoJUfxyES-&3@Fqy!rIVH3n7i2}m9@&r7E@zYdnIn)dW z&}}s88aa;bJ}MBD((BUkr58Knwn9aHOAFga+*2edfD`rcDpaq#H)9M;{W&<%wcPqr z0SO(!9glE56ThnkCVmXWbM%Hwc%Vu!|3>PF;dn;bi(;f0&KuC{>jOToCS3bEBg29C0*jb6oGW7#WGVa6+A zTF|pT^^2f{-|-cX$etnn@fQ@h%OIqpXZ_b#0TG>H6wgrDy6x;{P-82k4Cpd&rRosD zEUPP8;wfiJ{Z0g_BZ%5sEX8@8fRwJFh^M5^JxGoLU-A-+3tc>GTMJ6*8T;@g*O5-y z%fY<7z_FmscRMipuQ0f5d@+d;NW&XVYlE=tNg{+l6knHrVy)|76xXdI54doU?zUJN{y` z&WQ}|wRffUvQQr!I|5Y}W*IBufT&vjaZxg?Y-ltXC^8!w8PiajN*?47-1%OsKlRLF zrzClf1@-*LV(aHuCj^Cb*E0O>#Tu}B)HO#aCQ=~vLpQ9#FNi>2No0_rl%UbbBu*90 ztD<^R;F4Gdp>IEkfNtE)%NIckQUI0OApp;cCZVWc(Ap6QvJ2cVdK{8oiy%Q~ok{Q~ z!#mKtc}g)rXMo=WFtj&tx}Xd$@v8_@aCf@!XkP9z%r%(?9q(7+@Qf3R-rOoYoqsC` zCQfl1W({A=jl*t8Pca$FS8~#QyLI0Q-Tc6S04gs_d_S)>rc4n*vS1w0V_+5{ybL{( zR~~cVnm%yyBB-jRreF)(*geAYS5e4R-quG^UGU*L#LPnws?pZxl`IOIN)8NQ@Z2-7 zLP!0RCTQNSi*2NxOcS2&%VY)`@|tu-KRK;{$?yQCC$^noT_il3V{ZOL8ob|-&P#v? zH}ZT;p^@_a26p5PKM5}Y^icw#pTzU|KApT*(#4QQ$dAJI8Q$0q6YRdj`h9$kn>CF# ziV1aR1*8t>?un9R-LE8(#1GZ#fwQ3~@2*P@CJZwiEsfh@zm2jdn1$93G zVO(d8hbTx*x?eL9dK=LQG9Bfg-wFun_KCeTI3%8r&@PySAgt5a_0K7L1kbqnLDf!)RCDgNH@5nTTx%;0ZXgeesFm9Hkd8gGymJeas`5o?bG{JnodX0Yjg(F)gNm>uw)rvEy!YKKg+{k z1Rr}UIjtEsm>R*9IdMk^e%Y+%g(3^o!)owO)iL%;#Rcej*vnwu*>X>j$=zm5_-!YI zwE=WL$fi~^ussR$<`oKqz?~UE@CB3YI@qjzur-jMXIZ(WLoc^bhmGQOzq8<(uQoUm zQ!(r=S6PP0P_8NBu}llv_=V77QU`Z|_M2(Ue!zBG9G-h!{dVbaNYI}G)T(QQIYzc_ zqj22rXoaVZIbSdN9ZWi01>4M{*GAt5gWBXrercs0bY-+qt)Zs;A%JbE4E;Sd>tCWNzS@Tbg)G+_Lx z6mWKTf#i{n*_+4i>enu)Ba(dy2@1`i$d=P?+t33zc7538hm>?xiLh152vuhI9#+e8t?U{d_a0YN+^_*ZU@Zpk=U<%Dhq zx`lcvOGF7ELFJ`?aj^b{pWvI%NMTL#+Y?dgobSf*82$y{|9J=xmLM+BKSpoM3$7Fq z|N9eWJn))%XI<}rPojZmgy+t>4mL}+RtS8LaDb1wS1zPF)k4e-g9tFai^R!==X?-? z)#3H=n8W`tm4|_g-3*Q%-7MYTCj#IEI!IRM+}2b?6*oaJx{TKC6fyZ3l`P zX)H9Qd8H7P&d)buDLr@c*rIIj zBt;-f-yhw=B71&P!3Kp?T`d~2uPrq_Ux;jtB3d&=BlfFC;>dYi4_>PUe?k_)vtS!x+X?c2Vxs*Z literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/bin/normalizer b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/bin/normalizer new file mode 100755 index 0000000..39bac1a --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/bin/normalizer @@ -0,0 +1,8 @@ +#!/usr/bin/python3 +# -*- coding: utf-8 -*- +import re +import sys +from charset_normalizer.cli import cli_detect +if __name__ == '__main__': + sys.argv[0] = re.sub(r'(-script\.pyw|\.exe)?$', '', sys.argv[0]) + sys.exit(cli_detect()) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/INSTALLER b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/INSTALLER new file mode 100644 index 0000000..a1b589e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/INSTALLER @@ -0,0 +1 @@ +pip diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/LICENSE b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/LICENSE new file mode 100644 index 0000000..62b076c --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/LICENSE @@ -0,0 +1,20 @@ +This package contains a modified version of ca-bundle.crt: + +ca-bundle.crt -- Bundle of CA Root Certificates + +This is a bundle of X.509 certificates of public Certificate Authorities +(CA). These were automatically extracted from Mozilla's root certificates +file (certdata.txt). This file can be found in the mozilla source tree: +https://hg.mozilla.org/mozilla-central/file/tip/security/nss/lib/ckfw/builtins/certdata.txt +It contains the certificates in PEM format and therefore +can be directly used with curl / libcurl / php_curl, or with +an Apache+mod_ssl webserver for SSL client authentication. +Just configure this file as the SSLCACertificateFile.# + +***** BEGIN LICENSE BLOCK ***** +This Source Code Form is subject to the terms of the Mozilla Public License, +v. 2.0. If a copy of the MPL was not distributed with this file, You can obtain +one at http://mozilla.org/MPL/2.0/. + +***** END LICENSE BLOCK ***** +@(#) $RCSfile: certdata.txt,v $ $Revision: 1.80 $ $Date: 2011/11/03 15:11:58 $ diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/METADATA b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/METADATA new file mode 100644 index 0000000..5b357f5 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/METADATA @@ -0,0 +1,67 @@ +Metadata-Version: 2.1 +Name: certifi +Version: 2024.7.4 +Summary: Python package for providing Mozilla's CA Bundle. +Home-page: https://github.com/certifi/python-certifi +Author: Kenneth Reitz +Author-email: me@kennethreitz.com +License: MPL-2.0 +Project-URL: Source, https://github.com/certifi/python-certifi +Classifier: Development Status :: 5 - Production/Stable +Classifier: Intended Audience :: Developers +Classifier: License :: OSI Approved :: Mozilla Public License 2.0 (MPL 2.0) +Classifier: Natural Language :: English +Classifier: Programming Language :: Python +Classifier: Programming Language :: Python :: 3 +Classifier: Programming Language :: Python :: 3 :: Only +Classifier: Programming Language :: Python :: 3.6 +Classifier: Programming Language :: Python :: 3.7 +Classifier: Programming Language :: Python :: 3.8 +Classifier: Programming Language :: Python :: 3.9 +Classifier: Programming Language :: Python :: 3.10 +Classifier: Programming Language :: Python :: 3.11 +Classifier: Programming Language :: Python :: 3.12 +Requires-Python: >=3.6 +License-File: LICENSE + +Certifi: Python SSL Certificates +================================ + +Certifi provides Mozilla's carefully curated collection of Root Certificates for +validating the trustworthiness of SSL certificates while verifying the identity +of TLS hosts. It has been extracted from the `Requests`_ project. + +Installation +------------ + +``certifi`` is available on PyPI. Simply install it with ``pip``:: + + $ pip install certifi + +Usage +----- + +To reference the installed certificate authority (CA) bundle, you can use the +built-in function:: + + >>> import certifi + + >>> certifi.where() + '/usr/local/lib/python3.7/site-packages/certifi/cacert.pem' + +Or from the command line:: + + $ python -m certifi + /usr/local/lib/python3.7/site-packages/certifi/cacert.pem + +Enjoy! + +.. _`Requests`: https://requests.readthedocs.io/en/master/ + +Addition/Removal of Certificates +-------------------------------- + +Certifi does not support any addition/removal or other modification of the +CA trust store content. This project is intended to provide a reliable and +highly portable root of trust to python deployments. Look to upstream projects +for methods to use alternate trust. diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/RECORD b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/RECORD new file mode 100644 index 0000000..fea659e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/RECORD @@ -0,0 +1,14 @@ +certifi-2024.7.4.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4 +certifi-2024.7.4.dist-info/LICENSE,sha256=6TcW2mucDVpKHfYP5pWzcPBpVgPSH2-D8FPkLPwQyvc,989 +certifi-2024.7.4.dist-info/METADATA,sha256=L9_EuPoQQvHFzxu03_ctaEZxhEty7inz569jGWjlLGo,2221 +certifi-2024.7.4.dist-info/RECORD,, +certifi-2024.7.4.dist-info/WHEEL,sha256=y4mX-SOX4fYIkonsAGA5N0Oy-8_gI4FXw5HNI1xqvWg,91 +certifi-2024.7.4.dist-info/top_level.txt,sha256=KMu4vUCfsjLrkPbSNdgdekS-pVJzBAJFO__nI8NF6-U,8 +certifi/__init__.py,sha256=LHXz7E80YJYBzCBv6ZyidQ5-ciYSkSebpY2E5OM0l7o,94 +certifi/__main__.py,sha256=xBBoj905TUWBLRGANOcf7oi6e-3dMP4cEoG9OyMs11g,243 +certifi/__pycache__/__init__.cpython-312.pyc,, +certifi/__pycache__/__main__.cpython-312.pyc,, +certifi/__pycache__/core.cpython-312.pyc,, +certifi/cacert.pem,sha256=SIupYGAr8HzGP073rsEIaS_sQYIPwzKKjj894DgUmu4,291528 +certifi/core.py,sha256=qRDDFyXVJwTB_EmoGppaXU_R9qCZvhl-EzxPMuV3nTA,4426 +certifi/py.typed,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/WHEEL b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/WHEEL new file mode 100644 index 0000000..564c672 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/WHEEL @@ -0,0 +1,5 @@ +Wheel-Version: 1.0 +Generator: setuptools (70.2.0) +Root-Is-Purelib: true +Tag: py3-none-any + diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/top_level.txt b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/top_level.txt new file mode 100644 index 0000000..963eac5 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi-2024.7.4.dist-info/top_level.txt @@ -0,0 +1 @@ +certifi diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__init__.py new file mode 100644 index 0000000..d321f1b --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__init__.py @@ -0,0 +1,4 @@ +from .core import contents, where + +__all__ = ["contents", "where"] +__version__ = "2024.07.04" diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__main__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__main__.py new file mode 100644 index 0000000..8945b5d --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__main__.py @@ -0,0 +1,12 @@ +import argparse + +from certifi import contents, where + +parser = argparse.ArgumentParser() +parser.add_argument("-c", "--contents", action="store_true") +args = parser.parse_args() + +if args.contents: + print(contents()) +else: + print(where()) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..e3abb4766ea63bc3e42b6e1e2eb5850fd23833b3 GIT binary patch literal 279 zcmX@j%ge<81k+W{q{RX0#~=<2FhLog6@ZNC3@HpLj5!Rsj8TlaOi@gX3@J=0%;`)~ z%qc8UES0R9Y%dvs$~2j7aU|#Gm89mC6yIVk&qyswEn)_W7qI||DlQ`fBNIIXb3FqS zKTXzKEXn!E(zn>-;}dgo;^S{|$H$kY78Pga=f%gbWcUo!%J9ovza+OnzaXD#f%&KPNLuzo4=tBR@|+Ikl)HGc8j;K0Y%qvm`!Vub}c5hfQvNN@-52 rT@g3X9FQZ6#eu{JW=2NF`wWT?xJ4(FU*M8&V86j9)yQ4M36ui>Lc2(d literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/__main__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/__main__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..c3696e6bd558af7142f662c1b729c3cdc362a8d5 GIT binary patch literal 594 zcmZuu&ubGw6n?Y6cWGK_5Q3+mEp5bgPsK}95Ih%;lFPDYrtOC858h5F2|bj8sN~|U z{S%b;?>kpA{#8ji%o(^k zli(OAP|}5#idvT>T1!jxmQFwe1|6p?n#a)$woGPrDs#R>RHp_tzgi>xmLVX0OQkxG zcYPe@bc{J)B3zUwaOKoW=ZM^D1o~vA>Gx?3`@b@7H#Fh2vy`)x7sA}%W5@=Y-yV3r ze@A--&ya;2d#pi(6}5Ssr43Iw5$@&@7EIV}hCJShQQZgCLB--r-0dZ@?Q7*gVNIPV z79vVRSvb{%H)T~`2xGdMImRjf0_scP`bEH#JjmnR=Tc?d9~2o5=mrMe_-&B)`CgU= zv(1ArOrkgq!{>Sb+SyDp+Uv3{T$X**qZDuCa;XzSe#6o~cyi&^Kh!2}eeBjx-N%R4 zIam{@j-mSL)ycEZ2S1>C2Ak)0Wn$OHcJ0)DbZA`Y_WR~h^Oxa%TpvFDX*~QR(duyR K-8Mdu&2Ip}W{vUy literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/core.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/__pycache__/core.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..f924cd7e25548db58400895731d230327922575c GIT binary patch literal 3164 zcmbVO&2Jl35Pxq!?6u=$lh|?Grqov2(zRV{S%Pj5aXg$OOYypgnBc$5>ijhtalwJO%E{Eo0)z4 z-gw^3Z|3cfot;qvbZz%f({J|>@;g2R)Zr_QHz}+j2FVeF8bXogs3(P-U?dIcb15g9 zw4emr)}G?kT>(8dCp^Jkq-8G( z_BwN2B{io$X0M~oUaV=)^S3+K?a7{856I49Zz-OOQ)0%=p2EI$uLBKz+XfH0K3EYo zy8NePghYtZZ>VOU(QPJ;9(dOa1J4pQ;-AYo)jvz3&5ypOAKBEr8P!e3t!ZnxG8g@< zMbYTgjOAoXwsEm&W|+w@va*xmGiJsrJ6tOkHE!AEOwrbxianjtHMBHbF-sYnWi0Mw zbi2&WGIxff5AYP@Zm4NU56*;Ah9Sae90qocaNtcU;Or(cAngXZ<-eh1j%4Y0R&YD= zqbEk+n3&3sPQC9c`Mi0_;`#hd(!l+Xo*m((%1Fhk3~`N}H~G-KW3zeVIW|(XJ{+mc z@fo{3;)h{Gx0wmCa8=Jn^H6!6Ut)+%98Ln*BDp82Yf`EzrIr)Rd}ZnvX+J~EWrYXm z-2+4`I2P8N{IpdxT^YHf!)%LMC;thi+E2cCjHWDukP|of|^%HjtXc zgOVYaV6IZIt#U=7%w$+4eK4HUz!u5FZW2qacBCIB$-v;Zdu~K(gNN4!k5vbc-5#qAzE#`)_T|&} z26kTmWG#K9nm$rXKVKVo;qutMSnt&{SI%5Nb0>E24|QNw8SwsTLk2NRI2!K(gADrl zA<&qD$ZUz?R;~)I?1BNG4DmZD*bT9i#~E}&!Z7BptU0=6-K4H!mUY{(%ICA97eI!f zbR*2vj68&jZw`$T)FR8k!eJQB)4%}6YGUbJO--+<`>N``8#`+1^K0tys(So~y{qc+ znmVznO!&ZN2&V@aa{#vFB`XaN8zLgXgcp%-K-qxl*VZwOZSR%<3xG6%x6sUSw?_rc z=O)?$rRb1Hg;=1iOOC+uD2V1plrltiR$*}vt^#c#-@+e5_^>3heqOsw8 zFTzXbWngW1OOb(HD@Sh>Yuk_gZ-lja#7?li5n+blAqAriG)dS1h?|sQPB#0Q!8v3T zFdB#_%zSEj+sfGO7w)K|tIB9I$<&qKEkkFY@35WWvrvy?)&CcHYGLbL@)@ zY8(A=Lr{n|bM#i;U@`>5L%=0a+C5&+e~`%q;X4}O;5qWCv>7f_h5ZpJG&a?e)IG;Cc9nL5^b567RvGCp4$0l>2F!EM;+IHhs zsbVt@pAW-9ML6rXnRkbIeWlq*yuf7e-!Y(UH!`nEp8?I4`CP?x+z<%p=WHL&Mc?s0 zyr$rd8$KHp-$YP+8}GeG%1h1fv{%>(*o+x*BEah+rSvaBrcxtDXveRlvmsG>pso-p zye7u0Vti@#XL0AB(&78P$;H!v;l;7K)GzN?dbUA8)DKg6k}l~F3Cenigd%HlUsdi~ zPW~*X|CC;B-%MDR};He^wmVR+O>c2 z None: + _CACERT_CTX.__exit__(None, None, None) # type: ignore[union-attr] + + +if sys.version_info >= (3, 11): + + from importlib.resources import as_file, files + + _CACERT_CTX = None + _CACERT_PATH = None + + def where() -> str: + # This is slightly terrible, but we want to delay extracting the file + # in cases where we're inside of a zipimport situation until someone + # actually calls where(), but we don't want to re-extract the file + # on every call of where(), so we'll do it once then store it in a + # global variable. + global _CACERT_CTX + global _CACERT_PATH + if _CACERT_PATH is None: + # This is slightly janky, the importlib.resources API wants you to + # manage the cleanup of this file, so it doesn't actually return a + # path, it returns a context manager that will give you the path + # when you enter it and will do any cleanup when you leave it. In + # the common case of not needing a temporary file, it will just + # return the file system location and the __exit__() is a no-op. + # + # We also have to hold onto the actual context manager, because + # it will do the cleanup whenever it gets garbage collected, so + # we will also store that at the global level as well. + _CACERT_CTX = as_file(files("certifi").joinpath("cacert.pem")) + _CACERT_PATH = str(_CACERT_CTX.__enter__()) + atexit.register(exit_cacert_ctx) + + return _CACERT_PATH + + def contents() -> str: + return files("certifi").joinpath("cacert.pem").read_text(encoding="ascii") + +elif sys.version_info >= (3, 7): + + from importlib.resources import path as get_path, read_text + + _CACERT_CTX = None + _CACERT_PATH = None + + def where() -> str: + # This is slightly terrible, but we want to delay extracting the + # file in cases where we're inside of a zipimport situation until + # someone actually calls where(), but we don't want to re-extract + # the file on every call of where(), so we'll do it once then store + # it in a global variable. + global _CACERT_CTX + global _CACERT_PATH + if _CACERT_PATH is None: + # This is slightly janky, the importlib.resources API wants you + # to manage the cleanup of this file, so it doesn't actually + # return a path, it returns a context manager that will give + # you the path when you enter it and will do any cleanup when + # you leave it. In the common case of not needing a temporary + # file, it will just return the file system location and the + # __exit__() is a no-op. + # + # We also have to hold onto the actual context manager, because + # it will do the cleanup whenever it gets garbage collected, so + # we will also store that at the global level as well. + _CACERT_CTX = get_path("certifi", "cacert.pem") + _CACERT_PATH = str(_CACERT_CTX.__enter__()) + atexit.register(exit_cacert_ctx) + + return _CACERT_PATH + + def contents() -> str: + return read_text("certifi", "cacert.pem", encoding="ascii") + +else: + import os + import types + from typing import Union + + Package = Union[types.ModuleType, str] + Resource = Union[str, "os.PathLike"] + + # This fallback will work for Python versions prior to 3.7 that lack the + # importlib.resources module but relies on the existing `where` function + # so won't address issues with environments like PyOxidizer that don't set + # __file__ on modules. + def read_text( + package: Package, + resource: Resource, + encoding: str = 'utf-8', + errors: str = 'strict' + ) -> str: + with open(where(), encoding=encoding) as data: + return data.read() + + # If we don't have importlib.resources, then we will just do the old logic + # of assuming we're on the filesystem and munge the path directly. + def where() -> str: + f = os.path.dirname(__file__) + + return os.path.join(f, "cacert.pem") + + def contents() -> str: + return read_text("certifi", "cacert.pem", encoding="ascii") diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/py.typed b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/certifi/py.typed new file mode 100644 index 0000000..e69de29 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/INSTALLER b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/INSTALLER new file mode 100644 index 0000000..a1b589e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/INSTALLER @@ -0,0 +1 @@ +pip diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/LICENSE b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/LICENSE new file mode 100644 index 0000000..ad82355 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2019 TAHRI Ahmed R. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. \ No newline at end of file diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/METADATA b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/METADATA new file mode 100644 index 0000000..822550e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/METADATA @@ -0,0 +1,683 @@ +Metadata-Version: 2.1 +Name: charset-normalizer +Version: 3.3.2 +Summary: The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet. +Home-page: https://github.com/Ousret/charset_normalizer +Author: Ahmed TAHRI +Author-email: ahmed.tahri@cloudnursery.dev +License: MIT +Project-URL: Bug Reports, https://github.com/Ousret/charset_normalizer/issues +Project-URL: Documentation, https://charset-normalizer.readthedocs.io/en/latest +Keywords: encoding,charset,charset-detector,detector,normalization,unicode,chardet,detect +Classifier: Development Status :: 5 - Production/Stable +Classifier: License :: OSI Approved :: MIT License +Classifier: Intended Audience :: Developers +Classifier: Topic :: Software Development :: Libraries :: Python Modules +Classifier: Operating System :: OS Independent +Classifier: Programming Language :: Python +Classifier: Programming Language :: Python :: 3 +Classifier: Programming Language :: Python :: 3.7 +Classifier: Programming Language :: Python :: 3.8 +Classifier: Programming Language :: Python :: 3.9 +Classifier: Programming Language :: Python :: 3.10 +Classifier: Programming Language :: Python :: 3.11 +Classifier: Programming Language :: Python :: 3.12 +Classifier: Programming Language :: Python :: Implementation :: PyPy +Classifier: Topic :: Text Processing :: Linguistic +Classifier: Topic :: Utilities +Classifier: Typing :: Typed +Requires-Python: >=3.7.0 +Description-Content-Type: text/markdown +License-File: LICENSE +Provides-Extra: unicode_backport + +

Charset Detection, for Everyone 👋

+ +

+ The Real First Universal Charset Detector
+
+ + + + Download Count Total + + + + +

+

+ Featured Packages
+ + Static Badge + + + Static Badge + +

+

+ In other language (unofficial port - by the community)
+ + Static Badge + +

+ +> A library that helps you read text from an unknown charset encoding.
Motivated by `chardet`, +> I'm trying to resolve the issue by taking a new approach. +> All IANA character set names for which the Python core library provides codecs are supported. + +

+ >>>>> 👉 Try Me Online Now, Then Adopt Me 👈 <<<<< +

+ +This project offers you an alternative to **Universal Charset Encoding Detector**, also known as **Chardet**. + +| Feature | [Chardet](https://github.com/chardet/chardet) | Charset Normalizer | [cChardet](https://github.com/PyYoshi/cChardet) | +|--------------------------------------------------|:---------------------------------------------:|:--------------------------------------------------------------------------------------------------:|:-----------------------------------------------:| +| `Fast` | ❌ | ✅ | ✅ | +| `Universal**` | ❌ | ✅ | ❌ | +| `Reliable` **without** distinguishable standards | ❌ | ✅ | ✅ | +| `Reliable` **with** distinguishable standards | ✅ | ✅ | ✅ | +| `License` | LGPL-2.1
_restrictive_ | MIT | MPL-1.1
_restrictive_ | +| `Native Python` | ✅ | ✅ | ❌ | +| `Detect spoken language` | ❌ | ✅ | N/A | +| `UnicodeDecodeError Safety` | ❌ | ✅ | ❌ | +| `Whl Size (min)` | 193.6 kB | 42 kB | ~200 kB | +| `Supported Encoding` | 33 | 🎉 [99](https://charset-normalizer.readthedocs.io/en/latest/user/support.html#supported-encodings) | 40 | + +

+Reading Normalized TextCat Reading Text +

+ +*\*\* : They are clearly using specific code for a specific encoding even if covering most of used one*
+Did you got there because of the logs? See [https://charset-normalizer.readthedocs.io/en/latest/user/miscellaneous.html](https://charset-normalizer.readthedocs.io/en/latest/user/miscellaneous.html) + +## ⚡ Performance + +This package offer better performance than its counterpart Chardet. Here are some numbers. + +| Package | Accuracy | Mean per file (ms) | File per sec (est) | +|-----------------------------------------------|:--------:|:------------------:|:------------------:| +| [chardet](https://github.com/chardet/chardet) | 86 % | 200 ms | 5 file/sec | +| charset-normalizer | **98 %** | **10 ms** | 100 file/sec | + +| Package | 99th percentile | 95th percentile | 50th percentile | +|-----------------------------------------------|:---------------:|:---------------:|:---------------:| +| [chardet](https://github.com/chardet/chardet) | 1200 ms | 287 ms | 23 ms | +| charset-normalizer | 100 ms | 50 ms | 5 ms | + +Chardet's performance on larger file (1MB+) are very poor. Expect huge difference on large payload. + +> Stats are generated using 400+ files using default parameters. More details on used files, see GHA workflows. +> And yes, these results might change at any time. The dataset can be updated to include more files. +> The actual delays heavily depends on your CPU capabilities. The factors should remain the same. +> Keep in mind that the stats are generous and that Chardet accuracy vs our is measured using Chardet initial capability +> (eg. Supported Encoding) Challenge-them if you want. + +## ✨ Installation + +Using pip: + +```sh +pip install charset-normalizer -U +``` + +## 🚀 Basic Usage + +### CLI +This package comes with a CLI. + +``` +usage: normalizer [-h] [-v] [-a] [-n] [-m] [-r] [-f] [-t THRESHOLD] + file [file ...] + +The Real First Universal Charset Detector. Discover originating encoding used +on text file. Normalize text to unicode. + +positional arguments: + files File(s) to be analysed + +optional arguments: + -h, --help show this help message and exit + -v, --verbose Display complementary information about file if any. + Stdout will contain logs about the detection process. + -a, --with-alternative + Output complementary possibilities if any. Top-level + JSON WILL be a list. + -n, --normalize Permit to normalize input file. If not set, program + does not write anything. + -m, --minimal Only output the charset detected to STDOUT. Disabling + JSON output. + -r, --replace Replace file when trying to normalize it instead of + creating a new one. + -f, --force Replace file without asking if you are sure, use this + flag with caution. + -t THRESHOLD, --threshold THRESHOLD + Define a custom maximum amount of chaos allowed in + decoded content. 0. <= chaos <= 1. + --version Show version information and exit. +``` + +```bash +normalizer ./data/sample.1.fr.srt +``` + +or + +```bash +python -m charset_normalizer ./data/sample.1.fr.srt +``` + +🎉 Since version 1.4.0 the CLI produce easily usable stdout result in JSON format. + +```json +{ + "path": "/home/default/projects/charset_normalizer/data/sample.1.fr.srt", + "encoding": "cp1252", + "encoding_aliases": [ + "1252", + "windows_1252" + ], + "alternative_encodings": [ + "cp1254", + "cp1256", + "cp1258", + "iso8859_14", + "iso8859_15", + "iso8859_16", + "iso8859_3", + "iso8859_9", + "latin_1", + "mbcs" + ], + "language": "French", + "alphabets": [ + "Basic Latin", + "Latin-1 Supplement" + ], + "has_sig_or_bom": false, + "chaos": 0.149, + "coherence": 97.152, + "unicode_path": null, + "is_preferred": true +} +``` + +### Python +*Just print out normalized text* +```python +from charset_normalizer import from_path + +results = from_path('./my_subtitle.srt') + +print(str(results.best())) +``` + +*Upgrade your code without effort* +```python +from charset_normalizer import detect +``` + +The above code will behave the same as **chardet**. We ensure that we offer the best (reasonable) BC result possible. + +See the docs for advanced usage : [readthedocs.io](https://charset-normalizer.readthedocs.io/en/latest/) + +## 😇 Why + +When I started using Chardet, I noticed that it was not suited to my expectations, and I wanted to propose a +reliable alternative using a completely different method. Also! I never back down on a good challenge! + +I **don't care** about the **originating charset** encoding, because **two different tables** can +produce **two identical rendered string.** +What I want is to get readable text, the best I can. + +In a way, **I'm brute forcing text decoding.** How cool is that ? 😎 + +Don't confuse package **ftfy** with charset-normalizer or chardet. ftfy goal is to repair unicode string whereas charset-normalizer to convert raw file in unknown encoding to unicode. + +## 🍰 How + + - Discard all charset encoding table that could not fit the binary content. + - Measure noise, or the mess once opened (by chunks) with a corresponding charset encoding. + - Extract matches with the lowest mess detected. + - Additionally, we measure coherence / probe for a language. + +**Wait a minute**, what is noise/mess and coherence according to **YOU ?** + +*Noise :* I opened hundred of text files, **written by humans**, with the wrong encoding table. **I observed**, then +**I established** some ground rules about **what is obvious** when **it seems like** a mess. + I know that my interpretation of what is noise is probably incomplete, feel free to contribute in order to + improve or rewrite it. + +*Coherence :* For each language there is on earth, we have computed ranked letter appearance occurrences (the best we can). So I thought +that intel is worth something here. So I use those records against decoded text to check if I can detect intelligent design. + +## ⚡ Known limitations + + - Language detection is unreliable when text contains two or more languages sharing identical letters. (eg. HTML (english tags) + Turkish content (Sharing Latin characters)) + - Every charset detector heavily depends on sufficient content. In common cases, do not bother run detection on very tiny content. + +## ⚠️ About Python EOLs + +**If you are running:** + +- Python >=2.7,<3.5: Unsupported +- Python 3.5: charset-normalizer < 2.1 +- Python 3.6: charset-normalizer < 3.1 +- Python 3.7: charset-normalizer < 4.0 + +Upgrade your Python interpreter as soon as possible. + +## 👤 Contributing + +Contributions, issues and feature requests are very much welcome.
+Feel free to check [issues page](https://github.com/ousret/charset_normalizer/issues) if you want to contribute. + +## 📝 License + +Copyright © [Ahmed TAHRI @Ousret](https://github.com/Ousret).
+This project is [MIT](https://github.com/Ousret/charset_normalizer/blob/master/LICENSE) licensed. + +Characters frequencies used in this project © 2012 [Denny Vrandečić](http://simia.net/letters/) + +## 💼 For Enterprise + +Professional support for charset-normalizer is available as part of the [Tidelift +Subscription][1]. Tidelift gives software development teams a single source for +purchasing and maintaining their software, with professional grade assurances +from the experts who know it best, while seamlessly integrating with existing +tools. + +[1]: https://tidelift.com/subscription/pkg/pypi-charset-normalizer?utm_source=pypi-charset-normalizer&utm_medium=readme + +# Changelog +All notable changes to charset-normalizer will be documented in this file. This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/). + +## [3.3.2](https://github.com/Ousret/charset_normalizer/compare/3.3.1...3.3.2) (2023-10-31) + +### Fixed +- Unintentional memory usage regression when using large payload that match several encoding (#376) +- Regression on some detection case showcased in the documentation (#371) + +### Added +- Noise (md) probe that identify malformed arabic representation due to the presence of letters in isolated form (credit to my wife) + +## [3.3.1](https://github.com/Ousret/charset_normalizer/compare/3.3.0...3.3.1) (2023-10-22) + +### Changed +- Optional mypyc compilation upgraded to version 1.6.1 for Python >= 3.8 +- Improved the general detection reliability based on reports from the community + +## [3.3.0](https://github.com/Ousret/charset_normalizer/compare/3.2.0...3.3.0) (2023-09-30) + +### Added +- Allow to execute the CLI (e.g. normalizer) through `python -m charset_normalizer.cli` or `python -m charset_normalizer` +- Support for 9 forgotten encoding that are supported by Python but unlisted in `encoding.aliases` as they have no alias (#323) + +### Removed +- (internal) Redundant utils.is_ascii function and unused function is_private_use_only +- (internal) charset_normalizer.assets is moved inside charset_normalizer.constant + +### Changed +- (internal) Unicode code blocks in constants are updated using the latest v15.0.0 definition to improve detection +- Optional mypyc compilation upgraded to version 1.5.1 for Python >= 3.8 + +### Fixed +- Unable to properly sort CharsetMatch when both chaos/noise and coherence were close due to an unreachable condition in \_\_lt\_\_ (#350) + +## [3.2.0](https://github.com/Ousret/charset_normalizer/compare/3.1.0...3.2.0) (2023-06-07) + +### Changed +- Typehint for function `from_path` no longer enforce `PathLike` as its first argument +- Minor improvement over the global detection reliability + +### Added +- Introduce function `is_binary` that relies on main capabilities, and optimized to detect binaries +- Propagate `enable_fallback` argument throughout `from_bytes`, `from_path`, and `from_fp` that allow a deeper control over the detection (default True) +- Explicit support for Python 3.12 + +### Fixed +- Edge case detection failure where a file would contain 'very-long' camel cased word (Issue #289) + +## [3.1.0](https://github.com/Ousret/charset_normalizer/compare/3.0.1...3.1.0) (2023-03-06) + +### Added +- Argument `should_rename_legacy` for legacy function `detect` and disregard any new arguments without errors (PR #262) + +### Removed +- Support for Python 3.6 (PR #260) + +### Changed +- Optional speedup provided by mypy/c 1.0.1 + +## [3.0.1](https://github.com/Ousret/charset_normalizer/compare/3.0.0...3.0.1) (2022-11-18) + +### Fixed +- Multi-bytes cutter/chunk generator did not always cut correctly (PR #233) + +### Changed +- Speedup provided by mypy/c 0.990 on Python >= 3.7 + +## [3.0.0](https://github.com/Ousret/charset_normalizer/compare/2.1.1...3.0.0) (2022-10-20) + +### Added +- Extend the capability of explain=True when cp_isolation contains at most two entries (min one), will log in details of the Mess-detector results +- Support for alternative language frequency set in charset_normalizer.assets.FREQUENCIES +- Add parameter `language_threshold` in `from_bytes`, `from_path` and `from_fp` to adjust the minimum expected coherence ratio +- `normalizer --version` now specify if current version provide extra speedup (meaning mypyc compilation whl) + +### Changed +- Build with static metadata using 'build' frontend +- Make the language detection stricter +- Optional: Module `md.py` can be compiled using Mypyc to provide an extra speedup up to 4x faster than v2.1 + +### Fixed +- CLI with opt --normalize fail when using full path for files +- TooManyAccentuatedPlugin induce false positive on the mess detection when too few alpha character have been fed to it +- Sphinx warnings when generating the documentation + +### Removed +- Coherence detector no longer return 'Simple English' instead return 'English' +- Coherence detector no longer return 'Classical Chinese' instead return 'Chinese' +- Breaking: Method `first()` and `best()` from CharsetMatch +- UTF-7 will no longer appear as "detected" without a recognized SIG/mark (is unreliable/conflict with ASCII) +- Breaking: Class aliases CharsetDetector, CharsetDoctor, CharsetNormalizerMatch and CharsetNormalizerMatches +- Breaking: Top-level function `normalize` +- Breaking: Properties `chaos_secondary_pass`, `coherence_non_latin` and `w_counter` from CharsetMatch +- Support for the backport `unicodedata2` + +## [3.0.0rc1](https://github.com/Ousret/charset_normalizer/compare/3.0.0b2...3.0.0rc1) (2022-10-18) + +### Added +- Extend the capability of explain=True when cp_isolation contains at most two entries (min one), will log in details of the Mess-detector results +- Support for alternative language frequency set in charset_normalizer.assets.FREQUENCIES +- Add parameter `language_threshold` in `from_bytes`, `from_path` and `from_fp` to adjust the minimum expected coherence ratio + +### Changed +- Build with static metadata using 'build' frontend +- Make the language detection stricter + +### Fixed +- CLI with opt --normalize fail when using full path for files +- TooManyAccentuatedPlugin induce false positive on the mess detection when too few alpha character have been fed to it + +### Removed +- Coherence detector no longer return 'Simple English' instead return 'English' +- Coherence detector no longer return 'Classical Chinese' instead return 'Chinese' + +## [3.0.0b2](https://github.com/Ousret/charset_normalizer/compare/3.0.0b1...3.0.0b2) (2022-08-21) + +### Added +- `normalizer --version` now specify if current version provide extra speedup (meaning mypyc compilation whl) + +### Removed +- Breaking: Method `first()` and `best()` from CharsetMatch +- UTF-7 will no longer appear as "detected" without a recognized SIG/mark (is unreliable/conflict with ASCII) + +### Fixed +- Sphinx warnings when generating the documentation + +## [3.0.0b1](https://github.com/Ousret/charset_normalizer/compare/2.1.0...3.0.0b1) (2022-08-15) + +### Changed +- Optional: Module `md.py` can be compiled using Mypyc to provide an extra speedup up to 4x faster than v2.1 + +### Removed +- Breaking: Class aliases CharsetDetector, CharsetDoctor, CharsetNormalizerMatch and CharsetNormalizerMatches +- Breaking: Top-level function `normalize` +- Breaking: Properties `chaos_secondary_pass`, `coherence_non_latin` and `w_counter` from CharsetMatch +- Support for the backport `unicodedata2` + +## [2.1.1](https://github.com/Ousret/charset_normalizer/compare/2.1.0...2.1.1) (2022-08-19) + +### Deprecated +- Function `normalize` scheduled for removal in 3.0 + +### Changed +- Removed useless call to decode in fn is_unprintable (#206) + +### Fixed +- Third-party library (i18n xgettext) crashing not recognizing utf_8 (PEP 263) with underscore from [@aleksandernovikov](https://github.com/aleksandernovikov) (#204) + +## [2.1.0](https://github.com/Ousret/charset_normalizer/compare/2.0.12...2.1.0) (2022-06-19) + +### Added +- Output the Unicode table version when running the CLI with `--version` (PR #194) + +### Changed +- Re-use decoded buffer for single byte character sets from [@nijel](https://github.com/nijel) (PR #175) +- Fixing some performance bottlenecks from [@deedy5](https://github.com/deedy5) (PR #183) + +### Fixed +- Workaround potential bug in cpython with Zero Width No-Break Space located in Arabic Presentation Forms-B, Unicode 1.1 not acknowledged as space (PR #175) +- CLI default threshold aligned with the API threshold from [@oleksandr-kuzmenko](https://github.com/oleksandr-kuzmenko) (PR #181) + +### Removed +- Support for Python 3.5 (PR #192) + +### Deprecated +- Use of backport unicodedata from `unicodedata2` as Python is quickly catching up, scheduled for removal in 3.0 (PR #194) + +## [2.0.12](https://github.com/Ousret/charset_normalizer/compare/2.0.11...2.0.12) (2022-02-12) + +### Fixed +- ASCII miss-detection on rare cases (PR #170) + +## [2.0.11](https://github.com/Ousret/charset_normalizer/compare/2.0.10...2.0.11) (2022-01-30) + +### Added +- Explicit support for Python 3.11 (PR #164) + +### Changed +- The logging behavior have been completely reviewed, now using only TRACE and DEBUG levels (PR #163 #165) + +## [2.0.10](https://github.com/Ousret/charset_normalizer/compare/2.0.9...2.0.10) (2022-01-04) + +### Fixed +- Fallback match entries might lead to UnicodeDecodeError for large bytes sequence (PR #154) + +### Changed +- Skipping the language-detection (CD) on ASCII (PR #155) + +## [2.0.9](https://github.com/Ousret/charset_normalizer/compare/2.0.8...2.0.9) (2021-12-03) + +### Changed +- Moderating the logging impact (since 2.0.8) for specific environments (PR #147) + +### Fixed +- Wrong logging level applied when setting kwarg `explain` to True (PR #146) + +## [2.0.8](https://github.com/Ousret/charset_normalizer/compare/2.0.7...2.0.8) (2021-11-24) +### Changed +- Improvement over Vietnamese detection (PR #126) +- MD improvement on trailing data and long foreign (non-pure latin) data (PR #124) +- Efficiency improvements in cd/alphabet_languages from [@adbar](https://github.com/adbar) (PR #122) +- call sum() without an intermediary list following PEP 289 recommendations from [@adbar](https://github.com/adbar) (PR #129) +- Code style as refactored by Sourcery-AI (PR #131) +- Minor adjustment on the MD around european words (PR #133) +- Remove and replace SRTs from assets / tests (PR #139) +- Initialize the library logger with a `NullHandler` by default from [@nmaynes](https://github.com/nmaynes) (PR #135) +- Setting kwarg `explain` to True will add provisionally (bounded to function lifespan) a specific stream handler (PR #135) + +### Fixed +- Fix large (misleading) sequence giving UnicodeDecodeError (PR #137) +- Avoid using too insignificant chunk (PR #137) + +### Added +- Add and expose function `set_logging_handler` to configure a specific StreamHandler from [@nmaynes](https://github.com/nmaynes) (PR #135) +- Add `CHANGELOG.md` entries, format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/) (PR #141) + +## [2.0.7](https://github.com/Ousret/charset_normalizer/compare/2.0.6...2.0.7) (2021-10-11) +### Added +- Add support for Kazakh (Cyrillic) language detection (PR #109) + +### Changed +- Further, improve inferring the language from a given single-byte code page (PR #112) +- Vainly trying to leverage PEP263 when PEP3120 is not supported (PR #116) +- Refactoring for potential performance improvements in loops from [@adbar](https://github.com/adbar) (PR #113) +- Various detection improvement (MD+CD) (PR #117) + +### Removed +- Remove redundant logging entry about detected language(s) (PR #115) + +### Fixed +- Fix a minor inconsistency between Python 3.5 and other versions regarding language detection (PR #117 #102) + +## [2.0.6](https://github.com/Ousret/charset_normalizer/compare/2.0.5...2.0.6) (2021-09-18) +### Fixed +- Unforeseen regression with the loss of the backward-compatibility with some older minor of Python 3.5.x (PR #100) +- Fix CLI crash when using --minimal output in certain cases (PR #103) + +### Changed +- Minor improvement to the detection efficiency (less than 1%) (PR #106 #101) + +## [2.0.5](https://github.com/Ousret/charset_normalizer/compare/2.0.4...2.0.5) (2021-09-14) +### Changed +- The project now comply with: flake8, mypy, isort and black to ensure a better overall quality (PR #81) +- The BC-support with v1.x was improved, the old staticmethods are restored (PR #82) +- The Unicode detection is slightly improved (PR #93) +- Add syntax sugar \_\_bool\_\_ for results CharsetMatches list-container (PR #91) + +### Removed +- The project no longer raise warning on tiny content given for detection, will be simply logged as warning instead (PR #92) + +### Fixed +- In some rare case, the chunks extractor could cut in the middle of a multi-byte character and could mislead the mess detection (PR #95) +- Some rare 'space' characters could trip up the UnprintablePlugin/Mess detection (PR #96) +- The MANIFEST.in was not exhaustive (PR #78) + +## [2.0.4](https://github.com/Ousret/charset_normalizer/compare/2.0.3...2.0.4) (2021-07-30) +### Fixed +- The CLI no longer raise an unexpected exception when no encoding has been found (PR #70) +- Fix accessing the 'alphabets' property when the payload contains surrogate characters (PR #68) +- The logger could mislead (explain=True) on detected languages and the impact of one MBCS match (PR #72) +- Submatch factoring could be wrong in rare edge cases (PR #72) +- Multiple files given to the CLI were ignored when publishing results to STDOUT. (After the first path) (PR #72) +- Fix line endings from CRLF to LF for certain project files (PR #67) + +### Changed +- Adjust the MD to lower the sensitivity, thus improving the global detection reliability (PR #69 #76) +- Allow fallback on specified encoding if any (PR #71) + +## [2.0.3](https://github.com/Ousret/charset_normalizer/compare/2.0.2...2.0.3) (2021-07-16) +### Changed +- Part of the detection mechanism has been improved to be less sensitive, resulting in more accurate detection results. Especially ASCII. (PR #63) +- According to the community wishes, the detection will fall back on ASCII or UTF-8 in a last-resort case. (PR #64) + +## [2.0.2](https://github.com/Ousret/charset_normalizer/compare/2.0.1...2.0.2) (2021-07-15) +### Fixed +- Empty/Too small JSON payload miss-detection fixed. Report from [@tseaver](https://github.com/tseaver) (PR #59) + +### Changed +- Don't inject unicodedata2 into sys.modules from [@akx](https://github.com/akx) (PR #57) + +## [2.0.1](https://github.com/Ousret/charset_normalizer/compare/2.0.0...2.0.1) (2021-07-13) +### Fixed +- Make it work where there isn't a filesystem available, dropping assets frequencies.json. Report from [@sethmlarson](https://github.com/sethmlarson). (PR #55) +- Using explain=False permanently disable the verbose output in the current runtime (PR #47) +- One log entry (language target preemptive) was not show in logs when using explain=True (PR #47) +- Fix undesired exception (ValueError) on getitem of instance CharsetMatches (PR #52) + +### Changed +- Public function normalize default args values were not aligned with from_bytes (PR #53) + +### Added +- You may now use charset aliases in cp_isolation and cp_exclusion arguments (PR #47) + +## [2.0.0](https://github.com/Ousret/charset_normalizer/compare/1.4.1...2.0.0) (2021-07-02) +### Changed +- 4x to 5 times faster than the previous 1.4.0 release. At least 2x faster than Chardet. +- Accent has been made on UTF-8 detection, should perform rather instantaneous. +- The backward compatibility with Chardet has been greatly improved. The legacy detect function returns an identical charset name whenever possible. +- The detection mechanism has been slightly improved, now Turkish content is detected correctly (most of the time) +- The program has been rewritten to ease the readability and maintainability. (+Using static typing)+ +- utf_7 detection has been reinstated. + +### Removed +- This package no longer require anything when used with Python 3.5 (Dropped cached_property) +- Removed support for these languages: Catalan, Esperanto, Kazakh, Baque, Volapük, Azeri, Galician, Nynorsk, Macedonian, and Serbocroatian. +- The exception hook on UnicodeDecodeError has been removed. + +### Deprecated +- Methods coherence_non_latin, w_counter, chaos_secondary_pass of the class CharsetMatch are now deprecated and scheduled for removal in v3.0 + +### Fixed +- The CLI output used the relative path of the file(s). Should be absolute. + +## [1.4.1](https://github.com/Ousret/charset_normalizer/compare/1.4.0...1.4.1) (2021-05-28) +### Fixed +- Logger configuration/usage no longer conflict with others (PR #44) + +## [1.4.0](https://github.com/Ousret/charset_normalizer/compare/1.3.9...1.4.0) (2021-05-21) +### Removed +- Using standard logging instead of using the package loguru. +- Dropping nose test framework in favor of the maintained pytest. +- Choose to not use dragonmapper package to help with gibberish Chinese/CJK text. +- Require cached_property only for Python 3.5 due to constraint. Dropping for every other interpreter version. +- Stop support for UTF-7 that does not contain a SIG. +- Dropping PrettyTable, replaced with pure JSON output in CLI. + +### Fixed +- BOM marker in a CharsetNormalizerMatch instance could be False in rare cases even if obviously present. Due to the sub-match factoring process. +- Not searching properly for the BOM when trying utf32/16 parent codec. + +### Changed +- Improving the package final size by compressing frequencies.json. +- Huge improvement over the larges payload. + +### Added +- CLI now produces JSON consumable output. +- Return ASCII if given sequences fit. Given reasonable confidence. + +## [1.3.9](https://github.com/Ousret/charset_normalizer/compare/1.3.8...1.3.9) (2021-05-13) + +### Fixed +- In some very rare cases, you may end up getting encode/decode errors due to a bad bytes payload (PR #40) + +## [1.3.8](https://github.com/Ousret/charset_normalizer/compare/1.3.7...1.3.8) (2021-05-12) + +### Fixed +- Empty given payload for detection may cause an exception if trying to access the `alphabets` property. (PR #39) + +## [1.3.7](https://github.com/Ousret/charset_normalizer/compare/1.3.6...1.3.7) (2021-05-12) + +### Fixed +- The legacy detect function should return UTF-8-SIG if sig is present in the payload. (PR #38) + +## [1.3.6](https://github.com/Ousret/charset_normalizer/compare/1.3.5...1.3.6) (2021-02-09) + +### Changed +- Amend the previous release to allow prettytable 2.0 (PR #35) + +## [1.3.5](https://github.com/Ousret/charset_normalizer/compare/1.3.4...1.3.5) (2021-02-08) + +### Fixed +- Fix error while using the package with a python pre-release interpreter (PR #33) + +### Changed +- Dependencies refactoring, constraints revised. + +### Added +- Add python 3.9 and 3.10 to the supported interpreters + +MIT License + +Copyright (c) 2019 TAHRI Ahmed R. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/RECORD b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/RECORD new file mode 100644 index 0000000..bd8a715 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/RECORD @@ -0,0 +1,35 @@ +../../bin/normalizer,sha256=O1tLXvRzeuQHDVSDjsuiUko8eeXdZtA_eGTgJcdT5qs,233 +charset_normalizer-3.3.2.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4 +charset_normalizer-3.3.2.dist-info/LICENSE,sha256=6zGgxaT7Cbik4yBV0lweX5w1iidS_vPNcgIT0cz-4kE,1070 +charset_normalizer-3.3.2.dist-info/METADATA,sha256=cfLhl5A6SI-F0oclm8w8ux9wshL1nipdeCdVnYb4AaA,33550 +charset_normalizer-3.3.2.dist-info/RECORD,, +charset_normalizer-3.3.2.dist-info/WHEEL,sha256=4ZiCdXIWMxJyEClivrQv1QAHZpQh8kVYU92_ZAVwaok,152 +charset_normalizer-3.3.2.dist-info/entry_points.txt,sha256=ADSTKrkXZ3hhdOVFi6DcUEHQRS0xfxDIE_pEz4wLIXA,65 +charset_normalizer-3.3.2.dist-info/top_level.txt,sha256=7ASyzePr8_xuZWJsnqJjIBtyV8vhEo0wBCv1MPRRi3Q,19 +charset_normalizer/__init__.py,sha256=UzI3xC8PhmcLRMzSgPb6minTmRq0kWznnCBJ8ZCc2XI,1577 +charset_normalizer/__main__.py,sha256=JxY8bleaENOFlLRb9HfoeZCzAMnn2A1oGR5Xm2eyqg0,73 +charset_normalizer/__pycache__/__init__.cpython-312.pyc,, +charset_normalizer/__pycache__/__main__.cpython-312.pyc,, +charset_normalizer/__pycache__/api.cpython-312.pyc,, +charset_normalizer/__pycache__/cd.cpython-312.pyc,, +charset_normalizer/__pycache__/constant.cpython-312.pyc,, +charset_normalizer/__pycache__/legacy.cpython-312.pyc,, +charset_normalizer/__pycache__/md.cpython-312.pyc,, +charset_normalizer/__pycache__/models.cpython-312.pyc,, +charset_normalizer/__pycache__/utils.cpython-312.pyc,, +charset_normalizer/__pycache__/version.cpython-312.pyc,, +charset_normalizer/api.py,sha256=WOlWjy6wT8SeMYFpaGbXZFN1TMXa-s8vZYfkL4G29iQ,21097 +charset_normalizer/cd.py,sha256=xwZliZcTQFA3jU0c00PRiu9MNxXTFxQkFLWmMW24ZzI,12560 +charset_normalizer/cli/__init__.py,sha256=D5ERp8P62llm2FuoMzydZ7d9rs8cvvLXqE-1_6oViPc,100 +charset_normalizer/cli/__main__.py,sha256=2F-xURZJzo063Ye-2RLJ2wcmURpbKeAzKwpiws65dAs,9744 +charset_normalizer/cli/__pycache__/__init__.cpython-312.pyc,, +charset_normalizer/cli/__pycache__/__main__.cpython-312.pyc,, +charset_normalizer/constant.py,sha256=p0IsOVcEbPWYPOdWhnhRbjK1YVBy6fs05C5vKC-zoxU,40481 +charset_normalizer/legacy.py,sha256=T-QuVMsMeDiQEk8WSszMrzVJg_14AMeSkmHdRYhdl1k,2071 +charset_normalizer/md.cpython-312-x86_64-linux-gnu.so,sha256=W654QTU3QZI6eWJ0fanScAr0_O6sL0I61fyRSdC-39Y,16064 +charset_normalizer/md.py,sha256=NkSuVLK13_a8c7BxZ4cGIQ5vOtGIWOdh22WZEvjp-7U,19624 +charset_normalizer/md__mypyc.cpython-312-x86_64-linux-gnu.so,sha256=IlObIV4dmRhFV8V7H-zK4rTxPzTSi9JmrWZD26JQfxI,272640 +charset_normalizer/models.py,sha256=I5i0s4aKCCgLPY2tUY3pwkgFA-BUbbNxQ7hVkVTt62s,11624 +charset_normalizer/py.typed,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0 +charset_normalizer/utils.py,sha256=teiosMqzKjXyAHXnGdjSBOgnBZwx-SkBbCLrx0UXy8M,11894 +charset_normalizer/version.py,sha256=iHKUfHD3kDRSyrh_BN2ojh43TA5-UZQjvbVIEFfpHDs,79 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/WHEEL b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/WHEEL new file mode 100644 index 0000000..d1b3f1d --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/WHEEL @@ -0,0 +1,6 @@ +Wheel-Version: 1.0 +Generator: bdist_wheel (0.41.2) +Root-Is-Purelib: false +Tag: cp312-cp312-manylinux_2_17_x86_64 +Tag: cp312-cp312-manylinux2014_x86_64 + diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/entry_points.txt b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/entry_points.txt new file mode 100644 index 0000000..65619e7 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/entry_points.txt @@ -0,0 +1,2 @@ +[console_scripts] +normalizer = charset_normalizer.cli:cli_detect diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/top_level.txt b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/top_level.txt new file mode 100644 index 0000000..66958f0 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer-3.3.2.dist-info/top_level.txt @@ -0,0 +1 @@ +charset_normalizer diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__init__.py new file mode 100644 index 0000000..55991fc --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__init__.py @@ -0,0 +1,46 @@ +# -*- coding: utf-8 -*- +""" +Charset-Normalizer +~~~~~~~~~~~~~~ +The Real First Universal Charset Detector. +A library that helps you read text from an unknown charset encoding. +Motivated by chardet, This package is trying to resolve the issue by taking a new approach. +All IANA character set names for which the Python core library provides codecs are supported. + +Basic usage: + >>> from charset_normalizer import from_bytes + >>> results = from_bytes('Bсеки човек има право на образование. Oбразованието!'.encode('utf_8')) + >>> best_guess = results.best() + >>> str(best_guess) + 'Bсеки човек има право на образование. Oбразованието!' + +Others methods and usages are available - see the full documentation +at . +:copyright: (c) 2021 by Ahmed TAHRI +:license: MIT, see LICENSE for more details. +""" +import logging + +from .api import from_bytes, from_fp, from_path, is_binary +from .legacy import detect +from .models import CharsetMatch, CharsetMatches +from .utils import set_logging_handler +from .version import VERSION, __version__ + +__all__ = ( + "from_fp", + "from_path", + "from_bytes", + "is_binary", + "detect", + "CharsetMatch", + "CharsetMatches", + "__version__", + "VERSION", + "set_logging_handler", +) + +# Attach a NullHandler to the top level logger by default +# https://docs.python.org/3.3/howto/logging.html#configuring-logging-for-a-library + +logging.getLogger("charset_normalizer").addHandler(logging.NullHandler()) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__main__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__main__.py new file mode 100644 index 0000000..beae2ef --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__main__.py @@ -0,0 +1,4 @@ +from .cli import cli_detect + +if __name__ == "__main__": + cli_detect() diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..c6cce549f9aa8bdda9cc045c3260ac43d92affc4 GIT binary patch literal 1698 zcmcIk&1)M+6rYu3$y(WQ?9fX~VG1GALM$aVp+%$yJGHSOmW$)|u$N`DJJN1E`@zht zUHMSlT>2;EZz#FAg-}yk_tIN?SYe7`A>`0Q$<4*Locd-ZSt-f2dwBcan|bg3-q-v- zJF6r3p5FYUYZMXsO9|tzFk&u$1Li4mkck}4$uZ5;oV-(DIX`da{eoHWr_3q8XcjdD z`YBfOr_Je%FS4?)o4Q{yE16tkGybeOoAJ}^nm=dG`Pa?sAeYVg9HQFeo8#b#LY~9Zq;3OP5IOQWgo^4`a+Jaj>LcN!;b3k4b>z zU@r&{0&EZCV;b0@;|0CCz74tzW+R#t`ykFvCat14s9 zS7zC<)#*zr#s-j2%%s4dzHwHot_{9Po+m#gCwTB}a+>_01e}~CKPSgH`E_uV9E0u@ zC%-89H2FT${FvQ52IWceypFfur5-#$`>vFcXf_%>Pr7lZZijwjI~JVE#@kI>sq0NUjQZT`xw46Cwt<)KEZtQD zx9a*ZvAe6AJ1xD*JevlBHt|+#_jU&0Ve7$q`_XzfW4;iR3Sob6X?t&Kve ztNj?xLt4uCZj_cYCL+>J%bu`0UH~g*XlW6gz~&jbbY`@RTSVG!dhJb#3b=U#rrcs- zuLnzExlk-dIhd8cT;F-r+HR*6%Th}XHL)y1=TiWN!xM#@3v}xxGA;_0O75t1fswXwR60lV12ms3+&V+mbF?%-OUd%a@yF-O S8-wMIv*pb{QHy^7ZvO?qL_{^hOxYR?3`HDF z45^H(p$ZupDw!*pHCbLV0tGY~Z*e8(WX7kYmZT<^+~SCj&rQtCi;wryWWL1=lqg~b zDgp`TCFZ8a$FF4g3^L`HlYU8Vfqp?|fo@4+QF>~LZdGx9QB{g*k$z5Ql72yDNk)F2 zesV@)QE_TXd|rN0ZemVmRcetw%y_+m%3mBdx%nxjIjMFy1QYC zbYoZcOl74SZA`~W4QJy@am%V&rQ{E#)>U!-^pVG=lG*}9df4i4YUzqLGs+hwao1V< zBRS_b8Vzb-TbejkX^GvpZ{K_FdEax-z4$LapNE3$m)-w$Dsh&g{yV-HSADVYByWWl z6i@M%BsGCgYtoXkPFO8iwk2&T`-DB^m~f=3CaO}-31`YR;eu~=-jQ^tJQJRjcfy;Z zC+L)K!bj?>lGQ2ygg?bhFsYh}np9vSK3uUDQ>e68YdGpD8Zd>%Xi4M|c#QbKIZWjv^ zT|(ETQKQy;l72ri-;EOQHDDW03+4X3e|#HH3oc=s&@*Ligs!|#=;f>7&o4xHMyL`T zLLb(XZ#7T72ZVmU7XE_JHU!T)p?<24um8DYVxZzk4TAkgfZqu42P?vF0!sRT7VDJl zN1~+}#)?)LtDSFwv8*tfUD!5d{}D#(2hO#^XhUTF)I2N&Ju2(tv;;F=p5OHX( zqlq*p&W)bY?57fvthvt2%85*xOKP@pLDn4S)A05X^(kW4{PE01K@`$)AtrLrObb9c z!za?yu_TwC&T`X&q=izGu?p37DM6eTVoyPk0BZHg@zY06oighj=guBEb{wejqy$OQ@rhV9`q)KIlmz)SC&w>p z)#Y!36me>GTzW1h%?k0vR6^iOh-$U*tQ?bscd~@K_{D5`M$+5~F3rW#TuRVt6TFa? z6I0MRF&)c@vB^wI^ChHMd=_d_i6kd#b?}r($f zTt_yR&WI^4nV1*E`AE2zlj3qBB}61vVZ*&i;awq#I27NJTwrtr&@=FrG>0S$vy$c^ zh{F)`g65VliUN$BHU7tSAU65c<19Y*M($y_?8nMa?N( znN4zuv=%S~8#BTAg)}#r6k=0cGC9e`XS6C&kh5YsPFyQ$8C*2{+2HTVzY3x=m5VNk zq7+I7_o`pA-6&02Zx?H&F4<|+@|H_(qijB9uTfSg!wo(C{J^3(#iKG}L9R>HM#+5U zJZ0Z&%zC3F2aJ*d-9nZ12pM0^r(9>0%X*+4lgq?5=T*GCb*7i1#COUdHXAL?CvP($ z0Y!()TDO|5jMDRC{3o6(7Ks76+6)+%SfgY13XiQ<-G>9+r>hz1~3Z1UoDIs zguf8{)tPozYF97sGy0kszll<6$Tcbr@9+5zoE!cCoNLPD-e~k!8g3W;H`roD{_p{# zErzs;|6Pk%^BpZq_KmRQ{RU<8P#B>W>~H-g(AA{aMTY`+fMdDgRUG8a@h$~#0jRGb zrFy02(m|uY`Ba+9aB=0Dl?J5=J#el?X}Mw%y&%CuMr*Teu2pH`YXNSX(jv7yv-Sl6 zLdj3v_#=Q3dTtnXTVQEz8HohuLiM!>Kr8cdkrW(An%d~pFB>g5T zT?ccqY4atyR&K2{eb!iJjqSfTl2xJ7zRD1JR})ppLCeoxnQ}`DW55g(IQ!SYuZzZcExK_|FnlR zB%13~+CXDq*`_q}uB-*h)u25lCz}mTQ@q4$b}3zA^E2ZP8fT0IP)q*041T8ppKn9o zZoK8X<=09ycJu89A9LNjH5UesZv(H=1Ao1sOXH=MAQ`0-=8+bqRcTb(l;+#Tm#sO{Gv7ENX zVcBi)qkKf3MTRT38JKgx4}^K&ybrJqD`BM@>m(OgtmVd}LhJxa(?vbnCUt|wfD9!T zY^RLFyvbM4*Gm@+?9C_Gao1^Im!`Ke=q8QudpohYc=+&n5=jzfPgiv}9rmavLTCm<&duE;QQ<{DNV{@iylW6&^ z5_Ki7o*PJeuQAsDvcD5|pe;o!C@H*Y`)Z!)4l0C+;ZgSBW1xl)6j2p|R$(3`Ru_Q|b&{!Jmst zNVF=!_uJvwtOUhIC3I=Zgk_YJV5Qm_uu`Bf^nT9|V7k*Bv9i`HA+trg7x38j0}ywa z?Y{$Ju)Kx%;t#;v4NwvWwdT`UD^%ihMd|zIA%|o59pG>12gcn~hUNcbYgFpTVV!S* zzZ`wJtkgxxM-7T)So7-Fl(m}@AxU0_|M%-IShz{|8`MJ8jRTjdE4DYN%N7{nWdp8U zN{W*aUdy$YWwzSQuZ9*&;b+F63FbgEdT%#4Yeun3ppwTej}hL0SU=bP$L)aqpX;T| zmP%9rZ*~FZW_IlRdDHQOm~}&Z*__)}8sC27^B)-h$a9Pz{=xB|oiolGJx^m6*~?8q zc;R8;Ith8uG|RCfcbUa3uEZKi)&W+}ayUv1x23LBd!XU=uRdaM&S}o@NtiJ`v~Sj0mkc znG7jGUN%npO_G%TP&xx2ge$TR_~;zV3sW3G8z9YR#Y`MB#q8xoGRZK)U%SjS8M$$09%yMa-Ev4$QHOEd9&KTU#2R#DK$N>0}&CWuz zSx%G_@hs%S0RS(+`?SDvQ!+4P$M!ISN(r2l6$PG*6lKp{%t!(o7ZcDV!Lc0hCZ3h# zOe!%?m=VsbD1!GR!n4IXh@iU2kvCl$*jz#ArBAY;ATJuGCKvLnHIUUEbvkG7?)-f zDd0FT0mq#cMEIWKV56jn_8XZjo8so!%g_V)J(U3(**Op?%gHkCEC6CqFJ)3deu-}x zaR?=WlFk5N5fmkh%qmOg>!O;Cl`{GSHPjk{`D|7MH8s#UcM+6qDw{4c0#$=-N)W8a zM^A#@=>%|d$qdI28PaBv_Bj@JB|w+r!YtsEX3w8HF*v+ufIN5Zcv=k!pk!iFgzY7k z&w!O68L%~jYLcE~F9Kyr;3y#s8UqiJcVpRP@@4%K2xtm<1m=}N9YOvGx-s+=_a}M? zk#c5wS~t6MVwQ-9C?%IftwW$mXaL1{COwsy&XT<=!fuY|LG0tQC~&Fbpoj^vMJbz* zi2|aid0{d;Jq;UOI+e$Wf)cP$ha68qClr-IRUF8f6bQbc2U*xDnbW(@?>c@3wx2+6 zijDzILY|uipF-RX42A_x6uG$pb~+>PXW!eN6EXarfAM&6yRA%{K@PZmGpBbSKugZ1 z5UH#@6?*{$TGXzn<{&lG#!PlXqsHd{Xp1U=asY#)M8{;JDoKt|XVT9a3dJU2*9)mg z!nPsOVC?y^Kx^hQeAv&1rRcnMfSu=H6jMKcoKXlozBJ6+V0)qnn{=SiuoK4ih7%Fp zG;k}A?1&ZXz*}bsQ%t3t0)vJQgoV9QM0a%&bY-yZ20A1~MNEmzzjRKVL)L;K>h8oO zdP>ZsK$YYKX!dLdTp-8=n9}=RE@FU<&X1m#uzQl5pCdB^FX+3cpeb<<4VyR*-S%)g zcn4Gvl$V2z(}AZz9UdY64Cn_S&;qvh!1<&&aRzPJu-hp6s_x(B*#6<72S;^A!Hkw5 zfCYf*L-o-!r*#m3{8T~&xtdJ*9#EPCb}SQ#mrzHwD%7&!J^FL!j`=rBIva+`D3k7y z(Jo+OMcv_~K_Jth9;6_`4r~Hu01k19vKP=p$>2YTUzDpfe$4}sCoLtx;5B~AKOy)Qlz@!9w*$`vEpooDkCmvi0YJ7T-kQaT3 zS)7NcClCKOT=U#1Fa>bG>?xRSpy7V@2#FLokm!tNKD7V06M?zy&S8bS%7#4oDWWIbKr;cBOd4>fr9sP-&h9b z*$YC^7s6OZ3;0$P{Cm0I{`s%)`ge!sqa|A^nIBFOsM@IvC{Yqlq$DB8fcYBqDLS8d zuJ+(d*vn#<7U#{NC@NfJ7(Y1;OQ`4+OI_`hfd|b1U=vD|OT- z^gpaGanO3G{(a-VRcYK4nJkz-dKXZtB+OH|=3#p$!G#Y(n8PP{P8K30>@3c#=(y#J zIC+o|EKMdSm~swQ0)L(yCNbtz5n>l~tl;vE_^Y_Mibi&8o&>lPNyflhbC<#-%|X12 z<~|2u)N!7TlXr;2LT9xi)0g-G9nxMEv*sP#L z%nyios7HjI6-pd}o8|@Y2(dJ*o6@poMl zG^XY(F7P!Pk9`Tn@Llub+pHewX+EPmhR4k`zb*~F^gRei&G5t-_TkD;JLadya7*ekVOM{ob3A|<%V;WNiYciA0N?Hx5O-w&wHVyMs zEIX?)5DO&XOq`sVg`<60P>B#mw|LZTD@)xeUhfLW)}Tn1U~p`WK-2sDmtgK6MRG5Y$7^4r+IKmKu!Wm;?H1wvBiezUFWJM7cG3 z=ki_K-SdBaH2><^<@WJ>+qq@``Mm4=y0bR#Y)81B>z*~bX2WXn?Ovyu4@a+$E+m)f zu1&YY?b)EI7e*|nqFp#ewxkeZ2N7m~buhEsj?D<2$_!jyWvxPwS zJ!jZNN~M!3U8B-G z>z2a5YFiHVUh_QY3@;@Pd8-*=4^I!ECBD`!jjNT*im@d7=rGIc~~ zfA0YDL0+CR9;x(&Rr>7${kG9)6B_|ey?p@hQ56+EY60Ob&aJp2cjXNm<*46qQLd)E zGpxE=S6$r&S9dFP^^B zQfN7-(!sCr<<^^pmVNND?rm5+QSf$RQP--4gDb9%^~m5gzZxFC^Hw2zH1BFrJ9a;& zteu{f{jaHXBe42_C+}(iHqnjwmhA=a_QJl?sLwyS{*yH(q%vuhX$9{1sy958FQmdC zqXloc5ItJnh~Ls^!|rm2*7^?LZC&m=lczg20uAoaeSdd8^3vUKA#!q!sa>z{xwX4c zza3;0YFnJSXs_>e9+RKXNT_$FSqQ5Hkpfaq=G^B8qdMxiWz2H3 zcIk~z+dl8QllZIXy^h2A@z+7Cy-kaWd)}UW|AG9WSMT+|s?uGnbYFq)yLE7d-nW&< z+kwZx4$$d^%q?4?uK&(!E6mvH~upX9@@6oRkZZy0>g0W`HP z=58gv2;H^bJp;zl8Ca;^sG@=$`R+aUYWJv-y@lX5HPpE@eJ?bqhIf86w%)mY;g$Pz z@IlG5tMn^iY2e})hL(;M0zG$XR_L9?2Ry2#nDAQPi(kC8-1ka>Zh6qY>&{!t?Z@(T z%U9lJ6MvO?VU;;lU=9J2H+SZH_AYn50LXw%I6!GY^FsBY0%*dEC+~T?)J9N5r*FrC zW36*o4K}L5ZTEK^T{!m3mp^(r-#WMwjQ+J9gh&j9HWi`$OJ;b(5B)X+RLhP#k>%zW zLDQZ>WXCGAufXgBSudrwpx|actiE2oMmHEL*ly@w`x9jHrp*nmx`FaF<=eL3>G@)B zzV%pvK8D89b&m-@0GD&>`YDw;e0OjYCvEWNO#K>Dx5{)EnC_dg6=pZQ{nG!DKhN%7 zVfL)mb}a3^b+FL2FWTCJ!ivxZ{4q=g@KpKrNeDHY-9+!tvI&IjH*oMD$`$J`pHL-jxYG(*!8h| z^Wc|s^ebP(;@kPwonJA{_k*2kuzfYyUkLW!`s3B1(ZbN^z2N9N)0}5|ifqX@o?oF~ zSLs@Wuz280y63)+=m(Iw_1jA;bl+FbYMgo?UQy{8>;$cTF}6x~73ePXT+UydS{w#- z`}^Xg=l1Kd&AAoVdA;wdtEJ#-`6LDt5JG~eDBm!+;)w{>Y(Bk;JW((fi{Zoe=e-}McHMQUIKlVG|<+oP%G~B(B z>HUu1?sq`>cUE_TcKpt}C*gEFbUL7{S*K*{ zSE>{zoU3x*#>FaJB&mS#v~xYF$;@# zeg8<`4=QF*Aw`XOR05l%r*T&+o+SHIkWDJ@syB*QN%*hXv17y|{v7aouC=m+M42lW z@dJ3(oCNi$S@BQd?H?cwF5&TXSX!{Kv`}5151rSYzi_KApXv&zt{T-9B>!7fmtS=? zsjm7bAunCEL3tfjPoN{E*=ONLVOykvYkuVZlQi76N`)~kxVq%?I!y`QT7a^SWxzu zy+#3GSx>m@k^-V}!$jXwhdd+?TcyZr+|m`f1nkL-o*@Yoy&6`=lVk8RGkXT$65dC= z;&tH9b4irwfP^U)Q>?5mS2vL>%0m1z_#T8@x%3JYh-5w0*Z75zWq0ESMLRr;XV?6& zys0+UIUxwp$$u6+C#(!qx*3Gbc)qqlcEZV74^T&4v5s<>3x<6+l9EQBm4ct&u@{A`2>YvvIAl_% z@u0%Rl)lSTJnO;ET!sWaR2gSPz;Wpt^yEMRZe<%;Daf*8ZkdpShb;I6Ijn*kO1LAZ z?~cIk4M!4yEXi#T#$oRPvbUJUDK%jQ*0Iak( zk69=WINa6;bj=za+HlxliSDTKRKY5#w)NSd?J5ClrfQp>txuEDN4$n?b3eo%hCPHI zic`g1nE!leZ0y_#aUWEl19AN`c#0q6?VrP~^yvg-bn(EOX3a=MGFla+(Lq&3JGMoj zA|3@7op?hlg?ufqCyJ5VdfphVQ**(N0OspulH1mk-y{uAlIzwKU(7(G<4sB=cTTeC zxTl+d3QUyinQBa<>sfNlWRu)D$&zbs*q=H@&Uc81;fv-QFF(#99>Y2sQtT(lAq|+( zHFv34rfsLNodeDVaWYX!$ZcmbNmB`R?L=ky*A!td@z>wDUIf%3KmU^WDSQHVK}o%! z%o{d~#q!^%>fccHe@pHClG^*V-C?mlq2Ts4OQ~)O1$R@vd1%?a{c4pO=vnAl4fMbgY&j6Q>Q^cMD%Db;T2y=J>d94ms9+D} z>y9kjkHP{3U{q6qTD7iGt#49$2k?JK7#CA)m)gQU3Y~RYYE^%5;r!xgJ`^taw{6(4 zYTaAC;lKi{5^I7RPEvGHkZW+0qKB$&Ufi{0`_;ZeAiUuvb@Y}xAE~RRn%g)0q{vX! zfsGnc3{Z`28?~eur0SYB2o|uIuL?e?C$;Gk(#@5SZnjjZE@s09Pl6~si+Ey5M-xj= zVTn~wA&FHwj#$!B#FCC7mUINMq~nLB!xn?5713+4cvO#n!3Io))qi)v6W*{v9YGbI zMO3k*ql%@cP{pdJP{k@8RV?YKVo668OFF7p(ox0I(eFXE<5B34rCx1jml|&EyyN;J zobNbPXg<7QgIaOk;RgZES7X+u>{C^HtV58Eb0FM Du}j`c literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/cd.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/cd.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..bc400a8568678479de3e79275bce973924f6dcb6 GIT binary patch literal 13461 zcmd6NTW}m#dS3TjdoT^m;7Z)lxMM)##=A&@ckn8L(h^#Uux0FUx&aJ17pQwc64*f& z)~d?TnyIC1$AZ240IgZILrbYZ_C9c{T#0u5BA5Np&4G+jhg(4$RuWa^VF)m`rAo#5 z&gshxAWEsqQ@Vhj)2IJ)`dt41`)}uOOG`@_T<>@M-DGfxVg3twurB%r4_gigC>W6u z*%&iUejPD3?ihElr0k42imLCa5Ti~6&Di`S&B=ER5*54iX=rzMy>ZuayF5o zMPE#worr`Z(^AMSyU{+F}-5!>eY#B zS5CeB^29Zx<%rIWUohHXL_$=VP-c~xXe64PRbq2^h(shsiQbkbKvY9;Z!uC*Ps-ijisU!H|A2(1eztqXktpQNBwLf zN|wUtc|yUuB*d^hrr~^XBVl=T19r28^2Gd#c=eO1r1*8Q6V$(jJAq*P5!d zsXX>OZ`!-a-Wy0&+wZ*AJCU1Z&~7;GO*?P1vRibgooVke5R%`!j=NMEMc+I|9C1b* z^o`4SUU1#J?qX8A>|UK`nIC&2jwvSMcoQ>NK%Z$Zk&d)$-VZ4&x%Jx&BRkUG_Z;`i zU7%X9$8il$EUmf2g#7d8N(5Zrp<6A46(t#o60QAS%94HCTg~$pcPjngU(h|#sYFsH9Pg22 zIVmeL*{Ls1lH0%Fc1|YyKDCcte|;jv%T;*Ry%(>J5OT0>oO~}9y`h&H#ff-QoQ;8t zCzEnKoRSGo>TWt4-6K+1(A{KAid=(NGTAZRqtHQzIGHT9?ltISot@GBiX zyc}Kg_B<)8R%^~>%g(FZ`KM*O*2_Azvd$b=v(7bXT+?zi%k^wI9RbgO^VDjd+Ps@_ z^UpY@sUvfEt#SY2sa#vf;^kaJU$KcjpqDtFC$fjrZR8skHLy z%9)?s%vOh%-2dPYKIuF1=s>pb)Y8?BK(iX?$^~nm211#EY~aWv>2cspuCgt&TdO>f z+qeJz<&}U|HJA%FEMLtA_pGv7a0tJ-V9Uyo7VLO0kZ-`3o;NdmMc%`74E&?p*72RPElFux6o1;>Ij4XJ#y9c5Pm z>(VwRrI}kj*dq2`MVh@yaCFC&c34QkGAwhi&&AvuZ~@n@F(G#Tc(Ig56O#}U$W{zm zViqE(2(t5e<4Tje};h7mJAwmTXkXJstGo7=FdWp^F zita0v$$C+KmN9!q-?dGJKo^;#k`LkSN&G9nh1(*N=a|Ok#fwjc-Rr`TCJbeTeVdHS zU88Z0OWgh5TwVJnOi71;$xn#G<0Tc9l*1edWtT-vz+giNqleaE6x zbWULp3OcQ@PuLmP{7>o5T%*WnV4NkS_V(DY3Uurjt|j9|=qZF{Ntl+xx1+H+Ar?*C z!ak;w09H8_jm*ZvvfWFM5;8V(Y&xn4lNQ>FNo;>=nsf=CP-dXkF#r>lM|Jnh#4`BG zPk)5dVem=FK>>sA4j6+XUD>uRR1B5~C^J$dIvJHj6ZeR%ME2d-_6lpFMLT{R6j$-D zT)_=U#51jjR_C(9sm0M;d-vj%jfN2R*j=#{$oVUl2Oj%FxyIc~S3c*<^IlZvOBk+N z^)}{$O-nyex#p+-ww2+me@Jx=$%oP7i}(0{;LZC?nz?CPBd9R1f(4>AvVx4OQ=q$gn#&zZVRqOs1&EK-Zulf55Pu?|u51y92kNqth!TP1N z$~EM?!F6wg=51I$yXI|Ox&DhDt@8-*Y3chaS6_Jf@|ri4x&Bu@THk5tzomJVtK0CG zE?%T83=_v258qXYTHjBGR?M_y!zpaZD8Q*@0aA_yM+#5Im8N2HthhIRTrru`@P6gQ?#7`;Jq%QWYUgF2N=saKSdeqtOV00j!hBbVPg3aAV>jp z*mr7bI0~kQ z$i4$WIm=k)g#`u+&cZI=Bs1P|S@htGY115WEx1#*kx?*0sHx(Cy8s6y?G+ufjLhC^ zNPB1r1`M9sQnn+OcH1N1ifiF~_)O;mvzhr?&LElHQ8IpUTq z_|tyTNn8`qeizOcF-mq^X;<1mX+ts$Axya7#HAgg>m5dPf8_a)tRgO`a0kZ2o8!Tp z7x*+UQfCNb@zJsHw$tOgW4S*(+#ha!g!22>-5-my!NUcg2#R?M-g!bOm_i0Oe@%$@ zVPso-al6d0R5wvCt;niO+kWLAv+uK*CcLyc=HEK+un$=TF{o689J-@_(BN~zL#E>W z%6Du^N=SESV{_y)M%9&rD$STYihDaZS5viHzfAr8)eXa0GSdE7Mi=;BWk znd|G#hqR`#FR2W@UA>DvH}$7~Lax6#v28x&(?mYE2<{R+E3(AdxW+tmj8eDkA@h*c z*}Fwp{1taB7LMN#!^h`4zIB8q)z8tNLOi@hW|duS{n)k0P_P_(=+K?Fq&eLyOSdIB zMbs?}d39$vF=xOB;(`nnaorh{5;9qHxf8cgDHTWg6;eUAL$6elvvNe*hASrGSc^AN z*jSlZF!Ct5g-B~QqF38*C*V;=rcK`uP9^+ay)u%F&!BW8MgYn*flJYpz>|HMrqkCK zMVT8;CB*#~6_?uTcHGj9Z=LDXfwzR432eU1Q zmI6;ZdvdkA|DHc_e<<_T>ZL#b!H-^j%%6Z;*j1u(O|aQ(`!YY!b{$`GZ}@}v&;0(e z9ACZ8H)?$2@^r?H?|jA&m72F9^7IY+nEA<7u6xo}0;0bNa>+6A~w+&58`lVN)KSSr*Xyz0^H_-1a5XzIXkuS{_&*ts(TkWGknC}<9CkmMWL*;9rgiA zyN%$`LP=48i%XZxV}0z|`JoG3&oXhb)e12n}I(0V{y|IM_Rv6mqK zEr5vZ0eW*JyalV{*3Qvm?!J0p_s;sXPbBrF2=F=597<)dRybN0C|YxS-_m8)IE(Zj zZ`I91>ssZ7;0xOatoKFjORc(X?aK@8)Akoc2Xznp=^)mre#fl;Yf%fkPrF6=3tIe3 zx@eSzuM~oON@cou9Coio6ps7sz4pS|@S79K9o}zO&Bpw@CbA63m5KVUjWM(s!~TyRs8vh zP>B(`Dfw}!8EfiRaXSmCPf*d7gMm{O$&wEF?v~H z5MYX1dj0n2i6}9e4dtoV!N$SrVwf21O=F!Ai6F|hZb!2MLD4joi5n84ztV)E`1M_O zBP38JN$}QuQC{@IXrc#;swk~qVRlxm`pb=OimIqSv$eflFw}liQKvJ>84})!rsl9* zFdSq_ejB^=5&o5vKucHvL52(d(f2iP+mo_dwQl!%-CnJ3@9N=f-LY)hu*wZ@babk& z#wRUp4~}N;YVC)!Eid8uX-Bu(b0phwl)T$B@C*N=3)w7&LdPC(}(Mf5;vZV3tPlA7z z)T8yE$?>IXSx?^S7=WoF;QOerC0;iV->n<<{itt2>z*TzS|5$7-Iw8t=eiC*YJSwB zc3o7t+NW)uPxycuY=wF9;F=mbmF+yO@u#sG?Pyw$NV-WNWck(yXVjh(*^ZMMe-Z?3 zAgBWYng_bG{+`UK$NoNb@7Yh;$9pg4_>SW7`pXat&-%MFLy!G?)S=U#gdY!`-%dm3 z*z%x~>_+QxjX(ZL`(u727Z4uoQ@f96+Y#|T@yWimz`2b=&!1!c-eR$3dAN{#$AgI4 zdo0^Etoesk*D$r8^`Mc#5FyNO%@SnZX4#YIIDwq4J=7UR&Wt7Q=bN*JTlJ!N+J_(~ z7YQN21gI$(T7|eMiG(8y)`1{|i^f;0(4V^~5P{5>W!{*fh>A3Fb!N=fwTMV8TB0pX zxhlAcwsJSVP43n>U<|lOrtIEtk&=}~`}Q`)8Mb?O;9lCM8zS>ifIBbiTb2<(0wrOu zr6A8!k1#BlD=nm?yU2f;%e@Cmj3iN^!Kj){P6|p&?iXG&vav>XO&Aa?kVHd30fD%L zp$A9q_MbVHWzAQupeS>I0GNg_Ifz(2|2 z5rt+bR?-m})KRLQt|Hh|^aVl|!#EN`OiBSNjaUw;P2wgaWKBL}#&SkO9^D&N=p>A6 zS`cffyJN{alB~PPM|96^qQ8`oNB$vs=ZS^q&?{96@*YxCL2In&jghDeicuv3MMWF| zBb!E8)<9JQQY-04?R=Or6N{$gdm#E>_*ec0H|k0?3ybGAsyjECdiUWaAC2-gYW~Ko z=@b!62^~bBI&^9&u;H&){cWh)*fR(W*burl8IP|<xAnO-YmtaUVJYixLDcb~@ zFs&2+TmKuk_ZeG|`wT&bNOz$Gv83@I#D+}a@{$C%Ekc!~L|pq934S3KgkVLFm7GH4 z#bribcH;{W+5#XH3B1{_B|t@%^^P~xYGo~Om~r2GcCUB|5`oFbF_*?bS31FVH@pHYh9 zJ!UlJ7@*0FrmVb`DgPj~Xhu_HMBcDKG)RJ6IBY)=X5?&~nvq7-#4G=6(CC#gnQcSN zn2$mZgb>z4Kz{bdgi$ukONlgb)8Q!ut4*`VkkFbJ4_p3Y5Vn(%{u%`umfd%Ngk>x0 zAa0OSPp)3rWZb^POP6xZJ?~y!x^Q301$L<|d$qvc+|a>QuNrJ$xu6C65M<9G#K6Hm zSmy^desHz=Gyc#sKicM<=qfKTb$kA?+*j&>be2L+aeKm-Q;VZJ!)aB>JMaC)HT9*J zKYc@c>ATqjuWP~AbHVa0x3jct)9vw<HD33@;j?zYyKmu>&Taz zyHKr=D8nxYPaSb>+ig4ETZXCro~Jk!X{nVTd8pDwI2-DhwUfz?n}ABNhq)#{RG631uW;okLpJ@zd3A|37~Z{BRB zXySfhJf+B+#2DyN7E9Wrt<_0ezpxz;k_kADwVdVG_yE`<`T(~IcTGqSU4h4NRcPdhwemnD`dck{D-J0f{2ntazct5r^|xI zAcg6{ze{Zg*cj?M!Bhwe@JBZM6^o-(nMX-FNcSPHDJj#*n5gryDR{t<*sKBrFj6f4 z#6%^}=5bfZq*G)UTrjb5i0yaFVen!Vc3z?_@d*|!5ZOz6kV>v32jkM77vhV3T!m$d z^ta8cK!Kluo4p0>D2gz0Y3@ab_$-`T@D-w-q6e8S-`CM*0lA_SZ_R_o&)9oM2<4Cc z$niMofj8h5MM*z0J$@s{vrxJ~o;-J1at10z(!}&imlh(b82f3Ay{stuS(Yxf(KL__ zq}f~0&Twn0(*e;-kI<2rtr4??({i)Y>bLNlE-O0h7Z80`f5oVWKInlwWW7!Udw&M& z=>hPUoV=h{iogNA;24?vDEeuhi{D}6I2ZT@KdhY6`3!|P5}re(>eT3U`=AI=3sJ2I z@bCt(5vM^?^b7|9Fe7_qIVS`XfxD)wVz>-wf&-wjIdYx|Mv-Bq8>n~6coK$%GuG)h z0lp472S<+mf!gw7lmWw7H{Amo=lY7>BOk>a$F`|Q!qOBnVV@RqWngx?!Q_07!vsdZ zl^>I@fs~p_CML=eROoEdL_*^YVwX z)!o$bAr>0ZThswEPB!~V5SB!k;>m>k9tJ3vk=qoxy-jX3VRoOCI?3$=+(JR>qsc!b z6@Nx<#3rPfG`&Wdot(spWpLHDBv^Sda!pW=&rO*}ud*0yVp29(EsCT(0R@^^qq`^n z9FKaP851jn5+}^?V?l=~#IrQ*OZ&&r6oDP9D1Qvnak6j_I$~i~Fg?AC=W|WS`&VtW zwX3fBjeRH7eV3Q{_1a#owl}kHt#&|t^%{-^ktXXnD89Mx^`Y)SRt}$2ByIylpt2vmhIlSaYk_}9>+OXC(oNXDV zj^$eO;A8(FasG~9TpzgfvA7z3RQ?yNI&cZmGHu|}MlH@qIqFK*`jDmTRJ#u$(9~bD z$pmmL?g9c_jW5C2RqOYmy0L6&1lhS@_5HcW0fE@S(Wg>0aQ914yo##vi`BpHht zL0iS(MIUvqlF67N6H`g|z>7iu40&zFgVFB8jDCZ@AY^q$TkFo8oriIkD@ zCHg@|8p-5k0`|HiF3N;8bPvw`O87!Kd2r9Bq9~IbBRyh5PYu(fzBEh$=O-l>4#Uah z^qPE$G<4m-Flkzuii+-@j3sf1m`cn&LPfk6DlC-C46luxP@}Af^tW;P__+MdM`>;RVik4*44Oy_Ty7X1Au=GUuf^UjaQpUcYzRxWeFxCKE$#dE|2xlf?wvE%_TPSbXXg3- z&YXGXoadZ5=gb6ul#nn~!~dS1@#7s+zpQBk!U+E_Ssq+1o`n=znWk&Ht4^zTmAmSr z%A@L|%cJXK%46!?`m~F^d@;nc@w>(#>0^vQTEn5 zT93a8OdnF7;vEBPsIa0m?-+g9%P#i1d@L!$DP2POIIPgU47VpH|$3Y$S}x;|53vxv>quUFV?V%O_w3Y$YLO`ofVBJ1xi%5^>j9hVyNCt!-3r@7Y`5O5uohy?`d)?IMQpEr zx5DlrcDH`7!di*ltG6kvomiXRp|Jaib?Emi>;Yo;>kleyAF&7Z{R(@C*na(Cg*`&- zVf|5sJx1(N{c(kL5_?=fps+6xJD@+IuqTN`TNB z>4z0|gxF#I8HIhB*faXG3hN^Ftlq7#=ZJOd&nxUGvFG&{6!s#q7xb4Dc8u6ddXK`s zLaaxBSz%u#_Okvpg&imMHT@NZ^%8qUKcTR%6FZ^5s<3YmdsTl;Vc#V7n*O@Ys9gJq zzpkIOxqgb+N&O9ly-Dm1{Vj!ki`ZNG+X{P!*xUNI74{#*zO8>pVeb__@f6!t!`pXfhT*lA)v)jv?!&xn1X2Nm{nVnO{E z3i~CoU+BM5*coEK($CtA$~8p%tp018>;FmY*ZOZ1_Fu$)qyJW6{ltE&f2gqE5&KXd zP}n(QgZg=eT_AQ|zo@WF#4hT;SJ+3yey@M5us;y{SpTEK{+rkzbxUEFiCOv;gxmc$!0*E|qCeW;m3YQkel|mP5H-Dzl)>b|`65 znGI!*Lzyd;IZ);~lys@ggEHTtERf24C>aiAp;R)UEOID|rLqXh5{I%>Doda&b12KD zvJA=!hq6*CE1=xqP;QjU4Nz`!C^t*xCMdT!lv|~83zSv1B5N;Gs;i)8*($7Tsbt|e z$D!m(B?roChq6X0tD&rQD0xy@3uT={Sud4!P&PP}e5q`JQs7VurBVQ;$f4XOl_Ds` z4y8mY#ZXEeN|{tjp=@+0o20T4%4UbMMJk)2lslBIQYnXWyF=L~mD{1*;ZQ21atD;{ z4#gvt?NBOhMb=)GR4bwCwhGHDl^r-%#?P>51T83j$|xEZjiUv{PZ>+YqS3UV_$ec5 zSTv><6hCEL4U0zBg5sx)u3^#mT2TCyF*Yn3VGD|%GRlTU<817A(KuWv z_$gy?STq{P{$czcapd@@%<&N@k2#dbrSce*PKRCbuJeq%&JieIb|}wE<;zgI97?xTx}ZGgP@b2{b5M>t zlozD(A{1q`4vWU?g5sx)*(!Xy&QAY5vXbdkXe#$r=7LDSuKZ)NdM{aM(+)hDx)1ka2l{cY$%b~n2m2W|L z$Dw>%D(^t~4~Oy{sr(0&cOA-mQh683cOA<2r1D)T-*+fKkjnR={LrENNGd;s@?(ec z6RG?d%KHxGr&4(z%4vu4fmBXI`I)WA+6zkcXHb7`tFV3{m7nAImk#AuQu!s6GY;jf zR6z@=THWvavsVBhjLLW z7oc2nD8HA=B`6;`l#iwI5tKhTls`)4zoA$T<+4<+K)LErK9S0&Q2yjl{zoc*g7RmF z@)xOGgYs8fk+t_Xss0t}|Jo|7|C7r9;`r~15~XWW`Fm%S?s6zmq<}(+b|^7YiH72K zD6vwBgQCtDqI8}yfI?Ac3{m7MnX~N1yMTB z3!?NfP{umW87I#f3uU}RxlStMp-gZn6Qwc%$|Q#}St^sDOmQfwQke>6nypanMd{O} zIt}U!TZJ`KDl>4bj{c)`9{oq@v!SFp&Y2_6nF~c7<45T{#s`I>j`5>(9^->T$#CSh zQ0A5aWsyT!ER{u2)G>aP&SU&2eHoPHj&oMXb5=r8NAgiRkL08Do1on6IOi65&dpG6 zbttQ(ax0Wfhms|gOeon7B}XdRP;wp0YN@P&qK?(0bRMgNLQ%%*vi8=?^VUIC$Lmo# zkJmw=sN?l0oyY5-P>LL0+$M7?hEn2CN~KZ)rOcshl*%S3>Zm+Q=TUi-UJhle& zIa{G@b0~L6WgC70VN^f-JcBjm(5sGOmviAH^HK8`yDy)E1cHwxpL)jyhW+>_iJ4)vf zHYgNzgdL^x2s=u@2g<#U+*)OBZBW`BN{3Y1q1@+C?w85~P?T{rEFMEg>HBf~kmH<( zxRGx>Ttarnr6>mZD zQ^(O!avTi`MIA>+$#FC&6m=XOCCAaAP`>8yfXC3FP}DJWlpI5YLQ&SlVbQ8M_OIgi z4M%RT$@}>xl-C_fpHyCla?+vDdbptYz2Q*al;^wwNuEvdW>MIA#&={$yx(*Fa> zckFXsaLF^i1O9H9OZFaEWb7>2_rM~fX32g478x%~_Cv5Ah4aJlkB_)taFt(2Z^Fm( z`)}`P@Sljc*wq@2-ha+jJ^^pYM~Zjjr2SOB2_FXaw0B52xAKXU{sW|+gsV-)ZwgZU z>^==gsrXIBFK%ZJzx!6VFH0l*t~|W=PHKS?&Oc1cr#rj}N^fR(r$il-7TfWl8HYSy!ZWm8?&s^(k3@5*AihqxAnF z`_EGS3t88s^;fd~CawP^>;I$`!ntRqpMQrEt!t!2W0V`MM@i)(QeB|qXg!)z#mH1{ zvSOtbM^?Pd`@hH*;7Vj?zdS#L*mLb8$3} zj?!^7pN^r4u zlI53H6IlUi?ILTpwDyqIEUgx@_Dbt6vhJ4FJ!IW0tyZ$ygr(1><94ZZkaeH5?kDR3 zX+22RK56YI>mg}9Ox7d9(r3}}qf&W{tjC2V+iB->++GjJ{TJl^3Auk#?!PGaPf@#m z`bZpNbKXB`sRu>u;E6KBJ1^4jr^~oH#F5tgrP+t0HSH1-YH99Jd{$w8MOo?U6`|qs zXyLMotX$RFU|Wk9sT!;exoNIYoTtw4_`UwLsL;^7H3fymx!IW|xuLi!Uwxxd=S_L5|_6GL0sq%2St`?=frrMx#iPw8r#$Yg0W9 zdTO?>5wfA7T0-&J&8AUTCrs2p%c!ua+=Gz;B@~}&;)V=QgV8C>*tOnD)4SWyVug`u zdMZU0al$A;j_|bzMoTg)YHqERsIxf6BX1a%lxccE!CdyG~(F7?zKb%r(^Jhs$Z7pM*xt-^>~?`df8z;i7D z){uNpou?VUdZSg?aV17W4NOBzgcXCLz@@}t^ac+KVuVOiYE*hfF=$D`%5U~Gh=S=7 zR{R>T&#V?Tq2VLamSJl>4b_3V)ODVEoIFw_$Ze`Ie2pl!)={EP!=_qrT~JW@HD1$K z>-8GiXe6A8_KMI#fS`1ATp%^G(q|ggMgu~rq`9t6RI=Y_9fMQdh1E5mOCp@W9Y_qaU73ym7a#(C`ppm*VKDWLmLNaNWQP3 z+K1kz!RUqEGXLLlE7H0Q4deBYdxKG588C`)+!9;rG0x6q*0o=CN?=@0kw!m8>74=ka^a^vvzi4fW9}_4e#1&=KD$F4z0R%MJ z?+DwSv`OL`MK!(#FM0-5X%))k&r#G|-w}ys{i{N;dqhKz=ifc()HqTg$5 z@>3sI5~!4>(IrwOWd}^t+fdaUspr!IU;nS1-r+MNskNy{J(By}I-}Mb5sHK`ydY3t zi9UI?&#dlMtEb5)`tIov$L1UUDlb}BgVz`E zr^9^ACAnj!w;m?VsDkNx`B$(*e=qH$!(~r z^ZC)BGwT{_&=N%xLj%@kLL8Rm+mo7OdUoTPVYCX8m{sSis!h%1Czs#o5-|=!}sbfDNdgwZRdL2d3+ACtn@Vbjdx(S%y1@kl!QDF4@65OO|ioScg6(> zO`9zo$ud27P zE?ndDPzXcU)OkcFCLXlg0sdhOkZrVzbg|)waXQi#H_BjWr0494|LFG)X%o{f32vhL(ZU6T}tN(o%g`g%qLqwT6j@2Sx>5WUd!o zqcF9FLe26u`s#ftyDa8ols13N|XSh!q?$5NL_oE$z^=_3Un zMm}L&SBto|1eqAVXzJ&5d4{$KNv1?vl{j0D!l?f7+-j;pTrL)u6r#g9Lt6qqP4Mso zEmDAfyUR_@G~UTa!m(S7onkn**1N}pLaq;&ouL rO9w7+M#^;ad!(7LV&X+*jvO zpkYAa>NQS-&^SF{XfNO}dLsrPt6oI1&w0#XECoe8sOkgthV~Ltr9{S{rFdY3i@-<~ z+GmHlIfix&csTs=H5sV|xEI675NJF~rykLg*B~B7jt+E{(Bq40Jk|d6Mvu`7Gc>fs z6EHpgnkIAu{X!pQkK*iV)q2F4>oMA@N!@@8!3@O~dv_v!jqO4kql}g!r=gLwij?u| zJQx^?r+&XkJ5mn2>~!cYzJhcy=ydCi?Ku3LG{{Q`G-TLl;Cb3F%(3}iZxcon`JQHs z!qrDF)&P|un$m7Fg!0+)%rzS6gz(5sZL9AHWw?4FL;I@8L*BC;6TQCz{`{iAEuMim zVy#hKgUs;|tM)V@j9PyUI)P}BY3u?^E%W0sXs6Kr6Dblm_;x#BKVXu2MyBaSll}|v z#D8cbsdkGnw7(+BBzkgTD2xy(!ov?!Dthe8CvA~PGa-{^AD^R(&hP(_V$?>Ao%y^H zZ=JV_p1nyzN!;i)`8mpu?oL(q|I_wEur=;FfS4Sk3F4=&G zV53m}g^wukzazyYajD&g-c&<<$?8B|9b4>}g*2h~l16Wpfgak>Ft5aL1S3n2nVKbA zyT@!cTAhL{PYg;l7tTn`^j3Q@uIJWLkpU2jUE{+91~bTrTI4nB0a}F`UnVAQ;^_~Vy;(CSUF7$hnc5d_?!W&Wn{J|P=!gpm zmsdx_DU+h_+Z<{y831eUNM6qyTF6dl?U}`^a?w6tp}YV${7YGxFAFE z@WNc3>LXPERF0U>8LMEljLyfTPZVJ4TC5}Zs_U8?@ziRCWONBVDWYS{>^F9yY=(+V z*JGsVLkEnB@pgcgWKr@Zz5pVYS|IXojqn1Wsqik!0F!wG6CC0AI{=tZBip#lU0y#; z_+hn-$!my=BTx=S9^@h%-!8nj2-_2JRx384 z*e%``OlysIU_=%?BK>$aCiLJGrX@c7H5M+B0fLy6R-@3#)3WC3nt*Ba3VCRDjStVe zdXc`L(&yGSQ&4F5^>sPfHewvuixHIJZa` z@%f$_4<3j(SD2z{m}04-A6Cm)xio8-ukr1~l(a|~aruEdQEx^o zETdPTA?s@bx@R|rk%l%(Bw2&FY(hS*!ivGn8$JJMQEu3XH4d{T(1a_KRbuG6c&xUj zi0T+4P7vb^V>=EJv*9%X^?}zaQn^b#wHQ;JrZX~Yd>EvRMGi&Sgxon|fQn@W0kCNq zwh1?jQB^kL-{=xp8!vDU!rY&lSsO3|#&(d1jc) zTXJW>V|tAuU{RONSb+0kc>swr!sEMtxsGCwDlp;`rwuFe1mIXh>RJy5W)nbCK4*x7 zXWDjXp&?l)*IIu7)uBy63Q){?%npt1IBXe#Ro#GE^u3_QJ3>mLMKD#aTebu|(s z(J0t)uQkwC?Zgd7=c89`6h~NZYN+;mjMFe$hG3c4@4;}O#?WeE4@U>(*jDYy^k zCJUDW;(qHJF=iLz676B|QR{0AG~!eqxRlTWilIHKoMF!!jaI?MT+n03ZkA!aBCgmQ zk(3j(6A>Ee4>OGnK}Yiy?aahNl+g$&3ulLk8`F0t#;Rgp+L%@xGAtquLfI^p# z6jVhJFh#5}ZVrI26Z5|CCAX87?F$HJtMO>k?ekiNHr26Op|12q^3Z-R?&u5>k1Po^ zHDS_KVpKP55~C=@U~dS*XXhDf4DGk#q<-Oah2%DB!G~B7eyg*shQzk0ms?+``-1={F%Tu!x?LD;= zugXy07K99JT88J~dDY;Pyi1^jBD^dRRgK}ZjEObDLfSF8^_aF-;WbpMcy4-U!`^A68AU=IRcKO6!_XZQ0lDVa zDwOf1NbPS#Gv$R5Poo`+{{wwwW*r_=7}Dd+aA~y)Vf<&88zVgpUeH1R+!aC$vHk*W zhTZen+44h1y{&6Vntv4+RC}Rj=c42;2UO{e7+6b&$MVcR8%*i*vp`mm{FJCYqm#=g~ZhBuE8m0`2Ftp?#4Y_F{ zAT%Vh9vw<>G-S+sc{Lwvbz&hOFJfuIJ~Z6+z*A>FtYINxO4#3$-0Z@FoXp}a?0Lod z+%205i*s7;n0@OF_&;8lz_*6#w7XznLSXv6O?=Ea4S4JAH{6`MZSTT)3p4I!d)n>S zZ@V>Z_Et}NOJ;g`M*7Oz(<`>kRkgGsA$L{d@ahWkL zq|~E#xk|LOn1WDj1#Z_{wfYv3Qz)jsvdSNdHGNGL3m1oCo3LEqbY^(M>6C@1hcC3Ev9@y+3AIpSUS>gNMM+svQDJduZcb>l(?(pD6_kqN%~-q~ zUu;kTFG2yMpcgKo%2>2~vCx-hWSCz^j%hLG3GB>Q#pWAg^BOjM!lI>AQOlN*8cr$B z`b^42OEW@448L#1ilr+n@YM#cwrJ@>RAbA+j3p~Vag9wNOP5GtQCf6pXgKx4rS_RC zLveLj#A~R)sg%WHTU#zsIFsc{7K_OphktZCbSJpiB`AwHx)u0Ifru|o5Rc2)TDFj_ zMZBZpS+Q&>6~sSgN@estlmVpgilU+nmz&=g#qtxed0&Xprbweuq03WP63O_49|*}! zxtTu{^haXzP>yy{y8r=|G&gqj<@EQ1m z$F9jG=C_cMU1dwmw_%&_2xzBT7>YwHt5~)u!#oWoE!O<0NJXdGsg~KE;s(!~YLlmD0qHPt65o&P~tM{(I_k!0s85}_vP(v+bs ziKDckwtq5cS15jxAGWh}#dkh)n)yqB|Iaz%QlTOBo~jB{jAcW^#39}v*BbsBHVnLT z#vBR-Ao4fQiVa>1XeO5bHS6w)D@hkMjgMCFl?J}ON*5n>iBve1Qmrd8pCfU7 zVcv@LV!PTGwhR^56kSTXdc4R^vQ$Z;bR)|YtR647&s?D-Sz(Tfc!y8Ts5#@&l$Vvi zV(HS*a8ayP@)IgddHln7vg@_WYIouO%{K>=FTo!DehBbv20n3_{J@L zMavLz`zz8*^48!Zk+pfNODoppm4srljOwK=!|{?{$HxTe=r=PQ*20$In`~{7LtE^y zoVhG>oQEead|I+HZG@RDsvI{756#zcY>p6M2z`fF;Ww&7L;N+yj;4y8hCdWj3Fo+Z zoDxZ?-F;i6=l+?W;ER?nqsBxI48Fh52NDZ+>#=UKg73rw}=Z}b4|PE znsv=J@0u(9nrp!|*A3TPH(qnybj@}1HP^>n(OY+L=3a?3kxbr zGFRtTWR_&-iNpF(q!Prq+)Ke|-5`PI<{q2}+SMzIV)RsIEgBO1m!P@`hZVkgF-=GD0q2$kh;X z`9m%<Ow9(7xz)TjKkzzASY_L?SnOGs!OsscmCKfq06U&&Ii6u(S#4@60 zVs%h6v81P&6U7G0d76oZI?YTKo2gyjIEUGjijBPZ$N=kh^y2&}FC^>^h@@p%Noc$sH;usw65b@{_7i)ET?= zawv}8quDh^PLMlx;LxS*LLztQT2ww%T#@qOm?7`%f}!h2O2^DVDVPhyhTIlDu{&Q6 z#TH>TRWue3V>^N=w5hD9q9{kYLE9VhFp?vOw(XZ4VxmX_B4FNYXKy2wM_#;pKZ)-i zVxL~cgsKtCiR6^s!0gf?2goV%mI{jshWw#&qH9xS*|kHlW0wRJopNjl0c1!zF z&TsI@vz)H)o1E^IKDj?d`}2p|SwDG*_kC|moB8?PCplg3)3hIafcfC--{N$qx|sJd zzi{|C+xKxk7hims?fYN;RQNa8`#9SVzDD~CN7&!~p8S%Dnd^@pGphru~H{xx5D-HzC+eu>hbKk^l_ z&p*TUc;V1n#0MXEne`XgzRhyCWr8R+0hAL!toWuSv2 zcA%Ymq=Am`o?Gfbd$_#0hZty=<7%b;nKmDnb4vP~9ln+&=(SxN1(P}*cAx5>h3lZDV0 z4$iP04ocZr+GJyB3kRJH#x@xoZL+Z1<-Sb@ZJWILHrZ&}!oejQZ<`FBcA36i25(z9 ze;KT8GFaMVCAZ1KZI}1g7S2xwL%Y0An+(1-S?Fytc-mwzw8_eAlaE z&kT_5u{vGccFi6jlh5Q8joNKDXb4Qx2YYfcS6q`ECnx7c+KCZNLZ*VYOe48udTpxD==id0L zc?V81y<%gC&6aQ;=lVEM2EV`^#o%EMw810XkOueh{@fcJuoqw9z&rmmH-w8Xa^Ma2 zo-l70IqTt^2OpRIpX3lZ_ZBzt!BBwWUq~GE$^ZeJjiyM4MI`|AX-HWer)4y;;-tck0^5D@Pvm%`7#kaX1 zy!bY^-@zB&GPj1sOC6l!;Qf48=T32=bA8g+E_sE{2h8o^lLlWnX>NmIdLraaSq*P- zpE!89i;Lp%aJX@apYPzlckuX^Lqp1H@vWNp$`oC}O(MIS#by;YJkxs0yj6f~vB?pe zEU~#oY%;}WwbiGyCQob%#Abuo+$J`KVzXXsio~W^Y)ZtY44Z(MPk-=q zXb3*z-0c;AYZzW|p_#GW3DMGm-5F39VD|{r1yE-|-GV(mrhbY#18V)$LEI@WPV;6l zqvy`5kGcpxevy{0LUF5&204AFi&Ot-J4C%FIYe%dLv$f>gL)nEh3Fnvk>nYjO65S_+WwFi)2kerv zYmL01OOY#7Qd9y|aO5cYuo4&IKAUcmo*3joq}FI*k#FNLJ!0tiy+ffPk}Qe9Hzi3-7otUkQjM^IC_ zef$h}iyuAA1Fesr<_G@A&u~Za(L?+||EQb0$3J|L`Nz-jK-hL#KJTL!WI8!N{^)T||M4?Cfcy9% z>Gv~lhKAzXCVb$>>q)%oMx{y-Km|%gO9fA5L zxa0wOO8(I;_`)gQeKr(dEZ&GIeHs-D#Ur_6HxarVg(qE;va`#JG8VqE?;X6-E(+mO zTE9MSFGo^}?;qmbVIFG<4>{p;ytM6JjqfWAxe9pZB})8jUU@si%W-F3p%czNz&l=! zJG+l9UX?rZ6|&A8;~g*YoxLw0JPP$N{03QPc)jp!8*7~P8D8)^bDUD1LobDlWzX1Eh<^i#}Pi!6%n}@OCJbTPe0qz%@ zN5tlFv3U?1&ZNWqLiqU1^X8L6d_rs<6PquJ%~RNL+WqE%@bQ@!La{lHW!}$JEmb#F zyj`JoO;hYs*ioafqnjdvVvhohLf}r}1%>A>akN`(C{(ED5zPZbYOh(z5qGnYZxx%H z#O4;UStT~vVnfeydU|IGb2T<}Zyy}wC;n%i>A4~iJ;dqhPS14v&Zw;9FDn$!-8t7<3Ai7v(?=k#eBB|4cVQML;c|S}onPC_Zxg-KXtWO$6TK zfPAl;9C`0sTu{p*>0d!n)%kYeZ(SVE33AZB6Y`B*r79x_>B8g(IY`b#S}4B>qmF?p zkLowl0N;I--8d{t^N83`g^Mc1M^tdfQyYGeQsGjmP=SzNRt6TIWz=T}d&b(DAAygSUhFYxXl?_T8Hv%GtXcVEI^DFo{H z&umbF|1|U|*6sMu5%)`>E#jZYu{4BTBTR~Pig_`Zr3-!V5RZ5%{)i<)x1PqdY_FKgu)N{-eBP(|?rbTm5n-*Dv4b z^dIHfQ2)^f9py?zYL_9E92F$B8Y*>a98}=cRH-znaH%w@tx!!+8Pd32G?P#1$@-cp zp8VWOskCW$C)!Q8T>E5s^zn$ezmI3j{ql`TzkCDLf09RB{e3(k?(dWL*~jzA{ytd_ zeJ^pj_3=oszfYE@Ts`RTll3S^cKv-kYwYji`DcG0kJ$SAUgmsG@`^xzAJ2sQ`*;be zzmJyy`{f&^{*xWJBXQ5~pP=1O?_=w2-ks##YrK1lc0c6@`cFF;p5oo>thMs4op=0d z^!+zE$s4?Tg|$c6;z$4cud?+u-thq9{o|Z+Kkpu7t&goo)5h_g9+xF^Tt@P78M()0 z@d&A zZxT9nOt*?7@oZ=P2{Y0){p@+})eeaiMPftUo#^B!ZLkL)D8^@-K79U&Z@JuS@yU;Y zuZi&|xZ(+J&KH9_H~l$^nI?|$uOGB{YVo1h>SF$dcycRK!x z3KRdZ5KA?{Z15#-y-yF+d2cb_f`tET{sq%D z&5CxpTo<&GUuq@4(PsWu%lNI97Sz(Lcr9_vm8jUnSSwLWnto=)goC%APMj0oUmiPr zMO15IXG~|w!I@p|uBKzT-Fr``F8biQ#ivsie~`4~D*m)J%9^N6m~>hj*_j>GCY~KP z;b6|;A*Z#Z&gnsIYX6kkr?s&MM+LRnR&1U-J?c!%*h47?&BNoZXkqrpBp+CMaOA;~ zCvLIa0$8z{d;Fo9UC~`7hZk6JgyJ>#*hB7vRb7h@kFbUi8mgjUgobPGlmp&_*kcjL8r{_toG{NCOKhAY-FRZxY3_vm-p-tZGlGdztO>*>I@ly) zlO1ddu~f}H4&~F-RT>;W$C^rPnwswNbYe3!_t5=IJ4bgm1&2+vW)hpFxswj0bT%C< z4JJ>st|vBIb0_W(be0}m5*(3gr4gIsxW-&!^BgRl*n9_DKrBOZCm)!3Fy^2h968-u zNNkbg8jFc7ag@taV#^$CIk6R*d-(pc&Lsy&2NNb+D~a9UU^f!GNi75GW@5KEu6rx7 zRW3&%WV(o=<5Y_wn<)l+?qU0LJ7*k>2@aohC6_4%ernOKVTx{6%^{B|x>S{}XNtk0 z8a(+-F?e*3M68cK*c2Q!!zyHoE>}%^8&eD<)le&8icVWiTgG%F=)9h?-X(pbgXy%Jgm~MCG;9*(`sx+4>rn)n&m+1~rJ4~-sGpzw# zdcxb6^UjRmvNe{$bf+_iTBdcNN&~BB+5oDQua9XX=;#Aw2bXk>4yMeq?qq6$D*pPJ z;(4ml0MlKdb9-`oXY|Dc=iO}WX1d3jwwY-QsC{qNUZ!_}Ds^!;(|bUbySSI>swjsK znNb|Spi0-1%@qID0JXEoWs3h|fP2EB+^!kNVuBOXtu;*7f{H#=@5%{|OS_WCbe%Kb z^-MQ_&g}Lc%jumFoVDD_XIcQ7-sA1f>6;Opf2&o<6#s0bJGDCnPlnRq)J4{9Op8H9 zU!2o5BRJ-ItAr{3TLJ1_lrhDBCxCk7(Z`yC)0bGAm~IBO{k66*EeD<76X-4NTM}Hb z%G$~l|J49`WW;po!RzK)+nD0N7~mdtAot*mu9)EHnN|hU?Vw7jdze;&PCDf6$~iV8 zIC+6p#Z(8Kd??UWdTdE>N`~cSx&u`4teR;J=#1{NV@rBR2WKv`45m9B`Ch4IivLcR z8maY68$gvZ^D%7%Rjzg?Q~bBN+!GI#buBqIIyh;*bFIBh?{cQSo9R8yeD7ttDq3^T=~>#F z(&rA&y~WC;hrE>qdVP=kn76kqIQvE`n`sWHc$l~k27)7JTDeSDgDO6(VY(Jn)LZVs zrNP9hRvy!JprT!*9CHUJ%(vDv-2f`e!F#YQm^A%LKGOnF@n{Wnd4uEUS%plCoH^Xa zv=~$j9K6TMf~kwG5~ih~A|A?)kdv|W^HA9JE-liwTt<)iSLEoz)#UR@R#vy#5BO zo@s+4-zz?*_y=Isa=4Qz#`;{6Jyeo@qL-UM(F(hBdzJ<#FSG(ocY&fEADY>n5*&TK zwVUZ4Q22W&rJMY1X4(RZC;EYzhf;#Wr&xQL-UW)m(t(si?%=S=*4<3+0Y&U|r}R+l z+{<)T4E5E>d1f#n)yj+!{qN;0P_(!1r9ISIvYF<9B2wWowU%6_t3efi*DzfRiW=$; z^iU1uFFM7+vnM4uae%X9;%5Aj236Wy3DZ(gyN0fmG2IA? z5guCd%wWoFYZKGWph^qa!nE8;w=%sQ6eFf^nQdcw2dL5tE0}I~=HOvk=}cS2R0mZ` z$IEmFsM2#)Gpzx|7##PJ8yqpsGMMgk(psi>JJYUVx)xNa<21I&71zg#}v>eoK0oGQgw}UF>u#M>*ph~-_V7lFz zgNJD)s8TvrOm$GD)V)l1fGXus&9nwoiE4xCPEh5JYnj%8D*o0pZE#W_(?(|wcQVD| zpz4{QX_J!%nC=2qo(#L0?s2AVX4(R3w}2~qncfAe+{N8Y?*Uc%)O(q(igS3DNeft) zvp|&`vYF<9DzTo+bhR_>8m4POl_zf=({;|Y>zQtF(tM@`&KwGv;-AV_YyLK-#h^-G zQo^*ve-6y@@ zE(@+$Z&fkX9r;>braM6GmSt5ltpQc)!eF`+RJmF$(>hS4Wz{ona8e)BMrRIpGR3;K zTAO~RO`uBa4lvyXs+7ZSrh7mYf18=MfX?no=?R?h2Gee`_A6=zO{vEIj9&hjp-Q^oRDE{WqP|a?KY-&fQs7O*u610cAizi6#q2|gh9IS zF>|fmO!t6_*jd)IEI4VA)y%ZTN%u0n3sgk)t`ob0X}4H+Grb2?j51?;VuRN$u(H#= zaI8NtT?Z;+XZ4}g!9>j8m~H?SF*&AtOmNg}E1zirsB*PJrbVElFIm>TESNIKx{YZu zs8YuzOiP_Plrh~1YTui+iRorgtk#`aeR6ehezvuRX*sBJwXIBV2Nf-AR`;yn=rn5^ z(>t7LE0}Hv#Y#@kjuShAvv0OMOe;aLBG9w(#Kz$DH(6Cobx^EKpICNsSuj28ikImQ zP^EmUnbv?RrDHJN397~~(>hS4=Ifa@IMe!=Hi9apb0<^0HWX`OCuW_T6`Yr8`I$C> zDy0)(x(gI5IVWOI#s=qL{fy}zP%*2Ubz)X<#!9Q1X^S)MUZ!_B>D^54angI4uEL8g z1s#X%WIgf9jeXEkoRzQc(RP+v$N*PHhgw= zI_k7KIQtfHRDEK1aQ3ZNZ=-X?`@7M2`L^`n&JV_?eWK;LT~Svz4^5gMby}N(w_#P? z<3GVa3>$TMhBiI@Y>f9zOyX5{^mL(K9XfPWRO^V#_Owy&4zej=dTkJ4wECJTT-F{IkYUmy@(fsa=Vf&z{ys zcUJveTVTa*bY(=HjTsh9SZqa$;}2to2NM@tZgG5>#&)~+8CD#b=qM6|ID{+|Ps0Aa z`|7P>Wa6!1!u~yn#-B#}O(24ohDg4|8bKD`7jp7sGV!jE#8G77En&j`yY@9$DP-aW z;c(&6ShDbH5Y`53JXv@tNZJIl@H!CILTeIPco7I|wl#$;yaFU`Dp}LWy5aJ4vSzSl z%_M7wzSg7nnPBZHJ2>B-W$HZW?#9LPA1;$B?m{ASPRIacX}&3=UNNN#Ou7| z11mb`Sc}QTo4n+!THL5uYbn{{tr@@&fLs?5@vccG*}_D;%}EL-V;!7r@g4_uiB-$C zc!L8w$Es&ryt_#{FuU_Q%f~>xwn@6G4I3GYS2lDJ@d6`UQJ3?g1iQK}YFJV%f-5Dp zd(!Dq3(k(5f_?IWv!kbW-ze;)affD~9x?rF(!_oDT&<;ZPHSWE^0K6BMwh=k?cg0B zjGOm~w$X)m*k;t!If$sF1L;;Yjy|L#H;y=(YOFYMj8ID4-)s#L#}r64)-Z8QQB-3k zh+`2y`)jNb;uz7BbYP;DERGR6;&_xeM&O9!6mg8G5yxZ2F=9p>j~B;?7;!v79MkLL z8f%g`7SXbQvo%E=BUVNo$hW47V?>I$?sRcHLrWTeHevMHgcPw&o+$o5eB{~0iJ$ZT zgwa=P57kgBzdB1Bv#2$G-}HS|`)B`LTlnjg zmA17Kg_Ss>)!pj9FVPxWK4vCLG~uc?At~017S?6F+C`*HKsX+(;rN79r`C$bLRo6KkZ3_+}{nMAHb zd}Pn0GfLk2$*sfom3B_Y2NKx_nmgxz jkTCTVt$YlgFMH-`Q)hIo52j|E*2W#2{!1-`KB)PBdmcNB literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/legacy.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/legacy.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..01e17645813e866c14ffa3ba9efbdbbaf0c30025 GIT binary patch literal 2469 zcmZ`*O>7fK6rT0&+H1#2AR&K{pn)KWAwO+t0HLZtLn3~pP?3bHK`7dI$Mz=s&Jafo_pXb(h!N*sCsQK@M!^w_GETB$uG1gX&|2&A?LZb9V4sc+U^QYCaG@4Pqf z&3kXY_vVd%udIwA7`G1mk!sKo`b#jus45dLCxN(y3}i?avZZ0k4h@HFd04iUVMP+_ zAxpKx!(pIhL$M;ZHmv!yYDMkXa7;o`WW7oI7**Z13Pm&!x+kdj~$e)PJ_Ozo(aLLSe*Xl<)E~Zq71BC~2MIQA8{r&@9Lwp!%R3z1PZi2696gs}1PQnbie! z5d|K$&Ywze_854f6|8!@l^Mhuwy%zfv~L-~xo6~}{7JkhkL})~0IVY!>Wl*NJs@x1 zE;qvC#}T4p_Zy_JJ2Iof?rK8=jlJ9V7vNs_KEj|?UsR0fcpKQ;3EFtOHdR3*R;WY> zVv>xCoX}L*{y=jQ(dZ^uRK%e{Qz@#&uo1r_51>S)egTpc!!VK=of?GUQYB)Wu#9W? zlCy-7B*QF2FmaNuVLEB-rhGnaP7();qQ+3vAn3&B87`GJ9wpdzJ!a+csGbysZFD4E zJF7Eu)FPd}>E6JexCD60v@C4vESbSQtmXf3{)O5%APuMvRmY9oeGfhE^ z^KK5jQg=+?Ky=Tv^6fb3f*Y%Zi{U17HgOo74NRw8>N`y3D1b(>>A(t{3uK*GM4YvB z#{n0xj483*N!{v<`CCqAb*kGwqM}Wl6q&(;fP4vKGLeH65D^=h)@{=%<5=GIrk(;O z2K-iorwBOn0V?M>$foDJ_Fet&2Ry=AObRKbBCiIa0Q*GFgxKNW-YMTkp-q&LM_7j= zPHdS4IKE+e6xtgFlxfwpecBkW@o#yX10R?x&VB^b7{ford^gf+Lg`2Eq1!fNg3HpN>`}_Iq8rDNnWzEx?#+wK4>{`g&-n&xM z_EMFrW9vwU4KbwE%(vY+|2T4Rt+sKY@ykbX6Ssa|bu&yC3 zIyojZHbB(mnz~TURxT557)$B0}y(p z5|Z_-SxUbqx&~AZ^OH@*8vrHYx)ztkzXCO7xjOSxaUW6W{fHif&nxXcxN$j)yieZ- zR=oD!75J>nk|aGv9V@8g32OQW?RkRQ;k-vrypTJk@M=} eFQ^O2yWI<8%Z-WU>cdO1!^`TC4HfqJe*Xo_IE%Re literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/md.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/md.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..cf677a6970fd096c81b759127818300f08d66acc GIT binary patch literal 24483 zcmch9dvIIVncuy5kN^P^API_Z@q%yYK~kb@Nw!3Z5-FRqUN+@CSUU)W3sR8qpzj4N zlS^e4*Xb&b6Vq)HGtKOTnPwY0PC80wJ5hJjj<%24WOloQ%SVV{w6o0AZB~D5hccDj zMl+rE_nrFy2!N!WCVNSobMCq4`JL~4-*>+Ao%0vvaXoY*!NTZ7nLIkD|5widB4wZzu>M69_2(^T|$4f-v4a@s14abf7SUztypPduC#MV%k z*cRF&wuidKme8JYo7nM&)yT7Vs?*o~fJ*T38GA%Z`h$Vs)eyZ*gc9fC6B8lHXUbU4 zh2=!Xc5yNhj>iI#2h=d1In#9d;`#FzFZf3X&kXwqM^BH8_)kAO_`=}n%fl~>W~`SH z8qT!5cwyx9#i3#U=B2z~aC$E9e-jSsBWW|C^{TtEtyQlg47UnHRHq=IW&pJB;pb) zOrDBfiAOS}_>j072(ui?*rXJWC0HxUCDi?DNb66gJQ+hf#E@S?BSJxKte9ufUN$Zu z@GckP#(0q%Gl~3|Su}+#qB&$8w}_TEEMq0=yGZXPcrO+0VkvxE$c|KH<0jFTg9nZ& ztFJ6mbv`7^L!m?{h?ZZ9BqzeL>8UaS&nZAn2wag9QXrTRf{}nM3rRU73V^E+MJ_>P z+0cJsl4X>8SjNFfMEew%Wa0daqnCxyYl%=y6ax5#qmz+P6k{k%gkKHCP*UP*T-35= z?7^!5VlWYsG9^+dk(6RVZPqd<5JJ&>-Kb!&NU%t9Ugv%M^hs7dwVgU7MZ>X>5FXd+ zF$xystMOz+6t0AXar7n}Q(H~h-s3aX7vhN#y@?@lSd!w>d%$ct6d9Lxqb8Z!BM6U= z^(LZ|y_4a|{fU5tNw9xfj!VJ(E)z zTPPBq2m>9b8w&@ZNB`J?sy2wO-r^qFI9F@R=H0*>cj03I<%cSp)wMaLsCLWAbTV}5e@=m!i{huc$GyZFt)-C9io^^ za###WC=Mmj~#Du<{r-cg)76~aFBtj-kBoJ%Vt&Z5ff=*Kd zig%j69HI2ukU4XP>^+mzf=?HG&Wz3Pj|HM3zduvv_ebMmGD2ae-~UQ75YfJr`u$=& zh-foNP{wj49*;hW>-&29j21shAwB%6D@_9IK za1Tvpt8Kl^Vr`voTj$^{v~Q5N?zCE4=Ys1Tym@hhyp0ML&y`fHoA5fD{E)?(5%G{B z*s!wli<9gZP+<BD{5AbsjxX}l<rUBb#0i=};9- zNsxmCTC6@fb+#s4g|RGs4Qq{C|C;qhv(|T`rTMM#SuRM_!7~pCAU?Zv0-kh|9Lgir zkaHXk34bEEd_tH7ZMtJe^dQ72h;BQW$$stef$Gg^IUk@)tz>GR^45T?yiLcihJLRyKCLe zb@UK^d)Ldk%7#_9S8;on+->toe82CZT%PXxo|bw0l4s9CNb&TqQ4y_+?$-H$;_g~; zx30DCX9W~;I06sDwjKnqApFSmW{P{yq|y|hnL$zoF@s&+^k;lvx^qX+F>XxwEH|jI zQ>S}NTJW;zo^IYvy=d5`7q?h1Fc0A8KO%n}3|``=KpTtA6T}+Woy|LqVDa*%f$ul@ z8D2DBe+lK9X82Jop+`BwJp$`5^+JBx&z_|dfE2?+LOh0LJ`_2i2uV|FL7IY zi2uVQ{ts`X-E3`HFJt`QWxnpR3QHU za#v{xg+nI+x*Ld0V(C>tXbE?=X{pXrlho22o+>CVVTqPss=&8N0w4;MKjIMy!4mvrRO6TmmPBu#(zOhNV{I!U}ppZ&xprB9Gk&~*}brkl4MB;qZvA&E?r zuLy7Xz)?TvTXwXw>D;!6DgKJ$?EaavZQaZ{JJ|RY7d8cy_mMD8dJ!oLaBDvzr+07J zY)02Vhcr53>GYiFyN+1J8#c}wR-FEVo&(O?(sSg_f3~685142`8k~u7_WbMw>#t6w zYYZxFOgAjY3d!^~kRbB>Ix3Kf1>}RoGHdsn*#l&*n$p4GumDEROCM9S8j z?mm9cv)DbHaAFJD7mFrn<;zs?~Z?r>PWF8$eYA@iQKMTKw*4YUPVr72R)^n^?0kWSxZQL^K|2g8`WC+H$gZzlh?+wF+k%P`{1}BI_`SaxvnXQ23Wru3)#|i2D3VqWt1HIpN*Gdn4vkY~@7!ESOOHY0vbku5q7S>8 zXmd)V6tJx^d;%dP1-NvD90uQlE;2&6s}R6M0sjTE$uuIjxcfy3-iotrv)KJJ4eZ5f z3~{@B;-@iKAFnntfBYH2t1WCEqjYoBzB1N6wqV_!!Vy4-BmE{4E7n06=HhvY&Shm$ ziKv?NG8_;y266`c{C+Vhvsk}~ZhaHEWlE7tw=}VmtvI@{*jT{gWbZ;^wRcFtziTLE z8`^62JB}$X@DU>65$SEKvjAHKCC!KzN4`s-W zaEN|FTcb&qi>{}>^V%KzQrA-{+f#*9mC%Xx=X0QpA4kT-{53`qWoXamzm^~p&Ym2) z{ANyU(R_w3Ckc&=q2tj@;<)#8b@v6fw}^NH22L8WVOwQEG_8d>goj;Vk; z7u}tVny$DzKX5h8eR|2&_5I^_J*!7Ym7}9edoM4#E*B(BtC}Kh31qNnw31Maq33T% zSfmIFC?FP$5q9hZF2)xB6!~>Z;cZnZg}xBz@MS4QaVGtb$tFk8Qk_jQR4K|PckVSY z&3n}A?U-h#f?=*y+O_CNQa{d*Se+dq$Of1%;>rUSKw8}J} zR+;A0>m^QWFELGc#5Cb;G?}e?G?j_PI;1hpp)AuJ(wHVy5ya1U^!fd}W16lkHoZXm z?AvXU{D!y;bB9(iNu4+6@=Lb0pUX81Ha=+Au3#Q8rdgNQa)U|!6yVcQ|1g;1vaMHV zl4;t)fNEDA?*b-i%-U8Iu@jTjSfMnGw1t$7@xX#6>OAkSD96@aUEIf-gkRw+1ZhHRx!^RTVSN)65{yR`#9a(Yq z|8}-7iiyj*PL9B-!atwZGY(gi4=2Xa{+0kmVgvxCbFzc|>hx~Mj-@`Wi*vNkAmcU* zKa{(*YHO#3A8kvp#ovQE>evNxa=9AA9&PWT#n5VHF;2B`@+alMM5s`|RR|5@bbp6R zWRm4`mxreo9i7=-hkgZP8c>{vbN3q#LS>7!9_Q{&*?M+hd!+M~$oUCXb{-C~J+t-5 zI#z)NI|ViBP60e(d+;`T%us;oI|aS!MnSK(QnXon)!M22e`KDAc?h}mlcBIAeiHlV zJFgC3M;r5X7Ta0}kUfAwj5k{cuzbc^gS{C9STrM_LD1MYgOtLmK-=j$lff2i#=-Xf zRoMgV3^D$(??QuA#S zO8r-oFokQyY+PfL1|DS#G1#Pmjl~%{vjF&P zG1g39WJl3jpUq*~1}kSJJ-wxsK~JJmZ(Vk!%JO&<)mwb=Bx<(!Qp#qGMgPjgl_F4- zd1f(DtEbEQhImw)ASEe#vh9+c2@(+UVrO~j&x^0-@#Rn0NH*!Yvc54AhA@+8(Z3ci zEh{pyG6g+#)}JwHmKkn6ZpI{9*#7u!lvxBHkOPZz(RzIdNUK867>}GWE~+mOO9(`I ztE5jBZ?&50T8G}EtgpjbdMeSS$HEwwM9d;%He~2d^coqKG%;Avbjy1T_>xYFJq$OD z-T^W;2AO|~`V6Y7rv)@_B=+iW#aomh;eebC(~RXE(_8fx?xvMei>8|;GghfO2RE#G|Fy9zyH3K2Ni-v6iTs*%&=!z}J{XEM=emJ?rPRz39m5{n2ojWG417K52|s9@lh$Ga57y@Xz6| zG`B@3tgMbf2iLEcmi2YKWBB7sJfVNd&U2|b4_9c9r3g+IQe)b2roW(x=Ykl&o8}vw zuUxZ+y8M7B)5L%NRrgD8|EHA`5B@KnP0}e5WoqyS33AWDW|t(?mw~_}QEq28_jUeV zp6A}$WkJ%}FV3HQ zdgbIN(-l>3N4^wctBs~bXVW|n6Q>nt(|vFI{N?Yy^zE0Hya#WeXUbadqSHJ7vf@0r z;`FY$kaE%GO;^{hR_{})_buF1s*l}GELNXR_Z^xYTK4RRrGHJ^{Gsn2`}VOrCZ(-^ z*>fme*YqvtH=Oe?D0SVdb$v=*-*Vl-`*n>#$~&GPHT|$@xp82rZs1;rQuoZ7r*74= zZ_%^w4v)^Sc=qY#rct$NQB?__SnN9SsDwjXhrWC6+vonc<1T;q_|n0VCE@HpSS_tp zzo=`PQe^I+Py;W1zT-B?t?nTWYv3=3qzQ8MP--^4PX`N~0zdx$>Y-#_1 z;vN7Bzz~y2J?PbO*N&!231?m)>V8b)N23Azac3KmJU5XzEmdNar> zBe{lHx>=B8Z`nl>EsG3chJB;C#vXN9MAYUCqdq>H#7GLG1B{xm8BbI~B@k@x6Im$G zDiV92ZYVlknF8Vx&DTLB!hEf*XUmOtwmR{q+nB|)kZuuZHPV!BY$CtT&{L?Z8Ki5c z<%ys!7Yw+dNCS!zUUtw^xQmM?qDeEj1hk472q4ygAu7=xW8?Zk8DdldP6`ZYyBN$E zq!`Q?dCgzlk*<9!n30-dj9_*ci8M7uqvB|slNKFbGKU;cItT7~7duarDGtMb#nruV zXm#&N1^=#-Dci{%G!$=8o5}e#e)45Fq@i$H_pUb;+08!9TRTZJPd@1=$lo|?vROOU zJ=%`;pr)K3%qr&xHRU{26U5JWELv!TtjltaG|(xuGIsh5=Qu-FoIoovjxn%z(TsO? z3JvLS{%p)1Dnlv%Ehe+k8KYAzg`5aQ!FVTNNpF&sW(XJusM$8nxu92$UNA~J<@GDtvYd~iky zX%m7N56MC-o)E@yCJ0Bi=jhN0Xd93>IpZ<3c_e8AO%tP1Uvpl#o+Xwg!6Ey zS?K!U?iae)={AJk=u!{RY`3`}Fd#CW2SVz@-i&Etm|^}Rp z%7|hRHIxxo31dmxz%19d*njIMsMZE-rY?HK$^DP4u@hfTzhF9~ypc`KP0MQZ?;QkGT+Ti30 zqpER#eNiBg7#gP`P<5LSjOHp7XfMSTKuU>HF0De43~7iK4A%eB#v{4AQq=i2>+(sp5?y z;#vm?hu7@_ZZiL)55KMz9eFdn!oe;L2rkb{Jwh+RY*riHbmwlxf3#o!LE&24< zFN52JR6{771xKBRWt2Y%VZ|)IAtD+L5r;`wgYl7 z9QMa!k*R{2OV~CoYynn-1H4Y?bQDR!0UBB$=h@c|Jwfu^zBP5fX;1pdQF`ywwa{z5 zY#*vQ?PCXjRQc|=p?==7tvauG8*SZ*SB!y56R+4#p|G{Z*G&^NXM7U6tQoWP_2Qx> zM9(3#;}5p@YGxX%6Wd!zQ618Llu$%B$G){NeN&k+0gV9iIE@!0plO$~_)C~>2*6Cc zL@bOwY}4CVQf%ILVYQMxkoSldtp>aPLA0UKi&EAO zqdb&Wk(V5=pZ^L-?%*9}yeOF;-ynpnuV<`<-=d@2BWdm23nSp^Tpo66sR66+J zB(gCH=(4)|Tdr!jXw;-XA?GYP|B;*@lS3w2(tjZ5-;+b@D|SwY=$ER(g4F_}kDE*n z=wc1X>#${r(S;wutI61Px@n`B#X-|nw2s8Ae@=An^KfWAE3DRbE4AHAwR;w8&o1|# zxMyGLJ$u`k_6YOCDUa{A{TGnLaE|i0Qh)p&zgR!W^iPKr_o2I{MfX!_PxGn=I-`yy zPuIc|ileLth(N6WW>AL(fcu;My=w|(`giwgc-7gM&2 zSsA+M(W4)sFo_(R$@23EkP5_M?OAUqq5|o*?jZpf9tptkHZJp}*6#HxP5*I8(|=sj zC18v7k|qID9Un^qw&&o2rQtT1tRdK z8Dl6CRGLd>5jpoGZKpc$Zq*<|c>F6G1xqe?8?^26E?4Z}l71Y3mxy~8F7!JQJH0i~bSd^{)V6Y@#Tg@4 z-CX?=oq|^Hm)K-fVYFzHwTLlogz_I_tJ3&T>?p%FN)O%W!l0_8^w1AeF+C_XR{BeF z+Tau_H$VmG60Snb?IF(lbL#H_WCZ8UXA&PcTIY{0JN6gVYN!@l#T5vjLV3S^1%hVV zh6_#TIFoAIMmPvfLOZ-n_2#*=g$>&_xJgv;ZwMZ=lblNx^)s3szSWKar6YSrvjb-| z8`rXDk0r|KD}F|vW=2u{!eRPwgdC#U`R6%*N^#`;H)`2=1c<0YtFU2X`T`t+Qmww* zRjY3tiL$7w1$abR;jKFvO)asuk>wjaO{aj6O46zP2b=|M$NB7N;5C^p!@5Z|e~z3M zIGeB^Db@M-bu@}b`t!I1;TAsy+BRccwm`chPzhS$lWGtgPqa{sjQh}x7?uVxY8pEU z(JX~kPXS>ab>u%{iN1A@1;V!9VakAI;}G{UHgI7AVM!P>iQ4p*a|UJ+sF8oGlINyO z7W73deU;RiaBr5}w9Z&%(@cqE7j0V0U~jDU2F4L)e4&292!OTP&c1nyq{VH9v?n5? zUuuZuQ_FNBJ<5ayG$%Sxwijv0Zx)?exlX-Kv0RHO*JF^UNXb*YuVOmDbmp6GTT9%C z3oojd+2N)t7}>MCs03`svx~PvxHnLULw_y_nyNkL$}qaP$}mktS)cjz+2=AP&$2uHrX9GN3>)VprwYP(VvD#_LIA!d60ZByD& zzFgU-IQr5~55lQRFSfXTUR}3t$7kFqW3O8`nVn_WF1D9ppV(fPYQ(AXe%vs_ih76? z^-9yew5@!$MX_PYwcuCUkD)C;FRi6`>YEF#E^VE^dZ$(Y*fx#%LSx_|%P{>9#lh=KLEy&|`~GyvDwuh{z2&c;;BVOR#QIqK$6%-)5Y_go6g zly(rr932a_cP=VE?93G@7z-*!!NMF?+8MVPqH7vOtU+H%V)H4KsRS_#N0U)p^9a%7 zYCIxltYYX&aw13!Tz^P!!o-We2XTOSp~rLE9b+IXtDuS5SRwySvx&oD0WBx&s2s4P zf(=ftC7VvNAQT|oO>D=Jg%xg*L9LQmwA?I>mEqmWbW~=s1n(xX^k!+!jZL^HmGUO2 z#q60eY_hV}UoXSLoY{QYZrW!oAblOEt!$>O*gZ`%Hoa9Kfi*}&;zZt)O#?%pE|5sO zXlGhB+l+mtbQ&5Fyc2P={;e}v>r1ih4USr)!$_}}Y{$SfUP6BUt0f89Gew7y)-mI_X4qzCo0;(FVUWzyZ*m}$C2%Wd_-}H5SfWD)=SYnu=Zs-J zD7si*j_g=6HoL`2(bd4AOvC1m=XT6jg?!awWkEg~8Ax6?oja8<jP2VV^U0nS}!+?5=sCu2DdKqW{JFaYg z30I~P*qzm9S&wiTJFePH!zQja)6^|ow$rO_?9x?-9PTff`=N8O6|gl3httB%i9Fvxi(vQ_ z2_B!W#CUCrKR#Wpk4cvL9hd$cb;vbJ<SlyG6Xd^pB->ect~I_v|dO-~6A zh%EXl*d>aY3O{y5uCTjiL$cp5{UN?d-y&z899m(q{Z!lunT$##Bf=UkJ|PjY%GmvW zmJ|61-Y|m0{evR*;{FF^`=8|elHzSqQB9b!>u`}XC7KPKE3c0k?~agB4@p_WFgF-b{TkjF>8xJ#@%amn-Ed3v(J4gflXN>hfs^Z$8Tx}at+J=_e&iuXE zw6`Q(+ww)*m%&&OzBRJW!Gp0_^{&*e&ZR249-(UQtut%Q!mW#IrRB5c*JsiPzyN(| zyKDB)o4eEddhoKg4`*R~A2hY3guXk66yflXYwo`Kr_D=E&wR)^th*Fj-EI5q6X`nd zhn&goyZvn1RjZy-pRZqW?M=Ju-YtKpd@j7=?q0Vd0r-1))$HJ#BXb?8*3(ME>3gp% zHawd~-1yup?_66d7w+%&0!#0Fdf9toY4?fS7uQ_7Q?30=uKu69Yu0N~<--QfR(`*- zA=TKsRM~gCWX)FbcG(xp?mH{jO?>%*^nn*reWR&SF%?Rr#3U~4dX@L4y$4f5KUz@! z#3QTKUiPShbGlNlmL=Rqc93o(b5^~5_KRn~nw)o~`cB@fzSo-S8&36}N$q}S+4*et zYk8_?;I4c(nd%u%?bp7pRW*Ld@%H1lPi50peYfe`P4g8CSMF5(sP2b#cgj+`pI&hu zTQ?&e?C6}8vn})9B^*ezwEz0Uf5Ky6Wa0zwRt!IBx!^NR{L639^V1V&eETx?ak{G$ zx0%Wkp?;>6@B|Y@Mdy;l)Fi!7b_skB=t=@|A`nZc*9#J=Gs!e##Vx)l#6b~EBSDN+ zVj6fCg+Qk?qf%1QsFtNfL~`s&Yw4BfyLxL%1BK`i0Go~M-ZXa6kMvoJyGBluoHxk% z9yz2ZV{6Bpbte;K*=mzeI&Zc4*mg|4?{z>j1JCi#$*180lsx~}T+3f`&40sr|G{G6 zO)xa%P5)3<1&7<@{EEHqY2jNRa&R6E@%#95e5&i{BaQ-(KEv1X7x`4nfkzw#9z9vZ z5A&(IJ&!mFJnC!Zhxkjr$*QEcECFa}$3` zjiA7zff1g+#HV)mJ>ppC(WgxHd>g9`{=*}j$uWCqnTHTO%=7LvY*mBryu5B^FHao5 z8~ma6vSzh^h#N$BHdHX!Ue;)HUsjx~JV} zV;3Efny6>m!}1joZ?ty0Hd;4b7xhj1c+SE-&56!8IkECRi#CJldIqZktlES%NG_>S zYMQY$qtWyZsY=?xa?Px*3vJzI+m^)|zvn|5%+F^lf{}1gkrZSd%3Sc_kpsxt#f9j+ z;;+bBM`Mdw+juynW}Qb>Ne-%UIcs|+te|{iUJb`%!ARCVwJ;x%vi4Iklt1LPalKO~ zP6VDh`gGvr#IvU+CdVfH)@)@s7z+ks!KjpN3@d@?LPQM*PA{rbK#GOpVmLONbuYxi z$Vve@7@L(sG)d#B(KDNE*odo~#7*-eH*Klp#2(QiSw*X46K#@Rv`Y@rAy$Y^sY0^R zCd|0R$~W!PPO(a=6ssl2j7@aCX`8MpD7#UvmRzW{&sfBoH*N3fADeaqW&_NF7Bza_ zi@Znd6>IVKvR>4puAo;fgVyQaw}`%iIv=ZZphtZHwBCd^6hLvT_-1~b#)7&=R!3iM zDu6aID6L{g0d$86Z7zT|o6wd5Xp0GLEr7N%s1@V36+qht9f!oXI%iC(Sv-~1gUSGgsAi3=d7Jxdmph*sFM zWJO7*Z;o5CqeMNmIvYv`_W`d#$!^rmQpsVIMEZg`1J=@M)=|q!qqO8eiSasuEOLI! z>C0GQmNBA}=;*aSF}O_3rqay=$3H&D_@NfRYIC}}~W&{hcA^YbTntI_%0 z^Wpg+H7L(Y>QF+7%L#Er-W>^_-aWsl&c$Q9LmJiuVsSYNzL=2Y-BBEGL>Zo6#HIwo zv9KBlBpM2_YuEr+(qCj$yoNGW`cG*zP#nGlL^2dNRHHsMwa- ze~`WJ?HU5ul^NVk#jbmM_G{I%GH<+%6s@eA5b>7_tG2nA!YxGJ2M zgmCQT_*qF5;xXaXWg!?7@f!9!vsGaw98=UF$XxbeoifcdItC@$@4%{^`=F}_c?hGi9#nJ2(q6>bZC=F_(~9oX4pfG!${6^ zcRkI?-fy(s@eJRsYt48MZg>x;y@&7CHzn=wc&>TY>j%EseM5Xdb~CpA(Bqp{OKshz z)#j_oaW;2Nu8Q;4UtYeroU*@LbG;_*8NTg#VRiq;zOnSau@4qDo_-;XzkM&PIbV=> z;cG>hMBIj9(%*j?Ome8yo;`2ys)}+qA{#X z7Lh-TJ(oL{tfJ-YIC9OHQJH?_N24AmIdhbgY!q-6c~W&7ODd0v#yV85(eCUo>t8Rk z^78vZGsoAtGj+xo`8Rr$f$H=9U+lT|4Zk(FC{_(Lip#D?;|dYu?=$X~Q>=_6^(^+1NFj#-DF=%{6+@InUkm)ct1Y zYu!oltNyoR-%xJsfB)dkgI`}xH||e+M%J7oTNh3jA6xiq$UrdT&fs18obM~#gmMc- zKU4I|_ZIp0^v#2aWrE9pgKZ7;E(kRt6)4@0_H1V~)bF6;IFf?Rffz+X5b(CXXoGa< z)6{wx3HGJhbNSH4Lu=JL@3wX%)pwS!Eo+y>t-1Bqr!S0OdL{!bS-QBi=4{=%M|7}k zk0y~J_l>&%Xo%2JR`t`Rq;E~Z%03v+L$<%o;bDcd2Y@5 z+}69#M2)@oC(bd@fnl~kHqiHGi>=$d`df! zeUxKp+KpV+5uBfwVxoKig(3;Zg%1Xd(G$&uBM%o=eV#g=KvF2}toGj8|A#|&>)JBj z;~UXKUKonwg& zqCd&qHkP29A@+TdmOyQ20xaY%_+XV2q8|;6Y&l^7X8s&V>~r6kmvl!kiSD z7tYN|F+q`na%hgKA!rLnpE`bUWJIe8tNn@)f#Hc{5k(mLJZka+2Y4r)ZPv~N5shyg z13(uOvhH9+i3iwZ0zoCqFJ$@o5^=z5oMk|_h?U$xrPajSl`kQIx>v>Z^j&b@t#7@0 zeC7DtCmwLN%7KgH7e+6o*LD}z zv-=mD zg8W>$33!;$=E&Ryn1mRTq{ zFM>3d`6XWD$zru)xm0NbbQy>ovhXZ-4(ej!j)~G=V0t#NRRXe-c&thc4T)pU#}y?^ zBC%-(0opD=kqpNK-7o} zNl%rc^Xj4?y$tdQ&j|g-xB7*7IX*ARsMBl#kkq3Rs0zf>`MA)3D#p;gKmTEw?rLC! zfR|rWO|!gI$hMj7B+*!O6vp=y72Oo-3xs!ZJG#M~|aD&8}`^_df=)grhUSrI;j~gYpBsQ>73wN$}5b4Em5PiGvJ%O>{XI zjzn~vF~8cSqf1vFU9$F|5(0WO*kgMR_jUTy4jeGPfucc~l zd%9B5)x~t*lNjoruPyoP%AqyaPLda1zxaCcrL?Cr)tUD6tT}tOvN@upPa(Z9rVsgr zB;Qh|FFyugqOORzvDa}W3Aj?g_ItLQ1o00xi6@cSmW265A|kXXeMIJ*GLhakDYu~s zLo1nVDl+MzTV{O-z!H{ZD)(PQoz9ZjHh%f_jIWWd+)v(68@jT!kmy<@=9gtZBA>ub zBU-*`&Fe8YZId60==~v$L$0)#7@iHQ3TVVG(>=g;ymUcXH<)$^HWtG8xRPioI*_8e z-^I8Jq4Rm}pFH(frmjw}OsBfj4ZSyBy5rfq=G?m#PyQd4CDYmAeu&{E)9!CsL9IDU z!-SvcD8CA${`W9U(MrCw@}*QL-QZu{duJOZ{ZnE*5r|-$_h$VmU2WMTPa#5Qg=SWB@d(0?qGI-}R@G-apiV!j?-cP!EF3akEvrc9n0 zLf|@Bvkt8sTK5R4z1wjZGLW*#f5awVo{#*ht33Q9S7@;@7FHnpfyqGOB8ibbd4(Br zpvOk4Re|}sz^!4y7}k(w&X6CiOI9dJxa8k5wU-9cTQ>!EsxJsDt`8$8a;mYz{w3B=M`Gy z@70a&v3<{3F*@SnvjSm4#Pfdsx$q!I9m zyC##FDyIqQ5(Q$Twtnqyg%x9Fy?lL|Er$zY+;E%`v{1szu5m?j#Zp7 zSpz@6^Y@;yg$J8`M#Die z%Sf^?d14Ban2!WQl9(SRTcN|iSNgCv%{1@OrYiRWqGJO)mqL8VIy6KtaiM6yzePvo zb4Zwd#O2+n7Sh$iTJ^w<@r}XJ^x)_RFWeqHp6MC9Fn-6?dAGYSrGEXX{w!4pkn2pI@iF2K*%3=FJM*Yer9Xx_&EV4I4%}$NOk3y7ql9WMhoOYC4Mk)F zw0hy>XGak)#q0tLq;eUCEi^*-l0v>>KnL>Y?l+EnSeS(NUqJ2=xSzz+Mp&OK~fwTs8beAUcLCzB5hw$QA7L7fR4^mkJL1ljfA?yd?15Ero!p}Z>)cnJm# zy~fVuEe(b2Gl;oSv$oUmctozkX!1iyfHbGiKt+{7l$<j!@ zWODb@M3oCrb>8H1Uhbjc`<^EIfqS)$IXm7^3R^pJ6_j&wEjx3Sl&gXjI#*3O7gyhx zb5pK{Yw1dLUu)l_-noY>?7ze(kK{Odr_@dM&ehf12MCB4!SKora*mpug|{C_^*-S6 z+O!&goWo{sOZqlBymBty{yd-T-b9n<`AtWqy*t;aH|$7uQ_l{wX9wm?gI3wwQ#~o= zy8i)(tX_>=Zin8p=gJiI>@j=x=sf{T)t9fb+jl4Tr>xf=eZV2B_e2isr*Agfducj& z=~c+(4(Q+Oy|O@q8db>Y-?O6E$O8^9y%%!WWNl|2PO@GPo3nh_oaKQOdX;P%>t(aI zUpWP%thsFDa8}xYZONYGYw4C@>e^*G!Iaa!MT_5?ttsSFl9Ko%#$3nZ zF*O*D;d(k3R_DmhDK8dzqO{-w$VIrqv^!1IuSBvN3DF{Z8E#49su9HV!H*)liBUe36VzE9k~QTg5Ss-&WL`Kp5hy zX#LxktCnB0+tG57dxX1W{{!neo~;5_=HJ3VrS}z!p~L3GZChsItm5C$O(A6eSMERI zyG5V`A|N)L!fmJUbEf^i;cemH;&<5IcC_$W8~J;RPQr$+>?FRAOp!!TCJ0U@k&$|o zJWI?w0DaOtoh4p1#XUnDly?{Chy`LI^oz2i!iiT;4m=2=mU4keFXL*zRJUXyZSW*# z<5W`i+4BYuvGUedStJO755`%drfO9~yQ8MRX#2tbym^#X~CY-f@J z>^JNF9i5b4LBeDo7i6EWjoqmhbc9OPr+s~EuD-j~4SL007-XkXBkMl@h4D;F$2&vU zh8}Phch?mMx+D*5v_6t%Rp_7VT*nvQ~!j zMxI|Rw$(TrFcgA7K+JEEG-JkoWN2q( zC(Co5u^?g(DAL#HRT%ST)<&mnUDJo2>IYvdg>5EvNovpWs_9?UeizteuL9m2P} z^@=^?+p*#6N&9+k*fs_ZrUwqL`wreZ^=DuF?ic@Z{O>;ZSD#yd{5b^XY}EIq>!H2h zsUQ4NeM_zaU7;LRx-Yvgx;LC{X(t#fqT287(1Xy{cOcr`kU{9CFJhiV^o)6a2AS`f_qDs*FCYVJDh-YBj-`A&pB9nH<{QFP&Bx&Fo3w3(S|5G@XMxVg zq7I<_+4UT0ff@{N(P5TIhrU;agFT9aZdbH&JE4bN;)828PNU;e-`IL zE&Ujbeir9m^!jVFbz_n6ICDin===hc+_JX$pgN}+aHcRuwjmgSkRL-(z{~mH{3)6Z zhZ$&^&?;}u$-0c65YaeU7k)DcMz6&*giPTWT})CTj3D)^$o*1PsCKd6T~T}Xu-{z~ zyU|KTzqDe%!ZNgMj{RcFQ~{PMFeb?)T0bXBgr!=k5+y=mtyGN?VKsXebq7zi{0At@ z?^Cj$651a5Ta++^R+-I^S5fPCY4S1a{b@V0uTXEMKN&YIy)~kE2vv#Jt;c67lYS!U z=gNPp3K4j~^`|0&~}6RBX@enV@%9roESed+3)qN0CBlsD#3qOwffwNho&moLobQ914vzy@O$ZU5LK+rG`6V3DoP@9p@zX3H5un1}% zT@lngv?6FB+UXS-w~QbNC~?7(2hcKNAfWXn4N(;NuT_&nVe+PqF8}KTmq|9*!o4A$ zi-H+J@3?LuTfFlgnEL7Ft=g_4*^qW5-XdzDVLP zd*mX|f-`hl#VkKs1I+iYW`Sgvd{dXL67R8&hFdp-;$vOvyNsLJg)ujR(%) zE`)};g{uwgbth?qG!x5R7M=0p%8RS@w}N*(Pp&ziWDA<~*Oc6J+QmhvrQLGu;<`jd zqC)vHCB#=`!c=W;-=$p1J@!q4Q8GZ2xP=U?)s`Lh-S=v0b9TIOWWLtqzLlX|1(lp! z>&~Qd&7Z5JQWYokq{gl-=BlaW;(U!cH|1)$`W;E@%A+|CmAquuuBBWZ=WWROC|A$b zH|H8C*T^+t#Fc2SiAp=Trq<17%I#-nQ@6beW>qCMmVD(JEUPH$=1=5u9lU*%Px?N> z-8jl?#7|3^^tWbf4NC*y&{*>f$`K0ByV2#xZGu zNf2z8t7)fPNV3ilWE;r!s`is2xHZBNMKeMWp~|E-YiJaorg59$P@DS&;%#LDM2JTE6?*k=6Zk3wfvZC{0DA)gBwqCNn6mPF?{k#?H0F4c=UeY{l;)0DxVok*N^;^#B3;{czJ^Q@HRO-yygzje@}v9% Jj#9RV{{!T$0#N_} literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/utils.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/utils.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..6826c9b7b57b460e38d3cfd955088c55304dbd20 GIT binary patch literal 14336 zcmd6NYj7Odbzb+p-*^t*kH(9@fF#Hz2tIa6P(xtI#S#w^09U(^>G5#70Sq_~xO+en z&_ITztq5DoSlGzUPQ0ozR8dr5c4Hy&AI6XJx>6}iw#wDRfeP3b6~hTr34eJAtV=R~ z#Q9Fo6CjC|luB6*%(fk zFg(MvL1rSIvJmqq71l+HwVi@&IxCzVxl5cIZ+v^ny3m@ zPgI9$CTdtl!w4p!=3~o8Y`U+!RjB1{Lfxc}x4)zNC^LYG`j^nvg3eJu*YFZLhfrIM zxfQ~zWuB3pj=>WRY0=nh{=*kM{S`MHqFQ98ZfX-P!*LDD1MFHKR z1L!IX=-LmUt16)DIDoFYfX;OQT}=U9=K*xJ1$2iGpsOpOJ3@5$9Tlpwa#$dd^*M=b zDEOx9fVvwC=#KGjo)eDqO~NaX>#Q6a_~v)?6DOz+zNMh8)?8a{1$A_*HQ0pW?DxX) zNliwc551$CILWu?zU#ny4}Xz&A*WNQLz}ge2L3QwJH;PSsqDG6a1^ws`7Y!hQ%lZ( z@;LI&7Ub0-?-k^|%AXL}ncJBKS&;DElUknoeG((=p?Y|B(!`%ai|5P?-^ZWE=+7Yk ztZ<%x6*RA*SLg6MkNjSw7qX*5U(s8h#rIlubmjaPP)qMT>*{|(Ee^X_rF0Rtcob&p9{%L{oCj(*L7Yw=#iutk-7DQh(A}YGUfD~0s zBeT&!B_xQlb zuu^$_cmOqdyrb^n%bqcB-^kF#fniU-(wHq6^Yo1j_q#{mPLp`Ac;5cv$Y?*l9KUo1 z&A&A;|nKp1s4|)xOQ#VO^HtOAD4S4vfFfT^@D6>B->kzU$+j z1)G}R=jk699CR-@)VKZtw`bHdHZZnOlr9|@?Ylm7Y0&dl=F{V5f}I#@mMf$^VsZsbUG3~Ml&S|QExaRh9J`m zf_Q8$8VE{Vv-650AbEX$KSY1d7ZrGsL%r0R^alV-OiHKKJ0H~^+N?dCs6D(kkgPqm zY)zRMvomg$O)Wc&(R^gfS{Z*$wjSEi;$_=f9siPS?by-dC1qf2b@4CD*3KOxy_y(X z{i;>A9^Nt2tA(*urN6Y&tBtW$$FIoN_8mLDIhWK*M5`{_ALDvyxXpA-YQ^kNMX#m+3 zsG{{xi;6Z7j=HpIDX?V81YXgT&`1&ukmES9QLP4wEOJ}OOsd$4ybk;%H^36}xT0yZ z;#i{M*t$7c@#@kWpIV(;MOCt?YP+&&v$8!=*}kStRvuaMJhnRSNh>|^lK0QVN0UWd z(%K~Jns!kMvxmXdw#wj}KnfXLxT2#(p*}OY)tAj-n5;wA&)l#x%&&nli<(8O`dJ6${47jS5jQAlw$X=(NB=y%Hxl(HEW)xX9#Wz#s4hIa)~E zq!i_`ao0&NiJQQ(e@mz7Zi#`t=y|FPBSvR z>bpeaq5fo;pION1Lh%F&yYZ9G11vG0S(uvo_}d>gEDb$wIe%D|SjDn9Vg+O}0z|Ik*S(xZe{O|f_wHSA$LHLNmz9LO)DU_VzGYKJc=`a#%| zVUaASSPziVJL%DypgV%TXdo>1poj!aIs@=BtpR0FwsK2W1?ff0dDn)Izv`@IJ~X#$ zzst7oUCA_7b-WWm3I*+R%?V4YUu5Ss(cDTd5Kc`@v&7D8VO%t1AYA%kg}pj{NwHp? z3;RhaVlm#=rkAM64;?ub5$DyJMXsusOY?$~Emw;2d1*PJuII#rl; zCyyIkn++!t4JX#mCL7Mnx{7V1MRsrrBezvl_PC9*+s-eIY#S?NW5ZTa`8I@R1X@+r z9e!R;a(tWprT8Z4(&iZa(;mP-9Skz~cb66QEOaJsxOJK#ZW_VOF@+rlL-m(nek4UR z7!hAZSHyEP;5}?HgDuj0=w>7+dQkW_5nKg;+IlHRR{P|`=M$~xU&fizm56L@duZ*K zJI{ThOLX?jy8Z*0L@TyXxC#UXVgy0Sdne>osNRXH(l04yPbdxK>(&*@lu6a8GG&-+dHnX6TOtFXs-J4iQC213{Kiq%!v~%0|*5 z%);q}yDgH|6N%&^z!I}qtq-kN<&Ib7 zUcjre?&<*?>_-Ei$3gHn$2X8?o-BXUYvDdS?9$MHgONLMnt{yC&I;mvR@EXB%}>UP z6l0`*>^!`;ePY0OGbo6p^J4f(Wa2SeYx$w2Ca z3e5<0Z}jR_i%h;Wz?c)s^$Nr@~9T0s}zOYZc ziPHD*+buMaFBoY>ya6t-tZV<38tE1Hxckb%BfW*q%Pkt|Bu4pr_=$c3|4egZcpaPG z>w_B_Im))raU@~bpLgL~9{aiH%dW2AY6LAV+4i{#$?5q=_ByaS}}H&Fb`xXW;D z3M~HT#1VAEm&6DfTCfj{jlhNW^mCU+Mu%Q9iptz5ya6c!k6PfplW>+qGH`!}U&hF# zH{&nR8EM&kXuYy_?7^?gomXVtl^4ySly9X@O$hPhEuNi-FN!@=uGoPD6`0ehj*t>8PEZnpA zf~x>mjQ5H2UFU)kzb`2DcIC)_Kvj|N{k5hX@V??oB(J8`{|@(eBH>kgwe zH*eXTo3^Hettn}1S)G$@M|QNx-L^U76$xA8jvg=g)Ls#<0!_+n&>K`PDJDty%{d|L z7Zj@`_(cD-cOeoM{5eTPqh|b6=85R$UKc(uvDs*hWXOjBzslw#I0gQ#CLhg-T2Qz8 zke?hykRtPjKxMYZ8fK;_o1ag44X^!Jm!-+3i`s$~wb`}9>u(`YgMAhP9|(oOS6kG@ zbTbs=+V^Dr${CW&eGhNojk$JoQIbCOnIUoC_hjoqYqgoci+<4%)5mmbPYf{w1zys@ zmzW`)i-1gJVZM&J_of<{F)e&i4XJqUMky@J%~8aKbC2~63>=MwgYz84tq@q}u%I|; zR`3TV0|L$14uma{Y^+yd|4XCQZY;dToti=`w;)ChPL)ufw6OQJ<0mhoAnnG^%p+TelnJ+1R5jr%t~ z^6oG?b6djZS{{xMZ57qaP2CTRy0l{N$8v;WDj@$BlswqCn% zO_k|41u-x=&jlpTmla)qf#gzlhz@o*k~$8WiMxsI8xM>NL^(RYQDc#6UA?5J6#ZOu z(tA3coKXz)_R6Vr+I>PXr{BFdamtfeIXN*KC4dc0FPr75)@w; ziY=oD#|ADRyErmL`fVz3TL^PmQRF?AHYao0+J3#ckD1G{o!T% zqr+z(98Da4eOdq5>Rb`Nb$!FyvgNEy)VzA~M@1c2 z;j6q{*||~N`BabclpQst${Cwe9guh*jqI7moO?s&lp-pKIk8w}n&Dn55`Uk-hXm#T zAca&zp%hk1(~-F#@0AexpDi5NAA+!f2Ic^=#2|<+b0=l%Nm+L??LQd(v+2mafxh)e z_jnFD@%k%#{dtj|7sYvSx~$2H)*_RSlFpF1+4mIKT+Dawu!D(dNVwDk4|`0T6|fj9 z*5v&VUOQvmR~=rT*Kc2C>EsIMOd{!0@#_E!I3poPj*CV(oYtm~PE^H&)z7tmd9mGP z5PyfLzd?Y6Ni~3C9bx|t05bSJ!q*9Wlfdr+>^uK3s{%^V9`Qe+6o?6ukY`lH^U&I} zRmMHEada5c^wh+d9FH7Ta`kJQ)fW@h7e6_jtiFXW-b3SGtQ-wCI=uXD@ebIL4^E z9G6bf;$&8h5M!&s^NKErYXso+AE9eFSf>LmNevLDBgfSB{3_3!NlAWRSp3f@IYIpH z1G27tX%k!sU>9x z)n~=f-z$dq&dIvU^un>`Ce-W0j)2q;&93+6i&xNh(1AjR=4Df|<}U!iYX%)XN6*8bj^@@ZZ^+gN;lf62 z(O9sTFiz##T{OY(hj!Ti#7x=mWBP;3$$y8*>W*PIumGFBXt;M)$KcJhfZjkin1`pb zwTs^dCVq{;I|N7M&RmrGb>plw}~WQebTP8 z9a>!qgaSc?$)oe)UxMNbm<%Za1S`N;AHTI>?A++;|Kv*>UDvjXN*@bb}yM80->PuSt zwrowS*AlivwD&dQGjgYzR=X3{L$dCWx*qqeI#OZu+dTq6b}R1&sV8w(I+w}k#Tasp z)KeOE;dd;=$9@6Vcd!u>xWFVAy%XWoQ}kIM4$*xgeo-zc_^=&2bG!`)=qjVTRCo6I z>qs0Av&!A^NgTywa7F|7SKR`t4bdU}BprC-FqPXgYZ)(y6^qe1gdTFTvnP^nhyR)X zO#A_8-=djr0|K|x#+b`DDvx5*g9{?&3tP6zjoMe%abu-dw)Lj;+H4p>J*nM$6K28H z)`8t+G!PP85*OpzI)b=W5F{m+dB@3x1dg~QY!j(Sv8Nqo)eQ+x`DqHWPtKM2@5m`s zgr9Rr4SVvUYbJR`S-1&0$gNOA2DDW6J$dCjlM80#Nn)C;V#%fu9qkNl2KGHMU7lh- zW5bM!F&LSe!X{oZ;|kIsaGY-;WD^}s^J^?B3ck?m@QQJirPxq#N!@bL-7#|>wZQ&m zh;S!{wjknP6Zj#3VxT7I*bHHNszxGK7wCdAn$}D=D6~&BBJH2a@=Mo&s1C2gxoK}m z*c;-}q`h_N(w5Hh^^xBmS@CS>Y96D^(UNeqBpq!_m$!7*OtaR<1&USbrl%A(!5lNi%=pt%tg?n#w8ShD;yv?B%#sPomQzSprH9f7eTH_?8Y{Hs zxvP7;hHARik2z!S)x?-RwcBDk(HzsOeb6JCWFy)|Tg>(%j~ZJoqX_F7#<}vx`kZfV zLGG7gX522IHr~v8+OWI%sFyuv5?_y5cqV4AVPdA+tmrOq!7vI~K`a8^{847 zFAntB5wn65zhGZs^9%c!Z<%ax7t4fM*xoEpzncwn(`Caa6p2XNUe&LDhhEjq5KZ6{ z9f5zs1BdWEDk1|b-Xrkm0Ini&i*Rzp#ZL(+1b$555rLl&_-_RMmcV}nz@0G?NxHsC zk|~6F#pa)j<{V|EB3*!U_9*U9siN!kPv2758HrpHb;;#H+7Oo&)&OeMEQwD*Jxh!4 z3V<4Ce_FwqD&^Ya>z+jI*{zZ)iX&AmySK_)R^4mt+8g&Ba{1|H&!=TopB6i}N-N*H zLh++2sP|HAL0eSXs_OU~|HiRAfLm+d>Wsta$|A*b}c72ospZ*$hBu5cpugdep=U*Dno^-3Z|?I%(%>g z2mhEp#kttqXJ!8jYXNkz0fvJ#u;b}H#f7w=_BY^v`r49#%(`Dn`)einAW`Oiv%1?; z%&L8kM1qn?s#Vd5f*LMW4AJ>n=yuUa^{Mho%0?tJB9dz>+5nWIbbN@yLuzYkBuO#R zbr?isqv_xV*?2Yls@}I#k5$BS`dSMusOWB@b&(^QP68(g^boi}z(Zhwz&L>k0$u_) z2}}|Q5C{>NB_I+|*A3|!kxpYjeSNsQ51hHqNkFbVuTa{&h%oP8aar~Gm{Rz{i z{x|-FsrXyw!X|U!e=?_ksxz{hpE3YX%NdPTF6-Q252rK^))4on7$mFw4kf!V<~*zygG(ExomTW4%nXhENn5+Az6KE&HwEi2>i0e8CqaZYYOVrqfTv# zL9(jbp(H~G>}hcUos~U8eMCZiM3SKc_OxyforjH=5ut}&EhkD3npFdOeq zF_f;J#10l|hL+H$r3LjG*lTROk7%#4tNlcKEl+!GFD=WSTE&=cDrySJTKSs)e)TS)sX8ay9>)hr)=`S&fpeFV)NvDr zh!P}Jg5*K@E+shiC~1SG`=IXqx~=N|r$!6gxMi`Yv`DwDj+7oL4m`^%Q&fVBP6o@a znXn_wq0XmeJuD7raM>N{c3DMAj}+97vXqf96H`*2G81NDY8z8l!fZ@sZOTrVgDI^{ u6%kg<)N!d2!b+KnhPeOz8!4(8p;|-Hvb544Z(aVagud}JCo)xK_J08`s-idm literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/version.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/__pycache__/version.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..eb05a1e1df294eb296ad5437f3a12de90180efe4 GIT binary patch literal 295 zcmX@j%ge<81k+W{r1=Bs#~=<2Fhd!i^?;1&3@Hpz3@MCJjH!%StS}`AI)!O9BZL>l zT*<7-QYFCUT2YW+oT^ZkT2!2wpT||jYOH6hXY`9v&rg%(7JGbrN`7*D{4MVIc&G{> zhqbsMC$r=hdzfobu&2M@N`}uMGk-bim*f`c7i1RbmLwLXr CharsetMatches: + """ + Given a raw bytes sequence, return the best possibles charset usable to render str objects. + If there is no results, it is a strong indicator that the source is binary/not text. + By default, the process will extract 5 blocks of 512o each to assess the mess and coherence of a given sequence. + And will give up a particular code page after 20% of measured mess. Those criteria are customizable at will. + + The preemptive behavior DOES NOT replace the traditional detection workflow, it prioritize a particular code page + but never take it for granted. Can improve the performance. + + You may want to focus your attention to some code page or/and not others, use cp_isolation and cp_exclusion for that + purpose. + + This function will strip the SIG in the payload/sequence every time except on UTF-16, UTF-32. + By default the library does not setup any handler other than the NullHandler, if you choose to set the 'explain' + toggle to True it will alter the logger configuration to add a StreamHandler that is suitable for debugging. + Custom logging format and handler can be set manually. + """ + + if not isinstance(sequences, (bytearray, bytes)): + raise TypeError( + "Expected object of type bytes or bytearray, got: {0}".format( + type(sequences) + ) + ) + + if explain: + previous_logger_level: int = logger.level + logger.addHandler(explain_handler) + logger.setLevel(TRACE) + + length: int = len(sequences) + + if length == 0: + logger.debug("Encoding detection on empty bytes, assuming utf_8 intention.") + if explain: + logger.removeHandler(explain_handler) + logger.setLevel(previous_logger_level or logging.WARNING) + return CharsetMatches([CharsetMatch(sequences, "utf_8", 0.0, False, [], "")]) + + if cp_isolation is not None: + logger.log( + TRACE, + "cp_isolation is set. use this flag for debugging purpose. " + "limited list of encoding allowed : %s.", + ", ".join(cp_isolation), + ) + cp_isolation = [iana_name(cp, False) for cp in cp_isolation] + else: + cp_isolation = [] + + if cp_exclusion is not None: + logger.log( + TRACE, + "cp_exclusion is set. use this flag for debugging purpose. " + "limited list of encoding excluded : %s.", + ", ".join(cp_exclusion), + ) + cp_exclusion = [iana_name(cp, False) for cp in cp_exclusion] + else: + cp_exclusion = [] + + if length <= (chunk_size * steps): + logger.log( + TRACE, + "override steps (%i) and chunk_size (%i) as content does not fit (%i byte(s) given) parameters.", + steps, + chunk_size, + length, + ) + steps = 1 + chunk_size = length + + if steps > 1 and length / steps < chunk_size: + chunk_size = int(length / steps) + + is_too_small_sequence: bool = len(sequences) < TOO_SMALL_SEQUENCE + is_too_large_sequence: bool = len(sequences) >= TOO_BIG_SEQUENCE + + if is_too_small_sequence: + logger.log( + TRACE, + "Trying to detect encoding from a tiny portion of ({}) byte(s).".format( + length + ), + ) + elif is_too_large_sequence: + logger.log( + TRACE, + "Using lazy str decoding because the payload is quite large, ({}) byte(s).".format( + length + ), + ) + + prioritized_encodings: List[str] = [] + + specified_encoding: Optional[str] = ( + any_specified_encoding(sequences) if preemptive_behaviour else None + ) + + if specified_encoding is not None: + prioritized_encodings.append(specified_encoding) + logger.log( + TRACE, + "Detected declarative mark in sequence. Priority +1 given for %s.", + specified_encoding, + ) + + tested: Set[str] = set() + tested_but_hard_failure: List[str] = [] + tested_but_soft_failure: List[str] = [] + + fallback_ascii: Optional[CharsetMatch] = None + fallback_u8: Optional[CharsetMatch] = None + fallback_specified: Optional[CharsetMatch] = None + + results: CharsetMatches = CharsetMatches() + + sig_encoding, sig_payload = identify_sig_or_bom(sequences) + + if sig_encoding is not None: + prioritized_encodings.append(sig_encoding) + logger.log( + TRACE, + "Detected a SIG or BOM mark on first %i byte(s). Priority +1 given for %s.", + len(sig_payload), + sig_encoding, + ) + + prioritized_encodings.append("ascii") + + if "utf_8" not in prioritized_encodings: + prioritized_encodings.append("utf_8") + + for encoding_iana in prioritized_encodings + IANA_SUPPORTED: + if cp_isolation and encoding_iana not in cp_isolation: + continue + + if cp_exclusion and encoding_iana in cp_exclusion: + continue + + if encoding_iana in tested: + continue + + tested.add(encoding_iana) + + decoded_payload: Optional[str] = None + bom_or_sig_available: bool = sig_encoding == encoding_iana + strip_sig_or_bom: bool = bom_or_sig_available and should_strip_sig_or_bom( + encoding_iana + ) + + if encoding_iana in {"utf_16", "utf_32"} and not bom_or_sig_available: + logger.log( + TRACE, + "Encoding %s won't be tested as-is because it require a BOM. Will try some sub-encoder LE/BE.", + encoding_iana, + ) + continue + if encoding_iana in {"utf_7"} and not bom_or_sig_available: + logger.log( + TRACE, + "Encoding %s won't be tested as-is because detection is unreliable without BOM/SIG.", + encoding_iana, + ) + continue + + try: + is_multi_byte_decoder: bool = is_multi_byte_encoding(encoding_iana) + except (ModuleNotFoundError, ImportError): + logger.log( + TRACE, + "Encoding %s does not provide an IncrementalDecoder", + encoding_iana, + ) + continue + + try: + if is_too_large_sequence and is_multi_byte_decoder is False: + str( + sequences[: int(50e4)] + if strip_sig_or_bom is False + else sequences[len(sig_payload) : int(50e4)], + encoding=encoding_iana, + ) + else: + decoded_payload = str( + sequences + if strip_sig_or_bom is False + else sequences[len(sig_payload) :], + encoding=encoding_iana, + ) + except (UnicodeDecodeError, LookupError) as e: + if not isinstance(e, LookupError): + logger.log( + TRACE, + "Code page %s does not fit given bytes sequence at ALL. %s", + encoding_iana, + str(e), + ) + tested_but_hard_failure.append(encoding_iana) + continue + + similar_soft_failure_test: bool = False + + for encoding_soft_failed in tested_but_soft_failure: + if is_cp_similar(encoding_iana, encoding_soft_failed): + similar_soft_failure_test = True + break + + if similar_soft_failure_test: + logger.log( + TRACE, + "%s is deemed too similar to code page %s and was consider unsuited already. Continuing!", + encoding_iana, + encoding_soft_failed, + ) + continue + + r_ = range( + 0 if not bom_or_sig_available else len(sig_payload), + length, + int(length / steps), + ) + + multi_byte_bonus: bool = ( + is_multi_byte_decoder + and decoded_payload is not None + and len(decoded_payload) < length + ) + + if multi_byte_bonus: + logger.log( + TRACE, + "Code page %s is a multi byte encoding table and it appear that at least one character " + "was encoded using n-bytes.", + encoding_iana, + ) + + max_chunk_gave_up: int = int(len(r_) / 4) + + max_chunk_gave_up = max(max_chunk_gave_up, 2) + early_stop_count: int = 0 + lazy_str_hard_failure = False + + md_chunks: List[str] = [] + md_ratios = [] + + try: + for chunk in cut_sequence_chunks( + sequences, + encoding_iana, + r_, + chunk_size, + bom_or_sig_available, + strip_sig_or_bom, + sig_payload, + is_multi_byte_decoder, + decoded_payload, + ): + md_chunks.append(chunk) + + md_ratios.append( + mess_ratio( + chunk, + threshold, + explain is True and 1 <= len(cp_isolation) <= 2, + ) + ) + + if md_ratios[-1] >= threshold: + early_stop_count += 1 + + if (early_stop_count >= max_chunk_gave_up) or ( + bom_or_sig_available and strip_sig_or_bom is False + ): + break + except ( + UnicodeDecodeError + ) as e: # Lazy str loading may have missed something there + logger.log( + TRACE, + "LazyStr Loading: After MD chunk decode, code page %s does not fit given bytes sequence at ALL. %s", + encoding_iana, + str(e), + ) + early_stop_count = max_chunk_gave_up + lazy_str_hard_failure = True + + # We might want to check the sequence again with the whole content + # Only if initial MD tests passes + if ( + not lazy_str_hard_failure + and is_too_large_sequence + and not is_multi_byte_decoder + ): + try: + sequences[int(50e3) :].decode(encoding_iana, errors="strict") + except UnicodeDecodeError as e: + logger.log( + TRACE, + "LazyStr Loading: After final lookup, code page %s does not fit given bytes sequence at ALL. %s", + encoding_iana, + str(e), + ) + tested_but_hard_failure.append(encoding_iana) + continue + + mean_mess_ratio: float = sum(md_ratios) / len(md_ratios) if md_ratios else 0.0 + if mean_mess_ratio >= threshold or early_stop_count >= max_chunk_gave_up: + tested_but_soft_failure.append(encoding_iana) + logger.log( + TRACE, + "%s was excluded because of initial chaos probing. Gave up %i time(s). " + "Computed mean chaos is %f %%.", + encoding_iana, + early_stop_count, + round(mean_mess_ratio * 100, ndigits=3), + ) + # Preparing those fallbacks in case we got nothing. + if ( + enable_fallback + and encoding_iana in ["ascii", "utf_8", specified_encoding] + and not lazy_str_hard_failure + ): + fallback_entry = CharsetMatch( + sequences, encoding_iana, threshold, False, [], decoded_payload + ) + if encoding_iana == specified_encoding: + fallback_specified = fallback_entry + elif encoding_iana == "ascii": + fallback_ascii = fallback_entry + else: + fallback_u8 = fallback_entry + continue + + logger.log( + TRACE, + "%s passed initial chaos probing. Mean measured chaos is %f %%", + encoding_iana, + round(mean_mess_ratio * 100, ndigits=3), + ) + + if not is_multi_byte_decoder: + target_languages: List[str] = encoding_languages(encoding_iana) + else: + target_languages = mb_encoding_languages(encoding_iana) + + if target_languages: + logger.log( + TRACE, + "{} should target any language(s) of {}".format( + encoding_iana, str(target_languages) + ), + ) + + cd_ratios = [] + + # We shall skip the CD when its about ASCII + # Most of the time its not relevant to run "language-detection" on it. + if encoding_iana != "ascii": + for chunk in md_chunks: + chunk_languages = coherence_ratio( + chunk, + language_threshold, + ",".join(target_languages) if target_languages else None, + ) + + cd_ratios.append(chunk_languages) + + cd_ratios_merged = merge_coherence_ratios(cd_ratios) + + if cd_ratios_merged: + logger.log( + TRACE, + "We detected language {} using {}".format( + cd_ratios_merged, encoding_iana + ), + ) + + results.append( + CharsetMatch( + sequences, + encoding_iana, + mean_mess_ratio, + bom_or_sig_available, + cd_ratios_merged, + decoded_payload, + ) + ) + + if ( + encoding_iana in [specified_encoding, "ascii", "utf_8"] + and mean_mess_ratio < 0.1 + ): + logger.debug( + "Encoding detection: %s is most likely the one.", encoding_iana + ) + if explain: + logger.removeHandler(explain_handler) + logger.setLevel(previous_logger_level) + return CharsetMatches([results[encoding_iana]]) + + if encoding_iana == sig_encoding: + logger.debug( + "Encoding detection: %s is most likely the one as we detected a BOM or SIG within " + "the beginning of the sequence.", + encoding_iana, + ) + if explain: + logger.removeHandler(explain_handler) + logger.setLevel(previous_logger_level) + return CharsetMatches([results[encoding_iana]]) + + if len(results) == 0: + if fallback_u8 or fallback_ascii or fallback_specified: + logger.log( + TRACE, + "Nothing got out of the detection process. Using ASCII/UTF-8/Specified fallback.", + ) + + if fallback_specified: + logger.debug( + "Encoding detection: %s will be used as a fallback match", + fallback_specified.encoding, + ) + results.append(fallback_specified) + elif ( + (fallback_u8 and fallback_ascii is None) + or ( + fallback_u8 + and fallback_ascii + and fallback_u8.fingerprint != fallback_ascii.fingerprint + ) + or (fallback_u8 is not None) + ): + logger.debug("Encoding detection: utf_8 will be used as a fallback match") + results.append(fallback_u8) + elif fallback_ascii: + logger.debug("Encoding detection: ascii will be used as a fallback match") + results.append(fallback_ascii) + + if results: + logger.debug( + "Encoding detection: Found %s as plausible (best-candidate) for content. With %i alternatives.", + results.best().encoding, # type: ignore + len(results) - 1, + ) + else: + logger.debug("Encoding detection: Unable to determine any suitable charset.") + + if explain: + logger.removeHandler(explain_handler) + logger.setLevel(previous_logger_level) + + return results + + +def from_fp( + fp: BinaryIO, + steps: int = 5, + chunk_size: int = 512, + threshold: float = 0.20, + cp_isolation: Optional[List[str]] = None, + cp_exclusion: Optional[List[str]] = None, + preemptive_behaviour: bool = True, + explain: bool = False, + language_threshold: float = 0.1, + enable_fallback: bool = True, +) -> CharsetMatches: + """ + Same thing than the function from_bytes but using a file pointer that is already ready. + Will not close the file pointer. + """ + return from_bytes( + fp.read(), + steps, + chunk_size, + threshold, + cp_isolation, + cp_exclusion, + preemptive_behaviour, + explain, + language_threshold, + enable_fallback, + ) + + +def from_path( + path: Union[str, bytes, PathLike], # type: ignore[type-arg] + steps: int = 5, + chunk_size: int = 512, + threshold: float = 0.20, + cp_isolation: Optional[List[str]] = None, + cp_exclusion: Optional[List[str]] = None, + preemptive_behaviour: bool = True, + explain: bool = False, + language_threshold: float = 0.1, + enable_fallback: bool = True, +) -> CharsetMatches: + """ + Same thing than the function from_bytes but with one extra step. Opening and reading given file path in binary mode. + Can raise IOError. + """ + with open(path, "rb") as fp: + return from_fp( + fp, + steps, + chunk_size, + threshold, + cp_isolation, + cp_exclusion, + preemptive_behaviour, + explain, + language_threshold, + enable_fallback, + ) + + +def is_binary( + fp_or_path_or_payload: Union[PathLike, str, BinaryIO, bytes], # type: ignore[type-arg] + steps: int = 5, + chunk_size: int = 512, + threshold: float = 0.20, + cp_isolation: Optional[List[str]] = None, + cp_exclusion: Optional[List[str]] = None, + preemptive_behaviour: bool = True, + explain: bool = False, + language_threshold: float = 0.1, + enable_fallback: bool = False, +) -> bool: + """ + Detect if the given input (file, bytes, or path) points to a binary file. aka. not a string. + Based on the same main heuristic algorithms and default kwargs at the sole exception that fallbacks match + are disabled to be stricter around ASCII-compatible but unlikely to be a string. + """ + if isinstance(fp_or_path_or_payload, (str, PathLike)): + guesses = from_path( + fp_or_path_or_payload, + steps=steps, + chunk_size=chunk_size, + threshold=threshold, + cp_isolation=cp_isolation, + cp_exclusion=cp_exclusion, + preemptive_behaviour=preemptive_behaviour, + explain=explain, + language_threshold=language_threshold, + enable_fallback=enable_fallback, + ) + elif isinstance( + fp_or_path_or_payload, + ( + bytes, + bytearray, + ), + ): + guesses = from_bytes( + fp_or_path_or_payload, + steps=steps, + chunk_size=chunk_size, + threshold=threshold, + cp_isolation=cp_isolation, + cp_exclusion=cp_exclusion, + preemptive_behaviour=preemptive_behaviour, + explain=explain, + language_threshold=language_threshold, + enable_fallback=enable_fallback, + ) + else: + guesses = from_fp( + fp_or_path_or_payload, + steps=steps, + chunk_size=chunk_size, + threshold=threshold, + cp_isolation=cp_isolation, + cp_exclusion=cp_exclusion, + preemptive_behaviour=preemptive_behaviour, + explain=explain, + language_threshold=language_threshold, + enable_fallback=enable_fallback, + ) + + return not guesses diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cd.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cd.py new file mode 100644 index 0000000..4ea6760 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cd.py @@ -0,0 +1,395 @@ +import importlib +from codecs import IncrementalDecoder +from collections import Counter +from functools import lru_cache +from typing import Counter as TypeCounter, Dict, List, Optional, Tuple + +from .constant import ( + FREQUENCIES, + KO_NAMES, + LANGUAGE_SUPPORTED_COUNT, + TOO_SMALL_SEQUENCE, + ZH_NAMES, +) +from .md import is_suspiciously_successive_range +from .models import CoherenceMatches +from .utils import ( + is_accentuated, + is_latin, + is_multi_byte_encoding, + is_unicode_range_secondary, + unicode_range, +) + + +def encoding_unicode_range(iana_name: str) -> List[str]: + """ + Return associated unicode ranges in a single byte code page. + """ + if is_multi_byte_encoding(iana_name): + raise IOError("Function not supported on multi-byte code page") + + decoder = importlib.import_module( + "encodings.{}".format(iana_name) + ).IncrementalDecoder + + p: IncrementalDecoder = decoder(errors="ignore") + seen_ranges: Dict[str, int] = {} + character_count: int = 0 + + for i in range(0x40, 0xFF): + chunk: str = p.decode(bytes([i])) + + if chunk: + character_range: Optional[str] = unicode_range(chunk) + + if character_range is None: + continue + + if is_unicode_range_secondary(character_range) is False: + if character_range not in seen_ranges: + seen_ranges[character_range] = 0 + seen_ranges[character_range] += 1 + character_count += 1 + + return sorted( + [ + character_range + for character_range in seen_ranges + if seen_ranges[character_range] / character_count >= 0.15 + ] + ) + + +def unicode_range_languages(primary_range: str) -> List[str]: + """ + Return inferred languages used with a unicode range. + """ + languages: List[str] = [] + + for language, characters in FREQUENCIES.items(): + for character in characters: + if unicode_range(character) == primary_range: + languages.append(language) + break + + return languages + + +@lru_cache() +def encoding_languages(iana_name: str) -> List[str]: + """ + Single-byte encoding language association. Some code page are heavily linked to particular language(s). + This function does the correspondence. + """ + unicode_ranges: List[str] = encoding_unicode_range(iana_name) + primary_range: Optional[str] = None + + for specified_range in unicode_ranges: + if "Latin" not in specified_range: + primary_range = specified_range + break + + if primary_range is None: + return ["Latin Based"] + + return unicode_range_languages(primary_range) + + +@lru_cache() +def mb_encoding_languages(iana_name: str) -> List[str]: + """ + Multi-byte encoding language association. Some code page are heavily linked to particular language(s). + This function does the correspondence. + """ + if ( + iana_name.startswith("shift_") + or iana_name.startswith("iso2022_jp") + or iana_name.startswith("euc_j") + or iana_name == "cp932" + ): + return ["Japanese"] + if iana_name.startswith("gb") or iana_name in ZH_NAMES: + return ["Chinese"] + if iana_name.startswith("iso2022_kr") or iana_name in KO_NAMES: + return ["Korean"] + + return [] + + +@lru_cache(maxsize=LANGUAGE_SUPPORTED_COUNT) +def get_target_features(language: str) -> Tuple[bool, bool]: + """ + Determine main aspects from a supported language if it contains accents and if is pure Latin. + """ + target_have_accents: bool = False + target_pure_latin: bool = True + + for character in FREQUENCIES[language]: + if not target_have_accents and is_accentuated(character): + target_have_accents = True + if target_pure_latin and is_latin(character) is False: + target_pure_latin = False + + return target_have_accents, target_pure_latin + + +def alphabet_languages( + characters: List[str], ignore_non_latin: bool = False +) -> List[str]: + """ + Return associated languages associated to given characters. + """ + languages: List[Tuple[str, float]] = [] + + source_have_accents = any(is_accentuated(character) for character in characters) + + for language, language_characters in FREQUENCIES.items(): + target_have_accents, target_pure_latin = get_target_features(language) + + if ignore_non_latin and target_pure_latin is False: + continue + + if target_have_accents is False and source_have_accents: + continue + + character_count: int = len(language_characters) + + character_match_count: int = len( + [c for c in language_characters if c in characters] + ) + + ratio: float = character_match_count / character_count + + if ratio >= 0.2: + languages.append((language, ratio)) + + languages = sorted(languages, key=lambda x: x[1], reverse=True) + + return [compatible_language[0] for compatible_language in languages] + + +def characters_popularity_compare( + language: str, ordered_characters: List[str] +) -> float: + """ + Determine if a ordered characters list (by occurrence from most appearance to rarest) match a particular language. + The result is a ratio between 0. (absolutely no correspondence) and 1. (near perfect fit). + Beware that is function is not strict on the match in order to ease the detection. (Meaning close match is 1.) + """ + if language not in FREQUENCIES: + raise ValueError("{} not available".format(language)) + + character_approved_count: int = 0 + FREQUENCIES_language_set = set(FREQUENCIES[language]) + + ordered_characters_count: int = len(ordered_characters) + target_language_characters_count: int = len(FREQUENCIES[language]) + + large_alphabet: bool = target_language_characters_count > 26 + + for character, character_rank in zip( + ordered_characters, range(0, ordered_characters_count) + ): + if character not in FREQUENCIES_language_set: + continue + + character_rank_in_language: int = FREQUENCIES[language].index(character) + expected_projection_ratio: float = ( + target_language_characters_count / ordered_characters_count + ) + character_rank_projection: int = int(character_rank * expected_projection_ratio) + + if ( + large_alphabet is False + and abs(character_rank_projection - character_rank_in_language) > 4 + ): + continue + + if ( + large_alphabet is True + and abs(character_rank_projection - character_rank_in_language) + < target_language_characters_count / 3 + ): + character_approved_count += 1 + continue + + characters_before_source: List[str] = FREQUENCIES[language][ + 0:character_rank_in_language + ] + characters_after_source: List[str] = FREQUENCIES[language][ + character_rank_in_language: + ] + characters_before: List[str] = ordered_characters[0:character_rank] + characters_after: List[str] = ordered_characters[character_rank:] + + before_match_count: int = len( + set(characters_before) & set(characters_before_source) + ) + + after_match_count: int = len( + set(characters_after) & set(characters_after_source) + ) + + if len(characters_before_source) == 0 and before_match_count <= 4: + character_approved_count += 1 + continue + + if len(characters_after_source) == 0 and after_match_count <= 4: + character_approved_count += 1 + continue + + if ( + before_match_count / len(characters_before_source) >= 0.4 + or after_match_count / len(characters_after_source) >= 0.4 + ): + character_approved_count += 1 + continue + + return character_approved_count / len(ordered_characters) + + +def alpha_unicode_split(decoded_sequence: str) -> List[str]: + """ + Given a decoded text sequence, return a list of str. Unicode range / alphabet separation. + Ex. a text containing English/Latin with a bit a Hebrew will return two items in the resulting list; + One containing the latin letters and the other hebrew. + """ + layers: Dict[str, str] = {} + + for character in decoded_sequence: + if character.isalpha() is False: + continue + + character_range: Optional[str] = unicode_range(character) + + if character_range is None: + continue + + layer_target_range: Optional[str] = None + + for discovered_range in layers: + if ( + is_suspiciously_successive_range(discovered_range, character_range) + is False + ): + layer_target_range = discovered_range + break + + if layer_target_range is None: + layer_target_range = character_range + + if layer_target_range not in layers: + layers[layer_target_range] = character.lower() + continue + + layers[layer_target_range] += character.lower() + + return list(layers.values()) + + +def merge_coherence_ratios(results: List[CoherenceMatches]) -> CoherenceMatches: + """ + This function merge results previously given by the function coherence_ratio. + The return type is the same as coherence_ratio. + """ + per_language_ratios: Dict[str, List[float]] = {} + for result in results: + for sub_result in result: + language, ratio = sub_result + if language not in per_language_ratios: + per_language_ratios[language] = [ratio] + continue + per_language_ratios[language].append(ratio) + + merge = [ + ( + language, + round( + sum(per_language_ratios[language]) / len(per_language_ratios[language]), + 4, + ), + ) + for language in per_language_ratios + ] + + return sorted(merge, key=lambda x: x[1], reverse=True) + + +def filter_alt_coherence_matches(results: CoherenceMatches) -> CoherenceMatches: + """ + We shall NOT return "English—" in CoherenceMatches because it is an alternative + of "English". This function only keeps the best match and remove the em-dash in it. + """ + index_results: Dict[str, List[float]] = dict() + + for result in results: + language, ratio = result + no_em_name: str = language.replace("—", "") + + if no_em_name not in index_results: + index_results[no_em_name] = [] + + index_results[no_em_name].append(ratio) + + if any(len(index_results[e]) > 1 for e in index_results): + filtered_results: CoherenceMatches = [] + + for language in index_results: + filtered_results.append((language, max(index_results[language]))) + + return filtered_results + + return results + + +@lru_cache(maxsize=2048) +def coherence_ratio( + decoded_sequence: str, threshold: float = 0.1, lg_inclusion: Optional[str] = None +) -> CoherenceMatches: + """ + Detect ANY language that can be identified in given sequence. The sequence will be analysed by layers. + A layer = Character extraction by alphabets/ranges. + """ + + results: List[Tuple[str, float]] = [] + ignore_non_latin: bool = False + + sufficient_match_count: int = 0 + + lg_inclusion_list = lg_inclusion.split(",") if lg_inclusion is not None else [] + if "Latin Based" in lg_inclusion_list: + ignore_non_latin = True + lg_inclusion_list.remove("Latin Based") + + for layer in alpha_unicode_split(decoded_sequence): + sequence_frequencies: TypeCounter[str] = Counter(layer) + most_common = sequence_frequencies.most_common() + + character_count: int = sum(o for c, o in most_common) + + if character_count <= TOO_SMALL_SEQUENCE: + continue + + popular_character_ordered: List[str] = [c for c, o in most_common] + + for language in lg_inclusion_list or alphabet_languages( + popular_character_ordered, ignore_non_latin + ): + ratio: float = characters_popularity_compare( + language, popular_character_ordered + ) + + if ratio < threshold: + continue + elif ratio >= 0.8: + sufficient_match_count += 1 + + results.append((language, round(ratio, 4))) + + if sufficient_match_count >= 3: + break + + return sorted( + filter_alt_coherence_matches(results), key=lambda x: x[1], reverse=True + ) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__init__.py new file mode 100644 index 0000000..d95fedf --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__init__.py @@ -0,0 +1,6 @@ +from .__main__ import cli_detect, query_yes_no + +__all__ = ( + "cli_detect", + "query_yes_no", +) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__main__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__main__.py new file mode 100644 index 0000000..f4bcbaa --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__main__.py @@ -0,0 +1,296 @@ +import argparse +import sys +from json import dumps +from os.path import abspath, basename, dirname, join, realpath +from platform import python_version +from typing import List, Optional +from unicodedata import unidata_version + +import charset_normalizer.md as md_module +from charset_normalizer import from_fp +from charset_normalizer.models import CliDetectionResult +from charset_normalizer.version import __version__ + + +def query_yes_no(question: str, default: str = "yes") -> bool: + """Ask a yes/no question via input() and return their answer. + + "question" is a string that is presented to the user. + "default" is the presumed answer if the user just hits . + It must be "yes" (the default), "no" or None (meaning + an answer is required of the user). + + The "answer" return value is True for "yes" or False for "no". + + Credit goes to (c) https://stackoverflow.com/questions/3041986/apt-command-line-interface-like-yes-no-input + """ + valid = {"yes": True, "y": True, "ye": True, "no": False, "n": False} + if default is None: + prompt = " [y/n] " + elif default == "yes": + prompt = " [Y/n] " + elif default == "no": + prompt = " [y/N] " + else: + raise ValueError("invalid default answer: '%s'" % default) + + while True: + sys.stdout.write(question + prompt) + choice = input().lower() + if default is not None and choice == "": + return valid[default] + elif choice in valid: + return valid[choice] + else: + sys.stdout.write("Please respond with 'yes' or 'no' " "(or 'y' or 'n').\n") + + +def cli_detect(argv: Optional[List[str]] = None) -> int: + """ + CLI assistant using ARGV and ArgumentParser + :param argv: + :return: 0 if everything is fine, anything else equal trouble + """ + parser = argparse.ArgumentParser( + description="The Real First Universal Charset Detector. " + "Discover originating encoding used on text file. " + "Normalize text to unicode." + ) + + parser.add_argument( + "files", type=argparse.FileType("rb"), nargs="+", help="File(s) to be analysed" + ) + parser.add_argument( + "-v", + "--verbose", + action="store_true", + default=False, + dest="verbose", + help="Display complementary information about file if any. " + "Stdout will contain logs about the detection process.", + ) + parser.add_argument( + "-a", + "--with-alternative", + action="store_true", + default=False, + dest="alternatives", + help="Output complementary possibilities if any. Top-level JSON WILL be a list.", + ) + parser.add_argument( + "-n", + "--normalize", + action="store_true", + default=False, + dest="normalize", + help="Permit to normalize input file. If not set, program does not write anything.", + ) + parser.add_argument( + "-m", + "--minimal", + action="store_true", + default=False, + dest="minimal", + help="Only output the charset detected to STDOUT. Disabling JSON output.", + ) + parser.add_argument( + "-r", + "--replace", + action="store_true", + default=False, + dest="replace", + help="Replace file when trying to normalize it instead of creating a new one.", + ) + parser.add_argument( + "-f", + "--force", + action="store_true", + default=False, + dest="force", + help="Replace file without asking if you are sure, use this flag with caution.", + ) + parser.add_argument( + "-t", + "--threshold", + action="store", + default=0.2, + type=float, + dest="threshold", + help="Define a custom maximum amount of chaos allowed in decoded content. 0. <= chaos <= 1.", + ) + parser.add_argument( + "--version", + action="version", + version="Charset-Normalizer {} - Python {} - Unicode {} - SpeedUp {}".format( + __version__, + python_version(), + unidata_version, + "OFF" if md_module.__file__.lower().endswith(".py") else "ON", + ), + help="Show version information and exit.", + ) + + args = parser.parse_args(argv) + + if args.replace is True and args.normalize is False: + print("Use --replace in addition of --normalize only.", file=sys.stderr) + return 1 + + if args.force is True and args.replace is False: + print("Use --force in addition of --replace only.", file=sys.stderr) + return 1 + + if args.threshold < 0.0 or args.threshold > 1.0: + print("--threshold VALUE should be between 0. AND 1.", file=sys.stderr) + return 1 + + x_ = [] + + for my_file in args.files: + matches = from_fp(my_file, threshold=args.threshold, explain=args.verbose) + + best_guess = matches.best() + + if best_guess is None: + print( + 'Unable to identify originating encoding for "{}". {}'.format( + my_file.name, + "Maybe try increasing maximum amount of chaos." + if args.threshold < 1.0 + else "", + ), + file=sys.stderr, + ) + x_.append( + CliDetectionResult( + abspath(my_file.name), + None, + [], + [], + "Unknown", + [], + False, + 1.0, + 0.0, + None, + True, + ) + ) + else: + x_.append( + CliDetectionResult( + abspath(my_file.name), + best_guess.encoding, + best_guess.encoding_aliases, + [ + cp + for cp in best_guess.could_be_from_charset + if cp != best_guess.encoding + ], + best_guess.language, + best_guess.alphabets, + best_guess.bom, + best_guess.percent_chaos, + best_guess.percent_coherence, + None, + True, + ) + ) + + if len(matches) > 1 and args.alternatives: + for el in matches: + if el != best_guess: + x_.append( + CliDetectionResult( + abspath(my_file.name), + el.encoding, + el.encoding_aliases, + [ + cp + for cp in el.could_be_from_charset + if cp != el.encoding + ], + el.language, + el.alphabets, + el.bom, + el.percent_chaos, + el.percent_coherence, + None, + False, + ) + ) + + if args.normalize is True: + if best_guess.encoding.startswith("utf") is True: + print( + '"{}" file does not need to be normalized, as it already came from unicode.'.format( + my_file.name + ), + file=sys.stderr, + ) + if my_file.closed is False: + my_file.close() + continue + + dir_path = dirname(realpath(my_file.name)) + file_name = basename(realpath(my_file.name)) + + o_: List[str] = file_name.split(".") + + if args.replace is False: + o_.insert(-1, best_guess.encoding) + if my_file.closed is False: + my_file.close() + elif ( + args.force is False + and query_yes_no( + 'Are you sure to normalize "{}" by replacing it ?'.format( + my_file.name + ), + "no", + ) + is False + ): + if my_file.closed is False: + my_file.close() + continue + + try: + x_[0].unicode_path = join(dir_path, ".".join(o_)) + + with open(x_[0].unicode_path, "w", encoding="utf-8") as fp: + fp.write(str(best_guess)) + except IOError as e: + print(str(e), file=sys.stderr) + if my_file.closed is False: + my_file.close() + return 2 + + if my_file.closed is False: + my_file.close() + + if args.minimal is False: + print( + dumps( + [el.__dict__ for el in x_] if len(x_) > 1 else x_[0].__dict__, + ensure_ascii=True, + indent=4, + ) + ) + else: + for my_file in args.files: + print( + ", ".join( + [ + el.encoding or "undefined" + for el in x_ + if el.path == abspath(my_file.name) + ] + ) + ) + + return 0 + + +if __name__ == "__main__": + cli_detect() diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..53d87ec7b1c143488e1925507c9dbed99cba9275 GIT binary patch literal 256 zcmXv}J8r`;4AsX#jC|0w2k7D<(bTQzn6U@&La3J72#{=rRt9L?} zao%_b#wOdOak)QO%#dvlZTC_YV+jznYXMMFHx@+W3_yDiaAH@o?6y@YL=|0JCynnm zt%ttD!91e!?p4K{c3rEQoyOiK8jC@DH&|4(R{^-zC4f!LxAG};=HTr!PQOjp^>;)U S$vOXGn@b@V;$wy-<$eJ`k45YN literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__pycache__/__main__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/cli/__pycache__/__main__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..7d9e064175e872440d4b09e655e00468c40ccccc GIT binary patch literal 10360 zcmcgyeQX;?cHialWBDmcBqdT`UdbO49h35B{24ozWjXT6c4Euj>gkxL`cC3i0T_fS4l? zfk>W+>2ESdLfOQd(o~EhaUI2*)0UVeZH-yewwNtV$LO>@X4l%xyd&+5IW^kCyVCBM zJMD>iw6c|NNPA;mjVAfVbW_Zy(KgAdB zYa6p7_n%r~?WhTPI1lIMT0@{U{)5(zF*9m_)=q8}@}BJ_2#GckT<49-1W96woFc=% zFL3#2m{ct&o6g8#i)v#>=>VS`;1n)_`HypQ zmRF$G88^7&ah3jFmXmQaXu^%Lz@b_tPRU9_!c>_Lep%sa9!apYXq294f zoATsE3Yn)Vp)*e+i)IoES)tqvWm~08L)oK1fBixBJedQzH!3xMLfQ$XI%djj@YUWa zBZO*IM4re~IVc-aNJ6n2&4xo#PNSywHrl4mdGbw1-i#cYmXG2JkaZl)Its|XKoV7djdn-L}E zs3>quZ<=ETP*BqV_hyCaa57Bud)cG}8i=)_!;v_901u#g&7w)8QY^b5oRV7B_r?Z>ys5WaaM%YHO7mR(S(@pGYl*D zZP~bW)6N~w_puoz0xfCqNQ6%cTqKE2F~%l1D4yjaF#CugLM=E>o8ZVGtaA#gRdPx- zO>wG85LHsh*_cyPeZm<=@W-rBa&eJ9>u6wI>CbUlJLntk`K6)3a9YQHk7^ zmw65n2iQW+h!7)_No9iRfx&vPwR;4yhv~({RHfVlmJC}}$E(RaN;0R!1yM@F^m3fkm*A6q@pzg|3h{U} zGo`w~^wLxurh>WFfcysdlYays7m0F^2!!U9>sxPSKiXDs4P87~vUx84pw!rU*;=xD zXAa)AhpL5vAFk5q&pp9Aq3ySO3Zearp8h*@{{x3-iFUr_xa=s>!2%te4=xNALhJ9* z&n-1Jzuhv|G28L>s!P_Av+0hrbK&{x$Nz3m$rqe&ncaKG)m3u)X0n&#xT1OXg*z_h zb63M#hc6#4y4nk__B$P~-gCWHZX}!yk3eHWHG?tEC90_os<1h=1bWAV6KE|Brm86q z_tYOm-Zb5)^qwa3WC|O6#e=A2GH`lc@gTDy0a=jsrtL;0p_0T?-~cN=QgxI0kiGjOkh#f4|tg}R@C zdo@~v)}nO^Z5S8zpx&F|8TM1j&S=0*U&JSU?+ZZZc?XE^RBiLNQ<6T49?vrP`n5K%29K zv>w_z>$EwctzGFdTF@4y+n`f;nXh2moTcYd2O$BAhQB(GmNDnSeoGv+f83DagJVzlBzNj)u~ zHfr$H-ZyvMz&Qt=X-nRc+N9IVKaIGVw&txDf3VC?d+J4R-kjRJythu**9h&vR)dIp z0U~a%;nioiOrA<@dvYvgyHTg?G^qMo88MG`j}zkr+6RA5v;%ENyV2$wPQ9*CTXYkI>KPk-9SLc!aL&5xTBN=(--E z>w1KKibtGJM)#E;nF+9bz5EQhdxn($75rN#W>d#%J~AluV%4WO?~g3Y8T+3-XBaZR zMLsa6UN&^7y%Em$UdR9^YIO!>tnX zQ%3LF8}(PEJHazg+sSt4ovAamUIv8@)c2Q>WnnLWy0ymskhO%9pi#Yj7u))f60d48 z@a_GL4jMXYo@0KGo`2Y@)RkF)3|K>-ydCwYswJZqa#!_BxG{E~LWB6A6tC`x3TN;e zZK+YCruIgM&`URmj6HQ5G40B`QscFDgHnhPh>=sP!u4Z9hm!3l2=w61&dITM3X%{9Hzk-DB;uIJW@o>EOegL>Apf(8M3 zVXk#@;dxRvf$xsOoS)a{Y|O)Wlf;$NW|&g~`0!pl37-bFn%D$8+9Z_UAV~PR^1JiY z8^k2Jnov@PmTL&<$h5mQ=VejkHpck>$(L_Hj83~RxWPk*b!w8FBy^1{bE2!W11fwh zcgcbAfCIxr3@gikQnG>qz!S!$_8&j=DgYUX*)NR))+8t|V>Ce0_;+PkiA^*3+wv~G zLWjL}F&i-!#Q``27$}wkh|d_{FB?EorG~?351>aZ&nS|Z9pyPqLhc-fjgAA1$_yqY z0I5z2NsORE`GAf?FgheEN>OGYDJL)j1n^06JSngW9*PqZBEkd!XMjryjKZB)V04~~ z0-{xcF!V}5lmLJQb}ov6Rm8~&DXF2ess(qDRg*OO4f$NIc@Rpyau{P!fSR#@-cEt^ zFr}K6sSH3c0@y%S%@Z7-$(bVOa`s3B^codqPIbtNC~HM$~w97_R~t z13D-I*ds^7X4T4S7_yEEnPHxaguicqs%)+)62U-JgyjJm!!|s}sjg)OIX84Hs{lZ@ zLe-22kusX(lS&f6IYYw{F%#jz@jP?*#Id8yYeU1sn#C9%qACgl3OQ#4Ft>^yRC|@o z4ZqAuX#o4c#??w4Q>}P!Xbc(@2C%3Ncyi-7_7Fw}ajk}hRl^I9l*V32Cxs-SR;sN+ zKmWc@wO5;RCkHsZZ~>=I0AwttnKXMona;wZPm5Vd5`g=H0Y!*F9^;P) zW(JnTOA2Wb3UM7}Hb$8}FI4z|*c1hn67StwJW3ldg}<2UF{v*dd}X4o7EI)JSJr-{ zx_~9-`_oK>d0D$-(P_vOcwD`3BExa$WCjX33L})%vB5#rbnIxZ`^1De$>5ZN*Vtq0 z4U!ypKB+{*l&&4#Ml_v9a?z7u&#K4qBv}N&G!_9CSQgOWKYj{l6EjXAUtkn4w_fk8 zx$()amEh4kR!<`pqP#B`S>`F`)&0XK4>I7jERXQI8s(Hp4#Es9y#MF`wya6Q->g*| zcOHT>DICphJt;s8Lo|p?5`jCCV-WuJ@+IiUbbo)kJBp1KIl@kXdB5~89c@L zQ3)T%RNG16tRPMbDwS2na)+@jeI-;EsQ^x?#t->v! zCX#V-Rvp@aShg%Zk9)##3Gn?4TpcMAhW)fl0Zx)6`0h<;As~e@<;EWyF@t#&(!Ofe zZY!;9CIhl1I2;lZp1pJsvv>`&!~y4rn+jPCBygm~N4dCmEm_HxD$TRPc$OXKR6E>v zPOuP$vPzALY1N(KAZH0mT+0e-W3?zwa1w~;REp;WX$u|>c1BiG^a)xMJZzSbinOl56Da{u^uu5VAY~jELjE}>GD{v$- zs)^%O8t#AfvF)1UH0zqgxM~{9s3a$21LKob?U7dF@f>i264!SeDF+qUL-Ma+))$Gd zT!g2&=w4HBuPK{Mfwf;zW{>saVA(}joJDg>!Q4`!8~$pd*xXZS?zwJWY>wPIacAFa zWs0x_zamT)YuUPt(^aB1?1|bII#layOOSpdKnW)SWEo7A$#> z6ulz_@5qv?Wy#gL=xSebwJilYi-Dd(pr;s!6ataOKwmMiqY&6}J8&nEil`c zX!jk@-k+ZMB=&LaQ~KpngBLUA-ptL66l|e+bdA5tU*`&)TQtU9KlOdm`f=;0^l*jo z!kZW7sk^qedF9%Ls~2ujcUS3*FZ}etCx<^i{3(45GuoXO`ycpP=622QdIbN=U}?W( zTWSi;_go+O@Vg&;_oI z_muoV^cDPl5ZcmJ;~=0Nj<_RdmU$3kndYiprv>)p1k4=qHf?I8tCWd{*h zwXAz@!QTsV=8n!D)x>Qm_%~?8#)5yNrfKleDlbfpYI1wN>Lt9sneBg(pJ(qjtXdc- zuGw~X&9+i&*F(bJ*gDf+Y6;E97F&8s!PaZ`tM;Y#=n~U&-S(mD1J@$6t;BS{?|jz@ zuOhRhz-$4n`!*G$gN5iIXx-KQpm%+#Cw%?*ho?R`b+=~+=)ATEbnfZ~ox4_7y1wsv z*M$XH-?eIjHWrwT8nLy&Y%MWsO3Yf&x1;lGswvc3wt!mY4TRVK)`iO#7W{V`)|Px7 zMc=xDZ(Y&1so>jmYweey8CV{`Sw?y5HMz{m_TQ9}F+9-nrPeYldEGU-RDU z*T+BPKj0VF?p|!)Gh=_igx_y?x8WAG$ZVZ4;gH-jyJulr!3R!go*SASnjc+QU+msi z=-zhE|9q*XbLCin+wj02oI5;wcwsF>z*2BcDR{UTe5DY4Wx3K|+E53CWJpuE<4dLZR#iVkLiz^{@Jw{J~-1q^S#-F_x$TV4|RZAjaRv1=f*Yhxp)0S(@fJ`+uLo6-u1Vo zkGg)G{mF$NUnq5Sm0E&d*~}1&l-2GiuOnRUatje`pUchW9ujuD=h7i<$@=H)vv#~L z)-GES*S25X{@!@SBkOkGZQEVO3*(yes`GAe^TPKF!Ohwtc|=(oo4%&-8m2&Gxfw?J z?Zemb`uXj{C`9CMQY4-ww!rT`Z|QtUn8ASl&^xQ=*}qx$p8S69-Q1`C&2`-OPQ(4S z_TQE5!2drFgGA$VzkS#QQsp7o?0)78p6c`eXM6C}*5;qD+k4t#Dz0fewbN4EM+5x} zzwb<^OYPlxX0_+DotD!k`)7M?P`_lcpJ}r!dG?#mG+XXBTcCh", + "=", + ":", + "/", + "&", + ";", + "{", + "}", + "[", + "]", + ",", + "|", + '"', + "-", +} + + +KO_NAMES: Set[str] = {"johab", "cp949", "euc_kr"} +ZH_NAMES: Set[str] = {"big5", "cp950", "big5hkscs", "hz"} + +# Logging LEVEL below DEBUG +TRACE: int = 5 + + +# Language label that contain the em dash "—" +# character are to be considered alternative seq to origin +FREQUENCIES: Dict[str, List[str]] = { + "English": [ + "e", + "a", + "t", + "i", + "o", + "n", + "s", + "r", + "h", + "l", + "d", + "c", + "u", + "m", + "f", + "p", + "g", + "w", + "y", + "b", + "v", + "k", + "x", + "j", + "z", + "q", + ], + "English—": [ + "e", + "a", + "t", + "i", + "o", + "n", + "s", + "r", + "h", + "l", + "d", + "c", + "m", + "u", + "f", + "p", + "g", + "w", + "b", + "y", + "v", + "k", + "j", + "x", + "z", + "q", + ], + "German": [ + "e", + "n", + "i", + "r", + "s", + "t", + "a", + "d", + "h", + "u", + "l", + "g", + "o", + "c", + "m", + "b", + "f", + "k", + "w", + "z", + "p", + "v", + "ü", + "ä", + "ö", + "j", + ], + "French": [ + "e", + "a", + "s", + "n", + "i", + "t", + "r", + "l", + "u", + "o", + "d", + "c", + "p", + "m", + "é", + "v", + "g", + "f", + "b", + "h", + "q", + "à", + "x", + "è", + "y", + "j", + ], + "Dutch": [ + "e", + "n", + "a", + "i", + "r", + "t", + "o", + "d", + "s", + "l", + "g", + "h", + "v", + "m", + "u", + "k", + "c", + "p", + "b", + "w", + "j", + "z", + "f", + "y", + "x", + "ë", + ], + "Italian": [ + "e", + "i", + "a", + "o", + "n", + "l", + "t", + "r", + "s", + "c", + "d", + "u", + "p", + "m", + "g", + "v", + "f", + "b", + "z", + "h", + "q", + "è", + "à", + "k", + "y", + "ò", + ], + "Polish": [ + "a", + "i", + "o", + "e", + "n", + "r", + "z", + "w", + "s", + "c", + "t", + "k", + "y", + "d", + "p", + "m", + "u", + "l", + "j", + "ł", + "g", + "b", + "h", + "ą", + "ę", + "ó", + ], + "Spanish": [ + "e", + "a", + "o", + "n", + "s", + "r", + "i", + "l", + "d", + "t", + "c", + "u", + "m", + "p", + "b", + "g", + "v", + "f", + "y", + "ó", + "h", + "q", + "í", + "j", + "z", + "á", + ], + "Russian": [ + "о", + "а", + "е", + "и", + "н", + "с", + "т", + "р", + "в", + "л", + "к", + "м", + "д", + "п", + "у", + "г", + "я", + "ы", + "з", + "б", + "й", + "ь", + "ч", + "х", + "ж", + "ц", + ], + # Jap-Kanji + "Japanese": [ + "人", + "一", + "大", + "亅", + "丁", + "丨", + "竹", + "笑", + "口", + "日", + "今", + "二", + "彳", + "行", + "十", + "土", + "丶", + "寸", + "寺", + "時", + "乙", + "丿", + "乂", + "气", + "気", + "冂", + "巾", + "亠", + "市", + "目", + "儿", + "見", + "八", + "小", + "凵", + "県", + "月", + "彐", + "門", + "間", + "木", + "東", + "山", + "出", + "本", + "中", + "刀", + "分", + "耳", + "又", + "取", + "最", + "言", + "田", + "心", + "思", + "刂", + "前", + "京", + "尹", + "事", + "生", + "厶", + "云", + "会", + "未", + "来", + "白", + "冫", + "楽", + "灬", + "馬", + "尸", + "尺", + "駅", + "明", + "耂", + "者", + "了", + "阝", + "都", + "高", + "卜", + "占", + "厂", + "广", + "店", + "子", + "申", + "奄", + "亻", + "俺", + "上", + "方", + "冖", + "学", + "衣", + "艮", + "食", + "自", + ], + # Jap-Katakana + "Japanese—": [ + "ー", + "ン", + "ス", + "・", + "ル", + "ト", + "リ", + "イ", + "ア", + "ラ", + "ッ", + "ク", + "ド", + "シ", + "レ", + "ジ", + "タ", + "フ", + "ロ", + "カ", + "テ", + "マ", + "ィ", + "グ", + "バ", + "ム", + "プ", + "オ", + "コ", + "デ", + "ニ", + "ウ", + "メ", + "サ", + "ビ", + "ナ", + "ブ", + "ャ", + "エ", + "ュ", + "チ", + "キ", + "ズ", + "ダ", + "パ", + "ミ", + "ェ", + "ョ", + "ハ", + "セ", + "ベ", + "ガ", + "モ", + "ツ", + "ネ", + "ボ", + "ソ", + "ノ", + "ァ", + "ヴ", + "ワ", + "ポ", + "ペ", + "ピ", + "ケ", + "ゴ", + "ギ", + "ザ", + "ホ", + "ゲ", + "ォ", + "ヤ", + "ヒ", + "ユ", + "ヨ", + "ヘ", + "ゼ", + "ヌ", + "ゥ", + "ゾ", + "ヶ", + "ヂ", + "ヲ", + "ヅ", + "ヵ", + "ヱ", + "ヰ", + "ヮ", + "ヽ", + "゠", + "ヾ", + "ヷ", + "ヿ", + "ヸ", + "ヹ", + "ヺ", + ], + # Jap-Hiragana + "Japanese——": [ + "の", + "に", + "る", + "た", + "と", + "は", + "し", + "い", + "を", + "で", + "て", + "が", + "な", + "れ", + "か", + "ら", + "さ", + "っ", + "り", + "す", + "あ", + "も", + "こ", + "ま", + "う", + "く", + "よ", + "き", + "ん", + "め", + "お", + "け", + "そ", + "つ", + "だ", + "や", + "え", + "ど", + "わ", + "ち", + "み", + "せ", + "じ", + "ば", + "へ", + "び", + "ず", + "ろ", + "ほ", + "げ", + "む", + "べ", + "ひ", + "ょ", + "ゆ", + "ぶ", + "ご", + "ゃ", + "ね", + "ふ", + "ぐ", + "ぎ", + "ぼ", + "ゅ", + "づ", + "ざ", + "ぞ", + "ぬ", + "ぜ", + "ぱ", + "ぽ", + "ぷ", + "ぴ", + "ぃ", + "ぁ", + "ぇ", + "ぺ", + "ゞ", + "ぢ", + "ぉ", + "ぅ", + "ゐ", + "ゝ", + "ゑ", + "゛", + "゜", + "ゎ", + "ゔ", + "゚", + "ゟ", + "゙", + "ゕ", + "ゖ", + ], + "Portuguese": [ + "a", + "e", + "o", + "s", + "i", + "r", + "d", + "n", + "t", + "m", + "u", + "c", + "l", + "p", + "g", + "v", + "b", + "f", + "h", + "ã", + "q", + "é", + "ç", + "á", + "z", + "í", + ], + "Swedish": [ + "e", + "a", + "n", + "r", + "t", + "s", + "i", + "l", + "d", + "o", + "m", + "k", + "g", + "v", + "h", + "f", + "u", + "p", + "ä", + "c", + "b", + "ö", + "å", + "y", + "j", + "x", + ], + "Chinese": [ + "的", + "一", + "是", + "不", + "了", + "在", + "人", + "有", + "我", + "他", + "这", + "个", + "们", + "中", + "来", + "上", + "大", + "为", + "和", + "国", + "地", + "到", + "以", + "说", + "时", + "要", + "就", + "出", + "会", + "可", + "也", + "你", + "对", + "生", + "能", + "而", + "子", + "那", + "得", + "于", + "着", + "下", + "自", + "之", + "年", + "过", + "发", + "后", + "作", + "里", + "用", + "道", + "行", + "所", + "然", + "家", + "种", + "事", + "成", + "方", + "多", + "经", + "么", + "去", + "法", + "学", + "如", + "都", + "同", + "现", + "当", + "没", + "动", + "面", + "起", + "看", + "定", + "天", + "分", + "还", + "进", + "好", + "小", + "部", + "其", + "些", + "主", + "样", + "理", + "心", + "她", + "本", + "前", + "开", + "但", + "因", + "只", + "从", + "想", + "实", + ], + "Ukrainian": [ + "о", + "а", + "н", + "і", + "и", + "р", + "в", + "т", + "е", + "с", + "к", + "л", + "у", + "д", + "м", + "п", + "з", + "я", + "ь", + "б", + "г", + "й", + "ч", + "х", + "ц", + "ї", + ], + "Norwegian": [ + "e", + "r", + "n", + "t", + "a", + "s", + "i", + "o", + "l", + "d", + "g", + "k", + "m", + "v", + "f", + "p", + "u", + "b", + "h", + "å", + "y", + "j", + "ø", + "c", + "æ", + "w", + ], + "Finnish": [ + "a", + "i", + "n", + "t", + "e", + "s", + "l", + "o", + "u", + "k", + "ä", + "m", + "r", + "v", + "j", + "h", + "p", + "y", + "d", + "ö", + "g", + "c", + "b", + "f", + "w", + "z", + ], + "Vietnamese": [ + "n", + "h", + "t", + "i", + "c", + "g", + "a", + "o", + "u", + "m", + "l", + "r", + "à", + "đ", + "s", + "e", + "v", + "p", + "b", + "y", + "ư", + "d", + "á", + "k", + "ộ", + "ế", + ], + "Czech": [ + "o", + "e", + "a", + "n", + "t", + "s", + "i", + "l", + "v", + "r", + "k", + "d", + "u", + "m", + "p", + "í", + "c", + "h", + "z", + "á", + "y", + "j", + "b", + "ě", + "é", + "ř", + ], + "Hungarian": [ + "e", + "a", + "t", + "l", + "s", + "n", + "k", + "r", + "i", + "o", + "z", + "á", + "é", + "g", + "m", + "b", + "y", + "v", + "d", + "h", + "u", + "p", + "j", + "ö", + "f", + "c", + ], + "Korean": [ + "이", + "다", + "에", + "의", + "는", + "로", + "하", + "을", + "가", + "고", + "지", + "서", + "한", + "은", + "기", + "으", + "년", + "대", + "사", + "시", + "를", + "리", + "도", + "인", + "스", + "일", + ], + "Indonesian": [ + "a", + "n", + "e", + "i", + "r", + "t", + "u", + "s", + "d", + "k", + "m", + "l", + "g", + "p", + "b", + "o", + "h", + "y", + "j", + "c", + "w", + "f", + "v", + "z", + "x", + "q", + ], + "Turkish": [ + "a", + "e", + "i", + "n", + "r", + "l", + "ı", + "k", + "d", + "t", + "s", + "m", + "y", + "u", + "o", + "b", + "ü", + "ş", + "v", + "g", + "z", + "h", + "c", + "p", + "ç", + "ğ", + ], + "Romanian": [ + "e", + "i", + "a", + "r", + "n", + "t", + "u", + "l", + "o", + "c", + "s", + "d", + "p", + "m", + "ă", + "f", + "v", + "î", + "g", + "b", + "ș", + "ț", + "z", + "h", + "â", + "j", + ], + "Farsi": [ + "ا", + "ی", + "ر", + "د", + "ن", + "ه", + "و", + "م", + "ت", + "ب", + "س", + "ل", + "ک", + "ش", + "ز", + "ف", + "گ", + "ع", + "خ", + "ق", + "ج", + "آ", + "پ", + "ح", + "ط", + "ص", + ], + "Arabic": [ + "ا", + "ل", + "ي", + "م", + "و", + "ن", + "ر", + "ت", + "ب", + "ة", + "ع", + "د", + "س", + "ف", + "ه", + "ك", + "ق", + "أ", + "ح", + "ج", + "ش", + "ط", + "ص", + "ى", + "خ", + "إ", + ], + "Danish": [ + "e", + "r", + "n", + "t", + "a", + "i", + "s", + "d", + "l", + "o", + "g", + "m", + "k", + "f", + "v", + "u", + "b", + "h", + "p", + "å", + "y", + "ø", + "æ", + "c", + "j", + "w", + ], + "Serbian": [ + "а", + "и", + "о", + "е", + "н", + "р", + "с", + "у", + "т", + "к", + "ј", + "в", + "д", + "м", + "п", + "л", + "г", + "з", + "б", + "a", + "i", + "e", + "o", + "n", + "ц", + "ш", + ], + "Lithuanian": [ + "i", + "a", + "s", + "o", + "r", + "e", + "t", + "n", + "u", + "k", + "m", + "l", + "p", + "v", + "d", + "j", + "g", + "ė", + "b", + "y", + "ų", + "š", + "ž", + "c", + "ą", + "į", + ], + "Slovene": [ + "e", + "a", + "i", + "o", + "n", + "r", + "s", + "l", + "t", + "j", + "v", + "k", + "d", + "p", + "m", + "u", + "z", + "b", + "g", + "h", + "č", + "c", + "š", + "ž", + "f", + "y", + ], + "Slovak": [ + "o", + "a", + "e", + "n", + "i", + "r", + "v", + "t", + "s", + "l", + "k", + "d", + "m", + "p", + "u", + "c", + "h", + "j", + "b", + "z", + "á", + "y", + "ý", + "í", + "č", + "é", + ], + "Hebrew": [ + "י", + "ו", + "ה", + "ל", + "ר", + "ב", + "ת", + "מ", + "א", + "ש", + "נ", + "ע", + "ם", + "ד", + "ק", + "ח", + "פ", + "ס", + "כ", + "ג", + "ט", + "צ", + "ן", + "ז", + "ך", + ], + "Bulgarian": [ + "а", + "и", + "о", + "е", + "н", + "т", + "р", + "с", + "в", + "л", + "к", + "д", + "п", + "м", + "з", + "г", + "я", + "ъ", + "у", + "б", + "ч", + "ц", + "й", + "ж", + "щ", + "х", + ], + "Croatian": [ + "a", + "i", + "o", + "e", + "n", + "r", + "j", + "s", + "t", + "u", + "k", + "l", + "v", + "d", + "m", + "p", + "g", + "z", + "b", + "c", + "č", + "h", + "š", + "ž", + "ć", + "f", + ], + "Hindi": [ + "क", + "र", + "स", + "न", + "त", + "म", + "ह", + "प", + "य", + "ल", + "व", + "ज", + "द", + "ग", + "ब", + "श", + "ट", + "अ", + "ए", + "थ", + "भ", + "ड", + "च", + "ध", + "ष", + "इ", + ], + "Estonian": [ + "a", + "i", + "e", + "s", + "t", + "l", + "u", + "n", + "o", + "k", + "r", + "d", + "m", + "v", + "g", + "p", + "j", + "h", + "ä", + "b", + "õ", + "ü", + "f", + "c", + "ö", + "y", + ], + "Thai": [ + "า", + "น", + "ร", + "อ", + "ก", + "เ", + "ง", + "ม", + "ย", + "ล", + "ว", + "ด", + "ท", + "ส", + "ต", + "ะ", + "ป", + "บ", + "ค", + "ห", + "แ", + "จ", + "พ", + "ช", + "ข", + "ใ", + ], + "Greek": [ + "α", + "τ", + "ο", + "ι", + "ε", + "ν", + "ρ", + "σ", + "κ", + "η", + "π", + "ς", + "υ", + "μ", + "λ", + "ί", + "ό", + "ά", + "γ", + "έ", + "δ", + "ή", + "ω", + "χ", + "θ", + "ύ", + ], + "Tamil": [ + "க", + "த", + "ப", + "ட", + "ர", + "ம", + "ல", + "ன", + "வ", + "ற", + "ய", + "ள", + "ச", + "ந", + "இ", + "ண", + "அ", + "ஆ", + "ழ", + "ங", + "எ", + "உ", + "ஒ", + "ஸ", + ], + "Kazakh": [ + "а", + "ы", + "е", + "н", + "т", + "р", + "л", + "і", + "д", + "с", + "м", + "қ", + "к", + "о", + "б", + "и", + "у", + "ғ", + "ж", + "ң", + "з", + "ш", + "й", + "п", + "г", + "ө", + ], +} + +LANGUAGE_SUPPORTED_COUNT: int = len(FREQUENCIES) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/legacy.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/legacy.py new file mode 100644 index 0000000..43aad21 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/legacy.py @@ -0,0 +1,54 @@ +from typing import Any, Dict, Optional, Union +from warnings import warn + +from .api import from_bytes +from .constant import CHARDET_CORRESPONDENCE + + +def detect( + byte_str: bytes, should_rename_legacy: bool = False, **kwargs: Any +) -> Dict[str, Optional[Union[str, float]]]: + """ + chardet legacy method + Detect the encoding of the given byte string. It should be mostly backward-compatible. + Encoding name will match Chardet own writing whenever possible. (Not on encoding name unsupported by it) + This function is deprecated and should be used to migrate your project easily, consult the documentation for + further information. Not planned for removal. + + :param byte_str: The byte sequence to examine. + :param should_rename_legacy: Should we rename legacy encodings + to their more modern equivalents? + """ + if len(kwargs): + warn( + f"charset-normalizer disregard arguments '{','.join(list(kwargs.keys()))}' in legacy function detect()" + ) + + if not isinstance(byte_str, (bytearray, bytes)): + raise TypeError( # pragma: nocover + "Expected object of type bytes or bytearray, got: " + "{0}".format(type(byte_str)) + ) + + if isinstance(byte_str, bytearray): + byte_str = bytes(byte_str) + + r = from_bytes(byte_str).best() + + encoding = r.encoding if r is not None else None + language = r.language if r is not None and r.language != "Unknown" else "" + confidence = 1.0 - r.chaos if r is not None else None + + # Note: CharsetNormalizer does not return 'UTF-8-SIG' as the sig get stripped in the detection/normalization process + # but chardet does return 'utf-8-sig' and it is a valid codec name. + if r is not None and encoding == "utf_8" and r.bom: + encoding += "_sig" + + if should_rename_legacy is False and encoding in CHARDET_CORRESPONDENCE: + encoding = CHARDET_CORRESPONDENCE[encoding] + + return { + "encoding": encoding, + "language": language, + "confidence": confidence, + } diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md.cpython-312-x86_64-linux-gnu.so b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md.cpython-312-x86_64-linux-gnu.so new file mode 100755 index 0000000000000000000000000000000000000000..3d0b46ae77baa966a03418d61fbd1da9d141366e GIT binary patch literal 16064 zcmeHOZ)_Y_5r3D9n@b&Rlh!4Tk+O{vDM937yCe++C+GOz8riNf4h@KCyS_c=4(^ZH zTL)h%fvdELkVdjVNVFfILPAtUMePTwQUr3^QX;<40v`ZT$wH*ETSOBGmHCom=Dqh@ z@2<}Q35hS=XL)DlH#2YE&hFcryM6B~10#c*5($Bp6vqTh3vCL?Kyd_&5E*eqY^7s| z*ePu{uc_8^w`mAe_scPwSf%ACy{v}>3O&Ozp25!440-hFsun?memsQL1Il2vCrrmT zDfyJ9@MDqv+R{qjb}UR^)8hn9DYYCUkMoG`FG}}lJ5YH}gpFVI9Oge~D1#`4Jt+J> zNq$JN^1SsCX`j&XHp)v%j~`T@t~|dxDMXU~hsI8d$L}~@>-fceKRmVLd%O4j>H5KA zZr3wB0@ia**iVjcK0_C9Om@Tg?ezcm$9`7-$))QpZ~gY2mglZMKSa=m?SrH-8fd>k z7|toEes}|%2VevZHU9;ojr!r+-_SNeGC{)bAfS1h=yuU8#^0}i2QQN44RV*n zw}}_Dy*3x$k$AIsR^xKcu+p;5lqzMb>e;SmS;8um3!bp1i3n?Wa@2BiZthH>>gC+Y z(Y|7(oSU?#iaDigtg*6lHg{kb3+HlTyf#cdS|x|M(oBV-C^A}cW~rm`TAw{rB~HV_ z8n0RXIlEY_WZ`VdQPJp%g{c`Y@8)bLU9F@$SF;dTL3)2;e+t(Dr2%$M(UvodMjxC&=bV0Qb+C@Js*?j)zoni!%^s zAkILXfj9$k2I36F8F&w6z&!uglzFk~je|m%k1l#m%SY+t&GWCMURFt{ANn(?>U;k} z$JSjL;#khJa%HJbZSNmh=2Cg(H7WmwWiD-37Nz_vmbs)|c~;6VvCO6H%9B!lk!3Dn zR~AS%FZDb}fO)CuX(k_C_1bB8hnc70ZLKf0?wTiC@v^35|FE<_bdJgXo92aU=Ho>hSse>lnL8`tq-MXuP&40e9msDc*;7Rj*&zt-u-@I_u+eY2K^29)1oJL&Gm4`?d0~rZbiGRFmcL2x+kaT-T9g-q2CV|D{FHDWC11C-%Or!x zhd2Xq2I36F8Hh6wXCTf%oPjt4aR%ZH#2JV)uu%rGdE2e#JgZ!BOY+5^n=Uz)RjSR@ zvg~s!eVX4nTI($=@^{EL(UClA5alobue?*Qf1K!zYxO$oCa>4){Ee31A#+Qdn-Gb) zwnWFaEvW_iHDM27{H}MN{ASporERcf$0u5wzm%F6$9Eq6(7k(hGt4&q^#3*LSH5HI zZ)tnz_LkIe^H>YN|Kj(B9PbM0gYU@*id&q4I0JD8;ta$Yh%*ppAkILXfj9$k2Hq1H z@YhF1)`7h=9o%UHL1x0bOUvqQ^Ri?|d1di^DTf8z%IKX2A6 zEI-I^kg4H2+Y9_9k{Z@nep~B#{V=!RDMBl5RokJdcB2K53eaw1LF@7T6Kf(rpz#?U z82FXVN`Y}crR``Ds%(fyZ)fHBpVId93Rud>BYh2(@?%>6FD?7y)cyUx2-dSl;~mxu zZ3i{|w5HRVp4IfLnhy2#eazTLE5Y|0U7fU=x6A16?C$F9y0_EVH<5D;)24UcQgNWG zYkxFaSWeQ)TdbE4YLc{K7WYLMPYT=*VSKZ|eG|r;1o9uoZxgs~VSJ0g^$+7If%_zk zuV3HI`XsG(H*~(j_Rao&i!i=^J-F(JW}OkVRD4pj`1=Ne+N5X|^9}9W1m-LPV^nGXhEuW56f0A9(Q>?sTea-j zIgzcDW{Np4=g=mJh8A*%hh@92U9)m!&#j4R*DmEOXSP(TkxM{Qn=gWL@v7Bnf%G+g!H;43pW~_H~xQ|eJl3N3&HZ}Vv2%>!?a2gu9|3vSIb^qYt zrv@gi$=(wq1Ju>6ww(kvhp0^|>-Ud@H?(ZD>m;x%g@1kax0uN2|Ha0ZOeVPHL~WZ9 z>1wUy*;7P4SJ6DUa>dJ~&y;7=Q?rGlbD-b|Ddp{IUZkB`nLHKsT%|dibE}0)IV4!5 zb8|(T9W*yn^o0BYU8KF-9Px7NPTH+Fwr7iUF0U_T-XUK|%0pd#!05xcSa^twn!XNcohA{3M{-_r~QCE_QY`Qy$!X%DsJouxo z07V>(A9kQ8$)9UR$f!R+4IL>uehtfa8?1vr>J(7^9N>od(ep2pj{Q%t5jE5^pbH9? z{_Vs^{pSedoS-iEAM*NP@7MdfAC47lRT6^!hV}!U2^tfx)js`l#2=sgpnD@14F2f$ zk%&J&hd@!^!#+CxuWSEq7#Nz-^s~S-nYm+uHQ!cJ<&}x{*w{^c|%!(^7RQe z#0T~?Fk%G@3@lmg&{)0dI`!z9q z@4+8+DE8}OUoP^7xVR5~PrkwUs8^Q`stAT6{t^D5st#I(r%e|;K04*wvW81?@*j4k%f literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md.py new file mode 100644 index 0000000..77897aa --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md.py @@ -0,0 +1,615 @@ +from functools import lru_cache +from logging import getLogger +from typing import List, Optional + +from .constant import ( + COMMON_SAFE_ASCII_CHARACTERS, + TRACE, + UNICODE_SECONDARY_RANGE_KEYWORD, +) +from .utils import ( + is_accentuated, + is_arabic, + is_arabic_isolated_form, + is_case_variable, + is_cjk, + is_emoticon, + is_hangul, + is_hiragana, + is_katakana, + is_latin, + is_punctuation, + is_separator, + is_symbol, + is_thai, + is_unprintable, + remove_accent, + unicode_range, +) + + +class MessDetectorPlugin: + """ + Base abstract class used for mess detection plugins. + All detectors MUST extend and implement given methods. + """ + + def eligible(self, character: str) -> bool: + """ + Determine if given character should be fed in. + """ + raise NotImplementedError # pragma: nocover + + def feed(self, character: str) -> None: + """ + The main routine to be executed upon character. + Insert the logic in witch the text would be considered chaotic. + """ + raise NotImplementedError # pragma: nocover + + def reset(self) -> None: # pragma: no cover + """ + Permit to reset the plugin to the initial state. + """ + raise NotImplementedError + + @property + def ratio(self) -> float: + """ + Compute the chaos ratio based on what your feed() has seen. + Must NOT be lower than 0.; No restriction gt 0. + """ + raise NotImplementedError # pragma: nocover + + +class TooManySymbolOrPunctuationPlugin(MessDetectorPlugin): + def __init__(self) -> None: + self._punctuation_count: int = 0 + self._symbol_count: int = 0 + self._character_count: int = 0 + + self._last_printable_char: Optional[str] = None + self._frenzy_symbol_in_word: bool = False + + def eligible(self, character: str) -> bool: + return character.isprintable() + + def feed(self, character: str) -> None: + self._character_count += 1 + + if ( + character != self._last_printable_char + and character not in COMMON_SAFE_ASCII_CHARACTERS + ): + if is_punctuation(character): + self._punctuation_count += 1 + elif ( + character.isdigit() is False + and is_symbol(character) + and is_emoticon(character) is False + ): + self._symbol_count += 2 + + self._last_printable_char = character + + def reset(self) -> None: # pragma: no cover + self._punctuation_count = 0 + self._character_count = 0 + self._symbol_count = 0 + + @property + def ratio(self) -> float: + if self._character_count == 0: + return 0.0 + + ratio_of_punctuation: float = ( + self._punctuation_count + self._symbol_count + ) / self._character_count + + return ratio_of_punctuation if ratio_of_punctuation >= 0.3 else 0.0 + + +class TooManyAccentuatedPlugin(MessDetectorPlugin): + def __init__(self) -> None: + self._character_count: int = 0 + self._accentuated_count: int = 0 + + def eligible(self, character: str) -> bool: + return character.isalpha() + + def feed(self, character: str) -> None: + self._character_count += 1 + + if is_accentuated(character): + self._accentuated_count += 1 + + def reset(self) -> None: # pragma: no cover + self._character_count = 0 + self._accentuated_count = 0 + + @property + def ratio(self) -> float: + if self._character_count < 8: + return 0.0 + + ratio_of_accentuation: float = self._accentuated_count / self._character_count + return ratio_of_accentuation if ratio_of_accentuation >= 0.35 else 0.0 + + +class UnprintablePlugin(MessDetectorPlugin): + def __init__(self) -> None: + self._unprintable_count: int = 0 + self._character_count: int = 0 + + def eligible(self, character: str) -> bool: + return True + + def feed(self, character: str) -> None: + if is_unprintable(character): + self._unprintable_count += 1 + self._character_count += 1 + + def reset(self) -> None: # pragma: no cover + self._unprintable_count = 0 + + @property + def ratio(self) -> float: + if self._character_count == 0: + return 0.0 + + return (self._unprintable_count * 8) / self._character_count + + +class SuspiciousDuplicateAccentPlugin(MessDetectorPlugin): + def __init__(self) -> None: + self._successive_count: int = 0 + self._character_count: int = 0 + + self._last_latin_character: Optional[str] = None + + def eligible(self, character: str) -> bool: + return character.isalpha() and is_latin(character) + + def feed(self, character: str) -> None: + self._character_count += 1 + if ( + self._last_latin_character is not None + and is_accentuated(character) + and is_accentuated(self._last_latin_character) + ): + if character.isupper() and self._last_latin_character.isupper(): + self._successive_count += 1 + # Worse if its the same char duplicated with different accent. + if remove_accent(character) == remove_accent(self._last_latin_character): + self._successive_count += 1 + self._last_latin_character = character + + def reset(self) -> None: # pragma: no cover + self._successive_count = 0 + self._character_count = 0 + self._last_latin_character = None + + @property + def ratio(self) -> float: + if self._character_count == 0: + return 0.0 + + return (self._successive_count * 2) / self._character_count + + +class SuspiciousRange(MessDetectorPlugin): + def __init__(self) -> None: + self._suspicious_successive_range_count: int = 0 + self._character_count: int = 0 + self._last_printable_seen: Optional[str] = None + + def eligible(self, character: str) -> bool: + return character.isprintable() + + def feed(self, character: str) -> None: + self._character_count += 1 + + if ( + character.isspace() + or is_punctuation(character) + or character in COMMON_SAFE_ASCII_CHARACTERS + ): + self._last_printable_seen = None + return + + if self._last_printable_seen is None: + self._last_printable_seen = character + return + + unicode_range_a: Optional[str] = unicode_range(self._last_printable_seen) + unicode_range_b: Optional[str] = unicode_range(character) + + if is_suspiciously_successive_range(unicode_range_a, unicode_range_b): + self._suspicious_successive_range_count += 1 + + self._last_printable_seen = character + + def reset(self) -> None: # pragma: no cover + self._character_count = 0 + self._suspicious_successive_range_count = 0 + self._last_printable_seen = None + + @property + def ratio(self) -> float: + if self._character_count <= 24: + return 0.0 + + ratio_of_suspicious_range_usage: float = ( + self._suspicious_successive_range_count * 2 + ) / self._character_count + + return ratio_of_suspicious_range_usage + + +class SuperWeirdWordPlugin(MessDetectorPlugin): + def __init__(self) -> None: + self._word_count: int = 0 + self._bad_word_count: int = 0 + self._foreign_long_count: int = 0 + + self._is_current_word_bad: bool = False + self._foreign_long_watch: bool = False + + self._character_count: int = 0 + self._bad_character_count: int = 0 + + self._buffer: str = "" + self._buffer_accent_count: int = 0 + + def eligible(self, character: str) -> bool: + return True + + def feed(self, character: str) -> None: + if character.isalpha(): + self._buffer += character + if is_accentuated(character): + self._buffer_accent_count += 1 + if ( + self._foreign_long_watch is False + and (is_latin(character) is False or is_accentuated(character)) + and is_cjk(character) is False + and is_hangul(character) is False + and is_katakana(character) is False + and is_hiragana(character) is False + and is_thai(character) is False + ): + self._foreign_long_watch = True + return + if not self._buffer: + return + if ( + character.isspace() or is_punctuation(character) or is_separator(character) + ) and self._buffer: + self._word_count += 1 + buffer_length: int = len(self._buffer) + + self._character_count += buffer_length + + if buffer_length >= 4: + if self._buffer_accent_count / buffer_length > 0.34: + self._is_current_word_bad = True + # Word/Buffer ending with an upper case accentuated letter are so rare, + # that we will consider them all as suspicious. Same weight as foreign_long suspicious. + if ( + is_accentuated(self._buffer[-1]) + and self._buffer[-1].isupper() + and all(_.isupper() for _ in self._buffer) is False + ): + self._foreign_long_count += 1 + self._is_current_word_bad = True + if buffer_length >= 24 and self._foreign_long_watch: + camel_case_dst = [ + i + for c, i in zip(self._buffer, range(0, buffer_length)) + if c.isupper() + ] + probable_camel_cased: bool = False + + if camel_case_dst and (len(camel_case_dst) / buffer_length <= 0.3): + probable_camel_cased = True + + if not probable_camel_cased: + self._foreign_long_count += 1 + self._is_current_word_bad = True + + if self._is_current_word_bad: + self._bad_word_count += 1 + self._bad_character_count += len(self._buffer) + self._is_current_word_bad = False + + self._foreign_long_watch = False + self._buffer = "" + self._buffer_accent_count = 0 + elif ( + character not in {"<", ">", "-", "=", "~", "|", "_"} + and character.isdigit() is False + and is_symbol(character) + ): + self._is_current_word_bad = True + self._buffer += character + + def reset(self) -> None: # pragma: no cover + self._buffer = "" + self._is_current_word_bad = False + self._foreign_long_watch = False + self._bad_word_count = 0 + self._word_count = 0 + self._character_count = 0 + self._bad_character_count = 0 + self._foreign_long_count = 0 + + @property + def ratio(self) -> float: + if self._word_count <= 10 and self._foreign_long_count == 0: + return 0.0 + + return self._bad_character_count / self._character_count + + +class CjkInvalidStopPlugin(MessDetectorPlugin): + """ + GB(Chinese) based encoding often render the stop incorrectly when the content does not fit and + can be easily detected. Searching for the overuse of '丅' and '丄'. + """ + + def __init__(self) -> None: + self._wrong_stop_count: int = 0 + self._cjk_character_count: int = 0 + + def eligible(self, character: str) -> bool: + return True + + def feed(self, character: str) -> None: + if character in {"丅", "丄"}: + self._wrong_stop_count += 1 + return + if is_cjk(character): + self._cjk_character_count += 1 + + def reset(self) -> None: # pragma: no cover + self._wrong_stop_count = 0 + self._cjk_character_count = 0 + + @property + def ratio(self) -> float: + if self._cjk_character_count < 16: + return 0.0 + return self._wrong_stop_count / self._cjk_character_count + + +class ArchaicUpperLowerPlugin(MessDetectorPlugin): + def __init__(self) -> None: + self._buf: bool = False + + self._character_count_since_last_sep: int = 0 + + self._successive_upper_lower_count: int = 0 + self._successive_upper_lower_count_final: int = 0 + + self._character_count: int = 0 + + self._last_alpha_seen: Optional[str] = None + self._current_ascii_only: bool = True + + def eligible(self, character: str) -> bool: + return True + + def feed(self, character: str) -> None: + is_concerned = character.isalpha() and is_case_variable(character) + chunk_sep = is_concerned is False + + if chunk_sep and self._character_count_since_last_sep > 0: + if ( + self._character_count_since_last_sep <= 64 + and character.isdigit() is False + and self._current_ascii_only is False + ): + self._successive_upper_lower_count_final += ( + self._successive_upper_lower_count + ) + + self._successive_upper_lower_count = 0 + self._character_count_since_last_sep = 0 + self._last_alpha_seen = None + self._buf = False + self._character_count += 1 + self._current_ascii_only = True + + return + + if self._current_ascii_only is True and character.isascii() is False: + self._current_ascii_only = False + + if self._last_alpha_seen is not None: + if (character.isupper() and self._last_alpha_seen.islower()) or ( + character.islower() and self._last_alpha_seen.isupper() + ): + if self._buf is True: + self._successive_upper_lower_count += 2 + self._buf = False + else: + self._buf = True + else: + self._buf = False + + self._character_count += 1 + self._character_count_since_last_sep += 1 + self._last_alpha_seen = character + + def reset(self) -> None: # pragma: no cover + self._character_count = 0 + self._character_count_since_last_sep = 0 + self._successive_upper_lower_count = 0 + self._successive_upper_lower_count_final = 0 + self._last_alpha_seen = None + self._buf = False + self._current_ascii_only = True + + @property + def ratio(self) -> float: + if self._character_count == 0: + return 0.0 + + return self._successive_upper_lower_count_final / self._character_count + + +class ArabicIsolatedFormPlugin(MessDetectorPlugin): + def __init__(self) -> None: + self._character_count: int = 0 + self._isolated_form_count: int = 0 + + def reset(self) -> None: # pragma: no cover + self._character_count = 0 + self._isolated_form_count = 0 + + def eligible(self, character: str) -> bool: + return is_arabic(character) + + def feed(self, character: str) -> None: + self._character_count += 1 + + if is_arabic_isolated_form(character): + self._isolated_form_count += 1 + + @property + def ratio(self) -> float: + if self._character_count < 8: + return 0.0 + + isolated_form_usage: float = self._isolated_form_count / self._character_count + + return isolated_form_usage + + +@lru_cache(maxsize=1024) +def is_suspiciously_successive_range( + unicode_range_a: Optional[str], unicode_range_b: Optional[str] +) -> bool: + """ + Determine if two Unicode range seen next to each other can be considered as suspicious. + """ + if unicode_range_a is None or unicode_range_b is None: + return True + + if unicode_range_a == unicode_range_b: + return False + + if "Latin" in unicode_range_a and "Latin" in unicode_range_b: + return False + + if "Emoticons" in unicode_range_a or "Emoticons" in unicode_range_b: + return False + + # Latin characters can be accompanied with a combining diacritical mark + # eg. Vietnamese. + if ("Latin" in unicode_range_a or "Latin" in unicode_range_b) and ( + "Combining" in unicode_range_a or "Combining" in unicode_range_b + ): + return False + + keywords_range_a, keywords_range_b = unicode_range_a.split( + " " + ), unicode_range_b.split(" ") + + for el in keywords_range_a: + if el in UNICODE_SECONDARY_RANGE_KEYWORD: + continue + if el in keywords_range_b: + return False + + # Japanese Exception + range_a_jp_chars, range_b_jp_chars = ( + unicode_range_a + in ( + "Hiragana", + "Katakana", + ), + unicode_range_b in ("Hiragana", "Katakana"), + ) + if (range_a_jp_chars or range_b_jp_chars) and ( + "CJK" in unicode_range_a or "CJK" in unicode_range_b + ): + return False + if range_a_jp_chars and range_b_jp_chars: + return False + + if "Hangul" in unicode_range_a or "Hangul" in unicode_range_b: + if "CJK" in unicode_range_a or "CJK" in unicode_range_b: + return False + if unicode_range_a == "Basic Latin" or unicode_range_b == "Basic Latin": + return False + + # Chinese/Japanese use dedicated range for punctuation and/or separators. + if ("CJK" in unicode_range_a or "CJK" in unicode_range_b) or ( + unicode_range_a in ["Katakana", "Hiragana"] + and unicode_range_b in ["Katakana", "Hiragana"] + ): + if "Punctuation" in unicode_range_a or "Punctuation" in unicode_range_b: + return False + if "Forms" in unicode_range_a or "Forms" in unicode_range_b: + return False + if unicode_range_a == "Basic Latin" or unicode_range_b == "Basic Latin": + return False + + return True + + +@lru_cache(maxsize=2048) +def mess_ratio( + decoded_sequence: str, maximum_threshold: float = 0.2, debug: bool = False +) -> float: + """ + Compute a mess ratio given a decoded bytes sequence. The maximum threshold does stop the computation earlier. + """ + + detectors: List[MessDetectorPlugin] = [ + md_class() for md_class in MessDetectorPlugin.__subclasses__() + ] + + length: int = len(decoded_sequence) + 1 + + mean_mess_ratio: float = 0.0 + + if length < 512: + intermediary_mean_mess_ratio_calc: int = 32 + elif length <= 1024: + intermediary_mean_mess_ratio_calc = 64 + else: + intermediary_mean_mess_ratio_calc = 128 + + for character, index in zip(decoded_sequence + "\n", range(length)): + for detector in detectors: + if detector.eligible(character): + detector.feed(character) + + if ( + index > 0 and index % intermediary_mean_mess_ratio_calc == 0 + ) or index == length - 1: + mean_mess_ratio = sum(dt.ratio for dt in detectors) + + if mean_mess_ratio >= maximum_threshold: + break + + if debug: + logger = getLogger("charset_normalizer") + + logger.log( + TRACE, + "Mess-detector extended-analysis start. " + f"intermediary_mean_mess_ratio_calc={intermediary_mean_mess_ratio_calc} mean_mess_ratio={mean_mess_ratio} " + f"maximum_threshold={maximum_threshold}", + ) + + if len(decoded_sequence) > 16: + logger.log(TRACE, f"Starting with: {decoded_sequence[:16]}") + logger.log(TRACE, f"Ending with: {decoded_sequence[-16::]}") + + for dt in detectors: # pragma: nocover + logger.log(TRACE, f"{dt.__class__}: {dt.ratio}") + + return round(mean_mess_ratio, 3) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md__mypyc.cpython-312-x86_64-linux-gnu.so b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/md__mypyc.cpython-312-x86_64-linux-gnu.so new file mode 100755 index 0000000000000000000000000000000000000000..e3044d9abd70dd87a4a1262fa53e3fb0b434d993 GIT binary patch literal 272640 zcmeFa33yZ0*8hLXpb^1D6sa_e$F~; zuRWf9_Bm~r9a?Pw4)c;gaXI zy5*-j4^zSO8cvt?4HLV6wo}omPYa!nG2)&_F||G2vYp0t#e#_MBG`|!4bJzLXCZWuk*X}Qj6 zSPpht+z(B9rbquiOAY&qf20gr+4JsRVJEhggG>4!<_tM(>F&xYSv`zEip{v^m=m03 z0mC@g>AWoK+CC`_mOy=vE6a>2&bn#EgU9Z7={YlFy;41q{zk7aQuZ5h__QbYNwKFJ zeR?fTainapWiJie4-TaK*w7=_ZF8j?vy4$ao;P|J2YRyVdJVDkxS^LZc;D20nvIox zQWpG}->c^xN1q?M$I|Y(^1!1f_FC5~&}&o=yK|dm>>>934C7$iA%<^_>&dEK2Nn-Z zwXGdLs+XllMrg$u`&_wnLVv^FJCJVJ9at70!ybkG6WICoDTvQt{{r@}V2{DR4fgG@ zKiI9X z+h9Ks_WrOBfSqrLf=-3~FxUseegy1C!hRI&gJ4gC9k(I$ITSvJ(Rbv->HCTFITAic z!G0?2r@@{H`{}Tch8?#v>C;J{S@by$K679n5BmgSx$rrWzURT`Wcq#%e7a$u2K#hk zGvG5H_6td0M4y=E#qhn5=~?i-h_n|zi(#J!dnvIp_^g242fH8k`LNf(z7Y0BurG%F z3fPyx9)SHy*lS_u+f|^ihJ6|A*T5cv{W{ohfc-|;Z-V`1*qdO#1$NwSr%(KT2YkPi zX=Gv2_rmA>us;C%gRnmY`@^t53j5=*3_iI)3857`k(OG3j6c0zX1D- zu;ca;eXgZXWb5Jk2GSehvyHxQg3nj!`y2F$_M6%FH{ttROylu)LBFrDk4S$EpP#_~ z1?dj>+y?tMu|Mln!RK%E{df4>4SNa@B2TTl4D57Wr^C2fJv z{b26{dq3C@fSqqv&)CjuGDu z`Tg$HmER2RAH4an*S6>Uym`(3KU{p>8RrdpeDgI$h3ON&JmSlu6W8^gv7)#kXT{6+ zKX$vl=Khbq`R)zxpk9uXZ@etJ_Pv?=^{YF)p>;!j_4F$T{P9lv2V-9=hm5XBR|>SO4-zF{EW1>-hT9<-p%=~Gbg@&z!OjY zSl0N}qivrbylTG%??1Qr@xD(uU#iYtbi|$&~ ze&h{zRnEQqhhg^~SUqy*Z70rL=pg_OjgZkYXc;SPU zcE@=K?Cd}9nc<(@@zn2+-S*Huqt{>f(cC-oPJ7|1nKLixJ?5iH>z)o+vaWpnjkHsL z&Fisz+L(q*|2gEns&8T`wIfc;ExY1{GZy5mxcSt%zt{cPf5iA#ADDFN+ZDCdt&jfr z*{egU&N*~+YH?QCHIG+5yY;Z>u}2Q7xoXAJGm5%SUH{=7`$8M2d-mY_w(RHqy*}!= zy3;@H>C>*c@|`&Y295dRpbh)<9J1=F@Q77KbHBdv=%aUL9J?*&pIeuG^~v;=XHEQY z$Le{1Y=;`=omh-g4E9qgr2o!E(rLpFdf0z-{MUbJ@OsY&hhnz6V|K zucJ4{-o9yU@uk~-DVlakQP)G>ewV#}>s5!}`r#i-7d+5!+0)TUyFdDB^Ho`)SY_Q z?fYN$>C|uL54C-L@L5$^!E=hd(~l1Be_8qSSNySY`?XixH1_Cz-`#t&@5bAvoSy^b zc;dOYO&#^|k)4aadM!BR;2*wyv+E4+bCbu_KY7-X3^LJn{FOYbJg$xUlMvZ@##)>+^0uXT|p3fm~1Joult6sJ`lR$2H%db?2FH_xthO ziB&lZcig*U{iv~ljFQ^duKUPmzvHBpeJ9Vm-gjQX;)_NM`(~v-BPBC^bl#NPJkGM3 zZ)%@v-MZ$w_FcWdYMj;4ySJsNtM7x4-SGJG=+4JBJh?Ow+VRYRKP>8)H{{*EcYJ>N z`qbJN(|udA7SBnX~_}K5yRL%Nq-K>)5zx(8; zM_#(_$7lBa>7vbDZ~pegpnI2uo}Kq*&*x6KeBm$lFT0%Iz4c4(@_%@M6bc?3@+PtbVaqkL_=a+WgaiA=YU;sHi_r_Lz4Sh1e5Dz>1H1a^D|xm z^!>^MliMEw$L&e%Z#Ic%?Xhs}N@9Q6u;l(9HK~_fCgt-T#Gfo*(;?ktyf@q=CgV1f zdb#_scy*DR{ypJeUuPLuLX zg_W3O@k}u(=Orfbzi3jPVUzOj4HwyD=`J&A|5YaKJlAAgy4a-s_cV!fs!6?nZj$Z? zCjHlH;(w4yKe`F#4#~;^Z?~a{_Shab>8E#?w71tx#<60PasDln>-a_!``1nS#iJ(e z^C6S*aIi^xJJzKAj5qPKeBb2d=`iU>vrkBFKg6V69b?i?#+dkDWD?IlCjJ{t%JX&; zKVwYhw{Mt~TMSxMviA0|$vos5lX@Ru(*AFO33M|5A(M7%Hz~JGCfE0vN%`DmQZMZ$ z^OK8A%Cp_1-F{~hf5fER947t!0h98Nn2c9tCiVD?N%{Lt#-E`k{!cUUKf#)GZiijpCY#jD119q;uSuLWCjEDY$vE(dNjW!~wC9h_ z=8Y!hUun`Gk1!b@wwsjm6ezI4dZB^7-sHZu*`(b*m7cu)l$cx>UNM@-RD1C#i# zGb#T=O#FOi(r(9_)XP~W?O}%rKM~qLROKF9$fO=?O|FAwChhi07{~g<6YIcvICC|O z3N7RzH;6o?a20?$oZQbFLNAH$AgZxxL zBSAk=e2@j(JK}$MAAoqMQ}P#yKi7xshf5CCA-2&l&p|&eCrDmTd>FJV-6m zQhP8OC0FtPo5qt)8c)t9KZip+7{6nzv>yrUEVw-a<0^7DbzC@IY~vvequ#7k1 zJ`3X%FDZZz)eaAXhAr}iFDAf7!=jNx<5d7(W`IqNlix!7IS|eW<#r!`GU2)={Ci}% zEf;4Q#(jrK9+)fr%qD(6^`pQE(*7iiJm8@A(4v*wr_kUcY58mS`9<4pcs9tQVy4%m9diRATSM~KCwP*W9 zvYg+SAI321rygv;uuUdzrEw#SFKEElm+EB^wG%tNxT4BuBH84gCzc?Ka8PIQEAcPx2(MlkSZ(X&md+#<9#3PHV!y3yOE|7*$rEp&Ye(+g9xBHs9ixf7h65W>7h7P`7~4cv`m!o%p?1|21q{!zE}m@eBzH% zyK-DB>sO8cW2jy{&q;e#zjMitlL`Rm8MxtlN*Jey;v6Tj@gTL&D8BdvoAOf&@%bt8^PU=)TBRS=PVT4qN&9@s*OL9B{bf8(x(+TQ{yeoq+Z1WPfp{C0 zrw?E7f=!j@Vk*xlUBAYY{YvNum|sVlv>!tphaKeYG|;O0I;fYdUze8O)Ayrtqj?21 z53wCWHQ@KU8di)ixBiOE5wREo``@r(<^}dAKd59*+ zJ>{@&TuyP?(q$miDBb62{14Fh55*<6-=N=PIoN4@Q`h~=Vg8TYeUbFDlkDwO{`OlX z|Acr13Pjjbe*w2*vp~~99-;Q^B7Tsn-$~L>7V()BkLP&Fsd|iGMg0AYXuB*22iX_G zC;AV6F2M-mVVbx2PLuY>NO#8j)DE2sBv?lF1NuroHhcjSHr1Z*qjE3`Bp*WdyXd+c zdPwp@`C-gd_eV1%xQOh}AU_eB@Lol{liGiPu4^U4_oaD@ljgl@-uO={&rZ57A4B%V z)PFsX$#kEmcmh<;oiv`GO!hTUELd*#uO(3Bu-#7e^_g^_=AW+(lHAiFITe%PrS=e_ z@n7}R=b$~J|CVp1f7MUlp?Ylom#i1MOc`%d|Mi_M{i|^)K>aI1F?;a}ot(4y(RKM*Mcmwet==$rqSK6!bs+8)>eWB#4{X6%ia-fM`P9N!LHDm!WdIEBRkR9qB zqcnbI6F-#dJ+fT_)n9@tzZXkC1!R8;m751&N`|e7cu(S;)NY|!itPfr9(B_7h`PP; zE!A&?>bI5bf24Fn9_e3|!$~j>V|hk)NJG_rei$Tq6klqEP1V=eP!DKt&^QLoQfzn9 zxYRyNwl^q7xj{!pdmG&ks($@DTnLbd#!3HWWWJcv?fgpecZkCq_rkuD$`ei(+pAPQ z0d3vmGYA0Z;b9twV`Lwoamh~C#|McYO6B9w#*Hr^47^@M)%60(3pZbyj3-Jj(W?HN zLjG-KGX969xv`%5OAB2uRDXGs`d9dTX|KjBtmpnlUt|5vvOLL+@dBkA87lclbl?D} z2#hnL;w1hUwNEGYi}l3&o`ClK3_G>+0P%TLo}rUuJgU9jW2gK^C0F%gA4Yt(jK@oU zhEu+x)W22|$LnE#`01Va&)X31Mdf3s>ppZhu{})loEDl_lRIN$Kbfv=jErYF)yt8C zCAWVqc|G}QpmEzy^Db3i*HAl*(tRR?A+{OHKdqlYcEpxRJanq`KZAIf`lEU=U6s#F zTIVs&l;v{;*^g1<_BRr!em8;qcandV?*3Gs5h?)4j@WLX@^=TN|124nQK`zGu8*p{ z6{zv&0%^FD{N&L1=A`jW&4>R<*G>0{(*AL>pAG#B`)~L3QdEgeg`k@r4Zn2G}eiyBl>0V8ICbj2I8dq;2{yFud z@Gu#FDe>_`rT-A!r&F~V2OJ}L^n2<5OtL?M>OHVpa#imy(e=ec^_5NbtLeJda>LH*(O82LBI|73}c1-+$z+s_j0Lwqo}#d3>MMIAsq-!8d9KR_}?CU4B3@i{zM zf{nxvq;}#QAb}bOK2`0Iepp1s?t_)5v&kl6T8&BtiMGLraU8lRny$oN%zyOP?c zd${D&$o^I+Sd6oiItqj*wyxtP53P{ts&UCnE}VR-*t$zx6^tB6r4%z~@e$Q;lNYsU)yP(c@FuXeVmLxKm%tT+4mhHxs&FBgUJ3c8YkU!|5Z+W9CRqG-*A@%50jrS zA>+v1-${^5{2;Qoll>C%Glk;xkRc3fVta_%RSUH%Xf|RyjK*R6^|Jggf^iMEQ_0>q zUM8s8VILY--PC>-OLJopjbkk|kD5vRF>1F4&3hY&XH&jfXx@V32yU4ae~U|khb1;% zq55@b^?NF=&@L?3>PMcIP+gs_KTTvb}z9k-wtSU0OZ2q#Tb-Tj291J5=CaP%yr*w8}fxUs+uQ@qnIIS*;}b zoK{gWsjz&()CFa;DoW3(bXS)b`Kt^4B^Bi|g#z3#KbSA@Fd3pJhuuA76%~2Q@l@~Z zJE*u4l5#(0{%_fMOH1aKV2P2Rsnu1!lA@A|>Zf|%b>!?KQn~SS|Kzwl zJ$a3@^Gyug3vz0T3Z^cAL8UCGva+Jm08&|5FxBga?pabk*QoMC!$Uj``iQq+vUfgw zpI%;4R59CIkXsIeQF$(O^1>o7IkrJI@51-F#J;E4K{am1@=YW1E22Oe~n6kP)4E-C~{BvFJwFuMS< zOQ1w2du#m69?DCUV8R{<+Q+Mf&cfqaEnLVedsJgP!E1G3I*h{MmOQ%)vtnief)Qc|R zDgW8Q$rTW>$Y?xr{rq#vy>JX`*3@KbNf~ra(UJ=1&h^eN5Z$i|F8KvmPI(pObGsq% zH7#K{qoQQCTePFNp+emap|hWQGWUn}xN9lPI$?0CAFebQ(;i30R=}7uKk1>Ys;S*` zkN}CWa?6XRc;~RBvb_r6xcFCBD(JJ7-YOVbz$3HY;eTBgvy1+AjSrna&Fb+!pVuF;#8{bIb{{I6Gz<8Mhe7j z7hGsbsQaalx^OhC)7U0!Koio0$%0I5c zw_sdxAxwW@`XmYm&zK7LAUIwtOQ|XGDPEs8$5Mn0;JQ)iubK}%kGYsuSW*h}uA*X< zhn(`+(uU5;g4+o(ds2xKpu@RUc&n#Qo{Co#8kE5RZXj?H$db#dnm%oO2DEv!WPA@p z?BqG+c=qhXfKVU_J1?t>jG%aME-Ej|V+&`)rLejT?h`Sxu?zg(Dws5gNd}lmO%oFu zBc_xT6_W)HAfj5zM8lHSs%n|La=0BNZ&{Ucg=r#kpikXtpidX`@T^dK!@;*vP2 zN?vkB;HpI8?k85r`Ku~*ERS5A#8SL7#LamT+@DSI`ir4)LIaYKiZkPWWFrHa2g?G~ zJTODTD zwBvJE@FZmSCa#)rcUwNg#c>Me!*Z08r359B=zqegY*A{q42{SQa|7tjVtiCl@Q5%4 zT+N9y@CkFNLdZ6j88zr}@ur-MJs$e681{t2#0klKiN+E41GcKQBsn*y%;#T_T?luM zvTK61xM5WVINdiJZlQ9^vrDRAG!<<_c#%Aw11YgjW|fPvn=+ACQE^GN4{xGGUlpfL z@>b6EqA67FsJI7pu1Xk+y=q2@xOK*}P|EQnQ9^J>EH5XN7-)HatbB;eEB7LS^rMWh zaJY@o-Ayp@c%afpTnh8JlDB%wHD0vhhoH5gAFyXLG1&yg^;nb*HA!iu+yIn`igOjk zyH{`+_m5hbbt4!af=PuwA6yR#;@tx)ntCF3Ge69Zs)`CLMX!bSj(5-CJ#l@eTTQv7 zL1Cg})kEb0I15uuj5-BV3QNSSR$K(S_dlF%RKbi!+&i*XpSZtAQecr8*O=B!4w!9OUe=xI~Auo2P2C6PplP8W2-ojRf=vx$z|U1J*?4% zEDl-cA`DhOa9m`!;GAmzIdf=Wukyp}yV965zp@18X>;b3R#z1pg|p~lMmH!~Rk92r z`S{HQe!+57_rN%Zj8FR~SC`H5Ru=HtVZt;q$969u!vtbxRmCN9FvrS9>V!d_W{-6EX5)l|j-yDNjguRkoF9W**`O<}UD=5Ef+oW;1bb310VN!6yC~i3)ZvPT|G8cZvM{ zGrDDcFJh_`1tF`H%#$rUndCN^Y4Vu=$`WhpPtq4{B0l>{+?G&d{HrtnGJna6Em_FC zxRR~D@p6JHPG-W(2XmdwMs)!b7k_cMTV|5E=ehXnB|@Gj4EV3l;8}z${12SaEsKBc zKY51LBByxMxwdYc4TQOU%jk{;J=- ztFaY8>T+t%2er8u*K3u-y&H%rZMD3o7AIvT{`Ih#JTWz9siR_KP;ap42W1(Xy)wdF zm^V>ngsw`e3aa97%akqv0q^NlRlyxaK_$KkL-T>XF)Pp>(pSm1dBjRR-UW`UsH{MD z1>&w2--*GM0_-m3ba&`pFu_}HdKgbVzrh9~BVu=RkLU5lHUuBi|HC5u-eu;cFE%DSttfh5ZHD|Z(@#g^8 zqe{IsVvSwiL14MUxeLAJcs-SOmiUeCY+*74Wrb1amib_fpg?}$OKWfqO_h9L2B%=VDTARJ#%X!$t*qit ztK_}7@B#KvmdqSL{0W(i2#P21#0v&MKU@sd)49ZfJ$o^D5+e}{UuczX_odgkm5eCq zqDOq503q+i6+DUge{!eE-Td{HJh`>HSa&~~^oD_({Fi3B+|i%R(c)$k}jXkrx^@`l@hk4lgRDC9`~fv9vv+ zs$zr#brF6$)tHc%J9b>bs1YMij(;6B;uQ66_a2|}XAs~o!z4M@D4!)c(vy9ZP{9p83Cj|5pP4dnEvWHws39r{QOo z)X&x2aNSMtlTba4mxxslEP0xXFjhp(rgYaWuV)K12Key7~BUIc$JgRY}4VUcK z%D(zlpd_^y2jri?$r3f56E=gCfsAfeI`6$!b2uJY{FYic*KOa zoA9U!?=<0t_It-v`PfXj-Gn<#xYLBYO}NK|`%HL1<1O_22^us$;2v4;Arl_fcyXJw zZ`OD-@fMAD5^vRbgyM;4JOh7l7PdBx*AQ>lc!c;?jaxQJKT(aliN`cvL%dVtZN$4Y zZh2MuH|Xz(s{ZRHZqaxHaht~5iKl8j^)>0=u5lOfbd3jyJ2W04o}uwh;!cfcye`vq zX*@vOt?>x)e2sSz_h>xh4e7sF<2A&68jldK(YUc$`Uz-UwdZE~IZ0J7#We02GrNzs zj}y0O+@Nv6qj4v-=VFc9$v&d-kH~+U#-kL!{etfCd_nf<8h4WafX2Tj`v#4>$v&#_ zpUFO^@fgM9ys&#bDt?#7yU0GQapk{R;|Bd6EQ5X!Sk;TluSMe?RsI@R`7PGCPnEyM zRs3xlw^2Oyi@WDn#h?##Q{y z8h5Dj_jLEK;hxQf3`<4#rnh27&(@uzFtrOIF9D*gtIM^yQ1 zT*V*Lc)Ke9S>5AN@w+shugYKJD*k4TdsO)sb@#90w`e@7%3tFu{$h=Hs`A&kioZ?c zK2`qs3uIwa{ZYlAuJIaG{u)>DH)!0T>t$5qD*l+pZDjBCc8^EJ@6vdKDu0cu_?tBz zQsqCVyMGnGMdNmg$D?r-f3e0LWFOJEioZ?cVO9QfyT_yAPuF;}Du0cu_!~6tROPR6 z6@N_QZdLxp-Q!X5yENXa%3tFu{$`CwRQZ>5_pjo&Xxu~bcr>o!FV?t^>{~Sc2VL(X z8t-+VoIkW{ybtlH#;wFVHGT+jV_x@s9YNft@j=Ax8drWC8dvE$HGUlVacf-p@n~H6 z@o8N737GJZ2@h+0IK|VV@so&0G=3&=%O%~*Z5(mC#*M3`U5&=iC;O1b+jom$%}6cn z?%%mha=XUeyCipM+(YT+YuqT4ej79%*eU%q>3qBV{S)duHQwHPzifvV@~60`T-w_- zuKw_Ny2h`ea&TzeMt(9h?p`YWyEXnX^_P5&hw1lqwQBrsO1E9(?LDRc{POPQZ|{)h zLd*S+5VP5H8Eyz@ud9#S=KBR>v}e?xvUG;X7Q?bLWnt;|=x##KA_ zXgs`4+Hci(3iZ=YjYsGgKh<2?J-?Bd%vV6;;a??h*0?<=&u`VZr&98m#-r5EyEN{M z%J|iJs+}J~@fVXn#hpHB@6&joLGlKTr<0$M#yhEfHfg+_`b&$(Rr$AS-1DVOH?^vJ zd5)oU9U6~VqC$+B{20~U%RhXL^pmRb z%gB#i?NjG>_uu)Y%$Hr`w%;UoX*^2(E??tDjr7}~@rasVX}ptuf4@3U z^}AxaE?dZ-;t}e1HjNu0nXhz>t9IqkxR3l~XxzO*`f+Rg6DrSqjfbc`cr@N}E!B(0 zRXqkY?s-AlcWFFCU@=qCw?B;@1$~T(Cj@`(mtedW2NNH8dvq$qH!DfY1O#i6t zTc}-iXZfG=X%N0HLmK>q45@~#|)iQdvI%9m4Cj*+nfeu_1IA(ewq<8Ja(qj4Mg329uFf0M=yYCl~XZ&Bk|pnEwx zsr;KX9;N5+VU4?gm-W@AanH5V?^cZmuB7zTCyh((mAF7t+ z9MX9E&5}23d@1>9(YTZRv})W=e%dvz+QU|jcTzn@HSW7f#?z(o5XECG?OrbqYM&O3 zx8ErJ*foAX`AOG!fclX`<394^(zt3@ZjIaTmFc!>{CP^ZUE@BwKh3Z0p05DayGP?8 z;td*iu8`+9>AX(ztr~aG??ZLcan(;%zFZpbyhG+Ir18y^udv2HQT0XZTgrdiI=LQY z*Z4nZT}Z8mDf=RNe;}aQcaeQq zXk4Wm*0_p4qHz^ZRO2chbsw+Chah$uHtcOT*c$jxQZvBaTQNQ<0_u0 z##Q+kG(S>ts(9=gSMfMCuHx}%T*VXCxQZvDaTQNg<0>A5<`F7R6^~uxDjuiCRXl1w zqWq|M!kWE`C!%o`PgLV79)qs8%D;-ou5lHQx;`s=6;D93SMh{3uHuPkT*VXBxQfT1 z@mr;<;!)$e;woK_X0Or>Xk4Wm*0@SHqH&dOexAH;z)Ok-{0i;(=3zV_FA3sUG2^r( zDtOaX(hr()?ql|}geUBs%%1ZaW`7Gy*T(EQ4={ULk`w+L7>8f+9^XQYt9LZ|5#+?T7PDW`72=_px|5?_&0J zYb0|wDbdb9VSe1q59bzUPk(An_^~m5lJqS8Pi6c}#_fzB!O~4pfPFrLkL2IJcq zcQS5e{tZ^1oV%F)+02idarzTZ;;4`L;XI$&)1N#L_ARVDIrlJoTACO3ZOoqYVrKt5 z%U2hRhjSmZKZn^nnLXz<%>Dpozm?f@9$@zLCuv0dVHQ8<4a|Nr^WV(;a~@*$Co}sd z#tTJ?^1m?SMT|EyKAZ6t#)}zmWxRy(2;;PLC5}c|emQSr_GQdZJLA7FZfE7d`BrBC z04s-7mM-T}W?#wt#~44G`Ke*)a^A`8-{tl!UCz6h{d|_LF*z~L&@HYwYGM3n=HJ2M z;oQdTH!%Bj77ypC%${y>MY^5LKj(I4Pq%!+KAmy8ln{xoc{oqhjI0{U+}c8EMJ@#GyAP9&UO|j z=RRgnOW`7_5VPmJhS?v({M%VPoClbFKY1%I{WE*c8<_nZ=D&@_!+D6=Ph<8?jE`Wv znWf8lnAxus5z7CX882miqAVWHTbTWg%ug%hH!&Vz{AR}67{809+s^nc%zi85HdfB9 zEKbg&%%1*KsPGnG_MFFvwxIJ5tV*;`oobKb@5=d=7~Fni98a}wj5huK>g z|Cps4X8GdW#_aE5_Nk2bWd5Tpznt5d{YYkC%+lpNo!LLc(seL?9`h4nemKuy_NmO? z$#^E?F2)~Y>AD#|gxMRc{5j8O_D?WB9>xz~?a&Cx`a;*77c+Z$G$OqD82^pM6J_ym zUc>BDSh@|&p7Q{+AHeKmteiP-VD|J#M#LFn{5=+DF-w>8CT9OUE4MJ?FEHNB_(tYG zpZVv!h1t_9U&332wOh_xnf-yR9GX};a2{dyudq1V7^go0CXTi<{yMYY%6Na4u8pP3 zd6e1HpGp+oVvP4@e%e|2aNf!6-(m4|G5#*&ZLHi1S@~~eyqxhEZ%KwTPZ)Eljj5jmh%y^XfX=D5o#$$~C&iu5|x;G-un`!-7=MA*ptMg)7 zU)8zmn#8!r{iiQa&Mns_=P?uBydt^1h2`s442rgx32$Th<@U`iznnL){BmB*^2@o4 z<(KnxmM_jNEMJ_rnQ#}&myPAOm~nb#L6k%T<2N(=X2u6Gp3chWSjJt9-_3Y2;}wiI zFix-ZiFhomoE^+Qo$<#QcQO90s$BRiX8cWNA7gw1;}%wrYZ*^xoL)T_skj)=V)ku} z)1OKd_A$oWn7xIylYcXw&iDz8H#1IuN>cc5WBgENA7lI>#x1NJW;5Qv_yWe88Q;Np z8{=;=9%Fm}t8^AIG;S4{0!!&o$(WypRJ5P%j~0!JD7cp zaeiIyWc(B6r;G8C%#Sf8(f&sC$!_!*3Q7$3uUG2>@3?ql4^cn#xOj0YGW%XkCh=dsFO`v~I`7;j_T#dtg8{C;gKznIy(8K1%I^BF&naS!7K%ug}n>Tj6iX+FlkWcD?TKhJo8@$*@_ z4UErZJjD0~j5jg<74siv{6c2m%=iJ!zJ+oAJhYW@ejgWM{37PRjq!^aZ)bcmOLr^d z1W1O$6bTaN?e!3W+#keso(f+-RTNt0ixQ+3-jHfbw1B=tn_-4k_882ae z9E@Mb>@ygj$LyVqU&6SH@lwX!jF&T>&v*sn9>yPF@f0)eWA;AAFJ-)j@hZjxjQbgH zVEk;BZiw;2*}SWX@oMHL%=o*^Pc!3}G5Z$AYZz~3d;#MT#uqZ)#`p%7Zad@rdG1!m zFK2$Dj4xt5#`t2!I~l)%@h--fFm6mwwEvxqTNn>8ZeyH37fxmTXJ&6_oUe1HGyXNR zcQAe>;~9*1d%nzgEwgtqUeCCj@v9imXPmENco@H$*%ve3z_^cb{(QNHasC`Rz<7}P zX<&RA;~~Zy8E<0z8pgwnAI{ogGvlW*-op5A%ug%h%NdU_ehl-|#yEdY-Ol(dX1|qj z`cYnyN|fhZyJ2!J8PL&(aMuzK-!`#(OaTEsQrY`&Pz3W^qOszmxGc#_wXh zo$gV{S7e}vh)7=M&;H{<6qKlzNi822#FpW_!Z{y6jRW4wj& z8pfYwJiz$3EZqjiS26n#<6kn~#P~lL4>SH0OB z#%mbgz<7Z1jf^)i-o|){@lF5?AC?jfJU|JI|O@C|h_7F9=dH*7=RM~ywZqh07NsBwne5fOS5 zY8*5=T7+JU8Xr}6goR#>x;N^O(5q1IgE}De!>IQ~?GySQ)DWc6;Su^))cc`!3%wF` zAJk5vm!aMtwL|EosQaR}3%w9EJ~HmG30;Z$0Mv%i^H5t+cm4rj$Sl-0)KQ^lqCOCH zyU(4$Zvf;u4dFw}>l_6a>0bt-C)&;wB) zhT1K3f7Am}JB99p`f$_^p?jb{0<~S}T~~lU617d}?@=Fx+7Nmh>Z4J2{*L+o6tx|7 zROt6n4?^88^cK{EQAdQ{g!&lNEkdtFjgL}0!a}b`Jp^?~=vAnXMI8|OVbsT=_6dCt z>U7i|p>IV!6t!FEm8gfIb_%@=_3@}3LN7%<9JO8Og{bk7W`|AaO4K7z8$!=ReIn}4 z-$ebRcA$<5Jrngv)a^n~K|Km}MCggAPeR=y^jOpDirN9`2459-mV9YXg&eFkc~(7T}P7mq=06Z(79XQDQQ z-iG=t)SbVI`bX_V9Tob0)LE$8h2DaCEb55Rn^2EK-6Hf_)Y+)RLa#=hgE}PiD%9gq z2ZVkY^#s&Dq3=QMLhTXyR@Awu-9oQKJrT82=w+zSM(q%KDe64bcA*!d#z$NoHlZs~ zPeyGBJrDIcs5^Iw`bX_X9Tj>e>T^-I3q1w(6x0!+C!(H;x<%-*sHdS03w=83>8L|O zk3u~IbwKE0sLw;~6M8V}eAFJH2ckY7wOi=^sAr;f3f%|w1*jcD_dtCiYP-<87JnQD2PO5PBQx0@R(qi26tEK^+zPebj}h+lAhOdKT)4(3?;fp>7d+E$Z2*!$Pk{ z?L{3DdKKz9r~^VjjCw9=pV0T9#tTq~N9bEom!NhFy%P02)J~z7p}qvQL+GWbOHtc} zUWmF3wN2L0ZabyVn?s4qp`F7y=Cm8c^^PefgXx<%-*sQswJ zLZ6Ph8g)qMQK&CN9T0jL>iMXBLJvk=gW4nXK-3FRyM^wLdLe43(0x!}j@lt~57diL z+lAhBIq1cxZ9;#K`U=#B(A!WiLEZVYsDIP})KQ_|M|~ygcA>YRUWz&*^d{7`s9S_y zi@FYVSm@QL>rsbJKx^t(ff7Bt=QK4s|z7BP}&{I&aL>&=&BI@f= zw+KBJ^$n=QLZ6QMM${ppN1?t6bwKE0sBcE?6M8V}Ce$9G2co_OwOi=^sBcB>6uJ-U z+fX}%?t%Jt)OMkFEd+fBYMapCqrMZhA@nxXccJe5Nz^~;FzTq#@1wpOb-U18P~U?( zBJ?KI_o8kQdM)bvP=|$HjrxAnA)!~HegJhq=!a21h}tLgJ*b;edxX9f^+TxLLa#*q zFlwjJ%TPap+9C8()Q_UJ3%wBaW2kLHSE7C#wITF8)K8%9{87|D>K4>dp=Y9g5_P-K zQ&6u$9T9pW>VKea5qd1@r%;E5J{|Sbs6#@JLj4TtfY8HG{}Z)O=)tI4QG0|Qi27O7 zZlU|5UX9u*bRX2up>_z}1NHN$?LzNb0Qv>gHle>q{UT~Z=xwN9Lf!d;sDIQE)KQ_| zN4*AhyU<%uuSFdZdK2n(s9S_yi+Vlku+Xbfzl=I0^eWUFPzQv581+WfKB4bH-GbFscgdTd#K$)_ecFcYNybBP=A2hA#@Ma|3+;WdRGnT4^i8M{vP#5s12dFq5c?k z=Xaw1QAbfng?=CPC#c(n-h%p5)DfXKq5ceYi_mLPe~vmV^lH>!pbiPW3iX$$142KH z`YY5vq3=N*L+ugzR@5D+-9oQKy$!Wf=w+z4qjm_r6!q7r?Lsd^{S9iH(3PmaMQsQ@ z5A_bzot>ioQFo$_3Oy6`cc|Nio`U*&)DfX4qW%GOi_l|H|A;y)^y#R7LLCx%6zZL* z140i&{WEHx(1THTq4o$p5cMyp-9qsC`1;gBlp8h?bLBP8@F)cEMABOvrJ)Q6(>2|XA!{s?M^N9cj54@2!1xFofQQ`e@Xh--!B0ZATpy`hC=c zP`3-c1@&Om5urDs#z*}fEkdtForXFr^lH>YP=`S0)a~~7&I^{N*#l>!8UEhc!P#l4 zuExAHd)D*2ciW7SJF}kK4XrVEHN=A35?8P-H~5aLb`7j!*<6idEjt5vwYT}tw>~r0 zp4T|f*6ggF5{dPwjqY39mExaV+tnjGxHZd~vpy>`l5HIu$qTl-hIZvEr|6p*i_!8;BvO6l%QRfH7bUf0-Fse_S?y4Pg1z16#U-o6)KG%~VoPD0MvL(}?XZ%Aq6PFEwOwsCg|AHZPt z_IE8GaN9p1(xBTW)-3ltKWkcU@U7{t;7?Os!CzgCOH!RXH>UUxbJc$JhyNf~@SWXn z*GH=7B_eP&UTzmAhX@l}Uhqp{GC`GJ@U7FBpL$a~g2u7dW#0bMn7e`5E3lKf$ir zXo~+(ks&LO%6hahG9n{V74rWH{}a2%{}<(*{&&iIuk!c5oW8Xlr}xyqleb4}J>D@w z{Xu(8+8!4q+G9qt@;g6q+?ninX5zRDTl0RZBiJEDw`@@ZM2qUjTNL!)?(HeC#39@F zIImgzK5Pza-+?6~rTsys_8oBKf2}{r!J+&3VXepIigFgD7;2Ik%HSDtiG(4$Zp<#fTI`uWD4#3A8z!=0 zLMnQ-H}-)49f|UB3U?bOxKfgohpTbl`bf=wuG(0NE4Z)U62DHb`*Qbgk>B3WdZ6V@ z+wBR9An<{hiyIzPu+(R(fY_)9KKd*G7!Rqn>@H1QTg)`sk~j2>Cm1GCdoV|f2^ zMh}1AykHbBf@1!X+t@1&0_cMQ=n%JmY0N zn;w?&jAHRn08eZa0qoEG?@juxUvx|V$-+NPf7?Sc{Z;U~gDMY7e+f)*p#c7F`WfBR z4;K7s`h6(Qk0~=mx1hurs)1XRwPF;fNjiiHHcUuGl4@ zzwJ$XOz$4g0+V>CKMcHImd9WokL-{I|5N;4vF2z-}&ehm!El%Xm4P+SpuY(uavx5KLelX5^ zvuf9;`Jj-g>OUD zfin+$!fjn{?aL|InV(qennA-|WsY&iqUw!Tf}h<>to6skE!36xpdG%S0pHOeC3pGs z6!eVC0Kv_Lq{daEBZ?PH}Uvq;Su_9_*jngfzqDgj<=?XBAE%=~{AwIbC^~KUnMV&30Gg z=-6f3v6%6e7#hKAx#F7BPY(I}TI;TaphiYIPKAgoU=})V z03(r~;M>8?+dm9Jleq5u9!7TXQ)m^3J}p|s$VjaIYit)CpTQG+Sx+yH7CGM$djxu% zYq>iGBFVGnd=C|z+A$EE<^^}hHh(P6dJN9W%KRB`G5%^{F{Db5b+h!PjU2n!*KexmER^XRK*1FrkF}8&3;S(bL3Ti1Y zxD6tG>?sxL2T(K+X(ptJ`2wpB_!aee!NnP_;0YhWS7@H{3f?gQY~c9a;00Wq{twv& zHbsSlF1YiCgV+$@;3PWum^}D_JUCY#%%_7PdGJMfaH2eT2_3AG2k({#Pml+%po25y z!8&=+CJ(;xhzuxG9-IpYvx8sG$+DKO?|4a68?0Bzkpb`OV^6}>078XpGPI2yu^#{4 zy&GD`QLe@u3usqkz=^G=cD+U1LDT#>_8geGg5SbA09@{47eSMQlLpaAyF+-+r25bO zRy+|JC!E`n{?+c?`FP(g<}(wV*w7DcwAHRn@mqp6pb!`QAAlAD>EVDipx;bUj59F5 zqTM#09xH^_A(}T1H*x#M32=Y(m;PRWHVS#2%>5l`;xBzK{FO<6r*eO5K1v?n-uOFG z`a72UyVS&=V=v-+T{ejk+~1&N{{CwH=YRUR=+W$c;IA~TM^$6~GBc{}BX{n;nJ-86 zy&DdwH(|n>8fBu9| zvgc$$6LsL6+YPNBhD)4ni~loXx4$PQ7|<2OoIA8P^NY6k6W4ckHFpJnfZW?%kd6hr z3S0!zQuCIV!i*oU3EKzC@oO5c*ZOhoa!2e=7z&_!4$BLE2jiYt5BoTF7|g-|z73<* z1}vJ|^>%gfUKc_o*AVbxzAlt?9(0@Q;3w0wV0!h3m|0Afb+E(|tANZwW3<-c;|46P zMklTQ_OjLu0~T8j<3n!nWnpwK8r8z8s$sph9^xPQ!N|yVC-wWhAgqM0#VNrsm~Cgl z)vz(gfE$wonuKNQsbiasd>Sl!9i>XTu5CawdyAz zcWszEn4}bok>gI~I=T z$^hxkDaY^+&l&j*Hmkf~OqHjY3KWTXEgq5sQM}zA1iRHE616 zr+r#vJFSFPK+!!APyKdGy&2D2DbJG@3qIPuRBFD=THRl*rdGq6=mpT+;rh05Tq-tF zv2+xbcc1UcGTyhkJvIqlzk>Z{<2ZZVZmqO?PT8%B4MDp{!0x}8-iPn*U3yQW-G4)R zWqX-k&VN&SzrVA0`Fk7f_Q>DNc>Sg0IwP(FLf_sO>P9TY@P&i(WCeGxw@tF%)~R}1 z9V^3h{vqo((GHrV-F3>YA(n%7SAtz^G<=i3MLX_R-~avbz5e#z#dkm2iTG}VZzl0s z>#xO@PAj<87h)OW+F$iB_y$+e-TotFX*$3R2OBXZhGiIQ-EsivHH2jy?+0zNoZvx_ zSgomUjU9<`JgN7Wo21wj>Ef&^#d)`sc$Rr*wY&1Y(Do1PX810xlvohFn=tLJYW8S>HO)u?lUk?%I9X!p5&+l9?tg7c1h~-pIK5t?1Wp$5l<-afq|HZMAZYl3CQ$EerxL7d- z82_%8rh$08PE{%83u6nA#<`-xSXDZfF;cp|^Y!^rv{<@Zy#9{$(r*9QgvH}abW=6{yo zOJQ=w>UZrMl;2w*n(hQcR4;_q-+=f*6k4`zdRZxJ%A1N_C}zp*7}1$vHl6;11?d?apWmEjy$Huk^5qk zAlmJB$nhpIE-j@oWIk^z^RTTPiMhiD7w>OuzG$t((S^<($+Cjf zx7Ok4Lg#JAuWH=-2t@25Jnt>|M&nj|N@J~SNt|~-Kd%YTyA;p6HgTR+rlxJnvaLFLpetJ3#Hx9}3}u#rngljfwGYA9VWX^UtC-Fo}UDV{(_rq6%Ny9epM%B&H~Kjvcjhf0vlfo#jjpmSuAbPq=!ewU zwOGlt+_4rMWWkcTYk9vyFcYgAUrs9e3GKmg2w1K)dowJSr*FWs*6y)1bO96@Hf^!Q z;0nSL!ys4v7XKOWMin|))ChwmEPX`TYC{Mn?5^OnG)t@&%d-)_!70_RLuJYNILw8& zw?X@cbp&a5fwJ3vooG+XPkH7>$P_FyTn7~>Gvj|Hv9e>c*5TVRP|>%LT?yE!HJ&^0 z5Uc`0GU_$J z7OdyNqF$a@42Rbo)8R{Y{WsRSqkCad+G=;5XuWy_JS59)blR3rw1CT?#npJS15b0; z{sKp*z^WlWM1q$&EwyWH!2`wXeA#LFlj?WEV>vh%57}_>FeA5dJT%gi-@voMMXxkG zvB;m6jlk~8+^|^Kxn2AF)AFr#{d?odu>Of2^0RTRV!t&m2opx?Nc91^MH^k2uv%wb zu^bGu!6qBKQ2i^`Yw<yVZC-8d~?;pORCieHBKE4jl8c578hO6)$va?U@k0;`_y(p#+_gZZ+!;$ z!6%D(qag#Sr=^JA*w{zZ z#ZO=zd;{N^?OACH_Hi{HAf9>#DZKhZI0=gp%EeU#HJw}ZuB)*$&7Gau<+4t0$MUhc zGS|AS=d@#Q$H40PLbmgYc44l!ZdgAT^Q3K^o;HO60h7$YV4WY*mq51ihQ319vW|`-IxO9m>bNCq`HbW=4P&4 z@;;V)zTvlH+O}8|OqoPOz@%*==@e^S3N%zv#MW!!%@Ak>rD@JdjaS&RGT*i?zXgaZ zctjfXz`WqElY&31@e1oP9UesIHTpL|E(@?U4IgXhvv{{D@k{4W&czYfd4 z{u{_{ZexKB$KveF(lm>;4&Ro>2i)85&TVwVdhG_+^0DyH)CnD?54Ku2JfMWpXNINY zz29)y5aY^ti>2c^xD?5H&l$OUyA8(CTqupa%-ICOU7qTgXa{xUWPdO56Ze2Vqt zfOg!~@f{o%<7;E3#kG7gc%NwL=nW%BQW-3&I6Q0_xz#skyb_Rbq9y-3r zKQ_PY4XK&$Sy$li)PXC?tPl*S^;@iUr(mfz_WlAMUBftg)vYOTae~6nfT1P@?^6Qc z3!fO|!>9Nn-f6-fUw;7P4G)RcFWI6t_DVy$jsxM)q~IU9!H->yN2Ed9PfH*9&GzAt z-${+7-@+OsoCV`wUhvzz#xr6rDB0M(BFnOFv09-}7H!FT2}&C0^u^i1uEc1(E^{4> zh=;)M%Y>M(S&?G=Kj!`fJgOr5|Hl)cAqaSbh{TmRLxkbDI{ z4at{^1@XxG!JLag$A#Y00CNf|Wa)0tK>UnzQZcKPPVLQ#AI!SLq>dn7E-y~b6#6D* zO_?r&)e0+X-6_-oaI(ypY2*+2osInD(Th_~?bDQ~h+n@3d2evX&k4z!p6@27s?kKJ z0mzA_%X2G{G1<}&PX|kAV;!ncfT2u%wZED6EVv1CNu- zL40^+>^%tGfzOuELi$WKU98&*;RILROfKwH|W{iAtd=1R}k zPd_F;l?V4OYD!+Wt1VP^NGw?y`w4oA6COjvf6=AR1zod>TVV}d_&FyaZ3zfVBEyIX zG+kg0yoknrMs8gIlawM=#1>a3y0+2d88lp0vy}jE;PK*GBGPcH{&ZTRKTi1qRQff3 zmJgm-gbt(5ou1JbVWIu1MtKE&;5|ePU@w{P0bW+RM}f_`Wh0U{JwV#i=`vegSt5}i z2N|gztkBYQ_nkBpiCVRL1^mGJY|1AcD536C_SJEE^{p*+mwk1pUcJO#`)F((m3rw> zLmDbwZA*03t2MULdG=K+y{c9zBx+13QD1W2X5T(WU|a^qHv8hX z0O_;U`z*_AZxWbKDJ>?)^AGr zU&7e3(+JngP9=}0Z1~XFyi-q!PW|p<=|Q5lC?7qqjNMwaP|va2A~UJQ`$xRzd-+?T zeGkMI3VurEAVxIS7ER+rFBKxf*)w@C!IkVo8Ln~Y1zV1fxA|4xr*;qCE4k|1^4L%M zj`^s(;J4#z4*xZ$`bV1)RX2^GC~g6oc*Qj~{njEi9cxTnnHQU7T8qXHFBTq!HCu>k zj%u%{CO?|H4y=VtG;UIzlrJ$ze2hlp*UN#F5;|h9>2gkOi3!wBq}D>wkylaN=-hf3 zFBRF4XPOheV7|hl{rfK;!XkOBO;J5Eo(vC%##Z4gdg+P3JL@mIgf6ROf6#fU-a-7U zILo3_p13HN)Fg0PkQXi9gKVmgVYSJMihV|&8A(_ND$nZmQsEx^$iyw~t*=Q5h*;Eo z-E5P3ROZ|@8`;G^IlQRq(8Eie+G7DEqh&g?$2nyuiF-GhS-=`A$h_ou5Eb7m5<_y0 zo$J_^*3h`ZoazqIVgd!{wkf+D3ymL(wK&V`#ZO37kNee5X0AU zcsj;}TCi)F`}ka3IcUpJk1>*eOx&y?-pGyLYUE=AKW#kr0>4>S!1kkw0O#kz=x8k0 zoLpn$3>x0qnLZ9GEV9!_>!+1&`NxXusvn7cT>Q!8V<_2cQmI9{8rxb<#i3kF1MQB$zu(3 zr$7?$z9=V#**|)Ll!AcaJj3lL00bsG7tgP}U=v30H_5hNlt`zrvUoEuHY=v9J;X%p z^stHxHo8yGhQe5D!$g+EjkM@NySSzB*o;o1v9{*xU!~1fO4IuTqO5ogaR%MbIdMLt zg-JupV+Z33ej<1*Dm^~2$FFE?9)gV@M8bf(t^shcrcOC-?%X%LC!PLm#_goll^1_s zy|g@ja1p_3-tmbxzbf70$|$|x5DnexT6u{fTg!W|t;lVRChQk=oZ}N`{Ys+V^+j0g zgNuyLRK|YB0J`^@XaN^zeCG84j34XonzLgmF)**J_=g*Iub{5m2yO`a-xW3U2vMm} zS^QP?H==wH`f0(a)00C1dueZw`!&3(n|*Dq3Kind?lo;0%P=U}z=Jn08mO^5=k+WN zHnaVM(W)Erir;qw zz>kQ6q}j$#T}q&soCND^Tut}2CN~OchMk4cL>W3}-zR&@F_{)B4rX6SZrEpLn}V*4+=@pCh9=i4Lk{%sq^FlGUHO#TQF{ecyD6mLj5qu#sv0F z-!bXf0W4=?0sc-JNl#4FzxzWEeP3o?+N{ckbVTTLl$`?CA!|r zYo~S;w8;JM2{C0cw=%Z$WHE0H%-fCFB4FMDh*d$s5vJ#rTjom%evC*z?`F)vJ*7d4>G zQoB<(muzN9k%;6$Rawo?xd?JeS@9zH^MgJ(LrDbiRR29*IJJE& z!$urvMkf6rTJaw!AWU2`@?=BL<=~+toHO{82=GR<;%ndXP zK9>Qy!YQ8vB3JOUyqHYeu79)$%&`bKwVTjLsvOU2!peSSF|Zt1O5P4c{MzwCx>87&rNUqu-8BL$D za3@O_cGaguNtJWzl&~@8LyPI=vq( znu3g+-j5q|=k)$t(Ie)0R?$Dq-&c!f^EaBPEy_WQ7+lNH6zUal3I6FKyy@7_dsE=H zviStNRPu=c{ENyM$<*ZKu5q7AL5ekR-UO&N`_xhs&&F)yI|_w=3wDnE-{AjcCjRZo zx>hfTn1YueFvll`P^Af~*flxmLNi-jwZfy26vi)^OVyn3g4InZ^!(ZXkLb%Ju8DBS zfUX`G#RXI!sFJ;)w<3NjYFi2i@(ul2RQvJ~-Mwrk!DmhBeka+4?vQSp@rRvF_T(%5 z{OSKfzT2gLL)Ab{ke|&I1ruRmCG|wux+y6pPRF7W?9HuUTCylw>`s1Jzk2cO`seBk z;iHBH-%mQw=NI$d6Z*uK*34lhwX&$7B3?B=hp3!bf<1L?*N^p&7SFF}uO4gZc6 zrZ*i&fWcgMMZ9u8PMLDr;lBe#t4NF8c8STKr=CyGk49g@u;{-dqs5Kmdq;KfkNzu- z=5A(!c074fq}reMPvllZ@K&=hmo!ZI?L?a+P5yD+)@wQ>51AE=n^k;cxOj$ubADfY z3tnllz4+-YaBa@3-Z9Sp$6Rf4pCWvf5xqILI@o{6(+=#P;7c^dc8XR}Cgz6hy2#8e z@pI^|v!e~0Tlb$`#NGh-l5~ z+-pCJYDlU7VA+xhc@@rcvxP{Ab;V1n+0r4j_;1RP+C@&?g_MuCvy;&6qB_O_PC~-Q zkE8cmGCcb>oM0LXH|13yTpqu;U})~wcA6>JV%f>x>orBt-I0ISQjXpIg1^PQd|GdgX zQBHC=BxW(8Lgz&3KbS!1IzT0A-evCnSBtVJEZg|$&kPBz&!qgO=+aH5zp!4NyyrQ^PE*7f`#tU7w4QDCBo%8%es^=lQA($vYw(R_n^O#N$|!Dw~ziV3jD9TJI`5F zLOpy&M*Dy8T1&UDwhIN{Yi)+R7~E4IrQyHAb5@}i;qOF213SPy$DL^FhhK;5Gk3;0 z9_G+udzMG_4NZ__-THvb_90mFaAnC=9k(?LP==vq+BfKrU8AwFy<{9M5<0Pje(279 z8akSM$#Iv@gx)`=>0Qio@>(?C+Mh6fCauKaSKy;!)Is>YRb=opWd1+l*P{je24~^d zr$ziCIl>|S)V+u^6NPA&$+}J~)^yz1=;+wdCg0AfyOCB)Da)nQSLp5YFD3jSUn@Yfv)-KqD}{6C)OWL5h6U_EON&dS5> zqvufl-Ss>v`2IiE_vPRd*7wCc`_lE)xFvlx>4{F=)6gu2h8g1Lu^FZm`b=SJ$d>Kr zGbhlWTmNA6N8xyu@Jh3Uwb! z2K;iD>shN49)B0>`HbNCf6ULg+6&o_i9BzEpUv6RsT~`mq@x5z`Kr zm||+Q?@M@OP$_D@A-bw{rf0~3=Nr#8;J4Y_KpJ6cNeSMNpY!4N{m6xVI2 zI-jhit<_FCY9btExedR`3e$bjhUAgajqI>mA8lBD9b^9h_0h)JLL>DlpZ{z>J76cY-VJ?z&GJ18E|mtCJ=3^oF2A_3nsXO| zcvF})tT__Ygce6&xkpySmXr=^tolU9aMit6=?qz*^48Zxifqew-C$cjm6j_kVnSU7 zz4n8t)LhP&@`Ir>h!m|~0UY^3lEnZF(aR8q2F-a11)LJiT@o!`IKG6jO-GGT-G5L* z@)>C5Q+=?B^=XfTO?>_J;^wD(zt2%-HJi6qf0Al=$#88cTwA%Pk!h}n`+aDw{Wy#9 z2(A>C4VCorrs^!SDOEjUn_@rT*O2VKaZ7A{!|LwHs{`UfTE$yJvWi)-_g`sQa#R5J zbK3l`{dm#!_TxUm$A*ydpqI2=qPDvsBinp+$8sYk8&AhJHLU4=ABe1NaJ!dT39ZQe zu z!OA7buVgC+zKuUUEx>WIRIxeH#FQLBM@w`p-S~Y2>8;miq*vle@9?zrpxer+imh*E zFLAK{*pugdzC5jMS z!RUrHPHf@mh98{!$~JB)i#3!E+E~@ud1DC!sB-7IIpxI-uytX%MoP9n{&jc5s~0b~ zY(0lY%U(8$^$93B7NsfI*{`MPudn+0DO?USxOCzu9AQ&!&WUi|Xms9qM+n`w@#omO z(G5vQ!hN^u%iIsu8**5s9ysnkpxnaBa1GdLKN`bKK|ra+Ht}Xe=<2xZ^U*ffKmC{muhi>J+8c$7 zw(VW)!`V)INBZTw_D;9${lRPR9}nC1#D1Yn&9(3dz;UvE|Hc}rq{Cd&YX|iQux#L&RL5`JEu{pS3~j^+Di9N z!Jp>A|Cqlmz~}YHYU4Fi#A^fi%RKla((w1ofG@eY(l3_c?wW065MsaehwiucxA-06 zn4tNt00fpm^IJ|_M@{oI2h~MX{JV3JJK8Gd&P6H?o>qqQDE0}ogZVkjuKOcuGq3t$ zfP8x0-u(WwdUxJ06)1QV`4g#hMy$4 z&tLD1h&w&(4_xWoGkegSs+%dl=Ojw_gC*;4ow|NoF?;dILAw~u{h7mT z=;d?W!@M^dk9vjn^J4F!Zp&qT2gP(RYL%BAxQ-BYa2*IocDAa}Ze&w|NNdwACkVP-@%g z+^jTsDjQxN`1$xhApfPgqn*PeuB1Ie$5NcU)fBh-3Vow?GW6{~+R|5#Tqzj23Mk1@rYLq%a_z?(3qq~jVNe=A zN9$wx?kroY(`DvuFJ94j!^D1+4AJV`q+~+*ZzDNTlib3awEe1nC#Zo29JtB3S+^(w zYtwaYo!WO)Rx+n%6U0>=eAKN zx}K2^TN3oXc!85>!w=`h(+guu>`BKP<`h<6;Ji4SBX0+3KKXJ^J$7pEMknHX{5$r! z$%}Q*RfIznu&?uCv@rHg?9JJ$BQ>k`sQEItbjp@CRbBWuujSQ+%Tk7NKhs+E9nOn;9GbdUelT%mFUEO;YQE6N52x*x zYBc=>I8}l(T2LwH{CkfH$qUgvPY<%{#db?hmXb@KJ9DojLsWm<@#a0=#&iRh@5}7> zvo5syFf;ReCO&p%D9v#4^}G{Lym>}4AZm*qfo;mYBacCAh%C3UCxJA5t>Hwq?mA5C zt|JKj3zVCoQoWQ+FnzB!_9^dWy=NhQNdM&v$Z>uRY4JF_KdFUwA$CarMHR0@q5hkk zasq!#Wh;O_uQOc9;ppo^6ykM7 zvEKRD`Dg+yF@>x1w4EVq%Zk^s1A>FF7jO!8W$_Z{M%^}2nfno^V0Rl@x4dd6vfz#` z9H67HO=#{6alP}fomyR_Vz4_JBNnpb970kSdrQZHc{$jbnAT})WHcTvKweMpsJzTK zb$Ur+;D7B%gFJ;fM2pzXF`37iNdAtIf2%8$+VH)cQ{!EP)$bemm&X>k)66V~J@n;y zEV%Mf%HjAB=f#T(%Qnm_bn4deSP>sO$d_)}?C)BYy&)k1Q9@>6rJW~egb4%Yg{4dE z%uaxFpn(k%Lt@`laBN+kX}>JCf}C8^BcGv#vc$QJJvT{Yy<%tSTpT(vM^!UI=((qMe%n|?L2{{f$?`&#=e4} zZ-&NxN@bj{YCy0U?>68(s9ni27`3CtpE-%YVP0%5gfW zSRv-4YL@APHM4EUE?=8^()4HB9ei%|-{3LKFstms~{42k_pItl#H4JhTYm4+8X z$V!v$mXij-9=NOW&3*v0;nHAAdV4D{RmJhISHw1?b_x1}B_-ud{{nNFCdJZ`Ul~6i zSYKByBPo7pY-RsNTCCp{128mqRcanNn7t|zLkFP(GDZuH>Gtgnqx8aZmKMy;3%HUz z5e#H+ct3>AYW{oB_A#zi*fKP>)-)51ktp}<-9qZ%qRQM2No}~KzU+;7_$^JAuTAa= zRM}0$mfQ;x;NMpFqlYz?GzwdHIxkV{WG;WSk~TXy>qtb|Cz2z&%X10spw4%JkuN5+>-I#JG=BJ9WsV# zI+i>Q^s3BmCe5qr6pbI_%Ut{E2VUQfeH_JWt2$S*-R)sBq^Rnl99b&<;Pyowr7b8U zbMkfr64)Ylqpm8lnC4BotqP4i+f3bu`e&4#W0mpC^ZRc-E^%-l_xoD|^_v+@;6aS8 z$3DT#6uL{)&l1(BAbUO=qq!^G*Ljng8VV>i-tPqu-ezx(A{sK|5&Th#Nl6|qd6pGH zXBWDU(#P`Mhrvy@WLM2t=l5SEs76OnlPT`)GIllddO=Vr{cK*Z81{ z|L-xPi_#Z@q}tN&nertYe?n<&PI;m=q&BK`QIXzz`>d?Q-?(N%}0FW#sc zX?8yhV5FOx?b}BJld>4u6%BbNW=p*u_=`wPJWLFn$+$yV8^j?;CJaZ227^7(Fh@A% zVCDPAec3s+zw*jw$7`aeBEc0W3TFbgWU!#-H)s(**)l{lfysNfWy}lZ=($vOfX)q|1CcKtawoXrg3$^O5Z2=>Ur?H34S+&4X9|c!uo%~W!=4p!_WCp*@;-vRPxF`y zC(qu|&Tgbn|}Mp`0aO9`|LM?&)TqU zTQvOAdC_lKV3&C9Jp?eHCJPV$$9bCc?xD-YU$L|>bNJ;?lDx@rgZ+BXz{5Hyx zaS_d{pw2Y#^ga^HHGJF2D{@r0NLs(>oq6u~o2cIUY$U`}G`1{tv#)=C7VvMU_?#Ka z5!4~9S!X&d3+pbGu|Iei2loiLUHm3upQKi#IRsxP8~Hp9QEym`dwCeoz*4Z2`{j_! zB43MGWH%!mdQNQTwWgs^f3ea@`+e>w}@JFyhW6BX6!uE1zw z3`^gxGhMxqgwks!d)E_1Ie4KmUbKc(P-psWe5{ClU(xVe>x$g($>+`ETo6?-p)#h~ z!SuH_7guRMRJ-u&p5RCS4R{iFDM*cX9C~csl7MwngJ1S<|eH z?++tgJMX3QK9mM#4*MXMVe6ks1^(8ZR%61|X-a&z`ONW4TYnH4M@&l5&0hSupH~i%;O=xC6yaUaKPvFah2VI7N5fe(LQ6Z*SPCoE z@C#RRktXL)XgoG)j5n-B;2Lz=ivsde`Lxfm2->w79ej5F z4FfonrN9K7W=r?sAG<@*sJhvcmsN4IK#;NL4QQu`e7$C)T#={Tna4+?Po{tGfTc|C zG)44!*7mhujm(ZY%l7B-XoOK%feQ~8XCx=W-jIrF{A`XT7Af>|sNb|c&QA7qNVMA z#4^$l=SN;4a%KedRK)&!s*wv6O)f}H@ZwlQkJ(l`_?-M3Mv0zieE*NL=`lw=bN(}m z)gnEkK+)23RJ7)oEmeo}@7Agv$xPqfKdND_^mXcHgMT{@|4(4UNMn_K{6%Nxo3uX4 zzx*1FZREN-7XD6vb`9#ue`5PTvb7cfK*_np?#Rm>ESpF7A=vU}EHdP;8~k+G^Md60 z(~bUUh!~&p6wah-#|I z8;bd{F*kJt0}uTwV2Z(+uKmVw1{fNBoaEbiJ|<4hizVgQnd{0kC;#YvV)B;~r{Z1K z*f06+N@5?D)(0DPDgLzTSiw2h133O)3I_6{@c}ygMB@=^DwgL}zWY~GwQ9aKNB;Fd zoIrJ~OjgZ2j(PB{u7{U)dKZ5>=_@l@5vT+ct&CPI#9?{v$rj{?I_9{P3FkHL${XMz z2X!+lGS?F7ec5m({@*vsvNsyxNod!yc$*^6c?2>VN$@el?SP8I+3MAr1O6C&?YeFg z>pE>1?0Nm~3?sFrMiCgetyip`73E z__a895B|?Q8{i$1ldkjaa`FNLI6QxNibvNaknPcB^fDN&qH)Zxp`kUu9!VavAL;m zwi4|be*b9sP0MAmc^t{X8C*)*S}6{v$J^J6PQ2Bws6HK((Ztc{&A=PYaAg=~D01!w zQ-Z~VI;c;*416H>;>!mc)pPv$jx+uFjz6K!c^Bs?>C)%&X z(K;B7^cu4}v}#u~reHN5f5JS->BjgPKDZMng2~Fj-}_!gEBA_v)O-JHd?1*ju#rB( z6q`|fQF^MW(3}b%W&2rT;Bu{YdgtW0mtPA?@xzOd3jzmjRq%wHpQTKSB&BlJqAH%QI--GXVDqI0I z%<^}wvwZS6z}<&&+g7ukS`%2y49H9+2HvSfL0LP><+z7jBfc?7XBh`5F)k42rFF}z zdm4Pb2=Ndwroi5o8WRlr<2G#w{MNk)&0)LyiVExm1-(Q0xz6lBRUtO;IvFl~p5aZh z3)-aqHWJVTy*~W{7S${6n~{Ea%aBa;MLKh6m+9w&H7CgsspPqQu3X)Wg2`c-NxA}W zl1{wlzbWo_@_04eu;AkxFM0k)juiY_os(K$#k=Splvc4W(bx#0>PA`rJog(=kYUt3 zy6Oh=^&xzw{x=&RNBCU2O?=L3iqGxq!Dslk@j3N(;Ij_8GWl}_D~0YS9^~fv^A<)Y zi$5{wa_6bRmiaT^C{Q!}@#c?z^Lq2y9!^fJZlK2~epdzDM9F;CJfmjrj!SF?2}9eP z#>njCAw;8nMuPhZL$f$kbsX92Qjm>QkQ29IV)}T-qlOY5?$g9);($#~I9<{XJv4P?V-0y_YAxXsy>5kMtJjO8&x{pnJjuLn$so$8&2CE|;9v^&{kf{l!1C ze&?p3^(C1zFeotNf%ZOZ^qR)(;$O)@g8zdw)whM}MsPI^UGbiQ0{+QA87D|U5qWuy zhiixAj=Z#bAKvR39soq+onk7_FrfIvysGmwt|;{F@xwdF{&_eI7I97N@ma>JYN@ws zIM}%liek2A*S#mFv6|uDsX0}D0Lwx<&lc|{^V~kx&9mP@JfvV*mU?$}DBn__J(u~c zIpOgf_%8dQC45(~Qs&l6yFsUUeE&wA=V_n8_dDVLzrlB`IzY?#dgHZ^G>Y;f@qX?- zQotC2cRbQj#1s$7s~U}^iYlqXy;cz6MWLuTkUJLhS*GCeN9PKDYZipyXC?O`naI7L ziA(~2OFUineQu6w<%I5FB>^B+Z{lm#Wr!b?CSd|7cO>p@8l_3Q?W2IA0M(Qh{qmi- zOtU6-cWNhfpx}0eaXhy-!M}mfk%;E{on6r!oC+=sgKc zw@GiI4Vo;yWAQc3(c9s7(7Qsa^*iYOw zC$4~J%7x4}#edX3do{Ha1J@qGABGCg!YV^5>3@+kQhFIVnLh-%vsoe2DraH5vkibc z2ZJtd4`pvY{~~p(IUTv{ud{}xHS@Cd2mR>f=?B3k=FBZd^d85~2sFfG*&=V0@?6A! zVu7cpT30A^dNV)AhKFeoiG`9C=;qWZ6VpBX3f^#nO`%k#SMo%oPV(Q1UfoIR80M?b z*=n-lt!O%!{2r zGjnRedeEL)df1Z#LpK&=u6PN=T&*uKMvok91$AMG6;y;K!fRMTyh+i$lSZa9NxPLy zKY=3@P5s@($EI!eLu|1=A~t-Z+y;2tdHQc$Q}=SO?w_e^#wWo!19m)NOAmaP((e6~ zff0v@^66MVZ>Y>R$_09r`XjI6Sy8?Q2Ikrq#{V}cX4b?KEKI&eX@jTU5xVK!CA>@9 zAB|5jFNE`qH*FG&d#R+VcbuKX*hG@PbF7g8!^X61MW^PY;*;|>-24neol@N|I(XnX zs9;Z@e^^0C2!Vmq{MAuFixii>i58Eo(miaC&QApP{{Wj@*D$8mKSH?>7$ zAG-TB!;M2QO72vtCB34bG4zGmhCXV-Q|^$n{3kC&x)9F~m|&6D1QFxMBh>Tak$*K) zrXQVPcu_B>uBRjKx4`mD`O#*XfoH@` zI>wt-ho><#@-Kd;sy`=5oBPh&8f}OczgyKa5OA^=2FI6Q|Mzr#S}99FssEV2TUnt= zH#tL74emYSoaPZr$C#AFYx3MGn18m3yuuo0`?q_s;dJR3j$I3B6N}BJONYQSA8BSI zJ?HK2HHOZjGqS5VhvbHwoT@(2n!!0$M|!gZ#*RfA;8b9Hb-uYNYVHSoBK#?;{rgm} zZh&dGW`1ey&o@|qYGN{S_GGe+O}@w&O58TO(xxa|RSMJdOe{n0xpEa7Y`UVjuba3t zQS#9s39*BFr2IG6*?t5++<#uI{$uuI?M7c=m4B<-7bzhPTNwm({`QKkd|t{ z?Z%(A?^fGw*?61Ya_cfH%DUrk+H!j~DOBFd3370|VD_+YSUWe5pV%s6@aDV6*}+B= zn>VD%@Uw@8pF6S=u|{x{dqdQWvyEL&w<8le2CblI^#`dhus`3rBY5Ua8`DoS=yeRe z?V;DH(_FNB`Q-tU7w|KUWLKUT5j8<_SQ8|B3dzm^lGhUh3`|mPd#DrZDt>F>7Y$qlb8E}$(1J87iP~-J?_tA#+Ib+4aqoz-T{W*{h{}o zeRUWvx`Q;|HyRYJ`T0oBuZIghmQ(o6{E<}7%54}w(=1t!6w@rpx+}^iKAO4PuSB?)h$HON^P5cpYw@6sv76s zFSBn6xQ(A_0-nDxOh9@{t+I(scN4;Y2oQb>%6)q%ecN=AmE-3bLar72SO@sl{h05m znV$Z!exuNVE_NYS%yhdxhJby%O_!`WoBdAOd#R01Z?kKwL52{yupY2jj@ptlo1c~( zx6X`UO!!*jl}(l*F5-pAqLs!|JaCZp6q^wMdq^Vx)cyqzY}$b9%e{O_B`m&~_UBo8 zlI+i}+4cvew)9$i^P-f-*qaYSx~P6&=J(>03!@w?UA2>ezW>PN0?K>(&i+D+@0q0* z-{Zhn7u?wI?sC!3=@xQB*cA^R%kg1&N4SF>C0(hcvCIB!#sGOoS#AO zSPO64`qDNGufK&iz=L;7CcND(yexgm>c20-lz@LNU`jymy5)vmAKr19@Rl3T zx;^_BhWBVDyv^rj&>Oe#w#~nuVR$EH!kd{1Z}9KI??adp(3@-Ftv?d78OfZP2``2D z+OB+W3d4K;6T`nRJ$O50!h68N+qQfU3Bwy@;eF!4t3Nk`f5$hAUsiux1ycfgJ6m|~ zdGIdHg!c>P3wpQR-|h~>YglIJ_2KQ73GW#TZ`<@96NWb~6W*KWWY9a(!t?bdbC}TC zIP?w*EH{2^=1DaFq11z&u~M2}i_Ld?pQ*S@w~bYmH3_xM{18D6!A`PNsziKs?^*mM zQt@8*w#eFe!xjHiFTq^dsma)h`>M?VA-%phAmG&y+BWf>202q0fnI&TvYPKwLZ-=aWNTw1i;Xj+ zAJ?EzLCp@Prir`H<9+IW+wa^S(2-=QnK?n?_t@EJt=e5(G&-GcNozYD(t z;pdN^PcMsoq$ED>8-Z6!l<B3;FIuKQ2=yZfzx-#dOC_%{S~|7{XNDoSK!b znQLgxRT&ioEj zQnSsiott`yZMrC^D&lg?YwwRMp*tW#>j@p(I-NV_`Z$x0GFv#4DqK-KyJ|pu_(QbR z<{=v7VB&{C`4lb;TYbZ>@!^p+ya3x%T2&N(Fexuy9?6T9KU`?is~gru z{aHUJ?a0K$;bpJEzZ@pnm{nncn=3kR=9sSHLaV&0BSVS+*XQ48Z|TuX?3$XjeJGy3pDcYhM6IawDv`F*^wM+tRNz+|#?vPZKzxy(r%Yzm;4Ju>u?FT3$2j#`%WKtH9M$voZ|xxv*ee(vG% z)0sX)JcFmNcr4`vOC4XaHM!y!)t&;QbKJ!kbrO*^k2ss3J{xOisKBZ2+6Q1&A=uVs1t3X|f< zs;ooD+GcEsGkrM)j2-EaA+N>G^ak%s9$&1yo--WBA4#c5Y@3bzwkA*CEQT|U?0ztk zUs^ayzRWvLUi0l;S$yZ(gND~(3b0<@j#=ify8g%2spKN+%TrB187wZKu-wvAJ(QZ7>3B}mFgNNy({ zldFvAYNcNG^jPMl*rn4^VeH;(?R;&0Pd+BMY-$=mH0D-^%D4B+U$64-Y`1)Wzx+8W z|L5k*?-oSarJ9WI5Z(BZaAQt%t{-2|@;n;>>(A$i&nCX^-y|Rj$JZ-O|H1#Cgn$3m z>bd)ioc+SIJTvm!r{9bmOx#X@Nl%VPDi`Yx4keEEDm3Fal4Hl5E#=6HgboSj8m%25 z-!Q29Z#y-q5@rv7vL_HMK6;1bH5|Bo81blyIB@vf=sE?C*pi)?z6BHEw78>_zW^WfZhY&2Nj zw*3X>ogif9o#-R8lA3*O8;xEYHwSIZwVAcdeqU=vSE@`c)}S-;V~L~vUGSU*K;v5$ zvE+PkdXX}Ab*aH4Uz=p52PlG4BQ8HdMDr{4n*Tmg^1`0rR}|p45d5Z#vc$m29)8~j zAD?MfUW2wLuMaUro_=vNX;XRaD-<3Dxt8VCTJArjU++`e$m>gJ2iG1Ru7d+yTh=dP zmu>4;&osXMn!|U(9^kuf=(g}Z1r-hB+r!6qfW>z%u1wQ8@qp@<@$I!ee8eUp{Sgs` z`8$`=2H*D@4ZeLmeEVeL8}7e@RMPLiU3j4XT63cGl%W4k-wkBi1jwlWUT)ji*K4CO z_&B%O{;^$tyol0niy!TT!qnrp#gDI0fiOQ_ptRw~oCSs-bNlfJecL_2wPpEj*Z#Im z}Roy<%&nfgyA1;;am5W0sr-`z&|(x{+})U6(0PJ!N=z9*>?TWDiqD*ceDQJ zP@(YrF+PdS#gko7u`s{CqO{@n`Ub;`xQFZU0j@3U$9C=SA!&S@kAHUt-`s8DdjTpI z#`ho}-=i$PeLQ?02%xl#?{@9)O>_#6zs=g;kGg>GNkg{9U-^eHzBQCK{Jmqg;qT%D ztgfX3CD?A*J z4RCBeKHa|j=};a&o0tDil7E0gbNYG#Dir4DL6kQ9Jj&wQ#l!W10LuSH{wV!6<=gLd$p2yw z$72H=|6k=#r`)Fe^CkZPg=XcC3WfQ35T&jBEv~zJxIPd-`QOMNh2N(99myYNZbSa4 zP#E7DN?ZBAYIr-hk0<{CO3V0ew|{+z(r=5u`wHJjOSgq@>nwcVr?kQMOO{E{g{wV$ z2mcOyw`*T}rtxjozE0Q?eAgYhEqqTwrNaE};p02N;@ic;Hy%*^zu@n9I>5I0+t>+w z%eIN{Ur?zqzE@M)@b|`g!`~P7v-+?+fYLI)+vV>9I>EN|x0~?2{fKSx_eVq&#&<5I z4ZiQaZ15fF;oBz@-*CJ%NG1JvtP2msV>Ud@h?k~!1erDgGG_c|+c?o{qcQl{Wd5e# z@A8jFkQte2A8p*0?H`{#TtsL2#~(X@--RVUvt%FN0UmwA@$lO>z^{4xxZQYe7dn+E zuV&-9i-p1$AlI_JIT{rW%c~0r8+qv{DR72rP+v*Sh-T{33 zZxi1?p`u}YFQBx+_o{yze6RNKT^vAZ8Q<;phZj-OZS{wC!guQ6ZSnUjL=?vN1xg!y z=e%g}-QB}?_e^}XRLysOy;-(kTi|^6KZAlvcJdhfy)>~Az3g_HA$-;v#rI&-WGeh>ZyAbAT^)ebrl|TL zm3_XLvNddn_m(@EqbWsYG>?95FMm91!7o6GGKvQC^}&%oABuu=0GWErU*{jjQ*z4I zj3o>@(;2gJ*{&78lI=i|&-g7Zt&??UqMuz!O!POpKS56uIu4@3;Z&&atqIt~z%A`1 ziIP+D1S8KKN1d0ne8h27>HStu^)j58_+z#yC zN?GvW(6-2^e+e$zpEz};cuUm~cLu^@t@v;|hkxC^=unAx7>_*h0$A;1u^MBsdaa$s zYWbmtb@?nbz+eDkZNk$NM~H97pdE*|s``jcn0o>4+kb|3kihr+^!dhoeVN8mE7S87 zC(@ET3%t$d%&h!p$|r&5^ZSp~6~DX6JB9dNCoHp@S&HpkN#UegZ}B^x6&c$R2Mg!CyMx$pTjKlh}z z_&HzJIK@r16a%aoVge@BM{`Vai&2jVB-<) zGAtQv9B9>cZV|r+662k(U!5RN{P>rweTX0X0IpenTqYEbuqbr5DAcsE{CMTW;YOtW=_j&JcGhz4jKCgL zCL&i3pkd5HqSLNIA<=bSYj|}WeG^J9hSJH;3bUc?YRjuOdUQE~0Gv6VZ;PMvIm0nW zq5f*t`zG}OP-nw~$aNH~Kgv@4JPp9~+w}(xc}YJ|48!h_Q1r%zWN`=Z*pQ^zNz)7#A9 zp5AU=Z@m_Ma778i4Yv7~Ykf}ZtUX%6_xs>#6Wu$MHrGOE{qa^3|Fn{5M}@LiO%4L` z=$;K2yFh!_@H+K|Z9mYTz@MDi2ql4iJDjp|>DuT-lO=x>N3902?%6~b`$z$4LstJ=RrU9b7=2|>2rA+;~7SBU0o>Oxyo)7nH+8=5r_sXemPimV|D9w7exjz{#;}X;OytB+uV!k`w&(iZvEs55J{kU%rEu(BzYH2ii%# zAZLwV@*D~T@to}Cu@E30bU!e|UgldIGwkKB2&pA|+3Nt%Huf^PMH+B5WUD;KlE>j|&d~RI~Q6^=}C5TDaJ(eOv;e_2Vt) z@35TzmV@5Y_Hpa}S%6E8eH=l1E!)R>&4&l}aSzId?Bl5-bKCauerljYzI}Y<$&emp z*vH#JKg&M$Rh~gi?1)F!Q?b6+o%Cv7OIMbC{Pq`^RVms+_R*v!zb=R2 zB(2CFKa zw!>r*IK>(((T)Q5b-A)&TW~0?P#L^BF1hya`Vo)(T`fpmCVP?%B^#QoY7 z*u>riwxvgbo?m6lqan-P%~DZlshDTbIl53)OzmLwXzOWUIie3^k;{$I0d@JM2R6gH z&f;qJ7~^7YEy}5%D5!~nJ;nb-$&D)gm;H=x6`B!7(8vs9fAwkb0nb0-5#ZEe-M1zg zJ+uGRqzkq+O<~BAw`{TYOZ8?`&m2u>;sY7V&%x9T@{_#`y7-eO)4s2(gPQpA(Q0uoB2~}cJ@eP*_0;g^?p@K#bs{SsIg^6**I0&hMde_~xSu7| zJomQVh9_Bic_LrkS)#3h^V6H)e+%=^?l(kmpe=vB9{4`m#$R8;H;|OSZW~52Uh(l{jk@)yw81Pl81toWKJ*$MOmzuN~CjH5Pg)9BmB#t~T@s?SjS8x*?4JWqTd zQn58IF-kNA;OM=L8y+-uZQL;11U&lfMGNN!H7Nx^Tji2;72^}!Y2nuT_;rlNrCtd6 zJ~Qtk|Nd|Mk=S$Oz8U_#ABNtB1Te!J5A8t@Xvx3#+XqcC{=NN1F{oz^eb4sqA8JWH7fu7@QVQ1V+BF37C=DQxsrrMyKisp4K2af; zR)2?oACSuO@9Q8Z?BDyt$>#if@)6&^-y^r6@ei2(PXFGt{~f3K*uZ}54@n_^HxS}| z4z@5JxQ=cY@^_2DuKDr6qmMT6cb6+K;69p!ZLRoRKg05Qp5^nd+@v5rAG!}Em}atb zR8uG;DQx^N(mspI8U9YYaEPhAZq4*#BnCz}wa55_Cp%9b&HX?SMJF5tR)#CnIf0zx zKF?h%E8Uzo(|vu$o4uhQ@yH5+))`uLb{J(+eM26tQN;!y@Cd~?=P2-8=g|%HWIfj$ z6(S!OLVJZgS8$H#!~*N@_OrD-uRY7wDo8z*_HWk|;cd<`eckhKulxwB`ith~{o9>_ zk{Ec5_?;+uOr_`cptMj?>|p(ynIFWu6aXJ`mOji1N*(dWR%41hzij+lPt%nA8_Hq& zudLEaKxX>4ErO&Z&m_^LDc6jCYML|9&s%}v`M3LM-`C9+{M!#m(ChDu|J=M@8vnLx zC-kthK_+q?1?zSC2@DyCiouZEIaNt|_}m{1PqOsz3ckAk5pB)-xBZwAb|V-b&%b>M zd>?J&-=4NcN&c;87|D=-J4X18lSJZ?PaXoldo6xXASv)$x6b0{fM1q>AP5JZI zN80gUwdZs$^xc#!m@cB}A+#S6sKmez#m_{^VIJBe_Vyf9>Yw;C&h2X_%f~Ux7OQJb zJbXBAX}fOa3gn7n))GS@BvisO#5j z(5y>EjrC_+?@z0a@n?Sqny25X2SWOt?a%t=qd)y&GlICEg7uGEK`f;K1o6E7px^Iy zZ>m4oPg?yQ{;bv4S^jMA?wS7Vc4-%sWRF*O1wPYt=tZOPtApH&!Sr|fv(S9r>0HHd znm@|<5yAATjPG-+SjO1IoJ*Cjn@WbcQR`TpTEr#KPzXm*uFB#uSn!lMV@?|n8Sn+X ztc(v_0kHnFD~o^Pydg}ZAN7}=D&h6UgV2W~+RgpUuo>q8UEMW-j&T=+7 zQu8LcKzSOa{WFQEWw3VDZ1CRdKC_p&#>nYQ;ZXcXP}JoIIujH`xbsij>@=A1PcwDu z&a(>4nTU>i8P%N^`IS75x6Fsrkw@?@DZ8!t0#4au{PR7E*10=Cvi-wkG-k|wQoFqR zXVh+D;J#LAu2-Fh_Ef_eUZU)rFhA`0YOu;aFG?(Y&dc#`+HizWBT&3~!ispuqSRgK z`8|DpiqFX^i*Hl^u!Cl11OIRtWkd1H+xH0dZO&)zhc<-bmk#%a`Vpl0>n+^t&6lk4 z`iC9qSIfi$_Py}A-W<}G7}(|qajN8u?AO_>V=q83N=#RzYqMe1-f+U*Xx`;(0%1>NU%VC`Tg~^?#J!^#9$P_W$4M zKiUA$eHVk*vi}&R&@$vd%68v||0wd!vF|^=g6#VF7VW#m*F?$Y)fVjn&^D&s_aBYM zUgJLuR>i`Kt|b61w?SbJvsZ%^eTtV7Sxu`?-HuNVORx!tr=GERTc^V@c9sz3A_B={p;z|_YsP<~?j1|r zJorEd-xcblSBG{p49l{g8&|=svqW2HzO$+QoXMP#TW5z2nqN9ulJi`Gv7h(R%^*Pb z^NBF>A^X`=c&-x`=s#uZ?F{I^o)*t>U}E%tmnQljnqQj0K#y&-%r9-}*JOU_jebz> zzSC9nOI6G-`LnW`U$SQGDp{x|!MT~3K*nt#LdNw~%FC2|-4#>vu)n(Vp>Ld|!7+%q z>vo7B3RfqNipz&^VYHz_z8Wr6JuY&OZ#1s3a>-)cq8AoWl!(vV(saQoips|66+^2 z?CGoMPfPZ68lx_2PoMr;Eb2O(Kkg^p1ADslwzMkQc$|hkdpdGPs2^m<<6Bt2cOQk( zh++o{)-z8jQIwf>O7_+t^!~`5o9Gi2Vze6AQ_NA*^>(M$%(o{Z&wdoLsb+5JCGMF- zL9U3@bium%3-6=L7`FG*<1o#*+XW``?;!Vn=^bj*WF3Cgbl>heCVm*?J_kkHu)E@O z)BbrJ^FC?&^EWscvOf>ehTmCRn18wjCWY+J@ze-HpbY!7H+;*oKjT?dcXtHjA6RbXa33+ZsUSh5U*AD_6AM7;W>BgiVb!S{qIdDOj1J6gLlv>MPVKn1f;BN(Ie6eP6fBFk zbLu*QzfLZ0T^4JH>(&5bCgcg6K)Lm;#MGE{D|{-BT+F*N=dQ*n6Z`Y+dA<#)1?*G&cuD#iojOm9 zZEif~GeewM0ySl^1=$Th-CpoERL!c0zgjd!;Gi-Zz7s}tM%~Vs51)}M3?n0}z|RWk z8ADN~fTEp5(ZHuE6QP{hOYQWxpV(*Ea5xF-uyk|$-@UVcrmlX}Ot3~qPCeKmh z$gC@;W;z~^PgnhTWVpddJnqhmY*PP3X?WbtV01gAf<;AqR?$L!x()ehY}$L+j0j;f z!eaA@af2Ln(F`{0I(yhGf^@K15ceg1J1?@a*+gluiBZU@>j489k559L6GX&du%a*j{5(TwdNjg!sP<})S=o;b)(+IACs4rR}yw;esmnf`*&^ohgl z*OY0UFw(th}jp z)amV*)aeK_LGU6_P0w{V?wFS37DO(EJ})H6^F&I%n{V7G$G$fs$)$z~bh6h~-;UZt z6Cw|ow~H}F7uH)yP~+!NnElsB8qXT@f!Cuxq97wHruJ4YPy{W z!3^Yw2@$L--I<0J*5*p2(Rgd0tI=3%r}k%Y6`1ci_L#FY1?KM9+Esk7TYk-+wM2ub zg97bW)HJqo|EcZ`0)h&fLBOn*xLzFhHV2g>Le8~4Ia!g!5a$>`B6 z0VMC)j0$sp_(r#&BSGJdKim1E_{3qhxe~&*sg}ws|?&{h?xIqxBN!-7GCE#pX@oMTMEX^Ry7dtE0#& z2S<8P$fj7k1L5rG(05o>~8F{B&x zdRg=uXw0Iw0#vfmJC@R*S4$zMt}jgWO!6aO<@OC>Q|~dW8IyeMHn4f0Y6hF@R6ia$ zD8ObQFTjSz+o|z8=lE(?5rZqLSNmR7dwJTryEg@RJte&E-XYDU8)SZ)Gcc@|s9Uta zr8=q^yh@DujyzE3bLp2nAFnHTmyMVDWPsO}jR9W&5MEo_r|~-2b79zuK)J?PBNKO`x@ikMd(jv}a9eMU*~Oq@HR~U|K#)hYh}$<5NaMC(gZMV9Xf}wUZ|;IT zp3MiIandiicQ61aD=#;o>Z zF}7sohx{RM-_q8%Udv4NQY_~NzCXivcW)7$~BFPJdn=>Aa4RB z_-z5+NWohQS~kStehNE--&yD;sS%8CWq9%WAUW{kj|{E{tL~`*)P9yu_XXZ0$Nbk+ zEl0T6;z#uA8D1$)GRiWYH{ATg`ssJZ%!e6?Wl^bl^%;pfv9sUuJFdK2T@_`1ZU&8;I9`o?MYRY%Ric z!;$YN8^`e>MLeCINTUQ|<-CyxDOGox0M?3T;{ z^rz%->bqz2)rJ>?XfDv}7kO><`UTq4yn*!k5#A=B374B5l-m{0Npn`|CIqh^Gw5z~ zFH+TaB&t~BwBb-RoEOfE{7QDC=9G!LN$Gym`Te}YISQi5&VXw+n%6j^GCsBx78MSO z{ZLl3ipB9p^Kv3%7IXiT#@*`kL+Dh-R%S-T$15trQcjy?wc-HiVm;1;>+^@`+Lh`0 z5T96Tn{3ciY-}mw%)v0CVSg*q(tkLJZe}=tmr>S<3?IivEua;0{*6Zuqplq?Cl{_2 zGi1E}yc9v~3_q+YW-dSO-%9UyOm6xGf;7-M(3$=YV-q_RpT{pQS-pAd7N})NVbtpe z)Kv2lA(ljmny*p3+{+#z%AMjAFEmM`uxn_ddW*Z0G!*rm_KUiAF3YTIo#~e_TV)gN zj^kIfnCq;Z>BISn0TZ8p!>RgRdM@?U{Y_w9nA!bl-aW|#Q#J^H!o)tAMo;JD(#3bW zL0$Z4`rBcWR#xO-JLC{r8HS=2~cg7&Q zpXH#3m9Sp1^%6bYu}*T>>dw`}c}6I*pzW84M)kexaw#AiZ+n*~o*b<2Zm(LGO1G@AA{x~J%2Kcs3~Dd*AlxQlVD);-h-%rAVf zUeas1ty&bEF5)#QAqq7@c_vp|5dg(_QN%PxmLFg?^OdumX& zpUT3Vxp-&AK@3hAc`tB}#>iB}cZtpA=1zk9)p(IzoZ2eH!L;|Z=istozN+R~L0kT> zkfHZZ*>umLndCljz$7QC>{(m3Fyrpj{p~k_Zx@ZDqm|h4g0%H#ZfZH=wcv&st1MNI zNBJMnZ%55J&be>1iH2g-<1RJsGqg+GxTOK6iWZa99tx|8fO7KHo%kXuFv;C%5>HGB zEOctFQa|Ikd#g!DD9+|7utC#}o{jA#`<@(Tq-X6}Ep%9WwgN|~magJWas&z`{pe%4 zev#OnC~0^b!G8H0-yQi2qh?pD51UZpEi0|7u0>j;_(-n~u=QfplVqQys+H`G-=Wlb zYAIrrY^(c=z_v9St~rK1Jh1u64=CV%rmv$6-pt48;g|2Na?aJmG-77M{rUm6;aTq( zg!5?_GTgotGQqJsk2Z~ZnDMeY&||w;x@YPO^gqU5PybW4iSyLNZok@Mr|99aHF$x# zal-5c44^SzdO}&Rz6SDpS}ginEN*$rlK<4NJ{Cs=ZCpzmx|TNIJq|@Rn0Y$J)#2`F zxdW8Bz-)lYciU1Axx=93D(L6#FkeD*#o|OscbalbX(x4eG`7Nhf?vrxsRj@C>0vXN z%Xi$Whfc<9Y;`B=p&MW9s_p#602yppW+n-;Zk{@c($bCnEs+(r<-e-Zf?oi%D+Wu9 z>@BFS5wG0E6)NzJshjEC_A>T2(6yh%twhPGDn4HD7U3+klRQzfzurA&K$vJI>;8b3 zC@sW}w}}120_vzr2k^-XHE*?`ZFS=U{SNj0(2?W`sy8(o&2ZpEXups!(IgugezvKGWap%N%^ zf%)zjKv^x`LLISq6|)_cG8&b!cim+?SQ?8=OI0{ZS)}@b7OO`ryk8gDKCxQ>?H__B zlj+_qcyM7le+B<;ubt@zM{YM&JL7_OUUgOcTlYvnCI7(yB%~GtY-`hL&3*1?AMqgq zL<0u|Fs=cHnmQhLmF$2NqOs4Rx{P`Tdox?+{+$-Yq=M|R^E=R{Ry`VD6|)j01!}dJ zR+DYLZu=Gh0z=G`Ull!AK?gfI@$tV!>cY3&p2MoiRRTze&tSGu#@Z$h4yLcNds8jAsaVx>| zzXeo*Y7aD^wz|uO#Rp)KVdvh0Q0VOiAh36jp^(*(Pd%3ByK_2Qnbz}HjGn_6+sJRL zgczf2oR|DoXnb9$s3{&f~noiItenB}s2VHaaezKQe*AC04Nrmw=M*of~_ zekI!*2U)^~?vw@kGg{1;}+*K3PWm_ZutH32Jsnnov0TEEd(#yWK?VJV3)KYc!lLdT;oE^;$(Zl=1KzbOYhtYgtJl1r*_At%v z1ou1WUocG?QANfc$%TG6lb7M`9X zMs*#|ANLdbH@wvTqC+oFYrM(-coq)&`5%1CP@P(hy@98m-1jR0JxXDK>_EZ#F;*aD zrk#?#^#}bqa(xs1p+dtSnV&M-TsUvx#OCrps7Ka}xt`#PM9M(N)E;V;y` zpd>pVJ9e3$*Kw%468Ur=f$28#Izkd?W`Eymji&>9@zy$VFF0@DC))CDMhp2JJ78Z! z`5j}a5%4u5zoQJkWaW1(_yRr`!$sKk7!~XJUpDeW%jcJ8TRwlZmJ&7D`-|@3tNSbX zhVwftpQ@MG6cnjlv_afW`Xv-g-4}8B%8h^NqZ=OHAiEjatA%A#|@LQ_Z@u$LX zyv47r#qT5!zbn3PV$VYUaB`u#hS`7Hy-9xL>xF29`|Nk}gJ%CN{b+t}^%(6{vfGsI zpn!bLW&$J`|1ZD8_`g>DiuHs4@qL>t-jksDCrobrB#Y)TXa;PYN%ExFxR6%T?#$P} zHSU!-AHO}j&vv?v+H4d3q2E+XO-ZkZ`2O=?Q`h>>5hjGwZ_j^jgfF(iqeGrBH(kYg z!oqNCbNxDInj!Uqr}xJH?TcqM{x6m3|1gA2{GaJE&F7PkNQ$Gz|FK^{{*OQIC%6rG zDF65H=(MUB|Mz+_(C3jCXQ@iq|DE$GfF6a-0NH_p^~7Y-=Q7hy$=>=S|Cef_FI4DF ztAYPJw^{$E^M=;{J=_1S_Wd8n3>CD}VM9@S*ifPIi2dB|o<|%IIJ+6NckM;KKit>& zL;pYa-aIhMBKhM^fYEpku8O#djw?uT zRX~jkVpy_(PBb72D4sEd01-$qhk|F6WMv$qc&zI!uIsAn>Z-UN(N#bMyzl$MlV^;I zH+Yfv^R0fKxiV4wz3= znI<@6+&OpnN9YEAcSN<){qBd8HTO@m8;_-`IJ@D=0Sc(agF3$5NORsyZ{$C3x7x|% zy44x>V}Ubp8UFL>C{tJda~`WCXFsa%RljY!4L{zMaO2yLft4xMF#9pwsfOMw+kvvA zUQ0F7?Z;To4>LYN8}rw;&<!k+w?f_)E#cL`y6RMcMKAe_%Lri zVnz_*=7myR!deP4Lq`abTIStA*XHt16}#AQqR*Gzs5!v)vWD$>5>z_fsHv4*;vqFT zhbRSSWUIaTux+2b9R+!7?-O^^-V(8uy;E{fG`?9IQSq`S$4gE49umOr%^>gT52%tx zz}=TD1b=$2^AFc}Jw^B583QQCe#v<(OVZXqP)J+`{zd#?uwHrJH8Asig}+kj{RqG5_WtMI z6Ix(~Cs^Sy%IFPyPpChn;UJG6_ny!lLn!pdfjd~&U@A;?dZ$#!Jt;IpvsJD~7|u}* zMIHT9f3PnrBD#@vy5H$(+n{u`qB?g5#MU%?!65xfA?+I^*Ef%w8yl=|mZ_#&-$blx z5M=JZ%OL$LKzxal%y#?wcgS5dZ;7Out$*%4p*LMOye#>*7Vj9NWv8wySdggr)t@fT(9p44y?7-GiM){ z($y~3GwU&l=&J1ZF+k_iQyZTbJWq?SSF`Z{0Bn2B3FJ{Efk1Y-lOOqi@0v`q?tOLK zLFFlGo8DXaRqyxItV*sQST*?T2it}Vw_I#Jy~b-p;p7nfZB_dE;Zlrea{kx)Vf?YM z{efe9BggiMFlO^VRNREF?XcAPVUSH&>F@N6HRbkiJbgiHty-@2!`EiK-TI-oYNh)D z_Xaf+>Fb9jsVdG7SS5!l@B`)rb#km9UctYW2(Ei4bN|H1pxv6t+L z>9W|u3VMhB2sKEn_ke1WCiL8o zi?#U9o?brP3lp6swE&#<$=HWgm3K*LK&d@i2N=8}svZU8LYved#%PKm114}+JW)8`8pyc8yRu}&%U zX4)K?<8sw$)Ub;YV^kG;Yi#J^&$eU`%EHZ>f#mrfRO(j7p%g3RcGIQ<`ohs59r|eU zL(6!-+HA&Y5vFA~#`XfbELO=Ei-Gg~t=@00@6gC;S*}Cbcqn=#rtmPC&(@;ux9O+2 z{8lkl;GOY?4fr8;K9@EOFpAAo5bm|!N`M$!XM-l(vJjk!m-)xpP489;6SpVR8U>dt zYs-Ki`L}Q219*qQmamMqFR1GfiZfl~O`}3`UvSH|369lC?157EZqm7p!I`xG98+xv0mD!Yx=?y#2M_7vN0L$7Ub3^K16Z zJJH z_^+)L`y`HXB#In~i&W*VSA!-DfP@hD6yiCCxWntN#NSDH1HheF$zPfmJMWL2nz0^u z5Ujp`wdC+$^sjbe()RtUAIATTe|0-&z+MR)F*^SVVA~kio+<>42$tN$52N#)S8Q}< z`B&Fb>h++q{Hw0!W3G^%74fb$e=_iu@4$o*_*sbMIS!(7o5RhxNt*3?kipqTAAU;X zCv&-!N7%;E_8?4ppeDIov(gNk8astamw|Q+6JGPT&ioxK#4b$wF|&W!(|va_H>}@| z#>Z)e;g&}bNm__1Oy5igh%xTT0xUMY+aw`>zDS4?ECx#y-8-}UUj^QB=2w5dSmx#n zfAO(#W5`RqEOQB~HydM}m2M>fbkr3h@0#$D(a#kdbv3XwVxG;@&tJ4Of z{f#*v$;p`)lfunKj-Rn9eum}bXHVeZXG`E3BPrYbwEWZL8Qph6hHXX@=9t1>_fkq> zuLrNRVNm9bJ;-a*G!(@3XIhtcUX%gjLEYGQrVtgz8~*gSO<3W)p5f*W$*GfQ!h{!~ zlys$7@p{8Xpp<9&Yz*<)kifXC3QljZ&0gljaG5+QCv#EzP|cj*;l@I;(1fVM($p8H z!_AM9VFA~xy_q1j%edL&%SHcXMpSP{y^?tt!saUaYBX2DTS}d~;m?J~)14`KUjw+! zg?(*qZ$c!HRlwj6f5Rl5WYQDeaO^J>*~`4F6zPVd^Z%}&Voz|JyZ}-(KHKN8cm~az zlK@D3?&eV^s*^$Of?p4?>=6z*%Q_(+=#a;S{9n&&E3d=bmnD*$DzC%Rr}m58;KKv8 zQ&UmP+3w%i`2_N?|^RnBKrlODvrV?y2o)NSm=iQ1AItSNm&Z7lkz8p~PtIBJ8b zW({Z4O3;@$=rz{^-P7mo@+5S3@#e>I_@tHq+2%Lw2v_+oReqnYa3r2a1XOBladE=OohKTDKuzuU!^frs*AKX{+eVwc1sDR24sZHsI!6paOe1 z0(6Oo3{#%Bj}osX<)>ywl(n34DZtiB$WKkD5ppytMB^N2sMeHZF%$1-<4*k5w~&h5B%*eg4z4!7LVjqwrRbAZ~R zEkftMq-LwK*c7fW#Q)m_Gu{h0JM3ecYTEW+Jan@v+B*6l`C>4&a*VQc2{(^W?yx

Ude%8yZ^!Z|lc9jdo}U zsJN^AbIEY7L~7Ca4b<_F-iCU^Oz0OH{R@$2X>5tLX=D%aXWJH@7;d?k48n{t;AOGR z`+6gvVmR=)pG_Y5INm;Tb}DqAPm{xZ&3^W>2O&|!!YTfY{gSO9n&v7Xf2eE5GEax; ztYQDM*l9UE9k+i!9n#2g7x08z?!&)nza?qkyhA9o$FZ7eqBvgb4IwLm<<)vjL%mSx z^)Bts7iJKC=e;YmojPp?+JF}B8$}D*eU}!lxkf+5hfqmcSp6jRx}Kl3M%hgG&j!Ei zhfFWx3f0%E^xTsa`UMXCC!A<{TXcat*WvoAgaZ=u&S$rV`|M_EpixDruwl;XzOfmGe5ZyFct z!!1`jE*2mg?~E)Co}p}NX}D&o{&`xybdSDM!!wtd=h#Le3I_4;0G?m+nwS8cl#HKF zJ5Mu#x1Fa(qu4Dqh`NQFud}>N|Lbz{(8Uo4YG~_uYO&LKzfQY&>`>(c*0`(OF}G2% zL~bT2td`pgdR6FRGkRz2wWfxn-TO4}GETdEe}KIsH!>3ynk?)*{ME-8Pp^`+@%4R8ZrkoB8cwoSlZ#wQO8 zgey^Gb0^N$bD)Y+uWglUO@e07n$bdaauU@ch6*c*`YvAS)Yta5Oc1In8VKW`uKGr* z-roQ>XM{cD-O84L<0{WkfoD#D=Z^s|n(-g}E4;kxcsb4?yPquYW0S%*AbZ6-K8b7* z)4ehE`vBQFAXAPp_P)cjt;2JY@LasYaW6c*z#~h#WfEVd;d{k<6R5-lL$%g>Mu}rA z!F>iL8pW|}o6qRoG#8=u6oJ7$fyCj~t#A_iuKndQJ5YN4G62TGs;}LC{Nw06MPP!? z=eNqCTO#Q9mIs1cfoJ5^Q#rAd&&z(0YG0n)pJ|(j`Xv3CAHm}9-+VWcf}f9nfBVs- zKQru4KjY8b!-1uDHcT*jKQ3V=dCtlEM&y7v^5I`I$<7e(?9aTz;>a7N7O;Pl@e1a8eF{FiD7=zyrVxeu&Q$9cQSm68+vCr#q4oIJtlODC z{tIB)(4WH1%fxUpHg7*wVaND_R=}cXuWzC>eBt5bLe7o`qFU=u;q@0Y)D$;)*W=v; z9#g*p&>QvkjrG?$80h?(gzkFcr9^R@!hcz;O>R2?_!!gObXqjerQRfk(Lyik3(X%_ z!Wp>VZ$eRQp^eD&KQgVIe2H4M2Wht4h4TR?wSSZ$XS)3xX@sDo4mC{2 z9pRQGFvEFA^ZnMqJzobnI&{W}aPy0Bj+|{jhwTb6I4DidL(PkGM=-W8VsieCi;D`J;_Q>A!^#bl$*_6did2L!3LX0{_EY0d$PR zpP*jmwEv|Mlfq4hmF)Xs+aMaT()abca;1n|A=W8NSz+-!(UE| zQ|-GhXx~(IOpf;H4IN3+H7=^wq-m^c+{fk`;pbT69t}6ou}YbZYotkItmkX3H0Aoc zN1UpxoSxTGq3N{VIIh1T%Z_ZC3;1jK$lf?*rwwsabuTS!NI5kgq^9v489DwplD;*E zFIcy@_cKODGUiTzM`Sxdhe`~w$`RO@Nw$%gv5DA(S%$XMvfjTxEonwE=BxXOBG@KG1OY)EURwEr)%S*h?A3?k@aq7eJ z^AeJr+XvC5y!eIccn*Djg4NWakAEJ+_YHOEvlV6dQ=wAow-IcsuI-^dZ7n{5`s&&< z9}ec&h&6FUp7#b>iJO>b{dGt1X2&DsySsr`!U}~cdEKlk_fZ9TNq(0ry^WKfdfOdc z{sz}O)%RME&>!4iM7}SWuW9m?%QQ*#&kX#}HC|Nd3tU?GhbZ0b@O!^kVttZd_g?;t z3xpl{yhUkO^7-N+C!YcPBcI!yd_It1T8l@hKJqyp5Z`&T=8Zt=_=4KKT||+S$67c^ z$^*f>@=KEC2dB#`Szezke<{7bTmQjzG|u|(TUV8FX8E;2zBa*<{WBle*6Ry8_r8E$ zN=W(NP9Dd!`WT)vs=*;)roO!UUnh_4ha!(#oIGBXAh`db`p9D}AWj}`dv*kTNgsbW zpFw^SxPAMQb?@U`s-^V#{vqJM!r^al_@AY|@PGDTfPVokl)ihXfi>|-vc296rM1cD z+HZ0>(kLS@Js#la$3urf2funYxC8YMIdT;~xeFPtt~t9HImwyvrg}K_u2P(DDi%GZ z_VfKyHS=J2EMp}hO??{Q+#y&+CsOyVKN!s)nScY8y2#c2lq@xIha}D0T$O*SipZG? z#tYgnbT0EvRPg#BIp;Em=O0GLx}_7FPc0)!>5%jHu#?zNMbh^%z?9`Zc(N`3MOzMoQ$*AT+O~^b_cy8| z*#A4v$!1L(5S{n`DD}3Xa{B%s4l*AQ0o^6ya_I7gll58lp(`3{;v1L7zR`5iEw*uq zKXVXuG#Vj)ChKwVBkMc3liq0}d>!Yq^V(Yv0nPiNqu~!NZ#0(hsAT&#-T>x9Io~aB zZowYR!?XnXEh`)qTbD68I{WDTfE70A^W?n7`&?CooOCsNk+u($(;AF@K@$lc>de^! zYFhBnU-buG^FeA?8V0|4YrNYXiq6f@BYuWrf(MZ34bZ0ode-7)4k8Oj-BxRzT+P+KzEJ>Mc+7&M+ z1!$5oIUh90B*{d4(Ij|^u2@RnF}nFaBol%nbOB-^kQPw8H@NHw^Bw-k7zLb~RIwY)DrFycsSPG`nIAFZ}B!#|!J$-m#F60+&Y|ysdYHu@^U$$2_ zB6Vu|kkG_Ki}#j6S#*Nhz(Vbddj;uUVcW|ff+}p6y-0@thSY1QTxoo})Vo64g_|E_ zl?e~?zvY)5Yb~q3Fh@OegU!9jCZ6ZPXE!}FP$2e)t_)wO@9lJsrK{RZ%;|Zc)GlW< zhBJE<1(|&@UF|@A-yy%8`neBPN{IL2+d#BNn%c6OKb*=J03B^9|i&6OFfP*iPq3?am6)18jQGZ2l6M9 zbyi5EbV;2(!lCKR)E%lVG^Yk=US(Fp6qd~UI)C2h`J)O}aXd{HY{FfWk2o0G>rsK6 zqT9&WV_ZIKct1!E?EpiPwFexE&a7EY4eeHkBHa92s5?G_1_peb+!Y_YTl+xr^`;UN zJ-Cj|sIJ5`uq$3ZS8effTY%u{*B=z@)yA4fe$>axUo(Lp!251~FmuK;E zk3-UVm~ZU2WBzjzjCdK6;w8Y6-AF{Z9;1lMUAm4@J_e`_+1>l^k%Wr_oVRMp>$;u z-@CsD-?t9m84lmNv(oYP6#R4U{aB{MI|cupgCFDIS7yMk`Zw^`+cQXOypgK>7{p{F z_ERFCp0wwrm?yov*@EQxz0@Sh<9iB7(j-}|T?S^zFYWc5?7*OZAimU$7oNWz1hvf2 ztk<%s5-fBc6)U}zh=;!09lqB)zW=h&W$=kuuD%|nVYylV0I68212YfET>be^N!y9pZ zY3DH}DX))COE~!0R;LLEf<|0yD(IKt5%D&UXj!>N(z z;5j*O8=uc7GMhbJstoFvG7NO8*}Yw}Zw7^?t>#iD;)GJFG*0}yt-lTwo!?R>His%P zkp%qB>QA@yb=|Uwo{e$*aPJhX{0@8mGw=rBhz zFb`4v@BEj_u2SMLFpI$pl<01A$Qti#C5E{<xEbIZeVhlW z=BF?yock-Wt5jnllZSCz0#e%p<2;r7@!ZWHyqJsaWvyE7#U3w>t>TTSa|UtUq8Mu- zwU?7=-$;ue6f9F4H{nLtX!vRzX^YutD#BJpMZ2qLw)X>y!1OW~wyutXVIY?R+4ixU+KzYU@~=@WW54z$-Rrj60B#SV_FIGf($?Y| zgk&3#wBN6I|G|q(ju;brx@6*L?t;ah<=Xxbu-R?ChrR~A?(;>@{v;3Kmc~|Fd=zQ| z-cs=DMQN7a{{UP19Y3!T4){uwD*5;QxC^KK*C+yt#z%}p&JA00f}!8dI#%Iix&5s~ zI~E`<#?a)S+!Safy4kDNP-C_#aNDjGii7bAv;TVp8z4z(qoLeJW1+q2LutVp?|DhCl zztvLZK?LFN>e*HHlH-DYjfe8Z4??^iAtH?zyaMcz(Q99!_!&5w%4r&g!#h(=cTBNO zKEWN~_l%lY-qToPrvY{4Yc-3bM5wUoz%I(*#oiGngxvSr7%h;;sc@%($soH%W%ka> z9Oo|yQZvq8L?|`PEsOo$?O6t`3;I)5^3@v|VXt8qeZP4n>GqY*ul62LA}v1eR;8Ph z`ruuq%E#gj1b#U8|CRN3htJ#0_Ys;ek?Ruc?lvzH3#=G@@b8zV#Xv-(@mhwlq^Cpq z^LqGOTY5!(OnjyuW#zzJfmati!g5D%nHP>8{H=Wf2(4@1Q+j4GVjYN%8?SPyF15}J z&)<uPc89zkH<%XA|G>Ow zU4qbu)QJ0lK9>&ch}(Nuql#WBR1juX@Y*5PjK_!-07Hsik8tx5WEi_WVTTI^w2zp8 zwMI7@`_fAo={Z$8p=ZyIgX{48p$Oca4dArzVQ%9yUQcA6*qH?V2*Sp#`9&}ZoA+{lW3VtwJtv%^wns=cu_gTM9uh6ID~k9!y{$eUo5t9L?3LqBbpj=+AJ zZLr>}ghK>juy4|Ait_7Kw8Hxo(**x5c3UGpvG@J#w@_Z})v5gDul^DK>*5`?cxf4l z0mx>?eP8Ib-rjEb!vO`U1@iX&CUaYo2 z&25>%E-I(oy}e6J`Se-GhO46S;%0zQ$=hguppvtwZtB=N0{t7GrjqMQV-v}`L@L-i zU-}pwuspUB%`&C*y2qBFmJGPWHJlLm`yH}MJHeKX=*0DQpg96HTPuD;;+G|5$Ng-q zYJgpg9%Kx#X5Evye@j=|)T#7r`GN%OoBFKvim+_F(YbRp-q<^+bO>ds0o$z02h^D8 z*XV9F!p-eLM}+5F__cj+hFiHSp)A9E%yr_FL@{|Ad zyYdJ%@iESK%7^hb!x|^9rLB%%?+4TdIv?~lI^SIAl&J_3W+!x{W4alhf3`SsA0i63 zG?0+5b}Zx)(@6OKpF|Q>-no#44`AE`wCE~nlKX7v49dW6Jh=Kd9aRoW!zgXu!}P8>`bJ z{bOtJC%r3>fNvgJz6WJu$F%vy6oj2j>D<^^HU_05OPgLN@Fm>x4J}O++H!{PUqBvD5pncxW zGC~-?=7G}1*z&SgE>M=Wav4L%S-oL4uYIS$|HdPW41Qkk`oHUJeoKOKMd|tPV|YjX z!^Xl(s$8hb!Z$?t21WU+u)UAjmkHea0~xPjyyIQwqhce49!+R&aUX--!r^*OUIRYQ z+ukR1Glo`Xq#@gdz);x%oDpr`!QCUn&Zp??Wpo<3f03lI*1N@~o5q)%IrOiiZq#s? z?CX6<#DCbco+Lv^eKkq|M*~}!wet76C*m$@X|9DTx&3NvI;2O(~Hdo@S@*{%KG)#aq63yVxx`jRaq~*oz878carbCzkBfBYC+4>v*rB;CZ-6)STs;vx+-H z*e|daBqlJQ+j@=iX#7yFP(_D+!Mc?)e;pSp-A41&m()08dkphG)3aV2U&r7c+2lP>!z;KMzB_Olu9k9>k&YTMD`RjBeFZ7l(iJy3%={ zVHT(RsYdseb>_PLta^H1@&KII>$148~qizN_2K;kGxA;H{Zir zN-G<0h|cRF>rMdJA!1r*{UrG}@fRiw{iQEoH5|p`NLxI?8jWA(qv-{F(q~C{-VMm+ z%V>Cy#nIMDqSCm1`@p1rsdEEDb$lMCC+FB?d3~=mjvC)daOP_ySe-6zm?aX^lO!hj zBx3ZJPhz@}=+!>b>0b)}r}=dQsokCb9l}=0BR##vSa0$3Mq)fPz6>9`#Ni0Ht@~r* zP-`h))5_E1U;5~6>+~McO8n+Ct4mu)J<3od*1fU{JvpO?yrREJH+_epJNUG7c|mvS zp8SMp<%E_VrSZ*Qj&FsZ!2L3Wg0B!OTaL+>!?3FH%|lxExXJO`xUOv29(@}ZDmG+J z9&1>j#l##$=$Hs!pe?o}BZE6e#dj@hJ*|hgL)tRtbY_3pIPb;o(_q0*u6 zG>j^(+?a6#Kl?6s-pB`=Pn4L8G(rZ)aacNZ87m!xl96)s^#lOlxP)} z87;F4n3hlH9IO41vZ1H-3}5iJYAI;u;P|K?dXH`G`x6;?2gkSht}H$~5{*wUjK;Uv zDvaG9x@luG`*mz)P2lEUFF9=thpn{iER4pwnLps>mkEUA>mq=5!MIw|r@WHcu?QE} zHnqIdaO>PomaZ;78V!$X_oi8%D$)fbR5}Fg^4!9szVc!hsfK;7E@4jNw=fv-{&q3h zM673cD+}b4tfR!Pa!c=XgwCf;ch(f+5H!HtEzApTb#`ctR$i|zu)L8^> z`blW>&gh97uq=GRrKASG(ca6qgQF4f3`Tc;bl7n{&p5R#e)?Oi^lY|duXcS|eCDgY zy?a@(xEm1-wPort9v5T(2ZQF7!MlYWC%Q(2kTtWA4>~KY>*YmeT&a zYN(6TI{XuV`_Ftm(?>~|l|xzVdmQ%T%ITWlUWgp&%OZ@2nPai>D7$xdrw%qtEoj~Y1*oP-Mjk&ien$^qeLt~Vvl;4 z7`*KRq{dZ+Tabt6_XBmXC=a)6M@nkFGn(MG7Q(U3$g^+yx$(!XHz&X!*l9EY8jGkM zA7KMD@Fz4*Uj@VwntPQkn$Z(lj?ldSQj}Oir2szIuMFZ*_dH~CIc1?AH`7m_+w?P3 zm&GsHN<(SS2Q7cmO79B4Qf zJ?oI!fs&7`B@NkY4q3M?ejeGM9I{s(vJu*F@sSNlL-wFUw#6@S7IMf|Ib_i^WbK!y znt7c=*0jmbbGEXlcv<8*WaHA1U7LpN9Ea=ymUurWv$!FmE( z%n&nvS9^cQ;u470dB^G!{81X;&tj9Arf#xzy?fi>Dx+uZcd`2)?+@dnFEasjW^ZQL-^Z(@ zp2V`XIx8M}lb?s#3+C^5ll90YbDWfRH-JU6#cVvjKxMJehrEY`kgnyYEIw~OnS&P# z+h~Mb7JtAO@VQQu^MO*~I3;_9uBS(-dyb#`xRSj>n^BY8)5-N#*fi|g7pMDVVq`W~ zdwXK1>_vmrh9ce^!}0Izbm{K6y=(BWX=`ZJM%v(yWL>*jbh%oB*q=K;UF?1|5>Ko! z(bK;an&^iiur$%{k;Yn+(M%KlKw{>-$8DAl4w?OzRm5Tm61OeXDD@dj3o>8%s%fY3^InN6Nfa@SKI$u0GBF9s`h+e4Q7pr8As zfO>`cIN9Gru2;bX7by3C;4LNP71-UJQq~vOlTyCLG%s`)m~%+^W?#xP;^|WM#liK- z<~nehgohG#pC;kQu}%S7#~Zyg3AgS8501QK@2 zy-06~AdePxK`e9xCxz(}-iWm74|h^~#>q0z&+X|XyuHi)eyoGt-{o%RdgE(yy$;M- z(3BToDJ9`5=AE1peh^_KCH$f_KNJCT4hid`iu8Ds^SY356Sz#m+o5o25}uyM*6Bts zO~SVhgz=4-taD1Z7;uyDDE^RyK5-JB)dLA*&*443624GnUx#NHz@o*G$od}E_Iv>7yW2>V%I*jG~}WvjD{MlFRV@ZH#zPZRiBv&O!? z&K9`7MC$!TE=n$yUKR+v(iiwJ_(P>H%})t@RffQqQi2J2)d~E;LwteP^GBM%-*loK z1296IN}&XPpv!&5iS`6Pcea3fg>F&dfY8z8di~N`v}1q2c7JQQFYI1U*!$7n zIfU)`!X9{Ty0Fu1hlhMk&|@+MeF4sCFyNk}2sNB!a?qu=FLs0RJ@9^W3OWI}Y4#QT zAz3Wt)Xx{#!(5f%?|4r%oas*Yfsse4^+Y_++?Y$&K?mvltJI|bIVmBz4bgQhDm0K# zo|Eo(NVj8AL`VjN&IewAKX&Ai+1p`02+|#H5*QFV)rWYUYK)*bNk&kw(BZD@W{~zS zW6oja6A9YB9kNc1fpunrgE5dcBmK@qB?R5W1iZZ%nr(I$G3N$8XmwW)Yb;+gtAtCJyZ|MHb`~>EFgo$?15GS~g z)|-{tIGSnB?>)!~d74w?>C{K`clx=HQ3-i2r3c8p)z7`ko$D%m`=@rsWL&u`o4*nJ31-Rlz0ArzbBu%BC0SI&}{o+?$7hL3Wmy+w< zrWIlA(MdK6;9>7yU>xGov=0Frsmu62V&XcW{HJ(a++^yE>Z1>-07J4 zCe1A_vu-jAf&3C@iqb-u*FYgdXsGO zaSC)SJfv1R519eZvC6ra*1MULRn9fm-q3R**V%F`@I^ZL>@Gw)K8XwKai-x~v;f`n z7E%L=nM^-4phdl9&6%;iW-D_%kFc_N_dzHc`)KgL?eb~(Lsy2vM)YGeKQsZ;Dtos=3 z7<7u;L_J)^g~s_a-a;w`?O$!k(%NrjuKhoX{rJ4as^+(w#;}nkL9olj_o?Z}oFeFE zE#WBqK3@c>$9CDE;sn(@#;SG_!P~&w7(6Sd2%a>S7FkPt5llWS?e0g~By>BVc1%ft zORN{0S@wX?-s}d#0mmS{e9W^13jtgO|kta zcNtMuC(0@@?g#N~YzMF0qfj`i-Hh0n`?Dmx+l6d5hs>Qvc~>dx?j(LMuJjkF^l3`( zMHsH5@6AwpMl!8!tVzl`myl)KcjCU1(uWdzt^G>&WZHIC=e8CNrIj@Hk}>dq_Ziyu zB|aF>_C6YRUZMt29ajbB*^bd5IHX&Fz1Aij0{NzqU5&zOUM|6t&I2f%^g49?x7>!Ia}_moyaT-tPz6Z8d}`3T zepY3K>E|HfIKbzNcKK@aJ6HE~k-3J7i4O=83HED^pFsbGo&FbKg8&~eK*taGe6Z&o z*d78KBd|-e@vT$?T8nORfZYYyH_36mLR2#KJMQ4;I`|h#f&Y3gh=--r`j4>TFCM0q-i{Cjpif=%vJFb}@kA_njlRsjE6gRa>ZP!#(jLF-_@8 z^#R2QWw@ZqMc^L*h`>@MHWf~|@ip*X2fUSl_g48_ANVgyJZBO6#Q!SMQe@L0H~OxDLHQy*!a?03sONx6^!5qtE1Y4w!0=t04?MsD&lB+91>A0d zMQgl`1$?93Nm%WDuaXY}Zq9bxd`2Bw9aYupBscd_-?;H5xY9xWPEaF-<~*OkKa_ai z=f(%V$^n0K5Wu}uew+_HSBa~+vY?)tsl*#3(q(gktJP(YwMzWcXs`7qEAg_=$V4T) zfDykTr4G*x!n5pT05;2Fq|gDJBY+zKa4prfN3}FxI2Q*veTU&2U}@Z;sxn(R?*&@C z`!rv2fQsG^Miv}-Lzj} zenD{FRT}$I?7pDLEq5;6T6EWFgw)<(jE9?lBjxaq%n7M#n8?Alh2?*$FcH{%4wsa} z{BUy<_6hBSiHn5c7GZE9Z`Iz94BhzFM0mOA#jUg48vKg`gGl{w^Swz#gM{dWB%*Nh z=>a$1$4Dm&i}_Wl69V~u;btAH>#jtv&I^HBEBaPZ#+fJR2U6oec_?v6JCKS{bFD0N!y`|Gy{K80y@>muaZ(-PjO`BU(t+i+@-kMJP z>*^&ocYM0syIU!{|HQSEp2@gIty(yv=Y(~IcRenc4!rIZ9_y$yS+*RBN}~%qex^d9 zh z+`Iz8B*X6DU>qFsDD!O81-isIk*FlmK}dpI>aC@QH6Y$+Z}sHRSHsPJm3ZTO9u040 zLvj3*c-ZCw_&0{;YgLS`>3H66^C^Z!)io}t7jE7~e=uoW!SY0URAJS#hmrX$F6hNA zM_fE4=*D%N&=Yx0jDGv4!9*N2(iNDt(%2_D^Sp;K*nX$h4}Gp^7h9ug?=U3$l}UCS zF$&%){6F6snoKor-77`CPND>&$Q47VFdQy$x%dVYbKPuLN{P=>x_{PZfYB2L$dwtn zVcsaMeNKi&e;tX?WGa997~Wco&YU9C`hgo6+Y59P10BI?e^lS-wU^JscKE#?#4{a}if7^- z0F%=Y?+RML_;}OH!@$M6m&V>y2R;?+-u{^S@1TN?g{z?CueXO4y$kCN2ThHJYgXu= zr(vKK*IDCLku+9r@Glq44QX1@M?XzKOpT=CfR8 z?L4$D*ED>bKfEnkMWHqg!!&)=xab}45_%DQ{$%0<@&56C5`UnhCC3N-qK+R|!?gQ= zFE=QUQ2Gj&mP0d$bXINp+qC{TGbbg-fiO)t&Tdvnb%q{P&^TUS+HM^4?b7_lX!N=7 zqtC6MLul*sb2dvHh_rmV-H+^fAI&FPHTrB~ueAJAlKG!gY3>v4FG{|NW0;}RNCy4_ z&cfNBaG0Do?>$0TiI*BNpZznw-OYAWtg4ct&GbSqh3AAo^y-rXm%rPmvAzFMC1GL zwWNaR(De;f-U9Qw8jpql|EvbcKJ-z4469yygtfJ3?_z4S7B3y9iUr>1D7qYn>71cR z^G@IwNri5nLHXIsB+axPod|`h~OZE+^ zAB|l_vK7icYO?-*Bk^-Uo;|AS9VYh#;YM!ej-j6Rj~45L5aA1k^bkL%_l@Kgki76l z6>%40NR!ki9=hct{eUYFc5u zycGh>v424~5yY@YqMMECTPSv3vo0LwgS^D(8gAj%{2frcEh0BB{KAK+s zH0Wi$*6+U!I98m+_tC{;`j%b`H~%1xU&d!dAT6JniiOsG81&wMj-vMtR)brM8q{sA z#Xa^Hg#vGHYbEbF%@at$Z=klwLucc5Oes47v zY*Vx68uvrcT4`9zwQPnU;OVdvsL&cwZ!JD+sAJ+9qFeo^S)1t%Wrl_de1FIDVh29X z2d@#hzAl3@CE+(oL%+bmM|}9C3NVz8Qe*!$3HA4ocS-=twkim@YH&5y{Ebhbg6 zRP#-i9f^Uqsng{1cLntW{vxi{9e%B+anvN3BUq5A_O+`0g*I4{{Ki&1l-GkU+Z9mV z8@YyX<}_UKEAU>v@J(QYdd-#fa!P>xhWpr z?hU8P#udbtW-kT^jL2*Ho;v57GLB{hKI%rG7rrnK#q1Hdo{>NRXy3vT-GymcuWAHX z7c#`!w~*KxbhU>JZ>pRI6m;G?{EA(A=H+P&Y|gJ4o<}sIq;YQC9yQB=wfo-kEI1iB zh4WVBGXN*>EnO;=Fb#xT^7*T5D9;*)n>BjMpjK!IWH{uGAI2~$nfFmXlV7+cx~1wp zO1;7SRmLai3Po~I;$Yju!s4(p3eOKEJsPg~twV!_XwEdG+-?qyGZZ7}`NZ?Kv$K}h zY@^;0KyVc~wD_xP)H~;Wwtx_j}n!PUyN-P%d?pcXO2Q+1F8iaf+jSY?AWi zB;`p-%EQwsm-v*2@+(RwiPAD{@5DnzqEzN6J*dXD7MJ;yPJ~ioq&D2*p)CbA+=2bY zf%WsjM*0jrflDOpTMPSChy9gzQtde2Rr_oo*N)BoYL`;YN$^U^)Filozl3UKC8%~V zRE$AhSUj|4>%*m)I*VN^-cjtb(`76VU<8Nuj$xRkIzUWL6-g8XFQkiqeOMQMYzmbP0 zLLa^z%!u#P&^AWBcJU`mR;|Tf?(NzhVO2)^`gxPh)0;v(Ke}`tixww|1(J*C6jfzqHU> zN}d$`pXB&_9|YfW#ptPyaXd1ik7W5@H{jctA0bzNsK)y-cX*4@2QaYiz_@tlRG1f& zJa^TS!9`TCMEJ+fp@f^zCrub=c(o~ny;nk-iebbA5PNN^E^ArMB-z+kZHqVGtcq? zN@!8(o2fp1Rt@0&`$4W9XPyAA{toPSfcZ~-IiO)a&`|<9+~|kiLUd*Eo9{rX%oAEo zL%<_b^F##BgC*msvf4}z)01BwS)oaCx;G3L!|qsTciC*S=%K3&8IK9DG3tzbXu7gu z&p>do)Z%{l3COfEq*F^9oPkHlkl?>&wAk__o6Hjcl+IfZ=wVhjw5bu)m6~|dN;Qbt zD&k#gY`Qs5Q9m^E-Pir8Vg!)S`jCa*Z>9U%QC#K?gfmrVPdS@xg^1zIFaBTKD%-gT+2!wUdueFB2MYrxAXuo#@LF+IrU z(bpvQwPo?9RW!uiG`Svaw3{Y+UxWK%+U)S6t#|j;;M5L68-`c^HL?4_tuhqk?|m1L z4i9MV+r+Q;M>;|B!0I;7Fjn*|hFJ^~!Wi;8w`QW{W_Q3FR$t4zQb}2U!%NCysXK2S zE2ht6^tiY3s(wt-NNq{8q}c}^pHjI=hA3D~qelv!mdc$CUYgap@5cjBI`1byceJ{p zzZwyEX^YTIUIvLT^wj@nnbNs84X(zmOldZs-hG`BWsC7IEy#)Ou0d`fWLv}-HLY)s zG8CZ!P{ToErc>W|o8k`mJ)+K72nXt!&*{GGPT{`O-}~MHfOnj_dnH}sS6ga`_u{c8OzZk93@}aN)5y?5FzgIYXMzfVES>iw z51SxQ2G@qX{yQtWV)-h5v1Xr3EZxyoEh(gHdh|9!_Il&n_OX((zuPpTQ<%?Z z)U+_4YYj!{wwG0Lbs+l-uu5sNUyMj4`*kM!Wf=p4(eSUn&jKLX3(y;E&Zm?87S^?y zvcC^$P8bw+VB$;r5S&ShGF16EVEq!#p`;D zQ3g3g@4KP%?n|2c^l@07&bR3W9DJbTf3Kh7&jvt;`3pJ)-gY*w*LWAQqLSBkF2BrM zp=XZ5@%tUILgo*-)!S8=LHZ?epv3_^;|)8S*{B~U>*1Ck`PXK?0`D&j1)KSFRDstY zf~bA@XYB4U`U-V|#lm?iN}ko6PKtW{CPEohxMWkqh0AEPkN2sg0=$WPj9SkHvXXxwSr+GuQ8*ZKC$>WSwII5FlJU-xEF9lYitm=5r<>+)aT=v=Pn{dY zd=85DwJ4y?Gy9I9Hq8jfd!jiey%Am+DuN-#4O{MAMH9@*Wjb%W z1cU>JZX+xflaURE8e4OQCcOxA_MOMC$>^+Z{DwW?tb z$=3V@pL0Qr&4A828K!@lC*y|wWrCnt%i%XiCpH5r)J|v;B+&-&H2tY z$5&BD>U8iCh(CTJbF=qH)DCiTZ6+8+BDS-uonbU_))WJ6uWXgE_Z9ohZnrQ=N&j;? z9ZkSzF9GI~XH(Z1hAdR`oJ5iCR`m7`#vl-_i>!jYvubDvy4)vB|Vh9&gyxUoklngxW1}zgslFhShG{H{T<@X! zNeg)iDHto-2gWdpY^o&Qa_#)$8QOV_Yv-JP*3JUIox6ck?Yy0>HyQYU*za2Jc34s? zKN?RfhdRuCULyhKW5GNH+pk6(A)fxhOx<>*!{6KCzj;^0@z{8W{4kI@As*?Yy-;Z1 zTWzC#ytwmgzb>{~i%+DsdSN~Y+W*T)8z>k%rf4m?$H5%v!%Xpse8NVNTJVAWuJ%5G zGqs?vNSy*H$@M0H6Ct$vP8yqn%}u7Q#eeZpE;`&vWth+KKK8rT8wSI&Kf98q z$ukdkF2~|T+ec!a_n)blP>`OQ`IZu=I*MDRQM??n1Qd7mDVF#YAM@~66T3qepKNtK+xVRhy2>o<4ug)}YjrS%+iBoK&@MAj0I{@2G zH#F`9JaZ+`%$td4C{oAYF6iyu=G}WwLeJkisdn_fi@5e|C$OGIL0=<$ifnHrtai3B zO$=#TcA0Sby!UaqZu4xfy`=4`)c(`y(^V_e6(|#Yv zxeiCD92|+eKA<)ay}d_f;&y8o?{zCtFZbBIsO_leT|_Hd{0i|tLi}eCs}1*1DY3i5{qf`A_RZi)4spKE?9M*!n+#Wncb)xWFJMh* zF7$D~G8Wvs`?!x5?i#!wBzr*`?rk0J8+US&ePpcT`w$=ZNFVnhKJI-;ODPJx0X~(J zL}l4~uD8FYdSVw*q3c&Gu_p=dE&X+iBfgc0AEjQ17bKQrjK%VU0=U)zeEwJ<)z+d@ z)a2IUjeYL=2@K0aoweS4B~CQYR&(0peGvO7TItVesel0~(^Y9mf9H_iMFlC-vtz)s z45^p=H$Tr!eR~S^LfBE4MU?36c$*+JCpZ;)Lrk?6&+yU2gysy;s6C%3@g<%gUnxN+ zy)u|Kvpdfy=!JyMsP0_~Znw}r+V`d#hr?~3F`&k;VkZ~>TaCR+2(JMZN>jAHEIDbO zXByw(ou=~VUHP7GyK=21E@p3=D#cH@EZL;9$nu@} z><>dvZEY={v!j#TWo1rTc4Eb*QPazQ*LYjn?`m%&ex>AN!I-$7WwFHh9F-DF%&!iG zgxfbJ=R4dx`ndNO*!`GzSa^Fy3arY3eY1mOVQavI^(udp|NTQCwV#oaP5cjF-aus2 z$-;bUvbR53~zRYN~>O~dn7%R1r=mBzU9@;V8L?_Sk?%IqfR+a%g~urT!Q@)VQP z5l+D5SHE=<*ve<}3LJW2xyXK3dolZ6>s^F|)CrFr46{4Jtl2k_DuhjB=lcgk$pQ}l zAW`NDyxjzKGKmGee$IyZ%e?x|lkf8X3Gf+`3@^~z(1Vm3gm&kR;|f0^l7s9OH}7|N z_(vZlk0U`@lyg`D7J`Kg`%izfTxJ5z*~V0vlePK z-*}vNFM2^>&!FQJUkH9l=?1D0lf<*mm)S-^`@jA8Hfhu8+oMhI9!#xx=wNtj+s9dg z=hPLg#T69Gpqy3e@D5(A=(r|$WZ_xFtmpIb$0Q%FZ4%B76pM)nc)k#sQz6s-*W~#- zTOGa0oub^cdC!W6tbXDlt7z;SdV+n_vkJaF_f`lMG?FM9^N1w0Hr&!o)(AUKzKFjF zNeZ{j=MM`@`iU{Ya{NVJNLE(*-rW9Ns=rA1`0AE=)|IURo@bi)Ra!(xDc=HPYg@iWR>##E;)XITgR9`Psz-MTy@^ z+(a^n_v?O&;zZ}Z+5VyNpSYE#rqMuQu2}Mm_%CBNNW*_F$*%Apl8JvJd-8mrAZ?I7 z{-!$Qlb+t$tOf}A8v_fwEh8^}2AgGrbXa$=H_^%(OWdZ`ANNDUx*;k+XV9N*L)Evf zMLVH+sO34mRJ*`ic%Z2_Z(&NkrD5bV>IxZ78g(Zem@(=OBRe(f2(DPx^SHzT=y95O z7IfzSJdQDp|0O6A{GSO^mn{|tV~G1IXe<`VZE?>;^3%~7B;R%>kF~r8`Y1>8F-B!t zJd4KjnH(Z}TODK#K9%lit5Q>1i}u`3KgAbqD{=+izelGxxCxlN&io$zD!`KWRw;gW z(x6D^_dnLbdxeTK`Q0lQzuR}_cO&szA@RpUk1vK_c@yw^hI*#8_}y(puE6UUwE_I@ z{xZPgw*ndZ@*OS}P3QMRCIHE|byS9Y&kUxDboo}JI9c-j^S@k^q^HcmjjSMp7TjKcLGn3z)a`C%KXMX=I zeh-uM`2H`lX#33ZJ4=G)`@g?&{I2=a2Jm|&n-<3JVOTX^zP+;LJDRpgzGwU?L%ubr zYA5*~g`Q^1cW?N;Ueb$)HWk0e|@q0aE%IEjm|B{!k zzuWry`&3B=zYn3Ro%p?le$V3fO!51LxQU0326x+Oj^8aDzb9=aas}Rn^rCD`+I-*H zKJ5R5&+ix5L!aLx9?atRFC(0M`(*OFWiEcdqu;amT|XFpOB}!d1b5qV$M10xY-{n7 zo{rylpz@3SZpuo>pKuX;D19X;{<&cm2lA-dUeM4 zCl#?Cw~pbxQ6XU&CZ4lm5&Uq$>+e(1&q6*ewTXxRt)~4v@dU*a-%CX&f z7Ni%D@CFoXCCgv(kG&m8@u951-}5$8X_Iu<{9W&d14!!`X+Pbrbk9`!4W(aZ=f*F8 zLg}kh=?9daoJ!xSbYUuemC~QVjjJ!`Z@#kbGzQskQ^F6i##vGMbY-~*jropOS-fBQ zdK|a$8eF}*7+h{ZVS1ii%HX+4HY64*q#Ax?!>g?fz z%&Kars*BX{o97BMGb0sKRo*wRynNQ&*>fw)D;gT=>dVXX_J}B}c1q*SDpKX;CpA{g z6c!Sb8>?qFRM*t!^_#d?zlnJbjk9M~9dkgxDUs@is#*2JkMnaV=Kt#R0&emO2jo>W zL}u02H{?~#siGY^biS398gbW;NC~L?%~7>Kp2+Yo^ub zRo66BO@rSl)hAci0~x73xvFmJ%-U1(W>qvyk4&kZRZ(3Nsj921t#dhb6*beU{0!ir z$G^2{2qw>soLW^^o98G*s%xfH&56`DHbiQtMyzt)%xZYZkw3e3c4TT@?W{6sM~ldIU6SyeNQ#_b)cnlrnq zvY~2<6L2mBgkcJ zZB3Q_&a0eWQCDBpP+n78H>+Z1H8L7FYsy};=b{SLHPsEMLBrhH^hw?X`x#T!P?2{~ zRZUf0b*24XKCZ5|p|-MirllNgdDWbTsv7lMeO|@n%Dj?4jdZZ(wRP3g$|qOUS4s8C z%j;*>Ht4VV#@SVMc?UGsR7{>(6=|rY-|J`3te87I?*ONo!}IE@rXk$Ax&9x3PlIdd zRh3VtarJqsQqfR3y}Yuba(Y#sDM4Oi4NM$kfA4`D8;*mhuiXf_wvKw%%Fa?KXH-nd zA)UQuP4S0N-ju4!+9_32%Im96YOJc^8#c2l=2XvWoK@a1y{@W$dhN_9fJ|AiyP=Z7EubNpsts2QtP(@!ci0T*# zl{0JW>BFj;DS4(@G)3bwudp6sGKudHoE*GlRTX?5kq z*>r4K?I~4t0h-B;Q}fE}8!IajNA<~7<&AJLKfbthL$DVH@3YSNgh>S;Bw21=i^>iQ%v21=bgwK@fOic~NU6$eii*>ajb z6}|O;%PWupjdG~RH`dRtuB@(YtUp{zk>`Xk8*A90G2sg$O>XJ3qOYoJQuOjB)+8$i zt!qqW`4lJA){d#DnOkC9G^)1)SjU)U1r47qi%kxrDafjyJ8N?7%phfbmZWODAQ^h? z)Vbw8BrHm3d1L7LQOs7A4Yf(FaJHttadIVyoNbs@S6hyJ>Z;9F_!FYv=MiZdHr_Yp zg{MdAv6$6UtE;9&8cwOMtQzq1@O_zU)NPT|eZVg8_WhN3NBnB|Q>q)LYZjVaS5;Xx z1v?u#JyKCKCDPY1HbzVa6RS;7zDOd4{iY0vG)%9kNy@^PKwZ6+IRP*)R7EQ4rZvu@ zUXnRLtY&V+%wJ5dV#P^$|Ni~z`}=Z|*HAsVv7su`KYN(=*A&*ji*esS(#V86wYmm- zrvK9MxMAU{=Ng*nb<^u*shmtjfFxrq{cQcLp_7eZ6h2RNC4<8a6E{NA5jrtvv?q%% znE{8^A93St;2c^vE;XjQ#LMunszWyzoe>)vRrQg|iW=uYOlK0t&yj0VSvzZX^-N#5 z@Ra4{1x|APzYe7k=2fx1vy*zeRSk!hIe8o&Ru>ebXn zX4lqN%PdsPOzK&EC;XrSbq>&M8cF=Ks+k^8!8+#F>N;BQ>*}7e{z*!a{{1HQR~K|$ zFKCT{Mhf8pR{YkWhr!T5)gwtH*5U{rqg;hZp@%wOzv1ny@Be>oC*!=Uc24|1wG;itovV$^M9}8gRo2$v$tyEbz2Cla zOSAm^Iu;HrMrtK~bJ$H}KZ|Fdy@jW1I)nGiDyOgOadu~li!_EBhvbc$i#b+bc8zXi z1kF6Ps=Psr1+Jehi6V@a{gbY@CMOW#CE*(GfpQHQ#L5TfNET2YSm6M)yB>c`3S>gU z(~!-LR789}-2ArT@RR2@R5AMU+**d26bHsEe~z_^!1DS#oyR^+wsnKQIH`!ts+etF zzd_~YjT|?(e572P(OPn0f@WfDBAUEd%(!LOE&@%r&pF&eX9v6TF@M3XX8BXU3RgN` zUEm?Rv%i|nQaYYAXRMPGTh3HhF*9KCmr-vh-VMj-IxZb=R=dlwua#A97O$_G{p&Di z;O*>UJ7l?h^elm<g3HyBBl-Z_6F!@YK>e#yDW#?#q{|3Bf$lKTeZP!Fcd2g{IJ zXPEoH;i%H_WG-|z3`ctX)FNra>Snj23wdPcD_x*O6{5ogtQ=!I<8jU*Knh zT)=dEX?7teI~#&99bZoVIxX=s2UdFhPD?-6Z9j`4y?&?VpsU~2`Z0r%bUZoRu|Zfe z$HC9x*-+m)ov-wTY(~>I6j|0d?X*_@KOn^~?zEGqWufhOGV@{!SpTx>mxqk&t$i>} zz^uP=@87_Ko8i-2o^yuwmltftPN|xyg@?x9ufyA^hjQZd@dBJ{-p#>o=WU?=!D1+r zTjO`b@!EndwcnHrY1ix8TzqD3{QSShmu679bTqn<@UP?@$2ws4QMqdCw9h(FYjN6|Nn3K)TbSBV$Tkkh!(mfY<~ z)pLiWUBl%#;57;5#+%EDa{|o`-^C$Umwb1%D9g*kTS(0=GdU_v9gN$ChT|e*{hQpe z<+LsMJM(ajN}T_sAD_DT8jg_~>uT6twulo$ZLvV5C(s+!uyY11PvCP7>5Slx=s8Ii&utVR3ed$_=qQ~jfu2F?g(aT@&#wUXyH z{&1>ufO_+F8T^#mZXBTm@T2_urF^|i!O znH&e4puii#T8IZq0gy?T=>L(OPT`Z$QG2D)_e(ivb8JJ7b|!c04Zq;~SJcm~sT53q zHU{kI%nqk~<8K@G<>eLs4|{I|9@SN@4R4Y_(}t!~N?TOaX|0r6iUR~lEwvN!LqY>g zA*Hm^&V*z_(&lHH9~x?_W1$o)ZKG1eT6H`kqV{N1L{#jVV|fu3ZPd!CzST1-BBxSM zRK%Y1*35T5Yu#(l%$~hTXyshr`+dyS^qzgMXFY4JXFcnG?Ex1>y2D|q;?^!x70Ljr z67%#lMR5e!EV-l}b>^7SgTv%r+{udaW>W|5iK$ZuNOa;VP&f<&Y4u+DlMFTDK7c+_ zu;Y2=5EA#G6ydNsL=m@^{NXUC8;9vQWj5t-mFw*4yv9xtht}c{wg>2#ET_)3Y%-u- zV2`1%2g#uNu2iXCDQ7)6!jX$kOfa{68M~RoL5KYu*74}ic$hoW+*m?duKkjcJLQcg zol)FJ8dKL(c+t|X-a1pE(Pnl0Q-YgT=3>g!%4JKIEL$30QBhMJu2@l7R~N3Vtyo@B z*-*WFg=I}BMKW2#-8pSN&A7|dd#x&T;P|2p zE0!**4&PXP>n+QcR~6T?0Qh-=;u~=j@GcaluyXN@6KZjHsIR?bVPj8QlV7D!l6A{q zd<}LDdrHw|^PY{|tQmKnwC~4;k>iEccz@6M!P$3qouKXeYhjq*ops{`)@E{d(-uz&MLYPO*|*? z`in3SIIhuMU)bKY_JS3nS#~_77kh_a#VMbn(cHOV-PMM}1@G{WM_{M+RS2=er2IMEr0j;H?^&I1?oz4sl`nJUi`THMg2~Q{W0H+a zJZ@rHR)K%Cx#6VjmS~bexxMCwlfqfeRLftOKQAn}Fng+_N^`N!xntc+0~NeEGxu|y zGhUuGkIGh^bu1*Rit_9uy9^g(l>lN!CTc3)Ee{%idCK;bgZfg6HsRAOh7@!JIQpm2lx?w+)#K!_M8s$>FB_eN1R5oa{E&Et2%!?DQtb z{;W#B;EmbF&D)KB%PB+kp|~!GPuF&4*Zm^fa+zD6mwHaLQI9!&s&=#~UK8ze(51+w zjq@^{kje(Gmger&JIg#aud=L+1G##qHCijvxjFlPV*$L>Y@LI@*W>RE_?wEqH{$P2 z_`|P_S$_P9jGTF0jz8yT0*G<=t0c|`iadTw#ae{FLi~-#Upf9};14gzTP66LhCjJz z^%nf$M<1+n@rNI)u357om6NIKP^m7;pFnEtMi#!8z*l(;HgU=kN{B z{B`>3$G-D3BUkyvN9FUq8^*n%@Va&w^C@IF^7p@|H{<)z1taOeWtO$sH!z)SECp8_MmgFyeKBWVjinGga_2F8KYfhk}F=$kTu8%ENH zFmU+@eqIqg(7Fia1Wp0^--7Z3W58Nq5*U$i zU@tHQ+zcEBJ_)q0KzV>Z;C`SV_&hKGJPr&3rLly7lYtT7bYKj)0GI@>7XGax={PV2 zd>%M(d!^Z^59$Uo4UHqq3=$HoZQxv^|_<@(CbW}Huq+bCBfs@f`#eg$_gTN}_ z!19swDna~6)J9+gKRG48j28z!1xx^wz#-sszz}}C>jZERI2j$_Ft7|buyQ2b4h-Bf zlHLIfu0no+3E;4V-#U_>iq3KvxB%$K&qIfRL0~&D0^AHt0(Sw2f%|~*cfoEz-)fWt zH~^fC4mWr^`~{c<)&m3hP5owI2-pww;b)q+0~5gA@{Au$KLnJ2_aFrv0!pVn44e!M zH9{XS39JVO*1*2NIB+v?2$&GQ3HbuXfX@jJJSKcI@&^n7C;Jf&oBEz8mEOCV_{5 zp>Eh480dljqQ6Q2Bf#Olk+l56a$+6)S^6(v4CucHvv?H~>5ZwBCpQb2{W7KskT|z;<8)7zYjmw*##W@Kc~4m;@$)6S2?c-v~Palfc!$ z;RlfqU}_Wez76Rf z*I*}L61X22+XFuV`oE5T5_7R6FbIt8MLB`~Z$KUx2kr)@fJ4B6Z=&A;2EPTnUW@dB z4ZwkYs7GM%+h||H1BZlv8s!lFUq;gM4@3?F>w$?RtCop&zb^s0mCkOHTJnR6B1KWZApQB!ZN#GDL@eBB21=4!~`2zZX ziFyPM0-pr>{vCROA>c9KFtB(b@|%KQVEi{IH!$*BvSz8dM^AJgsy4xX1z zCxF3{bUF!4OiZVb15?0>HHeQNjF|!Sm!{J(pmhP{1usmeWpR=O&H#oc;pb$5iHp+d zeqai?9T=aSPVWT5Rk0s8RoanGoQ9Izgkx)kz2{}jjrlfb>e$m<{v90pFULpXjT zH3qb%B7NY{8`EjuV%XGT3%>donNE70#xr#Ay5z$7q$f0lRpjnD&Z0Qv*z^gdt; zcue?m#H)uLu1%-60{vC#^yDQ72L^%GE$Q?Yc?J#wL#xv1VPG6sv=s4xQ-R6b(&=`f z)dc;(L~}ZQ#WI8g%YiBU;%N+MwIF}M2yh25co*~mlfXa-`a6&hV5}>hP5}qypS8OQ z@(-ijz~CcDZ#l{j3<7-v$QLjO90CpiUjZh7z7uc$>zX8vC(&<&e)YlOX4DLlZFadlH82JY3{buOHzhXB7m;|l@#=ezKZv^`B!)AlP zA>a$Z__x#P;+3d}r_<>&UE`>bwj={656PG(&wv*Ae_}2X~7w4qg4Ws_K%;j4Dgw z$-j}Cd=>E;5bqe`^|_>1u-r~CC-0Kp7Q_pTKmB<75w9Qde(#pv_wDp5vkNG7^opc6 zA!94yd;ApbV^lyh?PwF_KX7AN`I z2QCEebn+$oPas}D;weAGvv9?5-mTzD@m)T`O$9gL-~!;bfSaJCv|JUq&EPK2;^be` z+2P>Y!6m^}X353Dy#g*f-L2qW2A7>b`A1GC7w5|D1Lp(xM(XneZIKi zgw881UQ}`${$EpKiOdPeY=+Fe8JP+dnk6%(2<>JRnFWvuo_lIN5y(6_ip)mHygZ7` zF32>Tms744$a7V8xeh@l2^p_)VTiMaAv3jPBz-l|T3+gVtYBg3lt&8}miiwlT39-L z%lL}Yz@`aRrR5vWsVNN=w47I34yK}XIwT;8-UGc(b%}-PlC@ww{&&Gh`hI}!SI`-4 zDqK|RzZ1@_d!@RP4tz&vr=n##tI3EW|9Dvt@nxvBnoIr7=nsY83clZke+vAd3%?)y zF&F*?@P1#ee&zq*SAmBcsE_i0ICO)9n+h)E-~!<49b6T-S_iiZT$O`s2N!g3ac~P9 z+*WYq-~e|1cHyDS!R-SV$l}y^1#Sj7nNG+U)2f_gH7pBT;BOe=s}cSLzO#KaL!{F9 zQ3L47=UCSBka@4jpvE5+A9+N4WJ?h|Vbl1k(!hoZi{Ks&=PBQ)$nuSaB?zr7ou17> zjrd+W^ja5=q(6^-SM)wsP$#}uo$GrQ;(Jx4!NNC;gY!X|!})4UrXc!W=xUxclJ3BF z3$C`IKpJng3VRM=dp*L25jOE6_jnUwq=-wH*mXL>b|dVgc6#qtmMvISS}ftU2rrxL z9_~kYtHek6ukH8+OQ2w3Nx^`s8);8lAQQhBYb=pbqO&;L}a77x9XxoL)RX%JdZCB@yo` z@gG&^1@F?8aL~5l5M&O$?$z7ScOKf$>qpY>ppR}TFm+I{$+qF*d>hsxUfCN?FP`{K z9Pt)R9Z7#bQ>J@RrrHvOiBBXDe*BHEt~_zXPa%H&o3K8_m~Sof>hD#XlLq~aYm-}8 zQdlI7aq%-~jR!Cm972QtAx48ApYxj#v6XOb>D{{?6MM*(@>8^2ArGw*^11lg}ki?gz zAl?OBC~?0vj*N&1gCwPYKZZP9an(rrB7B!m9Dni;xCX#g!$vw^)pmbWEn^`%pG^~J zn}LGD!U?YVsw^qEuXKCC($Yl1ZNP=45ZyTr-);mG0#<-2xPv0MkU)~<_=`_OK4y=k zzmD&cher#LhexDO+)`8}eeL4XctOGAuKnpg#Es7xN&ozmapULZMqX6XmP@FN_B`yijp+@V+G6~_rljDX0Tt5j zB>ogkNQ=rx($C_%e1w|;E(z{+iqTvU+#zsp%HkTpJrC|Ga?;LQ!JPotE1c@P-mB8S z3+0n=Ige|&7W-y)IOa_l9-0`w3*lQ4F8#cYue-h#2p8@k!gnKFjqA|AN&2k~G8a=T zu9{L`g%lEF&J_KykPeLike%zgl$RGX;M~z#Rl9-?jc_u$m5& ziams|*V|z?sW7RNsR$cF7`8YtX)5(0ehH5NZss zD)ooYEA>^Y<%i0ToQ-aW%)=ssIaOe_qXuQYjQ{Nie~Iw;NO>n- zi1LElEkv}`FCJP|QeRrUy3{Xun1S$E5N8V#?#Op7!j2%UNx}*$OMPLTj-1ynsK`yH z7hEkkHJ3sCDFqpd? zVKRV9ycELPUBaZiuOKXmup1c?mlp-EKb!wxEWO(r(olyh%daHTbDU_ z@w+7W1>ogZ|;D3>+!q7pIMq7thf@#+z8pl&4n zND&^?{N8PC$?+6p_50i>_^J;!Z7O$P4&!GSUy`-t zsV`|RonDzmAg;?a_3%^AoE#-a&{0d78RlXhIi^0qENj_5M zz2J(#VJWLVLHz#^s#!2Y``8!d|bhQV1bJ)WG`lGOA7v+&sLP&tV!e% zxz~AwC;O3vd>nopAGcw`rtw>f9w~gZK-K4T$ZR?O_w-FlT8|}9qH|8&g!Qs;s?9Dc zjTE3)_Ms@)gOR>SJ`UZH4JeoRh#!CNhtA7@@)2$rIu|VGc!y`HyP```f8dtmyLES| z?{*kU_^IIKZbpspZKXchMUZ~84E#ax?-m|)+6nX4l&n$zm+%IJPhVm8$G!+cs!AI1 z|3zw!*NgCegfEl$otgBufFA^3DSV4gFNm)@z#jvz+IMDtAT=9=N9y@ZWeG;vDHwRr zpH<6l2EQ*ZQFFgz(9zt0^FPsz+R5He?}aeb!i9AHCd04?AzLA`%{m{_zs(SX-#n6@ zJq`#RkI23V{S(r9*$1lrK((uy(!kwNR+H7NYSB!lWA$OTvkF<(X+N2P ziSGdPl|i?RZPI?lr>em31#kMIT5zkt?FP4BWRWZOqiPQcDQuE`#tjn+u$dvr*P70x zuH+U)*iA_6v;(@zSB<0(oLbj<=*n)W3rjFb5bd_IYV>wF1l9x4S%k^oF6ghK{w)QI zc-DfRo(CW;pK?&%LGASk=C7OAoRIm9i#Z6uAOG@i(LIjEIeo6oKvB}CkxF^RTyBd0@N~PX0l0FI0^_c1J7NK026lVGywXZ0q(_K)V z_;e-|mdkQes1yD7L4V>5>VEpvOJ4y?jPQ~~BY@>EeG@_QkF zVvOY;M80olV9v-V4lTxUyZdXzp8o3A;bwH&btvG_2Ih< z)ls45B}>)3<2b?-2)|asv7VFp%mREZ@?*RQe~<8)_A7fQSmUtWE-aDRukJjt|7*TV ze_4h2#nF-UEQyb5YiB*L1|I+~eWHA%Uyu1Q2L;#2{wI6xsm8^s(pbT_bysMQTNo6? zPER3jq6Ocbl#&L}$OJ}_ zk^9rDN0BMQK(u)jndy+(J&H^{WKyHZ#2_=V^VH?q3YqdzWcEU)c@&u!ATuzEjJ(*i zZxop;AaiUK8M$vhxy!p;()YJRM()}_ByDhwy%sOpsDH@3^EZ zNAB#?7MDn0jZ9z@abZcF&8zvW%vV~Wr|9mH^hZPw?wxQQgtFs48<#@ZB3El;$@6x| z_d;Inkwb5eJSHpB^+CQ`wq5M+h$mz1bBKEoai5=n2gH3$_Wr!?8N>=B1vu8rzvQyG zM8;e{CfKX{bMH2lf$Mj0wcxg9ad@;=NcRePX z`B~N+WKjv0BeJi7(d)*{97NJOi2pSp{!yu-+kpFmfr5qFLYO+DRz>y%{`dSC zWT!yZk3+20_u6~iKDdb5X!9d%0m9_niv+&wF-0c9*j$upDr#QRia=)SyT_KVEuwFX zvU?$W#eHMbdjzt(#vm)@^}P-Aocr_3D`lC1uo%L|V&heiJuybvjgaks&**yn$ipCH zUxDm)e9zb%lM%5wc0eVc&xyYGj;>E+t*fDL46|__{VrjW zMl-^S-#51W3_y0v7-jcC*7v~Zdi}`5G01L(Yy#gicFXnEiRh?&8%EbBWh#g4)-lNX zA=?buDH~6nw!E*i6*5mjezf+xTl76RHrW(ppB$s?#B0#rH;qlNyg#&KjIzy;o&M11 zdc}_hAo~<#BVvavAM@k!DTECpEP?M{bvOi>_RXWGC3X0U=o_Q#bS!Fm-#@zE2Iy^o z?8}h7cpM%u{^ad_qF3H9L9SOmi8BN2=4J0%R+nH%c9M%rWc~FN^d=wX*>J6_^$M_D z!$^QIDbFE<`#+GmW45W_R`kbm_*^Ob66;JSA-Z0M>=DS`i|;r$%+odH?J)lq?zyV* zM07Q36;&m;kR}~YwaQl&WRF4CO_!wAjPTk=M$(T;T1r;|20$#$anK;)8xg)2;aTzJ z$Uw~_1a(C8BYcO1t9|gy zK9*Y3p^h-3R?AL3CsNqWGE*D9KARrEc=H(7sW{%+f-`QlW)8?9EB6H!>8Tr6m+Ht( zZx~doJ)3su7=n(&k`LRa7}B*V3##!AHD#Au-hGP?@GgP28y3N+Nt8?0@%s=yjPP>t zGqq==#(deD!#<_Vicm#rgHdK__>S>k>~#Y1UjCrBJtt!$W6FoT?OBHK?FiorU3vDD z$*ZNk@VA2M!UY@F1o&P_Mxj=>SQxytG0R9^)7_( zM!4EHQo2lC%al-8HIC-xWLH1nevjx)A>Q$ic-OVO*En&zcU}7tz6Ig0wyrV!Sk2IJ z3_8Z*_w|t93i<6H#k-rVr|dl;b$%dKvN zlaPH7`CwmSw>hcP0Kz9eIg-9Pzs-r~YujTUCbnM<+2F^$ZGRuaBMA5Ex1L0J3gKHN zFV22z4DBp}XesDe@CoeUN`BGK9+UTo^6vZdPDVrqi*mQ6P{H32fa5|8R@pBCELQzm z)m*GUJ~_7f6}$98zCYn@PH!8^yTi2z z_p)IX!Ve;RACk)RQ(Q*lc;Gp{N*}QqI;uW9w(?6Ku@~|uApb)#hNoYv_gEH}CdU=t zI?lth5nbAKaXIX{e{6k({7y~r|MIqd1H$_ezC6$Naz#OR5wgJ|S&u{ZsRQ1&Paymd z!o6&tM0ovoU%mf|?TfIXzY99X;(MzhUk3SA2k}m}ln-OQYyXTrARg!H*#K^D?{oCe zbuuN*>9O_s^;YPA`FmrlizH;XeBZk+QV4$q;dOa+kv(qex|sM5%%2Z=*ToEk2NCX7 z7xE6fyesZH&&+JJE%cffNnH#;$BZA2tuDlWl8}D^@?PUr3gPuX!r7FRKWC1JizW0$ zSwM)ciPvE~diE6MM|d3Jp5;flHT3FzQSvYV9jl?ktvn%w4+JJc55$}+_|BCfi-khUO-t$_7(@t~?E_05GlES~q#;n_<18GQE_aPnYh0*OI zc{&E!t&qK}7!T-?9+SIUUU`a-D;#tmFRDulf9swr?yZJktkp+G&(nR##(j_-hOE4I z=9(v5(Y4<{L7qPEo+rG2@-bIK;m{N}%iS#~_Im~C$B&OKuk!m9lV8F;rt=WdZM;R} zv-3JIuJEcN*OYOHiuI36btA7h^>zv1p5`v3U-Y-p^ID7SJqOwCkbTo654&Q9%e+>V zMhdndUF6;|wMDvqME3`=pM>A9_!YimKgwTlKUUz2-LHMl+eQw(<4icxzYayo@j+@Zxi7qNBGLYzs0VD@Hdm!*N8C}#&bEsb|dUpMR-vC$tlm6zT@6>D@w$FHbPe|esknKk`8oj z!JA|HKE}N|+Zf7nx0Y}=q&JqV2%_vq{LP5J(Z%NKJ+_R$FDgabyiPKcZ(G>httxbR zr&pr9_&t;<1v-zcSG;kMU9XGuyStHsq^p;pkCZmj3tgM>TPm|&Z*;l!#cEB8_F0Ja zcWXmw?B>$`CGeOoFdr!>ZC!$qqq?-U0*`+cpUhviii;~BKZ5jDm8a8Rz_ZvlZ$B1s zH%vg2mPUiD=tff^$Cx>c%oqBhqO1!32YtV=ZQ;m&cAJS5#9VW?umqLsl55OausP}y zP+Q_h+VcB4Q?E;>AHjF+EBB!*T3GTP^?&qLpr3=xX2`r#^0y*)e$Kn2c=aQQ%n zzO}H!_)SGy3LnAyin{RV$+S6YWbTyHtEhcvX){&Tu8R+&XEpvBz#RnFbvYg&>OR-to=dWzaH)Ieu&AW)zb2L*ELc`LRB#KhqBL2c z`nlcE|9m8!e$?*g8cJ(dm4=p=)>fde`?%g<#H-~v8#f!uA!Ow^;sw^E(-rI|vfqi3 zO=HfTb>Wtk@G7i+T&!OE@#C!z^Q`S1T!c9^euqfa4bl*sG=S^R;=~79!R-gP8{c)` zEawThKp+{cE5Ta;=$jEFvRfg$3cqFaxg1$cWkhCaNuP>C*(79N7^CcQ$VTwnNMq4E zr51iOM%gOJw&FLI#-cX{+2doBeG;;33{jHF|DHl34tG&4-Bn#Dm1*A26J_ znK(q8a!7~Q663@qahO>CLoF94CW$W-%YUT9`-w@S^{nPixn&DOKA*uIWBHipukqRJ zSz1Fn{Co}8{*P!qujBI&{rwGmE+)#>xqO~yxH`MQvkCv}NV-eHBU+s`ULNoX;A~7j z6Es)@%!t`?(=V(y>E|h%j|FR|wAG=#Wn|u}r z_4BzJ?DR&keJWIt^7!|b)U&bUFrO!M=!pNt=RqSteP`jU1WBSBt#CgOT;!0u*aUF3JaT{?baS!nT@i6fy@g#AAy2OcpvX3~8IFDFETuE#p zt|M+DZX@m_?jar^9wr_oo+M8AH*|ARZBhDk%5LXggi0g=(h}(!eiF=3# zh=++si6@B@e#!KS(}?qkHN=&~7UDYMCgL{YPU0To0peleQQ}GB1a(mj?VmV}IFDFE zTuE#pt|M+DZX@m_?jar^9wr_oo+M8Acb1*|ARZTtb{ioJXu7t|Yb) z*AX`nw-I*|_Ye;d4-=0PPZB5mhUpWh5$6$Wh%1RL#C60?M6D(N|Kswh9A>m|Bi!oP zf6@P*F8;lz*ZBFO(Oc_24}6X4tswU+{AWo2ubBT7_Y+=gex31uNBzMwl>g(@A38(& z|3>}C&X9eK{a-#q`c3|=p#o>s{6n5i{YK7^{Z0MG&X9g%f8QChkFo!hGo;_xKYoVn zW9&b0hV&czPd`KUG4>CfA^pbwi8Ev$WB|c9^^c(vp&yanL{fEww zeq;YtXUIOr{*g1J-`GEOhU{bPKYWJt8~ex3kbR8(`_GVmV}Gme%*;QH{e5Rhzp?-3 zGh`oQ|A8~4-`L-OhU{bPA2>t$jr|j6$UesYyUvh)WB=e8vX8NU=nUyM_TPJk>|^Yo zJVW}8{Uc|{KF0pBe~|tWuIJ49zi5YE7n$et9M2axo-c7cPjx(B=6H6>JM~@p8s(kw zozF8I`sX;F-|2XEE(*uGzfws(Ccd$!_0Ve@m%P%ymFZ142@;21^Nx-~;aDH>u2c3W z_@aIa{dYF&{XOEeQ^)DqEq*drcl-}tmdllUtxuo+jBY=XPNuiPJ>4y=FCXPX54g+y zJKJaC&+g%;n_n+2pJIMO4uwO7UNIbk|L8}D|M>qyCy*!@TYiF@bNwaQmHRwec84AQ z6a4+y(j86jXyM;rJ)~IP*hB8=)^dL=(WS$ao80A|HuXw5pNHIbbB~I0kq6!N8UG%n z-wvvmp7Trf0@EEnp~HM0axYQN$Npi^qrKSe;6?X*<>%nlF<#oov0Xd+*Q9;3?A4|B zs$)6YNAj4~l=wem)98PHZhMGy=RS|7CFN`%DKE>7rs?#;FJV0dV>-R~X7_ZbQ*N04 zJmk@ij9*2Ly6ZW;+-2?=I^$i>{H$^WB#Zws={nSo{^;u}oN|dR?sDrW7hyXM zddPi%as!l0eZXCx>4yVMH{c=nN$N|P_VTd1zTK1y{#Dx|^?rA`eI|d@7x0j?+tt6j z>&dtH*cdNuKW4rH4mE@0y<#{7|Iv?*_BDJ|C*XT!Yzd_t?aS&vz4n!Kw6Ed4|1)-I z<-84C*qg?2N?sCO^ zA0=h{&%>XM|M|{vJ9E#aWxa{{bk0u)$9csVtp;CXxWoT^^uOd7*Z+wv4u8Af@jOcQ z5)S`Mec^w`4gvH2Qm;-g@?rOMjsFeO{{}t$)cDoVm)-S@Vurk6FD;cG{*xNXQ}I7T zIQ(bucRJa?7}q!PM{@lo_}<*-(F!r(@E>c3m*qy&bb8^&FB0^h3JM41L1O zaz^4GgI)BCfj*ty&_~?UeSmU7%K1Iyj6V+3&tmF_1@rSdKz#wWo1w?u)BOzP;%v_` z4>{wv{!hE>$UO4DAdz zycag{y>1ikjQ{c|`u{je`0qyv@8*8JNx#^9A->lUUgQWL?Qyj7z1IAXW}ma=%k|&0 z^_T0hXZB{N7Ej{tNBjxyj`xS#G}v zRcKvgx&01Ap*7iBRiD2OEwnDi4;Q=fmspWo-S|r_|9~6sT)pe__#*31dAHy$KtT$u z63eWsjkc@Fn{~F~tH6)5F0~@tHRH##eD1)X=rQ{}Mt&oCv+wk{2;=ib{Hb)g|6yET zuD=Lx_Bn46VSFZH87#cnKR5i9|KAtOo8~KQXUr*k0@E-*) z_74v0j9<+O_h%>{XSvKgVK3#)zSR9J?@!5_`&M=2E$CDF|EdYYUq*hw!7nCn&by5K zM)GEV&+t!^H}@@(4fT1!=;wZ*;s2YwIiE57h4_Ii$)`CtH2ggB<~-Z*H&e%A0$v{P`>EkL1nymfBozeL{L7dCt;emG3z zldy(-41YCwbG~T!YVziu=2beH)kNOhCpG!mK;E2_zk~8$F#36a!|>0LH}{mjPx)Vw zH}|QG{{KTha;_G96763;@{b)zxl{*>=eg%9+PaRs8GrX`+FAmBoOOwnyiM{71=OM*acn8Fc8`Mn2)-cak4)@Vm*!9sGC5#~l0+`G|v0kqX+PRi|%E8|PUh2`@qrQ=Lem{A058Lox zCvWbr8vY1*i}wW$f5mxPf5^e#LEhZIHS$l8H}?(=e~`Snw`lmkkRRZED#Kq^qSH0^ zwhX_Fyt(&f`1Rz?Jv77bByaAq8U9)F<{q5kPmnkFat!}E{7#|j2Y6q{@FDW%9);l_ zBya9v82(%2&AGSXe?#8lIg{Z_&Zqqy{B`8bIjNCvBX7>D4F5^;=Df@BKOt|<%M5>B zsZMujz3w-jNB=0FDdf$4{iif-EhcaA{<7iw$(wu45z6l(Z|+4W$p6g9^S-pvQ-BGp z*x%gCHvB^J=3ckq?;~&Sg&Te^d2_GagbQ_k%>7BjmytL3FO8l?^5*`g;U6Y%@jjX1 zzeL{LGfP+t@K|DL zf8hNRBYzcnb05I)w~{ya2@L-bd2|c@Av!%$cn7W6qHc-$LG; zLmU1R;AOmsus^S5y1U3*4*o0T6Rmn&F!KAT-<%iTKs`TK^5FZML|1WkVCD|z@yQ*M4L$S2n1@;6eCxrb-c?NjpSTOmif@1?xC zA8XS6F!iSzbM=3myx+lpmU<$*e`?bGS0#VGRqjal2b2%;-upiK!x8F_L~_&pBYDfg zzf3+6&Xq5~l30xwynk)-a~XKCzu%Fct0^B$>G96kp-RbLVx{iL)xVT{+`+FR?|1NP zsNcM2Ve<1nC4atE?8wgtC~w}oGVS!U)E`m*z?J^D5yf<0CZAZHo6m1iPvS*gE|cyr zmHheEFz+py{^9qOH}4A?I}}Y}|M0F{{iWpN4t@%Gzk|OVywr<%pU>o{+URlgGt08{}A~E?~`DdR-ez3A8_zb8~F!x zx(Qtk)^EwDcrVZJm%L8fIl=p$hOZzWd3Ua!DEU->F8>iDzb=>m26?L|mrs#T#&Y>{ zUeEmS{Zo@4`L{FG_;pvV{A%(;4!gCHw;cBGCLeT+Yxj{)I{N=jM&8l?4;XoepFCmY z9sT4EBk$->zG&nf{mEV<@9?Yd7<<%0k2&~e>hU@BbdsOq;QOg3 z?$Gl9`2h#Ng?gqt^lT#^aPSH0NjUU;p8TML-%UM1hn}a&*E;xv)RT1R`3dMj9*<&-u&K-;b&0K zW`~}64OMgBP>Z~A%ieE625K$(#3Ujr>aT<~`d4_4kpt9@hCZ@*g5^-m5gPm3*1Jc|Xj^f6wUQ zICzlye@ouH&tv3E-lX$y-s>^)bIF_cFO2*$@|GEwssApchxhG`{1)=&-hG1dUm|br zR~z}~jUL{!oRf>5kIbfZzvA=HNq10B%%Nvc$>*Q9dgcFFC4Yf+;wtSY*`;tR?=O{n{`u^S ziqAiv{R?>PiszjdPw;E|7dy^dCn+9_yijg_rh_+a5DM+j^?nPZFV=T=Xp1dj$YStr z@~b`g4(dt%R_l41dLHwTe}eJ}IRM4yMfHEYui)4DF&79PA^&agZuxnZ@&n~sPa%u_ zf`|NnQ9iEz5pet)^E#SUdYMkwzeP_>K45@HesH>0VC09uUx;(V0k#)YUw;Mfr_OA+@Gb88r-R4VV%}!~c-4;L zI$fw$pT!<}ZlQc|mzFo}<$e$OhbbSsQOj3S|7Sepzv{t1Lp=kZ(Rxh1zvLnR3gr_^ zwfuKASjDivD(}sjn8^IR#iL$spnQb>SxNa8@&og>~KH@;QMoBw&c;<0Z~SfBzY(y^A15AvMiVMe{( zLr*v5(x81GZ zkPpg*6MT%HTr|zSUHHK(e^{*L@1*{D9`Z{(_|+bKhX=pjgMSpf5w0>iUl+p8R&A+0-DxB_K z-bvu4zJ}Qk;5b8lF7uF|Mfp^pR{Rj<7m`o1pWI7+Ie6*+!<`Ps;HzePU8cG^k)2jqtbv?G}L#-BX&k5E3vdifCbTz-|dTVjV!*UY1qkoUb$ z^OsZpUE~MZ51aA#0q|~q_+iQ?spm23`4suYLapCV{>vVE4k-Ejdy7QQ$ zFZH$EQC}CoO_$f=d|(38T>#!K|0}>>2+xW;*6(+C$j7KZ!VVbOP@nga4>-oD0S`T& z_Tcw=@IUq7e+^#RMdEGRPuiKE6Xbmypmvilx?0PpSTE<2pQLy`WWkl--R$-b4}PTw z-{PVFUJv<4l|1e{g|+|eV4il6_bu1_0rFq*(DQW<{(ICDaOnS)hx{Kr_*Xpm^Ji%P z9CY~SW#Fa0Qgu52HO&74#b+6wUzbzf&vAJ<`4;jP`PY+Q2i~o|9-@4b^=|s@$BiEH z>!@c3`5*^I)8GCxc|ZLh+wbc0ui)L%y$A(#<9|#&A@)}jspofwU#;zPlKctq(%use zdycm=VJ0fo~xREqn!M3nbv}FyqofW2JdEv!neEg zZ}i{;9{ly-#cpxO__d6@e~-?Ona|wsq33ZAewPRTE$UAdXnUG<-!TvQzfwN(q|T4= z+e-sF|A`~oU@({Z%mVLbw+hPp=qDAFzeVwU$b!2(^xR85k*jrnUSyn4dB}f-@}U`8 zzJc<;ARqXnCQP~hMBe&?<}auGTW0C<`j2bkVe&VE_wjo+G<)#(c<_%=f9jIldf82W zhz;u!CUSs$Y>h5giw5i8z)QbT>*zQBM)_g-+j#0ZZ?=2>F99$9Imq%F`^+PsTB#F! zf_kdS53@qdyr_-5-!WhMF!==UA(;N>8{~(Yv>hf={}6aLJI}0j=YK^#p=mmw&r;8S z8U4&>Dfuhr=<+5xPv$h*noT}lrS%L@e!fS3Dk&ekLd!o-`BmVhUWOd?vVroUs4j08 z9qw`PZsq-)2fx>Y-|xXc=fNKVFZDjOM&}2^qWb)W{NNm2uG`3;gAEY3e7@C#pY6d{ zfR}Xr_h|i}rTzx;gKyUS*U8`Qq33;+PrgOVUr+gukPrN)CQSR?WBB$x;Qfr7 z4ZooLF#8ANKjY`>{14DRrk!32-pxL5puCUsggcqYbn=0hG-29Z1^M7jI)nQuAM((@ zn)24?w7eNdHh9QC?!kW!y!h=ZhuzC`|Wuz|#?`EHwlpo|c z$Z4E)yN7(g2mb-;u`0D4HZ$FAcFSfcfq@qHcnBLbkl8+5)-uQnl`9aQSusl?s+rYckOScEV!Gr&>2R{g2@)^2a z=jSBTeHy&fOVVM_ArC!&q@Kh_wI1Wo7rjI453)U0QU7J+{l~Suv0E*9>jT=)Z>Ibj z@~M=TH}>32KF)RVa>{>P@qEaFFH?T_Dy`={4c5=dCwcy5()}~}AlI#LqOQX0bh!fZ zVk16sKTJMT$S3->;*V(BnhxHr9_uJST&?9BDSr$3_$M`Q{PSV(QZGSAy?nt#|KB|L zZ+h@Q@!$`GSL67Hb$NL$%sNRv@o;W^owLBbyl((6dIn$6#^(6nO^&HY*eTjUEhBV{*Pss;3uQT(C-+SmUhJaf=P6e;p`&~N0A?E)Y@`JUS z|2+BMdCb$UqkLeomVYxTehwSf6XgAW z(Y(AjD4*|u4}*8J!v*hTyKtU{)@&ljKdKxuYgW#pT>~*x4XTZDV|EJWGbd0~h^N{}!%E!0qd~z9P{kPH6 zp)*p!d``N-J>7r@e?55dtKr{kJ*MAlA)mNZr~9T!I)O)xJo{S=$LjMj@-aF>=Xsj{ zSMomk$y+J^L-20)d4ci+!#Y1tQ@$Xm^BGIz=Ch3a0Ox5Pl)u67AJg&&$cGId(dFWG z3M+_%C%62xQ{KmmpHp-+>p}7s6}*S~A0r?6XPxdo4c3>yyXpU?2mb@=iSs^2o25U$ z@{oVg$UD{reEPq$WMol~Lh8G0)-NVv@K@6v=BuV<3CxV~OWJr(4ATnAl5J_O#a zysN>>{S!a$pTsHO<{{tb!9N6E{5Hh=(A}&Rs7K+4xbKQ-gZgZxd~D}9^=$g>Z+Ynd z1?2}AU*q{HAe2DXwCn$eD?HS>GX*cAje|d$wosU7@ z&HicXiCnA|RMWAhq9Ec|vDG?1Utm7Vz`N-QQa*81>oN0fO`H+-p7qYGY*cccDKVvaGvgFpYf0vKks+=`84p7 ze;@npdztPc^8P1uetu2-!Fxt#nE_q)DBelGa{_j$&XuLAF8 z{}q%EeO2p!NrUyEhy25oAN-?MZ0cnv`4sp0A7#4VB_Cn`Y}Px^k&i#3{nPZ5C&0Vq zvv`p^e~AZwC3w|N{klLuXMPrgzfj%}<@+5btve{6bnF{WQz^dTytlOKaWpc@226Pl)$s z!<4^{e4GuM+jG_u4?VXjc}C8HPNV-%IzMKSJor1nD|>!O`}2>ezk|H>D_t&L z3$Q*2-cOlq_yXl4HCleDR%d+^yjwnhVD$fsmN)Z(Kar39Qu7Zok;#kQ^-KpZ`42ko z^W5kmzuJTEpq>aToZA)F2J$}62Qa-?pT~?m&!?Km|C5LQuTVbqXI(BVf7IuDIrE$i)fi|d zS?A{c9^FjHyV)lQUi>ZbZCzhxUep3!`e(~ww_XoD4^U5#>&nZRsZV&we}VG8ujHot z0{PT(&0~6_K7aDi^NI)WTjE~cut&fBMi2RGJopOm;#U!eeQqVc%fa6TUhJHjq02Re z<=Q}g@VMqVTv=ZvA7}rJV_)_8CV01c{1N3N+&?k%jsNW-{}&JboTcviF9NUf@3_A) z3;c!5TQ*cv-m22&TF1bZ9{O86_@gu2^J9g>osGS1>!RU~=9x{_l4ws)RkSzS)Z5h^ zYVTXy)*0^YZd@1b?uojEHMK_@yWIlT^){|)k6H~~T}v7}*RNRLv8JniS$C+fv#GZa z$#r#7d0S^&@90u?7Dm;#Hrg8ww{%B4?_D46QK^PegnPQWn@uVeO-<2G$wai-S-_h+ zW8H0?D(B9i6@5Liwx+hOzMiVSSbJL&qH9Iog3B8_*G4neThSMbcHa_h>u$aUxyg^_ z5~>Q*))Q{(>qd!sRWZVA8k;RwUApL9-O;wSo#FPb&b8rt8he{st;##^s_R_W*xuH> zqPHvNOt_-EskO1K>E;;HukX4inpf*y0xG#ReJ$201x(f(dz#wX!d;#1>mlE`rmd;2 zr>kA+pr)(4!1rkIYFmbR*~Jd_ zFayJ5jc9Y-@Ln{Ko?f(>rf_5T+OVd3+}d1ow6VRttLfAg(%#t98*XfmwKj%(qS4M% zxDx8NCE5)E2 zRA|0SC^}PK_hLANv{6X9v|$zE>Lx10%SlwAOK02}y~n-EM)NA&Q|Fgi^Q?hzd@8RY=zd>HHYu)YU`XiYt|eIU%0+E+LJ8- zuD%UAosoK?z0J{<#=iDmM4hb_^~IVoLg0CpenzHx@D#{?3S67>RIZ;e+Vw>t8@Z!7tnb^M{+d z`Z{|@iD7q^wzT`Ot<;~Ea8Dm5L_Iw+1MHJY0HzL@1?XhLEp45R?WZ14P8I*uF&)_q z_q263MZ>C_?}^6T=PkN?cixp5J!lZumaC-i>6W=r59U4;^`1THAurshrii0UH#X;G z!&|qbwC=sQ$}pTFGl$d8;jI?aK|L=VO;FmiT_iJ7XASB3`EwEKu_puJta|TOGhLGb z6V1Idb9K(jtw`?$4 zciq#Dg~rVC`Jr%Pn++M44m3+)*({@Qj-Bl}^WCH6>7Rr3tlLIvmi{@jZT)uEXP3K2%hQkdfV_tE ztR(RE6&-b!tTEAuU8Y2Nx@XPxp3Y?{pH*fnw@ZT6w&$ivCLPmwYz1>|2QRZdakg!K zF2kGJyLzHCujLxOx3#(vLZkMvo>B4}bG~SPd(4*^ZTLG?4BbB5BwV~cU(D5c^ToV;%1zQ^ z|2iY8wu5@2oy{|^wY|W0k#f5YmfNjme#S*?51ebee3>10j@@g{w!61kw#$`Un6!zf zwBgX>-e~j8*;Yqab03bQG|Zf3VXp}rSkeAiS9foZ87k(OFLTY8`R2>D<_q?sIIv)Y z%Y2(>e=9fNW(VwVv+ZxT-r2U|*|z36w&poyCdM3F^Bh}qnXS3Z&Ow>2xy;sFW^0~n z=U}d_d9JN_uB~~Vor8I{=6SZ}dA8>Hb`J2;Cv7m_);!fTT3hqAWvsSvN3^%KtGUO!LmE{8Jr*V!IL!3yJ2NUg`&MdjZBQn%OEM9byfVz`gz`5N5iG8*&yI-?^$BomAMZ+>TLB6|wt>F}QGI&^spW^}p? z9!85xP$pgz`i@>4lHu6AIocgvi|HmdPJ6MTi__O=4^GybyTWVRyVf+ehnsPp-V<)@ z>$jS^FfPFfo6!NeO30>b8_xQ=8`rA=aJ|*ijlKDBb6-ctdPK>3(&J&aXgFN6ykbdp zxO!<7hDYe{=?b?tb~dB)3s>E`v|>qJC0P7(li})Giq=*w2i35o(nMNRzieSeeRx?- z&5G)Va6`qy`f3?~Z|-bs>S~ULYr4BS^s#{qzg2Bbz2Qo1ibG;)U&k6)U}jD~wWhH}{-b9z#*TJy{!}JEs(a@I zRZ;ZJBECco_G)V$Ot@2yxMU*G4cqkfwzZ>W)-@~%XWA@$Us`N~y0U@_q1V=Tb=}n$ ztLW|Ru4~2-d~;V{epzWPI2P=!Jx?a2l8uZb<@b2Dw>RK6Ni=MtDBp)WNn@$&?44J( zunS%-jx2t*Jc>h%ZfRC*Xmp`b)3U3Vt*fF(B`cX!DTcam+QO!c`mNFjaksSfwl0NP zl#8}@M;mc}MCQ{scQ&;~o9>D>Bcm!>R4O*V=EN0^FG9OEPGz*M9R*PBQaX~Vu0Hym z%1K=(?mQ^1u%1UhVb^oUz}~%lRvwTA)sM18pp>U*MS2e**4NvU=iU-A-;q`Cg<{en z>U!#XrT=Z~>1^!GS0SC|&FXklj8K7|2Oc5qHkv1Ex28(5x?N8<;xKe&n{M37niW0D zV?+Rk>A;a5J1I?Ma_rT9vb==;Rne?^q-?LW9g=NCx?(gCoCCLYu0_SdebD>i4pm!c z4<6YD=xJq)Eq4X_2Bj25Xpc6x^~B`f6q=hJ(QD+S z1YIAC)1zCfoiU`GWdSL`@+Gc>X4nqf^l%` zNnhcCxEffYTn(HE%a{@i+g{vm($X}4 zk7_}wB@`LaH7+HgkE?NB70pzE%Bu*-ntZfTl$w{C?ipjK9%B$d2h1KnveU3VT^WfT zrsPcA$75H-j5V2x!^nmx#?D#2UbPswsu8^%yK=Fh=j7CN_*|vuBBwCD-8W`tRuwpZ z*OLI{W3ao{BHmuz+1zsvdSn=fO>cQyQ>#og8ZjiO&VvTX_kBAl6!%nvqq^MDn3-gF z^y*n11!qvG0j*bzDcO)o5GpB?*+rFMY1FF!qWkcMAEdRr;r}SEp3*JHjfl36sJ4LZ zfjTuqvLr~mrma2Ni77HY6ph8qRjY53+=Qipwyo*wr9#P|o){vJv*wA2n7FQ|p}P;Z zM5o=>*^=84LnoU7TCK@}FpDtJ?X+EYiS!(p`rFdbD;*;mYg21?u1dQirJdo1A7)IF z6XVh=)g2bJDCMQf`|B_v?6+Dvx@58;a$3foKA5P|40}{e)VEqRt7#z0V0!IJMP!~c z^K)9YMLNB%F3gq0Skl9?m91#Sl#io8k3K?omZWV;_P=>%PRZYn5=?K z3y=y~9>orxwhFunoqa}iMbC;JblYKZFu`7D2J7qP7 zIT=UZ%=m!u7x$A{2(LV4&(6e4I$&)*_GC35sV>ZYk!9rqm?zfbLKw2PDB5X;L1_ee z{*M@{EB4qTG<~ra8^sdHsh*8NTD(GC9g{qnYL=;xX(#l&Wy;RRfO?W`h6&hT7BCCZ z8-;7JZbxy<5U*C2ot<5B-4++!Wai5jQ-gBL6a>O#mUbx4V5c?O(bN&k?eJht zH5F8jlS8{UzwGA01jjI+p=)G~%+l<$O=gzVu!S_7N*v&1MvtCZk~`IKyli5Y8EW9l z*;Y`kVQIAA-f2sMvO%o@hn)NK}OPZp@sBSWxv zwj^xeF=Nf{fH_NKtHF+s+7ePemKjLcBj_PZT9mFNljl=R>#~zl*0p;ceXZ4WC@5Lh zfR|CvF$PtMNxx$sqN5p0V`=iZUP;SjE!i>?n1;r-c3jZKYaDu<%bI<#^yuoaw&+>k z*_72OOLnDOw5JC2%v$U;NqU*SMCV+3I@1-Yt_~Y|@J;lS$fHbW%!&}xQ;4Di#g5e) zERfXL$I`FpThl8sBmvLGjzkaFG`7n!sJl-KXIamT>a>Z6w`3I|YilqZUfY2kDomxY zsi%(pM(HQAEBI!#sPasM!VEBz$O`=++VWgnq?E^Tp$FrrEuGB1+bKLucT|XywY>tb zVqKd}LwjDsc|-nIi)13VuXF9xRIeOcpXrrx;%l-`XNDDUPr&YTrH6NHnvNkId&Cx3 zk)VCa7g~gaY^Ig%7yRogk%UWt1^-?J_ zlgIfx)00HSi0EM#Ha5c-`#Nxx42I1BW0fokBpG-kP78bNd#&wQS!ZrUcgxLIW8M70 z&@QOhU;0Bm!8H3a(Crv~5W)1|xs#LJ(G%))2cOyWW*e#KVgDl2!`^UJTTfFX-fffg z;hi3Rrron@lPqgeZ)M3MLap%3Opg6kCARu{qq9XPCN_BQNUZ@dJyg4onChvW?o5A? zHA~l(?Q%^5N#$;~>+@J zva<8x+WfOUfK{}L3tQXUR;srtn=pG6AAu?C`KaEq%9zq@Y0*t(!fB?apy0=Er!~`G@qj^hLHXTac6FM}V2XupQ*_&y?pLZ8Eszpx zs;*PLV@NLyhvgN4_UO83J8zcg)2F(g>btYgzqscji%W-T^|W9y-hVL-atvOYZFbdu zyiBb|PT7#>z^Nw$w?(_Vq?hQyf<+G$xYZ!Z%Yxbc45TBoqO&W>#aTs(Y80-9Hr-gJ zDdx=*Q62UOYo;6(JzTul33AtkmEcu)Xfi2!wL?2CsLGmAm=VpT|EZU{w)<0Me9WPu z-EB=3>P5*x4uiQ ztR<4SdQ

GL>E3U8;wWJxulxD51)p=PryE4$P% zs%0}?ob3#fGjRy%k-xeJvTSh;3lozVly=?)q_TonL@g* ze2n|#N#`C9YD2hsvuy^cQJD1JXeTD%k|kwid`C9q{Z%UrPJG_Xl<`Q{lBSvQH+vHy zdzv(c34=Y~8e@g%oWohrO8CC7xI|@RpFX9um+Hz-(a*ut)w!e;PL^)%%P~%33u9S~ z{z6sacdSS6KFW3nWFWWcU}HJ7Ub-!_{xGAb|(*%V&V7?W*&Jr!iBkayi{#PnSt<)&VvkE&*PnX6}*e$J~O%<^aHupDPmdL74; zcKQjQxbT5%>4gvaFXMOST2Gb>xJ|!oR}rUG{w5_k^}duyXxGe~BQRfi$FbbW%`{Zg z?TxKT+Lr0zLPMgtO(Y~wUgovSsQS+pnPJ(jZ_#Z*&z#j%uMszDs{7SFg388N4=xGw zWK8)(U61T(aqzI)32Gzf{C;Vd@;ue27nm&mwhvidp{u)7jO7MiE5efq(}8K*7r9 z1lz2qMGRsQY$9TDC_*|tbB7nmUCvyD1RD#BU=?g^QwBQ=t%F$Dd8CjuLa?y1v9Yi) ze(&d-ot@lCaAEJw%+5D6JM-qv-@CU_&Wf}G>svWdIeKWLT4#9Oaf|{vANiq_He6;a zO}oxW7U70~3VP8cL}e&%nF3B(x22q7+r_>G@h=r6EiOWXv!g`x;UiAImB);TG9l<1r6lqdKS5xlYZ?nsLdI z%3|)fr7I>sE0XpUK0>8Qg<)QHWx6tli~Ib_+=!whhKlbBS7_R{$S=zxt>kB=3D4`4 zVPq>%ocq3_?h8w?4j*!2AkuPUGTK1J;V4BH)+#v;j}(%IH2#rCco`X}NZIaVPY!&j zg(~?@(nQHdv9Z2}^+)s~&P7mUV>FssflahzT!NB^R*NxJ_CB$fLlL&UlBu!) z!6}33BV`M{vf{7;i>lnA7_4_;Z4GpF#b}2voWZw?$GxY8tnyn^i>;u(j+|c=t@R#| zMlq7=6Pclkl3wb0fM+Z1rKSMf)yD+ASQJ@YtjbcW5Uoo*TZXBbW+>VnSFi81fThn6 zrjl<6x&On+m;O{@(7l1pC+s&y4|NKg% zm$G!-++_?c;QDoNuuQyvHXxAJPgv9mN6@}36Ts(t!b#l3Z=SLzq+77VDVO9cmJ5le zy~bIDN!rBAcO2v*{W4{K{+jhe`a*zN+;EVT|5(?ak10cZ+^4*q*vcnTZ}lS`Xa-Bd~G#J3d^gN z%bPQXy@X40VEuxtiU{N54qAAptjCw|}Y`;OoC>O>U1YEDT$!y&v! z{Kjo_ZCp1x^yX*1vE1Z?Jz&%P=kFM9{)W+QBg`)HKhyb|;X}g#vqo=a3`891_Y6<_ z=?~p5`u23pS{=2jH~fHK(qb`dv{U=sLORUIaW$tTKjDz~uQR~uq~kAV;a;7Jkw@as znn)2dj&IymZxA_f50P0M%3rA-mfd37@5Zi$K7$?E^kV)DI}67s{KQ3T@!yQ-G{^r1 DNR#cw literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/models.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/models.py new file mode 100644 index 0000000..a760b9c --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/models.py @@ -0,0 +1,340 @@ +from encodings.aliases import aliases +from hashlib import sha256 +from json import dumps +from typing import Any, Dict, Iterator, List, Optional, Tuple, Union + +from .constant import TOO_BIG_SEQUENCE +from .utils import iana_name, is_multi_byte_encoding, unicode_range + + +class CharsetMatch: + def __init__( + self, + payload: bytes, + guessed_encoding: str, + mean_mess_ratio: float, + has_sig_or_bom: bool, + languages: "CoherenceMatches", + decoded_payload: Optional[str] = None, + ): + self._payload: bytes = payload + + self._encoding: str = guessed_encoding + self._mean_mess_ratio: float = mean_mess_ratio + self._languages: CoherenceMatches = languages + self._has_sig_or_bom: bool = has_sig_or_bom + self._unicode_ranges: Optional[List[str]] = None + + self._leaves: List[CharsetMatch] = [] + self._mean_coherence_ratio: float = 0.0 + + self._output_payload: Optional[bytes] = None + self._output_encoding: Optional[str] = None + + self._string: Optional[str] = decoded_payload + + def __eq__(self, other: object) -> bool: + if not isinstance(other, CharsetMatch): + raise TypeError( + "__eq__ cannot be invoked on {} and {}.".format( + str(other.__class__), str(self.__class__) + ) + ) + return self.encoding == other.encoding and self.fingerprint == other.fingerprint + + def __lt__(self, other: object) -> bool: + """ + Implemented to make sorted available upon CharsetMatches items. + """ + if not isinstance(other, CharsetMatch): + raise ValueError + + chaos_difference: float = abs(self.chaos - other.chaos) + coherence_difference: float = abs(self.coherence - other.coherence) + + # Below 1% difference --> Use Coherence + if chaos_difference < 0.01 and coherence_difference > 0.02: + return self.coherence > other.coherence + elif chaos_difference < 0.01 and coherence_difference <= 0.02: + # When having a difficult decision, use the result that decoded as many multi-byte as possible. + # preserve RAM usage! + if len(self._payload) >= TOO_BIG_SEQUENCE: + return self.chaos < other.chaos + return self.multi_byte_usage > other.multi_byte_usage + + return self.chaos < other.chaos + + @property + def multi_byte_usage(self) -> float: + return 1.0 - (len(str(self)) / len(self.raw)) + + def __str__(self) -> str: + # Lazy Str Loading + if self._string is None: + self._string = str(self._payload, self._encoding, "strict") + return self._string + + def __repr__(self) -> str: + return "".format(self.encoding, self.fingerprint) + + def add_submatch(self, other: "CharsetMatch") -> None: + if not isinstance(other, CharsetMatch) or other == self: + raise ValueError( + "Unable to add instance <{}> as a submatch of a CharsetMatch".format( + other.__class__ + ) + ) + + other._string = None # Unload RAM usage; dirty trick. + self._leaves.append(other) + + @property + def encoding(self) -> str: + return self._encoding + + @property + def encoding_aliases(self) -> List[str]: + """ + Encoding name are known by many name, using this could help when searching for IBM855 when it's listed as CP855. + """ + also_known_as: List[str] = [] + for u, p in aliases.items(): + if self.encoding == u: + also_known_as.append(p) + elif self.encoding == p: + also_known_as.append(u) + return also_known_as + + @property + def bom(self) -> bool: + return self._has_sig_or_bom + + @property + def byte_order_mark(self) -> bool: + return self._has_sig_or_bom + + @property + def languages(self) -> List[str]: + """ + Return the complete list of possible languages found in decoded sequence. + Usually not really useful. Returned list may be empty even if 'language' property return something != 'Unknown'. + """ + return [e[0] for e in self._languages] + + @property + def language(self) -> str: + """ + Most probable language found in decoded sequence. If none were detected or inferred, the property will return + "Unknown". + """ + if not self._languages: + # Trying to infer the language based on the given encoding + # Its either English or we should not pronounce ourselves in certain cases. + if "ascii" in self.could_be_from_charset: + return "English" + + # doing it there to avoid circular import + from charset_normalizer.cd import encoding_languages, mb_encoding_languages + + languages = ( + mb_encoding_languages(self.encoding) + if is_multi_byte_encoding(self.encoding) + else encoding_languages(self.encoding) + ) + + if len(languages) == 0 or "Latin Based" in languages: + return "Unknown" + + return languages[0] + + return self._languages[0][0] + + @property + def chaos(self) -> float: + return self._mean_mess_ratio + + @property + def coherence(self) -> float: + if not self._languages: + return 0.0 + return self._languages[0][1] + + @property + def percent_chaos(self) -> float: + return round(self.chaos * 100, ndigits=3) + + @property + def percent_coherence(self) -> float: + return round(self.coherence * 100, ndigits=3) + + @property + def raw(self) -> bytes: + """ + Original untouched bytes. + """ + return self._payload + + @property + def submatch(self) -> List["CharsetMatch"]: + return self._leaves + + @property + def has_submatch(self) -> bool: + return len(self._leaves) > 0 + + @property + def alphabets(self) -> List[str]: + if self._unicode_ranges is not None: + return self._unicode_ranges + # list detected ranges + detected_ranges: List[Optional[str]] = [ + unicode_range(char) for char in str(self) + ] + # filter and sort + self._unicode_ranges = sorted(list({r for r in detected_ranges if r})) + return self._unicode_ranges + + @property + def could_be_from_charset(self) -> List[str]: + """ + The complete list of encoding that output the exact SAME str result and therefore could be the originating + encoding. + This list does include the encoding available in property 'encoding'. + """ + return [self._encoding] + [m.encoding for m in self._leaves] + + def output(self, encoding: str = "utf_8") -> bytes: + """ + Method to get re-encoded bytes payload using given target encoding. Default to UTF-8. + Any errors will be simply ignored by the encoder NOT replaced. + """ + if self._output_encoding is None or self._output_encoding != encoding: + self._output_encoding = encoding + self._output_payload = str(self).encode(encoding, "replace") + + return self._output_payload # type: ignore + + @property + def fingerprint(self) -> str: + """ + Retrieve the unique SHA256 computed using the transformed (re-encoded) payload. Not the original one. + """ + return sha256(self.output()).hexdigest() + + +class CharsetMatches: + """ + Container with every CharsetMatch items ordered by default from most probable to the less one. + Act like a list(iterable) but does not implements all related methods. + """ + + def __init__(self, results: Optional[List[CharsetMatch]] = None): + self._results: List[CharsetMatch] = sorted(results) if results else [] + + def __iter__(self) -> Iterator[CharsetMatch]: + yield from self._results + + def __getitem__(self, item: Union[int, str]) -> CharsetMatch: + """ + Retrieve a single item either by its position or encoding name (alias may be used here). + Raise KeyError upon invalid index or encoding not present in results. + """ + if isinstance(item, int): + return self._results[item] + if isinstance(item, str): + item = iana_name(item, False) + for result in self._results: + if item in result.could_be_from_charset: + return result + raise KeyError + + def __len__(self) -> int: + return len(self._results) + + def __bool__(self) -> bool: + return len(self._results) > 0 + + def append(self, item: CharsetMatch) -> None: + """ + Insert a single match. Will be inserted accordingly to preserve sort. + Can be inserted as a submatch. + """ + if not isinstance(item, CharsetMatch): + raise ValueError( + "Cannot append instance '{}' to CharsetMatches".format( + str(item.__class__) + ) + ) + # We should disable the submatch factoring when the input file is too heavy (conserve RAM usage) + if len(item.raw) <= TOO_BIG_SEQUENCE: + for match in self._results: + if match.fingerprint == item.fingerprint and match.chaos == item.chaos: + match.add_submatch(item) + return + self._results.append(item) + self._results = sorted(self._results) + + def best(self) -> Optional["CharsetMatch"]: + """ + Simply return the first match. Strict equivalent to matches[0]. + """ + if not self._results: + return None + return self._results[0] + + def first(self) -> Optional["CharsetMatch"]: + """ + Redundant method, call the method best(). Kept for BC reasons. + """ + return self.best() + + +CoherenceMatch = Tuple[str, float] +CoherenceMatches = List[CoherenceMatch] + + +class CliDetectionResult: + def __init__( + self, + path: str, + encoding: Optional[str], + encoding_aliases: List[str], + alternative_encodings: List[str], + language: str, + alphabets: List[str], + has_sig_or_bom: bool, + chaos: float, + coherence: float, + unicode_path: Optional[str], + is_preferred: bool, + ): + self.path: str = path + self.unicode_path: Optional[str] = unicode_path + self.encoding: Optional[str] = encoding + self.encoding_aliases: List[str] = encoding_aliases + self.alternative_encodings: List[str] = alternative_encodings + self.language: str = language + self.alphabets: List[str] = alphabets + self.has_sig_or_bom: bool = has_sig_or_bom + self.chaos: float = chaos + self.coherence: float = coherence + self.is_preferred: bool = is_preferred + + @property + def __dict__(self) -> Dict[str, Any]: # type: ignore + return { + "path": self.path, + "encoding": self.encoding, + "encoding_aliases": self.encoding_aliases, + "alternative_encodings": self.alternative_encodings, + "language": self.language, + "alphabets": self.alphabets, + "has_sig_or_bom": self.has_sig_or_bom, + "chaos": self.chaos, + "coherence": self.coherence, + "unicode_path": self.unicode_path, + "is_preferred": self.is_preferred, + } + + def to_json(self) -> str: + return dumps(self.__dict__, ensure_ascii=True, indent=4) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/py.typed b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/py.typed new file mode 100644 index 0000000..e69de29 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/utils.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/utils.py new file mode 100644 index 0000000..e5cbbf4 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/utils.py @@ -0,0 +1,421 @@ +import importlib +import logging +import unicodedata +from codecs import IncrementalDecoder +from encodings.aliases import aliases +from functools import lru_cache +from re import findall +from typing import Generator, List, Optional, Set, Tuple, Union + +from _multibytecodec import MultibyteIncrementalDecoder + +from .constant import ( + ENCODING_MARKS, + IANA_SUPPORTED_SIMILAR, + RE_POSSIBLE_ENCODING_INDICATION, + UNICODE_RANGES_COMBINED, + UNICODE_SECONDARY_RANGE_KEYWORD, + UTF8_MAXIMAL_ALLOCATION, +) + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_accentuated(character: str) -> bool: + try: + description: str = unicodedata.name(character) + except ValueError: + return False + return ( + "WITH GRAVE" in description + or "WITH ACUTE" in description + or "WITH CEDILLA" in description + or "WITH DIAERESIS" in description + or "WITH CIRCUMFLEX" in description + or "WITH TILDE" in description + or "WITH MACRON" in description + or "WITH RING ABOVE" in description + ) + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def remove_accent(character: str) -> str: + decomposed: str = unicodedata.decomposition(character) + if not decomposed: + return character + + codes: List[str] = decomposed.split(" ") + + return chr(int(codes[0], 16)) + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def unicode_range(character: str) -> Optional[str]: + """ + Retrieve the Unicode range official name from a single character. + """ + character_ord: int = ord(character) + + for range_name, ord_range in UNICODE_RANGES_COMBINED.items(): + if character_ord in ord_range: + return range_name + + return None + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_latin(character: str) -> bool: + try: + description: str = unicodedata.name(character) + except ValueError: + return False + return "LATIN" in description + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_punctuation(character: str) -> bool: + character_category: str = unicodedata.category(character) + + if "P" in character_category: + return True + + character_range: Optional[str] = unicode_range(character) + + if character_range is None: + return False + + return "Punctuation" in character_range + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_symbol(character: str) -> bool: + character_category: str = unicodedata.category(character) + + if "S" in character_category or "N" in character_category: + return True + + character_range: Optional[str] = unicode_range(character) + + if character_range is None: + return False + + return "Forms" in character_range and character_category != "Lo" + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_emoticon(character: str) -> bool: + character_range: Optional[str] = unicode_range(character) + + if character_range is None: + return False + + return "Emoticons" in character_range or "Pictographs" in character_range + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_separator(character: str) -> bool: + if character.isspace() or character in {"|", "+", "<", ">"}: + return True + + character_category: str = unicodedata.category(character) + + return "Z" in character_category or character_category in {"Po", "Pd", "Pc"} + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_case_variable(character: str) -> bool: + return character.islower() != character.isupper() + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_cjk(character: str) -> bool: + try: + character_name = unicodedata.name(character) + except ValueError: + return False + + return "CJK" in character_name + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_hiragana(character: str) -> bool: + try: + character_name = unicodedata.name(character) + except ValueError: + return False + + return "HIRAGANA" in character_name + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_katakana(character: str) -> bool: + try: + character_name = unicodedata.name(character) + except ValueError: + return False + + return "KATAKANA" in character_name + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_hangul(character: str) -> bool: + try: + character_name = unicodedata.name(character) + except ValueError: + return False + + return "HANGUL" in character_name + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_thai(character: str) -> bool: + try: + character_name = unicodedata.name(character) + except ValueError: + return False + + return "THAI" in character_name + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_arabic(character: str) -> bool: + try: + character_name = unicodedata.name(character) + except ValueError: + return False + + return "ARABIC" in character_name + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_arabic_isolated_form(character: str) -> bool: + try: + character_name = unicodedata.name(character) + except ValueError: + return False + + return "ARABIC" in character_name and "ISOLATED FORM" in character_name + + +@lru_cache(maxsize=len(UNICODE_RANGES_COMBINED)) +def is_unicode_range_secondary(range_name: str) -> bool: + return any(keyword in range_name for keyword in UNICODE_SECONDARY_RANGE_KEYWORD) + + +@lru_cache(maxsize=UTF8_MAXIMAL_ALLOCATION) +def is_unprintable(character: str) -> bool: + return ( + character.isspace() is False # includes \n \t \r \v + and character.isprintable() is False + and character != "\x1A" # Why? Its the ASCII substitute character. + and character != "\ufeff" # bug discovered in Python, + # Zero Width No-Break Space located in Arabic Presentation Forms-B, Unicode 1.1 not acknowledged as space. + ) + + +def any_specified_encoding(sequence: bytes, search_zone: int = 8192) -> Optional[str]: + """ + Extract using ASCII-only decoder any specified encoding in the first n-bytes. + """ + if not isinstance(sequence, bytes): + raise TypeError + + seq_len: int = len(sequence) + + results: List[str] = findall( + RE_POSSIBLE_ENCODING_INDICATION, + sequence[: min(seq_len, search_zone)].decode("ascii", errors="ignore"), + ) + + if len(results) == 0: + return None + + for specified_encoding in results: + specified_encoding = specified_encoding.lower().replace("-", "_") + + encoding_alias: str + encoding_iana: str + + for encoding_alias, encoding_iana in aliases.items(): + if encoding_alias == specified_encoding: + return encoding_iana + if encoding_iana == specified_encoding: + return encoding_iana + + return None + + +@lru_cache(maxsize=128) +def is_multi_byte_encoding(name: str) -> bool: + """ + Verify is a specific encoding is a multi byte one based on it IANA name + """ + return name in { + "utf_8", + "utf_8_sig", + "utf_16", + "utf_16_be", + "utf_16_le", + "utf_32", + "utf_32_le", + "utf_32_be", + "utf_7", + } or issubclass( + importlib.import_module("encodings.{}".format(name)).IncrementalDecoder, + MultibyteIncrementalDecoder, + ) + + +def identify_sig_or_bom(sequence: bytes) -> Tuple[Optional[str], bytes]: + """ + Identify and extract SIG/BOM in given sequence. + """ + + for iana_encoding in ENCODING_MARKS: + marks: Union[bytes, List[bytes]] = ENCODING_MARKS[iana_encoding] + + if isinstance(marks, bytes): + marks = [marks] + + for mark in marks: + if sequence.startswith(mark): + return iana_encoding, mark + + return None, b"" + + +def should_strip_sig_or_bom(iana_encoding: str) -> bool: + return iana_encoding not in {"utf_16", "utf_32"} + + +def iana_name(cp_name: str, strict: bool = True) -> str: + cp_name = cp_name.lower().replace("-", "_") + + encoding_alias: str + encoding_iana: str + + for encoding_alias, encoding_iana in aliases.items(): + if cp_name in [encoding_alias, encoding_iana]: + return encoding_iana + + if strict: + raise ValueError("Unable to retrieve IANA for '{}'".format(cp_name)) + + return cp_name + + +def range_scan(decoded_sequence: str) -> List[str]: + ranges: Set[str] = set() + + for character in decoded_sequence: + character_range: Optional[str] = unicode_range(character) + + if character_range is None: + continue + + ranges.add(character_range) + + return list(ranges) + + +def cp_similarity(iana_name_a: str, iana_name_b: str) -> float: + if is_multi_byte_encoding(iana_name_a) or is_multi_byte_encoding(iana_name_b): + return 0.0 + + decoder_a = importlib.import_module( + "encodings.{}".format(iana_name_a) + ).IncrementalDecoder + decoder_b = importlib.import_module( + "encodings.{}".format(iana_name_b) + ).IncrementalDecoder + + id_a: IncrementalDecoder = decoder_a(errors="ignore") + id_b: IncrementalDecoder = decoder_b(errors="ignore") + + character_match_count: int = 0 + + for i in range(255): + to_be_decoded: bytes = bytes([i]) + if id_a.decode(to_be_decoded) == id_b.decode(to_be_decoded): + character_match_count += 1 + + return character_match_count / 254 + + +def is_cp_similar(iana_name_a: str, iana_name_b: str) -> bool: + """ + Determine if two code page are at least 80% similar. IANA_SUPPORTED_SIMILAR dict was generated using + the function cp_similarity. + """ + return ( + iana_name_a in IANA_SUPPORTED_SIMILAR + and iana_name_b in IANA_SUPPORTED_SIMILAR[iana_name_a] + ) + + +def set_logging_handler( + name: str = "charset_normalizer", + level: int = logging.INFO, + format_string: str = "%(asctime)s | %(levelname)s | %(message)s", +) -> None: + logger = logging.getLogger(name) + logger.setLevel(level) + + handler = logging.StreamHandler() + handler.setFormatter(logging.Formatter(format_string)) + logger.addHandler(handler) + + +def cut_sequence_chunks( + sequences: bytes, + encoding_iana: str, + offsets: range, + chunk_size: int, + bom_or_sig_available: bool, + strip_sig_or_bom: bool, + sig_payload: bytes, + is_multi_byte_decoder: bool, + decoded_payload: Optional[str] = None, +) -> Generator[str, None, None]: + if decoded_payload and is_multi_byte_decoder is False: + for i in offsets: + chunk = decoded_payload[i : i + chunk_size] + if not chunk: + break + yield chunk + else: + for i in offsets: + chunk_end = i + chunk_size + if chunk_end > len(sequences) + 8: + continue + + cut_sequence = sequences[i : i + chunk_size] + + if bom_or_sig_available and strip_sig_or_bom is False: + cut_sequence = sig_payload + cut_sequence + + chunk = cut_sequence.decode( + encoding_iana, + errors="ignore" if is_multi_byte_decoder else "strict", + ) + + # multi-byte bad cutting detector and adjustment + # not the cleanest way to perform that fix but clever enough for now. + if is_multi_byte_decoder and i > 0: + chunk_partial_size_chk: int = min(chunk_size, 16) + + if ( + decoded_payload + and chunk[:chunk_partial_size_chk] not in decoded_payload + ): + for j in range(i, i - 4, -1): + cut_sequence = sequences[j:chunk_end] + + if bom_or_sig_available and strip_sig_or_bom is False: + cut_sequence = sig_payload + cut_sequence + + chunk = cut_sequence.decode(encoding_iana, errors="ignore") + + if chunk[:chunk_partial_size_chk] in decoded_payload: + break + + yield chunk diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/version.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/version.py new file mode 100644 index 0000000..5a4da4f --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/charset_normalizer/version.py @@ -0,0 +1,6 @@ +""" +Expose version +""" + +__version__ = "3.3.2" +VERSION = __version__.split(".") diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/INSTALLER b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/INSTALLER new file mode 100644 index 0000000..a1b589e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/INSTALLER @@ -0,0 +1 @@ +pip diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/LICENSE.md b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/LICENSE.md new file mode 100644 index 0000000..19b6b45 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/LICENSE.md @@ -0,0 +1,31 @@ +BSD 3-Clause License + +Copyright (c) 2013-2024, Kim Davies and contributors. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +3. Neither the name of the copyright holder nor the names of its + contributors may be used to endorse or promote products derived from + this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED +TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR +PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF +LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING +NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/METADATA b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/METADATA new file mode 100644 index 0000000..a04a7f9 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/METADATA @@ -0,0 +1,245 @@ +Metadata-Version: 2.1 +Name: idna +Version: 3.8 +Summary: Internationalized Domain Names in Applications (IDNA) +Author-email: Kim Davies +Requires-Python: >=3.6 +Description-Content-Type: text/x-rst +Classifier: Development Status :: 5 - Production/Stable +Classifier: Intended Audience :: Developers +Classifier: Intended Audience :: System Administrators +Classifier: License :: OSI Approved :: BSD License +Classifier: Operating System :: OS Independent +Classifier: Programming Language :: Python +Classifier: Programming Language :: Python :: 3 +Classifier: Programming Language :: Python :: 3 :: Only +Classifier: Programming Language :: Python :: 3.6 +Classifier: Programming Language :: Python :: 3.7 +Classifier: Programming Language :: Python :: 3.8 +Classifier: Programming Language :: Python :: 3.9 +Classifier: Programming Language :: Python :: 3.10 +Classifier: Programming Language :: Python :: 3.11 +Classifier: Programming Language :: Python :: 3.12 +Classifier: Programming Language :: Python :: 3.13 +Classifier: Programming Language :: Python :: Implementation :: CPython +Classifier: Programming Language :: Python :: Implementation :: PyPy +Classifier: Topic :: Internet :: Name Service (DNS) +Classifier: Topic :: Software Development :: Libraries :: Python Modules +Classifier: Topic :: Utilities +Project-URL: Changelog, https://github.com/kjd/idna/blob/master/HISTORY.rst +Project-URL: Issue tracker, https://github.com/kjd/idna/issues +Project-URL: Source, https://github.com/kjd/idna + +Internationalized Domain Names in Applications (IDNA) +===================================================== + +Support for the Internationalized Domain Names in +Applications (IDNA) protocol as specified in `RFC 5891 +`_. This is the latest version of +the protocol and is sometimes referred to as “IDNA 2008”. + +This library also provides support for Unicode Technical +Standard 46, `Unicode IDNA Compatibility Processing +`_. + +This acts as a suitable replacement for the “encodings.idna” +module that comes with the Python standard library, but which +only supports the older superseded IDNA specification (`RFC 3490 +`_). + +Basic functions are simply executed: + +.. code-block:: pycon + + >>> import idna + >>> idna.encode('ドメイン.テスト') + b'xn--eckwd4c7c.xn--zckzah' + >>> print(idna.decode('xn--eckwd4c7c.xn--zckzah')) + ドメイン.テスト + + +Installation +------------ + +This package is available for installation from PyPI: + +.. code-block:: bash + + $ python3 -m pip install idna + + +Usage +----- + +For typical usage, the ``encode`` and ``decode`` functions will take a +domain name argument and perform a conversion to A-labels or U-labels +respectively. + +.. code-block:: pycon + + >>> import idna + >>> idna.encode('ドメイン.テスト') + b'xn--eckwd4c7c.xn--zckzah' + >>> print(idna.decode('xn--eckwd4c7c.xn--zckzah')) + ドメイン.テスト + +You may use the codec encoding and decoding methods using the +``idna.codec`` module: + +.. code-block:: pycon + + >>> import idna.codec + >>> print('домен.испытание'.encode('idna2008')) + b'xn--d1acufc.xn--80akhbyknj4f' + >>> print(b'xn--d1acufc.xn--80akhbyknj4f'.decode('idna2008')) + домен.испытание + +Conversions can be applied at a per-label basis using the ``ulabel`` or +``alabel`` functions if necessary: + +.. code-block:: pycon + + >>> idna.alabel('测试') + b'xn--0zwm56d' + +Compatibility Mapping (UTS #46) ++++++++++++++++++++++++++++++++ + +As described in `RFC 5895 `_, the +IDNA specification does not normalize input from different potential +ways a user may input a domain name. This functionality, known as +a “mapping”, is considered by the specification to be a local +user-interface issue distinct from IDNA conversion functionality. + +This library provides one such mapping that was developed by the +Unicode Consortium. Known as `Unicode IDNA Compatibility Processing +`_, it provides for both a regular +mapping for typical applications, as well as a transitional mapping to +help migrate from older IDNA 2003 applications. Strings are +preprocessed according to Section 4.4 “Preprocessing for IDNA2008” +prior to the IDNA operations. + +For example, “Königsgäßchen” is not a permissible label as *LATIN +CAPITAL LETTER K* is not allowed (nor are capital letters in general). +UTS 46 will convert this into lower case prior to applying the IDNA +conversion. + +.. code-block:: pycon + + >>> import idna + >>> idna.encode('Königsgäßchen') + ... + idna.core.InvalidCodepoint: Codepoint U+004B at position 1 of 'Königsgäßchen' not allowed + >>> idna.encode('Königsgäßchen', uts46=True) + b'xn--knigsgchen-b4a3dun' + >>> print(idna.decode('xn--knigsgchen-b4a3dun')) + königsgäßchen + +Transitional processing provides conversions to help transition from +the older 2003 standard to the current standard. For example, in the +original IDNA specification, the *LATIN SMALL LETTER SHARP S* (ß) was +converted into two *LATIN SMALL LETTER S* (ss), whereas in the current +IDNA specification this conversion is not performed. + +.. code-block:: pycon + + >>> idna.encode('Königsgäßchen', uts46=True, transitional=True) + 'xn--knigsgsschen-lcb0w' + +Implementers should use transitional processing with caution, only in +rare cases where conversion from legacy labels to current labels must be +performed (i.e. IDNA implementations that pre-date 2008). For typical +applications that just need to convert labels, transitional processing +is unlikely to be beneficial and could produce unexpected incompatible +results. + +``encodings.idna`` Compatibility +++++++++++++++++++++++++++++++++ + +Function calls from the Python built-in ``encodings.idna`` module are +mapped to their IDNA 2008 equivalents using the ``idna.compat`` module. +Simply substitute the ``import`` clause in your code to refer to the new +module name. + +Exceptions +---------- + +All errors raised during the conversion following the specification +should raise an exception derived from the ``idna.IDNAError`` base +class. + +More specific exceptions that may be generated as ``idna.IDNABidiError`` +when the error reflects an illegal combination of left-to-right and +right-to-left characters in a label; ``idna.InvalidCodepoint`` when +a specific codepoint is an illegal character in an IDN label (i.e. +INVALID); and ``idna.InvalidCodepointContext`` when the codepoint is +illegal based on its positional context (i.e. it is CONTEXTO or CONTEXTJ +but the contextual requirements are not satisfied.) + +Building and Diagnostics +------------------------ + +The IDNA and UTS 46 functionality relies upon pre-calculated lookup +tables for performance. These tables are derived from computing against +eligibility criteria in the respective standards. These tables are +computed using the command-line script ``tools/idna-data``. + +This tool will fetch relevant codepoint data from the Unicode repository +and perform the required calculations to identify eligibility. There are +three main modes: + +* ``idna-data make-libdata``. Generates ``idnadata.py`` and + ``uts46data.py``, the pre-calculated lookup tables used for IDNA and + UTS 46 conversions. Implementers who wish to track this library against + a different Unicode version may use this tool to manually generate a + different version of the ``idnadata.py`` and ``uts46data.py`` files. + +* ``idna-data make-table``. Generate a table of the IDNA disposition + (e.g. PVALID, CONTEXTJ, CONTEXTO) in the format found in Appendix + B.1 of RFC 5892 and the pre-computed tables published by `IANA + `_. + +* ``idna-data U+0061``. Prints debugging output on the various + properties associated with an individual Unicode codepoint (in this + case, U+0061), that are used to assess the IDNA and UTS 46 status of a + codepoint. This is helpful in debugging or analysis. + +The tool accepts a number of arguments, described using ``idna-data +-h``. Most notably, the ``--version`` argument allows the specification +of the version of Unicode to be used in computing the table data. For +example, ``idna-data --version 9.0.0 make-libdata`` will generate +library data against Unicode 9.0.0. + + +Additional Notes +---------------- + +* **Packages**. The latest tagged release version is published in the + `Python Package Index `_. + +* **Version support**. This library supports Python 3.6 and higher. + As this library serves as a low-level toolkit for a variety of + applications, many of which strive for broad compatibility with older + Python versions, there is no rush to remove older interpreter support. + Removing support for older versions should be well justified in that the + maintenance burden has become too high. + +* **Python 2**. Python 2 is supported by version 2.x of this library. + Use "idna<3" in your requirements file if you need this library for + a Python 2 application. Be advised that these versions are no longer + actively developed. + +* **Testing**. The library has a test suite based on each rule of the + IDNA specification, as well as tests that are provided as part of the + Unicode Technical Standard 46, `Unicode IDNA Compatibility Processing + `_. + +* **Emoji**. It is an occasional request to support emoji domains in + this library. Encoding of symbols like emoji is expressly prohibited by + the technical standard IDNA 2008 and emoji domains are broadly phased + out across the domain industry due to associated security risks. For + now, applications that need to support these non-compliant labels + may wish to consider trying the encode/decode operation in this library + first, and then falling back to using `encodings.idna`. See `the Github + project `_ for more discussion. + diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/RECORD b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/RECORD new file mode 100644 index 0000000..2faffc5 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/RECORD @@ -0,0 +1,22 @@ +idna-3.8.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4 +idna-3.8.dist-info/LICENSE.md,sha256=pZ8LDvNjWHQQmkRhykT_enDVBpboFHZ7-vch1Mmw2w8,1541 +idna-3.8.dist-info/METADATA,sha256=t8baHZrBTPkJi3Lr8ZHm0pbRKnelgO5AU7EGIeTvEcg,9948 +idna-3.8.dist-info/RECORD,, +idna-3.8.dist-info/WHEEL,sha256=EZbGkh7Ie4PoZfRQ8I0ZuP9VklN_TvcZ6DSE5Uar4z4,81 +idna/__init__.py,sha256=KJQN1eQBr8iIK5SKrJ47lXvxG0BJ7Lm38W4zT0v_8lk,849 +idna/__pycache__/__init__.cpython-312.pyc,, +idna/__pycache__/codec.cpython-312.pyc,, +idna/__pycache__/compat.cpython-312.pyc,, +idna/__pycache__/core.cpython-312.pyc,, +idna/__pycache__/idnadata.cpython-312.pyc,, +idna/__pycache__/intranges.cpython-312.pyc,, +idna/__pycache__/package_data.cpython-312.pyc,, +idna/__pycache__/uts46data.cpython-312.pyc,, +idna/codec.py,sha256=PS6m-XmdST7Wj7J7ulRMakPDt5EBJyYrT3CPtjh-7t4,3426 +idna/compat.py,sha256=0_sOEUMT4CVw9doD3vyRhX80X19PwqFoUBs7gWsFME4,321 +idna/core.py,sha256=OHDXwDVbb3R1gNXjHw7JWeeE2rn2u3a-QV-KCeznYcA,12884 +idna/idnadata.py,sha256=dqRwytzkjIHMBa2R1lYvHDwACenZPt8eGVu1Y8UBE-E,78320 +idna/intranges.py,sha256=YBr4fRYuWH7kTKS2tXlFjM24ZF1Pdvcir-aywniInqg,1881 +idna/package_data.py,sha256=DogtAD5vs_-I2Q0k3_ZA4egUq2YLJ4pBbbhI8APzOcY,21 +idna/py.typed,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0 +idna/uts46data.py,sha256=1KuksWqLuccPXm2uyRVkhfiFLNIhM_H2m4azCcnOqEU,206503 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/WHEEL b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/WHEEL new file mode 100644 index 0000000..3b5e64b --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna-3.8.dist-info/WHEEL @@ -0,0 +1,4 @@ +Wheel-Version: 1.0 +Generator: flit 3.9.0 +Root-Is-Purelib: true +Tag: py3-none-any diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__init__.py new file mode 100644 index 0000000..a40eeaf --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__init__.py @@ -0,0 +1,44 @@ +from .package_data import __version__ +from .core import ( + IDNABidiError, + IDNAError, + InvalidCodepoint, + InvalidCodepointContext, + alabel, + check_bidi, + check_hyphen_ok, + check_initial_combiner, + check_label, + check_nfc, + decode, + encode, + ulabel, + uts46_remap, + valid_contextj, + valid_contexto, + valid_label_length, + valid_string_length, +) +from .intranges import intranges_contain + +__all__ = [ + "IDNABidiError", + "IDNAError", + "InvalidCodepoint", + "InvalidCodepointContext", + "alabel", + "check_bidi", + "check_hyphen_ok", + "check_initial_combiner", + "check_label", + "check_nfc", + "decode", + "encode", + "intranges_contain", + "ulabel", + "uts46_remap", + "valid_contextj", + "valid_contexto", + "valid_label_length", + "valid_string_length", +] diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..434dc0fc73203c7469561e32a74edd76b70db1df GIT binary patch literal 842 zcmbu7J#W-77{~2gE_b`L$foywsvOR#+zNW zp%Ry8X3+{vGR+9bSt-^`Qe~o6Zymxmk*Apna+=xFCZMwYZrdr*R@aA5v7&-hX4JH3 z&6-Bu-pNZdYyUSZF{iT785hj<3^6jCiu0!C^bLcyS z4(`HLeWSEs*C)IN;zAn)lP3pnX+7x6k~Ut z7#~!-oBlIV=37pms|VJ^y|#K~@x22f`~n_bdkOTe!Qc4#7{KKZe;#@7d+NSj@e32= B;|Tx& literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/codec.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/codec.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..5163e213d624e338d0a04b75bddc8ac7326cd947 GIT binary patch literal 4947 zcmd6qO>7&-6@X{CKV1GuBt^-xDA|@|M>3I0a_lNGWGAg1*{Ka#F5)|FXT%A)kdo7`h%4=mxYM49ha(Q6I+NRNl~ zZ-9MFkq!rWg(%V@QJkuj9I$HJxwBozDmOL#Ow$dT9?%?qjAj?p z^nzxG+6lTN578B@x=4`ec7m>t>F#}uZnxrBdz65R{eNexULRB?1f^?Hi1fl7Ny&X% zb<|#ajyO`_!@>JFV`0&h)J#09sHUW-Rvt^m=G2ra<*nRxVtV$-F-o)aJ{p}3^Co{J zQ!vHX^0}01%BORNmd(Ucc`vm7c>Jr2?|l8|Uw{3V-@O?}bvwBlh1v`hmWfItoI)ZF z#i?*AuQ=e(tAZ-3Qo_MLMpA@D5jFv~i_LbvtzCq6xgdpQQ+yf5A2$UhX2jrgaHzT| zQPs%POuVt$ta}k8KG!H4MA4yeKYf7^8ZsKYhrljOw!gt%Bc$lC=g!XG;fkEj6?g+} zvQ*^kHp98KF5x&s!osX6=?2x}#)DmFGkQLk%ThyC2HB7YFT^rRO3R!d9R9_^@O4KG zjZhgxSfFUploDB*ju{jOX!0pFbDcK@T}>ruC#w2D=-4(mIQZbX2_v1G$Z5GTBSz1w z#@M``rSr-pok(eO6S;zMA)A@dluT>_7d<|nD=@S3UN)EG)}BDW)~7&RBvntKbna8n zjyqlbD+AwK8#rDWIDYfzs{^yEU8h&Pr~l~-R)c-_d_5)Q-QtI5u6BR$qZQxCiabJl z;PwBrMW9_UCK?2B-C=H+V!91m&_QW03Pg=Pr8H!>*^^{B4BB~uN!tFXNtz9FY+zxR zDMzE3SXzxnO?Nb!&MNs7mc7yF&+@TUqlJf!L~(&kajsyfy2)!9YiqFaUngwltw95o z2}OasNq+^zBKbyeilgNN>jbiEJj*_ryxDV$zZt3=nyF#+H(jVQX{qeCRLc>qtfaS(0J-sb8Gb9U9)aCcb|fnDg%PP6MoCQj9~nlWOjV~kC- zwZTm>p#f~DA1uckBxU{LNrRie_7ir}JQd$=+D|q;n)Ss*%ik9SMOYAv0_`peiir5q zB}Kv-MSPKDTt!}YT4m62V9R;3ASuoTsGTNnK1axcT$GYFB3oS$!(%@bWt%Q`&XJ;% zibba)&%*+MEvJDC!BR`xYJ2a10B2$n39%^^CEH$6oQJjr*9JSybG6Y2v@(*pW?N1~ zyWu^y6Yl>9QVm%;&cH<-Pz=kAUd**je>9)bkT_8#Yv@s`nxdXdX@)7qayd1lP{b+o zJyS?#wM^JeaXwq?PeE!KTUv>9rY36Pq2ygiOOG34$|KCJ#?OHlk z^>$r8b?MZHBUgJq82ik-_cq|y-(BXexJp9R>wo{{viRGR74ObV)9WsHVZD=VA6PD2 zDO}yQ+PnAK;Y#ldOWvyNeV;GQtony4@(>vJ^_O2;@eQrWLu@T)!!C+35#5Di5XBG( zQ<%$UQw%&510lK_#UzS7C=mA+bTIUxC@==o$3QHSb;nL|_$ojLvOfTHAp2yRWjD{> znp}DH?5(NFvDfQZZ&||kp8zcaL=hsOMS@u3f1zcXg*$C%VO#4lU@1R6u(SmY27-&F z8|W>NbZ>hAp$K;U0%st((N}30 z!~?D!O71o&xiwwO=te9PSJ@t?&*D26W>eg@6j#WK2k<<5IFjfDDq+}7f#-zoM{xjz z>23fB&g;kH#|kGl;HR-ioA|L*UIMfFzd(FD{DkiL`pSEL&wu9Ib0@g1WR%}n4L-9p zeQyht`Zhvo_)$2eA&ti}2TRg^@{v7Ly=DCP9Wwf()2+VC9ErZXNt9L_6?oAqijKfFwNc zFx9*uTG38{3p-5j8H1{^^cz$&R62W|-;C5v%=|uBpeSPSuOTHCNmY=oj}E3Px|NG6f7XEg0J02h{{;n}>hxV-U-v2={q*gW?LLb%#ne zKn5z!R3xpN(v3!KvWdQ?+QYP(&}-AOBTQo8q_bq;CCDmaaLCd}jvI~04Q^ljtSRG- zXaBx^2g6Q!3^drChsDcgm)43ptw4ZosIy#;nqKf@SkbrGirP<51JewVyToo&y6Ixq zs1q5uu^~lU{jd{}Z9%rqZ2lqe$HC}0(Sue@;?va_jbDf+@|ieZujwqbX{dxN34ZVN zEX{xF?5p~McRYbLPk+VJU+oCo@pZrZ*5$V^z1=GGkKKV^&k+3TKG`d+6IqnlLWlcI zA)cjb+u(4=S-8V#qcb2(2Lx%7QOH4*MVYfP7sK<%bjGvkoR(58VB&|Gp`$F8QkAVi z6#MjtDl{;+X<96=K7|9puQz3?p4W8nqfHz6fqdAyBfUgl2R)oc{f{8ld5+`0B!@mH zhrS>kUl7-qWVAv??*@02_AgIenOfO7wHiFMLi}~1iyK`!etG87Or1cnzIPWlT;8_U zH&yAIsuOsqALWMHtKgyj1F-HYO_oR2LSvQCSe?LQUEW%^E_*ns4A&>fuI|0|{MxgJ dD)1XVT*I365aIk6rC<4e=_~m@hvi2X{4bGy3fcew literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/compat.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/compat.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..bcbbb913817c4f62ccc56d2e499071bd00bf2712 GIT binary patch literal 848 zcmb7Bzi$&U6t;6e@{908DWVlB+yKKtORAzs41g2?LnL}j(ru{OEQOM}7|_CUr$ zrie_LmAJtyR>r!5btNmi)iYE;T&n1UGkvvNP(~}xlywvbB34%D_jssm;Bp9YU+-Oq zfk2PtCZ@8s_okY4&i5NKN*YO!>`EVwx!fJ40!FL} zjWFmnl1!e6xDl|}Z}df!`0`PbsbWX84qvp}a1~ovIF?s1y(RPNjq&{t&t~T45^M7R zIzj)4R?4_m3cBq|C)5zCaz~&cIaSBHgafYWbX~JF_5STjM%UK7qi(?)?X+KdEoXmk z?}@_%Pn}puXDEX(NVyaH5l?_8P69%Tz6eoX-4n7MB_WS^EIE4xAi$-tfg=7^TUwum zTgX&3s|`b+D%-O=uYXhyX68XI-K{FKFMumczpbxqnI%Dd4BA_;F)1UJpsZddd78Vf z${PCseg@i#{EF$yh}^65($h$=VaT7uUF7v=ryWcSgHk#t^*P!2NwyazrCa023xd<6 nxzy9b)=Ni|=0|sS`{DPSJ30BKeo1WZi39MwXm=uK_!9 z$6-=4B27(1m@SkFwX1BiGp5tK%WQYeGP|=|*-6z@SMB_eET=4PYigNl_6NU4#QexI zwX=K9cOR0C^Xl!c+FPaXyWjhK=bm%EbIy14-yMz$3Z9#r|88_}4@Lb33+m%gURHP= z^q^RZr6bfNJw($Kt7G*M-H?vt`XN2Z4MPUV4H4s{X~;Bb9x_8eiZw-!X2!8t$EE440CYlB)l=hAB3q}Bno&azq$ zsdYiEyR6pBdN?2J<$R+C*7v?)s1nM4wi13`u4>f8`k}6xts>ox#jWTb(ug_gQCEp=R#GH*S!*0Z~z-On~?wHx0z4mFTET;0HKf?gZT z$_$h@$z@g#?Tt`oNV$nXgb+7FU86EH)^1j2x3DcRdlU3Faejcdc~mb$OJ>>vqc$rm z;Xb!Qx#iiuWY4Y8wuRlp1_1VLF#C40f`8P)?tm4xvK@e*)oZjtkDc%<^{yGUv+dBk zmEHTTy%Eb5>@MgTn9&FJJwkd2(2^z0MuTin3_e0i=nv>5e2+G={P#(47 zhN_zsM-9;|1@ui1>1T8Sy<|Pv)8BQB=VScr0p@5>;27?5h$E{rqcNTdMj{M$Y2%`y z7#og`F+3LuiX6*K@v)HzHz_dvcMOtccsLrI`M+BTfS)MPecH+2AY6!e)`*{=yv&^~Zg=p+jlnIRo`Cv%oc*NOs zG>iyEQ4=sqwz8sR4aFu$!cpLCNgo>LB?EG+RPjnMGR+aL26r?Anxd zZMv;bAN{F$$<Rr+C>@~;jl0)cjC7~ zBmRVqkN^&B^|uDn-cSDE_W1Ia{n;)1?_SJqIh3;<&KM5MJEVnGB!?^FZ)GziH>o%^ zp%EQaC=W}kA0I&0^-Gqi>F5l8UpOsHL{4*eXdbAI5^%Kg!K}k-H@*#Ow_!8NqnDNJ_R2CvaLRAt53aD29acp1V^~Y`hX$rmD55A7~s1e;5&Lo2Pdzg|IuOS z**kcLmh=%W3TWDm>z0A!C4y#{tThZ>#>8>{0Q4dKWcUi^ip0J@oJ}6R@^0Q$nYX#* zPico^IvfE;f@5wq$!cE}k-k2dahiuiIZCrS1zi1%Az_qzgci+v%AvQ0#<|di;fTnu;x;^F z2|?ZiE&*Mcp3{{iSRC|am3w-qH%?L1>(FaXKW8ZM;)DTaSo6dUDgnYFcuoFR zcs23I0bbihny)Q`)4m>@fJJ4;YEH1|P&}=0{{CLH z^(cv&-K`#wWtv@BoWWC)@I3R*91|3oshAK(wGWD*CDSiUx~|jk>mMY?EO6lwn2ztl zIqB20FZ70aK`d8V%4VCKhNck?bTUnq#05|9U|vS$tm|~3qBI+S6sOc3>xbWfr0a&? zu|Y|97RpEaC4K+Enc3rtB2}7@XzC@6X*Kw`vmnEV$Hv7rG1eC0Mn!q2aMWp=;6X-G zWNjX}7^MutL276BbO)nE)twAqW}?%R93PA@;>;8$eDl;6zFQs7AH%m^Opar60+W-N z;7Y&UZg3O08L}&7H@ec2v%5~?QNeIgR$wlL#c?JaiEv{8b_q$Vzed0$Svh%cpfc41 zV3K2%@-OT0?bu-8xhXzimF4gYSW|&rq$~P3Nfxo~rp%1^>p>bUK*xw|+&Lj2o|76TZYq zp>or5Wm~qgZDAx=xjSLa+bUDK4-P-{ZpttN%gj)g8CrU6IP(^ldu=o`ej&$1a^A^| zeG>X*Y66S4Kz>8R)l)?WO!(MI*{ePd=Uu)hCdyO4><(nzfrXa4^qtn6yJP-j-t12H zWzC!NPVZHH-s(+;7OfldPTy7iLuXy4{*Db1Gw*df=;> zKb`kh&G(h>pw8H`{to`Z=6v9*&oHlNeXkd)nlqaxmp6;q&0=Qya&GfXu4*>po_*k| z$<%jbT^;#N&DZUDPi=}@^fc!;ZBE*uDRp|$)q20WDc`jHdf$WUrgS)0-Co$ZJ+tGj z+{R$0CRj94l?@r@#jNkeZ&@MLmvwC|Es!G%T(=hw0O*f9DSJ%;x80v}p3PX!K2UUm zRmut;gyblF1zyUvfc4A?I9g@pR1wT_3A6(=B5Wlyfz?F!6`E)aL_SIM8I=b{xUq0l z;R4{}5+f+ed&y834CrObx1gms7ULCzdp}Yhf}tpqRWfCQ%^-$@5ycGPc>Y!BavA%g zDu>F3ciCK*HP@w%r5is!ku$fXgIROyLieJ%z2L0Q)SSvW`!be3RexHAE5sAQ)m!j_ zdN2!`Q7xsY3bxWw$!e+u99iI$BhDZbVo9(-nH=XVDFfCNT!M2;bIAeLtbvODM|e6s z!Y?$dYipa`E6b1Zpipi}kIzhjQ-Dal4xVL#QI^>YvPC^A2}Uc3gQk)sohI97qd`wcALK?wqqHW9eBJ>l%fghWWpXLRrAKs(i&M zq8yadWto9GgXSrmUA^72EoE4NBN2|KezXiC;aPB_z-ikHC8k>?L~B%OChX{%FwE^q`A_mj28R0Y=fK0$S4YRWgGezxMyd zjw{sNedCUe@{Z&B0g8tG4p6x30kA|^8^K}g@0MC-j5Ef7y+3Sc;CMhbChG2BFaHL- zOY|VojU>8fhWX%RaIH^AG7`_T>qO|-23Oz&AA|Ovz)y$( zi@_P<@+SACeAhdF^6vbJ2WD4tf6lz&fz6rpd~l#Z+(*Y2nn5Mm`e}cT>BzbEEHF;0N?dEjor>#HlzN`Q2M5b|H*0V3~-;mVZ zcl-ar?Js&@&c~IM+ne{*tX>ryUoD?Z(MxIx zp5Q?EUU&i*K+!_E{jw;uYR>-<3PAPITyB5zT>?=b2h*4kcn_LiRlQ5AcdV*+YxVTCoq%(r0ib3*aXtA~weYQstoH)u&G=2C41od4 zb8xj-hIdWx(#DzDN*o79c@2I`nz~jGa~oOTs<}xYd2YZK?oXcE^Br>&nAXlsO#4Uw z5pZ7;dXFMd9PABG0|iUQ<2=V*2(JJIho3+qnNDycJa;MlPrE1zdr-gm!~ZN7w}DgA{Y(71@bB!#soNy3jZ%iKsOPfz`XsyfJoPX*|p1V<- z>bhRPXhZqN{dC*H+y8oJ!Pk)D(%lPx-gdW?a$cvmyJwaUf935X*WzjB=D-< z<2m1fjQv1a@4UDAE6QN4PaFjqm3;MsAA>k8xHhDkQWHzAz|V*7>F%9cYCHaSotal& z%?u5H+4t7{>bjy8MieVxe-EtAWb2Z(ImLZxZ6OOxdQjA z>mTbW_qL)Q+7UCbQFSB?FWM=)r)Z;mHD6KRdjgyLSuZ%cACY2K(vYrJ3q?f&fck=m zFL_2a*C_7+KfdOgQrp1_(fs&xROxD`Og^gCp62*0xAsI$u`7+B*HxdO79IWMS=ATa z*=uThK$U&NuQ(jh*$eMVA5EhNwXIsK)r;s`CeH+L^4f=$)k_6GJbi7~4;V|VIaOZq zhpm*@pw5pnSZxt@i<{JX)-=(mzL#>bS$!|LIzcL%XQ5g|b|y~=H>!%Qs(DxFYuA1N z+*WcHse3*o21+ZGpaxw0Wf|NRzaO~8?dsaB?f0{SffCW+Cr=53Z~{=xl($&yka1)^==i3Z1U#7nDpdzS4F2WRGO&KHEQd z?A5_jv)fLAZVPv%;QU2nUA;Sh)|2|q9MP<2pI6<;C68i|od|{?Hh>Xh3@W|ybn8u_ zEqwNATeo%}|2@{8UEO`n+_BL$@CT};im(9gA2ApWaguRlM&ty^idm57gENwe*!52z)T&XCUqzz7LD!yhHgV+W{VJ%ksr9ClIxrT(k4&Atm>D{26>>Fu`Mvgc9)R z$ON}DxxoryEiwu@FG)BH9+mP*X;W^a@N@C+L#K!E6aK4wOqxB(mRl{iH)J+!Uo!6i zb@-1t%`Q_fA#PF(Ocrdt+#U;5e#Rc)D_Z!GU* zvpd-(ZX$C*$Z=xk;!I}to$SSTo`7qJKB_BHRJZPgZUsvxF>61CX>}jAc=~h?y-k_s zmzSH*XPeJ24S_3oJU0~1T!?03Q`rksOZ>&mrFf2?%QgQv=Y2P0f4A6(n0d09GP)Ae zUmE;hKk-qO8{s5{-By8D`ORg9%Q9S{azm>1#@Y11g6Gq7KkvEg|Ev%8*!UyZV|6F& z(bEa1v!nB=V2AJcHwRzn_3HlCd+@l!xXSB?XD2yfVKZ>TTEFxDd#+rg*G^NAGpKlx z2js0{Q>?lk(#|qDd;%nu=0pKW1#XJ-RMeo#l9JRamv16&g*@xIEbwFj=zbs^=qED< zg-|#=>y$lZVl2i)V$m@$*HMy7rs)Xb3AkyKL!l%ugp46a9>V}FIb?%yjN}{+lD@-J zJU1G?Om6+}$k)e`O>Q9qVbwLVNgl&rgZTjsln{rPd8(*08y)$ox|@;fk@SIF)%Jv~ zU~wkiS+dj>T#f1NORk*-FZjQAU9dHLMbSpbeT%)Qhx{pAB^cdF z>C2sxpQu0sTQ&I`&h4Y3o67F>bpvW zd>0s@KDGAQc9yCovjMScir4B`p9xL%QfDbwBw0BcQZ|#fmd#;QA-F=9k+a4e;G?3y zedYmV$MyS|)VV>8)eiV_R*8dYyoSZx<;uY7z9HRt=&v##jMEfMU`;!WD`7_SOJ1SX z{sBur|3`qD*?nh%5ez$l2)C{_Lhd`@Y-e6nVr3XE5*`af1S8xDg7XQE?a|nDlqC)` z{&k$7Ng2jyKKy4~_xv{O=u$6al>q?<|1Q+?^O(Gc39>Gqzy!}Sh-87tJYK4RbD0+f zyrAT-V>c(1*)k!ESbyvoSoA{{X7WS(X1|?1)Jf@+mSa1|0d5+%4|*`AkFml5JN} zXMjt&+D-pz$HzO;mvXi3SNp)Us;*Di9(Ws;z0Fx~bI#i`-{qIGxou}t!mlUkOiI{%h|T1`K)al#FN-|lRigs z-mZ+j>!HP$>|3%hAPSaUjad*9TXU{$8Oye!L2ulich@buo3ievbZ5@JGhr+VhP=%^ zfBNeuZIrtS?X?XBdv(gVWZwwhwGU1gjZpJXPqx5y8w!@~#G@a`Imx^rVYWXN&_YOg zx*gQtw0pV()EADb?k)N+T4+oI{_aD1P2OL8ZOfvIx%6%!0W$TEqR23z3V z;K1Jf7%m;+1W?Aub`lE$qT;O6qOf;A24(UXmG%g33cy!C)c*+SjUR$UqF>=hN#4P~ zLh_S5UI6lMK>}h1$c!rK=#pt9EI_ofWRr7<0vnZG^isviD9c?Y@tm?IzD7^ShzCB1 zliK*}`2Gbz_)BAWIgq6FzncA~waKI4wvv2$G0^ zIYfe`k%x#IOimOPpNtuXc&WapoO2)fe0SE}^H@*U z^wNnF5Bv?O;PuxMz4_XWi9WnsceBF87l=swUJgp0(_w+xT)Ve4ypT@D<_N==F`&FkpK58gbF*hO^ zchlF!7TCy>U6j3g*~VmTOxnL-%Gug8hW4+Y*eG}HSCrm*u;6XVyALnBd$aD|g4>^* z$hjNS9iUks0L{AUv(unidpcM2I^V$}=-~&8dKe>X)_-=?(5=&bp*z_9f)PIj9|mdw zGZ@G$q^Y8SYE5VQXF&Hi=}aoi2@Y_)AW4!3uj18~Ik?Z_9p$bo5K{(~edbU=8po(P z6Nm>dxWJGM);y)_`#E#eUs9>p>sw+_h(I%gh%vLqG5NBgJn~BuvY^_Vl>h)Eah)5n z`~qD5!|kRSg!Fb0YL+tPT@#nEFA5+wttU)MP=JHGsdPijYB!!&@P^X}PQP`>v)bJu z93Zv{O&2U7Ca&!O^r(j1DubX*vZ zO-JB=9T3aS1l5pnRic3$L-{s39VP#UVE7;ud8mV!k|2Y2gwk_o?^Ajwk!Mfsvd=|6 zZi!+w_*C)3$VLpx>J^|sYUix0haAe_J5lT%8_}U8JrJ>G;`9)2g)GI0nuKCQG73|X zum}O^N?1FF-wGgChz%o|f>TqVw@C(c$?(s^00`Y`g^d3*O#U2`lCXOYiuhjuVLBp8 zCIY2E+!eyJAzHFl2Sh{-pycuq$%P77@Ro1M)=<>xtz&cnT=ZSZOE+AJuE!?I;y`tV zPIac^Is4uO4N46JL!qR*Z+7H8-ka6et5d!k^;b;~J&ntrty$031v=;1mN4D7f$u)8 zONk%7iGB@d&bc*X*_t;y5+m=;CSP7OSLf~Cr!WO-fbECwxSJsKDJYq%Dlz-q2sC}8CtT`<}LOQtyitd zEji1E`L2R(W9senjwPEMx}&IEBvSwDC;N!5M&oYL2IO+y(Tsf*EIz1tDj?T?WbfWe zeX-Tw{k%S;Q76=Ea_Db~90ECm)Igp%RdT9pbZ`IuatK`Iip(N%$N+N42r5mLh=fC) z^(?v)cSC$Hy6rV5yE+Q2E$!+HB%2B3km)<+kV%$9a486HL;`_QrAQ!inFP|*6GZ|U z{~sif0VL46<5|rX1PNqVR|080ehYb0p~#aO%_WLbORmOm;^66=y=@f-+dPF;OncSzpv2MN$icwZ zO&@gr4w-jk$pV*#PV$eA-khy2W2pQ3Njqf+ryULZ!pOTlIcG=4(t$piy)uJdsqeN? zU)cQJj6Oj326ThH0Yfi50X-($^f{E0RCb z@MGA5)~#fQKMYNUBb@vtlUPr_ZY91|VS`-wqETa)%D6l6~-@cm@j`%LLQ6(;Y+3M1`E`HB=|Y2ONFMJG)kp_3ip zMuj}Bm-7V!_*S7@G|@DZgaMGH{8-13s>A@PN)E_X7Cr5TtKDM@9qCiqjqOEn?z!*w ztYB8OW7~B4+(LJHD7$GFY5UwjvR_q_E|2Zc(e7lZNI{lnNp@FU!BX)e4WrY|r1!#R zWkMrN2=GFd-iv#17u`C#i%tSen5PC;NM5YiLHkoM7P53V$rb=6C_R3Y-b#D02{LSg z>~0UqK8L|jDh|^1bX9UXH307M4Vi{L*=kr3s_p?|AS)hn)743s0J2mIIQZ%6;+9$( zt`1Uq2nsxzscFl4cNQtAy4$gW+2hUzdRIzcq##?UB-!V%B$P7eUR}Zb@ez6>4L1qN z?vy`m%~S@m&TT~sst`2Deg&f-%Y?>AUZkiax*l-6Lmj-oq} Va2m*P8py~rn2VR5V3`o;{{{_)l1tj8WlAd(*+U2+Ns=gpBne4K zLK2dYgb+fv+YyTb zESC6^A^yK~m0!n|=5jT;VX3tb55{x zuuHIOFgMsO*ge=Im>29B>=o=C>=W!8>=*2h;Vb2bc|dSra8Ph?a7b`ya9FS)cusJ5 z@Z8{t;CaE3!BN4{7{1c^VIC8_AUHO7VQ^gVqF@xfI5<9dNpM1NVsKJ$a&SuUQVd^d zYM3tzP76*C&Iry776xYpX9q72&I!&9&I`^DE(k6RUV-5&T^Z)0;G*DF!K;IdgVzMF z4PF<#K6pd$#^6oCCBd76w*+s+@RgQ^`L^Kg!8?M>f_Db*3f>)D9=s=bZ}7h0is1dh zmB9yst1x_}2gAHN_)u_7@ZsRv;3L6x!AFCS1=j~R1RoDR5qvVZG58dQuk>`7p9yXX zJ{#N|d@i^p_9sJw9&YhQ=(|FHGxXh| zzZKjQd^`9~@ZE5my}|c_`-1O>kM0kCfZ;2B80L?H2ZA354+cL89twUM{4Dr+@No2n zt^G*oUj~l`zY2aG{075UIu_<{!&<%z{rlkY@M!!H{4w}b@I>(E;4i^ngC~Rk3H}!R zZ}4{vU+Ir9{~7!%cq;gJ@SotnxU^W5P!?k?Hm50z>v)p&+VK*~bY)7Jq0A)t>UP_b zx{p%I(#kT*vdVJG^2!Rz)0C$xD=N=WR#H}0R#Bd*tor}0LuDgnV`URkk4u);*Hqa|*<9H|*;3g`*;<*cY@=+eY^Q9m?4azZ z?4-;gwU*90)nXBxk?5^yg%v1JM_EPp%_EGj#_EYv(<|_w~TFXEk8>Aep9HJbm z$8wnF0_8b6K3sXOa)k0co$v(*C?;m z?XFW^ue?Edqw*%*eu?sCl`994n zG~cgzrRE2et8_d()7qasJlAS1;ThMCh38z$@T_YYo_8(7Gp}WM?zIfhzLw$n*D^c< zTZZRg%kV608J>qN!!xmEcrLaK&&HPFx!5v18*44$IoXbdXJyOqylfesnJvR}vt@X8 zwhYhDmf;!Na-05~FY3?zlJaHccI7L|9m-dgJ4vnOH607j;db9|Xx^o-@uqUO@-2OQ zkMeEhJIZ&JdzJ4g_bK03?pOZr8Q#8jc#gLW&+?YxdEPQS(_0?Y8a`2m=X*OIp7AX| z(|vxfJgnP&q4|jBFO^{zV4oNE0hVDWpvUDK-R79`Tir+45!h|N*L+<0gYrjZ*c;gG z!tTH_><=u%4#6_)5iG+l!7}U6V`0Bw`KP|dU&>R;zm@+e{|%XD zdk6b|FHN(5OM3d=fqz%}oK%)jrYlp*3^J@G&Hml#pW}Onw5XKk(#kT*vP$1Oq($X5 zS5W%iAuT#xb48`^9nvD-JETRvcSwtT?~rEyD*eB;RMqF474|@BQ8ne+%IeA*%9_er z%G%00%DU_m?QyE7xxTW2vZ1n(vN5U0rHPJZDVr*rDVr->C|fF9DO)SEm2H%5mF<-6 zl^v8Fm7Vx|s&aj8LAZ9H|_o z^u0q`bUw4zGDi39dxx}WtY+Ukq($R2U!?TCLt5l}hqTD|4r$RP`uGIpMCByqWaSj) zrOK(K)^eGSO;b)+&QQ+O-^D`ZEahzd`7T$^QO;G)Q_fc|(ETmc<9CHJ{0m!a3Ht~8 zdmsL#ZRvZ5G}}AyZ;!Mn{CnH-8r|o$%IlQZD{oNVsJuzJM0vCF7NzeU(xRoTQERzP z>%Cp+dxx~h_YP^%ojQJ(@^0PNa^*eBdzJSoeeaMK`Q9NdTB+j?C|4;TB(;{+I`)uq zjq+jTTID0kb;?JTk15wHHz9a?~vwu2dyRSAMAVJdxtdb9n!RS zNYmaSO?!tl?H$szcSzITAJ9X?e@>-`^x>K*7AXleW?6Mc|iHG@}Tk)YJ4r$suq-pPvroBU&_6}*< zJEUpvkmh>_ttIRq?EC6_hcxXS(roYG-~VvF!9E_&I9UFzR6_-q_UK~|&^L+16Jo3Fm z@yPcM#UtN46pwuGP&^8I2d$-(J~v0%S=mL|Rhg^ortGflq0CeERQ6K#R`yZ$RrXW% zC$*M*9UGt=s2rpmtQ?{osvM>)Q2O4Xc;tJB;?cP}K0=FEmL*uGUYVobma`?Ol6^RmU6c8a^)Q5 zT;)9FeB}b=Lgf{t)^eqe6)6`fuToyET&%oCd9Cs~<@L%Nls77GQZ7;6th_~eE2*_C z)v?=@w=3^ZE>qsAyi0kva=G#z<-N-Llq;0?D_1HXP_81imIrlgwelh58s)>vwaQ17 z>y(cwA5*SZZcsk1d_wu8a-;GoQfqly$DUDcQa-EPtb9(nMftpPtMUcqHsy=Tmy|Cn zw<}*!?jW_6S9NTs@-^k_$~Tm|ly53`E8kM?QNFEwNBORDuktDbrGZP{6YDn z@+aj9<lscS!2ILo)L74#~*RJ0x}9A?fEGv=%@2ko0p8wkALCkc`d>`}w5p9qiu>cKmE* zb!81@O=T@*ZDk#0U1dFGePsh>LsDyLq+^YhO_W*6rpji@=E@ezmdaMj*2-*U8)aK% zJ7s%i2U2V4sAHX!e%>J&`FV$Acl{1txm4(V#NMd zq^?;cb; z4oRJNNb0;pQs*6#k?$RnI`5Fwd52`=dxxaG&cGfgttIRq>}&hpAsPAJAsPAJAsPAJ zA!*kv{IT`DLo)KcLo)KcLo)KcLo)KcLo)KcLo)KcLo)KcLo)KcLo)KcLoy0`2dyRS zA8akYcSuIQcSzbb3;)`_cSzbb3!i=OkhE(SKKtGw8TsBJY1b_LxbGd3k?$Rnk?$Rn zk?$Rn_NoQHUD!KlEn)v)Yw^89(ym+hZG7*LjC}8qjC}8qjC}8qv}+cAJKsAbBi}nD zBi}nDBi}nDb>1PV^A1U!cS!2IL(1Nv`Q9O^ z^A1U!cSuIQcSuIQcPOE~LkaC2N@(v;LVJf2+B=l6*E`ssDXhg_As7C9CHxg~OYI|? zeeY1hUhlx4zl2@0@GPw?qb#c|r!23mpgc`^y0W733}q!!YpJYbRg`Bct18b@R#Tp> ztgft~tf{P}tgWo0tgEc2tgmc9YAp?QtdX*@vWYTF*;Ls~*<9H|*;3g`*;<*cY@=+e zY^Q8bYAqdftfR7%GDq22*+tn^nXBxk?5^yg%v1JM_EPp%_EGjFwU&N5)?b;g9H1Pi z9Hbnq9HJbm9HuN#o}(PDJXbkFd7g44skMyKvC+!&m1C3_D946$tHPdQ(?fYe$R z>ev;^E0smcMarv`S1T7QuTfsByiR$&@&@IN%A1r+lsA)F%Pl%~t8%IGHs$TgJCw_m zcPj5v-mP4&yhnMj@;>DX<^9T)q}K9)j;&HYs9ddlNV!J&uyU>P5#>7NqsqsW>y;an zk1L;0K1pgV8+Gg{<iQ*Kc{uiUD9LAg!&qVgr>%gXJf*7Ayu?NGj| z+^Kv``MUBADc?q{mKuNABKHw3BBH-gkJAZ zLa%oyVS5Mm)Fq-%l!ug`DnC+9#ej+{7(73^0@K` z<&VmrlqZxwD}Pb`N@^`9b?iUN-<1DV{;vE(`KR(Ppsi0OdgCAmw1?5am$iFlB-A9OZE3xyljB^OPe= zt!0#sjaHto9HYEIIaYb0a-8xaWu&}VIbL~*a)NTAa*}c~skKbeu}hUxm6s`}DW@xE zC}%1Qm9vzym6t2$DCa8YDd#H}kXp+^9lJt#rLsu5NO_g=YUN_(HOgz1*D0@8-k`iu zd6RO9@@7(NxkblrRW4QDro3H0aqdtqQ{Jh(OL=#A#Y4KCaj;iQ*v|-mm1Me|aq#)R z|NX>Tp(FlUhje?bL;U)RbUW|hxAxacrrS9O|GBqX`H*sr^5Os8>slRoM7d7suXaec zvkrbw>-7~jXntJzg!0M%Z#5fr+o$wcJgt02x80DoJ_YwwV5=Ng={oO_uJaD*I`5FK^A71c z?~tzZ4(U4YkZ$K4{A>8$A>Gb9FsE$qz;`dDy+cZShm`gXssC^9kkZ~ErM*MS&O7*h zWGFM0C6%R=rIlrrWtHWW<&_nbr-lD2Qg+S4eyZ5odoZQucZWd)&g`-ITrN z!5@c)%0|k@$|lMzWm9D{WpiZmBUtYc1{dIpMm6 zJq{i9=L)Zvv^hs}XWg!g=B~}*Gi_M9-8x%J(a!mdA*f=IIgwy)vsF zdkC#2>?785GlRWBIWP2&|1Pi!q(z@h?L%Kk75oS zz0)G4cUq+MPK%V@X_3-9EmC@?Mar&P_}aoALTd^82>V*The$=fhe$=fhe$=fhe+ww zk}17fGNo5bru1sbl)YNg@7wnfsmS*bsmS*bDP6TlMZSkf>8eF43VR5xCF~8eFaS1nSyYLU`aisA_+o<&YLrPaIQo3r9(p8I;u3DsY z)gq;<7Aak|Na?CYN>?pXx@wWqRg09aTBLNtw3h8!!z;=i%2$;;m9HsZSH7X# zrF>JlTlto9kMeEhJIZ&Jdr7V3JssPpd|$a=`GN97exx;f0Vx| z|Ev66`G@jPo4)gr7VLsu>`{L01B3|+Oz&{c~J zUA4&Yclg`KOX|K$DN8HMD9b9#Da$J>D1G;kq1{7;a!5(W{YYk;hWi4fGWgTT*Wj#`Bsjp)Vlns@Ql#P{5lv&EA z%4W*u$`;C&%2rC>J!EM2kfGf}hVLGXYYAus=Y_f8S@>1ngog z%IV4(%9+YSksb%DKvUq}DQD#}+6TDz8vpsVq`1QeLIJTDe$xjq+OMb;|3N zHz;pZ-b89GOLXjJ_k za+UHyVDc@J_SAL-UQ2CMafbwJILFFgPL&{H;pD90A9wxPxFLdmP@=N7WIr~F=dT=|3YN99k-6Uv`St>qUT`&D^T`5)zP%Ks{VSN@^=Q~8(jl=5%o zKgxeYW@_({sl7v{?;XNgGJXHBG*f$rOzj;qwRgzW-XT+ahfM7qGPQTe)U}IDUAxG% zS4-NT)9$aVvYfKKvV!t7<>{o>Qc=gwP*ze_R#s7-sjR9zOIb~Mwz9gihO(xzma?|8 zjytjEM-$=Gi7sS3uQ}XD`jhCwz3VWwY1f-cFOk34$6+o zPRbl*XJr>cl{1txm4(V#%Gt`xm2;GHNv&m`j?GstP%cznp}bOAq+F!DN_n+% zvGN+_waV+1*DG&O-biXKH|f|C<;}`ll(#CEDsNNXuDnCJOnImBF6G_I<;r`M_bTrr zwU!k+cE56^@&V;4<%7!A%7>I|ln*P{Dj!j4BaBjo|*$I63Bf5k(lu3BX3H#}tOszs(> zwa{Ap%0;HGTx9z1d9vp=ziN@Gs}`BMYLTg{7MZ$gk*TW|nf7W)&RS>cszs)L!$YR7 zT4d^~MW(%4(r@QiEi&!ZlJObdOkKIiv{y{}ZNilcyH9_`L#AD|@ZGElTRDMM>K`aGxdh8y-sPw?mcGZ+Iwadk6oxU$rQycUqLxJ1t7;ofakaPK%QM zP7AH&bbW3`$4JmpB`DCKD7`N}cM3zTD(7b?doFH%OzibEsd{DVs`H*sr@?qs#67n(}q!8_HeEHcxv`J3{;%HNfLDF0Oc zr97qlTltUj-;kyJyhB(^DV=*LrRx@@bl#zq&O4OSd52Ou?@&tT9ZKoELn)niD5dib zrF7n*l+HVp(s_qcI`2@*_73(qEG=bw2hR$m)^eJTovy5?JVRMYSy@>{d8V?e@+@UF z<=M*W${Na=%38|Wq}EbL$LcEUDeEg6C>tspDH|)BD6^DJmCcmRl`WJlm93PmNv$PY z$J!{{D%&aBD?2DVDmy82l%17blwFm%%5KW;${xx*Qfuj{W4)BUm3@?bmHm|cmHEm6 z%7My3%E8JZ%Av|($^zv%q}DQA$IexbP@bn8sT`#otvp{jMtOm9tnxzTIORpkNO`ex zJgK!@qGJ=36P1&cla*7Hmnx?!FH=raPFK!Q&QumEXDMeZFDD-^HZslr+nQtln`{4@ zXaAeOqWH+-OH0jN&~Ra?L}Ffg%QnqgHfzzS?vtH%qC?PWrpV|BmRE36*#T4eQ< z*K4enFB@)qoz*H{Z?am`>&;eMcwKF^z1JgFmv~Ji?W>gw_t50*L}GbisN<{_&I)xh zN4;*hdTMq!TB(MubU~=qt&a8D%W9F=fmUlSJZ@hoF~Vx@!f@M>RwJ*YtxoYe#%iJ0 zE37W?`mEK&72(rfvwFbmeydfk3`Y-H9pUwa)k3fTvAWCazg7=iImP~ji3YXoPmwH^ z2*da$#S+V!mhj=$Vrhv)i3}eew4o?nL$9H>`aWe7jVguDy0@9#Pe+=aV;dI7LyirHZ8*;Awhu4{>vIw{i`h3S%@;Ivo()mThl4h3 zpQz#JWoe1)yO#1h_{E0p@o>0)3A?-U{*jLDY^ZjI57pb-aK47s14|@|#%lOta*4$D zj+OjoW2V~Byt04M>htV###Z)^^go?nj$g%xjdju!xdW;s8fAuW$1b~FUZvxF$G^9l zTR9y4kJW9J!volEez8R16fM8A4Ts~Qs|~-$Lw6ezm+EFcZ73ZNgKel{L!ey0?;&l(Vp}^K1?rnk%OKoUW;$Vs1GcLY(^1QDn}LM^Bbb)YWPgZj__ z8bTvz3{4;lnnE+Mhc+>hhjgMnV2O#XpfzMe8)ysdpgnYej?f8mpfhxVu8<4epgZ({ zJm?9%pf~h^zR(Z)Lp}_EfiMUL!w}%d&BS3)0O!DPI2T61c`y=2!Du)i#=r$I7A}Nw za1lgsF^q>xU;<2pNiZ4sFLvUkFcmI?tL+EW#Kmw8TnpF1^>72+X8(;(ydCa9)Wf6C_D!1VFNr4Pr#F~5uSpl;ThNj z&%$PS4z|GauoYf_ZSW$z46ncr*a@$}8&KYUCQhsXrvX1ACsu?rpb}JuDsU!Lg=$dK z_%@IKE^E_<((K2o{gsD$P#+pVLudqzp$TL`Q)mXwp#`*rR?r%F>nD)h09#78J>eJ@H}jV7hoH_2rt3QupM539q=mb zgxBD8cmsC9o3I<+f<5pyyaVsTUU(1o!Taz5d&MMs0p>8 zHq?Q-P!H-u184}1pfNOoENBYNpgFXFme2}XLpHR5w$KjRLkH*xogfD~Ll@`@xzG)| zLl4M9cI8xD1=!s8!m@AFc;>*d{_Xs1GFC~ za3!pTM_?U13Xj2h*Z_~i6YwN#gx&BK?18u89e5Y^!h5g}-iQ700elD_!2$Rf4#FpJ z2tI|+;Bz<(U%(Og5{|-G@HKn`$KYG|4!(!u@B{n^Kfww38GeCZ;ZOJ*DrFdzp$eP{ zXF)YM8>&MMs0p>8Hq?Q7P#+pVBWMgwAPbs8E_8$L&;#cO0yqbT!?`d5&V!LK3dX`XxCkP+7%qVcFcBufG?)%EU?vp8ESL?K!yK3k z^I$$KfQ4`cTnR<62(E&wVKH0-*TM~OBisZ_;AXf5mcu=8FWd(!;C@&M55OvT5LUxO zum&E6weSe6gGb>pSPvWE33w7V!c*`xJOi8HS=bEE!4`NPw!#ar4PJzo;APkjufPs? z6?VdF@H)H!yI?oG1$*Facn98vz3?9FgZE)Sd;lN9M{oc>hJ)}49D+~bGx!`1!x!)+ z9EGpoYxo9^!ME@od=JOr2lx?wf)nsF`~ttiN%#-^2LFZM;Scx|{(@8RH~a(tLL$>B z25Ha{a-bV@haQjzJ)sx$hCVO=hQLr51_f{q42N@J99#s8U>m#wJK$B=32(y@_!9ns zV)p;qZ(Z@?~i8;-!2@F)BQ zr{Hh+2mXa(cH(bh4%lfMTO@Rc9*_qE;2anZQ+d zKj;tnFaXYh;V=#^f<>?mUWV6U54;UW;7dr9F^WMa$boLq9eRMB!>}&|pXr&TsihlpF*mNQ4&f)X($8bpeEFU z+E54TLOrMt4WJ=3g2vDUvY;t6gXYizT0$#m4cX8J+Cn>M4;`Q*bb=h{3|*irC@Yv5YA4z7nA;6}I! zmcY$$3)~7z;WoG(?to=*C)@>h!*aL>?uGkc1>6rS;Q?3$55j7A2-d*EuofPHb?_)W z1~tz#YC&yi01crPbbyY~2`X1Ls=!$=97e!-FcL<=XgD9nz*rau7sGhC1SY^lm;{qy z3e1E;m<6-pa+m{iVIItf1#l&7gs0$Xcm_7Xv#=SSgDvnpY=swK8@vcF!OO56UV$C( zD(r;U;B|NdcEOvl8{UFF@HV^yiL;DikOsve8`?rUXb&BrBjiALm<&_kQkV*t!8Di- zGhikZ!6H}<55XFE7}mj~upTzRm!z}xT+ybF8bJ=h2D!+!VxK7^0p0DKGw;S)FnpTcMGIUI&B z;0SyPN8u~@8oq&J@GX1?-@|eE0e*y^-~{{(zre3>68;0f!GGa*_yhigzu*-74gbKu zP^zX;2FgM?Xbept3z|YR7z-D|IJgKRm;{qy3S0_P;WF3@@4-HJANIos@F9Ez2jF8k z2%o?q_!K^a&*3n90Y~6VI0|3E*YFJ-gKyzG_#TeK5AY-W1SdkvqQTE_WmDrYd;v$` zOE?N&!PoE&9D{G+JNO=s!w>Ky`~)Z9XZQtvg_H0f_znIGzr!E!C;SDc;BWW`{sk_0 zPiz8N&=l^0d*QOR#x$4?GoTP=!ECr3=D=K-2lHV8EQFQt0GxoIA#I(J4yB+T)Q2p{ zg>KLtdO#lZgkI1a`aoak2mK)*2EafV1cPA+425A(0O!DPI2T61c`y=2!Du)i#=r$I z7A}Nwa1lgsF^q>xU;<2pNiZ3vz@;!1E`w<>9cCEc<|nM}WPA+{!xwM_zJ#Oj6?_ff zz%lq1zJu@KIQ#%V!cTAleujUc{-Z_%Xb6p!+)01SjdFc^kF z5iEkM;2GEq&%qXW9=5@Y@D((A%xDZvAPbs8GiV8|pbfNz9*_?UU?V&Y&%h>l4z|Ec z@G`st$KeO~4Zd1$9D^UA`d>!kAEOwgL2*bz2}p+&WI!gAgi=r%%0O8t2Q{G<)P_1x z7wSQMXaEhN5j2J-kOfVl88nA~;g5ffKjAOyu{8E^b^7b6_sagJLC(G$;-w zARS6W87K?opgnYej?fjh!z-`@UWJ|T8oU8-!ftpQ-hp>vFT4l);Cm9)-tXJ#2u-;R#5TF^WMN6o({~fOJSf24q4>CdAJ zgfpNLRE8>WCRBy9pcOftn2lb%=tS@V9fWP4%_!nA~Gg?9`XbsuW z2HHY9Xb&BrBXois=nP$;E962q=ng#~4|+jw=mUMBAM}TO7ytud5DbPPFcgMC0ZfDG zFau^nAC@xiAmr!va_cSHP7}1dHG*xEdD2HLww$hG$?CJPVs)3p@{7;RVmti{`f={7!B_kW!KwD@B?V$s7gwD_va$!9@ z4jbVqcp9F8P4Fx{2WM9{szVK^4RxR{)Pn}l5E?;aXadcv7%iYBw1U=<4Q-$;w1W=N z5jve|z)%A|Y3Lb>j@DQwlhhZ%| z0*}FZ*Z_~i6YwN#gs0&dcosH8%d?GE&>FI#4YY-hkOQ5eE962q=ng#~4|+mxSPHkn zop3k&THQDai5f;RXbbJ2J#>JMkPF?RMYhorT0v{bhBnX^+Ch8h03D$dFI#4YY+pml?Oh zQn(Fnhof-+He)5Mf(KzWJOqh%jbe}n#UTkLARSVW0hv$|NKLtdO#lZgkEsTd&UHq2s5D&X2EQ@9Ol4Wmq0HD!^%QI#h%+pb}JuDsU!Lg|naH&FcL<=XgD9nzy&ZCE`)J#5kzn?jE75L0!)NSFd3%6ELaTp z!3ww^R>A}DAgqRmU=2JBYvB=C2am#IupTzRCZ9z*$fY&W7qx18PDor~`GOJ~V)a&n}#IChj{@FV;Ldyg6K!9I8&_QMD8Atb&via{C_ha{AMbVxx4 zWI{VL2al5b)g>AhX&9P8bM=d0$I=$nn81D0WF~ww1#YG18t!lw1*DR z5jsH*bcQa_6>^~)bcY_02R)$|^oBmr7y3be$cF(i5C*|u7y?6K7!<%cFdWW>5pW)i zgi$aW&WAB@0gQzUVH{ip5nK%8;S!ht6JZiehAD6H& zFcL<=XgD9nzy&ZCE`)J#5kzn?jE75L0!)NSFd3%6r7#sPgK01wX247+gjp~fE{8cV z7v{lySO5#*3b+!AU=dseSHohs2Cjwc;Ci?LZiJg)3ET{~z^$+pZiCz54p;_v!d-AT zEQfpGUbqid!2Pfi9)MNwAgqRmU=2JBYvB=C2am#IupTzR812fPY9;Wc<2-hf^3ChUf{U=O?v@4&mT7v6(?@ILH^ z58y-i2oAuSC{TtuFCe-|8~24Xv*5+SuwEuUS?%cx`5Nlh+njw|Q-4b*I<1R`+}D zVD*sKPF9b3?QHdg*REE7_u9j1Mv3r9_Ox2wtGy#PQN?Rtt2MpayKxg)UI$vu_Bz;V zj@O}9^Sl;V&G$OoYJt}gR!4gsX*KdX+UgXqW2_c>9cy)g*Kt-CdyT9v@jBk>GOrV? zuJCGS9};W4PO-Yd>r|_oyiT*a&Fc)SJG~ZK-Q#t()%{-QSUu#G_f8-4y3pzguUA_A z-RmN&iS+PDF1A|Q>$O%ZdcDDFO|Q3DZQ=C}t9`uQWwpTT3agRV2dvKVy4vbuuWPI> z@w(RPGOv$XUFCIy)pcHR_)QSsmf^W2JqPCTV3Y$ znAH_tzq7i=>v5|ay#8o)lh>cEZu9z^)%{-ow0hL*DXYi5{$ur|*M$ATf>U18tR^%3 zCydq7Uem2s^qOI{n%9z6>v}D1HOp&RtJz-5Tg~x$n$eXGm7Hnh6JYh$Zxyk=S5;I*06Ob)(fBuRE+BEg2s5 zeO9ZK3iSu88@>Kyb&FTtE}keIZopf`GyL~<@XqflUZ+{j^~$d!*y)vD0tU-4ydJT-*y~ZNOT2z< zb(z;=R#$la&gvSk$E|Mg`lHoNUQbxv=Jll2JzoE?df4mVR*!ofYtOLT%ZEp2oYln@ zLXE60@jBk>GOrV?uJAg^>Kd>7s)P+*r&`_Qb(+;}UT0X{>9x@69LIW5 ztRD5c!0K_YS6DsiwaDrzuUA=3o)*^2JK;-vU1BxM>n&EZy)Lzy~)RRC0^HBUFLP2)fHYJv%1FX2CEyq zK4Eo}*Ns-Ud1Vi@)9WUyd%SM8y5H*-tB1U9wR+U+Hmk?IzGU^J*X>qMd41Jt#_8eV zd(CQjuWwkb;`L3dHNC!NwV~Iyt+w#G*J^vO`>f`9-ETGD>xWhgydJPR+Ur59k=H|3 zr+EF$YN6M|Ru_0ZVs)|CqgI!A{o3j>ug9#e@cNzAHD3889UHv?_vBX*F_CvTz zsJT{)ypFY+JTn}fWp#_!{Z@~9{nTo~S>XoXT3z7vgw=Ik6ZXE?V_y4P&8-%0`?S^U zvqSyOYNAG{|5!cgwONK8tr?Dvrq&8|vehE5*IV80^;WBOYlj;gu{zf4h)nw~)Cor; zt3~xfoo02p*Tq(MdcE0d#roj}w^_~c`l!`>uTNQB=k*z@yS#3-dcf;zR!?|+(`vN_ z;m+Q*n&tI?)zMy$S}pSWi`C^`|F(L<>%Ufi_nIte-++eU&PrLW=(U2?9IuV6=6h{v zb)DDNR(E-AYjwZZj#dwQ?QHdg*B(}X_uAKLwMOBq4YZo&b*R-mujgBx=5@B!sC*A-EFm6lW@Q9Sk3bKp4D8h zN39llJz;gZ*F-7%>*+OVHJKIep^VjvUMpD5@!H60zSovk*Llshy31=vtNXq7w0gp8 zU#r!c`U7P(%j*cM1zsbo3%pLVy4>pwt2@0ewwlo_+`~;)D|)@nYJ0DDS?%NXKC6+} z`>js%y2|PtuMb;Y;&r{%RbIDR-Qx9CtG|1F(`uFG{-9cI==D9Txn2)g9qsjm)#YBx zl(zp0TZB)mV70y1MppZH?PztK*Pd2Scu_D*T`y- z*J)OldtGcb(JI{8%~mUVz0GQSua8>o<8_nObzZkx-S71^t0%m^X|+mge;lkf^!kz2 z0td_Pw&5P`wp!8a(^e;V-DY)<*O#oG^!kR?M7!{5Z&_{V^#iLp zUO%!r!s}tHW4)fRy4>qYtGm3mE^BLOAMUJ^)xBN^Sxs~ZM@L%C^?Eh8?HG<;W3{~3 zo2*vxy2fe?uWPL?^ZJa{6<%Mmy4UM#Rui4VoxNeTir06o*7SPNYOdGAR_AyvR?a>x zCwy9It65&FS{>`PvDG54ZLRM2+TQ9RuN|!(_1eSg?_T>@E#EoZ?*OZHy$-e7-s`zm z^SzF?I@aq%tA$=KwYttL@2uVFmABUJ^~&32k9obuYDSmv)p#Rp6|c*!4))4BUL&u( z$90ZZ-qpIqEAL}n<&}4&Zu0t~)ni`Yuv(>S_!9lf+hdj+>PoA*-9r6~+9T9N1^dh8 zweM+m+dkpwK&uV=hI+2mT(9R@9qVn)grHdSlu})9Ia$;PECvswT;yUUJE#SemHum)grIct#0vJ zXmyuY-bb4l6K=cT>H)6@td71Q9R1AdG_T)TE%I8`-h7xlHr!yY)grI!ttQ5WqrX|* z?zM)!_b?HKqghsqyyjTl?sclwDi?(3))w*6wTg~!X)@rub z@>X-ao@O=AYelR1UMpEG@LI*{Xs=bRMqaB~o#M5+)k3c|tuF9d+v;Mkb*(P(THoq2 zuMMrP@Y>kw8n0PaH+XGkb(7Z?R=0U=Wp$_5Y^!^`wzaz7YkRAQymqvD)N78_<6gU1 zJ?S;q>M5_?ttRJ&$2ZSvX|KJkR`lA(YBjI@tk(6KZ#B#7K&#na2V2eYI@D^O*8;2g zUWZ#P@H)ckXs;u!MqWo-o#J(j)k3dhtuF97&gx>Xk<}$$$6Hy<8_MF z4PK{O-Q;ze)oos9Sl#Kh(CQwqv#sv;I>+iEuk)-P^}4|7aj#ccJ?XW`>M5^RSxwFh zkMClurM+HjwW8PStyc4Tqt&`zmsrj6dW+R;uS>1wc)i_fp4Vko^S$0{wZQ92tJA!$ zvbwsqVJysopl!s}yJ*LdAvb%WO@tZwqU(dss@Pg~vTb(7USUN>9a z?{$mSLteL9J?eFv)#F}YvU<|%cB`kn?y#DiA0ED)R!e(*-D*XzyR268y4z}9uY0U! zd40!fw%5H@bG+`en&)-D)qJlXS}pK;!0KqP2dze44_Te!^)su5UJqMc;Pr^r#a@qE zUE=j?tINC|v%13TcUISUJ#KY_*B`BJ@_NGRHm|=}-RbqD)jeK+v%25w?^X|a{nP4E zucxdY_xg|3lU_4w*yHP!U(=ksAUwVet?G9(x3{|8kMbLv6ANe9`RYWt)dX&}Fx2VX z%Ii$4yS&b_y4UOFRu6ccYxS_#`Bsm4U1;@$*Qc#+zarf4b5`}soZqmjU*`P2)!Zw? z4GvhL#Hx6hY{R;ExYUM?@i4=No$)ZshCT7Hz=i|yaFq>7yWAPR=wcg6$HTQY zRE&q~ZKxIxH`-7)9+udU6%V)AkR1<8ZODm-+il2;hh;Y8$HQGV6vV@F8%D>&y*5Pg zu)>BZ@vzc{!gyF^!-9BNZNuVtSYyMIcvx%0vUpf$!-{x#%!W1bu)&56@$iHVo8n=k z4cp@3X&ZLN!zLT{#KUGA_Q%5(8xF<8RvV7S!!{d^$HPlDoQ#L-)3Q zhSKryx(yZMVV4cn;$gQ9b>m@=4O#KlJ{5Ch&wac>c z?`r?YhTPNjYvs$-w~yG#@^DvKHssnl@-TF_A$g{TJR3^KLoXXD#zP+)s>MS;8|ubG zz71LNFwlnVco=L$PCN{?Auk>ZY{-v?;WiY+!w4Hj$HPb)qIei>!<2X!V?$v)jJ07w zJdCqpaXdseEQyElHY|&W2{x>Vhe0#Z4YeU6&xZZ|p@o=LJb>m@)4O#JUiw)WFu+)Z}c(~n$ym(k+f4;-S6`%i^J-4J+cI zu?=hDADMc<5zA#dzprL$!G5XG7h1$hRRY9tPTw9S?(T$ccxcHsr-afercb zFx-ZMco<>B=y(`uLlh6AZI}`dV{9mlhp{#+h=*}DERKiBh9&VZ-iBrIFu{fu@i57T zHSsXTh7IvB)rL*+FwKT-@i5nho$)Z=hGX%t(1sK7P-MfYc(}@jq+L_Y$ zht)PLj)yfiEQyD;HY|&WbvCSshsSJK6Av40*cK0)ZP*_VTWmNK4_j?G8V}oSI35o# z*>Ex*w%c$j9(LG}tf2>Srwyg!;Y}NA#=~1SG>nIRHsr;_ejD=R;X@k=;^BY|qvPSA z4N*M&Zo`3iXlO5}I~EU3ZP-}z|MhgIG0v{{eczuW%R1Vnqs6l0MaNn!$y#m8+9mTj zB!~OH4awnfxDEGhxDB`AQy^_+KxmDiFI>ZMj3O@_qeW9AXww!&Pmnq=0vAY&pfyxC za03KM8zDW1ZfjQ+nqItr-+$j6oX_`vku!7do6nhtyvd7iXX)_l=fOX?z`a)L9qsQs z_&yH)(&2^SM-D$QeBm?h$2R00UU#psdUx>m9G-})5z*A6cXU%g!6=U#vH zmL)Iv45&Ex3>$|RhQIIdFAV?0Vf0yU^TuVF;V&Hi$nf%K-BEC_=z3r0eGZ>6e8eGO z_>{v7!xtTX*HCqM-QX_9e)ht)cKMeM&%VfA|0{>TZTR8kHio}ha?9MS$KH4F{+)YZ z^w`7W0}cVhhaKXER~-(9k2(BR!zUfSXZS^j-!^>IU7YvmK4jYaI$wHn->Cc4Xb($= zKX#uU?cv?eE`J+i51LOoeA)0#hu<}P$Kee_(&0yjTL<4u+`<3j@a!$%|9$B#?jkbq z*Dn{3y%YR*4lfM<%LVUZ^6HPdW$y;h9sZ6X>hSjWFxfl!48L=^&3l>rHx4fh|H$Fh z_c8gMx4NI_{owZmT;L|_u?(IXM?eMzcKXADD2_}Ew@IAwS;qb?X|H|P9 zhOfTt?(HYJP4R-C1wDrshJWKS`8g(UyIe;1DtL#(tA?*QeA@7Jhd(uZ+u;pE(cwpi zjl+wd=idH?!?TZpKfg>q4*oBPe`NTHcerJrVDb%z7lyxknfwBi*B$=S@Yc%}f1hUZ zvcrcAA9DDT;U^vPhOaoZ4c~P5GlS3JM~0)ri_dV^f8F8PFM>b1;IrVLJAA_Mm3O(x z=a>{P_&iuRyfFN=%fwyD;5`;1mn#*&1pfSjUjd(fkHeS2HymC!{Ql*V#&0nBj~xC( z!yh=jZur^vxyQmc?cN-I`&%I6@VepOy5QSP{_ukDfWL5f@oOM-xp>kC)(*e<9Q>CK zKQjD%hqwEg{I3o^!w(%^H~i`=?%o0{^Ev#9A?)z}Ad{to&#<{HGyI{$vn!VUw+^2O zf&aXVP^Qi<)Y6p%f99iH@xQXmxh1)vMkE7Uw3%b@b5T$+VDFL-!l9yhlAl? zI=pW9;RP}7?X4elcO3`sarlto6^CybKI0HK{F1}(8NTfBM}}`W{9{AV;Rl9@!_Or6 zI!TAm88Qw&!?nYWq3y6Vj2(W{uyT0a5W8G1o93=74!#U%Iy@Tw!DU&N$salVOb&ei zavQ^c`eC=M$mH)i{F&jOINX((JilC+dkumP?=ORjgU|4vUzSyv{KE^X;HN+0;4T^R z9&?{_SQ@_J@VX&%Syp4&H!qg}-+}+_f);rBr`#EDc&CHgu2FaWAqTg&qVN$1w}GJW z6$iJ|pYU~uKQ#m#eqg9L_&O~6J%<}%;9^6U%Onb++z}U_?bTV zEeD_BcN~@jCjYm?>xOq+u5q3*`KrUG4bL6^%usRg%~|#v4u53$J%{iElmE=&ZyH|y zS$EeKFx?t|sM zlP~Z|hYx@^zvyoB9q^?uyNM4JFK{0t@7*SJ&7-1Rjcjt;NS!LMH??#f7S@>>o*!{2aN8oqG3-2Gec)v}Po>xQph_A=`+ z89V&Iuy**zeJ1~=!}|x|cO6ECzwPi>4IjO1fOcTnXC3}M!^?MW^6Y*34t~nvRl~;| zMuty1e9!P%hu<{(hQqhs!X146vc1|{!FL>9H$*R!A7_$s_?qEAZo2V)zias49sZ8tUpu^R_`}OqZm)8i|IxwsaS(U=yM6Z)pyJ^B zw2AAiKF19#6ae#-mT%U(&Z|Fm~6KXT8k{=hx6 z`k5d5{@c>U=kZA3`)~KBlKJ3uKKlRvTPpdPw|@U!_4>N=u;@=G_4@Z;UbG(iv*qIZ z?-@+{lm4VzUv6ie#rI!nP1~KBOUrs|)L1M!i@){k&)s+S?1x|e;&MFu;;cXW{Ic=T z?JPgPTTCBz?O%QP;;7&J;%vL@O($RMwU`(n^3=5Z z>)^A+^FMIU1^?JfFTLch%YENRUcBp#w|?@yZ+j#D(nsF?wl}`?&iB3Tjh}e=mAAd| z{`bA|wl_O(X}I;T;~{DZIdylIY%o=-sv~R$x_hZ$UT=i&ogh)cK<*Ki}cw=jCQ z-HPsM6OViG0FR=3w#1vBMBiJ)=Wo&Rg?=#rgQELg!Mklp42$Q87-bq0-8;d&#R)M9 zQ(_us#4OB-c~}sOuq0l?vRHvt@dnn!TUZzGU_)%eme__J@g8=?9_)+m*PF`^cpi!) zreo3ly5jx#Q*j38;sacWOSlr(a3em#t+<1G@c@tF6FiB&AJez--1{T-jn|-G48Wl1 zHel896~izhMqx~hi|2&sHf8m0n-bm5tR6F>+n&{9PIP;;dMt=;qgIb4(e2jiu`IgZ zQao108(0(F=B?heF1lYeJT^r4yMo7-=zd%9*b&`^t{%Ih`@g@(zBqtG(fwc9n~p`d z$?JvZsp#H`=uPLMdzI7ULUiv)^tck;|NK2}ME52|k6UpE_u>H_MfWyFZ}Ca=y;Xev zRy}^9Ukt#Ycm+dZ7)Hb>jEQlW5R)(^rp0qc%rec1c~}sOuq0l?vRHvt@dnn!TUZzG zU_)%emgwI6=>5m(i0%!L9=l=>_C@zbNN+k6-LG06$KnJ|#TlH7?k^FS#pi{%WV#a9 za3em#t+<1G@c@tF6FiB&AJ=#FT)zjs2K{0H2E{8F62mYeMqx~h!-SZGDKQN*VixAa zym&5%MW!Y38kWThtco|VCf>rjcn2F|6Sl-Q?1=ZUEB0Vt9KfMCf@5(4r{WCGMfZEY zcQP!*C0vPX@w^cqnQp}$+=~Zz6rbQp^zobR^S9~o3;kjM21U0~u=ibs#4wDAQ5X~B zFd-&kN=(Cyn1wkp4+~-umc(oETox-#tKto;iMOyW-ob|0ge|cRJK{a;iappD-Cvfx z{~AMa1jph8PQ@9Vi|(&*I=vh9?!@z6JTN_qPw*uAUe*_SuD`mx2K}Pj z^VRz{f}-2_RmWEh!-yD#F)Ok9~0fhaTT_FaCMcu{eQK zaR%q2``fvCbS;+qT7kq<56_m(O!5yiSA_!Z~FZ0 zm&fm$uR*^UfI-o{sNgLQiSAVaj}g&5t?w}=x+mN{Cd4F6iSB7~Z<-O^)8QU-VjdPm z_r$k1Es5^gZjWWrJ*(}pD!M1EJ=VlqSQp)s)|ctIAvT$|ME6v)ciWEWo>KPM72Q+E z9{ZwuR@mcE9Ko?Tfm6{vH|#B*i|&aRj|=y$}gQDB7(_0)8-KL!$BVrWB#5hcdNthDTFe7GRPIS9| zdiPuq-PWHTOQL%tvd6MmfmQJa*2G&_7w=$0Y{Hi4-q(D&=W|EAXWA8eurChaP#nRr zIDu2qy-nKtp68-_PR-*&T*8&Oh8yt_Zp9tkiwAfVpWsRK@%+*Ack1yA{bB$H#Vhd~ z62nX*Vid+iw?nG;BP2xk_GXVMF%2`Kd&jdk&53zf5R0%RUc<6jfmQJa*2G&_7w=$0 zY{Hh9Z@OJ#J^DqrRjkLLcm+dZ7)HdXc#es2rU@|#Q(_us#4OB-c~}tL z7Pa2DQ4-y|x;>V~3apAZuqNKZx_Ad0qTBb@yQ`My-X!j^Bi_TV*n@p>0Egm8Jdec* z)2Zm*bMD>qTy)Qbdt8W1xDwZJBR;~dxPyD~0FUAmJc(|bUhfM%f43gL&@TpHP;}e* zdW%D%+tb%$M0C6RdW?x~i(iikF)5x?Vw!12%)*?QhXv7X5A5AlNxX(-u>z~&4Xlao zJ?h?V>*5`3h;GkeZ`u;uup{2XuGoWpaR7(n2#&=GoQm#E@s}@jo{R294)5zO#3fvb zYq${~;a1$iy?B5}@d=(p_d=WZg`RuQ>A&eVM)v3z-R{U9gW?qoiD4KKqcA4MVM0v8 zl$eGYF)N;PVxDP1EW(oL-em86S7osRtKto;iMOyW-ob|GHhuQ)swKMj?0f8p_pmGW zU|$@-p*VtLaRR5Jdx_G!=eg)!ee}2xm*ROPu97=ZDZ~I2no^cW$iH~reQ|R!kn0g1+gfeOX4-tvgkg7z`N(F zcmr$VEv$=oupu^KOKiiAcn`axdwJLULVeM_a_ey@j^J3Fz^OQcbJ4x4!@KQ5T*8&O zh8yuwJa5Gv)4k|kCid>?C_cfH=zE{0&%Kx7-h2)E#Q+S7S1=^H4?XbiIU+`3OpL>X zn1m@Y4Kt$qqy+D-a$+79#3C$-*RU*B#B)`2AFtruRZYBwb@2{1#3pQsZP*d-VOQ+I zzBqtGaRkTW1Wv^noQv+_1n-+%h;AEok1KHvH{v7QiaWR$590YKy8YF?yE=(JURZtp zem#DnUkt#Ycm+dZ7)C_*IS}4G$HX{Hh)I|d(=a1uVNT4$f>?wl(QRVxeW9{gfmQJa z)joU`PzZh!}-2F%A=A5~jp7 z%!pZ-6Z5bj7GX)ehGnq=tKto;iMOyW-ob|06wfWO&9o!l!>-taeQ^MX;s}n#37m>E zI2Ya9>U4a?C0vPXxDg-WR@}k8cz{Ro37$kB*Frr1fF8flF9yVOP`qLq62mYeMqx~h z!-VKQuEqO_Qeqlr#4OB-c~}sOuq0l?vRHvt@dnmJ_bD*m*R6|pupu^KOKiiAcrTv2 zVvlKG9KfMCf@5(4r{WCGMfX-n9ba(?SK=CO#7DRlcW^Hr;8A>nC(-voeWB;x#V&8Y z2K{0H2E{8F62sy-B1W0U#5hcdNthDTFe7GRPRzrCScE0<8kWThtco|VCf>rj=ss}A z`w!a?o3JIeVMn}&U9kuI;y^qP#Szo7IDu1f2Ir!?a8SorT*8&Oh8yt_Zp9tkiwAfV zpWsRKarx5o59#p>{bB$H#VZ&R!!RO7VN8sR=Y*JKniA76BW7Vv%)^3MgeCDBmciCLFxDwZJBR;~d zxPyD~0FUAmJc+&!^Z50yPkZw<=obSpC|<#k7={rs3S(j%Cd4F6iD~hi5wlElVjdR6 zA}op5uq;+!RlI>U@fOy_JJ=ALuqC!(N4$q!u?PF&01m|w9E%e;6=!fRy32hp$M?Jt zmrPgU8g9f#xD|JBFCO4ge1a#@#}$Xqe?pI6=obSpC|<#k7={rs3S(j%Cd4F6iD{S- zvoI&-#dAR{GA)VMuq;+!RlI>U@fOy_JJ=ALuqC!(N4$q!u?PF&01m|w9E%e;6=!fR zx=Xh8_!XCMC9cKuMto$t6?bqi9^g@Yf+x}U5gxzZC8ck^2K{0H2E{8F62mYeMqx~h z!-SZGDKQN*Vix8^_d#*qk6#druq0lK=dxH~S`}|#O}vG5@eVe`CTxjq*b(nxSM0&Q zIDkWO1jph8PQ@9Vi|%TC9beIX?w!Y#xP}|?5pKnuc;1T#rbqD!oH=- zfxr10^os!)6t7@N48w>Rg)uP>6Jipk#5Bx^S(p>^upky;NxX(-u>z~&4XlZ`urA(- z=Z4s1+7jEaBi_TV*n@p>0EglTjz#y`kKRLaD$d|se1Hpa30LA8Zp25p6?bqi9^g@Y zf+x|(b^Xu(iXOk>*)Il|2E{8F62mYeMqx~h!-SZGDKQN*VixAaJS>PsSQ4*cS**aS zcmr$VEv$=oupu^KOKgkhj(E?sEB0Vt9KfMCf@5(4r{WCG#Rs?$mvAMn;YNIfTX6^X z;sGATCwLNlKh5LUd*jBNuR*^UfI;y}Jcqphk5`DZC=lRd*@eBQ800zY?7!t!UBD&9Uy?m4Bm>6f8 z5R)(^reQ|R!kn0g1+fTA;x#Ob6<8H-U`@P*b@2{1#3pQsZP*d-VOQ+IzBqtGaU`C{ z;)Ll`oWZ&H02ksCuEaImh>vh9?%-ZLz@z9sLf1Q0PNMH;#pm98t=@bM`o#bYidQfs zhG9gE!k8F`2{9?2Q(~HFM$E#Tn1=nfoyoGh~4mQLlY>92y5$|DF z?7_Y`fJ1Qv$KnJ|#hG}Xiw{f};u5aJHQb2qgNnUFwiS19FCHA<_1)LrIEqj3B>LRD z=PuLdKc~kp^os!)6t7@N48w>Rg)uP>6Jipk#5Bx^S@E0`^Gpk35thVjSQaa=D&D}F zcnj;|9c+kA*b>{YBi_TV*n@p>0EglTj>QR_iZeJDAK*e5Zl2~%PkX2dMaiFsHMi{iN? zUNbF=6<8H-U`@P*b@2{1#3pQsZP*d-VOMmYAM5@2eQ^MX;s}n#37m>EI2Rw_LR`X? zxP}|?Q9N(O9n-ydfJgBOojlBeN~TN=obSpC|<#k7={rs3S(j%Cd4F6iD{S- zvoI&-VL>dyl6VcvVnsYx#T%wI@fOy_JJ=ALuqC!(N4$q!u?PF&01m|w9E%e;6=!fR zKEQ>zge!3kH{v7QiaWR$590YKJ~2IszMtp#{=AMa^os!)6t7@N48w>Rg)uP>6Jipk z#5Bx^S(p>^upky;NxX(-u>z~&4XlZ`;<+x~F>Q!V*b>{YBi_TV*n@p>0EglTj>QR_ ziZeJDAK*e2Y3{p;7Rm-%sam4=O5GY72oiS0T>joU`PzZh!}-2 zF%A=A5~jp7%!pZ-6Z5bj7GX)ehGnq=tKto;iMOyW-ob|06wfWO&9o!l!>-taeQ^MX z;s}n#37m>EI2Rw_LR`X?xP}|?5pKmD+=~Zz6rbQp^nIMi@5gm~p5Zl2~%PkX2dMaiFsHMi?AeK!?IX`Rq+Pa#9LSw?_fi0!j{;E9r0c~cf}sl zzBqtGaRkTW1Wv^noQn@|Aui!cT*Hm{2)E)6?!^N{YBi_TV z*n@p>AfAWfi0N3Iz^OQcbMXN##3fvbYq${~;a1$iy?B5}@d=(p-zPb~pVaY%elY-p z;uQ>uVHgpkFeb*ub3#lqO^Iok5wkES=3zlB!jgCm%VGsq#T!@?Z(&`$gAK6>TVfk_ z#CzBkd$2DK;7}aFu{aUWQ*p+0EQXK|C+SCDWC-h8yt_Zp9tkiwAfVpWsRKeTw7z zDIH(v7XvUTUcrzUh7mCeV`3a8#3W3KX_yhSFem24b3rUJEs58#ELLDuyn!|G7S_c( z*btkrCAMKlyoX(}2m9gx4#g21ixW5%XK*e)z=gPkD{(EJH{v7Ht+<1G@c@tF6FiB& zPjh@ft>X**VgLrkD;N^PFd{}_OpL>Xn1m@Y4KrdE=EOWKh(%Zuuf=m&tT3&LH?St& z!n$||8)6f-#5U}R_pmGWU|$@-p*VtLaRR5}49>*|xDc0cC9dH{e1uzZC!Y7>f$33v zf+x}U8IJE~bbO&-48Wjx1w&#OM#LzLiE)?^lQ1QwVMfftoS26Nu?S1zH7tu2SQT%? zb4|QuS{LtNLu|s9*oGbP9(KhZ?27|96i09@PT*9W!MXSV7vd7G#5LTAk8msQ;9fky zqxdAAPonP^IljNB;|u*_00zY?7!t!UB1U0MjKhSOgefr%Gh!Cz#5^pBMOYHAVOgxe zs(1ry;w`L;cjCDrHkr1>HtdM^uq*apUmU=pID%tw0;l2(&cz3~5SMTzuHi;}gj;b3 z_u>H_#V2?YeV^s{epbgnfoyoGh~4mQLlY>930+!61YcEuj-ivu_mM{q1o;8dK!x%dDV;u5aJHQb1g za4YWMUOd2~_ykX)?{ggA&*}I=zZif)@k%_0#4yu{7=*$M=gmzR)iQU{Jh*Au$XiVid;2 zI82C1m=e=4BWA^OPRuhch(%ZuuVGoNz^ZryYvL`ei+8XgHepL_!;W|lyJ8Ra#Q_|O zBRCc(a4OE=Tzr5FaVefx;+pA3e1uzZ2lwLP!e4jSZ-`G!PonQj9N#bL_(H!JfI;yJ zhQu(8h*205<1is6VMH}t*5`3h)wa_65C8W;=SX$zngudEB0Vt9KfMCf@5(4r{WCG#Rs?$mvAMn;YNIfTX6^X z;sGATCwLNlU)GQC{L4DN&@TqWb5Oiu8WO`WB1U0MjKhSOgefr%Gh!Cz#5^pBMOYHA zVOgxes(1ry;w`L;cNhM8_Kk+vWZDwjup{1!=dRde+7}0KD30J*oWQ9#gLCl#F2v=9 z?z>uvYo;6V5pKmD+=~Zz6rbQp^!+Nw_g8g%p5Zl2~%Pk zX2dMaiFsHMi?AeK!?IX`Rq+Pa#9LSw?_fi0!j{;E9q}G^#UAX71Mxf*M@+}!1Wv^n zoQn@|Aui!cT*Hm{2)E)6?!^NRz0jS6F)^;` zIUy!loD$P8BW7Vv%)^3MgeCDBmc zjEQlW5R)(^rp0qc%rec1c~}sOuq0l?vRHvt@dnn!TUZzGU_)%eme__J@g8=?9_)() zI21>4EKcB5oWZ&HAf6ZElIcoZ!;Sa|x8e@&#REKwPw*uAzQ*zWnvO5@ivbuEuV6?F z!-yD#F)GdLF?;6hx&mADqq8}X6pR@}k8cz{Ro37$mX*Ezml*YSmZF#v<& z6%2`C7!ji|CdOexOv03yh8Zynb7CGA#3C$-*W$S>R+v`B8(0%>VO_j~4Y3JZVjFhE zd)O6wurChaP#nRrIDu1f2It}fT!>4!64!7eKEkcI6VH3`!1O3S!IS9whW@Ad{2MyH z7rMU@_{9JWidQfshG9gE!k8F`2{8#%Vj5<|EX;{{SP+Y_BwoX^Sb92y5$|DF?7_Y`fJ1Qv$KnJ|#TlH74{#wa;YwV?jra(+;tuY`13ZdP;`t={ zzRBbFn>xPGF9u*xyn-Py3?pI`#>6;Gh)I|d(=a1uVNT4$f>?wl@fw!J3apAZuqNKZ zx_Bp^8)B1bOKiiAcn`Z`5B9|Y9Eu}27AJ5j&fr{pfD3U6SK=CO#7DRlcW^Hr;8A>n zC(-vUj_7o%F$q&*8fL^S%!zqe5R0%RUc<6jfmQJa z*2G&_7w=$0Y{Hh<7SA2=o@rO?!M-?vLvaMh;sj2`8Jvp`a3L{7B>KM1@%^@rFZ7E67!b4Uy`jfhbg6XP%;CSgiU!;F}PIWZ3lViA_aYgiU5 zuqxibns^KA;vH;=P1q9Kup{2XuGkaLeR05aD30J*oWQ9#gLCl#F2p5ViEFqKAK_Nq z!M%8ZNAU@sMBjHfzTeUDg?=#rgW?qoiD4KKqvAOx#+fF>But5Em=UuuC+1;6EW(m_ z4a;H$R>d1w6K`Q%yn_v~30qi%sW=nQbMb-cLR`X? zxP}|?5pKmD+=~Zz6rbQp^j$WHz5K@f-1m}>umwLMU?E7jvJfJKEkp=W3o%06LV}RA zkRqflWC&TpIY-FbiUOf%p+va0P$pC?R0%g0YJ^)0b;6y62BB%8MQB^-5biB>2|Wva z!ob3iFtRWvOe{V!KB4MNjGi_o^vA>3Q&5_%T;gn@-2VPs)Um{^z+W)|jz2MY_r(!z?cwy+^Q z63$z~&Q|OR2Mb5SlZ6w(ciB{S(p3f`Gg=n{Gs`h)@DJS2>4#h5U$ zFeS_^%n1(`7KEjR6=7{*LwK~XCG0Hh2?q;D!jpv)!56agBgFY(!A}TS2okO=ga}~^ z5kk~Lj1VWB6NIF#ND#5dkbAc&qALturMTyEQ|>g!g)%V*@`*g!NP*Dw6G$qEo=yn7Pf?)g+1Y5;YfJ0 za3c7^c7B98KP>nO0SiIGm4y%?Y#~C3T8I(i77~P{g%lx8IA;i1TahE=Effev3njv} zg)*UHp-Q;1P$S%0s1xoiGzd)#EkfHuhj4G9OXykX69yKBgpq|YVPauQm|2(;9th_J zVQDK?gtdhY;nBjDu(Ply94s6OPZmxDU&PLj2IECdNx7D9xug$N;PAx4N>NDz`1QiQaH3?XYFN61?!5Q-K`glodNOsLq3D&fXL zjc{wBPPntsAT%ws2yF`;!o7tqp=Y5_7+4q*Mi$0|iG?X)W?@cvu&^L3EvyJ@3md|t zg)L!6IPVDuTX7^jSvV1VF*`qEoF5kagn)%0;mSgY5VjB@L@mS!aSI7T(n5-mwvZuY zE#wG!3k5>aLWyu~p-iY)s1j}n=NjSGR@4c178-=6g%+W0p+mU0&?WRN^a%qCL&C_y zm@u(0CCn_$2@e()gr$WQVQpbUc(kx3>@4gF2Mb5S6XAR!_~Lec#5q4K_z3|ELBf@V z5Fu@;m=hi>EC@>rE5h2shVW=%OW0Z16Al)R zgeMCpf-hm`M}qT%aP|`dwjxNlvJfJKEkp=W3o%06LV}RAkRqflWC&RcIYQn-fl#zi zB3xT26Dk&}gc}Pr!mWim;m$&X(6rDZvm1P$%43Xb_qfT78(vg&ZMop+G2FC=sqLlnE6JRl<#h8sXMLop5KNL1}a1 z!j**(A#5Q+h+2pd;uaEwq=ghAZ6QO*63#h7-c}R{MGGauwS_XFVxda7u}~x2TBsB5 zEHnsB3oSz1LWgi~p-bpl=o1DOhJ=xYF=1k1N|;%g6CNxq2us3wMOfR44dKzkmawz1 zCmbvs2~QSI1Yg$9k1Xeh1wSERAxOBg5F&&vL%D|v_kPZ(Gj5=Iurgo%YIVP;`Yc(AY_EG?`EYYQ8~qlGPDXJJn`5Y9)!ldU)r ze0e)R@|+(Q{DgpoAmPeFh!D0AAw(_22yqJuLefHtkhYK^WG&m1P$%43Xb_r&bBoZn6&=F8g)X6I zp-&iC7!pPn#)OH5DPd+|PI$1eAS^Ac2x|))!lQ*PVP|1aI9NCmo-CXQzM}p4QRMuv z;3otK=OE$AR)h#)3lT!pLW~f%kRT*2qzGvX8A8@Vj*z!dAQUZ>2-glFX^lU|+Ft9Krj4X@^6AM$q%)*@TU|~U6T38X*7B+-O z3tPg@!k%!ja3nlgI1zj$J3mUC9~S(CfQ2C8%0h?`CY&RLsI7<*;uaEwq=ghAZ6QO* zTF4Rd77B!-g%aV~LYYvpP$k@0s1a^0)CqSM8ib~W7NKpSL%6rlCG;%x2?N4;NEq3Q zF=1k1N|;%g6CNxq2ulkq!rH=y@MvL6*jd;U4i=7tCkrQn@7m6fYt9b~enP-PkZ@%o zLNVN941&Qrq7R?G}a1!j**(A#5Q+h+2pd z;uaEwq=ghAZ6QO*TF4RdgmZyVv=t@7wS_XFVxda7u}~x2TBsB5EHnsB3oSz1LWgi~ zp-bpl=o1DOhJ=xYF=1k1N|;%g6CNxq2ulkq!kTd25FTyCmawz1Cmbvs2~QSI1Ygz8 zk1FSf1wSERAxOBg5F&&vL7fK6rTNa5@2Kzo!NE4 zsne!a4{?jsNJYZj%%PGIm-NQ5$4c!XKS;G!s6Dh7Zf?Vg3w<+dCj>Fl?z}heXWqQ| z-kaZ|(J+E>@8IvLPnr<=n=y?MsuP=cfVhVYG>r_w5G`R^fLXG{j5IA};^qUAu>^nP)cN6N;aClm8U~SGpx11rw}C-GQzOdWJEX*+OXEpZUsrR5d}%xtA4<) z1?<{E8qSMqhu$I}6h3QyPHe1W%XB^Lq_AmwBu%J0gfqH9a4yRh2WOouN#!gnuY#(Z z(Jc$xxy*G!nbdOZG^RP*4Fi*OY?mZ+9=LtQSJKI3a~=U>O0tx=#P)R0bZlns%@Uk) zXeK;3=z2Q!Musr4jS+PS2mCS4A5(EW9#`XdYL>-oySHF-W;&N6E_Zd{mhR%)xb8k| z+Fa~VGi}RFD^>J0Hu)iv$vgMQlhXkt*wZAqkfow+%P{I>Inq z7l4Vt1=>l%kU(`iP2Bgw7)Bio+EIS{+R-gIXaPPn1`vjbA?)UovvAkCx8uUOmj;@# zP6;Nr^`vLzLCbLoAZ6Q*<4!a2*eO^ZWAFn8Fo|6Upkl_u+}ULwUf{}3ItDS=5nR(w zTiaN#gBFjC;lwdqV7?$k+wqvL$3W%AxwmI8VLW3%p)9v*$Pc*=^@!msJP*EP5!(;x z*(|v5qZ%X$w$uWd!ab=W%E07D0z-{u7_iF2^uv}8(7i=XkNAS=N0T{9q3i+&F6&Dy z%^1HJ9riNW;jEcG0@ar$-jR85H*bv6VavQeoXtbJ>|xWe^`!fOHn7o zH>cg;mf^wu34V*{c?XK^F75j9$m02Gw0&{B+8J9s_cYpdH?jQ1Mr>dsdhkCKQhJtz zYNU1PQZaEiwtQ`)vwuC(Uv1x08YzBR-dnj;nR__7)<3e+zt*2vZ%xj|3#=C&HhYHZV=YcN>^H4*8a`ECb z43dXH(Ow`Zs~DGAVN7?ig|@~I1L1bUZxK~t_shlerNmlf|Ej#7_Q0wy&>h`{?aFs% zDXs4eH3|`k^8lKZ2)j!c>0XdpOz-7aFTauy-3O#9(6?Z68McBb06qrUh7aun$pBMf z&RIOs<*wq{<+;+tTF;@?$l+D_a1fLXm#k41^^UYK)bZf{1Y&3FGlWK~SP-|H-VGTP zUmMV##4TM3T9t6~3?!`I+iFks1_mvSrS%az4~$PCy$dolGPwXz-4<`|0V}1T@Wv?S zC1_33EA4En$#QwmPVaB<8)ANg7MhpxvZ~CVIzv1{Go}qyp29OMB{Mh$Z=lOwI0ri* zsJ~-Dd9X)jCLm|xyt*lCuT$fy!tvmTuAA^kdVVCBHH)M?ekrsS^wcJbVd81`L%h;8 zU&=bJFEd5x4`zDS^99XinPN2zgQLyw+%8IZh&|o3sR}yp!smVszeV&1z4vMtErPbS;FMBTJXQx%ISrpgdklK<$k_nAqq(R*WpkOQafU zUq1dM(pP$WJrK5+yZXwZvil&i(KS?T0wbLpeK!W`)kp`2 zl^XGzG|h05nnn*mRB*_A7TPFfn4%0SzQhi~&>0jE1FSD!cN~kKhr^t^;>Ui`JeF~c zoJHQJaZqG9ahKp%lLSHdS5yRfvkeJtf1&*~IVS8bdF9jh^ECuy<;qIpv9xmXp|;7` z+95&cE5&LErgDN$mBc3FY9T=wTApM}L!~R_L`5o}ybnge)|%Ue&eG``f~m5r;;x*o Q+^dWGBV!a6K>=#VgYgi DnTIW~ literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/uts46data.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/__pycache__/uts46data.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..2e93766390737ed32c3d86828d4b4c5b7b7463a5 GIT binary patch literal 158809 zcmbT92Xs}%*2j|@#D)cX7dxQz4kFkE6j2co5hz#TyS0-{Wt5@gWXo# zo)C8e5%=FYVc_RSFQ*i7iE)YXz2o}Cw~Ox+X&32}&@Lf9?%cSp6CUlK- zJ*#WkZjq}gn+;Pe0Wr&LD6vdxnRaKFD#uxroD9G8|V zM|sL|S*dbdLOCukRgOz3#}%c@aT(>fvQ#-PryN(6D#sO+QQ>q+SQI2a% zmE&s4ab2l$TthjoFIA3fDaQ?^%5fd#xUp0@uBRLoN|oaV%5hVva@QjQv>%2ADS)GSqw>Xf5a zsdChy9JNc8qbB93Q>q-bC`a8=<)}?L>Xj--9m-L^R5|KWjs~U5QIB#oELD#Bl%r9p zax|bEcb6(hL(0*(R5=<^j(bX#<8I2)q*OT?Q;w#k%5e|nxVKa}noy4WN|mE2<+#68 zIqsz#50om$eU#(DQsuaxay(S391l>Ahf9^?LCWz+sd79-IhvI!$HSDPd8u+dLOEKL zDn~QQ@o1@XG^ZSol`2OI%F(h^IUc1PkC!UPW0a#+sdBWW98Z)g$K#aa$x`KLMLC`- zRgNbpN9$7Mc#?8FU8)>UQI0mH%F&u~JX5M1Pg9Pzk+`nU(!aCUgqsEwKF5Ve5Tp3H zDt?}dpReNORQv)Jzfi?5Qt^vbyu6BEqT-jT_+=`7xr$$*;#aEpRVse9ieIDR*Q)q+ zDt^6+-=N|*s(1wzze&Y!R`FX@{8kmeO~r3l@jFz!qKa2i@yaTGr;6XD;#E|Sf5ysnDZQ}OyL-ay40s(2$6zgxu{tN1-C-bBTls`$MsexHip zui_7=_=76`kcvO7;*Y3!GZk;H;w@DCQ5Ano#apWQ<0{@t#h*~|Csq6@6>qKLPpfzv z6@Ny>+w%CDcxxEjwHw~1(laH9R7%J%^JsM7p!~C15ANT)YyMeJ_l@@JJECljI#p{_ zt)5>t=sIX{(6@`tXa7d%{}Slm&)Bt{71y1%WEaOj6;~8#KIS|aCsKKgoQ6< z;mcTC#4J>>k3s+#_n^^c}7QTgrZ)M@z zSon4pzJrA;vT!99uFS%BvhZCjT!q5<@olI#R0XX|e<)myrKrw$4HmA+!nIhqHVfBb zVI0~Wza9(MXW<4c+z{cgr#52YyIHs~3*W=SO<1_84=0q|OX2+Z$MWMlRZ1wi4?+t= zI#cxiShNd8ABaU0Df(b6+LfXY#iHFP`fx1TouZG#qCF_uEEbJYw0SJrlcK0WSdCs3 zeKZ#BP0`0<(LNMy8H@I%=;N_yKZ>@BMf+3qiCA<1MW2jC1ByNsiw>k{>sWLUMW2pE z2UE07EINdu&%~lbDcUv`9Y)b-W6|LhZ5NA1Hrxw1dT zb&Wr(Y%qop3ibcNt|rjG|KAvwB$DJR-j#*Bv2b@5?!m%Q7VgQyy;!(63-@8+zAW62 zh5NJc02U5dcpwW8V&TCoJcNaZvhXk#9?rs;{kwK}5#g{?yu`vIS@>lZeuagTD4ZYP zmb%s`&^7dj!pSV0!osO6oW{bVSvZ}A(S_VGaiv{&EDNJ|I6j_*C$R8D7M{eylUaBQ z3r}U?X)HXQg=etvOctKS!n0X;4hzp^;dv}PpM^77cmWG9^x=e(EQE38{)n$Y&AtfH za8xd4;Uz4*l!ceE@NyPj;ll|fD-lK!gE6Wq9L%6{Rxy1w!Y%Lz#*;*J0auB&EWD1w z`SHyt#d=Q@N;V*j!=JK;PbGb$*CQp_KAcdp31JkKA77J9TaJs`zMD|88Gs#Y6eZf? z5}kr!IFw6=-wG7A(l#GXDA|rMJJS`EeFvB=vIa$Wx@gdYLUgQM0OnW;CAm%L;&>IphA@rt1O9{Ot z(K14NC0b7CZHZPGn{NM@;fQe3m3C+2@8M2!r!v+ zcP#ub7XF@ve_-JsS@_>9{1XfR%)-C0@F^Dlm4*Mq!oRWb?=1WW3;)T&|7GF7SonV| z{I?G$l*G}~1<`5Y;a zA^BV;pC{#UB%jaZa#Ef^@&!!3P|A}?zKF>eOL+>(<(Yhml&6t=DU&ag@(hwMXYv(N zo<;JNOukCWb4b3L$=67E9?91-`8p|Ql6*arZ;k1t~8g`6edcEafF6-@@cu zrM!&f+n9X2lZ_#Ma|OwFFu9_WZC_hOawR5Lmhu{s?{xBMyhqKT4W%*`>P);x^e$QK zIx4n`E4ETXw5pUhkX(())x8V{6+MVPUW4g1ot__w(yB39+r@1gY@y_JSn|43-bQjg zCO44sPLdlkxsjA<#uB}o$&IC)NAf*PZsKK}O7GXVQFZV24CdjjWXf_M%W}VzX$BU3 zfXNR^c{IrnG5KLB)ATU<2$P$68TC1kOAF^{bH_{%dkZ$91(#f`L*o3E;+}g>uY}kaSnT$>vv!rjqCOpIBwo-;oc$UfSqzs$z z9FyBi88+d0CU=lBY{Cmn?kHv0gicKEEM?e)E=*38GHgOuCU=uEY(jS?_mDDdLX^op zr3{J5|fxX%88~j`=?Q5k{vRY z*$c;?!g8ca8IC`V$)lZY4>+9;nC_50AO?E|%Q42uHpfiLF;=2kgvL2!4>Fz(GM*h| zqLa-*-p-^PlLXp7htOn+<`J6WkUj2HI_^}Ua27Pp$+mJ?r}0L$0*nV^7thEWO_xPs zu+3mKnJHyj*F(a`+%OdD zn7rP}Hg^V5Eb}T>A8xxcRv3Os^-*s_Q;@cDH zkcWW6p>bHslSw|pQ2PFD8F4W%$e=nEY=i=SLDpQ1|%7#clV17d*w1|0?9YGbqP@B!cJrO`x~Y ztAA$)`9sRPNdA+_|CKU2{a;M}pOp8I{5O;7K^8VI+c%2jcp$d`mNM*00+Y)~8Gi6A zCYO~m76)fD`5Y;m1u&D(lQJf|=QFvSlqa0VE7cAL(Gx;(pV-kHildq7nSy(gqDk;P7UCrccq-++}OukOaW?{|b8>DO& z)=aJ-^QiegO!sMz_hC!&t*LZRV>TW zSjcChof60qOIWQR)G%Cy_4uRhk{}DNZUPl34o?80AWLYiZHu< zGMbL?nPTb0@)g6Z>vP30|NTO-6k=a0hUWeXEUd#(gmJqjz>1YJ9P^;FJ%!^Qm?cy~ z^n?c^Y>JZ(nC3bF>s0_07SWV?XKV}LAo|(862bf22NdSGU&>gRJ>XFpD)eB+K{WS+ z4w{R52oCfie;Dc*2xD8Hcq`8nqWxVqQ{Q*Z0+`8xl+6N|$%BM^0EOa4pR4;2A-`)D zz)n7mtEv;cMD2emn(d5S)i9K?#$JyR2*>)BX_psW9jMt}cKRRjjVSsGqUZvqIS%7| zlYqjbrMlDsZbDG{GzU)Mt{vUqG}mIZJBqy)bO$M#E|A$+%Mj=g-BgN>k%(?8MaN16 z+dB>@tkHNOAI5Tc0+T07c>*19l0=xzPX-G6+Y})mqT5r^sS?rcspvF`==M}}xT3Odcdkmm|?v5e}DM zuZg4|V9W1ypEM!*hLrK(%9~7nOUig~WiON8mNM>T?_=_QDUT)j0F&R5GFI&enf$Jl z%?&puACWSQ#CuGBU&=5NA29htDZ@y7#N>~q3?uOglRtH`>31KPl@^opooqVR2QU(! zGx-ZCo0S%mzml?9X)*bzlrfl(G5NTZ%}R^OC#7swT1+mKvRP>{x!B3}yv<6B$=^8H zp0`DZ_4D&g3hk47+h9ldqC8?8enhzDCNh8`m=VIw`|$ zT+ieiqzt=pBa_!zPSCumCMl~?X942(z(gfK2bE=VTEM-9oxgO0FdCqh%js;+NqQ&}xlkoWS^G#-}j8kMSdnf6Mp} zjN?|2t615xu40ksbqI$QzTWZEIIRW&p0dh0L#LGx9gH$sP#X+JLwvg8GxWtF0)CcZ z;7|uKF^Ky--N0cEn(UvAB}j{KK-18)M~-lKK3_3@;n^{MF~VW`7K}f}_$J0*W&BUZ z|6;r<-Oh96R!2BIeiO!OuVQ>Pi@OvXPeIw)Tkcdx!7y5+Bt(2NkX)Ps>d2zj~86obd9>PIt^uf6yvFkr!hW}@kxwN zWqcars~BI+csApk7~jnJ7RGlnp3C@N#@}ZA0ORj4eu(iSjK9bDQN~X)UdZ@QjQ`F! zz9`{_V?4s)wJ*c?S&U!6_(hDDXZ%veD=}V~@fwWRWV|-xbr^5R_}z>@$oRvIH)Fg7 z<1HC~n(?-tCq&yL+=BW&CLVD|*DgA`76a*dg%<-yq8)rrdJ_rZumuwt@5cBr#*-OO zWju}Xag0x7daLyR9`{5{4$Vf<6Z3mN~D@wjra>vaLbYv_X0HNBAW@{C`?cqPUwJAOJ#StGzJ z0x4%`DapsM0`GPOQe_`x{2|7hG2WcRW&AnDpJ%)S;~g1KWV{>W{TUz1 z_yoo$GCqazsf@2;d^O{n8Q;SAPR4T?e~a46I<8c?T4vVnsu#A^y{1V0=Wc(qF#?u&| z#rRytH!+^WcrN3+8P8+nO-Ug{={w`Y75<0*`%GM>ixXvW7eKA!QVj4xw+ zIpZrlr+35;W}egTn94fdW^KumJgJgQu}Pj{NuE(jX4)ie zS(5fD$vm6nd6p!qk|Z6?!+o5dJ_$Y8fpB;l13XWN4pdpQkM2g_8pM(e{$~=iRU~oV zrlWb-=^N@XEmh-=65gF{m0?~njh&Zc@oA~Z*7-K;0+wX4O0vi%S;CU6P)U~CBr92xwJOOPn`9kJ zvO^`AY%k_cpM>ssBOIPa9^>yaeu(kU8IQZzHEJZ9g|Imez2%8;3)o8xmE)Unr(z$| z-&HzpHXQOgz0-+sc(MNL(&C}bxML~vDeYfgrwM&|S1vs(g>X2zZ+1zHH%B<+Eg5gc z_%n>RW&Byj+cDmO@s5m-VSFs(6B(b(csApk7~jhHcE7<&3IGB?`8Y}#``kfpYg$rCo#U3 z@r{fhVEhQhl=FVf(jY{1wKN82^Rw|1w_xy4Z0VAsn7>bH*R@JRzEda0{||f%$4g214c!jAJmC z{^W<7v$X?!C14ls+cqgSm>~^@4ed;r)X7js>6C2Fi3GYyiAous|`qU$9UyykL-} zSQfEGis2!O#fsr6iY1ESF^Z*%;W>(Bis33DDTb#g_9%vD-ChL?jn+Pd zL!)?v@jn@lyWXXzmmLr`#_UltTvR|65AbbA0#!X|2|$kqvFz2o_@qr;!-Liq)byaE z9Zj`7Xlql{_Mn{wbv$TqL0u2Rx6A8!(9x!-??Gn^8hDUsK|>F^0nnxnfN3>)2*`^) zZ0g1y47Ihs$Ag|WMH3JDTF}&kz=C@{7-YeH9t^YKeh?!V?}mYm0c&gRteF^5A(&ak{lhod93XxrLVbXXag7yOP3YgnxNj zG5D7@js@YRf5wCGO1JeOywcA)5FQ#Hqn%?x)Smit9t^Rq)!u;RDn>6I0fe1tm>2OiEE=%GnK;jhwr66hG2fw}m2J*U2h6k7`!S_h;81Y6 zZHa{*;EPO@BFlp|_9%-Sut$MUU+j=A9PWFGM7VNG9SVBbLof57y9LV~u*ZQ*UEz@J z0$cFJ-AczyvIFQ#s~obGf`;I&E)v+{fXTKO^NOtw1;cEb zZ65TqV7mk1=z+D`;aJe$Cfe!2a0_;M@Up$$xel1J55NTPmIx*|&!J#|J6a~!mRcEGT7VS1v{G5)(Uy_?c8{<|~1hte_rqfGCqbd3LA zOz*99jQ>7N@2hl-|9(vGuXK$60Zb2+j`2T`>4TJx@jsa9LzIs3Ka}ail#cN~oarN! zj`9B@(_d0L#{WpBzpQkO|5uovB=wyb|D%|mtaOb36sD&t9pgWZ>7$j7@t^MW(>bPk z0lp3T^BFs)3{@};%NSQMIi|5nhhZ7V^zllEVVS`6iAslInZ)$TN{3;Y!t|+1hhdq< z^yx~6VVS}7xkB%B09!lr91HM`Rmw1*Wmw=uGi`nYhF~F+vz%-P`c4>vMND6;bQppq zOkb*W7=mR?U#@f*f)z|(sdN~ERZL&4bQpp)Okb;X7=m?7U$1l+f(=aHsB{>DY^HBg zIt)P$(>E&}hF}ZRw<;ZmU>no7D;d9fn{R({q&$L$I6ac}j;N*u(T!rM?S> z;5DYdu5=iJH<m5%ZHF4GSw9pm*d z(~l?}QF%kHj>0c-v6M-+8 z{*}@({=a7WQKe)2A7lD)rDOb`VERd=WBeB|y-?{G|3yqMRyxLi3Ddt(I>!IEO#e>l z82|rb`u9r5`2T_FKPo-@bk3=M@BuFG`1DImPr} zl@7!5AEy7NbQqT3nf`~;VOaiT`hS%U!}1r?|EF{qmcN;P&W&R0A~%T~)wzn{CC&2` z!@kb>is3cQa*E+S%?lL6*42fI;k!>4DF!2SF__s#p@&Tn4)3R2rP5*_=W4~Uk#mh= z*h#!rG2FDgPBGlHyk0RFjT^wi`!5v`4!3wJsDUo$pcpm|8!Co-ZjBVfPT}2(VXLsQVz}pak7Bsz z)(_c_J98^cJ@S65eI{IH!G4#KlilP7YQVjjC zw_@mjeH26g>#G?0Uq8jr|N4W4bsgaJAjwXI111jiB7Rqfat>nRU@xXvaR?KKdNI|C z!*wI_wB0zUW2snNj++943zRV!F-wGCA4O?M;V%| zXtJRxil!Kvs%WaAX^N&9I$F`uhNdf;erU((d}f0HKcn!*8T!nGXof2;z|THV8;tSb zCkw`U@UsQuJisqQP?qr?oU&ko2l#OaN-@!c|5z}|1N<-qrI_qMctNsEV@y$Wk)cx+ zU2NzyMVA;lUD2h6&QNrjp)(a-Zs;sUR~S0m(Ez_wK_@WB1N>M8fw>;wrz!}{^8mkB zL14ZI__YcGnI7OLD+ny`06$nkV4(*Q3$h%r?Y7&t+ag76yDe7Kw%Za#ZM!X1)VA9) zMQyt+SJbxK3Po+Zt#mX=Qaqe z_uyO$Hh6$v+#oZu5g@c{o18e<7=zs#%@xjZ)OzHhJvDoSdGO*p6oVJvDcNqM+vS+GzzNY@5Ad@glwvo)Ib_q!&SQmx zm?P!+MB%5k_qap>eqe-Byy}42rl{~PJnw6sq4xCYb3Mu zv~9KCwAEXHVO#A*IBcu8ePYvAd#o|s=c#Ecdb1%Ry5F(DI2!snBM0mr%Wh0#-f=82 z4ksac&;$I?38i=!01ahMgc{0xtpCtIC?+O{HKnGY2j)S;>VJT63mlD(9(M@8k@O)@ zc%~n-q@Vhv=A8Cm2K<>~m;vWYwi~mq&m9XwSNR2iDTH3LL71J?;NmKa1SOZ{{mxY zlVQ&0dq;y;tjYYrfj{CqQWbwhG;EKb5H@FEhjp&$l|MUby6WLE2L9rp>8gh(nyz}v zAB(*_G@%k7Vey+N-Ygcs zsR`w6&hkEkusP#$aqQIW*|lW}UqG0*TSowMdFlQY!ePTFGTzm5`n3^+QBr<DiMB#kLLG8U~!(U)V_Wws0YjBe=agy$_>Hn@RN9$2rL$sH>r$;B)ub#3g9)7Nsuq~X zQzOxHT)jv<*NI`hyAeCjG5f44ZAf|$Uhj)Mcskyk{>2^`OG2Oi_rP?3Nc1v*@cLZt z#qio+;Xr<*Z$E0eD_P>Jo#q}Ry~cyyw(YO=z&wRXn~5xY1t;c52KJ$oyUE8B26gRC z;ARgZgZfa}x3J8&IxTn^MbVchnRvSwGvkeT2NNrLG0a(siIu(B(VoGb9{gp&T^_Ww zpo#~k!$qQ10mAmI=EZPK*YKbXvPYsd0Zgwa2kXUfDAx8Mv;cJ+FgHyA}Y{utRt+SXjn`P7j{6P5H0~VQW3&LD+eldC`kbIh3$NZ@P?QGxyr4J&Xa_;-h4cka%Y^MfNjo}dJ4`~flLPtmkPId0?Blc* z3(&=bNOTCr6J0zQg3Ff>?dm{&WC${J^YMfs<_O(AC_?~AdUz6vqGLu~JP4g)PY3cN z!;qnuk0%T>N9gT95W2uV9)v!luLohz?B_u^GW&ZF_RIku;1?yS*uVq)o+N>R9^gkM z2@LWeY>mMl;5Q~I#SjnhLz4uCdVrsqBrwba{MICa;U0v|F~S4<^dzNt(F6ScB!QPa z=uB7TbS|-GfZwP5^Nd~MNMBOe&@X!sHuNhVn1-ewnFBBboF4Q+IGiD*dQOu!m&pwL z>ePp8k*OK$Q_v5gvz(JXr<+bU(-ARSFkj|6p0S4hM=estW3wtT7z!D8D51Tn=2O9j z9M4!!|D(*+J+_&Fq0obzEOVt>!jjG0`a}|b;H9!+c;?_vu<-ovxRt`;`8P#4 zL5eWWDEOBC&_O$SaLj_v9$+FxDY|$NPN)+-2q)BCJqRb%-8={<)ZIM@C)7PW2q)B0 z2l6Av)b?cY8dQs3EMAl1y;&SaxDShC+0&QBVPgBSI1FZg7Ka}gz~V4`0gJ;U42;EV z!W9fc94#~=p<<0n1O_uu6JQ7fwE%`PP#a(v19bp~Gf)>`1OxQ|USyy?z)K7?02t{( znTphsL|*2^)b$lkOl6ZeF|{4ViK%WfC#JqBoR|uya$;(n#)+x&XiiL>(;1=GrGA|O zV)`;|=R5U}go>STLYWM723WvA7l4HfBm!hH&=p`21Kj`?GteDi2?IR4D$>1hA2T!2sC| z3<220z)*l328ID_W?(qL76wKDYy~jZCS1gB^B|laZ}%WH`8zxaP5w>~!dc%g587A* zmFt0dMUVFCJqVXQc^-uBc#j8WqDUL{9(1IGp3ceD3ff2Ln;>Mo&urcInlGudt^VsC zBwFx>2jME~O%K9({#zb|OYXfMgiEWpJupkFgy=pG`rA_Wdk|P~z=J^+yyL+T3l4fP z%z}442xk+AJb1~bIP8I0PSKBEdJuMr_dE!@#QPqEUE%`|!Y=Wl2Vs}^$b+y;eC$Ek zB|h;W>=K`P5O#^rJP5l)z6TxcxqR+Hc;&wEAkn7y(u45IedR%T<-YbHymCi92(R2R z55g;V+=KASo$w&Mawk0quUvr#;gu`&AiQ!#9)wq}*n{xOm3RNOUISvplCQqr2P@6HxJu8>tHMis7zdL@{h_ zCn%Oftc+r~X?B)kTZolaY%8&|728Ja9L2U1J6AD0VsV~gxF2-BVtBc-oMO14ae-pH ziCw4|9@xG}u|32tmMlAoSb4=p5xYb&+zGu@F+78GnPPYb>2k&JyxbLv;d!|$6~hlD zUZof&(pM`shS)WV;kOd6Rcsuw>lDMUC0?)C1Y$QRhTluPQL#zHDkz3Mo0}BFrp?WY zVb|ss#jtI2t76lM-KN+KVz({#WySEZkvkQ`$42f_Z2swd zZS9}~`C9Y+`SCP5OZhb}TBxbQGN}Sp6~l*2swsx2jjMx&MysRJ@w9O#rgwI_**@Ek zHDVWs%INgdhk`e zS=sgVpvZ!L9(-v*e-DlW(91>uVXFjA4C{+KiUXNGSm|3yAHwvPoF0T8ccceH=xS4g zz3jkX>IQN9U~gU#Xg|zNl1IjbZyH7Ai~(VIfLml zm5xU(XEA-Y((x|99H!4zI^G4C$MpG1$GZTTOkbdMjLwBj&r&)@=OU&rRyy7VSi3Do|1=Ck59q$6HV)|;OW20yd)7L5;?*go2`g*0~U4RWt->CF#(zBVq zN$D7;IZWTIblhIw!t||5$0Nzxn7&=mg(lP$uVEUU%$M}DX>3fx)ema*`C+JMJ%KZAr_|m&9ddY|tyiXMj!?K_0 z2b2!O@($AvDjkO9U8WyWItbRc+<>u|#q^(rUXq8t_zRf1zO+uQ7Un;NNzTdb znE1pyX0FM}?f8~mL@}%@6BNTds*GdycsnqMKg%(Dyq#EQm37Rf+llqg*^Y(jvWT7I zSeOp$&vP9!=?YR&?s<}>;gQ7i9W!|g(lCE6=a|hq8tcUi6vLY3LdB5xBFWNGzl$BS zWu#*bUfwZVMh4pS631-1u~@TQ>X=P84(sj9BpZ)4)#Zv|4RnQKSifKCm@Q)h*2h;l zX3Lm>ulZc9*s9Yxp1MJAay;|Sqi!<3^p1xXz_PH3Xz*(lLua~9vPoD_U#}Qmn7Ki+ zd00%|=$Jk6`3s3vaLk_g5?sKWBwLEQ+^iTD=(i|_i*T!A_~_$pj@fdTVWZ}D$85Rl zu<*V^vi0Z?6(!q%3s_0AjabN6cFdNsaWSzw9kXR@MBcj`v+1&NPq2z(HeEJ0oT^H; z4IQzXVi-Kt6+_+{iedAnrer&?fmKT}4BFa?VbIo*Y!^1Q>N;l6V;9P(=a@YY`c(mX zv_vs%QZ$fkH`>0TVvC41QViGaZprpw)2Ojvg&F9R_b7(G+r%+b=fW|lUsK0SoeQVq zBb@gthV#A8F`IWLHka;q%;uemKK_7Wcv0*@#b7`ll57@?)WeS1GG^iWKH``yV;(jr zn>l9F&BysRR}9Xeg=04FT9omqWb4pRA9KteZyoB_(lMKNJ=*?p$u^+?9Y#I!IC&lm*VQ0yvVG%2lx!~SS}(=W&b=j@hje`;TZlI8 zs~GxeKgG}|`%AVIHf(@o%VBo|#bB=nO127pZIENOP1m4Z20LckbPdMG5XrJpm!Xp7 zpxj}S<)ZzDOST&uydxybgMWL`FGCrF?6sD z#V~lrNHzwYbF5-;oZ}S3g&r^29NYz%pco9-M9CImk}=6KbD@hDq0W;PL%U3I%wFha z=)_YUvw4@J!%lO|rdxq)G+nZlD0hZr8*#^JrexW;vogyuTShh}TC*LqWn`lb=18^) z8}4%@+X9C;&oO(vEig#)9ka*VitC#x*-o_I0>^CLT^J|}9kY4!aDB5Jv+2zHfQuXp z(_s~`Sg?|048|prrJLmYXHZ zg5laC*<#drt7J=XEw?F#vASKdpR1 z5!>gOO}7gZ>HUhqh8<80edry>?D2M?{~dHJJRY3YyOQNjBz8!#X~YgIhKcGC$7~t7 zsPlV{*)n!x?7y!VY~2Tr*}Qo;j}H~Y*!svZd%V0X+I9ID%Gho+^detO6=~pr$xtu>v&DvrVPCqDKL~vm z1YuP4bl$#xFojC!b%x%ap2%kf&T<7(Mdo-;)*NB9(%>@mr^1P347>Rn&ZS(LEZ0JW z(R}9N+7rncCz8ifk}Q_wZ*snJW zSfE;xjmAu)wq&Wv#Og>k8djvPVz7MmBumAps;?L>ZUe>Ah&7aKG`wOX#j=Urtr#pz zW5r-`?@4=9GE{DX?Yqdue!uiHv)v_2N8j$D82WZp zG4#crilN{2QVd?Mw_?~X>Z2G;XJ5%u;i>vbmX4Wqf5k9686a6I(gliP#y3#0EMkKc zLq8s@82a%L#n2arDu#YHOfmGa;fkS;jZh4I>_x@U$6itleQcy+=sPbfh8goKlBK~P zBq@e#K1wlM-(<L%FGvrQ!OfDTZ0)XvJ{N(~ z(bLjb6^70}RxudGaf-nxj#mtWY=UCwbQ2ZBO~grHX0S%0lMxPQS5sZuAkj{drg_lK zg6R$z7k_d)T*?f=3g%()FjKIT+u>$rDTXdLTQRtvIgT0gQ8XQwd9GtYS6h*J4wytI zx0~sYVwh`WI%XY&30lk)+=y&qmsd6&<$}w7jC3xuBOQx*`MgQbjjT2fa+v z?~>PoUashjRM0CFU0}}mN<}xWMB1wq-LV<;YDxc32)a z8DH-yx?sicW-t9N%T)P>e+d7YM?xfeBZSaNSMZ5U-^JZ+s_RXP(!FP*H!DiRp6D%- zV&D_KRnn6?O^e?qX+hdLq`h6zliSUhxI>_SXca~0o9kOu(vo!3&#OsVK(|=w2-PJmq#H{_Ybctv8nmXO^G*BK zlC)@P9@5s9v|#cC&^nS9joATOSJL85i$Lp1TC~ixWPM2s#+r6$AnD0nOK^mSk`_!c z{jrgv>y{(!-I5l~Ge>AF>B(Gk-R_aJILBDHCXyCRFg>cNq(#e2kGfaVley*!-6v^r zx@qcLVAx_Pj|g6|tt1XCnu-1Z}9;~yVmj~-D z=;5})jA{qHkTB%4zo|9H8l9At}m5OBKHEE?H7_*k>cm~<-!lr+Qc!Nj=UhPO&kk)*n?#_U=xx1qxFMhZcB5l2SaSGaUP7YV7v#zEtufJ zPzxq{FvfyO9`vD0aLd^a%yyo%rSGKh2+xc7MWmhXmpFrF_RbWj8+ta z!I{yDLNK^8T2VM=%77!I6@_E=c;v=tMIl(x3Uq+El1<0$p?Qu4{p^X&cfcI1WYj83 zlqpz2Do%ERWE0GaLa@Rd^!Y5oO0uv6xkxa0EV@4?SixwlZk7mExDLAlOC1Xi*a|Q6 z;2jH=dvMT#6%Lp-E7*pOu9cEa!p6@k$80-}$E|?XlC8&LdyQn|^y#*kU~u_#TTC!G ze7Y?r7~DPG784B4o^FdtwiKH)*^cE$YQZUOVsSX792T!n@y#p_r?e#&uU-9g-nT~Z zEw$W|Gxok)SwZl2+gKdlZaa&^+wEZS+7#c(;_!C6SR5yw%i=ik-7Jn1&tq|%_?}q2 z4!rTJE^h85)WBq!Zkh>L)56yUtYzUF0@k+hO#$mz_?CcmE!-<$JqzC!u)c-+1Z-g8 zeh;yVsZrh11Coa4^p2$ANgZ@FKhmQ+o%y>yp3pS_IOIX3>kx_`_VI+?gAxfGalnkI z6Uo@ZdrvVq-}e>6Ncli97>N%RgMs--F>LF7tQcI$CyHUa?o-9GiG8LRMtr_vTZnzG z7_8(MiorU6sTi!qSBmW>_O)WTd3sc`6j+91ieX}LT(Qx_PAG=Hdr~p%JryX1eWpUi zFtI374Bn_%F>E!LD27$SH;PRq_N`(wh<&FRywSfD!yelAieWeJ2gR`c{G(!+_552g zc*~y@LqGjlG4#`46hl8fr5O6@uZqDr{zozN-QN^L-~C-NOeX(O4E^~}#n7Ms>zMIO zCsN>S|56Nn{C|$wahbA-*x!zs8=xn5EiIUe%N|$DE&9mJ$I%czkuv2(N-l1F(th4Q z#Wg2VW}HYyqelKI(jC*e)(Rwe5#Jp$hoxiU{L6U77P$08%D59LIVX~FGG}?wW+Rb~ ziD6MzDa%hJuOg9@v%PYWDQe}3ht#T+^3 zbkmxeK}A}DoPWWYZYo@(3Z}|Z7oa{xy#TFpt=DZclTIg2rwo&Nofqx-WJ5_thr3=W zbd~7>z=YrMPlb+#DgTXLu|;h`CD8XV(kgh-HqaJ3m`qi0b#C&y&AiR@g>WR^>_uD8 zT{bgiyXF5?U@mTzis?M|+-~!V=|3syCz9b$Z&!GXt@s@ZQ&+)AsHpJR6De>=l{_{z zO_}KXPGzM`GM5Mr^-iytrm-e3*`6cLhrMF2-vZO9H07Hb}AU5-&ZH$H12L_KH0kDO5KaV5r2?UbIJ} z^Mw^|*ipdx7IqS_frXttv};;RyGRP%JfTac-UP;YP^On9V?BxV??x%c#o~PtAMfH} zHNhq*hW(+5j#1SSpA?JtLVR*8-eUyCr}%h6F9W8=Kpz99#XxrhrpLe_17!Sv&Ham2zp zZ1CJX@NPM3vC#=MhEUn;SiCRdn_N7+IAA%B(ZxZ0b1dE;wrfi)-WTz$E*>5OY@1_r z48*s`;=K^x;o?Cj+d4ZPpo$Kq1iNDKzKG|#cvuM7ZpWw)#PeeDUWo5;@t~_M;=M7v-eYkb@O>Xo=-m&t=K~KSy@yf!Ll+Mk*%Cf-AU~l`6jtG52KoVf;z6W; z4{DH45f2;WGp{A|?~e-Qdl2al_xX7&J`nLQSRCEy%UFCUTJ$RyHzRcjT?8EUYe74O z^r)wp_|?DzHneXnU`>Lj^NzKHk<<*IpRsp5E=sFqt8hZV+7_M^u#SZV0@k&#P{4W? z771A2!eRj%SXkm=ctgZA%QupSjrFahXf0~O?<5V+>R*zEr}e$0;d%WaX?S8kN*bQo zzaN6e~~miw^Nda=k}|l;ko@s((v4VlQcZH-z5#t?GH)AbNf@$ z@ZA0@X?Sjb30f;WxBp2Rp4;D!<|lNg$ql`nQ=7(Q_^j%LrEYxEv%Lt1{B6dMFn-r^ zm!4iqLD)b0^v#@6bnJV=Jv8Pl6P zJ@~?Y8nFcvA9bQ}65r6fz>(-&nBG?D`101XOmC-je0l3Rrngr*zP$B3(>o{~Upsn%=^d4h z2gN%vy|dEs<*hDEPgFWS>DQI%-IR_``gLb|52ddnJ<9Z+O2;StdNIAX((y^ZK1@%N z`doDGQA|%(Iy!d>(^Hj>&Yi~e(Mm_>PG@?C({2Bni_SfU>0_O4``29a$x5b=S33Il z1g1|^I{Nn{rcYM7`DCTjPv<4;1j#fa?!S=iz!I(`zanAI7W2^x8_tOJQ}G zURUY(qGdg%*H=2eXxV`24V8{BS~g<(-Acz7EgLia9;M@pmQ9%6RO*?=_c8rGr5oSJ z^aqq~d>_*vQo8YdOn*e_#`iJ3xzb@CS}^@lr5pFh^p;9D?vLrMly2M~)1Oqjaeqv2 zt#sr5nBGR|#{Dt9tt(^d$;5zs#pOAjKdKvyrW&p}V}Fz+3tnI*0XO2;tFWcmW7V;C-EdX~~L3>PtdvC=UNmoR;)(lHE| zF@3qxF$`BQeWlVd3|BFIwbO$UcCxU>gRd=E>%j>N);VB5LBE!|*m{S80(*%!0EDZo zjZQRQU_XF|T(TufC$!0-pwJeR!wkn&5|vEQ{Dm=7PVFBaLU`5zFp~X$~&08 zQ|WNZyO^GJJ+4->!TSWs*mZm$ET z;f`&^;}mZT_RT_k0%IRo*l_!mj<0AO@H%}G8sTu4?1)N>A^RRn`@T<0pK@mWL&iVy zoVMr?j?FX|VhDf2^iP$JA^e%wBhh?>!@B+C(gv+)?oKEEvj=S~_{D?X7Myax_Opff ziGg3i!lwDn>A};seSi0$o$c&@_|!B7UFj-AKmUNRIZ7njknyIB4`V!u@x6>6VmzPm zql~v+6_$HCPg5@#L!RbRx+Q%kD<4{3qmb}~M!Ev2xsn(^#Q0&x^BMn&@xK|5TOB)o zJ%r6wrLWX5-jeZFjJIRFJ>zdM{yF3SVLYD7ap!e5!eP1RGJX-`hZh_OjU+x2)DbM~yiu=XQF{QB z=$>AtpY}kQ{-M17J}H$ScWh!7u>p!LB8K#_;d*T1Vqyao!wV9F6kAGcuwvMs9irHB zVnY>ML2Q^}D~SzP3=eXQPz;Z7zNi?U+;~Yb__2|Stt0lbV(W>$q8OgTNm2|?zK&81 zkMSlewuxAZVmZW8728ZKO))&uK3cJ@#L^W*-^ox64_A#*4D;Bris56J;}pX^^YMz| zQJD#f;X$#9is2=xNs8fduE~;3N+LEzu~EdPDwa%anqn!$rYn|8Y=&ZZUumXdqlwK@ z3=@>uis4zZIf~&%-dx4-tmiz%#u1yZ*mz=@icKK4Kry)Ug^J+`u`I>#)WssjrVv}K z*i>Rm6vJF=sbZLGEK>}R|1Vc;Cb1QY%_6o^F}xlVde zShp$$!@5l|7}o8I!LaU742E^5Vlb?`6oX;SRSbr8w_-4?d5XcX?okY@`d7iiS;zMX z(?2Zee`Nd*#^ct;(l7lamVP6`;c?z({2j*s>p8td@jIn&L1h`=TAYmmA1_$pJQ(GO zW5H;lJ5!S5HQ!+%`pn8{l-2bcdM$?{-3FBYtLHtcwL$riwWTq4;L z_?}AzD@le8yUa0LmzA*Xmpf+aQn(po{|dp1QeZc(lxz~#nO6x`JQ@DzYQaj<(2cK= zYz6%EwSt}8iMm`TSiuDN-|Gb{Tnj&QgJ4A&sPm1270<>Hs32I$cGUSM!3ws(j^8X; z;T{aLTLdef1z&NiWXoV0ZWF9<9DLO6f)%I37T+OR7ED(~$ISI8FyG0oBv|2m*!Ief z*=w`~ZF;9*MdL6(xJ$4S^Q3OU^M10)g&8-wyG{z;WV^;4awHPm(>)k z$UKo)OR{+|g|!_EUbZ8xjsxbzif5y8bsaN}QalHar=DXr-8M`J>kC#gAH%zWWb2Tw zp=8@IU>Z4Q$|zcl$-&)@nKFu&VX!rpY%6@rJ%SZa!Ub<4Sjl)aR8z--vG!!|b-A`c2yJPI?vhXgAc11I;eWJ@q(dPK0|9E`qZf|bnM zb~;bqAect>?8F&+^5&wjf+ZLtEhNiEq^1#Bx=@g$ha zX9X*n1GCspuwwH&D9;I2I1X*l-mzdJT`vO9J7Btg@fsA`!7uf)(YUv%Dl&@feK0k&>-J2YOksl63Ui zR|G257gm;I9SeHet3A#Ed&TC#1CEz$9c=U+1S?8I51205RInM6t$>r6>6q!EMcXi&pXHc2-{Mi| z6|*JF#Y$?9WYf??=L%Mmg!;{sYy!%iFIYhaE=HzgW07}(WK%JHT_{+QdD$&Xu;L}? zd5ati=32YD*nzO;p;4Adwg=sKsbGZ@VDpwqwjL+DT(F{z=%FhlGxOt>g3&ALlx~$^ z1@mCfS34HWv=v_CfUWRW7^Ag<6(+$;trM(h;-=F~3+U4*3+U)AE~cg389n^7UKTcG z6;)t^WO?YS8wD#Kg<+E|SV;!D+a}58VfB?GStbnZX34TJ9oZt-$vn9Gt%4OT$CcV9 zSjlLVyIr!m@H#sLD@?(r#7@CZ?!^%z zDZr}^m@8kDK9Lf=CfOYH@z(__o|a4O4Z%uAfxYQiFwq*dw;V796wXBp?-i_MHqPK} z!3xG=%CRkw_mJ|7sWx+yz?pQF(8i+3(Fegzm7k%?f!3r`kKEIM|G938Vl4WDk zaa6Fv*_g^7lPnWm@wjA*R}woRnfbMilY$jZM*RvTn*}#nDA{gU!y>_om!QtYieY?~ zI2L5sEBlQDwo&GxfNupW7>|MYonVDKVO{?vSixj$pMEb`Q98QV50XuVG5S%k;#oM} zzXdCq3!nCrWZAf~KTEa~i_BjHD_nqdrzG13gZHao#p$>h|8XpM$u`Pw4wyzMT8q`` z?~-l8RPPVT#w8K^Q!?|z6#o^hcpVzxFTqakLf-!gRy-co{cphvGSEJMg z6=YzI67QI)bHUE##3F(fjzbSk5UeN%tM)R26|BdM@+`p$H)E|(R9mzPBQZi^$R4Ml|-An7lMU1F)wzyZJkB< z6_D~wzeMPTb2guD0#GAZMs1vPh7*8D^io#v<*s0Rg6U||D;zVGEgBE2ccoRQKa8OvcDt`n>z6W!o?$7~s!Fh#q;v0x;w5`9D&AZ+Oh zPBa;cXXAGAO-#Sp>89Y~HQPzQh3U5my(9@Pcq+e)p}RWX2mck}Ml_x!bW|fE}KV9WV`0 zm^_^l-Q$=kv@i{YHgU|R8x0rORI>C<#O{^Md};VT$L#TpySv{pd%U@5lm{eR41@Kc zWLt329&*ecZ#$-*4?AX$mkW>gh+su&xVX(6GkJ?LFqdgA*<|ExA=zTo?@`BsoF_?it5|Ogp1$>wwKj-$kd*J;`?9VC^K^jm!U>W2S)OBwWJwj+x^X zr(<{GdCAPjP+xG&=A8m(-_bFfcPUz~lVdiW`MtKzlC4Gkx+sPjRib0|cscM!T^+N> z+l(vL%`uxU4?erQW5HV6P(2(l8B5F;L8Fo_#4M|)WLa1&^m5D;P&f*U?%tl2p$Wi` zOUI$Z_VEz2g5r$XWI6kSnH!+ATPO6B+c85J;Fzgc!Dt*jaLg1~UL9$6`rHPVF#*%lEWK(eVlO>x0qd3K}V5u#1st1!TnC5^z z$NBRp*L25h&CE<_hGW4nYhGu1FwY)omIsS0nC*Z)%q|>yj$^jCU08t3bu7rW8Rt1* z5)~z37B}CqV7E<_>3}(U(E`jg7C2@zW?<|tbj+q3i`h|@W5Ei0utg5oj8kw=X0c;7 z<8&-Omna5nv{bU$n2sz{4C}Gwjs+`ip(`A)1(=`7S?QRqhm1LQi{H}J)=FNmv zS>u?^y9D<});ea>t;UJ1b1Zn(R%E>cHc>XtYJ+53aPc-e=Dc0D12$tWrpKEc3tqEF z&vC#cDxQG8x>>SGxF}m3J4N~8iZkJIwmN3>E`w{@CfRaam+g)PZ`eY2IAAlbhAY|W zSg^(>+U0;vWPW8j*RkMDn`pNOGc3q+;1tE~SpkzxM7s*otC%AO1d@oFwO{ zm?JrhhyfKv%!&b2M2`^%F^5CWaL5@BIp-YBIe`&S?^O@+nlLM-Uq8K8KfAlBFZCAx zy;V}hu9?sD%=FA!)7>*WoR_80a}K1?QpD_eXUQv4=miH-Xfp=;FFNaqtsm%xfx%0m z*&qLYIkZ9OWM2twA_o1hI!j)aoxVm`DDb)i*`xit-)}feUXwy^IV&l$X|-9?R{tV2zKY7 z?f$@-Ew?)d+4P|^+4Y=37@d6-;VKN1J`Qo7z4P8dG>4lyu%(YFxHGh^!_5d|7feSO zsXxp#J_5BX-L0D`pXJSGoB6aif3KM@!1)5*x}iWpA5fwYA>HGlBlY49lYOS1eU7ph zPiGgwj`T3fyPeuI_u=Xfk!}@Y#GQ4;7;%$ODa5UI^~xcx{t#bKs{+)W)(i@KJn^H| zra&#A-fY(n3#|MIH#l{Ork_fEjPb*dffvOrx2_8T@IV<2*TNNE2~2nikW zi6J2yPYMZxm6JnSXy_DBQB%XDx>Vs*mcan_;{_k1tvfBo-Ud%67Pcin+HA|7aX6#& znPj`&TzitviV;muy%^Dc)DLmwN5BRljz(4wAdoVNfuj%IN4&W5T_V4UlIoDPFsfsrr84Lcm>*o1@i1>&kb>gU8}9P z)_GxpS$3`SL!52by1-lO!mz+xyH>jp=UKcc#Q7F44sn6SOF~>|v3-bRKSJwyX^0~~ zLZ5nBh?6aL2ywQ>%R|il7?)2+A}-dQ7@b@h62>CehJ;Z@r+{{0_;X7@J8}PXTS%yI zw~%mPcL%f!k9zJ83HOCbNa&y*4hj9i;~`;e@^nbJ*Xtb;o=o%&31heZA=$f+kZ|)c zI3)CaLqo#jm*FAdE@)Ip7=n!p3HNQ2LPCV5IkI10+=UaJ=g797yAZV50eyl9%?$|+ z+`@o%A+$>a`UHcBzWntrzV3LD5|poP8Y7CkVjKkPxO%Lc*#2%u%vU zzPR=u2lg;O!64}KkZ{NUWk?ug><$S-jQx)6S=>43NL_iO}5-y86yt!tQc{a^&+&}tREw?u0f2* zx`rY4wkM=fgm#;aW5hO_#E5M+4Y7}HIh)0ZHmP}xILsC?;xJoAxD#WERxzUWIy*+x zvvrK9=Q$zvwP(IfjHuGNF``OsBeZAfycn_f^JB!`F9@-p-TQ?xV(;x@#NIE8(C+(e)A9z26Wcj;K?NgO4-}X`Hk*o%L1b zkCq(W`vNz*z1b76WBJbIrV2NOxWeMi4&?+4vUm#+x6JmpKBD=>&V#FRFb(s7ut3KvHSG9Y5++p&MlzM`Y zG8t^P^CY2$z*B^p0#6g_2s}eLRv?FPoIo$ai2}U|CkgZ+oGj3naEd@b!Wjbn31{b5e^B=Cg_zo$AN5kq22IYhwkc`N63;BHlL6dSU@Nsu#iwtU=g8^z+ysSfhB|@ z0!s-+1(p$t2`ncR7g#|kA+XYc1a6HD+$x7jNh!6OP)cA8;TVCngwg`*2xSD;6Uqu~ zAe0x_NT?vNiBM5sGog~e7D8o#t%NEDj?@h|NiH%aHXU_0{4DoWRd)Rxp_;(+gz5q> z5NZj$NT@CF5}~fZ%Y@?vULl+y@G3!@%hw3nT)s{?RaSX}aGJoIgwqAyB53>hwga0d zJNw!T;T?xbJz4EtLVba4ga!iJ3EH5(M`$D^-X}B`_<+zv;6sA8tRFe}*%V0a>~Aag zvBRW=thR&DQedY8Ii>-2XtK*;(n?BwLO5ICQ$lNj&j{Mg{>OpTXRxi$e;vBk@N>ci zvYjso+N^y^xKK*u6SRHWO=u@2_7JpZ-|N60wQF8drN+Ai#OU~9Z%l`VB3#MO2H z{J$8{hJWQS(H#7mpgH&rK@;j*f(G$B!X?8aSs^aACDSpYWPuQu+L8rhM9D%SuCXNx$B2?eLR@Q0 z7L5@li-ow_-pLh@5qEMWV#GkCq{HMgNt{v+Hm1lXG>sr(0#$#}jT7IDv4x zz=?#e0w)pf5IC8jNpuRKo0K?}aHqg&gu4VzCu9qpLC|`fNzi(nMbLWGBWOM96E2mF zHXw8mXhY7O`8+6rY#7%+m-|!@wIZ$(^Mn1W8O~u z`f_Waem0>a3*b%q9p<6F?S!s~S)O=bbr{>ySH~>RvagBQ-16ZGKhY$}K|c<*6sH*$Z-Yt6QC zsvd}0V)-6Az9L9Fr4;{{kPEW^jl;&B!E&Z@#Im!)s@Q)tOsNiEEZ`9I{AI{k2 z6NfW4@?^l~9RNAXrybi0?(D5c`HW**L9nfNj$@pKFaGIOZ#Qskg|Qz2FKEVnNGxRWTRs#jkAWnXj918Hh8n+q=!^(3n3BM>Oksh z_HB3bY{;e|v;17ZXd5g)A961}vKIn27oTkVMaRiQQiqoa_X)gAxL4p62U1HUIL_#+ z0pq0^X{Ambe+Gl1)>kA{AX z7xXcQiFbK^3KpP)F#qwXsh@)d*fA2sEchi{u);i@7--+@{WV;$!R%Tdwfq(=*g4Rw z(bsP3cP`LzOkdj`90J?7#E!*Lm|gE2RL31m9a9av;X2-i{@@z;yUOPD_N{{#yAB?R z{K*~J^RnWTp;%->@D~>7X;1xargxe3%?f2Ojk1TbPB*h61sV;)SW@^gBbRm;J& zlPaGn-og~G;AWGjmy0-cz=Y@3>Tn48ML}6{h)82h&>d zdUW&2R<|CWS*5+00(-W|Q(#mCFcE zNORGVfEzBe$`t^d#^hl@I{Qk14Y~PBCrfKqT|;<8R=<|;n80;}M+L42*d07Ba05$d z;5!jC@HY~klvQpbJSA{5z;5(ufm;aA2y}L<9LlO|4zo*U_Czy#tDD`Gb?T9xLo`nY zn9coo)E)e7Za?nR>9+$=@k3c>n0j<|%MWF>GP8GNW?P%tZf-WIiEx^~>ITr*+~pP? z%DTyv&CbjoZ)We#%${Io@5#)zG26Kpv$~z`ZjsHxI_3u4e0LLuTH3pE^H>#_LjjRUxbA5&7P3(d6okqVMOswNccqXcaD<($=lc8JFu~~Bf*~? z$+g^f2NLtw7?GO4$B0b)BS!pPpTB_ivQB6JgK0a4F@Lu2ALr(s1x%x-O0*+LJ2;ee zoY`;zH=Fd87P}x}m_Q-IaDl>vegZ`t9LhS$Y_h1Ebwi3`1npUh6Z*>*N)YtxLnR5? zL6!obiAn~^D#s9VrIRh~RymY)mZ?PP*tERp_)K7fDMuM=G6(>-`5}vmV>WJuw9b*lrLe3DRG3pv~j&; znJIB&1yky%p6S=-o^+^DhcH4acPzk$>QXt4#}PUR)FtR&|w8cMH@f+$+$4aKAu9 zLU(~ighZe*;UR%0gog#15*`(3MtEGHIpIlx7KEn-S^{h)_Lfk#A`BHco6tv~wSz-h zx0oyD95N6_pzpP<=s0YS6lLV{*TJA!7%MFh=`iwT+? zmk=~N+7r6S>A94k*>M>`v!eq+v*U7tW=BVYX2%r-&5kPxnjKdWG&`;)Xm(sf(CoOD zpxJR9L9^p}f@a4J1kH|41kH{c0X93_{eXi*Sx=hS-|S`+y*;?a!J(|D&GOEeMda-e z_shBHbGt-_PWM)4iMH&w5ppEyZYT5-=t{7+Pi6@3KyK>#;456+oFykoH+`oADbyRo z$Gaj!kDMJDI^??}!$9z!$S~}?H?%(3-hGi_d-q3%?L80~hBDnF+idJXXUQLOjU|LX z1$q$v5_pL4w?I$AKLQUE@VAf6ULGN22|P+j3p_?BAn-V$puiJ^LIO_`3JW|%C?fDQ zp{T$!gkl0YgyI6d2qgr16G|F5QtwzlS#2`v#R{g>QT2{}xTjLG>%N3z1o{z53-l+H z5g0%yD=?5yPGAtByue^W1%V-iiULCkl>~+nDhmuJR1p|Ks49?4s3tIyP+edYp@zU{ zLQR1&gjxb)3AF{r5$XtxCmbsu#2Ej0U6 zkJBT=j}PX-7D*>D!!1un%Y`(PFh*b&VXVMx!Z?9Bgz*A%2@?e75he=ECrlDpK$tAB zkT6AH5n-ypV!||mC4}h$O9^=b%Lp?BmJ?Iu!=B8U^QW`z#76lfwhGB z0_zA11lAK43Tz-O64*#sEU<~NL|`*vslXP(GJ&mx z=We0BHGctj;a`M=9{S6W@E9f^WJf=r$%VcN4fSCQd~*w>Nak^eWLjmtYy57;2tWO~5UDw--DRS)=WxU=#2 zB++*;d%))5L@JB#UzEhOdMVFO^894aTYBEg^VXi9<9P?qJ9>VL=Q*DL;dv@6Q_ljJ z)_NB4ypiWkJs;tDuIE!d&+~kS=i5C0+w+`sran_Kt@X+Ce7onLd;X{AsREhp9FJ+; z&KaJ!_q?O$Pk5f=`83a`d;XH=uX+9v-Fzdyps7Q9+!dI#OC8M3#q-mw7%`Mi$B1XB z1!BZg)PgbM0xlFIo}?Cz5zkVK#E7SiE8l}@l3Tuj2K^(j1kXOOT~yM ztH;EMXRD=S#M9L>G2;1Z*%r;z@7K7;)cOD@NRS){YU+d+WrAC%(tVh)=T|7bD)g ztQ#ZV!#O@iyf=A5jCgbM#2E3;%tda9xbk4X%$d&)|j_XB??ZYnW^?ZOiDR z?$S2Kd&8(p9cENzJq|XF zhz9cI7|}q!5+fSOS7Ss2`C5!K7xf zul_OO`Wg@;uCIYH;`$mCBd)K(F|IJDaR^XPTT{7SB_K zGuv-k#ML&P-3HUT-)lYZ;`v>k=g>`>VcK58=B70DX0AET-XY}GMr3=Rob)(}U@E%I@; zp@hx`j@0KiN}e@+?jJ|p=MHmwviHqjti{P0PD7<%M{_qKB(y=f0lk3>cVs}XnOQK%8YX$WzbxX59oEYF%trMqpzWfA)zUm6cQSe$&QkN z`rOii+%8SEe{6Ls(MEV028q*X_GF=1nNG5|T2nV;B%DXInSfPikhB~I$1@!!$IFq= za$t}Abu7LK?e7WbJd;X*6KY9L(=YM!!qgdv6Yhzl^ zLkrK(@w|=aIi9cge6#1zj~f3p~riqKBRH-yvgC)D;?dV$aHoS>_ii}x!a*h z{A)eG-t!)wKkE4?&nJ35)$;|OFZVoEG85Q~F|BPy4yN0iZcHD0t-=-FD@I)7y<@~x z-X}&p{^%Pc`k8()qS5akBU<|Fh;b^gJQ(vkHImb;TaMm9)Apt5syEH#fZlr z!(&AEG$KYcw7D^2fHg8kj3P$Gh{xumW5jdwF)@xYI5x(y2FJxX&fxeManm*-Ml|*l zW5h6TQjEB1n;atsB~xO=C}e7kxM`afBL+;cdwJb*5 zy)BOscW*0V#M6o972SKj{2OeOi;`MboFfdDMN{A#aDNvY7*IjA=d4CZ1p9c}LG5 z@jS=#&prRb^PfFWmCNk69Hw=@te**PYdwp4UflB%o;UTph373jZ{>Mw&(HDvBF{T|-pTVWo_F*7PS3MF zzuWT>p67Z#%Jb2lPxL&`^M#&&UMq9ne#f+nd+m&u#k6`k&s%!l+WC=2%*~QlO)Eb6 zC|mJ#b|-I#%iRu5BeBBs=RE(x^M5>_R5x=#Df0~6H5dFjwI&+qp9e$Suv z{5j9x@O+!+-+F$~^Itqq-IJ-$g_zd!(9!cwp5N&CZJyum`Jc92doiryLi@h^HKv z#E7RH?PJ7Kj!R?2Q;y4G#8ZwAG2$u5fPl;esR@s#7r81Wg9t762P)mO)e zH>kZxz;|7DBV#FI(H^zu}t#68Pv%#BV++y&S81Y_K z=NO+gZB!SaUZ;~W?b?S2GTt83>X&;y(DMZj1n zrGx4AXt427{DV{bjW_?%mUfO8Owa{gxS*u0VHcQ%XvA*)zZRk~yY2s4h(_)9|7#%{ zx32%!LOja70}C~UdSF@)^9j1SQ{o2XF#B)NquCrU*r*G(aDg1Atf7awHC|}f(uL2) z3+=wlLY#x=;)QO_W#&kp$3i`luQ2Tb`Ci5^#I*Wzo`2x^=br!MdFuVlcCN#;Zl{aq zkI~IX$v-e<+M6gRmzoz-`z(TfwKz@CuND^|=vRvi67;LZg$UQmMhg@4tHnhK`qkp1 z1pR7pF@k=zxHzGUY_tU7Hi43at^%b9`qkoN2zN<|(ggi#aT$Vs_M$97zgk?5pkFO6 zPtdOxS0LzDiz^Zymfcn&=vRv?6ZEUaRS5dk;;IDwYH>A!My@(RBUgi0g3PDriRD!0&X#`D)(+QdqXAm?c&Ln6`oJG)-s7KJ0s87(8Xh6`EXh_hM zXhhJIXiU(QXhP7GXiCtOXhzVKXim_SXhG1FXi3nNXhqPJIGdm;(VBpiFwM?61dUu9 zf=2FKf<~?_K_hn_K_hoQK_hnoK_hn|K_l0WppmtBlieFBljplBlj3VBlkE#BliSBBljdhBli?RBlk2xBliqJBbP(a z$n_#<2sroo+ro=dc zro?!Hro;q-ro=>oro<$Iro?1|ro`oD_LQfymjLuYmU5wG*oX8G*oXAG*oX9G*oXBG*s^pG*s^rG*sIN8mjFC4b^)D4b}Su8>#}?9}u*y z{E%SdRUrE#g1u(UpKK>+&~^|sXgdiSv|R)Z+9w1J+NT5!+Ghm4zWzhd>+8P+jojx1 zjocRmjog<6ja)uKBe$ENk=sMi$n7O) zxo-&?x$g*w+>tu92FbgoQ)^lEXgjro+>@rn_XJIe9|)QfKN2)0ej;c}{7lf4_=TV; z@hd@7;x~e(#P0-6i9-ZUi9ZOM5`PjjCH^94O8iaGl=z3BDUtfnv?uLx(lsTr2$~XU zf~G_Pf~G`4f~G_vf=!8Zc42_FT1B`}v!N(Kv!NJ4ujAqb8?2k*P+|$W$k2 zWNHv>WYXC+0a}GxT&O{*P0;JK4neQeV+k6W;|Lm=x&)2P@dUk`P9W&zbRt17r;`X8 zuagNHuTuybuTu#cuhR$`uhR({uQLc5uQLgHIh{q&%c&kggI1rQL2E$Jpfx0D&>9gm zXpIRPv?c_-oSG8!a%x7<$TcVE<MP~&wj zLF3hypz%77pz%7NVB=+evK^p1xR48NsM6W(yoHx=p~j#+L1S5XyhIuXykelG;$9UG;)s+G;)s;G;)s-G;)s-785jbO9&ddr38)KGJ-~KIYA@0f}oLGNzllxB534R z6Et#b2pYMy1dZG}f<|sVK_j<;ppn~1K;(|p`87)3FPKV|sCKkBbDOv)O^M9}O^Gc8 zO^K}pO^Ig-ni9_uG$o!VXiB_5(3E(QpegYZK~v&of~LeP1Wk!o37QhG5i})UCumB% zLC}CeMZp8{fD5D`!7Kw_c=i$_XR;C_a#9imru~h z?IvjC_7F63dkGr3eFTl%eu75s06`=7KY~W?D}qMuYl24Z8-hmeTY^UJJAy{;AVDMd zJwYS)13@GABS9ng6G0>QGeINw3qd3ID?uao8$l!YJ3%9Nh@g@CgP@W7lc16Ni=dJF zo1l^VhoF&5ePr$>+N0&u$Yl{Ua%qA_t^h$JSCF8QD@4%96((rpiV!q%MF|?YVg!v` zae_v!1VJNLlAw_*MbO9{L(s^TCTQf!5HxaS2^zU_1dUvIf<~?aK_gd@ppmOY(8yIL zXymF8G;&o58o6o&ja+qtMy>`yBUh84k*h^OrT+fJxI{VB?OIJ4}wPSA%aG(CqX0kFhL{t2tgzFC_y9l7(pZVI6))#1VJPB zBtawh6hR~RG(jWx3_&B8L(s_eB534#6A-y0b$(5fj|-+!pHw^A&aV&mq$$ytpefOh zpefOxpeZqcpeZqspeZqkpeZq!peZqgpeZqwpeZqopeZq&peZqeped0{(3BWS(3BWO z(3BWW(3BWM(3BWU(3BWQ(3BWY(3F@!(3F@+(3F@&(3F@=(3F@$(2IF0K_fSfpplzS z(8%QxG;%Wt8o8MSjod7PMsBtP`-5~Z;mZMY0(xzo`Ap4RkiHKv-z`qecWUry(glP; z0t*R)^;ho*Lj)ER%y)6HjU@#0B^j~ooHW0L?8wum3#3sT7fz5=80$T`^1hx_;3p`7hBJdnx zs=)IOe#Wl|emM}oWblGB7rYk<8oZYX8oZYY8oXBs8oXBt8obvC8obvDdP?3PXz<=7 zXz<=5Xz<=9Xz<=4Xz<=8Xz;cXGNYGe)M9^4$Owd^EAZV<1 z5;Ru32pX$T9B8cY^A?{vOY}T{M$ohPAA+8={}Qw+pA*K(@qIziGw>xrFXw!MX2foS zX2c$XX2f2C)^s01Gh#mh8F8c@uxav%=>gBHezZN{0q#jp(*FpWYF`obtbI+;RQraY zsrD^FQ|&u~rrJS*rrP%eJ<&f9#z`oCBxp^4B53aYOwio>g`m0jD?tPP8$omLcY@~L zA%f=KAB3Ie%$vmflb|W_7eQ0vZ-S=8KLkyQ)W_~=kETQxK~o}4&_<#FLC;4)f<~?o zK_gd~pph#=(8v`fXyl3!G;+lW8o3e#ja*5>IEh>-!gztw1PxRff(EKAK?7Bepn)n+ z&_GonXrL+*c1fTr5%eTiCg>@wLeMi-m7w*gM$m(+PSC@zLC|!lNzintMbLDpP0)0x zL(rNYOVD&Uj-csKm!QXTJVDdp1cDyii3ClDlL(p)ClfRsP9bPIoJ!DiIE|p^<8*?a zu`>u-(=!R=G(Q>>^g?bz(8x6BX>4I&qr&5M(!MfMy?G(BX=%ABiELokvor|kvpHDk-LDPk-Lzf zk!wd7FM+z4pnE&_G>A&_Hz{AW%o@{F)`7nJatIQFnfqb5GhrbR=l> zt{`Y^t|VwEt|I6GUQN)mb`3$#>$L>Uv+D?&XV()n&u$=So^>KZPQB%>4IpTs1`;$-g9v&d4<_hI9zxJlIFz7gY#2f7F`S?WH-eytpG(km7)j7{ z7)8)@7){W07(>vSjwNV1j3a0|j3?-^Odx1FOeE;RO(JMIOeSbLOd)7GOeJVKOe1JI zOeg61$Rp?(n?cZ;&LoVN{Fp`1{FqJ9{Fp<~xXdMJe#|3ie#|Fmek>s9g}jiUky}L2 z$So#l@rn z8iJ<8T7ss;I)bLedV;3J27;!n2E0Jf z40w^CEyPO%jo!-yjm;|ry@*~VXgyvd=)t{C(8GU&Fdavm&VCD^j|Si2!U}17C;2Yn zD|z6yjqruQc0y5s_Xrhb8}Ab;34B1PEbt+rioi#NssbMqstN2MXiaw#w5GcVTGLMm zTGLMnTGP)6TGRg!w5IX3E#b^di~j37((kdFt~_`68Is@Unj~kMq2) z=O=i6qUWd43uM>BbbC{`WNwyiLFyCc2{a(g7idUWAkc`gP@pkkkw6o|VgpC$lbY5` zzA$~#6Gz=AHRYa`$gZ0amI^c{EE8x!ST4|#utJ~}VU@tygw+DA32Ow-A*>Z>Ls%zp zE@8buTfzo`^9UOS&L?aVxPY)(;6lO{fp&yv1uh~yFK{v81%XQlz2q-UwI{qGB`zh* z61a>oTc88sO@Ye^uL*Q?(9?7fsrT`t$5%LVxp*Z(bMY#I=Hk@^&Bbd7nv2&GG#9TU zAQ#PUuP12A+(6Kj=|s?!xsjkLa}z-`S{v_Y!g>hwdZ1juPqY`vKa> zjli@vuDPD4zR36)nAY<3Ja6rJ8_zHCyo2W*Jq_?f+eG2$mn3&n_^EG--(ezLSkjQGjYqA}tpON+&b zpDZmNBYv{9M2z^!(vmUa*ZxYyxa>%MQ~f00^iBCk-8UT*?+rg2SUN_0BA`r+_$}13 zG2*vS%f*P_LMm}9E^G=@M z;&~U(AN)GAoi&)&?PPtE@z$8OZZ6Gl%``5}B-iAasa+Ofq(GW5MxX#;JRqH25TM&D z#Dxo`bYa3Ifg*&l0!0ba1&R?C2^1&H5hy{JD^QX!PoNZGzQ8er$pWPbGX%;IW(kxf zOcf|cm@QDAFj1faVTwRS!YF}CgwX<(3F8E+5GDvzB}@~jM#vMWPM9fB!@%0r$8+HVR4Sc)g17J_ zF0@%-{%X9p@Dwi81UQwT32+)g6X0}$Ccqg4O@K2AngC}JGy&=nGy&=pGyxhAYyzaS z8v^v~G~z;yePe>gz6n8N-;`iupU!Ru(CsznLL2sUb_;J|OD?n#PiMFC7PjR=4a<4n z!ggG!XZ|8@;l*5N&wM)j5^rI9F0>~-oqegd@G>sc^WA}f^L?cLtwFNilxSbmlp2bb zXpnii-Tdc2hc~S976_q4_O8Z{c-ZsL{IKTX+K(YP33e3vc8?jn+-x!kf9!UYP0ZTfBvxxp1Fc zL|wdvw{oFgkGByt@V9%VyK+u1CUXR@gdObc!&{!q}jb#sjR^cHo)a$V)L9fS$33@#~LeL053efF6 z#)aApKTgnQ_z8kG!%q_SNc5fp==PrG!o9Na8E;_@7iz!Ui=eUYP0)V155e}!=C5!P zY{1Q5;3R10+@GMG^8kXT!9aqh!61UR5Q71FNJF?#o8_SdO@mC&|t11XfW3jG??oM8qD6q5?^*kTrd7kIXJYV7YbDlr% z`8LnDd;SaE+&6r0>VQY)kEiRMZaU?3X1+e=3uNXSV7_2xz9HrdW#$`UzHnx~G3JY8 z=9^%?XlA}C=8I+Kn_<3qX1@99X7E`8^Y%QN+g!ISX)Es%l_i`fP>yiEKzYIi0u=}s z3REPt6R1SENT4#|Vu31zO9ZMC+6z=8Tq;nVaG5|2LI;7Ggv$kL5jqOgCR`youJ>tID?Qaw?Ah(*p+_dag!itVO|rYo?GUAzrQ{~zvj|_pgU|x z(66~PBIws#8WXNHbvKo6LeQ_dG$rWQT$&MXl2w`$^lL6H2wkK^OTujetq5HO&L(sd zXid0F;2eT}&7}=Nzvgl-K~Ha6f_}~AJc54B<$QvE&E*2Z!?N283Hmjcb_D&J%SD7I zWtEEw`ZbqJ9PCQp^{_d|?cIEGtAzbh2fNZeaPx4Pn@<|bBjgSab`|K}9hFlN0iFOrx-40DfQ$M&1tFSq<`Moyf_rl+p%nG^ps{Gz~`j>W`6vA0eXBPn2&6?Jg z3wy{#Th>8O+{Eo!fItjg=29zYo60Qo&i$O*U51f&Bu-p4s?wj+LC*9qgZn zC&`taC2z}$RUFttyEo#=a@D~0PRKJ>EwFuk@m!?3vm{TlsD=YMq(S&An>9n*ibJa9 zOlsR7#>+T(gr?GVc+cOYWP8v-HgA>c~WSD(YT%*+A!ED&XTTDky8n;37qD@*6cv9!Dg+~oh7@a&>4g` z1*<13S=fn7OE0!SteP z!{xeo#9M=-6e=@Xvs^89npzxMo~=ihst z`Yp5ll9<-*m+|}}&pUeF$@4Cr5A;0O^QE3I_k5-2soyj8x%yD1K3y=a=k0#ayLx~t3ecDU8;&?L*Vp1vvxn|n=yo|S4m+>~3)^w@0KI3&Ttv>Uej4#Ku z`WIhi{2->)Z~4}_8NmEzrg0W+qq=)N-qOp84DTnVL)(CEp#aS!T3ms3f(0b#qRTp=bER`LUa3Fm}AADY= zWMKKD@YknH(c};&U=PPQOqR*kN;{CP^+S(eCNhkR%0`BFXUoxK4`cA>vC9*2lJZAk zSWzLcJ^k<=d_`x;Z)R-+l^pbxt&PQKvoaA|+tVM-eU-@Uur09Nn=sO<7TBKti;Y!x zmb@XyU&Ddyb-{q?rc_ObNw!=&wH(M<8ra7asvTJVXslQ#uss72{9{8Kgg-TZoU`P2 zIrzE`WCw$AdXEn*e+&j$Cpb&ql=`1YST1l9VTHiSgtr7vaUlB|+RtqF)W}fD)0`y} zWyRAS$cn@8SMSeomaLRQXFAYA7>%D58HPdiBE!{LKQg?v-iRh?F&|-UOf)-9?dyf{ zY?HwDjKJu!X=I2|Gn#C03GNM=6S2WPBk+li7LnoO5G_N?#d&HKn!WhW4lNh$OzY4_ zVpw@jWcVOTo6tthJW`j~B>B@E##cw#C7M4d9PVs1MxJd$8T(u5ch5n}xT|uMBPaaAQ|RhK*evS|0B9t_f`#+PP~(%fn5Xmij( zcA-g4CLx_~jc_tPLUkL_R&O4T;Y%VILW5&4&+=eL!LiK zlRYfPnh8<%fX1*#Xv_PXLwX3Nht$(8Pr6IT^{@lGxBO`s+dLB3o)s9zJnAfYP*!}* zfmCxyUg;5^dGj;N(0-(}D=m(?ltVOY51)&^Y8ohL3FZ3T@pC zW4$9oQuYZfKM#L8wr^m2)}iz17utH{ZvV(oZa`=o@O))pVEHq!-$68cz%%>fEDR>% zfb(bIK!yaiXCpeZp^+g=hDC;^dbqP>gxR2h5e{TLvvBw*gSifqM4~&=fs~p#6m83B zhd-lk`v)Rd#yFES*o*@k7g+u*JbxKavj;nCFgm;mAG^vEzS%?oUAZyfQA!18Bf)I2jXjB{r>OV-GlpY1@; z>0}J0=MZtUd+h_vxuNw#b287FJ@Mn4g21HI0=iKC2Qq?7dwzb{n5oNi43j5(#UWDE(>h{ZdjH(OV-H_RuF~> ztaKoI9EgF*s>sl5tPX9^RAXyG8;p!!8`=;=Y+Y!>u#fdLxs(?pJR69na;d#T(Kc)h zZ3r&!O`#1#yRtd7;bR3(GI*7+GI2~Z-+J!Hz)4|mcJPH)9*SAM` zM}}Lp4+7ge1wH47p-n;q@=;*>doMBeabUYgpu#(xCAm`JorLWIyBx^5oPwV4lhCH( z0{b*FjNw0{$vGc^RQwMS=RAK2&gFjt+dCai!snq)L)Lu}+6PxexN7$~Oa3c+*zZ8j$(-J%(1FnAB9;CZ+B^(SzY1+3 zuGp_>a-Jq(dH)at!6Z3vBOV1n3}5HaHVQ+wX~XgG+E|KLnP)0;lE2 z!1gXd)B96sOL3}xc9u+*)AEZ0IW0@^fZ|u0)MO#L(BDFwu^M+NzlS($5t85#(bn14 z?+==6awQtVKZ&;BN(^ZK3T+j3{dZ_9aAN)mZ8h%tQosAp_x7$v8q30#h7xA-h>JIe>QF9&<6;4FDxPDVus_GIkK!6jEIu>7@1j>>`Uv+p%li3~k< z)yU9+RSV6w%++c3(DKI2F$HT7aTNRdAxCP`Y{A)s&`{JO+JgP3nESTcFuiZ96D}W! z7Ux)J$p>=i$2pKgAB2%fU7GA|0tS=E6YbsxqX#-6GW1j@(q!c+YYd(gVIJC`lZkeV z!*Jc7654Py5T^!~zY)FqX@TtD??BGW zC`6$_XrnQbXc$=jW~5G|!1j$nN8gwxr)4>Aw3-m@85o1crYTJdu0&tg%waM?s@L3s z-WT*o!`y;sH#Y&XY)O;NZACZHDn^{DvqPNItFOV7_s^VM0I~G@stXI4y`^>!#MtUqnrvw)>UtXy1@|pO zoNkW{W6Q3A?H-68{|=gLa3xx?ZbZAmRk+~p3~cw{JY#nSwr>^M)9lC)!Mj6SjeXoh zlO1nGt?wn;9k0R4_XW0lD4rhNAK1QiXv7`}Z9Ps`_s}*V{0|1Udng7H3C&h!uI(9m zL^$Y(BZB5hK{Fz#TjyvW4m`xY*=P^LHQ$pa)fxhPm}t+@7IYGi(4^o{w409-ZNaVR ziyjN@S*-lHv*dYG(7+Q8vrz*>9oY6_|3LI7!$RANCVY5cyGP<89}(F8!5A>+ zMur0(85!E*QGx9ljILvJVEgTZnlX`~+}Ox4nj06|5H!f+X>tM=qm7&3FqtB$HPL~b zfuX3~q|k;Tu_lK$95=30LK}*5Q$rh$+D!{>1R^=zS@MEZB+r3VWEg@tBQ*Qg=FG_O zNNQGOi1lom9KIdR%!zOf0y#IrRY>u9M4R?wP;h==`$yxU)Pl$mp@pH1L6^LUW~(#L z9?N1PcCvpgMqx{6Qt!=Gw?`Z@DhCNwD>iVOX{yv?&;tYz%EOp7d>Umh6;@Y<3_O znSxerOK4MZR9i!vhWC!1g=w$;T)2EX&g1i;<)MpvA+X)!ahvvHVEbpFxqZo5(p%ni zc-eup-t+7!dxePezke1U)xR1UTAtSe+dTmd-s^$wpM^f-jll9p;Q_~+G|9P{xL18E z!Z~Ow-X_{?n1n|8ozNzuOMf@8{R?rt+ngo4Brw|vp9s81=qqRBeFu6*Rw8yE5bYUR ziP(J@+A751qtI64cIM;I)~q|iqk?AjlEP+SFr?1W3=A$cJKMpX$!Xn;q3F&K^YYM@ z>>}DjS~tYlC!wuHtNdwb>(Cj0Mzed#n}uxn57BOL6Yf#}>n!WV;*z5~!Aa3OLhc*P+e;~36 z#{L)DAe^kPLK}hW@axcW(SmWVu|{v(H0!h!8&4y?#Ag-V9D3S*p7f$d&}JscAmF1gZy9aw{-C_}R~S=a|FmnGV0 ztiokejwS{B;`XV0gafg5g$V8Fw4%dgh_u6%9N2@~y#~Rp>?|27g{nA^Gq4HgvubFY zQIBeo;Xb>1WY|FsXUQT5ni6cOK-gN z$IBqR48hB2yiCK(9K5`PmwkBo3NLNVDM&8D%iVbCj+X&=S%#O@c-e%PEqHkrFVExU zMZCO>msj!fI$qwy%iDN)7cblK@;+WZ#LLHc`2;VY;pM-0`2sKbc-fB^d@tF49n5}E z-hMRDel)RWgr}%HDcyyg&2i$=Ff4YEB^7}67RH<@1 z3l{Hl(aypp``q_S?7nkW0h0JtGnJ!h> zOdliDrHh#9GBRDZsF^M&)8&hq=?bYL$MnhmzGCr0WxlT@)0In@=_)c^wWOJ@CezhR zndurbUGo?-T}!5Gmp0RNWct`LX8Jgpu3OejA1~7nQmUgOt+Bf zmNm_EE15pKmYHrX)92JS(`~Y3=G?40X0ENyotJg2nLA(SF3390%w4E+?Xv2cxr=n} z;;iG%+$B2KKI;TCcd5=@mUW_;>!5R&XPso`I_lgNStpyhD|POwtW(U~)jD@g)~ROB zJg2iEx-RQ9Gk3kt-H>&BH8*n)>0HmO7G~~YoqHs!rI~wF=N`*yW#%5&xhJyDHgo0?rLE^v zS*^|7(>nJ|);VUbO_I6Hemx-DkS55n2mcIoplYkvLB z&R(28AG7AC-t27q^aYqTzw2gaFH2vDS@R=qcJ}ggJIr>}*(=f)Vb=USn_YTU`eMwQ z-(s_~*Q77Otoh+JJ9}NaJ!Y@h*&EWAVz!gc-e{iknpyMM)E2%u-2t=a0jiztoW2~h jrm3*Ax28K{);w9Yv$vqs#jQIZn#TG{F literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/codec.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/codec.py new file mode 100644 index 0000000..c855a4d --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/codec.py @@ -0,0 +1,118 @@ +from .core import encode, decode, alabel, ulabel, IDNAError +import codecs +import re +from typing import Any, Tuple, Optional + +_unicode_dots_re = re.compile('[\u002e\u3002\uff0e\uff61]') + +class Codec(codecs.Codec): + + def encode(self, data: str, errors: str = 'strict') -> Tuple[bytes, int]: + if errors != 'strict': + raise IDNAError('Unsupported error handling \"{}\"'.format(errors)) + + if not data: + return b"", 0 + + return encode(data), len(data) + + def decode(self, data: bytes, errors: str = 'strict') -> Tuple[str, int]: + if errors != 'strict': + raise IDNAError('Unsupported error handling \"{}\"'.format(errors)) + + if not data: + return '', 0 + + return decode(data), len(data) + +class IncrementalEncoder(codecs.BufferedIncrementalEncoder): + def _buffer_encode(self, data: str, errors: str, final: bool) -> Tuple[bytes, int]: + if errors != 'strict': + raise IDNAError('Unsupported error handling \"{}\"'.format(errors)) + + if not data: + return b'', 0 + + labels = _unicode_dots_re.split(data) + trailing_dot = b'' + if labels: + if not labels[-1]: + trailing_dot = b'.' + del labels[-1] + elif not final: + # Keep potentially unfinished label until the next call + del labels[-1] + if labels: + trailing_dot = b'.' + + result = [] + size = 0 + for label in labels: + result.append(alabel(label)) + if size: + size += 1 + size += len(label) + + # Join with U+002E + result_bytes = b'.'.join(result) + trailing_dot + size += len(trailing_dot) + return result_bytes, size + +class IncrementalDecoder(codecs.BufferedIncrementalDecoder): + def _buffer_decode(self, data: Any, errors: str, final: bool) -> Tuple[str, int]: + if errors != 'strict': + raise IDNAError('Unsupported error handling \"{}\"'.format(errors)) + + if not data: + return ('', 0) + + if not isinstance(data, str): + data = str(data, 'ascii') + + labels = _unicode_dots_re.split(data) + trailing_dot = '' + if labels: + if not labels[-1]: + trailing_dot = '.' + del labels[-1] + elif not final: + # Keep potentially unfinished label until the next call + del labels[-1] + if labels: + trailing_dot = '.' + + result = [] + size = 0 + for label in labels: + result.append(ulabel(label)) + if size: + size += 1 + size += len(label) + + result_str = '.'.join(result) + trailing_dot + size += len(trailing_dot) + return (result_str, size) + + +class StreamWriter(Codec, codecs.StreamWriter): + pass + + +class StreamReader(Codec, codecs.StreamReader): + pass + + +def search_function(name: str) -> Optional[codecs.CodecInfo]: + if name != 'idna2008': + return None + return codecs.CodecInfo( + name=name, + encode=Codec().encode, + decode=Codec().decode, + incrementalencoder=IncrementalEncoder, + incrementaldecoder=IncrementalDecoder, + streamwriter=StreamWriter, + streamreader=StreamReader, + ) + +codecs.register(search_function) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/compat.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/compat.py new file mode 100644 index 0000000..786e6bd --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/compat.py @@ -0,0 +1,13 @@ +from .core import * +from .codec import * +from typing import Any, Union + +def ToASCII(label: str) -> bytes: + return encode(label) + +def ToUnicode(label: Union[bytes, bytearray]) -> str: + return decode(label) + +def nameprep(s: Any) -> None: + raise NotImplementedError('IDNA 2008 does not utilise nameprep protocol') + diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/core.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/core.py new file mode 100644 index 0000000..69b66ef --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/core.py @@ -0,0 +1,399 @@ +from . import idnadata +import bisect +import unicodedata +import re +from typing import Union, Optional +from .intranges import intranges_contain + +_virama_combining_class = 9 +_alabel_prefix = b'xn--' +_unicode_dots_re = re.compile('[\u002e\u3002\uff0e\uff61]') + +class IDNAError(UnicodeError): + """ Base exception for all IDNA-encoding related problems """ + pass + + +class IDNABidiError(IDNAError): + """ Exception when bidirectional requirements are not satisfied """ + pass + + +class InvalidCodepoint(IDNAError): + """ Exception when a disallowed or unallocated codepoint is used """ + pass + + +class InvalidCodepointContext(IDNAError): + """ Exception when the codepoint is not valid in the context it is used """ + pass + + +def _combining_class(cp: int) -> int: + v = unicodedata.combining(chr(cp)) + if v == 0: + if not unicodedata.name(chr(cp)): + raise ValueError('Unknown character in unicodedata') + return v + +def _is_script(cp: str, script: str) -> bool: + return intranges_contain(ord(cp), idnadata.scripts[script]) + +def _punycode(s: str) -> bytes: + return s.encode('punycode') + +def _unot(s: int) -> str: + return 'U+{:04X}'.format(s) + + +def valid_label_length(label: Union[bytes, str]) -> bool: + if len(label) > 63: + return False + return True + + +def valid_string_length(label: Union[bytes, str], trailing_dot: bool) -> bool: + if len(label) > (254 if trailing_dot else 253): + return False + return True + + +def check_bidi(label: str, check_ltr: bool = False) -> bool: + # Bidi rules should only be applied if string contains RTL characters + bidi_label = False + for (idx, cp) in enumerate(label, 1): + direction = unicodedata.bidirectional(cp) + if direction == '': + # String likely comes from a newer version of Unicode + raise IDNABidiError('Unknown directionality in label {} at position {}'.format(repr(label), idx)) + if direction in ['R', 'AL', 'AN']: + bidi_label = True + if not bidi_label and not check_ltr: + return True + + # Bidi rule 1 + direction = unicodedata.bidirectional(label[0]) + if direction in ['R', 'AL']: + rtl = True + elif direction == 'L': + rtl = False + else: + raise IDNABidiError('First codepoint in label {} must be directionality L, R or AL'.format(repr(label))) + + valid_ending = False + number_type = None # type: Optional[str] + for (idx, cp) in enumerate(label, 1): + direction = unicodedata.bidirectional(cp) + + if rtl: + # Bidi rule 2 + if not direction in ['R', 'AL', 'AN', 'EN', 'ES', 'CS', 'ET', 'ON', 'BN', 'NSM']: + raise IDNABidiError('Invalid direction for codepoint at position {} in a right-to-left label'.format(idx)) + # Bidi rule 3 + if direction in ['R', 'AL', 'EN', 'AN']: + valid_ending = True + elif direction != 'NSM': + valid_ending = False + # Bidi rule 4 + if direction in ['AN', 'EN']: + if not number_type: + number_type = direction + else: + if number_type != direction: + raise IDNABidiError('Can not mix numeral types in a right-to-left label') + else: + # Bidi rule 5 + if not direction in ['L', 'EN', 'ES', 'CS', 'ET', 'ON', 'BN', 'NSM']: + raise IDNABidiError('Invalid direction for codepoint at position {} in a left-to-right label'.format(idx)) + # Bidi rule 6 + if direction in ['L', 'EN']: + valid_ending = True + elif direction != 'NSM': + valid_ending = False + + if not valid_ending: + raise IDNABidiError('Label ends with illegal codepoint directionality') + + return True + + +def check_initial_combiner(label: str) -> bool: + if unicodedata.category(label[0])[0] == 'M': + raise IDNAError('Label begins with an illegal combining character') + return True + + +def check_hyphen_ok(label: str) -> bool: + if label[2:4] == '--': + raise IDNAError('Label has disallowed hyphens in 3rd and 4th position') + if label[0] == '-' or label[-1] == '-': + raise IDNAError('Label must not start or end with a hyphen') + return True + + +def check_nfc(label: str) -> None: + if unicodedata.normalize('NFC', label) != label: + raise IDNAError('Label must be in Normalization Form C') + + +def valid_contextj(label: str, pos: int) -> bool: + cp_value = ord(label[pos]) + + if cp_value == 0x200c: + + if pos > 0: + if _combining_class(ord(label[pos - 1])) == _virama_combining_class: + return True + + ok = False + for i in range(pos-1, -1, -1): + joining_type = idnadata.joining_types.get(ord(label[i])) + if joining_type == ord('T'): + continue + elif joining_type in [ord('L'), ord('D')]: + ok = True + break + else: + break + + if not ok: + return False + + ok = False + for i in range(pos+1, len(label)): + joining_type = idnadata.joining_types.get(ord(label[i])) + if joining_type == ord('T'): + continue + elif joining_type in [ord('R'), ord('D')]: + ok = True + break + else: + break + return ok + + if cp_value == 0x200d: + + if pos > 0: + if _combining_class(ord(label[pos - 1])) == _virama_combining_class: + return True + return False + + else: + + return False + + +def valid_contexto(label: str, pos: int, exception: bool = False) -> bool: + cp_value = ord(label[pos]) + + if cp_value == 0x00b7: + if 0 < pos < len(label)-1: + if ord(label[pos - 1]) == 0x006c and ord(label[pos + 1]) == 0x006c: + return True + return False + + elif cp_value == 0x0375: + if pos < len(label)-1 and len(label) > 1: + return _is_script(label[pos + 1], 'Greek') + return False + + elif cp_value == 0x05f3 or cp_value == 0x05f4: + if pos > 0: + return _is_script(label[pos - 1], 'Hebrew') + return False + + elif cp_value == 0x30fb: + for cp in label: + if cp == '\u30fb': + continue + if _is_script(cp, 'Hiragana') or _is_script(cp, 'Katakana') or _is_script(cp, 'Han'): + return True + return False + + elif 0x660 <= cp_value <= 0x669: + for cp in label: + if 0x6f0 <= ord(cp) <= 0x06f9: + return False + return True + + elif 0x6f0 <= cp_value <= 0x6f9: + for cp in label: + if 0x660 <= ord(cp) <= 0x0669: + return False + return True + + return False + + +def check_label(label: Union[str, bytes, bytearray]) -> None: + if isinstance(label, (bytes, bytearray)): + label = label.decode('utf-8') + if len(label) == 0: + raise IDNAError('Empty Label') + + check_nfc(label) + check_hyphen_ok(label) + check_initial_combiner(label) + + for (pos, cp) in enumerate(label): + cp_value = ord(cp) + if intranges_contain(cp_value, idnadata.codepoint_classes['PVALID']): + continue + elif intranges_contain(cp_value, idnadata.codepoint_classes['CONTEXTJ']): + try: + if not valid_contextj(label, pos): + raise InvalidCodepointContext('Joiner {} not allowed at position {} in {}'.format( + _unot(cp_value), pos+1, repr(label))) + except ValueError: + raise IDNAError('Unknown codepoint adjacent to joiner {} at position {} in {}'.format( + _unot(cp_value), pos+1, repr(label))) + elif intranges_contain(cp_value, idnadata.codepoint_classes['CONTEXTO']): + if not valid_contexto(label, pos): + raise InvalidCodepointContext('Codepoint {} not allowed at position {} in {}'.format(_unot(cp_value), pos+1, repr(label))) + else: + raise InvalidCodepoint('Codepoint {} at position {} of {} not allowed'.format(_unot(cp_value), pos+1, repr(label))) + + check_bidi(label) + + +def alabel(label: str) -> bytes: + try: + label_bytes = label.encode('ascii') + ulabel(label_bytes) + if not valid_label_length(label_bytes): + raise IDNAError('Label too long') + return label_bytes + except UnicodeEncodeError: + pass + + check_label(label) + label_bytes = _alabel_prefix + _punycode(label) + + if not valid_label_length(label_bytes): + raise IDNAError('Label too long') + + return label_bytes + + +def ulabel(label: Union[str, bytes, bytearray]) -> str: + if not isinstance(label, (bytes, bytearray)): + try: + label_bytes = label.encode('ascii') + except UnicodeEncodeError: + check_label(label) + return label + else: + label_bytes = label + + label_bytes = label_bytes.lower() + if label_bytes.startswith(_alabel_prefix): + label_bytes = label_bytes[len(_alabel_prefix):] + if not label_bytes: + raise IDNAError('Malformed A-label, no Punycode eligible content found') + if label_bytes.decode('ascii')[-1] == '-': + raise IDNAError('A-label must not end with a hyphen') + else: + check_label(label_bytes) + return label_bytes.decode('ascii') + + try: + label = label_bytes.decode('punycode') + except UnicodeError: + raise IDNAError('Invalid A-label') + check_label(label) + return label + + +def uts46_remap(domain: str, std3_rules: bool = True, transitional: bool = False) -> str: + """Re-map the characters in the string according to UTS46 processing.""" + from .uts46data import uts46data + output = '' + + for pos, char in enumerate(domain): + code_point = ord(char) + try: + uts46row = uts46data[code_point if code_point < 256 else + bisect.bisect_left(uts46data, (code_point, 'Z')) - 1] + status = uts46row[1] + replacement = None # type: Optional[str] + if len(uts46row) == 3: + replacement = uts46row[2] + if (status == 'V' or + (status == 'D' and not transitional) or + (status == '3' and not std3_rules and replacement is None)): + output += char + elif replacement is not None and (status == 'M' or + (status == '3' and not std3_rules) or + (status == 'D' and transitional)): + output += replacement + elif status != 'I': + raise IndexError() + except IndexError: + raise InvalidCodepoint( + 'Codepoint {} not allowed at position {} in {}'.format( + _unot(code_point), pos + 1, repr(domain))) + + return unicodedata.normalize('NFC', output) + + +def encode(s: Union[str, bytes, bytearray], strict: bool = False, uts46: bool = False, std3_rules: bool = False, transitional: bool = False) -> bytes: + if not isinstance(s, str): + try: + s = str(s, 'ascii') + except UnicodeDecodeError: + raise IDNAError('should pass a unicode string to the function rather than a byte string.') + if uts46: + s = uts46_remap(s, std3_rules, transitional) + trailing_dot = False + result = [] + if strict: + labels = s.split('.') + else: + labels = _unicode_dots_re.split(s) + if not labels or labels == ['']: + raise IDNAError('Empty domain') + if labels[-1] == '': + del labels[-1] + trailing_dot = True + for label in labels: + s = alabel(label) + if s: + result.append(s) + else: + raise IDNAError('Empty label') + if trailing_dot: + result.append(b'') + s = b'.'.join(result) + if not valid_string_length(s, trailing_dot): + raise IDNAError('Domain too long') + return s + + +def decode(s: Union[str, bytes, bytearray], strict: bool = False, uts46: bool = False, std3_rules: bool = False) -> str: + try: + if not isinstance(s, str): + s = str(s, 'ascii') + except UnicodeDecodeError: + raise IDNAError('Invalid ASCII in A-label') + if uts46: + s = uts46_remap(s, std3_rules, False) + trailing_dot = False + result = [] + if not strict: + labels = _unicode_dots_re.split(s) + else: + labels = s.split('.') + if not labels or labels == ['']: + raise IDNAError('Empty domain') + if not labels[-1]: + del labels[-1] + trailing_dot = True + for label in labels: + s = ulabel(label) + if s: + result.append(s) + else: + raise IDNAError('Empty label') + if trailing_dot: + result.append('') + return '.'.join(result) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/idnadata.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/idnadata.py new file mode 100644 index 0000000..c61dcf9 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/idnadata.py @@ -0,0 +1,4245 @@ +# This file is automatically generated by tools/idna-data + +__version__ = '15.1.0' +scripts = { + 'Greek': ( + 0x37000000374, + 0x37500000378, + 0x37a0000037e, + 0x37f00000380, + 0x38400000385, + 0x38600000387, + 0x3880000038b, + 0x38c0000038d, + 0x38e000003a2, + 0x3a3000003e2, + 0x3f000000400, + 0x1d2600001d2b, + 0x1d5d00001d62, + 0x1d6600001d6b, + 0x1dbf00001dc0, + 0x1f0000001f16, + 0x1f1800001f1e, + 0x1f2000001f46, + 0x1f4800001f4e, + 0x1f5000001f58, + 0x1f5900001f5a, + 0x1f5b00001f5c, + 0x1f5d00001f5e, + 0x1f5f00001f7e, + 0x1f8000001fb5, + 0x1fb600001fc5, + 0x1fc600001fd4, + 0x1fd600001fdc, + 0x1fdd00001ff0, + 0x1ff200001ff5, + 0x1ff600001fff, + 0x212600002127, + 0xab650000ab66, + 0x101400001018f, + 0x101a0000101a1, + 0x1d2000001d246, + ), + 'Han': ( + 0x2e8000002e9a, + 0x2e9b00002ef4, + 0x2f0000002fd6, + 0x300500003006, + 0x300700003008, + 0x30210000302a, + 0x30380000303c, + 0x340000004dc0, + 0x4e000000a000, + 0xf9000000fa6e, + 0xfa700000fada, + 0x16fe200016fe4, + 0x16ff000016ff2, + 0x200000002a6e0, + 0x2a7000002b73a, + 0x2b7400002b81e, + 0x2b8200002cea2, + 0x2ceb00002ebe1, + 0x2ebf00002ee5e, + 0x2f8000002fa1e, + 0x300000003134b, + 0x31350000323b0, + ), + 'Hebrew': ( + 0x591000005c8, + 0x5d0000005eb, + 0x5ef000005f5, + 0xfb1d0000fb37, + 0xfb380000fb3d, + 0xfb3e0000fb3f, + 0xfb400000fb42, + 0xfb430000fb45, + 0xfb460000fb50, + ), + 'Hiragana': ( + 0x304100003097, + 0x309d000030a0, + 0x1b0010001b120, + 0x1b1320001b133, + 0x1b1500001b153, + 0x1f2000001f201, + ), + 'Katakana': ( + 0x30a1000030fb, + 0x30fd00003100, + 0x31f000003200, + 0x32d0000032ff, + 0x330000003358, + 0xff660000ff70, + 0xff710000ff9e, + 0x1aff00001aff4, + 0x1aff50001affc, + 0x1affd0001afff, + 0x1b0000001b001, + 0x1b1200001b123, + 0x1b1550001b156, + 0x1b1640001b168, + ), +} +joining_types = { + 0xad: 84, + 0x300: 84, + 0x301: 84, + 0x302: 84, + 0x303: 84, + 0x304: 84, + 0x305: 84, + 0x306: 84, + 0x307: 84, + 0x308: 84, + 0x309: 84, + 0x30a: 84, + 0x30b: 84, + 0x30c: 84, + 0x30d: 84, + 0x30e: 84, + 0x30f: 84, + 0x310: 84, + 0x311: 84, + 0x312: 84, + 0x313: 84, + 0x314: 84, + 0x315: 84, + 0x316: 84, + 0x317: 84, + 0x318: 84, + 0x319: 84, + 0x31a: 84, + 0x31b: 84, + 0x31c: 84, + 0x31d: 84, + 0x31e: 84, + 0x31f: 84, + 0x320: 84, + 0x321: 84, + 0x322: 84, + 0x323: 84, + 0x324: 84, + 0x325: 84, + 0x326: 84, + 0x327: 84, + 0x328: 84, + 0x329: 84, + 0x32a: 84, + 0x32b: 84, + 0x32c: 84, + 0x32d: 84, + 0x32e: 84, + 0x32f: 84, + 0x330: 84, + 0x331: 84, + 0x332: 84, + 0x333: 84, + 0x334: 84, + 0x335: 84, + 0x336: 84, + 0x337: 84, + 0x338: 84, + 0x339: 84, + 0x33a: 84, + 0x33b: 84, + 0x33c: 84, + 0x33d: 84, + 0x33e: 84, + 0x33f: 84, + 0x340: 84, + 0x341: 84, + 0x342: 84, + 0x343: 84, + 0x344: 84, + 0x345: 84, + 0x346: 84, + 0x347: 84, + 0x348: 84, + 0x349: 84, + 0x34a: 84, + 0x34b: 84, + 0x34c: 84, + 0x34d: 84, + 0x34e: 84, + 0x34f: 84, + 0x350: 84, + 0x351: 84, + 0x352: 84, + 0x353: 84, + 0x354: 84, + 0x355: 84, + 0x356: 84, + 0x357: 84, + 0x358: 84, + 0x359: 84, + 0x35a: 84, + 0x35b: 84, + 0x35c: 84, + 0x35d: 84, + 0x35e: 84, + 0x35f: 84, + 0x360: 84, + 0x361: 84, + 0x362: 84, + 0x363: 84, + 0x364: 84, + 0x365: 84, + 0x366: 84, + 0x367: 84, + 0x368: 84, + 0x369: 84, + 0x36a: 84, + 0x36b: 84, + 0x36c: 84, + 0x36d: 84, + 0x36e: 84, + 0x36f: 84, + 0x483: 84, + 0x484: 84, + 0x485: 84, + 0x486: 84, + 0x487: 84, + 0x488: 84, + 0x489: 84, + 0x591: 84, + 0x592: 84, + 0x593: 84, + 0x594: 84, + 0x595: 84, + 0x596: 84, + 0x597: 84, + 0x598: 84, + 0x599: 84, + 0x59a: 84, + 0x59b: 84, + 0x59c: 84, + 0x59d: 84, + 0x59e: 84, + 0x59f: 84, + 0x5a0: 84, + 0x5a1: 84, + 0x5a2: 84, + 0x5a3: 84, + 0x5a4: 84, + 0x5a5: 84, + 0x5a6: 84, + 0x5a7: 84, + 0x5a8: 84, + 0x5a9: 84, + 0x5aa: 84, + 0x5ab: 84, + 0x5ac: 84, + 0x5ad: 84, + 0x5ae: 84, + 0x5af: 84, + 0x5b0: 84, + 0x5b1: 84, + 0x5b2: 84, + 0x5b3: 84, + 0x5b4: 84, + 0x5b5: 84, + 0x5b6: 84, + 0x5b7: 84, + 0x5b8: 84, + 0x5b9: 84, + 0x5ba: 84, + 0x5bb: 84, + 0x5bc: 84, + 0x5bd: 84, + 0x5bf: 84, + 0x5c1: 84, + 0x5c2: 84, + 0x5c4: 84, + 0x5c5: 84, + 0x5c7: 84, + 0x610: 84, + 0x611: 84, + 0x612: 84, + 0x613: 84, + 0x614: 84, + 0x615: 84, + 0x616: 84, + 0x617: 84, + 0x618: 84, + 0x619: 84, + 0x61a: 84, + 0x61c: 84, + 0x620: 68, + 0x622: 82, + 0x623: 82, + 0x624: 82, + 0x625: 82, + 0x626: 68, + 0x627: 82, + 0x628: 68, + 0x629: 82, + 0x62a: 68, + 0x62b: 68, + 0x62c: 68, + 0x62d: 68, + 0x62e: 68, + 0x62f: 82, + 0x630: 82, + 0x631: 82, + 0x632: 82, + 0x633: 68, + 0x634: 68, + 0x635: 68, + 0x636: 68, + 0x637: 68, + 0x638: 68, + 0x639: 68, + 0x63a: 68, + 0x63b: 68, + 0x63c: 68, + 0x63d: 68, + 0x63e: 68, + 0x63f: 68, + 0x640: 67, + 0x641: 68, + 0x642: 68, + 0x643: 68, + 0x644: 68, + 0x645: 68, + 0x646: 68, + 0x647: 68, + 0x648: 82, + 0x649: 68, + 0x64a: 68, + 0x64b: 84, + 0x64c: 84, + 0x64d: 84, + 0x64e: 84, + 0x64f: 84, + 0x650: 84, + 0x651: 84, + 0x652: 84, + 0x653: 84, + 0x654: 84, + 0x655: 84, + 0x656: 84, + 0x657: 84, + 0x658: 84, + 0x659: 84, + 0x65a: 84, + 0x65b: 84, + 0x65c: 84, + 0x65d: 84, + 0x65e: 84, + 0x65f: 84, + 0x66e: 68, + 0x66f: 68, + 0x670: 84, + 0x671: 82, + 0x672: 82, + 0x673: 82, + 0x675: 82, + 0x676: 82, + 0x677: 82, + 0x678: 68, + 0x679: 68, + 0x67a: 68, + 0x67b: 68, + 0x67c: 68, + 0x67d: 68, + 0x67e: 68, + 0x67f: 68, + 0x680: 68, + 0x681: 68, + 0x682: 68, + 0x683: 68, + 0x684: 68, + 0x685: 68, + 0x686: 68, + 0x687: 68, + 0x688: 82, + 0x689: 82, + 0x68a: 82, + 0x68b: 82, + 0x68c: 82, + 0x68d: 82, + 0x68e: 82, + 0x68f: 82, + 0x690: 82, + 0x691: 82, + 0x692: 82, + 0x693: 82, + 0x694: 82, + 0x695: 82, + 0x696: 82, + 0x697: 82, + 0x698: 82, + 0x699: 82, + 0x69a: 68, + 0x69b: 68, + 0x69c: 68, + 0x69d: 68, + 0x69e: 68, + 0x69f: 68, + 0x6a0: 68, + 0x6a1: 68, + 0x6a2: 68, + 0x6a3: 68, + 0x6a4: 68, + 0x6a5: 68, + 0x6a6: 68, + 0x6a7: 68, + 0x6a8: 68, + 0x6a9: 68, + 0x6aa: 68, + 0x6ab: 68, + 0x6ac: 68, + 0x6ad: 68, + 0x6ae: 68, + 0x6af: 68, + 0x6b0: 68, + 0x6b1: 68, + 0x6b2: 68, + 0x6b3: 68, + 0x6b4: 68, + 0x6b5: 68, + 0x6b6: 68, + 0x6b7: 68, + 0x6b8: 68, + 0x6b9: 68, + 0x6ba: 68, + 0x6bb: 68, + 0x6bc: 68, + 0x6bd: 68, + 0x6be: 68, + 0x6bf: 68, + 0x6c0: 82, + 0x6c1: 68, + 0x6c2: 68, + 0x6c3: 82, + 0x6c4: 82, + 0x6c5: 82, + 0x6c6: 82, + 0x6c7: 82, + 0x6c8: 82, + 0x6c9: 82, + 0x6ca: 82, + 0x6cb: 82, + 0x6cc: 68, + 0x6cd: 82, + 0x6ce: 68, + 0x6cf: 82, + 0x6d0: 68, + 0x6d1: 68, + 0x6d2: 82, + 0x6d3: 82, + 0x6d5: 82, + 0x6d6: 84, + 0x6d7: 84, + 0x6d8: 84, + 0x6d9: 84, + 0x6da: 84, + 0x6db: 84, + 0x6dc: 84, + 0x6df: 84, + 0x6e0: 84, + 0x6e1: 84, + 0x6e2: 84, + 0x6e3: 84, + 0x6e4: 84, + 0x6e7: 84, + 0x6e8: 84, + 0x6ea: 84, + 0x6eb: 84, + 0x6ec: 84, + 0x6ed: 84, + 0x6ee: 82, + 0x6ef: 82, + 0x6fa: 68, + 0x6fb: 68, + 0x6fc: 68, + 0x6ff: 68, + 0x70f: 84, + 0x710: 82, + 0x711: 84, + 0x712: 68, + 0x713: 68, + 0x714: 68, + 0x715: 82, + 0x716: 82, + 0x717: 82, + 0x718: 82, + 0x719: 82, + 0x71a: 68, + 0x71b: 68, + 0x71c: 68, + 0x71d: 68, + 0x71e: 82, + 0x71f: 68, + 0x720: 68, + 0x721: 68, + 0x722: 68, + 0x723: 68, + 0x724: 68, + 0x725: 68, + 0x726: 68, + 0x727: 68, + 0x728: 82, + 0x729: 68, + 0x72a: 82, + 0x72b: 68, + 0x72c: 82, + 0x72d: 68, + 0x72e: 68, + 0x72f: 82, + 0x730: 84, + 0x731: 84, + 0x732: 84, + 0x733: 84, + 0x734: 84, + 0x735: 84, + 0x736: 84, + 0x737: 84, + 0x738: 84, + 0x739: 84, + 0x73a: 84, + 0x73b: 84, + 0x73c: 84, + 0x73d: 84, + 0x73e: 84, + 0x73f: 84, + 0x740: 84, + 0x741: 84, + 0x742: 84, + 0x743: 84, + 0x744: 84, + 0x745: 84, + 0x746: 84, + 0x747: 84, + 0x748: 84, + 0x749: 84, + 0x74a: 84, + 0x74d: 82, + 0x74e: 68, + 0x74f: 68, + 0x750: 68, + 0x751: 68, + 0x752: 68, + 0x753: 68, + 0x754: 68, + 0x755: 68, + 0x756: 68, + 0x757: 68, + 0x758: 68, + 0x759: 82, + 0x75a: 82, + 0x75b: 82, + 0x75c: 68, + 0x75d: 68, + 0x75e: 68, + 0x75f: 68, + 0x760: 68, + 0x761: 68, + 0x762: 68, + 0x763: 68, + 0x764: 68, + 0x765: 68, + 0x766: 68, + 0x767: 68, + 0x768: 68, + 0x769: 68, + 0x76a: 68, + 0x76b: 82, + 0x76c: 82, + 0x76d: 68, + 0x76e: 68, + 0x76f: 68, + 0x770: 68, + 0x771: 82, + 0x772: 68, + 0x773: 82, + 0x774: 82, + 0x775: 68, + 0x776: 68, + 0x777: 68, + 0x778: 82, + 0x779: 82, + 0x77a: 68, + 0x77b: 68, + 0x77c: 68, + 0x77d: 68, + 0x77e: 68, + 0x77f: 68, + 0x7a6: 84, + 0x7a7: 84, + 0x7a8: 84, + 0x7a9: 84, + 0x7aa: 84, + 0x7ab: 84, + 0x7ac: 84, + 0x7ad: 84, + 0x7ae: 84, + 0x7af: 84, + 0x7b0: 84, + 0x7ca: 68, + 0x7cb: 68, + 0x7cc: 68, + 0x7cd: 68, + 0x7ce: 68, + 0x7cf: 68, + 0x7d0: 68, + 0x7d1: 68, + 0x7d2: 68, + 0x7d3: 68, + 0x7d4: 68, + 0x7d5: 68, + 0x7d6: 68, + 0x7d7: 68, + 0x7d8: 68, + 0x7d9: 68, + 0x7da: 68, + 0x7db: 68, + 0x7dc: 68, + 0x7dd: 68, + 0x7de: 68, + 0x7df: 68, + 0x7e0: 68, + 0x7e1: 68, + 0x7e2: 68, + 0x7e3: 68, + 0x7e4: 68, + 0x7e5: 68, + 0x7e6: 68, + 0x7e7: 68, + 0x7e8: 68, + 0x7e9: 68, + 0x7ea: 68, + 0x7eb: 84, + 0x7ec: 84, + 0x7ed: 84, + 0x7ee: 84, + 0x7ef: 84, + 0x7f0: 84, + 0x7f1: 84, + 0x7f2: 84, + 0x7f3: 84, + 0x7fa: 67, + 0x7fd: 84, + 0x816: 84, + 0x817: 84, + 0x818: 84, + 0x819: 84, + 0x81b: 84, + 0x81c: 84, + 0x81d: 84, + 0x81e: 84, + 0x81f: 84, + 0x820: 84, + 0x821: 84, + 0x822: 84, + 0x823: 84, + 0x825: 84, + 0x826: 84, + 0x827: 84, + 0x829: 84, + 0x82a: 84, + 0x82b: 84, + 0x82c: 84, + 0x82d: 84, + 0x840: 82, + 0x841: 68, + 0x842: 68, + 0x843: 68, + 0x844: 68, + 0x845: 68, + 0x846: 82, + 0x847: 82, + 0x848: 68, + 0x849: 82, + 0x84a: 68, + 0x84b: 68, + 0x84c: 68, + 0x84d: 68, + 0x84e: 68, + 0x84f: 68, + 0x850: 68, + 0x851: 68, + 0x852: 68, + 0x853: 68, + 0x854: 82, + 0x855: 68, + 0x856: 82, + 0x857: 82, + 0x858: 82, + 0x859: 84, + 0x85a: 84, + 0x85b: 84, + 0x860: 68, + 0x862: 68, + 0x863: 68, + 0x864: 68, + 0x865: 68, + 0x867: 82, + 0x868: 68, + 0x869: 82, + 0x86a: 82, + 0x870: 82, + 0x871: 82, + 0x872: 82, + 0x873: 82, + 0x874: 82, + 0x875: 82, + 0x876: 82, + 0x877: 82, + 0x878: 82, + 0x879: 82, + 0x87a: 82, + 0x87b: 82, + 0x87c: 82, + 0x87d: 82, + 0x87e: 82, + 0x87f: 82, + 0x880: 82, + 0x881: 82, + 0x882: 82, + 0x883: 67, + 0x884: 67, + 0x885: 67, + 0x886: 68, + 0x889: 68, + 0x88a: 68, + 0x88b: 68, + 0x88c: 68, + 0x88d: 68, + 0x88e: 82, + 0x898: 84, + 0x899: 84, + 0x89a: 84, + 0x89b: 84, + 0x89c: 84, + 0x89d: 84, + 0x89e: 84, + 0x89f: 84, + 0x8a0: 68, + 0x8a1: 68, + 0x8a2: 68, + 0x8a3: 68, + 0x8a4: 68, + 0x8a5: 68, + 0x8a6: 68, + 0x8a7: 68, + 0x8a8: 68, + 0x8a9: 68, + 0x8aa: 82, + 0x8ab: 82, + 0x8ac: 82, + 0x8ae: 82, + 0x8af: 68, + 0x8b0: 68, + 0x8b1: 82, + 0x8b2: 82, + 0x8b3: 68, + 0x8b4: 68, + 0x8b5: 68, + 0x8b6: 68, + 0x8b7: 68, + 0x8b8: 68, + 0x8b9: 82, + 0x8ba: 68, + 0x8bb: 68, + 0x8bc: 68, + 0x8bd: 68, + 0x8be: 68, + 0x8bf: 68, + 0x8c0: 68, + 0x8c1: 68, + 0x8c2: 68, + 0x8c3: 68, + 0x8c4: 68, + 0x8c5: 68, + 0x8c6: 68, + 0x8c7: 68, + 0x8c8: 68, + 0x8ca: 84, + 0x8cb: 84, + 0x8cc: 84, + 0x8cd: 84, + 0x8ce: 84, + 0x8cf: 84, + 0x8d0: 84, + 0x8d1: 84, + 0x8d2: 84, + 0x8d3: 84, + 0x8d4: 84, + 0x8d5: 84, + 0x8d6: 84, + 0x8d7: 84, + 0x8d8: 84, + 0x8d9: 84, + 0x8da: 84, + 0x8db: 84, + 0x8dc: 84, + 0x8dd: 84, + 0x8de: 84, + 0x8df: 84, + 0x8e0: 84, + 0x8e1: 84, + 0x8e3: 84, + 0x8e4: 84, + 0x8e5: 84, + 0x8e6: 84, + 0x8e7: 84, + 0x8e8: 84, + 0x8e9: 84, + 0x8ea: 84, + 0x8eb: 84, + 0x8ec: 84, + 0x8ed: 84, + 0x8ee: 84, + 0x8ef: 84, + 0x8f0: 84, + 0x8f1: 84, + 0x8f2: 84, + 0x8f3: 84, + 0x8f4: 84, + 0x8f5: 84, + 0x8f6: 84, + 0x8f7: 84, + 0x8f8: 84, + 0x8f9: 84, + 0x8fa: 84, + 0x8fb: 84, + 0x8fc: 84, + 0x8fd: 84, + 0x8fe: 84, + 0x8ff: 84, + 0x900: 84, + 0x901: 84, + 0x902: 84, + 0x93a: 84, + 0x93c: 84, + 0x941: 84, + 0x942: 84, + 0x943: 84, + 0x944: 84, + 0x945: 84, + 0x946: 84, + 0x947: 84, + 0x948: 84, + 0x94d: 84, + 0x951: 84, + 0x952: 84, + 0x953: 84, + 0x954: 84, + 0x955: 84, + 0x956: 84, + 0x957: 84, + 0x962: 84, + 0x963: 84, + 0x981: 84, + 0x9bc: 84, + 0x9c1: 84, + 0x9c2: 84, + 0x9c3: 84, + 0x9c4: 84, + 0x9cd: 84, + 0x9e2: 84, + 0x9e3: 84, + 0x9fe: 84, + 0xa01: 84, + 0xa02: 84, + 0xa3c: 84, + 0xa41: 84, + 0xa42: 84, + 0xa47: 84, + 0xa48: 84, + 0xa4b: 84, + 0xa4c: 84, + 0xa4d: 84, + 0xa51: 84, + 0xa70: 84, + 0xa71: 84, + 0xa75: 84, + 0xa81: 84, + 0xa82: 84, + 0xabc: 84, + 0xac1: 84, + 0xac2: 84, + 0xac3: 84, + 0xac4: 84, + 0xac5: 84, + 0xac7: 84, + 0xac8: 84, + 0xacd: 84, + 0xae2: 84, + 0xae3: 84, + 0xafa: 84, + 0xafb: 84, + 0xafc: 84, + 0xafd: 84, + 0xafe: 84, + 0xaff: 84, + 0xb01: 84, + 0xb3c: 84, + 0xb3f: 84, + 0xb41: 84, + 0xb42: 84, + 0xb43: 84, + 0xb44: 84, + 0xb4d: 84, + 0xb55: 84, + 0xb56: 84, + 0xb62: 84, + 0xb63: 84, + 0xb82: 84, + 0xbc0: 84, + 0xbcd: 84, + 0xc00: 84, + 0xc04: 84, + 0xc3c: 84, + 0xc3e: 84, + 0xc3f: 84, + 0xc40: 84, + 0xc46: 84, + 0xc47: 84, + 0xc48: 84, + 0xc4a: 84, + 0xc4b: 84, + 0xc4c: 84, + 0xc4d: 84, + 0xc55: 84, + 0xc56: 84, + 0xc62: 84, + 0xc63: 84, + 0xc81: 84, + 0xcbc: 84, + 0xcbf: 84, + 0xcc6: 84, + 0xccc: 84, + 0xccd: 84, + 0xce2: 84, + 0xce3: 84, + 0xd00: 84, + 0xd01: 84, + 0xd3b: 84, + 0xd3c: 84, + 0xd41: 84, + 0xd42: 84, + 0xd43: 84, + 0xd44: 84, + 0xd4d: 84, + 0xd62: 84, + 0xd63: 84, + 0xd81: 84, + 0xdca: 84, + 0xdd2: 84, + 0xdd3: 84, + 0xdd4: 84, + 0xdd6: 84, + 0xe31: 84, + 0xe34: 84, + 0xe35: 84, + 0xe36: 84, + 0xe37: 84, + 0xe38: 84, + 0xe39: 84, + 0xe3a: 84, + 0xe47: 84, + 0xe48: 84, + 0xe49: 84, + 0xe4a: 84, + 0xe4b: 84, + 0xe4c: 84, + 0xe4d: 84, + 0xe4e: 84, + 0xeb1: 84, + 0xeb4: 84, + 0xeb5: 84, + 0xeb6: 84, + 0xeb7: 84, + 0xeb8: 84, + 0xeb9: 84, + 0xeba: 84, + 0xebb: 84, + 0xebc: 84, + 0xec8: 84, + 0xec9: 84, + 0xeca: 84, + 0xecb: 84, + 0xecc: 84, + 0xecd: 84, + 0xece: 84, + 0xf18: 84, + 0xf19: 84, + 0xf35: 84, + 0xf37: 84, + 0xf39: 84, + 0xf71: 84, + 0xf72: 84, + 0xf73: 84, + 0xf74: 84, + 0xf75: 84, + 0xf76: 84, + 0xf77: 84, + 0xf78: 84, + 0xf79: 84, + 0xf7a: 84, + 0xf7b: 84, + 0xf7c: 84, + 0xf7d: 84, + 0xf7e: 84, + 0xf80: 84, + 0xf81: 84, + 0xf82: 84, + 0xf83: 84, + 0xf84: 84, + 0xf86: 84, + 0xf87: 84, + 0xf8d: 84, + 0xf8e: 84, + 0xf8f: 84, + 0xf90: 84, + 0xf91: 84, + 0xf92: 84, + 0xf93: 84, + 0xf94: 84, + 0xf95: 84, + 0xf96: 84, + 0xf97: 84, + 0xf99: 84, + 0xf9a: 84, + 0xf9b: 84, + 0xf9c: 84, + 0xf9d: 84, + 0xf9e: 84, + 0xf9f: 84, + 0xfa0: 84, + 0xfa1: 84, + 0xfa2: 84, + 0xfa3: 84, + 0xfa4: 84, + 0xfa5: 84, + 0xfa6: 84, + 0xfa7: 84, + 0xfa8: 84, + 0xfa9: 84, + 0xfaa: 84, + 0xfab: 84, + 0xfac: 84, + 0xfad: 84, + 0xfae: 84, + 0xfaf: 84, + 0xfb0: 84, + 0xfb1: 84, + 0xfb2: 84, + 0xfb3: 84, + 0xfb4: 84, + 0xfb5: 84, + 0xfb6: 84, + 0xfb7: 84, + 0xfb8: 84, + 0xfb9: 84, + 0xfba: 84, + 0xfbb: 84, + 0xfbc: 84, + 0xfc6: 84, + 0x102d: 84, + 0x102e: 84, + 0x102f: 84, + 0x1030: 84, + 0x1032: 84, + 0x1033: 84, + 0x1034: 84, + 0x1035: 84, + 0x1036: 84, + 0x1037: 84, + 0x1039: 84, + 0x103a: 84, + 0x103d: 84, + 0x103e: 84, + 0x1058: 84, + 0x1059: 84, + 0x105e: 84, + 0x105f: 84, + 0x1060: 84, + 0x1071: 84, + 0x1072: 84, + 0x1073: 84, + 0x1074: 84, + 0x1082: 84, + 0x1085: 84, + 0x1086: 84, + 0x108d: 84, + 0x109d: 84, + 0x135d: 84, + 0x135e: 84, + 0x135f: 84, + 0x1712: 84, + 0x1713: 84, + 0x1714: 84, + 0x1732: 84, + 0x1733: 84, + 0x1752: 84, + 0x1753: 84, + 0x1772: 84, + 0x1773: 84, + 0x17b4: 84, + 0x17b5: 84, + 0x17b7: 84, + 0x17b8: 84, + 0x17b9: 84, + 0x17ba: 84, + 0x17bb: 84, + 0x17bc: 84, + 0x17bd: 84, + 0x17c6: 84, + 0x17c9: 84, + 0x17ca: 84, + 0x17cb: 84, + 0x17cc: 84, + 0x17cd: 84, + 0x17ce: 84, + 0x17cf: 84, + 0x17d0: 84, + 0x17d1: 84, + 0x17d2: 84, + 0x17d3: 84, + 0x17dd: 84, + 0x1807: 68, + 0x180a: 67, + 0x180b: 84, + 0x180c: 84, + 0x180d: 84, + 0x180f: 84, + 0x1820: 68, + 0x1821: 68, + 0x1822: 68, + 0x1823: 68, + 0x1824: 68, + 0x1825: 68, + 0x1826: 68, + 0x1827: 68, + 0x1828: 68, + 0x1829: 68, + 0x182a: 68, + 0x182b: 68, + 0x182c: 68, + 0x182d: 68, + 0x182e: 68, + 0x182f: 68, + 0x1830: 68, + 0x1831: 68, + 0x1832: 68, + 0x1833: 68, + 0x1834: 68, + 0x1835: 68, + 0x1836: 68, + 0x1837: 68, + 0x1838: 68, + 0x1839: 68, + 0x183a: 68, + 0x183b: 68, + 0x183c: 68, + 0x183d: 68, + 0x183e: 68, + 0x183f: 68, + 0x1840: 68, + 0x1841: 68, + 0x1842: 68, + 0x1843: 68, + 0x1844: 68, + 0x1845: 68, + 0x1846: 68, + 0x1847: 68, + 0x1848: 68, + 0x1849: 68, + 0x184a: 68, + 0x184b: 68, + 0x184c: 68, + 0x184d: 68, + 0x184e: 68, + 0x184f: 68, + 0x1850: 68, + 0x1851: 68, + 0x1852: 68, + 0x1853: 68, + 0x1854: 68, + 0x1855: 68, + 0x1856: 68, + 0x1857: 68, + 0x1858: 68, + 0x1859: 68, + 0x185a: 68, + 0x185b: 68, + 0x185c: 68, + 0x185d: 68, + 0x185e: 68, + 0x185f: 68, + 0x1860: 68, + 0x1861: 68, + 0x1862: 68, + 0x1863: 68, + 0x1864: 68, + 0x1865: 68, + 0x1866: 68, + 0x1867: 68, + 0x1868: 68, + 0x1869: 68, + 0x186a: 68, + 0x186b: 68, + 0x186c: 68, + 0x186d: 68, + 0x186e: 68, + 0x186f: 68, + 0x1870: 68, + 0x1871: 68, + 0x1872: 68, + 0x1873: 68, + 0x1874: 68, + 0x1875: 68, + 0x1876: 68, + 0x1877: 68, + 0x1878: 68, + 0x1885: 84, + 0x1886: 84, + 0x1887: 68, + 0x1888: 68, + 0x1889: 68, + 0x188a: 68, + 0x188b: 68, + 0x188c: 68, + 0x188d: 68, + 0x188e: 68, + 0x188f: 68, + 0x1890: 68, + 0x1891: 68, + 0x1892: 68, + 0x1893: 68, + 0x1894: 68, + 0x1895: 68, + 0x1896: 68, + 0x1897: 68, + 0x1898: 68, + 0x1899: 68, + 0x189a: 68, + 0x189b: 68, + 0x189c: 68, + 0x189d: 68, + 0x189e: 68, + 0x189f: 68, + 0x18a0: 68, + 0x18a1: 68, + 0x18a2: 68, + 0x18a3: 68, + 0x18a4: 68, + 0x18a5: 68, + 0x18a6: 68, + 0x18a7: 68, + 0x18a8: 68, + 0x18a9: 84, + 0x18aa: 68, + 0x1920: 84, + 0x1921: 84, + 0x1922: 84, + 0x1927: 84, + 0x1928: 84, + 0x1932: 84, + 0x1939: 84, + 0x193a: 84, + 0x193b: 84, + 0x1a17: 84, + 0x1a18: 84, + 0x1a1b: 84, + 0x1a56: 84, + 0x1a58: 84, + 0x1a59: 84, + 0x1a5a: 84, + 0x1a5b: 84, + 0x1a5c: 84, + 0x1a5d: 84, + 0x1a5e: 84, + 0x1a60: 84, + 0x1a62: 84, + 0x1a65: 84, + 0x1a66: 84, + 0x1a67: 84, + 0x1a68: 84, + 0x1a69: 84, + 0x1a6a: 84, + 0x1a6b: 84, + 0x1a6c: 84, + 0x1a73: 84, + 0x1a74: 84, + 0x1a75: 84, + 0x1a76: 84, + 0x1a77: 84, + 0x1a78: 84, + 0x1a79: 84, + 0x1a7a: 84, + 0x1a7b: 84, + 0x1a7c: 84, + 0x1a7f: 84, + 0x1ab0: 84, + 0x1ab1: 84, + 0x1ab2: 84, + 0x1ab3: 84, + 0x1ab4: 84, + 0x1ab5: 84, + 0x1ab6: 84, + 0x1ab7: 84, + 0x1ab8: 84, + 0x1ab9: 84, + 0x1aba: 84, + 0x1abb: 84, + 0x1abc: 84, + 0x1abd: 84, + 0x1abe: 84, + 0x1abf: 84, + 0x1ac0: 84, + 0x1ac1: 84, + 0x1ac2: 84, + 0x1ac3: 84, + 0x1ac4: 84, + 0x1ac5: 84, + 0x1ac6: 84, + 0x1ac7: 84, + 0x1ac8: 84, + 0x1ac9: 84, + 0x1aca: 84, + 0x1acb: 84, + 0x1acc: 84, + 0x1acd: 84, + 0x1ace: 84, + 0x1b00: 84, + 0x1b01: 84, + 0x1b02: 84, + 0x1b03: 84, + 0x1b34: 84, + 0x1b36: 84, + 0x1b37: 84, + 0x1b38: 84, + 0x1b39: 84, + 0x1b3a: 84, + 0x1b3c: 84, + 0x1b42: 84, + 0x1b6b: 84, + 0x1b6c: 84, + 0x1b6d: 84, + 0x1b6e: 84, + 0x1b6f: 84, + 0x1b70: 84, + 0x1b71: 84, + 0x1b72: 84, + 0x1b73: 84, + 0x1b80: 84, + 0x1b81: 84, + 0x1ba2: 84, + 0x1ba3: 84, + 0x1ba4: 84, + 0x1ba5: 84, + 0x1ba8: 84, + 0x1ba9: 84, + 0x1bab: 84, + 0x1bac: 84, + 0x1bad: 84, + 0x1be6: 84, + 0x1be8: 84, + 0x1be9: 84, + 0x1bed: 84, + 0x1bef: 84, + 0x1bf0: 84, + 0x1bf1: 84, + 0x1c2c: 84, + 0x1c2d: 84, + 0x1c2e: 84, + 0x1c2f: 84, + 0x1c30: 84, + 0x1c31: 84, + 0x1c32: 84, + 0x1c33: 84, + 0x1c36: 84, + 0x1c37: 84, + 0x1cd0: 84, + 0x1cd1: 84, + 0x1cd2: 84, + 0x1cd4: 84, + 0x1cd5: 84, + 0x1cd6: 84, + 0x1cd7: 84, + 0x1cd8: 84, + 0x1cd9: 84, + 0x1cda: 84, + 0x1cdb: 84, + 0x1cdc: 84, + 0x1cdd: 84, + 0x1cde: 84, + 0x1cdf: 84, + 0x1ce0: 84, + 0x1ce2: 84, + 0x1ce3: 84, + 0x1ce4: 84, + 0x1ce5: 84, + 0x1ce6: 84, + 0x1ce7: 84, + 0x1ce8: 84, + 0x1ced: 84, + 0x1cf4: 84, + 0x1cf8: 84, + 0x1cf9: 84, + 0x1dc0: 84, + 0x1dc1: 84, + 0x1dc2: 84, + 0x1dc3: 84, + 0x1dc4: 84, + 0x1dc5: 84, + 0x1dc6: 84, + 0x1dc7: 84, + 0x1dc8: 84, + 0x1dc9: 84, + 0x1dca: 84, + 0x1dcb: 84, + 0x1dcc: 84, + 0x1dcd: 84, + 0x1dce: 84, + 0x1dcf: 84, + 0x1dd0: 84, + 0x1dd1: 84, + 0x1dd2: 84, + 0x1dd3: 84, + 0x1dd4: 84, + 0x1dd5: 84, + 0x1dd6: 84, + 0x1dd7: 84, + 0x1dd8: 84, + 0x1dd9: 84, + 0x1dda: 84, + 0x1ddb: 84, + 0x1ddc: 84, + 0x1ddd: 84, + 0x1dde: 84, + 0x1ddf: 84, + 0x1de0: 84, + 0x1de1: 84, + 0x1de2: 84, + 0x1de3: 84, + 0x1de4: 84, + 0x1de5: 84, + 0x1de6: 84, + 0x1de7: 84, + 0x1de8: 84, + 0x1de9: 84, + 0x1dea: 84, + 0x1deb: 84, + 0x1dec: 84, + 0x1ded: 84, + 0x1dee: 84, + 0x1def: 84, + 0x1df0: 84, + 0x1df1: 84, + 0x1df2: 84, + 0x1df3: 84, + 0x1df4: 84, + 0x1df5: 84, + 0x1df6: 84, + 0x1df7: 84, + 0x1df8: 84, + 0x1df9: 84, + 0x1dfa: 84, + 0x1dfb: 84, + 0x1dfc: 84, + 0x1dfd: 84, + 0x1dfe: 84, + 0x1dff: 84, + 0x200b: 84, + 0x200d: 67, + 0x200e: 84, + 0x200f: 84, + 0x202a: 84, + 0x202b: 84, + 0x202c: 84, + 0x202d: 84, + 0x202e: 84, + 0x2060: 84, + 0x2061: 84, + 0x2062: 84, + 0x2063: 84, + 0x2064: 84, + 0x206a: 84, + 0x206b: 84, + 0x206c: 84, + 0x206d: 84, + 0x206e: 84, + 0x206f: 84, + 0x20d0: 84, + 0x20d1: 84, + 0x20d2: 84, + 0x20d3: 84, + 0x20d4: 84, + 0x20d5: 84, + 0x20d6: 84, + 0x20d7: 84, + 0x20d8: 84, + 0x20d9: 84, + 0x20da: 84, + 0x20db: 84, + 0x20dc: 84, + 0x20dd: 84, + 0x20de: 84, + 0x20df: 84, + 0x20e0: 84, + 0x20e1: 84, + 0x20e2: 84, + 0x20e3: 84, + 0x20e4: 84, + 0x20e5: 84, + 0x20e6: 84, + 0x20e7: 84, + 0x20e8: 84, + 0x20e9: 84, + 0x20ea: 84, + 0x20eb: 84, + 0x20ec: 84, + 0x20ed: 84, + 0x20ee: 84, + 0x20ef: 84, + 0x20f0: 84, + 0x2cef: 84, + 0x2cf0: 84, + 0x2cf1: 84, + 0x2d7f: 84, + 0x2de0: 84, + 0x2de1: 84, + 0x2de2: 84, + 0x2de3: 84, + 0x2de4: 84, + 0x2de5: 84, + 0x2de6: 84, + 0x2de7: 84, + 0x2de8: 84, + 0x2de9: 84, + 0x2dea: 84, + 0x2deb: 84, + 0x2dec: 84, + 0x2ded: 84, + 0x2dee: 84, + 0x2def: 84, + 0x2df0: 84, + 0x2df1: 84, + 0x2df2: 84, + 0x2df3: 84, + 0x2df4: 84, + 0x2df5: 84, + 0x2df6: 84, + 0x2df7: 84, + 0x2df8: 84, + 0x2df9: 84, + 0x2dfa: 84, + 0x2dfb: 84, + 0x2dfc: 84, + 0x2dfd: 84, + 0x2dfe: 84, + 0x2dff: 84, + 0x302a: 84, + 0x302b: 84, + 0x302c: 84, + 0x302d: 84, + 0x3099: 84, + 0x309a: 84, + 0xa66f: 84, + 0xa670: 84, + 0xa671: 84, + 0xa672: 84, + 0xa674: 84, + 0xa675: 84, + 0xa676: 84, + 0xa677: 84, + 0xa678: 84, + 0xa679: 84, + 0xa67a: 84, + 0xa67b: 84, + 0xa67c: 84, + 0xa67d: 84, + 0xa69e: 84, + 0xa69f: 84, + 0xa6f0: 84, + 0xa6f1: 84, + 0xa802: 84, + 0xa806: 84, + 0xa80b: 84, + 0xa825: 84, + 0xa826: 84, + 0xa82c: 84, + 0xa840: 68, + 0xa841: 68, + 0xa842: 68, + 0xa843: 68, + 0xa844: 68, + 0xa845: 68, + 0xa846: 68, + 0xa847: 68, + 0xa848: 68, + 0xa849: 68, + 0xa84a: 68, + 0xa84b: 68, + 0xa84c: 68, + 0xa84d: 68, + 0xa84e: 68, + 0xa84f: 68, + 0xa850: 68, + 0xa851: 68, + 0xa852: 68, + 0xa853: 68, + 0xa854: 68, + 0xa855: 68, + 0xa856: 68, + 0xa857: 68, + 0xa858: 68, + 0xa859: 68, + 0xa85a: 68, + 0xa85b: 68, + 0xa85c: 68, + 0xa85d: 68, + 0xa85e: 68, + 0xa85f: 68, + 0xa860: 68, + 0xa861: 68, + 0xa862: 68, + 0xa863: 68, + 0xa864: 68, + 0xa865: 68, + 0xa866: 68, + 0xa867: 68, + 0xa868: 68, + 0xa869: 68, + 0xa86a: 68, + 0xa86b: 68, + 0xa86c: 68, + 0xa86d: 68, + 0xa86e: 68, + 0xa86f: 68, + 0xa870: 68, + 0xa871: 68, + 0xa872: 76, + 0xa8c4: 84, + 0xa8c5: 84, + 0xa8e0: 84, + 0xa8e1: 84, + 0xa8e2: 84, + 0xa8e3: 84, + 0xa8e4: 84, + 0xa8e5: 84, + 0xa8e6: 84, + 0xa8e7: 84, + 0xa8e8: 84, + 0xa8e9: 84, + 0xa8ea: 84, + 0xa8eb: 84, + 0xa8ec: 84, + 0xa8ed: 84, + 0xa8ee: 84, + 0xa8ef: 84, + 0xa8f0: 84, + 0xa8f1: 84, + 0xa8ff: 84, + 0xa926: 84, + 0xa927: 84, + 0xa928: 84, + 0xa929: 84, + 0xa92a: 84, + 0xa92b: 84, + 0xa92c: 84, + 0xa92d: 84, + 0xa947: 84, + 0xa948: 84, + 0xa949: 84, + 0xa94a: 84, + 0xa94b: 84, + 0xa94c: 84, + 0xa94d: 84, + 0xa94e: 84, + 0xa94f: 84, + 0xa950: 84, + 0xa951: 84, + 0xa980: 84, + 0xa981: 84, + 0xa982: 84, + 0xa9b3: 84, + 0xa9b6: 84, + 0xa9b7: 84, + 0xa9b8: 84, + 0xa9b9: 84, + 0xa9bc: 84, + 0xa9bd: 84, + 0xa9e5: 84, + 0xaa29: 84, + 0xaa2a: 84, + 0xaa2b: 84, + 0xaa2c: 84, + 0xaa2d: 84, + 0xaa2e: 84, + 0xaa31: 84, + 0xaa32: 84, + 0xaa35: 84, + 0xaa36: 84, + 0xaa43: 84, + 0xaa4c: 84, + 0xaa7c: 84, + 0xaab0: 84, + 0xaab2: 84, + 0xaab3: 84, + 0xaab4: 84, + 0xaab7: 84, + 0xaab8: 84, + 0xaabe: 84, + 0xaabf: 84, + 0xaac1: 84, + 0xaaec: 84, + 0xaaed: 84, + 0xaaf6: 84, + 0xabe5: 84, + 0xabe8: 84, + 0xabed: 84, + 0xfb1e: 84, + 0xfe00: 84, + 0xfe01: 84, + 0xfe02: 84, + 0xfe03: 84, + 0xfe04: 84, + 0xfe05: 84, + 0xfe06: 84, + 0xfe07: 84, + 0xfe08: 84, + 0xfe09: 84, + 0xfe0a: 84, + 0xfe0b: 84, + 0xfe0c: 84, + 0xfe0d: 84, + 0xfe0e: 84, + 0xfe0f: 84, + 0xfe20: 84, + 0xfe21: 84, + 0xfe22: 84, + 0xfe23: 84, + 0xfe24: 84, + 0xfe25: 84, + 0xfe26: 84, + 0xfe27: 84, + 0xfe28: 84, + 0xfe29: 84, + 0xfe2a: 84, + 0xfe2b: 84, + 0xfe2c: 84, + 0xfe2d: 84, + 0xfe2e: 84, + 0xfe2f: 84, + 0xfeff: 84, + 0xfff9: 84, + 0xfffa: 84, + 0xfffb: 84, + 0x101fd: 84, + 0x102e0: 84, + 0x10376: 84, + 0x10377: 84, + 0x10378: 84, + 0x10379: 84, + 0x1037a: 84, + 0x10a01: 84, + 0x10a02: 84, + 0x10a03: 84, + 0x10a05: 84, + 0x10a06: 84, + 0x10a0c: 84, + 0x10a0d: 84, + 0x10a0e: 84, + 0x10a0f: 84, + 0x10a38: 84, + 0x10a39: 84, + 0x10a3a: 84, + 0x10a3f: 84, + 0x10ac0: 68, + 0x10ac1: 68, + 0x10ac2: 68, + 0x10ac3: 68, + 0x10ac4: 68, + 0x10ac5: 82, + 0x10ac7: 82, + 0x10ac9: 82, + 0x10aca: 82, + 0x10acd: 76, + 0x10ace: 82, + 0x10acf: 82, + 0x10ad0: 82, + 0x10ad1: 82, + 0x10ad2: 82, + 0x10ad3: 68, + 0x10ad4: 68, + 0x10ad5: 68, + 0x10ad6: 68, + 0x10ad7: 76, + 0x10ad8: 68, + 0x10ad9: 68, + 0x10ada: 68, + 0x10adb: 68, + 0x10adc: 68, + 0x10add: 82, + 0x10ade: 68, + 0x10adf: 68, + 0x10ae0: 68, + 0x10ae1: 82, + 0x10ae4: 82, + 0x10ae5: 84, + 0x10ae6: 84, + 0x10aeb: 68, + 0x10aec: 68, + 0x10aed: 68, + 0x10aee: 68, + 0x10aef: 82, + 0x10b80: 68, + 0x10b81: 82, + 0x10b82: 68, + 0x10b83: 82, + 0x10b84: 82, + 0x10b85: 82, + 0x10b86: 68, + 0x10b87: 68, + 0x10b88: 68, + 0x10b89: 82, + 0x10b8a: 68, + 0x10b8b: 68, + 0x10b8c: 82, + 0x10b8d: 68, + 0x10b8e: 82, + 0x10b8f: 82, + 0x10b90: 68, + 0x10b91: 82, + 0x10ba9: 82, + 0x10baa: 82, + 0x10bab: 82, + 0x10bac: 82, + 0x10bad: 68, + 0x10bae: 68, + 0x10d00: 76, + 0x10d01: 68, + 0x10d02: 68, + 0x10d03: 68, + 0x10d04: 68, + 0x10d05: 68, + 0x10d06: 68, + 0x10d07: 68, + 0x10d08: 68, + 0x10d09: 68, + 0x10d0a: 68, + 0x10d0b: 68, + 0x10d0c: 68, + 0x10d0d: 68, + 0x10d0e: 68, + 0x10d0f: 68, + 0x10d10: 68, + 0x10d11: 68, + 0x10d12: 68, + 0x10d13: 68, + 0x10d14: 68, + 0x10d15: 68, + 0x10d16: 68, + 0x10d17: 68, + 0x10d18: 68, + 0x10d19: 68, + 0x10d1a: 68, + 0x10d1b: 68, + 0x10d1c: 68, + 0x10d1d: 68, + 0x10d1e: 68, + 0x10d1f: 68, + 0x10d20: 68, + 0x10d21: 68, + 0x10d22: 82, + 0x10d23: 68, + 0x10d24: 84, + 0x10d25: 84, + 0x10d26: 84, + 0x10d27: 84, + 0x10eab: 84, + 0x10eac: 84, + 0x10efd: 84, + 0x10efe: 84, + 0x10eff: 84, + 0x10f30: 68, + 0x10f31: 68, + 0x10f32: 68, + 0x10f33: 82, + 0x10f34: 68, + 0x10f35: 68, + 0x10f36: 68, + 0x10f37: 68, + 0x10f38: 68, + 0x10f39: 68, + 0x10f3a: 68, + 0x10f3b: 68, + 0x10f3c: 68, + 0x10f3d: 68, + 0x10f3e: 68, + 0x10f3f: 68, + 0x10f40: 68, + 0x10f41: 68, + 0x10f42: 68, + 0x10f43: 68, + 0x10f44: 68, + 0x10f46: 84, + 0x10f47: 84, + 0x10f48: 84, + 0x10f49: 84, + 0x10f4a: 84, + 0x10f4b: 84, + 0x10f4c: 84, + 0x10f4d: 84, + 0x10f4e: 84, + 0x10f4f: 84, + 0x10f50: 84, + 0x10f51: 68, + 0x10f52: 68, + 0x10f53: 68, + 0x10f54: 82, + 0x10f70: 68, + 0x10f71: 68, + 0x10f72: 68, + 0x10f73: 68, + 0x10f74: 82, + 0x10f75: 82, + 0x10f76: 68, + 0x10f77: 68, + 0x10f78: 68, + 0x10f79: 68, + 0x10f7a: 68, + 0x10f7b: 68, + 0x10f7c: 68, + 0x10f7d: 68, + 0x10f7e: 68, + 0x10f7f: 68, + 0x10f80: 68, + 0x10f81: 68, + 0x10f82: 84, + 0x10f83: 84, + 0x10f84: 84, + 0x10f85: 84, + 0x10fb0: 68, + 0x10fb2: 68, + 0x10fb3: 68, + 0x10fb4: 82, + 0x10fb5: 82, + 0x10fb6: 82, + 0x10fb8: 68, + 0x10fb9: 82, + 0x10fba: 82, + 0x10fbb: 68, + 0x10fbc: 68, + 0x10fbd: 82, + 0x10fbe: 68, + 0x10fbf: 68, + 0x10fc1: 68, + 0x10fc2: 82, + 0x10fc3: 82, + 0x10fc4: 68, + 0x10fc9: 82, + 0x10fca: 68, + 0x10fcb: 76, + 0x11001: 84, + 0x11038: 84, + 0x11039: 84, + 0x1103a: 84, + 0x1103b: 84, + 0x1103c: 84, + 0x1103d: 84, + 0x1103e: 84, + 0x1103f: 84, + 0x11040: 84, + 0x11041: 84, + 0x11042: 84, + 0x11043: 84, + 0x11044: 84, + 0x11045: 84, + 0x11046: 84, + 0x11070: 84, + 0x11073: 84, + 0x11074: 84, + 0x1107f: 84, + 0x11080: 84, + 0x11081: 84, + 0x110b3: 84, + 0x110b4: 84, + 0x110b5: 84, + 0x110b6: 84, + 0x110b9: 84, + 0x110ba: 84, + 0x110c2: 84, + 0x11100: 84, + 0x11101: 84, + 0x11102: 84, + 0x11127: 84, + 0x11128: 84, + 0x11129: 84, + 0x1112a: 84, + 0x1112b: 84, + 0x1112d: 84, + 0x1112e: 84, + 0x1112f: 84, + 0x11130: 84, + 0x11131: 84, + 0x11132: 84, + 0x11133: 84, + 0x11134: 84, + 0x11173: 84, + 0x11180: 84, + 0x11181: 84, + 0x111b6: 84, + 0x111b7: 84, + 0x111b8: 84, + 0x111b9: 84, + 0x111ba: 84, + 0x111bb: 84, + 0x111bc: 84, + 0x111bd: 84, + 0x111be: 84, + 0x111c9: 84, + 0x111ca: 84, + 0x111cb: 84, + 0x111cc: 84, + 0x111cf: 84, + 0x1122f: 84, + 0x11230: 84, + 0x11231: 84, + 0x11234: 84, + 0x11236: 84, + 0x11237: 84, + 0x1123e: 84, + 0x11241: 84, + 0x112df: 84, + 0x112e3: 84, + 0x112e4: 84, + 0x112e5: 84, + 0x112e6: 84, + 0x112e7: 84, + 0x112e8: 84, + 0x112e9: 84, + 0x112ea: 84, + 0x11300: 84, + 0x11301: 84, + 0x1133b: 84, + 0x1133c: 84, + 0x11340: 84, + 0x11366: 84, + 0x11367: 84, + 0x11368: 84, + 0x11369: 84, + 0x1136a: 84, + 0x1136b: 84, + 0x1136c: 84, + 0x11370: 84, + 0x11371: 84, + 0x11372: 84, + 0x11373: 84, + 0x11374: 84, + 0x11438: 84, + 0x11439: 84, + 0x1143a: 84, + 0x1143b: 84, + 0x1143c: 84, + 0x1143d: 84, + 0x1143e: 84, + 0x1143f: 84, + 0x11442: 84, + 0x11443: 84, + 0x11444: 84, + 0x11446: 84, + 0x1145e: 84, + 0x114b3: 84, + 0x114b4: 84, + 0x114b5: 84, + 0x114b6: 84, + 0x114b7: 84, + 0x114b8: 84, + 0x114ba: 84, + 0x114bf: 84, + 0x114c0: 84, + 0x114c2: 84, + 0x114c3: 84, + 0x115b2: 84, + 0x115b3: 84, + 0x115b4: 84, + 0x115b5: 84, + 0x115bc: 84, + 0x115bd: 84, + 0x115bf: 84, + 0x115c0: 84, + 0x115dc: 84, + 0x115dd: 84, + 0x11633: 84, + 0x11634: 84, + 0x11635: 84, + 0x11636: 84, + 0x11637: 84, + 0x11638: 84, + 0x11639: 84, + 0x1163a: 84, + 0x1163d: 84, + 0x1163f: 84, + 0x11640: 84, + 0x116ab: 84, + 0x116ad: 84, + 0x116b0: 84, + 0x116b1: 84, + 0x116b2: 84, + 0x116b3: 84, + 0x116b4: 84, + 0x116b5: 84, + 0x116b7: 84, + 0x1171d: 84, + 0x1171e: 84, + 0x1171f: 84, + 0x11722: 84, + 0x11723: 84, + 0x11724: 84, + 0x11725: 84, + 0x11727: 84, + 0x11728: 84, + 0x11729: 84, + 0x1172a: 84, + 0x1172b: 84, + 0x1182f: 84, + 0x11830: 84, + 0x11831: 84, + 0x11832: 84, + 0x11833: 84, + 0x11834: 84, + 0x11835: 84, + 0x11836: 84, + 0x11837: 84, + 0x11839: 84, + 0x1183a: 84, + 0x1193b: 84, + 0x1193c: 84, + 0x1193e: 84, + 0x11943: 84, + 0x119d4: 84, + 0x119d5: 84, + 0x119d6: 84, + 0x119d7: 84, + 0x119da: 84, + 0x119db: 84, + 0x119e0: 84, + 0x11a01: 84, + 0x11a02: 84, + 0x11a03: 84, + 0x11a04: 84, + 0x11a05: 84, + 0x11a06: 84, + 0x11a07: 84, + 0x11a08: 84, + 0x11a09: 84, + 0x11a0a: 84, + 0x11a33: 84, + 0x11a34: 84, + 0x11a35: 84, + 0x11a36: 84, + 0x11a37: 84, + 0x11a38: 84, + 0x11a3b: 84, + 0x11a3c: 84, + 0x11a3d: 84, + 0x11a3e: 84, + 0x11a47: 84, + 0x11a51: 84, + 0x11a52: 84, + 0x11a53: 84, + 0x11a54: 84, + 0x11a55: 84, + 0x11a56: 84, + 0x11a59: 84, + 0x11a5a: 84, + 0x11a5b: 84, + 0x11a8a: 84, + 0x11a8b: 84, + 0x11a8c: 84, + 0x11a8d: 84, + 0x11a8e: 84, + 0x11a8f: 84, + 0x11a90: 84, + 0x11a91: 84, + 0x11a92: 84, + 0x11a93: 84, + 0x11a94: 84, + 0x11a95: 84, + 0x11a96: 84, + 0x11a98: 84, + 0x11a99: 84, + 0x11c30: 84, + 0x11c31: 84, + 0x11c32: 84, + 0x11c33: 84, + 0x11c34: 84, + 0x11c35: 84, + 0x11c36: 84, + 0x11c38: 84, + 0x11c39: 84, + 0x11c3a: 84, + 0x11c3b: 84, + 0x11c3c: 84, + 0x11c3d: 84, + 0x11c3f: 84, + 0x11c92: 84, + 0x11c93: 84, + 0x11c94: 84, + 0x11c95: 84, + 0x11c96: 84, + 0x11c97: 84, + 0x11c98: 84, + 0x11c99: 84, + 0x11c9a: 84, + 0x11c9b: 84, + 0x11c9c: 84, + 0x11c9d: 84, + 0x11c9e: 84, + 0x11c9f: 84, + 0x11ca0: 84, + 0x11ca1: 84, + 0x11ca2: 84, + 0x11ca3: 84, + 0x11ca4: 84, + 0x11ca5: 84, + 0x11ca6: 84, + 0x11ca7: 84, + 0x11caa: 84, + 0x11cab: 84, + 0x11cac: 84, + 0x11cad: 84, + 0x11cae: 84, + 0x11caf: 84, + 0x11cb0: 84, + 0x11cb2: 84, + 0x11cb3: 84, + 0x11cb5: 84, + 0x11cb6: 84, + 0x11d31: 84, + 0x11d32: 84, + 0x11d33: 84, + 0x11d34: 84, + 0x11d35: 84, + 0x11d36: 84, + 0x11d3a: 84, + 0x11d3c: 84, + 0x11d3d: 84, + 0x11d3f: 84, + 0x11d40: 84, + 0x11d41: 84, + 0x11d42: 84, + 0x11d43: 84, + 0x11d44: 84, + 0x11d45: 84, + 0x11d47: 84, + 0x11d90: 84, + 0x11d91: 84, + 0x11d95: 84, + 0x11d97: 84, + 0x11ef3: 84, + 0x11ef4: 84, + 0x11f00: 84, + 0x11f01: 84, + 0x11f36: 84, + 0x11f37: 84, + 0x11f38: 84, + 0x11f39: 84, + 0x11f3a: 84, + 0x11f40: 84, + 0x11f42: 84, + 0x13430: 84, + 0x13431: 84, + 0x13432: 84, + 0x13433: 84, + 0x13434: 84, + 0x13435: 84, + 0x13436: 84, + 0x13437: 84, + 0x13438: 84, + 0x13439: 84, + 0x1343a: 84, + 0x1343b: 84, + 0x1343c: 84, + 0x1343d: 84, + 0x1343e: 84, + 0x1343f: 84, + 0x13440: 84, + 0x13447: 84, + 0x13448: 84, + 0x13449: 84, + 0x1344a: 84, + 0x1344b: 84, + 0x1344c: 84, + 0x1344d: 84, + 0x1344e: 84, + 0x1344f: 84, + 0x13450: 84, + 0x13451: 84, + 0x13452: 84, + 0x13453: 84, + 0x13454: 84, + 0x13455: 84, + 0x16af0: 84, + 0x16af1: 84, + 0x16af2: 84, + 0x16af3: 84, + 0x16af4: 84, + 0x16b30: 84, + 0x16b31: 84, + 0x16b32: 84, + 0x16b33: 84, + 0x16b34: 84, + 0x16b35: 84, + 0x16b36: 84, + 0x16f4f: 84, + 0x16f8f: 84, + 0x16f90: 84, + 0x16f91: 84, + 0x16f92: 84, + 0x16fe4: 84, + 0x1bc9d: 84, + 0x1bc9e: 84, + 0x1bca0: 84, + 0x1bca1: 84, + 0x1bca2: 84, + 0x1bca3: 84, + 0x1cf00: 84, + 0x1cf01: 84, + 0x1cf02: 84, + 0x1cf03: 84, + 0x1cf04: 84, + 0x1cf05: 84, + 0x1cf06: 84, + 0x1cf07: 84, + 0x1cf08: 84, + 0x1cf09: 84, + 0x1cf0a: 84, + 0x1cf0b: 84, + 0x1cf0c: 84, + 0x1cf0d: 84, + 0x1cf0e: 84, + 0x1cf0f: 84, + 0x1cf10: 84, + 0x1cf11: 84, + 0x1cf12: 84, + 0x1cf13: 84, + 0x1cf14: 84, + 0x1cf15: 84, + 0x1cf16: 84, + 0x1cf17: 84, + 0x1cf18: 84, + 0x1cf19: 84, + 0x1cf1a: 84, + 0x1cf1b: 84, + 0x1cf1c: 84, + 0x1cf1d: 84, + 0x1cf1e: 84, + 0x1cf1f: 84, + 0x1cf20: 84, + 0x1cf21: 84, + 0x1cf22: 84, + 0x1cf23: 84, + 0x1cf24: 84, + 0x1cf25: 84, + 0x1cf26: 84, + 0x1cf27: 84, + 0x1cf28: 84, + 0x1cf29: 84, + 0x1cf2a: 84, + 0x1cf2b: 84, + 0x1cf2c: 84, + 0x1cf2d: 84, + 0x1cf30: 84, + 0x1cf31: 84, + 0x1cf32: 84, + 0x1cf33: 84, + 0x1cf34: 84, + 0x1cf35: 84, + 0x1cf36: 84, + 0x1cf37: 84, + 0x1cf38: 84, + 0x1cf39: 84, + 0x1cf3a: 84, + 0x1cf3b: 84, + 0x1cf3c: 84, + 0x1cf3d: 84, + 0x1cf3e: 84, + 0x1cf3f: 84, + 0x1cf40: 84, + 0x1cf41: 84, + 0x1cf42: 84, + 0x1cf43: 84, + 0x1cf44: 84, + 0x1cf45: 84, + 0x1cf46: 84, + 0x1d167: 84, + 0x1d168: 84, + 0x1d169: 84, + 0x1d173: 84, + 0x1d174: 84, + 0x1d175: 84, + 0x1d176: 84, + 0x1d177: 84, + 0x1d178: 84, + 0x1d179: 84, + 0x1d17a: 84, + 0x1d17b: 84, + 0x1d17c: 84, + 0x1d17d: 84, + 0x1d17e: 84, + 0x1d17f: 84, + 0x1d180: 84, + 0x1d181: 84, + 0x1d182: 84, + 0x1d185: 84, + 0x1d186: 84, + 0x1d187: 84, + 0x1d188: 84, + 0x1d189: 84, + 0x1d18a: 84, + 0x1d18b: 84, + 0x1d1aa: 84, + 0x1d1ab: 84, + 0x1d1ac: 84, + 0x1d1ad: 84, + 0x1d242: 84, + 0x1d243: 84, + 0x1d244: 84, + 0x1da00: 84, + 0x1da01: 84, + 0x1da02: 84, + 0x1da03: 84, + 0x1da04: 84, + 0x1da05: 84, + 0x1da06: 84, + 0x1da07: 84, + 0x1da08: 84, + 0x1da09: 84, + 0x1da0a: 84, + 0x1da0b: 84, + 0x1da0c: 84, + 0x1da0d: 84, + 0x1da0e: 84, + 0x1da0f: 84, + 0x1da10: 84, + 0x1da11: 84, + 0x1da12: 84, + 0x1da13: 84, + 0x1da14: 84, + 0x1da15: 84, + 0x1da16: 84, + 0x1da17: 84, + 0x1da18: 84, + 0x1da19: 84, + 0x1da1a: 84, + 0x1da1b: 84, + 0x1da1c: 84, + 0x1da1d: 84, + 0x1da1e: 84, + 0x1da1f: 84, + 0x1da20: 84, + 0x1da21: 84, + 0x1da22: 84, + 0x1da23: 84, + 0x1da24: 84, + 0x1da25: 84, + 0x1da26: 84, + 0x1da27: 84, + 0x1da28: 84, + 0x1da29: 84, + 0x1da2a: 84, + 0x1da2b: 84, + 0x1da2c: 84, + 0x1da2d: 84, + 0x1da2e: 84, + 0x1da2f: 84, + 0x1da30: 84, + 0x1da31: 84, + 0x1da32: 84, + 0x1da33: 84, + 0x1da34: 84, + 0x1da35: 84, + 0x1da36: 84, + 0x1da3b: 84, + 0x1da3c: 84, + 0x1da3d: 84, + 0x1da3e: 84, + 0x1da3f: 84, + 0x1da40: 84, + 0x1da41: 84, + 0x1da42: 84, + 0x1da43: 84, + 0x1da44: 84, + 0x1da45: 84, + 0x1da46: 84, + 0x1da47: 84, + 0x1da48: 84, + 0x1da49: 84, + 0x1da4a: 84, + 0x1da4b: 84, + 0x1da4c: 84, + 0x1da4d: 84, + 0x1da4e: 84, + 0x1da4f: 84, + 0x1da50: 84, + 0x1da51: 84, + 0x1da52: 84, + 0x1da53: 84, + 0x1da54: 84, + 0x1da55: 84, + 0x1da56: 84, + 0x1da57: 84, + 0x1da58: 84, + 0x1da59: 84, + 0x1da5a: 84, + 0x1da5b: 84, + 0x1da5c: 84, + 0x1da5d: 84, + 0x1da5e: 84, + 0x1da5f: 84, + 0x1da60: 84, + 0x1da61: 84, + 0x1da62: 84, + 0x1da63: 84, + 0x1da64: 84, + 0x1da65: 84, + 0x1da66: 84, + 0x1da67: 84, + 0x1da68: 84, + 0x1da69: 84, + 0x1da6a: 84, + 0x1da6b: 84, + 0x1da6c: 84, + 0x1da75: 84, + 0x1da84: 84, + 0x1da9b: 84, + 0x1da9c: 84, + 0x1da9d: 84, + 0x1da9e: 84, + 0x1da9f: 84, + 0x1daa1: 84, + 0x1daa2: 84, + 0x1daa3: 84, + 0x1daa4: 84, + 0x1daa5: 84, + 0x1daa6: 84, + 0x1daa7: 84, + 0x1daa8: 84, + 0x1daa9: 84, + 0x1daaa: 84, + 0x1daab: 84, + 0x1daac: 84, + 0x1daad: 84, + 0x1daae: 84, + 0x1daaf: 84, + 0x1e000: 84, + 0x1e001: 84, + 0x1e002: 84, + 0x1e003: 84, + 0x1e004: 84, + 0x1e005: 84, + 0x1e006: 84, + 0x1e008: 84, + 0x1e009: 84, + 0x1e00a: 84, + 0x1e00b: 84, + 0x1e00c: 84, + 0x1e00d: 84, + 0x1e00e: 84, + 0x1e00f: 84, + 0x1e010: 84, + 0x1e011: 84, + 0x1e012: 84, + 0x1e013: 84, + 0x1e014: 84, + 0x1e015: 84, + 0x1e016: 84, + 0x1e017: 84, + 0x1e018: 84, + 0x1e01b: 84, + 0x1e01c: 84, + 0x1e01d: 84, + 0x1e01e: 84, + 0x1e01f: 84, + 0x1e020: 84, + 0x1e021: 84, + 0x1e023: 84, + 0x1e024: 84, + 0x1e026: 84, + 0x1e027: 84, + 0x1e028: 84, + 0x1e029: 84, + 0x1e02a: 84, + 0x1e08f: 84, + 0x1e130: 84, + 0x1e131: 84, + 0x1e132: 84, + 0x1e133: 84, + 0x1e134: 84, + 0x1e135: 84, + 0x1e136: 84, + 0x1e2ae: 84, + 0x1e2ec: 84, + 0x1e2ed: 84, + 0x1e2ee: 84, + 0x1e2ef: 84, + 0x1e4ec: 84, + 0x1e4ed: 84, + 0x1e4ee: 84, + 0x1e4ef: 84, + 0x1e8d0: 84, + 0x1e8d1: 84, + 0x1e8d2: 84, + 0x1e8d3: 84, + 0x1e8d4: 84, + 0x1e8d5: 84, + 0x1e8d6: 84, + 0x1e900: 68, + 0x1e901: 68, + 0x1e902: 68, + 0x1e903: 68, + 0x1e904: 68, + 0x1e905: 68, + 0x1e906: 68, + 0x1e907: 68, + 0x1e908: 68, + 0x1e909: 68, + 0x1e90a: 68, + 0x1e90b: 68, + 0x1e90c: 68, + 0x1e90d: 68, + 0x1e90e: 68, + 0x1e90f: 68, + 0x1e910: 68, + 0x1e911: 68, + 0x1e912: 68, + 0x1e913: 68, + 0x1e914: 68, + 0x1e915: 68, + 0x1e916: 68, + 0x1e917: 68, + 0x1e918: 68, + 0x1e919: 68, + 0x1e91a: 68, + 0x1e91b: 68, + 0x1e91c: 68, + 0x1e91d: 68, + 0x1e91e: 68, + 0x1e91f: 68, + 0x1e920: 68, + 0x1e921: 68, + 0x1e922: 68, + 0x1e923: 68, + 0x1e924: 68, + 0x1e925: 68, + 0x1e926: 68, + 0x1e927: 68, + 0x1e928: 68, + 0x1e929: 68, + 0x1e92a: 68, + 0x1e92b: 68, + 0x1e92c: 68, + 0x1e92d: 68, + 0x1e92e: 68, + 0x1e92f: 68, + 0x1e930: 68, + 0x1e931: 68, + 0x1e932: 68, + 0x1e933: 68, + 0x1e934: 68, + 0x1e935: 68, + 0x1e936: 68, + 0x1e937: 68, + 0x1e938: 68, + 0x1e939: 68, + 0x1e93a: 68, + 0x1e93b: 68, + 0x1e93c: 68, + 0x1e93d: 68, + 0x1e93e: 68, + 0x1e93f: 68, + 0x1e940: 68, + 0x1e941: 68, + 0x1e942: 68, + 0x1e943: 68, + 0x1e944: 84, + 0x1e945: 84, + 0x1e946: 84, + 0x1e947: 84, + 0x1e948: 84, + 0x1e949: 84, + 0x1e94a: 84, + 0x1e94b: 84, + 0xe0001: 84, + 0xe0020: 84, + 0xe0021: 84, + 0xe0022: 84, + 0xe0023: 84, + 0xe0024: 84, + 0xe0025: 84, + 0xe0026: 84, + 0xe0027: 84, + 0xe0028: 84, + 0xe0029: 84, + 0xe002a: 84, + 0xe002b: 84, + 0xe002c: 84, + 0xe002d: 84, + 0xe002e: 84, + 0xe002f: 84, + 0xe0030: 84, + 0xe0031: 84, + 0xe0032: 84, + 0xe0033: 84, + 0xe0034: 84, + 0xe0035: 84, + 0xe0036: 84, + 0xe0037: 84, + 0xe0038: 84, + 0xe0039: 84, + 0xe003a: 84, + 0xe003b: 84, + 0xe003c: 84, + 0xe003d: 84, + 0xe003e: 84, + 0xe003f: 84, + 0xe0040: 84, + 0xe0041: 84, + 0xe0042: 84, + 0xe0043: 84, + 0xe0044: 84, + 0xe0045: 84, + 0xe0046: 84, + 0xe0047: 84, + 0xe0048: 84, + 0xe0049: 84, + 0xe004a: 84, + 0xe004b: 84, + 0xe004c: 84, + 0xe004d: 84, + 0xe004e: 84, + 0xe004f: 84, + 0xe0050: 84, + 0xe0051: 84, + 0xe0052: 84, + 0xe0053: 84, + 0xe0054: 84, + 0xe0055: 84, + 0xe0056: 84, + 0xe0057: 84, + 0xe0058: 84, + 0xe0059: 84, + 0xe005a: 84, + 0xe005b: 84, + 0xe005c: 84, + 0xe005d: 84, + 0xe005e: 84, + 0xe005f: 84, + 0xe0060: 84, + 0xe0061: 84, + 0xe0062: 84, + 0xe0063: 84, + 0xe0064: 84, + 0xe0065: 84, + 0xe0066: 84, + 0xe0067: 84, + 0xe0068: 84, + 0xe0069: 84, + 0xe006a: 84, + 0xe006b: 84, + 0xe006c: 84, + 0xe006d: 84, + 0xe006e: 84, + 0xe006f: 84, + 0xe0070: 84, + 0xe0071: 84, + 0xe0072: 84, + 0xe0073: 84, + 0xe0074: 84, + 0xe0075: 84, + 0xe0076: 84, + 0xe0077: 84, + 0xe0078: 84, + 0xe0079: 84, + 0xe007a: 84, + 0xe007b: 84, + 0xe007c: 84, + 0xe007d: 84, + 0xe007e: 84, + 0xe007f: 84, + 0xe0100: 84, + 0xe0101: 84, + 0xe0102: 84, + 0xe0103: 84, + 0xe0104: 84, + 0xe0105: 84, + 0xe0106: 84, + 0xe0107: 84, + 0xe0108: 84, + 0xe0109: 84, + 0xe010a: 84, + 0xe010b: 84, + 0xe010c: 84, + 0xe010d: 84, + 0xe010e: 84, + 0xe010f: 84, + 0xe0110: 84, + 0xe0111: 84, + 0xe0112: 84, + 0xe0113: 84, + 0xe0114: 84, + 0xe0115: 84, + 0xe0116: 84, + 0xe0117: 84, + 0xe0118: 84, + 0xe0119: 84, + 0xe011a: 84, + 0xe011b: 84, + 0xe011c: 84, + 0xe011d: 84, + 0xe011e: 84, + 0xe011f: 84, + 0xe0120: 84, + 0xe0121: 84, + 0xe0122: 84, + 0xe0123: 84, + 0xe0124: 84, + 0xe0125: 84, + 0xe0126: 84, + 0xe0127: 84, + 0xe0128: 84, + 0xe0129: 84, + 0xe012a: 84, + 0xe012b: 84, + 0xe012c: 84, + 0xe012d: 84, + 0xe012e: 84, + 0xe012f: 84, + 0xe0130: 84, + 0xe0131: 84, + 0xe0132: 84, + 0xe0133: 84, + 0xe0134: 84, + 0xe0135: 84, + 0xe0136: 84, + 0xe0137: 84, + 0xe0138: 84, + 0xe0139: 84, + 0xe013a: 84, + 0xe013b: 84, + 0xe013c: 84, + 0xe013d: 84, + 0xe013e: 84, + 0xe013f: 84, + 0xe0140: 84, + 0xe0141: 84, + 0xe0142: 84, + 0xe0143: 84, + 0xe0144: 84, + 0xe0145: 84, + 0xe0146: 84, + 0xe0147: 84, + 0xe0148: 84, + 0xe0149: 84, + 0xe014a: 84, + 0xe014b: 84, + 0xe014c: 84, + 0xe014d: 84, + 0xe014e: 84, + 0xe014f: 84, + 0xe0150: 84, + 0xe0151: 84, + 0xe0152: 84, + 0xe0153: 84, + 0xe0154: 84, + 0xe0155: 84, + 0xe0156: 84, + 0xe0157: 84, + 0xe0158: 84, + 0xe0159: 84, + 0xe015a: 84, + 0xe015b: 84, + 0xe015c: 84, + 0xe015d: 84, + 0xe015e: 84, + 0xe015f: 84, + 0xe0160: 84, + 0xe0161: 84, + 0xe0162: 84, + 0xe0163: 84, + 0xe0164: 84, + 0xe0165: 84, + 0xe0166: 84, + 0xe0167: 84, + 0xe0168: 84, + 0xe0169: 84, + 0xe016a: 84, + 0xe016b: 84, + 0xe016c: 84, + 0xe016d: 84, + 0xe016e: 84, + 0xe016f: 84, + 0xe0170: 84, + 0xe0171: 84, + 0xe0172: 84, + 0xe0173: 84, + 0xe0174: 84, + 0xe0175: 84, + 0xe0176: 84, + 0xe0177: 84, + 0xe0178: 84, + 0xe0179: 84, + 0xe017a: 84, + 0xe017b: 84, + 0xe017c: 84, + 0xe017d: 84, + 0xe017e: 84, + 0xe017f: 84, + 0xe0180: 84, + 0xe0181: 84, + 0xe0182: 84, + 0xe0183: 84, + 0xe0184: 84, + 0xe0185: 84, + 0xe0186: 84, + 0xe0187: 84, + 0xe0188: 84, + 0xe0189: 84, + 0xe018a: 84, + 0xe018b: 84, + 0xe018c: 84, + 0xe018d: 84, + 0xe018e: 84, + 0xe018f: 84, + 0xe0190: 84, + 0xe0191: 84, + 0xe0192: 84, + 0xe0193: 84, + 0xe0194: 84, + 0xe0195: 84, + 0xe0196: 84, + 0xe0197: 84, + 0xe0198: 84, + 0xe0199: 84, + 0xe019a: 84, + 0xe019b: 84, + 0xe019c: 84, + 0xe019d: 84, + 0xe019e: 84, + 0xe019f: 84, + 0xe01a0: 84, + 0xe01a1: 84, + 0xe01a2: 84, + 0xe01a3: 84, + 0xe01a4: 84, + 0xe01a5: 84, + 0xe01a6: 84, + 0xe01a7: 84, + 0xe01a8: 84, + 0xe01a9: 84, + 0xe01aa: 84, + 0xe01ab: 84, + 0xe01ac: 84, + 0xe01ad: 84, + 0xe01ae: 84, + 0xe01af: 84, + 0xe01b0: 84, + 0xe01b1: 84, + 0xe01b2: 84, + 0xe01b3: 84, + 0xe01b4: 84, + 0xe01b5: 84, + 0xe01b6: 84, + 0xe01b7: 84, + 0xe01b8: 84, + 0xe01b9: 84, + 0xe01ba: 84, + 0xe01bb: 84, + 0xe01bc: 84, + 0xe01bd: 84, + 0xe01be: 84, + 0xe01bf: 84, + 0xe01c0: 84, + 0xe01c1: 84, + 0xe01c2: 84, + 0xe01c3: 84, + 0xe01c4: 84, + 0xe01c5: 84, + 0xe01c6: 84, + 0xe01c7: 84, + 0xe01c8: 84, + 0xe01c9: 84, + 0xe01ca: 84, + 0xe01cb: 84, + 0xe01cc: 84, + 0xe01cd: 84, + 0xe01ce: 84, + 0xe01cf: 84, + 0xe01d0: 84, + 0xe01d1: 84, + 0xe01d2: 84, + 0xe01d3: 84, + 0xe01d4: 84, + 0xe01d5: 84, + 0xe01d6: 84, + 0xe01d7: 84, + 0xe01d8: 84, + 0xe01d9: 84, + 0xe01da: 84, + 0xe01db: 84, + 0xe01dc: 84, + 0xe01dd: 84, + 0xe01de: 84, + 0xe01df: 84, + 0xe01e0: 84, + 0xe01e1: 84, + 0xe01e2: 84, + 0xe01e3: 84, + 0xe01e4: 84, + 0xe01e5: 84, + 0xe01e6: 84, + 0xe01e7: 84, + 0xe01e8: 84, + 0xe01e9: 84, + 0xe01ea: 84, + 0xe01eb: 84, + 0xe01ec: 84, + 0xe01ed: 84, + 0xe01ee: 84, + 0xe01ef: 84, +} +codepoint_classes = { + 'PVALID': ( + 0x2d0000002e, + 0x300000003a, + 0x610000007b, + 0xdf000000f7, + 0xf800000100, + 0x10100000102, + 0x10300000104, + 0x10500000106, + 0x10700000108, + 0x1090000010a, + 0x10b0000010c, + 0x10d0000010e, + 0x10f00000110, + 0x11100000112, + 0x11300000114, + 0x11500000116, + 0x11700000118, + 0x1190000011a, + 0x11b0000011c, + 0x11d0000011e, + 0x11f00000120, + 0x12100000122, + 0x12300000124, + 0x12500000126, + 0x12700000128, + 0x1290000012a, + 0x12b0000012c, + 0x12d0000012e, + 0x12f00000130, + 0x13100000132, + 0x13500000136, + 0x13700000139, + 0x13a0000013b, + 0x13c0000013d, + 0x13e0000013f, + 0x14200000143, + 0x14400000145, + 0x14600000147, + 0x14800000149, + 0x14b0000014c, + 0x14d0000014e, + 0x14f00000150, + 0x15100000152, + 0x15300000154, + 0x15500000156, + 0x15700000158, + 0x1590000015a, + 0x15b0000015c, + 0x15d0000015e, + 0x15f00000160, + 0x16100000162, + 0x16300000164, + 0x16500000166, + 0x16700000168, + 0x1690000016a, + 0x16b0000016c, + 0x16d0000016e, + 0x16f00000170, + 0x17100000172, + 0x17300000174, + 0x17500000176, + 0x17700000178, + 0x17a0000017b, + 0x17c0000017d, + 0x17e0000017f, + 0x18000000181, + 0x18300000184, + 0x18500000186, + 0x18800000189, + 0x18c0000018e, + 0x19200000193, + 0x19500000196, + 0x1990000019c, + 0x19e0000019f, + 0x1a1000001a2, + 0x1a3000001a4, + 0x1a5000001a6, + 0x1a8000001a9, + 0x1aa000001ac, + 0x1ad000001ae, + 0x1b0000001b1, + 0x1b4000001b5, + 0x1b6000001b7, + 0x1b9000001bc, + 0x1bd000001c4, + 0x1ce000001cf, + 0x1d0000001d1, + 0x1d2000001d3, + 0x1d4000001d5, + 0x1d6000001d7, + 0x1d8000001d9, + 0x1da000001db, + 0x1dc000001de, + 0x1df000001e0, + 0x1e1000001e2, + 0x1e3000001e4, + 0x1e5000001e6, + 0x1e7000001e8, + 0x1e9000001ea, + 0x1eb000001ec, + 0x1ed000001ee, + 0x1ef000001f1, + 0x1f5000001f6, + 0x1f9000001fa, + 0x1fb000001fc, + 0x1fd000001fe, + 0x1ff00000200, + 0x20100000202, + 0x20300000204, + 0x20500000206, + 0x20700000208, + 0x2090000020a, + 0x20b0000020c, + 0x20d0000020e, + 0x20f00000210, + 0x21100000212, + 0x21300000214, + 0x21500000216, + 0x21700000218, + 0x2190000021a, + 0x21b0000021c, + 0x21d0000021e, + 0x21f00000220, + 0x22100000222, + 0x22300000224, + 0x22500000226, + 0x22700000228, + 0x2290000022a, + 0x22b0000022c, + 0x22d0000022e, + 0x22f00000230, + 0x23100000232, + 0x2330000023a, + 0x23c0000023d, + 0x23f00000241, + 0x24200000243, + 0x24700000248, + 0x2490000024a, + 0x24b0000024c, + 0x24d0000024e, + 0x24f000002b0, + 0x2b9000002c2, + 0x2c6000002d2, + 0x2ec000002ed, + 0x2ee000002ef, + 0x30000000340, + 0x34200000343, + 0x3460000034f, + 0x35000000370, + 0x37100000372, + 0x37300000374, + 0x37700000378, + 0x37b0000037e, + 0x39000000391, + 0x3ac000003cf, + 0x3d7000003d8, + 0x3d9000003da, + 0x3db000003dc, + 0x3dd000003de, + 0x3df000003e0, + 0x3e1000003e2, + 0x3e3000003e4, + 0x3e5000003e6, + 0x3e7000003e8, + 0x3e9000003ea, + 0x3eb000003ec, + 0x3ed000003ee, + 0x3ef000003f0, + 0x3f3000003f4, + 0x3f8000003f9, + 0x3fb000003fd, + 0x43000000460, + 0x46100000462, + 0x46300000464, + 0x46500000466, + 0x46700000468, + 0x4690000046a, + 0x46b0000046c, + 0x46d0000046e, + 0x46f00000470, + 0x47100000472, + 0x47300000474, + 0x47500000476, + 0x47700000478, + 0x4790000047a, + 0x47b0000047c, + 0x47d0000047e, + 0x47f00000480, + 0x48100000482, + 0x48300000488, + 0x48b0000048c, + 0x48d0000048e, + 0x48f00000490, + 0x49100000492, + 0x49300000494, + 0x49500000496, + 0x49700000498, + 0x4990000049a, + 0x49b0000049c, + 0x49d0000049e, + 0x49f000004a0, + 0x4a1000004a2, + 0x4a3000004a4, + 0x4a5000004a6, + 0x4a7000004a8, + 0x4a9000004aa, + 0x4ab000004ac, + 0x4ad000004ae, + 0x4af000004b0, + 0x4b1000004b2, + 0x4b3000004b4, + 0x4b5000004b6, + 0x4b7000004b8, + 0x4b9000004ba, + 0x4bb000004bc, + 0x4bd000004be, + 0x4bf000004c0, + 0x4c2000004c3, + 0x4c4000004c5, + 0x4c6000004c7, + 0x4c8000004c9, + 0x4ca000004cb, + 0x4cc000004cd, + 0x4ce000004d0, + 0x4d1000004d2, + 0x4d3000004d4, + 0x4d5000004d6, + 0x4d7000004d8, + 0x4d9000004da, + 0x4db000004dc, + 0x4dd000004de, + 0x4df000004e0, + 0x4e1000004e2, + 0x4e3000004e4, + 0x4e5000004e6, + 0x4e7000004e8, + 0x4e9000004ea, + 0x4eb000004ec, + 0x4ed000004ee, + 0x4ef000004f0, + 0x4f1000004f2, + 0x4f3000004f4, + 0x4f5000004f6, + 0x4f7000004f8, + 0x4f9000004fa, + 0x4fb000004fc, + 0x4fd000004fe, + 0x4ff00000500, + 0x50100000502, + 0x50300000504, + 0x50500000506, + 0x50700000508, + 0x5090000050a, + 0x50b0000050c, + 0x50d0000050e, + 0x50f00000510, + 0x51100000512, + 0x51300000514, + 0x51500000516, + 0x51700000518, + 0x5190000051a, + 0x51b0000051c, + 0x51d0000051e, + 0x51f00000520, + 0x52100000522, + 0x52300000524, + 0x52500000526, + 0x52700000528, + 0x5290000052a, + 0x52b0000052c, + 0x52d0000052e, + 0x52f00000530, + 0x5590000055a, + 0x56000000587, + 0x58800000589, + 0x591000005be, + 0x5bf000005c0, + 0x5c1000005c3, + 0x5c4000005c6, + 0x5c7000005c8, + 0x5d0000005eb, + 0x5ef000005f3, + 0x6100000061b, + 0x62000000640, + 0x64100000660, + 0x66e00000675, + 0x679000006d4, + 0x6d5000006dd, + 0x6df000006e9, + 0x6ea000006f0, + 0x6fa00000700, + 0x7100000074b, + 0x74d000007b2, + 0x7c0000007f6, + 0x7fd000007fe, + 0x8000000082e, + 0x8400000085c, + 0x8600000086b, + 0x87000000888, + 0x8890000088f, + 0x898000008e2, + 0x8e300000958, + 0x96000000964, + 0x96600000970, + 0x97100000984, + 0x9850000098d, + 0x98f00000991, + 0x993000009a9, + 0x9aa000009b1, + 0x9b2000009b3, + 0x9b6000009ba, + 0x9bc000009c5, + 0x9c7000009c9, + 0x9cb000009cf, + 0x9d7000009d8, + 0x9e0000009e4, + 0x9e6000009f2, + 0x9fc000009fd, + 0x9fe000009ff, + 0xa0100000a04, + 0xa0500000a0b, + 0xa0f00000a11, + 0xa1300000a29, + 0xa2a00000a31, + 0xa3200000a33, + 0xa3500000a36, + 0xa3800000a3a, + 0xa3c00000a3d, + 0xa3e00000a43, + 0xa4700000a49, + 0xa4b00000a4e, + 0xa5100000a52, + 0xa5c00000a5d, + 0xa6600000a76, + 0xa8100000a84, + 0xa8500000a8e, + 0xa8f00000a92, + 0xa9300000aa9, + 0xaaa00000ab1, + 0xab200000ab4, + 0xab500000aba, + 0xabc00000ac6, + 0xac700000aca, + 0xacb00000ace, + 0xad000000ad1, + 0xae000000ae4, + 0xae600000af0, + 0xaf900000b00, + 0xb0100000b04, + 0xb0500000b0d, + 0xb0f00000b11, + 0xb1300000b29, + 0xb2a00000b31, + 0xb3200000b34, + 0xb3500000b3a, + 0xb3c00000b45, + 0xb4700000b49, + 0xb4b00000b4e, + 0xb5500000b58, + 0xb5f00000b64, + 0xb6600000b70, + 0xb7100000b72, + 0xb8200000b84, + 0xb8500000b8b, + 0xb8e00000b91, + 0xb9200000b96, + 0xb9900000b9b, + 0xb9c00000b9d, + 0xb9e00000ba0, + 0xba300000ba5, + 0xba800000bab, + 0xbae00000bba, + 0xbbe00000bc3, + 0xbc600000bc9, + 0xbca00000bce, + 0xbd000000bd1, + 0xbd700000bd8, + 0xbe600000bf0, + 0xc0000000c0d, + 0xc0e00000c11, + 0xc1200000c29, + 0xc2a00000c3a, + 0xc3c00000c45, + 0xc4600000c49, + 0xc4a00000c4e, + 0xc5500000c57, + 0xc5800000c5b, + 0xc5d00000c5e, + 0xc6000000c64, + 0xc6600000c70, + 0xc8000000c84, + 0xc8500000c8d, + 0xc8e00000c91, + 0xc9200000ca9, + 0xcaa00000cb4, + 0xcb500000cba, + 0xcbc00000cc5, + 0xcc600000cc9, + 0xcca00000cce, + 0xcd500000cd7, + 0xcdd00000cdf, + 0xce000000ce4, + 0xce600000cf0, + 0xcf100000cf4, + 0xd0000000d0d, + 0xd0e00000d11, + 0xd1200000d45, + 0xd4600000d49, + 0xd4a00000d4f, + 0xd5400000d58, + 0xd5f00000d64, + 0xd6600000d70, + 0xd7a00000d80, + 0xd8100000d84, + 0xd8500000d97, + 0xd9a00000db2, + 0xdb300000dbc, + 0xdbd00000dbe, + 0xdc000000dc7, + 0xdca00000dcb, + 0xdcf00000dd5, + 0xdd600000dd7, + 0xdd800000de0, + 0xde600000df0, + 0xdf200000df4, + 0xe0100000e33, + 0xe3400000e3b, + 0xe4000000e4f, + 0xe5000000e5a, + 0xe8100000e83, + 0xe8400000e85, + 0xe8600000e8b, + 0xe8c00000ea4, + 0xea500000ea6, + 0xea700000eb3, + 0xeb400000ebe, + 0xec000000ec5, + 0xec600000ec7, + 0xec800000ecf, + 0xed000000eda, + 0xede00000ee0, + 0xf0000000f01, + 0xf0b00000f0c, + 0xf1800000f1a, + 0xf2000000f2a, + 0xf3500000f36, + 0xf3700000f38, + 0xf3900000f3a, + 0xf3e00000f43, + 0xf4400000f48, + 0xf4900000f4d, + 0xf4e00000f52, + 0xf5300000f57, + 0xf5800000f5c, + 0xf5d00000f69, + 0xf6a00000f6d, + 0xf7100000f73, + 0xf7400000f75, + 0xf7a00000f81, + 0xf8200000f85, + 0xf8600000f93, + 0xf9400000f98, + 0xf9900000f9d, + 0xf9e00000fa2, + 0xfa300000fa7, + 0xfa800000fac, + 0xfad00000fb9, + 0xfba00000fbd, + 0xfc600000fc7, + 0x10000000104a, + 0x10500000109e, + 0x10d0000010fb, + 0x10fd00001100, + 0x120000001249, + 0x124a0000124e, + 0x125000001257, + 0x125800001259, + 0x125a0000125e, + 0x126000001289, + 0x128a0000128e, + 0x1290000012b1, + 0x12b2000012b6, + 0x12b8000012bf, + 0x12c0000012c1, + 0x12c2000012c6, + 0x12c8000012d7, + 0x12d800001311, + 0x131200001316, + 0x13180000135b, + 0x135d00001360, + 0x138000001390, + 0x13a0000013f6, + 0x14010000166d, + 0x166f00001680, + 0x16810000169b, + 0x16a0000016eb, + 0x16f1000016f9, + 0x170000001716, + 0x171f00001735, + 0x174000001754, + 0x17600000176d, + 0x176e00001771, + 0x177200001774, + 0x1780000017b4, + 0x17b6000017d4, + 0x17d7000017d8, + 0x17dc000017de, + 0x17e0000017ea, + 0x18100000181a, + 0x182000001879, + 0x1880000018ab, + 0x18b0000018f6, + 0x19000000191f, + 0x19200000192c, + 0x19300000193c, + 0x19460000196e, + 0x197000001975, + 0x1980000019ac, + 0x19b0000019ca, + 0x19d0000019da, + 0x1a0000001a1c, + 0x1a2000001a5f, + 0x1a6000001a7d, + 0x1a7f00001a8a, + 0x1a9000001a9a, + 0x1aa700001aa8, + 0x1ab000001abe, + 0x1abf00001acf, + 0x1b0000001b4d, + 0x1b5000001b5a, + 0x1b6b00001b74, + 0x1b8000001bf4, + 0x1c0000001c38, + 0x1c4000001c4a, + 0x1c4d00001c7e, + 0x1cd000001cd3, + 0x1cd400001cfb, + 0x1d0000001d2c, + 0x1d2f00001d30, + 0x1d3b00001d3c, + 0x1d4e00001d4f, + 0x1d6b00001d78, + 0x1d7900001d9b, + 0x1dc000001e00, + 0x1e0100001e02, + 0x1e0300001e04, + 0x1e0500001e06, + 0x1e0700001e08, + 0x1e0900001e0a, + 0x1e0b00001e0c, + 0x1e0d00001e0e, + 0x1e0f00001e10, + 0x1e1100001e12, + 0x1e1300001e14, + 0x1e1500001e16, + 0x1e1700001e18, + 0x1e1900001e1a, + 0x1e1b00001e1c, + 0x1e1d00001e1e, + 0x1e1f00001e20, + 0x1e2100001e22, + 0x1e2300001e24, + 0x1e2500001e26, + 0x1e2700001e28, + 0x1e2900001e2a, + 0x1e2b00001e2c, + 0x1e2d00001e2e, + 0x1e2f00001e30, + 0x1e3100001e32, + 0x1e3300001e34, + 0x1e3500001e36, + 0x1e3700001e38, + 0x1e3900001e3a, + 0x1e3b00001e3c, + 0x1e3d00001e3e, + 0x1e3f00001e40, + 0x1e4100001e42, + 0x1e4300001e44, + 0x1e4500001e46, + 0x1e4700001e48, + 0x1e4900001e4a, + 0x1e4b00001e4c, + 0x1e4d00001e4e, + 0x1e4f00001e50, + 0x1e5100001e52, + 0x1e5300001e54, + 0x1e5500001e56, + 0x1e5700001e58, + 0x1e5900001e5a, + 0x1e5b00001e5c, + 0x1e5d00001e5e, + 0x1e5f00001e60, + 0x1e6100001e62, + 0x1e6300001e64, + 0x1e6500001e66, + 0x1e6700001e68, + 0x1e6900001e6a, + 0x1e6b00001e6c, + 0x1e6d00001e6e, + 0x1e6f00001e70, + 0x1e7100001e72, + 0x1e7300001e74, + 0x1e7500001e76, + 0x1e7700001e78, + 0x1e7900001e7a, + 0x1e7b00001e7c, + 0x1e7d00001e7e, + 0x1e7f00001e80, + 0x1e8100001e82, + 0x1e8300001e84, + 0x1e8500001e86, + 0x1e8700001e88, + 0x1e8900001e8a, + 0x1e8b00001e8c, + 0x1e8d00001e8e, + 0x1e8f00001e90, + 0x1e9100001e92, + 0x1e9300001e94, + 0x1e9500001e9a, + 0x1e9c00001e9e, + 0x1e9f00001ea0, + 0x1ea100001ea2, + 0x1ea300001ea4, + 0x1ea500001ea6, + 0x1ea700001ea8, + 0x1ea900001eaa, + 0x1eab00001eac, + 0x1ead00001eae, + 0x1eaf00001eb0, + 0x1eb100001eb2, + 0x1eb300001eb4, + 0x1eb500001eb6, + 0x1eb700001eb8, + 0x1eb900001eba, + 0x1ebb00001ebc, + 0x1ebd00001ebe, + 0x1ebf00001ec0, + 0x1ec100001ec2, + 0x1ec300001ec4, + 0x1ec500001ec6, + 0x1ec700001ec8, + 0x1ec900001eca, + 0x1ecb00001ecc, + 0x1ecd00001ece, + 0x1ecf00001ed0, + 0x1ed100001ed2, + 0x1ed300001ed4, + 0x1ed500001ed6, + 0x1ed700001ed8, + 0x1ed900001eda, + 0x1edb00001edc, + 0x1edd00001ede, + 0x1edf00001ee0, + 0x1ee100001ee2, + 0x1ee300001ee4, + 0x1ee500001ee6, + 0x1ee700001ee8, + 0x1ee900001eea, + 0x1eeb00001eec, + 0x1eed00001eee, + 0x1eef00001ef0, + 0x1ef100001ef2, + 0x1ef300001ef4, + 0x1ef500001ef6, + 0x1ef700001ef8, + 0x1ef900001efa, + 0x1efb00001efc, + 0x1efd00001efe, + 0x1eff00001f08, + 0x1f1000001f16, + 0x1f2000001f28, + 0x1f3000001f38, + 0x1f4000001f46, + 0x1f5000001f58, + 0x1f6000001f68, + 0x1f7000001f71, + 0x1f7200001f73, + 0x1f7400001f75, + 0x1f7600001f77, + 0x1f7800001f79, + 0x1f7a00001f7b, + 0x1f7c00001f7d, + 0x1fb000001fb2, + 0x1fb600001fb7, + 0x1fc600001fc7, + 0x1fd000001fd3, + 0x1fd600001fd8, + 0x1fe000001fe3, + 0x1fe400001fe8, + 0x1ff600001ff7, + 0x214e0000214f, + 0x218400002185, + 0x2c3000002c60, + 0x2c6100002c62, + 0x2c6500002c67, + 0x2c6800002c69, + 0x2c6a00002c6b, + 0x2c6c00002c6d, + 0x2c7100002c72, + 0x2c7300002c75, + 0x2c7600002c7c, + 0x2c8100002c82, + 0x2c8300002c84, + 0x2c8500002c86, + 0x2c8700002c88, + 0x2c8900002c8a, + 0x2c8b00002c8c, + 0x2c8d00002c8e, + 0x2c8f00002c90, + 0x2c9100002c92, + 0x2c9300002c94, + 0x2c9500002c96, + 0x2c9700002c98, + 0x2c9900002c9a, + 0x2c9b00002c9c, + 0x2c9d00002c9e, + 0x2c9f00002ca0, + 0x2ca100002ca2, + 0x2ca300002ca4, + 0x2ca500002ca6, + 0x2ca700002ca8, + 0x2ca900002caa, + 0x2cab00002cac, + 0x2cad00002cae, + 0x2caf00002cb0, + 0x2cb100002cb2, + 0x2cb300002cb4, + 0x2cb500002cb6, + 0x2cb700002cb8, + 0x2cb900002cba, + 0x2cbb00002cbc, + 0x2cbd00002cbe, + 0x2cbf00002cc0, + 0x2cc100002cc2, + 0x2cc300002cc4, + 0x2cc500002cc6, + 0x2cc700002cc8, + 0x2cc900002cca, + 0x2ccb00002ccc, + 0x2ccd00002cce, + 0x2ccf00002cd0, + 0x2cd100002cd2, + 0x2cd300002cd4, + 0x2cd500002cd6, + 0x2cd700002cd8, + 0x2cd900002cda, + 0x2cdb00002cdc, + 0x2cdd00002cde, + 0x2cdf00002ce0, + 0x2ce100002ce2, + 0x2ce300002ce5, + 0x2cec00002ced, + 0x2cee00002cf2, + 0x2cf300002cf4, + 0x2d0000002d26, + 0x2d2700002d28, + 0x2d2d00002d2e, + 0x2d3000002d68, + 0x2d7f00002d97, + 0x2da000002da7, + 0x2da800002daf, + 0x2db000002db7, + 0x2db800002dbf, + 0x2dc000002dc7, + 0x2dc800002dcf, + 0x2dd000002dd7, + 0x2dd800002ddf, + 0x2de000002e00, + 0x2e2f00002e30, + 0x300500003008, + 0x302a0000302e, + 0x303c0000303d, + 0x304100003097, + 0x30990000309b, + 0x309d0000309f, + 0x30a1000030fb, + 0x30fc000030ff, + 0x310500003130, + 0x31a0000031c0, + 0x31f000003200, + 0x340000004dc0, + 0x4e000000a48d, + 0xa4d00000a4fe, + 0xa5000000a60d, + 0xa6100000a62c, + 0xa6410000a642, + 0xa6430000a644, + 0xa6450000a646, + 0xa6470000a648, + 0xa6490000a64a, + 0xa64b0000a64c, + 0xa64d0000a64e, + 0xa64f0000a650, + 0xa6510000a652, + 0xa6530000a654, + 0xa6550000a656, + 0xa6570000a658, + 0xa6590000a65a, + 0xa65b0000a65c, + 0xa65d0000a65e, + 0xa65f0000a660, + 0xa6610000a662, + 0xa6630000a664, + 0xa6650000a666, + 0xa6670000a668, + 0xa6690000a66a, + 0xa66b0000a66c, + 0xa66d0000a670, + 0xa6740000a67e, + 0xa67f0000a680, + 0xa6810000a682, + 0xa6830000a684, + 0xa6850000a686, + 0xa6870000a688, + 0xa6890000a68a, + 0xa68b0000a68c, + 0xa68d0000a68e, + 0xa68f0000a690, + 0xa6910000a692, + 0xa6930000a694, + 0xa6950000a696, + 0xa6970000a698, + 0xa6990000a69a, + 0xa69b0000a69c, + 0xa69e0000a6e6, + 0xa6f00000a6f2, + 0xa7170000a720, + 0xa7230000a724, + 0xa7250000a726, + 0xa7270000a728, + 0xa7290000a72a, + 0xa72b0000a72c, + 0xa72d0000a72e, + 0xa72f0000a732, + 0xa7330000a734, + 0xa7350000a736, + 0xa7370000a738, + 0xa7390000a73a, + 0xa73b0000a73c, + 0xa73d0000a73e, + 0xa73f0000a740, + 0xa7410000a742, + 0xa7430000a744, + 0xa7450000a746, + 0xa7470000a748, + 0xa7490000a74a, + 0xa74b0000a74c, + 0xa74d0000a74e, + 0xa74f0000a750, + 0xa7510000a752, + 0xa7530000a754, + 0xa7550000a756, + 0xa7570000a758, + 0xa7590000a75a, + 0xa75b0000a75c, + 0xa75d0000a75e, + 0xa75f0000a760, + 0xa7610000a762, + 0xa7630000a764, + 0xa7650000a766, + 0xa7670000a768, + 0xa7690000a76a, + 0xa76b0000a76c, + 0xa76d0000a76e, + 0xa76f0000a770, + 0xa7710000a779, + 0xa77a0000a77b, + 0xa77c0000a77d, + 0xa77f0000a780, + 0xa7810000a782, + 0xa7830000a784, + 0xa7850000a786, + 0xa7870000a789, + 0xa78c0000a78d, + 0xa78e0000a790, + 0xa7910000a792, + 0xa7930000a796, + 0xa7970000a798, + 0xa7990000a79a, + 0xa79b0000a79c, + 0xa79d0000a79e, + 0xa79f0000a7a0, + 0xa7a10000a7a2, + 0xa7a30000a7a4, + 0xa7a50000a7a6, + 0xa7a70000a7a8, + 0xa7a90000a7aa, + 0xa7af0000a7b0, + 0xa7b50000a7b6, + 0xa7b70000a7b8, + 0xa7b90000a7ba, + 0xa7bb0000a7bc, + 0xa7bd0000a7be, + 0xa7bf0000a7c0, + 0xa7c10000a7c2, + 0xa7c30000a7c4, + 0xa7c80000a7c9, + 0xa7ca0000a7cb, + 0xa7d10000a7d2, + 0xa7d30000a7d4, + 0xa7d50000a7d6, + 0xa7d70000a7d8, + 0xa7d90000a7da, + 0xa7f60000a7f8, + 0xa7fa0000a828, + 0xa82c0000a82d, + 0xa8400000a874, + 0xa8800000a8c6, + 0xa8d00000a8da, + 0xa8e00000a8f8, + 0xa8fb0000a8fc, + 0xa8fd0000a92e, + 0xa9300000a954, + 0xa9800000a9c1, + 0xa9cf0000a9da, + 0xa9e00000a9ff, + 0xaa000000aa37, + 0xaa400000aa4e, + 0xaa500000aa5a, + 0xaa600000aa77, + 0xaa7a0000aac3, + 0xaadb0000aade, + 0xaae00000aaf0, + 0xaaf20000aaf7, + 0xab010000ab07, + 0xab090000ab0f, + 0xab110000ab17, + 0xab200000ab27, + 0xab280000ab2f, + 0xab300000ab5b, + 0xab600000ab69, + 0xabc00000abeb, + 0xabec0000abee, + 0xabf00000abfa, + 0xac000000d7a4, + 0xfa0e0000fa10, + 0xfa110000fa12, + 0xfa130000fa15, + 0xfa1f0000fa20, + 0xfa210000fa22, + 0xfa230000fa25, + 0xfa270000fa2a, + 0xfb1e0000fb1f, + 0xfe200000fe30, + 0xfe730000fe74, + 0x100000001000c, + 0x1000d00010027, + 0x100280001003b, + 0x1003c0001003e, + 0x1003f0001004e, + 0x100500001005e, + 0x10080000100fb, + 0x101fd000101fe, + 0x102800001029d, + 0x102a0000102d1, + 0x102e0000102e1, + 0x1030000010320, + 0x1032d00010341, + 0x103420001034a, + 0x103500001037b, + 0x103800001039e, + 0x103a0000103c4, + 0x103c8000103d0, + 0x104280001049e, + 0x104a0000104aa, + 0x104d8000104fc, + 0x1050000010528, + 0x1053000010564, + 0x10597000105a2, + 0x105a3000105b2, + 0x105b3000105ba, + 0x105bb000105bd, + 0x1060000010737, + 0x1074000010756, + 0x1076000010768, + 0x1078000010781, + 0x1080000010806, + 0x1080800010809, + 0x1080a00010836, + 0x1083700010839, + 0x1083c0001083d, + 0x1083f00010856, + 0x1086000010877, + 0x108800001089f, + 0x108e0000108f3, + 0x108f4000108f6, + 0x1090000010916, + 0x109200001093a, + 0x10980000109b8, + 0x109be000109c0, + 0x10a0000010a04, + 0x10a0500010a07, + 0x10a0c00010a14, + 0x10a1500010a18, + 0x10a1900010a36, + 0x10a3800010a3b, + 0x10a3f00010a40, + 0x10a6000010a7d, + 0x10a8000010a9d, + 0x10ac000010ac8, + 0x10ac900010ae7, + 0x10b0000010b36, + 0x10b4000010b56, + 0x10b6000010b73, + 0x10b8000010b92, + 0x10c0000010c49, + 0x10cc000010cf3, + 0x10d0000010d28, + 0x10d3000010d3a, + 0x10e8000010eaa, + 0x10eab00010ead, + 0x10eb000010eb2, + 0x10efd00010f1d, + 0x10f2700010f28, + 0x10f3000010f51, + 0x10f7000010f86, + 0x10fb000010fc5, + 0x10fe000010ff7, + 0x1100000011047, + 0x1106600011076, + 0x1107f000110bb, + 0x110c2000110c3, + 0x110d0000110e9, + 0x110f0000110fa, + 0x1110000011135, + 0x1113600011140, + 0x1114400011148, + 0x1115000011174, + 0x1117600011177, + 0x11180000111c5, + 0x111c9000111cd, + 0x111ce000111db, + 0x111dc000111dd, + 0x1120000011212, + 0x1121300011238, + 0x1123e00011242, + 0x1128000011287, + 0x1128800011289, + 0x1128a0001128e, + 0x1128f0001129e, + 0x1129f000112a9, + 0x112b0000112eb, + 0x112f0000112fa, + 0x1130000011304, + 0x113050001130d, + 0x1130f00011311, + 0x1131300011329, + 0x1132a00011331, + 0x1133200011334, + 0x113350001133a, + 0x1133b00011345, + 0x1134700011349, + 0x1134b0001134e, + 0x1135000011351, + 0x1135700011358, + 0x1135d00011364, + 0x113660001136d, + 0x1137000011375, + 0x114000001144b, + 0x114500001145a, + 0x1145e00011462, + 0x11480000114c6, + 0x114c7000114c8, + 0x114d0000114da, + 0x11580000115b6, + 0x115b8000115c1, + 0x115d8000115de, + 0x1160000011641, + 0x1164400011645, + 0x116500001165a, + 0x11680000116b9, + 0x116c0000116ca, + 0x117000001171b, + 0x1171d0001172c, + 0x117300001173a, + 0x1174000011747, + 0x118000001183b, + 0x118c0000118ea, + 0x118ff00011907, + 0x119090001190a, + 0x1190c00011914, + 0x1191500011917, + 0x1191800011936, + 0x1193700011939, + 0x1193b00011944, + 0x119500001195a, + 0x119a0000119a8, + 0x119aa000119d8, + 0x119da000119e2, + 0x119e3000119e5, + 0x11a0000011a3f, + 0x11a4700011a48, + 0x11a5000011a9a, + 0x11a9d00011a9e, + 0x11ab000011af9, + 0x11c0000011c09, + 0x11c0a00011c37, + 0x11c3800011c41, + 0x11c5000011c5a, + 0x11c7200011c90, + 0x11c9200011ca8, + 0x11ca900011cb7, + 0x11d0000011d07, + 0x11d0800011d0a, + 0x11d0b00011d37, + 0x11d3a00011d3b, + 0x11d3c00011d3e, + 0x11d3f00011d48, + 0x11d5000011d5a, + 0x11d6000011d66, + 0x11d6700011d69, + 0x11d6a00011d8f, + 0x11d9000011d92, + 0x11d9300011d99, + 0x11da000011daa, + 0x11ee000011ef7, + 0x11f0000011f11, + 0x11f1200011f3b, + 0x11f3e00011f43, + 0x11f5000011f5a, + 0x11fb000011fb1, + 0x120000001239a, + 0x1248000012544, + 0x12f9000012ff1, + 0x1300000013430, + 0x1344000013456, + 0x1440000014647, + 0x1680000016a39, + 0x16a4000016a5f, + 0x16a6000016a6a, + 0x16a7000016abf, + 0x16ac000016aca, + 0x16ad000016aee, + 0x16af000016af5, + 0x16b0000016b37, + 0x16b4000016b44, + 0x16b5000016b5a, + 0x16b6300016b78, + 0x16b7d00016b90, + 0x16e6000016e80, + 0x16f0000016f4b, + 0x16f4f00016f88, + 0x16f8f00016fa0, + 0x16fe000016fe2, + 0x16fe300016fe5, + 0x16ff000016ff2, + 0x17000000187f8, + 0x1880000018cd6, + 0x18d0000018d09, + 0x1aff00001aff4, + 0x1aff50001affc, + 0x1affd0001afff, + 0x1b0000001b123, + 0x1b1320001b133, + 0x1b1500001b153, + 0x1b1550001b156, + 0x1b1640001b168, + 0x1b1700001b2fc, + 0x1bc000001bc6b, + 0x1bc700001bc7d, + 0x1bc800001bc89, + 0x1bc900001bc9a, + 0x1bc9d0001bc9f, + 0x1cf000001cf2e, + 0x1cf300001cf47, + 0x1da000001da37, + 0x1da3b0001da6d, + 0x1da750001da76, + 0x1da840001da85, + 0x1da9b0001daa0, + 0x1daa10001dab0, + 0x1df000001df1f, + 0x1df250001df2b, + 0x1e0000001e007, + 0x1e0080001e019, + 0x1e01b0001e022, + 0x1e0230001e025, + 0x1e0260001e02b, + 0x1e08f0001e090, + 0x1e1000001e12d, + 0x1e1300001e13e, + 0x1e1400001e14a, + 0x1e14e0001e14f, + 0x1e2900001e2af, + 0x1e2c00001e2fa, + 0x1e4d00001e4fa, + 0x1e7e00001e7e7, + 0x1e7e80001e7ec, + 0x1e7ed0001e7ef, + 0x1e7f00001e7ff, + 0x1e8000001e8c5, + 0x1e8d00001e8d7, + 0x1e9220001e94c, + 0x1e9500001e95a, + 0x200000002a6e0, + 0x2a7000002b73a, + 0x2b7400002b81e, + 0x2b8200002cea2, + 0x2ceb00002ebe1, + 0x2ebf00002ee5e, + 0x300000003134b, + 0x31350000323b0, + ), + 'CONTEXTJ': ( + 0x200c0000200e, + ), + 'CONTEXTO': ( + 0xb7000000b8, + 0x37500000376, + 0x5f3000005f5, + 0x6600000066a, + 0x6f0000006fa, + 0x30fb000030fc, + ), +} diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/intranges.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/intranges.py new file mode 100644 index 0000000..6a43b04 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/intranges.py @@ -0,0 +1,54 @@ +""" +Given a list of integers, made up of (hopefully) a small number of long runs +of consecutive integers, compute a representation of the form +((start1, end1), (start2, end2) ...). Then answer the question "was x present +in the original list?" in time O(log(# runs)). +""" + +import bisect +from typing import List, Tuple + +def intranges_from_list(list_: List[int]) -> Tuple[int, ...]: + """Represent a list of integers as a sequence of ranges: + ((start_0, end_0), (start_1, end_1), ...), such that the original + integers are exactly those x such that start_i <= x < end_i for some i. + + Ranges are encoded as single integers (start << 32 | end), not as tuples. + """ + + sorted_list = sorted(list_) + ranges = [] + last_write = -1 + for i in range(len(sorted_list)): + if i+1 < len(sorted_list): + if sorted_list[i] == sorted_list[i+1]-1: + continue + current_range = sorted_list[last_write+1:i+1] + ranges.append(_encode_range(current_range[0], current_range[-1] + 1)) + last_write = i + + return tuple(ranges) + +def _encode_range(start: int, end: int) -> int: + return (start << 32) | end + +def _decode_range(r: int) -> Tuple[int, int]: + return (r >> 32), (r & ((1 << 32) - 1)) + + +def intranges_contain(int_: int, ranges: Tuple[int, ...]) -> bool: + """Determine if `int_` falls into one of the ranges in `ranges`.""" + tuple_ = _encode_range(int_, 0) + pos = bisect.bisect_left(ranges, tuple_) + # we could be immediately ahead of a tuple (start, end) + # with start < int_ <= end + if pos > 0: + left, right = _decode_range(ranges[pos-1]) + if left <= int_ < right: + return True + # or we could be immediately behind a tuple (int_, end) + if pos < len(ranges): + left, _ = _decode_range(ranges[pos]) + if left == int_: + return True + return False diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/package_data.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/package_data.py new file mode 100644 index 0000000..79aa47c --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/package_data.py @@ -0,0 +1,2 @@ +__version__ = '3.8' + diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/py.typed b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/py.typed new file mode 100644 index 0000000..e69de29 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/uts46data.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/uts46data.py new file mode 100644 index 0000000..6a1eddb --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/idna/uts46data.py @@ -0,0 +1,8598 @@ +# This file is automatically generated by tools/idna-data +# vim: set fileencoding=utf-8 : + +from typing import List, Tuple, Union + + +"""IDNA Mapping Table from UTS46.""" + + +__version__ = '15.1.0' +def _seg_0() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x0, '3'), + (0x1, '3'), + (0x2, '3'), + (0x3, '3'), + (0x4, '3'), + (0x5, '3'), + (0x6, '3'), + (0x7, '3'), + (0x8, '3'), + (0x9, '3'), + (0xA, '3'), + (0xB, '3'), + (0xC, '3'), + (0xD, '3'), + (0xE, '3'), + (0xF, '3'), + (0x10, '3'), + (0x11, '3'), + (0x12, '3'), + (0x13, '3'), + (0x14, '3'), + (0x15, '3'), + (0x16, '3'), + (0x17, '3'), + (0x18, '3'), + (0x19, '3'), + (0x1A, '3'), + (0x1B, '3'), + (0x1C, '3'), + (0x1D, '3'), + (0x1E, '3'), + (0x1F, '3'), + (0x20, '3'), + (0x21, '3'), + (0x22, '3'), + (0x23, '3'), + (0x24, '3'), + (0x25, '3'), + (0x26, '3'), + (0x27, '3'), + (0x28, '3'), + (0x29, '3'), + (0x2A, '3'), + (0x2B, '3'), + (0x2C, '3'), + (0x2D, 'V'), + (0x2E, 'V'), + (0x2F, '3'), + (0x30, 'V'), + (0x31, 'V'), + (0x32, 'V'), + (0x33, 'V'), + (0x34, 'V'), + (0x35, 'V'), + (0x36, 'V'), + (0x37, 'V'), + (0x38, 'V'), + (0x39, 'V'), + (0x3A, '3'), + (0x3B, '3'), + (0x3C, '3'), + (0x3D, '3'), + (0x3E, '3'), + (0x3F, '3'), + (0x40, '3'), + (0x41, 'M', 'a'), + (0x42, 'M', 'b'), + (0x43, 'M', 'c'), + (0x44, 'M', 'd'), + (0x45, 'M', 'e'), + (0x46, 'M', 'f'), + (0x47, 'M', 'g'), + (0x48, 'M', 'h'), + (0x49, 'M', 'i'), + (0x4A, 'M', 'j'), + (0x4B, 'M', 'k'), + (0x4C, 'M', 'l'), + (0x4D, 'M', 'm'), + (0x4E, 'M', 'n'), + (0x4F, 'M', 'o'), + (0x50, 'M', 'p'), + (0x51, 'M', 'q'), + (0x52, 'M', 'r'), + (0x53, 'M', 's'), + (0x54, 'M', 't'), + (0x55, 'M', 'u'), + (0x56, 'M', 'v'), + (0x57, 'M', 'w'), + (0x58, 'M', 'x'), + (0x59, 'M', 'y'), + (0x5A, 'M', 'z'), + (0x5B, '3'), + (0x5C, '3'), + (0x5D, '3'), + (0x5E, '3'), + (0x5F, '3'), + (0x60, '3'), + (0x61, 'V'), + (0x62, 'V'), + (0x63, 'V'), + ] + +def _seg_1() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x64, 'V'), + (0x65, 'V'), + (0x66, 'V'), + (0x67, 'V'), + (0x68, 'V'), + (0x69, 'V'), + (0x6A, 'V'), + (0x6B, 'V'), + (0x6C, 'V'), + (0x6D, 'V'), + (0x6E, 'V'), + (0x6F, 'V'), + (0x70, 'V'), + (0x71, 'V'), + (0x72, 'V'), + (0x73, 'V'), + (0x74, 'V'), + (0x75, 'V'), + (0x76, 'V'), + (0x77, 'V'), + (0x78, 'V'), + (0x79, 'V'), + (0x7A, 'V'), + (0x7B, '3'), + (0x7C, '3'), + (0x7D, '3'), + (0x7E, '3'), + (0x7F, '3'), + (0x80, 'X'), + (0x81, 'X'), + (0x82, 'X'), + (0x83, 'X'), + (0x84, 'X'), + (0x85, 'X'), + (0x86, 'X'), + (0x87, 'X'), + (0x88, 'X'), + (0x89, 'X'), + (0x8A, 'X'), + (0x8B, 'X'), + (0x8C, 'X'), + (0x8D, 'X'), + (0x8E, 'X'), + (0x8F, 'X'), + (0x90, 'X'), + (0x91, 'X'), + (0x92, 'X'), + (0x93, 'X'), + (0x94, 'X'), + (0x95, 'X'), + (0x96, 'X'), + (0x97, 'X'), + (0x98, 'X'), + (0x99, 'X'), + (0x9A, 'X'), + (0x9B, 'X'), + (0x9C, 'X'), + (0x9D, 'X'), + (0x9E, 'X'), + (0x9F, 'X'), + (0xA0, '3', ' '), + (0xA1, 'V'), + (0xA2, 'V'), + (0xA3, 'V'), + (0xA4, 'V'), + (0xA5, 'V'), + (0xA6, 'V'), + (0xA7, 'V'), + (0xA8, '3', ' ̈'), + (0xA9, 'V'), + (0xAA, 'M', 'a'), + (0xAB, 'V'), + (0xAC, 'V'), + (0xAD, 'I'), + (0xAE, 'V'), + (0xAF, '3', ' ̄'), + (0xB0, 'V'), + (0xB1, 'V'), + (0xB2, 'M', '2'), + (0xB3, 'M', '3'), + (0xB4, '3', ' ́'), + (0xB5, 'M', 'μ'), + (0xB6, 'V'), + (0xB7, 'V'), + (0xB8, '3', ' ̧'), + (0xB9, 'M', '1'), + (0xBA, 'M', 'o'), + (0xBB, 'V'), + (0xBC, 'M', '1⁄4'), + (0xBD, 'M', '1⁄2'), + (0xBE, 'M', '3⁄4'), + (0xBF, 'V'), + (0xC0, 'M', 'à'), + (0xC1, 'M', 'á'), + (0xC2, 'M', 'â'), + (0xC3, 'M', 'ã'), + (0xC4, 'M', 'ä'), + (0xC5, 'M', 'å'), + (0xC6, 'M', 'æ'), + (0xC7, 'M', 'ç'), + ] + +def _seg_2() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xC8, 'M', 'è'), + (0xC9, 'M', 'é'), + (0xCA, 'M', 'ê'), + (0xCB, 'M', 'ë'), + (0xCC, 'M', 'ì'), + (0xCD, 'M', 'í'), + (0xCE, 'M', 'î'), + (0xCF, 'M', 'ï'), + (0xD0, 'M', 'ð'), + (0xD1, 'M', 'ñ'), + (0xD2, 'M', 'ò'), + (0xD3, 'M', 'ó'), + (0xD4, 'M', 'ô'), + (0xD5, 'M', 'õ'), + (0xD6, 'M', 'ö'), + (0xD7, 'V'), + (0xD8, 'M', 'ø'), + (0xD9, 'M', 'ù'), + (0xDA, 'M', 'ú'), + (0xDB, 'M', 'û'), + (0xDC, 'M', 'ü'), + (0xDD, 'M', 'ý'), + (0xDE, 'M', 'þ'), + (0xDF, 'D', 'ss'), + (0xE0, 'V'), + (0xE1, 'V'), + (0xE2, 'V'), + (0xE3, 'V'), + (0xE4, 'V'), + (0xE5, 'V'), + (0xE6, 'V'), + (0xE7, 'V'), + (0xE8, 'V'), + (0xE9, 'V'), + (0xEA, 'V'), + (0xEB, 'V'), + (0xEC, 'V'), + (0xED, 'V'), + (0xEE, 'V'), + (0xEF, 'V'), + (0xF0, 'V'), + (0xF1, 'V'), + (0xF2, 'V'), + (0xF3, 'V'), + (0xF4, 'V'), + (0xF5, 'V'), + (0xF6, 'V'), + (0xF7, 'V'), + (0xF8, 'V'), + (0xF9, 'V'), + (0xFA, 'V'), + (0xFB, 'V'), + (0xFC, 'V'), + (0xFD, 'V'), + (0xFE, 'V'), + (0xFF, 'V'), + (0x100, 'M', 'ā'), + (0x101, 'V'), + (0x102, 'M', 'ă'), + (0x103, 'V'), + (0x104, 'M', 'ą'), + (0x105, 'V'), + (0x106, 'M', 'ć'), + (0x107, 'V'), + (0x108, 'M', 'ĉ'), + (0x109, 'V'), + (0x10A, 'M', 'ċ'), + (0x10B, 'V'), + (0x10C, 'M', 'č'), + (0x10D, 'V'), + (0x10E, 'M', 'ď'), + (0x10F, 'V'), + (0x110, 'M', 'đ'), + (0x111, 'V'), + (0x112, 'M', 'ē'), + (0x113, 'V'), + (0x114, 'M', 'ĕ'), + (0x115, 'V'), + (0x116, 'M', 'ė'), + (0x117, 'V'), + (0x118, 'M', 'ę'), + (0x119, 'V'), + (0x11A, 'M', 'ě'), + (0x11B, 'V'), + (0x11C, 'M', 'ĝ'), + (0x11D, 'V'), + (0x11E, 'M', 'ğ'), + (0x11F, 'V'), + (0x120, 'M', 'ġ'), + (0x121, 'V'), + (0x122, 'M', 'ģ'), + (0x123, 'V'), + (0x124, 'M', 'ĥ'), + (0x125, 'V'), + (0x126, 'M', 'ħ'), + (0x127, 'V'), + (0x128, 'M', 'ĩ'), + (0x129, 'V'), + (0x12A, 'M', 'ī'), + (0x12B, 'V'), + ] + +def _seg_3() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x12C, 'M', 'ĭ'), + (0x12D, 'V'), + (0x12E, 'M', 'į'), + (0x12F, 'V'), + (0x130, 'M', 'i̇'), + (0x131, 'V'), + (0x132, 'M', 'ij'), + (0x134, 'M', 'ĵ'), + (0x135, 'V'), + (0x136, 'M', 'ķ'), + (0x137, 'V'), + (0x139, 'M', 'ĺ'), + (0x13A, 'V'), + (0x13B, 'M', 'ļ'), + (0x13C, 'V'), + (0x13D, 'M', 'ľ'), + (0x13E, 'V'), + (0x13F, 'M', 'l·'), + (0x141, 'M', 'ł'), + (0x142, 'V'), + (0x143, 'M', 'ń'), + (0x144, 'V'), + (0x145, 'M', 'ņ'), + (0x146, 'V'), + (0x147, 'M', 'ň'), + (0x148, 'V'), + (0x149, 'M', 'ʼn'), + (0x14A, 'M', 'ŋ'), + (0x14B, 'V'), + (0x14C, 'M', 'ō'), + (0x14D, 'V'), + (0x14E, 'M', 'ŏ'), + (0x14F, 'V'), + (0x150, 'M', 'ő'), + (0x151, 'V'), + (0x152, 'M', 'œ'), + (0x153, 'V'), + (0x154, 'M', 'ŕ'), + (0x155, 'V'), + (0x156, 'M', 'ŗ'), + (0x157, 'V'), + (0x158, 'M', 'ř'), + (0x159, 'V'), + (0x15A, 'M', 'ś'), + (0x15B, 'V'), + (0x15C, 'M', 'ŝ'), + (0x15D, 'V'), + (0x15E, 'M', 'ş'), + (0x15F, 'V'), + (0x160, 'M', 'š'), + (0x161, 'V'), + (0x162, 'M', 'ţ'), + (0x163, 'V'), + (0x164, 'M', 'ť'), + (0x165, 'V'), + (0x166, 'M', 'ŧ'), + (0x167, 'V'), + (0x168, 'M', 'ũ'), + (0x169, 'V'), + (0x16A, 'M', 'ū'), + (0x16B, 'V'), + (0x16C, 'M', 'ŭ'), + (0x16D, 'V'), + (0x16E, 'M', 'ů'), + (0x16F, 'V'), + (0x170, 'M', 'ű'), + (0x171, 'V'), + (0x172, 'M', 'ų'), + (0x173, 'V'), + (0x174, 'M', 'ŵ'), + (0x175, 'V'), + (0x176, 'M', 'ŷ'), + (0x177, 'V'), + (0x178, 'M', 'ÿ'), + (0x179, 'M', 'ź'), + (0x17A, 'V'), + (0x17B, 'M', 'ż'), + (0x17C, 'V'), + (0x17D, 'M', 'ž'), + (0x17E, 'V'), + (0x17F, 'M', 's'), + (0x180, 'V'), + (0x181, 'M', 'ɓ'), + (0x182, 'M', 'ƃ'), + (0x183, 'V'), + (0x184, 'M', 'ƅ'), + (0x185, 'V'), + (0x186, 'M', 'ɔ'), + (0x187, 'M', 'ƈ'), + (0x188, 'V'), + (0x189, 'M', 'ɖ'), + (0x18A, 'M', 'ɗ'), + (0x18B, 'M', 'ƌ'), + (0x18C, 'V'), + (0x18E, 'M', 'ǝ'), + (0x18F, 'M', 'ə'), + (0x190, 'M', 'ɛ'), + (0x191, 'M', 'ƒ'), + (0x192, 'V'), + (0x193, 'M', 'ɠ'), + ] + +def _seg_4() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x194, 'M', 'ɣ'), + (0x195, 'V'), + (0x196, 'M', 'ɩ'), + (0x197, 'M', 'ɨ'), + (0x198, 'M', 'ƙ'), + (0x199, 'V'), + (0x19C, 'M', 'ɯ'), + (0x19D, 'M', 'ɲ'), + (0x19E, 'V'), + (0x19F, 'M', 'ɵ'), + (0x1A0, 'M', 'ơ'), + (0x1A1, 'V'), + (0x1A2, 'M', 'ƣ'), + (0x1A3, 'V'), + (0x1A4, 'M', 'ƥ'), + (0x1A5, 'V'), + (0x1A6, 'M', 'ʀ'), + (0x1A7, 'M', 'ƨ'), + (0x1A8, 'V'), + (0x1A9, 'M', 'ʃ'), + (0x1AA, 'V'), + (0x1AC, 'M', 'ƭ'), + (0x1AD, 'V'), + (0x1AE, 'M', 'ʈ'), + (0x1AF, 'M', 'ư'), + (0x1B0, 'V'), + (0x1B1, 'M', 'ʊ'), + (0x1B2, 'M', 'ʋ'), + (0x1B3, 'M', 'ƴ'), + (0x1B4, 'V'), + (0x1B5, 'M', 'ƶ'), + (0x1B6, 'V'), + (0x1B7, 'M', 'ʒ'), + (0x1B8, 'M', 'ƹ'), + (0x1B9, 'V'), + (0x1BC, 'M', 'ƽ'), + (0x1BD, 'V'), + (0x1C4, 'M', 'dž'), + (0x1C7, 'M', 'lj'), + (0x1CA, 'M', 'nj'), + (0x1CD, 'M', 'ǎ'), + (0x1CE, 'V'), + (0x1CF, 'M', 'ǐ'), + (0x1D0, 'V'), + (0x1D1, 'M', 'ǒ'), + (0x1D2, 'V'), + (0x1D3, 'M', 'ǔ'), + (0x1D4, 'V'), + (0x1D5, 'M', 'ǖ'), + (0x1D6, 'V'), + (0x1D7, 'M', 'ǘ'), + (0x1D8, 'V'), + (0x1D9, 'M', 'ǚ'), + (0x1DA, 'V'), + (0x1DB, 'M', 'ǜ'), + (0x1DC, 'V'), + (0x1DE, 'M', 'ǟ'), + (0x1DF, 'V'), + (0x1E0, 'M', 'ǡ'), + (0x1E1, 'V'), + (0x1E2, 'M', 'ǣ'), + (0x1E3, 'V'), + (0x1E4, 'M', 'ǥ'), + (0x1E5, 'V'), + (0x1E6, 'M', 'ǧ'), + (0x1E7, 'V'), + (0x1E8, 'M', 'ǩ'), + (0x1E9, 'V'), + (0x1EA, 'M', 'ǫ'), + (0x1EB, 'V'), + (0x1EC, 'M', 'ǭ'), + (0x1ED, 'V'), + (0x1EE, 'M', 'ǯ'), + (0x1EF, 'V'), + (0x1F1, 'M', 'dz'), + (0x1F4, 'M', 'ǵ'), + (0x1F5, 'V'), + (0x1F6, 'M', 'ƕ'), + (0x1F7, 'M', 'ƿ'), + (0x1F8, 'M', 'ǹ'), + (0x1F9, 'V'), + (0x1FA, 'M', 'ǻ'), + (0x1FB, 'V'), + (0x1FC, 'M', 'ǽ'), + (0x1FD, 'V'), + (0x1FE, 'M', 'ǿ'), + (0x1FF, 'V'), + (0x200, 'M', 'ȁ'), + (0x201, 'V'), + (0x202, 'M', 'ȃ'), + (0x203, 'V'), + (0x204, 'M', 'ȅ'), + (0x205, 'V'), + (0x206, 'M', 'ȇ'), + (0x207, 'V'), + (0x208, 'M', 'ȉ'), + (0x209, 'V'), + (0x20A, 'M', 'ȋ'), + (0x20B, 'V'), + (0x20C, 'M', 'ȍ'), + ] + +def _seg_5() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x20D, 'V'), + (0x20E, 'M', 'ȏ'), + (0x20F, 'V'), + (0x210, 'M', 'ȑ'), + (0x211, 'V'), + (0x212, 'M', 'ȓ'), + (0x213, 'V'), + (0x214, 'M', 'ȕ'), + (0x215, 'V'), + (0x216, 'M', 'ȗ'), + (0x217, 'V'), + (0x218, 'M', 'ș'), + (0x219, 'V'), + (0x21A, 'M', 'ț'), + (0x21B, 'V'), + (0x21C, 'M', 'ȝ'), + (0x21D, 'V'), + (0x21E, 'M', 'ȟ'), + (0x21F, 'V'), + (0x220, 'M', 'ƞ'), + (0x221, 'V'), + (0x222, 'M', 'ȣ'), + (0x223, 'V'), + (0x224, 'M', 'ȥ'), + (0x225, 'V'), + (0x226, 'M', 'ȧ'), + (0x227, 'V'), + (0x228, 'M', 'ȩ'), + (0x229, 'V'), + (0x22A, 'M', 'ȫ'), + (0x22B, 'V'), + (0x22C, 'M', 'ȭ'), + (0x22D, 'V'), + (0x22E, 'M', 'ȯ'), + (0x22F, 'V'), + (0x230, 'M', 'ȱ'), + (0x231, 'V'), + (0x232, 'M', 'ȳ'), + (0x233, 'V'), + (0x23A, 'M', 'ⱥ'), + (0x23B, 'M', 'ȼ'), + (0x23C, 'V'), + (0x23D, 'M', 'ƚ'), + (0x23E, 'M', 'ⱦ'), + (0x23F, 'V'), + (0x241, 'M', 'ɂ'), + (0x242, 'V'), + (0x243, 'M', 'ƀ'), + (0x244, 'M', 'ʉ'), + (0x245, 'M', 'ʌ'), + (0x246, 'M', 'ɇ'), + (0x247, 'V'), + (0x248, 'M', 'ɉ'), + (0x249, 'V'), + (0x24A, 'M', 'ɋ'), + (0x24B, 'V'), + (0x24C, 'M', 'ɍ'), + (0x24D, 'V'), + (0x24E, 'M', 'ɏ'), + (0x24F, 'V'), + (0x2B0, 'M', 'h'), + (0x2B1, 'M', 'ɦ'), + (0x2B2, 'M', 'j'), + (0x2B3, 'M', 'r'), + (0x2B4, 'M', 'ɹ'), + (0x2B5, 'M', 'ɻ'), + (0x2B6, 'M', 'ʁ'), + (0x2B7, 'M', 'w'), + (0x2B8, 'M', 'y'), + (0x2B9, 'V'), + (0x2D8, '3', ' ̆'), + (0x2D9, '3', ' ̇'), + (0x2DA, '3', ' ̊'), + (0x2DB, '3', ' ̨'), + (0x2DC, '3', ' ̃'), + (0x2DD, '3', ' ̋'), + (0x2DE, 'V'), + (0x2E0, 'M', 'ɣ'), + (0x2E1, 'M', 'l'), + (0x2E2, 'M', 's'), + (0x2E3, 'M', 'x'), + (0x2E4, 'M', 'ʕ'), + (0x2E5, 'V'), + (0x340, 'M', '̀'), + (0x341, 'M', '́'), + (0x342, 'V'), + (0x343, 'M', '̓'), + (0x344, 'M', '̈́'), + (0x345, 'M', 'ι'), + (0x346, 'V'), + (0x34F, 'I'), + (0x350, 'V'), + (0x370, 'M', 'ͱ'), + (0x371, 'V'), + (0x372, 'M', 'ͳ'), + (0x373, 'V'), + (0x374, 'M', 'ʹ'), + (0x375, 'V'), + (0x376, 'M', 'ͷ'), + (0x377, 'V'), + ] + +def _seg_6() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x378, 'X'), + (0x37A, '3', ' ι'), + (0x37B, 'V'), + (0x37E, '3', ';'), + (0x37F, 'M', 'ϳ'), + (0x380, 'X'), + (0x384, '3', ' ́'), + (0x385, '3', ' ̈́'), + (0x386, 'M', 'ά'), + (0x387, 'M', '·'), + (0x388, 'M', 'έ'), + (0x389, 'M', 'ή'), + (0x38A, 'M', 'ί'), + (0x38B, 'X'), + (0x38C, 'M', 'ό'), + (0x38D, 'X'), + (0x38E, 'M', 'ύ'), + (0x38F, 'M', 'ώ'), + (0x390, 'V'), + (0x391, 'M', 'α'), + (0x392, 'M', 'β'), + (0x393, 'M', 'γ'), + (0x394, 'M', 'δ'), + (0x395, 'M', 'ε'), + (0x396, 'M', 'ζ'), + (0x397, 'M', 'η'), + (0x398, 'M', 'θ'), + (0x399, 'M', 'ι'), + (0x39A, 'M', 'κ'), + (0x39B, 'M', 'λ'), + (0x39C, 'M', 'μ'), + (0x39D, 'M', 'ν'), + (0x39E, 'M', 'ξ'), + (0x39F, 'M', 'ο'), + (0x3A0, 'M', 'π'), + (0x3A1, 'M', 'ρ'), + (0x3A2, 'X'), + (0x3A3, 'M', 'σ'), + (0x3A4, 'M', 'τ'), + (0x3A5, 'M', 'υ'), + (0x3A6, 'M', 'φ'), + (0x3A7, 'M', 'χ'), + (0x3A8, 'M', 'ψ'), + (0x3A9, 'M', 'ω'), + (0x3AA, 'M', 'ϊ'), + (0x3AB, 'M', 'ϋ'), + (0x3AC, 'V'), + (0x3C2, 'D', 'σ'), + (0x3C3, 'V'), + (0x3CF, 'M', 'ϗ'), + (0x3D0, 'M', 'β'), + (0x3D1, 'M', 'θ'), + (0x3D2, 'M', 'υ'), + (0x3D3, 'M', 'ύ'), + (0x3D4, 'M', 'ϋ'), + (0x3D5, 'M', 'φ'), + (0x3D6, 'M', 'π'), + (0x3D7, 'V'), + (0x3D8, 'M', 'ϙ'), + (0x3D9, 'V'), + (0x3DA, 'M', 'ϛ'), + (0x3DB, 'V'), + (0x3DC, 'M', 'ϝ'), + (0x3DD, 'V'), + (0x3DE, 'M', 'ϟ'), + (0x3DF, 'V'), + (0x3E0, 'M', 'ϡ'), + (0x3E1, 'V'), + (0x3E2, 'M', 'ϣ'), + (0x3E3, 'V'), + (0x3E4, 'M', 'ϥ'), + (0x3E5, 'V'), + (0x3E6, 'M', 'ϧ'), + (0x3E7, 'V'), + (0x3E8, 'M', 'ϩ'), + (0x3E9, 'V'), + (0x3EA, 'M', 'ϫ'), + (0x3EB, 'V'), + (0x3EC, 'M', 'ϭ'), + (0x3ED, 'V'), + (0x3EE, 'M', 'ϯ'), + (0x3EF, 'V'), + (0x3F0, 'M', 'κ'), + (0x3F1, 'M', 'ρ'), + (0x3F2, 'M', 'σ'), + (0x3F3, 'V'), + (0x3F4, 'M', 'θ'), + (0x3F5, 'M', 'ε'), + (0x3F6, 'V'), + (0x3F7, 'M', 'ϸ'), + (0x3F8, 'V'), + (0x3F9, 'M', 'σ'), + (0x3FA, 'M', 'ϻ'), + (0x3FB, 'V'), + (0x3FD, 'M', 'ͻ'), + (0x3FE, 'M', 'ͼ'), + (0x3FF, 'M', 'ͽ'), + (0x400, 'M', 'ѐ'), + (0x401, 'M', 'ё'), + (0x402, 'M', 'ђ'), + ] + +def _seg_7() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x403, 'M', 'ѓ'), + (0x404, 'M', 'є'), + (0x405, 'M', 'ѕ'), + (0x406, 'M', 'і'), + (0x407, 'M', 'ї'), + (0x408, 'M', 'ј'), + (0x409, 'M', 'љ'), + (0x40A, 'M', 'њ'), + (0x40B, 'M', 'ћ'), + (0x40C, 'M', 'ќ'), + (0x40D, 'M', 'ѝ'), + (0x40E, 'M', 'ў'), + (0x40F, 'M', 'џ'), + (0x410, 'M', 'а'), + (0x411, 'M', 'б'), + (0x412, 'M', 'в'), + (0x413, 'M', 'г'), + (0x414, 'M', 'д'), + (0x415, 'M', 'е'), + (0x416, 'M', 'ж'), + (0x417, 'M', 'з'), + (0x418, 'M', 'и'), + (0x419, 'M', 'й'), + (0x41A, 'M', 'к'), + (0x41B, 'M', 'л'), + (0x41C, 'M', 'м'), + (0x41D, 'M', 'н'), + (0x41E, 'M', 'о'), + (0x41F, 'M', 'п'), + (0x420, 'M', 'р'), + (0x421, 'M', 'с'), + (0x422, 'M', 'т'), + (0x423, 'M', 'у'), + (0x424, 'M', 'ф'), + (0x425, 'M', 'х'), + (0x426, 'M', 'ц'), + (0x427, 'M', 'ч'), + (0x428, 'M', 'ш'), + (0x429, 'M', 'щ'), + (0x42A, 'M', 'ъ'), + (0x42B, 'M', 'ы'), + (0x42C, 'M', 'ь'), + (0x42D, 'M', 'э'), + (0x42E, 'M', 'ю'), + (0x42F, 'M', 'я'), + (0x430, 'V'), + (0x460, 'M', 'ѡ'), + (0x461, 'V'), + (0x462, 'M', 'ѣ'), + (0x463, 'V'), + (0x464, 'M', 'ѥ'), + (0x465, 'V'), + (0x466, 'M', 'ѧ'), + (0x467, 'V'), + (0x468, 'M', 'ѩ'), + (0x469, 'V'), + (0x46A, 'M', 'ѫ'), + (0x46B, 'V'), + (0x46C, 'M', 'ѭ'), + (0x46D, 'V'), + (0x46E, 'M', 'ѯ'), + (0x46F, 'V'), + (0x470, 'M', 'ѱ'), + (0x471, 'V'), + (0x472, 'M', 'ѳ'), + (0x473, 'V'), + (0x474, 'M', 'ѵ'), + (0x475, 'V'), + (0x476, 'M', 'ѷ'), + (0x477, 'V'), + (0x478, 'M', 'ѹ'), + (0x479, 'V'), + (0x47A, 'M', 'ѻ'), + (0x47B, 'V'), + (0x47C, 'M', 'ѽ'), + (0x47D, 'V'), + (0x47E, 'M', 'ѿ'), + (0x47F, 'V'), + (0x480, 'M', 'ҁ'), + (0x481, 'V'), + (0x48A, 'M', 'ҋ'), + (0x48B, 'V'), + (0x48C, 'M', 'ҍ'), + (0x48D, 'V'), + (0x48E, 'M', 'ҏ'), + (0x48F, 'V'), + (0x490, 'M', 'ґ'), + (0x491, 'V'), + (0x492, 'M', 'ғ'), + (0x493, 'V'), + (0x494, 'M', 'ҕ'), + (0x495, 'V'), + (0x496, 'M', 'җ'), + (0x497, 'V'), + (0x498, 'M', 'ҙ'), + (0x499, 'V'), + (0x49A, 'M', 'қ'), + (0x49B, 'V'), + (0x49C, 'M', 'ҝ'), + (0x49D, 'V'), + ] + +def _seg_8() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x49E, 'M', 'ҟ'), + (0x49F, 'V'), + (0x4A0, 'M', 'ҡ'), + (0x4A1, 'V'), + (0x4A2, 'M', 'ң'), + (0x4A3, 'V'), + (0x4A4, 'M', 'ҥ'), + (0x4A5, 'V'), + (0x4A6, 'M', 'ҧ'), + (0x4A7, 'V'), + (0x4A8, 'M', 'ҩ'), + (0x4A9, 'V'), + (0x4AA, 'M', 'ҫ'), + (0x4AB, 'V'), + (0x4AC, 'M', 'ҭ'), + (0x4AD, 'V'), + (0x4AE, 'M', 'ү'), + (0x4AF, 'V'), + (0x4B0, 'M', 'ұ'), + (0x4B1, 'V'), + (0x4B2, 'M', 'ҳ'), + (0x4B3, 'V'), + (0x4B4, 'M', 'ҵ'), + (0x4B5, 'V'), + (0x4B6, 'M', 'ҷ'), + (0x4B7, 'V'), + (0x4B8, 'M', 'ҹ'), + (0x4B9, 'V'), + (0x4BA, 'M', 'һ'), + (0x4BB, 'V'), + (0x4BC, 'M', 'ҽ'), + (0x4BD, 'V'), + (0x4BE, 'M', 'ҿ'), + (0x4BF, 'V'), + (0x4C0, 'X'), + (0x4C1, 'M', 'ӂ'), + (0x4C2, 'V'), + (0x4C3, 'M', 'ӄ'), + (0x4C4, 'V'), + (0x4C5, 'M', 'ӆ'), + (0x4C6, 'V'), + (0x4C7, 'M', 'ӈ'), + (0x4C8, 'V'), + (0x4C9, 'M', 'ӊ'), + (0x4CA, 'V'), + (0x4CB, 'M', 'ӌ'), + (0x4CC, 'V'), + (0x4CD, 'M', 'ӎ'), + (0x4CE, 'V'), + (0x4D0, 'M', 'ӑ'), + (0x4D1, 'V'), + (0x4D2, 'M', 'ӓ'), + (0x4D3, 'V'), + (0x4D4, 'M', 'ӕ'), + (0x4D5, 'V'), + (0x4D6, 'M', 'ӗ'), + (0x4D7, 'V'), + (0x4D8, 'M', 'ә'), + (0x4D9, 'V'), + (0x4DA, 'M', 'ӛ'), + (0x4DB, 'V'), + (0x4DC, 'M', 'ӝ'), + (0x4DD, 'V'), + (0x4DE, 'M', 'ӟ'), + (0x4DF, 'V'), + (0x4E0, 'M', 'ӡ'), + (0x4E1, 'V'), + (0x4E2, 'M', 'ӣ'), + (0x4E3, 'V'), + (0x4E4, 'M', 'ӥ'), + (0x4E5, 'V'), + (0x4E6, 'M', 'ӧ'), + (0x4E7, 'V'), + (0x4E8, 'M', 'ө'), + (0x4E9, 'V'), + (0x4EA, 'M', 'ӫ'), + (0x4EB, 'V'), + (0x4EC, 'M', 'ӭ'), + (0x4ED, 'V'), + (0x4EE, 'M', 'ӯ'), + (0x4EF, 'V'), + (0x4F0, 'M', 'ӱ'), + (0x4F1, 'V'), + (0x4F2, 'M', 'ӳ'), + (0x4F3, 'V'), + (0x4F4, 'M', 'ӵ'), + (0x4F5, 'V'), + (0x4F6, 'M', 'ӷ'), + (0x4F7, 'V'), + (0x4F8, 'M', 'ӹ'), + (0x4F9, 'V'), + (0x4FA, 'M', 'ӻ'), + (0x4FB, 'V'), + (0x4FC, 'M', 'ӽ'), + (0x4FD, 'V'), + (0x4FE, 'M', 'ӿ'), + (0x4FF, 'V'), + (0x500, 'M', 'ԁ'), + (0x501, 'V'), + (0x502, 'M', 'ԃ'), + ] + +def _seg_9() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x503, 'V'), + (0x504, 'M', 'ԅ'), + (0x505, 'V'), + (0x506, 'M', 'ԇ'), + (0x507, 'V'), + (0x508, 'M', 'ԉ'), + (0x509, 'V'), + (0x50A, 'M', 'ԋ'), + (0x50B, 'V'), + (0x50C, 'M', 'ԍ'), + (0x50D, 'V'), + (0x50E, 'M', 'ԏ'), + (0x50F, 'V'), + (0x510, 'M', 'ԑ'), + (0x511, 'V'), + (0x512, 'M', 'ԓ'), + (0x513, 'V'), + (0x514, 'M', 'ԕ'), + (0x515, 'V'), + (0x516, 'M', 'ԗ'), + (0x517, 'V'), + (0x518, 'M', 'ԙ'), + (0x519, 'V'), + (0x51A, 'M', 'ԛ'), + (0x51B, 'V'), + (0x51C, 'M', 'ԝ'), + (0x51D, 'V'), + (0x51E, 'M', 'ԟ'), + (0x51F, 'V'), + (0x520, 'M', 'ԡ'), + (0x521, 'V'), + (0x522, 'M', 'ԣ'), + (0x523, 'V'), + (0x524, 'M', 'ԥ'), + (0x525, 'V'), + (0x526, 'M', 'ԧ'), + (0x527, 'V'), + (0x528, 'M', 'ԩ'), + (0x529, 'V'), + (0x52A, 'M', 'ԫ'), + (0x52B, 'V'), + (0x52C, 'M', 'ԭ'), + (0x52D, 'V'), + (0x52E, 'M', 'ԯ'), + (0x52F, 'V'), + (0x530, 'X'), + (0x531, 'M', 'ա'), + (0x532, 'M', 'բ'), + (0x533, 'M', 'գ'), + (0x534, 'M', 'դ'), + (0x535, 'M', 'ե'), + (0x536, 'M', 'զ'), + (0x537, 'M', 'է'), + (0x538, 'M', 'ը'), + (0x539, 'M', 'թ'), + (0x53A, 'M', 'ժ'), + (0x53B, 'M', 'ի'), + (0x53C, 'M', 'լ'), + (0x53D, 'M', 'խ'), + (0x53E, 'M', 'ծ'), + (0x53F, 'M', 'կ'), + (0x540, 'M', 'հ'), + (0x541, 'M', 'ձ'), + (0x542, 'M', 'ղ'), + (0x543, 'M', 'ճ'), + (0x544, 'M', 'մ'), + (0x545, 'M', 'յ'), + (0x546, 'M', 'ն'), + (0x547, 'M', 'շ'), + (0x548, 'M', 'ո'), + (0x549, 'M', 'չ'), + (0x54A, 'M', 'պ'), + (0x54B, 'M', 'ջ'), + (0x54C, 'M', 'ռ'), + (0x54D, 'M', 'ս'), + (0x54E, 'M', 'վ'), + (0x54F, 'M', 'տ'), + (0x550, 'M', 'ր'), + (0x551, 'M', 'ց'), + (0x552, 'M', 'ւ'), + (0x553, 'M', 'փ'), + (0x554, 'M', 'ք'), + (0x555, 'M', 'օ'), + (0x556, 'M', 'ֆ'), + (0x557, 'X'), + (0x559, 'V'), + (0x587, 'M', 'եւ'), + (0x588, 'V'), + (0x58B, 'X'), + (0x58D, 'V'), + (0x590, 'X'), + (0x591, 'V'), + (0x5C8, 'X'), + (0x5D0, 'V'), + (0x5EB, 'X'), + (0x5EF, 'V'), + (0x5F5, 'X'), + (0x606, 'V'), + (0x61C, 'X'), + (0x61D, 'V'), + ] + +def _seg_10() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x675, 'M', 'اٴ'), + (0x676, 'M', 'وٴ'), + (0x677, 'M', 'ۇٴ'), + (0x678, 'M', 'يٴ'), + (0x679, 'V'), + (0x6DD, 'X'), + (0x6DE, 'V'), + (0x70E, 'X'), + (0x710, 'V'), + (0x74B, 'X'), + (0x74D, 'V'), + (0x7B2, 'X'), + (0x7C0, 'V'), + (0x7FB, 'X'), + (0x7FD, 'V'), + (0x82E, 'X'), + (0x830, 'V'), + (0x83F, 'X'), + (0x840, 'V'), + (0x85C, 'X'), + (0x85E, 'V'), + (0x85F, 'X'), + (0x860, 'V'), + (0x86B, 'X'), + (0x870, 'V'), + (0x88F, 'X'), + (0x898, 'V'), + (0x8E2, 'X'), + (0x8E3, 'V'), + (0x958, 'M', 'क़'), + (0x959, 'M', 'ख़'), + (0x95A, 'M', 'ग़'), + (0x95B, 'M', 'ज़'), + (0x95C, 'M', 'ड़'), + (0x95D, 'M', 'ढ़'), + (0x95E, 'M', 'फ़'), + (0x95F, 'M', 'य़'), + (0x960, 'V'), + (0x984, 'X'), + (0x985, 'V'), + (0x98D, 'X'), + (0x98F, 'V'), + (0x991, 'X'), + (0x993, 'V'), + (0x9A9, 'X'), + (0x9AA, 'V'), + (0x9B1, 'X'), + (0x9B2, 'V'), + (0x9B3, 'X'), + (0x9B6, 'V'), + (0x9BA, 'X'), + (0x9BC, 'V'), + (0x9C5, 'X'), + (0x9C7, 'V'), + (0x9C9, 'X'), + (0x9CB, 'V'), + (0x9CF, 'X'), + (0x9D7, 'V'), + (0x9D8, 'X'), + (0x9DC, 'M', 'ড়'), + (0x9DD, 'M', 'ঢ়'), + (0x9DE, 'X'), + (0x9DF, 'M', 'য়'), + (0x9E0, 'V'), + (0x9E4, 'X'), + (0x9E6, 'V'), + (0x9FF, 'X'), + (0xA01, 'V'), + (0xA04, 'X'), + (0xA05, 'V'), + (0xA0B, 'X'), + (0xA0F, 'V'), + (0xA11, 'X'), + (0xA13, 'V'), + (0xA29, 'X'), + (0xA2A, 'V'), + (0xA31, 'X'), + (0xA32, 'V'), + (0xA33, 'M', 'ਲ਼'), + (0xA34, 'X'), + (0xA35, 'V'), + (0xA36, 'M', 'ਸ਼'), + (0xA37, 'X'), + (0xA38, 'V'), + (0xA3A, 'X'), + (0xA3C, 'V'), + (0xA3D, 'X'), + (0xA3E, 'V'), + (0xA43, 'X'), + (0xA47, 'V'), + (0xA49, 'X'), + (0xA4B, 'V'), + (0xA4E, 'X'), + (0xA51, 'V'), + (0xA52, 'X'), + (0xA59, 'M', 'ਖ਼'), + (0xA5A, 'M', 'ਗ਼'), + (0xA5B, 'M', 'ਜ਼'), + (0xA5C, 'V'), + (0xA5D, 'X'), + ] + +def _seg_11() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xA5E, 'M', 'ਫ਼'), + (0xA5F, 'X'), + (0xA66, 'V'), + (0xA77, 'X'), + (0xA81, 'V'), + (0xA84, 'X'), + (0xA85, 'V'), + (0xA8E, 'X'), + (0xA8F, 'V'), + (0xA92, 'X'), + (0xA93, 'V'), + (0xAA9, 'X'), + (0xAAA, 'V'), + (0xAB1, 'X'), + (0xAB2, 'V'), + (0xAB4, 'X'), + (0xAB5, 'V'), + (0xABA, 'X'), + (0xABC, 'V'), + (0xAC6, 'X'), + (0xAC7, 'V'), + (0xACA, 'X'), + (0xACB, 'V'), + (0xACE, 'X'), + (0xAD0, 'V'), + (0xAD1, 'X'), + (0xAE0, 'V'), + (0xAE4, 'X'), + (0xAE6, 'V'), + (0xAF2, 'X'), + (0xAF9, 'V'), + (0xB00, 'X'), + (0xB01, 'V'), + (0xB04, 'X'), + (0xB05, 'V'), + (0xB0D, 'X'), + (0xB0F, 'V'), + (0xB11, 'X'), + (0xB13, 'V'), + (0xB29, 'X'), + (0xB2A, 'V'), + (0xB31, 'X'), + (0xB32, 'V'), + (0xB34, 'X'), + (0xB35, 'V'), + (0xB3A, 'X'), + (0xB3C, 'V'), + (0xB45, 'X'), + (0xB47, 'V'), + (0xB49, 'X'), + (0xB4B, 'V'), + (0xB4E, 'X'), + (0xB55, 'V'), + (0xB58, 'X'), + (0xB5C, 'M', 'ଡ଼'), + (0xB5D, 'M', 'ଢ଼'), + (0xB5E, 'X'), + (0xB5F, 'V'), + (0xB64, 'X'), + (0xB66, 'V'), + (0xB78, 'X'), + (0xB82, 'V'), + (0xB84, 'X'), + (0xB85, 'V'), + (0xB8B, 'X'), + (0xB8E, 'V'), + (0xB91, 'X'), + (0xB92, 'V'), + (0xB96, 'X'), + (0xB99, 'V'), + (0xB9B, 'X'), + (0xB9C, 'V'), + (0xB9D, 'X'), + (0xB9E, 'V'), + (0xBA0, 'X'), + (0xBA3, 'V'), + (0xBA5, 'X'), + (0xBA8, 'V'), + (0xBAB, 'X'), + (0xBAE, 'V'), + (0xBBA, 'X'), + (0xBBE, 'V'), + (0xBC3, 'X'), + (0xBC6, 'V'), + (0xBC9, 'X'), + (0xBCA, 'V'), + (0xBCE, 'X'), + (0xBD0, 'V'), + (0xBD1, 'X'), + (0xBD7, 'V'), + (0xBD8, 'X'), + (0xBE6, 'V'), + (0xBFB, 'X'), + (0xC00, 'V'), + (0xC0D, 'X'), + (0xC0E, 'V'), + (0xC11, 'X'), + (0xC12, 'V'), + (0xC29, 'X'), + (0xC2A, 'V'), + ] + +def _seg_12() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xC3A, 'X'), + (0xC3C, 'V'), + (0xC45, 'X'), + (0xC46, 'V'), + (0xC49, 'X'), + (0xC4A, 'V'), + (0xC4E, 'X'), + (0xC55, 'V'), + (0xC57, 'X'), + (0xC58, 'V'), + (0xC5B, 'X'), + (0xC5D, 'V'), + (0xC5E, 'X'), + (0xC60, 'V'), + (0xC64, 'X'), + (0xC66, 'V'), + (0xC70, 'X'), + (0xC77, 'V'), + (0xC8D, 'X'), + (0xC8E, 'V'), + (0xC91, 'X'), + (0xC92, 'V'), + (0xCA9, 'X'), + (0xCAA, 'V'), + (0xCB4, 'X'), + (0xCB5, 'V'), + (0xCBA, 'X'), + (0xCBC, 'V'), + (0xCC5, 'X'), + (0xCC6, 'V'), + (0xCC9, 'X'), + (0xCCA, 'V'), + (0xCCE, 'X'), + (0xCD5, 'V'), + (0xCD7, 'X'), + (0xCDD, 'V'), + (0xCDF, 'X'), + (0xCE0, 'V'), + (0xCE4, 'X'), + (0xCE6, 'V'), + (0xCF0, 'X'), + (0xCF1, 'V'), + (0xCF4, 'X'), + (0xD00, 'V'), + (0xD0D, 'X'), + (0xD0E, 'V'), + (0xD11, 'X'), + (0xD12, 'V'), + (0xD45, 'X'), + (0xD46, 'V'), + (0xD49, 'X'), + (0xD4A, 'V'), + (0xD50, 'X'), + (0xD54, 'V'), + (0xD64, 'X'), + (0xD66, 'V'), + (0xD80, 'X'), + (0xD81, 'V'), + (0xD84, 'X'), + (0xD85, 'V'), + (0xD97, 'X'), + (0xD9A, 'V'), + (0xDB2, 'X'), + (0xDB3, 'V'), + (0xDBC, 'X'), + (0xDBD, 'V'), + (0xDBE, 'X'), + (0xDC0, 'V'), + (0xDC7, 'X'), + (0xDCA, 'V'), + (0xDCB, 'X'), + (0xDCF, 'V'), + (0xDD5, 'X'), + (0xDD6, 'V'), + (0xDD7, 'X'), + (0xDD8, 'V'), + (0xDE0, 'X'), + (0xDE6, 'V'), + (0xDF0, 'X'), + (0xDF2, 'V'), + (0xDF5, 'X'), + (0xE01, 'V'), + (0xE33, 'M', 'ํา'), + (0xE34, 'V'), + (0xE3B, 'X'), + (0xE3F, 'V'), + (0xE5C, 'X'), + (0xE81, 'V'), + (0xE83, 'X'), + (0xE84, 'V'), + (0xE85, 'X'), + (0xE86, 'V'), + (0xE8B, 'X'), + (0xE8C, 'V'), + (0xEA4, 'X'), + (0xEA5, 'V'), + (0xEA6, 'X'), + (0xEA7, 'V'), + (0xEB3, 'M', 'ໍາ'), + (0xEB4, 'V'), + ] + +def _seg_13() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xEBE, 'X'), + (0xEC0, 'V'), + (0xEC5, 'X'), + (0xEC6, 'V'), + (0xEC7, 'X'), + (0xEC8, 'V'), + (0xECF, 'X'), + (0xED0, 'V'), + (0xEDA, 'X'), + (0xEDC, 'M', 'ຫນ'), + (0xEDD, 'M', 'ຫມ'), + (0xEDE, 'V'), + (0xEE0, 'X'), + (0xF00, 'V'), + (0xF0C, 'M', '་'), + (0xF0D, 'V'), + (0xF43, 'M', 'གྷ'), + (0xF44, 'V'), + (0xF48, 'X'), + (0xF49, 'V'), + (0xF4D, 'M', 'ཌྷ'), + (0xF4E, 'V'), + (0xF52, 'M', 'དྷ'), + (0xF53, 'V'), + (0xF57, 'M', 'བྷ'), + (0xF58, 'V'), + (0xF5C, 'M', 'ཛྷ'), + (0xF5D, 'V'), + (0xF69, 'M', 'ཀྵ'), + (0xF6A, 'V'), + (0xF6D, 'X'), + (0xF71, 'V'), + (0xF73, 'M', 'ཱི'), + (0xF74, 'V'), + (0xF75, 'M', 'ཱུ'), + (0xF76, 'M', 'ྲྀ'), + (0xF77, 'M', 'ྲཱྀ'), + (0xF78, 'M', 'ླྀ'), + (0xF79, 'M', 'ླཱྀ'), + (0xF7A, 'V'), + (0xF81, 'M', 'ཱྀ'), + (0xF82, 'V'), + (0xF93, 'M', 'ྒྷ'), + (0xF94, 'V'), + (0xF98, 'X'), + (0xF99, 'V'), + (0xF9D, 'M', 'ྜྷ'), + (0xF9E, 'V'), + (0xFA2, 'M', 'ྡྷ'), + (0xFA3, 'V'), + (0xFA7, 'M', 'ྦྷ'), + (0xFA8, 'V'), + (0xFAC, 'M', 'ྫྷ'), + (0xFAD, 'V'), + (0xFB9, 'M', 'ྐྵ'), + (0xFBA, 'V'), + (0xFBD, 'X'), + (0xFBE, 'V'), + (0xFCD, 'X'), + (0xFCE, 'V'), + (0xFDB, 'X'), + (0x1000, 'V'), + (0x10A0, 'X'), + (0x10C7, 'M', 'ⴧ'), + (0x10C8, 'X'), + (0x10CD, 'M', 'ⴭ'), + (0x10CE, 'X'), + (0x10D0, 'V'), + (0x10FC, 'M', 'ნ'), + (0x10FD, 'V'), + (0x115F, 'X'), + (0x1161, 'V'), + (0x1249, 'X'), + (0x124A, 'V'), + (0x124E, 'X'), + (0x1250, 'V'), + (0x1257, 'X'), + (0x1258, 'V'), + (0x1259, 'X'), + (0x125A, 'V'), + (0x125E, 'X'), + (0x1260, 'V'), + (0x1289, 'X'), + (0x128A, 'V'), + (0x128E, 'X'), + (0x1290, 'V'), + (0x12B1, 'X'), + (0x12B2, 'V'), + (0x12B6, 'X'), + (0x12B8, 'V'), + (0x12BF, 'X'), + (0x12C0, 'V'), + (0x12C1, 'X'), + (0x12C2, 'V'), + (0x12C6, 'X'), + (0x12C8, 'V'), + (0x12D7, 'X'), + (0x12D8, 'V'), + (0x1311, 'X'), + (0x1312, 'V'), + ] + +def _seg_14() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1316, 'X'), + (0x1318, 'V'), + (0x135B, 'X'), + (0x135D, 'V'), + (0x137D, 'X'), + (0x1380, 'V'), + (0x139A, 'X'), + (0x13A0, 'V'), + (0x13F6, 'X'), + (0x13F8, 'M', 'Ᏸ'), + (0x13F9, 'M', 'Ᏹ'), + (0x13FA, 'M', 'Ᏺ'), + (0x13FB, 'M', 'Ᏻ'), + (0x13FC, 'M', 'Ᏼ'), + (0x13FD, 'M', 'Ᏽ'), + (0x13FE, 'X'), + (0x1400, 'V'), + (0x1680, 'X'), + (0x1681, 'V'), + (0x169D, 'X'), + (0x16A0, 'V'), + (0x16F9, 'X'), + (0x1700, 'V'), + (0x1716, 'X'), + (0x171F, 'V'), + (0x1737, 'X'), + (0x1740, 'V'), + (0x1754, 'X'), + (0x1760, 'V'), + (0x176D, 'X'), + (0x176E, 'V'), + (0x1771, 'X'), + (0x1772, 'V'), + (0x1774, 'X'), + (0x1780, 'V'), + (0x17B4, 'X'), + (0x17B6, 'V'), + (0x17DE, 'X'), + (0x17E0, 'V'), + (0x17EA, 'X'), + (0x17F0, 'V'), + (0x17FA, 'X'), + (0x1800, 'V'), + (0x1806, 'X'), + (0x1807, 'V'), + (0x180B, 'I'), + (0x180E, 'X'), + (0x180F, 'I'), + (0x1810, 'V'), + (0x181A, 'X'), + (0x1820, 'V'), + (0x1879, 'X'), + (0x1880, 'V'), + (0x18AB, 'X'), + (0x18B0, 'V'), + (0x18F6, 'X'), + (0x1900, 'V'), + (0x191F, 'X'), + (0x1920, 'V'), + (0x192C, 'X'), + (0x1930, 'V'), + (0x193C, 'X'), + (0x1940, 'V'), + (0x1941, 'X'), + (0x1944, 'V'), + (0x196E, 'X'), + (0x1970, 'V'), + (0x1975, 'X'), + (0x1980, 'V'), + (0x19AC, 'X'), + (0x19B0, 'V'), + (0x19CA, 'X'), + (0x19D0, 'V'), + (0x19DB, 'X'), + (0x19DE, 'V'), + (0x1A1C, 'X'), + (0x1A1E, 'V'), + (0x1A5F, 'X'), + (0x1A60, 'V'), + (0x1A7D, 'X'), + (0x1A7F, 'V'), + (0x1A8A, 'X'), + (0x1A90, 'V'), + (0x1A9A, 'X'), + (0x1AA0, 'V'), + (0x1AAE, 'X'), + (0x1AB0, 'V'), + (0x1ACF, 'X'), + (0x1B00, 'V'), + (0x1B4D, 'X'), + (0x1B50, 'V'), + (0x1B7F, 'X'), + (0x1B80, 'V'), + (0x1BF4, 'X'), + (0x1BFC, 'V'), + (0x1C38, 'X'), + (0x1C3B, 'V'), + (0x1C4A, 'X'), + (0x1C4D, 'V'), + (0x1C80, 'M', 'в'), + ] + +def _seg_15() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1C81, 'M', 'д'), + (0x1C82, 'M', 'о'), + (0x1C83, 'M', 'с'), + (0x1C84, 'M', 'т'), + (0x1C86, 'M', 'ъ'), + (0x1C87, 'M', 'ѣ'), + (0x1C88, 'M', 'ꙋ'), + (0x1C89, 'X'), + (0x1C90, 'M', 'ა'), + (0x1C91, 'M', 'ბ'), + (0x1C92, 'M', 'გ'), + (0x1C93, 'M', 'დ'), + (0x1C94, 'M', 'ე'), + (0x1C95, 'M', 'ვ'), + (0x1C96, 'M', 'ზ'), + (0x1C97, 'M', 'თ'), + (0x1C98, 'M', 'ი'), + (0x1C99, 'M', 'კ'), + (0x1C9A, 'M', 'ლ'), + (0x1C9B, 'M', 'მ'), + (0x1C9C, 'M', 'ნ'), + (0x1C9D, 'M', 'ო'), + (0x1C9E, 'M', 'პ'), + (0x1C9F, 'M', 'ჟ'), + (0x1CA0, 'M', 'რ'), + (0x1CA1, 'M', 'ს'), + (0x1CA2, 'M', 'ტ'), + (0x1CA3, 'M', 'უ'), + (0x1CA4, 'M', 'ფ'), + (0x1CA5, 'M', 'ქ'), + (0x1CA6, 'M', 'ღ'), + (0x1CA7, 'M', 'ყ'), + (0x1CA8, 'M', 'შ'), + (0x1CA9, 'M', 'ჩ'), + (0x1CAA, 'M', 'ც'), + (0x1CAB, 'M', 'ძ'), + (0x1CAC, 'M', 'წ'), + (0x1CAD, 'M', 'ჭ'), + (0x1CAE, 'M', 'ხ'), + (0x1CAF, 'M', 'ჯ'), + (0x1CB0, 'M', 'ჰ'), + (0x1CB1, 'M', 'ჱ'), + (0x1CB2, 'M', 'ჲ'), + (0x1CB3, 'M', 'ჳ'), + (0x1CB4, 'M', 'ჴ'), + (0x1CB5, 'M', 'ჵ'), + (0x1CB6, 'M', 'ჶ'), + (0x1CB7, 'M', 'ჷ'), + (0x1CB8, 'M', 'ჸ'), + (0x1CB9, 'M', 'ჹ'), + (0x1CBA, 'M', 'ჺ'), + (0x1CBB, 'X'), + (0x1CBD, 'M', 'ჽ'), + (0x1CBE, 'M', 'ჾ'), + (0x1CBF, 'M', 'ჿ'), + (0x1CC0, 'V'), + (0x1CC8, 'X'), + (0x1CD0, 'V'), + (0x1CFB, 'X'), + (0x1D00, 'V'), + (0x1D2C, 'M', 'a'), + (0x1D2D, 'M', 'æ'), + (0x1D2E, 'M', 'b'), + (0x1D2F, 'V'), + (0x1D30, 'M', 'd'), + (0x1D31, 'M', 'e'), + (0x1D32, 'M', 'ǝ'), + (0x1D33, 'M', 'g'), + (0x1D34, 'M', 'h'), + (0x1D35, 'M', 'i'), + (0x1D36, 'M', 'j'), + (0x1D37, 'M', 'k'), + (0x1D38, 'M', 'l'), + (0x1D39, 'M', 'm'), + (0x1D3A, 'M', 'n'), + (0x1D3B, 'V'), + (0x1D3C, 'M', 'o'), + (0x1D3D, 'M', 'ȣ'), + (0x1D3E, 'M', 'p'), + (0x1D3F, 'M', 'r'), + (0x1D40, 'M', 't'), + (0x1D41, 'M', 'u'), + (0x1D42, 'M', 'w'), + (0x1D43, 'M', 'a'), + (0x1D44, 'M', 'ɐ'), + (0x1D45, 'M', 'ɑ'), + (0x1D46, 'M', 'ᴂ'), + (0x1D47, 'M', 'b'), + (0x1D48, 'M', 'd'), + (0x1D49, 'M', 'e'), + (0x1D4A, 'M', 'ə'), + (0x1D4B, 'M', 'ɛ'), + (0x1D4C, 'M', 'ɜ'), + (0x1D4D, 'M', 'g'), + (0x1D4E, 'V'), + (0x1D4F, 'M', 'k'), + (0x1D50, 'M', 'm'), + (0x1D51, 'M', 'ŋ'), + (0x1D52, 'M', 'o'), + (0x1D53, 'M', 'ɔ'), + ] + +def _seg_16() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D54, 'M', 'ᴖ'), + (0x1D55, 'M', 'ᴗ'), + (0x1D56, 'M', 'p'), + (0x1D57, 'M', 't'), + (0x1D58, 'M', 'u'), + (0x1D59, 'M', 'ᴝ'), + (0x1D5A, 'M', 'ɯ'), + (0x1D5B, 'M', 'v'), + (0x1D5C, 'M', 'ᴥ'), + (0x1D5D, 'M', 'β'), + (0x1D5E, 'M', 'γ'), + (0x1D5F, 'M', 'δ'), + (0x1D60, 'M', 'φ'), + (0x1D61, 'M', 'χ'), + (0x1D62, 'M', 'i'), + (0x1D63, 'M', 'r'), + (0x1D64, 'M', 'u'), + (0x1D65, 'M', 'v'), + (0x1D66, 'M', 'β'), + (0x1D67, 'M', 'γ'), + (0x1D68, 'M', 'ρ'), + (0x1D69, 'M', 'φ'), + (0x1D6A, 'M', 'χ'), + (0x1D6B, 'V'), + (0x1D78, 'M', 'н'), + (0x1D79, 'V'), + (0x1D9B, 'M', 'ɒ'), + (0x1D9C, 'M', 'c'), + (0x1D9D, 'M', 'ɕ'), + (0x1D9E, 'M', 'ð'), + (0x1D9F, 'M', 'ɜ'), + (0x1DA0, 'M', 'f'), + (0x1DA1, 'M', 'ɟ'), + (0x1DA2, 'M', 'ɡ'), + (0x1DA3, 'M', 'ɥ'), + (0x1DA4, 'M', 'ɨ'), + (0x1DA5, 'M', 'ɩ'), + (0x1DA6, 'M', 'ɪ'), + (0x1DA7, 'M', 'ᵻ'), + (0x1DA8, 'M', 'ʝ'), + (0x1DA9, 'M', 'ɭ'), + (0x1DAA, 'M', 'ᶅ'), + (0x1DAB, 'M', 'ʟ'), + (0x1DAC, 'M', 'ɱ'), + (0x1DAD, 'M', 'ɰ'), + (0x1DAE, 'M', 'ɲ'), + (0x1DAF, 'M', 'ɳ'), + (0x1DB0, 'M', 'ɴ'), + (0x1DB1, 'M', 'ɵ'), + (0x1DB2, 'M', 'ɸ'), + (0x1DB3, 'M', 'ʂ'), + (0x1DB4, 'M', 'ʃ'), + (0x1DB5, 'M', 'ƫ'), + (0x1DB6, 'M', 'ʉ'), + (0x1DB7, 'M', 'ʊ'), + (0x1DB8, 'M', 'ᴜ'), + (0x1DB9, 'M', 'ʋ'), + (0x1DBA, 'M', 'ʌ'), + (0x1DBB, 'M', 'z'), + (0x1DBC, 'M', 'ʐ'), + (0x1DBD, 'M', 'ʑ'), + (0x1DBE, 'M', 'ʒ'), + (0x1DBF, 'M', 'θ'), + (0x1DC0, 'V'), + (0x1E00, 'M', 'ḁ'), + (0x1E01, 'V'), + (0x1E02, 'M', 'ḃ'), + (0x1E03, 'V'), + (0x1E04, 'M', 'ḅ'), + (0x1E05, 'V'), + (0x1E06, 'M', 'ḇ'), + (0x1E07, 'V'), + (0x1E08, 'M', 'ḉ'), + (0x1E09, 'V'), + (0x1E0A, 'M', 'ḋ'), + (0x1E0B, 'V'), + (0x1E0C, 'M', 'ḍ'), + (0x1E0D, 'V'), + (0x1E0E, 'M', 'ḏ'), + (0x1E0F, 'V'), + (0x1E10, 'M', 'ḑ'), + (0x1E11, 'V'), + (0x1E12, 'M', 'ḓ'), + (0x1E13, 'V'), + (0x1E14, 'M', 'ḕ'), + (0x1E15, 'V'), + (0x1E16, 'M', 'ḗ'), + (0x1E17, 'V'), + (0x1E18, 'M', 'ḙ'), + (0x1E19, 'V'), + (0x1E1A, 'M', 'ḛ'), + (0x1E1B, 'V'), + (0x1E1C, 'M', 'ḝ'), + (0x1E1D, 'V'), + (0x1E1E, 'M', 'ḟ'), + (0x1E1F, 'V'), + (0x1E20, 'M', 'ḡ'), + (0x1E21, 'V'), + (0x1E22, 'M', 'ḣ'), + (0x1E23, 'V'), + ] + +def _seg_17() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1E24, 'M', 'ḥ'), + (0x1E25, 'V'), + (0x1E26, 'M', 'ḧ'), + (0x1E27, 'V'), + (0x1E28, 'M', 'ḩ'), + (0x1E29, 'V'), + (0x1E2A, 'M', 'ḫ'), + (0x1E2B, 'V'), + (0x1E2C, 'M', 'ḭ'), + (0x1E2D, 'V'), + (0x1E2E, 'M', 'ḯ'), + (0x1E2F, 'V'), + (0x1E30, 'M', 'ḱ'), + (0x1E31, 'V'), + (0x1E32, 'M', 'ḳ'), + (0x1E33, 'V'), + (0x1E34, 'M', 'ḵ'), + (0x1E35, 'V'), + (0x1E36, 'M', 'ḷ'), + (0x1E37, 'V'), + (0x1E38, 'M', 'ḹ'), + (0x1E39, 'V'), + (0x1E3A, 'M', 'ḻ'), + (0x1E3B, 'V'), + (0x1E3C, 'M', 'ḽ'), + (0x1E3D, 'V'), + (0x1E3E, 'M', 'ḿ'), + (0x1E3F, 'V'), + (0x1E40, 'M', 'ṁ'), + (0x1E41, 'V'), + (0x1E42, 'M', 'ṃ'), + (0x1E43, 'V'), + (0x1E44, 'M', 'ṅ'), + (0x1E45, 'V'), + (0x1E46, 'M', 'ṇ'), + (0x1E47, 'V'), + (0x1E48, 'M', 'ṉ'), + (0x1E49, 'V'), + (0x1E4A, 'M', 'ṋ'), + (0x1E4B, 'V'), + (0x1E4C, 'M', 'ṍ'), + (0x1E4D, 'V'), + (0x1E4E, 'M', 'ṏ'), + (0x1E4F, 'V'), + (0x1E50, 'M', 'ṑ'), + (0x1E51, 'V'), + (0x1E52, 'M', 'ṓ'), + (0x1E53, 'V'), + (0x1E54, 'M', 'ṕ'), + (0x1E55, 'V'), + (0x1E56, 'M', 'ṗ'), + (0x1E57, 'V'), + (0x1E58, 'M', 'ṙ'), + (0x1E59, 'V'), + (0x1E5A, 'M', 'ṛ'), + (0x1E5B, 'V'), + (0x1E5C, 'M', 'ṝ'), + (0x1E5D, 'V'), + (0x1E5E, 'M', 'ṟ'), + (0x1E5F, 'V'), + (0x1E60, 'M', 'ṡ'), + (0x1E61, 'V'), + (0x1E62, 'M', 'ṣ'), + (0x1E63, 'V'), + (0x1E64, 'M', 'ṥ'), + (0x1E65, 'V'), + (0x1E66, 'M', 'ṧ'), + (0x1E67, 'V'), + (0x1E68, 'M', 'ṩ'), + (0x1E69, 'V'), + (0x1E6A, 'M', 'ṫ'), + (0x1E6B, 'V'), + (0x1E6C, 'M', 'ṭ'), + (0x1E6D, 'V'), + (0x1E6E, 'M', 'ṯ'), + (0x1E6F, 'V'), + (0x1E70, 'M', 'ṱ'), + (0x1E71, 'V'), + (0x1E72, 'M', 'ṳ'), + (0x1E73, 'V'), + (0x1E74, 'M', 'ṵ'), + (0x1E75, 'V'), + (0x1E76, 'M', 'ṷ'), + (0x1E77, 'V'), + (0x1E78, 'M', 'ṹ'), + (0x1E79, 'V'), + (0x1E7A, 'M', 'ṻ'), + (0x1E7B, 'V'), + (0x1E7C, 'M', 'ṽ'), + (0x1E7D, 'V'), + (0x1E7E, 'M', 'ṿ'), + (0x1E7F, 'V'), + (0x1E80, 'M', 'ẁ'), + (0x1E81, 'V'), + (0x1E82, 'M', 'ẃ'), + (0x1E83, 'V'), + (0x1E84, 'M', 'ẅ'), + (0x1E85, 'V'), + (0x1E86, 'M', 'ẇ'), + (0x1E87, 'V'), + ] + +def _seg_18() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1E88, 'M', 'ẉ'), + (0x1E89, 'V'), + (0x1E8A, 'M', 'ẋ'), + (0x1E8B, 'V'), + (0x1E8C, 'M', 'ẍ'), + (0x1E8D, 'V'), + (0x1E8E, 'M', 'ẏ'), + (0x1E8F, 'V'), + (0x1E90, 'M', 'ẑ'), + (0x1E91, 'V'), + (0x1E92, 'M', 'ẓ'), + (0x1E93, 'V'), + (0x1E94, 'M', 'ẕ'), + (0x1E95, 'V'), + (0x1E9A, 'M', 'aʾ'), + (0x1E9B, 'M', 'ṡ'), + (0x1E9C, 'V'), + (0x1E9E, 'M', 'ß'), + (0x1E9F, 'V'), + (0x1EA0, 'M', 'ạ'), + (0x1EA1, 'V'), + (0x1EA2, 'M', 'ả'), + (0x1EA3, 'V'), + (0x1EA4, 'M', 'ấ'), + (0x1EA5, 'V'), + (0x1EA6, 'M', 'ầ'), + (0x1EA7, 'V'), + (0x1EA8, 'M', 'ẩ'), + (0x1EA9, 'V'), + (0x1EAA, 'M', 'ẫ'), + (0x1EAB, 'V'), + (0x1EAC, 'M', 'ậ'), + (0x1EAD, 'V'), + (0x1EAE, 'M', 'ắ'), + (0x1EAF, 'V'), + (0x1EB0, 'M', 'ằ'), + (0x1EB1, 'V'), + (0x1EB2, 'M', 'ẳ'), + (0x1EB3, 'V'), + (0x1EB4, 'M', 'ẵ'), + (0x1EB5, 'V'), + (0x1EB6, 'M', 'ặ'), + (0x1EB7, 'V'), + (0x1EB8, 'M', 'ẹ'), + (0x1EB9, 'V'), + (0x1EBA, 'M', 'ẻ'), + (0x1EBB, 'V'), + (0x1EBC, 'M', 'ẽ'), + (0x1EBD, 'V'), + (0x1EBE, 'M', 'ế'), + (0x1EBF, 'V'), + (0x1EC0, 'M', 'ề'), + (0x1EC1, 'V'), + (0x1EC2, 'M', 'ể'), + (0x1EC3, 'V'), + (0x1EC4, 'M', 'ễ'), + (0x1EC5, 'V'), + (0x1EC6, 'M', 'ệ'), + (0x1EC7, 'V'), + (0x1EC8, 'M', 'ỉ'), + (0x1EC9, 'V'), + (0x1ECA, 'M', 'ị'), + (0x1ECB, 'V'), + (0x1ECC, 'M', 'ọ'), + (0x1ECD, 'V'), + (0x1ECE, 'M', 'ỏ'), + (0x1ECF, 'V'), + (0x1ED0, 'M', 'ố'), + (0x1ED1, 'V'), + (0x1ED2, 'M', 'ồ'), + (0x1ED3, 'V'), + (0x1ED4, 'M', 'ổ'), + (0x1ED5, 'V'), + (0x1ED6, 'M', 'ỗ'), + (0x1ED7, 'V'), + (0x1ED8, 'M', 'ộ'), + (0x1ED9, 'V'), + (0x1EDA, 'M', 'ớ'), + (0x1EDB, 'V'), + (0x1EDC, 'M', 'ờ'), + (0x1EDD, 'V'), + (0x1EDE, 'M', 'ở'), + (0x1EDF, 'V'), + (0x1EE0, 'M', 'ỡ'), + (0x1EE1, 'V'), + (0x1EE2, 'M', 'ợ'), + (0x1EE3, 'V'), + (0x1EE4, 'M', 'ụ'), + (0x1EE5, 'V'), + (0x1EE6, 'M', 'ủ'), + (0x1EE7, 'V'), + (0x1EE8, 'M', 'ứ'), + (0x1EE9, 'V'), + (0x1EEA, 'M', 'ừ'), + (0x1EEB, 'V'), + (0x1EEC, 'M', 'ử'), + (0x1EED, 'V'), + (0x1EEE, 'M', 'ữ'), + (0x1EEF, 'V'), + (0x1EF0, 'M', 'ự'), + ] + +def _seg_19() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1EF1, 'V'), + (0x1EF2, 'M', 'ỳ'), + (0x1EF3, 'V'), + (0x1EF4, 'M', 'ỵ'), + (0x1EF5, 'V'), + (0x1EF6, 'M', 'ỷ'), + (0x1EF7, 'V'), + (0x1EF8, 'M', 'ỹ'), + (0x1EF9, 'V'), + (0x1EFA, 'M', 'ỻ'), + (0x1EFB, 'V'), + (0x1EFC, 'M', 'ỽ'), + (0x1EFD, 'V'), + (0x1EFE, 'M', 'ỿ'), + (0x1EFF, 'V'), + (0x1F08, 'M', 'ἀ'), + (0x1F09, 'M', 'ἁ'), + (0x1F0A, 'M', 'ἂ'), + (0x1F0B, 'M', 'ἃ'), + (0x1F0C, 'M', 'ἄ'), + (0x1F0D, 'M', 'ἅ'), + (0x1F0E, 'M', 'ἆ'), + (0x1F0F, 'M', 'ἇ'), + (0x1F10, 'V'), + (0x1F16, 'X'), + (0x1F18, 'M', 'ἐ'), + (0x1F19, 'M', 'ἑ'), + (0x1F1A, 'M', 'ἒ'), + (0x1F1B, 'M', 'ἓ'), + (0x1F1C, 'M', 'ἔ'), + (0x1F1D, 'M', 'ἕ'), + (0x1F1E, 'X'), + (0x1F20, 'V'), + (0x1F28, 'M', 'ἠ'), + (0x1F29, 'M', 'ἡ'), + (0x1F2A, 'M', 'ἢ'), + (0x1F2B, 'M', 'ἣ'), + (0x1F2C, 'M', 'ἤ'), + (0x1F2D, 'M', 'ἥ'), + (0x1F2E, 'M', 'ἦ'), + (0x1F2F, 'M', 'ἧ'), + (0x1F30, 'V'), + (0x1F38, 'M', 'ἰ'), + (0x1F39, 'M', 'ἱ'), + (0x1F3A, 'M', 'ἲ'), + (0x1F3B, 'M', 'ἳ'), + (0x1F3C, 'M', 'ἴ'), + (0x1F3D, 'M', 'ἵ'), + (0x1F3E, 'M', 'ἶ'), + (0x1F3F, 'M', 'ἷ'), + (0x1F40, 'V'), + (0x1F46, 'X'), + (0x1F48, 'M', 'ὀ'), + (0x1F49, 'M', 'ὁ'), + (0x1F4A, 'M', 'ὂ'), + (0x1F4B, 'M', 'ὃ'), + (0x1F4C, 'M', 'ὄ'), + (0x1F4D, 'M', 'ὅ'), + (0x1F4E, 'X'), + (0x1F50, 'V'), + (0x1F58, 'X'), + (0x1F59, 'M', 'ὑ'), + (0x1F5A, 'X'), + (0x1F5B, 'M', 'ὓ'), + (0x1F5C, 'X'), + (0x1F5D, 'M', 'ὕ'), + (0x1F5E, 'X'), + (0x1F5F, 'M', 'ὗ'), + (0x1F60, 'V'), + (0x1F68, 'M', 'ὠ'), + (0x1F69, 'M', 'ὡ'), + (0x1F6A, 'M', 'ὢ'), + (0x1F6B, 'M', 'ὣ'), + (0x1F6C, 'M', 'ὤ'), + (0x1F6D, 'M', 'ὥ'), + (0x1F6E, 'M', 'ὦ'), + (0x1F6F, 'M', 'ὧ'), + (0x1F70, 'V'), + (0x1F71, 'M', 'ά'), + (0x1F72, 'V'), + (0x1F73, 'M', 'έ'), + (0x1F74, 'V'), + (0x1F75, 'M', 'ή'), + (0x1F76, 'V'), + (0x1F77, 'M', 'ί'), + (0x1F78, 'V'), + (0x1F79, 'M', 'ό'), + (0x1F7A, 'V'), + (0x1F7B, 'M', 'ύ'), + (0x1F7C, 'V'), + (0x1F7D, 'M', 'ώ'), + (0x1F7E, 'X'), + (0x1F80, 'M', 'ἀι'), + (0x1F81, 'M', 'ἁι'), + (0x1F82, 'M', 'ἂι'), + (0x1F83, 'M', 'ἃι'), + (0x1F84, 'M', 'ἄι'), + (0x1F85, 'M', 'ἅι'), + (0x1F86, 'M', 'ἆι'), + (0x1F87, 'M', 'ἇι'), + ] + +def _seg_20() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1F88, 'M', 'ἀι'), + (0x1F89, 'M', 'ἁι'), + (0x1F8A, 'M', 'ἂι'), + (0x1F8B, 'M', 'ἃι'), + (0x1F8C, 'M', 'ἄι'), + (0x1F8D, 'M', 'ἅι'), + (0x1F8E, 'M', 'ἆι'), + (0x1F8F, 'M', 'ἇι'), + (0x1F90, 'M', 'ἠι'), + (0x1F91, 'M', 'ἡι'), + (0x1F92, 'M', 'ἢι'), + (0x1F93, 'M', 'ἣι'), + (0x1F94, 'M', 'ἤι'), + (0x1F95, 'M', 'ἥι'), + (0x1F96, 'M', 'ἦι'), + (0x1F97, 'M', 'ἧι'), + (0x1F98, 'M', 'ἠι'), + (0x1F99, 'M', 'ἡι'), + (0x1F9A, 'M', 'ἢι'), + (0x1F9B, 'M', 'ἣι'), + (0x1F9C, 'M', 'ἤι'), + (0x1F9D, 'M', 'ἥι'), + (0x1F9E, 'M', 'ἦι'), + (0x1F9F, 'M', 'ἧι'), + (0x1FA0, 'M', 'ὠι'), + (0x1FA1, 'M', 'ὡι'), + (0x1FA2, 'M', 'ὢι'), + (0x1FA3, 'M', 'ὣι'), + (0x1FA4, 'M', 'ὤι'), + (0x1FA5, 'M', 'ὥι'), + (0x1FA6, 'M', 'ὦι'), + (0x1FA7, 'M', 'ὧι'), + (0x1FA8, 'M', 'ὠι'), + (0x1FA9, 'M', 'ὡι'), + (0x1FAA, 'M', 'ὢι'), + (0x1FAB, 'M', 'ὣι'), + (0x1FAC, 'M', 'ὤι'), + (0x1FAD, 'M', 'ὥι'), + (0x1FAE, 'M', 'ὦι'), + (0x1FAF, 'M', 'ὧι'), + (0x1FB0, 'V'), + (0x1FB2, 'M', 'ὰι'), + (0x1FB3, 'M', 'αι'), + (0x1FB4, 'M', 'άι'), + (0x1FB5, 'X'), + (0x1FB6, 'V'), + (0x1FB7, 'M', 'ᾶι'), + (0x1FB8, 'M', 'ᾰ'), + (0x1FB9, 'M', 'ᾱ'), + (0x1FBA, 'M', 'ὰ'), + (0x1FBB, 'M', 'ά'), + (0x1FBC, 'M', 'αι'), + (0x1FBD, '3', ' ̓'), + (0x1FBE, 'M', 'ι'), + (0x1FBF, '3', ' ̓'), + (0x1FC0, '3', ' ͂'), + (0x1FC1, '3', ' ̈͂'), + (0x1FC2, 'M', 'ὴι'), + (0x1FC3, 'M', 'ηι'), + (0x1FC4, 'M', 'ήι'), + (0x1FC5, 'X'), + (0x1FC6, 'V'), + (0x1FC7, 'M', 'ῆι'), + (0x1FC8, 'M', 'ὲ'), + (0x1FC9, 'M', 'έ'), + (0x1FCA, 'M', 'ὴ'), + (0x1FCB, 'M', 'ή'), + (0x1FCC, 'M', 'ηι'), + (0x1FCD, '3', ' ̓̀'), + (0x1FCE, '3', ' ̓́'), + (0x1FCF, '3', ' ̓͂'), + (0x1FD0, 'V'), + (0x1FD3, 'M', 'ΐ'), + (0x1FD4, 'X'), + (0x1FD6, 'V'), + (0x1FD8, 'M', 'ῐ'), + (0x1FD9, 'M', 'ῑ'), + (0x1FDA, 'M', 'ὶ'), + (0x1FDB, 'M', 'ί'), + (0x1FDC, 'X'), + (0x1FDD, '3', ' ̔̀'), + (0x1FDE, '3', ' ̔́'), + (0x1FDF, '3', ' ̔͂'), + (0x1FE0, 'V'), + (0x1FE3, 'M', 'ΰ'), + (0x1FE4, 'V'), + (0x1FE8, 'M', 'ῠ'), + (0x1FE9, 'M', 'ῡ'), + (0x1FEA, 'M', 'ὺ'), + (0x1FEB, 'M', 'ύ'), + (0x1FEC, 'M', 'ῥ'), + (0x1FED, '3', ' ̈̀'), + (0x1FEE, '3', ' ̈́'), + (0x1FEF, '3', '`'), + (0x1FF0, 'X'), + (0x1FF2, 'M', 'ὼι'), + (0x1FF3, 'M', 'ωι'), + (0x1FF4, 'M', 'ώι'), + (0x1FF5, 'X'), + (0x1FF6, 'V'), + ] + +def _seg_21() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1FF7, 'M', 'ῶι'), + (0x1FF8, 'M', 'ὸ'), + (0x1FF9, 'M', 'ό'), + (0x1FFA, 'M', 'ὼ'), + (0x1FFB, 'M', 'ώ'), + (0x1FFC, 'M', 'ωι'), + (0x1FFD, '3', ' ́'), + (0x1FFE, '3', ' ̔'), + (0x1FFF, 'X'), + (0x2000, '3', ' '), + (0x200B, 'I'), + (0x200C, 'D', ''), + (0x200E, 'X'), + (0x2010, 'V'), + (0x2011, 'M', '‐'), + (0x2012, 'V'), + (0x2017, '3', ' ̳'), + (0x2018, 'V'), + (0x2024, 'X'), + (0x2027, 'V'), + (0x2028, 'X'), + (0x202F, '3', ' '), + (0x2030, 'V'), + (0x2033, 'M', '′′'), + (0x2034, 'M', '′′′'), + (0x2035, 'V'), + (0x2036, 'M', '‵‵'), + (0x2037, 'M', '‵‵‵'), + (0x2038, 'V'), + (0x203C, '3', '!!'), + (0x203D, 'V'), + (0x203E, '3', ' ̅'), + (0x203F, 'V'), + (0x2047, '3', '??'), + (0x2048, '3', '?!'), + (0x2049, '3', '!?'), + (0x204A, 'V'), + (0x2057, 'M', '′′′′'), + (0x2058, 'V'), + (0x205F, '3', ' '), + (0x2060, 'I'), + (0x2061, 'X'), + (0x2064, 'I'), + (0x2065, 'X'), + (0x2070, 'M', '0'), + (0x2071, 'M', 'i'), + (0x2072, 'X'), + (0x2074, 'M', '4'), + (0x2075, 'M', '5'), + (0x2076, 'M', '6'), + (0x2077, 'M', '7'), + (0x2078, 'M', '8'), + (0x2079, 'M', '9'), + (0x207A, '3', '+'), + (0x207B, 'M', '−'), + (0x207C, '3', '='), + (0x207D, '3', '('), + (0x207E, '3', ')'), + (0x207F, 'M', 'n'), + (0x2080, 'M', '0'), + (0x2081, 'M', '1'), + (0x2082, 'M', '2'), + (0x2083, 'M', '3'), + (0x2084, 'M', '4'), + (0x2085, 'M', '5'), + (0x2086, 'M', '6'), + (0x2087, 'M', '7'), + (0x2088, 'M', '8'), + (0x2089, 'M', '9'), + (0x208A, '3', '+'), + (0x208B, 'M', '−'), + (0x208C, '3', '='), + (0x208D, '3', '('), + (0x208E, '3', ')'), + (0x208F, 'X'), + (0x2090, 'M', 'a'), + (0x2091, 'M', 'e'), + (0x2092, 'M', 'o'), + (0x2093, 'M', 'x'), + (0x2094, 'M', 'ə'), + (0x2095, 'M', 'h'), + (0x2096, 'M', 'k'), + (0x2097, 'M', 'l'), + (0x2098, 'M', 'm'), + (0x2099, 'M', 'n'), + (0x209A, 'M', 'p'), + (0x209B, 'M', 's'), + (0x209C, 'M', 't'), + (0x209D, 'X'), + (0x20A0, 'V'), + (0x20A8, 'M', 'rs'), + (0x20A9, 'V'), + (0x20C1, 'X'), + (0x20D0, 'V'), + (0x20F1, 'X'), + (0x2100, '3', 'a/c'), + (0x2101, '3', 'a/s'), + (0x2102, 'M', 'c'), + (0x2103, 'M', '°c'), + (0x2104, 'V'), + ] + +def _seg_22() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2105, '3', 'c/o'), + (0x2106, '3', 'c/u'), + (0x2107, 'M', 'ɛ'), + (0x2108, 'V'), + (0x2109, 'M', '°f'), + (0x210A, 'M', 'g'), + (0x210B, 'M', 'h'), + (0x210F, 'M', 'ħ'), + (0x2110, 'M', 'i'), + (0x2112, 'M', 'l'), + (0x2114, 'V'), + (0x2115, 'M', 'n'), + (0x2116, 'M', 'no'), + (0x2117, 'V'), + (0x2119, 'M', 'p'), + (0x211A, 'M', 'q'), + (0x211B, 'M', 'r'), + (0x211E, 'V'), + (0x2120, 'M', 'sm'), + (0x2121, 'M', 'tel'), + (0x2122, 'M', 'tm'), + (0x2123, 'V'), + (0x2124, 'M', 'z'), + (0x2125, 'V'), + (0x2126, 'M', 'ω'), + (0x2127, 'V'), + (0x2128, 'M', 'z'), + (0x2129, 'V'), + (0x212A, 'M', 'k'), + (0x212B, 'M', 'å'), + (0x212C, 'M', 'b'), + (0x212D, 'M', 'c'), + (0x212E, 'V'), + (0x212F, 'M', 'e'), + (0x2131, 'M', 'f'), + (0x2132, 'X'), + (0x2133, 'M', 'm'), + (0x2134, 'M', 'o'), + (0x2135, 'M', 'א'), + (0x2136, 'M', 'ב'), + (0x2137, 'M', 'ג'), + (0x2138, 'M', 'ד'), + (0x2139, 'M', 'i'), + (0x213A, 'V'), + (0x213B, 'M', 'fax'), + (0x213C, 'M', 'π'), + (0x213D, 'M', 'γ'), + (0x213F, 'M', 'π'), + (0x2140, 'M', '∑'), + (0x2141, 'V'), + (0x2145, 'M', 'd'), + (0x2147, 'M', 'e'), + (0x2148, 'M', 'i'), + (0x2149, 'M', 'j'), + (0x214A, 'V'), + (0x2150, 'M', '1⁄7'), + (0x2151, 'M', '1⁄9'), + (0x2152, 'M', '1⁄10'), + (0x2153, 'M', '1⁄3'), + (0x2154, 'M', '2⁄3'), + (0x2155, 'M', '1⁄5'), + (0x2156, 'M', '2⁄5'), + (0x2157, 'M', '3⁄5'), + (0x2158, 'M', '4⁄5'), + (0x2159, 'M', '1⁄6'), + (0x215A, 'M', '5⁄6'), + (0x215B, 'M', '1⁄8'), + (0x215C, 'M', '3⁄8'), + (0x215D, 'M', '5⁄8'), + (0x215E, 'M', '7⁄8'), + (0x215F, 'M', '1⁄'), + (0x2160, 'M', 'i'), + (0x2161, 'M', 'ii'), + (0x2162, 'M', 'iii'), + (0x2163, 'M', 'iv'), + (0x2164, 'M', 'v'), + (0x2165, 'M', 'vi'), + (0x2166, 'M', 'vii'), + (0x2167, 'M', 'viii'), + (0x2168, 'M', 'ix'), + (0x2169, 'M', 'x'), + (0x216A, 'M', 'xi'), + (0x216B, 'M', 'xii'), + (0x216C, 'M', 'l'), + (0x216D, 'M', 'c'), + (0x216E, 'M', 'd'), + (0x216F, 'M', 'm'), + (0x2170, 'M', 'i'), + (0x2171, 'M', 'ii'), + (0x2172, 'M', 'iii'), + (0x2173, 'M', 'iv'), + (0x2174, 'M', 'v'), + (0x2175, 'M', 'vi'), + (0x2176, 'M', 'vii'), + (0x2177, 'M', 'viii'), + (0x2178, 'M', 'ix'), + (0x2179, 'M', 'x'), + (0x217A, 'M', 'xi'), + (0x217B, 'M', 'xii'), + (0x217C, 'M', 'l'), + ] + +def _seg_23() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x217D, 'M', 'c'), + (0x217E, 'M', 'd'), + (0x217F, 'M', 'm'), + (0x2180, 'V'), + (0x2183, 'X'), + (0x2184, 'V'), + (0x2189, 'M', '0⁄3'), + (0x218A, 'V'), + (0x218C, 'X'), + (0x2190, 'V'), + (0x222C, 'M', '∫∫'), + (0x222D, 'M', '∫∫∫'), + (0x222E, 'V'), + (0x222F, 'M', '∮∮'), + (0x2230, 'M', '∮∮∮'), + (0x2231, 'V'), + (0x2329, 'M', '〈'), + (0x232A, 'M', '〉'), + (0x232B, 'V'), + (0x2427, 'X'), + (0x2440, 'V'), + (0x244B, 'X'), + (0x2460, 'M', '1'), + (0x2461, 'M', '2'), + (0x2462, 'M', '3'), + (0x2463, 'M', '4'), + (0x2464, 'M', '5'), + (0x2465, 'M', '6'), + (0x2466, 'M', '7'), + (0x2467, 'M', '8'), + (0x2468, 'M', '9'), + (0x2469, 'M', '10'), + (0x246A, 'M', '11'), + (0x246B, 'M', '12'), + (0x246C, 'M', '13'), + (0x246D, 'M', '14'), + (0x246E, 'M', '15'), + (0x246F, 'M', '16'), + (0x2470, 'M', '17'), + (0x2471, 'M', '18'), + (0x2472, 'M', '19'), + (0x2473, 'M', '20'), + (0x2474, '3', '(1)'), + (0x2475, '3', '(2)'), + (0x2476, '3', '(3)'), + (0x2477, '3', '(4)'), + (0x2478, '3', '(5)'), + (0x2479, '3', '(6)'), + (0x247A, '3', '(7)'), + (0x247B, '3', '(8)'), + (0x247C, '3', '(9)'), + (0x247D, '3', '(10)'), + (0x247E, '3', '(11)'), + (0x247F, '3', '(12)'), + (0x2480, '3', '(13)'), + (0x2481, '3', '(14)'), + (0x2482, '3', '(15)'), + (0x2483, '3', '(16)'), + (0x2484, '3', '(17)'), + (0x2485, '3', '(18)'), + (0x2486, '3', '(19)'), + (0x2487, '3', '(20)'), + (0x2488, 'X'), + (0x249C, '3', '(a)'), + (0x249D, '3', '(b)'), + (0x249E, '3', '(c)'), + (0x249F, '3', '(d)'), + (0x24A0, '3', '(e)'), + (0x24A1, '3', '(f)'), + (0x24A2, '3', '(g)'), + (0x24A3, '3', '(h)'), + (0x24A4, '3', '(i)'), + (0x24A5, '3', '(j)'), + (0x24A6, '3', '(k)'), + (0x24A7, '3', '(l)'), + (0x24A8, '3', '(m)'), + (0x24A9, '3', '(n)'), + (0x24AA, '3', '(o)'), + (0x24AB, '3', '(p)'), + (0x24AC, '3', '(q)'), + (0x24AD, '3', '(r)'), + (0x24AE, '3', '(s)'), + (0x24AF, '3', '(t)'), + (0x24B0, '3', '(u)'), + (0x24B1, '3', '(v)'), + (0x24B2, '3', '(w)'), + (0x24B3, '3', '(x)'), + (0x24B4, '3', '(y)'), + (0x24B5, '3', '(z)'), + (0x24B6, 'M', 'a'), + (0x24B7, 'M', 'b'), + (0x24B8, 'M', 'c'), + (0x24B9, 'M', 'd'), + (0x24BA, 'M', 'e'), + (0x24BB, 'M', 'f'), + (0x24BC, 'M', 'g'), + (0x24BD, 'M', 'h'), + (0x24BE, 'M', 'i'), + (0x24BF, 'M', 'j'), + (0x24C0, 'M', 'k'), + ] + +def _seg_24() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x24C1, 'M', 'l'), + (0x24C2, 'M', 'm'), + (0x24C3, 'M', 'n'), + (0x24C4, 'M', 'o'), + (0x24C5, 'M', 'p'), + (0x24C6, 'M', 'q'), + (0x24C7, 'M', 'r'), + (0x24C8, 'M', 's'), + (0x24C9, 'M', 't'), + (0x24CA, 'M', 'u'), + (0x24CB, 'M', 'v'), + (0x24CC, 'M', 'w'), + (0x24CD, 'M', 'x'), + (0x24CE, 'M', 'y'), + (0x24CF, 'M', 'z'), + (0x24D0, 'M', 'a'), + (0x24D1, 'M', 'b'), + (0x24D2, 'M', 'c'), + (0x24D3, 'M', 'd'), + (0x24D4, 'M', 'e'), + (0x24D5, 'M', 'f'), + (0x24D6, 'M', 'g'), + (0x24D7, 'M', 'h'), + (0x24D8, 'M', 'i'), + (0x24D9, 'M', 'j'), + (0x24DA, 'M', 'k'), + (0x24DB, 'M', 'l'), + (0x24DC, 'M', 'm'), + (0x24DD, 'M', 'n'), + (0x24DE, 'M', 'o'), + (0x24DF, 'M', 'p'), + (0x24E0, 'M', 'q'), + (0x24E1, 'M', 'r'), + (0x24E2, 'M', 's'), + (0x24E3, 'M', 't'), + (0x24E4, 'M', 'u'), + (0x24E5, 'M', 'v'), + (0x24E6, 'M', 'w'), + (0x24E7, 'M', 'x'), + (0x24E8, 'M', 'y'), + (0x24E9, 'M', 'z'), + (0x24EA, 'M', '0'), + (0x24EB, 'V'), + (0x2A0C, 'M', '∫∫∫∫'), + (0x2A0D, 'V'), + (0x2A74, '3', '::='), + (0x2A75, '3', '=='), + (0x2A76, '3', '==='), + (0x2A77, 'V'), + (0x2ADC, 'M', '⫝̸'), + (0x2ADD, 'V'), + (0x2B74, 'X'), + (0x2B76, 'V'), + (0x2B96, 'X'), + (0x2B97, 'V'), + (0x2C00, 'M', 'ⰰ'), + (0x2C01, 'M', 'ⰱ'), + (0x2C02, 'M', 'ⰲ'), + (0x2C03, 'M', 'ⰳ'), + (0x2C04, 'M', 'ⰴ'), + (0x2C05, 'M', 'ⰵ'), + (0x2C06, 'M', 'ⰶ'), + (0x2C07, 'M', 'ⰷ'), + (0x2C08, 'M', 'ⰸ'), + (0x2C09, 'M', 'ⰹ'), + (0x2C0A, 'M', 'ⰺ'), + (0x2C0B, 'M', 'ⰻ'), + (0x2C0C, 'M', 'ⰼ'), + (0x2C0D, 'M', 'ⰽ'), + (0x2C0E, 'M', 'ⰾ'), + (0x2C0F, 'M', 'ⰿ'), + (0x2C10, 'M', 'ⱀ'), + (0x2C11, 'M', 'ⱁ'), + (0x2C12, 'M', 'ⱂ'), + (0x2C13, 'M', 'ⱃ'), + (0x2C14, 'M', 'ⱄ'), + (0x2C15, 'M', 'ⱅ'), + (0x2C16, 'M', 'ⱆ'), + (0x2C17, 'M', 'ⱇ'), + (0x2C18, 'M', 'ⱈ'), + (0x2C19, 'M', 'ⱉ'), + (0x2C1A, 'M', 'ⱊ'), + (0x2C1B, 'M', 'ⱋ'), + (0x2C1C, 'M', 'ⱌ'), + (0x2C1D, 'M', 'ⱍ'), + (0x2C1E, 'M', 'ⱎ'), + (0x2C1F, 'M', 'ⱏ'), + (0x2C20, 'M', 'ⱐ'), + (0x2C21, 'M', 'ⱑ'), + (0x2C22, 'M', 'ⱒ'), + (0x2C23, 'M', 'ⱓ'), + (0x2C24, 'M', 'ⱔ'), + (0x2C25, 'M', 'ⱕ'), + (0x2C26, 'M', 'ⱖ'), + (0x2C27, 'M', 'ⱗ'), + (0x2C28, 'M', 'ⱘ'), + (0x2C29, 'M', 'ⱙ'), + (0x2C2A, 'M', 'ⱚ'), + (0x2C2B, 'M', 'ⱛ'), + (0x2C2C, 'M', 'ⱜ'), + ] + +def _seg_25() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2C2D, 'M', 'ⱝ'), + (0x2C2E, 'M', 'ⱞ'), + (0x2C2F, 'M', 'ⱟ'), + (0x2C30, 'V'), + (0x2C60, 'M', 'ⱡ'), + (0x2C61, 'V'), + (0x2C62, 'M', 'ɫ'), + (0x2C63, 'M', 'ᵽ'), + (0x2C64, 'M', 'ɽ'), + (0x2C65, 'V'), + (0x2C67, 'M', 'ⱨ'), + (0x2C68, 'V'), + (0x2C69, 'M', 'ⱪ'), + (0x2C6A, 'V'), + (0x2C6B, 'M', 'ⱬ'), + (0x2C6C, 'V'), + (0x2C6D, 'M', 'ɑ'), + (0x2C6E, 'M', 'ɱ'), + (0x2C6F, 'M', 'ɐ'), + (0x2C70, 'M', 'ɒ'), + (0x2C71, 'V'), + (0x2C72, 'M', 'ⱳ'), + (0x2C73, 'V'), + (0x2C75, 'M', 'ⱶ'), + (0x2C76, 'V'), + (0x2C7C, 'M', 'j'), + (0x2C7D, 'M', 'v'), + (0x2C7E, 'M', 'ȿ'), + (0x2C7F, 'M', 'ɀ'), + (0x2C80, 'M', 'ⲁ'), + (0x2C81, 'V'), + (0x2C82, 'M', 'ⲃ'), + (0x2C83, 'V'), + (0x2C84, 'M', 'ⲅ'), + (0x2C85, 'V'), + (0x2C86, 'M', 'ⲇ'), + (0x2C87, 'V'), + (0x2C88, 'M', 'ⲉ'), + (0x2C89, 'V'), + (0x2C8A, 'M', 'ⲋ'), + (0x2C8B, 'V'), + (0x2C8C, 'M', 'ⲍ'), + (0x2C8D, 'V'), + (0x2C8E, 'M', 'ⲏ'), + (0x2C8F, 'V'), + (0x2C90, 'M', 'ⲑ'), + (0x2C91, 'V'), + (0x2C92, 'M', 'ⲓ'), + (0x2C93, 'V'), + (0x2C94, 'M', 'ⲕ'), + (0x2C95, 'V'), + (0x2C96, 'M', 'ⲗ'), + (0x2C97, 'V'), + (0x2C98, 'M', 'ⲙ'), + (0x2C99, 'V'), + (0x2C9A, 'M', 'ⲛ'), + (0x2C9B, 'V'), + (0x2C9C, 'M', 'ⲝ'), + (0x2C9D, 'V'), + (0x2C9E, 'M', 'ⲟ'), + (0x2C9F, 'V'), + (0x2CA0, 'M', 'ⲡ'), + (0x2CA1, 'V'), + (0x2CA2, 'M', 'ⲣ'), + (0x2CA3, 'V'), + (0x2CA4, 'M', 'ⲥ'), + (0x2CA5, 'V'), + (0x2CA6, 'M', 'ⲧ'), + (0x2CA7, 'V'), + (0x2CA8, 'M', 'ⲩ'), + (0x2CA9, 'V'), + (0x2CAA, 'M', 'ⲫ'), + (0x2CAB, 'V'), + (0x2CAC, 'M', 'ⲭ'), + (0x2CAD, 'V'), + (0x2CAE, 'M', 'ⲯ'), + (0x2CAF, 'V'), + (0x2CB0, 'M', 'ⲱ'), + (0x2CB1, 'V'), + (0x2CB2, 'M', 'ⲳ'), + (0x2CB3, 'V'), + (0x2CB4, 'M', 'ⲵ'), + (0x2CB5, 'V'), + (0x2CB6, 'M', 'ⲷ'), + (0x2CB7, 'V'), + (0x2CB8, 'M', 'ⲹ'), + (0x2CB9, 'V'), + (0x2CBA, 'M', 'ⲻ'), + (0x2CBB, 'V'), + (0x2CBC, 'M', 'ⲽ'), + (0x2CBD, 'V'), + (0x2CBE, 'M', 'ⲿ'), + (0x2CBF, 'V'), + (0x2CC0, 'M', 'ⳁ'), + (0x2CC1, 'V'), + (0x2CC2, 'M', 'ⳃ'), + (0x2CC3, 'V'), + (0x2CC4, 'M', 'ⳅ'), + (0x2CC5, 'V'), + (0x2CC6, 'M', 'ⳇ'), + ] + +def _seg_26() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2CC7, 'V'), + (0x2CC8, 'M', 'ⳉ'), + (0x2CC9, 'V'), + (0x2CCA, 'M', 'ⳋ'), + (0x2CCB, 'V'), + (0x2CCC, 'M', 'ⳍ'), + (0x2CCD, 'V'), + (0x2CCE, 'M', 'ⳏ'), + (0x2CCF, 'V'), + (0x2CD0, 'M', 'ⳑ'), + (0x2CD1, 'V'), + (0x2CD2, 'M', 'ⳓ'), + (0x2CD3, 'V'), + (0x2CD4, 'M', 'ⳕ'), + (0x2CD5, 'V'), + (0x2CD6, 'M', 'ⳗ'), + (0x2CD7, 'V'), + (0x2CD8, 'M', 'ⳙ'), + (0x2CD9, 'V'), + (0x2CDA, 'M', 'ⳛ'), + (0x2CDB, 'V'), + (0x2CDC, 'M', 'ⳝ'), + (0x2CDD, 'V'), + (0x2CDE, 'M', 'ⳟ'), + (0x2CDF, 'V'), + (0x2CE0, 'M', 'ⳡ'), + (0x2CE1, 'V'), + (0x2CE2, 'M', 'ⳣ'), + (0x2CE3, 'V'), + (0x2CEB, 'M', 'ⳬ'), + (0x2CEC, 'V'), + (0x2CED, 'M', 'ⳮ'), + (0x2CEE, 'V'), + (0x2CF2, 'M', 'ⳳ'), + (0x2CF3, 'V'), + (0x2CF4, 'X'), + (0x2CF9, 'V'), + (0x2D26, 'X'), + (0x2D27, 'V'), + (0x2D28, 'X'), + (0x2D2D, 'V'), + (0x2D2E, 'X'), + (0x2D30, 'V'), + (0x2D68, 'X'), + (0x2D6F, 'M', 'ⵡ'), + (0x2D70, 'V'), + (0x2D71, 'X'), + (0x2D7F, 'V'), + (0x2D97, 'X'), + (0x2DA0, 'V'), + (0x2DA7, 'X'), + (0x2DA8, 'V'), + (0x2DAF, 'X'), + (0x2DB0, 'V'), + (0x2DB7, 'X'), + (0x2DB8, 'V'), + (0x2DBF, 'X'), + (0x2DC0, 'V'), + (0x2DC7, 'X'), + (0x2DC8, 'V'), + (0x2DCF, 'X'), + (0x2DD0, 'V'), + (0x2DD7, 'X'), + (0x2DD8, 'V'), + (0x2DDF, 'X'), + (0x2DE0, 'V'), + (0x2E5E, 'X'), + (0x2E80, 'V'), + (0x2E9A, 'X'), + (0x2E9B, 'V'), + (0x2E9F, 'M', '母'), + (0x2EA0, 'V'), + (0x2EF3, 'M', '龟'), + (0x2EF4, 'X'), + (0x2F00, 'M', '一'), + (0x2F01, 'M', '丨'), + (0x2F02, 'M', '丶'), + (0x2F03, 'M', '丿'), + (0x2F04, 'M', '乙'), + (0x2F05, 'M', '亅'), + (0x2F06, 'M', '二'), + (0x2F07, 'M', '亠'), + (0x2F08, 'M', '人'), + (0x2F09, 'M', '儿'), + (0x2F0A, 'M', '入'), + (0x2F0B, 'M', '八'), + (0x2F0C, 'M', '冂'), + (0x2F0D, 'M', '冖'), + (0x2F0E, 'M', '冫'), + (0x2F0F, 'M', '几'), + (0x2F10, 'M', '凵'), + (0x2F11, 'M', '刀'), + (0x2F12, 'M', '力'), + (0x2F13, 'M', '勹'), + (0x2F14, 'M', '匕'), + (0x2F15, 'M', '匚'), + (0x2F16, 'M', '匸'), + (0x2F17, 'M', '十'), + (0x2F18, 'M', '卜'), + (0x2F19, 'M', '卩'), + ] + +def _seg_27() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2F1A, 'M', '厂'), + (0x2F1B, 'M', '厶'), + (0x2F1C, 'M', '又'), + (0x2F1D, 'M', '口'), + (0x2F1E, 'M', '囗'), + (0x2F1F, 'M', '土'), + (0x2F20, 'M', '士'), + (0x2F21, 'M', '夂'), + (0x2F22, 'M', '夊'), + (0x2F23, 'M', '夕'), + (0x2F24, 'M', '大'), + (0x2F25, 'M', '女'), + (0x2F26, 'M', '子'), + (0x2F27, 'M', '宀'), + (0x2F28, 'M', '寸'), + (0x2F29, 'M', '小'), + (0x2F2A, 'M', '尢'), + (0x2F2B, 'M', '尸'), + (0x2F2C, 'M', '屮'), + (0x2F2D, 'M', '山'), + (0x2F2E, 'M', '巛'), + (0x2F2F, 'M', '工'), + (0x2F30, 'M', '己'), + (0x2F31, 'M', '巾'), + (0x2F32, 'M', '干'), + (0x2F33, 'M', '幺'), + (0x2F34, 'M', '广'), + (0x2F35, 'M', '廴'), + (0x2F36, 'M', '廾'), + (0x2F37, 'M', '弋'), + (0x2F38, 'M', '弓'), + (0x2F39, 'M', '彐'), + (0x2F3A, 'M', '彡'), + (0x2F3B, 'M', '彳'), + (0x2F3C, 'M', '心'), + (0x2F3D, 'M', '戈'), + (0x2F3E, 'M', '戶'), + (0x2F3F, 'M', '手'), + (0x2F40, 'M', '支'), + (0x2F41, 'M', '攴'), + (0x2F42, 'M', '文'), + (0x2F43, 'M', '斗'), + (0x2F44, 'M', '斤'), + (0x2F45, 'M', '方'), + (0x2F46, 'M', '无'), + (0x2F47, 'M', '日'), + (0x2F48, 'M', '曰'), + (0x2F49, 'M', '月'), + (0x2F4A, 'M', '木'), + (0x2F4B, 'M', '欠'), + (0x2F4C, 'M', '止'), + (0x2F4D, 'M', '歹'), + (0x2F4E, 'M', '殳'), + (0x2F4F, 'M', '毋'), + (0x2F50, 'M', '比'), + (0x2F51, 'M', '毛'), + (0x2F52, 'M', '氏'), + (0x2F53, 'M', '气'), + (0x2F54, 'M', '水'), + (0x2F55, 'M', '火'), + (0x2F56, 'M', '爪'), + (0x2F57, 'M', '父'), + (0x2F58, 'M', '爻'), + (0x2F59, 'M', '爿'), + (0x2F5A, 'M', '片'), + (0x2F5B, 'M', '牙'), + (0x2F5C, 'M', '牛'), + (0x2F5D, 'M', '犬'), + (0x2F5E, 'M', '玄'), + (0x2F5F, 'M', '玉'), + (0x2F60, 'M', '瓜'), + (0x2F61, 'M', '瓦'), + (0x2F62, 'M', '甘'), + (0x2F63, 'M', '生'), + (0x2F64, 'M', '用'), + (0x2F65, 'M', '田'), + (0x2F66, 'M', '疋'), + (0x2F67, 'M', '疒'), + (0x2F68, 'M', '癶'), + (0x2F69, 'M', '白'), + (0x2F6A, 'M', '皮'), + (0x2F6B, 'M', '皿'), + (0x2F6C, 'M', '目'), + (0x2F6D, 'M', '矛'), + (0x2F6E, 'M', '矢'), + (0x2F6F, 'M', '石'), + (0x2F70, 'M', '示'), + (0x2F71, 'M', '禸'), + (0x2F72, 'M', '禾'), + (0x2F73, 'M', '穴'), + (0x2F74, 'M', '立'), + (0x2F75, 'M', '竹'), + (0x2F76, 'M', '米'), + (0x2F77, 'M', '糸'), + (0x2F78, 'M', '缶'), + (0x2F79, 'M', '网'), + (0x2F7A, 'M', '羊'), + (0x2F7B, 'M', '羽'), + (0x2F7C, 'M', '老'), + (0x2F7D, 'M', '而'), + ] + +def _seg_28() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2F7E, 'M', '耒'), + (0x2F7F, 'M', '耳'), + (0x2F80, 'M', '聿'), + (0x2F81, 'M', '肉'), + (0x2F82, 'M', '臣'), + (0x2F83, 'M', '自'), + (0x2F84, 'M', '至'), + (0x2F85, 'M', '臼'), + (0x2F86, 'M', '舌'), + (0x2F87, 'M', '舛'), + (0x2F88, 'M', '舟'), + (0x2F89, 'M', '艮'), + (0x2F8A, 'M', '色'), + (0x2F8B, 'M', '艸'), + (0x2F8C, 'M', '虍'), + (0x2F8D, 'M', '虫'), + (0x2F8E, 'M', '血'), + (0x2F8F, 'M', '行'), + (0x2F90, 'M', '衣'), + (0x2F91, 'M', '襾'), + (0x2F92, 'M', '見'), + (0x2F93, 'M', '角'), + (0x2F94, 'M', '言'), + (0x2F95, 'M', '谷'), + (0x2F96, 'M', '豆'), + (0x2F97, 'M', '豕'), + (0x2F98, 'M', '豸'), + (0x2F99, 'M', '貝'), + (0x2F9A, 'M', '赤'), + (0x2F9B, 'M', '走'), + (0x2F9C, 'M', '足'), + (0x2F9D, 'M', '身'), + (0x2F9E, 'M', '車'), + (0x2F9F, 'M', '辛'), + (0x2FA0, 'M', '辰'), + (0x2FA1, 'M', '辵'), + (0x2FA2, 'M', '邑'), + (0x2FA3, 'M', '酉'), + (0x2FA4, 'M', '釆'), + (0x2FA5, 'M', '里'), + (0x2FA6, 'M', '金'), + (0x2FA7, 'M', '長'), + (0x2FA8, 'M', '門'), + (0x2FA9, 'M', '阜'), + (0x2FAA, 'M', '隶'), + (0x2FAB, 'M', '隹'), + (0x2FAC, 'M', '雨'), + (0x2FAD, 'M', '靑'), + (0x2FAE, 'M', '非'), + (0x2FAF, 'M', '面'), + (0x2FB0, 'M', '革'), + (0x2FB1, 'M', '韋'), + (0x2FB2, 'M', '韭'), + (0x2FB3, 'M', '音'), + (0x2FB4, 'M', '頁'), + (0x2FB5, 'M', '風'), + (0x2FB6, 'M', '飛'), + (0x2FB7, 'M', '食'), + (0x2FB8, 'M', '首'), + (0x2FB9, 'M', '香'), + (0x2FBA, 'M', '馬'), + (0x2FBB, 'M', '骨'), + (0x2FBC, 'M', '高'), + (0x2FBD, 'M', '髟'), + (0x2FBE, 'M', '鬥'), + (0x2FBF, 'M', '鬯'), + (0x2FC0, 'M', '鬲'), + (0x2FC1, 'M', '鬼'), + (0x2FC2, 'M', '魚'), + (0x2FC3, 'M', '鳥'), + (0x2FC4, 'M', '鹵'), + (0x2FC5, 'M', '鹿'), + (0x2FC6, 'M', '麥'), + (0x2FC7, 'M', '麻'), + (0x2FC8, 'M', '黃'), + (0x2FC9, 'M', '黍'), + (0x2FCA, 'M', '黑'), + (0x2FCB, 'M', '黹'), + (0x2FCC, 'M', '黽'), + (0x2FCD, 'M', '鼎'), + (0x2FCE, 'M', '鼓'), + (0x2FCF, 'M', '鼠'), + (0x2FD0, 'M', '鼻'), + (0x2FD1, 'M', '齊'), + (0x2FD2, 'M', '齒'), + (0x2FD3, 'M', '龍'), + (0x2FD4, 'M', '龜'), + (0x2FD5, 'M', '龠'), + (0x2FD6, 'X'), + (0x3000, '3', ' '), + (0x3001, 'V'), + (0x3002, 'M', '.'), + (0x3003, 'V'), + (0x3036, 'M', '〒'), + (0x3037, 'V'), + (0x3038, 'M', '十'), + (0x3039, 'M', '卄'), + (0x303A, 'M', '卅'), + (0x303B, 'V'), + (0x3040, 'X'), + ] + +def _seg_29() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x3041, 'V'), + (0x3097, 'X'), + (0x3099, 'V'), + (0x309B, '3', ' ゙'), + (0x309C, '3', ' ゚'), + (0x309D, 'V'), + (0x309F, 'M', 'より'), + (0x30A0, 'V'), + (0x30FF, 'M', 'コト'), + (0x3100, 'X'), + (0x3105, 'V'), + (0x3130, 'X'), + (0x3131, 'M', 'ᄀ'), + (0x3132, 'M', 'ᄁ'), + (0x3133, 'M', 'ᆪ'), + (0x3134, 'M', 'ᄂ'), + (0x3135, 'M', 'ᆬ'), + (0x3136, 'M', 'ᆭ'), + (0x3137, 'M', 'ᄃ'), + (0x3138, 'M', 'ᄄ'), + (0x3139, 'M', 'ᄅ'), + (0x313A, 'M', 'ᆰ'), + (0x313B, 'M', 'ᆱ'), + (0x313C, 'M', 'ᆲ'), + (0x313D, 'M', 'ᆳ'), + (0x313E, 'M', 'ᆴ'), + (0x313F, 'M', 'ᆵ'), + (0x3140, 'M', 'ᄚ'), + (0x3141, 'M', 'ᄆ'), + (0x3142, 'M', 'ᄇ'), + (0x3143, 'M', 'ᄈ'), + (0x3144, 'M', 'ᄡ'), + (0x3145, 'M', 'ᄉ'), + (0x3146, 'M', 'ᄊ'), + (0x3147, 'M', 'ᄋ'), + (0x3148, 'M', 'ᄌ'), + (0x3149, 'M', 'ᄍ'), + (0x314A, 'M', 'ᄎ'), + (0x314B, 'M', 'ᄏ'), + (0x314C, 'M', 'ᄐ'), + (0x314D, 'M', 'ᄑ'), + (0x314E, 'M', 'ᄒ'), + (0x314F, 'M', 'ᅡ'), + (0x3150, 'M', 'ᅢ'), + (0x3151, 'M', 'ᅣ'), + (0x3152, 'M', 'ᅤ'), + (0x3153, 'M', 'ᅥ'), + (0x3154, 'M', 'ᅦ'), + (0x3155, 'M', 'ᅧ'), + (0x3156, 'M', 'ᅨ'), + (0x3157, 'M', 'ᅩ'), + (0x3158, 'M', 'ᅪ'), + (0x3159, 'M', 'ᅫ'), + (0x315A, 'M', 'ᅬ'), + (0x315B, 'M', 'ᅭ'), + (0x315C, 'M', 'ᅮ'), + (0x315D, 'M', 'ᅯ'), + (0x315E, 'M', 'ᅰ'), + (0x315F, 'M', 'ᅱ'), + (0x3160, 'M', 'ᅲ'), + (0x3161, 'M', 'ᅳ'), + (0x3162, 'M', 'ᅴ'), + (0x3163, 'M', 'ᅵ'), + (0x3164, 'X'), + (0x3165, 'M', 'ᄔ'), + (0x3166, 'M', 'ᄕ'), + (0x3167, 'M', 'ᇇ'), + (0x3168, 'M', 'ᇈ'), + (0x3169, 'M', 'ᇌ'), + (0x316A, 'M', 'ᇎ'), + (0x316B, 'M', 'ᇓ'), + (0x316C, 'M', 'ᇗ'), + (0x316D, 'M', 'ᇙ'), + (0x316E, 'M', 'ᄜ'), + (0x316F, 'M', 'ᇝ'), + (0x3170, 'M', 'ᇟ'), + (0x3171, 'M', 'ᄝ'), + (0x3172, 'M', 'ᄞ'), + (0x3173, 'M', 'ᄠ'), + (0x3174, 'M', 'ᄢ'), + (0x3175, 'M', 'ᄣ'), + (0x3176, 'M', 'ᄧ'), + (0x3177, 'M', 'ᄩ'), + (0x3178, 'M', 'ᄫ'), + (0x3179, 'M', 'ᄬ'), + (0x317A, 'M', 'ᄭ'), + (0x317B, 'M', 'ᄮ'), + (0x317C, 'M', 'ᄯ'), + (0x317D, 'M', 'ᄲ'), + (0x317E, 'M', 'ᄶ'), + (0x317F, 'M', 'ᅀ'), + (0x3180, 'M', 'ᅇ'), + (0x3181, 'M', 'ᅌ'), + (0x3182, 'M', 'ᇱ'), + (0x3183, 'M', 'ᇲ'), + (0x3184, 'M', 'ᅗ'), + (0x3185, 'M', 'ᅘ'), + (0x3186, 'M', 'ᅙ'), + (0x3187, 'M', 'ᆄ'), + (0x3188, 'M', 'ᆅ'), + ] + +def _seg_30() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x3189, 'M', 'ᆈ'), + (0x318A, 'M', 'ᆑ'), + (0x318B, 'M', 'ᆒ'), + (0x318C, 'M', 'ᆔ'), + (0x318D, 'M', 'ᆞ'), + (0x318E, 'M', 'ᆡ'), + (0x318F, 'X'), + (0x3190, 'V'), + (0x3192, 'M', '一'), + (0x3193, 'M', '二'), + (0x3194, 'M', '三'), + (0x3195, 'M', '四'), + (0x3196, 'M', '上'), + (0x3197, 'M', '中'), + (0x3198, 'M', '下'), + (0x3199, 'M', '甲'), + (0x319A, 'M', '乙'), + (0x319B, 'M', '丙'), + (0x319C, 'M', '丁'), + (0x319D, 'M', '天'), + (0x319E, 'M', '地'), + (0x319F, 'M', '人'), + (0x31A0, 'V'), + (0x31E4, 'X'), + (0x31F0, 'V'), + (0x3200, '3', '(ᄀ)'), + (0x3201, '3', '(ᄂ)'), + (0x3202, '3', '(ᄃ)'), + (0x3203, '3', '(ᄅ)'), + (0x3204, '3', '(ᄆ)'), + (0x3205, '3', '(ᄇ)'), + (0x3206, '3', '(ᄉ)'), + (0x3207, '3', '(ᄋ)'), + (0x3208, '3', '(ᄌ)'), + (0x3209, '3', '(ᄎ)'), + (0x320A, '3', '(ᄏ)'), + (0x320B, '3', '(ᄐ)'), + (0x320C, '3', '(ᄑ)'), + (0x320D, '3', '(ᄒ)'), + (0x320E, '3', '(가)'), + (0x320F, '3', '(나)'), + (0x3210, '3', '(다)'), + (0x3211, '3', '(라)'), + (0x3212, '3', '(마)'), + (0x3213, '3', '(바)'), + (0x3214, '3', '(사)'), + (0x3215, '3', '(아)'), + (0x3216, '3', '(자)'), + (0x3217, '3', '(차)'), + (0x3218, '3', '(카)'), + (0x3219, '3', '(타)'), + (0x321A, '3', '(파)'), + (0x321B, '3', '(하)'), + (0x321C, '3', '(주)'), + (0x321D, '3', '(오전)'), + (0x321E, '3', '(오후)'), + (0x321F, 'X'), + (0x3220, '3', '(一)'), + (0x3221, '3', '(二)'), + (0x3222, '3', '(三)'), + (0x3223, '3', '(四)'), + (0x3224, '3', '(五)'), + (0x3225, '3', '(六)'), + (0x3226, '3', '(七)'), + (0x3227, '3', '(八)'), + (0x3228, '3', '(九)'), + (0x3229, '3', '(十)'), + (0x322A, '3', '(月)'), + (0x322B, '3', '(火)'), + (0x322C, '3', '(水)'), + (0x322D, '3', '(木)'), + (0x322E, '3', '(金)'), + (0x322F, '3', '(土)'), + (0x3230, '3', '(日)'), + (0x3231, '3', '(株)'), + (0x3232, '3', '(有)'), + (0x3233, '3', '(社)'), + (0x3234, '3', '(名)'), + (0x3235, '3', '(特)'), + (0x3236, '3', '(財)'), + (0x3237, '3', '(祝)'), + (0x3238, '3', '(労)'), + (0x3239, '3', '(代)'), + (0x323A, '3', '(呼)'), + (0x323B, '3', '(学)'), + (0x323C, '3', '(監)'), + (0x323D, '3', '(企)'), + (0x323E, '3', '(資)'), + (0x323F, '3', '(協)'), + (0x3240, '3', '(祭)'), + (0x3241, '3', '(休)'), + (0x3242, '3', '(自)'), + (0x3243, '3', '(至)'), + (0x3244, 'M', '問'), + (0x3245, 'M', '幼'), + (0x3246, 'M', '文'), + (0x3247, 'M', '箏'), + (0x3248, 'V'), + (0x3250, 'M', 'pte'), + (0x3251, 'M', '21'), + ] + +def _seg_31() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x3252, 'M', '22'), + (0x3253, 'M', '23'), + (0x3254, 'M', '24'), + (0x3255, 'M', '25'), + (0x3256, 'M', '26'), + (0x3257, 'M', '27'), + (0x3258, 'M', '28'), + (0x3259, 'M', '29'), + (0x325A, 'M', '30'), + (0x325B, 'M', '31'), + (0x325C, 'M', '32'), + (0x325D, 'M', '33'), + (0x325E, 'M', '34'), + (0x325F, 'M', '35'), + (0x3260, 'M', 'ᄀ'), + (0x3261, 'M', 'ᄂ'), + (0x3262, 'M', 'ᄃ'), + (0x3263, 'M', 'ᄅ'), + (0x3264, 'M', 'ᄆ'), + (0x3265, 'M', 'ᄇ'), + (0x3266, 'M', 'ᄉ'), + (0x3267, 'M', 'ᄋ'), + (0x3268, 'M', 'ᄌ'), + (0x3269, 'M', 'ᄎ'), + (0x326A, 'M', 'ᄏ'), + (0x326B, 'M', 'ᄐ'), + (0x326C, 'M', 'ᄑ'), + (0x326D, 'M', 'ᄒ'), + (0x326E, 'M', '가'), + (0x326F, 'M', '나'), + (0x3270, 'M', '다'), + (0x3271, 'M', '라'), + (0x3272, 'M', '마'), + (0x3273, 'M', '바'), + (0x3274, 'M', '사'), + (0x3275, 'M', '아'), + (0x3276, 'M', '자'), + (0x3277, 'M', '차'), + (0x3278, 'M', '카'), + (0x3279, 'M', '타'), + (0x327A, 'M', '파'), + (0x327B, 'M', '하'), + (0x327C, 'M', '참고'), + (0x327D, 'M', '주의'), + (0x327E, 'M', '우'), + (0x327F, 'V'), + (0x3280, 'M', '一'), + (0x3281, 'M', '二'), + (0x3282, 'M', '三'), + (0x3283, 'M', '四'), + (0x3284, 'M', '五'), + (0x3285, 'M', '六'), + (0x3286, 'M', '七'), + (0x3287, 'M', '八'), + (0x3288, 'M', '九'), + (0x3289, 'M', '十'), + (0x328A, 'M', '月'), + (0x328B, 'M', '火'), + (0x328C, 'M', '水'), + (0x328D, 'M', '木'), + (0x328E, 'M', '金'), + (0x328F, 'M', '土'), + (0x3290, 'M', '日'), + (0x3291, 'M', '株'), + (0x3292, 'M', '有'), + (0x3293, 'M', '社'), + (0x3294, 'M', '名'), + (0x3295, 'M', '特'), + (0x3296, 'M', '財'), + (0x3297, 'M', '祝'), + (0x3298, 'M', '労'), + (0x3299, 'M', '秘'), + (0x329A, 'M', '男'), + (0x329B, 'M', '女'), + (0x329C, 'M', '適'), + (0x329D, 'M', '優'), + (0x329E, 'M', '印'), + (0x329F, 'M', '注'), + (0x32A0, 'M', '項'), + (0x32A1, 'M', '休'), + (0x32A2, 'M', '写'), + (0x32A3, 'M', '正'), + (0x32A4, 'M', '上'), + (0x32A5, 'M', '中'), + (0x32A6, 'M', '下'), + (0x32A7, 'M', '左'), + (0x32A8, 'M', '右'), + (0x32A9, 'M', '医'), + (0x32AA, 'M', '宗'), + (0x32AB, 'M', '学'), + (0x32AC, 'M', '監'), + (0x32AD, 'M', '企'), + (0x32AE, 'M', '資'), + (0x32AF, 'M', '協'), + (0x32B0, 'M', '夜'), + (0x32B1, 'M', '36'), + (0x32B2, 'M', '37'), + (0x32B3, 'M', '38'), + (0x32B4, 'M', '39'), + (0x32B5, 'M', '40'), + ] + +def _seg_32() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x32B6, 'M', '41'), + (0x32B7, 'M', '42'), + (0x32B8, 'M', '43'), + (0x32B9, 'M', '44'), + (0x32BA, 'M', '45'), + (0x32BB, 'M', '46'), + (0x32BC, 'M', '47'), + (0x32BD, 'M', '48'), + (0x32BE, 'M', '49'), + (0x32BF, 'M', '50'), + (0x32C0, 'M', '1月'), + (0x32C1, 'M', '2月'), + (0x32C2, 'M', '3月'), + (0x32C3, 'M', '4月'), + (0x32C4, 'M', '5月'), + (0x32C5, 'M', '6月'), + (0x32C6, 'M', '7月'), + (0x32C7, 'M', '8月'), + (0x32C8, 'M', '9月'), + (0x32C9, 'M', '10月'), + (0x32CA, 'M', '11月'), + (0x32CB, 'M', '12月'), + (0x32CC, 'M', 'hg'), + (0x32CD, 'M', 'erg'), + (0x32CE, 'M', 'ev'), + (0x32CF, 'M', 'ltd'), + (0x32D0, 'M', 'ア'), + (0x32D1, 'M', 'イ'), + (0x32D2, 'M', 'ウ'), + (0x32D3, 'M', 'エ'), + (0x32D4, 'M', 'オ'), + (0x32D5, 'M', 'カ'), + (0x32D6, 'M', 'キ'), + (0x32D7, 'M', 'ク'), + (0x32D8, 'M', 'ケ'), + (0x32D9, 'M', 'コ'), + (0x32DA, 'M', 'サ'), + (0x32DB, 'M', 'シ'), + (0x32DC, 'M', 'ス'), + (0x32DD, 'M', 'セ'), + (0x32DE, 'M', 'ソ'), + (0x32DF, 'M', 'タ'), + (0x32E0, 'M', 'チ'), + (0x32E1, 'M', 'ツ'), + (0x32E2, 'M', 'テ'), + (0x32E3, 'M', 'ト'), + (0x32E4, 'M', 'ナ'), + (0x32E5, 'M', 'ニ'), + (0x32E6, 'M', 'ヌ'), + (0x32E7, 'M', 'ネ'), + (0x32E8, 'M', 'ノ'), + (0x32E9, 'M', 'ハ'), + (0x32EA, 'M', 'ヒ'), + (0x32EB, 'M', 'フ'), + (0x32EC, 'M', 'ヘ'), + (0x32ED, 'M', 'ホ'), + (0x32EE, 'M', 'マ'), + (0x32EF, 'M', 'ミ'), + (0x32F0, 'M', 'ム'), + (0x32F1, 'M', 'メ'), + (0x32F2, 'M', 'モ'), + (0x32F3, 'M', 'ヤ'), + (0x32F4, 'M', 'ユ'), + (0x32F5, 'M', 'ヨ'), + (0x32F6, 'M', 'ラ'), + (0x32F7, 'M', 'リ'), + (0x32F8, 'M', 'ル'), + (0x32F9, 'M', 'レ'), + (0x32FA, 'M', 'ロ'), + (0x32FB, 'M', 'ワ'), + (0x32FC, 'M', 'ヰ'), + (0x32FD, 'M', 'ヱ'), + (0x32FE, 'M', 'ヲ'), + (0x32FF, 'M', '令和'), + (0x3300, 'M', 'アパート'), + (0x3301, 'M', 'アルファ'), + (0x3302, 'M', 'アンペア'), + (0x3303, 'M', 'アール'), + (0x3304, 'M', 'イニング'), + (0x3305, 'M', 'インチ'), + (0x3306, 'M', 'ウォン'), + (0x3307, 'M', 'エスクード'), + (0x3308, 'M', 'エーカー'), + (0x3309, 'M', 'オンス'), + (0x330A, 'M', 'オーム'), + (0x330B, 'M', 'カイリ'), + (0x330C, 'M', 'カラット'), + (0x330D, 'M', 'カロリー'), + (0x330E, 'M', 'ガロン'), + (0x330F, 'M', 'ガンマ'), + (0x3310, 'M', 'ギガ'), + (0x3311, 'M', 'ギニー'), + (0x3312, 'M', 'キュリー'), + (0x3313, 'M', 'ギルダー'), + (0x3314, 'M', 'キロ'), + (0x3315, 'M', 'キログラム'), + (0x3316, 'M', 'キロメートル'), + (0x3317, 'M', 'キロワット'), + (0x3318, 'M', 'グラム'), + (0x3319, 'M', 'グラムトン'), + ] + +def _seg_33() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x331A, 'M', 'クルゼイロ'), + (0x331B, 'M', 'クローネ'), + (0x331C, 'M', 'ケース'), + (0x331D, 'M', 'コルナ'), + (0x331E, 'M', 'コーポ'), + (0x331F, 'M', 'サイクル'), + (0x3320, 'M', 'サンチーム'), + (0x3321, 'M', 'シリング'), + (0x3322, 'M', 'センチ'), + (0x3323, 'M', 'セント'), + (0x3324, 'M', 'ダース'), + (0x3325, 'M', 'デシ'), + (0x3326, 'M', 'ドル'), + (0x3327, 'M', 'トン'), + (0x3328, 'M', 'ナノ'), + (0x3329, 'M', 'ノット'), + (0x332A, 'M', 'ハイツ'), + (0x332B, 'M', 'パーセント'), + (0x332C, 'M', 'パーツ'), + (0x332D, 'M', 'バーレル'), + (0x332E, 'M', 'ピアストル'), + (0x332F, 'M', 'ピクル'), + (0x3330, 'M', 'ピコ'), + (0x3331, 'M', 'ビル'), + (0x3332, 'M', 'ファラッド'), + (0x3333, 'M', 'フィート'), + (0x3334, 'M', 'ブッシェル'), + (0x3335, 'M', 'フラン'), + (0x3336, 'M', 'ヘクタール'), + (0x3337, 'M', 'ペソ'), + (0x3338, 'M', 'ペニヒ'), + (0x3339, 'M', 'ヘルツ'), + (0x333A, 'M', 'ペンス'), + (0x333B, 'M', 'ページ'), + (0x333C, 'M', 'ベータ'), + (0x333D, 'M', 'ポイント'), + (0x333E, 'M', 'ボルト'), + (0x333F, 'M', 'ホン'), + (0x3340, 'M', 'ポンド'), + (0x3341, 'M', 'ホール'), + (0x3342, 'M', 'ホーン'), + (0x3343, 'M', 'マイクロ'), + (0x3344, 'M', 'マイル'), + (0x3345, 'M', 'マッハ'), + (0x3346, 'M', 'マルク'), + (0x3347, 'M', 'マンション'), + (0x3348, 'M', 'ミクロン'), + (0x3349, 'M', 'ミリ'), + (0x334A, 'M', 'ミリバール'), + (0x334B, 'M', 'メガ'), + (0x334C, 'M', 'メガトン'), + (0x334D, 'M', 'メートル'), + (0x334E, 'M', 'ヤード'), + (0x334F, 'M', 'ヤール'), + (0x3350, 'M', 'ユアン'), + (0x3351, 'M', 'リットル'), + (0x3352, 'M', 'リラ'), + (0x3353, 'M', 'ルピー'), + (0x3354, 'M', 'ルーブル'), + (0x3355, 'M', 'レム'), + (0x3356, 'M', 'レントゲン'), + (0x3357, 'M', 'ワット'), + (0x3358, 'M', '0点'), + (0x3359, 'M', '1点'), + (0x335A, 'M', '2点'), + (0x335B, 'M', '3点'), + (0x335C, 'M', '4点'), + (0x335D, 'M', '5点'), + (0x335E, 'M', '6点'), + (0x335F, 'M', '7点'), + (0x3360, 'M', '8点'), + (0x3361, 'M', '9点'), + (0x3362, 'M', '10点'), + (0x3363, 'M', '11点'), + (0x3364, 'M', '12点'), + (0x3365, 'M', '13点'), + (0x3366, 'M', '14点'), + (0x3367, 'M', '15点'), + (0x3368, 'M', '16点'), + (0x3369, 'M', '17点'), + (0x336A, 'M', '18点'), + (0x336B, 'M', '19点'), + (0x336C, 'M', '20点'), + (0x336D, 'M', '21点'), + (0x336E, 'M', '22点'), + (0x336F, 'M', '23点'), + (0x3370, 'M', '24点'), + (0x3371, 'M', 'hpa'), + (0x3372, 'M', 'da'), + (0x3373, 'M', 'au'), + (0x3374, 'M', 'bar'), + (0x3375, 'M', 'ov'), + (0x3376, 'M', 'pc'), + (0x3377, 'M', 'dm'), + (0x3378, 'M', 'dm2'), + (0x3379, 'M', 'dm3'), + (0x337A, 'M', 'iu'), + (0x337B, 'M', '平成'), + (0x337C, 'M', '昭和'), + (0x337D, 'M', '大正'), + ] + +def _seg_34() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x337E, 'M', '明治'), + (0x337F, 'M', '株式会社'), + (0x3380, 'M', 'pa'), + (0x3381, 'M', 'na'), + (0x3382, 'M', 'μa'), + (0x3383, 'M', 'ma'), + (0x3384, 'M', 'ka'), + (0x3385, 'M', 'kb'), + (0x3386, 'M', 'mb'), + (0x3387, 'M', 'gb'), + (0x3388, 'M', 'cal'), + (0x3389, 'M', 'kcal'), + (0x338A, 'M', 'pf'), + (0x338B, 'M', 'nf'), + (0x338C, 'M', 'μf'), + (0x338D, 'M', 'μg'), + (0x338E, 'M', 'mg'), + (0x338F, 'M', 'kg'), + (0x3390, 'M', 'hz'), + (0x3391, 'M', 'khz'), + (0x3392, 'M', 'mhz'), + (0x3393, 'M', 'ghz'), + (0x3394, 'M', 'thz'), + (0x3395, 'M', 'μl'), + (0x3396, 'M', 'ml'), + (0x3397, 'M', 'dl'), + (0x3398, 'M', 'kl'), + (0x3399, 'M', 'fm'), + (0x339A, 'M', 'nm'), + (0x339B, 'M', 'μm'), + (0x339C, 'M', 'mm'), + (0x339D, 'M', 'cm'), + (0x339E, 'M', 'km'), + (0x339F, 'M', 'mm2'), + (0x33A0, 'M', 'cm2'), + (0x33A1, 'M', 'm2'), + (0x33A2, 'M', 'km2'), + (0x33A3, 'M', 'mm3'), + (0x33A4, 'M', 'cm3'), + (0x33A5, 'M', 'm3'), + (0x33A6, 'M', 'km3'), + (0x33A7, 'M', 'm∕s'), + (0x33A8, 'M', 'm∕s2'), + (0x33A9, 'M', 'pa'), + (0x33AA, 'M', 'kpa'), + (0x33AB, 'M', 'mpa'), + (0x33AC, 'M', 'gpa'), + (0x33AD, 'M', 'rad'), + (0x33AE, 'M', 'rad∕s'), + (0x33AF, 'M', 'rad∕s2'), + (0x33B0, 'M', 'ps'), + (0x33B1, 'M', 'ns'), + (0x33B2, 'M', 'μs'), + (0x33B3, 'M', 'ms'), + (0x33B4, 'M', 'pv'), + (0x33B5, 'M', 'nv'), + (0x33B6, 'M', 'μv'), + (0x33B7, 'M', 'mv'), + (0x33B8, 'M', 'kv'), + (0x33B9, 'M', 'mv'), + (0x33BA, 'M', 'pw'), + (0x33BB, 'M', 'nw'), + (0x33BC, 'M', 'μw'), + (0x33BD, 'M', 'mw'), + (0x33BE, 'M', 'kw'), + (0x33BF, 'M', 'mw'), + (0x33C0, 'M', 'kω'), + (0x33C1, 'M', 'mω'), + (0x33C2, 'X'), + (0x33C3, 'M', 'bq'), + (0x33C4, 'M', 'cc'), + (0x33C5, 'M', 'cd'), + (0x33C6, 'M', 'c∕kg'), + (0x33C7, 'X'), + (0x33C8, 'M', 'db'), + (0x33C9, 'M', 'gy'), + (0x33CA, 'M', 'ha'), + (0x33CB, 'M', 'hp'), + (0x33CC, 'M', 'in'), + (0x33CD, 'M', 'kk'), + (0x33CE, 'M', 'km'), + (0x33CF, 'M', 'kt'), + (0x33D0, 'M', 'lm'), + (0x33D1, 'M', 'ln'), + (0x33D2, 'M', 'log'), + (0x33D3, 'M', 'lx'), + (0x33D4, 'M', 'mb'), + (0x33D5, 'M', 'mil'), + (0x33D6, 'M', 'mol'), + (0x33D7, 'M', 'ph'), + (0x33D8, 'X'), + (0x33D9, 'M', 'ppm'), + (0x33DA, 'M', 'pr'), + (0x33DB, 'M', 'sr'), + (0x33DC, 'M', 'sv'), + (0x33DD, 'M', 'wb'), + (0x33DE, 'M', 'v∕m'), + (0x33DF, 'M', 'a∕m'), + (0x33E0, 'M', '1日'), + (0x33E1, 'M', '2日'), + ] + +def _seg_35() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x33E2, 'M', '3日'), + (0x33E3, 'M', '4日'), + (0x33E4, 'M', '5日'), + (0x33E5, 'M', '6日'), + (0x33E6, 'M', '7日'), + (0x33E7, 'M', '8日'), + (0x33E8, 'M', '9日'), + (0x33E9, 'M', '10日'), + (0x33EA, 'M', '11日'), + (0x33EB, 'M', '12日'), + (0x33EC, 'M', '13日'), + (0x33ED, 'M', '14日'), + (0x33EE, 'M', '15日'), + (0x33EF, 'M', '16日'), + (0x33F0, 'M', '17日'), + (0x33F1, 'M', '18日'), + (0x33F2, 'M', '19日'), + (0x33F3, 'M', '20日'), + (0x33F4, 'M', '21日'), + (0x33F5, 'M', '22日'), + (0x33F6, 'M', '23日'), + (0x33F7, 'M', '24日'), + (0x33F8, 'M', '25日'), + (0x33F9, 'M', '26日'), + (0x33FA, 'M', '27日'), + (0x33FB, 'M', '28日'), + (0x33FC, 'M', '29日'), + (0x33FD, 'M', '30日'), + (0x33FE, 'M', '31日'), + (0x33FF, 'M', 'gal'), + (0x3400, 'V'), + (0xA48D, 'X'), + (0xA490, 'V'), + (0xA4C7, 'X'), + (0xA4D0, 'V'), + (0xA62C, 'X'), + (0xA640, 'M', 'ꙁ'), + (0xA641, 'V'), + (0xA642, 'M', 'ꙃ'), + (0xA643, 'V'), + (0xA644, 'M', 'ꙅ'), + (0xA645, 'V'), + (0xA646, 'M', 'ꙇ'), + (0xA647, 'V'), + (0xA648, 'M', 'ꙉ'), + (0xA649, 'V'), + (0xA64A, 'M', 'ꙋ'), + (0xA64B, 'V'), + (0xA64C, 'M', 'ꙍ'), + (0xA64D, 'V'), + (0xA64E, 'M', 'ꙏ'), + (0xA64F, 'V'), + (0xA650, 'M', 'ꙑ'), + (0xA651, 'V'), + (0xA652, 'M', 'ꙓ'), + (0xA653, 'V'), + (0xA654, 'M', 'ꙕ'), + (0xA655, 'V'), + (0xA656, 'M', 'ꙗ'), + (0xA657, 'V'), + (0xA658, 'M', 'ꙙ'), + (0xA659, 'V'), + (0xA65A, 'M', 'ꙛ'), + (0xA65B, 'V'), + (0xA65C, 'M', 'ꙝ'), + (0xA65D, 'V'), + (0xA65E, 'M', 'ꙟ'), + (0xA65F, 'V'), + (0xA660, 'M', 'ꙡ'), + (0xA661, 'V'), + (0xA662, 'M', 'ꙣ'), + (0xA663, 'V'), + (0xA664, 'M', 'ꙥ'), + (0xA665, 'V'), + (0xA666, 'M', 'ꙧ'), + (0xA667, 'V'), + (0xA668, 'M', 'ꙩ'), + (0xA669, 'V'), + (0xA66A, 'M', 'ꙫ'), + (0xA66B, 'V'), + (0xA66C, 'M', 'ꙭ'), + (0xA66D, 'V'), + (0xA680, 'M', 'ꚁ'), + (0xA681, 'V'), + (0xA682, 'M', 'ꚃ'), + (0xA683, 'V'), + (0xA684, 'M', 'ꚅ'), + (0xA685, 'V'), + (0xA686, 'M', 'ꚇ'), + (0xA687, 'V'), + (0xA688, 'M', 'ꚉ'), + (0xA689, 'V'), + (0xA68A, 'M', 'ꚋ'), + (0xA68B, 'V'), + (0xA68C, 'M', 'ꚍ'), + (0xA68D, 'V'), + (0xA68E, 'M', 'ꚏ'), + (0xA68F, 'V'), + (0xA690, 'M', 'ꚑ'), + (0xA691, 'V'), + ] + +def _seg_36() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xA692, 'M', 'ꚓ'), + (0xA693, 'V'), + (0xA694, 'M', 'ꚕ'), + (0xA695, 'V'), + (0xA696, 'M', 'ꚗ'), + (0xA697, 'V'), + (0xA698, 'M', 'ꚙ'), + (0xA699, 'V'), + (0xA69A, 'M', 'ꚛ'), + (0xA69B, 'V'), + (0xA69C, 'M', 'ъ'), + (0xA69D, 'M', 'ь'), + (0xA69E, 'V'), + (0xA6F8, 'X'), + (0xA700, 'V'), + (0xA722, 'M', 'ꜣ'), + (0xA723, 'V'), + (0xA724, 'M', 'ꜥ'), + (0xA725, 'V'), + (0xA726, 'M', 'ꜧ'), + (0xA727, 'V'), + (0xA728, 'M', 'ꜩ'), + (0xA729, 'V'), + (0xA72A, 'M', 'ꜫ'), + (0xA72B, 'V'), + (0xA72C, 'M', 'ꜭ'), + (0xA72D, 'V'), + (0xA72E, 'M', 'ꜯ'), + (0xA72F, 'V'), + (0xA732, 'M', 'ꜳ'), + (0xA733, 'V'), + (0xA734, 'M', 'ꜵ'), + (0xA735, 'V'), + (0xA736, 'M', 'ꜷ'), + (0xA737, 'V'), + (0xA738, 'M', 'ꜹ'), + (0xA739, 'V'), + (0xA73A, 'M', 'ꜻ'), + (0xA73B, 'V'), + (0xA73C, 'M', 'ꜽ'), + (0xA73D, 'V'), + (0xA73E, 'M', 'ꜿ'), + (0xA73F, 'V'), + (0xA740, 'M', 'ꝁ'), + (0xA741, 'V'), + (0xA742, 'M', 'ꝃ'), + (0xA743, 'V'), + (0xA744, 'M', 'ꝅ'), + (0xA745, 'V'), + (0xA746, 'M', 'ꝇ'), + (0xA747, 'V'), + (0xA748, 'M', 'ꝉ'), + (0xA749, 'V'), + (0xA74A, 'M', 'ꝋ'), + (0xA74B, 'V'), + (0xA74C, 'M', 'ꝍ'), + (0xA74D, 'V'), + (0xA74E, 'M', 'ꝏ'), + (0xA74F, 'V'), + (0xA750, 'M', 'ꝑ'), + (0xA751, 'V'), + (0xA752, 'M', 'ꝓ'), + (0xA753, 'V'), + (0xA754, 'M', 'ꝕ'), + (0xA755, 'V'), + (0xA756, 'M', 'ꝗ'), + (0xA757, 'V'), + (0xA758, 'M', 'ꝙ'), + (0xA759, 'V'), + (0xA75A, 'M', 'ꝛ'), + (0xA75B, 'V'), + (0xA75C, 'M', 'ꝝ'), + (0xA75D, 'V'), + (0xA75E, 'M', 'ꝟ'), + (0xA75F, 'V'), + (0xA760, 'M', 'ꝡ'), + (0xA761, 'V'), + (0xA762, 'M', 'ꝣ'), + (0xA763, 'V'), + (0xA764, 'M', 'ꝥ'), + (0xA765, 'V'), + (0xA766, 'M', 'ꝧ'), + (0xA767, 'V'), + (0xA768, 'M', 'ꝩ'), + (0xA769, 'V'), + (0xA76A, 'M', 'ꝫ'), + (0xA76B, 'V'), + (0xA76C, 'M', 'ꝭ'), + (0xA76D, 'V'), + (0xA76E, 'M', 'ꝯ'), + (0xA76F, 'V'), + (0xA770, 'M', 'ꝯ'), + (0xA771, 'V'), + (0xA779, 'M', 'ꝺ'), + (0xA77A, 'V'), + (0xA77B, 'M', 'ꝼ'), + (0xA77C, 'V'), + (0xA77D, 'M', 'ᵹ'), + (0xA77E, 'M', 'ꝿ'), + (0xA77F, 'V'), + ] + +def _seg_37() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xA780, 'M', 'ꞁ'), + (0xA781, 'V'), + (0xA782, 'M', 'ꞃ'), + (0xA783, 'V'), + (0xA784, 'M', 'ꞅ'), + (0xA785, 'V'), + (0xA786, 'M', 'ꞇ'), + (0xA787, 'V'), + (0xA78B, 'M', 'ꞌ'), + (0xA78C, 'V'), + (0xA78D, 'M', 'ɥ'), + (0xA78E, 'V'), + (0xA790, 'M', 'ꞑ'), + (0xA791, 'V'), + (0xA792, 'M', 'ꞓ'), + (0xA793, 'V'), + (0xA796, 'M', 'ꞗ'), + (0xA797, 'V'), + (0xA798, 'M', 'ꞙ'), + (0xA799, 'V'), + (0xA79A, 'M', 'ꞛ'), + (0xA79B, 'V'), + (0xA79C, 'M', 'ꞝ'), + (0xA79D, 'V'), + (0xA79E, 'M', 'ꞟ'), + (0xA79F, 'V'), + (0xA7A0, 'M', 'ꞡ'), + (0xA7A1, 'V'), + (0xA7A2, 'M', 'ꞣ'), + (0xA7A3, 'V'), + (0xA7A4, 'M', 'ꞥ'), + (0xA7A5, 'V'), + (0xA7A6, 'M', 'ꞧ'), + (0xA7A7, 'V'), + (0xA7A8, 'M', 'ꞩ'), + (0xA7A9, 'V'), + (0xA7AA, 'M', 'ɦ'), + (0xA7AB, 'M', 'ɜ'), + (0xA7AC, 'M', 'ɡ'), + (0xA7AD, 'M', 'ɬ'), + (0xA7AE, 'M', 'ɪ'), + (0xA7AF, 'V'), + (0xA7B0, 'M', 'ʞ'), + (0xA7B1, 'M', 'ʇ'), + (0xA7B2, 'M', 'ʝ'), + (0xA7B3, 'M', 'ꭓ'), + (0xA7B4, 'M', 'ꞵ'), + (0xA7B5, 'V'), + (0xA7B6, 'M', 'ꞷ'), + (0xA7B7, 'V'), + (0xA7B8, 'M', 'ꞹ'), + (0xA7B9, 'V'), + (0xA7BA, 'M', 'ꞻ'), + (0xA7BB, 'V'), + (0xA7BC, 'M', 'ꞽ'), + (0xA7BD, 'V'), + (0xA7BE, 'M', 'ꞿ'), + (0xA7BF, 'V'), + (0xA7C0, 'M', 'ꟁ'), + (0xA7C1, 'V'), + (0xA7C2, 'M', 'ꟃ'), + (0xA7C3, 'V'), + (0xA7C4, 'M', 'ꞔ'), + (0xA7C5, 'M', 'ʂ'), + (0xA7C6, 'M', 'ᶎ'), + (0xA7C7, 'M', 'ꟈ'), + (0xA7C8, 'V'), + (0xA7C9, 'M', 'ꟊ'), + (0xA7CA, 'V'), + (0xA7CB, 'X'), + (0xA7D0, 'M', 'ꟑ'), + (0xA7D1, 'V'), + (0xA7D2, 'X'), + (0xA7D3, 'V'), + (0xA7D4, 'X'), + (0xA7D5, 'V'), + (0xA7D6, 'M', 'ꟗ'), + (0xA7D7, 'V'), + (0xA7D8, 'M', 'ꟙ'), + (0xA7D9, 'V'), + (0xA7DA, 'X'), + (0xA7F2, 'M', 'c'), + (0xA7F3, 'M', 'f'), + (0xA7F4, 'M', 'q'), + (0xA7F5, 'M', 'ꟶ'), + (0xA7F6, 'V'), + (0xA7F8, 'M', 'ħ'), + (0xA7F9, 'M', 'œ'), + (0xA7FA, 'V'), + (0xA82D, 'X'), + (0xA830, 'V'), + (0xA83A, 'X'), + (0xA840, 'V'), + (0xA878, 'X'), + (0xA880, 'V'), + (0xA8C6, 'X'), + (0xA8CE, 'V'), + (0xA8DA, 'X'), + (0xA8E0, 'V'), + (0xA954, 'X'), + ] + +def _seg_38() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xA95F, 'V'), + (0xA97D, 'X'), + (0xA980, 'V'), + (0xA9CE, 'X'), + (0xA9CF, 'V'), + (0xA9DA, 'X'), + (0xA9DE, 'V'), + (0xA9FF, 'X'), + (0xAA00, 'V'), + (0xAA37, 'X'), + (0xAA40, 'V'), + (0xAA4E, 'X'), + (0xAA50, 'V'), + (0xAA5A, 'X'), + (0xAA5C, 'V'), + (0xAAC3, 'X'), + (0xAADB, 'V'), + (0xAAF7, 'X'), + (0xAB01, 'V'), + (0xAB07, 'X'), + (0xAB09, 'V'), + (0xAB0F, 'X'), + (0xAB11, 'V'), + (0xAB17, 'X'), + (0xAB20, 'V'), + (0xAB27, 'X'), + (0xAB28, 'V'), + (0xAB2F, 'X'), + (0xAB30, 'V'), + (0xAB5C, 'M', 'ꜧ'), + (0xAB5D, 'M', 'ꬷ'), + (0xAB5E, 'M', 'ɫ'), + (0xAB5F, 'M', 'ꭒ'), + (0xAB60, 'V'), + (0xAB69, 'M', 'ʍ'), + (0xAB6A, 'V'), + (0xAB6C, 'X'), + (0xAB70, 'M', 'Ꭰ'), + (0xAB71, 'M', 'Ꭱ'), + (0xAB72, 'M', 'Ꭲ'), + (0xAB73, 'M', 'Ꭳ'), + (0xAB74, 'M', 'Ꭴ'), + (0xAB75, 'M', 'Ꭵ'), + (0xAB76, 'M', 'Ꭶ'), + (0xAB77, 'M', 'Ꭷ'), + (0xAB78, 'M', 'Ꭸ'), + (0xAB79, 'M', 'Ꭹ'), + (0xAB7A, 'M', 'Ꭺ'), + (0xAB7B, 'M', 'Ꭻ'), + (0xAB7C, 'M', 'Ꭼ'), + (0xAB7D, 'M', 'Ꭽ'), + (0xAB7E, 'M', 'Ꭾ'), + (0xAB7F, 'M', 'Ꭿ'), + (0xAB80, 'M', 'Ꮀ'), + (0xAB81, 'M', 'Ꮁ'), + (0xAB82, 'M', 'Ꮂ'), + (0xAB83, 'M', 'Ꮃ'), + (0xAB84, 'M', 'Ꮄ'), + (0xAB85, 'M', 'Ꮅ'), + (0xAB86, 'M', 'Ꮆ'), + (0xAB87, 'M', 'Ꮇ'), + (0xAB88, 'M', 'Ꮈ'), + (0xAB89, 'M', 'Ꮉ'), + (0xAB8A, 'M', 'Ꮊ'), + (0xAB8B, 'M', 'Ꮋ'), + (0xAB8C, 'M', 'Ꮌ'), + (0xAB8D, 'M', 'Ꮍ'), + (0xAB8E, 'M', 'Ꮎ'), + (0xAB8F, 'M', 'Ꮏ'), + (0xAB90, 'M', 'Ꮐ'), + (0xAB91, 'M', 'Ꮑ'), + (0xAB92, 'M', 'Ꮒ'), + (0xAB93, 'M', 'Ꮓ'), + (0xAB94, 'M', 'Ꮔ'), + (0xAB95, 'M', 'Ꮕ'), + (0xAB96, 'M', 'Ꮖ'), + (0xAB97, 'M', 'Ꮗ'), + (0xAB98, 'M', 'Ꮘ'), + (0xAB99, 'M', 'Ꮙ'), + (0xAB9A, 'M', 'Ꮚ'), + (0xAB9B, 'M', 'Ꮛ'), + (0xAB9C, 'M', 'Ꮜ'), + (0xAB9D, 'M', 'Ꮝ'), + (0xAB9E, 'M', 'Ꮞ'), + (0xAB9F, 'M', 'Ꮟ'), + (0xABA0, 'M', 'Ꮠ'), + (0xABA1, 'M', 'Ꮡ'), + (0xABA2, 'M', 'Ꮢ'), + (0xABA3, 'M', 'Ꮣ'), + (0xABA4, 'M', 'Ꮤ'), + (0xABA5, 'M', 'Ꮥ'), + (0xABA6, 'M', 'Ꮦ'), + (0xABA7, 'M', 'Ꮧ'), + (0xABA8, 'M', 'Ꮨ'), + (0xABA9, 'M', 'Ꮩ'), + (0xABAA, 'M', 'Ꮪ'), + (0xABAB, 'M', 'Ꮫ'), + (0xABAC, 'M', 'Ꮬ'), + (0xABAD, 'M', 'Ꮭ'), + (0xABAE, 'M', 'Ꮮ'), + ] + +def _seg_39() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xABAF, 'M', 'Ꮯ'), + (0xABB0, 'M', 'Ꮰ'), + (0xABB1, 'M', 'Ꮱ'), + (0xABB2, 'M', 'Ꮲ'), + (0xABB3, 'M', 'Ꮳ'), + (0xABB4, 'M', 'Ꮴ'), + (0xABB5, 'M', 'Ꮵ'), + (0xABB6, 'M', 'Ꮶ'), + (0xABB7, 'M', 'Ꮷ'), + (0xABB8, 'M', 'Ꮸ'), + (0xABB9, 'M', 'Ꮹ'), + (0xABBA, 'M', 'Ꮺ'), + (0xABBB, 'M', 'Ꮻ'), + (0xABBC, 'M', 'Ꮼ'), + (0xABBD, 'M', 'Ꮽ'), + (0xABBE, 'M', 'Ꮾ'), + (0xABBF, 'M', 'Ꮿ'), + (0xABC0, 'V'), + (0xABEE, 'X'), + (0xABF0, 'V'), + (0xABFA, 'X'), + (0xAC00, 'V'), + (0xD7A4, 'X'), + (0xD7B0, 'V'), + (0xD7C7, 'X'), + (0xD7CB, 'V'), + (0xD7FC, 'X'), + (0xF900, 'M', '豈'), + (0xF901, 'M', '更'), + (0xF902, 'M', '車'), + (0xF903, 'M', '賈'), + (0xF904, 'M', '滑'), + (0xF905, 'M', '串'), + (0xF906, 'M', '句'), + (0xF907, 'M', '龜'), + (0xF909, 'M', '契'), + (0xF90A, 'M', '金'), + (0xF90B, 'M', '喇'), + (0xF90C, 'M', '奈'), + (0xF90D, 'M', '懶'), + (0xF90E, 'M', '癩'), + (0xF90F, 'M', '羅'), + (0xF910, 'M', '蘿'), + (0xF911, 'M', '螺'), + (0xF912, 'M', '裸'), + (0xF913, 'M', '邏'), + (0xF914, 'M', '樂'), + (0xF915, 'M', '洛'), + (0xF916, 'M', '烙'), + (0xF917, 'M', '珞'), + (0xF918, 'M', '落'), + (0xF919, 'M', '酪'), + (0xF91A, 'M', '駱'), + (0xF91B, 'M', '亂'), + (0xF91C, 'M', '卵'), + (0xF91D, 'M', '欄'), + (0xF91E, 'M', '爛'), + (0xF91F, 'M', '蘭'), + (0xF920, 'M', '鸞'), + (0xF921, 'M', '嵐'), + (0xF922, 'M', '濫'), + (0xF923, 'M', '藍'), + (0xF924, 'M', '襤'), + (0xF925, 'M', '拉'), + (0xF926, 'M', '臘'), + (0xF927, 'M', '蠟'), + (0xF928, 'M', '廊'), + (0xF929, 'M', '朗'), + (0xF92A, 'M', '浪'), + (0xF92B, 'M', '狼'), + (0xF92C, 'M', '郎'), + (0xF92D, 'M', '來'), + (0xF92E, 'M', '冷'), + (0xF92F, 'M', '勞'), + (0xF930, 'M', '擄'), + (0xF931, 'M', '櫓'), + (0xF932, 'M', '爐'), + (0xF933, 'M', '盧'), + (0xF934, 'M', '老'), + (0xF935, 'M', '蘆'), + (0xF936, 'M', '虜'), + (0xF937, 'M', '路'), + (0xF938, 'M', '露'), + (0xF939, 'M', '魯'), + (0xF93A, 'M', '鷺'), + (0xF93B, 'M', '碌'), + (0xF93C, 'M', '祿'), + (0xF93D, 'M', '綠'), + (0xF93E, 'M', '菉'), + (0xF93F, 'M', '錄'), + (0xF940, 'M', '鹿'), + (0xF941, 'M', '論'), + (0xF942, 'M', '壟'), + (0xF943, 'M', '弄'), + (0xF944, 'M', '籠'), + (0xF945, 'M', '聾'), + (0xF946, 'M', '牢'), + (0xF947, 'M', '磊'), + (0xF948, 'M', '賂'), + (0xF949, 'M', '雷'), + ] + +def _seg_40() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xF94A, 'M', '壘'), + (0xF94B, 'M', '屢'), + (0xF94C, 'M', '樓'), + (0xF94D, 'M', '淚'), + (0xF94E, 'M', '漏'), + (0xF94F, 'M', '累'), + (0xF950, 'M', '縷'), + (0xF951, 'M', '陋'), + (0xF952, 'M', '勒'), + (0xF953, 'M', '肋'), + (0xF954, 'M', '凜'), + (0xF955, 'M', '凌'), + (0xF956, 'M', '稜'), + (0xF957, 'M', '綾'), + (0xF958, 'M', '菱'), + (0xF959, 'M', '陵'), + (0xF95A, 'M', '讀'), + (0xF95B, 'M', '拏'), + (0xF95C, 'M', '樂'), + (0xF95D, 'M', '諾'), + (0xF95E, 'M', '丹'), + (0xF95F, 'M', '寧'), + (0xF960, 'M', '怒'), + (0xF961, 'M', '率'), + (0xF962, 'M', '異'), + (0xF963, 'M', '北'), + (0xF964, 'M', '磻'), + (0xF965, 'M', '便'), + (0xF966, 'M', '復'), + (0xF967, 'M', '不'), + (0xF968, 'M', '泌'), + (0xF969, 'M', '數'), + (0xF96A, 'M', '索'), + (0xF96B, 'M', '參'), + (0xF96C, 'M', '塞'), + (0xF96D, 'M', '省'), + (0xF96E, 'M', '葉'), + (0xF96F, 'M', '說'), + (0xF970, 'M', '殺'), + (0xF971, 'M', '辰'), + (0xF972, 'M', '沈'), + (0xF973, 'M', '拾'), + (0xF974, 'M', '若'), + (0xF975, 'M', '掠'), + (0xF976, 'M', '略'), + (0xF977, 'M', '亮'), + (0xF978, 'M', '兩'), + (0xF979, 'M', '凉'), + (0xF97A, 'M', '梁'), + (0xF97B, 'M', '糧'), + (0xF97C, 'M', '良'), + (0xF97D, 'M', '諒'), + (0xF97E, 'M', '量'), + (0xF97F, 'M', '勵'), + (0xF980, 'M', '呂'), + (0xF981, 'M', '女'), + (0xF982, 'M', '廬'), + (0xF983, 'M', '旅'), + (0xF984, 'M', '濾'), + (0xF985, 'M', '礪'), + (0xF986, 'M', '閭'), + (0xF987, 'M', '驪'), + (0xF988, 'M', '麗'), + (0xF989, 'M', '黎'), + (0xF98A, 'M', '力'), + (0xF98B, 'M', '曆'), + (0xF98C, 'M', '歷'), + (0xF98D, 'M', '轢'), + (0xF98E, 'M', '年'), + (0xF98F, 'M', '憐'), + (0xF990, 'M', '戀'), + (0xF991, 'M', '撚'), + (0xF992, 'M', '漣'), + (0xF993, 'M', '煉'), + (0xF994, 'M', '璉'), + (0xF995, 'M', '秊'), + (0xF996, 'M', '練'), + (0xF997, 'M', '聯'), + (0xF998, 'M', '輦'), + (0xF999, 'M', '蓮'), + (0xF99A, 'M', '連'), + (0xF99B, 'M', '鍊'), + (0xF99C, 'M', '列'), + (0xF99D, 'M', '劣'), + (0xF99E, 'M', '咽'), + (0xF99F, 'M', '烈'), + (0xF9A0, 'M', '裂'), + (0xF9A1, 'M', '說'), + (0xF9A2, 'M', '廉'), + (0xF9A3, 'M', '念'), + (0xF9A4, 'M', '捻'), + (0xF9A5, 'M', '殮'), + (0xF9A6, 'M', '簾'), + (0xF9A7, 'M', '獵'), + (0xF9A8, 'M', '令'), + (0xF9A9, 'M', '囹'), + (0xF9AA, 'M', '寧'), + (0xF9AB, 'M', '嶺'), + (0xF9AC, 'M', '怜'), + (0xF9AD, 'M', '玲'), + ] + +def _seg_41() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xF9AE, 'M', '瑩'), + (0xF9AF, 'M', '羚'), + (0xF9B0, 'M', '聆'), + (0xF9B1, 'M', '鈴'), + (0xF9B2, 'M', '零'), + (0xF9B3, 'M', '靈'), + (0xF9B4, 'M', '領'), + (0xF9B5, 'M', '例'), + (0xF9B6, 'M', '禮'), + (0xF9B7, 'M', '醴'), + (0xF9B8, 'M', '隸'), + (0xF9B9, 'M', '惡'), + (0xF9BA, 'M', '了'), + (0xF9BB, 'M', '僚'), + (0xF9BC, 'M', '寮'), + (0xF9BD, 'M', '尿'), + (0xF9BE, 'M', '料'), + (0xF9BF, 'M', '樂'), + (0xF9C0, 'M', '燎'), + (0xF9C1, 'M', '療'), + (0xF9C2, 'M', '蓼'), + (0xF9C3, 'M', '遼'), + (0xF9C4, 'M', '龍'), + (0xF9C5, 'M', '暈'), + (0xF9C6, 'M', '阮'), + (0xF9C7, 'M', '劉'), + (0xF9C8, 'M', '杻'), + (0xF9C9, 'M', '柳'), + (0xF9CA, 'M', '流'), + (0xF9CB, 'M', '溜'), + (0xF9CC, 'M', '琉'), + (0xF9CD, 'M', '留'), + (0xF9CE, 'M', '硫'), + (0xF9CF, 'M', '紐'), + (0xF9D0, 'M', '類'), + (0xF9D1, 'M', '六'), + (0xF9D2, 'M', '戮'), + (0xF9D3, 'M', '陸'), + (0xF9D4, 'M', '倫'), + (0xF9D5, 'M', '崙'), + (0xF9D6, 'M', '淪'), + (0xF9D7, 'M', '輪'), + (0xF9D8, 'M', '律'), + (0xF9D9, 'M', '慄'), + (0xF9DA, 'M', '栗'), + (0xF9DB, 'M', '率'), + (0xF9DC, 'M', '隆'), + (0xF9DD, 'M', '利'), + (0xF9DE, 'M', '吏'), + (0xF9DF, 'M', '履'), + (0xF9E0, 'M', '易'), + (0xF9E1, 'M', '李'), + (0xF9E2, 'M', '梨'), + (0xF9E3, 'M', '泥'), + (0xF9E4, 'M', '理'), + (0xF9E5, 'M', '痢'), + (0xF9E6, 'M', '罹'), + (0xF9E7, 'M', '裏'), + (0xF9E8, 'M', '裡'), + (0xF9E9, 'M', '里'), + (0xF9EA, 'M', '離'), + (0xF9EB, 'M', '匿'), + (0xF9EC, 'M', '溺'), + (0xF9ED, 'M', '吝'), + (0xF9EE, 'M', '燐'), + (0xF9EF, 'M', '璘'), + (0xF9F0, 'M', '藺'), + (0xF9F1, 'M', '隣'), + (0xF9F2, 'M', '鱗'), + (0xF9F3, 'M', '麟'), + (0xF9F4, 'M', '林'), + (0xF9F5, 'M', '淋'), + (0xF9F6, 'M', '臨'), + (0xF9F7, 'M', '立'), + (0xF9F8, 'M', '笠'), + (0xF9F9, 'M', '粒'), + (0xF9FA, 'M', '狀'), + (0xF9FB, 'M', '炙'), + (0xF9FC, 'M', '識'), + (0xF9FD, 'M', '什'), + (0xF9FE, 'M', '茶'), + (0xF9FF, 'M', '刺'), + (0xFA00, 'M', '切'), + (0xFA01, 'M', '度'), + (0xFA02, 'M', '拓'), + (0xFA03, 'M', '糖'), + (0xFA04, 'M', '宅'), + (0xFA05, 'M', '洞'), + (0xFA06, 'M', '暴'), + (0xFA07, 'M', '輻'), + (0xFA08, 'M', '行'), + (0xFA09, 'M', '降'), + (0xFA0A, 'M', '見'), + (0xFA0B, 'M', '廓'), + (0xFA0C, 'M', '兀'), + (0xFA0D, 'M', '嗀'), + (0xFA0E, 'V'), + (0xFA10, 'M', '塚'), + (0xFA11, 'V'), + (0xFA12, 'M', '晴'), + ] + +def _seg_42() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFA13, 'V'), + (0xFA15, 'M', '凞'), + (0xFA16, 'M', '猪'), + (0xFA17, 'M', '益'), + (0xFA18, 'M', '礼'), + (0xFA19, 'M', '神'), + (0xFA1A, 'M', '祥'), + (0xFA1B, 'M', '福'), + (0xFA1C, 'M', '靖'), + (0xFA1D, 'M', '精'), + (0xFA1E, 'M', '羽'), + (0xFA1F, 'V'), + (0xFA20, 'M', '蘒'), + (0xFA21, 'V'), + (0xFA22, 'M', '諸'), + (0xFA23, 'V'), + (0xFA25, 'M', '逸'), + (0xFA26, 'M', '都'), + (0xFA27, 'V'), + (0xFA2A, 'M', '飯'), + (0xFA2B, 'M', '飼'), + (0xFA2C, 'M', '館'), + (0xFA2D, 'M', '鶴'), + (0xFA2E, 'M', '郞'), + (0xFA2F, 'M', '隷'), + (0xFA30, 'M', '侮'), + (0xFA31, 'M', '僧'), + (0xFA32, 'M', '免'), + (0xFA33, 'M', '勉'), + (0xFA34, 'M', '勤'), + (0xFA35, 'M', '卑'), + (0xFA36, 'M', '喝'), + (0xFA37, 'M', '嘆'), + (0xFA38, 'M', '器'), + (0xFA39, 'M', '塀'), + (0xFA3A, 'M', '墨'), + (0xFA3B, 'M', '層'), + (0xFA3C, 'M', '屮'), + (0xFA3D, 'M', '悔'), + (0xFA3E, 'M', '慨'), + (0xFA3F, 'M', '憎'), + (0xFA40, 'M', '懲'), + (0xFA41, 'M', '敏'), + (0xFA42, 'M', '既'), + (0xFA43, 'M', '暑'), + (0xFA44, 'M', '梅'), + (0xFA45, 'M', '海'), + (0xFA46, 'M', '渚'), + (0xFA47, 'M', '漢'), + (0xFA48, 'M', '煮'), + (0xFA49, 'M', '爫'), + (0xFA4A, 'M', '琢'), + (0xFA4B, 'M', '碑'), + (0xFA4C, 'M', '社'), + (0xFA4D, 'M', '祉'), + (0xFA4E, 'M', '祈'), + (0xFA4F, 'M', '祐'), + (0xFA50, 'M', '祖'), + (0xFA51, 'M', '祝'), + (0xFA52, 'M', '禍'), + (0xFA53, 'M', '禎'), + (0xFA54, 'M', '穀'), + (0xFA55, 'M', '突'), + (0xFA56, 'M', '節'), + (0xFA57, 'M', '練'), + (0xFA58, 'M', '縉'), + (0xFA59, 'M', '繁'), + (0xFA5A, 'M', '署'), + (0xFA5B, 'M', '者'), + (0xFA5C, 'M', '臭'), + (0xFA5D, 'M', '艹'), + (0xFA5F, 'M', '著'), + (0xFA60, 'M', '褐'), + (0xFA61, 'M', '視'), + (0xFA62, 'M', '謁'), + (0xFA63, 'M', '謹'), + (0xFA64, 'M', '賓'), + (0xFA65, 'M', '贈'), + (0xFA66, 'M', '辶'), + (0xFA67, 'M', '逸'), + (0xFA68, 'M', '難'), + (0xFA69, 'M', '響'), + (0xFA6A, 'M', '頻'), + (0xFA6B, 'M', '恵'), + (0xFA6C, 'M', '𤋮'), + (0xFA6D, 'M', '舘'), + (0xFA6E, 'X'), + (0xFA70, 'M', '並'), + (0xFA71, 'M', '况'), + (0xFA72, 'M', '全'), + (0xFA73, 'M', '侀'), + (0xFA74, 'M', '充'), + (0xFA75, 'M', '冀'), + (0xFA76, 'M', '勇'), + (0xFA77, 'M', '勺'), + (0xFA78, 'M', '喝'), + (0xFA79, 'M', '啕'), + (0xFA7A, 'M', '喙'), + (0xFA7B, 'M', '嗢'), + (0xFA7C, 'M', '塚'), + ] + +def _seg_43() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFA7D, 'M', '墳'), + (0xFA7E, 'M', '奄'), + (0xFA7F, 'M', '奔'), + (0xFA80, 'M', '婢'), + (0xFA81, 'M', '嬨'), + (0xFA82, 'M', '廒'), + (0xFA83, 'M', '廙'), + (0xFA84, 'M', '彩'), + (0xFA85, 'M', '徭'), + (0xFA86, 'M', '惘'), + (0xFA87, 'M', '慎'), + (0xFA88, 'M', '愈'), + (0xFA89, 'M', '憎'), + (0xFA8A, 'M', '慠'), + (0xFA8B, 'M', '懲'), + (0xFA8C, 'M', '戴'), + (0xFA8D, 'M', '揄'), + (0xFA8E, 'M', '搜'), + (0xFA8F, 'M', '摒'), + (0xFA90, 'M', '敖'), + (0xFA91, 'M', '晴'), + (0xFA92, 'M', '朗'), + (0xFA93, 'M', '望'), + (0xFA94, 'M', '杖'), + (0xFA95, 'M', '歹'), + (0xFA96, 'M', '殺'), + (0xFA97, 'M', '流'), + (0xFA98, 'M', '滛'), + (0xFA99, 'M', '滋'), + (0xFA9A, 'M', '漢'), + (0xFA9B, 'M', '瀞'), + (0xFA9C, 'M', '煮'), + (0xFA9D, 'M', '瞧'), + (0xFA9E, 'M', '爵'), + (0xFA9F, 'M', '犯'), + (0xFAA0, 'M', '猪'), + (0xFAA1, 'M', '瑱'), + (0xFAA2, 'M', '甆'), + (0xFAA3, 'M', '画'), + (0xFAA4, 'M', '瘝'), + (0xFAA5, 'M', '瘟'), + (0xFAA6, 'M', '益'), + (0xFAA7, 'M', '盛'), + (0xFAA8, 'M', '直'), + (0xFAA9, 'M', '睊'), + (0xFAAA, 'M', '着'), + (0xFAAB, 'M', '磌'), + (0xFAAC, 'M', '窱'), + (0xFAAD, 'M', '節'), + (0xFAAE, 'M', '类'), + (0xFAAF, 'M', '絛'), + (0xFAB0, 'M', '練'), + (0xFAB1, 'M', '缾'), + (0xFAB2, 'M', '者'), + (0xFAB3, 'M', '荒'), + (0xFAB4, 'M', '華'), + (0xFAB5, 'M', '蝹'), + (0xFAB6, 'M', '襁'), + (0xFAB7, 'M', '覆'), + (0xFAB8, 'M', '視'), + (0xFAB9, 'M', '調'), + (0xFABA, 'M', '諸'), + (0xFABB, 'M', '請'), + (0xFABC, 'M', '謁'), + (0xFABD, 'M', '諾'), + (0xFABE, 'M', '諭'), + (0xFABF, 'M', '謹'), + (0xFAC0, 'M', '變'), + (0xFAC1, 'M', '贈'), + (0xFAC2, 'M', '輸'), + (0xFAC3, 'M', '遲'), + (0xFAC4, 'M', '醙'), + (0xFAC5, 'M', '鉶'), + (0xFAC6, 'M', '陼'), + (0xFAC7, 'M', '難'), + (0xFAC8, 'M', '靖'), + (0xFAC9, 'M', '韛'), + (0xFACA, 'M', '響'), + (0xFACB, 'M', '頋'), + (0xFACC, 'M', '頻'), + (0xFACD, 'M', '鬒'), + (0xFACE, 'M', '龜'), + (0xFACF, 'M', '𢡊'), + (0xFAD0, 'M', '𢡄'), + (0xFAD1, 'M', '𣏕'), + (0xFAD2, 'M', '㮝'), + (0xFAD3, 'M', '䀘'), + (0xFAD4, 'M', '䀹'), + (0xFAD5, 'M', '𥉉'), + (0xFAD6, 'M', '𥳐'), + (0xFAD7, 'M', '𧻓'), + (0xFAD8, 'M', '齃'), + (0xFAD9, 'M', '龎'), + (0xFADA, 'X'), + (0xFB00, 'M', 'ff'), + (0xFB01, 'M', 'fi'), + (0xFB02, 'M', 'fl'), + (0xFB03, 'M', 'ffi'), + (0xFB04, 'M', 'ffl'), + (0xFB05, 'M', 'st'), + ] + +def _seg_44() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFB07, 'X'), + (0xFB13, 'M', 'մն'), + (0xFB14, 'M', 'մե'), + (0xFB15, 'M', 'մի'), + (0xFB16, 'M', 'վն'), + (0xFB17, 'M', 'մխ'), + (0xFB18, 'X'), + (0xFB1D, 'M', 'יִ'), + (0xFB1E, 'V'), + (0xFB1F, 'M', 'ײַ'), + (0xFB20, 'M', 'ע'), + (0xFB21, 'M', 'א'), + (0xFB22, 'M', 'ד'), + (0xFB23, 'M', 'ה'), + (0xFB24, 'M', 'כ'), + (0xFB25, 'M', 'ל'), + (0xFB26, 'M', 'ם'), + (0xFB27, 'M', 'ר'), + (0xFB28, 'M', 'ת'), + (0xFB29, '3', '+'), + (0xFB2A, 'M', 'שׁ'), + (0xFB2B, 'M', 'שׂ'), + (0xFB2C, 'M', 'שּׁ'), + (0xFB2D, 'M', 'שּׂ'), + (0xFB2E, 'M', 'אַ'), + (0xFB2F, 'M', 'אָ'), + (0xFB30, 'M', 'אּ'), + (0xFB31, 'M', 'בּ'), + (0xFB32, 'M', 'גּ'), + (0xFB33, 'M', 'דּ'), + (0xFB34, 'M', 'הּ'), + (0xFB35, 'M', 'וּ'), + (0xFB36, 'M', 'זּ'), + (0xFB37, 'X'), + (0xFB38, 'M', 'טּ'), + (0xFB39, 'M', 'יּ'), + (0xFB3A, 'M', 'ךּ'), + (0xFB3B, 'M', 'כּ'), + (0xFB3C, 'M', 'לּ'), + (0xFB3D, 'X'), + (0xFB3E, 'M', 'מּ'), + (0xFB3F, 'X'), + (0xFB40, 'M', 'נּ'), + (0xFB41, 'M', 'סּ'), + (0xFB42, 'X'), + (0xFB43, 'M', 'ףּ'), + (0xFB44, 'M', 'פּ'), + (0xFB45, 'X'), + (0xFB46, 'M', 'צּ'), + (0xFB47, 'M', 'קּ'), + (0xFB48, 'M', 'רּ'), + (0xFB49, 'M', 'שּ'), + (0xFB4A, 'M', 'תּ'), + (0xFB4B, 'M', 'וֹ'), + (0xFB4C, 'M', 'בֿ'), + (0xFB4D, 'M', 'כֿ'), + (0xFB4E, 'M', 'פֿ'), + (0xFB4F, 'M', 'אל'), + (0xFB50, 'M', 'ٱ'), + (0xFB52, 'M', 'ٻ'), + (0xFB56, 'M', 'پ'), + (0xFB5A, 'M', 'ڀ'), + (0xFB5E, 'M', 'ٺ'), + (0xFB62, 'M', 'ٿ'), + (0xFB66, 'M', 'ٹ'), + (0xFB6A, 'M', 'ڤ'), + (0xFB6E, 'M', 'ڦ'), + (0xFB72, 'M', 'ڄ'), + (0xFB76, 'M', 'ڃ'), + (0xFB7A, 'M', 'چ'), + (0xFB7E, 'M', 'ڇ'), + (0xFB82, 'M', 'ڍ'), + (0xFB84, 'M', 'ڌ'), + (0xFB86, 'M', 'ڎ'), + (0xFB88, 'M', 'ڈ'), + (0xFB8A, 'M', 'ژ'), + (0xFB8C, 'M', 'ڑ'), + (0xFB8E, 'M', 'ک'), + (0xFB92, 'M', 'گ'), + (0xFB96, 'M', 'ڳ'), + (0xFB9A, 'M', 'ڱ'), + (0xFB9E, 'M', 'ں'), + (0xFBA0, 'M', 'ڻ'), + (0xFBA4, 'M', 'ۀ'), + (0xFBA6, 'M', 'ہ'), + (0xFBAA, 'M', 'ھ'), + (0xFBAE, 'M', 'ے'), + (0xFBB0, 'M', 'ۓ'), + (0xFBB2, 'V'), + (0xFBC3, 'X'), + (0xFBD3, 'M', 'ڭ'), + (0xFBD7, 'M', 'ۇ'), + (0xFBD9, 'M', 'ۆ'), + (0xFBDB, 'M', 'ۈ'), + (0xFBDD, 'M', 'ۇٴ'), + (0xFBDE, 'M', 'ۋ'), + (0xFBE0, 'M', 'ۅ'), + (0xFBE2, 'M', 'ۉ'), + (0xFBE4, 'M', 'ې'), + (0xFBE8, 'M', 'ى'), + ] + +def _seg_45() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFBEA, 'M', 'ئا'), + (0xFBEC, 'M', 'ئە'), + (0xFBEE, 'M', 'ئو'), + (0xFBF0, 'M', 'ئۇ'), + (0xFBF2, 'M', 'ئۆ'), + (0xFBF4, 'M', 'ئۈ'), + (0xFBF6, 'M', 'ئې'), + (0xFBF9, 'M', 'ئى'), + (0xFBFC, 'M', 'ی'), + (0xFC00, 'M', 'ئج'), + (0xFC01, 'M', 'ئح'), + (0xFC02, 'M', 'ئم'), + (0xFC03, 'M', 'ئى'), + (0xFC04, 'M', 'ئي'), + (0xFC05, 'M', 'بج'), + (0xFC06, 'M', 'بح'), + (0xFC07, 'M', 'بخ'), + (0xFC08, 'M', 'بم'), + (0xFC09, 'M', 'بى'), + (0xFC0A, 'M', 'بي'), + (0xFC0B, 'M', 'تج'), + (0xFC0C, 'M', 'تح'), + (0xFC0D, 'M', 'تخ'), + (0xFC0E, 'M', 'تم'), + (0xFC0F, 'M', 'تى'), + (0xFC10, 'M', 'تي'), + (0xFC11, 'M', 'ثج'), + (0xFC12, 'M', 'ثم'), + (0xFC13, 'M', 'ثى'), + (0xFC14, 'M', 'ثي'), + (0xFC15, 'M', 'جح'), + (0xFC16, 'M', 'جم'), + (0xFC17, 'M', 'حج'), + (0xFC18, 'M', 'حم'), + (0xFC19, 'M', 'خج'), + (0xFC1A, 'M', 'خح'), + (0xFC1B, 'M', 'خم'), + (0xFC1C, 'M', 'سج'), + (0xFC1D, 'M', 'سح'), + (0xFC1E, 'M', 'سخ'), + (0xFC1F, 'M', 'سم'), + (0xFC20, 'M', 'صح'), + (0xFC21, 'M', 'صم'), + (0xFC22, 'M', 'ضج'), + (0xFC23, 'M', 'ضح'), + (0xFC24, 'M', 'ضخ'), + (0xFC25, 'M', 'ضم'), + (0xFC26, 'M', 'طح'), + (0xFC27, 'M', 'طم'), + (0xFC28, 'M', 'ظم'), + (0xFC29, 'M', 'عج'), + (0xFC2A, 'M', 'عم'), + (0xFC2B, 'M', 'غج'), + (0xFC2C, 'M', 'غم'), + (0xFC2D, 'M', 'فج'), + (0xFC2E, 'M', 'فح'), + (0xFC2F, 'M', 'فخ'), + (0xFC30, 'M', 'فم'), + (0xFC31, 'M', 'فى'), + (0xFC32, 'M', 'في'), + (0xFC33, 'M', 'قح'), + (0xFC34, 'M', 'قم'), + (0xFC35, 'M', 'قى'), + (0xFC36, 'M', 'قي'), + (0xFC37, 'M', 'كا'), + (0xFC38, 'M', 'كج'), + (0xFC39, 'M', 'كح'), + (0xFC3A, 'M', 'كخ'), + (0xFC3B, 'M', 'كل'), + (0xFC3C, 'M', 'كم'), + (0xFC3D, 'M', 'كى'), + (0xFC3E, 'M', 'كي'), + (0xFC3F, 'M', 'لج'), + (0xFC40, 'M', 'لح'), + (0xFC41, 'M', 'لخ'), + (0xFC42, 'M', 'لم'), + (0xFC43, 'M', 'لى'), + (0xFC44, 'M', 'لي'), + (0xFC45, 'M', 'مج'), + (0xFC46, 'M', 'مح'), + (0xFC47, 'M', 'مخ'), + (0xFC48, 'M', 'مم'), + (0xFC49, 'M', 'مى'), + (0xFC4A, 'M', 'مي'), + (0xFC4B, 'M', 'نج'), + (0xFC4C, 'M', 'نح'), + (0xFC4D, 'M', 'نخ'), + (0xFC4E, 'M', 'نم'), + (0xFC4F, 'M', 'نى'), + (0xFC50, 'M', 'ني'), + (0xFC51, 'M', 'هج'), + (0xFC52, 'M', 'هم'), + (0xFC53, 'M', 'هى'), + (0xFC54, 'M', 'هي'), + (0xFC55, 'M', 'يج'), + (0xFC56, 'M', 'يح'), + (0xFC57, 'M', 'يخ'), + (0xFC58, 'M', 'يم'), + (0xFC59, 'M', 'يى'), + (0xFC5A, 'M', 'يي'), + ] + +def _seg_46() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFC5B, 'M', 'ذٰ'), + (0xFC5C, 'M', 'رٰ'), + (0xFC5D, 'M', 'ىٰ'), + (0xFC5E, '3', ' ٌّ'), + (0xFC5F, '3', ' ٍّ'), + (0xFC60, '3', ' َّ'), + (0xFC61, '3', ' ُّ'), + (0xFC62, '3', ' ِّ'), + (0xFC63, '3', ' ّٰ'), + (0xFC64, 'M', 'ئر'), + (0xFC65, 'M', 'ئز'), + (0xFC66, 'M', 'ئم'), + (0xFC67, 'M', 'ئن'), + (0xFC68, 'M', 'ئى'), + (0xFC69, 'M', 'ئي'), + (0xFC6A, 'M', 'بر'), + (0xFC6B, 'M', 'بز'), + (0xFC6C, 'M', 'بم'), + (0xFC6D, 'M', 'بن'), + (0xFC6E, 'M', 'بى'), + (0xFC6F, 'M', 'بي'), + (0xFC70, 'M', 'تر'), + (0xFC71, 'M', 'تز'), + (0xFC72, 'M', 'تم'), + (0xFC73, 'M', 'تن'), + (0xFC74, 'M', 'تى'), + (0xFC75, 'M', 'تي'), + (0xFC76, 'M', 'ثر'), + (0xFC77, 'M', 'ثز'), + (0xFC78, 'M', 'ثم'), + (0xFC79, 'M', 'ثن'), + (0xFC7A, 'M', 'ثى'), + (0xFC7B, 'M', 'ثي'), + (0xFC7C, 'M', 'فى'), + (0xFC7D, 'M', 'في'), + (0xFC7E, 'M', 'قى'), + (0xFC7F, 'M', 'قي'), + (0xFC80, 'M', 'كا'), + (0xFC81, 'M', 'كل'), + (0xFC82, 'M', 'كم'), + (0xFC83, 'M', 'كى'), + (0xFC84, 'M', 'كي'), + (0xFC85, 'M', 'لم'), + (0xFC86, 'M', 'لى'), + (0xFC87, 'M', 'لي'), + (0xFC88, 'M', 'ما'), + (0xFC89, 'M', 'مم'), + (0xFC8A, 'M', 'نر'), + (0xFC8B, 'M', 'نز'), + (0xFC8C, 'M', 'نم'), + (0xFC8D, 'M', 'نن'), + (0xFC8E, 'M', 'نى'), + (0xFC8F, 'M', 'ني'), + (0xFC90, 'M', 'ىٰ'), + (0xFC91, 'M', 'ير'), + (0xFC92, 'M', 'يز'), + (0xFC93, 'M', 'يم'), + (0xFC94, 'M', 'ين'), + (0xFC95, 'M', 'يى'), + (0xFC96, 'M', 'يي'), + (0xFC97, 'M', 'ئج'), + (0xFC98, 'M', 'ئح'), + (0xFC99, 'M', 'ئخ'), + (0xFC9A, 'M', 'ئم'), + (0xFC9B, 'M', 'ئه'), + (0xFC9C, 'M', 'بج'), + (0xFC9D, 'M', 'بح'), + (0xFC9E, 'M', 'بخ'), + (0xFC9F, 'M', 'بم'), + (0xFCA0, 'M', 'به'), + (0xFCA1, 'M', 'تج'), + (0xFCA2, 'M', 'تح'), + (0xFCA3, 'M', 'تخ'), + (0xFCA4, 'M', 'تم'), + (0xFCA5, 'M', 'ته'), + (0xFCA6, 'M', 'ثم'), + (0xFCA7, 'M', 'جح'), + (0xFCA8, 'M', 'جم'), + (0xFCA9, 'M', 'حج'), + (0xFCAA, 'M', 'حم'), + (0xFCAB, 'M', 'خج'), + (0xFCAC, 'M', 'خم'), + (0xFCAD, 'M', 'سج'), + (0xFCAE, 'M', 'سح'), + (0xFCAF, 'M', 'سخ'), + (0xFCB0, 'M', 'سم'), + (0xFCB1, 'M', 'صح'), + (0xFCB2, 'M', 'صخ'), + (0xFCB3, 'M', 'صم'), + (0xFCB4, 'M', 'ضج'), + (0xFCB5, 'M', 'ضح'), + (0xFCB6, 'M', 'ضخ'), + (0xFCB7, 'M', 'ضم'), + (0xFCB8, 'M', 'طح'), + (0xFCB9, 'M', 'ظم'), + (0xFCBA, 'M', 'عج'), + (0xFCBB, 'M', 'عم'), + (0xFCBC, 'M', 'غج'), + (0xFCBD, 'M', 'غم'), + (0xFCBE, 'M', 'فج'), + ] + +def _seg_47() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFCBF, 'M', 'فح'), + (0xFCC0, 'M', 'فخ'), + (0xFCC1, 'M', 'فم'), + (0xFCC2, 'M', 'قح'), + (0xFCC3, 'M', 'قم'), + (0xFCC4, 'M', 'كج'), + (0xFCC5, 'M', 'كح'), + (0xFCC6, 'M', 'كخ'), + (0xFCC7, 'M', 'كل'), + (0xFCC8, 'M', 'كم'), + (0xFCC9, 'M', 'لج'), + (0xFCCA, 'M', 'لح'), + (0xFCCB, 'M', 'لخ'), + (0xFCCC, 'M', 'لم'), + (0xFCCD, 'M', 'له'), + (0xFCCE, 'M', 'مج'), + (0xFCCF, 'M', 'مح'), + (0xFCD0, 'M', 'مخ'), + (0xFCD1, 'M', 'مم'), + (0xFCD2, 'M', 'نج'), + (0xFCD3, 'M', 'نح'), + (0xFCD4, 'M', 'نخ'), + (0xFCD5, 'M', 'نم'), + (0xFCD6, 'M', 'نه'), + (0xFCD7, 'M', 'هج'), + (0xFCD8, 'M', 'هم'), + (0xFCD9, 'M', 'هٰ'), + (0xFCDA, 'M', 'يج'), + (0xFCDB, 'M', 'يح'), + (0xFCDC, 'M', 'يخ'), + (0xFCDD, 'M', 'يم'), + (0xFCDE, 'M', 'يه'), + (0xFCDF, 'M', 'ئم'), + (0xFCE0, 'M', 'ئه'), + (0xFCE1, 'M', 'بم'), + (0xFCE2, 'M', 'به'), + (0xFCE3, 'M', 'تم'), + (0xFCE4, 'M', 'ته'), + (0xFCE5, 'M', 'ثم'), + (0xFCE6, 'M', 'ثه'), + (0xFCE7, 'M', 'سم'), + (0xFCE8, 'M', 'سه'), + (0xFCE9, 'M', 'شم'), + (0xFCEA, 'M', 'شه'), + (0xFCEB, 'M', 'كل'), + (0xFCEC, 'M', 'كم'), + (0xFCED, 'M', 'لم'), + (0xFCEE, 'M', 'نم'), + (0xFCEF, 'M', 'نه'), + (0xFCF0, 'M', 'يم'), + (0xFCF1, 'M', 'يه'), + (0xFCF2, 'M', 'ـَّ'), + (0xFCF3, 'M', 'ـُّ'), + (0xFCF4, 'M', 'ـِّ'), + (0xFCF5, 'M', 'طى'), + (0xFCF6, 'M', 'طي'), + (0xFCF7, 'M', 'عى'), + (0xFCF8, 'M', 'عي'), + (0xFCF9, 'M', 'غى'), + (0xFCFA, 'M', 'غي'), + (0xFCFB, 'M', 'سى'), + (0xFCFC, 'M', 'سي'), + (0xFCFD, 'M', 'شى'), + (0xFCFE, 'M', 'شي'), + (0xFCFF, 'M', 'حى'), + (0xFD00, 'M', 'حي'), + (0xFD01, 'M', 'جى'), + (0xFD02, 'M', 'جي'), + (0xFD03, 'M', 'خى'), + (0xFD04, 'M', 'خي'), + (0xFD05, 'M', 'صى'), + (0xFD06, 'M', 'صي'), + (0xFD07, 'M', 'ضى'), + (0xFD08, 'M', 'ضي'), + (0xFD09, 'M', 'شج'), + (0xFD0A, 'M', 'شح'), + (0xFD0B, 'M', 'شخ'), + (0xFD0C, 'M', 'شم'), + (0xFD0D, 'M', 'شر'), + (0xFD0E, 'M', 'سر'), + (0xFD0F, 'M', 'صر'), + (0xFD10, 'M', 'ضر'), + (0xFD11, 'M', 'طى'), + (0xFD12, 'M', 'طي'), + (0xFD13, 'M', 'عى'), + (0xFD14, 'M', 'عي'), + (0xFD15, 'M', 'غى'), + (0xFD16, 'M', 'غي'), + (0xFD17, 'M', 'سى'), + (0xFD18, 'M', 'سي'), + (0xFD19, 'M', 'شى'), + (0xFD1A, 'M', 'شي'), + (0xFD1B, 'M', 'حى'), + (0xFD1C, 'M', 'حي'), + (0xFD1D, 'M', 'جى'), + (0xFD1E, 'M', 'جي'), + (0xFD1F, 'M', 'خى'), + (0xFD20, 'M', 'خي'), + (0xFD21, 'M', 'صى'), + (0xFD22, 'M', 'صي'), + ] + +def _seg_48() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFD23, 'M', 'ضى'), + (0xFD24, 'M', 'ضي'), + (0xFD25, 'M', 'شج'), + (0xFD26, 'M', 'شح'), + (0xFD27, 'M', 'شخ'), + (0xFD28, 'M', 'شم'), + (0xFD29, 'M', 'شر'), + (0xFD2A, 'M', 'سر'), + (0xFD2B, 'M', 'صر'), + (0xFD2C, 'M', 'ضر'), + (0xFD2D, 'M', 'شج'), + (0xFD2E, 'M', 'شح'), + (0xFD2F, 'M', 'شخ'), + (0xFD30, 'M', 'شم'), + (0xFD31, 'M', 'سه'), + (0xFD32, 'M', 'شه'), + (0xFD33, 'M', 'طم'), + (0xFD34, 'M', 'سج'), + (0xFD35, 'M', 'سح'), + (0xFD36, 'M', 'سخ'), + (0xFD37, 'M', 'شج'), + (0xFD38, 'M', 'شح'), + (0xFD39, 'M', 'شخ'), + (0xFD3A, 'M', 'طم'), + (0xFD3B, 'M', 'ظم'), + (0xFD3C, 'M', 'اً'), + (0xFD3E, 'V'), + (0xFD50, 'M', 'تجم'), + (0xFD51, 'M', 'تحج'), + (0xFD53, 'M', 'تحم'), + (0xFD54, 'M', 'تخم'), + (0xFD55, 'M', 'تمج'), + (0xFD56, 'M', 'تمح'), + (0xFD57, 'M', 'تمخ'), + (0xFD58, 'M', 'جمح'), + (0xFD5A, 'M', 'حمي'), + (0xFD5B, 'M', 'حمى'), + (0xFD5C, 'M', 'سحج'), + (0xFD5D, 'M', 'سجح'), + (0xFD5E, 'M', 'سجى'), + (0xFD5F, 'M', 'سمح'), + (0xFD61, 'M', 'سمج'), + (0xFD62, 'M', 'سمم'), + (0xFD64, 'M', 'صحح'), + (0xFD66, 'M', 'صمم'), + (0xFD67, 'M', 'شحم'), + (0xFD69, 'M', 'شجي'), + (0xFD6A, 'M', 'شمخ'), + (0xFD6C, 'M', 'شمم'), + (0xFD6E, 'M', 'ضحى'), + (0xFD6F, 'M', 'ضخم'), + (0xFD71, 'M', 'طمح'), + (0xFD73, 'M', 'طمم'), + (0xFD74, 'M', 'طمي'), + (0xFD75, 'M', 'عجم'), + (0xFD76, 'M', 'عمم'), + (0xFD78, 'M', 'عمى'), + (0xFD79, 'M', 'غمم'), + (0xFD7A, 'M', 'غمي'), + (0xFD7B, 'M', 'غمى'), + (0xFD7C, 'M', 'فخم'), + (0xFD7E, 'M', 'قمح'), + (0xFD7F, 'M', 'قمم'), + (0xFD80, 'M', 'لحم'), + (0xFD81, 'M', 'لحي'), + (0xFD82, 'M', 'لحى'), + (0xFD83, 'M', 'لجج'), + (0xFD85, 'M', 'لخم'), + (0xFD87, 'M', 'لمح'), + (0xFD89, 'M', 'محج'), + (0xFD8A, 'M', 'محم'), + (0xFD8B, 'M', 'محي'), + (0xFD8C, 'M', 'مجح'), + (0xFD8D, 'M', 'مجم'), + (0xFD8E, 'M', 'مخج'), + (0xFD8F, 'M', 'مخم'), + (0xFD90, 'X'), + (0xFD92, 'M', 'مجخ'), + (0xFD93, 'M', 'همج'), + (0xFD94, 'M', 'همم'), + (0xFD95, 'M', 'نحم'), + (0xFD96, 'M', 'نحى'), + (0xFD97, 'M', 'نجم'), + (0xFD99, 'M', 'نجى'), + (0xFD9A, 'M', 'نمي'), + (0xFD9B, 'M', 'نمى'), + (0xFD9C, 'M', 'يمم'), + (0xFD9E, 'M', 'بخي'), + (0xFD9F, 'M', 'تجي'), + (0xFDA0, 'M', 'تجى'), + (0xFDA1, 'M', 'تخي'), + (0xFDA2, 'M', 'تخى'), + (0xFDA3, 'M', 'تمي'), + (0xFDA4, 'M', 'تمى'), + (0xFDA5, 'M', 'جمي'), + (0xFDA6, 'M', 'جحى'), + (0xFDA7, 'M', 'جمى'), + (0xFDA8, 'M', 'سخى'), + (0xFDA9, 'M', 'صحي'), + (0xFDAA, 'M', 'شحي'), + ] + +def _seg_49() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFDAB, 'M', 'ضحي'), + (0xFDAC, 'M', 'لجي'), + (0xFDAD, 'M', 'لمي'), + (0xFDAE, 'M', 'يحي'), + (0xFDAF, 'M', 'يجي'), + (0xFDB0, 'M', 'يمي'), + (0xFDB1, 'M', 'ممي'), + (0xFDB2, 'M', 'قمي'), + (0xFDB3, 'M', 'نحي'), + (0xFDB4, 'M', 'قمح'), + (0xFDB5, 'M', 'لحم'), + (0xFDB6, 'M', 'عمي'), + (0xFDB7, 'M', 'كمي'), + (0xFDB8, 'M', 'نجح'), + (0xFDB9, 'M', 'مخي'), + (0xFDBA, 'M', 'لجم'), + (0xFDBB, 'M', 'كمم'), + (0xFDBC, 'M', 'لجم'), + (0xFDBD, 'M', 'نجح'), + (0xFDBE, 'M', 'جحي'), + (0xFDBF, 'M', 'حجي'), + (0xFDC0, 'M', 'مجي'), + (0xFDC1, 'M', 'فمي'), + (0xFDC2, 'M', 'بحي'), + (0xFDC3, 'M', 'كمم'), + (0xFDC4, 'M', 'عجم'), + (0xFDC5, 'M', 'صمم'), + (0xFDC6, 'M', 'سخي'), + (0xFDC7, 'M', 'نجي'), + (0xFDC8, 'X'), + (0xFDCF, 'V'), + (0xFDD0, 'X'), + (0xFDF0, 'M', 'صلے'), + (0xFDF1, 'M', 'قلے'), + (0xFDF2, 'M', 'الله'), + (0xFDF3, 'M', 'اكبر'), + (0xFDF4, 'M', 'محمد'), + (0xFDF5, 'M', 'صلعم'), + (0xFDF6, 'M', 'رسول'), + (0xFDF7, 'M', 'عليه'), + (0xFDF8, 'M', 'وسلم'), + (0xFDF9, 'M', 'صلى'), + (0xFDFA, '3', 'صلى الله عليه وسلم'), + (0xFDFB, '3', 'جل جلاله'), + (0xFDFC, 'M', 'ریال'), + (0xFDFD, 'V'), + (0xFE00, 'I'), + (0xFE10, '3', ','), + (0xFE11, 'M', '、'), + (0xFE12, 'X'), + (0xFE13, '3', ':'), + (0xFE14, '3', ';'), + (0xFE15, '3', '!'), + (0xFE16, '3', '?'), + (0xFE17, 'M', '〖'), + (0xFE18, 'M', '〗'), + (0xFE19, 'X'), + (0xFE20, 'V'), + (0xFE30, 'X'), + (0xFE31, 'M', '—'), + (0xFE32, 'M', '–'), + (0xFE33, '3', '_'), + (0xFE35, '3', '('), + (0xFE36, '3', ')'), + (0xFE37, '3', '{'), + (0xFE38, '3', '}'), + (0xFE39, 'M', '〔'), + (0xFE3A, 'M', '〕'), + (0xFE3B, 'M', '【'), + (0xFE3C, 'M', '】'), + (0xFE3D, 'M', '《'), + (0xFE3E, 'M', '》'), + (0xFE3F, 'M', '〈'), + (0xFE40, 'M', '〉'), + (0xFE41, 'M', '「'), + (0xFE42, 'M', '」'), + (0xFE43, 'M', '『'), + (0xFE44, 'M', '』'), + (0xFE45, 'V'), + (0xFE47, '3', '['), + (0xFE48, '3', ']'), + (0xFE49, '3', ' ̅'), + (0xFE4D, '3', '_'), + (0xFE50, '3', ','), + (0xFE51, 'M', '、'), + (0xFE52, 'X'), + (0xFE54, '3', ';'), + (0xFE55, '3', ':'), + (0xFE56, '3', '?'), + (0xFE57, '3', '!'), + (0xFE58, 'M', '—'), + (0xFE59, '3', '('), + (0xFE5A, '3', ')'), + (0xFE5B, '3', '{'), + (0xFE5C, '3', '}'), + (0xFE5D, 'M', '〔'), + (0xFE5E, 'M', '〕'), + (0xFE5F, '3', '#'), + (0xFE60, '3', '&'), + (0xFE61, '3', '*'), + ] + +def _seg_50() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFE62, '3', '+'), + (0xFE63, 'M', '-'), + (0xFE64, '3', '<'), + (0xFE65, '3', '>'), + (0xFE66, '3', '='), + (0xFE67, 'X'), + (0xFE68, '3', '\\'), + (0xFE69, '3', '$'), + (0xFE6A, '3', '%'), + (0xFE6B, '3', '@'), + (0xFE6C, 'X'), + (0xFE70, '3', ' ً'), + (0xFE71, 'M', 'ـً'), + (0xFE72, '3', ' ٌ'), + (0xFE73, 'V'), + (0xFE74, '3', ' ٍ'), + (0xFE75, 'X'), + (0xFE76, '3', ' َ'), + (0xFE77, 'M', 'ـَ'), + (0xFE78, '3', ' ُ'), + (0xFE79, 'M', 'ـُ'), + (0xFE7A, '3', ' ِ'), + (0xFE7B, 'M', 'ـِ'), + (0xFE7C, '3', ' ّ'), + (0xFE7D, 'M', 'ـّ'), + (0xFE7E, '3', ' ْ'), + (0xFE7F, 'M', 'ـْ'), + (0xFE80, 'M', 'ء'), + (0xFE81, 'M', 'آ'), + (0xFE83, 'M', 'أ'), + (0xFE85, 'M', 'ؤ'), + (0xFE87, 'M', 'إ'), + (0xFE89, 'M', 'ئ'), + (0xFE8D, 'M', 'ا'), + (0xFE8F, 'M', 'ب'), + (0xFE93, 'M', 'ة'), + (0xFE95, 'M', 'ت'), + (0xFE99, 'M', 'ث'), + (0xFE9D, 'M', 'ج'), + (0xFEA1, 'M', 'ح'), + (0xFEA5, 'M', 'خ'), + (0xFEA9, 'M', 'د'), + (0xFEAB, 'M', 'ذ'), + (0xFEAD, 'M', 'ر'), + (0xFEAF, 'M', 'ز'), + (0xFEB1, 'M', 'س'), + (0xFEB5, 'M', 'ش'), + (0xFEB9, 'M', 'ص'), + (0xFEBD, 'M', 'ض'), + (0xFEC1, 'M', 'ط'), + (0xFEC5, 'M', 'ظ'), + (0xFEC9, 'M', 'ع'), + (0xFECD, 'M', 'غ'), + (0xFED1, 'M', 'ف'), + (0xFED5, 'M', 'ق'), + (0xFED9, 'M', 'ك'), + (0xFEDD, 'M', 'ل'), + (0xFEE1, 'M', 'م'), + (0xFEE5, 'M', 'ن'), + (0xFEE9, 'M', 'ه'), + (0xFEED, 'M', 'و'), + (0xFEEF, 'M', 'ى'), + (0xFEF1, 'M', 'ي'), + (0xFEF5, 'M', 'لآ'), + (0xFEF7, 'M', 'لأ'), + (0xFEF9, 'M', 'لإ'), + (0xFEFB, 'M', 'لا'), + (0xFEFD, 'X'), + (0xFEFF, 'I'), + (0xFF00, 'X'), + (0xFF01, '3', '!'), + (0xFF02, '3', '"'), + (0xFF03, '3', '#'), + (0xFF04, '3', '$'), + (0xFF05, '3', '%'), + (0xFF06, '3', '&'), + (0xFF07, '3', '\''), + (0xFF08, '3', '('), + (0xFF09, '3', ')'), + (0xFF0A, '3', '*'), + (0xFF0B, '3', '+'), + (0xFF0C, '3', ','), + (0xFF0D, 'M', '-'), + (0xFF0E, 'M', '.'), + (0xFF0F, '3', '/'), + (0xFF10, 'M', '0'), + (0xFF11, 'M', '1'), + (0xFF12, 'M', '2'), + (0xFF13, 'M', '3'), + (0xFF14, 'M', '4'), + (0xFF15, 'M', '5'), + (0xFF16, 'M', '6'), + (0xFF17, 'M', '7'), + (0xFF18, 'M', '8'), + (0xFF19, 'M', '9'), + (0xFF1A, '3', ':'), + (0xFF1B, '3', ';'), + (0xFF1C, '3', '<'), + (0xFF1D, '3', '='), + (0xFF1E, '3', '>'), + ] + +def _seg_51() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFF1F, '3', '?'), + (0xFF20, '3', '@'), + (0xFF21, 'M', 'a'), + (0xFF22, 'M', 'b'), + (0xFF23, 'M', 'c'), + (0xFF24, 'M', 'd'), + (0xFF25, 'M', 'e'), + (0xFF26, 'M', 'f'), + (0xFF27, 'M', 'g'), + (0xFF28, 'M', 'h'), + (0xFF29, 'M', 'i'), + (0xFF2A, 'M', 'j'), + (0xFF2B, 'M', 'k'), + (0xFF2C, 'M', 'l'), + (0xFF2D, 'M', 'm'), + (0xFF2E, 'M', 'n'), + (0xFF2F, 'M', 'o'), + (0xFF30, 'M', 'p'), + (0xFF31, 'M', 'q'), + (0xFF32, 'M', 'r'), + (0xFF33, 'M', 's'), + (0xFF34, 'M', 't'), + (0xFF35, 'M', 'u'), + (0xFF36, 'M', 'v'), + (0xFF37, 'M', 'w'), + (0xFF38, 'M', 'x'), + (0xFF39, 'M', 'y'), + (0xFF3A, 'M', 'z'), + (0xFF3B, '3', '['), + (0xFF3C, '3', '\\'), + (0xFF3D, '3', ']'), + (0xFF3E, '3', '^'), + (0xFF3F, '3', '_'), + (0xFF40, '3', '`'), + (0xFF41, 'M', 'a'), + (0xFF42, 'M', 'b'), + (0xFF43, 'M', 'c'), + (0xFF44, 'M', 'd'), + (0xFF45, 'M', 'e'), + (0xFF46, 'M', 'f'), + (0xFF47, 'M', 'g'), + (0xFF48, 'M', 'h'), + (0xFF49, 'M', 'i'), + (0xFF4A, 'M', 'j'), + (0xFF4B, 'M', 'k'), + (0xFF4C, 'M', 'l'), + (0xFF4D, 'M', 'm'), + (0xFF4E, 'M', 'n'), + (0xFF4F, 'M', 'o'), + (0xFF50, 'M', 'p'), + (0xFF51, 'M', 'q'), + (0xFF52, 'M', 'r'), + (0xFF53, 'M', 's'), + (0xFF54, 'M', 't'), + (0xFF55, 'M', 'u'), + (0xFF56, 'M', 'v'), + (0xFF57, 'M', 'w'), + (0xFF58, 'M', 'x'), + (0xFF59, 'M', 'y'), + (0xFF5A, 'M', 'z'), + (0xFF5B, '3', '{'), + (0xFF5C, '3', '|'), + (0xFF5D, '3', '}'), + (0xFF5E, '3', '~'), + (0xFF5F, 'M', '⦅'), + (0xFF60, 'M', '⦆'), + (0xFF61, 'M', '.'), + (0xFF62, 'M', '「'), + (0xFF63, 'M', '」'), + (0xFF64, 'M', '、'), + (0xFF65, 'M', '・'), + (0xFF66, 'M', 'ヲ'), + (0xFF67, 'M', 'ァ'), + (0xFF68, 'M', 'ィ'), + (0xFF69, 'M', 'ゥ'), + (0xFF6A, 'M', 'ェ'), + (0xFF6B, 'M', 'ォ'), + (0xFF6C, 'M', 'ャ'), + (0xFF6D, 'M', 'ュ'), + (0xFF6E, 'M', 'ョ'), + (0xFF6F, 'M', 'ッ'), + (0xFF70, 'M', 'ー'), + (0xFF71, 'M', 'ア'), + (0xFF72, 'M', 'イ'), + (0xFF73, 'M', 'ウ'), + (0xFF74, 'M', 'エ'), + (0xFF75, 'M', 'オ'), + (0xFF76, 'M', 'カ'), + (0xFF77, 'M', 'キ'), + (0xFF78, 'M', 'ク'), + (0xFF79, 'M', 'ケ'), + (0xFF7A, 'M', 'コ'), + (0xFF7B, 'M', 'サ'), + (0xFF7C, 'M', 'シ'), + (0xFF7D, 'M', 'ス'), + (0xFF7E, 'M', 'セ'), + (0xFF7F, 'M', 'ソ'), + (0xFF80, 'M', 'タ'), + (0xFF81, 'M', 'チ'), + (0xFF82, 'M', 'ツ'), + ] + +def _seg_52() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFF83, 'M', 'テ'), + (0xFF84, 'M', 'ト'), + (0xFF85, 'M', 'ナ'), + (0xFF86, 'M', 'ニ'), + (0xFF87, 'M', 'ヌ'), + (0xFF88, 'M', 'ネ'), + (0xFF89, 'M', 'ノ'), + (0xFF8A, 'M', 'ハ'), + (0xFF8B, 'M', 'ヒ'), + (0xFF8C, 'M', 'フ'), + (0xFF8D, 'M', 'ヘ'), + (0xFF8E, 'M', 'ホ'), + (0xFF8F, 'M', 'マ'), + (0xFF90, 'M', 'ミ'), + (0xFF91, 'M', 'ム'), + (0xFF92, 'M', 'メ'), + (0xFF93, 'M', 'モ'), + (0xFF94, 'M', 'ヤ'), + (0xFF95, 'M', 'ユ'), + (0xFF96, 'M', 'ヨ'), + (0xFF97, 'M', 'ラ'), + (0xFF98, 'M', 'リ'), + (0xFF99, 'M', 'ル'), + (0xFF9A, 'M', 'レ'), + (0xFF9B, 'M', 'ロ'), + (0xFF9C, 'M', 'ワ'), + (0xFF9D, 'M', 'ン'), + (0xFF9E, 'M', '゙'), + (0xFF9F, 'M', '゚'), + (0xFFA0, 'X'), + (0xFFA1, 'M', 'ᄀ'), + (0xFFA2, 'M', 'ᄁ'), + (0xFFA3, 'M', 'ᆪ'), + (0xFFA4, 'M', 'ᄂ'), + (0xFFA5, 'M', 'ᆬ'), + (0xFFA6, 'M', 'ᆭ'), + (0xFFA7, 'M', 'ᄃ'), + (0xFFA8, 'M', 'ᄄ'), + (0xFFA9, 'M', 'ᄅ'), + (0xFFAA, 'M', 'ᆰ'), + (0xFFAB, 'M', 'ᆱ'), + (0xFFAC, 'M', 'ᆲ'), + (0xFFAD, 'M', 'ᆳ'), + (0xFFAE, 'M', 'ᆴ'), + (0xFFAF, 'M', 'ᆵ'), + (0xFFB0, 'M', 'ᄚ'), + (0xFFB1, 'M', 'ᄆ'), + (0xFFB2, 'M', 'ᄇ'), + (0xFFB3, 'M', 'ᄈ'), + (0xFFB4, 'M', 'ᄡ'), + (0xFFB5, 'M', 'ᄉ'), + (0xFFB6, 'M', 'ᄊ'), + (0xFFB7, 'M', 'ᄋ'), + (0xFFB8, 'M', 'ᄌ'), + (0xFFB9, 'M', 'ᄍ'), + (0xFFBA, 'M', 'ᄎ'), + (0xFFBB, 'M', 'ᄏ'), + (0xFFBC, 'M', 'ᄐ'), + (0xFFBD, 'M', 'ᄑ'), + (0xFFBE, 'M', 'ᄒ'), + (0xFFBF, 'X'), + (0xFFC2, 'M', 'ᅡ'), + (0xFFC3, 'M', 'ᅢ'), + (0xFFC4, 'M', 'ᅣ'), + (0xFFC5, 'M', 'ᅤ'), + (0xFFC6, 'M', 'ᅥ'), + (0xFFC7, 'M', 'ᅦ'), + (0xFFC8, 'X'), + (0xFFCA, 'M', 'ᅧ'), + (0xFFCB, 'M', 'ᅨ'), + (0xFFCC, 'M', 'ᅩ'), + (0xFFCD, 'M', 'ᅪ'), + (0xFFCE, 'M', 'ᅫ'), + (0xFFCF, 'M', 'ᅬ'), + (0xFFD0, 'X'), + (0xFFD2, 'M', 'ᅭ'), + (0xFFD3, 'M', 'ᅮ'), + (0xFFD4, 'M', 'ᅯ'), + (0xFFD5, 'M', 'ᅰ'), + (0xFFD6, 'M', 'ᅱ'), + (0xFFD7, 'M', 'ᅲ'), + (0xFFD8, 'X'), + (0xFFDA, 'M', 'ᅳ'), + (0xFFDB, 'M', 'ᅴ'), + (0xFFDC, 'M', 'ᅵ'), + (0xFFDD, 'X'), + (0xFFE0, 'M', '¢'), + (0xFFE1, 'M', '£'), + (0xFFE2, 'M', '¬'), + (0xFFE3, '3', ' ̄'), + (0xFFE4, 'M', '¦'), + (0xFFE5, 'M', '¥'), + (0xFFE6, 'M', '₩'), + (0xFFE7, 'X'), + (0xFFE8, 'M', '│'), + (0xFFE9, 'M', '←'), + (0xFFEA, 'M', '↑'), + (0xFFEB, 'M', '→'), + (0xFFEC, 'M', '↓'), + (0xFFED, 'M', '■'), + ] + +def _seg_53() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0xFFEE, 'M', '○'), + (0xFFEF, 'X'), + (0x10000, 'V'), + (0x1000C, 'X'), + (0x1000D, 'V'), + (0x10027, 'X'), + (0x10028, 'V'), + (0x1003B, 'X'), + (0x1003C, 'V'), + (0x1003E, 'X'), + (0x1003F, 'V'), + (0x1004E, 'X'), + (0x10050, 'V'), + (0x1005E, 'X'), + (0x10080, 'V'), + (0x100FB, 'X'), + (0x10100, 'V'), + (0x10103, 'X'), + (0x10107, 'V'), + (0x10134, 'X'), + (0x10137, 'V'), + (0x1018F, 'X'), + (0x10190, 'V'), + (0x1019D, 'X'), + (0x101A0, 'V'), + (0x101A1, 'X'), + (0x101D0, 'V'), + (0x101FE, 'X'), + (0x10280, 'V'), + (0x1029D, 'X'), + (0x102A0, 'V'), + (0x102D1, 'X'), + (0x102E0, 'V'), + (0x102FC, 'X'), + (0x10300, 'V'), + (0x10324, 'X'), + (0x1032D, 'V'), + (0x1034B, 'X'), + (0x10350, 'V'), + (0x1037B, 'X'), + (0x10380, 'V'), + (0x1039E, 'X'), + (0x1039F, 'V'), + (0x103C4, 'X'), + (0x103C8, 'V'), + (0x103D6, 'X'), + (0x10400, 'M', '𐐨'), + (0x10401, 'M', '𐐩'), + (0x10402, 'M', '𐐪'), + (0x10403, 'M', '𐐫'), + (0x10404, 'M', '𐐬'), + (0x10405, 'M', '𐐭'), + (0x10406, 'M', '𐐮'), + (0x10407, 'M', '𐐯'), + (0x10408, 'M', '𐐰'), + (0x10409, 'M', '𐐱'), + (0x1040A, 'M', '𐐲'), + (0x1040B, 'M', '𐐳'), + (0x1040C, 'M', '𐐴'), + (0x1040D, 'M', '𐐵'), + (0x1040E, 'M', '𐐶'), + (0x1040F, 'M', '𐐷'), + (0x10410, 'M', '𐐸'), + (0x10411, 'M', '𐐹'), + (0x10412, 'M', '𐐺'), + (0x10413, 'M', '𐐻'), + (0x10414, 'M', '𐐼'), + (0x10415, 'M', '𐐽'), + (0x10416, 'M', '𐐾'), + (0x10417, 'M', '𐐿'), + (0x10418, 'M', '𐑀'), + (0x10419, 'M', '𐑁'), + (0x1041A, 'M', '𐑂'), + (0x1041B, 'M', '𐑃'), + (0x1041C, 'M', '𐑄'), + (0x1041D, 'M', '𐑅'), + (0x1041E, 'M', '𐑆'), + (0x1041F, 'M', '𐑇'), + (0x10420, 'M', '𐑈'), + (0x10421, 'M', '𐑉'), + (0x10422, 'M', '𐑊'), + (0x10423, 'M', '𐑋'), + (0x10424, 'M', '𐑌'), + (0x10425, 'M', '𐑍'), + (0x10426, 'M', '𐑎'), + (0x10427, 'M', '𐑏'), + (0x10428, 'V'), + (0x1049E, 'X'), + (0x104A0, 'V'), + (0x104AA, 'X'), + (0x104B0, 'M', '𐓘'), + (0x104B1, 'M', '𐓙'), + (0x104B2, 'M', '𐓚'), + (0x104B3, 'M', '𐓛'), + (0x104B4, 'M', '𐓜'), + (0x104B5, 'M', '𐓝'), + (0x104B6, 'M', '𐓞'), + (0x104B7, 'M', '𐓟'), + (0x104B8, 'M', '𐓠'), + (0x104B9, 'M', '𐓡'), + ] + +def _seg_54() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x104BA, 'M', '𐓢'), + (0x104BB, 'M', '𐓣'), + (0x104BC, 'M', '𐓤'), + (0x104BD, 'M', '𐓥'), + (0x104BE, 'M', '𐓦'), + (0x104BF, 'M', '𐓧'), + (0x104C0, 'M', '𐓨'), + (0x104C1, 'M', '𐓩'), + (0x104C2, 'M', '𐓪'), + (0x104C3, 'M', '𐓫'), + (0x104C4, 'M', '𐓬'), + (0x104C5, 'M', '𐓭'), + (0x104C6, 'M', '𐓮'), + (0x104C7, 'M', '𐓯'), + (0x104C8, 'M', '𐓰'), + (0x104C9, 'M', '𐓱'), + (0x104CA, 'M', '𐓲'), + (0x104CB, 'M', '𐓳'), + (0x104CC, 'M', '𐓴'), + (0x104CD, 'M', '𐓵'), + (0x104CE, 'M', '𐓶'), + (0x104CF, 'M', '𐓷'), + (0x104D0, 'M', '𐓸'), + (0x104D1, 'M', '𐓹'), + (0x104D2, 'M', '𐓺'), + (0x104D3, 'M', '𐓻'), + (0x104D4, 'X'), + (0x104D8, 'V'), + (0x104FC, 'X'), + (0x10500, 'V'), + (0x10528, 'X'), + (0x10530, 'V'), + (0x10564, 'X'), + (0x1056F, 'V'), + (0x10570, 'M', '𐖗'), + (0x10571, 'M', '𐖘'), + (0x10572, 'M', '𐖙'), + (0x10573, 'M', '𐖚'), + (0x10574, 'M', '𐖛'), + (0x10575, 'M', '𐖜'), + (0x10576, 'M', '𐖝'), + (0x10577, 'M', '𐖞'), + (0x10578, 'M', '𐖟'), + (0x10579, 'M', '𐖠'), + (0x1057A, 'M', '𐖡'), + (0x1057B, 'X'), + (0x1057C, 'M', '𐖣'), + (0x1057D, 'M', '𐖤'), + (0x1057E, 'M', '𐖥'), + (0x1057F, 'M', '𐖦'), + (0x10580, 'M', '𐖧'), + (0x10581, 'M', '𐖨'), + (0x10582, 'M', '𐖩'), + (0x10583, 'M', '𐖪'), + (0x10584, 'M', '𐖫'), + (0x10585, 'M', '𐖬'), + (0x10586, 'M', '𐖭'), + (0x10587, 'M', '𐖮'), + (0x10588, 'M', '𐖯'), + (0x10589, 'M', '𐖰'), + (0x1058A, 'M', '𐖱'), + (0x1058B, 'X'), + (0x1058C, 'M', '𐖳'), + (0x1058D, 'M', '𐖴'), + (0x1058E, 'M', '𐖵'), + (0x1058F, 'M', '𐖶'), + (0x10590, 'M', '𐖷'), + (0x10591, 'M', '𐖸'), + (0x10592, 'M', '𐖹'), + (0x10593, 'X'), + (0x10594, 'M', '𐖻'), + (0x10595, 'M', '𐖼'), + (0x10596, 'X'), + (0x10597, 'V'), + (0x105A2, 'X'), + (0x105A3, 'V'), + (0x105B2, 'X'), + (0x105B3, 'V'), + (0x105BA, 'X'), + (0x105BB, 'V'), + (0x105BD, 'X'), + (0x10600, 'V'), + (0x10737, 'X'), + (0x10740, 'V'), + (0x10756, 'X'), + (0x10760, 'V'), + (0x10768, 'X'), + (0x10780, 'V'), + (0x10781, 'M', 'ː'), + (0x10782, 'M', 'ˑ'), + (0x10783, 'M', 'æ'), + (0x10784, 'M', 'ʙ'), + (0x10785, 'M', 'ɓ'), + (0x10786, 'X'), + (0x10787, 'M', 'ʣ'), + (0x10788, 'M', 'ꭦ'), + (0x10789, 'M', 'ʥ'), + (0x1078A, 'M', 'ʤ'), + (0x1078B, 'M', 'ɖ'), + (0x1078C, 'M', 'ɗ'), + ] + +def _seg_55() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1078D, 'M', 'ᶑ'), + (0x1078E, 'M', 'ɘ'), + (0x1078F, 'M', 'ɞ'), + (0x10790, 'M', 'ʩ'), + (0x10791, 'M', 'ɤ'), + (0x10792, 'M', 'ɢ'), + (0x10793, 'M', 'ɠ'), + (0x10794, 'M', 'ʛ'), + (0x10795, 'M', 'ħ'), + (0x10796, 'M', 'ʜ'), + (0x10797, 'M', 'ɧ'), + (0x10798, 'M', 'ʄ'), + (0x10799, 'M', 'ʪ'), + (0x1079A, 'M', 'ʫ'), + (0x1079B, 'M', 'ɬ'), + (0x1079C, 'M', '𝼄'), + (0x1079D, 'M', 'ꞎ'), + (0x1079E, 'M', 'ɮ'), + (0x1079F, 'M', '𝼅'), + (0x107A0, 'M', 'ʎ'), + (0x107A1, 'M', '𝼆'), + (0x107A2, 'M', 'ø'), + (0x107A3, 'M', 'ɶ'), + (0x107A4, 'M', 'ɷ'), + (0x107A5, 'M', 'q'), + (0x107A6, 'M', 'ɺ'), + (0x107A7, 'M', '𝼈'), + (0x107A8, 'M', 'ɽ'), + (0x107A9, 'M', 'ɾ'), + (0x107AA, 'M', 'ʀ'), + (0x107AB, 'M', 'ʨ'), + (0x107AC, 'M', 'ʦ'), + (0x107AD, 'M', 'ꭧ'), + (0x107AE, 'M', 'ʧ'), + (0x107AF, 'M', 'ʈ'), + (0x107B0, 'M', 'ⱱ'), + (0x107B1, 'X'), + (0x107B2, 'M', 'ʏ'), + (0x107B3, 'M', 'ʡ'), + (0x107B4, 'M', 'ʢ'), + (0x107B5, 'M', 'ʘ'), + (0x107B6, 'M', 'ǀ'), + (0x107B7, 'M', 'ǁ'), + (0x107B8, 'M', 'ǂ'), + (0x107B9, 'M', '𝼊'), + (0x107BA, 'M', '𝼞'), + (0x107BB, 'X'), + (0x10800, 'V'), + (0x10806, 'X'), + (0x10808, 'V'), + (0x10809, 'X'), + (0x1080A, 'V'), + (0x10836, 'X'), + (0x10837, 'V'), + (0x10839, 'X'), + (0x1083C, 'V'), + (0x1083D, 'X'), + (0x1083F, 'V'), + (0x10856, 'X'), + (0x10857, 'V'), + (0x1089F, 'X'), + (0x108A7, 'V'), + (0x108B0, 'X'), + (0x108E0, 'V'), + (0x108F3, 'X'), + (0x108F4, 'V'), + (0x108F6, 'X'), + (0x108FB, 'V'), + (0x1091C, 'X'), + (0x1091F, 'V'), + (0x1093A, 'X'), + (0x1093F, 'V'), + (0x10940, 'X'), + (0x10980, 'V'), + (0x109B8, 'X'), + (0x109BC, 'V'), + (0x109D0, 'X'), + (0x109D2, 'V'), + (0x10A04, 'X'), + (0x10A05, 'V'), + (0x10A07, 'X'), + (0x10A0C, 'V'), + (0x10A14, 'X'), + (0x10A15, 'V'), + (0x10A18, 'X'), + (0x10A19, 'V'), + (0x10A36, 'X'), + (0x10A38, 'V'), + (0x10A3B, 'X'), + (0x10A3F, 'V'), + (0x10A49, 'X'), + (0x10A50, 'V'), + (0x10A59, 'X'), + (0x10A60, 'V'), + (0x10AA0, 'X'), + (0x10AC0, 'V'), + (0x10AE7, 'X'), + (0x10AEB, 'V'), + (0x10AF7, 'X'), + (0x10B00, 'V'), + ] + +def _seg_56() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x10B36, 'X'), + (0x10B39, 'V'), + (0x10B56, 'X'), + (0x10B58, 'V'), + (0x10B73, 'X'), + (0x10B78, 'V'), + (0x10B92, 'X'), + (0x10B99, 'V'), + (0x10B9D, 'X'), + (0x10BA9, 'V'), + (0x10BB0, 'X'), + (0x10C00, 'V'), + (0x10C49, 'X'), + (0x10C80, 'M', '𐳀'), + (0x10C81, 'M', '𐳁'), + (0x10C82, 'M', '𐳂'), + (0x10C83, 'M', '𐳃'), + (0x10C84, 'M', '𐳄'), + (0x10C85, 'M', '𐳅'), + (0x10C86, 'M', '𐳆'), + (0x10C87, 'M', '𐳇'), + (0x10C88, 'M', '𐳈'), + (0x10C89, 'M', '𐳉'), + (0x10C8A, 'M', '𐳊'), + (0x10C8B, 'M', '𐳋'), + (0x10C8C, 'M', '𐳌'), + (0x10C8D, 'M', '𐳍'), + (0x10C8E, 'M', '𐳎'), + (0x10C8F, 'M', '𐳏'), + (0x10C90, 'M', '𐳐'), + (0x10C91, 'M', '𐳑'), + (0x10C92, 'M', '𐳒'), + (0x10C93, 'M', '𐳓'), + (0x10C94, 'M', '𐳔'), + (0x10C95, 'M', '𐳕'), + (0x10C96, 'M', '𐳖'), + (0x10C97, 'M', '𐳗'), + (0x10C98, 'M', '𐳘'), + (0x10C99, 'M', '𐳙'), + (0x10C9A, 'M', '𐳚'), + (0x10C9B, 'M', '𐳛'), + (0x10C9C, 'M', '𐳜'), + (0x10C9D, 'M', '𐳝'), + (0x10C9E, 'M', '𐳞'), + (0x10C9F, 'M', '𐳟'), + (0x10CA0, 'M', '𐳠'), + (0x10CA1, 'M', '𐳡'), + (0x10CA2, 'M', '𐳢'), + (0x10CA3, 'M', '𐳣'), + (0x10CA4, 'M', '𐳤'), + (0x10CA5, 'M', '𐳥'), + (0x10CA6, 'M', '𐳦'), + (0x10CA7, 'M', '𐳧'), + (0x10CA8, 'M', '𐳨'), + (0x10CA9, 'M', '𐳩'), + (0x10CAA, 'M', '𐳪'), + (0x10CAB, 'M', '𐳫'), + (0x10CAC, 'M', '𐳬'), + (0x10CAD, 'M', '𐳭'), + (0x10CAE, 'M', '𐳮'), + (0x10CAF, 'M', '𐳯'), + (0x10CB0, 'M', '𐳰'), + (0x10CB1, 'M', '𐳱'), + (0x10CB2, 'M', '𐳲'), + (0x10CB3, 'X'), + (0x10CC0, 'V'), + (0x10CF3, 'X'), + (0x10CFA, 'V'), + (0x10D28, 'X'), + (0x10D30, 'V'), + (0x10D3A, 'X'), + (0x10E60, 'V'), + (0x10E7F, 'X'), + (0x10E80, 'V'), + (0x10EAA, 'X'), + (0x10EAB, 'V'), + (0x10EAE, 'X'), + (0x10EB0, 'V'), + (0x10EB2, 'X'), + (0x10EFD, 'V'), + (0x10F28, 'X'), + (0x10F30, 'V'), + (0x10F5A, 'X'), + (0x10F70, 'V'), + (0x10F8A, 'X'), + (0x10FB0, 'V'), + (0x10FCC, 'X'), + (0x10FE0, 'V'), + (0x10FF7, 'X'), + (0x11000, 'V'), + (0x1104E, 'X'), + (0x11052, 'V'), + (0x11076, 'X'), + (0x1107F, 'V'), + (0x110BD, 'X'), + (0x110BE, 'V'), + (0x110C3, 'X'), + (0x110D0, 'V'), + (0x110E9, 'X'), + (0x110F0, 'V'), + ] + +def _seg_57() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x110FA, 'X'), + (0x11100, 'V'), + (0x11135, 'X'), + (0x11136, 'V'), + (0x11148, 'X'), + (0x11150, 'V'), + (0x11177, 'X'), + (0x11180, 'V'), + (0x111E0, 'X'), + (0x111E1, 'V'), + (0x111F5, 'X'), + (0x11200, 'V'), + (0x11212, 'X'), + (0x11213, 'V'), + (0x11242, 'X'), + (0x11280, 'V'), + (0x11287, 'X'), + (0x11288, 'V'), + (0x11289, 'X'), + (0x1128A, 'V'), + (0x1128E, 'X'), + (0x1128F, 'V'), + (0x1129E, 'X'), + (0x1129F, 'V'), + (0x112AA, 'X'), + (0x112B0, 'V'), + (0x112EB, 'X'), + (0x112F0, 'V'), + (0x112FA, 'X'), + (0x11300, 'V'), + (0x11304, 'X'), + (0x11305, 'V'), + (0x1130D, 'X'), + (0x1130F, 'V'), + (0x11311, 'X'), + (0x11313, 'V'), + (0x11329, 'X'), + (0x1132A, 'V'), + (0x11331, 'X'), + (0x11332, 'V'), + (0x11334, 'X'), + (0x11335, 'V'), + (0x1133A, 'X'), + (0x1133B, 'V'), + (0x11345, 'X'), + (0x11347, 'V'), + (0x11349, 'X'), + (0x1134B, 'V'), + (0x1134E, 'X'), + (0x11350, 'V'), + (0x11351, 'X'), + (0x11357, 'V'), + (0x11358, 'X'), + (0x1135D, 'V'), + (0x11364, 'X'), + (0x11366, 'V'), + (0x1136D, 'X'), + (0x11370, 'V'), + (0x11375, 'X'), + (0x11400, 'V'), + (0x1145C, 'X'), + (0x1145D, 'V'), + (0x11462, 'X'), + (0x11480, 'V'), + (0x114C8, 'X'), + (0x114D0, 'V'), + (0x114DA, 'X'), + (0x11580, 'V'), + (0x115B6, 'X'), + (0x115B8, 'V'), + (0x115DE, 'X'), + (0x11600, 'V'), + (0x11645, 'X'), + (0x11650, 'V'), + (0x1165A, 'X'), + (0x11660, 'V'), + (0x1166D, 'X'), + (0x11680, 'V'), + (0x116BA, 'X'), + (0x116C0, 'V'), + (0x116CA, 'X'), + (0x11700, 'V'), + (0x1171B, 'X'), + (0x1171D, 'V'), + (0x1172C, 'X'), + (0x11730, 'V'), + (0x11747, 'X'), + (0x11800, 'V'), + (0x1183C, 'X'), + (0x118A0, 'M', '𑣀'), + (0x118A1, 'M', '𑣁'), + (0x118A2, 'M', '𑣂'), + (0x118A3, 'M', '𑣃'), + (0x118A4, 'M', '𑣄'), + (0x118A5, 'M', '𑣅'), + (0x118A6, 'M', '𑣆'), + (0x118A7, 'M', '𑣇'), + (0x118A8, 'M', '𑣈'), + (0x118A9, 'M', '𑣉'), + (0x118AA, 'M', '𑣊'), + ] + +def _seg_58() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x118AB, 'M', '𑣋'), + (0x118AC, 'M', '𑣌'), + (0x118AD, 'M', '𑣍'), + (0x118AE, 'M', '𑣎'), + (0x118AF, 'M', '𑣏'), + (0x118B0, 'M', '𑣐'), + (0x118B1, 'M', '𑣑'), + (0x118B2, 'M', '𑣒'), + (0x118B3, 'M', '𑣓'), + (0x118B4, 'M', '𑣔'), + (0x118B5, 'M', '𑣕'), + (0x118B6, 'M', '𑣖'), + (0x118B7, 'M', '𑣗'), + (0x118B8, 'M', '𑣘'), + (0x118B9, 'M', '𑣙'), + (0x118BA, 'M', '𑣚'), + (0x118BB, 'M', '𑣛'), + (0x118BC, 'M', '𑣜'), + (0x118BD, 'M', '𑣝'), + (0x118BE, 'M', '𑣞'), + (0x118BF, 'M', '𑣟'), + (0x118C0, 'V'), + (0x118F3, 'X'), + (0x118FF, 'V'), + (0x11907, 'X'), + (0x11909, 'V'), + (0x1190A, 'X'), + (0x1190C, 'V'), + (0x11914, 'X'), + (0x11915, 'V'), + (0x11917, 'X'), + (0x11918, 'V'), + (0x11936, 'X'), + (0x11937, 'V'), + (0x11939, 'X'), + (0x1193B, 'V'), + (0x11947, 'X'), + (0x11950, 'V'), + (0x1195A, 'X'), + (0x119A0, 'V'), + (0x119A8, 'X'), + (0x119AA, 'V'), + (0x119D8, 'X'), + (0x119DA, 'V'), + (0x119E5, 'X'), + (0x11A00, 'V'), + (0x11A48, 'X'), + (0x11A50, 'V'), + (0x11AA3, 'X'), + (0x11AB0, 'V'), + (0x11AF9, 'X'), + (0x11B00, 'V'), + (0x11B0A, 'X'), + (0x11C00, 'V'), + (0x11C09, 'X'), + (0x11C0A, 'V'), + (0x11C37, 'X'), + (0x11C38, 'V'), + (0x11C46, 'X'), + (0x11C50, 'V'), + (0x11C6D, 'X'), + (0x11C70, 'V'), + (0x11C90, 'X'), + (0x11C92, 'V'), + (0x11CA8, 'X'), + (0x11CA9, 'V'), + (0x11CB7, 'X'), + (0x11D00, 'V'), + (0x11D07, 'X'), + (0x11D08, 'V'), + (0x11D0A, 'X'), + (0x11D0B, 'V'), + (0x11D37, 'X'), + (0x11D3A, 'V'), + (0x11D3B, 'X'), + (0x11D3C, 'V'), + (0x11D3E, 'X'), + (0x11D3F, 'V'), + (0x11D48, 'X'), + (0x11D50, 'V'), + (0x11D5A, 'X'), + (0x11D60, 'V'), + (0x11D66, 'X'), + (0x11D67, 'V'), + (0x11D69, 'X'), + (0x11D6A, 'V'), + (0x11D8F, 'X'), + (0x11D90, 'V'), + (0x11D92, 'X'), + (0x11D93, 'V'), + (0x11D99, 'X'), + (0x11DA0, 'V'), + (0x11DAA, 'X'), + (0x11EE0, 'V'), + (0x11EF9, 'X'), + (0x11F00, 'V'), + (0x11F11, 'X'), + (0x11F12, 'V'), + (0x11F3B, 'X'), + (0x11F3E, 'V'), + ] + +def _seg_59() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x11F5A, 'X'), + (0x11FB0, 'V'), + (0x11FB1, 'X'), + (0x11FC0, 'V'), + (0x11FF2, 'X'), + (0x11FFF, 'V'), + (0x1239A, 'X'), + (0x12400, 'V'), + (0x1246F, 'X'), + (0x12470, 'V'), + (0x12475, 'X'), + (0x12480, 'V'), + (0x12544, 'X'), + (0x12F90, 'V'), + (0x12FF3, 'X'), + (0x13000, 'V'), + (0x13430, 'X'), + (0x13440, 'V'), + (0x13456, 'X'), + (0x14400, 'V'), + (0x14647, 'X'), + (0x16800, 'V'), + (0x16A39, 'X'), + (0x16A40, 'V'), + (0x16A5F, 'X'), + (0x16A60, 'V'), + (0x16A6A, 'X'), + (0x16A6E, 'V'), + (0x16ABF, 'X'), + (0x16AC0, 'V'), + (0x16ACA, 'X'), + (0x16AD0, 'V'), + (0x16AEE, 'X'), + (0x16AF0, 'V'), + (0x16AF6, 'X'), + (0x16B00, 'V'), + (0x16B46, 'X'), + (0x16B50, 'V'), + (0x16B5A, 'X'), + (0x16B5B, 'V'), + (0x16B62, 'X'), + (0x16B63, 'V'), + (0x16B78, 'X'), + (0x16B7D, 'V'), + (0x16B90, 'X'), + (0x16E40, 'M', '𖹠'), + (0x16E41, 'M', '𖹡'), + (0x16E42, 'M', '𖹢'), + (0x16E43, 'M', '𖹣'), + (0x16E44, 'M', '𖹤'), + (0x16E45, 'M', '𖹥'), + (0x16E46, 'M', '𖹦'), + (0x16E47, 'M', '𖹧'), + (0x16E48, 'M', '𖹨'), + (0x16E49, 'M', '𖹩'), + (0x16E4A, 'M', '𖹪'), + (0x16E4B, 'M', '𖹫'), + (0x16E4C, 'M', '𖹬'), + (0x16E4D, 'M', '𖹭'), + (0x16E4E, 'M', '𖹮'), + (0x16E4F, 'M', '𖹯'), + (0x16E50, 'M', '𖹰'), + (0x16E51, 'M', '𖹱'), + (0x16E52, 'M', '𖹲'), + (0x16E53, 'M', '𖹳'), + (0x16E54, 'M', '𖹴'), + (0x16E55, 'M', '𖹵'), + (0x16E56, 'M', '𖹶'), + (0x16E57, 'M', '𖹷'), + (0x16E58, 'M', '𖹸'), + (0x16E59, 'M', '𖹹'), + (0x16E5A, 'M', '𖹺'), + (0x16E5B, 'M', '𖹻'), + (0x16E5C, 'M', '𖹼'), + (0x16E5D, 'M', '𖹽'), + (0x16E5E, 'M', '𖹾'), + (0x16E5F, 'M', '𖹿'), + (0x16E60, 'V'), + (0x16E9B, 'X'), + (0x16F00, 'V'), + (0x16F4B, 'X'), + (0x16F4F, 'V'), + (0x16F88, 'X'), + (0x16F8F, 'V'), + (0x16FA0, 'X'), + (0x16FE0, 'V'), + (0x16FE5, 'X'), + (0x16FF0, 'V'), + (0x16FF2, 'X'), + (0x17000, 'V'), + (0x187F8, 'X'), + (0x18800, 'V'), + (0x18CD6, 'X'), + (0x18D00, 'V'), + (0x18D09, 'X'), + (0x1AFF0, 'V'), + (0x1AFF4, 'X'), + (0x1AFF5, 'V'), + (0x1AFFC, 'X'), + (0x1AFFD, 'V'), + ] + +def _seg_60() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1AFFF, 'X'), + (0x1B000, 'V'), + (0x1B123, 'X'), + (0x1B132, 'V'), + (0x1B133, 'X'), + (0x1B150, 'V'), + (0x1B153, 'X'), + (0x1B155, 'V'), + (0x1B156, 'X'), + (0x1B164, 'V'), + (0x1B168, 'X'), + (0x1B170, 'V'), + (0x1B2FC, 'X'), + (0x1BC00, 'V'), + (0x1BC6B, 'X'), + (0x1BC70, 'V'), + (0x1BC7D, 'X'), + (0x1BC80, 'V'), + (0x1BC89, 'X'), + (0x1BC90, 'V'), + (0x1BC9A, 'X'), + (0x1BC9C, 'V'), + (0x1BCA0, 'I'), + (0x1BCA4, 'X'), + (0x1CF00, 'V'), + (0x1CF2E, 'X'), + (0x1CF30, 'V'), + (0x1CF47, 'X'), + (0x1CF50, 'V'), + (0x1CFC4, 'X'), + (0x1D000, 'V'), + (0x1D0F6, 'X'), + (0x1D100, 'V'), + (0x1D127, 'X'), + (0x1D129, 'V'), + (0x1D15E, 'M', '𝅗𝅥'), + (0x1D15F, 'M', '𝅘𝅥'), + (0x1D160, 'M', '𝅘𝅥𝅮'), + (0x1D161, 'M', '𝅘𝅥𝅯'), + (0x1D162, 'M', '𝅘𝅥𝅰'), + (0x1D163, 'M', '𝅘𝅥𝅱'), + (0x1D164, 'M', '𝅘𝅥𝅲'), + (0x1D165, 'V'), + (0x1D173, 'X'), + (0x1D17B, 'V'), + (0x1D1BB, 'M', '𝆹𝅥'), + (0x1D1BC, 'M', '𝆺𝅥'), + (0x1D1BD, 'M', '𝆹𝅥𝅮'), + (0x1D1BE, 'M', '𝆺𝅥𝅮'), + (0x1D1BF, 'M', '𝆹𝅥𝅯'), + (0x1D1C0, 'M', '𝆺𝅥𝅯'), + (0x1D1C1, 'V'), + (0x1D1EB, 'X'), + (0x1D200, 'V'), + (0x1D246, 'X'), + (0x1D2C0, 'V'), + (0x1D2D4, 'X'), + (0x1D2E0, 'V'), + (0x1D2F4, 'X'), + (0x1D300, 'V'), + (0x1D357, 'X'), + (0x1D360, 'V'), + (0x1D379, 'X'), + (0x1D400, 'M', 'a'), + (0x1D401, 'M', 'b'), + (0x1D402, 'M', 'c'), + (0x1D403, 'M', 'd'), + (0x1D404, 'M', 'e'), + (0x1D405, 'M', 'f'), + (0x1D406, 'M', 'g'), + (0x1D407, 'M', 'h'), + (0x1D408, 'M', 'i'), + (0x1D409, 'M', 'j'), + (0x1D40A, 'M', 'k'), + (0x1D40B, 'M', 'l'), + (0x1D40C, 'M', 'm'), + (0x1D40D, 'M', 'n'), + (0x1D40E, 'M', 'o'), + (0x1D40F, 'M', 'p'), + (0x1D410, 'M', 'q'), + (0x1D411, 'M', 'r'), + (0x1D412, 'M', 's'), + (0x1D413, 'M', 't'), + (0x1D414, 'M', 'u'), + (0x1D415, 'M', 'v'), + (0x1D416, 'M', 'w'), + (0x1D417, 'M', 'x'), + (0x1D418, 'M', 'y'), + (0x1D419, 'M', 'z'), + (0x1D41A, 'M', 'a'), + (0x1D41B, 'M', 'b'), + (0x1D41C, 'M', 'c'), + (0x1D41D, 'M', 'd'), + (0x1D41E, 'M', 'e'), + (0x1D41F, 'M', 'f'), + (0x1D420, 'M', 'g'), + (0x1D421, 'M', 'h'), + (0x1D422, 'M', 'i'), + (0x1D423, 'M', 'j'), + (0x1D424, 'M', 'k'), + ] + +def _seg_61() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D425, 'M', 'l'), + (0x1D426, 'M', 'm'), + (0x1D427, 'M', 'n'), + (0x1D428, 'M', 'o'), + (0x1D429, 'M', 'p'), + (0x1D42A, 'M', 'q'), + (0x1D42B, 'M', 'r'), + (0x1D42C, 'M', 's'), + (0x1D42D, 'M', 't'), + (0x1D42E, 'M', 'u'), + (0x1D42F, 'M', 'v'), + (0x1D430, 'M', 'w'), + (0x1D431, 'M', 'x'), + (0x1D432, 'M', 'y'), + (0x1D433, 'M', 'z'), + (0x1D434, 'M', 'a'), + (0x1D435, 'M', 'b'), + (0x1D436, 'M', 'c'), + (0x1D437, 'M', 'd'), + (0x1D438, 'M', 'e'), + (0x1D439, 'M', 'f'), + (0x1D43A, 'M', 'g'), + (0x1D43B, 'M', 'h'), + (0x1D43C, 'M', 'i'), + (0x1D43D, 'M', 'j'), + (0x1D43E, 'M', 'k'), + (0x1D43F, 'M', 'l'), + (0x1D440, 'M', 'm'), + (0x1D441, 'M', 'n'), + (0x1D442, 'M', 'o'), + (0x1D443, 'M', 'p'), + (0x1D444, 'M', 'q'), + (0x1D445, 'M', 'r'), + (0x1D446, 'M', 's'), + (0x1D447, 'M', 't'), + (0x1D448, 'M', 'u'), + (0x1D449, 'M', 'v'), + (0x1D44A, 'M', 'w'), + (0x1D44B, 'M', 'x'), + (0x1D44C, 'M', 'y'), + (0x1D44D, 'M', 'z'), + (0x1D44E, 'M', 'a'), + (0x1D44F, 'M', 'b'), + (0x1D450, 'M', 'c'), + (0x1D451, 'M', 'd'), + (0x1D452, 'M', 'e'), + (0x1D453, 'M', 'f'), + (0x1D454, 'M', 'g'), + (0x1D455, 'X'), + (0x1D456, 'M', 'i'), + (0x1D457, 'M', 'j'), + (0x1D458, 'M', 'k'), + (0x1D459, 'M', 'l'), + (0x1D45A, 'M', 'm'), + (0x1D45B, 'M', 'n'), + (0x1D45C, 'M', 'o'), + (0x1D45D, 'M', 'p'), + (0x1D45E, 'M', 'q'), + (0x1D45F, 'M', 'r'), + (0x1D460, 'M', 's'), + (0x1D461, 'M', 't'), + (0x1D462, 'M', 'u'), + (0x1D463, 'M', 'v'), + (0x1D464, 'M', 'w'), + (0x1D465, 'M', 'x'), + (0x1D466, 'M', 'y'), + (0x1D467, 'M', 'z'), + (0x1D468, 'M', 'a'), + (0x1D469, 'M', 'b'), + (0x1D46A, 'M', 'c'), + (0x1D46B, 'M', 'd'), + (0x1D46C, 'M', 'e'), + (0x1D46D, 'M', 'f'), + (0x1D46E, 'M', 'g'), + (0x1D46F, 'M', 'h'), + (0x1D470, 'M', 'i'), + (0x1D471, 'M', 'j'), + (0x1D472, 'M', 'k'), + (0x1D473, 'M', 'l'), + (0x1D474, 'M', 'm'), + (0x1D475, 'M', 'n'), + (0x1D476, 'M', 'o'), + (0x1D477, 'M', 'p'), + (0x1D478, 'M', 'q'), + (0x1D479, 'M', 'r'), + (0x1D47A, 'M', 's'), + (0x1D47B, 'M', 't'), + (0x1D47C, 'M', 'u'), + (0x1D47D, 'M', 'v'), + (0x1D47E, 'M', 'w'), + (0x1D47F, 'M', 'x'), + (0x1D480, 'M', 'y'), + (0x1D481, 'M', 'z'), + (0x1D482, 'M', 'a'), + (0x1D483, 'M', 'b'), + (0x1D484, 'M', 'c'), + (0x1D485, 'M', 'd'), + (0x1D486, 'M', 'e'), + (0x1D487, 'M', 'f'), + (0x1D488, 'M', 'g'), + ] + +def _seg_62() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D489, 'M', 'h'), + (0x1D48A, 'M', 'i'), + (0x1D48B, 'M', 'j'), + (0x1D48C, 'M', 'k'), + (0x1D48D, 'M', 'l'), + (0x1D48E, 'M', 'm'), + (0x1D48F, 'M', 'n'), + (0x1D490, 'M', 'o'), + (0x1D491, 'M', 'p'), + (0x1D492, 'M', 'q'), + (0x1D493, 'M', 'r'), + (0x1D494, 'M', 's'), + (0x1D495, 'M', 't'), + (0x1D496, 'M', 'u'), + (0x1D497, 'M', 'v'), + (0x1D498, 'M', 'w'), + (0x1D499, 'M', 'x'), + (0x1D49A, 'M', 'y'), + (0x1D49B, 'M', 'z'), + (0x1D49C, 'M', 'a'), + (0x1D49D, 'X'), + (0x1D49E, 'M', 'c'), + (0x1D49F, 'M', 'd'), + (0x1D4A0, 'X'), + (0x1D4A2, 'M', 'g'), + (0x1D4A3, 'X'), + (0x1D4A5, 'M', 'j'), + (0x1D4A6, 'M', 'k'), + (0x1D4A7, 'X'), + (0x1D4A9, 'M', 'n'), + (0x1D4AA, 'M', 'o'), + (0x1D4AB, 'M', 'p'), + (0x1D4AC, 'M', 'q'), + (0x1D4AD, 'X'), + (0x1D4AE, 'M', 's'), + (0x1D4AF, 'M', 't'), + (0x1D4B0, 'M', 'u'), + (0x1D4B1, 'M', 'v'), + (0x1D4B2, 'M', 'w'), + (0x1D4B3, 'M', 'x'), + (0x1D4B4, 'M', 'y'), + (0x1D4B5, 'M', 'z'), + (0x1D4B6, 'M', 'a'), + (0x1D4B7, 'M', 'b'), + (0x1D4B8, 'M', 'c'), + (0x1D4B9, 'M', 'd'), + (0x1D4BA, 'X'), + (0x1D4BB, 'M', 'f'), + (0x1D4BC, 'X'), + (0x1D4BD, 'M', 'h'), + (0x1D4BE, 'M', 'i'), + (0x1D4BF, 'M', 'j'), + (0x1D4C0, 'M', 'k'), + (0x1D4C1, 'M', 'l'), + (0x1D4C2, 'M', 'm'), + (0x1D4C3, 'M', 'n'), + (0x1D4C4, 'X'), + (0x1D4C5, 'M', 'p'), + (0x1D4C6, 'M', 'q'), + (0x1D4C7, 'M', 'r'), + (0x1D4C8, 'M', 's'), + (0x1D4C9, 'M', 't'), + (0x1D4CA, 'M', 'u'), + (0x1D4CB, 'M', 'v'), + (0x1D4CC, 'M', 'w'), + (0x1D4CD, 'M', 'x'), + (0x1D4CE, 'M', 'y'), + (0x1D4CF, 'M', 'z'), + (0x1D4D0, 'M', 'a'), + (0x1D4D1, 'M', 'b'), + (0x1D4D2, 'M', 'c'), + (0x1D4D3, 'M', 'd'), + (0x1D4D4, 'M', 'e'), + (0x1D4D5, 'M', 'f'), + (0x1D4D6, 'M', 'g'), + (0x1D4D7, 'M', 'h'), + (0x1D4D8, 'M', 'i'), + (0x1D4D9, 'M', 'j'), + (0x1D4DA, 'M', 'k'), + (0x1D4DB, 'M', 'l'), + (0x1D4DC, 'M', 'm'), + (0x1D4DD, 'M', 'n'), + (0x1D4DE, 'M', 'o'), + (0x1D4DF, 'M', 'p'), + (0x1D4E0, 'M', 'q'), + (0x1D4E1, 'M', 'r'), + (0x1D4E2, 'M', 's'), + (0x1D4E3, 'M', 't'), + (0x1D4E4, 'M', 'u'), + (0x1D4E5, 'M', 'v'), + (0x1D4E6, 'M', 'w'), + (0x1D4E7, 'M', 'x'), + (0x1D4E8, 'M', 'y'), + (0x1D4E9, 'M', 'z'), + (0x1D4EA, 'M', 'a'), + (0x1D4EB, 'M', 'b'), + (0x1D4EC, 'M', 'c'), + (0x1D4ED, 'M', 'd'), + (0x1D4EE, 'M', 'e'), + (0x1D4EF, 'M', 'f'), + ] + +def _seg_63() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D4F0, 'M', 'g'), + (0x1D4F1, 'M', 'h'), + (0x1D4F2, 'M', 'i'), + (0x1D4F3, 'M', 'j'), + (0x1D4F4, 'M', 'k'), + (0x1D4F5, 'M', 'l'), + (0x1D4F6, 'M', 'm'), + (0x1D4F7, 'M', 'n'), + (0x1D4F8, 'M', 'o'), + (0x1D4F9, 'M', 'p'), + (0x1D4FA, 'M', 'q'), + (0x1D4FB, 'M', 'r'), + (0x1D4FC, 'M', 's'), + (0x1D4FD, 'M', 't'), + (0x1D4FE, 'M', 'u'), + (0x1D4FF, 'M', 'v'), + (0x1D500, 'M', 'w'), + (0x1D501, 'M', 'x'), + (0x1D502, 'M', 'y'), + (0x1D503, 'M', 'z'), + (0x1D504, 'M', 'a'), + (0x1D505, 'M', 'b'), + (0x1D506, 'X'), + (0x1D507, 'M', 'd'), + (0x1D508, 'M', 'e'), + (0x1D509, 'M', 'f'), + (0x1D50A, 'M', 'g'), + (0x1D50B, 'X'), + (0x1D50D, 'M', 'j'), + (0x1D50E, 'M', 'k'), + (0x1D50F, 'M', 'l'), + (0x1D510, 'M', 'm'), + (0x1D511, 'M', 'n'), + (0x1D512, 'M', 'o'), + (0x1D513, 'M', 'p'), + (0x1D514, 'M', 'q'), + (0x1D515, 'X'), + (0x1D516, 'M', 's'), + (0x1D517, 'M', 't'), + (0x1D518, 'M', 'u'), + (0x1D519, 'M', 'v'), + (0x1D51A, 'M', 'w'), + (0x1D51B, 'M', 'x'), + (0x1D51C, 'M', 'y'), + (0x1D51D, 'X'), + (0x1D51E, 'M', 'a'), + (0x1D51F, 'M', 'b'), + (0x1D520, 'M', 'c'), + (0x1D521, 'M', 'd'), + (0x1D522, 'M', 'e'), + (0x1D523, 'M', 'f'), + (0x1D524, 'M', 'g'), + (0x1D525, 'M', 'h'), + (0x1D526, 'M', 'i'), + (0x1D527, 'M', 'j'), + (0x1D528, 'M', 'k'), + (0x1D529, 'M', 'l'), + (0x1D52A, 'M', 'm'), + (0x1D52B, 'M', 'n'), + (0x1D52C, 'M', 'o'), + (0x1D52D, 'M', 'p'), + (0x1D52E, 'M', 'q'), + (0x1D52F, 'M', 'r'), + (0x1D530, 'M', 's'), + (0x1D531, 'M', 't'), + (0x1D532, 'M', 'u'), + (0x1D533, 'M', 'v'), + (0x1D534, 'M', 'w'), + (0x1D535, 'M', 'x'), + (0x1D536, 'M', 'y'), + (0x1D537, 'M', 'z'), + (0x1D538, 'M', 'a'), + (0x1D539, 'M', 'b'), + (0x1D53A, 'X'), + (0x1D53B, 'M', 'd'), + (0x1D53C, 'M', 'e'), + (0x1D53D, 'M', 'f'), + (0x1D53E, 'M', 'g'), + (0x1D53F, 'X'), + (0x1D540, 'M', 'i'), + (0x1D541, 'M', 'j'), + (0x1D542, 'M', 'k'), + (0x1D543, 'M', 'l'), + (0x1D544, 'M', 'm'), + (0x1D545, 'X'), + (0x1D546, 'M', 'o'), + (0x1D547, 'X'), + (0x1D54A, 'M', 's'), + (0x1D54B, 'M', 't'), + (0x1D54C, 'M', 'u'), + (0x1D54D, 'M', 'v'), + (0x1D54E, 'M', 'w'), + (0x1D54F, 'M', 'x'), + (0x1D550, 'M', 'y'), + (0x1D551, 'X'), + (0x1D552, 'M', 'a'), + (0x1D553, 'M', 'b'), + (0x1D554, 'M', 'c'), + (0x1D555, 'M', 'd'), + (0x1D556, 'M', 'e'), + ] + +def _seg_64() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D557, 'M', 'f'), + (0x1D558, 'M', 'g'), + (0x1D559, 'M', 'h'), + (0x1D55A, 'M', 'i'), + (0x1D55B, 'M', 'j'), + (0x1D55C, 'M', 'k'), + (0x1D55D, 'M', 'l'), + (0x1D55E, 'M', 'm'), + (0x1D55F, 'M', 'n'), + (0x1D560, 'M', 'o'), + (0x1D561, 'M', 'p'), + (0x1D562, 'M', 'q'), + (0x1D563, 'M', 'r'), + (0x1D564, 'M', 's'), + (0x1D565, 'M', 't'), + (0x1D566, 'M', 'u'), + (0x1D567, 'M', 'v'), + (0x1D568, 'M', 'w'), + (0x1D569, 'M', 'x'), + (0x1D56A, 'M', 'y'), + (0x1D56B, 'M', 'z'), + (0x1D56C, 'M', 'a'), + (0x1D56D, 'M', 'b'), + (0x1D56E, 'M', 'c'), + (0x1D56F, 'M', 'd'), + (0x1D570, 'M', 'e'), + (0x1D571, 'M', 'f'), + (0x1D572, 'M', 'g'), + (0x1D573, 'M', 'h'), + (0x1D574, 'M', 'i'), + (0x1D575, 'M', 'j'), + (0x1D576, 'M', 'k'), + (0x1D577, 'M', 'l'), + (0x1D578, 'M', 'm'), + (0x1D579, 'M', 'n'), + (0x1D57A, 'M', 'o'), + (0x1D57B, 'M', 'p'), + (0x1D57C, 'M', 'q'), + (0x1D57D, 'M', 'r'), + (0x1D57E, 'M', 's'), + (0x1D57F, 'M', 't'), + (0x1D580, 'M', 'u'), + (0x1D581, 'M', 'v'), + (0x1D582, 'M', 'w'), + (0x1D583, 'M', 'x'), + (0x1D584, 'M', 'y'), + (0x1D585, 'M', 'z'), + (0x1D586, 'M', 'a'), + (0x1D587, 'M', 'b'), + (0x1D588, 'M', 'c'), + (0x1D589, 'M', 'd'), + (0x1D58A, 'M', 'e'), + (0x1D58B, 'M', 'f'), + (0x1D58C, 'M', 'g'), + (0x1D58D, 'M', 'h'), + (0x1D58E, 'M', 'i'), + (0x1D58F, 'M', 'j'), + (0x1D590, 'M', 'k'), + (0x1D591, 'M', 'l'), + (0x1D592, 'M', 'm'), + (0x1D593, 'M', 'n'), + (0x1D594, 'M', 'o'), + (0x1D595, 'M', 'p'), + (0x1D596, 'M', 'q'), + (0x1D597, 'M', 'r'), + (0x1D598, 'M', 's'), + (0x1D599, 'M', 't'), + (0x1D59A, 'M', 'u'), + (0x1D59B, 'M', 'v'), + (0x1D59C, 'M', 'w'), + (0x1D59D, 'M', 'x'), + (0x1D59E, 'M', 'y'), + (0x1D59F, 'M', 'z'), + (0x1D5A0, 'M', 'a'), + (0x1D5A1, 'M', 'b'), + (0x1D5A2, 'M', 'c'), + (0x1D5A3, 'M', 'd'), + (0x1D5A4, 'M', 'e'), + (0x1D5A5, 'M', 'f'), + (0x1D5A6, 'M', 'g'), + (0x1D5A7, 'M', 'h'), + (0x1D5A8, 'M', 'i'), + (0x1D5A9, 'M', 'j'), + (0x1D5AA, 'M', 'k'), + (0x1D5AB, 'M', 'l'), + (0x1D5AC, 'M', 'm'), + (0x1D5AD, 'M', 'n'), + (0x1D5AE, 'M', 'o'), + (0x1D5AF, 'M', 'p'), + (0x1D5B0, 'M', 'q'), + (0x1D5B1, 'M', 'r'), + (0x1D5B2, 'M', 's'), + (0x1D5B3, 'M', 't'), + (0x1D5B4, 'M', 'u'), + (0x1D5B5, 'M', 'v'), + (0x1D5B6, 'M', 'w'), + (0x1D5B7, 'M', 'x'), + (0x1D5B8, 'M', 'y'), + (0x1D5B9, 'M', 'z'), + (0x1D5BA, 'M', 'a'), + ] + +def _seg_65() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D5BB, 'M', 'b'), + (0x1D5BC, 'M', 'c'), + (0x1D5BD, 'M', 'd'), + (0x1D5BE, 'M', 'e'), + (0x1D5BF, 'M', 'f'), + (0x1D5C0, 'M', 'g'), + (0x1D5C1, 'M', 'h'), + (0x1D5C2, 'M', 'i'), + (0x1D5C3, 'M', 'j'), + (0x1D5C4, 'M', 'k'), + (0x1D5C5, 'M', 'l'), + (0x1D5C6, 'M', 'm'), + (0x1D5C7, 'M', 'n'), + (0x1D5C8, 'M', 'o'), + (0x1D5C9, 'M', 'p'), + (0x1D5CA, 'M', 'q'), + (0x1D5CB, 'M', 'r'), + (0x1D5CC, 'M', 's'), + (0x1D5CD, 'M', 't'), + (0x1D5CE, 'M', 'u'), + (0x1D5CF, 'M', 'v'), + (0x1D5D0, 'M', 'w'), + (0x1D5D1, 'M', 'x'), + (0x1D5D2, 'M', 'y'), + (0x1D5D3, 'M', 'z'), + (0x1D5D4, 'M', 'a'), + (0x1D5D5, 'M', 'b'), + (0x1D5D6, 'M', 'c'), + (0x1D5D7, 'M', 'd'), + (0x1D5D8, 'M', 'e'), + (0x1D5D9, 'M', 'f'), + (0x1D5DA, 'M', 'g'), + (0x1D5DB, 'M', 'h'), + (0x1D5DC, 'M', 'i'), + (0x1D5DD, 'M', 'j'), + (0x1D5DE, 'M', 'k'), + (0x1D5DF, 'M', 'l'), + (0x1D5E0, 'M', 'm'), + (0x1D5E1, 'M', 'n'), + (0x1D5E2, 'M', 'o'), + (0x1D5E3, 'M', 'p'), + (0x1D5E4, 'M', 'q'), + (0x1D5E5, 'M', 'r'), + (0x1D5E6, 'M', 's'), + (0x1D5E7, 'M', 't'), + (0x1D5E8, 'M', 'u'), + (0x1D5E9, 'M', 'v'), + (0x1D5EA, 'M', 'w'), + (0x1D5EB, 'M', 'x'), + (0x1D5EC, 'M', 'y'), + (0x1D5ED, 'M', 'z'), + (0x1D5EE, 'M', 'a'), + (0x1D5EF, 'M', 'b'), + (0x1D5F0, 'M', 'c'), + (0x1D5F1, 'M', 'd'), + (0x1D5F2, 'M', 'e'), + (0x1D5F3, 'M', 'f'), + (0x1D5F4, 'M', 'g'), + (0x1D5F5, 'M', 'h'), + (0x1D5F6, 'M', 'i'), + (0x1D5F7, 'M', 'j'), + (0x1D5F8, 'M', 'k'), + (0x1D5F9, 'M', 'l'), + (0x1D5FA, 'M', 'm'), + (0x1D5FB, 'M', 'n'), + (0x1D5FC, 'M', 'o'), + (0x1D5FD, 'M', 'p'), + (0x1D5FE, 'M', 'q'), + (0x1D5FF, 'M', 'r'), + (0x1D600, 'M', 's'), + (0x1D601, 'M', 't'), + (0x1D602, 'M', 'u'), + (0x1D603, 'M', 'v'), + (0x1D604, 'M', 'w'), + (0x1D605, 'M', 'x'), + (0x1D606, 'M', 'y'), + (0x1D607, 'M', 'z'), + (0x1D608, 'M', 'a'), + (0x1D609, 'M', 'b'), + (0x1D60A, 'M', 'c'), + (0x1D60B, 'M', 'd'), + (0x1D60C, 'M', 'e'), + (0x1D60D, 'M', 'f'), + (0x1D60E, 'M', 'g'), + (0x1D60F, 'M', 'h'), + (0x1D610, 'M', 'i'), + (0x1D611, 'M', 'j'), + (0x1D612, 'M', 'k'), + (0x1D613, 'M', 'l'), + (0x1D614, 'M', 'm'), + (0x1D615, 'M', 'n'), + (0x1D616, 'M', 'o'), + (0x1D617, 'M', 'p'), + (0x1D618, 'M', 'q'), + (0x1D619, 'M', 'r'), + (0x1D61A, 'M', 's'), + (0x1D61B, 'M', 't'), + (0x1D61C, 'M', 'u'), + (0x1D61D, 'M', 'v'), + (0x1D61E, 'M', 'w'), + ] + +def _seg_66() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D61F, 'M', 'x'), + (0x1D620, 'M', 'y'), + (0x1D621, 'M', 'z'), + (0x1D622, 'M', 'a'), + (0x1D623, 'M', 'b'), + (0x1D624, 'M', 'c'), + (0x1D625, 'M', 'd'), + (0x1D626, 'M', 'e'), + (0x1D627, 'M', 'f'), + (0x1D628, 'M', 'g'), + (0x1D629, 'M', 'h'), + (0x1D62A, 'M', 'i'), + (0x1D62B, 'M', 'j'), + (0x1D62C, 'M', 'k'), + (0x1D62D, 'M', 'l'), + (0x1D62E, 'M', 'm'), + (0x1D62F, 'M', 'n'), + (0x1D630, 'M', 'o'), + (0x1D631, 'M', 'p'), + (0x1D632, 'M', 'q'), + (0x1D633, 'M', 'r'), + (0x1D634, 'M', 's'), + (0x1D635, 'M', 't'), + (0x1D636, 'M', 'u'), + (0x1D637, 'M', 'v'), + (0x1D638, 'M', 'w'), + (0x1D639, 'M', 'x'), + (0x1D63A, 'M', 'y'), + (0x1D63B, 'M', 'z'), + (0x1D63C, 'M', 'a'), + (0x1D63D, 'M', 'b'), + (0x1D63E, 'M', 'c'), + (0x1D63F, 'M', 'd'), + (0x1D640, 'M', 'e'), + (0x1D641, 'M', 'f'), + (0x1D642, 'M', 'g'), + (0x1D643, 'M', 'h'), + (0x1D644, 'M', 'i'), + (0x1D645, 'M', 'j'), + (0x1D646, 'M', 'k'), + (0x1D647, 'M', 'l'), + (0x1D648, 'M', 'm'), + (0x1D649, 'M', 'n'), + (0x1D64A, 'M', 'o'), + (0x1D64B, 'M', 'p'), + (0x1D64C, 'M', 'q'), + (0x1D64D, 'M', 'r'), + (0x1D64E, 'M', 's'), + (0x1D64F, 'M', 't'), + (0x1D650, 'M', 'u'), + (0x1D651, 'M', 'v'), + (0x1D652, 'M', 'w'), + (0x1D653, 'M', 'x'), + (0x1D654, 'M', 'y'), + (0x1D655, 'M', 'z'), + (0x1D656, 'M', 'a'), + (0x1D657, 'M', 'b'), + (0x1D658, 'M', 'c'), + (0x1D659, 'M', 'd'), + (0x1D65A, 'M', 'e'), + (0x1D65B, 'M', 'f'), + (0x1D65C, 'M', 'g'), + (0x1D65D, 'M', 'h'), + (0x1D65E, 'M', 'i'), + (0x1D65F, 'M', 'j'), + (0x1D660, 'M', 'k'), + (0x1D661, 'M', 'l'), + (0x1D662, 'M', 'm'), + (0x1D663, 'M', 'n'), + (0x1D664, 'M', 'o'), + (0x1D665, 'M', 'p'), + (0x1D666, 'M', 'q'), + (0x1D667, 'M', 'r'), + (0x1D668, 'M', 's'), + (0x1D669, 'M', 't'), + (0x1D66A, 'M', 'u'), + (0x1D66B, 'M', 'v'), + (0x1D66C, 'M', 'w'), + (0x1D66D, 'M', 'x'), + (0x1D66E, 'M', 'y'), + (0x1D66F, 'M', 'z'), + (0x1D670, 'M', 'a'), + (0x1D671, 'M', 'b'), + (0x1D672, 'M', 'c'), + (0x1D673, 'M', 'd'), + (0x1D674, 'M', 'e'), + (0x1D675, 'M', 'f'), + (0x1D676, 'M', 'g'), + (0x1D677, 'M', 'h'), + (0x1D678, 'M', 'i'), + (0x1D679, 'M', 'j'), + (0x1D67A, 'M', 'k'), + (0x1D67B, 'M', 'l'), + (0x1D67C, 'M', 'm'), + (0x1D67D, 'M', 'n'), + (0x1D67E, 'M', 'o'), + (0x1D67F, 'M', 'p'), + (0x1D680, 'M', 'q'), + (0x1D681, 'M', 'r'), + (0x1D682, 'M', 's'), + ] + +def _seg_67() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D683, 'M', 't'), + (0x1D684, 'M', 'u'), + (0x1D685, 'M', 'v'), + (0x1D686, 'M', 'w'), + (0x1D687, 'M', 'x'), + (0x1D688, 'M', 'y'), + (0x1D689, 'M', 'z'), + (0x1D68A, 'M', 'a'), + (0x1D68B, 'M', 'b'), + (0x1D68C, 'M', 'c'), + (0x1D68D, 'M', 'd'), + (0x1D68E, 'M', 'e'), + (0x1D68F, 'M', 'f'), + (0x1D690, 'M', 'g'), + (0x1D691, 'M', 'h'), + (0x1D692, 'M', 'i'), + (0x1D693, 'M', 'j'), + (0x1D694, 'M', 'k'), + (0x1D695, 'M', 'l'), + (0x1D696, 'M', 'm'), + (0x1D697, 'M', 'n'), + (0x1D698, 'M', 'o'), + (0x1D699, 'M', 'p'), + (0x1D69A, 'M', 'q'), + (0x1D69B, 'M', 'r'), + (0x1D69C, 'M', 's'), + (0x1D69D, 'M', 't'), + (0x1D69E, 'M', 'u'), + (0x1D69F, 'M', 'v'), + (0x1D6A0, 'M', 'w'), + (0x1D6A1, 'M', 'x'), + (0x1D6A2, 'M', 'y'), + (0x1D6A3, 'M', 'z'), + (0x1D6A4, 'M', 'ı'), + (0x1D6A5, 'M', 'ȷ'), + (0x1D6A6, 'X'), + (0x1D6A8, 'M', 'α'), + (0x1D6A9, 'M', 'β'), + (0x1D6AA, 'M', 'γ'), + (0x1D6AB, 'M', 'δ'), + (0x1D6AC, 'M', 'ε'), + (0x1D6AD, 'M', 'ζ'), + (0x1D6AE, 'M', 'η'), + (0x1D6AF, 'M', 'θ'), + (0x1D6B0, 'M', 'ι'), + (0x1D6B1, 'M', 'κ'), + (0x1D6B2, 'M', 'λ'), + (0x1D6B3, 'M', 'μ'), + (0x1D6B4, 'M', 'ν'), + (0x1D6B5, 'M', 'ξ'), + (0x1D6B6, 'M', 'ο'), + (0x1D6B7, 'M', 'π'), + (0x1D6B8, 'M', 'ρ'), + (0x1D6B9, 'M', 'θ'), + (0x1D6BA, 'M', 'σ'), + (0x1D6BB, 'M', 'τ'), + (0x1D6BC, 'M', 'υ'), + (0x1D6BD, 'M', 'φ'), + (0x1D6BE, 'M', 'χ'), + (0x1D6BF, 'M', 'ψ'), + (0x1D6C0, 'M', 'ω'), + (0x1D6C1, 'M', '∇'), + (0x1D6C2, 'M', 'α'), + (0x1D6C3, 'M', 'β'), + (0x1D6C4, 'M', 'γ'), + (0x1D6C5, 'M', 'δ'), + (0x1D6C6, 'M', 'ε'), + (0x1D6C7, 'M', 'ζ'), + (0x1D6C8, 'M', 'η'), + (0x1D6C9, 'M', 'θ'), + (0x1D6CA, 'M', 'ι'), + (0x1D6CB, 'M', 'κ'), + (0x1D6CC, 'M', 'λ'), + (0x1D6CD, 'M', 'μ'), + (0x1D6CE, 'M', 'ν'), + (0x1D6CF, 'M', 'ξ'), + (0x1D6D0, 'M', 'ο'), + (0x1D6D1, 'M', 'π'), + (0x1D6D2, 'M', 'ρ'), + (0x1D6D3, 'M', 'σ'), + (0x1D6D5, 'M', 'τ'), + (0x1D6D6, 'M', 'υ'), + (0x1D6D7, 'M', 'φ'), + (0x1D6D8, 'M', 'χ'), + (0x1D6D9, 'M', 'ψ'), + (0x1D6DA, 'M', 'ω'), + (0x1D6DB, 'M', '∂'), + (0x1D6DC, 'M', 'ε'), + (0x1D6DD, 'M', 'θ'), + (0x1D6DE, 'M', 'κ'), + (0x1D6DF, 'M', 'φ'), + (0x1D6E0, 'M', 'ρ'), + (0x1D6E1, 'M', 'π'), + (0x1D6E2, 'M', 'α'), + (0x1D6E3, 'M', 'β'), + (0x1D6E4, 'M', 'γ'), + (0x1D6E5, 'M', 'δ'), + (0x1D6E6, 'M', 'ε'), + (0x1D6E7, 'M', 'ζ'), + (0x1D6E8, 'M', 'η'), + ] + +def _seg_68() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D6E9, 'M', 'θ'), + (0x1D6EA, 'M', 'ι'), + (0x1D6EB, 'M', 'κ'), + (0x1D6EC, 'M', 'λ'), + (0x1D6ED, 'M', 'μ'), + (0x1D6EE, 'M', 'ν'), + (0x1D6EF, 'M', 'ξ'), + (0x1D6F0, 'M', 'ο'), + (0x1D6F1, 'M', 'π'), + (0x1D6F2, 'M', 'ρ'), + (0x1D6F3, 'M', 'θ'), + (0x1D6F4, 'M', 'σ'), + (0x1D6F5, 'M', 'τ'), + (0x1D6F6, 'M', 'υ'), + (0x1D6F7, 'M', 'φ'), + (0x1D6F8, 'M', 'χ'), + (0x1D6F9, 'M', 'ψ'), + (0x1D6FA, 'M', 'ω'), + (0x1D6FB, 'M', '∇'), + (0x1D6FC, 'M', 'α'), + (0x1D6FD, 'M', 'β'), + (0x1D6FE, 'M', 'γ'), + (0x1D6FF, 'M', 'δ'), + (0x1D700, 'M', 'ε'), + (0x1D701, 'M', 'ζ'), + (0x1D702, 'M', 'η'), + (0x1D703, 'M', 'θ'), + (0x1D704, 'M', 'ι'), + (0x1D705, 'M', 'κ'), + (0x1D706, 'M', 'λ'), + (0x1D707, 'M', 'μ'), + (0x1D708, 'M', 'ν'), + (0x1D709, 'M', 'ξ'), + (0x1D70A, 'M', 'ο'), + (0x1D70B, 'M', 'π'), + (0x1D70C, 'M', 'ρ'), + (0x1D70D, 'M', 'σ'), + (0x1D70F, 'M', 'τ'), + (0x1D710, 'M', 'υ'), + (0x1D711, 'M', 'φ'), + (0x1D712, 'M', 'χ'), + (0x1D713, 'M', 'ψ'), + (0x1D714, 'M', 'ω'), + (0x1D715, 'M', '∂'), + (0x1D716, 'M', 'ε'), + (0x1D717, 'M', 'θ'), + (0x1D718, 'M', 'κ'), + (0x1D719, 'M', 'φ'), + (0x1D71A, 'M', 'ρ'), + (0x1D71B, 'M', 'π'), + (0x1D71C, 'M', 'α'), + (0x1D71D, 'M', 'β'), + (0x1D71E, 'M', 'γ'), + (0x1D71F, 'M', 'δ'), + (0x1D720, 'M', 'ε'), + (0x1D721, 'M', 'ζ'), + (0x1D722, 'M', 'η'), + (0x1D723, 'M', 'θ'), + (0x1D724, 'M', 'ι'), + (0x1D725, 'M', 'κ'), + (0x1D726, 'M', 'λ'), + (0x1D727, 'M', 'μ'), + (0x1D728, 'M', 'ν'), + (0x1D729, 'M', 'ξ'), + (0x1D72A, 'M', 'ο'), + (0x1D72B, 'M', 'π'), + (0x1D72C, 'M', 'ρ'), + (0x1D72D, 'M', 'θ'), + (0x1D72E, 'M', 'σ'), + (0x1D72F, 'M', 'τ'), + (0x1D730, 'M', 'υ'), + (0x1D731, 'M', 'φ'), + (0x1D732, 'M', 'χ'), + (0x1D733, 'M', 'ψ'), + (0x1D734, 'M', 'ω'), + (0x1D735, 'M', '∇'), + (0x1D736, 'M', 'α'), + (0x1D737, 'M', 'β'), + (0x1D738, 'M', 'γ'), + (0x1D739, 'M', 'δ'), + (0x1D73A, 'M', 'ε'), + (0x1D73B, 'M', 'ζ'), + (0x1D73C, 'M', 'η'), + (0x1D73D, 'M', 'θ'), + (0x1D73E, 'M', 'ι'), + (0x1D73F, 'M', 'κ'), + (0x1D740, 'M', 'λ'), + (0x1D741, 'M', 'μ'), + (0x1D742, 'M', 'ν'), + (0x1D743, 'M', 'ξ'), + (0x1D744, 'M', 'ο'), + (0x1D745, 'M', 'π'), + (0x1D746, 'M', 'ρ'), + (0x1D747, 'M', 'σ'), + (0x1D749, 'M', 'τ'), + (0x1D74A, 'M', 'υ'), + (0x1D74B, 'M', 'φ'), + (0x1D74C, 'M', 'χ'), + (0x1D74D, 'M', 'ψ'), + (0x1D74E, 'M', 'ω'), + ] + +def _seg_69() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D74F, 'M', '∂'), + (0x1D750, 'M', 'ε'), + (0x1D751, 'M', 'θ'), + (0x1D752, 'M', 'κ'), + (0x1D753, 'M', 'φ'), + (0x1D754, 'M', 'ρ'), + (0x1D755, 'M', 'π'), + (0x1D756, 'M', 'α'), + (0x1D757, 'M', 'β'), + (0x1D758, 'M', 'γ'), + (0x1D759, 'M', 'δ'), + (0x1D75A, 'M', 'ε'), + (0x1D75B, 'M', 'ζ'), + (0x1D75C, 'M', 'η'), + (0x1D75D, 'M', 'θ'), + (0x1D75E, 'M', 'ι'), + (0x1D75F, 'M', 'κ'), + (0x1D760, 'M', 'λ'), + (0x1D761, 'M', 'μ'), + (0x1D762, 'M', 'ν'), + (0x1D763, 'M', 'ξ'), + (0x1D764, 'M', 'ο'), + (0x1D765, 'M', 'π'), + (0x1D766, 'M', 'ρ'), + (0x1D767, 'M', 'θ'), + (0x1D768, 'M', 'σ'), + (0x1D769, 'M', 'τ'), + (0x1D76A, 'M', 'υ'), + (0x1D76B, 'M', 'φ'), + (0x1D76C, 'M', 'χ'), + (0x1D76D, 'M', 'ψ'), + (0x1D76E, 'M', 'ω'), + (0x1D76F, 'M', '∇'), + (0x1D770, 'M', 'α'), + (0x1D771, 'M', 'β'), + (0x1D772, 'M', 'γ'), + (0x1D773, 'M', 'δ'), + (0x1D774, 'M', 'ε'), + (0x1D775, 'M', 'ζ'), + (0x1D776, 'M', 'η'), + (0x1D777, 'M', 'θ'), + (0x1D778, 'M', 'ι'), + (0x1D779, 'M', 'κ'), + (0x1D77A, 'M', 'λ'), + (0x1D77B, 'M', 'μ'), + (0x1D77C, 'M', 'ν'), + (0x1D77D, 'M', 'ξ'), + (0x1D77E, 'M', 'ο'), + (0x1D77F, 'M', 'π'), + (0x1D780, 'M', 'ρ'), + (0x1D781, 'M', 'σ'), + (0x1D783, 'M', 'τ'), + (0x1D784, 'M', 'υ'), + (0x1D785, 'M', 'φ'), + (0x1D786, 'M', 'χ'), + (0x1D787, 'M', 'ψ'), + (0x1D788, 'M', 'ω'), + (0x1D789, 'M', '∂'), + (0x1D78A, 'M', 'ε'), + (0x1D78B, 'M', 'θ'), + (0x1D78C, 'M', 'κ'), + (0x1D78D, 'M', 'φ'), + (0x1D78E, 'M', 'ρ'), + (0x1D78F, 'M', 'π'), + (0x1D790, 'M', 'α'), + (0x1D791, 'M', 'β'), + (0x1D792, 'M', 'γ'), + (0x1D793, 'M', 'δ'), + (0x1D794, 'M', 'ε'), + (0x1D795, 'M', 'ζ'), + (0x1D796, 'M', 'η'), + (0x1D797, 'M', 'θ'), + (0x1D798, 'M', 'ι'), + (0x1D799, 'M', 'κ'), + (0x1D79A, 'M', 'λ'), + (0x1D79B, 'M', 'μ'), + (0x1D79C, 'M', 'ν'), + (0x1D79D, 'M', 'ξ'), + (0x1D79E, 'M', 'ο'), + (0x1D79F, 'M', 'π'), + (0x1D7A0, 'M', 'ρ'), + (0x1D7A1, 'M', 'θ'), + (0x1D7A2, 'M', 'σ'), + (0x1D7A3, 'M', 'τ'), + (0x1D7A4, 'M', 'υ'), + (0x1D7A5, 'M', 'φ'), + (0x1D7A6, 'M', 'χ'), + (0x1D7A7, 'M', 'ψ'), + (0x1D7A8, 'M', 'ω'), + (0x1D7A9, 'M', '∇'), + (0x1D7AA, 'M', 'α'), + (0x1D7AB, 'M', 'β'), + (0x1D7AC, 'M', 'γ'), + (0x1D7AD, 'M', 'δ'), + (0x1D7AE, 'M', 'ε'), + (0x1D7AF, 'M', 'ζ'), + (0x1D7B0, 'M', 'η'), + (0x1D7B1, 'M', 'θ'), + (0x1D7B2, 'M', 'ι'), + (0x1D7B3, 'M', 'κ'), + ] + +def _seg_70() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1D7B4, 'M', 'λ'), + (0x1D7B5, 'M', 'μ'), + (0x1D7B6, 'M', 'ν'), + (0x1D7B7, 'M', 'ξ'), + (0x1D7B8, 'M', 'ο'), + (0x1D7B9, 'M', 'π'), + (0x1D7BA, 'M', 'ρ'), + (0x1D7BB, 'M', 'σ'), + (0x1D7BD, 'M', 'τ'), + (0x1D7BE, 'M', 'υ'), + (0x1D7BF, 'M', 'φ'), + (0x1D7C0, 'M', 'χ'), + (0x1D7C1, 'M', 'ψ'), + (0x1D7C2, 'M', 'ω'), + (0x1D7C3, 'M', '∂'), + (0x1D7C4, 'M', 'ε'), + (0x1D7C5, 'M', 'θ'), + (0x1D7C6, 'M', 'κ'), + (0x1D7C7, 'M', 'φ'), + (0x1D7C8, 'M', 'ρ'), + (0x1D7C9, 'M', 'π'), + (0x1D7CA, 'M', 'ϝ'), + (0x1D7CC, 'X'), + (0x1D7CE, 'M', '0'), + (0x1D7CF, 'M', '1'), + (0x1D7D0, 'M', '2'), + (0x1D7D1, 'M', '3'), + (0x1D7D2, 'M', '4'), + (0x1D7D3, 'M', '5'), + (0x1D7D4, 'M', '6'), + (0x1D7D5, 'M', '7'), + (0x1D7D6, 'M', '8'), + (0x1D7D7, 'M', '9'), + (0x1D7D8, 'M', '0'), + (0x1D7D9, 'M', '1'), + (0x1D7DA, 'M', '2'), + (0x1D7DB, 'M', '3'), + (0x1D7DC, 'M', '4'), + (0x1D7DD, 'M', '5'), + (0x1D7DE, 'M', '6'), + (0x1D7DF, 'M', '7'), + (0x1D7E0, 'M', '8'), + (0x1D7E1, 'M', '9'), + (0x1D7E2, 'M', '0'), + (0x1D7E3, 'M', '1'), + (0x1D7E4, 'M', '2'), + (0x1D7E5, 'M', '3'), + (0x1D7E6, 'M', '4'), + (0x1D7E7, 'M', '5'), + (0x1D7E8, 'M', '6'), + (0x1D7E9, 'M', '7'), + (0x1D7EA, 'M', '8'), + (0x1D7EB, 'M', '9'), + (0x1D7EC, 'M', '0'), + (0x1D7ED, 'M', '1'), + (0x1D7EE, 'M', '2'), + (0x1D7EF, 'M', '3'), + (0x1D7F0, 'M', '4'), + (0x1D7F1, 'M', '5'), + (0x1D7F2, 'M', '6'), + (0x1D7F3, 'M', '7'), + (0x1D7F4, 'M', '8'), + (0x1D7F5, 'M', '9'), + (0x1D7F6, 'M', '0'), + (0x1D7F7, 'M', '1'), + (0x1D7F8, 'M', '2'), + (0x1D7F9, 'M', '3'), + (0x1D7FA, 'M', '4'), + (0x1D7FB, 'M', '5'), + (0x1D7FC, 'M', '6'), + (0x1D7FD, 'M', '7'), + (0x1D7FE, 'M', '8'), + (0x1D7FF, 'M', '9'), + (0x1D800, 'V'), + (0x1DA8C, 'X'), + (0x1DA9B, 'V'), + (0x1DAA0, 'X'), + (0x1DAA1, 'V'), + (0x1DAB0, 'X'), + (0x1DF00, 'V'), + (0x1DF1F, 'X'), + (0x1DF25, 'V'), + (0x1DF2B, 'X'), + (0x1E000, 'V'), + (0x1E007, 'X'), + (0x1E008, 'V'), + (0x1E019, 'X'), + (0x1E01B, 'V'), + (0x1E022, 'X'), + (0x1E023, 'V'), + (0x1E025, 'X'), + (0x1E026, 'V'), + (0x1E02B, 'X'), + (0x1E030, 'M', 'а'), + (0x1E031, 'M', 'б'), + (0x1E032, 'M', 'в'), + (0x1E033, 'M', 'г'), + (0x1E034, 'M', 'д'), + (0x1E035, 'M', 'е'), + (0x1E036, 'M', 'ж'), + ] + +def _seg_71() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1E037, 'M', 'з'), + (0x1E038, 'M', 'и'), + (0x1E039, 'M', 'к'), + (0x1E03A, 'M', 'л'), + (0x1E03B, 'M', 'м'), + (0x1E03C, 'M', 'о'), + (0x1E03D, 'M', 'п'), + (0x1E03E, 'M', 'р'), + (0x1E03F, 'M', 'с'), + (0x1E040, 'M', 'т'), + (0x1E041, 'M', 'у'), + (0x1E042, 'M', 'ф'), + (0x1E043, 'M', 'х'), + (0x1E044, 'M', 'ц'), + (0x1E045, 'M', 'ч'), + (0x1E046, 'M', 'ш'), + (0x1E047, 'M', 'ы'), + (0x1E048, 'M', 'э'), + (0x1E049, 'M', 'ю'), + (0x1E04A, 'M', 'ꚉ'), + (0x1E04B, 'M', 'ә'), + (0x1E04C, 'M', 'і'), + (0x1E04D, 'M', 'ј'), + (0x1E04E, 'M', 'ө'), + (0x1E04F, 'M', 'ү'), + (0x1E050, 'M', 'ӏ'), + (0x1E051, 'M', 'а'), + (0x1E052, 'M', 'б'), + (0x1E053, 'M', 'в'), + (0x1E054, 'M', 'г'), + (0x1E055, 'M', 'д'), + (0x1E056, 'M', 'е'), + (0x1E057, 'M', 'ж'), + (0x1E058, 'M', 'з'), + (0x1E059, 'M', 'и'), + (0x1E05A, 'M', 'к'), + (0x1E05B, 'M', 'л'), + (0x1E05C, 'M', 'о'), + (0x1E05D, 'M', 'п'), + (0x1E05E, 'M', 'с'), + (0x1E05F, 'M', 'у'), + (0x1E060, 'M', 'ф'), + (0x1E061, 'M', 'х'), + (0x1E062, 'M', 'ц'), + (0x1E063, 'M', 'ч'), + (0x1E064, 'M', 'ш'), + (0x1E065, 'M', 'ъ'), + (0x1E066, 'M', 'ы'), + (0x1E067, 'M', 'ґ'), + (0x1E068, 'M', 'і'), + (0x1E069, 'M', 'ѕ'), + (0x1E06A, 'M', 'џ'), + (0x1E06B, 'M', 'ҫ'), + (0x1E06C, 'M', 'ꙑ'), + (0x1E06D, 'M', 'ұ'), + (0x1E06E, 'X'), + (0x1E08F, 'V'), + (0x1E090, 'X'), + (0x1E100, 'V'), + (0x1E12D, 'X'), + (0x1E130, 'V'), + (0x1E13E, 'X'), + (0x1E140, 'V'), + (0x1E14A, 'X'), + (0x1E14E, 'V'), + (0x1E150, 'X'), + (0x1E290, 'V'), + (0x1E2AF, 'X'), + (0x1E2C0, 'V'), + (0x1E2FA, 'X'), + (0x1E2FF, 'V'), + (0x1E300, 'X'), + (0x1E4D0, 'V'), + (0x1E4FA, 'X'), + (0x1E7E0, 'V'), + (0x1E7E7, 'X'), + (0x1E7E8, 'V'), + (0x1E7EC, 'X'), + (0x1E7ED, 'V'), + (0x1E7EF, 'X'), + (0x1E7F0, 'V'), + (0x1E7FF, 'X'), + (0x1E800, 'V'), + (0x1E8C5, 'X'), + (0x1E8C7, 'V'), + (0x1E8D7, 'X'), + (0x1E900, 'M', '𞤢'), + (0x1E901, 'M', '𞤣'), + (0x1E902, 'M', '𞤤'), + (0x1E903, 'M', '𞤥'), + (0x1E904, 'M', '𞤦'), + (0x1E905, 'M', '𞤧'), + (0x1E906, 'M', '𞤨'), + (0x1E907, 'M', '𞤩'), + (0x1E908, 'M', '𞤪'), + (0x1E909, 'M', '𞤫'), + (0x1E90A, 'M', '𞤬'), + (0x1E90B, 'M', '𞤭'), + (0x1E90C, 'M', '𞤮'), + (0x1E90D, 'M', '𞤯'), + ] + +def _seg_72() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1E90E, 'M', '𞤰'), + (0x1E90F, 'M', '𞤱'), + (0x1E910, 'M', '𞤲'), + (0x1E911, 'M', '𞤳'), + (0x1E912, 'M', '𞤴'), + (0x1E913, 'M', '𞤵'), + (0x1E914, 'M', '𞤶'), + (0x1E915, 'M', '𞤷'), + (0x1E916, 'M', '𞤸'), + (0x1E917, 'M', '𞤹'), + (0x1E918, 'M', '𞤺'), + (0x1E919, 'M', '𞤻'), + (0x1E91A, 'M', '𞤼'), + (0x1E91B, 'M', '𞤽'), + (0x1E91C, 'M', '𞤾'), + (0x1E91D, 'M', '𞤿'), + (0x1E91E, 'M', '𞥀'), + (0x1E91F, 'M', '𞥁'), + (0x1E920, 'M', '𞥂'), + (0x1E921, 'M', '𞥃'), + (0x1E922, 'V'), + (0x1E94C, 'X'), + (0x1E950, 'V'), + (0x1E95A, 'X'), + (0x1E95E, 'V'), + (0x1E960, 'X'), + (0x1EC71, 'V'), + (0x1ECB5, 'X'), + (0x1ED01, 'V'), + (0x1ED3E, 'X'), + (0x1EE00, 'M', 'ا'), + (0x1EE01, 'M', 'ب'), + (0x1EE02, 'M', 'ج'), + (0x1EE03, 'M', 'د'), + (0x1EE04, 'X'), + (0x1EE05, 'M', 'و'), + (0x1EE06, 'M', 'ز'), + (0x1EE07, 'M', 'ح'), + (0x1EE08, 'M', 'ط'), + (0x1EE09, 'M', 'ي'), + (0x1EE0A, 'M', 'ك'), + (0x1EE0B, 'M', 'ل'), + (0x1EE0C, 'M', 'م'), + (0x1EE0D, 'M', 'ن'), + (0x1EE0E, 'M', 'س'), + (0x1EE0F, 'M', 'ع'), + (0x1EE10, 'M', 'ف'), + (0x1EE11, 'M', 'ص'), + (0x1EE12, 'M', 'ق'), + (0x1EE13, 'M', 'ر'), + (0x1EE14, 'M', 'ش'), + (0x1EE15, 'M', 'ت'), + (0x1EE16, 'M', 'ث'), + (0x1EE17, 'M', 'خ'), + (0x1EE18, 'M', 'ذ'), + (0x1EE19, 'M', 'ض'), + (0x1EE1A, 'M', 'ظ'), + (0x1EE1B, 'M', 'غ'), + (0x1EE1C, 'M', 'ٮ'), + (0x1EE1D, 'M', 'ں'), + (0x1EE1E, 'M', 'ڡ'), + (0x1EE1F, 'M', 'ٯ'), + (0x1EE20, 'X'), + (0x1EE21, 'M', 'ب'), + (0x1EE22, 'M', 'ج'), + (0x1EE23, 'X'), + (0x1EE24, 'M', 'ه'), + (0x1EE25, 'X'), + (0x1EE27, 'M', 'ح'), + (0x1EE28, 'X'), + (0x1EE29, 'M', 'ي'), + (0x1EE2A, 'M', 'ك'), + (0x1EE2B, 'M', 'ل'), + (0x1EE2C, 'M', 'م'), + (0x1EE2D, 'M', 'ن'), + (0x1EE2E, 'M', 'س'), + (0x1EE2F, 'M', 'ع'), + (0x1EE30, 'M', 'ف'), + (0x1EE31, 'M', 'ص'), + (0x1EE32, 'M', 'ق'), + (0x1EE33, 'X'), + (0x1EE34, 'M', 'ش'), + (0x1EE35, 'M', 'ت'), + (0x1EE36, 'M', 'ث'), + (0x1EE37, 'M', 'خ'), + (0x1EE38, 'X'), + (0x1EE39, 'M', 'ض'), + (0x1EE3A, 'X'), + (0x1EE3B, 'M', 'غ'), + (0x1EE3C, 'X'), + (0x1EE42, 'M', 'ج'), + (0x1EE43, 'X'), + (0x1EE47, 'M', 'ح'), + (0x1EE48, 'X'), + (0x1EE49, 'M', 'ي'), + (0x1EE4A, 'X'), + (0x1EE4B, 'M', 'ل'), + (0x1EE4C, 'X'), + (0x1EE4D, 'M', 'ن'), + (0x1EE4E, 'M', 'س'), + ] + +def _seg_73() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1EE4F, 'M', 'ع'), + (0x1EE50, 'X'), + (0x1EE51, 'M', 'ص'), + (0x1EE52, 'M', 'ق'), + (0x1EE53, 'X'), + (0x1EE54, 'M', 'ش'), + (0x1EE55, 'X'), + (0x1EE57, 'M', 'خ'), + (0x1EE58, 'X'), + (0x1EE59, 'M', 'ض'), + (0x1EE5A, 'X'), + (0x1EE5B, 'M', 'غ'), + (0x1EE5C, 'X'), + (0x1EE5D, 'M', 'ں'), + (0x1EE5E, 'X'), + (0x1EE5F, 'M', 'ٯ'), + (0x1EE60, 'X'), + (0x1EE61, 'M', 'ب'), + (0x1EE62, 'M', 'ج'), + (0x1EE63, 'X'), + (0x1EE64, 'M', 'ه'), + (0x1EE65, 'X'), + (0x1EE67, 'M', 'ح'), + (0x1EE68, 'M', 'ط'), + (0x1EE69, 'M', 'ي'), + (0x1EE6A, 'M', 'ك'), + (0x1EE6B, 'X'), + (0x1EE6C, 'M', 'م'), + (0x1EE6D, 'M', 'ن'), + (0x1EE6E, 'M', 'س'), + (0x1EE6F, 'M', 'ع'), + (0x1EE70, 'M', 'ف'), + (0x1EE71, 'M', 'ص'), + (0x1EE72, 'M', 'ق'), + (0x1EE73, 'X'), + (0x1EE74, 'M', 'ش'), + (0x1EE75, 'M', 'ت'), + (0x1EE76, 'M', 'ث'), + (0x1EE77, 'M', 'خ'), + (0x1EE78, 'X'), + (0x1EE79, 'M', 'ض'), + (0x1EE7A, 'M', 'ظ'), + (0x1EE7B, 'M', 'غ'), + (0x1EE7C, 'M', 'ٮ'), + (0x1EE7D, 'X'), + (0x1EE7E, 'M', 'ڡ'), + (0x1EE7F, 'X'), + (0x1EE80, 'M', 'ا'), + (0x1EE81, 'M', 'ب'), + (0x1EE82, 'M', 'ج'), + (0x1EE83, 'M', 'د'), + (0x1EE84, 'M', 'ه'), + (0x1EE85, 'M', 'و'), + (0x1EE86, 'M', 'ز'), + (0x1EE87, 'M', 'ح'), + (0x1EE88, 'M', 'ط'), + (0x1EE89, 'M', 'ي'), + (0x1EE8A, 'X'), + (0x1EE8B, 'M', 'ل'), + (0x1EE8C, 'M', 'م'), + (0x1EE8D, 'M', 'ن'), + (0x1EE8E, 'M', 'س'), + (0x1EE8F, 'M', 'ع'), + (0x1EE90, 'M', 'ف'), + (0x1EE91, 'M', 'ص'), + (0x1EE92, 'M', 'ق'), + (0x1EE93, 'M', 'ر'), + (0x1EE94, 'M', 'ش'), + (0x1EE95, 'M', 'ت'), + (0x1EE96, 'M', 'ث'), + (0x1EE97, 'M', 'خ'), + (0x1EE98, 'M', 'ذ'), + (0x1EE99, 'M', 'ض'), + (0x1EE9A, 'M', 'ظ'), + (0x1EE9B, 'M', 'غ'), + (0x1EE9C, 'X'), + (0x1EEA1, 'M', 'ب'), + (0x1EEA2, 'M', 'ج'), + (0x1EEA3, 'M', 'د'), + (0x1EEA4, 'X'), + (0x1EEA5, 'M', 'و'), + (0x1EEA6, 'M', 'ز'), + (0x1EEA7, 'M', 'ح'), + (0x1EEA8, 'M', 'ط'), + (0x1EEA9, 'M', 'ي'), + (0x1EEAA, 'X'), + (0x1EEAB, 'M', 'ل'), + (0x1EEAC, 'M', 'م'), + (0x1EEAD, 'M', 'ن'), + (0x1EEAE, 'M', 'س'), + (0x1EEAF, 'M', 'ع'), + (0x1EEB0, 'M', 'ف'), + (0x1EEB1, 'M', 'ص'), + (0x1EEB2, 'M', 'ق'), + (0x1EEB3, 'M', 'ر'), + (0x1EEB4, 'M', 'ش'), + (0x1EEB5, 'M', 'ت'), + (0x1EEB6, 'M', 'ث'), + (0x1EEB7, 'M', 'خ'), + (0x1EEB8, 'M', 'ذ'), + ] + +def _seg_74() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1EEB9, 'M', 'ض'), + (0x1EEBA, 'M', 'ظ'), + (0x1EEBB, 'M', 'غ'), + (0x1EEBC, 'X'), + (0x1EEF0, 'V'), + (0x1EEF2, 'X'), + (0x1F000, 'V'), + (0x1F02C, 'X'), + (0x1F030, 'V'), + (0x1F094, 'X'), + (0x1F0A0, 'V'), + (0x1F0AF, 'X'), + (0x1F0B1, 'V'), + (0x1F0C0, 'X'), + (0x1F0C1, 'V'), + (0x1F0D0, 'X'), + (0x1F0D1, 'V'), + (0x1F0F6, 'X'), + (0x1F101, '3', '0,'), + (0x1F102, '3', '1,'), + (0x1F103, '3', '2,'), + (0x1F104, '3', '3,'), + (0x1F105, '3', '4,'), + (0x1F106, '3', '5,'), + (0x1F107, '3', '6,'), + (0x1F108, '3', '7,'), + (0x1F109, '3', '8,'), + (0x1F10A, '3', '9,'), + (0x1F10B, 'V'), + (0x1F110, '3', '(a)'), + (0x1F111, '3', '(b)'), + (0x1F112, '3', '(c)'), + (0x1F113, '3', '(d)'), + (0x1F114, '3', '(e)'), + (0x1F115, '3', '(f)'), + (0x1F116, '3', '(g)'), + (0x1F117, '3', '(h)'), + (0x1F118, '3', '(i)'), + (0x1F119, '3', '(j)'), + (0x1F11A, '3', '(k)'), + (0x1F11B, '3', '(l)'), + (0x1F11C, '3', '(m)'), + (0x1F11D, '3', '(n)'), + (0x1F11E, '3', '(o)'), + (0x1F11F, '3', '(p)'), + (0x1F120, '3', '(q)'), + (0x1F121, '3', '(r)'), + (0x1F122, '3', '(s)'), + (0x1F123, '3', '(t)'), + (0x1F124, '3', '(u)'), + (0x1F125, '3', '(v)'), + (0x1F126, '3', '(w)'), + (0x1F127, '3', '(x)'), + (0x1F128, '3', '(y)'), + (0x1F129, '3', '(z)'), + (0x1F12A, 'M', '〔s〕'), + (0x1F12B, 'M', 'c'), + (0x1F12C, 'M', 'r'), + (0x1F12D, 'M', 'cd'), + (0x1F12E, 'M', 'wz'), + (0x1F12F, 'V'), + (0x1F130, 'M', 'a'), + (0x1F131, 'M', 'b'), + (0x1F132, 'M', 'c'), + (0x1F133, 'M', 'd'), + (0x1F134, 'M', 'e'), + (0x1F135, 'M', 'f'), + (0x1F136, 'M', 'g'), + (0x1F137, 'M', 'h'), + (0x1F138, 'M', 'i'), + (0x1F139, 'M', 'j'), + (0x1F13A, 'M', 'k'), + (0x1F13B, 'M', 'l'), + (0x1F13C, 'M', 'm'), + (0x1F13D, 'M', 'n'), + (0x1F13E, 'M', 'o'), + (0x1F13F, 'M', 'p'), + (0x1F140, 'M', 'q'), + (0x1F141, 'M', 'r'), + (0x1F142, 'M', 's'), + (0x1F143, 'M', 't'), + (0x1F144, 'M', 'u'), + (0x1F145, 'M', 'v'), + (0x1F146, 'M', 'w'), + (0x1F147, 'M', 'x'), + (0x1F148, 'M', 'y'), + (0x1F149, 'M', 'z'), + (0x1F14A, 'M', 'hv'), + (0x1F14B, 'M', 'mv'), + (0x1F14C, 'M', 'sd'), + (0x1F14D, 'M', 'ss'), + (0x1F14E, 'M', 'ppv'), + (0x1F14F, 'M', 'wc'), + (0x1F150, 'V'), + (0x1F16A, 'M', 'mc'), + (0x1F16B, 'M', 'md'), + (0x1F16C, 'M', 'mr'), + (0x1F16D, 'V'), + (0x1F190, 'M', 'dj'), + (0x1F191, 'V'), + ] + +def _seg_75() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1F1AE, 'X'), + (0x1F1E6, 'V'), + (0x1F200, 'M', 'ほか'), + (0x1F201, 'M', 'ココ'), + (0x1F202, 'M', 'サ'), + (0x1F203, 'X'), + (0x1F210, 'M', '手'), + (0x1F211, 'M', '字'), + (0x1F212, 'M', '双'), + (0x1F213, 'M', 'デ'), + (0x1F214, 'M', '二'), + (0x1F215, 'M', '多'), + (0x1F216, 'M', '解'), + (0x1F217, 'M', '天'), + (0x1F218, 'M', '交'), + (0x1F219, 'M', '映'), + (0x1F21A, 'M', '無'), + (0x1F21B, 'M', '料'), + (0x1F21C, 'M', '前'), + (0x1F21D, 'M', '後'), + (0x1F21E, 'M', '再'), + (0x1F21F, 'M', '新'), + (0x1F220, 'M', '初'), + (0x1F221, 'M', '終'), + (0x1F222, 'M', '生'), + (0x1F223, 'M', '販'), + (0x1F224, 'M', '声'), + (0x1F225, 'M', '吹'), + (0x1F226, 'M', '演'), + (0x1F227, 'M', '投'), + (0x1F228, 'M', '捕'), + (0x1F229, 'M', '一'), + (0x1F22A, 'M', '三'), + (0x1F22B, 'M', '遊'), + (0x1F22C, 'M', '左'), + (0x1F22D, 'M', '中'), + (0x1F22E, 'M', '右'), + (0x1F22F, 'M', '指'), + (0x1F230, 'M', '走'), + (0x1F231, 'M', '打'), + (0x1F232, 'M', '禁'), + (0x1F233, 'M', '空'), + (0x1F234, 'M', '合'), + (0x1F235, 'M', '満'), + (0x1F236, 'M', '有'), + (0x1F237, 'M', '月'), + (0x1F238, 'M', '申'), + (0x1F239, 'M', '割'), + (0x1F23A, 'M', '営'), + (0x1F23B, 'M', '配'), + (0x1F23C, 'X'), + (0x1F240, 'M', '〔本〕'), + (0x1F241, 'M', '〔三〕'), + (0x1F242, 'M', '〔二〕'), + (0x1F243, 'M', '〔安〕'), + (0x1F244, 'M', '〔点〕'), + (0x1F245, 'M', '〔打〕'), + (0x1F246, 'M', '〔盗〕'), + (0x1F247, 'M', '〔勝〕'), + (0x1F248, 'M', '〔敗〕'), + (0x1F249, 'X'), + (0x1F250, 'M', '得'), + (0x1F251, 'M', '可'), + (0x1F252, 'X'), + (0x1F260, 'V'), + (0x1F266, 'X'), + (0x1F300, 'V'), + (0x1F6D8, 'X'), + (0x1F6DC, 'V'), + (0x1F6ED, 'X'), + (0x1F6F0, 'V'), + (0x1F6FD, 'X'), + (0x1F700, 'V'), + (0x1F777, 'X'), + (0x1F77B, 'V'), + (0x1F7DA, 'X'), + (0x1F7E0, 'V'), + (0x1F7EC, 'X'), + (0x1F7F0, 'V'), + (0x1F7F1, 'X'), + (0x1F800, 'V'), + (0x1F80C, 'X'), + (0x1F810, 'V'), + (0x1F848, 'X'), + (0x1F850, 'V'), + (0x1F85A, 'X'), + (0x1F860, 'V'), + (0x1F888, 'X'), + (0x1F890, 'V'), + (0x1F8AE, 'X'), + (0x1F8B0, 'V'), + (0x1F8B2, 'X'), + (0x1F900, 'V'), + (0x1FA54, 'X'), + (0x1FA60, 'V'), + (0x1FA6E, 'X'), + (0x1FA70, 'V'), + (0x1FA7D, 'X'), + (0x1FA80, 'V'), + (0x1FA89, 'X'), + ] + +def _seg_76() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x1FA90, 'V'), + (0x1FABE, 'X'), + (0x1FABF, 'V'), + (0x1FAC6, 'X'), + (0x1FACE, 'V'), + (0x1FADC, 'X'), + (0x1FAE0, 'V'), + (0x1FAE9, 'X'), + (0x1FAF0, 'V'), + (0x1FAF9, 'X'), + (0x1FB00, 'V'), + (0x1FB93, 'X'), + (0x1FB94, 'V'), + (0x1FBCB, 'X'), + (0x1FBF0, 'M', '0'), + (0x1FBF1, 'M', '1'), + (0x1FBF2, 'M', '2'), + (0x1FBF3, 'M', '3'), + (0x1FBF4, 'M', '4'), + (0x1FBF5, 'M', '5'), + (0x1FBF6, 'M', '6'), + (0x1FBF7, 'M', '7'), + (0x1FBF8, 'M', '8'), + (0x1FBF9, 'M', '9'), + (0x1FBFA, 'X'), + (0x20000, 'V'), + (0x2A6E0, 'X'), + (0x2A700, 'V'), + (0x2B73A, 'X'), + (0x2B740, 'V'), + (0x2B81E, 'X'), + (0x2B820, 'V'), + (0x2CEA2, 'X'), + (0x2CEB0, 'V'), + (0x2EBE1, 'X'), + (0x2EBF0, 'V'), + (0x2EE5E, 'X'), + (0x2F800, 'M', '丽'), + (0x2F801, 'M', '丸'), + (0x2F802, 'M', '乁'), + (0x2F803, 'M', '𠄢'), + (0x2F804, 'M', '你'), + (0x2F805, 'M', '侮'), + (0x2F806, 'M', '侻'), + (0x2F807, 'M', '倂'), + (0x2F808, 'M', '偺'), + (0x2F809, 'M', '備'), + (0x2F80A, 'M', '僧'), + (0x2F80B, 'M', '像'), + (0x2F80C, 'M', '㒞'), + (0x2F80D, 'M', '𠘺'), + (0x2F80E, 'M', '免'), + (0x2F80F, 'M', '兔'), + (0x2F810, 'M', '兤'), + (0x2F811, 'M', '具'), + (0x2F812, 'M', '𠔜'), + (0x2F813, 'M', '㒹'), + (0x2F814, 'M', '內'), + (0x2F815, 'M', '再'), + (0x2F816, 'M', '𠕋'), + (0x2F817, 'M', '冗'), + (0x2F818, 'M', '冤'), + (0x2F819, 'M', '仌'), + (0x2F81A, 'M', '冬'), + (0x2F81B, 'M', '况'), + (0x2F81C, 'M', '𩇟'), + (0x2F81D, 'M', '凵'), + (0x2F81E, 'M', '刃'), + (0x2F81F, 'M', '㓟'), + (0x2F820, 'M', '刻'), + (0x2F821, 'M', '剆'), + (0x2F822, 'M', '割'), + (0x2F823, 'M', '剷'), + (0x2F824, 'M', '㔕'), + (0x2F825, 'M', '勇'), + (0x2F826, 'M', '勉'), + (0x2F827, 'M', '勤'), + (0x2F828, 'M', '勺'), + (0x2F829, 'M', '包'), + (0x2F82A, 'M', '匆'), + (0x2F82B, 'M', '北'), + (0x2F82C, 'M', '卉'), + (0x2F82D, 'M', '卑'), + (0x2F82E, 'M', '博'), + (0x2F82F, 'M', '即'), + (0x2F830, 'M', '卽'), + (0x2F831, 'M', '卿'), + (0x2F834, 'M', '𠨬'), + (0x2F835, 'M', '灰'), + (0x2F836, 'M', '及'), + (0x2F837, 'M', '叟'), + (0x2F838, 'M', '𠭣'), + (0x2F839, 'M', '叫'), + (0x2F83A, 'M', '叱'), + (0x2F83B, 'M', '吆'), + (0x2F83C, 'M', '咞'), + (0x2F83D, 'M', '吸'), + (0x2F83E, 'M', '呈'), + (0x2F83F, 'M', '周'), + (0x2F840, 'M', '咢'), + ] + +def _seg_77() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2F841, 'M', '哶'), + (0x2F842, 'M', '唐'), + (0x2F843, 'M', '啓'), + (0x2F844, 'M', '啣'), + (0x2F845, 'M', '善'), + (0x2F847, 'M', '喙'), + (0x2F848, 'M', '喫'), + (0x2F849, 'M', '喳'), + (0x2F84A, 'M', '嗂'), + (0x2F84B, 'M', '圖'), + (0x2F84C, 'M', '嘆'), + (0x2F84D, 'M', '圗'), + (0x2F84E, 'M', '噑'), + (0x2F84F, 'M', '噴'), + (0x2F850, 'M', '切'), + (0x2F851, 'M', '壮'), + (0x2F852, 'M', '城'), + (0x2F853, 'M', '埴'), + (0x2F854, 'M', '堍'), + (0x2F855, 'M', '型'), + (0x2F856, 'M', '堲'), + (0x2F857, 'M', '報'), + (0x2F858, 'M', '墬'), + (0x2F859, 'M', '𡓤'), + (0x2F85A, 'M', '売'), + (0x2F85B, 'M', '壷'), + (0x2F85C, 'M', '夆'), + (0x2F85D, 'M', '多'), + (0x2F85E, 'M', '夢'), + (0x2F85F, 'M', '奢'), + (0x2F860, 'M', '𡚨'), + (0x2F861, 'M', '𡛪'), + (0x2F862, 'M', '姬'), + (0x2F863, 'M', '娛'), + (0x2F864, 'M', '娧'), + (0x2F865, 'M', '姘'), + (0x2F866, 'M', '婦'), + (0x2F867, 'M', '㛮'), + (0x2F868, 'X'), + (0x2F869, 'M', '嬈'), + (0x2F86A, 'M', '嬾'), + (0x2F86C, 'M', '𡧈'), + (0x2F86D, 'M', '寃'), + (0x2F86E, 'M', '寘'), + (0x2F86F, 'M', '寧'), + (0x2F870, 'M', '寳'), + (0x2F871, 'M', '𡬘'), + (0x2F872, 'M', '寿'), + (0x2F873, 'M', '将'), + (0x2F874, 'X'), + (0x2F875, 'M', '尢'), + (0x2F876, 'M', '㞁'), + (0x2F877, 'M', '屠'), + (0x2F878, 'M', '屮'), + (0x2F879, 'M', '峀'), + (0x2F87A, 'M', '岍'), + (0x2F87B, 'M', '𡷤'), + (0x2F87C, 'M', '嵃'), + (0x2F87D, 'M', '𡷦'), + (0x2F87E, 'M', '嵮'), + (0x2F87F, 'M', '嵫'), + (0x2F880, 'M', '嵼'), + (0x2F881, 'M', '巡'), + (0x2F882, 'M', '巢'), + (0x2F883, 'M', '㠯'), + (0x2F884, 'M', '巽'), + (0x2F885, 'M', '帨'), + (0x2F886, 'M', '帽'), + (0x2F887, 'M', '幩'), + (0x2F888, 'M', '㡢'), + (0x2F889, 'M', '𢆃'), + (0x2F88A, 'M', '㡼'), + (0x2F88B, 'M', '庰'), + (0x2F88C, 'M', '庳'), + (0x2F88D, 'M', '庶'), + (0x2F88E, 'M', '廊'), + (0x2F88F, 'M', '𪎒'), + (0x2F890, 'M', '廾'), + (0x2F891, 'M', '𢌱'), + (0x2F893, 'M', '舁'), + (0x2F894, 'M', '弢'), + (0x2F896, 'M', '㣇'), + (0x2F897, 'M', '𣊸'), + (0x2F898, 'M', '𦇚'), + (0x2F899, 'M', '形'), + (0x2F89A, 'M', '彫'), + (0x2F89B, 'M', '㣣'), + (0x2F89C, 'M', '徚'), + (0x2F89D, 'M', '忍'), + (0x2F89E, 'M', '志'), + (0x2F89F, 'M', '忹'), + (0x2F8A0, 'M', '悁'), + (0x2F8A1, 'M', '㤺'), + (0x2F8A2, 'M', '㤜'), + (0x2F8A3, 'M', '悔'), + (0x2F8A4, 'M', '𢛔'), + (0x2F8A5, 'M', '惇'), + (0x2F8A6, 'M', '慈'), + (0x2F8A7, 'M', '慌'), + (0x2F8A8, 'M', '慎'), + ] + +def _seg_78() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2F8A9, 'M', '慌'), + (0x2F8AA, 'M', '慺'), + (0x2F8AB, 'M', '憎'), + (0x2F8AC, 'M', '憲'), + (0x2F8AD, 'M', '憤'), + (0x2F8AE, 'M', '憯'), + (0x2F8AF, 'M', '懞'), + (0x2F8B0, 'M', '懲'), + (0x2F8B1, 'M', '懶'), + (0x2F8B2, 'M', '成'), + (0x2F8B3, 'M', '戛'), + (0x2F8B4, 'M', '扝'), + (0x2F8B5, 'M', '抱'), + (0x2F8B6, 'M', '拔'), + (0x2F8B7, 'M', '捐'), + (0x2F8B8, 'M', '𢬌'), + (0x2F8B9, 'M', '挽'), + (0x2F8BA, 'M', '拼'), + (0x2F8BB, 'M', '捨'), + (0x2F8BC, 'M', '掃'), + (0x2F8BD, 'M', '揤'), + (0x2F8BE, 'M', '𢯱'), + (0x2F8BF, 'M', '搢'), + (0x2F8C0, 'M', '揅'), + (0x2F8C1, 'M', '掩'), + (0x2F8C2, 'M', '㨮'), + (0x2F8C3, 'M', '摩'), + (0x2F8C4, 'M', '摾'), + (0x2F8C5, 'M', '撝'), + (0x2F8C6, 'M', '摷'), + (0x2F8C7, 'M', '㩬'), + (0x2F8C8, 'M', '敏'), + (0x2F8C9, 'M', '敬'), + (0x2F8CA, 'M', '𣀊'), + (0x2F8CB, 'M', '旣'), + (0x2F8CC, 'M', '書'), + (0x2F8CD, 'M', '晉'), + (0x2F8CE, 'M', '㬙'), + (0x2F8CF, 'M', '暑'), + (0x2F8D0, 'M', '㬈'), + (0x2F8D1, 'M', '㫤'), + (0x2F8D2, 'M', '冒'), + (0x2F8D3, 'M', '冕'), + (0x2F8D4, 'M', '最'), + (0x2F8D5, 'M', '暜'), + (0x2F8D6, 'M', '肭'), + (0x2F8D7, 'M', '䏙'), + (0x2F8D8, 'M', '朗'), + (0x2F8D9, 'M', '望'), + (0x2F8DA, 'M', '朡'), + (0x2F8DB, 'M', '杞'), + (0x2F8DC, 'M', '杓'), + (0x2F8DD, 'M', '𣏃'), + (0x2F8DE, 'M', '㭉'), + (0x2F8DF, 'M', '柺'), + (0x2F8E0, 'M', '枅'), + (0x2F8E1, 'M', '桒'), + (0x2F8E2, 'M', '梅'), + (0x2F8E3, 'M', '𣑭'), + (0x2F8E4, 'M', '梎'), + (0x2F8E5, 'M', '栟'), + (0x2F8E6, 'M', '椔'), + (0x2F8E7, 'M', '㮝'), + (0x2F8E8, 'M', '楂'), + (0x2F8E9, 'M', '榣'), + (0x2F8EA, 'M', '槪'), + (0x2F8EB, 'M', '檨'), + (0x2F8EC, 'M', '𣚣'), + (0x2F8ED, 'M', '櫛'), + (0x2F8EE, 'M', '㰘'), + (0x2F8EF, 'M', '次'), + (0x2F8F0, 'M', '𣢧'), + (0x2F8F1, 'M', '歔'), + (0x2F8F2, 'M', '㱎'), + (0x2F8F3, 'M', '歲'), + (0x2F8F4, 'M', '殟'), + (0x2F8F5, 'M', '殺'), + (0x2F8F6, 'M', '殻'), + (0x2F8F7, 'M', '𣪍'), + (0x2F8F8, 'M', '𡴋'), + (0x2F8F9, 'M', '𣫺'), + (0x2F8FA, 'M', '汎'), + (0x2F8FB, 'M', '𣲼'), + (0x2F8FC, 'M', '沿'), + (0x2F8FD, 'M', '泍'), + (0x2F8FE, 'M', '汧'), + (0x2F8FF, 'M', '洖'), + (0x2F900, 'M', '派'), + (0x2F901, 'M', '海'), + (0x2F902, 'M', '流'), + (0x2F903, 'M', '浩'), + (0x2F904, 'M', '浸'), + (0x2F905, 'M', '涅'), + (0x2F906, 'M', '𣴞'), + (0x2F907, 'M', '洴'), + (0x2F908, 'M', '港'), + (0x2F909, 'M', '湮'), + (0x2F90A, 'M', '㴳'), + (0x2F90B, 'M', '滋'), + (0x2F90C, 'M', '滇'), + ] + +def _seg_79() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2F90D, 'M', '𣻑'), + (0x2F90E, 'M', '淹'), + (0x2F90F, 'M', '潮'), + (0x2F910, 'M', '𣽞'), + (0x2F911, 'M', '𣾎'), + (0x2F912, 'M', '濆'), + (0x2F913, 'M', '瀹'), + (0x2F914, 'M', '瀞'), + (0x2F915, 'M', '瀛'), + (0x2F916, 'M', '㶖'), + (0x2F917, 'M', '灊'), + (0x2F918, 'M', '災'), + (0x2F919, 'M', '灷'), + (0x2F91A, 'M', '炭'), + (0x2F91B, 'M', '𠔥'), + (0x2F91C, 'M', '煅'), + (0x2F91D, 'M', '𤉣'), + (0x2F91E, 'M', '熜'), + (0x2F91F, 'X'), + (0x2F920, 'M', '爨'), + (0x2F921, 'M', '爵'), + (0x2F922, 'M', '牐'), + (0x2F923, 'M', '𤘈'), + (0x2F924, 'M', '犀'), + (0x2F925, 'M', '犕'), + (0x2F926, 'M', '𤜵'), + (0x2F927, 'M', '𤠔'), + (0x2F928, 'M', '獺'), + (0x2F929, 'M', '王'), + (0x2F92A, 'M', '㺬'), + (0x2F92B, 'M', '玥'), + (0x2F92C, 'M', '㺸'), + (0x2F92E, 'M', '瑇'), + (0x2F92F, 'M', '瑜'), + (0x2F930, 'M', '瑱'), + (0x2F931, 'M', '璅'), + (0x2F932, 'M', '瓊'), + (0x2F933, 'M', '㼛'), + (0x2F934, 'M', '甤'), + (0x2F935, 'M', '𤰶'), + (0x2F936, 'M', '甾'), + (0x2F937, 'M', '𤲒'), + (0x2F938, 'M', '異'), + (0x2F939, 'M', '𢆟'), + (0x2F93A, 'M', '瘐'), + (0x2F93B, 'M', '𤾡'), + (0x2F93C, 'M', '𤾸'), + (0x2F93D, 'M', '𥁄'), + (0x2F93E, 'M', '㿼'), + (0x2F93F, 'M', '䀈'), + (0x2F940, 'M', '直'), + (0x2F941, 'M', '𥃳'), + (0x2F942, 'M', '𥃲'), + (0x2F943, 'M', '𥄙'), + (0x2F944, 'M', '𥄳'), + (0x2F945, 'M', '眞'), + (0x2F946, 'M', '真'), + (0x2F948, 'M', '睊'), + (0x2F949, 'M', '䀹'), + (0x2F94A, 'M', '瞋'), + (0x2F94B, 'M', '䁆'), + (0x2F94C, 'M', '䂖'), + (0x2F94D, 'M', '𥐝'), + (0x2F94E, 'M', '硎'), + (0x2F94F, 'M', '碌'), + (0x2F950, 'M', '磌'), + (0x2F951, 'M', '䃣'), + (0x2F952, 'M', '𥘦'), + (0x2F953, 'M', '祖'), + (0x2F954, 'M', '𥚚'), + (0x2F955, 'M', '𥛅'), + (0x2F956, 'M', '福'), + (0x2F957, 'M', '秫'), + (0x2F958, 'M', '䄯'), + (0x2F959, 'M', '穀'), + (0x2F95A, 'M', '穊'), + (0x2F95B, 'M', '穏'), + (0x2F95C, 'M', '𥥼'), + (0x2F95D, 'M', '𥪧'), + (0x2F95F, 'X'), + (0x2F960, 'M', '䈂'), + (0x2F961, 'M', '𥮫'), + (0x2F962, 'M', '篆'), + (0x2F963, 'M', '築'), + (0x2F964, 'M', '䈧'), + (0x2F965, 'M', '𥲀'), + (0x2F966, 'M', '糒'), + (0x2F967, 'M', '䊠'), + (0x2F968, 'M', '糨'), + (0x2F969, 'M', '糣'), + (0x2F96A, 'M', '紀'), + (0x2F96B, 'M', '𥾆'), + (0x2F96C, 'M', '絣'), + (0x2F96D, 'M', '䌁'), + (0x2F96E, 'M', '緇'), + (0x2F96F, 'M', '縂'), + (0x2F970, 'M', '繅'), + (0x2F971, 'M', '䌴'), + (0x2F972, 'M', '𦈨'), + (0x2F973, 'M', '𦉇'), + ] + +def _seg_80() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2F974, 'M', '䍙'), + (0x2F975, 'M', '𦋙'), + (0x2F976, 'M', '罺'), + (0x2F977, 'M', '𦌾'), + (0x2F978, 'M', '羕'), + (0x2F979, 'M', '翺'), + (0x2F97A, 'M', '者'), + (0x2F97B, 'M', '𦓚'), + (0x2F97C, 'M', '𦔣'), + (0x2F97D, 'M', '聠'), + (0x2F97E, 'M', '𦖨'), + (0x2F97F, 'M', '聰'), + (0x2F980, 'M', '𣍟'), + (0x2F981, 'M', '䏕'), + (0x2F982, 'M', '育'), + (0x2F983, 'M', '脃'), + (0x2F984, 'M', '䐋'), + (0x2F985, 'M', '脾'), + (0x2F986, 'M', '媵'), + (0x2F987, 'M', '𦞧'), + (0x2F988, 'M', '𦞵'), + (0x2F989, 'M', '𣎓'), + (0x2F98A, 'M', '𣎜'), + (0x2F98B, 'M', '舁'), + (0x2F98C, 'M', '舄'), + (0x2F98D, 'M', '辞'), + (0x2F98E, 'M', '䑫'), + (0x2F98F, 'M', '芑'), + (0x2F990, 'M', '芋'), + (0x2F991, 'M', '芝'), + (0x2F992, 'M', '劳'), + (0x2F993, 'M', '花'), + (0x2F994, 'M', '芳'), + (0x2F995, 'M', '芽'), + (0x2F996, 'M', '苦'), + (0x2F997, 'M', '𦬼'), + (0x2F998, 'M', '若'), + (0x2F999, 'M', '茝'), + (0x2F99A, 'M', '荣'), + (0x2F99B, 'M', '莭'), + (0x2F99C, 'M', '茣'), + (0x2F99D, 'M', '莽'), + (0x2F99E, 'M', '菧'), + (0x2F99F, 'M', '著'), + (0x2F9A0, 'M', '荓'), + (0x2F9A1, 'M', '菊'), + (0x2F9A2, 'M', '菌'), + (0x2F9A3, 'M', '菜'), + (0x2F9A4, 'M', '𦰶'), + (0x2F9A5, 'M', '𦵫'), + (0x2F9A6, 'M', '𦳕'), + (0x2F9A7, 'M', '䔫'), + (0x2F9A8, 'M', '蓱'), + (0x2F9A9, 'M', '蓳'), + (0x2F9AA, 'M', '蔖'), + (0x2F9AB, 'M', '𧏊'), + (0x2F9AC, 'M', '蕤'), + (0x2F9AD, 'M', '𦼬'), + (0x2F9AE, 'M', '䕝'), + (0x2F9AF, 'M', '䕡'), + (0x2F9B0, 'M', '𦾱'), + (0x2F9B1, 'M', '𧃒'), + (0x2F9B2, 'M', '䕫'), + (0x2F9B3, 'M', '虐'), + (0x2F9B4, 'M', '虜'), + (0x2F9B5, 'M', '虧'), + (0x2F9B6, 'M', '虩'), + (0x2F9B7, 'M', '蚩'), + (0x2F9B8, 'M', '蚈'), + (0x2F9B9, 'M', '蜎'), + (0x2F9BA, 'M', '蛢'), + (0x2F9BB, 'M', '蝹'), + (0x2F9BC, 'M', '蜨'), + (0x2F9BD, 'M', '蝫'), + (0x2F9BE, 'M', '螆'), + (0x2F9BF, 'X'), + (0x2F9C0, 'M', '蟡'), + (0x2F9C1, 'M', '蠁'), + (0x2F9C2, 'M', '䗹'), + (0x2F9C3, 'M', '衠'), + (0x2F9C4, 'M', '衣'), + (0x2F9C5, 'M', '𧙧'), + (0x2F9C6, 'M', '裗'), + (0x2F9C7, 'M', '裞'), + (0x2F9C8, 'M', '䘵'), + (0x2F9C9, 'M', '裺'), + (0x2F9CA, 'M', '㒻'), + (0x2F9CB, 'M', '𧢮'), + (0x2F9CC, 'M', '𧥦'), + (0x2F9CD, 'M', '䚾'), + (0x2F9CE, 'M', '䛇'), + (0x2F9CF, 'M', '誠'), + (0x2F9D0, 'M', '諭'), + (0x2F9D1, 'M', '變'), + (0x2F9D2, 'M', '豕'), + (0x2F9D3, 'M', '𧲨'), + (0x2F9D4, 'M', '貫'), + (0x2F9D5, 'M', '賁'), + (0x2F9D6, 'M', '贛'), + (0x2F9D7, 'M', '起'), + ] + +def _seg_81() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]: + return [ + (0x2F9D8, 'M', '𧼯'), + (0x2F9D9, 'M', '𠠄'), + (0x2F9DA, 'M', '跋'), + (0x2F9DB, 'M', '趼'), + (0x2F9DC, 'M', '跰'), + (0x2F9DD, 'M', '𠣞'), + (0x2F9DE, 'M', '軔'), + (0x2F9DF, 'M', '輸'), + (0x2F9E0, 'M', '𨗒'), + (0x2F9E1, 'M', '𨗭'), + (0x2F9E2, 'M', '邔'), + (0x2F9E3, 'M', '郱'), + (0x2F9E4, 'M', '鄑'), + (0x2F9E5, 'M', '𨜮'), + (0x2F9E6, 'M', '鄛'), + (0x2F9E7, 'M', '鈸'), + (0x2F9E8, 'M', '鋗'), + (0x2F9E9, 'M', '鋘'), + (0x2F9EA, 'M', '鉼'), + (0x2F9EB, 'M', '鏹'), + (0x2F9EC, 'M', '鐕'), + (0x2F9ED, 'M', '𨯺'), + (0x2F9EE, 'M', '開'), + (0x2F9EF, 'M', '䦕'), + (0x2F9F0, 'M', '閷'), + (0x2F9F1, 'M', '𨵷'), + (0x2F9F2, 'M', '䧦'), + (0x2F9F3, 'M', '雃'), + (0x2F9F4, 'M', '嶲'), + (0x2F9F5, 'M', '霣'), + (0x2F9F6, 'M', '𩅅'), + (0x2F9F7, 'M', '𩈚'), + (0x2F9F8, 'M', '䩮'), + (0x2F9F9, 'M', '䩶'), + (0x2F9FA, 'M', '韠'), + (0x2F9FB, 'M', '𩐊'), + (0x2F9FC, 'M', '䪲'), + (0x2F9FD, 'M', '𩒖'), + (0x2F9FE, 'M', '頋'), + (0x2FA00, 'M', '頩'), + (0x2FA01, 'M', '𩖶'), + (0x2FA02, 'M', '飢'), + (0x2FA03, 'M', '䬳'), + (0x2FA04, 'M', '餩'), + (0x2FA05, 'M', '馧'), + (0x2FA06, 'M', '駂'), + (0x2FA07, 'M', '駾'), + (0x2FA08, 'M', '䯎'), + (0x2FA09, 'M', '𩬰'), + (0x2FA0A, 'M', '鬒'), + (0x2FA0B, 'M', '鱀'), + (0x2FA0C, 'M', '鳽'), + (0x2FA0D, 'M', '䳎'), + (0x2FA0E, 'M', '䳭'), + (0x2FA0F, 'M', '鵧'), + (0x2FA10, 'M', '𪃎'), + (0x2FA11, 'M', '䳸'), + (0x2FA12, 'M', '𪄅'), + (0x2FA13, 'M', '𪈎'), + (0x2FA14, 'M', '𪊑'), + (0x2FA15, 'M', '麻'), + (0x2FA16, 'M', '䵖'), + (0x2FA17, 'M', '黹'), + (0x2FA18, 'M', '黾'), + (0x2FA19, 'M', '鼅'), + (0x2FA1A, 'M', '鼏'), + (0x2FA1B, 'M', '鼖'), + (0x2FA1C, 'M', '鼻'), + (0x2FA1D, 'M', '𪘀'), + (0x2FA1E, 'X'), + (0x30000, 'V'), + (0x3134B, 'X'), + (0x31350, 'V'), + (0x323B0, 'X'), + (0xE0100, 'I'), + (0xE01F0, 'X'), + ] + +uts46data = tuple( + _seg_0() + + _seg_1() + + _seg_2() + + _seg_3() + + _seg_4() + + _seg_5() + + _seg_6() + + _seg_7() + + _seg_8() + + _seg_9() + + _seg_10() + + _seg_11() + + _seg_12() + + _seg_13() + + _seg_14() + + _seg_15() + + _seg_16() + + _seg_17() + + _seg_18() + + _seg_19() + + _seg_20() + + _seg_21() + + _seg_22() + + _seg_23() + + _seg_24() + + _seg_25() + + _seg_26() + + _seg_27() + + _seg_28() + + _seg_29() + + _seg_30() + + _seg_31() + + _seg_32() + + _seg_33() + + _seg_34() + + _seg_35() + + _seg_36() + + _seg_37() + + _seg_38() + + _seg_39() + + _seg_40() + + _seg_41() + + _seg_42() + + _seg_43() + + _seg_44() + + _seg_45() + + _seg_46() + + _seg_47() + + _seg_48() + + _seg_49() + + _seg_50() + + _seg_51() + + _seg_52() + + _seg_53() + + _seg_54() + + _seg_55() + + _seg_56() + + _seg_57() + + _seg_58() + + _seg_59() + + _seg_60() + + _seg_61() + + _seg_62() + + _seg_63() + + _seg_64() + + _seg_65() + + _seg_66() + + _seg_67() + + _seg_68() + + _seg_69() + + _seg_70() + + _seg_71() + + _seg_72() + + _seg_73() + + _seg_74() + + _seg_75() + + _seg_76() + + _seg_77() + + _seg_78() + + _seg_79() + + _seg_80() + + _seg_81() +) # type: Tuple[Union[Tuple[int, str], Tuple[int, str, str]], ...] diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/INSTALLER b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/INSTALLER new file mode 100644 index 0000000..a1b589e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/INSTALLER @@ -0,0 +1 @@ +pip diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/LICENSE b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/LICENSE new file mode 100644 index 0000000..67db858 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/LICENSE @@ -0,0 +1,175 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/METADATA b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/METADATA new file mode 100644 index 0000000..72d9dc5 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/METADATA @@ -0,0 +1,119 @@ +Metadata-Version: 2.1 +Name: requests +Version: 2.32.3 +Summary: Python HTTP for Humans. +Home-page: https://requests.readthedocs.io +Author: Kenneth Reitz +Author-email: me@kennethreitz.org +License: Apache-2.0 +Project-URL: Documentation, https://requests.readthedocs.io +Project-URL: Source, https://github.com/psf/requests +Classifier: Development Status :: 5 - Production/Stable +Classifier: Environment :: Web Environment +Classifier: Intended Audience :: Developers +Classifier: License :: OSI Approved :: Apache Software License +Classifier: Natural Language :: English +Classifier: Operating System :: OS Independent +Classifier: Programming Language :: Python +Classifier: Programming Language :: Python :: 3 +Classifier: Programming Language :: Python :: 3.8 +Classifier: Programming Language :: Python :: 3.9 +Classifier: Programming Language :: Python :: 3.10 +Classifier: Programming Language :: Python :: 3.11 +Classifier: Programming Language :: Python :: 3.12 +Classifier: Programming Language :: Python :: 3 :: Only +Classifier: Programming Language :: Python :: Implementation :: CPython +Classifier: Programming Language :: Python :: Implementation :: PyPy +Classifier: Topic :: Internet :: WWW/HTTP +Classifier: Topic :: Software Development :: Libraries +Requires-Python: >=3.8 +Description-Content-Type: text/markdown +License-File: LICENSE +Requires-Dist: charset-normalizer <4,>=2 +Requires-Dist: idna <4,>=2.5 +Requires-Dist: urllib3 <3,>=1.21.1 +Requires-Dist: certifi >=2017.4.17 +Provides-Extra: security +Provides-Extra: socks +Requires-Dist: PySocks !=1.5.7,>=1.5.6 ; extra == 'socks' +Provides-Extra: use_chardet_on_py3 +Requires-Dist: chardet <6,>=3.0.2 ; extra == 'use_chardet_on_py3' + +# Requests + +**Requests** is a simple, yet elegant, HTTP library. + +```python +>>> import requests +>>> r = requests.get('https://httpbin.org/basic-auth/user/pass', auth=('user', 'pass')) +>>> r.status_code +200 +>>> r.headers['content-type'] +'application/json; charset=utf8' +>>> r.encoding +'utf-8' +>>> r.text +'{"authenticated": true, ...' +>>> r.json() +{'authenticated': True, ...} +``` + +Requests allows you to send HTTP/1.1 requests extremely easily. There’s no need to manually add query strings to your URLs, or to form-encode your `PUT` & `POST` data — but nowadays, just use the `json` method! + +Requests is one of the most downloaded Python packages today, pulling in around `30M downloads / week`— according to GitHub, Requests is currently [depended upon](https://github.com/psf/requests/network/dependents?package_id=UGFja2FnZS01NzA4OTExNg%3D%3D) by `1,000,000+` repositories. You may certainly put your trust in this code. + +[![Downloads](https://static.pepy.tech/badge/requests/month)](https://pepy.tech/project/requests) +[![Supported Versions](https://img.shields.io/pypi/pyversions/requests.svg)](https://pypi.org/project/requests) +[![Contributors](https://img.shields.io/github/contributors/psf/requests.svg)](https://github.com/psf/requests/graphs/contributors) + +## Installing Requests and Supported Versions + +Requests is available on PyPI: + +```console +$ python -m pip install requests +``` + +Requests officially supports Python 3.8+. + +## Supported Features & Best–Practices + +Requests is ready for the demands of building robust and reliable HTTP–speaking applications, for the needs of today. + +- Keep-Alive & Connection Pooling +- International Domains and URLs +- Sessions with Cookie Persistence +- Browser-style TLS/SSL Verification +- Basic & Digest Authentication +- Familiar `dict`–like Cookies +- Automatic Content Decompression and Decoding +- Multi-part File Uploads +- SOCKS Proxy Support +- Connection Timeouts +- Streaming Downloads +- Automatic honoring of `.netrc` +- Chunked HTTP Requests + +## API Reference and User Guide available on [Read the Docs](https://requests.readthedocs.io) + +[![Read the Docs](https://raw.githubusercontent.com/psf/requests/main/ext/ss.png)](https://requests.readthedocs.io) + +## Cloning the repository + +When cloning the Requests repository, you may need to add the `-c +fetch.fsck.badTimezone=ignore` flag to avoid an error about a bad commit (see +[this issue](https://github.com/psf/requests/issues/2690) for more background): + +```shell +git clone -c fetch.fsck.badTimezone=ignore https://github.com/psf/requests.git +``` + +You can also apply this setting to your global Git config: + +```shell +git config --global fetch.fsck.badTimezone ignore +``` + +--- + +[![Kenneth Reitz](https://raw.githubusercontent.com/psf/requests/main/ext/kr.png)](https://kennethreitz.org) [![Python Software Foundation](https://raw.githubusercontent.com/psf/requests/main/ext/psf.png)](https://www.python.org/psf) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/RECORD b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/RECORD new file mode 100644 index 0000000..f34e5a1 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/RECORD @@ -0,0 +1,43 @@ +requests-2.32.3.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4 +requests-2.32.3.dist-info/LICENSE,sha256=CeipvOyAZxBGUsFoaFqwkx54aPnIKEtm9a5u2uXxEws,10142 +requests-2.32.3.dist-info/METADATA,sha256=ZY7oRUweLnb7jCEnEW9hFWs7IpQbNVnAA4ncpwA4WBo,4610 +requests-2.32.3.dist-info/RECORD,, +requests-2.32.3.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0 +requests-2.32.3.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92 +requests-2.32.3.dist-info/top_level.txt,sha256=fMSVmHfb5rbGOo6xv-O_tUX6j-WyixssE-SnwcDRxNQ,9 +requests/__init__.py,sha256=4xaAERmPDIBPsa2PsjpU9r06yooK-2mZKHTZAhWRWts,5072 +requests/__pycache__/__init__.cpython-312.pyc,, +requests/__pycache__/__version__.cpython-312.pyc,, +requests/__pycache__/_internal_utils.cpython-312.pyc,, +requests/__pycache__/adapters.cpython-312.pyc,, +requests/__pycache__/api.cpython-312.pyc,, +requests/__pycache__/auth.cpython-312.pyc,, +requests/__pycache__/certs.cpython-312.pyc,, +requests/__pycache__/compat.cpython-312.pyc,, +requests/__pycache__/cookies.cpython-312.pyc,, +requests/__pycache__/exceptions.cpython-312.pyc,, +requests/__pycache__/help.cpython-312.pyc,, +requests/__pycache__/hooks.cpython-312.pyc,, +requests/__pycache__/models.cpython-312.pyc,, +requests/__pycache__/packages.cpython-312.pyc,, +requests/__pycache__/sessions.cpython-312.pyc,, +requests/__pycache__/status_codes.cpython-312.pyc,, +requests/__pycache__/structures.cpython-312.pyc,, +requests/__pycache__/utils.cpython-312.pyc,, +requests/__version__.py,sha256=FVfglgZmNQnmYPXpOohDU58F5EUb_-VnSTaAesS187g,435 +requests/_internal_utils.py,sha256=nMQymr4hs32TqVo5AbCrmcJEhvPUh7xXlluyqwslLiQ,1495 +requests/adapters.py,sha256=KIcecscqam6reOCXRl4DwP4jX8Jcl8sd57ft17KR2cQ,27451 +requests/api.py,sha256=_Zb9Oa7tzVIizTKwFrPjDEY9ejtm_OnSRERnADxGsQs,6449 +requests/auth.py,sha256=kF75tqnLctZ9Mf_hm9TZIj4cQWnN5uxRz8oWsx5wmR0,10186 +requests/certs.py,sha256=Z9Sb410Anv6jUFTyss0jFFhU6xst8ctELqfy8Ev23gw,429 +requests/compat.py,sha256=C5w_DPLSurXPgcdWU78fora0APmbYkX2G89QvH5xzPA,1817 +requests/cookies.py,sha256=bNi-iqEj4NPZ00-ob-rHvzkvObzN3lEpgw3g6paS3Xw,18590 +requests/exceptions.py,sha256=jJPS1UWATs86ShVUaLorTiJb1SaGuoNEWgICJep-VkY,4260 +requests/help.py,sha256=gPX5d_H7Xd88aDABejhqGgl9B1VFRTt5BmiYvL3PzIQ,3875 +requests/hooks.py,sha256=CiuysiHA39V5UfcCBXFIx83IrDpuwfN9RcTUgv28ftQ,733 +requests/models.py,sha256=k42roXzC8u_OagAPQi9U4MkfO7i4r2FdaqvMqstPehc,35418 +requests/packages.py,sha256=_g0gZ681UyAlKHRjH6kanbaoxx2eAb6qzcXiODyTIoc,904 +requests/sessions.py,sha256=ykTI8UWGSltOfH07HKollH7kTBGw4WhiBVaQGmckTw4,30495 +requests/status_codes.py,sha256=iJUAeA25baTdw-6PfD0eF4qhpINDJRJI-yaMqxs4LEI,4322 +requests/structures.py,sha256=-IbmhVz06S-5aPSZuUthZ6-6D9XOjRuTXHOabY041XM,2912 +requests/utils.py,sha256=HiQC6Nq_Da3ktaMiFzQkh-dCk3iQHHKEsYS5kDc-8Cw,33619 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/REQUESTED b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/REQUESTED new file mode 100644 index 0000000..e69de29 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/WHEEL b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/WHEEL new file mode 100644 index 0000000..bab98d6 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/WHEEL @@ -0,0 +1,5 @@ +Wheel-Version: 1.0 +Generator: bdist_wheel (0.43.0) +Root-Is-Purelib: true +Tag: py3-none-any + diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/top_level.txt b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/top_level.txt new file mode 100644 index 0000000..f229360 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests-2.32.3.dist-info/top_level.txt @@ -0,0 +1 @@ +requests diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__init__.py new file mode 100644 index 0000000..051cda1 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__init__.py @@ -0,0 +1,184 @@ +# __ +# /__) _ _ _ _ _/ _ +# / ( (- (/ (/ (- _) / _) +# / + +""" +Requests HTTP Library +~~~~~~~~~~~~~~~~~~~~~ + +Requests is an HTTP library, written in Python, for human beings. +Basic GET usage: + + >>> import requests + >>> r = requests.get('https://www.python.org') + >>> r.status_code + 200 + >>> b'Python is a programming language' in r.content + True + +... or POST: + + >>> payload = dict(key1='value1', key2='value2') + >>> r = requests.post('https://httpbin.org/post', data=payload) + >>> print(r.text) + { + ... + "form": { + "key1": "value1", + "key2": "value2" + }, + ... + } + +The other HTTP methods are supported - see `requests.api`. Full documentation +is at . + +:copyright: (c) 2017 by Kenneth Reitz. +:license: Apache 2.0, see LICENSE for more details. +""" + +import warnings + +import urllib3 + +from .exceptions import RequestsDependencyWarning + +try: + from charset_normalizer import __version__ as charset_normalizer_version +except ImportError: + charset_normalizer_version = None + +try: + from chardet import __version__ as chardet_version +except ImportError: + chardet_version = None + + +def check_compatibility(urllib3_version, chardet_version, charset_normalizer_version): + urllib3_version = urllib3_version.split(".") + assert urllib3_version != ["dev"] # Verify urllib3 isn't installed from git. + + # Sometimes, urllib3 only reports its version as 16.1. + if len(urllib3_version) == 2: + urllib3_version.append("0") + + # Check urllib3 for compatibility. + major, minor, patch = urllib3_version # noqa: F811 + major, minor, patch = int(major), int(minor), int(patch) + # urllib3 >= 1.21.1 + assert major >= 1 + if major == 1: + assert minor >= 21 + + # Check charset_normalizer for compatibility. + if chardet_version: + major, minor, patch = chardet_version.split(".")[:3] + major, minor, patch = int(major), int(minor), int(patch) + # chardet_version >= 3.0.2, < 6.0.0 + assert (3, 0, 2) <= (major, minor, patch) < (6, 0, 0) + elif charset_normalizer_version: + major, minor, patch = charset_normalizer_version.split(".")[:3] + major, minor, patch = int(major), int(minor), int(patch) + # charset_normalizer >= 2.0.0 < 4.0.0 + assert (2, 0, 0) <= (major, minor, patch) < (4, 0, 0) + else: + warnings.warn( + "Unable to find acceptable character detection dependency " + "(chardet or charset_normalizer).", + RequestsDependencyWarning, + ) + + +def _check_cryptography(cryptography_version): + # cryptography < 1.3.4 + try: + cryptography_version = list(map(int, cryptography_version.split("."))) + except ValueError: + return + + if cryptography_version < [1, 3, 4]: + warning = "Old version of cryptography ({}) may cause slowdown.".format( + cryptography_version + ) + warnings.warn(warning, RequestsDependencyWarning) + + +# Check imported dependencies for compatibility. +try: + check_compatibility( + urllib3.__version__, chardet_version, charset_normalizer_version + ) +except (AssertionError, ValueError): + warnings.warn( + "urllib3 ({}) or chardet ({})/charset_normalizer ({}) doesn't match a supported " + "version!".format( + urllib3.__version__, chardet_version, charset_normalizer_version + ), + RequestsDependencyWarning, + ) + +# Attempt to enable urllib3's fallback for SNI support +# if the standard library doesn't support SNI or the +# 'ssl' library isn't available. +try: + try: + import ssl + except ImportError: + ssl = None + + if not getattr(ssl, "HAS_SNI", False): + from urllib3.contrib import pyopenssl + + pyopenssl.inject_into_urllib3() + + # Check cryptography version + from cryptography import __version__ as cryptography_version + + _check_cryptography(cryptography_version) +except ImportError: + pass + +# urllib3's DependencyWarnings should be silenced. +from urllib3.exceptions import DependencyWarning + +warnings.simplefilter("ignore", DependencyWarning) + +# Set default logging handler to avoid "No handler found" warnings. +import logging +from logging import NullHandler + +from . import packages, utils +from .__version__ import ( + __author__, + __author_email__, + __build__, + __cake__, + __copyright__, + __description__, + __license__, + __title__, + __url__, + __version__, +) +from .api import delete, get, head, options, patch, post, put, request +from .exceptions import ( + ConnectionError, + ConnectTimeout, + FileModeWarning, + HTTPError, + JSONDecodeError, + ReadTimeout, + RequestException, + Timeout, + TooManyRedirects, + URLRequired, +) +from .models import PreparedRequest, Request, Response +from .sessions import Session, session +from .status_codes import codes + +logging.getLogger(__name__).addHandler(NullHandler()) + +# FileModeWarnings go off per the default. +warnings.simplefilter("default", FileModeWarning, append=True) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..ab98fb852295c03ea518b9fbddf96f03edf5fb4d GIT binary patch literal 5382 zcmcf_TTC3+_0G=j&g|^MnuozQ&N6@(SPaX<#&(Fo!5EAa46aQYWt3_&>|9`$nVs#O z*^srNa??tsX{FHqgf>5J6IH34k4VXfKl+hKiB+lnSb|%~G*Mh7RpmbtCrV`h^xWB< zWn-fDqg4m(nS0MU_ndRjz2`CfsiHza@Vs>B&$Ia&gg&7Y_u-3!yW=cyAO%TCVHA(X zNR0FLNFIe%yc(-}B`<>lli@z*$R)=AT@y0O07XZC>;bTtP<89(j!tt zZRnQo9+%>Jx74loNIiP5)a&q7gV+0{KK+PvL_aDW)%&G>{g`x2KQ0~DPe>>9 zhoy)00ck*gM0&*GuhCBGgVLZrBn|1Oq*D&AR(n(*mWK7y(rIVDR~ymKNM{@mG^AeG z?EyUIdMx$gZYrF>LD$;WAnUuAKG2+P60NYLQ(PpfW#P1_ zro{_6Yu-qAin9h0=d(Jn&R{h?XU2uovZ*G;v!l~u)|BV)fFOvXI5adQs(QvCmPm@` zxM(5{mT>VoY_+$|TUN##=F|6iktQJv}aMrmbL^ zNbMIh#F!(pu7hQwCa34JU{D)1pTv_!8n$B5b<-q^1tA`fi?EpsQ|P&-8tY%C0#!S8zWfLO$fVly=j5X}YSnmY@81wvnm(AQkRFBj=W zfy;t0Jhn#ZJY<~oM+RltV?i)J=MPYx?$muO-vKI0x?T+XP^#Kp0!riqG?%4`+LSQVTI_5q~xyH7(Xy@Zxfs+h?g zY7r>R^&)l|I26wuvv3?C)AJa5p0P^OmXOP(unX-7kt&cz%S z?6WwRafx*~%5bGsWjLS9x9kH6>=LW^7M^x3b7s^IZpo|o%kT`D^q?gs<*F-t@9b1T z3U}atYMsI_u}j`1-z=N-Jm*}sNWR<#+oot^&v5LuiOx$J_{OlcC`fa9%(5rK2F9mcIV+mbJD3wqhG4_tX zgrHd9p!fnu0ddFs4aDWAo=D3x8Wt@>oK@3`C?}IRV>zhgyiDYz1sMP$2q$SA!^n*l z2u`2_g(gWlG_jRPLl%-X^)e>0c#N}sW=2yjo7HgI_RAT%)Mg=*+5BQ5(oEY+M}!&` z^V{Jp(V(~-abwR87j={n2X<>J(R{j`GKlSi>`q@9*-Flv)FCueisHQ!-Iku|&ZwC# zOD0fQx-Odrxvcb)ZqV6XC@kG>X6jBP)U;|P5>RpM8b~n71t>2%2vuiP*i?=j1jz&N zGp8ZeucEEG=w{vF^}55ajcnBQT%Fnq9$3q+&AlIt=DpE;F#3fb@xhf-8(hQM_uuEl zExvw}kF4{NHS-qVvh7C=9qZoutD`IZtI-b+JhX;i?szr%TJ)9FTP<(kH#=6NEB#kT zZwL3R4!dFwYOJyYPcR%T{D4A33oZ8Cs7F-7q&IBX6I6`#br_+5cYnr~IB5D}GwB z?O`gqKMh5{QFqd+MK6={K+-}fdI27Ic9NDG zaHX^eE9M|!|CXU)Oga@d6?|YZOm`CZGGkS^^i-ug+IcTA)*g4}>VkF?{#uabe&ir% z9$DI~uG>OKnm?XK3MVp$;d`@h?vK$k2IVUFN ztO<2mGZqzNF&&QuY_F!85Q(~+A=Ol37=SH&mv%0rgh0IbX$K)&1U|(OsinXPN{?Mz zuA&rdoEyP3t%xFNpz>-G#Xu=DibR3(J@}ahfU9WR%lg6}HnzMv@;aOEI-Bnr-t0QN z-gWkm>_*qb#-Z~Yjgxu);5Lu=gTGea=i0Wa$2Y5|)~lzsLgHQ4QzNW!5K4h6dRo@r_@ zsoK?K*nV{m@)V}c#w0XM<8oTjAa8nX9vYejXiQDpm$jgAi3zrlNXS`ez(^ut?$smm9v^P9b*W+T(NQLG3Z~xV>EPZu6Va>0lW5@PAJ*cyDygG zWKvJp1!ez5LI4Ie&NU54S zpEd-(+1e;ijhaq@XP~-S20dw7Z|zWdjFT41S6!sV%eDc{A+kdze7I?NR@I<2usO|` zn}eR2bWj>1hv7v!Dd?ggPC+*XJrwj(&_}@$3h2K&NIw9Zg)awkj836ZM&twq4^u#| z7@=jBJVL=q3I-_{qTmz-k5Vv9!D$LcC^$pGCmLS^5QCYhk90C;o)wh7yX_)5zO9+8LWdYS|8@h3r7R>MPN7N)d5 znQs7ue8e!Hg_;=e-7y9+dp<#x|3JNv44KxCyc63z%QSrCJ@&aEGQ#I$OpqDajszM1 z2j2QEKD@~{K!sgPDIlizHrjiY-$Z-Y(cabhyx4mS_1*O&Cj1d< z{3m+oD^HN|e1%G2A7aijn`mqUjeQI0_&PfFF=~aSw^7wqZWC3lqpH>R4b-rSTGvtQ zZ?3$ud<*qMgTvI7l&aSnZ`A%34Sl^mYY%5f=8ERY)HC}7X_f0^x zs1-nQp!utyAH2rGqWjws6so61qGqeI`e!UH6E*j@_Z9U)o#d&uz&&#YPVSffGkxe+ zez-@!s~xRGfAEe8=pEEOwhz7A$DJ8u-#y6yd=GJ>LH0d?p|G-ljAL*5843k%Y%hDW XiUt0gwG18ab;kRAV@>Q$kpcKGx;Sd= literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/__version__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/__version__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..64cdecb1ac457e7c693c49513f65176ba2ee5f95 GIT binary patch literal 546 zcmY*WL2DE-6wd6nyR);M?PA3R5uAg9OS?0&;-wZ*yc7f}(o-&BI!SjzXC^Vp2%FRR z13dR4cx`V5e}*1B4tvx;u+UpizG>Z}kC1%dmwb=+UcURjhagTL{W$*SAoRN-s{no- zmpgErB8o7g4t8h@w`d!;=^9?6>v)}ZaEEqrm%7-cJ=~jn_f@4(ROq&H>oIs z{lmk9;8>_&zs%!8hxTD=jMTePw0asU7E_ZlDiR%XVLQ|C87$tOwvhGTvZ7!n4c;?u ztli4ltCJf=H9{!V%zCe7oTO|r4WHW48zJY4&r%co=PWm%nO|Sdg5}rG7Xg5GV{g$T z#Bh@_LKd5ZP^J^brQxCgp-V`qG5~!-J~E|mRB#-XJfom{gv2GZr~nUdG0S8A*Ol>v z6}n086OydT0_p;dPvGJlT{e@xdJ&miMv}{kiPemmiPb_``dmdBKZ@k_AaBPN{ZmgU z=U47tE@+vtmud*Pn$Od_ur1q;<19VokE&jMXS>?0z3r-75AId{dgCr={)5V^x1Rh& U!+LNZ#NoK|>;B_Ut{Q;-5B6)au>b%7 literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/_internal_utils.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/_internal_utils.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..99a613a12027987fadd1ada09e776391e71b7318 GIT binary patch literal 1986 zcmah}-D?zA6u&dGpR=26VvUk$^kTQsZEF@RQdmDqtlOGUHEd$RRWr`c+_*QLo!Q=d z*SJesr1+pu`cN=J!IvTwp-||5VIKw}?RMxxp!C7FwCO|fsprmq1XDvV%$+&s{?0k~ zp5O1zvw;B}!FZVcY4MjRLcdF+HzM7S&7a}pA+k{!*@~??N?EZrJL0G{t*j|XMMPOj z^n$kDcJ!&zvC7dMF|j@-wj(Cq$HaHUB>I>HiIK#jT27KEiNjkbDWa1!Nm8{uV5jWl z9i=>I>vvE&(^PZm*7rIipEn2>eA1wc(LJH zf_g5;qG}3kGJ-9z8Z~0$UM{DJD@|PL*3g%$)T&~e)QM|j&&A}HV5CL>wMdqw6>b1m ziBl(x<0HHQaFavcTHO>m{e^7lg%`53IVDI{8q^WgHMn4W7<>y?77ADSH951Z?zOkG zt>OQ;ct!%R&RtpPVpbNit;{xur2?ooq!KiEHfLdah(woHgjSH~+nBF8VHZdH7x;L;_St6Er7c+9hWVS;%$KE0q%{q}j(O}SV z6Ta$su<%T>Zin8qa*lr>p% z63*+b+XYr=VNI|Jqi!c!*m<{t)s-Q2NU1C^E^J$9^8Fb+en~v=Jw1+6lF&4*Y4F; z&#eu7!9duy#b)cZ8`X&-FSxt^CV(?$N zjGEdqx}{x4%StZN`tdA*yHTSq!E_M_pg>ulQ_qD91XoX((D*J#R@G#t1u=Y551A>{ z!BLYkz>RKq3fmJ24_j4YeKv{DH@LtR(gTDUq`stHTuYB4c;%g)W_Gu6X;3unD&EmOv@=u{vUEfLEJEG&oYcaWh97oen1^P$E86X z5{wz2PJJ?c);L$3I$JCm7pBe^jZ)D#b9ufPjJ|$tZoU-kdvytNT-u7;mb1So1NZbQ zg=MGaFP7#E>EHVrf4GTgr6~w!LvW&CxVy`(*zj_Mo%{~50l2j?!RC1$L4&r icRiByQ-|7-xSu?@5!FUi9}RD&btSVomR3f>9sdi`R2@11 literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/adapters.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/adapters.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..2e019ee14113a4cd2d901bac1fa47e2d03effa91 GIT binary patch literal 28326 zcmeHwdvIIVdFRE8011HL1AK_jONtT+i2@~APfC_ek(4Y;q8N#eV6|TXlBw*HVu( zS$qH3-*@f<7a(LiZf3UG-7D$f-t+j*`+J|Gzw&y^I6OBx{_EI*^BngN^r1fv?d8FQ z6*)M83vq%)u*NMREBm#DZ0y$_va?@D$bny5yd>caITNms%R>3>_%02Vv3CdF-60Qq zFTuMvhcb`xZZ%=FtZDjA2@s7l%(5A%Z z&}Q~s74J-Rg}T^#bv%&R655j38rq7syA$1^?!>mxwnQ)#L^~@JJ)xe&_Rw~;tA^$G z$9E)lhIX>|n)qXhU7=mRVKECnM%WJ->TQrYFgr>tybA|~;PlrSBS@}sGw9El|*UY>~ZvKUE9Qz=pA z_2P(*$oy#yDnBhnku${$(Xm)ES{6wPd;+Bj0zpbfN99;5DFw@ZLcJLZSQTG?JS9bi z;Z!Oes)U?bZ0~V$9sgaRk{lj}Kc_9*y2~R~MLR1Xcm8uh|(FlS5 zawI+-RRMWVMlPO?%Hk#UvuY?hqk%>~Ez7W&l2fBv)u^Qm5f{}0Xj{c;z&E!;@t%&N z|4B)$0tH-W&YVzNWmVkNiIb6JWIQS=PHJSL_R;b}3BtWFIQb!I9eN>MG|!5WF! z+EFnYky&&+cJ8q-4Sn>Y{1aM7NcM%#MWonhI5I6yge6%-1IrMD*%V{Ram9sN7+8XY zVq#=e28h)8SX2tjsqkb(43uHGjag8Kpge!L#S&De__Xn5qw&n?6N*0IXGSNYiHK6B zr6WmnQvtVWq?EGUsEg%l+gfsyX!J3RVN#08u?x|G*r*(EDzyWHNBW*QF%s_Y z3m<-FXyC+Pc(`xmDaEh%Wi~c76&1o$5qUyVD#xR;IuiN_D;p>(njB3D7!GydC)oOs zl=>+#Iu%U{VTsxw4adg9$!JuF3W`UH#<3{FY_=3H#t=(ajEvJDqpg)^PW2x@!-hed z*im%IcxX@h@b5uAf*YKy?RXCOM&I=>SOV6e+0K(ONkX%*F{mAAC1!;mONl(IfS0DH zXj=sX7O@$iFtzrGI4&tA=V$0wB9y@MAMfjt6H`4?v8in`qNDP*St%vX3cJM~ESR3D zOY%f2*`sgq9(|7nr!I+G0DuKg;6;uYiO?D*%%bw15aYA8%ELcjWe%$1}|Ce84)Op{J?ZuMP9 zv~y0Bajj3EbIG*)*pmjyjBz@eoGVS2PI~pU+^=9Y+EFIcFtA79rY#pOqRqmk%RJni zTd>V}(jc(YoM;mqbDreW_$tAdC+!wZ<g`nic4GMD*atY<>D6Eug6W+ z>TkK<$ql)8{Vi=QA*m#7K}}9plY_mx=soR0Y$yMCwR5*a;;XYkw$aTqJc8~q+NpVHQSs$ZBIMKtY^4D#gI}3 z6sF<)@Dz|^`239GmZZ3j+7xg9;OUX@>A^2ObL{lsz!9aCeGi=)8XQqvqml4vRFoyf zt-XbXn5dLeTo{X7`U$NvkpeApEEbQ7HT3N|9|i8kXTYYEsGDA~PoyMSvC}>aREV@= z6&v=u_&B{e;;EUaDAMjwoY+|rSr!!=UX)tkhG;wmLId<+YI<1=8(NYh$8UsppXdsB76D?sqQM*uO0)jzjB^oCp5}O4LcwTQ>q>0pY zTnK}Jhk*ej({b6HF7C&`NVK1L^CJdnyy~fPMzQq9Xp~EQ7Rezhc>tL43b*Frs%x$s z&sO=b9ADkgw$S<3);G2;Z3r&fYqQ?g74PPZck_z3JLBzM@&>OQ$-0|Y-0c~6`;~!* zF0P?%p>Z*I`2E968;(+e_FXIO`!enO-fLcJM?~vgSIdI1=-TpuYiRMYp~aq|H5=#H zxaQ(2`76h=PVe=aU;k#--+Hw)Tk5;M>uO7;sdshLfqD1!lOMR+S4*p}A9<~Rxs+e^ zRbHF9I&*FA>fFsQFZ(*Oo4e&o%#?u@-D>#SOIwye5q zuAhH%_p&?i?&$5UOTk0$w|x-o&vx#-z2l9`DC5p}0B6VTwl|U*EHta@F)igzReiRi zeWhY+rebTh!hg?cuP(WAe65W0)ZKJ1x;HM`H;O$N#5~HQBiIK!k@BxWd!k&(0yzTm zL&!GIjX|1t(G{|TZ*>T^7cGz|@4IGgx9F8SpayU%X z4P#?c>tXCo0=EYOTL5@M!bFw>gDoYb!J@kAG#XU;W5(> zYBOsmp?GsEL5?kvek7d%8J740YR9L}O@bQ;f}xeCMKHZO+oC6wmFdgBmu*U3Tk*X- z4PYX$NZ6qGxpPh(;{T7L{R#O=_ zuGP(0^kRTym4nWM^i*nwkEc*IK+QyAGUGvrwU?qIuo0^PBV)9Qx+_HF2pSA-CCZP- zE>Od#r@Hxw#7FosU`Dx{2O|^Vd&THj@7XR5=kr?i-FdLkH9=1a@CUU#5=Mj}OVeP; zm!=?a=v`p-P&F)@0aBX<6_4h1bTGz73=Ic5jYg8)JVcP0iP-1_KT7KyT_-Fhrs5K! z)#06q@+u?)K6O7gI-L?fa^eh6XgW3)gTN8hdaknIMXE?lOEQKIgF}QNA8ZP-{eAqo z>7)QT3-bZoYvj;6Mpfl?t1o$p@`>BPuwICPCh-tJ%q=27s8AMBb5t;mr@CH=&jst5 z2Xh3|uf_8Mm~mQk;w1tUnVO2T7a9X?x#d8<4PJgIB_B(G$|bM>qk<|4ImNGI*NG<) zfcUc2tT?rq6o)9*&M2Kzt5l+$OCya(r6@oTNny6ai~=a;8uCfRk6z&(wsXGrMOT}; z_01^iQ@8$XTR$xZ2@6;kVR>mPI!e=tB@sTIRCQ7q~^ zl#!UzE8N}kHoZ-6JB|#E3=IWbg!hQ>hr>!)IIK$5c=v?E-{T=^VjrQj+hG$Hu;i`?JYJ099Cjz&`^Ic8_%#r9%p$i;|C zso(%mpk865f}e@S;|$)kgvEfphOMh=0R)0epmd^gMr{&*P|qaITTEdQ8$QvGihjeDx&s20+CtW z^JZv?$VDkO8&x6UBbJy>@HvR4${0zBTmZ&Rvi=a{Ja{M#E*44*LQ6EK>%nQsd=!l_ zwbH+}d^l2MIZYG{#B5fDg5EWv3T&=Qawh}r<1(sZhHHpm~oL`pK^v%7QZ zGa-eRCQ~wSE%a8r+ExQnt{qa4KQ_i+N=>5~=*&2Hw&{38)F~QIYk<{;A_9~ww368} zF<_~b5Cl)HDWYR{(69tk@M&uTB=79m)6|-?`g)@wnF7~lz+x&ul7&Fq^JbQ4A>h`mRkE z_|sfiml3#RLoU}ODfkMWwCx=tDR|7KV)Uhx29A9hZIeA}e$X8U*nX%Ma%?{o6kOO) z)}*cYD%EpCIlzUPT|}*IvQAIQ{i3`zZGYFUt8z$?2snnApnn89IXm%?;5{5{yaFD@ zr)v&R500EZHh4y?1~5@VptzWJ5V%*QaZ|j+aa;;(08^lWL`9EQ+;GrPnm%jJvsF7H~|<%@A<@3vx=-7zj9P<&Xeh z>-oSPSZ(cC_|mOsmRld2ANbJIbhowR^~7SYN8LBj23m3_=Tgo8iQ- z0wRP$h=ZhdfjB50W-;oR+gT(nW}Q6*?*z>ZbT3erhiB{a2Qrs(2Sp_4x4@WX4?g*y zhyMN0-};W<9=LA*-SL~k!oaPLrP`iMMb8JmmY(=kBz}! z3B5%8uyY+GoX2iwOoX>1WaM{a8jaL+?C_%*gUx~XuaHA=z#;=p6b&J*b(N9FOaaUzW-6ER4=5y!A;79H;aYfgt*Wc~P9y*N zfmaWF`|Wa>KDpox08BhDdz)HuS zOvj%0gq1@>nM0%xDsA~GXDuyL*EzLRe`qd9llmxUd zf{h_AXrW)TrR{H8eurQfbzHIr?2%d&I|da<47RITQ2L0$c?|>AoK$sw8tX=5sM_Hm zo2CSvMiO&CJR+Dy5PrgLOdJGB6~OTjX$H?jypBPgqZg;hz^3xV5PTu*CSh+l$CyWr zUo|r8%%*8e@dtGZYuF6Ul=9G7Q-gJ>)zJEWQC5?BuL0AD0!k0m)TQ8_86O}iPOZ=4uVD=iy$$MDu>V9dI*G#wkVJwi zRLHq87fDWLWyRBYlL#fTT2$&o`+2s>G{eC{YPUwE`Ve3{ws7s+G!oLGkr1{$>+d#h zUgI21W!c)ctiLf^Rd>&cFNmDJhI^%Wo40@Hs#kZKv0DI=uo~NGe})~U?zCbwC-au;O7qx+x0?l6hH(zf0M_MFACDuSl#^i)q=zP+`wDn=#+IWO!3? zQYiwUzIx76d3|8Tzd3`y?#no{Zm8dA(%+?Z9LumKGT_AR#aO)(- ztMD<9a1jJ;Lc-_MHZdkx)0P}d1w+1V+9FD68_=*Jtrj!?PZA+1c+w6XK}zMa;Q$~2 zfq$F(eZ%nmg5@(H6M-#wOpsk52bP?Sn`~y^2FXa)2$XJ+Jpl&%TyFMdm42nkOFqLMt;{~<w@Xh}h8R$rBU9c#KCs4bZ8v(^ZN<&H9jYU2(+uu(f7fjs?XGw?-kji2* z2^`GI*x#3D)>F-dWMX8VkIbIf%ZqyeN>z<9$Cuf?1we^eD6m=bnH!g1zPvE8T-USO z(6(l^GzPMP9k!+G8Q zE$^MSOZ1#cFIRL1-jQnsk zgO*xXL8Wau8krNu@^ag9E`2%{M=9b!*kgA8E5;$1${3skDciz1<(qA?h?;DYSkQt8 zr3|gMS@fFp7i7fedMYlqf!-9!SzzaW#HhU`L`HeF*((c9tEqUMmLyl$`FSP zx+iK5)Ed#$Oh2Dnt)){*10MO%LQeVRtF?4flc9(LSySnoJ`4q3J$w;2A6*Hg+MH!o zcr%8;=!7N_QbImC*0UP^M@)}{pjQ*+4BgymZCnkQn-M53-I-dkiIEwl1a=oGl~l3!la#@6?vfmZld=$H z#fcqNoSMtI>i$udQ%mVOV;h=GHXLb6ap~PF&>EMMRi9iNRbTtr1~X#MPaDVjl>P%M zhD(T_^EbWHJMVf}!ttF8@~yAjmX}%&&byXfO^9mhd3WZv{N8gvurBo+Uurx-@%4yr z-gA3mWzUh!o+C?5M=5ecwytsB^^zys(EfV&tKBON+cFK?5aGKEH^0#v<1dfDHoffL zlx=KzeebJ#UqAHfpyrW@7>|0CZEeIHF-x^BC z;~?Z@Nr|1C#-yq0Nw^s3jGtMBk(;zaWeu6kfeB#EW=e=WS8+19N0~Nyo90pj4p1e{ zJhKhtJi$m$O_^CVc_7dSQEad^aCMEsRf6~@fnE|gNP^vsI!Sd(y-*De#zIF%LIC(t zeffc?ave}rLul_NwG`1VZv9aL;{-wWiLDn zV9N;deNerR<=RE=2QwnHzsd1#wTbBESSk)zW2Sds*Fn^Sb2ky@1;V@~A~~mooMV<@ z1n2oJX$( zrpA*npUAJ%8mvZ-D5M&hL0F~16U+J6Txy)rQt$UcNkOjjOIg&Y&Vm>HP?J$yuK4a2pBfxVeh5by6T(?1C^P@YAwdiJs zEf!%^po!IlGT1i99*UfUgA3eu#^JPwZ9h5@NsgltI_kg*kg$p+%#{%2kEBEcR`gfDKGWgBY!cB3Yr zgRiN8QYr?EVt){>qvi9BX|&IT65|Z%p?7SZ5YAx@!zn3U>8o`KQ#uj35KB#qCcI^E z5bQKSuhB+o>j;3Fcom!$00_cBG-r9fLfTo4oW$D8yl|Ok!fAq=cca*Ccv5s!b4Rx|ZN^KWKk0!uN#JiPNE(cu=N-8kMdj#4}G)k8V}Rt4cf z9Td|hwh*y{a;ndxf;o3(d0J<6zv95tgsE6%zY{rBT+VfzM ze;W;?#&~ZYLSaLKzO@{}0^~6v&21PxzqgvM42|cPT51NiHiS8K9x~4I)&PT7{T-Cg=T(bwsc>}Bc-J{cDY?0r zEejea%eY*_|BIPqOK=3xAwDY`+Grd{GeOE}oO4=wb_B49Y%jTUN9A&o_6u;=m^2Kk zI!_IqyJ1h5E3@KwU@;k9D1jSL$(t5v{hcuj8F=U1Y4;fp`MILU{fg)T9tC3~CmWgz zocXT8k;k0vz?HVZp+_6f7ob_0b6s}LSd0_j&d4`xx`CGQMe7}X3Fpw3Q5j?nm$SV} zYD1lB=T5 zxJZA@UbgEgr%DliNyILnz~!~#3lcltAaHrm7^ePw#ExvI%s?jS=(_(zn>}zsl5Nx3~@kB(7EI6k@hhK(p{krSfaSXfVnSVBvcds0^%jIPU^dZepM&HR=8x+iC>*skr^p0$0hv~@a$I8 zP7i)YW^x;n{t5MfN_BCS%{QNY{j0Bj6&jd|o%4=0tFv@RwsY%B=WwQTI9pMdt*FJ3 z$_Gw+S2@mL;=pC&J$ThtuKK%gJ#+iWlK;T`;A(x_!ltGAuK8ox>ZTiq{>`D)+D*`- z*X+(yoRgh>XQqja`c3=iPiCukUw?e1dUvLJ_dU+)FV9vr-?P#0);;&>cYa_E)^q>7 zd##l7@4volrFvtgdgDs^Q)q+3uMtm!1 zXz-e2TC}V>#WEkQ?K1{%njaDu637fpSD~>MCin%8Rga(xv;R;q^=EmU z6asGn-#Af3{-+n218j3 ze_5QL{9|ll@lO!ossk6U9!QefN3qkJQZ=A;6Y|%yYLZII9!amNO@xEdE222GL6s70 zBl;Mos$44VdJ^vsWKhSj!bcU&Yu>BgHM^~H$O03vxAmdVRa*A2iYU{W1yH3e^Nt_8D}D(ChhM4Qm8sr!`^-}H zevp@PMlBweaHYKx4qIc-=D3n(+SSrO!eOPY)jP#=Lhcis^{IR z{HCE=bV4N(j8Oa@J|1<%pL1*?m12Gtba4eHH zMFfYS*?CGFj)w{uE82t>`lm&a>EyKofb5K}sumz7O>=i-ycWU1$xfIC^86)pN;&Pk zI34^221RZ%2Y^w_tx23u(^t|EEL^k}6`T}~MntymaK#5Z6#*Ha+_V`VrCsKuI%CHW zJ6mbmyFu38de9N+aiqaz!NZO=)Z?my6<15f)w1m3vo#x5YC1DDohvoLOigg9W;-zq z4fBIpPvy1aSC9Yp$$Q`yw0jYXas|Ipz!hL3G#ZXdjR(f!9A!5I_2PMT`d#dR88`qN z?$^PkWN=%voQEgK9B$6RO+Yqrmz;xZQ21gnik*iss5Vh`Lp5MDpUZI-sLN7}2bpuF zT}4Y8CV0^gvEDUla4II~hH8ME#sJA7)}>3Nnw)y!(?^QxrmHw2PhgNwonx1z5w{Pd zMud#C-Aq1CM9veDrzAKEVaXfx$5?wX15t7UXM}N1lGI=(4KMs{Q`6&6z^O-=8RM=R z>&Ae_NfcpZNX{wsA$}0S3-YG`mDw!1Ndnc_0(O*^T1Qnffw4fN#@xP)wyozVKF9Hu zLQcYfR!n1HB z|7@~oicE+`xBWwIGkPxmKGx+C@fC!#)}Ee^Ej@u!laNRRQ@tLjkKS$|Ag6A~VOVTR zNu2ClQ(^$oD8?`q39u$gO1Ma=i{SzxCiM$p;t=%9hm=ajhK8BrxOSDA=CG~yk4dT$ z>8*5RsrzqfOPQLH@4sbAXeVU&Z&4T&x2aI%Tdmx1v-9<>uWntc+`Lk`EmOH|zT{4O z=LhYN-#T)8Jk$O7qN_FAglic#{2j<}Q_>WHJcZ! zI_LX;j5~_99$c+zU2wkTe#5;~)ji*T$5%D49WyILtAwT=khFD!QML&6u1_H0{}Qh` zYOqt?AT!zx06A)-nV9(tJA>O*R+LVR8;bz^`UGJLlrzqj!_Z3TARZl4?|LDn70hy4 zHtb@^C+q;X&NCX&Xm{(Y{|j!Y|7W&7&~*fJsLx*!*+W0)F@jNrL8aiZ7;~1Q0Vf%Y zkUw2_(iO4~eZCFDR5qIn)@;r7b?k#qxo_c z^*uLwY%pm|u_rV{z>JlqwW*Udh9EVu6@v=z6y~K2e8R4@NJKOvv0+D5oma@ABWK4M zO@U_|RsA?%5=G6_9*s~!Vq$kM!O9G-6I4{5hANAlztr0n%Nf`EPYn$X_K)O9Fe9WU z%lJC^`d>ITWTRksr4jpWjE%-*P!E|L`02tiO}H_Ev(>|-Kit*_+h$6P%`(#_xa3V( zE@CYL?O>y-dHe&4HO~4J9%v-NWp;xJMFm-#^_?(G3!WUQu;3eT0o}ZFwVBS#H1E#1 z8s=TsyMFAhUfp)^y|27~acSG|{Lw{!AmiC`$5%UFuI>%PR}?VlGzHrme+sts22L|V z_AyISNTvr0Gkdxu?SOTLb`u`hueeDwBsH2#JHaFxex+I@e(1=dUY1E%Mc7-^QljrQ zSi87l7hW=38ulbksFdJN1HI;_q(OepJI42E%SG_Ea zeNoR>I*C%m8d$uSLaF)(V@m4uf+uZDm%Ur|jy5B6UgSDfkOiL@d9U7+GaT%A29DM2 zcsap`?0AN#1v{QC-;Rf}hDs7;ahtbHzLx9}oN3#)Il=Y&hVb-)VgExpUdzVG?fTo8 zmDOJ^(_Ujwx_n*z<(JE6Eb?YO2TJ?^mPf-r3W10$5CxA+C;Hf<_gn1z%rf1DWhAfM zqsOHSM&>i2ZP!a0E%3^Z>2bd>v|V~h6Ep~~>hlXj+ozW_K|7$wt%H`Eoq{pYSBFfb zl|9;e`s@-$e`pn9K23djN5f*d)h8S6mC1(09=3L#&tD0-e4nddrZpr#sev_&4x(4? z*W=cWh`Ho|p379{Q9Z7(& z;4(DnTQkC&)&9Sl4rhfOV>WVgxB9>^lT7z7;d)42O`$Q#Qt)))5e4vjITJIf)Q7Cyv0SrsQ$2ZGZ#%&p&TwH6&KfYIvUmyEXDhTz>Gez6_}NI1AI9-TKEmsl zl6FI!hzJ2A3%gBJzr+(VG3-C;O`}W%gP$b%!|9il>T-bu4|UZEJ$NMGR!US4Ri@)m z?B`O#C3c2_PB*CT!b$}iK_}R#V3_RfiVwyfx>H&;fhT39Ts=c!eB+L2b|W4e33PN~ zI(a@S1U8BPkw%92NY&2&9eR6`g1@04L&4ut@COtOQt&ha#iQ+zGm&X5n)fKmiOrM3 zZS>-YluM$3&Jl^PQ$VL^MPf_Ew<#bdRwVt6NDP-qT(HO^z}01pk5`ZR5krJqoZ$DS zeiOST0?oodAx!MK8cUX7v6W)W!`hTRg-L;0f|yhB4-o`>COP*}3qo9=?0-tZlN78{ zuuK6h2ayy;iVaXDAKnbTllr16-^Yi1}|$~u5`mg&RJRp$AS9R8|jzR3-V&!)(`4VFZMj~{@%ZQ;?JL0 z>^Z$yb!Og4=TOu$DDZdiR%Q9lm%Z1WH~p&(n{Um$H?rJt_+{rq4_97))A?o-?jpdA zNOx=7Z|!}rZn?G(_ZHY6E3HMRZXA61V79J>PB&)#b=jJx8((|*YuWnN*L|=0vKv~m zZJV?Frfh2myP=>fQ{RO&{9UW#{QLvX!#Y0!KSBSBuRY^yU)XzVV9B>*(Y52}567)s zMf;s_yQEqCl)_U*e{*S661R@WO{ z%iV{T>z-I`=(<&T`{;7R!A1YUyL#3)PcHj*q74g`w~j8??pmzal}kFl?A!i`q+`pz z;9Z#AzHzH_xpwDb#m>8EQQNI&m#cO!dUm5l=$r*DDu`uH9XxaDcxBt7r}dM&6&qgb zUG#0f&y|+evi86B+_JAT5AkuYYVF2_J`6|g z-o=W&cPeT=S*r%PkEJ9Q_X{-xwcK~hs|I#)f5G+H2P?Sm)s_zIuzj!9JJ4@>h_JafT@k6KgnBVq8KYQoh$F|yjxV4Jn zAMdL_USs>K8V5eKd)$VG#7Wd0s29)UM~qXDpnzH=zKB4n&~NM;K6UEEnPZ_rF-_5x z=IFyG@LzAJxAXl56?};Ty1R(^F^LTE5v~ybhysQdzejH|3UbJhlmqI8x+!{_LSVi> zSENV^-l7BokNb1)S?e9H`@2diORgMS^K%VbvNfBs{*Bq{j-R^yj$zCFZj0lD<$j6V zQMT5^Z9VwFR_`dgzpKMhcmITCx1;KQ(z4M}|KMrMb_Z6oVCixAADpvvI{f!fTU?HY z`~DV3_5CL;9*6gSQ?;XRt(#rb`!n05#j%sA99WA2WvVOIc4{Kg!r4l?%bHKqsTYJp zIEx^jqWF#Q(g*Phj*v_CSCNVMx_GjCM9rdNT#2Szv@vC8Z_m`3ZJ7lP=2;lXhKQ-l4-j}09a z**g120&|xFwj=%K9T^@uc5?94Gb8x#E~L0PfJ{maV`5bPnhxkQHJ+sUvp+{r*#5ds zZ#@(Q5q#`AsNRBoNc;q!BzH>35yHXEV!3B6vDhC}a2DU+b6)n>_uskxkGMS_afg0p zby%zqI0QfSaF+c);tqYp?fMaS;3IDPM_l_yTn9e?k!$-A*Yy#%^=DSM#riW&4}MzD zS(;h2i=q+SqhQVNupG5~WZw&a3VYd#t?mO`-A8u1POzq7k*myB*DP`s*{bR*J{$^N z)~dQK9a(S7nhn2q zJgsXE`~qs#-Zdw^xwxvp{L@VUGJ4*&OaDP$VKG4a1 WZ-Z-~!}h(6779C^g!Z>v5dLqKHZQCI literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/api.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/api.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..e94062140b653e7bda834421b567c901079870e9 GIT binary patch literal 7166 zcmeHM&u<&Y72YLRzeqc7o!E(+)ScEvDB6^0TUMMBj%-DeYo~@RgmRI%DYUEIp}5v^ zmz`Ofp{g`Kq(FOVb7)~5ia>`PY~pl=BGLEKZg4>@V{rW!`}sg(~> zg8!t(Whh6js+;;**Of}mmtDy!fm8E1b1PMkSGXTa7M3}CJ${Q#&Yd4kr3!XXZ3uU% z92VHHon^<59y`t!8|(+%_jy>xa5r2TO%*)X=Dy?wHd(doGC!VUl5=+9{M5{BafX!w zf#n2e4i7EYlcT9mb!<7Sw+1Db(hYoRx0OLU8Ne@%-{v(G*R_xatLsYlsJQK;_&%<^ zlT2u<$tyCO*`ErP~Qd{e2YAr)x#+kakRydL4>?Q`7O+NW7hV zQ>*J)!}|A-rcFV}P}FSb$?_d+&v#H`1>3WvESRz0*r~WOVM2QhSD|VNtHLVKR^Sxk zyV3}$+voM|QXjul!Dxq2>ITdASsdVIul zmw88mNW*Qx+5#;GPD9BL!#q%qD>CqVSaX&WZBQI6v zmczw=(>Y0dZhn4_or{KbmZ`gNP6F5i_hARYvdec)PNthueXm(!`wkv%YSQ`6i3v2Y zIixntjBizVrocMZ8HubSO%nhk@cy)Ch(gsnrkRbxNzDsg;4x&}w*!YD1k?qV69JZB zW}0eh^&aN5EuSrNxa{!})r9`x42@871Gume?zcNTid^JBgngXMmB~BHV=LPiz!5vp%wO%KBH3&Rz`J-$`=`HWL zQt1zgA|L07JSBxZ@x zcMDn-!Q1x>AF-ELtZJ21ieX`32Og=P07{vMvIMF$L!-yMFq2zq^jLQWu?)tu7_E=Z z=O|v+%dTC9PfIYEP+?vKoYrX?4W1BU}AE@7m6JRZFReJX7Qe-@9c@nnBDR~8# zRZx#DzplHUM}oMO3akmqy#{lFx=+E6$KfwV5^Zn$^hK3#bBuPO971}`_FM!rrHv>^ z43AcMB|FN_m)JZd^Bfz_&}12ezGdFXWbwKyV#5g@)&%n5R;r051{aEIaD*tfN9Yj* zuL8gr6V&#wh%jA}))Friq6fw%CMJlZ28i_S7h>g851QC3osQ9X#Bc`wK(dy@uqq4r zJlz*ve>4zF`6V7^vb|HpPaS#LkB%Qb`r`@JoK3X)Bl6Ztf;i3I)UrvD1h;Gr6eI51 z8i<$88ln#!qMv&Em+O{TlC6O@!zEfuAiOu04=dGt)vb<%7{SAl6&Z*XXI$hxcQId8 zv?1T#YaZ-<6cii`R8z%MsK{v)*R+4Wp=+tVw}%dF3?2B>(DQdRy>C)qtADcR;4kXG ze)pH}Hus!aFWow{vFFUk`%!$Br2fy;sJp7XCkHXnZ}*)@{=V;(f!Q7oPCHQ?oT1Xq z!5w{7D}g<)>aHHK=^|8OIUwo9m=r_%ZJYG6;Qv|X`PSjL4o3zpu!}MIWw2hYeR8rw zIBsk-q|?w^<~Zh%y^%Z~mw(W7tt24R>W`@SOe@O8)sO4rNvVc-P9V*+pe;Rc`1)cHbeiYFCUef*d*6fXR zZvBTSnnq519bNZV`x*3Hhmx;!8wG82(f5L_Lu^Q9R~H?4ONlPi7}j!^gT`b)#ox!| zp^s)6WSBVkg0F8Q9E$7uK}am&s*Bu)tQ@j-`jZ?)EMRf6WW$#1OcYeBf#gn`Z-5;W z&tU}$nh zYucUtT3`CMv2VlJ*W91EvG31D{;%o1@4vJ*wvo=Rzlfq~WFr`LV1O4XFsL~G9aMID z?ys{^5SM(+F8qIZh<`NS_)@Zm0oMqDL4(ZDGU!W&3Si(aDuqyX z5ESU6JYt}RJQ638Z%{iGOZdreqChZvj)ECb*i4^ZpTA{nq)&g0RC2m$oQ}X4e`3Sn zu2jPCuoH|sNX6}LC|>#siC_40(i4QlWVIFw1viyIV+x}hc2bywz>A>bDt>JWqmZX4 z%-H&LGd*_W>_&R5X^eew-2J5+cXW#WDh9T{3L)pxx9`vW&GZREULVfBc6keX;#&l& z9?JY}!W$Jo-;TGFYf~HP@pY$}9=}mSt!a!ufV({eW&V5n)D(TFdCW+Ag4EvcaF2&v zr5mw>@*EI)S*1$ zQ|iE@n71NQDs8Cc;ikCJI4(Sn}{||M)Pg4K@ literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/auth.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/auth.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..ac269788ff0a756cc48175950e798bcf05f8f824 GIT binary patch literal 13885 zcmdrzTWlNGl{0*cZ;F&C$&x*K*b-$uEZJ5ZH*%s_jvt%IsjZ}rnk-9e#ujOcl<$me zizQRH2vEw+t|bJ!k~b~FbhC(z1gQHJ=c_3SY}?%hN}6iPOx;}-&3**f565!R!XJx0 z=MIMyDJqY4u|W6AymRll?{n@w=iGCT|J7zQGZ2NCqyQryzns#Ab>cfs6PUYFA088BEiUcpH?=X4Tvxm%*k5#%BEQoo(T|9 zfClx#6^R5UCI4hJdLbx?e&`?+AW-6>Rs4Jq3a5ksFOXPkU}h#JsXyS&{XQDMSMUCOcu~f(OCmAB6htQpi7K|6Q?20NX2?8LB#!%x^6znP{ucL~;~IV%0gR z-_M*|u|dgA@rICBO_#oL zCeEJIsH3ajP-CfvntG>@Q0v4XpU}iLrx~9y)_h8kW(k~)0QY1-3{G+*a6UL?EBD3T z8;eGIl?*p43M3Mk7DVoHFdXJ0Q7#;foEHdpR^Y_hnVBe&1fB~O%+qVb)xM#xx zoDMvNmjoiwLl`|95+)^XE;`$JN#JGzqNp_O`g$u#_&6yF(O$BDG)rdvgvYwM1c2*vJO+S0r^5el50nW86qg0?kh?aV#EeI zX>LZ44GKpgc>W183|SY71|zZ_Q9lE0&7{&?HmQh{jmSWuf`|<`j(fPTUz(ojp9#+N zN&#|Ska}Zcl*IV`q(2-y+dnfWO+_R9DzEOx)_pT`vcnH7GdStTJn~V}4Bg@874JfH zm3iP{tn~|1Z<$vuyYHHu*KPB*dm62+;SUC;amNkA@|A2u*WJ3#-&+hd<_C7h<6XG& z+HlhJk)>|yM&FfE$6kLq+t62~;R6F>s$J;%?%`D0Xo z^{b7(yC&B{$C7W+w|pjbCEdIyTRV_74dzS-GNuDr)4_GErpfRLqj4Cn9=&H`tnRC0 z>##m%5+gOJ{CT||AWMwEfXHT0T!X0AfEd-yX?;4`geMbrf)Lw>F*g~8y$oj|AaMaW zkBCSvI6VXVAH*9KZXyQ~1>_WWjzp)+Bm~k9f9nlil0iyZM=tWPr*YsNvjDG*#B zO=m?35Bnqx7l3nyr_4PTm5!@}3j7g5qU5GV)`>#+oXipt#SO=iZSavzem^$#`(rM3 zDSayF7*r7L5M5>N+FR3YPh{;QY10U40npe@J+?*Ol6a^$#d2gp$;cqpHfN>fZ&x zJV@OtI!RdzO?iv+MVWXS);v~P?@gVoh3!WHvJn_nKmxWyQKO-#k@Zm^L;0RH`2E5~ zK#HdlDF{6c3s^q{5o}sV?V8iGWLvbozW8BJ`_JdmVKppr6~jynk^x z?cmZTZu96ms6=(guw-u9%+m%^OzXGJlPgJ0Jq;?A&*2{Jocc_|gZXKYixM&t!L=O0w5$ z=4%%EGp4q@!e@hOvI~cyhp0rt!wAC&$s*#d21$5y9Y|Q9nOX=%N+{Co3CMpw z8NnMsQkZxn#5KGLVl!U@v1QKev&eSjGNZxsaFwLweWIMaN=X&^enIJRiq7`aq(_Ot zRy)1wg#zRa?iw2A6wc(+Z#cI#(iDMPEnbTC;V7I++2&V3ewrnFplO*HqDL*}Ek{F9 z1Vykq3hHtZ^s4QnmR)c7Z}_ti|)B>M=OxB@D zAD0<|Bl=9hU;`qRh9@9TkcG)+&@Lr^Bno#7*+M^HzL2jI?M<}B|BVNBq7#OLEoyiB8{e*H;6^S8I5EDk}oGE^fS&!QMe;O3~T4*9ArG_(b7me1KDRNNk=2E10i z=qL1lW=|#KhT+fbNnf0kkvCl17B^hg^2UTI;*1+Y#qC*IgUVqNra16Q)O|!fq)eD1 z2IQEDnt08%Z4nNj<^mKfjtO(z4A44&S_@DcKrL|#K+OQPQ>dPI0Mr_{UfY)3c8=wp zub2|H`E6I(IRkG<*rlSuD_&G46OOneWG>B6OQ#i-!R{H?(wGUM>Rl0_y*}ZJv$Td2a@s_#hMC_McNMYiruo`p z-V@(ychy#O4q1vTt~%wfup!Up7Q6@7GpX?xF%@y~p6Wf6>QpbU+JD{ax3iu zmMR9S8OZp0wKP#5uaE0Ky$+=q)RXX1OGBtxO_jdt4*r~dp;V(G#1#@7KD<|*pE9=8 zt`>$m)KuvkFRmtp%4|hY=fxZNh9)NAEuJbT-6?Lmmvl7t;{H-cPPpTG(V=1Dwzxa4 zlzVW;se&@m5ZM#g^NqM?L^t0U*N0Gnt_XaS+TSIHcnkg1siX1R;@GD#(O4L#aYOHL zHn-Zl{^EJ%n_)*(KS?e0ByFc-?uf%_;kkGN#I4`6B%0zzQWJ0D+u}wF(Na7&#SIkN z9ygRh?G)M(x0gZn#0ov^jN@u{#Q}HFvtH?k?~FIWy3pX-6>Bkr(Ts+J1g&rf(a>3h z$$HS3!qc)|k-XZA(HXfW5C%JDP@0;S4bhnZJbH}D+Gj@h$4n6Qo<4H=^kk*3gI47A zYY>&|I-70o)UI7kh!pKWVAn1(=#Z&`o{%ls_d}M=rRsKrySQfTp?+36*L%QcAb1a@ zmPmqDZmNGwfwfT9PV@WanknH5PnF=Ctju27s8E=o+z*``i0!M;AmgT@(?p62Bd_&_KrW>Y|H{0M_7`f}+zV!9QucroH zdpYOr&v^T@-hs4pfNBP^_VlrlzXV*9mtc*X&`i))1g5#EzyJwAlAML847*VDCtz1? zbpyNmZ0yDt__$FX_eGsBg-^VX6zMKkVyjFt{L@ga zHoOT~CSi=wQcz~*M7Bv8?RH4~9lOMU1cl2YaDEnbGLVf0woI*D57~p%;sDPotSGZQ zu(^OZMJHFd0$-)3q=%-*!hz|teBjU*<8f-MTQC_B9}@m}mAT6!X z97w(4HXIcCh)fP+@uWI}v0w%9)sYi0P4Z=&s}{_;vK}5G1wwEIvTi0IP04zYm1M4D zksxTqCeLDoGEEUaIw?3U$ofh8(ZIFVI7`4OAUaL?B{`23kzK;G7`)6&zGlT(Y?v0n zXvxc3c$p{9W2LWPbOxgrFq(h}UMq^rBs@Z=FuH(I6w5V#HHy!0609EH*!zQ6xw6y0Du72OYPH*KkJq-~ERHF;-!^2)-+WzVu9ZQGI5{MPPW z)_i9=sr^t*tXZ53qbk-0GM<4umH`+^v6AGh-FK|rD}ju)|5w)TwQ>_lU1P4UGgH@@ ztJ|BY+k5M9+H)XjylZtV=v1=xWt@FkYk$ro@Dc;n&flWUz~q&xif2P z12Z}Wy*hqRn4W%FfBKBeds7A>>ic`0LRO0plh8kU+Do0kKx?Z~;h zGp_C|kn!}&*|ci_2nob$x?^eouy)(BxGbawQqQH10uy_Fh# zaiw+Tsg(n_hHkgtu1k9#PadNkEl*|ZJLiuA2|W#KUA;+N&eQ}mT{Z25cUwo}vgeJK z8!gL@RP5HyTi)B|5B7i1d5>XFupZcT3q#8-smrP0%EfzH7WS2vsj+rkpb zWm;j=p6-kl>{cIIJP4gm9Z!8}C6M;)$yoOw)K#^v9iZuYI7+EGcvKp?-St6h+B2H5 zj>3*{HPHRw*pW8v*espUw1*1$`V$c0TVV*km4VcPtg32@Dw#LuG~jQgjrmRqq9Ac) zCO`1$0FxlNfPf*7#!PD?CJYKw36j0EdP1Vwn+G zb|_9+#kR5S6`ZJ|{J)?l%IK~#YZmME;cLVBe!!`+_tCbeWvq>xF@z$3VkitU5Ip8U zYFES2q~?m|LK84-J+HX{SQYCcELeQDGWsIkX~5U5>bR|DQ~&0pFnX2iRW+Ma2y85s z;q#BAY9%c0i7I#H>P||$zIYec@`kuJgqlx9c&CuR#4NBRw#AH4->3*+;RCEeo3B-G z1Gc7Wt>`TsY)wUsmt3Yor~p+2-Xs+*Rv~-^uL$qf6j!J#*>=DhgoQ1MC2tL=@QrMhZLZIjSTohl4$FLaRMhp?I~a2r6x$O_e>%TONb@U^QYx z`zjhjHZ-&u7T2F+;n79&7W=ns!T?t21DorFzO)$@FB(P=7jZ-B1uSkj{W-aU&l-!G zRc&lMZ~>e{N-ub*&7scBfey-n9~KlUs&OwW#64W_9QeKoyukOFi+!k;B-P8R4|p~0 zq*x=k0C$n#1BfVhjych>6gwd4`d(?^IID`~~qvx!)nyhGeFDwI?*l17XRc+O z?uEe8^y2iY!_+BY9WtQsZLdQp;jXddI-6L8>CJS=g& zwRSjp`0lPpZfk#JeBbzi=7Xowr%vBCW)F;KcRi;{UU-`W)d}Z$?Reg5yMA>3=&Q$J zK}(M=KDu;h@le*?o*cbvZA%BUZ@0YJ zvTE&L>)Dg*8O`*JqEC%w(Xu@L#+e&uz`?H9o*cdY^!(GyfCe9`;Oz@8)Gc$awu}pU z&$tFxh9F8lnYY@npO`<9v$kZcVE$XRa{0!Vgel`IilO3rtySSgd&q%wAs$fLwou4Q z4+t+Xub#imT+zP3TxNZ`G0Ny1-790KC}b<*JRC^ z@H)0?>e#?Gy6#xI^1j}jZzSUz`JnZuT|e&n*~l-B{QOAPcPcr8jAS92vF^I3G1heF zckX)o`8S_``>St$^&ej0pLTi7H0qBZN9?}<|mG(!#&!c>}DY@ zJ9)U<=*f#iqWoQ>+GBdjh2?+StB~x42@upXHo4$YFR@r%1?yLQ2nT>l}Jl=Mz9Z@kyp293f z7vLwN3WuIjC+_QX`u_V?lYZZQPngwn_g~a%^#k|K-FnykGi)uyUEm0}j*f5?1+)ua zlj38CZxiGdjQ$CuV;Fr4BWjB@ph0VBpW>wM0FP8SIFUdYtf#@SNd4Er90poMK%x%u ziggb)W>hZdf4Wh01$cnM22{CdK74X){K(k2fBc1KkNBTDdFmPebElp@GIsdn=#f#` zTUPqab5D;S_dh#wYFzP6#OGS-!bcs(6oix`3Cy^PoAM#@&rlhKgeXA-1_GA-M5AYQ z>vo29{Fa%{)XB88>VAz$CGKMIp5TuX1wy59x(8E;5?~iTNlp!p2080_WuBicvvg| literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/certs.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/certs.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..ea6d118323c18206d120abd84a609061c03576c3 GIT binary patch literal 628 zcmY*XF>4h;5Z--v&&1VO3Z|OEU>>~ORcS;75d=X}NUAi)zT3I?mfY>0b9=^nh1dv+ zt&ra!!C#`4ov#wD>>|M?mAm&Yg#)|H4D)?6-_Cy7+7is$>D{lzXU^EK5L{V2I2ZT5 zbIKGuVv4I#$*a-Ph%<~-biB(L-5N2B{TZDNfHTh&jI%E8;>oyu;uC`KMT?DVk{ro3 z;`M(f#Nk3WP+8TM2!yUB(|}tb)Pw~Rp#p`4Y)c1^A3>ndh0dizn6*Zgn84uz2|+i) znz93H5PrV-*i!_*AY1jp0EJrS$8wH|5Kjx}Yzxw(*GX;W@O+qd3Yg53DHN7K!ZU5! zSD>`j{?x(J*(^}ViPSPCR-mMP^+g3y+ zv`9IC0DTMx(%Fc-Q$(E&n2eJ@GmSU-nf|XFJShZr`A{XkMj!hAOdLFNCTd6 z3T_b>6}d`tO6~w2aLc&t4&uSkmUV{QVZ1NoIcLNj#iJq5J7exR9uIlJ+3!x^33n1t zx(Dz9cM4CrI@aBT_@FzDr`-y!xHEXhJ%kU1{zc~<_b@)}9>GW4Dz3Um@lp2}KBgdY z9M8gcoYZiQ04}JwPEL?HkSEEB1qGk#s1-zVGl-_bNUD>?*=uNxub`W;YiLEOmR5h( zD7n!ljI&zPcLS4a-@H9E?P|+ry6anQhv)$%%eLQUPDgKeH%9<-SA={Fpq8u5X{Ib2q35b}-9Lx=8r!D)Z^8b(+?}sUC#&sPB}% z9_70hbi{~33G!epAhf88caCIuyV$%kA!z|vPZg#{NcS2dBi(e^nJS}2UbX)}>( zdyz5MCy_bRrjA7xsJSR4C7#?JI8$fIw>^;t63A+Xj0JEbga)>@7h0feMm z5c}S6gLum}^*xt(ToglRqs4h(I5y)VCs%ZgMkg>C6Qg^zy$h@Fij-kke$y~$60#^_ zti!_cMO~8X-yFmC7JLymKov=w8A0b{U!D?$mdOkT9p{iG=6gch!{gFI(-4^!WcX~; zcburX87)dnagU{DHkz~~od+by4ia&BCORl-zbvxBbJ7ZrkSr6ULvmKNeL5^j4zdS6 zwJ;@gADHNfgi#6dji=)h;C>@IAz@O&0SQw8qR?O8Z+NQ9nS&ChB~&EL06?xd71>7H zcDU^sQb{yA9IB)>Oa`x{Y!(r-p*)EN$2Ymidu^9cyJ_%F0B(7hB8!AZ>W^p(f+8ya zp0?BPMOXKI`XQ+Dabb@E;1(##b2X*Jx5`Kvc!IPSg^V)zd=zD;A8D0ts#iei?BmqP z!_-JO-b*5_aM!#yvi{M%iEi@$YI&qv=&1>%^dvs{ba<>g|2&Q2>)@;YajCzg*hQ zN>D@#K^6uCS(I%_aX@5$Z38y;*FIpE?Xn~37dLAutfI36Bf1>n%Zczi;F383?gD59+)|U0C+LB@9%{ev~zGgB*BE9H?dO zs?aVNuY2FF^{!{NA=HNB-V;6gB1(Vbp7$ME+eWz><2A`OD4XS4lr3_jT!*n+<$C;D zH)-1>#H%(7iW}>pH3tU*uLx(qFd@8Ve?^!OBTd=g_bKr&kH^)F+8ax!PbT83@0Tks zpYKq5bS#=l97`kC|F^)V z5D|;vOnNYd$(@Q1su?Ab8i_cIt|MthjVFu2BjXvG;*sds7@icpe2K}#v7%>ONsdL) zs_4Vrc#7S}IAD3H;Zs<73%@T2aRKxq5UqetY=Evqwxe{)4wNq0iPBA!FyN8hD7`W$ zV8AC=1M}j5pJ6@#ybA+WGH^Z+jECglTf+O=8wbMp4Xhi#tMNN*`du^WjnowVN7AvA z&vS%De+&q`tVG9DDJl&a(AAy}5r#$+qlp+j#S*dToxS?QUY}3Gb@X_gV>6Mu7y9C_ zjm2ZYPv&?6$Vz46%5XFm$DNc`X8z? z@!lRuj$?$;L@F*#9FJ#!Z_H3@8jGfgtkig>M;ZZ2Q+Q{b4JoHbqluI%rH83XCnhPH zlG$(G-?Xf>k{C&(qDiA=`q&9fP{In7cvRk&P9-OMIRKK0cuISqj-^v-f{1!Jtzc5g zB>I4I*c9l!srUpaG>TQL(y0U>I}*vl{#zTsU#b0KB`5I^XiK)%v~ z0^qg;Rb zln9;8^exPAEz+<=jKM`1LAzv8M~&KGO=MQw`ht-0>LaYt%YraukuWLSKCtU5%V{y= z|BP`g2u7drXZNuu?5tlxT7leqT zzvy^^=+QZz8Qyk3^aW2m1qFumga9MxqFWQ)MLST>$Xg*c;UrJ6RH{)F9ngS|7hTX3 zqN8fj37tuSz!_GeBcs?pB6h~%MF$ZSYo*3zm1qImEa&(DQ5LkBAzXKEVrJsp8#8Y#hT8L?_W3>6LtB<=8!zlVzxTp}=O4@k+HQq5%sbw5 zUv|G2x*WRd%1e7c>bf3!YT9wLx_NH%rLK!zm$qKqTBz=vcHIg!e;jVOP<6g)DO|UN zJO6n<{b3ai7Xs%4^ec2ebi2x36s*XvtN>6jmpyyBHNS-t z>fm_lR9s06CrA^^wwl*n@$fN>r4lDFKI1Pn6RRNzo@Xzmjm~ltGxtGDx=snNi7E^L z)`#X?ah(!$S!d^BZZjGvArx0^8fH_`(YQ)O>j?E7kE+@(ooz5Lt5p94nyVcs*otN| z7beb6TzKRB8@W*Dwa}r3%~v-s?mU#=c__E#P|kCRt++o%RHI*R+%SpqCT{+r5``_^ zf@@D$NFU-)T^8tnbr3mBAfm-FIB6W9>_SD+4V@)Ap3IbUfR8wUb6YvUO7%~px4Hub z7q#WIzk8u>G18Zh^esjXd$%lIklKUNB0bLO}H`djU~bQrWmnh zk8lOzL{yQ0I4PBulJSv5CNT<4O(MgFR6(ZtjzU{a%MVIXS(XwR=~y&&Qc4U5f1^)%K?|PmYcy zp(jDrmLF4;w4#d_`^orZ(S9nLtN<*HX9d_&eLn$~BD+Az zx^@P-DVsH;O^N&Pe3Gj=*l`)Va6!n)z=@f{wxppAG1$1q+OwO?EVM==QggIbEVXw{ zI~G07c@L!AHP43CGK#bWMgTvBqNW@`<5k*1hzQf9-Iq(Riia=L+zc&YF(l9I9OmZOVr>6+#_3PscB8 zdXm-jLY1mknfR}G_@#RZwa5+yiU(@ zgWY-GvQKn2FS|r%4;34hT{TYMa<}NLqo0q8D=428mt79j21I8!)oz6H;R=3Y6P=wa zcHG^jJELxkQMbjY+ra9m2j@jLofu|fTsoPraKgX0M`h9pTQb1$!p!n`_RkD&2f3PH z3-&&7^yqU(;;IU7gO$Uh7h)ul8csvu8q$0Ny}i8?$D^5tq(`D^A{I?1CwnCLH`0*v zWZyG4kSx)-hMmvcQuI)bE6`-%Kj8E6L8h@z6Vb^^_sI|q3egUyNgDmw;G-6{yCDlm zG-H1+v)w0Yd-~du=t=Ayk{J?gOByovEw*&>YG`YudG#?xRbN9N2C#q`{5SAcM3d=} z^tdX)+onuv{tCS#TO*Cve+8JL|iZvB3YEf}b z8RnX(Z;1dCX{trido*=G*@=oWkiCS8Y-8DUOU+-S)@1oW9r6UuRn1f_dZfHZny131dkGPd5(Li~M3R0hxXQ*KEhPF$EUQj76o~1e}M(|&ywj?eb5ElWbQ(6v+&h;b| zy10a)hGkl*0~HKNzl$5QYBdG-sIDz40oZ3|(4s9}syJyg`JoK3owjF4+hvz^Pb&|U zZtI?e=CmQkYc1rkqd-XrdNrV5?A$)g1XqpSjx)dEp?~T8TblgB$|{2yn9hebG@p@coD{1+HjgTt51TglF}0?-EFDr zE?bHFFU$LIIn*a{_wFtx4xiVglet5&M)P?@lkj@*UgWBCL*b2PGK%s`fEwRJ2-ijX zs5(*%#W|P;H4wqCZpW$>BFCafAEs!>)TvOJqF1t{V!a*|Ai$_@RqNBcBJ5IJ9FrkuVMDJ#m1fa#+{3ed-9EY z3ckH(4lOy{i;l*;qjAnY_reXw#(S_baZwqSmS~PNTPtR^>2w8?(Pm{Iy^k^JI$_W( z|4n7dz<>wBmOa6c_M8F@AqGjFGP{B`^3ueu#3LA5a787zG&2{5H1dEm7!tdm>lXLWN z9Fg?UFS16NBx!@>zW{MWeEg{J>Ty9h?VNI+(A$~*PKhU>DJkOF+9}&t!mv%8R#HZ5 z(=la78#~&V->QwKwb?u6u)?DCxYi?~)-*%?cGzB`qO+L5lmjb+qwR}W@oC#>`)P7u z7~VR)7x}d?V^I$Yio)4e2RtmGq?0eE5E`L)4@Zr3Y*HdcvxjaplUquYjsnF-(nBT` zBO&LNsu2y>qBx13_jHp-QqnNKwX~!m+My-sZ*#-Pp|0xQl zFVxhXd1|Sqby;vb9}}ltOaAI}56(OY!_VKg6sW_`oPYg%=fdId9=USlTKfa6E|l}P z&N~)d-}PVdUz2uGou@{#824P-e{ugp=XbYW*?RTVzkL1oUeC20y5V{Bc8JEmT_bFW zEDKPV^PZMz*Q{e!Uh-6*3(bV)T=R~3`G#lfCw4sL_mP7qe zIyH=#Sccj5+21}&F;5AxPAM}%p)?kT#qJc%NTcz%wofSuM9mUWNrhSoXBs>Sh`*I~ zFbNpohcPq%qv}^GASSmU&MN+taaJ#4 zs(uz_53pEk6^pe7KO=AlogS9#8wfBr}%j-dsc&Ib?mMdclGE; zar6fKt;gR+xdAPkmcUW6{}b6@X;!_HjLg{Rayr$O(a=6gzAQxH6DjOiYI+nyvM8x4jl$O9rj4N~X=`BPvXQj0je0VH z#>Xhe&(|%-mWb~ha9LgP9C@n^SjZqXziql86juf!C*;F0*09`RXQ=QX2=?1 z?~RqEDX^UrItc5a%^%Dq$9tuNkd6j4SUQ8|rJG1AC)rSGU_c8sA4|W+cVT@jsB^H& zPbJ8khmdq83Lvq-^w5wYREMxt$9qRO^9&6=^YU}1M+^Z&Lx&T|xT#iy#fzzAf*E{D zd}KTcr=-!O2e<;^#E685g2ocDlMvkyuv*vNUPO_V6im3jJ_b2}IH~}b2D}-znWRaj zl~IBtB>sI7hE*_rN&3f}29F8?-P`ehg)EB;$bP}LrAsdj+0$BmYFq{^(I)cpFBF|t1SV#H;CwFGdkAtvBh{W}M6vC73o5o0^a9$_igVi@t4Z`%2GAJ9M z)i=)`M!p18j(h5XKzHpRd58y7=|OoMo{JdRQ!RR)j!$y;u9L+W_zp_yRcRZo(5ji{ zmaW$r#-I%n_}@oI&3Aq~X!o`vOte_LHD9}R;nAy|A8szxK9mbQ^eFsTaQG-(>$Sag)8w*rT8(8CEMr6tIYGXL`+XX2QCa3N0Hd^cv3%<>&*) z`|b`rD`+` zx^zH-JF{0yw1{o?uD07OdllI2q|acbx+GuC_K%zja7*fn=pYDipV`J zh#+J$5$mJ?{T!Mb^m5V4ruYr+aWJo_lct+Lf2FX9;3N~06 zeDo-q!4`}yh4gi{TX5j3hR8A8j7*a=sv&ORKSabQ4WUj0@t6wULfbe~3N!IhytO26 z`YE%9o-n*=0Zb)HNFaf%8|WTtLNm^`td=MGv;R!JI#B$L@F_F;8e8XffAa*1khbZ= zOEpawww~Ww2&{)f>}~tW3NiAVQoC3Ne5z#o2f4Y+0dFNabkkZ#3V2h@ezgQ>OCU=S z@NCPjgssal0WT0$V4N9v2@93eDip*dL%7662k@H8s z`7APDa-PlHkT7ql1g`%V^!lw57zxA1dYQ4Y2F3D5M7uvP$!Zw87r`pOOfY?ziZ@V{ z5vs2=)$F>}@GU)Erk>Wsx`7jG&-tE0ppA%i!%vj2p!qMHP~R#+cn#Ev6A~2FuxJ0bao`1Gb*HH*{<}|-^8QctN9YUvj zO4oI3OIOHT5)>8JuuYS?Z6>K(LB${dT0U1D*C1jN3)|T8qzp7Lq&d?DO4m;-cgx{z zu#Q>m+Bp?7N65oi$ZAsd60x%RW?NT--*{+;EKqwf!fL78V@Tb(Qe|0ZcYndV;JO%D&yE=af@KP8u4LVH9+) zf=^_KC)YCPhB4ZyXeyCRMkSsXs#%!B63``ae2+yFif(BV!pnA46IMC#n>SJ@Rg8^( zm2g?fMox~###PhoWe);`LXC-n$m4>ewbmdq#)HlKrf;i;{gzKjR_kj3sV7m9D^#|6bb#ne&sp;SWL9vl7 z`Ezo?gV<^)PE@5C^Jp_C@rbOV*VU4?!-I%U;ww?ud99Am9luc{Xg)s~dfj$+y4_+v%Q1L!A zIeQQi&dwy~n_ghv^`8H-e<4$lc742M$9H?K^vwD|QV(8y@LIU*wig|d4H9n2d73#@86HEt z$Dpc5@Z(z|c^)&k-*QVi}w zg?5=C0gL(nJPMp~&+6bHa7bFo;2_jwiUnA>%DEwzlX>sbQDz{Eq0R`$l%ot2wLlpY zD=7LSqB2DYfXJ`d$AAH2k=7V69zRDIpyW7kl27nfo%76iX6t6hZ+O<MHTa(2!*y8>a!0cW4F(^UGG| zfDuK?acJAbpw{p(9=}ZR2r_uw@d(~FctRh&p=ZdNg(pe)5dNa=>_N?uT?L`6J@>eiDzJ2}jHDI>;5SWa-(rQ5YU^ZL6U6R{AxFTl25KO4y`r8XLu}K<(_|3(uT?X1?co zU^^Yefj+$$?#hR|7VOun{ z%*{~U%tSu4alSJb>RZ@-E!1~)Pd?O_^YpD|8PcCflUuopqLNHX@jEL$Oh<*%GbKW^ zgZTlg)G{He6tl6?%ODK_2D_V%b;Sl{>J-O5sUF~U4f(%|Usf(QKFBa3{xLKm#IqR3D~s!Qs`lt-pk&F&VqE`jqpymda8EaL2#sI=5eU!pSuyza^DQq2g7>spP}{7 zaZ|?o29SZWLrfXJw<6B7tnRId^DL`1lyOa2rz|U)RmBy9q4okay;As2hS~PEO@@O5 zrG3i&w(Z--i9Q_IaYU~JcKWVOJClZcLv?_Mjim^X&w^Y<+Lp)NJElPHlV*bssvt|r z;o)MIfzu9F5Iflo9jT;5Wk|b1 zSjaR1V=#+}nC7gdi_*4DIo(>mpr*&t+}Vb1xay5jwSL^u(kFH6HcrH12rbIK<{;!Z z_>3W_Ny*$P&4OD`eHu!78A^<&cbzo({dc`M^3EJW`|rAYSmxUPh|AaCgkfg;4uaZS(Ab`Ip{% z_42D%hYKD1mKs}Ur{+(+_xk16ugZn4zNHNv;=`5dS`?Kpds(jOHYMcPY8gTda! z>JG;0&Q+}Liv9%Hcm#45E@7sX4{{wz^8*jj=Mr$woW@N4509sqolB8YWCx|<$b~fM z3!*}n;&8>_vlFme;JMVL$p1$S7KMXJm7dlTO8^HwYDWnwlv#z-Fe%x9NuRpoREww-KgSsDh za?L`=UqeS>gm49u-$9A)ZcPLlw8(-EHK#@l3Rma(0h2w_=s1H>-pA`ou~2a&QKZ zTvKr1dd z?fGzfA-s9o`LU5x!q>cRA%7++D`6CpR=icwfb@y2~vxS3t+S$Oug6p+B=9mPmmo@ag|)y8Uc%0 zgeNJ#MO;R_JrBTzJ)Z&PK0Uq4E6{#)>0dMS7l-_cESv9 zM%Y=4v=Vyl2L#<6=m{&Ly1h`n8L9D}pnfX)()Nqn3oTo(dwNhwhsS2+>z-DqG1EW) z$vZd}JGGUQ508t$=jaPhlh{!~6qGScJ8dtHvb*&)!g7OC9|iX}D}RPtE6W(%sdf1S zT3LXtj1J&V%}nJyt&AQb_Wu5Ud~TvYvfeT!omiGTp3czSTU30FifJl{8I`kCoTuW~ zsh}W~a*>L6sJKMMWh#D~ib*PnL6m<%1#JP!pHT6ADoE_G9Pkao*`NdoU zwCIQV=0Q}zNP$dk^-UC?(y6V>#@`NnPA^(Ou7S zjoaBtKO2|BE@%C6*zc@gX{mCy+-Y+-o0bD^XYX>26McgY=axJ8`QRNiZeI!4IG+|* zx?52$_c_rK&v(%&zlOgL+MN6VB%4%>W~yI?SKt}APc3y+Lzi7^_s~ZI>(S95?q{%M)6aO5p{JJEo%{@ZN9t#&1hc+^C3CbU=#J12 znMqq>(M{|L9|KnoXjxDWcpy8BooQ@R+n!jPzrf=UiHf7R!TC+M@67A?meVbFa9W)` zeBIspaj53pYcsEXJ&WMStzgZ$#7tt&{`J(E$Cn)bUpexXBX2#sR8tR6fU}plI<)9% z!Euy#c3*nn;sf(96y~^ovN~!odGM8)nR1pW})LFisw)oOAwd6rTwUsTl=<9W*yiqg{$!{ zQ7G9KQ+C;4*~!5)JPt5_CiRmJQa9V6ut(8>4t(DPb^=*W zFp8p5JBx|&Nw;gMqzX|}zw#c+yW;l4M~j{(aP0nBd^j&sRdi!$%BVM`20Q44N6Gre z$KK+xaV1`KBgTWMriwg}go;Dva?y?O69qYoe(i=niBxo;O$IL4;n>dmc07>XS(cTI zK*I=~3rX?ACzv!ccW_(-lh;DGYM-QB!(59&n#Z64Z#JW1m_w;leOK%))@YUV(YOT8 z#>(joKf4wrGo{p)9iNVP*sfCa9>tMMmbTB6gP88*pa{P5J9s^FBPz#m2jz;HAP-Y5 z=_^GSR)~WIMfb6&Os-?YVXSS7bWl~H;@^_o_z`YcsI{)1KG#&;KxGZS+f=($(}?7L z?H?lb)va?!b743onm%a_23=H3dCxxjO!kHEl+a5AYg+j-s5d~?I5`NIo)F83EU>^gH8=jif|bvHM5%nvX8 zQoeIfVdGw^T%UKeEp3V{bmuqiTHJIXzv;k-YGKnMdbA<$kgUeI<*!@BVDztJZWu+* zVeti$Fcwb2b>;h-0`CC==(;gy*`RA0|+Vl{b@0^3(uYW zEwT%rFf&3BRz3~WyGc!{xb%@qk-pMWO8xaa^bJxgd?yPoSvmAU_GJH51Zr&DT$G43=;!Pv&9;wbg0?z^j2GT3=9Sb^rpq);K$_OW|e#jo0G>gZR zACm+d1(i>3KgHx>Z-3T38hvdWzVwmxYBzmSHY|v%=#c%rZ4NMFYb(&I;tDu0RRhf7jQ$>Dd=Lm$VWPl751{8aK(ko1dGvG&R$ zRotM0xeDkVoVTHj2u$iIOLX@`D%cPY(;bZy@fYow8$NjniCgr&L|;VW(&Ml3wCI5d zMz|@e6kXI{WVGmkQx~!J(KwR?%EvTN9~BRyfXVCP=Qr3wi&fNc5P?I4sbK69*XSyV zGC`fF_#Y%qkPJc6#3h7kp<%eIrW4oPO_ZE)M7-J1{Lbb}k&BVHw|-z>IDGYie9!(u z_kn!NfkMMWGmoQ>FFfnL=51MO+BIEuv!><3_Ve4{Wro{T*VW1Vj)NcVFSLKYQ1d); zi~LQL2QrxtZ@gL8G}kci%{Ol;)FC6U9)`#4@qB0llJl0TYR?VK4B*e~;h8TjRaGwq zo8~&_Tk$VVdx<0+*M*<0D zQ(z@Et#gS5*TQ7J`+;0nU#{<|+`6X=HP7S%&rq7h5%I1{D$z{OA)D~0wsnV)WziL=OSe+(e_` zw&A4GVqvszZfDvA3xV;ZAk6`)MG3eXz#J=m5@jZkb!&7(xFt=d9i3eR3<&Y%2)`i)$Df8=aV1^#*aAi4yA?SLkvC&IcJJqW1`G5C4oG`zl%9ucwa2kLW?0yiVw079 zpe(b~Wy*BI^Ij2R)n6j#k}vR0bAGd!F@l3SnJeK^P>^;%_IXl`T~A}Dgk_2O@M}u^ zDPz@j?DVRk(d+%oBg-^4{l^JbvZC09e6n@q`~ef!f{7{8U9CSW{Vm0^!JPFDl>cysQ-DA|qpm^DlZ$^wJ4pUu2NG8~43i#SF3pC}^UQoLRHfNK96ilW0{0EMa4 z!GriRO#(;Zwe6Bv5QaEoI2aHtM2n+~oEH-*VzjdTuUN%qqI-;$AESR8vDOvbAi5V6 z0u8f?cbgYC?#^%Aeck`Lo57}B^S(lGf6lZ2mb-ek>z&=#-O|mvt_Amp59FSE@p|1$ z)85-*&M+*qhb1z>HbRc7iao6+%V6ji{c!h8q zvFPrljolRC-#v@(uxk7{|LTqKE(-1M#&*j(-S(p8U6%Xwy^Yle_XywHv+>#K@P9AQp5bG(V z?J6IkDEjgFNtjSfODTrr@zK%ALBlu9J}kq&9ih)GhG*c#6~!uHCS33&Spn zGUYF*VD=4DOFp5WgprCbQ{DCK<6qJ{p!{zVE7yB8nS65vcs}kgZ1S`b0pnyroKPUzR-Lwv~pk*mI}T zE_&vA?g;pEC-9gp#8ya#--x0)1lle{yuuyt?nQPbr2U1iee?TAlSgCzjN+swj50$Du% zOvhBkh#B!*JfE0uRFwwhMa4+mP>e>|bT{UIH?1++1XPn+gf=tU3^Xa5W#ip=&^p2R z2H-7Kts59^1=?1HCK+u9+98us&l?!s2y{~w+QMij(9Kmnv@*H{=vJAOtr3eh#=C%b z0}W@=&geFv+pGHMV6+G5jw*B`qdS52N=JgK|s6u#3?lpnIygbTgU)x)*)KA}-q)e;oKQ@a+-a!}vbnBUQcZV00Ad{wj1Q zqfY>RQuanX`WQU`^eNdVMbvXY;|GBsl6_I@frY12&y+4F9rcUCK zv7JvU83wl8RM2g7Hs=(j_35Cee`|ULRq(u>XE$WuDsfll zW-D>snR6?RSLf-MzpON;)0v#^y6Ln_%R~$L#@Az`UcN9|Fbn%Uw3Obyl50C9<;G{as}(wKRBNOD$s@1&V?uEIlvN=}I!4 z_I(rYE$Q^DMLiePG^Nvqok^#80+rT4Eg6~1L4m5XiFlJa9&)FmTb+)-{-mL5|NZU)p+HP(erv43Q^} zOnex3w$Kn;Npz9uhWJqN2WFlSA5zTU6%MMfJDp?;GD$ zRK=qK`ENZ(<+jR|a6=F_#V>td<&tWuL2tvb9Hz+J$Kh+9Q_OhGeND8*G+a-&GE&T% zj_djUs^@ai*W^hf0wL5AMOO;b8$uWbCNO)1|Eiu(pXbFCuFU~8>Va|t=}EW+nK5V0 zjQ_pvNKz|0H3UL)^mTQks1J%8)Q@io(-oeeF$Wy0-}j@u1Uj>)ue=p zRJ^if+|CztZ;b}nAJ~E%ve#71p-|564m&gLK+uEl7VQ1qYr2S>pR$yD0OAd0rA=w> zeV`5A(*~EkvUcE(abG*|iPrr<>%XV*YmxynM$Y7Z{-C=19X67nqJ5sVAl|{bj zdeH*RNY=k?1zM+eYqTKtppohET93MBzL1l&?5U^^tTL+Qb*!)lBg*BtOBhozFD)Rm z@O|GLkxpm_GAt|`{Z;cI0y*=l&nB>$VNNT==-lLaF;5OFW)|SEvwAV-@jPjyh{rco z!G=T~gjQ%2F#_2!W@KUeVER5{JBD-~8C9ym>BrJg&<&M~NJ{3zku)%w$51Y9U!yFT zO!x_{u1jGKM$@5m?0(Qbdar%-?FbAn4=DMJ0$Z^(D15i^AEyyXjMGam2_B!I zy2fvsGV{_ddZoKlaF}4I4EN z&>vX&SPdqJhzW^wHItn_6T<6a(t6HxU0CVGOjhRg(kQJg>ByzB6no^z+=$3}UO^z6 z)32K%{pJ0yYEXQJD3Ty5k+Kf^6hjRrQyL*+S$-$Cz~<=xV0e@mlCY~8KI1baye@|Af!;1q zz9r=i5J%8L_9c6a2x66k<*lK)V;I^Y;o^y+$gt0g@Va?;Z+Ua{-J#hawmx#i67I;aT2_{AgC^0ofkbv>Uktm7Y7BySLgv! zXvQbZ2M5l35jDQ-%i%L)flsOQVGW*?=p7QTJHrhFm;UUZ7 zc9b%4xFw^b{-d3U--FPxKQk6;sPHV&Ch=A^?UO!j!t0{l9`budcP!XpY5NO0ZXR%_ zMfjfOEK>4*8rpj>{5U5tEVG1!++#fy(Go2zPIC znEg1Uh+`-eoHw}@4!JX?r8^5EC#^XzTZ8|3;!oli)%>S?{)E@XKfJ4SPe_n8u;>fn zOpf8WfP*?`I}i=4g<(sVE@$$*Gxy+X{;3@^#Rk;H;Y&EWHCJn2_C4ZH;#c(YBnftX zf+kXr@g-hmQ_;!cw)H^O{+^GCl~!8r=-&jD#th%u@M+dRZZ`#|bpMW$?)dmL$44nX z&+rDGH?zDu|e@r zD~&Dc-dpo43Vv34Rkgp|HMFAOcSYNx9x87gEblq8qTqF9zp4(DI|Nk@tZ1q_gi0z5 zQDNX#UsTb5^Yx&IMpY}f^{y!RUD*^@wOi?>xfKO3D{ZQJR=vd|omHuWgXK*F^wmKs z^adn)sW4XFyld$S)s0c{gc_Ak@R$3`8~c~WsD3}yAC9UIQ*qxd{&XL`pHa&_k5j`l z{NX;7?)-?#Tzj;MSC literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/help.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/help.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..badec2e5c42293f240e0018362a8f8a698fdf8d0 GIT binary patch literal 4289 zcmbUkZEO?Cb=JGK*Nzh>aU3V);;fT^*@QTh@R3qPo0gEmg(M}w_58LjQ@DnI+PNcXS(VJB2JOHh%H{-D2nKqW*~sc&Z2!O21I zu4C_fym@cln>TOXd-IpZMlXVLwg0aReSU<#AcI=r?9Pi<(7B2v6h{&xIZ{lVp{*nC zpe-9`Y0Jeq+B)M-+PdN{iIupNJI%*E4Dwji-niH9`Qkp>bEX>8P4Onin)k>3l)5?I zEV+Jx;w_RJ>Q;$|Iv}@6o(sDX!n^~?fjhQ<49Yojjy@ze^dszqbsTZ;hv<|2%jgpO zAzEg(%=lpD$hH}f4rrR-YlhDc7)NUuqIV^FN|UlFS(w*UBdMs0dR~~zo)@s3(Xb&b z%BhTuck5#884+jd83VP*m<@@i_H zOv@6Cx0l*}S5Y2xMfDJ@qo|!%9oZ%Yqy8Oe9F*oWiCuEnA=zDnufdk6P1HtKyX4zC zCZn&RX!_O^&0nRsL$m{BmH8TOtrlK=EpZnPfvwC*&ZS^I-0J85j}^~5?${@^%BTlH zqpojx3hx1p`&-gDBz~32qdX&dt~+Lt=uJKZAx_Ii7OO&1kd%2tSXPWh!B~`qnVhkx zse+Quq~x>=25W!?3Q1KGY-@~py#kaOtX)(jS(wvoLN%F|DIQtH#uc=McP~npna^Sj zTv9m!XH{}FV#09^3-YBT5nzu1ynkeiG!pyH-q?ts5Mfg(xIRRFy2wXS!aRCdh}yW( zJwntLfj}+F=&CLHnMFkx7P9I*-P*E-FX+OYtQ+;r$cATfGr7Zpq6(QLHkA2nDv9?H z_8F|rCFfE(%3IQ8U5$cFu#B((qMx)B2)z?nQ!UwHQ(2H!hQ%%dBjvoMRee#*rX=7k zNSZ3sWd&^lv&B6g8PLk?FF8G`(*`G~H*_3#zuPiVl+_>NMT92E_)Gudy(L8M?j1R{JoU zY_LsYx`;eU!({cGZnk7{ncSu`Q`7~`bf%L_8iqzut!5r;rVq<0IjKW+QBIlMlBN)0 znzpfO-#V_Xs}p}G2(R}K8|ln&M#&5rNqk;5hE{Y9uSf^*a7vjQw!|F9^3Sqx4*D>0 zzOhWs^l#e`4#R4_@ag}As(@a$qxNt)I8q9ZtOpMirk=Qi*E-kSy&Dm+92qS|M%N>U zOMJNE30*t5=804ygXPG+Qe@wT&tLXMO1?Ry!8&#|m3+Nb7xH#o8(s7C zy+y7gYo6#f@RP^@uzS+hTO1xQH5@N;$6vs1(Ut(y2ml&jeo6z3=NpEYZx&W0=DK4Q z86LuwlsDl74BQIzo1=Hov&Lq)p!l1kci?jpCpje- zNbEE=g9RRX(|;RX-E5n+$NGAyy?$i%CHL<*iwo?bvo>$+sP!aXa@K+x>>g62I;{8J zf#o)cLDTX!o~yjX=J}s=Nz#AnlB8V|vMS@GL42g;JV@LjPA*xOEychg zxWK0va@us;?gA4N#gKfWDNJlebkKq6xAUc%hcKB-n4~zO50j(DT~L``Yq136Ri;0y zLjX!_CR%2P1(;t8;HuKel(HgYl8sG6Ha0suX}YsG1+HbpbQ3&DHq6$y5cuYC zE@NotaWb=*GdV?4lO|ttLt?8XQG|#^lxVuAXU8!H-%pMWi=-l=<3UmlKm`~!f0hW* zK0Px&1)apX@zb*>rl%59XHWfb{Iux?512FzjQ0@2AwtN)RxwE%&E^{anubKL*;w=R z3F@Z<+ng;0`s^KBD50^{w@aYm{HU(7WJWlV^_V88hH`;o8bR*PL4n<3$=z2)}(#dvuuQa}F zLtO*wI|hqfsM6MbeYxDTuhg@z7#Jx`R(f{d?k|Rii(D5>T{DV-{=(#AcW0$<&x6t^|b~jZzBA*>9_Z=+t9V~_pUGaenZtJLYbpxArS7GX3JmURNL*a60 zpcER|=oN1b-W)9V9xL@8`}0qVkqJQC;l0vS^&(H}r-!Z|x!wII$9mvx!=c*#V z)Aj1*ID>qF=ZJH9pS1S?7pl3B8>=ipUh6HO?aSh^4)l3P(=n0#d^ZF2mdHV#2sCn> zgHHX^#2`>wmWWYrE5_#2q81IvbM7u%^Lcmd1R5S~oakH;XCM(Yazh!cs8-5E-d5Bo zAOWGdt1g_Jot}!Fc?J;-yo2e1jKD}-kRdg3DXIkN=ak5qPPzi59lEBPPAQwt=$M$* z9}w<=#%uhbWoJClZ7P z-f%(Fok&R9d?JB~sajWlKk1RkKrg3t(}|f|*ZlzLkvnfToJf<`qU98*1Mu6oFh-u0 zSec`D+Pdd^2^sYqWCK)OA_vLpfcXT0ZEoo`e T_I{Kh^E{(!Yl`P8}NZqNtk+%w-jbLQOd-1*eqZ6d(_=;z#b z4WXavp$*&$n!^z6BM&Vj59jeR_OushS@U%8dfBiN+aFC%pKMYgMW*2U>%x5gA53$p zzy#Uwz0D#e0r$6x5A21L&1F}ctxM&e>bl!c@l8PmMK<*=f&1~uZ1 zJEpn1%BcwalAx=rcT56Uf}(AXqt14c+di&Z6JR=6a}wM> zlHe~eh4zrEF|ZZLsh|+$(OYddX#i6}i{Nn_Jw+Ctvv8DnI6ptTr~9x$Qi zQbniNZhlKy2V=GA`t6;WFDdKDu>Qaz4A|Z=2Mt%9sErN?Qee$0xP27jXIMb*3{`N5 zAGb#idu@d1u*IqjJ}UoJ3$cd};nFB@J%p>FGN#bVWl+e_P-ui&4l@+$@9=9}NrZ_i z-t7q!6>YcAK%usXENy#oiiyCHZUN@+#B(Jcb0zaj4lfhG1Z19pgd||prNqw>&yh|h z>a=awDHd(p(jpzCjFJUMI8t(}BhuGtIZDK0MO|vK)jLtg`cqI{M24awGgdR+5lR$w zc?jVu1i@QP#W}nWxIr+n00LK!Qzt_s2kdz0_WMb2wMUJfq2r#h#?|X@y3Uf2aMp>^14l-G z6Fz|EEF((Vw&%OH&D9X&iN{@hK>Ug#RF~(ScQ5{^dt5cAh9pM7o#`0kUz&-Hvq5C` T*V5I*?+%Q|o0n2}Ab$NXK*ABF literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/models.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/models.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..c428368db7c1def5a99f965a5d015f145f0a901e GIT binary patch literal 35368 zcmdVD3v?UTnI>3;7x5wif&|}>;!^@eLQl&Q^{^#Tv}H-OBGGmXJ550ZC_w^1x(bv` z1a!;pY#L0Ih_ZWHRNLL6GoCfo_KuaA%tSqtGi^KR#AlwMNe^Kh=Cm@cnc1A(>7_(v z?N)kD@Auz&ph!V>(r3@<-I925>(;GXx9;PA|9}0v;$l08<8tf29}0YnA;6hx03-KXCln?Oi*AOt`*BCX$%mFh`*Gy4MtSC?vvj(g&Tfi2x2kbFNz`?GW zqs~}ypqS+?(UO=e;9~irs5@2~C`H~HvPC_yvOrm^JW$Tg?NM*6B2dBdj%a19Do_=x z4phf#0yVMPKy9opP#3EY)W;eE4Xln6bs7T#%NHZx6ljVy2byCoffiO)5^asO1=?cm zf%e#%z#3NOimr|M0=`&Bpd+>}urAga=!|s*x?=u-pIvw3dUaqu%a#`AvaMEMFeo9NQAu!t&neL$R%att?*=eK@u)u#M#_quXQMf$rFjz>e6?z|PpN zz^>Tt!0y;1fk$GG1|E&=3G9jO4eX8W3+&^$@Yd65bxQKTD8+oOK2UmLbs0x3e79if zkaRp5zGb>LvACUD5WJ;sG`lh z1Y8`AhK0f5cp?~yOG4sQSQrr_v7k6644*h19!yYKFd>W#p9_n^QMFO~FR2TCK0a6e zR9qSz85tH6;n0&KVKJD9499)uoTDc^h$rtC#bGh$IW#=TE*uGpl2TTDL>x{G4-QA= zD(<7fDrO%LaCx!>&=)l?VfRqp;@sm0CXgtDNh)4rLX)qGOeZ`OW_aE6C zlp=$BMiZxeMLFxfU^E&$5e?^DPaJ!)Pya?mhl3*{)R6r|P{KH~Mja zJQWl};Y7|hI6Qm?{f?Z#Gfbx?439BqL+|8w$XSt%3Ph`1UUn=YhJ!IYMH-EvH?$b2dMG>;#LNwx!n;W*Fw;~}rfeTZ^FUk*$E65O zR}bFMXU}=j?%2#9Tv%df!ei9AfoMcZ{IUT<5aHHRf*n7IGwo0y0JppoMVGlS2TZ^P3}N7bZ*cD@ z)dHrlIb_hCTX1gFofnOnu+PesouSV3;mC`T_#mx&^&luhf6I4~T;@)4<9tH9p5jic zy;1Aq_Z{W>xFKaYtw0;yWp3PBVeHR@j!@}^8KseNIx3hJO zfEaAGte1jQ4Pgb3P1YY+G6-Xti7(bo~+QhiVS zTJ4+(&^(m04h%3XFmTTdl+d-UpD<8pSPH-3v*qj&ATlWtj1Pu$M#AIf6JrVBilS3N zDVRuz;wB8QSVjp!@0>**53vd-1RH4lau#3;;I|xqCTBP+<@mFC*dXqqyGjP++Xh(g zrDRLN?Y^?oY1}CNMU-W%W}h-s+ey>-xbnH;%qvGyl+`Y)#!%`Q+Yg zb?qIlsI+EsPqwn^(s;J2;cD@f;#&_r@;?8Q&GQdEHqF0nebYKqIWKJd=qrnbitTil0N8q}Z$PBiH9u92Wiijy4q z{Q`KQtom2@1g^_RiqAtEb#6mo2XE8I$W|bK?s{2`LPID&Vc3;F`5h~*vB1lf5Cc1 ztX>i7VHJ&|-ncbhjWb{^`E1-4FHO|m{{(qOq>9GvDa*J+*I!3|eDb56s8d@Q(&k5%O=S?ri&Mp? zTh#0M-<0)TyE?~=Kr4W+QpNci7d`=IX;be{X?ux{aLKqURg!WI8Gv6L!GD6ynWwc* z42Q-9aArbK&^WdA#Hn==m;~r&6wq&iZit|lgx>@!!alo-lQEuKezSXU|EQDzrzo>Hk}r=7 zla;+}NMoo#eH;;o&qhMwkUv?|LvzE*H>u?YIa$B_P#Aoec_0E_#P z_)IwyF<*lcWrImjU)RWjXuP!RV+g3=j`cI}E8Z^m>R+4^r|3 zB{HIwnK1D%N^)j4z&R7q7da#NFL50e+Xz<&MKL(WIwcb1&6UK0XLOPRk;p=yJ7=ao zN^*bg@$fnDjF2rzIg9d(>p0ID!O)3Eaf^6_8Z!(f@OKJ-ar}*-6^8H);!w^+t6c>7 z$VqM_>TIdMGU6{*aXNc?viS?~KC6?a25(|po#$?sb8hdVr!G^!bwf9ZKEpN;8o;h#($KG`_O_PSKw_?(83k^5F zA-%Q#-R+r%hvr>dvsECF7E7z9JX254m$u^cYSERV*KL=~+0wGfnykC(W>w9k`BrKD z^v0QoZftsAoG*O>y>yl=IO}Jf^)s6?&iZ+$KkKZJ3#Lwd;%r)a2rqSa8`tpg_2gXr z-dSr++LVsobd^m$pKtWAs%>hoENKBcWRFp#qk49F5Xx;~OD8DSL}U;Y{i)%Qcnn2i9LY6~HOiKr_z;y+(vLrBH@##_K-5Ks^k0$-eBi}Lem>G;)HN>Tua4=wE_#~hnn5UpX@-u(ZuM@!v;j;j-f;18yi~xXz zI)!r)$UEdxT027XJ-(U2@f93B4bo=(Ez@#3h%qO+`)ie;h4jKA{(fFn;xCk^_&?+? z^WZ|OP23pwzZuW**Z4l4L5AuC3n79v_&4PEQxahfL0}8=o^9vJa6J6th`2ks>AuC_ zS6`C}3H>{xkRV5;-G1$!ELxIilKyw@^Yh%ttw&}y{>c9R#-E(}WZRQ(ePy=w$lpjL zcY4L!$WIkDqCZ7BGm|%p&!ITqH-=qA!Z_gNUIc;)T{DW0(5ab?TF%7oqO}N6u0Zh> zol7=;N$>v??v*4Y5Z72ZXX%vbs{M+6*3nE*yYcWx;g6ol^gorUe|paIOvd@lEr%Dp z-Q)9)wye|5#51FSDhtlmS!e5X|0m84nbTve-F+4C;@3^{tw%m_9swLKS;Kbepnhk8 zz?FB_abzxo+xo(_s=pKU=~%G?_!chD^t5uKk>{S}#ti4U7md$y=Xjqn8R-eD!-XX~ zB8JaKhDRmcLI$(W7P3a*91SN%MQ9`X#nCW{1xPDFHH7eswDPg2d$AVSB~U1Nnx?swz2Zgmwt#&~CC-7n+)RX9rmC z&w;7#aJ;Sh)3T~1BYy8m#5cXt(8RrI>oUH}cNzP9W^ov0;s_-#Q1W|}e3Oy{CHpAZ zL&;e+A=Y0a(D4oKj=^UB3cp+d1S;30N`v^*4%%mQEN?@ihr$7)4O71QU&sQ{G9NGz z7z&s}W~3Gw!u}}| z3_;q8sfV~DECjVXkH{qRA|x1_#3{ zMv62l-2$bI!J|p}!rlsNv60zWkz|muf9L@*7#glpxD#b6WXYI3RV*({D`_;CR9+no zi1Pjapd&#FsBVE&hQg^}JQM|H#v87stIGo5kwP1 z;Qi=?trz_Qz_6(+K)eR>0B9O<*dr5%=JSS=9Hdod$kR+p z-UKPW@w_2IQ&LMH+U2BwiB^EO>$r-V$>%4;=|tL;t*D)h zT{6sg)8=ediT=GO+&rVIAP@~SEC)!Hkyuh-9& zuOTGAL1t4y4Jv5-pv~Z>i)@)@1ewj17WJ&e)f+bI+ zEj8-uausgWs|eLCGY($uG}TyjVAFuqSbd;W+YtF{DAl&Yic)P8tSHr%|BBL*{F$0V zyTrDvI#B9aRfJQNYGUgARg`KX>wGD;z0xy?U3pB7A^BA@j!1~3WNGu;5JocA6@zgp zMz$9~!@xa&$ui{}N%(#C2k$hts|sv4pEKuL1%z`&3Yh-wTf1hEH~ga*06pU;UPeLE zrS4RveVCDP(kWay&)ss?&N=JTeAa5aXq&KsroO!6(vGaV{Id0u75n4zp-YFdo{GyI zmpULCx?Fv!TK!RKDupX*E_ped=Pu{4*_Wy~cWK(n*6cNVpLY0)RuSd7qJe?X@E|tD zMf6Mj14^jxt4Z`Ul~MBF@FzWt=L$%oo!HK&ZumN4qmUyzorCI3Xk*cT5m4dnP zP7lwUJC`jkbE!>G*hb(n zNU{K1G%y}yDW%(4%Bs7cS?Qz=#JVD#8XkqQh$8%!wZVx9Yb+LwLk1Te+aZKt3vyDB zK*~eL4?;RLIv5s4<1k~2h%^qYrSQ-Ynb7@1(O5E(b|0O^=r7hkL3j|&rCg?}lAhK( z20H)%8;xdT75u~$trayo?xrf|y5Xq`lz|*f%A$5{%T8j-52W6M8lj0XMe2%{-^()aR?Kh>&r_b6_B0M%O1Vlu_&nMUk04Je^^%7Gdh7()#WFsau$ z?&X@o<%O6?6~x71If|AwkeCO8XsZCdtL_}!qxAqa3(>&5j_E8+5A!-kv@mVV>zGr} zyE4$VGxA|I=2?eW$9M)U8Qd8R3~UYHliXSKbgmMxGwIP*pYz-q^4tL%X>Sn?O0g1b9UX%xplkeY92}V zeCObjk#n}(zd^Nu{3hBXcoO2G&{08&@c?ErWO!GzyD2naA9l*Fr66TLTYK z4yZPYcrIa8&tKs+6^FS`q@B&o2uBmrmaWV{f{XzpAxMx9K>h4(?AY_Hf1(dL`m)*&5%3R1Z60oTouP6}O8X40D0?n>X(p=i?5YA)aRT z$K(bD=nHk_kHfbr#h>NGHF$ypeOh&>^$MBx=8beED-+3Sl+KvRw!*kp-Cxh6#<+1D zW`N_C@uG3-xDA%^p1i?X$PA6NAp}!m2xN->STn7A1;R?nl_1o_4yB%Th2}bMe5Tze zl`(x?y?S5%H>K4XH^=Kz=7R61nSH@HGXHFioQWdoJjxzI!l?A zoJF*v9CYLB+#eg1vLg5c6pt6>#i@F2dw%|P=6epE>6&Iz29E=-pvhXkhBM_9ohd8& zV8xi0q@3u55ypFllylsgH&aWjQO5=XR7a{PWP;Gsc2YB%RA-RZ6Bq^EOhcoo$$7Bt zE645mu}aws$#uTVy#jOVar;a5a~fDcD-CK7(25hlqu_{ZV8oTIdk|zM9Y@XtW94o4 z_-?=o2-f?OPQ??4DYKFrx`jSyr^o>(Zv^cZj)cWi!4XLq8yynDxDXJ9Z7oF zZ3I&^%jsk_c}Kw984NL$1<)8pLIT{N!cjl;_MUr*gq{22aMoALRIO&JqtNU{sK^ zL+z!QVLw2;EWU}xlC`Tru8QQqDO@2qJBI|O*(GF}J^02$^Nyyh$4fG*Dd_cEC-&X) zcqa#6TbteoDC_cEJUwyx+tIXf$<8@llPwe7Q-fC{S0b;US!mcY+py*O)AJ2GVTP6N zx$t<_=~=QEZS9M@AN$Douj8}M9qHc59uVcG>Cnvn>)UQyId{dPr!nhkn3ASWE^&N& zSGH>dE|mgkmu^`$8p}$SIAd|iZ9CvPj1Hz!Gy7&9&TQ(*)bF43^k$sBcb%MDm^RJ3 z+LjE);@#QG+J(wZvz42!Z<(vycFBY;mv}A?Obko~=8M-dW3z2@p6wauc3kmPyjnBm zNn1X3l%lJXgA<3-y;*C?Wa~r;6}nJ3#ZR?PRZO0qbqeX;+k|D9TMAh^43X*8RCM04 zj_9qSId50G_olac!Mk?WyLP5x&buLP|J33A)K#9X6{glqmri$2cV?>AUozjUYK9e7 zN%b2Y(?c^u*F!gY-f#P;D${m!uIAWWNq^eNgzn$5ets9Uxx1NgSv$Ra@aoW&p^T?3 z<81piVYT*O-)-m0VG_p|?_R7BGEF<@Dt2YuyKt>|_dSUgZQexVZ`t5v&eUd&!8k{W*X;J{tqIJN>U|6RrSBdzA8`rE80~@P!qe#!d0!C ztL!9M$)^rawx;Q7*Oji<*Wckx#k(dgx7=7c^X{%}L+d5Sq-ipoeR$`j>9X^ZbH2W7 zCNx*S`D6E%+cwlCva(DjD@|xwJv7?odyIAo@#7}^0e4HgQpT5egbd?m;D2qx3Jr0} z7&5+VQt6vIiB02`#wPi!0oEiqvQ5p1|iZR-#;>gompoGvDg3#Jr zOH&5W9bM{KNKbcIMIk}JogFDnnuO)NK`qVyhU~O>nJTnSEgj=SjtA6s7OIWDRG>bY z^sG8kpdZySW*ZCCU3?2R=_b^FXjNsL=4EUvW?eTYYHM%?DOK->gI2LxF2eH@&oG2a zu;#eagjH7^DUD6Rb~lUlAy?sdC3{Fx3KtwTccF1uWxwSax9F&DsF3qcWT0{Qam!1V z6*P`E{&{LAA*h`nGJ^84z*nCiw?4~F@)z1wY6njxSi%m}DFb!1PCYNQa@gI1dbh7M z+58}I#jH@szQo^`bi-5xuD;Cmd_CE!^ui9^1_A!?IhfeSaZ;p+2^q^K_M!_pQz9IV zCN~~quD?(qph2?2AoZGTze4&2Xgio90E&vi=%@tIqW@kARC#3J-gPJ(Kgkr|vJ-Z) zw4d~JLol7%ulQp#^YmnszI!irojZ4~iy7j8qLAIgLP^zVzKe|JlTP&s{p1i(pK}Zj z$KX!)BE1@1*hXU`l5FzUj2F?7WQXa!jCgNm=O`Q6{|;688YM*Rio~DiY}BsIpqA`` zvs(mSck;PN$ShX`Zj?E}{X4pa7{y z^Frm?*-H4*-SEy=J~C;#Yvsxtrb2J+pD*jcZI{1(>Fd)E&sDCQG~Ft%yyb>{{?zF? zw{H=Z5^tUULF;uZG3y=IJf3H%?mM z+Y5C-&n;KQWMb;+>HaxaN5-{v$!ad$obB+x=ey>6XWe8E>}c?Zo1)m;)kj4r)Hb>W!LYJdocAov+ho& z{`ijV^SkGG3@cG&+ZQX^r^V}A<}0>k+}ns=E8hO=y8`EJc;lt{_4_hqJyfe9TV4N} zg)TPy8cv2)jdwU>>1I$3>o&f#cCu%oe9cl33hqfeuo^B@?ths3V3(uU%Y9ho?cK!v z#lyBHXB@#e&$hYvq3U82h0J{1f=F;?j!;Ck{^i?krq4AS4F$xZoCM-Czhd&bc>b+}+rZ z{*CFLi-#r-WvYE2J3E$aTcvN=7#d`|=&F6$;8Sz|?rWxSDzSC#dyc zj6ydd+z%(cjB3CrR?g{8?_4C5@m|%ns=3Nd>Bkovo2R$EF@9;=_11LHFB~rNZEAhX zJnw3Mck@i*o$WXHKiz$+vUNI?Aw&X@S?Znaf6boW16+hvdU)dSf>Qu5Jze^C&6_pz z&Q4aYLfQ9h*KD6SH!W4;$@02HceF!Wmp4$P=S=lt+Cp$iTU)YdR9owDx1JGEXAxw- zRztTI3qmxkJ*9^faO7n-2=Ic+t2~tQ8G}~b@*o;eR?n`EWxygH4UNW`y|nBSBhzrI zu?SgU9Y4O0nJdCVT4qCK0}?2Z?J8j*t4!o)NU)+MLlF54(LMY^51bZYrL2{#kp!{| zIT`O{mMwCtT4T(vMKLvjPl9H)0&D3AA|6C3VgZ6KkmCdFcS(dNo5;WlSbY_(tw9Lv zhU4(8fSn9k{xTpv2m>A1Ba;R^8X00S9`rAx8u2SbsS-%{8HVJI`h`95F$fD!AYQ^K z$Ts#Q)jC+9H$Q$n51N?;Gscp==BeP>FwANMnD$`c1=%{L6IL^D#FVvB&GO(kYp+X~MOINk62Oyhj4d>7nr+-P@7SEJYk^AZ@U6P_ z*Nf)rwn3(M_*Ru~ruDt9Yh5?W=c;z6i?fcZjH5N%wn;`WQ&k^3n}JxIZTD|rO|rAg3vH!zoT%WJLiFGv=S6*9$V!1xS8)X8EfQ z*-L1E84IsO)Bh`qll7|>QeLQoZ6%$hVIqbefYHvCR=nzf;Lr?nSQ5@{N$=O}Xs1S} z!!!HejDF(Wd>bOVEo>OXEA-$b5_E_}&_2&9i#_p=sK!M~E>rRclw6}^ni7c;CRTov za^IumElP;O5DBh}G}|J*$!a4%GI?W)>+Kj=DTOmK^7ELjch{_lk#G9+{JZ~s5Z(J72 z&71FZdd!=b*A|(T@t{5p;!ith;nK1Eefu<@dGvr2#e7&4^f076>oMAdu{41OP6o7H#By5|>?!6yjHgLI_eurelm+&N;{% zcT~bToXDQVOvu5aiV$%xF^oV`R>s`}j+38S5WG7xc+VAuqfpg^Ln84Lg{^4Fnq9V{ z$(s+51$bVT408}JZ)n2K)J4JN@w7Tos7v}6cCfk{zroHl8k3!AROU%~hNgmL*GPcM zjzp!J%STi}ZOs%VFJe5ciH_7ei1&F%0b9676MwQNxYb(lRxtMUGL^fpRQw+(&XuY| zProeGT+TcI*V2Ue*SMUQTIY;n@SLoBTA~a87bUkTVYq>z0xOY*2?Qd{*(gQuL};z< zP#v0<`|OVh)+9^S1*IAMy-I-Yo45vZ`6_1Fmu+fKo93+zS>nAf*h#7&P(jsQdtSB; zpvVjWt+=dZWXnKYsv^rlvK3@TgAOJXpV>55>8IkmZmvpLsPxTN`evFGQ8|duDi~Z8 zawDK&riHOgGfvinigk_*_FhAw&bl#Y8-V=*C}wyDcy#Zolzl)iOKSx$>nck-WSpf; zB#JqTfX7jV;Ni{$DH@JI+eFSKFkVfSAp`QY|=qJ=G z2ktO&$|9(spW2V-zds|s=2!(HSD;d(S^_!^ci;bk4W z28W#xXY7o1da_5w{H;H%A7WvP}UCMJE{f~)Og7jrm1^sPfTcRu>(eSg;XpIry9 zLvr*7C#OQwJu|Iy73*i+>pylK%vcZp4Spng^S8Z^m{v$dXg#q3eFYgJPrhiXL9Rgh z$b{?^y-kBuDd@CdbgG<#NGV4I8r@ac{TT9BS6ngX2bUI-&(z0;v0o&Vh%x&XesV>U zEXeeknBXC2W`o5vR^rc4fxQ~h`?7x#1{60G8qj?4f1&~1i+i!$YK5yiuIzYy7g059 zCJv^1CfgRBWlU#l{>0f%O2;)29NOHIrc8wo;jpY57OgH)Tut?VVwEE+6h;8ec))LF zM(NP7obVj8p9Iaspy8^$&1j?*+ebE?T%h+My%FB0v~H?@0kXsTu1uYO=0wJ|F=O3$ z|1Q^HN)78J_6&YkAIG?BeDDmauJ-corghwXT!%ZEld8fS0PAkqutBk;rEkkwoOg@Nje$^puNo znEvHrOdjBa8}NbRL8eRo-g7S6Fyo?~l2z+3=RmlV;dnAE4x=LoXDX9sz@%E~E%Zf1 z$ZOdxzVOCqMOPn$Sn@_?%;lUR)(QE9~C>HSM7?T!S#uRkq*~W?jN`*_^8_V^tVCyp(pBkRuqk+=E03 z%%H!nRMeqK1Jr1EgnU4aW@Nz^G!rC9NnS()f1i!EI>dsuApife?fyTo>w5bs^t2d^ zAYw3N7SL4@S0FZFy6#&*4$M>1p)LO5Gk0j|bfPNupU24JO)NN@W}Qv*&K8ESKfenj z&4Pg@+-2NrwnpQh@Qub5dxcgCTVJ$VAB;rKaxe0thmkhg+QJRWkq`E9mLiH8l7Ezs z(gEnBz5xw?P&fxoDpP4fZo^EB#c&9|8Sw04K3#*%&x)i%+VVO9uuSe$6mJwaL6|xm zqsT^(W{nAJPmBrOq-*FtuJ|D#N{lodMObgOVd=Oo##zovQDay@a-+1 z5$Z#{4f6bwC^CUM+J3PD>lTU~#^f^UVh!FYSIR_n1KQ2eF~r(dThhk%zJd2*i0`kK zY)}`KzuWt?XZhmPl?Tb|3u;4 zZzC3X}8$Gp>FRw)q5Q8vTiDaaf^CotLtBnS2mroaz^ z?N{i*eZyp;rjo_lsL-jK2BAb7gz}5YiDbqqM~7Jf1Zd&W-*P_^i2sqw$IH!m^;98V z2h^NNt(*UShsFp;h{ek~hR8pN`12%5U0~Y)LkXgp6q^SG!%$)j!mpFbqw(Gd)Sm#N z$0CbHKmrhHMWu+F4{7xY#QKHlgVG-O2Q9U12i(#Ol5c)f!( zhU%fQJda{DexLh&{xX;5)7%guq<_OYZk#Ac2aBzFwgoi`jBSG2Wrr%Q747$na9-gj z_?Oq}+T!!UN7ehJs=UfCWXRi4N`?D|I~C+GZi4#Is1haP<_Em3 zA!T9#IuNQ>bS8)KEMbt*xgVVC$?Gu>RI%CS*?T6)D(7F zw*S~A!!e2xgmBYws;*%aWy>k#cJSUMyMV|5yaYuN#tk7B2S{n1 zMF{JZTgAA_92OfV?L~rUG=7pke?oJpV=WIL61n`v2jxQ#G&8isw0NvC+Xgk8TrUJB zLS0TL5Ys>Zh_k^6`+|rD1@p!eG_~q#%Cl;N>dv5F0t%b)xBSllSpJbgj?0$^(-X!* zfEwJ6vNc7&jVoNIkn7EaLGLTIAHLRK2ax+i<7LA)&1Mcpe1-{QUXDA45CacrTay6O zE6B%$Cf6llm}EnEf>o_)F$C8=%w5<9zD5In;A`CDI@xvJQUL~u+&K3V!p!ACo>H4Q zS9TPvO^A{mN^K3;6|7D6ar)YXf!I-~wrZkCQ4k?}f>#1t{^T51qAV(fiG&BkAvD9} zQX+*{5$To121;n+MS+qcN*XC4@q12tPiP*nJwp>J-^wRj7t$| zoj)&&w5+PCIk`r|jd~V0A8}EwxPcJmf4~zyXAu{fRodkjFTFTjh0w7}23x5=+t_mT z#Vapf{oO0SJCppVb?SHL8lPM!e=<}4y#7dicuWnU1-- zhbH%bS}Q+s0WKMzSK|dh8yQSZv4>hME=7H$KEF6hfOTs<=DH;_~ACn z|JdZ%=Q94-Wu|<&5iKOwNIHtRSZoBI_4PBQ1&7@YKIK&;6>|YwK9@!{%hc(e$yS>8;b( z%YRt^{raDn=G*r#dfMhZYckF?+2YDfam%|;Tuekwmq12Z-3qVm!*3qG-p%ynzo-&kx2KD5Hn%S{Z~M4;+ok#&v9#qE zj_O74=IgyTdgi=)(!Dob-gGe|=lcfrbQR@W@VD&7E6KnV=2T?vg!9!0Y0BT#Vi7=4 z9fTwwF$`X&I0j~7-Ed}vAEUWoR0Yj!YupldqmHI#%Rfh>nLzg-Vk|;1R^y`B1pDqr z^-L~H;llxRjhSyz$bEtes}8L-6YR+8tt|(NP zCH!TD&(g+v4>Qa_?NT|1Xdy++E2@3g+n%j#y6#^xausWqIYWh=VtLo6_mfnpGUIAS zIJ4=tE3QfNFI-iCsaG9W9McEps{G_IRliWRcD8EmTvZ2ME}!yFiGNi6=IC|rb@BVv zH#U909v)PN4}2eQJeaL%yz0B+dwt!dqMJ1hlSMZx>lU1Kv(CDuCOmDa6>c=(l(L@c zZy!caoQ-f9F0Q{P5w3h?&*r@r{)313y(Y^CTV2Sn;6Q07;Ptp=8e=B1#mVX;#E){~ z$--JU_>gG3DX%bw?`lEgvXGH>4b$Ke23>WW$44iiYSv2QT_JNJuVJ*UkrY~GE};<; z@8DhNP=6IKS_;o6UqA{kV4b2KEoxWt8SptgCT)n5RMifNA0rbh?L413PpV=)(orsr8{l50fo;?&&?A9!5miY7p*mgd|1gEX%nmpc8G)_HnB6$ zR{+B zFbHC$VsC2gK~dGk#M@`$!{=aiiK`?+puo97QvIPNc_av>QS0id_r5?ET15YK0t#qD>t3vYDfHFOE1fge8`bj_ z`_hjA`?)LAC7<6d<4Wt^csAn#d0%AfhNE?5jZ$@NzGC~tV>ewD>5`=~T)QU`NB1wP z_PDqYTH|NH2bR4cJy-9QTUmKP*grx`w$<&{(p=AE?~fK&_2n$R~`Bm0GBl62Uuhz z&Etj6gj>A@WgB48kr(tC3)%dqjD^A}pp*;`Rvju_1lJE+k(a<W z75vk-CO14eiZ(!=ikbnhf*M+8LVh?X=zyCN?)v$T=R3}vqX-Dy!jmH`qIVR+t&{j} zYFzyY@A2dG1V04~mjD$=#D~~|jI2b`%`}Zf0x&vT^20ST%vzHCt3F@bO#!p1#~QgH zdrb~Q=mt_*Ym%C#_kenW1bT=A!8)K_7oWx)^&wht9-I)lBa+@y{EtW|^aDC8hrjVC zF>iX9Y)u9;v`=%DN0lzG>SoRulTPN02*F8owDD#Eb?H zQn}go$YNQ;LRsr<89v(Z_Oow3J6pE>dOH#XP5At-m#gZy!Z>GGL$txb?e~rGm$-T|?2<-pLI%b;QYrEEV zz4V9P?|X0Xe{TLW^PFdQ#<}~~aCoyla!=Zd_x-@;-&@Unu)T3#BllsoZC{=7!&WP$ zo$K~h8h>1AM*hc*ww@~EkJqm2DKq}0%#8dBXh{?ehL2nRS4bWNEekQidE1L|z#l+2 zUfiLBotgqd`TFKM&^?G^P_QLUh6v&sA3A?PtvusRjJhFZ-iaPx=mO(QUnnyrx9N8* zR8*v9R=f~h?|{1^-1#X-Z1hBLriBEDg922T{5<1ng>(?@;^)P~Xv>L?1# zgzK7xGKO0@5Ln2JFjQL+oT=dbx~Ey$)0)`R8Vc9Ob8KJ!H0+P!yn>GW^6;%bW$a$z z#~gZo064bcLG}R!$2Pw=48Yd^SjC?{XL8+9GETX`a98HC0cI3hz#?lU|%I4VMC zEl2-h4)aNTEp@nS+qQ?ccWsPJVvR)Z(kgZd`($%D)$nrq*(v51!FgzHX%_6)LaP#H5v$$aozw>1~chi zL92@8)URr7cda(c`LDFm{ySR4Mze4=b?K5t`UubEGndZ1g-AZWCA+b>8$QMq`+cE$ z-E8%`naAd;w_G9@ZEUmWEq1$}Y*|aj(>nd+ z_1^2-ZgjsN`q`-uPQ4$@(r0`Z`Yow7fioYDSL{Xgap)KO9z=s9T zfz*;?8?5{&B4fWuqj(bJk&dA2=pzxNa4a81TDETh=N1p6K0227&%@`h5TGIg6{^2O z>r2iF97AtL?hNrhkUUHuz(g{Ci&4;y3~ z-j7c_ez9+&Z{AsVs}hdVq`#SIfKyuK?zA)OsLVK8K6O@or;nCaD?<>FmJ+D!_0<>j zy@H}palpDqJ^i1Qkk<-@0a5(15DE=0xs>$MRgn@0ozkZQ#5zg<))dZ^NuOK?`u88z zi=M~_OE&)4LpjnoiiAMfK4&Aa+I{Q)q$-r0$8wd-s7vl!2Dooo9i^7@2kz8#nd|QS z4nnb)-?8v!?;VT9e2Bl}wwPP)xOwxYI~FV4vdURvFt=mZT1svkoU-c{KAndg7+xwf z(WjZ@@99yNoV-wKHrtg#Gj zy}dlU*=?>@Dk2AYEH&6-u2jm9yYmF!XnsVkUSe)gE+KbEs5S3c?sk}EYZf*xzN519 z+-Df0T!|`tko**UGH27ybB4&U91O$*cn%w#%{o3q)?3ovmvxyWos#vIC2D2)>zeYH zIo3f_YxM!vBFO=O&`&j;(AIpP_mJdO-OQPW^#w`kq!fV<;=qXWMa+(QxU|#!&j{GMt6`J zV#6TGRrKud-SgC;{sGM%^3Z|92l~aGRO2a19-`*YQj(_R4=G_AiOj|rG+^qCd)A%u zXDWA#r*IqoL*9-Q8djdi(&tUfB^>WwwsU;N&$*V*OcvhoD~=Krul+f<_2*pkf9D?g zIoJ4^!O9yxjTO}CmI2IRc9SCALvQ?MsRYb+l{x~3 zv8rGh_9Cdd4L>(b@Txa(?Nr`KABMANOJ3*)z~x1^>*ACDpUZl=^hD z|DcmgaF9V6)GY41wElhfk2WL6lNeP@65a^>*i{PAV+N>@y9LrnpG6iS^cB3{Az1W6 zP17L=s1MEb?FFuG+}jC+XM5+KWMAaDh64d=>KCF*vBlU<^_4?l_&$_n3sTj>jrpGC zf%UBV!d zSFr{-X`5{<`0Ky;LwSE_rgyKp?t~N1N6Svv=ew7q>-{VJ_OShO>$%;vd#R%kyu9AI y(z!wM!Ep9zq5a|Sc6nc0p|)Wuyck{{-q3bxZ)c;YpxjWB>r~`{J8w49{rmtXMFUI# literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/sessions.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/sessions.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..39b934624a7400aef43c7d64a3250e809c6d27e5 GIT binary patch literal 27844 zcmeHw3vgW5dEVV87P|}VF0fcU2m%)bNMJ!c_!bF1WQyQRB0-u2tq6XAOWX@$!F|B@ zE(iiz$h7Kdmo^guQW`>)5`l>tLY5jck7?+poltHjR?=j;OF+ivmY&kB)7sNcOOedj zR?|+u|J=te7E8%>>tveAk$CppbI4Hqge>-bgUoKF}WBIIuC=G0+k19O#U84Rl4j2fCx11~x@E z4{VNZ8Q2otI{-*ga_u)=vFnrzC!H zT$B@Xmn_P1I3AOoFBJx-vwtKk^U=649ufI5DSk05h%z7IPpeh<__yovZ=ER+ae6bI#mgl?$Pk^cUZ`-RY0 zLX`0689Wz~!$X7A2^9)jm6GG3u`v`@O4T7m!snEdaVaty562V-5@R7r7E#c5N}HVn zY^cwMB&AZVG8&QwhoyLQP{7cXfOsh(g@zJ?+9wTSSSX>CMMdensOO?V|ACS5*acBI z7#oTU7{NhFic83i#}Z;J(JSWXmK}{<3`N4i>7fxZ8dALd@%ZsjZ1R*Sge6S395gFs zf;b!+k0b_1Fg_WNVRfnL?!DB~{AMIDljpx(- z`}>b7o|BS@Zx#jZdzBI`f%&sxOjs3@Qh6XGi$`O!7?Z;^<7`o!N}1lr$rGpgPb(f{ zNMZc^9GAk1M-t_D z1gor<#@mT-Oc*>D7bcY|c_cm_!NcTONS2K<9<0IzadHr|I2ZvaDmGNvx@Ab)2y8ph z_M+!UbqsMOO_$9{?lhO=@M}8FB?!(~NSYGbw&FN_gGt`J_uT6DGHc7sCCv#PL2^mc zJ6fCi@3bXp87-pax0Rc=vpjn*_j!zOx+G~ymh9!OmRQmHY1A}vLzZdVv~>boZR!WT zA~sYs9HXs2hIJT|!l8ty?{9uME&(N+2Vlf_S~?(=4n7gO04V3fG2n*K&`^9lmT>Y2 zi4l<(FO5aQLtz6$@bMV(Ly25%LL*dCLm_BJdt{iZi$6Ndhgfq)0m4eOBZ0_5(j@vH z5hwYHa3sQ?6M427(PA8sHX=&=xJ+X^OXUZLB7mH;tg)a?afb0qPK07ZqC~SSZ9t^h z$HxSGv0@7+#Hbu}5LB}79Mt+(JQ@-;GMu@_m2$OzbWQ;?JI6+I;3d zEB3vr#)2CY_9soF#$H9H76fCro#z;_)pj?^ zb3bKy!UEJ63rX~qH0z}FG#4~ay?qi}L6jnsDtyWOxp-nkhhe}YU|3rio?+=OCxbFZ zQbAQ?;t;4PfE5rr6dIRBeqtoIgH*)M@7>G4*a{Rl2Kp?v_VAzm{4|4Y))E6N{+uL+ zF31K+W?k{1DWDaR$u3qf;a72~ zWKDg&8#$k)A}0{3pjDMFsh=-f<~L{f&9~YY`Mq~4?(zq+p8B+-{(g!7W8Qw>RWrAC zq3qVwqU)Ko^_fR#k{hB(4>}Hhv=2GgIgtZ{$q{o2mc}BO5nD^S+<$^Yu!1?V2{yd3 z3wFdMLJ4BWq$OCY_)n`Gj80RJhcAU=LwX<7rxpJgq$OB?fHKN02vP^~^J{7E1ye0j z)8?dk)WH9_s)G3)4PvLw2?PHp&4NXzFQ>UlYtT0J)G5FS@G2pFB=tmBE{oqga8Tw!@oucwrZXtdfc z5?>-pL=^!SR#}V;D^`LU=~KvB2?dOb>un6G2x_XW*o<}&X)h>wf!ZV30myhcw|CjK z=B{f^wtCI=O*-UkJ>d1p~u7A3% zLH!ko!C0<8#nfJ3LB5U2w&W4*+!9zpP>U>K(poI{!c(9Lrb!d(P>%&cFf&xsfwx7t zcfoRzlN!)&v6@y^(}TCgYT8iKG-)s1Zt*%aQjqPh!n2S+%>Rb7V#oH4~ zbifr#hRt9n?DE79?p0nsrPa0&|RG2VqA>y!V5hk4xbx z2H(62z`V)_60MiSX#Aom=*U#vARzbsighHB7z>(zcoLt~r`YHTtaSJf05E-r`hs?e zD39V8iOY#tC@Ly;nfPx}v5v*1gtQhfrJaa^4(SjTEQy2hB&N0`CQh(~lXBPzLQtHP zsioaRBca%N5%18DQm#K~&AWBJnclA80#uyq(|BAu=8Q3ZdTK+_y|${{moQ8@i|8`< z{i?Nd=NGFsq@4GRRMu6s>}trk8s^)V*KNu$|@ z>#lodJ@Y*oZzs~r-lmMVY5w`U-VXiE?u@tVeq{{^dCfZ7v+gCx=Uz%XIvE=18!{jkpGq*h5&s_D!#;YBGXWQz=cb*-iGGeHpLXSu zdULTIs$-F2`*Yfzbj_HhzXrO`9}9*-L1)dU%aYDfmztL!=SBgTcS15^t^>0%XyAcT zJdKv;*HF_YF0n?>MG1o5f}oEXUteGF3Xc~)2Z&yiXw=^bw&LYp=LGw&T9T%Bja~k- z3H>$c^>V-Zm*P8Iqs_T|Jta8w5lOrA=G*jf^F3WIl#Z^~Tgd$;TJ?0Yd=%1@!l3t* zbe+%P`utUP=_RH;Nl&p=6`TwwS0&w2B}x!f6@;Yw-Mm&}HO1SJ+{N<&HJ;JVf+q2( z&*HQT?}-O12r{48tY={zicpipR^z=fJ{?0(yJD_l@38}NGiuaImJJ%T5zs-WiGq+U z1N>@bu|5#!f214%KhfOC9+-+hRqjEQitH4_9neJt~P+G`I2R$#03_F z(ftJ(cue}hY#F1w%3C?XjBhevw|Gm_70HTXtqEoMttAfX{h<{i2?ZeuLBeRDAQO-J zAp-mNsQ&f|EpVgH>Lqf&x$i-(X}bC9-J3rq7+KtU=SZR&JQvj6i#W<%`SS9pEt_oPC&!bW43y6YtFkT6qX`@OB zNqytv3B`UQp;jDn5j#Xz zVobo12Li#kG^vzmUn=>i4y~EuJ_Ruq`c#Fp7AZ7AXP}UvSR!H!l9kYXCzO@tF8ij{=P>>wreQ4t5~j7362U?_1KB8JfpVJ8k~67d4kIx15xiRZ?{ z;2xvkapQvGLVJmE8H<5484-D<0+J^%h!7VTLr^LpeSq8@GjHTcy;RsT79UfrBq5bN z^z6_D(GmeEeL0iAE1oe``m4Vtxt2N(eTvdq@?evq(uHiq26qM3I0I^L@%&8<+(ZQl6!4-P2;?2 z-aNN6)qC~W1FNNMTh{Bp?taA$@twDFX4~~WvwIdj{Cw|n%Z^OTj=P>6_W~QTfyR03 zGQTCmZ%H?9y|p{-fBOBF#};#S#RJalt9am~9-h7OELyaqm1{3ud1+2q@-*LTz(8+a zx^Zc-VbhE&8>qcLGCQ)wZ@RT+dGmqH<^zj-@13D^!Jcew%d~$&c(p4SBEn zcJofm(2|?K4>5wf5fa5TM%S|Beu_TCzwBwucpC3{tCqcO8E>1Bcwn=%m4C=tyyfU^ z-3z9f@@zu~M3cU!XAWikEzACnjK5>qzbWJ2bSrS%|ABuW1eLz0@3(cNz5J4Q{r$j( z>^(3Luzbyu>ram=IF*2kF1=5+Jc<>oz^<~_HE?ri(^&i8gMxsTm**QV>*m+Q7> z>bBnM|NYPX_UD$|&t%>8%kGYhyCdDXce(RWrt{E}`!EJxy=FPko(Z(4H}1au{9@oB z^@7i%16jJE>lVOZJI0OXYIkO8ciyq4YkMDZ=DPB%m!ChJ_HMlEJ)Z7<=Fa(a_wff7 zoaH`ra^AXo-Zkm^jwNp=I;d<;9r&JSEf)0E()-o?Oyc_F>}1wo{lHRMQ*nPyQ?|Z2 zi@0_zC0c?XdXNoKP4)T@eMrq%9|t&JDu^8Ak zW61{UUUB}_2@B_``0-;uR~1}p-}guEbmehOwhFn9S;zIV*|LQ*GiA%(t(fMrZGSBj zcl+}GrsEx^_gdV?wsY@odd`H0Kig`ic>AW~LCc@7w;=uJZ6-S+8&3@1URxT(N6%k=lT-=s}1Y2t_n30kIp_&kY_&xxeo&`}o2LZAW(K^+o`F#=`<1ft;Bd9zx4hF%*%zcvV5ns1_-E#7HCz zwj%+dxGIQ|jrK?$4q`e6-46*gK~M5}hj2%Nh8b$&FtBp2&s<+T2(7G&vuT7%*$O#O zU$BJXc1Aa(=P^l2iS_|d9!ujgQ#(q;_bYCl>d_b=_950?N>N0dO|BWmK{6aFB-47U z^TOzYbQ#Z6O+}?J`2>?xi}D1@f&w_P?UpOrGZpQrl5Baya{0PU`MQ+lzN>ETe8#nY zp=G)KQJ_4Te_-Z$U8RJq}{ zkaA>Qm1$QaLnpzEJGjvHfg4+ibMvdkqy)|&O5CFk4DHDqR|A##2M>g&UBe}98RpG#IqFyNYAy6BUdKvk}p{zc@mX+ zAv!APn~}C6oivlS(;OIgL$m@G-GQTuS?}is?&=Pm+uB>o)BkRiY%BZU^=W*wW`Fjg8fJV({dt6Tk362kmopZ$Du)UHl2WktV{js1_Czd^C(b7dvmX zrhWt|B$;A2K?WeyaT|27L$CwTG^?~-SzlvpFc_WAs~Iin!-rjmk(WPzz#nmZBjb(L z2|P&?*tue3>jGYeAdF@V-C17KJyHT^j2@;1HVRHv7HRWsb6=ly3;+;xs=J*I3@YXz zj$LY|=oN}cHl{e96DQe;K>8x(5&qU>z$(@tu2yY_@%t_&`BhC?U{fNC5|bu7$UN1ozSuXZ*~zz`8tXNqtxVKlzTpv!RX4=buIe3mwh`jz8xw1y}!HP_!x?u& z>d4Fp1i{|GvWL%rpR8W;1m7O{=FWSadv5>2olA?ICsT*heqfvS`<}YAqwdF#eVmun zyQLl3rj4wDS4Ke2OFKT2>1g$y%lC|#`7-AaU!#4-K7b_@_9^fYouEV5%JP^v#6$t-r1%726imZN2xl!RkHlJ! z9NgclSPmbA?&Rc&)BVtqD0a0UiKv=-GA)%waS)nsQBrKfu=5ZU8`Ho9t%a18or!3% zh?J^?^dg?7nm-ou)eesn;9o*%0KS8(ShwtJ%lO(-cF;pmOjl#Z)%e!-n@`_(`mSrs zt&4X8cb__(t*T2MLgBpkyKn5i>*~6-_omO_I0*G&Uf!2<2L4O(;3my_1KglWwkIi33I zlu#`=pk*%=N>Sb^I1#%97h<E;z05dfxF?Gsh;hHi%l%{HhV zs4|EKk>t*?csv4%2kS#{q${Yk*3dI#HprimVbIvqqtmW^`}Xl+62TZ|N;+#xZ)AS2 zzUSmFZM1DcZTqnTqzZ3qWlG1M?r!=$7mjtsrSsi*(W)2SqpSJ(&u-bY>GS*4-cP{5 ziuC;$Yyt*{nz5y{a&RPkDl!JDDfeh2>FVlYY^?kWPqAxUn~C@4~TZ z3pwU9ucmQ|V`Yug8(2?n&@jM&W`G+sFhA?V(B>r!NiND5XEj#C(7WZdabbgHMd@;5 zWQ}?%Z)Aql7;JL0{yz6BSQ6{?C%u-=#xhBMu{zd|t24<3ZGDIOryM#cPL)s!Fd3|r z8qk-zx^Gj8)>W#ah*%DZ2B5CtIZ6#tR80}BrphqU$4Uel5-o`IE+Qfa5UWZw&u^O; zO^|6NHIpLX(QquB7#y7PYWt>3&-sTaCcloNmpO>HYFZbo+fvr6ZlLt4S|mzwDypfY z9FjdXzdDE{os_ESr3-|ix}GKckf^YPUhlD+YuJ{uE;;JZR9yq!l_RTWMlG{ zd$ldEmmyh}b-1rNuQ+FV-gxo#=_N;}{=Dmr3$I5%aCE3gECVtzSW45!KO!*05er78 zZ=3q0-^7#j4Mh1LUpfeDSQuC0>wUSe*RuXKeLl_FWe#{h=2oe4m{g~NWU<*U)DpOOsl^2#oyi~X(YR(_im|Q4}F{v~2i*9vX)PNpH z=**_z2grTWDN{A_2*XM$@3d+DcxFxqec6@U=CI1srXMZQ&{)Vz8RtoTCNNKWvAkcs zZM3I-3lk6-+c#Hq+KLv8jhoAtnv+(!3Ga&3k*o5~qNY&;o#bj8UtvwqreZ-KF^PeS zDTyE$s?*Enen-hxr6A}np+=FukxN^@ARw17$igFX*R9UYp&Y#5u=+h_rATg~O)vSb zNtXz$XsKO)pZi5iMRN5u%d1VRRAeRel1WRVQ*RYx?$Xn_U(_#>tJijp?7H zp{uj`CvZmkbsnUru%EovA7`r(vMCl6JnWE&1c%A#0d&mDrQPKFk%mtNBTkQmWp)a&b1uSTV0L3%|?t(2rdP|i{YNgD?e9R zcfEVI`))<+{Hat4D51A*uJx^5%gsA7%{!JnPu&Xy7g`qsTT+MduC5iDjitJci*=m~ ziEkv|PAx`6>Td;$ZP;)(~~J6I$NFi>&nwPBFJ z74ss235&tZs{5Kj|-Oo>r;%YT}qlhQaXWwOTQ3 z0&DGOMi^DeDuxYz0`9peHe8K&$OnvV6Pbrwh-x_>6X+qg?RB$f9RV39CF9Hl{G~di zt;R{J5TOT_`lMgiB%2~^@F!MdDZLHCLlk;cv1E_rm*xl5hY(gXboh6gf^NtWc;YfQeZrK+IB3)Jwx5sVgMO`Y3YK!EiY6F%_bq zjhist6FTnT$vcW+`0+8I#SV2C9W)@qlbw<9g`7f&+RQopk=9=yBv~5hlBZ7`58>Pu zK9#1*{~)MGE9q)4u5>eoT!LtNP~ zz7j5K7&4h|bGj*eR8&OH^8<|Mxle(rtJOM5>3;z{fgeM`*+lsz* zOvPRTQ>lfbfG0wkIt=Dbk&3l}En!NwVhB(rk+hn63rFErOwNqZR}1lp7=b_gGT8Gl zm#Y;+0FaQgZWrIHI^RNR701Rq1Vt8{ZdP@z8m+D9`XHEH^bE+vN{OLZ2Vu~Ok?_!n zs#^nWQzue9A{+h=Q0l2Itr!bUzY6}~k^7IGW`h0jFlqB4?PQ>>5{e>S=#vJWT_`cK zvRTqI9@x*HgB)Mo(NJI&elUS0zL#ez3Y<1D4J#TkrldnZ3*c+W6%&r2;uz8Q$-*HM z{U@@wQnN{rl>1OsV9Oc`pO4YTHsBFwr6{>SlVL$j=*H*6#}uwnE5Vm^AKDZFfYfPc z%|$~OM1C?pj+G(v1kEDi;&_DYCsoY0;sarH*BOp=VrZSwus{>lc08Oo9^^xbL}=&& zl(^Wyw?Y-% z8bnj!Jk`*uBbd&N8Lj0Xy415x!J((vfy=BK42obZVb4L54e4J|bO(`Ar}`e|Y0Y(q zT3J1BwNufT5d{NGvXwjasYfby;9`e8cEn@jVJE&2RisW;fhV2)3dNl4oc0g!0^UI2 zR27GQ$cCvV7$MDek(ocr0Tk0GbmgzA>!Fj}lt({{X@|4N;Oyn!!W+msUovr?K(?}$ zjQL*Om-SX={cExn)mdNFD|K@f_`$nZ_RO846npcy%H?sUEYJv((OYxI(>#A*(F0-W z{fgRGI_GeXyI)zoT)8Dvxdo8M zxtL6noLqD{igv2VZv!kFEIc%Y2kcHAuvz|xi<&0_8i&27m;^9M4XEekskr5#(;CA6X|J=l?8_;wQ# z*HsCP{x0tqs!rfiSmVK0{ta`|s$o=1=zS0#eVxe2<8N)9{(qNKtP&*USS#%`^z)}1 zzlIfuUe6FML*GgiBWTM}jND7z_L) zDVCFG`c+uTVBy}@jJcR%gMk+V9zsL}JSyy1#>NvlwgV4eBFJe%8Kzh;Act`odlvfB zo;|ldlkx0HJNEp)hMS3exY^%-;K<*jwZADOq}WcmpKV$G(r@Wat$5NoXeTNMWA(flmE;4<0+%fADV&P=5Yf z+OB?~L>syYw`s=(d${Rqs$5?b_4zuj3MnSp*}>SvN9Knzo^1=*zuVG|ZL1fA>{1wC zGK`gf@;MN?E3{u2a%aOQoFB=nfFPJi6O5OVbdYmyw!Tk`BnU?f(|g8{ik zG-0|G18(!Nl8-@xY++cyJ#vQ4h~6I@e+&-=!Eoon^$O-uGP^1Wf<1T93NvCh>_l<} zbN61sO2srg5LBbmf(y+aeV;Jz|+peM!jv!M2DWv{oN=PxU1b(?h{)!VPqfMO41^= zFfHqrf{yT*bmYrJrd>%FZu@f%nb}=`*bTVm#EJX;?6}|0J?)GkA6HDc;l}1Jc5#E? zN;-5ngawPc7{nRt>`1z?CWhru(ju>ir_NLQ7(af*f?Fs7SI1x>Z-otLgVhvTAEoV5 z5HK!>b|0a6+BreqIz4(3cL?*|h=A>R3e0_l!%eg7@Pql5>rZHiU>uirY^ITics`Rh!i`_fglA| ztT9*}D>huxiJ!95iTK!27%egfCutM~gJtUZf>r-hsxDG=mLfL75^Z#fjXBCICQ14a z^ztwwx{xl$1|pLw4Y89(Pz9zhBRh8_p;^CyX_PAvfhLt3@~pYG`QDq)-FR-vu_@~) zS7ls9^ES-4+zj3b;-io}>r3yww8(!Zb!cW6d~RWS z>JH4De`8|F)q1a@KE3vt#fk%I_kjm?ZcWph?XR_`*YCJ(U98)i@{nV5-E7_5kwxG7 zl$|V7;M*gnJzIfxsbj7;GimlAL#>X#un^=*u+SK7|$F3ZktIoJL z&L2XQGQp0e5=EQm#Z1M{r^tDp*vpsH_vEK8NCpY|cRp(>XFZl!SF><&)PQ8>i&L!SVzLs2g{#NMs z#orc}9D6=QTWjuDw9T|ESF~j++7^5Zhcgw#f>rEG9muwA{7#@_-ug-+9q33M&ICH{ z2WnD>sZ!;AI7Rne>6_a;7b4$m)qdyIvef=;O=D{R)uSlnZG2$1l~vuVYsmWBXL^_Y z?HPaj!sdnZ8UL9(LfU`k{b8gaonBKhWBTQi56KlNi%&cH)uZ=4-jw4f4>xnwoj-ou z0y`i2$g02a`srh;K9Y&#{c(5ckw)vcH?|yU;ofg4J+jI2ezytnP(JOalc@#&9$5iM z%z73Ng+cn2r1{G}&|@lD5OVkU!By7;`baIZ0KZ53yT)yP@K`JvX2~JPp}5wyK}9Hx z05cz>(LVST$JsT-lOPcP731nxDo!2z^qGUF`%e!Z*gyEpnZDj*2bJ;zP_5^l;YuZ- zYyqu+BL<@pj1chjp7(Kb8O7kSSHsJPIKezUSfyos!d1TBjc$o~*C?ZvX=Mzo0Nf-_S_GHt_zIUFj_cXC|({IQ!y!&r)^Q z``d8uBkT%?ZXa2yJD7SdThpvw8n;-pk+ytr);eRF*$gbZ>|K}fuAARHANl|e(!c^i zGCd5;`LDb*ADD0WzCUpN+1Y2W_s#aDo1a?r@5F5hRSoy5Yp+kuPF;U#_9eJTE>=JF z5Qc*d_p8@FDB*n7kIT7Ae!gVE|Bd>$>lZ6_0QbUt@FI{X(D$NmD_koJpFQ<+{qx&y z?z*vSk*UYltXmkqV^5##&v?$H9cNabkPQ6uN0^Bx;h$oAHxF;@(C`L1HJXZDR-l(H zhJS!*42*>#XhE-`?{3+2bz9OxcS4`$z~LIWi6qLen}5}?zJJ+-J8@q!KwUT2BmF(J z>c*|nnxzdamw1gSFwA*WrVWr^WE&Zbn(j>01-l|~zj}3y(dpENzBpM>Xs%v*4=_I< ze`V&K$a;f7^j&-|+c1g^mk5DZ`XXh}X-s!qq-~+tiIWOnlKwLuR?0A>`^cKA)S*3( z2P*@ukbePh0p4zoZ+Ub2wdv)?Et$qGi;dd=e5H+7PJp>Mob^EzJnQF& zZ$@rJek1mQXM47~;g#|SHk8DbBDg)bq4&<|JBQQt#}>q3iz3~9ud<0c2*>$MPfCpl}VY59BgBI0rgI(C&7qqCZ zKz8z%7v+5a6BU~fRnUDx$B@oRhS&v5bu^=`$iK|p_f=hAJG*w-w?5-rzvycvpW^^n z3or+VuN?lxqaVWQIG|2YKFKC=1e+j2x+IPOX+WwlB-M)nioU~P3)_Glws3Trw&c03 z7*`MEF4fipXdnP8u$?h#xNLU(@U)E@e>OEHX#9a?l__Q#Y#TZ$1B#ZA`@(4S5q$6<*s zFDx`>mwpSGIiO%3WsO)*nI;e0%*i#u+~Hc;m9m-PjAL!Kx%KAW8+*S~eRMALdk1ct ze)rJ7Jbfqd2cKQscI2O!*e#=o?pHPv@azOL+qC}X+8b+^o3>=&2fr0pn5TNL9lvsX zuKBLJfdFdfPafL1nrBUn>it^%{>|1uup%1D--3h~8H5cW@uV#X7{c0w>2iKBN3`AY zAO@~Af^j?GtLCc}fE6>!n2jT_X+m@1GAnQ$gSC+)!|AvLxQEi%Wrxr=Ji73}j#@Ap zq9K7!s}g#+C!;J~E(XWtDg6>`INarO+i6y}pb|X1_U`|~FMRV0-|-&1)j#9^_ zKtqfb2K26&8?b75!WKe9`dp}J9OrCx7Bp4G|3r7vUn5d%D%PRVVJ31@feJ;YBA44m zQ=wv=>>B>f-LLI_eJ?>w>y_tHy)*0YxhrRS=UV1%AGkLVkhC(a6D;pj1N_7(NWVhk z_#H&>C;1IZzeUkMMWmDr4hr$1!9nRG%DP3-?^5*7DY`?^EJcjL`*TYDTZ-;d^c{-+ zf}(pAy-d-!D7sG(p-{GEr2j=Jx>Z4SKqL&I9;z28MUjA)@~x2^Nxl*t4ibi2t`_0S%)`5wSK7tZIZ3px_z6gcFlp zd>_0P=w?9u)@xV~8p`LF3`PmWnf+NG-5vd`(J=5m?p4B9@FARBSSkG?C)^SRb42|P zZP+ovT6!G5XCe>vyr@ltZos5X8*3NG83s|mi6vnBKt(v%l&pOTfAfjkY5}CVQ2;h> zHINg0ZCBdrS2xWb39>v+`tNwDSY-T33@ce#D=t_hM^v|cnRyf|4jKo&Q>9rRI1huc z!J%SsJQ0q_>b;AMwA{ve=`y%0!>efXEQ}w1qr-(~1 zRU4e#HIa--WY<5cZqX#EXVNrWj)7IdAV@ARksN~gfH6Zx#hrJhqpaSXfmwvSS5nP@o*Fv3TUJ?b?U`=m;|#s8dq2N4cbCew#zyUF^foHIH99f$v2 z-{qRW%QgHZ*ZEzp3IG3lZr38W>qlmr$^3{z^domJ#hEt!$gV&Bm76p1-{m&`$m~KX zPLJSjWi9zfd%nD9=Bc}uI$RsK9B9o1TEBeaexUApcs6|b1SDIZGCgN{#H}&aJ=nwb q97NJ>I$-)y!-T~Y{E(ygaiZi{iK#VRzV0zciAP^3cblphfcc4z6`t8k+STfoY|Dx4i7#2kI((5}8|8!F8g2JVZST%(W@at# zMkWRVC}1GqB$i1a4pkuu2?hV*562H~ViJnfRDMw55BfK@0|ZkXU-z3`$+5Fl`^|js zy?)*OUia&s-!wO8H2lu3`fdKbHck7hB(+~6db#qR4hxNGmd11zE9k}8p_r}-jm25w ztj>}w1#DoAz%*1@^Obz>l%@zyUT09Ad-34QwND6Wa{j!afeXmE8vX1ltPS z#_<8mu@C)pVz%Q{G;8X0&vZq7w zn8su5D{q{69a)sWLkafPC$&RK$dj*=NYk~-*ZRM1wZt?nb8wOyV`Djoac^wQaK?}E zoNq9m7dH0{%P3lSREa^V_w zxyW6SvkGVdzv~Svm*bu%#tYow0yeH;!MX3dV!Z6b7hFNWM9vqEZMl_<@OjZ2%w%?* zw2Gwy-?}xEG4R{5V}~J%CCBv*mp@kKp6}J=HNl|j^Kc(Lz!1(%mowpFT75^A@uuNh zKcdl~&#jWal@Ngz`z$tQ?sWEAt;6|}r@C8Oqfx_%j3dQo~{DrJYE~93xR< z&ar)Am-!qgL8mt*{M;lKhgotR-^n=zZ!Rx&u^`io2ycjY}pm2?>J_`u_uDAD4XU&>D(`+X+scmjt2=jyC8+hnP83dghahfI1a1E zk)?7RE#7Q8c1#&2j%odl95y5F+^gt9_F!u*(kO;DB zDVemxg4Wu?stKCr)goxQMl0stq%pNw1NB7?La&q&?0}EP3t*N%auJ zWR|rZ-z+*zosgVuSO8dH$23&iHAS$*X7 zN)WUo4=7SdE@~RKs?UQIiNw>gRV-*4w;1eIkqP1;;v3P>%67Css+hqy$-1p%Rf>p> zYJpq&Ob*syM1OjPald%LO_=EV(mJR+KvEntz`+6|*#q*4hsAMUgvYKWK~a7m4pso9}fcEz_@* z;Pg6qkeOGD3)Fgf)B*N`YuOWAWywQ~y}XcF2x?)g83f%ov=c8$e|pftPnK{pQIaSc z;=9yU6ZR*@rcR_F6+N4UY0Znp%jBiAC_FmiWVf_t#rMcfSJ_6IWigiHGbxxs^EJ|- z`x;s+N8%N7pDH-Hr zj-=SADE8`X5Z@=qZROI0YcXD5G(kfo5pR%1_rirzH*@#N{Qe*sopg&rB?}(i5Q4^< zNc@m&7Ehuga@Rx+Dll(;83k=0mWZEF3v596lP9Rhg9Hu(E`CayjLUu8F>n@6%Ic1H z@iWq_8mG9K<5F!iXUa2C-;sf+;=4F8gZAr0;^)-97lq~oHi*g_s)t$N6KIKQ?qL`~ z^EFglk&X1AJ690s!ORsL)b?5o#QRd42)c3La@U3zkGr^cnA~+8H^?qz)%cKeBsw_H ziNBNER#|Lt^D1yz<**k1L2^|kCvc=rSrze5DT@W2(i;vCbHVt7rUgWN5IKz+nzhRE zFLJPS()UYdbSbcA-vOB}a=-Sgx=zYpdWnrp+fDoT|82ihq;7OJL9E^CG80 zTSt5E=^N{p;#3}QTQf5nd2N6_#j=^i2sr!b$aoWIN+fd|C7Rau-xYU zl;a-%$eNp7Xn-rm4b71Rb&tkw!Ic@AOvr0?4lBFe@Z*0PwU`2@gDP&wFZ8w_BI`x)?SZ%>DqMcSh}W}e=_}b^e=y| zerC;$y&P*Ii-lMl&%z$g>`rKB_9rwJds6#y+|SnRKf7`MoyFx9k;RX-*0l4_nRs4j zi6p9#V1IJ7KXz3=a#bJ7MH5rbWOzF9zk=w=4`Th; zLaj2vurP2Rp{3un)`OSpJ3OVc__Q{y=VMib`T(}#Xf?LpxTZV#{k;kQD{BFJ@Qrp( zo7RrvdmW9@^m&Z-+wtf0bGojb$tJXl{)70G-XE*R#>Pfpllv|ix2Kob4&vC14i#t>h<3pti?ilt^twatjTziA1%GLDt32x(Ta(7f$*N; z`WtC<_D23k2VX0^-Lvhjwrw-XcUpU94_??ZyZ2&i|C^2dS75AN)iXB^{vedk>hRAKs|hN zMS9(U4=8>sMt;=w(xwakE1$TyVuWJ%`HpVAKkYsXqadlikAnt$TF9^HAgPK*kU<(< zUtXPY7O9WTpusc|In#8Xk?m4g1E}8p2{lUGDuiF)UXWBz8njH4VHmel*pq6&?#mDs z@%N+`9(g=J=HSX^5;qS#2-s#u#eyg6)Fq(hS4uv3vPWw$fzR&0?}Ee{tfvP7v?hCPZcRje<(NwJ$1 z+Z*;OwoI{Q;c~?cFm!f{BC8_RYQ@$lHgu^^v9;20Y1psGI;C13eoV3TiY*NX6dRO= z%fcZ=h9lJm#WpJTsc@5Go54aYkx7MH6u(_p>gC}by5e^dUmD&;d?)d>;V$C4B}Y$p z6CELSZ+H)J9Ema+gW(?H_Y%K3+)I3v`2KJo@%_a6!uyEdFZoRG&2+B5|Ae zEullaM0`*97;#tfnVUk7s88zkVVU>|;@iS0;wOo(4J*W}#5abI6Q3r&?(!+(pCNu* z_yqCWW6^N$h*9=x{4U}nN;j}l)Rn#9M5KX}Pf i{B-J4KBlERXItKG>^q&joNCikm)2-{>I)63uKXV;Y$VtK literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/structures.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/structures.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..85e59811dae9e141c474237c31be761e0c2a6c30 GIT binary patch literal 5579 zcmb_gU2GKB6`ni0vmWo-48#Tzk~BkXSR2e5C5H0jP+S`dF)>MS(`r*RJKnjr2hZ+o z?#$wNV=Ak%R4k>1C~0j(D_p5kL8KCW>TCPdhxWmnrG>0`sT!%xTVf|_%2Us|^W(L> zpeXH?_Uz2uzw`6m@1A@A+}s=&pv<@bWi*ozgn!^mP$d6h7@H|7B$e9_9rqqzM=;8YCStnvKXTNk@(7tdN$_ z%yi6%fow3qxU_7@ARCQFkZ~gpGGQb@HW^JIo2SIiP1Tlu-Jz%R4$V8JYhI+Np8hv* zRG*rKntkSKm72*IP@Bo@v&;#q+9MZe)=kCZDwNZ?f<<#Q?>ee(S!#~DdO@m^cgm&bblF9Ecs|bD+_n zC%&te?zlK&Fa~wIxJ8)^Ow2mKHLjk|(#}k#%eM=s@4$CZkt^B z$SADYd>GM-x>e*M)uDT`-|u!J=mx!DffoRtRP_e$f)8UlGc4+O9tAjz+mjp;UJEs^ z=cqafV6~Y!X66C%Qvfj=mUploJOqJ~9zWO+G5~6^VCXJIe4tft7In*Xry%0Fg3e6v zC%3p}!61^yU{&TlU~_^Q*DnIRu`iCu7XqTp=?X0#q0q*J82|#syg^6JJSv7RAIb)F zf~JT#jBz%q6Z4l;yUClNGsb1=5uK zAz<&b_3aHCq@aiMG>94D)0nWUTK(-BpgSb@H&@hPm;|&WNynwwu!|p3BSKgj`d*Ou}hp!#J zezdG4Z<4aIXGz}k7{iW0e~91LFzm%3ZrmESqmCH{g%$p|_=F7(VsG@yjBvkc^OeE5 z!G*|;#%qn&6Xm9MPyKKyLaQ(?1MmWA5Se|136F!`fDnL?M<%;|0(9-lZV-b4;XXRw zC8XW2vwMhRxXu;$Om-Gs1_;VELKn7rwvv_WN>K8T^lf zAp4QBg>?E$D(208i*U#}XsHi2qzpdEBPoN|9>)1F#52N2%HSR2_Y=RHxOebW`QWL_ z!I$nTgG=(@W1`dr9p{Brf(5wM5;4?bx$OtwoJR+cAx12k=bXSW47F-EXd2YP!hfp1 z<9H=pI?;fov&o0T&K1SF7AEHXBGngr&dvO&&YSg8U6kXV+-Ep2L za-Kt+ciS^>2L&vm#MZ0y7vH;^*!7?_c~h#irsht3+_H12Y3IjE%hiE)8Ca4BHZD7aDG$aecvusRx)gCC3fKymgGYl z?Lkm*drrbbtvxP&^&=dCT^GHm7b{7 zzT6a%_AkeYw0Aj1q+KY^5R~e2Oq9M$mgSgqf-FBlq{A!lHR%nE!)4(YmLLu*sK$>W zMr*DVVwZ(cxKEjFglmNeToXwAasjRt;Cg|i8!iiPk+clyLPIrv#GY6^kPk>VbXybvx3kjSZ(Ct;pDZ<49ce$S^ zvwj$;+Nfz+IJi5I8>6ABI^($(V^eBbRXIEhybcvSk$^Pfe(QEP3N${Do97zJ^7g;V zJ2nCwN5$XDb09GDs-HSu7Yy;25pYywsMHAQ3%W{8mc-<-PQo=^k6#XmbsBnzO$Qo+ zf?IYh^k8l!7_Zqf*;?dEqqNECsypFS}bJE&*gxfPDm# z?hR=!$9ieo8qbEw`FT_w7Xv?aY;L`BY3|ZJMJ+4pV#}gYQT8s$dp!ftr9t^0444+z z8NiTN1BBp7quKx`V!dd&Yj^*bpsKW~#tN`u1im?#V1VP{Xi=;CSVc)K$tiD%;n}UT zk>Pq}FQPbx0{3Q*68KW*lz_8Tn|+98;l@kT01hYME6?qYdsxMcf}uEv6}Y{BIV*e= zZTliBN>44zMCx3QMWn8O0~K_88erogPyy$xCbG6=!R;5`x%mfhe#PK=nKfBfwccq*!y{`pOEB2>T?1AKR+XG OCf!$CzYyS$5BFc-;R8be literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/utils.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__pycache__/utils.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..8569a34353673d1b92ef83e6eade15055a3b5913 GIT binary patch literal 36392 zcmc(|3wTpko+o&(-fzh-`H2w*`~W{N1_I_4KY;)y!6pxflp}m)kdYj(AhY#21KvvJVK&Za>VJDUg1>}(md zu(Ng0inBIg8?z7EdAf%#;23ibI>%gtF8tODhCsns;b0-l8v{jSMT12wZweHTl?;}Q zxd+{2rGuqoWrJm`+#Dz$s~D^ps~oHxs~W5tTQ|6Fta`9|Z2jPRcHM&Op1}<)Z$-Xl zux4!I;Ks2{gPX=S4{jc-9jqOz8>}0vAFO9}Y=MTcErVNF-X7RG);QQW)->2O);!oe z)-u?_${m4iW37X&$U6tOYdBxw=!i0r+4B$N?BEW;B@_sSH#CDgg`&~1Yz-xc9`vI@ zO3RV?fkyhJln(CpnMTEIJ0&NSov-IO(IAw6lN)RoDv;I) zl}PsrRY>;sc{+p*sM#shAng)1BJCD7 zA?-nbo6%pdP>WxOggT^$g?gk%ga)LK30sgJ6}BQhCNv^FE;J$S!&9CRn$@RyTxdb* z6T&v6Cxup|{la#n140|pQ^F3UPd;RvJ9EbQl&}jmpB9b?k6={K2)prXPBrPYZid`kb&2={JP^qyIMh%t}r;ppNW$-}A!3sGj2ny~sVva%Y4Nv>g^YkqSZ= zQlHR`bVTSudRFK~dQLcm)IX_dI2L`wBKlsK@P#Ac=81?u5VpLu>abV_&iTWhv5+tk z@Oj3?&;`HX3wx-lKQieVnFtO?{Gnjj6FKLNc)X&|GZFR)o{Rp-Ie*Y|QtsNKUiAjT zA*wPm5%7$JM33)M#3u&50nacxnHU?V&YCTs(ZlvN@EPj~QSga)0{?KNL6fnKdC&WX z&iTA33}?*aUNP(&nh*n@(RxI6{jg7rgx^8Cp`iTg zkh36sOR%vg|{ z2(mopr)W47I`8+5dc~m;F*G(L(ERE$&R&1OcRVEcp7M%8dKUYU;015MFC1o5p0UV3 zPn|rLDLEAseHZ;f!Fwj)>kJ8#J)#&A@eD;>n2RI9urC<)({xGiE^25F`Xb_R#xTUr zpFNIO=Kt4tad@vfdf<$n(r{GM=!xnYPlvY*(1du0hkfG_Jn3*qz=)!9L6cID(PIp4 z+lOU{L<@&A;176%yITgxbd56;T;~GZ6mRBY{3!Oz+5@H3X3ZgJ705QFiI|m(sB2a7 z*>g-I=#<(5&!D0_qABe|Tj*D}n9{|xq9&#b^OHzN3$nc{Il-Xp{V83fNG;`J>b=p2 zuA6&ql;fuKF}+}vA+9OLUEoCx&rOZmumw?8xzxd_;G`nZ2s42ALQ^ix>ap^M?uT@#{+ zo%*B%OimxceigBPJ^j8&1j{j;u|7`QvnNQqAY*4gP5|_X0F(Fmy;0-7Kxo(-IB=hD z9*AmAH)r@QQBCuf`~1NMN5+7qEBel6tVhPiLt=z&pp5avxG#9rHwhSYwC9X%%7clBD2 zBWbI;XW=TV6C;b&t*PqPz9g3ukE|KZ%#XRDqXY{H6HqVAYHU&rhD00aOKkM zrGzdayxsZz?(cPf>}>d?v~r~Y{jU^qu97eAb@3S19ga7be}a)|asKVSGOnQPMn%%O zX;u0C@J3A6tGcdw?%N&Cu1C0^)|Zi$z*I9#7Xf-|+b`kr$UHJz;rkdCq##8pz*6D2nxzgF9L8;c?%vf5h(- z8r7~qQ_ww?rPQomXwZs+L?4n`Uwdp6EivtZr0 zT(ot*J6+V8w6%U(R6k#wE^1ENn(v|xw`x*#C}5LHo##$!3}{FJjiM{YjjB^ieMpBg z@l%-YeqhFEi!`BOk2mO%b|`42Fp*WkVV{T4HfS8LIO&-f7rYT)b4Krv_{PG(sm62O zus0GB#lz?tn3NZCo;2g4rb8fUl)l8HsP+>6!qrId*aptzoOvN$w_vPTve~a3nmzQ| zks1EB)i!-t>_wGT4^8WVJ@o&WTuSSE05#2?dx0btRz(`4BY9N}J*$ zMx_+fr{ZJLmV=MgbveZcUs_dP#fqXGcT#vtr9+(2!ndl0ijl=-dM8(jfDt^pX6O0iRn<{h3gUVU;Bq|mb zpJGq4A=_TbsZXL=)zYl=DYnP>>D{dLMx{;m44O)%7v{T!X)f_$P$k$H z@=8HZ{4{v`DLzuC+)LnNd`uICv_KhIKL;-BFzAACp+BaQ17O$=)qwN5Iv8mtlxabG_X8EM*`F%As{d|){;TAUdA^#wy2 z{*0IKn8FNsurWP?57>6h9|UwGa0Tus0y3is&CW*7G0q4KR2X24@n+zdKy0v@XZ&ot zhy78XCnUjFV0m9VpzK8-2#-cqi;CEN&iH&mPY4tRZUlxb0)C5_IiIKA-|TB5kyk}WGjESl>Gb>GQNTZ)@~~ zC&r1k!JPsDg8rg!EOdcjIsi3|GQ4V7%|uxQ0vTP{=R5xyL5zmtjKzL`C`YG8(4Ygz5OJJ7xP{tMsMZ5ue=Xh%w z*RVt^4vmM1^9cpnu)>582+=VVlQH9dVEE8P6ma3&_zO>9bxd<07^aUcm6j!S#h)4r z;v3%RUoe&v=si4pIQ~@Hwr+<1)aU?6Zdfo@Etgg#T3^2~Yx~sfiWkIt7R(iBdTrwB zgi>^P!MtuoQ)(_;Dsf+X`s&lK56<-7b8uDFZ|%Omd#*QKxplF!Emhezb8N-Lxr!1S z-m1M`n{s-VU1itoSM4i0eff6OFWL0BMV5j>&>ajN)M894niBKorS+b-E?mFx<|U%L zK(3U=Ur5w0I5*4%lC|wCI&;D1+r=f&oE>A)Jjj;nB35sDr`+#wdwg!<>;)@kZ2s-N%^2Ao&S2gK!p>Edbk;3x zY)QI2zge-P?0%Tu=Lefy-P^gJnq56LAe$cPDd0ZZUf$!-{>;u(T43#2ul-pyPic+4 zXS?=itvu3U6`i3A75&8+`ir1QI!1GADP{Rko(ce`G%?L9x|n8!pV9{Hg7%wSL}g98 zRiW3E7EG;9&ypoF<6)-$y z`ij;n^Qp82!ZRtY!LD`1Oj8D)3-UTHW|#&;n?-3^l5xr`7^W;)CJ{u!1Bgv5h*?G} zvv*N)LUyc{m^mK`7+tT_&7NZxWsHK3nDi;DnbUA!L{-LmG!Gh!S(R2(wwO&UirJ*r zBAEUlFPNt6F)HRdIfO_of893S1 zw~DqSx~>g>cj?YY@c`F=?Vp1@1T+i=`zH4Xn(y-0c%Hj#1%J-}OYKD-gsbMImcDmL zwxem@mf=Ujv=L+&c;CG5ED+MAaq&QO19(MAAT&gSYnIsM@PTHvN*WErL2O8yy>`QjG>GLI?z8g<9bI{TUOJ34pz3 zT#rc9SjHF#o%IKY{9&SBfueE_30pZ}V@t+@q;cI+<>o}wtn-%@d)|F^p<>UBb4AyrxBmyzw%aA;GnU&0o;#e??4IdZ z(HQKd%kHvkXRn@Jbl0cc_45U3_tv-;sK-@!<>KtcD=*Eylo^7DS6-fdIdLiN#EnwUtuwk6oyF|_q@*Izo-V0fEZLbV*?Ch)m+YPC{lr;vd;R7) z??0KmzG2=QH!eXEaPhix-hGpQr#xBOmUOkP7&({wi+gQcaTO4fz4VTWD<}m*vX}mL zrJXDAyj_}fHV~?ElZc^e$yM^X7UvZsN`8w+w3pqePFm}Mw)FN-Og11bz5RapdCc&S zo!t%G2fFp$dd&wL*CYR-)<~(f!-msO%eHoxa3AT--G%y(92%5-RKQcdP)qp|M|Z9E zqm4Y}H}jOQW#tXd?!DTN+Igg_wz!JF{yFZvmS+V!Mj!yk6bNy#Ge;!AM|9GaENL#b z#-LCm7%1q@KY}G)kKcOs+rWOW&*HOuELlF5E2d&cf~wNL24i&FfC%9_k)&s#z#tWb zkCBu?@0dy(OJFW^W)#FKh)cR8lkEJy&;B0Aef|Im^0Cetv&?obp+*K4#4vIh6AAaJ zC7_EIU5Vd9X)Zv^IM@K#=A?S!WmEu0=E4MGrnyh8h4Hq8VNRE}Zl3P`#AtoPlGyQf z#e%ExX7Nq$k4oR``lIUiyMJEz!QtfN{U4qn$q*L)qH}%9xgL$2o0F!^D_X9HAK-6R zCtZ!xkq0?&f@t)b?w&-7SBR{1d|eVGiqjjcLwiZ4B;jXoP9@GpiTr1>(7a@@#LQN`{^a>5S=tn0dDY_>Z0`UT54-D=hL@O&l15l}X0{-(p z0z{KwbVqzxOW>D1W4^I7$b((?dZPYu3!z!BID8Hy7~{Yh~1sOTMzfKwh0 zjZZ49z9d|4^pNH>5caX2MkgR%6(zYVfj~%6Nl7cPv3a1NJ?9OcC2=d=_CDVt63^M! z;K)Ka@d8RD(nL2J@&_|UjFM3rV7-Twym8P!-b>_%iC`RQCo?9<8s&-rp!7rViy14Z znlb z3&zUZ&Y~IXJrh@2PE^RXv8!Wq-D!8jD<`H8%{=*urQk-*TXom#-fF(yJYTv{(Yjnw z#eO$kZ<;rzE4Ix#XN++-h=mmcXD?hTD85#9wJfn~ZdbBmOS)j|jNx-TXD!U_kQ&*q5cKYh+xs7udz90Ku>}FTGZufhIsk(jXlKsGeAnY&(Aq zb;GXP*7BsTeC7a>U+dN1_rt_b{;Xv~Z6{?If3nPpr=KwjPQFcCH39!R=wZy%wg$X&m(BrN- z0E<;92bNB|7IIwnsQO41s)GeA<#R`;GKbmDv(Sp?UgZ=yBjc%b(Wa+pF9C?qJ|NIS z+gMqpE05iZD@!q z1=_JabwFRpJ%t#A2p=T8p(=+IA2{OH8{htoTbFRbrN>8hst z;)lU1=pD;;=apw>pNYRT7fIV2X$e=~v@R8{yJcHPE4KPmljVwK))L>Hc=}^gEiKw= zR_V96gRT4yr$HB}VxBd}>laLwOD6k@9%X+Q-hrXK`bg(S{!iVVkO{f;9XqrilvGo` zjYshZJME-+o-J${$ z$O8C+z9m!x!L*m5iL7F&*>frgDJ{gbQj1_HlBZR8V)$I6f`q(5)<=%%PNT=ye73n! zQuwvEXBB@34jf?ehoSSn$st&pFr%0HXY1?myROkwhoZWM=Nedlw1{&0{E}Mvd#wZS z3mI@-wzmObSl=1%@Oe-D80jb>(I%V@eSN?a@WT40UA=L0b5@g>RkXL$B+`sX0%>`^ zWqJSx1t1k7p6yLc_!3t8%0Ijp*)z9G&peeK$F`Y`=R#S*0uDEA$Te}tc(*HAzHPzSy6h-RmiML|hmxj4pIY7ViL`ZHQn&6wCP&?0 zKSrnj$oq>Pj~&>xDgsat2h-o?k)W!?H5XCMch>CB57F`eulw^z&Th``K~SPt(WD_F z$zS+OcOcZjx$o{vcGlXRxoSPU0GiTx-qrx+^Z5~4g+otC0ZX33%N*9b9AY-~_y=r~k zKBNEC>Wu4O+ndz6AKXf+ydaJnUE|JzU(ZEUKaiI{)CoJm%R?yveXpj1!x{0fVvebrAE?#eA@n8is$kpP#5q(V|uR!z=jEN*+K?h zBAqGG8fSo~&P;kv_I7!;Z`-vSmRQUN!n0krCxHeMR*sOZP6WKrhBAvs@K9r8-lnh* zzhEUH$bDWU^Abix`2s#N$P8n{u-8k3727~#P<;A>!+{B?Oqofg&?KReaI?qLvAPI% zfr$%iPx@Rh5oOYySzWM=O;Q&gsSBw-)U;p&*#$`#dQM{N#{2@<9JG9b>^d<47^tiy;x#HH{l_9G%2(?0KE zTqHBoWdRc&S z&+`l=b-62OZlUNEye9!Yd2y5f@y*1EZ_kF9mf zMRoJK`6uSZc}u#e4W@7=#})gmJuZA~s$4OmEhP1}!s+8*0+s$--1i#ie>hYEP@Muy zifJJAG6;YzG0i@-xon4oik@!G0qCX5dl;vvB@-(NLgB0<*p>s+^s8W+%1@FFlAz0h zY3KuY*0MW4Cc`d+_ZuL=AE(#EUOoX85AbWFv_i1B{o>bwXSB)KA^xE{vis~CAG8G6NJ<|4*`>bnd^sw7fnR;VT^3sL` z#e(exc!o>CkUTA95aOkIB2GiG7J0r8vbF~y!>Xqv(uMpDV8d<)4Ma};^+Q^zv+5Z_0wYqa;Lkip(>T(kF$`gOGT9dTjy;8NxKncn!0SxAwJ zm)sTCMz4;}70r3m?)q8ljBduaWOc<0;~Qr7B=m_hiQ$9=@~64skF5>M#r5+g^Do>i zoUcq5@0{sbDy^C^%tXFpTXCZQ6-dWa_<+r%9y;V`ci$yB0xcUJ`m8+lSw)xbhcrg_kbdI-j>J$v5k<}6&HJAihv zM1OTka=##4CnFpNlYz|ZPm+;V7)G1`3NmhCIBON~e!f9M70mWZ2m#>|BPpXLAXGG$ zU_Rj)*eQ7~lK0IS5fLt8mAhV*^)%5K_lTID09 zfF{%2=Pr=H@sjup5U8G-+kX9-g@UH}jYvrSTQGfWrHCtV$Gr(n+&ZKG92(=wgm12M z?umqde%Gz)R@if2+kbWcoSRweE*9-d745n?@!oK{s55En#M+!b_8g z>*lWT!x}#p)^k{2qyr_z`q~4fxeHak{JQ3Hr4EP+tzZ!{3=(-5`HQf}jZQ0e8Vu;Q zumzH9(94XTy`C=SsPmXtTup2YkG5woDRLgXFIfT((vtjp!i>;a{qj^8f;U0{fxQ+` z7MkJFj6rIau}Wv=78It*P-%rC1}PZ3FV%qyk@$1eNYh(uK?V@R!R|y5qa9 z?Y+8p&hUNP_iU-6#$@4v>7z)NtZwimzqzC3iViY(^sVYT-714Bb)S3MtCFCx>KcxA8Na#QzRS?!L&Bcm;vI2(s3eZclUm7pV6?)0~r>0hSnm znClZS&UdD*ElFL=gUec-(Qlwp?u_PJwn84oJ|x#9eqqO`Ny%l;f+j1-%qMq$SEawe zX?}T6y06_+j^%RRG3kGRr=^2=VX5}oQW>RL;SA`;FTEb6+S;$KgH>sW29#B)xT#4y zQMS60t$k%SaLtO8EP>m>%d$k*sdXY)7psx%eqJRY)tD zmu&X*0xgV%h#Ct5Ll9dT0uKaUPvY++1{qq0;fXLgRC@5=9}Z9WJR7%f-?gjRQ_rxJ zY+CNEVMHgdGv5rf&;4PJv-*5tO57Oc@1?{@$mN` zF5nL2w;H~R3^uTZ)7!s&{FUP?I*q**+DLQdJ-bnFfNia0VwJ3V^e;94UiaVY77C6} zKep^Dyk@y-Nmd?Nc%pytiBqX3PA#~eoIXPOk-^!)WZA*A{n6>(6$583S~OLpOcjYo z(x#0|7U&KuQ7^*4l6fo=*EL!1wNH(l6x`Q>V;mg|6by%9ZV+L4}nqU-Q z$R}RPu@g1N%z}v#dt1>)7c*Dn^}&f{fd=|S8!c^pV*B!qCa1P3W{T-xnxFzVG?NeI zc^RV^0;3314zdw#Fh~En0xFaZN;DP|urQ26egdn2heV-C9E?oANk#24JYhIR6*5SM zpVT)*8$>QXa2vwt*w^GlBul@5?LEXtLMupjmylE=9z`PfNOag2)z;L(&5In=83hP# zgV{Ff31*FFbhLFc`T(2~#0E>oAPq5NU}Btb#wL$~IX*-EPxpc^rF3T4F5_Sn+BeZ;%g7Kdo0o-IwP(rsI7f)9UQ^WT z0t}`uaAGkDf{ESAyXSNY+U*CE72{E#pEL+YIcGxP0dsUpS@#OeUbV^(4-7o+In2Dy z8JV>jNlL3J+@4D>=RuNrs9%M3i7G3wiMCrG;JbvBqMEuI@{>d*_~} z)~E}pEI{VE*eETdVYqf2$FqawegP+u7Lxc^tN?CzY|vrx7gV^6WHkX@o{JJB%&fHd z6)IQKdVC%kMn)G`68)Tb3BHEY$9`!oCG}b5&YOXBWmig9HhnB!d)w%W_om>Y=PZf) z;k~iwgbzpU+(g>hlr%Nnh6zbk3f8#J%G<{B#Oai=;kMJgqUTIoq{V`}sRvPr8}WDd z?~urL-g#M_X={w@0oVN^mezMQ*EGMY*K@Fe;5A%!;fzvmYmWSkld@C<4Jbr~T7z{3 zkN}8(&~14w&a&QhCTvXG-wa zp+*4B1ucU&AayH>7coN(`ix2GJHx|STfT^37Uw2{=V7~jAxyY82dGtJ6=QTTzM$@j z>==g?I3i&L{Zt^{L-ifBkiLlwv#(fzH>dgA(O05LxD*vtE}ANnWc=W`?bvmBWYMuD z<=8Uc`os2j+S86*@A(%Tho=uM6~J6Vt1kg)vln0a#_Tr|J!yN*j3#5X1OB~sm;|{c z5ae14u2j!fC$w`rW~$TX`svP3jOHbW>opTBR!tUg=;o^X%zppX!j66X8+=E*?!WHP zBKtvk4blhLKDGq^D-2v(f&w!meFacN;Ll@0z$IB;B)P;p@z?pv&tn$E^$^lRffeHk zk5_QgGGV_#@RMrmp)L8#)nskV7KJwIIl`6zY>Oen@q_^nurk2@c@;vQp+|%*VLoYK zsSSh+5kMCwxTDXU;h6z@B|3gxT;%_j>9(s9CDKGD~#X8-!WGsSzR3bM2!mah& z$op&8>o3mOmMr!+wDI28t+yGH7}X0GqIGZaz=|SZ*@pD zKeklYzvungsm~C0{!0bSM zRpYLd;ccsCTm9th`jxdAKmmxNgE@@m8e$cbpH03H8@cL8xO(nXOt9c^syge!kjqIT z#eAb2hJ$FoYPi*)i~fy*=SaLJb7{~(Dr6WlKY^xD-n*;uoY)Qz9%*yu$anxtlCnhPfEbUDz;4t0#ww@KB*VCe{VnqJk7; zjTCXTicJ47F9Rw!mynzSq*T%Ve{TMhL2dCfEQSV4mK7BLM-+&JdBy*Yk}^t?NHVrl z5;SG*J>s8Ik$C{L0{acjzd|KWY;YKwD)2rm{+}pay}22}&pQ?3|AWdWXsf@83|PRj z{45}dywdXN6R==&HOv?Mu>76!w6ksc@Gp%{3XIXTT;z_waBcGHDa`5U@Ps^!DF(blh=O8@s#RHI;*rFR`N)rogJNB z-95dB4j*~!=&|E{Cmw&|WdFdaC!c!ynL+QFVZk?Y_MCt8d|)gX8h=3yMe`ir^SKvL^Qm@&|DdV6Y!}gQ!@A z3(aYx5+kyK!x0F7REQ>bjFZCIiF*K(RFnA}=%f|YpaLqy1L+ZQDSd!Cc7ktIMxql; z6&ztIRi*i)-*x1OBp#FP?i6c-wQ%V^ zzgg0sV~=r6FYy`8dbCCkWA(71!wBy_U)Pr*NFgz`BAL)Lw4O2gp}h%CjAgXL=foUS z9}jxYI8ODQ>_McSCwsbw`g;b%D<}kk2Y)_)h8WmLIK%rhJi_k`uO;dV6)paRI!Piz z5(4c3K>Q8*0Y_lt?5-!WG=hC7^HUpvDu+2A@3hw&%k zFU%aD;g`vm`n6s0C%&^c(fZb&>w9kO1<nGwo2su~58+|Fb z*;Q60Cgz^FercYc*Cb-8%B^vI-23~c+v}>O^2BK3fLv5wk=Qv`aD8`TOZ=sop7@6E z9A2r!C`dcwAe-~}&ezCx{EK@8#UySXbV~=~n>*l`I*@WFRIaA~wL~S%Yn-5`@|9pCi}hvyx}F>{ZT0UiNBh zA``Q9A3)^qp7crfJIrE8axBB@R>=XrUxSWS@kKs2gzSP+aEK(`WM*wD+{Yc|18QM;Vaetuy6iH2h|1+l@1Mme zIhNn5oJF~pdM1d6Lms34|J%K@%=YSMkLja$M#y0`QV!BmRzhlb$ToG+|C^}>)Lj9% z4h^+uGBiP|w$wa8Lc6D$QfiMskcMMvIcAy4| zF%@P(rkE}JILuyJ_iS%&-L<>9wYgQo6d;mwOSiRb-@*15BqJpT7Qq{d1DqH}BsL1YID8(zL&N9cU~Wd_m&g#r2|)?L zID`<~rv&nZAM=LKGqi%{8c0&LD9af9<4^-aIDj84qdVgVE}@@PpJkYpA5kds6G{Tm zLaGk?{UP{yqc&9%J$P&Xf_7s9wVCb^g3sq>pMz7Xdl6ALHniTXNpIMhw(q+6Ldw1e zqR`^fYe%jgNesW<_sVg2MGY*Y!Px9rqWkUI#hUG@n(aS6@X^Nig`YO0+m5Acj;9@c zKYtY*7$}N;F0c?mQBXCxrmXq)T9(Sox6`2+P~&td`w6RAAAO}uGQ>hS zRLr@=P_C&aK;Z1} zU;g`-wFsk&>}MV%QO$uPkiNU|Qss38rL|WChsz=s44;SFvW~5)btuZ!EsF?Q43-DU zpU`T684M8_4tUll3KD1Lc3k&gubyvBl{KcUjnm!B)`CTAWy)H4qxY?&*N?)&Pe@m_ zr62OL2+K0y+lLIr;QVqBlm)L8AOp;HE|!M<4q`lJNlx;vc`TV@Td0BH}G`AJIHCOY>lYd~4a{STvQTOl67k1=B`I(QK|S z?&;yWM|@JrC(dGGkV+&x^lC{NmoRVA{vp5VA>Q@mh4|G{ctJ9(K8Y!#31kOk4Jvj} z%CO>9dR~I_%4(H#ZzTH)liW;qz8jOlPaqW{XfFh73fE_hJ}a(v4w>p@US zuS%U>;InS`v&@Cgu2PSXsk>@V%L>6dgeNA88@>imc*>Tv{Z% zUbkn#){dw~HWvh~6fLrpb5#&?pA#(7#iAeO6x|QkV1VCU*HO>?+q#ZNxDV>h*<@!y{cKm8F%p5r21g<0%!zfWS|XWL6_?kKmGYO)@^pPlUc@>w~uk8 zGo=u|P&M$7x@pAvm$lP{U)5?q07gvvRkf&Z68&%d2lRUpW*}du-;1ggP!5UnKOwX# zTh%#XEMfdAtz=IfN}2m)9bppke4FsqNob&-JOp5{aKRs%2utR&jh;!rFCa8BS_eCY z3_!xrPDs`otLs8MjSCe2jcqpCS6?v#d0QPBQN}@R2wBcHdV~@kMG=#vY2#vBR=l8x>fLkTOnBFKXh$u;y>w3&Vn9ZTv97gtg- zSDY-~JbnBVWASpa``TkyAG_9fwQp{By0~%1ytIDPWsT(cnKD(aXpH*SUzqH_w3aP7 z%aVv`CN)T0N)^}NuG{v8hHNJiyKlKRt(f5!`o--2uT}5w!c`d2t9v>t_&?KiY~?=S zwj%q%*2d0K?T4jWze(B##PvdmLldG-fqGG3X)eW*vpXOs%D1QB zRSFtK{6x@ylcd=BFaxx$3ay?`Y6YWKOfnrgF~#^ScF2EUrH!~h#zTSzdI3QsvT}I6 zdc8cCN6GgDu$sV}&;ivQfGeIS?~}%uAwKFnLUnXpa43I0@F2Q;K{&-iSbCWAUn5ys zlr%sF_B7j&Gv@C-ubx1SKNiM4zM=+yd7Cu;oS@xsJXhvmC&$8fmPj)Kkx$;aP-b_^ z1iBahl-4}=vI*E-H)#R3bt`>jBdO&Jtj%JLAwrE{nKD7k(U8U0s{>$MZkDBf*61+{ z@fC_P1FlnmBO*Kq6pJq@tS^hh!=0%$4WRkLP3UNvqc}j(*{Bo%EA52kNXOe}zCZfC(eDSp7rfd3lV^VP z%)fdzUE7f~buebB50N=!0%>5?1k+Y)!{6OnBr*b*Be=zQY%XkooCt0lp(}9*;DdM$ z^$=F4}74Qj2GB#!Ih7iD2+4oMG=>L}nda^k^7>95WL$9-?23%eq_OmqqN>DT zx~LwJ%%sR>)4j0c`1Z@Myqq*vBUTCYJ_sgO+|SQFy|{U2YV*#U!|!cRZ$7ZNxjVJF z`~Cj(<|7M5CudBbTA?H+>!k(j)}<=M3pd(5ano{4dVM94yOql&8|G@i-}1edbjkLa-d`J04!eGn1C}qht>C@v zTtUSR_EbsdR-$$*mr5$W(+f7tTzUW3X6lCex*y(xH}a8_?3gb-tME3#BjUX7?m&_&Hza2-1RRkumk5hRgvp|s>``S0*-abo+?k`c+w8+monuHr_D2ztu&_4L;K#0hHC9o8KA>jKST40I^d4lkR$?IknK{3D@Rdq^up)yg+^Y9VOO>ZaiB z3`-$0Np%ppgHWL`X9LVMK@G>);VFdmjOqG0SREmSnCM^j!Mc27sH5ge9S7;;r| z(ZyYrENRXNdNJXuG$?$*MY8Mc%V;5%jcVIlTA~Kza0Z5}z~hViXx)*48^o5Z(*^@u ze;K2E^Njp?8Au{6tXm2rfEdgyPu9`&;TkHU*PRO+ZDBS=5^fZqz1yJ4fHsryCEXod=Vq zgOJgf3$8e4or%pU)B3skML;P0H?=L9TvUuxeD`9}rWF30Hc|W+v%b(U{TS)i3Z{FO zN)SU>t1kpgVJ%J=Zy|_eab@C2s<;+DYPJHvAb1^FQGqz`0>ys_gI5oA^ANX8n}@=N z2YK2&kgurKvY9Du7KUUc?fDGoun_rtbV^nZgaw*6%$)+8NLDYN$f4P_G5xzLB^mC_ zq1#toVIkM@Xult3@0{gqlx;f&>u93JM^!Czb_URk8m=Cj3BlMJbl!I`eN24-Bjj@- z1h7F&8|4!bIi3oV7}g8+SBjKQYaME`5&zi_ggP zBxz!wEKx{TSr^UxB$&bt7Io@JDOhh5?S=vp^qm-b{N#zJpP`OPU^Fi8_*M50D>SgQ z%jI#BVUILm?9<0#bmIkwE*Je{Y;zfEKpO!f2AHDV(+Q=852_a!5h73m&4fbJ<7rsE zRoF^;rZomYDzcL3s6zxWDC!piy)i_^z{pW5Wne@{q3k4dM#w2+0oM+r-dGB&X)BNyzhZib(W}LTO>la-cQ?8A3z4Ip)8xN)$555m*)th!5n$iCf zmg2Tj*%D{h{LTeitK=Ie;be?ZJqX0m-`z4KBt(XRMvmwV%&e9X9w*r9k=Qh>a!HPf zWe<@M1$mT0Bi!&UWA?R?r%luL1CA)^ApvWfu;NFr!&s5(%B z8qqy$(28PCUQyv@JPp)v(5r`=yWrNe=IdmvO;o$3WlPj@-sc-{f?)T854~AV;klYR zXnLZ~4)!IorXKlAWEq20kg;@yf5As%^}FCZuvAg|xmjT)H+NCPKgkl^_FY^c|2! z&@RA2DxWM09zF^dV7hQbtA~Y=F5gJ9-a39BxJsYDzaPjO19!%Pp;-6uy2*EERm#Qg zYoe#ich~ImLxXMl@){&DzPt~_US2$#jU$h6=$EM$GdWSoU1&(?QzEbln?l@vNM62` zmAtIdqsX!1FYi#U!(-yl)Ll){KL~LFYtYvg1ODK7*>hXMkR)1=*b4TQk7Kyr?%7A5 z*K2PGNeb8&X(bkFVLis|FGZ3S13&K^zJ)3(~_o=*V1oyGWGh5RKi!<-&y;ST50 zlf^YmGi#PA*1gqmyCZfS5#JKxAUBo=s{1zU> zl8u%-gBa^D$Z|_|pFb|?JgE7gwYaNL_u)Z%ms9^!2Ty6Cxof@gr`0^t`#dLxXqpF* ze1@sxR*9c+inNqpE~(48N`0(3M#v8dT21l{An&}K+UkDGHX)l7 z)MkDJ6!syfHX*k)N6uAP7py(xJHwwTpF3~_jG}ZXaEcgYcpge4Fe7hZc@G;oJ_PkG z=1G;c2$gGEaGgF+{IKgb^dtq}s!-=ZwNaP*uuFa5dDmWXO!5uRXvr#ksUZEn&uG4* z2KuT|+jj9B-dohnK5^6(_Mep^Jg|$cyCid$<5Zp1Xx-I>SjY4N)ZYQ0lx^FNOKLXY zgLUQqg?brV=ZWJ(rv`f4whtZa$^F&YlQGHHcB|#ByK-ycS7(p71q00Jhk_IMbP&ET ziqm%a+y*xc9lng_1rN*2hcafm%(TF(?bYNM?&RDxghv%GpwB-iFz_+P2r%H_9EI_k zcV0WzkOk`u02)Po-Ej#GVWb+mg3sXnVA=+qi;M(^0ZsVO-s&- zY~jeFyCLOncz4(0)&r@n2a+WRQ^teT%;mmjyK1{}D(%`hePju4T^+B!1aec!SqrXi zjCaI0&hEWYd&`RN4puK&Vd)v)1WV6Nv-@uBx@Fyf!rO8~T%)nJ-*6KPt5mMZ7TmTv zC8{A;@IyO+?bLUX$)&@x5_Ve4r$Jr7V;6XQ$}nYw?=9AJJ|W7KC1wf3BQ|D1EeqVO ziV%c751t19XUPe|Zi#89B|VuDp90fN8MEO6V%nG`W(4(NikU~$kl>*Fw9$WYh<(w7 zERK(X#Dzf)g)aklMJEcM!s4uXWuXWh+<`kFD`wQNWXvfEIV7L@ZYAi7jA1+^&0!R@ z+yVR;@GTW0rJ)ujzE6s|4XzM875K>s^7K+zzct30_xVQ|=7XSxW<$J037HCuB&ut$ zG8{&q^0+u8jY;glVib?kD%a7sL!?i5?5DyoT4eNKoWx1Q<|Ti0+?Vwjw&Ic`bz!MQ zZQ=vM?78Khhx{Wj3-cjdxHyIG{+bs2i)hE>g^tpA__c3fx$oMS(zQ+Z0@-Y$?^VwA z%~i+9dqtPGw{-k0qcMIrKN&O%2}sl zB!AR>itlt>NL-kU%%8kj@}4Q_?nqlZle*3aiCF?hY+3#@WFE3C@onEMvjD(MZPpwL zI9^pR52{e=jljB?!nQ!IrlN?5iVl>|^$=P845W)WPCuIHi^^goSsq&{IiGx?APN*` z01F2p2N9W53iVElNsaF%xoyk-*u-6t?xT^+iebUG*517yaJvzIQZz0|iAjMXtuTWm z$|K(aNbBT&pw*B&Vjr9lNk0PCC5n@@(#WiHHFPW>2{S!|uz4FG9 zq!mODuZOa}bXEtzG<|f%h@bbvBrE#8Eqk~>Dd=!$Kd|#iS5X$Ud)UJ0M247RM(5*& zWR1;8W)Jxo)xrVYAVw`6WbO^|vU+7w3y$ymFh!y-ijwU%K#0VW5uFX;sSpa*QD_(` zv?F~EPm-FzdoK*@PAN(n0SR(&$Z?ut;rb;jznoG9HlS}fno2inm!h>oOpH(U0kp`L zPxb8OONJkEWGD&k(&DAhq?bsxNC%+eO^@l%F*fWna#_(@kYjB?tjTT*SaE-Tk0&zLvycA1zY=R=)Y4;Tnc zRQ&NOEQRvQB~|;naD_^1X#_pK`DMTdxCy?p1D@?Vh-07?aO^$&U9Hw>S>d#13(4+Ft{j{_nAnSul}nyo?`^o{*?V>5{n8oh zvZHcE!#iu2YFp=?yIFJd*_$UGXbuC=`UkO;N<6)U;jdcsY7E@d*s%0n9EEs_X+R#q z!=1vPfP~83Lg<4IVwIFdF9loxa8pSras@+s9lrFgTSX4(qfaryJ{Jv14wn*Kk?91* zdW?M-4#-H3aKPZ50-x5v?}ibS5+fmt9A!}u7T^LwaNPfJ3@F+2Ca*Z;4Mr*y3#M|$Jk07#qX z%b-=Z6{>3W^bG0;juoqJ!P+*?#)sgPu@KBUT4yMFl~J_seAOn_oyNjis-QV zJ?0~F*&CAI9I>>oH0Qh@E}y0|OHC+mRxDcb-xK&kECPHwfI{a|Y$)h4{Pby9iH>HUP3?>B?Z6jp=tFj%&@lT-szBNX zs(ca9fV!7OwVpE}VUp=R)qbK|PX)==S5n_l{V%DEAojDE5(-@}Ofry`aSTyD`%zXh zHIhELw*fgA$GeCmCjAQ{DKHI0#>`sKH)vO>+2PVew`cu{uVeQ2(9$GX0h7`elqJjR z7t5MbWli%JZbs6seT8@RL?@YOO zer($X4ZU+ya?=xO$H}DWB=goqbQ!JLv0PZUi4B3#8xCmQ3z!0L0y%CXwC?e5+5+Wk=2kHCm?DZAX z&-W-Pp@gj7BC2_H$t?W z*iB_eDG@079ZD`!GKVDNkYCA|HwX!=D19vDkLdCrQ}XAOyiduWQ1Ww1{(_PPO8$nD zUr}<8lHX854(1s%gu79A72>m)kUh)(edLhG%%&tCkgO>c8Q*4AbWAtTRAo%3A(Co> z2}s2!ssC~M`2r>6V#h=#jE!Wx0iz@(%uZmOZJ0H>kNc*5_&)PQz;{4=8&&WhC;TrSI!NmTwA8?D+aD|J;`#HbhhcvZy$c;@XS+J12=apxOXS_JeG1FP3w+fgH~#i zTq(#4o$=fIUfCCaNfG)?zr8&;m&q9znPNKJKG(&T4Us^?i6q0%Rhgd=L##AbOb~SHPenemJ+_=&bA_c z=bc6yl4=tYbmO|?F5z7(+j53d$hXQvLGI3$cD~?llsBW_vQlJsl<}o^cNzGNcM7ez ze^m`%umb(9*~tQapG}*pr}ax_N4#LReA=L9?ikkLR*&)(d>4PG-HyD+#5dk?yLii; RS_j|3->q@-{XE0X|1WEr0j2-| literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__version__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__version__.py new file mode 100644 index 0000000..2c105ac --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/__version__.py @@ -0,0 +1,14 @@ +# .-. .-. .-. . . .-. .-. .-. .-. +# |( |- |.| | | |- `-. | `-. +# ' ' `-' `-`.`-' `-' `-' ' `-' + +__title__ = "requests" +__description__ = "Python HTTP for Humans." +__url__ = "https://requests.readthedocs.io" +__version__ = "2.32.3" +__build__ = 0x023203 +__author__ = "Kenneth Reitz" +__author_email__ = "me@kennethreitz.org" +__license__ = "Apache-2.0" +__copyright__ = "Copyright Kenneth Reitz" +__cake__ = "\u2728 \U0001f370 \u2728" diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/_internal_utils.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/_internal_utils.py new file mode 100644 index 0000000..f2cf635 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/_internal_utils.py @@ -0,0 +1,50 @@ +""" +requests._internal_utils +~~~~~~~~~~~~~~ + +Provides utility functions that are consumed internally by Requests +which depend on extremely few external helpers (such as compat) +""" +import re + +from .compat import builtin_str + +_VALID_HEADER_NAME_RE_BYTE = re.compile(rb"^[^:\s][^:\r\n]*$") +_VALID_HEADER_NAME_RE_STR = re.compile(r"^[^:\s][^:\r\n]*$") +_VALID_HEADER_VALUE_RE_BYTE = re.compile(rb"^\S[^\r\n]*$|^$") +_VALID_HEADER_VALUE_RE_STR = re.compile(r"^\S[^\r\n]*$|^$") + +_HEADER_VALIDATORS_STR = (_VALID_HEADER_NAME_RE_STR, _VALID_HEADER_VALUE_RE_STR) +_HEADER_VALIDATORS_BYTE = (_VALID_HEADER_NAME_RE_BYTE, _VALID_HEADER_VALUE_RE_BYTE) +HEADER_VALIDATORS = { + bytes: _HEADER_VALIDATORS_BYTE, + str: _HEADER_VALIDATORS_STR, +} + + +def to_native_string(string, encoding="ascii"): + """Given a string object, regardless of type, returns a representation of + that string in the native string type, encoding and decoding where + necessary. This assumes ASCII unless told otherwise. + """ + if isinstance(string, builtin_str): + out = string + else: + out = string.decode(encoding) + + return out + + +def unicode_is_ascii(u_string): + """Determine if unicode string only contains ASCII characters. + + :param str u_string: unicode string to check. Must be unicode + and not Python 2 `str`. + :rtype: bool + """ + assert isinstance(u_string, str) + try: + u_string.encode("ascii") + return True + except UnicodeEncodeError: + return False diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/adapters.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/adapters.py new file mode 100644 index 0000000..9a58b16 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/adapters.py @@ -0,0 +1,719 @@ +""" +requests.adapters +~~~~~~~~~~~~~~~~~ + +This module contains the transport adapters that Requests uses to define +and maintain connections. +""" + +import os.path +import socket # noqa: F401 +import typing +import warnings + +from urllib3.exceptions import ClosedPoolError, ConnectTimeoutError +from urllib3.exceptions import HTTPError as _HTTPError +from urllib3.exceptions import InvalidHeader as _InvalidHeader +from urllib3.exceptions import ( + LocationValueError, + MaxRetryError, + NewConnectionError, + ProtocolError, +) +from urllib3.exceptions import ProxyError as _ProxyError +from urllib3.exceptions import ReadTimeoutError, ResponseError +from urllib3.exceptions import SSLError as _SSLError +from urllib3.poolmanager import PoolManager, proxy_from_url +from urllib3.util import Timeout as TimeoutSauce +from urllib3.util import parse_url +from urllib3.util.retry import Retry +from urllib3.util.ssl_ import create_urllib3_context + +from .auth import _basic_auth_str +from .compat import basestring, urlparse +from .cookies import extract_cookies_to_jar +from .exceptions import ( + ConnectionError, + ConnectTimeout, + InvalidHeader, + InvalidProxyURL, + InvalidSchema, + InvalidURL, + ProxyError, + ReadTimeout, + RetryError, + SSLError, +) +from .models import Response +from .structures import CaseInsensitiveDict +from .utils import ( + DEFAULT_CA_BUNDLE_PATH, + extract_zipped_paths, + get_auth_from_url, + get_encoding_from_headers, + prepend_scheme_if_needed, + select_proxy, + urldefragauth, +) + +try: + from urllib3.contrib.socks import SOCKSProxyManager +except ImportError: + + def SOCKSProxyManager(*args, **kwargs): + raise InvalidSchema("Missing dependencies for SOCKS support.") + + +if typing.TYPE_CHECKING: + from .models import PreparedRequest + + +DEFAULT_POOLBLOCK = False +DEFAULT_POOLSIZE = 10 +DEFAULT_RETRIES = 0 +DEFAULT_POOL_TIMEOUT = None + + +try: + import ssl # noqa: F401 + + _preloaded_ssl_context = create_urllib3_context() + _preloaded_ssl_context.load_verify_locations( + extract_zipped_paths(DEFAULT_CA_BUNDLE_PATH) + ) +except ImportError: + # Bypass default SSLContext creation when Python + # interpreter isn't built with the ssl module. + _preloaded_ssl_context = None + + +def _urllib3_request_context( + request: "PreparedRequest", + verify: "bool | str | None", + client_cert: "typing.Tuple[str, str] | str | None", + poolmanager: "PoolManager", +) -> "(typing.Dict[str, typing.Any], typing.Dict[str, typing.Any])": + host_params = {} + pool_kwargs = {} + parsed_request_url = urlparse(request.url) + scheme = parsed_request_url.scheme.lower() + port = parsed_request_url.port + + # Determine if we have and should use our default SSLContext + # to optimize performance on standard requests. + poolmanager_kwargs = getattr(poolmanager, "connection_pool_kw", {}) + has_poolmanager_ssl_context = poolmanager_kwargs.get("ssl_context") + should_use_default_ssl_context = ( + _preloaded_ssl_context is not None and not has_poolmanager_ssl_context + ) + + cert_reqs = "CERT_REQUIRED" + if verify is False: + cert_reqs = "CERT_NONE" + elif verify is True and should_use_default_ssl_context: + pool_kwargs["ssl_context"] = _preloaded_ssl_context + elif isinstance(verify, str): + if not os.path.isdir(verify): + pool_kwargs["ca_certs"] = verify + else: + pool_kwargs["ca_cert_dir"] = verify + pool_kwargs["cert_reqs"] = cert_reqs + if client_cert is not None: + if isinstance(client_cert, tuple) and len(client_cert) == 2: + pool_kwargs["cert_file"] = client_cert[0] + pool_kwargs["key_file"] = client_cert[1] + else: + # According to our docs, we allow users to specify just the client + # cert path + pool_kwargs["cert_file"] = client_cert + host_params = { + "scheme": scheme, + "host": parsed_request_url.hostname, + "port": port, + } + return host_params, pool_kwargs + + +class BaseAdapter: + """The Base Transport Adapter""" + + def __init__(self): + super().__init__() + + def send( + self, request, stream=False, timeout=None, verify=True, cert=None, proxies=None + ): + """Sends PreparedRequest object. Returns Response object. + + :param request: The :class:`PreparedRequest ` being sent. + :param stream: (optional) Whether to stream the request content. + :param timeout: (optional) How long to wait for the server to send + data before giving up, as a float, or a :ref:`(connect timeout, + read timeout) ` tuple. + :type timeout: float or tuple + :param verify: (optional) Either a boolean, in which case it controls whether we verify + the server's TLS certificate, or a string, in which case it must be a path + to a CA bundle to use + :param cert: (optional) Any user-provided SSL certificate to be trusted. + :param proxies: (optional) The proxies dictionary to apply to the request. + """ + raise NotImplementedError + + def close(self): + """Cleans up adapter specific items.""" + raise NotImplementedError + + +class HTTPAdapter(BaseAdapter): + """The built-in HTTP Adapter for urllib3. + + Provides a general-case interface for Requests sessions to contact HTTP and + HTTPS urls by implementing the Transport Adapter interface. This class will + usually be created by the :class:`Session ` class under the + covers. + + :param pool_connections: The number of urllib3 connection pools to cache. + :param pool_maxsize: The maximum number of connections to save in the pool. + :param max_retries: The maximum number of retries each connection + should attempt. Note, this applies only to failed DNS lookups, socket + connections and connection timeouts, never to requests where data has + made it to the server. By default, Requests does not retry failed + connections. If you need granular control over the conditions under + which we retry a request, import urllib3's ``Retry`` class and pass + that instead. + :param pool_block: Whether the connection pool should block for connections. + + Usage:: + + >>> import requests + >>> s = requests.Session() + >>> a = requests.adapters.HTTPAdapter(max_retries=3) + >>> s.mount('http://', a) + """ + + __attrs__ = [ + "max_retries", + "config", + "_pool_connections", + "_pool_maxsize", + "_pool_block", + ] + + def __init__( + self, + pool_connections=DEFAULT_POOLSIZE, + pool_maxsize=DEFAULT_POOLSIZE, + max_retries=DEFAULT_RETRIES, + pool_block=DEFAULT_POOLBLOCK, + ): + if max_retries == DEFAULT_RETRIES: + self.max_retries = Retry(0, read=False) + else: + self.max_retries = Retry.from_int(max_retries) + self.config = {} + self.proxy_manager = {} + + super().__init__() + + self._pool_connections = pool_connections + self._pool_maxsize = pool_maxsize + self._pool_block = pool_block + + self.init_poolmanager(pool_connections, pool_maxsize, block=pool_block) + + def __getstate__(self): + return {attr: getattr(self, attr, None) for attr in self.__attrs__} + + def __setstate__(self, state): + # Can't handle by adding 'proxy_manager' to self.__attrs__ because + # self.poolmanager uses a lambda function, which isn't pickleable. + self.proxy_manager = {} + self.config = {} + + for attr, value in state.items(): + setattr(self, attr, value) + + self.init_poolmanager( + self._pool_connections, self._pool_maxsize, block=self._pool_block + ) + + def init_poolmanager( + self, connections, maxsize, block=DEFAULT_POOLBLOCK, **pool_kwargs + ): + """Initializes a urllib3 PoolManager. + + This method should not be called from user code, and is only + exposed for use when subclassing the + :class:`HTTPAdapter `. + + :param connections: The number of urllib3 connection pools to cache. + :param maxsize: The maximum number of connections to save in the pool. + :param block: Block when no free connections are available. + :param pool_kwargs: Extra keyword arguments used to initialize the Pool Manager. + """ + # save these values for pickling + self._pool_connections = connections + self._pool_maxsize = maxsize + self._pool_block = block + + self.poolmanager = PoolManager( + num_pools=connections, + maxsize=maxsize, + block=block, + **pool_kwargs, + ) + + def proxy_manager_for(self, proxy, **proxy_kwargs): + """Return urllib3 ProxyManager for the given proxy. + + This method should not be called from user code, and is only + exposed for use when subclassing the + :class:`HTTPAdapter `. + + :param proxy: The proxy to return a urllib3 ProxyManager for. + :param proxy_kwargs: Extra keyword arguments used to configure the Proxy Manager. + :returns: ProxyManager + :rtype: urllib3.ProxyManager + """ + if proxy in self.proxy_manager: + manager = self.proxy_manager[proxy] + elif proxy.lower().startswith("socks"): + username, password = get_auth_from_url(proxy) + manager = self.proxy_manager[proxy] = SOCKSProxyManager( + proxy, + username=username, + password=password, + num_pools=self._pool_connections, + maxsize=self._pool_maxsize, + block=self._pool_block, + **proxy_kwargs, + ) + else: + proxy_headers = self.proxy_headers(proxy) + manager = self.proxy_manager[proxy] = proxy_from_url( + proxy, + proxy_headers=proxy_headers, + num_pools=self._pool_connections, + maxsize=self._pool_maxsize, + block=self._pool_block, + **proxy_kwargs, + ) + + return manager + + def cert_verify(self, conn, url, verify, cert): + """Verify a SSL certificate. This method should not be called from user + code, and is only exposed for use when subclassing the + :class:`HTTPAdapter `. + + :param conn: The urllib3 connection object associated with the cert. + :param url: The requested URL. + :param verify: Either a boolean, in which case it controls whether we verify + the server's TLS certificate, or a string, in which case it must be a path + to a CA bundle to use + :param cert: The SSL certificate to verify. + """ + if url.lower().startswith("https") and verify: + conn.cert_reqs = "CERT_REQUIRED" + + # Only load the CA certificates if 'verify' is a string indicating the CA bundle to use. + # Otherwise, if verify is a boolean, we don't load anything since + # the connection will be using a context with the default certificates already loaded, + # and this avoids a call to the slow load_verify_locations() + if verify is not True: + # `verify` must be a str with a path then + cert_loc = verify + + if not os.path.exists(cert_loc): + raise OSError( + f"Could not find a suitable TLS CA certificate bundle, " + f"invalid path: {cert_loc}" + ) + + if not os.path.isdir(cert_loc): + conn.ca_certs = cert_loc + else: + conn.ca_cert_dir = cert_loc + else: + conn.cert_reqs = "CERT_NONE" + conn.ca_certs = None + conn.ca_cert_dir = None + + if cert: + if not isinstance(cert, basestring): + conn.cert_file = cert[0] + conn.key_file = cert[1] + else: + conn.cert_file = cert + conn.key_file = None + if conn.cert_file and not os.path.exists(conn.cert_file): + raise OSError( + f"Could not find the TLS certificate file, " + f"invalid path: {conn.cert_file}" + ) + if conn.key_file and not os.path.exists(conn.key_file): + raise OSError( + f"Could not find the TLS key file, invalid path: {conn.key_file}" + ) + + def build_response(self, req, resp): + """Builds a :class:`Response ` object from a urllib3 + response. This should not be called from user code, and is only exposed + for use when subclassing the + :class:`HTTPAdapter ` + + :param req: The :class:`PreparedRequest ` used to generate the response. + :param resp: The urllib3 response object. + :rtype: requests.Response + """ + response = Response() + + # Fallback to None if there's no status_code, for whatever reason. + response.status_code = getattr(resp, "status", None) + + # Make headers case-insensitive. + response.headers = CaseInsensitiveDict(getattr(resp, "headers", {})) + + # Set encoding. + response.encoding = get_encoding_from_headers(response.headers) + response.raw = resp + response.reason = response.raw.reason + + if isinstance(req.url, bytes): + response.url = req.url.decode("utf-8") + else: + response.url = req.url + + # Add new cookies from the server. + extract_cookies_to_jar(response.cookies, req, resp) + + # Give the Response some context. + response.request = req + response.connection = self + + return response + + def build_connection_pool_key_attributes(self, request, verify, cert=None): + """Build the PoolKey attributes used by urllib3 to return a connection. + + This looks at the PreparedRequest, the user-specified verify value, + and the value of the cert parameter to determine what PoolKey values + to use to select a connection from a given urllib3 Connection Pool. + + The SSL related pool key arguments are not consistently set. As of + this writing, use the following to determine what keys may be in that + dictionary: + + * If ``verify`` is ``True``, ``"ssl_context"`` will be set and will be the + default Requests SSL Context + * If ``verify`` is ``False``, ``"ssl_context"`` will not be set but + ``"cert_reqs"`` will be set + * If ``verify`` is a string, (i.e., it is a user-specified trust bundle) + ``"ca_certs"`` will be set if the string is not a directory recognized + by :py:func:`os.path.isdir`, otherwise ``"ca_certs_dir"`` will be + set. + * If ``"cert"`` is specified, ``"cert_file"`` will always be set. If + ``"cert"`` is a tuple with a second item, ``"key_file"`` will also + be present + + To override these settings, one may subclass this class, call this + method and use the above logic to change parameters as desired. For + example, if one wishes to use a custom :py:class:`ssl.SSLContext` one + must both set ``"ssl_context"`` and based on what else they require, + alter the other keys to ensure the desired behaviour. + + :param request: + The PreparedReqest being sent over the connection. + :type request: + :class:`~requests.models.PreparedRequest` + :param verify: + Either a boolean, in which case it controls whether + we verify the server's TLS certificate, or a string, in which case it + must be a path to a CA bundle to use. + :param cert: + (optional) Any user-provided SSL certificate for client + authentication (a.k.a., mTLS). This may be a string (i.e., just + the path to a file which holds both certificate and key) or a + tuple of length 2 with the certificate file path and key file + path. + :returns: + A tuple of two dictionaries. The first is the "host parameters" + portion of the Pool Key including scheme, hostname, and port. The + second is a dictionary of SSLContext related parameters. + """ + return _urllib3_request_context(request, verify, cert, self.poolmanager) + + def get_connection_with_tls_context(self, request, verify, proxies=None, cert=None): + """Returns a urllib3 connection for the given request and TLS settings. + This should not be called from user code, and is only exposed for use + when subclassing the :class:`HTTPAdapter `. + + :param request: + The :class:`PreparedRequest ` object to be sent + over the connection. + :param verify: + Either a boolean, in which case it controls whether we verify the + server's TLS certificate, or a string, in which case it must be a + path to a CA bundle to use. + :param proxies: + (optional) The proxies dictionary to apply to the request. + :param cert: + (optional) Any user-provided SSL certificate to be used for client + authentication (a.k.a., mTLS). + :rtype: + urllib3.ConnectionPool + """ + proxy = select_proxy(request.url, proxies) + try: + host_params, pool_kwargs = self.build_connection_pool_key_attributes( + request, + verify, + cert, + ) + except ValueError as e: + raise InvalidURL(e, request=request) + if proxy: + proxy = prepend_scheme_if_needed(proxy, "http") + proxy_url = parse_url(proxy) + if not proxy_url.host: + raise InvalidProxyURL( + "Please check proxy URL. It is malformed " + "and could be missing the host." + ) + proxy_manager = self.proxy_manager_for(proxy) + conn = proxy_manager.connection_from_host( + **host_params, pool_kwargs=pool_kwargs + ) + else: + # Only scheme should be lower case + conn = self.poolmanager.connection_from_host( + **host_params, pool_kwargs=pool_kwargs + ) + + return conn + + def get_connection(self, url, proxies=None): + """DEPRECATED: Users should move to `get_connection_with_tls_context` + for all subclasses of HTTPAdapter using Requests>=2.32.2. + + Returns a urllib3 connection for the given URL. This should not be + called from user code, and is only exposed for use when subclassing the + :class:`HTTPAdapter `. + + :param url: The URL to connect to. + :param proxies: (optional) A Requests-style dictionary of proxies used on this request. + :rtype: urllib3.ConnectionPool + """ + warnings.warn( + ( + "`get_connection` has been deprecated in favor of " + "`get_connection_with_tls_context`. Custom HTTPAdapter subclasses " + "will need to migrate for Requests>=2.32.2. Please see " + "https://github.com/psf/requests/pull/6710 for more details." + ), + DeprecationWarning, + ) + proxy = select_proxy(url, proxies) + + if proxy: + proxy = prepend_scheme_if_needed(proxy, "http") + proxy_url = parse_url(proxy) + if not proxy_url.host: + raise InvalidProxyURL( + "Please check proxy URL. It is malformed " + "and could be missing the host." + ) + proxy_manager = self.proxy_manager_for(proxy) + conn = proxy_manager.connection_from_url(url) + else: + # Only scheme should be lower case + parsed = urlparse(url) + url = parsed.geturl() + conn = self.poolmanager.connection_from_url(url) + + return conn + + def close(self): + """Disposes of any internal state. + + Currently, this closes the PoolManager and any active ProxyManager, + which closes any pooled connections. + """ + self.poolmanager.clear() + for proxy in self.proxy_manager.values(): + proxy.clear() + + def request_url(self, request, proxies): + """Obtain the url to use when making the final request. + + If the message is being sent through a HTTP proxy, the full URL has to + be used. Otherwise, we should only use the path portion of the URL. + + This should not be called from user code, and is only exposed for use + when subclassing the + :class:`HTTPAdapter `. + + :param request: The :class:`PreparedRequest ` being sent. + :param proxies: A dictionary of schemes or schemes and hosts to proxy URLs. + :rtype: str + """ + proxy = select_proxy(request.url, proxies) + scheme = urlparse(request.url).scheme + + is_proxied_http_request = proxy and scheme != "https" + using_socks_proxy = False + if proxy: + proxy_scheme = urlparse(proxy).scheme.lower() + using_socks_proxy = proxy_scheme.startswith("socks") + + url = request.path_url + if url.startswith("//"): # Don't confuse urllib3 + url = f"/{url.lstrip('/')}" + + if is_proxied_http_request and not using_socks_proxy: + url = urldefragauth(request.url) + + return url + + def add_headers(self, request, **kwargs): + """Add any headers needed by the connection. As of v2.0 this does + nothing by default, but is left for overriding by users that subclass + the :class:`HTTPAdapter `. + + This should not be called from user code, and is only exposed for use + when subclassing the + :class:`HTTPAdapter `. + + :param request: The :class:`PreparedRequest ` to add headers to. + :param kwargs: The keyword arguments from the call to send(). + """ + pass + + def proxy_headers(self, proxy): + """Returns a dictionary of the headers to add to any request sent + through a proxy. This works with urllib3 magic to ensure that they are + correctly sent to the proxy, rather than in a tunnelled request if + CONNECT is being used. + + This should not be called from user code, and is only exposed for use + when subclassing the + :class:`HTTPAdapter `. + + :param proxy: The url of the proxy being used for this request. + :rtype: dict + """ + headers = {} + username, password = get_auth_from_url(proxy) + + if username: + headers["Proxy-Authorization"] = _basic_auth_str(username, password) + + return headers + + def send( + self, request, stream=False, timeout=None, verify=True, cert=None, proxies=None + ): + """Sends PreparedRequest object. Returns Response object. + + :param request: The :class:`PreparedRequest ` being sent. + :param stream: (optional) Whether to stream the request content. + :param timeout: (optional) How long to wait for the server to send + data before giving up, as a float, or a :ref:`(connect timeout, + read timeout) ` tuple. + :type timeout: float or tuple or urllib3 Timeout object + :param verify: (optional) Either a boolean, in which case it controls whether + we verify the server's TLS certificate, or a string, in which case it + must be a path to a CA bundle to use + :param cert: (optional) Any user-provided SSL certificate to be trusted. + :param proxies: (optional) The proxies dictionary to apply to the request. + :rtype: requests.Response + """ + + try: + conn = self.get_connection_with_tls_context( + request, verify, proxies=proxies, cert=cert + ) + except LocationValueError as e: + raise InvalidURL(e, request=request) + + self.cert_verify(conn, request.url, verify, cert) + url = self.request_url(request, proxies) + self.add_headers( + request, + stream=stream, + timeout=timeout, + verify=verify, + cert=cert, + proxies=proxies, + ) + + chunked = not (request.body is None or "Content-Length" in request.headers) + + if isinstance(timeout, tuple): + try: + connect, read = timeout + timeout = TimeoutSauce(connect=connect, read=read) + except ValueError: + raise ValueError( + f"Invalid timeout {timeout}. Pass a (connect, read) timeout tuple, " + f"or a single float to set both timeouts to the same value." + ) + elif isinstance(timeout, TimeoutSauce): + pass + else: + timeout = TimeoutSauce(connect=timeout, read=timeout) + + try: + resp = conn.urlopen( + method=request.method, + url=url, + body=request.body, + headers=request.headers, + redirect=False, + assert_same_host=False, + preload_content=False, + decode_content=False, + retries=self.max_retries, + timeout=timeout, + chunked=chunked, + ) + + except (ProtocolError, OSError) as err: + raise ConnectionError(err, request=request) + + except MaxRetryError as e: + if isinstance(e.reason, ConnectTimeoutError): + # TODO: Remove this in 3.0.0: see #2811 + if not isinstance(e.reason, NewConnectionError): + raise ConnectTimeout(e, request=request) + + if isinstance(e.reason, ResponseError): + raise RetryError(e, request=request) + + if isinstance(e.reason, _ProxyError): + raise ProxyError(e, request=request) + + if isinstance(e.reason, _SSLError): + # This branch is for urllib3 v1.22 and later. + raise SSLError(e, request=request) + + raise ConnectionError(e, request=request) + + except ClosedPoolError as e: + raise ConnectionError(e, request=request) + + except _ProxyError as e: + raise ProxyError(e) + + except (_SSLError, _HTTPError) as e: + if isinstance(e, _SSLError): + # This branch is for urllib3 versions earlier than v1.22 + raise SSLError(e, request=request) + elif isinstance(e, ReadTimeoutError): + raise ReadTimeout(e, request=request) + elif isinstance(e, _InvalidHeader): + raise InvalidHeader(e, request=request) + else: + raise + + return self.build_response(request, resp) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/api.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/api.py new file mode 100644 index 0000000..5960744 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/api.py @@ -0,0 +1,157 @@ +""" +requests.api +~~~~~~~~~~~~ + +This module implements the Requests API. + +:copyright: (c) 2012 by Kenneth Reitz. +:license: Apache2, see LICENSE for more details. +""" + +from . import sessions + + +def request(method, url, **kwargs): + """Constructs and sends a :class:`Request `. + + :param method: method for the new :class:`Request` object: ``GET``, ``OPTIONS``, ``HEAD``, ``POST``, ``PUT``, ``PATCH``, or ``DELETE``. + :param url: URL for the new :class:`Request` object. + :param params: (optional) Dictionary, list of tuples or bytes to send + in the query string for the :class:`Request`. + :param data: (optional) Dictionary, list of tuples, bytes, or file-like + object to send in the body of the :class:`Request`. + :param json: (optional) A JSON serializable Python object to send in the body of the :class:`Request`. + :param headers: (optional) Dictionary of HTTP Headers to send with the :class:`Request`. + :param cookies: (optional) Dict or CookieJar object to send with the :class:`Request`. + :param files: (optional) Dictionary of ``'name': file-like-objects`` (or ``{'name': file-tuple}``) for multipart encoding upload. + ``file-tuple`` can be a 2-tuple ``('filename', fileobj)``, 3-tuple ``('filename', fileobj, 'content_type')`` + or a 4-tuple ``('filename', fileobj, 'content_type', custom_headers)``, where ``'content_type'`` is a string + defining the content type of the given file and ``custom_headers`` a dict-like object containing additional headers + to add for the file. + :param auth: (optional) Auth tuple to enable Basic/Digest/Custom HTTP Auth. + :param timeout: (optional) How many seconds to wait for the server to send data + before giving up, as a float, or a :ref:`(connect timeout, read + timeout) ` tuple. + :type timeout: float or tuple + :param allow_redirects: (optional) Boolean. Enable/disable GET/OPTIONS/POST/PUT/PATCH/DELETE/HEAD redirection. Defaults to ``True``. + :type allow_redirects: bool + :param proxies: (optional) Dictionary mapping protocol to the URL of the proxy. + :param verify: (optional) Either a boolean, in which case it controls whether we verify + the server's TLS certificate, or a string, in which case it must be a path + to a CA bundle to use. Defaults to ``True``. + :param stream: (optional) if ``False``, the response content will be immediately downloaded. + :param cert: (optional) if String, path to ssl client cert file (.pem). If Tuple, ('cert', 'key') pair. + :return: :class:`Response ` object + :rtype: requests.Response + + Usage:: + + >>> import requests + >>> req = requests.request('GET', 'https://httpbin.org/get') + >>> req + + """ + + # By using the 'with' statement we are sure the session is closed, thus we + # avoid leaving sockets open which can trigger a ResourceWarning in some + # cases, and look like a memory leak in others. + with sessions.Session() as session: + return session.request(method=method, url=url, **kwargs) + + +def get(url, params=None, **kwargs): + r"""Sends a GET request. + + :param url: URL for the new :class:`Request` object. + :param params: (optional) Dictionary, list of tuples or bytes to send + in the query string for the :class:`Request`. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :return: :class:`Response ` object + :rtype: requests.Response + """ + + return request("get", url, params=params, **kwargs) + + +def options(url, **kwargs): + r"""Sends an OPTIONS request. + + :param url: URL for the new :class:`Request` object. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :return: :class:`Response ` object + :rtype: requests.Response + """ + + return request("options", url, **kwargs) + + +def head(url, **kwargs): + r"""Sends a HEAD request. + + :param url: URL for the new :class:`Request` object. + :param \*\*kwargs: Optional arguments that ``request`` takes. If + `allow_redirects` is not provided, it will be set to `False` (as + opposed to the default :meth:`request` behavior). + :return: :class:`Response ` object + :rtype: requests.Response + """ + + kwargs.setdefault("allow_redirects", False) + return request("head", url, **kwargs) + + +def post(url, data=None, json=None, **kwargs): + r"""Sends a POST request. + + :param url: URL for the new :class:`Request` object. + :param data: (optional) Dictionary, list of tuples, bytes, or file-like + object to send in the body of the :class:`Request`. + :param json: (optional) A JSON serializable Python object to send in the body of the :class:`Request`. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :return: :class:`Response ` object + :rtype: requests.Response + """ + + return request("post", url, data=data, json=json, **kwargs) + + +def put(url, data=None, **kwargs): + r"""Sends a PUT request. + + :param url: URL for the new :class:`Request` object. + :param data: (optional) Dictionary, list of tuples, bytes, or file-like + object to send in the body of the :class:`Request`. + :param json: (optional) A JSON serializable Python object to send in the body of the :class:`Request`. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :return: :class:`Response ` object + :rtype: requests.Response + """ + + return request("put", url, data=data, **kwargs) + + +def patch(url, data=None, **kwargs): + r"""Sends a PATCH request. + + :param url: URL for the new :class:`Request` object. + :param data: (optional) Dictionary, list of tuples, bytes, or file-like + object to send in the body of the :class:`Request`. + :param json: (optional) A JSON serializable Python object to send in the body of the :class:`Request`. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :return: :class:`Response ` object + :rtype: requests.Response + """ + + return request("patch", url, data=data, **kwargs) + + +def delete(url, **kwargs): + r"""Sends a DELETE request. + + :param url: URL for the new :class:`Request` object. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :return: :class:`Response ` object + :rtype: requests.Response + """ + + return request("delete", url, **kwargs) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/auth.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/auth.py new file mode 100644 index 0000000..4a7ce6d --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/auth.py @@ -0,0 +1,314 @@ +""" +requests.auth +~~~~~~~~~~~~~ + +This module contains the authentication handlers for Requests. +""" + +import hashlib +import os +import re +import threading +import time +import warnings +from base64 import b64encode + +from ._internal_utils import to_native_string +from .compat import basestring, str, urlparse +from .cookies import extract_cookies_to_jar +from .utils import parse_dict_header + +CONTENT_TYPE_FORM_URLENCODED = "application/x-www-form-urlencoded" +CONTENT_TYPE_MULTI_PART = "multipart/form-data" + + +def _basic_auth_str(username, password): + """Returns a Basic Auth string.""" + + # "I want us to put a big-ol' comment on top of it that + # says that this behaviour is dumb but we need to preserve + # it because people are relying on it." + # - Lukasa + # + # These are here solely to maintain backwards compatibility + # for things like ints. This will be removed in 3.0.0. + if not isinstance(username, basestring): + warnings.warn( + "Non-string usernames will no longer be supported in Requests " + "3.0.0. Please convert the object you've passed in ({!r}) to " + "a string or bytes object in the near future to avoid " + "problems.".format(username), + category=DeprecationWarning, + ) + username = str(username) + + if not isinstance(password, basestring): + warnings.warn( + "Non-string passwords will no longer be supported in Requests " + "3.0.0. Please convert the object you've passed in ({!r}) to " + "a string or bytes object in the near future to avoid " + "problems.".format(type(password)), + category=DeprecationWarning, + ) + password = str(password) + # -- End Removal -- + + if isinstance(username, str): + username = username.encode("latin1") + + if isinstance(password, str): + password = password.encode("latin1") + + authstr = "Basic " + to_native_string( + b64encode(b":".join((username, password))).strip() + ) + + return authstr + + +class AuthBase: + """Base class that all auth implementations derive from""" + + def __call__(self, r): + raise NotImplementedError("Auth hooks must be callable.") + + +class HTTPBasicAuth(AuthBase): + """Attaches HTTP Basic Authentication to the given Request object.""" + + def __init__(self, username, password): + self.username = username + self.password = password + + def __eq__(self, other): + return all( + [ + self.username == getattr(other, "username", None), + self.password == getattr(other, "password", None), + ] + ) + + def __ne__(self, other): + return not self == other + + def __call__(self, r): + r.headers["Authorization"] = _basic_auth_str(self.username, self.password) + return r + + +class HTTPProxyAuth(HTTPBasicAuth): + """Attaches HTTP Proxy Authentication to a given Request object.""" + + def __call__(self, r): + r.headers["Proxy-Authorization"] = _basic_auth_str(self.username, self.password) + return r + + +class HTTPDigestAuth(AuthBase): + """Attaches HTTP Digest Authentication to the given Request object.""" + + def __init__(self, username, password): + self.username = username + self.password = password + # Keep state in per-thread local storage + self._thread_local = threading.local() + + def init_per_thread_state(self): + # Ensure state is initialized just once per-thread + if not hasattr(self._thread_local, "init"): + self._thread_local.init = True + self._thread_local.last_nonce = "" + self._thread_local.nonce_count = 0 + self._thread_local.chal = {} + self._thread_local.pos = None + self._thread_local.num_401_calls = None + + def build_digest_header(self, method, url): + """ + :rtype: str + """ + + realm = self._thread_local.chal["realm"] + nonce = self._thread_local.chal["nonce"] + qop = self._thread_local.chal.get("qop") + algorithm = self._thread_local.chal.get("algorithm") + opaque = self._thread_local.chal.get("opaque") + hash_utf8 = None + + if algorithm is None: + _algorithm = "MD5" + else: + _algorithm = algorithm.upper() + # lambdas assume digest modules are imported at the top level + if _algorithm == "MD5" or _algorithm == "MD5-SESS": + + def md5_utf8(x): + if isinstance(x, str): + x = x.encode("utf-8") + return hashlib.md5(x).hexdigest() + + hash_utf8 = md5_utf8 + elif _algorithm == "SHA": + + def sha_utf8(x): + if isinstance(x, str): + x = x.encode("utf-8") + return hashlib.sha1(x).hexdigest() + + hash_utf8 = sha_utf8 + elif _algorithm == "SHA-256": + + def sha256_utf8(x): + if isinstance(x, str): + x = x.encode("utf-8") + return hashlib.sha256(x).hexdigest() + + hash_utf8 = sha256_utf8 + elif _algorithm == "SHA-512": + + def sha512_utf8(x): + if isinstance(x, str): + x = x.encode("utf-8") + return hashlib.sha512(x).hexdigest() + + hash_utf8 = sha512_utf8 + + KD = lambda s, d: hash_utf8(f"{s}:{d}") # noqa:E731 + + if hash_utf8 is None: + return None + + # XXX not implemented yet + entdig = None + p_parsed = urlparse(url) + #: path is request-uri defined in RFC 2616 which should not be empty + path = p_parsed.path or "/" + if p_parsed.query: + path += f"?{p_parsed.query}" + + A1 = f"{self.username}:{realm}:{self.password}" + A2 = f"{method}:{path}" + + HA1 = hash_utf8(A1) + HA2 = hash_utf8(A2) + + if nonce == self._thread_local.last_nonce: + self._thread_local.nonce_count += 1 + else: + self._thread_local.nonce_count = 1 + ncvalue = f"{self._thread_local.nonce_count:08x}" + s = str(self._thread_local.nonce_count).encode("utf-8") + s += nonce.encode("utf-8") + s += time.ctime().encode("utf-8") + s += os.urandom(8) + + cnonce = hashlib.sha1(s).hexdigest()[:16] + if _algorithm == "MD5-SESS": + HA1 = hash_utf8(f"{HA1}:{nonce}:{cnonce}") + + if not qop: + respdig = KD(HA1, f"{nonce}:{HA2}") + elif qop == "auth" or "auth" in qop.split(","): + noncebit = f"{nonce}:{ncvalue}:{cnonce}:auth:{HA2}" + respdig = KD(HA1, noncebit) + else: + # XXX handle auth-int. + return None + + self._thread_local.last_nonce = nonce + + # XXX should the partial digests be encoded too? + base = ( + f'username="{self.username}", realm="{realm}", nonce="{nonce}", ' + f'uri="{path}", response="{respdig}"' + ) + if opaque: + base += f', opaque="{opaque}"' + if algorithm: + base += f', algorithm="{algorithm}"' + if entdig: + base += f', digest="{entdig}"' + if qop: + base += f', qop="auth", nc={ncvalue}, cnonce="{cnonce}"' + + return f"Digest {base}" + + def handle_redirect(self, r, **kwargs): + """Reset num_401_calls counter on redirects.""" + if r.is_redirect: + self._thread_local.num_401_calls = 1 + + def handle_401(self, r, **kwargs): + """ + Takes the given response and tries digest-auth, if needed. + + :rtype: requests.Response + """ + + # If response is not 4xx, do not auth + # See https://github.com/psf/requests/issues/3772 + if not 400 <= r.status_code < 500: + self._thread_local.num_401_calls = 1 + return r + + if self._thread_local.pos is not None: + # Rewind the file position indicator of the body to where + # it was to resend the request. + r.request.body.seek(self._thread_local.pos) + s_auth = r.headers.get("www-authenticate", "") + + if "digest" in s_auth.lower() and self._thread_local.num_401_calls < 2: + self._thread_local.num_401_calls += 1 + pat = re.compile(r"digest ", flags=re.IGNORECASE) + self._thread_local.chal = parse_dict_header(pat.sub("", s_auth, count=1)) + + # Consume content and release the original connection + # to allow our new request to reuse the same one. + r.content + r.close() + prep = r.request.copy() + extract_cookies_to_jar(prep._cookies, r.request, r.raw) + prep.prepare_cookies(prep._cookies) + + prep.headers["Authorization"] = self.build_digest_header( + prep.method, prep.url + ) + _r = r.connection.send(prep, **kwargs) + _r.history.append(r) + _r.request = prep + + return _r + + self._thread_local.num_401_calls = 1 + return r + + def __call__(self, r): + # Initialize per-thread state, if needed + self.init_per_thread_state() + # If we have a saved nonce, skip the 401 + if self._thread_local.last_nonce: + r.headers["Authorization"] = self.build_digest_header(r.method, r.url) + try: + self._thread_local.pos = r.body.tell() + except AttributeError: + # In the case of HTTPDigestAuth being reused and the body of + # the previous request was a file-like object, pos has the + # file position of the previous body. Ensure it's set to + # None. + self._thread_local.pos = None + r.register_hook("response", self.handle_401) + r.register_hook("response", self.handle_redirect) + self._thread_local.num_401_calls = 1 + + return r + + def __eq__(self, other): + return all( + [ + self.username == getattr(other, "username", None), + self.password == getattr(other, "password", None), + ] + ) + + def __ne__(self, other): + return not self == other diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/certs.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/certs.py new file mode 100644 index 0000000..be422c3 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/certs.py @@ -0,0 +1,17 @@ +#!/usr/bin/env python + +""" +requests.certs +~~~~~~~~~~~~~~ + +This module returns the preferred default CA certificate bundle. There is +only one — the one from the certifi package. + +If you are packaging Requests, e.g., for a Linux distribution or a managed +environment, you can change the definition of where() to return a separately +packaged CA bundle. +""" +from certifi import where + +if __name__ == "__main__": + print(where()) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/compat.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/compat.py new file mode 100644 index 0000000..095de1b --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/compat.py @@ -0,0 +1,94 @@ +""" +requests.compat +~~~~~~~~~~~~~~~ + +This module previously handled import compatibility issues +between Python 2 and Python 3. It remains for backwards +compatibility until the next major version. +""" + +import importlib +import sys + +# ------------------- +# Character Detection +# ------------------- + + +def _resolve_char_detection(): + """Find supported character detection libraries.""" + chardet = None + for lib in ("chardet", "charset_normalizer"): + if chardet is None: + try: + chardet = importlib.import_module(lib) + except ImportError: + pass + return chardet + + +chardet = _resolve_char_detection() + +# ------- +# Pythons +# ------- + +# Syntax sugar. +_ver = sys.version_info + +#: Python 2.x? +is_py2 = _ver[0] == 2 + +#: Python 3.x? +is_py3 = _ver[0] == 3 + +# json/simplejson module import resolution +has_simplejson = False +try: + import simplejson as json + + has_simplejson = True +except ImportError: + import json + +if has_simplejson: + from simplejson import JSONDecodeError +else: + from json import JSONDecodeError + +# Keep OrderedDict for backwards compatibility. +from collections import OrderedDict +from collections.abc import Callable, Mapping, MutableMapping +from http import cookiejar as cookielib +from http.cookies import Morsel +from io import StringIO + +# -------------- +# Legacy Imports +# -------------- +from urllib.parse import ( + quote, + quote_plus, + unquote, + unquote_plus, + urldefrag, + urlencode, + urljoin, + urlparse, + urlsplit, + urlunparse, +) +from urllib.request import ( + getproxies, + getproxies_environment, + parse_http_list, + proxy_bypass, + proxy_bypass_environment, +) + +builtin_str = str +str = str +bytes = bytes +basestring = (str, bytes) +numeric_types = (int, float) +integer_types = (int,) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/cookies.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/cookies.py new file mode 100644 index 0000000..f69d0cd --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/cookies.py @@ -0,0 +1,561 @@ +""" +requests.cookies +~~~~~~~~~~~~~~~~ + +Compatibility code to be able to use `http.cookiejar.CookieJar` with requests. + +requests.utils imports from here, so be careful with imports. +""" + +import calendar +import copy +import time + +from ._internal_utils import to_native_string +from .compat import Morsel, MutableMapping, cookielib, urlparse, urlunparse + +try: + import threading +except ImportError: + import dummy_threading as threading + + +class MockRequest: + """Wraps a `requests.Request` to mimic a `urllib2.Request`. + + The code in `http.cookiejar.CookieJar` expects this interface in order to correctly + manage cookie policies, i.e., determine whether a cookie can be set, given the + domains of the request and the cookie. + + The original request object is read-only. The client is responsible for collecting + the new headers via `get_new_headers()` and interpreting them appropriately. You + probably want `get_cookie_header`, defined below. + """ + + def __init__(self, request): + self._r = request + self._new_headers = {} + self.type = urlparse(self._r.url).scheme + + def get_type(self): + return self.type + + def get_host(self): + return urlparse(self._r.url).netloc + + def get_origin_req_host(self): + return self.get_host() + + def get_full_url(self): + # Only return the response's URL if the user hadn't set the Host + # header + if not self._r.headers.get("Host"): + return self._r.url + # If they did set it, retrieve it and reconstruct the expected domain + host = to_native_string(self._r.headers["Host"], encoding="utf-8") + parsed = urlparse(self._r.url) + # Reconstruct the URL as we expect it + return urlunparse( + [ + parsed.scheme, + host, + parsed.path, + parsed.params, + parsed.query, + parsed.fragment, + ] + ) + + def is_unverifiable(self): + return True + + def has_header(self, name): + return name in self._r.headers or name in self._new_headers + + def get_header(self, name, default=None): + return self._r.headers.get(name, self._new_headers.get(name, default)) + + def add_header(self, key, val): + """cookiejar has no legitimate use for this method; add it back if you find one.""" + raise NotImplementedError( + "Cookie headers should be added with add_unredirected_header()" + ) + + def add_unredirected_header(self, name, value): + self._new_headers[name] = value + + def get_new_headers(self): + return self._new_headers + + @property + def unverifiable(self): + return self.is_unverifiable() + + @property + def origin_req_host(self): + return self.get_origin_req_host() + + @property + def host(self): + return self.get_host() + + +class MockResponse: + """Wraps a `httplib.HTTPMessage` to mimic a `urllib.addinfourl`. + + ...what? Basically, expose the parsed HTTP headers from the server response + the way `http.cookiejar` expects to see them. + """ + + def __init__(self, headers): + """Make a MockResponse for `cookiejar` to read. + + :param headers: a httplib.HTTPMessage or analogous carrying the headers + """ + self._headers = headers + + def info(self): + return self._headers + + def getheaders(self, name): + self._headers.getheaders(name) + + +def extract_cookies_to_jar(jar, request, response): + """Extract the cookies from the response into a CookieJar. + + :param jar: http.cookiejar.CookieJar (not necessarily a RequestsCookieJar) + :param request: our own requests.Request object + :param response: urllib3.HTTPResponse object + """ + if not (hasattr(response, "_original_response") and response._original_response): + return + # the _original_response field is the wrapped httplib.HTTPResponse object, + req = MockRequest(request) + # pull out the HTTPMessage with the headers and put it in the mock: + res = MockResponse(response._original_response.msg) + jar.extract_cookies(res, req) + + +def get_cookie_header(jar, request): + """ + Produce an appropriate Cookie header string to be sent with `request`, or None. + + :rtype: str + """ + r = MockRequest(request) + jar.add_cookie_header(r) + return r.get_new_headers().get("Cookie") + + +def remove_cookie_by_name(cookiejar, name, domain=None, path=None): + """Unsets a cookie by name, by default over all domains and paths. + + Wraps CookieJar.clear(), is O(n). + """ + clearables = [] + for cookie in cookiejar: + if cookie.name != name: + continue + if domain is not None and domain != cookie.domain: + continue + if path is not None and path != cookie.path: + continue + clearables.append((cookie.domain, cookie.path, cookie.name)) + + for domain, path, name in clearables: + cookiejar.clear(domain, path, name) + + +class CookieConflictError(RuntimeError): + """There are two cookies that meet the criteria specified in the cookie jar. + Use .get and .set and include domain and path args in order to be more specific. + """ + + +class RequestsCookieJar(cookielib.CookieJar, MutableMapping): + """Compatibility class; is a http.cookiejar.CookieJar, but exposes a dict + interface. + + This is the CookieJar we create by default for requests and sessions that + don't specify one, since some clients may expect response.cookies and + session.cookies to support dict operations. + + Requests does not use the dict interface internally; it's just for + compatibility with external client code. All requests code should work + out of the box with externally provided instances of ``CookieJar``, e.g. + ``LWPCookieJar`` and ``FileCookieJar``. + + Unlike a regular CookieJar, this class is pickleable. + + .. warning:: dictionary operations that are normally O(1) may be O(n). + """ + + def get(self, name, default=None, domain=None, path=None): + """Dict-like get() that also supports optional domain and path args in + order to resolve naming collisions from using one cookie jar over + multiple domains. + + .. warning:: operation is O(n), not O(1). + """ + try: + return self._find_no_duplicates(name, domain, path) + except KeyError: + return default + + def set(self, name, value, **kwargs): + """Dict-like set() that also supports optional domain and path args in + order to resolve naming collisions from using one cookie jar over + multiple domains. + """ + # support client code that unsets cookies by assignment of a None value: + if value is None: + remove_cookie_by_name( + self, name, domain=kwargs.get("domain"), path=kwargs.get("path") + ) + return + + if isinstance(value, Morsel): + c = morsel_to_cookie(value) + else: + c = create_cookie(name, value, **kwargs) + self.set_cookie(c) + return c + + def iterkeys(self): + """Dict-like iterkeys() that returns an iterator of names of cookies + from the jar. + + .. seealso:: itervalues() and iteritems(). + """ + for cookie in iter(self): + yield cookie.name + + def keys(self): + """Dict-like keys() that returns a list of names of cookies from the + jar. + + .. seealso:: values() and items(). + """ + return list(self.iterkeys()) + + def itervalues(self): + """Dict-like itervalues() that returns an iterator of values of cookies + from the jar. + + .. seealso:: iterkeys() and iteritems(). + """ + for cookie in iter(self): + yield cookie.value + + def values(self): + """Dict-like values() that returns a list of values of cookies from the + jar. + + .. seealso:: keys() and items(). + """ + return list(self.itervalues()) + + def iteritems(self): + """Dict-like iteritems() that returns an iterator of name-value tuples + from the jar. + + .. seealso:: iterkeys() and itervalues(). + """ + for cookie in iter(self): + yield cookie.name, cookie.value + + def items(self): + """Dict-like items() that returns a list of name-value tuples from the + jar. Allows client-code to call ``dict(RequestsCookieJar)`` and get a + vanilla python dict of key value pairs. + + .. seealso:: keys() and values(). + """ + return list(self.iteritems()) + + def list_domains(self): + """Utility method to list all the domains in the jar.""" + domains = [] + for cookie in iter(self): + if cookie.domain not in domains: + domains.append(cookie.domain) + return domains + + def list_paths(self): + """Utility method to list all the paths in the jar.""" + paths = [] + for cookie in iter(self): + if cookie.path not in paths: + paths.append(cookie.path) + return paths + + def multiple_domains(self): + """Returns True if there are multiple domains in the jar. + Returns False otherwise. + + :rtype: bool + """ + domains = [] + for cookie in iter(self): + if cookie.domain is not None and cookie.domain in domains: + return True + domains.append(cookie.domain) + return False # there is only one domain in jar + + def get_dict(self, domain=None, path=None): + """Takes as an argument an optional domain and path and returns a plain + old Python dict of name-value pairs of cookies that meet the + requirements. + + :rtype: dict + """ + dictionary = {} + for cookie in iter(self): + if (domain is None or cookie.domain == domain) and ( + path is None or cookie.path == path + ): + dictionary[cookie.name] = cookie.value + return dictionary + + def __contains__(self, name): + try: + return super().__contains__(name) + except CookieConflictError: + return True + + def __getitem__(self, name): + """Dict-like __getitem__() for compatibility with client code. Throws + exception if there are more than one cookie with name. In that case, + use the more explicit get() method instead. + + .. warning:: operation is O(n), not O(1). + """ + return self._find_no_duplicates(name) + + def __setitem__(self, name, value): + """Dict-like __setitem__ for compatibility with client code. Throws + exception if there is already a cookie of that name in the jar. In that + case, use the more explicit set() method instead. + """ + self.set(name, value) + + def __delitem__(self, name): + """Deletes a cookie given a name. Wraps ``http.cookiejar.CookieJar``'s + ``remove_cookie_by_name()``. + """ + remove_cookie_by_name(self, name) + + def set_cookie(self, cookie, *args, **kwargs): + if ( + hasattr(cookie.value, "startswith") + and cookie.value.startswith('"') + and cookie.value.endswith('"') + ): + cookie.value = cookie.value.replace('\\"', "") + return super().set_cookie(cookie, *args, **kwargs) + + def update(self, other): + """Updates this jar with cookies from another CookieJar or dict-like""" + if isinstance(other, cookielib.CookieJar): + for cookie in other: + self.set_cookie(copy.copy(cookie)) + else: + super().update(other) + + def _find(self, name, domain=None, path=None): + """Requests uses this method internally to get cookie values. + + If there are conflicting cookies, _find arbitrarily chooses one. + See _find_no_duplicates if you want an exception thrown if there are + conflicting cookies. + + :param name: a string containing name of cookie + :param domain: (optional) string containing domain of cookie + :param path: (optional) string containing path of cookie + :return: cookie.value + """ + for cookie in iter(self): + if cookie.name == name: + if domain is None or cookie.domain == domain: + if path is None or cookie.path == path: + return cookie.value + + raise KeyError(f"name={name!r}, domain={domain!r}, path={path!r}") + + def _find_no_duplicates(self, name, domain=None, path=None): + """Both ``__get_item__`` and ``get`` call this function: it's never + used elsewhere in Requests. + + :param name: a string containing name of cookie + :param domain: (optional) string containing domain of cookie + :param path: (optional) string containing path of cookie + :raises KeyError: if cookie is not found + :raises CookieConflictError: if there are multiple cookies + that match name and optionally domain and path + :return: cookie.value + """ + toReturn = None + for cookie in iter(self): + if cookie.name == name: + if domain is None or cookie.domain == domain: + if path is None or cookie.path == path: + if toReturn is not None: + # if there are multiple cookies that meet passed in criteria + raise CookieConflictError( + f"There are multiple cookies with name, {name!r}" + ) + # we will eventually return this as long as no cookie conflict + toReturn = cookie.value + + if toReturn: + return toReturn + raise KeyError(f"name={name!r}, domain={domain!r}, path={path!r}") + + def __getstate__(self): + """Unlike a normal CookieJar, this class is pickleable.""" + state = self.__dict__.copy() + # remove the unpickleable RLock object + state.pop("_cookies_lock") + return state + + def __setstate__(self, state): + """Unlike a normal CookieJar, this class is pickleable.""" + self.__dict__.update(state) + if "_cookies_lock" not in self.__dict__: + self._cookies_lock = threading.RLock() + + def copy(self): + """Return a copy of this RequestsCookieJar.""" + new_cj = RequestsCookieJar() + new_cj.set_policy(self.get_policy()) + new_cj.update(self) + return new_cj + + def get_policy(self): + """Return the CookiePolicy instance used.""" + return self._policy + + +def _copy_cookie_jar(jar): + if jar is None: + return None + + if hasattr(jar, "copy"): + # We're dealing with an instance of RequestsCookieJar + return jar.copy() + # We're dealing with a generic CookieJar instance + new_jar = copy.copy(jar) + new_jar.clear() + for cookie in jar: + new_jar.set_cookie(copy.copy(cookie)) + return new_jar + + +def create_cookie(name, value, **kwargs): + """Make a cookie from underspecified parameters. + + By default, the pair of `name` and `value` will be set for the domain '' + and sent on every request (this is sometimes called a "supercookie"). + """ + result = { + "version": 0, + "name": name, + "value": value, + "port": None, + "domain": "", + "path": "/", + "secure": False, + "expires": None, + "discard": True, + "comment": None, + "comment_url": None, + "rest": {"HttpOnly": None}, + "rfc2109": False, + } + + badargs = set(kwargs) - set(result) + if badargs: + raise TypeError( + f"create_cookie() got unexpected keyword arguments: {list(badargs)}" + ) + + result.update(kwargs) + result["port_specified"] = bool(result["port"]) + result["domain_specified"] = bool(result["domain"]) + result["domain_initial_dot"] = result["domain"].startswith(".") + result["path_specified"] = bool(result["path"]) + + return cookielib.Cookie(**result) + + +def morsel_to_cookie(morsel): + """Convert a Morsel object into a Cookie containing the one k/v pair.""" + + expires = None + if morsel["max-age"]: + try: + expires = int(time.time() + int(morsel["max-age"])) + except ValueError: + raise TypeError(f"max-age: {morsel['max-age']} must be integer") + elif morsel["expires"]: + time_template = "%a, %d-%b-%Y %H:%M:%S GMT" + expires = calendar.timegm(time.strptime(morsel["expires"], time_template)) + return create_cookie( + comment=morsel["comment"], + comment_url=bool(morsel["comment"]), + discard=False, + domain=morsel["domain"], + expires=expires, + name=morsel.key, + path=morsel["path"], + port=None, + rest={"HttpOnly": morsel["httponly"]}, + rfc2109=False, + secure=bool(morsel["secure"]), + value=morsel.value, + version=morsel["version"] or 0, + ) + + +def cookiejar_from_dict(cookie_dict, cookiejar=None, overwrite=True): + """Returns a CookieJar from a key/value dictionary. + + :param cookie_dict: Dict of key/values to insert into CookieJar. + :param cookiejar: (optional) A cookiejar to add the cookies to. + :param overwrite: (optional) If False, will not replace cookies + already in the jar with new ones. + :rtype: CookieJar + """ + if cookiejar is None: + cookiejar = RequestsCookieJar() + + if cookie_dict is not None: + names_from_jar = [cookie.name for cookie in cookiejar] + for name in cookie_dict: + if overwrite or (name not in names_from_jar): + cookiejar.set_cookie(create_cookie(name, cookie_dict[name])) + + return cookiejar + + +def merge_cookies(cookiejar, cookies): + """Add cookies to cookiejar and returns a merged CookieJar. + + :param cookiejar: CookieJar object to add the cookies to. + :param cookies: Dictionary or CookieJar object to be added. + :rtype: CookieJar + """ + if not isinstance(cookiejar, cookielib.CookieJar): + raise ValueError("You can only merge into CookieJar") + + if isinstance(cookies, dict): + cookiejar = cookiejar_from_dict(cookies, cookiejar=cookiejar, overwrite=False) + elif isinstance(cookies, cookielib.CookieJar): + try: + cookiejar.update(cookies) + except AttributeError: + for cookie_in_jar in cookies: + cookiejar.set_cookie(cookie_in_jar) + + return cookiejar diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/exceptions.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/exceptions.py new file mode 100644 index 0000000..83986b4 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/exceptions.py @@ -0,0 +1,151 @@ +""" +requests.exceptions +~~~~~~~~~~~~~~~~~~~ + +This module contains the set of Requests' exceptions. +""" +from urllib3.exceptions import HTTPError as BaseHTTPError + +from .compat import JSONDecodeError as CompatJSONDecodeError + + +class RequestException(IOError): + """There was an ambiguous exception that occurred while handling your + request. + """ + + def __init__(self, *args, **kwargs): + """Initialize RequestException with `request` and `response` objects.""" + response = kwargs.pop("response", None) + self.response = response + self.request = kwargs.pop("request", None) + if response is not None and not self.request and hasattr(response, "request"): + self.request = self.response.request + super().__init__(*args, **kwargs) + + +class InvalidJSONError(RequestException): + """A JSON error occurred.""" + + +class JSONDecodeError(InvalidJSONError, CompatJSONDecodeError): + """Couldn't decode the text into json""" + + def __init__(self, *args, **kwargs): + """ + Construct the JSONDecodeError instance first with all + args. Then use it's args to construct the IOError so that + the json specific args aren't used as IOError specific args + and the error message from JSONDecodeError is preserved. + """ + CompatJSONDecodeError.__init__(self, *args) + InvalidJSONError.__init__(self, *self.args, **kwargs) + + def __reduce__(self): + """ + The __reduce__ method called when pickling the object must + be the one from the JSONDecodeError (be it json/simplejson) + as it expects all the arguments for instantiation, not just + one like the IOError, and the MRO would by default call the + __reduce__ method from the IOError due to the inheritance order. + """ + return CompatJSONDecodeError.__reduce__(self) + + +class HTTPError(RequestException): + """An HTTP error occurred.""" + + +class ConnectionError(RequestException): + """A Connection error occurred.""" + + +class ProxyError(ConnectionError): + """A proxy error occurred.""" + + +class SSLError(ConnectionError): + """An SSL error occurred.""" + + +class Timeout(RequestException): + """The request timed out. + + Catching this error will catch both + :exc:`~requests.exceptions.ConnectTimeout` and + :exc:`~requests.exceptions.ReadTimeout` errors. + """ + + +class ConnectTimeout(ConnectionError, Timeout): + """The request timed out while trying to connect to the remote server. + + Requests that produced this error are safe to retry. + """ + + +class ReadTimeout(Timeout): + """The server did not send any data in the allotted amount of time.""" + + +class URLRequired(RequestException): + """A valid URL is required to make a request.""" + + +class TooManyRedirects(RequestException): + """Too many redirects.""" + + +class MissingSchema(RequestException, ValueError): + """The URL scheme (e.g. http or https) is missing.""" + + +class InvalidSchema(RequestException, ValueError): + """The URL scheme provided is either invalid or unsupported.""" + + +class InvalidURL(RequestException, ValueError): + """The URL provided was somehow invalid.""" + + +class InvalidHeader(RequestException, ValueError): + """The header value provided was somehow invalid.""" + + +class InvalidProxyURL(InvalidURL): + """The proxy URL provided is invalid.""" + + +class ChunkedEncodingError(RequestException): + """The server declared chunked encoding but sent an invalid chunk.""" + + +class ContentDecodingError(RequestException, BaseHTTPError): + """Failed to decode response content.""" + + +class StreamConsumedError(RequestException, TypeError): + """The content for this response was already consumed.""" + + +class RetryError(RequestException): + """Custom retries logic failed""" + + +class UnrewindableBodyError(RequestException): + """Requests encountered an error when trying to rewind a body.""" + + +# Warnings + + +class RequestsWarning(Warning): + """Base warning for Requests.""" + + +class FileModeWarning(RequestsWarning, DeprecationWarning): + """A file was opened in text mode, but Requests determined its binary length.""" + + +class RequestsDependencyWarning(RequestsWarning): + """An imported dependency doesn't match the expected version range.""" diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/help.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/help.py new file mode 100644 index 0000000..8fbcd65 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/help.py @@ -0,0 +1,134 @@ +"""Module containing bug report helper(s).""" + +import json +import platform +import ssl +import sys + +import idna +import urllib3 + +from . import __version__ as requests_version + +try: + import charset_normalizer +except ImportError: + charset_normalizer = None + +try: + import chardet +except ImportError: + chardet = None + +try: + from urllib3.contrib import pyopenssl +except ImportError: + pyopenssl = None + OpenSSL = None + cryptography = None +else: + import cryptography + import OpenSSL + + +def _implementation(): + """Return a dict with the Python implementation and version. + + Provide both the name and the version of the Python implementation + currently running. For example, on CPython 3.10.3 it will return + {'name': 'CPython', 'version': '3.10.3'}. + + This function works best on CPython and PyPy: in particular, it probably + doesn't work for Jython or IronPython. Future investigation should be done + to work out the correct shape of the code for those platforms. + """ + implementation = platform.python_implementation() + + if implementation == "CPython": + implementation_version = platform.python_version() + elif implementation == "PyPy": + implementation_version = "{}.{}.{}".format( + sys.pypy_version_info.major, + sys.pypy_version_info.minor, + sys.pypy_version_info.micro, + ) + if sys.pypy_version_info.releaselevel != "final": + implementation_version = "".join( + [implementation_version, sys.pypy_version_info.releaselevel] + ) + elif implementation == "Jython": + implementation_version = platform.python_version() # Complete Guess + elif implementation == "IronPython": + implementation_version = platform.python_version() # Complete Guess + else: + implementation_version = "Unknown" + + return {"name": implementation, "version": implementation_version} + + +def info(): + """Generate information for a bug report.""" + try: + platform_info = { + "system": platform.system(), + "release": platform.release(), + } + except OSError: + platform_info = { + "system": "Unknown", + "release": "Unknown", + } + + implementation_info = _implementation() + urllib3_info = {"version": urllib3.__version__} + charset_normalizer_info = {"version": None} + chardet_info = {"version": None} + if charset_normalizer: + charset_normalizer_info = {"version": charset_normalizer.__version__} + if chardet: + chardet_info = {"version": chardet.__version__} + + pyopenssl_info = { + "version": None, + "openssl_version": "", + } + if OpenSSL: + pyopenssl_info = { + "version": OpenSSL.__version__, + "openssl_version": f"{OpenSSL.SSL.OPENSSL_VERSION_NUMBER:x}", + } + cryptography_info = { + "version": getattr(cryptography, "__version__", ""), + } + idna_info = { + "version": getattr(idna, "__version__", ""), + } + + system_ssl = ssl.OPENSSL_VERSION_NUMBER + system_ssl_info = {"version": f"{system_ssl:x}" if system_ssl is not None else ""} + + return { + "platform": platform_info, + "implementation": implementation_info, + "system_ssl": system_ssl_info, + "using_pyopenssl": pyopenssl is not None, + "using_charset_normalizer": chardet is None, + "pyOpenSSL": pyopenssl_info, + "urllib3": urllib3_info, + "chardet": chardet_info, + "charset_normalizer": charset_normalizer_info, + "cryptography": cryptography_info, + "idna": idna_info, + "requests": { + "version": requests_version, + }, + } + + +def main(): + """Pretty-print the bug information as JSON.""" + print(json.dumps(info(), sort_keys=True, indent=2)) + + +if __name__ == "__main__": + main() diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/hooks.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/hooks.py new file mode 100644 index 0000000..d181ba2 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/hooks.py @@ -0,0 +1,33 @@ +""" +requests.hooks +~~~~~~~~~~~~~~ + +This module provides the capabilities for the Requests hooks system. + +Available hooks: + +``response``: + The response generated from a Request. +""" +HOOKS = ["response"] + + +def default_hooks(): + return {event: [] for event in HOOKS} + + +# TODO: response is the only one + + +def dispatch_hook(key, hooks, hook_data, **kwargs): + """Dispatches a hook dictionary on a given piece of data.""" + hooks = hooks or {} + hooks = hooks.get(key) + if hooks: + if hasattr(hooks, "__call__"): + hooks = [hooks] + for hook in hooks: + _hook_data = hook(hook_data, **kwargs) + if _hook_data is not None: + hook_data = _hook_data + return hook_data diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/models.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/models.py new file mode 100644 index 0000000..8f56ca7 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/models.py @@ -0,0 +1,1037 @@ +""" +requests.models +~~~~~~~~~~~~~~~ + +This module contains the primary objects that power Requests. +""" + +import datetime + +# Import encoding now, to avoid implicit import later. +# Implicit import within threads may cause LookupError when standard library is in a ZIP, +# such as in Embedded Python. See https://github.com/psf/requests/issues/3578. +import encodings.idna # noqa: F401 +from io import UnsupportedOperation + +from urllib3.exceptions import ( + DecodeError, + LocationParseError, + ProtocolError, + ReadTimeoutError, + SSLError, +) +from urllib3.fields import RequestField +from urllib3.filepost import encode_multipart_formdata +from urllib3.util import parse_url + +from ._internal_utils import to_native_string, unicode_is_ascii +from .auth import HTTPBasicAuth +from .compat import ( + Callable, + JSONDecodeError, + Mapping, + basestring, + builtin_str, + chardet, + cookielib, +) +from .compat import json as complexjson +from .compat import urlencode, urlsplit, urlunparse +from .cookies import _copy_cookie_jar, cookiejar_from_dict, get_cookie_header +from .exceptions import ( + ChunkedEncodingError, + ConnectionError, + ContentDecodingError, + HTTPError, + InvalidJSONError, + InvalidURL, +) +from .exceptions import JSONDecodeError as RequestsJSONDecodeError +from .exceptions import MissingSchema +from .exceptions import SSLError as RequestsSSLError +from .exceptions import StreamConsumedError +from .hooks import default_hooks +from .status_codes import codes +from .structures import CaseInsensitiveDict +from .utils import ( + check_header_validity, + get_auth_from_url, + guess_filename, + guess_json_utf, + iter_slices, + parse_header_links, + requote_uri, + stream_decode_response_unicode, + super_len, + to_key_val_list, +) + +#: The set of HTTP status codes that indicate an automatically +#: processable redirect. +REDIRECT_STATI = ( + codes.moved, # 301 + codes.found, # 302 + codes.other, # 303 + codes.temporary_redirect, # 307 + codes.permanent_redirect, # 308 +) + +DEFAULT_REDIRECT_LIMIT = 30 +CONTENT_CHUNK_SIZE = 10 * 1024 +ITER_CHUNK_SIZE = 512 + + +class RequestEncodingMixin: + @property + def path_url(self): + """Build the path URL to use.""" + + url = [] + + p = urlsplit(self.url) + + path = p.path + if not path: + path = "/" + + url.append(path) + + query = p.query + if query: + url.append("?") + url.append(query) + + return "".join(url) + + @staticmethod + def _encode_params(data): + """Encode parameters in a piece of data. + + Will successfully encode parameters when passed as a dict or a list of + 2-tuples. Order is retained if data is a list of 2-tuples but arbitrary + if parameters are supplied as a dict. + """ + + if isinstance(data, (str, bytes)): + return data + elif hasattr(data, "read"): + return data + elif hasattr(data, "__iter__"): + result = [] + for k, vs in to_key_val_list(data): + if isinstance(vs, basestring) or not hasattr(vs, "__iter__"): + vs = [vs] + for v in vs: + if v is not None: + result.append( + ( + k.encode("utf-8") if isinstance(k, str) else k, + v.encode("utf-8") if isinstance(v, str) else v, + ) + ) + return urlencode(result, doseq=True) + else: + return data + + @staticmethod + def _encode_files(files, data): + """Build the body for a multipart/form-data request. + + Will successfully encode files when passed as a dict or a list of + tuples. Order is retained if data is a list of tuples but arbitrary + if parameters are supplied as a dict. + The tuples may be 2-tuples (filename, fileobj), 3-tuples (filename, fileobj, contentype) + or 4-tuples (filename, fileobj, contentype, custom_headers). + """ + if not files: + raise ValueError("Files must be provided.") + elif isinstance(data, basestring): + raise ValueError("Data must not be a string.") + + new_fields = [] + fields = to_key_val_list(data or {}) + files = to_key_val_list(files or {}) + + for field, val in fields: + if isinstance(val, basestring) or not hasattr(val, "__iter__"): + val = [val] + for v in val: + if v is not None: + # Don't call str() on bytestrings: in Py3 it all goes wrong. + if not isinstance(v, bytes): + v = str(v) + + new_fields.append( + ( + field.decode("utf-8") + if isinstance(field, bytes) + else field, + v.encode("utf-8") if isinstance(v, str) else v, + ) + ) + + for k, v in files: + # support for explicit filename + ft = None + fh = None + if isinstance(v, (tuple, list)): + if len(v) == 2: + fn, fp = v + elif len(v) == 3: + fn, fp, ft = v + else: + fn, fp, ft, fh = v + else: + fn = guess_filename(v) or k + fp = v + + if isinstance(fp, (str, bytes, bytearray)): + fdata = fp + elif hasattr(fp, "read"): + fdata = fp.read() + elif fp is None: + continue + else: + fdata = fp + + rf = RequestField(name=k, data=fdata, filename=fn, headers=fh) + rf.make_multipart(content_type=ft) + new_fields.append(rf) + + body, content_type = encode_multipart_formdata(new_fields) + + return body, content_type + + +class RequestHooksMixin: + def register_hook(self, event, hook): + """Properly register a hook.""" + + if event not in self.hooks: + raise ValueError(f'Unsupported event specified, with event name "{event}"') + + if isinstance(hook, Callable): + self.hooks[event].append(hook) + elif hasattr(hook, "__iter__"): + self.hooks[event].extend(h for h in hook if isinstance(h, Callable)) + + def deregister_hook(self, event, hook): + """Deregister a previously registered hook. + Returns True if the hook existed, False if not. + """ + + try: + self.hooks[event].remove(hook) + return True + except ValueError: + return False + + +class Request(RequestHooksMixin): + """A user-created :class:`Request ` object. + + Used to prepare a :class:`PreparedRequest `, which is sent to the server. + + :param method: HTTP method to use. + :param url: URL to send. + :param headers: dictionary of headers to send. + :param files: dictionary of {filename: fileobject} files to multipart upload. + :param data: the body to attach to the request. If a dictionary or + list of tuples ``[(key, value)]`` is provided, form-encoding will + take place. + :param json: json for the body to attach to the request (if files or data is not specified). + :param params: URL parameters to append to the URL. If a dictionary or + list of tuples ``[(key, value)]`` is provided, form-encoding will + take place. + :param auth: Auth handler or (user, pass) tuple. + :param cookies: dictionary or CookieJar of cookies to attach to this request. + :param hooks: dictionary of callback hooks, for internal usage. + + Usage:: + + >>> import requests + >>> req = requests.Request('GET', 'https://httpbin.org/get') + >>> req.prepare() + + """ + + def __init__( + self, + method=None, + url=None, + headers=None, + files=None, + data=None, + params=None, + auth=None, + cookies=None, + hooks=None, + json=None, + ): + # Default empty dicts for dict params. + data = [] if data is None else data + files = [] if files is None else files + headers = {} if headers is None else headers + params = {} if params is None else params + hooks = {} if hooks is None else hooks + + self.hooks = default_hooks() + for k, v in list(hooks.items()): + self.register_hook(event=k, hook=v) + + self.method = method + self.url = url + self.headers = headers + self.files = files + self.data = data + self.json = json + self.params = params + self.auth = auth + self.cookies = cookies + + def __repr__(self): + return f"" + + def prepare(self): + """Constructs a :class:`PreparedRequest ` for transmission and returns it.""" + p = PreparedRequest() + p.prepare( + method=self.method, + url=self.url, + headers=self.headers, + files=self.files, + data=self.data, + json=self.json, + params=self.params, + auth=self.auth, + cookies=self.cookies, + hooks=self.hooks, + ) + return p + + +class PreparedRequest(RequestEncodingMixin, RequestHooksMixin): + """The fully mutable :class:`PreparedRequest ` object, + containing the exact bytes that will be sent to the server. + + Instances are generated from a :class:`Request ` object, and + should not be instantiated manually; doing so may produce undesirable + effects. + + Usage:: + + >>> import requests + >>> req = requests.Request('GET', 'https://httpbin.org/get') + >>> r = req.prepare() + >>> r + + + >>> s = requests.Session() + >>> s.send(r) + + """ + + def __init__(self): + #: HTTP verb to send to the server. + self.method = None + #: HTTP URL to send the request to. + self.url = None + #: dictionary of HTTP headers. + self.headers = None + # The `CookieJar` used to create the Cookie header will be stored here + # after prepare_cookies is called + self._cookies = None + #: request body to send to the server. + self.body = None + #: dictionary of callback hooks, for internal usage. + self.hooks = default_hooks() + #: integer denoting starting position of a readable file-like body. + self._body_position = None + + def prepare( + self, + method=None, + url=None, + headers=None, + files=None, + data=None, + params=None, + auth=None, + cookies=None, + hooks=None, + json=None, + ): + """Prepares the entire request with the given parameters.""" + + self.prepare_method(method) + self.prepare_url(url, params) + self.prepare_headers(headers) + self.prepare_cookies(cookies) + self.prepare_body(data, files, json) + self.prepare_auth(auth, url) + + # Note that prepare_auth must be last to enable authentication schemes + # such as OAuth to work on a fully prepared request. + + # This MUST go after prepare_auth. Authenticators could add a hook + self.prepare_hooks(hooks) + + def __repr__(self): + return f"" + + def copy(self): + p = PreparedRequest() + p.method = self.method + p.url = self.url + p.headers = self.headers.copy() if self.headers is not None else None + p._cookies = _copy_cookie_jar(self._cookies) + p.body = self.body + p.hooks = self.hooks + p._body_position = self._body_position + return p + + def prepare_method(self, method): + """Prepares the given HTTP method.""" + self.method = method + if self.method is not None: + self.method = to_native_string(self.method.upper()) + + @staticmethod + def _get_idna_encoded_host(host): + import idna + + try: + host = idna.encode(host, uts46=True).decode("utf-8") + except idna.IDNAError: + raise UnicodeError + return host + + def prepare_url(self, url, params): + """Prepares the given HTTP URL.""" + #: Accept objects that have string representations. + #: We're unable to blindly call unicode/str functions + #: as this will include the bytestring indicator (b'') + #: on python 3.x. + #: https://github.com/psf/requests/pull/2238 + if isinstance(url, bytes): + url = url.decode("utf8") + else: + url = str(url) + + # Remove leading whitespaces from url + url = url.lstrip() + + # Don't do any URL preparation for non-HTTP schemes like `mailto`, + # `data` etc to work around exceptions from `url_parse`, which + # handles RFC 3986 only. + if ":" in url and not url.lower().startswith("http"): + self.url = url + return + + # Support for unicode domain names and paths. + try: + scheme, auth, host, port, path, query, fragment = parse_url(url) + except LocationParseError as e: + raise InvalidURL(*e.args) + + if not scheme: + raise MissingSchema( + f"Invalid URL {url!r}: No scheme supplied. " + f"Perhaps you meant https://{url}?" + ) + + if not host: + raise InvalidURL(f"Invalid URL {url!r}: No host supplied") + + # In general, we want to try IDNA encoding the hostname if the string contains + # non-ASCII characters. This allows users to automatically get the correct IDNA + # behaviour. For strings containing only ASCII characters, we need to also verify + # it doesn't start with a wildcard (*), before allowing the unencoded hostname. + if not unicode_is_ascii(host): + try: + host = self._get_idna_encoded_host(host) + except UnicodeError: + raise InvalidURL("URL has an invalid label.") + elif host.startswith(("*", ".")): + raise InvalidURL("URL has an invalid label.") + + # Carefully reconstruct the network location + netloc = auth or "" + if netloc: + netloc += "@" + netloc += host + if port: + netloc += f":{port}" + + # Bare domains aren't valid URLs. + if not path: + path = "/" + + if isinstance(params, (str, bytes)): + params = to_native_string(params) + + enc_params = self._encode_params(params) + if enc_params: + if query: + query = f"{query}&{enc_params}" + else: + query = enc_params + + url = requote_uri(urlunparse([scheme, netloc, path, None, query, fragment])) + self.url = url + + def prepare_headers(self, headers): + """Prepares the given HTTP headers.""" + + self.headers = CaseInsensitiveDict() + if headers: + for header in headers.items(): + # Raise exception on invalid header value. + check_header_validity(header) + name, value = header + self.headers[to_native_string(name)] = value + + def prepare_body(self, data, files, json=None): + """Prepares the given HTTP body data.""" + + # Check if file, fo, generator, iterator. + # If not, run through normal process. + + # Nottin' on you. + body = None + content_type = None + + if not data and json is not None: + # urllib3 requires a bytes-like body. Python 2's json.dumps + # provides this natively, but Python 3 gives a Unicode string. + content_type = "application/json" + + try: + body = complexjson.dumps(json, allow_nan=False) + except ValueError as ve: + raise InvalidJSONError(ve, request=self) + + if not isinstance(body, bytes): + body = body.encode("utf-8") + + is_stream = all( + [ + hasattr(data, "__iter__"), + not isinstance(data, (basestring, list, tuple, Mapping)), + ] + ) + + if is_stream: + try: + length = super_len(data) + except (TypeError, AttributeError, UnsupportedOperation): + length = None + + body = data + + if getattr(body, "tell", None) is not None: + # Record the current file position before reading. + # This will allow us to rewind a file in the event + # of a redirect. + try: + self._body_position = body.tell() + except OSError: + # This differentiates from None, allowing us to catch + # a failed `tell()` later when trying to rewind the body + self._body_position = object() + + if files: + raise NotImplementedError( + "Streamed bodies and files are mutually exclusive." + ) + + if length: + self.headers["Content-Length"] = builtin_str(length) + else: + self.headers["Transfer-Encoding"] = "chunked" + else: + # Multi-part file uploads. + if files: + (body, content_type) = self._encode_files(files, data) + else: + if data: + body = self._encode_params(data) + if isinstance(data, basestring) or hasattr(data, "read"): + content_type = None + else: + content_type = "application/x-www-form-urlencoded" + + self.prepare_content_length(body) + + # Add content-type if it wasn't explicitly provided. + if content_type and ("content-type" not in self.headers): + self.headers["Content-Type"] = content_type + + self.body = body + + def prepare_content_length(self, body): + """Prepare Content-Length header based on request method and body""" + if body is not None: + length = super_len(body) + if length: + # If length exists, set it. Otherwise, we fallback + # to Transfer-Encoding: chunked. + self.headers["Content-Length"] = builtin_str(length) + elif ( + self.method not in ("GET", "HEAD") + and self.headers.get("Content-Length") is None + ): + # Set Content-Length to 0 for methods that can have a body + # but don't provide one. (i.e. not GET or HEAD) + self.headers["Content-Length"] = "0" + + def prepare_auth(self, auth, url=""): + """Prepares the given HTTP auth data.""" + + # If no Auth is explicitly provided, extract it from the URL first. + if auth is None: + url_auth = get_auth_from_url(self.url) + auth = url_auth if any(url_auth) else None + + if auth: + if isinstance(auth, tuple) and len(auth) == 2: + # special-case basic HTTP auth + auth = HTTPBasicAuth(*auth) + + # Allow auth to make its changes. + r = auth(self) + + # Update self to reflect the auth changes. + self.__dict__.update(r.__dict__) + + # Recompute Content-Length + self.prepare_content_length(self.body) + + def prepare_cookies(self, cookies): + """Prepares the given HTTP cookie data. + + This function eventually generates a ``Cookie`` header from the + given cookies using cookielib. Due to cookielib's design, the header + will not be regenerated if it already exists, meaning this function + can only be called once for the life of the + :class:`PreparedRequest ` object. Any subsequent calls + to ``prepare_cookies`` will have no actual effect, unless the "Cookie" + header is removed beforehand. + """ + if isinstance(cookies, cookielib.CookieJar): + self._cookies = cookies + else: + self._cookies = cookiejar_from_dict(cookies) + + cookie_header = get_cookie_header(self._cookies, self) + if cookie_header is not None: + self.headers["Cookie"] = cookie_header + + def prepare_hooks(self, hooks): + """Prepares the given hooks.""" + # hooks can be passed as None to the prepare method and to this + # method. To prevent iterating over None, simply use an empty list + # if hooks is False-y + hooks = hooks or [] + for event in hooks: + self.register_hook(event, hooks[event]) + + +class Response: + """The :class:`Response ` object, which contains a + server's response to an HTTP request. + """ + + __attrs__ = [ + "_content", + "status_code", + "headers", + "url", + "history", + "encoding", + "reason", + "cookies", + "elapsed", + "request", + ] + + def __init__(self): + self._content = False + self._content_consumed = False + self._next = None + + #: Integer Code of responded HTTP Status, e.g. 404 or 200. + self.status_code = None + + #: Case-insensitive Dictionary of Response Headers. + #: For example, ``headers['content-encoding']`` will return the + #: value of a ``'Content-Encoding'`` response header. + self.headers = CaseInsensitiveDict() + + #: File-like object representation of response (for advanced usage). + #: Use of ``raw`` requires that ``stream=True`` be set on the request. + #: This requirement does not apply for use internally to Requests. + self.raw = None + + #: Final URL location of Response. + self.url = None + + #: Encoding to decode with when accessing r.text. + self.encoding = None + + #: A list of :class:`Response ` objects from + #: the history of the Request. Any redirect responses will end + #: up here. The list is sorted from the oldest to the most recent request. + self.history = [] + + #: Textual reason of responded HTTP Status, e.g. "Not Found" or "OK". + self.reason = None + + #: A CookieJar of Cookies the server sent back. + self.cookies = cookiejar_from_dict({}) + + #: The amount of time elapsed between sending the request + #: and the arrival of the response (as a timedelta). + #: This property specifically measures the time taken between sending + #: the first byte of the request and finishing parsing the headers. It + #: is therefore unaffected by consuming the response content or the + #: value of the ``stream`` keyword argument. + self.elapsed = datetime.timedelta(0) + + #: The :class:`PreparedRequest ` object to which this + #: is a response. + self.request = None + + def __enter__(self): + return self + + def __exit__(self, *args): + self.close() + + def __getstate__(self): + # Consume everything; accessing the content attribute makes + # sure the content has been fully read. + if not self._content_consumed: + self.content + + return {attr: getattr(self, attr, None) for attr in self.__attrs__} + + def __setstate__(self, state): + for name, value in state.items(): + setattr(self, name, value) + + # pickled objects do not have .raw + setattr(self, "_content_consumed", True) + setattr(self, "raw", None) + + def __repr__(self): + return f"" + + def __bool__(self): + """Returns True if :attr:`status_code` is less than 400. + + This attribute checks if the status code of the response is between + 400 and 600 to see if there was a client error or a server error. If + the status code, is between 200 and 400, this will return True. This + is **not** a check to see if the response code is ``200 OK``. + """ + return self.ok + + def __nonzero__(self): + """Returns True if :attr:`status_code` is less than 400. + + This attribute checks if the status code of the response is between + 400 and 600 to see if there was a client error or a server error. If + the status code, is between 200 and 400, this will return True. This + is **not** a check to see if the response code is ``200 OK``. + """ + return self.ok + + def __iter__(self): + """Allows you to use a response as an iterator.""" + return self.iter_content(128) + + @property + def ok(self): + """Returns True if :attr:`status_code` is less than 400, False if not. + + This attribute checks if the status code of the response is between + 400 and 600 to see if there was a client error or a server error. If + the status code is between 200 and 400, this will return True. This + is **not** a check to see if the response code is ``200 OK``. + """ + try: + self.raise_for_status() + except HTTPError: + return False + return True + + @property + def is_redirect(self): + """True if this Response is a well-formed HTTP redirect that could have + been processed automatically (by :meth:`Session.resolve_redirects`). + """ + return "location" in self.headers and self.status_code in REDIRECT_STATI + + @property + def is_permanent_redirect(self): + """True if this Response one of the permanent versions of redirect.""" + return "location" in self.headers and self.status_code in ( + codes.moved_permanently, + codes.permanent_redirect, + ) + + @property + def next(self): + """Returns a PreparedRequest for the next request in a redirect chain, if there is one.""" + return self._next + + @property + def apparent_encoding(self): + """The apparent encoding, provided by the charset_normalizer or chardet libraries.""" + if chardet is not None: + return chardet.detect(self.content)["encoding"] + else: + # If no character detection library is available, we'll fall back + # to a standard Python utf-8 str. + return "utf-8" + + def iter_content(self, chunk_size=1, decode_unicode=False): + """Iterates over the response data. When stream=True is set on the + request, this avoids reading the content at once into memory for + large responses. The chunk size is the number of bytes it should + read into memory. This is not necessarily the length of each item + returned as decoding can take place. + + chunk_size must be of type int or None. A value of None will + function differently depending on the value of `stream`. + stream=True will read data as it arrives in whatever size the + chunks are received. If stream=False, data is returned as + a single chunk. + + If decode_unicode is True, content will be decoded using the best + available encoding based on the response. + """ + + def generate(): + # Special case for urllib3. + if hasattr(self.raw, "stream"): + try: + yield from self.raw.stream(chunk_size, decode_content=True) + except ProtocolError as e: + raise ChunkedEncodingError(e) + except DecodeError as e: + raise ContentDecodingError(e) + except ReadTimeoutError as e: + raise ConnectionError(e) + except SSLError as e: + raise RequestsSSLError(e) + else: + # Standard file-like object. + while True: + chunk = self.raw.read(chunk_size) + if not chunk: + break + yield chunk + + self._content_consumed = True + + if self._content_consumed and isinstance(self._content, bool): + raise StreamConsumedError() + elif chunk_size is not None and not isinstance(chunk_size, int): + raise TypeError( + f"chunk_size must be an int, it is instead a {type(chunk_size)}." + ) + # simulate reading small chunks of the content + reused_chunks = iter_slices(self._content, chunk_size) + + stream_chunks = generate() + + chunks = reused_chunks if self._content_consumed else stream_chunks + + if decode_unicode: + chunks = stream_decode_response_unicode(chunks, self) + + return chunks + + def iter_lines( + self, chunk_size=ITER_CHUNK_SIZE, decode_unicode=False, delimiter=None + ): + """Iterates over the response data, one line at a time. When + stream=True is set on the request, this avoids reading the + content at once into memory for large responses. + + .. note:: This method is not reentrant safe. + """ + + pending = None + + for chunk in self.iter_content( + chunk_size=chunk_size, decode_unicode=decode_unicode + ): + if pending is not None: + chunk = pending + chunk + + if delimiter: + lines = chunk.split(delimiter) + else: + lines = chunk.splitlines() + + if lines and lines[-1] and chunk and lines[-1][-1] == chunk[-1]: + pending = lines.pop() + else: + pending = None + + yield from lines + + if pending is not None: + yield pending + + @property + def content(self): + """Content of the response, in bytes.""" + + if self._content is False: + # Read the contents. + if self._content_consumed: + raise RuntimeError("The content for this response was already consumed") + + if self.status_code == 0 or self.raw is None: + self._content = None + else: + self._content = b"".join(self.iter_content(CONTENT_CHUNK_SIZE)) or b"" + + self._content_consumed = True + # don't need to release the connection; that's been handled by urllib3 + # since we exhausted the data. + return self._content + + @property + def text(self): + """Content of the response, in unicode. + + If Response.encoding is None, encoding will be guessed using + ``charset_normalizer`` or ``chardet``. + + The encoding of the response content is determined based solely on HTTP + headers, following RFC 2616 to the letter. If you can take advantage of + non-HTTP knowledge to make a better guess at the encoding, you should + set ``r.encoding`` appropriately before accessing this property. + """ + + # Try charset from content-type + content = None + encoding = self.encoding + + if not self.content: + return "" + + # Fallback to auto-detected encoding. + if self.encoding is None: + encoding = self.apparent_encoding + + # Decode unicode from given encoding. + try: + content = str(self.content, encoding, errors="replace") + except (LookupError, TypeError): + # A LookupError is raised if the encoding was not found which could + # indicate a misspelling or similar mistake. + # + # A TypeError can be raised if encoding is None + # + # So we try blindly encoding. + content = str(self.content, errors="replace") + + return content + + def json(self, **kwargs): + r"""Returns the json-encoded content of a response, if any. + + :param \*\*kwargs: Optional arguments that ``json.loads`` takes. + :raises requests.exceptions.JSONDecodeError: If the response body does not + contain valid json. + """ + + if not self.encoding and self.content and len(self.content) > 3: + # No encoding set. JSON RFC 4627 section 3 states we should expect + # UTF-8, -16 or -32. Detect which one to use; If the detection or + # decoding fails, fall back to `self.text` (using charset_normalizer to make + # a best guess). + encoding = guess_json_utf(self.content) + if encoding is not None: + try: + return complexjson.loads(self.content.decode(encoding), **kwargs) + except UnicodeDecodeError: + # Wrong UTF codec detected; usually because it's not UTF-8 + # but some other 8-bit codec. This is an RFC violation, + # and the server didn't bother to tell us what codec *was* + # used. + pass + except JSONDecodeError as e: + raise RequestsJSONDecodeError(e.msg, e.doc, e.pos) + + try: + return complexjson.loads(self.text, **kwargs) + except JSONDecodeError as e: + # Catch JSON-related errors and raise as requests.JSONDecodeError + # This aliases json.JSONDecodeError and simplejson.JSONDecodeError + raise RequestsJSONDecodeError(e.msg, e.doc, e.pos) + + @property + def links(self): + """Returns the parsed header links of the response, if any.""" + + header = self.headers.get("link") + + resolved_links = {} + + if header: + links = parse_header_links(header) + + for link in links: + key = link.get("rel") or link.get("url") + resolved_links[key] = link + + return resolved_links + + def raise_for_status(self): + """Raises :class:`HTTPError`, if one occurred.""" + + http_error_msg = "" + if isinstance(self.reason, bytes): + # We attempt to decode utf-8 first because some servers + # choose to localize their reason strings. If the string + # isn't utf-8, we fall back to iso-8859-1 for all other + # encodings. (See PR #3538) + try: + reason = self.reason.decode("utf-8") + except UnicodeDecodeError: + reason = self.reason.decode("iso-8859-1") + else: + reason = self.reason + + if 400 <= self.status_code < 500: + http_error_msg = ( + f"{self.status_code} Client Error: {reason} for url: {self.url}" + ) + + elif 500 <= self.status_code < 600: + http_error_msg = ( + f"{self.status_code} Server Error: {reason} for url: {self.url}" + ) + + if http_error_msg: + raise HTTPError(http_error_msg, response=self) + + def close(self): + """Releases the connection back to the pool. Once this method has been + called the underlying ``raw`` object must not be accessed again. + + *Note: Should not normally need to be called explicitly.* + """ + if not self._content_consumed: + self.raw.close() + + release_conn = getattr(self.raw, "release_conn", None) + if release_conn is not None: + release_conn() diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/packages.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/packages.py new file mode 100644 index 0000000..5ab3d8e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/packages.py @@ -0,0 +1,23 @@ +import sys + +from .compat import chardet + +# This code exists for backwards compatibility reasons. +# I don't like it either. Just look the other way. :) + +for package in ("urllib3", "idna"): + locals()[package] = __import__(package) + # This traversal is apparently necessary such that the identities are + # preserved (requests.packages.urllib3.* is urllib3.*) + for mod in list(sys.modules): + if mod == package or mod.startswith(f"{package}."): + sys.modules[f"requests.packages.{mod}"] = sys.modules[mod] + +if chardet is not None: + target = chardet.__name__ + for mod in list(sys.modules): + if mod == target or mod.startswith(f"{target}."): + imported_mod = sys.modules[mod] + sys.modules[f"requests.packages.{mod}"] = imported_mod + mod = mod.replace(target, "chardet") + sys.modules[f"requests.packages.{mod}"] = imported_mod diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/sessions.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/sessions.py new file mode 100644 index 0000000..b387bc3 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/sessions.py @@ -0,0 +1,831 @@ +""" +requests.sessions +~~~~~~~~~~~~~~~~~ + +This module provides a Session object to manage and persist settings across +requests (cookies, auth, proxies). +""" +import os +import sys +import time +from collections import OrderedDict +from datetime import timedelta + +from ._internal_utils import to_native_string +from .adapters import HTTPAdapter +from .auth import _basic_auth_str +from .compat import Mapping, cookielib, urljoin, urlparse +from .cookies import ( + RequestsCookieJar, + cookiejar_from_dict, + extract_cookies_to_jar, + merge_cookies, +) +from .exceptions import ( + ChunkedEncodingError, + ContentDecodingError, + InvalidSchema, + TooManyRedirects, +) +from .hooks import default_hooks, dispatch_hook + +# formerly defined here, reexposed here for backward compatibility +from .models import ( # noqa: F401 + DEFAULT_REDIRECT_LIMIT, + REDIRECT_STATI, + PreparedRequest, + Request, +) +from .status_codes import codes +from .structures import CaseInsensitiveDict +from .utils import ( # noqa: F401 + DEFAULT_PORTS, + default_headers, + get_auth_from_url, + get_environ_proxies, + get_netrc_auth, + requote_uri, + resolve_proxies, + rewind_body, + should_bypass_proxies, + to_key_val_list, +) + +# Preferred clock, based on which one is more accurate on a given system. +if sys.platform == "win32": + preferred_clock = time.perf_counter +else: + preferred_clock = time.time + + +def merge_setting(request_setting, session_setting, dict_class=OrderedDict): + """Determines appropriate setting for a given request, taking into account + the explicit setting on that request, and the setting in the session. If a + setting is a dictionary, they will be merged together using `dict_class` + """ + + if session_setting is None: + return request_setting + + if request_setting is None: + return session_setting + + # Bypass if not a dictionary (e.g. verify) + if not ( + isinstance(session_setting, Mapping) and isinstance(request_setting, Mapping) + ): + return request_setting + + merged_setting = dict_class(to_key_val_list(session_setting)) + merged_setting.update(to_key_val_list(request_setting)) + + # Remove keys that are set to None. Extract keys first to avoid altering + # the dictionary during iteration. + none_keys = [k for (k, v) in merged_setting.items() if v is None] + for key in none_keys: + del merged_setting[key] + + return merged_setting + + +def merge_hooks(request_hooks, session_hooks, dict_class=OrderedDict): + """Properly merges both requests and session hooks. + + This is necessary because when request_hooks == {'response': []}, the + merge breaks Session hooks entirely. + """ + if session_hooks is None or session_hooks.get("response") == []: + return request_hooks + + if request_hooks is None or request_hooks.get("response") == []: + return session_hooks + + return merge_setting(request_hooks, session_hooks, dict_class) + + +class SessionRedirectMixin: + def get_redirect_target(self, resp): + """Receives a Response. Returns a redirect URI or ``None``""" + # Due to the nature of how requests processes redirects this method will + # be called at least once upon the original response and at least twice + # on each subsequent redirect response (if any). + # If a custom mixin is used to handle this logic, it may be advantageous + # to cache the redirect location onto the response object as a private + # attribute. + if resp.is_redirect: + location = resp.headers["location"] + # Currently the underlying http module on py3 decode headers + # in latin1, but empirical evidence suggests that latin1 is very + # rarely used with non-ASCII characters in HTTP headers. + # It is more likely to get UTF8 header rather than latin1. + # This causes incorrect handling of UTF8 encoded location headers. + # To solve this, we re-encode the location in latin1. + location = location.encode("latin1") + return to_native_string(location, "utf8") + return None + + def should_strip_auth(self, old_url, new_url): + """Decide whether Authorization header should be removed when redirecting""" + old_parsed = urlparse(old_url) + new_parsed = urlparse(new_url) + if old_parsed.hostname != new_parsed.hostname: + return True + # Special case: allow http -> https redirect when using the standard + # ports. This isn't specified by RFC 7235, but is kept to avoid + # breaking backwards compatibility with older versions of requests + # that allowed any redirects on the same host. + if ( + old_parsed.scheme == "http" + and old_parsed.port in (80, None) + and new_parsed.scheme == "https" + and new_parsed.port in (443, None) + ): + return False + + # Handle default port usage corresponding to scheme. + changed_port = old_parsed.port != new_parsed.port + changed_scheme = old_parsed.scheme != new_parsed.scheme + default_port = (DEFAULT_PORTS.get(old_parsed.scheme, None), None) + if ( + not changed_scheme + and old_parsed.port in default_port + and new_parsed.port in default_port + ): + return False + + # Standard case: root URI must match + return changed_port or changed_scheme + + def resolve_redirects( + self, + resp, + req, + stream=False, + timeout=None, + verify=True, + cert=None, + proxies=None, + yield_requests=False, + **adapter_kwargs, + ): + """Receives a Response. Returns a generator of Responses or Requests.""" + + hist = [] # keep track of history + + url = self.get_redirect_target(resp) + previous_fragment = urlparse(req.url).fragment + while url: + prepared_request = req.copy() + + # Update history and keep track of redirects. + # resp.history must ignore the original request in this loop + hist.append(resp) + resp.history = hist[1:] + + try: + resp.content # Consume socket so it can be released + except (ChunkedEncodingError, ContentDecodingError, RuntimeError): + resp.raw.read(decode_content=False) + + if len(resp.history) >= self.max_redirects: + raise TooManyRedirects( + f"Exceeded {self.max_redirects} redirects.", response=resp + ) + + # Release the connection back into the pool. + resp.close() + + # Handle redirection without scheme (see: RFC 1808 Section 4) + if url.startswith("//"): + parsed_rurl = urlparse(resp.url) + url = ":".join([to_native_string(parsed_rurl.scheme), url]) + + # Normalize url case and attach previous fragment if needed (RFC 7231 7.1.2) + parsed = urlparse(url) + if parsed.fragment == "" and previous_fragment: + parsed = parsed._replace(fragment=previous_fragment) + elif parsed.fragment: + previous_fragment = parsed.fragment + url = parsed.geturl() + + # Facilitate relative 'location' headers, as allowed by RFC 7231. + # (e.g. '/path/to/resource' instead of 'http://domain.tld/path/to/resource') + # Compliant with RFC3986, we percent encode the url. + if not parsed.netloc: + url = urljoin(resp.url, requote_uri(url)) + else: + url = requote_uri(url) + + prepared_request.url = to_native_string(url) + + self.rebuild_method(prepared_request, resp) + + # https://github.com/psf/requests/issues/1084 + if resp.status_code not in ( + codes.temporary_redirect, + codes.permanent_redirect, + ): + # https://github.com/psf/requests/issues/3490 + purged_headers = ("Content-Length", "Content-Type", "Transfer-Encoding") + for header in purged_headers: + prepared_request.headers.pop(header, None) + prepared_request.body = None + + headers = prepared_request.headers + headers.pop("Cookie", None) + + # Extract any cookies sent on the response to the cookiejar + # in the new request. Because we've mutated our copied prepared + # request, use the old one that we haven't yet touched. + extract_cookies_to_jar(prepared_request._cookies, req, resp.raw) + merge_cookies(prepared_request._cookies, self.cookies) + prepared_request.prepare_cookies(prepared_request._cookies) + + # Rebuild auth and proxy information. + proxies = self.rebuild_proxies(prepared_request, proxies) + self.rebuild_auth(prepared_request, resp) + + # A failed tell() sets `_body_position` to `object()`. This non-None + # value ensures `rewindable` will be True, allowing us to raise an + # UnrewindableBodyError, instead of hanging the connection. + rewindable = prepared_request._body_position is not None and ( + "Content-Length" in headers or "Transfer-Encoding" in headers + ) + + # Attempt to rewind consumed file-like object. + if rewindable: + rewind_body(prepared_request) + + # Override the original request. + req = prepared_request + + if yield_requests: + yield req + else: + resp = self.send( + req, + stream=stream, + timeout=timeout, + verify=verify, + cert=cert, + proxies=proxies, + allow_redirects=False, + **adapter_kwargs, + ) + + extract_cookies_to_jar(self.cookies, prepared_request, resp.raw) + + # extract redirect url, if any, for the next loop + url = self.get_redirect_target(resp) + yield resp + + def rebuild_auth(self, prepared_request, response): + """When being redirected we may want to strip authentication from the + request to avoid leaking credentials. This method intelligently removes + and reapplies authentication where possible to avoid credential loss. + """ + headers = prepared_request.headers + url = prepared_request.url + + if "Authorization" in headers and self.should_strip_auth( + response.request.url, url + ): + # If we get redirected to a new host, we should strip out any + # authentication headers. + del headers["Authorization"] + + # .netrc might have more auth for us on our new host. + new_auth = get_netrc_auth(url) if self.trust_env else None + if new_auth is not None: + prepared_request.prepare_auth(new_auth) + + def rebuild_proxies(self, prepared_request, proxies): + """This method re-evaluates the proxy configuration by considering the + environment variables. If we are redirected to a URL covered by + NO_PROXY, we strip the proxy configuration. Otherwise, we set missing + proxy keys for this URL (in case they were stripped by a previous + redirect). + + This method also replaces the Proxy-Authorization header where + necessary. + + :rtype: dict + """ + headers = prepared_request.headers + scheme = urlparse(prepared_request.url).scheme + new_proxies = resolve_proxies(prepared_request, proxies, self.trust_env) + + if "Proxy-Authorization" in headers: + del headers["Proxy-Authorization"] + + try: + username, password = get_auth_from_url(new_proxies[scheme]) + except KeyError: + username, password = None, None + + # urllib3 handles proxy authorization for us in the standard adapter. + # Avoid appending this to TLS tunneled requests where it may be leaked. + if not scheme.startswith("https") and username and password: + headers["Proxy-Authorization"] = _basic_auth_str(username, password) + + return new_proxies + + def rebuild_method(self, prepared_request, response): + """When being redirected we may want to change the method of the request + based on certain specs or browser behavior. + """ + method = prepared_request.method + + # https://tools.ietf.org/html/rfc7231#section-6.4.4 + if response.status_code == codes.see_other and method != "HEAD": + method = "GET" + + # Do what the browsers do, despite standards... + # First, turn 302s into GETs. + if response.status_code == codes.found and method != "HEAD": + method = "GET" + + # Second, if a POST is responded to with a 301, turn it into a GET. + # This bizarre behaviour is explained in Issue 1704. + if response.status_code == codes.moved and method == "POST": + method = "GET" + + prepared_request.method = method + + +class Session(SessionRedirectMixin): + """A Requests session. + + Provides cookie persistence, connection-pooling, and configuration. + + Basic Usage:: + + >>> import requests + >>> s = requests.Session() + >>> s.get('https://httpbin.org/get') + + + Or as a context manager:: + + >>> with requests.Session() as s: + ... s.get('https://httpbin.org/get') + + """ + + __attrs__ = [ + "headers", + "cookies", + "auth", + "proxies", + "hooks", + "params", + "verify", + "cert", + "adapters", + "stream", + "trust_env", + "max_redirects", + ] + + def __init__(self): + #: A case-insensitive dictionary of headers to be sent on each + #: :class:`Request ` sent from this + #: :class:`Session `. + self.headers = default_headers() + + #: Default Authentication tuple or object to attach to + #: :class:`Request `. + self.auth = None + + #: Dictionary mapping protocol or protocol and host to the URL of the proxy + #: (e.g. {'http': 'foo.bar:3128', 'http://host.name': 'foo.bar:4012'}) to + #: be used on each :class:`Request `. + self.proxies = {} + + #: Event-handling hooks. + self.hooks = default_hooks() + + #: Dictionary of querystring data to attach to each + #: :class:`Request `. The dictionary values may be lists for + #: representing multivalued query parameters. + self.params = {} + + #: Stream response content default. + self.stream = False + + #: SSL Verification default. + #: Defaults to `True`, requiring requests to verify the TLS certificate at the + #: remote end. + #: If verify is set to `False`, requests will accept any TLS certificate + #: presented by the server, and will ignore hostname mismatches and/or + #: expired certificates, which will make your application vulnerable to + #: man-in-the-middle (MitM) attacks. + #: Only set this to `False` for testing. + self.verify = True + + #: SSL client certificate default, if String, path to ssl client + #: cert file (.pem). If Tuple, ('cert', 'key') pair. + self.cert = None + + #: Maximum number of redirects allowed. If the request exceeds this + #: limit, a :class:`TooManyRedirects` exception is raised. + #: This defaults to requests.models.DEFAULT_REDIRECT_LIMIT, which is + #: 30. + self.max_redirects = DEFAULT_REDIRECT_LIMIT + + #: Trust environment settings for proxy configuration, default + #: authentication and similar. + self.trust_env = True + + #: A CookieJar containing all currently outstanding cookies set on this + #: session. By default it is a + #: :class:`RequestsCookieJar `, but + #: may be any other ``cookielib.CookieJar`` compatible object. + self.cookies = cookiejar_from_dict({}) + + # Default connection adapters. + self.adapters = OrderedDict() + self.mount("https://", HTTPAdapter()) + self.mount("http://", HTTPAdapter()) + + def __enter__(self): + return self + + def __exit__(self, *args): + self.close() + + def prepare_request(self, request): + """Constructs a :class:`PreparedRequest ` for + transmission and returns it. The :class:`PreparedRequest` has settings + merged from the :class:`Request ` instance and those of the + :class:`Session`. + + :param request: :class:`Request` instance to prepare with this + session's settings. + :rtype: requests.PreparedRequest + """ + cookies = request.cookies or {} + + # Bootstrap CookieJar. + if not isinstance(cookies, cookielib.CookieJar): + cookies = cookiejar_from_dict(cookies) + + # Merge with session cookies + merged_cookies = merge_cookies( + merge_cookies(RequestsCookieJar(), self.cookies), cookies + ) + + # Set environment's basic authentication if not explicitly set. + auth = request.auth + if self.trust_env and not auth and not self.auth: + auth = get_netrc_auth(request.url) + + p = PreparedRequest() + p.prepare( + method=request.method.upper(), + url=request.url, + files=request.files, + data=request.data, + json=request.json, + headers=merge_setting( + request.headers, self.headers, dict_class=CaseInsensitiveDict + ), + params=merge_setting(request.params, self.params), + auth=merge_setting(auth, self.auth), + cookies=merged_cookies, + hooks=merge_hooks(request.hooks, self.hooks), + ) + return p + + def request( + self, + method, + url, + params=None, + data=None, + headers=None, + cookies=None, + files=None, + auth=None, + timeout=None, + allow_redirects=True, + proxies=None, + hooks=None, + stream=None, + verify=None, + cert=None, + json=None, + ): + """Constructs a :class:`Request `, prepares it and sends it. + Returns :class:`Response ` object. + + :param method: method for the new :class:`Request` object. + :param url: URL for the new :class:`Request` object. + :param params: (optional) Dictionary or bytes to be sent in the query + string for the :class:`Request`. + :param data: (optional) Dictionary, list of tuples, bytes, or file-like + object to send in the body of the :class:`Request`. + :param json: (optional) json to send in the body of the + :class:`Request`. + :param headers: (optional) Dictionary of HTTP Headers to send with the + :class:`Request`. + :param cookies: (optional) Dict or CookieJar object to send with the + :class:`Request`. + :param files: (optional) Dictionary of ``'filename': file-like-objects`` + for multipart encoding upload. + :param auth: (optional) Auth tuple or callable to enable + Basic/Digest/Custom HTTP Auth. + :param timeout: (optional) How long to wait for the server to send + data before giving up, as a float, or a :ref:`(connect timeout, + read timeout) ` tuple. + :type timeout: float or tuple + :param allow_redirects: (optional) Set to True by default. + :type allow_redirects: bool + :param proxies: (optional) Dictionary mapping protocol or protocol and + hostname to the URL of the proxy. + :param hooks: (optional) Dictionary mapping hook name to one event or + list of events, event must be callable. + :param stream: (optional) whether to immediately download the response + content. Defaults to ``False``. + :param verify: (optional) Either a boolean, in which case it controls whether we verify + the server's TLS certificate, or a string, in which case it must be a path + to a CA bundle to use. Defaults to ``True``. When set to + ``False``, requests will accept any TLS certificate presented by + the server, and will ignore hostname mismatches and/or expired + certificates, which will make your application vulnerable to + man-in-the-middle (MitM) attacks. Setting verify to ``False`` + may be useful during local development or testing. + :param cert: (optional) if String, path to ssl client cert file (.pem). + If Tuple, ('cert', 'key') pair. + :rtype: requests.Response + """ + # Create the Request. + req = Request( + method=method.upper(), + url=url, + headers=headers, + files=files, + data=data or {}, + json=json, + params=params or {}, + auth=auth, + cookies=cookies, + hooks=hooks, + ) + prep = self.prepare_request(req) + + proxies = proxies or {} + + settings = self.merge_environment_settings( + prep.url, proxies, stream, verify, cert + ) + + # Send the request. + send_kwargs = { + "timeout": timeout, + "allow_redirects": allow_redirects, + } + send_kwargs.update(settings) + resp = self.send(prep, **send_kwargs) + + return resp + + def get(self, url, **kwargs): + r"""Sends a GET request. Returns :class:`Response` object. + + :param url: URL for the new :class:`Request` object. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :rtype: requests.Response + """ + + kwargs.setdefault("allow_redirects", True) + return self.request("GET", url, **kwargs) + + def options(self, url, **kwargs): + r"""Sends a OPTIONS request. Returns :class:`Response` object. + + :param url: URL for the new :class:`Request` object. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :rtype: requests.Response + """ + + kwargs.setdefault("allow_redirects", True) + return self.request("OPTIONS", url, **kwargs) + + def head(self, url, **kwargs): + r"""Sends a HEAD request. Returns :class:`Response` object. + + :param url: URL for the new :class:`Request` object. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :rtype: requests.Response + """ + + kwargs.setdefault("allow_redirects", False) + return self.request("HEAD", url, **kwargs) + + def post(self, url, data=None, json=None, **kwargs): + r"""Sends a POST request. Returns :class:`Response` object. + + :param url: URL for the new :class:`Request` object. + :param data: (optional) Dictionary, list of tuples, bytes, or file-like + object to send in the body of the :class:`Request`. + :param json: (optional) json to send in the body of the :class:`Request`. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :rtype: requests.Response + """ + + return self.request("POST", url, data=data, json=json, **kwargs) + + def put(self, url, data=None, **kwargs): + r"""Sends a PUT request. Returns :class:`Response` object. + + :param url: URL for the new :class:`Request` object. + :param data: (optional) Dictionary, list of tuples, bytes, or file-like + object to send in the body of the :class:`Request`. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :rtype: requests.Response + """ + + return self.request("PUT", url, data=data, **kwargs) + + def patch(self, url, data=None, **kwargs): + r"""Sends a PATCH request. Returns :class:`Response` object. + + :param url: URL for the new :class:`Request` object. + :param data: (optional) Dictionary, list of tuples, bytes, or file-like + object to send in the body of the :class:`Request`. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :rtype: requests.Response + """ + + return self.request("PATCH", url, data=data, **kwargs) + + def delete(self, url, **kwargs): + r"""Sends a DELETE request. Returns :class:`Response` object. + + :param url: URL for the new :class:`Request` object. + :param \*\*kwargs: Optional arguments that ``request`` takes. + :rtype: requests.Response + """ + + return self.request("DELETE", url, **kwargs) + + def send(self, request, **kwargs): + """Send a given PreparedRequest. + + :rtype: requests.Response + """ + # Set defaults that the hooks can utilize to ensure they always have + # the correct parameters to reproduce the previous request. + kwargs.setdefault("stream", self.stream) + kwargs.setdefault("verify", self.verify) + kwargs.setdefault("cert", self.cert) + if "proxies" not in kwargs: + kwargs["proxies"] = resolve_proxies(request, self.proxies, self.trust_env) + + # It's possible that users might accidentally send a Request object. + # Guard against that specific failure case. + if isinstance(request, Request): + raise ValueError("You can only send PreparedRequests.") + + # Set up variables needed for resolve_redirects and dispatching of hooks + allow_redirects = kwargs.pop("allow_redirects", True) + stream = kwargs.get("stream") + hooks = request.hooks + + # Get the appropriate adapter to use + adapter = self.get_adapter(url=request.url) + + # Start time (approximately) of the request + start = preferred_clock() + + # Send the request + r = adapter.send(request, **kwargs) + + # Total elapsed time of the request (approximately) + elapsed = preferred_clock() - start + r.elapsed = timedelta(seconds=elapsed) + + # Response manipulation hooks + r = dispatch_hook("response", hooks, r, **kwargs) + + # Persist cookies + if r.history: + # If the hooks create history then we want those cookies too + for resp in r.history: + extract_cookies_to_jar(self.cookies, resp.request, resp.raw) + + extract_cookies_to_jar(self.cookies, request, r.raw) + + # Resolve redirects if allowed. + if allow_redirects: + # Redirect resolving generator. + gen = self.resolve_redirects(r, request, **kwargs) + history = [resp for resp in gen] + else: + history = [] + + # Shuffle things around if there's history. + if history: + # Insert the first (original) request at the start + history.insert(0, r) + # Get the last request made + r = history.pop() + r.history = history + + # If redirects aren't being followed, store the response on the Request for Response.next(). + if not allow_redirects: + try: + r._next = next( + self.resolve_redirects(r, request, yield_requests=True, **kwargs) + ) + except StopIteration: + pass + + if not stream: + r.content + + return r + + def merge_environment_settings(self, url, proxies, stream, verify, cert): + """ + Check the environment and merge it with some settings. + + :rtype: dict + """ + # Gather clues from the surrounding environment. + if self.trust_env: + # Set environment's proxies. + no_proxy = proxies.get("no_proxy") if proxies is not None else None + env_proxies = get_environ_proxies(url, no_proxy=no_proxy) + for k, v in env_proxies.items(): + proxies.setdefault(k, v) + + # Look for requests environment configuration + # and be compatible with cURL. + if verify is True or verify is None: + verify = ( + os.environ.get("REQUESTS_CA_BUNDLE") + or os.environ.get("CURL_CA_BUNDLE") + or verify + ) + + # Merge all the kwargs. + proxies = merge_setting(proxies, self.proxies) + stream = merge_setting(stream, self.stream) + verify = merge_setting(verify, self.verify) + cert = merge_setting(cert, self.cert) + + return {"proxies": proxies, "stream": stream, "verify": verify, "cert": cert} + + def get_adapter(self, url): + """ + Returns the appropriate connection adapter for the given URL. + + :rtype: requests.adapters.BaseAdapter + """ + for prefix, adapter in self.adapters.items(): + if url.lower().startswith(prefix.lower()): + return adapter + + # Nothing matches :-/ + raise InvalidSchema(f"No connection adapters were found for {url!r}") + + def close(self): + """Closes all adapters and as such the session""" + for v in self.adapters.values(): + v.close() + + def mount(self, prefix, adapter): + """Registers a connection adapter to a prefix. + + Adapters are sorted in descending order by prefix length. + """ + self.adapters[prefix] = adapter + keys_to_move = [k for k in self.adapters if len(k) < len(prefix)] + + for key in keys_to_move: + self.adapters[key] = self.adapters.pop(key) + + def __getstate__(self): + state = {attr: getattr(self, attr, None) for attr in self.__attrs__} + return state + + def __setstate__(self, state): + for attr, value in state.items(): + setattr(self, attr, value) + + +def session(): + """ + Returns a :class:`Session` for context-management. + + .. deprecated:: 1.0.0 + + This method has been deprecated since version 1.0.0 and is only kept for + backwards compatibility. New code should use :class:`~requests.sessions.Session` + to create a session. This may be removed at a future date. + + :rtype: Session + """ + return Session() diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/status_codes.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/status_codes.py new file mode 100644 index 0000000..c7945a2 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/status_codes.py @@ -0,0 +1,128 @@ +r""" +The ``codes`` object defines a mapping from common names for HTTP statuses +to their numerical codes, accessible either as attributes or as dictionary +items. + +Example:: + + >>> import requests + >>> requests.codes['temporary_redirect'] + 307 + >>> requests.codes.teapot + 418 + >>> requests.codes['\o/'] + 200 + +Some codes have multiple names, and both upper- and lower-case versions of +the names are allowed. For example, ``codes.ok``, ``codes.OK``, and +``codes.okay`` all correspond to the HTTP status code 200. +""" + +from .structures import LookupDict + +_codes = { + # Informational. + 100: ("continue",), + 101: ("switching_protocols",), + 102: ("processing", "early-hints"), + 103: ("checkpoint",), + 122: ("uri_too_long", "request_uri_too_long"), + 200: ("ok", "okay", "all_ok", "all_okay", "all_good", "\\o/", "✓"), + 201: ("created",), + 202: ("accepted",), + 203: ("non_authoritative_info", "non_authoritative_information"), + 204: ("no_content",), + 205: ("reset_content", "reset"), + 206: ("partial_content", "partial"), + 207: ("multi_status", "multiple_status", "multi_stati", "multiple_stati"), + 208: ("already_reported",), + 226: ("im_used",), + # Redirection. + 300: ("multiple_choices",), + 301: ("moved_permanently", "moved", "\\o-"), + 302: ("found",), + 303: ("see_other", "other"), + 304: ("not_modified",), + 305: ("use_proxy",), + 306: ("switch_proxy",), + 307: ("temporary_redirect", "temporary_moved", "temporary"), + 308: ( + "permanent_redirect", + "resume_incomplete", + "resume", + ), # "resume" and "resume_incomplete" to be removed in 3.0 + # Client Error. + 400: ("bad_request", "bad"), + 401: ("unauthorized",), + 402: ("payment_required", "payment"), + 403: ("forbidden",), + 404: ("not_found", "-o-"), + 405: ("method_not_allowed", "not_allowed"), + 406: ("not_acceptable",), + 407: ("proxy_authentication_required", "proxy_auth", "proxy_authentication"), + 408: ("request_timeout", "timeout"), + 409: ("conflict",), + 410: ("gone",), + 411: ("length_required",), + 412: ("precondition_failed", "precondition"), + 413: ("request_entity_too_large", "content_too_large"), + 414: ("request_uri_too_large", "uri_too_long"), + 415: ("unsupported_media_type", "unsupported_media", "media_type"), + 416: ( + "requested_range_not_satisfiable", + "requested_range", + "range_not_satisfiable", + ), + 417: ("expectation_failed",), + 418: ("im_a_teapot", "teapot", "i_am_a_teapot"), + 421: ("misdirected_request",), + 422: ("unprocessable_entity", "unprocessable", "unprocessable_content"), + 423: ("locked",), + 424: ("failed_dependency", "dependency"), + 425: ("unordered_collection", "unordered", "too_early"), + 426: ("upgrade_required", "upgrade"), + 428: ("precondition_required", "precondition"), + 429: ("too_many_requests", "too_many"), + 431: ("header_fields_too_large", "fields_too_large"), + 444: ("no_response", "none"), + 449: ("retry_with", "retry"), + 450: ("blocked_by_windows_parental_controls", "parental_controls"), + 451: ("unavailable_for_legal_reasons", "legal_reasons"), + 499: ("client_closed_request",), + # Server Error. + 500: ("internal_server_error", "server_error", "/o\\", "✗"), + 501: ("not_implemented",), + 502: ("bad_gateway",), + 503: ("service_unavailable", "unavailable"), + 504: ("gateway_timeout",), + 505: ("http_version_not_supported", "http_version"), + 506: ("variant_also_negotiates",), + 507: ("insufficient_storage",), + 509: ("bandwidth_limit_exceeded", "bandwidth"), + 510: ("not_extended",), + 511: ("network_authentication_required", "network_auth", "network_authentication"), +} + +codes = LookupDict(name="status_codes") + + +def _init(): + for code, titles in _codes.items(): + for title in titles: + setattr(codes, title, code) + if not title.startswith(("\\", "/")): + setattr(codes, title.upper(), code) + + def doc(code): + names = ", ".join(f"``{n}``" for n in _codes[code]) + return "* %d: %s" % (code, names) + + global __doc__ + __doc__ = ( + __doc__ + "\n" + "\n".join(doc(code) for code in sorted(_codes)) + if __doc__ is not None + else None + ) + + +_init() diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/structures.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/structures.py new file mode 100644 index 0000000..188e13e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/structures.py @@ -0,0 +1,99 @@ +""" +requests.structures +~~~~~~~~~~~~~~~~~~~ + +Data structures that power Requests. +""" + +from collections import OrderedDict + +from .compat import Mapping, MutableMapping + + +class CaseInsensitiveDict(MutableMapping): + """A case-insensitive ``dict``-like object. + + Implements all methods and operations of + ``MutableMapping`` as well as dict's ``copy``. Also + provides ``lower_items``. + + All keys are expected to be strings. The structure remembers the + case of the last key to be set, and ``iter(instance)``, + ``keys()``, ``items()``, ``iterkeys()``, and ``iteritems()`` + will contain case-sensitive keys. However, querying and contains + testing is case insensitive:: + + cid = CaseInsensitiveDict() + cid['Accept'] = 'application/json' + cid['aCCEPT'] == 'application/json' # True + list(cid) == ['Accept'] # True + + For example, ``headers['content-encoding']`` will return the + value of a ``'Content-Encoding'`` response header, regardless + of how the header name was originally stored. + + If the constructor, ``.update``, or equality comparison + operations are given keys that have equal ``.lower()``s, the + behavior is undefined. + """ + + def __init__(self, data=None, **kwargs): + self._store = OrderedDict() + if data is None: + data = {} + self.update(data, **kwargs) + + def __setitem__(self, key, value): + # Use the lowercased key for lookups, but store the actual + # key alongside the value. + self._store[key.lower()] = (key, value) + + def __getitem__(self, key): + return self._store[key.lower()][1] + + def __delitem__(self, key): + del self._store[key.lower()] + + def __iter__(self): + return (casedkey for casedkey, mappedvalue in self._store.values()) + + def __len__(self): + return len(self._store) + + def lower_items(self): + """Like iteritems(), but with all lowercase keys.""" + return ((lowerkey, keyval[1]) for (lowerkey, keyval) in self._store.items()) + + def __eq__(self, other): + if isinstance(other, Mapping): + other = CaseInsensitiveDict(other) + else: + return NotImplemented + # Compare insensitively + return dict(self.lower_items()) == dict(other.lower_items()) + + # Copy is required + def copy(self): + return CaseInsensitiveDict(self._store.values()) + + def __repr__(self): + return str(dict(self.items())) + + +class LookupDict(dict): + """Dictionary lookup object.""" + + def __init__(self, name=None): + self.name = name + super().__init__() + + def __repr__(self): + return f"" + + def __getitem__(self, key): + # We allow fall-through here, so values default to None + + return self.__dict__.get(key, None) + + def get(self, key, default=None): + return self.__dict__.get(key, default) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/utils.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/utils.py new file mode 100644 index 0000000..ae6c42f --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/requests/utils.py @@ -0,0 +1,1096 @@ +""" +requests.utils +~~~~~~~~~~~~~~ + +This module provides utility functions that are used within Requests +that are also useful for external consumption. +""" + +import codecs +import contextlib +import io +import os +import re +import socket +import struct +import sys +import tempfile +import warnings +import zipfile +from collections import OrderedDict + +from urllib3.util import make_headers, parse_url + +from . import certs +from .__version__ import __version__ + +# to_native_string is unused here, but imported here for backwards compatibility +from ._internal_utils import ( # noqa: F401 + _HEADER_VALIDATORS_BYTE, + _HEADER_VALIDATORS_STR, + HEADER_VALIDATORS, + to_native_string, +) +from .compat import ( + Mapping, + basestring, + bytes, + getproxies, + getproxies_environment, + integer_types, +) +from .compat import parse_http_list as _parse_list_header +from .compat import ( + proxy_bypass, + proxy_bypass_environment, + quote, + str, + unquote, + urlparse, + urlunparse, +) +from .cookies import cookiejar_from_dict +from .exceptions import ( + FileModeWarning, + InvalidHeader, + InvalidURL, + UnrewindableBodyError, +) +from .structures import CaseInsensitiveDict + +NETRC_FILES = (".netrc", "_netrc") + +DEFAULT_CA_BUNDLE_PATH = certs.where() + +DEFAULT_PORTS = {"http": 80, "https": 443} + +# Ensure that ', ' is used to preserve previous delimiter behavior. +DEFAULT_ACCEPT_ENCODING = ", ".join( + re.split(r",\s*", make_headers(accept_encoding=True)["accept-encoding"]) +) + + +if sys.platform == "win32": + # provide a proxy_bypass version on Windows without DNS lookups + + def proxy_bypass_registry(host): + try: + import winreg + except ImportError: + return False + + try: + internetSettings = winreg.OpenKey( + winreg.HKEY_CURRENT_USER, + r"Software\Microsoft\Windows\CurrentVersion\Internet Settings", + ) + # ProxyEnable could be REG_SZ or REG_DWORD, normalizing it + proxyEnable = int(winreg.QueryValueEx(internetSettings, "ProxyEnable")[0]) + # ProxyOverride is almost always a string + proxyOverride = winreg.QueryValueEx(internetSettings, "ProxyOverride")[0] + except (OSError, ValueError): + return False + if not proxyEnable or not proxyOverride: + return False + + # make a check value list from the registry entry: replace the + # '' string by the localhost entry and the corresponding + # canonical entry. + proxyOverride = proxyOverride.split(";") + # filter out empty strings to avoid re.match return true in the following code. + proxyOverride = filter(None, proxyOverride) + # now check if we match one of the registry values. + for test in proxyOverride: + if test == "": + if "." not in host: + return True + test = test.replace(".", r"\.") # mask dots + test = test.replace("*", r".*") # change glob sequence + test = test.replace("?", r".") # change glob char + if re.match(test, host, re.I): + return True + return False + + def proxy_bypass(host): # noqa + """Return True, if the host should be bypassed. + + Checks proxy settings gathered from the environment, if specified, + or the registry. + """ + if getproxies_environment(): + return proxy_bypass_environment(host) + else: + return proxy_bypass_registry(host) + + +def dict_to_sequence(d): + """Returns an internal sequence dictionary update.""" + + if hasattr(d, "items"): + d = d.items() + + return d + + +def super_len(o): + total_length = None + current_position = 0 + + if isinstance(o, str): + o = o.encode("utf-8") + + if hasattr(o, "__len__"): + total_length = len(o) + + elif hasattr(o, "len"): + total_length = o.len + + elif hasattr(o, "fileno"): + try: + fileno = o.fileno() + except (io.UnsupportedOperation, AttributeError): + # AttributeError is a surprising exception, seeing as how we've just checked + # that `hasattr(o, 'fileno')`. It happens for objects obtained via + # `Tarfile.extractfile()`, per issue 5229. + pass + else: + total_length = os.fstat(fileno).st_size + + # Having used fstat to determine the file length, we need to + # confirm that this file was opened up in binary mode. + if "b" not in o.mode: + warnings.warn( + ( + "Requests has determined the content-length for this " + "request using the binary size of the file: however, the " + "file has been opened in text mode (i.e. without the 'b' " + "flag in the mode). This may lead to an incorrect " + "content-length. In Requests 3.0, support will be removed " + "for files in text mode." + ), + FileModeWarning, + ) + + if hasattr(o, "tell"): + try: + current_position = o.tell() + except OSError: + # This can happen in some weird situations, such as when the file + # is actually a special file descriptor like stdin. In this + # instance, we don't know what the length is, so set it to zero and + # let requests chunk it instead. + if total_length is not None: + current_position = total_length + else: + if hasattr(o, "seek") and total_length is None: + # StringIO and BytesIO have seek but no usable fileno + try: + # seek to end of file + o.seek(0, 2) + total_length = o.tell() + + # seek back to current position to support + # partially read file-like objects + o.seek(current_position or 0) + except OSError: + total_length = 0 + + if total_length is None: + total_length = 0 + + return max(0, total_length - current_position) + + +def get_netrc_auth(url, raise_errors=False): + """Returns the Requests tuple auth for a given url from netrc.""" + + netrc_file = os.environ.get("NETRC") + if netrc_file is not None: + netrc_locations = (netrc_file,) + else: + netrc_locations = (f"~/{f}" for f in NETRC_FILES) + + try: + from netrc import NetrcParseError, netrc + + netrc_path = None + + for f in netrc_locations: + try: + loc = os.path.expanduser(f) + except KeyError: + # os.path.expanduser can fail when $HOME is undefined and + # getpwuid fails. See https://bugs.python.org/issue20164 & + # https://github.com/psf/requests/issues/1846 + return + + if os.path.exists(loc): + netrc_path = loc + break + + # Abort early if there isn't one. + if netrc_path is None: + return + + ri = urlparse(url) + + # Strip port numbers from netloc. This weird `if...encode`` dance is + # used for Python 3.2, which doesn't support unicode literals. + splitstr = b":" + if isinstance(url, str): + splitstr = splitstr.decode("ascii") + host = ri.netloc.split(splitstr)[0] + + try: + _netrc = netrc(netrc_path).authenticators(host) + if _netrc: + # Return with login / password + login_i = 0 if _netrc[0] else 1 + return (_netrc[login_i], _netrc[2]) + except (NetrcParseError, OSError): + # If there was a parsing error or a permissions issue reading the file, + # we'll just skip netrc auth unless explicitly asked to raise errors. + if raise_errors: + raise + + # App Engine hackiness. + except (ImportError, AttributeError): + pass + + +def guess_filename(obj): + """Tries to guess the filename of the given object.""" + name = getattr(obj, "name", None) + if name and isinstance(name, basestring) and name[0] != "<" and name[-1] != ">": + return os.path.basename(name) + + +def extract_zipped_paths(path): + """Replace nonexistent paths that look like they refer to a member of a zip + archive with the location of an extracted copy of the target, or else + just return the provided path unchanged. + """ + if os.path.exists(path): + # this is already a valid path, no need to do anything further + return path + + # find the first valid part of the provided path and treat that as a zip archive + # assume the rest of the path is the name of a member in the archive + archive, member = os.path.split(path) + while archive and not os.path.exists(archive): + archive, prefix = os.path.split(archive) + if not prefix: + # If we don't check for an empty prefix after the split (in other words, archive remains unchanged after the split), + # we _can_ end up in an infinite loop on a rare corner case affecting a small number of users + break + member = "/".join([prefix, member]) + + if not zipfile.is_zipfile(archive): + return path + + zip_file = zipfile.ZipFile(archive) + if member not in zip_file.namelist(): + return path + + # we have a valid zip archive and a valid member of that archive + tmp = tempfile.gettempdir() + extracted_path = os.path.join(tmp, member.split("/")[-1]) + if not os.path.exists(extracted_path): + # use read + write to avoid the creating nested folders, we only want the file, avoids mkdir racing condition + with atomic_open(extracted_path) as file_handler: + file_handler.write(zip_file.read(member)) + return extracted_path + + +@contextlib.contextmanager +def atomic_open(filename): + """Write a file to the disk in an atomic fashion""" + tmp_descriptor, tmp_name = tempfile.mkstemp(dir=os.path.dirname(filename)) + try: + with os.fdopen(tmp_descriptor, "wb") as tmp_handler: + yield tmp_handler + os.replace(tmp_name, filename) + except BaseException: + os.remove(tmp_name) + raise + + +def from_key_val_list(value): + """Take an object and test to see if it can be represented as a + dictionary. Unless it can not be represented as such, return an + OrderedDict, e.g., + + :: + + >>> from_key_val_list([('key', 'val')]) + OrderedDict([('key', 'val')]) + >>> from_key_val_list('string') + Traceback (most recent call last): + ... + ValueError: cannot encode objects that are not 2-tuples + >>> from_key_val_list({'key': 'val'}) + OrderedDict([('key', 'val')]) + + :rtype: OrderedDict + """ + if value is None: + return None + + if isinstance(value, (str, bytes, bool, int)): + raise ValueError("cannot encode objects that are not 2-tuples") + + return OrderedDict(value) + + +def to_key_val_list(value): + """Take an object and test to see if it can be represented as a + dictionary. If it can be, return a list of tuples, e.g., + + :: + + >>> to_key_val_list([('key', 'val')]) + [('key', 'val')] + >>> to_key_val_list({'key': 'val'}) + [('key', 'val')] + >>> to_key_val_list('string') + Traceback (most recent call last): + ... + ValueError: cannot encode objects that are not 2-tuples + + :rtype: list + """ + if value is None: + return None + + if isinstance(value, (str, bytes, bool, int)): + raise ValueError("cannot encode objects that are not 2-tuples") + + if isinstance(value, Mapping): + value = value.items() + + return list(value) + + +# From mitsuhiko/werkzeug (used with permission). +def parse_list_header(value): + """Parse lists as described by RFC 2068 Section 2. + + In particular, parse comma-separated lists where the elements of + the list may include quoted-strings. A quoted-string could + contain a comma. A non-quoted string could have quotes in the + middle. Quotes are removed automatically after parsing. + + It basically works like :func:`parse_set_header` just that items + may appear multiple times and case sensitivity is preserved. + + The return value is a standard :class:`list`: + + >>> parse_list_header('token, "quoted value"') + ['token', 'quoted value'] + + To create a header from the :class:`list` again, use the + :func:`dump_header` function. + + :param value: a string with a list header. + :return: :class:`list` + :rtype: list + """ + result = [] + for item in _parse_list_header(value): + if item[:1] == item[-1:] == '"': + item = unquote_header_value(item[1:-1]) + result.append(item) + return result + + +# From mitsuhiko/werkzeug (used with permission). +def parse_dict_header(value): + """Parse lists of key, value pairs as described by RFC 2068 Section 2 and + convert them into a python dict: + + >>> d = parse_dict_header('foo="is a fish", bar="as well"') + >>> type(d) is dict + True + >>> sorted(d.items()) + [('bar', 'as well'), ('foo', 'is a fish')] + + If there is no value for a key it will be `None`: + + >>> parse_dict_header('key_without_value') + {'key_without_value': None} + + To create a header from the :class:`dict` again, use the + :func:`dump_header` function. + + :param value: a string with a dict header. + :return: :class:`dict` + :rtype: dict + """ + result = {} + for item in _parse_list_header(value): + if "=" not in item: + result[item] = None + continue + name, value = item.split("=", 1) + if value[:1] == value[-1:] == '"': + value = unquote_header_value(value[1:-1]) + result[name] = value + return result + + +# From mitsuhiko/werkzeug (used with permission). +def unquote_header_value(value, is_filename=False): + r"""Unquotes a header value. (Reversal of :func:`quote_header_value`). + This does not use the real unquoting but what browsers are actually + using for quoting. + + :param value: the header value to unquote. + :rtype: str + """ + if value and value[0] == value[-1] == '"': + # this is not the real unquoting, but fixing this so that the + # RFC is met will result in bugs with internet explorer and + # probably some other browsers as well. IE for example is + # uploading files with "C:\foo\bar.txt" as filename + value = value[1:-1] + + # if this is a filename and the starting characters look like + # a UNC path, then just return the value without quotes. Using the + # replace sequence below on a UNC path has the effect of turning + # the leading double slash into a single slash and then + # _fix_ie_filename() doesn't work correctly. See #458. + if not is_filename or value[:2] != "\\\\": + return value.replace("\\\\", "\\").replace('\\"', '"') + return value + + +def dict_from_cookiejar(cj): + """Returns a key/value dictionary from a CookieJar. + + :param cj: CookieJar object to extract cookies from. + :rtype: dict + """ + + cookie_dict = {cookie.name: cookie.value for cookie in cj} + return cookie_dict + + +def add_dict_to_cookiejar(cj, cookie_dict): + """Returns a CookieJar from a key/value dictionary. + + :param cj: CookieJar to insert cookies into. + :param cookie_dict: Dict of key/values to insert into CookieJar. + :rtype: CookieJar + """ + + return cookiejar_from_dict(cookie_dict, cj) + + +def get_encodings_from_content(content): + """Returns encodings from given content string. + + :param content: bytestring to extract encodings from. + """ + warnings.warn( + ( + "In requests 3.0, get_encodings_from_content will be removed. For " + "more information, please see the discussion on issue #2266. (This" + " warning should only appear once.)" + ), + DeprecationWarning, + ) + + charset_re = re.compile(r']', flags=re.I) + pragma_re = re.compile(r']', flags=re.I) + xml_re = re.compile(r'^<\?xml.*?encoding=["\']*(.+?)["\'>]') + + return ( + charset_re.findall(content) + + pragma_re.findall(content) + + xml_re.findall(content) + ) + + +def _parse_content_type_header(header): + """Returns content type and parameters from given header + + :param header: string + :return: tuple containing content type and dictionary of + parameters + """ + + tokens = header.split(";") + content_type, params = tokens[0].strip(), tokens[1:] + params_dict = {} + items_to_strip = "\"' " + + for param in params: + param = param.strip() + if param: + key, value = param, True + index_of_equals = param.find("=") + if index_of_equals != -1: + key = param[:index_of_equals].strip(items_to_strip) + value = param[index_of_equals + 1 :].strip(items_to_strip) + params_dict[key.lower()] = value + return content_type, params_dict + + +def get_encoding_from_headers(headers): + """Returns encodings from given HTTP Header Dict. + + :param headers: dictionary to extract encoding from. + :rtype: str + """ + + content_type = headers.get("content-type") + + if not content_type: + return None + + content_type, params = _parse_content_type_header(content_type) + + if "charset" in params: + return params["charset"].strip("'\"") + + if "text" in content_type: + return "ISO-8859-1" + + if "application/json" in content_type: + # Assume UTF-8 based on RFC 4627: https://www.ietf.org/rfc/rfc4627.txt since the charset was unset + return "utf-8" + + +def stream_decode_response_unicode(iterator, r): + """Stream decodes an iterator.""" + + if r.encoding is None: + yield from iterator + return + + decoder = codecs.getincrementaldecoder(r.encoding)(errors="replace") + for chunk in iterator: + rv = decoder.decode(chunk) + if rv: + yield rv + rv = decoder.decode(b"", final=True) + if rv: + yield rv + + +def iter_slices(string, slice_length): + """Iterate over slices of a string.""" + pos = 0 + if slice_length is None or slice_length <= 0: + slice_length = len(string) + while pos < len(string): + yield string[pos : pos + slice_length] + pos += slice_length + + +def get_unicode_from_response(r): + """Returns the requested content back in unicode. + + :param r: Response object to get unicode content from. + + Tried: + + 1. charset from content-type + 2. fall back and replace all unicode characters + + :rtype: str + """ + warnings.warn( + ( + "In requests 3.0, get_unicode_from_response will be removed. For " + "more information, please see the discussion on issue #2266. (This" + " warning should only appear once.)" + ), + DeprecationWarning, + ) + + tried_encodings = [] + + # Try charset from content-type + encoding = get_encoding_from_headers(r.headers) + + if encoding: + try: + return str(r.content, encoding) + except UnicodeError: + tried_encodings.append(encoding) + + # Fall back: + try: + return str(r.content, encoding, errors="replace") + except TypeError: + return r.content + + +# The unreserved URI characters (RFC 3986) +UNRESERVED_SET = frozenset( + "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz" + "0123456789-._~" +) + + +def unquote_unreserved(uri): + """Un-escape any percent-escape sequences in a URI that are unreserved + characters. This leaves all reserved, illegal and non-ASCII bytes encoded. + + :rtype: str + """ + parts = uri.split("%") + for i in range(1, len(parts)): + h = parts[i][0:2] + if len(h) == 2 and h.isalnum(): + try: + c = chr(int(h, 16)) + except ValueError: + raise InvalidURL(f"Invalid percent-escape sequence: '{h}'") + + if c in UNRESERVED_SET: + parts[i] = c + parts[i][2:] + else: + parts[i] = f"%{parts[i]}" + else: + parts[i] = f"%{parts[i]}" + return "".join(parts) + + +def requote_uri(uri): + """Re-quote the given URI. + + This function passes the given URI through an unquote/quote cycle to + ensure that it is fully and consistently quoted. + + :rtype: str + """ + safe_with_percent = "!#$%&'()*+,/:;=?@[]~" + safe_without_percent = "!#$&'()*+,/:;=?@[]~" + try: + # Unquote only the unreserved characters + # Then quote only illegal characters (do not quote reserved, + # unreserved, or '%') + return quote(unquote_unreserved(uri), safe=safe_with_percent) + except InvalidURL: + # We couldn't unquote the given URI, so let's try quoting it, but + # there may be unquoted '%'s in the URI. We need to make sure they're + # properly quoted so they do not cause issues elsewhere. + return quote(uri, safe=safe_without_percent) + + +def address_in_network(ip, net): + """This function allows you to check if an IP belongs to a network subnet + + Example: returns True if ip = 192.168.1.1 and net = 192.168.1.0/24 + returns False if ip = 192.168.1.1 and net = 192.168.100.0/24 + + :rtype: bool + """ + ipaddr = struct.unpack("=L", socket.inet_aton(ip))[0] + netaddr, bits = net.split("/") + netmask = struct.unpack("=L", socket.inet_aton(dotted_netmask(int(bits))))[0] + network = struct.unpack("=L", socket.inet_aton(netaddr))[0] & netmask + return (ipaddr & netmask) == (network & netmask) + + +def dotted_netmask(mask): + """Converts mask from /xx format to xxx.xxx.xxx.xxx + + Example: if mask is 24 function returns 255.255.255.0 + + :rtype: str + """ + bits = 0xFFFFFFFF ^ (1 << 32 - mask) - 1 + return socket.inet_ntoa(struct.pack(">I", bits)) + + +def is_ipv4_address(string_ip): + """ + :rtype: bool + """ + try: + socket.inet_aton(string_ip) + except OSError: + return False + return True + + +def is_valid_cidr(string_network): + """ + Very simple check of the cidr format in no_proxy variable. + + :rtype: bool + """ + if string_network.count("/") == 1: + try: + mask = int(string_network.split("/")[1]) + except ValueError: + return False + + if mask < 1 or mask > 32: + return False + + try: + socket.inet_aton(string_network.split("/")[0]) + except OSError: + return False + else: + return False + return True + + +@contextlib.contextmanager +def set_environ(env_name, value): + """Set the environment variable 'env_name' to 'value' + + Save previous value, yield, and then restore the previous value stored in + the environment variable 'env_name'. + + If 'value' is None, do nothing""" + value_changed = value is not None + if value_changed: + old_value = os.environ.get(env_name) + os.environ[env_name] = value + try: + yield + finally: + if value_changed: + if old_value is None: + del os.environ[env_name] + else: + os.environ[env_name] = old_value + + +def should_bypass_proxies(url, no_proxy): + """ + Returns whether we should bypass proxies or not. + + :rtype: bool + """ + + # Prioritize lowercase environment variables over uppercase + # to keep a consistent behaviour with other http projects (curl, wget). + def get_proxy(key): + return os.environ.get(key) or os.environ.get(key.upper()) + + # First check whether no_proxy is defined. If it is, check that the URL + # we're getting isn't in the no_proxy list. + no_proxy_arg = no_proxy + if no_proxy is None: + no_proxy = get_proxy("no_proxy") + parsed = urlparse(url) + + if parsed.hostname is None: + # URLs don't always have hostnames, e.g. file:/// urls. + return True + + if no_proxy: + # We need to check whether we match here. We need to see if we match + # the end of the hostname, both with and without the port. + no_proxy = (host for host in no_proxy.replace(" ", "").split(",") if host) + + if is_ipv4_address(parsed.hostname): + for proxy_ip in no_proxy: + if is_valid_cidr(proxy_ip): + if address_in_network(parsed.hostname, proxy_ip): + return True + elif parsed.hostname == proxy_ip: + # If no_proxy ip was defined in plain IP notation instead of cidr notation & + # matches the IP of the index + return True + else: + host_with_port = parsed.hostname + if parsed.port: + host_with_port += f":{parsed.port}" + + for host in no_proxy: + if parsed.hostname.endswith(host) or host_with_port.endswith(host): + # The URL does match something in no_proxy, so we don't want + # to apply the proxies on this URL. + return True + + with set_environ("no_proxy", no_proxy_arg): + # parsed.hostname can be `None` in cases such as a file URI. + try: + bypass = proxy_bypass(parsed.hostname) + except (TypeError, socket.gaierror): + bypass = False + + if bypass: + return True + + return False + + +def get_environ_proxies(url, no_proxy=None): + """ + Return a dict of environment proxies. + + :rtype: dict + """ + if should_bypass_proxies(url, no_proxy=no_proxy): + return {} + else: + return getproxies() + + +def select_proxy(url, proxies): + """Select a proxy for the url, if applicable. + + :param url: The url being for the request + :param proxies: A dictionary of schemes or schemes and hosts to proxy URLs + """ + proxies = proxies or {} + urlparts = urlparse(url) + if urlparts.hostname is None: + return proxies.get(urlparts.scheme, proxies.get("all")) + + proxy_keys = [ + urlparts.scheme + "://" + urlparts.hostname, + urlparts.scheme, + "all://" + urlparts.hostname, + "all", + ] + proxy = None + for proxy_key in proxy_keys: + if proxy_key in proxies: + proxy = proxies[proxy_key] + break + + return proxy + + +def resolve_proxies(request, proxies, trust_env=True): + """This method takes proxy information from a request and configuration + input to resolve a mapping of target proxies. This will consider settings + such as NO_PROXY to strip proxy configurations. + + :param request: Request or PreparedRequest + :param proxies: A dictionary of schemes or schemes and hosts to proxy URLs + :param trust_env: Boolean declaring whether to trust environment configs + + :rtype: dict + """ + proxies = proxies if proxies is not None else {} + url = request.url + scheme = urlparse(url).scheme + no_proxy = proxies.get("no_proxy") + new_proxies = proxies.copy() + + if trust_env and not should_bypass_proxies(url, no_proxy=no_proxy): + environ_proxies = get_environ_proxies(url, no_proxy=no_proxy) + + proxy = environ_proxies.get(scheme, environ_proxies.get("all")) + + if proxy: + new_proxies.setdefault(scheme, proxy) + return new_proxies + + +def default_user_agent(name="python-requests"): + """ + Return a string representing the default user agent. + + :rtype: str + """ + return f"{name}/{__version__}" + + +def default_headers(): + """ + :rtype: requests.structures.CaseInsensitiveDict + """ + return CaseInsensitiveDict( + { + "User-Agent": default_user_agent(), + "Accept-Encoding": DEFAULT_ACCEPT_ENCODING, + "Accept": "*/*", + "Connection": "keep-alive", + } + ) + + +def parse_header_links(value): + """Return a list of parsed link headers proxies. + + i.e. Link: ; rel=front; type="image/jpeg",; rel=back;type="image/jpeg" + + :rtype: list + """ + + links = [] + + replace_chars = " '\"" + + value = value.strip(replace_chars) + if not value: + return links + + for val in re.split(", *<", value): + try: + url, params = val.split(";", 1) + except ValueError: + url, params = val, "" + + link = {"url": url.strip("<> '\"")} + + for param in params.split(";"): + try: + key, value = param.split("=") + except ValueError: + break + + link[key.strip(replace_chars)] = value.strip(replace_chars) + + links.append(link) + + return links + + +# Null bytes; no need to recreate these on each call to guess_json_utf +_null = "\x00".encode("ascii") # encoding to ASCII for Python 3 +_null2 = _null * 2 +_null3 = _null * 3 + + +def guess_json_utf(data): + """ + :rtype: str + """ + # JSON always starts with two ASCII characters, so detection is as + # easy as counting the nulls and from their location and count + # determine the encoding. Also detect a BOM, if present. + sample = data[:4] + if sample in (codecs.BOM_UTF32_LE, codecs.BOM_UTF32_BE): + return "utf-32" # BOM included + if sample[:3] == codecs.BOM_UTF8: + return "utf-8-sig" # BOM included, MS style (discouraged) + if sample[:2] in (codecs.BOM_UTF16_LE, codecs.BOM_UTF16_BE): + return "utf-16" # BOM included + nullcount = sample.count(_null) + if nullcount == 0: + return "utf-8" + if nullcount == 2: + if sample[::2] == _null2: # 1st and 3rd are null + return "utf-16-be" + if sample[1::2] == _null2: # 2nd and 4th are null + return "utf-16-le" + # Did not detect 2 valid UTF-16 ascii-range characters + if nullcount == 3: + if sample[:3] == _null3: + return "utf-32-be" + if sample[1:] == _null3: + return "utf-32-le" + # Did not detect a valid UTF-32 ascii-range character + return None + + +def prepend_scheme_if_needed(url, new_scheme): + """Given a URL that may or may not have a scheme, prepend the given scheme. + Does not replace a present scheme with the one provided as an argument. + + :rtype: str + """ + parsed = parse_url(url) + scheme, auth, host, port, path, query, fragment = parsed + + # A defect in urlparse determines that there isn't a netloc present in some + # urls. We previously assumed parsing was overly cautious, and swapped the + # netloc and path. Due to a lack of tests on the original defect, this is + # maintained with parse_url for backwards compatibility. + netloc = parsed.netloc + if not netloc: + netloc, path = path, netloc + + if auth: + # parse_url doesn't provide the netloc with auth + # so we'll add it ourselves. + netloc = "@".join([auth, netloc]) + if scheme is None: + scheme = new_scheme + if path is None: + path = "" + + return urlunparse((scheme, netloc, path, "", query, fragment)) + + +def get_auth_from_url(url): + """Given a url with authentication components, extract them into a tuple of + username,password. + + :rtype: (str,str) + """ + parsed = urlparse(url) + + try: + auth = (unquote(parsed.username), unquote(parsed.password)) + except (AttributeError, TypeError): + auth = ("", "") + + return auth + + +def check_header_validity(header): + """Verifies that header parts don't contain leading whitespace + reserved characters, or return characters. + + :param header: tuple, in the format (name, value). + """ + name, value = header + _validate_header_part(header, name, 0) + _validate_header_part(header, value, 1) + + +def _validate_header_part(header, header_part, header_validator_index): + if isinstance(header_part, str): + validator = _HEADER_VALIDATORS_STR[header_validator_index] + elif isinstance(header_part, bytes): + validator = _HEADER_VALIDATORS_BYTE[header_validator_index] + else: + raise InvalidHeader( + f"Header part ({header_part!r}) from {header} " + f"must be of type str or bytes, not {type(header_part)}" + ) + + if not validator.match(header_part): + header_kind = "name" if header_validator_index == 0 else "value" + raise InvalidHeader( + f"Invalid leading whitespace, reserved character(s), or return " + f"character(s) in header {header_kind}: {header_part!r}" + ) + + +def urldefragauth(url): + """ + Given a url remove the fragment and the authentication part. + + :rtype: str + """ + scheme, netloc, path, params, query, fragment = urlparse(url) + + # see func:`prepend_scheme_if_needed` + if not netloc: + netloc, path = path, netloc + + netloc = netloc.rsplit("@", 1)[-1] + + return urlunparse((scheme, netloc, path, params, query, "")) + + +def rewind_body(prepared_request): + """Move file pointer back to its recorded starting position + so it can be read again on redirect. + """ + body_seek = getattr(prepared_request.body, "seek", None) + if body_seek is not None and isinstance( + prepared_request._body_position, integer_types + ): + try: + body_seek(prepared_request._body_position) + except OSError: + raise UnrewindableBodyError( + "An error occurred when rewinding request body for redirect." + ) + else: + raise UnrewindableBodyError("Unable to rewind request body for redirect.") diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/INSTALLER b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/INSTALLER new file mode 100644 index 0000000..a1b589e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/INSTALLER @@ -0,0 +1 @@ +pip diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/METADATA b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/METADATA new file mode 100644 index 0000000..baeb1dd --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/METADATA @@ -0,0 +1,154 @@ +Metadata-Version: 2.3 +Name: urllib3 +Version: 2.2.2 +Summary: HTTP library with thread-safe connection pooling, file post, and more. +Project-URL: Changelog, https://github.com/urllib3/urllib3/blob/main/CHANGES.rst +Project-URL: Documentation, https://urllib3.readthedocs.io +Project-URL: Code, https://github.com/urllib3/urllib3 +Project-URL: Issue tracker, https://github.com/urllib3/urllib3/issues +Author-email: Andrey Petrov +Maintainer-email: Seth Michael Larson , Quentin Pradet , Illia Volochii +License-File: LICENSE.txt +Keywords: filepost,http,httplib,https,pooling,ssl,threadsafe,urllib +Classifier: Environment :: Web Environment +Classifier: Intended Audience :: Developers +Classifier: License :: OSI Approved :: MIT License +Classifier: Operating System :: OS Independent +Classifier: Programming Language :: Python +Classifier: Programming Language :: Python :: 3 +Classifier: Programming Language :: Python :: 3 :: Only +Classifier: Programming Language :: Python :: 3.8 +Classifier: Programming Language :: Python :: 3.9 +Classifier: Programming Language :: Python :: 3.10 +Classifier: Programming Language :: Python :: 3.11 +Classifier: Programming Language :: Python :: 3.12 +Classifier: Programming Language :: Python :: Implementation :: CPython +Classifier: Programming Language :: Python :: Implementation :: PyPy +Classifier: Topic :: Internet :: WWW/HTTP +Classifier: Topic :: Software Development :: Libraries +Requires-Python: >=3.8 +Provides-Extra: brotli +Requires-Dist: brotli>=1.0.9; (platform_python_implementation == 'CPython') and extra == 'brotli' +Requires-Dist: brotlicffi>=0.8.0; (platform_python_implementation != 'CPython') and extra == 'brotli' +Provides-Extra: h2 +Requires-Dist: h2<5,>=4; extra == 'h2' +Provides-Extra: socks +Requires-Dist: pysocks!=1.5.7,<2.0,>=1.5.6; extra == 'socks' +Provides-Extra: zstd +Requires-Dist: zstandard>=0.18.0; extra == 'zstd' +Description-Content-Type: text/markdown + +

+ +![urllib3](https://github.com/urllib3/urllib3/raw/main/docs/_static/banner_github.svg) + +

+ +

+ PyPI Version + Python Versions + Join our Discord + Coverage Status + Build Status on GitHub + Documentation Status
+ OpenSSF Scorecard + SLSA 3 + CII Best Practices +

+ +urllib3 is a powerful, *user-friendly* HTTP client for Python. Much of the +Python ecosystem already uses urllib3 and you should too. +urllib3 brings many critical features that are missing from the Python +standard libraries: + +- Thread safety. +- Connection pooling. +- Client-side SSL/TLS verification. +- File uploads with multipart encoding. +- Helpers for retrying requests and dealing with HTTP redirects. +- Support for gzip, deflate, brotli, and zstd encoding. +- Proxy support for HTTP and SOCKS. +- 100% test coverage. + +urllib3 is powerful and easy to use: + +```python3 +>>> import urllib3 +>>> resp = urllib3.request("GET", "http://httpbin.org/robots.txt") +>>> resp.status +200 +>>> resp.data +b"User-agent: *\nDisallow: /deny\n" +``` + +## Installing + +urllib3 can be installed with [pip](https://pip.pypa.io): + +```bash +$ python -m pip install urllib3 +``` + +Alternatively, you can grab the latest source code from [GitHub](https://github.com/urllib3/urllib3): + +```bash +$ git clone https://github.com/urllib3/urllib3.git +$ cd urllib3 +$ pip install . +``` + + +## Documentation + +urllib3 has usage and reference documentation at [urllib3.readthedocs.io](https://urllib3.readthedocs.io). + + +## Community + +urllib3 has a [community Discord channel](https://discord.gg/urllib3) for asking questions and +collaborating with other contributors. Drop by and say hello 👋 + + +## Contributing + +urllib3 happily accepts contributions. Please see our +[contributing documentation](https://urllib3.readthedocs.io/en/latest/contributing.html) +for some tips on getting started. + + +## Security Disclosures + +To report a security vulnerability, please use the +[Tidelift security contact](https://tidelift.com/security). +Tidelift will coordinate the fix and disclosure with maintainers. + + +## Maintainers + +- [@sethmlarson](https://github.com/sethmlarson) (Seth M. Larson) +- [@pquentin](https://github.com/pquentin) (Quentin Pradet) +- [@illia-v](https://github.com/illia-v) (Illia Volochii) +- [@theacodes](https://github.com/theacodes) (Thea Flowers) +- [@haikuginger](https://github.com/haikuginger) (Jess Shapiro) +- [@lukasa](https://github.com/lukasa) (Cory Benfield) +- [@sigmavirus24](https://github.com/sigmavirus24) (Ian Stapleton Cordasco) +- [@shazow](https://github.com/shazow) (Andrey Petrov) + +👋 + + +## Sponsorship + +If your company benefits from this library, please consider [sponsoring its +development](https://urllib3.readthedocs.io/en/latest/sponsors.html). + + +## For Enterprise + +Professional support for urllib3 is available as part of the [Tidelift +Subscription][1]. Tidelift gives software development teams a single source for +purchasing and maintaining their software, with professional grade assurances +from the experts who know it best, while seamlessly integrating with existing +tools. + +[1]: https://tidelift.com/subscription/pkg/pypi-urllib3?utm_source=pypi-urllib3&utm_medium=referral&utm_campaign=readme diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/RECORD b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/RECORD new file mode 100644 index 0000000..7c9ac85 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/RECORD @@ -0,0 +1,75 @@ +urllib3-2.2.2.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4 +urllib3-2.2.2.dist-info/METADATA,sha256=1lFmEu2KSrvTuzjDf_UQxhN3hm5dHoUoUe8iX0XpK20,6434 +urllib3-2.2.2.dist-info/RECORD,, +urllib3-2.2.2.dist-info/WHEEL,sha256=zEMcRr9Kr03x1ozGwg5v9NQBKn3kndp6LSoSlVg-jhU,87 +urllib3-2.2.2.dist-info/licenses/LICENSE.txt,sha256=Ew46ZNX91dCWp1JpRjSn2d8oRGnehuVzIQAmgEHj1oY,1093 +urllib3/__init__.py,sha256=JMo1tg1nIV1AeJ2vENC_Txfl0e5h6Gzl9DGVk1rWRbo,6979 +urllib3/__pycache__/__init__.cpython-312.pyc,, +urllib3/__pycache__/_base_connection.cpython-312.pyc,, +urllib3/__pycache__/_collections.cpython-312.pyc,, +urllib3/__pycache__/_request_methods.cpython-312.pyc,, +urllib3/__pycache__/_version.cpython-312.pyc,, +urllib3/__pycache__/connection.cpython-312.pyc,, +urllib3/__pycache__/connectionpool.cpython-312.pyc,, +urllib3/__pycache__/exceptions.cpython-312.pyc,, +urllib3/__pycache__/fields.cpython-312.pyc,, +urllib3/__pycache__/filepost.cpython-312.pyc,, +urllib3/__pycache__/http2.cpython-312.pyc,, +urllib3/__pycache__/poolmanager.cpython-312.pyc,, +urllib3/__pycache__/response.cpython-312.pyc,, +urllib3/_base_connection.py,sha256=tH0ZlOxWKika-S9NW-MuIlI_PLFQUUmSnoE_9MeywkM,5652 +urllib3/_collections.py,sha256=aGhh9zCYce3o-5FW9DPSUay6O9LjHx8z6T7wDtdhrkY,17370 +urllib3/_request_methods.py,sha256=ucEpHQyQf06b9o1RxKLkCpzGH0ct-v7X2xGpU6rmmlo,9984 +urllib3/_version.py,sha256=NcS90vVEriRXqG3ygXh7bjsUTZrTaLODQB3cjBtxkAw,98 +urllib3/connection.py,sha256=jSJmWOwEfzghV-P9F5dU4opSt6TFG6g6Y23JAaN2Bxg,34762 +urllib3/connectionpool.py,sha256=5fPIHypPwlbKBASMs6bESTEJVEGlsj9FOY9_GGU2GpM,43393 +urllib3/contrib/__init__.py,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0 +urllib3/contrib/__pycache__/__init__.cpython-312.pyc,, +urllib3/contrib/__pycache__/pyopenssl.cpython-312.pyc,, +urllib3/contrib/__pycache__/socks.cpython-312.pyc,, +urllib3/contrib/emscripten/__init__.py,sha256=u6KNgzjlFZbuAAXa_ybCR7gQ71VJESnF-IIdDA73brw,733 +urllib3/contrib/emscripten/__pycache__/__init__.cpython-312.pyc,, +urllib3/contrib/emscripten/__pycache__/connection.cpython-312.pyc,, +urllib3/contrib/emscripten/__pycache__/fetch.cpython-312.pyc,, +urllib3/contrib/emscripten/__pycache__/request.cpython-312.pyc,, +urllib3/contrib/emscripten/__pycache__/response.cpython-312.pyc,, +urllib3/contrib/emscripten/connection.py,sha256=kaBe2tWt7Yy9vNUFRBV7CSyDnfhCYILGxju9KTZj8Sw,8755 +urllib3/contrib/emscripten/emscripten_fetch_worker.js,sha256=CDfYF_9CDobtx2lGidyJ1zjDEvwNT5F-dchmVWXDh0E,3655 +urllib3/contrib/emscripten/fetch.py,sha256=ymwJlHBBuw6WTpKgPHpdmmrNBxlsr75HqoD4Rn27YXk,14131 +urllib3/contrib/emscripten/request.py,sha256=mL28szy1KvE3NJhWor5jNmarp8gwplDU-7gwGZY5g0Q,566 +urllib3/contrib/emscripten/response.py,sha256=wEYWPHCL-JsgCtpCpfnWGYA1-DcjDGpFGqWCXZLwbHY,10017 +urllib3/contrib/pyopenssl.py,sha256=X31eCYGwB09EkAHX8RhDKC0X0Ki7d0cCVWoMJZUM5bQ,19161 +urllib3/contrib/socks.py,sha256=-iardc61GypsJzD6W6yuRS7KVCyfowcQrl_719H7lIM,7549 +urllib3/exceptions.py,sha256=RDaiudtR7rqbVKTKpLSgZBBtwaIqV7eZtervZV_mZag,9393 +urllib3/fields.py,sha256=8vi0PeRo_pE5chPmJA07LZtMkVls4UrBS1k2xM506jM,10843 +urllib3/filepost.py,sha256=-9qJT11cNGjO9dqnI20-oErZuTvNaM18xZZPCjZSbOE,2395 +urllib3/http2.py,sha256=ZfXCqoeKqMoC2JOn9ajMFwNgdyqJozj-6oBZNAUcqd0,7517 +urllib3/poolmanager.py,sha256=2_L2AjVDgoQ0qBmYbX9u9QqyU1u5J37zQbtv_-ueZQA,22913 +urllib3/py.typed,sha256=UaCuPFa3H8UAakbt-5G8SPacldTOGvJv18pPjUJ5gDY,93 +urllib3/response.py,sha256=NS0rqwRmtwWtC_6XDqgDJN_uo-jEmBVzx0V6KCsHlwg,44801 +urllib3/util/__init__.py,sha256=-qeS0QceivazvBEKDNFCAI-6ACcdDOE4TMvo7SLNlAQ,1001 +urllib3/util/__pycache__/__init__.cpython-312.pyc,, +urllib3/util/__pycache__/connection.cpython-312.pyc,, +urllib3/util/__pycache__/proxy.cpython-312.pyc,, +urllib3/util/__pycache__/request.cpython-312.pyc,, +urllib3/util/__pycache__/response.cpython-312.pyc,, +urllib3/util/__pycache__/retry.cpython-312.pyc,, +urllib3/util/__pycache__/ssl_.cpython-312.pyc,, +urllib3/util/__pycache__/ssl_match_hostname.cpython-312.pyc,, +urllib3/util/__pycache__/ssltransport.cpython-312.pyc,, +urllib3/util/__pycache__/timeout.cpython-312.pyc,, +urllib3/util/__pycache__/url.cpython-312.pyc,, +urllib3/util/__pycache__/util.cpython-312.pyc,, +urllib3/util/__pycache__/wait.cpython-312.pyc,, +urllib3/util/connection.py,sha256=QeUUEuNmhznpuKNPL-B0IVOkMdMCu8oJX62OC0Vpzug,4462 +urllib3/util/proxy.py,sha256=seP8-Q5B6bB0dMtwPj-YcZZQ30vHuLqRu-tI0JZ2fzs,1148 +urllib3/util/request.py,sha256=QIZWYzQ6Y4MpJsD_kssVEIrWNu69ioUMuE6fjd4qhPM,8069 +urllib3/util/response.py,sha256=vQE639uoEhj1vpjEdxu5lNIhJCSUZkd7pqllUI0BZOA,3374 +urllib3/util/retry.py,sha256=bj-2YUqblxLlv8THg5fxww-DM54XCbjgZXIQ71XioCY,18459 +urllib3/util/ssl_.py,sha256=DevjBk-8GNMgZjHzgCHHaxmWlXb-dKjcgymNd3ZT-ew,19107 +urllib3/util/ssl_match_hostname.py,sha256=gaWqixoYtQ_GKO8fcRGFj3VXeMoqyxQQuUTPgWeiL_M,5812 +urllib3/util/ssltransport.py,sha256=HHvjU0i-PjPThvNYQ8R1SEsseY0x07tPfVntiXg72n0,8990 +urllib3/util/timeout.py,sha256=4eT1FVeZZU7h7mYD1Jq2OXNe4fxekdNvhoWUkZusRpA,10346 +urllib3/util/url.py,sha256=wHORhp80RAXyTlAIkTqLFzSrkU7J34ZDxX-tN65MBZk,15213 +urllib3/util/util.py,sha256=j3lbZK1jPyiwD34T8IgJzdWEZVT-4E-0vYIJi9UjeNA,1146 +urllib3/util/wait.py,sha256=_ph8IrUR3sqPqi0OopQgJUlH4wzkGeM5CiyA7XGGtmI,4423 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/WHEEL b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/WHEEL new file mode 100644 index 0000000..516596c --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/WHEEL @@ -0,0 +1,4 @@ +Wheel-Version: 1.0 +Generator: hatchling 1.24.2 +Root-Is-Purelib: true +Tag: py3-none-any diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/licenses/LICENSE.txt b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/licenses/LICENSE.txt new file mode 100644 index 0000000..e6183d0 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3-2.2.2.dist-info/licenses/LICENSE.txt @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2008-2020 Andrey Petrov and contributors. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__init__.py new file mode 100644 index 0000000..3fe782c --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__init__.py @@ -0,0 +1,211 @@ +""" +Python HTTP library with thread-safe connection pooling, file post support, user friendly, and more +""" + +from __future__ import annotations + +# Set default logging handler to avoid "No handler found" warnings. +import logging +import sys +import typing +import warnings +from logging import NullHandler + +from . import exceptions +from ._base_connection import _TYPE_BODY +from ._collections import HTTPHeaderDict +from ._version import __version__ +from .connectionpool import HTTPConnectionPool, HTTPSConnectionPool, connection_from_url +from .filepost import _TYPE_FIELDS, encode_multipart_formdata +from .poolmanager import PoolManager, ProxyManager, proxy_from_url +from .response import BaseHTTPResponse, HTTPResponse +from .util.request import make_headers +from .util.retry import Retry +from .util.timeout import Timeout + +# Ensure that Python is compiled with OpenSSL 1.1.1+ +# If the 'ssl' module isn't available at all that's +# fine, we only care if the module is available. +try: + import ssl +except ImportError: + pass +else: + if not ssl.OPENSSL_VERSION.startswith("OpenSSL "): # Defensive: + warnings.warn( + "urllib3 v2 only supports OpenSSL 1.1.1+, currently " + f"the 'ssl' module is compiled with {ssl.OPENSSL_VERSION!r}. " + "See: https://github.com/urllib3/urllib3/issues/3020", + exceptions.NotOpenSSLWarning, + ) + elif ssl.OPENSSL_VERSION_INFO < (1, 1, 1): # Defensive: + raise ImportError( + "urllib3 v2 only supports OpenSSL 1.1.1+, currently " + f"the 'ssl' module is compiled with {ssl.OPENSSL_VERSION!r}. " + "See: https://github.com/urllib3/urllib3/issues/2168" + ) + +__author__ = "Andrey Petrov (andrey.petrov@shazow.net)" +__license__ = "MIT" +__version__ = __version__ + +__all__ = ( + "HTTPConnectionPool", + "HTTPHeaderDict", + "HTTPSConnectionPool", + "PoolManager", + "ProxyManager", + "HTTPResponse", + "Retry", + "Timeout", + "add_stderr_logger", + "connection_from_url", + "disable_warnings", + "encode_multipart_formdata", + "make_headers", + "proxy_from_url", + "request", + "BaseHTTPResponse", +) + +logging.getLogger(__name__).addHandler(NullHandler()) + + +def add_stderr_logger( + level: int = logging.DEBUG, +) -> logging.StreamHandler[typing.TextIO]: + """ + Helper for quickly adding a StreamHandler to the logger. Useful for + debugging. + + Returns the handler after adding it. + """ + # This method needs to be in this __init__.py to get the __name__ correct + # even if urllib3 is vendored within another package. + logger = logging.getLogger(__name__) + handler = logging.StreamHandler() + handler.setFormatter(logging.Formatter("%(asctime)s %(levelname)s %(message)s")) + logger.addHandler(handler) + logger.setLevel(level) + logger.debug("Added a stderr logging handler to logger: %s", __name__) + return handler + + +# ... Clean up. +del NullHandler + + +# All warning filters *must* be appended unless you're really certain that they +# shouldn't be: otherwise, it's very hard for users to use most Python +# mechanisms to silence them. +# SecurityWarning's always go off by default. +warnings.simplefilter("always", exceptions.SecurityWarning, append=True) +# InsecurePlatformWarning's don't vary between requests, so we keep it default. +warnings.simplefilter("default", exceptions.InsecurePlatformWarning, append=True) + + +def disable_warnings(category: type[Warning] = exceptions.HTTPWarning) -> None: + """ + Helper for quickly disabling all urllib3 warnings. + """ + warnings.simplefilter("ignore", category) + + +_DEFAULT_POOL = PoolManager() + + +def request( + method: str, + url: str, + *, + body: _TYPE_BODY | None = None, + fields: _TYPE_FIELDS | None = None, + headers: typing.Mapping[str, str] | None = None, + preload_content: bool | None = True, + decode_content: bool | None = True, + redirect: bool | None = True, + retries: Retry | bool | int | None = None, + timeout: Timeout | float | int | None = 3, + json: typing.Any | None = None, +) -> BaseHTTPResponse: + """ + A convenience, top-level request method. It uses a module-global ``PoolManager`` instance. + Therefore, its side effects could be shared across dependencies relying on it. + To avoid side effects create a new ``PoolManager`` instance and use it instead. + The method does not accept low-level ``**urlopen_kw`` keyword arguments. + + :param method: + HTTP request method (such as GET, POST, PUT, etc.) + + :param url: + The URL to perform the request on. + + :param body: + Data to send in the request body, either :class:`str`, :class:`bytes`, + an iterable of :class:`str`/:class:`bytes`, or a file-like object. + + :param fields: + Data to encode and send in the request body. + + :param headers: + Dictionary of custom headers to send, such as User-Agent, + If-None-Match, etc. + + :param bool preload_content: + If True, the response's body will be preloaded into memory. + + :param bool decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + + :param redirect: + If True, automatically handle redirects (status codes 301, 302, + 303, 307, 308). Each redirect counts as a retry. Disabling retries + will disable redirect, too. + + :param retries: + Configure the number of retries to allow before raising a + :class:`~urllib3.exceptions.MaxRetryError` exception. + + If ``None`` (default) will retry 3 times, see ``Retry.DEFAULT``. Pass a + :class:`~urllib3.util.retry.Retry` object for fine-grained control + over different types of retries. + Pass an integer number to retry connection errors that many times, + but no other types of errors. Pass zero to never retry. + + If ``False``, then retries are disabled and any exception is raised + immediately. Also, instead of raising a MaxRetryError on redirects, + the redirect response will be returned. + + :type retries: :class:`~urllib3.util.retry.Retry`, False, or an int. + + :param timeout: + If specified, overrides the default timeout for this one + request. It may be a float (in seconds) or an instance of + :class:`urllib3.util.Timeout`. + + :param json: + Data to encode and send as JSON with UTF-encoded in the request body. + The ``"Content-Type"`` header will be set to ``"application/json"`` + unless specified otherwise. + """ + + return _DEFAULT_POOL.request( + method, + url, + body=body, + fields=fields, + headers=headers, + preload_content=preload_content, + decode_content=decode_content, + redirect=redirect, + retries=retries, + timeout=timeout, + json=json, + ) + + +if sys.platform == "emscripten": + from .contrib.emscripten import inject_into_urllib3 # noqa: 401 + + inject_into_urllib3() diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..fdcb16d10becc27cc9e42871e47bb0d6ffb90de4 GIT binary patch literal 7277 zcmbVQ?Qa`LdY>gJitn;4%a;5)@~h}blwaa=qVv7jk!&llCDoGKglRynxI>BZE|)jE zv`kegl*6I90tK3)A5x$>AVt6Q;QJ$5plA!UAEJu`@isM*w&;g^W9mDg$fy3E*GOndgzC}uE&6`7$K5mU1w z#fV1zs2MFr)iYL%sb^2IM?K@kIG!;xYV{U-F}KHvn+YpfOsambnX=NwwCX3!jFl~B zRX=IwtiEEO>Zi=08Y~W42a5;QIAb2NhKfVhaB?=!hIQXEnJedbB)RPmI?lD;ITi>Jluwbw)8yU(?| z-G10J`X6h4-x-TA5nr1PzjU9*{%@!Eml0#&XHk({oA1sIdygZ2Ph+(+SbZ;i-+dYf z9$=0EXNX6RUb3 z2g7ilMwFJjbHZLlOG2;E>}g~8Cq2bWZ}loIRl@Jxr*RmXSnZC(o^j+CM<2uQ=%=w4 zu0Dph|N#aBga&Hd)i#>oexuwf2SamxIzb**?!Nq8;fL1WEmGkOXZKFwrQV{fuQ`S*49 zDEcN_*Yf8!L~6e2uG%$zdvS4|o7H8h%O+p1x~tq>l|nbh9lauW*{;<@*{xz?-L}nY zZDovCs;0omakotR0wiKx^iSNATrS)3Pc6FlT%+h$a zVVbuw%@p!W3Ie=KiAQBoS5s(IT6}YUx^!c1>P?Jt#N};pCFE4K>=K1i>7kGg2$o9u zsJEXcyw+iM9=v)3^lst#mtBcU6=_?ghBWgLFXL}_b7uO^)PgrGYGvCHC97e&)w(X- zQpJ{*p}RV^N)z$BdQD#u(#yk?Lyznx+M-U`q=?_F{ zRmtXH+;dO3vWZUbV$~9M!`(>C)kSS#;SS%p4`yMi%lzRbZr99aXaI+YQ!W4Cb7gO9-!OuC4c@7pa8n9f|fmN+KjA;1w-ndfW3qnltRoAUMlM@pw@Pfv20kbB8 z4Li@O<1~abarwff3;C$*f#tf*|AWq@i{E)=WAu8>kfO=wA-MgJkHRf5EY#KTht8_L zVXqfz!p(cpyEBXVeUfsDOi+`irjMF^)C^EFNXsjFH3u6z$m%-hRN`&bPGybk(e& zabw{qgt~XMT`S_@*X}b6-ghFKk+o#^ec0QzI!LVH7kV06xKH@h*rv9Y-95+eZ$|da zAPqkE+hluYkXoMm8IfJ`byCh|WP#&5+@z21NshY}i;`}Nfc*Q!s{tMzeLm*8W3!?ERtaYar5BPQw!-aCO?DphM$w^S|HnbfZ z`tZ=s@cHfG^B=!-?~~z$C$Ys=EVUCG+>Q;tzw#t@9HaN<-kp1Y`bq3C_3ylU=i~k# z{Qc0A*z2wI{;k<(*o}E{-CWn3&LUtguGax?hSzI|iVnQp6K)hhD%>uh^S_0gp}}c8 zj@XRA4X?e(4SfVqo@kmpgw+raeCP4v)s-5u*evoxBK!nvR;{`zkOW~(@SiB_u2`{U z(;+P25=oiK;jnptjzho#4JTMnb|*Hx9UK0O(T{F_8XK2+eE5>g`SYX~Tegj+7q3)> zX*e*ppAfvhx)i3Z8ztl|7l`iV454yUI8I1mR3&mWp_YpjjK$>d$Q)j5&9Q6c5Sa*1 z2n&=#Z=eH(qV<1k#Kv>KO`ykSWHY)M+w9qlZ}x5`Hj|sFUucgBcJV``NA&kVR%!V< z6$=kV4Mjj%j3J`yTo7>`-9?1X&L>vb1#m zJbcaud!+~K5cPp*uG?m5(}&@+#LIertMh zjL*+4P7<9i7O!MKYOicplER5F9la>H?LiwCnpeT<s=Iu$~M`%X1DV zoujA&q#+oB)rf~`4K}g_O7iAj!PG8$0p(jZQ3NS_S@2>|@)xMR)rQNcaSaMAaMQ8n zxd5QXm9`Oi=K=-oPkZjrL0=RT1G6uV}cDxnGnuihq(yaxYVnTN=lurL%09KAV(Ftr=-GN z{n0&QeOgLeF7eKnfGI)>ILguzIT}D_G{~@d-$Rtt{4%Fx;lNpiz*I%AFg1Pi`u#hL zOG^blkFe$Xi`i+oRkNT-71Y|LAQDy4SE<6oS0Gdk{z3jAZL>ql#`%pKRX{kMRJhx$ z!;D?s_;5-x_$&Y#kN{D`^FWQzoi73ihi6n&__n0FP&KWlc708*e{7D!QQ z^GT9CM(qqwV354^Oan;`wDV!_gz1ZO~d6hbZ^MV@g`1Jw*C-(kqF6ri^bg)nf!xKTna z`i0TbUiPU<>hd1uwCA$~pyKs~xmo|re1Gw#4{QouRdk0LlOVC{yo&(nrKOVq0;=A| z7oqu+h($kFbPR;zpL`AzQ4O0wJjyN;#1|%aL~7JboLIV=_5FAqPUY_>FQX_!v6?Lf z0bH7&o4X?q)7!Kc_veGQ&G*zMbZ+M6Q)cx3c}MzQNYML#?56twU#8{lnD9zifZ|5X+1_ zW0_36%`!c4RSe@2$a2cET8FYwTMtxgl+|%`ac#P&p}UWKOrF7JUKB6AxbN8;r-SoY zVb96yE%-Umw6G{1xifQbW93Dx+{lvqzx8|m+5c@hMbu)1k@+F{14SAIhx{RW@+LK; ztBwBdeH7p1G+U`}V_^5iQTT;)x^W`d{Vq%jF5UuBpsXw34rh_lzfP+Z98gpixJ7#^ zGpHWfVq^Fo;XD=wvmtv(h0L^ZG;nOZ^n+xR&@!AtM%?HR*trf=3brH3)fGqndtPs; zWY}dKUQ?w~r2)9WK~_d-!cjC{)M+|i+$SL?=yi-kQtQ zCJac|e(J&ohveYaPSR<_%XOE~^`d{XL+<8Z)FkMtk!~6#om8UzzPB(l zH|wQo!Z8^52U7}G6}n!c9!&Q3!xAW7mJ8hglypY?Ia7hDV*cyIHUAFr`;so(>AdUQ z$LX>i)imv^NJNYMCc(5*&*Dt$`;4VNW7*GG-&1ztKiSYzHmd%Oe9qq3W^a7XzV|u1 zvCVFL&R%}X&OT+wp0bg4s$WZe7R$90EYr7>KE9nkzLU;xr}KYv{z>{uD>3-f#GhvW zINOeB*^8}vx{8D`0>B@CV2K>{vV6uMM=)IraRaC;zMmea%W{{#omJf&J2=wrQ{8=Rkhl9)cR%Yp+#XQf11xv0 zJ*c|4Jv!e$q`E^yS8dup%;E>19Z_!|Mp&%(y=(7Yd;i)mqbHumuKru>(5JECb}x(Z r|8AFiSYqJ6n5HFv6-$siCBJs)?)C2qv74{5e|WX$mKOa-rlI{G>b~O5 literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/_base_connection.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/_base_connection.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..becd3d03d5949d9f396dad397da28535d5609d3a GIT binary patch literal 6824 zcmb_gO>7(25q>0>}mcFG%e=a}llNX5+zC#od zCi)Bg@EcS8)pQ}vcOF*iTvTyFgFfU_gy#9h&nOD+Xmn_1gKOs?)cuL{Zl%Gvswm zH)_Qy-Htlae72<9ScZ<2)mf!xEZr3>QI=6umaV8PS2d-fB96=QJB_01wj^Y^L+i49 zmu#Z0wx3%ts`Z6>rGCUHvg_11vY~5iLpi|~)XLgIy=km#wS@*#;qCZ>yjFz0!FFr3 zgx1T~n+(4*PT~M`^zZkH**nt`X3Vi{OURo2r&_`(Gn4&X$TIX}F1)|F&Oq}4=0d{- zxRC@v!8URXhrBR1oS2J%%e+GMIye_yu5%}|0-!{zo6&a~R5#=*gkN#6~%E+B?A?Qdc^AAfahm_Gf!9qwmtc=|e3SpE`jws`b z#Q!Ef5gzWdm!ssBEX*P*3(6#n5rMI$;5SNR%28$dj_@hhB?R0!=gf3)x;SUHgVWv2 zP=NS2pN&+Gx~OdJR5` z!xFB_i)P)r)liw>lN}M%Yl`zG{K6otI-gyv zqRTfatCTBL*@$5f^@MvJ;g0sD3XurO=RzzGn`g(6EFd|Ku)gvGxc@M*{9D{GARxxCGWB6ew$a{^Li1aX! z_lTV#T|N9eF9m_o`RrOGI}J_FGJ_1ishw3?;dNS6DATQwURtMBs^ds}UCyGSI(UiE z0AEx$M)z6PPV+hF=q;?fy)ewlozDRayX)f%(@|V( z1XsoRm7HLOOY4o=4XQ8++SmjVjGApVq51GRU^Tf2UyT)V<9h(&I_6}h$)1B=>^u?) zNqgx13>tRR!oE9j+b+W>p4P@5S8MDn_U_PG4Dv2~Z#-jdjP0Yhj`kw1e-R1h(h`o+ z`5d5{ho%gcR86NFnSCbXEeZ_!J*V;I{2O1swhlR!G6{&}S{cp<60LATZD@a~NvZo@LK^~Gx_^G_s8Z%T_Taq)h4?*|bRiS73%qnpGZi9*GY8u*~w%;Z~Q-pm|tiO26J23z8w znVxHjbN8Wy06aX?5@+lvk*4f$JkkSb=A?PzX>)YKeC7wHG-WOvf6xyN_mlm05CuY{ zZ`2b_Puel$#mVS#y9-e_$qd^GL_K8mDZ3X@lBCA$K13-pe8k4l>@?|4ZVn*I!qn!e z)8>$5$HMMB@axWlNF?bKb_7urY9KBJGeZ9^;B6*-(9lh055XXIECDYmGMY7~=FG`i z^U%VBVPM@)4cI|!3K7^w7?DW&rtAo!C=Ty-Ob^-p$V-#4tUZ7zLq;d;K}17jI%nf( z_6SZs3TQJ6lW&G_1tAhm{>v}GYXFdq2o{MvUqtq~OoV$RAD|=;kKDc`uy6Z8SAqv_ zBf#JXl(&z(jp!)OVo+ekd8vg3n^T-2>gK!zpdOBT0VUhWDbw(tBh~Kf6l~Zx-R60v z+vu*+4a>KK{)RtE?JckVfA7keQw~CjHE#8J(eldKc8$emL9Yz&uUHPrJdo`kCk}R8 zn?y=@qXI`aoh4AL2T3oIB$5~syuGl*Qc*@(-HN$LRw`^ex$E9$t!Yr*inj%dkP$Ex zT77sI1SzFbZB((I(cuK-GK;r&G5M{LC*iEFTv4ed-k?pHqd1~E6pptvra;Ye25X+w zqpK6P3afB7hx@V;aFGO)w6Bu*9$68E){yWs9z|3}f(I40j--O*Z6NI`%Ddz|;CPuE z*i)c9)A_lRF@HMecyy6}b{P;+o)2$!*1X++ZAWt6_X$+;lt%bNg|`jmYQVmgGIS zIXOa`I*z}SdPCol^!B8%pWqNkn($x$TKYy? z;)vNl-V(>1>;=3r$YQhR=q%Fy>6SQ+BaF4gQ8PJ$(rKwBN^WKwf@s{%Y}s~ZGw1W> z3+K%v#}FJlff-|F9x|Spe**s5@U)Fvv!8&RwsjnklZ(($ zxnaB(E;rx^4cEd9K4CcHIR`c?(J(4%ey3n#Se09G&UNpNobwO5yd`oz-j<5^8oXM= z2p4n$qW{9O6?neZw8RT|p}nS3=Xxr-b9S?$OK?rCtl;I7b8kF?<8<+h|FbVGo_+bk z(u;6ctE+61&*v4z43BC&v2xejbFA7HpLH(1f5_eiIdDm${|bm5@cDdSk?hx`>liN6HzJ+<`NDd;s_1kc_N9==+eh15QM5IAyzjM&l?_%###69Tg_lSaOJ6B;=o4#w+ zDDRBe1`GQO8N4gv9W3fE5(S%ZKv3MT3yMcAe9z8H^cO1yO5qt>zt2YX$?1B`C&l}o zXuy`P2vcOil&uI;Y{8VHrFOIa^j#@L{<`$L`J`5=Kt6aGw-ZpjWx4+}Rx;9O@nl4|T?a+8H(8nb2ce zLfNWyN5ZGOheqOOW6|zmErPer-2wDGqK4R@yM{(mj`L_UQJ1$XUG%L4Z7fMht_TZW z-x3~#kTFVnW>;1hwIbwc#Yk@3G%B64Q$18hmbFsKC=3M9&v0BF36q2f6>YazJ?MSfkq9oK5K>aM2Qc7x);go!jet&lss@E z;ehlxRr!J%Qls(6$cwtF^v0s`U^uF3sp6-P9eeI+H3$+T0!!HghmIk6iITm?@)Hqt zK21d6EB5!0Ll;O$1dVzEN6{4OkM#K^Z52Lft0`GSi4#ex03;q53hL-f?ugbB5G8*6 z=^iAn3%@R{yixV)GkiGoEsGqfMmE=_lzgaHYyy=hA|j{Ae^I` zaxSaf#yF81yUrQH!hEND{E@Z9nc!h?))Qw_qk`GOioK#)&AH4n+MaLSt30)2^qI&i z=UTbX#IUpaP0NQ}qY#@`-d}2x?3s0s2!2Oj2K^H;`#q_GupW-;@nAHh zYK_QBIr*APxt3-l&L+_s6{rO?G%GIs1pR*_V^P0| zd4ycBsSd^d1imQ_JW1@yi6<9(a^uNEPb8w1GE-FJxqM6*5S4=0i~1#{LMeo7aVnLH z7k3u~c@gezrCKS*-J{efKHLkGTBQW{LZyxgdheKUN$f8=D){R)8BGKyu&N7WTo7~@ z!iuWPK{o!2wmK`RI&<&#N-#i!(R*;@NQMtUL%#M;W?2JS4|stddiw27{OM za6&zGN+vNtpb?cSj9mor$ia)j5xl8#L{zz z5-VM@+>3|P!O(dFjTgg_hz$8?0I;eO4Thx4&{0l6f^^7`ASWTutfo_TOaermfs%*K zMnP(XG>sD{s6>a{7mKPVWy0gD#q;B&KjeO;F0pGwVETpMos#t7A;?t- z^>8#C4+ONW0MH(zgjSojnG!0ek@o6$a9zY@;DrG~eg;Aj2**G`r!pX%D_q*|#9Lx@ zUP<0%Hh2s$Ix(iNz>o?APw`b((p_`cUAIuPX3TM|XrZBf%yHLUd#|qbtxjb4?p4&@ zI56gT)5H0Lg&kC3N!EXXmr3yabGYYTTLs`%IG0(@06Ax2FI{F-e9w^2mu-aqeC0+( z;wq!I5Sd)~XG#tclDk>hDCpuvnAgs<2=|LhuOGj9{ByzXsaYtmp4>gLd%k>avV84~ zK3BeeZ0|yI+t}XgN3I^3>P>oOKz!)};^ z$O^p-5?%@E9!Adj5cp`s57(+l^XN?nCOxK23{hDSJeXGIo%1fi#I2 z*>d+gGiX#|tT^R0n0SDoQeq%gWM;7MI^hpQjEn0lFkSSt>9P_%TOb1{t}h^g^;BIy z=3Ov}y2NupTyzu{A$1FK^UU6NkGykazU8rG%VQtd=USeaUGv1accHCg+%f5!@Xgqh zB`sh2SfRCow`R7m`Ick8efy{F+ZWcXPkI~1dd4mJp8hh^+TZap-#rbb+OlNpXli6uzl3gQ`IX;AKPrm`Pd=S zvt*}dx71te%Ca1-CHMiV_^0Q2%a&GNt3xXT!CKM<9Wky~EYjqQX&FhjXL3VF4lQzW z%V3Gxe$<=A5y=Qv)CiFs8Nn-2k_GY#Rqz}VP?AYRqNj7AqGs~Q#F6=mwq!-yE&E(W z$Jo9v?f8JX20auud|KF$CJgm6Z_A=x@UHsOMIZtagH1N{l-NHik$P%f`7OR7wEU<hc}AE2W;c{i>I_lg@Ay!)2yHebP_VDl7kb;Rg4ATrdE0wx_Xr7Sx;A$8=Nraj-% zGL=3PQJ0}A<|CPNmYSGu*DTBYx>*Vf>c}ILwAxq1y~0U2kDvqz=SU;SxkfV<`n5`j zAvd#CpKINji`~fe>NYmD~P{M4KZS+JAzLbMZG1w>M zwA7l+Y^@njD3;D85yEo0Q}Z}|Usj58;dfpf#W}vj6nLx>3&C6J3j{LU=CHcRQsNHNXXxoLC4H1UPYKaELwBmkFttKzBoYYR z7PTkwiFtya;ueBTpp^9BPmdt^>d%DFZH1D1u}&!MoO5(66qkPg*@d#LbB?VG1-|be zf~HbaxA4SMi!P7UaKE%-QNkT^uX+c|!RLbF-+Pd^R3%9@OU2bv=h7xgYF#R}N$pE+ zyHv1L;FkPfR@kKO6@L zhL25-UyR9cX~SC+8(=jC6-85Z-SBQ49FQ-naNTHd{gb#MZ$^wc8BBl1#c=#A8iGG1 z9u5shf|^Vo@eV3xIV6JAG`u#f0p_vbT|o2j;J^hD3c|&QKShSD)0xm4kl}b>-#L@q z!5ufdcI}dt6K&t=0!i%DD;6YjiA4Sr{OwhZKD6WD)S!7r-S5tg2cXfR>cR+gnaUt zHVkY4+uU_S-=p&B;c!GDR~9+FfClo9Q4`uo#z^HSb9&bP-KL(V9dgsgrVhDj4?PXU zVojI*tTzlfU6{dk0O9*4Bt~ypAC^JwA*joxsF7CzFGvi;3XC~HUlj=c(Cs^*K z|A1PUFo6&vhtiuxkI>Wl0i3CZ{!{2>?-?55QN!it(DtGg?I4+AGS3QBt%zI zLe62PaxYVTG>2qk1JP8#EgJ&KuSZQ1#vTZK3?RJ{2`0%`e*N;*%k#dqN#EKzU;C`P zo%fu2YhDgKFbew5c*vZvQ87;h?MOO)llJB*;(2Tx(0WEi<_?03DI*SNOFMi_U!K;H z@!g*1JGpG~#M#c}RhCEXX1zxR1k>$(zoX&phoVA`fRq%cun#Ac24rwTsSH3w1sHb? zfJ+!_%W%nRPf@`F9-|Ckv0Be4V7g@uQxCCP!_f_wZK8Qa`bq=+9V*wKMFJu#tQ=R~ z-gmdK>F4^bEk7H%)AQ5sEwuWR-lnlwXow+x-kYHj|ep zF3(r*NLKIoV8@4vx#|~YOI}#;Rj`Te!vI34nQ@G?PNvaXG*qyJY^YsW-8?|e@RJtf zCsD^!fKNGNr_Vt)8yey181@%D1G6roT3q7NC|JTHqgRbe6N^YW zSVXGXP>EU$m8g}gM9Nxh!l8&%o6^ppJ%BDy{D@;wT*}YlSYBlvi(?fj>scJDSZQT( zET7_2O5PTg4n(h<{Uu7LQif94jB;)*?`3AHbSdSpJIqzzU$FvIw^ES>Re7!>vljk5 zAZEnfHYk;^OZ^qfMx_d^SF08MHTbK=UmgDHl}$=D@*9-RN)7I-09T9qYGsR3hx;1b z>v5Nrtx5y#jmkD<74A*SW6EmWo0Z3vHMqCnF5}+HVsvW}qub7iEjWZ3VbaQoe;Gn1 z9kA+QQ7VlBK3vkN5v7wYKxlXndtDI2kbT%3Kx!L>!Q{c=NIZ!0O|xOR4a{! z`a+*0VG4UQoq}QFh5fzqW1BW_=#u$*CPie(jFOUW!!-(q9t$}X#gugwnj-a84TjFL zx^i*I=EWH9iwL=&!H_e2%^0~pf{D7sG~J6Nc6E+S(vn~Y7{igFZ3QEFTY$=oaWOrJ zkZwk6E!09;4i1I8P+#B6Ab`W3)_>X2yLh4|; zr=>MA-z2|pvRySGDGJyuPPGL<3q+aT_2^Z*Mz_eOSG**!i$( zDAZ3f^_lfDqdpD{ySp=F0iO;go_u-u(xtX#Ri9|1#R_j=ClshN@w06w(Vw=*+Hz|> z(ROs-F|$U)sDe&UUFd*yV^qJqRIgF{VWV~iVb-5$HDp<~0?%a`SsV0p@+9+!WogYM zJ)ld7OQiFBQ`|U=2xmszSbTMJ-15#tN3!%3Qww4K`+S;;<%bo8Xel(DJOQY*PDOz+ zR#QHx3l!Gyyiiy+TezCEn6{tqy6fAtP*TAn zM=rSe?&G;|qHyZK-IA7H7nYK@@X*ymQ_j!4YsmRm#`RP?sx~j`7T(3B*YWU;dTQyY zm@g2T_Jza6D~{UEkPDU^h&dNZKf={Z?icJ$vh_W5MPU0yJ2zsh8&@_@kAMrNoQfKP z=YzXqr3m~3+U<n7Gs9iJ;}8|z(YUw`Z9Ok&J&-FMYDWxwf}_Pka2sk?=vGE?QJ&^$w> zf`^ri6`&v!{eYy)R9tHDeA%YtMe?XkLGZp#c+axdpp-wfb;!S?3?PD0X9CYD$GKQI zs(lxa+2~-g`Q_-ag7S9Mq_0OY7&*md*JD>>Q=yyT>F`_Ulf~=C>}2?iTpgJzpL%}k zg{kT}U*oL1aXB7nd<+k?aQ-knJZUaJsMpr8v?>}9VceWv@%e1#>F%uYe2KZ!sd?wjsRj;GCoZZD}-Xe4xw5 zNGgA#ei;d;4Ihf!=q-TahEM42&36meERrnnNTJL zI#80$7FCg-Y15K6*>KvRrrAvuU@1Ym2BA`#tdIQIDVLF%kN3R+fJAN1h|=}=Xgp+T z6Zi8~T)mj|HO@58T%7ZD&$|4C*4ujD-}#F*x7W=1cg*{CzEd$%I@2>QPP!&s zH#}1tC%kjMoeQnI=35UYTMy2)9{SR5drB<$^{U3H=V!#Rp6ds$9{AzG@t3b2Mr;%x zJ{N2yJVN?43VyvLP$t_|^w;%!B{Wy%gP&oe)Xs^WQ^RxRt+T$?S$8XE#F^c&I!Q)u z*2>7cN6cIgW>;<8yTkZzZeWdE5{aB(2Lvl~_sP`DQUK8UEgRoL8@lFv&9m<2{9SA& z_2WB$KO~48mw3*-9wjvq_k~(Ps)r(y1pSFPDT>0iLW=SJmHi@x=jjL%VVw=;7=LDN zTLMW_su;S>yj1gup@&4gLT-jR#r9s@sNr4ngeh{%)YaX zWL$QRN~6wUQQMr}emd$jNnf#@hwRsF&j_!Hqjt?V>QwARQHp~k^r(%c$a?~BBdF&b zt&5y1El#kZNE(s+&fwQ*yhl-JgLOL(wlNQlpSc1$WF@BR(YAQn;AbW*cj6%Ug}`4h zLff)O3ZU4sOT7d$%yfNF&cOkcfvrn>P7w2gt;^yg#)Pq0QrehDLeOM)?ThL_4d6wL?)m1pFwdXSSQJJ!3e$dj{Cc!wEoV z5(@W5`~l6g&UeUEqd(oSb`c9iJB#FZ{}-3`Jv{YcQzuz=+9gUxC`qfpq#rWTlX7xu z^1IU8Iki#xI*lad!K4S66_|3vEk$7mUHb{X=%f--|8X%pFlEQ&C(3d(59DMQd;f70i_<-hYC90?h7EEJYc zZAlic!Ksvr>hbuE?K9$!cFlSl$9MhOSG7>TX2v%C_>3~W`_|E9{f2SJ_zORBn-+WT zXC?BYPw>jiWh5EW;4|XVetRy5wfL6E_T<*2qk)PoBN$}4NZ!JE+rO}zrCt;B!657e z9;iu>rtBPPR8%B{o-DO^G+$_`18VIfOnXRZm<5))oPU2-2A78Pu5}3GVpPa#*9%Or zE8o6plf!H4(HBxba;~(B{fG1=`nN0egd)T_m(`O%TE^r%zZ_4GCr>RIU&$!Ux#DEY zvn&0?kH3+;N(b*?(%7@G?}TAmXcW!3jXEF&4H?O?AKeqLHvvZNiuG07mX+@^OKIzX zcRHDvb7kWl@_VKB?W2s|%=&mQMs44EF2D82uv5pA`0#*=)0*Ls3;_|-;xe5BVjB)f zq>!W{(}+SUob~d9P&{_W_YV+v=~041Ih$azou-CcI?Er=_aX3Y43;2c;+oF-5_7iP z?r5InWw@-Y5*lq3PIPm>W4m9D2hYgx7#_1+A7K0$oFh2~{o^a8w3pMIz z8ZnP067jK}U44EZXS|+c7(CyH%Gh)xL8z46q=ZyfjkMsD!~~MoNf~5iXkC;vP|{5a zRc)|uoUlf$NE@c?Ym~4JZ;YMq$Llhtt&tkM%n;(keV+KXf`lE&@%qN%Kioe4@(-T8 zS607J*7K|850#JoAJ%_zV7BBKEWGk!?0zjO23KxaGZlYp`z`UG?*jLI{ztA`+L%O+ zKNSZI3p*AX8gCw%J~G$PNqZ=pC*0%q@uTEkbx*kA^a_1e()0!PQ8xd!sCr5=jvy9w zQK>`Ihu(U2#X_|C(ketJ5sSL-Rn$!$nmF`x=exdleE-(@@4f%p`^%%hYX0Cm$qoCH z@_|n(=PHhj?ORygOqI4y6rd+BrhB4(R?pK0SVP zs`WFkOa@FI4<9CmTfe0I(`j{Pm2hIpbzr4ja4(V$v&<$j@-Bch8B57kNk?rpMm&jSE)eC4<`%3^UZ_u)6NSEN2**QGrUf;r#3*M`UimeXT zKdd^cmtC;x>M0PB-lCCjTgEVsx1E9O<~T~z!7aL*R-oUW806bKNlPc}5~s@Ef5)Pb zq~wytfwPMgAnlT^Qc;VMsDnfC5nc(b4MUr@j1s1BcQIx|N6*vV*j|i$;No@9Vl>UHc=?{qnjW^eqW@bgtY zZX6M_QR)(rhR~*US<}7?S(CyUoY(!SNKS=}ZRMHpM!`&TkG7T5S$MxK@e>QZFQ|h! z5C9FE2lVtIH549z+%XIwBLI6^h1>zu*e z2hXS(IWg?6L-af0HA|6XNEDlIJb;*T?hT(oPZLFl>1^+_s20Og{Gv7mEE%gbRb!wa zV4}d>dY5t<<_#@-lUP!9fgw$$z&+bZ#K#_B_)!!7994d0&}&3iB$=)VUlh1o3TEB% zVwq6Q_HZ}y{q%>g9-gWKvm?((BNY2Fg9&9$HtFDu2@T*O%gbTKWAdFEguX3i=#6;~ zAes8ndq#UGWBUsShzQXgvHhXw$I>Dbg>4c_IoK)rAJTh{PmT`A0%3GQWV!c>fA~v6 z2FYr8=HR1>-&i+a)|xD9oh@BE6C?-gF9Np%bDg{9+IP>kJ@uhD>)SKy-orVhp&O#G zAdoGo3? zUNE~x3?~m!; zc6i?&%OW3>42a|8b9Ukv91PS# zbcksmEh7yYl;KmRvne=ckm=II4>urAohZ*)G?e+TXt+&$xFvNzc8njpQE_a!WYXt5}ojhNm$S~uP){bFp`&M;B zu5n%X`-DV(dYtQ~B>$PeA%}!ijZ28DztcHfISm zY&@Lmnc6dciRq3|)vD?cy*M+ak4NT8nwZ}BxrEY&4|)4eF-v5TpMy;R5kbZT?D*p+ zfTlvpyBcXa6h}G^ZB5D(m=Fh>5Gk=^g$co2P@svVRrX9kszDz_xT%Xz26>6N(xF|U z$K}Cn;(^N+GR*>yWc>|I!vVmgr@`jwq_tc%**(!c)BLXg9skePC(F7huW~#%u@(oe z{L}uK-do}=+suKvx{lehjyZ1!t?JINSwQQx9NHzFBXd71z#`DAv4C zs48n-EN>VK3p>->v7u)R`Q%Speu4Euy)&f`^)ywSeRz{ut)^YV1ksy-%0dX8vBH4{ z$m!()G?xDfp@9r(_WL($_KMl@(0k>L@F_01z1It`7S2|*-F3HPXNIY@y4D<^9wYH!q!ITzf;*Nd(e%~tvEy4NlED#wgd7Mb|61oaTQ`E6+i;+*s$ zcBO@M8XqfSEK{K8#TXOqgfZwSBxt+>Si0d z=SnwNSQ=OEBKmG2i4#2E1plz%rC=niq?hy2*svB-jUSld?j7>~m?s*UFNk@0*i#)1 z=Qt(gT!gq~UZCtxW^RnYSOJ<31R%33C4-;4nive#fs%}>vP-g!`Wi_zgdNiDr8_lE zHBlSs&Hd>9&ybO-%sbljFf&TzjwRu-HcMt9gY~<`Z0(`Xf&vcl3vtU}6F%$5-#7$s z^S`17=zMJKFEthCMdZ<39)K^oRsWF?rUW9zYeb{H=V1G#DWS}`_~dk8zp~5UkjM} zK)<@Drz-IbXUJeM9y$wE!>}$>4j8F%=8p>CtM+fGENRZ1HIY`Qky60~vPM!%`%jd7 zOv!(t=A|1Z8*gGj}8w`U{pDzO-o*z z)U@QrF^narU8?-Y0#Vwqt`*8^uROER&^+s?#U|4$dr_^g>dFB+Khi5ww;o$6K&O`qB&m6+*nvZ~UQy~` z16e9?Nfk?FZmH_a3M5QL0iA3BO0@K1{5!n*o9IUw2Zr&pj@Z$nk(g%w_t3$<1DYFvsZzM@0T5t*Vmg?r zYeb#w2OUZ9V&ZYQ*+pKAmvDl=iM};cLJKk_y% zRB^V$Uy}isvLD5<^ix!VQAaU7RZvojg!qP=DXD|{KYwE{T2ItXT_u6YgXU%PJ0&|6$_4nH~L=f8{a%-AAdaQXrT8auO1oS zKY4iK@J#tkXr=}mT#}CU3y%6lmt9)*xm~KY%?gzdN<^_{-0?ubZP8sSRzPMf+Ht=R znw4;W(2k$`?Vj3yvv0cZ*5*6*TaPCjw%i$*-*zau?a(K^v(F#<slI^>at9CyS@bSSZ@kNJNHU83k<+^0$I-|q5C{ea_Mg6RnUM}rW{wZTimPN`^YLbFP*){8CIoz2gho0Tp z%*=`+yF~54Xqf_S=ro8FAZS!HKyBDS)gK_~Ti;rseIOyDUTketMcRkFts(&h^wjU% zJ2SgnQjQDvAwWB#X3osLbI!Tvo_p?h&g?&Rbi^ebH;?~wUP?;R&*{cHqJoegWMuS^ zR7sT$sUXkEGSLAeFc;+4&|C=Dpb;)a<|1edsbM2ph|R?~9WmMp@wqssqegonF_$QG z%ysbln9*72n(G4HwkXeaYoX;KPk7^sr^g$29)+hTJ-Tt#`X9riU)z@t97IQPCJH^% zjW<2&%W@EW<^}@NtCAXj49MEx>>ZRao<+946T?m zRqYqBD)oqGXWzU$nSEtu;!WIjUYwo1d{I+W&6?12PAX7Ki1rJYCSRMlT01CS&KAms zqn8xR$>vR~pel}nm%Cq4Y>gOP(d-fgYPHTQ+PBJ@?M!LTlBwD`p`thk#YKMbFCcD8 znlvY?(p*55=YmU^-#?czuWf2v4ZRnh3%5z)pW5zGdtcRr8b<$!*Q$1S)ZSOMQ;nd1 zlv>rU$Moq|qv#X!T7RVuJ!%a7+g5|AUaK90Q+|rE#u<+DX7RdK)L}%874#c=k->Z{ zXDGI<*=%LWWO|`wXa%k4Folg5V7BpjOqp5Iit~(aO*PHza&C#UQ*1WQU*??*ePJv^ z=7*G`mZLepY?{VAQ;I6@-rAR1r<9_ys9E!wIPY@VGOz0@bXm}rlsOg*M_ZUooS;?leo6XRcxZm#@+3-0b;_k5S)O*_~CTxXLiSYSZ+jneMO^ z-7uJ8ns2jmiS!d5S1MU%$qaD5cx(eB7CD3ow+=F zX=eKBbj}UDJe(1Y#V$V>1aVWU$Tws=AWOPbk+Qr4omQm}WeUbocPNOmAzL%@Rv#K| zV!_y>v!hO-G+NS2BaUJ%YR<@-ZCY#Uv(_lq`Dkesp`bVlcc4{2n)Mcj2oZLsv|5X0 zvpUR~&8`hx*%5^^Uc(rP>%i$9sXB1@d+WD{HbQ@tcz_2|&fR^9rU6NaWAcLoAZ|(y z?Hv42<&RwY+j1%}y*72;jbz#l$6by)MZ>FYrzyr^GIWcXD@8W%hdD3KWniJcY16sn zMMO=Vv@Fv~#jJivuSLXIYe5*H7NV8J?N{q|gM+_-YP~+0T`B0kSi81=r`{R&`E%%G@5kvK>0!UrHB=AC9q9+bU{|~@1>54*0Gf7~E`kT# zbRTdKQ<0Z_T zjvvb$VtIGsS_v=Hytf>l9v+mqE?eDBm)EHh_9h#Wf|aludJ#=dkJrB3>rstsC8CDa z$j8x--0>`vm0J!q=JO3=?BPnV5>?xXcSXiX$=WT)b;$zoK^ysF%YkhybU9lI<&kKjfb3{?qjfnKd>=O1k{3+OhoA3ii1BlEBy|nyw3%fEY zU}y>!nNonOI~0fuO0ldMzI-i@c)x1DX~d4v4y~$JZD|R0UMPxi*`+}tUE0DLDQVOs?ivCGMNC@CMy%(@nDR{ zfqJKzhRqLqoQL*o$C`%;U7WbE>S*?S!)l~2yg(vWIlwOlCK zwTPIeT3=Jl%(^(R*6SLnsjb%6@{CO7f+~ylNb3-tNLwpOCqkvQ5EmJDgJ^bd^yD($ zg`V8!lVD_b0sy@u)qhKtdJo)u;{7N7_C${@1 zJ{vss!NA?YXEvkN;TJcfw>r1GlmF3o;O5ug|N1TGPW&JDebP7cY2WMHeXm!$2Oy=t zb7R66arDH-H#VXeZ!llKkXad?i;Rl@2__E)x(kg&U!>T zaJYKl$o)3DiA#M?-ft&Lia_aZsXtBcJhk2T6yCWNtdpqf@!>nK-sjZWOZ>`*C{QB+ zhkp>wQR5FlAd3ib%;z^Zi1m;vS3i)r-#{0&`tM{HdeP?lN_{>JE8teXU*LS*Z#XpH1`}g*qYNBg%>_-Q0 zKX>;aMVIZw@W%OjU57TD?^eE3xpm?8`R%ULAH0CmR_yfd+|rK{2Sjf9g;AoBQC33U zsz=<2Au3!_ktZRiYHvga)sGC{mMdYar;%48JBxfA@-oD?5CYcQ*5kzvrwv2rMTcxcMQv*Doi>We|zLyc(S`Rf+iF;fTt73cQrlwXGH#oI2Ci_ zR8;u~sOHC(|Lr(Mo9CAgR82VpFVVHesW&J|nx7Xju~B4yY1S%h092<`Ew7;Ro=Q{V z&?s8%z` zHgEI%8wqEFk-k`j%tqS4M?G_{>?}1Q^s9h=NX4mU?&i{p(Oe$j*(p^(DKP>38|5e$ z`M3q%Haj;x;R~cz8lY1~s*qvl_-Of!C>)%k#vZ@X(q>k%M~lRGufdY z$vjFdq$0YUqOL?|oEuIu&64iq^G^xEJytLIx=7KHc=GhJ@q`4iQ#84G-9mw6hlk;@KW*G6Qq2?37Rpp-qHjQ` zJctmoKt+~U#s>wS0DIvNM%Z1IhCTclX)@lg zf0^q4(JMZf+h4I#)4FZ%tlFShL?{4=fq%Z|?%0$@iJ~<5sP9&zRAC&UaL+@z@1GQv zs7cwQZs))3e<|6e1%6N9Rd?MbTSUBRSqy&B2bD5Z79GS3uHgQx6J++RfU8JN#_(`$=!;Vm8vNg(pZ(W3Avd`Y*p;08ZSn8lxcl7H*6{R3?0!T_ z^j5p}-5T8PI`-NABh~)5P$n7ZMWv#r_kK+3W}lrnQ|%wzI`RC&VBlo$cK6U`=zZg1 zT-tZ|R{n1PiE97z^{_N>Y%_$S2s^%Uar5=<#1qv-|K^+9i6fsTD9ica%+Fr@BysUx zQ#SO4X^%ypmfYm-(Gl1KJ6dK6lZESVBisUKIo9v63NN?TA{JnfRjh@m_?ik$PtQ)L zx<%^u6!?hp7N^M0k9rzEfN?p9**!~rX?E!2qG|9sdK8Bsuh$WJJML<8uDEKwOmEQF zHWE7hMMAAts4L~5kNTQ_U*oan?!^^2jXrBV4Iy3+?ktnU^V@9w02lX znw&mAGclRPPam@4M?D_PhEUF&Td2W&ZwvA?`T}Xtc$<6ld3wg(dV;9EIL7G{H6fC0 z7QaHu7EHBl5S_?ozlEx-+Y-%YRWp~(TF($4`Wk34Iz2}x%FV4YoIb=SL8AB3iPj1~ z(RX6|d&rL8lkNuw!?9n!ARRip6&iRLlEWwJozk&nb?o`-(G%6wNWH5g9KT1kJzP=S z>+GpViHb>GtlmacTeDt|>X($t4isir}P>!O6JPbG+Wp$pp#k;AAH$!QY3Rfur>v{!|F!WIiB$?K#M) zw;u~X%Vpr|iXbW`^^Dfrh!Ue9Dj^LF);oymB#pa>x*|)-r6njy4 z_Ze#r4ODcs{}88oP?qJ-rJ44(tt!qhs!A~}($C3E(l4ki$;i*sFD=Re@{ILi u+Vu)5e{tC4=BJeAq}mm60?lCr;$mJP@qw9m(gQxxM(!eZpa=jQ<2_#h literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/connection.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/connection.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..07a9fbbcb925b2361679ed576e31f053e16fa68e GIT binary patch literal 32227 zcmch=33OcNl^*zN18QG@!d?I#b`+KZxRVe`5d=Vri$IzHC9!0>RKzQg0IN{&s{%>D z1qYHf)8L8RB5ij_jqRA4=!~e5(qYn`Y4-G-Y1{22PBQ1DilBm0nL2}>b~;gdIw^_N zNX^bH-~HcKD3)ZWJ!c-lzwZ0@_5SzX|K9)oD~H3%;knWNzfS+l-{H7Frx)cZlK|br z|K5NYoWKdXC>PTObvlCeQGHO)ehonb`!xoQ?AH`DvEQ;_8T%~{ma|`T(9C`)K_`RDqGd5x(5>Sl=Gj)ITH3EzA(RW|Xhp0tSc&-Mf+gyW zRRyaUY>igOYJxQkwnb}Wb-_9Y+oScdhF}AO9Z_GbG1wSu3O2=>gU!s(8RcUw!4?L) zqOGyEV4IG!NG)y;wny4$k7_kgpkOCTuZZ@}3Mfct~}46cd>Vgtbe z23JQ1V_Sk-Vq1e-W7~q;V%vk;V>^O7VmpI7S$Iu!S8R81cWh5^Pi!bS6niT86!Wi* z?v3pW?qhHrTD(8_G=u8_9|#_Z4F`u~2ZIM=Bf*i_XmFH;HAKf^hk}P`3qkdiH4WXyjP%n4XImW^XF((S9S(zN?eog5yG?&?GefKp#AT*!tO9S}X+;c%elo ze;4zGp5Rvy&ouj%^j7E!t!l0lh%*@}7uw#{OEH3{_1s}jXn&OxIwE#8FB|jigl|{G zrusg|e7oW6#~k_n!ZIXSjroGmBlP}2XTezhcK?KJLf@-p!84c>+c)PV>=622H3fsh zP9gBBG5DgeOBlfKS6LkgQO7N68_!1C6Z**6;B%4Zf?q>UyS1EzJ;GMx5?a)^agnY_ z_q4v96FnF;eXyP7<7b% z2*V5$DC3xuoBetDeHZCL=7h=YboKUW$aKXl{v- zuP1VqiWe0qcTmnnFPFved?*p0x)@1fD!50GWM+D13Z+PGbjHHTsSBYC@kEkF9#u1( z7NZ}X#30T5F=o{}`ke7XGC7|!k(-$LcjX-S5$&E!4KIGJzoo6cqqD20H}JL4OQ~-T z_U{SzFAetx&*n_w1z{$+X^NVW2#@aJ6(GakDVU_EvH1oK5u>25LpU~AL!?YF?gbnv zpLJ83%@2GlHv7<uvKV&)%Y$o22ao(anF_@41l8f!dSv~p#_MzLMlVp@nl)TPF70mtBznL&~_VQ zdr{hMY(rXURm`WOz^9t|bQbv3FrTghpITuT%e(tkd$5j57WR}Ve~88Lqx^c|DF*i- zegliYS1=2`>|fsxj8CR5_7V1B8!8X_q_oAMD1Se;CsVMIg+I;88bDc1tK1b`uz7;> z9}tb`-0(WKaVw99aHGJ-=lG$iDAwfAOEk>`Q_-2oTr#kEPkD(yw~*xL#rUNeA(G(3 zb3E3j80N7`fu9$ql5vq`c`iJ4@p4!c68%&0*gUqVb2HJIGY+c?o9)_#@LiHhNx85fS<*;v8!Z&kK?1@Io{x^++_1tykcu#dr*@*gSRtIi`#X zwfgXvFU(9`;N@OO@WM(t%PD3{6@XS_wp~w<(=CtE#EIjfi4!Bo#wPoeftxrHIyN?T za`^a>=f?WbKS~Xe>a0@m36Zrr7GC5phcSWBD5?J=n;OTTTV&0lX+f(lHczW*CXwX3 zBZ2dQK8*H@XJ2~BFHLfBHx~GkH@P^E_<<2x)z5{+7qP>h&DoV{KqQ-Jp@@UU5epWL zM4dhXLHd-8RaaY5Zft3p#(LDumF2jL?0zS4QHvQ2%RWZ{uTlgBAm}xxJUJz z#d)x#0-9}d*{kCUYI_S44+s)qV)Zd=Ks_}hu17ka;G&t=UKy!z_GCHnq7Ce7sjz1rni-_T99}i}ZC*ohGhwZ1y4X)FA465hBNoOELtH=~qf3$(77}c?U6k{`gs1{I2inLm z6{En~+E&c-Sl2)`*yzq9A0X#&VU|jJSq-IK65W99UE9-W>xf0v`hjyMPKKx5fhd5; z6%Y+e?Hr14a{llIF1Kgq^)CW&Y>F+w!*wtJDN z49W#W&iNT4JE@yMXvRU3F+vaYCa5&DVn!jpcqE9!cM2qQf~Ep!P?mFH+q!205$w=x zWTgJ1UX@!$lujZ^^cIml7qqbtPbD!g8U3T}b9{J8jDy0GD7MRyE|hnk4GHo|L{Lvc zJLu)FFCf>1Ob!rodaMh8`L%?Exdhv$a%CcRu$lRHbmH?^*a<=lyoA394K7s{;VT!tV#23+2zn=AQ&IH_nQK1gue_c=i7?BdRIijcCTz&JZ@!QTP(Kqd^tZ(he z^afbZq>9{U3&#M_=mC0HcXY`|_Eq@cl+Nq>oM1#qiM~XL>4zpoX1uAKdL>_! zQ-yLGm3Nd=mePNp`=P#6I#ot&UW$*YSS2j;BL&PU+uXp!VOJ3%V9GJilSyE9u+4K= z8wLBukQhlWh;u_c1cguLqs?~A@-bABkxJuB&Jm6M17=!krJ=3Z`Zw9mv;AN-QFAa>-KDO+j{fXO!HP1cw{koovWjtc60Xn2X@!%N3I@8 zSNGnYytDle_x$5McZENh`Jev6y)xYxzr?U*}9#nMP65gJ9 zbLNis&ezu}_T2q?+J4|~9=Lp;a7NUnq64L7D|o3Aw`}R&XMW-R*S>$@`-L<8-1BMo z3lB|(N@u=|^H$}{4UVe6d1U3>HJ@+>O52XK>Dv8wzkYWrU48JOL0{?IsPyJddc?~c z5an@V5bb_t*m2On{mf7~YB2n)y7pke@UwuO;Gyo3R>PmR68xtD_sD+3pYAsSo>CbT zBqo@l#IFG$wkTy3beD9ZOGAxdSd8D-3x*%6%+D*jq>3)Dn!r2(u@du?GQ4M0&;Za2 zmT`!NlRaQqOylA%z)S5%<``K>JJl5|CC1!IyBK2&v92(2Tl@If0_cfz5k3NH3HwJE zP310-8xoZ0!Wts(BUdgRmLwo*w?0RkhBWggDa?wMDzlLi^HRnp9Gke(M2}IlGN~5g z3wTKo*2Em-d6_|p<9(^FXaZ{aen@F(k$^=3(_ybj*Y#v-kWV||8;Cf8ig>nL*2LFAwP-`7@e+$0*{v1 z!NeMYs0wvx5KHAbmE1T^$xp{6Rjv~;OYB?k%Ho(s#n{T6cV0HAqy&Fr>;d%Y|)#I;?V<~p`-5&i%N8dTR*0qaqj2jfa>z=JE z+tIT+`o6t2Z{Y0RPZAomI@qeBUHpsqM1fo2CUAgAbPsEHajPs4`bDXJy-XnZN6+}?So1g zquv?0U%5N&+MPDL{vp>1btCf1sROa75-uigRyiDi*gO&iuO<;R{Gl*j)U0qOENY9At=QtOt7KV{ zCpt%44 zE>op)_2Y;9R*`LsCWcs~MS1|W7Kh1UOQ4j*Ph!cW-I01r*%`kHc*$EdrYvh{XmE+& zLojWMdb_3Tf!%ZU@YQEuJCQeYb&ac|uN}!Yw-e6wWjp-z+nVhiWH?xT=UI4TR{3r1 zB&6H?dEWI~=J1&Dir;b$Te+WFhYlJy(?m3oY%!Al&t_3^DcN31mF+E?QYIX4X_G{k z(t&c)r%bczmOOm-G!xB00uTj*p5()JC8Ud zAog;eo^|(N#yxnadd2BzB+-ogHP@DhIa9Jm9_=cQy2C7xy`sb!1U`Ugq zh`6*I^nt;g?oy%P>9J)m3DU33i~E;)i?AJLqQrg#_Tr=zo8-{EM7gs};}>#?qD+;7Vna9|)UJd0Wuzi}VCb?JMRH|nm}-Q4-Ur}duu7*=wNGi`4KhgI2_ ztr$u_bv!-v>@U8OcAwA|dEUY~_x<(%?mosCy`S>FgO%n<@Q&q7)hZ(7T=QatGy^1M zDjc>tg$SL6tMAp3InXpvcp!`mHHJ_$GIu_CLFKGzBx&`sUF0_0FQPtQ?f~(Ih{aFI zeWoNcr>sJ-X$ANKym%Q7A=Rj`j)^ejQh8yZ10(r9SZePaZSoVV(e1l#rMh-dBL(hWuGOPchR%#fIqPjMbEMm zdu@$Sj#@z?kKBQ?iXZ3+SrpWuWUZ1`$yY?I**3*j z`xV?uZy+DgN+`KQ3soS&lk8I9lt)RC@=WWOKyoYZKf5# zW5S3^I#hScR7*&vR&2^UQ7u0}&BPy)^Y`JD-nYgPqV8K5E^MX+`&OyNt#r0h9eK}c z-n?h&89o=khwQ;&|1N%Vx{HMym3R$)Oa7uQO0Is14Jtw?nP!``K{b!u3BOf#>+5e{ ze)IA_SX}3~WSU3heW|TOx8#!O!hVG=WI{AlglITM%>n)$f=8$p9vnT+C8i^y8h^<% zsd$aaq^0L%lOk@h%g->eBiyE&vNQBVa#tb#ey3{-#aYNb=^wd zIrJ0ZpU?et?tbm*RY%s-wC?H1csf?gvUQ#7bvrV3J64?^m!Z_GtMxVnF+1oyzJwSm7@o~>+2SNgLxjp-VH zwzczSdA8Q~Bj+2=bl1?`Bk$K9+K^<6>9%b@p19kzw&R)m-Xjnw+G}rq1M*<%rtz!e zH}~H6A6WAryl)@LHn#uh>>FplAEL8_o~zHU9=bNB#M*gl$NP4F-hhA&sp-&Mq0B1M zw#IB-^Cz6u(Q(a$7S%Rpy*`|J+>E?6aUa$5wfyM#8^>?gtogQF8~dQLo+O?}t{=G> z|8eD=(|=HZ_jG!2B-1qVzIT-BOCgc>z3urbz1COJe(dYIsfaw>YHlLVYY7(q?QrGg(S^OrAu%c@M< z;V78eIVj4KPKTt|2+i3TPUGacD(lmb8UZP5(u!lp+-eTA&Llkyne2lGrNr*C!#+|U zfkp*X@OY+ar>0watu%I(6!jxQx1W@8ga~LzQkjQt3$zR_lj6lWlBJPqj{t=TUO9ii zv^B6LFi2W0FdPUAbRJ);()~WdHFPo#GS>`|9~mYjaz=u36{B)pp*#G%6eRu=q>_074L50dF%-*&LP8ua zxrRy~EH!<3AN>PDB->F2SoUhp;(6V1)sffh953j8Rn?WPsr}Sqg8r7Bvp8P2U$tL* z?&buR_wzpyR_*Vbk3A{#b0Q};9e*Fa!49!X64fhKjpfK)f3v`!^I?H9h?+M5C;dld*L?XW&n$a%!3t+eQYAR|!Z zg;)5}IcCvAOvCKfB2T=+mu61U17E(#3$O24-nC1<%VnuDrtP3=Bxpn{vnbmIc1YDC zC`Dom#-vIlL*t@kc?$UpqL0+J%vf=~eMK9bx)- z=g5iys2D0pqI3cQEO}`rzCb0&4c6i!*_;3!hdy4Z;J9ps$Ep;b!O0j?_NN+AJG4v` zB}rLlQtA%Huz^oph%ZFZ7W5H2UX$ztpvR%&X~`ckz~++zY7NPI92781E~Qji3u&pBm)QeZcLej8KT(g@C+M^Wrk zwYeF~Bi=$S#W&&j8yFESf+>@aZr>t^&|l8145(-$ze)15fnHX4%5YwppkyE0qX2pOHD_A}1paDGe<^j(nXae@R5KkcX*b#gyK(@jqA?Tcm|Rl28YO6ioP*>Xg7dhO%q?Jt09I5nfGTCn!L$$_ zTThFMg$C1=e_U}=vqM#k8L*;A6)b0@oZr!l_oytYnBT})G6qY&Yve1%c_peE zKSZa5j3Z^exT>aonV_f1c}0cP{2<6@%qC0ohMGnT*N=~b-7S?b(Ws9-nq9BlfzrbJ zH$TxS#Sp zK+Z5ZZgNh;$(eB?4xE!*WTQ=oYoy~VX~)DVR)U;Mry|j4C4#`io2hpuJp~^Ao+>)br2) zC{Iwnoh!5c&WkU<_=&#U)J*=KJcBA4P2N1Nm_W6*?aEgB@;1AvgVhYba?J=ba}`_i z7J{st$ID`&jwsOqzlT1TsTT_4RIJX_A{Pq?8IYgBv`6*>gbbv3eQLZuIiAt9U-kp^ zsoi1f%6CGJ0o|p%t-@s8a98F{_(g1VT{%H!&Rd(e5MZtM}t7@?+VuKq+4anmHGrw=mF3O;=J^ROemH7fRbrc@G0C zaJZkZWT2O8>BzHOF)~)?!y4v$)S%SCV>+&5AYmdV=MAbgR{w*g^a_RsSJ z?~}IB|6lnCHO!8>0#@p>m3d*#LT%yO7sEoGPzlTIN}*oxk_EcZAXMSEidkk?LkGf_ za}m`wF{19-OTWihsb|S}O15Y&FkEJmA|k&v^J``pO@^8pezEkpI)WKrslHN;(9?7s zh4>eg&%Yz*BXa(dod1KI{{SZ^^};k1+H+<|wnGfE6GS6JrtGRMrx)>wO)`-9@jqZu zZdTB_S|e$ADMCa@Gn9i+Y8f7g9jkB{iv3M`Qr=B^tJRwhN*#DJsWI(%BVLC+DJ$Mo z@ns4JqngfFsuFJ&HKqq|RA=_2a1<3H5<_}(LT3RtEost-Syc+5#NoJ7@`#jru!#J$ zqgL17IzN{p2||8EkFY0&L&Ojf&eEG@We4P2YFiY4j(fSOwEt|o7Ds`WEh$*shG-<& zv&d=3eS&(t_hc-;ejIv46G-#rv(#V3*iA-Hi62w+JUO3`^PkB1kL3InIc(nA&4NhvZDb<$$iOuQ zZVPL^ZPzTU{)*LD;S8ts&#=wk2e$bw4m%7h0jv=fe;`-+c^NpXlz%BX^0HyhR-m?F zRMzY=Q?V$(PMfUEAxka9PDZ?G*oiFH)%G&Wbqzb2{?^z;RcJ)+8g?@Ot@AT0Ek%AB zb|O5YVy8u;-?a1s+plQ}OkTiFFI!d15Qa{MG|ZlEZ9QYB_RG7Q%L+D;1FwlmtOve zod1a&hDbgmh~Xy<5fY}7u%U(nACcduK4D*(w~>k ziOfouJ&A{ukiCS5s3kx{P3qB*-a+!N>TWt4vXO1S_t!4->y}^n`sKB~QOg&is3J^N zjG2B54D`Oa?#bgRTJj8md(*y$|DSqCSJ+6>xjvBs9$5X_a7d^{*93+qdWhrzr z2Y;E^DNH8lNf}b?M5wyJweZsAK+97ml#1&m7=VgEER`(D$Vw__M`&sd$>6hqVB%)g zg{##<=>>K+tfth$m&wewLVH)BmqD79@`ov?N@mQ;yquDTerHLvQ}ifx(2j#Hq7Rmh zDWlk`8J5mA6(z%~VA9e+=e6vIh9s}VQu+}s)0fnYDpwHPvMJf2q!Mapa3@(x_g$R; zR9EU)4j~{!OC8N2gtYZ~l)SWGgiwE#IG{raNZwM1bO>=GgiuM*gAf-&wibEg6(OX9 zw!LHsh~n9uB||_U&+aZ6QkgO#PY~?0LnXtjQU-+6tR#lH=s^f=v?O^edcLdsT^$_| z&K@WVz-!@ZMCyZ2#(+^9t=U#3WX^+}MwK`1w=hofu;PzApHX1#SD6b%E5@nCP$01x zImm~ciXZ*1RD5AA)OAG~Z?Ma(8$ZPO(@E(Xq-N;~LuPGE+u&uGJIAM|`EL0%Y-xv| zE`^{F`M!#CIQzrxN~FC24x4ToVbn2QQ-ZS^9@KMOOo&0$N-{WMyT@j#yJ*KLCUI5D zIA={pak1fC2tNgsGx1FRjshD(Mu8ut5}$>Wt5D94D4leBQGvyaNb#tMoSE(_Ayu)Q zk)WI@85hEfIoqkRk+E^y;yFAyRQM#{Ey0%ae-_JC$Hs6ydQTzWz&1PG;wz*DG zc`0%Zki%r(CjiOT6;kK2uKFAJvRkF7Eg_6vuDXal4~a3zvy;&5hT%1y-W)jz$akbt$f6vvw(bl!zHk4@_y1V^P_WaSFp9pJh$I|X&*Noq@ z+#Jm|wp_P@6Iu7PXP}r>cFz;Y`UBUD_uZYyvrn=c+JJ%;v)tThYF%#{$TSVCo?sT6 z%^6#B+SZ#T@2#1pt*a+~Ro!$Wc0IOU?ax&E*Q$HpyO^oovugXmR{g;4ef`<1&u&!j z`0>R%XY-tHM7I-e)lSeKo>nNZIh^?lt`$dWyD}}i?i$uw_NL8Ezw$l(3Fm3Fe&DIf z8}PePU4LWlJ9BvxU{tWKalN+tUTt^2oZiilYOeFU@A13y7J9d8?>2h3b4Y#mJ7@C_ zdV`2nN$sL{l9aC3_1vrL$$RL%f~#p@WmVFfS4mq%Z`E4d8oYm8%QbGx*HK8lmTLor z__*5Ed?ST4ag8nOzQKFG!F)5l^Bmv4-n{c(^Uiz=-qX-RYv-yurISJ$WYm`iwe6m* zjahWPZ})9953V=w%{1?2_FW|mY0(FihD>R1kFNI}%=8^h_Z`i4>|F0SnCUpE*w*$R z)1_@)5=8|HN_{E;F^cNd-+(34j6r}YRotiM#VI>8=qW=fYNk+6KBb=~imU{_g>MP$ z3}2O5(Mp7G2^t2zDy_09ZV9>taf#tCdLZ;Nq78%$iyrv;ioEbDK*oGi>}`Ud8(U4!N!nBEhWC?6M_gY`YUihGP~(7XT&{3Ns%Zyc8V*pOghY|-=sJV zFCU-`hRGoeje}68U|?3|qcaqAk{pK6jVM67V?bh!#Q%(7$vU)3>Bcv%f8(vE?ikkxhcko2Yc&UY%_@M_N-EDBC-^W5oZvak_@^>$=2Zb zE#t}qVZ0VqORlw3ORiOnO-k6n$)Zh`d8x{(1&ZrbDlS!|G~cFb%#iawITUHhA@{`u z=mcB{T~l-}E`C5UbL7xLxHJsEB#2dtmHiRD77;%EGNDfiulEC(_2_lMvEeUah zpg)6Ccvk)Abd&8`38b~Tw_zI61m&w0T;me!wi*7)c z;&Z$r=W2?av7l`8Z&AD#x*Vv%S!C8fy3h44k`E`}xF zrsWAt1+>MiY}l2c)G&!pH~NK7X@f{B%;Ben z;;FiCtddetd^1G{qcrDAJA_AW&1gW=%Em2X$cY|E ztc{u>y=H8znZPf5=JYA&vZqw6l&9c!8+)QNWlOZDY;+?A6hdi}VNa=Ztc1HDyabt- zAfcA0K#XNhw5BWxK4ncbrQD(~=}~e|c?9*YGSLllI3ik$9!1myp^)R{ohipG^>fi9 zlqr3(jPJXoDqz6qO;zAhfr^qQkE$4{o?EUcFhf)g-9)5Zc4#Js&}A;eDJhIaaVlp` zIZ~dK>pk#d(WQWvmlZV$uSs69QB&VZe;5n)4)8ff`1|ipyB#HGV~xfEGT*(M}+7 z9&D5R(HB)pOq|gAl^Wx8_t&+lM~SQbl1LQ!+K?0Nee6lul|FmVrt}%pQV%FG+BvZT zv!il$i{hjGDlOGFB?ACLfgz$t`w1bB} zzzHJFtt13s_csdh%edxl4#J%xF^6*NE3}}cn>q`wnB6153$>XJVgSfodqj z^5MAD zhzz_UnkRZu@dPpCv^Ji6Bzc(*kwkKSNqgsC0f653AXM)_S!T;C(&hD_Leu7k2Nm59 zYI|=VTdM^Vwhey|s=IDm)~dJSM#4(#)p8Ixl})SVzpC%OePpeE=gQ&x#+r|&C_0U-Of1 zz4@(eZ|{3^-#z;vGFkWb-1GKi-OaZaGVZ>O{vGT6!RSQFMyCEgRUDanmtj zmG9=^bjQJ;jIDW(-t$iUA_6N$Pv0YC>!aHk-OcyhTW>v`Mci^DF5|OvZhyA2AzRzL zUfY|g?R_t?K5!s|zuE(^%dG20x2Cg1aPz)GMear27u#0-7F?Z@uOWBj>}Z! z-HNCpWxv2KZdk_Gy9%fu9jIxvEzAzv(xuQA~BBru+2D_*{V8)xkbb|d4J0AG-RJRrcv z*XTG2(a>>`xQ(1&kn=C#;G<83VAyFpXxL7~&3PnDgzph3S+m6nfi|Ho5aOEuEV3vv zStOk+*nz`&0lk~JfEZY#ZmzCpy>=i|J8;LiR=Wer$`8sh_#OAlJF~uil5QAnCg%fl z^|fTWF_0cS_P+V}=MQWRpKuoPw!LngK$&GYW;Uesmxyk`t!%ggM1mo}5=;ay8-%h#@hIq1gIJ!@31)TxjEh6(aBxYt z?_yrbdDGPzDU&v@QYMHGt>ce%{8HJAU&F_s&MtW`i*eeYB}*lKZXtFqA}+b{9jrMb zM6l&2<5ThIk{9-E^qCv!D>>7+5EtLHS^DDue+HkUk#Dpko-B;(uRua5msU%*Vni^| zJY`xPumBSm>9(vn++=>9zA&PsKYi*rrG?T6MGWv0k;o9c6+1CBFra9D!gNXi69@Z% zL|`U95Sbf@;`Aty90&`S=z1Zce<6XZ0Rk72v1l6^872Ce2(+IajrEg{RRy zA=xbC+^pbG!A9rBJ$=!ci;?J}WJ|`1%vCVEG6shfgRFA8lNafWMVL8{^yM%qHY-4+ z3y?%wU^h@JEHE=y+i>H`^($}b-!{K#zFqs{ZFdrXu=@}9|Kt5@+eX&-(Y2bfw9&g^ zZh{q4+PoDQ*0M8eYlI0?+P38r1Ku`ZH`TEtZQGGA=S+2ZyTQ^8^lqvF8h6!Yt?eJQ z?6}+ai>`Y^U&$cd^Jmi5AQ{nrRkvZbJuEl6%2p0z$E)+vW?GfCRjiCl#|x;R`p`^e zYmZhct-YigL~|MQRX@Jul0JyjFVBGikw+x4h>N~We&qaJ>ICA5aRaHt_k$O2KAW~d z(A4u};pj1XbPq{5rimZuduNM!e2LFBx)6)e7w=?ErKSGUvhK2gFFj$t;95uNYG^Ia zNL0DIKL88xk}`mzitnL;BjO_<6z%0cjDEb^`iw9zT*CdxD@($+wJM z^}(b{;*QPXs}ybkA&IgjT`S5Ufez+CNlK*SzoaDO{5RC^vgBY33pueC129=U8Gt#?A4$X*gmV$)rB6bw%K&HTS zi}(V+j;;fyJ$|WKvI%?gQ<{oI-cNaan{p$e`u~a)}P1 zCh44}LMw}6NcYW2Wz&~OMZ%zBBU+g=gC!kf7snI(1k*V7EfMCEa}F!tp_5{?Py%=8 z9C$(H1dNP+8!0n(TGvcjm=&uAv4vittu24JHNmc+7uzU$J2@TX(8efs!O0m}RlDik zPfiaxy%ZufQ#MEobx@=WJ5SCiM$i`64?~KBFMUer`WKW{j-3CS9FBSj9BXWzqz&I9uUe|( zd4m2NPR>f7FBK-~(_oS?ml#rs>}9+1ZHh^lJXfR0tBa>OLq?l7hR5c;($`=2i$SEt zAD8$J_Dk%sI^Bm{>z{M3Uvkc0au)XI_$6okB?s5_A-Cs4Zs&(w_lI2XhQYFKsJUmT z`Ow(;p>f-X#({rJ{)7J;cQC^p{E%z>kZXrEv(E8LBQCtJzOncE-j(B@x;dTyLvHtn z6r<%ceYsBm8AlHMM|5lCi#!f|rZ3a!Kjq+j=HzsTP$jxFr?Pd$m91!5aRDx`T{*vA zR+A~KxoKW2YgsXD)cbBFGM?TQ;yhix)eEo3uEuVT-fFq^l{IJAifzN!dGp|pj=pg; z-8Hu6JCx??{>)Q*v-0NoHBaXX?s9*zOjmm?^oXP1M=5*ApzFRi_Xzi^>$)F}mY3_Q zZ@8cl^aJ&41{H1Yu>^@E1lHX7-%QZ!9XV& zE4moyCQC;T17YY5qd5k8$+wDu)f|pgY8Y6{Rd(d-7+B9$@6IkUo@q)lZBu&%d8JA z@O!wuT37jSt4`PZnOUdX{V_+5nKRq6)g3D*kfNa{&D9|O0o|xBZz$J2tIJw@WMJ!F z3D_{1ADJlV^Zexo&f>lHwRCwqKC+;5WUbDXkw-?I$#HG@GY&uba`-+@5Ni4v=RP#V Q{j(wO;R?e)_vqmMzurUxj{pDw literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/connectionpool.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/connectionpool.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..a3ebb091dd3b1669f08147c4ab26ee8cd763e831 GIT binary patch literal 39710 zcmeIb3wT@Coga8X03<*F1W14c-@JT@ghW!3CCd`6hb2-^OOz~8cFe>9LEcLV6hJT+ zpd~V(NA@IBDs@KEBpu0(=Zic^$8_y>JZ-<$vpe0`GfCrVcVmAPJHsCd4g677O`{Vnstm>}egcvZrmx#-8>eJ9`!n6|-l_PzifFh8%cW zW6pT#kc;JEi@D>TArJg^sW?^^_YQfPza-|1mk*UQzav%=_Ye7*-x&+UD~BrMRYO(r z;7~ALJyad98LElb4%No%hU((=L-j0PDdIH@H88&`));RZYKn_PV!U~%Io>kV5^o)9 zjkgW8#oLG4;~R!H#5;yM;+;dC@z78xzHw+{eACb-mew8XigyonGruR+6W=_vnfc3N zTjE=Xwlcpr_DFo&(6;#Yq3!J57kf0mV`vBSm&YE9?;P66{1vfX@!p}{_~S#5$9E6y zW?}x=p7`FOz43iR``CK`?@tWvXZ}j~4-6e({;F7Cynm?QBFM$#U(trgcq$dFe-8~E z!ZR2<96vI2gr%!SpB^1L8b3C4%pw#CvUU8ojZ~UXKK`bK`-e^-|5vqe<0)r7lpchN;!utSyyCYB9V%uqKS#*z#EoqNh%tb z6H_UC@(e1GQF$aXdSP&SQvNA*C_+oagU_Bi7(Q^a|5?119T^-vbwrLxveF+NrBr37 zY#`N8FN=aOz49248vgP56N@OxTNkL(mN~AhXCX`foWICK2 zJuk=QkSFWyizSk>bSjaE@miD}j8CSfjd#zXsaVW-^&LqhQ+?+n6X#@!C#X6)k(5WL z6j^QWGZAGXI&m&raXc}~y7TEsY)WmS=S1YvX*s1#^Q096@VxWR7O~3G#MV%yEiN;iOES>!iOePsDe?8 zDsnP>K9!mbr=~C(u~1RgZ;W>M)X6hP2alc{$d)JNRCp{Jlf#pVWRwO4nb}zbsS16v zl8TN+(F?r!A#2tb?mu{F|Jmb%;lZOP4xT(anDy|C)!=N2+71+HJ*&jBWnp<@G$G01 zR75!^)4cMAClX3L5{u5r;qw>_1UV-oN>UC_DKWehrxM|0ibmUZMvjdkqYAArjK0qL zwJ_5J8dVn=d#KCPvZ~4zElu9ni zjs@qG+)^>Bf74f60i=(kf zGAWKF6fqKuiN*kmlZcz_5|dM-=fy~pCFo_5dxv{yLgeQG=c zPmc%yA@}yOH&i1(qaO5rVp5*y42e=gPEuU_R|iT&H78|dRGvt6^YIkzAJi=e z_RQH{c4h+A^tkU98aB;uf5-M6*B`o;>-$&gk1f_8TdF@kXZwMpW)*n}qxu-*h44Z) z2gcyJAsFMI7PRpnSMdTw(0|{+{3tvVzELD$)W=nPQ%?X7zF2>!_>2&;4a^jG(lG3q zDe1!cRZ@E%SVAFN)|SG4OZ_qtiOb=z(d8J;y~rU+H5ZkAaI+<0f_mt@s&$>m!aq;( zd*ECa?o?D=OMPwQN=5r(Mf*behFfFvgTMdm8_&+4cqjO7;QKZ2)x7I@|EUG<$pyzr zWj~VS^$?ZGdWf2YRU(`b-mnb3At;CNZmy9t4A`BLsZQ1F>ZE>&P#T)OmxYYiKj-4b z=}QD3sIysdZSYWW<5Yn)KW!;kglS8tXy6clzkQT8_K=NrRMsJ18V$4FEFs_Xkyy5v z1&t)BFw9=H8`0VFrH4#H{y{?gqz}$zA?FsHo~xx-N?&&0^#;~=71ff}oyxd@y1h{} z)2{(2kzpPTdeaJ!B@+-&GN>#?laY~_ET+!O461WDMs*!fjv>djJ+7QU;7njmU$cIg zz?W6($`=JzP30*3p<*_pvQ|tGwvr!|Mki7_gjD3zlroXE5xfi)DbFB*{w?Hp zC{z4C5FSI&-Su2`tp zkSigdLnv?0ImuTlls2up;JY8N+TDBvsk~AA*MDyA1IB_CQV3&_?I2pMatX&;B)ja8 zilq{er|Q2kr-qMw@>8k=#zL4)6~kCcrJz(Tl_JC?)krRe%hXD4!eyjd$%AK^R40|; z>0O(*R4;iE?&GyUov21W`uEG!N6S@ekjhbua;Z_OK&};1ljO(KueK4nq6BKMTFRJP zOZlrkB~c2Xyuh?Q)SRtYk6%Un4i#$~Jg)$K?@mU>fV}BgI9u2Zjl(Kqo3@H>^#Z4j z#94@rafwH0QwMe=u@tHEz?G;-6DlTl%01_L#FiL{j~MMKEg@_vKoyY&i#wr19}VRr zG{0vw76m|FgC1&#pIQ^zmyDX6BGl^>YC?d6&^e+g0C7=*m`aE{x9By}D?>HYkVpJ9rV|r6n zWTGi}8da>zR#3C*5>P_>gM?8UM(uWCgt3d?l?Z#ln zr(&sSiY+6w9R%kTXIJ!yN5{nB;StRF3&X>d76U{@vF)NOzyHj&xfliMgc^)uWu}nj z$P|*Dm#0PcfhZV!r20x?f<}(Mbv$p31?xRlc}^m!D}`0W=m}I#tOf^1Q&E7@nVF-1++AOq}WtYd&gAABvE{vyulDpD)RFLSg=$R5}^utBXOQFq>{#1 za1IrlhtY}A*c4iF5mSm`Ve0w;?L0LRlR;c3(0M3{=fOIb)}#R=k#xmU-qg)u(+3_Fmmes!m(hoA0qlR$Dt-4qDq`~S) z7ikP>i;$w!>{p1?MeJgYxq-Mk>mhAT0oCC@?R&B^<~1zh8K+K@eu$s7ICd)p(A#8h*_u=`00{@N$!lu@J%) z`d2U%!hY>7?ZR6?e-p-QHNWvx22ggV@viyCH)%fODHWX)v{AAURb3#z!nsLS;(6j* zqmi5Ddq@h#CB?S_{W9xG5ig4U#(OlM@k|RTqBGeq?J?#k7+v-Og(%u=S(2fB;RF*4 zB(rt~c(QKxAci-fZm5P6X-^=5LK87t8ck|TQrXA?#*{=n%uqgM0|k_*JZXiNL$*YP z>dG*^fnS!0W$kRISI$w0hZm=UJLNou*%gu#WUZ4^sjPQmDsJMwC$nw}(7=7RgkT5Y zSGE+mg1RGQOD@Wh3yM6JbpY#Q9Pex}%;d zqqkzdk$}aXS9NgY%{`|O?8sWeN*vE5tp~yzjUT6gpFsFbT|NvuMSMMtb@vC98bU>I zP43qV&ftopY0=Si%XUke?_YLoz2m6TL(VNbdOq;h-0b-FW6R!6cd8mzsyY{|I_HB+ zRa@r{-*r{Y?YmP|cO!m1j<;YVxP0ymf85=<`#YXL^t^j+Y3Bgr0an)HQF^zsjvkqY zO}87i&MR}aWk+qMK19!&`yjW2*Dijo@k7Dl6zBG5+`g+vuN=L4;>wAeZ9i}~<*Wz> zB`!8o^!iMF152hA=<;6e{Yo#sd&;jKzjA!V-MZ**U1;0>_QuWZ`AxM{Z<*0|{I1QW>@xH^4hdd_y=Avk?2j_O56_07O?(~ft*qujHe ztwbOfVBE3_p)6yGU9yZLXzfq3%mAp37KQZ>DOxY=H?D(tEd(5H;!_&0x(}fRxR(gk z0kIxc;Gk2oYBEof%pzu~5kvDy0KuO=U&PhHwU$HSO+vE0icMnNXT;Kc-?sdwW!93m zfa6*`vr9)gfSiHN1@tx_56GX(poO(5&vx6H&NJX~r+{#Z6Y@n)_Zhpt*x4?Hdd2o+ zZ+kLZ1cKMPW?eD{Qpl;0Y$N7y)r`X`waHc_cwn^Nvo`ve zq;b_an9eY2#6ZJLeSRbOg4DkLC!|SUfdf7!=ACE7QGeS}f6KDyX#Rnt{*J?S)p^C4 zaqqy2SaFMsZc$wt>f^S%;b!2z)9x(Il?lF|1CoY5%jYmib2G^aQkJN2 z?5=zj(#FO)8>$)ri2+qcl1|sE^cF2iP}d-XjkULi0_NgPY-p1Ze{v21F$ji-8E;^C zm{G`B{d)a46fp9m*t~KehB+lf#j2#fx+D#%gT9?nnNA=vE=HonL;#sAiy$5eUQA80 zI)Q@&1mv7vF3VJv(`r;0BotiNA=#6!l>l;LjFI-#TU0}tlolx8{QL^En|KhzCU7<| z<0ZI2nJ~;k>H&YBumuKuW{zkd^%5|81oBKh1U?Srv7j_b{)@4brobvmh^)7%#bC_K zJu@OS5#$sDnX2Z2DGvgcKw${SPzcM-S|RM`NK4uN6v%0?X1Ef8LV~QUo%M%82*1)o z&Wq%{L=KZno*>_EzyauGco9Jo<;!q1X(gAMIm0ODV}Pah74(3R{4*p6u&l;@J!iX% zt$){*T??-II~C2h+7>!hNo3CEc9v)S!5h1-@4B()`kq^<*JoavdFQcfdzSotbN%<~ z1-EZG5SnjW4s5>T_7bwOP_^@&w(o@gFtqIMC+K?Y%CVP^-}U-$dpoYBZoF{)g{5G} zf}`UX_nQSD!&44gOl7`nTX6S(0O7(HuYB=Cp%{e&w$6NI=1x@`WT2VA=U464U(``O>_a1zah=q--}HT z1+zNnG18o)l>1f8dPN`}2142b8j!v@~;RrQebl-ST_v#+4^#%;Tl*X=k%(=1~3w*6or^=Bv)WS zjAQ~(GSLAf*jf1iC=TT>0A3v>876LeuNJDUE=|%vFc9!ut1Q8!NQ|T=(<1aiVk$S& zsGbh9SY;qC9gQfGY{0+~c{D;ywu|6b0+h=5CaMGx;~5(;jPDwH4ulJWi9bOMGrd8m z7I@H{&#kf80QA5|L=}luYU~bc8o>dpy46tYjDl6ZEP|LGT7E+eq;ud9ME(SoXZA9H zj1r;2##$4NPsPCup8?w!nmihF*(gEX5M!jvA@$50Hw`b%2CACSDcea1?O_la6fM_|V^A8hSIS8F5r} z3{=*>b`n(nhe!>mOmLM0WHDD%<*CT{0ymu3oi{w!JvXKK_G_MH-Ru1xsX+Ft z$8%P^{o;PN5NP>ODDqVP#22{ZufEZHz4t@G=c)LKKL`+d7Pxu97x6g$OHhv#2tq{<&gv7g4}5*h0VR6w zypCiuq`HY$UX)&;F4Hsrx4pnH)&y-$gUlyW~)4I+X zXjaQi?-4mhvJWOaQ-yRKHN_fV$H2~$DMHnQ7=xUkB-NM+S&34>MsjF70@kM^N_mUX z%}^v2(Vb~3H2ws~)d-)XF*uC;Fb1xQ<*E&ft__3@?Y_Qy#oxZ@Z(s6vEVw&9a8+JA z_v*!ES4YNQOK8&9_AR(u!2bx;@o2ZsE%|#E+&z2}(a32(9U=Mq2+7mXvKaggeFQ2D zW;PhtMbOf+LRYKkcdXi$nkFiU@?<}tCOWOBv;$!%z~eAzrsoCaQ{_Kxo3@4QGy9Kn zsj*Dj$YNv^^2=BZSi2^%-KUa5pbSX*d>R|ypeo8nd=lb6Xrw?EA0o-ARFBw+h0Fu+ zx<~0lE3$SJFp(I*n9~qvJzOlVW~DSzSP2Au5#ZGdX~aV-SHsmwQ+gti)YPV|c+FZt zj$}RR_!2mPbejf*c59ABmxYO%fsQV(ZQ-Sw7v(%n6WTSv4)h7`s%xXK?pbz)?o_k@ zZeJT+Xn6dc6YuPMzj>kV_^P$YUv}4Dm9rOlf&jB_|Fvy5OO{>YtuwDb``WY1j~rNR zKk$hO0qHmNSr%L(n^1$J;Ed@%7kpNN3#YJF3B~=i{4_ueq+9z-m%NGA(Qnq1_Iw=t zFpEzL%`~Jg36uA-KfFTydK`culaX`8Vq7@s&A`S>TTxs`P zwl~$857gN+zTL=A^UV@Ey+eC5p2>zZRCz7{+9>5IqQ%$`YtJebr+rv^CC1u&$&yAc z=2jrj$F(%ZQ-hbY<>}&dd6;G}`=yVW1OKdAYPrv#BtAyElJ4;isE zA3~34e&fmdtbF{K5u*9h<>SXSzwt!qfbpjJ-c)x0^m94m-RLBR!A}}10uj?TTZVcR z5^@0;y7ib}?^V1@{gwsj0WiOOnv}oi5h$)>Pl_Hdc{ZhIh$S6NmuYcA1eykXE z`V#6?HtRKs!^#S!8q@i4iYsM|SD7}G^K$ThLamG%=sYK-7v$Ye^g)YOPvfa{A-v6a z*L(oQ9hyJwEu6N{4AFL$S#R3=5_XGqecGkvivFTeSwsTw7u>HJLkBPk#hP_vRj4KgJXBZm>hMs1*+ z0W4BeUVvU0xS-nG$aG3h4jV)-ZSthNM*6p;i)>O}qlBB+q$Bbkk`x>X>W)P(Ai7yq zjPg?Jy-t0EzR|%kRe^-m#-@@f47VCnYm$DjMLdi1Al>`Vfk@AON=G0qd|#6U4?jMWZ0Rt5p9 zw}GizGIdR@JN3qxRyxDM2_1(XVw?t%aMxu1;FCHa_$gcsOfQ+IRND^j1(<6IaKyO= zCfc{AUorL83LCVsrTM4o_)Cm=L-o*k{zRrToY~-KQ5&Q2xGY6Mk3;KB+#gFObd4_7 zEnKRALCPC;2vE>tTnB7TBRPcOpAd(Stj?7}RUwwi<8Ad)PiXz$yMF4e8}BYn50hX6 z>A`BMqinh`-7Jj)$_HiWI{g4s7t?W7utGTvr76v+B!{67jrp55fmG;;HBJLPO=1d7 zv9}Z8QB@EQF~F6lq??zEw!pOYl}B8gMqCANqvxk4F34-P3^a!;fU24BPG)eL27!Px zz!77=@#JC(`Xfoq{Jg5L^K*#RBc3EUei4KhG#2@(s)uJuC6NBH1P*Clc32ZBz|d}} zXP<-89_>0kVn0_&L|3aywCkIwO%=u#${)8gq*Iks@EjUhuPeGQ9Q`w&fAcc=N8{a0k6hLZ5Ic-~H zOn*acX;0#nsdylyh5TTAcPdGW{R$QD!NS6^a&#ZbO}I8$5DiSko|nTapwf6F%CA#0 z;t48WC+By_AqIrx2krfs$;RLW4>gmYRjA}}b6cY+MQMSPbrX`->}&onCzG z^iuE)DYNBlb1d6a9&s zGfmx@jy<_@!BcY|)hNq7B2>4o1UD}RH_zd8qW|g(UwMJ_Z0c`*;kH-2Q?&u&iJPqp z&HLVUzw-i4dp4Z}qYZLmp$K9Mh&4Lr`d>btE4Dc+GQql)V8>#xV<{M#JAypwTjw0h zj_OQP7d`7UH4Sr)m&-oTG=_Spj!#~Bk{*z5>yL_z+naF*R^0WA?s|Bxp1g9By|*vA z+wc2Jp-BYMdi9+57xym~36(A1-o4=8LSh-CALcFd$#>hn-}PSCg0FSicQWIv{D}C1 zRUh3i6Fh-C?#4UrYW7!u#~sLdN_?ds3gzfcA1Ux1yaTPm=2v6OUAq?=_AGn%-l-OE zm4Cx^%?>RB61Q+h&Vqt+TdSJG9_Q$qU*hV9yk#Z7+IE;tN~4=qezKuQ zb@ngnq5hQWv^`n%30n8M(%P(jVngA4lC^33r_F^idy6F0A1qNYk;g~@llGl8KZKU8 z3BqgP^2e-{D^t}R*O7}p!bmjLC(bb%rZZ|FSb=Ru#JH@H&kWtgp?OtRfoO)PZfC-b zY7#@hz&0LOHV-PJsMLV66E1Alz-9#Y_9Pu>QHVRoEho_arjW*mGDi-v!I?xGA{UyJ zd=F!xFKC~*sRSA^zU}bs#*N)JNr(GMrJ|s4%^YDj&D(Dw3(Q*xLcCY^UfFxIb=lPj z2^;2Vd(Zsnw+0p*&2z=qEZ4T*4BWD0%7eGdn{V!zE6%vQ3$D65{+3(Y-!5MEKQ`A7 zC{I)WE4yA9yyI_H#cpFu{_ZRNOmp+MYHp^!{lZGeuEmaB?`&A=*nhieKMI=bzw4{I zX}c*ccw6Ufzwdg(_4eRDd-e~Web@GV=X=hDj$@17V+)RBe6^Sb5;XR}bS$g?8vMXK z!JRQ5eQ94IAuJgGw##&~!iGH7{AO(?@tu9W5H{KJ3G>(vp+dp=YA`l2vr8`*r9HEy z=@PJD3kzEGRwO+p1yKkc({_yw4}nKfK}{k39E?(#(pmf|T_ea)GksHqzOzLWrkLn8 zoq=z3j}aG&vlZ#mS$|4b97P*+roNE^p*nlr6k4v;e>RW~BsZmPq2vTi%*>>+lZew2?zdOJ_XO4lR$_AYyDXzG%L*6L3@O zw~BOdTxZd1F#v@s!bWcw?3)+GbO2*tQHV9KRIu7@GxF1X=?bl62zW}9Md^wO3tC#k z)Z%w*v5aTBg3e+Af(DsD&IOTNP1=(#lS*E7q`gdqy;gF}R;8W)*{cVCA>vvaH8xI^z$sjuhovrT598|wPv)U{It9< z()RJ>nvZx**BW!d)W=inV@l=dxq5BYeQXccQxA`k=oWpvriUwDE!BEBbx|t?{Z{~r zj!$dfji=<->Z?6x8_=>Z8Zk5<`l#Tjq#Lw0C=>q=_wTb>*~asi=-&Y5FE&&9eQfWt z`TNPeo33S|TU|_^(gouw!Xwyk%-SX>J7=r03Ln?PjAxp{3qa&Ta2;!27Ze&fyj86A zH52w)W~*PQ&J*?$X2O1`M=>A+pa|ft|0N;yg!(}+gyyCe^y^=Z_8rp0bisJ)m=-qX zKneeOwwj=Mx_Y+Gv_Ds;j6C#|dE(*2S}y5oeb$+Cs58~erZiEkLX^dyGIrWtGmaZ$Dwh+#u&9B+Ii5622nCoxUP@j#8J9SViO>(B| zj9fkjI@RHn1_Tdp^Wa={Of%syUVC28>i$*N~7AvR{S>6-QB z-P~uMSO0x>qKkq_O@Y`>?1y>P!l3Jf7GgZ1LH-F)`6WQ$Q5;S=^YMA7jXX8quabAD zGV*2Ua+GRZro(FvzHn(a5h_e5Ny@vL)E80`vwYdG!C++ zZY;5EK?|w;KgdfHB);pw_X%h~6Q7w2RiJnli|MtadMJ^L;6bNgI|6bw{flAuPY*(q zn6VDXL*t1FW>g>rhIwR?&YLJCoT6e#^O_0XVKV{dWgsl&96ob4n#5dH30Es^)(09EcKZY)|H9W$3WyoN=*haUt&LS0u}vq(Xlz)zEu z`c9KavGSv&R*+0UPzQliG64=g(T`BjGv_t}wksPe($a@oG_2H+d>PguMxwE3$}C6x z8$ATJi2gPTHL0J>LG-Z5%n|$_NYhoaj@-g zbQ1nXCqa|e>*_GSl1_rAFp)1T)uqLeDX1p_TGQ4$4QaG0(pHr$pbW-@URbN7vaoH- z)-E`Y*9A0uaHs7E|V7Rt0@krK)`*j0(M$)-N!^2{P6ZSWKT{TK6w!WW6E zP@-ppQ%8w}X**Z<60!&fnWfHqT-V6qVSZ8+HqU5trM(a)ccHPuRAy+)W2e9%4I63xd&P6n1?eT9#qIQC-YT%l!!0o@Q&>s$naW#tf+*;ecsghJ;z@rDAv0 z@FgY$#T(AVsE1&H63NkX6RfUgq($>B ztE*CT$cY&bU$b0>NdlHVQ+;6Yo^a!6!hFU~9l{ahP3i;>)9x_oTTsh2A@IZXJJ@+i zND>lxs$AyM@^uQrRmZ z)dn_CP)XIiAyqZ59w>>Oq&CN3hL(3e0=BlhG_7_`p>A%)_LaF(<=u z`7mG|9?!rPfasuV#SlQkFe2W8GN`%gL;(cNYofVG%nY?Q`MP$`0uZrgX=D@u{=8g< zhm{`lkaUKyB)IyH(N&0qP>@G};AHWDivH9c&oouJCM)a;kWw^Bwq#M)xWS4<4NQto z!^3%1p^7r7tm^1N(l;0zV zDc_LF4cEZ=pUF2*4r$vA&iMOur5G_Xf@9z)?x)02#U&4P{tPNi{}gXf76KkLdI6e@ zqw>sFhO86%(%G(r)Pt$UX8?mZ5m4g2BKNp4|13QfYS zJsFebNq+qMI>mpHoU4?mMBRk4m2_lOn~-5LR!o}z$~zR(Nil1o(Z)~z0)-26R3tpg z?p;x8DMC3vPnej{v&oi92%BJ&BI{+92vcGJT4kEq1|glnM2yMovknN>*_W(W&xxb# zp++vm|DUKbuaRRc2;xL4G)a_2a#;6%?7Yajv`vy3cZ0SwbUNv#l57R&0$4*~4Oj1@ zVFpUjGIe$nbl|NCm@Z>Mt=SDNl5z`G$d-;`DNHb<^~xVno&GsFY`L;I|G!WqWXadQ z-ql$zsSvUb2(ts?NfP`rVDV6gsVpczM7){W0;)CY*q#OyNd5#pgQJ}zR-vltX7X#F zpM&+aj+KU<#fF{*M=i7AmZ_?}5xX9nJIrmpJ-X}-ky*Ei>l3%0dHd4)fxoE#)B5GA zr{`etEx6!n%G7O~JAMx;3-!19SK1z3Y&2@RnIN6iOKdr40XmRD}t zR;ojb)uDw=d!P^}mM%Ez@4>)TTc)aks{6Hxxx*Q^|LVY%ft%Y`>be)}x|iKO%%Ihr z6_2XAxl%gD+>Z`KB%O)gdwuVG*R{P% zq>OR5Zo^95j>WniTc!5ORWS$i@^}|2DyS@uEbMahFaCM8LEQN7Hr(a6$bAG>2tN< zZ@gCnAC&t<*sGsAcJK2RA<%fQR3Q5?s{MmZUDLJxOk3xIulXllvWN#8UuD_VX=)#$&p*{yC#9|>JUfWKmzg3Mzs#%czRcCx+&g%=5K{>BR z%ru1P50$HFRx8&)-x{fMP2__?hO*oSp`rbD{n7dAmC)hE(BY-fQ4HP>UG*7nkc{i! zYQ61kzgyFIt@v)R?wajREm;k$-MUhHe6jZUQtiOClANvBBW7xw)xkLQcHg_53#Xr6 zsNJ+w`wTuqjj)ny+AYIepWDwZ`rSIR?C#dB^>odTE^O;xb|1|6n@o*sX5AjlIjOd# z)Fw2gc`LQ)Q#J1X2BEI$=B1UU&5KQ&SDLmhHf?+R#8T6NrP{tZZ^l)z;;LJ8)!jUF z>&WXTUpx7Bc-eIjbK;k34Kr)lx$JIL+j8x~t!>M0oWVD@!~fsdj$E6n#W`gcYTCbj z?ycE{;GPc!n`!pKjN+~BulK&z`}*G3_TtKs`uFN_K)bT@zED(2Ml~vHKgv0g;G_F{ znaLw)q27g->9LI1zTj?v-XpY~JT-UR`13OtN}tgFgwkhKuG~pVpKZPu2jvZogArck|%455M)? zLhIwp<-6}xw=ZmX{GGE*JM=D@up}j5tbv=>TaUhN`)(`gu>MKU!c(Ug51c{MgPp5F zQLt?8FdFX(&@jDx5?+7cH~T)y9krk}AKe@HLqx(ic^tGL- zw=Pu`pJ@}8>g@px?I_LRwA)0c@hNL1REs2s%3qN~*w}+6oMr+d*mDBHD?C4oGaV3_rIhEi zl(geNsA2dVf*4JdrZY_1chZJ}wvv6iAP8pZdX;G-(9+avj@1K|k ze)8 zm4x5u45KdW6D16Z%ERiatWwha+A05$!We4Eie>mA^U+B1iZV=*O;sWzW?brQV$Crc z@fY;1*60oWzCEp53bpNDQz8GE9KCI!N_I7lGDM-DCFgVGFiND1d=fd&k<&@e6Xg5` zIgEa|PQI^`!$=24SQrGu3Hrb&7QzRWW8~~7XCFBunsW)BDQYF8H{8@7=QU zoE=Z3_15G{$mgKDa-8HV6)GxoF7lB%-JFMfWkSW)oR@q)p<+|6oO~5Rd0oy=zJO4( zGgnEzDxglR1nd}r#?=~xt$nIHnl-f7vs>|)c zyPj=1JD#W!>Q+KNhfv*>bCM5t_LQx<$hSpk?VtvUZ44b~Q2kAVP3SaG3RAoG_WaG&b$>uMODtvyaAzlYp#-c ztAN<$g3Mbj)HLL3n73AFZs#?C{jAd3)dmV(9k-X-H?CF(>`z*9+ts>bFlrhy&F$0z zw5F{yQ{9l+yp7t_)S7FWw4)I|f6h)GwL6#>mR`l2lX)>jTXQbvMI$!lJj`1r_=7nw z^ZJ1QBjcCgGnKvK=n{$=STO|ZrazW;;rdHN4Z>`|(&ebt*J+-odc^j#ftX@EB zt6Or-EVKo!yx&S*K3i#`j^e-m^K+kN^)@_z3u?;iFMj-_Yn0ThhV*Nd=zYxpt6eYj zNvS0FoG@m=RZJdS#pF@1Vk*N$Ot@rH^0IHPFS&;h>yl;219f^|)=wLT={f;o&PVF7 zL>af}3@Ob+SiCG7m1~$6+m!b(DS?2g%Z)7z537t7ochMS63`Tx zNWlUtD_8$UQYE^%3rtdyA`A~x0A3iE4SePVEd0R)Rzk$-vgp{fiFc|V24@0fwIEYw zNUCzgaip82rHe^bv4eyfs!bULCvAB6f;`PGHYEeG!^5K_DkH9+=@nFXQhkktDFVHz zO&R4OVbI(>N-`M>tEb_30Od~xoi3s|)KajgnfeO4ixgI1A`u2BhLMc3Z&7*O_AToc zN-#!I*~Ll39_gin5OlL5zf6cqWEbFan{SNcJT-}XgCwrflFxRAk_x*yiDd_A8g_g& zi1QG$c49yzXKLu|H@oI-%_Mq`Z6?}H6qWjNVjBMf*iM$!1qA*bi&^jgN>y6;D!7mN zdcvf`I_8WD=}OXeCar0l55n~1KXwm-Re!^o0OLYUXcY@#+HKh{4Rbk$X`yrgZzcLS zFWwybn-6cqbz;ACIo?Y3H)u_p?v3!{&8>Z#R*^LiSYA_*Pq7^|>(J&-)~U}M)k||G z>o$*l)}hXoWY%SxHCdNw#$^5U632;2SbEf^ks27elo#k-Gw-t%>sMST$k|)F&Ip7u3{zU|Dq3s z=w@*bB(rOb3o3(nFU(%L%n^qt5P_R5H$f2sI{HNde~H0QeihMv0shh!!C7{t1m^O= zykUQSknA82nF|lj&DGxXyKu5FAmAWgCHZQF8rbrG*^{Yh!J|xj;J_o@2au^2*~hvK z^je+Ko~=9RUCe0DrXG5)&$Mi(i$t5)ZjxtguozWDRV}Ok8$1s?8K=}k>lfeG{tD@n zN*1Q!ZiNPB(F86P#rZHxA>(4u92W|m3`3|spXK8&pM_ms zGHv(hLGVsTV$me*rHHUU!>)}s!Da|3l*H7z^IWfy&K@7^8|+d33rb+;t$>0vywsSK zGz$kpC7k6=-`LF<>P@uD9!l6tPJ%wM+cTi;r&)U@>If$5SS?iEYM$L^hSJWotN~(t zo@sn%rc6+RZb%Z^Oy&&PT@N?gzPa(0jVk--;_ccUnflf%C+^m_%$WN_g77NYUnProUF*LPVgOvWWac=KyO~xFhq0{OU#FD6V&Syes{lCb;?_<1HR9R}6_^i(iQ6#KP!J4j z*OXKd1nvW9U}v=-dQHh=?1X%wYf2h#R_fQ31aL{oZEy3f!Ik#M7TX{DqkW6*$L>@# zWPE3tl~EW!fQ-QbM#MLFy|N3|8X%&IUXQ{VT$f~)zK^!oT~ux?d%M26f6A$lJPZUIx1J zK$f#DFACeA?{G$K6@vrI57cSe?b zMMgWpo{R>J$leM-0&b;F_Cyn#<%!Lt!;wsFMl!k~R_dNg;^M`g^Qm~OH5E&Ct47n4 z15i`=1zNz_a{rioC0H3*7v#iRi?ZbmaS5A)99jlh8~He}p?$-QFOjiI?RE?m8z=7H zL$IVgli&MjjgBEQ;pDhWh~eaoH&e@wHt>QVSKa#+CSHZ%l9vY%0<$LGrrX}8dD}|o z-rJpfA-o}x$K9$!@20*#{oeGu7jlC2w51JhWgA&m@A#S5ft6_$Li-lH9N7+aJyZt3 z+0WC|J^!AZe3rk#Q06RKM&$e_ikBwmKaj&9@1x{nu#ou(20!p|&OZiPW5zQ0%px%O z%zO+g`_Y|@GI~%6`mJa1_?f4goI^}L&LJjWmEdp41<6Mo;#>{+YK1^su8w^5#Gz~;AEeb_I+9Nm zsy5`B$=4z@Zp*cjuZ?`|Wt;`ZFtNKm$ZK2WI>Z7bi0-v=0~b5 zrW>OQ0esj|*AFa`(GQ6k>rl!}#~f|oO5#v*6rh@8Ylaa999LfREo6^e))55$u zmklep?*sZN46Bq0O-WlUXf&&K1lhje6c^8EODM4(Vl?Ql^zX;vdp`=E^w4@_) zgnQwT7y)xYc&3pfl^47Z7d=231ARro{C;q?p{CP(I+p#gR`!rJR?@bm{#B0`@>al2 ziew5_&qLL@$F%#)xeG}u|tc|6TR?- z>|B43%Gpdv*%V8|PcURkmPjxO`}C|6Ju(;o9>6mM-sY*VeD^)vUG5k1YAO zUhdD7c&-I+msH>JLK|w)yK5fCS$4fW0^fpT*9Sm&+ZMe$=LZ+OJKsJH--2W3dQ=eQ zb5szu0n|{Ln+lN>Zxr!n5gR7Y%u+W3m_;1A5MY(y4)`Rtl3yxwr4C(CIM++am2RLb zaFqyEk|C~>@Z`fdAgn68cor0^(g7M0G1vY~W|_c-F3c@?Q-!JuE^?BrlC4&t96@>7 zXZEqFH2`awkr>^*LjVI8>0tV^L!3%9i50~F2w3{;FoViaSEUpWET4T~d5)2sKmBX` zfQdbhDl*ki=u%Ed+~m;1`(_qBkfbD-G_VC!d$a9U@sg|Ka{oP_;Ba5F-SA%b-m)(H z+U5hl-|$Am+sWn7KJ+9KMDpNujhI5w6mBbRZQ&f!*F~ z(v1t(FTg;O^9|=aw(mIq(D}Y?*>z&Y_0*#4sRi3pyzkWs#=44nlJ)&d@Z8{+H3)?* zior6GnvyOwW%O5pDgGwQmUy@?x0`QHD>OPdSr6p$Sx`#ax%-f9=8=9Es#-(GDrZn;$@D&*90HfIm;ZufWkdl#tWB6@Q6hkn`Kri+%8b z+P4+kJ(;o!(v;kJedn$AYtW~JRl*;7NkQ#K>GjgDyK^O=aeo1l!(D#$@hgwR=$_s4 zLx&re_S!uUk|d~kX+x(l@84_v=a#)z6<{l8skCZzpb2eO0Xl=;ghKQA@F@A1LIp#s zi%ld4!9vCOPI)4KmY#*K`OdLR(FlFk&?$P(RPWDbOT*!@Dd19aIIPf2;TAzl)V0BG?Na^{;n`xIgHld~KF>n9 zY>?~Q{0@cKNeY-$XpPg=G0+fVTFT(RlMXi#`dK$Za5)tVNpg*DA5&b$!c?`nlj=R( z#*E_X=`?Bz(f$eoDV5f#Bs!m46-JbEtJ((a)=nrI-!k!9AFY6%!3s8 zA_dydP9Sd9&TmBjkixf9c=5sghxZ>H$hrykdG0E4;;HWOLVVt0P_uhLNW{&>(^rWvC#5w1ow}GvLBIK`Xj;f zBf*Q;9}Am)EHwRFq4US|*Y)!vr={rU0-RNHeijfcyMA6&Mq!%sGxGhcQLuFUSa{^e z!ef6WJn>_p;m5+Ge=tlzwG(BqsQXDC&0-`7HF{2oyWJ@ zS6a3$wrpGQZ(k66_lu8tEY&v~=Ns<}SZb4+EgG1G>z3(5BGp0R_MuRpYM?JgTNHE}Bh0n}R3v>c&<82pz($_> z{r{Pnou!s`SimFgnKS>n{pXzj{MW;Ot*@_D@Vv9@-zNWdm!kZVKHR5DX4IAAA=FR| z#ZXg9TAff;$_G+`i2%QY6G485CPH`zQ{i;gL>1QwrK;1Bi5gWggRix^-Im^>!w4Hy zsSWA6i8|B|8`Y`$bi+gg=Od}cbkjr==W9|M)6EmjsuEC!6{Ge|#n@oBydRW3O|&w! z4$yjYlLu|Xn6c7WZVu1`Zoc$38qChgKqmlewCXe(WVuWyp5ZYYF=mt5>W#UXp&J2h zHaC0FEeve|wAEL4D?>K{+UA39V`w{|9X{xGhIRt_j1Q`r+Qben*^H7c<`!?noebRy z=r$kpS%z*0RP*(+i=jIJ-RXnwX6Unk?lO0y4^RL-6MGoG8}L2mZg0FUhIRqkZFZp- zw{|zfqk!)^`hVBEj$G1v*8M+_Pm=C&-p}l|}@IiYRdJxb<=6>IJF@_%o{5dn` zjn~W2BY+S&@JCCEdd6-%6M>G@_QXOhdaitJ%{@OG{^sT*{1%-VYTb@pwj0 zoAG#|HXfI7*EQb_G~ci2B9qKa z<#+ImZ_2OA^A+_p3=J&@B%UtX+=Mb7O8aCDg2l>ka%f0h=|Rz3t9HQ%-BBi0Bk*P& zWJ%Zvz8RVb-%)O<6IJ6%w5m`;TP^pech&w(W`$ zgDMKG8@?ggkokf7jxwjtDRC;{#}2r;yTLi-`!x#6--Yy>3%skm7kuBPB4t*&9~jLC z`ZSPEh(;-dt=x<$h$xboq#ch(LxqrKrY6N^^jN4)OKLCF#N&ySZdviTMXXZOwA+H$ zax1>_&E70yZa+H#U!ml)+sbll$DPpkYW^!yf4BOhNXNpNg` zrwiRf4K^aVtvqUMdHdUUzr8TG)VOacA_*c|#Y-U~s3Eo^DFiKB6sm-2=R~Fu8qH?R z`vK8KB`xvGU%NCI9~(S#Wq@AeSI%F)Uo9G_X(J_ciUo}&Xx+qaB!zlsX%l8D1zev6 zjPXAu7r28eQbJ=})WK(OD!&LF`%Nei?)@|p2=_?3r78*hyvHG*{}#d{(2BX{Bw0^_XKp@#fQn$f)u8f_xVhKmAGES6d5`GRDCgH#uBph-{crN(9 zL)a>jt~v^`4T8;xE$D)mFdF6!ms@m@ptMX(3w*FasAZJ8$v-iVSV`-$NS7jFZD|9s zMm%C|UAXyir0Z!K^``Rz+O0{WM7z!uP|bS`Wim+AD@e181{hz#=5g!%vKt%R(u{cNcE4nF(QnHVd z)uc$vBq*WM5-Gk!q}WZQcvO-iRVgDym;bCK#UkV5=Ow8f8`F~{w{A|G84XY^VG27r znM{DFv`IagvNYn58I9z?xR&q)Y;3e5t0!6$lsu2$iYt8vB%TB>!xQ95kGewJ;^*{N zz)N8>1k8{TJdQF0JRV#>1g`Jr_O+Kp_SUSNNsoUf_O$84RkO1im^{^$bBYye23@&b zXvm7>R5GKd;w&A?#DGV1?isQPUw)YJV}cM2fzqj&qci3a;H*P%!O{T|$Iv<&lBbB- zTbPHHM~KE-b%I(-bM(&7X;ibGL4xz+9h~;X-9L+TFK>JHPUz#vW=VxrK8ou{eL;tZ zc_-6ev?8x8G{)mTEet%8nI}o(r%05xSx`c~Tf`GT`!2ZU(Z^NFrfvTb+WIL-b=MOG zi6jB4T1En2M5-Ikn2D@m%02G)@3EelR4O$Dmc`pk@( zfx4J9_6sQjdWEB)u7NS_y`bb}{FvvGes@-4Oz<*{iJ#!7sMD#VC6Vapxe zpG4(V|3J_mG_;gsIm=8UQ#d0@bcCr}*^I1|%NV9e&C+i1>GWabR&#Ok7|B&RxiT5- zsgY-~{49f^F2-p`_>l^u5ts|U8!&?Jg>7j*RUeF91V@;w_``V6($3K zmRBQ%R?akEr*#iVEf*%qZ`CLyIaDZ`VTl(()gtZ9C(P*-_#}E2K54_sM0#5pF?c-b zD(YG!>A;h4`rEfcs&9DIdiaBZ4~{&j`|#BdU;bx(srk~K>R-8PY3qWuIQ((M(Wh84 zSC*QDRldnvXl+g-C9uTC?pLj?@>S$o1L#mtas@w&I5Kp+CxJ*f^0-ZTSshg$2dl&T zms@wrceF>oj}GzsQBD1)VU#~nkjQgKeSHb%uIX&nvInO1%#>+J4)~(~+(9gxx004k zWJ>2igQaL`I_QFxNsTNXol-M7mC>frSGk7hQRgY3Pt@rcFagjZAo96Obm+)AKON2y zCHo{Dtb%;kWt@0}#BCOAZPnO5>WumXVxih$6i-v*IbiTb)Y!Rti9CW#qqRlKl_bbb z#~%zlII`4y`cAbcGMNH@7U@}T-*zYT{W{*usQO6|jn+`$2&Mc6=7k``WX3L0p%_Nl zQvz~?fRvC)Ws&$}b7BNXWJnzbp@qZSnb7D>ghub@U*b0t8or+>NFP)t5Tv^u}#khi!9Dbf8 z>X(QTd|imvIfzO+|3^QLx&|}nx@l_;I+7=A*+e2IEJvmc=yrmoE4yEqX@lTWDcJfb z(5_{{8T-H}`>vAL$Um0F%>DRk@X4!K6T@la2$!;E+VKj|lUHNhUF8+KL@P$gEUj2I zk~fuK2SVY9Tr(KPw%EwO$mFL{`$34(wfE& zWXzjB+a;!5vEV06&1!=K7e`0O28XVU51#pwoK=Es3UXD^+WPba$6Wa;N`3seg0Zss z={bA+_>ZXd4oX^(l=+`LK}1CKj$%7Z4NTJ$Feq>yL$w{P7ItCaC&7|x1lyl9mQ@cn z0}9hONYCsdDcMDqAbfE4EUBi3IfH}1E)+WM%rdUg;Yeq1K$OAwb#zYc#-Z53*a6xP zbVLi(g;L7~H;H{hXu_dfi)~C?PnkE&6#RM-$5Uz*LX;~spK-c^qOmK7+7}KFI|EhY07X9CELL;1%3wg^0UwQe&*BTD?k*DfvVEEHZFe-i@*Q z>~Tb?YWOwutj?7naz)C?Ge|8epFvuj)rN}^EIENaGbL1L8HJx6{{3t!M;>{3S;sI0fYfYBYzh#b76sl#YuO&ulj@iZjT(;b3!_4Jk@_)w%u#3RCK z*Od=;Y29KFjp4`Kf|vBHNoBkcA{^y@{Vv-0mI`zBj@%E?xwQugRG{V7u6v=y8~4UP zX!{`YKwWC?D^r9#ryGdHAe^X~k8B8+e4~`Zu_-;t61K9+qf<*t{sO;}+v*_s0=mf; z&@K0zs+8@y3ILupb(x02^o%`A=AGQy0sq!YFTN&nFsGsKkOk^W2!wlBmS?hv%Luql z>6c1nZ^9z2Ea@hJhM?p}_<3%D3leXFuM6+`pf5*Gw1$3GQqS#IF7~4rYIpn!Ju{F+)KTE29SkE9SnXZXRm=T*%yM6zr)X4=pl(T!OM^i z0)R(dSqDG!CUQv^mNStP{)xcei!)1up=Tx2$&@Y}r!8~}cr_rYXcI~^N%-X{p@d&4 z#s%{aOzyqF>j9tnNAWE({{rv3$5Y0_yq@5Yfa$lf#OQcn3VD^7TOk6<t*vK~Fk{=jIK4Qr)O^6l(As|%+3~1DgH>108-ihZ#62{uC-^G! zuPoJ}sQHApdD1)`&P!#lY_^r|;>nx`p77bx#_Eqo| z5392Lo5OH|l8^B7M0cOWlHlvYvTX!cMSv&NO7^L_$oBe?P3tU_`E0^?M)(ZVkO4DC zKCU4`exGoq6c8CYyraZs*==+(n;wh%<@$yUB*pdI?FK-<@r3X*IP6-O8y7Gm1-p9^$NOP zFDhBr3wj@z&SkEfM!w&L!F^&HxFf+7laQsvUb6xb9Rh>(g5P3-xCTVU)*2h~ z2S7_u^1qaMkrE~;0<8<(j+e5=EKogb+cP+91Gu~fIsske-{LKyV$GV)=2EymW_q!% zX;hCTARRI`$G6-GUd4&MZgR_Rc?l$=P0r9xisZE%9Jlc9!Qly~I4&bo9*KX2QE9{(yLJ-{+s-1oc5f}A@vt+bvrOQ_uK2~2eU z+xQamNT6kN49^2t)HgzQzUyLOYW^#eo~ji<$E*&)J3tYT@6|2)ROT`d9d(MIy7B@t z94M-IN38Pgo5?`FN>TXkSiZL$m+sw3+?liyCZ=WU(eTM8y1PRB5rwE;!i2pObMTvR>~2DbMh%N7Tu}%E`p9>1RWcc zhK=7jzl`L<3Y;W6ijh!QV#W0nsOmkggK0$rsC3%+zDyYRBI%BOmAn@T-L$&UJR-w7 z1H=U6QOWOfV3ISq$BdOwhc#e3q_$b^X{N!M3{pJ!ocfwan*cbE>kUVI&?`mFkXv4Q zqXrQcKYYQ`tHX3p3&xLokEW^+vTh%xdR9x4OtAmkk3OQ;$mK?k`>$&@-Dg( ze~zTW3EBMgB6+6-e_)_kd(jS*v}M;{Uih;M?_T7yva9FkyH0$x>jXaP`QYH?vrE35 z^K;;7OuMI`ZOFN5y9J-2(vgb7xl5Clw7u#a2_n;c<;lxq)aE}%r|JBhyL-+#O*lq_ z6^{|GbPWwkBNxJqjnC@-0icy_leG`eJJcN|^@NdYh8$TT6Rue29T%!mc3d0^T+^pm z@2uxpupd+8yD3aC&3OtF+(`1Z3g`;tDw<|F!9mhBl!isZl9H{2CDAWk&N(ER0Kv;} zb7+5E{(@#)F}gKd?lCyXunT$y_v8gjOIAP~vz=W)lxIs*8tRoD2HqtV)ljd4<%xiy zybhnxZQR6rJ&*xc;akq3_kv&KA%agRJX)wBr%#F;RQZ#PB0Dptp?|>>D-r2&H6IwV z&^p-xNAkL_w-+j#Mp+B_{EqVWej`S9q~$fQFI?{Cma94uwD{r%l1g`~H$T0w9t+q* zyGfGoGrrqW*F69ApKj2WH+9|_THdhn&dKGrSMLr#>Nxgb&x4Mo)A~}|wL8P!C4=^l zBhq069~3z%@`w_Nr|z&+c18UaVNA&m!hkGk_FVLT8mS5Ie4-$cq(xQANb8HpzO8Jw zo`WZUV#svj=&t>0Wpg3{`D{;%Y;J1Wv1?~Qh0f(J-(FNU&VEFbpyZJMPz+1V30{V| zcPI{^WOd-D?5cPIOpp$lQOBi*t5CS^0OKt#k9ZuK8P)31pgC)B#lu|# z10MDe?i$dY(NuOScGLNL2XeK*O$T*6;ot}aSsY4{*oP0k;-%hFEvQz83>XF84dA>4 zeIC`2<54a9JAr6$v{3E305|r)%SX6DouuG=pT@N7T)r+;8~n#GR-xXl6{lK0j~j6w z=zwMSwl+V#Fdl&)qn#lcCkec5>rXdD7i*SU_b%=2e{f-`|NK((1-}cW(!2ixzxj>~ zzR8W}90qDyMp9pN7&cwW2=it#W018@=9r|KV{YUZW^^`30S;^jjArS=V>cB-H{_6F zvywUh$y_6AuVQ3|;~JEl0z%>lGV%xzD0-UyaAGnCqYZyJA&9^VRWjOEsKQN1Qg6ON zz&g@)QZdHC5~ME`Huwx2))xzH1c9v?FITn;_59}&17`;Z&W(%?7ivqvCP8L-p`iqz zP_z6S3{RRDY7tgV#pt@$tf)nOd7HS7T2?!L68>ACLilnHf1p)}3?RxzYg(w1hLRu> z<3Fz8YwdhdoNo{F6=Un9EZQy%)e1nSb8u9fRzJ$W}IXKkJ!A1_(ao~$1 zMupl^^oOG~?9pd0FncrEMaaH4_HVKCi2X0@sbIsOjbGL|Sfm#kPBZUtBg@Q}nXfUi z3f|swmH)SqUDBpuvdi&OQQh%IU4%NPO@r{e~0}E~Q z=ROK)i+g_D^TVEdH$JfL{oY4A`?BZtgS(FbcI*3qeeYCe~j`+iyf+Z zM!hpj{hm>ak%+o$zO$&{Rcuq$A$2}VB||7t)e&`mguX`9$F)j}cDu1y*R1ZJKVMYv zD(;P_+vn$~>2_**e1Y*kUW|m*2n~i;u}M{5QRn9tzd_x+q895^^_;rULtp1GM3dUN z)Y)?{SyYfK?g^{iOV6MXZ)!QJ&VP++jxsW14l-l>g)+2q%ZAm3XBN5cFiNY{9ZQ}2 ziVEJv)@pU@QhSs>wia7M>PearUd0Ag?VrC+UG&pb`xfGq@1y*43yqY2j`IC7&vh=V z3t1|-j4?uLWMKpK6rrAm)P=40YN?DCj>=}8vKF;={%cFx(V~J}v8P_GUFcle)mMaS zTU*pr^{`yw!^KF0x^rRMQWOh^TydwWo>dnnsLQiFrJW0%G>M(XR@%3Pk>8-?jLJ;q F{{V;;Sup?r literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/fields.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/fields.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..b1c5e492ded37b8f3ff23bd1eb37dd858031cd43 GIT binary patch literal 12039 zcmc&)Yit`wexF@(DZWJN)M42LW zvr9YT(RV&HK%|@jD?nT8a0yN=io%AkI0Nm6v_R2bz8ui@0~I?kZ!ZPZUQjeB3NVq; zUiGQ}|LlVgQ_eLg+9fzUJ3I5A*YE$F{rkp7FM;cJ&p%APet?i)G3loAO%=)e7<-5|LxTpAMpkTtYMGY)(E4Q$6(9&bH z-1@!JFy%nnMmpj15ZUV?)=&1yj<Q%#x%QwCTeQW%G}SPx4@EhA1pg<@7srl-Y$xr{szpG(du8g!+` zBb6P<%9NB%X=VE7r^Ixoc613TElw&%Uy9r-nys+^xS2P}Qe2xbuY2tNbT1oX3_FJx zZfo#*gV|EWCZf1`G^)+bN9U9CeVRn46|FC)W@t`6N~5XdWORN(o5`f3S(<{UBhjg( zl9JWP{DR(MkWU!P$-1G4{~-L;5F|Iq7u$)u>C@oON5Ss3VE5{|2f@BO(pvD)$HC+G zUo5zf7kw=^#x|fTsRDrj1q=ieu(j`Sz%3kb2)WMZ`B?-=%_TcDr&T07e=6KF>u^Lf zxsH$}PIFszEKJhoC2rPdm6q?a>z)azcR8)mDqrNLI6${sb`OzzW}#J2?Z}fK1KO83 zNWC98uRA;>@0i7vsJUdH)doQ7xJWdcPiME+RE5V`M0Cxy#KHJXMtGNF{ra)r4;=4u zO91nQA5&<@q zp>vWZN@-dAPBx<{z$Xanlp@Y3k_?p@rzjfa47>w(F)iYzA6;wxv* zi2eOX4x3!|vP89HBAb$EY5`g+Q`r>u_XK5Cyf%|e%!qTz=^0H#s7c8*>m;2?_YGb= zbN;+|RZ0OX_KKc}_erqiOT% zKs2glGAT8ZRJ5r`hE7Lkw7FE2P9^%GLAPo&=z|8Q;<0L3@uZw!G6EzE${Tx?dT{|Y zijqNjYaZyq%D^%MdmHn}q*Du3B7#k3-OrNpcIH+tonaIeBIaqV9kqB((JXI2~werA#*dI9* zImA{Kh2!O9Dupwl%3S8EvE!z|5U=(}4ntjIH(*0R@Z&U+GH$p{AReCsX_$n?(xNz$ zK3UQvm_jYoRAYshv>VIa3K^r08P#HJtz)=nFr$zNy_LtzfPC$1j#I2Nx;kU~9QpDt zr+ZaRN?b`PSC!PJkkzL8UP#zV3~Hc!I)X}WA7uW3yFfUm>fQtib)Cy|OZ-*xhum$B zBR9QHvOxaKagDpnjol?-ht5Y1>3m{F7Yx)RB~iRVJ#gRjoS0V904;hd7kSFML{6kK z2`QzXirDqP3C-1Qko@Lf$!~6uj|0&ax=5EV-TdxaAo^b_O4r{DG;=v;*Bg!AP5xxp zCfB74lA1^+bNqpm;YQtkO`>UlwyHZZr?(85U;$xr*?6UUlOR7}Wzq>n7Z^r$m#iSv zbcd8)&|ONJJ+xdh065GZhbhfa-6|Vm^^Gz?nUj(!9Tqs5QuTn*+S>iFQ+Fa8QWUGS z9TMF|6%|0nrX$8hk*%8E{*n39QVE3JN@sB{$RAk^Pab+MMTR zQB&7kGI!6!I%0X&*1+XzGA}!1r!2hhsHlnh)0Id4+3te}|zk`EYhiMPzg3 z6TE0jtx6TZWM=&Gxxw+vFN){JM@PhqfJIrNay*7|6QpYYq5i|sL&u_r5A}+m`w}yN zXf^~Cx0A|@bTtVw6)GmOl!6T@PEybFGK;auflj7*0sN-FgCp5fNP# z*a3U+)rdfUA(er?z!cjG7hf@^SC~5ks+eZxVD0LOLfr17FnhqIJ&w9H!OUQQ&ZK0+ z0)qvswF+zsHP!(ur)an49D5H9Vlo6te}CBVIr`Y&Odvyj{%k56nR%S$fO*mCQo zrI%K>-5I{0UF$gcz<&yaa-e1L)#d(WW%=^TV8Qon!TBsj52H%V+V0IO@aBKRxyggC zYl&qLovzKd*?Ke^@wRUvT( z z?Sp5wWD0r|T4&+E@f;*z9Qdn^gS~Z(g8=b|@3h^?KJXnaIFJ56V1xFPUX?!<=n^bu1=s^VluUMM?~-~+KHW~l0E zsunyTiv|naM8wgo3TBI9IeAqMCyt<6(PBxIsW~==s@hgOsoVnG$;>>44Z@CEI83>01)@5sikDvsio)FfFS??fB1W&g6nCIci zHpY_>A&sH9VprZtn>2I<&8K^2tExJ}4|*V+MpD9cSKc*ihqtU&1cK2T3QKm$j-NWq z;k3K}l{Q|7?Uu$OSqJw+La7_G}kw(nYW-t-oq*#ox#c!6;96eEY==KrOy<^-_T^of7ZXFY@LZiq!w z6hfzj*nZt#!9$f_$Jg=e_Gz|Pm**`A$=nq%sAxl;e*@rl-FY40limSO07ZN%M_Thv zs}0m}$^3OE{9Sqey1)Zi0op>|nRoouanBs#^@e=ItPNT=UY6ut06i1H5G!o}!$y$) z9J=!wOD~Fp;y@w=e$_zyd#1{dn9=FVU5JZQ;6!EUf??!>b=s$D3lPQBvh$GIJZ(u; zq<%3wKcAtRisIOCd@ySFTlNN~v^_+dI*O?)%7Q6NfhNXE#KEy4R*KkV!->G8><5%G zl1*yA1#mb80D$+3qvuD5MHbvQr*dsZp)f6AIr|loutcXJym5MGLA5AvNpmp&fdNA* zVliG|5oAIGVrWvLp@^?aRvhmmd1MKMl4lAN^r& z9_dn=7{+@q*NBiQrVteP}NU?S2;?O_s zY%lt^Eo-YYg~4wX6W3h)OU&&_0*=V5s6;!Nh6s7QF~ zV1=Yj3&SQ*W@~6~SqO4OJk8EL@LaFgpbc@>lyUZetNz>hS!JZvHSmxSs#V;3lq$&Y z_INOSv}HVn4S`jyjj32P4NI>M(XWoHAc>0DioH|=u)LBupPfu46J<*=%rSi$cF@zX zXJ!AZ+6C~(z%7K6CIqmSd!`DYm9HKH4Rr@3pkF&kQ`@6p&swl&b^OlJ2f@Py_u(hq zEaVghqQ8U8Z88mKi(fC=X}Jd19cez#U3cUiL*&gcA(mdu3pco%9yqte9&0XuZaux{ z%nKHD@0rkslYoOxI0cuAuBy!28f(7(p1p6OfQc3vu<%T*oxVF(Kk20_^* zGIR4875sL6vuM5U!P)*Mz)jp5eY% z_yIVmK~Y7g2+k0&&;3_=#j9aM|AF#>K&-8$(d>gGuyP&iMAL>QlEd?|D~BP-cev}g zc%>gQ{g8=7BIcPH*4gBbi(!`$Z2BgwzAmsC>Mm&>^p;F9V5B=|Gs!g6LOkpK%JJ(0 zn}+U&R#ciyDHU)>%M81)BywXVtkvAEEg`QuVV~6`GzZM@Bh9Ug!l%A%%c(yZdgu!m zcXU765nkI7ez4=<(z*2=-HYee+q=IcyyxW7g~g%ey~SYLT2Qo3C&nM`j;!sD+|lk| zda(QWCru|x0@Q@Vho-h$3rhXXK{e05UBR>P3eFjFqLQfYo;}s$NsFIh z^xYL)?9B65IT({KFF+dDVq{J>GNGpbz0iOCladPiR(95v1@>7ATEDrIHgq9)2XfJf zC7X_p>Fk0+GS$ApTxF{-?AUCr!-SiDt8g65tIa0sX#@@lkx9?y_yIA;H+sVYbA)sU zd?G?G!U|H1U(#_%EZhqzIPVAJ1il~9Vqos7y4%X?K9eU$^;Ui<|0vkG7VKPg-`V>~@Q?}p zRrgBnPRpI4pN-rd`Eci2@9Dz9GlktlpEM043!LSE;(^G|I_`En3Ljq!AAb-&`6Y39 z&Twn~y^9xCI*P$vtKpA>2ldv@V%syfN8TG*y|8-nK7aqj{YYWY;3sXTOAT1P_7({?TgweTnp+StB-xuNVj0S_3JsQb2oy+wAd*Vc`1 z7d&CFv;o^_qk9xgUc`1SmLa+WAs(s1E~|mMO@W>JnT8#Fkie`xwfu2ag%0ZKEf*sL zbX6U6*dL2o+|X4SY(mq^8UeGb@MD+?1!^j@grWIja#{10Eg_WsXwKEwkESVRb%Jrg zh&W_?ItDA0L4OTS>d+w!*^{s77QLpY^oNrUS%zd)M_UoZ&j(O4JcX#WTw4&fDd#-) z`02L*3%Y3wqGq8Jn7oe38<32F{6Semzl{k3hn~a)gEMdx#Pn`!ou#JC7izNJSc5md z0Jr7iB~WbqwXq_n{WZnf*jO@^RU3NUS>$>4u~dD^!oJX*!XKN z568})A08Qsy*fB@X_z^joA5ab74za)CatjL%5?%JAOH~=1q%l5ufzLZJobFksx=7Y zHjkRM&VUnxcFXHVy(c<(v$`#QXb^VO3vi<|nBXCtzT=5zvGGeUj|>}ewJTT!zR$q# zljs0E+;tgNl1+f3twZN9!7|wKOK{7*j%MB#<1#0MlQL&=(KH=jXFl&&G<&n6H@+h8 zrc*cyv?v(1jNG(chGW#7xY%Kz4xvF*c(Iu7jm6-5&}<6x{#figSt(_{X^6$-Od=Me zXRxJ@#k36BMMse;+Ls3E6PQD&(pF5+8(^M1TQZjX2#VBygXC@U1s@dLr2|ClDIR&g z_{yuL#$Cc`ZavUk5-$N3HFlA^ z%#}O`gx%|{+e-r6fl5=T)POlRR%b7vqIdh3J}BI9U^^aj-{t~Be@Waeh$R=-IK-72 zFzYAY#*IeEZJcTrx?r>iqs8t}F?6ux=@d?^?+%p&xI-^H_LLeh2fgfN@351=V;__m z>wu^UbGe-WX>c`}fQn||>j@3QeGpEX0~>`&6}E4vj0|wvh@xpE(1QCkmBkMoU_(%= z>OS_FQG|VEME7DtjF0Lr15>&HUn^zO2C+_ji$K+daf~j~6c%_fIe-ZsH?mVhc93Q4 zTJ=tDx=$D=IYm+Lg3uxApF#p3@o?NflCEEqmS2&kUy;W3wq4BNXkArScdfPc7D#h( zm-v(3AN3ZU+lo%_J0m|BS#B+C4;7k2YtH?ZC3jj2&An^RKCp3w=ob!WJ6|9>ATWIZ zHpS7%wH5MXh<#l1Mx5*BIyXkRAa`t|2a^Bn$@AQaFTn)hjGg#z DCr2X^ literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/filepost.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/filepost.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..f7c9fe75ab9bc495e80514b907836f3b19005eb0 GIT binary patch literal 3480 zcma(TOKcm*b#}Q+EQ;`~gbGpjO^w4ur^wJ(kNP&cn0|r488S5QS=%KDT3Y##kJJ^@9s%Au_g)hjqkxP`)@7kYT)?Co;~?D1<1M zr5RWCLd?>#IUUOc=X52Fv)G_=#w2o9%VKJpx)o1fGffMpX3V^yDx?s11U=aW!lR-s z&1i;Vr8Uj=UBkcBwM@b0P0RM>iDIZ`*7mA6ZL0VW=owSyyWoN3W`u3(3^X+a_&jzy?-5T-fwt%O1yYr&ps zu;=dU_a^R4+$Wz-tpo?wfl6W(w+2i6Z&95yCZGcMN6!roT>TrzL*o<^g<{#fj)|OMk!i&P4&{74moo{q zWL>kUY-Z#`?+?n?qcY7yAXqXuPFA%vwFaFfW3qtD**cQeA#g^fe^vKUye@ca0!-JB znTmStfCf=!QN>7O+e-^M2szt#PRTh7QKL9(5oS6&m?361Rns8qvAs39wgfChnbEN= z)-WuqAdX2p+tkjeDTk0UXJ#?zO!fhR{jG~I{R{mELZbso?d5}a58jL4iLd&i>yhr; zCqF*<$>{}YBho!DZM1cNg9LGSUVIenEaSWHtp*RTx9?tj>v4PETKnN@`{4&;mG+^P z(9lyqu>IF!3Hj?YFP(XrOE&@pPz>$l_b6bu=653y_!2i4pzI3HXyCbKwwKVudVoT( z`~`x=Q{s0DE)~M*Q>gHtd3MTt)#FNWA%|$tJ-5WW*qtPoJhLq>XA`=*x;r@pe63Bo zySgb*mSxT;36#0X8I9l$(oPpw5?pE9c6GQMja@x2tbIc!hm5wJZPz>(Zn3j^V(=$(6w?&%AF0F<*V3ms-#*o zU&9Ljr&qlbZRDK>QDRHbRj)H^N4z^Che_CdzX){^(3l2iItvLR;8i!aK}<{p*Sx* zh61hLePcB!KZAYN&6Sei7>52<=*$SePi&)llz7{rKZw zNIjeTK%-3=iT)2KZcUWi%WsxPmM>Mp{cGWYYIxwm_)7TLs&IUxbNKT&KOdWwkN%2-Wn_9Sxxn6LmL?1ku9$!XT#NhhI2uUO@>Se1^Y)KSlIWpx+ic`~3VF6n^kYH92lJJSz4(~makbkdooQzBpjWG&Bdn)V}qP)Lt5 z`bp2Z`v3^i&ZA$w7@T|eKF)oe*FE?CyVvU`5EiF(X8AQNwkJGO-cc{$;w2&Bo2nhH zWobvkKUFtc$I{M3{Zzwf14rb#(SVJ}{N!$PaOGHXy#wRJFxq4zr->xqB$6BI_UpNo zP;P30&v)#4-e@zcUjy|$a-Egi!g9Tk>yy1!ZmU!$)!yVs+aUHs+@7|D>wk@i!kktU zO(s)nRE?*S$_RY>Pec{@*^3unI4>*HkSG5dhX@5e%zRdkN-`aa$5hCv#heQ#Q^}+p z!}gHXP?hyUDwWWXH&5&vUKk9B=jGB3C8ITK{y_|Mx)cyG7ZHNQAG)<6HzrZ5tn2o6b&iU zax6X;kA+gKRp_!j5l>1`kN{l$Zie9Egd7@AMH8V3naZI!U`U0gY3eGVKn(Gz>4Y4* z7EK%ZD)b(T#$qz|l?p|Z25yFnbsl4D98#iVav}{~B957a8coWn83l6m#lgAtP)*xnV8rwQd+X>;; zhS&zG1`QK3Sy_u!1&TG|EQwg9Sq{DcgC5f4J~tBPHBp~$JUOlj=W%N_9ydkfBQTP% zP2&|gF{at!LqSZT(BlIG>eTeWbbPu`jnZ*h?aL@Bnvo9DfkgcBz;s%jNF@hmXac_W z4@{`)^kDyVT60Ar@nl?$L^4eqD5&4e-vQW_Z2)eN2Z7+ixjX0bfu1@3wpa{oo8w;- z*Kpi1Yu50A<6$c@0*M8ZC6f?Whe>P3NS%^8h-c_vO} zS_fbEIa&{qf&&TB0G5l9hzz?-VQ$;1=Vlb_#3t7u9g*7Td}s` z_4KXuva6XkL4{c5c&r)fO#7$IFm24mX3T}k2^nNfm}k?_T=Ml;L`_f2niEr3qY2Hy zvMwt)5aeuqlCXdB^{w|$&qqnC;CkF3B@Yq3s6a&kKw1u+1N2W9 z1$9C)tvHsKQ5v4Q9+Rh0z+DPuLnEoAOgpebU_+T%)M>R<`Y+OGOuihAUAYLT%nI9~ zg2p47uoG!98J&_N5zQTmOr@lm1g1Ta$d_lL38TariAbqfBtjdZC2d6z0&t(OsjxMn zHJFQ_8UD&q05{1)n^SPD)!T&THJ43jDY+a%`)d8(k^phZLF#vwoS1Tvx;-TkQ*Pq+ zt=B+GM~vuV@VA0N58T>!A?wu&(Jg}3suI*Sb7YK@xSL)O>K;R=ds&|Srbid-l5b-h z{E})xz@rxSO9BXbr{t9!5W7HgIUyEVoqEXyX}6@~69FIecAXpbTp-~FT`LWiwNk8- z?F1M(%!^z5HYC2oF;=Z)WMi)H7%_+`t5gCOEsL;m{IW1hT-JV-D7<9DnAWIBS1d^O zcMJ?)=Tux#7H;ub@)~Rv2twPKEl#rb?{nYeIFcq|enb;M247EW9u`GFZjZ&sGu(|h zIzb|>W}0zS690CA3u&!aD(vgzkmdCUU~6u*?=2h*-ftdG-Y^@ z%yL<7(pr8%WP}YZ|KP2dMAcdqOibqHumb}e8s0$#2myJti|hlfd(Fm?m*5+7uG?QC z*En5OJLw?Q)11bpP_*T>2DCWhQB`JaY3voRpn2m|z^02P5}HSfs?ms=ieLt4d{pk5 z)8Jo{MQ2P-!d5GY#f^_}8BgZ@K zKk5{Y_c~*h9D{<7ZS#k~fuCjx!A1&M*z~e+%?exbow*rRqLxfLAE=h#3n#bFkz4O zw4&!u$zW+q3a;;w=nSN3Turk|N2a6dL|D|Bz!RbJmuF-}jet$AwS&P9y6UJv{?jl8rOdTFqVMvd=?1Y5u`@dS$*u9~_?>vJwzJsLxx~LM-W3H8u6B04m3||=c;#N*y#wz(b^ocK?fJ70?aRB5F1H_> z7gs(0f~P&_X)k!Xa-Oc$!0uvW=Tg(#!Mnk~>s$`(D>m*}I#cLAkn28>?>@8~I9zND zE-G(j-pIU}T@LImi9%idy4~sZJ!*gvKOz7gB6zGI{l0eM$VtEbU;M(!7Uzb8AFdVr zxwY>@0+`!2L@vQP%p!9^PIcJozym~IDK3mA5@(X>XG!<0{j=MSSxTBCx1Z*_&|@BImZ?Jo3ef9iTDBk# zy-0#4%Ci9AjMdoo8)6rIbEiPUR_Dm#-Umzwv|iAGCis zp5HgT>_7d9-RAW@v_tF9P^Ts6<}>6hDooTGRRJ~(=T#LT*YKQG7BK6_zyYe6o3xDE zaxGJ8UFT+Pv<>iVA#1l%x7msp^{Ln!CDSK~kV65gbQw0)U}#nS5YHhO#xK0^l(E*en&wWyl6f5&-PHscW6$6Nau0 z4wzOnZ~)W>M`M_8FkJ0+<LBdA1<>tYAtlQ2mY}GS6KCuhFcte9p@{Rm&il z^jQP55|e%_X(dcclO|PkQLtdm)RlEk2F%=Y408A)Azy+um=$N;Sy8fI=>@uORnd#Z zLe@Qr{^P1(;2_|2xB43eboi6P;6EO6>T&Y%A)*T$2-PoFKjw1-F{j>D}|jS!|~t!4upYjSHca% z45-|w5{t(#f-~5mupIg_;MQs?>_++uzuq9(MJ%ZRA@>MuxE1KWD;W)2XmnbSfy+=E^+BJtHqn)YQqmra~h5(sW z69=KSfM+k6x|WcoaT!co)~BR*+B62H1)lX(no2;0NJ37IgMWJz+tplPdg~Or@^vkQ z3P=-TiIgI1UM4opu~9T5Gyx~8ggyFkUV<#P47#%V64vl;=%1n<(gZe9HX-^2Z1Y6~ zsP>qdhenMVbkny6Omb>m`()ax#dk$v8gaY@f|$8)>YLCT(EN?B%<-1eYZDKE(rf9M zdroT#t#9Q}f4i4Nnz=-G$)3TyWp}efi)s^TWmMyVgj3 zWB;P?psi;~e)l|@#f84pxxUjYZO=Z~c_6>@(BkRhzC#}be-Qi)aRhhX^)5N?3B|7P zz0sd_9e&XFgl<9oLr1>vnY+WQ-Fx2t{N2wNd;8z>-uJ#gp6~tKKMOzc{K)ffU(7%A z1u(CAc0LpV%etR*^xhNRrSGNhrwaq8as#JUg2To3(9)^5pS$~9uDyS8sMy|BXg`)~ zKUNI&6hcRHp`#zl|CIV+3a|t_)?FJA4CMxfei1xX4EO!bbEO`bP^p)6?_)1jmx#$mtETd zg43ng&{7PvG5Z01W)JF`=GAYtt&4)+T_S?$esq$<_5{FV1r_ugr)o~O+W&Ru0f0Yg z6;5|KH{4xVj+r6YPs1e&t*Qe$UqrP2(3+?Um7-%S6WuJgtivs=%q&Xmg<-Db-XpkI z#ilg@;zy&LPiTHf0I*X68*K~*Y6WBm2;3U#!>Ze-2*F`II&iW(CKq_?MT&b8s}y1)WPo7g){qjayxZUwMDI4<^+=p#192o|?QjiX zh$OVrKwN?Ct_KOfEFlX%3}NKgX!2(q$lQ3xLnZjs?G)!#nJREIsrifqo_+BK9d0zE z3g+uJ3^PT*>Y*|=#lAqOFad*vqzSs!;@7Pduw|yA;IK}P8!onThkE;05Xq|u7$M%Sw5`$DFGm&1)O}Ps3p1A;TW+44M{aKhqh%sOZGyVV#7zVX#0M?ImzZXqxLL zGb1V{-Cn^wCdU|gRLMa@qOtN>s0p0Zg$=q9SYl0c!Nn)sKB{S5EZ)XalwB@W+jY@E=#W`|UXr5v0Pcm%-9mP8i>(4`fSwHO(G8xob5T&l(3Wmdp``I$yRq85y7k{apPP?U8KpXu$7x3V%a;)CCZLLu=Y&qW0B@PY26^6OemVucr!zf zLLo)=*7zAUo&d*=l89)&<7ZzOiM(+B+{JSz&z-%X6L=F=MLC6cUHBji9@)TMmWk;* zSOR|q&y;W_)q8k_-?qZ{JP1E|^K^l4%JEGr{7%@UaNp9^o2Oqr`?a$LzA?u){+#dD zNgUc);s3)bXIywgGO(|IAG}oyz?H~&1ev?yy&T20r}GHzAh1@O{xyDn3jvZ*^#TXr z9t2*Ns1bZFX07ld)ch~_D`*wq3LiCB_*lgXul5cuWw%;i$`~?;?@-2O;5it)L!qdJ zD7vjQ0UyICnnSm$G*LI1;38T-QhPU;P^{QEWY-%6P+?)Q$!c|G0TNa}qbt9eWu8GP zk9~VUdBGW)Juy^tfn%+d<||un(`bINC0)Q~PJDFpB6tW;H*3z*GQ8V~$MlynjPjBD zDAFaxrK?)x$F8ILbDYmnG@ntsC@9UqdgZu}$&OzU|3}305%ID_;3MMy6>0g1G=EI` z{)hB_Om=-t23EK2Tqc24zW&DWt0P|oOe0Uy-pxr8|DPAf8Eb>2N);(FJO)q;{X5v literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/poolmanager.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/poolmanager.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..c79a50a436789fde8356d075b9cf3c65c674665f GIT binary patch literal 24041 zcmb_^d2k%pnP2xDm=hS>_t7{=U~rP)DM%E>o3u!f7NCRhF&IoY$bsg7y9Xoz4`cY) zc;Lt(Szd=wyc^S7P7Fq_6}OVjYAgT9f7!02)))@87`3QcIF_?9V80^7~$2 z18}HaZ?;i*{q^hjzIXI{-~Hylm6v-tT(^7v`|Ou5a@;TI!ML0nz(1U~ZZ0v5Iva`Em%E9i=DJSmsSXtaPPgTcjrfTA~Q?)G58>@@gPu0g8rW)dnQ;qSasV0{1 zi#5kvrdk;6kG00zrrH=>9&3+xOm#50A|}K;r#cxNh;_xgr@9$j8S9DfnA#EFIkl7L zB*)yiF?{PTd)c`9ruuNNiUs5SQ~f-5i4&{;jGr2?agu%RHLJ7%Nkeb(8ay>D)=Z6v zwNtxn+$m11`x+_%snV}h;8W0GmEyM@GELC$g93^ zB9TmmQ_*BX8OL+^q#TY&GvUbVlZ*2bGF%ICY%Up1{E8+dXj3arPflJqErmr%J|2yv z)Vi0Xh?Gdh7GG8*@mMmE3P%%?jEWU6Nncoyl+-yXbvY?2)Yb(#d2JD8W}}yacD0%? z;VB_SsQC-YWK6B0yoqg@74u0s6`ENLDUr)kTnakW>a)oR>+>t&*n)IImXoqtelC3N zB`GB@YLC^du?be=<;3fW!avMvB{O-AEVav_B&v%f6I zRL^`^R-_PS6E7VTQfwAe;G;pG3n#*tBw6*d9ve>;^E6qZSveVJmHevvbqUYWn523l z5+#&IT++bUKxX2fZPo70P-@(2guK$azGUf3IM7!p(+!qHlZ35 zs%20eYSc5R0Z=1@ngBJMPz!?yb1Q?|0JSrS`q#lA0Z=D{x&U>Xc|8o;fxMjz>IKwi zz6~;{A9(`|qBaIiXox}7#xOyPBf(v&i&n~u(&Ez3yaKKxv6#Ttw196xpFs%AmlopK zh>DQ998L+58%!zzmK0$#OF2MO0FjeENIVl7}$N#FCNMm+Dgs^D*f&=pm*mk@_4^up-s0yU7JP zB89@D2r{62>_sW#J=-BvhV9Wxg6QAeGv)MTZDQ+@ZDdy4*vw1S8s3@3l%yE=8Afw| zVv{dbYEw|uhXA!vwDp(j@Gv}icH$L{6d1S~jB?wlg7sn>Wnh@i)}!*r4D-aqSQvD<^>XMC-Ym70qVq<1{ToMKmr|kRJY$f0TMCwjV&pAV>1(HG z>T9Se&_|-u23b_=i!x`iwIq37#z#|G;cYZjWh;WML7J=api^~+LPT9dA=MiS#gpPf zj9`B#^o50ROn>7Fg~Vh8*?~}~h_8o2cezJIj6WV5NyXRlbqrfoOU}`fuVQa2HO$ZC9M9w%f;mSp-?%5|*pqK$ zIZdp5>&~2GXTGUB=jcXT4;*dsq%n?&E_UIW<49lzpW+|ckb9d;^K-fY$lmJ7Tl)RF zEo~F|COpmQyscCzDns-eciTUrtc_89`*H4bgB*9=p0=lLS2%@#!=1LJ?Noo6f1@I$ z3-*Ln%bjx-x2?fOKi|^FKxGO08^aFNoAW$bLv$KtuRGF?FIS{|Mwzt3c!O~`2}`Qn zd}o^r7_fEU-a1Bv?qfu@xhkua0j2Fl_{-AvCA?sLZ9!kTxoV@Fbq78_@Hx{?%n(mA zBswrc*0(n*o;pI8(ay3bRcm0wm|WDF4Q+|;C}!vT{J-WWxS%KeJ1hh*@!Dgu6i!Lt zTa0yL7Yh*Ugybx8NCJ`oZzq^z*KXfVr21k9NjDcJ8zCyxnxo;kRG5bP** znXyQX2xCHtrlMCQjZaQqmSkx*DNBPIH=SKbu(pImQjUjX zpc0CPc7~OrE`cH~pbRyxGk!K68UYZYQGrR@#wdn`Gqb{CazVHnRnWVn5V;%%nbMk@ zkuHa?M8WX}4T*x`3dd5CoS^B6gk!PrOboq1&FN_(cC!gfXrG?eXJia=aF~e>p-2og za*W}jdBz9@mPHsA6iK*xSxP)P4qzTeSqK!m$N?cIED!}086Pq6U5)CKJUy*V^Yk>E z=;>*iYCHgwB0MRPjHRIY2=rF(;dbQu5cH29(m%d6kRyV%4u)dU*Cio2GY2IHGsz?~ zrX#U$VyqkXIn3|CMxgg%dm{|BCWwtedRdSYW5SW54(e^-+hSTUi4Y7i#v(D!T*cb5 z8k1?XV}fu2)c!?jk+rRs>7tl}W(s1gOqvN{TD09c)Q;vM;GRVo@cf5(?zcC+Afc1S*m#)#}jk z6DNIbs*1G)MkWS{)<`9c|2dH6S+&G~G`p7&MU?ES{` ztC#LX-i&42_djgux%2AU#P>eCvEx8?$AR3AXL2oLnNv59edBDwi5dkzSJQlZ;MTx; z`*5y$WckIst9sql{;(&wHjwMtpK+~M3R!pOV>ee>d-K%ov$xKEYdja|{td@FccV3- z_Xoc3`PPo*gk2fe&9c>+TmJj*wt^jR3vRBuWuvMqTh&E<>&iIuzRFeCeP2hutrI;s z@r`lnL07@cxdUJS;+Ma8^Kj19z3v)#*u4+90$I24b6;)N*KzYIl66N1W4m{4s)N*J z)k&!m!5o^GLxcE7!Y{+G!iFFqGogSMGusV_oixuF1*|`>gSRm< z0K*Iv8>)-Fqg!bh`Or{DqiO8i~TlwYAmH_V-)EVnYwTe%0#35m5vKhd2-u7}Jx$D?yAgRz{d< z0yNQL77FBLv$ZjeFHY-n_^{Ok8}~8uTM)^f#_*I>IDs#v_wB^Ba2!hOn8qZAhcWY_ zG{kg?u`xlD@wInE>Y{PdsRg|)E1x!~aLC9XrlxeuRG;~o4~+(`3K+utZq%TP!#eTp z>pFE}vTIQ2V%vReWaLsZc_}7gMDdZXpgCZwI{F7xjfbPLZPoYuL)90~|yZm_2tvZ#3dGKOrn6L|`pgvYxOU_u;vKv(}0W?EuJ>4|n2nJBo zFsm}NM6uK-e;&1h|?SfN6? zpnxHOioygMTB_UHT|GNb73iZbbNN6`#>bdp#QdIkLEoP>*#m%@{3P|0=N9>(ZTuve znGWbeYH-ju)PLqaJ!AFFIcD!)I=@ zwvvv+^%NYg?Kq%ELMu(%XKm0W9l9>*4F3%#$0RzYKADiN3V$H6pMh>D3dsc17NLrP zb`R<%*g;Zm%tpeAMFEyclmB4Dl18)DRIGChS{G3Lrl+^b%utb_Wf=x!G8PvlG1^O-<5R7mVLx?^@X-dMGAxA|Kx+ke+nyEXw#N17q z&P4Myu6j)KT+lARiWMc3BT;qGH<7;pFzAxglucxg5kh%}AaVlAvq)4wOs1h1Ph5QU z{7c6tf^N2lEllzoRB(<8x^;T1$T51fy?#}p^-leuOWV_)5Y`hT*W0L&k^M_lQSKta zt`@lA(T$hOa&A zYhV3h&Nr~`+w*YXQ0DyVi&=jk$V2Tg^a;;E=2#xZ{2f_;#~u5f$@l#IP$WD9P;dOz zH($B$Yk61?Re~=czG=%>c5GC3XDhq!99?s~S2=`&<-@;*9@Mz%SQWE@{dbZ`*4_Ix zazm8XxJ)`pM#!g;n@=*zX|!|cKbyJ>UI z-*7jAU%uyVev+OOpJ4Qycors@S9~e+1AyA;@K<=yag^JBS=K^Od;2wBvB6Of+nna% zOWTxQ%Yr#)3L+L3DoM7^QZ`D1ABYZvZj&7rHJIfu%>!cUAbM7c-kTOqC`_*K_c0Lj z8=jKLE%i?&#YE@GPGXQ_S~!~hq-dEi`bwmM5!FO*N?gR;qo(OM(GWV%rstiEXc0?%Z^ z1qu@H7%kTj6KPj{MKj1~vO)^0~gOJa$c)pW(FNRiW;q!I{@;S}N!%iOQK zV5WIk-LnoePxaWke{8e4eWQ7Iwt4rxfn4+RnLxg$|9;Qjwb@Ky)eW=G`+=H=HJuwZ zJF+!9?j-MB&h9+CvGYWB=ZW0TQ$MNB)tt>7&v)%a;j*l|!-6&gH5-9}Y+zvRd@k_Z zy8Ahe2owutCJ{iG4~T%sr}-o^>&;hq2x@jqyMl8J}QvLs@ z8oIni`-0Y95xFQOi^bt|Cv!EkjIcTgwb@Q5Ad#^hXgKz1i9!!pkOWp8R3=PP8#q)+ zBfV)&KqYNITU!xUVR*|UsU>j|6t7o%=(S86B+n(1LM%zXP3(8t$Rw&>U~WZW&wwud zF>)t|qp_k zcelPD=zdt;b!UIBx_{l@|9(yHS|C?*Fym$$elQytTzl=^FRcd#bAeaa-LGo9zL6--Qfgh%uEYM6eQA3Hj#B!wsKx{=B%0F{JJY7o z2M824(LuriR64E{RY^Obe3hkbKXksOQzGU@E!nd)bIopVH*KHby1CtutFA(DxrlM` z+?SAd&3=))$_LBB)tH)pMgm~4U&an;Uv41*#!>{!F74{V<_A4UCP;4r2?04kv`sv| zkRnEGc2jdcLESk*QjQ+wLCPGX2yp9Z(K?o}F$mH?ylHxRt4=vRtqU-kzr>;p<81E~ z@yvgVuLPq639E48z}2E{#+#Jw(ze_kz?yagjVT%1hJjg2H1?|RG%}_w^?cG!Gp6fP zwAE;1Vyo4171cMUR;F%*Rzkn#{GLAOBejjU$8L??e*V_;clvTQ1DWGsr1^%H-}&%b zD^tnU@3`|?wr)6cGGBuom96OqFD-%^SnZu_J@*{%CT~8Ut9b?QyL&UoZ+vRyQ#Y?= z{lf2>sIgXX^o;L!Z5I5oLKNwC$B{$!A8~sqJ>)#a7q$;?Y#%T@TljB_m;6LD9*u<&C6*M%$OAq0G(mJb z#RYXYJizo>b#WM0#3HGbX;9{tATb(#U5JhJVHrPRzU3m7$t2N|NNbjijKxBhwji!* zW(-3lB@<_q`OD1>LIV6BCj6HYt4(wzY$mL6lBMC57)A&g{N-%xLjElpqL_sD99pD_ ziFhbYHMq7WNkcc#L-cgffr0^wV*F@_7SAbs4Hhz}r_>K?+rnk*=$2o)#XfQLH`7h8D(WQr#~~T9~&kz^QJdBWfj?NVjNy%x30fLhyF+?T>+M zsl9lKKB+lgp%wZC6lCnARoG}5&9;ngv>eE`9LTjiv+izu-&d1w-}&9dn~7XIjA5?w z(Oce|_M0!~YZ`AJD%k9GZTZ&0wTWyixz&e8*K2$3Ox&*x76K?)sN^bzb$7?_AA7jg z9vH~#+TL$$g+;8cO=A`R#eT$Y`;pyqB;fo}1&_3J*c$nmp0?7L`9(fuuJ+QB8gff9 z4!#uQFisTs;TQ?pmj07TV$LM+`49|*?ELuniDQ!{HZ4BiT2d#m zrfAA!vW&?Kln@n!fsJ^s>Se+DA_d+nB=8zG)=oYAg*wNA|4|?mo>7vqg_INmZH_Mu zZCOp=W(eYcdhs_b@&{9@zw*Y|%GkOOVUdj=)r{ux40&SJvC$YrJjvSF#=vvgf#)9C zZM8)CwvfN#k4JuCv#T0;&R<}7n zdb909+hnKNc9rfCgn7M<>t!N*Ia<6PgYqEKWD}KfNGk1`BTZ)8WwIZ4+O62q zt_d#HViW;GaT^NKbvNp_8gHz-=w<$^oucnL)G3Ueosvj(7$s;nsM)u$>gby5)b7Qp z(Fb$p9CO{p?=@H~H*j3{q;?qZ)1K5$12+1qG^BcsytzIDvhHb5+Wx}|qx5x8+B4U0 zy)__t2482$c(U%86MZbor;X9gjacsu$QadiuTcu@dpB6OFYTMdefwpUFWnm!mn)>b zb9=Ve!27~r8@h)}#Qlyxwu@I1HzB2U05&G!B<^#g%ZEWR^>5$bNr zXpxXM9>#G^4m=gHUNGd7pERs{B!s>wOm{{&PH&J!BZ;~x4dNInT~D#kg@xG##G69; z)X$G#ZjA3EOeTf!m1Gp!3I*mqX`2%e%uIF3iN-pHm?eZAv2SK|ht40dCxi<14ht_q zTY|ufYE0S$;;5o5AXwGt|0RrWVTMKZ=shtHFR+rz$mlbpyM9F+9LMl*J}xC)O3I5W zj_M%HEhb&Tkv*HGdt!$MY~BbZp#j;JQpF_RP*RhNE(D9Foy zskcJWOmvP=b!yJo+L!bdNbz+$6k+Ijq(MQ`w3zDk9n_Tngpxm{WSjPNk@DU~!j59n znpb`Ll7)N{RqGHi3kgG8H*<{eKiDG41N9BKy+H8*H8wC9aLWWS{L_+>+ z4et{(@DAns$op+XFPG^6i6jQap*wS+%l{R*OEtyfn@(fi#79@gv5KIh)|)!&rq6%l z;L5>uc(x5QuD$9Ak4U5D!F)^WZ_8aU=2pW1q-nBiRd3hdt-lxktJ%MpefQHpe(guE ztq1yYf$@xEvvX(02B9zOZqGNhXKb0Vm5NPY?dnl@-1Du%chA0gHghzyxN>gO7ufLa z&iZ!W>wMtbn{Vj8nYx|6mA-Rw?O3*9|GiNpE2lS$vX8ud?(Vs4!wc`cgd}r%v$f}b z>zTF2jo_(l@Ki2%X5HQNegG$NS~BM!mvL=9caE(G$8xRDB7f6YbK~&J;nm1}U*~3B zbLQk`QyY45W#v;3Tl?2W*P?e1h6r|VW4TX z_xt-E1cDFiTW%+ACGNa>@7ja<7c!?{S90VelkKQcH*EHRJ?$&ePdj8I<8#_*AcbvLkb1Glk zar^wO^O%X_@73-`WHJ;h45&}*R>4u`!KtIRjr!hfeeYV?J^MSCevr?XK>eQzHBe(B{d&Rw8)w@=+K79Cr`-M$+<%YW@>u!1AZp#N+GN~KsmGtV# z^`3p%z;o|ZBY`LF_m7*n%C_Hd4m202$9KOE3r1z57VPk#a!0Fhh>xBt|~BMsVq<;4pG=E+~eUA1HXG2-)a2SU3*M263SgW#?mON5WY zI4{Svh1%fOcEfF|4ZDKnkicBGjs&{#I=aTPPv)bzD@;d zx4hHO#>wQ!SgPG}RNQz)O)S;veK?DlemNZb%*k*}kv_+Q=z?C&)H{H3nvID;%n{zywU0B$@c3P?hIcPvV|a%NVx*Skk@-q~K#7IO zp|x9AvfZL`W%3=WNFpk$A#ZHOQ>GCrHm1_;{70%_wNCY+jQ%<0HW;{wyCh?G`ALlB zr4SN>(T#)4Uc} za+{!UQ$i+p`3IEzF(q$PLPSz6*JCy#QY?nUg}l6sTo#M+f<{W4sVF6XMlb#x^z-+0 zSg-?!1&{JvQ`_>1%ov>n>>XG>yI$Rsa}2;T(%hQgbD-b~I1g^t)EAt%V-HvFW;uA> z5iEEp&&zo$e(MADsEc>j7Rubty3Ojrf)jTtzq8;X$jw#lD0m1$`Hn|Eg4(%f4i$Vo z&I6m3H3cW`C?BXUxCn9+rH3CfOTKpgjs#-eV5=W3)67N?Kdi$9 zq;Qa#OxH+Q3EelKS@qdiw$#_99ScYC!8F5TNWC*oJ}?c%h(^Lt5v`_&ane}e^uTdE zunJRaL0_1)4Z}v%0p#=WV*lck|!h?usP z!~ut4;h6EG2F#yAt`Ig2Ca&-TswProgJgkoPfiJ)hlkKe(H7RU(9~-4iGWNa7=xl2 zSTmRcSSsOBWv3!h6i4W(kZ~YJnVX3RvdGo9q=@qJv39nT(T3 z<~bwMf@3rhV|#Xw9;CBI<_Dm!PUn;uqJQE+rBAL)TX-g#7*5KUwzO;=Hqz?PL&V#9 z+GzLIZqlKqKd31~r=>CO{Rb*3U@s4+)fkr$Qv>AN4^|W~ZJY z^=Vg{Pmu|RU524o4#K-y?6lC|e}_dImhw8`4ZO0YLKeQm{i*Z1H-Wd;y(#oTyVBmb z^d2xHZ;7@9OJ zsJz8l9XG}lWjJTl?>*rM$TV< zGy0%&4;hp?`ZhX7vK=Gq?Yr*T@16Op@xK^f-*fEU-S1xf@#lZ^`Ss(I>#Z-t3e~zJ zbM9ef)9O&JvM=M@^i|$?Zsoc4j$K*bE<`WidHDyQ{oZGD)uZeFQJfgNvGk24D@s}V zLF{|6dq;CM2M{k++jM*U*7%y^=6J4lD070WOgO2RZ|lF`wrg#M4(m1NJ4fl>{;;(d z2BN&bC-3h>`pDyK^U{kZ7;pLpf3WnurFD1n>cOnLCqJ@hW8_G7TL!Z3!8}g7 z3?I%8AEqLQv+jY9+~wMN!KOQ>vhJhnBS&)XqgoIN8BL9g2%4P;8W{zMt)%(8Ihc%724rFUa^7!2XarNXqA3}a=cOm4bwgQgt@(LJPE9+LSB8Xl0 zk>5DKa(;F4yHjsYeK+)GXia>3?(UrS)qnCC3KtsO9xjA0YhDDiFC7Cw;qIa>%3rsa zin}Z2GpFDm8D|@@KG?79q;2qo*-M2ESpn$qp&_g^=vcaG3MLa0e!I=k#PsL}9B(7) z0L5WU(9b{6@2o(rB;o!@giLl!mOTww$Hb%~85Yh{WGHlnBD{!{07mT>;eegcfMCg1 zWQ1C#p{;bB`y)Ds0Lyh?c<$k^(rYg?7pYkD&7kE)ti_k62;qiSciYGMoCz&j5r2mcj?ol@Yr*uq9qKGiG@7}EPMt8%2Q^Pfv1=SHm9nLw<|7C zs2+_%%_68eZI2={KtGvkUwXmtxRM^#HxWE$Dz;?&Fubf3T?y`k7_RNU&0&rIkwFrc zU0NnuNDU()%+UBM<;_q+YefDvCD$k+Q=)O|kr_GJLLy9-i$|-ojJ)C#k2;fM4x8F7 zD+rw=4_Ta+O%k<;$GJ_H&BMU(TI%hkyG!rv-FWtF_Sv&P3IFW!PcJ_Ryb8-*L(}cq zTeGVd*Bo#A@A`A~`!c8Cec5Q;lWpB|@7OyHxz;0^JK>{1?aI}aFRfm=qhtfe@4=6A z{9QNzj<36qvvr0D=f6SI$pBPA{|e;;vhJ3DT^+ z1Zmb@g2-n4+j4@sxa0h37;Xd3MrOFBd*=)6dDGMR2=?v9LJu>~`kg0uW}amLnP(Y5 z=2-@id6ocXo+SWL>PXpQV-p$C)db9`b|RlqwpKh8M}LVpW|8Kw`*~yck85jl0tF!k z&?kXIg)NO6fQuvFWJ1Q0G;OUqJS}q%eGOUP;GOPu-{4v`pmoQfwgJjy;^<4|SWD7p zh>jp!^K;wXCH*L}WhGLZvbAtocgE<~4z;+0P)H_5jh~F7Up^zk3wnZfi(}Sr`ca1ADskf@v zl3JKnpjKEJq`_-C2x(nR-%!2y!3E8crm(|^%5Kgr3MSe#x1B!}!?g6USaWGkyv` zv#P|@Ds7(d;}1CUPQM4NFmE7!S1Sau0>Av>K`_BtOe#)gjT5FHQ}RtpE)!1gI1EeT zB>gC=<^m%ctGY0|6jQGqyGm1O^8K&{r7av=d>TNd|vip<mojPrYWAs;|EF5O3tv-_sg|Hz5w z!Zn^NZ_k|B@V90CZR_p(?p@9K59g6}aihFFTi(9jvHu-cuKa~xJMFc$b*>UrqI=)^ t;g_;a6YE_4 literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/response.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/__pycache__/response.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..a054b95535183f702afac95570db582892da84eb GIT binary patch literal 50427 zcmeIbd3;;feJ^+~c9I|g65zgpi%5d2s9n@%iWIGtazr||X*(1|fD$P#$^~eNFlEb* zUqjhSP1;FCHR+gcGPOKT8)aTHaoWy{>@3YpJ2QYFmo&`u$*KBj)9L38ZK}_X^FH(D z`#a|@0C*|OeQD>PcO@R2d+yopx##@$^E-c;nVBx&x?KHNgW`7t;cw|ixzcz?X$99Tc3^nruC(<-}Jt8_M6d{ zfnVc@eKfN#lhtV&$r^R^Ia%C{cy?b7i(5uqqwc<3Q3#|BH!9uJekF_F>bH&Lj~4V5 zh(a3vvHA=9isV>HU#UR|l;N*D;6Z2|-m8^XV*a#1>2RlVr~STR;PK)6wKOI6h8$7y zydm<0zUn}=Km9aHN=AQ1-?}lQ-`=+ly|MZ;N9snseO|nm)t`kv*Z0-4xMQSYw6U*| z#hoKfqs@KIqb+?cqwD+Dv$X7y*3k`p8%8(wZ5-Xyw`p{9-{#RReOpGi_H7;A*0*hR zd*Alaw!XH}9eq1k{+yAWqr3WcjqdK-&F)@)2KiZ6!n2w{aiDh4h#Dvd<_9b7P;z)1ens8!it!BJ*w}c;7aAHL3wGl^YhZjV z6gU?e^^N&X1|-U{zqj{+BY|KL_qesw?Xf`c3<}V_H8eCD7@r9JiY6xRbN2dz0m{=c zJ~kE@po+t;FVsD{zG?g84c^C^m6+Ec(X{_n4uY;;6f{kQhDPw4-rxJk1N-{-9_@St zcUe@`{(#RPkUED3LSAFsP7U<*9Ns5M;}U6E-f{nA_jqW3 zD0F6I=tRf(=o!52iIG4&qcbot?ho*K(pWiO<${vBJmT)30uA?^>2_n$&_7z^{UKuDTIBqw=%9~d7W8Ne{AmkdwDl@cUf76L+_ z=obJ>O@0wG*626;4fr)p8oicy76vaA7z^>ikOt(ktS*XUjfpFHte%hzdjvs&O3#X~ zi`}n_aTi|e01eqFY6|$-JHKv-n}UIn!MMrq3;BXnm&fzT)|SxdnU*s{XPQDj>0}_( z6b_C{VgF{S1s|v7%w*`)_*lz?G=jU0Ey@@)pP7uO`|-6#&mbunE==xov-XG}=t>5H z3&K)XMJ%f-VyjxgtuUbW9XI#zUQ#9UNmU457o{5f1gQd#REIEb9vqnno(j8Dy1`Np zB7;;5ICwwFPiR7jH%~Y0G&$=UdD3yXP`~~d@o)cCKqPhBx1p(^^d#pc4s*yio zj+o^+V&QWHIK+s#VxBa4ZSkzmz~G246j0`h?wB59_4&mqp&v1R`3<;JbBD}I`mjZb zX}`+cLJ5LF z@#A5fhsK6N{r%zm9)x6y zPY{M_nx>=%KLh?CeI<{FgA`U- zxG-fxYT0{{H~6OrE(q^BT#K&!=|i_1t{0zv{%OQ7Z=c=1;Hr(fYOk7NuBM2+>6Xp@ zV*2yxGybTp=qu^V276lNVsZH^+plb2C~k=sw_G#DiZ@Rme%DdFSXnz``l@5Gv;sfr zi>~sBz5L@PR2{w;{!p->Tv^q0=cS`d1tkjw_0fX*Z+CvD`}OXtdtwDUkbYp!F9nYD2n?13+On@k&@&Y# zFpwH{r;I)W=d^BDTnGRQFe;N5CtrN};?psQCt~x+5T1kaxT$-5EFiT|^&1epZjm-p zd=mwmDcD1S3c)3M9}b%dr%2nBpc|23HUa|TMzeP%-EFSC(T!gWl%2^ZxMA85wl0!*Ss{40VH-QLtL$L(DQj`j5RAK7g_Z^e(dgAt;huRMxKKf99XM1mZ>gyarg%Sm0_>*5}(dE8yc+s7E;Rs^S z9Okb>d6Hg723O)rHJ&8A&fO4GM#8Hl%^nl#z}yg5o@1416pS8J^ot?n;@2>hOu53i zS0G3tG)#b7I&csqf(jR2sCl@lMJXY5!1Ms`Y0Pm#g~1FB1xy)~!R%oy^%T{tGl0WDYN?lo4hiM4KIxTo zr#?~K(mRtpMu9w>) z_R__yoMl5=X5OOHH50l#IXk(K-w@4jxY`-ZZ;d)zXN=1^g1dlY-MXl&Zo2bbSN>9d z$z0FN;fS+hiK^WeE!qbBcu2*YS2ujm^naWH7}Iyh?eaDTFzK>Roq;+d0|~gbX~^{SI6yQ&%EpFZ8zNO7M;1v z4ix(&NZ;@WWqY>^Z*OnU>2w%>l4(Gg1PckUGFbTEh)Jb=s7N1$W+#3DhChFo@)BRd zKuxzq44Q@{r2}-Ef(buIX%rANW-msV&|u!QVsn}A6YtcksE{)0UzmK=F}>CHFZbhIov z^XE)+BUd}WbKvy@3yt?h8}EC^*?v1Ybyu`;*E`PL9HpteCTgegXJ6BgNaEMjM`Q`# zrbs`B9)G6Hf*xVg0A7_*l&mXY0DNfo(}+)3@({7L^9srZs}W#))bXgj>8K}q8(@iO z?pS_Z#96oK%1c~dM1OkCy7Xr=^(AG&Jx*y9d=-C+{J>^T+jA$&n3m5fW{>rk8g=kq z$+W&;$gj8HRM2#cRi;rLcUy3G`wUo&_~iVWXz%BYZ($}c09w5rsY?kMHo`eiCP?M*Yw*2meO| zkQ})37xRlC(t5>v#k)|{94%_T8j2NdiWF|1KDd~ZciB7Zz1;Lt(|qS^2VOm}P`&*| z_4dWG%2$T23@wyxjFxSj$yh4!ER?iHOIl+k8y8C2qb2RJk`9n4X^YOH1!qOnSutPz zn)g-jLgkid<(6wt#wt5*Iy;xG0;CkFwa2QrFWUrn{^f16+vX0&T(uE+`|&JTh8_XmGF*Z&_Ko>{lHWsL#4{B145`Wj zd@)VJa2hpBM3h0#QA6=Z5XeGsF0~~{9L`SsXbk9opYqW&2pr^3(lXl;%c+{~kVQS0 zcfGW0DX$_@d0#BAJ>qN!@Si@&2JW87t3lK)QSchIL|tUk;G^EIj{WiY|a%0P+*_#%(ADI{lDU_Dag<(x6(!EO>AN3sT>e#wrV{02r zq0|F|9tcuAdDTBLzq)0KEfK zVl{d~rvhqSNCwPCk}sqcI+a-Ikq3KvJtqT@+(00L+GLS_(>}RbwJOrVpsK;4zz7}u{PLa-jj`l$iAvz+?5UxFQ)*2pG3hxQz`M!s(aattvEeie*{pw# zjr5c_oVX^CMwd22JB1ew1BR23{XPzqblwm`S$+Yc63$7v6xjQQTAMUswjO{q|*M*0#`M%LO|HaqNzIyhXlkXI@-Y7f_ z5k}Up@yo#BS3SE-NmRT_R1n9x7Ub}Yg?OrmYn3tTA(;&mm0>BLMP^RhrBVuPIp-w3 z5?jwdM~Pq&0xm#&>f%##zNo{q;HZf@YGRJMh^=llnP5VG_W2(}+g6;S`3PX2 zX!hQ*7|m|>HCWE1*+eUfeUfh>0$UYel_vx#LnBqERM{YDX#55|P1n|;Hk&jd%`*<< zGcr+2x`uZWa@x=oyClkKl5=J#sR=nD1ml;M<~4UqK_o)EY&r?a?(LS|L>11IZ9r5I$|sP zJF8=+bFS;9ZZ%UzVJxFKVk+iq1GTG{Oiqg{+mMvNcn}h@$x6#KuC(;0b0p-?@SA~* ztbV)Sf?wOD6#^^gUed^ZZXz%d*gG*e2n3LUs*ePKbtanvgM&i@LqIAXrnmK+U^&tm zpza+9&LJ(Xhl4+b78paa&tK>DfI{#DVazb%85|!O89&RA0dFJVKX8=n7d-6`9B2d* z@Qek3$9$|_-UdTzBWHb+L8TRrVI&F06dvE`_yjsNKFIskEcfUX2obq>@YMJOFw}_v zP}Rr?DxU}fdwK?ZBO^doixOwYq4veAVElpufia&nG){f>p+jRQ zM}UW^rbZRx@|U>jJf0vEYzDz+03Naw5uAkx3_;b=tDO z8;6=G5@L!_0wU}JPx>Sxz^56o8X4hsGQqgnANb-#0P+_$-Jsm2k=B=~6sAsJ6@%VE z#X-Vq0KW}e78-U&8+OJTc0>4|u~<|LoSDuSRpRSWoIy9jRBPc%1zm{JSCA{UTLg$l z0%Opt7wB}2J^2{Ln0$fbLZ}!cw!+oePi2yyxJzgBP_~BQi0y-t+=L2JE)CFXxn;Gv z3|RyS)R@W;xabl}OCuD}E60s^4QU->iIjZYh&2^{2 z{3V3zYnC~A0J?@ozRhA{a4^Ctb? z46C?Gryg@i#adHlr6=btQ>G~k>*-@tu=boX6$w-3DU)9)63*MsTc?b=5(2AIeocNq zTkC-mo3bUA!gL{KDCL?mg+VL8rb3l-z~aC-oSTvjx61ec`|I~neMfn6>a}J`Z4F~> zQB_>48-;519{QtvFY(g5pVoJx8fXHtRT*~3NCiMPFnT658Fq|$Gz7ETv)-G*mPp)w z3}^`kZ`|4~{qw$&2{~>U8joAq+Bk3&V&ZWai4BINSu_zhpOuC}fp|I>d$4r2%4`7p zu(+EDKx{&bCoYb~t%HHkz$wtD#7D=|q`)YU3!r}7%z%E}&VC30k$GM^Ro2g+WJp6N zPsuky`ijJ4vWpvY8PS@~>P6~*Mdn}$mIzjFhJ8kSehXOb#q8Y6#V-{v<&;Ir*T-^N zBlgzC%&eL0=O0|kDT$Oe$8uUC_Lf^Yu4(I1mh;8oi^DIBK;x8^J10JWdaTf!s{&8QC`QC%$lcxjM1R)wqOU2ZLFgFmzuwu7ypWH(oRba{xCI;T?+7#i3l#a8P&_kWPbG z7gdNR)6Llzjl(L`;$m$rPg~w~&%reJ?+DvFmn@`*Qtk{mYGz)Y%;`c3AA9)=(_M?Xd1O_%=*XSUWXp)l?_|5sxN&GKg!ijOpSTXam14vWBlQ~; z{|*H#m25~ElZ=5(=8vTd^oRs5(u)+lM8P*H_+tvTP|!d@9R<@$@VAHrJqU23#qUOX;i~ioY|$|H75Ufu^YFIC_|3;}34ROk zTZ-R8{FZ4o@tD8WUxf5>j9M{%J^l^;68u*9H~LHQTj}5A-|R0#%~eP#M@ltD(SzT0 zP_S+R_bzWUIHqhxFiOv2K&3Ash+F;KP`O)rj?zvc@S2C3u*8R&DQKZ!BL#$`!o{Hp zkR^|XCeH*ORrd}&-sov=ZhkzT+qtjfXeaF6_8mKR^jLq#;r5=MeLaw>Sh+|z7`H+k zAPohADwMXNJ(Y5Q3N0jw@Whac@l-1S8z|`n`++g1M#XDvN@5N&meM4(Q%2lTi|hgg zE%d8YKB(se3$!T>T9n3&F#3(Lu3h^A3)vS=VD^&W7kg#mS#kshRuWOxz^T3YnvR`g4l?uN3?T3VuYv zbp-K@)N13FkkpUijHf9dG8m-K4`i=g9G4N!3m2|A#Ms0p1g{~_1>sJCV9%R5`HiP; zW;8DrS59|+tI=V z(^k01bKlCRvUZ{*fQfAy{Urlk-)Wx5;LK1$2dgin^-ip=~EFbE}vk{uOU}L2U9O?Zk`u49!<{}S;MHL)%X1bZ>-LNPNx2e|0^1hx+gzk zD=suHHIGXtTX0K%+cs?8UKQkJnowr<@&3dPjzic_BJlzA1$y{{Jx9A`g@)ug;|ub) z=WG?de;XP5wH>D+P)M$3`l`pVvemv$jzgs&S19X-A&n2hFxa2a^Z~9#SbKONZlVRp zYVcvJCh0Ad!BN{f{@~aUt@=);gJy!K<6L`yft7qiP-ZrhF#$>VKeZ`YF@X=q;Rhd$ z@qr22(1=gsIX(vjGC8&||ncx?A zZAOFKM8PEbj1u&l{&I5DxKpps)O0H7jHiRZQg%!iuX<_i;R|bbfI0)vD6ZU-8V979 z%( zko;;YW1aBU`~ta;EjIrZ7nEyOC`JJlC*#?x@Tx>#Sc)S6jn3u((X2^xfD+aogqLX$ znveyH!y?#Sk&LqWt*`C*!#$w<*lsu}nqR+=zcZS@6ZG5u#e#CE-ng7+K6B@LPnj=)?&4JodH5bUUFv{yuf0 z{$HUJ>3$$=h8f4gt3jXk@Xdd%4w#we1)T}O(*JDjW>sBv7+bEBC4@c99*RjhBqsdffHAIAO;QVHAsQD0(qEv46v&v#9TRZ6O$wK-0tiXZ z{{tpmkR&F+KX#$S^UBUEJ4vll+z@Hpeccc%?pP>35G_6sD?Svl70{NqT^DynGCYf* z-Zm{%ZHwZ+W80FaG19av=Gl#%+L?>l?npshG`kK64g1eZH%3c0Uh9aJZu`$>Q)$kv z0thtc1`X=0 z)>uGpvdx?WB-Vy@jJY^1Jpr_Q5Q>JGPe#?2& zQ>L?`vXj$m4R@<+h;un?4Ked5;t0X0!X}HX+s=%W%NVf9Bahn_$MDu;e{D8voX&{=g|w|UkD8(}RM@(lWh$UqLvCGVMMDAe5TO_$!H zI=@Q6Pbgs4r2n2`-=pB06fht_1|0FMel`FKpurw`Mhp?xBojkP&!vB+2X_##na?>l zSw|_?p+j=YPolKs|2LGqAbemKoMrGxu;8e>;iy~6t6VmSxjR>k#{8UR!I+&xJ1YvN z4=tP0({jmi!TIOU)2^}ev*#D`TcY{o0V03%jA^lP{fz0R)B6ELMum%Z=S-(+k`T3f zr#qQt?#IiyVEz^y-lzjcycSegUiHeGIFO(mNmLG|gAC1^c zmU2qbpX}O2@AeOjVs_gtXZDKKjft#SN`E7ORqg=eKL`Y=Kt|Gt6Iq-%{bcfrYFl!5?M^cupa)fLl4 zK7nMRkqp9{6_M!p7#0e|5`5Yc3SxGLe7!Ie#(@yL{ESShwVepivZ0;P+Hzu~AI!3~ zS;?%Oi3dq=a3lR1_u=x@$RlYU{y#L8HX|pnM>>fMcRjz0WQ4nBcP+RYqOOLk9WmGX zYny(s>$|%aHg-ifcEvXCkGl3ppuu+JtmgFyjI;0aJBYCFBabd_)k}la8dO!jLh_~s zB~>+dgP|Er*o1@{RPO=Bx~VW$WEPeN>F>}!vnfzEC5R{DrV#9zl6eA{!27U$BQ&m~ zGf*D=nnrC0>f;8C5QlujHTSu%=Ry1dVF=6uLN9EGozHIAxWfm^bo=z_uNr4MUrw9u zUUFeW>&x4*HdYhxDy}<*niD0i`lc}GD@l=}lcz(f2I z2fZmXJ)W+;hz{GJJv4xymCZ1hY|a-mFJ=NdWgZo8=hlLv`R6oqS~^H5$hTl86|u=S z=LB(-OZ`F;QhwWCXjoObD$Nnqfo+7cgoA&`m zX2+lpwl!Y<9VKiDqRqu-{E%}&XkaN&QKPcROjMXD;;C@*QcF|2A1+!2r_^T|^wr3i z1$NBZSNpu~SCgfZrumaGM{~s1yn2zLlb=B}ra#|ILt}&EI-(0o&ZXYkS#Js7Ce9>k zTDd-BH*TU_s&FoD!4Q#TbhVU+KPaHC5Ch1e)VYi2rX6fRygBT>KG_XR2duZ|Be1;0 z@1qb7HIl;ZanF<|<SIi-=VHCjV+5Ywe8cCM!MTiu)-xJ`*kG5 zO()=`Q2HrlfXh{ZNf1u+O~O1Uy^p7# zqyv8_Z*!dzGU%<96sqi#Jh_ht=q(_de3TFE>&EWxuGei6RU_q7BUE03w^>2DO)=Uv zso8pAOIkNPOzGujU1s)R_oEyq3^1U0m%rswV*{x zr>?M1ok1~eSSjYMNi{%Qp`ye#N&k+5{~bZxdf+J2*l;IE?UYUwcHGh5pWu)bo4QU> zY8vg5<@xte*1x1g8(dC6PZpZwFL;9<&}W7aG!VkzN{f`jKH4uS_IDKgJq7zeV=M5#TM)4SDPah8=|%iWYn83^oS3M%UMFjx({+I%=O^j za~=?vtrWGv;CDHVV(CIo?s5jj>_TD5awf&HgzVyF2gRI1Vd-)<#d3r^&$5eRZXu^^ znN^r4q-U+IdkJCGE?7&-AGUoU8z) zr&gk-m8un&Qd;Jhzwpc#J~WtMc!&nw%M?TByTpUyve9U+UUZf6->rMu@2#}*6*JP2 zr?`BvrXEi0meVZe>RXxl;5(3R5elo9trW8f1tshm1}NRJl0j*1UTWEDmW$w5E^c&qRItBmzl z=ed^@fBCd92%*VyneamAk+8M zHvbCZaH~%0; zi5g*&_K#{qntNlYRpyEUL% zKXs_(t(a}BLX1;@MpluuCHYn$85(nvpnes+JhP8b*gm;5zKef?*1hLPPyL|9_2FVKrKJllHvD!cWwXx4MgrP%U zp9qYxt-=r_!W+oQ1T4|$1(p7>PwNkym^g{ex6&DS_zr@BMp>;wWS7puV#ULq;U&MP ztaR7jt{0WdiOO>2);d^^A@x0;l6m%K@~hrV`6rthxebdQWmeK?lQ@;+Ov=}$uFE!; z$^8g`%aI0DwXVF^O6%4>{+v&L(7}8!7B=Mu22K;V;n_>3ROkq{PNO+&D~72RY)(DQ z8fw&s{axyauL5E& zpT^9NWwZ-}Wylm046xI1r%Gm+4#BE4JY~l-RVy$hN~Ix}`b-SDm3WAZ@z^z}$^|4V zvwTonok~Yt#DTJFDg$?_W-p|gRYQuV8f42g;Jx{kYCJt$p*+!kryOr!^yotU**pe^ zck7gxf_U&$dlRd)PG9>GEI>L5*i)`4+qYE>Bx+LMaT4a-u<$T%B*QO%sEX) z{euSL)IU7AUq{@V3x6dOfCFq-OgvA2USnJ01YGYk{V!~&2wKIB@X;U7=~ouE3V28f zaHgLza!A9G0mjkbN$Jn1UB)I6^MyLjfESEs5LA}Ue3)lA*!|G9bu6bra;w68lgrx} zo%|Pd%DWxeJ{vGeGP3OF+cOz!<8?8`1M%7Z$u-9&?nuE6Y((POt6#}Pz2!U04s46myei>hHL?YNa& zh@bSu^_%cxTdZVO+2xC6u)-nZZTL(=^7|Q%uO6HWeQV&`o97?9>E5tdSPEO6gG$-r zb(Fc_c1F(3rn$VE(4FQNlPwQ;f!YRY1d)n$3!c`fr}bKM%+pTUOJP~#SsyEJrJIru zU>a0Bzv;EMKWszguM}P>yw*Hd7%Oatk@-PrM5~*p_b@76U)%A!7>PBt9e^Er65^mZ z`5AN?`gJI491h%Roy#j;+Zk_^XdjJ4`)KghvD2N+>QqS;W3t1ANgq1V+~i66*qiW* zTu>E$K0NPUsA#=W(F#=r^I?85eZf`|wUx~EE|fM!OPg-mV4#mr_>PV9K1riSFqXl0 zKN~fs{Z)I8B>7Sx6t;$l@V86gfnAzhJ)}Zw&9(EOsTxP^h{7W%rD{wK;s1-F8JgwC zu<#kZ=pPCWkcTke7-2hk}n`MbDPcgd$RUqi*?oKBOzJJ=hNoS9QBnx{RIIX z;4=1zt$cM)&a>8OlcBdrp^sgl8%g|OkqlT zg@&Af0kb?J%Ye$L0|L%UKH_+)UMfibM>Me3a=p8Ho=nc3c?uKBq}HlNq&y8&>#5N+ z4=4ck*whOnv<$Vd8u6>7CXC%+RCWsfJ{||@4DY50`K5UleaUdi0aG;-o~q_IFsz}u zh0AX~-HD;hN-(~$z()$kLCFErB-5};8uL;VDro6EjCK6h(-=hw=QN!+k6}yld2^bO z&=*0^>AX@uJg8XwwkL#Ojz4Y6GGI7oI1TuKy4Y!PLF z98)l&vJx-qy*F@AxgMDZJR6%gHg5pyesT=tGOROnT9HK^ z^c3h-c8aZ`eX!cA`q9SSRzZ@*c5X6%58-Vob<^9ER1SMe$dx8`D??PkSY~R94QJ3( zw=U?F9TooSukZrR#^wntrwX_ zZ6)lhsJYM0N88w)9(SB&UO+{!-^j=SO!RxC(NFM%pte1m2y zDoCLY6WO2F2+R~C4>M7zsekRUS07tgw>i3Qb7V_bY~B6SS+_C@BN^+My7l>~JEZC$ zcPP*fZyu7*^%xLHb`*@k;TP;;)y^Sa9Pm znrnZl4d>^~c7YqnE1K?Fw!v%mQf|SVo3h1n*C7ceHaRnW(Twu>jaO@KR&BYq5y6|y zKkvHHc8uIWbloB+5WoI#t5AGU{P<3m;4TAIlvxIz;Ux>`qRg`2+$j>AMMNs)qrmfB zL@ech65N78eM@w8xP-UdIUQN1w`!UZf4e-lqgwcJmKpIMyD~Z|j6e2>6jo<+Y%u<~ zRYbUobgm-vs*i!n`Q~SMgksWkzv1_cJ!FaVFL*bu@uRlJonJ}O2^ z6ojG2xfpY`v{Ivf9SUxOA?|;l#rTdQj&PxW{5(Z5 z@S_=lC*`9xVH6_o>;!siqWzYHiDa5pt>p>$X!MPRkQsC__nNHMs8z*?Rx$#{R+H1f zah%>(D>(%RUUDydXND4ZZ5RlN~Mf~s;7?1_*jv3H-}w7*lM%V`02nH_O^So&Nhedb8D#Y{0eL^H@gSR*!o^8EYVyPXNI3X!&Sg_!#zu~HfhqDEDL)6`{;BJk&TW`8I z0twQ?D&SZ4usZ6lUU1h(-Ss!!jVMWsM9mFH&DBi{4SS;vdlwoGMH>#?Y&ZfxWed!= z{5#Gnh|C(h#fYQk<2yc4a94aN7&CiBh}`mP`SEktHbu4{jO87QeC}ApdF(g0UF9%Y zMwVNyrtkHoSA9d}xT~s;W`t^pZtr2(Q?Yx>b3Zm|`%#F9)xt9;l9*nr_;k@mY zv@2d99p=Z9|;tiM&XYqsN7Ny|0y>O`by^GwH5Ue$cZ)$CYa!?o;) zbHi_LyDPr6HR5U@tbRzu(@4$sH!I%Eja2Wsj$9o-N3MgvAxwWr{LKeAU+CX*EdNWe zACu=<Ol@7z~w{AsP3;*CaB@za*Qw)?jl|6(iE+y(JFnct{>&M~V5;^}}7#g$)T zqOHXrazAjOM~qOAn4$DA5|0%uof0qnJuo#&re4x}`suu+^jDgwPtRmF=+eY~dMEGr z4U9W`9j9cH?~K&Oaj&;=L*pQO1dVgl!>S4$avo>*fjbkQ!5_RoZ^c^g$6bzw@h}!< z#Y_}@p9o)(02uIkXP7eMUcYa-t2;bpd4s+NE_m3qGM|zrJ#Rir&mc%M4HIZexuz2Q za6Sd~)CKXGt?M8#gqaU~xDwAs;4$)jUrO`8+s%nsNlkM>Wm+>9O&%R30j7!o_|FlX1ktn1@7M zgXGDYVGiCaI02%ku!#WY3>7%gmf9OI@yD@4`8b{8aGW`Z=8T}G$$|;Un16^2!g+15 zg^&(2+*4%x_KClaC-YT(=rqc!mm-whRv-Tt5_VF$Sp)uYwP9> zn>TOYzJ9$XsGxqx1@VUD6a?f2`>baskK%L}jCvDE-;qjDdDl~N`NS7!T@ULBNG0Gz zXG|Vb|2V!55h3)Awa=^7F@(+UPkRl&0$>$>MM`fNsR~Xm8OY>P)(u2BWFR?iKhV?v zz#~T=*w>Bz!0rBIFmA`!CXY~H#vu$Ln4RE=(FmvDT;P3$9()}Ebg@hz@IEC__ITO= z%7*&kT%5ay%|wjvWbVhbz+ExJpm)85Z?&h*S}f2sc#4)Duhw1)SF+sh+SxA*FS8}7}wNucey z;qZK`W1)Iew0hIEvp1@Dzw2<*HmP&7=Po}r`_%kUEPs8(xqc}(pF4R3C!ZyhR!$#T z%*mZ;n0H+j|F8h6#F;%y9zyq}G0)Z+_;$^o+YZ_W1c9dsw{m^hdNuz@EWc&O^lpAJ znf+NHJGi`Oc2CSz9kEwq8)bI>W&5msuJ@+15`D#{D_7nuYvh{+P;Vw?em65`vA*eQ z%giP^Jm>Q6+1>M1F;`8*e)P@IkIwz@+>f66;Zw0a*ok!%tsrB$oDsWw=3O{UB;kzPW7a$}2F%gU;b}>J53Mj_H(Br_ADd<}R?WL`*Pid72B50wcT+$P$ zOJ$I?htCY_r^~%~R73B`r^7bumsZ{j0%C)-U419Rlu05h37vi<5CW9kv!*$bJT zXr?EYS^0rbmR9j@TL(Y@TmDz~&Fs4A+VFGNbSHN5O+O8ZWW^tD`)(&Hg_AnltnG5v zY!q@4yi@9U$}30TIoGdT9$|%5Y%~Qwzw;Lb{T>yt+3KrdKU-71O=qrE{S{5&0G3(LSFrfnnqHIk>4~#H1Bd???P-o@& zrhXmpf=&IJR8IwMq&Z{nt7_$xw*_iQZjpE&y|L7x&Nbdg6z+8tZ8ilS7jK?@EsF~h+Epu?LvF1DP zIiGVDyoDcb>p*JyM${Ua2{W^aZiDm2WDDct$C-uA@#9GjhK?tBQe)+zVh<%U2OiIU za4(}15NU!9AQV6nJkq?Q<3wjNS8+i|--d9)n;(jDcrYTK3#!53=^zQoH{RRU>`NHA9Y8;LrGkX zjE0XhZdl#+z`N#Q8fdTD0zY`8OZpg44Zd;NjSweklvy! zU!~wB1d4L@eM-1a!EFkN&5~%-U)-+Pj?&Ao*2$77Q;Nw4z2)x`@o@zWgZS74u_!;r z2KJ4Mq=K!0`g5UleYAA_bocuiSu-2wvR~SID<|(_$6}^)x__~xV*1E!2aG5eT(wbG zEnEj)?YQA+0cXTdR+n8;7-QHu=iEdt<>;8aftaIm+H|X+crG-Taid`ORpZq!zHYlw zx9d&!wTGuO-*>paVVvt+C|MsZSsyECz4o~q1vsE1fBMiZY{cI|CRFU0x%shcqcK+} z4rzCkpr1IbG<~@lEaP;>2VTKliF^yL#v882rJ@?r`QDeT>n$jm$+%TqPR@0%ny!w$ zIT|ZIj59ijO7TSPo&|e#)LsqSQTvA5U5)StX)vTSjmA{ zem(qcaL*Z6JFhigZ;F*aFk@%*Om);*z2K~iI_s{M+;ncalL^)@wX*-&58jgm=rn{0 zJ{n{v9h`x~XHqYsK5#FtoZt)`r()E{T7*$Ckk-jmjDe^aU)2}3Gf zquJLyD{7|)p{&XTXrL=O zbjYx3xx@QJA>QBoZHvPG&?!fta*P-7$J$g)-L(=*pG52vn=*ouqMB8@MaxH8O;`xY z-v;!S{#)zOCaULi&}!x&v4Y~5TfhH)YjXcD9sIW)VXw{iC46EPoFz~O$Jg8=#z1JR zjMj0CBlEYKfNLS3l*x*r@#ekkRJ4GfcspzcBDmCgJb|Eqpi-kJw7pdtvRX|}tVXz> znQ+j2zW)D>vK6$#5lPsW=zOX5vwL4!Rb-X>B?fbP8OuB*co^2Yj%lCZK#AE9G1T?P z^x&HmF#N@^8{2Qqu$JsK>3w>BodOkMNvANWf<&$I*W;!`e~C72UIdYFK*T5mWSN!GUm2IvdL zEz#nZh2pKz;;pgb?Gg9(HE`J?TC5;@-aH86Af{w^?W%kFDY&VaHofa8op;ZdaHM6k zYe+RKXVFtVw;yuGdqO?$I*PBH$8k-B^GFt0ebqm+JLcLr-3fPV4j1_YcQA~oAdi-) zt0m@QXIGIJv?}VTT5!}x9ko}DF-K#>*0>s*m@wj1giS^;y2|kgdO{{2p1jDhp4Pas<;st!6<=~<;OkTYhQxmrIydw8}ZV9vM$;xT$*B587VrWc4hA( zbSuh+MzW;jBsV*NlyA&w_Oycyfh!-rv6D6jz-SPg0aXyKkfq#mSUX>vmJ;6=NtJ>m zRxBIP46A_}Q)@|h4r-grxPA+8mAO!tw`tO=l2aniQh3O@qvmv+-~!|97@xuRcQW4^ zU@JLtAfpYr432 z<0(fLP*2stq1whMBPq%hj%fAhB(u31#-ifM?A2%8OiMM~h0UYKbV=*5tkq+#-^a3K za2TqcKSeyACo8Igia%N=stj^h8k+IG2JVTEkd0Efmy+vLB|-IMYZU31ND8}>AUQT0 z!-;VgAWo1fEN9-A-{^3d}me3ch(<)jwbVn_(_m#6QA9r&ZFCAZ-%y^S^-_}SX-Eikvi(vVMkh8!P?t4DPD|Fb zrljmN&(SWY z{TKJs32-;vQG4Z0do^*oPe1?kl0A!dMZI|R;?cRzckC6g zadPTxvZ49IzAgmiYkys@wxLaL$HYC${nY&mjQdf)0Qw+bO!cR7U6?yMc{CTtY)0th z(Bs6E*#$e9Ppey&Mtlqi_FD$%A{Ck_KOc+d^nO>3Oa5n(>>FB z`Qh1z=fXEL>xr;~qIbbn9d%VRMQ@Fk;oQy4IynQWlW|HR4)9zJ9MtLaN9fO5z~RCg z-gGsVAHyt9fW)7a51sf(jt{HEoAxl_Llfv?SE5LPJQp@4q6QBcos40J70KElt;5&x z;81VeQ6d~U#4Y?Le6*M3ta#8wxLlSGf@}eWl2jq?IT3~Zni9@d_a`+05#)e0bOvs^ zfXmnZuaoP!bj!8N}pHxIa- zQwZr)_IfZVaH9&N$E?*~m@oqa5PyQmT3`5?1D~p|SBY?G!>50Dd@uRi1qp$$ZsE1gH65o^evB?VjVgZ zgO7YBsx)E;dC0&nB(9i95p5^U-;wcgWMnhirxyQI$0e$C{2`omPiEMd^w`@3kA4t! zLx4W69X3St{@@wSTRKyVkog$SB!ak}6eee}e-Rc@kl!PnQ?x-i-Z;y*F~KcPQ0&g?g+@*nJo`44#3PIUk0RfA!SQe45r&RpP2`)~7}vqVG;pG`J4P5}f%n zAu{BdcgGwx5nIjbPpGaJ(yFhyUifZ$J;I2lK+1KuxlY?>^pv@YCjt14WFJWzZxWbB z7=J2kF;u8(i<7ifPqm}KW(aKJ#0u0AZ7OgU&qXOy+nP9qd!=T-fK4Q-@KQT+kmJyeRUWFhUnW$Gss_%>C zwOd#c7n5Hr{*dNvdew z8mGiCNKC8|tzRa*AN6gmK9EYF{a@S%K8#7>-8VC@8aJhX_xug?$5Qz&zrC-CQh+A*Q?F^8VTV+)Mpc({~)NJ7Vr_)B6@-mDw#bUN9hv z+RNv~oA%1ZGMwgl>F9C^yycUt%wi!c=f(bu{gKSNt3B{;zURApZZz#puGAQFH=@F_ z%2&p(j9)WG%OFR+bd)s!&yc(xmyne`(|P&m?9m&Uw3{WNPjYcic&zRUuP0ru$10$i zhp#-$wWrtIKPdlhd91YkF0ZoaD8-9#WR|!@iQBFsF~h@1Rpqnta>X{C<*t zPhIe^z0ozvRBA&h)p`WXfZQ%Cm7zARMwC*_+*4OVD{W6QqEykGT7}A=O4aC@&hz1H zEw2(&+9i#hABT^Fc$Gl~V}E;Q^`N^8Ft(sj#=iN=)fnatY+s8JlO?^wagmY`8*cLHkwPf)9eAIObxW5BQsB>eu{?c!}E7`QA*z zpp$<0d9ZpGq?(sb8WVR&`hJF~ozCDHf&?9>tfou?XGHR@si0IVQ4OB-?44GNia)c0 zk_5>A-LgsZA*p=4@P3tQ1$)DGbrL;EE=Bj_!$D+U3m=`yXNIfJ8fu9p8pU=Ha8S+R z)6BJDke`1HLH}AdaEx^$=Z_vaFVnfO0Ltq`#tR!hhF~zYn!jq6&4fT6U&lgXMm_A* z!pwAUHa8j~iM>R8gmfB{RU$aZ?UozpmW0=w)Mh+3k>t{o6fiRV0>zkK_Scke61U2c zHt$oybqW}Ix5|b@5}kauN!k*7Z_k8|l z!$ZvMrZ(!VU2rx=Io0)DZ0hg~GY0DO%JND{7gszUwODIV{L=xo);D zl2bz}4cfEvt2yAd}(ZK*-{vs_C0S(&-3 z*7~z5E8|HGLOj{On3ok!9`{*^( z%%ic~%^wOGY3slNIoxyRi%%^UmXRNu`3GZ#4KtR-yu!<;W>3vM5zDK&ns-fny)c@$ z;o5`IytW%oc(?@DHD5Vbf?e*})idpjMa6T0E8drnVqbf9^(|N7TqRuPlvU3kyD~iY z*lgFW(sBgOyvv!hnR9`6oYl+uX!(NzILpBXJA!R}wHhu; zto;Zq7JMfIN`~)K*V!Q?Z0iy05;TA&-AO8;pp=3<1fVwFr{^hWpiqCqRjV3jmMclEqx)KU_Li)=^`x3j~8K4e!d8c@&iU#)Co5s z%h@cNLx+vHSkx_)Y+cS}(LBLXx17(S1wwB9av_Tr30ZZ^#VlGv=aH1MXc_$OE|;^Y zM<}dXu3*thI=ZBaMXQC}Lf&)i4^Gee=UPf#nG(%7LL@8AoQ(~&boz)5Cv5N|Ob~-~ zho4BoP8ngxns`=l%tpX=hJ!W?F2~HwGY`Mz-5^dSM)!Z$D zTFWo_AdRBzun{@Ui9=Xelpiv}qM*E~)CM%n3n9kJ@DwUSFJ*%8WwzTsURz0OG_Ziryu$U|4Y7qlXt{o)9J`p=e#`BTIVXoq+l;%EG`R~vY z&{nyJQa=X?X8+&>DJ7uLC%Qv=o`T<_;06T|1aMt9eiEk&oQxZ!fb=LWI12|l{J^uF zlqVe)Z=t}s5FH*tt395P!0$;U?~J>2KsZ~Jad+Yqg#pExMQlf^L{x|L09)t1k36ui zzhnQtjzb5!?~gnC>8ON6-{B-~i>IHE#?g;~!NDPR#8N!tz$hJ~x{qAo$J4^fK^OcS zC39#3o&({X+;@hdKRPPOCk>o}Q}TXg&woFT7lR`FOc0O;#r?_yc6d`ft6e!qnYF;3 z0umx-&IA~qg%9(AaX3b0$3+CCOnS)RWERCpJH;Fc$I~_cPn<<1B32>|6my0oF-1@w z-I4%}dro2$8!-*>O!-s;PUv(0vBcTN)3xIcB$A6U4~4S*B6De8Mu~I+-C=xbY|`0? zd+7j%T=GzC8wH0b_#6d~Q!q%u7b%#aV44DECGuU0ZK0rn0!XfePi#B+;UT-FtEd$J zL2Mxe2_%ZY5Gwyx$azmldrxq`CuFfm`g=m=dxGOVA>$Xqx?c!wzYuo*LTI>UOj|JK z-!SI?!nA4GWD#?g4Mua`d$y`&yF)B^&s2gFTXT!vwPj3q%oNV#TrQl&$x*G>HZ5%I zh;HnNWp^%QABtulie(>(*}7MZhFr^qBUtXX+?lgCtYwR?f{Qljyf51RPRRL%P>28j zQRs*Y9UmDoM8ijd8WafPu3reH3BB2H%aVWLK$UqN7Y@TnD+r7lbCnsm|@f?7R*Rw#dk-b_?_d{2Q$Q~ zh^y+K1&VyUd None: + ... + + def set_tunnel( + self, + host: str, + port: int | None = None, + headers: typing.Mapping[str, str] | None = None, + scheme: str = "http", + ) -> None: + ... + + def connect(self) -> None: + ... + + def request( + self, + method: str, + url: str, + body: _TYPE_BODY | None = None, + headers: typing.Mapping[str, str] | None = None, + # We know *at least* botocore is depending on the order of the + # first 3 parameters so to be safe we only mark the later ones + # as keyword-only to ensure we have space to extend. + *, + chunked: bool = False, + preload_content: bool = True, + decode_content: bool = True, + enforce_content_length: bool = True, + ) -> None: + ... + + def getresponse(self) -> BaseHTTPResponse: + ... + + def close(self) -> None: + ... + + @property + def is_closed(self) -> bool: + """Whether the connection either is brand new or has been previously closed. + If this property is True then both ``is_connected`` and ``has_connected_to_proxy`` + properties must be False. + """ + + @property + def is_connected(self) -> bool: + """Whether the connection is actively connected to any origin (proxy or target)""" + + @property + def has_connected_to_proxy(self) -> bool: + """Whether the connection has successfully connected to its proxy. + This returns False if no proxy is in use. Used to determine whether + errors are coming from the proxy layer or from tunnelling to the target origin. + """ + + class BaseHTTPSConnection(BaseHTTPConnection, Protocol): + default_port: typing.ClassVar[int] + default_socket_options: typing.ClassVar[_TYPE_SOCKET_OPTIONS] + + # Certificate verification methods + cert_reqs: int | str | None + assert_hostname: None | str | typing.Literal[False] + assert_fingerprint: str | None + ssl_context: ssl.SSLContext | None + + # Trusted CAs + ca_certs: str | None + ca_cert_dir: str | None + ca_cert_data: None | str | bytes + + # TLS version + ssl_minimum_version: int | None + ssl_maximum_version: int | None + ssl_version: int | str | None # Deprecated + + # Client certificates + cert_file: str | None + key_file: str | None + key_password: str | None + + def __init__( + self, + host: str, + port: int | None = None, + *, + timeout: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + source_address: tuple[str, int] | None = None, + blocksize: int = 16384, + socket_options: _TYPE_SOCKET_OPTIONS | None = ..., + proxy: Url | None = None, + proxy_config: ProxyConfig | None = None, + cert_reqs: int | str | None = None, + assert_hostname: None | str | typing.Literal[False] = None, + assert_fingerprint: str | None = None, + server_hostname: str | None = None, + ssl_context: ssl.SSLContext | None = None, + ca_certs: str | None = None, + ca_cert_dir: str | None = None, + ca_cert_data: None | str | bytes = None, + ssl_minimum_version: int | None = None, + ssl_maximum_version: int | None = None, + ssl_version: int | str | None = None, # Deprecated + cert_file: str | None = None, + key_file: str | None = None, + key_password: str | None = None, + ) -> None: + ... diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_collections.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_collections.py new file mode 100644 index 0000000..8a4409a --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_collections.py @@ -0,0 +1,483 @@ +from __future__ import annotations + +import typing +from collections import OrderedDict +from enum import Enum, auto +from threading import RLock + +if typing.TYPE_CHECKING: + # We can only import Protocol if TYPE_CHECKING because it's a development + # dependency, and is not available at runtime. + from typing import Protocol + + from typing_extensions import Self + + class HasGettableStringKeys(Protocol): + def keys(self) -> typing.Iterator[str]: + ... + + def __getitem__(self, key: str) -> str: + ... + + +__all__ = ["RecentlyUsedContainer", "HTTPHeaderDict"] + + +# Key type +_KT = typing.TypeVar("_KT") +# Value type +_VT = typing.TypeVar("_VT") +# Default type +_DT = typing.TypeVar("_DT") + +ValidHTTPHeaderSource = typing.Union[ + "HTTPHeaderDict", + typing.Mapping[str, str], + typing.Iterable[typing.Tuple[str, str]], + "HasGettableStringKeys", +] + + +class _Sentinel(Enum): + not_passed = auto() + + +def ensure_can_construct_http_header_dict( + potential: object, +) -> ValidHTTPHeaderSource | None: + if isinstance(potential, HTTPHeaderDict): + return potential + elif isinstance(potential, typing.Mapping): + # Full runtime checking of the contents of a Mapping is expensive, so for the + # purposes of typechecking, we assume that any Mapping is the right shape. + return typing.cast(typing.Mapping[str, str], potential) + elif isinstance(potential, typing.Iterable): + # Similarly to Mapping, full runtime checking of the contents of an Iterable is + # expensive, so for the purposes of typechecking, we assume that any Iterable + # is the right shape. + return typing.cast(typing.Iterable[typing.Tuple[str, str]], potential) + elif hasattr(potential, "keys") and hasattr(potential, "__getitem__"): + return typing.cast("HasGettableStringKeys", potential) + else: + return None + + +class RecentlyUsedContainer(typing.Generic[_KT, _VT], typing.MutableMapping[_KT, _VT]): + """ + Provides a thread-safe dict-like container which maintains up to + ``maxsize`` keys while throwing away the least-recently-used keys beyond + ``maxsize``. + + :param maxsize: + Maximum number of recent elements to retain. + + :param dispose_func: + Every time an item is evicted from the container, + ``dispose_func(value)`` is called. Callback which will get called + """ + + _container: typing.OrderedDict[_KT, _VT] + _maxsize: int + dispose_func: typing.Callable[[_VT], None] | None + lock: RLock + + def __init__( + self, + maxsize: int = 10, + dispose_func: typing.Callable[[_VT], None] | None = None, + ) -> None: + super().__init__() + self._maxsize = maxsize + self.dispose_func = dispose_func + self._container = OrderedDict() + self.lock = RLock() + + def __getitem__(self, key: _KT) -> _VT: + # Re-insert the item, moving it to the end of the eviction line. + with self.lock: + item = self._container.pop(key) + self._container[key] = item + return item + + def __setitem__(self, key: _KT, value: _VT) -> None: + evicted_item = None + with self.lock: + # Possibly evict the existing value of 'key' + try: + # If the key exists, we'll overwrite it, which won't change the + # size of the pool. Because accessing a key should move it to + # the end of the eviction line, we pop it out first. + evicted_item = key, self._container.pop(key) + self._container[key] = value + except KeyError: + # When the key does not exist, we insert the value first so that + # evicting works in all cases, including when self._maxsize is 0 + self._container[key] = value + if len(self._container) > self._maxsize: + # If we didn't evict an existing value, and we've hit our maximum + # size, then we have to evict the least recently used item from + # the beginning of the container. + evicted_item = self._container.popitem(last=False) + + # After releasing the lock on the pool, dispose of any evicted value. + if evicted_item is not None and self.dispose_func: + _, evicted_value = evicted_item + self.dispose_func(evicted_value) + + def __delitem__(self, key: _KT) -> None: + with self.lock: + value = self._container.pop(key) + + if self.dispose_func: + self.dispose_func(value) + + def __len__(self) -> int: + with self.lock: + return len(self._container) + + def __iter__(self) -> typing.NoReturn: + raise NotImplementedError( + "Iteration over this class is unlikely to be threadsafe." + ) + + def clear(self) -> None: + with self.lock: + # Copy pointers to all values, then wipe the mapping + values = list(self._container.values()) + self._container.clear() + + if self.dispose_func: + for value in values: + self.dispose_func(value) + + def keys(self) -> set[_KT]: # type: ignore[override] + with self.lock: + return set(self._container.keys()) + + +class HTTPHeaderDictItemView(typing.Set[typing.Tuple[str, str]]): + """ + HTTPHeaderDict is unusual for a Mapping[str, str] in that it has two modes of + address. + + If we directly try to get an item with a particular name, we will get a string + back that is the concatenated version of all the values: + + >>> d['X-Header-Name'] + 'Value1, Value2, Value3' + + However, if we iterate over an HTTPHeaderDict's items, we will optionally combine + these values based on whether combine=True was called when building up the dictionary + + >>> d = HTTPHeaderDict({"A": "1", "B": "foo"}) + >>> d.add("A", "2", combine=True) + >>> d.add("B", "bar") + >>> list(d.items()) + [ + ('A', '1, 2'), + ('B', 'foo'), + ('B', 'bar'), + ] + + This class conforms to the interface required by the MutableMapping ABC while + also giving us the nonstandard iteration behavior we want; items with duplicate + keys, ordered by time of first insertion. + """ + + _headers: HTTPHeaderDict + + def __init__(self, headers: HTTPHeaderDict) -> None: + self._headers = headers + + def __len__(self) -> int: + return len(list(self._headers.iteritems())) + + def __iter__(self) -> typing.Iterator[tuple[str, str]]: + return self._headers.iteritems() + + def __contains__(self, item: object) -> bool: + if isinstance(item, tuple) and len(item) == 2: + passed_key, passed_val = item + if isinstance(passed_key, str) and isinstance(passed_val, str): + return self._headers._has_value_for_header(passed_key, passed_val) + return False + + +class HTTPHeaderDict(typing.MutableMapping[str, str]): + """ + :param headers: + An iterable of field-value pairs. Must not contain multiple field names + when compared case-insensitively. + + :param kwargs: + Additional field-value pairs to pass in to ``dict.update``. + + A ``dict`` like container for storing HTTP Headers. + + Field names are stored and compared case-insensitively in compliance with + RFC 7230. Iteration provides the first case-sensitive key seen for each + case-insensitive pair. + + Using ``__setitem__`` syntax overwrites fields that compare equal + case-insensitively in order to maintain ``dict``'s api. For fields that + compare equal, instead create a new ``HTTPHeaderDict`` and use ``.add`` + in a loop. + + If multiple fields that are equal case-insensitively are passed to the + constructor or ``.update``, the behavior is undefined and some will be + lost. + + >>> headers = HTTPHeaderDict() + >>> headers.add('Set-Cookie', 'foo=bar') + >>> headers.add('set-cookie', 'baz=quxx') + >>> headers['content-length'] = '7' + >>> headers['SET-cookie'] + 'foo=bar, baz=quxx' + >>> headers['Content-Length'] + '7' + """ + + _container: typing.MutableMapping[str, list[str]] + + def __init__(self, headers: ValidHTTPHeaderSource | None = None, **kwargs: str): + super().__init__() + self._container = {} # 'dict' is insert-ordered + if headers is not None: + if isinstance(headers, HTTPHeaderDict): + self._copy_from(headers) + else: + self.extend(headers) + if kwargs: + self.extend(kwargs) + + def __setitem__(self, key: str, val: str) -> None: + # avoid a bytes/str comparison by decoding before httplib + if isinstance(key, bytes): + key = key.decode("latin-1") + self._container[key.lower()] = [key, val] + + def __getitem__(self, key: str) -> str: + val = self._container[key.lower()] + return ", ".join(val[1:]) + + def __delitem__(self, key: str) -> None: + del self._container[key.lower()] + + def __contains__(self, key: object) -> bool: + if isinstance(key, str): + return key.lower() in self._container + return False + + def setdefault(self, key: str, default: str = "") -> str: + return super().setdefault(key, default) + + def __eq__(self, other: object) -> bool: + maybe_constructable = ensure_can_construct_http_header_dict(other) + if maybe_constructable is None: + return False + else: + other_as_http_header_dict = type(self)(maybe_constructable) + + return {k.lower(): v for k, v in self.itermerged()} == { + k.lower(): v for k, v in other_as_http_header_dict.itermerged() + } + + def __ne__(self, other: object) -> bool: + return not self.__eq__(other) + + def __len__(self) -> int: + return len(self._container) + + def __iter__(self) -> typing.Iterator[str]: + # Only provide the originally cased names + for vals in self._container.values(): + yield vals[0] + + def discard(self, key: str) -> None: + try: + del self[key] + except KeyError: + pass + + def add(self, key: str, val: str, *, combine: bool = False) -> None: + """Adds a (name, value) pair, doesn't overwrite the value if it already + exists. + + If this is called with combine=True, instead of adding a new header value + as a distinct item during iteration, this will instead append the value to + any existing header value with a comma. If no existing header value exists + for the key, then the value will simply be added, ignoring the combine parameter. + + >>> headers = HTTPHeaderDict(foo='bar') + >>> headers.add('Foo', 'baz') + >>> headers['foo'] + 'bar, baz' + >>> list(headers.items()) + [('foo', 'bar'), ('foo', 'baz')] + >>> headers.add('foo', 'quz', combine=True) + >>> list(headers.items()) + [('foo', 'bar, baz, quz')] + """ + # avoid a bytes/str comparison by decoding before httplib + if isinstance(key, bytes): + key = key.decode("latin-1") + key_lower = key.lower() + new_vals = [key, val] + # Keep the common case aka no item present as fast as possible + vals = self._container.setdefault(key_lower, new_vals) + if new_vals is not vals: + # if there are values here, then there is at least the initial + # key/value pair + assert len(vals) >= 2 + if combine: + vals[-1] = vals[-1] + ", " + val + else: + vals.append(val) + + def extend(self, *args: ValidHTTPHeaderSource, **kwargs: str) -> None: + """Generic import function for any type of header-like object. + Adapted version of MutableMapping.update in order to insert items + with self.add instead of self.__setitem__ + """ + if len(args) > 1: + raise TypeError( + f"extend() takes at most 1 positional arguments ({len(args)} given)" + ) + other = args[0] if len(args) >= 1 else () + + if isinstance(other, HTTPHeaderDict): + for key, val in other.iteritems(): + self.add(key, val) + elif isinstance(other, typing.Mapping): + for key, val in other.items(): + self.add(key, val) + elif isinstance(other, typing.Iterable): + other = typing.cast(typing.Iterable[typing.Tuple[str, str]], other) + for key, value in other: + self.add(key, value) + elif hasattr(other, "keys") and hasattr(other, "__getitem__"): + # THIS IS NOT A TYPESAFE BRANCH + # In this branch, the object has a `keys` attr but is not a Mapping or any of + # the other types indicated in the method signature. We do some stuff with + # it as though it partially implements the Mapping interface, but we're not + # doing that stuff safely AT ALL. + for key in other.keys(): + self.add(key, other[key]) + + for key, value in kwargs.items(): + self.add(key, value) + + @typing.overload + def getlist(self, key: str) -> list[str]: + ... + + @typing.overload + def getlist(self, key: str, default: _DT) -> list[str] | _DT: + ... + + def getlist( + self, key: str, default: _Sentinel | _DT = _Sentinel.not_passed + ) -> list[str] | _DT: + """Returns a list of all the values for the named field. Returns an + empty list if the key doesn't exist.""" + try: + vals = self._container[key.lower()] + except KeyError: + if default is _Sentinel.not_passed: + # _DT is unbound; empty list is instance of List[str] + return [] + # _DT is bound; default is instance of _DT + return default + else: + # _DT may or may not be bound; vals[1:] is instance of List[str], which + # meets our external interface requirement of `Union[List[str], _DT]`. + return vals[1:] + + def _prepare_for_method_change(self) -> Self: + """ + Remove content-specific header fields before changing the request + method to GET or HEAD according to RFC 9110, Section 15.4. + """ + content_specific_headers = [ + "Content-Encoding", + "Content-Language", + "Content-Location", + "Content-Type", + "Content-Length", + "Digest", + "Last-Modified", + ] + for header in content_specific_headers: + self.discard(header) + return self + + # Backwards compatibility for httplib + getheaders = getlist + getallmatchingheaders = getlist + iget = getlist + + # Backwards compatibility for http.cookiejar + get_all = getlist + + def __repr__(self) -> str: + return f"{type(self).__name__}({dict(self.itermerged())})" + + def _copy_from(self, other: HTTPHeaderDict) -> None: + for key in other: + val = other.getlist(key) + self._container[key.lower()] = [key, *val] + + def copy(self) -> Self: + clone = type(self)() + clone._copy_from(self) + return clone + + def iteritems(self) -> typing.Iterator[tuple[str, str]]: + """Iterate over all header lines, including duplicate ones.""" + for key in self: + vals = self._container[key.lower()] + for val in vals[1:]: + yield vals[0], val + + def itermerged(self) -> typing.Iterator[tuple[str, str]]: + """Iterate over all headers, merging duplicate ones together.""" + for key in self: + val = self._container[key.lower()] + yield val[0], ", ".join(val[1:]) + + def items(self) -> HTTPHeaderDictItemView: # type: ignore[override] + return HTTPHeaderDictItemView(self) + + def _has_value_for_header(self, header_name: str, potential_value: str) -> bool: + if header_name in self: + return potential_value in self._container[header_name.lower()][1:] + return False + + def __ior__(self, other: object) -> HTTPHeaderDict: + # Supports extending a header dict in-place using operator |= + # combining items with add instead of __setitem__ + maybe_constructable = ensure_can_construct_http_header_dict(other) + if maybe_constructable is None: + return NotImplemented + self.extend(maybe_constructable) + return self + + def __or__(self, other: object) -> Self: + # Supports merging header dicts using operator | + # combining items with add instead of __setitem__ + maybe_constructable = ensure_can_construct_http_header_dict(other) + if maybe_constructable is None: + return NotImplemented + result = self.copy() + result.extend(maybe_constructable) + return result + + def __ror__(self, other: object) -> Self: + # Supports merging header dicts using operator | when other is on left side + # combining items with add instead of __setitem__ + maybe_constructable = ensure_can_construct_http_header_dict(other) + if maybe_constructable is None: + return NotImplemented + result = type(self)(maybe_constructable) + result.extend(self) + return result diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_request_methods.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_request_methods.py new file mode 100644 index 0000000..632042f --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_request_methods.py @@ -0,0 +1,279 @@ +from __future__ import annotations + +import json as _json +import typing +from urllib.parse import urlencode + +from ._base_connection import _TYPE_BODY +from ._collections import HTTPHeaderDict +from .filepost import _TYPE_FIELDS, encode_multipart_formdata +from .response import BaseHTTPResponse + +__all__ = ["RequestMethods"] + +_TYPE_ENCODE_URL_FIELDS = typing.Union[ + typing.Sequence[typing.Tuple[str, typing.Union[str, bytes]]], + typing.Mapping[str, typing.Union[str, bytes]], +] + + +class RequestMethods: + """ + Convenience mixin for classes who implement a :meth:`urlopen` method, such + as :class:`urllib3.HTTPConnectionPool` and + :class:`urllib3.PoolManager`. + + Provides behavior for making common types of HTTP request methods and + decides which type of request field encoding to use. + + Specifically, + + :meth:`.request_encode_url` is for sending requests whose fields are + encoded in the URL (such as GET, HEAD, DELETE). + + :meth:`.request_encode_body` is for sending requests whose fields are + encoded in the *body* of the request using multipart or www-form-urlencoded + (such as for POST, PUT, PATCH). + + :meth:`.request` is for making any kind of request, it will look up the + appropriate encoding format and use one of the above two methods to make + the request. + + Initializer parameters: + + :param headers: + Headers to include with all requests, unless other headers are given + explicitly. + """ + + _encode_url_methods = {"DELETE", "GET", "HEAD", "OPTIONS"} + + def __init__(self, headers: typing.Mapping[str, str] | None = None) -> None: + self.headers = headers or {} + + def urlopen( + self, + method: str, + url: str, + body: _TYPE_BODY | None = None, + headers: typing.Mapping[str, str] | None = None, + encode_multipart: bool = True, + multipart_boundary: str | None = None, + **kw: typing.Any, + ) -> BaseHTTPResponse: # Abstract + raise NotImplementedError( + "Classes extending RequestMethods must implement " + "their own ``urlopen`` method." + ) + + def request( + self, + method: str, + url: str, + body: _TYPE_BODY | None = None, + fields: _TYPE_FIELDS | None = None, + headers: typing.Mapping[str, str] | None = None, + json: typing.Any | None = None, + **urlopen_kw: typing.Any, + ) -> BaseHTTPResponse: + """ + Make a request using :meth:`urlopen` with the appropriate encoding of + ``fields`` based on the ``method`` used. + + This is a convenience method that requires the least amount of manual + effort. It can be used in most situations, while still having the + option to drop down to more specific methods when necessary, such as + :meth:`request_encode_url`, :meth:`request_encode_body`, + or even the lowest level :meth:`urlopen`. + + :param method: + HTTP request method (such as GET, POST, PUT, etc.) + + :param url: + The URL to perform the request on. + + :param body: + Data to send in the request body, either :class:`str`, :class:`bytes`, + an iterable of :class:`str`/:class:`bytes`, or a file-like object. + + :param fields: + Data to encode and send in the request body. Values are processed + by :func:`urllib.parse.urlencode`. + + :param headers: + Dictionary of custom headers to send, such as User-Agent, + If-None-Match, etc. If None, pool headers are used. If provided, + these headers completely replace any pool-specific headers. + + :param json: + Data to encode and send as JSON with UTF-encoded in the request body. + The ``"Content-Type"`` header will be set to ``"application/json"`` + unless specified otherwise. + """ + method = method.upper() + + if json is not None and body is not None: + raise TypeError( + "request got values for both 'body' and 'json' parameters which are mutually exclusive" + ) + + if json is not None: + if headers is None: + headers = self.headers + + if not ("content-type" in map(str.lower, headers.keys())): + headers = HTTPHeaderDict(headers) + headers["Content-Type"] = "application/json" + + body = _json.dumps(json, separators=(",", ":"), ensure_ascii=False).encode( + "utf-8" + ) + + if body is not None: + urlopen_kw["body"] = body + + if method in self._encode_url_methods: + return self.request_encode_url( + method, + url, + fields=fields, # type: ignore[arg-type] + headers=headers, + **urlopen_kw, + ) + else: + return self.request_encode_body( + method, url, fields=fields, headers=headers, **urlopen_kw + ) + + def request_encode_url( + self, + method: str, + url: str, + fields: _TYPE_ENCODE_URL_FIELDS | None = None, + headers: typing.Mapping[str, str] | None = None, + **urlopen_kw: str, + ) -> BaseHTTPResponse: + """ + Make a request using :meth:`urlopen` with the ``fields`` encoded in + the url. This is useful for request methods like GET, HEAD, DELETE, etc. + + :param method: + HTTP request method (such as GET, POST, PUT, etc.) + + :param url: + The URL to perform the request on. + + :param fields: + Data to encode and send in the request body. + + :param headers: + Dictionary of custom headers to send, such as User-Agent, + If-None-Match, etc. If None, pool headers are used. If provided, + these headers completely replace any pool-specific headers. + """ + if headers is None: + headers = self.headers + + extra_kw: dict[str, typing.Any] = {"headers": headers} + extra_kw.update(urlopen_kw) + + if fields: + url += "?" + urlencode(fields) + + return self.urlopen(method, url, **extra_kw) + + def request_encode_body( + self, + method: str, + url: str, + fields: _TYPE_FIELDS | None = None, + headers: typing.Mapping[str, str] | None = None, + encode_multipart: bool = True, + multipart_boundary: str | None = None, + **urlopen_kw: str, + ) -> BaseHTTPResponse: + """ + Make a request using :meth:`urlopen` with the ``fields`` encoded in + the body. This is useful for request methods like POST, PUT, PATCH, etc. + + When ``encode_multipart=True`` (default), then + :func:`urllib3.encode_multipart_formdata` is used to encode + the payload with the appropriate content type. Otherwise + :func:`urllib.parse.urlencode` is used with the + 'application/x-www-form-urlencoded' content type. + + Multipart encoding must be used when posting files, and it's reasonably + safe to use it in other times too. However, it may break request + signing, such as with OAuth. + + Supports an optional ``fields`` parameter of key/value strings AND + key/filetuple. A filetuple is a (filename, data, MIME type) tuple where + the MIME type is optional. For example:: + + fields = { + 'foo': 'bar', + 'fakefile': ('foofile.txt', 'contents of foofile'), + 'realfile': ('barfile.txt', open('realfile').read()), + 'typedfile': ('bazfile.bin', open('bazfile').read(), + 'image/jpeg'), + 'nonamefile': 'contents of nonamefile field', + } + + When uploading a file, providing a filename (the first parameter of the + tuple) is optional but recommended to best mimic behavior of browsers. + + Note that if ``headers`` are supplied, the 'Content-Type' header will + be overwritten because it depends on the dynamic random boundary string + which is used to compose the body of the request. The random boundary + string can be explicitly set with the ``multipart_boundary`` parameter. + + :param method: + HTTP request method (such as GET, POST, PUT, etc.) + + :param url: + The URL to perform the request on. + + :param fields: + Data to encode and send in the request body. + + :param headers: + Dictionary of custom headers to send, such as User-Agent, + If-None-Match, etc. If None, pool headers are used. If provided, + these headers completely replace any pool-specific headers. + + :param encode_multipart: + If True, encode the ``fields`` using the multipart/form-data MIME + format. + + :param multipart_boundary: + If not specified, then a random boundary will be generated using + :func:`urllib3.filepost.choose_boundary`. + """ + if headers is None: + headers = self.headers + + extra_kw: dict[str, typing.Any] = {"headers": HTTPHeaderDict(headers)} + body: bytes | str + + if fields: + if "body" in urlopen_kw: + raise TypeError( + "request got values for both 'fields' and 'body', can only specify one." + ) + + if encode_multipart: + body, content_type = encode_multipart_formdata( + fields, boundary=multipart_boundary + ) + else: + body, content_type = ( + urlencode(fields), # type: ignore[arg-type] + "application/x-www-form-urlencoded", + ) + + extra_kw["body"] = body + extra_kw["headers"].setdefault("Content-Type", content_type) + + extra_kw.update(urlopen_kw) + + return self.urlopen(method, url, **extra_kw) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_version.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_version.py new file mode 100644 index 0000000..7442f2b --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/_version.py @@ -0,0 +1,4 @@ +# This file is protected via CODEOWNERS +from __future__ import annotations + +__version__ = "2.2.2" diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/connection.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/connection.py new file mode 100644 index 0000000..1b16279 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/connection.py @@ -0,0 +1,929 @@ +from __future__ import annotations + +import datetime +import logging +import os +import re +import socket +import sys +import typing +import warnings +from http.client import HTTPConnection as _HTTPConnection +from http.client import HTTPException as HTTPException # noqa: F401 +from http.client import ResponseNotReady +from socket import timeout as SocketTimeout + +if typing.TYPE_CHECKING: + from .response import HTTPResponse + from .util.ssl_ import _TYPE_PEER_CERT_RET_DICT + from .util.ssltransport import SSLTransport + +from ._collections import HTTPHeaderDict +from .util.response import assert_header_parsing +from .util.timeout import _DEFAULT_TIMEOUT, _TYPE_TIMEOUT, Timeout +from .util.util import to_str +from .util.wait import wait_for_read + +try: # Compiled with SSL? + import ssl + + BaseSSLError = ssl.SSLError +except (ImportError, AttributeError): + ssl = None # type: ignore[assignment] + + class BaseSSLError(BaseException): # type: ignore[no-redef] + pass + + +from ._base_connection import _TYPE_BODY +from ._base_connection import ProxyConfig as ProxyConfig +from ._base_connection import _ResponseOptions as _ResponseOptions +from ._version import __version__ +from .exceptions import ( + ConnectTimeoutError, + HeaderParsingError, + NameResolutionError, + NewConnectionError, + ProxyError, + SystemTimeWarning, +) +from .util import SKIP_HEADER, SKIPPABLE_HEADERS, connection, ssl_ +from .util.request import body_to_chunks +from .util.ssl_ import assert_fingerprint as _assert_fingerprint +from .util.ssl_ import ( + create_urllib3_context, + is_ipaddress, + resolve_cert_reqs, + resolve_ssl_version, + ssl_wrap_socket, +) +from .util.ssl_match_hostname import CertificateError, match_hostname +from .util.url import Url + +# Not a no-op, we're adding this to the namespace so it can be imported. +ConnectionError = ConnectionError +BrokenPipeError = BrokenPipeError + + +log = logging.getLogger(__name__) + +port_by_scheme = {"http": 80, "https": 443} + +# When it comes time to update this value as a part of regular maintenance +# (ie test_recent_date is failing) update it to ~6 months before the current date. +RECENT_DATE = datetime.date(2023, 6, 1) + +_CONTAINS_CONTROL_CHAR_RE = re.compile(r"[^-!#$%&'*+.^_`|~0-9a-zA-Z]") + +_HAS_SYS_AUDIT = hasattr(sys, "audit") + + +class HTTPConnection(_HTTPConnection): + """ + Based on :class:`http.client.HTTPConnection` but provides an extra constructor + backwards-compatibility layer between older and newer Pythons. + + Additional keyword parameters are used to configure attributes of the connection. + Accepted parameters include: + + - ``source_address``: Set the source address for the current connection. + - ``socket_options``: Set specific options on the underlying socket. If not specified, then + defaults are loaded from ``HTTPConnection.default_socket_options`` which includes disabling + Nagle's algorithm (sets TCP_NODELAY to 1) unless the connection is behind a proxy. + + For example, if you wish to enable TCP Keep Alive in addition to the defaults, + you might pass: + + .. code-block:: python + + HTTPConnection.default_socket_options + [ + (socket.SOL_SOCKET, socket.SO_KEEPALIVE, 1), + ] + + Or you may want to disable the defaults by passing an empty list (e.g., ``[]``). + """ + + default_port: typing.ClassVar[int] = port_by_scheme["http"] # type: ignore[misc] + + #: Disable Nagle's algorithm by default. + #: ``[(socket.IPPROTO_TCP, socket.TCP_NODELAY, 1)]`` + default_socket_options: typing.ClassVar[connection._TYPE_SOCKET_OPTIONS] = [ + (socket.IPPROTO_TCP, socket.TCP_NODELAY, 1) + ] + + #: Whether this connection verifies the host's certificate. + is_verified: bool = False + + #: Whether this proxy connection verified the proxy host's certificate. + # If no proxy is currently connected to the value will be ``None``. + proxy_is_verified: bool | None = None + + blocksize: int + source_address: tuple[str, int] | None + socket_options: connection._TYPE_SOCKET_OPTIONS | None + + _has_connected_to_proxy: bool + _response_options: _ResponseOptions | None + _tunnel_host: str | None + _tunnel_port: int | None + _tunnel_scheme: str | None + + def __init__( + self, + host: str, + port: int | None = None, + *, + timeout: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + source_address: tuple[str, int] | None = None, + blocksize: int = 16384, + socket_options: None + | (connection._TYPE_SOCKET_OPTIONS) = default_socket_options, + proxy: Url | None = None, + proxy_config: ProxyConfig | None = None, + ) -> None: + super().__init__( + host=host, + port=port, + timeout=Timeout.resolve_default_timeout(timeout), + source_address=source_address, + blocksize=blocksize, + ) + self.socket_options = socket_options + self.proxy = proxy + self.proxy_config = proxy_config + + self._has_connected_to_proxy = False + self._response_options = None + self._tunnel_host: str | None = None + self._tunnel_port: int | None = None + self._tunnel_scheme: str | None = None + + @property + def host(self) -> str: + """ + Getter method to remove any trailing dots that indicate the hostname is an FQDN. + + In general, SSL certificates don't include the trailing dot indicating a + fully-qualified domain name, and thus, they don't validate properly when + checked against a domain name that includes the dot. In addition, some + servers may not expect to receive the trailing dot when provided. + + However, the hostname with trailing dot is critical to DNS resolution; doing a + lookup with the trailing dot will properly only resolve the appropriate FQDN, + whereas a lookup without a trailing dot will search the system's search domain + list. Thus, it's important to keep the original host around for use only in + those cases where it's appropriate (i.e., when doing DNS lookup to establish the + actual TCP connection across which we're going to send HTTP requests). + """ + return self._dns_host.rstrip(".") + + @host.setter + def host(self, value: str) -> None: + """ + Setter for the `host` property. + + We assume that only urllib3 uses the _dns_host attribute; httplib itself + only uses `host`, and it seems reasonable that other libraries follow suit. + """ + self._dns_host = value + + def _new_conn(self) -> socket.socket: + """Establish a socket connection and set nodelay settings on it. + + :return: New socket connection. + """ + try: + sock = connection.create_connection( + (self._dns_host, self.port), + self.timeout, + source_address=self.source_address, + socket_options=self.socket_options, + ) + except socket.gaierror as e: + raise NameResolutionError(self.host, self, e) from e + except SocketTimeout as e: + raise ConnectTimeoutError( + self, + f"Connection to {self.host} timed out. (connect timeout={self.timeout})", + ) from e + + except OSError as e: + raise NewConnectionError( + self, f"Failed to establish a new connection: {e}" + ) from e + + # Audit hooks are only available in Python 3.8+ + if _HAS_SYS_AUDIT: + sys.audit("http.client.connect", self, self.host, self.port) + + return sock + + def set_tunnel( + self, + host: str, + port: int | None = None, + headers: typing.Mapping[str, str] | None = None, + scheme: str = "http", + ) -> None: + if scheme not in ("http", "https"): + raise ValueError( + f"Invalid proxy scheme for tunneling: {scheme!r}, must be either 'http' or 'https'" + ) + super().set_tunnel(host, port=port, headers=headers) + self._tunnel_scheme = scheme + + def connect(self) -> None: + self.sock = self._new_conn() + if self._tunnel_host: + # If we're tunneling it means we're connected to our proxy. + self._has_connected_to_proxy = True + + # TODO: Fix tunnel so it doesn't depend on self.sock state. + self._tunnel() # type: ignore[attr-defined] + + # If there's a proxy to be connected to we are fully connected. + # This is set twice (once above and here) due to forwarding proxies + # not using tunnelling. + self._has_connected_to_proxy = bool(self.proxy) + + if self._has_connected_to_proxy: + self.proxy_is_verified = False + + @property + def is_closed(self) -> bool: + return self.sock is None + + @property + def is_connected(self) -> bool: + if self.sock is None: + return False + return not wait_for_read(self.sock, timeout=0.0) + + @property + def has_connected_to_proxy(self) -> bool: + return self._has_connected_to_proxy + + @property + def proxy_is_forwarding(self) -> bool: + """ + Return True if a forwarding proxy is configured, else return False + """ + return bool(self.proxy) and self._tunnel_host is None + + def close(self) -> None: + try: + super().close() + finally: + # Reset all stateful properties so connection + # can be re-used without leaking prior configs. + self.sock = None + self.is_verified = False + self.proxy_is_verified = None + self._has_connected_to_proxy = False + self._response_options = None + self._tunnel_host = None + self._tunnel_port = None + self._tunnel_scheme = None + + def putrequest( + self, + method: str, + url: str, + skip_host: bool = False, + skip_accept_encoding: bool = False, + ) -> None: + """""" + # Empty docstring because the indentation of CPython's implementation + # is broken but we don't want this method in our documentation. + match = _CONTAINS_CONTROL_CHAR_RE.search(method) + if match: + raise ValueError( + f"Method cannot contain non-token characters {method!r} (found at least {match.group()!r})" + ) + + return super().putrequest( + method, url, skip_host=skip_host, skip_accept_encoding=skip_accept_encoding + ) + + def putheader(self, header: str, *values: str) -> None: # type: ignore[override] + """""" + if not any(isinstance(v, str) and v == SKIP_HEADER for v in values): + super().putheader(header, *values) + elif to_str(header.lower()) not in SKIPPABLE_HEADERS: + skippable_headers = "', '".join( + [str.title(header) for header in sorted(SKIPPABLE_HEADERS)] + ) + raise ValueError( + f"urllib3.util.SKIP_HEADER only supports '{skippable_headers}'" + ) + + # `request` method's signature intentionally violates LSP. + # urllib3's API is different from `http.client.HTTPConnection` and the subclassing is only incidental. + def request( # type: ignore[override] + self, + method: str, + url: str, + body: _TYPE_BODY | None = None, + headers: typing.Mapping[str, str] | None = None, + *, + chunked: bool = False, + preload_content: bool = True, + decode_content: bool = True, + enforce_content_length: bool = True, + ) -> None: + # Update the inner socket's timeout value to send the request. + # This only triggers if the connection is re-used. + if self.sock is not None: + self.sock.settimeout(self.timeout) + + # Store these values to be fed into the HTTPResponse + # object later. TODO: Remove this in favor of a real + # HTTP lifecycle mechanism. + + # We have to store these before we call .request() + # because sometimes we can still salvage a response + # off the wire even if we aren't able to completely + # send the request body. + self._response_options = _ResponseOptions( + request_method=method, + request_url=url, + preload_content=preload_content, + decode_content=decode_content, + enforce_content_length=enforce_content_length, + ) + + if headers is None: + headers = {} + header_keys = frozenset(to_str(k.lower()) for k in headers) + skip_accept_encoding = "accept-encoding" in header_keys + skip_host = "host" in header_keys + self.putrequest( + method, url, skip_accept_encoding=skip_accept_encoding, skip_host=skip_host + ) + + # Transform the body into an iterable of sendall()-able chunks + # and detect if an explicit Content-Length is doable. + chunks_and_cl = body_to_chunks(body, method=method, blocksize=self.blocksize) + chunks = chunks_and_cl.chunks + content_length = chunks_and_cl.content_length + + # When chunked is explicit set to 'True' we respect that. + if chunked: + if "transfer-encoding" not in header_keys: + self.putheader("Transfer-Encoding", "chunked") + else: + # Detect whether a framing mechanism is already in use. If so + # we respect that value, otherwise we pick chunked vs content-length + # depending on the type of 'body'. + if "content-length" in header_keys: + chunked = False + elif "transfer-encoding" in header_keys: + chunked = True + + # Otherwise we go off the recommendation of 'body_to_chunks()'. + else: + chunked = False + if content_length is None: + if chunks is not None: + chunked = True + self.putheader("Transfer-Encoding", "chunked") + else: + self.putheader("Content-Length", str(content_length)) + + # Now that framing headers are out of the way we send all the other headers. + if "user-agent" not in header_keys: + self.putheader("User-Agent", _get_default_user_agent()) + for header, value in headers.items(): + self.putheader(header, value) + self.endheaders() + + # If we're given a body we start sending that in chunks. + if chunks is not None: + for chunk in chunks: + # Sending empty chunks isn't allowed for TE: chunked + # as it indicates the end of the body. + if not chunk: + continue + if isinstance(chunk, str): + chunk = chunk.encode("utf-8") + if chunked: + self.send(b"%x\r\n%b\r\n" % (len(chunk), chunk)) + else: + self.send(chunk) + + # Regardless of whether we have a body or not, if we're in + # chunked mode we want to send an explicit empty chunk. + if chunked: + self.send(b"0\r\n\r\n") + + def request_chunked( + self, + method: str, + url: str, + body: _TYPE_BODY | None = None, + headers: typing.Mapping[str, str] | None = None, + ) -> None: + """ + Alternative to the common request method, which sends the + body with chunked encoding and not as one block + """ + warnings.warn( + "HTTPConnection.request_chunked() is deprecated and will be removed " + "in urllib3 v2.1.0. Instead use HTTPConnection.request(..., chunked=True).", + category=DeprecationWarning, + stacklevel=2, + ) + self.request(method, url, body=body, headers=headers, chunked=True) + + def getresponse( # type: ignore[override] + self, + ) -> HTTPResponse: + """ + Get the response from the server. + + If the HTTPConnection is in the correct state, returns an instance of HTTPResponse or of whatever object is returned by the response_class variable. + + If a request has not been sent or if a previous response has not be handled, ResponseNotReady is raised. If the HTTP response indicates that the connection should be closed, then it will be closed before the response is returned. When the connection is closed, the underlying socket is closed. + """ + # Raise the same error as http.client.HTTPConnection + if self._response_options is None: + raise ResponseNotReady() + + # Reset this attribute for being used again. + resp_options = self._response_options + self._response_options = None + + # Since the connection's timeout value may have been updated + # we need to set the timeout on the socket. + self.sock.settimeout(self.timeout) + + # This is needed here to avoid circular import errors + from .response import HTTPResponse + + # Get the response from http.client.HTTPConnection + httplib_response = super().getresponse() + + try: + assert_header_parsing(httplib_response.msg) + except (HeaderParsingError, TypeError) as hpe: + log.warning( + "Failed to parse headers (url=%s): %s", + _url_from_connection(self, resp_options.request_url), + hpe, + exc_info=True, + ) + + headers = HTTPHeaderDict(httplib_response.msg.items()) + + response = HTTPResponse( + body=httplib_response, + headers=headers, + status=httplib_response.status, + version=httplib_response.version, + version_string=getattr(self, "_http_vsn_str", "HTTP/?"), + reason=httplib_response.reason, + preload_content=resp_options.preload_content, + decode_content=resp_options.decode_content, + original_response=httplib_response, + enforce_content_length=resp_options.enforce_content_length, + request_method=resp_options.request_method, + request_url=resp_options.request_url, + ) + return response + + +class HTTPSConnection(HTTPConnection): + """ + Many of the parameters to this constructor are passed to the underlying SSL + socket by means of :py:func:`urllib3.util.ssl_wrap_socket`. + """ + + default_port = port_by_scheme["https"] # type: ignore[misc] + + cert_reqs: int | str | None = None + ca_certs: str | None = None + ca_cert_dir: str | None = None + ca_cert_data: None | str | bytes = None + ssl_version: int | str | None = None + ssl_minimum_version: int | None = None + ssl_maximum_version: int | None = None + assert_fingerprint: str | None = None + + def __init__( + self, + host: str, + port: int | None = None, + *, + timeout: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + source_address: tuple[str, int] | None = None, + blocksize: int = 16384, + socket_options: None + | (connection._TYPE_SOCKET_OPTIONS) = HTTPConnection.default_socket_options, + proxy: Url | None = None, + proxy_config: ProxyConfig | None = None, + cert_reqs: int | str | None = None, + assert_hostname: None | str | typing.Literal[False] = None, + assert_fingerprint: str | None = None, + server_hostname: str | None = None, + ssl_context: ssl.SSLContext | None = None, + ca_certs: str | None = None, + ca_cert_dir: str | None = None, + ca_cert_data: None | str | bytes = None, + ssl_minimum_version: int | None = None, + ssl_maximum_version: int | None = None, + ssl_version: int | str | None = None, # Deprecated + cert_file: str | None = None, + key_file: str | None = None, + key_password: str | None = None, + ) -> None: + super().__init__( + host, + port=port, + timeout=timeout, + source_address=source_address, + blocksize=blocksize, + socket_options=socket_options, + proxy=proxy, + proxy_config=proxy_config, + ) + + self.key_file = key_file + self.cert_file = cert_file + self.key_password = key_password + self.ssl_context = ssl_context + self.server_hostname = server_hostname + self.assert_hostname = assert_hostname + self.assert_fingerprint = assert_fingerprint + self.ssl_version = ssl_version + self.ssl_minimum_version = ssl_minimum_version + self.ssl_maximum_version = ssl_maximum_version + self.ca_certs = ca_certs and os.path.expanduser(ca_certs) + self.ca_cert_dir = ca_cert_dir and os.path.expanduser(ca_cert_dir) + self.ca_cert_data = ca_cert_data + + # cert_reqs depends on ssl_context so calculate last. + if cert_reqs is None: + if self.ssl_context is not None: + cert_reqs = self.ssl_context.verify_mode + else: + cert_reqs = resolve_cert_reqs(None) + self.cert_reqs = cert_reqs + + def set_cert( + self, + key_file: str | None = None, + cert_file: str | None = None, + cert_reqs: int | str | None = None, + key_password: str | None = None, + ca_certs: str | None = None, + assert_hostname: None | str | typing.Literal[False] = None, + assert_fingerprint: str | None = None, + ca_cert_dir: str | None = None, + ca_cert_data: None | str | bytes = None, + ) -> None: + """ + This method should only be called once, before the connection is used. + """ + warnings.warn( + "HTTPSConnection.set_cert() is deprecated and will be removed " + "in urllib3 v2.1.0. Instead provide the parameters to the " + "HTTPSConnection constructor.", + category=DeprecationWarning, + stacklevel=2, + ) + + # If cert_reqs is not provided we'll assume CERT_REQUIRED unless we also + # have an SSLContext object in which case we'll use its verify_mode. + if cert_reqs is None: + if self.ssl_context is not None: + cert_reqs = self.ssl_context.verify_mode + else: + cert_reqs = resolve_cert_reqs(None) + + self.key_file = key_file + self.cert_file = cert_file + self.cert_reqs = cert_reqs + self.key_password = key_password + self.assert_hostname = assert_hostname + self.assert_fingerprint = assert_fingerprint + self.ca_certs = ca_certs and os.path.expanduser(ca_certs) + self.ca_cert_dir = ca_cert_dir and os.path.expanduser(ca_cert_dir) + self.ca_cert_data = ca_cert_data + + def connect(self) -> None: + sock: socket.socket | ssl.SSLSocket + self.sock = sock = self._new_conn() + server_hostname: str = self.host + tls_in_tls = False + + # Do we need to establish a tunnel? + if self._tunnel_host is not None: + # We're tunneling to an HTTPS origin so need to do TLS-in-TLS. + if self._tunnel_scheme == "https": + # _connect_tls_proxy will verify and assign proxy_is_verified + self.sock = sock = self._connect_tls_proxy(self.host, sock) + tls_in_tls = True + elif self._tunnel_scheme == "http": + self.proxy_is_verified = False + + # If we're tunneling it means we're connected to our proxy. + self._has_connected_to_proxy = True + + self._tunnel() # type: ignore[attr-defined] + # Override the host with the one we're requesting data from. + server_hostname = self._tunnel_host + + if self.server_hostname is not None: + server_hostname = self.server_hostname + + is_time_off = datetime.date.today() < RECENT_DATE + if is_time_off: + warnings.warn( + ( + f"System time is way off (before {RECENT_DATE}). This will probably " + "lead to SSL verification errors" + ), + SystemTimeWarning, + ) + + # Remove trailing '.' from fqdn hostnames to allow certificate validation + server_hostname_rm_dot = server_hostname.rstrip(".") + + sock_and_verified = _ssl_wrap_socket_and_match_hostname( + sock=sock, + cert_reqs=self.cert_reqs, + ssl_version=self.ssl_version, + ssl_minimum_version=self.ssl_minimum_version, + ssl_maximum_version=self.ssl_maximum_version, + ca_certs=self.ca_certs, + ca_cert_dir=self.ca_cert_dir, + ca_cert_data=self.ca_cert_data, + cert_file=self.cert_file, + key_file=self.key_file, + key_password=self.key_password, + server_hostname=server_hostname_rm_dot, + ssl_context=self.ssl_context, + tls_in_tls=tls_in_tls, + assert_hostname=self.assert_hostname, + assert_fingerprint=self.assert_fingerprint, + ) + self.sock = sock_and_verified.socket + + # Forwarding proxies can never have a verified target since + # the proxy is the one doing the verification. Should instead + # use a CONNECT tunnel in order to verify the target. + # See: https://github.com/urllib3/urllib3/issues/3267. + if self.proxy_is_forwarding: + self.is_verified = False + else: + self.is_verified = sock_and_verified.is_verified + + # If there's a proxy to be connected to we are fully connected. + # This is set twice (once above and here) due to forwarding proxies + # not using tunnelling. + self._has_connected_to_proxy = bool(self.proxy) + + # Set `self.proxy_is_verified` unless it's already set while + # establishing a tunnel. + if self._has_connected_to_proxy and self.proxy_is_verified is None: + self.proxy_is_verified = sock_and_verified.is_verified + + def _connect_tls_proxy(self, hostname: str, sock: socket.socket) -> ssl.SSLSocket: + """ + Establish a TLS connection to the proxy using the provided SSL context. + """ + # `_connect_tls_proxy` is called when self._tunnel_host is truthy. + proxy_config = typing.cast(ProxyConfig, self.proxy_config) + ssl_context = proxy_config.ssl_context + sock_and_verified = _ssl_wrap_socket_and_match_hostname( + sock, + cert_reqs=self.cert_reqs, + ssl_version=self.ssl_version, + ssl_minimum_version=self.ssl_minimum_version, + ssl_maximum_version=self.ssl_maximum_version, + ca_certs=self.ca_certs, + ca_cert_dir=self.ca_cert_dir, + ca_cert_data=self.ca_cert_data, + server_hostname=hostname, + ssl_context=ssl_context, + assert_hostname=proxy_config.assert_hostname, + assert_fingerprint=proxy_config.assert_fingerprint, + # Features that aren't implemented for proxies yet: + cert_file=None, + key_file=None, + key_password=None, + tls_in_tls=False, + ) + self.proxy_is_verified = sock_and_verified.is_verified + return sock_and_verified.socket # type: ignore[return-value] + + +class _WrappedAndVerifiedSocket(typing.NamedTuple): + """ + Wrapped socket and whether the connection is + verified after the TLS handshake + """ + + socket: ssl.SSLSocket | SSLTransport + is_verified: bool + + +def _ssl_wrap_socket_and_match_hostname( + sock: socket.socket, + *, + cert_reqs: None | str | int, + ssl_version: None | str | int, + ssl_minimum_version: int | None, + ssl_maximum_version: int | None, + cert_file: str | None, + key_file: str | None, + key_password: str | None, + ca_certs: str | None, + ca_cert_dir: str | None, + ca_cert_data: None | str | bytes, + assert_hostname: None | str | typing.Literal[False], + assert_fingerprint: str | None, + server_hostname: str | None, + ssl_context: ssl.SSLContext | None, + tls_in_tls: bool = False, +) -> _WrappedAndVerifiedSocket: + """Logic for constructing an SSLContext from all TLS parameters, passing + that down into ssl_wrap_socket, and then doing certificate verification + either via hostname or fingerprint. This function exists to guarantee + that both proxies and targets have the same behavior when connecting via TLS. + """ + default_ssl_context = False + if ssl_context is None: + default_ssl_context = True + context = create_urllib3_context( + ssl_version=resolve_ssl_version(ssl_version), + ssl_minimum_version=ssl_minimum_version, + ssl_maximum_version=ssl_maximum_version, + cert_reqs=resolve_cert_reqs(cert_reqs), + ) + else: + context = ssl_context + + context.verify_mode = resolve_cert_reqs(cert_reqs) + + # In some cases, we want to verify hostnames ourselves + if ( + # `ssl` can't verify fingerprints or alternate hostnames + assert_fingerprint + or assert_hostname + # assert_hostname can be set to False to disable hostname checking + or assert_hostname is False + # We still support OpenSSL 1.0.2, which prevents us from verifying + # hostnames easily: https://github.com/pyca/pyopenssl/pull/933 + or ssl_.IS_PYOPENSSL + or not ssl_.HAS_NEVER_CHECK_COMMON_NAME + ): + context.check_hostname = False + + # Try to load OS default certs if none are given. We need to do the hasattr() check + # for custom pyOpenSSL SSLContext objects because they don't support + # load_default_certs(). + if ( + not ca_certs + and not ca_cert_dir + and not ca_cert_data + and default_ssl_context + and hasattr(context, "load_default_certs") + ): + context.load_default_certs() + + # Ensure that IPv6 addresses are in the proper format and don't have a + # scope ID. Python's SSL module fails to recognize scoped IPv6 addresses + # and interprets them as DNS hostnames. + if server_hostname is not None: + normalized = server_hostname.strip("[]") + if "%" in normalized: + normalized = normalized[: normalized.rfind("%")] + if is_ipaddress(normalized): + server_hostname = normalized + + ssl_sock = ssl_wrap_socket( + sock=sock, + keyfile=key_file, + certfile=cert_file, + key_password=key_password, + ca_certs=ca_certs, + ca_cert_dir=ca_cert_dir, + ca_cert_data=ca_cert_data, + server_hostname=server_hostname, + ssl_context=context, + tls_in_tls=tls_in_tls, + ) + + try: + if assert_fingerprint: + _assert_fingerprint( + ssl_sock.getpeercert(binary_form=True), assert_fingerprint + ) + elif ( + context.verify_mode != ssl.CERT_NONE + and not context.check_hostname + and assert_hostname is not False + ): + cert: _TYPE_PEER_CERT_RET_DICT = ssl_sock.getpeercert() # type: ignore[assignment] + + # Need to signal to our match_hostname whether to use 'commonName' or not. + # If we're using our own constructed SSLContext we explicitly set 'False' + # because PyPy hard-codes 'True' from SSLContext.hostname_checks_common_name. + if default_ssl_context: + hostname_checks_common_name = False + else: + hostname_checks_common_name = ( + getattr(context, "hostname_checks_common_name", False) or False + ) + + _match_hostname( + cert, + assert_hostname or server_hostname, # type: ignore[arg-type] + hostname_checks_common_name, + ) + + return _WrappedAndVerifiedSocket( + socket=ssl_sock, + is_verified=context.verify_mode == ssl.CERT_REQUIRED + or bool(assert_fingerprint), + ) + except BaseException: + ssl_sock.close() + raise + + +def _match_hostname( + cert: _TYPE_PEER_CERT_RET_DICT | None, + asserted_hostname: str, + hostname_checks_common_name: bool = False, +) -> None: + # Our upstream implementation of ssl.match_hostname() + # only applies this normalization to IP addresses so it doesn't + # match DNS SANs so we do the same thing! + stripped_hostname = asserted_hostname.strip("[]") + if is_ipaddress(stripped_hostname): + asserted_hostname = stripped_hostname + + try: + match_hostname(cert, asserted_hostname, hostname_checks_common_name) + except CertificateError as e: + log.warning( + "Certificate did not match expected hostname: %s. Certificate: %s", + asserted_hostname, + cert, + ) + # Add cert to exception and reraise so client code can inspect + # the cert when catching the exception, if they want to + e._peer_cert = cert # type: ignore[attr-defined] + raise + + +def _wrap_proxy_error(err: Exception, proxy_scheme: str | None) -> ProxyError: + # Look for the phrase 'wrong version number', if found + # then we should warn the user that we're very sure that + # this proxy is HTTP-only and they have a configuration issue. + error_normalized = " ".join(re.split("[^a-z]", str(err).lower())) + is_likely_http_proxy = ( + "wrong version number" in error_normalized + or "unknown protocol" in error_normalized + or "record layer failure" in error_normalized + ) + http_proxy_warning = ( + ". Your proxy appears to only use HTTP and not HTTPS, " + "try changing your proxy URL to be HTTP. See: " + "https://urllib3.readthedocs.io/en/latest/advanced-usage.html" + "#https-proxy-error-http-proxy" + ) + new_err = ProxyError( + f"Unable to connect to proxy" + f"{http_proxy_warning if is_likely_http_proxy and proxy_scheme == 'https' else ''}", + err, + ) + new_err.__cause__ = err + return new_err + + +def _get_default_user_agent() -> str: + return f"python-urllib3/{__version__}" + + +class DummyConnection: + """Used to detect a failed ConnectionCls import.""" + + +if not ssl: + HTTPSConnection = DummyConnection # type: ignore[misc, assignment] # noqa: F811 + + +VerifiedHTTPSConnection = HTTPSConnection + + +def _url_from_connection( + conn: HTTPConnection | HTTPSConnection, path: str | None = None +) -> str: + """Returns the URL from a given connection. This is mainly used for testing and logging.""" + + scheme = "https" if isinstance(conn, HTTPSConnection) else "http" + + return Url(scheme=scheme, host=conn.host, port=conn.port, path=path).url diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/connectionpool.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/connectionpool.py new file mode 100644 index 0000000..a2c3cf6 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/connectionpool.py @@ -0,0 +1,1182 @@ +from __future__ import annotations + +import errno +import logging +import queue +import sys +import typing +import warnings +import weakref +from socket import timeout as SocketTimeout +from types import TracebackType + +from ._base_connection import _TYPE_BODY +from ._collections import HTTPHeaderDict +from ._request_methods import RequestMethods +from .connection import ( + BaseSSLError, + BrokenPipeError, + DummyConnection, + HTTPConnection, + HTTPException, + HTTPSConnection, + ProxyConfig, + _wrap_proxy_error, +) +from .connection import port_by_scheme as port_by_scheme +from .exceptions import ( + ClosedPoolError, + EmptyPoolError, + FullPoolError, + HostChangedError, + InsecureRequestWarning, + LocationValueError, + MaxRetryError, + NewConnectionError, + ProtocolError, + ProxyError, + ReadTimeoutError, + SSLError, + TimeoutError, +) +from .response import BaseHTTPResponse +from .util.connection import is_connection_dropped +from .util.proxy import connection_requires_http_tunnel +from .util.request import _TYPE_BODY_POSITION, set_file_position +from .util.retry import Retry +from .util.ssl_match_hostname import CertificateError +from .util.timeout import _DEFAULT_TIMEOUT, _TYPE_DEFAULT, Timeout +from .util.url import Url, _encode_target +from .util.url import _normalize_host as normalize_host +from .util.url import parse_url +from .util.util import to_str + +if typing.TYPE_CHECKING: + import ssl + + from typing_extensions import Self + + from ._base_connection import BaseHTTPConnection, BaseHTTPSConnection + +log = logging.getLogger(__name__) + +_TYPE_TIMEOUT = typing.Union[Timeout, float, _TYPE_DEFAULT, None] + + +# Pool objects +class ConnectionPool: + """ + Base class for all connection pools, such as + :class:`.HTTPConnectionPool` and :class:`.HTTPSConnectionPool`. + + .. note:: + ConnectionPool.urlopen() does not normalize or percent-encode target URIs + which is useful if your target server doesn't support percent-encoded + target URIs. + """ + + scheme: str | None = None + QueueCls = queue.LifoQueue + + def __init__(self, host: str, port: int | None = None) -> None: + if not host: + raise LocationValueError("No host specified.") + + self.host = _normalize_host(host, scheme=self.scheme) + self.port = port + + # This property uses 'normalize_host()' (not '_normalize_host()') + # to avoid removing square braces around IPv6 addresses. + # This value is sent to `HTTPConnection.set_tunnel()` if called + # because square braces are required for HTTP CONNECT tunneling. + self._tunnel_host = normalize_host(host, scheme=self.scheme).lower() + + def __str__(self) -> str: + return f"{type(self).__name__}(host={self.host!r}, port={self.port!r})" + + def __enter__(self) -> Self: + return self + + def __exit__( + self, + exc_type: type[BaseException] | None, + exc_val: BaseException | None, + exc_tb: TracebackType | None, + ) -> typing.Literal[False]: + self.close() + # Return False to re-raise any potential exceptions + return False + + def close(self) -> None: + """ + Close all pooled connections and disable the pool. + """ + + +# This is taken from http://hg.python.org/cpython/file/7aaba721ebc0/Lib/socket.py#l252 +_blocking_errnos = {errno.EAGAIN, errno.EWOULDBLOCK} + + +class HTTPConnectionPool(ConnectionPool, RequestMethods): + """ + Thread-safe connection pool for one host. + + :param host: + Host used for this HTTP Connection (e.g. "localhost"), passed into + :class:`http.client.HTTPConnection`. + + :param port: + Port used for this HTTP Connection (None is equivalent to 80), passed + into :class:`http.client.HTTPConnection`. + + :param timeout: + Socket timeout in seconds for each individual connection. This can + be a float or integer, which sets the timeout for the HTTP request, + or an instance of :class:`urllib3.util.Timeout` which gives you more + fine-grained control over request timeouts. After the constructor has + been parsed, this is always a `urllib3.util.Timeout` object. + + :param maxsize: + Number of connections to save that can be reused. More than 1 is useful + in multithreaded situations. If ``block`` is set to False, more + connections will be created but they will not be saved once they've + been used. + + :param block: + If set to True, no more than ``maxsize`` connections will be used at + a time. When no free connections are available, the call will block + until a connection has been released. This is a useful side effect for + particular multithreaded situations where one does not want to use more + than maxsize connections per host to prevent flooding. + + :param headers: + Headers to include with all requests, unless other headers are given + explicitly. + + :param retries: + Retry configuration to use by default with requests in this pool. + + :param _proxy: + Parsed proxy URL, should not be used directly, instead, see + :class:`urllib3.ProxyManager` + + :param _proxy_headers: + A dictionary with proxy headers, should not be used directly, + instead, see :class:`urllib3.ProxyManager` + + :param \\**conn_kw: + Additional parameters are used to create fresh :class:`urllib3.connection.HTTPConnection`, + :class:`urllib3.connection.HTTPSConnection` instances. + """ + + scheme = "http" + ConnectionCls: ( + type[BaseHTTPConnection] | type[BaseHTTPSConnection] + ) = HTTPConnection + + def __init__( + self, + host: str, + port: int | None = None, + timeout: _TYPE_TIMEOUT | None = _DEFAULT_TIMEOUT, + maxsize: int = 1, + block: bool = False, + headers: typing.Mapping[str, str] | None = None, + retries: Retry | bool | int | None = None, + _proxy: Url | None = None, + _proxy_headers: typing.Mapping[str, str] | None = None, + _proxy_config: ProxyConfig | None = None, + **conn_kw: typing.Any, + ): + ConnectionPool.__init__(self, host, port) + RequestMethods.__init__(self, headers) + + if not isinstance(timeout, Timeout): + timeout = Timeout.from_float(timeout) + + if retries is None: + retries = Retry.DEFAULT + + self.timeout = timeout + self.retries = retries + + self.pool: queue.LifoQueue[typing.Any] | None = self.QueueCls(maxsize) + self.block = block + + self.proxy = _proxy + self.proxy_headers = _proxy_headers or {} + self.proxy_config = _proxy_config + + # Fill the queue up so that doing get() on it will block properly + for _ in range(maxsize): + self.pool.put(None) + + # These are mostly for testing and debugging purposes. + self.num_connections = 0 + self.num_requests = 0 + self.conn_kw = conn_kw + + if self.proxy: + # Enable Nagle's algorithm for proxies, to avoid packet fragmentation. + # We cannot know if the user has added default socket options, so we cannot replace the + # list. + self.conn_kw.setdefault("socket_options", []) + + self.conn_kw["proxy"] = self.proxy + self.conn_kw["proxy_config"] = self.proxy_config + + # Do not pass 'self' as callback to 'finalize'. + # Then the 'finalize' would keep an endless living (leak) to self. + # By just passing a reference to the pool allows the garbage collector + # to free self if nobody else has a reference to it. + pool = self.pool + + # Close all the HTTPConnections in the pool before the + # HTTPConnectionPool object is garbage collected. + weakref.finalize(self, _close_pool_connections, pool) + + def _new_conn(self) -> BaseHTTPConnection: + """ + Return a fresh :class:`HTTPConnection`. + """ + self.num_connections += 1 + log.debug( + "Starting new HTTP connection (%d): %s:%s", + self.num_connections, + self.host, + self.port or "80", + ) + + conn = self.ConnectionCls( + host=self.host, + port=self.port, + timeout=self.timeout.connect_timeout, + **self.conn_kw, + ) + return conn + + def _get_conn(self, timeout: float | None = None) -> BaseHTTPConnection: + """ + Get a connection. Will return a pooled connection if one is available. + + If no connections are available and :prop:`.block` is ``False``, then a + fresh connection is returned. + + :param timeout: + Seconds to wait before giving up and raising + :class:`urllib3.exceptions.EmptyPoolError` if the pool is empty and + :prop:`.block` is ``True``. + """ + conn = None + + if self.pool is None: + raise ClosedPoolError(self, "Pool is closed.") + + try: + conn = self.pool.get(block=self.block, timeout=timeout) + + except AttributeError: # self.pool is None + raise ClosedPoolError(self, "Pool is closed.") from None # Defensive: + + except queue.Empty: + if self.block: + raise EmptyPoolError( + self, + "Pool is empty and a new connection can't be opened due to blocking mode.", + ) from None + pass # Oh well, we'll create a new connection then + + # If this is a persistent connection, check if it got disconnected + if conn and is_connection_dropped(conn): + log.debug("Resetting dropped connection: %s", self.host) + conn.close() + + return conn or self._new_conn() + + def _put_conn(self, conn: BaseHTTPConnection | None) -> None: + """ + Put a connection back into the pool. + + :param conn: + Connection object for the current host and port as returned by + :meth:`._new_conn` or :meth:`._get_conn`. + + If the pool is already full, the connection is closed and discarded + because we exceeded maxsize. If connections are discarded frequently, + then maxsize should be increased. + + If the pool is closed, then the connection will be closed and discarded. + """ + if self.pool is not None: + try: + self.pool.put(conn, block=False) + return # Everything is dandy, done. + except AttributeError: + # self.pool is None. + pass + except queue.Full: + # Connection never got put back into the pool, close it. + if conn: + conn.close() + + if self.block: + # This should never happen if you got the conn from self._get_conn + raise FullPoolError( + self, + "Pool reached maximum size and no more connections are allowed.", + ) from None + + log.warning( + "Connection pool is full, discarding connection: %s. Connection pool size: %s", + self.host, + self.pool.qsize(), + ) + + # Connection never got put back into the pool, close it. + if conn: + conn.close() + + def _validate_conn(self, conn: BaseHTTPConnection) -> None: + """ + Called right before a request is made, after the socket is created. + """ + + def _prepare_proxy(self, conn: BaseHTTPConnection) -> None: + # Nothing to do for HTTP connections. + pass + + def _get_timeout(self, timeout: _TYPE_TIMEOUT) -> Timeout: + """Helper that always returns a :class:`urllib3.util.Timeout`""" + if timeout is _DEFAULT_TIMEOUT: + return self.timeout.clone() + + if isinstance(timeout, Timeout): + return timeout.clone() + else: + # User passed us an int/float. This is for backwards compatibility, + # can be removed later + return Timeout.from_float(timeout) + + def _raise_timeout( + self, + err: BaseSSLError | OSError | SocketTimeout, + url: str, + timeout_value: _TYPE_TIMEOUT | None, + ) -> None: + """Is the error actually a timeout? Will raise a ReadTimeout or pass""" + + if isinstance(err, SocketTimeout): + raise ReadTimeoutError( + self, url, f"Read timed out. (read timeout={timeout_value})" + ) from err + + # See the above comment about EAGAIN in Python 3. + if hasattr(err, "errno") and err.errno in _blocking_errnos: + raise ReadTimeoutError( + self, url, f"Read timed out. (read timeout={timeout_value})" + ) from err + + def _make_request( + self, + conn: BaseHTTPConnection, + method: str, + url: str, + body: _TYPE_BODY | None = None, + headers: typing.Mapping[str, str] | None = None, + retries: Retry | None = None, + timeout: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + chunked: bool = False, + response_conn: BaseHTTPConnection | None = None, + preload_content: bool = True, + decode_content: bool = True, + enforce_content_length: bool = True, + ) -> BaseHTTPResponse: + """ + Perform a request on a given urllib connection object taken from our + pool. + + :param conn: + a connection from one of our connection pools + + :param method: + HTTP request method (such as GET, POST, PUT, etc.) + + :param url: + The URL to perform the request on. + + :param body: + Data to send in the request body, either :class:`str`, :class:`bytes`, + an iterable of :class:`str`/:class:`bytes`, or a file-like object. + + :param headers: + Dictionary of custom headers to send, such as User-Agent, + If-None-Match, etc. If None, pool headers are used. If provided, + these headers completely replace any pool-specific headers. + + :param retries: + Configure the number of retries to allow before raising a + :class:`~urllib3.exceptions.MaxRetryError` exception. + + Pass ``None`` to retry until you receive a response. Pass a + :class:`~urllib3.util.retry.Retry` object for fine-grained control + over different types of retries. + Pass an integer number to retry connection errors that many times, + but no other types of errors. Pass zero to never retry. + + If ``False``, then retries are disabled and any exception is raised + immediately. Also, instead of raising a MaxRetryError on redirects, + the redirect response will be returned. + + :type retries: :class:`~urllib3.util.retry.Retry`, False, or an int. + + :param timeout: + If specified, overrides the default timeout for this one + request. It may be a float (in seconds) or an instance of + :class:`urllib3.util.Timeout`. + + :param chunked: + If True, urllib3 will send the body using chunked transfer + encoding. Otherwise, urllib3 will send the body using the standard + content-length form. Defaults to False. + + :param response_conn: + Set this to ``None`` if you will handle releasing the connection or + set the connection to have the response release it. + + :param preload_content: + If True, the response's body will be preloaded during construction. + + :param decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + + :param enforce_content_length: + Enforce content length checking. Body returned by server must match + value of Content-Length header, if present. Otherwise, raise error. + """ + self.num_requests += 1 + + timeout_obj = self._get_timeout(timeout) + timeout_obj.start_connect() + conn.timeout = Timeout.resolve_default_timeout(timeout_obj.connect_timeout) + + try: + # Trigger any extra validation we need to do. + try: + self._validate_conn(conn) + except (SocketTimeout, BaseSSLError) as e: + self._raise_timeout(err=e, url=url, timeout_value=conn.timeout) + raise + + # _validate_conn() starts the connection to an HTTPS proxy + # so we need to wrap errors with 'ProxyError' here too. + except ( + OSError, + NewConnectionError, + TimeoutError, + BaseSSLError, + CertificateError, + SSLError, + ) as e: + new_e: Exception = e + if isinstance(e, (BaseSSLError, CertificateError)): + new_e = SSLError(e) + # If the connection didn't successfully connect to it's proxy + # then there + if isinstance( + new_e, (OSError, NewConnectionError, TimeoutError, SSLError) + ) and (conn and conn.proxy and not conn.has_connected_to_proxy): + new_e = _wrap_proxy_error(new_e, conn.proxy.scheme) + raise new_e + + # conn.request() calls http.client.*.request, not the method in + # urllib3.request. It also calls makefile (recv) on the socket. + try: + conn.request( + method, + url, + body=body, + headers=headers, + chunked=chunked, + preload_content=preload_content, + decode_content=decode_content, + enforce_content_length=enforce_content_length, + ) + + # We are swallowing BrokenPipeError (errno.EPIPE) since the server is + # legitimately able to close the connection after sending a valid response. + # With this behaviour, the received response is still readable. + except BrokenPipeError: + pass + except OSError as e: + # MacOS/Linux + # EPROTOTYPE and ECONNRESET are needed on macOS + # https://erickt.github.io/blog/2014/11/19/adventures-in-debugging-a-potential-osx-kernel-bug/ + # Condition changed later to emit ECONNRESET instead of only EPROTOTYPE. + if e.errno != errno.EPROTOTYPE and e.errno != errno.ECONNRESET: + raise + + # Reset the timeout for the recv() on the socket + read_timeout = timeout_obj.read_timeout + + if not conn.is_closed: + # In Python 3 socket.py will catch EAGAIN and return None when you + # try and read into the file pointer created by http.client, which + # instead raises a BadStatusLine exception. Instead of catching + # the exception and assuming all BadStatusLine exceptions are read + # timeouts, check for a zero timeout before making the request. + if read_timeout == 0: + raise ReadTimeoutError( + self, url, f"Read timed out. (read timeout={read_timeout})" + ) + conn.timeout = read_timeout + + # Receive the response from the server + try: + response = conn.getresponse() + except (BaseSSLError, OSError) as e: + self._raise_timeout(err=e, url=url, timeout_value=read_timeout) + raise + + # Set properties that are used by the pooling layer. + response.retries = retries + response._connection = response_conn # type: ignore[attr-defined] + response._pool = self # type: ignore[attr-defined] + + log.debug( + '%s://%s:%s "%s %s HTTP/%s" %s %s', + self.scheme, + self.host, + self.port, + method, + url, + response.version, + response.status, + response.length_remaining, + ) + + return response + + def close(self) -> None: + """ + Close all pooled connections and disable the pool. + """ + if self.pool is None: + return + # Disable access to the pool + old_pool, self.pool = self.pool, None + + # Close all the HTTPConnections in the pool. + _close_pool_connections(old_pool) + + def is_same_host(self, url: str) -> bool: + """ + Check if the given ``url`` is a member of the same host as this + connection pool. + """ + if url.startswith("/"): + return True + + # TODO: Add optional support for socket.gethostbyname checking. + scheme, _, host, port, *_ = parse_url(url) + scheme = scheme or "http" + if host is not None: + host = _normalize_host(host, scheme=scheme) + + # Use explicit default port for comparison when none is given + if self.port and not port: + port = port_by_scheme.get(scheme) + elif not self.port and port == port_by_scheme.get(scheme): + port = None + + return (scheme, host, port) == (self.scheme, self.host, self.port) + + def urlopen( # type: ignore[override] + self, + method: str, + url: str, + body: _TYPE_BODY | None = None, + headers: typing.Mapping[str, str] | None = None, + retries: Retry | bool | int | None = None, + redirect: bool = True, + assert_same_host: bool = True, + timeout: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + pool_timeout: int | None = None, + release_conn: bool | None = None, + chunked: bool = False, + body_pos: _TYPE_BODY_POSITION | None = None, + preload_content: bool = True, + decode_content: bool = True, + **response_kw: typing.Any, + ) -> BaseHTTPResponse: + """ + Get a connection from the pool and perform an HTTP request. This is the + lowest level call for making a request, so you'll need to specify all + the raw details. + + .. note:: + + More commonly, it's appropriate to use a convenience method + such as :meth:`request`. + + .. note:: + + `release_conn` will only behave as expected if + `preload_content=False` because we want to make + `preload_content=False` the default behaviour someday soon without + breaking backwards compatibility. + + :param method: + HTTP request method (such as GET, POST, PUT, etc.) + + :param url: + The URL to perform the request on. + + :param body: + Data to send in the request body, either :class:`str`, :class:`bytes`, + an iterable of :class:`str`/:class:`bytes`, or a file-like object. + + :param headers: + Dictionary of custom headers to send, such as User-Agent, + If-None-Match, etc. If None, pool headers are used. If provided, + these headers completely replace any pool-specific headers. + + :param retries: + Configure the number of retries to allow before raising a + :class:`~urllib3.exceptions.MaxRetryError` exception. + + If ``None`` (default) will retry 3 times, see ``Retry.DEFAULT``. Pass a + :class:`~urllib3.util.retry.Retry` object for fine-grained control + over different types of retries. + Pass an integer number to retry connection errors that many times, + but no other types of errors. Pass zero to never retry. + + If ``False``, then retries are disabled and any exception is raised + immediately. Also, instead of raising a MaxRetryError on redirects, + the redirect response will be returned. + + :type retries: :class:`~urllib3.util.retry.Retry`, False, or an int. + + :param redirect: + If True, automatically handle redirects (status codes 301, 302, + 303, 307, 308). Each redirect counts as a retry. Disabling retries + will disable redirect, too. + + :param assert_same_host: + If ``True``, will make sure that the host of the pool requests is + consistent else will raise HostChangedError. When ``False``, you can + use the pool on an HTTP proxy and request foreign hosts. + + :param timeout: + If specified, overrides the default timeout for this one + request. It may be a float (in seconds) or an instance of + :class:`urllib3.util.Timeout`. + + :param pool_timeout: + If set and the pool is set to block=True, then this method will + block for ``pool_timeout`` seconds and raise EmptyPoolError if no + connection is available within the time period. + + :param bool preload_content: + If True, the response's body will be preloaded into memory. + + :param bool decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + + :param release_conn: + If False, then the urlopen call will not release the connection + back into the pool once a response is received (but will release if + you read the entire contents of the response such as when + `preload_content=True`). This is useful if you're not preloading + the response's content immediately. You will need to call + ``r.release_conn()`` on the response ``r`` to return the connection + back into the pool. If None, it takes the value of ``preload_content`` + which defaults to ``True``. + + :param bool chunked: + If True, urllib3 will send the body using chunked transfer + encoding. Otherwise, urllib3 will send the body using the standard + content-length form. Defaults to False. + + :param int body_pos: + Position to seek to in file-like body in the event of a retry or + redirect. Typically this won't need to be set because urllib3 will + auto-populate the value when needed. + """ + parsed_url = parse_url(url) + destination_scheme = parsed_url.scheme + + if headers is None: + headers = self.headers + + if not isinstance(retries, Retry): + retries = Retry.from_int(retries, redirect=redirect, default=self.retries) + + if release_conn is None: + release_conn = preload_content + + # Check host + if assert_same_host and not self.is_same_host(url): + raise HostChangedError(self, url, retries) + + # Ensure that the URL we're connecting to is properly encoded + if url.startswith("/"): + url = to_str(_encode_target(url)) + else: + url = to_str(parsed_url.url) + + conn = None + + # Track whether `conn` needs to be released before + # returning/raising/recursing. Update this variable if necessary, and + # leave `release_conn` constant throughout the function. That way, if + # the function recurses, the original value of `release_conn` will be + # passed down into the recursive call, and its value will be respected. + # + # See issue #651 [1] for details. + # + # [1] + release_this_conn = release_conn + + http_tunnel_required = connection_requires_http_tunnel( + self.proxy, self.proxy_config, destination_scheme + ) + + # Merge the proxy headers. Only done when not using HTTP CONNECT. We + # have to copy the headers dict so we can safely change it without those + # changes being reflected in anyone else's copy. + if not http_tunnel_required: + headers = headers.copy() # type: ignore[attr-defined] + headers.update(self.proxy_headers) # type: ignore[union-attr] + + # Must keep the exception bound to a separate variable or else Python 3 + # complains about UnboundLocalError. + err = None + + # Keep track of whether we cleanly exited the except block. This + # ensures we do proper cleanup in finally. + clean_exit = False + + # Rewind body position, if needed. Record current position + # for future rewinds in the event of a redirect/retry. + body_pos = set_file_position(body, body_pos) + + try: + # Request a connection from the queue. + timeout_obj = self._get_timeout(timeout) + conn = self._get_conn(timeout=pool_timeout) + + conn.timeout = timeout_obj.connect_timeout # type: ignore[assignment] + + # Is this a closed/new connection that requires CONNECT tunnelling? + if self.proxy is not None and http_tunnel_required and conn.is_closed: + try: + self._prepare_proxy(conn) + except (BaseSSLError, OSError, SocketTimeout) as e: + self._raise_timeout( + err=e, url=self.proxy.url, timeout_value=conn.timeout + ) + raise + + # If we're going to release the connection in ``finally:``, then + # the response doesn't need to know about the connection. Otherwise + # it will also try to release it and we'll have a double-release + # mess. + response_conn = conn if not release_conn else None + + # Make the request on the HTTPConnection object + response = self._make_request( + conn, + method, + url, + timeout=timeout_obj, + body=body, + headers=headers, + chunked=chunked, + retries=retries, + response_conn=response_conn, + preload_content=preload_content, + decode_content=decode_content, + **response_kw, + ) + + # Everything went great! + clean_exit = True + + except EmptyPoolError: + # Didn't get a connection from the pool, no need to clean up + clean_exit = True + release_this_conn = False + raise + + except ( + TimeoutError, + HTTPException, + OSError, + ProtocolError, + BaseSSLError, + SSLError, + CertificateError, + ProxyError, + ) as e: + # Discard the connection for these exceptions. It will be + # replaced during the next _get_conn() call. + clean_exit = False + new_e: Exception = e + if isinstance(e, (BaseSSLError, CertificateError)): + new_e = SSLError(e) + if isinstance( + new_e, + ( + OSError, + NewConnectionError, + TimeoutError, + SSLError, + HTTPException, + ), + ) and (conn and conn.proxy and not conn.has_connected_to_proxy): + new_e = _wrap_proxy_error(new_e, conn.proxy.scheme) + elif isinstance(new_e, (OSError, HTTPException)): + new_e = ProtocolError("Connection aborted.", new_e) + + retries = retries.increment( + method, url, error=new_e, _pool=self, _stacktrace=sys.exc_info()[2] + ) + retries.sleep() + + # Keep track of the error for the retry warning. + err = e + + finally: + if not clean_exit: + # We hit some kind of exception, handled or otherwise. We need + # to throw the connection away unless explicitly told not to. + # Close the connection, set the variable to None, and make sure + # we put the None back in the pool to avoid leaking it. + if conn: + conn.close() + conn = None + release_this_conn = True + + if release_this_conn: + # Put the connection back to be reused. If the connection is + # expired then it will be None, which will get replaced with a + # fresh connection during _get_conn. + self._put_conn(conn) + + if not conn: + # Try again + log.warning( + "Retrying (%r) after connection broken by '%r': %s", retries, err, url + ) + return self.urlopen( + method, + url, + body, + headers, + retries, + redirect, + assert_same_host, + timeout=timeout, + pool_timeout=pool_timeout, + release_conn=release_conn, + chunked=chunked, + body_pos=body_pos, + preload_content=preload_content, + decode_content=decode_content, + **response_kw, + ) + + # Handle redirect? + redirect_location = redirect and response.get_redirect_location() + if redirect_location: + if response.status == 303: + # Change the method according to RFC 9110, Section 15.4.4. + method = "GET" + # And lose the body not to transfer anything sensitive. + body = None + headers = HTTPHeaderDict(headers)._prepare_for_method_change() + + try: + retries = retries.increment(method, url, response=response, _pool=self) + except MaxRetryError: + if retries.raise_on_redirect: + response.drain_conn() + raise + return response + + response.drain_conn() + retries.sleep_for_retry(response) + log.debug("Redirecting %s -> %s", url, redirect_location) + return self.urlopen( + method, + redirect_location, + body, + headers, + retries=retries, + redirect=redirect, + assert_same_host=assert_same_host, + timeout=timeout, + pool_timeout=pool_timeout, + release_conn=release_conn, + chunked=chunked, + body_pos=body_pos, + preload_content=preload_content, + decode_content=decode_content, + **response_kw, + ) + + # Check if we should retry the HTTP response. + has_retry_after = bool(response.headers.get("Retry-After")) + if retries.is_retry(method, response.status, has_retry_after): + try: + retries = retries.increment(method, url, response=response, _pool=self) + except MaxRetryError: + if retries.raise_on_status: + response.drain_conn() + raise + return response + + response.drain_conn() + retries.sleep(response) + log.debug("Retry: %s", url) + return self.urlopen( + method, + url, + body, + headers, + retries=retries, + redirect=redirect, + assert_same_host=assert_same_host, + timeout=timeout, + pool_timeout=pool_timeout, + release_conn=release_conn, + chunked=chunked, + body_pos=body_pos, + preload_content=preload_content, + decode_content=decode_content, + **response_kw, + ) + + return response + + +class HTTPSConnectionPool(HTTPConnectionPool): + """ + Same as :class:`.HTTPConnectionPool`, but HTTPS. + + :class:`.HTTPSConnection` uses one of ``assert_fingerprint``, + ``assert_hostname`` and ``host`` in this order to verify connections. + If ``assert_hostname`` is False, no verification is done. + + The ``key_file``, ``cert_file``, ``cert_reqs``, ``ca_certs``, + ``ca_cert_dir``, ``ssl_version``, ``key_password`` are only used if :mod:`ssl` + is available and are fed into :meth:`urllib3.util.ssl_wrap_socket` to upgrade + the connection socket into an SSL socket. + """ + + scheme = "https" + ConnectionCls: type[BaseHTTPSConnection] = HTTPSConnection + + def __init__( + self, + host: str, + port: int | None = None, + timeout: _TYPE_TIMEOUT | None = _DEFAULT_TIMEOUT, + maxsize: int = 1, + block: bool = False, + headers: typing.Mapping[str, str] | None = None, + retries: Retry | bool | int | None = None, + _proxy: Url | None = None, + _proxy_headers: typing.Mapping[str, str] | None = None, + key_file: str | None = None, + cert_file: str | None = None, + cert_reqs: int | str | None = None, + key_password: str | None = None, + ca_certs: str | None = None, + ssl_version: int | str | None = None, + ssl_minimum_version: ssl.TLSVersion | None = None, + ssl_maximum_version: ssl.TLSVersion | None = None, + assert_hostname: str | typing.Literal[False] | None = None, + assert_fingerprint: str | None = None, + ca_cert_dir: str | None = None, + **conn_kw: typing.Any, + ) -> None: + super().__init__( + host, + port, + timeout, + maxsize, + block, + headers, + retries, + _proxy, + _proxy_headers, + **conn_kw, + ) + + self.key_file = key_file + self.cert_file = cert_file + self.cert_reqs = cert_reqs + self.key_password = key_password + self.ca_certs = ca_certs + self.ca_cert_dir = ca_cert_dir + self.ssl_version = ssl_version + self.ssl_minimum_version = ssl_minimum_version + self.ssl_maximum_version = ssl_maximum_version + self.assert_hostname = assert_hostname + self.assert_fingerprint = assert_fingerprint + + def _prepare_proxy(self, conn: HTTPSConnection) -> None: # type: ignore[override] + """Establishes a tunnel connection through HTTP CONNECT.""" + if self.proxy and self.proxy.scheme == "https": + tunnel_scheme = "https" + else: + tunnel_scheme = "http" + + conn.set_tunnel( + scheme=tunnel_scheme, + host=self._tunnel_host, + port=self.port, + headers=self.proxy_headers, + ) + conn.connect() + + def _new_conn(self) -> BaseHTTPSConnection: + """ + Return a fresh :class:`urllib3.connection.HTTPConnection`. + """ + self.num_connections += 1 + log.debug( + "Starting new HTTPS connection (%d): %s:%s", + self.num_connections, + self.host, + self.port or "443", + ) + + if not self.ConnectionCls or self.ConnectionCls is DummyConnection: # type: ignore[comparison-overlap] + raise ImportError( + "Can't connect to HTTPS URL because the SSL module is not available." + ) + + actual_host: str = self.host + actual_port = self.port + if self.proxy is not None and self.proxy.host is not None: + actual_host = self.proxy.host + actual_port = self.proxy.port + + return self.ConnectionCls( + host=actual_host, + port=actual_port, + timeout=self.timeout.connect_timeout, + cert_file=self.cert_file, + key_file=self.key_file, + key_password=self.key_password, + cert_reqs=self.cert_reqs, + ca_certs=self.ca_certs, + ca_cert_dir=self.ca_cert_dir, + assert_hostname=self.assert_hostname, + assert_fingerprint=self.assert_fingerprint, + ssl_version=self.ssl_version, + ssl_minimum_version=self.ssl_minimum_version, + ssl_maximum_version=self.ssl_maximum_version, + **self.conn_kw, + ) + + def _validate_conn(self, conn: BaseHTTPConnection) -> None: + """ + Called right before a request is made, after the socket is created. + """ + super()._validate_conn(conn) + + # Force connect early to allow us to validate the connection. + if conn.is_closed: + conn.connect() + + # TODO revise this, see https://github.com/urllib3/urllib3/issues/2791 + if not conn.is_verified and not conn.proxy_is_verified: + warnings.warn( + ( + f"Unverified HTTPS request is being made to host '{conn.host}'. " + "Adding certificate verification is strongly advised. See: " + "https://urllib3.readthedocs.io/en/latest/advanced-usage.html" + "#tls-warnings" + ), + InsecureRequestWarning, + ) + + +def connection_from_url(url: str, **kw: typing.Any) -> HTTPConnectionPool: + """ + Given a url, return an :class:`.ConnectionPool` instance of its host. + + This is a shortcut for not having to parse out the scheme, host, and port + of the url before creating an :class:`.ConnectionPool` instance. + + :param url: + Absolute URL string that must include the scheme. Port is optional. + + :param \\**kw: + Passes additional parameters to the constructor of the appropriate + :class:`.ConnectionPool`. Useful for specifying things like + timeout, maxsize, headers, etc. + + Example:: + + >>> conn = connection_from_url('http://google.com/') + >>> r = conn.request('GET', '/') + """ + scheme, _, host, port, *_ = parse_url(url) + scheme = scheme or "http" + port = port or port_by_scheme.get(scheme, 80) + if scheme == "https": + return HTTPSConnectionPool(host, port=port, **kw) # type: ignore[arg-type] + else: + return HTTPConnectionPool(host, port=port, **kw) # type: ignore[arg-type] + + +@typing.overload +def _normalize_host(host: None, scheme: str | None) -> None: + ... + + +@typing.overload +def _normalize_host(host: str, scheme: str | None) -> str: + ... + + +def _normalize_host(host: str | None, scheme: str | None) -> str | None: + """ + Normalize hosts for comparisons and use with sockets. + """ + + host = normalize_host(host, scheme) + + # httplib doesn't like it when we include brackets in IPv6 addresses + # Specifically, if we include brackets but also pass the port then + # httplib crazily doubles up the square brackets on the Host header. + # Instead, we need to make sure we never pass ``None`` as the port. + # However, for backward compatibility reasons we can't actually + # *assert* that. See http://bugs.python.org/issue28539 + if host and host.startswith("[") and host.endswith("]"): + host = host[1:-1] + return host + + +def _url_from_pool( + pool: HTTPConnectionPool | HTTPSConnectionPool, path: str | None = None +) -> str: + """Returns the URL from a given connection pool. This is mainly used for testing and logging.""" + return Url(scheme=pool.scheme, host=pool.host, port=pool.port, path=path).url + + +def _close_pool_connections(pool: queue.LifoQueue[typing.Any]) -> None: + """Drains a queue of connections and closes each one.""" + try: + while True: + conn = pool.get(block=False) + if conn: + conn.close() + except queue.Empty: + pass # Done. diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__init__.py new file mode 100644 index 0000000..e69de29 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..9831ea6c31b28b2735154ae7c945137b8bb9577f GIT binary patch literal 160 zcmX@j%ge<81k+W{q=D$iAOanHW&w&!XQ*V*Wb|9fP{ah}eFmxdWv^e7TcBT%S)f~z zSd^YxqFYs*UsRQ1TBM(onWSG(S(1^Tr(ar>1LPU&C+Fvt6aj_f<1_OzOXB183Mzkb f*yQG?l;)(`6|n-%V+7)25aS~=BO_xGGmr%UaqB0` literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/pyopenssl.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/pyopenssl.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..e3c5f6d57372920d4b0c709349cdfefe459845c2 GIT binary patch literal 26897 zcmdUX3vgRkdfvUbcmpIzf+YBqu1Ly!h=d-LWLhtqA}NcOL_J9PLDvgGyr2XM1n3J; z6luz)yh<#2y|L8YjpW(gm~Jy&s!nQcvx%Lgo%prcPMS^uQ!41Y+E&{*Gu^f`rA=?+ zXw%2{pZfp^LXy47Os7}kxd-R`=k=d+{^vRO-xd@&IXqVy{&M)^$2jh<=!gCks1bhY zPwar;j&c$=$Vt3pitwYRK@(4LAtDT#@is>+qt-zy&p9a760wci2kjb!YtY3Y-GgrS zE*LDp+a4(#^$dC#j3ZJsS~OV9;!ea%21^ikN$!Yuv~;kP=RyS|Eqb>yZ`q1^3L@pB zzCj=03nkA9(_lrYbYxQoMvskb)?=A>$UL$&^GlD7bm+0n`!02E%RuO{uTZCZWQSfV z^S(>@T^R^H78V9YsVKBYDyC{oT&OPOmP+0wkNtpMxP}|5eD|6q}lDfH9xmWoiA_jDzG9ewKZ|Kx~np! z1~;)1)%Ph;lU1Ufm8iW>iB(x8HnS3|?^8m|DzSx?SVJYSx*{uaJrZ4+7TS0h*s-qw zE9ZsXMA*Gc?TLGoXun6f)Aud6`5vXue7VwL>)=jCrRu&iF4ZxsBT##?} zIzQI$-)er`->aYbv7Ud8<;5{Dx{G17o-isk3_g4p?liMA+@_evY3X1se%+@qY-a-Ngc=@fnNu~6~IZ|AA~ zvA{k(m6d8msWzk3eh1`+eE+0Pk{>M{m=x-{kfVW z!JQGF;wJbZNGB?do8X$;ga5KRGV=*}qlEnVL-d6GWctVWECd95v=`$D(mjFN3SR!^p4vw9iB(TwNG(0*!DsJ?*`!~0W!*XmC2#*2bz!57E zmZHII$W2s}b8l=SgfX^e&5jg8DRdTC$!?_;!xkq_hB2oTAxvqA;VW@c4gs-Y3_1~+ z6i;nN`i42LGfF@4-}=-F|Ulz^nCV&mdaFsh@1Fg24;WAD1IohVA~LSTrGrkNb_f z{o&{ca1jVc6S05>bxfU)$=J9oYU_%+?o=1Ih;*#;6XB>h8lfV5}FG52w8 za}aWl1Jki+2m`|Y!RikuLPO*6L~JxX6*_jzsqUXv5jze`J{X-8V?drPCc>j3Z6i@z z$Q>Jt(CDzR)rRBR7Cm-M@A0u#XC!r9CL#6+H&v zT_N%zu&J4q3!NDXjU~ih)<%yk$K*`IW5IZwEsB6K72CvIr18?hI^psy`fKkhDZH5GSw~$B$#`N7tVkk=C>I^9v%k&Aj3YMx(I=Lv6edzs+a1 zYKJ}bQU|RzDLpqJ7x5f_mB{zOt;X>RX4+YRP$v2y13zGVp1;ri+M1!ND zKtOQ@0_t=l?hXW=9S=s-oNL??)pqBR^@-83^;rIGiJ*KUlxUlZ$K)w#i@YA|cD*`( z>$OQ(udQMvYZL?6VvVwZ)Vnx!;XJoscgrrsSUQGf+dT;a)q4<8YaIJ9l%PafaIx{k zFGx4SZ}WH}9Jz+~lfZ@I&9gz2($JZNjQtlN!liGUsX{3{lz19DsTE5;@r+U&(7G4U z$+A*(=*Yo=gIx#r2f$BGZwzcy3bjb!K+nM5gWW42Ht7(XbO_hMLxH}70dS_%o0O~{ z?TUbAm9juqe&FB{2H36xveqyKDvbK8AnOP9C_59smt~_n%d$5u&u-7jZdX*MjMkc zAQSZOZ_{?5f1t0~s#FC|2P0t#G(Mnmyijx~9Et}QwIw)|6F~NwVFg zCVQr)NprJf>N&;<9}me8P#`)o>DE}Sjd5MLYJ>b7iip`Oo1`(414589LJ2>sXW*n9 zn~00YvRLXdF+5D-*Q6MPEC*(mftG1$fS@}K4i;B@;4J~{5S60^Agu?6BH+b+Q%^Q# zv(iRgOdk!$nL3~ge$kM5`td6Hhatmc*K9Xd)#0^>sDdqqKPlqup|f`=OQOKoWCsOEDb+*dA_lAru!D46PKR23gG&rZJh?ZJ_EccaQ0S} zq8Jn&jZt6NS|_6(*1ARF&zsM}?mW$%=46EZY~4{os*Bi~i~!{Vm=?RT6ee*@hN?M)?UU&X(@DppVG_)tYRYWw zG1U<{B;vJ6(CeVnvD%n^)!E3a1*MD?N7bBn204KhN0C$ z18RkYu2zPgM@ie#RD*WXuYwV1TY7~Ig+Ug_F1f6gI;GU$*kUK zK3{%j7m#h3>>mA`8C3n=u>D*;!Q_#MMx2?p^%(3f0?$3gO`3H3O0#9^BZf*^$-86F zd?v^ya55GN#e-yIA$6b7tSzBsi~W!sqh00~dlMo}6g2zsgi)Jj9-%pIOo$^;C&hSh zm{fJrcg15g<9>B9AKON2mlV;^nXw41ZcuxpqKR-s8Y1%yO|`DI22aPr%s4aGbJlaS)* z?e6PjN+1*?Gc_vj1O^rBm>e1opIJs?6&KYQP|Hs>2Bc`53Is@kPSDQr?|>Bndv2FM z3-BkXF8*}{GaQsMN9m&3=BQYxTKgF%6zt(ISr@#%D-U0Ocy{YeZ_7gU>faS+_xw}W zY(cWxf2n(+dd=%QU)wq7o3Gw@z5DHbKiv1Od46+Gs=DW+(w;>dRj_F1N-M5xzr6iw zV&2=3bT@pl;PJjXd2urBsY`k4KI3>t#m8RXqJa0Ecn$jTo8_H#-1j#jc(16K!n(@N zUBY`id4zZPZGCqv#}K1H6tJ}np;gVLaKsSQ zGHD4z_|3N&b<&YL9yDa&^_bp+ZUc*Y3eQbjh*)KffJBs> z2L#H(bJXLfK>o5|3v&SRGf||cWx*SM}r%h+gFiu;hjyj3_YHiQ+8(y{uce!o*Ea3UG7X(x?Cb%b>@W5&$3D>AwZQU!s9?7NyJMy2G#;ixM6 zf}-C`M#?e`28V}1joS;)LoM4h+g&mUcCyTn+QC2WGk#?OsdC zLSf0Pv5T>E;g(e4mLEy!t%p-v56>4KNf$nuDtz*S@cA~btl~yR%UoBwwJX)y^5>0wF&9{GyNecFo}{aK(ZV@Bm&`90EDA`T=~?9PT6A(2=S%y~?f;a` zuYY6O-;?t9d?@`S`d)P2fAn*j%6JkF*}h#DSDjGV~D%3dq3|Cqhyn6dR7icpi=gARERN8%z{2sFclSnDIi9VL5_Q ztf)MS7^5JWjRK=PoNI|dV5)o>qWpS#84;!?6vUQsbJc4vm|yWMl-JA0{4T214GaQMb&s}^j?OBuZteN-JC++nsg)~~&Y+ip8k-PO+;!kx0 zv(UrN@FRfBeI(PAkF=<)6~W~b<>X=rfqBF^ee^sxiGR)7n)n3`7=mpSFFA%lv9S4; z#}UuM2K)&Sg0Uh3s_P;gi%+dyj++$#YY9!NDHl}i)twi2UfuYSt7gGn^y-0^4_rN* za^B|WGP5DqV&4;mlewY6( z{;V(!nFlhPu|4vcX!FUtkhAtew&e23yK?EYc_feQhbhHUmn~1>c;Z>}^X5rY0%K60 zyOa<}d`pl8ojucrfk>C%rp+&!)Y>Mp+yZ$=kw! z&PEQIchdCY{jgn;DW%8I&tqrJ87*SO&?0mQjz&QePR^4*b!1Hr7=G$w(=i)&C+c;m zEYk+?&DNShY;_p)z*tu#-K(<#iJHyzeP^d3Q;#0Qs8?asjr#8qB9u9gWSKU9*YthE zK$E>5bQ!+c+IP+Li~oaXs_-a@jbJ&Dn|luKVH=AvgF7`O=gOg=B*IZBs}62*M&kE) z;*Oi;Ffn+W*j&b_zGBA7h0}^nV`qv0w}ayDpNw}w@MnS=V+o2GPE;_CgZ*k6$+e1S zFeJy0Fyogh(z%&Pb#go*#U`Rk@sXacp5DiMx&!@tj}CMne4-DW7H3+HpnqyDv?Y{+ zi6EE@+0ChYDgk$*BF%{^)9z9%Y6AkCPKq5}WIvlNjK0fXCkX2)h?3}{86GVd?vcb? zw#3FX+W!L5rb?F6HyZppB59iufPIbR(=>PZt;erDo_z4YM{Ngg`KmrCue}<4 zefYKE*~71ef6qI2_|5Y9@(tI6$)X2;b<0z(*3y#lv`{VO#Cu-2_(IyVF6CJ_?`ivy z@9pXzR;M@ir8f3`%n{_1n9 zF)T6V5y=9x<5o%8mDbCxvo&+UxueO|?eis@-&vD%Z~qn9Wp><&KLV`2SR-NBBP1S%#Dke3bsd=FYMnkMLs$j~_qwh!n1`++!F1+-^a9nJ8dzg_^$? zSNMBy1c+gG;RwQgIRf z-(Q*|s5TakY%TYlox5=a;XWL}JS{Ba2wCgF;0TsJ`8li^M*8Km6nh?lPS_np+t@KI zd4}@NQSc%KB;zxpDW9hp(Q^4WC?HW*eu;t$6cBlqFH%5Sh5RxFM2+QdQ1A)`-$Vd& zD~Z`^jlV@PMt#kQWr*)({F?HuB)+VJ-9&*~H40qn*s>l(*s^nDSQSqr4A(Wy-r2l=u0|&(9{3zO8eoQ@*V?i?;syl(%{n_dB(F zT*9ALcft~0T~FaIP+phtK^digunCkG)Yiu1$Bzp{3fn68ScN~gS`Z(~mViKSRh6a# zk-Moh`INAXO{|}j<0z~vV$Qh1$C1QV2`!*(Gno7>BurH-Um2NVPt($Xjs)gxsAX$Y zp0%?l<~{zT-LGmD*`px-fsyb_-$PN-DqtVaFB{W%bDr#x{F)lY0a(gidbRoZ1$smK zDd)+bIzoFe=UE}+x)NR;M9-Txy{JmBrsqwsya?$P@B7j!!vd|>#&M8dn=l@l0QSJz zo=38mc*f5R|3JnGY49`jNAHDBzpj~76Gn5PCW*#j*vrr=rI3WhCuAJ*%#s!h4QX+L za&jpXqi>9=eI5N(&98#G@Lr_^Mww{db*WG(3Q)5F*s5{nhEA7Gty;bobMwDOEAl(2 z0xPnxWYJ_R=veSoUwPs33u)iFlyBW!_q-1>*2XVxd8^2~mG-u!ylvz&tGwl_PWxI? zzLvSoZ*9M}{T=h4x&GLd?&wQ(^v!o1y5T!~t7^@6o9Bv?r7gFLDt={DurB3Y2VtzB z15(^wWl6|m1s!+dYtXZ=R}od{0#)b~b_>G$f{6J0_4Qp=;RCA$@nzed45Mtr5Z>sl z51ntwoPo=1iBs5S@&+u_yc-9$EK^3MB=2xl=EMZfN=yq=1RJ*^rG?N5U^(?&ZGhq9!efgL&QqzDyjj?=(&9mMilO?eQdoUolc7hauw=AT>~T%q z$~ErDv&hc1*y+H}(s)U5oZ)WU-LHBsdeU|=WfyPS>+aF%BPc-Y1C~g{)Ca2}oA_#} zlIc_x=I+Z{tp=C~gBg#ZJTqG%HG_g-Dw^WK)EyCoxA>FS^N zV|NKDdfq#6vW2}^S;Kv=c8Bn%{Ep=`#K0Ra;R0`89cx5$;`r-_0Y>h~(2=}GFbBGl z^W3L|GY1?$!KAd63-b;S;op>xS?jZ!k7W;=hWTMW%dlq{a3s_BFcR2f$u>WVgP`QQ zf*;UEK0X+3ltL|nqhBn`p|ZeIGN2gFEbR&gn|H;k`tg(^X?%2y`MR`hrC?9*{+@xS z4)p{&`};O3F5Rz1?U=gym{$vXi=;2bbvzu!)gdysjIKP1$I4RkqNU@|CGEf(!5Py4)Q%LVh#amvB#yRh%)u5w~wyDsladpD)Ln|}1*+q-_aE8TuD z)qXH}_~^X%@ud54R8ZZRZ0eXZr<*!bO&#-1+tN)tQ%yUQmAjG^k0gD&Z>?H?-8{c) z%cmBhNImtpa^D(+l@|D~v;H!IDXudgfkW1R)1%7Qf8XkA0tyOZ(-+SG(ef9FNa{2 zg6Wa~uULj7v0y@Nj5T1EnSAvpdVM-{PAY@t_n?}8L6Co_gHP45s}4A@(~9eD@x;@a zjz05@erQJ<9Ob@dK(G^gm)l{iFcj2;kzRBA@3zHa`YW*8?q!4yUE|c4^C^1#hh6 z;_5{k#q8YbdX@)wuCs8-g|wv#-qNsSH(M%~+&)Xi(xx)YjwL^DS-)g;SUQ%!ROMwVtZM*1(}_fn&FpIdlv3TxpdaTmF_-GdFJ`S|&HI zhmF{i)u*CRQQn^83kS=fXvD=?DaE*Nnn!t))<`AUP?L`4I(Z%DWa@n<*+6>5;HVfh z+{nyL%$&*UnMG~S<4PNLJYBaqc1(;hMu9_%R2074FzgGyVDmtw~;D#k+O8T@1>IK`&TfMN~|CCE>%svcMG;3~xjdi#1096b=|KYHlU!6O4bxZJhk z_EYhJ&L>v_Ex!S!+hYCC(njY2%#vt%7R>^QBvnoyk>(Xn*89Iw8!~-Kdky^pK!Mpf3TiY-S^S9J$Npbfdo+^(o) z=Pc;NPi@Lxd(*ypB|@o>Yz*CqEZf6*mAQKzJg7tsI_d?ba@o~9cCeUar||Hk{2l-m z4@p&O0^QyWt(YcPR_0XAimA%VeT&9S3u1=*1TMGIw<@nyrki)Cns?7Pcc(l(Nqf)A z$uk3<4P4b^zr2=`A!RC=%N*s@b%@O5n$@wA=~Ejk@S>iwrt{V@^-8*)RixvC=r3K1 zkpCSzxoq-NNVqpL{(z7{GM}o>J1#oX_L`Kv=0@$->*J}~oi`pnc+-Apxix#T4JI{M$4{BIgjJVX8#s*`pm&f!RK4z_&SSL4qvk2zN{Xav6c~TnqlI66iw41 ztuStV5le<{#XK&LAYI!QH0Yu581AYENch#rvtm=z;@PV~abBRTqH(d1#<+WF$m!q>!%$K)ac+^1Unv{LbY~xLP3tJ?8%TBNn(`CD602N}D z@aG6)22PQyJbR!u$8mDQAwL3Wb?uZ9puW@S4hNGZWD-a+GDoh%PCYjPlR}WrzR{cZ zD827`c;Y`&{~lPeUGuj7XSDFXj{@vGpt~dq(_2~fm1izLGyC9t*}4mR7F@+E(iTk? z$5Eb+jP+jZO}p2n-0SA{T;FrUy?wz`mh`NF_4SJ5vLjuzK2@~-N49sYf8e=U^a#v& zMRi|%q93Es%~nTw?bt$c&7OCkeK(X`y??&sK(c=z=^kJQ7mo6G;v~w=b(%U`x%XOY zcQ*>}J1TeA3Gdfg5YN8>NTqs7_-basY=Ur6IQMYo((6TGB^!wsUld02NXD71^)j7K zK+kiZ5krE_AZ_dEO*?joQLoHQDUTqg6cABoLy!VP#}zM?9Fy6n zT5$VcEiywz&Qb6U3SOb$n+UWsQi`3r!gjk2WmqeJO)$(MMid@e>M`}8l;UB#Iy3sI zj7F$y1UV2%!p3W;1=v`0+Z{(T8+k*@z2SPr4fnPMk1y$|zvWvq+w^-qH+-8GRyV%> z!fP+gP0X);@X}smdpD+v8t0p~-zZ|oM;R?>PPv=s8b4~;dHuG&Kf7`{ zWIBthktAH~Kxr7$it$qHkS>`KFH5QjM#iF8D^Nn?x(V2!>!fjoAIrJqMhh)d1g6jU zRQ-y*u@dMuO@Al)0O4%sp8rt#=sWzk2d+GI`KfeSW2&rij-Pw*W?6f(^wA3r1mwqO zxBTez+Fa$lr#)$J|J%<5u52&Q&g}h0W2eJBWN7!Om*Q+rW`M8U_odhg+bPd+NNp!^uRVS;cq+sW+0LMH)$rp4 z@zk$ryho|DYuOh)6n8it2#*ETdt)m3H*^Ht=D@B@MB=auGUE_)Lny_RI;7SJ^%9?P zQQT52U^K2C;krmoyi5T}sX4rXS+(JKAe#fc=D7Vr+Jy|YEfB}uKgE|_UmzCMn^S!c z9t~8tS1H0!^o+_+h!=yOut&XY<(j|^8ts}v9<3!S_Y_Qo$hFXmw9Vh1|tP+I0dM{~;8JlAmD{I=(Zp7{-(H{h|V zT9d5XJYTitosG%T9m|e#G^D%@bd;luzg1p&C2~138@PV>dQY-`+kE-zXm=a;ep_w#PT>RRhOUQ&4;~f~|8R9>cZcv{hXwIvr)PN_ZP32Zht<_9%stKP z&4A#bLth^l$$tXK9elPz);zZIZ6wGJ>f6sL_80|5#gJdA(0`@Gy%hX63K;ZX8?g+u zSzbiyR55c8XLaM5tQyUG2Jme&xBRzM{znwtq2LcG_>~bGHDZ5<*i=bYWqQY1vti@{ zJ+!V@B8?^|H?<_kDJ}miYKfdG%oBtwIf+U6FX*Qg6bkM-nQXhv6e{1M7+G25|4zYY z6#Q=rXo;wOU`-OCWi&|jPOqb%6kI`n;@?GZp8M2fw%C{4IN-}K7ID_X&rCf0&jMoj zdJ^+fTMJ(L+PSZNW-?hsN-xC~V2cQ^wF%cEp)#1Z!3*`6qSdQ|yi>eka6w$omENbV9Yt?McFV0e%;4Ek53N1(Y+a+a- zaB&}@awRp3HWsyWUX)`|)t^q$CDCNrjCO157MfZY);2HrH!T*_TAFSbRxDcZMg`?n zi#Cecxw;1y9TantW8OtEH&@ll;8BIsx8yb%ix4H2K#AA_K{kpi9#ZIN!;!H)4AB&c=_i~PSRPAnRC;AJ@wjVTU# z;|pgn-MQ4SoIpauHyfz#jO-=fq=FRGqM^9TGB8Sa$)&>=wI_LW+$HBsJPYdcdB3SRNcrPw3GR) zD!zDXI~k1Ar`Ke%ValWt$|QWqBxWg&uAU(>EdAi2f!>3C zo%@ZvLp?o56gBTi&*7uJN8nbj*2?Ya?A;&e-9ujoC9nY1Am5-yEI52U8khe)wYrsp zRTPL6)KSnt0V!DWhZOu6fnrg=4r)^exKYs}oAgM#{1bv@f*;mDCx4fMRth#CP#ka{ z?#KLL*+b;yWb#C-ADJwpSPKOQC^$g@QE$bLFAC#pNU*6fLP@)TOoFEr{xp+aHf+#s zf$G;}cgY*EH1VH{_h1P_6zBQROb_tpUmoH)zW%SclAm$4i)IU7@H6vPh+n+tr=0Vr zT*1${@}F^yKjW(Yn)BWk9BIM#k>LB8xgM0m4PBrk>3nF$20CPM(8n&*=Bkvr>guDf z?|W@ux@JqNX3K)vu4b%Bnb*ud_=D|lY){wkNY(FHFx%4R@|3y!s_k{xYp!&~hE&Cd zMVoo8DajRI+O@=)dDEwE&g{C-o-C@nA=F>9UAMjM`k^bi^T3U!z6Jl5w@zIhFq_xguG$-uO)uo~+q;eSfOvk-UlT?n>1hUY4_9ubp+L z?5%Upr|di5Elk<_ZtJyEYb&!Cy{>kQef8|BCCQ zwexj2Img#8mH2q)(&h*Frlli%8(;i4$M_d`e*32!g^S&0uBstj*_x_sohi7%mH&;k z%fySHauhD^H`{pMf&&Na@V@OVT(sbg)(VOiZ4|R}MczdR#he^u6BotYoYnbx0b*Y) zKJDS`Uf2Tog3ryorQqu1-*9*>T9EK}=nGeSm}l3QzGFSiaX+alIP9~gxT3?QLdwe{ F{J*ip=1Bkm literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/socks.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/__pycache__/socks.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..7a32c7ab13a796f00d558f0584c73cdd6beeae9c GIT binary patch literal 8138 zcmb_hYit`=cD}dFAL4G&L=S_Gy;v%a1e0_~mr>1yR@5e5y#gQvymR#b`kXg>A z<_2nfqV){<;rE=8SZnH_3yX8Lvl|lC##nX zHHUl1`6+uKwqH)=6p8IJ0HpG=noCUrV;KW>o5`gO#!|+Z+b^rIuS#X$)<|iZJT^C; zPhZewVAAOVzI4f!47rqHfjlvx*ySB9Ql$tVTsH(^16Na49^t@CR88@5CYg&FblRIZ`;7lKsq~4k?CMHm!b4eij z>|>0({?uS!UpyY4n21#;$~{}mduZAKvxiL8Y~E1iqodi(0HuCa} zUNsHl4(tPjY-2HXK#!iD2J`4(V5BpbpTQYb-N6JP1TF;z0TxmQlLL&C*JhYKVOJ%e z1FN9hB9E4qkQNAY(RL;^rJ#k=S_T}USI;P_JUgxC@NDE%a6m97Y?A^~SvV>(>HwUG ziQ8XunG<6d`%1}W!cJN@#{)yr;cV^|4EQ~h z-wuXWL<61V3us3;<4d9 zK& zyMugQBa>D0Ge*p129KXUJ$A%CZ26oS!uEKr1Ez#GP8rMRH8Zkl8g|0eh`sQ%MgJJ3 zd1{77)!7k#xRJk*40&0Vc|sx>dGi7?NHwK*x~HzUc@XU2{tnOT#k#!jC&H9BtcnVew;n7Wb> zq42tVAn68`i}EPMGE-tMnZ)zs)bW^`qT|)3==hr{OroL$s^s+1m|%*@Bzj~rX-dhY zbxlIOE}49DCZ*XUp=5HMJ0_DKkyTW~gF}5rw$N9|6nc#mJ*OJI^Ln1nD+9C-KtP{$ z`W?^cO9QH)(9NWX7v?D97goFo6@3pBe@@DgrrSbOxxVeT&}NsxmfJ#0*(#;r)o;^I zXWiBoK~4T(olO)j!TSJPuK!OF7ReMK&#QF_KvfEVRY}S|MM#wdxNd8JBr0B|!BL55SM;u4yARdgycr%!^yuv!ry6J{U zpi;DICYLdi$(Y*|bXA+8T|m?nz)ZU7xiHJVzGO13LC8!db>s!3^kphTjdnvZ-?B*y zafjv^7}e1V_b-!59qH^{6n-nV-w^}Xyvt(CQddcg-RQn8#+aqj0QIXsKh!`hZuKaX z*GYyffXL^o!?g+xZQWnw6b=mxqw7^^FJ!B>=!aG8NcxC@g0kOvI~j4>_yww<=FLCo zWhu?Z{wdcK@?N*G7h4M73gtFq!Xw7qj~MejV$A!9G0`3iZo#MTeQ%LNcUo{2UE^do zF{&vAq#nHsyb*C$6^SBkt(~6|#SbG}(1($_pShiMq{v@!DS-w4d;BbC*r^gB=cCRJ zwJ+>#EbvACd{eE@snPMR`xgWQ1!cdYP?N*io%Z~H%VM-w_k#qoDEyTC%;oHMh1)dB zuOHo@i4KPfNZkk;-$-@ab=CAOG(W^53m)EMkONI>8GRZ;Pfnd(ADu8B)ezgdh=l9R zpbj89ttL~70)RoscKU*9B<-L=!@wj(OVLIw&@QwY3)Fec>s&d;T%mduAt^T73|e=4WPpy$~KTx@i{dnA?7tP}#U z#x_bAlw%>fAKC7O0wN`5fM!D)Ad8_UZMtx?ngY8=1-wC7*ko*(fpMl38$wVFWu`QS zDVqf+BwJ}JrKSW~GiIa!cqm2)(|c;%0vK-k7`8>0b|x>(ngVWYa;oWug?USIo7)pJG2}-w0OMKxM#Vp z`|h?Q6=9#R@lK>=C9-!pvbWsOc)j(dr zf393@6_?u&ZEAJyUg>;tx%0_i4lZ{dE^lmA*Iit0KUi+*_@M5+x_b>kzY->q_InYi zEgr4B&XM})qW}Kd5L9-2MFik3yr*0rEr;bB(Z6Z^dFu^-Y2Wc*NB_O!HyytYmR^0W zRR8*_n~wx59ujS=c={wEN zarU>719#ebfthk!&xg^!YyGJ8Lx1VOSm~u#R$e;0{LKak%b?NInyN zBc1$b4LwJm;Xiw(3F`kG8tOZCnE#iPB8lv%_^>7sDfqP?YJUhn?T%Vt5J{!sullnw2e*ocuLjTOILHN}>=*kR%^8gp;v1BEjK zwP{B*eKT(epeYuA4S%{93g9ie`>m4}cR2DVac3dFO)A=kJ*JoMzz&<48pS>=K7zk0 zQ#}q-II@8$8xwG=IIYc0RRG8XwCAq|5?%)BMF!~`n8I1O zwv)U0X&cnr2^Bu~;1%iQ&+F$}=$^uT1Nn6Arm%26EMk-tbt;pCONi}cJyckzADm9W zJlS-!Y&pFid7`o4D&bZqT~-oc*uD!0lKa@MFL;Zt%ZG~m<-wwNE8P25eCz)6RkRDc z*gvI4RWxvS_A83cUW)4iL<#CHihl+iEw})QdACBv3eV<6j4C$X3JWjz6k$Qi8Qais z|B*C2K;z|YXm}r@5p<-geQiD---d?xN76t(f<}WwSMe1&hU{!RUEx>?=X1u3KG<&y zgbTe}VB4ar$QLC=df&6)FZzof#gCaz4cA_)gEX)o{6Z+Yr!W=tSgD{<#gOMQW^MXG zN(o7(^@F6bZu9{+Nb#(h9v0RIMoh0&nLcfI_1iuDsrkoVv0mN*hbgL|(kytm?cmO_ zVehCh&!a&iyMto&6iowJC_JkH{wio0!{jwJ2m7)&T?*0>vtjJzQ?H*{_Y5-da96)6 zy_(WyR113f3eL+pJqQ%&Q&{Z50uxy}28G#FfbeSNyQ-d?oJ(3;#sUnG(FvSb1-7Oy zH)oyzz zI#rYHPhgq87aZ*VWwI6~;r69xZa3^%^xXAFO8)j6Vo84dm#_ZA8-M>sY2Z8MXxsG{ zfBfP~bkA~h&yDo$=-$O+cS7NJ2mW$?>7}>7U*5BKxqjEX;!;o9-|)_}*PdNEe#_r= zr{h~I9S4>>4lJH5M_R5OEe9g+oV|8-DRV3E*oLv@+Sv51K=+2R|6|=3;f_-0$j!N% z7fL%`z8xMf)s5e6-L)wE5TV-6edRX!gMIH+KP_?@{*SiY3wT?l#XzN=JpOD+Y%8_z zTNd|!;XE_6-gseI94_?@-4cht=zeOYdvv*bbW!*ZaW}j5V#4U?ml&HyV|C2BCJzs0 zmWeT~wGtRso5Us_YKj-qe5Z|%PNoWoliq-3@YZS2v-WEnRdDJs6fxiC%la4&vFjLb zF`B}H`QQlFUVvgf4noId-ubsUK%rnbhzA^0M;dy{4Y7M}ey67-w1E!fE6(Ph)zZ2?LWx@qNC;R?~JpFre^!McX&&i(8iChtQF7!JgxF&hH&{FqG+ur52 zy=w#-YvB=&i@uv%Blul|fA8jeOV53HYK=f;P2{+)($2@R(S?mzsq;x}#MZ>8xKrGc z|7(KZ`;{Sqh>@>I0GWvVw-CQ8G+aLZgOhKatO%~a84iH5uWc>hb$h^L+)||-CVo@t vXKOevRF;BQj-W`P2RhywZwtdA@=wC>LGo#+Yxn^F=|S%i!hiZ42j%|)3m+1+ literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__init__.py new file mode 100644 index 0000000..8a3c5be --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__init__.py @@ -0,0 +1,16 @@ +from __future__ import annotations + +import urllib3.connection + +from ...connectionpool import HTTPConnectionPool, HTTPSConnectionPool +from .connection import EmscriptenHTTPConnection, EmscriptenHTTPSConnection + + +def inject_into_urllib3() -> None: + # override connection classes to use emscripten specific classes + # n.b. mypy complains about the overriding of classes below + # if it isn't ignored + HTTPConnectionPool.ConnectionCls = EmscriptenHTTPConnection + HTTPSConnectionPool.ConnectionCls = EmscriptenHTTPSConnection + urllib3.connection.HTTPConnection = EmscriptenHTTPConnection # type: ignore[misc,assignment] + urllib3.connection.HTTPSConnection = EmscriptenHTTPSConnection # type: ignore[misc,assignment] diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..130a368b4e623e2fa9b020fde67a438713530f89 GIT binary patch literal 868 zcmaJ-l9!Cx-qH z`3G3|TVO#7LV8NY&;eybN~ccTxv`UU;D*!PcmD3q-@9-1dX0dM_r9NBYlPfjQW)fD zblw3!CO+|LL}Kbuim?`HUd6BYdZfoyuNoVk0eICnA~Uu;E4Dowa?3Zbbgwqj9D9b% z9I7_@oF}p`!-QwOSp`8&HQt<^opuw>g8>#!lO$42#NMxiGkX91lan|bh%l7_UuUY; zdS!(_zy%7!pM%+S{sn?Dkp)iV;%X1lxi#{9xhc7_$X>~38Zjlxth6hq7LPIg>yA=Rq+@d u&J+!Bch-wI@rO}xELxD_F=o5q{#GcZ*W~F9Y5gH5zsb8>!=zoB6aN8v#Le#j literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/connection.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/connection.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..9b9fdd768279091c87cd1395b0980d257227a253 GIT binary patch literal 10207 zcmb_CTWlQHb$51W-%sv~yIekoPjM-U)Wa4N*DpP7Su$-)R2{8qtX4Ziap`?fcZL?1 zS-DK2Hd0~3a?n6>;v#ZUz&2#G4p5-}Eb4q1Xn|5*r5aD=ia^>A1Nm4-3SuxnJ?GA2 zR}>{AMK7f@=bU@*xsN&b+;h(CzXk$c0_F11zs>9%Ammp_n8l$Z+#Sk63v!HzMC3}O z%w;(aaa+ljwXvr?Ylo-3#Frge2dm=&cV?Y{J49#6Rd#3H40n}0WpCD7_GNu#f7Z`< z?oyx}%mx|mDTT`6Y?$HRQb#$GjWFC-ik4&9SUH}JGumHDlsmJXfCt22DOpZsQ{}E~ zS2>+cm%Fpwj2|lXlzX$i3=f0czHDDv$O;^h>~nj}MYf*Q4Rh^)xejCp%7fWKj@ZaE zM2ws#V)U9#ZNb)>XN>f$kh?Ey= zU*XK4!ke2u{^I`Jo)`8V&)Bsf_S;*nRHOoS)O;_}>S7HTGsV+daK1{F+^JelF3d`0 z2|D|yi)E?0pzNo#N^z7ud09dc=4il+=>r^nVeg^+)43O3oId!%)X|Jh3+MLjKd}4Q z;pyD;!RPnCaBNx&=q(Kry4sJ?(pR8aB*R1H5$Vi=BgPa)B1-6{%u~gPHWSn9nN8ygB!mX?}iQqFSU?ZB{|2h`H3Z-HMvL zqb+6u-;i0{I>Oy~gPj+NWI2&!ZO1_0L@ouDSzfeB4$+QpSmXh7Fw6;SRjJ%U=z1ll0qaJ-hlpd6TTF^Q z@E`wr-*tL``|v+;v)FgumG$VY#4Y!?7PpGRc}LbOj*I>0`K%9Hh!bL59AJNg@ACKe zS<9kbaS^m>JJyEPEuV{Wzn#nJelpLOorQ!8$Hq!l9w1nA7t`=UE zlw6gaQhCWgRjo)uU6?6V^NQwDbPd<+pvf9PTa^{f4ufhuj-`1{m7up=T$0uj%EEj} zIswhL2skScfs(YKTwS0ADVG;TD#`L%dZX#IHEy5GnimeAS?8EXGq4tEvj%3BpH<}w z%tRc}_*2ztN%Ixu+-njo&J-naYRQK@vwer&zOBJhsaQnUxK=>wS{h5MP%Apn}UC>JZTlCKmb&B64E?VRS+ZMWvi6-rfE66tpA zVr`(lscd`M&Q3sW#-s7FRGMi?fA~v~ae0DS)(%f7<@t&E;`~-6PfttA)+M=0m&8Zu zM5%acV!o!#Rx1+=v;@@72~Z=20$Z}oG_s7_Xnek=xpTQH`0UM~x-%acf}92QUAlbYtN0x6l6bAaML@q8lDQwKL7AR1Z9YO(#io z0peA=g$w)*cS=nSAYbi;#|?MddZwZJm+s^p7>pDwwLl6AQ$p07%cMp=J3W26(~J zb|A3aGcAf1pFRQLLypZ&#^!=PzRP$AOTq&OH(I;|o!IP`iR$*Vai`((b`@q9Dz8eS z7MiCL7&j5^1>C`k78IpIRg^3`AysCoXtRt4xsp^lt;||`ira_>jZOXt_*|F4StngySWOE)Ok8q=jS@iy4LfWf$k%( zbQ1Dsut(>-=X@YB+G=BBb#L8gnmLZVk>YhDWSJxnsXOJc0&?_H_n0$iH(ao)nAxKB zT<%cNrD0{`el<7`gGA{vTMZGKKId1^oUu~(&-I#k>uJrv|9yxp&iP;WpXC(6tT$u~ zn)Dwo<1AUUA17zIjBDz^8aJ_Ie{5o6jeCruV-GrP2OFh1%M#ctQ8$45u_8iu!2^yc zST{vJTU2J*5pErAnt*!NL385~JyjKJnxm+IiPI0Ze)4rg9LKh}mlR(XMV-=IWw^WZ zrzILe7OF@lpqr0F$aoIhz_lyZ=#xnAMX(P6&W|1dpt(%Xn0r;@Ueh>9#;e3M(Jf0u zj{y52r`!-T4Xxw=94N3ay(EdI(y#i0Z#{YO$t#05e7&pj)a4UzpSbk=)#%mf_m97K z{OX|(&U_sEr_|3=ANy7!kAEUxkLx%!+^8?{DcfJ8nh#u5#~t-t#mf zV;^%X{_Veq@jN@$?eSLmqO;?xxRdFmtq;UjazKY-N?{wWa8@NBhCy}j}pc5PfSzteJ*30g7B~d zyi18z@+HeH)78&wn175l9l9o?$zbZlT2Ndj-3_4qUh#oDVET7ULl3-L+FI370*ZnA z#TP<_Tk#Fwif&T}M&2KPZyav-%TsSp-HeT0kB!}ojbD$AtLeVGET>nG8{ zMr3HkKXm_{i07QW2?3Dx*9!B-j4K3!Zvy)a{$GxVBI5-2spd&c%5E3gj6f#X0Bpjk5oT@6b!pW21 z(;K5n;>nW&4sr4%NN;g-N;Sv)|C1*z(T2#PBn#yQS%Ikt2l6FZY7L&@^nG5x#U31x zd9h0a58P&}&0pbG2iaDGSqaD9s$ZC_5x9{K5@IzN*4)r6LqUq^5VNrkB zYJUBI)u1NG3xxvQH!};R^-C%$?ENp+T5o0=b%ILD0iLZym&vdEMK*1rJn zQaA>&2JVX}fdPS}j3k`ZmDJJ$33EuWofLHz(>B5kt(KV%>(Wa38fY(Uqt0jUa0%Oi zSk!cVca2?d&GEp-yPeorF_$JDxbGWxxZL&zK&|5J4S)~LyoQMG2J}N47M9UL!~_KB z-sy4d2x7wsSS^dYMv>f%UOSOA#ut{ZI43)b2Qq?v25 z)@P(Ao`=L1Y@D7jfUJR;Fwi|0HroP@C;|W@*M?6`fy2Yx4%P~N56Uof{FgfP`~v0@ z+sCCd*laI?aRmD;jCm-Ghi-~q+cug$GCI=cEU;}Ricw%CUzTz?NMGj4RdJz&xIdRW zvyd<8HPnj|(S6iHxm;U%G?$|o)zWPU&>qllBX|nI9t7wE(c=hC0MOiqfvVA0kcW{5 z%_G2IiM?$WB++gp5unp6-{uJU3!-KwKXG2qJhgmyB{I_BpHjPbH~8JFfpmjUuX+PN zIH)oZiu_P;3rmn@dh7PBSQ^-Xf@fheCSfF!S|@cnH4^M>AMX+vl<$0 z@S{yHi6@$_l%pT8fgS4hN7Yo1y6Z6rR@KcDU&opoO6tNiT%rsG2GeNw;JDrFwzCQ55|r+K=nVeG=5Tc1u>;mb45o!VniBp=`(fQpN83c^h#cvz>xWbmRhA+EM)N;mAvL*@@9%9Nprs{)p88;BQ_7Y=d)ERu5}oud^h+RMz+@{%OyQ+vZ!c`fE26@ zE;*Ip-Dy#*hI_SGUMOR77HbS|-1;_3-cCF3BGE$J2NPPUDZc%R~W&UM_al$(s&H`Ero4vDbM> z#yab+x*I|vBi94p1u@NwS2-*7I8Y$XpkhFwkH|_r0Tf6xr~pt-i-NpQDaJsCpP?8!@G`@Cj2Itgv)Bz8zK|nBu20F5N*Afc3!iKCM9QbSADj&*8MvlL6$6iab5TUCY+DS2g9^Gb{J5UYTjO4sWd(@mBGPp(VY z{!vOz*;M{$Mbz>QH|AAi2`Z%b~d|6rXpF=zOKLC8QOz!R? zp5R3nq*qjbSnY_bu{0!K)I=Y`NT-?_Zgvn)>Mrqkyyyn>LZ-*JnuKKc8v!#F-aV>k z#?vGCOsak3`0Tcx1CJmL5{>%7T}TV6`AiC*CwKqdk@sJI@8z4rlh=nQKXEsPce4@F zBcG?A`)J2MOnx|dbMq6|H$U;otBuXi>BAVqnpqwO8 zy1{3jgxWUsVQ-x25HmR~^|6ePjIvv=K+lk~%pO|phrI#J{$ZP6g8(yVOPc9=ysW5%s8_#*wJJ?n3-l6+hvBK|D*>So+-1yz0qpg>fV}mt9xr=8!cs{ z$+iZJQT&WXXAu+;;M-+kgT6y^NU{Me1z2ZE^j%|t1YR4o4*?!VdJzEpP(eS#1*ufZ zINtmL##EW(u(`()D;VjaWD7+0^Vote12RHTw_~NMcj7AF%-v?P(4oHbfFaa~QD^ zl(z}7QPMlw%pf*~*k;7Gki-^dSam%ARHbu^=ulgjg7t z*MV3B7Z62EkIWFm$n1BWfawt_>XSw&hN4<$4sJ{Q$$*?g4;B+}O0`feQA{Li$$M*M zt2&dx;Cf~Ok~9-Flhj}e#SL^9HB?>A>_LmAHLGi zFp`cLNh!?gA5Egb&_AoN4=hKJOd#k)kOZIw*w3K$KD&SKp@UP;u$^NYq{sE_kiLP9 znL&6Hv3ukHHTUCsBH~H<4%C9TN#vgZfNujF_g`e-SH$z5B=B1&;U>Q%qyIz3Zj=4j z$^I|N2#{Zrowv!Kd`Z%`$*~4G2F%;!nN_>zroHoXd*^Nb(C?i4Y+U?ng7EGX{~eAC ztO(z_OAu);+6eE}n|`t5xzBcdcBZl8r4>HC(gVqam%e!9`Oi+R968!}WO{|~Ug_O_ NgP(3X2(RCi{|jMH-rHPGf;PfAYj0v zWhDl@QV}duOK>AEsVXO?BBqwkDlwC6C3KwKwX?2Tj0P%iQxz_me(I=ncxW6NhVXV4?-`rzD3ho6? z*7ud)PDK9r8~2hI|wGL-`X0Lj^o1Ib|E-9O1%=qM;(B&l8>D;)xwYJDA%QE}1AD zD&@I6PIM2IiJqZy(K}Qj`i3gS{GlonCpo0*_jtYa;|GoIq`zW8D)w+X)NqM~w~LJU zA;H8Q=fvXIIdO+n_nui#GgQw)OAuNr)u%!mSZEnS%QHe7#dfjcb<0o_i>*X#m1G`& z&ZsT@O_kHaQdT2n&3m9cnW0v(L##z9etZRd+wiT!cPGB}__mAYp$@S@>J%FfAU$Z% z{vON8adI_$Z7E*~e15~H_~6@_@;TsZHGD%I5fdx5Q*1&FU1D?a39(CTfqNI+yWwty z`$_Q$(U0#QahKSJ?_RWMC%#{pG5dE1;}(u{4opo>MrBnPjmmDn&Y-&Te5;nifWa7o;F!JDkpAAz4wwGws4mbPC~-7F7_V z*~Ot0bxaZ_f^fWW5^hu`whP13NN`G#grFLo2#qM6)4`A`gcK?x7!F6LC9%^vkZM>o z5}pyJqw;yQYLu#LktIQ%ibSZ@lQU5CQDH_4jM zB6`li=RGxG?U(&}{P^EB~ z27q-+&tNl`|p!Wgh*H>sE5X!Jbw5~Lx5z8sDY2gBQmBZs>XABylcPj!#wj3uibGOdI~_tBN5MnG!IASchA*Ce?gYr%ud{W# z5b8uJFH5RQ?V-j@kD*{^vH(gM;9ZUx6 ze7?QO#FvcyMuLh2raTskpmmHVQMWWqY>lCx9t(|(f#DbjNf|w3{DuyLT9|mCP&9%f zLuv>F3{B811|LnS;1G12O_X8E9+dU8Ba#!eQ{^a9E6Hx45Ogx#)J~xXO%lEqWV4X0 z00cuIMcn|+*_l@V*C-oHvsG@eCZcP7NA{(Fj;ca*G^1J}Iy^3o zs7j|WI3~@oR1t8gD2ywCHYci@2%ZNYsKQ8C3KE5gduApjDn-vq<+F^P&W}j8`gzS2 zj6|X;n`cTN{I=(VGUgau*3nQ{Qv4>(Gx*Z;y@8$+y*^rWRyCXAxi)KHiu-UJ< zPARx2N3 zJAyAu5%r`04fE0eBI|#W^*>mt6HZZjOh~ z$jzxXBh{j1j(f8J@!U9;rfg%Z`#d+pz03Fct#TQX$mOs!`vhbS=&4ziDad2Z5eU%C z2n76A&7w%*QMroJrZeOP0wdv|q67j8QH*5frB9D{sS}f3lcC8DOd1G=j#(ut&x(8H zu5f6$YjQ>%i$=PpD)g#BiEqF*^(_Z>@-@`gE(a;tlwSYHoRO} z?SkbEccM(d$CD_nA>X>gvuKYw%9e|7R9&z7(9yh!nnRQ}H3UfkV6q22K zHCvX+Xl&g!qKQDCmS;xmSap$aS#g62m$|5nqJ$yVto58&}(~VRc$tHXK~Xu0-eVk6rNGFQ_yE z3)?pGDB8&twf~mlKIUM_^+su1I6TQl{H7bxY5tz!F`<2dl&X;AT(jIrr8JS%4C`G^ zFP1g8jY7$K9=}augx9%*#i6I5@XuYbComYAkfKwnUad?6EVq-zI>Bn|A}?8k%&2egK+T@xdzNhHGmIWv$cmnl;WuA{y;WivQflj0bc#Hb zShMI7P54?wH{_RP$ST?3vb=6dDam%x#iX0{b@z}1aWfZA>XXXM`bZH2dNiG zifzPU$9DcG_`|Duj1;12&OD10h6Id2pd(MJWgK6%Q z7+tC`aax=)C@Eq36(m*2f-EiMDw`lZeTmBE1IkU5*|fq*DMsLmE`?I#O-g%Z;wy~HIP?#s?aXRbz3 z6Ii1v;9!lyH`@#tO_9N5oO~QsW;60q12(%OvmvSADat^S7ftaMU4C`()fGq0XAr0! zNgqd`bem2g^|m(IbPk#=%xsVzHbbrPvDVy2Yre7gjkvFN#ZkMxK_nR&acV#&rl5T0 zm??8?%BDs&YdX{PLutBUlhKm$k>Zn@&MYn^mBA-oBVGC{KZWr8wBK-z7a6YfSKVQ_ zY0{6=dYffJydfrxFMt^m2`O=*lET2uB81eNd$)3GT0{)W$B^on-z&3WIRuYPh)u@y zWjw^Rsve4X2A1Z6#86M``WRaj^r>A<38+B7Nf!bF+zL%3;gUYhDRQ=8+aS+Vx(l$N zFcHgPkXL=RiK^;_qi>uxJ~j35ok`R-EF4{RS0$3(%36dzN15inGndFOzUI2(TFY;V z<+t4S-nHK=Uh5u+bq}mOH5hMwVKx5`619y>maFb{cfsQE#nW$|+1SD53)@)wirxf}f6u|UP*0ax7)3Ha?G%bhJ?KK&pZ=xoq z;80D)pQ9#u0688}l_E*!w^wC^E>Xr8$fCKQ+9klv(Hg}j;V?+|C<&#Msp+W&2F<1D zh}>+s?m*TKHti5OT7G&npzvjQ!Am7isQyp>ufpWSRGpLQJ$0BP#)1%8!OkG(RX5|EHmDe6#%cX=+0Z_EaNTP z<53^_mTks&W`}Sb1gzOmoefbsZ_VIM`<(S3ao>Zue>{hZ4$vVbtdWCs{w!m(9O{Bu z-DN}~Z4Ta6pETlCh;QA@Z4>-P>*t{Z=Ik|26|xOdlDd^;9uaDrMLMIF@u#ygQCu=; z-aco~)l$&dR*4yOkpVv3r-WN3>yfjor z*i_~^L-Ls5J{i? z^~JG`%30tA|}+Pz|zO0HF^6o^&@b zx@2{lV_d<$0FfF{RF$G%28~`ur3#5)rqUZ)y}qd+s&8K#DfGLP>mC%aq@wwqSJw;c z68VP`WmPxa*WHQo>W6kqk#~c$c)S1(-1(OeE*@O&j=QQKxV@K8EuLC)SH;{_%Y!!p z*8{hL?^mz74=0f7*~Mqq+zl~z!}t5{oV=^99X=a7e0Jr@{&?fSs(bK3e&IFe73VeI z72i$E4}9lZw;<>9E^1wTdgKI_L!)rDYFx5RO!Rz52HK_NhA;6c zAUU01c*D80FYc&XKD#`-;%KA&i03<=<%*c2;Z0AL&sVpv!Vgr5W$6QC? z1sofW2336m(E6ofP>HEdNweSV8N~$;P4P+N|KM#hW%tN7ip`?bZrLVAhrqG$Un5 zwT9t0X%$c7WP}0(?=Xv29X-KOpiL`C<7UU`R7;Y#08)08fHj@pyny*g5RJ$$W*{Gr z0i`H+mPxPcFY~I)h!mkkWNcrO9hm2nAhqRn_q-{iE*kDEGoF(F>4@~YIB(9#ol9pc zOy@FO<2hOny#RC|11b>5GV_?SQ>(v`9-3#avP~Ifr+SD@nXT`bW}!om*^=PoBt$wp z+2~52-E7gcNdv?7k>4DH<1PN%+_!May`)VJTMz zW^aB(isUFUY{}BMg>6!epn3R~iLs3-kSg57(f-ruE<;J4M4ga3M$62)$?fDeQm00k`I6-Jx?Y z^hO~vCO5*=55UO(@BKg_D=1bW7X95N?icwG+Hd)Ed2C^gkSR(RnF?H>a~@ii1oiTw z5#w0JPUj3b3BsYvtCZt4vM!PJEwUJxMVQCez9tx*$j_$m?4JLdartYMsZydZwfNX8;SU7sQZ?SLH-I!=<)7>As>-FB*^k%Z&v9@OQ(<2kAATzzpas+44 zau9y4Brq`8-`jl}hk=1}XZoM*?GN;vIoiuKGR^!#|8ts8KYP_-atd(jC)k6yR-oC= zu@hYRbt=n_(?a4ftu#eZotXnk!eG@Rx-mXrn$3 ztny{f1@~_pd3ie@mT*WrdS!I2q&-&Be(THelKl&=_3}zmAlAw|V&xrc<-20#yYB3a zmmdN|>RoT~|6u-|`L&h}QW8*k}fuzcufWTUY~Fp&<8>B4U&z%PIR z_;Cben{k>@S;p8(9OW*XE}KWpA*lOb!C~Q-F>~fkB*Ijp6f+lig@1##qUP_K-YBwg z^A?sO=O$y`I%iSSaJkixM`#%_O_mY)x6Rm2@#87coK7H`*cP}k*>vXi58=!^Nx(%xt5t6x#t|I+<6(fN#Dvc<2iGSR%6>Y@65=b15_9% z;4jO}<%uShIGLF=l=7I8>Wm!eFO_7pgy%By*Qe7MuADvL$7ylOG8yGGXGOtl)R${Z zJ@3L+xovx%@s90bD(&f*nRCp!=4_(v?UZ6+jLw!m<)Us1C@{*x5z-dw&e;uE2T&Da z2v|weo`EplG@KyX=Ww`m+hL3efFC2z9-{`9=er2cV<3$?gIZrO(xkt+sBX;VdC#0D z7i=)+9H%3qEQ4b(w?TV@KJ#Anppk6+kl{*y=e((uKDFBj$HARXbW-c_buo(cq~h}C zoVjOh?vX_aZdMZiUJ|Ie?J+1mkf!)iqkKla7yiGY-f^Q{qIb^A;H<3iSJNqc1~24F zH-by2Bj$PYylI;A=l4OCuqSV)(I!ot(QFeEE>MUJUXk~sTI|{KxsPZch{U$!38WcI z9*&=B6N39X!3kxyC3&(=H^11?Bi+`@yj_^QnWBR?w7zII+j+uIg1XvKulcumF8~SI$K3Ll zC?{<;<*&ffY`EJL8l929Lm|r);vm(QT~)G-$k=mtLM*oLjIY>RR7#x@-Bfoj)!8o0^~1 z#CE*6;Jm+U-;Zj4SbJ~R2fL15ZCDbQ&ru!Fs8$O*e%iQTU$3lQtL%zZcCA%D8LNEq z&hdEVffYyDdRfH{&vnmQnLk$MUuoMPFZ<$xC#8M0#md`Oc7E~h*?9Tk1@8lglMaH{ z9A$J2)KtJmx50?zmO3>e#tnQFWvFdh?C8>uopB{oqUQeChrAAMO0% z&UnS4wThltMbCndU>onEcg;~BbJVZ9EAH2HCMw$!4ILlb0V{2qZ65DKvm?*>u$aqp zQLUGKi@s&g%~x)B+$~*obSGS8%LOr4<=gWgxZ2kXYZLiTC(3HGAv$m6@~)Vt`ujB> zc)Fm#SF`{(EB7y)dI0sZ=6cOq`Oa85)XI*9Q;03AUn^~mmA2lhS@R!^`48R=-m8fF zpNp5CUO4ffvi8RQ>-%qx#VflOo?9ssF-B#P@2#r28e z%4=t?oJkayUF*Bjmnar)*2IdRK@XgI;6o2)J?7Ymt zE{T4#{5~qt`~4$wZ5@2AjBatz&G3MJV;i?~=*BiK=iEi=R_ZaK6v-a1l(xrR9Ur(( zykEbz`$TN_i51I<&*GWo-N{bafIoR1D0}^w9iklp_Bdvi_W`tU+?>d`Y?F ze~b8b8WvjjFL4hXzN@CClW|AQC!9I2bKPBZ^~kkTS5Do`i@V!CF(c@K5wup^94l_V zWsAGJKCvPKCl(%`ekxKEbJyr6AU7|>+#MTvR;%qZ#`X8$+s~ZwY_7_0QjZs40R>A_ zB#Q(^Ac3xL1#s^_6sEfd@;zkQo5iBZNx3gIDOW7}SXXAtwypcg>#n%$%2bprgd4(5 z7jVOHfQ@16My^et_!`?5c}F^aoM5jklLj>hIMr@M8oATg!7TER5vfB_B&@Yks7lf4 zjO+HvHwCyaR)%UwX6HW7vk=r?8?JYPj;B0f>;OxG0 z`jd(Mf}!H$VFL78AvNms#DP5+N{VSZa>ZFKq&yV66KBr#8ONuAbKU)YfbDeM+76YU z9*NKasvPn2?9Oy1^>*llPF`3HB*`rQNA&m%5wD36@7J!nL>A1XbVsP;J^z*Rf3$FcwbGA_s zp2szOdSF81$QGOATO)+&i;Z)3CsMJ?^z0!@^6?f<(Q}NnbM}y+qpEmiBoI=IHz2sT zPw%(zmSiilpa}N9Mv7br;f>Y=o>z1poBiiPY73yB(ld;M*K9xUK7#dwdr64 zPfKuR054~zPyu_xl{$?`KKVlLNIYRrp}%;GNcuY(ywM8p7h3ekGs$-XonS>AmJfHP z-wAXw0mL4qo@+arT*e+nk?J2VJ0#_Jj2bduX?-Dc_v6OU<7o8^>$M%hjJ(+4U_ zA$7|Dl7B*3$r>VtC-nak_iI-}qM>EQAtVa-gW-KGt3H3iU9?hqDCR!2aD3g>xaw+V z0lhJIF9Lk^tG-4Sa4zOPM=2`euBw~Xn5zk)8ysII@gH-%N8%Tb|JqS=-{HILUUV;= z`_NInQO&uN_%Mkz!;q$j>A`Ovvyk-3%MiumDQ(e6j3czvWJ!k^tUu3h7rx3a+~njl zE?;xGP+qw=efb)wPc9tTl!@V@#8f*XExD%^G>~LJ*_E*zWy($!c(!hgKCnqzWQ3-_ zXjO6AXSfiW1OEk5oD?{$W?D(I%s8oiS;lC=QSK|9nJ9ZMJl9B@#uXU?UkyssWfcoA z;qnHK$8&EyVIe`(usxkhQkWU^tJ!d;zXm;xFSI(p5v%SrTt?e+A+V@7g~1x>)0dWv za*gl2B?mwGQN|PLyoPK1NyC-?rdqN$9cH+UxOr=&@)0FIWu#4ifx;(w3K!F!Ho}pg z;I%A+X9ieCZrjq>WCN!jFcLL#@)*uFY`HL0(atc-(hU66Hh#p&nf{`5hcT|ejdPck zmn^H-$cJ=~Eld5qQj6TY?Hjgfeww>zeu zfZa55{0X`9(U;@{z7ts95X`Uu7v;E02`ucz4kRqyf}yTsiPLuA%3F6h+@E~kr{`4I z13P()lG@cMA$2(DWKRzz9Uc5*DwXsOeLF)FN?&qF6ye1O$s5fERPW-L%#vtUyd;{+ zfL%2+TDa}mhvsG~uA$ie3dKx-+m#!z@Z7`HWIeQAP_$N1A1kO|D`<`tG{*~C7iiu+)~lYjZe#TSWcG z*7W~@mpI~{@E@27XBy4*HOYBnXZ}tq1B4qGyII{Deev1KQlupVFPpw%Gr-m zvV57Wt!>uI9`*WK{?ADLJ?cmU9Dh#-{n+KLdrQ{5oiT6cnxk{Y(Fs<(?<>X@C9msK z#f@~YRW$K$^9`2o*_(I>Gg^XX*+alDVd}RFc=`Ml9Z)32M5dl4k4iGIMyij&kn#^H zUcZ7j>!K@o#$(c_GMZAOjv4hNAL6A%|OnrXTKPf=8B_6e`jm zu;XQICtdNGk^!a2q*G}&+)8y-##%r;9KWn({xUTrT5mr1#7*cF@AkJ@6thFp2*nfUONW<`|EL zB9lRNOv|IqLx2_%d69DGrS1mnFJarLTqY3dU{uTN4^E#va|GCsex!1dq6utd_!~oe zaWP6r9l2USwA6*M5E5*#2Q(Q^r_>3{-pPi{0U;gH=Obe z>Xe`#s`HP`%0 zu64s=<}DCoI~rHGg8KzUm%IsY{v}r;zwnYLQCNJ*_pyz$Iu~}vEhWFQdcOJMinlFp z-T5o4_nR**+b_Kox6;m;FMa5B@hwXyA9DCStm65+rHO|eJ`Ww_KF!>?3(0r$4;>>s zU$Inwt^G>-L%fvbD}MW&`Kvtd{g@+r^C)`K&r{lyux-3;vykWM(q(hoCC7@hKF<07 z)?Bh`F8hVGdevGRYwccb?fHeL^o=k7txt&i>c4pclmF6*O`DZ3#ueI%+7+&ZJazC? f)va)4o3?zuX0y4OKeXA;TlnIKUMs(YNsIpj_I`r1 literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/request.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/request.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..b8a58b01f7889af5974c90d28c6ebfea574694ec GIT binary patch literal 1388 zcmZuxON$#v5bmC7jovG-ZEdn%XDx3`ykl(3U=lDGAHq7$17s7{2Tw?v+38j+GY`3^ z6_C(DU?*%2Aby*#8zlUwr5AoW58{}!d&Ed4kgmI$PFTL z4~cO0ASaH!`9!>YKkpWvB6F!J`*ECTUw4u?buCjAzV?IAPg9d?cVsA@+Vk&9eEZI= z>-^oDTX%v*qHMx23_AM??3hU6Q9(TGHWVstVO<4phU^SMp&|!7Ls!w}m^ zL?2YE3EB30q2_Hr(242~mR?O|@^_^#q)HWv4^oDSuT5TeBAN8`wt+lJXqJQw5+Qkz z#89XX7FuTQGqAwv>>7YE8CpYfFAKbChVB6e8*3-D-g>7Um=ypSXS*OBGftS;Gl4IuF^Gi9(?#rq-VkG j+mzDZ$i`n}^G|Ya-yv4{AFE1N_X(Jp4fJoMS)zXdsF+yP literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/response.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/__pycache__/response.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..822b85bd9563b68ef61f4cba89e1751a0da8f1b2 GIT binary patch literal 12673 zcmd^Fdu&_RdB2zUk|HTlq($oex{4%Av?a=RY{yX@C${8wAZNCdB5D$v=Do5h^P%2* zWrd35+ChfcS<=|aTH9y`ds~4yaE4|>fpvdvZH=vHgH5!Yk!5XELkn!#UyPL^sk;ID zedqF$v`ouxR}39?B%XU7-}%mWUf=7SAG=&m4&i*)hhrT*9QSj|n89i!_(cy72u|i? zKFY=TQJ$x?C2AQJ*jF4C+1EO1#aD>hViltm3`UIFV~$Y=OIxGPSmkIXOWUGVG1sUo zRy|sce1&X}x?`SEPi)2L3YK?7YhvC}FH1Y4zF6&OEz*^8RkSWvKU&XoigkRANoMh@ z+JVazZHzUIHpQApn|aQ{DdPC1B7~VzTCZYE6h_+=hlSh8$p_{{c~!^#A;@LRGK+mgDX?cSHQ?cTR7q$wX$FDQ5Ijvo(2Bl0dKBr9sR z>R=?MBqsIks+u6A9)cxY`xR{hT`MTF?pJg*`7sR*xfR=ET3C%t=t_LQ^5scI(}A_d zY&MjL$CWVAkoB5n2a1JZ8l4&PIvKghafRxBmR-|k! zRe_Y9Qb~v3nXM_M$DlbYMB;k3Qp5C3YQb1tzo zq#5ZjO;}buoRE{M8`!fIsxiJ1znHZLgYi&I2?n#yU@(@DC!>_E3I@MC8H(m>+`(YU zq6LHRaf?91-Ptps$0i0QA`|_3NIjzH{nJ`Pot8JK1JTIgfr+GkG!Y+|RHMi}IzY>; zqF5=+@_?FOioirt^#UP_>X6Wy5d9&yu);Sl`ZBKOd9gX;Y?v1tGOo58Vw>7#0^c?5 zB1#eX#XVTj*Gnee!8x!YDK`G(n$z4EFY~XtMg>Kby|U#sv9N`$I4o5LrqWpU$--Sw zqFgJBB_$QWR3}?YO6-cgET($dRtg2$8cfQNZj>utvyM9CCfWX)IO@z(++2j9l-wda z09DD-r6X&UohYx8Tjff$cHvuvZ#8IZlU*gfy5)8pVR6(02sgeflp0x*JtYv{)7;Da zsP6#h@5r_mx8g2cpD>Tm7uC?jgrbJ?6VIm0ff)OrU+lsne2phQIKu@CGs$v!UczxR zJnHg11UUw;qO(9cA%vfZLjMFDu z-?v?@Fp7ClIbK@;DI`!@prKI6jngJw62=>r6d-GIP0;Q#YuQMu&0Lc6SB&gXX%41s z#GVG8%yI|)6)N?RwHYTpTbVzwK^&%R#c@T|h!0ig6G0sONc>3FrYa$g%4LOE1NZ|N zYh3rcv)155A`!)hctF+>G!I@@WEd+6)Z}gz!EiL8DRS1TO=5A0K}6yaJs4ypsWeAm z53DGv#EI9TfI!xYd`ScxOHp-{`mI?}Q=((p6<}wI8V^N_ z6bUp$X9+!yAP9mi2nID;e+l8F+K!aE7SZ&|Ww&O)B%T^*XAymVlFLuL9|HyHe|RrPu9Ct=l&*JwxbQ zGaV~WiyzqyUKTE#2vA6Ac7liro~M0@@6vF9dygM^k5~Iqfe#59jT%bE)Q}9H?pS_m zFwu`uGdfErxdpfP?c|x{oV|f@*KpxfqL$K(B05ZI0w0qc{KoR>K4LVGChwYKi#|h^c1(?lhm3{ESsgY zyFKM@pR>3B&q#ZZ$H`Kme?$~*DSafMS;chs@-*hbhKRu8GR~fvowK+6mdm&exXfi7 zCcLG~NCgi`(@ttzi3sP-#x+Vw#eg2Gnmh!R)Ske*PbDMMUIV@T^q z6$$K8?)6Is;|c&Y9EwJzsR*LO(M0%|G#S?;(E_SNhe9#^&>=&el8%OsE7D;_i8D0P zn3{+&q{VF`p&N#Q$_rRZ>LZ$Du-bsLP(3&iQbREbJq;GhXdJr|Q&Ma)d{jz|ncWa? zm-GbdKOh~%fJ%l+gTU^XRO8a*1fcFh#t@N`ErG#H5wKvUj`vB2Cv_0Rf7r#9yT#IIP7ueM42T}<2tG>nO##NoQ1SQ#%poM=En=C9_DopSwYV$S)|mNFz;C2bc@`qh+1O!EX;^ztt=b^M^LME z;vg)@;*4b)V=y6JLEdp+29Swa!>&>oM>G6=wFVHEy98tfh>aDBF&6T8ms! zzBX)m*>ViB7}BC3F`#6o)b zD4ieJyf9Uz-fqp$v`D|@;}3x)vIcARv5eHmKSY!jcWvJ~>~|Pyr2tzE>fJ;%qN_ft z6+nVYo{g+9k(kIjpChEqa#p)g>bJ3-ovk+2(7di^jv#1^AS-~FY=x20vbKDJHXiMN zQx{l={Pe2jw|}XAIR<#`CL)O6ZvS7r@TV`NyEmk|H_UC^G2gxOboD}I<6LET&a%Sw z2sFDjThaqVsez%tADSQ7^)F4kuL$3K^n&&$o93E!pRGW2(_43T>fOzkJFa^>Z#MPh zEPUhI%%fXB5%|V!{GuQ<*X1~&wk~JqnmR5uUu^zH>scEzzNQOX-xc+b5=fo?A);%?w-p-h%)Zh%XQb?JqxvUr*|y4Yfrm=b$cz> zyodk%(`wGwcAMi}ZJEZ_cWgNUsXN*u7~m!EwgK+1YqqTtzb6Ke{QfE{#RHYwo)Esj znMZt=sYR!Xo#=HqjrTjz+B4YI*tJW;sbRfvhRZ{Y)50wYy4@@=1+m)k@U6$0^UTCx zd{sUPb#l3rya8&#?}k?Gd7b@~_x4~L&bxO=&{?tE% z*9ga60I&Ix41W3WeT>(eqb+`CirgHgb2)B!sz+}$;mbpm%wmCKPh)Lm!Q2(4a|Ik_ zjBwRm9ydk`uBug+>tlvz{JaY-%k1cK`*pn897*wON(k&KI1Y?3P9CKtL6^(|$fbOL zVMr1BGxI!mfYjB8rKZe!nAFUQP-rV=uqMG3g?|56)~DP|=U1WmK5O^ra%-plo~=(O zw-(0V6r}U>;3PbkG-a@Lgc&3UncUpruTcju@oFEUtTO^V7S5MAJQlQQDxLhSE$E{BBI3*HZbVrj7J4~rWv#L{Jvjk^ofX3&4bqo6W!2Sy@>`ec zjjnJAcuoI}x(7f7-$&k{CiK&fEH6Y!Dg7gAdmFj{%&=+_SWmz4bOxsWi8CkW+}$@l zO&8W*+H!GAx;c<)4t&RU!}Hj8hyQNmZ%5Lb_oX)POK*Pe`sU{rymbq%6=|20a!K>9 zM?T@&9BY2zZM`60ieHSU+t#Mq)_!N>4e#L1-qlxzzdiEaNV@OIRNs^Hy-%GLZ+N;h z{(kzd{Kd-tEAqGF@5R%Bt*OA)`IXzwis!4(Rp0P*LVBM5%H>C|bo|+-1*!Y2D^uTm z{=~Tx>H1Zv`c>)rfmHp#2f}>)`m-X`-?XoNR1H+%y(>s!yia_*IHZMf1kUqA3!H^$8dpX=osT9y(xU%&RO z_!F;`>F7Q?{KtEK142n9(cgXiGXKt&@-#!^co_Pg0DYg);@qa_jz+58_X69kdtAal zJTYX$=SME)Y@I?EFq!9He@`t znVR}H_U0T#tEi=ozsuQ1Q^9nouOe|j9ZIb#&*Rwyly%RQvyaN-FtrP^5y1QNmKLsn z47ZwJP*;I6=Ej2Kc4AUzzS?^{MwrSdyuXZT#2-ABMc8Y=t`YA#$q`?eeq;KwFWs^B zddFJq;01ft+s-r2w7n%|Z@F+V-P)gO?Z06Uz}-pC%eJ zFl8R`V$)9-Lis(Ta>^47zgYZBq0D?!2wkwkgOGnB0`-6Bnc@q8!7&Mw!7($iqw+G)CBxk_j zxxu-r)&;{YaAiF?1=h?}tyyNohk@dLBYuDbfG;ZI<$jd#NlyVyO#KX$kBEGrm;y)C+89K z-N0lv{87&y+|j?OkMP3bRiNn5{vAWorVZ;Jmkt;=yV9n>T50o9+;C}w0|Qf2Qvr1> z+^@(Hcn<>!^~eCS^xL#DoR??g5xPJcX4go}4R9#$7KK+X6oKC?AU$kXp#oZVJD;D8M0hd=7aNvD zIy8Xa{U!Or28>sDV9(bX;4+h1`k02Q>4v=#8jBJ94eU-0Ff6|8)P2R`){0b zd(Pat)7D9StbY?^8mVGgo3Q}6PNQD4)@ULmYo^bfDQm<9O^2UIKo2_J1oIIZX+4Ob zs&#Q5A6>^7mkpOI=H0!g#hY&5+pnB?<-+=Tw=`#$?mgim8iOnGi*;bS_dDU*tPU6> zKqOI{C86BOE@SwUn*Wfk$19g~foxF-01sVWED6l9P^Nr&Tug`-92e}awSYGXapSju zCs!Dn{)?z#>V8qhSD6?JP{qYU8u@ev*(&GIqJEUX||m=*AXK>WHu zS10gZA_rwIsTaJdSdi)h#zLZ;uRt$Y_NHQ}4nKVBanewi1dX=UL-tLD)=#q zofPYn;_qn0>wW`@%ZylEf%XreG$|&UeOi~jU-zVoa3{qQOeZ;^OHoZ@Hr ze7nLie7JU|w;DbFKinTv-2avRF~!lJakIcKL2c9jRS>&F_d`r?MlyGD$5|$M6 zRUK(0YGNvmt4(Q40XQCH^%W50)eNX-{UrS9(jot*3zrYj=;FGDw`U392HSRXL>puaF}z<0(U?XxUyC@V0984LOo6qosq17`!|(%saj4* zyhIgDQj8;I`fmy-@O%X$j0cJMEUzqe-O$sC>AvEElzCAVxZA-*ukEzsIM&SE{j7#_ zY+9&oI_=Dft&ZNGR;_@4psDT5o=-fuSojpajP?uqr4tuVq}$h}+Sh$&#|_^XGA+`j zk&7egmVs2uK)Pk)^_GnbFqrRkc`T6J=}37xKJs*a>MV<@q2*Hb#p-m!>Quw(bi=yq z4eNj^?dwkYxGgdgz#j5cBls#2?%6Q4uL7)`1Q3d&jK7Wma!?L+Ovtv)rQD^O0XztHh@dX#CZpc+o3Orz# z|0PxC)^N7!+ZNv1xF{fn>rQJU0Bw%fM^BAXIeej<%|qo4RL)?f0<2UhYb}(uQkm=Z zmrlKO+hVaYSYM7(IVZP+-^1sG25Vi$+iH9t+s3{Nj=n`J$`{vnTI+HnJkh^$Ri>>o z=U8oBv*4=FS@8wt#;#lirR;FAvN~XOx)&>{?4^9OT!quxz}n!OZ$l|N=j>l}Ahp-Dxh7(BPo;z{m2!x?Zsy=(MNUzxO)LEs~%~p~L&mJz~eHY!dW-H0D5C}&jFnpP8 z$yy=_nJ2N~LD!qJA>2fLSzypA%K|XdcZFb!MCyp3QiEX!50;K)Mw%{H6 zX5(G>7WG|}VFz+r0uh)s&)?!6`8ntNDOded&UK6HzQuLi;x_(_Yx_5D!!54&7T11@ zTe%=O(n9@pq5fy$-UVCz$s=i7eacpU!9H*6I4NL-ER~;GM7}-8A;LmfDsz None: + self.host = host + self.port = port + self.timeout = timeout if isinstance(timeout, float) else 0.0 + self.scheme = "http" + self._closed = True + self._response = None + # ignore these things because we don't + # have control over that stuff + self.proxy = None + self.proxy_config = None + self.blocksize = blocksize + self.source_address = None + self.socket_options = None + self.is_verified = False + + def set_tunnel( + self, + host: str, + port: int | None = 0, + headers: typing.Mapping[str, str] | None = None, + scheme: str = "http", + ) -> None: + pass + + def connect(self) -> None: + pass + + def request( + self, + method: str, + url: str, + body: _TYPE_BODY | None = None, + headers: typing.Mapping[str, str] | None = None, + # We know *at least* botocore is depending on the order of the + # first 3 parameters so to be safe we only mark the later ones + # as keyword-only to ensure we have space to extend. + *, + chunked: bool = False, + preload_content: bool = True, + decode_content: bool = True, + enforce_content_length: bool = True, + ) -> None: + self._closed = False + if url.startswith("/"): + # no scheme / host / port included, make a full url + url = f"{self.scheme}://{self.host}:{self.port}" + url + request = EmscriptenRequest( + url=url, + method=method, + timeout=self.timeout if self.timeout else 0, + decode_content=decode_content, + ) + request.set_body(body) + if headers: + for k, v in headers.items(): + request.set_header(k, v) + self._response = None + try: + if not preload_content: + self._response = send_streaming_request(request) + if self._response is None: + self._response = send_request(request) + except _TimeoutError as e: + raise TimeoutError(e.message) from e + except _RequestError as e: + raise HTTPException(e.message) from e + + def getresponse(self) -> BaseHTTPResponse: + if self._response is not None: + return EmscriptenHttpResponseWrapper( + internal_response=self._response, + url=self._response.request.url, + connection=self, + ) + else: + raise ResponseNotReady() + + def close(self) -> None: + self._closed = True + self._response = None + + @property + def is_closed(self) -> bool: + """Whether the connection either is brand new or has been previously closed. + If this property is True then both ``is_connected`` and ``has_connected_to_proxy`` + properties must be False. + """ + return self._closed + + @property + def is_connected(self) -> bool: + """Whether the connection is actively connected to any origin (proxy or target)""" + return True + + @property + def has_connected_to_proxy(self) -> bool: + """Whether the connection has successfully connected to its proxy. + This returns False if no proxy is in use. Used to determine whether + errors are coming from the proxy layer or from tunnelling to the target origin. + """ + return False + + +class EmscriptenHTTPSConnection(EmscriptenHTTPConnection): + default_port = port_by_scheme["https"] + # all this is basically ignored, as browser handles https + cert_reqs: int | str | None = None + ca_certs: str | None = None + ca_cert_dir: str | None = None + ca_cert_data: None | str | bytes = None + cert_file: str | None + key_file: str | None + key_password: str | None + ssl_context: typing.Any | None + ssl_version: int | str | None = None + ssl_minimum_version: int | None = None + ssl_maximum_version: int | None = None + assert_hostname: None | str | typing.Literal[False] + assert_fingerprint: str | None = None + + def __init__( + self, + host: str, + port: int = 0, + *, + timeout: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + source_address: tuple[str, int] | None = None, + blocksize: int = 16384, + socket_options: None + | _TYPE_SOCKET_OPTIONS = HTTPConnection.default_socket_options, + proxy: Url | None = None, + proxy_config: ProxyConfig | None = None, + cert_reqs: int | str | None = None, + assert_hostname: None | str | typing.Literal[False] = None, + assert_fingerprint: str | None = None, + server_hostname: str | None = None, + ssl_context: typing.Any | None = None, + ca_certs: str | None = None, + ca_cert_dir: str | None = None, + ca_cert_data: None | str | bytes = None, + ssl_minimum_version: int | None = None, + ssl_maximum_version: int | None = None, + ssl_version: int | str | None = None, # Deprecated + cert_file: str | None = None, + key_file: str | None = None, + key_password: str | None = None, + ) -> None: + super().__init__( + host, + port=port, + timeout=timeout, + source_address=source_address, + blocksize=blocksize, + socket_options=socket_options, + proxy=proxy, + proxy_config=proxy_config, + ) + self.scheme = "https" + + self.key_file = key_file + self.cert_file = cert_file + self.key_password = key_password + self.ssl_context = ssl_context + self.server_hostname = server_hostname + self.assert_hostname = assert_hostname + self.assert_fingerprint = assert_fingerprint + self.ssl_version = ssl_version + self.ssl_minimum_version = ssl_minimum_version + self.ssl_maximum_version = ssl_maximum_version + self.ca_certs = ca_certs and os.path.expanduser(ca_certs) + self.ca_cert_dir = ca_cert_dir and os.path.expanduser(ca_cert_dir) + self.ca_cert_data = ca_cert_data + + self.cert_reqs = None + + # The browser will automatically verify all requests. + # We have no control over that setting. + self.is_verified = True + + def set_cert( + self, + key_file: str | None = None, + cert_file: str | None = None, + cert_reqs: int | str | None = None, + key_password: str | None = None, + ca_certs: str | None = None, + assert_hostname: None | str | typing.Literal[False] = None, + assert_fingerprint: str | None = None, + ca_cert_dir: str | None = None, + ca_cert_data: None | str | bytes = None, + ) -> None: + pass + + +# verify that this class implements BaseHTTP(s) connection correctly +if typing.TYPE_CHECKING: + _supports_http_protocol: BaseHTTPConnection = EmscriptenHTTPConnection("", 0) + _supports_https_protocol: BaseHTTPSConnection = EmscriptenHTTPSConnection("", 0) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/emscripten_fetch_worker.js b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/emscripten_fetch_worker.js new file mode 100644 index 0000000..243b862 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/emscripten_fetch_worker.js @@ -0,0 +1,110 @@ +let Status = { + SUCCESS_HEADER: -1, + SUCCESS_EOF: -2, + ERROR_TIMEOUT: -3, + ERROR_EXCEPTION: -4, +}; + +let connections = {}; +let nextConnectionID = 1; +const encoder = new TextEncoder(); + +self.addEventListener("message", async function (event) { + if (event.data.close) { + let connectionID = event.data.close; + delete connections[connectionID]; + return; + } else if (event.data.getMore) { + let connectionID = event.data.getMore; + let { curOffset, value, reader, intBuffer, byteBuffer } = + connections[connectionID]; + // if we still have some in buffer, then just send it back straight away + if (!value || curOffset >= value.length) { + // read another buffer if required + try { + let readResponse = await reader.read(); + + if (readResponse.done) { + // read everything - clear connection and return + delete connections[connectionID]; + Atomics.store(intBuffer, 0, Status.SUCCESS_EOF); + Atomics.notify(intBuffer, 0); + // finished reading successfully + // return from event handler + return; + } + curOffset = 0; + connections[connectionID].value = readResponse.value; + value = readResponse.value; + } catch (error) { + console.log("Request exception:", error); + let errorBytes = encoder.encode(error.message); + let written = errorBytes.length; + byteBuffer.set(errorBytes); + intBuffer[1] = written; + Atomics.store(intBuffer, 0, Status.ERROR_EXCEPTION); + Atomics.notify(intBuffer, 0); + } + } + + // send as much buffer as we can + let curLen = value.length - curOffset; + if (curLen > byteBuffer.length) { + curLen = byteBuffer.length; + } + byteBuffer.set(value.subarray(curOffset, curOffset + curLen), 0); + + Atomics.store(intBuffer, 0, curLen); // store current length in bytes + Atomics.notify(intBuffer, 0); + curOffset += curLen; + connections[connectionID].curOffset = curOffset; + + return; + } else { + // start fetch + let connectionID = nextConnectionID; + nextConnectionID += 1; + const intBuffer = new Int32Array(event.data.buffer); + const byteBuffer = new Uint8Array(event.data.buffer, 8); + try { + const response = await fetch(event.data.url, event.data.fetchParams); + // return the headers first via textencoder + var headers = []; + for (const pair of response.headers.entries()) { + headers.push([pair[0], pair[1]]); + } + let headerObj = { + headers: headers, + status: response.status, + connectionID, + }; + const headerText = JSON.stringify(headerObj); + let headerBytes = encoder.encode(headerText); + let written = headerBytes.length; + byteBuffer.set(headerBytes); + intBuffer[1] = written; + // make a connection + connections[connectionID] = { + reader: response.body.getReader(), + intBuffer: intBuffer, + byteBuffer: byteBuffer, + value: undefined, + curOffset: 0, + }; + // set header ready + Atomics.store(intBuffer, 0, Status.SUCCESS_HEADER); + Atomics.notify(intBuffer, 0); + // all fetching after this goes through a new postmessage call with getMore + // this allows for parallel requests + } catch (error) { + console.log("Request exception:", error); + let errorBytes = encoder.encode(error.message); + let written = errorBytes.length; + byteBuffer.set(errorBytes); + intBuffer[1] = written; + Atomics.store(intBuffer, 0, Status.ERROR_EXCEPTION); + Atomics.notify(intBuffer, 0); + } + } +}); +self.postMessage({ inited: true }); diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/fetch.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/fetch.py new file mode 100644 index 0000000..8d197ea --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/fetch.py @@ -0,0 +1,418 @@ +""" +Support for streaming http requests in emscripten. + +A few caveats - + +Firstly, you can't do streaming http in the main UI thread, because atomics.wait isn't allowed. +Streaming only works if you're running pyodide in a web worker. + +Secondly, this uses an extra web worker and SharedArrayBuffer to do the asynchronous fetch +operation, so it requires that you have crossOriginIsolation enabled, by serving over https +(or from localhost) with the two headers below set: + + Cross-Origin-Opener-Policy: same-origin + Cross-Origin-Embedder-Policy: require-corp + +You can tell if cross origin isolation is successfully enabled by looking at the global crossOriginIsolated variable in +javascript console. If it isn't, streaming requests will fallback to XMLHttpRequest, i.e. getting the whole +request into a buffer and then returning it. it shows a warning in the javascript console in this case. + +Finally, the webworker which does the streaming fetch is created on initial import, but will only be started once +control is returned to javascript. Call `await wait_for_streaming_ready()` to wait for streaming fetch. + +NB: in this code, there are a lot of javascript objects. They are named js_* +to make it clear what type of object they are. +""" +from __future__ import annotations + +import io +import json +from email.parser import Parser +from importlib.resources import files +from typing import TYPE_CHECKING, Any + +import js # type: ignore[import-not-found] +from pyodide.ffi import ( # type: ignore[import-not-found] + JsArray, + JsException, + JsProxy, + to_js, +) + +if TYPE_CHECKING: + from typing_extensions import Buffer + +from .request import EmscriptenRequest +from .response import EmscriptenResponse + +""" +There are some headers that trigger unintended CORS preflight requests. +See also https://github.com/koenvo/pyodide-http/issues/22 +""" +HEADERS_TO_IGNORE = ("user-agent",) + +SUCCESS_HEADER = -1 +SUCCESS_EOF = -2 +ERROR_TIMEOUT = -3 +ERROR_EXCEPTION = -4 + +_STREAMING_WORKER_CODE = ( + files(__package__) + .joinpath("emscripten_fetch_worker.js") + .read_text(encoding="utf-8") +) + + +class _RequestError(Exception): + def __init__( + self, + message: str | None = None, + *, + request: EmscriptenRequest | None = None, + response: EmscriptenResponse | None = None, + ): + self.request = request + self.response = response + self.message = message + super().__init__(self.message) + + +class _StreamingError(_RequestError): + pass + + +class _TimeoutError(_RequestError): + pass + + +def _obj_from_dict(dict_val: dict[str, Any]) -> JsProxy: + return to_js(dict_val, dict_converter=js.Object.fromEntries) + + +class _ReadStream(io.RawIOBase): + def __init__( + self, + int_buffer: JsArray, + byte_buffer: JsArray, + timeout: float, + worker: JsProxy, + connection_id: int, + request: EmscriptenRequest, + ): + self.int_buffer = int_buffer + self.byte_buffer = byte_buffer + self.read_pos = 0 + self.read_len = 0 + self.connection_id = connection_id + self.worker = worker + self.timeout = int(1000 * timeout) if timeout > 0 else None + self.is_live = True + self._is_closed = False + self.request: EmscriptenRequest | None = request + + def __del__(self) -> None: + self.close() + + # this is compatible with _base_connection + def is_closed(self) -> bool: + return self._is_closed + + # for compatibility with RawIOBase + @property + def closed(self) -> bool: + return self.is_closed() + + def close(self) -> None: + if not self.is_closed(): + self.read_len = 0 + self.read_pos = 0 + self.int_buffer = None + self.byte_buffer = None + self._is_closed = True + self.request = None + if self.is_live: + self.worker.postMessage(_obj_from_dict({"close": self.connection_id})) + self.is_live = False + super().close() + + def readable(self) -> bool: + return True + + def writable(self) -> bool: + return False + + def seekable(self) -> bool: + return False + + def readinto(self, byte_obj: Buffer) -> int: + if not self.int_buffer: + raise _StreamingError( + "No buffer for stream in _ReadStream.readinto", + request=self.request, + response=None, + ) + if self.read_len == 0: + # wait for the worker to send something + js.Atomics.store(self.int_buffer, 0, ERROR_TIMEOUT) + self.worker.postMessage(_obj_from_dict({"getMore": self.connection_id})) + if ( + js.Atomics.wait(self.int_buffer, 0, ERROR_TIMEOUT, self.timeout) + == "timed-out" + ): + raise _TimeoutError + data_len = self.int_buffer[0] + if data_len > 0: + self.read_len = data_len + self.read_pos = 0 + elif data_len == ERROR_EXCEPTION: + string_len = self.int_buffer[1] + # decode the error string + js_decoder = js.TextDecoder.new() + json_str = js_decoder.decode(self.byte_buffer.slice(0, string_len)) + raise _StreamingError( + f"Exception thrown in fetch: {json_str}", + request=self.request, + response=None, + ) + else: + # EOF, free the buffers and return zero + # and free the request + self.is_live = False + self.close() + return 0 + # copy from int32array to python bytes + ret_length = min(self.read_len, len(memoryview(byte_obj))) + subarray = self.byte_buffer.subarray( + self.read_pos, self.read_pos + ret_length + ).to_py() + memoryview(byte_obj)[0:ret_length] = subarray + self.read_len -= ret_length + self.read_pos += ret_length + return ret_length + + +class _StreamingFetcher: + def __init__(self) -> None: + # make web-worker and data buffer on startup + self.streaming_ready = False + + js_data_blob = js.Blob.new( + [_STREAMING_WORKER_CODE], _obj_from_dict({"type": "application/javascript"}) + ) + + def promise_resolver(js_resolve_fn: JsProxy, js_reject_fn: JsProxy) -> None: + def onMsg(e: JsProxy) -> None: + self.streaming_ready = True + js_resolve_fn(e) + + def onErr(e: JsProxy) -> None: + js_reject_fn(e) # Defensive: never happens in ci + + self.js_worker.onmessage = onMsg + self.js_worker.onerror = onErr + + js_data_url = js.URL.createObjectURL(js_data_blob) + self.js_worker = js.globalThis.Worker.new(js_data_url) + self.js_worker_ready_promise = js.globalThis.Promise.new(promise_resolver) + + def send(self, request: EmscriptenRequest) -> EmscriptenResponse: + headers = { + k: v for k, v in request.headers.items() if k not in HEADERS_TO_IGNORE + } + + body = request.body + fetch_data = {"headers": headers, "body": to_js(body), "method": request.method} + # start the request off in the worker + timeout = int(1000 * request.timeout) if request.timeout > 0 else None + js_shared_buffer = js.SharedArrayBuffer.new(1048576) + js_int_buffer = js.Int32Array.new(js_shared_buffer) + js_byte_buffer = js.Uint8Array.new(js_shared_buffer, 8) + + js.Atomics.store(js_int_buffer, 0, ERROR_TIMEOUT) + js.Atomics.notify(js_int_buffer, 0) + js_absolute_url = js.URL.new(request.url, js.location).href + self.js_worker.postMessage( + _obj_from_dict( + { + "buffer": js_shared_buffer, + "url": js_absolute_url, + "fetchParams": fetch_data, + } + ) + ) + # wait for the worker to send something + js.Atomics.wait(js_int_buffer, 0, ERROR_TIMEOUT, timeout) + if js_int_buffer[0] == ERROR_TIMEOUT: + raise _TimeoutError( + "Timeout connecting to streaming request", + request=request, + response=None, + ) + elif js_int_buffer[0] == SUCCESS_HEADER: + # got response + # header length is in second int of intBuffer + string_len = js_int_buffer[1] + # decode the rest to a JSON string + js_decoder = js.TextDecoder.new() + # this does a copy (the slice) because decode can't work on shared array + # for some silly reason + json_str = js_decoder.decode(js_byte_buffer.slice(0, string_len)) + # get it as an object + response_obj = json.loads(json_str) + return EmscriptenResponse( + request=request, + status_code=response_obj["status"], + headers=response_obj["headers"], + body=_ReadStream( + js_int_buffer, + js_byte_buffer, + request.timeout, + self.js_worker, + response_obj["connectionID"], + request, + ), + ) + elif js_int_buffer[0] == ERROR_EXCEPTION: + string_len = js_int_buffer[1] + # decode the error string + js_decoder = js.TextDecoder.new() + json_str = js_decoder.decode(js_byte_buffer.slice(0, string_len)) + raise _StreamingError( + f"Exception thrown in fetch: {json_str}", request=request, response=None + ) + else: + raise _StreamingError( + f"Unknown status from worker in fetch: {js_int_buffer[0]}", + request=request, + response=None, + ) + + +# check if we are in a worker or not +def is_in_browser_main_thread() -> bool: + return hasattr(js, "window") and hasattr(js, "self") and js.self == js.window + + +def is_cross_origin_isolated() -> bool: + return hasattr(js, "crossOriginIsolated") and js.crossOriginIsolated + + +def is_in_node() -> bool: + return ( + hasattr(js, "process") + and hasattr(js.process, "release") + and hasattr(js.process.release, "name") + and js.process.release.name == "node" + ) + + +def is_worker_available() -> bool: + return hasattr(js, "Worker") and hasattr(js, "Blob") + + +_fetcher: _StreamingFetcher | None = None + +if is_worker_available() and ( + (is_cross_origin_isolated() and not is_in_browser_main_thread()) + and (not is_in_node()) +): + _fetcher = _StreamingFetcher() +else: + _fetcher = None + + +def send_streaming_request(request: EmscriptenRequest) -> EmscriptenResponse | None: + if _fetcher and streaming_ready(): + return _fetcher.send(request) + else: + _show_streaming_warning() + return None + + +_SHOWN_TIMEOUT_WARNING = False + + +def _show_timeout_warning() -> None: + global _SHOWN_TIMEOUT_WARNING + if not _SHOWN_TIMEOUT_WARNING: + _SHOWN_TIMEOUT_WARNING = True + message = "Warning: Timeout is not available on main browser thread" + js.console.warn(message) + + +_SHOWN_STREAMING_WARNING = False + + +def _show_streaming_warning() -> None: + global _SHOWN_STREAMING_WARNING + if not _SHOWN_STREAMING_WARNING: + _SHOWN_STREAMING_WARNING = True + message = "Can't stream HTTP requests because: \n" + if not is_cross_origin_isolated(): + message += " Page is not cross-origin isolated\n" + if is_in_browser_main_thread(): + message += " Python is running in main browser thread\n" + if not is_worker_available(): + message += " Worker or Blob classes are not available in this environment." # Defensive: this is always False in browsers that we test in + if streaming_ready() is False: + message += """ Streaming fetch worker isn't ready. If you want to be sure that streaming fetch +is working, you need to call: 'await urllib3.contrib.emscripten.fetch.wait_for_streaming_ready()`""" + from js import console + + console.warn(message) + + +def send_request(request: EmscriptenRequest) -> EmscriptenResponse: + try: + js_xhr = js.XMLHttpRequest.new() + + if not is_in_browser_main_thread(): + js_xhr.responseType = "arraybuffer" + if request.timeout: + js_xhr.timeout = int(request.timeout * 1000) + else: + js_xhr.overrideMimeType("text/plain; charset=ISO-8859-15") + if request.timeout: + # timeout isn't available on the main thread - show a warning in console + # if it is set + _show_timeout_warning() + + js_xhr.open(request.method, request.url, False) + for name, value in request.headers.items(): + if name.lower() not in HEADERS_TO_IGNORE: + js_xhr.setRequestHeader(name, value) + + js_xhr.send(to_js(request.body)) + + headers = dict(Parser().parsestr(js_xhr.getAllResponseHeaders())) + + if not is_in_browser_main_thread(): + body = js_xhr.response.to_py().tobytes() + else: + body = js_xhr.response.encode("ISO-8859-15") + return EmscriptenResponse( + status_code=js_xhr.status, headers=headers, body=body, request=request + ) + except JsException as err: + if err.name == "TimeoutError": + raise _TimeoutError(err.message, request=request) + elif err.name == "NetworkError": + raise _RequestError(err.message, request=request) + else: + # general http error + raise _RequestError(err.message, request=request) + + +def streaming_ready() -> bool | None: + if _fetcher: + return _fetcher.streaming_ready + else: + return None # no fetcher, return None to signify that + + +async def wait_for_streaming_ready() -> bool: + if _fetcher: + await _fetcher.js_worker_ready_promise + return True + else: + return False diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/request.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/request.py new file mode 100644 index 0000000..e692e69 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/request.py @@ -0,0 +1,22 @@ +from __future__ import annotations + +from dataclasses import dataclass, field + +from ..._base_connection import _TYPE_BODY + + +@dataclass +class EmscriptenRequest: + method: str + url: str + params: dict[str, str] | None = None + body: _TYPE_BODY | None = None + headers: dict[str, str] = field(default_factory=dict) + timeout: float = 0 + decode_content: bool = True + + def set_header(self, name: str, value: str) -> None: + self.headers[name.capitalize()] = value + + def set_body(self, body: _TYPE_BODY | None) -> None: + self.body = body diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/response.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/response.py new file mode 100644 index 0000000..cd3d80e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/emscripten/response.py @@ -0,0 +1,285 @@ +from __future__ import annotations + +import json as _json +import logging +import typing +from contextlib import contextmanager +from dataclasses import dataclass +from http.client import HTTPException as HTTPException +from io import BytesIO, IOBase + +from ...exceptions import InvalidHeader, TimeoutError +from ...response import BaseHTTPResponse +from ...util.retry import Retry +from .request import EmscriptenRequest + +if typing.TYPE_CHECKING: + from ..._base_connection import BaseHTTPConnection, BaseHTTPSConnection + +log = logging.getLogger(__name__) + + +@dataclass +class EmscriptenResponse: + status_code: int + headers: dict[str, str] + body: IOBase | bytes + request: EmscriptenRequest + + +class EmscriptenHttpResponseWrapper(BaseHTTPResponse): + def __init__( + self, + internal_response: EmscriptenResponse, + url: str | None = None, + connection: BaseHTTPConnection | BaseHTTPSConnection | None = None, + ): + self._pool = None # set by pool class + self._body = None + self._response = internal_response + self._url = url + self._connection = connection + self._closed = False + super().__init__( + headers=internal_response.headers, + status=internal_response.status_code, + request_url=url, + version=0, + version_string="HTTP/?", + reason="", + decode_content=True, + ) + self.length_remaining = self._init_length(self._response.request.method) + self.length_is_certain = False + + @property + def url(self) -> str | None: + return self._url + + @url.setter + def url(self, url: str | None) -> None: + self._url = url + + @property + def connection(self) -> BaseHTTPConnection | BaseHTTPSConnection | None: + return self._connection + + @property + def retries(self) -> Retry | None: + return self._retries + + @retries.setter + def retries(self, retries: Retry | None) -> None: + # Override the request_url if retries has a redirect location. + self._retries = retries + + def stream( + self, amt: int | None = 2**16, decode_content: bool | None = None + ) -> typing.Generator[bytes, None, None]: + """ + A generator wrapper for the read() method. A call will block until + ``amt`` bytes have been read from the connection or until the + connection is closed. + + :param amt: + How much of the content to read. The generator will return up to + much data per iteration, but may return less. This is particularly + likely when using compressed data. However, the empty string will + never be returned. + + :param decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + """ + while True: + data = self.read(amt=amt, decode_content=decode_content) + + if data: + yield data + else: + break + + def _init_length(self, request_method: str | None) -> int | None: + length: int | None + content_length: str | None = self.headers.get("content-length") + + if content_length is not None: + try: + # RFC 7230 section 3.3.2 specifies multiple content lengths can + # be sent in a single Content-Length header + # (e.g. Content-Length: 42, 42). This line ensures the values + # are all valid ints and that as long as the `set` length is 1, + # all values are the same. Otherwise, the header is invalid. + lengths = {int(val) for val in content_length.split(",")} + if len(lengths) > 1: + raise InvalidHeader( + "Content-Length contained multiple " + "unmatching values (%s)" % content_length + ) + length = lengths.pop() + except ValueError: + length = None + else: + if length < 0: + length = None + + else: # if content_length is None + length = None + + # Check for responses that shouldn't include a body + if ( + self.status in (204, 304) + or 100 <= self.status < 200 + or request_method == "HEAD" + ): + length = 0 + + return length + + def read( + self, + amt: int | None = None, + decode_content: bool | None = None, # ignored because browser decodes always + cache_content: bool = False, + ) -> bytes: + if ( + self._closed + or self._response is None + or (isinstance(self._response.body, IOBase) and self._response.body.closed) + ): + return b"" + + with self._error_catcher(): + # body has been preloaded as a string by XmlHttpRequest + if not isinstance(self._response.body, IOBase): + self.length_remaining = len(self._response.body) + self.length_is_certain = True + # wrap body in IOStream + self._response.body = BytesIO(self._response.body) + if amt is not None and amt >= 0: + # don't cache partial content + cache_content = False + data = self._response.body.read(amt) + if self.length_remaining is not None: + self.length_remaining = max(self.length_remaining - len(data), 0) + if (self.length_is_certain and self.length_remaining == 0) or len( + data + ) < amt: + # definitely finished reading, close response stream + self._response.body.close() + return typing.cast(bytes, data) + else: # read all we can (and cache it) + data = self._response.body.read() + if cache_content: + self._body = data + if self.length_remaining is not None: + self.length_remaining = max(self.length_remaining - len(data), 0) + if len(data) == 0 or ( + self.length_is_certain and self.length_remaining == 0 + ): + # definitely finished reading, close response stream + self._response.body.close() + return typing.cast(bytes, data) + + def read_chunked( + self, + amt: int | None = None, + decode_content: bool | None = None, + ) -> typing.Generator[bytes, None, None]: + # chunked is handled by browser + while True: + bytes = self.read(amt, decode_content) + if not bytes: + break + yield bytes + + def release_conn(self) -> None: + if not self._pool or not self._connection: + return None + + self._pool._put_conn(self._connection) + self._connection = None + + def drain_conn(self) -> None: + self.close() + + @property + def data(self) -> bytes: + if self._body: + return self._body + else: + return self.read(cache_content=True) + + def json(self) -> typing.Any: + """ + Deserializes the body of the HTTP response as a Python object. + + The body of the HTTP response must be encoded using UTF-8, as per + `RFC 8529 Section 8.1 `_. + + To use a custom JSON decoder pass the result of :attr:`HTTPResponse.data` to + your custom decoder instead. + + If the body of the HTTP response is not decodable to UTF-8, a + `UnicodeDecodeError` will be raised. If the body of the HTTP response is not a + valid JSON document, a `json.JSONDecodeError` will be raised. + + Read more :ref:`here `. + + :returns: The body of the HTTP response as a Python object. + """ + data = self.data.decode("utf-8") + return _json.loads(data) + + def close(self) -> None: + if not self._closed: + if isinstance(self._response.body, IOBase): + self._response.body.close() + if self._connection: + self._connection.close() + self._connection = None + self._closed = True + + @contextmanager + def _error_catcher(self) -> typing.Generator[None, None, None]: + """ + Catch Emscripten specific exceptions thrown by fetch.py, + instead re-raising urllib3 variants, so that low-level exceptions + are not leaked in the high-level api. + + On exit, release the connection back to the pool. + """ + from .fetch import _RequestError, _TimeoutError # avoid circular import + + clean_exit = False + + try: + yield + # If no exception is thrown, we should avoid cleaning up + # unnecessarily. + clean_exit = True + except _TimeoutError as e: + raise TimeoutError(str(e)) + except _RequestError as e: + raise HTTPException(str(e)) + finally: + # If we didn't terminate cleanly, we need to throw away our + # connection. + if not clean_exit: + # The response may not be closed but we're not going to use it + # anymore so close it now + if ( + isinstance(self._response.body, IOBase) + and not self._response.body.closed + ): + self._response.body.close() + # release the connection back to the pool + self.release_conn() + else: + # If we have read everything from the response stream, + # return the connection back to the pool. + if ( + isinstance(self._response.body, IOBase) + and self._response.body.closed + ): + self.release_conn() diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/pyopenssl.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/pyopenssl.py new file mode 100644 index 0000000..b89a6da --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/pyopenssl.py @@ -0,0 +1,548 @@ +""" +Module for using pyOpenSSL as a TLS backend. This module was relevant before +the standard library ``ssl`` module supported SNI, but now that we've dropped +support for Python 2.7 all relevant Python versions support SNI so +**this module is no longer recommended**. + +This needs the following packages installed: + +* `pyOpenSSL`_ (tested with 16.0.0) +* `cryptography`_ (minimum 1.3.4, from pyopenssl) +* `idna`_ (minimum 2.0) + +However, pyOpenSSL depends on cryptography, so while we use all three directly here we +end up having relatively few packages required. + +You can install them with the following command: + +.. code-block:: bash + + $ python -m pip install pyopenssl cryptography idna + +To activate certificate checking, call +:func:`~urllib3.contrib.pyopenssl.inject_into_urllib3` from your Python code +before you begin making HTTP requests. This can be done in a ``sitecustomize`` +module, or at any other time before your application begins using ``urllib3``, +like this: + +.. code-block:: python + + try: + import urllib3.contrib.pyopenssl + urllib3.contrib.pyopenssl.inject_into_urllib3() + except ImportError: + pass + +.. _pyopenssl: https://www.pyopenssl.org +.. _cryptography: https://cryptography.io +.. _idna: https://github.com/kjd/idna +""" + +from __future__ import annotations + +import OpenSSL.SSL # type: ignore[import-untyped] +from cryptography import x509 + +try: + from cryptography.x509 import UnsupportedExtension # type: ignore[attr-defined] +except ImportError: + # UnsupportedExtension is gone in cryptography >= 2.1.0 + class UnsupportedExtension(Exception): # type: ignore[no-redef] + pass + + +import logging +import ssl +import typing +from io import BytesIO +from socket import socket as socket_cls +from socket import timeout + +from .. import util + +if typing.TYPE_CHECKING: + from OpenSSL.crypto import X509 # type: ignore[import-untyped] + + +__all__ = ["inject_into_urllib3", "extract_from_urllib3"] + +# Map from urllib3 to PyOpenSSL compatible parameter-values. +_openssl_versions: dict[int, int] = { + util.ssl_.PROTOCOL_TLS: OpenSSL.SSL.SSLv23_METHOD, # type: ignore[attr-defined] + util.ssl_.PROTOCOL_TLS_CLIENT: OpenSSL.SSL.SSLv23_METHOD, # type: ignore[attr-defined] + ssl.PROTOCOL_TLSv1: OpenSSL.SSL.TLSv1_METHOD, +} + +if hasattr(ssl, "PROTOCOL_TLSv1_1") and hasattr(OpenSSL.SSL, "TLSv1_1_METHOD"): + _openssl_versions[ssl.PROTOCOL_TLSv1_1] = OpenSSL.SSL.TLSv1_1_METHOD + +if hasattr(ssl, "PROTOCOL_TLSv1_2") and hasattr(OpenSSL.SSL, "TLSv1_2_METHOD"): + _openssl_versions[ssl.PROTOCOL_TLSv1_2] = OpenSSL.SSL.TLSv1_2_METHOD + + +_stdlib_to_openssl_verify = { + ssl.CERT_NONE: OpenSSL.SSL.VERIFY_NONE, + ssl.CERT_OPTIONAL: OpenSSL.SSL.VERIFY_PEER, + ssl.CERT_REQUIRED: OpenSSL.SSL.VERIFY_PEER + + OpenSSL.SSL.VERIFY_FAIL_IF_NO_PEER_CERT, +} +_openssl_to_stdlib_verify = {v: k for k, v in _stdlib_to_openssl_verify.items()} + +# The SSLvX values are the most likely to be missing in the future +# but we check them all just to be sure. +_OP_NO_SSLv2_OR_SSLv3: int = getattr(OpenSSL.SSL, "OP_NO_SSLv2", 0) | getattr( + OpenSSL.SSL, "OP_NO_SSLv3", 0 +) +_OP_NO_TLSv1: int = getattr(OpenSSL.SSL, "OP_NO_TLSv1", 0) +_OP_NO_TLSv1_1: int = getattr(OpenSSL.SSL, "OP_NO_TLSv1_1", 0) +_OP_NO_TLSv1_2: int = getattr(OpenSSL.SSL, "OP_NO_TLSv1_2", 0) +_OP_NO_TLSv1_3: int = getattr(OpenSSL.SSL, "OP_NO_TLSv1_3", 0) + +_openssl_to_ssl_minimum_version: dict[int, int] = { + ssl.TLSVersion.MINIMUM_SUPPORTED: _OP_NO_SSLv2_OR_SSLv3, + ssl.TLSVersion.TLSv1: _OP_NO_SSLv2_OR_SSLv3, + ssl.TLSVersion.TLSv1_1: _OP_NO_SSLv2_OR_SSLv3 | _OP_NO_TLSv1, + ssl.TLSVersion.TLSv1_2: _OP_NO_SSLv2_OR_SSLv3 | _OP_NO_TLSv1 | _OP_NO_TLSv1_1, + ssl.TLSVersion.TLSv1_3: ( + _OP_NO_SSLv2_OR_SSLv3 | _OP_NO_TLSv1 | _OP_NO_TLSv1_1 | _OP_NO_TLSv1_2 + ), + ssl.TLSVersion.MAXIMUM_SUPPORTED: ( + _OP_NO_SSLv2_OR_SSLv3 | _OP_NO_TLSv1 | _OP_NO_TLSv1_1 | _OP_NO_TLSv1_2 + ), +} +_openssl_to_ssl_maximum_version: dict[int, int] = { + ssl.TLSVersion.MINIMUM_SUPPORTED: ( + _OP_NO_SSLv2_OR_SSLv3 + | _OP_NO_TLSv1 + | _OP_NO_TLSv1_1 + | _OP_NO_TLSv1_2 + | _OP_NO_TLSv1_3 + ), + ssl.TLSVersion.TLSv1: ( + _OP_NO_SSLv2_OR_SSLv3 | _OP_NO_TLSv1_1 | _OP_NO_TLSv1_2 | _OP_NO_TLSv1_3 + ), + ssl.TLSVersion.TLSv1_1: _OP_NO_SSLv2_OR_SSLv3 | _OP_NO_TLSv1_2 | _OP_NO_TLSv1_3, + ssl.TLSVersion.TLSv1_2: _OP_NO_SSLv2_OR_SSLv3 | _OP_NO_TLSv1_3, + ssl.TLSVersion.TLSv1_3: _OP_NO_SSLv2_OR_SSLv3, + ssl.TLSVersion.MAXIMUM_SUPPORTED: _OP_NO_SSLv2_OR_SSLv3, +} + +# OpenSSL will only write 16K at a time +SSL_WRITE_BLOCKSIZE = 16384 + +orig_util_SSLContext = util.ssl_.SSLContext + + +log = logging.getLogger(__name__) + + +def inject_into_urllib3() -> None: + "Monkey-patch urllib3 with PyOpenSSL-backed SSL-support." + + _validate_dependencies_met() + + util.SSLContext = PyOpenSSLContext # type: ignore[assignment] + util.ssl_.SSLContext = PyOpenSSLContext # type: ignore[assignment] + util.IS_PYOPENSSL = True + util.ssl_.IS_PYOPENSSL = True + + +def extract_from_urllib3() -> None: + "Undo monkey-patching by :func:`inject_into_urllib3`." + + util.SSLContext = orig_util_SSLContext + util.ssl_.SSLContext = orig_util_SSLContext + util.IS_PYOPENSSL = False + util.ssl_.IS_PYOPENSSL = False + + +def _validate_dependencies_met() -> None: + """ + Verifies that PyOpenSSL's package-level dependencies have been met. + Throws `ImportError` if they are not met. + """ + # Method added in `cryptography==1.1`; not available in older versions + from cryptography.x509.extensions import Extensions + + if getattr(Extensions, "get_extension_for_class", None) is None: + raise ImportError( + "'cryptography' module missing required functionality. " + "Try upgrading to v1.3.4 or newer." + ) + + # pyOpenSSL 0.14 and above use cryptography for OpenSSL bindings. The _x509 + # attribute is only present on those versions. + from OpenSSL.crypto import X509 + + x509 = X509() + if getattr(x509, "_x509", None) is None: + raise ImportError( + "'pyOpenSSL' module missing required functionality. " + "Try upgrading to v0.14 or newer." + ) + + +def _dnsname_to_stdlib(name: str) -> str | None: + """ + Converts a dNSName SubjectAlternativeName field to the form used by the + standard library on the given Python version. + + Cryptography produces a dNSName as a unicode string that was idna-decoded + from ASCII bytes. We need to idna-encode that string to get it back, and + then on Python 3 we also need to convert to unicode via UTF-8 (the stdlib + uses PyUnicode_FromStringAndSize on it, which decodes via UTF-8). + + If the name cannot be idna-encoded then we return None signalling that + the name given should be skipped. + """ + + def idna_encode(name: str) -> bytes | None: + """ + Borrowed wholesale from the Python Cryptography Project. It turns out + that we can't just safely call `idna.encode`: it can explode for + wildcard names. This avoids that problem. + """ + import idna + + try: + for prefix in ["*.", "."]: + if name.startswith(prefix): + name = name[len(prefix) :] + return prefix.encode("ascii") + idna.encode(name) + return idna.encode(name) + except idna.core.IDNAError: + return None + + # Don't send IPv6 addresses through the IDNA encoder. + if ":" in name: + return name + + encoded_name = idna_encode(name) + if encoded_name is None: + return None + return encoded_name.decode("utf-8") + + +def get_subj_alt_name(peer_cert: X509) -> list[tuple[str, str]]: + """ + Given an PyOpenSSL certificate, provides all the subject alternative names. + """ + cert = peer_cert.to_cryptography() + + # We want to find the SAN extension. Ask Cryptography to locate it (it's + # faster than looping in Python) + try: + ext = cert.extensions.get_extension_for_class(x509.SubjectAlternativeName).value + except x509.ExtensionNotFound: + # No such extension, return the empty list. + return [] + except ( + x509.DuplicateExtension, + UnsupportedExtension, + x509.UnsupportedGeneralNameType, + UnicodeError, + ) as e: + # A problem has been found with the quality of the certificate. Assume + # no SAN field is present. + log.warning( + "A problem was encountered with the certificate that prevented " + "urllib3 from finding the SubjectAlternativeName field. This can " + "affect certificate validation. The error was %s", + e, + ) + return [] + + # We want to return dNSName and iPAddress fields. We need to cast the IPs + # back to strings because the match_hostname function wants them as + # strings. + # Sadly the DNS names need to be idna encoded and then, on Python 3, UTF-8 + # decoded. This is pretty frustrating, but that's what the standard library + # does with certificates, and so we need to attempt to do the same. + # We also want to skip over names which cannot be idna encoded. + names = [ + ("DNS", name) + for name in map(_dnsname_to_stdlib, ext.get_values_for_type(x509.DNSName)) + if name is not None + ] + names.extend( + ("IP Address", str(name)) for name in ext.get_values_for_type(x509.IPAddress) + ) + + return names + + +class WrappedSocket: + """API-compatibility wrapper for Python OpenSSL's Connection-class.""" + + def __init__( + self, + connection: OpenSSL.SSL.Connection, + socket: socket_cls, + suppress_ragged_eofs: bool = True, + ) -> None: + self.connection = connection + self.socket = socket + self.suppress_ragged_eofs = suppress_ragged_eofs + self._io_refs = 0 + self._closed = False + + def fileno(self) -> int: + return self.socket.fileno() + + # Copy-pasted from Python 3.5 source code + def _decref_socketios(self) -> None: + if self._io_refs > 0: + self._io_refs -= 1 + if self._closed: + self.close() + + def recv(self, *args: typing.Any, **kwargs: typing.Any) -> bytes: + try: + data = self.connection.recv(*args, **kwargs) + except OpenSSL.SSL.SysCallError as e: + if self.suppress_ragged_eofs and e.args == (-1, "Unexpected EOF"): + return b"" + else: + raise OSError(e.args[0], str(e)) from e + except OpenSSL.SSL.ZeroReturnError: + if self.connection.get_shutdown() == OpenSSL.SSL.RECEIVED_SHUTDOWN: + return b"" + else: + raise + except OpenSSL.SSL.WantReadError as e: + if not util.wait_for_read(self.socket, self.socket.gettimeout()): + raise timeout("The read operation timed out") from e + else: + return self.recv(*args, **kwargs) + + # TLS 1.3 post-handshake authentication + except OpenSSL.SSL.Error as e: + raise ssl.SSLError(f"read error: {e!r}") from e + else: + return data # type: ignore[no-any-return] + + def recv_into(self, *args: typing.Any, **kwargs: typing.Any) -> int: + try: + return self.connection.recv_into(*args, **kwargs) # type: ignore[no-any-return] + except OpenSSL.SSL.SysCallError as e: + if self.suppress_ragged_eofs and e.args == (-1, "Unexpected EOF"): + return 0 + else: + raise OSError(e.args[0], str(e)) from e + except OpenSSL.SSL.ZeroReturnError: + if self.connection.get_shutdown() == OpenSSL.SSL.RECEIVED_SHUTDOWN: + return 0 + else: + raise + except OpenSSL.SSL.WantReadError as e: + if not util.wait_for_read(self.socket, self.socket.gettimeout()): + raise timeout("The read operation timed out") from e + else: + return self.recv_into(*args, **kwargs) + + # TLS 1.3 post-handshake authentication + except OpenSSL.SSL.Error as e: + raise ssl.SSLError(f"read error: {e!r}") from e + + def settimeout(self, timeout: float) -> None: + return self.socket.settimeout(timeout) + + def _send_until_done(self, data: bytes) -> int: + while True: + try: + return self.connection.send(data) # type: ignore[no-any-return] + except OpenSSL.SSL.WantWriteError as e: + if not util.wait_for_write(self.socket, self.socket.gettimeout()): + raise timeout() from e + continue + except OpenSSL.SSL.SysCallError as e: + raise OSError(e.args[0], str(e)) from e + + def sendall(self, data: bytes) -> None: + total_sent = 0 + while total_sent < len(data): + sent = self._send_until_done( + data[total_sent : total_sent + SSL_WRITE_BLOCKSIZE] + ) + total_sent += sent + + def shutdown(self) -> None: + # FIXME rethrow compatible exceptions should we ever use this + self.connection.shutdown() + + def close(self) -> None: + self._closed = True + if self._io_refs <= 0: + self._real_close() + + def _real_close(self) -> None: + try: + return self.connection.close() # type: ignore[no-any-return] + except OpenSSL.SSL.Error: + return + + def getpeercert( + self, binary_form: bool = False + ) -> dict[str, list[typing.Any]] | None: + x509 = self.connection.get_peer_certificate() + + if not x509: + return x509 # type: ignore[no-any-return] + + if binary_form: + return OpenSSL.crypto.dump_certificate(OpenSSL.crypto.FILETYPE_ASN1, x509) # type: ignore[no-any-return] + + return { + "subject": ((("commonName", x509.get_subject().CN),),), # type: ignore[dict-item] + "subjectAltName": get_subj_alt_name(x509), + } + + def version(self) -> str: + return self.connection.get_protocol_version_name() # type: ignore[no-any-return] + + +WrappedSocket.makefile = socket_cls.makefile # type: ignore[attr-defined] + + +class PyOpenSSLContext: + """ + I am a wrapper class for the PyOpenSSL ``Context`` object. I am responsible + for translating the interface of the standard library ``SSLContext`` object + to calls into PyOpenSSL. + """ + + def __init__(self, protocol: int) -> None: + self.protocol = _openssl_versions[protocol] + self._ctx = OpenSSL.SSL.Context(self.protocol) + self._options = 0 + self.check_hostname = False + self._minimum_version: int = ssl.TLSVersion.MINIMUM_SUPPORTED + self._maximum_version: int = ssl.TLSVersion.MAXIMUM_SUPPORTED + + @property + def options(self) -> int: + return self._options + + @options.setter + def options(self, value: int) -> None: + self._options = value + self._set_ctx_options() + + @property + def verify_mode(self) -> int: + return _openssl_to_stdlib_verify[self._ctx.get_verify_mode()] + + @verify_mode.setter + def verify_mode(self, value: ssl.VerifyMode) -> None: + self._ctx.set_verify(_stdlib_to_openssl_verify[value], _verify_callback) + + def set_default_verify_paths(self) -> None: + self._ctx.set_default_verify_paths() + + def set_ciphers(self, ciphers: bytes | str) -> None: + if isinstance(ciphers, str): + ciphers = ciphers.encode("utf-8") + self._ctx.set_cipher_list(ciphers) + + def load_verify_locations( + self, + cafile: str | None = None, + capath: str | None = None, + cadata: bytes | None = None, + ) -> None: + if cafile is not None: + cafile = cafile.encode("utf-8") # type: ignore[assignment] + if capath is not None: + capath = capath.encode("utf-8") # type: ignore[assignment] + try: + self._ctx.load_verify_locations(cafile, capath) + if cadata is not None: + self._ctx.load_verify_locations(BytesIO(cadata)) + except OpenSSL.SSL.Error as e: + raise ssl.SSLError(f"unable to load trusted certificates: {e!r}") from e + + def load_cert_chain( + self, + certfile: str, + keyfile: str | None = None, + password: str | None = None, + ) -> None: + try: + self._ctx.use_certificate_chain_file(certfile) + if password is not None: + if not isinstance(password, bytes): + password = password.encode("utf-8") # type: ignore[assignment] + self._ctx.set_passwd_cb(lambda *_: password) + self._ctx.use_privatekey_file(keyfile or certfile) + except OpenSSL.SSL.Error as e: + raise ssl.SSLError(f"Unable to load certificate chain: {e!r}") from e + + def set_alpn_protocols(self, protocols: list[bytes | str]) -> None: + protocols = [util.util.to_bytes(p, "ascii") for p in protocols] + return self._ctx.set_alpn_protos(protocols) # type: ignore[no-any-return] + + def wrap_socket( + self, + sock: socket_cls, + server_side: bool = False, + do_handshake_on_connect: bool = True, + suppress_ragged_eofs: bool = True, + server_hostname: bytes | str | None = None, + ) -> WrappedSocket: + cnx = OpenSSL.SSL.Connection(self._ctx, sock) + + # If server_hostname is an IP, don't use it for SNI, per RFC6066 Section 3 + if server_hostname and not util.ssl_.is_ipaddress(server_hostname): + if isinstance(server_hostname, str): + server_hostname = server_hostname.encode("utf-8") + cnx.set_tlsext_host_name(server_hostname) + + cnx.set_connect_state() + + while True: + try: + cnx.do_handshake() + except OpenSSL.SSL.WantReadError as e: + if not util.wait_for_read(sock, sock.gettimeout()): + raise timeout("select timed out") from e + continue + except OpenSSL.SSL.Error as e: + raise ssl.SSLError(f"bad handshake: {e!r}") from e + break + + return WrappedSocket(cnx, sock) + + def _set_ctx_options(self) -> None: + self._ctx.set_options( + self._options + | _openssl_to_ssl_minimum_version[self._minimum_version] + | _openssl_to_ssl_maximum_version[self._maximum_version] + ) + + @property + def minimum_version(self) -> int: + return self._minimum_version + + @minimum_version.setter + def minimum_version(self, minimum_version: int) -> None: + self._minimum_version = minimum_version + self._set_ctx_options() + + @property + def maximum_version(self) -> int: + return self._maximum_version + + @maximum_version.setter + def maximum_version(self, maximum_version: int) -> None: + self._maximum_version = maximum_version + self._set_ctx_options() + + +def _verify_callback( + cnx: OpenSSL.SSL.Connection, + x509: X509, + err_no: int, + err_depth: int, + return_code: int, +) -> bool: + return err_no == 0 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/socks.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/socks.py new file mode 100644 index 0000000..c62b5e0 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/contrib/socks.py @@ -0,0 +1,228 @@ +""" +This module contains provisional support for SOCKS proxies from within +urllib3. This module supports SOCKS4, SOCKS4A (an extension of SOCKS4), and +SOCKS5. To enable its functionality, either install PySocks or install this +module with the ``socks`` extra. + +The SOCKS implementation supports the full range of urllib3 features. It also +supports the following SOCKS features: + +- SOCKS4A (``proxy_url='socks4a://...``) +- SOCKS4 (``proxy_url='socks4://...``) +- SOCKS5 with remote DNS (``proxy_url='socks5h://...``) +- SOCKS5 with local DNS (``proxy_url='socks5://...``) +- Usernames and passwords for the SOCKS proxy + +.. note:: + It is recommended to use ``socks5h://`` or ``socks4a://`` schemes in + your ``proxy_url`` to ensure that DNS resolution is done from the remote + server instead of client-side when connecting to a domain name. + +SOCKS4 supports IPv4 and domain names with the SOCKS4A extension. SOCKS5 +supports IPv4, IPv6, and domain names. + +When connecting to a SOCKS4 proxy the ``username`` portion of the ``proxy_url`` +will be sent as the ``userid`` section of the SOCKS request: + +.. code-block:: python + + proxy_url="socks4a://@proxy-host" + +When connecting to a SOCKS5 proxy the ``username`` and ``password`` portion +of the ``proxy_url`` will be sent as the username/password to authenticate +with the proxy: + +.. code-block:: python + + proxy_url="socks5h://:@proxy-host" + +""" + +from __future__ import annotations + +try: + import socks # type: ignore[import-not-found] +except ImportError: + import warnings + + from ..exceptions import DependencyWarning + + warnings.warn( + ( + "SOCKS support in urllib3 requires the installation of optional " + "dependencies: specifically, PySocks. For more information, see " + "https://urllib3.readthedocs.io/en/latest/advanced-usage.html#socks-proxies" + ), + DependencyWarning, + ) + raise + +import typing +from socket import timeout as SocketTimeout + +from ..connection import HTTPConnection, HTTPSConnection +from ..connectionpool import HTTPConnectionPool, HTTPSConnectionPool +from ..exceptions import ConnectTimeoutError, NewConnectionError +from ..poolmanager import PoolManager +from ..util.url import parse_url + +try: + import ssl +except ImportError: + ssl = None # type: ignore[assignment] + + +class _TYPE_SOCKS_OPTIONS(typing.TypedDict): + socks_version: int + proxy_host: str | None + proxy_port: str | None + username: str | None + password: str | None + rdns: bool + + +class SOCKSConnection(HTTPConnection): + """ + A plain-text HTTP connection that connects via a SOCKS proxy. + """ + + def __init__( + self, + _socks_options: _TYPE_SOCKS_OPTIONS, + *args: typing.Any, + **kwargs: typing.Any, + ) -> None: + self._socks_options = _socks_options + super().__init__(*args, **kwargs) + + def _new_conn(self) -> socks.socksocket: + """ + Establish a new connection via the SOCKS proxy. + """ + extra_kw: dict[str, typing.Any] = {} + if self.source_address: + extra_kw["source_address"] = self.source_address + + if self.socket_options: + extra_kw["socket_options"] = self.socket_options + + try: + conn = socks.create_connection( + (self.host, self.port), + proxy_type=self._socks_options["socks_version"], + proxy_addr=self._socks_options["proxy_host"], + proxy_port=self._socks_options["proxy_port"], + proxy_username=self._socks_options["username"], + proxy_password=self._socks_options["password"], + proxy_rdns=self._socks_options["rdns"], + timeout=self.timeout, + **extra_kw, + ) + + except SocketTimeout as e: + raise ConnectTimeoutError( + self, + f"Connection to {self.host} timed out. (connect timeout={self.timeout})", + ) from e + + except socks.ProxyError as e: + # This is fragile as hell, but it seems to be the only way to raise + # useful errors here. + if e.socket_err: + error = e.socket_err + if isinstance(error, SocketTimeout): + raise ConnectTimeoutError( + self, + f"Connection to {self.host} timed out. (connect timeout={self.timeout})", + ) from e + else: + # Adding `from e` messes with coverage somehow, so it's omitted. + # See #2386. + raise NewConnectionError( + self, f"Failed to establish a new connection: {error}" + ) + else: + raise NewConnectionError( + self, f"Failed to establish a new connection: {e}" + ) from e + + except OSError as e: # Defensive: PySocks should catch all these. + raise NewConnectionError( + self, f"Failed to establish a new connection: {e}" + ) from e + + return conn + + +# We don't need to duplicate the Verified/Unverified distinction from +# urllib3/connection.py here because the HTTPSConnection will already have been +# correctly set to either the Verified or Unverified form by that module. This +# means the SOCKSHTTPSConnection will automatically be the correct type. +class SOCKSHTTPSConnection(SOCKSConnection, HTTPSConnection): + pass + + +class SOCKSHTTPConnectionPool(HTTPConnectionPool): + ConnectionCls = SOCKSConnection + + +class SOCKSHTTPSConnectionPool(HTTPSConnectionPool): + ConnectionCls = SOCKSHTTPSConnection + + +class SOCKSProxyManager(PoolManager): + """ + A version of the urllib3 ProxyManager that routes connections via the + defined SOCKS proxy. + """ + + pool_classes_by_scheme = { + "http": SOCKSHTTPConnectionPool, + "https": SOCKSHTTPSConnectionPool, + } + + def __init__( + self, + proxy_url: str, + username: str | None = None, + password: str | None = None, + num_pools: int = 10, + headers: typing.Mapping[str, str] | None = None, + **connection_pool_kw: typing.Any, + ): + parsed = parse_url(proxy_url) + + if username is None and password is None and parsed.auth is not None: + split = parsed.auth.split(":") + if len(split) == 2: + username, password = split + if parsed.scheme == "socks5": + socks_version = socks.PROXY_TYPE_SOCKS5 + rdns = False + elif parsed.scheme == "socks5h": + socks_version = socks.PROXY_TYPE_SOCKS5 + rdns = True + elif parsed.scheme == "socks4": + socks_version = socks.PROXY_TYPE_SOCKS4 + rdns = False + elif parsed.scheme == "socks4a": + socks_version = socks.PROXY_TYPE_SOCKS4 + rdns = True + else: + raise ValueError(f"Unable to determine SOCKS version from {proxy_url}") + + self.proxy_url = proxy_url + + socks_options = { + "socks_version": socks_version, + "proxy_host": parsed.host, + "proxy_port": parsed.port, + "username": username, + "password": password, + "rdns": rdns, + } + connection_pool_kw["_socks_options"] = socks_options + + super().__init__(num_pools, headers, **connection_pool_kw) + + self.pool_classes_by_scheme = SOCKSProxyManager.pool_classes_by_scheme diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/exceptions.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/exceptions.py new file mode 100644 index 0000000..b0792f0 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/exceptions.py @@ -0,0 +1,321 @@ +from __future__ import annotations + +import socket +import typing +import warnings +from email.errors import MessageDefect +from http.client import IncompleteRead as httplib_IncompleteRead + +if typing.TYPE_CHECKING: + from .connection import HTTPConnection + from .connectionpool import ConnectionPool + from .response import HTTPResponse + from .util.retry import Retry + +# Base Exceptions + + +class HTTPError(Exception): + """Base exception used by this module.""" + + +class HTTPWarning(Warning): + """Base warning used by this module.""" + + +_TYPE_REDUCE_RESULT = typing.Tuple[ + typing.Callable[..., object], typing.Tuple[object, ...] +] + + +class PoolError(HTTPError): + """Base exception for errors caused within a pool.""" + + def __init__(self, pool: ConnectionPool, message: str) -> None: + self.pool = pool + super().__init__(f"{pool}: {message}") + + def __reduce__(self) -> _TYPE_REDUCE_RESULT: + # For pickling purposes. + return self.__class__, (None, None) + + +class RequestError(PoolError): + """Base exception for PoolErrors that have associated URLs.""" + + def __init__(self, pool: ConnectionPool, url: str, message: str) -> None: + self.url = url + super().__init__(pool, message) + + def __reduce__(self) -> _TYPE_REDUCE_RESULT: + # For pickling purposes. + return self.__class__, (None, self.url, None) + + +class SSLError(HTTPError): + """Raised when SSL certificate fails in an HTTPS connection.""" + + +class ProxyError(HTTPError): + """Raised when the connection to a proxy fails.""" + + # The original error is also available as __cause__. + original_error: Exception + + def __init__(self, message: str, error: Exception) -> None: + super().__init__(message, error) + self.original_error = error + + +class DecodeError(HTTPError): + """Raised when automatic decoding based on Content-Type fails.""" + + +class ProtocolError(HTTPError): + """Raised when something unexpected happens mid-request/response.""" + + +#: Renamed to ProtocolError but aliased for backwards compatibility. +ConnectionError = ProtocolError + + +# Leaf Exceptions + + +class MaxRetryError(RequestError): + """Raised when the maximum number of retries is exceeded. + + :param pool: The connection pool + :type pool: :class:`~urllib3.connectionpool.HTTPConnectionPool` + :param str url: The requested Url + :param reason: The underlying error + :type reason: :class:`Exception` + + """ + + def __init__( + self, pool: ConnectionPool, url: str, reason: Exception | None = None + ) -> None: + self.reason = reason + + message = f"Max retries exceeded with url: {url} (Caused by {reason!r})" + + super().__init__(pool, url, message) + + +class HostChangedError(RequestError): + """Raised when an existing pool gets a request for a foreign host.""" + + def __init__( + self, pool: ConnectionPool, url: str, retries: Retry | int = 3 + ) -> None: + message = f"Tried to open a foreign host with url: {url}" + super().__init__(pool, url, message) + self.retries = retries + + +class TimeoutStateError(HTTPError): + """Raised when passing an invalid state to a timeout""" + + +class TimeoutError(HTTPError): + """Raised when a socket timeout error occurs. + + Catching this error will catch both :exc:`ReadTimeoutErrors + ` and :exc:`ConnectTimeoutErrors `. + """ + + +class ReadTimeoutError(TimeoutError, RequestError): + """Raised when a socket timeout occurs while receiving data from a server""" + + +# This timeout error does not have a URL attached and needs to inherit from the +# base HTTPError +class ConnectTimeoutError(TimeoutError): + """Raised when a socket timeout occurs while connecting to a server""" + + +class NewConnectionError(ConnectTimeoutError, HTTPError): + """Raised when we fail to establish a new connection. Usually ECONNREFUSED.""" + + def __init__(self, conn: HTTPConnection, message: str) -> None: + self.conn = conn + super().__init__(f"{conn}: {message}") + + @property + def pool(self) -> HTTPConnection: + warnings.warn( + "The 'pool' property is deprecated and will be removed " + "in urllib3 v2.1.0. Use 'conn' instead.", + DeprecationWarning, + stacklevel=2, + ) + + return self.conn + + +class NameResolutionError(NewConnectionError): + """Raised when host name resolution fails.""" + + def __init__(self, host: str, conn: HTTPConnection, reason: socket.gaierror): + message = f"Failed to resolve '{host}' ({reason})" + super().__init__(conn, message) + + +class EmptyPoolError(PoolError): + """Raised when a pool runs out of connections and no more are allowed.""" + + +class FullPoolError(PoolError): + """Raised when we try to add a connection to a full pool in blocking mode.""" + + +class ClosedPoolError(PoolError): + """Raised when a request enters a pool after the pool has been closed.""" + + +class LocationValueError(ValueError, HTTPError): + """Raised when there is something wrong with a given URL input.""" + + +class LocationParseError(LocationValueError): + """Raised when get_host or similar fails to parse the URL input.""" + + def __init__(self, location: str) -> None: + message = f"Failed to parse: {location}" + super().__init__(message) + + self.location = location + + +class URLSchemeUnknown(LocationValueError): + """Raised when a URL input has an unsupported scheme.""" + + def __init__(self, scheme: str): + message = f"Not supported URL scheme {scheme}" + super().__init__(message) + + self.scheme = scheme + + +class ResponseError(HTTPError): + """Used as a container for an error reason supplied in a MaxRetryError.""" + + GENERIC_ERROR = "too many error responses" + SPECIFIC_ERROR = "too many {status_code} error responses" + + +class SecurityWarning(HTTPWarning): + """Warned when performing security reducing actions""" + + +class InsecureRequestWarning(SecurityWarning): + """Warned when making an unverified HTTPS request.""" + + +class NotOpenSSLWarning(SecurityWarning): + """Warned when using unsupported SSL library""" + + +class SystemTimeWarning(SecurityWarning): + """Warned when system time is suspected to be wrong""" + + +class InsecurePlatformWarning(SecurityWarning): + """Warned when certain TLS/SSL configuration is not available on a platform.""" + + +class DependencyWarning(HTTPWarning): + """ + Warned when an attempt is made to import a module with missing optional + dependencies. + """ + + +class ResponseNotChunked(ProtocolError, ValueError): + """Response needs to be chunked in order to read it as chunks.""" + + +class BodyNotHttplibCompatible(HTTPError): + """ + Body should be :class:`http.client.HTTPResponse` like + (have an fp attribute which returns raw chunks) for read_chunked(). + """ + + +class IncompleteRead(HTTPError, httplib_IncompleteRead): + """ + Response length doesn't match expected Content-Length + + Subclass of :class:`http.client.IncompleteRead` to allow int value + for ``partial`` to avoid creating large objects on streamed reads. + """ + + partial: int # type: ignore[assignment] + expected: int + + def __init__(self, partial: int, expected: int) -> None: + self.partial = partial + self.expected = expected + + def __repr__(self) -> str: + return "IncompleteRead(%i bytes read, %i more expected)" % ( + self.partial, + self.expected, + ) + + +class InvalidChunkLength(HTTPError, httplib_IncompleteRead): + """Invalid chunk length in a chunked response.""" + + def __init__(self, response: HTTPResponse, length: bytes) -> None: + self.partial: int = response.tell() # type: ignore[assignment] + self.expected: int | None = response.length_remaining + self.response = response + self.length = length + + def __repr__(self) -> str: + return "InvalidChunkLength(got length %r, %i bytes read)" % ( + self.length, + self.partial, + ) + + +class InvalidHeader(HTTPError): + """The header provided was somehow invalid.""" + + +class ProxySchemeUnknown(AssertionError, URLSchemeUnknown): + """ProxyManager does not support the supplied scheme""" + + # TODO(t-8ch): Stop inheriting from AssertionError in v2.0. + + def __init__(self, scheme: str | None) -> None: + # 'localhost' is here because our URL parser parses + # localhost:8080 -> scheme=localhost, remove if we fix this. + if scheme == "localhost": + scheme = None + if scheme is None: + message = "Proxy URL had no scheme, should start with http:// or https://" + else: + message = f"Proxy URL had unsupported scheme {scheme}, should use http:// or https://" + super().__init__(message) + + +class ProxySchemeUnsupported(ValueError): + """Fetching HTTPS resources through HTTPS proxies is unsupported""" + + +class HeaderParsingError(HTTPError): + """Raised by assert_header_parsing, but we convert it to a log.warning statement.""" + + def __init__( + self, defects: list[MessageDefect], unparsed_data: bytes | str | None + ) -> None: + message = f"{defects or 'Unknown'}, unparsed data: {unparsed_data!r}" + super().__init__(message) + + +class UnrewindableBodyError(HTTPError): + """urllib3 encountered an error when trying to rewind a body""" diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/fields.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/fields.py new file mode 100644 index 0000000..3e258a5 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/fields.py @@ -0,0 +1,341 @@ +from __future__ import annotations + +import email.utils +import mimetypes +import typing + +_TYPE_FIELD_VALUE = typing.Union[str, bytes] +_TYPE_FIELD_VALUE_TUPLE = typing.Union[ + _TYPE_FIELD_VALUE, + typing.Tuple[str, _TYPE_FIELD_VALUE], + typing.Tuple[str, _TYPE_FIELD_VALUE, str], +] + + +def guess_content_type( + filename: str | None, default: str = "application/octet-stream" +) -> str: + """ + Guess the "Content-Type" of a file. + + :param filename: + The filename to guess the "Content-Type" of using :mod:`mimetypes`. + :param default: + If no "Content-Type" can be guessed, default to `default`. + """ + if filename: + return mimetypes.guess_type(filename)[0] or default + return default + + +def format_header_param_rfc2231(name: str, value: _TYPE_FIELD_VALUE) -> str: + """ + Helper function to format and quote a single header parameter using the + strategy defined in RFC 2231. + + Particularly useful for header parameters which might contain + non-ASCII values, like file names. This follows + `RFC 2388 Section 4.4 `_. + + :param name: + The name of the parameter, a string expected to be ASCII only. + :param value: + The value of the parameter, provided as ``bytes`` or `str``. + :returns: + An RFC-2231-formatted unicode string. + + .. deprecated:: 2.0.0 + Will be removed in urllib3 v2.1.0. This is not valid for + ``multipart/form-data`` header parameters. + """ + import warnings + + warnings.warn( + "'format_header_param_rfc2231' is deprecated and will be " + "removed in urllib3 v2.1.0. This is not valid for " + "multipart/form-data header parameters.", + DeprecationWarning, + stacklevel=2, + ) + + if isinstance(value, bytes): + value = value.decode("utf-8") + + if not any(ch in value for ch in '"\\\r\n'): + result = f'{name}="{value}"' + try: + result.encode("ascii") + except (UnicodeEncodeError, UnicodeDecodeError): + pass + else: + return result + + value = email.utils.encode_rfc2231(value, "utf-8") + value = f"{name}*={value}" + + return value + + +def format_multipart_header_param(name: str, value: _TYPE_FIELD_VALUE) -> str: + """ + Format and quote a single multipart header parameter. + + This follows the `WHATWG HTML Standard`_ as of 2021/06/10, matching + the behavior of current browser and curl versions. Values are + assumed to be UTF-8. The ``\\n``, ``\\r``, and ``"`` characters are + percent encoded. + + .. _WHATWG HTML Standard: + https://html.spec.whatwg.org/multipage/ + form-control-infrastructure.html#multipart-form-data + + :param name: + The name of the parameter, an ASCII-only ``str``. + :param value: + The value of the parameter, a ``str`` or UTF-8 encoded + ``bytes``. + :returns: + A string ``name="value"`` with the escaped value. + + .. versionchanged:: 2.0.0 + Matches the WHATWG HTML Standard as of 2021/06/10. Control + characters are no longer percent encoded. + + .. versionchanged:: 2.0.0 + Renamed from ``format_header_param_html5`` and + ``format_header_param``. The old names will be removed in + urllib3 v2.1.0. + """ + if isinstance(value, bytes): + value = value.decode("utf-8") + + # percent encode \n \r " + value = value.translate({10: "%0A", 13: "%0D", 34: "%22"}) + return f'{name}="{value}"' + + +def format_header_param_html5(name: str, value: _TYPE_FIELD_VALUE) -> str: + """ + .. deprecated:: 2.0.0 + Renamed to :func:`format_multipart_header_param`. Will be + removed in urllib3 v2.1.0. + """ + import warnings + + warnings.warn( + "'format_header_param_html5' has been renamed to " + "'format_multipart_header_param'. The old name will be " + "removed in urllib3 v2.1.0.", + DeprecationWarning, + stacklevel=2, + ) + return format_multipart_header_param(name, value) + + +def format_header_param(name: str, value: _TYPE_FIELD_VALUE) -> str: + """ + .. deprecated:: 2.0.0 + Renamed to :func:`format_multipart_header_param`. Will be + removed in urllib3 v2.1.0. + """ + import warnings + + warnings.warn( + "'format_header_param' has been renamed to " + "'format_multipart_header_param'. The old name will be " + "removed in urllib3 v2.1.0.", + DeprecationWarning, + stacklevel=2, + ) + return format_multipart_header_param(name, value) + + +class RequestField: + """ + A data container for request body parameters. + + :param name: + The name of this request field. Must be unicode. + :param data: + The data/value body. + :param filename: + An optional filename of the request field. Must be unicode. + :param headers: + An optional dict-like object of headers to initially use for the field. + + .. versionchanged:: 2.0.0 + The ``header_formatter`` parameter is deprecated and will + be removed in urllib3 v2.1.0. + """ + + def __init__( + self, + name: str, + data: _TYPE_FIELD_VALUE, + filename: str | None = None, + headers: typing.Mapping[str, str] | None = None, + header_formatter: typing.Callable[[str, _TYPE_FIELD_VALUE], str] | None = None, + ): + self._name = name + self._filename = filename + self.data = data + self.headers: dict[str, str | None] = {} + if headers: + self.headers = dict(headers) + + if header_formatter is not None: + import warnings + + warnings.warn( + "The 'header_formatter' parameter is deprecated and " + "will be removed in urllib3 v2.1.0.", + DeprecationWarning, + stacklevel=2, + ) + self.header_formatter = header_formatter + else: + self.header_formatter = format_multipart_header_param + + @classmethod + def from_tuples( + cls, + fieldname: str, + value: _TYPE_FIELD_VALUE_TUPLE, + header_formatter: typing.Callable[[str, _TYPE_FIELD_VALUE], str] | None = None, + ) -> RequestField: + """ + A :class:`~urllib3.fields.RequestField` factory from old-style tuple parameters. + + Supports constructing :class:`~urllib3.fields.RequestField` from + parameter of key/value strings AND key/filetuple. A filetuple is a + (filename, data, MIME type) tuple where the MIME type is optional. + For example:: + + 'foo': 'bar', + 'fakefile': ('foofile.txt', 'contents of foofile'), + 'realfile': ('barfile.txt', open('realfile').read()), + 'typedfile': ('bazfile.bin', open('bazfile').read(), 'image/jpeg'), + 'nonamefile': 'contents of nonamefile field', + + Field names and filenames must be unicode. + """ + filename: str | None + content_type: str | None + data: _TYPE_FIELD_VALUE + + if isinstance(value, tuple): + if len(value) == 3: + filename, data, content_type = value + else: + filename, data = value + content_type = guess_content_type(filename) + else: + filename = None + content_type = None + data = value + + request_param = cls( + fieldname, data, filename=filename, header_formatter=header_formatter + ) + request_param.make_multipart(content_type=content_type) + + return request_param + + def _render_part(self, name: str, value: _TYPE_FIELD_VALUE) -> str: + """ + Override this method to change how each multipart header + parameter is formatted. By default, this calls + :func:`format_multipart_header_param`. + + :param name: + The name of the parameter, an ASCII-only ``str``. + :param value: + The value of the parameter, a ``str`` or UTF-8 encoded + ``bytes``. + + :meta public: + """ + return self.header_formatter(name, value) + + def _render_parts( + self, + header_parts: ( + dict[str, _TYPE_FIELD_VALUE | None] + | typing.Sequence[tuple[str, _TYPE_FIELD_VALUE | None]] + ), + ) -> str: + """ + Helper function to format and quote a single header. + + Useful for single headers that are composed of multiple items. E.g., + 'Content-Disposition' fields. + + :param header_parts: + A sequence of (k, v) tuples or a :class:`dict` of (k, v) to format + as `k1="v1"; k2="v2"; ...`. + """ + iterable: typing.Iterable[tuple[str, _TYPE_FIELD_VALUE | None]] + + parts = [] + if isinstance(header_parts, dict): + iterable = header_parts.items() + else: + iterable = header_parts + + for name, value in iterable: + if value is not None: + parts.append(self._render_part(name, value)) + + return "; ".join(parts) + + def render_headers(self) -> str: + """ + Renders the headers for this request field. + """ + lines = [] + + sort_keys = ["Content-Disposition", "Content-Type", "Content-Location"] + for sort_key in sort_keys: + if self.headers.get(sort_key, False): + lines.append(f"{sort_key}: {self.headers[sort_key]}") + + for header_name, header_value in self.headers.items(): + if header_name not in sort_keys: + if header_value: + lines.append(f"{header_name}: {header_value}") + + lines.append("\r\n") + return "\r\n".join(lines) + + def make_multipart( + self, + content_disposition: str | None = None, + content_type: str | None = None, + content_location: str | None = None, + ) -> None: + """ + Makes this request field into a multipart request field. + + This method overrides "Content-Disposition", "Content-Type" and + "Content-Location" headers to the request parameter. + + :param content_disposition: + The 'Content-Disposition' of the request body. Defaults to 'form-data' + :param content_type: + The 'Content-Type' of the request body. + :param content_location: + The 'Content-Location' of the request body. + + """ + content_disposition = (content_disposition or "form-data") + "; ".join( + [ + "", + self._render_parts( + (("name", self._name), ("filename", self._filename)) + ), + ] + ) + + self.headers["Content-Disposition"] = content_disposition + self.headers["Content-Type"] = content_type + self.headers["Content-Location"] = content_location diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/filepost.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/filepost.py new file mode 100644 index 0000000..1c90a21 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/filepost.py @@ -0,0 +1,89 @@ +from __future__ import annotations + +import binascii +import codecs +import os +import typing +from io import BytesIO + +from .fields import _TYPE_FIELD_VALUE_TUPLE, RequestField + +writer = codecs.lookup("utf-8")[3] + +_TYPE_FIELDS_SEQUENCE = typing.Sequence[ + typing.Union[typing.Tuple[str, _TYPE_FIELD_VALUE_TUPLE], RequestField] +] +_TYPE_FIELDS = typing.Union[ + _TYPE_FIELDS_SEQUENCE, + typing.Mapping[str, _TYPE_FIELD_VALUE_TUPLE], +] + + +def choose_boundary() -> str: + """ + Our embarrassingly-simple replacement for mimetools.choose_boundary. + """ + return binascii.hexlify(os.urandom(16)).decode() + + +def iter_field_objects(fields: _TYPE_FIELDS) -> typing.Iterable[RequestField]: + """ + Iterate over fields. + + Supports list of (k, v) tuples and dicts, and lists of + :class:`~urllib3.fields.RequestField`. + + """ + iterable: typing.Iterable[RequestField | tuple[str, _TYPE_FIELD_VALUE_TUPLE]] + + if isinstance(fields, typing.Mapping): + iterable = fields.items() + else: + iterable = fields + + for field in iterable: + if isinstance(field, RequestField): + yield field + else: + yield RequestField.from_tuples(*field) + + +def encode_multipart_formdata( + fields: _TYPE_FIELDS, boundary: str | None = None +) -> tuple[bytes, str]: + """ + Encode a dictionary of ``fields`` using the multipart/form-data MIME format. + + :param fields: + Dictionary of fields or list of (key, :class:`~urllib3.fields.RequestField`). + Values are processed by :func:`urllib3.fields.RequestField.from_tuples`. + + :param boundary: + If not specified, then a random boundary will be generated using + :func:`urllib3.filepost.choose_boundary`. + """ + body = BytesIO() + if boundary is None: + boundary = choose_boundary() + + for field in iter_field_objects(fields): + body.write(f"--{boundary}\r\n".encode("latin-1")) + + writer(body).write(field.render_headers()) + data = field.data + + if isinstance(data, int): + data = str(data) # Backwards compatibility + + if isinstance(data, str): + writer(body).write(data) + else: + body.write(data) + + body.write(b"\r\n") + + body.write(f"--{boundary}--\r\n".encode("latin-1")) + + content_type = f"multipart/form-data; boundary={boundary}" + + return body.getvalue(), content_type diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/http2.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/http2.py new file mode 100644 index 0000000..ceb4060 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/http2.py @@ -0,0 +1,230 @@ +from __future__ import annotations + +import threading +import types +import typing + +import h2.config # type: ignore[import-untyped] +import h2.connection # type: ignore[import-untyped] +import h2.events # type: ignore[import-untyped] + +import urllib3.connection +import urllib3.util.ssl_ +from urllib3.response import BaseHTTPResponse + +from ._collections import HTTPHeaderDict +from .connection import HTTPSConnection +from .connectionpool import HTTPSConnectionPool + +orig_HTTPSConnection = HTTPSConnection + +T = typing.TypeVar("T") + + +class _LockedObject(typing.Generic[T]): + """ + A wrapper class that hides a specific object behind a lock. + + The goal here is to provide a simple way to protect access to an object + that cannot safely be simultaneously accessed from multiple threads. The + intended use of this class is simple: take hold of it with a context + manager, which returns the protected object. + """ + + def __init__(self, obj: T): + self.lock = threading.RLock() + self._obj = obj + + def __enter__(self) -> T: + self.lock.acquire() + return self._obj + + def __exit__( + self, + exc_type: type[BaseException] | None, + exc_val: BaseException | None, + exc_tb: types.TracebackType | None, + ) -> None: + self.lock.release() + + +class HTTP2Connection(HTTPSConnection): + def __init__( + self, host: str, port: int | None = None, **kwargs: typing.Any + ) -> None: + self._h2_conn = self._new_h2_conn() + self._h2_stream: int | None = None + self._h2_headers: list[tuple[bytes, bytes]] = [] + + if "proxy" in kwargs or "proxy_config" in kwargs: # Defensive: + raise NotImplementedError("Proxies aren't supported with HTTP/2") + + super().__init__(host, port, **kwargs) + + def _new_h2_conn(self) -> _LockedObject[h2.connection.H2Connection]: + config = h2.config.H2Configuration(client_side=True) + return _LockedObject(h2.connection.H2Connection(config=config)) + + def connect(self) -> None: + super().connect() + + with self._h2_conn as h2_conn: + h2_conn.initiate_connection() + self.sock.sendall(h2_conn.data_to_send()) + + def putrequest( + self, + method: str, + url: str, + skip_host: bool = False, + skip_accept_encoding: bool = False, + ) -> None: + with self._h2_conn as h2_conn: + self._request_url = url + self._h2_stream = h2_conn.get_next_available_stream_id() + + if ":" in self.host: + authority = f"[{self.host}]:{self.port or 443}" + else: + authority = f"{self.host}:{self.port or 443}" + + self._h2_headers.extend( + ( + (b":scheme", b"https"), + (b":method", method.encode()), + (b":authority", authority.encode()), + (b":path", url.encode()), + ) + ) + + def putheader(self, header: str, *values: str) -> None: # type: ignore[override] + for value in values: + self._h2_headers.append( + (header.encode("utf-8").lower(), value.encode("utf-8")) + ) + + def endheaders(self) -> None: # type: ignore[override] + with self._h2_conn as h2_conn: + h2_conn.send_headers( + stream_id=self._h2_stream, + headers=self._h2_headers, + end_stream=True, + ) + if data_to_send := h2_conn.data_to_send(): + self.sock.sendall(data_to_send) + + def send(self, data: bytes) -> None: # type: ignore[override] # Defensive: + if not data: + return + raise NotImplementedError("Sending data isn't supported yet") + + def getresponse( # type: ignore[override] + self, + ) -> HTTP2Response: + status = None + data = bytearray() + with self._h2_conn as h2_conn: + end_stream = False + while not end_stream: + # TODO: Arbitrary read value. + if received_data := self.sock.recv(65535): + events = h2_conn.receive_data(received_data) + for event in events: + if isinstance(event, h2.events.ResponseReceived): + headers = HTTPHeaderDict() + for header, value in event.headers: + if header == b":status": + status = int(value.decode()) + else: + headers.add( + header.decode("ascii"), value.decode("ascii") + ) + + elif isinstance(event, h2.events.DataReceived): + data += event.data + h2_conn.acknowledge_received_data( + event.flow_controlled_length, event.stream_id + ) + + elif isinstance(event, h2.events.StreamEnded): + end_stream = True + + if data_to_send := h2_conn.data_to_send(): + self.sock.sendall(data_to_send) + + # We always close to not have to handle connection management. + self.close() + + assert status is not None + return HTTP2Response( + status=status, + headers=headers, + request_url=self._request_url, + data=bytes(data), + ) + + def close(self) -> None: + with self._h2_conn as h2_conn: + try: + h2_conn.close_connection() + if data := h2_conn.data_to_send(): + self.sock.sendall(data) + except Exception: + pass + + # Reset all our HTTP/2 connection state. + self._h2_conn = self._new_h2_conn() + self._h2_stream = None + self._h2_headers = [] + + super().close() + + +class HTTP2Response(BaseHTTPResponse): + # TODO: This is a woefully incomplete response object, but works for non-streaming. + def __init__( + self, + status: int, + headers: HTTPHeaderDict, + request_url: str, + data: bytes, + decode_content: bool = False, # TODO: support decoding + ) -> None: + super().__init__( + status=status, + headers=headers, + # Following CPython, we map HTTP versions to major * 10 + minor integers + version=20, + version_string="HTTP/2", + # No reason phrase in HTTP/2 + reason=None, + decode_content=decode_content, + request_url=request_url, + ) + self._data = data + self.length_remaining = 0 + + @property + def data(self) -> bytes: + return self._data + + def get_redirect_location(self) -> None: + return None + + def close(self) -> None: + pass + + +def inject_into_urllib3() -> None: + HTTPSConnectionPool.ConnectionCls = HTTP2Connection + urllib3.connection.HTTPSConnection = HTTP2Connection # type: ignore[misc] + + # TODO: Offer 'http/1.1' as well, but for testing purposes this is handy. + urllib3.util.ssl_.ALPN_PROTOCOLS = ["h2"] + + +def extract_from_urllib3() -> None: + HTTPSConnectionPool.ConnectionCls = orig_HTTPSConnection + urllib3.connection.HTTPSConnection = orig_HTTPSConnection # type: ignore[misc] + + urllib3.util.ssl_.ALPN_PROTOCOLS = ["http/1.1"] diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/poolmanager.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/poolmanager.py new file mode 100644 index 0000000..085d1db --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/poolmanager.py @@ -0,0 +1,637 @@ +from __future__ import annotations + +import functools +import logging +import typing +import warnings +from types import TracebackType +from urllib.parse import urljoin + +from ._collections import HTTPHeaderDict, RecentlyUsedContainer +from ._request_methods import RequestMethods +from .connection import ProxyConfig +from .connectionpool import HTTPConnectionPool, HTTPSConnectionPool, port_by_scheme +from .exceptions import ( + LocationValueError, + MaxRetryError, + ProxySchemeUnknown, + URLSchemeUnknown, +) +from .response import BaseHTTPResponse +from .util.connection import _TYPE_SOCKET_OPTIONS +from .util.proxy import connection_requires_http_tunnel +from .util.retry import Retry +from .util.timeout import Timeout +from .util.url import Url, parse_url + +if typing.TYPE_CHECKING: + import ssl + + from typing_extensions import Self + +__all__ = ["PoolManager", "ProxyManager", "proxy_from_url"] + + +log = logging.getLogger(__name__) + +SSL_KEYWORDS = ( + "key_file", + "cert_file", + "cert_reqs", + "ca_certs", + "ca_cert_data", + "ssl_version", + "ssl_minimum_version", + "ssl_maximum_version", + "ca_cert_dir", + "ssl_context", + "key_password", + "server_hostname", +) +# Default value for `blocksize` - a new parameter introduced to +# http.client.HTTPConnection & http.client.HTTPSConnection in Python 3.7 +_DEFAULT_BLOCKSIZE = 16384 + + +class PoolKey(typing.NamedTuple): + """ + All known keyword arguments that could be provided to the pool manager, its + pools, or the underlying connections. + + All custom key schemes should include the fields in this key at a minimum. + """ + + key_scheme: str + key_host: str + key_port: int | None + key_timeout: Timeout | float | int | None + key_retries: Retry | bool | int | None + key_block: bool | None + key_source_address: tuple[str, int] | None + key_key_file: str | None + key_key_password: str | None + key_cert_file: str | None + key_cert_reqs: str | None + key_ca_certs: str | None + key_ca_cert_data: str | bytes | None + key_ssl_version: int | str | None + key_ssl_minimum_version: ssl.TLSVersion | None + key_ssl_maximum_version: ssl.TLSVersion | None + key_ca_cert_dir: str | None + key_ssl_context: ssl.SSLContext | None + key_maxsize: int | None + key_headers: frozenset[tuple[str, str]] | None + key__proxy: Url | None + key__proxy_headers: frozenset[tuple[str, str]] | None + key__proxy_config: ProxyConfig | None + key_socket_options: _TYPE_SOCKET_OPTIONS | None + key__socks_options: frozenset[tuple[str, str]] | None + key_assert_hostname: bool | str | None + key_assert_fingerprint: str | None + key_server_hostname: str | None + key_blocksize: int | None + + +def _default_key_normalizer( + key_class: type[PoolKey], request_context: dict[str, typing.Any] +) -> PoolKey: + """ + Create a pool key out of a request context dictionary. + + According to RFC 3986, both the scheme and host are case-insensitive. + Therefore, this function normalizes both before constructing the pool + key for an HTTPS request. If you wish to change this behaviour, provide + alternate callables to ``key_fn_by_scheme``. + + :param key_class: + The class to use when constructing the key. This should be a namedtuple + with the ``scheme`` and ``host`` keys at a minimum. + :type key_class: namedtuple + :param request_context: + A dictionary-like object that contain the context for a request. + :type request_context: dict + + :return: A namedtuple that can be used as a connection pool key. + :rtype: PoolKey + """ + # Since we mutate the dictionary, make a copy first + context = request_context.copy() + context["scheme"] = context["scheme"].lower() + context["host"] = context["host"].lower() + + # These are both dictionaries and need to be transformed into frozensets + for key in ("headers", "_proxy_headers", "_socks_options"): + if key in context and context[key] is not None: + context[key] = frozenset(context[key].items()) + + # The socket_options key may be a list and needs to be transformed into a + # tuple. + socket_opts = context.get("socket_options") + if socket_opts is not None: + context["socket_options"] = tuple(socket_opts) + + # Map the kwargs to the names in the namedtuple - this is necessary since + # namedtuples can't have fields starting with '_'. + for key in list(context.keys()): + context["key_" + key] = context.pop(key) + + # Default to ``None`` for keys missing from the context + for field in key_class._fields: + if field not in context: + context[field] = None + + # Default key_blocksize to _DEFAULT_BLOCKSIZE if missing from the context + if context.get("key_blocksize") is None: + context["key_blocksize"] = _DEFAULT_BLOCKSIZE + + return key_class(**context) + + +#: A dictionary that maps a scheme to a callable that creates a pool key. +#: This can be used to alter the way pool keys are constructed, if desired. +#: Each PoolManager makes a copy of this dictionary so they can be configured +#: globally here, or individually on the instance. +key_fn_by_scheme = { + "http": functools.partial(_default_key_normalizer, PoolKey), + "https": functools.partial(_default_key_normalizer, PoolKey), +} + +pool_classes_by_scheme = {"http": HTTPConnectionPool, "https": HTTPSConnectionPool} + + +class PoolManager(RequestMethods): + """ + Allows for arbitrary requests while transparently keeping track of + necessary connection pools for you. + + :param num_pools: + Number of connection pools to cache before discarding the least + recently used pool. + + :param headers: + Headers to include with all requests, unless other headers are given + explicitly. + + :param \\**connection_pool_kw: + Additional parameters are used to create fresh + :class:`urllib3.connectionpool.ConnectionPool` instances. + + Example: + + .. code-block:: python + + import urllib3 + + http = urllib3.PoolManager(num_pools=2) + + resp1 = http.request("GET", "https://google.com/") + resp2 = http.request("GET", "https://google.com/mail") + resp3 = http.request("GET", "https://yahoo.com/") + + print(len(http.pools)) + # 2 + + """ + + proxy: Url | None = None + proxy_config: ProxyConfig | None = None + + def __init__( + self, + num_pools: int = 10, + headers: typing.Mapping[str, str] | None = None, + **connection_pool_kw: typing.Any, + ) -> None: + super().__init__(headers) + self.connection_pool_kw = connection_pool_kw + + self.pools: RecentlyUsedContainer[PoolKey, HTTPConnectionPool] + self.pools = RecentlyUsedContainer(num_pools) + + # Locally set the pool classes and keys so other PoolManagers can + # override them. + self.pool_classes_by_scheme = pool_classes_by_scheme + self.key_fn_by_scheme = key_fn_by_scheme.copy() + + def __enter__(self) -> Self: + return self + + def __exit__( + self, + exc_type: type[BaseException] | None, + exc_val: BaseException | None, + exc_tb: TracebackType | None, + ) -> typing.Literal[False]: + self.clear() + # Return False to re-raise any potential exceptions + return False + + def _new_pool( + self, + scheme: str, + host: str, + port: int, + request_context: dict[str, typing.Any] | None = None, + ) -> HTTPConnectionPool: + """ + Create a new :class:`urllib3.connectionpool.ConnectionPool` based on host, port, scheme, and + any additional pool keyword arguments. + + If ``request_context`` is provided, it is provided as keyword arguments + to the pool class used. This method is used to actually create the + connection pools handed out by :meth:`connection_from_url` and + companion methods. It is intended to be overridden for customization. + """ + pool_cls: type[HTTPConnectionPool] = self.pool_classes_by_scheme[scheme] + if request_context is None: + request_context = self.connection_pool_kw.copy() + + # Default blocksize to _DEFAULT_BLOCKSIZE if missing or explicitly + # set to 'None' in the request_context. + if request_context.get("blocksize") is None: + request_context["blocksize"] = _DEFAULT_BLOCKSIZE + + # Although the context has everything necessary to create the pool, + # this function has historically only used the scheme, host, and port + # in the positional args. When an API change is acceptable these can + # be removed. + for key in ("scheme", "host", "port"): + request_context.pop(key, None) + + if scheme == "http": + for kw in SSL_KEYWORDS: + request_context.pop(kw, None) + + return pool_cls(host, port, **request_context) + + def clear(self) -> None: + """ + Empty our store of pools and direct them all to close. + + This will not affect in-flight connections, but they will not be + re-used after completion. + """ + self.pools.clear() + + def connection_from_host( + self, + host: str | None, + port: int | None = None, + scheme: str | None = "http", + pool_kwargs: dict[str, typing.Any] | None = None, + ) -> HTTPConnectionPool: + """ + Get a :class:`urllib3.connectionpool.ConnectionPool` based on the host, port, and scheme. + + If ``port`` isn't given, it will be derived from the ``scheme`` using + ``urllib3.connectionpool.port_by_scheme``. If ``pool_kwargs`` is + provided, it is merged with the instance's ``connection_pool_kw`` + variable and used to create the new connection pool, if one is + needed. + """ + + if not host: + raise LocationValueError("No host specified.") + + request_context = self._merge_pool_kwargs(pool_kwargs) + request_context["scheme"] = scheme or "http" + if not port: + port = port_by_scheme.get(request_context["scheme"].lower(), 80) + request_context["port"] = port + request_context["host"] = host + + return self.connection_from_context(request_context) + + def connection_from_context( + self, request_context: dict[str, typing.Any] + ) -> HTTPConnectionPool: + """ + Get a :class:`urllib3.connectionpool.ConnectionPool` based on the request context. + + ``request_context`` must at least contain the ``scheme`` key and its + value must be a key in ``key_fn_by_scheme`` instance variable. + """ + if "strict" in request_context: + warnings.warn( + "The 'strict' parameter is no longer needed on Python 3+. " + "This will raise an error in urllib3 v2.1.0.", + DeprecationWarning, + ) + request_context.pop("strict") + + scheme = request_context["scheme"].lower() + pool_key_constructor = self.key_fn_by_scheme.get(scheme) + if not pool_key_constructor: + raise URLSchemeUnknown(scheme) + pool_key = pool_key_constructor(request_context) + + return self.connection_from_pool_key(pool_key, request_context=request_context) + + def connection_from_pool_key( + self, pool_key: PoolKey, request_context: dict[str, typing.Any] + ) -> HTTPConnectionPool: + """ + Get a :class:`urllib3.connectionpool.ConnectionPool` based on the provided pool key. + + ``pool_key`` should be a namedtuple that only contains immutable + objects. At a minimum it must have the ``scheme``, ``host``, and + ``port`` fields. + """ + with self.pools.lock: + # If the scheme, host, or port doesn't match existing open + # connections, open a new ConnectionPool. + pool = self.pools.get(pool_key) + if pool: + return pool + + # Make a fresh ConnectionPool of the desired type + scheme = request_context["scheme"] + host = request_context["host"] + port = request_context["port"] + pool = self._new_pool(scheme, host, port, request_context=request_context) + self.pools[pool_key] = pool + + return pool + + def connection_from_url( + self, url: str, pool_kwargs: dict[str, typing.Any] | None = None + ) -> HTTPConnectionPool: + """ + Similar to :func:`urllib3.connectionpool.connection_from_url`. + + If ``pool_kwargs`` is not provided and a new pool needs to be + constructed, ``self.connection_pool_kw`` is used to initialize + the :class:`urllib3.connectionpool.ConnectionPool`. If ``pool_kwargs`` + is provided, it is used instead. Note that if a new pool does not + need to be created for the request, the provided ``pool_kwargs`` are + not used. + """ + u = parse_url(url) + return self.connection_from_host( + u.host, port=u.port, scheme=u.scheme, pool_kwargs=pool_kwargs + ) + + def _merge_pool_kwargs( + self, override: dict[str, typing.Any] | None + ) -> dict[str, typing.Any]: + """ + Merge a dictionary of override values for self.connection_pool_kw. + + This does not modify self.connection_pool_kw and returns a new dict. + Any keys in the override dictionary with a value of ``None`` are + removed from the merged dictionary. + """ + base_pool_kwargs = self.connection_pool_kw.copy() + if override: + for key, value in override.items(): + if value is None: + try: + del base_pool_kwargs[key] + except KeyError: + pass + else: + base_pool_kwargs[key] = value + return base_pool_kwargs + + def _proxy_requires_url_absolute_form(self, parsed_url: Url) -> bool: + """ + Indicates if the proxy requires the complete destination URL in the + request. Normally this is only needed when not using an HTTP CONNECT + tunnel. + """ + if self.proxy is None: + return False + + return not connection_requires_http_tunnel( + self.proxy, self.proxy_config, parsed_url.scheme + ) + + def urlopen( # type: ignore[override] + self, method: str, url: str, redirect: bool = True, **kw: typing.Any + ) -> BaseHTTPResponse: + """ + Same as :meth:`urllib3.HTTPConnectionPool.urlopen` + with custom cross-host redirect logic and only sends the request-uri + portion of the ``url``. + + The given ``url`` parameter must be absolute, such that an appropriate + :class:`urllib3.connectionpool.ConnectionPool` can be chosen for it. + """ + u = parse_url(url) + + if u.scheme is None: + warnings.warn( + "URLs without a scheme (ie 'https://') are deprecated and will raise an error " + "in a future version of urllib3. To avoid this DeprecationWarning ensure all URLs " + "start with 'https://' or 'http://'. Read more in this issue: " + "https://github.com/urllib3/urllib3/issues/2920", + category=DeprecationWarning, + stacklevel=2, + ) + + conn = self.connection_from_host(u.host, port=u.port, scheme=u.scheme) + + kw["assert_same_host"] = False + kw["redirect"] = False + + if "headers" not in kw: + kw["headers"] = self.headers + + if self._proxy_requires_url_absolute_form(u): + response = conn.urlopen(method, url, **kw) + else: + response = conn.urlopen(method, u.request_uri, **kw) + + redirect_location = redirect and response.get_redirect_location() + if not redirect_location: + return response + + # Support relative URLs for redirecting. + redirect_location = urljoin(url, redirect_location) + + if response.status == 303: + # Change the method according to RFC 9110, Section 15.4.4. + method = "GET" + # And lose the body not to transfer anything sensitive. + kw["body"] = None + kw["headers"] = HTTPHeaderDict(kw["headers"])._prepare_for_method_change() + + retries = kw.get("retries") + if not isinstance(retries, Retry): + retries = Retry.from_int(retries, redirect=redirect) + + # Strip headers marked as unsafe to forward to the redirected location. + # Check remove_headers_on_redirect to avoid a potential network call within + # conn.is_same_host() which may use socket.gethostbyname() in the future. + if retries.remove_headers_on_redirect and not conn.is_same_host( + redirect_location + ): + new_headers = kw["headers"].copy() + for header in kw["headers"]: + if header.lower() in retries.remove_headers_on_redirect: + new_headers.pop(header, None) + kw["headers"] = new_headers + + try: + retries = retries.increment(method, url, response=response, _pool=conn) + except MaxRetryError: + if retries.raise_on_redirect: + response.drain_conn() + raise + return response + + kw["retries"] = retries + kw["redirect"] = redirect + + log.info("Redirecting %s -> %s", url, redirect_location) + + response.drain_conn() + return self.urlopen(method, redirect_location, **kw) + + +class ProxyManager(PoolManager): + """ + Behaves just like :class:`PoolManager`, but sends all requests through + the defined proxy, using the CONNECT method for HTTPS URLs. + + :param proxy_url: + The URL of the proxy to be used. + + :param proxy_headers: + A dictionary containing headers that will be sent to the proxy. In case + of HTTP they are being sent with each request, while in the + HTTPS/CONNECT case they are sent only once. Could be used for proxy + authentication. + + :param proxy_ssl_context: + The proxy SSL context is used to establish the TLS connection to the + proxy when using HTTPS proxies. + + :param use_forwarding_for_https: + (Defaults to False) If set to True will forward requests to the HTTPS + proxy to be made on behalf of the client instead of creating a TLS + tunnel via the CONNECT method. **Enabling this flag means that request + and response headers and content will be visible from the HTTPS proxy** + whereas tunneling keeps request and response headers and content + private. IP address, target hostname, SNI, and port are always visible + to an HTTPS proxy even when this flag is disabled. + + :param proxy_assert_hostname: + The hostname of the certificate to verify against. + + :param proxy_assert_fingerprint: + The fingerprint of the certificate to verify against. + + Example: + + .. code-block:: python + + import urllib3 + + proxy = urllib3.ProxyManager("https://localhost:3128/") + + resp1 = proxy.request("GET", "https://google.com/") + resp2 = proxy.request("GET", "https://httpbin.org/") + + print(len(proxy.pools)) + # 1 + + resp3 = proxy.request("GET", "https://httpbin.org/") + resp4 = proxy.request("GET", "https://twitter.com/") + + print(len(proxy.pools)) + # 3 + + """ + + def __init__( + self, + proxy_url: str, + num_pools: int = 10, + headers: typing.Mapping[str, str] | None = None, + proxy_headers: typing.Mapping[str, str] | None = None, + proxy_ssl_context: ssl.SSLContext | None = None, + use_forwarding_for_https: bool = False, + proxy_assert_hostname: None | str | typing.Literal[False] = None, + proxy_assert_fingerprint: str | None = None, + **connection_pool_kw: typing.Any, + ) -> None: + if isinstance(proxy_url, HTTPConnectionPool): + str_proxy_url = f"{proxy_url.scheme}://{proxy_url.host}:{proxy_url.port}" + else: + str_proxy_url = proxy_url + proxy = parse_url(str_proxy_url) + + if proxy.scheme not in ("http", "https"): + raise ProxySchemeUnknown(proxy.scheme) + + if not proxy.port: + port = port_by_scheme.get(proxy.scheme, 80) + proxy = proxy._replace(port=port) + + self.proxy = proxy + self.proxy_headers = proxy_headers or {} + self.proxy_ssl_context = proxy_ssl_context + self.proxy_config = ProxyConfig( + proxy_ssl_context, + use_forwarding_for_https, + proxy_assert_hostname, + proxy_assert_fingerprint, + ) + + connection_pool_kw["_proxy"] = self.proxy + connection_pool_kw["_proxy_headers"] = self.proxy_headers + connection_pool_kw["_proxy_config"] = self.proxy_config + + super().__init__(num_pools, headers, **connection_pool_kw) + + def connection_from_host( + self, + host: str | None, + port: int | None = None, + scheme: str | None = "http", + pool_kwargs: dict[str, typing.Any] | None = None, + ) -> HTTPConnectionPool: + if scheme == "https": + return super().connection_from_host( + host, port, scheme, pool_kwargs=pool_kwargs + ) + + return super().connection_from_host( + self.proxy.host, self.proxy.port, self.proxy.scheme, pool_kwargs=pool_kwargs # type: ignore[union-attr] + ) + + def _set_proxy_headers( + self, url: str, headers: typing.Mapping[str, str] | None = None + ) -> typing.Mapping[str, str]: + """ + Sets headers needed by proxies: specifically, the Accept and Host + headers. Only sets headers not provided by the user. + """ + headers_ = {"Accept": "*/*"} + + netloc = parse_url(url).netloc + if netloc: + headers_["Host"] = netloc + + if headers: + headers_.update(headers) + return headers_ + + def urlopen( # type: ignore[override] + self, method: str, url: str, redirect: bool = True, **kw: typing.Any + ) -> BaseHTTPResponse: + "Same as HTTP(S)ConnectionPool.urlopen, ``url`` must be absolute." + u = parse_url(url) + if not connection_requires_http_tunnel(self.proxy, self.proxy_config, u.scheme): + # For connections using HTTP CONNECT, httplib sets the necessary + # headers on the CONNECT to the proxy. If we're not using CONNECT, + # we'll definitely need to set 'Host' at the very least. + headers = kw.get("headers", self.headers) + kw["headers"] = self._set_proxy_headers(url, headers) + + return super().urlopen(method, url, redirect=redirect, **kw) + + +def proxy_from_url(url: str, **kw: typing.Any) -> ProxyManager: + return ProxyManager(proxy_url=url, **kw) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/py.typed b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/py.typed new file mode 100644 index 0000000..5f3ea3d --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/py.typed @@ -0,0 +1,2 @@ +# Instruct type checkers to look for inline type annotations in this package. +# See PEP 561. diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/response.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/response.py new file mode 100644 index 0000000..a0273d6 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/response.py @@ -0,0 +1,1265 @@ +from __future__ import annotations + +import collections +import io +import json as _json +import logging +import re +import sys +import typing +import warnings +import zlib +from contextlib import contextmanager +from http.client import HTTPMessage as _HttplibHTTPMessage +from http.client import HTTPResponse as _HttplibHTTPResponse +from socket import timeout as SocketTimeout + +if typing.TYPE_CHECKING: + from ._base_connection import BaseHTTPConnection + +try: + try: + import brotlicffi as brotli # type: ignore[import-not-found] + except ImportError: + import brotli # type: ignore[import-not-found] +except ImportError: + brotli = None + +try: + import zstandard as zstd +except (AttributeError, ImportError, ValueError): # Defensive: + HAS_ZSTD = False +else: + # The package 'zstandard' added the 'eof' property starting + # in v0.18.0 which we require to ensure a complete and + # valid zstd stream was fed into the ZstdDecoder. + # See: https://github.com/urllib3/urllib3/pull/2624 + _zstd_version = tuple( + map(int, re.search(r"^([0-9]+)\.([0-9]+)", zstd.__version__).groups()) # type: ignore[union-attr] + ) + if _zstd_version < (0, 18): # Defensive: + HAS_ZSTD = False + else: + HAS_ZSTD = True + +from . import util +from ._base_connection import _TYPE_BODY +from ._collections import HTTPHeaderDict +from .connection import BaseSSLError, HTTPConnection, HTTPException +from .exceptions import ( + BodyNotHttplibCompatible, + DecodeError, + HTTPError, + IncompleteRead, + InvalidChunkLength, + InvalidHeader, + ProtocolError, + ReadTimeoutError, + ResponseNotChunked, + SSLError, +) +from .util.response import is_fp_closed, is_response_to_head +from .util.retry import Retry + +if typing.TYPE_CHECKING: + from .connectionpool import HTTPConnectionPool + +log = logging.getLogger(__name__) + + +class ContentDecoder: + def decompress(self, data: bytes) -> bytes: + raise NotImplementedError() + + def flush(self) -> bytes: + raise NotImplementedError() + + +class DeflateDecoder(ContentDecoder): + def __init__(self) -> None: + self._first_try = True + self._data = b"" + self._obj = zlib.decompressobj() + + def decompress(self, data: bytes) -> bytes: + if not data: + return data + + if not self._first_try: + return self._obj.decompress(data) + + self._data += data + try: + decompressed = self._obj.decompress(data) + if decompressed: + self._first_try = False + self._data = None # type: ignore[assignment] + return decompressed + except zlib.error: + self._first_try = False + self._obj = zlib.decompressobj(-zlib.MAX_WBITS) + try: + return self.decompress(self._data) + finally: + self._data = None # type: ignore[assignment] + + def flush(self) -> bytes: + return self._obj.flush() + + +class GzipDecoderState: + FIRST_MEMBER = 0 + OTHER_MEMBERS = 1 + SWALLOW_DATA = 2 + + +class GzipDecoder(ContentDecoder): + def __init__(self) -> None: + self._obj = zlib.decompressobj(16 + zlib.MAX_WBITS) + self._state = GzipDecoderState.FIRST_MEMBER + + def decompress(self, data: bytes) -> bytes: + ret = bytearray() + if self._state == GzipDecoderState.SWALLOW_DATA or not data: + return bytes(ret) + while True: + try: + ret += self._obj.decompress(data) + except zlib.error: + previous_state = self._state + # Ignore data after the first error + self._state = GzipDecoderState.SWALLOW_DATA + if previous_state == GzipDecoderState.OTHER_MEMBERS: + # Allow trailing garbage acceptable in other gzip clients + return bytes(ret) + raise + data = self._obj.unused_data + if not data: + return bytes(ret) + self._state = GzipDecoderState.OTHER_MEMBERS + self._obj = zlib.decompressobj(16 + zlib.MAX_WBITS) + + def flush(self) -> bytes: + return self._obj.flush() + + +if brotli is not None: + + class BrotliDecoder(ContentDecoder): + # Supports both 'brotlipy' and 'Brotli' packages + # since they share an import name. The top branches + # are for 'brotlipy' and bottom branches for 'Brotli' + def __init__(self) -> None: + self._obj = brotli.Decompressor() + if hasattr(self._obj, "decompress"): + setattr(self, "decompress", self._obj.decompress) + else: + setattr(self, "decompress", self._obj.process) + + def flush(self) -> bytes: + if hasattr(self._obj, "flush"): + return self._obj.flush() # type: ignore[no-any-return] + return b"" + + +if HAS_ZSTD: + + class ZstdDecoder(ContentDecoder): + def __init__(self) -> None: + self._obj = zstd.ZstdDecompressor().decompressobj() + + def decompress(self, data: bytes) -> bytes: + if not data: + return b"" + data_parts = [self._obj.decompress(data)] + while self._obj.eof and self._obj.unused_data: + unused_data = self._obj.unused_data + self._obj = zstd.ZstdDecompressor().decompressobj() + data_parts.append(self._obj.decompress(unused_data)) + return b"".join(data_parts) + + def flush(self) -> bytes: + ret = self._obj.flush() # note: this is a no-op + if not self._obj.eof: + raise DecodeError("Zstandard data is incomplete") + return ret + + +class MultiDecoder(ContentDecoder): + """ + From RFC7231: + If one or more encodings have been applied to a representation, the + sender that applied the encodings MUST generate a Content-Encoding + header field that lists the content codings in the order in which + they were applied. + """ + + def __init__(self, modes: str) -> None: + self._decoders = [_get_decoder(m.strip()) for m in modes.split(",")] + + def flush(self) -> bytes: + return self._decoders[0].flush() + + def decompress(self, data: bytes) -> bytes: + for d in reversed(self._decoders): + data = d.decompress(data) + return data + + +def _get_decoder(mode: str) -> ContentDecoder: + if "," in mode: + return MultiDecoder(mode) + + # According to RFC 9110 section 8.4.1.3, recipients should + # consider x-gzip equivalent to gzip + if mode in ("gzip", "x-gzip"): + return GzipDecoder() + + if brotli is not None and mode == "br": + return BrotliDecoder() + + if HAS_ZSTD and mode == "zstd": + return ZstdDecoder() + + return DeflateDecoder() + + +class BytesQueueBuffer: + """Memory-efficient bytes buffer + + To return decoded data in read() and still follow the BufferedIOBase API, we need a + buffer to always return the correct amount of bytes. + + This buffer should be filled using calls to put() + + Our maximum memory usage is determined by the sum of the size of: + + * self.buffer, which contains the full data + * the largest chunk that we will copy in get() + + The worst case scenario is a single chunk, in which case we'll make a full copy of + the data inside get(). + """ + + def __init__(self) -> None: + self.buffer: typing.Deque[bytes] = collections.deque() + self._size: int = 0 + + def __len__(self) -> int: + return self._size + + def put(self, data: bytes) -> None: + self.buffer.append(data) + self._size += len(data) + + def get(self, n: int) -> bytes: + if n == 0: + return b"" + elif not self.buffer: + raise RuntimeError("buffer is empty") + elif n < 0: + raise ValueError("n should be > 0") + + fetched = 0 + ret = io.BytesIO() + while fetched < n: + remaining = n - fetched + chunk = self.buffer.popleft() + chunk_length = len(chunk) + if remaining < chunk_length: + left_chunk, right_chunk = chunk[:remaining], chunk[remaining:] + ret.write(left_chunk) + self.buffer.appendleft(right_chunk) + self._size -= remaining + break + else: + ret.write(chunk) + self._size -= chunk_length + fetched += chunk_length + + if not self.buffer: + break + + return ret.getvalue() + + def get_all(self) -> bytes: + buffer = self.buffer + if not buffer: + assert self._size == 0 + return b"" + if len(buffer) == 1: + result = buffer.pop() + else: + ret = io.BytesIO() + ret.writelines(buffer.popleft() for _ in range(len(buffer))) + result = ret.getvalue() + self._size = 0 + return result + + +class BaseHTTPResponse(io.IOBase): + CONTENT_DECODERS = ["gzip", "x-gzip", "deflate"] + if brotli is not None: + CONTENT_DECODERS += ["br"] + if HAS_ZSTD: + CONTENT_DECODERS += ["zstd"] + REDIRECT_STATUSES = [301, 302, 303, 307, 308] + + DECODER_ERROR_CLASSES: tuple[type[Exception], ...] = (IOError, zlib.error) + if brotli is not None: + DECODER_ERROR_CLASSES += (brotli.error,) + + if HAS_ZSTD: + DECODER_ERROR_CLASSES += (zstd.ZstdError,) + + def __init__( + self, + *, + headers: typing.Mapping[str, str] | typing.Mapping[bytes, bytes] | None = None, + status: int, + version: int, + version_string: str, + reason: str | None, + decode_content: bool, + request_url: str | None, + retries: Retry | None = None, + ) -> None: + if isinstance(headers, HTTPHeaderDict): + self.headers = headers + else: + self.headers = HTTPHeaderDict(headers) # type: ignore[arg-type] + self.status = status + self.version = version + self.version_string = version_string + self.reason = reason + self.decode_content = decode_content + self._has_decoded_content = False + self._request_url: str | None = request_url + self.retries = retries + + self.chunked = False + tr_enc = self.headers.get("transfer-encoding", "").lower() + # Don't incur the penalty of creating a list and then discarding it + encodings = (enc.strip() for enc in tr_enc.split(",")) + if "chunked" in encodings: + self.chunked = True + + self._decoder: ContentDecoder | None = None + self.length_remaining: int | None + + def get_redirect_location(self) -> str | None | typing.Literal[False]: + """ + Should we redirect and where to? + + :returns: Truthy redirect location string if we got a redirect status + code and valid location. ``None`` if redirect status and no + location. ``False`` if not a redirect status code. + """ + if self.status in self.REDIRECT_STATUSES: + return self.headers.get("location") + return False + + @property + def data(self) -> bytes: + raise NotImplementedError() + + def json(self) -> typing.Any: + """ + Deserializes the body of the HTTP response as a Python object. + + The body of the HTTP response must be encoded using UTF-8, as per + `RFC 8529 Section 8.1 `_. + + To use a custom JSON decoder pass the result of :attr:`HTTPResponse.data` to + your custom decoder instead. + + If the body of the HTTP response is not decodable to UTF-8, a + `UnicodeDecodeError` will be raised. If the body of the HTTP response is not a + valid JSON document, a `json.JSONDecodeError` will be raised. + + Read more :ref:`here `. + + :returns: The body of the HTTP response as a Python object. + """ + data = self.data.decode("utf-8") + return _json.loads(data) + + @property + def url(self) -> str | None: + raise NotImplementedError() + + @url.setter + def url(self, url: str | None) -> None: + raise NotImplementedError() + + @property + def connection(self) -> BaseHTTPConnection | None: + raise NotImplementedError() + + @property + def retries(self) -> Retry | None: + return self._retries + + @retries.setter + def retries(self, retries: Retry | None) -> None: + # Override the request_url if retries has a redirect location. + if retries is not None and retries.history: + self.url = retries.history[-1].redirect_location + self._retries = retries + + def stream( + self, amt: int | None = 2**16, decode_content: bool | None = None + ) -> typing.Iterator[bytes]: + raise NotImplementedError() + + def read( + self, + amt: int | None = None, + decode_content: bool | None = None, + cache_content: bool = False, + ) -> bytes: + raise NotImplementedError() + + def read1( + self, + amt: int | None = None, + decode_content: bool | None = None, + ) -> bytes: + raise NotImplementedError() + + def read_chunked( + self, + amt: int | None = None, + decode_content: bool | None = None, + ) -> typing.Iterator[bytes]: + raise NotImplementedError() + + def release_conn(self) -> None: + raise NotImplementedError() + + def drain_conn(self) -> None: + raise NotImplementedError() + + def close(self) -> None: + raise NotImplementedError() + + def _init_decoder(self) -> None: + """ + Set-up the _decoder attribute if necessary. + """ + # Note: content-encoding value should be case-insensitive, per RFC 7230 + # Section 3.2 + content_encoding = self.headers.get("content-encoding", "").lower() + if self._decoder is None: + if content_encoding in self.CONTENT_DECODERS: + self._decoder = _get_decoder(content_encoding) + elif "," in content_encoding: + encodings = [ + e.strip() + for e in content_encoding.split(",") + if e.strip() in self.CONTENT_DECODERS + ] + if encodings: + self._decoder = _get_decoder(content_encoding) + + def _decode( + self, data: bytes, decode_content: bool | None, flush_decoder: bool + ) -> bytes: + """ + Decode the data passed in and potentially flush the decoder. + """ + if not decode_content: + if self._has_decoded_content: + raise RuntimeError( + "Calling read(decode_content=False) is not supported after " + "read(decode_content=True) was called." + ) + return data + + try: + if self._decoder: + data = self._decoder.decompress(data) + self._has_decoded_content = True + except self.DECODER_ERROR_CLASSES as e: + content_encoding = self.headers.get("content-encoding", "").lower() + raise DecodeError( + "Received response with content-encoding: %s, but " + "failed to decode it." % content_encoding, + e, + ) from e + if flush_decoder: + data += self._flush_decoder() + + return data + + def _flush_decoder(self) -> bytes: + """ + Flushes the decoder. Should only be called if the decoder is actually + being used. + """ + if self._decoder: + return self._decoder.decompress(b"") + self._decoder.flush() + return b"" + + # Compatibility methods for `io` module + def readinto(self, b: bytearray) -> int: + temp = self.read(len(b)) + if len(temp) == 0: + return 0 + else: + b[: len(temp)] = temp + return len(temp) + + # Compatibility methods for http.client.HTTPResponse + def getheaders(self) -> HTTPHeaderDict: + warnings.warn( + "HTTPResponse.getheaders() is deprecated and will be removed " + "in urllib3 v2.1.0. Instead access HTTPResponse.headers directly.", + category=DeprecationWarning, + stacklevel=2, + ) + return self.headers + + def getheader(self, name: str, default: str | None = None) -> str | None: + warnings.warn( + "HTTPResponse.getheader() is deprecated and will be removed " + "in urllib3 v2.1.0. Instead use HTTPResponse.headers.get(name, default).", + category=DeprecationWarning, + stacklevel=2, + ) + return self.headers.get(name, default) + + # Compatibility method for http.cookiejar + def info(self) -> HTTPHeaderDict: + return self.headers + + def geturl(self) -> str | None: + return self.url + + +class HTTPResponse(BaseHTTPResponse): + """ + HTTP Response container. + + Backwards-compatible with :class:`http.client.HTTPResponse` but the response ``body`` is + loaded and decoded on-demand when the ``data`` property is accessed. This + class is also compatible with the Python standard library's :mod:`io` + module, and can hence be treated as a readable object in the context of that + framework. + + Extra parameters for behaviour not present in :class:`http.client.HTTPResponse`: + + :param preload_content: + If True, the response's body will be preloaded during construction. + + :param decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + + :param original_response: + When this HTTPResponse wrapper is generated from an :class:`http.client.HTTPResponse` + object, it's convenient to include the original for debug purposes. It's + otherwise unused. + + :param retries: + The retries contains the last :class:`~urllib3.util.retry.Retry` that + was used during the request. + + :param enforce_content_length: + Enforce content length checking. Body returned by server must match + value of Content-Length header, if present. Otherwise, raise error. + """ + + def __init__( + self, + body: _TYPE_BODY = "", + headers: typing.Mapping[str, str] | typing.Mapping[bytes, bytes] | None = None, + status: int = 0, + version: int = 0, + version_string: str = "HTTP/?", + reason: str | None = None, + preload_content: bool = True, + decode_content: bool = True, + original_response: _HttplibHTTPResponse | None = None, + pool: HTTPConnectionPool | None = None, + connection: HTTPConnection | None = None, + msg: _HttplibHTTPMessage | None = None, + retries: Retry | None = None, + enforce_content_length: bool = True, + request_method: str | None = None, + request_url: str | None = None, + auto_close: bool = True, + ) -> None: + super().__init__( + headers=headers, + status=status, + version=version, + version_string=version_string, + reason=reason, + decode_content=decode_content, + request_url=request_url, + retries=retries, + ) + + self.enforce_content_length = enforce_content_length + self.auto_close = auto_close + + self._body = None + self._fp: _HttplibHTTPResponse | None = None + self._original_response = original_response + self._fp_bytes_read = 0 + self.msg = msg + + if body and isinstance(body, (str, bytes)): + self._body = body + + self._pool = pool + self._connection = connection + + if hasattr(body, "read"): + self._fp = body # type: ignore[assignment] + + # Are we using the chunked-style of transfer encoding? + self.chunk_left: int | None = None + + # Determine length of response + self.length_remaining = self._init_length(request_method) + + # Used to return the correct amount of bytes for partial read()s + self._decoded_buffer = BytesQueueBuffer() + + # If requested, preload the body. + if preload_content and not self._body: + self._body = self.read(decode_content=decode_content) + + def release_conn(self) -> None: + if not self._pool or not self._connection: + return None + + self._pool._put_conn(self._connection) + self._connection = None + + def drain_conn(self) -> None: + """ + Read and discard any remaining HTTP response data in the response connection. + + Unread data in the HTTPResponse connection blocks the connection from being released back to the pool. + """ + try: + self.read() + except (HTTPError, OSError, BaseSSLError, HTTPException): + pass + + @property + def data(self) -> bytes: + # For backwards-compat with earlier urllib3 0.4 and earlier. + if self._body: + return self._body # type: ignore[return-value] + + if self._fp: + return self.read(cache_content=True) + + return None # type: ignore[return-value] + + @property + def connection(self) -> HTTPConnection | None: + return self._connection + + def isclosed(self) -> bool: + return is_fp_closed(self._fp) + + def tell(self) -> int: + """ + Obtain the number of bytes pulled over the wire so far. May differ from + the amount of content returned by :meth:``urllib3.response.HTTPResponse.read`` + if bytes are encoded on the wire (e.g, compressed). + """ + return self._fp_bytes_read + + def _init_length(self, request_method: str | None) -> int | None: + """ + Set initial length value for Response content if available. + """ + length: int | None + content_length: str | None = self.headers.get("content-length") + + if content_length is not None: + if self.chunked: + # This Response will fail with an IncompleteRead if it can't be + # received as chunked. This method falls back to attempt reading + # the response before raising an exception. + log.warning( + "Received response with both Content-Length and " + "Transfer-Encoding set. This is expressly forbidden " + "by RFC 7230 sec 3.3.2. Ignoring Content-Length and " + "attempting to process response as Transfer-Encoding: " + "chunked." + ) + return None + + try: + # RFC 7230 section 3.3.2 specifies multiple content lengths can + # be sent in a single Content-Length header + # (e.g. Content-Length: 42, 42). This line ensures the values + # are all valid ints and that as long as the `set` length is 1, + # all values are the same. Otherwise, the header is invalid. + lengths = {int(val) for val in content_length.split(",")} + if len(lengths) > 1: + raise InvalidHeader( + "Content-Length contained multiple " + "unmatching values (%s)" % content_length + ) + length = lengths.pop() + except ValueError: + length = None + else: + if length < 0: + length = None + + else: # if content_length is None + length = None + + # Convert status to int for comparison + # In some cases, httplib returns a status of "_UNKNOWN" + try: + status = int(self.status) + except ValueError: + status = 0 + + # Check for responses that shouldn't include a body + if status in (204, 304) or 100 <= status < 200 or request_method == "HEAD": + length = 0 + + return length + + @contextmanager + def _error_catcher(self) -> typing.Generator[None, None, None]: + """ + Catch low-level python exceptions, instead re-raising urllib3 + variants, so that low-level exceptions are not leaked in the + high-level api. + + On exit, release the connection back to the pool. + """ + clean_exit = False + + try: + try: + yield + + except SocketTimeout as e: + # FIXME: Ideally we'd like to include the url in the ReadTimeoutError but + # there is yet no clean way to get at it from this context. + raise ReadTimeoutError(self._pool, None, "Read timed out.") from e # type: ignore[arg-type] + + except BaseSSLError as e: + # FIXME: Is there a better way to differentiate between SSLErrors? + if "read operation timed out" not in str(e): + # SSL errors related to framing/MAC get wrapped and reraised here + raise SSLError(e) from e + + raise ReadTimeoutError(self._pool, None, "Read timed out.") from e # type: ignore[arg-type] + + except IncompleteRead as e: + if ( + e.expected is not None + and e.partial is not None + and e.expected == -e.partial + ): + arg = "Response may not contain content." + else: + arg = f"Connection broken: {e!r}" + raise ProtocolError(arg, e) from e + + except (HTTPException, OSError) as e: + raise ProtocolError(f"Connection broken: {e!r}", e) from e + + # If no exception is thrown, we should avoid cleaning up + # unnecessarily. + clean_exit = True + finally: + # If we didn't terminate cleanly, we need to throw away our + # connection. + if not clean_exit: + # The response may not be closed but we're not going to use it + # anymore so close it now to ensure that the connection is + # released back to the pool. + if self._original_response: + self._original_response.close() + + # Closing the response may not actually be sufficient to close + # everything, so if we have a hold of the connection close that + # too. + if self._connection: + self._connection.close() + + # If we hold the original response but it's closed now, we should + # return the connection back to the pool. + if self._original_response and self._original_response.isclosed(): + self.release_conn() + + def _fp_read( + self, + amt: int | None = None, + *, + read1: bool = False, + ) -> bytes: + """ + Read a response with the thought that reading the number of bytes + larger than can fit in a 32-bit int at a time via SSL in some + known cases leads to an overflow error that has to be prevented + if `amt` or `self.length_remaining` indicate that a problem may + happen. + + The known cases: + * 3.8 <= CPython < 3.9.7 because of a bug + https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900. + * urllib3 injected with pyOpenSSL-backed SSL-support. + * CPython < 3.10 only when `amt` does not fit 32-bit int. + """ + assert self._fp + c_int_max = 2**31 - 1 + if ( + (amt and amt > c_int_max) + or ( + amt is None + and self.length_remaining + and self.length_remaining > c_int_max + ) + ) and (util.IS_PYOPENSSL or sys.version_info < (3, 10)): + if read1: + return self._fp.read1(c_int_max) + buffer = io.BytesIO() + # Besides `max_chunk_amt` being a maximum chunk size, it + # affects memory overhead of reading a response by this + # method in CPython. + # `c_int_max` equal to 2 GiB - 1 byte is the actual maximum + # chunk size that does not lead to an overflow error, but + # 256 MiB is a compromise. + max_chunk_amt = 2**28 + while amt is None or amt != 0: + if amt is not None: + chunk_amt = min(amt, max_chunk_amt) + amt -= chunk_amt + else: + chunk_amt = max_chunk_amt + data = self._fp.read(chunk_amt) + if not data: + break + buffer.write(data) + del data # to reduce peak memory usage by `max_chunk_amt`. + return buffer.getvalue() + elif read1: + return self._fp.read1(amt) if amt is not None else self._fp.read1() + else: + # StringIO doesn't like amt=None + return self._fp.read(amt) if amt is not None else self._fp.read() + + def _raw_read( + self, + amt: int | None = None, + *, + read1: bool = False, + ) -> bytes: + """ + Reads `amt` of bytes from the socket. + """ + if self._fp is None: + return None # type: ignore[return-value] + + fp_closed = getattr(self._fp, "closed", False) + + with self._error_catcher(): + data = self._fp_read(amt, read1=read1) if not fp_closed else b"" + if amt is not None and amt != 0 and not data: + # Platform-specific: Buggy versions of Python. + # Close the connection when no data is returned + # + # This is redundant to what httplib/http.client _should_ + # already do. However, versions of python released before + # December 15, 2012 (http://bugs.python.org/issue16298) do + # not properly close the connection in all cases. There is + # no harm in redundantly calling close. + self._fp.close() + if ( + self.enforce_content_length + and self.length_remaining is not None + and self.length_remaining != 0 + ): + # This is an edge case that httplib failed to cover due + # to concerns of backward compatibility. We're + # addressing it here to make sure IncompleteRead is + # raised during streaming, so all calls with incorrect + # Content-Length are caught. + raise IncompleteRead(self._fp_bytes_read, self.length_remaining) + elif read1 and ( + (amt != 0 and not data) or self.length_remaining == len(data) + ): + # All data has been read, but `self._fp.read1` in + # CPython 3.12 and older doesn't always close + # `http.client.HTTPResponse`, so we close it here. + # See https://github.com/python/cpython/issues/113199 + self._fp.close() + + if data: + self._fp_bytes_read += len(data) + if self.length_remaining is not None: + self.length_remaining -= len(data) + return data + + def read( + self, + amt: int | None = None, + decode_content: bool | None = None, + cache_content: bool = False, + ) -> bytes: + """ + Similar to :meth:`http.client.HTTPResponse.read`, but with two additional + parameters: ``decode_content`` and ``cache_content``. + + :param amt: + How much of the content to read. If specified, caching is skipped + because it doesn't make sense to cache partial content as the full + response. + + :param decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + + :param cache_content: + If True, will save the returned data such that the same result is + returned despite of the state of the underlying file object. This + is useful if you want the ``.data`` property to continue working + after having ``.read()`` the file object. (Overridden if ``amt`` is + set.) + """ + self._init_decoder() + if decode_content is None: + decode_content = self.decode_content + + if amt and amt < 0: + # Negative numbers and `None` should be treated the same. + amt = None + elif amt is not None: + cache_content = False + + if len(self._decoded_buffer) >= amt: + return self._decoded_buffer.get(amt) + + data = self._raw_read(amt) + + flush_decoder = amt is None or (amt != 0 and not data) + + if not data and len(self._decoded_buffer) == 0: + return data + + if amt is None: + data = self._decode(data, decode_content, flush_decoder) + if cache_content: + self._body = data + else: + # do not waste memory on buffer when not decoding + if not decode_content: + if self._has_decoded_content: + raise RuntimeError( + "Calling read(decode_content=False) is not supported after " + "read(decode_content=True) was called." + ) + return data + + decoded_data = self._decode(data, decode_content, flush_decoder) + self._decoded_buffer.put(decoded_data) + + while len(self._decoded_buffer) < amt and data: + # TODO make sure to initially read enough data to get past the headers + # For example, the GZ file header takes 10 bytes, we don't want to read + # it one byte at a time + data = self._raw_read(amt) + decoded_data = self._decode(data, decode_content, flush_decoder) + self._decoded_buffer.put(decoded_data) + data = self._decoded_buffer.get(amt) + + return data + + def read1( + self, + amt: int | None = None, + decode_content: bool | None = None, + ) -> bytes: + """ + Similar to ``http.client.HTTPResponse.read1`` and documented + in :meth:`io.BufferedReader.read1`, but with an additional parameter: + ``decode_content``. + + :param amt: + How much of the content to read. + + :param decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + """ + if decode_content is None: + decode_content = self.decode_content + if amt and amt < 0: + # Negative numbers and `None` should be treated the same. + amt = None + # try and respond without going to the network + if self._has_decoded_content: + if not decode_content: + raise RuntimeError( + "Calling read1(decode_content=False) is not supported after " + "read1(decode_content=True) was called." + ) + if len(self._decoded_buffer) > 0: + if amt is None: + return self._decoded_buffer.get_all() + return self._decoded_buffer.get(amt) + if amt == 0: + return b"" + + # FIXME, this method's type doesn't say returning None is possible + data = self._raw_read(amt, read1=True) + if not decode_content or data is None: + return data + + self._init_decoder() + while True: + flush_decoder = not data + decoded_data = self._decode(data, decode_content, flush_decoder) + self._decoded_buffer.put(decoded_data) + if decoded_data or flush_decoder: + break + data = self._raw_read(8192, read1=True) + + if amt is None: + return self._decoded_buffer.get_all() + return self._decoded_buffer.get(amt) + + def stream( + self, amt: int | None = 2**16, decode_content: bool | None = None + ) -> typing.Generator[bytes, None, None]: + """ + A generator wrapper for the read() method. A call will block until + ``amt`` bytes have been read from the connection or until the + connection is closed. + + :param amt: + How much of the content to read. The generator will return up to + much data per iteration, but may return less. This is particularly + likely when using compressed data. However, the empty string will + never be returned. + + :param decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + """ + if self.chunked and self.supports_chunked_reads(): + yield from self.read_chunked(amt, decode_content=decode_content) + else: + while not is_fp_closed(self._fp) or len(self._decoded_buffer) > 0: + data = self.read(amt=amt, decode_content=decode_content) + + if data: + yield data + + # Overrides from io.IOBase + def readable(self) -> bool: + return True + + def close(self) -> None: + if not self.closed and self._fp: + self._fp.close() + + if self._connection: + self._connection.close() + + if not self.auto_close: + io.IOBase.close(self) + + @property + def closed(self) -> bool: + if not self.auto_close: + return io.IOBase.closed.__get__(self) # type: ignore[no-any-return] + elif self._fp is None: + return True + elif hasattr(self._fp, "isclosed"): + return self._fp.isclosed() + elif hasattr(self._fp, "closed"): + return self._fp.closed + else: + return True + + def fileno(self) -> int: + if self._fp is None: + raise OSError("HTTPResponse has no file to get a fileno from") + elif hasattr(self._fp, "fileno"): + return self._fp.fileno() + else: + raise OSError( + "The file-like object this HTTPResponse is wrapped " + "around has no file descriptor" + ) + + def flush(self) -> None: + if ( + self._fp is not None + and hasattr(self._fp, "flush") + and not getattr(self._fp, "closed", False) + ): + return self._fp.flush() + + def supports_chunked_reads(self) -> bool: + """ + Checks if the underlying file-like object looks like a + :class:`http.client.HTTPResponse` object. We do this by testing for + the fp attribute. If it is present we assume it returns raw chunks as + processed by read_chunked(). + """ + return hasattr(self._fp, "fp") + + def _update_chunk_length(self) -> None: + # First, we'll figure out length of a chunk and then + # we'll try to read it from socket. + if self.chunk_left is not None: + return None + line = self._fp.fp.readline() # type: ignore[union-attr] + line = line.split(b";", 1)[0] + try: + self.chunk_left = int(line, 16) + except ValueError: + self.close() + if line: + # Invalid chunked protocol response, abort. + raise InvalidChunkLength(self, line) from None + else: + # Truncated at start of next chunk + raise ProtocolError("Response ended prematurely") from None + + def _handle_chunk(self, amt: int | None) -> bytes: + returned_chunk = None + if amt is None: + chunk = self._fp._safe_read(self.chunk_left) # type: ignore[union-attr] + returned_chunk = chunk + self._fp._safe_read(2) # type: ignore[union-attr] # Toss the CRLF at the end of the chunk. + self.chunk_left = None + elif self.chunk_left is not None and amt < self.chunk_left: + value = self._fp._safe_read(amt) # type: ignore[union-attr] + self.chunk_left = self.chunk_left - amt + returned_chunk = value + elif amt == self.chunk_left: + value = self._fp._safe_read(amt) # type: ignore[union-attr] + self._fp._safe_read(2) # type: ignore[union-attr] # Toss the CRLF at the end of the chunk. + self.chunk_left = None + returned_chunk = value + else: # amt > self.chunk_left + returned_chunk = self._fp._safe_read(self.chunk_left) # type: ignore[union-attr] + self._fp._safe_read(2) # type: ignore[union-attr] # Toss the CRLF at the end of the chunk. + self.chunk_left = None + return returned_chunk # type: ignore[no-any-return] + + def read_chunked( + self, amt: int | None = None, decode_content: bool | None = None + ) -> typing.Generator[bytes, None, None]: + """ + Similar to :meth:`HTTPResponse.read`, but with an additional + parameter: ``decode_content``. + + :param amt: + How much of the content to read. If specified, caching is skipped + because it doesn't make sense to cache partial content as the full + response. + + :param decode_content: + If True, will attempt to decode the body based on the + 'content-encoding' header. + """ + self._init_decoder() + # FIXME: Rewrite this method and make it a class with a better structured logic. + if not self.chunked: + raise ResponseNotChunked( + "Response is not chunked. " + "Header 'transfer-encoding: chunked' is missing." + ) + if not self.supports_chunked_reads(): + raise BodyNotHttplibCompatible( + "Body should be http.client.HTTPResponse like. " + "It should have have an fp attribute which returns raw chunks." + ) + + with self._error_catcher(): + # Don't bother reading the body of a HEAD request. + if self._original_response and is_response_to_head(self._original_response): + self._original_response.close() + return None + + # If a response is already read and closed + # then return immediately. + if self._fp.fp is None: # type: ignore[union-attr] + return None + + if amt and amt < 0: + # Negative numbers and `None` should be treated the same, + # but httplib handles only `None` correctly. + amt = None + + while True: + self._update_chunk_length() + if self.chunk_left == 0: + break + chunk = self._handle_chunk(amt) + decoded = self._decode( + chunk, decode_content=decode_content, flush_decoder=False + ) + if decoded: + yield decoded + + if decode_content: + # On CPython and PyPy, we should never need to flush the + # decoder. However, on Jython we *might* need to, so + # lets defensively do it anyway. + decoded = self._flush_decoder() + if decoded: # Platform-specific: Jython. + yield decoded + + # Chunk content ends with \r\n: discard it. + while self._fp is not None: + line = self._fp.fp.readline() + if not line: + # Some sites may not end with '\r\n'. + break + if line == b"\r\n": + break + + # We read everything; close the "file". + if self._original_response: + self._original_response.close() + + @property + def url(self) -> str | None: + """ + Returns the URL that was the source of this response. + If the request that generated this response redirected, this method + will return the final redirect location. + """ + return self._request_url + + @url.setter + def url(self, url: str) -> None: + self._request_url = url + + def __iter__(self) -> typing.Iterator[bytes]: + buffer: list[bytes] = [] + for chunk in self.stream(decode_content=True): + if b"\n" in chunk: + chunks = chunk.split(b"\n") + yield b"".join(buffer) + chunks[0] + b"\n" + for x in chunks[1:-1]: + yield x + b"\n" + if chunks[-1]: + buffer = [chunks[-1]] + else: + buffer = [] + else: + buffer.append(chunk) + if buffer: + yield b"".join(buffer) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__init__.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__init__.py new file mode 100644 index 0000000..5341260 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__init__.py @@ -0,0 +1,42 @@ +# For backwards compatibility, provide imports that used to be here. +from __future__ import annotations + +from .connection import is_connection_dropped +from .request import SKIP_HEADER, SKIPPABLE_HEADERS, make_headers +from .response import is_fp_closed +from .retry import Retry +from .ssl_ import ( + ALPN_PROTOCOLS, + IS_PYOPENSSL, + SSLContext, + assert_fingerprint, + create_urllib3_context, + resolve_cert_reqs, + resolve_ssl_version, + ssl_wrap_socket, +) +from .timeout import Timeout +from .url import Url, parse_url +from .wait import wait_for_read, wait_for_write + +__all__ = ( + "IS_PYOPENSSL", + "SSLContext", + "ALPN_PROTOCOLS", + "Retry", + "Timeout", + "Url", + "assert_fingerprint", + "create_urllib3_context", + "is_connection_dropped", + "is_fp_closed", + "parse_url", + "make_headers", + "resolve_cert_reqs", + "resolve_ssl_version", + "ssl_wrap_socket", + "wait_for_read", + "wait_for_write", + "SKIP_HEADER", + "SKIPPABLE_HEADERS", +) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/__init__.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/__init__.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..273611935eebca5ed7fb694a6e7bbcd41e960711 GIT binary patch literal 973 zcmY+C&rcIU6vt<~ZMVNme^5YB6VyWwxCdk6ftXZmBC(+j#e;L1tlcSWnAu%treL}G zS8(;}-=Y_JJ?BL8J6RDoKNg5EAS#NCbq*$ zyo}4df-Ag=t9$`3@EWf1I#p1z#i~byvo<` zn(>SH;k48)UxM7WrHft|M#@t`6v|6$7F!G?8AV}8M-V2yh~k*~ZCe+I@3#l!UAObL zyQ^#93_5Rm-Mh$8m$-LG$pQ6zDx@i1GKI!58L>#3d`o9`sS?w6PFFg;!44Vh_V@Z* z{hmqO9+JVw{-C=v9QJgDEY4Pf;=vj0K-wfY#(} zO;8!JBT7b)A?RnR8}}h8896elOhdW~&av=fBBRkERYsY!7jPO)R6C{Z4}$4@>oqzm%}C1tf^`khdz=6Okdoih`N&2njSvCarsK_XG7 zVGc9N^A6@}|5v6RH5*aVnYPXFXYD~NIt??Ki`Nbz9%F=jN7v>zy4`dYkKH(kHR3fFAVji>4$3f;SXx)T*JmyjSdQzy^k>1}S4NB)G-*W#He2Cr1UGPtrW y%ep}87ii-gb$+4F8CpL>%QvaKmAXL&*ML7wWIa4bkI#{Nm2MVOUmfwpB>x59f(YLL literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/connection.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/connection.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..4512ffd50c4fd2e6554bb8c4cc7758f84c70a978 GIT binary patch literal 4716 zcmaJEOKcm*b@oGY`KLr#jQ=A?twY78?Zg%mHBO_5Ql-X`m55GbB@VUXE-lJSE<3xl zB7ux#BS56Wt!<#F4HN|wpg>&sQlKr6o{Ato1ZWRZB*4rzL5-$8#jAOXz6oDZnvgi83N!64%B>N0JGNHtObx;yKf7|oe?ka{Wc({SO>$OHE|qjsHVb;m82yU3H``C? zIkq(>6GI&&L?>U-+ezMvWz&O0{bx>PvYC;W2Tz~LSmA8u?AV~Y1eEPB%7!|e$&3x? zrIMPXsB;c&N)*w#0K?`UnA|{BG(&f{wGbKy_U3;cz|dY*%?c?QI72EbF66N}t>Ro0 zIW8DjA$qy2Dp)Ql*qGKUnu4bQM$-*dNiiIKWtqrDcC8Qhr*ozgN*}(3l)s41Fb5s7U{yEBH;(mA2EyNBjrN*uql)Cs(EL;!gd{ze?SMbrqOSjXKcUW?+@AYK*m zCTydeNPDMwVPqP92MkIz{3eVwvF53YGp&|zz!lDY8>9^&;O6$G@GeA6RD_z>^tceW zok`8-M{w8iKlhZ5is;_ukQsJQW~fx#T2-uisy;L1ZqLNr+17a5ku#0X5s*o$N^b%$ zHGeHo3)VulFmM;~x6)~1+rm-xR|D1HZAZ>p#H5O4ts1Ecx2Y3A<4~0|oBm$mKsS+@ zgnic9SDV^{8$5%ej=rr`n;HbD$jt6-$FQt6Jrw*ObX<+(cn-WkL{;x4hyYdZWzO8| z-cx+8RxfjpBU5tsyAgr-VFul`0yh6OQoO$rTzEye%+I2?g|ldu-lR^*8rIQ&tx5=jQ**eFDywhOR%r@ik#otpGs*A)kqV8EjC_xwS4d9H zHmyTh0Qm|gE>;YahEo~a+ST*eRxf6%Ww=1PR@p(gsRG1e*??O%X6#@FOiUF;`GTwM zmN3YW^_MU;9|l4P4`RSf>ENT-R5i_DWKNG${Q>uEZH3%%197wHTn8}zG07DYfm@Syo zmd7wjp=`Cwnx@aHO7^^5$mZo@L7TI@@Jw|@wL)h~1v+7glh9CUd2LHr!4`5>aQyVZ zOWEM*uIicsXxL^oBWCRxMAN=%#M@b8-nBS}v*< zZ^)KN&n+%%(0EO~wzUx&@~yTUQDswgQz!Tqc?$Mv7&ImzB|%#2M(sN<{dh6G)Lr)l z-&?q}aLw58?XE}TSLc`KZ+5Ro_b-X{KxA>?egH-Adbn$Gs38iTSGc+qx*A*#UK`qw zcHfs!tn+TPYc1Nf(tS(3mH%V@Ztw6~@9=tbSw6viv!N@*i>;$F0KV_#}5nySY-ZbYv~ zS9}|>Cq9errAz;H|IO4!ELji5uAW*xb+dgVwC7%X=h8qup7_~IjV>VENFgb>xX|E5 zf1=*LV`&7$h<2`aKD!?2Tb260y+6RA&|}{q4kY?Kf>(~MWLAb&d(x|2gX@u@PtvQ> zSVN$P-`(#)vBWn>@b9g+$ALsNz8c+6xd>bj{4(^PZyP>1`mWJ|;)&&f2gXs*@t@iT zj-ikG`X5h6_>a5!^fTz=W4qEp;ZDS#KH<5O=tv*++&Su@^Jm2Lb3)F^fp8T;0&=Q} zUYI~N!7Xxg&_f1>>bu7C|D%Gd^1px_dL=HRIjH1Dp;n>~nLZVG-ARE^zAT^f(k%fd z2F=LucG#04G%>O6988QPbnr;LNQy2l)TIbmgX(G@*i%X@iC3e`(VOv4rM+K+j`k5+ zF6H3gY|WbURoJ?L%;v#NtEA3u4Vg}r0UX3yU};^ot<^w!R;m6WGYt{b%~7l-RgJ>= z62xPORI@s{fD3kd0OvK;w`p{=UHPt_qJu^B!HaI|$(sbh{ z04R1D29}G;DuJ+Cgm9Z49f!y*liW0>QF%%?r}4GU~(MdTuvv7kxGh$mMWGH zNQ{gQW-MvAe>^)f_FAvyZ&FQigeu>zac$Fd!kWI)J9lebm3vgJT7{}6-%_b5VvVnIBnHsUips@>&{j26<;T&sDomg?(v|(qI>)1_%2-49v^Ob1-|zxh#Ly#Y28b!6-l;xe3TU-Z$KJ81RiCcBac&fS^$%7dfvJ199QwEUQ)^T;PAn2`(u?R-oZ@v z^jK!(GlGpmrLk$N=q5(C$Ury#SphQnX2)E#^C1XSMA%#3}+1h8n>V zfLR7c`eB)T%nD?)`3ii~s@W_NV9U0x7ji6=L{>m`O=+;|!IqHL0!&Ox8drZ>p(U~9 z$C03jZC2|Basf2ReQ) zvG>Np^@Wv-A5`D3{(j)Y_=owwXn)o|d3ts1%qM+o&%d^M{I#`%KUqt>zKS~T3I4l6 z;!`2*2Z@d(ggA{qV8+Q@suU54j)I!+RP6jQ7I38Xg!SG3D_2BMH5|i@3 DT9%v; literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/proxy.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/proxy.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..0c8969bb4072591468e60eaa77ed36e9d656ad80 GIT binary patch literal 1185 zcmZ8g%}*0S6rb7c$F{Tr4GBeK90emAfrc0l5`%{Z!Dv=Os)@a9mhQA&+%IQ$qa{6X z@PB}R!M{Zh+6#3P5)$HpTN6BS^37~(8>Z>ZoA-Y2>-T2A7mIlW>v-u$vztQbf?q~U zP6T|_1mPH&$iy~sa2;bVOSV*(OxaA?vXiQ(Frw0dh&6IgPL?s#X2#Aq*?JbEocNha za*lR0XJ)^q>qL%=TczI3Xd+q7DZVX52~ zaXZ}c)gB1PsEdwp2X`e?`nZe`<1#wnxEsrqg?+knb{7a<9%v&bm?cf-ImGuo z+c8|DMcJC)nJgp-88K-PTCRZWL8DC_Iu2QbeiPlOunF`US+>?FX@{X7tcYWU(6FJ3 z1TW(hH^gaSuBlR-Ndm>?D4=@NW1kIXT5gMrx&Wziocqs8Tu8*EowziScUWb>-vsb; z{j3r?e#N)^)zDxq8m=A&9y>IjvWji(SNu-c_S^~(4YwziD75T~2n|%k_r}B2N5d4w z=wSp?w%IJ?n1X+>3EL4G5Twlh%$EDpbAt?0ZlApGWf%EHLAlbYQvRisPqur?;_pJa zUnrjz)_aBZbAc_)TtNh+%9^IB3M+zqn1|O+x6CO9%o3nU*@f{Zgv zJjyt=4`WqxabDM(5j<0>>x@$pXTpvT#Kto8%+g#_tbN$s(yKdL)z`1I?KnT~nq|Q* zy8MP%iOVyvT`SKW&x~xk$?m|Ff1H5^+d#$`pP>gAsQ3rXoy)mXdA=vlpQV<8fV=nm nj~@3Qs)H=SGyUm>fehz)X=#v#6WCf<6c#{c@_%!n6Z!rD=txDQ literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/request.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/request.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..af0992e28747e5e30a8b5a7b97552141f628ce43 GIT binary patch literal 8004 zcmb_hT~HiXcD_B`^UnYS3<&Wv4M-l14Fj@%ENf-iXf%?rWnc~Vu2AezGu?X4u1X&AlB$)Jhg2n%f<-Bf+VY0fDyjHwY^W_6 zzvP_T(=!8BY9BUN;`aSL_uPBW&v)+pi_hmFkgo6h*NN{33HdEntYkL}+~)5%7(ren zGLg9yNpoWyhh`1xN?lCu%ow6(CNqfh< z98vhGJ=Q|yFLeMNcZyH@#(Xf|GgfUQO3h^=dw;=w1YBSmtCg$9{BGhld8iw!SNyUs z=Yt+-W&AXbH9=do*=8eWiCpt0k!uy_M|_dS9%awe<7T-sAKNSYl@__~1T+GN$13~G zveKsPnXolOWvqRY$n}58jRlbx>z};WDt+@Sx5y1|+Q-Do9=TNxyeW)z$Zc{Xd^;Jp zO~CCQSpUp7*Dvj0UnLbR%k6SAP}o0f>mo|SK0@*I@s>qX49YB%#nc?RjSM+ zRaqKODW@{>Y>d(j{Ty!(hPw1je0)|{G$`B8BvmPu^FQ;gnm;>Ev{eF44=1-jmZZG$$XS zy{Y7Q@ARxbnNfSQGzGOoy;(h(>ZQu7Sw+($)3dY&D6lL91p zo!G_QEWd1cD>iV_0pkt+Y;4pJ@JJ2&=nMVPnBh1bJ0Ba38P4d?;9x8|YB-06M+b%m zM-n)}N>~Oh;Wl-q^+_`CnB(Y4teI(!)A58@`lwiSS&TH?=FxmGpX^ zQysd?>YnH3xH*SxLrt8sQTv%7mGgMDxbxoYe zP!XhFp`e25Ww9tX;-n(U3e_SWHvIUsM5VNNMNy{XQYv{>InJ7q(!hjx>C!08Dwi&G zi;^sBVknVORV9HMeVk3{VN*gynmb9F+8DRAu}n8Asp7aIO5%7XlTswLTTCT2y;}r! zHJt*hkrE5m`l3!HRYRrKL_H&hD%Cg?VXP`ieNv$!WWe<}&FHD*rAt7wf|l8un3%wx zX(@39jDncd#H6a}QYxj$I|+kz2w^wa51EaDgDbOk9(WdKlBpD&u`W(!k}8ZEpA{3C zbXqD88(}*#2g0TqElCrnY36EDR)AjREuf`}GfP!Its()cOjAVz8-`bjn=D&3aW<0` zXCxJlP|GGJMM*2|xzjWtJ(dCKiyZCTvEsO-B@=Net523!jAl|9wMSD>GIZD!u7tJ= zL`BnPGE^>J6BDoy&dtzdj@kL+A|oh9B9Tyu2^{fI34uenHXHxLSzvT}{s2bgq=ud+ zo{$ogzefRZL=UKePBW?FqMGSpb9QM!?3$FGP5~u$29XE|g{<_9r!t8v$B&EVotS;7 zXUX(5sH|ALqjLK+=z@Nr*c?IIA4yABlz35r50rKGDb&(#c2TDIJk@zh($kXKdoa@1 z84j1OqD%ba3LOp|7eh#-sKwo4s4P_2SEdn~FOm3tT6 z4%CEV@L-M%0gaO(pn@AU{n2P_cr+dxj1HY17(7eSXBiF?)EEv~Vc^DTFlJ42Y7|jP z$qpI}kC@kFc*??W)b3UX!?!~&4QKJFB@+ABKh`?_b1<(yz$z4`x8q;_uG3Ghw}Rm zFFIFiJJwvC|LOGS#YY#N%T;TxHdg5_R|*bN6Zpx6mE4_R-&(Nmap-_--F*Q~k34R77TAOkvy61ad3V+g{)$d93Loy>8sS69Fc zs9OMpgYpQ`VXT?v0QkzB1(sj0cau3XRSamXG5EDyKEjO=Mx%@9B{&2i+QX4bP;!Bd zDZyht_ZrhB@UD_Lozar$P0`K3^)r{yEv7S96>%b&Qqb4wladbOz!aEHWeDBeOi}}V zpHV{Kek5I2($hMQr67P{o-61g2AIg|S;`!SNny|sbS0Gv+YPUYy5r*jxeX`yF`z{$ z1~~xqMi>aEO;8Kl41tZ|fng0#+mbxLrs#2GHEwN%Vg&T3@TVmp1M#aSF7Lu?_gwYM zr&qdeyV?tNq^f4&*)2cu_?H`&ude9p?tQE7zJkr}ZqL^>UJt(&e*3Y-XrYRYTRgPz z?1L>Yscrg_@b3042dQsgif(wT7oIJ6pc|AtMr&GUc4&u}FfbLRe=$yk4- zXkdH=kV~FLNs+{aLUk#rmPF8$jbWNhOEj69HIWL6kA)klA}2w>09Z;uh$;YVlwBwi zsh4rY84!z}RPu@S(&=m@_ri-RVt@)YVj5_P zH3K{U2RS*5s1?rCIwFhaL0kZTJ5AoFfrJyjR^-uyMY_n>=6RDS&o*wmhV!IbZ$sKMBA3?yc(8r-%Oe)zzwR zZ}K+m2iyN(D^OJAz`eRqzIFt<>Z>>E8wz%tFYtAN=iPyA4NcC^UHt)aGvMy;bdg@Mat+^H35nPMWoc9Y$kxGOJ$E`c*j!5Dw7v zc}2afPv+X-7%}h|&>>m^DY(eq8(tRY#KDZJ7>)#+mh+&57Tc;31OkP4ijjcmpW<@? z^_)e9>eD;vBec=an$^UKaf+aj5;$-UrvyO1^ z4yL2Tu~e~wxqj=e@wMRG@d{az?Mvic+j}-^r!x13%`(F9QWmw!VVCp*T+Aq-cZgph zcsn;bI$ScWX$2xExtrN$2(-~kW2B%Za}Xq}GPC3?{sps@X7kf%Kfs6sZYT;Y8WvMX z(STu~246N)15%0}fzVNg823P!EdVn!(+E7Ilo%?iLXW8nyF!`%Z}!7dAyf+pj={Dj z%%B`LWhw$QaZp1G#283OYKYlBSpjC#EKb(Io=;}7DHdFcp;3(PC*YMXhR=hbh{w&% zD6$zvG86;P6li4;otFafLH6=y2ozcp)~((V8cK5 z_+b36(?3tI2M#Zu0hE?+72h9tXW&M1y|r)IeYZ)>H#Fa^Z_bP1J7V9O*!OYkx_EMV zAm14LaZSNT>YKjO&~SaP-_`Hsazi2HBUEyW@D_v*yp?F7o4NU&E#TiRfscp-rXVo4 z8Me{WK%K@Q1F-4^uJPe!J?t~=fI<{%w8Wo}jh-7iJrW-rg0Swp!|=ulab5h> z(CG{8Drgr_H0+E!idSp!Am$K?Ng85h!;@Ch89IA4smvG-l?^l8qu`T^?itx-hCb{x zeYC^WcKSTBTjH4xB57OtDvRwdiI+<5+Nj=nWAq}7{73lHzJly4z}NeTt7>5`?++|G z@?QUsPAr}Hvy-`j;#7S z7ajMSTUTDX(f`hcciWe$aUetGx83c(6Wng`i$+o>uKPQHcyrrQb-`8Z4&C>+tenQS zQ-!^xsb%>)AQ5fB_be8>K`svq2|Z~c-8zSetsb$!RDyPe#^r{`Bn|KgdKw{ zg{x^8CT@H2>9Od^DU!;y6A4)u=Gcm4MCQx z2II(R!Mhv~3_F+v8>{n+ghUwdT&9`}!x%lwV$N)aDTk9er`U+&$>^+u94_z$N z83FS2X&7bHKZF+J#t_hC1GYq@nDdwCS}R?^l~CGE(L~6^CYsXw2>zg929f||5RTAi zAu}8%A;SR=8OqVa=7Wf!z;8PgF@@n#uHkPo_!AIAu!ex|Sf(cV*smzjbFt`i_?Chp zl;N%TRmX5o&`eHIA;dKN*go8U>U^yDlg|i!gwZd*=^BA}R)q&F+4|wd>@vIq?0wBt zNJp{J4L|yTZ4wLMz0@HJuCIyA5r>Za=%;aBh|OH|oTN8qhGVtzhHry`Q=she7s+ z{JXUaF+svBKzA&`q;JE5#eT%>c+7BGN6MAYb^wffP)wge*Jhjo- zdOh`4>c*kf1IJdoj;%F5xk~E4tR}(laI2&RCIq|kN1n{Lb>RQ55U6v(cb?z~i^& z2>Wi>gPV4!ZyspjJXf9!G7;+z_vs{|xus;CYLB$47q#1z#Coz}N==S}u@ zw=;8g?l>bW;vo@8X?SrZS_z>(fP#2LMIh9?0uN`!lFcfJNVE@qJK_jIp7>_=HoiE0 zV5Hlb+3)Ype81m!f63>w2*$>%f324C2>nxT;-N(gyn7WE8^}gBc2ONKVl3C1tJU>I zL#=f;QBN)=>#4;Q>@NA1U=Y8=lxr~Hg z$h5(2;Ucwc%C1_BJ6`PqV?L{38L~GFn018k?w?_?fikF#uJ_A(YWI8dHFN@r-iaXe zDq=cD?;_7wMK|?#(JEH<(&xVMf7vDX8Nt@Z4fK+2Ud9xeSlia__cFeP<2;IbOJoU* zZ!Xiy4Ng{)m{mrlFR4NCl_>u{FD;iTgFoZ6+VvYUmIx9UJB9m`EC*o4c~3wY5(L$ zo%HelJTk|gAe_kmEuHJ?FhA=ijYR(OVBv1-POFn1`!a>+URLg`d@yqR1wT9K+-KR5 z&gfeYvvVC|uA7oRc@g5@8Z4lnWybZ7@VNdfZm!~EMVm%=*M2)Hz=f||Rrs5T1+1`8}-PJ2v4OO%s z96@MJ@AImQkyuY0j8}VJxz^V2X+J$?pfzJnZyT`3EHB1l&9>3TzcJz*Zs8`x!4PLn zUq!`)brz0B)&3mkl!-p9xh`2&?8C{jwL-}f1?2HYr9wHcHe9z!0Avbs5?vQ=3T9Qn zo_ZDFF@O%W36+G!NtO9^0stmZzd(z`uPReuv^YW!wr_jjb=7A8dEX;f6#~ea7cspo zL{O@@4)sLo;=;n!E0B&=qp_!15>Y0X5MH6osWxMKW;vX4(nC~<-mK6-5q9ZimffR` zOMA)oKF4A}B$BHm(rAs-n*opze6P$6&|2!{bc)n`L7w4~>)-AonEo|{(u4P= z9}SRS9r`rCH89^v&v$h+O#b`i0EoG4TMxc5ajs;%z($f&6dSz-iw)UVVctIg&G4ik+apbXxmZ~=2XX++66UKG?*maFd6+52$PJ82J=E=$@g6lj)Sl@ z90RitRP1$WX3YB@1+}k8wUK_c_{5YRI|XtH)pEJo0ROaHX7b)cv+oXM*O#=!Buj@m zTDKgx6mdp`KMATZyT>~Ukg9bnB&h@VHDa=bD%d?szghR~hD*<~ufjXo#MIe9`^Nb1 i=#|gW@qeK2eU4t=O&-JN@b1|+@Z0!l6=(5D<>Y@AuHM!F literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/retry.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/retry.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..dc09b19812574ef596744b6ca25376e9f4bca7d8 GIT binary patch literal 20254 zcmch9Yj7Lam1g5fyhwmA@J%);N+Ku{r1gj`+Okbiq$FFWWQnm8I$987HziPbFx`M9 z!r+XYajK{!JEol3kurA5%uH${kCTn7He2QWwNC9;O=fnh1{5_#q@z?ZHQw6wuZ2zT zX2!qvJNI@s018ermF%|V+xOk~o_k*RoCE&X+FFl*=XU>pTj)3?2>(b0<8kneW#?%N zdI*vrS>i&%GHbC=-Ws>gTG`t+Yh!Qwtew3bvkvxl&N|t%$lNq<}G-+!xtn3|_W|>OZ1F$f9|p$z&=W zO~+D6bsA-NI(k*Ub|n^>b$HjVL3AE z{1JfzYpGFWB^py{S@sKZd;#w|eIZ!;xl}5Sn!xd>DxaE}IcH2UPunye9b7;m)Z7+i zVb&rEv(_&Hm1LV_eFC*CXJa`#>KrWRM6Skcby05F9r9>(=jE?vWHo&%rlwQM@@F13 zt%x~sI+c_)XF^V2NlBV5qr^W8OkSUtmk7p2vqL7ReddWJ(?*q3#W7@5tzMC(m;(4l z;;DIdFw-Hs=88m;(S#g{Xr4$Uk&-fT%KIXbuV$igy~Q7il$~ZI@{X{Br3#-N9Z4sa zMwVhr!|AAUSxygU)s&KzjwmDX*rk!BWh^u~f_0*FXe5)4#YYr6y71Dn(uDCW=|x8E zLGpE>;0tcrg9UfvpPVgtJ2veddPPg`eS5FcXN;%-eE_w1EIWU}sJ9&Svo>I={W56y zFD(YP&N}ouTUnh`ud|oc)kuz6m*kY)`T@BlxAC9sK+Yq(BrpDROJ2D~@+}11!teW^ z)Fsuv=9u+J-BR6a_F1p&qZy^1%6TPG^1tSImv38`t(AJE0D9L+eNsK%erb=?fOkOZ zmm2Y|m-b3ccsEGy)qep9b zt2A6*s?1AasRQHMq!FnT0 z7vf7itB6aoGOP~~2f&g6^3==V8!-vX2Fxne=du5ywGl`d)Q+7e1~Kr+ zXh>f!mCKJPrbaKtaYmPx#igjK#*&xCxw)xmT$ShM{{O6yeN0~+6C^4}QQ+7$CAzeP z#l@21*nAwz8=Lzho&AMngHx;F3K2FZW|DDPRT(1aP!OXE4ng1Q5KYHVX&yp|9ngF< z!?tctYA%6^G6TQImZC~Df$?cE4Ot8fCQPGehKgb`lei=+VrszvKe~z0cszA2EY3h& ztKt&mg)GU*d6}Vzm;yQ|!2e7#t?EQX(_N713pfc9QFC*YSL6hc3agEQz94kdSQ*w4 zO-kYdJ|U9u7a_OUjOMyNf96p>?Lssbr(uMa3o%7av!yRrTZ@hrv=|+h?CUX*#4?u3 zAQed^BPKQK1N6DdfTxpi34Etg*Th6L3Fg9y8v+;<6=yt%31H9>fdIIS#g;8@=8B9X zq~q1Q@$&+M0-xb$YfvWOrpoN(*k%cy;DD;EfK-P}fN{jQhB;L=laR$LU|!I>L{QCT z@DLy)L5h!}H7zNrd0?A9CDSs>mS>*hZ-zEu3_I8~w6}-BMQpALtkO{HD&PVDMI{{& zWsBf2(&0m((qR-`NCWq1I|hiZVYB5h(t!i^Pu)xy8Ql}nWxxkWse;oD%L@x&%T=-X z_uM^a?o}XQU>bu0xG>H<5f;zH5-}VY5eg0{`f@5p90Z~$hVwRtn45{GQcLBF9yhy) zm>?>Wl8P#w2{Y*!6}bk;R$}@o8zq! z9OS$lhqgX9_lJRA8S`Nb@^{)WXU?2(%9e2!w4fOLri}HZuSCI*u|?t+IwRvcN=ZWj zY8VhO=B0zBhr>`O(?sm@l{BeYe=u5Q6aGJq6qcn3zwN1|^Cyx7`^`YnQ0NO1r+D5^glxD(%pE5SnV?=tW#STW`XM=V zeA!U)faiqxOf}}+ME#q((m@zP0vxbl;v|J*HusIn#1iBZT(R~Cceky3h71A z&4GPTz9E{JG9rVAtD+2`7>(v!tP>HG9126Dki{`v0hF;hQURC4Cnl%Hzj$UQGJfXF z*%v2IM4p?RId%5Lg(~zGE$JcbK0xPXfB?s_%z&iR$HRc%P0=ODk25p??4ifVkgXi> zW&GhGz%#Z0Tr$2MHup+go1hKEBR(HvnnR4FstG>*7 zIehoNDmYa+Ixsyn(lCdO`7h&j;nO6B5L#6fZ3pg4&1m6F~J{rKfr zDxsTOVSAUBcP~o8 zS*H@=OfrTQCk94`O3UOEujn_EitkSW_WE5A{EcIou^# z7(a|$!Tm@sW2icca-3q_MYfCKamGG*chX|@Qz3K$BR9=j=0++c>-ou<^IwjPPt8o8 zk6f4;pZVg2$i&$blNaU)eW4ar9!Qyv!ms%HD%A>VGQV_zHqOik3nE`1yXENCfdwU% zV90J<(SViZgknw;OG+`aSp&6+jQ9g2@$h7XGID1{K?r+(!Dl-tufB9LZerWQJ1Sh z$z_(@D7np&2PNi-qnex-C9m1$L&;~BYVj>AJX^E}^Lx2ElrQw-2bFXosxp@srM=@5f4GS3PYxO8&DMcA!ZEIG?! zc~7*{V|@3|Ew?Qe;afqwuq^z@cFppRg*;yl*wbVsWYw(UQO$Bir6Ylvcn@Bmxu3W! z)3rf)GTX~=AsmU2LKumJpCB(yTzxWZcKHM&)D9&7Q~0MF!Y6|Du&2=8u{!?x$(tu% zKmD-{<$qS`P`}pRX$duG4tBlKYV^CEW+!`#LKA2Xc30F~1}SMaNJ}lSn|EveU0SDB zX9#63WHql*hLDDbi9|>_BhdV26`xzH(RsPnPExNr$J5+k3|SeTx-@koLt-^9Q(6qy zeM0q`U4;ivIf^YRR}*gD0qI|AWCpA2ZzPIr=H#%#L6^;9)IA zr_eLJYX1jU2lKX75QP(40kK+k{s{zdTS%K^Al1j<-OLG#CaXbD{rR><0!vyn8I4gd z2xtLmFVd{L9<+e%ESfB&)QlD|u|<=CRJ4GhEt>43q6G|T(PSDGEiSZ}45Fe1Y-_Qh zRAc0@0`r?0RyhYm`C<(tC~OoM13fI^Uf2`<6eoTo6JH)4xA)F}h+DM#RO~Z>UkT zL%^s1(35LU?itkVWT_6>lxOfo&3g5k=493gRV7{zy5_`egLg6O=5&nguhFI=qyi-T zpuYJNp}xUWXb9dOd}FX^Lw>ud_4b)J&J-QUgL2T)_C{N=hDt6W*na!s8yAaiDtQF- zeEf~ai(V@EgvJ&&M=h1=gs$GL&e40FqeVZJ144J-R@cFMT?dQxRBjMD#jTF;y^e6P zk;+X%Th~_Wz`fRiVl$P4LeHM9?!))G4;Ndg+*+Eijmqspa~oS_2bDU7fuXJaQ}^~y z6}zb1T`KobSuB067v)uFai8G!zg~N@cJ0!AS6ji~_O0~ViEm~%{Cn<9A<4V;a86N9 z;iNDCtd^aBhYUogk?vb__jByO~10#x{wm%F6L#J!3*{3Ozl zQyIZZG*1i;JcvZ7#tIRgW~W<#W{amTYYs`il(`&oXtw#dO7SV|^31-V)#!d{%?ku& zmj$dtC6F`eqzfg|t09-thEOufbwFnI%jgWD6cBukt4|er2lBm#Z(V+W&wo1b9}lda z{LtIHcKNN$eed2vWBcm#hm9?FT;G23UgO}pwCehKukf%m@aOu^rtceOt(IEY;{beP#CI7)|}ruDN&vbAmSqw$RRjh^4Ekizk_D1v@qIAJsscoETzwQX_2;Z6GatItAT$U=`@ zv8GKOG~H;-C)v`?Mjqp<2$7tL*1LBNq;+Ob!@>jeYm^}=p)G=K$O?e_D!Zh@Jge(z zr8tE#g?Qqa$ZU8XhCN6sWIjoBEYh+=;)ayqYSb$U8R3GU97Y$A0f{W=yq4=KorbRE zx}Jzf6PKjuli2~zToEf2F%(B~+>|N1de0DHDuL>Tus*)k|L8{lqwgQi_dj(*U>K&5 zKKi;#W`a)gnbt99elm4uGwb7ZtdJ^J+RSw z;OduUUS} z>?TQLU;2}?84P8`p0k(8wVI}A5Ir#xkhV$CIjdwdc21fXNtWqs-M{*ZI{4D)@X?D0 zkm=8M>YfxM`kJ&2HgR&pughr^>c)6o07U zFyZ(Od>%ON6nu5BKX&u6eAC|bSMGZcJ%B7Zuo>KU^W=v;{cpeWomaMc9^L49^nLGU z&xyRRv*7Q^`}aQx?#b^v{=wrP4CnjLZ3dsu2cG}1t^4hc?{sXng*V#5`H`nK+n!#1 zrVtdrfA|MSzjySn9^VLtA;lUX#qNCd+as$r+y3Bc-NT4XM9UC)4jEEXsb2{U zOof>a_J(DdNhd_C8w!C_XzAGs?%N3N z+X@bD1PAXP+YBCE^=^BEd2e^2v1QxexaHrw;orM{b<=+^?>hJ!p!x!)WCBBn0gC2R zM!tZc5-jNf)h>!9I9h~dKs#ico|yuN{v*t%s7N#i^F}B+^}Ro~89cn|{kb;?zWn+#H=kL1<-TtZ140wucKOCkWSYe+pSNv;S1|R& zqN^vuZ`r(wY}mXIvU1ZPc2C&KcCXw(E@b7@U84&ol~}fMsi}+b{pxMmCXNV|wJ#D3 z_F)uY&=A~e*uT-Rf3qR9T2t^gtVO@^M8Vhaz~y`0bJMf-sA(Q37Yrr{u3(bSQx%k8 z&Z0DdUaHX5F08ODlS!cpT^V2`YzSGS$FcAW%!Oz86dBT+o<-ewP3p}IIoWhSIdlE# z1}HHK;-jc4`2FX&x0#bA0s{;R({0zLnnW&F23DqH!QH?tzlKYK*e-@LFE}{}5Np6( z^7uZ58Ng{sQA-qRU{1&ugwRxYN#F`WlsY=Z5Td7_T39UidXZkIHyEx}Og%~-7IQ-8 zQmou9^W&7cOiS))@ELCNdKIUqyoLl7&rp5^38S#3bOmuSywiDAm_gzqp%Cd|U?mNL zFR$A+upA6#7z^AS6y0ghO9 zI6;++O}HMKSZ4@W#Ru+9BX&KwR$@u~!8lXRFvfu|Te8_nikC;I0y!S8$@>xPfDl6k z{$w?SJUcc5w;n+!AvTMSkisIN71HUO5Z4c!qK|R1M(~9mdaU~aVIVa7hwRD>R;PH8 zXmxNOT#hB9ajs}8blH7JCu z|JK-jXps%gTMhji4gISV5BzO+_T29|xamKXcO828M2HgEiG-0USNzIPq;z#(Fz+i2 z%73gwnSqlz&dNOghVO?$7nv&%*J8RtGeDYAEGF3WK*!xDb4k7o($T{k>GBhUjPgg`q$CXW7OIN$U1rhh!| z8h;pWgslv2rbI-=?nmhY2BX*R$KZ93y zlBA0wC5WmD_%fX3{D@0qisLTF+1+ig5UjaKf<2A+NzXlR&-&C4&V298UroQ?zcn_! zfq(teg~rx`zmbE!oDG;vU4W3m?v(jUc7j@P=`QeTVRK*YmPzjU{C=dJUjCP0>a;C=Rv}?p@(wicA6$c%Kpn z=yyvJxrEsP(#@EMq=9>+l~mk3$Csl@jD{c#B?D(UNRhZ+DF%YMl63T89$Ypb3z9@f z3Ue^0GQ=uPz*tg+d%A20EnoLpBWFs*aw%p+DbQTl7I*cQ?-c{FIcjDOc<9w-t+Y^c zS-Y^`7{)(44_80;7)PNlvVZ_ERzQxguk_Ok;JZ^l>datBZ29dxD7OI`3E-q19yY> z{i7g=ZL$D}_q^izOYfc7I(&Kq|Ms4S{`#T6vA{LjPXt@-Qw0nRjBEr(KCz*+9q9SQ zfj3#RyT~MPY(qSjuRpfqb_6^{!Qu9BD#NGEhr}vlaQBh>~ zE1yF>=v#$a7Mv%9*Ddqb%fh_%BIY8En{3Fptlx6kaZg9tO4MGm8R z{$H_Nqsv=x9I60?Ng|vKXu_GO`V{vchiZO{*WxmEVW?B&tJi#tKym!^D~bxOO7r1( z%}AJR10$bsdEIyD*i)DV$LyP1g805c3`oHm& zviC|&uI5!ou12zDA&60`iY_bU+9Pwwu4jcDdsR?oh1_~o+=qyPsOmgi@k#cTTEt1z z;eS7Nb_o4U%WmnTa4_h5Q~Gi)28Xiy?(YBt*Q@^v`($&c`*DSXK^G*$i5k(`^w zb2R2GuhyftX7j-%RyZUW-!IDMe z3Z3j;qgUyT_#0Qwo%0~N#+R%AVa>ZbwXQVe8W!mau_zh+Gj8f}ZiMy~XhT>Hva~=}6#sl758SYrRMU0Wd z#GHK04DK_3<7a#~y!+SUrC4o!wWZ%}Grs~BjcY&ML=hUlJB*QOH|FKC?6*3!WZD*~ z{aisZ!b_pP={HoEDKhi(a1kzK;_>pI$&K-i61WKXy5R#R4-T`^uBWD%vqh`PB(Ek@ z*OJ+WbSlMv{bocDsc`&!8wdVdMd2hmW&2MXF_$=2CgGUdY5-x`$M)}4_lL+^8fxKE zl??RCSxUwzsTR-kO=|epl#pJgHFFaukNY!!>aM`~CTO)MC#NURpPqQ*wtA5_Ae(;*=MWgqlkFoI;$A8A=qQ9L*7--^*&=2-Lj! ztN7g`T)a$0tlWX-Gu1%gGz(4A9Q4CZna3&-=ixz8fb=Wjl%0OULb3ZoRU~R266?7#nCqQs2DlEOd%_SKF_=fwh^f=I};y_-^KY^AT9@@4)2T z^B~yumb8B4&8v5hya%trllj1th5FWfeSaa)a_5m-zFRfFs%=viu*TVFW4@rASbb1&Tg!i!a>YR=d9LRGqBx#hlP$5h+?ro3M)1e)*E z-}2mY{HnJ3&cIgtV;k*{-ESY;_P6BydkTTpJL9)%*Ib3Bfz`=E=#j0^$&Jv-&Cuz* zZ{N@Tp+Y}a*;{Dtx*fR{xjFTzM`-TbY8u&S8X+54%binipZ$xog~pzIze5Ys4se|}|ul>#! z)(_ov+7vcr=Rs^&qi3}ScVoVsHv(f6nu^si+-WGYe#T3 zdsf|uDe*OLd3!g!z4yI)5RP`Q`QTfLyOW#U2Un*aH1w=H*44XHn+=EF59WPOeQ5ao zAA5h#`^)!Tr?>sBc~|Sh7Xy-ZOf&omG8Gmh^DNt6UDyLVo@# z`W{*+n5>G%hZYJZt0I%p;{2`;GOA`eTQk5ezQ?kjA^H&%`yqd}hW|?LSk_zmq1>^o z8}=&pTft+WSwi51jA?aY@70K(kvO>KGiWdKlv6mNA}=YCh;iLB%C#U%mDtY>0arMR z!P)ZnZTS20b$iwyy?gk_WABXJ9eQu^gQmaf{AuS0bw$B)*3tyi>+RFGPOm+F=jz@5 z9}mAXe7EO)_XqudbKs{3KIr;cv}m)`K5r@7Z2G+})W??kSv?C#&%yL#{0$M#eA{U= zj03YA3#RL4g*Q+Fm^ zS&r@N$5cmhRv~p?c^gT#dBXe|KK=a+V+-rl)>QGQhKwfmd46Vm-L!*Hhth?YLeVY? zDfwDWBqF8eL4zl$)bcsMK~&zL);^>4{N!_IUzm*0&k82bUx=KYj+~!7ar*q^#EjNx z^f^90@$A{DsmOEVUs6PjR-UDVv<=P6emTO;ddgR*dXW-x{Boz~tCV|D4iCmahvRTc5Q$TpxeMF7ym&t|t(7(&NnA zJ3jUZV(71XHhYfd?VTSxg~3CbYYdHpXxs+_L`Qet-U4$`UH_(i4@6G?zCw3jp`)j; zZ?MqS3z=Rxdaf|`WI^mLbd47J_7%kb!jYqe10xtyJ5mt$6!#x+3~&3zq62TTJ9QRo zDCZLVZACZbJVIlC(Mvg>P~TCkrCc3s??pf50z&(v#d^v$2px|V8!3kv$?jq^<$?&j zF1Apv6_Jg_Hp;aN?cK!=%5@42hl*X4>lXHgianGQt$RJiUdrvGS!i{|0l`zZ6GCoh z*3#_gFNOtYJr=nCKw#9)qv4k5fWVsW%>18xq=(3!OsYgpDL zG!7QsEb9>hV$sX8J|VETSj)0?LU53e2fP7`daC{OxXte120?~QA3@j)p?>-^QVSVy zO#B%sg{qVk60HV-jqq<>RwSy5Q=(G6lQUAyjX!pv;9?P1dE}OZ?pmtipgtb+2Wcwv zi?KKtu8@0ZA}=K*$hnelr_dP1Pa|t*zI<*nGI45h;@Q*FC$)P1F<98}14|VKUX}4} zt*+!tBh_6YLr#f{YHr*p&S3etpfUbHVp#J`<2TLH3`NWEKW0VTo5gnSBDc?6Pw+ph z^`!Ej(FHoTpc3^$`dTc%6#D*A@clxl`-M>Z3&H&h!HdiT+26)?V0Z-nY@b h?^6MVUk9$#SfCfO^h$Qw2{9itf8SwxB literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/ssl_.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/ssl_.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..d2082d19f047aa5a1fe27c129f792f330c7cc635 GIT binary patch literal 16542 zcmc(Gd2k%Zx!>$Pd*dJu0w6HB2rdCG2!JPaLLf*%A_0g1ZEGdH<#K00EVu_eGaw0g z8AFQw3@55sij|OlPcILuxKdQfFJY=)rBq2OQRE|XB~@=h(1q2Qj^R8dDOD;}YmqLw z=s%L**K_OwqV()kjv=?_n?Ano{<{0?-}iOnKLmq54$t+j|2X@PpW(Q_rVsPsb;5S< zCr;$x&T%3q+R|Lc7PHxiwx{heJ9|4~4)%7&ob2t2x!BtsbF;T6=E2*M<}==ymz8y< zeHnkup9#bQnP4o4IG5;7hce+o>LekmXYMgN&bE*CMCC_XQ6a^rX$wDdKON*Go7(c)`O~aSEer3ZR70RDNd~Z1}D}?ouc;# zweLWp^u+e2xLA+4OWG&aJ&JFyF4y*0JGj<^Ya|xQ)W_;G`(yhvy|La*U#u^4Aa)=V zjYTv4vHr}#*ul&|Y#_5MwktCj8?z;=wZghfv~x*!d0DJ4QvZ6aSBD z9TdANYyG?yi$kB6^2PDupx6x=o)8a-dm;NV@vzu~_en_p$Y)E6N5y@}eQL?x$w|Xq zob0r5&vUQYUTwOj*m}$ z=}3I!#EG-9_}MXyr|(0cPA>Cvs=ClW5FLm(J{C~!V=N%<<0la$9SF>aX#8yVXr5o^ z@=(KUsk!oY(SGSgj+>@92aD^?+eD}6YT~XrKr!`q&6#(IZc4pslU+70?-V^$>Z(nF zVnrIiEzN7BQBH^G)A=v?BZ0(^(6_Uax+rIb8F^6>W^=MII<=(E<+8$1^jP$GZy(;r zqeHy{Qih@f2YZD?Rura|rj~@GQDo^AuFOfY#Er>NOP zMv6ne$xBK+nagBy**HZBYEC$rNGp295^;Kc>Kr^tH$Isn^TnNoV1`O7II=VE2;epOAAYSaG>8{ zHgtICI4h+&DHU_hgZcC^&90Am1ezzgzy@*hz5$KBqPVi1R+ko z%|%>V?REjPk<$W~C0W5bi>I=)Ijx%Nj&F^$@p{;^uiSXc9 zznWR-Uq~$+P!sY+Njo9N&Cn_O_>MD=e&yuZIs5_ya|6%bNGLH&U$cSQ}g$ zDb(*>^%tvJZanvTc-6HPY`k%DJ=k$OIIy;O%l6jtC!9UFw^-GDzb|lYwkQ0om`D|>c(0Ih*D`R*^{^D9eL+F#`iQAaZD`plM7N7t4&D#RaI3Ll$lR~ zL{;SqrXdqc#G{3C$V2io21u*l5fRTWW-dsw+=OamlB3*$K=VP;Moz7zOk)5rkK+S} z4j(M<;suCQaY8mkd|c9j>qv+#t>lWYPg#A z&FbFu>fW2rY*Zgzd8Xv!x`yA4t#_U(IE5{L-6xzQ;4boApKvzsIon--YoTrM*6G4i z(;NPolFQ+8%kAIjgloIk zhp6kE#KmkP7qbH=+a!l*C#)hmKsg!Z0_7%Z$rItV#`w(hQ)BU|v9Yu9(Xq2L*bZjm zC&ou-mYdZ@=%^R;P*LSR0l`asLNpqENed~97v`m;I+9i=pcI#TDlJ3K-nN$mx?Voy&MuD>K9U3wNF6s zlGYrD%;R4gJ3Bo-IT4?kjL)2&Ha{Z)EocbrxpU)Z$4+R?PmfH;C&rLHKKk_7=(F+B z$unnAZerxjm{vVG6`z=-sHwBqios6{=utD{qtA}bXyM7Jv5AW6wE7(p@riS1o*Fx= z1*XnU&PCdC0Hr?@9M1b_k**gvj9m^2_WNRFe$g=uNKw+d}Rx@5(#TG|8v z+@N2vGjxy3sNP5ktQcdj1mo<}JrG0}v^L~>mzw=i8z$OkQ zRM9f%GzRmn_NhU$99kMS>GIobiP@uTPCL*_o-@DatIK&!$}DrurPi8p^E6L)Jb4#1 zry*5EsA#2|S}A(+u6f!5cRVI{Gy;X89thb0Pyr5$DL@pZPe>-R!Uc&IC+6(}erVf;CE%nqkdj`- z#B$3-uCl=l9a3)=BuS1wunlY6a$99(s3MiUoJglcAuVMus&m7_^4^LJiXbA1P#MEp zQDN-r0#qNW?pWqK`h<%}>3Cr4hy-K;Aeu*(7Sf5Nq`A_$E0U}^z*P%CIXr#x+{9@7 z%*d4H0DO?i^w!)`HVI{~xzR;QQ8njWCXv)aKv@v56gOfWkU_+)IcXd;e}(w8pq?YH zw_M|~f6dJYTLXgItPI#S?|Y}M@9tm$5_>0V3T9NeghZq^)HuQ{|)b7bY&ySo~0_&0WS zt(>_VZr%*Ht%uvzf*axJ%F`eEYl+A1WA8S<8!R-O+z6d2@Tcy(x!oOWy_+3});kVu zbR5}eJX&zp{i>$v#-Zl#>i70!fMgjwZ4t zb5>Gv>C47~1nyiU^i4)cLI487_L*d6f|{UROE)fzRkA=MDk3Z6Lo48loLGn}x#T5D z6=;%>(b=Do09-|3R?cPgMX#gsnir&z0?wBNnzm;O;!#yAFGhQbwz;|uzJoLZ6QMrDnLkFxFAcH zQ_No0E8RDp6P9v|OgBI$Bmtj<^JmBOP5C^SDyozaNs*lYoHnP_9!1DXK%bHL zrSn+sG9+v$A=p-W7tjROpR^2?OL|ZAL13-6dQu(-F(pG+z<5K)tpTYV2t#XWF4nk+ zOFo7vK`@pYp2%X!9;65lG)6)NWO6|GZ`(C51{rDz3R!c=lA_QyVJ_urM9`dxv-K`Z zUsdE;B>!{#lyL-D$@LsxUGOyC4Yw5dmXAEuuSMRRzT;`X8>)LFdE@w+xDo1Ibrk)f z)kp5u?0&QJ#+949*W0kbhgL_6;hI(7mVZ~lx$6rS)4xDHfAC^@@?p#5e|Isd*3Lg4 zKx1}1YRHTLZZP&(bMY+;Y&6rUOOo&zQL>~7`4oyrc=>U>e2!< zDO7d>THS#iOHLww+c?#l%q#31`4Vz{KsgD$Vx)L;q?!wS^Y1ZIU%UDIdfSnWnxm_u zcf)nx`P#R?_U6!&}mfw|m zAw8fw#8`+k?~tqW?)mm|ev`^uvW5L^Td7hz%#`^qlPbTn*krKL*jM(7o@@5JUEOP@ zEdznF7_x5JW5w+MObl6?>@o7d?w^mEapia3PU%T|+`_5qfSH(e}dG|Ee$*GT;Jm5rjkaPLf5z9>+OpuFa6x$6! zX>uuIkC{zfT!iYtr!bsMV`tKLA$4f9}L$foqF{B*)Uull3}~djMA2<&@kB22Jk^0 zVpKSXny5omTeNI~_Xra392+kK#gO?!8DW|%!tA21R5l}VwX&T%nxQBD-)aUmWdc?Y zgvh+XqK@t0NT;4AvT%hm+YPOk(FM%Y9i5Gy8TrcinR932)90q9CeO}{o#-(g<-{Q*ZYxpYLZT#E5S0vd zchdRotxcvDAQ+|G+Ap(H2t68Reu}gU4P6>0D-)Wr+z_WoX&~6BaH7HvFtD<+1Z)i_ zfT@y1s~1LvM*jwa}kCdqUy>DGs{%`K{w zh{bDICd)CsplN%M=F(M(p)Y&b7#SjasE#4yMo-wjsC$+#v1p5t-jN+DjAj7St1vNS zDU-X*)S9X6h0B8w{K2R&4uO#&^tqbOIBd~)(u@~#@)GmQCoiSp4o}N=>{43o0uILD zBhQLBjl3kq6N~EH%tPFF=L}@iA4DF63{$)K$ z3-8eC@=4+!&TJRA=EvNN8xxPgcxH^rPg09UC>W;T5d@mYm{U6B&rwuhd^$e$yy3Og z{7ls>krP{jKZiVSar59#Yc{Ee958C35!iXD3yZ2Q70m;m4m17iIYskG*~=*z9@_;} z3IDyHwj^VIz$hdS4m0@jtdT}vwAzPkTt?&$5qPke=?GK{qKH1MG^z?YR7vgAqaT;l z>nkO0fC`+Hu!8cd$XUcs`6U4I3U~jcjpJ(yp51pt4TZ+%HbQ3${MnM5<7;mm`hLru z{-+8}qwAhg#01(3{{4mMNFjRWZcR(cZmS-#-E%lORy}w4wu&@-{TfzTxX6b$`Q~+;+MT+?ccBA&`wQJi z-f(PIwcoC4e|LOke9IGB`FgRYcGa`Rhu?T)oo}tAP{Lbvr?zXI?^^ZX#K>Fq#-rQGq)TYi-2)5xHqno?B*LQW_ z_H_S6y4c!7Db2<9Zt6qpR{LK1ZZ+dePKPU4j1Ey`uf;fW$Fu)#W7D7ezUTY%(Dy=X zUx({$HTa>wvAB0=_0*j}=a#=_W#YH@>$pG@POx0T5BWgJf%gN2EUO<6drltZesa`% z%HjC;b{oQ^W%MAK9vG3fdrlD7xh3vx+XOqZc{_-!4RA(j9?UbEWY9dAzeLG@jJ%|X zmO5A3Fuigc&q%zG7k-Y?gAxqR?p zr!BBky?MV`#>Qn^^ZZIn*?P|hMTcbtRe^`)SwVY@$2@f)8&q!0`&Q~JPfp%Jd+Cw= zWe*Qdc#K$_0@>w#C{qjGmc^@=pb%%smX8Ll`+{6~U%3~ox7B4XCZ$^50JDDB@|Jy? zhm7)pyz3pBt$415^I>MC8Q&ZSE3NuksN9cy$mEj`yg0YWg-U#d{)4!_-($yqxQRwCXvwW<%k8@Z|Ok>9P3FV1Q$0NGSkG!-5 zIv8IoGKHHXiOV`BR_G>6MoQ4eNk=unWJ|cE0uYYlphfr|FS4@3ANmNX}Tf=+&!oF66bpQ zIf7*{QyUEHree-ic2;+00~r$JS23*A%F&TZktyWG&)~cuh06ng_B22+^cjYLv7%VL zwT6QZ@C+LPZukSEBMS)t=-G4vhks-}LMjOsWiF0NL#-@rea0D}E1d&|1^!d^MYb8v zl{-SYW0TC5OQe~Do;C|ITc~1VU!rltF`c}$0FS{oewLi*Sj6g@#m_iC_+nvAjh&%o zjvzVh$8{w&y zr;GmDmC4`UAL6PS=!#VLU7Y$3e7ARPpb+T#9iXPS`*-*E!$8=9J|mF9pVU5egnPfb zZnTzr|A=?A%JKdafl}H8X(+a9 z=qX)GTKkxOrvo|*Zi?}#%ZEsf;(bI&h$7s^#yyFVH13#+2A|4g_+*%~I7S=P_zCld ztLb`F%lA)*g{O^svZOAgs|i@yrlV4K*bM9Ua}9NBwa{#v*`hw2l6mS=l%H011$J!fQ@k z3fyUlYTmJl(X-D_!3R4ra}wfn=5X^8cfoj5rE0cW&6&o~DzH5`=p|hpy@d~%g8xi{ z)X$Ya@&;Gu{%&iDbGlk?3>0_K#Yb<;>Iu4jD&7uv6dRg9^&*XB_%-xW%cl_}T;UeKVZ`~$; ze4Ri3ZtorbByRKEII-4y^XnVoCkp%%TmJe@f5*DNW9`tpaNu-o_{R&*akeCIKHfwX z9i)Ix=Cm69wyAlea(v?CB)hizVE1Peggnj|vbY(gs}lJyzyJuL%i`Eg)I0^-YmxsY z#nD-x{I4kZ*A%eQZu!fgmjn96G@ZZv6-s7Jq>P%ADuob5d_1V44>W`>#^ni7>&$51 zF|x@2hKjQ)s3{Tm1bZSOw);Qu=_QGcjt>4UWzSQDOVHCqCtZoKWSR6wujAD?*YMIR9XeK?V z+g`odT!v{_E(UBEMd;>1jUhR`YfRt_@hsQr7bBvlapoW=(l4;TrFe-+aG89L)W>Od zMak%t{66^oAMA?!L*n;&4VQmJschZQlws|9Ko)noUFdryRHi%Hk$^tzEIf&+@y}3p z*noIXmaWSvN*5^DN11}``Z>EV zJw9N^lJ`?;0D@P|JMUW6PO-CF-ttk(ewcz|6bw^9K6?343Lc|?UDJ7js3$2H zp@F6&=A&CXJPvGRGF5aJ;4Ny~TNE%Qy_=|Z3fd4n;2+hm<~=Tdh))}S zN+$*l5ZPw?Ph7`ebN-)m-k)>9pL0GIhJV4e{*von=eqwJcl?*!&{nW|#a9g1t^|s$ zodvGB7~Tc4rscJkmC#mQ^Ys^Be{rpIO}ROGtM*p1&~bddZn(hJz*Ak z21@Q`TU~K?OUZ%vR!vvQg*UP^4wO7Z@toUt&r8&!wKjLLuCe66d#k0bwIIey=$|5XuW-Cv;Ek5`>}UV-fn+t)v?L%xy|qSztw1@DtAMs#|rI>@IKJho`5DRZTZeVDmg zi%@K8rT=^P<9{i5%5JMIRyUU%L~Mn3ms~_Zx}nCBhmkyyUPk)3rmm8okpUuEX>`NA z>t2|}&Nw+c|E;!{+rXf?wTS;MZ4`EN7hBtlO?!%wJ|fyWiaq;_`+7^wVH;ocHIy89 zZv`7lF1%3`&F~Nf1Fxy%CCW!}exd?gy-*4g72f^vjeIOXA zj|3z2p>^h{-S05H_*$$x z+n!=$8}5h~Yj>}lF4i=!JgW!YdkfCJE0eFKi%l&X&W2JDIUgvrO}u|-WO&@m{iwhG m>BsCpcJZJ;c+55KcKy`u0R2;!jc7Ncy|v?lJG(hE z#`botxRgqEgT$g#vLn=nNR>iGABYq+RP6(m(kfE>V6z}L6QZIfFL~QwSE_jGf9A5g z5J+!lHD}J{KmYmvv*-WLcjhmCKZhVKZ2jx#M>Pn2Nh)??%mTIYTPQ3b5se^`5*-OD z=@@ZPq)aF15!!e=N1Vo+8DZe%hlj#{A zllY{d#m8b}DOFR1q|_AVM<z_d07)V(gZSE?F&0}Z|}g__6||RFw&^(vnpRx=774`@T&vS*g!No z80(A<4#x(g!?CX3&f$z3W{m8N?24P-nmHK-iCXbNzJMe&Lc!8IrYV>!)G1+29+l&Q zCPgt$;l41fdtx!-RV=1+u~;%CP9#X#7mK|)AtcP6U!xVG^Wl*;Etzgh%js54z^5gx zHKV3*M%;_r67s3Gw6P3r6F332J#7=3oM=A?ZJ zJ#PJhP)EoG57em@2jmOrG@7BaNTsH!EE>1GHRP;JbX>DqXPjB5NUw+X83syDk=cM| zTv=wkQoB9MRT|~ay0eZmU0`CZW^G~wTTFA?vt*Gin}H^~e2&Vx)n<+OW+brAYnRLK zYgRE!eOK?9rn254l!dKMTJV}IJ?<~-vP+`Jwt+&*kHEj6-BW&xtSzHf!Q9^|fww(* z9<9pOH@?O$mET#$p22>DHSPbOrtx)U{dP&@MDI0+Su4+!b# zg(fGe@EG9j@g(|0|2WxRkEJYaYa#nX43Jzaf!O$l$Hbv(`!mC4+3`)^?$1)T#vv3A zX2xD2fJBf*h{sb{Bqc4y4<6~{_wCvZD5OdzJnf6LNA_?W4{1!((g)kxv{WjgMr27F zjim7DwlOW4Xv3p%GOW=W)oP9+gN{6;BABc-CPCPzQ_Yzc&;Wp_O!Jd+LW~PoRC!t9 z<7H&wyZVNB0vreV4D;F>k&`B}LRZ70^dhCuMC+cVJ0(Norh3OS&6|B!oB=;;Cd> zPDr|QJS8hS*W2CKKN#)o7>eqQ0Y+g?cZiDau@PPOCxxk4$sgUB7Bp37(qtOllaNNW zBw)YJVks%eiU_u_6~d!fIIYuU2ssSNvY82!AkzaeQBe&THKxWpps@}fwI5Jw78L`? z7ntq(%D>v?ItBk%Q&F;gE0Lz2Ms1;f0<{J@34D zrRjsn`;mOZ?&a#;`QV-<&z>TOJfYm4b8i)0i1lCe&Us8O)rstNMp1X16c2g&eFa>{pc%k=F@8Vd#dixzuQ)zrf^WEyU zhd`!k!vjPy+vc1FkB`h|NsI6F-|=iM($KZ)LSFyH=K1E_vBhKWjl4T@)tTSay1cIS zIoGfisSZlfW_VDNEWVz}F|VK8opKO86-l6P*&`n#nIn5T{1@ z-T_`P*?^=*%+MuqePGwFou#mbppNW4$TxKGSQ?eEq{Jm&776drrcE8Ky^SfX}1mGWfdx^xF%_83oj@lJRoT3 zvW53m3h&xyNk{nCB9X{R{%MA4(`jM>SZgRVA_Pp6P1CG(Ak&-P#er4<&cW>RfW?yd zvqEA*vYauLs1v8g0scA?S|4B#FHLEZV)$b@T!B=P24h5+(OEfd&8Bm5I%bz$Sk-v&G!nmBfXR z3u9}0AYXvZt9r}ZTPz(I=O|#bjx2Q+;U=v#ew+lxV<`)a9JX$W=9Ih3lxjnX?#$52 zx__tdnoY!LAZ<*#vo4GJG-T=7fJS^a5>PbC z9);mHF->QkPohRyw`~K3F0_I+Hwilm+vV)(iHkny>y}r?UmFe>$KNE>lM1SnDgrir2UHPtl7a8>1DHbNaEMq@^kl4){i zU}&!-aV?KsdU-{XfawWjg?QCiA~J~7$T%o`Wg{(<4%{=SZviJ*0J zJ$kHnFxvHy+SaEB9tCPlE;c$1+%dz!A!Nb3?zW_K4oF=xr4URv$Y_SO{{=p?o)=S+ zs%*DTQrids{EVZ8&jcUqHW+QD4IBnWiBoAT!+jW5?vZn2RF)FpFc44j|4k@j*spWP z$zfys1Gp8;#SvmNgGYfB>NM;agWX{gD+b={bV5?h+itz#T~bJ65@%sncaoij8%Xmr zwkNUpm=r&w#!Od@YdI#zh3>I9q^i@Zpy>1&XjLx&%-p%b940EG2m^vZ9jXy5UiPd>sLRxzU@Zc?Z(5Og=z}E>WlsJ{fp5% zzJ`K7lzTbv=Rs&G*l>IM_iivZCU0-=eoU-b1zN!yPve!zD{uX7s<5_pVgIH5i@jHH zer@vu#IQT&It%q%9w4WG$0aUD=Z+QD)-1N<*FJl%cH0%{>WSO6`}Df{LiNUl{!9H= zqIasBzhObPNW;+80P=X}_Wxui_vS5k-4}uSzqhns7eAIils}H4%Oe`x6TzF{D( z{^QgNO_NomS#H&XIRD&K?rxy3$nFHnDF{nhWj(z&(AJ5#3Ep0xQ4;)|e z9RDg%zqENEA2_UeJMqP z7rAVOU3eD^!aXD-doQ!T;sX^3LCyX`ggd2saBVfoOBEI=)pR25S4C_qw9rkcT zk?tgBgsXISEGDMn=J%-43BYIg9)$^WF=LKgpLLh%1|~EH6Vk5xjjv>#J<-mWdi%O{ zC;9S(3765mv6#hDLC3Bsx2 RS*suJj4p1KHQEjP{{=(@D$M`@ literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/ssltransport.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/ssltransport.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..b1d7157c03a9ba420a5b4c64f5428c0c6d479ed7 GIT binary patch literal 13519 zcmcgTZERcDb?@=P2qH(R@!9Wr|eq zdz37O%G}IDr8I-(6|0pdZIrb@9b_0hU_Sz^7!b6;fbIjN8BYxB0t$+5$bPYwffnA6 z?VS7GE(^{rhxNPd4y1zz4172V{DAng=yta z>Xytm_;HK0UE*(;$E{M2WPx0ec1TvpZPHFDAPLaIF71+fB^y8vimR^*&u(BEKkk(J zr2)wSkPDzak`tgh7+U=!7lBbLtKIs|h3z8RT^GVN2J{YG_IxICp?uU0jRdAZOxr|ad;$j@rHK2)2q2F}<8z8QA5UPn@MI_wqsXQcQ8fZx z#j!J^WkV^@>WZvR%A{W$RssJ^h^UcpA{rvmc`>2L6N#u8nV|S$vMfP!impfo#WxpG zCnGTgb<&X;;b=%vM14Ce;&fb5kz5$dV8rqB!(x0!CYnCzr-;M4KB3ZzI+0@-c4Hp^ zw;8oqmjdl*Xc)zzLL2RoOz-P$USnag%*lHcDX!0jP((pyi?y{4P7+C*A@SLW1QS)1 zXb_e}m9ME{I27BVikD?%h*ZQl5hrx^6*D(PAsz$%5&3J02%*a*Mu63mAyu1y8E$<* ztd+$bC^W&#k@$|{DATYyaY@m*gV^(e(J1+cxR~1T##jo<14<6i-ETD984%|tBjHIP z0w)rh4Mn0LezF*kiLrQWcMMiwmWr?5a|HCQbuy%cRFx1^m8iSRIHDkz#mCPLsM9k8 zGm)9yYKVXs?M^Cjl9UdTfoSCNzzmhyfdq-d+x~%s8i@`74v=YW@AS{i=evWmp=d-3 zsdBIkeGph1RHI5T62mOHw|ryuf1WO#K%cT5lIzSPA5-77{L1Q!AGrq}cy<;{Y{S6~ zj`P+P7|vB!;F$V78_8h{a~Z5^u*AhDJEE~EeY#WdK85> zWrqH`8Ne_p7T$^!rA$+<@)0#S#Y`33mujKZQhGC>6!+Kc`}$ab*;*`TrWy>mlmm{s z(whNIc?_tO8yk*g;GpM{UoHynAdz8NQ2~~(o){wW1SmjV7bX-`j8EElC7}oTb1O2L zl}T_C6iF;JEsq53c@BgoZ#yeb$I1MO;d6N*5(~$t0cBo@C)6u(gnX!ih^#0<61s9l zmV$D8Ldjb+0tn6$UX*D3@)Xz%D1?!CFdC1~3*m8&EB=veVNvM_l5n$3nNyjSKP!@#!*~uGbv`2d5;}=4-(P=CE6y} zreq5S;miT<2b2D)IqBsuU=Nh4>rBq=U36?74z~t0U^lt}z~QElfU3vXN+3=Q*#?!c z@_aZNSLA?+Qk7?e3Suf_HXN|En5`9`hPH|W5}-?P-n1{-|J+%dHp+@a(2~*ydG#|@ z+^VG-gWge{S`!tJyk#O1m1A*&Q!V2o>4o>Cw}OLO%Mqy9K#8L4yZOq}D{Jn~jJq@I z?n(aazn0H^Vl1A_CG%ZZ5znJ73^ zQJ&4%EZI;&H5UB=G*XH*uerBn+}l?7-?3!f18HGkGtG#U(tJ{*8LaKA&%hpXlyqhJ z0S*F!J*u7*YiOKNCcupll!at3o?=Ov#Knnd=!yb|nr;cfK@R6*7_1_+bl{K-&%)7W zr%u5TA#p=&#@+z`{A|myf@G_<^TAz2(KM=XBb6 z8n%MYmqS_iuC%aA;|i{x@f26`kD&xsl6wkQOxMc{o)R|}Ou(<=d0`-jbHoH~kV){A zacs|T!7(nkQE)~eJi0ctA=4>}D%DXe ze;GUB#=FiGoQ$)f$i#D5&-t|Te9qCZclRpJaGgf_fdI!t+^e8H09QkJX0c+vq2 zV*`q+o)iyD&9pMb9#-gKO~Nt1z!m$lZ*+j?4nJcFX*8hXeV*xJ_JWd`GqKFe3=6+E zJlD9FnK`z)e4f$D17>~O^nXqvP~?~dTPV+-2=G)2^7d(Z=FUdsxx6_XQdBAzctpme zfS@T9GnjQDDiNT;;m}v}X4>9{q7tN_B{WSd*jYsY_Mp((<>RVNRIREbaUGMi_r3D|fph&fR>yJRB zJWVS-f6<@wHQye-HM|nJ!{4!_w+>`|dzRT;ed9{QE&DQG;2Cf8O3%0Yf6W8BUn5SM z{0gDR6r^|`E8Bpo?|F_NaJclaeoCIaLNYOJhmNF?gxc zp@=OG#R~d(m1|k9L&c0+T=o61?cKJu&V8BAeRof0-Or|lXX)k-aCt!n%TGdk&myB< zSMt`FJQt0COKtEObF_3IXEzSR&MY_UOS^s&e9P~%SHZAT+$F6bff{|wByry@?)=wS z$(&+mnFWi)V}6ZQIF?CSoXmnXWmU{6i(-0_fmRmUN|3Azwv?6dDVxO8U2aQR=$l!4 zQ;W*G=87>Xo1p_1?6CeQF;&ksb_#b<)guXrKWr*uce7+ohQ0KcDUy83ttIuca`W88Kv>Z#0HKF~U(7wuMgwFdyd(PoY zJKA&2t&76|E`ROyqYs)}*P8n?&Hc1wg?;_l$KI9)elgv7GV32o*AL~q{>2wRad>Xc zJ!ouNYwXE1_N*#*2Jg0H8^5@8>SLF$ym&azKqD;7_E>}be&TNckg za5t>EJ2LK$Rm&aWZqElhvhEX$W;pu6d$v8nb43}arv{4c6P+!lR-mVro;Gx5$;ahL z=^(WvV(6c3avdcYyUKOcTHe7`$2bI>o`SQ|_wUQJ_T3kDYbJ8JyN#-pPU#B(&?!M) z{nYZm42QQwyyo(f9ngCd(O8)DRM>CSnMW)NDr`!#CM+1UxG%J6wCbuJT4)cY)eP`$ zBQQX^;O#vO*U5$QdaXffJzTu6a>bm2M9hV4de>; z#>TqkN+JM1d9c5O+6_GHuQTg{9w#Xu3a0wMTbhy$V>tUJYMW7dep@O(04kIwN+o(+ zG$7HFardmgl6CJ-*9s@$9OyFr-(x7$qO?M^Pl3-Nn}iB&){> z?mb!ezO=CK_rE@M5N9T^I+|c8o7QC(=h0R_?p1D{eNBhv*f~A&_nt|M{6UDWXmHYC zF7X2b@SsM|(5QHxheIqD&%2-?ICSB{xeLLebEoLXE+gzqH-(1O zt29;RCx?H7<_daE5b!lwZ2p|LY0cZ6@pi9{{qWMem)5o)%xph+SNY&n);pMX4*uqW z+jBFulzIq}Hh<1te{*hW?(MF%*4|8OFE}@M&1-vx@9i0W(A2zM-}qkz8?<^%4dT~& z0?d2f<9oOt1&;S}AMRo??d72$T)m`J5O5lm_NAc-%oB-NxIz&i|B@}0;#l_ea2=}2 zRZQr?UM_b~sL5T8;k0it8q;F3s)k{)bF(}5vhN!WXYJE2^Vi#&}qMBdCi&xz+$afv?V=b6t zQz;9Y7ur)RY)7~1#V3q{l2P@jczV#MI9CC}R_%ZRcWBi!g}3vno>Uo~5GJeL508tg z$KVOf&P>=heyZYv(`Ra{0hMx9G++pn>3fN)Jfpa#(gc+^gu&5T%JZ}NSXL_(hbRIQ zrdbw3dsYZS*2KMF0i|eKu)bP)RAmHKAkYWkOv?ysj`ja8ASv01#_Z=VS=e z8J7wMj5`H1vR1mt)ITf>#QDqe3N4A5D`#Wz%m!52X<{CFt=wrm1bw zk*o78a-Y<-U_520U~;%b(Cy1dR!^>;`M7oKTRpc1bB!&_UjcYUeQVdP!A}ra9m}@v zS{?)x-lp5TZ|z?5bZ0!>Sx?X6Al`L2y>xob*^zN}ta2YYyVu>m#f99~u3L^=gC9?U zy_wd%_Zs%*{H?dI-nzQx@5%Ukez1`BA6(`>_WJRg&e>aM*L*uNz8!bC`@X()qog;1^L`{91Z-TLSNQ}0KA@$Dmbyjl0|w6Oa(kGdFN)9oX-j=;Ht^YGn%=GHSm*uU0w zIMa3bM}uoe#xh67(%W9jcwbs?ZCidm*WB`s^-b%yc|3w#;$!MPzb+2;GC%J14sqO% zj~zaFjQhzk9$+{{G06S64vvg|kO}?XRo(*Y0+&|v=8<>|Zaj>P1?==fLDHoeM*aG= z73@s@5)(Ar9@`;CDyBs2L=Wk_`EndwyKiHI+mOI9MqxBaU}&%(n512koBrdm`ArS; z9K?PDrcW7A+9Lsr_R;q{hz(EtWJ9T|F)E^e?7)a|N~E8HVaT_z11bl=Z~$S7;b0M> zB)yHVU&ls*76EkzX~>WCqYXEg3WLh?h>~A9wskfvVsW>^it@>Vi^vR+^cix1P%5Mp93oO z5-pYt@A{&S(&+l|Ib)gVlCk};Qj>_NQSWvJBhjJgrBk7(B7c=GTC(Fw7oY(c@w8YnT0CXpbclL!^t)^0ar>d0cZL|n!qZ2)j*_)T(T2x zxvH0HH7vF?lUD%gW9LLP4i_YKF)po=F1zpIz}2GoxE_fQ5fYlO=!jAU^FS4tY|*Da z2p>A|*5jp1U+ts3(O9T$5R2A!%ci!JInV*8My(@FTqt=c&mgvRlz~k>p$B~Ps3H$A zX&5zJbVs0iCVzzq#fstxTYtpBysa8@e}8|USbn`-BdoX==m5YDAb_g=GTiihfGecI zAYP#h2J`k{5WYYpq6j;K!LKDkQN6|*3`+4Z7Q$Y5@zhJZTf%W?K0uMQ0ZD=c45fb3546OsK_Vx`2ls#$|__jwrjz0{Y zJGU3C`*se&vSu^}2=vkL4D|x7BFj-BNI1nG>lO~TWR^E^Nrz2OP19p6NIe3S>bG`0pfrlLEcY6v} zgapRjQLrHdY;-?#0HhO-Wqzi6XAU@N>*o8{>-H3Q$gy*0!HSU986oKGf8+p26CxCy zfFHNSL;_A>*b)RB7KV&rLM<~CEKPvz^0lx$L;sM4UXX?lg!tDfgD(sXo*o`~KCd5< zLHL>{$1sYm5IlV0h74Z2LxoDv-pcbY#h?C^y`-RZIkW8-jO}NP>t~D|(qA$I>zr+kYr4lZ{oLI1 zALc>e3m87&T(1nTCe!T@zukA;nR9PhoW1$#(yJ>mu!XKW!L7dT`nBb_neBhbU`qM* EKbl^uL;wH) literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/timeout.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/timeout.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..9108e7e493fe9a92274a60c29021739aa3b78789 GIT binary patch literal 11657 zcmd5?U2GdycAnvnL{XHeUrTXpXCgbc=*X1gM9GG>cjL&i<207tT28Sn5^BU5N@J58 zW@czvtT(XJ6mW_K;-C+9kSyXn#c393(xTWtEQ$mL`d^f)ypX^;h0$yu^2W7Xv`8P? z@7z0ghSX1z-R(oi)}71ybMCq4oO}N6{C!79RKjz8*FWUW4NKA&^g}#hUXfStp>kb1 zD`}D@=cR(2mSw63@_}@Ky@Tl>-obpR5Kf0#Unt*FXic}G9@bj&kwRO#O_ucFxjq5h ze_Jh>+nNs++SBc_6p)TfTI6*}YtzFY1^K9SOpl%0>dz3hbf*^8<68S6Gyt|D+Wj|L zhx}inruXQvT;Kuxq`!18TQi0=J3b2VG3maAK%(%|YHRa)Y!gQHHNG+HuB`yAB*+WRWDX;ri_Ycy}njFuLhIkPxgw(|J( z_-NTN@}usKlBETUM1&QcsMu{NUYF`EQb+vCgw-wjDt&Bwzte>AOSLY6d}ivz$%#{E zr<(TfGFV>yDZu#qhp2%9dMF*%0(y%UBnE3C9shE{HmUKS7T3bBhtsWEm)7!nC>_xw z={7y8b!)A!hd#nAdeZHBOzVMA`7Ir2>DAgAS~|5pEeZ&6tzT=$y9@6a-rahSwngh` z7}<-K0j;y4rEejW7_7CrJXdeGOOjhxvSu-7%$6-CJjrNO!Q=MXN>(i@Gr9s1GK#vU zsJ5cg50WP(XIl7GGR=I7&q^i%Ow;$x`l5z3R9CCex}!vrB|m3)4FowK+n;dp zbz6Kc8@4)=2b*UW6kCVFD9$QsKF{zjsTPj2qg&X9sZ38#nnitj`r9F1G&3#|KwY3A zxJrOrwo*00+%`C^M!rhm$5|2wD zi~XpjQXY_9^+1F>%C!I!2V$Jtm2wtJ*fS$C5o|=sFP%j#V zazRlGW*HPPbDV<1MiErS49!juY3Ef#s2~>%Y@fGXl~a`ls+eXG=~1`K*{qIjD5nYr zmv43kg={NqyF$M;a$_y+UEbOYHn=A=;)qhR%o!Y^1!bDx&gSteFM2)P1Z`eUnjOu$<}YXD_0cEyKR)w>Hum)6PmO(N^aa>P56aH`*yCg0 zoz5gZa71#xE0Rbka|6o0XgFLf;SMk@?h{aP31>I4)9p`vBST5#esyln=+3;Z7fH~; zY1n`Z{&8TZ&4hYoX3BPrkEbNOW5s#B8G}8#tYvi5Nhe8RhvDnE>w#+KvUhU+UvRgH zi;Ov&vk=xBE~K7vbvm7Kn9&6#r)C`!YM)#IHJ5`WX2fAfeC;76m%ugeL_|w>%2van zEGo}UO`Y~sdxJJPhKa7Z9Z^m*!QW#mM<>tFU^7q0S2LlYfuUl~=nEVL?!o$s&*O>7 zbg4LA$|-OYs@L5J)2WTSA!UVim=nO2jZw_z%bG8JbH?nPGJg830$m36%6{7OY6;er zY`A64!a6EexmaX26DJKL=h0!9mf+5rMns1lP&LgU zSDu4sqEE`6liXDwHY^boO+i=fGL%2zK|KJ;4w1Lk+JnnWk3#RRec{bm)rzCB~QVpA&54!J8Pxh{;dT;+>s%nf8}aW^azk>p2!IrgP!)V~b9}VL(9;ORY zA~acRb&XIhL=s&??1)pF2-mtZ7u39=A&3=DCSp%9Hk_fs)`I|B>&(Dew;a)j7&T<; z`5f!CD9W}dez$2^I)+vcO+pw;<}#D1bWL$>lN2ol8vPuK%ThfiJ+OUwFu6FGyfy#l zZA*jCUJd=QW2OIr<^D$(`yah^^yA%2{ZFGU>bFgN{M1taLDn|1|7z%Gkq23zn)L__ z$PxT8239JFV9t9I$u4Xuf_}2NMSuuiC~PVdr={&ckt#<894;UlR^=kpTQVx zU!F_^tX>SXDC>k|NvnI%8+SC|nyZZKL<*U#JS4-|feaEbcyX zJFYCnhpLguPv=qaop{(`s3#tKK~wBRz7n}4H|-{HNj@X_J3_A~6yn@j?M^FTu?J_@ z6|2|eHp!th3VSZeqFqL6@1}DXhAkkdbQ?MYu6U~}P9SdC)B^5%CJBKn}dOF90AwoSs?R<^a9yX-L{eQfG0u2=t*(+i!Un>L&ykE0_M#D99R<@ZiYZ- z77lljwopbi$6*i@GQYO+A~mx-VM;lXQxJTCLaKr^qiz{lJ_~-1O+hp~Me^q;)dyTX zPz17~TP6zz$XsI4MCHuE~xFotCk|D{ zIXJda*HiVeb`u2Z*AY(HpG>qcl~aovwo!!rDrWUsi1u5H`V6Us8Nq68Q&7D;l^d)D zvw6D~W*e-9Na$=*9pC^nY}Pi~!UIAnt+S!8q1*mP6fkaEq*(XW!#5^wKQgwsZEU4? z@ahXcZ|}dRzdLoiedtclwt7JB9$5_rdpqk=u%ojcX=xk06YIYA$PZtrceb|;uEhIp z$bV4ze2a3gMM@s{ld*a@(4Sfjh6Z}-QmDJ99+bMa)(54o{;RS7y1z&2-uiB;8sB|S z3bhS>-m~rB68rwBTo20KPx3Wdq`tv=Yp`Rm9>jqEzQ0xKdf?lQ{mR~g9evn-Brg5g zz>zWOv-r*<2ZEoCZGW~Wm~FJ9q$EKtd6lTtWOwCD@{c`t2u2~Gc46W;ybP!eoCbYf zB)E8{2XTNtt7Z|exDvo+)K6Zn*COnMBLhc?0OY!n27vGA@Z6M5%0qzSp1gOuT%Tt+ z0Uwm5uCf<~6K)9PIoGaI$uflL{HC&b)wWa9t|Ux*;LMqGJk*1J^wu|unsLF<*tzB# zVooTD`1G`k*Yq@(X%A8f3-CkYP_ivoE@mmXS+7`K09;{hOgB;?^tfpzjswd}G--|$ zY1GuT8;Ulilap&);%PrM#X&bJPM2w%7T$(Z7AdaO=Cp&OK)xjNDigBRk2;$6Q`0aC zn`BLRm{CeyWY__&^tfC|`fWd^@pOZ6S-QVX>KeFl{MK*Zj*nF%W9vN|@=KW5rcr4U zTWKRVabp*8WA_k356JW|p&umsDTF?2LPRM|*I?0Hig_e+H%6f{yhF!;L18INWELPA zlr^VBI8(p6iln&+B8$k@k(lP-HqEVrCS=r9^dgIb*<6ayC?Yg)Xv}$pX5{vd+KySG zaF^Y6G-Wb9J4q?lO}F9;$2T!Q=tmRG@lAx71gvp~tw%u2M%OW%%>(mFhmZmG^QScE zArxRgG~~by=e-}i{ezF6_(|%M)TdK_o&GF+JAS$vIlW#Oh+Rw=DyXpF4)3+km3H4b zM40C}e~x>xDs31m2*(&fng-ocO& zA!(&w@V=?}?*Phv3Iz)^V_nPbI~Ln_RNMF7>DgJ`b#kd^vKpJbvt#JJ;@icg9m%Vq z+mQ!X;=Rl9p+$-whQ3BNEI{2%HZK2~vayjoR1gF(1rmp-9T!%OsHEt5wM1qDeomGr zd9v*8$y8FfcbZF0H_>Fe(Rv6!cftk1;8FgSUl;gX6pEW^TTh$(UkVrQtrZ9~OH#Wz zYQn~sv*I3dOetZ+Ma@U9k{Va3mq56-yctw8AfE7Yfmq)GBiBh+A3zD&$_T6~+opgJ zGXKeqdVfZ;mg2J3CHb|#m;WrLf+m)L~KREgR$=hQSi@PSMKlN6s8r%N!c+a&bXza~hAMAa9?^1kU zHL`ELhV)V^cfsY&G~|`v+gMB-PmIg5^$Nz&0a)`~(Kl{yntKLgykv&y&`dzT>I25mc%KYmL|C)d8!9`$$^oNZg%MHtzUmz@*d-LE*aKrhh z_{=*Yl)&f7e4JYHI>bR#aOVzh*)rhR;e(@T0$ zqe~I@*2lZD@qm$HQ0S5Y-}&%cH5Xrj20l#SuKk*Qu&weGj9&D>;WHZCe;f83eT9JN z5{_DG`qgjawoUV!ks1HCgWvl!Y}`{>FH$awd^u9L8#7Ai$Ms5VosRnD>_4cnp+n-4 zfL0b4QVS3%X6?zBfpf#y0LJjZ#aFc~qm+nnUCDCHENxDnBowB4(fS^0)?q3VRIH61 zV#Ik*dG-nA+1UCYm}mb53TVzMc0GKjcgwX`-radad+*%a=Wac*{OHleM~^N&dTepWF`kxR z+InWGcd8njTETkhH`3LPowq`N9Q`nQJN5kH@bhf`ja~2UeS7asXL-*vi+i3~+Vkw< z)@PS`$E&gNyS)R;y`zi0qe%BhKZ!2&9<0U=GF2@oMd=(KY_S@Pxv5rb;VxkR;%xosZ?-vHBDW1tReA9`phiUX~cQm#_pHt$rIYyTJ zV^d?2QEO-U9JhtiSJo3$JW0htDoBWG5jPHBu%4l|aVqHhPDWjxAf(N(-O;54O9lSE z^ozix9FEjy0@Cg$FQ2;h(o$%w9+8w?D-S=mvLjhYN#v3xz^H9B&Y7q%- z)K`y6(azO&)K<61;i61E1DB8A4R_xQ$l+7+YEWwFK{gRpOm9K!o^U@kcGsy^|1Fs{ zc7%}$WQ|nY5exq&5_N6iovT}7;V0|cq?XQmfp|DcV>;_ps}HfZ?cqbL?H2*m_)Zze z`sowZTp6D#;1g9VNc(;oMXd#aJ|fdvNJo;}3b7{ssSUdUszv=Ml!tpA>`U13=O)H~ z146=NH0LJYw+NgP1Py4N5hBpp*R!I>(Ry1^#yE^+v{&PdNwui3T z-rxDIUdA@*nZ3ZL?{U8Kz0P;e`OZ1~quHFx;ajZ#ALG{!a@=pJkoxkK4F7aS3kXi& z1m444<41X(@+yyNRKnQsI5rlGrs{n$K6*c<aH__k4+hTrxAcx5i@;j3N%U%mKDO-mZ~baO?qwLvR8F-SGKQPg-x)D z758|-Dq2`tjm0QD{_JZt|l|qjnW{f)kqF=LFq$aU)HDY-hH*Q%268e;>H!{aG5{CL1Fj%n)^wh zQ5xg>dK?n=WcSG6%Hf2=LdW}>(Otq3p%cHmH^(L%74~Lf*s}%H%fh~FD4|<;2{`u% z$Ata(?GSo|1NiL}dWA0h?wwY-R6OGoH#mFWx3nTVpD;STUZ3CTcl*5Z;J3ueP+54& z=VDc7oRTc|Ns>?cmbfdLbbg;h_DgnkLUYCMpG;^el?MZshPRxp8*?B&$l0~LltV? zy2x^9IZuUT?a{8frZ#G?4^+{ZYzDhqIzs2$?6*2XnQ|bX@|YuLdg0dYmd;S11RZW& z5pRZ+G-*|J>Ipz|?@yl1-6IVUgyuQh|CD}i9{l?Adz^>hUIy(36dujiHHplta zcLHjR@{A8Y_iycMus2tG%(_MHLM`L_ZZ`_c0k0yPA5@%&roFEn%! z32p#x4%A$1YTuG5L6b-8pYa!;@%7*S-#`BGkI(ofU_O7LKA^hT6xdF4=-SnMv?;hN z_||UR8ii1Ifh-vJiBk_@B8pe7#P;(+2i5HSqHWwK z*(7mN5@pfrcY80}oL*c1@bDSi$k|hEwh>trY);wc1Ps8vw(CyM6zjxrb&XGXU0s(Z zi3K{QB+sQb+cBU2ip_sTw8^e3;x!TI1ltv#?6)~FnAay=b9&qX1u3AWshXi0qkb-@ zEVjD6n2PN7yRW0S%jJ^N;)0*;$A1i8O3bI>n? zd{7ls2Q@)$P#4tSPtFN@t{RkzfyS;$3 zEq5);>PKZQacfDqXrXJiH*PG57^~vN zm5b*W&VO`q_V{B<(cF!>cf<11@#WqJ^$#@oc?8l{c2Q0K3SryX&lsl2I4Y647xaZtoGpyhxxH!jV(Vzzqp%q2H+;n{CpT7nn&^t!Tav5|JdUnuTW)$dcbk~OL3mOD+aYus8s`|4^*_55h~?WK|>L&R#2nCve&qW6Gwt0S7>r?;SKsdDohjlxi8RW#OP7=rxpb)|Jthu?b-Z*bz2}!M*(N0)xH>2d63j0;g$w}*$f zj+j`FR7*)Sk}T%KjyI4?$EXbV5w*iWL}!=}wtMHm+<}O3TijY2#~nNH!GU;5#iDz` zJ^$7czf}LX_Rs7~l@V)e#MBzcjogYw;T^27DAHr-AkU*F#D`QNbx0G^hIAo4Sd#(L z&=5o_sM0LQfO|%DDnXr9r@pO4otiNvLr`=<#{4W4~?0$Fb+o5S(;)nM=s-E~zN=bhF7v>=cT#<5*dV+dDbs_Y-oJPk4pVKzxaeA*ZPK4EXJhm%Ns8C&)^fljgQLtyRr@oucYm*+aE3;Q^ZD5Ro z*gA%LbhWF?rsxQnc3Qm~j1&8fp-FF8-!@`9oN8zzg(9H=(%$$^KnH)J`&&Ffu_)nUr2uyKeGZA+*yvH$ZN=@D1~3l7uGIwSO0z z%TYFwx{b3)Z~-;8pUD}SLQR&6942g}?YOi|3T5%BI;taGL25uknu2GY zuBpf(=>Qr7dh9eU>N6DNpCAG6+Q%I{8a2E$tDD!%3*p|S`ep6%&3In^tQyLcsgTr0 zXbStneG5mTrkdFvaJPuDlIl9cbqiflQ`NeJeH7dIva z#EyzJvGZa%Iy43jbB#{nUdf_#gqrpv!TZnvZ69~S;Yj2<9M^opl!x*rhvV%jrzhEh z~W>8lA{ddhp3VHU&s8NHOMQ)mtNH_SL`&^aC zNh`Dov(rNlOu^y0f+zVpjlS3+dWpe1++L_U?j(prFS}pi-&4{Ia9s_Y)}ZKr-#@x^ z9DSq{NU}#_C|UBDnqQ%WJ(aQ%ru7gLYUy%8f9Hm{EX^V98wqj#bk7O+#h(9QO+o*Z z-TFLWLmXZO+yssB+(%xs6l6$EFZT(0H$V3Y+WSeZCCB8K!)K z&TmQOgX&bz)F{2&h4+C&2OEJds1uk*Q^AGw{(^KLeX0-iE{&uO>IE&0E0;nqGF-)a zq_UuX!kU85{HA6TmJ&6#fZv zK0NmcX+Pma<#SCarh1b8mRcRpefaM*u*6m$a=Ps zw&R1cB#F++NzXK%x49%^eM|%N+MFIV2-7y`;#p{f3<5(7I(m_zh#sDU645MpuJ$riOt=81CNUj|TkSQc-*qKR@qcDG)qLb#DQS+DG{;I>W|Zp|&`$ZsTlXi-@)Ud% zmz{o*^qr@)ss=VW34T%T+ZiMh@f1iMx-bc&<4oV#p1#3h$JsuZNT$ZT37v8f39Sp- zGK@}R(|FxTl5;wtm7LzoVnU6lQ$h_@DxniZVlwD*(=U1j#VMc-j6)lhh`&SA=%*0} zXsCkZ2`S6QG0KS?*c%*#UrrRdWyd-IQAiXhGXe8Tz2OtQJE5Tt2?M1LOky+jgxDP8 zNxwx#wqh5+>r9-XAfhjeTgqV0`6j<)ema(4Gc)jAE?3{aQr8i!>-gHxvh04UR@LjG z8r#f3#9{-3ET~w?w?*@9OQp;0vHY%?fp~fIviqmL&wUStSX)oDyeFb5d0bX=&lu4Z ze`7A3-~E@au>B)%%-ryV%hA5h&+@C5vT#B8wWWf)BN0p8tmd(`WZwS~-soSOs+T&K zJAZsAZYr9WKNt-AKfQJL*1gaJb9DRRRa4bcQPk8BF+pc4iW|yT47RAjwp8?mb@`3^ zRS({NAVut5EB5ZFy*p;_S+Ng9?E}B8iP=xB*w04oXJhu^XwAs44CmIYG>x?q&Q!Hx ztcx1!V#bDureWi|p9q6Voio_6@4pox{xY#%9!zf!n4UVQ7F5K_B>ux3!GB;H!530aaRf2}N7#n>vmahTRPl_3y za2f&p+$ZQ#tV}A{d<_}FK^DG=w1~(c3aU~#=sByHh@bIo0aaU@aw*Ab1G|-~y)B?_ zZ)>ybVJn`5aWkOs3(1s5~-vK9U01D8#bU?u`X*Sd~UB@Bh^u}K^B>j7-nTK zOFTgn`cw@aD{)N4j8yJW9*7Ql&p^fVJ5q3x3_t{xaPmE5X1G--tbw^exbBDV&h*F4 zmYL(L*2*VbuC{zuziKR;cYSaKgh@H!gQIa%;hk6KUJW5-o5?qy!=RC`PsSU>kphinT{Ls?wIGy^UiSLBf~aaHo$~#hvqLl($}Th z#vU2USB-gh_RsB~KOQqyMl_Wh6%5Q*pmtLbzM#t#s!9K@8 zFUfzM3_Vh#=UfjIL$AvV@vAoj!n>%r?^ zYQNgs7q7K1*DTjA?YygBO=ZLS$JHGVPCPn17^^-#e}Yi#Tj~pYR;qVJt9Qk!_e82X z9_)Vb`hx-Z!aBa}d^qv&e5CSZr0C>o<@Qgz?snZf6e((aTwJwyapB@p@1tV-QIvyjbL zMhXKiy!s1GDx!#8$xRqc3VJjAxCEFfeM4Lwm+`~abCQ|o{OOlohUEy{d#W4UP4%1H z4Ze?$MH2AC7Z0cM9~F-H=KCg}}I*bU5~-mC@VYRGaU-9clvoRj{XpeZ>; z*XA>1V2grN;n3Wn509*=v^iz}Y${zd;TPV9#e)k6p@jzS2JQtP^nN)!e=ue}88MxN z_6(;4e0@JWv|_A|8mq%MV#daZrt$aRm2>&f3e-7ej|=PL`A4BYTk}?}rE6N1xol01 z`ai6}4pVgJow;|?V1;GjqOdMfeISzGwXwr9xdgNPk*2$hTde8c&HcQrq`OW1^WC;% z1?qK_P12rG_J2oak;@3pO;yf}n1n-B&hyh=vJZ5C$c|6a0_;7sZ)Q(O(JT{*@S*tA zs%22+Cqd4>v>4L_)wj#CVATFJRi#>b)wLWsfD`|C67p0i3w2J_L{6c@iu z_JR7Gj0EA~P{J+Xd{Bsr3_@^Gh?1<>%g;z6oabHvVHR+WP!Ncp9Gz)r3GxhCqki4ELRhGncNIwna_b z!slY9`kB73jrouBY)i+Nx+1Opk(z;6-pPpJg%eff?T8cD@-6C`)`L^M>@6mE7B!-0ohk*W1)f->L{Lf=MGwwya!&FlUOOi|Q z%2I8nHKyk6r-%#oU5Bm&EjItf@X&PC(golq`ate&uq1TJOy0tMBm;ZJX9(Jad-r zX~df}NgW|0W?ls&WTl^UGxlX%xG;of)}-;)$wpFF@K3?Nif}jt(X@)=V6brRDh^v1wNL~|MuR}$4h&iz5rI6wFSpr_ zyG4(ns0HAc*WCi3nM)ULVR8s5T$A~?nGPZm`%J~hv5*HU?A!lRCo_9`+)i&QItA`* zW!i9o`!2g(N`#*1!L-usAJPRPWDL=G2;LK&*WGY!`@C!)SgeJBDL}LkpGSOzH149X zJVZb!Do@hS3pk4x=iT1Qv#offY5wH#e%`U&NRI7I{MwE7j2E}gHUjsv64-Z`b!b$gh7LDo z+~KGq&-!6HT4Z5|IoznY$kEaUGmx?!M2FuqqYO@Xg}0oCG7i}|Hk$=`x7i#Nuz%I~ z?c+Y*(J`m=rwpB3?S_Q|1(wa6*@qhmS8@+%`LK+&4=RrAeYn(iHGHN_EqDL%kEARA z2|jFlG4sGdolqXa^jy6ST=3UI*`N|Vgr&ctgczvw4mIXVAZI^Qm*CUvKRq<;ICJ_e zX*Y`IVR4M$Jv=aY{B%xCMOo{aMq{T2Xh#QVWX08ew%cke?WqG(EXgr@{OhNhf}kr z)qb6ZST{-dAO>E${eg%jYfk+a4WyEzFyGI`c`LHTzUgGsl>8MM0J ze^&|Z^y9pUvGEDV;|!peR>bmJ9@In(9e-F;qw1MV4)~w+amV%CFZ7nNn2y(~ ze^IMN-mX*pH54YmoHoyj{nL{aP>SFyzZ0R8(pzBg7qWs0lpYBU-EP)J`hq&MXoJ5) zE`^eXCk#+irk(1N_G=cIunuhv!4d|A_*wsKtgM|)l#~}GMj{jApi}6c^?I&7IqHw7 z7wb>G5?bbl!fe9p>XnEIjS}IIhGrbazK^0O#-}K*9$^yD9Jqu^f-_9nvP7q7D13jmEVT$WLJ=}fjl=KPJ<|uYHymer5 z>+gGmUOfpNX%$Wi3O_Z}v4>S@9dO{uu<2cQN^a#pFoE-A+3wJfS?Lsv`&cJa+5$*e zE!jpwsxX7)op20xzuHI8(qGb4-=|42gOrv~onfHTj|nQ5j3~k|sagrcX|}cS{<2f~ zjKIqX$bjHC$>Vbhj8QY6hGK{(6Np65If?ihoU{B*8GMb~#rPf^vx+)%MEXZmQiFUG zXNp_H^S|b5f6L|kGiUx^+|FNfWiY#y?}~86__dVJj@_AFAGI`e#h>!qTuk zT3EL<9xZHH4n_+PKD-<)>;t;|&KYyoDh|cWhi7tEjm5Kj$owS2V>@O>x{{UNslbUtfH8;oT)UTDmi0YKfbz^XC>F3y!6sXfXn;oBvG}Mf2l} zz6IZs3vPbU08S)a^6B=w+n24;a)kZ1tyv5?xlgr5t?oNDO=|6=hEo}Su>JP-HIcP2`lp5pKL2S~KHv0ohlQ{Bu6~^7b^r3@Rt{Hv Pgc-B{Tb1eL!QB4`8!5bt literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/util.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/util.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..711f830dab4ae7ce61ca9ba3a2c372a61471dcfd GIT binary patch literal 1962 zcmd^9&1)N15Pxr1`ys7Ywq?6^9U`yo5V9$PR@ zY)s>k9H9N)-RnGqk-p1+L_Z6WeG>=R7XpD?2++FTk7K(4*TD`s1x!y8AI2j8OAz_1 zPVM(DT0(nLt~mnvF`POigSy_TK_M+hQ>xLG%zP;Ol(H=Tplo zI-yi(P{$8NfQ50E(3=bu#@HpHn$LSy*~#bOuve_u&Yl?JdZ_XZxFRaV;j;=DhH*BZ zrR8e2>Q*zAybnEe3w|-sQsviz6w$#P8HgIo#d;Yuk zTCuTHaEAWxokZB{F%`m^oM?=&)+Pgtu*M}xAfaqKtP#i%Y@*7O5pIDZLKl$<*f7OQ zC0sgEUVov4*N^n+|FVQ+3|#h=kUeHT3_b&42Zl?4*Fk!D1wsvzVX(b8NP3{4?-_66 zSr~oaVEBX$R2M%-8+Z@rOd-_sc^VBRcr3{cm#&>_OfeK_HI%-#N;L<>LVw;A;td)K-d`$IR}$jrsJ(L2@=3B0&7mP+403kmharG7o92_++Tug?kEj_Q17!5 z_Me-heN#PxGY8E(QvA*&U8fJC)z|u0^X5P{35r2Z+Yx_9CSSDe*l%+ Bt}y@r literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/wait.cpython-312.pyc b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/__pycache__/wait.cpython-312.pyc new file mode 100644 index 0000000000000000000000000000000000000000..0b8f25f879f189abaeecfefa342f044f01eff873 GIT binary patch literal 3408 zcmc&$&2JmW6`xt|7r$j&k{!vi*RB(ki7W-Ko4AQ&G(k!?MIgJ5iy(3XVx?V5E3dfh z?9loM39y0DO6|cC>Ov~ogN`=TgHHweH?#-35>R=o00DvmZBJ~a0D(?@Z+1!1hLBte zbR@p_X6DW8%x`}0&HO2yP7o+-7yewlc8rkEvC=BB(4c#N0Ar0<#G)>lrQ?*MExFRT zBy?;%20G@-v&y&veX^xYN#kmq;GdNWb*Hq_mU>Sa*S^w20}tKGSo%GAJpPrQ@q3Dy zu(DQ{m4GoxVI{#zEl9az|HMt?Xpl5ZC6Alj@k;&})U~q7xMR9Odd_rsq3E#!vrQ|= zw5xN>;r65)f*_;{5h?N`8{lmXAd@Bl{CNMQSqqlqzM%s`5+(X3G9be4Q6pTH`scMU~qlCD8Gf_xmI#jU8N?t@zyV%l4#GTrf;-xV8xmUdcARqJhYb-eMJd&=9Bz zJEsJxo0SrGX6^4W=CMFE%VoP{F-6UgEW6fsGl;ZU!_ z1C>oq+t91dg<2|>pbcFYpe@q#Liwe>gPLWjCZ_$Ld!6 z_4?aS2hMJ2zrFoL?yKjQ@+WOhaUOV`WmFM-&|ZzW%8$gk|dx5+cyL}mzX?t}4j z_3PMaNi`Xmd7>(F3FpEx)5-O)i7a*lS7c!4vz|wAF7)JWp3msf6dh_avVWm2t24=t zj>xP6b2p>)U?N#ki`0tUOVt#fZg~Tjl|wFfuv8gi_(_K2C)*(j6NavH-Z zX9#zo-njnWd+&|~8tUsmy2VaotIq5x7-}2LDIcNFxKFDI?UZO?Ko(AlNMiVK!>Ap^I^WHWI_4{;q3@I%+E#X0%0*qJ|qjV zIWiynkj&AXJSJ#*D-S1%2NRw{<}J>dGg0AD!ql$6FEVG2hL9sojS%ePg=zDyU6}LO z9j7!U7{^|Q?wj!QM?lm`Q&*Ml-4idYy}A14uSS>j9lc9rB6C|m)znE>_m}$`N%#Nm zS|fSkKZGhhPqW?480Z5ZY4FL5-y{#SZ^Zsc--tbvX)yK$hAtRu9SFA2V%lL&F{M&3 zN2-Xz+c^P{i|}SD$DA#SDIMN$kPB#4f=G`r6=5jA%BfB(MOK4MI(b0vP@;t%Xd;=aL;yQ&> zHMnO?*oJx6bX;@7g`2iyn8uWI*De|1Wi*t)4crvr?;Cgl8&1*S({|KvIKG$+M-Lh> za~^U}+b6nS4ST-qFxv_zyOoo|$j6|6Ls>;oe+LDh!-oRNe-_uKYXESg@OqeTtU2eM6iWnCn80hJnr-n5&IEAbfAySdRE1? zud*x9h3U%wI|#@slzvLie@@bWBk51cz-P(6#_7RE;$mHEULnU%?!fjR|O3J1$tBDGXMYp literal 0 HcmV?d00001 diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/connection.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/connection.py new file mode 100644 index 0000000..5c7da73 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/connection.py @@ -0,0 +1,137 @@ +from __future__ import annotations + +import socket +import typing + +from ..exceptions import LocationParseError +from .timeout import _DEFAULT_TIMEOUT, _TYPE_TIMEOUT + +_TYPE_SOCKET_OPTIONS = typing.Sequence[typing.Tuple[int, int, typing.Union[int, bytes]]] + +if typing.TYPE_CHECKING: + from .._base_connection import BaseHTTPConnection + + +def is_connection_dropped(conn: BaseHTTPConnection) -> bool: # Platform-specific + """ + Returns True if the connection is dropped and should be closed. + :param conn: :class:`urllib3.connection.HTTPConnection` object. + """ + return not conn.is_connected + + +# This function is copied from socket.py in the Python 2.7 standard +# library test suite. Added to its signature is only `socket_options`. +# One additional modification is that we avoid binding to IPv6 servers +# discovered in DNS if the system doesn't have IPv6 functionality. +def create_connection( + address: tuple[str, int], + timeout: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + source_address: tuple[str, int] | None = None, + socket_options: _TYPE_SOCKET_OPTIONS | None = None, +) -> socket.socket: + """Connect to *address* and return the socket object. + + Convenience function. Connect to *address* (a 2-tuple ``(host, + port)``) and return the socket object. Passing the optional + *timeout* parameter will set the timeout on the socket instance + before attempting to connect. If no *timeout* is supplied, the + global default timeout setting returned by :func:`socket.getdefaulttimeout` + is used. If *source_address* is set it must be a tuple of (host, port) + for the socket to bind as a source address before making the connection. + An host of '' or port 0 tells the OS to use the default. + """ + + host, port = address + if host.startswith("["): + host = host.strip("[]") + err = None + + # Using the value from allowed_gai_family() in the context of getaddrinfo lets + # us select whether to work with IPv4 DNS records, IPv6 records, or both. + # The original create_connection function always returns all records. + family = allowed_gai_family() + + try: + host.encode("idna") + except UnicodeError: + raise LocationParseError(f"'{host}', label empty or too long") from None + + for res in socket.getaddrinfo(host, port, family, socket.SOCK_STREAM): + af, socktype, proto, canonname, sa = res + sock = None + try: + sock = socket.socket(af, socktype, proto) + + # If provided, set socket level options before connecting. + _set_socket_options(sock, socket_options) + + if timeout is not _DEFAULT_TIMEOUT: + sock.settimeout(timeout) + if source_address: + sock.bind(source_address) + sock.connect(sa) + # Break explicitly a reference cycle + err = None + return sock + + except OSError as _: + err = _ + if sock is not None: + sock.close() + + if err is not None: + try: + raise err + finally: + # Break explicitly a reference cycle + err = None + else: + raise OSError("getaddrinfo returns an empty list") + + +def _set_socket_options( + sock: socket.socket, options: _TYPE_SOCKET_OPTIONS | None +) -> None: + if options is None: + return + + for opt in options: + sock.setsockopt(*opt) + + +def allowed_gai_family() -> socket.AddressFamily: + """This function is designed to work in the context of + getaddrinfo, where family=socket.AF_UNSPEC is the default and + will perform a DNS search for both IPv6 and IPv4 records.""" + + family = socket.AF_INET + if HAS_IPV6: + family = socket.AF_UNSPEC + return family + + +def _has_ipv6(host: str) -> bool: + """Returns True if the system can bind an IPv6 address.""" + sock = None + has_ipv6 = False + + if socket.has_ipv6: + # has_ipv6 returns true if cPython was compiled with IPv6 support. + # It does not tell us if the system has IPv6 support enabled. To + # determine that we must bind to an IPv6 address. + # https://github.com/urllib3/urllib3/pull/611 + # https://bugs.python.org/issue658327 + try: + sock = socket.socket(socket.AF_INET6) + sock.bind((host, 0)) + has_ipv6 = True + except Exception: + pass + + if sock: + sock.close() + return has_ipv6 + + +HAS_IPV6 = _has_ipv6("::1") diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/proxy.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/proxy.py new file mode 100644 index 0000000..908fc66 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/proxy.py @@ -0,0 +1,43 @@ +from __future__ import annotations + +import typing + +from .url import Url + +if typing.TYPE_CHECKING: + from ..connection import ProxyConfig + + +def connection_requires_http_tunnel( + proxy_url: Url | None = None, + proxy_config: ProxyConfig | None = None, + destination_scheme: str | None = None, +) -> bool: + """ + Returns True if the connection requires an HTTP CONNECT through the proxy. + + :param URL proxy_url: + URL of the proxy. + :param ProxyConfig proxy_config: + Proxy configuration from poolmanager.py + :param str destination_scheme: + The scheme of the destination. (i.e https, http, etc) + """ + # If we're not using a proxy, no way to use a tunnel. + if proxy_url is None: + return False + + # HTTP destinations never require tunneling, we always forward. + if destination_scheme == "http": + return False + + # Support for forwarding with HTTPS proxies and HTTPS destinations. + if ( + proxy_url.scheme == "https" + and proxy_config + and proxy_config.use_forwarding_for_https + ): + return False + + # Otherwise always use a tunnel. + return True diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/request.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/request.py new file mode 100644 index 0000000..859597e --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/request.py @@ -0,0 +1,256 @@ +from __future__ import annotations + +import io +import typing +from base64 import b64encode +from enum import Enum + +from ..exceptions import UnrewindableBodyError +from .util import to_bytes + +if typing.TYPE_CHECKING: + from typing import Final + +# Pass as a value within ``headers`` to skip +# emitting some HTTP headers that are added automatically. +# The only headers that are supported are ``Accept-Encoding``, +# ``Host``, and ``User-Agent``. +SKIP_HEADER = "@@@SKIP_HEADER@@@" +SKIPPABLE_HEADERS = frozenset(["accept-encoding", "host", "user-agent"]) + +ACCEPT_ENCODING = "gzip,deflate" +try: + try: + import brotlicffi as _unused_module_brotli # type: ignore[import-not-found] # noqa: F401 + except ImportError: + import brotli as _unused_module_brotli # type: ignore[import-not-found] # noqa: F401 +except ImportError: + pass +else: + ACCEPT_ENCODING += ",br" +try: + import zstandard as _unused_module_zstd # noqa: F401 +except ImportError: + pass +else: + ACCEPT_ENCODING += ",zstd" + + +class _TYPE_FAILEDTELL(Enum): + token = 0 + + +_FAILEDTELL: Final[_TYPE_FAILEDTELL] = _TYPE_FAILEDTELL.token + +_TYPE_BODY_POSITION = typing.Union[int, _TYPE_FAILEDTELL] + +# When sending a request with these methods we aren't expecting +# a body so don't need to set an explicit 'Content-Length: 0' +# The reason we do this in the negative instead of tracking methods +# which 'should' have a body is because unknown methods should be +# treated as if they were 'POST' which *does* expect a body. +_METHODS_NOT_EXPECTING_BODY = {"GET", "HEAD", "DELETE", "TRACE", "OPTIONS", "CONNECT"} + + +def make_headers( + keep_alive: bool | None = None, + accept_encoding: bool | list[str] | str | None = None, + user_agent: str | None = None, + basic_auth: str | None = None, + proxy_basic_auth: str | None = None, + disable_cache: bool | None = None, +) -> dict[str, str]: + """ + Shortcuts for generating request headers. + + :param keep_alive: + If ``True``, adds 'connection: keep-alive' header. + + :param accept_encoding: + Can be a boolean, list, or string. + ``True`` translates to 'gzip,deflate'. If either the ``brotli`` or + ``brotlicffi`` package is installed 'gzip,deflate,br' is used instead. + List will get joined by comma. + String will be used as provided. + + :param user_agent: + String representing the user-agent you want, such as + "python-urllib3/0.6" + + :param basic_auth: + Colon-separated username:password string for 'authorization: basic ...' + auth header. + + :param proxy_basic_auth: + Colon-separated username:password string for 'proxy-authorization: basic ...' + auth header. + + :param disable_cache: + If ``True``, adds 'cache-control: no-cache' header. + + Example: + + .. code-block:: python + + import urllib3 + + print(urllib3.util.make_headers(keep_alive=True, user_agent="Batman/1.0")) + # {'connection': 'keep-alive', 'user-agent': 'Batman/1.0'} + print(urllib3.util.make_headers(accept_encoding=True)) + # {'accept-encoding': 'gzip,deflate'} + """ + headers: dict[str, str] = {} + if accept_encoding: + if isinstance(accept_encoding, str): + pass + elif isinstance(accept_encoding, list): + accept_encoding = ",".join(accept_encoding) + else: + accept_encoding = ACCEPT_ENCODING + headers["accept-encoding"] = accept_encoding + + if user_agent: + headers["user-agent"] = user_agent + + if keep_alive: + headers["connection"] = "keep-alive" + + if basic_auth: + headers[ + "authorization" + ] = f"Basic {b64encode(basic_auth.encode('latin-1')).decode()}" + + if proxy_basic_auth: + headers[ + "proxy-authorization" + ] = f"Basic {b64encode(proxy_basic_auth.encode('latin-1')).decode()}" + + if disable_cache: + headers["cache-control"] = "no-cache" + + return headers + + +def set_file_position( + body: typing.Any, pos: _TYPE_BODY_POSITION | None +) -> _TYPE_BODY_POSITION | None: + """ + If a position is provided, move file to that point. + Otherwise, we'll attempt to record a position for future use. + """ + if pos is not None: + rewind_body(body, pos) + elif getattr(body, "tell", None) is not None: + try: + pos = body.tell() + except OSError: + # This differentiates from None, allowing us to catch + # a failed `tell()` later when trying to rewind the body. + pos = _FAILEDTELL + + return pos + + +def rewind_body(body: typing.IO[typing.AnyStr], body_pos: _TYPE_BODY_POSITION) -> None: + """ + Attempt to rewind body to a certain position. + Primarily used for request redirects and retries. + + :param body: + File-like object that supports seek. + + :param int pos: + Position to seek to in file. + """ + body_seek = getattr(body, "seek", None) + if body_seek is not None and isinstance(body_pos, int): + try: + body_seek(body_pos) + except OSError as e: + raise UnrewindableBodyError( + "An error occurred when rewinding request body for redirect/retry." + ) from e + elif body_pos is _FAILEDTELL: + raise UnrewindableBodyError( + "Unable to record file position for rewinding " + "request body during a redirect/retry." + ) + else: + raise ValueError( + f"body_pos must be of type integer, instead it was {type(body_pos)}." + ) + + +class ChunksAndContentLength(typing.NamedTuple): + chunks: typing.Iterable[bytes] | None + content_length: int | None + + +def body_to_chunks( + body: typing.Any | None, method: str, blocksize: int +) -> ChunksAndContentLength: + """Takes the HTTP request method, body, and blocksize and + transforms them into an iterable of chunks to pass to + socket.sendall() and an optional 'Content-Length' header. + + A 'Content-Length' of 'None' indicates the length of the body + can't be determined so should use 'Transfer-Encoding: chunked' + for framing instead. + """ + + chunks: typing.Iterable[bytes] | None + content_length: int | None + + # No body, we need to make a recommendation on 'Content-Length' + # based on whether that request method is expected to have + # a body or not. + if body is None: + chunks = None + if method.upper() not in _METHODS_NOT_EXPECTING_BODY: + content_length = 0 + else: + content_length = None + + # Bytes or strings become bytes + elif isinstance(body, (str, bytes)): + chunks = (to_bytes(body),) + content_length = len(chunks[0]) + + # File-like object, TODO: use seek() and tell() for length? + elif hasattr(body, "read"): + + def chunk_readable() -> typing.Iterable[bytes]: + nonlocal body, blocksize + encode = isinstance(body, io.TextIOBase) + while True: + datablock = body.read(blocksize) + if not datablock: + break + if encode: + datablock = datablock.encode("iso-8859-1") + yield datablock + + chunks = chunk_readable() + content_length = None + + # Otherwise we need to start checking via duck-typing. + else: + try: + # Check if the body implements the buffer API. + mv = memoryview(body) + except TypeError: + try: + # Check if the body is an iterable + chunks = iter(body) + content_length = None + except TypeError: + raise TypeError( + f"'body' must be a bytes-like object, file-like " + f"object, or iterable. Instead was {body!r}" + ) from None + else: + # Since it implements the buffer API can be passed directly to socket.sendall() + chunks = (body,) + content_length = mv.nbytes + + return ChunksAndContentLength(chunks=chunks, content_length=content_length) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/response.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/response.py new file mode 100644 index 0000000..0f45786 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/response.py @@ -0,0 +1,101 @@ +from __future__ import annotations + +import http.client as httplib +from email.errors import MultipartInvariantViolationDefect, StartBoundaryNotFoundDefect + +from ..exceptions import HeaderParsingError + + +def is_fp_closed(obj: object) -> bool: + """ + Checks whether a given file-like object is closed. + + :param obj: + The file-like object to check. + """ + + try: + # Check `isclosed()` first, in case Python3 doesn't set `closed`. + # GH Issue #928 + return obj.isclosed() # type: ignore[no-any-return, attr-defined] + except AttributeError: + pass + + try: + # Check via the official file-like-object way. + return obj.closed # type: ignore[no-any-return, attr-defined] + except AttributeError: + pass + + try: + # Check if the object is a container for another file-like object that + # gets released on exhaustion (e.g. HTTPResponse). + return obj.fp is None # type: ignore[attr-defined] + except AttributeError: + pass + + raise ValueError("Unable to determine whether fp is closed.") + + +def assert_header_parsing(headers: httplib.HTTPMessage) -> None: + """ + Asserts whether all headers have been successfully parsed. + Extracts encountered errors from the result of parsing headers. + + Only works on Python 3. + + :param http.client.HTTPMessage headers: Headers to verify. + + :raises urllib3.exceptions.HeaderParsingError: + If parsing errors are found. + """ + + # This will fail silently if we pass in the wrong kind of parameter. + # To make debugging easier add an explicit check. + if not isinstance(headers, httplib.HTTPMessage): + raise TypeError(f"expected httplib.Message, got {type(headers)}.") + + unparsed_data = None + + # get_payload is actually email.message.Message.get_payload; + # we're only interested in the result if it's not a multipart message + if not headers.is_multipart(): + payload = headers.get_payload() + + if isinstance(payload, (bytes, str)): + unparsed_data = payload + + # httplib is assuming a response body is available + # when parsing headers even when httplib only sends + # header data to parse_headers() This results in + # defects on multipart responses in particular. + # See: https://github.com/urllib3/urllib3/issues/800 + + # So we ignore the following defects: + # - StartBoundaryNotFoundDefect: + # The claimed start boundary was never found. + # - MultipartInvariantViolationDefect: + # A message claimed to be a multipart but no subparts were found. + defects = [ + defect + for defect in headers.defects + if not isinstance( + defect, (StartBoundaryNotFoundDefect, MultipartInvariantViolationDefect) + ) + ] + + if defects or unparsed_data: + raise HeaderParsingError(defects=defects, unparsed_data=unparsed_data) + + +def is_response_to_head(response: httplib.HTTPResponse) -> bool: + """ + Checks whether the request of a response has been a HEAD-request. + + :param http.client.HTTPResponse response: + Response to check if the originating request + used 'HEAD' as a method. + """ + # FIXME: Can we do this somehow without accessing private httplib _method? + method_str = response._method # type: str # type: ignore[attr-defined] + return method_str.upper() == "HEAD" diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/retry.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/retry.py new file mode 100644 index 0000000..0456cce --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/retry.py @@ -0,0 +1,533 @@ +from __future__ import annotations + +import email +import logging +import random +import re +import time +import typing +from itertools import takewhile +from types import TracebackType + +from ..exceptions import ( + ConnectTimeoutError, + InvalidHeader, + MaxRetryError, + ProtocolError, + ProxyError, + ReadTimeoutError, + ResponseError, +) +from .util import reraise + +if typing.TYPE_CHECKING: + from typing_extensions import Self + + from ..connectionpool import ConnectionPool + from ..response import BaseHTTPResponse + +log = logging.getLogger(__name__) + + +# Data structure for representing the metadata of requests that result in a retry. +class RequestHistory(typing.NamedTuple): + method: str | None + url: str | None + error: Exception | None + status: int | None + redirect_location: str | None + + +class Retry: + """Retry configuration. + + Each retry attempt will create a new Retry object with updated values, so + they can be safely reused. + + Retries can be defined as a default for a pool: + + .. code-block:: python + + retries = Retry(connect=5, read=2, redirect=5) + http = PoolManager(retries=retries) + response = http.request("GET", "https://example.com/") + + Or per-request (which overrides the default for the pool): + + .. code-block:: python + + response = http.request("GET", "https://example.com/", retries=Retry(10)) + + Retries can be disabled by passing ``False``: + + .. code-block:: python + + response = http.request("GET", "https://example.com/", retries=False) + + Errors will be wrapped in :class:`~urllib3.exceptions.MaxRetryError` unless + retries are disabled, in which case the causing exception will be raised. + + :param int total: + Total number of retries to allow. Takes precedence over other counts. + + Set to ``None`` to remove this constraint and fall back on other + counts. + + Set to ``0`` to fail on the first retry. + + Set to ``False`` to disable and imply ``raise_on_redirect=False``. + + :param int connect: + How many connection-related errors to retry on. + + These are errors raised before the request is sent to the remote server, + which we assume has not triggered the server to process the request. + + Set to ``0`` to fail on the first retry of this type. + + :param int read: + How many times to retry on read errors. + + These errors are raised after the request was sent to the server, so the + request may have side-effects. + + Set to ``0`` to fail on the first retry of this type. + + :param int redirect: + How many redirects to perform. Limit this to avoid infinite redirect + loops. + + A redirect is a HTTP response with a status code 301, 302, 303, 307 or + 308. + + Set to ``0`` to fail on the first retry of this type. + + Set to ``False`` to disable and imply ``raise_on_redirect=False``. + + :param int status: + How many times to retry on bad status codes. + + These are retries made on responses, where status code matches + ``status_forcelist``. + + Set to ``0`` to fail on the first retry of this type. + + :param int other: + How many times to retry on other errors. + + Other errors are errors that are not connect, read, redirect or status errors. + These errors might be raised after the request was sent to the server, so the + request might have side-effects. + + Set to ``0`` to fail on the first retry of this type. + + If ``total`` is not set, it's a good idea to set this to 0 to account + for unexpected edge cases and avoid infinite retry loops. + + :param Collection allowed_methods: + Set of uppercased HTTP method verbs that we should retry on. + + By default, we only retry on methods which are considered to be + idempotent (multiple requests with the same parameters end with the + same state). See :attr:`Retry.DEFAULT_ALLOWED_METHODS`. + + Set to a ``None`` value to retry on any verb. + + :param Collection status_forcelist: + A set of integer HTTP status codes that we should force a retry on. + A retry is initiated if the request method is in ``allowed_methods`` + and the response status code is in ``status_forcelist``. + + By default, this is disabled with ``None``. + + :param float backoff_factor: + A backoff factor to apply between attempts after the second try + (most errors are resolved immediately by a second try without a + delay). urllib3 will sleep for:: + + {backoff factor} * (2 ** ({number of previous retries})) + + seconds. If `backoff_jitter` is non-zero, this sleep is extended by:: + + random.uniform(0, {backoff jitter}) + + seconds. For example, if the backoff_factor is 0.1, then :func:`Retry.sleep` will + sleep for [0.0s, 0.2s, 0.4s, 0.8s, ...] between retries. No backoff will ever + be longer than `backoff_max`. + + By default, backoff is disabled (factor set to 0). + + :param bool raise_on_redirect: Whether, if the number of redirects is + exhausted, to raise a MaxRetryError, or to return a response with a + response code in the 3xx range. + + :param bool raise_on_status: Similar meaning to ``raise_on_redirect``: + whether we should raise an exception, or return a response, + if status falls in ``status_forcelist`` range and retries have + been exhausted. + + :param tuple history: The history of the request encountered during + each call to :meth:`~Retry.increment`. The list is in the order + the requests occurred. Each list item is of class :class:`RequestHistory`. + + :param bool respect_retry_after_header: + Whether to respect Retry-After header on status codes defined as + :attr:`Retry.RETRY_AFTER_STATUS_CODES` or not. + + :param Collection remove_headers_on_redirect: + Sequence of headers to remove from the request when a response + indicating a redirect is returned before firing off the redirected + request. + """ + + #: Default methods to be used for ``allowed_methods`` + DEFAULT_ALLOWED_METHODS = frozenset( + ["HEAD", "GET", "PUT", "DELETE", "OPTIONS", "TRACE"] + ) + + #: Default status codes to be used for ``status_forcelist`` + RETRY_AFTER_STATUS_CODES = frozenset([413, 429, 503]) + + #: Default headers to be used for ``remove_headers_on_redirect`` + DEFAULT_REMOVE_HEADERS_ON_REDIRECT = frozenset( + ["Cookie", "Authorization", "Proxy-Authorization"] + ) + + #: Default maximum backoff time. + DEFAULT_BACKOFF_MAX = 120 + + # Backward compatibility; assigned outside of the class. + DEFAULT: typing.ClassVar[Retry] + + def __init__( + self, + total: bool | int | None = 10, + connect: int | None = None, + read: int | None = None, + redirect: bool | int | None = None, + status: int | None = None, + other: int | None = None, + allowed_methods: typing.Collection[str] | None = DEFAULT_ALLOWED_METHODS, + status_forcelist: typing.Collection[int] | None = None, + backoff_factor: float = 0, + backoff_max: float = DEFAULT_BACKOFF_MAX, + raise_on_redirect: bool = True, + raise_on_status: bool = True, + history: tuple[RequestHistory, ...] | None = None, + respect_retry_after_header: bool = True, + remove_headers_on_redirect: typing.Collection[ + str + ] = DEFAULT_REMOVE_HEADERS_ON_REDIRECT, + backoff_jitter: float = 0.0, + ) -> None: + self.total = total + self.connect = connect + self.read = read + self.status = status + self.other = other + + if redirect is False or total is False: + redirect = 0 + raise_on_redirect = False + + self.redirect = redirect + self.status_forcelist = status_forcelist or set() + self.allowed_methods = allowed_methods + self.backoff_factor = backoff_factor + self.backoff_max = backoff_max + self.raise_on_redirect = raise_on_redirect + self.raise_on_status = raise_on_status + self.history = history or () + self.respect_retry_after_header = respect_retry_after_header + self.remove_headers_on_redirect = frozenset( + h.lower() for h in remove_headers_on_redirect + ) + self.backoff_jitter = backoff_jitter + + def new(self, **kw: typing.Any) -> Self: + params = dict( + total=self.total, + connect=self.connect, + read=self.read, + redirect=self.redirect, + status=self.status, + other=self.other, + allowed_methods=self.allowed_methods, + status_forcelist=self.status_forcelist, + backoff_factor=self.backoff_factor, + backoff_max=self.backoff_max, + raise_on_redirect=self.raise_on_redirect, + raise_on_status=self.raise_on_status, + history=self.history, + remove_headers_on_redirect=self.remove_headers_on_redirect, + respect_retry_after_header=self.respect_retry_after_header, + backoff_jitter=self.backoff_jitter, + ) + + params.update(kw) + return type(self)(**params) # type: ignore[arg-type] + + @classmethod + def from_int( + cls, + retries: Retry | bool | int | None, + redirect: bool | int | None = True, + default: Retry | bool | int | None = None, + ) -> Retry: + """Backwards-compatibility for the old retries format.""" + if retries is None: + retries = default if default is not None else cls.DEFAULT + + if isinstance(retries, Retry): + return retries + + redirect = bool(redirect) and None + new_retries = cls(retries, redirect=redirect) + log.debug("Converted retries value: %r -> %r", retries, new_retries) + return new_retries + + def get_backoff_time(self) -> float: + """Formula for computing the current backoff + + :rtype: float + """ + # We want to consider only the last consecutive errors sequence (Ignore redirects). + consecutive_errors_len = len( + list( + takewhile(lambda x: x.redirect_location is None, reversed(self.history)) + ) + ) + if consecutive_errors_len <= 1: + return 0 + + backoff_value = self.backoff_factor * (2 ** (consecutive_errors_len - 1)) + if self.backoff_jitter != 0.0: + backoff_value += random.random() * self.backoff_jitter + return float(max(0, min(self.backoff_max, backoff_value))) + + def parse_retry_after(self, retry_after: str) -> float: + seconds: float + # Whitespace: https://tools.ietf.org/html/rfc7230#section-3.2.4 + if re.match(r"^\s*[0-9]+\s*$", retry_after): + seconds = int(retry_after) + else: + retry_date_tuple = email.utils.parsedate_tz(retry_after) + if retry_date_tuple is None: + raise InvalidHeader(f"Invalid Retry-After header: {retry_after}") + + retry_date = email.utils.mktime_tz(retry_date_tuple) + seconds = retry_date - time.time() + + seconds = max(seconds, 0) + + return seconds + + def get_retry_after(self, response: BaseHTTPResponse) -> float | None: + """Get the value of Retry-After in seconds.""" + + retry_after = response.headers.get("Retry-After") + + if retry_after is None: + return None + + return self.parse_retry_after(retry_after) + + def sleep_for_retry(self, response: BaseHTTPResponse) -> bool: + retry_after = self.get_retry_after(response) + if retry_after: + time.sleep(retry_after) + return True + + return False + + def _sleep_backoff(self) -> None: + backoff = self.get_backoff_time() + if backoff <= 0: + return + time.sleep(backoff) + + def sleep(self, response: BaseHTTPResponse | None = None) -> None: + """Sleep between retry attempts. + + This method will respect a server's ``Retry-After`` response header + and sleep the duration of the time requested. If that is not present, it + will use an exponential backoff. By default, the backoff factor is 0 and + this method will return immediately. + """ + + if self.respect_retry_after_header and response: + slept = self.sleep_for_retry(response) + if slept: + return + + self._sleep_backoff() + + def _is_connection_error(self, err: Exception) -> bool: + """Errors when we're fairly sure that the server did not receive the + request, so it should be safe to retry. + """ + if isinstance(err, ProxyError): + err = err.original_error + return isinstance(err, ConnectTimeoutError) + + def _is_read_error(self, err: Exception) -> bool: + """Errors that occur after the request has been started, so we should + assume that the server began processing it. + """ + return isinstance(err, (ReadTimeoutError, ProtocolError)) + + def _is_method_retryable(self, method: str) -> bool: + """Checks if a given HTTP method should be retried upon, depending if + it is included in the allowed_methods + """ + if self.allowed_methods and method.upper() not in self.allowed_methods: + return False + return True + + def is_retry( + self, method: str, status_code: int, has_retry_after: bool = False + ) -> bool: + """Is this method/status code retryable? (Based on allowlists and control + variables such as the number of total retries to allow, whether to + respect the Retry-After header, whether this header is present, and + whether the returned status code is on the list of status codes to + be retried upon on the presence of the aforementioned header) + """ + if not self._is_method_retryable(method): + return False + + if self.status_forcelist and status_code in self.status_forcelist: + return True + + return bool( + self.total + and self.respect_retry_after_header + and has_retry_after + and (status_code in self.RETRY_AFTER_STATUS_CODES) + ) + + def is_exhausted(self) -> bool: + """Are we out of retries?""" + retry_counts = [ + x + for x in ( + self.total, + self.connect, + self.read, + self.redirect, + self.status, + self.other, + ) + if x + ] + if not retry_counts: + return False + + return min(retry_counts) < 0 + + def increment( + self, + method: str | None = None, + url: str | None = None, + response: BaseHTTPResponse | None = None, + error: Exception | None = None, + _pool: ConnectionPool | None = None, + _stacktrace: TracebackType | None = None, + ) -> Self: + """Return a new Retry object with incremented retry counters. + + :param response: A response object, or None, if the server did not + return a response. + :type response: :class:`~urllib3.response.BaseHTTPResponse` + :param Exception error: An error encountered during the request, or + None if the response was received successfully. + + :return: A new ``Retry`` object. + """ + if self.total is False and error: + # Disabled, indicate to re-raise the error. + raise reraise(type(error), error, _stacktrace) + + total = self.total + if total is not None: + total -= 1 + + connect = self.connect + read = self.read + redirect = self.redirect + status_count = self.status + other = self.other + cause = "unknown" + status = None + redirect_location = None + + if error and self._is_connection_error(error): + # Connect retry? + if connect is False: + raise reraise(type(error), error, _stacktrace) + elif connect is not None: + connect -= 1 + + elif error and self._is_read_error(error): + # Read retry? + if read is False or method is None or not self._is_method_retryable(method): + raise reraise(type(error), error, _stacktrace) + elif read is not None: + read -= 1 + + elif error: + # Other retry? + if other is not None: + other -= 1 + + elif response and response.get_redirect_location(): + # Redirect retry? + if redirect is not None: + redirect -= 1 + cause = "too many redirects" + response_redirect_location = response.get_redirect_location() + if response_redirect_location: + redirect_location = response_redirect_location + status = response.status + + else: + # Incrementing because of a server error like a 500 in + # status_forcelist and the given method is in the allowed_methods + cause = ResponseError.GENERIC_ERROR + if response and response.status: + if status_count is not None: + status_count -= 1 + cause = ResponseError.SPECIFIC_ERROR.format(status_code=response.status) + status = response.status + + history = self.history + ( + RequestHistory(method, url, error, status, redirect_location), + ) + + new_retry = self.new( + total=total, + connect=connect, + read=read, + redirect=redirect, + status=status_count, + other=other, + history=history, + ) + + if new_retry.is_exhausted(): + reason = error or ResponseError(cause) + raise MaxRetryError(_pool, url, reason) from reason # type: ignore[arg-type] + + log.debug("Incremented Retry for (url='%s'): %r", url, new_retry) + + return new_retry + + def __repr__(self) -> str: + return ( + f"{type(self).__name__}(total={self.total}, connect={self.connect}, " + f"read={self.read}, redirect={self.redirect}, status={self.status})" + ) + + +# For backwards compatibility (equivalent to pre-v1.9): +Retry.DEFAULT = Retry(3) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssl_.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssl_.py new file mode 100644 index 0000000..c46dd83 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssl_.py @@ -0,0 +1,509 @@ +from __future__ import annotations + +import hmac +import os +import socket +import sys +import typing +import warnings +from binascii import unhexlify +from hashlib import md5, sha1, sha256 + +from ..exceptions import ProxySchemeUnsupported, SSLError +from .url import _BRACELESS_IPV6_ADDRZ_RE, _IPV4_RE + +SSLContext = None +SSLTransport = None +HAS_NEVER_CHECK_COMMON_NAME = False +IS_PYOPENSSL = False +ALPN_PROTOCOLS = ["http/1.1"] + +_TYPE_VERSION_INFO = typing.Tuple[int, int, int, str, int] + +# Maps the length of a digest to a possible hash function producing this digest +HASHFUNC_MAP = {32: md5, 40: sha1, 64: sha256} + + +def _is_bpo_43522_fixed( + implementation_name: str, + version_info: _TYPE_VERSION_INFO, + pypy_version_info: _TYPE_VERSION_INFO | None, +) -> bool: + """Return True for CPython 3.8.9+, 3.9.3+ or 3.10+ and PyPy 7.3.8+ where + setting SSLContext.hostname_checks_common_name to False works. + + Outside of CPython and PyPy we don't know which implementations work + or not so we conservatively use our hostname matching as we know that works + on all implementations. + + https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963 + https://foss.heptapod.net/pypy/pypy/-/issues/3539 + """ + if implementation_name == "pypy": + # https://foss.heptapod.net/pypy/pypy/-/issues/3129 + return pypy_version_info >= (7, 3, 8) # type: ignore[operator] + elif implementation_name == "cpython": + major_minor = version_info[:2] + micro = version_info[2] + return ( + (major_minor == (3, 8) and micro >= 9) + or (major_minor == (3, 9) and micro >= 3) + or major_minor >= (3, 10) + ) + else: # Defensive: + return False + + +def _is_has_never_check_common_name_reliable( + openssl_version: str, + openssl_version_number: int, + implementation_name: str, + version_info: _TYPE_VERSION_INFO, + pypy_version_info: _TYPE_VERSION_INFO | None, +) -> bool: + # As of May 2023, all released versions of LibreSSL fail to reject certificates with + # only common names, see https://github.com/urllib3/urllib3/pull/3024 + is_openssl = openssl_version.startswith("OpenSSL ") + # Before fixing OpenSSL issue #14579, the SSL_new() API was not copying hostflags + # like X509_CHECK_FLAG_NEVER_CHECK_SUBJECT, which tripped up CPython. + # https://github.com/openssl/openssl/issues/14579 + # This was released in OpenSSL 1.1.1l+ (>=0x101010cf) + is_openssl_issue_14579_fixed = openssl_version_number >= 0x101010CF + + return is_openssl and ( + is_openssl_issue_14579_fixed + or _is_bpo_43522_fixed(implementation_name, version_info, pypy_version_info) + ) + + +if typing.TYPE_CHECKING: + from ssl import VerifyMode + from typing import TypedDict + + from .ssltransport import SSLTransport as SSLTransportType + + class _TYPE_PEER_CERT_RET_DICT(TypedDict, total=False): + subjectAltName: tuple[tuple[str, str], ...] + subject: tuple[tuple[tuple[str, str], ...], ...] + serialNumber: str + + +# Mapping from 'ssl.PROTOCOL_TLSX' to 'TLSVersion.X' +_SSL_VERSION_TO_TLS_VERSION: dict[int, int] = {} + +try: # Do we have ssl at all? + import ssl + from ssl import ( # type: ignore[assignment] + CERT_REQUIRED, + HAS_NEVER_CHECK_COMMON_NAME, + OP_NO_COMPRESSION, + OP_NO_TICKET, + OPENSSL_VERSION, + OPENSSL_VERSION_NUMBER, + PROTOCOL_TLS, + PROTOCOL_TLS_CLIENT, + OP_NO_SSLv2, + OP_NO_SSLv3, + SSLContext, + TLSVersion, + ) + + PROTOCOL_SSLv23 = PROTOCOL_TLS + + # Setting SSLContext.hostname_checks_common_name = False didn't work before CPython + # 3.8.9, 3.9.3, and 3.10 (but OK on PyPy) or OpenSSL 1.1.1l+ + if HAS_NEVER_CHECK_COMMON_NAME and not _is_has_never_check_common_name_reliable( + OPENSSL_VERSION, + OPENSSL_VERSION_NUMBER, + sys.implementation.name, + sys.version_info, + sys.pypy_version_info if sys.implementation.name == "pypy" else None, # type: ignore[attr-defined] + ): + HAS_NEVER_CHECK_COMMON_NAME = False + + # Need to be careful here in case old TLS versions get + # removed in future 'ssl' module implementations. + for attr in ("TLSv1", "TLSv1_1", "TLSv1_2"): + try: + _SSL_VERSION_TO_TLS_VERSION[getattr(ssl, f"PROTOCOL_{attr}")] = getattr( + TLSVersion, attr + ) + except AttributeError: # Defensive: + continue + + from .ssltransport import SSLTransport # type: ignore[assignment] +except ImportError: + OP_NO_COMPRESSION = 0x20000 # type: ignore[assignment] + OP_NO_TICKET = 0x4000 # type: ignore[assignment] + OP_NO_SSLv2 = 0x1000000 # type: ignore[assignment] + OP_NO_SSLv3 = 0x2000000 # type: ignore[assignment] + PROTOCOL_SSLv23 = PROTOCOL_TLS = 2 # type: ignore[assignment] + PROTOCOL_TLS_CLIENT = 16 # type: ignore[assignment] + + +_TYPE_PEER_CERT_RET = typing.Union["_TYPE_PEER_CERT_RET_DICT", bytes, None] + + +def assert_fingerprint(cert: bytes | None, fingerprint: str) -> None: + """ + Checks if given fingerprint matches the supplied certificate. + + :param cert: + Certificate as bytes object. + :param fingerprint: + Fingerprint as string of hexdigits, can be interspersed by colons. + """ + + if cert is None: + raise SSLError("No certificate for the peer.") + + fingerprint = fingerprint.replace(":", "").lower() + digest_length = len(fingerprint) + hashfunc = HASHFUNC_MAP.get(digest_length) + if not hashfunc: + raise SSLError(f"Fingerprint of invalid length: {fingerprint}") + + # We need encode() here for py32; works on py2 and p33. + fingerprint_bytes = unhexlify(fingerprint.encode()) + + cert_digest = hashfunc(cert).digest() + + if not hmac.compare_digest(cert_digest, fingerprint_bytes): + raise SSLError( + f'Fingerprints did not match. Expected "{fingerprint}", got "{cert_digest.hex()}"' + ) + + +def resolve_cert_reqs(candidate: None | int | str) -> VerifyMode: + """ + Resolves the argument to a numeric constant, which can be passed to + the wrap_socket function/method from the ssl module. + Defaults to :data:`ssl.CERT_REQUIRED`. + If given a string it is assumed to be the name of the constant in the + :mod:`ssl` module or its abbreviation. + (So you can specify `REQUIRED` instead of `CERT_REQUIRED`. + If it's neither `None` nor a string we assume it is already the numeric + constant which can directly be passed to wrap_socket. + """ + if candidate is None: + return CERT_REQUIRED + + if isinstance(candidate, str): + res = getattr(ssl, candidate, None) + if res is None: + res = getattr(ssl, "CERT_" + candidate) + return res # type: ignore[no-any-return] + + return candidate # type: ignore[return-value] + + +def resolve_ssl_version(candidate: None | int | str) -> int: + """ + like resolve_cert_reqs + """ + if candidate is None: + return PROTOCOL_TLS + + if isinstance(candidate, str): + res = getattr(ssl, candidate, None) + if res is None: + res = getattr(ssl, "PROTOCOL_" + candidate) + return typing.cast(int, res) + + return candidate + + +def create_urllib3_context( + ssl_version: int | None = None, + cert_reqs: int | None = None, + options: int | None = None, + ciphers: str | None = None, + ssl_minimum_version: int | None = None, + ssl_maximum_version: int | None = None, +) -> ssl.SSLContext: + """Creates and configures an :class:`ssl.SSLContext` instance for use with urllib3. + + :param ssl_version: + The desired protocol version to use. This will default to + PROTOCOL_SSLv23 which will negotiate the highest protocol that both + the server and your installation of OpenSSL support. + + This parameter is deprecated instead use 'ssl_minimum_version'. + :param ssl_minimum_version: + The minimum version of TLS to be used. Use the 'ssl.TLSVersion' enum for specifying the value. + :param ssl_maximum_version: + The maximum version of TLS to be used. Use the 'ssl.TLSVersion' enum for specifying the value. + Not recommended to set to anything other than 'ssl.TLSVersion.MAXIMUM_SUPPORTED' which is the + default value. + :param cert_reqs: + Whether to require the certificate verification. This defaults to + ``ssl.CERT_REQUIRED``. + :param options: + Specific OpenSSL options. These default to ``ssl.OP_NO_SSLv2``, + ``ssl.OP_NO_SSLv3``, ``ssl.OP_NO_COMPRESSION``, and ``ssl.OP_NO_TICKET``. + :param ciphers: + Which cipher suites to allow the server to select. Defaults to either system configured + ciphers if OpenSSL 1.1.1+, otherwise uses a secure default set of ciphers. + :returns: + Constructed SSLContext object with specified options + :rtype: SSLContext + """ + if SSLContext is None: + raise TypeError("Can't create an SSLContext object without an ssl module") + + # This means 'ssl_version' was specified as an exact value. + if ssl_version not in (None, PROTOCOL_TLS, PROTOCOL_TLS_CLIENT): + # Disallow setting 'ssl_version' and 'ssl_minimum|maximum_version' + # to avoid conflicts. + if ssl_minimum_version is not None or ssl_maximum_version is not None: + raise ValueError( + "Can't specify both 'ssl_version' and either " + "'ssl_minimum_version' or 'ssl_maximum_version'" + ) + + # 'ssl_version' is deprecated and will be removed in the future. + else: + # Use 'ssl_minimum_version' and 'ssl_maximum_version' instead. + ssl_minimum_version = _SSL_VERSION_TO_TLS_VERSION.get( + ssl_version, TLSVersion.MINIMUM_SUPPORTED + ) + ssl_maximum_version = _SSL_VERSION_TO_TLS_VERSION.get( + ssl_version, TLSVersion.MAXIMUM_SUPPORTED + ) + + # This warning message is pushing users to use 'ssl_minimum_version' + # instead of both min/max. Best practice is to only set the minimum version and + # keep the maximum version to be it's default value: 'TLSVersion.MAXIMUM_SUPPORTED' + warnings.warn( + "'ssl_version' option is deprecated and will be " + "removed in urllib3 v2.1.0. Instead use 'ssl_minimum_version'", + category=DeprecationWarning, + stacklevel=2, + ) + + # PROTOCOL_TLS is deprecated in Python 3.10 so we always use PROTOCOL_TLS_CLIENT + context = SSLContext(PROTOCOL_TLS_CLIENT) + + if ssl_minimum_version is not None: + context.minimum_version = ssl_minimum_version + else: # Python <3.10 defaults to 'MINIMUM_SUPPORTED' so explicitly set TLSv1.2 here + context.minimum_version = TLSVersion.TLSv1_2 + + if ssl_maximum_version is not None: + context.maximum_version = ssl_maximum_version + + # Unless we're given ciphers defer to either system ciphers in + # the case of OpenSSL 1.1.1+ or use our own secure default ciphers. + if ciphers: + context.set_ciphers(ciphers) + + # Setting the default here, as we may have no ssl module on import + cert_reqs = ssl.CERT_REQUIRED if cert_reqs is None else cert_reqs + + if options is None: + options = 0 + # SSLv2 is easily broken and is considered harmful and dangerous + options |= OP_NO_SSLv2 + # SSLv3 has several problems and is now dangerous + options |= OP_NO_SSLv3 + # Disable compression to prevent CRIME attacks for OpenSSL 1.0+ + # (issue #309) + options |= OP_NO_COMPRESSION + # TLSv1.2 only. Unless set explicitly, do not request tickets. + # This may save some bandwidth on wire, and although the ticket is encrypted, + # there is a risk associated with it being on wire, + # if the server is not rotating its ticketing keys properly. + options |= OP_NO_TICKET + + context.options |= options + + # Enable post-handshake authentication for TLS 1.3, see GH #1634. PHA is + # necessary for conditional client cert authentication with TLS 1.3. + # The attribute is None for OpenSSL <= 1.1.0 or does not exist when using + # an SSLContext created by pyOpenSSL. + if getattr(context, "post_handshake_auth", None) is not None: + context.post_handshake_auth = True + + # The order of the below lines setting verify_mode and check_hostname + # matter due to safe-guards SSLContext has to prevent an SSLContext with + # check_hostname=True, verify_mode=NONE/OPTIONAL. + # We always set 'check_hostname=False' for pyOpenSSL so we rely on our own + # 'ssl.match_hostname()' implementation. + if cert_reqs == ssl.CERT_REQUIRED and not IS_PYOPENSSL: + context.verify_mode = cert_reqs + context.check_hostname = True + else: + context.check_hostname = False + context.verify_mode = cert_reqs + + try: + context.hostname_checks_common_name = False + except AttributeError: # Defensive: for CPython < 3.8.9 and 3.9.3; for PyPy < 7.3.8 + pass + + # Enable logging of TLS session keys via defacto standard environment variable + # 'SSLKEYLOGFILE', if the feature is available (Python 3.8+). Skip empty values. + if hasattr(context, "keylog_filename"): + sslkeylogfile = os.environ.get("SSLKEYLOGFILE") + if sslkeylogfile: + context.keylog_filename = sslkeylogfile + + return context + + +@typing.overload +def ssl_wrap_socket( + sock: socket.socket, + keyfile: str | None = ..., + certfile: str | None = ..., + cert_reqs: int | None = ..., + ca_certs: str | None = ..., + server_hostname: str | None = ..., + ssl_version: int | None = ..., + ciphers: str | None = ..., + ssl_context: ssl.SSLContext | None = ..., + ca_cert_dir: str | None = ..., + key_password: str | None = ..., + ca_cert_data: None | str | bytes = ..., + tls_in_tls: typing.Literal[False] = ..., +) -> ssl.SSLSocket: + ... + + +@typing.overload +def ssl_wrap_socket( + sock: socket.socket, + keyfile: str | None = ..., + certfile: str | None = ..., + cert_reqs: int | None = ..., + ca_certs: str | None = ..., + server_hostname: str | None = ..., + ssl_version: int | None = ..., + ciphers: str | None = ..., + ssl_context: ssl.SSLContext | None = ..., + ca_cert_dir: str | None = ..., + key_password: str | None = ..., + ca_cert_data: None | str | bytes = ..., + tls_in_tls: bool = ..., +) -> ssl.SSLSocket | SSLTransportType: + ... + + +def ssl_wrap_socket( + sock: socket.socket, + keyfile: str | None = None, + certfile: str | None = None, + cert_reqs: int | None = None, + ca_certs: str | None = None, + server_hostname: str | None = None, + ssl_version: int | None = None, + ciphers: str | None = None, + ssl_context: ssl.SSLContext | None = None, + ca_cert_dir: str | None = None, + key_password: str | None = None, + ca_cert_data: None | str | bytes = None, + tls_in_tls: bool = False, +) -> ssl.SSLSocket | SSLTransportType: + """ + All arguments except for server_hostname, ssl_context, tls_in_tls, ca_cert_data and + ca_cert_dir have the same meaning as they do when using + :func:`ssl.create_default_context`, :meth:`ssl.SSLContext.load_cert_chain`, + :meth:`ssl.SSLContext.set_ciphers` and :meth:`ssl.SSLContext.wrap_socket`. + + :param server_hostname: + When SNI is supported, the expected hostname of the certificate + :param ssl_context: + A pre-made :class:`SSLContext` object. If none is provided, one will + be created using :func:`create_urllib3_context`. + :param ciphers: + A string of ciphers we wish the client to support. + :param ca_cert_dir: + A directory containing CA certificates in multiple separate files, as + supported by OpenSSL's -CApath flag or the capath argument to + SSLContext.load_verify_locations(). + :param key_password: + Optional password if the keyfile is encrypted. + :param ca_cert_data: + Optional string containing CA certificates in PEM format suitable for + passing as the cadata parameter to SSLContext.load_verify_locations() + :param tls_in_tls: + Use SSLTransport to wrap the existing socket. + """ + context = ssl_context + if context is None: + # Note: This branch of code and all the variables in it are only used in tests. + # We should consider deprecating and removing this code. + context = create_urllib3_context(ssl_version, cert_reqs, ciphers=ciphers) + + if ca_certs or ca_cert_dir or ca_cert_data: + try: + context.load_verify_locations(ca_certs, ca_cert_dir, ca_cert_data) + except OSError as e: + raise SSLError(e) from e + + elif ssl_context is None and hasattr(context, "load_default_certs"): + # try to load OS default certs; works well on Windows. + context.load_default_certs() + + # Attempt to detect if we get the goofy behavior of the + # keyfile being encrypted and OpenSSL asking for the + # passphrase via the terminal and instead error out. + if keyfile and key_password is None and _is_key_file_encrypted(keyfile): + raise SSLError("Client private key is encrypted, password is required") + + if certfile: + if key_password is None: + context.load_cert_chain(certfile, keyfile) + else: + context.load_cert_chain(certfile, keyfile, key_password) + + try: + context.set_alpn_protocols(ALPN_PROTOCOLS) + except NotImplementedError: # Defensive: in CI, we always have set_alpn_protocols + pass + + ssl_sock = _ssl_wrap_socket_impl(sock, context, tls_in_tls, server_hostname) + return ssl_sock + + +def is_ipaddress(hostname: str | bytes) -> bool: + """Detects whether the hostname given is an IPv4 or IPv6 address. + Also detects IPv6 addresses with Zone IDs. + + :param str hostname: Hostname to examine. + :return: True if the hostname is an IP address, False otherwise. + """ + if isinstance(hostname, bytes): + # IDN A-label bytes are ASCII compatible. + hostname = hostname.decode("ascii") + return bool(_IPV4_RE.match(hostname) or _BRACELESS_IPV6_ADDRZ_RE.match(hostname)) + + +def _is_key_file_encrypted(key_file: str) -> bool: + """Detects if a key file is encrypted or not.""" + with open(key_file) as f: + for line in f: + # Look for Proc-Type: 4,ENCRYPTED + if "ENCRYPTED" in line: + return True + + return False + + +def _ssl_wrap_socket_impl( + sock: socket.socket, + ssl_context: ssl.SSLContext, + tls_in_tls: bool, + server_hostname: str | None = None, +) -> ssl.SSLSocket | SSLTransportType: + if tls_in_tls: + if not SSLTransport: + # Import error, ssl is not available. + raise ProxySchemeUnsupported( + "TLS in TLS requires support for the 'ssl' module" + ) + + SSLTransport._validate_ssl_context_for_tls_in_tls(ssl_context) + return SSLTransport(sock, ssl_context, server_hostname) + + return ssl_context.wrap_socket(sock, server_hostname=server_hostname) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssl_match_hostname.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssl_match_hostname.py new file mode 100644 index 0000000..453cfd4 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssl_match_hostname.py @@ -0,0 +1,159 @@ +"""The match_hostname() function from Python 3.5, essential when using SSL.""" + +# Note: This file is under the PSF license as the code comes from the python +# stdlib. http://docs.python.org/3/license.html +# It is modified to remove commonName support. + +from __future__ import annotations + +import ipaddress +import re +import typing +from ipaddress import IPv4Address, IPv6Address + +if typing.TYPE_CHECKING: + from .ssl_ import _TYPE_PEER_CERT_RET_DICT + +__version__ = "3.5.0.1" + + +class CertificateError(ValueError): + pass + + +def _dnsname_match( + dn: typing.Any, hostname: str, max_wildcards: int = 1 +) -> typing.Match[str] | None | bool: + """Matching according to RFC 6125, section 6.4.3 + + http://tools.ietf.org/html/rfc6125#section-6.4.3 + """ + pats = [] + if not dn: + return False + + # Ported from python3-syntax: + # leftmost, *remainder = dn.split(r'.') + parts = dn.split(r".") + leftmost = parts[0] + remainder = parts[1:] + + wildcards = leftmost.count("*") + if wildcards > max_wildcards: + # Issue #17980: avoid denials of service by refusing more + # than one wildcard per fragment. A survey of established + # policy among SSL implementations showed it to be a + # reasonable choice. + raise CertificateError( + "too many wildcards in certificate DNS name: " + repr(dn) + ) + + # speed up common case w/o wildcards + if not wildcards: + return bool(dn.lower() == hostname.lower()) + + # RFC 6125, section 6.4.3, subitem 1. + # The client SHOULD NOT attempt to match a presented identifier in which + # the wildcard character comprises a label other than the left-most label. + if leftmost == "*": + # When '*' is a fragment by itself, it matches a non-empty dotless + # fragment. + pats.append("[^.]+") + elif leftmost.startswith("xn--") or hostname.startswith("xn--"): + # RFC 6125, section 6.4.3, subitem 3. + # The client SHOULD NOT attempt to match a presented identifier + # where the wildcard character is embedded within an A-label or + # U-label of an internationalized domain name. + pats.append(re.escape(leftmost)) + else: + # Otherwise, '*' matches any dotless string, e.g. www* + pats.append(re.escape(leftmost).replace(r"\*", "[^.]*")) + + # add the remaining fragments, ignore any wildcards + for frag in remainder: + pats.append(re.escape(frag)) + + pat = re.compile(r"\A" + r"\.".join(pats) + r"\Z", re.IGNORECASE) + return pat.match(hostname) + + +def _ipaddress_match(ipname: str, host_ip: IPv4Address | IPv6Address) -> bool: + """Exact matching of IP addresses. + + RFC 9110 section 4.3.5: "A reference identity of IP-ID contains the decoded + bytes of the IP address. An IP version 4 address is 4 octets, and an IP + version 6 address is 16 octets. [...] A reference identity of type IP-ID + matches if the address is identical to an iPAddress value of the + subjectAltName extension of the certificate." + """ + # OpenSSL may add a trailing newline to a subjectAltName's IP address + # Divergence from upstream: ipaddress can't handle byte str + ip = ipaddress.ip_address(ipname.rstrip()) + return bool(ip.packed == host_ip.packed) + + +def match_hostname( + cert: _TYPE_PEER_CERT_RET_DICT | None, + hostname: str, + hostname_checks_common_name: bool = False, +) -> None: + """Verify that *cert* (in decoded format as returned by + SSLSocket.getpeercert()) matches the *hostname*. RFC 2818 and RFC 6125 + rules are followed, but IP addresses are not accepted for *hostname*. + + CertificateError is raised on failure. On success, the function + returns nothing. + """ + if not cert: + raise ValueError( + "empty or no certificate, match_hostname needs a " + "SSL socket or SSL context with either " + "CERT_OPTIONAL or CERT_REQUIRED" + ) + try: + # Divergence from upstream: ipaddress can't handle byte str + # + # The ipaddress module shipped with Python < 3.9 does not support + # scoped IPv6 addresses so we unconditionally strip the Zone IDs for + # now. Once we drop support for Python 3.9 we can remove this branch. + if "%" in hostname: + host_ip = ipaddress.ip_address(hostname[: hostname.rfind("%")]) + else: + host_ip = ipaddress.ip_address(hostname) + + except ValueError: + # Not an IP address (common case) + host_ip = None + dnsnames = [] + san: tuple[tuple[str, str], ...] = cert.get("subjectAltName", ()) + key: str + value: str + for key, value in san: + if key == "DNS": + if host_ip is None and _dnsname_match(value, hostname): + return + dnsnames.append(value) + elif key == "IP Address": + if host_ip is not None and _ipaddress_match(value, host_ip): + return + dnsnames.append(value) + + # We only check 'commonName' if it's enabled and we're not verifying + # an IP address. IP addresses aren't valid within 'commonName'. + if hostname_checks_common_name and host_ip is None and not dnsnames: + for sub in cert.get("subject", ()): + for key, value in sub: + if key == "commonName": + if _dnsname_match(value, hostname): + return + dnsnames.append(value) + + if len(dnsnames) > 1: + raise CertificateError( + "hostname %r " + "doesn't match either of %s" % (hostname, ", ".join(map(repr, dnsnames))) + ) + elif len(dnsnames) == 1: + raise CertificateError(f"hostname {hostname!r} doesn't match {dnsnames[0]!r}") + else: + raise CertificateError("no appropriate subjectAltName fields were found") diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssltransport.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssltransport.py new file mode 100644 index 0000000..b52c477 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/ssltransport.py @@ -0,0 +1,279 @@ +from __future__ import annotations + +import io +import socket +import ssl +import typing + +from ..exceptions import ProxySchemeUnsupported + +if typing.TYPE_CHECKING: + from typing_extensions import Self + + from .ssl_ import _TYPE_PEER_CERT_RET, _TYPE_PEER_CERT_RET_DICT + + +_WriteBuffer = typing.Union[bytearray, memoryview] +_ReturnValue = typing.TypeVar("_ReturnValue") + +SSL_BLOCKSIZE = 16384 + + +class SSLTransport: + """ + The SSLTransport wraps an existing socket and establishes an SSL connection. + + Contrary to Python's implementation of SSLSocket, it allows you to chain + multiple TLS connections together. It's particularly useful if you need to + implement TLS within TLS. + + The class supports most of the socket API operations. + """ + + @staticmethod + def _validate_ssl_context_for_tls_in_tls(ssl_context: ssl.SSLContext) -> None: + """ + Raises a ProxySchemeUnsupported if the provided ssl_context can't be used + for TLS in TLS. + + The only requirement is that the ssl_context provides the 'wrap_bio' + methods. + """ + + if not hasattr(ssl_context, "wrap_bio"): + raise ProxySchemeUnsupported( + "TLS in TLS requires SSLContext.wrap_bio() which isn't " + "available on non-native SSLContext" + ) + + def __init__( + self, + socket: socket.socket, + ssl_context: ssl.SSLContext, + server_hostname: str | None = None, + suppress_ragged_eofs: bool = True, + ) -> None: + """ + Create an SSLTransport around socket using the provided ssl_context. + """ + self.incoming = ssl.MemoryBIO() + self.outgoing = ssl.MemoryBIO() + + self.suppress_ragged_eofs = suppress_ragged_eofs + self.socket = socket + + self.sslobj = ssl_context.wrap_bio( + self.incoming, self.outgoing, server_hostname=server_hostname + ) + + # Perform initial handshake. + self._ssl_io_loop(self.sslobj.do_handshake) + + def __enter__(self) -> Self: + return self + + def __exit__(self, *_: typing.Any) -> None: + self.close() + + def fileno(self) -> int: + return self.socket.fileno() + + def read(self, len: int = 1024, buffer: typing.Any | None = None) -> int | bytes: + return self._wrap_ssl_read(len, buffer) + + def recv(self, buflen: int = 1024, flags: int = 0) -> int | bytes: + if flags != 0: + raise ValueError("non-zero flags not allowed in calls to recv") + return self._wrap_ssl_read(buflen) + + def recv_into( + self, + buffer: _WriteBuffer, + nbytes: int | None = None, + flags: int = 0, + ) -> None | int | bytes: + if flags != 0: + raise ValueError("non-zero flags not allowed in calls to recv_into") + if nbytes is None: + nbytes = len(buffer) + return self.read(nbytes, buffer) + + def sendall(self, data: bytes, flags: int = 0) -> None: + if flags != 0: + raise ValueError("non-zero flags not allowed in calls to sendall") + count = 0 + with memoryview(data) as view, view.cast("B") as byte_view: + amount = len(byte_view) + while count < amount: + v = self.send(byte_view[count:]) + count += v + + def send(self, data: bytes, flags: int = 0) -> int: + if flags != 0: + raise ValueError("non-zero flags not allowed in calls to send") + return self._ssl_io_loop(self.sslobj.write, data) + + def makefile( + self, + mode: str, + buffering: int | None = None, + *, + encoding: str | None = None, + errors: str | None = None, + newline: str | None = None, + ) -> typing.BinaryIO | typing.TextIO | socket.SocketIO: + """ + Python's httpclient uses makefile and buffered io when reading HTTP + messages and we need to support it. + + This is unfortunately a copy and paste of socket.py makefile with small + changes to point to the socket directly. + """ + if not set(mode) <= {"r", "w", "b"}: + raise ValueError(f"invalid mode {mode!r} (only r, w, b allowed)") + + writing = "w" in mode + reading = "r" in mode or not writing + assert reading or writing + binary = "b" in mode + rawmode = "" + if reading: + rawmode += "r" + if writing: + rawmode += "w" + raw = socket.SocketIO(self, rawmode) # type: ignore[arg-type] + self.socket._io_refs += 1 # type: ignore[attr-defined] + if buffering is None: + buffering = -1 + if buffering < 0: + buffering = io.DEFAULT_BUFFER_SIZE + if buffering == 0: + if not binary: + raise ValueError("unbuffered streams must be binary") + return raw + buffer: typing.BinaryIO + if reading and writing: + buffer = io.BufferedRWPair(raw, raw, buffering) # type: ignore[assignment] + elif reading: + buffer = io.BufferedReader(raw, buffering) + else: + assert writing + buffer = io.BufferedWriter(raw, buffering) + if binary: + return buffer + text = io.TextIOWrapper(buffer, encoding, errors, newline) + text.mode = mode # type: ignore[misc] + return text + + def unwrap(self) -> None: + self._ssl_io_loop(self.sslobj.unwrap) + + def close(self) -> None: + self.socket.close() + + @typing.overload + def getpeercert( + self, binary_form: typing.Literal[False] = ... + ) -> _TYPE_PEER_CERT_RET_DICT | None: + ... + + @typing.overload + def getpeercert(self, binary_form: typing.Literal[True]) -> bytes | None: + ... + + def getpeercert(self, binary_form: bool = False) -> _TYPE_PEER_CERT_RET: + return self.sslobj.getpeercert(binary_form) # type: ignore[return-value] + + def version(self) -> str | None: + return self.sslobj.version() + + def cipher(self) -> tuple[str, str, int] | None: + return self.sslobj.cipher() + + def selected_alpn_protocol(self) -> str | None: + return self.sslobj.selected_alpn_protocol() + + def selected_npn_protocol(self) -> str | None: + return self.sslobj.selected_npn_protocol() + + def shared_ciphers(self) -> list[tuple[str, str, int]] | None: + return self.sslobj.shared_ciphers() + + def compression(self) -> str | None: + return self.sslobj.compression() + + def settimeout(self, value: float | None) -> None: + self.socket.settimeout(value) + + def gettimeout(self) -> float | None: + return self.socket.gettimeout() + + def _decref_socketios(self) -> None: + self.socket._decref_socketios() # type: ignore[attr-defined] + + def _wrap_ssl_read(self, len: int, buffer: bytearray | None = None) -> int | bytes: + try: + return self._ssl_io_loop(self.sslobj.read, len, buffer) + except ssl.SSLError as e: + if e.errno == ssl.SSL_ERROR_EOF and self.suppress_ragged_eofs: + return 0 # eof, return 0. + else: + raise + + # func is sslobj.do_handshake or sslobj.unwrap + @typing.overload + def _ssl_io_loop(self, func: typing.Callable[[], None]) -> None: + ... + + # func is sslobj.write, arg1 is data + @typing.overload + def _ssl_io_loop(self, func: typing.Callable[[bytes], int], arg1: bytes) -> int: + ... + + # func is sslobj.read, arg1 is len, arg2 is buffer + @typing.overload + def _ssl_io_loop( + self, + func: typing.Callable[[int, bytearray | None], bytes], + arg1: int, + arg2: bytearray | None, + ) -> bytes: + ... + + def _ssl_io_loop( + self, + func: typing.Callable[..., _ReturnValue], + arg1: None | bytes | int = None, + arg2: bytearray | None = None, + ) -> _ReturnValue: + """Performs an I/O loop between incoming/outgoing and the socket.""" + should_loop = True + ret = None + + while should_loop: + errno = None + try: + if arg1 is None and arg2 is None: + ret = func() + elif arg2 is None: + ret = func(arg1) + else: + ret = func(arg1, arg2) + except ssl.SSLError as e: + if e.errno not in (ssl.SSL_ERROR_WANT_READ, ssl.SSL_ERROR_WANT_WRITE): + # WANT_READ, and WANT_WRITE are expected, others are not. + raise e + errno = e.errno + + buf = self.outgoing.read() + self.socket.sendall(buf) + + if errno is None: + should_loop = False + elif errno == ssl.SSL_ERROR_WANT_READ: + buf = self.socket.recv(SSL_BLOCKSIZE) + if buf: + self.incoming.write(buf) + else: + self.incoming.write_eof() + return typing.cast(_ReturnValue, ret) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/timeout.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/timeout.py new file mode 100644 index 0000000..4bb1be1 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/timeout.py @@ -0,0 +1,275 @@ +from __future__ import annotations + +import time +import typing +from enum import Enum +from socket import getdefaulttimeout + +from ..exceptions import TimeoutStateError + +if typing.TYPE_CHECKING: + from typing import Final + + +class _TYPE_DEFAULT(Enum): + # This value should never be passed to socket.settimeout() so for safety we use a -1. + # socket.settimout() raises a ValueError for negative values. + token = -1 + + +_DEFAULT_TIMEOUT: Final[_TYPE_DEFAULT] = _TYPE_DEFAULT.token + +_TYPE_TIMEOUT = typing.Optional[typing.Union[float, _TYPE_DEFAULT]] + + +class Timeout: + """Timeout configuration. + + Timeouts can be defined as a default for a pool: + + .. code-block:: python + + import urllib3 + + timeout = urllib3.util.Timeout(connect=2.0, read=7.0) + + http = urllib3.PoolManager(timeout=timeout) + + resp = http.request("GET", "https://example.com/") + + print(resp.status) + + Or per-request (which overrides the default for the pool): + + .. code-block:: python + + response = http.request("GET", "https://example.com/", timeout=Timeout(10)) + + Timeouts can be disabled by setting all the parameters to ``None``: + + .. code-block:: python + + no_timeout = Timeout(connect=None, read=None) + response = http.request("GET", "https://example.com/", timeout=no_timeout) + + + :param total: + This combines the connect and read timeouts into one; the read timeout + will be set to the time leftover from the connect attempt. In the + event that both a connect timeout and a total are specified, or a read + timeout and a total are specified, the shorter timeout will be applied. + + Defaults to None. + + :type total: int, float, or None + + :param connect: + The maximum amount of time (in seconds) to wait for a connection + attempt to a server to succeed. Omitting the parameter will default the + connect timeout to the system default, probably `the global default + timeout in socket.py + `_. + None will set an infinite timeout for connection attempts. + + :type connect: int, float, or None + + :param read: + The maximum amount of time (in seconds) to wait between consecutive + read operations for a response from the server. Omitting the parameter + will default the read timeout to the system default, probably `the + global default timeout in socket.py + `_. + None will set an infinite timeout. + + :type read: int, float, or None + + .. note:: + + Many factors can affect the total amount of time for urllib3 to return + an HTTP response. + + For example, Python's DNS resolver does not obey the timeout specified + on the socket. Other factors that can affect total request time include + high CPU load, high swap, the program running at a low priority level, + or other behaviors. + + In addition, the read and total timeouts only measure the time between + read operations on the socket connecting the client and the server, + not the total amount of time for the request to return a complete + response. For most requests, the timeout is raised because the server + has not sent the first byte in the specified time. This is not always + the case; if a server streams one byte every fifteen seconds, a timeout + of 20 seconds will not trigger, even though the request will take + several minutes to complete. + """ + + #: A sentinel object representing the default timeout value + DEFAULT_TIMEOUT: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT + + def __init__( + self, + total: _TYPE_TIMEOUT = None, + connect: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + read: _TYPE_TIMEOUT = _DEFAULT_TIMEOUT, + ) -> None: + self._connect = self._validate_timeout(connect, "connect") + self._read = self._validate_timeout(read, "read") + self.total = self._validate_timeout(total, "total") + self._start_connect: float | None = None + + def __repr__(self) -> str: + return f"{type(self).__name__}(connect={self._connect!r}, read={self._read!r}, total={self.total!r})" + + # __str__ provided for backwards compatibility + __str__ = __repr__ + + @staticmethod + def resolve_default_timeout(timeout: _TYPE_TIMEOUT) -> float | None: + return getdefaulttimeout() if timeout is _DEFAULT_TIMEOUT else timeout + + @classmethod + def _validate_timeout(cls, value: _TYPE_TIMEOUT, name: str) -> _TYPE_TIMEOUT: + """Check that a timeout attribute is valid. + + :param value: The timeout value to validate + :param name: The name of the timeout attribute to validate. This is + used to specify in error messages. + :return: The validated and casted version of the given value. + :raises ValueError: If it is a numeric value less than or equal to + zero, or the type is not an integer, float, or None. + """ + if value is None or value is _DEFAULT_TIMEOUT: + return value + + if isinstance(value, bool): + raise ValueError( + "Timeout cannot be a boolean value. It must " + "be an int, float or None." + ) + try: + float(value) + except (TypeError, ValueError): + raise ValueError( + "Timeout value %s was %s, but it must be an " + "int, float or None." % (name, value) + ) from None + + try: + if value <= 0: + raise ValueError( + "Attempted to set %s timeout to %s, but the " + "timeout cannot be set to a value less " + "than or equal to 0." % (name, value) + ) + except TypeError: + raise ValueError( + "Timeout value %s was %s, but it must be an " + "int, float or None." % (name, value) + ) from None + + return value + + @classmethod + def from_float(cls, timeout: _TYPE_TIMEOUT) -> Timeout: + """Create a new Timeout from a legacy timeout value. + + The timeout value used by httplib.py sets the same timeout on the + connect(), and recv() socket requests. This creates a :class:`Timeout` + object that sets the individual timeouts to the ``timeout`` value + passed to this function. + + :param timeout: The legacy timeout value. + :type timeout: integer, float, :attr:`urllib3.util.Timeout.DEFAULT_TIMEOUT`, or None + :return: Timeout object + :rtype: :class:`Timeout` + """ + return Timeout(read=timeout, connect=timeout) + + def clone(self) -> Timeout: + """Create a copy of the timeout object + + Timeout properties are stored per-pool but each request needs a fresh + Timeout object to ensure each one has its own start/stop configured. + + :return: a copy of the timeout object + :rtype: :class:`Timeout` + """ + # We can't use copy.deepcopy because that will also create a new object + # for _GLOBAL_DEFAULT_TIMEOUT, which socket.py uses as a sentinel to + # detect the user default. + return Timeout(connect=self._connect, read=self._read, total=self.total) + + def start_connect(self) -> float: + """Start the timeout clock, used during a connect() attempt + + :raises urllib3.exceptions.TimeoutStateError: if you attempt + to start a timer that has been started already. + """ + if self._start_connect is not None: + raise TimeoutStateError("Timeout timer has already been started.") + self._start_connect = time.monotonic() + return self._start_connect + + def get_connect_duration(self) -> float: + """Gets the time elapsed since the call to :meth:`start_connect`. + + :return: Elapsed time in seconds. + :rtype: float + :raises urllib3.exceptions.TimeoutStateError: if you attempt + to get duration for a timer that hasn't been started. + """ + if self._start_connect is None: + raise TimeoutStateError( + "Can't get connect duration for timer that has not started." + ) + return time.monotonic() - self._start_connect + + @property + def connect_timeout(self) -> _TYPE_TIMEOUT: + """Get the value to use when setting a connection timeout. + + This will be a positive float or integer, the value None + (never timeout), or the default system timeout. + + :return: Connect timeout. + :rtype: int, float, :attr:`Timeout.DEFAULT_TIMEOUT` or None + """ + if self.total is None: + return self._connect + + if self._connect is None or self._connect is _DEFAULT_TIMEOUT: + return self.total + + return min(self._connect, self.total) # type: ignore[type-var] + + @property + def read_timeout(self) -> float | None: + """Get the value for the read timeout. + + This assumes some time has elapsed in the connection timeout and + computes the read timeout appropriately. + + If self.total is set, the read timeout is dependent on the amount of + time taken by the connect timeout. If the connection time has not been + established, a :exc:`~urllib3.exceptions.TimeoutStateError` will be + raised. + + :return: Value to use for the read timeout. + :rtype: int, float or None + :raises urllib3.exceptions.TimeoutStateError: If :meth:`start_connect` + has not yet been called on this object. + """ + if ( + self.total is not None + and self.total is not _DEFAULT_TIMEOUT + and self._read is not None + and self._read is not _DEFAULT_TIMEOUT + ): + # In case the connect timeout has not yet been established. + if self._start_connect is None: + return self._read + return max(0, min(self.total - self.get_connect_duration(), self._read)) + elif self.total is not None and self.total is not _DEFAULT_TIMEOUT: + return max(0, self.total - self.get_connect_duration()) + else: + return self.resolve_default_timeout(self._read) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/url.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/url.py new file mode 100644 index 0000000..d53ea93 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/url.py @@ -0,0 +1,471 @@ +from __future__ import annotations + +import re +import typing + +from ..exceptions import LocationParseError +from .util import to_str + +# We only want to normalize urls with an HTTP(S) scheme. +# urllib3 infers URLs without a scheme (None) to be http. +_NORMALIZABLE_SCHEMES = ("http", "https", None) + +# Almost all of these patterns were derived from the +# 'rfc3986' module: https://github.com/python-hyper/rfc3986 +_PERCENT_RE = re.compile(r"%[a-fA-F0-9]{2}") +_SCHEME_RE = re.compile(r"^(?:[a-zA-Z][a-zA-Z0-9+-]*:|/)") +_URI_RE = re.compile( + r"^(?:([a-zA-Z][a-zA-Z0-9+.-]*):)?" + r"(?://([^\\/?#]*))?" + r"([^?#]*)" + r"(?:\?([^#]*))?" + r"(?:#(.*))?$", + re.UNICODE | re.DOTALL, +) + +_IPV4_PAT = r"(?:[0-9]{1,3}\.){3}[0-9]{1,3}" +_HEX_PAT = "[0-9A-Fa-f]{1,4}" +_LS32_PAT = "(?:{hex}:{hex}|{ipv4})".format(hex=_HEX_PAT, ipv4=_IPV4_PAT) +_subs = {"hex": _HEX_PAT, "ls32": _LS32_PAT} +_variations = [ + # 6( h16 ":" ) ls32 + "(?:%(hex)s:){6}%(ls32)s", + # "::" 5( h16 ":" ) ls32 + "::(?:%(hex)s:){5}%(ls32)s", + # [ h16 ] "::" 4( h16 ":" ) ls32 + "(?:%(hex)s)?::(?:%(hex)s:){4}%(ls32)s", + # [ *1( h16 ":" ) h16 ] "::" 3( h16 ":" ) ls32 + "(?:(?:%(hex)s:)?%(hex)s)?::(?:%(hex)s:){3}%(ls32)s", + # [ *2( h16 ":" ) h16 ] "::" 2( h16 ":" ) ls32 + "(?:(?:%(hex)s:){0,2}%(hex)s)?::(?:%(hex)s:){2}%(ls32)s", + # [ *3( h16 ":" ) h16 ] "::" h16 ":" ls32 + "(?:(?:%(hex)s:){0,3}%(hex)s)?::%(hex)s:%(ls32)s", + # [ *4( h16 ":" ) h16 ] "::" ls32 + "(?:(?:%(hex)s:){0,4}%(hex)s)?::%(ls32)s", + # [ *5( h16 ":" ) h16 ] "::" h16 + "(?:(?:%(hex)s:){0,5}%(hex)s)?::%(hex)s", + # [ *6( h16 ":" ) h16 ] "::" + "(?:(?:%(hex)s:){0,6}%(hex)s)?::", +] + +_UNRESERVED_PAT = r"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789._\-~" +_IPV6_PAT = "(?:" + "|".join([x % _subs for x in _variations]) + ")" +_ZONE_ID_PAT = "(?:%25|%)(?:[" + _UNRESERVED_PAT + "]|%[a-fA-F0-9]{2})+" +_IPV6_ADDRZ_PAT = r"\[" + _IPV6_PAT + r"(?:" + _ZONE_ID_PAT + r")?\]" +_REG_NAME_PAT = r"(?:[^\[\]%:/?#]|%[a-fA-F0-9]{2})*" +_TARGET_RE = re.compile(r"^(/[^?#]*)(?:\?([^#]*))?(?:#.*)?$") + +_IPV4_RE = re.compile("^" + _IPV4_PAT + "$") +_IPV6_RE = re.compile("^" + _IPV6_PAT + "$") +_IPV6_ADDRZ_RE = re.compile("^" + _IPV6_ADDRZ_PAT + "$") +_BRACELESS_IPV6_ADDRZ_RE = re.compile("^" + _IPV6_ADDRZ_PAT[2:-2] + "$") +_ZONE_ID_RE = re.compile("(" + _ZONE_ID_PAT + r")\]$") + +_HOST_PORT_PAT = ("^(%s|%s|%s)(?::0*?(|0|[1-9][0-9]{0,4}))?$") % ( + _REG_NAME_PAT, + _IPV4_PAT, + _IPV6_ADDRZ_PAT, +) +_HOST_PORT_RE = re.compile(_HOST_PORT_PAT, re.UNICODE | re.DOTALL) + +_UNRESERVED_CHARS = set( + "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789._-~" +) +_SUB_DELIM_CHARS = set("!$&'()*+,;=") +_USERINFO_CHARS = _UNRESERVED_CHARS | _SUB_DELIM_CHARS | {":"} +_PATH_CHARS = _USERINFO_CHARS | {"@", "/"} +_QUERY_CHARS = _FRAGMENT_CHARS = _PATH_CHARS | {"?"} + + +class Url( + typing.NamedTuple( + "Url", + [ + ("scheme", typing.Optional[str]), + ("auth", typing.Optional[str]), + ("host", typing.Optional[str]), + ("port", typing.Optional[int]), + ("path", typing.Optional[str]), + ("query", typing.Optional[str]), + ("fragment", typing.Optional[str]), + ], + ) +): + """ + Data structure for representing an HTTP URL. Used as a return value for + :func:`parse_url`. Both the scheme and host are normalized as they are + both case-insensitive according to RFC 3986. + """ + + def __new__( # type: ignore[no-untyped-def] + cls, + scheme: str | None = None, + auth: str | None = None, + host: str | None = None, + port: int | None = None, + path: str | None = None, + query: str | None = None, + fragment: str | None = None, + ): + if path and not path.startswith("/"): + path = "/" + path + if scheme is not None: + scheme = scheme.lower() + return super().__new__(cls, scheme, auth, host, port, path, query, fragment) + + @property + def hostname(self) -> str | None: + """For backwards-compatibility with urlparse. We're nice like that.""" + return self.host + + @property + def request_uri(self) -> str: + """Absolute path including the query string.""" + uri = self.path or "/" + + if self.query is not None: + uri += "?" + self.query + + return uri + + @property + def authority(self) -> str | None: + """ + Authority component as defined in RFC 3986 3.2. + This includes userinfo (auth), host and port. + + i.e. + userinfo@host:port + """ + userinfo = self.auth + netloc = self.netloc + if netloc is None or userinfo is None: + return netloc + else: + return f"{userinfo}@{netloc}" + + @property + def netloc(self) -> str | None: + """ + Network location including host and port. + + If you need the equivalent of urllib.parse's ``netloc``, + use the ``authority`` property instead. + """ + if self.host is None: + return None + if self.port: + return f"{self.host}:{self.port}" + return self.host + + @property + def url(self) -> str: + """ + Convert self into a url + + This function should more or less round-trip with :func:`.parse_url`. The + returned url may not be exactly the same as the url inputted to + :func:`.parse_url`, but it should be equivalent by the RFC (e.g., urls + with a blank port will have : removed). + + Example: + + .. code-block:: python + + import urllib3 + + U = urllib3.util.parse_url("https://google.com/mail/") + + print(U.url) + # "https://google.com/mail/" + + print( urllib3.util.Url("https", "username:password", + "host.com", 80, "/path", "query", "fragment" + ).url + ) + # "https://username:password@host.com:80/path?query#fragment" + """ + scheme, auth, host, port, path, query, fragment = self + url = "" + + # We use "is not None" we want things to happen with empty strings (or 0 port) + if scheme is not None: + url += scheme + "://" + if auth is not None: + url += auth + "@" + if host is not None: + url += host + if port is not None: + url += ":" + str(port) + if path is not None: + url += path + if query is not None: + url += "?" + query + if fragment is not None: + url += "#" + fragment + + return url + + def __str__(self) -> str: + return self.url + + +@typing.overload +def _encode_invalid_chars( + component: str, allowed_chars: typing.Container[str] +) -> str: # Abstract + ... + + +@typing.overload +def _encode_invalid_chars( + component: None, allowed_chars: typing.Container[str] +) -> None: # Abstract + ... + + +def _encode_invalid_chars( + component: str | None, allowed_chars: typing.Container[str] +) -> str | None: + """Percent-encodes a URI component without reapplying + onto an already percent-encoded component. + """ + if component is None: + return component + + component = to_str(component) + + # Normalize existing percent-encoded bytes. + # Try to see if the component we're encoding is already percent-encoded + # so we can skip all '%' characters but still encode all others. + component, percent_encodings = _PERCENT_RE.subn( + lambda match: match.group(0).upper(), component + ) + + uri_bytes = component.encode("utf-8", "surrogatepass") + is_percent_encoded = percent_encodings == uri_bytes.count(b"%") + encoded_component = bytearray() + + for i in range(0, len(uri_bytes)): + # Will return a single character bytestring + byte = uri_bytes[i : i + 1] + byte_ord = ord(byte) + if (is_percent_encoded and byte == b"%") or ( + byte_ord < 128 and byte.decode() in allowed_chars + ): + encoded_component += byte + continue + encoded_component.extend(b"%" + (hex(byte_ord)[2:].encode().zfill(2).upper())) + + return encoded_component.decode() + + +def _remove_path_dot_segments(path: str) -> str: + # See http://tools.ietf.org/html/rfc3986#section-5.2.4 for pseudo-code + segments = path.split("/") # Turn the path into a list of segments + output = [] # Initialize the variable to use to store output + + for segment in segments: + # '.' is the current directory, so ignore it, it is superfluous + if segment == ".": + continue + # Anything other than '..', should be appended to the output + if segment != "..": + output.append(segment) + # In this case segment == '..', if we can, we should pop the last + # element + elif output: + output.pop() + + # If the path starts with '/' and the output is empty or the first string + # is non-empty + if path.startswith("/") and (not output or output[0]): + output.insert(0, "") + + # If the path starts with '/.' or '/..' ensure we add one more empty + # string to add a trailing '/' + if path.endswith(("/.", "/..")): + output.append("") + + return "/".join(output) + + +@typing.overload +def _normalize_host(host: None, scheme: str | None) -> None: + ... + + +@typing.overload +def _normalize_host(host: str, scheme: str | None) -> str: + ... + + +def _normalize_host(host: str | None, scheme: str | None) -> str | None: + if host: + if scheme in _NORMALIZABLE_SCHEMES: + is_ipv6 = _IPV6_ADDRZ_RE.match(host) + if is_ipv6: + # IPv6 hosts of the form 'a::b%zone' are encoded in a URL as + # such per RFC 6874: 'a::b%25zone'. Unquote the ZoneID + # separator as necessary to return a valid RFC 4007 scoped IP. + match = _ZONE_ID_RE.search(host) + if match: + start, end = match.span(1) + zone_id = host[start:end] + + if zone_id.startswith("%25") and zone_id != "%25": + zone_id = zone_id[3:] + else: + zone_id = zone_id[1:] + zone_id = _encode_invalid_chars(zone_id, _UNRESERVED_CHARS) + return f"{host[:start].lower()}%{zone_id}{host[end:]}" + else: + return host.lower() + elif not _IPV4_RE.match(host): + return to_str( + b".".join([_idna_encode(label) for label in host.split(".")]), + "ascii", + ) + return host + + +def _idna_encode(name: str) -> bytes: + if not name.isascii(): + try: + import idna + except ImportError: + raise LocationParseError( + "Unable to parse URL without the 'idna' module" + ) from None + + try: + return idna.encode(name.lower(), strict=True, std3_rules=True) + except idna.IDNAError: + raise LocationParseError( + f"Name '{name}' is not a valid IDNA label" + ) from None + + return name.lower().encode("ascii") + + +def _encode_target(target: str) -> str: + """Percent-encodes a request target so that there are no invalid characters + + Pre-condition for this function is that 'target' must start with '/'. + If that is the case then _TARGET_RE will always produce a match. + """ + match = _TARGET_RE.match(target) + if not match: # Defensive: + raise LocationParseError(f"{target!r} is not a valid request URI") + + path, query = match.groups() + encoded_target = _encode_invalid_chars(path, _PATH_CHARS) + if query is not None: + query = _encode_invalid_chars(query, _QUERY_CHARS) + encoded_target += "?" + query + return encoded_target + + +def parse_url(url: str) -> Url: + """ + Given a url, return a parsed :class:`.Url` namedtuple. Best-effort is + performed to parse incomplete urls. Fields not provided will be None. + This parser is RFC 3986 and RFC 6874 compliant. + + The parser logic and helper functions are based heavily on + work done in the ``rfc3986`` module. + + :param str url: URL to parse into a :class:`.Url` namedtuple. + + Partly backwards-compatible with :mod:`urllib.parse`. + + Example: + + .. code-block:: python + + import urllib3 + + print( urllib3.util.parse_url('http://google.com/mail/')) + # Url(scheme='http', host='google.com', port=None, path='/mail/', ...) + + print( urllib3.util.parse_url('google.com:80')) + # Url(scheme=None, host='google.com', port=80, path=None, ...) + + print( urllib3.util.parse_url('/foo?bar')) + # Url(scheme=None, host=None, port=None, path='/foo', query='bar', ...) + """ + if not url: + # Empty + return Url() + + source_url = url + if not _SCHEME_RE.search(url): + url = "//" + url + + scheme: str | None + authority: str | None + auth: str | None + host: str | None + port: str | None + port_int: int | None + path: str | None + query: str | None + fragment: str | None + + try: + scheme, authority, path, query, fragment = _URI_RE.match(url).groups() # type: ignore[union-attr] + normalize_uri = scheme is None or scheme.lower() in _NORMALIZABLE_SCHEMES + + if scheme: + scheme = scheme.lower() + + if authority: + auth, _, host_port = authority.rpartition("@") + auth = auth or None + host, port = _HOST_PORT_RE.match(host_port).groups() # type: ignore[union-attr] + if auth and normalize_uri: + auth = _encode_invalid_chars(auth, _USERINFO_CHARS) + if port == "": + port = None + else: + auth, host, port = None, None, None + + if port is not None: + port_int = int(port) + if not (0 <= port_int <= 65535): + raise LocationParseError(url) + else: + port_int = None + + host = _normalize_host(host, scheme) + + if normalize_uri and path: + path = _remove_path_dot_segments(path) + path = _encode_invalid_chars(path, _PATH_CHARS) + if normalize_uri and query: + query = _encode_invalid_chars(query, _QUERY_CHARS) + if normalize_uri and fragment: + fragment = _encode_invalid_chars(fragment, _FRAGMENT_CHARS) + + except (ValueError, AttributeError) as e: + raise LocationParseError(source_url) from e + + # For the sake of backwards compatibility we put empty + # string values for path if there are any defined values + # beyond the path in the URL. + # TODO: Remove this when we break backwards compatibility. + if not path: + if query is not None or fragment is not None: + path = "" + else: + path = None + + return Url( + scheme=scheme, + auth=auth, + host=host, + port=port_int, + path=path, + query=query, + fragment=fragment, + ) diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/util.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/util.py new file mode 100644 index 0000000..35c77e4 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/util.py @@ -0,0 +1,42 @@ +from __future__ import annotations + +import typing +from types import TracebackType + + +def to_bytes( + x: str | bytes, encoding: str | None = None, errors: str | None = None +) -> bytes: + if isinstance(x, bytes): + return x + elif not isinstance(x, str): + raise TypeError(f"not expecting type {type(x).__name__}") + if encoding or errors: + return x.encode(encoding or "utf-8", errors=errors or "strict") + return x.encode() + + +def to_str( + x: str | bytes, encoding: str | None = None, errors: str | None = None +) -> str: + if isinstance(x, str): + return x + elif not isinstance(x, bytes): + raise TypeError(f"not expecting type {type(x).__name__}") + if encoding or errors: + return x.decode(encoding or "utf-8", errors=errors or "strict") + return x.decode() + + +def reraise( + tp: type[BaseException] | None, + value: BaseException, + tb: TracebackType | None = None, +) -> typing.NoReturn: + try: + if value.__traceback__ is not tb: + raise value.with_traceback(tb) + raise value + finally: + value = None # type: ignore[assignment] + tb = None diff --git a/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/wait.py b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/wait.py new file mode 100644 index 0000000..aeca0c7 --- /dev/null +++ b/examples/lambda-layers/lambda-layer1/python/lib/python3.12/site-packages/urllib3/util/wait.py @@ -0,0 +1,124 @@ +from __future__ import annotations + +import select +import socket +from functools import partial + +__all__ = ["wait_for_read", "wait_for_write"] + + +# How should we wait on sockets? +# +# There are two types of APIs you can use for waiting on sockets: the fancy +# modern stateful APIs like epoll/kqueue, and the older stateless APIs like +# select/poll. The stateful APIs are more efficient when you have a lots of +# sockets to keep track of, because you can set them up once and then use them +# lots of times. But we only ever want to wait on a single socket at a time +# and don't want to keep track of state, so the stateless APIs are actually +# more efficient. So we want to use select() or poll(). +# +# Now, how do we choose between select() and poll()? On traditional Unixes, +# select() has a strange calling convention that makes it slow, or fail +# altogether, for high-numbered file descriptors. The point of poll() is to fix +# that, so on Unixes, we prefer poll(). +# +# On Windows, there is no poll() (or at least Python doesn't provide a wrapper +# for it), but that's OK, because on Windows, select() doesn't have this +# strange calling convention; plain select() works fine. +# +# So: on Windows we use select(), and everywhere else we use poll(). We also +# fall back to select() in case poll() is somehow broken or missing. + + +def select_wait_for_socket( + sock: socket.socket, + read: bool = False, + write: bool = False, + timeout: float | None = None, +) -> bool: + if not read and not write: + raise RuntimeError("must specify at least one of read=True, write=True") + rcheck = [] + wcheck = [] + if read: + rcheck.append(sock) + if write: + wcheck.append(sock) + # When doing a non-blocking connect, most systems signal success by + # marking the socket writable. Windows, though, signals success by marked + # it as "exceptional". We paper over the difference by checking the write + # sockets for both conditions. (The stdlib selectors module does the same + # thing.) + fn = partial(select.select, rcheck, wcheck, wcheck) + rready, wready, xready = fn(timeout) + return bool(rready or wready or xready) + + +def poll_wait_for_socket( + sock: socket.socket, + read: bool = False, + write: bool = False, + timeout: float | None = None, +) -> bool: + if not read and not write: + raise RuntimeError("must specify at least one of read=True, write=True") + mask = 0 + if read: + mask |= select.POLLIN + if write: + mask |= select.POLLOUT + poll_obj = select.poll() + poll_obj.register(sock, mask) + + # For some reason, poll() takes timeout in milliseconds + def do_poll(t: float | None) -> list[tuple[int, int]]: + if t is not None: + t *= 1000 + return poll_obj.poll(t) + + return bool(do_poll(timeout)) + + +def _have_working_poll() -> bool: + # Apparently some systems have a select.poll that fails as soon as you try + # to use it, either due to strange configuration or broken monkeypatching + # from libraries like eventlet/greenlet. + try: + poll_obj = select.poll() + poll_obj.poll(0) + except (AttributeError, OSError): + return False + else: + return True + + +def wait_for_socket( + sock: socket.socket, + read: bool = False, + write: bool = False, + timeout: float | None = None, +) -> bool: + # We delay choosing which implementation to use until the first time we're + # called. We could do it at import time, but then we might make the wrong + # decision if someone goes wild with monkeypatching select.poll after + # we're imported. + global wait_for_socket + if _have_working_poll(): + wait_for_socket = poll_wait_for_socket + elif hasattr(select, "select"): + wait_for_socket = select_wait_for_socket + return wait_for_socket(sock, read, write, timeout) + + +def wait_for_read(sock: socket.socket, timeout: float | None = None) -> bool: + """Waits for reading to be available on a given socket. + Returns True if the socket is readable, or False if the timeout expired. + """ + return wait_for_socket(sock, read=True, timeout=timeout) + + +def wait_for_write(sock: socket.socket, timeout: float | None = None) -> bool: + """Waits for writing to be available on a given socket. + Returns True if the socket is readable, or False if the timeout expired. + """ + return wait_for_socket(sock, write=True, timeout=timeout) diff --git a/examples/lambda-layers/main.tf b/examples/lambda-layers/main.tf new file mode 100644 index 0000000..bcb4252 --- /dev/null +++ b/examples/lambda-layers/main.tf @@ -0,0 +1,51 @@ +resource "aws_lambda_layer_version" "libraries" { + description = "Python3 requests library" + depends_on = [data.archive_file.layer1] + filename = "lambda-layer1.zip" + layer_name = "Python3RequestsLibrary" + + compatible_runtimes = ["python3.12"] +} + +data "archive_file" "layer1" { + source_dir = "lambda-layer1" + type = "zip" + output_path = "lambda-layer1.zip" +} + +data "archive_file" "function1" { + source_file = "function.py" + type = "zip" + output_path = "function1.zip" +} + +resource "aws_lambda_function" "myFunction" { + description = "Lambda layer test" + filename = data.archive_file.function1.output_path + source_code_hash = data.archive_file.function1.output_base64sha256 + function_name = "TestFunction" + role = aws_iam_role.lambda-role1.arn + handler = "function.lambda_handler" + runtime = "python3.12" + architectures = ["arm64"] + layers = [aws_lambda_layer_version.libraries.arn] +} + +resource "aws_iam_role" "lambda-role1" { + name = "TestFunctionRole" + assume_role_policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "lambda.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) + managed_policy_arns = ["arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole"] +} \ No newline at end of file diff --git a/examples/lambda-layers/provider.tf b/examples/lambda-layers/provider.tf new file mode 100644 index 0000000..148b476 --- /dev/null +++ b/examples/lambda-layers/provider.tf @@ -0,0 +1,19 @@ +provider "aws" { + region = "ap-east-1" + default_tags { + tags = { + TerraformMode = "managed" + TerraformDir = join("/", reverse(slice(reverse(split("/", path.cwd)), 0, 2))) + } + } +} + +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.40" + } + } +} \ No newline at end of file diff --git a/examples/skel/README.md b/examples/skel/README.md new file mode 100644 index 0000000..2127c47 --- /dev/null +++ b/examples/skel/README.md @@ -0,0 +1,9 @@ +# Every module should be documented + +## Description + +## Input variables + +## Output variables + +## Example \ No newline at end of file diff --git a/examples/skel/main.tf b/examples/skel/main.tf new file mode 100644 index 0000000..16f7e2e --- /dev/null +++ b/examples/skel/main.tf @@ -0,0 +1 @@ +# main.tf \ No newline at end of file diff --git a/examples/skel/provider.tf b/examples/skel/provider.tf new file mode 100644 index 0000000..96b64fc --- /dev/null +++ b/examples/skel/provider.tf @@ -0,0 +1,27 @@ +provider "aws" { + region = var.aws-region + default_tags { + tags = { + Environment = var.environment + Project = var.project + Application = var.application + TerraformMode = "managed" + TerraformDir = "${reverse(split("/", path.cwd))[1]}/${reverse(split("/", path.cwd))[0]}" + } + } +} + + +terraform { + required_version = ">= 1.3" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} + +output "last-updated" { + value = timestamp() +} diff --git a/examples/skel/terraform.tfvars b/examples/skel/terraform.tfvars new file mode 100644 index 0000000..ab01a90 --- /dev/null +++ b/examples/skel/terraform.tfvars @@ -0,0 +1,5 @@ +aws-region = "ap-east-1" +customer-name = "CX" +environment = "prod" +project = "SupportTools" +application = "Undefined" diff --git a/examples/skel/variables.tf b/examples/skel/variables.tf new file mode 100644 index 0000000..9233cee --- /dev/null +++ b/examples/skel/variables.tf @@ -0,0 +1,5 @@ +variable "aws-region" {} +variable "customer-name" {} +variable "environment" {} +variable "project" {} +variable "application" {} diff --git a/headdesk-aws/all-layers/ec2.tf b/headdesk-aws/all-layers/ec2.tf new file mode 100644 index 0000000..00ae741 --- /dev/null +++ b/headdesk-aws/all-layers/ec2.tf @@ -0,0 +1,52 @@ +resource "aws_key_pair" "xpk-kp1" { + public_key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGiM5WTFNTa31Cm5CmOcw493T9vQ3GxeHP1AjfcomhHK kn@ism" + tags = local.default-tags +} + +module "headdesk-ec2" { + source = "../../modules/compute/ec2" + + additional_tags = {} + # Rocky9 ARM + ami-id = "ami-0f516dde04bd55b1a" + asso-eip = true + # setting to false requires replacement during terraform apply + asso-public-ip = true + default-tags = local.default-tags + ebs-encrypted = true + instance-name = "${local.resource-prefix}-mailwww" + instance-type = "t4g.small" + key-name = aws_key_pair.xpk-kp1.key_name + root-volume-size = 30 + security-groups = module.headdesk-sg.sg-ids + subnet-id = module.vpc-subnet.public-subnet-ids[1] +} + +module "headdesk-sg" { + source = "../../modules/compute/security-groups" + + security-groups = [ + { + name = "WebAccess" + description = "Public web access" + rules = [ + [1, "tcp", "0.0.0.0/0", "80", "80", "ingress", "web"], + [2, "tcp", "0.0.0.0/0", "443", "443", "ingress", "web"], + [3, "tcp", "0.0.0.0/0", "25", "25", "ingress", "mail"], + [4, "tcp", "0.0.0.0/0", "587", "587", "ingress", "mail"], + [5, "tcp", "0.0.0.0/0", "11993", "11993", "ingress", "mail"], + [6, "-1", "0.0.0.0/0", "0", "0", "egress", "Allow outbound traffic"], + [7, "tcp", "0.0.0.0/0", "2201", "2201", "ingress", "ssh"] + ] + }, + { + name = "MgmtAccess" + description = "Allow management access" + rules = [ + [1, "tcp", "223.18.148.85/32", "22", "22", "ingress", "xpk"] + ] + } + ] + tags = local.default-tags + vpc-id = module.vpc-subnet.vpc_id +} \ No newline at end of file diff --git a/headdesk-aws/all-layers/main.tf b/headdesk-aws/all-layers/main.tf new file mode 100644 index 0000000..9e631d9 --- /dev/null +++ b/headdesk-aws/all-layers/main.tf @@ -0,0 +1,21 @@ +module "vpc-subnet" { + source = "../../modules/networking/vpc_subnets" + + application = var.application + aws-region = var.aws-region + customer-name = var.customer-name + default-tags = local.default-tags + environment = var.environment + project = var.project + vpc-cidr = "172.28.0.0/16" + vpcflowlog-cwl-loggroup-key-arn = "" + enable-flow-log = false + number-of-private-subnets-per-az = 0 + number-of-public-subnets-per-az = 1 + create-nat-gateway = false +} + +module delete-default-vpcs { + source = "../../modules/networking/delete-default-vpcs" + +} \ No newline at end of file diff --git a/headdesk-aws/all-layers/provider.tf b/headdesk-aws/all-layers/provider.tf new file mode 100644 index 0000000..6b15561 --- /dev/null +++ b/headdesk-aws/all-layers/provider.tf @@ -0,0 +1,13 @@ +provider "aws" { + region = var.aws-region +} + +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = "~> 4.33.0" + } + } +} diff --git a/headdesk-aws/all-layers/security.tf b/headdesk-aws/all-layers/security.tf new file mode 100644 index 0000000..9f15393 --- /dev/null +++ b/headdesk-aws/all-layers/security.tf @@ -0,0 +1,3 @@ +module other-security-defaults { + source = "../../modules/security_identity_compliance/other-default-settings" +} diff --git a/headdesk-aws/all-layers/terraform.tfvars b/headdesk-aws/all-layers/terraform.tfvars new file mode 100644 index 0000000..018bda1 --- /dev/null +++ b/headdesk-aws/all-layers/terraform.tfvars @@ -0,0 +1,5 @@ +aws-region = "ap-east-1" +customer-name = "xpk" +environment = "prod" +project = "headdesk" +application = "mail+web" \ No newline at end of file diff --git a/headdesk-aws/all-layers/variables.tf b/headdesk-aws/all-layers/variables.tf new file mode 100644 index 0000000..3b297a1 --- /dev/null +++ b/headdesk-aws/all-layers/variables.tf @@ -0,0 +1,19 @@ +variable "aws-region" {} +variable "customer-name" {} +variable "environment" {} +variable "project" {} +variable "application" {} + +locals { + default-tags = { + ServiceProvider = "Headdesk" + Environment = var.environment + Project = var.project + Application = var.application + TerraformMode = "managed" + TerraformDir = trimprefix(path.cwd, "/my/work/xpk-git/") + BuildDate = formatdate("YYYYMMDD", timestamp()) + } + resource-prefix = "${var.environment}-${substr(var.aws-region,0,2)}-${var.customer-name}-${var.project}" +} + diff --git a/layers/networking/base-network-experimental/.terraform.lock.hcl b/layers/networking/base-network-experimental/.terraform.lock.hcl new file mode 100644 index 0000000..af3db26 --- /dev/null +++ b/layers/networking/base-network-experimental/.terraform.lock.hcl @@ -0,0 +1,36 @@ +# This file is maintained automatically by "terraform init". +# Manual edits may be lost in future updates. + +provider "registry.terraform.io/hashicorp/aws" { + version = "3.26.0" + hashes = [ + "h1:0i78FItlPeiomd+4ThZrtm56P5K33k7/6dnEe4ZePI0=", + "zh:26043eed36d070ca032cf04bc980c654a25821a8abc0c85e1e570e3935bbfcbb", + "zh:2fe68f3f78d23830a04d7fac3eda550eef1f627dfc130486f70a65dc5c254300", + "zh:3d66484c608c64678e639db25d63872783ce60363a1246e30317f21c9c23b84b", + "zh:46ffd755cfd4cf94fe66342797b5afdcef010a24e126c67fee141b357d393535", + "zh:5e96f24357e945c9067cf5e032ad1d003609629c956c2f9f642fefe714e74587", + "zh:60c27aca36bb63bf3e865c2193be80ca83b376581d00f9c220af4b013e163c4d", + "zh:896f0f22d19d41e71b22f9240b261714c3915b165ddefeb771e7734d69dc47ea", + "zh:90de9966cb2fd3e2f326df291595e55d2dd2d90e7d6dd085c2c8691dce82bdb4", + "zh:ad05a91a88ceb1d6de5a568f7cc0b0e5bc0a79f3da70bc28c1e7f3750e362d58", + "zh:e8c63f59c6465329e1f3357498face3dd7ef10a033df3c366a33aa9e94b46c01", + ] +} + +provider "registry.terraform.io/hashicorp/null" { + version = "3.0.0" + hashes = [ + "h1:ysHGBhBNkIiJLEpthB/IVCLpA1Qoncp3KbCTFGFZTO0=", + "zh:05fb7eab469324c97e9b73a61d2ece6f91de4e9b493e573bfeda0f2077bc3a4c", + "zh:1688aa91885a395c4ae67636d411475d0b831e422e005dcf02eedacaafac3bb4", + "zh:24a0b1292e3a474f57c483a7a4512d797e041bc9c2fbaac42fe12e86a7fb5a3c", + "zh:2fc951bd0d1b9b23427acc93be09b6909d72871e464088171da60fbee4fdde03", + "zh:6db825759425599a326385a68acc6be2d9ba0d7d6ef587191d0cdc6daef9ac63", + "zh:85985763d02618993c32c294072cc6ec51f1692b803cb506fcfedca9d40eaec9", + "zh:a53186599c57058be1509f904da512342cfdc5d808efdaf02dec15f0f3cb039a", + "zh:c2e07b49b6efa676bdc7b00c06333ea1792a983a5720f9e2233db27323d2707c", + "zh:cdc8fe1096103cf5374751e2e8408ec4abd2eb67d5a1c5151fe2c7ecfd525bef", + "zh:dbdef21df0c012b0d08776f3d4f34eb0f2f229adfde07ff252a119e52c0f65b7", + ] +} diff --git a/layers/networking/base-network-experimental/main.tf b/layers/networking/base-network-experimental/main.tf new file mode 100644 index 0000000..7f2a968 --- /dev/null +++ b/layers/networking/base-network-experimental/main.tf @@ -0,0 +1,21 @@ +data aws_availability_zones available-az { + state = "available" +} + +module "subnet_addrs" { + source = "hashicorp/subnets/cidr" + + base_cidr_block = "10.0.0.0/16" + + networks = [ + for az in data.aws_availability_zones.available-az.names : + { + name = az + new_bits = 8 + } + ] +} + +output module-output { + value = values(module.subnet_addrs.network_cidr_blocks) +} \ No newline at end of file diff --git a/layers/networking/base-network/.terraform.lock.hcl b/layers/networking/base-network/.terraform.lock.hcl new file mode 100644 index 0000000..a1bd719 --- /dev/null +++ b/layers/networking/base-network/.terraform.lock.hcl @@ -0,0 +1,37 @@ +# This file is maintained automatically by "terraform init". +# Manual edits may be lost in future updates. + +provider "registry.terraform.io/hashicorp/aws" { + version = "3.25.0" + constraints = ">= 3.25.0" + hashes = [ + "h1:9bXU5cFO/2DX8z5whaGMA7wcCalKQJZrBm89AuePuEM=", + "zh:2d3c65461bc63ec39bce7b5afdbed9a3b4dd5c2c8ee94616ad1866e24cf9b8f0", + "zh:2fb2ea6ccac30b909b603e183433737a30c58ec1f9a6a8b5565f0f051490c07a", + "zh:31a5f192c8cf29fb677cd639824f9a685578a2564c6b790517db33ea56229045", + "zh:437a12cf9a4d7bc92c9bf14ee7e224d5d3545cbd2154ba113ae82c4bb68edc27", + "zh:4bbdc3155a5dea90b2d50adfa460b0759c4dd959efaf7f66b2a0385a53b469b2", + "zh:63a8cd523ba31358692a34a06e111d88769576ac6d0e5adad8e0b4ae0a2d8882", + "zh:c4301ce86e8cb2c464949bb99e729ffe7b0c55eaf34b82ba526bb5039bca36f3", + "zh:c97b84861c6c550b8d2feb12d089660fffbf51dc7d660dcc9d54d4a7b3c2c882", + "zh:d6a103570e2d5c387b068fac4b88654dfa21d44ca1bdfa4bc8ab94c88effd71a", + "zh:f08cf2faf960a8ca374ac860f37c31c88ed2bab460116ac74678e0591babaac5", + ] +} + +provider "registry.terraform.io/hashicorp/null" { + version = "3.0.0" + hashes = [ + "h1:ysHGBhBNkIiJLEpthB/IVCLpA1Qoncp3KbCTFGFZTO0=", + "zh:05fb7eab469324c97e9b73a61d2ece6f91de4e9b493e573bfeda0f2077bc3a4c", + "zh:1688aa91885a395c4ae67636d411475d0b831e422e005dcf02eedacaafac3bb4", + "zh:24a0b1292e3a474f57c483a7a4512d797e041bc9c2fbaac42fe12e86a7fb5a3c", + "zh:2fc951bd0d1b9b23427acc93be09b6909d72871e464088171da60fbee4fdde03", + "zh:6db825759425599a326385a68acc6be2d9ba0d7d6ef587191d0cdc6daef9ac63", + "zh:85985763d02618993c32c294072cc6ec51f1692b803cb506fcfedca9d40eaec9", + "zh:a53186599c57058be1509f904da512342cfdc5d808efdaf02dec15f0f3cb039a", + "zh:c2e07b49b6efa676bdc7b00c06333ea1792a983a5720f9e2233db27323d2707c", + "zh:cdc8fe1096103cf5374751e2e8408ec4abd2eb67d5a1c5151fe2c7ecfd525bef", + "zh:dbdef21df0c012b0d08776f3d4f34eb0f2f229adfde07ff252a119e52c0f65b7", + ] +} diff --git a/layers/networking/base-network/main.tf b/layers/networking/base-network/main.tf new file mode 100644 index 0000000..88174ea --- /dev/null +++ b/layers/networking/base-network/main.tf @@ -0,0 +1,17 @@ +data aws_caller_identity this {} + +module networking-vpc-subnets { + source = "../../../modules/networking/vpc_subnets" + application = var.application + environment = var.environment + customer-name = var.customer-name + project = var.project + default-tags = local.default-tags + number-of-private-subnets-per-az = 2 + number-of-public-subnets-per-az = 1 + create-nat-gateway = true + vpc-cidr = "10.2.0.0/16" + aws-region-short = "apne1" + aws-region = var.aws-region + vpcflowlog-cwl-loggroup-key-arn = "arn:aws:kms:${var.aws-region}:${data.aws_caller_identity.this.account_id}:alias/${local.resource-prefix}-kmskey-default" +} \ No newline at end of file diff --git a/layers/networking/base-network/outputs.tf b/layers/networking/base-network/outputs.tf new file mode 100644 index 0000000..b2d1176 --- /dev/null +++ b/layers/networking/base-network/outputs.tf @@ -0,0 +1,11 @@ +output vpc_id { + value = module.networking-vpc-subnets.vpc_id +} + +output public_subnets { + value = module.networking-vpc-subnets.public_subnets +} + +output private_subnets { + value = module.networking-vpc-subnets.private_subnets +} \ No newline at end of file diff --git a/layers/networking/base-network/provider.tf b/layers/networking/base-network/provider.tf new file mode 100644 index 0000000..4e906ad --- /dev/null +++ b/layers/networking/base-network/provider.tf @@ -0,0 +1,13 @@ +provider "aws" { + region = var.aws-region +} + +terraform { + required_version = ">= 0.14" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 3.25" + } + } +} \ No newline at end of file diff --git a/layers/networking/base-network/terraform.tfvars b/layers/networking/base-network/terraform.tfvars new file mode 100644 index 0000000..9f12b0d --- /dev/null +++ b/layers/networking/base-network/terraform.tfvars @@ -0,0 +1,6 @@ +aws-region = "ap-northeast-1" +aws-region-short = "apne1" +customer-name = "racken" +environment = "lab" +project = "cleanslate" +application = "infra" \ No newline at end of file diff --git a/layers/networking/base-network/variables.tf b/layers/networking/base-network/variables.tf new file mode 100644 index 0000000..b705e28 --- /dev/null +++ b/layers/networking/base-network/variables.tf @@ -0,0 +1,22 @@ +variable "aws-region" {} +variable "aws-region-short" {} +variable "customer-name" {} +variable "environment" {} +variable "project" {} +variable "application" {} + +locals { + default-tags = { + ServiceProvider = "RackspaceTechnology" + Environment = var.environment + Project = var.project + Application = var.application + TerraformMode = "managed" + TerraformDir = trimprefix(path.cwd, "/my/work/xpk-git/") + CreatedBy = data.aws_caller_identity.this.arn + BuildDate = formatdate("YYYYMMDD", timestamp()) + } + ct-bucket-name = "${var.environment}-${var.aws-region-short}-${var.customer-name}-${var.project}-ctbucket-${data.aws_caller_identity.this.account_id}" + resource-prefix = "${var.environment}-${var.aws-region-short}-${var.customer-name}-${var.project}" +} + diff --git a/modules/ApplicationIntegration/apigw-lambda/README.md b/modules/ApplicationIntegration/apigw-lambda/README.md new file mode 100644 index 0000000..5927476 --- /dev/null +++ b/modules/ApplicationIntegration/apigw-lambda/README.md @@ -0,0 +1,77 @@ + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | +| random | n/a | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_api_gateway_deployment.apigw-deployment](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_deployment) | resource | +| [aws_api_gateway_integration.api-integration](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_integration) | resource | +| [aws_api_gateway_integration_response.integration-response](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_integration_response) | resource | +| [aws_api_gateway_method.api-method](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_method) | resource | +| [aws_api_gateway_method_response.response_200](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_method_response) | resource | +| [aws_api_gateway_method_settings.apigw-method-settings](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_method_settings) | resource | +| [aws_api_gateway_resource.api-res](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_resource) | resource | +| [aws_api_gateway_rest_api.api](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_rest_api) | resource | +| [aws_api_gateway_rest_api_policy.api-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_rest_api_policy) | resource | +| [aws_api_gateway_stage.apigw-stage](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_stage) | resource | +| [aws_api_gateway_vpc_link.api-vpc-link](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/api_gateway_vpc_link) | resource | +| [aws_cloudwatch_log_group.lambda-logs](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_log_group) | resource | +| [aws_cloudwatch_log_group.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_log_group) | resource | +| [aws_iam_role.lambda-exec-role](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_iam_role_policy.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy) | resource | +| [aws_lambda_function.function](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function) | resource | +| [aws_lambda_permission.allow_api_gateway](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission) | resource | +| [aws_vpc_endpoint.apigw-vpcep](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc_endpoint) | resource | +| [random_id.this](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/id) | resource | +| [aws_caller_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | +| [aws_iam_policy_document.api-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_policy_document) | data source | +| [aws_region.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/region) | data source | +| [aws_vpc.vpc](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/vpc) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| apigw-security-group-id | Security group id of apigateway | `string` | n/a | yes | +| apigw-subnet-ids | Subnet IDs of apigateway | `list(string)` | n/a | yes | +| apigw-type | Type of apigateway: private or regional | `string` | n/a | yes | +| apigw-vpc-id | VPC id of apigateway | `string` | n/a | yes | +| apigw-vpc-link-target-arns | Target arns for apigateway VPC link | `list(string)` | `[]` | no | +| cloudwatchlog-retention | Cloudwatch log group retention days | `number` | `14` | no | +| create-vpc-link | Set true to create vpc link for outbound access to specific targets | `bool` | n/a | yes | +| cwl-cmk-key-id | CMK arn for cloudwatch logs encryption | `string` | `null` | no | +| description | Description of apigateway | `string` | n/a | yes | +| lambda-archive-file | Path to lambda zip archive | `string` | n/a | yes | +| lambda-main-function-name | Main python file without the .py extension | `string` | n/a | yes | +| lambda-runtime-version | Lambda runtime version | `string` | `"python3.12"` | no | +| name | Name of apigateway | `string` | n/a | yes | +| resources | Apigateway resources (path\_part) |
map(object({
method = string
authorization = string
integration_type = string
content_handling = string
}))
| n/a | yes | +| stages | apigateway stages |
map(object({
description = string
variables = map(string)
}))
| n/a | yes | + +## Outputs + +| Name | Description | +|------|-------------| +| apigw-id | n/a | +| apigw-vpc-endpoints | n/a | + +--- +## Authorship +This module was developed by UPDATE_THIS. \ No newline at end of file diff --git a/modules/ApplicationIntegration/apigw-lambda/examples/main.tf b/modules/ApplicationIntegration/apigw-lambda/examples/main.tf new file mode 100644 index 0000000..bda12ea --- /dev/null +++ b/modules/ApplicationIntegration/apigw-lambda/examples/main.tf @@ -0,0 +1,111 @@ +module "apigw" { + source = "../../modules/ApplicationIntegration/apigw-lambda" + + apigw-type = "regional" + apigw-security-group-id = "sg-04ec154cb0f516e76" + apigw-subnet-ids = ["subnet-0d1e0e378cbcd7295", "subnet-0d86aa4c05033dea8"] + apigw-vpc-id = "vpc-01a10b033169f89a8" + create-vpc-link = false + description = "test apigw-lambda module" + lambda-archive-file = "${path.module}/lambda_function.zip" + name = "ken2026-test" + lambda-main-function-name = "main" + cwl-cmk-key-id = aws_kms_key.cwl-key.arn + resources = { + "foo" : { + "method" : "POST", + "authorization" : "NONE", + "integration-type" : "AWS" + "content-handling" : "CONVERT_TO_TEXT" + } + "bar" : { + "method" : "POST", + "authorization" : "NONE", + "integration-type" : "AWS", + "content-handling" : "CONVERT_TO_TEXT" + } + } + stages = { + "dev" : { + "description" : "Dev stage" + "variables" : { + "var1" : "foo" + } + } + "prd" : { + "description" : "Prd stage" + "variables" : { + "var1" : "bar" + } + } + } +} + +data "archive_file" "lambda" { + source_dir = "function" + output_path = "lambda_function.zip" + type = "zip" +} + +resource "aws_kms_key" "cwl-key" { + enable_key_rotation = true + deletion_window_in_days = 7 + policy = jsonencode( + { + "Version" : "2012-10-17", + "Id" : "key-default-1", + "Statement" : [ + { + "Sid" : "Enable IAM User Permissions", + "Effect" : "Allow", + "Principal" : { + "AWS" : "arn:aws:iam::040216112220:root" + }, + "Action" : "kms:*", + "Resource" : "*" + }, + { + "Sid" : "Allow cloudwatch log service", + "Effect" : "Allow", + "Principal" : { + "Service" : [ + "logs.ap-east-1.amazonaws.com", + "apigateway.ap-east-1.amazonaws.com" + ] + }, + "Action" : "kms:*", + "Resource" : "*" + } + ] + } + ) +} + + +# apigateway account settings, needed for first apigateway deployment only +resource "aws_api_gateway_account" "settings" { + cloudwatch_role_arn = aws_iam_role.apigw-logging-role.arn +} + +resource "aws_iam_role" "apigw-logging-role" { + name = "ApiGatewayLoggingRole" + assume_role_policy = data.aws_iam_policy_document.apigw-logging-role.json +} + +data "aws_iam_policy_document" "apigw-logging-role" { + statement { + effect = "Allow" + + principals { + type = "Service" + identifiers = ["apigateway.amazonaws.com"] + } + + actions = ["sts:AssumeRole"] + } +} + +resource "aws_iam_role_policy_attachment" "apigw-cloudwatch" { + policy_arn = "arn:aws:iam::aws:policy/service-role/AmazonAPIGatewayPushToCloudWatchLogs" + role = aws_iam_role.apigw-logging-role.id +} \ No newline at end of file diff --git a/modules/ApplicationIntegration/apigw-lambda/main.tf b/modules/ApplicationIntegration/apigw-lambda/main.tf new file mode 100644 index 0000000..8ed91e3 --- /dev/null +++ b/modules/ApplicationIntegration/apigw-lambda/main.tf @@ -0,0 +1,256 @@ +resource "aws_api_gateway_rest_api" "api" { + name = var.name + description = var.description + + dynamic "endpoint_configuration" { + for_each = [1] + content { + types = var.apigw-type == "private" ? ["PRIVATE"] : ["REGIONAL"] + vpc_endpoint_ids = var.apigw-type == "private" ? [aws_vpc_endpoint.apigw-vpcep[0].id] : null + } + } +} + +# private endpoint for inbound access +# to connect to the private api gateway, provide the header x-apigw-api-id +# curl -IX GET -H 'x-apigw-api-id:' https:/// +data "aws_region" "current" {} + +resource "aws_vpc_endpoint" "apigw-vpcep" { + count = var.apigw-type == "private" ? 1 : 0 + private_dns_enabled = false + security_group_ids = [var.apigw-security-group-id] + service_name = "com.amazonaws.${data.aws_region.current.name}.execute-api" + subnet_ids = var.apigw-subnet-ids + vpc_endpoint_type = "Interface" + vpc_id = var.apigw-vpc-id +} + +# vpc link for outbound access +resource "aws_api_gateway_vpc_link" "api-vpc-link" { + count = var.create-vpc-link ? 1 : 0 + name = "${var.name}-vpclink" + description = "VPC link for apigateway ${var.name}" + target_arns = var.apigw-vpc-link-target-arns +} + +# Apigw resources, integration, method, responses +resource "aws_api_gateway_resource" "api-res" { + depends_on = [aws_api_gateway_rest_api_policy.api-policy] + for_each = var.resources + path_part = each.key + parent_id = aws_api_gateway_rest_api.api.root_resource_id + rest_api_id = aws_api_gateway_rest_api.api.id +} + +resource "aws_api_gateway_method" "api-method" { + depends_on = [aws_api_gateway_resource.api-res] + for_each = var.resources + rest_api_id = aws_api_gateway_rest_api.api.id + resource_id = aws_api_gateway_resource.api-res[each.key].id + http_method = each.value["method"] + authorization = each.value["authorization"] +} + +# non-proxy integration +resource "aws_api_gateway_integration" "api-integration" { + depends_on = [aws_api_gateway_method.api-method] + for_each = var.resources + rest_api_id = aws_api_gateway_rest_api.api.id + resource_id = aws_api_gateway_resource.api-res[each.key].id + http_method = aws_api_gateway_method.api-method[each.key].http_method + integration_http_method = each.value["method"] + type = each.value["integration-type"] + content_handling = each.value["content-handling"] + uri = aws_lambda_function.function.invoke_arn +} + +resource "aws_api_gateway_method_response" "response_200" { + depends_on = [aws_api_gateway_method.api-method] + for_each = var.resources + rest_api_id = aws_api_gateway_rest_api.api.id + resource_id = aws_api_gateway_resource.api-res[each.key].id + http_method = aws_api_gateway_method.api-method[each.key].http_method + status_code = "200" +} + +resource "aws_api_gateway_integration_response" "integration-response" { + depends_on = [aws_api_gateway_integration.api-integration] + for_each = var.resources + rest_api_id = aws_api_gateway_rest_api.api.id + resource_id = aws_api_gateway_resource.api-res[each.key].id + http_method = aws_api_gateway_method.api-method[each.key].http_method + status_code = aws_api_gateway_method_response.response_200[each.key].status_code +} + +# apigw deployment and stage +resource "aws_api_gateway_deployment" "apigw-deployment" { + depends_on = [aws_api_gateway_integration.api-integration] + rest_api_id = aws_api_gateway_rest_api.api.id + + triggers = { + redeployment = sha1(jsonencode(aws_api_gateway_rest_api.api.body)) + } + + lifecycle { + create_before_destroy = true + } +} + +resource "aws_api_gateway_stage" "apigw-stage" { + for_each = var.stages + depends_on = [aws_api_gateway_rest_api_policy.api-policy, aws_cloudwatch_log_group.this] + deployment_id = aws_api_gateway_deployment.apigw-deployment.id + rest_api_id = aws_api_gateway_rest_api.api.id + stage_name = each.key + description = each.value["description"] + variables = each.value["variables"] + + access_log_settings { + destination_arn = aws_cloudwatch_log_group.this[each.key].arn + # https://docs.aws.amazon.com/apigateway/latest/developerguide/set-up-logging.html + format = jsonencode({ + "requestId" : "$context.requestId", + "extendedRequestId" : "$context.extendedRequestId", + "ip" : "$context.identity.sourceIp", + "caller" : "$context.identity.caller", + "user" : "$context.identity.user", + "requestTime" : "$context.requestTime", + "httpMethod" : "$context.httpMethod", + "resourcePath" : "$context.resourcePath", + "status" : "$context.status", + "protocol" : "$context.protocol", + "responseLength" : "$context.responseLength" + } + ) + } +} + +resource "aws_api_gateway_method_settings" "apigw-method-settings" { + depends_on = [aws_api_gateway_rest_api_policy.api-policy] + for_each = aws_api_gateway_stage.apigw-stage + rest_api_id = aws_api_gateway_rest_api.api.id + stage_name = each.value.stage_name + method_path = "*/*" + + settings { + metrics_enabled = true + logging_level = "INFO" + } +} + +# Cloudwatch log group path: API-Gateway-Execution-Logs_{rest-api-id}/{stage_name} +resource "aws_cloudwatch_log_group" "this" { + for_each = var.stages + name = "API-Gateway-Execution-Logs_${aws_api_gateway_rest_api.api.id}/${each.key}" + retention_in_days = var.cloudwatchlog-retention + kms_key_id = var.cwl-cmk-key-id +} + +# lambda function +resource "aws_cloudwatch_log_group" "lambda-logs" { + name = "/aws/lambda/${var.name}-lambda-function" + retention_in_days = var.cloudwatchlog-retention + kms_key_id = var.cwl-cmk-key-id +} + +resource "aws_lambda_function" "function" { + filename = var.lambda-archive-file + function_name = "${var.name}-lambda-function" + handler = "main.lambda_handler" + role = aws_iam_role.lambda-exec-role.arn + runtime = var.lambda-runtime-version + # source_code_hash = local.source_code_hash +} + +resource "aws_lambda_permission" "allow_api_gateway" { + action = "lambda:InvokeFunction" + function_name = aws_lambda_function.function.function_name + principal = "apigateway.amazonaws.com" +} + +# Lambda execution role +data "aws_caller_identity" "this" {} + +resource "random_id" "this" { + byte_length = 4 +} + +resource "aws_iam_role" "lambda-exec-role" { + name = "lambda-apigw-${var.name}-${random_id.this.dec}" + + assume_role_policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "lambda.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) +} + +resource "aws_iam_role_policy" "this" { + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Sid" : "AllowCreationOfCloudwatchLogGroup", + "Effect" : "Allow", + "Action" : "logs:CreateLogGroup", + "Resource" : "arn:aws:logs:ap-east-1:${data.aws_caller_identity.this.account_id}:*" + }, + { + "Sid" : "AllowWritingToCloudwatchLogGroup", + "Effect" : "Allow", + "Action" : [ + "logs:CreateLogStream", + "logs:PutLogEvents" + ], + "Resource" : [ + "arn:aws:logs:ap-east-1:${data.aws_caller_identity.this.account_id}:log-group:/aws/lambda/*" + ] + } + ] + } + ) + role = aws_iam_role.lambda-exec-role.id + name = "LambdaExecutionPolicy" +} + +# apigateway policy +data "aws_iam_policy_document" "api-policy" { + statement { + effect = "Allow" + + principals { + type = "AWS" + identifiers = ["*"] + } + + actions = ["execute-api:Invoke"] + resources = [aws_api_gateway_rest_api.api.execution_arn] + + condition { + test = "IpAddress" + variable = "aws:SourceIp" + values = [data.aws_vpc.vpc.cidr_block] + } + } +} + +data "aws_vpc" "vpc" { + id = var.apigw-vpc-id +} +resource "aws_api_gateway_rest_api_policy" "api-policy" { + rest_api_id = aws_api_gateway_rest_api.api.id + policy = data.aws_iam_policy_document.api-policy.json +} + + diff --git a/modules/ApplicationIntegration/apigw-lambda/outputs.tf b/modules/ApplicationIntegration/apigw-lambda/outputs.tf new file mode 100644 index 0000000..867502a --- /dev/null +++ b/modules/ApplicationIntegration/apigw-lambda/outputs.tf @@ -0,0 +1,7 @@ +output "apigw-id" { + value = aws_api_gateway_rest_api.api.id +} + +output "apigw-vpc-endpoints" { + value = try(aws_vpc_endpoint.apigw-vpcep.*.dns_entry[0].*.dns_name, null) +} \ No newline at end of file diff --git a/modules/ApplicationIntegration/apigw-lambda/variables.tf b/modules/ApplicationIntegration/apigw-lambda/variables.tf new file mode 100644 index 0000000..ae5558c --- /dev/null +++ b/modules/ApplicationIntegration/apigw-lambda/variables.tf @@ -0,0 +1,90 @@ +variable "name" { + type = string + description = "Name of apigateway" +} + +variable "description" { + type = string + description = "Description of apigateway" +} + +variable "apigw-type" { + type = string + description = "Type of apigateway: private or regional" + validation { + condition = can(regex("^(private|regional)$", var.apigw-type)) + error_message = "Invalid apigw type, only allowed types are: 'private', 'regional'" + } +} + +variable "resources" { + type = map(object({ + method = string + authorization = string + integration_type = string + content_handling = string + })) + description = "Apigateway resources (path_part)" +} + +variable "stages" { + type = map(object({ + description = string + variables = map(string) + })) + description = "apigateway stages" +} + +variable "lambda-archive-file" { + type = string + description = "Path to lambda zip archive" +} + +variable "lambda-runtime-version" { + type = string + description = "Lambda runtime version" + default = "python3.12" +} + +variable "lambda-main-function-name" { + type = string + description = "Main python file without the .py extension" +} + +variable "apigw-vpc-id" { + type = string + description = "VPC id of apigateway" +} + +variable "apigw-subnet-ids" { + type = list(string) + description = "Subnet IDs of apigateway" +} + +variable "apigw-security-group-id" { + type = string + description = "Security group id of apigateway" +} + +variable "create-vpc-link" { + type = bool + description = "Set true to create vpc link for outbound access to specific targets" +} + +variable "apigw-vpc-link-target-arns" { + type = list(string) + description = "Target arns for apigateway VPC link" + default = [] +} + +variable "cloudwatchlog-retention" { + type = number + description = "Cloudwatch log group retention days" + default = 14 +} + +variable "cwl-cmk-key-id" { + type = string + description = "CMK arn for cloudwatch logs encryption" + default = null +} \ No newline at end of file diff --git a/modules/ApplicationIntegration/apigw-lambda/versions.tf b/modules/ApplicationIntegration/apigw-lambda/versions.tf new file mode 100644 index 0000000..ceb041e --- /dev/null +++ b/modules/ApplicationIntegration/apigw-lambda/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} \ No newline at end of file diff --git a/modules/ApplicationIntegration/terraform-aws-apigateway-v2 b/modules/ApplicationIntegration/terraform-aws-apigateway-v2 new file mode 160000 index 0000000..801edb6 --- /dev/null +++ b/modules/ApplicationIntegration/terraform-aws-apigateway-v2 @@ -0,0 +1 @@ +Subproject commit 801edb68278c09cccf9bf34f121e2e0a32d4e1fe diff --git a/modules/FrontendWebMobile/Ses/README.md b/modules/FrontendWebMobile/Ses/README.md new file mode 100644 index 0000000..0254694 --- /dev/null +++ b/modules/FrontendWebMobile/Ses/README.md @@ -0,0 +1,42 @@ + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_sesv2_configuration_set.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sesv2_configuration_set) | resource | +| [aws_sesv2_email_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sesv2_email_identity) | resource | +| [aws_sesv2_email_identity_policy.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sesv2_email_identity_policy) | resource | +| [aws_caller_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | +| [aws_iam_policy_document.ses-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_policy_document) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| emails | Email addresses to be added to SES | `list(string)` | n/a | yes | +| reputation\_metrics\_enabled | Enable reputation metrics | `bool` | `true` | no | + +## Outputs + +No outputs. + +--- +## Authorship +This module was developed by UPDATE_THIS. \ No newline at end of file diff --git a/modules/FrontendWebMobile/Ses/main.tf b/modules/FrontendWebMobile/Ses/main.tf new file mode 100644 index 0000000..6eb4294 --- /dev/null +++ b/modules/FrontendWebMobile/Ses/main.tf @@ -0,0 +1,63 @@ +data "aws_caller_identity" "this" {} +data "aws_region" "this" {} + +resource "aws_sesv2_email_identity" "this" { + for_each = toset(var.emails) + email_identity = each.value + configuration_set_name = aws_sesv2_configuration_set.this.configuration_set_name +} + +resource "aws_sesv2_configuration_set" "this" { + configuration_set_name = "default-sesv2-configuration-set" + + delivery_options { + tls_policy = var.require_tls ? "REQUIRE" : "OPTIONAL" + } + + reputation_options { + reputation_metrics_enabled = var.reputation_metrics_enabled + } + + sending_options { + sending_enabled = true + } +} + +# The exact same policy can be created successfully on console! +#resource "aws_sesv2_email_identity_policy" "this" { +# for_each = aws_sesv2_email_identity.this +# email_identity = each.value.arn +# policy_name = "default-policy" +# # policy = data.aws_iam_policy_document.ses-policy[each.key].json +# policy = jsonencode({ +# "Version" : "2012-10-17", +# "Statement" : [ +# { +# "Sid" : "default", +# "Effect" : "Allow", +# "Principal" : { +# "AWS" : "arn:aws:iam::${data.aws_caller_identity.this.account_id}:root" +# }, +# "Action" : [ +# "ses:SendEmail", +# "ses:SendRawEmail" +# ], +# "Resource" : each.value.arn, +# "Condition" : {} +# } +# ] +# }) +#} + +#data "aws_iam_policy_document" "ses-policy" { +# for_each = aws_sesv2_email_identity.this +# statement { +# sid = "default" +# actions = ["SES:SendEmail", "SES:SendRawEmail"] +# resources = [each.value.arn] +# principals { +# identifiers = [data.aws_caller_identity.this.account_id] +# type = "AWS" +# } +# } +#} \ No newline at end of file diff --git a/modules/FrontendWebMobile/Ses/variables.tf b/modules/FrontendWebMobile/Ses/variables.tf new file mode 100644 index 0000000..ed9e2d6 --- /dev/null +++ b/modules/FrontendWebMobile/Ses/variables.tf @@ -0,0 +1,16 @@ +variable "emails" { + type = list(string) + description = "Email addresses to be added to SES" +} + +variable "reputation_metrics_enabled" { + type = bool + description = "Enable reputation metrics" + default = true +} + +variable "require_tls" { + type = bool + description = "Require TLS delivery option" + default = true +} \ No newline at end of file diff --git a/modules/FrontendWebMobile/Ses/versions.tf b/modules/FrontendWebMobile/Ses/versions.tf new file mode 100644 index 0000000..c8b0ffc --- /dev/null +++ b/modules/FrontendWebMobile/Ses/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0, < 5.39" + } + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/CwAgentInstallUsingSsm/README.md b/modules/ManagementGovernance/CwAgentInstallUsingSsm/README.md new file mode 100644 index 0000000..a779a64 --- /dev/null +++ b/modules/ManagementGovernance/CwAgentInstallUsingSsm/README.md @@ -0,0 +1,50 @@ + +This module installs Cloudwatch agent via SSM State Manager. +It creates an association and install the agent to all instances every 1 day. + +Then a default cloudwatch agent config is generated using amazon-cloudwatch-agent-config-wizard, +saved on /opt/aws/amazon-cloudwatch-agent/bin/config.json, supplemented with additional collections, +and uploaded on SSM parameter store as ```AmazonCloudWatch-linux```. + +Note that for cloudwatch agent to fully function, the instance needs an instance profile with the +following managed policies attached: + +* CloudWatchAgentServerPolicy +* AmazonSSMManagedInstanceCore + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_ssm_association.ConfigCwAgent](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ssm_association) | resource | +| [aws_ssm_association.InstallCwAgent](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ssm_association) | resource | +| [aws_ssm_parameter.CwAgentConfigLinux](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ssm_parameter) | resource | + +## Inputs + +No inputs. + +## Outputs + +No outputs. + +--- +## Authorship +This module was developed by UPDATE_THIS. \ No newline at end of file diff --git a/modules/ManagementGovernance/CwAgentInstallUsingSsm/main.tf b/modules/ManagementGovernance/CwAgentInstallUsingSsm/main.tf new file mode 100644 index 0000000..febc80a --- /dev/null +++ b/modules/ManagementGovernance/CwAgentInstallUsingSsm/main.tf @@ -0,0 +1,135 @@ +resource "aws_ssm_association" "InstallCwAgent" { + name = "AWS-ConfigureAWSPackage" + association_name = "CwAgentInstall" + schedule_expression = "cron(0 00 01 ? * * *)" + max_concurrency = 10 + parameters = { + name = "AmazonCloudWatchAgent" + action = "Install" + installationType = "Uninstall and reinstall" + additionalArguments = "{}" + } + targets { + key = "InstanceIds" + values = ["*"] + } +} + +resource "aws_ssm_association" "ConfigCwAgent" { + name = "AmazonCloudWatch-ManageAgent" + association_name = "CwAgentConfiguration" + schedule_expression = "cron(0 00 02 ? * * *)" + max_concurrency = 10 + parameters = { + action = "configure" + optionalConfigurationLocation = "AmazonCloudWatch-linux" + optionalConfigurationSource = "ssm" + mode = "ec2" + optionalRestart = "yes" + } + targets { + key = "InstanceIds" + values = ["*"] + } +} + +resource "aws_ssm_parameter" "CwAgentConfigLinux" { + name = "AmazonCloudWatch-linux" + description = "Cloudwatch agent Standard config for Linux" + type = "String" + value = local.CwAgentLinuxConfig +} + +locals { + CwAgentLinuxConfig = jsonencode( + { + "agent" : { + "metrics_collection_interval" : 60, + "run_as_user" : "root" + }, + "metrics" : { + "aggregation_dimensions" : [ + [ + "InstanceId" + ] + ], + "append_dimensions" : { + "AutoScalingGroupName" : "$${aws:AutoScalingGroupName}", + "ImageId" : "$${aws:ImageId}", + "InstanceId" : "$${aws:InstanceId}", + "InstanceType" : "$${aws:InstanceType}" + }, + "metrics_collected" : { + "cpu" : { + "measurement" : [ + "cpu_usage_idle", + "cpu_usage_iowait", + "cpu_usage_user", + "cpu_usage_system" + ], + "metrics_collection_interval" : 60, + "resources" : [ + "*" + ], + "totalcpu" : false + }, + "disk" : { + "measurement" : [ + "used_percent", + "inodes_free" + ], + "metrics_collection_interval" : 60, + "resources" : [ + "*" + ], + "ignore_file_system_types" : [ + "devtmpfs", + "overlay", + "sysfs", + "tmpfs" + ] + }, + "diskio" : { + "measurement" : [ + "io_time" + ], + "metrics_collection_interval" : 60, + "resources" : [ + "*" + ] + }, + "mem" : { + "measurement" : [ + "mem_used_percent" + ], + "metrics_collection_interval" : 60 + }, + "statsd" : { + "metrics_aggregation_interval" : 60, + "metrics_collection_interval" : 10, + "service_address" : ":8125" + }, + "swap" : { + "measurement" : [ + "swap_used_percent" + ], + "metrics_collection_interval" : 60 + }, + "net": { + "measurement": [ + "net_err_in", + "net_err_out" + ], + "metrics_collection_interval": 60 + }, + "processes": { + "measurement": [ + "processes_total" + ], + "metrics_collection_interval": 60 + } + } + } + } + ) +} \ No newline at end of file diff --git a/modules/ManagementGovernance/CwAgentInstallUsingSsm/versions.tf b/modules/ManagementGovernance/CwAgentInstallUsingSsm/versions.tf new file mode 100644 index 0000000..ceb041e --- /dev/null +++ b/modules/ManagementGovernance/CwAgentInstallUsingSsm/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Cwl-firehose-s3/README.md b/modules/ManagementGovernance/Cwl-firehose-s3/README.md new file mode 100644 index 0000000..d15b8a2 --- /dev/null +++ b/modules/ManagementGovernance/Cwl-firehose-s3/README.md @@ -0,0 +1,61 @@ + + +This module configure CloudwatchLog and stream logs to s3 bucket via Kinesis Firehose + +## Requirements + +| Name | Version | +|------|---------| +| terraform | ~> 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | +| random | n/a | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_cloudwatch_log_group.firehose-log](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_log_group) | resource | +| [aws_cloudwatch_log_subscription_filter.cwl-sub-filter](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_log_subscription_filter) | resource | +| [aws_iam_policy.cwlog-role-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_policy) | resource | +| [aws_iam_policy.firehose-role-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_policy) | resource | +| [aws_iam_role.cwlog-stream-role](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_iam_role.firehose-stream-iam-role](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_iam_role_policy_attachment.cwlog-role-policy-attachment](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy_attachment) | resource | +| [aws_iam_role_policy_attachment.firehose-role-policy-attachment](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy_attachment) | resource | +| [aws_kinesis_firehose_delivery_stream.cwl-s3-firehose-stream](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kinesis_firehose_delivery_stream) | resource | +| [random_id.rid](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/id) | resource | +| [aws_caller_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| cwl-region | AWS region where Cloudwatch LogGroup resides. Needed for setting up cwlog-stream-role | `string` | n/a | yes | +| dest-bucket-arn | Destination S3 bucket ARN | `string` | n/a | yes | +| dest-bucket-kmskey-arn | KMS key ARN for destination bucket | `string` | n/a | yes | +| dest-bucket-prefix | S3 object prefix for this stream. Please do not start with / end with a /. For example, r53-log/acme.local/ | `string` | n/a | yes | +| enable-firehose-errorlog | Enable firehose errorlog | `bool` | `false` | no | +| firehose-kmskey-arn | KMS Key arn for Firehose | `string` | n/a | yes | +| source-cwlgroup-name | Name of source CloudwatchLog group | `string` | n/a | yes | +| stream-name | Name of Kinesis Data Firehose delivery stream | `string` | n/a | yes | + +## Outputs + +| Name | Description | +|------|-------------| +| cloudwatchstream-iam-role-arn | n/a | +| firehose-iam-role-arn | n/a | + +--- +## Authorship +This module was developed by Rackspace. \ No newline at end of file diff --git a/modules/ManagementGovernance/Cwl-firehose-s3/main.tf b/modules/ManagementGovernance/Cwl-firehose-s3/main.tf new file mode 100644 index 0000000..8143e95 --- /dev/null +++ b/modules/ManagementGovernance/Cwl-firehose-s3/main.tf @@ -0,0 +1,161 @@ +resource "aws_kinesis_firehose_delivery_stream" "cwl-s3-firehose-stream" { + name = var.stream-name + destination = "extended_s3" + + extended_s3_configuration { + role_arn = aws_iam_role.firehose-stream-iam-role.arn + bucket_arn = var.dest-bucket-arn + prefix = trimprefix(var.dest-bucket-prefix, "/") + error_output_prefix = "FirehoseErrors/" + kms_key_arn = var.dest-bucket-kmskey-arn + cloudwatch_logging_options { + enabled = var.enable-firehose-errorlog + log_group_name = try(aws_cloudwatch_log_group.firehose-log[0].name, null) + log_stream_name = "DestinationDelivery" + } + } + server_side_encryption { + enabled = true + key_type = "CUSTOMER_MANAGED_CMK" + key_arn = var.firehose-kmskey-arn + } +} + +resource "aws_cloudwatch_log_group" "firehose-log" { + count = var.enable-firehose-errorlog ? 1 : 0 + name = "/aws/kinesisfirehose/${var.stream-name}" + retention_in_days = 365 +} + +resource "aws_cloudwatch_log_subscription_filter" "cwl-sub-filter" { + log_group_name = var.source-cwlgroup-name + name = "stream-to-s3" + role_arn = aws_iam_role.cwlog-stream-role.arn + filter_pattern = "" + destination_arn = aws_kinesis_firehose_delivery_stream.cwl-s3-firehose-stream.arn +} + +resource "random_id" "rid" { + byte_length = 4 +} + +resource "aws_iam_role" "firehose-stream-iam-role" { + name = "firehose-stream-role-${var.stream-name}-${random_id.rid.dec}" + description = "Kinesis Firehose IAM role for streaming logs from CloudwatchLog to S3" + assume_role_policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Sid" : "FirehoseStreaming", + "Effect" : "Allow", + "Principal" : { + "Service" : "firehose.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) +} + +resource "aws_iam_role_policy_attachment" "firehose-role-policy-attachment" { + role = aws_iam_role.firehose-stream-iam-role.name + policy_arn = aws_iam_policy.firehose-role-policy.arn +} + +resource "aws_iam_policy" "firehose-role-policy" { + name = "kinesis-firehose-log-stream-${var.stream-name}-${random_id.rid.dec}" + description = "Policy for Kinesis Firehose streaming logs to s3" + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Action" : [ + "s3:AbortMultipartUpload", + "s3:GetBucketLocation", + "s3:GetObject", + "s3:ListBucket", + "s3:ListBucketMultipartUploads", + "s3:PutObject" + ], + "Resource" : [ + var.dest-bucket-arn, + "${var.dest-bucket-arn}/*" + ] + }, + { + "Effect" : "Allow", + "Action" : [ + "kms:Decrypt", + "kms:GenerateDataKey" + ], + "Resource" : [ + var.dest-bucket-kmskey-arn + ] + }, + { + "Effect" : "Allow", + "Action" : [ + "logs:PutLogEvents", + "logs:PutLogEventsBatch", + "logs:CreateLogStream" + ], + "Resource" : [ + "arn:aws:logs:*:*:log-group:/aws/kinesisfirehose/${var.stream-name}/*" + ] + } + ] + } + ) +} + + +resource "aws_iam_role" "cwlog-stream-role" { + name = "cloudwatchlog-stream-role-${var.stream-name}-${random_id.rid.dec}" + description = "CloudwatchLog role for streaming to firehose" + assume_role_policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Sid" : "CloudwatchLogStreaming", + "Effect" : "Allow", + "Principal" : { + "Service" : "logs.${var.cwl-region}.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) +} + + +resource "aws_iam_role_policy_attachment" "cwlog-role-policy-attachment" { + role = aws_iam_role.cwlog-stream-role.name + policy_arn = aws_iam_policy.cwlog-role-policy.arn +} + +resource "aws_iam_policy" "cwlog-role-policy" { + name = "cloudwatchlog-stream-${var.stream-name}-${random_id.rid.dec}" + description = "Policy for CloudWatch Logs streaming to Kinesis Firehose" + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Action" : ["firehose:PutRecord"], + "Resource" : [ + "arn:aws:firehose:${var.cwl-region}:${data.aws_caller_identity.this.account_id}:deliverystream/${var.stream-name}" + ] + } + ] + } + ) +} + +data "aws_caller_identity" "this" {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Cwl-firehose-s3/outputs.tf b/modules/ManagementGovernance/Cwl-firehose-s3/outputs.tf new file mode 100644 index 0000000..a4d952a --- /dev/null +++ b/modules/ManagementGovernance/Cwl-firehose-s3/outputs.tf @@ -0,0 +1,7 @@ +output firehose-iam-role-arn { + value = aws_iam_role.firehose-stream-iam-role.arn +} + +output cloudwatchstream-iam-role-arn { + value = aws_iam_role.cwlog-stream-role.arn +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Cwl-firehose-s3/variables.tf b/modules/ManagementGovernance/Cwl-firehose-s3/variables.tf new file mode 100644 index 0000000..e5dffc6 --- /dev/null +++ b/modules/ManagementGovernance/Cwl-firehose-s3/variables.tf @@ -0,0 +1,40 @@ +variable "stream-name" { + type = string + description = "Name of Kinesis Data Firehose delivery stream" +} + +variable "firehose-kmskey-arn" { + type = string + description = "KMS Key arn for Firehose" +} + +variable "dest-bucket-arn" { + type = string + description = "Destination S3 bucket ARN" +} + +variable "dest-bucket-prefix" { + type = string + description = "S3 object prefix for this stream. Please do not start with / end with a /. For example, r53-log/acme.local/" +} + +variable "dest-bucket-kmskey-arn" { + type = string + description = "KMS key ARN for destination bucket" +} + +variable "source-cwlgroup-name" { + type = string + description = "Name of source CloudwatchLog group" +} + +variable "cwl-region" { + type = string + description = "AWS region where Cloudwatch LogGroup resides. Needed for setting up cwlog-stream-role" +} + +variable "enable-firehose-errorlog" { + type = bool + description = "Enable firehose errorlog" + default = false +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Cwl-firehose-s3/versions.tf b/modules/ManagementGovernance/Cwl-firehose-s3/versions.tf new file mode 100644 index 0000000..2a10c6a --- /dev/null +++ b/modules/ManagementGovernance/Cwl-firehose-s3/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.ALB/README.md b/modules/ManagementGovernance/Monitoring.ALB/README.md new file mode 100644 index 0000000..70ab42c --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ALB/README.md @@ -0,0 +1,22 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "alb-arns" { + source = "../../modules/util/resource-list" + resource-type = "alb" +} + +module "alb-monitoring" { + for_each = toset(split(" ", data.external.alb-arns.result.result)) + source = "../../modules/ManagementGovernance/Monitoring.ALB" + default-tags = local.default-tags + load-balancer = each.value + threshold-HealthHostCountMin = 1 +} + +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.ALB/list-alb-targetgroups.sh b/modules/ManagementGovernance/Monitoring.ALB/list-alb-targetgroups.sh new file mode 100755 index 0000000..6c7c5a8 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ALB/list-alb-targetgroups.sh @@ -0,0 +1,6 @@ +#!/bin/bash +eval "$(jq -r '@sh "lb=\(.lb)"')" + +RESULTS=$(aws elbv2 describe-target-groups --load-balancer-arn $lb --query TargetGroups[*].TargetGroupArn --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' + diff --git a/modules/ManagementGovernance/Monitoring.ALB/main.tf b/modules/ManagementGovernance/Monitoring.ALB/main.tf new file mode 100644 index 0000000..c56421f --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ALB/main.tf @@ -0,0 +1,110 @@ +locals { + alb-name = "app/${split("/", var.load-balancer)[2]}/${split("/", var.load-balancer)[3]}" +} + +resource "aws_cloudwatch_metric_alarm" "alb-HTTPCode_ELB_5XX_Count" { + alarm_name = "${var.settings.HTTPCode_ELB_5XX_Count.ecccode}-ALB_${local.alb-name}-HTTPCode_ELB_5XX_Count" + comparison_operator = var.settings.HTTPCode_ELB_5XX_Count.comparison_operator + evaluation_periods = var.settings.HTTPCode_ELB_5XX_Count.evaluation_periods + metric_name = "HTTPCode_ELB_5XX_Count" + period = var.settings.HTTPCode_ELB_5XX_Count.period + statistic = var.settings.HTTPCode_ELB_5XX_Count.statistic + threshold = var.settings.HTTPCode_ELB_5XX_Count.threshold + alarm_description = "ALB:HTTPCode_ELB_5XX_Count" + namespace = "AWS/ApplicationELB" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.HTTPCode_ELB_5XX_Count.action] + ok_actions = [var.settings.HTTPCode_ELB_5XX_Count.action] + dimensions = { + LoadBalancer = local.alb-name + } +} + +resource "aws_cloudwatch_metric_alarm" "alb-TargetConnectionErrorCount" { + alarm_name = "${var.settings.TargetConnectionErrorCount.ecccode}-ALB_${local.alb-name}-TargetConnectionErrorCount" + comparison_operator = var.settings.TargetConnectionErrorCount.comparison_operator + evaluation_periods = var.settings.TargetConnectionErrorCount.evaluation_periods + metric_name = "TargetConnectionErrorCount" + period = var.settings.TargetConnectionErrorCount.period + statistic = var.settings.TargetConnectionErrorCount.statistic + threshold = var.settings.TargetConnectionErrorCount.threshold + alarm_description = "ALB:TargetConnectionErrorCount" + namespace = "AWS/ApplicationELB" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.TargetConnectionErrorCount.action] + ok_actions = [var.settings.TargetConnectionErrorCount.action] + dimensions = { + LoadBalancer = local.alb-name + } +} + +resource "aws_cloudwatch_metric_alarm" "alb-TargetResponseTime" { + alarm_name = "${var.settings.TargetResponseTime.ecccode}-ALB_${local.alb-name}-TargetResponseTime" + comparison_operator = var.settings.TargetResponseTime.comparison_operator + evaluation_periods = var.settings.TargetResponseTime.evaluation_periods + metric_name = "TargetResponseTime" + period = var.settings.TargetResponseTime.period + statistic = var.settings.TargetResponseTime.statistic + threshold = var.settings.TargetResponseTime.threshold + alarm_description = "ALB:TargetResponseTime" + namespace = "AWS/ApplicationELB" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.TargetResponseTime.action] + ok_actions = [var.settings.TargetResponseTime.action] + dimensions = { + LoadBalancer = local.alb-name + } +} + +/* +module "alb-targetgroups" { + source = "../../util/resource-list" + resource-type = "alb-targetgroups" + query-input = var.load-balancer + asrolearn = var.asrolearn +} +*/ +// causes Rate exceeded error, maybe because of adaptive AWS_RETRY_MODE? + +/* +module "alb_tgs" { + assume_role_arn = var.asrolearn + role_session_name = "terraform-resource-list" + source = "../../util/terraform-aws-cli" + aws_cli_commands = ["elbv2", "describe-target-groups", "--load-balancer-arn", var.load-balancer] + aws_cli_query = "TargetGroups[*].TargetGroupArn" +} +*/ + +module alb_tgs { + source = "../../util/awscli" + access_key = var.target-account-ak + aws_cli_commands = "elbv2 describe-target-groups --load-balancer-arn ${var.load-balancer} --query TargetGroups[*].TargetGroupArn" + secret_key = var.target-account-sk + session_token = var.target-account-token +} + +resource "aws_cloudwatch_metric_alarm" "alb-HealthyHostCount" { + # for_each = module.alb-targetgroups.result-set + for_each = toset(module.alb_tgs.awscliout) + alarm_name = "${var.settings.HealthHostCountMin.ecccode}-ALBTG_:${split(":", each.value)[5]}-HealthyHostCount" + comparison_operator = var.settings.HealthHostCountMin.comparison_operator + evaluation_periods = var.settings.HealthHostCountMin.evaluation_periods + metric_name = "HealthyHostCount" + period = var.settings.HealthHostCountMin.period + statistic = var.settings.HealthHostCountMin.statistic + threshold = var.settings.HealthHostCountMin.threshold + alarm_description = "ALBTG:HealthyHostCount" + namespace = "AWS/ApplicationELB" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.HealthHostCountMin.action] + ok_actions = [var.settings.HealthHostCountMin.action] + dimensions = { + TargetGroup = split(":", each.value)[5] + LoadBalancer = "app/${split("/", var.load-balancer)[2]}/${split("/", var.load-balancer)[3]}" + } +} diff --git a/modules/ManagementGovernance/Monitoring.ALB/outputs.tf b/modules/ManagementGovernance/Monitoring.ALB/outputs.tf new file mode 100644 index 0000000..3007af1 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ALB/outputs.tf @@ -0,0 +1,4 @@ +output alb-tg-count { + # value = length(module.alb-targetgroups.result-set) + value = length(flatten(module.alb_tgs.awscliout)) +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.ALB/provider.tf b/modules/ManagementGovernance/Monitoring.ALB/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ALB/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.ALB/variables.tf b/modules/ManagementGovernance/Monitoring.ALB/variables.tf new file mode 100644 index 0000000..8762244 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ALB/variables.tf @@ -0,0 +1,8 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable load-balancer {} +variable settings {} +# variable asrolearn {} +variable target-account-ak {} +variable target-account-sk {} +variable target-account-token {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.ASG/README.md b/modules/ManagementGovernance/Monitoring.ASG/README.md new file mode 100644 index 0000000..d3b9c14 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ASG/README.md @@ -0,0 +1,24 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "asg" { + source = "../../modules/util/resource-list" + resource-type = "asg" +} + +module "asg-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.asg.result-set + source = "../../modules/ManagementGovernance/Monitoring.ASG" + default-tags = local.default-tags + asg-name = each.value + threshold-CPUUtilization = 90 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.ASG/main.tf b/modules/ManagementGovernance/Monitoring.ASG/main.tf new file mode 100644 index 0000000..2485ccd --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ASG/main.tf @@ -0,0 +1,41 @@ +data "aws_autoscaling_group" "asg" { + name = var.asg-name +} + +resource "aws_cloudwatch_metric_alarm" "asg-CPUUtilization" { + alarm_name = "${var.settings.CPUUtilization.ecccode}-ASG_${var.asg-name}-CPUUtilization" + comparison_operator = var.settings.CPUUtilization.comparison_operator + evaluation_periods = var.settings.CPUUtilization.evaluation_periods + metric_name = "CPUUtilization" + period = var.settings.CPUUtilization.period + statistic = var.settings.CPUUtilization.statistic + threshold = var.settings.CPUUtilization.threshold + alarm_description = "ASG:CPUUtilization" + namespace = "AWS/EC2" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.CPUUtilization.action] + ok_actions = [var.settings.CPUUtilization.action] + dimensions = { + AutoScalingGroupName =var.asg-name + } +} + +resource "aws_cloudwatch_metric_alarm" "asg-GroupInServiceCapacity" { + alarm_name = "${var.settings.GroupInServiceCapacity.ecccode}-ASG_${var.asg-name}-GroupInServiceCapacity" + comparison_operator = "LessThanThreshold" + evaluation_periods = var.settings.GroupInServiceCapacity.evaluation_periods + metric_name = "GroupInServiceCapacity" + period = var.settings.GroupInServiceCapacity.period + statistic = "Minimum" + threshold = data.aws_autoscaling_group.asg.min_size + alarm_description = "ASG:GroupInServiceCapacity" + namespace = "AWS/AutoScaling" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.GroupInServiceCapacity.action] + ok_actions = [var.settings.GroupInServiceCapacity.action] + dimensions = { + AutoScalingGroupName = var.asg-name + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.ASG/provider.tf b/modules/ManagementGovernance/Monitoring.ASG/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ASG/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.ASG/variables.tf b/modules/ManagementGovernance/Monitoring.ASG/variables.tf new file mode 100644 index 0000000..819318f --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.ASG/variables.tf @@ -0,0 +1,5 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable asg-name {} +variable settings {} +variable ecccode {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EC2/README.md b/modules/ManagementGovernance/Monitoring.EC2/README.md new file mode 100644 index 0000000..45f5b9b --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EC2/README.md @@ -0,0 +1,74 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "ec2-instances" { + source = "../../modules/util/resource-list" + resource-type = "ec2" +} + +module "ec2-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.ec2-instances.result-set + source = "../../modules/ManagementGovernance/Monitoring.EC2" + default-tags = local.default-tags + ec2-instance-id = each.value + threshold-CPUUtilization = 90 + threshold-mem_free = 100000 + threshold-swap_free = 100000 + threshold-disk_free = 1 * 1000 * 1000 * 1000 + threshold-disk_inodes_free = 10000 + threshold-processes_total = 500 + threshold-LogicalDiskFreePct = 10 + threshold-MemoryCommittedPct = 90 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` + +## Sample cloudwatch alarm email notification +``` +Subject: ALARM: "TestAlarmPleaseIgnore" in Asia Pacific (Hong Kong) + +You are receiving this email because your Amazon CloudWatch Alarm "TestAlarmPleaseIgnore" in the +Asia Pacific (Hong Kong) region has entered the ALARM state, because "Threshold Crossed: 1 out of +the last 1 datapoints [864.0 (24/01/24 00:56:00)] was less than or equal to the threshold (900.0) +(minimum 1 datapoint for OK -> ALARM transition)." at "Wednesday 24 January, 2024 01:01:34 UTC". + +View this alarm in the AWS Management Console: +https://ap-east-1.console.aws.amazon.com%2Fcloudwatch... + +Alarm Details: +- Name: TestAlarmPleaseIgnore +- Description: Cloudwatch alarm for the following resource +- Instance ID: xxx +- Instance Name: yyy +- Instance IP: zz.zz.zz.zz +- State Change: OK -> ALARM +- Reason for State Change: Threshold Crossed: 1 out of the last 1 datapoints [864.0 (24/01/24 00:56:00)] was less than or equal to the threshold (900.0) (minimum 1 datapoint for OK -> ALARM transition). +- Timestamp: Wednesday 24 January, 2024 01:01:34 UTC +- AWS Account: 111122223333 +- Alarm Arn: arn:aws:cloudwatch:ap-east-1:111122223333:alarm:TestAlarmPleaseIgnore + +Threshold: +- The alarm is in the ALARM state when the metric is LessThanOrEqualToThreshold 900.0 for at least 1 of the last 1 period(s) of 300 seconds. + +Monitored Metric: +- MetricNamespace: AWS/EC2 +- MetricName: CPUCreditBalance +- Dimensions: [InstanceId = i-050d4adeafaa53cd0] +- Period: 300 seconds +- Statistic: Average +- Unit: not specified +- TreatMissingData: missing + + +State Change Actions: +- OK: +- ALARM: [arn:aws:sns:ap-east-1:111122223333:CWA-SNS-Email-KenFong] +- INSUFFICIENT_DATA: +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EC2/get-cwagent-device.sh b/modules/ManagementGovernance/Monitoring.EC2/get-cwagent-device.sh new file mode 100755 index 0000000..bf513e9 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EC2/get-cwagent-device.sh @@ -0,0 +1,22 @@ +#!/bin/bash +eval "$(jq -r '@sh "export id=\(.input) asrolearn=\(.asrolearn)"')" +eval $(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken, "export AWS_SESSION_EXPIRATION=" + .Credentials.Expiration') + +aws cloudwatch list-metrics --namespace CWAgent --metric-name disk_inodes_free \ +--dimensions Name=InstanceId,Value=$id Name=path,Value=/ | \ +jq '.Metrics[] | .Dimensions[] | select ((.Name=="device") or (.Name=="fstype")) | { (.Name): (.Value)}' | \ +jq -s 'add // {"device":"unknown", "fstype":"unknown"}' + + +exit 0 + +DEVICE=$(aws cloudwatch list-metrics --namespace CWAgent --metric-name disk_inodes_free \ +--dimensions Name=InstanceId,Value=$id Name=path,Value=/ \ +--query 'Metrics[].Dimensions[?Name==`device`].Value' --output text) + +FSTYPE=$(aws cloudwatch list-metrics --namespace CWAgent --metric-name disk_inodes_free \ + --dimensions Name=InstanceId,Value=$id Name=path,Value=/ \ + --query 'Metrics[].Dimensions[?Name==`fstype`].Value' --output text) + +jq -n --arg device "$DEVICE" --arg fstype "$FSTYPE" '{"device":$device,"fstype":$fstype}' + diff --git a/modules/ManagementGovernance/Monitoring.EC2/get-cwagent-dimensions.sh b/modules/ManagementGovernance/Monitoring.EC2/get-cwagent-dimensions.sh new file mode 100755 index 0000000..8001bfd --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EC2/get-cwagent-dimensions.sh @@ -0,0 +1,25 @@ +#!/bin/bash +# Get the query +TERRAFORM_QUERY=$(jq -Mc .) + +# Extract the query attributes +access_key=$(echo "${TERRAFORM_QUERY}" | jq -r '.access_key') +secret_key=$(echo "${TERRAFORM_QUERY}" | jq -r '.secret_key') +session_token=$(echo "${TERRAFORM_QUERY}" | jq -r '.session_token') +iid=$(echo "${TERRAFORM_QUERY}" | jq -r '.iid') + +# eval "$(jq -r '@sh "export id=\(.input) asrolearn=\(.asrolearn)"')" +# eval $(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken, "export AWS_SESSION_EXPIRATION=" + .Credentials.Expiration') + +export AWS_ACCESS_KEY_ID=$access_key +export AWS_SECRET_ACCESS_KEY=$secret_key +export AWS_SESSION_TOKEN=$session_token + +#aws cloudwatch list-metrics --namespace CWAgent --metric-name disk_inodes_free \ +#--dimensions Name=InstanceId,Value=$iid Name=path,Value=/ | \ +#jq '.Metrics[] | .Dimensions[] | {(.Name):(.Value)}' | jq -s 'add' + +# when there are multiple metrics with the same name... +aws cloudwatch list-metrics --namespace CWAgent --metric-name disk_inodes_free \ +--dimensions Name=InstanceId,Value=$iid Name=path,Value=/ --query Metrics[] | \ +jq '. | last | .Dimensions[] | {(.Name):(.Value)}' | jq -s 'add' diff --git a/modules/ManagementGovernance/Monitoring.EC2/get-os-platform.sh b/modules/ManagementGovernance/Monitoring.EC2/get-os-platform.sh new file mode 100755 index 0000000..f9de740 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EC2/get-os-platform.sh @@ -0,0 +1,12 @@ +#!/bin/bash +eval "$(jq -r '@sh "export id=\(.input) asrolearn=\(.asrolearn)"')" +eval $(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken, "export AWS_SESSION_EXPIRATION=" + .Credentials.Expiration') + +EC2OS=$(aws ec2 describe-instances --instance-ids $id | jq -r '.Reservations[].Instances[].PlatformDetails') + +if [ $EC2OS == "Windows" ]; then + echo '{"os": "Windows"}' +else + echo '{"os": "Linux"}' +fi + diff --git a/modules/ManagementGovernance/Monitoring.EC2/main.tf b/modules/ManagementGovernance/Monitoring.EC2/main.tf new file mode 100644 index 0000000..1e10344 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EC2/main.tf @@ -0,0 +1,395 @@ +locals { + # alarm-message limited to 1024 characters + alarm-message = < 0 ? 1 : 0 + alarm_name = "${var.settings.mem_used_percent.ecccode}-EC2_${var.ec2-instance-id}-mem_used_percent" + comparison_operator = var.settings.mem_used_percent.comparison_operator + evaluation_periods = var.settings.mem_used_percent.evaluation_periods + metric_name = "mem_used_percent" + period = var.settings.mem_used_percent.period + statistic = var.settings.mem_used_percent.statistic + threshold = var.settings.mem_used_percent.threshold + # alarm_description = "EC2:mem_used_percent" + alarm_description = local.alarm-message + namespace = "CWAgent" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.mem_used_percent.action] + ok_actions = [var.settings.mem_used_percent.action] + dimensions = { + InstanceId = var.ec2-instance-id + ImageId = data.aws_instance.ec2-instance.ami + InstanceType = data.aws_instance.ec2-instance.instance_type + } +} + +data "external" "cw-dimensions" { + program = ["bash", "${path.module}/get-cwagent-dimensions.sh"] + query = { + iid = var.ec2-instance-id + access_key = var.target-account-ak + secret_key = var.target-account-sk + session_token = var.target-account-token + } +} + +/* module returns blank +module "cw-dimensions" { + source = "../../util/awscli" + access_key = var.target-account-ak + aws_cli_commands = "cloudwatch list-metrics --namespace CWAgent --metric-name disk_inodes_free --dimensions Name=InstanceId,Value=${var.ec2-instance-id} Name=path,Value=/ --query Metrics[].Dimensions[] | jq '.[] | {(.Name):(.Value)}' | jq -s 'add'" + secret_key = var.target-account-sk + session_token = var.target-account-token +} +*/ + +resource "aws_cloudwatch_metric_alarm" "ec2-swap_used_percent" { + count = module.ec2_os.awscliout[0] != "Windows" && length(module.detect_cloudwatch_agent.awscliout) > 0 ? 1 : 0 + alarm_name = "${var.settings.swap_used_percent.ecccode}-EC2_${var.ec2-instance-id}-swap_used_percent" + comparison_operator = var.settings.swap_used_percent.comparison_operator + evaluation_periods = var.settings.swap_used_percent.evaluation_periods + metric_name = "swap_used_percent" + period = var.settings.swap_used_percent.period + statistic = var.settings.swap_used_percent.statistic + threshold = var.settings.swap_used_percent.threshold + # alarm_description = "EC2:swap_used_percent" + alarm_description = local.alarm-message + namespace = "CWAgent" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.swap_used_percent.action] + ok_actions = [var.settings.swap_used_percent.action] + dimensions = { + InstanceId = var.ec2-instance-id + ImageId = data.aws_instance.ec2-instance.ami + InstanceType = data.aws_instance.ec2-instance.instance_type + } +} + +resource "aws_cloudwatch_metric_alarm" "ec2-disk_used_percent_warn" { + count = module.ec2_os.awscliout[0] != "Windows" && data.external.cw-dimensions.result != null ? 1 : 0 + alarm_name = "${var.settings.disk_used_percent_warn.ecccode}-EC2_${var.ec2-instance-id}-disk_used_percent" + comparison_operator = var.settings.disk_used_percent_warn.comparison_operator + evaluation_periods = var.settings.disk_used_percent_warn.evaluation_periods + metric_name = "disk_used_percent" + period = var.settings.disk_used_percent_warn.period + statistic = var.settings.disk_used_percent_warn.statistic + threshold = var.settings.disk_used_percent_warn.threshold + # alarm_description = "EC2:disk_used_percent" + alarm_description = local.alarm-message + namespace = "CWAgent" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.disk_used_percent_warn.action] + ok_actions = [var.settings.disk_used_percent_warn.action] + dimensions = data.external.cw-dimensions.result +} + +resource "aws_cloudwatch_metric_alarm" "ec2-disk_used_percent_crit" { + count = module.ec2_os.awscliout[0] != "Windows" && data.external.cw-dimensions.result != null ? 1 : 0 + alarm_name = "${var.settings.disk_used_percent_crit.ecccode}-EC2_${var.ec2-instance-id}-disk_used_percent" + comparison_operator = var.settings.disk_used_percent_crit.comparison_operator + evaluation_periods = var.settings.disk_used_percent_crit.evaluation_periods + metric_name = "disk_used_percent" + period = var.settings.disk_used_percent_crit.period + statistic = var.settings.disk_used_percent_crit.statistic + threshold = var.settings.disk_used_percent_crit.threshold + # alarm_description = "EC2:disk_used_percent" + alarm_description = local.alarm-message + namespace = "CWAgent" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.disk_used_percent_crit.action] + ok_actions = [var.settings.disk_used_percent_crit.action] + dimensions = data.external.cw-dimensions.result +} + +resource "aws_cloudwatch_metric_alarm" "ec2-disk_inodes_free" { + count = module.ec2_os.awscliout[0] != "Windows" && data.external.cw-dimensions.result != null ? 1 : 0 + alarm_name = "${var.settings.disk_inodes_free.ecccode}-EC2_${var.ec2-instance-id}-disk_inodes_free" + comparison_operator = var.settings.disk_inodes_free.comparison_operator + evaluation_periods = var.settings.disk_inodes_free.evaluation_periods + metric_name = "disk_inodes_free" + period = var.settings.disk_inodes_free.period + statistic = var.settings.disk_inodes_free.statistic + threshold = var.settings.disk_inodes_free.threshold + # alarm_description = "EC2:disk_inodes_free" + alarm_description = local.alarm-message + namespace = "CWAgent" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.disk_inodes_free.action] + ok_actions = [var.settings.disk_inodes_free.action] + dimensions = data.external.cw-dimensions.result +} + +# process metric not published by default cw agent config +resource "aws_cloudwatch_metric_alarm" "ec2-processes_total" { + count = module.ec2_os.awscliout[0] != "Windows" && length(module.detect_cloudwatch_agent.awscliout) > 0 ? 1 : 0 + alarm_name = "${var.settings.processes_total.ecccode}-EC2_${var.ec2-instance-id}-processes_total" + comparison_operator = var.settings.processes_total.comparison_operator + evaluation_periods = var.settings.processes_total.evaluation_periods + metric_name = "processes_total" + period = var.settings.processes_total.period + statistic = var.settings.processes_total.statistic + threshold = var.settings.processes_total.threshold + # alarm_description = "EC2:processes_total" + alarm_description = local.alarm-message + namespace = "CWAgent" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.processes_total.action] + ok_actions = [var.settings.processes_total.action] + dimensions = { + InstanceId = var.ec2-instance-id + ImageId = data.aws_instance.ec2-instance.ami + InstanceType = data.aws_instance.ec2-instance.instance_type + } +} + +resource "aws_cloudwatch_metric_alarm" "ec2-net_err" { + count = module.ec2_os.awscliout[0] != "Windows" && length(module.detect_cloudwatch_agent.awscliout) > 0 ? 1 : 0 + alarm_name = "${var.settings.net_err_in.ecccode}-EC2_${var.ec2-instance-id}-net_err" + comparison_operator = "GreaterThanThreshold" + evaluation_periods = var.settings.net_err_in.evaluation_periods + threshold = 0 + # alarm_description = "EC2:net_err_in or EC2:net_err_out exceeds threshold" + alarm_description = local.alarm-message + insufficient_data_actions = [] + actions_enabled = false + alarm_actions = [var.settings.net_err_in.action] + ok_actions = [var.settings.net_err_in.action] + treat_missing_data = "notBreaching" + + metric_query { + id = "e1" + expression = "IF(m1 > ${var.settings.net_err_in.threshold} OR m2 > ${var.settings.net_err_out.threshold}, 1, 0)" + label = "net_err_exceeds_threshold" + return_data = "true" + } + + metric_query { + id = "m1" + metric { + metric_name = "net_err_in" + namespace = "CWAgent" + period = var.settings.net_err_in.period + stat = var.settings.net_err_in.statistic + dimensions = { + InstanceId = var.ec2-instance-id + ImageId = data.aws_instance.ec2-instance.ami + InstanceType = data.aws_instance.ec2-instance.instance_type + interface = "eth0" + } + } + } + + metric_query { + id = "m2" + metric { + metric_name = "net_err_out" + namespace = "CWAgent" + period = var.settings.net_err_out.period + stat = var.settings.net_err_out.statistic + dimensions = { + InstanceId = var.ec2-instance-id + ImageId = data.aws_instance.ec2-instance.ami + InstanceType = data.aws_instance.ec2-instance.instance_type + interface = "eth0" + } + } + } +} + +resource "aws_cloudwatch_metric_alarm" "ec2-NetworkIn" { + count = try(var.settings.NetworkIn.monitor, false) ? 1 : 0 + alarm_name = "${var.settings.NetworkIn.ecccode}-EC2_${var.ec2-instance-id}-NetworkIn" + comparison_operator = var.settings.NetworkIn.comparison_operator + evaluation_periods = var.settings.NetworkIn.evaluation_periods + metric_name = "NetworkIn" + period = var.settings.NetworkIn.period + statistic = var.settings.NetworkIn.statistic + threshold = var.settings.NetworkIn.threshold + # alarm_description = "EC2:NetworkIn" + alarm_description = local.alarm-message + namespace = "AWS/EC2" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.NetworkIn.action] + ok_actions = [var.settings.NetworkIn.action] + dimensions = { + InstanceId = var.ec2-instance-id + } +} + +resource "aws_cloudwatch_metric_alarm" "ec2-NetworkOut" { + count = try(var.settings.NetworkIn.monitor, false) ? 1 : 0 + alarm_name = "${var.settings.NetworkOut.ecccode}-EC2_${var.ec2-instance-id}-NetworkOut" + comparison_operator = var.settings.NetworkOut.comparison_operator + evaluation_periods = var.settings.NetworkOut.evaluation_periods + metric_name = "NetworkOut" + period = var.settings.NetworkOut.period + statistic = var.settings.NetworkOut.statistic + threshold = var.settings.NetworkOut.threshold + # alarm_description = "EC2:NetworkOut" + alarm_description = local.alarm-message + namespace = "AWS/EC2" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.NetworkOut.action] + ok_actions = [var.settings.NetworkOut.action] + dimensions = { + InstanceId = var.ec2-instance-id + } +} + +# Windows specific checks +resource "aws_cloudwatch_metric_alarm" "ec2-MemoryCommittedPct" { + count = module.ec2_os.awscliout[0] == "Windows" && length(module.detect_cloudwatch_agent.awscliout) > 0 ? 1 : 0 + alarm_name = "${var.settings.MemoryCommittedPct.ecccode}-EC2_${var.ec2-instance-id}-MemoryCommittedPct" + comparison_operator = var.settings.MemoryCommittedPct.comparison_operator + evaluation_periods = var.settings.MemoryCommittedPct.evaluation_periods + metric_name = "Memory % Committed Bytes In Use" + period = var.settings.MemoryCommittedPct.period + statistic = var.settings.MemoryCommittedPct.statistic + threshold = var.settings.MemoryCommittedPct.threshold + # alarm_description = "EC2:MemoryCommittedBytes" + alarm_description = local.alarm-message + namespace = "CWAgent" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.MemoryCommittedPct.action] + ok_actions = [var.settings.MemoryCommittedPct.action] + dimensions = { + objectname = "Memory" + InstanceId = var.ec2-instance-id + ImageId = data.aws_instance.ec2-instance.ami + InstanceType = data.aws_instance.ec2-instance.instance_type + } +} + +resource "aws_cloudwatch_metric_alarm" "ec2-LogicalDiskFreePct" { + count = module.ec2_os.awscliout[0] == "Windows" && length(module.detect_cloudwatch_agent.awscliout) > 0 ? 1 : 0 + alarm_name = "${var.settings.LogicalDiskFreePct.ecccode}-EC2_${var.ec2-instance-id}-LogicalDiskFreePct" + comparison_operator = var.settings.LogicalDiskFreePct.comparison_operator + evaluation_periods = var.settings.LogicalDiskFreePct.evaluation_periods + metric_name = "LogicalDisk % Free Space" + period = var.settings.LogicalDiskFreePct.period + statistic = var.settings.LogicalDiskFreePct.statistic + threshold = var.settings.LogicalDiskFreePct.threshold + # alarm_description = "EC2:OsDiskFreePct" + alarm_description = local.alarm-message + namespace = "CWAgent" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.LogicalDiskFreePct.action] + ok_actions = [var.settings.LogicalDiskFreePct.action] + dimensions = { + instance = "C:" + objectname = "LogicalDisk" + InstanceId = var.ec2-instance-id + ImageId = data.aws_instance.ec2-instance.ami + InstanceType = data.aws_instance.ec2-instance.instance_type + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EC2/provider.tf b/modules/ManagementGovernance/Monitoring.EC2/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EC2/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.EC2/variables.tf b/modules/ManagementGovernance/Monitoring.EC2/variables.tf new file mode 100644 index 0000000..9ad19dd --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EC2/variables.tf @@ -0,0 +1,8 @@ +variable "cw-alarm-prefix" {} +variable "actions-enabled" {} +variable "ec2-instance-id" {} +variable "settings" {} +# variable asrolearn {} +variable target-account-ak {} +variable target-account-sk {} +variable target-account-token {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EKS/README.md b/modules/ManagementGovernance/Monitoring.EKS/README.md new file mode 100644 index 0000000..59cf483 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EKS/README.md @@ -0,0 +1,27 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. +Unlike other monitoring modules which discovers resources details automatically, EKS pod name need to be supplied to this module. +AWS cli does not provide pod information. + +## Example +```terraform +data "aws_eks_clusters" "eks-clusters" {} + +module "eks-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = data.aws_eks_clusters.eks-clusters.names + source = "../../modules/ManagementGovernance/Monitoring.EKS" + default-tags = local.default-tags + cluster-name = each.value + eks-namespace = "default" + pod-names = ["depl-nginx", "depl-alpine"] + threshold-pod_cpu_utilization = 85 + threshold-pod_memory_utilization = 85 + threshold-pod_number_of_container_restarts = 5 + actions-enabled = var.actions-enabled + sns-targets = local.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EKS/main.tf b/modules/ManagementGovernance/Monitoring.EKS/main.tf new file mode 100644 index 0000000..bab15c9 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EKS/main.tf @@ -0,0 +1,69 @@ +// The following checks requires container insights + +resource "aws_cloudwatch_metric_alarm" "eks-pod_cpu_utilization" { + for_each = toset(var.pod-names) + alarm_name = "${each.value["ecccode"]}:${var.cw-alarm-prefix}:EKS:${var.cluster-name}:${each.value}:${var.settings.alarm1.metric}" + comparison_operator = var.settings.alarm1.comparison_operator + evaluation_periods = var.settings.alarm1.evaluation_periods + metric_name = var.settings.alarm1.metric + period = var.settings.alarm1.period + statistic = var.settings.alarm1.statistic + threshold = var.settings.alarm1.threshold + alarm_description = "EKS:${var.settings.alarm1.metric}" + namespace = "ContainerInsights" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.alarm1.action] + ok_actions = [var.settings.alarm1.action] + dimensions = { + "PodName" = each.value + "ClusterName" = var.cluster-name + "Namespace" = var.eks-namespace + } +} + +resource "aws_cloudwatch_metric_alarm" "eks-pod_memory_utilization" { + for_each = toset(var.pod-names) + + alarm_name = "${each.value["ecccode"]}:${var.cw-alarm-prefix}:EKS:${var.cluster-name}:${each.value}:${var.settings.alarm2.metric}" + comparison_operator = "GreaterThanThreshold" + evaluation_periods = "3" + metric_name = var.settings.alarm2.metric + period = var.settings.alarm2.period + statistic = var.settings.alarm2.statistic + threshold = var.settings.alarm2.threshold + alarm_description = "EKS:${var.settings.alarm2.metric}" + namespace = "ContainerInsights" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.alarm2.action] + ok_actions = [var.settings.alarm2.action] + dimensions = { + "PodName" = each.value + "ClusterName" = var.cluster-name + "Namespace" = var.eks-namespace + } +} + +resource "aws_cloudwatch_metric_alarm" "eks-pod_number_of_container_restarts" { + for_each = toset(var.pod-names) + + alarm_name = "${each.value["ecccode"]}:${var.cw-alarm-prefix}:EKS:${var.cluster-name}:${each.value}:${var.settings.alarm3.metric}" + comparison_operator = "GreaterThanThreshold" + evaluation_periods = "3" + metric_name = var.settings.alarm3.metric + period = var.settings.alarm3.period + statistic = var.settings.alarm3.statistic + threshold = var.settings.alarm3.threshold + alarm_description = "EKS:${var.settings.alarm3.metric}" + namespace = "ContainerInsights" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.alarm3.action] + ok_actions = [var.settings.alarm3.action] + dimensions = { + "PodName" = each.value + "ClusterName" = var.cluster-name + "Namespace" = var.eks-namespace + } +} diff --git a/modules/ManagementGovernance/Monitoring.EKS/provider.tf b/modules/ManagementGovernance/Monitoring.EKS/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EKS/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.EKS/variables.tf b/modules/ManagementGovernance/Monitoring.EKS/variables.tf new file mode 100644 index 0000000..7eb4d63 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EKS/variables.tf @@ -0,0 +1,8 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable cluster-name {} +variable eks-namespace {} +variable pod-names { + type = list +} +variable settings {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EMR/README.md b/modules/ManagementGovernance/Monitoring.EMR/README.md new file mode 100644 index 0000000..6d394fa --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EMR/README.md @@ -0,0 +1,25 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "emr-clusters" { + source = "../../modules/util/resource-list" + resource-type = "emr" +} + +module "emr-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.emr-clusters.result-set + source = "../../modules/ManagementGovernance/Monitoring.EMR" + default-tags = local.default-tags + job-flow-id = split("/", each.value)[1] + threshold-AppsPending = 2 + threshold-CapacityRemainingGB = 100 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EMR/main.tf b/modules/ManagementGovernance/Monitoring.EMR/main.tf new file mode 100644 index 0000000..06c999e --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EMR/main.tf @@ -0,0 +1,19 @@ +resource "aws_cloudwatch_metric_alarm" "emr-alarms" { + for_each = var.settings + alarm_name = "${each.value["ecccode"]}-EMR_${var.job-flow-id}-${each.value["metric"]}" + comparison_operator = each.value["comparison_operator"] + evaluation_periods = each.value["evaluation_periods"] + metric_name = each.value["metric"] + period = each.value["period"] + statistic = each.value["statistic"] + threshold = each.value["threshold"] + alarm_description = "EMR:${each.value["metric"]}" + namespace = "AWS/ElasticMapReduce" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [each.value["action"]] + ok_actions = [each.value["action"]] + dimensions = { + JobFlowId = var.job-flow-id + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EMR/provider.tf b/modules/ManagementGovernance/Monitoring.EMR/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EMR/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.EMR/variables.tf b/modules/ManagementGovernance/Monitoring.EMR/variables.tf new file mode 100644 index 0000000..cccfe64 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EMR/variables.tf @@ -0,0 +1,4 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable job-flow-id {} +variable settings {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EventBridge/README.md b/modules/ManagementGovernance/Monitoring.EventBridge/README.md new file mode 100644 index 0000000..616d36f --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EventBridge/README.md @@ -0,0 +1,5 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. diff --git a/modules/ManagementGovernance/Monitoring.EventBridge/main.tf b/modules/ManagementGovernance/Monitoring.EventBridge/main.tf new file mode 100644 index 0000000..25950f5 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EventBridge/main.tf @@ -0,0 +1,46 @@ +resource "aws_cloudwatch_event_rule" "EventRule" { + name = "${var.cw-alarm-prefix}-health-events" + description = "A CloudWatch Event Rule that triggers on changes in the status of AWS Personal Health Dashboard (AWS Health) and forwards the events to an SNS topic." + state = var.actions-enabled + event_pattern = < on AWS account ." + +"Resources: " +"Start time: " +"End time: " + +"Detail: " +EOF + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.EventBridge/provider.tf b/modules/ManagementGovernance/Monitoring.EventBridge/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EventBridge/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.EventBridge/variables.tf b/modules/ManagementGovernance/Monitoring.EventBridge/variables.tf new file mode 100644 index 0000000..51a3d17 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.EventBridge/variables.tf @@ -0,0 +1,3 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable settings {} diff --git a/modules/ManagementGovernance/Monitoring.Kafka/README.md b/modules/ManagementGovernance/Monitoring.Kafka/README.md new file mode 100644 index 0000000..3951397 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.Kafka/README.md @@ -0,0 +1,24 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "kafka-clusters" { + source = "../../modules/util/resource-list" + resource-type = "kafka" +} + +module "kafka-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.kafka-clusters.result-set + source = "../../modules/ManagementGovernance/Monitoring.Kafka" + default-tags = local.default-tags + cluster-name = each.value + threshold-ZooKeeperRequestLatencyMsMean = 30 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.Kafka/main.tf b/modules/ManagementGovernance/Monitoring.Kafka/main.tf new file mode 100644 index 0000000..8782918 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.Kafka/main.tf @@ -0,0 +1,116 @@ +resource "aws_cloudwatch_metric_alarm" "Kafka-ZooKeeperRequestLatencyMsMean" { + alarm_name = "${var.settings.ZooKeeperRequestLatencyMsMean.ecccode}-Kafka_${var.cluster-name}-ZooKeeperRequestLatencyMsMean" + comparison_operator = var.settings.ZooKeeperRequestLatencyMsMean.comparison_operator + evaluation_periods = var.settings.ZooKeeperRequestLatencyMsMean.evaluation_periods + metric_name = "ZooKeeperRequestLatencyMsMean" + period = var.settings.ZooKeeperRequestLatencyMsMean.period + statistic = var.settings.ZooKeeperRequestLatencyMsMean.statistic + threshold = var.settings.ZooKeeperRequestLatencyMsMean.threshold + alarm_description = "Kafka:ZooKeeperRequestLatencyMsMean" + namespace = "AWS/Kafka" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.ZooKeeperRequestLatencyMsMean.action] + ok_actions = [var.settings.ZooKeeperRequestLatencyMsMean.action] + dimensions = { + "Cluster Name" = var.cluster-name + } +} + +data "aws_msk_cluster" "msk-cluster" { + cluster_name = var.cluster-name +} + +data "aws_msk_broker_nodes" "msk-broker" { + cluster_arn = data.aws_msk_cluster.msk-cluster.arn +} + +resource "aws_cloudwatch_metric_alarm" "Kafka-CpuUserSystem" { + for_each = toset([for i in data.aws_msk_broker_nodes.msk-broker.node_info_list[*].broker_id : tostring(i)]) + alarm_name = "${var.settings.CpuUserSystem.ecccode}-Kafka_${var.cluster-name}-${each.value}-CpuUsage" + comparison_operator = var.settings.CpuUserSystem.comparison_operator + evaluation_periods = var.settings.CpuUserSystem.evaluation_periods + threshold = var.settings.CpuUserSystem.threshold + alarm_description = "Kafka:ZooKeeperRequestLatencyMsMean" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.CpuUserSystem.action] + ok_actions = [var.settings.CpuUserSystem.action] + metric_query { + id = "m1" + metric { + metric_name = "CpuUser" + namespace = "AWS/Kafka" + period = var.settings.CpuUserSystem.period + stat = var.settings.CpuUserSystem.statistic + dimensions = { + "Cluster Name" = var.cluster-name + "Broker ID" = each.value + } + } + } + + metric_query { + id = "m2" + metric { + metric_name = "CpuSystem" + namespace = "AWS/Kafka" + period = var.settings.CpuUserSystem.period + stat = var.settings.CpuUserSystem.statistic + dimensions = { + "Cluster Name" = var.cluster-name + "Broker ID" = each.value + } + } + } + + metric_query { + id = "e1" + expression = "m1 + m2" + label = "CpuUserSystem" + return_data = "true" + } +} + +resource "aws_cloudwatch_metric_alarm" "Kafka-KafkaDataLogsDiskUsed" { + for_each = toset([for i in data.aws_msk_broker_nodes.msk-broker.node_info_list[*].broker_id : tostring(i)]) + alarm_name = "${var.settings.KafkaDataLogsDiskUsed.ecccode}-Kafka_${var.cluster-name}-${each.value}-KafkaDataLogsDiskUsed" + comparison_operator = var.settings.KafkaDataLogsDiskUsed.comparison_operator + evaluation_periods = var.settings.KafkaDataLogsDiskUsed.evaluation_periods + metric_name = "KafkaDataLogsDiskUsed" + period = var.settings.KafkaDataLogsDiskUsed.period + statistic = var.settings.KafkaDataLogsDiskUsed.statistic + threshold = var.settings.KafkaDataLogsDiskUsed.threshold + alarm_description = "Kafka:KafkaDataLogsDiskUsed" + namespace = "AWS/Kafka" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.KafkaDataLogsDiskUsed.action] + ok_actions = [var.settings.KafkaDataLogsDiskUsed.action] + dimensions = { + "Cluster Name" = var.cluster-name + "Broker ID" = each.value + } +} + +resource "aws_cloudwatch_metric_alarm" "Kafka-HeapMemoryAfterGC" { + for_each = toset([for i in data.aws_msk_broker_nodes.msk-broker.node_info_list[*].broker_id : tostring(i)]) + alarm_name = "${var.settings.HeapMemoryAfterGC.ecccode}-Kafka_${var.cluster-name}-${each.value}-HeapMemoryAfterGC" + comparison_operator = var.settings.HeapMemoryAfterGC.comparison_operator + evaluation_periods = var.settings.HeapMemoryAfterGC.evaluation_periods + metric_name = "HeapMemoryAfterGC" + period = var.settings.HeapMemoryAfterGC.period + statistic = var.settings.HeapMemoryAfterGC.statistic + threshold = var.settings.HeapMemoryAfterGC.threshold + alarm_description = "Kafka:HeapMemoryAfterGC" + namespace = "AWS/Kafka" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.HeapMemoryAfterGC.action] + ok_actions = [var.settings.HeapMemoryAfterGC.action] + dimensions = { + "Cluster Name" = var.cluster-name + "Broker ID" = each.value + } +} + diff --git a/modules/ManagementGovernance/Monitoring.Kafka/provider.tf b/modules/ManagementGovernance/Monitoring.Kafka/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.Kafka/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.Kafka/variables.tf b/modules/ManagementGovernance/Monitoring.Kafka/variables.tf new file mode 100644 index 0000000..45861ea --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.Kafka/variables.tf @@ -0,0 +1,4 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable cluster-name {} +variable settings {} diff --git a/modules/ManagementGovernance/Monitoring.NGW/README.md b/modules/ManagementGovernance/Monitoring.NGW/README.md new file mode 100644 index 0000000..3e7b777 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NGW/README.md @@ -0,0 +1,26 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "ngw" { + source = "../../modules/util/resource-list" + resource-type = "ngw" +} + +module "ngw-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.ngw.result-set + source = "../../modules/ManagementGovernance/Monitoring.NGW" + default-tags = local.default-tags + job-flow-id = split("/", each.value)[1] + threshold-ErrorPortAllocation = 2 + threshold-ConnectionEstablishedCount = 1000 + threshold-PacketsDropCount = 10 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.NGW/main.tf b/modules/ManagementGovernance/Monitoring.NGW/main.tf new file mode 100644 index 0000000..89d6b19 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NGW/main.tf @@ -0,0 +1,19 @@ +resource "aws_cloudwatch_metric_alarm" "ngw-alarms" { + for_each = var.settings + alarm_name = "${each.value["ecccode"]}-NGW_${var.res-id}-${each.value["metric"]}" + comparison_operator = each.value["comparison_operator"] + evaluation_periods = each.value["evaluation_periods"] + metric_name = each.value["metric"] + period = each.value["period"] + statistic = each.value["statistic"] + threshold = each.value["threshold"] + alarm_description = "NGW:${each.value["metric"]}" + namespace = "AWS/NATGateway" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [each.value["action"]] + ok_actions = [each.value["action"]] + dimensions = { + NatGatewayId = var.res-id + } +} diff --git a/modules/ManagementGovernance/Monitoring.NGW/provider.tf b/modules/ManagementGovernance/Monitoring.NGW/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NGW/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.NGW/variables.tf b/modules/ManagementGovernance/Monitoring.NGW/variables.tf new file mode 100644 index 0000000..7847a64 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NGW/variables.tf @@ -0,0 +1,4 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable res-id {} +variable settings {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.NLB/README.md b/modules/ManagementGovernance/Monitoring.NLB/README.md new file mode 100644 index 0000000..0c6f192 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NLB/README.md @@ -0,0 +1,24 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "nlb-arns" { + source = "../../modules/util/resource-list" + resource-type = "nlb" +} + +module "nlb-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.nlb-arns.result-set + source = "../../modules/ManagementGovernance/Monitoring.NLB" + default-tags = local.default-tags + load-balancer = each.value + threshold-HealthHostCountMin = 1 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.NLB/main.tf b/modules/ManagementGovernance/Monitoring.NLB/main.tf new file mode 100644 index 0000000..d98cfb4 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NLB/main.tf @@ -0,0 +1,105 @@ +/* +data "external" "nlb-targetgroups" { + program = ["bash", "${path.module}/list-nlb-targetgroups.sh"] + query = { + parameter = var.load-balancer + } +} +*/ +locals { + nlb-name = "net/${split("/", var.load-balancer)[2]}/${split("/", var.load-balancer)[3]}" +} + +resource "aws_cloudwatch_metric_alarm" "nlb-TCP_Target_Reset_Count" { + alarm_name = "${var.settings.TCP_Target_Reset_Count.ecccode}-NLB_${local.nlb-name}-TCP_Target_Reset_Count" + comparison_operator = var.settings.TCP_Target_Reset_Count.comparison_operator + evaluation_periods = var.settings.TCP_Target_Reset_Count.evaluation_periods + metric_name = "TCP_Target_Reset_Count" + period = var.settings.TCP_Target_Reset_Count.period + statistic = var.settings.TCP_Target_Reset_Count.statistic + threshold = var.settings.TCP_Target_Reset_Count.threshold + alarm_description = "NLB:TCP_Target_Reset_Count" + namespace = "AWS/NetworkELB" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.TCP_Target_Reset_Count.action] + ok_actions = [var.settings.TCP_Target_Reset_Count.action] + dimensions = { + LoadBalancer = local.nlb-name + } +} + +/* +module "nlb-targetgroups" { + source = "../../util/resource-list" + resource-type = "nlb-targetgroups" + query-input = var.load-balancer + asrolearn = var.asrolearn +} +*/ + +// causes Rate exceeded error, maybe because of adaptive AWS_RETRY_MODE? + +/* +module "nlb_tgs" { + assume_role_arn = var.asrolearn + role_session_name = "terraform-resource-list" + source = "../../util/terraform-aws-cli" + aws_cli_commands = ["elbv2", "describe-target-groups", "--load-balancer-arn", var.load-balancer] + aws_cli_query = "TargetGroups[*].TargetGroupArn" +} +*/ + +module nlb_tgs { + source = "../../util/awscli" + access_key = var.target-account-ak + aws_cli_commands = "elbv2 describe-target-groups --load-balancer-arn ${var.load-balancer} --query TargetGroups[*].TargetGroupArn" + secret_key = var.target-account-sk + session_token = var.target-account-token +} + + +resource "aws_cloudwatch_metric_alarm" "nlb-HealthyHostCount" { + # for_each = module.nlb-targetgroups.result-set + for_each = toset(module.nlb_tgs.awscliout) + alarm_name = "${var.settings.HealthHostCountMin.ecccode}-NLBTG_${split(":", each.value)[5]}-HealthyHostCount" + comparison_operator = var.settings.HealthHostCountMin.comparison_operator + evaluation_periods = var.settings.HealthHostCountMin.evaluation_periods + metric_name = "HealthyHostCount" + period = var.settings.HealthHostCountMin.period + statistic = var.settings.HealthHostCountMin.statistic + threshold = var.settings.HealthHostCountMin.threshold + alarm_description = "NLBTG:HealthyHostCount" + namespace = "AWS/NetworkELB" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.HealthHostCountMin.action] + ok_actions = [var.settings.HealthHostCountMin.action] + dimensions = { + TargetGroup = split(":", each.value)[5] + LoadBalancer = "net/${split("/", var.load-balancer)[2]}/${split("/", var.load-balancer)[3]}" + } +} + + +resource "aws_cloudwatch_metric_alarm" "nlb-UnHealthyHostCount" { + # for_each = module.nlb-targetgroups.result-set + for_each = toset(module.nlb_tgs.awscliout) + alarm_name = "${var.settings.UnHealthyHostCount.ecccode}-NLBTG_${split(":", each.value)[5]}-UnHealthyHostCount" + comparison_operator = var.settings.UnHealthyHostCount.comparison_operator + evaluation_periods = var.settings.UnHealthyHostCount.evaluation_periods + metric_name = "UnHealthyHostCount" + period = var.settings.UnHealthyHostCount.period + statistic = var.settings.UnHealthyHostCount.statistic + threshold = var.settings.UnHealthyHostCount.threshold + alarm_description = "NLBTG:UnHealthyHostCount" + namespace = "AWS/NetworkELB" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [var.settings.UnHealthyHostCount.action] + ok_actions = [var.settings.UnHealthyHostCount.action] + dimensions = { + TargetGroup = split(":", each.value)[5] + LoadBalancer = "net/${split("/", var.load-balancer)[2]}/${split("/", var.load-balancer)[3]}" + } +} diff --git a/modules/ManagementGovernance/Monitoring.NLB/outputs.tf b/modules/ManagementGovernance/Monitoring.NLB/outputs.tf new file mode 100644 index 0000000..7f36908 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NLB/outputs.tf @@ -0,0 +1,4 @@ +output nlb-tg-count { + # value = length(module.nlb-targetgroups.result-set) + value = length(flatten(module.nlb_tgs.awscliout)) +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.NLB/provider.tf b/modules/ManagementGovernance/Monitoring.NLB/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NLB/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.NLB/variables.tf b/modules/ManagementGovernance/Monitoring.NLB/variables.tf new file mode 100644 index 0000000..8762244 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.NLB/variables.tf @@ -0,0 +1,8 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable load-balancer {} +variable settings {} +# variable asrolearn {} +variable target-account-ak {} +variable target-account-sk {} +variable target-account-token {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.OpenSearch/README.md b/modules/ManagementGovernance/Monitoring.OpenSearch/README.md new file mode 100644 index 0000000..76aaa33 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.OpenSearch/README.md @@ -0,0 +1,27 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "es-domains" { + source = "../../modules/util/resource-list" + resource-type = "opensearch" +} + +module "es-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.es-domains.result-set + source = "../../modules/ManagementGovernance/Monitoring.OpenSearch" + default-tags = local.default-tags + domain-name = each.value + threshold-CPUUtilization = 90 + threshold-IndexingLatency = 3 + threshold-SearchLatency = 3 + # threshold-KibanaHealthyNodes = 1 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.OpenSearch/main.tf b/modules/ManagementGovernance/Monitoring.OpenSearch/main.tf new file mode 100644 index 0000000..ade6050 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.OpenSearch/main.tf @@ -0,0 +1,22 @@ +data "aws_caller_identity" "this" {} + +resource "aws_cloudwatch_metric_alarm" "ES-alarms" { + for_each = var.settings + alarm_name = "${each.value["ecccode"]}-ES_${var.domain-name}-${each.value["metric"]}" + comparison_operator = each.value["comparison_operator"] + evaluation_periods = each.value["evaluation_periods"] + metric_name = each.value["metric"] + period = each.value["period"] + statistic = each.value["statistic"] + threshold = each.value["threshold"] + alarm_description = "ES:${each.value["metric"]}" + namespace = "AWS/ES" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [each.value["action"]] + ok_actions = [each.value["action"]] + dimensions = { + DomainName = var.domain-name + ClientId = data.aws_caller_identity.this.id + } +} diff --git a/modules/ManagementGovernance/Monitoring.OpenSearch/provider.tf b/modules/ManagementGovernance/Monitoring.OpenSearch/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.OpenSearch/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.OpenSearch/variables.tf b/modules/ManagementGovernance/Monitoring.OpenSearch/variables.tf new file mode 100644 index 0000000..e41ff5c --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.OpenSearch/variables.tf @@ -0,0 +1,4 @@ +variable "cw-alarm-prefix" {} +variable "actions-enabled" {} +variable "domain-name" {} +variable "settings" {} diff --git a/modules/ManagementGovernance/Monitoring.RDS/README.md b/modules/ManagementGovernance/Monitoring.RDS/README.md new file mode 100644 index 0000000..60a3027 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.RDS/README.md @@ -0,0 +1,31 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. +AWS provider 4.47.0 or above is needed for datasource aws_db_instances (https://github.com/hashicorp/terraform-provider-aws/blob/main/CHANGELOG.md) + +## Example +```terraform +module "rds-instances" { + source = "../../modules/util/resource-list" + resource-type = "rds" +} + +module "rds-monitoring" { + # for_each = toset(var.rds-instance-ids) + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.rds-instances.result-set + source = "../../modules/ManagementGovernance/Monitoring.RDS" + default-tags = local.default-tags + rds-instance-name = each.value + threshold-CpuUtilization = 90 + threshold-FreeableMemory = 512 * 1024 * 1024 + threshold-FreeStorageSpace = 5 * 1024 * 1024 * 1024 + threshold-DiskQueueDepth = 30 + threshold-ReadLatency = 0.03 + threshold-WriteLatency = 0.03 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.RDS/main.tf b/modules/ManagementGovernance/Monitoring.RDS/main.tf new file mode 100644 index 0000000..1fd7e53 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.RDS/main.tf @@ -0,0 +1,19 @@ +resource "aws_cloudwatch_metric_alarm" "rds-alarms" { + for_each = var.settings + alarm_name = "${each.value["ecccode"]}-RDS_${var.rds-instance-name}-${each.value["metric"]}" + comparison_operator = each.value["comparison_operator"] + evaluation_periods = each.value["evaluation_periods"] + metric_name = each.value["metric"] + period = each.value["period"] + statistic = each.value["statistic"] + threshold = each.value["threshold"] + alarm_description = "RDS:${each.value["metric"]}" + namespace = "AWS/RDS" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [each.value["action"]] + ok_actions = [each.value["action"]] + dimensions = { + DBInstanceIdentifier = var.rds-instance-name + } +} diff --git a/modules/ManagementGovernance/Monitoring.RDS/provider.tf b/modules/ManagementGovernance/Monitoring.RDS/provider.tf new file mode 100644 index 0000000..9b051fa --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.RDS/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.47.0" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.RDS/variables.tf b/modules/ManagementGovernance/Monitoring.RDS/variables.tf new file mode 100644 index 0000000..0652b1f --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.RDS/variables.tf @@ -0,0 +1,4 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable rds-instance-name {} +variable settings {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.Redis/README.md b/modules/ManagementGovernance/Monitoring.Redis/README.md new file mode 100644 index 0000000..ebc9052 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.Redis/README.md @@ -0,0 +1,26 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "redis-instances" { + source = "../../modules/util/resource-list" + resource-type = "redis" +} + +module "redis-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.redis-instances.result-set + source = "../../modules/ManagementGovernance/Monitoring.Redis" + default-tags = local.default-tags + redis-cluster-id = each.value + threshold-EngineCPUUtilization = 90 + threshold-DatabaseMemoryUsagePercentage = 90 + threshold-CacheHitRate = 3 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.Redis/main.tf b/modules/ManagementGovernance/Monitoring.Redis/main.tf new file mode 100644 index 0000000..85b4be9 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.Redis/main.tf @@ -0,0 +1,21 @@ +resource "aws_cloudwatch_metric_alarm" "redis-alarms" { + for_each = var.settings + alarm_name = "${each.value["ecccode"]}-Redis_${var.redis-cluster-id}-${each.value["metric"]}" + comparison_operator = each.value["comparison_operator"] + evaluation_periods = each.value["evaluation_periods"] + metric_name = each.value["metric"] + period = each.value["period"] + statistic = each.value["statistic"] + threshold = each.value["threshold"] + alarm_description = "ElastiCache:${each.value["metric"]}" + namespace = "AWS/ElastiCache" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [each.value["action"]] + ok_actions = [each.value["action"]] + treat_missing_data = "notBreaching" + dimensions = { + CacheClusterId = var.redis-cluster-id + } + +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.Redis/provider.tf b/modules/ManagementGovernance/Monitoring.Redis/provider.tf new file mode 100644 index 0000000..933a1eb --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.Redis/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.36.1" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.Redis/variables.tf b/modules/ManagementGovernance/Monitoring.Redis/variables.tf new file mode 100644 index 0000000..520ab62 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.Redis/variables.tf @@ -0,0 +1,4 @@ +variable "cw-alarm-prefix" {} +variable "actions-enabled" {} +variable "redis-cluster-id" {} +variable "settings" {} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.TGW/README.md b/modules/ManagementGovernance/Monitoring.TGW/README.md new file mode 100644 index 0000000..6ad5506 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.TGW/README.md @@ -0,0 +1,24 @@ +# Monitoring module +This module deploys the default cloudwatch metric monitoring + +## Notes +Terraform lifecycle ignores tags to speed up terraform subsequent update. Cloudwatch alarm tags cannot be read on aws console anyway. + +## Example +```terraform +module "tgw" { + source = "../../modules/util/resource-list" + resource-type = "tgw" +} + +module "tgw-monitoring" { + cw-alarm-prefix = local.cw-alarm-prefix + for_each = module.tgw.result-set + source = "../../modules/ManagementGovernance/Monitoring.TGW" + default-tags = local.default-tags + job-flow-id = split("/", each.value)[1] + threshold-PacketDropCountNoRoute = 1 + actions-enabled = var.actions-enabled + sns-targets = var.sns-targets +} +``` \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.TGW/main.tf b/modules/ManagementGovernance/Monitoring.TGW/main.tf new file mode 100644 index 0000000..b2b3c12 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.TGW/main.tf @@ -0,0 +1,19 @@ +resource "aws_cloudwatch_metric_alarm" "tgw-PacketDropCountNoRoute" { + for_each = var.settings + alarm_name = "${each.value["ecccode"]}-TGW_${var.tgw-id}-PacketDropCountNoRoute" + comparison_operator = each.value["comparison_operator"] + evaluation_periods = each.value["evaluation_periods"] + metric_name = each.value["metric"] + period = each.value["period"] + statistic = each.value["statistic"] + threshold = each.value["threshold"] + alarm_description = "TGW:${each.value["metric"]}" + namespace = "AWS/TransitGateway" + insufficient_data_actions = [] + actions_enabled = var.actions-enabled + alarm_actions = [each.value["action"]] + ok_actions = [each.value["action"]] + dimensions = { + TransitGateway = var.tgw-id + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/Monitoring.TGW/provider.tf b/modules/ManagementGovernance/Monitoring.TGW/provider.tf new file mode 100644 index 0000000..9b051fa --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.TGW/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.47.0" + } + } +} diff --git a/modules/ManagementGovernance/Monitoring.TGW/variables.tf b/modules/ManagementGovernance/Monitoring.TGW/variables.tf new file mode 100644 index 0000000..6624936 --- /dev/null +++ b/modules/ManagementGovernance/Monitoring.TGW/variables.tf @@ -0,0 +1,4 @@ +variable cw-alarm-prefix {} +variable actions-enabled {} +variable tgw-id {} +variable settings {} \ No newline at end of file diff --git a/modules/ManagementGovernance/SnsTopicEmailSubscription/README.md b/modules/ManagementGovernance/SnsTopicEmailSubscription/README.md new file mode 100644 index 0000000..eabf084 --- /dev/null +++ b/modules/ManagementGovernance/SnsTopicEmailSubscription/README.md @@ -0,0 +1,47 @@ + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_sns_topic.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sns_topic) | resource | +| [aws_sns_topic_subscription.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sns_topic_subscription) | resource | +| [aws_caller_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | +| [aws_region.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/region) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| email-addresses | Email recipients of SNS notifications | `set(string)` | n/a | yes | +| kms-key-id | KMS key id for SNS topic at-rest encryption. Make sure the sender has access to this key | `string` | n/a | yes | +| sender | ARN of SNS sender or sending service name | `string` | n/a | yes | +| sender-type | Sender principal type. Value should be either *AWS* or *Service* | `string` | n/a | yes | +| sns-topic-description | SNS topic display name | `string` | n/a | yes | +| sns-topic-name | Name of SNS topic | `string` | n/a | yes | + +## Outputs + +| Name | Description | +|------|-------------| +| sns-topic-arn | n/a | + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/ManagementGovernance/SnsTopicEmailSubscription/main.tf b/modules/ManagementGovernance/SnsTopicEmailSubscription/main.tf new file mode 100644 index 0000000..4746cb3 --- /dev/null +++ b/modules/ManagementGovernance/SnsTopicEmailSubscription/main.tf @@ -0,0 +1,69 @@ +data "aws_caller_identity" "this" {} +data "aws_region" "this" {} + +resource "aws_sns_topic" "this" { + name = var.sns-topic-name + display_name = var.sns-topic-description + kms_master_key_id = var.kms-key-id + policy = jsonencode( + { + "Version" : "2008-10-17", + "Id" : "SnsTopicPolicy", + "Statement" : [ + { + "Sid" : "SnsTopicAdmin", + "Effect" : "Allow", + "Principal" : { + "AWS" : data.aws_caller_identity.this.account_id + }, + "Action" : [ + "SNS:GetTopicAttributes", + "SNS:SetTopicAttributes", + "SNS:AddPermission", + "SNS:RemovePermission", + "SNS:DeleteTopic", + "SNS:Subscribe", + "SNS:ListSubscriptionsByTopic", + "SNS:Publish", + "SNS:Receive" + ], + "Resource" : "arn:aws:sns:${data.aws_region.this.name}:${data.aws_caller_identity.this.account_id}:${var.sns-topic-name}", + "Condition" : { + "StringEquals" : { + "AWS:SourceOwner" : data.aws_caller_identity.this.account_id + } + } + }, + { + "Sid" : "AllowPublishing", + "Effect" : "Allow", + "Principal" : { + "${var.sender-type}" : var.sender + }, + "Action" : "sns:Publish", + "Resource" : "arn:aws:sns:${data.aws_region.this.name}:${data.aws_caller_identity.this.account_id}:${var.sns-topic-name}" + }, + { + "Sid" : "AllowPublishThroughSSLOnly", + "Action" : "SNS:Publish", + "Effect" : "Deny", + "Resource" : "arn:aws:sns:${data.aws_region.this.name}:${data.aws_caller_identity.this.account_id}:${var.sns-topic-name}", + "Condition" : { + "Bool" : { + "aws:SecureTransport" : "false" + } + }, + "Principal" : "*" + } + ] + } + ) +} + +resource "aws_sns_topic_subscription" "this" { + for_each = var.email-addresses + topic_arn = aws_sns_topic.this.arn + protocol = "email" + endpoint = each.value +} + diff --git a/modules/ManagementGovernance/SnsTopicEmailSubscription/outputs.tf b/modules/ManagementGovernance/SnsTopicEmailSubscription/outputs.tf new file mode 100644 index 0000000..7f2eed8 --- /dev/null +++ b/modules/ManagementGovernance/SnsTopicEmailSubscription/outputs.tf @@ -0,0 +1,3 @@ +output "sns-topic-arn" { + value = aws_sns_topic.this.arn +} \ No newline at end of file diff --git a/modules/ManagementGovernance/SnsTopicEmailSubscription/variables.tf b/modules/ManagementGovernance/SnsTopicEmailSubscription/variables.tf new file mode 100644 index 0000000..07f32f2 --- /dev/null +++ b/modules/ManagementGovernance/SnsTopicEmailSubscription/variables.tf @@ -0,0 +1,33 @@ +variable "sender" { + type = string + description = "ARN of SNS sender or sending service name" +} + +variable "sender-type" { + type = string + description = "Sender principal type. Value should be either *AWS* or *Service*" + validation { + condition = var.sender-type == "AWS" || var.sender-type == "Service" + error_message = "Valid values are AWS or Service" + } +} + +variable "sns-topic-name" { + type = string + description = "Name of SNS topic" +} + +variable "sns-topic-description" { + type = string + description = "SNS topic display name" +} + +variable "kms-key-id" { + type = string + description = "KMS key id for SNS topic at-rest encryption. Make sure the sender has access to this key" +} + +variable "email-addresses" { + type = set(string) + description = "Email recipients of SNS notifications" +} \ No newline at end of file diff --git a/modules/ManagementGovernance/SnsTopicEmailSubscription/versions.tf b/modules/ManagementGovernance/SnsTopicEmailSubscription/versions.tf new file mode 100644 index 0000000..ceb041e --- /dev/null +++ b/modules/ManagementGovernance/SnsTopicEmailSubscription/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/acm-cert-expiry-notice/README.md b/modules/ManagementGovernance/acm-cert-expiry-notice/README.md new file mode 100644 index 0000000..8534c90 --- /dev/null +++ b/modules/ManagementGovernance/acm-cert-expiry-notice/README.md @@ -0,0 +1,101 @@ +ACM sends daily expiration events for all active certificates (public, private and imported) starting 45 days prior to expiration [1]. +This module sets up event rule and sns notification. Deliver email notifications for expiring certificates, useful for imported certificates. + +## Notes +* DaysToExpiry cannot be greater than 45 + +```bash +❯ aws acm put-account-configuration --idempotency-token abcd123456 --expiry-events DaysBeforeExpiry=46 --region=ap-east-1 + +An error occurred (ValidationException) when calling the PutAccountConfiguration operation: Days before expiry cannot be over 45. +``` +* KMS key for SNS must allow events.amazonaws.com. Check that this statement is present in the KMS key policy. Otherwise you will get FailedInvocation in event rule graph and there is no other debug info. The default alias/aws/sns managed key does not allow encryption / decryption from cloudwatch or events [2]. +```json +{ +"Sid": "Allow publish from events", +"Effect": "Allow", +"Principal": { +"Service": "events.amazonaws.com" +}, +"Action": [ +"kms:Encrypt", +"kms:Decrypt", +"kms:ReEncrypt*", +"kms:GenerateDataKey*", +"kms:DescribeKey" +], +"Resource": "*" +} +``` +[1] https://docs.aws.amazon.com/acm/latest/userguide/supported-events.html +[2] https://docs.gruntwork.io/discussions/knowledge-base/238/ + +## Sample Event bridge event +```json +{ + "version": "0", + "id": "id", + "detail-type": "ACM Certificate Approaching Expiration", + "source": "aws.acm", + "account": "account", + "time": "2020-09-30T06:51:08Z", + "region": "region", + "resources": [ + "arn:aws:acm:region:account:certificate/certificate_ID" + ], + "detail": { + "DaysToExpiry": 31, + "CommonName": "example.com" + } +} +``` + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | +| random | n/a | + +## Modules + +| Name | Source | Version | +|------|--------|---------| +| awscli | ../../util/terraform-aws-cli | n/a | + +## Resources + +| Name | Type | +|------|------| +| [aws_cloudwatch_event_rule.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_event_rule) | resource | +| [aws_cloudwatch_event_target.sns](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_event_target) | resource | +| [aws_sns_topic.ssl-cert-expiry-notice](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sns_topic) | resource | +| [aws_sns_topic_policy.default](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sns_topic_policy) | resource | +| [aws_sns_topic_subscription.ssl-cert-expiry-notice-sub](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/sns_topic_subscription) | resource | +| [random_id.this](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/id) | resource | +| [aws_caller_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | +| [aws_iam_policy_document.sns_topic_policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_policy_document) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|----------------------------------------------------------------------------------|------|---------|:--------:| +| days-before-expiry | ACM DaysBeforeExpiry account configuration | `number` | `45` | no | +| email-addresses | Set of email addresses to receive SNS notifications | `set(string)` | n/a | yes | +| res-prefix | Resource name prefix | `string` | `"aws"` | no | +| sns-kms-key-arn | ARN of KMS key used for SNS encryption. This key must allow events.amazonaws.com | `string` | `null` | no | + +## Outputs + +No outputs. + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/ManagementGovernance/acm-cert-expiry-notice/examples/main.tf b/modules/ManagementGovernance/acm-cert-expiry-notice/examples/main.tf new file mode 100644 index 0000000..6a5d601 --- /dev/null +++ b/modules/ManagementGovernance/acm-cert-expiry-notice/examples/main.tf @@ -0,0 +1,6 @@ +module "acm-cert-expiry-notice" { + source = "../../modules/ManagementGovernance/acm-cert-expiry-notice" + email-addresses = var.email-addresses + days-before-expiry = var.days-before-expiry + res-prefix = var.res-prefix +} \ No newline at end of file diff --git a/modules/ManagementGovernance/acm-cert-expiry-notice/main.tf b/modules/ManagementGovernance/acm-cert-expiry-notice/main.tf new file mode 100644 index 0000000..63cfa31 --- /dev/null +++ b/modules/ManagementGovernance/acm-cert-expiry-notice/main.tf @@ -0,0 +1,98 @@ +data "aws_caller_identity" "this" {} + +resource "random_id" "this" { + byte_length = 2 +} + +resource "aws_cloudwatch_event_rule" "this" { + name = "${var.res-prefix}-ssl-cert-expiry-${random_id.this.dec}" + description = "Reminder of SSL expiring certificates" + + event_pattern = jsonencode({ + "source" : ["aws.acm"], + "detail-type" : ["ACM Certificate Approaching Expiration"] + }) +} + +resource "aws_cloudwatch_event_target" "sns" { + rule = aws_cloudwatch_event_rule.this.name + target_id = "ssl-cert-expiry-sns-${random_id.this.dec}" + arn = aws_sns_topic.ssl-cert-expiry-notice.arn + input_transformer { + input_paths = { + "cert" : "$.resources[0]", + "days" : "$.detail.DaysToExpiry", + "cn" : "$.detail.CommonName" + } + input_template = <<-EOT + "The following ACM certificate will expire soon" + + "ID: " + "CommonName: " + "Days to expiry: " + EOT + } +} + +# Modify ACM DaysBeforeExpiry account setting if it should be set lower than the default 45 days +module "awscli" { + count = var.days-before-expiry < 45 ? 1 : 0 + source = "../../util/terraform-aws-cli" + + role_session_name = "terraform-awscli" + aws_cli_commands = ["acm", "put-account-configuration", "--idempotency-token", random_id.this.dec, "--expiry-events DaysBeforeExpiry=${var.days-before-expiry}"] +} + +# SNS topic and subscription +resource "aws_sns_topic" "ssl-cert-expiry-notice" { + name = "${var.res-prefix}-ssl-cert-expiry-notice-${random_id.this.dec}" + kms_master_key_id = var.sns-kms-key-arn +} + +resource "aws_sns_topic_policy" "default" { + arn = aws_sns_topic.ssl-cert-expiry-notice.arn + policy = data.aws_iam_policy_document.sns_topic_policy.json +} + +data "aws_iam_policy_document" "sns_topic_policy" { + statement { + sid = "AllowPublishingFromEvents" + effect = "Allow" + actions = [ + "sns:Publish", + "SNS:Publish" + ] + + principals { + type = "Service" + identifiers = ["events.amazonaws.com"] + } + + resources = [aws_sns_topic.ssl-cert-expiry-notice.arn] + } + statement { + sid = "AllowPublishThroughSSLOnly" + effect = "Deny" + principals { + identifiers = ["*"] + type = "AWS" + } + actions = [ + "sns:Publish", + "SNS:Publish" + ] + condition { + test = "Bool" + values = ["false"] + variable = "aws:SecureTransport" + } + resources = [aws_sns_topic.ssl-cert-expiry-notice.arn] + } +} + +resource "aws_sns_topic_subscription" "ssl-cert-expiry-notice-sub" { + for_each = var.email-addresses + topic_arn = aws_sns_topic.ssl-cert-expiry-notice.arn + protocol = "email" + endpoint = each.value +} diff --git a/modules/ManagementGovernance/acm-cert-expiry-notice/variables.tf b/modules/ManagementGovernance/acm-cert-expiry-notice/variables.tf new file mode 100644 index 0000000..13a63ec --- /dev/null +++ b/modules/ManagementGovernance/acm-cert-expiry-notice/variables.tf @@ -0,0 +1,22 @@ +variable "email-addresses" { + type = set(string) + description = "Set of email addresses to receive SNS notifications" +} + +variable "days-before-expiry" { + type = number + description = "ACM DaysBeforeExpiry account configuration" + default = 45 +} + +variable "res-prefix" { + type = string + description = "Resource name prefix" + default = "aws" +} + +variable "sns-kms-key-arn" { + type = string + description = "ARN of KMS key used for SNS encryption. This key must allow events.amazonaws.com" + default = null +} \ No newline at end of file diff --git a/modules/ManagementGovernance/acm-cert-expiry-notice/versions.tf b/modules/ManagementGovernance/acm-cert-expiry-notice/versions.tf new file mode 100644 index 0000000..ceb041e --- /dev/null +++ b/modules/ManagementGovernance/acm-cert-expiry-notice/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} \ No newline at end of file diff --git a/modules/ManagementGovernance/ssm-schedule-run-command/README.md b/modules/ManagementGovernance/ssm-schedule-run-command/README.md new file mode 100644 index 0000000..4da96b2 --- /dev/null +++ b/modules/ManagementGovernance/ssm-schedule-run-command/README.md @@ -0,0 +1,44 @@ + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_cloudwatch_log_group.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_log_group) | resource | +| [aws_ssm_maintenance_window.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ssm_maintenance_window) | resource | +| [aws_ssm_maintenance_window_target.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ssm_maintenance_window_target) | resource | +| [aws_ssm_maintenance_window_task.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ssm_maintenance_window_task) | resource | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| cron-expression | Cron expression for SSM maintenance window schedule | `string` | n/a | yes | +| description | Description of command to run | `string` | n/a | yes | +| instance-id | Id of Ec2 instance to execute the script | `string` | n/a | yes | +| schedule-name | Name of maintenance window. e.g. Daily0900UTC8 | `string` | n/a | yes | +| shell-script-path | Full path to script | `string` | n/a | yes | + +## Outputs + +No outputs. + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/ManagementGovernance/ssm-schedule-run-command/main.tf b/modules/ManagementGovernance/ssm-schedule-run-command/main.tf new file mode 100644 index 0000000..7604ff6 --- /dev/null +++ b/modules/ManagementGovernance/ssm-schedule-run-command/main.tf @@ -0,0 +1,80 @@ +# SSM run command +#resource "aws_ssm_document" "this" { +# name = replace(title(var.description), " ", "") +# document_type = "Command" +# target_type = "/AWS::EC2::Instance" +# content = jsonencode( +# { +# "schemaVersion" : "2.2", +# "description" : "Run script for ${var.description}", +# "parameters" : { +# }, +# "mainSteps" : [ +# { +# "action" : "aws:runShellScript", +# "name" : "RunShellScript", +# "inputs" : { +# "runCommand" : var.shell-script-path +# } +# } +# ] +# } +# ) +#} + +resource "aws_ssm_maintenance_window" "this" { + name = replace(title(var.description), " ", "") + description = var.description + schedule = var.cron-expression + duration = var.maintenance-window-duration + cutoff = 1 +} + +resource "aws_ssm_maintenance_window_target" "this" { + window_id = aws_ssm_maintenance_window.this.id + name = replace(title(var.description), " ", "") + description = var.description + resource_type = "INSTANCE" + + targets { + key = "InstanceIds" + values = [var.instance-id] + } +} + +resource "aws_ssm_maintenance_window_task" "this" { + name = replace(title(var.description), " ", "") + max_concurrency = 1 + max_errors = 1 + priority = 1 + task_arn = "AWS-RunShellScript" + task_type = "RUN_COMMAND" + window_id = aws_ssm_maintenance_window.this.id + + targets { + key = "InstanceIds" + values = [var.instance-id] + } + + task_invocation_parameters { + run_command_parameters { + timeout_seconds = 60 # If this time is reached and the command has not already started executing, it doesn't run. + + cloudwatch_config { + cloudwatch_log_group_name = aws_cloudwatch_log_group.this.name + cloudwatch_output_enabled = true + } + + parameter { + name = "commands" + values = [var.shell-script-path] + } + } + } +} + +resource "aws_cloudwatch_log_group" "this" { + name = "/aws/ssm-maintenance/${replace(title(var.description), " ", "")}" + retention_in_days = var.cloudwatch-log-retention-days + log_group_class = "STANDARD" # infrequent access logs can only be viewed via insight +} \ No newline at end of file diff --git a/modules/ManagementGovernance/ssm-schedule-run-command/variables.tf b/modules/ManagementGovernance/ssm-schedule-run-command/variables.tf new file mode 100644 index 0000000..0513c03 --- /dev/null +++ b/modules/ManagementGovernance/ssm-schedule-run-command/variables.tf @@ -0,0 +1,36 @@ +variable shell-script-path { + type = string + description = "Full path to script" +} + +variable cron-expression { + type = string + description = "Cron expression for SSM maintenance window schedule" +} + +variable instance-id { + type = string + description = "Id of Ec2 instance to execute the script" +} + +variable description { + type = string + description = "Description of command to run" +} + +variable schedule-name { + type = string + description = "Name of maintenance window. e.g. Daily0900UTC8" +} + +variable maintenance-window-duration { + type = number + description = "Duration of maintenance window, must be >= 2" + default = 2 +} + +variable cloudwatch-log-retention-days { + type = number + description = "Days to retain logs on cloudwatch logs" + default = 30 +} \ No newline at end of file diff --git a/modules/ManagementGovernance/ssm-schedule-run-command/versions.tf b/modules/ManagementGovernance/ssm-schedule-run-command/versions.tf new file mode 100644 index 0000000..ceb041e --- /dev/null +++ b/modules/ManagementGovernance/ssm-schedule-run-command/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} \ No newline at end of file diff --git a/modules/compute/ec2-instance-scheduler/Ec2Scheduler.py b/modules/compute/ec2-instance-scheduler/Ec2Scheduler.py new file mode 100644 index 0000000..819bd07 --- /dev/null +++ b/modules/compute/ec2-instance-scheduler/Ec2Scheduler.py @@ -0,0 +1,16 @@ +import boto3 +import os +import json + +# reference: https://aws.amazon.com/premiumsupport/knowledge-center/start-stop-lambda-eventbridge/ + +ec2 = boto3.client('ec2', region_name=os.environ['AWS_REGION']) + +def lambda_handler(event, context): + if event['action'] == 'start': + resp = ec2.start_instances(InstanceIds=json.loads(os.environ['instances'])) + elif event['action'] == 'stop': + resp = ec2.stop_instances(InstanceIds=json.loads(os.environ['instances'])) + else: + resp = "Event action not provided" + return resp diff --git a/modules/compute/ec2-instance-scheduler/README.md b/modules/compute/ec2-instance-scheduler/README.md new file mode 100644 index 0000000..5e8b733 --- /dev/null +++ b/modules/compute/ec2-instance-scheduler/README.md @@ -0,0 +1,52 @@ + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| archive | n/a | +| aws | >= 5.0 | +| random | n/a | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_iam_role.eventscheduler](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_iam_role.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_iam_role_policy.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy) | resource | +| [aws_iam_role_policy_attachment.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy_attachment) | resource | +| [aws_lambda_function.ec2-start-stop](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_function) | resource | +| [aws_lambda_permission.lambda_permission](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lambda_permission) | resource | +| [aws_scheduler_schedule.start](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/scheduler_schedule) | resource | +| [aws_scheduler_schedule.stop](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/scheduler_schedule) | resource | +| [random_id.this](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/id) | resource | +| [archive_file.lambda-package](https://registry.terraform.io/providers/hashicorp/archive/latest/docs/data-sources/file) | data source | +| [aws_caller_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| description | A description of instances to be started/stopped on schedule | `string` | n/a | yes | +| instance-ids | Instances to be automatically started/stopped on schedule | `list(string)` | n/a | yes | +| instance-start-cron-expression | Cron expression for instance start schedule | `string` | n/a | yes | +| instance-stop-cron-expression | Cron expression for instance stop schedule | `string` | n/a | yes | + +## Outputs + +No outputs. + +--- +## Authorship +This module was developed by UPDATE_THIS. \ No newline at end of file diff --git a/modules/compute/ec2-instance-scheduler/main.tf b/modules/compute/ec2-instance-scheduler/main.tf new file mode 100644 index 0000000..e4d53cc --- /dev/null +++ b/modules/compute/ec2-instance-scheduler/main.tf @@ -0,0 +1,203 @@ +data "aws_caller_identity" "this" {} + +resource "random_id" "this" { + byte_length = 4 +} + +resource "aws_iam_role" "eventscheduler" { + name = "EventSchedulerRole-${random_id.this.dec}" + assume_role_policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "scheduler.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) +} + +resource "aws_iam_role_policy_attachment" "default" { + policy_arn = "arn:aws:iam::aws:policy/AmazonEventBridgeSchedulerFullAccess" + role = aws_iam_role.eventscheduler.name +} + +resource "aws_iam_role" "this" { + name = "lambda-startstop-ec2-${var.description}" + + assume_role_policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : "lambda.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) +} + +resource "aws_iam_role_policy" "this" { + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Sid" : "AllowCreationOfCloudwatchLogGroup", + "Effect" : "Allow", + "Action" : "logs:CreateLogGroup", + "Resource" : "arn:aws:logs:ap-east-1:${data.aws_caller_identity.this.account_id}:*" + }, + { + "Sid" : "AllowWritingToCloudwatchLogGroup", + "Effect" : "Allow", + "Action" : [ + "logs:CreateLogStream", + "logs:PutLogEvents" + ], + "Resource" : [ + "arn:aws:logs:ap-east-1:${data.aws_caller_identity.this.account_id}:log-group:/aws/lambda/*" + ] + }, + { + "Sid" : "AllowStartingStoppingOfEc2Instance", + "Action" : [ + "ec2:StopInstances", + "ec2:StartInstances", + "kms:CreateGrant" + ], + "Effect" : "Allow", + "Resource" : "*" + } + ] + } + ) + role = aws_iam_role.this.id + name = "LambdaExecutionPolicy" +} + +resource "aws_iam_role_policy" "eventscheduler" { + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Sid" : "AllowInvocationOfLambdaFunction", + "Effect" : "Allow", + "Action" : "lambda:InvokeFunction", + "Resource" : "*" + } + ] + } + ) + role = aws_iam_role.eventscheduler.id + name = "LambdaInvocation" +} + +resource "aws_scheduler_schedule" "start" { + name = "scheduled-start-of-${var.description}-instances" + description = "Starts ${var.description} ec2 instance" + flexible_time_window { + mode = "OFF" + } + + schedule_expression = var.instance-start-cron-expression + + target { + arn = aws_lambda_function.ec2-start-stop.arn + role_arn = aws_iam_role.eventscheduler.arn + input = jsonencode({ "action" : "start" }) + retry_policy { + maximum_event_age_in_seconds = 600 + maximum_retry_attempts = 1 + } + } + +} + +resource "aws_scheduler_schedule" "stop" { + name = "scheduled-stop-of-${var.description}-instances" + description = "Stops ${var.description} ec2 instance" + flexible_time_window { + mode = "OFF" + } + + schedule_expression = var.instance-stop-cron-expression + + target { + arn = aws_lambda_function.ec2-start-stop.arn + role_arn = aws_iam_role.eventscheduler.arn + input = jsonencode({ "action" : "stop" }) + retry_policy { + maximum_event_age_in_seconds = 600 + maximum_retry_attempts = 1 + } + } +} +# +#resource "aws_cloudwatch_event_rule" "start" { +# name = "scheduled-start-of-${var.description}-instances" +# description = "Starts automation ec2 instance" +# schedule_expression = var.instance-start-cron-expression +#} +# +#resource "aws_cloudwatch_event_rule" "stop" { +# name = "scheduled-stop-of-${var.description}-instances" +# description = "Stops automation ec2 instance" +# schedule_expression = var.instance-stop-cron-expression +#} +# +#resource "aws_cloudwatch_event_target" "start" { +# rule = aws_cloudwatch_event_rule.start.name +# arn = aws_lambda_function.ec2-start-stop.arn +# input = "{\"action\": \"start\"}" +#} +# +#resource "aws_cloudwatch_event_target" "stop" { +# rule = aws_cloudwatch_event_rule.stop.name +# arn = aws_lambda_function.ec2-start-stop.arn +# input = "{\"action\": \"stop\"}" +#} + +# Lambda function for instance scheduler +data "archive_file" "lambda-package" { + type = "zip" + source_file = "${path.module}/Ec2Scheduler.py" + output_path = "lambda-package.zip" +} + +resource "aws_lambda_function" "ec2-start-stop" { + function_name = "${var.description}-ec2-start-stop" + filename = data.archive_file.lambda-package.output_path + source_code_hash = data.archive_file.lambda-package.output_base64sha256 + handler = "Ec2Scheduler.lambda_handler" + runtime = "python3.12" + role = aws_iam_role.this.arn + timeout = 30 + environment { + variables = { + instances = jsonencode(var.instance-ids) + } + } +} + +resource "aws_lambda_permission" "lambda_permission" { + statement_id = "AllowCloudWatchToInvokeLambda" + action = "lambda:InvokeFunction" + function_name = aws_lambda_function.ec2-start-stop.function_name + principal = "events.amazonaws.com" +} + +resource "aws_cloudwatch_log_group" "this" { + name = "/aws/lambda/${var.description}-ec2-start-stop" + retention_in_days = var.cloudwatchlog-retention +} \ No newline at end of file diff --git a/modules/compute/ec2-instance-scheduler/variables.tf b/modules/compute/ec2-instance-scheduler/variables.tf new file mode 100644 index 0000000..80e7aa7 --- /dev/null +++ b/modules/compute/ec2-instance-scheduler/variables.tf @@ -0,0 +1,25 @@ +variable "instance-start-cron-expression" { + type = string + description = "Cron expression for instance start schedule" +} + +variable "instance-stop-cron-expression" { + type = string + description = "Cron expression for instance stop schedule" +} + +variable "instance-ids" { + type = list(string) + description = "Instances to be automatically started/stopped on schedule" +} + +variable "description" { + type = string + description = "A description of instances to be started/stopped on schedule" +} + +variable "cloudwatchlog-retention" { + type = number + description = "Cloudwatch log retention days" + default = 30 +} \ No newline at end of file diff --git a/modules/compute/ec2-instance-scheduler/versions.tf b/modules/compute/ec2-instance-scheduler/versions.tf new file mode 100644 index 0000000..cd63239 --- /dev/null +++ b/modules/compute/ec2-instance-scheduler/versions.tf @@ -0,0 +1,13 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + + archive = { + source = "hashicorp/archive" + } + } +} \ No newline at end of file diff --git a/modules/compute/ec2/README.md b/modules/compute/ec2/README.md new file mode 100644 index 0000000..0caa147 --- /dev/null +++ b/modules/compute/ec2/README.md @@ -0,0 +1,78 @@ + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | ~> 5.35.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | ~> 5.35.0 | +| random | n/a | +| tls | n/a | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_ebs_volume.data-volumes](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_volume) | resource | +| [aws_eip.ec2-eip](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eip) | resource | +| [aws_instance.ec2-instance](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/instance) | resource | +| [aws_key_pair.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/key_pair) | resource | +| [aws_secretsmanager_secret.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/secretsmanager_secret) | resource | +| [aws_secretsmanager_secret_version.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/secretsmanager_secret_version) | resource | +| [aws_volume_attachment.data-volume-attachments](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/volume_attachment) | resource | +| [random_id.this](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/id) | resource | +| [tls_private_key.this](https://registry.terraform.io/providers/hashicorp/tls/latest/docs/resources/private_key) | resource | +| [aws_default_tags.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/default_tags) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| additional-tags | Additional tags to be assigned on top of provider default tags. Useful for setting backup tags. | `map(string)` | n/a | yes | +| ami-id | Image id of EC2 instance | `string` | n/a | yes | +| asso-eip | Whether to associate Elastic IP | `bool` | n/a | yes | +| asso-public-ip | Whether to associate ephemeral public IP | `bool` | n/a | yes | +| create-ssh-key | Set true to create ssh key and store on secret manager | `bool` | `false` | no | +| data-volumes | Attach additional data volumes |
map(object({
size = number
type = string
}))
| n/a | yes | +| delete-on-termination | Whether to delete volumes on termination | `bool` | `true` | no | +| disable\_secure\_idmsv2 | If set to true, the insecure IDMSv1 will be used. | `bool` | `false` | no | +| ebs-encrypted | Whether to enable EBS encryption | `bool` | `true` | no | +| enable-detail-monitoring | Set true to enable detail monitoring | `bool` | `false` | no | +| enable-termination-protection | Whether to enable prevent accidential deletion of instance | `bool` | `false` | no | +| instance-name | Name of ec2 instance | `string` | n/a | yes | +| instance-profile | Ec2 instance profile name | `string` | `""` | no | +| instance-type | Instance type | `string` | n/a | yes | +| key-name | Instance ssh key name | `string` | `""` | no | +| kms-key-id | Disk encryption KMS key id | `string` | n/a | yes | +| private-ip | Specify private IP to be used on this instance | `string` | `null` | no | +| root-volume-size | Size of root volume | `number` | n/a | yes | +| root-volume-type | Root volume type | `string` | `"gp3"` | no | +| security-groups | List of security groups for Ec2 instance | `list(string)` | n/a | yes | +| spot-max-price | Max hourly price for spot instance. If greater than zero, spot instance will be used. | `number` | `0` | no | +| subnet-id | Id of subnet to deploy Ec2 instance to | `string` | n/a | yes | +| user-data | Ec2 user-data | `string` | `""` | no | + +## Outputs + +| Name | Description | +|------|-------------| +| ec2-id-ip | Ec2 instance id and private ip | +| elastic-ip | Ec2 instance EIP | +| instance-id | Ec2 instance id | +| private-ip | Ec2 instance private IP | +| public-ip | Ec2 instance ephemeral public IP | +| ssh-key-name | Ec2 instance ssh key name | +| ssh-key-secret-arn | Secretsmanager arn for ec2 instance ssh key | + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/compute/ec2/main.tf b/modules/compute/ec2/main.tf new file mode 100644 index 0000000..68b59e0 --- /dev/null +++ b/modules/compute/ec2/main.tf @@ -0,0 +1,125 @@ +resource "aws_instance" "ec2-instance" { + ami = var.ami-id + instance_type = var.instance-type + associate_public_ip_address = var.asso-public-ip + // availability_zone = var.az + iam_instance_profile = var.instance-profile + key_name = var.create-ssh-key ? aws_key_pair.this[0].key_name : var.key-name + private_ip = var.private-ip + root_block_device { + encrypted = var.ebs-encrypted + volume_size = var.root-volume-size + volume_type = var.root-volume-type + kms_key_id = var.kms-key-id + delete_on_termination = var.delete-on-termination + } + ebs_optimized = true + subnet_id = var.subnet-id + vpc_security_group_ids = var.security-groups + + # IMDSv2 requirement + dynamic "metadata_options" { + for_each = var.disable_secure_idmsv2 == false ? { set_idmsv2 : true } : {} + content { + http_endpoint = "enabled" + http_tokens = "required" + http_put_response_hop_limit = 2 + } + } + + # spot instance option + dynamic "instance_market_options" { + for_each = var.spot-max-price > 0 ? { use_spot : true } : {} + content { + market_type = "spot" + + dynamic "spot_options" { + for_each = { use_spot : true } + content { + max_price = var.spot-max-price + } + } + } + } + + disable_api_termination = var.enable-termination-protection + user_data = var.user-data + monitoring = var.enable-detail-monitoring + + tags = merge(var.additional-tags, { "Name" : var.instance-name }) + volume_tags = merge({ "Name" : "${var.instance-name}-root" }, data.aws_default_tags.this.tags) + + # do not redeploy instance when a new ami is released + lifecycle { + ignore_changes = [ami] + } +} + +resource "aws_ebs_volume" "data-volumes" { + for_each = var.data-volumes + availability_zone = aws_instance.ec2-instance.availability_zone + size = each.value["size"] + type = each.value["type"] + iops = try(each.value["iops"], null) + kms_key_id = aws_instance.ec2-instance.root_block_device[0].kms_key_id + encrypted = aws_instance.ec2-instance.root_block_device[0].encrypted + tags = merge( + { Name : "${var.instance-name}-${each.key}" }, + data.aws_default_tags.this.tags + ) +} + +locals { + a_to_z = split(",", "a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t,u,v,w,x,y,z") +} + + +resource "aws_volume_attachment" "data-volume-attachments" { + count = length(aws_ebs_volume.data-volumes) + volume_id = [for v in aws_ebs_volume.data-volumes : v.id][count.index] + instance_id = aws_instance.ec2-instance.id + device_name = "/dev/xvda${element(local.a_to_z, count.index)}" +} + + +resource "aws_eip" "ec2-eip" { + count = var.asso-eip ? 1 : 0 + instance = aws_instance.ec2-instance.id + domain = "vpc" +} + +resource "tls_private_key" "this" { + count = var.create-ssh-key ? 1 : 0 + algorithm = "ED25519" +} + +resource "aws_key_pair" "this" { + count = var.create-ssh-key ? 1 : 0 + key_name = "${var.instance-name}-sshkey" + public_key = tls_private_key.this[0].public_key_openssh +} + +resource "random_id" "this" { + byte_length = 2 +} + +resource "aws_secretsmanager_secret" "this" { + count = var.create-ssh-key ? 1 : 0 + name = "${var.instance-name}-sshkey-${random_id.this.dec}" + description = "Private key for ${aws_instance.ec2-instance.id}" +} + +resource "aws_secretsmanager_secret_version" "this" { + count = var.create-ssh-key ? 1 : 0 + secret_id = aws_secretsmanager_secret.this[0].id + secret_string = tls_private_key.this[0].private_key_openssh +} + +data "aws_default_tags" "this" { + lifecycle { + postcondition { + condition = length(self.tags) >= 1 + error_message = "Validation failed: Provider default_tags not set." + } + } +} \ No newline at end of file diff --git a/modules/compute/ec2/outputs.tf b/modules/compute/ec2/outputs.tf new file mode 100644 index 0000000..086faa7 --- /dev/null +++ b/modules/compute/ec2/outputs.tf @@ -0,0 +1,37 @@ +output "ec2-id-ip" { + description = "Ec2 instance id and private ip" + value = { + instance-id = aws_instance.ec2-instance.id + private-ip = aws_instance.ec2-instance.private_ip + } +} + +output "instance-id" { + description = "Ec2 instance id" + value = aws_instance.ec2-instance.id +} + +output "private-ip" { + description = "Ec2 instance private IP" + value = aws_instance.ec2-instance.private_ip +} + +output "ssh-key-name" { + description = "Ec2 instance ssh key name" + value = var.create-ssh-key ? aws_key_pair.this[0].key_name : var.key-name +} + +output "ssh-key-secret-arn" { + description = "Secretsmanager arn for ec2 instance ssh key" + value = var.create-ssh-key ? aws_secretsmanager_secret.this[0].arn : null +} + +output "elastic-ip" { + description = "Ec2 instance EIP" + value = var.asso-eip ? aws_eip.ec2-eip[0].public_ip : null +} + +output "public-ip" { + description = "Ec2 instance ephemeral public IP" + value = var.asso-public-ip ? aws_instance.ec2-instance.public_ip : null +} \ No newline at end of file diff --git a/modules/compute/ec2/provider.tf b/modules/compute/ec2/provider.tf new file mode 100644 index 0000000..a535735 --- /dev/null +++ b/modules/compute/ec2/provider.tf @@ -0,0 +1,10 @@ +# aws plugin 5.0.0 or above is required to support domain attribute in aws_eip +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = "~> 5.35.0" + } + } +} diff --git a/modules/compute/ec2/variable.tf b/modules/compute/ec2/variable.tf new file mode 100644 index 0000000..d13803e --- /dev/null +++ b/modules/compute/ec2/variable.tf @@ -0,0 +1,107 @@ +variable "instance-type" { + type = string + description = "Instance type" +} +variable "ami-id" { + type = string + description = "Image id of EC2 instance" +} +variable "asso-public-ip" { + type = bool + description = "Whether to associate ephemeral public IP" +} +variable "instance-profile" { + type = string + default = "" + description = "Ec2 instance profile name" +} +variable "key-name" { + type = string + description = "Instance ssh key name" + default = "" +} +variable "ebs-encrypted" { + type = bool + default = true + description = "Whether to enable EBS encryption" +} +variable "root-volume-size" { + type = number + description = "Size of root volume" +} +variable "root-volume-type" { + type = string + default = "gp3" + description = "Root volume type" +} +variable "kms-key-id" { + type = string + description = "Disk encryption KMS key id" +} +variable "delete-on-termination" { + type = bool + default = true + description = "Whether to delete volumes on termination" +} +variable "subnet-id" { + type = string + description = "Id of subnet to deploy Ec2 instance to" +} +variable "security-groups" { + type = list(string) + description = "List of security groups for Ec2 instance" +} +variable "instance-name" { + type = string + description = "Name of ec2 instance" +} +variable "asso-eip" { + type = bool + description = "Whether to associate Elastic IP" +} +variable "data-volumes" { + type = map(object({ + size = number + type = string + })) + description = "Attach additional data volumes" +} +variable "private-ip" { + type = string + default = null + description = "Specify private IP to be used on this instance" +} +variable "additional-tags" { + type = map(string) + description = "Additional tags to be assigned on top of provider default tags. Useful for setting backup tags." +} +variable "disable_secure_idmsv2" { + type = bool + default = false + description = "If set to true, the insecure IDMSv1 will be used." +} +variable "enable-termination-protection" { + type = bool + default = false + description = "Whether to enable prevent accidential deletion of instance" +} +variable "user-data" { + type = string + default = "" + description = "Ec2 user-data" +} +variable "enable-detail-monitoring" { + type = bool + default = false + description = "Set true to enable detail monitoring" +} +variable "spot-max-price" { + type = number + description = "Max hourly price for spot instance. If greater than zero, spot instance will be used." + default = 0 +} +variable "create-ssh-key" { + type = bool + default = false + description = "Set true to create ssh key and store on secret manager" +} \ No newline at end of file diff --git a/modules/compute/security-groups/README.md b/modules/compute/security-groups/README.md new file mode 100644 index 0000000..1cbe23f --- /dev/null +++ b/modules/compute/security-groups/README.md @@ -0,0 +1,52 @@ +# security-groups-gen2 +This module create security groups from a map + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:-----:| +| tags | tags | List | n/a | yes | +| vpc-id | VPC id | string | n/a | yes | +| security-groups | See example below | map | n/a | yes | + +### security-groups input +Below is a sample security-groups map this module ingests. The rule list needs to have +the id column to prevent list from being randomly sorted. + +```hcl +module "headdesk-sg" { + source = "../../modules/compute/security-groups" + + security-groups = [ + { + name = "WebAccess" + description = "Public web access" + rules = [ + [1, "tcp", "0.0.0.0/0", "80", "80", "ingress", "web"], + [2, "tcp", "0.0.0.0/0", "443", "443", "ingress", "web"], + [3, "tcp", "0.0.0.0/0", "25", "25", "ingress", "mail"], + [4, "tcp", "0.0.0.0/0", "587", "587", "ingress", "mail"], + [5, "tcp", "0.0.0.0/0", "11993", "11993", "ingress", "mail"], + [6, "-1", "0.0.0.0/0", "0", "0", "egress", "Allow outbound traffic"], + [7, "tcp", "0.0.0.0/0", "2201", "2201", "ingress", "ssh"] + ] + }, + { + name = "MgmtAccess" + description = "Allow management access" + rules = [ + [1, "tcp", "223.18.148.85/32", "22", "22", "ingress", "xpk"] + ] + } + ] + tags = local.default-tags + vpc-id = module.vpc-subnet.vpc_id +} +``` + +## Outputs + +| Name | Description | +|------|-------------| +| sg-id-name | A map of SG id and their names | + diff --git a/modules/compute/security-groups/main.tf b/modules/compute/security-groups/main.tf new file mode 100644 index 0000000..be6bc55 --- /dev/null +++ b/modules/compute/security-groups/main.tf @@ -0,0 +1,45 @@ +resource "aws_security_group" "sg" { + count = length(var.security-groups) + name = var.security-groups[count.index].name + description = var.security-groups[count.index].description + vpc_id = var.vpc-id + tags = { Name = var.security-groups[count.index].name } +} + +// see https://www.terraform.io/docs/configuration/functions/flatten.html + +locals { + rules = flatten([ + for sg_key, sg in var.security-groups : [ + for rule_key, rule in sg.rules : { + sg_key = trimspace(sg.name) + rule_key = rule[0] + sg_name = sg.name + protocol = rule[1] + cidr_blocks = rule[2] + from_port = rule[3] + to_port = rule[4] + type = rule[5] + description = rule[6] + } + ] + ]) + + +} + +resource "aws_security_group_rule" "rules" { + for_each = { + for rule in local.rules : "${rule.sg_key}.${rule.rule_key}" => rule + } + + security_group_id = matchkeys(aws_security_group.sg.*.id, aws_security_group.sg.*.name, [each.value.sg_name])[0] + protocol = each.value.protocol + source_security_group_id = substr(each.value.cidr_blocks,0,2) == "sg" ? each.value.cidr_blocks : null + cidr_blocks = substr(each.value.cidr_blocks,0,2) != "sg" ? [each.value.cidr_blocks] : null + from_port = each.value.from_port + to_port = each.value.to_port + type = each.value.type + description = "${each.value.description} (${each.value.sg_name}.${each.value.rule_key})" +} + diff --git a/modules/compute/security-groups/outputs.tf b/modules/compute/security-groups/outputs.tf new file mode 100644 index 0000000..cf52a14 --- /dev/null +++ b/modules/compute/security-groups/outputs.tf @@ -0,0 +1,14 @@ +/* +output sg-id-name { + value = [ + for id, name in zipmap( + sort(aws_security_group.sg.*.id), + sort(aws_security_group.sg.*.name)) : + tomap(id, name) + ] +} +*/ + +output sg-ids { + value = aws_security_group.sg.*.id +} \ No newline at end of file diff --git a/modules/compute/security-groups/variables.tf b/modules/compute/security-groups/variables.tf new file mode 100644 index 0000000..7b55843 --- /dev/null +++ b/modules/compute/security-groups/variables.tf @@ -0,0 +1,3 @@ +variable security-groups {} +variable vpc-id {} +variable tags {} \ No newline at end of file diff --git a/modules/compute/security_group/README.md b/modules/compute/security_group/README.md new file mode 100644 index 0000000..d8e0d8a --- /dev/null +++ b/modules/compute/security_group/README.md @@ -0,0 +1,43 @@ +# security-group +This module create security group. + +## Inputs + +| Name | Description | Type | Default | Required | +|---------|-------------------|----------|---------|:--------:| +| vpc-id | VPC id | string | n/a | yes | +| ingress | See example below | map | n/a | yes | +| egress | See example below | map | n/a | yes | + +## Outputs + +| Name | Description | +|------------|--------------------------------| +| sg-id-name | A map of SG id and their names | + +### Example +Below is a sample root module calling this shared module + +```hcl +module "admin-sg" { + + source = "../../modules/compute/security_group" + + description = "Security group for admins" + egress = { + r1 = "tcp,4750,4750,1.2.3.4/32,Patch Management Tool" + r2 = "tcp,22,22,1.2.3.4/32,Patch Management Tool" + r3 = "tcp,52311,52311,${aws_ec2_managed_prefix_list.bigfix.id},Client to BigFix server" + } + ingress = { + r1 = "tcp,4750,4750,1.2.3.4/32,Patch Management Tool" + r2 = "tcp,22,22,1.2.3.4/32,Patch Management Tool" + r3 = "tcp,52311,52311,${aws_ec2_managed_prefix_list.bigfix.id},BigFix server to client" + } + name = "admin-sg" + vpc-id = "vpc-01a10b033169f89a8" +} +``` + + + diff --git a/modules/compute/security_group/main.tf b/modules/compute/security_group/main.tf new file mode 100644 index 0000000..6fb358e --- /dev/null +++ b/modules/compute/security_group/main.tf @@ -0,0 +1,39 @@ +data "aws_default_tags" "this" { + lifecycle { + postcondition { + condition = length(self.tags) >= 1 + error_message = "Validation failed: Provider default_tags not set." + } + } +} + +resource "aws_security_group" "sg" { + name = var.name + description = var.description + vpc_id = var.vpc-id + tags = { Name = var.name } +} + +resource "aws_vpc_security_group_ingress_rule" "ingress-rules" { + for_each = var.ingress + security_group_id = aws_security_group.sg.id + ip_protocol = split(",", each.value)[0] + from_port = split(",", each.value)[1] + to_port = split(",", each.value)[2] + cidr_ipv4 = substr(split(",", each.value)[3], 2, 1) != "-" ? split(",", each.value)[3] : null + referenced_security_group_id = substr(split(",", each.value)[3], 0, 2) == "sg" ? split(",", each.value)[3] : null + prefix_list_id = substr(split(",", each.value)[3], 0, 2) == "pl" ? split(",", each.value)[3] : null + description = split(",", each.value)[4] +} + +resource "aws_vpc_security_group_egress_rule" "egress-rules" { + for_each = var.egress + security_group_id = aws_security_group.sg.id + ip_protocol = split(",", each.value)[0] + from_port = split(",", each.value)[1] + to_port = split(",", each.value)[2] + cidr_ipv4 = substr(split(",", each.value)[3], 2, 1) != "-" ? split(",", each.value)[3] : null + referenced_security_group_id = substr(split(",", each.value)[3], 0, 2) == "sg" ? split(",", each.value)[3] : null + prefix_list_id = substr(split(",", each.value)[3], 0, 2) == "pl" ? split(",", each.value)[3] : null + description = split(",", each.value)[4] +} diff --git a/modules/compute/security_group/outputs.tf b/modules/compute/security_group/outputs.tf new file mode 100644 index 0000000..5a963bf --- /dev/null +++ b/modules/compute/security_group/outputs.tf @@ -0,0 +1,3 @@ +output id { + value = aws_security_group.sg.id +} \ No newline at end of file diff --git a/modules/compute/security_group/variables.tf b/modules/compute/security_group/variables.tf new file mode 100644 index 0000000..4fb72d0 --- /dev/null +++ b/modules/compute/security_group/variables.tf @@ -0,0 +1,5 @@ +variable name {} +variable description {} +variable vpc-id {} +variable ingress {} +variable egress {} \ No newline at end of file diff --git a/modules/compute/sg_default_tags/README.md b/modules/compute/sg_default_tags/README.md new file mode 100644 index 0000000..2164266 --- /dev/null +++ b/modules/compute/sg_default_tags/README.md @@ -0,0 +1,43 @@ +# security-groups-gen2 +This module create security groups from a map + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:-----:| +| tags | tags | List | n/a | yes | +| vpc-id | VPC id | string | n/a | yes | +| security-groups | See example below | map | n/a | yes | + +### security-groups input +Below is a sample security-groups map this module ingests. The rule list needs to have +the id column to prevent list from being randomly sorted. + +```hcl +module "endpoint_sg" { + source = "../../../../whk1-bea-sys-ss-prd-codecommit-sharedmodules/Compute/sg_default_tags" + name = "vwhk1-bea-sys-ss-prd-vpc01-ep-sg" + description = "vpc endpoint security group" + egress-sg-rules = { + name = "outbound access" + rules = [ + [1, "-1", "0.0.0.0/0", "0", "0", "outbound access"] + ] + } + + ingress-sg-rules = { + name = "HttpsAccessToVpcEndpoints" + rules = [ + [1, "tcp", data.aws_vpc.vpc1.cidr_block, "443", "443", "TLS from VPC"] + ] + } + vpc-id = var.vpc-id +} +``` + +## Outputs + +| Name | Description | +|------|-------------| +| sg-id-name | A map of SG id and their names | + diff --git a/modules/compute/sg_default_tags/main.tf b/modules/compute/sg_default_tags/main.tf new file mode 100644 index 0000000..4e2a3a7 --- /dev/null +++ b/modules/compute/sg_default_tags/main.tf @@ -0,0 +1,71 @@ +data "aws_default_tags" "this" { + lifecycle { + postcondition { + condition = length(self.tags) >= 1 + error_message = "Validation failed: Provider default_tags not set." + } + } +} + +resource "aws_security_group" "sg" { + name = var.name + description = var.description + vpc_id = var.vpc-id +} + +// see https://www.terraform.io/docs/configuration/functions/flatten.html + +locals { + ingress_rules = flatten([ + for rule_key, rule in var.ingress-sg-rules.rules : { + sg_key = "ingress" + rule_key = rule[0] + protocol = rule[1] + cidr_blocks = rule[2] + from_port = rule[3] + to_port = rule[4] + description = rule[5] + } + ]) + + egress_rules = flatten([ + for rule_key, rule in var.egress-sg-rules.rules : { + sg_key = "egress" + rule_key = rule[0] + protocol = rule[1] + cidr_blocks = rule[2] + from_port = rule[3] + to_port = rule[4] + description = rule[5] + } + ]) + +} + +resource "aws_vpc_security_group_egress_rule" "egress_rules" { + for_each = { + for rule in local.egress_rules : "${rule.sg_key}.${rule.rule_key}" => rule + } + + security_group_id = aws_security_group.sg.id + ip_protocol = each.value.protocol + referenced_security_group_id = substr(each.value.cidr_blocks, 0, 2) == "sg" ? each.value.cidr_blocks : null + cidr_ipv4 = substr(each.value.cidr_blocks, 0, 2) != "sg" ? each.value.cidr_blocks : null + from_port = each.value.protocol == "-1" ? null : each.value.from_port + to_port = each.value.protocol == "-1" ? null : each.value.to_port + description = each.value.description +} + +resource "aws_vpc_security_group_ingress_rule" "ingress_rules" { + for_each = { + for rule in local.ingress_rules : "${rule.sg_key}.${rule.rule_key}" => rule + } + + security_group_id = aws_security_group.sg.id + ip_protocol = each.value.protocol + referenced_security_group_id = substr(each.value.cidr_blocks, 0, 2) == "sg" ? each.value.cidr_blocks : null + cidr_ipv4 = substr(each.value.cidr_blocks, 0, 2) != "sg" ? each.value.cidr_blocks : null + from_port = each.value.protocol == "-1" ? null : each.value.from_port + to_port = each.value.protocol == "-1" ? null : each.value.to_port + description = each.value.description +} diff --git a/modules/compute/sg_default_tags/outputs.tf b/modules/compute/sg_default_tags/outputs.tf new file mode 100644 index 0000000..cf52a14 --- /dev/null +++ b/modules/compute/sg_default_tags/outputs.tf @@ -0,0 +1,14 @@ +/* +output sg-id-name { + value = [ + for id, name in zipmap( + sort(aws_security_group.sg.*.id), + sort(aws_security_group.sg.*.name)) : + tomap(id, name) + ] +} +*/ + +output sg-ids { + value = aws_security_group.sg.*.id +} \ No newline at end of file diff --git a/modules/compute/sg_default_tags/variables.tf b/modules/compute/sg_default_tags/variables.tf new file mode 100644 index 0000000..acd469d --- /dev/null +++ b/modules/compute/sg_default_tags/variables.tf @@ -0,0 +1,6 @@ +# variable security-groups {} +variable vpc-id {} +variable ingress-sg-rules {} +variable egress-sg-rules {} +variable name {} +variable description {} \ No newline at end of file diff --git a/modules/global-variables/README.md b/modules/global-variables/README.md new file mode 100644 index 0000000..5b36d91 --- /dev/null +++ b/modules/global-variables/README.md @@ -0,0 +1,27 @@ +# global-variables module +This module provides global variables that can be used in all layers + + +## Basic Usage +Variables are stored in a map in outputs.tf + +```hcl +module "global-variables" { + source = "../../../../../../../../../terraform_modules_shared/global-variables" +} + +// then retrieve global variable from the module. for example: +sys-sec-account = module.global-variables.vars.prod.sys-sec-acc +``` + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|:----:|:-----:|:-----:| + +## Outputs + +| Name | Description | +|------|-------------| +| vars | map of variables | + diff --git a/modules/global-variables/outputs.tf b/modules/global-variables/outputs.tf new file mode 100644 index 0000000..053f9f5 --- /dev/null +++ b/modules/global-variables/outputs.tf @@ -0,0 +1,18 @@ +output vars { + value = { + "prod" = { + sys-log-acc = "174677273835" + sys-ss-acc = "827262612707" + stm-acc = "205233139210" + sys-sec-acc = "033205333431" + mp-acc = "616302076454" + } + "plike" = { + sys-log-acc = "870377016556" + sys-ss-acc = "022321612404" + stm-acc = "313794563353" + sys-sec-acc = "240016403383" + mp-acc = "684740086263" + } + } +} \ No newline at end of file diff --git a/modules/networking/VpcSubnet/README.md b/modules/networking/VpcSubnet/README.md new file mode 100644 index 0000000..42522ff --- /dev/null +++ b/modules/networking/VpcSubnet/README.md @@ -0,0 +1,93 @@ +This module performs the following tasks: + +- Create VPC, vpcflow log +- Create subnets in every AZ +- Create IGW, NGW +- Create s3 and ddb endpoints which are free + + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | +| random | n/a | + +## Modules + +| Name | Source | Version | +|------|--------|---------| +| private-route | ./modules/RouteTables | n/a | +| private-route-multiaz | ./modules/RouteTables | n/a | +| vpc-ep | ../vpc-endpoints | n/a | + +## Resources + +| Name | Type | +|------|------| +| [aws_cloudwatch_log_group.vpcflowlog-loggroup](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_log_group) | resource | +| [aws_default_security_group.default-sg](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/default_security_group) | resource | +| [aws_eip.ngw-eip](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eip) | resource | +| [aws_eip.ngw-eip-multiaz](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/eip) | resource | +| [aws_flow_log.vpc-flowlog](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/flow_log) | resource | +| [aws_flow_log.vpc-flowlog-s3](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/flow_log) | resource | +| [aws_iam_role.vpcflowlog-role](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_iam_role_policy.vpcflowlog-role-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy) | resource | +| [aws_internet_gateway.igw](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/internet_gateway) | resource | +| [aws_nat_gateway.ngw](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/nat_gateway) | resource | +| [aws_nat_gateway.ngw-multiaz](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/nat_gateway) | resource | +| [aws_route.public-routes](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route) | resource | +| [aws_route_table.public-route-table](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route_table) | resource | +| [aws_route_table_association.public_route_association](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route_table_association) | resource | +| [aws_subnet.private-subnets](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet) | resource | +| [aws_subnet.public-subnets](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet) | resource | +| [aws_vpc.vpc](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc) | resource | +| [aws_vpc_ipv4_cidr_block_association.additional_cidr](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc_ipv4_cidr_block_association) | resource | +| [random_id.rid](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/id) | resource | +| [aws_availability_zones.available-az](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/availability_zones) | data source | +| [aws_caller_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | +| [aws_default_tags.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/default_tags) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| create-free-vpc-endpoints | Whether to deploy free VPC endpoints (s3 and dynamodb) | `bool` | `true` | no | +| create-nat-gateway | Deploy NAT gateway for private subnets | `bool` | `false` | no | +| enable-flow-log | Whether to enable VPC flowlog | `bool` | `true` | no | +| flow-log-bucket-arn | Arn of S3 bucket to be used for flow logging | `string` | `null` | no | +| flow-log-destination | Destination of flowlog. Valid destinations are s3 or cwlog | `string` | `null` | no | +| multiaz-nat-gateway | Whether to deploy 1 NAT gateway for each AZ | `bool` | `false` | no | +| private-subnet-cidrs | Private subnet CIDRs | `list(string)` | `[]` | no | +| public-subnet-cidrs | Public subnet CIDRs | `list(string)` | `[]` | no | +| resource-prefix | Prefix of resource | `string` | n/a | yes | +| secondary\_cidr\_blocks | Additional cidr blocks | `list(string)` | `[]` | no | +| vpc-cidr | VPC primary CIDR | `string` | n/a | yes | +| vpcflowlog-cwl-loggroup-key-arn | KMS key arn for cwlog encryption | `string` | n/a | yes | +| vpcflowlog-retain-days | Log retention period for CWlogs | `number` | `90` | no | + +## Outputs + +| Name | Description | +|------|-------------| +| private-subnet-details | Details of private subnets | +| private-subnet-ids | List of private subnet id | +| private\_subnets | Private subnet cidrs | +| public-route-table-id | Public route table id | +| public-subnet-details | Details of public subnets | +| public-subnet-ids | List of public subnet id | +| public\_subnets | Public subnet cidrs | +| secondary\_cidr\_blocks | Secondary CIDR block | +| vpc-cidr | VPC primary cidr | +| vpc\_id | VPC id | + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/networking/VpcSubnet/example/main.tf b/modules/networking/VpcSubnet/example/main.tf new file mode 100644 index 0000000..52ea50d --- /dev/null +++ b/modules/networking/VpcSubnet/example/main.tf @@ -0,0 +1,12 @@ +module "vpc-subnets" { + source = "../../modules/networking/vpc-subnet-manual" + + resource-prefix = local.resource-prefix + private-subnet-cidrs = ["172.17.0.0/24", "172.17.1.0/24"] + public-subnet-cidrs = ["172.17.10.0/24", "172.17.11.0/24"] + vpc-cidr = "172.17.0.0/16" + enable-flow-log = false + vpcflowlog-cwl-loggroup-key-arn = "" + create-nat-gateway = true + create-free-vpc-endpoints = true +} \ No newline at end of file diff --git a/modules/networking/VpcSubnet/main.tf b/modules/networking/VpcSubnet/main.tf new file mode 100644 index 0000000..8550326 --- /dev/null +++ b/modules/networking/VpcSubnet/main.tf @@ -0,0 +1,203 @@ +data "aws_caller_identity" "this" {} + +data "aws_availability_zones" "available-az" { + state = "available" +} + +data "aws_default_tags" "this" { + lifecycle { + postcondition { + condition = length(self.tags) >= 1 + error_message = "Validation failed: Provider default_tags not set." + } + } +} + +locals { + # no-az = 2 # hard-coding to 2AZ + vpc-cidr = var.vpc-cidr +} + +resource "aws_subnet" "private-subnets" { + count = length(var.private-subnet-cidrs) + vpc_id = aws_vpc.vpc.id + availability_zone = element(data.aws_availability_zones.available-az.names, count.index % 2) + cidr_block = var.private-subnet-cidrs[count.index] + tags = merge(data.aws_default_tags.this.tags, { + Name = "${var.resource-prefix}-private-${split("-", element(data.aws_availability_zones.available-az.names, count.index))[2]}-${count.index + 1}" + }) +} + +resource "aws_subnet" "public-subnets" { + count = length(var.public-subnet-cidrs) + vpc_id = aws_vpc.vpc.id + availability_zone = element(data.aws_availability_zones.available-az.names, count.index % 2) + cidr_block = var.public-subnet-cidrs[count.index] + tags = merge(data.aws_default_tags.this.tags, { + Name = "${var.resource-prefix}-public-${split("-", element(data.aws_availability_zones.available-az.names, count.index))[2]}-${count.index + 1}" + }) +} + +resource "aws_vpc" "vpc" { + cidr_block = var.vpc-cidr + enable_dns_hostnames = true + enable_dns_support = true + + tags = { + Name = "${var.resource-prefix}-vpc" + } + + lifecycle { + create_before_destroy = true + } +} + +resource "aws_vpc_ipv4_cidr_block_association" "additional_cidr" { + for_each = toset(var.secondary_cidr_blocks) + vpc_id = aws_vpc.vpc.id + cidr_block = each.value +} + +resource "aws_internet_gateway" "igw" { + count = length(var.public-subnet-cidrs) > 0 ? 1 : 0 + vpc_id = aws_vpc.vpc.id + + tags = { + Name = "${var.resource-prefix}-igw" + } +} + +resource "aws_eip" "ngw-eip" { + count = var.create-nat-gateway ? 1 : 0 + domain = "vpc" + depends_on = [aws_internet_gateway.igw] +} + +resource "aws_nat_gateway" "ngw" { + count = var.create-nat-gateway && !var.multiaz-nat-gateway ? 1 : 0 + allocation_id = aws_eip.ngw-eip[0].id + subnet_id = aws_subnet.public-subnets[0].id + + tags = { + Name = "${var.resource-prefix}-ngw" + } + depends_on = [aws_internet_gateway.igw] +} + +resource "aws_eip" "ngw-eip-multiaz" { + count = var.multiaz-nat-gateway ? length(distinct(aws_subnet.private-subnets.*.availability_zone)) : 0 + domain = "vpc" + depends_on = [aws_internet_gateway.igw] +} + +resource "aws_nat_gateway" "ngw-multiaz" { + count = var.multiaz-nat-gateway ? length(aws_eip.ngw-eip-multiaz) : 0 + allocation_id = aws_eip.ngw-eip-multiaz[count.index].id + subnet_id = aws_subnet.public-subnets[count.index].id + tags = { + Name = "${var.resource-prefix}-ngw-${count.index + 1}" + } + depends_on = [aws_internet_gateway.igw] +} + +resource "aws_route_table" "public-route-table" { + count = length(var.public-subnet-cidrs) > 0 ? 1 : 0 + vpc_id = aws_vpc.vpc.id + tags = { + Name = "${var.resource-prefix}-public" + } +} + +module "private-route" { + source = "./modules/RouteTables" + count = var.create-nat-gateway && !var.multiaz-nat-gateway ? length(aws_subnet.private-subnets) : 0 + ngw-id = aws_nat_gateway.ngw[0].id + resource-prefix = var.resource-prefix + subnet-id = aws_subnet.private-subnets[count.index].id + vpc-id = aws_vpc.vpc.id +} + +module "private-route-multiaz" { + source = "./modules/RouteTables" + count = var.multiaz-nat-gateway ? length(aws_subnet.private-subnets) : 0 + ngw-id = aws_nat_gateway.ngw-multiaz[count.index].id + resource-prefix = var.resource-prefix + subnet-id = aws_subnet.private-subnets[count.index].id + vpc-id = aws_vpc.vpc.id +} + + + +# resource "aws_route_table" "private-route-table" { +# count = length(var.private-subnet-cidrs) > 0 ? 1 : 0 +# vpc_id = aws_vpc.vpc.id +# tags = { +# Name = "${var.resource-prefix}-privateroutetable" +# } +# } + +resource "aws_route" "public-routes" { + count = length(var.public-subnet-cidrs) > 0 ? 1 : 0 + + destination_cidr_block = "0.0.0.0/0" + gateway_id = aws_internet_gateway.igw[0].id + route_table_id = aws_route_table.public-route-table[0].id +} + +# resource "aws_route" "private-routes" { +# count = length(var.private-subnet-cidrs) > 0 && var.create-nat-gateway ? 1 : 0 +# +# destination_cidr_block = "0.0.0.0/0" +# nat_gateway_id = aws_nat_gateway.ngw[0].id +# route_table_id = aws_route_table.private-route-table[0].id +# } + +resource "aws_route_table_association" "public_route_association" { + count = length(aws_subnet.public-subnets) + route_table_id = aws_route_table.public-route-table[0].id + subnet_id = aws_subnet.public-subnets[count.index].id +} + +# resource "aws_route_table_association" "private_route_association" { +# count = length(aws_subnet.private-subnets) +# route_table_id = aws_route_table.private-route-table[0].id +# subnet_id = aws_subnet.private-subnets[count.index].id +# } + +/* +harden default security group. the default sg created by aws allows all egress. +this resource limits ingress and egress from and to itself +and allow icmp only +*/ + +resource "aws_default_security_group" "default-sg" { + vpc_id = aws_vpc.vpc.id + ingress { + protocol = "icmp" + self = true + from_port = -1 + to_port = -1 + description = "Allow traffic coming from this SG" + } + egress { + from_port = -1 + protocol = "icmp" + to_port = -1 + self = true + description = "Allow traffic going to this SG" + } + tags = { + Name = "${var.resource-prefix}-defaultsg" + } +} + +# Enable gateway endpoints which are free +module "vpc-ep" { + count = var.create-free-vpc-endpoints ? 1 : 0 + source = "../vpc-endpoints" + + gateway-ep-services = ["s3", "dynamodb"] + interface-ep-services = [] + resource-prefix = var.resource-prefix + vpc-id = aws_vpc.vpc.id +} \ No newline at end of file diff --git a/modules/networking/VpcSubnet/modules/RouteTables/README.md b/modules/networking/VpcSubnet/modules/RouteTables/README.md new file mode 100644 index 0000000..59e41e9 --- /dev/null +++ b/modules/networking/VpcSubnet/modules/RouteTables/README.md @@ -0,0 +1,39 @@ + +## Requirements + +No requirements. + +## Providers + +| Name | Version | +|------|---------| +| aws | n/a | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_route.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route) | resource | +| [aws_route_table.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route_table) | resource | +| [aws_route_table_association.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route_table_association) | resource | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| ngw-id | NAT Gateway ID | `string` | n/a | yes | +| resource-prefix | Resource prefix | `string` | n/a | yes | +| subnet-id | Subnet ID | `string` | n/a | yes | +| vpc-id | VPC ID | `string` | n/a | yes | + +## Outputs + +No outputs. + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/networking/VpcSubnet/modules/RouteTables/main.tf b/modules/networking/VpcSubnet/modules/RouteTables/main.tf new file mode 100644 index 0000000..5fff011 --- /dev/null +++ b/modules/networking/VpcSubnet/modules/RouteTables/main.tf @@ -0,0 +1,17 @@ +resource "aws_route_table" "this" { + vpc_id = var.vpc-id + tags = { + Name = "${var.resource-prefix}-private" + } +} + +resource "aws_route" "this" { + destination_cidr_block = "0.0.0.0/0" + nat_gateway_id = var.ngw-id + route_table_id = aws_route_table.this.id +} + +resource "aws_route_table_association" "this" { + route_table_id = aws_route_table.this.id + subnet_id = var.subnet-id +} diff --git a/modules/networking/VpcSubnet/modules/RouteTables/variables.tf b/modules/networking/VpcSubnet/modules/RouteTables/variables.tf new file mode 100644 index 0000000..3632eb8 --- /dev/null +++ b/modules/networking/VpcSubnet/modules/RouteTables/variables.tf @@ -0,0 +1,19 @@ +variable vpc-id { + type = string + description = "VPC ID" +} + +variable ngw-id { + type = string + description = "NAT Gateway ID" +} + +variable subnet-id { + type = string + description = "Subnet ID" +} + +variable resource-prefix { + type = string + description = "Resource prefix" +} diff --git a/modules/networking/VpcSubnet/outputs.tf b/modules/networking/VpcSubnet/outputs.tf new file mode 100644 index 0000000..b04b319 --- /dev/null +++ b/modules/networking/VpcSubnet/outputs.tf @@ -0,0 +1,70 @@ +output "vpc_id" { + description = "VPC id" + value = aws_vpc.vpc.id +} + +output "vpc-cidr" { + description = "VPC primary cidr" + value = aws_vpc.vpc.cidr_block +} + +output "public_subnets" { + description = "Public subnet cidrs" + value = aws_subnet.public-subnets.*.cidr_block +} + +output "private_subnets" { + description = "Private subnet cidrs" + value = aws_subnet.private-subnets.*.cidr_block +} + +output "public-subnet-ids" { + description = "List of public subnet id" + value = aws_subnet.public-subnets.*.id +} + +output "private-subnet-ids" { + description = "List of private subnet id" + value = aws_subnet.private-subnets.*.id +} + +# output "private-route-table-id" { +# value = aws_route_table.private-route-table.*.id +# } + +output "public-route-table-id" { + description = "Public route table id" + value = aws_route_table.public-route-table.*.id +} + +# output "route_tables_for_gateway_endpoints" { +# value = concat(aws_route_table.public-route-table.*.id, aws_route_table.private-route-table.*.id) +# } + +output "secondary_cidr_blocks" { + description = "Secondary CIDR block" + value = var.secondary_cidr_blocks +} + +output "public-subnet-details" { + description = "Details of public subnets" + value = [ + for k, v in aws_subnet.public-subnets : { + cidr = v.cidr_block, + az = v.availability_zone, + name = v.tags["Name"] + } + ] +} + +output "private-subnet-details" { + description = "Details of private subnets" + value = [ + for k, v in aws_subnet.public-subnets : { + cidr = v.cidr_block, + az = v.availability_zone, + name = v.tags["Name"] + } + ] +} + diff --git a/modules/networking/VpcSubnet/variables.tf b/modules/networking/VpcSubnet/variables.tf new file mode 100644 index 0000000..2ff263b --- /dev/null +++ b/modules/networking/VpcSubnet/variables.tf @@ -0,0 +1,75 @@ +variable "resource-prefix" { + type = string + description = "Prefix of resource" +} + +# VPC variables +variable "vpc-cidr" { + type = string + description = "VPC primary CIDR" +} + +variable "private-subnet-cidrs" { + type = list(string) + description = "Private subnet CIDRs" + default = [] +} + +variable "public-subnet-cidrs" { + type = list(string) + description = "Public subnet CIDRs" + default = [] +} + +variable "create-nat-gateway" { + description = "Deploy NAT gateway for private subnets" + type = bool + default = false +} + +variable "multiaz-nat-gateway" { + type = bool + description = "Whether to deploy 1 NAT gateway for each AZ" + default = false +} + +variable "flow-log-destination" { + type = string + description = "Destination of flowlog. Valid destinations are s3 or cwlog" + default = null +} + +variable "flow-log-bucket-arn" { + type = string + default = null + description = "Arn of S3 bucket to be used for flow logging" +} + +variable "enable-flow-log" { + description = "Whether to enable VPC flowlog" + type = bool + default = true +} + +variable "vpcflowlog-retain-days" { + type = number + default = 90 + description = "Log retention period for CWlogs" +} + +variable "vpcflowlog-cwl-loggroup-key-arn" { + type = string + description = "KMS key arn for cwlog encryption" +} + +variable "create-free-vpc-endpoints" { + description = "Whether to deploy free VPC endpoints (s3 and dynamodb)" + type = bool + default = true +} + +variable "secondary_cidr_blocks" { + type = list(string) + description = "Additional cidr blocks" + default = [] +} \ No newline at end of file diff --git a/modules/networking/VpcSubnet/versions.tf b/modules/networking/VpcSubnet/versions.tf new file mode 100644 index 0000000..ceb041e --- /dev/null +++ b/modules/networking/VpcSubnet/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} \ No newline at end of file diff --git a/modules/networking/VpcSubnet/vpc-flowlog.tf b/modules/networking/VpcSubnet/vpc-flowlog.tf new file mode 100644 index 0000000..2f10904 --- /dev/null +++ b/modules/networking/VpcSubnet/vpc-flowlog.tf @@ -0,0 +1,81 @@ +resource "aws_flow_log" "vpc-flowlog" { + count = var.enable-flow-log && var.flow-log-destination == "cwlog" ? 1 : 0 + iam_role_arn = aws_iam_role.vpcflowlog-role[0].arn + log_destination = aws_cloudwatch_log_group.vpcflowlog-loggroup[0].arn + traffic_type = "ALL" + vpc_id = aws_vpc.vpc.id + tags = { + Name = "${var.resource-prefix}-vpcflowlog" + } +} + +resource "aws_flow_log" "vpc-flowlog-s3" { + count = var.enable-flow-log && var.flow-log-destination == "s3" ? 1 : 0 + log_destination_type = "s3" + log_destination = var.flow-log-bucket-arn + traffic_type = "ALL" + vpc_id = aws_vpc.vpc.id + tags = { + Name = "${var.resource-prefix}-vpcflowlog" + } +} + +resource "aws_cloudwatch_log_group" "vpcflowlog-loggroup" { + count = var.enable-flow-log && var.flow-log-destination == "cwlog" ? 1 : 0 + name_prefix = "vpcflowlog/${aws_vpc.vpc.id}/" + kms_key_id = var.vpcflowlog-cwl-loggroup-key-arn + retention_in_days = var.vpcflowlog-retain-days +} + +resource "random_id" "rid" { + byte_length = 2 +} + +resource "aws_iam_role" "vpcflowlog-role" { + count = var.enable-flow-log && var.flow-log-destination == "cwlog" ? 1 : 0 + name = "VpcFlowlogRole-${random_id.rid.dec}" + path = "/service/" + assume_role_policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Sid" : "", + "Effect" : "Allow", + "Principal" : { + "Service" : "vpc-flow-logs.amazonaws.com" + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) +} + +resource "aws_iam_role_policy" "vpcflowlog-role-policy" { + count = var.enable-flow-log && var.flow-log-destination == "cwlog" ? 1 : 0 + name = "VpcFlowlogRole-${random_id.rid.dec}" + role = aws_iam_role.vpcflowlog-role[0].id + + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Action" : [ + "logs:CreateLogGroup", + "logs:CreateLogStream", + "logs:PutLogEvents", + "logs:DescribeLogGroups", + "logs:DescribeLogStreams", + "kms:Encrypt", + "kms:ReEncrypt", + "kms:Decrypt" + ], + "Effect" : "Allow", + "Resource" : "*" + } + ] + } + ) +} diff --git a/modules/networking/delete-default-vpcs/README.md b/modules/networking/delete-default-vpcs/README.md new file mode 100644 index 0000000..a87e5c0 --- /dev/null +++ b/modules/networking/delete-default-vpcs/README.md @@ -0,0 +1,13 @@ +# delete-default-vpc module +This terraform module calls awscli to delete default vpc in specified region. + +## Example of root module +```terraform +data "aws_regions" "current" {} + +module delete-default-vpc { + source = "git::https://xpk.headdesk.me/git/xpk/terraform.aws-baseline-infra//modules/networking/delete-default-vpcs" + for_each = data.aws_regions.current.names + region-name = each.value +} +``` diff --git a/modules/networking/delete-default-vpcs/exec.sh b/modules/networking/delete-default-vpcs/exec.sh new file mode 100755 index 0000000..db63db5 --- /dev/null +++ b/modules/networking/delete-default-vpcs/exec.sh @@ -0,0 +1,23 @@ +#!/bin/bash + +region=$1 +vpc=$(aws ec2 --region ${region} describe-vpcs --filter Name=isDefault,Values=true | jq -r .Vpcs[0].VpcId) +if [ "${vpc}" = "null" ]; then + echo "No default vpc found" + exit 0 +fi + +aws ec2 --region ${region} describe-internet-gateways --filter Name=attachment.vpc-id,Values=${vpc} | jq -r '.InternetGateways[0].InternetGatewayId' | while read igw; do + echo "Removing internet gateway ${igw}" + aws ec2 --region ${region} detach-internet-gateway --internet-gateway-id ${igw} --vpc-id ${vpc} + aws ec2 --region ${region} delete-internet-gateway --internet-gateway-id ${igw} +done + +aws ec2 --region ${region} describe-subnets --filters Name=vpc-id,Values=${vpc} | jq -r '.Subnets[].SubnetId' | while read subnet; do + echo "Removing subnet ${subnet}" + aws ec2 --region ${region} delete-subnet --subnet-id ${subnet} +done + +echo "Removing vpc ${vpc}" +aws ec2 --region ${region} delete-vpc --vpc-id ${vpc} + diff --git a/modules/networking/delete-default-vpcs/main.tf b/modules/networking/delete-default-vpcs/main.tf new file mode 100644 index 0000000..ea8e4cd --- /dev/null +++ b/modules/networking/delete-default-vpcs/main.tf @@ -0,0 +1,8 @@ +data aws_regions all-aws-regions {} + +resource "null_resource" "shell" { + for_each = data.aws_regions.all-aws-regions.names + provisioner "local-exec" { + command = "/bin/bash -c '${path.module}/exec.sh ${each.value}'" + } +} \ No newline at end of file diff --git a/modules/networking/nacl/README.md b/modules/networking/nacl/README.md new file mode 100644 index 0000000..a431d9f --- /dev/null +++ b/modules/networking/nacl/README.md @@ -0,0 +1,23 @@ +# nacl module +This module takes in list(list(string)) and construct NACL using dynamic block. + +Example code in root module +```hcl +module "nacl" { + source = "../../modules/networking/nacl" + + egress_rules = [ + ["210", "-1", "0", "0", "10.29.0.0/16", "allow"], + ["220", "tcp", "443", "443", "10.35.32.0/22", "allow"], + ["230", "udp", "53", "53", "10.35.67.0/24", "allow"] + ] + ingress_rules = [ + ["310", "-1", "0", "0", "10.29.0.0/16", "allow"], + ["320", "tcp", "80", "81", "10.35.32.0/22", "allow"], + ["330", "udp", "53", "53", "10.35.67.0/24", "allow"] + ] + subnet_ids = ["subnet-0927ba1b06ccfe6c5", "subnet-0551e96ffd016192a"] + vpc_id = "vpc-01a10b033169f89a8" + acl_name = "test-nacl" +} +``` \ No newline at end of file diff --git a/modules/networking/nacl/main.tf b/modules/networking/nacl/main.tf new file mode 100644 index 0000000..58acfdf --- /dev/null +++ b/modules/networking/nacl/main.tf @@ -0,0 +1,32 @@ + +resource "aws_network_acl" "this" { + vpc_id = var.vpc_id + subnet_ids = var.subnet_ids + tags = { + Name = var.acl_name + } + dynamic "ingress" { + for_each = var.ingress_rules + content { + rule_no = ingress.value[0] + protocol = ingress.value[1] + from_port = ingress.value[2] + to_port = ingress.value[3] + cidr_block = ingress.value[4] + action = ingress.value[5] + } + } + + dynamic "egress" { + for_each = var.egress_rules + content { + rule_no = egress.value[0] + protocol = egress.value[1] + from_port = egress.value[2] + to_port = egress.value[3] + cidr_block = egress.value[4] + action = egress.value[5] + } + } + +} \ No newline at end of file diff --git a/modules/networking/nacl/provider.tf b/modules/networking/nacl/provider.tf new file mode 100644 index 0000000..356af51 --- /dev/null +++ b/modules/networking/nacl/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.0" + } + } +} diff --git a/modules/networking/nacl/variables.tf b/modules/networking/nacl/variables.tf new file mode 100644 index 0000000..13952c4 --- /dev/null +++ b/modules/networking/nacl/variables.tf @@ -0,0 +1,19 @@ +variable vpc_id { + type = string +} + +variable subnet_ids { + type = list(string) +} + +variable ingress_rules { + type = list(list(string)) +} + +variable egress_rules { + type = list(list(string)) +} + +variable acl_name { + type = string +} \ No newline at end of file diff --git a/modules/networking/r53-record-geo/README.md b/modules/networking/r53-record-geo/README.md new file mode 100644 index 0000000..9dd9767 --- /dev/null +++ b/modules/networking/r53-record-geo/README.md @@ -0,0 +1,19 @@ +# r53-record-geo sub module +Create route53 geolocation records + +## Example +```hcl +module "r53-www" { + source = "../../modules/networking/r53-record-geo" + + record_name = "www" + record_type = "A" + record_values = ["192.168.33.10"] + set_identifier = "Global web servers" + record_type_locational = "A" + record_values_locational = ["172.17.16.10"] + set_identifier_locational = "China web servers" + country_code = "CN" + zone_id = aws_route53_zone.zone.zone_id +} +``` \ No newline at end of file diff --git a/modules/networking/r53-record-geo/main.tf b/modules/networking/r53-record-geo/main.tf new file mode 100644 index 0000000..5be9e36 --- /dev/null +++ b/modules/networking/r53-record-geo/main.tf @@ -0,0 +1,60 @@ +resource "aws_route53_record" "default" { + zone_id = var.zone_id + name = var.record_name + type = var.record_type + ttl = length(var.alias) > 0 ? null : var.record_ttl + records = var.record_values + set_identifier = var.set_identifier + geolocation_routing_policy { + country = "*" + } + dynamic "alias" { + for_each = var.alias + content { + name = alias.value["name"] + zone_id = alias.value["zone_id"] + evaluate_target_health = alias.value["evaluate_target_health"] + } + } + dynamic "weighted_routing_policy" { + for_each = var.weighted_routing_policy + content { + weight = weighted_routing_policy.value["weight"] + } + } +} + +resource "aws_route53_record" "locational" { + zone_id = var.zone_id + name = var.record_name + type = var.record_type_locational + ttl = length(var.alias_locational) > 0 ? null : var.record_ttl_locational + records = var.record_values_locational + set_identifier = var.set_identifier_locational + dynamic "alias" { + for_each = var.alias_locational + content { + name = alias.value["name"] + zone_id = alias.value["zone_id"] + evaluate_target_health = alias.value["evaluate_target_health"] + } + } + geolocation_routing_policy { + country = var.country_code + continent = var.continent_code + } + dynamic "alias" { + for_each = var.alias_locational + content { + name = alias.value["name"] + zone_id = alias.value["zone_id"] + evaluate_target_health = alias.value["evaluate_target_health"] + } + } + dynamic "weighted_routing_policy" { + for_each = var.weighted_routing_policy_locational + content { + weight = weighted_routing_policy.value["weight"] + } + } +} \ No newline at end of file diff --git a/modules/networking/r53-record-geo/variables.tf b/modules/networking/r53-record-geo/variables.tf new file mode 100644 index 0000000..3e4ed15 --- /dev/null +++ b/modules/networking/r53-record-geo/variables.tf @@ -0,0 +1,62 @@ +variable "zone_id" {} +variable "record_name" {} +variable "record_type" {} +variable "record_ttl" { + type = number + default = 900 +} +variable "record_values" { + type = list(string) +} +variable "set_identifier" {} +variable "alias" { + type = list( + object({ + zone_id = string + name = string + evaluate_target_health = bool + }) + ) +} +variable "weighted_routing_policy" { + type = list( + object({ + weight = number + }) + ) + default = [] +} +variable "record_type_locational" {} +variable "record_ttl_locational" { + type = number + default = 900 +} +variable "record_values_locational" { + type = list(string) +} +variable "set_identifier_locational" {} +variable "country_code" { + type = string + default = null +} +variable "continent_code" { + type = string + default = null +} +variable "alias_locational" { + type = list( + object({ + zone_id = string + name = string + evaluate_target_health = bool + }) + ) +} +variable "weighted_routing_policy_locational" { + type = list( + object({ + weight = number + }) + ) + default = [] +} \ No newline at end of file diff --git a/modules/networking/r53-record/README.md b/modules/networking/r53-record/README.md new file mode 100644 index 0000000..f8f1304 --- /dev/null +++ b/modules/networking/r53-record/README.md @@ -0,0 +1,30 @@ +# r53-record sub module +Create route53 record + +## Example +```hcl +module "r53-ftp" { + source = "../../modules/networking/r53-record" + + record_name = "ftp" + record_type = "A" + record_values = ["192.168.0.100"] + zone_id = aws_route53_zone.zone.zone_id +} + +module "r53-www" { + source = "../../modules/networking/r53-record" + + record_name = "www" + record_type = "A" + record_values = null + alias = [ + { + zone_id = "Z2LIHJ7PKBEMWN" + name = "vpce-07b8a9af30673995f-2n2ird8h.ssm.ap-east-1.vpce.amazonaws.com" + evaluate_target_health = true + } + ] + zone_id = aws_route53_zone.zone.zone_id +} +``` \ No newline at end of file diff --git a/modules/networking/r53-record/main.tf b/modules/networking/r53-record/main.tf new file mode 100644 index 0000000..35ba90c --- /dev/null +++ b/modules/networking/r53-record/main.tf @@ -0,0 +1,22 @@ +resource "aws_route53_record" "this" { + zone_id = var.zone_id + name = var.record_name + type = var.record_type + ttl = length(var.alias) > 0 ? null : var.record_ttl + records = var.record_values + set_identifier = var.set_identifier + dynamic "alias" { + for_each = var.alias + content { + name = alias.value["name"] + zone_id = alias.value["zone_id"] + evaluate_target_health = alias.value["evaluate_target_health"] + } + } + dynamic "weighted_routing_policy" { + for_each = var.weighted_routing_policy + content { + weight = weighted_routing_policy.value["weight"] + } + } +} \ No newline at end of file diff --git a/modules/networking/r53-record/variables.tf b/modules/networking/r53-record/variables.tf new file mode 100644 index 0000000..1079b28 --- /dev/null +++ b/modules/networking/r53-record/variables.tf @@ -0,0 +1,32 @@ +variable "zone_id" {} +variable "record_name" {} +variable "record_type" {} +variable "record_ttl" { + type = number + default = 900 +} +variable "record_values" { + type = list(string) +} +variable "set_identifier" { + type = string + default = "" +} +variable "alias" { + type = list( + object({ + zone_id = string + name = string + evaluate_target_health = bool + }) + ) + default = [] +} +variable "weighted_routing_policy" { + type = list( + object({ + weight = number + }) + ) + default = [] +} \ No newline at end of file diff --git a/modules/networking/vpc-endpoints/README.md b/modules/networking/vpc-endpoints/README.md new file mode 100644 index 0000000..174018f --- /dev/null +++ b/modules/networking/vpc-endpoints/README.md @@ -0,0 +1,275 @@ +# vpc-endpoints module +This module deploys VPC endpoints. + +Automatically, this module performs the following additional tasks +- Create and attach security group which allows access from the same VPC +- Associate endpoints with 1 subnet in each availability zone + +# Inputs +| Variable | Type | Required | Description | +|-----------------------|--------------|----------|-------------------------------------------------| +| voc-id | string | yes | ID of VPC to deploy endpoints to | +| interface-ep-services | list(string) | yes | Interface endpoint names | +| gateway-ep-services | list(string) | no | Gateway endpoint names | +| resource-prefix | string | yes | Prefix that will be added to resource name tags | + + +# Types of endpoints +## Gateway endpoints +At time of writing, AWS provides 2 gateway endpoints at no charge. +* s3 +* dynamodb + +For gateway endpoints, all route tables in the VPC will be updated with routes to the private links. + +Full documentation: https://docs.aws.amazon.com/vpc/latest/privatelink/gateway-endpoints.html + +## Interface endpoints +Interface endpoints are placed in one subnet for every AZ. Security group is created automatically +and allow access from the VPC's cidr, plus all additional CIDRs if applicable. + +At time of writing, AWS provides 200+ interface endpoints: +* access-analyzer +* account +* execute-api +* appmesh +* appmesh-envoy-management +* apprunner +* apprunner.requests +* application-autoscaling +* mgn +* appstream.api +* appstream.streaming +* appsync-api +* athena +* auditmanager +* rds +* autoscaling-plans +* backup +* backup-gateway +* batch +* billingconductor +* braket +* cleanrooms +* cloudcontrolapi +* cloudcontrolapi-fips +* clouddirectory +* cloudformation +* cloudhsmv2 +* cloudtrail +* evidently +* evidently-dataplane +* monitoring +* rum +* rum-dataplane +* synthetics +* events +* logs +* codeartifact.api +* codeartifact.repositories +* codebuild +* codebuild-fips +* codecommit +* codecommit-fips +* git-codecommit +* git-codecommit-fips +* codedeploy +* codedeploy-commands-secure +* codeguru-profiler +* codeguru-reviewer +* codepipeline +* codestar-connections.api +* comprehend +* comprehendmedical +* config +* app-integrations +* cases +* connect-campaigns +* profile +* voiceid +* wisdom +* dataexchange +* dms +* dms-fips +* datasync +* devops-guru +* ds +* ebs +* ec2 +* autoscaling +* imagebuilder +* ecr.api +* ecr.dkr +* ecs +* ecs-agent +* ecs-telemetry +* eks +* elasticbeanstalk +* elasticbeanstalk-health +* drs +* elasticfilesystem +* elasticfilesystem-fips +* elastic-inference.runtime +* elasticloadbalancing +* elasticache +* elasticache-fips +* elasticmapreduce +* emr-containers +* emr-serverless +* events +* fis +* finspace +* finspace-api +* forecast +* forecastquery +* forecast-fips +* forecastquery-fips +* frauddetector +* fsx +* fsx-fips +* glue +* databrew +* grafana +* grafana-workspace +* groundstation +* guardduty-data +* guardduty-data-fips +* healthlake +* identitystore +* rolesanywhere +* inspector2 +* iot.data +* iot.fleethub.api +* deviceadvisor.iot +* iotwireless.api +* lorawan.cups +* lorawan.lns +* iotfleetwise +* greengrass +* iotroborunner +* iotsitewise.api +* iotsitewise.data +* iottwinmaker.api +* iottwinmaker.data +* kendra +* kendra-ranking +* kms +* kms-fips +* cassandra +* cassandra-fips +* kinesis-firehose +* kinesis-streams +* lakeformation +* lambda +* models-v2-lex +* runtime-v2-lex +* license-manager +* license-manager-fips +* lookoutequipment +* lookoutmetrics +* lookoutvision +* macie2 +* m2 +* aps +* aps-workspaces +* airflow.api +* airflow.env +* airflow.ops +* console +* signin +* memory-db +* memorydb-fips +* migrationhub-orchestrator +* refactor-spaces +* migrationhub-strategy +* nimble +* analytics-omics +* control-storage-omics +* storage-omics +* tags-omics +* workflows-omics +* service-managed +* panorama +* payment-cryptography.controlplane +* payment-cryptography.dataplane +* personalize +* personalize-events +* personalize-runtime +* pinpoint +* pinpoint-sms-voice-v2 +* polly +* private-networks +* acm-pca +* proton +* qldb.session +* rds +* rds-data +* redshift +* redshift-fips +* redshift-data +* rekognition +* rekognition-fips +* streaming-rekognition +* streaming-rekognition-fips +* robomaker +* s3 +* com.amazonaws.s3-global.accesspoint +* s3-outposts +* aws.sagemaker.region.notebook +* aws.sagemaker.region.studio +* sagemaker.api +* sagemaker.featurestore-runtime +* sagemaker.metrics +* sagemaker.runtime +* sagemaker.runtime-fips +* secretsmanager +* securityhub +* sts +* servicecatalog +* servicecatalog-appregistry +* email-smtp +* simspaceweaver +* snow-device-management +* sns +* sqs +* swf +* swf-fips +* states +* sync-states +* storagegateway +* ec2messages +* ssm +* ssm-contacts +* ssm-incidents +* ssmmessages +* tnb +* textract +* textract-fips +* transcribe +* transcribestreaming +* transcribe +* transcribestreaming +* transfer +* transfer.server +* translate +* verifiedpermissions +* vpc-lattice +* workspaces +* xray + + +Full documentation: https://docs.aws.amazon.com/vpc/latest/privatelink/aws-services-privatelink-support.html + + +## Example +```hcl +module "vpc-ep" { + count = var.create-free-vpc-endpoints ? 1 : 0 + source = "../vpc-endpoints" + + gateway-ep-services = ["s3", "dynamodb"] + interface-ep-services = [] + resource-prefix = var.resource-prefix + vpc-id = aws_vpc.vpc.id +} +``` \ No newline at end of file diff --git a/modules/networking/vpc-endpoints/main.tf b/modules/networking/vpc-endpoints/main.tf new file mode 100644 index 0000000..22f4ff6 --- /dev/null +++ b/modules/networking/vpc-endpoints/main.tf @@ -0,0 +1,102 @@ +data "aws_region" "this" {} +data "aws_default_tags" "this" { + lifecycle { + postcondition { + condition = length(self.tags) >= 1 + error_message = "Validation failed: Provider default_tags not set." + } + } +} + +resource "aws_vpc_endpoint" "vpc-interface-ep" { + for_each = toset(var.interface-ep-services) + vpc_id = data.aws_vpc.this-vpc.id + service_name = "com.amazonaws.${data.aws_region.this.name}.${each.value}" + vpc_endpoint_type = "Interface" + + security_group_ids = [ + aws_security_group.vpc-ep-sg.id, + ] + + # deploy to all subnets + subnet_ids = local.one_subnet_in_each_az + + private_dns_enabled = true + tags = { "Name" : "${var.resource-prefix}-vpcep-${each.value}" } + + lifecycle { + precondition { + condition = data.aws_vpc.this-vpc.enable_dns_support + error_message = "enableDnsSupport needs to be turned on." + } + } +} + +resource "aws_vpc_endpoint" "vpc-gateway-ep" { + for_each = toset(var.gateway-ep-services) + vpc_id = data.aws_vpc.this-vpc.id + service_name = "com.amazonaws.${data.aws_region.this.name}.${each.value}" + vpc_endpoint_type = "Gateway" + route_table_ids = data.aws_route_tables.this.ids + tags = { "Name" : "${var.resource-prefix}-vpcep-${each.value}" } +} + +resource "random_id" "rid" { + byte_length = 2 +} + +resource "aws_security_group" "vpc-ep-sg" { + name = "HttpsAccessToVpcEndpoints-${random_id.rid.dec}" + description = "HttpsAccessToVpcEndpoints-${random_id.rid.dec}" + vpc_id = data.aws_vpc.this-vpc.id + + ingress { + description = "TLS from VPC" + from_port = 443 + to_port = 443 + protocol = "tcp" + # cidr_blocks = [data.aws_vpc.this-vpc.cidr_block] + cidr_blocks = data.aws_vpc.this-vpc.cidr_block_associations.*.cidr_block + } + + egress { + from_port = 0 + to_port = 0 + protocol = "-1" + cidr_blocks = ["0.0.0.0/0"] + } + + tags = { "Name" : "VpcEpAccess" } +} + +data "aws_vpc" "this-vpc" { + id = var.vpc-id +} + +data "aws_availability_zones" "this" { + state = "available" +} + +# find all subnets for this vpc in all availability zones +data "aws_subnets" "subnets_and_az" { + for_each = toset(data.aws_availability_zones.this.zone_ids) + + filter { + name = "vpc-id" + values = [var.vpc-id] + } + + filter { + name = "availability-zone-id" + values = [each.value] + } +} + +data "aws_route_tables" "this" { + vpc_id = var.vpc-id +} + +locals { + # pick first subnet in each AZ + one_subnet_in_each_az = compact([for k, v in data.aws_subnets.subnets_and_az : try(element(v.ids, length(v.ids) - 1), "")]) +} diff --git a/modules/networking/vpc-endpoints/provider.tf b/modules/networking/vpc-endpoints/provider.tf new file mode 100644 index 0000000..ad7cae0 --- /dev/null +++ b/modules/networking/vpc-endpoints/provider.tf @@ -0,0 +1,11 @@ +# requires 1.3.0 for postcondition validation +# https://learn.hashicorp.com/tutorials/terraform/custom-conditions +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 3.75.2" + } + } +} diff --git a/modules/networking/vpc-endpoints/variables.tf b/modules/networking/vpc-endpoints/variables.tf new file mode 100644 index 0000000..ea4d12b --- /dev/null +++ b/modules/networking/vpc-endpoints/variables.tf @@ -0,0 +1,18 @@ +variable vpc-id {} +variable interface-ep-services { + type = list(string) + description = "List of interface endpoint. E.g. dkr,lambda,kms,elasticloadbalancing,execute-api,ec2,ssm,secretsmanager,monitoring,guardduty-data" +} +variable gateway-ep-services { + type = list(string) + default = [] + description = "s3 and dynamodb gateway endpoints are free." +} +variable resource-prefix {} +/* +variable secondary_cidrs { + type = list(string) + description = "Additional cidr blocks" + default = [] +} +*/ \ No newline at end of file diff --git a/modules/networking/vpc-subnet-manual-5r/README.md b/modules/networking/vpc-subnet-manual-5r/README.md new file mode 100644 index 0000000..b96b604 --- /dev/null +++ b/modules/networking/vpc-subnet-manual-5r/README.md @@ -0,0 +1,52 @@ +# Overview +This module performs the following tasks: + +- Create VPC, vpcflow log +- Create subnets in every AZ +- Create IGW, NGW +- Create s3 and ddb endpoints which are free + +## Subnet addressing + +Subnet cidrs needs to be specified manually + +## Inputs: + +| Name | Description | Type | Default | Required | +|---------------------------------|---------------------------------------------------|---------------|---------|----------| +| private-subnet-cidrs | private subnets | list | [] | yes | +| public-subnet-cidrs | public subnets | list | [] | yes | +| create-nat-gateway | whether to deploy NAT gateway for private subnets | bool | true | yes | +| vpc-cidr | VPC cidr | string | none | yes | +| enable-flowlog | whether to enable vpc flowlog | bool | true | yes | +| vpcflowlog-retain-days | number of days to retain vpc cloudwatch log | number | 90 | yes | +| vpcflowlog-cwl-loggroup-key-arn | kms key alias arn for log group encryption | string | none | yes | +| secondary_cidr_blocks | Additional CIDR blocks to be associated with VPC | list(string) | none | no | +| resource-prefix | Prefix of resource name | string | "" | yes | + + +## Outputs: + +| Name | Description | Type | +|-----------------------|-------------------------|---------| +| vpc_id | vpc id | string | +| public_subnets | list of cidr blocks | list | +| private_subnets | list of cidr blocks | list | +| secondary_cidr_blocks | list of secondary cidrs | list | + +## Example: + +```hcl +module "vpc-subnets" { + source = "../../modules/networking/vpc-subnet-manual" + + resource-prefix = local.resource-prefix + private-subnet-cidrs = ["172.17.0.0/24", "172.17.1.0/24"] + public-subnet-cidrs = ["172.17.10.0/24", "172.17.11.0/24"] + vpc-cidr = "172.17.0.0/16" + enable-flow-log = false + vpcflowlog-cwl-loggroup-key-arn = "" + create-nat-gateway = true + create-free-vpc-endpoints = true +} +``` \ No newline at end of file diff --git a/modules/networking/vpc-subnet-manual-5r/main.tf b/modules/networking/vpc-subnet-manual-5r/main.tf new file mode 100644 index 0000000..b65b65d --- /dev/null +++ b/modules/networking/vpc-subnet-manual-5r/main.tf @@ -0,0 +1,204 @@ +data "aws_caller_identity" "this" { + provider = aws.NetworkDeployer +} + +data "aws_availability_zones" "available-az" { + provider = aws.NetworkDeployer + state = "available" +} + +data "aws_default_tags" "this" { + lifecycle { + postcondition { + condition = length(self.tags) >= 1 + error_message = "Validation failed: Provider default_tags not set." + } + } +} + +locals { + no-az = 2 # hard-coding to 2AZ + vpc-cidr = var.vpc-cidr +} + +resource "aws_subnet" "private-subnets" { + provider = aws.NetworkDeployer + + count = length(var.private-subnet-cidrs) + vpc_id = aws_vpc.vpc.id + availability_zone = element(data.aws_availability_zones.available-az.names, count.index % 2) + cidr_block = var.private-subnet-cidrs[count.index] + tags = merge(data.aws_default_tags.this.tags, { + Name = "${var.resource-prefix}-private-${split("-", element(data.aws_availability_zones.available-az.names, count.index))[2]}-${count.index + 1}" + }) +} + +resource "aws_subnet" "public-subnets" { + provider = aws.NetworkDeployer + + count = length(var.public-subnet-cidrs) + vpc_id = aws_vpc.vpc.id + availability_zone = element(data.aws_availability_zones.available-az.names, count.index % 2) + cidr_block = var.public-subnet-cidrs[count.index] + tags = merge(data.aws_default_tags.this.tags, { + Name = "${var.resource-prefix}-public-${split("-", element(data.aws_availability_zones.available-az.names, count.index))[2]}-${count.index + 1}" + }) +} + +resource "aws_vpc" "vpc" { + provider = aws.NetworkDeployer + + cidr_block = var.vpc-cidr + enable_dns_hostnames = true + enable_dns_support = true + + tags = { + Name = "${var.resource-prefix}-vpc" + } + + lifecycle { + create_before_destroy = true + } +} + +resource "aws_vpc_ipv4_cidr_block_association" "additional_cidr" { + provider = aws.NetworkDeployer + + for_each = toset(var.secondary_cidr_blocks) + vpc_id = aws_vpc.vpc.id + cidr_block = each.value +} + +resource "aws_internet_gateway" "igw" { + provider = aws.NetworkDeployer + + count = length(var.public-subnet-cidrs) > 0 ? 1 : 0 + vpc_id = aws_vpc.vpc.id + + tags = { + Name = "${var.resource-prefix}-igw" + } +} + +resource "aws_eip" "ngw-eip" { + provider = aws.NetworkDeployer + + count = var.create-nat-gateway ? 1 : 0 + # deprecated # vpc = true + domain = "vpc" + depends_on = [aws_internet_gateway.igw] +} + +resource "aws_nat_gateway" "ngw" { + provider = aws.NetworkDeployer + + count = var.create-nat-gateway ? 1 : 0 + allocation_id = aws_eip.ngw-eip[0].id + subnet_id = aws_subnet.public-subnets[0].id + + tags = { + Name = "${var.resource-prefix}-ngw" + } + depends_on = [aws_internet_gateway.igw] +} + +resource "aws_route_table" "public-route-table" { + provider = aws.NetworkDeployer + + count = length(var.public-subnet-cidrs) > 0 ? 1 : 0 + vpc_id = aws_vpc.vpc.id + tags = { + Name = "${var.resource-prefix}-publicroutetable" + } +} + +resource "aws_route_table" "private-route-table" { + provider = aws.NetworkDeployer + + count = length(var.private-subnet-cidrs) > 0 ? 1 : 0 + vpc_id = aws_vpc.vpc.id + tags = { + Name = "${var.resource-prefix}-privateroutetable" + } +} + +resource "aws_route" "public-routes" { + provider = aws.NetworkDeployer + + count = length(var.public-subnet-cidrs) > 0 ? 1 : 0 + + destination_cidr_block = "0.0.0.0/0" + gateway_id = aws_internet_gateway.igw[0].id + route_table_id = aws_route_table.public-route-table[0].id +} + +resource "aws_route" "private-routes" { + provider = aws.NetworkDeployer + + count = length(var.private-subnet-cidrs) > 0 && var.create-nat-gateway ? 1 : 0 + + destination_cidr_block = "0.0.0.0/0" + nat_gateway_id = aws_nat_gateway.ngw[0].id + route_table_id = aws_route_table.private-route-table[0].id +} + +resource "aws_route_table_association" "public_route_association" { + provider = aws.NetworkDeployer + + count = length(aws_subnet.public-subnets) + route_table_id = aws_route_table.public-route-table[0].id + subnet_id = aws_subnet.public-subnets[count.index].id +} + +resource "aws_route_table_association" "private_route_association" { + provider = aws.NetworkDeployer + + count = length(aws_subnet.private-subnets) + route_table_id = aws_route_table.private-route-table[0].id + subnet_id = aws_subnet.private-subnets[count.index].id +} + +/* +harden default security group. the default sg created by aws allows all egress. +this resource limits ingress and egress from and to itself +*/ + +resource "aws_default_security_group" "default-sg" { + provider = aws.NetworkDeployer + + vpc_id = aws_vpc.vpc.id + ingress { + protocol = -1 + self = true + from_port = 0 + to_port = 0 + description = "Allow traffic coming from this SG" + } + egress { + from_port = 0 + protocol = -1 + to_port = 0 + self = true + description = "Allow traffic going to this SG" + } + tags = { + Name = "${var.resource-prefix}-defaultsg" + } +} + +# Enable gateway endpoints which are free + +module "vpc-ep" { + providers = { + aws = aws.NetworkDeployer + } + + count = var.create-free-vpc-endpoints ? 1 : 0 + source = "../vpc-endpoints" + + gateway-ep-services = ["s3", "dynamodb"] + interface-ep-services = [] + resource-prefix = var.resource-prefix + vpc-id = aws_vpc.vpc.id +} + diff --git a/modules/networking/vpc-subnet-manual-5r/outputs.tf b/modules/networking/vpc-subnet-manual-5r/outputs.tf new file mode 100644 index 0000000..89b527a --- /dev/null +++ b/modules/networking/vpc-subnet-manual-5r/outputs.tf @@ -0,0 +1,39 @@ +output "vpc_id" { + value = aws_vpc.vpc.id +} + +output "vpc-cidr" { + value = aws_vpc.vpc.cidr_block +} + +output "public_subnets" { + value = aws_subnet.public-subnets.*.cidr_block +} + +output "private_subnets" { + value = aws_subnet.private-subnets.*.cidr_block +} + +output "public-subnet-ids" { + value = aws_subnet.public-subnets.*.id +} + +output "private-subnet-ids" { + value = aws_subnet.private-subnets.*.id +} + +output "private-route-table-id" { + value = aws_route_table.private-route-table.*.id +} + +output "public-route-table-id" { + value = aws_route_table.public-route-table.*.id +} + +output "route_tables_for_gateway_endpoints" { + value = concat(aws_route_table.public-route-table.*.id, aws_route_table.private-route-table.*.id) +} + +output "secondary_cidr_blocks" { + value = var.secondary_cidr_blocks +} \ No newline at end of file diff --git a/modules/networking/vpc-subnet-manual-5r/provider.tf b/modules/networking/vpc-subnet-manual-5r/provider.tf new file mode 100644 index 0000000..f2caff6 --- /dev/null +++ b/modules/networking/vpc-subnet-manual-5r/provider.tf @@ -0,0 +1,15 @@ +# requires 1.3.0 for postcondition validation +# https://learn.hashicorp.com/tutorials/terraform/custom-conditions + +# provider 5.0.0 or above is required by the domain attribute in aws_eip +terraform { + required_version = "~> 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0.0" + configuration_aliases = [ aws.NetworkDeployer, aws.SecurityDeployer, aws.CommonDeployer ] + + } + } +} diff --git a/modules/networking/vpc-subnet-manual-5r/variables.tf b/modules/networking/vpc-subnet-manual-5r/variables.tf new file mode 100644 index 0000000..c2f6b74 --- /dev/null +++ b/modules/networking/vpc-subnet-manual-5r/variables.tf @@ -0,0 +1,37 @@ +variable resource-prefix {} + +# VPC variables +variable "vpc-cidr" {} + +variable "private-subnet-cidrs" { + type = list(any) +} + +variable "public-subnet-cidrs" { + type = list(any) +} + +variable "create-nat-gateway" { + type = bool + default = false +} +variable "enable-flow-log" { + type = bool + default = true +} +variable "vpcflowlog-retain-days" { + type = number + default = 90 +} +variable "vpcflowlog-cwl-loggroup-key-arn" {} +# variable "private-subnet-cidrs" {} +# variable "public-subnet-cidrs" {} +variable "create-free-vpc-endpoints" { + type = bool + default = true +} +variable "secondary_cidr_blocks" { + type = list(string) + description = "Additional cidr blocks" + default = [] +} \ No newline at end of file diff --git a/modules/networking/vpc-subnet-manual-5r/vpc-flowlog.tf b/modules/networking/vpc-subnet-manual-5r/vpc-flowlog.tf new file mode 100644 index 0000000..9b97622 --- /dev/null +++ b/modules/networking/vpc-subnet-manual-5r/vpc-flowlog.tf @@ -0,0 +1,71 @@ +resource "aws_flow_log" "vpc-flowlog" { + provider = aws.NetworkDeployer + count = var.enable-flow-log ? 1 : 0 + iam_role_arn = aws_iam_role.vpcflowlog-role.arn + log_destination = aws_cloudwatch_log_group.vpcflowlog-loggroup[0].arn + traffic_type = "ALL" + vpc_id = aws_vpc.vpc.id + tags = { + Name = "${var.resource-prefix}-vpcflowlog" + } +} + +resource "aws_cloudwatch_log_group" "vpcflowlog-loggroup" { + provider = aws.CommonDeployer + count = var.enable-flow-log ? 1 : 0 + + name_prefix = "vpcflowlog/${aws_vpc.vpc.id}/" + kms_key_id = var.vpcflowlog-cwl-loggroup-key-arn + + retention_in_days = var.vpcflowlog-retain-days +} + +resource "random_id" "rid" { + byte_length = 2 +} + +resource "aws_iam_role" "vpcflowlog-role" { + provider = aws.SecurityDeployer + name = "VpcFlowlogRole-${random_id.rid.dec}" + path = "/service/" + assume_role_policy = <=8 ? cidrsubnets(local.vpc-cidr, 4,4,4,4,4,4,4,4) : local.total-no-subnets >=6 ? cidrsubnets(local.vpc-cidr, 3,3,3,3,3,3) : local.total-no-subnets >=4 ? cidrsubnets(local.vpc-cidr, 2,2,2,2) : local.total-no-subnets >=2 ? cidrsubnets(local.vpc-cidr, 1,1) : null + simple-divide = local.total-no-subnets >= 12 ? cidrsubnets(local.vpc-cidr, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4) : local.total-no-subnets >= 8 ? cidrsubnets(local.vpc-cidr, 3, 3, 3, 3, 3, 3, 3, 3) : local.total-no-subnets >= 6 ? cidrsubnets(local.vpc-cidr, 3, 3, 3, 3, 3, 3) : local.total-no-subnets >= 4 ? cidrsubnets(local.vpc-cidr, 2, 2, 2, 2) : local.total-no-subnets >= 2 ? cidrsubnets(local.vpc-cidr, 1, 1) : null + public-subnets = slice(local.simple-divide, 0, var.number-of-public-subnets-per-az * local.no-az) + private-subnets = slice(local.simple-divide, var.number-of-public-subnets-per-az * local.no-az, local.total-no-subnets) +} + +resource "aws_subnet" "private-subnets" { + count = length(local.private-subnets) + # count = length(var.private-subnet-cidrs) + # count = var.number-of-private-subnets-per-az * length(data.aws_availability_zones.available-az.names) + vpc_id = aws_vpc.vpc.id + availability_zone = element(data.aws_availability_zones.available-az.names, count.index) + # cidr_block = cidrsubnet(local.subnet_start[0], 2, count.index) + # cidr_block = var.private-subnet-cidrs[count.index] + cidr_block = local.private-subnets[count.index] + tags = { + Name = "${local.resource-prefix}-private-${split("-", element(data.aws_availability_zones.available-az.names, count.index))[2]}-${count.index + 1}" + } +} + +resource "aws_subnet" "public-subnets" { + count = length(local.public-subnets) + # count = length(var.public-subnet-cidrs) + # count = var.number-of-public-subnets-per-az * length(data.aws_availability_zones.available-az.names) + vpc_id = aws_vpc.vpc.id + availability_zone = element(data.aws_availability_zones.available-az.names, count.index) + # cidr_block = cidrsubnet(local.subnet_start[1], 2, count.index) + # cidr_block = var.public-subnet-cidrs[count.index] + cidr_block = local.public-subnets[count.index] + tags = { + Name = "${local.resource-prefix}-public-${split("-", element(data.aws_availability_zones.available-az.names, count.index))[2]}-${count.index + 1}" + } +} + +resource "aws_vpc" "vpc" { + cidr_block = var.vpc-cidr + enable_dns_hostnames = true + enable_dns_support = true + + tags = { + Name = "${local.resource-prefix}-vpc" + } + + lifecycle { + create_before_destroy = true + } +} + +resource "aws_internet_gateway" "igw" { + count = var.number-of-public-subnets-per-az > 0 ? 1 : 0 + vpc_id = aws_vpc.vpc.id + + tags = { + Name = "${local.resource-prefix}-igw" + } +} + +resource "aws_eip" "ngw-eip" { + count = var.create-nat-gateway ? 1 : 0 + domain = "vpc" + depends_on = [aws_internet_gateway.igw] +} + +resource "aws_nat_gateway" "ngw" { + count = var.create-nat-gateway ? 1 : 0 + allocation_id = aws_eip.ngw-eip[0].id + subnet_id = aws_subnet.public-subnets[0].id + + tags = { + Name = "${local.resource-prefix}-ngw" + } + + depends_on = [aws_internet_gateway.igw] +} + +resource "aws_route_table" "public-route-table" { + count = var.number-of-public-subnets-per-az > 0 ? 1 : 0 + vpc_id = aws_vpc.vpc.id + tags = { + Name = "${local.resource-prefix}-public" + } +} + +resource "aws_route_table" "private-route-table" { + count = var.number-of-private-subnets-per-az > 0 ? 1 : 0 + vpc_id = aws_vpc.vpc.id + tags = { + Name = "${local.resource-prefix}-private" + } +} + +resource "aws_route" "public-routes" { + count = var.number-of-public-subnets-per-az > 0 ? 1 : 0 + + destination_cidr_block = "0.0.0.0/0" + gateway_id = aws_internet_gateway.igw[0].id + route_table_id = aws_route_table.public-route-table[0].id +} + +resource "aws_route" "private-routes" { + count = var.number-of-private-subnets-per-az > 0 && var.create-nat-gateway ? 1 : 0 + + destination_cidr_block = "0.0.0.0/0" + nat_gateway_id = aws_nat_gateway.ngw[0].id + route_table_id = aws_route_table.private-route-table[0].id +} + +resource "aws_route_table_association" "public_route_association" { + count = length(aws_subnet.public-subnets) + route_table_id = aws_route_table.public-route-table[0].id + subnet_id = aws_subnet.public-subnets[count.index].id +} + +resource "aws_route_table_association" "private_route_association" { + count = length(aws_subnet.private-subnets) + route_table_id = aws_route_table.private-route-table[0].id + subnet_id = aws_subnet.private-subnets[count.index].id +} + +/* +harden default security group. the default sg created by aws allows all egress. +this resource limits ingress and egress from and to itself +*/ + +resource "aws_default_security_group" "default-sg" { + vpc_id = aws_vpc.vpc.id + ingress { + protocol = -1 + self = true + from_port = 0 + to_port = 0 + description = "Allow traffic coming from this SG" + } + egress { + from_port = 0 + protocol = -1 + to_port = 0 + self = true + description = "Allow traffic going to this SG" + } + tags = { + Name = "${local.resource-prefix}-defaultsg" + } +} + +# Enable gateway endpoints which are free +module "vpc-ep" { + count = var.create-free-vpc-endpoints ? 1 : 0 + source = "../vpc-endpoints" + + gateway-ep-services = ["s3", "dynamodb"] + interface-ep-services = [] + resource-prefix = local.resource-prefix + vpc-id = aws_vpc.vpc.id +} \ No newline at end of file diff --git a/modules/security_identity_compliance/aws_config/Cis14Level1.yaml b/modules/security_identity_compliance/aws_config/Cis14Level1.yaml new file mode 100644 index 0000000..0c69e1d --- /dev/null +++ b/modules/security_identity_compliance/aws_config/Cis14Level1.yaml @@ -0,0 +1,601 @@ +################################################################################## +# +# Conformance Pack: +# Operational Best Practices for CIS AWS Foundations Benchmark Level 1 +# +# This conformance pack helps verify compliance with CIS AWS Foundations Benchmark Level 1 requirements. +# +# See Parameters section for names and descriptions of required parameters. +# +################################################################################## + +Parameters: + AccessKeysRotatedParamMaxAccessKeyAge: + Default: '90' + Type: String + IamPasswordPolicyParamMaxPasswordAge: + Default: '90' + Type: String + IamPasswordPolicyParamMinimumPasswordLength: + Default: '14' + Type: String + IamPasswordPolicyParamPasswordReusePrevention: + Default: '24' + Type: String + IamPasswordPolicyParamRequireLowercaseCharacters: + Default: 'true' + Type: String + IamPasswordPolicyParamRequireNumbers: + Default: 'true' + Type: String + IamPasswordPolicyParamRequireSymbols: + Default: 'true' + Type: String + IamPasswordPolicyParamRequireUppercaseCharacters: + Default: 'true' + Type: String + IamPolicyInUseParamPolicyARN: + Default: arn:aws:iam::aws:policy/AWSSupportAccess + Type: String + IamUserUnusedCredentialsCheckParamMaxCredentialUsageAge: + Default: '45' + Type: String + RestrictedIncomingTrafficParamBlockedPort3: + Default: '3389' + Type: String + S3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicAcls: + Default: 'True' + Type: String + S3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicPolicy: + Default: 'True' + Type: String + S3AccountLevelPublicAccessBlocksPeriodicParamIgnorePublicAcls: + Default: 'True' + Type: String + S3AccountLevelPublicAccessBlocksPeriodicParamRestrictPublicBuckets: + Default: 'True' + Type: String + S3BucketVersioningEnabledParamIsMfaDeleteEnabled: + Default: 'TRUE' + Type: String +Resources: + AccessKeysRotated: + Properties: + ConfigRuleName: access-keys-rotated + InputParameters: + maxAccessKeyAge: + Fn::If: + - accessKeysRotatedParamMaxAccessKeyAge + - Ref: AccessKeysRotatedParamMaxAccessKeyAge + - Ref: AWS::NoValue + Source: + Owner: AWS + SourceIdentifier: ACCESS_KEYS_ROTATED + Type: AWS::Config::ConfigRule + CloudTrailCloudWatchLogsEnabled: + Properties: + ConfigRuleName: cloud-trail-cloud-watch-logs-enabled + Source: + Owner: AWS + SourceIdentifier: CLOUD_TRAIL_CLOUD_WATCH_LOGS_ENABLED + Type: AWS::Config::ConfigRule + Ec2EbsEncryptionByDefault: + Properties: + ConfigRuleName: ec2-ebs-encryption-by-default + Source: + Owner: AWS + SourceIdentifier: EC2_EBS_ENCRYPTION_BY_DEFAULT + Type: AWS::Config::ConfigRule + EncryptedVolumes: + Properties: + ConfigRuleName: encrypted-volumes + Scope: + ComplianceResourceTypes: + - AWS::EC2::Volume + Source: + Owner: AWS + SourceIdentifier: ENCRYPTED_VOLUMES + Type: AWS::Config::ConfigRule + IamNoInlinePolicyCheck: + Properties: + ConfigRuleName: iam-no-inline-policy-check + Scope: + ComplianceResourceTypes: + - AWS::IAM::User + - AWS::IAM::Role + - AWS::IAM::Group + Source: + Owner: AWS + SourceIdentifier: IAM_NO_INLINE_POLICY_CHECK + Type: AWS::Config::ConfigRule + IamPasswordPolicy: + Properties: + ConfigRuleName: iam-password-policy + InputParameters: + MaxPasswordAge: + Fn::If: + - iamPasswordPolicyParamMaxPasswordAge + - Ref: IamPasswordPolicyParamMaxPasswordAge + - Ref: AWS::NoValue + MinimumPasswordLength: + Fn::If: + - iamPasswordPolicyParamMinimumPasswordLength + - Ref: IamPasswordPolicyParamMinimumPasswordLength + - Ref: AWS::NoValue + PasswordReusePrevention: + Fn::If: + - iamPasswordPolicyParamPasswordReusePrevention + - Ref: IamPasswordPolicyParamPasswordReusePrevention + - Ref: AWS::NoValue + RequireLowercaseCharacters: + Fn::If: + - iamPasswordPolicyParamRequireLowercaseCharacters + - Ref: IamPasswordPolicyParamRequireLowercaseCharacters + - Ref: AWS::NoValue + RequireNumbers: + Fn::If: + - iamPasswordPolicyParamRequireNumbers + - Ref: IamPasswordPolicyParamRequireNumbers + - Ref: AWS::NoValue + RequireSymbols: + Fn::If: + - iamPasswordPolicyParamRequireSymbols + - Ref: IamPasswordPolicyParamRequireSymbols + - Ref: AWS::NoValue + RequireUppercaseCharacters: + Fn::If: + - iamPasswordPolicyParamRequireUppercaseCharacters + - Ref: IamPasswordPolicyParamRequireUppercaseCharacters + - Ref: AWS::NoValue + Source: + Owner: AWS + SourceIdentifier: IAM_PASSWORD_POLICY + Type: AWS::Config::ConfigRule + IamPolicyInUse: + Properties: + ConfigRuleName: iam-policy-in-use + InputParameters: + policyARN: + Fn::If: + - iamPolicyInUseParamPolicyARN + - Ref: IamPolicyInUseParamPolicyARN + - Ref: AWS::NoValue + Source: + Owner: AWS + SourceIdentifier: IAM_POLICY_IN_USE + Type: AWS::Config::ConfigRule + IamPolicyNoStatementsWithAdminAccess: + Properties: + ConfigRuleName: iam-policy-no-statements-with-admin-access + Scope: + ComplianceResourceTypes: + - AWS::IAM::Policy + Source: + Owner: AWS + SourceIdentifier: IAM_POLICY_NO_STATEMENTS_WITH_ADMIN_ACCESS + Type: AWS::Config::ConfigRule + IamRootAccessKeyCheck: + Properties: + ConfigRuleName: iam-root-access-key-check + Source: + Owner: AWS + SourceIdentifier: IAM_ROOT_ACCESS_KEY_CHECK + Type: AWS::Config::ConfigRule + IamUserGroupMembershipCheck: + Properties: + ConfigRuleName: iam-user-group-membership-check + Scope: + ComplianceResourceTypes: + - AWS::IAM::User + Source: + Owner: AWS + SourceIdentifier: IAM_USER_GROUP_MEMBERSHIP_CHECK + Type: AWS::Config::ConfigRule + IamUserNoPoliciesCheck: + Properties: + ConfigRuleName: iam-user-no-policies-check + Scope: + ComplianceResourceTypes: + - AWS::IAM::User + Source: + Owner: AWS + SourceIdentifier: IAM_USER_NO_POLICIES_CHECK + Type: AWS::Config::ConfigRule + IamUserUnusedCredentialsCheck: + Properties: + ConfigRuleName: iam-user-unused-credentials-check + InputParameters: + maxCredentialUsageAge: + Fn::If: + - iamUserUnusedCredentialsCheckParamMaxCredentialUsageAge + - Ref: IamUserUnusedCredentialsCheckParamMaxCredentialUsageAge + - Ref: AWS::NoValue + Source: + Owner: AWS + SourceIdentifier: IAM_USER_UNUSED_CREDENTIALS_CHECK + Type: AWS::Config::ConfigRule + IncomingSshDisabled: + Properties: + ConfigRuleName: restricted-ssh + Scope: + ComplianceResourceTypes: + - AWS::EC2::SecurityGroup + Source: + Owner: AWS + SourceIdentifier: INCOMING_SSH_DISABLED + Type: AWS::Config::ConfigRule + MfaEnabledForIamConsoleAccess: + Properties: + ConfigRuleName: mfa-enabled-for-iam-console-access + Source: + Owner: AWS + SourceIdentifier: MFA_ENABLED_FOR_IAM_CONSOLE_ACCESS + Type: AWS::Config::ConfigRule + MultiRegionCloudTrailEnabled: + Properties: + ConfigRuleName: multi-region-cloudtrail-enabled + Source: + Owner: AWS + SourceIdentifier: MULTI_REGION_CLOUD_TRAIL_ENABLED + Type: AWS::Config::ConfigRule + RdsSnapshotEncrypted: + Properties: + ConfigRuleName: rds-snapshot-encrypted + Scope: + ComplianceResourceTypes: + - AWS::RDS::DBSnapshot + - AWS::RDS::DBClusterSnapshot + Source: + Owner: AWS + SourceIdentifier: RDS_SNAPSHOT_ENCRYPTED + Type: AWS::Config::ConfigRule + RdsStorageEncrypted: + Properties: + ConfigRuleName: rds-storage-encrypted + Scope: + ComplianceResourceTypes: + - AWS::RDS::DBInstance + Source: + Owner: AWS + SourceIdentifier: RDS_STORAGE_ENCRYPTED + Type: AWS::Config::ConfigRule + RestrictedIncomingTraffic: + Properties: + ConfigRuleName: restricted-common-ports + InputParameters: + blockedPort3: + Fn::If: + - restrictedIncomingTrafficParamBlockedPort3 + - Ref: RestrictedIncomingTrafficParamBlockedPort3 + - Ref: AWS::NoValue + Scope: + ComplianceResourceTypes: + - AWS::EC2::SecurityGroup + Source: + Owner: AWS + SourceIdentifier: RESTRICTED_INCOMING_TRAFFIC + Type: AWS::Config::ConfigRule + RootAccountMfaEnabled: + Properties: + ConfigRuleName: root-account-mfa-enabled + Source: + Owner: AWS + SourceIdentifier: ROOT_ACCOUNT_MFA_ENABLED + Type: AWS::Config::ConfigRule + S3AccountLevelPublicAccessBlocksPeriodic: + Properties: + ConfigRuleName: s3-account-level-public-access-blocks-periodic + InputParameters: + BlockPublicAcls: + Fn::If: + - s3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicAcls + - Ref: S3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicAcls + - Ref: AWS::NoValue + BlockPublicPolicy: + Fn::If: + - s3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicPolicy + - Ref: S3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicPolicy + - Ref: AWS::NoValue + IgnorePublicAcls: + Fn::If: + - s3AccountLevelPublicAccessBlocksPeriodicParamIgnorePublicAcls + - Ref: S3AccountLevelPublicAccessBlocksPeriodicParamIgnorePublicAcls + - Ref: AWS::NoValue + RestrictPublicBuckets: + Fn::If: + - s3AccountLevelPublicAccessBlocksPeriodicParamRestrictPublicBuckets + - Ref: S3AccountLevelPublicAccessBlocksPeriodicParamRestrictPublicBuckets + - Ref: AWS::NoValue + Source: + Owner: AWS + SourceIdentifier: S3_ACCOUNT_LEVEL_PUBLIC_ACCESS_BLOCKS_PERIODIC + Type: AWS::Config::ConfigRule + S3BucketLevelPublicAccessProhibited: + Properties: + ConfigRuleName: s3-bucket-level-public-access-prohibited + Scope: + ComplianceResourceTypes: + - AWS::S3::Bucket + Source: + Owner: AWS + SourceIdentifier: S3_BUCKET_LEVEL_PUBLIC_ACCESS_PROHIBITED + Type: AWS::Config::ConfigRule + S3BucketLoggingEnabled: + Properties: + ConfigRuleName: s3-bucket-logging-enabled + Scope: + ComplianceResourceTypes: + - AWS::S3::Bucket + Source: + Owner: AWS + SourceIdentifier: S3_BUCKET_LOGGING_ENABLED + Type: AWS::Config::ConfigRule + S3BucketPublicReadProhibited: + Properties: + ConfigRuleName: s3-bucket-public-read-prohibited + Scope: + ComplianceResourceTypes: + - AWS::S3::Bucket + Source: + Owner: AWS + SourceIdentifier: S3_BUCKET_PUBLIC_READ_PROHIBITED + Type: AWS::Config::ConfigRule + S3BucketPublicWriteProhibited: + Properties: + ConfigRuleName: s3-bucket-public-write-prohibited + Scope: + ComplianceResourceTypes: + - AWS::S3::Bucket + Source: + Owner: AWS + SourceIdentifier: S3_BUCKET_PUBLIC_WRITE_PROHIBITED + Type: AWS::Config::ConfigRule + S3BucketVersioningEnabled: + Properties: + ConfigRuleName: s3-bucket-versioning-enabled + InputParameters: + isMfaDeleteEnabled: + Fn::If: + - s3BucketVersioningEnabledParamIsMfaDeleteEnabled + - Ref: S3BucketVersioningEnabledParamIsMfaDeleteEnabled + - Ref: AWS::NoValue + Scope: + ComplianceResourceTypes: + - AWS::S3::Bucket + Source: + Owner: AWS + SourceIdentifier: S3_BUCKET_VERSIONING_ENABLED + Type: AWS::Config::ConfigRule + AccountContactDetailsConfigured: + Properties: + ConfigRuleName: account-contact-details-configured + Description: Ensure the contact email and telephone number for AWS accounts are current and map to more than one individual in your organization. Within the My Account section of the console ensure correct information is specified in the Contact Information section. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AccountSecurityContactConfigured: + Properties: + ConfigRuleName: account-security-contact-configured + Description: Ensure the contact email and telephone number for the your organizations security team are current. Within the My Account section of the AWS Management Console ensure the correct information is specified in the Security section. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AccountSecurityQuestionsConfigured: + Properties: + ConfigRuleName: account-security-questions-configured + Description: Ensure the security questions that can be used to authenticate individuals calling AWS customer service for support are configured. Within the My Account section of the AWS Management Console ensure three security challenge questions are configured. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + RootAccountRegularUse: + Properties: + ConfigRuleName: root-account-regular-use + Description: Ensure the use of the root account is avoided for everyday tasks. Within IAM, run a credential report to examine when the root user was last used. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + IAMUserConsoleAndAPIAccessAtCreation: + Properties: + ConfigRuleName: iam-user-console-and-api-access-at-creation + Description: Ensure access keys are not setup during the initial user setup for all IAM users that have a console password. For all IAM users with console access, compare the user 'Creation time` to the Access Key `Created` date. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + IAMUserSingleAccessKey: + Properties: + ConfigRuleName: iam-user-single-access-key + Description: Ensure there is only one active access key available for any single IAM user. For all IAM users check that there is only one active key used within the Security Credentials tab for each user within IAM. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + IAMExpiredCertificates: + Properties: + ConfigRuleName: iam-expired-certificates + Description: Ensure that all the expired SSL/TLS certificates stored in IAM are removed. From the command line with the installed AWS CLI run the 'aws iam list-server-certificates' command and determine if there are any expired server certificates. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + IAMAccessAnalyzerEnabled: + Properties: + ConfigRuleName: iam-access-analyzer-enabled + Description: Ensure that IAM Access analyzer is enabled. Within the IAM section of the console, select Access analyzer and ensure that the STATUS is set to Active. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmUnauthorizedAPIcalls: + Properties: + ConfigRuleName: alarm-unauthorized-api-calls + Description: Ensure a log metric filter and an alarm exists for unauthorized API calls. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmSignInWithoutMFA: + Properties: + ConfigRuleName: alarm-sign-in-without-mfa + Description: Ensure a log metric filter and an alarm exists for AWS Management Console sign-in without Multi-Factor Authentication (MFA). + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmRootAccountUse: + Properties: + ConfigRuleName: alarm-root-account-use + Description: Ensure a log metric filter and an alarm exists for usage of the root account. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmIAMpolicyChange: + Properties: + ConfigRuleName: alarm-iam-policy-change + Description: Ensure a log metric filter and an alarm exists for IAM policy changes. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmCloudtrailConfigChange: + Properties: + ConfigRuleName: alarm-cloudtrail-config-change + Description: Ensure a log metric filter and an alarm exists for AWS CloudTrail configuration changes. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmS3BucketPolicyChange: + Properties: + ConfigRuleName: alarm-s3-bucket-policy-change + Description: Ensure a log metric filter and an alarm exists for Amazon S3 bucket policy changes. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmVPCNetworkGatewayChange: + Properties: + ConfigRuleName: alarm-vpc-network-gateway-change + Description: Ensure a log metric filter and an alarm exists for changes to network gateways. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmVPCroutetableChange: + Properties: + ConfigRuleName: alarm-vpc-route-table-change + Description: Ensure a log metric filter and an alarm exists for route table changes. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmVPCChange: + Properties: + ConfigRuleName: alarm-vpc-change + Description: Ensure a log metric filter and an alarm exists for Amazon Virtual Private Cloud (VPC) changes. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + AlarmOrganizationsChange: + Properties: + ConfigRuleName: alarm-organizations-change + Description: Ensure a log metric filter and an alarm exists for AWS Organizations changes. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule + VPCNetworkACLOpenAdminPorts: + Properties: + ConfigRuleName: vpc-networkacl-open-admin-ports + Description: Ensure no network ACLs allow public ingress to the remote server administration ports. Within the VPC section of the console, ensure there are network ACLs with a source of '0.0.0.0/0' with allowing ports or port ranges including remote server admin ports. + Source: + Owner: AWS + SourceIdentifier: AWS_CONFIG_PROCESS_CHECK + Type: AWS::Config::ConfigRule +Conditions: + accessKeysRotatedParamMaxAccessKeyAge: + Fn::Not: + - Fn::Equals: + - '' + - Ref: AccessKeysRotatedParamMaxAccessKeyAge + iamPasswordPolicyParamMaxPasswordAge: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamPasswordPolicyParamMaxPasswordAge + iamPasswordPolicyParamMinimumPasswordLength: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamPasswordPolicyParamMinimumPasswordLength + iamPasswordPolicyParamPasswordReusePrevention: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamPasswordPolicyParamPasswordReusePrevention + iamPasswordPolicyParamRequireLowercaseCharacters: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamPasswordPolicyParamRequireLowercaseCharacters + iamPasswordPolicyParamRequireNumbers: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamPasswordPolicyParamRequireNumbers + iamPasswordPolicyParamRequireSymbols: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamPasswordPolicyParamRequireSymbols + iamPasswordPolicyParamRequireUppercaseCharacters: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamPasswordPolicyParamRequireUppercaseCharacters + iamPolicyInUseParamPolicyARN: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamPolicyInUseParamPolicyARN + iamUserUnusedCredentialsCheckParamMaxCredentialUsageAge: + Fn::Not: + - Fn::Equals: + - '' + - Ref: IamUserUnusedCredentialsCheckParamMaxCredentialUsageAge + restrictedIncomingTrafficParamBlockedPort3: + Fn::Not: + - Fn::Equals: + - '' + - Ref: RestrictedIncomingTrafficParamBlockedPort3 + s3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicAcls: + Fn::Not: + - Fn::Equals: + - '' + - Ref: S3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicAcls + s3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicPolicy: + Fn::Not: + - Fn::Equals: + - '' + - Ref: S3AccountLevelPublicAccessBlocksPeriodicParamBlockPublicPolicy + s3AccountLevelPublicAccessBlocksPeriodicParamIgnorePublicAcls: + Fn::Not: + - Fn::Equals: + - '' + - Ref: S3AccountLevelPublicAccessBlocksPeriodicParamIgnorePublicAcls + s3AccountLevelPublicAccessBlocksPeriodicParamRestrictPublicBuckets: + Fn::Not: + - Fn::Equals: + - '' + - Ref: S3AccountLevelPublicAccessBlocksPeriodicParamRestrictPublicBuckets + s3BucketVersioningEnabledParamIsMfaDeleteEnabled: + Fn::Not: + - Fn::Equals: + - '' + - Ref: S3BucketVersioningEnabledParamIsMfaDeleteEnabled diff --git a/modules/security_identity_compliance/aws_config/README.md b/modules/security_identity_compliance/aws_config/README.md new file mode 100644 index 0000000..1f41ce1 --- /dev/null +++ b/modules/security_identity_compliance/aws_config/README.md @@ -0,0 +1,25 @@ +# Overview +This module performs the following tasks: + +- Enable AWS config in all regions +- Deploy [CIS1.4 level 1 conformance pack](https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-cis_aws_benchmark_level_1.html). Rules file Cis14Level1.yaml is downloaded from https://raw.githubusercontent.com/awslabs/aws-config-rules/master/aws-config-conformance-packs/Operational-Best-Practices-for-CIS-AWS-v1.4-Level1.yaml +- Set Config retention period +- Setup Config aggregator, aggregate Config in all regions into primary region +- Create s3 bucket for config use + +## Inputs: +| Name | Description | Type | Default | Required | +|--------------------|-------------------------------------------------------------|------|---------|:-----:| +| application | name of application | string | none | yes | +| environment | capacity of environment (prd/dev/lab) | string | none | yes | +| customer-name | owner of aws resources | string | none | yes | +| project | name of project | string | none | yes | +| default-tags | tags to be added to resources | list | none | yes | +| aws-region-short | short name of aws region (e.g. apne1) | string | none | yes | +| primary-aws-region | name of primary region where global events will be recorded | string | none | yes | + + +# Notes +- It takes a while for AWS to process Config changes. +- [AWS managed config rules](https://docs.aws.amazon.com/config/latest/developerguide/managed-rules-by-aws-config.html) are automatically applied. Those rule may duplicate with Cis1.4. + diff --git a/modules/security_identity_compliance/aws_config/cis-rules.tf-no b/modules/security_identity_compliance/aws_config/cis-rules.tf-no new file mode 100644 index 0000000..6a8eacd --- /dev/null +++ b/modules/security_identity_compliance/aws_config/cis-rules.tf-no @@ -0,0 +1,122 @@ +// Config rules from asecure.cloud https://asecure.cloud/p/monitoring_cis_benchmark/ +// Conformance pack has not been made available to terraform https://github.com/hashicorp/terraform-provider-aws/issues/11098 + +resource "aws_config_config_rule" "ConfigRule1" { + name = "mfa-enabled-for-iam-console-access" + description = "A Config rule that checks whether AWS Multi-Factor Authentication (MFA) is enabled for all AWS Identity and Access Management (IAM) users that use a console password. The rule is COMPLIANT if MFA is enabled." + + source { + owner = "AWS" + source_identifier = "MFA_ENABLED_FOR_IAM_CONSOLE_ACCESS" + } + scope { + compliance_resource_types = [] + } +} + +resource "aws_config_config_rule" "ConfigRule2" { + name = "iam-user-unused-credentials-check" + description = "A config rule that checks whether your AWS Identity and Access Management (IAM) users have passwords or active access keys that have not been used within the specified number of days you provided. Re-evaluating this rule within 4 hours of the first eva..." + input_parameters = "{\"maxCredentialUsageAge\":\"90\"}" + + source { + owner = "AWS" + source_identifier = "IAM_USER_UNUSED_CREDENTIALS_CHECK" + } + scope { + compliance_resource_types = [] + } +} + +resource "aws_config_config_rule" "ConfigRule3" { + name = "access-keys-rotated" + description = "A config rule that checks whether the active access keys are rotated within the number of days specified in maxAccessKeyAge. The rule is NON_COMPLIANT if the access keys have not been rotated for more than maxAccessKeyAge number of days." + input_parameters = "{\"maxAccessKeyAge\":\"90\"}" + + source { + owner = "AWS" + source_identifier = "ACCESS_KEYS_ROTATED" + } + scope { + compliance_resource_types = [] + } +} + +resource "aws_config_config_rule" "ConfigRule4" { + name = "iam-password-policy" + description = "A Config rule that checks whether the account password policy for IAM users meets the specified requirements." + input_parameters = "{\"RequireUppercaseCharacters\":\"true\",\"RequireLowercaseCharacters\":\"true\",\"RequireSymbols\":\"true\",\"RequireNumbers\":\"true\",\"MinimumPasswordLength\":\"14\",\"PasswordReusePrevention\":\"24\",\"MaxPasswordAge\":\"90\"}" + + source { + owner = "AWS" + source_identifier = "IAM_PASSWORD_POLICY" + } + scope { + compliance_resource_types = [] + } +} + +resource "aws_config_config_rule" "ConfigRule5" { + name = "iam-root-access-key-check" + description = "A config rule that checks whether the root user access key is available. The rule is COMPLIANT if the user access key does not exist." + + source { + owner = "AWS" + source_identifier = "IAM_ROOT_ACCESS_KEY_CHECK" + } + scope { + compliance_resource_types = [] + } +} + +resource "aws_config_config_rule" "ConfigRule6" { + name = "root-account-mfa-enabled" + description = "A Config rule that checks whether users of your AWS account require a multi-factor authentication (MFA) device to sign in with root credentials." + + source { + owner = "AWS" + source_identifier = "ROOT_ACCOUNT_MFA_ENABLED" + } + scope { + compliance_resource_types = [] + } +} + +resource "aws_config_config_rule" "ConfigRule7" { + name = "root-account-hardware-mfa-enabled" + description = "A config rule that checks whether your AWS account is enabled to use multi-factor authentication (MFA) hardware device to sign in with root credentials. The rule is NON_COMPLIANT if any virtual MFA devices are permitted for signing in with root credent..." + + source { + owner = "AWS" + source_identifier = "ROOT_ACCOUNT_HARDWARE_MFA_ENABLED" + } + scope { + compliance_resource_types = [] + } +} + +resource "aws_config_config_rule" "ConfigRule8" { + name = "iam-user-no-policies-check" + description = "A Config rule that checks that none of your IAM users have policies attached. IAM users must inherit permissions from IAM groups or roles." + + source { + owner = "AWS" + source_identifier = "IAM_USER_NO_POLICIES_CHECK" + } + scope { + compliance_resource_types = ["AWS::IAM::User"] + } +} + +resource "aws_config_config_rule" "ConfigRule11" { + name = "iam-policy-no-statements-with-admin-access" + description = "A config rule that checks whether the default version of AWS Identity and Access Management (IAM) policies do not have administrator access. If any statement has 'Effect': 'Allow' with 'Action': '*' over 'Resource': '*', the rule is NON_COMPLIANT." + + source { + owner = "AWS" + source_identifier = "IAM_POLICY_NO_STATEMENTS_WITH_ADMIN_ACCESS" + } + scope { + compliance_resource_types = ["AWS::IAM::Policy"] + } +} \ No newline at end of file diff --git a/modules/security_identity_compliance/aws_config/main.tf b/modules/security_identity_compliance/aws_config/main.tf new file mode 100644 index 0000000..274350e --- /dev/null +++ b/modules/security_identity_compliance/aws_config/main.tf @@ -0,0 +1,154 @@ +/* + AWS Config Service + If config is already enabled, import it with + terraform import aws_config_configuration_recorder.config-recorder default +*/ + +data aws_caller_identity this {} +data aws_regions all-regions {} + +resource "aws_iam_service_linked_role" "config" { + aws_service_name = "config.amazonaws.com" +} + +resource null_resource cli-resource-awsconfig { + for_each = data.aws_regions.all-regions.names + provisioner "local-exec" { + when = create + command = <<-EOD + aws configservice --region ${each.value} put-configuration-recorder --configuration-recorder name=default,roleARN="${aws_iam_service_linked_role.config.arn}" --recording-group allSupported=true,includeGlobalResourceTypes=false + aws configservice --region ${each.value} put-delivery-channel --delivery-channel name=default,s3BucketName=${module.config-bucket.bucket-name},configSnapshotDeliveryProperties={deliveryFrequency=Twelve_Hours} + aws configservice --region ${each.value} put-retention-configuration --retention-period-in-days ${var.config-retention-days} + aws configservice --region ${each.value} put-conformance-pack --conformance-pack-name Cis14Level1 --template-body file://Cis14Level1.yaml + aws configservice --region ${each.value} start-configuration-recorder --configuration-recorder-name default + if [ \"${each.value}\" == \"${var.primary-aws-region}\" ]; then + aws configservice --region ${each.value} put-configuration-recorder --configuration-recorder name=default,roleARN="${aws_iam_service_linked_role.config.arn}" --recording-group allSupported=true,includeGlobalResourceTypes=true + fi +EOD + } + + // Destroy provisioner does not accept variables. Workaround is to delete recorder in all regions. + provisioner "local-exec" { + when = destroy + on_failure = continue + command = <<-EOD + aws ec2 describe-regions | jq -cr .Regions[].RegionName | while read r; do + aws configservice --region $r describe-configuration-recorders --output text | while read dummy; do + aws configservice --region $r stop-configuration-recorder --configuration-recorder-name default + aws configservice --region $r delete-delivery-channel --delivery-channel-name default + aws configservice --region $r delete-configuration-recorder --configuration-recorder-name default + done + done +EOD + } +} + +resource "aws_config_configuration_aggregator" "config-aggregator" { + depends_on = [null_resource.cli-resource-awsconfig] + name = "ConfigAggregator" + + account_aggregation_source { + account_ids = [data.aws_caller_identity.this.id] + all_regions = true + } +} + +/* +resource "aws_config_configuration_recorder" "config-recorder" { + name = "${local.resource-prefix}-awsconfig" + role_arn = aws_iam_service_linked_role.config.arn + + recording_group { + all_supported = true + include_global_resource_types = true + } +} + +resource "aws_config_delivery_channel" "config-delivery-channel" { + name = "${local.resource-prefix}-configdeliverychannel" + s3_bucket_name = module.config-bucket.bucket-name + + depends_on = [aws_config_configuration_recorder.config-recorder] +} + +resource "aws_config_configuration_recorder_status" "main" { + name = aws_config_configuration_recorder.config-recorder.name + is_enabled = true + depends_on = [aws_config_delivery_channel.config-delivery-channel] +} +*/ + +######## Config Bucket - Policy ######## + +module config-bucket { + source = "../../storage/infra-s3-bucket" + bucket-name = "${var.resource-prefix}-configbucket-${data.aws_caller_identity.this.account_id}" + add-random-suffix = false + bucket-policy-json = data.aws_iam_policy_document.config_bucket_policy.json + default-tags = var.default-tags +} + +data "aws_iam_policy_document" "config_bucket_policy" { + + statement { + sid = "AWSConfigBucketPermissionsCheck" + + principals { + type = "Service" + identifiers = ["config.amazonaws.com"] + } + + actions = [ + "s3:GetBucketAcl", + ] + + resources = [ + "arn:aws:s3:::${var.resource-prefix}-configbucket-${data.aws_caller_identity.this.account_id}", + ] + } + + statement { + sid = "AWSConfigBucketExistenceCheck" + + principals { + type = "Service" + identifiers = ["config.amazonaws.com"] + } + + actions = [ + "s3:ListBucket", + ] + + resources = [ + "arn:aws:s3:::${var.resource-prefix}-configbucket-${data.aws_caller_identity.this.account_id}", + ] + } + + statement { + sid = "AWSConfigBucketDelivery" + + principals { + type = "Service" + identifiers = ["config.amazonaws.com"] + } + + actions = [ + "s3:PutObject", + ] + + resources = [ + "arn:aws:s3:::${var.resource-prefix}-configbucket-${data.aws_caller_identity.this.account_id}/*", + ] + + condition { + test = "StringEquals" + variable = "s3:x-amz-acl" + + values = [ + "bucket-owner-full-control", + ] + } + } +} + + diff --git a/modules/security_identity_compliance/aws_config/provider.tf b/modules/security_identity_compliance/aws_config/provider.tf new file mode 100644 index 0000000..2387c08 --- /dev/null +++ b/modules/security_identity_compliance/aws_config/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.2.5" + required_providers { + aws = { + source = "hashicorp/aws" + version = "~> 3.75.2" + } + } +} \ No newline at end of file diff --git a/modules/security_identity_compliance/aws_config/variables.tf b/modules/security_identity_compliance/aws_config/variables.tf new file mode 100644 index 0000000..78b77dc --- /dev/null +++ b/modules/security_identity_compliance/aws_config/variables.tf @@ -0,0 +1,9 @@ +variable "default-tags" {} +variable resource-prefix {} + +variable config-retention-days { + type = number + default = 365 +} + +variable primary-aws-region {} \ No newline at end of file diff --git a/modules/security_identity_compliance/cloudtrail_cwlogs/README.md b/modules/security_identity_compliance/cloudtrail_cwlogs/README.md new file mode 100644 index 0000000..64e92cc --- /dev/null +++ b/modules/security_identity_compliance/cloudtrail_cwlogs/README.md @@ -0,0 +1,21 @@ +# Overview +This module performs the following tasks: + +- Create KMS key for cloudtrail and CWL encryption +- Create s3 bucket for cloudtrail use +- Create cloudtrail +- Create cloudwatch log group for cloudtrail +- Create cloudwatch metric filter for CIS1.1 +- Create cloudwatch alarm for CIS1.1 + +## Inputs: +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:-----:| +| application | name of application | string | none | yes | +| environment | capacity of environment (prd/dev/lab) | string | none | yes | +| customer-name | owner of aws resources | string | none | yes | +| project | name of project | string | none | yes | +| default-tags | tags to be added to resources | list | none | yes | +| cloudtrail-retain-days | Days before cloudtrail logs are expired on s3 | number | 90 | yes | +| aws-region-short | short name of aws region (e.g. apne1) | string | none | yes | + diff --git a/modules/security_identity_compliance/cloudtrail_cwlogs/cloudtrail.tf b/modules/security_identity_compliance/cloudtrail_cwlogs/cloudtrail.tf new file mode 100644 index 0000000..eb88545 --- /dev/null +++ b/modules/security_identity_compliance/cloudtrail_cwlogs/cloudtrail.tf @@ -0,0 +1,80 @@ +resource "aws_iam_role" "iam_cloudtrial_cloudwatch_role" { + name = "${var.resource-prefix}-cwl-role" + assume_role_policy = data.aws_iam_policy_document.ct-role-assumerole-policy.json + description = "Enables AWS CloudTrail to deliver log to CloudWatch log" + tags = var.default-tags +} + +resource "aws_iam_role_policy" "iam_cloudtrial_cloudwatach_role_policy" { + name = "${var.resource-prefix}-cwl-role-policy" + role = aws_iam_role.iam_cloudtrial_cloudwatch_role.id + policy = data.aws_iam_policy_document.ct-role-pdoc.json +} + +data "aws_iam_policy_document" "ct-role-assumerole-policy" { + statement { + effect = "Allow" + actions = ["sts:AssumeRole"] + + principals { + type = "Service" + identifiers = ["cloudtrail.amazonaws.com"] + } + } +} + +data "aws_iam_policy_document" "ct-role-pdoc" { + statement { + effect = "Allow" + actions = ["logs:CreateLogStream"] + + resources = [ + "${aws_cloudwatch_log_group.ct-cwl.arn}:log-stream:*", + ] + } + + statement { + effect = "Allow" + actions = ["logs:PutLogEvents"] + + resources = [ + "${aws_cloudwatch_log_group.ct-cwl.arn}:log-stream:*", + ] + } +} + + + +resource "aws_cloudtrail" "default" { + name = "${var.resource-prefix}-trail-001" + enable_logging = true + s3_bucket_name = local.ct-bucket-name + enable_log_file_validation = true + is_multi_region_trail = true + include_global_service_events = true + cloud_watch_logs_role_arn = aws_iam_role.iam_cloudtrial_cloudwatch_role.arn + cloud_watch_logs_group_arn = "${aws_cloudwatch_log_group.ct-cwl.arn}:*" + tags = var.default-tags + kms_key_id = aws_kms_key.ctbucket-key.arn + is_organization_trail = false + + event_selector { + read_write_type = "All" + include_management_events = true + + data_resource { + type = "AWS::S3::Object" + values = ["arn:aws:s3:::"] + } + + data_resource { + type = "AWS::Lambda::Function" + values = ["arn:aws:lambda"] + } + } + + #insight_selector { + # insight_type = "ApiCallRateInsight" + #} +} + diff --git a/modules/security_identity_compliance/cloudtrail_cwlogs/ct-key.tf b/modules/security_identity_compliance/cloudtrail_cwlogs/ct-key.tf new file mode 100644 index 0000000..3640e86 --- /dev/null +++ b/modules/security_identity_compliance/cloudtrail_cwlogs/ct-key.tf @@ -0,0 +1,69 @@ +resource "aws_kms_key" "ctbucket-key" { + deletion_window_in_days = 7 + tags = var.default-tags + policy = data.aws_iam_policy_document.key-policy.json + enable_key_rotation = true +} + +resource "aws_kms_alias" ctbucket-key-aliaas { + name = "alias/${var.resource-prefix}-kmskey-default" + target_key_id = aws_kms_key.ctbucket-key.key_id +} + +# https://gist.github.com/shortjared/4c1e3fe52bdfa47522cfe5b41e5d6f22 +data "aws_iam_policy_document" "key-policy" { + statement { + sid = "Key usage by aws services" + principals { + identifiers = [ + "autoscaling.amazonaws.com", + "cloudtrail.amazonaws.com", + "eks.amazonaws.com", + "eks-nodegroup.amazonaws.com", + "guardduty.amazonaws.com", + "delivery.logs.amazonaws.com", + "sns.amazonaws.com", + "sqs.amazonaws.com", + "lambda.amazonaws.com", + "backup.amazonaws.com", + "events.amazonaws.com", + "cloudwatch.amazonaws.com", + "s3.amazonaws.com", + "logs.amazonaws.com" + ] + type = "Service" + } + + actions = [ + "kms:Encrypt", + "kms:Decrypt", + "kms:ReEncrypt*", + "kms:GenerateDataKey*", + "kms:DescribeKey" + ] + + resources = [ + "*" + ] + + effect = "Allow" + } + + statement { + sid = "Key administrator" + actions = [ + "kms:*" + ] + + resources = [ + "*" + ] + + principals { + type = "AWS" + identifiers = [data.aws_caller_identity.this.account_id] + } + + effect = "Allow" + } +} diff --git a/modules/security_identity_compliance/cloudtrail_cwlogs/ct-s3-bucket.tf b/modules/security_identity_compliance/cloudtrail_cwlogs/ct-s3-bucket.tf new file mode 100644 index 0000000..4d1f05b --- /dev/null +++ b/modules/security_identity_compliance/cloudtrail_cwlogs/ct-s3-bucket.tf @@ -0,0 +1,64 @@ + + +data "aws_iam_policy_document" "cloudtrail_bucket_policy" { + statement { + sid = "AWSCloudTrailAclCheck" + + principals { + type = "Service" + identifiers = ["cloudtrail.amazonaws.com"] + } + + actions = [ + "s3:GetBucketAcl", + ] + + resources = [ + "arn:aws:s3:::${local.ct-bucket-name}", + ] + } + + statement { + sid = "AWSCloudTrailWrite" + + principals { + type = "Service" + identifiers = ["config.amazonaws.com", "cloudtrail.amazonaws.com"] + } + + actions = [ + "s3:PutObject" + ] + + resources = [ + "arn:aws:s3:::${local.ct-bucket-name}/*" + ] + } + + statement { + sid = "ReadAccessForAccountOwner" + + principals { + type = "AWS" + identifiers = [data.aws_caller_identity.this.account_id] + } + + actions = [ + "s3:Get*" + ] + + resources = [ + "arn:aws:s3:::${local.ct-bucket-name}", + "arn:aws:s3:::${local.ct-bucket-name}/*" + ] + } + +} + +module ct-bucket { + source = "../../storage/infra-s3-bucket" + + bucket-name = local.ct-bucket-name + bucket-policy-json = data.aws_iam_policy_document.cloudtrail_bucket_policy.json + default-tags = var.default-tags +} diff --git a/modules/security_identity_compliance/cloudtrail_cwlogs/cw-loggroup.tf b/modules/security_identity_compliance/cloudtrail_cwlogs/cw-loggroup.tf new file mode 100644 index 0000000..b6e2467 --- /dev/null +++ b/modules/security_identity_compliance/cloudtrail_cwlogs/cw-loggroup.tf @@ -0,0 +1,377 @@ +resource "aws_cloudwatch_log_group" "ct-cwl" { + name_prefix = "cloudtrail/" + retention_in_days = var.cloudtrail-retain-days + kms_key_id = aws_kms_key.ctbucket-key.arn + tags = var.default-tags +} + +resource "aws_cloudwatch_log_metric_filter" "cwl-metric-filter-cis11" { + name = "cis11-rootaccess-filter" + pattern = <= 1 + error_message = "Validation failed: Provider default_tags not set." + } + } +} + +data "aws_iam_policy_document" "assume-role-policy" { + statement { + actions = ["sts:AssumeRole"] + + principals { + type = "AWS" + identifiers = [var.role-trusted-entity-arn] + } + } +} + +resource "aws_iam_role" "SecurityDeployer" { + name = "SecurityDeployer" + description = "Admin access to IAM, KMS, SecretsManager, ec2 Key Pair" + max_session_duration = var.max_session_duration + assume_role_policy = data.aws_iam_policy_document.assume-role-policy.json +} + +resource "aws_iam_role_policy" "SecurityDeployerPolicy" { + name = "SecurityDeployerPolicy" + policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Action" : [ + "iam:*", + "secretsmanager:*", + "ec2:ImportKeyPair", + "kms:*", + "ec2:CreateKeyPair", + "ec2:DescribeKeyPairs", + "ec2:DeleteKeyPair", + "acm:*", + "config:*", + "guardduty:*", + "inspector2:*", + "securityhub:*", + "shield:*", + "sso:*", + "organizations:*" + ], + "Resource" : "*" + } + ] + } + ) + role = aws_iam_role.SecurityDeployer.id +} + +resource "aws_iam_role" "NetworkDeployer" { + name = "NetworkDeployer" + description = "Admin access to VPC, SecurityGroup, Route53" + max_session_duration = var.max_session_duration + assume_role_policy = data.aws_iam_policy_document.assume-role-policy.json +} + +# iam:PassRole required to create flowlogs +resource "aws_iam_role_policy" "NetworkDeployerPolicy" { + name = "NetworkDeployerPolicy" + policy = jsonencode({ + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Action" : [ + "iam:PassRole", + "ec2:AcceptVpcEndpointConnections", + "ec2:AllocateAddress", + "ec2:AssignIpv6Addresses", + "ec2:AssignPrivateIpAddresses", + "ec2:AssociateAddress", + "ec2:AssociateDhcpOptions", + "ec2:AssociateRouteTable", + "ec2:AssociateSubnetCidrBlock", + "ec2:AssociateVpcCidrBlock", + "ec2:AttachInternetGateway", + "ec2:AttachNetworkInterface", + "ec2:AttachVpnGateway", + "ec2:CreateCarrierGateway", + "ec2:CreateCustomerGateway", + "ec2:CreateDefaultSubnet", + "ec2:CreateDefaultVpc", + "ec2:CreateDhcpOptions", + "ec2:CreateEgressOnlyInternetGateway", + "ec2:CreateFlowLogs", + "ec2:CreateInternetGateway", + "ec2:CreateNatGateway", + "ec2:CreateNetworkAcl", + "ec2:CreateNetworkAclEntry", + "ec2:CreateNetworkInterface", + "ec2:CreateNetworkInterfacePermission", + "ec2:CreatePlacementGroup", + "ec2:CreateRoute", + "ec2:CreateRouteTable", + "ec2:CreateSecurityGroup", + "ec2:CreateSubnet", + "ec2:CreateTags", + "ec2:CreateVpc", + "ec2:CreateVpcEndpoint", + "ec2:CreateVpcEndpointConnectionNotification", + "ec2:CreateVpcEndpointServiceConfiguration", + "ec2:CreateVpnConnection", + "ec2:CreateVpnConnectionRoute", + "ec2:CreateVpnGateway", + "ec2:DeleteCarrierGateway", + "ec2:DeleteEgressOnlyInternetGateway", + "ec2:DeleteFlowLogs", + "ec2:DeleteNatGateway", + "ec2:DeleteNetworkInterface", + "ec2:DeleteNetworkInterfacePermission", + "ec2:DeletePlacementGroup", + "ec2:DeleteSubnet", + "ec2:DeleteTags", + "ec2:DeleteVpc", + "ec2:DeleteVpcEndpointConnectionNotifications", + "ec2:DeleteVpcEndpointServiceConfigurations", + "ec2:DeleteVpcEndpoints", + "ec2:DeleteVpnConnection", + "ec2:DeleteVpnConnectionRoute", + "ec2:DeleteVpnGateway", + "ec2:DescribeAccountAttributes", + "ec2:DescribeAddresses", + "ec2:DescribeAvailabilityZones", + "ec2:DescribeCarrierGateways", + "ec2:DescribeClassicLinkInstances", + "ec2:DescribeCustomerGateways", + "ec2:DescribeDhcpOptions", + "ec2:DescribeEgressOnlyInternetGateways", + "ec2:DescribeFlowLogs", + "ec2:DescribeInstances", + "ec2:DescribeInternetGateways", + "ec2:DescribeKeyPairs", + "ec2:DescribeMovingAddresses", + "ec2:DescribeNatGateways", + "ec2:DescribeNetworkAcls", + "ec2:DescribeNetworkInterfaceAttribute", + "ec2:DescribeNetworkInterfacePermissions", + "ec2:DescribeNetworkInterfaces", + "ec2:DescribePlacementGroups", + "ec2:DescribePrefixLists", + "ec2:DescribeRouteTables", + "ec2:DescribeSecurityGroupReferences", + "ec2:DescribeSecurityGroupRules", + "ec2:DescribeSecurityGroups", + "ec2:DescribeStaleSecurityGroups", + "ec2:DescribeSubnets", + "ec2:DescribeTags", + "ec2:DescribeVpcAttribute", + "ec2:DescribeVpcClassicLink", + "ec2:DescribeVpcClassicLinkDnsSupport", + "ec2:DescribeVpcEndpointConnectionNotifications", + "ec2:DescribeVpcEndpointConnections", + "ec2:DescribeVpcEndpointServiceConfigurations", + "ec2:DescribeVpcEndpointServicePermissions", + "ec2:DescribeVpcEndpointServices", + "ec2:DescribeVpcEndpoints", + "ec2:DescribeVpcPeeringConnections", + "ec2:DescribeVpcs", + "ec2:DescribeVpnConnections", + "ec2:DescribeVpnGateways", + "ec2:DescribePublicIpv4Pools", + "ec2:DescribeIpv6Pools", + "ec2:DetachInternetGateway", + "ec2:DetachNetworkInterface", + "ec2:DetachVpnGateway", + "ec2:DisableVgwRoutePropagation", + "ec2:DisableVpcClassicLinkDnsSupport", + "ec2:DisassociateAddress", + "ec2:DisassociateRouteTable", + "ec2:DisassociateSubnetCidrBlock", + "ec2:DisassociateVpcCidrBlock", + "ec2:EnableVgwRoutePropagation", + "ec2:EnableVpcClassicLinkDnsSupport", + "ec2:ModifyNetworkInterfaceAttribute", + "ec2:ModifySecurityGroupRules", + "ec2:ModifySubnetAttribute", + "ec2:ModifyVpcAttribute", + "ec2:ModifyVpcEndpoint", + "ec2:ModifyVpcEndpointConnectionNotification", + "ec2:ModifyVpcEndpointServiceConfiguration", + "ec2:ModifyVpcEndpointServicePermissions", + "ec2:ModifyVpcPeeringConnectionOptions", + "ec2:ModifyVpcTenancy", + "ec2:MoveAddressToVpc", + "ec2:RejectVpcEndpointConnections", + "ec2:ReleaseAddress", + "ec2:ReplaceNetworkAclAssociation", + "ec2:ReplaceNetworkAclEntry", + "ec2:ReplaceRoute", + "ec2:ReplaceRouteTableAssociation", + "ec2:ResetNetworkInterfaceAttribute", + "ec2:RestoreAddressToClassic", + "ec2:UnassignIpv6Addresses", + "ec2:UnassignPrivateIpAddresses", + "ec2:UpdateSecurityGroupRuleDescriptionsEgress", + "ec2:UpdateSecurityGroupRuleDescriptionsIngress", + "ec2:AcceptVpcPeeringConnection", + "ec2:AttachClassicLinkVpc", + "ec2:AuthorizeSecurityGroupEgress", + "ec2:AuthorizeSecurityGroupIngress", + "ec2:CreateVpcPeeringConnection", + "ec2:DeleteCustomerGateway", + "ec2:DeleteDhcpOptions", + "ec2:DeleteInternetGateway", + "ec2:DeleteNetworkAcl", + "ec2:DeleteNetworkAclEntry", + "ec2:DeleteRoute", + "ec2:DeleteRouteTable", + "ec2:DeleteSecurityGroup", + "ec2:DeleteVolume", + "ec2:DeleteVpcPeeringConnection", + "ec2:DetachClassicLinkVpc", + "ec2:DisableVpcClassicLink", + "ec2:EnableVpcClassicLink", + "ec2:GetConsoleScreenshot", + "ec2:RejectVpcPeeringConnection", + "ec2:RevokeSecurityGroupEgress", + "ec2:RevokeSecurityGroupIngress", + "ec2:CreateLocalGatewayRoute", + "ec2:CreateLocalGatewayRouteTableVpcAssociation", + "ec2:DeleteLocalGatewayRoute", + "ec2:DeleteLocalGatewayRouteTableVpcAssociation", + "ec2:DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations", + "ec2:DescribeLocalGatewayRouteTableVpcAssociations", + "ec2:DescribeLocalGatewayRouteTables", + "ec2:DescribeLocalGatewayVirtualInterfaceGroups", + "ec2:DescribeLocalGatewayVirtualInterfaces", + "ec2:DescribeLocalGateways", + "ec2:SearchLocalGatewayRoutes", + "ec2:AcceptTransitGatewayVpcAttachment", + "ec2:AssociateTransitGatewayRouteTable", + "ec2:CreateTransitGateway", + "ec2:CreateTransitGatewayRoute", + "ec2:CreateTransitGatewayRouteTable", + "ec2:CreateTransitGatewayVpcAttachment", + "ec2:DeleteTransitGateway", + "ec2:DeleteTransitGatewayRoute", + "ec2:DeleteTransitGatewayRouteTable", + "ec2:DeleteTransitGatewayVpcAttachment", + "ec2:DescribeTransitGatewayAttachments", + "ec2:DescribeTransitGatewayRouteTables", + "ec2:DescribeTransitGatewayVpcAttachments", + "ec2:DescribeTransitGateways", + "ec2:DisableTransitGatewayRouteTablePropagation", + "ec2:DisassociateTransitGatewayRouteTable", + "ec2:EnableTransitGatewayRouteTablePropagation", + "ec2:ExportTransitGatewayRoutes", + "ec2:GetTransitGatewayAttachmentPropagations", + "ec2:GetTransitGatewayRouteTableAssociations", + "ec2:GetTransitGatewayRouteTablePropagations", + "ec2:ModifyTransitGateway", + "ec2:ModifyTransitGatewayVpcAttachment", + "ec2:RejectTransitGatewayVpcAttachment", + "ec2:ReplaceTransitGatewayRoute", + "ec2:SearchTransitGatewayRoutes", + "route53domains:*", + "route53resolver:*", + "route53:*", + "directconnect:*" + ], + "Resource" : "*" + } + ] + } + ) + role = aws_iam_role.NetworkDeployer.id +} + +resource "aws_iam_role" "DatabaseDeployer" { + name = "DatabaseDeployer" + description = "Admin access to databases" + max_session_duration = var.max_session_duration + assume_role_policy = data.aws_iam_policy_document.assume-role-policy.json +} + +resource "aws_iam_role_policy" "DatabaseDeployerPolicy" { + name = "DatabaseDeployerPolicy" + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Action" : [ + "rds:*", + "redshift:*", + "elasticache:*", + "kms:Get*", + "kms:List*", + "kms:Describe*" + ], + "Resource" : "*" + } + ] + } + ) + role = aws_iam_role.DatabaseDeployer.id +} + +resource "aws_iam_role" "StorageDeployer" { + name = "StorageDeployer" + description = "Admin access to S3, RDS, ElastiCache, ECR" + max_session_duration = var.max_session_duration + assume_role_policy = data.aws_iam_policy_document.assume-role-policy.json +} + +resource "aws_iam_role_policy" "StorageDeployerPolicy" { + name = "StorageDeployerPolicy" + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Action" : [ + "s3:*", + "ecr:*", + "elasticfilesystem:*", + "fsx:*", + "kms:Get*", + "kms:List*", + "kms:Describe*" + ], + "Resource" : "*" + } + ] + } + ) + role = aws_iam_role.StorageDeployer.id +} + +resource "aws_iam_role" "CommonDeployer" { + name = "CommonDeployer" + description = "Admin access to all services except those allowed in other deployer roles" + max_session_duration = var.max_session_duration + assume_role_policy = data.aws_iam_policy_document.assume-role-policy.json +} + +resource "aws_iam_role_policy" "CommonDeployerPolicy" { + name = "CommonDeployerPolicy" + policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Sid" : "NegateSecurityDeployerPermissions", + "Effect" : "Allow", + "NotAction" : [ + "iam:*", + "secretsmanager:*", + "ec2:ImportKeyPair", + "kms:EnableKey", + "kms:ImportKeyMaterial", + "kms:Decrypt", + "kms:GenerateRandom", + "kms:PutKeyPolicy", + "kms:GenerateDataKeyWithoutPlaintext", + "kms:Verify", + "kms:CancelKeyDeletion", + "kms:ReplicateKey", + "kms:GenerateDataKeyPair", + "kms:SynchronizeMultiRegionKey", + "kms:DeleteCustomKeyStore", + "kms:GenerateMac", + "kms:UpdatePrimaryRegion", + "kms:UpdateCustomKeyStore", + "kms:Encrypt", + "kms:ScheduleKeyDeletion", + "kms:ReEncryptTo", + "kms:CreateKey", + "kms:ConnectCustomKeyStore", + "kms:Sign", + "kms:CreateGrant", + "kms:EnableKeyRotation", + "kms:UpdateKeyDescription", + "kms:DeleteImportedKeyMaterial", + "kms:GenerateDataKeyPairWithoutPlaintext", + "kms:DisableKey", + "kms:ReEncryptFrom", + "kms:DisableKeyRotation", + "kms:RetireGrant", + "kms:VerifyMac", + "kms:UpdateAlias", + "kms:CreateCustomKeyStore", + "kms:RevokeGrant", + "kms:GenerateDataKey", + "kms:CreateAlias", + "kms:DisconnectCustomKeyStore", + "kms:DeleteAlias", + "ec2:CreateKeyPair", + "ec2:DescribeKeyPairs", + "ec2:DeleteKeyPair", + "acm:*", + "config:*", + "guardduty:*", + "inspector2:*", + "securityhub:*", + "shield:*", + "sso:*", + "organizations:*" + ], + "Resource" : "*" + }, + { + "Sid" : "NegateNetworkDeployerPermissions", + "Effect" : "Allow", + "NotAction" : [ + "ec2:AcceptVpcEndpointConnections", + "ec2:AllocateAddress", + "ec2:AssignIpv6Addresses", + "ec2:AssignPrivateIpAddresses", + "ec2:AssociateAddress", + "ec2:AssociateDhcpOptions", + "ec2:AssociateRouteTable", + "ec2:AssociateSubnetCidrBlock", + "ec2:AssociateVpcCidrBlock", + "ec2:AttachInternetGateway", + "ec2:AttachNetworkInterface", + "ec2:AttachVpnGateway", + "ec2:CreateCarrierGateway", + "ec2:CreateCustomerGateway", + "ec2:CreateDefaultSubnet", + "ec2:CreateDefaultVpc", + "ec2:CreateDhcpOptions", + "ec2:CreateEgressOnlyInternetGateway", + "ec2:CreateFlowLogs", + "ec2:CreateInternetGateway", + "ec2:CreateNatGateway", + "ec2:CreateNetworkAcl", + "ec2:CreateNetworkAclEntry", + "ec2:CreateNetworkInterface", + "ec2:CreateNetworkInterfacePermission", + "ec2:CreatePlacementGroup", + "ec2:CreateRoute", + "ec2:CreateRouteTable", + "ec2:CreateSecurityGroup", + "ec2:CreateSubnet", + "ec2:CreateTags", + "ec2:CreateVpc", + "ec2:CreateVpcEndpoint", + "ec2:CreateVpcEndpointConnectionNotification", + "ec2:CreateVpcEndpointServiceConfiguration", + "ec2:CreateVpnConnection", + "ec2:CreateVpnConnectionRoute", + "ec2:CreateVpnGateway", + "ec2:DeleteCarrierGateway", + "ec2:DeleteEgressOnlyInternetGateway", + "ec2:DeleteFlowLogs", + "ec2:DeleteNatGateway", + "ec2:DeleteNetworkInterface", + "ec2:DeleteNetworkInterfacePermission", + "ec2:DeletePlacementGroup", + "ec2:DeleteSubnet", + "ec2:DeleteTags", + "ec2:DeleteVpc", + "ec2:DeleteVpcEndpointConnectionNotifications", + "ec2:DeleteVpcEndpointServiceConfigurations", + "ec2:DeleteVpcEndpoints", + "ec2:DeleteVpnConnection", + "ec2:DeleteVpnConnectionRoute", + "ec2:DeleteVpnGateway", + "ec2:DescribeAccountAttributes", + "ec2:DescribeAddresses", + "ec2:DescribeAvailabilityZones", + "ec2:DescribeCarrierGateways", + "ec2:DescribeClassicLinkInstances", + "ec2:DescribeCustomerGateways", + "ec2:DescribeDhcpOptions", + "ec2:DescribeEgressOnlyInternetGateways", + "ec2:DescribeFlowLogs", + "ec2:DescribeInstances", + "ec2:DescribeInternetGateways", + "ec2:DescribeKeyPairs", + "ec2:DescribeMovingAddresses", + "ec2:DescribeNatGateways", + "ec2:DescribeNetworkAcls", + "ec2:DescribeNetworkInterfaceAttribute", + "ec2:DescribeNetworkInterfacePermissions", + "ec2:DescribeNetworkInterfaces", + "ec2:DescribePlacementGroups", + "ec2:DescribePrefixLists", + "ec2:DescribeRouteTables", + "ec2:DescribeSecurityGroupReferences", + "ec2:DescribeSecurityGroupRules", + "ec2:DescribeSecurityGroups", + "ec2:DescribeStaleSecurityGroups", + "ec2:DescribeSubnets", + "ec2:DescribeTags", + "ec2:DescribeVpcAttribute", + "ec2:DescribeVpcClassicLink", + "ec2:DescribeVpcClassicLinkDnsSupport", + "ec2:DescribeVpcEndpointConnectionNotifications", + "ec2:DescribeVpcEndpointConnections", + "ec2:DescribeVpcEndpointServiceConfigurations", + "ec2:DescribeVpcEndpointServicePermissions", + "ec2:DescribeVpcEndpointServices", + "ec2:DescribeVpcEndpoints", + "ec2:DescribeVpcPeeringConnections", + "ec2:DescribeVpcs", + "ec2:DescribeVpnConnections", + "ec2:DescribeVpnGateways", + "ec2:DescribePublicIpv4Pools", + "ec2:DescribeIpv6Pools", + "ec2:DetachInternetGateway", + "ec2:DetachNetworkInterface", + "ec2:DetachVpnGateway", + "ec2:DisableVgwRoutePropagation", + "ec2:DisableVpcClassicLinkDnsSupport", + "ec2:DisassociateAddress", + "ec2:DisassociateRouteTable", + "ec2:DisassociateSubnetCidrBlock", + "ec2:DisassociateVpcCidrBlock", + "ec2:EnableVgwRoutePropagation", + "ec2:EnableVpcClassicLinkDnsSupport", + "ec2:ModifyNetworkInterfaceAttribute", + "ec2:ModifySecurityGroupRules", + "ec2:ModifySubnetAttribute", + "ec2:ModifyVpcAttribute", + "ec2:ModifyVpcEndpoint", + "ec2:ModifyVpcEndpointConnectionNotification", + "ec2:ModifyVpcEndpointServiceConfiguration", + "ec2:ModifyVpcEndpointServicePermissions", + "ec2:ModifyVpcPeeringConnectionOptions", + "ec2:ModifyVpcTenancy", + "ec2:MoveAddressToVpc", + "ec2:RejectVpcEndpointConnections", + "ec2:ReleaseAddress", + "ec2:ReplaceNetworkAclAssociation", + "ec2:ReplaceNetworkAclEntry", + "ec2:ReplaceRoute", + "ec2:ReplaceRouteTableAssociation", + "ec2:ResetNetworkInterfaceAttribute", + "ec2:RestoreAddressToClassic", + "ec2:UnassignIpv6Addresses", + "ec2:UnassignPrivateIpAddresses", + "ec2:UpdateSecurityGroupRuleDescriptionsEgress", + "ec2:UpdateSecurityGroupRuleDescriptionsIngress", + "ec2:AcceptVpcPeeringConnection", + "ec2:AttachClassicLinkVpc", + "ec2:AuthorizeSecurityGroupEgress", + "ec2:AuthorizeSecurityGroupIngress", + "ec2:CreateVpcPeeringConnection", + "ec2:DeleteCustomerGateway", + "ec2:DeleteDhcpOptions", + "ec2:DeleteInternetGateway", + "ec2:DeleteNetworkAcl", + "ec2:DeleteNetworkAclEntry", + "ec2:DeleteRoute", + "ec2:DeleteRouteTable", + "ec2:DeleteSecurityGroup", + "ec2:DeleteVolume", + "ec2:DeleteVpcPeeringConnection", + "ec2:DetachClassicLinkVpc", + "ec2:DisableVpcClassicLink", + "ec2:EnableVpcClassicLink", + "ec2:GetConsoleScreenshot", + "ec2:RejectVpcPeeringConnection", + "ec2:RevokeSecurityGroupEgress", + "ec2:RevokeSecurityGroupIngress", + "ec2:CreateLocalGatewayRoute", + "ec2:CreateLocalGatewayRouteTableVpcAssociation", + "ec2:DeleteLocalGatewayRoute", + "ec2:DeleteLocalGatewayRouteTableVpcAssociation", + "ec2:DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations", + "ec2:DescribeLocalGatewayRouteTableVpcAssociations", + "ec2:DescribeLocalGatewayRouteTables", + "ec2:DescribeLocalGatewayVirtualInterfaceGroups", + "ec2:DescribeLocalGatewayVirtualInterfaces", + "ec2:DescribeLocalGateways", + "ec2:SearchLocalGatewayRoutes", + "ec2:AcceptTransitGatewayVpcAttachment", + "ec2:AssociateTransitGatewayRouteTable", + "ec2:CreateTransitGateway", + "ec2:CreateTransitGatewayRoute", + "ec2:CreateTransitGatewayRouteTable", + "ec2:CreateTransitGatewayVpcAttachment", + "ec2:DeleteTransitGateway", + "ec2:DeleteTransitGatewayRoute", + "ec2:DeleteTransitGatewayRouteTable", + "ec2:DeleteTransitGatewayVpcAttachment", + "ec2:DescribeTransitGatewayAttachments", + "ec2:DescribeTransitGatewayRouteTables", + "ec2:DescribeTransitGatewayVpcAttachments", + "ec2:DescribeTransitGateways", + "ec2:DisableTransitGatewayRouteTablePropagation", + "ec2:DisassociateTransitGatewayRouteTable", + "ec2:EnableTransitGatewayRouteTablePropagation", + "ec2:ExportTransitGatewayRoutes", + "ec2:GetTransitGatewayAttachmentPropagations", + "ec2:GetTransitGatewayRouteTableAssociations", + "ec2:GetTransitGatewayRouteTablePropagations", + "ec2:ModifyTransitGateway", + "ec2:ModifyTransitGatewayVpcAttachment", + "ec2:RejectTransitGatewayVpcAttachment", + "ec2:ReplaceTransitGatewayRoute", + "ec2:SearchTransitGatewayRoutes", + "route53domains:*", + "route53resolver:*", + "route53:*", + "directconnect:*" + ], + "Resource" : "*" + }, + { + "Sid" : "NegateDatabaseDeployerPermissions", + "Effect" : "Allow", + "NotAction" : [ + "rds:*", + "redshift:*", + "elasticache:*" + ], + "Resource" : "*" + }, + { + "Sid" : "NegateStorageDeployerPermissions", + "Effect" : "Allow", + "NotAction" : [ + "s3:*", + "ecr:*", + "elasticfilesystem:*", + "fsx:*" + ], + "Resource" : "*" + } + ] + } + ) + role = aws_iam_role.CommonDeployer.id +} \ No newline at end of file diff --git a/modules/security_identity_compliance/five-deployer-roles/outputs.tf b/modules/security_identity_compliance/five-deployer-roles/outputs.tf new file mode 100644 index 0000000..c35730e --- /dev/null +++ b/modules/security_identity_compliance/five-deployer-roles/outputs.tf @@ -0,0 +1,9 @@ +output "devsecops-roles" { + value = [ + aws_iam_role.CommonDeployer.arn, + aws_iam_role.DatabaseDeployer.arn, + aws_iam_role.NetworkDeployer.arn, + aws_iam_role.DatabaseDeployer.arn, + aws_iam_role.StorageDeployer.arn + ] +} \ No newline at end of file diff --git a/modules/security_identity_compliance/five-deployer-roles/provider.tf b/modules/security_identity_compliance/five-deployer-roles/provider.tf new file mode 100644 index 0000000..a8fb0be --- /dev/null +++ b/modules/security_identity_compliance/five-deployer-roles/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 3.25" + } + } +} diff --git a/modules/security_identity_compliance/five-deployer-roles/variables.tf b/modules/security_identity_compliance/five-deployer-roles/variables.tf new file mode 100644 index 0000000..89d7b39 --- /dev/null +++ b/modules/security_identity_compliance/five-deployer-roles/variables.tf @@ -0,0 +1,12 @@ +/* variable "aws-region" {} +variable "aws-region-short" {} +variable "customer-name" {} +variable "environment" {} +variable "project" {} +variable "application" {} +*/ +variable max_session_duration { + type = number + default = 14400 +} +variable role-trusted-entity-arn {} \ No newline at end of file diff --git a/modules/security_identity_compliance/guardduty/README.md b/modules/security_identity_compliance/guardduty/README.md new file mode 100644 index 0000000..1fea08d --- /dev/null +++ b/modules/security_identity_compliance/guardduty/README.md @@ -0,0 +1,17 @@ +# Overview +This module performs the following tasks: + +- Enable AWS config +- Create AWS config files for CIS benchmark +- Create s3 bucket for config use + +## Inputs: +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:-----:| +| application | name of application | string | none | yes | +| environment | capacity of environment (prd/dev/lab) | string | none | yes | +| customer-name | owner of aws resources | string | none | yes | +| project | name of project | string | none | yes | +| default-tags | tags to be added to resources | list | none | yes | +| aws-region-short | short name of aws region (e.g. apne1) | string | none | yes | + diff --git a/modules/security_identity_compliance/guardduty/main.tf b/modules/security_identity_compliance/guardduty/main.tf new file mode 100644 index 0000000..7d803f6 --- /dev/null +++ b/modules/security_identity_compliance/guardduty/main.tf @@ -0,0 +1,8 @@ +data aws_caller_identity this {} + +resource aws_guardduty_detector gd { + enable = true + finding_publishing_frequency = "ONE_HOUR" + tags = var.default-tags +} + diff --git a/modules/security_identity_compliance/guardduty/outputs.tf b/modules/security_identity_compliance/guardduty/outputs.tf new file mode 100644 index 0000000..22633ae --- /dev/null +++ b/modules/security_identity_compliance/guardduty/outputs.tf @@ -0,0 +1,3 @@ +output guardduty-arn { + value = aws_guardduty_detector.gd.arn +} \ No newline at end of file diff --git a/modules/security_identity_compliance/guardduty/variables.tf b/modules/security_identity_compliance/guardduty/variables.tf new file mode 100644 index 0000000..bace9fa --- /dev/null +++ b/modules/security_identity_compliance/guardduty/variables.tf @@ -0,0 +1 @@ +variable "default-tags" {} diff --git a/modules/security_identity_compliance/iam-group/README.md b/modules/security_identity_compliance/iam-group/README.md new file mode 100644 index 0000000..df14578 --- /dev/null +++ b/modules/security_identity_compliance/iam-group/README.md @@ -0,0 +1,24 @@ +# iam-user module +Module for creating IAM user. Credentials, if any, will be stored in secretsmanager + +## Example +```terraform +module iam-user { + source = "../../modules/security_identity_compliance/iam-user" + + default-tags = local.default-tags + iam-user-name = var.iam-user-name + iam-user-policy = "" + iam-user-policy-name = "SelfServicePermissions" + create-access-key = false + create-password = false + managed-policy-arns = ["arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"] + create-group = true + add-to-groups = [] + iam-group-name = var.iam-group-name +} + +output iam-user-arn { + value = module.iam-user.iam-user-arn +} +``` \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-group/main.tf b/modules/security_identity_compliance/iam-group/main.tf new file mode 100644 index 0000000..39f8698 --- /dev/null +++ b/modules/security_identity_compliance/iam-group/main.tf @@ -0,0 +1,17 @@ +resource "aws_iam_group" "iam-group" { + name = var.iam-group-name +} + +resource "aws_iam_group_policy" "iam-group-policy-new-group" { + count = var.iam-group-policy != "" ? 1 : 0 + name = var.iam-group-policy-name + group = aws_iam_group.iam-group.name + policy = var.iam-group-policy +} + +resource "aws_iam_group_policy_attachment" "iam-group-managed-policies" { + count = length(var.managed-policy-arns) > 0 ? 1 : 0 + group = aws_iam_group.iam-group.name + policy_arn = var.managed-policy-arns[count.index] +} + diff --git a/modules/security_identity_compliance/iam-group/outputs.tf b/modules/security_identity_compliance/iam-group/outputs.tf new file mode 100644 index 0000000..e3b8efa --- /dev/null +++ b/modules/security_identity_compliance/iam-group/outputs.tf @@ -0,0 +1,7 @@ +output iam-group-name { + value = aws_iam_group.iam-group.name +} + +output iam-group-arn { + value = aws_iam_group.iam-group.arn +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-group/variables.tf b/modules/security_identity_compliance/iam-group/variables.tf new file mode 100644 index 0000000..e727b89 --- /dev/null +++ b/modules/security_identity_compliance/iam-group/variables.tf @@ -0,0 +1,4 @@ +variable managed-policy-arns {} +variable iam-group-name {} +variable iam-group-policy {} +variable iam-group-policy-name {} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-group/versions.tf b/modules/security_identity_compliance/iam-group/versions.tf new file mode 100644 index 0000000..e015cf1 --- /dev/null +++ b/modules/security_identity_compliance/iam-group/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.9" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-role/LICENSE b/modules/security_identity_compliance/iam-role/LICENSE new file mode 100644 index 0000000..b64d22a --- /dev/null +++ b/modules/security_identity_compliance/iam-role/LICENSE @@ -0,0 +1,12 @@ +BSD Zero Clause License + +Permission to use, copy, modify, and/or distribute this software for any +purpose with or without fee is hereby granted. + +THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH +REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY +AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, +INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM +LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR +OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR +PERFORMANCE OF THIS SOFTWARE. \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-role/README.md b/modules/security_identity_compliance/iam-role/README.md new file mode 100644 index 0000000..2d9f7d4 --- /dev/null +++ b/modules/security_identity_compliance/iam-role/README.md @@ -0,0 +1,51 @@ + +Inline policy for IAM role is not supported by this module. Use managed policies instead. + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.4.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.4.0 | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_iam_instance_profile.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_instance_profile) | resource | +| [aws_iam_role.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| assume-role-policy | The actual assume role policy if trusted-entity is not provided. | `string` | `null` | no | +| create-instance-profile | Determines whether instance profile will be created | `bool` | `false` | no | +| description | Description of IAM role | `string` | n/a | yes | +| managed-policy-arns | List of managed policies to be attached to role | `list(string)` | `null` | no | +| path | Path of IAM role. Defaults to /Customer/ | `string` | `"/Customer/"` | no | +| role-name | Name of IAM role | `string` | n/a | yes | +| trusted-entity | AWS service allowed to assume this role. Either this or assume-role-policy must be provided. | `string` | n/a | yes | + +## Outputs + +| Name | Description | +|------|-------------| +| instance-profile-arn | ARN of IAM instance profile | +| name | Name of IAM role | +| profile-name | Name of IAM instance profile | +| role-arn | IAM role ARN | + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-role/examples/main.tf b/modules/security_identity_compliance/iam-role/examples/main.tf new file mode 100644 index 0000000..7d5e0fd --- /dev/null +++ b/modules/security_identity_compliance/iam-role/examples/main.tf @@ -0,0 +1,34 @@ +module "role1" { + source = ".../iam-role" + role-name = "${local.resource_prefix}-${var.application}-role1" + description = "IAM role for ${var.application}" + trusted-entity = "ec2.amazonaws.com" + create-instance-profile = true + + managed-policy-arns = [ + "arn:aws:iam::aws:policy/ReadOnlyAccess" + ] +} + +module "role2" { + source = ".../iam-role" + role-name = "${local.resource_prefix}-${var.application}-role2" + description = "IAM role for ${var.application}" + trusted-entity = null + assume-role-policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : [ + "ssm.amazonaws.com" + ] + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-role/main.tf b/modules/security_identity_compliance/iam-role/main.tf new file mode 100644 index 0000000..d494e3a --- /dev/null +++ b/modules/security_identity_compliance/iam-role/main.tf @@ -0,0 +1,40 @@ +# Assume role policy can be provided as-is, or built using the trusted-entity variable +locals { + assume-role-policy = var.assume-role-policy != null ? var.assume-role-policy : jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Effect" : "Allow", + "Principal" : { + "Service" : [ + var.trusted-entity + ] + }, + "Action" : "sts:AssumeRole" + } + ] + } + ) +} + +resource "aws_iam_instance_profile" "this" { + count = var.create-instance-profile ? 1 : 0 + name = "${var.role-name}-profile" + role = aws_iam_role.this.name + path = var.path +} + +resource "aws_iam_role" "this" { + name = var.role-name + description = var.description + assume_role_policy = local.assume-role-policy + managed_policy_arns = var.managed-policy-arns + force_detach_policies = true + path = var.path + # disable use of inline policy + # inline_policy { + # name = var.inline-policy-name + # policy = var.inline-policy + # } +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-role/outputs.tf b/modules/security_identity_compliance/iam-role/outputs.tf new file mode 100644 index 0000000..c325bea --- /dev/null +++ b/modules/security_identity_compliance/iam-role/outputs.tf @@ -0,0 +1,19 @@ +output "profile-name" { + description = "Name of IAM instance profile" + value = aws_iam_instance_profile.this[*].name +} + +output "role-arn" { + description = "IAM role ARN" + value = aws_iam_role.this.arn +} + +output "name" { + description = "Name of IAM role" + value = aws_iam_role.this.name +} + +output "instance-profile-arn" { + description = "ARN of IAM instance profile" + value = aws_iam_instance_profile.this.*.arn +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-role/provider.tf b/modules/security_identity_compliance/iam-role/provider.tf new file mode 100644 index 0000000..bc0239a --- /dev/null +++ b/modules/security_identity_compliance/iam-role/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.4.0" + } + } +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-role/variables.tf b/modules/security_identity_compliance/iam-role/variables.tf new file mode 100644 index 0000000..d1c0311 --- /dev/null +++ b/modules/security_identity_compliance/iam-role/variables.tf @@ -0,0 +1,38 @@ +variable "create-instance-profile" { + description = "Determines whether instance profile will be created" + type = bool + default = false +} + +variable "description" { + description = "Description of IAM role" + type = string +} + +variable "managed-policy-arns" { + description = "List of managed policies to be attached to role" + type = list(string) + default = null +} + +variable "role-name" { + description = "Name of IAM role" + type = string +} + +variable "path" { + description = "Path of IAM role. Defaults to /Customer/" + type = string + default = "/Customer/" +} + +variable "trusted-entity" { + description = "AWS service allowed to assume this role. Set this to null if assume-role-policy is to be provided." + type = string +} + +variable "assume-role-policy" { + description = "The actual assume role policy if trusted-entity is not provided." + type = string + default = null +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-user/README.md b/modules/security_identity_compliance/iam-user/README.md new file mode 100644 index 0000000..39bd6d4 --- /dev/null +++ b/modules/security_identity_compliance/iam-user/README.md @@ -0,0 +1,56 @@ + +## Requirements + +No requirements. + +## Providers + +| Name | Version | +|------|---------| +| aws | n/a | +| random | n/a | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_iam_access_key.iam-user-access-key](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_access_key) | resource | +| [aws_iam_group_membership.group-membership](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_group_membership) | resource | +| [aws_iam_user.iam-user](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_user) | resource | +| [aws_iam_user_login_profile.iam-user-profile](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_user_login_profile) | resource | +| [aws_iam_user_policy.iam-user-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_user_policy) | resource | +| [aws_iam_user_policy.iam-user-selfservice-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_user_policy) | resource | +| [aws_iam_user_policy_attachment.iam-user-managed-policies](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_user_policy_attachment) | resource | +| [aws_secretsmanager_secret.secretmanager](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/secretsmanager_secret) | resource | +| [aws_secretsmanager_secret_version.iam-user-secret](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/secretsmanager_secret_version) | resource | +| [random_id.secrets-random-id](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/id) | resource | +| [random_password.iam-user-pass](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/password) | resource | +| [aws_iam_policy_document.user-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_policy_document) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| add-to-groups | n/a | `list(string)` | `[]` | no | +| create-access-key | n/a | `bool` | n/a | yes | +| create-password | n/a | `bool` | n/a | yes | +| iam-user-name | n/a | `any` | n/a | yes | +| iam-user-policy | n/a | `string` | `""` | no | +| iam-user-policy-name | n/a | `string` | `""` | no | +| managed-policy-arns | n/a | `any` | n/a | yes | + +## Outputs + +| Name | Description | +|------|-------------| +| iam-user-access-key | n/a | +| iam-user-arn | n/a | +| iam-user-name | n/a | + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-user/main.tf b/modules/security_identity_compliance/iam-user/main.tf new file mode 100644 index 0000000..ebeb863 --- /dev/null +++ b/modules/security_identity_compliance/iam-user/main.tf @@ -0,0 +1,99 @@ +resource "aws_iam_user" "iam-user" { + name = var.iam-user-name + force_destroy = true +} + +resource "aws_iam_access_key" "iam-user-access-key" { + count = var.create-access-key ? 1 : 0 + user = aws_iam_user.iam-user.name +} + +resource "aws_iam_user_policy" "iam-user-policy" { + count = var.iam-user-policy != "" ? 1 : 0 + name = var.iam-user-policy-name + user = aws_iam_user.iam-user.name + policy = var.iam-user-policy +} + +resource "aws_iam_user_policy" "iam-user-selfservice-policy" { + name = "SelfServicePermissions" + user = aws_iam_user.iam-user.name + policy = data.aws_iam_policy_document.user-policy.json +} + +data "aws_iam_policy_document" "user-policy" { + statement { + sid = "ManageOwnCredentials" + + actions = [ + "iam:ChangePassword", + "iam:UpdateLoginProfile", + "iam:CreateAccessKey", + "iam:DeleteAccessKey", + "iam:ListAccessKeys", + "iam:CreateVirtualMFADevice", + "iam:EnableMFADevice", + "iam:ListMFA*", + "iam:ListVirtualMFA*", + "iam:ResyncMFADevice", + "iam:GetUser" + ] + + effect = "Allow" + resources = ["arn:aws:iam::*:user/$${aws:username}"] + } + + statement { + sid = "GetBasicUserInfo" + actions = [ + "iam:GetAccountPasswordPolicy", + "iam:GetAccessKeyLastUsed", + "iam:GetUserPolicy" + ] + effect = "Allow" + resources = ["*"] + } +} + +resource "aws_iam_user_policy_attachment" "iam-user-managed-policies" { + count = length(var.add-to-groups) > 0 ? 0 : length(var.managed-policy-arns) + user = aws_iam_user.iam-user.name + policy_arn = var.managed-policy-arns[count.index] +} + +resource "aws_iam_user_login_profile" "iam-user-profile" { + count = var.create-password ? 1 : 0 + user = aws_iam_user.iam-user.name + password_length = 20 + pgp_key = null +} + +resource "random_id" "secrets-random-id" { + byte_length = 2 +} + +resource "aws_secretsmanager_secret" "secretmanager" { + count = var.create-access-key || var.create-password ? 1 : 0 + name = "IamUserCredential-${random_id.secrets-random-id.dec}-${var.iam-user-name}" + description = "AWS resource credential" +} + +resource "aws_secretsmanager_secret_version" "iam-user-secret" { + count = var.create-access-key || var.create-password ? 1 : 0 + secret_id = aws_secretsmanager_secret.secretmanager[0].id + secret_string = jsonencode( + { + "ConsolePassword" : length(aws_iam_user_login_profile.iam-user-profile[0].password) > 0 ? aws_iam_user_login_profile.iam-user-profile[0].password : "NotSet", + "AccessKeyId" : length(aws_iam_access_key.iam-user-access-key) > 0 ? aws_iam_access_key.iam-user-access-key[0].id : "NotSet", + "KeySecret" : length(aws_iam_access_key.iam-user-access-key) > 0 ? aws_iam_access_key.iam-user-access-key[0].secret : "NotSet" + } + ) +} + +resource "aws_iam_group_membership" "group-membership" { + for_each = toset(var.add-to-groups) + name = "MembershipToExistingGroups" + group = each.value + users = [aws_iam_user.iam-user.name] +} + diff --git a/modules/security_identity_compliance/iam-user/outputs.tf b/modules/security_identity_compliance/iam-user/outputs.tf new file mode 100644 index 0000000..6799e31 --- /dev/null +++ b/modules/security_identity_compliance/iam-user/outputs.tf @@ -0,0 +1,15 @@ +output "iam-user-name" { + value = aws_iam_user.iam-user.name +} + +output "iam-user-arn" { + value = aws_iam_user.iam-user.arn +} + +output "iam-user-access-key" { + value = try(aws_iam_access_key.iam-user-access-key[0].id, "none") +} + +output "iam-user-secret-arn" { + value = try(aws_secretsmanager_secret_version.iam-user-secret[0].arn, "none") +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-user/variables.tf b/modules/security_identity_compliance/iam-user/variables.tf new file mode 100644 index 0000000..b18b57a --- /dev/null +++ b/modules/security_identity_compliance/iam-user/variables.tf @@ -0,0 +1,20 @@ +variable "iam-user-name" {} +variable "iam-user-policy" { + type = string + default = "" +} +variable "iam-user-policy-name" { + type = string + default = "" +} +variable "create-access-key" { + type = bool +} +variable "create-password" { + type = bool +} +variable "managed-policy-arns" {} +variable "add-to-groups" { + type = list(string) + default = [] +} \ No newline at end of file diff --git a/modules/security_identity_compliance/iam-user/versions.tf b/modules/security_identity_compliance/iam-user/versions.tf new file mode 100644 index 0000000..e015cf1 --- /dev/null +++ b/modules/security_identity_compliance/iam-user/versions.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.9" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} \ No newline at end of file diff --git a/modules/security_identity_compliance/inspector2/README.md b/modules/security_identity_compliance/inspector2/README.md new file mode 100644 index 0000000..7dce7d1 --- /dev/null +++ b/modules/security_identity_compliance/inspector2/README.md @@ -0,0 +1,2 @@ +# inspector2 module +Via awscli, enable inspector2 scanning of ECR repositories \ No newline at end of file diff --git a/modules/security_identity_compliance/inspector2/main.tf b/modules/security_identity_compliance/inspector2/main.tf new file mode 100644 index 0000000..2737461 --- /dev/null +++ b/modules/security_identity_compliance/inspector2/main.tf @@ -0,0 +1,11 @@ +resource "null_resource" "cli-inspector2" { + provisioner "local-exec" { + when = create + command = "/bin/bash -c 'aws inspector2 enable --resource-types \"ECR\"'" + } + + provisioner "local-exec" { + when = destroy + command = "/bin/bash -c 'aws inspector2 disable --resource-types \"ECR\"; sleep 30; aws inspector2 disable'" + } +} \ No newline at end of file diff --git a/modules/security_identity_compliance/other-default-settings/main.tf b/modules/security_identity_compliance/other-default-settings/main.tf new file mode 100644 index 0000000..d1ae967 --- /dev/null +++ b/modules/security_identity_compliance/other-default-settings/main.tf @@ -0,0 +1,24 @@ +resource "aws_s3_account_public_access_block" "default-s3-public-access-settings" { + block_public_acls = true + block_public_policy = true + ignore_public_acls = true + restrict_public_buckets = true + lifecycle { ignore_changes = all } +} + +resource "aws_ebs_encryption_by_default" "default-ebs-encryption-setting" { + enabled = true + lifecycle { ignore_changes = all } +} + +resource "aws_iam_account_password_policy" "password-policy1" { + minimum_password_length = 14 + require_lowercase_characters = true + require_numbers = true + require_uppercase_characters = true + require_symbols = true + allow_users_to_change_password = true + max_password_age = 90 + password_reuse_prevention = 24 + hard_expiry = true +} \ No newline at end of file diff --git a/modules/security_identity_compliance/roles_iam_resources/README.md b/modules/security_identity_compliance/roles_iam_resources/README.md new file mode 100644 index 0000000..8647a0b --- /dev/null +++ b/modules/security_identity_compliance/roles_iam_resources/README.md @@ -0,0 +1,19 @@ +# Overview +This module performs the following tasks + +- Create IAM roles based on job functions +- Create IAM password policy +- Enable IAM access analyzer + +## Inputs: +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:-----:| +| application | name of application | string | none | yes | +| environment | capacity of environment (prd/dev/lab) | string | none | yes | +| customer-name | owner of aws resources | string | none | yes | +| project | name of project | string | none | yes | +| default-tags | tags to be added to resources | list | none | yes | +| aws-region-short | short name of aws region (e.g. apne1) | string | none | yes | +| create-cloudhealth-resources | create cloudhealth role | bool | none | yes | +| cloudheath-ext-id1 | cloudhealth role external id for sts | string | none | no | +| cloudheath-ext-id2 | cloudhealth role external id for sts | string | none | no | diff --git a/modules/security_identity_compliance/roles_iam_resources/access-analyzer.tf b/modules/security_identity_compliance/roles_iam_resources/access-analyzer.tf new file mode 100644 index 0000000..9a74114 --- /dev/null +++ b/modules/security_identity_compliance/roles_iam_resources/access-analyzer.tf @@ -0,0 +1,4 @@ +resource "aws_accessanalyzer_analyzer" "iam-aa" { + analyzer_name = "IAMAcecssAnalyzer" + tags = var.default-tags +} \ No newline at end of file diff --git a/modules/security_identity_compliance/roles_iam_resources/cloudhealth-role.tf b/modules/security_identity_compliance/roles_iam_resources/cloudhealth-role.tf new file mode 100644 index 0000000..01753ee --- /dev/null +++ b/modules/security_identity_compliance/roles_iam_resources/cloudhealth-role.tf @@ -0,0 +1,168 @@ +resource "aws_iam_role" "cloudhealth-role" { + count = var.create-cloudhealth-resources ? 1 : 0 + name = "CloudHealth-Role" + tags = var.default-tags + assume_role_policy = < item } + + default-tags = local.default-tags + pset-name = each.value.name + pset-desc = each.value.desc + pset-managed-policy-arn = each.value.mpolicy + pset-session-duration = each.value.session + +} + +locals { + csv_data = <<-CSV + name,desc,mpolicy,session + ViewOnly,View only access,arn:aws:iam::aws:policy/job-function/ViewOnlyAccess,PT4H + ReadOnly,Read only access,arn:aws:iam::aws:policy/ReadOnlyAccess,PT4H + FullAccess,Full admin access,arn:aws:iam::aws:policy/AdministratorAccess,PT4H + NetworkAdmin,Network admin access,arn:aws:iam::aws:policy/job-function/NetworkAdministrator,PT4H + DatabaseAdmin,Database admin access,arn:aws:iam::aws:policy/job-function/DatabaseAdministrator,PT4H + BillingAdmin,Billing admin access,arn:aws:iam::aws:policy/job-function/Billing,PT4H + SecurityAudit,Security admin access,arn:aws:iam::aws:policy/SecurityAudit,PT4H + PowerUser,Full access excluding IAM,arn:aws:iam::aws:policy/PowerUserAccess,PT4H + CSV + + items = csvdecode(local.csv_data) +} +``` \ No newline at end of file diff --git a/modules/security_identity_compliance/sso-permissionsets/main.tf b/modules/security_identity_compliance/sso-permissionsets/main.tf new file mode 100644 index 0000000..764afc4 --- /dev/null +++ b/modules/security_identity_compliance/sso-permissionsets/main.tf @@ -0,0 +1,25 @@ +data "aws_ssoadmin_instances" "sso1" {} + +resource "aws_ssoadmin_permission_set" "pset" { + name = var.pset-name + description = var.pset-desc + instance_arn = tolist(data.aws_ssoadmin_instances.sso1.arns)[0] + session_duration = var.pset-session-duration + tags = var.default-tags +} + +resource "aws_ssoadmin_managed_policy_attachment" "psetatt" { + instance_arn = tolist(data.aws_ssoadmin_instances.sso1.arns)[0] + managed_policy_arn = var.pset-managed-policy-arn + permission_set_arn = aws_ssoadmin_permission_set.pset.arn +} + +# use inline policy for additional permissions. aws sso will populate this policy to target accounts +# automatically. customer managed policies, on the other hand, needs to be created manually in the target accounts. +resource "aws_ssoadmin_permission_set_inline_policy" "pset-inline-policy1" { + count = length(var.inline-policy-json) > 0 ? 1 : 0 + instance_arn = tolist(data.aws_ssoadmin_instances.sso1.arns)[0] + permission_set_arn = aws_ssoadmin_permission_set.pset.arn + inline_policy = var.inline-policy-json +} + diff --git a/modules/security_identity_compliance/sso-permissionsets/outputs.tf b/modules/security_identity_compliance/sso-permissionsets/outputs.tf new file mode 100644 index 0000000..898c17e --- /dev/null +++ b/modules/security_identity_compliance/sso-permissionsets/outputs.tf @@ -0,0 +1,7 @@ +output pset-name { + value = aws_ssoadmin_permission_set.pset.name +} + +output pset-arn { + value = aws_ssoadmin_permission_set.pset.arn +} \ No newline at end of file diff --git a/modules/security_identity_compliance/sso-permissionsets/variables.tf b/modules/security_identity_compliance/sso-permissionsets/variables.tf new file mode 100644 index 0000000..20cd66e --- /dev/null +++ b/modules/security_identity_compliance/sso-permissionsets/variables.tf @@ -0,0 +1,6 @@ +variable pset-name {} +variable pset-desc {} +variable pset-session-duration {} +variable default-tags {} +variable pset-managed-policy-arn {} +variable inline-policy-json {} diff --git a/modules/security_identity_compliance/terraform-user/main.tf b/modules/security_identity_compliance/terraform-user/main.tf new file mode 100644 index 0000000..c5ddd0b --- /dev/null +++ b/modules/security_identity_compliance/terraform-user/main.tf @@ -0,0 +1,96 @@ +module "terraform-user" { + source = "../iam-user" + + create-access-key = true + create-password = false + default-tags = var.default-tags + iam-user-name = "${var.user-name}-${formatdate("YYYYMMDD_hhmm", timestamp())}" + managed-policy-arns = lookup(local.CannedPoliciesByServiceCategory, var.service-category) + pgp-key = var.gpg-key +} + +locals { + CannedPoliciesByServiceCategory = { + NetworkingContentDelivery = [ + "arn:aws:iam::aws:policy/NetworkAdministrator", + "arn:aws:iam::aws:policy/AmazonRoute53FullAccess", + "arn:aws:iam::aws:policy/GlobalAcceleratorFullAccess" + ] + SecurityIdentityCompliance = [ + "arn:aws:iam::aws:policy/IAMFullAccess", + "arn:aws:iam::aws:policy/SecurityAudit", + "arn:aws:iam::aws:policy/AWSSecurityHubFullAccess", + "arn:aws:iam::aws:policy/AmazonGuardDutyFullAccess", + "arn:aws:iam::aws:policy/AmazonInspectorFullAccess", + "arn:aws:iam::aws:policy/AWSSSODirectoryAdministrator", + "arn:aws:iam::aws:policy/AWSOrganizationsFullAccess", + "arn:aws:iam::aws:policy/WellArchitectedConsoleFullAccess", + "arn:aws:iam::aws:policy/AWSKeyManagementServicePowerUser", + "arn:aws:iam::aws:policy/AWSDirectoryServiceFullAccess" + ] + ManagementGovernance = [ + "arn:aws:iam::aws:policy/CloudWatchFullAccess", + "arn:aws:iam::aws:policy/CloudWatchLogsFullAccess", + "arn:aws:iam::aws:policy/CloudWatchEventsFullAccess", + "arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess", + "arn:aws:iam::aws:policy/AmazonSSMFullAccess", + "arn:aws:iam::aws:policy/AWSResourceAccessManagerFullAccess", + "arn:aws:iam::aws:policy/AWSOrganizationsFullAccess", + "arn:aws:iam::aws:policy/AmazonSQSFullAccess", + "arn:aws:iam::aws:policy/AmazonSNSFullAccess", + "arn:aws:iam::aws:policy/AWSCloudFormationFullAccess" + ] + Compute = [ + "arn:aws:iam::aws:policy/AmazonEC2FullAccess", + "arn:aws:iam::aws:policy/AmazonWorkSpacesAdmin", + "arn:aws:iam::aws:policy/AWSMarketplaceFullAccess", + "arn:aws:iam::aws:policy/AutoScalingFullAccess", + "arn:aws:iam::aws:policy/AWSImageBuilderFullAccess", + "arn:aws:iam::aws:policy/AWSBackupFullAccess" + ] + Containers = [ + "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryFullAccess", + "arn:aws:iam::aws:policy/AmazonECS_FullAccess", + "arn:aws:iam::aws:policy/AmazonEC2FullAccess" + ] + Storage = [ + "arn:aws:iam::aws:policy/AmazonS3FullAccess", + "arn:aws:iam::aws:policy/AmazonEC2FullAccess", + "arn:aws:iam::aws:policy/AmazonElasticFileSystemFullAccess", + "arn:aws:iam::aws:policy/AmazonFSxFullAccess", + "arn:aws:iam::aws:policy/AmazonGlacierFullAccess", + "arn:aws:iam::aws:policy/AWSBackupFullAccess" + ] + Database = [ + "arn:aws:iam::aws:policy/DatabaseAdministrator", + "arn:aws:iam::aws:policy/AWSBackupFullAccess" + ] + DeveloperTools = [ + "arn:aws:iam::aws:policy/AWSCodeCommitFullAccess", + "arn:aws:iam::aws:policy/AWSCodeBuildAdminAccess", + "arn:aws:iam::aws:policy/AWSCodePipeline_FullAccess" + ] + Analytics = [ + "arn:aws:iam::aws:policy/AmazonOpenSearchServiceFullAccess", + "arn:aws:iam::aws:policy/AmazonMSKFullAccess", + "arn:aws:iam::aws:policy/AmazonEMRFullAccessPolicy_v2", + "arn:aws:iam::aws:policy/AmazonRedshiftFullAccess" + ] + MachineLearning = [ + "arn:aws:iam::aws:policy/AmazonSageMakerFullAccess", + "arn:aws:iam::aws:policy/AmazonMachineLearningFullAccess", + "arn:aws:iam::aws:policy/AWSGlueConsoleFullAccess", + "arn:aws:iam::aws:policy/AWSStepFunctionsFullAccess" + ] + Serverless = [ + "arn:aws:iam::aws:policy/AWSLambda_FullAccess", + "arn:aws:iam::aws:policy/AdministratorAccess-AWSElasticBeanstalk", + "arn:aws:iam::aws:policy/AmazonAPIGatewayAdministrator", + "arn:aws:iam::aws:policy/AWSDirectoryServiceFullAccess", + "arn:aws:iam::aws:policy/AmazonSESFullAccess", + "arn:aws:iam::aws:policy/AmazonWorkSpacesAdmin" + ] + } + + +} \ No newline at end of file diff --git a/modules/security_identity_compliance/terraform-user/outputs.tf b/modules/security_identity_compliance/terraform-user/outputs.tf new file mode 100644 index 0000000..e83d263 --- /dev/null +++ b/modules/security_identity_compliance/terraform-user/outputs.tf @@ -0,0 +1,6 @@ +output keys { + value = { + access-key = module.terraform-user.iam-user-access-key-pgp + secret-key = module.terraform-user.iam-user-secret-key-pgp + } +} diff --git a/modules/security_identity_compliance/terraform-user/provider.tf b/modules/security_identity_compliance/terraform-user/provider.tf new file mode 100644 index 0000000..6bdf7d8 --- /dev/null +++ b/modules/security_identity_compliance/terraform-user/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.3.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 4.40" + } + } +} \ No newline at end of file diff --git a/modules/security_identity_compliance/terraform-user/variables.tf b/modules/security_identity_compliance/terraform-user/variables.tf new file mode 100644 index 0000000..65844df --- /dev/null +++ b/modules/security_identity_compliance/terraform-user/variables.tf @@ -0,0 +1,7 @@ +variable default-tags {} +variable user-name { + type = string + default = "terraform-role" +} +variable service-category {} +variable gpg-key {} \ No newline at end of file diff --git a/modules/storage/aws-backup/README.md b/modules/storage/aws-backup/README.md new file mode 100644 index 0000000..29a1aa5 --- /dev/null +++ b/modules/storage/aws-backup/README.md @@ -0,0 +1,47 @@ + +## Requirements + +No requirements. + +## Providers + +| Name | Version | +|------|---------| +| aws | n/a | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_backup_plan.ab-plan](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/backup_plan) | resource | +| [aws_backup_region_settings.ab-settings](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/backup_region_settings) | resource | +| [aws_backup_selection.ab-selection-by-service-type](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/backup_selection) | resource | +| [aws_backup_vault.ab-vault](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/backup_vault) | resource | +| [aws_backup_vault_policy.ab-vault-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/backup_vault_policy) | resource | +| [aws_iam_role.ab-iam-role](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_iam_role_policy_attachment.ab-iam-role-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy_attachment) | resource | +| [aws_kms_alias.ab-kms-key-alias](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kms_alias) | resource | +| [aws_kms_key.ab-kms-key](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kms_key) | resource | +| [aws_caller_identity.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| daily-backup-cron | Daily backup rule cron expression | `string` | n/a | yes | +| daily-backup-retention | Daily backup retention period | `number` | n/a | yes | +| monthly-backup-cron | Monthly backup rule cron expression | `string` | n/a | yes | +| monthly-backup-retention | Monthly backup retention period | `number` | n/a | yes | +| service-opt-in | n/a |
map(object({
enabled = bool
}))
|
{
"Aurora": {
"enabled": false
},
"DynamoDB": {
"enabled": true
},
"EBS": {
"enabled": false
},
"EC2": {
"enabled": true
},
"EFS": {
"enabled": true
},
"FSx": {
"enabled": false
},
"RDS": {
"enabled": true
},
"Redshift": {
"enabled": true
},
"S3": {
"enabled": false
},
"VirtualMachine": {
"enabled": false
}
}
| no | + +## Outputs + +No outputs. + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/storage/aws-backup/kms-key.tf b/modules/storage/aws-backup/kms-key.tf new file mode 100644 index 0000000..ddb3397 --- /dev/null +++ b/modules/storage/aws-backup/kms-key.tf @@ -0,0 +1,43 @@ +data "aws_caller_identity" "this" {} + +resource "aws_kms_key" "ab-kms-key" { + description = "KMS key for aws backup" + deletion_window_in_days = 10 + policy = jsonencode( + { + "Version" : "2012-10-17", + "Id" : "awsbackup-service", + "Statement" : [ + { + "Sid" : "Enable IAM User Permissions", + "Effect" : "Allow", + "Principal" : { + "AWS" : "arn:aws:iam::${data.aws_caller_identity.this.id}:root" + }, + "Action" : "kms:*", + "Resource" : "*" + }, + { + "Sid" : "Allow attachment of persistent resources", + "Effect" : "Allow", + "Principal" : "*", + "Action" : [ + "kms:CreateGrant", + "kms:ListGrants", + "kms:RevokeGrant" + ], + "Resource" : "*", + "Condition" : { + "Bool" : { + "kms:GrantIsForAWSResource" : "true" + } + } + } + ] + }) +} + +resource "aws_kms_alias" "ab-kms-key-alias" { + name = "alias/awsbackup-kms-key" + target_key_id = aws_kms_key.ab-kms-key.id +} diff --git a/modules/storage/aws-backup/main.tf b/modules/storage/aws-backup/main.tf new file mode 100644 index 0000000..d4cc5b0 --- /dev/null +++ b/modules/storage/aws-backup/main.tf @@ -0,0 +1,176 @@ +# build local data structure + +locals { + backup-config = { + "Aurora" : { + enabled = var.service-opt-in.Aurora.enabled + arn-prefix = "arn:aws:rds:*:*:cluster:*" + } + "DynamoDB" : { + enabled = var.service-opt-in.DynamoDB.enabled + arn-prefix = "arn:aws:dynamodb:*:*:table/*" + } + "EBS" : { + enabled = var.service-opt-in.EBS.enabled + arn-prefix = "arn:aws:ec2:*:*:volume/*" + } + "EC2" : { + enabled = var.service-opt-in.EC2.enabled + arn-prefix = "arn:aws:ec2:*:*:instance/*" + } + "EFS" : { + enabled = var.service-opt-in.EFS.enabled + arn-prefix = "arn:aws:elasticfilesystem:*:*:file-system/*" + } + "FSx" : { + enabled = var.service-opt-in.FSx.enabled + arn-prefix = "arn:*:fsx:*" + } + "Redshift" : { + enabled = var.service-opt-in.Redshift.enabled + arn-prefix = "arn:aws:redshift:*:*:cluster:*" + } + "RDS" : { + enabled = var.service-opt-in.RDS.enabled + arn-prefix = "arn:aws:rds:*:*:db:*" + } + # this version can't handle space + # "Storage Gateway" : { + # enabled = var.opt-in-storagegateway + # arn-prefix = "arn:aws:storagegateway:*:*:gateway/*" + # } + "VirtualMachine" : { + enabled = var.service-opt-in.VirtualMachine.enabled + arn-prefix = "arn:aws:backup-gateway:*:*:vm/*" + } + "S3" : { + enabled = var.service-opt-in.S3.enabled + arn-prefix = "arn:aws:s3:::*" + } + } +} + +resource "aws_backup_region_settings" "ab-settings" { + resource_type_opt_in_preference = { + for k, v in local.backup-config : k => v.enabled + } +} + +resource "aws_backup_vault" "ab-vault" { + for_each = toset([ + for k, v in local.backup-config : k + if v.enabled + ]) + name = "BackupVault-${each.value}" + kms_key_arn = aws_kms_key.ab-kms-key.arn +} + +resource "aws_backup_vault_policy" "ab-vault-policy" { + for_each = aws_backup_vault.ab-vault + backup_vault_name = each.value.name + policy = jsonencode( + { + "Version" : "2012-10-17", + "Id" : "default", + "Statement" : [ + { + "Sid" : "default", + "Effect" : "Allow", + "Principal" : { + "AWS" : data.aws_caller_identity.this.account_id + }, + "Action" : [ + "backup:DescribeBackupVault", + "backup:DeleteBackupVault", + "backup:PutBackupVaultAccessPolicy", + "backup:DeleteBackupVaultAccessPolicy", + "backup:GetBackupVaultAccessPolicy", + "backup:StartBackupJob", + "backup:GetBackupVaultNotifications", + "backup:PutBackupVaultNotifications" + ], + "Resource" : each.value.arn + } + ] + }) +} + +resource "aws_backup_plan" "ab-plan" { + for_each = aws_backup_vault.ab-vault + name = "BackupPlan-${replace(each.value.name, "BackupVault-", "")}" + + # daily backup + rule { + rule_name = "Daily" + target_vault_name = each.value.name + schedule = var.daily-backup-cron + start_window = 60 + completion_window = 240 + + lifecycle { + delete_after = var.daily-backup-retention + } + + recovery_point_tags = { + "CreatedBy" : "AWSBackup" + "AWSBackupPlan" : "BackupPlan-${replace(each.value.name, "BackupVault-", "")}-Daily" + } + } + + # monthly backup (when overlap with daily, only monthly backup will be created. + # see https://docs.aws.amazon.com/aws-backup/latest/devguide/creating-a-backup-plan.html) + rule { + rule_name = "Monthly" + target_vault_name = each.value.name + schedule = var.monthly-backup-cron + start_window = 60 + completion_window = 240 + + lifecycle { + delete_after = var.monthly-backup-retention + cold_storage_after = var.daily-backup-retention # move to cold storage after daily retention, supported on a few services only + } + + recovery_point_tags = { + "CreatedBy" : "AWSBackup" + "AWSBackupPlan" : "BackupPlan-${replace(each.value.name, "BackupVault-", "")}-Monthly" + } + } + + # advanced_backup_setting { + # backup_options = { + # WindowsVSS = "enabled" + # } + # resource_type = "EC2" + # } +} +# +resource "aws_iam_role" "ab-iam-role" { + name = "AwsBackupRole" + assume_role_policy = jsonencode( + { + "Version" : "2012-10-17", + "Statement" : [ + { + "Action" : ["sts:AssumeRole"], + "Effect" : "allow", + "Principal" : { + "Service" : ["backup.amazonaws.com"] + } + } + ] + }) +} + +resource "aws_iam_role_policy_attachment" "ab-iam-role-policy" { + policy_arn = "arn:aws:iam::aws:policy/service-role/AWSBackupServiceRolePolicyForBackup" + role = aws_iam_role.ab-iam-role.name +} + +resource "aws_backup_selection" "ab-selection-by-service-type" { + for_each = aws_backup_plan.ab-plan + iam_role_arn = aws_iam_role.ab-iam-role.arn + name = "SelectionByServiceType" + plan_id = each.value.id + resources = [lookup(local.backup-config, replace(each.value.name, "BackupPlan-", "")).arn-prefix] +} diff --git a/modules/storage/aws-backup/variables.tf b/modules/storage/aws-backup/variables.tf new file mode 100644 index 0000000..ea30eb4 --- /dev/null +++ b/modules/storage/aws-backup/variables.tf @@ -0,0 +1,57 @@ +variable "daily-backup-cron" { + type = string + description = "Daily backup rule cron expression" +} + +variable "monthly-backup-cron" { + type = string + description = "Monthly backup rule cron expression" +} + +variable "daily-backup-retention" { + type = number + description = "Daily backup retention period" +} + +variable "monthly-backup-retention" { + type = number + description = "Monthly backup retention period" +} + +variable "service-opt-in" { + type = map(object({ + enabled = bool + })) + default = { + "Aurora" : { + enabled = false + } + "DynamoDB" : { + enabled = true + } + "EBS" : { + enabled = false + } + "EC2" : { + enabled = true + } + "EFS" : { + enabled = true + } + "FSx" : { + enabled = false + } + "Redshift" : { + enabled = true + } + "RDS" : { + enabled = true + } + "VirtualMachine" : { + enabled = false + } + "S3" : { + enabled = false + } + } +} \ No newline at end of file diff --git a/modules/storage/infra-s3-bucket/README.md b/modules/storage/infra-s3-bucket/README.md new file mode 100644 index 0000000..70880ed --- /dev/null +++ b/modules/storage/infra-s3-bucket/README.md @@ -0,0 +1,19 @@ +# Overview +This module creates s3 bucket using default settings and AWS AES256 encryption +The bucket is meant for infrastructure use. Versioning is off and object expires in 90 days + +## Inputs: +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:-----:| +| application | name of application | string | none | yes | +| environment | capacity of environment (prd/dev/lab) | string | none | yes | +| customer-name | owner of aws resources | string | none | yes | +| project | name of project | string | none | yes | +| default-tags | tags to be added to resources | list | none | yes | +| aws-region-short | short name of aws region (e.g. apne1) | string | none | yes | +| bucket-name | name or prefix of s3 bucket | string | none | yes | +| add-random-suffix | Whether to append a random string to bucket name | bool | false | no | +| bucket-policy-json | bucket policy | json | none | yes | +| enable-bucket-versioning | Whether to enable bucket versioning | bool | false | no | +| bucket-retain-days | Days before s3 objects are expired on s3 | number | 90 | no | + diff --git a/modules/storage/infra-s3-bucket/main.tf b/modules/storage/infra-s3-bucket/main.tf new file mode 100644 index 0000000..0b6132f --- /dev/null +++ b/modules/storage/infra-s3-bucket/main.tf @@ -0,0 +1,82 @@ +module random-suffix { + source = "../../util/random" +} + +resource "aws_s3_bucket" "s3bucket" { + bucket = var.add-random-suffix ? "${var.bucket-name}-${module.random-suffix.number}" : var.bucket-name + tags = var.default-tags +} + +resource "aws_s3_bucket_policy" "bucket-policy" { + bucket = aws_s3_bucket.s3bucket.bucket + policy = var.bucket-policy-json + +} + resource "aws_s3_bucket_lifecycle_configuration" "bucket-lifecycle-config" { + count = var.bucket-enable-lifecycle ? 1 : 0 + + bucket = aws_s3_bucket.s3bucket.bucket + + rule { + id = "default" + status = "Enabled" + + dynamic "noncurrent_version_expiration" { + for_each = var.enable-bucket-versioning ? [1] : [] + content { + noncurrent_days = 90 + } + } + + dynamic "expiration" { + for_each = var.bucket-retain-days > 0 ? [1] : [] + content { + days = var.bucket-retain-days + } + } + + transition { + days = var.transition-ia-days + storage_class = "STANDARD_IA" + } + } +} + +resource "aws_s3_bucket_acl" "bucket-acl" { + bucket = aws_s3_bucket.s3bucket.bucket + acl = var.bucket-acl +} + +resource "aws_s3_bucket_versioning" "bucket-versioning" { + count = var.enable-bucket-versioning ? 1 : 0 + bucket = aws_s3_bucket.s3bucket.id + versioning_configuration { + status = "Enabled" + } +} + +resource "aws_s3_bucket_server_side_encryption_configuration" "bucket-encryption" { + bucket = aws_s3_bucket.s3bucket.bucket + rule { + apply_server_side_encryption_by_default { + sse_algorithm = "AES256" + } + } +} + +resource "aws_s3_bucket_public_access_block" "s3-public-access-settings" { + bucket = aws_s3_bucket.s3bucket.id + + block_public_acls = true + block_public_policy = true + ignore_public_acls = true + restrict_public_buckets = true +} + +resource "aws_s3_bucket_ownership_controls" "ctbucket-ownership-setting" { + bucket = aws_s3_bucket.s3bucket.id + + rule { + object_ownership = "BucketOwnerPreferred" + } +} \ No newline at end of file diff --git a/modules/storage/infra-s3-bucket/outputs.tf b/modules/storage/infra-s3-bucket/outputs.tf new file mode 100644 index 0000000..46af43c --- /dev/null +++ b/modules/storage/infra-s3-bucket/outputs.tf @@ -0,0 +1,3 @@ +output bucket-name { + value = aws_s3_bucket.s3bucket.id +} \ No newline at end of file diff --git a/modules/storage/infra-s3-bucket/variables.tf b/modules/storage/infra-s3-bucket/variables.tf new file mode 100644 index 0000000..02ae502 --- /dev/null +++ b/modules/storage/infra-s3-bucket/variables.tf @@ -0,0 +1,30 @@ +variable "default-tags" {} +variable "bucket-retain-days" { + type = number + default = 90 +} +variable "bucket-name" {} +variable "bucket-policy-json" {} +variable "enable-bucket-versioning" { + type = bool + default = false +} +variable "add-random-suffix" { + type = bool + default = false +} + +variable bucket-acl { + type = string + default = "private" +} + +variable bucket-enable-lifecycle { + type = bool + default = true +} + +variable transition-ia-days { + type = number + default = 30 +} \ No newline at end of file diff --git a/modules/storage/s3-bucket-replication/README.md b/modules/storage/s3-bucket-replication/README.md new file mode 100644 index 0000000..8904c0a --- /dev/null +++ b/modules/storage/s3-bucket-replication/README.md @@ -0,0 +1,50 @@ + +## Requirements + +| Name | Version | +|------|---------| +| terraform | >= 1.3.0 | +| aws | >= 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| aws | >= 5.0 | +| random | n/a | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_iam_role.replication-role](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource | +| [aws_iam_role_policy.role-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy) | resource | +| [aws_s3_bucket_replication_configuration.replication-config](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_replication_configuration) | resource | +| [random_id.rid](https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/id) | resource | +| [aws_iam_policy_document.assume_role_policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_policy_document) | data source | +| [aws_iam_policy_document.replication-role-policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_policy_document) | data source | +| [aws_s3_bucket.destination-bucket](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/s3_bucket) | data source | +| [aws_s3_bucket.source-bucket](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/s3_bucket) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|------------------|:--------:| +| destination-bucket-account-id | Account id of destination bucket. | `string` | `"111122223333"` | no | +| destination-bucket-encryption-key-arn | Encryption key arn for destination bucket | `string` | n/a | yes | +| destination-bucket-name | Name of destination bucket | `string` | n/a | yes | +| source-bucket-name | Name of source s3 bucket | `string` | n/a | yes | + +## Outputs + +| Name | Description | +|------|-------------| +| replication-role-arn | n/a | + +--- +## Authorship +This module was developed by xpk. \ No newline at end of file diff --git a/modules/storage/s3-bucket-replication/main.tf b/modules/storage/s3-bucket-replication/main.tf new file mode 100644 index 0000000..f114e26 --- /dev/null +++ b/modules/storage/s3-bucket-replication/main.tf @@ -0,0 +1,152 @@ +# sets up data sources for s3 buckets + +data "aws_s3_bucket" "source-bucket" { + bucket = var.source-bucket-name +} + +data "aws_s3_bucket" "destination-bucket" { + bucket = var.destination-bucket-name +} + +# Create replication role in source account +data "aws_iam_policy_document" "assume_role_policy" { + statement { + actions = ["sts:AssumeRole"] + + principals { + type = "Service" + identifiers = ["s3.amazonaws.com"] + } + } +} + +data "aws_iam_policy_document" "replication-role-policy" { + statement { + sid = "AccessToReplicaBucket" + actions = [ + "s3:ReplicateObject", + "s3:ReplicateDelete", + "s3:ReplicateTags", + "s3:ObjectOwnerOverrideToBucketOwner" + ] + effect = "Allow" + resources = [ + data.aws_s3_bucket.source-bucket.arn, + data.aws_s3_bucket.destination-bucket.arn, + "${data.aws_s3_bucket.source-bucket.arn}/*", + "${data.aws_s3_bucket.destination-bucket.arn}/*" + ] + } + statement { + sid = "ReadAccessOnSourceBuckets" + actions = ["s3:Get*", "s3:List*"] + effect = "Allow" + resources = [ + data.aws_s3_bucket.source-bucket.arn, + ] + } + statement { + sid = "ObjectAccessOnSourceBuckets" + actions = [ + "s3:GetObjectVersionForReplication", + "s3:GetObjectVersionAcl", + "s3:GetObjectVersionTagging" + ] + effect = "Allow" + resources = [ + "${data.aws_s3_bucket.source-bucket.arn}/*" + ] + } + statement { + sid = "DecryptSourceBucketObjects" + actions = [ + "kms:Decrypt" + ] + effect = "Allow" + resources = ["*"] + } + statement { + sid = "EncryptReplicaObjects" + actions = [ + "kms:Encrypt" + ] + effect = "Allow" + resources = ["*"] + } +} + +resource "random_id" "rid" { + byte_length = 4 +} + +resource "aws_iam_role" "replication-role" { + name = "BucketReplicationRole${random_id.rid.dec}" + assume_role_policy = data.aws_iam_policy_document.assume_role_policy.json +} + +resource "aws_iam_role_policy" "role-policy" { + name = "bucket-replication" + role = aws_iam_role.replication-role.id + policy = data.aws_iam_policy_document.replication-role-policy.json +} + +# Setup bucket replication +resource "aws_s3_bucket_replication_configuration" "replication-config" { + role = aws_iam_role.replication-role.arn + bucket = var.source-bucket-name + + rule { + id = "ReplicateAll" + + status = "Enabled" + + source_selection_criteria { + sse_kms_encrypted_objects { + status = "Enabled" + } + } + + # V2 replication configurations + delete_marker_replication { + status = "Enabled" + } + + filter { + } + + destination { + bucket = data.aws_s3_bucket.destination-bucket.arn + storage_class = "INTELLIGENT_TIERING" + account = var.destination-bucket-account-id + + access_control_translation { + owner = "Destination" + } + + encryption_configuration { + replica_kms_key_id = var.destination-bucket-encryption-key-arn + } + + replication_time { + status = "Enabled" + time { + minutes = 15 + } + } + + metrics { + status = "Enabled" + event_threshold { + minutes = 15 + } + } + } + } +} + +resource "aws_s3_object" "test-file" { + depends_on = [aws_s3_bucket_replication_configuration.replication-config] + bucket = data.aws_s3_bucket.source-bucket.id + key = "replication-test-file" + content = "If this file shows up in the destination bucket, replication has been successfully configured." +} \ No newline at end of file diff --git a/modules/storage/s3-bucket-replication/outputs.tf b/modules/storage/s3-bucket-replication/outputs.tf new file mode 100644 index 0000000..fd0bfde --- /dev/null +++ b/modules/storage/s3-bucket-replication/outputs.tf @@ -0,0 +1,3 @@ +output replication-role-arn { + value = aws_iam_role.replication-role.arn +} \ No newline at end of file diff --git a/modules/storage/s3-bucket-replication/variables.tf b/modules/storage/s3-bucket-replication/variables.tf new file mode 100644 index 0000000..f58caf0 --- /dev/null +++ b/modules/storage/s3-bucket-replication/variables.tf @@ -0,0 +1,20 @@ +variable source-bucket-name { + type = string + description = "Name of source s3 bucket" +} + +variable destination-bucket-name { + type = string + description = "Name of destination bucket" +} + +variable destination-bucket-account-id { + type = string + description = "Account id of destination bucket. Defaults to BEA-SYS-LOG-UAT" + default = "894849410890" +} + +variable destination-bucket-encryption-key-arn { + type = string + description = "Encryption key arn for destination bucket" +} \ No newline at end of file diff --git a/modules/storage/s3-bucket-replication/versions.tf b/modules/storage/s3-bucket-replication/versions.tf new file mode 100644 index 0000000..f0f3f05 --- /dev/null +++ b/modules/storage/s3-bucket-replication/versions.tf @@ -0,0 +1,10 @@ +terraform { + required_version = ">= 1.3.0" + + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} diff --git a/modules/storage/s3_bucket_2023/README.md b/modules/storage/s3_bucket_2023/README.md new file mode 100644 index 0000000..a4ccbd9 --- /dev/null +++ b/modules/storage/s3_bucket_2023/README.md @@ -0,0 +1,263 @@ +# s3_bucket_2023 module +This module creates s3 bucket, following new terraform standards. + +If lifecycle policy is enabled, provide the expiration days. +Transition days are hard-coded with intelligent-tiering class to simplify administration. + +## Example +```hcl +module "bucket1" { + source = "../../../../whk1-bea-sys-ss-prd-codecommit-sharedmodules/Storage/s3_bucket_2023" + + bucket_name = var.bucket_name1 + bucket_policy_json = jsonencode( + { + "Version" : "2012-10-17", + "Id" : "", + "Statement" : [ + { + "Sid" : "Set permissions for objects", + "Effect" : "Allow", + "Principal" : { + "AWS" : "851239346925" + }, + "Action" : ["s3:ReplicateObject", "s3:ReplicateDelete"], + "Resource" : "arn:aws:s3:::${var.bucket_name1}/*" + } + ] + } + ) + enable_encryption = true + encryption_key_arn = var.encryption_key_arn + enable_versioning = false + enable_bucket_logging = false + enable_bucket_lifecycle = true + current_version_expiration_days = 731 + noncurrent_version_expiration_days = 731 +} + +``` + +## Note on bucket replication +To securely replicate a bucket to a bucket in another aws account, kms key is required. + +Steps to setup replication are: +1. Create replication iam role on the source account, with an assume role policy trusting s3 +```json + { + "Effect":"Allow", + "Principal":{ + "Service":"s3.amazonaws.com" + }, + "Action":"sts:AssumeRole" + } +``` +The role needs permissions granted in the role iam policy. For example: +```json +{ + "Statement": [ + { + "Action": [ + "s3:ListBucket", + "s3:GetReplicationConfiguration" + ], + "Effect": "Allow", + "Resource": "arn:aws:s3:::whk1-bea-icc-mbk-prd-vpc01-flowlog-s3-accept", + "Sid": "" + }, + { + "Action": [ + "s3:GetObjectVersionTagging", + "s3:GetObjectVersionForReplication", + "s3:GetObjectVersionAcl" + ], + "Effect": "Allow", + "Resource": "arn:aws:s3:::whk1-bea-icc-mbk-prd-vpc01-flowlog-s3-accept/*", + "Sid": "" + }, + { + "Action": [ + "s3:ReplicateTags", + "s3:ReplicateObject", + "s3:ReplicateDelete", + "s3:ObjectOwnerOverrideToBucketOwner" + ], + "Effect": "Allow", + "Resource": "arn:aws:s3:::whk1-bea-icc-log-mbk-prd-vpc01-flowlog-s3-accept/*", + "Sid": "" + }, + { + "Effect": "Allow", + "Action": [ + "kms:Decrypt", + "kms:GenerateDataKey" + ], + "Resource": [ + "arn:aws:kms:ap-east-1:851239346925:key/708b6ece-05f5-40ed-a91c-dbcf2af46407" + ] + }, + { + "Effect": "Allow", + "Action": [ + "kms:GenerateDataKey", + "kms:Encrypt" + ], + "Resource": [ + "arn:aws:kms:ap-east-1:894849410890:key/b555d9d6-d451-4ec8-8ca2-cb6849cadee4" + ] + } + ], + "Version": "2012-10-17" +} +``` +If bucket key is used, then additional permission needs to be granted +```json +{ + "Action":[ + "kms:Decrypt" + ], + "Effect":"Allow", + "Condition":{ + "StringLike":{ + "kms:ViaService":"s3.ap-east-1.amazonaws.com", + "kms:EncryptionContext:aws:s3:arn":[ + "arn:aws:s3:::/*" + ] + } + }, + "Resource":[ + "arn:aws:kms:ap-east-1::key/" + ] + }, + { + "Action":[ + "kms:Encrypt" + ], + "Effect":"Allow", + "Condition":{ + "StringLike":{ + "kms:ViaService":"s3.ap-east-1.amazonaws.com", + "kms:EncryptionContext:aws:s3:arn":[ + "arn:aws:s3:::/*" + ] + } + }, + "Resource":[ + "arn:aws:kms:ap-east-1::key/" + ] + } +``` + +2. On the destination account, grant access in KMS key policy +```json +{ + "Version": "2012-10-17", + "Id": "key-consolepolicy-3", + "Statement": [ + { + "Sid": "Enable IAM User Permissions", + "Effect": "Allow", + "Principal": { + "AWS": "arn:aws:iam:::root" + }, + "Action": "kms:*", + "Resource": "*" + }, + { + "Sid": "Allow use of the key", + "Effect": "Allow", + "Principal": { + "AWS": [ + "arn:aws:iam:::root", + "arn:aws:iam:::root" + ] + }, + "Action": [ + "kms:Encrypt", + "kms:Decrypt", + "kms:ReEncrypt*", + "kms:GenerateDataKey*", + "kms:DescribeKey" + ], + "Resource": "*" + }, + { + "Sid": "Allow attachment of persistent resources", + "Effect": "Allow", + "Principal": { + "AWS": [ + "arn:aws:iam:::root", + "arn:aws:iam:::root" + ] + }, + "Action": [ + "kms:CreateGrant", + "kms:ListGrants", + "kms:RevokeGrant" + ], + "Resource": "*", + "Condition": { + "Bool": { + "kms:GrantIsForAWSResource": "true" + } + } + }, + { + "Sid": "Allow AWS Service to use the key", + "Effect": "Allow", + "Principal": { + "Service": [ + "s3.amazonaws.com", + "delivery.logs.amazonaws.com", + "cloudtrail.amazonaws.com" + ] + }, + "Action": [ + "kms:Encrypt", + "kms:Decrypt", + "kms:ReEncrypt*", + "kms:GenerateDataKey*", + "kms:DescribeKey" + ], + "Resource": "*" + } + ] +} +``` + +3. Edit destination bucket policy +```json +{ + "Version": "2012-10-17", + "Id": "", + "Statement": [ + { + "Sid": "Set permissions for objects", + "Effect": "Allow", + "Principal": { + "AWS": "arn:aws:iam:::root" + }, + "Action": [ + "s3:ReplicateDelete", + "s3:ReplicateObject", + "s3:ReplicateTags", + "s3:ObjectOwnerOverrideToBucketOwner" + ], + "Resource": "arn:aws:s3:::/*" + }, + { + "Sid": "Set permissions on bucket", + "Effect": "Allow", + "Principal": { + "AWS": "arn:aws:iam:::root" + }, + "Action": [ + "s3:List*", + "s3:GetBucketVersioning", + "s3:PutBucketVersioning" + ], + "Resource": "arn:aws:s3:::" + } + ] +} +``` diff --git a/modules/storage/s3_bucket_2023/main.tf b/modules/storage/s3_bucket_2023/main.tf new file mode 100644 index 0000000..26cc06d --- /dev/null +++ b/modules/storage/s3_bucket_2023/main.tf @@ -0,0 +1,173 @@ +resource "aws_s3_bucket" "this" { + bucket = var.bucket_name + force_destroy = var.bucket_force_destroy +} + +resource "aws_s3_bucket_public_access_block" "block_public_access" { + bucket = aws_s3_bucket.this.id + + block_public_acls = true + block_public_policy = true + ignore_public_acls = true + restrict_public_buckets = true +} + +# Add SecureTransport restriction by default +data "aws_iam_policy_document" "bucket_policy" { + source_policy_documents = [var.bucket_policy_json] + + statement { + sid = "AllowSSLRequestsOnly" + actions = ["s3:*"] + effect = "Deny" + principals { + type = "*" + identifiers = ["*"] + } + resources = [ + aws_s3_bucket.this.arn, + "${aws_s3_bucket.this.arn}/*" + ] + condition { + test = "Bool" + values = [false] + variable = "aws:SecureTransport" + } + } +} + +resource "aws_s3_bucket_policy" "bucket_policy" { + bucket = aws_s3_bucket.this.id + # policy = var.bucket_policy_json + policy = data.aws_iam_policy_document.bucket_policy.json +} + +resource "aws_s3_bucket_lifecycle_configuration" "lifecycle" { + count = var.enable_bucket_lifecycle ? 1 : 0 + bucket = aws_s3_bucket.this.id + rule { + id = "CurrentVersion" + + expiration { + days = var.current_version_expiration_days + } + + status = "Enabled" + + transition { + days = 15 + storage_class = "INTELLIGENT_TIERING" + } + } + + rule { + id = "NonCurrentVersion" + + noncurrent_version_expiration { + noncurrent_days = var.noncurrent_version_expiration_days + } + + noncurrent_version_transition { + noncurrent_days = 15 + storage_class = "INTELLIGENT_TIERING" + } + + status = var.enable_versioning ? "Enabled" : "Disabled" + } +} + + +resource "aws_s3_bucket_intelligent_tiering_configuration" "intel_tiering_config" { + bucket = aws_s3_bucket.this.id + name = "IntelligentTieringArchiveConfigurations" + + tiering { + access_tier = "DEEP_ARCHIVE_ACCESS" + days = 180 # minimum + } + tiering { + access_tier = "ARCHIVE_ACCESS" + days = 90 + } +} + +resource "aws_s3_bucket_logging" "logging" { + count = var.enable_bucket_logging ? 1 : 0 + bucket = aws_s3_bucket.this.id + target_bucket = var.logging_bucket_id + target_prefix = "s3-log/" +} + +resource "aws_s3_bucket_server_side_encryption_configuration" "encryption" { + count = var.enable_encryption ? 1 : 0 + bucket = aws_s3_bucket.this.id + rule { + apply_server_side_encryption_by_default { + kms_master_key_id = var.encryption_key_arn + sse_algorithm = length(var.encryption_key_arn) > 0 ? "aws:kms" : "AES256" + } + bucket_key_enabled = length(var.encryption_key_arn) > 0 ? true : false + } +} + +resource "aws_s3_bucket_versioning" "versioning" { + count = var.enable_versioning ? 1 : 0 + bucket = aws_s3_bucket.this.id + versioning_configuration { + status = "Enabled" + } +} + +resource "aws_s3_bucket_replication_configuration" "replication" { + count = var.enable_replication && var.enable_versioning ? 1 : 0 + role = var.replication_role_arn + bucket = aws_s3_bucket.this.id + + + rule { + id = "replrule1" + status = "Enabled" + delete_marker_replication { + status = "Enabled" + } + + source_selection_criteria { + replica_modifications { + status = "Enabled" + } + sse_kms_encrypted_objects { + status = "Enabled" + } + } + + destination { + bucket = var.replication_dest_bucket_name + storage_class = "INTELLIGENT_TIERING" + + account = var.replication_destination_aws_account_id + + encryption_configuration { + replica_kms_key_id = var.replication_destination_kms_key_arn + } + + access_control_translation { + owner = "Destination" + } + + replication_time { + status = "Enabled" + time { + minutes = 15 + } + } + + metrics { + status = "Enabled" + event_threshold { + minutes = 15 + } + } + } + } +} + diff --git a/modules/storage/s3_bucket_2023/outputs.tf b/modules/storage/s3_bucket_2023/outputs.tf new file mode 100644 index 0000000..a321e73 --- /dev/null +++ b/modules/storage/s3_bucket_2023/outputs.tf @@ -0,0 +1,7 @@ +output bucket_name { + value = aws_s3_bucket.this.id +} + +output bucket_arn { + value = aws_s3_bucket.this.arn +} \ No newline at end of file diff --git a/modules/storage/s3_bucket_2023/variables.tf b/modules/storage/s3_bucket_2023/variables.tf new file mode 100644 index 0000000..eea730d --- /dev/null +++ b/modules/storage/s3_bucket_2023/variables.tf @@ -0,0 +1,89 @@ +variable "bucket_name" { + type = string + description = "Name of bucket" +} + +variable "bucket_force_destroy" { + type = bool + default = false + description = "Indicates all objects should be deleted from the bucket when the bucket is destroyed." +} + +variable "bucket_policy_json" { + type = string + default = "{}" + description = "Json-encoded bucket policy. The AllowSSLRequestsOnly policy is merged with this input." +} + +variable "current_version_expiration_days" { + type = number + default = 2560 + description = "731 for flowlogs" + validation { + condition = var.current_version_expiration_days > 15 + error_message = "Must be greater than 15 days" + } +} + +variable "noncurrent_version_expiration_days" { + type = number + default = 2560 + description = "731 for flowlogs" +} + +variable "enable_bucket_logging" { + type = bool + description = "Enable bucket logging" +} +variable "logging_bucket_id" { + type = string + default = null + description = "Logging bucket id" +} +variable "enable_encryption" { + type = bool + description = "Enable encryption for s3 bucket" +} +variable "encryption_key_arn" { + type = string + default = "" + description = "Leave blank to use AES256" +} +variable "enable_versioning" { + type = bool + description = "Enable s3 bucket versioning" +} +variable "enable_bucket_lifecycle" { + type = bool + description = "Enable s3 bucket lifecycle" +} + +variable "enable_replication" { + type = bool + default = false + description = "Enable s3 bucket replication" +} + +variable "replication_role_arn" { + type = string + default = null + description = "IAM role of s3 bucket replication" +} + +variable "replication_dest_bucket_name" { + type = string + default = null + description = "Replica bucket name" +} + +variable "replication_destination_aws_account_id" { + type = number + default = null + description = "AWS account id of replica bucket" +} + +variable "replication_destination_kms_key_arn" { + type = string + default = null + description = "KMS key ARN of destination bucket" +} \ No newline at end of file diff --git a/modules/storage/s3_bucket_2023/versions.tf b/modules/storage/s3_bucket_2023/versions.tf new file mode 100644 index 0000000..cd4b7aa --- /dev/null +++ b/modules/storage/s3_bucket_2023/versions.tf @@ -0,0 +1,10 @@ +terraform { + required_version = ">= 1.3.0" + + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 3.72.0" + } + } +} diff --git a/modules/syntax-test/main.tf b/modules/syntax-test/main.tf new file mode 100644 index 0000000..02f641e --- /dev/null +++ b/modules/syntax-test/main.tf @@ -0,0 +1,11 @@ +resource aws_iam_role this { + for_each = var.roles + name = each.key + assume_role_policy = each.value["assume_role_policy"] +} + +resource "aws_iam_role_policy_attachment" "fargate-policy-attachment" { + for_each = aws_iam_role.this + policy_arn = "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess" + role = each.value["name"] +} \ No newline at end of file diff --git a/modules/syntax-test/variables.tf b/modules/syntax-test/variables.tf new file mode 100644 index 0000000..b094c97 --- /dev/null +++ b/modules/syntax-test/variables.tf @@ -0,0 +1 @@ +variable roles {} \ No newline at end of file diff --git a/modules/terraform-setup/README.md b/modules/terraform-setup/README.md new file mode 100644 index 0000000..626886b --- /dev/null +++ b/modules/terraform-setup/README.md @@ -0,0 +1,9 @@ +# terraform-setup module +Module for creating terraform state bucket and locks. + +The output ```provider-config-block``` shows how to configure terraform provider. + +Please enable terraform default tags. See https://www.hashicorp.com/blog/default-tags-in-the-terraform-aws-provider + +## Examples +See examples in the examples directory. diff --git a/modules/terraform-setup/examples/.terraform.lock.hcl b/modules/terraform-setup/examples/.terraform.lock.hcl new file mode 100644 index 0000000..8953a5b --- /dev/null +++ b/modules/terraform-setup/examples/.terraform.lock.hcl @@ -0,0 +1,10 @@ +# This file is maintained automatically by "terraform init". +# Manual edits may be lost in future updates. + +provider "registry.terraform.io/hashicorp/aws" { + version = "4.26.0" + constraints = ">= 3.25.0" + hashes = [ + "h1:jt8jLpFFhaapdbBqw4WQpDuLN8y7zF8/iLyCzypDxSQ=", + ] +} diff --git a/modules/terraform-setup/examples/main.tf b/modules/terraform-setup/examples/main.tf new file mode 100644 index 0000000..940d79b --- /dev/null +++ b/modules/terraform-setup/examples/main.tf @@ -0,0 +1,46 @@ +# variables.tf +variable "aws-region" {} +variable "customer-name" {} +variable "project" {} +variable "application" {} +variable "environment" {} + +# provider.tf +provider "aws" { + region = var.aws-region + default_tags { + tags = { + Environment = var.environment + Project = var.project + Application = var.application + TerraformMode = "managed" + TerraformDir = path.cwd + BuildDate = formatdate("YYYYMMDD", timestamp()) + } + } +} + +terraform { + required_version = ">= 0.14" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 3.25" + } + } +} + +# main.tf +locals { + aws-region-short = substr(var.aws-region, 0, 2) + resource-prefix = "${var.environment}-${local.aws-region-short}-${var.customer-name}-${var.project}" +} + +module "terraform-state-store" { + source = "git::https://xpk.headdesk.me/git/xpk/terraform.aws-baseline-infra//modules/terraform-setup" + enable-bucket-versioning = true + transition-ia-days = 30 + bucket-acl = "private" + ddb-table-name = "${local.resource-prefix}-tflock" + bucket-name = "${local.resource-prefix}-tfstate" +} \ No newline at end of file diff --git a/modules/terraform-setup/main.tf b/modules/terraform-setup/main.tf new file mode 100644 index 0000000..3f3cac5 --- /dev/null +++ b/modules/terraform-setup/main.tf @@ -0,0 +1,131 @@ +resource "aws_s3_bucket" "s3bucket" { + bucket = var.bucket-name +} + +resource "aws_s3_bucket_public_access_block" "s3-public-access-settings" { + depends_on = [aws_s3_bucket.s3bucket] + bucket = aws_s3_bucket.s3bucket.id + + block_public_acls = true + block_public_policy = true + ignore_public_acls = true + restrict_public_buckets = true +} + +resource "aws_s3_bucket_ownership_controls" "bucket-ownership-setting" { + depends_on = [aws_s3_bucket_public_access_block.s3-public-access-settings] + bucket = aws_s3_bucket.s3bucket.id + + rule { + object_ownership = "BucketOwnerPreferred" + } +} + +resource "aws_s3_bucket_lifecycle_configuration" "bucket-lifecycle-config" { + count = var.bucket-enable-lifecycle ? 1 : 0 + + bucket = aws_s3_bucket.s3bucket.bucket + + rule { + id = "default" + status = "Enabled" + + dynamic "noncurrent_version_expiration" { + for_each = var.enable-bucket-versioning ? [1] : [] + content { + noncurrent_days = 90 + } + } + + dynamic "expiration" { + for_each = var.bucket-retain-days > 0 ? [1] : [] + content { + days = var.bucket-retain-days + } + } + + transition { + days = var.transition-ia-days + storage_class = "STANDARD_IA" + } + } +} + +resource "aws_s3_bucket_versioning" "bucket-versioning" { + count = var.enable-bucket-versioning ? 1 : 0 + bucket = aws_s3_bucket.s3bucket.id + versioning_configuration { + status = "Enabled" + } +} + +resource "aws_s3_bucket_server_side_encryption_configuration" "bucket-encryption" { + bucket = aws_s3_bucket.s3bucket.bucket + rule { + apply_server_side_encryption_by_default { + sse_algorithm = "AES256" + } + } +} + +resource "aws_s3_bucket_acl" "bucket-acl" { + bucket = aws_s3_bucket.s3bucket.bucket + acl = var.bucket-acl +} + +resource "aws_s3_bucket_policy" "bucket-policy" { + bucket = aws_s3_bucket.s3bucket.bucket + policy = <&2 + exit 1 +fi +if ! [ -x "$(command -v jq)" ]; then + echo 'Error: jq is not installed.' >&2 + exit 1 +fi + +# Get the query +TERRAFORM_QUERY=$(jq -Mc .) + +# Extract the query attributes +ASSUME_ROLE_ARN=$(echo "${TERRAFORM_QUERY}" | jq -r '.assume_role_arn') +ROLE_SESSION_NAME=$(echo "${TERRAFORM_QUERY}" | jq -r '.role_session_name') + +aws sts assume-role --output json \ +--role-arn "${ASSUME_ROLE_ARN}" \ +--role-session-name "${ROLE_SESSION_NAME}" \ +--query Credentials \ No newline at end of file diff --git a/modules/util/assume_role/main.tf b/modules/util/assume_role/main.tf new file mode 100644 index 0000000..ed8bed7 --- /dev/null +++ b/modules/util/assume_role/main.tf @@ -0,0 +1,12 @@ +data "external" "awscli" { + program = [format("%s/assumeRole.sh", path.module)] + query = { + assume_role_arn = "arn:aws:iam::${var.account_id}:role/${var.role_name}" + role_session_name = var.role_session_name + } +} + +output temp_credential { + value = data.external.awscli.result + sensitive = true +} diff --git a/modules/util/assume_role/variables.tf b/modules/util/assume_role/variables.tf new file mode 100644 index 0000000..35882ce --- /dev/null +++ b/modules/util/assume_role/variables.tf @@ -0,0 +1,13 @@ +variable "role_session_name" { + description = "The role session name" + type = string + default = "tf_awscli" +} + +variable account_id { + type = string +} + +variable role_name { + type = string +} \ No newline at end of file diff --git a/modules/util/aws-region-short/README.md b/modules/util/aws-region-short/README.md new file mode 100644 index 0000000..6f2e3b3 --- /dev/null +++ b/modules/util/aws-region-short/README.md @@ -0,0 +1,13 @@ +# aws-region-short module +Module which returns a map of aws regions and their short code. + +## Example root module +```terraform +module region-short { + source = "git::https://xpk.headdesk.me/git/xpk/terraform.aws-baseline-infra//modules/util/aws-region-short" +} + +output region-short-code { + value = lookup(module.region-short.region-map, var.aws-region) +} +``` diff --git a/modules/util/aws-region-short/examples/main.tf b/modules/util/aws-region-short/examples/main.tf new file mode 100644 index 0000000..aeb16cc --- /dev/null +++ b/modules/util/aws-region-short/examples/main.tf @@ -0,0 +1,7 @@ +module region-short { + source = "git::https://xpk.headdesk.me/git/xpk/terraform.aws-baseline-infra//modules/util/aws-region-short" +} + +output region-short-code { + value = lookup(module.region-short.region-map, "ap-northeast-2") +} \ No newline at end of file diff --git a/modules/util/aws-region-short/main.tf b/modules/util/aws-region-short/main.tf new file mode 100644 index 0000000..010127a --- /dev/null +++ b/modules/util/aws-region-short/main.tf @@ -0,0 +1,25 @@ +output "region-map" { + value = local.region-map +} + +locals { + region-map = { + ap-northeast-1 = "apne1" + ap-northeast-2 = "apne2" + ap-northeast-3 = "apne3" + ap-south-1 = "aps1" + ap-southeast-1 = "apse1" + ap-southeast-2 = "apse2" + ca-central-1 = "cac1" + eu-central-1 = "euc1" + eu-north-1 = "eun1" + eu-west-1 = "euw1" + eu-west-2 = "euw2" + eu-west-3 = "euw3" + sa-east-1 = "sae1" + us-east-1 = "use1" + us-east-2 = "use2" + us-west-1 = "usw1" + us-west-2 = "usw2" + } +} \ No newline at end of file diff --git a/modules/util/aws-region-short/provider.tf b/modules/util/aws-region-short/provider.tf new file mode 100644 index 0000000..7372cb4 --- /dev/null +++ b/modules/util/aws-region-short/provider.tf @@ -0,0 +1,9 @@ +terraform { + required_version = "~> 1.2.5" + required_providers { + aws = { + source = "hashicorp/aws" + version = "~> 3.75.2" + } + } +} \ No newline at end of file diff --git a/modules/util/awscli/README.md b/modules/util/awscli/README.md new file mode 100644 index 0000000..5c72729 --- /dev/null +++ b/modules/util/awscli/README.md @@ -0,0 +1,56 @@ +# awscli module +This module executes awscli and returns the output. + +# input variables +Set the temp credentials if role switching is needed. Otherwise, leave them alone. + +| variable | type | required | description | +|------------------|---------|----------|-------------------------------------| +| access_key | string | no | for role switching | +| secret_key | string | no | for role switching | +| session_token | string | no | for role switching | +| aws_cli_commands | string | yes | command and parameters after `aws` | + +# output variable +Normally terraform only produces a simple map of string in output. To work +around this, awscli outout are base64 encoded. The output variable is then +base64decoded back to the original text. + +| variable | type | description | +|:--------------|:-------|:-------------------| +| awscli_output | string | output from awscli | + +## Usage example +```hcl +module "awscli_exec" { + source = "../../modules/util/awscli" + + access_key = module.as_role.temp_credential.AccessKeyId + secret_key = module.as_role.temp_credential.SecretAccessKey + session_token = module.as_role.temp_credential.SessionToken + aws_cli_commands = "ec2 describe-instances --query Reservations[].Instances[].InstanceId" +} + +output awscli_output { + value = module.awscli_exec.awscliout +} +``` + +Output +``` +Outputs: + +awscli_output = [ + "i-0cd5e682bc68dbcd2", + "i-050d4adeafaa53cd0", + "i-008328e9dfb56b883", + "i-0634c5ef3528a7b6f", + "i-0dc9009c249f3e3bd", + "i-08034d509751ff058", + "i-0bdd375df2b78a620", + "i-0655d2b3716b1383e", +] +``` + +# References +This module is based on https://registry.terraform.io/modules/digitickets/cli/aws/latest \ No newline at end of file diff --git a/modules/util/awscli/main.tf b/modules/util/awscli/main.tf new file mode 100644 index 0000000..a24320c --- /dev/null +++ b/modules/util/awscli/main.tf @@ -0,0 +1,14 @@ +data "external" "awscli_program" { + program = [format("%s/run_awscli.sh", path.module)] + query = { + access_key = var.access_key + secret_key = var.secret_key + session_token = var.session_token + aws_cli_commands = var.aws_cli_commands + } +} + +# decode encapsulated string back to original +output awscliout { + value = jsondecode(base64decode(data.external.awscli_program.result.awscliout)) +} \ No newline at end of file diff --git a/modules/util/awscli/run_awscli.sh b/modules/util/awscli/run_awscli.sh new file mode 100755 index 0000000..1de5447 --- /dev/null +++ b/modules/util/awscli/run_awscli.sh @@ -0,0 +1,36 @@ +#!/usr/bin/env bash + +# tell bash to exit if any subcommand fails +set -eo pipefail + +# Validate required commands +if ! [ -x "$(command -v aws)" ]; then + echo 'Error: aws is not installed.' >&2 + exit 1 +fi +if ! [ -x "$(command -v jq)" ]; then + echo 'Error: jq is not installed.' >&2 + exit 1 +fi + +# Process inputs +TERRAFORM_QUERY=$(jq -Mc .) +AWS_CLI_COMMANDS=$(echo "${TERRAFORM_QUERY}" | jq -r '.aws_cli_commands') +access_key=$(echo "${TERRAFORM_QUERY}" | jq -r '.access_key') +secret_key=$(echo "${TERRAFORM_QUERY}" | jq -r '.secret_key') +session_token=$(echo "${TERRAFORM_QUERY}" | jq -r '.session_token') + +# Set temp credentials if provided +if [ -n "${access_key}" ]; then + export AWS_ACCESS_KEY_ID=$access_key + export AWS_SECRET_ACCESS_KEY=$secret_key + export AWS_SESSION_TOKEN=$session_token +fi + +# awscli options +export AWS_PAGER="" # disable pager +export AWS_RETRY_MODE=standard # adaptive causes throttling, use standard for now +export AWS_MAX_ATTEMPTS=3 # default is 2 + +# Run the awscli command, encapsulate output in base64 +jq -n --arg jqarg1 "$(aws ${AWS_CLI_COMMANDS})" '{ "awscliout" : $jqarg1 | @base64 }' diff --git a/modules/util/awscli/variables.tf b/modules/util/awscli/variables.tf new file mode 100644 index 0000000..026549f --- /dev/null +++ b/modules/util/awscli/variables.tf @@ -0,0 +1,18 @@ +variable "aws_cli_commands" { + type = string +} + +variable "access_key" { + type = string + sensitive = true +} + +variable "secret_key" { + type = string + sensitive = true +} + +variable "session_token" { + type = string + sensitive = true +} \ No newline at end of file diff --git a/modules/util/random/main.tf b/modules/util/random/main.tf new file mode 100644 index 0000000..6a4d35d --- /dev/null +++ b/modules/util/random/main.tf @@ -0,0 +1,17 @@ +resource "random_string" "string" { + length = 4 + special = false +} + +resource "random_integer" "number" { + min = 1000 + max = 9999 +} + +output "string" { + value = random_string.string.result +} + +output "number" { + value = random_integer.number.result +} diff --git a/modules/util/resource-list/README.md b/modules/util/resource-list/README.md new file mode 100644 index 0000000..14c4130 --- /dev/null +++ b/modules/util/resource-list/README.md @@ -0,0 +1,2 @@ +# resource-list module +Module for listing resources, where native terraform data source is not available. \ No newline at end of file diff --git a/modules/util/resource-list/list-alb-targetgroups.sh b/modules/util/resource-list/list-alb-targetgroups.sh new file mode 100755 index 0000000..60dc5c8 --- /dev/null +++ b/modules/util/resource-list/list-alb-targetgroups.sh @@ -0,0 +1,6 @@ +#!/bin/bash +eval "$(jq -r '@sh "export lb=\(.input) asrolearn=\(.asrolearn)"')" +eval "$(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken')" + +RESULTS=$(aws elbv2 describe-target-groups --load-balancer-arn $lb --query TargetGroups[*].TargetGroupArn --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' \ No newline at end of file diff --git a/modules/util/resource-list/list-alb.sh b/modules/util/resource-list/list-alb.sh new file mode 100755 index 0000000..73dd90b --- /dev/null +++ b/modules/util/resource-list/list-alb.sh @@ -0,0 +1,4 @@ +#!/bin/bash +RESULTS=$(aws elbv2 describe-load-balancers --query 'LoadBalancers[?Type==`application`].LoadBalancerArn' --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' + diff --git a/modules/util/resource-list/list-asg.sh b/modules/util/resource-list/list-asg.sh new file mode 100755 index 0000000..9026862 --- /dev/null +++ b/modules/util/resource-list/list-asg.sh @@ -0,0 +1,6 @@ +#!/bin/bash +# exclude ASG instances +RESULTS=$(aws autoscaling describe-auto-scaling-groups --query 'AutoScalingGroups[*].AutoScalingGroupName' --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' + + diff --git a/modules/util/resource-list/list-ec2.sh b/modules/util/resource-list/list-ec2.sh new file mode 100755 index 0000000..b0e9a9b --- /dev/null +++ b/modules/util/resource-list/list-ec2.sh @@ -0,0 +1,4 @@ +#!/bin/bash +# exclude ASG instances +RESULTS=$(aws ec2 describe-instances --query 'Reservations[].Instances[?!not_null(Tags[?Key == `aws:autoscaling:groupName`].Value)].InstanceId' --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' diff --git a/modules/util/resource-list/list-emr.sh b/modules/util/resource-list/list-emr.sh new file mode 100755 index 0000000..3bec841 --- /dev/null +++ b/modules/util/resource-list/list-emr.sh @@ -0,0 +1,6 @@ +#!/bin/bash +eval "$(jq -r '@sh "asrolearn=\(.asrolearn)"')" +eval "$(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken')" + +RESULTS=$(aws emr list-clusters --active --query Clusters[*].ClusterArn --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' diff --git a/modules/util/resource-list/list-kafka.sh b/modules/util/resource-list/list-kafka.sh new file mode 100755 index 0000000..a6f30b5 --- /dev/null +++ b/modules/util/resource-list/list-kafka.sh @@ -0,0 +1,8 @@ +#!/bin/bash +eval "$(jq -r '@sh "asrolearn=\(.asrolearn)"')" +eval "$(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken')" + +RESULTS=$(aws kafka list-clusters --query ClusterInfoList[*].ClusterName --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' + + diff --git a/modules/util/resource-list/list-ngw.sh b/modules/util/resource-list/list-ngw.sh new file mode 100755 index 0000000..1779ae7 --- /dev/null +++ b/modules/util/resource-list/list-ngw.sh @@ -0,0 +1,3 @@ +#!/bin/bash +RESULTS=$(aws ec2 describe-nat-gateways --query 'NatGateways[].NatGatewayId' --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' \ No newline at end of file diff --git a/modules/util/resource-list/list-nlb-targetgroups.sh b/modules/util/resource-list/list-nlb-targetgroups.sh new file mode 100755 index 0000000..6b6070b --- /dev/null +++ b/modules/util/resource-list/list-nlb-targetgroups.sh @@ -0,0 +1,7 @@ +#!/bin/bash +eval "$(jq -r '@sh "export lb=\(.input) asrolearn=\(.asrolearn)"')" +eval "$(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken')" + +RESULTS=$(aws elbv2 describe-target-groups --load-balancer-arn $lb --query TargetGroups[*].TargetGroupArn --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' + diff --git a/modules/util/resource-list/list-nlb.sh b/modules/util/resource-list/list-nlb.sh new file mode 100755 index 0000000..7ecc5e3 --- /dev/null +++ b/modules/util/resource-list/list-nlb.sh @@ -0,0 +1,3 @@ +#!/bin/bash +RESULTS=$(aws elbv2 describe-load-balancers --query 'LoadBalancers[?Type==`network`].LoadBalancerArn' --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' \ No newline at end of file diff --git a/modules/util/resource-list/list-opensearch.sh b/modules/util/resource-list/list-opensearch.sh new file mode 100755 index 0000000..8f4472b --- /dev/null +++ b/modules/util/resource-list/list-opensearch.sh @@ -0,0 +1,8 @@ +#!/bin/bash +eval "$(jq -r '@sh "asrolearn=\(.asrolearn)"')" +eval "$(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken')" + +RESULTS=$(aws opensearch list-domain-names --query DomainNames[*].DomainName --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' + + diff --git a/modules/util/resource-list/list-rds.sh b/modules/util/resource-list/list-rds.sh new file mode 100755 index 0000000..7b031ca --- /dev/null +++ b/modules/util/resource-list/list-rds.sh @@ -0,0 +1,3 @@ +#!/bin/bash +RESULTS=$(aws rds describe-db-instances --query 'DBInstances[*].DBInstanceIdentifier' --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' diff --git a/modules/util/resource-list/list-redis.sh b/modules/util/resource-list/list-redis.sh new file mode 100644 index 0000000..82390c4 --- /dev/null +++ b/modules/util/resource-list/list-redis.sh @@ -0,0 +1,6 @@ +#!/bin/bash +eval "$(jq -r '@sh "asrolearn=\(.asrolearn)"')" +eval "$(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken')" + +RESULTS=$( aws elasticache describe-cache-clusters --query 'CacheClusters[*].CacheClusterId' --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' diff --git a/modules/util/resource-list/list-tgw.sh b/modules/util/resource-list/list-tgw.sh new file mode 100755 index 0000000..d37abaf --- /dev/null +++ b/modules/util/resource-list/list-tgw.sh @@ -0,0 +1,7 @@ +#!/bin/bash + +eval "$(jq -r '@sh "asrolearn=\(.asrolearn)"')" +eval "$(aws sts assume-role --role-arn $asrolearn --role-session-name awscli | jq -cr '"export AWS_ACCESS_KEY_ID=" + .Credentials.AccessKeyId, "export AWS_SECRET_ACCESS_KEY=" + .Credentials.SecretAccessKey, "export AWS_SESSION_TOKEN=" + .Credentials.SessionToken')" + +RESULTS=$(aws ec2 describe-transit-gateways --query 'TransitGateways[].TransitGatewayId' --output text --no-cli-pager | sed 's/\t/\n/g' | sort | xargs) +jq -n --arg result "$RESULTS" '{"result":$result}' \ No newline at end of file diff --git a/modules/util/resource-list/main.tf b/modules/util/resource-list/main.tf new file mode 100644 index 0000000..0605f20 --- /dev/null +++ b/modules/util/resource-list/main.tf @@ -0,0 +1,13 @@ +data "external" "instances" { + program = ["bash", "${path.module}/list-${var.resource-type}.sh"] + query = { + input = var.query-input + asrolearn = var.asrolearn + } +} + +output result-set { + # value = toset(split(" ", data.external.instances.result.result)) + # prevents terraform from returning [""] + value = length(data.external.instances.result.result) > 0 ? toset(split(" ", data.external.instances.result.result)) : [] +} \ No newline at end of file diff --git a/modules/util/resource-list/variables.tf b/modules/util/resource-list/variables.tf new file mode 100644 index 0000000..5003682 --- /dev/null +++ b/modules/util/resource-list/variables.tf @@ -0,0 +1,17 @@ +variable resource-type { + type = string +} + +variable query-input { + type = string + default = null +} + +variable asrolearn { + type = string + + validation { + condition = length(var.asrolearn) > 1 + error_message = "asrolearn is too short" + } +} \ No newline at end of file diff --git a/modules/util/terraform-aws-cli/.gitignore b/modules/util/terraform-aws-cli/.gitignore new file mode 100644 index 0000000..680685a --- /dev/null +++ b/modules/util/terraform-aws-cli/.gitignore @@ -0,0 +1,5 @@ +/test-reports/ +.idea/ +/PersonalSettingsMakefile +.terraform/ +/temp/ diff --git a/modules/util/terraform-aws-cli/.pre-commit-config.yaml b/modules/util/terraform-aws-cli/.pre-commit-config.yaml new file mode 100644 index 0000000..c41a49e --- /dev/null +++ b/modules/util/terraform-aws-cli/.pre-commit-config.yaml @@ -0,0 +1,43 @@ +repos: + - repo: https://github.com/antonbabenko/pre-commit-terraform + rev: v1.77.2 + hooks: + - id: terraform_tflint + - id: terraform_fmt + - id: terraform_validate + exclude: modules + - id: terraform_docs + - repo: https://github.com/pre-commit/pre-commit-hooks + rev: v4.4.0 + hooks: + - id: check-added-large-files + - id: check-executables-have-shebangs + - id: check-json + - id: check-merge-conflict + - id: check-symlinks + - id: check-yaml + - id: detect-aws-credentials + args: + - --allow-missing-credentials + - id: detect-private-key + - id: end-of-file-fixer + - id: fix-byte-order-marker + - id: pretty-format-json + files: .*\.json$ + args: + - --autofix + - --indent=2 + - --no-sort-keys + - id: trailing-whitespace + + - repo: https://github.com/jumanjihouse/pre-commit-hook-yamlfmt + rev: 0.2.2 + hooks: + - id: yamlfmt + args: + - --implicit_start + - --preserve-quotes + - --mapping=2 + - --offset=2 + - --sequence=4 + - --width=300 diff --git a/modules/util/terraform-aws-cli/.terraform-version b/modules/util/terraform-aws-cli/.terraform-version new file mode 100644 index 0000000..e516bb9 --- /dev/null +++ b/modules/util/terraform-aws-cli/.terraform-version @@ -0,0 +1 @@ +1.4.5 diff --git a/modules/util/terraform-aws-cli/.tflint.hcl b/modules/util/terraform-aws-cli/.tflint.hcl new file mode 100644 index 0000000..49299ef --- /dev/null +++ b/modules/util/terraform-aws-cli/.tflint.hcl @@ -0,0 +1,32 @@ +config { + module = true + force = false +} + +// Only the AWS plugin is enabled. The Google and Azure plugins are not enabled as we have no current use for them. +plugin "aws" { + enabled = true + source = "github.com/terraform-linters/tflint-ruleset-aws" + version = "0.22.1" + deep_check = true +} + +rule "terraform_naming_convention" { + enabled = true +} + +rule "terraform_deprecated_interpolation" { + enabled = true +} + +rule "terraform_documented_outputs" { + enabled = true +} + +rule "terraform_documented_variables" { + enabled = true +} + +rule "terraform_module_pinned_source" { + enabled = true +} diff --git a/modules/util/terraform-aws-cli/.travis.yml b/modules/util/terraform-aws-cli/.travis.yml new file mode 100644 index 0000000..505891c --- /dev/null +++ b/modules/util/terraform-aws-cli/.travis.yml @@ -0,0 +1,12 @@ +install: + - sudo apt-get -y install jq + - curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" + - unzip awscliv2.zip + - sudo ./aws/install + - git clone https://github.com/tfutils/tfenv.git ~/.tfenv + - sudo ln -s ~/.tfenv/bin/* /usr/local/bin + - tfenv install + +script: + - terraform init + - tests/tests.sh diff --git a/modules/util/terraform-aws-cli/CHANGELOG.md b/modules/util/terraform-aws-cli/CHANGELOG.md new file mode 100644 index 0000000..0a2b75e --- /dev/null +++ b/modules/util/terraform-aws-cli/CHANGELOG.md @@ -0,0 +1,86 @@ +# Changelog + +# v5.0.4 - 2022/11/28 + +- Allow `var.role_session_name` to be optional. Thank you [Byron Kim](https://github.com/digitickets/terraform-aws-cli/issues/4) + +# v5.0.3 - 2022/05/31 + +- Fix for when the AWS call being made has no output (which is invalid JSON). Thank you [Yaron Yarimi and Pavel Kargin](https://github.com/digitickets/terraform-aws-cli/issues/3) + +# v5.0.2 - 2022/05/26 + +- Fix for when this module is used in an iteration. + +# v5.0.1 - 2022/05/24 + +- Explicitly specify output type as json for assume role call. Thank you [Niranjan Rajendran](https://github.com/digitickets/terraform-aws-cli/pull/2) + +# v5.0.0 - 2022/01/27 + +- Fixed incompatibilities with Terraform 1.1.0. + +# v4.1.0 - 2021/10/05 + +- Validate role_session_name so that the maximum length is 64 characters and that it must match a specific regex. + +# v4.0.0 - 2021/05/18 + +- Set minimum terraform version to 0.15.0. + +# No release required - 2021/03/30 + +- Updated tests to use an AWS request that does not require credentials, allowing the full terraform plan and apply + process to be run and tested with the module. + +# v3.1.1 - 2021/03/25 + +- Re-releasing as accidentally released v3.0.0 as v3.1.0. + +# v3.1.0 - 2021/03/25 + +- Add an optional `debug_log_filename` variable. If supplied, a log file will be produced in the supplied location. This + option enables the `--debug` option of the AWS CLI. Use this in safe environments as potentially sensitive content may + be logged. +- Added [adaptive retry mode](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-retries.html#cli-usage-retries-modes-adaptive) + to help alleviate throttling issues. + +# v3.0.0 - 2020/12/03 + +- Set minimum terraform version to 0.14.0. +- Introduced `.terraform.lock.hcl` for versioning of dependencies. + +# v2.0.1 - 2020/09/17 + +- Add `depends_on` to enforce the order in which the resources get instantiated / evaluated. + +# v2.0.0 - 2020/09/17 + +- Set minimum terraform version to 0.13.0 +- Added variable validation to optional `assume_role_arn` to match syntax described in + [IAM Identifiers](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html). + +# v1.3.0 - 2020/08/03 + +- Set minimum version of random provider to 2.3.0 + +# v1.2.2 - 2020/05/11 + +- Updated examples in [README.md](README.md). + +# v1.2.1 - 2020/05/11 + +- Updated [README.md](README.md) to reflect `digiticketsgroup/terraforming` image that includes all the required + resources for using this module. + +# v1.2.0 - 2020/05/11 + +- Drop down to using `sh` rather than `bash` so this module can operate with Hashicorp Terraform Docker image. + +# v1.1.0 - 2020/05/07 + +- Updated examples in README.md with registry path as displayed by registry. +- Updated `assume_role_arn` to reflect that it is optional. + +# v1.0.0 - 2020/05/07 +Initial release diff --git a/modules/util/terraform-aws-cli/README.md b/modules/util/terraform-aws-cli/README.md new file mode 100644 index 0000000..40b72a0 --- /dev/null +++ b/modules/util/terraform-aws-cli/README.md @@ -0,0 +1,131 @@ +[![Build Status](https://img.shields.io/travis/digitickets/terraform-aws-cli.svg?style=for-the-badge&logo=travis)](https://travis-ci.com/digitickets/terraform-aws-cli) +[![GitHub issues](https://img.shields.io/github/issues/digitickets/terraform-aws-cli.svg?style=for-the-badge&logo=github)](https://github.com/digitickets/terraform-aws-cli/issues) + +# terraform-aws-cli + +Run the AWS CLI, with the ability to run under an assumed role, to access resources and properties missing from the +Terraform AWS Provider. + +# Requirements + +This module requires a couple of additional resources to operate successfully. + +1. Amazon Web Service Command Line Interface (awscli) + : This is available in several forms [here](https://aws.amazon.com/cli/). + +2. JSON processor (jq) + : This is available [here](https://stedolan.github.io/jq/). + +# Examples + +## 1. Get the desired capacity of an autoscaling group. + +If you are using a blue/green style deployment, you would want to create the same number of EC2 instances as you are +replacing. + +```hcl-terraform +module "current_desired_capacity" { + source = "digitickets/cli/aws" + role_session_name = "GettingDesiredCapacityFor${var.environment}" + aws_cli_commands = ["autoscaling", "describe-auto-scaling-groups"] + aws_cli_query = "AutoScalingGroups[?Tags[?Key==`Name`]|[?Value==`digitickets-${var.environment}-asg-app`]]|[0].DesiredCapacity" +} +``` + +You can now set the desired capacity of an aws_autoscaling_group: + +```hcl-terraform + desired_capacity = module.current_desired_capacity.result +``` + +## 2. Assuming a role. + +Extending the first example above, assuming a role is as simple as adding an `assume_role_arn` to the module: + +```hcl-terraform +module "current_desired_capacity" { + source = "digitickets/cli/aws" + assume_role_arn = "arn:aws:iam::${data.aws_caller_identity.current.account_id}:role/OrganizationAccountAccessRole" + role_session_name = "GettingDesiredCapacityFor${var.environment}" + aws_cli_commands = ["autoscaling", "describe-auto-scaling-groups"] + aws_cli_query = "AutoScalingGroups[?Tags[?Key==`Name`]|[?Value==`digitickets-${var.environment}-asg-app`]]|[0].DesiredCapacity" +} +``` + + +## Requirements + +| Name | Version | +|------|---------| +|
[terraform](#requirement\_terraform) | >= 0.15 | +| [external](#requirement\_external) | ~> 2.0 | +| [local](#requirement\_local) | ~> 2.0 | + +## Providers + +| Name | Version | +|------|---------| +| [external](#provider\_external) | 2.3.1 | +| [local](#provider\_local) | 2.4.0 | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [external_external.awscli_program](https://registry.terraform.io/providers/hashicorp/external/latest/docs/data-sources/external) | data source | +| [local_file.awscli_results_file](https://registry.terraform.io/providers/hashicorp/local/latest/docs/data-sources/file) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| [assume\_role\_arn](#input\_assume\_role\_arn) | The ARN of the role being assumed (optional) | `string` | `""` | no | +| [aws\_cli\_commands](#input\_aws\_cli\_commands) | The AWS CLI command and subcommands | `list(string)` | n/a | yes | +| [aws\_cli\_query](#input\_aws\_cli\_query) | The --query value | `string` | `""` | no | +| [debug\_log\_filename](#input\_debug\_log\_filename) | Generate a debug log if a `debug_log_filename` is supplied | `string` | `""` | no | +| [role\_session\_name](#input\_role\_session\_name) | The role session name | `string` | `""` | no | + +## Outputs + +| Name | Description | +|------|-------------| +| [result](#output\_result) | The output of the AWS CLI command | + + +# Docker + +To help with getting this running in a pipeline that uses Docker, the image [digiticketsgroup/terraforming](https://hub.docker.com/repository/docker/digiticketsgroup/terraforming) has Terraform, AWSCLI, and jq all ready to go. + +If you want to build or adapt your own image, then the Dockerfile below is how that image has been built. + +```Dockerfile +# Based upon https://github.com/aws/aws-cli/blob/2.0.10/docker/Dockerfile +FROM amazonlinux:2 as installer +ARG TERRAFORM_VERSION +RUN yum update -y \ + && yum install -y unzip \ + && curl https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip -o awscli-exe-linux-x86_64.zip \ + && unzip awscli-exe-linux-x86_64.zip \ + # The --bin-dir is specified so that we can copy the + # entire bin directory from the installer stage into + # into /usr/local/bin of the final stage without + # accidentally copying over any other executables that + # may be present in /usr/local/bin of the installer stage. + && ./aws/install --bin-dir /aws-cli-bin/ \ + && curl "https://releases.hashicorp.com/terraform/${TERRAFORM_VERSION}/terraform_${TERRAFORM_VERSION}_linux_amd64.zip" -o terraform.zip \ + && unzip terraform.zip + +FROM amazonlinux:2 +COPY --from=installer /usr/local/aws-cli/ /usr/local/aws-cli/ +COPY --from=installer /aws-cli-bin/ /usr/local/bin/ +COPY --from=installer terraform /usr/bin/ +RUN yum update -y \ + && yum install -y less groff jq \ + && yum clean all + +ENTRYPOINT ["/bin/sh"] +``` diff --git a/modules/util/terraform-aws-cli/main.tf b/modules/util/terraform-aws-cli/main.tf new file mode 100644 index 0000000..8f58642 --- /dev/null +++ b/modules/util/terraform-aws-cli/main.tf @@ -0,0 +1,42 @@ +locals { + joined_aws_cli_command = join(" ", var.aws_cli_commands) + output_file = format( + "%s/temp/results-%s.json", + path.module, + md5( + join( + "-", + [ + var.assume_role_arn, + var.role_session_name, + local.joined_aws_cli_command, + var.aws_cli_query, + var.debug_log_filename + ] + ) + ) + ) +} + +data "external" "awscli_program" { + program = [format("%s/scripts/awsWithAssumeRole.sh", path.module)] + query = { + assume_role_arn = var.assume_role_arn + role_session_name = var.role_session_name + aws_cli_commands = local.joined_aws_cli_command + aws_cli_query = var.aws_cli_query + output_file = local.output_file + debug_log_filename = var.debug_log_filename + } +} + +data "local_file" "awscli_results_file" { + depends_on = [data.external.awscli_program] + filename = data.external.awscli_program.query.output_file +} + +output "result" { + depends_on = [data.local_file.awscli_results_file] + description = "The output of the AWS CLI command" + value = try(jsondecode(data.local_file.awscli_results_file.content), null) +} diff --git a/modules/util/terraform-aws-cli/scripts/awsWithAssumeRole.sh b/modules/util/terraform-aws-cli/scripts/awsWithAssumeRole.sh new file mode 100755 index 0000000..5fedb06 --- /dev/null +++ b/modules/util/terraform-aws-cli/scripts/awsWithAssumeRole.sh @@ -0,0 +1,65 @@ +#!/usr/bin/env sh + +# Validate required commands +if ! [ -x "$(command -v aws)" ]; then + echo 'Error: aws is not installed.' >&2 + exit 1 +fi +if ! [ -x "$(command -v jq)" ]; then + echo 'Error: jq is not installed.' >&2 + exit 1 +fi + +# Get the query +TERRAFORM_QUERY=$(jq -Mc .) + +# Extract the query attributes +AWS_CLI_COMMANDS=$(echo "${TERRAFORM_QUERY}" | jq -r '.aws_cli_commands') +AWS_CLI_QUERY=$(echo "${TERRAFORM_QUERY}" | jq -r '.aws_cli_query') +OUTPUT_FILE=$(echo "${TERRAFORM_QUERY}" | jq -r '.output_file') +ASSUME_ROLE_ARN=$(echo "${TERRAFORM_QUERY}" | jq -r '.assume_role_arn') +ROLE_SESSION_NAME=$(echo "${TERRAFORM_QUERY}" | jq -r '.role_session_name') +DEBUG_LOG_FILENAME=$(echo "${TERRAFORM_QUERY}" | jq -r '.debug_log_filename') + +# Do we need to assume a role? +if [ -n "${ASSUME_ROLE_ARN}" ]; then + TEMP_ROLE=$(aws sts assume-role --output json --role-arn "${ASSUME_ROLE_ARN}" --role-session-name "${ROLE_SESSION_NAME:-AssumingRole}") + export AWS_ACCESS_KEY_ID=$(echo "${TEMP_ROLE}" | jq -r '.Credentials.AccessKeyId') + export AWS_SECRET_ACCESS_KEY=$(echo "${TEMP_ROLE}" | jq -r '.Credentials.SecretAccessKey') + export AWS_SESSION_TOKEN=$(echo "${TEMP_ROLE}" | jq -r '.Credentials.SessionToken') +fi + +# Do we have a query? +if [ -n "${AWS_CLI_QUERY}" ]; then + AWS_CLI_QUERY_PARAM="--query '${AWS_CLI_QUERY}'" +fi + +# Do we want to be debug? +export AWS_DEBUG_OPTION="" +if [ -n "${DEBUG_LOG_FILENAME}" ]; then + AWS_DEBUG_OPTION="--debug 2>${DEBUG_LOG_FILENAME}" + mkdir -p "$(dirname ${DEBUG_LOG_FILENAME})" +fi + +# Make sure output file directory exists +mkdir -p "$(dirname ${OUTPUT_FILE})" + +# Make sure output file does not exist +rm -f "${OUTPUT_FILE}" + +# Disable any assigned pager +export AWS_PAGER="" + +# Configure adaptive retry mode +# export AWS_RETRY_MODE=adaptive +export AWS_RETRY_MODE=standard +export AWS_MAX_ATTEMPTS=3 + +# Run the AWS_CLI command, exiting with a non zero exit code if required. +if ! eval "aws ${AWS_CLI_COMMANDS} ${AWS_CLI_QUERY_PARAM:-} --output json ${AWS_DEBUG_OPTION}" >"${OUTPUT_FILE}" ; then + echo "Error: aws failed." + exit 1 +fi + +# All is good. +echo '{"output_file":"'"${OUTPUT_FILE}"'"}' diff --git a/modules/util/terraform-aws-cli/tests/bad_arn/terraform.tfvars b/modules/util/terraform-aws-cli/tests/bad_arn/terraform.tfvars new file mode 100644 index 0000000..0c1d712 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/bad_arn/terraform.tfvars @@ -0,0 +1,3 @@ +assume_role_arn = "bad_arn" +aws_cli_commands = ["version"] +role_session_name = "bad_arn" diff --git a/modules/util/terraform-aws-cli/tests/bad_arn/test.sh b/modules/util/terraform-aws-cli/tests/bad_arn/test.sh new file mode 100755 index 0000000..a71977f --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/bad_arn/test.sh @@ -0,0 +1,20 @@ +#!/usr/bin/env bash + +function run_test() { +if [[ -f $PLAN_FILE ]]; then + echo "Incorrectly generated a plan - $PLAN_FILE"; + exit 1; +fi + +if [[ ! -z "$(cat $PLAN_LOG_FILE)" ]]; then + echo "Incorrectly generated content in the plan log file - $PLAN_LOG_FILE"; + exit 2; +fi + +if [[ ! "$(cat $PLAN_ERROR_FILE)" == *'The optional ARN must match the format documented in'* ]]; then + echo 'Failed to detect invalid ARN.'; + exit 3; +fi +} + +. tests/common.sh $0 diff --git a/modules/util/terraform-aws-cli/tests/common.sh b/modules/util/terraform-aws-cli/tests/common.sh new file mode 100644 index 0000000..c8f46b1 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/common.sh @@ -0,0 +1,30 @@ +#!/usr/bin/env bash + +TEST_PATH=$(dirname $1) +TEST_NAME=$(basename $TEST_PATH) + +echo "Start : $TEST_PATH" + +TERRAFORM_TFVARS=$TEST_PATH/terraform.tfvars +EXPECTED_VARIABLES=$TEST_PATH/expected_variables.json + +RESOURCE_PATH=test-reports/$TEST_NAME +mkdir -p $RESOURCE_PATH + +INIT_LOG_FILE=$RESOURCE_PATH/init.log +INIT_ERROR_FILE=$RESOURCE_PATH/init.error.log +PLAN_FILE=$RESOURCE_PATH/terraform.plan +PLAN_LOG_FILE=$RESOURCE_PATH/plan.log +PLAN_ERROR_FILE=$RESOURCE_PATH/plan.error.log +STATE_FILE=$RESOURCE_PATH/terraform.tfstate +APPLY_LOG_FILE=$RESOURCE_PATH/apply.log +APPLY_ERROR_FILE=$RESOURCE_PATH/apply.error.log +DEBUG_LOG_FILE=$RESOURCE_PATH/debug.log + +terraform init > $INIT_LOG_FILE 2> $INIT_ERROR_FILE + +terraform plan -var-file=$TERRAFORM_TFVARS -out=$PLAN_FILE > $PLAN_LOG_FILE 2> $PLAN_ERROR_FILE + +run_test + +echo "Passed : $TEST_PATH" diff --git a/modules/util/terraform-aws-cli/tests/empty_result/expected_variables.json b/modules/util/terraform-aws-cli/tests/empty_result/expected_variables.json new file mode 100644 index 0000000..e9556b9 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/empty_result/expected_variables.json @@ -0,0 +1,24 @@ +{ + "assume_role_arn": { + "value": "" + }, + "aws_cli_commands": { + "value": [ + "guardduty", + "update-detector", + "--finding-publishing-frequency", + "ONE_HOUR", + "--detector-id", + "0123456789abcdef0123456789abcdef" + ] + }, + "aws_cli_query": { + "value": "" + }, + "debug_log_filename": { + "value": "" + }, + "role_session_name": { + "value": "empty_result" + } +} diff --git a/modules/util/terraform-aws-cli/tests/empty_result/notes.txt b/modules/util/terraform-aws-cli/tests/empty_result/notes.txt new file mode 100644 index 0000000..0a481f4 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/empty_result/notes.txt @@ -0,0 +1,26 @@ +This test requires Guard Duty. As this is a paid service, the test is disabled. + +The test can be enabled by running the following commands with a suitable profile or set of AWS credentials in play. + +1. Create the Guard Duty detector + + aws guardduty create-detector --enable + + +2. Get the detector ID + + aws guardduty list-detectors --query='DetectorIds[0]' + + +3. Copy the detector ID reported into terraform.tfvars and update the expected_variables.json file to match, replacing + 0123456789abcdef0123456789abcdef (unless that's your detector ID of course! ... It COULD happen!) + + +4. Change the RUN_TEST to true in ./test.sh + + +Once you've finished the testing, revert the changes above, and disable the detector using + + aws guardduty delete-detector --detector-id + +replacing with the detector ID you extracted in step 2 above. diff --git a/modules/util/terraform-aws-cli/tests/empty_result/terraform.tfvars b/modules/util/terraform-aws-cli/tests/empty_result/terraform.tfvars new file mode 100644 index 0000000..5e8c5e5 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/empty_result/terraform.tfvars @@ -0,0 +1,3 @@ +// An empty result from AWS +aws_cli_commands = ["guardduty", "update-detector", "--finding-publishing-frequency", "ONE_HOUR", "--detector-id", "0123456789abcdef0123456789abcdef"] +role_session_name = "empty_result" diff --git a/modules/util/terraform-aws-cli/tests/empty_result/test.sh b/modules/util/terraform-aws-cli/tests/empty_result/test.sh new file mode 100755 index 0000000..3098091 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/empty_result/test.sh @@ -0,0 +1,41 @@ +#!/usr/bin/env bash + +function run_test() { +if [[ ! -f $PLAN_FILE ]]; then + echo "Failed to generate a plan - $PLAN_FILE"; + exit 1; +fi + +if [[ ! "$(terraform show -json $PLAN_FILE | jq -MSr .variables)" == "$(cat $EXPECTED_VARIABLES)" ]]; then + echo 'Failed to incorporate expected variable values into plan.'; + exit 2; +fi + +terraform apply -auto-approve -backup=- -state-out $STATE_FILE -var-file $TERRAFORM_TFVARS > $APPLY_LOG_FILE 2> $APPLY_ERROR_FILE + +if [[ ! -f $STATE_FILE ]]; then + echo "Failed to generate state file - $STATE_FILE"; + exit 3; +fi + +# Validate the presence of the plan error file. +if [[ ! -f $PLAN_ERROR_FILE ]]; then + echo "Failed to generate plan error file - $PLAN_ERROR_FILE"; + exit 4; +fi + +# Validate the plan error file is empty. +if [[ -s $PLAN_ERROR_FILE ]]; then + echo "Plan error file is not empty - $PLAN_ERROR_FILE"; + exit 5; +fi +} + +# Set to true to allow this test to run +RUN_TEST=false +if [[ "$RUN_TEST" == "false" ]]; then + echo "Start : $(dirname $0)"; + echo "Skipped : $(dirname $0) : See $(dirname $0)/notes.txt"; +else + . tests/common.sh $0 +fi diff --git a/modules/util/terraform-aws-cli/tests/role_session_name_invalid_characters/terraform.tfvars b/modules/util/terraform-aws-cli/tests/role_session_name_invalid_characters/terraform.tfvars new file mode 100644 index 0000000..4db5bf2 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/role_session_name_invalid_characters/terraform.tfvars @@ -0,0 +1,4 @@ +// 64 characters, but $ is invalid +role_session_name = "$234567890123456789012345678901234567890123456789012345678901234" +aws_cli_commands = ["version"] +debug_log_filename = "test-reports/role_session_name_invalid_characters/debug.log" diff --git a/modules/util/terraform-aws-cli/tests/role_session_name_invalid_characters/test.sh b/modules/util/terraform-aws-cli/tests/role_session_name_invalid_characters/test.sh new file mode 100755 index 0000000..e7a93c5 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/role_session_name_invalid_characters/test.sh @@ -0,0 +1,20 @@ +#!/usr/bin/env bash + +function run_test() { +if [[ -f $PLAN_FILE ]]; then + echo "Incorrectly generated a plan - $PLAN_FILE"; + exit 1; +fi + +if [[ ! -z "$(cat $PLAN_LOG_FILE)" ]]; then + echo "Incorrectly generated content in the plan log file - $PLAN_LOG_FILE"; + exit 2; +fi + +if [[ ! "$(cat $PLAN_ERROR_FILE)" == *'The role session name match the regular expression'* ]]; then + echo 'Failed to detect invalid characters in role_session_name.'; + exit 3; +fi +} + +. tests/common.sh $0 diff --git a/modules/util/terraform-aws-cli/tests/role_session_name_optional/expected_variables.json b/modules/util/terraform-aws-cli/tests/role_session_name_optional/expected_variables.json new file mode 100644 index 0000000..aff5d95 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/role_session_name_optional/expected_variables.json @@ -0,0 +1,23 @@ +{ + "assume_role_arn": { + "value": "" + }, + "aws_cli_commands": { + "value": [ + "s3api", + "list-objects", + "--bucket", + "ryft-public-sample-data", + "--no-sign-request" + ] + }, + "aws_cli_query": { + "value": "max_by(Contents, &Size)" + }, + "debug_log_filename": { + "value": "" + }, + "role_session_name": { + "value": "" + } +} diff --git a/modules/util/terraform-aws-cli/tests/role_session_name_optional/terraform.tfvars b/modules/util/terraform-aws-cli/tests/role_session_name_optional/terraform.tfvars new file mode 100644 index 0000000..c50a0a0 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/role_session_name_optional/terraform.tfvars @@ -0,0 +1,3 @@ +// ryft-public-sample-data is a publicly accessible S3 bucket. +aws_cli_commands = ["s3api", "list-objects", "--bucket", "ryft-public-sample-data", "--no-sign-request"] +aws_cli_query = "max_by(Contents, &Size)" diff --git a/modules/util/terraform-aws-cli/tests/role_session_name_optional/test.sh b/modules/util/terraform-aws-cli/tests/role_session_name_optional/test.sh new file mode 100755 index 0000000..641a619 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/role_session_name_optional/test.sh @@ -0,0 +1,40 @@ +#!/usr/bin/env bash + +function run_test() { +if [[ ! -f $PLAN_FILE ]]; then + echo "Failed to generate a plan - $PLAN_FILE"; + exit 1; +fi + +if [[ ! "$(terraform show -json $PLAN_FILE | jq -MSr .variables)" == "$(cat $EXPECTED_VARIABLES)" ]]; then + echo 'Failed to incorporate expected variable values into plan.'; + exit 2; +fi + +terraform apply -auto-approve -backup=- -state-out $STATE_FILE -var-file $TERRAFORM_TFVARS > $APPLY_LOG_FILE 2> $APPLY_ERROR_FILE + +if [[ ! -f $STATE_FILE ]]; then + echo "Failed to generate state file - $STATE_FILE"; + exit 3; +fi + +# Extract some content the state file. +if [[ ! "$(cat $STATE_FILE)" == *'0ae8f910a30bc83fd81c4e3c1a6bbd9bab0afe4e0762b56a2807d22fcd77d517'* ]]; then + echo 'Failed to retrieve expected content from AWS.'; + exit 4; +fi + +# Extract some content from the apply log. +if [[ ! "$(cat $APPLY_LOG_FILE)" == *"0ae8f910a30bc83fd81c4e3c1a6bbd9bab0afe4e0762b56a2807d22fcd77d517"* ]]; then + echo 'Failed to present expected content to Terraform.'; + exit 5; +fi + +# Validate the absence of the debug log. +if [[ -f $DEBUG_LOG_FILE ]]; then + echo "Incorrectly generated debug.log file - $DEBUG_LOG_FILE"; + exit 6; +fi +} + +. tests/common.sh $0 diff --git a/modules/util/terraform-aws-cli/tests/role_session_name_too_long/terraform.tfvars b/modules/util/terraform-aws-cli/tests/role_session_name_too_long/terraform.tfvars new file mode 100644 index 0000000..3e0e2b3 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/role_session_name_too_long/terraform.tfvars @@ -0,0 +1,4 @@ +// 65 characters is too long +role_session_name = "12345678901234567890123456789012345678901234567890123456789012345" +aws_cli_commands = ["version"] +debug_log_filename = "test-reports/role_session_name_too_long/debug.log" diff --git a/modules/util/terraform-aws-cli/tests/role_session_name_too_long/test.sh b/modules/util/terraform-aws-cli/tests/role_session_name_too_long/test.sh new file mode 100755 index 0000000..f755c29 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/role_session_name_too_long/test.sh @@ -0,0 +1,20 @@ +#!/usr/bin/env bash + +function run_test() { +if [[ -f $PLAN_FILE ]]; then + echo "Incorrectly generated a plan - $PLAN_FILE"; + exit 1; +fi + +if [[ ! -z "$(cat $PLAN_LOG_FILE)" ]]; then + echo "Incorrectly generated content in the plan log file - $PLAN_LOG_FILE"; + exit 2; +fi + +if [[ ! "$(cat $PLAN_ERROR_FILE)" == *'The role session name must be less than or equal to 64 characters'* ]]; then + echo 'Failed to detect too long role_session_name.'; + exit 3; +fi +} + +. tests/common.sh $0 diff --git a/modules/util/terraform-aws-cli/tests/test_with_debug/expected_variables.json b/modules/util/terraform-aws-cli/tests/test_with_debug/expected_variables.json new file mode 100644 index 0000000..62a36aa --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/test_with_debug/expected_variables.json @@ -0,0 +1,23 @@ +{ + "assume_role_arn": { + "value": "" + }, + "aws_cli_commands": { + "value": [ + "s3api", + "list-objects", + "--bucket", + "ryft-public-sample-data", + "--no-sign-request" + ] + }, + "aws_cli_query": { + "value": "max_by(Contents, &Size)" + }, + "debug_log_filename": { + "value": "test-reports/test_with_debug/debug.log" + }, + "role_session_name": { + "value": "test_with_debug" + } +} diff --git a/modules/util/terraform-aws-cli/tests/test_with_debug/terraform.tfvars b/modules/util/terraform-aws-cli/tests/test_with_debug/terraform.tfvars new file mode 100644 index 0000000..6292ed1 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/test_with_debug/terraform.tfvars @@ -0,0 +1,5 @@ +// ryft-public-sample-data is a publicly accessible S3 bucket. +aws_cli_commands = ["s3api", "list-objects", "--bucket", "ryft-public-sample-data", "--no-sign-request"] +aws_cli_query = "max_by(Contents, &Size)" +debug_log_filename = "test-reports/test_with_debug/debug.log" +role_session_name = "test_with_debug" diff --git a/modules/util/terraform-aws-cli/tests/test_with_debug/test.sh b/modules/util/terraform-aws-cli/tests/test_with_debug/test.sh new file mode 100755 index 0000000..74b36e9 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/test_with_debug/test.sh @@ -0,0 +1,40 @@ +#!/usr/bin/env bash + +function run_test() { +if [[ ! -f $PLAN_FILE ]]; then + echo "Failed to generate a plan - $PLAN_FILE"; + exit 1; +fi + +if [[ ! "$(terraform show -json $PLAN_FILE | jq -MSr .variables)" == "$(cat $EXPECTED_VARIABLES)" ]]; then + echo 'Failed to incorporate expected variable values into plan.'; + exit 2; +fi + +terraform apply -auto-approve -backup=- -state-out $STATE_FILE -var-file $TERRAFORM_TFVARS > $APPLY_LOG_FILE 2> $APPLY_ERROR_FILE + +if [[ ! -f $STATE_FILE ]]; then + echo "Failed to generate state file - $STATE_FILE"; + exit 3; +fi + +# Extract some content the state file. +if [[ ! "$(cat $STATE_FILE)" == *'0ae8f910a30bc83fd81c4e3c1a6bbd9bab0afe4e0762b56a2807d22fcd77d517'* ]]; then + echo 'Failed to retrieve expected content from AWS.'; + exit 4; +fi + +# Extract some content from the apply log. +if [[ ! "$(cat $APPLY_LOG_FILE)" == *"0ae8f910a30bc83fd81c4e3c1a6bbd9bab0afe4e0762b56a2807d22fcd77d517"* ]]; then + echo 'Failed to present expected content to Terraform.'; + exit 5; +fi + +# Validate the presence of the debug log. +if [[ ! -f $DEBUG_LOG_FILE ]]; then + echo "Failed to generate debug.log file - $DEBUG_LOG_FILE"; + exit 6; +fi +} + +. tests/common.sh $0 diff --git a/modules/util/terraform-aws-cli/tests/test_without_debug/expected_variables.json b/modules/util/terraform-aws-cli/tests/test_without_debug/expected_variables.json new file mode 100644 index 0000000..984aa62 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/test_without_debug/expected_variables.json @@ -0,0 +1,23 @@ +{ + "assume_role_arn": { + "value": "" + }, + "aws_cli_commands": { + "value": [ + "s3api", + "list-objects", + "--bucket", + "ryft-public-sample-data", + "--no-sign-request" + ] + }, + "aws_cli_query": { + "value": "max_by(Contents, &Size)" + }, + "debug_log_filename": { + "value": "" + }, + "role_session_name": { + "value": "test_without_debug" + } +} diff --git a/modules/util/terraform-aws-cli/tests/test_without_debug/terraform.tfvars b/modules/util/terraform-aws-cli/tests/test_without_debug/terraform.tfvars new file mode 100644 index 0000000..f7f2c31 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/test_without_debug/terraform.tfvars @@ -0,0 +1,4 @@ +// ryft-public-sample-data is a publicly accessible S3 bucket. +aws_cli_commands = ["s3api", "list-objects", "--bucket", "ryft-public-sample-data", "--no-sign-request"] +aws_cli_query = "max_by(Contents, &Size)" +role_session_name = "test_without_debug" diff --git a/modules/util/terraform-aws-cli/tests/test_without_debug/test.sh b/modules/util/terraform-aws-cli/tests/test_without_debug/test.sh new file mode 100755 index 0000000..641a619 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/test_without_debug/test.sh @@ -0,0 +1,40 @@ +#!/usr/bin/env bash + +function run_test() { +if [[ ! -f $PLAN_FILE ]]; then + echo "Failed to generate a plan - $PLAN_FILE"; + exit 1; +fi + +if [[ ! "$(terraform show -json $PLAN_FILE | jq -MSr .variables)" == "$(cat $EXPECTED_VARIABLES)" ]]; then + echo 'Failed to incorporate expected variable values into plan.'; + exit 2; +fi + +terraform apply -auto-approve -backup=- -state-out $STATE_FILE -var-file $TERRAFORM_TFVARS > $APPLY_LOG_FILE 2> $APPLY_ERROR_FILE + +if [[ ! -f $STATE_FILE ]]; then + echo "Failed to generate state file - $STATE_FILE"; + exit 3; +fi + +# Extract some content the state file. +if [[ ! "$(cat $STATE_FILE)" == *'0ae8f910a30bc83fd81c4e3c1a6bbd9bab0afe4e0762b56a2807d22fcd77d517'* ]]; then + echo 'Failed to retrieve expected content from AWS.'; + exit 4; +fi + +# Extract some content from the apply log. +if [[ ! "$(cat $APPLY_LOG_FILE)" == *"0ae8f910a30bc83fd81c4e3c1a6bbd9bab0afe4e0762b56a2807d22fcd77d517"* ]]; then + echo 'Failed to present expected content to Terraform.'; + exit 5; +fi + +# Validate the absence of the debug log. +if [[ -f $DEBUG_LOG_FILE ]]; then + echo "Incorrectly generated debug.log file - $DEBUG_LOG_FILE"; + exit 6; +fi +} + +. tests/common.sh $0 diff --git a/modules/util/terraform-aws-cli/tests/tests.sh b/modules/util/terraform-aws-cli/tests/tests.sh new file mode 100755 index 0000000..a315cd0 --- /dev/null +++ b/modules/util/terraform-aws-cli/tests/tests.sh @@ -0,0 +1,4 @@ +#!/usr/bin/env bash -e +rm -rf temp +rm -rf test-reports +find . -type f -name test.sh | sort | xargs -L 1 bash diff --git a/modules/util/terraform-aws-cli/variables.tf b/modules/util/terraform-aws-cli/variables.tf new file mode 100644 index 0000000..52d2fc1 --- /dev/null +++ b/modules/util/terraform-aws-cli/variables.tf @@ -0,0 +1,43 @@ +variable "assume_role_arn" { + description = "The ARN of the role being assumed (optional)" + type = string + default = "" + + validation { + condition = can(regex("^(?:arn:aws(?:-cn|-us-gov|):(?:iam|sts)::[0-9]{12}:.+|)$", var.assume_role_arn)) + error_message = "The optional ARN must match the format documented in https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html." + } +} + +variable "aws_cli_commands" { + description = "The AWS CLI command and subcommands" + type = list(string) +} + +variable "aws_cli_query" { + description = "The --query value" + type = string + default = "" +} + +variable "role_session_name" { + description = "The role session name" + type = string + default = "" + + validation { + condition = length(var.role_session_name) <= 64 + error_message = "The role session name must be less than or equal to 64 characters." + } + + validation { + condition = can(regex("^[\\w+=,.@-]*$", var.role_session_name)) + error_message = "The role session name match the regular expression '^[\\w+=,.@-]*$'." + } +} + +variable "debug_log_filename" { + description = "Generate a debug log if a `debug_log_filename` is supplied" + type = string + default = "" +} diff --git a/modules/util/terraform-aws-cli/versions.tf b/modules/util/terraform-aws-cli/versions.tf new file mode 100644 index 0000000..df95b58 --- /dev/null +++ b/modules/util/terraform-aws-cli/versions.tf @@ -0,0 +1,13 @@ +terraform { + required_version = ">= 0.15" + required_providers { + external = { + source = "hashicorp/external" + version = "~> 2.0" + } + local = { + source = "hashicorp/local" + version = "~> 2.0" + } + } +} diff --git a/rslab-ali/network/main.tf b/rslab-ali/network/main.tf new file mode 100644 index 0000000..98f0a90 --- /dev/null +++ b/rslab-ali/network/main.tf @@ -0,0 +1,38 @@ +locals { + default-tags = { + Owner : "ken2026", + Environment : "lab" + TerraformDir = join("/", reverse(slice(reverse(split("/", path.cwd)), 0, 2))) + } +} + +data "alicloud_regions" "this" { +} + +data "alicloud_zones" "this" { + available_disk_category = "cloud_efficiency" + available_resource_creation = "VSwitch" + multi = true +} + +module "network-with-security-group" { + source = "terraform-alicloud-modules/network-with-security-group/alicloud" + version = "1.2.0" + + create_vpc = true + use_existing_vpc = false + vpc_name = "lab-ken2026" + vpc_cidr = "172.16.0.0/16" + vpc_description = "Lab vpc for ken2026" + vpc_tags = local.default-tags + + vswitch_cidrs = cidrsubnets("172.16.0.0/16", 8, 8) + availability_zones = data.alicloud_zones.this.ids + vswitch_name = "lab-ken2026-subnet" + use_num_suffix = false + vswitch_description = "Lab subnet for ken2026" + vswitch_tags = local.default-tags + + create_security_group = false +} + diff --git a/rslab-ali/network/outputs.tf b/rslab-ali/network/outputs.tf new file mode 100644 index 0000000..a63b51d --- /dev/null +++ b/rslab-ali/network/outputs.tf @@ -0,0 +1,7 @@ +#output alicloud_regions { +# value = data.alicloud_regions.this.regions.*.id +#} +# +#output "alicloud_zones" { +# value = data.alicloud_zones.this.zones.*.id +#} \ No newline at end of file diff --git a/rslab-ali/network/provider.tf b/rslab-ali/network/provider.tf new file mode 100644 index 0000000..dd87b27 --- /dev/null +++ b/rslab-ali/network/provider.tf @@ -0,0 +1,14 @@ +provider "alicloud" { + # set credentials via environment variables + region = "cn-hangzhou" +} + +terraform { + required_version = ">= 1.3.9" + required_providers { + alicloud = { + source = "hashicorp/alicloud" + version = ">= 1.219.0" + } + } +} \ No newline at end of file