libsamba-util0-4.9.5+git.149.9593f64a5c3-lp151.1.3 >  A \~/=„*;d*i^0S,˪Q2BIPCvpεh*0(Ybi-`0o!*I}LzE0(Z]cA/6ނ'e:8ˬ1Wc+K73 l9n"-̔aR`%?VhFm'C#.=Up0ϟ:a'T)j6eP=Ai ⥹ST($ۖGLƟlA^ee08ac6413c0dd39712c7533b477af14e30067cd7b3cd26b687e3f3dd2a9daaba481d336cdefd4d3470e6f47f96550ec0369410c܉\~/=„IF hi_ 8"dY߇U2Xւ0@2Em3-'}/^->WtEȗe-S([0 +zWͻ0]K&&@dtMʟ*';? >ڬ)rm {PsQ {`;3gïedq ՐɓIJj0kϸq-sD/;*m$"_4ӢR-epb5H͵B<`@v"{X""$yw >p@ZX?ZHd+ 5 T '-4< @ D L  p%%%(89 :?>V@VFVGVHVIVXWYW\W\]Wd^WbWcXCdXeXfXlXuXvXwYTxY\yYd!zYYYZZDClibsamba-util04.9.5+git.149.9593f64a5c3lp151.1.3Samba utility function libraryThis subpackage contains generic data structures and functions used within Samba.\[sheep83 openSUSE Leap 15.1openSUSEGPL-3.0-or-laterhttps://bugs.opensuse.orgSystem/Librarieshttps://www.samba.org/linuxx86_64 \\"e1f892331a120f95beec731cd5f998c0efaba92553d1a5255843e6b0ce06765flibsamba-util.so.0.0.1rootrootrootrootsamba-4.9.5+git.149.9593f64a5c3-lp151.1.3.src.rpmlibsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba-util0libsamba-util0(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)librt.so.1()(64bit)librt.so.1(GLIBC_2.2.5)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1\N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USanpower David Mulder David Mulder David Disseldorp Samuel Cabrero David Mulder ddiss@suse.comnopower@suse.comJan Engelhardt David Mulder Samuel Cabrero Samuel Cabrero Samuel Cabrero dmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comSamuel Cabrero dmulder@suse.comSamuel Cabrero dmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigsheep83 15569334674.9.5+git.149.9593f64a5c3-lp151.1.34.9.5+git.149.9593f64a5c3-lp151.1.3libsamba-util.so.0libsamba-util.so.0.0.1/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.1/standard/f8490f6d0334c3a4fa732b71fd01beb3-sambacpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=240a18e352fc98be7a4e1ef8d5335efb9d10b972, stripped!PPRRR RRRRR RRR RR RRRRRRR RRR RRRRRRRR"|P3/ utf-8ff5e55758bd50c808e901ed2a904be9ed5dd9753e80b10e3a4a4d34c93b940a5?7zXZ !t/l] cr$x#ǿ7}y :d} I %,Jm0Ƒñ9DY_Պ\kߢ{Ĵc(ʷ]t7'@@Og8Ét'n 7}]We5ddv٤.MJ<gm)50\S^Y(KIfO\C+jJKW1$NWrWGŭ\Ҿ$B3:+_@P%bqptcy=Mӓp晏`o!@kd [^ 06])mF+iF"q.%۝7vJ Sh(4Ľ(ϐ"b{):#;ە^=!N}QJ̤ b;W{NsQZ } c.D:PbwH%%  #_B&9_I1*G*ՖiJ"H2kHuYGjQXS<ؘʃ ?.KXtg AL$6;2IqX1 h0$S&NAV{>PE/sG˅n:T̩ڋ.%Ƹ#R!+dl1&F~GeR}U^-YxFhPG{!y.:A|cڸ%zHX\"ڽJ&"ɚ/UOp+#}# OV'#o^5 5H?J!-zsBPVos<$nthBۚRUrj=<4cG_v$7=ϲ ɞʶ͂BK:3 bC]{*O`nkk NȪq!$Ď>Daq/@j+`+K%^ Vx&2Ua&|iN;x Vp:K'lIDMʛq gnr~M{ 7Ӭ6֛rm۽$>b{/9|~ \Y4譔`,g . ě?@@#%)z>*0(I&{3]fIvO%.CQz \_Wn^8@ LsƂzfKT||x =ZhIT Q/*"0YMFgr)jʒo%HvQK^f?ʢzV Q,}mh0d| y\0G {dFO1R bX\aC$2߱t}iUQx]h@tau'F &FR׃Qa;P3`U3`UD:q:m5¼ p ˣ\ 15]B 8`*h\xHDO/%M@70{ya>^I&Jq]Q꺭Y}CAu E\j+YJFemx\k߫J*jg f":1i^j>'k };?v`\拑\.d̵9:z#7d,]ؕ) 8C(B0A9WpQWEFGדYT ,%/Ή~Gi_o<Ͻ#D+6d\- |\~#Ml *k}|H7FAۓgҚy}Ra{޷3_'%Iν<:"tU(ǼFV66܀, ̡|D˥EvUkjKox($.,?,t 7ci>jKoLt6mjC(x(p0x |9T wS`-r-OXzuOWhJ2Y7,JBATWS:\l,>(?Q޶8{hJmP3YKq̢ϸn.zMD~OŒ퉍R%*QݜD!1uA$W[.irCY"lr2A)ts\9#5޾m$]N kVjPvl)_Nڪz_zk^0G jbX QBL+1s (k<h#:X#;6̺PFzEy,:ߐwrs ;LM>kA T@v\<8;l|De4>d11Jx򇞄&ЁC[(UO {CZ0롵sپ b ~.fh*fKARslNr=j_CNk:hEA0԰>9'Wulv74TSMM|%P&f*~cOe,Oe8Ty%4̖EB2[r + ь-)‚BT+ڝ:Dzn;XbWrWPinx^2"skc+jnz.5eŪe֘u ٝ\bI ӏ^3fbcqR ,j!dePw 5S5`8iNKk j8,щ]=P>rAr[ ^"7ZKP|YwSW3ɹfp9F:@Hso=,jG˿.~smJ7:)^SĹgc`pY 3ԜuQ:eTiѦRLR*,l+^<L4gc}䛅EJ :rj0p=?dAfn>o`_}| tKh~kncͷO_G9p:DE: 4 A>M#x"+u8ްMSNxӬЁ^f a07?FoȀ,¢e8wмiSX&w墥v/YB1<\ۮ٠>ֲ ;FO$fJW{yGy| !'QF q|4:{yBU.eF: GˣrX}\z+.^ȑ!ȋ5R΃t`Q nO?fMⰳ 5ܦAZu`"ƨIi7\E׋S HT5'f-1atB /خ:O(lVŎ-';Kp@'%ٺDݢ媽KN$So m4}ߚ+HH<5AQ,+fwwkvH3LL-j 931V (͡ҷ ~=;!ۡ|@j?6Ӵ낱 \ߖJF38Ϥ.tGdL7Avځ>g[~p0SK<_<[2E|d9CoXa2kID=-gm)ĬBQ\7n_2Fm*Fd坲{r4  ͦ|i1nXvUkO,$XKz˽5)^i?le8.ZR:ć(\@R@Kp_irQ^Y:K=T:h#yi=BnmgQ4dJgݤs"^Nm' |zN} B,zuߖ߾zb q%(`Z NDhS}I%FsY ل~tx}ȗ2m٠ %z?Rē^5܂R>qSqH؂+F*2v\6BW}x3 nJ!>#F|ʂ~_fhm6uEI>;{D/m6>lc[%IJ@/ߑ㰜}N+;GYsז R )0A"V+_:iG*A?',?!ˎ[qy M!0:t@df* 'p̝+OV3خeV6"ZҪV0r$Ye{diC*c'j`p?ꠕ7DbȰ]:8vZ[c6%dRhp]]Ҳ[_x) :ۗb$J`MԘu>pӠ3J;*P8Fqwo %)v9h'ܹWViџgJC?G2GŲIe˿QD\P/4x`̂ĥ {hVP3Ţ"AШ<)uVhlrc^U7.澆)2`{vq^Ο f_3G_kwވ_@""lwFo׆M4|'Gg}:+̑pa!4HЌ O;XeC}܇,q&E똂 YG |nBџv Hў |%za^ \Y2YVi1c6A6Z7,ͨaӸYHost=6V( yӇ|{hDVIΥS7DEo፶Y7sXH6v #iO *׷{oUddNڽÒ{$BrC#bcS z6k}dFS!a˻:^2KMVuJ7ׄh];~<6O*/OdڍoǖP_DVLX."~~ FUTx?$רqY?|vݬeK]!M+K)s/kqejbv7v*aIEA6oS@+(a"$D'ayI6J)_+ 3ʒ"|ocVg/< )?= $S9w(uPْݺZf5ɰ(x9 g[W\ #DQy'7섂t>xbSF>CbgԔbq>p)te$R]v Dx$} S"`C`mCwi1]73yy:)uOVC_y<&# qY𮖗h[aގ,Ji;`}yL:Csb Kk,"D*ID(!^6[w:tQddW"Lu'ՃJJOT]Om0;hIN '3h5[2J(A7W;+RNsB;b&ƺ1%.R*ZIzмMt6y,a WW4ac.u[%M-ņ\PNύk͡M]'E \ 2Bx4>$Zw8 ';zE1 kh |b= U~ P-܃6:x=ZJ :QGGMƐ`KǍ`rfI?QӇz6܋SԬօ'*nхv9Vzy0ƔjaO%.TRZ/L&y(X'j8KRelV6W(Օ'áu>@3Du䉮R\qXٳ*m,^ngݓ0{ o*;w}P5q|?ٶA+ҁcJu86"7C\Sƕȷ;hWڼ籣l?" ԍ<4qVx9ҝ {cmWL@uxʺ(4+^ /GwPL oϙWQA0S0}v:dBКN+)w #)UZzCHNhP% -CziӐ0xmrRǃҟMJ^ \2icoZ =LW[Ċm(|]L$[ŒcY[x2AN%t|K$G%Ds<"Ѽ>4|L^pmNNjpu"HgUI0*&Cܣ~Py?}…'ا [pg&P%L7}R-TC  O:1 Aq/x:jh4Ҥ$g(Ed-z7s| ;xҘt;cp@&MBlN s2%h=+?]I>qMq47JC]U:i_ϒ.P7'u+ ~)W` 5 w hb.Ny0U3^Ӫ\{}j-9ߌ(=ts[1M:CwފUYMz4#(y@'w*'wT$yMtDZmwMa3lux=LDIyy R\~z6>j?$ &R8ޣz+YQ{èɳFQl*Fm]:;ri 桽/񣕉v=f0oTWB~Rk4燷PC8KhZ [ZzO"Nw,WA3se9ݗӃz7l!vkjP@x/hOLICi1p87 pBj}v*,c>,ٚX vWWޝfxIiYm%3{wG fx 4g__ss[/j]5[Ǩe`({UyJ}hhIBDĴ4y{%!CU񭼽cq™e]ַĸ^ l~HOM}C7C9ݹdQӕؼt?{|MQP}6_0^t\J)ǤWـn14Yn$o>=tlUݏ51TLbnI,\ vP }GSXF>Qy`*BwP!v Lf QnZ'!K!Q'>=.6nP]1IA{1mV']B Oӡ-A3zYG`O 7"ҩ(Cل[퐪,Y^Ga|Oe1=j 1 tOȗyQLA|@ۮ,LtN H݅YS~-`VfRˌЅRpD4fmW 7E ^ vuKq[[W(-qY/K&Zp"b{͟5eW\ 8Ldu# 2 cvЪE䀔o ~+1Y5>V_nv~֎>q7M9c՟W &V oVL\'i\:$AdB*ahy5zty/_ v\c "id}KLJt< Bצ{hu?OӗC!@Y8f-Xsʷ⛠ڗ#Ksel|Fnuoc#ZP1{AN h.B w<y휙`}Vuw 1cC$@a Fh*$!{e Q*W$ž+;t2/tb'T\z)Xr#V 5VHᎻIe`ۊӟٛ!ƓhJ?V*ukDic_÷#w6>~G`U5.*CǏ;f'(6y(gΠڤcn]l뻀џ.@ Q˯_?5B]R 1Z;O9沔ҘFiM!9X8)Dm$m'vˆKZYr䋛KƧCjZO>zq ZzPt!unCڔ4[N#cL?go I(C6?s\ǯvP- fH;-*N@&v7.p:^CFk\tHigxid `D5X,=`j!o7k<f2gR3>ċy5E2/Ȣz2s;_ }P\BSF"yӴUC=*Iz㐊*Sa*('CZ3f"Jai5u.-ԢjLu+&J~i2}ÖhG۟X(!icA,{f{FkgYm<A(LjkrJJpGnO-S0x B&Α˙ȰtEٚ]gP8tF;k*E%J\+sD5GDqF{D3&C寝VݲYboLDwIC0qp [ЁC51YPq8Xo5D_I@M?x{nI-7ܖA">E9Ek^*ݟ [:2-`ب3,di 7%: MQb~Ao#8gpF4tFhQ?Y4$ZҠq٧KdZW{h5thU?`|ɝq>LwxZa;U18Z~ـ|ӻZ !na٨k,ilN{&[ӊߵ*줙:L#`%:DesrRj:U ߛg]maˇ;{dˆ6uW:⤊ Sur4X99wIdQ QYSa3g3DWo%(VG9~}@9҅fr,?ȽRe uTƾX,'7K*90yFv:QzzҮdcᢣOxM*?YܾX' DOg-_0TEGZ6?={rg]R]JR {cx 8o\(ضW6_2 >ͬ n{UnH 8-tqw5e p:mgZy7sW0̅кC| yHMj1{w%:LQ({{xc'Km/z)]dZԯh}p<z9'47,w\&w[€O#Lk+$Hm F)Ej,dƽDOL>qc[8(6s%E2/NS^87'mnwvs0Z(ϸ@P kg c@8[%f<7f-kf~[0G@QT1uwPBGp /wshDsKxݻg޻3>:.q$^B\q:2Vy=/L 6 "zzfMQ5ZbQ։&W#mfq0h+l!T-O r׈8wzٜO]C!pPpΦ%#){0{,L jd<Ŵ.H$Kd~7:{Z&j6;1X^UO hHn8̷~EAXB3*Hʆxd/sTqǟ]OpFcIb[R ֒l-i"\e!] 9Fޞ D.@8t ~G2ȫj!+ĹFJ뱳Jitx]M# /aԤl =s uJ#]4uI.v!`}NZ(2u }jJu9=ƚ򈯪\`rZԟ6$ypNCz|V|4ZxhKL%.0"0V9{ U`Tm;OpZϠb(jj;*Ε/*!z8uM7ߛ07"PXtob`d_5`{t*` ʜL_H`suN/?JC9K'oeO>nLVdn>0~.oj~991K ͐ ;eI irHCOP p&4^P_=^u5%滉%"%ƻif- 3R-&Y4h]^;k~~y> 3B56Nx4u`JS*{wZ[in¶p+V nA2HPѻ6Zyh@rJ@kS؎R%iK6dsoVlvw, +Tōm .,-/F}^w<-Do,#ذmۦ@;>Ɉ"VBϤ`&2׸\γ\ksCH(#G~E˼ľ2FvfE3TΜXP o Tnt *U|$ȹ f=`= 7LC Eџ&/2he?%::z7 {2\ڝ6׿$ܪӻ>v-OQhbbX1.EPhc*H wvEh[:%t` rcn)VPc sQ怵jt+`3#&_5Iؤ\puH,cUC$u1zD\B*i05|^tgiF YgmC }_;iO\4AamX%^,|y$H@oMwWF%2Ae~Og'&tؽm#4P#kHD{^-&;H3*рK@?El8vd8O.e'Dt`F;jDiCHJVzT~ؗ߾9U3*/j<w{D$sa AGNn1߽+_oqJ'۴w&(ف[? J'P|Sn!U G=f_8~ۋR7}Ww&T& o ICmG`6E5,"2ŸFapt(zN"sF%֫wMɒiaКlU*M5nO{nی%E] j s4xSnk}Ь4 GǴB'2T%;?.AU:J{kY)ZȖj!_ƴ˰VƁרivY7*PV\?ȽDc# 2,y]V"ڋ9Hz֢z_J3.5̦+)V娨R^#c]U,%kbnq 蓷}ѴD [W+9ؔf=\S0>uhkDH}wwjǓ$\f|A%uXhNInaAPo[dc)˸ռ1xx› #ʼn.ѨK-[榉dO؅x)cү!zoC4[Ti|IFFr9G;*MmYt~e Ti~4RUy;U,`\[WpY̶t_wSi̴yAZp| K*RkaԪ+|l*_2͝-l!#?EG/GN&kB =$FuBO.BFMLU4sbC#u{9Ϝ5xc@%3 kR>DgLpPw0*S^f bJ`48X ̸}Imٚl|8A5R[껏 SfRD}Rr.Ed; ܉ rèy4:ᡳ_ w3 ]%@?aV@YERV9Og2W"`,QDeTd~~1e@o[AKҹ < Dku0;k4U)QEPw|>Xa]]cD5[xw?^mwlOQVkijU=UhTEC )~j.>*cɺ:Rz|E+R&r4WtU?2KR|r? W%Hylu5PVP؋cx|g(y,Y x@h @0gL& \^ac18>PHϿ=yRe'gķWhJ}E0 a5ZK ؾ&hq t6 e6pG֨\vH=3JcmZ`Wz2vm̿9#+=)c}"<[f)A}9QRkL]=4]25[4k ZkF3ڭI]G ьϺ{%Z'p;z';X*yl/_|BSwxEC{0~z܏^/ Ó$%͉|=[t K*[YNO \m(x C4q%vW؋̸bRc ^gAPk) ~/' XP;D^>F d-dfN7`YkIc[wu\DӕN6tvR.WB{f蒭 !QLpl:ӔE$B]'%sU`.` ^zqmv1觘Qր'G]Eojr*4qEWT J 8 ~E}Ev2IBKl'VȇAX0$^,2tzC6}, ɋCz2sĿZ+Vl?lM +mF]t4D2eJ[mahh)}p]VSBTQ گeT pkp&b&??d%*4(P|0@4Gy&FCKLuJ~5GHM=E`at=gUCTwZaiy$fkҲBDPhmfԉq Pf{xY0chI=/XevHӖ/sE(=›c:l)X2wu~ Nq>Yk]) KuOb1|t2ml䬃EHE\[.x.y*Ŝe!&9 Ro8>E.w~X܏[,&xϊ@o:]5 a͂פoUPirU*pb"52%T»>AnY/0R`%2ztOal6r>_O0]w3^\l o9 (?b:"\`B3O'kІT2ءۄ=1,6ASᰐgfM~k_8[OXTd@ pռXL]'>zo$DN-[fYdJq˼s$}3H OՖ/#8jz|=w5NS1Ku%ߺG4,CLDR^gκ@W%FQP6e7;#SPD9T9Ik Psr t&Br _d Hx}bѯ,MpjVlMPo'SJtV.R* {vzp}a%Gʤ<mD@h$+m󝼂HЄmm%Y &XE73 3і1ˈ,qw6H*ڜE%xCisDj#KA8fƱk`SF {(^;j5U|YyhΛ<nWtEBawe \}#X#d&XV!ϻnwCE fjWpƼ 7o2 j<׷Aa:R`~>S.L:g<KNJ (ݙ1fTCX7M,۠:OFl0"ȳQ줊&n:po.}T4 8ݝʽl1&?ﲂ݀5R nj 6It7+4+WtH@&fGg/`ML\V q8s:˒G2v/~̱* x<"BP*AaT#7;BfLS췌JYBV.GOqtI=pb'Xp]:wT+9L=kpVt s 5{MhkŽYgθ:ʗZX>0Gr ytˡRZwY ٹ>o[j.Dd^ aXd)-~?>S:  ZTdYz34XL&ʰ= ۚ}\.qtwU[`4R:BFITű`)@ EƼ+w]ѻ2o öIArTRЋ*8 зRꣿF=().my`a}?3N;K4TbA=zr dOK=ͩU^Id|_A"ɑ~`kdId/=d xa(]p?Q0߾kIvP+Hl3#,2!ֱ)YoTF0=k5 &Dd5f WFz.}]ԟG)]E~+kah/' Fec*q2I*"6] `#RNʒX\vPԹ0tuY(ic 'Z'FĐR6@8uAI^f(ge@3i!"Tkف~Qt:_[y 5*{'̲;-[.* 'GJQp P0t@-¦Tj:2 1. :O0!Ƃ}ȹϧhEYǛg Lַq˩Ry>YzXWLm|i;I w+8m'^:z#4p& h`I `LJI41cPN5` *yY2կ2$lZ"f Ǥ4chPb :@%_@||tu$KmxS=Q2e-X`SӮ xx-iH]NrGvQ8}%h U4w;a,tMVpg9b}8љۘi,V~O^=V]VzنeQz JS Q׸= E٢xW)8j{.93m5 ' 2*ks~fTyG=b5m^Vs2S{i2Ρ8Ϸ mt}DԬ#.03.'yJKNsOP [V@b<8GIXrJX8"ts`OϦUD9ݒ-NvT;t TH{·_v-f}.p58$#NqJwlK|ߡG5k&bFKbr,DV] ''-ߖD ]3] ?+ʩ֌BF +Fo1tZZ}Ώa7F--;58IQB} a.g@g\&Myqg' TFxjFpb,S$gq~ZDB";n4EԇܾǮ$ĺb>VCg0fd\YeQpHWdݒQ,xV ,|@V:fLofO_k7d<̚Zp8u'v6 ’Y6v<*9K#o[ndzD>#6˞SI{gzyԦӽӂ_^aL@ e9^K=bNO$$GT*Zy}/sup pg)7"!(͡k}j,dζe;K ip@PP˺o\3`hR<(0H@k1ukUp<:0"~(usFS_}Qs,%D?6K2q9(0O)99i9*B< "?:Nb:hkTg "d9oxk  !h.q TVTGPq~^Q2M֓(~uKN׌ O;[J4i;̕OoRD6HݱUT/;1cm݋3DsӗCz/}ow5lHP$`ȧAn]]Y4s h(Ѫ~?&<7mϻRԙf)P_ʥ${wt'y%k.E Hz+x 4}H^L˳$jo>6yca2`|sU+Y"HPirxpT- =Ӓfсs92p1XKx ^E\TTxL#t'N*K+x H&B9>vsF}*҂=%F@9?Mbf 4벛?d|J3.`,Suar:^Ed4k.vYtI}j7vs;\`'7?yG7x-8m i5p{|DC* yc0D!>Rm\ԯ<)G1j:ñ]{u[zɟ 1mN4qڲҢb1gZz @>p7vN­kZ,dlȳN z_~aHe7 7$DF('9)cQ5=qxj‰I^>-\8L_.dݵӆH: =ZenFy?L/k%L^*6#d Sb|/B5Y,P,䆔]'$4Py=b5 ږAD`Q@kj%?( \ dlF_"҇@*9 UE3j98Jl>(B@c#E+5c]vP~J=} b "=X'FCLj |xˮ9T; Fj#uQmymtP[ 8AۨdY/f 5&ə,]O68)\/˗dFH:3*F?Cpwr;2#~%?oa?>ӕA.$]b?N^x?8n)Cբ@uբ~(>ڱ GTr9|:gouPf 侼JbR]}Q7npde',i6 um=+Vk?p"?[*y!N&BaJ"@~TwF˄֬'dxGc.B&ןx"-tvvIJ`QXPd|N-.޴XotCTX fWa(Fѯ@?& f&q:mL+FxN?c,> ( H_(^KȬAsB:N"IZfZk$;Dev. d)Y_rFvo:|^Ү 4:7!7Hί\5dɉFMKӣY 8 9C"0lP;&.uI#BJ59Xh,_5FT] 쩕JfXLvpǦ Oߪ|@7IWI opyS@ԭ#@,}x65'8،\F<;r0qH,`a&gy7@e# kU+' NZo49BK諻X.+sƮ Elsh9y| 'CM'{oI,* b!4OOOR_¹{lpLNXZ<n2=H^Tm(BrЭo9[M+ya Ā^`g*Z>mo Nzjul3AIPW@GCtw~ŹDžگi+#kBN'IUB@JЈ5TIOѱXqeJD)P6 `.p~?oҝ⋣prZdR$8hնQL*=ԫ *xD\區jU4.C{Ƹ=bOX фo^Pf,ƺɲ]5Wez}@EbFv [2B ޟv`1w:r~w Ybe;) *&fm <̅u0RY5£5O^rR{0p*m(sBN3 Z$f h4T>. &)+:$t{.Ba&X/)/LTTGYWN9ooY"ߨ_" nQ?E^(+-nrk(au۵o.dK1l8 %EHT-pi& Ӑ.x_T,ZW*DV5 geWpL "A2`=I]4+<ғ|'k;|Q*B!EO:( W[HM$9ħtX_8,Z#lb#%R6y7ᝑ7y)g B/0Dɱ)p_S>$@7$M^C`)H:N&KIc5|&xyT1Xfe0|9wTjR5RI CwA6١=PS6;+ȞM,%U<[sM:BĻ^AQ=S-TғOkW7R`v[fo 6#Mζ=۶ʴ傘Aٟ53#B1_ hw,hHC2# O H0JZ jez*côQT;FItĝ3\<1Uwz !VMm R~F-nۻ -R3GSы 3#Gz WIBȇ>xe吶lcM*tLXQ/cZaWd /5be]ު 3NL=^ oRݰ^IK ºY (k]ڏ+ Ϧbػx[%NX/_R AkmIx? NX{ h`${pIk儡TK}[/?mg|4^/"%9sOᡝ(L[.b1gA=S?cx!5JK隰gY)N{*8 $++q5voEؤPRږ_`0~m$4jkn>"zn~B6;!;n RhCG%,#NUQ1c|zd<$> b1 )Wo>98P @ ۶MXqe! ַ@Ga=)9^BP BcbFLf/3-_xΐk#>rR}0Ձ8|I5hYc[ 6xVL&p<!9z :Ot:f}K4VArVjt 7VΞl7xX $"P l[0ڥ߫zhEۿyY4hR>k-:w؝9UZc{]Iy2c-G+;^v8Ⱦm,69)h֬ ) dBk B!-oV%f.2/!d# X-3X%kIdF!%U;!n{+ MXbQzįlڿ] 6DڴȰWp`lV#Jd c4>D$7b|NqMYXwUmcIP+'}U)Χ$i^?4-6$\sNڥځ4s"Ӧ߀'z̛1JhPqvv&k2x/PQYZF$y]O7!ڤ#y}ԕ쐵Љ9t`TA#q3hCW:}M[څ?Jv]!0f>`$--eeseCwyA"evW9 jaq3ҕ"tn&+Jx3aEY4/,kymu=ۀz[Fd;K6?:Rz䰄s#10sY}rbxޛxHS+E){~N#D/Jy!e  U8x7Ͱ,TWېKW0$=I LQ?FoL kT1bi% G EC.)ڻ"R1SMs=k|ohESՃXdr=TzJtA%joDBMLz}jheoɮ6}z.fHh>n~Pgkม֥RHΡ脕~}e<Ldi T/6Xva,0۫cc9< %Z Fջb n/;mp(ܳFIDۅf/c5I[#I$#K.`Y?s6x^ X.P/W1$KdH:sB gv^$J*Pkhج`[\ >g"]ﲮ'cKͥ;v*ARʏHr {X2T '\KHn{?ڽ`lf !d`f> ԘJ_'~K ֠jWW?yf1I|3n /Ij kr8Uym&RlhF,&U'kV6qn~0ri?cNRn;t6zge!/6BsnC6F+s9UIWǦs] PSn.OxK|&gR䝺n+שHU*?g2q|| ldfHG JO^ ~E5D^/:ǂ? \r>0ds k@2$ѻpiORq| +A}MS5'Gz_:x!_ozlKBB]'' dET7t倀e>V]cIиŨ<@9T7Z i кmb䄜qKYLǢ9HPҷ' 9THC CUo-"& 'kۜ~Ԣ'>֗z"CzuЭ eW݁F"IjlrN9@nEȵ^<5`NC5HM6Yjc6Mwm@hYHyb:bbRx;\E(iipB6dQ m_r7ITjٸjNTۨ:*}l`H6י+ -}ƇV䝵H@\hǫ=\ѡ?L" F9#QIR] ?C?n]vĒ&~>΅%}m,ժ, 8a+R+6nEyK4K*/<#6F*8Sj`9]Zv)X8VXPRoj!C‹l2)̸2Y! ߇T9Q ʖ"U(/ :-%0Aa]KFe3Թpt=A6+ݝv3\\ Rm1^VX`;5l涾[yzKMQiFw3{d+>@Xe]ε]]F@eΈ2>A'7zǮ}xl.@J/ǭKOj*^V PX>xdS}41&Gy'GB6_Ed0-R [1.tіUdYeĚUJMm,ٮ7!µX4[-d?FW So{T aVI9#[]}Wc6ʫu,Lu٥Q+~]IXz_ Jv$:8}zا$BYM8L {mJny!(>N|DBgV,(WMákp &H1ljV?CsU5D=47Ԧm̑A]O?=^:ꑚ~ QAS\ /SsɳC_uQq 9)>,fYĶvF@)Cys|ʫG߆g=tFy.Әsw70;Za[AݯUh<{R{ ilcl@M#ŨMn;~gnB9{/Q2(85RC[ H'b74p?IT#=G@?} ,dGTDR{HPOʒ+0LWHQX3#({% :" cywMp,COH2cf%vd[~C퐼?f7s1vlag>$)7X @R0 Tw'`+eE Σ7d13hfۊV ?_va[ήфOLaOa z;#&ޞ._e6± zb?Ƽ--+#dVT/rnDOf1;3i`9a:"f yUϗt9L~FfUUW2:Mcw`3I^0E*ޮ岳7&%N&uwU2Y,V]%szf n92 렌JdM>2ah;CKx_C?tg}f;[|C' rw7%Gd |'sȌx҃l^ &4D\Y:!!@tǵgYc҄ Ln;Uaw7P,`HǶl66%UV1ru6Ѳ(If^Сx- ueɘyeCSm$͊*g5f/
WV?)MgﲵMR{٩^0& FG O ^f޳ j@eh4vf3<\H7lrrrhImFy`DI3#-g<z᤮/-QR?}&ѕ;mv!T6o_;Krf|GՎ Ҧ,p. Ɂp:W't'#)9P{1'/s%4Dse.D ڮgINveBsr0p=)p^6 +[{*a3-Eol25$:ӭ=nupt:?ɸ,[ * sG iNT!uZ,WQ7_GID|p83h;ΨpH'_u9U7{ 86֨X>9*XȧHp2 d@wI,FщgB®=b>9bsyƵ?jy!nryRvNS(2&ѺIpVV H#{@w9 rT1E;qY")6\G0B܋zM!KdY[ @bc}H&wqp4OdyDMP(q㾑ݐ EQ SLĴ/}fc05-Z[]k31hLf\z7cҼ8>|Ds$J"6r$} ֕7]j̈9E~#:IXu&O x,u0ۭʊ{% pJڱE-}Ah[}$pj#VKvE$~S{@7 |Ղc3!R=nZz ϑc> K1PkBtF,GvGJkjm850Nހl'HI~'Ep!j=`N8Y?oO+KE+:B ,q&4 jx܎" A$ ؈ N:=2 ~,Uz~]s/BjC[*\dzj/xp]77-pv?et/FWfv5q j77 (6g*E#ʓ@|LCOF =a8 P2١(LCwY %ۯ:YE:Z= |qi4~R0f& 'UJGX`|qv-[eSUvNTcO4Tʌ72^OG0k D8Dmy{Vt<5k [zXwVWZiͥ8ȭt\}F+˜<9kZu6$/upwxz褤8Qּ~F,d=h}}3[T{A,Gr0-'U$O )r/uGV[JOK,|Bd݋ ^^kpRTȩ4 R2%?\A?rɋֱ VOm U+ uȖ/3+5z{Iu3ŵf!/^&8ݺ+Ivxy8|v 2C9P^U S8ì^G(q/<ZIcfb40J?=ZݲŠJkl@W rG5A-V@҄Cʊh+MI;hLhKI̷p?v N}Q9^1 Cu3a)"(5VFR@4M!n/KrN.nE9KT607'9nB *13FJ5!2nj4By#P5Ow5Rk9}䇤J^,r[BWid_K c+-%twUROb i}Td27^Fp'KW)>'/έ!=!H-Tͪh u/iG{^BCT8dD1,\(]}DRS0hUؾs4гtJ ¨8Hge{DX(WEl@51xߓD8I$ݒך >%c +2p6AU$7^D,B~us讣E``ӱ}] paEzOM~EeAu/20&rXsy4JvU %B4nZ?zЄřZt3aa>ImtYٷ=,ΰ2DGz莃"p ͽ]e߇jL 3^4-K!cJ"0Q|L6(M1' [vf@7Z7ԫϜ= gUA𧯴71"~ͻ-0ezPP(+fwfƓkAJ"'h1%~#A'Y 0^ǧύ_ѢxҲ"\L 9;eo_zYMy< wa+Hҝ.@0WHf8i8Aw:|b~Yu’x!LTC&ߙ=v o6 M{kL]J4ToGNm3^7R8ua{LovIL3e]o:ݒFx4un+>;D9ǮL6 a}gˎL; ҈$Te.ӡ3̅U\h鋫.fw֧buz u;?!.;'{gY4JAe Lr>>Y7FhT{R e>at~HzN}[΃ulQcH}Z\uOTHnЋ6*bMEg#XP؅{NBnIaKPbe~c_/8e[RszP- D[: FR  #rHmibfjh'ɪ9qKu._^fB GeMYO@%m$FܢdPA0iiaeGW² K܈^hcg@tlO> 5٘b'bezIA xl(-&`%M$M'{ˁA3%c:N 9X o0Cf36 &nȸ|/G ˫.UB'! jM2w ?.vP*KZ@|և;||X4*T G> n85aXg;?+q3R^\ܐz_$(gifs|y9Iy}@DdSno)}43HSIť(Ӂvqߋ\#C{z?v!\_=j8T+)1A\{qNroR?6"44b yƇ/6 |)ïR_d9(AQ<8,XHA9։p&H"]IxgfnuaѤyeJ%CBNºL `oz &2A"u~H Zυ '뒋,5ÛӤ! PQ%&uIey`r(ɋ )!\P9P.ԡR"QTEd-E'W#G?\ƪuSM˦D$5N,=\ERd_s^[jkE_H7Odیx#}.`1m 2;)m}TB\@q0Q6g>+oJMR^haL⿢\r|rKd^?U=q\ΔC6Hv#Tք\_sh~-*$t`vQgivtqGq[0q A7XNe!]+!WWxK<[IgǗH\4Q+Gb;&W%XR.z)S[Զ 򄲪U3%y+CT~_B"ɹYNVrpοUHʻ`fq)v;U:x>sߘԙBF3x\eBݾY5f̔xLq&L&t^Zb_b.6Ϫ @1XaJ+L^[̷ݏhj(ns%ZAa94}+i P[6~AJ}8~2%?hp,ሥ pΧ!!`޻qfOmAϬ_/ѡ[hy~JL}W'q!T.r }ň7&6cjצ21BڱDBuJ rcQхʝi*kAk}@73#H !Hh򙘬h}" #E$ADFyC)H.IkDϸl;PM\/Fekz>iT;&iF%;wx~ɷx{^d%Ўu#Gu~o4ݬ9,D aX]ҧ5InČ]ZGgT1h6Q71'?7 ŧNM@)j٘Akm(ԩv)R5T<)Lkj7 R]=\:Bv]n-ӳ{!ՅIq ?)WŰκR{@vvWW&1"nn,'@SxT)"Sq|p_wx6o)=S㴤XDE(=1Q v-O^jU:k #(5X@̸FPx/ͥo^7BpIA &7ʩْ)x'pU$x|WF*k#}6=ys)F\QzdՠaU|2=/;nFH$ivkwqY`CĀexM; 8ҡiiZS( ׻~VhBgTMW?9KNcȼ˭^rV .atݪŮV+!j؇[{40(TckV裡p0B< H vݤ+iZzr僝EfO*~((^ pD֟yP8W*eҪo1Nرz4l9P>HT)NLB˻Xuz9pAoA 4 پB j8YYߥ&{zqT-8@5d!\oWL N<yc0#9 Sgg*|ӑG!c~K?)ie./܈# ,Y&W;WHz3MPyٮ)J77S*%kEɢxxI/.>x\5,t #cf> t%ʴ\HZ0QQf&?3?"KZ+|&C+O3=)`x\GY_kM=RYq{.jRϢmp'azӵA7L2 h! 4= *MDiPrq{L 8 j5|BD:pOxB{h40bX=x q :n֑h ߿,q캺' Z[G[^yҗ"ىu>k3zCGX Qgylۘ*?mǖTx7X #Xs''uZ4YyvP?drtH (4ЋJ=A{!h #ԀK$A;3ϨR]j0x̄u6/KZfY\AUjyeʘQ~X{&OhI.QB-舌KNa0O/ǪI?saR1-[3zjCp$?g2sw6#e<^y7#Q ^'t5s83C,#Xō pLE`yG{4C~lʠSSUKhDL/Uo{ 3 URitf.#B-1#"@=M9 G BS0]k :}2ݰ|nuo/F9|5spQCX gL'\P)F~Y͘v?o$K;Z:]ȡ#"ft/WiQP"-7Q@8"fPhm=lMd$tvec[MiSIb%pR*32`+ϰL̠ןٌS& ʞlUeĩ%|Iuؗb^_S $&Xn>B+\ {]p B th="Y&2`c|ͧK~f} d@w2,&ʆcΓQrb$$>7S{5Ȉm'_5ݜ Z}CiŦ -hsz&+¹+‹*N6l+};N6'  ZcЃRTfWy³]bS?DKزw*O} MCf A4ȫ3{|4祯}-Vp2>,Ё6w?tӯ&*F吆bݪE_N~"*>k. նma0{No"\^RLS* &_@vh%BҌ"h aeiƲnKe>/=fyj_z.$<]6ËGn!/)?\]_Tvm @I_Izvf="UEb}{0"1!Rܰ夳Aʏoz(J&sؽv[j_aыd̸r?;m@b+ҕҤP=2awfV& 2i-^yBbF $!U0$Ws{H[xwg-X:_׽[,q\&[*gH9<͏I-̾fcRa}KUuWBp]P;fI$%V$BԓEHHSB؂͎d͹uVJN𒤊BX 2CH dVsZ3N.YB m"S2VOm)Y: Ea;ZN4ǩ3L1 &O ŌȠ+N n3lvp8slq܌p yE' 2>owȀc-U! M0a0.- j10Fn8t0 %B75Yi2 :EmLB86w ;U 5Ɵ*$aH+}Hܶ-0h>X\ c5VRĨM 4jOdmVHjz}]ntW)RM]s__LUn"!VE,̊X:$$gy0℆T|hpa4|vN@sY!=Vezz;cO6*6*Q7Sj/H*'{,_Y`4w36:BFv֠;n|﷯P͠X, 5,h,ZJP6}4!R~|2[ 0+ˊ1kw# :3V:\ fI;1w耙)ܜ9h:n7Rb]˛= eK)w0fj}7 D<`>̏F$,焀_Z=)]Ka |X٥p}#LnYnZมn_C>+6h:$k&*wcӸ,hݼ۵=ĕِ<~|%Ͱmj34Z64@;ɡZuPaW]*"OgP7.-UMrYC¶4 _ uBo2ms캚A!n7, -RR/ Zd`\v+;1n;bC>#T}*nS:xi/3M }Lj1L1eS^l#,>q?&XN. .$--A!IhYw]jgwWy̸ȈbB7л4wI KVkiu8m)kx[B^䐐Gv@e3`g}`^YXwvAbj-Ry^p+%YRr$oC=SH\0H56=K*"陳{lJJQ8D=Ƕ)kY)P˶hKSX JIH3jQtQ9K2ҾW(8\z|Ôq[:^7%1S]}vl_H6JXoQ`?:uaLx sϩ:6Yʅf\܎jB&!ptFכ\7 ]U,Z،S>;M8M(ַ@1¤0w7(e¨$ݢ9^=G ᣦІPEQ ]Q%5ݚ l::{}<Bz mՊ@o-DNΫjzܭNQo(rlvg$m"Wd5WIF5,IIH=A Y"zSF7<_a?ŸW$NHlg+Wjѷ>O@Rc*;K #nT[C5T=Y(9 m]gϡghFfz7K_D1L}+Vu!1 1!ͭjƎ OsuH/+^AώO J}c5`rBkd6>>J߼qmet}*CQC BHZ"J%*G#_9}j| f8: 2֮v]_͜$i*WTXym%B '3U=ֿE1WIbjzM:qQ" IM"!!ƨAX5e P27&MGZ;N" rQfmN:#Q#+Yg.n94OD[4 ݜf򕅝zBi^WM.:$ԋɾِY}_!pgpeCXs&ڤq+po1ݶwp6`@u b.%#ɖ5)@Q·D'0x,0̄<8yt6[{|*ǚO_>]RNXqJVA3-_3tI;p:i g3L(0ŀ-X(囯b--}u:2=OKN~?9r(HYAzs1^w*@.9@`o+^j e4J麏Xֆ&tQKPygjEwE+=Zqo$ 29q:ݿ;]OQ.,);h͗>p-Fv~[ez t1i*qAυyƈ/PdJ@'UM!B',c} _dѪ5|*a aϸN"GٗzG^!" JL1+bNıNO?2Lnxгw4O}*k!1q{bdQ0cWfyJңeC|ַ.L^~t NGʩa+. ꍍL<͵s+?eTVJԖҾ(e$L\-#%Cl1bW/Q_}Bt(>V@>Y1I$Ѯ*\G7Ry~Eඏv?(SY*/#V&-ȶUDg}j]uB2i+ˢ~^J} eFA]]޹+ƚ{!k~}zoŸ'G 'bV9dǥK@.7GIIwȥL^R=f =礩*F8Wn3u8ndMhf UyuYD˾Y-#|a$ ^]Xvk>㪤t׸;O ek QMl6Gu/#KلvxBfާT/@K!lE%FN:K!ւsI0U2\-~Jt>e;_8r'XI늃˒`BCHxT@[O{+9kDf"^7$HOvj2_y 9ayjr=s㺪B1$&y@O <1vsxcJ܀:ԃ@=ד镖x1/m}tPAz#RXPp   jxۜZ)x3\id7" D JW,>A,V#ɦX3(U?GBȼm,Zը, MﴃݸW=?r:TAsZi0 5G܊G,"6?>&>N׷B 8s{4 ;/dg;S~U?Y1 au_!nX/ӉC@{CSġ+`{nܿ:X ?tqd`:,%"FTIdd9ߨ\ H27#WP4tUu^ottf6+mҠB]J,~{^?0PS L͓v4N@'i՚7#Y/F%"Qvnk"h~!/F1&;2C/RW-G5&@.@S~4 Pj|{d26EppO! Gdػ=cs|-s꿣M8TnA;zpp|[A0Ok#w4`5Kt:,2F2.ij[0K-@-W%v=hXs /Cۨn,7+G~cKwvNLy<%;Tc<ωuxIh#UTWSp{zկ꾩=W%P> |d`S4ZΏ-J+mmvhw~mo2,9}Pf o)74#P1Dp7hwJ]LۅN4bz\4&v)q2윊5Op!,͌[KKraք*Y%ٍ)>HTp1lmKDkhR?>}o~t/ l|n.( x R-؈Iy=h^g6Y%A\mw7Dxmf[g{)i%WAJ+7+3IZ,_gQW#* ",wsMa Z9{-{g>4qb&h@kv,KGTw O}qZ`G8@_K^vv`^J/Dd_X?tMv5%2V3: .]H[GJ8KZČ6 >u6c5.jcmJ"l ?3W<a@Q(@p3Kt${[6جa1-)zD,FTl T {_ 8s1U׫K(ԧ" ͘0 &)Ne܏lȸ\0 u6F'ZN/v|W 8i/G%ldwG>oEU(d@ -fkA!fٓO]$>uo#Sp`4>,LInt `#,0 Wl >;\ňsjxv2mv m?Ў /Y׽?ۨ-LQ0/:Qz`7|4eMczNSS$(&,?jBi@Ư 8x|UzT nM !FuSi<ZQ[~w d U1!T#w:cEΊ鮗f']7is4Rӧy MB`euE+ +U)_֋jAkI"ڇ~yR~80иhrsсr+uͭoӅY?[rwRMX{U~ߟ>T%K3J/pYB6:_[ Phlo=F _ʣ}ڏ^BV,pyవ8AlٹU_ߨ{=7|+f}bйnȒ*?9lϺQ8 Ģ'd2XǦU5ͨюdt;kZFDVF'jLDo-ʪs#m9j6zB\\uuzAjdVOf~B &hr/-.sOSc8*)k9! Z>$g5O9G2 إՓTN*wjy<6ç `vᜉCp"?0ߜtJو+q]aPtzdX 58t ~kLd{Aq"F>HU(4;θ\._VO5yg:Ր/ZQĬi5R`iQ֨)VB2+~'!Pr$|g 9za`F2P.!X[e(Y$Zf*zye"Ĵ+OlHnho}kdP]A$,e6w%sqD~P\ l9t>BIP,xr)-dTD2W2ǿ}#bt~kcH ́xO[0g %@pܪGڂ+AA v\S"`Dgנ!XÍ &-ҥpʼ^˔;pXO)qaeUz`hTm xGI$@ydy_(@{<ٟbpR Oj S=J;fIELJ†oOɶ>J%.&G[:ewy59(RAuDt@%ug'MM *މwL^HXYf-OgfuI|[+\ w+ \ }-'rDa +72($~Y!9/.8}0z)؛! y̲E Xow5H5Jq*+CR׬a&JESΠH̅37 fEW֧ӷ~G.? nI +e><4e#FIv%8WF+x8Ke F{̝pi:t?%kuZ%.kF*0eɅEy ˏ/|ql r I}tu&OUQ8StX=֒8&Qùϩ@/9 U"؋5 Y:p}6FXLشK69el[_]F. js3n[tV,1,7x KN/>&Mzfm<.'9FDH伶 \1̛eKzk 5K[6(v0MM7{5LyZUnKugt}Q+ Cy&\n8_;"f\A#8Ϻ3ܝa҆U-gê>VE / J̺U붕Nů5@]B[`zX/^wARw`!3>~*2 !%QIp 4 !xvnK/4Jb{Yi"]@Z!$bՍ޷v9?q}Q`́fx1\E:\4m K{$-_'=݂:&AzƸ}A,܅~'/,H˙ 9m˞\̨Vא'y _i VWRxҽcܱ;Bcoeu 5N+ 8]zcnJ, b<4S4G%{86b|&)tʔ-Ov^j /nYWv8bAWJ"x[Nh* z'@VqwᱲF2px b"ܬ:dbAX"S0%7pҭzUwƈ݈ С9]nqh֞} EAa9>xTaE)'&C)`K$2&1I$ J 6﫧SGЮG,0ŕ@aJ=LqYW#=W'J%c+\3JХJ:b"%eaۊ{DG4ͤ=ٸN6˷y /2bژ-I4%7)"1x\o2 cOhl: v&賚F9U5eW :Qw"&cy`84Byۂ[G1AuEMYMNdd9Ek7t%}5AĬjL$n܏}TkQEWk)fYL t*SΟR#RlIOKۡ.WwJ ١ɓ/:Kuh-b+nKR._Me_ά[i폧:aTA{=`N Va w6~{ֶٓ0 6g MDjJMS0 L%?lXqӏiVnrD+ Y757ϴ0&HP,ak ǂT&ES~>J]d-1EXnT06H B ^nIh ?BwS'܉$pvؽ>_pt[ ];vBl^y 3H-cϗ%Q<.CWnۣfնy8?vJٛZvcC},ќbus M-g2Ju۷tvi-G@zҰğ:nuXX1}9S, Ebc'wq џN:;D{Y>n!g o$˒ʱŞĕ/#ħ gʁCZk,ČܑfЎZ!`- 1;dZ]'*ɧ<-LhYäî%ޅ>4p'' 4 Y˶FyL$ _n;Z +ȹ#'`;2f9 9$\0i|z0jhCNzqe(9§3pZfUy{A[ei/78@ p"T?U;OPt;B'nȚ/UV\xB:c'=ؼrb%e/#=m*ٷ HWi9r|F{$'h BZ::*S@e@:ސ!EC0,g M8W f L=V5>@~̷>0 WJַ󃫦X9A AOhk+$q ߿P2j ԾnOt $:z:I_`$>i!uw^v,y5E%1vY`tLT-U_6lJuyժipK}Ui)Aŏ_)ɂ+N8ۜ NGoN!08RN2&~ze=6+16-+]`֎k[V#a$i#(q|I S%V/>|}%B<3'rL՚K)xRL~#H ةmX 33Gk1 יT+D]TcW6~Qv(tuG[ &)KN^5=՛| 2u{SkO9팋Zt(X\ķy {U? ~ez}!r^b7dc/Nhd,!*P3nBy>ptƬ-xo tɨh8+_^Ĥe/Qa`N}qZ`~$;S"|`OL٤Ø2!F>$bl5T/iQ} ¢ٱ0jYA!2_SpNdEgmwM>ߌ/>4LKGD#.!Gf:n"agx&3Y'Cu<T9g>-*ό)q[^e3,"@026H4i- .-[QQ2]edߚ^ف-m{ pdgG0 H T%e$Appzw".aK[G^3~#Y$:B$Ju|8;WŔFЭhm-\tv۶v3>8C(pO*d,ar-nt9:"Ez>@->ge72~ ʎAi>5dr塊9 $WFY@ 1UđlX"\"׵LX.{HDPC;͊uDV\Bq7"PBIm+>,?JR9c&eh#zjhduL|I[T,a{-k#v/+; % q$3u8ziئ0v84om^ghG7>DŽUW)=\EjyFyϖ4#_&@I5#>~{$j{ KIw ϩW-+T*,Bg\ uOrS"+At/sY-ɿ /+b Ҿ*^@Srs*I(8Bi " tiDis<.ЖvL _?X :!WC[h\2<A@z7; ;+KzK8GS- ;.Ux,lr Oi=D;.m^PCR_riܬ83-59oZ i`}4O5&#}U at) 3ɥ`єr\54 ȔɐNU<'TkUj%`$!# ~T)XuF4w܌;oVr$Ҧ4lVJɤj ,2mF_ 5^[/{';_ͬJ1IlDiJ1OL=וֹexqfiޭ$ǐɤȮA!2܋sdM~@*Ff{ߛ08(>q/,6ӟ^~Ur付8Ԭq (dikor.$8$ C.W͒fA{q681'aqh:V5 wMx/D.Raʉ:yz[b 0|poc3n;2c,U:F{eǎdcϪ|W!.\i|RC;lp͖J "#I>閆ޚ\~wfIBCXjnDlOمAo撏jփj$G$eJN9pypZ $S${XCWy[,A`:>|6荕Ȃ@;4rwDvoˠ1Ϟ< yW,¹dw~IimC@jkARf KODžْ˜4JV/c)g=T!'1ma(.-4i;Н8!ԵZguP/ă5gOm,F-?3,]ˎVxybI<38ط ̂OY.8OY9._\lF{̣V 3B4oce5}E~rw[vJ=z (v43YG29罥8hMB[BMΗ9k.9Vzz8& ?~kZ͟?T \71FLMi:㸇$f|Qeֻtڨ oI%ҵBTwԔ+/D7C:vm.!bAZhј@9:pɶA #v3&"f/k%=.[ NLQDE+υ|uSĠ\bEp11Ɍ] 0sZ:,p(-Zy!b}Z]ҟ8y|:w9?4K K1v6ǽ Poo:FwZʒ﵂OHVa[,Op)l sB^C:btO4VSqh9S`iA]0qwH@73"S\9A*VGX%S%HKE>px,.`3ɂ,a(~C?l}yF/ڶIn3AzYkdZ.fa`Dcbֵ*:1tN*‰iu+SMZkZc/}NKS ̇A//`apg JWu>u%!pxZw].mt fQy8 uUuK{;f{uE#*j^ba6;l?5U(I5\Uxsb,Lh\AOk.HUTtԫqkGi~{QBs8RvO?ԀG wBYp T8^"ٔGw-K4 Ƣ&{/= 'T:SO/cHw9k*ʸ&!=*Il У{zkPj>Yޭ#0Z#C@C؝\obܢj %iu(<à^K,SwհˉDqbGHs=$y܊ Gj $uԛJ&-(0ͩ:D6* V>DZn27(Tc!5HfE""tf$Yǘ`6p<-Nw /*Yc0oH=hgGUD{-^A8S'  V^5V82 ktz0쨑,2q̣ƟPYW\2%nӥR]47Rz#^{2F 鬿B^&_SAl$ Z9<=hQc%g)mHһLx MlE RL#N$" ވe*Ts3bompΪg^FҴS(gwQ-a$(7-qJ2UYLެ4=k81cJ'Mۦ:Kv/'wnV~U7Gʌq߲ wžIkn`TI! ;8*@P+QszU,rFLK83l8 dL#l@19/!0F{*hvR}iif(hC.}k q{P΄)wS}K$8K6]w½NRVOR|d": DԨ#D%`}Cd(rE˷RN%Fk\r T2 Xv H*|5 r sl R˰{đ6G P ]`Azi$/2 ;"я[}h1[,<_` ^gWDtʚ(`s,@)iJIvrQE$] ~ʊ:So4^[|}0r19lhGWpr32qަ=o=HE@0VA8 TX%u䭛%TCꥱ۟x%R~G}Hf|uABJ9 ]z0Jxeo! =Q}tuh't"v0~Y)P>zKh/f"v1%>!^^^mUky6E)e )(BT3[q6L!1# !x˿ԛeZR]ҍ3?F.I0nt ynwX 㛈Tu9s{%t !5X0(Qj;ޝQtLIQqqr `j:фz)x[&:*ߍMy&- U~r/]s ,Tƺh2Y3=]c.;TvWN<7NWpvA.3BM8UL^RPD("R:XU>t]7?[JUe}0j Z($IfL5 +Fp#J-.]:ynu+={[L",VO1ȤacFui9) 2OHrx$&joH38,Y=Cx纹}4gzXY=QVDhNCGmsRז('҂bs?#s|:xtz;pRf*-jC0Q:b^` wbԊnx)'nf'bY^{F-08y>oӎ`MUpW@[3άLyEJR(+jN*sx3RR,5ӓ`aDP4Y9%Pe@#3WAhCJ?KPdo+C $pPvk^NTu5\=4L8y%X2 Dh'llVnٔYޯ} u1%\'\DILU}-#FdqվrwMv V_ c!zCM7dRfe8&E#|2wT.o$=>ÕLx6jYQLY5d{ķ-YSQy sSf/&N ɦ7WHu u0jvK_E}.#UQXH_N&RвKB=ornLMkq[ג,Z;d~2<}ciN ,Yܖ?¯#c6s: (; Y4RnOW&JOg%=i%UA|SBMlk L{_wcxut`@ }-CLfi% #[>kzwe ]";ߍ hv%-4zJdΆ:zP՟8P'@JiGMs"qf\Ѩ\̒;`IFFes=H7 A4Tb/=<̱ LјB9ZpX)dg01PrK8 >2 l,dcI {s4lEC $X6,s;oga~A}mCXj8WxBK ,dLɺhYE1=tv.7l_ZRڕ2 0"Dꗼzy`n43o u MY,ϔy C< %º=(tOx/. luXղstt|tk~\gJa^y<^ vCoo<^!Ȧae@# n3:0:5e,*ۊ]Rq Im,MmrդXGro[̤oӉH\F)b>C p.9bc*BH3:Hzߕ鏾koX:ƀoE9>t¤eՖ;y׶՚%X*1-{j'>(u}&~VJyio)?wzOXO }2u=k].4~ֹv7&CZ(zR0 1=1Zb*D=lbzoO  sXoMMV;IKVüɿ~ 'pB/ 9}Jls~4vOX:bk;zYᠴCs,Y]Ҩ{=n:{{!؜ߊes0aȬ0ޫhЯOM@(>LCto,ziM@Dj\S h""XxjEEm  QeƲV D^x:Ɉǭd\ǠH<_1cdjV,ilSȗ4pa }h"3kxQpv\3rcaCݱy_=>v2oHc0OuL+ z@K`x̳Gi1<2(DwX;(11|lC#D,@H>}E;ǧsj7FS|M %MjNvKBeS@xƹtؚ=;qLqp)׬ IHDLr3 !=/]*AB_u?FFf<{炔!(אu{thM,ʩ2mT}f4{ryu0Fy5󆉉\WVyxO]n j]$r tXH/ 4a Lj!&wxuy3B  +?U3—3ak0tV~*|RgE]2κ!~ h l*ӥ^SX֩mM7jAڰB6𮏕к66MQtf9Y+ងιdoMkdh9 Q^d+w 8q+II/~XW6~@ 5יî6I0{qk "r1Ij5!Hd}D2=:Jӎ9̼ws w__^ f%iՊѣgݲw#|K|N"Y@! 'KdGyV*b;J-5iȚ) ]DbEh9@Hۅ @"^~〇E"*qG˔k:#[,,`NI8_m ܈EMM~ rVh+0zsޕGmEẔ0ir)VD~-5n}+ Q )ǟ3mo)58o-!Hr`W1"&Tf'"dAxZ=(SxRnoړ 7 X0?!iZP=MT_@Gpi6͑RzA<.M|8oޓ9b؃R4pW#Yh)ukJRW?_}<|(w/j_W7 m3*sI0)Zf0K)azLċTOf/kYOEKh<4 hR` VZ(^]E1ahbbÓo߭\L*\SrgQ?l_S㶫xP^(Fg,c;P3rE70%uQyg"uaEv'SFbS Ao5<6sX{.?hKP8D'-) #EU|?|_?rɥ8^Lص*&7FW 0;azzXO`Ll@{6 YΕ:saׇދu裿h5)F;&ǏoUPjӟ#~Q!ήT,l$@N$,ylI _ܷ~Qwsgu5{;4Jmk6m|ȫs:ʅH]DK\(nIl*  ]0c&3{:9Pυ$.L6ArwKm1퉥8jwy|v/)n#-W`ľYp I,>%3&Vy%Npm0$qރQb[ 47K P;K*bR qȿD8\5@GyZO!Jsd j1 1~Kyo )xf G=k7yz[F^ p0P$*zedt*^㬜B8E[6BM6Ky*6A dZ4[?2#'Y2ݩ]5`ەƆ= 8S ǯ^T/y-b4R.wԴ!/~j/)`R@}! ҃;{YP"yν>KW)3KPȐ[_u lydR]^YZ]>\+:UgG3Fڻ C({ ˁ^}4]t\Vx?H[kaLG)k귦ZzQka F HCR@(D.Dx6n˕5:{]I| Z:g& 4o ^2Y#/!th$Oܷ՗d0y#$^ uNkls|a Çpi"fT-3>۽L,͝(#4 hqQiF+ΚS&t7mF"K(堌[[!?՚;[E+ !3'r.UÂz<L[Hrު>Fx"#luzUKPGWzt#|FbQKF毃f{.9Vwn!@}w++)Os`1_1(7d_홎qIs$LLbQs2dl+z_I;Tp3Z@nŞwYTvc|d-Ti2QvƁϰuw]Y*0a"B} c哘8_oaogъ7|f6[v!=G&Np62K#eT/\/ 2lS/'%&M̃2n*riLuUC$s2_>tElUZ4]gP3A+ ?D /1( }2 ټnӹ(O,8^i8gL)Ds^Icϭ\,/BR22OsvRGc!?GB&pY?!I>Vx $1_oӓY![_3w6^bI<쓲:L[R )ȩ».>k\d\~ fda#RA#m!rd0p# %LI?MYQa#(]Έi b+z< Ca2Qญe$ 6Z|udP [rls^]OsDeȥ,ZpYY]ˠL$PHV;D!w+Va`GY%hRلqW=oq>σ3Jy\jeOu9̩E@INw<}ΎI 83"HzX 2 .XkPx'NS\|KΦrHô1Q E۶Db>u\<̳^SuH3s'L\~u&,c!r%Y\qMyrGK)A&I4֝Poe_M7SC):tʧvy<}<̂B"] ޻8,&T%xZ~%d[m6khҨSICM-$ RC {F09L4QN (YC'\l`z縇?ml*3;aVž꽞h]{Gs}`X.ݕ ?"tREZCCr9ٶQ$ yASKj);fϽ@lu]NA,q )| ?$YFڞk36tw/(V&W<. MS'u蓅c@7qW(g:06, A}[2Bx<+kOƒhuUX .n%S,֍M 'FTn-sn|#k$y"T宣 .RZ&ZEs5 *z_(G6t@vY~hx eRW:Ӹ**chq3_iN6 G{pm[KR$EAC`!XҳKI#_%F2n(s-Pͦ@uc3< ߗY.r }aImw.8-4w Or+]˄@؏ښVC61m)7ߨ mu3ky[Zᙹ@5~z<Lx,Xں*R˱ ek|CwGszy=2j/?; xЄc1 Ԃ`c ;jq `wK&)d xxH&\$m?3QX/0ER)hBUY5iR s9 yN3:mW,SGr8E}"\2A>uT7 M'CWTǦDí,%fC ׿xsLL pA>0FRiǥ1z,\z@9=QA5IrX~ i]aɀ/=Ư١ϡ=[^Q=p8IJl.^A Gѳ&ZR\>r|I(:Bt Bpݛ=wʟ;Z}*E]lC);52?'a;c Sbj3*L3el"TI'`Ju3{,( hJ)FblObߣpqZO`E*ͭ9\GRGf f)c@ &raO-h UEfhDWKɩg&aאmF5Db&cP8.E\Ɔ#z}$U)<%'y!B268jgEBi)lC峚RwR9g\C.j<*'S?lF:~lePi&l5 Η!ET) [{qr +Db2 mZ7b?2\*,3&TJ /UL(CsU$4耡2G'vW=;(2Cq  b=kٓfr~;W\3ec!wZmҳCxŦέ$&#ŧX:ҥw"̲ڭIF F`+ohQV[q0 E1f:j//&`񤎒ޤbFD?,A`2Zco?D,C8c)LV'.-Z| %gK"%-NUC3!ltS-ϸxv )/.K$k\!th%SņMSk$Ig%ן8զ"3p RdR j;W=i3r9 !*@&pK6_)*tjLTUcJYrL.t9P|~NPkdAuq` &=UƳ\vnu|\[706G? =i@M/ -Z v шPu*j8zV^̔5@0cѢ}Nٛ{; ss\j16z>f|>/iaq.D_hjnOu`d!Jգj=QoO*]X'Qi'xa`S-DY۲o&bRrjѶ*%W,?pU l?i ݦx.ȔqHxHPGjZ<†ԫcHR Ǚ:xL]nnO, ?bލ8%S/rHI0r2^Ds)g _9$|-pSx ~/`}' ܹI-/X$M mPCaIB<[enP*'gSG{#*$HR~ =.r L$_!,Go{}Y?5>y[Ӡe^k1+6R^3:)ي4ID8=m0iwsxcgއD6DNH4&ʓ>VK]yҍs#eR2[&,zWt% |\SIʴi̎P%<J9m HtJ?=Z6B3!}(a't0\tIO%;=.V0]jzD;v$@O,k)Gucg.w`1'>,|&bؙޭIb7B_Sv+J%2')4=Jda壧%BJP*uv"Loahx•VenխN8@8t db7%Y^ƛbf䩏8kgPdʐke?Mǻ +IgPlT8'%,*f[hA{]Cĸ $S~bc\8QGBF^Ne7:o3}KC % H^; T_-QDy9I*ֺ˼a}>ӖS.+ibD=V_,(;+DvvԃFC-M{ncI:5TQe]#`#bs{73AHѻRǣ`W:5t RݏfS񑬡!( #u58:Õ{b|74 2* 0ȊPg[vAw(lo㶰~pE?;D g7bLoc[4J !{` EM Y4RxLFf È 35]?97G9€؇aωo^ߧL|N3ʴ-[jhPqo":okz|V߅6UvƋ PQa8YQai()&_ubm-a2D.{`xCښ ԑ M. 9̷ ͸^+MÂ#nO'tvMڷićeh)f/ T^ߖ*GJVh-qM!jX3`+$SM8uArڛĶct&Zr]2i}-I(9C z ^Ïî@K6$#ԏEu/; <6>б-6L1C\C!|,n>X1m4ZUx;A NY ] ?b# /,%{r[8qt+$l{eubq#ռXCnjSxu[Pb-v? ~{ɼJ $*GK@=~y(U|s5mTsǐOZ 2Jؘ89Fl 3]ye6{v›¤(K (pWW@t|ˍQL8 &$#ݘx CAԬ:g1`E1~LBBZ)6PGzU0Fv%-7HFΓWn;BL֖S^h?쵽JDDDzb*jBiMQ jAuc@*ڎkiǘAK 9x|ߙAb=6H'M+cv)nNmvx l!ڵ qpj˘|&Uf/ 'R{j2 ;}  r=9)bZ{tv?7!d?)R-ZǹvsTgr,.S/mg~OLvf\|>Am_(FHإKStZI-r9/;Q+X<`eTf RBݱl5ןX !-ΜeV*iHT+s5 9eru٠n."Ec9YsPFup{JჵL,Zu#~<jMzh4bVgHik猹@W WƃFEfwqil%˄hA$x8 З~xg#*PE̖(a%'b bT9wժj^Vֵ͡& $bPkP4g8f=&GdyD,pd>wI4N IcVVn[;ߚUKO5Tϐ̐3"Ʒmi9UWmi+2=#BHhDtSRkW5ZW[-/ F`Dn~ I@C8 WWn/D Æ 'ؙQc{ 7G pCz\gpr U Sh@Q®U&-Eͣ_zq)単!YTGdװPew4Qcm kBx~\}W8vBO>}x 6t wea o(՘!~HK5o !iUВ{}i)eRѭ єY0 QmY35CڨHT ]VD~5S>'F ZYkBv1"0<Ss=tG26F)FQ4> ޤAԡ$27Q:&.D9g*[u3o]ڭ;-uJ ma-$mvv5x|#22¶r~őS3o)= %/˟A RNgŹ Olƶ0][dZ448ÖV_pj+\Q't'+f/{}Oe+m5?ªFx~F\O3y7xe+FV ,ƺ>kཥĵ{6!ȋL+͠4uOO^yREG[ ,8³U?3pTYX<#D?͇v:hfғA C~C>}pD0U]ÌV[L |H,޵CO|-"xu%ۿ8̊L ͭmuKJXQ/^%/߅?=M~(s&z7;휗&.e=HE_Jp&ւn 0Zک'Bcw+Weޛfy`:3ćeNӂ_bXL,B"L3A6F[Uul_Zc@~X]1dNYҬ d™ N$S#7%h K~eEh|#6T\}wdi]+HTQ4"l՞ b;YqBZK!r%!Ɲ'%tE!3qT$OGa{!O/&zaK )&6_46zٵD+**IbGcňhK@^<R~sm.@Td-}`Z+ZЪq$MCTw^ #=3VA. s)&xt|YDF*i */fO']痩ޕ Z|HMK6c=5X E=LԧGCjC ˤ*zXͭ!ȡz" ӊ @CHzxܟ wTWӫ-RPrX-ebqG2.t3N*Z/G@C`ޠL~j[S] b!x4i-)_EX'u`22W#p'RFn ^*ɘ &Fa֧ D oŐ/@BP~[{8:K/nyӑUDks8h>چw'w V'ި Qݼ/KtnV$mu twEk*ȶM3},}_!QNƺa$ ß1=Un0qC(N&2X9)V~[u}}(ķ=u$ܜ|dŽԒwP ` R:'Y; }>P.z='I  `{)M%v_eP~H6hdjd|"B^`kR? j-1P˪lXM{1Six^Į 9]^`2uGgȡĥ,+4DNqѾv)fì0rMy"wl꽔lqD{ )^S VIFRmS+軟? *nADA2=_:$"M4dU\}qf!fzzX@ڧ=}ZAvL6->HKQs:*Fh'-~R~lssЂ,^[aV3.吙U<8S:a"E4Fvhp"O"2/Zl,ݱT 0ȦpUi2cR#"w1PA bTޞL$ިE:} ptlu5 7娊Ml)R\uQ$'"V%&P)C^ p ¦IQk;<; +mQҼ#^c۫. qt=*ezi87-QqZfBUѬȒzCS.#nKd)jBZM<K'Z7F>B^lC61Do> V]XrGX>,N `5i01G ^$UEwaMCbu@hs7obS]!ip}*Llm2a~tR" 2Z#rGԍ3=_Me=\oeĪݨ >\:LCݗ|DaecS#`t.VMbORZ%J,̸l8 {ۛ] $0F+^Cv9.y'T)#=il)Kl^X96e_)bk07{=bK膶W=XLOhrNDL ilǞ!ٱt9![r/C,yRiԴluHyx p* ^GMoADVrUjٮ*MgC,qͅc+"tō JOwRهMu\C?iN!}W?Z|_/[g顁vgĦ)>W/qVo|my u[GE_rmڟևj-sN>lBjX772k0YB>/%P>`, Iuؠ&a_ƾ˚D>/4nU{a#ߙ5T*5PVl:~CO=eD)+~hH!J[XঈQ݅;YZ+#sA}wx0$ZoGwV (x21UEkj?&JeCfIɣs`Ҋq#a<]TJ ]\K뼷06nj^@E=i ZV}v !^b; na[$1Tb0Ki.'W<5nU ۠z@ޓws VyD /Pz) &dJgeZy윔jGrNP$G;[ *b^aL6 uX.9a{Oςɐțp+˝-& e?ؼLZ^gH+ᑾ\0;iS1/OtCQX /sp!Q S}d^xiS s&UfM zfC~ez,I9U 5ܗ dh7 :6GNMb@-AcZ8-n ϣqg5RtNwHFZ-S[iφj9,)CK}퍢Թ5Ȉ<ƤQ؟~agu.+N^1=6& 6O ',Gs6)k>df t>_j(j} 퀁u_ܨ]X⊙!_R%$UgH?d)a?Ֆ!Rt.8|TFYz"`.xʫdž Y#6WM(|-5)d_Ij2DnڑIφ%r-C|8-:`w'J@`GG% lY'X.h7h9 'n(CLfuMkUh} [/>Q4. c Tk%X 5Dlx>+yfcI=7idCԽ?zN8@\Q0u4 3<7VK{ bssCss}:Thχu\Ŭ/Z(3&/A|#A2yᲧgʖ=$O_[P\;*@%4;k]5!ݳЙn'5d Ġw,I.w؃ }gcʺ-:Z5*U*\8|)7?ĺsc űb^Ruƌ AuW뚷O'~3S֧Vo[_ҿr 6Z!2>?B?hs8o7LZ;^~`Ifѷ?6VT&LPceVĺc0T{^ov{ U#:N]< I£IP3VeD`2 fw ۽Iӗ6SJ&t```לƴ$W3wflD9,de[ [ܗ~J$ ZOF`uÇb|RSoք]ʯ{֤džeFhucLhrB`рr[z;B\=k#^ 5T;$_jPuy $`|PL$Z( ΗO' N:ͮe5Blֽc@"Wy @rs|_F3i} u:Eo<]ƴpvC /^ Jvūzr틼J(>s:.&: .D(am1QZOM8 YKa~ uf ݡvE2M-7HGcÔ[INszDdyLMֲ+j8E6ۤ sjݜ)NnAsrIiO+ FܤTX'Z+_eL74dluÿYRlsz;aMw⒦[| (Q0=Lںקf{a=l~6jpeo x}_Z AΌe.10}cWdžI~TW AEE)c* ; v!k[PɄo^j,NhH]q'هqbFN(I~NN~IiJqs2`hUfW4f%ԛ }xQ5b1kp]y{Q- -; tg|%Y_l*댊b306rXe9MvϿ}1 cr< q`Z— >cSe!I{uaՉhvZ _]g@ K6UmDYccZ z>DZNn}tF96:J"H5[dڊQ0O?][45JܞsDd W Rd>Xqk!pR3٠vݱᡆ';e)DUX1ݡAi M{7C&&8k*aGPΓ^I#$տiJȔbIlo?t}<*kGҴY~3x.ܢN([Ŗa7F'x"f $@2Q4V`Od'xҩz\F~0GE$>)hX{!Kð#ޢ m2rqL{ޅ :2P..t0^9_mČ\{GTy<(^rZZe/~xlo!a7ۓ&Ħl<ݡ)oQ5>%3ea&Uf{Z Y.۔8% !obS* s-yE!}H}+Ğ'wNeR~k]1 o}mV;98gaS"fc[,jY'yV~/4]|r }]|c49Vr_r.fc ]O$UeGvj 4^PCbkBi2h:Ɖ5" 0->M[DַkYbOkɝEoSd-aҠtĦRQ'2G)~SLCEY[pGr%4DMu}y]fP /zo?VŝL]Rv+{BӬm1~4T=@mJy>sBraf& YQxle\nfcbok[pyR=٬ޡofӳtȋěR^`iyI pot'TܣL?CPK쥺oDsuN+00YvJtDgf` =d%* C)agȫ2w\Tf2F k{]7XDTxp=gGn^:GV_E;7ܟp[͙HOd׎(d!qşyGZ{;oGm`[p#q?!lE=‘,k| p o`|9u d" j%&k =bsS~N:\ף@&tkh(t)k K۫W(ɉ聼Nq!RCcTN^4mqԝR݇:|=o gMY .Hu΁z_M$ aLWahdVc`w|GU=5;2]9 ÷BFzN5 y}}xG{|/"naؚSKaQi DhPX4mR/Y"Hp~Bg+\Ȯtկ|0<_ Qz3$i:$g5Ao^n QQmvOMK<,*e:S'rYPE `D=^XuiE[?,;rO+}2>陮Ә*[vßT5yhdCy!A ek=3}^0M˯R܇{qb)i w!_]iӾ_- Q.MS7{@0C*ﴻw\v<Q @'Ah k`;^2-KUS-v#'7;3r~tiOw54p oW7A[1yH'3J T,$6a}J%b{ mie98ձYAҫkY^/MK|ȴm>]vlYg͇Ҏ>;9χy+WqY3cq6Cd M?Ѳr,"gB _qۮ^eaŝ`N|*z1f=/)Hlek>PMJ ATeƿj縍IYcX RsLwgQĀ>BRK)$Il[*OLj[g4~d5j㤄cE@",Nܶ@vN.`Q>H)}s-#[R++[vw* TqJ:e[CWND;B삇u#C&"oquO_z&C[ʮRѻA@5[|c6&΢Rq~ִ&p'èh(|mb_ ^::T_iuM/>prZJS]ˡθTq?_Gi@L'RK!`↌70,ik$!ܾk@G%[Er-:cCMuֈ΃v`!.N={)x{>{M.S Tn;APK[ `SwcᇇO}H# ms)ΡB"j{!{- s# b1!٨"Nhi%?y?.t:'$Q߈naZ=-d"yC3FNѿGs6U4jy 9ɠ:u`C$ԑdbuBo,؛:t7 RX:ZAqLX5[u ^~ GAs3-6Cc U4w` hjP!u1d('~Nyمj0~{n%}TH3{-#"rƿRpXَ@vEi*ȻA!JGrɜ#~9 P,P2c9c38{{ 8/ə~Z빢zJWqUgߋZ;d>_d۝JNy*H9 )(}JdsPHnփs5*$ =oRi8͖$mhP "ދi+%@3\c6i5O>]/z2BQϐ% ;ާb={=` T?%m6=e487 Ni1i64۹ŸL3kUA{\anȼlm}#[+oœ`0]O͵?KL_wcVuۛAN:T~²0E+WfuW|=HFJʺfA]TP7v^I^jդoVR\f:l~M W2^-Eb.#eC*ZrCUX=r" }cODtOij{#|[AyC/s_|>MU"nVp Y(AAH^=[ږLT[c!K i]qFwrGA5 yd߻+BAT;9Nt~敩;ל~Wc2la8%s6t5*'CJ/=tki;P#GStg$,n7'29*W6X x,?fLh^x!ПO?V,fRe@\Q@^}(тoϾ˰k: өhoUSUSOL7.QԩS\#D`1 Ρ)Wl#=d25WO5$$tP5DsfV#FZыZEU5 aoʟNW_ 0~&唬?t"g+XfvfhQR 8*BAB8kl$g|0B'`uM8D#ݷ")F:%&JXF4N!9tdo Zٷܦㅃai0\XMHȲWJU㫭OX>]@1>9H5:Z}+΃ t37.E oU ͛&wwB{5PE ТĩN˘J%{<:S@'y=s7.0+{b3Uݬ3KX[Pen'ncR~e: QLyah9a.$TbӘx !S3J6XSh 3.zܻMyG0"ir;SEmW p?*JD鳯 oAFr`M]l9cR䙃t]sWRCA e*[Q$UD8!ⓤVu7CGzZΔс7ȗkQYyVШ^i g `_v] 5$ r/%Drh] yTFVI#ݠ [(KWeld+ȁH~7|BZD*pc`tSlq- R8Vh^M;zgO4VsШ]apP\W}yUYL^ؕ۝'_=y}$dn `TݎG;o=aV"M/1'٧ R"}l" u9ꊪ- )O{ū" $㩘hL{Ty~%/~**ڔdZ֗fn'VUI!d+XDӏ^K%3'-$si ?Zp 9Z,͔QEDd9aԸ1Ї]ߚ g7 ~:߸DCA/d9`%o՞Qjd$[Q~l7U ?׊N 7ndquL"Iey:XhO< lnCF/ʚ01̛X*R:x~ \仆EҼF ZϹN?%|R5 w)"XI!cD /ZόrLٮn{:>rFSa8~ :0X'[`bo]"..e-9ط]"VQ<{F@,!NR -d&&&tӍ:ZQ+ܶW)>)8g3? u\C5W\K}Bw 1v9Xh/fKO^\-o{:y ւ*Ks=?^ϼĝo ӚauX5dZ5K=n^献}!OL>j;}jBY'pC#W;u#˰7g t,8v? TM݅CT> >48~7I.ӼlAS/:ոGLon̐Fdu##l+sZv ,o8KGoFb R @y> w~YfGf(o ž"8Ѫ=x?`ۙYԚ/Hr>;>  md>(T+.?9>;N]s[*KIɋCyʧBъ1c\)kV)Uj eu<~R[RJ6ITY_ 7xɳ^L 70dT"P-}Um (29"P]~Cቋw|dC+iڻ#O؉uz>s!BnhF1.=p5Wޠp Eqkʋl|:[wJ#V=*@k3v;P}qW:غ,zi8wq!2]5%h`0DȆHum/5TIm) t@govOvL_BR[. f(Bkb4}GH`e"YX3N6~77,rX}̔ ĀVk n quv^(F6)we(U 0-_D ue+LrLߞ}#d'#EN2 'dlJ/~AUlȑt6X=7[7޳lKP}U UJl|;'g,Vcp5crLLEX7CQ83&h;aQ-I[ղ;ѻ~A(C.j, ^@A֩* :Ї$=/|*ȯmL_.dklkZ Ug1 @zg۔Iό .'21n8)7`~Y|1])< D7+)RƗE ge5:Klܲ᭼c 4e E0^@& j  8G՜y`ߧumPMtj 7 <\UqLe >˥!.t)qш#m ?Prvd{J3C4n60p#Umyԟi'ң ZE8L[4ݥ P gWnQGb 3_W@ $Q%k\/#7D:QEjۻk{㓻`*R%ʥ'kr|57nh> ]ð)L8~u Jf7'vP-J^XFNQsaOq;D!ʂ:ժO{2z%G\A,qɯ/;}ၡڏ2ݪe*ubn=6$k 7"n@t|dlc]FT#$pE5-^\*mix)W}Cӓ:{;yn5 ln% N _;ع5VDu sPH^1X ]Lgܕ$y '.yO!j=$ (gꠢ*k˄@qZb\mәsD NYU#W6g"NM :IyFOĂs_6i7n ~l@VaV 㕯~\R3]/ +\m [F/UL]u2`0.k8&U҇e_s#)2Eޢ9V!OQ@A#VsZ6Tpv:'(iR|]pRUֳd2jD%T/U2piY܊~#=PS&7=5" d2;iˉ C켿~K:{Lw/1]@w.HZsDaߔܚdV{oK\=v|%D&AO0 P"~ہ Gc`-mک'fexzeYL}ź*f~3]wTd7W# U٠nY=MovFzԝXD޺_4cuڎ6ӵQi*"y~Z7U*>-} |o5H>D :L8q;kav_G?j }c\MI wmUʰ}&ʂn\hjbwDeً9K¾wiufAڋ`9;)iM ۧ‰p0q)7O3-SOkbv)A3{壷#Pva@W3o8E{evi`Vka D+:Mw{$LД#X3C!0zc7י&Rkq Hj4a oЗu&y4n-?㒟_ /^ #8~]=gWY܀}s?;Y@mdǏ ƹ=m%>:12)7yVb C>~Ï$q<{vRJ G/u0|fa$ONs'+<ZaOqh@S质!v-/Gz SbdK3NA⿷n[rޑeL>m\JaX̐"NAcxyr4Re2tJZsѨar%g2:*nnC({ќjqa_fLkqe^ZM$aP[,$$m-%\4^֬]}VU)zcCe0]V(K)[yl="q~EBw 0|w/wT>fAk4!w)z^0[Q:;Wo]|+4I>DpϢMԧ!ixh Ӎ9:ۚ)t%].ڕ1Àn`MOKF 7i. n:p.s`WgP]~ks6MzѬI*j+-j VcxyJFA%TGbQDLj-OVc>`5%Bty:ߴ(93vu{T$=c5BnZ91esE(@]BR%u'@m[$^,y3TYL~0|*h2hNzUx >ct(|>~U^X?D ],.9ݧz6hW{Oa7DImG>8'nA_Vr| g6m^NuTA{فn͸v~{8&$ q &(n[s'WE=GspVfOT Y rH^`CDf2M HDNPW.q49Ox4eV[6~0qR\<]Ԑ. 5#nw %\PG}YI'cdRkQۻ6Tp<>myOԗ7ŴcQXZn{h;N*FjN&;n4H {r1MzC<H7LKz3PǔS.B98#xP[KqJ< 90@ds)={D*+łC83 Uq鬲t^ pZ SD3! 8']'U4AZ/fC)YzHFNZ& u(+S1xfc@ J+x+J }Bn0O2/yl}V\eeP-Ф\vo:SL[a]n 144^]%2!3 tr#mWپhhE7~gk݇4֪mvGG>ybbcO <1OboQl0;B\CWsdJ9AF irZ5+"l; ^% w_KQ#]xkW޴g/@mQ fͭN~H1oS?1ۅi5t>\s9r~QUoW pŷ2i/'[dR ~L*$^=0lAo R_oxNN61ڝo.'Wt[lvarEHpUu we r,D~3#Z\f "%S׊pI]T Nz⤡8IoRYGR5hXv rEqa^\LSw,iCeeҁ@ ]j&r i6'fyh!5-ؘayS~ᤊ Xwvջd i_G\>!gm̏7xǝ,oERq ugoMFvڲV8QyT3!՞)Sı57I6Xu~0~xȂun< A"Z~`ciUE?V :0$`ziBmPrxC P~Wq- uͶbH[ {қs yɪNx~Í` @. )UAVxk!)V;{?^"o*>2 ѿz&+FT<ʂT>r9F$ ƶ䶩$L*F$ /3Pu^}K>ӈBi O1e08=6O/JgR!1 a$0%KʃY fIrx6b(!\%[aR%QVL / YU)Rnџ$]pCzqU)T[tO?X.)VbRכ2KWLl[ڵC_/$51.jڮjڂF!i")!7fDr5`허kh\̫"^Qoj~yZ')h(֘yiwjxmRp/OEY[=H%j/[Ut85 THr}X: qd]x]#r:*iHFvX}_"͔zʎmöE@+,R 0z&C:rwӸթ`k7})2D\[T-AeW GYч9I=+ 5"f+63ɓmT W2-Fߵ/{FB:<Z1Y*ݞ쀴Sb}Qݡ!gtp9%ItߞWr @;[fAO0FWX-|l )(T`g [|v %8?цRz_eo Б".Xr*x,SP :BNWbDW6y ciR#>s5Ýv%,30fG" * B + 1"_F7l#CEjiO0VFX=Z4p,Dn׵(3.ސ3e+3#SȘ>Ĥ{rd l~GB3Ʋ>Xyp"Tfف7i~WgR5lsJy&$ ˝ǒr.׌o pmmĞw&u#tQTB|{?,rw4rc 5#RyL ;J~7ZO]*u;+5XƁUqSsfR]mRel3wfDi aaI~tSߐ0^=`)&Ѫ!1ʥ(R*/zZwtK_#.~N_e1Jal,xF>8z:VjVM=߉Л̈́kgݹ~:R{&}"c}ڈ`RDW :lkw?N丣hV(ݯ)F^Ҝ-`K9Wؠ- 7ţ@%^\Xi8ҠUEAsQcGq% 3UIʦ)w T? gYe3yu0S/bf2zX j/7Sf4*^6/1;coMBbg!?-?E jՠ 0;4#RO!ɤI_v9@qez.\2Y{!u2vu~Frg<Ƨ f]V.EӾ-V|>ܞ8FEhOWV5ވ$CY[K~"5:*"f )Woؼ7~̯ug[s]ZDBF|w4PS !skcm-uPQ;fQ,`">qZwC$w?)k()I-jIdn_X~H0vh=vUlb qH*B5k-!Pr"Gaz䖢MWGʳ/?1=Lh Sb|-ݡ8M~qȣ$cu]g;˔`I& 8Y0sOsPQN6ҹ!ѬmO*\wxzr78mnXVU EMΒwvbw?9AB\ҷh~\v\9CdVN琐-Wh#h||6YD ;&خ-3U-k'`ST@2 4 ˼ Ĥ5JЬ}mVnq}a?-Cь^dy8찡^ YA";  أʇ(|/ ر 6+Pc^1%klu}TPQўlLl#ayRg)(l)WD=6 }l+>sHs`bqe@9bGB&s' c Գ?zIKDxP7䂀vs eZQi@.hTQ9WENPíFWBf^I|zIZ)arR[TOƕzW "dtc4mgmDܺ6FR,ҫ_OzKVo=p&SzIa16ch*8VJRl(2*n#>R| !Ew{&|3CcBlvz˓< r! $]}O*zHA <ӤlCGUx'ֱ W\#d_uj(Q׸ :ol#X[>`iv{7ۻMq6qWUz: ᮕc*N*VF<^%G$ˌ5ӡ81K'v/CSR;kn۠|#}ÛfNr W $ Uu~7\inRnL Pa u/:לʏRs_Jy[a'YhN4lE;%0?JU$Q\!s ޣliB[x %dƊ;whTZѢ( |ͻ|l՗'tt, O_e,aMMxV*k[+eugO Q 牉JK]nCzcM#%Ō_WvO@)hg e\BͺoK bU%E?pֵ 6A_va= WD ~ \,@1Ștv#Jty4e6|菎Mua9{6K A 1& md_aT~1@jYtNCقɨSs5Of .VUr(s>=e J<%QLݏBp0248%g[`v]iر0Ho(1[qmXi,ً3?*ȶ bd˗8KB3?CGߐ>^ͬ//E@~<) uf0`Y6[+%QIUN !Ȼ%69t#;Xe6z0D |<2ԣ۩`m'.9EK$vKL`1"ӉC?EK{  %, xd>'^!0EZXxT]7p|Ͽ4'5flX8Fdf<Ƨ型)ͲS8]JrxуΖ4摨%S.[RRWz'I{j4I/o৕{Vg;v΄Ʃ:uv"x[f&UTsJcKzgƕs3Rz̈P6П;<ᅪ:c\[PECD~hkz$ ,Mnh0pI8׊2 . vӃT\ VC W`[e}TMiNJRvIM}j O t5ղ>#nHxyI+}_5h n.'Ϊp@4{ CǕN76SS Ir^]QpW>]Γ{RXN*fXr毐߭&o| d \"*1۾FE/Xl1bmiX﯀Z+#AfyiMLtR&-e}Pu) ehY@̒˕AsӋrQN֧tD)*(/œ PaǾ3@œfJ ('o=U*`(FW2twʪܹDBi,Y| ʐ2DG!aUoЯa|^ bY9'Qrn rѻvZ=KwٿVolT-\k-@/T!FtӨ W(]zgZBv_o0# خ${udr#`nЧ~D9wW,b}@#Ңkl<ȗr*\X|M1f?K00I"@ҸwHӬ6& I.kcrnE e* d(;-ʺj&465;'_~[N1Wp'oże]TѦzX31!(pi[PO'd W2fv.7dtE#5e #.K5ahLW5x|sjDPoL2zߍ-{\dWHWeH.%/Ӥ_ދz{d d"bu(ftx>89F?t3Pv PCW] -! IoqFNe.s%sU*8͵|{HØIO0\Ma~-%A\c7V$=q^Ӄp`1ԾxtGOȏeozY ) Eױ3* TCr6XL(~ݶR' cAEX$;ы4`&?92{džl'*wthsnI+J)jcU2vPgꩌ] v6Ij+Nj"ǠY >YT 1VP @8l32~Z(;$a^}YƇ 8(ٯ@ y3d'}@ ,71p@i3OS%jA j|#U>$Kpn ^i.=q^j^$Hi-qhQwC/FוP!dh0.5M ` U*.~ [3 fޅBcЀ)wydā&&7P6X޳XS^_qg3%uIJu; $hջgwsqEs9'Eo!ڏA77[A> 2,6#ow揘^ODڶ"_.لd5LЉ߄l'+MEqEX5Lx s>vLWlj뜈gPYA`*VPdB@;fxQvԺN}cAZY%C#46OnF0nCI"13S9r}fwvT1=ӧQӪCY~MK\к~(!#Nc}f7 rr$ԤpՒ(9G9R@Vh1) \gyA" Vo w?*\8pjz DmmR{Fg;_ji(]Sڂ.!ƙEɇL'~Pw E3oVrl^@3ZQ:Bm҉Ngagz( l S9Ҋ?PMO+5vqhnE+'3cϰ6[ihʥL]7"m$^5$5!5I,`*Tlf>L8={t؏©[ZxNg~87zsUwx[f[+oMB"{Ux392"jtNeTnvTN(X]Pvx\̳د M rn'iV1,% R֋޸r=&]`=c`Efz7f}Isz_XoQ_ JJC͡ }ѾFp}CpˡT≁UW?8 Y. ukPdBi¤ǔ Hts=CJ"&{&@;Y)ВVYyI^2رz7Sx|'Z@>Qw@I݄eG)7%~<ҁ3 {h[ rXP6W(6k!6DښA ALڊlꭞ?n:݄ZmWٗ~5L3~AbfXϋۂiqκv 囃;]sS:5 $Z՗ #=eW>|IAӔ@h`Y1!2WCt=^h{bKYKY:l\zy -'1V"W VM{{t@UfFQ',"_NCLb/S^\Bhא'Aj3vsy=bSRgu'ž?CM@Ghɏ:$`D>HBه[;bY%;n+ɻu=4SXca5}NgLz3}C>v #10-Ic\|0riTҵpGH58(Ki9ԭm*j,6#ry9zcG ?U~h(bUhYp?@Bt@Xr@:ʓBwQH (ɅM[ֹ$+zL%sK$Ao !dzBWM\ɢQS?W E(t'9P׻j- CMd ΁5.)"{Ad+t,oA/ U\|=H{A\QGbUE_"jt`SJn CXzScdaIcu[2#j#H8P^xe֠[FLւa'e6fA1܅wd_rϸ$/a"0;+d.'NZCA< Hqf&ȎKr-7_Ǧ -Do};R%N&SqFv\V h_?E$L T]]/Ƚ sNN=~[`Csj3ɩŷ{Vk'Pqh;>OO#*шLc .<]qdUp:FoMQ\!HW\>Kfdp)|oQ5ښ@`Ⱥg}{!4-B q5b]215-9q$IQ aiJ1+Ҙ#:VGnº^˼P#$;Ik:"d}I!xI>\"Hx#B u |~9բ>ά *9c3 !LKSK!Ml//I"fWB1֬Mn#q/SzRuS[%UDsRb}e*=C/YG̤)}Ѧg꓏g-I; !7ƻߩ W/;O,O;3<|1FAxƓ#}׃:۬^J` vآlYv8)!? TW/{.-1sY.P.EVM[6&|G$iqC֚1"*?0jAY_3jlc74l F g"8L89 >BlC+ڊ]^0@}K:5n| ^I0H@..d>Y)X/wڬsj9ƌ_%'i^F@؟E:Xy>Ae >YU_5مnIյ'aPA0b<_v=kt{ϼ<"gzMs٧mPFs8aC~Y*XS[ţGF'b{ؗ]n5uR&}Z/Nk9żmˊH)! M$&"o5ljZ?gĤ3YM &Q"=0;eEc6x$>KP74QZLMYf$۔>|Q'[n\1cWݤ;eR 56x=v#RP-Ge2tP'fFY 5 Oy~$54'F] 7w)ꆗ7#H[6^fwJN3 ̢T4$)tJa:A c)ݲ5=L O*O|IR96j9/vV '%@LI]QikKc>t/̜=[rg-Ew;3EYA7֗[|nmZhrϭm q&yC:u` UzǖwЉRJKG fU*ZYr[;Ӥ@FJ[2iiLJy! ~'Fh{.x־ ҄n }JcS DHAVsUxv,}"YJ g ;#m,Htr{tÙe ,?ITiU1o[wFDV*]J o,l~ss ߕ>mZG#ݍbxGh[T[Kb'Yk{)iU8\v5#bmJ6Y:jJj岂8Y*ܤ@*!0cixCl@]@w[&%,kevx)Ejly. ojH[6u!E{d$HO"_ǧ5Rސw\jR*<DJ˕uZ%1=KNvuس࿇;ٷC}*Ϯq"ɹT{ֱBCK}ĵƷĂlu,r@.i-lp` Rw쀌$avܽ0dxSpG-A؞x_YٺjՓ:?ozCuy`Tey:HTh"֚d PZ40X֩MwՌ/0H! u4 *(Y7 @@ H!cԔ^ s}mP *l#Pi ~- #V,qĿw2o(9oFһ~rпyd7jC=lLϤpglC~s9s*Ymudm%1 ~ur3!Єn)it~_wò`MxL1G{fAnmsi^L\ݝm TBrʍc@Ok 1^E˛1O8~zU8fsOsiFFV8Y 瓙zs@#Ȁ0nT ԩqXc:DnP᣽~D"Jx M.3%i\kh\bjq8qRhrʙ>bᡥXz1Nc_ fī^V7!a_S):~t!8"8X&|L )y^>B)tE'>Z@wћھ~'lkV"񮇔gf&j' :6I"ZpOriN)}#FmyHKj'B-ZyY :YjE7:Pv鵧xKs_{ѾBsDh nW  d)#eC`cXW\ˮpචJ[o_sj|NUwGxIBMfXVz=POy_M_!Iإ.YȘ7h )>0LrRVʥEj:ڎXr./O2(^% u!~Yc=X7vW)'RyhTAb_)bM@,X<{Rl @9wF!882~qK]8k׮ŭlbxXZ# U\8[Oi0ʂϖ<46&|*"QETY16{o X?$=ܰ`:Ȥ$vBf(5jℤ~SOt=HSʻ?4WOue<9E!911PM:`v/?xY(=fdֶ/Yfz kX 6cO#`]E91QRzF+|֟:9ZYhCV^>JO.\1~;Y2&r'ӡ|ȤGu_nyOo㡤n>%W0q7mŜ- &nET"S򽃼۴gl|ON&&eECߋMM?!,@Dz,sgYWEMa:𡞶f=:%/hpԕSLnFTN${4@ l${ R]ϣش7ϗu0jэѡ>r` s}u1,DL14Uuhʕ _E0Gz4B<xi$:q [uP[%z9M@'pc1@sIF}a%9GdZP("^750T؁&FK:{GH(if=:g"ڏ"j}:ٵ:\8PG%G0Tk>h}6< kg `=K?46YX(2G;%q-t%9ܯԚ |?J+[A$Ad,s+"E(@fU(s*E tCāHW9"ru R~Bok4}{EN"ukP;Q b=Gh?evdU+vZq{d٧8{,aجAhZ%6ZU`Q.L +p(j*/H$za?v}O;X DH B\~H)sDDÅpdeVWN6VRxts&%_iܕcδ1I%)~=C =\y^ bͰx5 I߃OnESe@k*^YIʇ0n K%zYl::Pq19(d%1J}gv{lC]IHo=$CHB@[[*)0n[[]>ъWeUF-691g#V^) XH\Cjchyvg TX8x~E6rxj_{reEE& T+yݱbq1!ۂxZFwn񔱶| J7lG E@S(/H[%ngKRzr=`Èƈ҆XOlJ[δڠ[r-fRĭ2t!lk+0i^]ߓn Ӄe!j`Dv.a 7d.V~8B v9GjE.әϓct[,s}F!iDYRkDJ0f!tMŃ]~?}]͈Am6+BKb仙^U{}DgJl xR9UNqqg躲+03dIFjN j?z]'M+WR҅C?lFۼ?oc{%1t]ɒ(Pܶ3,xEw/&fɫA@zH*q,A@Xf7;ˡuvoLezu6OeD$S)$Hm X:IyWpz::/᜺L)i$ˤw_edwX_ 15GZ|*a~ l_6=[so4g< xtYnz}=ENMwDG?76;L0}9g(2=d)UXckhHqJ9,Ɨ;Ex#Gn4TII:Fť?N'6(W3'TAq\8t +lDGqC dE\ |kNtrA])Z*~GV|/{sMt>2^f pKb  iʬxÆblgI0-]q!|>plBq~]gM7D㘤@@d~hyA-h aT*/E!XV/L8n@г+=.LjJbb.nN13Nwdэ@LHכ a:I)*kRb<l~U4MdZAaeZW] w6牶' 'K^x/;^y-?cRcn v5uëuHdR!٫; `j_G՞M;Vl`֝vOcn-xL=+hW'6zT-Q.ڂ0a0 S`W}!(N[@(ܨ$;WJAYc׽O*֧ʗWsgh&GҁF$ }oW8f՞!{p \P |-~#HWh?!l0)<ꎐUyؚz{"xV 25Xhk`)hw` -i$;u-{x]AjP|=~Fk5 }.`: ^;<ȍ +s'v'n&>QGB_;60cҾ*vH%6<˱w"` !W/J}yg3rWFfbTNXXfуz⭚Onesm#!c,s^Al}ie3 +dL0DBnUT 蛐iP+ڳRO0WoF%C+D<{bU R;$Pܔ+i%~/Yo9IʓG(Vջn[KuesjvTrd@A4ZiQ!ϰE< _*&͂ruFf0UD36LK'nw. 7ɳ_KsāRGξ!zg-X+SRl~eM  {.C;=e$9H#,Zlw*2J `P9&+3a!I)EAEy7j\:M*`{7ٝ /lΩ+Lo7+{ Se3-c[&suls]G gn(/H#{nho1hdu #/ę*\N)>쬼#?'îTYyiapEۋAU +swgB[ov.+`j*>P!{đWnw9>D"|w(KAo8&IVZqE°\e2m7@.X]R prfF8 : ,uEC1ԀYU/[Q( nM)UI6w)%? $uzӿjhf`0wB H:K /CxX)3mnMgKF7[;­+$>$R|ݵl뎾@G{~nc֏XQDh xpJt?ZSP^]zw>6 k#D1&DBgݖ6b>o{9,k廠Z{ }8TDnOu%} %՝&6g> 3@#6"jj`XqvC!ZstrT_ JO!iOHlL'3z[_IdnQeL߱nV;8}qnpL-綠XfQLZ4U:gMdh\%UkIt)tOonMWZi׌zKgP 3y'XpSEdaTSN@9oy%HՌ'Sӣ_=ݡ3L&J%Ge3RkJ.<FX0Hɔw]X+ּZ1{4Rc_z;;@?;qʲLQtKaoۼnm:PsNOqxN^6[GRÄ1'[=247 x[$`G׊. fu#~~{ܟH_YXO`jۂVthGZm v7cMfk鱑=QuMSwAhJD 4?QJJVv#x/O*3xT1bY;.ͥx`wKWYxMHv7Z߻lWv jF Y 0wB%fO;UmB g>ڱ@#kqkDy"$L:`S'%_x8B]EceTɸJdwau^j9=)L'Ӝ\@f(١b\: \oKtvU!_Ccbb&]45Oͨ:o'Ȉ-{-%<ѠtpǕ[&@j:!Eag.P}uvƄk,cI(`~@Gc,!Ȃ}5< օ#u*_ej۔G5+mWE0=vABDpaDs19 rٔ )K^[58-IBH&`ᄍ+'賱7Ni1h.w+Cc8!(cR̕޲Rp{6ykNw!lXQU$ pi䇪uLuBcY/8Yz$8ܙRϡ-oD+u]Z95;BIo3ꁪhV*V(I Y7Rq,-`Ba>WQi723W7]He]G ˑΉ$ucM $0L8r$=l7|33+E*3m}c]SHt .fUKVl88Xǣva<+:qe": nOGpUoRY>J6VȵT30S;44aw"`6%g7Bk1&u]Vx,Ba:p̦5%$jcRbtęUPuzqq+%<] -}FrZFi?b,(~oD Ze#OEl9er|7<4z0Z8!1=@GqK@n[+}hKm҄lKF*7aDCuxH dT+3py!]5PŊ+b6~G0*b{k{8h0Ձ`';V+f( @W<-uYZL_b !Rd?Qexs #%$ ;xTF ص+m#P m;c&Hp:(Ru%P4aRDODZߖzK i[Fu}4{.b7NdF]U̜`Y *E9c{P{~YC@݋QD3a˗te7H`ĤcZ'z|EH%ĩ`z{Ke:q bghܗtOlW$ sdqF̘taHoqc58|oLxm}kn+ti*5qjq~I̲-h!uz_ M0 E0h@Aל٠۱G}-lftp#)(C!@ ToڹX]E++ ]qj lb̗*=U%ePFrpq`ʤ1yp (ɛ.XGcc,O7eN+ӛCpꢛ1~+>HZuQze8[_c /[ɫ?7ـIGaSw0vxNgq\߫gOBVQawj:jv~UJS+ڷeY*4q\-U'DU9PhEqvҞBR`Cݷj.=ei a'"`tH?uYIv0^ O}#;Ŕͥ.[8P +hMV o[OFO0!Ť6nN~̻zކf~['#fGN4w&&)ҧd0vYO&$1D=u.l=MsWm-֞˩9KR-f5$iB7A1@|.П&0hJJ:<5#ӯ#;p=GP)\|{/յKJ dD7j{r߳i(amNQ}v.i8]`]吝{آ~/ܳ3npM_y @k Da҈%Ls_>KH kYz$du&têX$tp#зY+k?Z5>0Ks~5aևlYVMZGŬj2Ry rWqN+cp~I=nWv!V 6tN7/RPhag`j|ص:j13HQs;R1h3-٢tZ?@vz O&#Vft愂toi[;Hot14BRfepź5c=do8:?Nf^XȂ",ތvs^q7ԯL_9] 2C0\ܟ.B_ 3ߑCF*>K&wP ̴_)md/aR)]06 : 4|%}0/ ]75hpZos偠J6|p6[0[Os u1^b!a[SU]&Kk8=< YfEҾCzE y¼hx-}kpq` G-[2 B7z6ѪUYjQfP/ڼ-z;@6g)Pu[l;M4gXCCp;anǣ:\Pkd7H<e˱g.<ڦ,H: omqS>\u2ubڀ'HiKb.@2l SL'%hOfo4R˚w~= yZ FRϔR (K.;m~j=`ӧ@ǞLn{tngY"X>TR&To:ې; gL׾ZEup1329ԻL1oj4}qAb{>qX?r Z0n{ E(IvA)q!(ЧdhpLIP0{M Z= GFz p m|un4[~X֬2eF%YȪ΋׸W_[ &͇SMX!4՝A( zuG5xC9䥅fv^ H;I7= ɹ7gJлǟ~4q/-;~X[,I?áf~ژ(~&'mE=>A"/ޏC!DeDfˈW(Hm씚7QWce{;eAq' jW7?g"?.kӯ|ԟRՙ řL+}VU+;|ɖ-HMmA8nA㜻>MwLX@vϿ@SLQ)$cDqx$+xq0LRz΂gmkkjtWoZPA@I.S'o^ ԧZJ,ocm5,tv7؄+-!,r LVGZH4 B¨%{0 鰄jƞRP>{Ǘ4mI* ;/.f5U"UkpL^F9h5&8syt: ~5Տ`j49~K%_W`f&; Ci<mv;S%?RciNC#7ją_ az2^PdLr*BR5@%|g*;F̟HZ_o$,~Q'eLm8%ӢڏޡI1Pe,VpH.U^DH0̼~}zoZL;'n3v,b/%ovߩ%Kh:q]<| S@ؕR(@CHL)H6~,Kߵ&/FɸOh}(AZ ;u+Ɠ` HĀ*#QV'O qJQ>'D )W Z^&MXƭR͞- TU5 ${_?=^5Kb 1J~ шyk?EcoW\" 58/1WZ1)^T_ ފckɘ_56w_t ZLCfLh Ęf;Œ#5atձ09ػLLXq=IFƦ]d]%gG$ >T+Wa"g' O]RS\VZ5 Zej1jpjA+uj{`2_i) ,Hƶ_h 7h`DIl bar8ҟ?tu0a+QYfN7TY81?~R+Wт /ic =SI,zJBHwϑXߗ&;T2ٵߊPS|/RNlP yXa@!ĉ'ݨ%n wq Q9T>rD{>.03ahט j+nJ ?̫YaۖFIFʠ=/WP)Gy?TG.q_h؈)IRW.VI^}R2!%dbjJ-H;Î;:[pv`lr?Yҗw{Rb~ɟoE4} &)gUR]ֲ$nVٸ#œzSDE|)Lq~B-i/K@$9;..$w_9;Y@bv{YAu(q;GU]Ѿ{ҤVU{J6 -'{A8h+΅ր8V_MZeUo*e`cy/̘h=· HŸ\&%~w,S;C9vi:WϿ\sկ<B YzCuB{FVJ/)}o㜗$oɃ>]ӯ&+v=nN5aq!$nBmw/Hu"nk2?4M8xQLϰ: 宯:tQjvN"*Y)ңw5[Q)Ɲ b;hx|'TFwxc}T+.g~`.(c Z!"^k[تHN[dhcil#@bM"hV,cB8Ī5؝;. }"-A,9*Kf^&Wb=ƍ!7wz[?H}DcvnHm͚~E-I`L㭷!&:m'j VY(^,S V "5{ar!AÿDC'qbV7KG|%G<8_?,Jj';H*=ui'.Ru󹆆Uj2x.nt)SB\Q7~oLlͿ,jXf?ʈY|9ó)~j+.ANdypWZ>6 r{cfZDF5͂&ی?$|&7)=Tfv2YvnLsta03,U;Iepq 2*JD<,'˯ (u;,Ôr, 51ضYM}λwXL !7d@ER/,m oZp`#9'爫|rudxWAm8r'=4:5='}? (mccե9wUʈz K4h=X3Q?(ִ0PL nmU}i:Mz<ڳ]Iۗ)~ќ 6մnִ;*NabqûX>vVǘ$Fx$o|r=Lc[iU|sm5T"+Ma\OJ7wz:vF<>$q:la\aCL.Vԧi!usG|hAׄ95J q  h^%AM\@C<*"CߛFAdk0]9U1>)OmK=Bz-1Z'K!jߥ B9߸!XJ^t'[(6˦(&GQ̤XVVKLy9kCR4:Z1';BdI5̕沮B V3V\]G ::j6Ռ^s0.K{s^&vM~WMlJOCM&F҂FB57cՀ#QSv`+M7?&o`Q Vd2gkPsR}p^ml.}mh4:za@P~Fc wiucEyb!Hy4#gKߦ!'BFUǁ9;=EqX&a$Wsk1փIOϋyn4CU]ɃKQST-/g`ݶ <|"0|(_?|I۫F˙Gz x\MBF]r)S!eS~A$ 1c okS^8E:r;t@t򊖕F\? Jiby?>fyuo;pU P@w:5~a @%\(.$n%,i{C2-Zj}\C+#mr:5,J&,)kMQ>{A 9&su y P*R SqM䊡 ξ!㲤ERkߌ=ɫi.c${Q9zo=;Mp?OpxLؘwA Do8ntƶa=3ThUnZn6Gz;ssj7R d;R*G^[ g,+{ωDMev kQB41pQQb1þOVm@j'Gx#߫5Hޅzb{75Vo|9uϱ~Qs8+#E~y P~vޡQKDg{B^ɃJܼB|VYrvV\!`+"E`,/?oA}'VtǢrXTj{1N^LC9gXeaGLIuMHXq V2*bRr6|i+,?l C PfKq!ͬG|ȕmj9`gn7֮"oE :rr(t~ZM*5՗\ci[}ЮZuQJtPd] ktiJcBIVN3-}R"6s`WPoI-SЊD 05sa8 *'Yē>ig`~JM ǰbhՋ!2ɇ/ Z $㤅 )2h\>M3T0N5.bûh*9jWw+]/;)"JJtPȮ|+Xte\H9/*Lu/h.Xp+ rU ̚bEJel{ȈӔ5ȹs h#Zγud89?*q9ʘp݁JKeOӉ͈-X?gЦ9Qd#箂U@@$TM'sq> LQ ƘlWvKZkBVN|uR;FƼS.lXi(g o`Q{|5V̑]9zIAA]PجtGE2 "?sTA}6ֿ\++ ۩J/  4@B=cиGkm,t%VDY+crxJ)sBq4BK-7c)wuBݨv\+$XhS`:c/rL#r#(\0\*g"ѻ2nؠ(7gΚ|a!~ { mOC9U2)[w4ȸSD݄PhСe*V݌$5 lԠ}_iB1;<|Le_ZN͸-+5RF|HMJ[h+wuT0i~T#WmktthaFQiyW02e5M6痜K`[RyxVGxsu(؁ʁ!Lv@ǣʧyT؟ i6C# !5cdm&;<9wMp*g\NTv ' @0fXd8648#RS#蒔9_~꼞ɥ\2*g>.w0iUJ:@Ae9_GPU)$Y(*'d{ Usb[N=b(Mҿz|wa Kdz(1E@dOVM++U qvVx@Ŝ s<"0k|]jST+7"FtoQj­g88[ $C1N!!ajMX-[kʤ;KwM% ȫ0,e?9A K3 Mo5G!o&ڕʴ$w8Qvkߺb= ;zN^ˡ{ a.flk!t$jmN_S;eD[^b,k9au@-пxDR,Ob*bZXǍ\)k0h_A*@~^]ZTiXP5~@F@'!q')k(1~_x\;N%+ t ֦uݪ ߕ0(w}Dgt@&.fCiZbNY;,^C%O}BJK|яܠcmBwmgܦ:C]۶[KTlN0 ,S'鯓T!͖ؠ;}!"F+T/[xf66[w15Mw贛BM鹄X`ɢ+[2+:ڌ ~H4߻? GOGAΈ&-hs[I2NqAk?<*Qѻh-ϐ.rgkxµbnyy4jBߵ S}1ъs9Zр %yB6^/cXѺMlo$>L~Y3쬖qj.7>m4ާ?b4.6i>`<.ƴ4RC&iҿDly>*&f=vڢ ժ@}]SK5Ծ sFe.DVjU:>`LK bDh1Lf Ik{QI%XADx aclEʼnV,A?=_pwg:$Om-cO0[g.u@Qz}mj)u #l΁${늴Y1zB.Dd;rsWJʽC-%)$)TD@pk ľJ$ռoȧߒ-՛(c/Fb6tN`giy%.3Ta~&=5i: ZEY~4HTo-8k3 䣎 E$sچ"_{l0J"Ѕ50 P ɩzGV6hvwQG شmxܬG`y*q]B_M;(Mo6]kx{9'u^Ez+3MS>_,e'O7p#r s$| CJ7ֹzAH!BhuD?S6ޙf rs;AicʛK1t*X6֊96m\JO۫3b!=oHXh _ $+.<X v!*J~~f*sJeb{1`lu !fmiXOel!^akA&lyF8hrZ/1l'_k_)EN*>cE!ڨ(]^4'y!˝B qD ߘ G-{w8@%;ªY1fe#J_[q07c"VS%UpDb &iWp!]9FjG2^^,>GU1>ToґbF}du2|0fH Z ;"av/CQbXzAfJIґ(> 9MVD^\ Ow而> #O$i9Yy@I@=D|hy6Yx5ǮQ_3Iw@I j0OQ {nQ}Ѫa  BLq{Z0fE?lH M= mlHn1B߇zjUz[[ᇓ-໇m%¡a5?!HoمFQ) oϖڹH@'1dP3Z.b\F9o ),1/ lOKBB{W1pLޘ4#a}$&87?:KAe*ahaRlg-nq B!>1f|e9ἃ8ڮ{QZ[}=%x/UFg͔"=Eg>3ybcIl}ǏI4⼎v7Dya=r/U?!{\76wYH`á^S]F\D_2MJTmvP1]y޾8YtP=f79Ot햾܏~es*MH ~D@3UuivpQKd'3y^ HUꋙPm s;Fϝ|67[*caxVWqZ`UA5Gy )HdAk:=iYvDiRp9 /3]S[Rs~Cܒf,rB{ViYth2IKH=֦&f"+b-rEa5uӿеװS 5[qzmԊT=Pm!)*j݇NHLP[?f/=V#zTq4gXf`1a=WK")@+ -X(lt]2XYF&vCO1WyJ3r5KizQ˓w^$w>tK=|#ػ~VNx';Vgh%z=j㟵i_/L+o1j{P-᮹|eF4zuaʭd *uﰙKWKlV`> 7cqŁZe㴼W%@2j2o8e">vݽ]t7jhx)m<BTc"c$<yuEFZejMXswK\!o~A'$ȱSta)c_2ϯIB:#VƚuEdX;qe3w嬷($9{15:ϖ"CO@fEU@HUw"]Y0uN_22_T5¸w!!yP;]H,ja"%6HTYݵ`jf>$ 2WC[#F8hGG/wyp;`Aq5Fn"lueB$G4Q^׳E,:~MJXq5L$[e[ڵsP&h& 1'6kζ%3ԍy,oݍCq@fcxkE 2@y: xe|N4N`>;Vs-M8OOW@+gbP.آė#[.tG9ޫn+UMT"i%"~=)EeE2G{ D5xjZr$v3X:z4,դOh'OṔi>R {XD9فatN4EaآVI`f*-$,A >x@ݳAbwuވ91!Pēn]raP/xw W[h|=yhSsΚ~ˡ~yTq=-Ikj՗Dћ;ȝCU.ޭxW8>JJZhzE8~ɢlorUo@X9 F>ZGs׬/`Oؕe˔(!\Y Fh׏)Q42H$^mL+ TXVH>agmư T q%A7eE<Кeϲ.JxROo\su/[~f3;m_H~ miuv+ݒ^'ҋPlV ,M9zZYH@IQ;c(D`=)!kj򁚕&w-/;&N=uڎ{D6sAt+ceJPޅ:2B`!siɣ`ܸ_v,+s؊_EAv;Hjw3!u|*n#T14u []Sb 06+3#tdbz)G=^0n!J@S:w(z,zBX^t߱eieq44UtKjD[LY4ǁ9d/@$Pf 5T8ƛRbȇ݆['*f3j$ 7 ,mb뷙.4 抮) 'R u\rcv95ff[:-*@9}<4?n{{e- ¬z?"pRWHd"J fʹD1t0IV`a~ ]x%, a!!jٱBܤxQȷ?SỦuI JSk./.%:̃?QϪ ϼ9zJsTf{S,K.V~ ':OdMyb_;i7aocVCuG0@HCY-@S*nA`/787Lj(7@HYEq w "S5d t.?mHgoD4u}@L#ev#㽊)P%S>T>nh ~5{\58L%.ɫ^pBR.`smy,IHM߸&gSl9Ԛmft"<X]m4HzYKe/ށ+Qqow8/+`Wwz$-H@eST w8cev95fN}5*WԽ=^%*D$A~xI^q*`(AUxL{4-ۅ)8$>wAt/,u_^e|-8hLҵsD\FJ[HA_Prx>XA}$WE tdP }J0+7&̀%zGj=GTFмُuHI}Eb=E9iF,+FχZ5^ ?J匩%@xd] `,2m6zɟ\6`>`U  QB](Z4h(qEyC/6Ss Nk@y% 1jHWFԁSB؀'i ݮBאiwAMxp4y<0%5| = /5m'5v*#bڈPuz.T~JD oBu6 cn"v\꯻5x1пٳ^~G ;u&ӍIQo62ǡs<j51'q񙥦cAڒzuY_ W 3<<AlG3`#guswG~Z oҖ.F))=_y6hX]n8]ҙ#R.ɠ]'m/+8?NdoZ' Ȓ7YmkCe\/P C6zn18=U62,r[!h c_QO^!f֮qz~T gCb 1!Y X8tXÙ{ (! &y hڪ}k֗2X0%Dj:KC T$ H:E. ,q5$_}wLbC(;!X?ۇ8L]> # Cu_{|N. "}[|x W;~vcY_)>Y>{X:lոbj~9cJpt.>PfTiIp:0 r<>l,p%Sכ)Dx%eWP ZߴezF- P/>o4Z"lJ&>(7o߹J$ab{?iK ?JP\mvVuVV {+eI¤)fbWL9T~;/FD=JoD|dYRGsgnzòZ*Tl %B\wHpz4T˜+呿>Y펼BB0q?os,\XޛU>*c3uja(bbZ`-G™uh!(gևsi{U aN#ޖ2D$(=dȯ~MVD/ĶZ5 MxO/c~ r09{g>jKTދ]*St7xGY ~b+m? G2W_>y Mm1J${WnbH⯴jd67% F5Be=KR&\hqA%9yc4ElIFΔHl&jw#u_8[+޹"-w݅Bݵy3&& jo R)WQ1< Ha񯡡t~"Ɂ$t;@aՋ9YVg1+ _DPLcR=T(ZE$#a||[{))qzm__䕋#Z]5s6_=/!@Fu{1l;\2O^< t)99=`mAhbZ$LA)Tcg 2܃ztPMSkV 4EP"+8~Ģ;EU 3-壝eNR'.[I$fߎ8#@/?i!#A/`ƑpYz#y950pݨ\k­^ԯzmL,JN(=xQ+.Q?X?6;{2Ʉ1^. ꡄŴwKOCMk5@J\Yz4*[S}S9hZ`o8g/|m-#+ؓ aǐbk_4A`kyVuz̿nj3@/m\9/C<͆Njk+qv[N`AG/`= Ap,3bbAhh¯3M_Ak]JK1ý)(p@1`^0$/2 422vb$Lue<#afO5{,LZlf&3E:V APiWM 4fMZ &/Z8xC[٠V*LQG[ L6YjfatkE&e2yQ^8cř9btǾ3Ce\!J3E ڹ2>Q"}^$=^W{^5M2錗=d^H =๽x#I/, 2#R98B?!rˤ -ms2rPly)P˔6F JuD+UJuֆA~5@}I'gD. tz2#SZ3%I2CQm+7 :Exʓy!]!\yn O ;XTKKcwZfE!uw]DEPkŬWd.a3>;|וluw]K8ֱNH3L`1:VuawݪSGÖg_ۼ8ʠEWcJ1O(<^H!0iL n+C%5h ÷=w8ih4( ..X;]t$!t{ ) ;ڥ-/QSy))rel7ka<PKpx}>+;S[>4N*SO%\d?=g _$B"RWاP=NU 6~9!` # C=UjH7+6ݯ̪M.w  AɅ%1L~¶ ^S' {rM"e:sfjgwi#!3f-rK_F̥C' dQZI,r9'ϟ^ |̫l lȪN{賙$ύy-,'ŋE4({r'Ħ2+g3~Ke0' کq3@'yY ChۜgQVs·4ltvaRiCg&F U3S,)tFQ8/P43J0'FJgc^S&d!P)SUbPX3܁۹F2*vm#zb6*G, txݷ=M ~e44]t?b]nמ,l%kfO׷اRP,hZ4 8.} [ρ}'$"^nbl[}UFٓ@l`{(;OCzgO; @x[1b%׌)mɛB s1ڂOɼhP61j8*0ҚB$vn "Ilp}ĻgkzNW;gɼ776ܮ-Z%0ǚ3+bHn w>؋]'ࣔavueU d)ʢgIsa/U7 -t9ÝpjýNJ~i ̣PԴzlIDΚϋ"9AL/i>~N`5[S000o%fx<,In*xNWu= B,$Ǒ&3̕w5@pfDTҡ|4OsûF"`-op+5G8?"V`J3M[I->WH5>%;1!Yx - Bz-R7|8pI#yȎoӉqy LS+r0;^+SV9AWZP֊D1[lɔs5[cMFe&v%TI;]8]2E~3if\#1וm;jn!s.NR?(#hL+QPR s*2P`&>/J5w#$eFop<=/f 8݆`磶sk r/F!H8@'3Ҥʒ;Yw m9/#*~Yb݌ߌ^ƁV[i)ͯTh# ecC4չ8UEQ};ojn7,fcW}vhlS<\ 5U{HA5I| (2 =u*q^w5&y];`TV؍1|qRAAa>" \P_T8~%ygQNiTRڙMƷQ@ePћC")7Ilah]@yځw[,䴒&r^-+_d5G tӓݾ%JosGx3=I.R:Ft~%jQѿ`e|ڽ]563C+5:I~eIʇGeVp]Lo&-|Tx 7:Gۛbr V)0ohX pl\&la .Y>e~?r] q2𪔛B )\D .A/GHG]_9~5J*UOhOtdEvF6 :ppv1Y+9xL}KiW_ZTW`9ߟTn%oAҎϬqE]~|8j1M 8d1mBઘ/*T*@$MN|D!R9ࢾ,cgI ti[ĀUfԤt/kZ 2gyFFdp&?ۮI^*OF y .4b_%ͅm@n2R܇ gZN+r"16Lh٠vD̹hNJMX[ŸN G7U[KwY9X>7KR_U{!aX:") Oy^+3]}kfѓm)CN%%ۿx-Wyn)[MtCpD5!bͫSwj(5WLx8wn"8+S@Al! %bIiKyҕʹBQt"aL9˕$n@rGFKwPL w߲(O }aheHǩ~ְԣ'O҃DkcXPLG 4 Y3Qu" 20Z 4ʑr^4:[dʨ|WP 6Be~l5i^[Ukۙ=[9` G|+u,F )ҫɢC DX0*7Ђʤ{AX{rU5FR][X8jrH-7Il2 e.'9Ig`njҋI+m4hꪬ{K}|ԧX)Bi,Ra@ԑZzF*wDx450LJI[]Hi1yCpiG VhyUx+3>VΗ%t89hE[tA>>WC,lU5]I* .$B0㤬ʴ7lѮ]tnOA$zŦmcf ^CPFmQ;1xXiЌ:Ə3k&}j]b襄)C'*yYˑz}Jqo(^/_rn 8(a Ҷy_l9Ǜbjn/.U)5ўuD/y(ZgLj[\:8R@F$2GT ΁<MRs_ ͟F#;0,+(rD'XnOAla}I{l@UG;}iRP(q-uLl|Ƣf$ •풬d‹A$0̧ B:YGy_V)Jf*$B"ZٕIt*ǚ%@8]$ C$\vK\aQ)ضlRC\/~hQ7iV E.s~!@ yiIm~N86:Oe|Aa ''m2ZU&'k`Zvy)6sDtMLJ*tŵ!>pw ?`EgS?l>1-X,?ZRx) -m _ab}yuP`1OM{fsm19{BxX;nxTx{\;yAY#EJn#w"J4 59 ܖCDz9LDhfXT4̥B 637v2~1`NIaɈ`ղ6{X"ƦLcgb89XlR]鷚t4f|Qrvu1 }n,ziQ돎i/S`z JyWA9>]cI]y b6op1"Ot AE7:IQGp -F 0HA *)-@ӫT3}~qÅA#2B}g,K\m) }2ll; ា![K .jHvK|4;W>NqK>w^ئymDFʸC% PYӐ|o@3mDzTg|faj8c*k~/{w{c @$n2eO@6ˋ-$iC&ZCPLJOmdx?dzc. "otv@>+JMC\.iĒE"Èɴz"K?M9閛m{}+8LOָ'|)?ءFv??z l]q~q _q#()P|IWY\]ryTa}OA[{ 4\å`]՚ @[-8%Vjų @jn_펵}[k5k9(tIGR WP5="8H/Q ª%|iX(1B]z \dlCsF 4T͋̔v9vA -0L-Kϵ${4،pE8m!WRZSYK~ ithiQ(%#ÊM[(ː3Ĭ:rE]_isv㇪޺)rhb#ͳ#[Jxi 257L0M-q9`p~@VH)uEf£ x{+Nng!uw; l,tAUl(z4噌MB64㌵tNΙy2WX sۃCUF)T;>PlDkʠÍx?u> ],FƕvI4Z=nXj!ܮ ]v$x[0ll4@!S^ pzSWmACn6 Ήc;YƞGJ$tj}b0! ' Ҷ2vq#\wЄ@+VJ?/@{_L%-ly0eϿրߒn&9Wݕ\ų9Dwz {{>"iX唛gɾKp5{$oQ˂~h$e&TQtag̮nFnG>g)腬`:֝Zz4OP*H{L/Njf <3}P[s|p<L9PNt\57 0URe4Y2揈\`IK {\_k EJ ]֚Sw˞ѥLc|e0 rpf$[#3f!YDn)b\ oTHk0Qw̓ ! TCYol{(V o¡& y9@凞6Ivn?sO]f+RVMiS.^Wغ80yF۠9(>ׁ/'H~+ *Bo4Cj(H )值 ᅠGdz Cul1z^PuFM%lrdELazyZ^\$3\hxyÍi"-G!`#ޒIؗV잩V bR3H_\\4<ò>CNncTY~𾈦8j,L`h@]Z-ҢޏSl,8WLfqNNdbu!mQʁ 65>Fm=;O\MמB#_~m)jIw<ł֭=b}?ٸaDs4$;uU#}^߮l)Q9|j1ds4ǐNI6",8RRMCdQN$nW{iatM)J(3/`9 PE9|З44Q֔s6жGw@C~afQt4Ѝ0Cs:<9+}bKwbo O*F7{ ٨%dMMᾶe(bO82`l!!CVm7; a덹4lN&q&C'4+HQ8Fzz"s>$Ж phZ1Sk[&wa ?c*KaӵkN489% OA?n#,N&;/v"` ࿑W52i] |E |yoKFȧ !0~OgzdOhcj P#Јwm@WZ)m=n:+=A)r!*uzp~Y`v"k= Ή9ԍyɕ@o~Uk#!ux ꁠa?[O s9~ n*)\~}púT\oz|}mq4cb6ȿoRiGk))8HGv-;/ [ OI'vsjrRcC< b:{Vzi ?AHby8|@fL yM"tMQ Bi,Fܿݳ>lb>fka1wۉLm[o=+\MZMC69Pn_EF Lʤ)@mjq;O?Mn`lOq~58/_jx| >p_NHI7L ܃96c&C%&_Ёߑ r56> o'zs\[)VHɹCtt}M^ie"?pŚW|*Q{|=$ h;ye¼,aLszK0Qx+5-k*%O5ʠ+j+'8 v=&g-K uC,7PS8LٓlԮF/-'5i`+$%p=nN^Uԉx-3];nOucUPwƼB3r [/_'gtmLfÈ 0Zq1"rv+iQ>sy1P{/]7cm0)4,W-!1~'I^Mtl{ _Ј02`;8ofY FqIUCpNV1CfHX|K: >R"އFS;.?} vG˜2L(p%$낏+fz!؇̖{v@͂zķ&xr ZTA@"oQ\,iy"MV̫lE]T!r91n:sA_ATF]%u.@֕HK[M,"XlzŽCzeC&y9RMav`!:^)?FbN4#>?JA5*2qz(~+?[\ł̖Jmkx..է+!> iGz.0V+ZZv`z[<81Sp\C+#+$gmuH-", YXWS7I2&~udNCӂ ݩ¹"C[y $#rT_d.zn^uw7R؀rE^dx9#3R,< c39t֒XutWTGvxL *^ ®J:B' 6hJ3'&N/,hus 4UC)oBpV\U:On*3oQ vTcv^켄 9TW< B,Q@J_RjcL>=J@o!%zP_z~%u' nx.\^=*$&f&7g]}K w\;4u"EdR4;iRܞH;(H]t}|ʤ'}*,n1e0C<}Y-qP0LQd8dl OBŽO 'j|fpiCutaSՁ/cMFb  H* x^r(Kjd1a#MfZZuydcu ?a (%=&"(oߒljX-U_''Nzi4#g?,}10c8u6CExgzRT^>vA7:<>E&{cv΅k\" wΌPfG[9'|a'{}2! *ҔH70) S|>PJ1:[2U{ {@&7Hc0dK)3!)p-?VV:vWoг0 #MC;?́ VQN?Go/JG#@ 5*(e <*~DZ@夓#gRF0 w/-8[;Փړ9\KVC:t&l?fp_@.ڡYd$'gx`OA6MR5 0 3c6+e,PȋnϜ}@Z3>ջ QS !7^Ƥ\*2`=z5.0%@t8nJ >Q]1͈Pn8Rˇ=P;Ha!lin]e<Gi<-q=v:QbnUZίzM+ht>.b82UO%R$R!y81s݌Pkܡ8tϑaE-&Q@v->R% mf?`Fo Ͷ|OGNٓ-y3|ZTX'ЂW{*U"93\Vxs"+j9/fW9X4A*pc# cv5xhEU}%9.}Uk X:y54܉WBF m 4ԿَFRkVCs (>QEUY/FZLg;R+[Xy&v#Vw"Etka,E4L?*~SB5_],M=@&1+{"F g*D|:O:7s gW] ߢBwBR~Sߕjr@~\Iv;e$N"DhОT'KW.L !&߷X?_Umsg48n.h9#;6QzySGoF {fSyyMpʯyfL`. {c豥wnR%Ԇ^ :eqni·'ՏٚWONqQ"`S}PoXʇ<ӑ`jٴ4Df^T?A:"eQ,= F*V\Qn*94XڤZ 1psүJ~-g0H :*y#+p10 gk^*S ܲ%TW g4@d?H;j i.nIiP.[RE{MF!FB< ڄ20[YKE: A9+%VEY؅$2䑻cCމ&'dFrΛzƯLp VW]k"E7Ɍϵ6RQBݓ3P;2PaY45:Xmc AG/[hǶ@XO_W諜j17PViaUH%f[^"i P.^|FT4u( F b;鹟yD.*䔴Oֳwĝ(5 Y|ċYꜬOxb19@]XF{d!ޖ!EͰ'XOAO0\N^wd".?]p4|sra}F-Ql![_6~Ԍ?@?Ii.tyw Li I:Rj3׍H=K|"[$^) Gt="2iIF ; UMUcFYcN >SW.#59&WQˈ)tjsI)Ź]3pH>z>$=,(G|ӹP8 nO3QgY-#d$1ޏ_!=Xc1U':zkO1J%h!p^#nU)KvwX˔߷{YN@B#!{H6Cӳ~/K$[UY);ㆥ8 ^$Wh.Qߐ*e)e2so:N?w08v.DUxK8B؏TraM&T2yGekفGcR`8=A!p,@p+2OD-rܝw8PT':^5 e^ m@iay7KmՎ@2E0c>%Mqat >?p{/Nk033&p8ĕ <-(@)Cv=Fj$`о`5H3F=p鐕[+wp3V=%J@W"ץd%d_ # vA\-bP #dM|*4rH*_i*vB$\ld,ЩH=˷EWJY5>չ/pHI'{.w~q>e+ ]ONc2یޕ;; ہѻ(rLbVڙeQÝIf̀ yb˞ tD7+:BEj|WRw2QmZihs}'yX>Af.D1 P54j)Amw+|+©ŁE=)){e=?rs*:Y*i9lxVuZ옍V흛H!Je`/0{s9.,ہ)4Ca <Y4~V^JI\Ζq ǓZct@DxuOXG2xՍ>C=ceTb:sk}>Dtj&!-W,e#zVv*mV`c*6OFWi hW[=o1S1r͞*JَnqC|Lm(g!N|#/PЫS+'B *0W gcqM:Uhw 40D)/UO^"31.[g#/_yc;/)XVh-Zj9Am%(D\Cgc50εۺ*N\\{isyCӅ?pQ Ȼʦ [}fvu7FEWuPg>>җ-5m!PԔxSwSa[|@pCݜ^xQ| 8U&?G1-7bq@laAaؿRLRs_l<\~1-o#GFZjWTP v9r2S]6z}Iq ͡ `.p bz$q`%t>k ˌ%7QX۶tA9yT/ՌŐ?d]@hB]8ީWFnw L1S߉Dp1TBHXA-O ľ%ONs}#0o418%soq6Ҙ9+s_̟If 0 .߿ s 4V8ޯWM|Eyzni= `e'-x䳠ieFy/T Le^SOFS [k'4UO(: yRp¨ I O؂-j@SJgI&!GopAXA<5p ɔru ,7?Jj ȑz'"S%Cid k%N?Ucۅl>9E#NHд`^m,7}4׾4'b=C1 / OShIPb(׍l 5Ā7I@d(ý6y@w.!#=6Vi c|~XB wv2rqs3ErkPg̨RbT(ƈrbTǢm?A(4Ra|uwBf[B\E4o- tMc#6O6R7:wdE^lLaLFb~&cPW>e:n:,j $kp^Q)YY#V!ߦtj*;l̷h!Œg@X [;$;~O3.7JPq8;q?%hrT@!BgyfZi <|U9תdb V֐Q%SjZt"ۨel:mDn,#x=0.͕:]jҁ۲~9~8IbT\fc`& #i<=1=;Q'{d16\T!Rmx'O_KMMR>\H9j{dL /n@4)Ռy"m)FWcyʃ(]6H'UϪ ص斶 YZ