libsmbconf0-4.9.5+git.149.9593f64a5c3-lp151.1.3 >  A \~/=„YɑjI%^ X_y3T$RVSqʿ2:yiV1=ˉ[V&J3v*#zVi,aR KpY!jY`y&C4%iM'%V&,0ʉQҖB>ό==f1TNuquU sw>|ԱG ӑ㜰xT+d6sAOz[nЬhG/㺂\U8d73b6a70e6d324ff222d4fcba11d0cb31304e55d2b97ef670c5bfc4151b84c0803e0e8545e1b0fdc752e22d3ec38d7b836d1adf#@\~/=„?BRO?7Xx{ץ9U1^:xlJ q8=Ұ!Ʋ!ޝB\QyͻyE=< =Zm @^ϥ4-}_[U6vRÚ5,Jn|YOLNT?Q\#fA,01%YjdLK; ;R&>C7b27VQb͠%W̩2BF5v&" pltE#*7s8bUl3=W@>p@h?hd( 2 O +18< > @ D  (dd d(89T:%>do@d~FdGdHdIdXdYd\e]e ^ebe(cedf-ef2ff5lf7ufLvfPwfxfyf`zhhhxh|hhClibsmbconf04.9.5+git.149.9593f64a5c3lp151.1.3Samba3 configuration librarylibsmbconf is a library to read or, based on the backend, modify the Samba configuration.\[sheep838openSUSE Leap 15.1openSUSEGPL-3.0-or-laterhttps://bugs.opensuse.orgSystem/Librarieshttps://www.samba.org/linuxx86_648\"8e62fd758d026634497288fdacd52c069eb0fbe9bc6fbe299edbc95cfe89b356rootrootsamba-4.9.5+git.149.9593f64a5c3-lp151.1.3.src.rpmlibsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0)(64bit)libsmbconf0libsmbconf0(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.5)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libndr.so.0(NDR_0.0.4)(64bit)libnsl.so.2()(64bit)libnsl.so.2(LIBNSL_1.0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libtalloc-report-samba4.so()(64bit)libtalloc-report-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.2.2)(64bit)libtdb.so.1(TDB_1.2.5)(64bit)libtdb.so.1(TDB_1.3.0)(64bit)libtdb.so.1(TDB_1.3.11)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.21)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.9.5_GIT.149.9593F64A5C3LP151.1.3_SUSE_OS15.0_X86_64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1\N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USanpower David Mulder David Mulder David Disseldorp Samuel Cabrero David Mulder ddiss@suse.comnopower@suse.comJan Engelhardt David Mulder Samuel Cabrero Samuel Cabrero Samuel Cabrero dmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comSamuel Cabrero dmulder@suse.comSamuel Cabrero dmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigsheep83 15569334674.9.5+git.149.9593f64a5c3-lp151.1.34.9.5+git.149.9593f64a5c3-lp151.1.3libsmbconf.so.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.1/standard/f8490f6d0334c3a4fa732b71fd01beb3-sambacpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a951564ced80f9e432dab148218e8a4898d7470a, stripped`PPRRCRYR_RR]R=R%RRR!RR?R+R9RPRRR'R;R#R7RMRNRLRKRJRFRERAR1R[RURSRTRRRVRWR5R/R)RHR3RRRR R RR R RR-RRR"R2RRBROR$RRR0R.RRXR\R(RGR:R,RR8RDR RRIRRQR"|P3/ utf-8f88d2db1c71e6338ae4678aa24b6fd0b1883bf3c65e78df2be953960f4072f7d?7zXZ !t/A] crv9u>uL [_[dy̮1 :$u[;r[Uű501Nրu1P$ǝ9Q귁 ӒbPே)5ZW)5D͔:k^e"*rwPqhIp")$u Q4r8ނ/ [(-  8eOA}AKtY~xr郋 u7N_='N"ʑo)3BطǺ0:BSt%xO%ȝRZ,BB+? R% ANGE֜O$'ybQwov$ RL]4(" vG d<yiqbSې2;M$oZ1VN1YfWjbTpҋLsɛbk-XPvN#5h;ʙMDN|ٲL p:ڪ &84FzkGݼ_=08>(VF!&p@NTr6ڪDdP{LnW߳5b]y{1Jxs(?Ȓ2YH&u]E2ä FD,@ #ыA&*Tד`@_QP][ciNaef,>Jz JƼr%\&!0<8np`Z&{\`٨KKz!N׼~FBrfu0m{((ShOz,N[D4Ѷm0`!Wjgi"V_ AʢV3;N||(S!C?"K,j#u/)KrFz(YȄRf؃g'yoI~*gexb/?"̕amX8^rm*dYcVgCC{c>h,T?P.Iצ4N?aLPUL9|_.qr:*,wbV%9DDul,n?a\n!Erq?t2ċk&BMOQOݟB~1S<2h%m ׯң 3al \f9K ueq:JrVTJ>1a˕6}d!)84 6y#'&*?N\ԀDY';0s2~qWQx,Mm3[L4֙#;iB7'ͪ>FX}wc`S]bW%9 q/awLԶFqBge`Eme48:m7XxcY $b0ο/OJbI#RS;,vptH1*`kZZC'a}yʾp bR)<4~vurrQH[7bX}2gYH^.Yg]~4~Fhxliݰy88}CfG: Lu1+@!IcJۘ3i;>NS{\+AI P %$s,ڌRaz^Gsvqv Ç|}5PK?Bܬڲ^v XK3\H$Y(꬈v+MV='#מEM 98gCLWKk  j&b6dJ#:){fbY5wb| w$O:EaÑu0p'3}Ud,)i_=:&V*|m~*VoH{3&Dj U&LL?_B,q8B| пg+sî3!; ݲZrgNw{sg;:F[Gh(4e ʽqDH=1(}FfωsBh:|sL=.G4SbAczhB"n abqs(80 ;ehfݢqڈh$Ue+jׯ P1%! 3]J̄-iQ6ڼf̓)S/`MXtEZ(my^'o>K [PL[d ԦqgSȵ~qR 8wWjOCtX9HI]hpAbF n}Kҿ0OduOK2$̦D]sR n'4eIk@w]}dlcQ ێuA1Gl#r0mKL5_|ڍW>>C-~Aα9/S}hۥ82 1&),|o"̠}ڂᒹ$`5ib+GqaBGbɳ҂\w.i|6VZ݄.a\C'!MX-&[J9*?T(.[y%fxim=^$h}|rUB3\h0F41Os8~*;z ¿m%kB>2aZ (kE_~ dݶQD8Z36,'6+9ؐRRE N,+r lT X͉fUy^;n\C"T6WcF'~JlQt $A`(^'._xf́ bmAӟPVұ9m)Dzɮ-ڔAl"I@up&#BotBMmiT6= '=iol]$Npfɡ<= -wV++k+טjX fC"l."6e7+Û5YT-ffYOnŸلpM&x:q]x]՝YsSl]#`n;.އV€P !54 nbȍ< c!"ZЗΑ[6mSa=!7-ca!J͝1 ^Cmk6jP:ȄBq̽7Z' .`@?xsJM O2pQzY_hG:{&8c@uZgR3V+x&7rѡR 4r.}5퉋%{--p jw G=d>"nЪa=FZQHT0ydm0: -U' ^ğnoSj0HΕ[=KU:9Ů @TJS夢ɫu?O[ $]M{wp#(G4땱-M儍>_Xx.{c,ͪk#m!U^&TDG0^t9:v_i商=Gţv7vl%[YF\Ϟ3::3H?':9,2zT-^+@-`G+CH^u cVwͤ%a;Vfs#C>d8hA iJ{PFUF1eVІ-Ң:sx!Ubr0mJj=ޝ6bRM *gd͎qǙ eExtJ%$MmG - U; ̾ !jY۸kHw%stoE~3;3#+*$#[WNu=t_*z0Ќ( y fMLgiGZ/xM=g^ C | >]B @ -3h/4~֒;P-)j5jQ%&4o}wZrI q!/K1N/]g9XBmH@X@Z$z}=xY_pOl`;$Zj; DW*FKXR~й@=Ve/U$6=XߋIDPtɓj*RU$"teF~}WG3m^j0I[Rm."[*MgJ1 }grG* Kz~R;{-9QjL8mWҟxC@‡:I>ٟh2cpne 8֝F ol UiA̘*e?u|:s:_>PaEs뎫x{B7v2|j ɏTVn:Dz7S$O-3c:>JA(`mg0_wJ81(] DZæl4O>:JTY"(%ȬDx=og3LX&A7;Sκ과 np 'c6iq2iz3E0!0ulkxg$Ah}>(W@wٝ!)m'̄|W#Zꁭ8/#tnuQHZY?NP q^'[+=9pk 8"5ϱ/A6?\% 艘LQѣjLtW½}' %f!VHyŧ􉾝I,zY^~!^ >eMcڍk*v`}ʇL;u+(Vw3ѳB0 鄕Uvإbs_߼#cKlcy/4.Tm1  8uu/zOtWP9arLP 1k!+(am]:k៪b4vU\:GOp Nr:jhCMO3bS Gu7O pFcs?Vl@.^:։VGhҔXuw`iWp fPGѻڙ]zmG5|F? j1^snq.rgo@0;~ ؃v\כv !ǜR"vCwADkf۴b JV */^{uO8K<"c2g/-^.J&u6A90 !q'Ks9Y R2Vֱ}YpbX5!E0!f72@}لbR!TR9bGrv?Q0:kMnI*!]4;H<|~rfEYZ7h2MA+#%?~5PУWwiQ)=9N]+gu !)KCBq}1EY-d@7vYyUi"wb*JxJ&}/>2*^Dy{IrpKumTcl]X "gD:NGnJ}Bh yPVgƗ-뱩a&2X!B&bJfhjmէFDed!'Ѡbl9Qdtț&z`$Fhcz[,Pȉw9Q?N+V*81$;(;v"/d2 S?I-~n'Og+|&غ6ohvxm5 U &^Z{d)8%r^>pإ+r?"qSAXr=%oaW$gcy"_9Gy/O24.- g' ~rPS,5"'lv.ײu7mD_\r䞛fne4fuH8>τ:Q|_gbx` `(>gZ%50Nko `9og!TB^.5HxS@ـ6yI[8 vKtPZe٥bA3AllKlQJMCuBL]qȸF?Ku :]a"eY3ubo[߂^X\-ROaIdyHd4`;mU@GbA4VDE TĎ:b̟k#{;`X[;W)R {Ś ~&L$qUJݕS4Fg]xi~ /] *9kMyu!中7R3"6pjfj(uaOW-hNF\rٳQB<+( k0 1Ycd_)78 oOkNˢ]gV_35a)P5IStQ4M06qql0=5o:y.)ԶN`8T~2|XYy >Iq,T_ pPu,,$ O}^<ζ4kU[e3.As1XpHs`w cNؼYgk&D-=b\7ʏ 5EB& cPg%Dr0j$,, {G/tAɗ!$a'{CMC38y2j-q0D(!Z$mELH[R= [њ `16=v4[~Ј'"*0Zx\jh B 7gOBB.?tʳE?mߎO+X:mX<3 9#u*g /dۓI"iĒOБʗ`GwZ4f ӾΊ?uTುDvB k~evTephDCEș;ɜVI~u]P&_29වSK =ٴއM5E-=܍@_Y GnKH,zoiО/mzb='vErUICdoVFQ}n|y 3fy>P8|^cG3a?a}bG u*OYi]@OmT\m-oA"ӶQ ˣ:Og#P…gQٿ$ 伋=%ęxަx/1+JMh,/,opKV6ib*-cV*r[&a)O 70B\!!ѕOF;k03)ooPNÞve>4 ~V1b(HL3ޫ HR[ˋfr'#Y4;tqB*PM >v$&6Y+#+$ 4{p̎q_UC3蕚7_9Dn- >NNt<2kH,i5F.PJtC/&X~I7^;k͸ h@]x:CDd8E\h$;))Ǵ#ʎ{X[G%aj(r D\*>p!N\~XeH-#o/H#lEtAHmn;j5"Hb}tc3hhS,e,Ie"/"=FL SʶLP݀{gtrWu&0p1AC9aXBQ尶܌Nt6aϖ͇/'.N`Y.o{xʰTJ,jH~*7hk#R2i PǨt$^̺eӮF=. rlv-kAW/ܝ!(ޱƇEO?Jzqz pM`T_W7w{˦{rה Ik$j1H@Hav +4m:VlX'Mȯ\ofFI'GA+`hf(#q:Ziy8 z\,۠z}qfqcgA[6-_ %ZȘc6h{qw9$/Qqίƌ5ݤ; vakXק)?e Nc PF kA0@ʦ3dkyt\#STfZ~q^twSz_}GW "bPW`<Ʋ&[$O$oZPث}ZEhǔiB'PJD$B兩 ͸G=U%~#I/pr³I;7E`N" pޓ1~$ Uy٦/uOb "+xtamug-P +l'ڌ6 @ٚL%V?XCz DdieGPf3By[zB`YK8멖(ex<7%8FL_Q4EZ+O[[c:Z2jr}R K7~@1ErIw?'|jfd4D H+HO`$<ܼmy=9q~ I툤osNuK.P"la_M9*nн,c*pGJ⌨jI^iZU6`e ɜHuWÞӥrRЅ+[nZ8X:N6mjE.Jfryp\RN0FqiPcD$>`(EP$=)M8y|y/*EPހRtrkPe-Tޒr>~nCCY^Pbk&7*sd7n4u)Btd!/2e\q&cj,6~abM# &j\/:Q.ivR0@>W" R>Zqa tTuZwCcn}f&uǛ"\h׵.AG z=aM^>8w3`O?/u:ŭV\#B3=٣f%īogGvZҴr6[MmfI@zVuf]).@uBe&_C56&T j*e:Uc>tĢ^g>kHB V5B(z.txY;g_]W0~(VvOzr"(dhFJC qx\0ҹ=Pt:"ܔ?H0HU ]BY4)Ľo./!-BȽә<;@XD'^AZV#)vfӦL!У4V,=~XGG2Rܶrƣ+RH3ӥVymcݤ_]P+] P3~Nwtm[&R8=aKkd?ioC|oA_d E&Aߘ3_)>"8g:Ф%?>W-eԦZAn`͆5* GVj,愯ΗbUz PqˊƆ+r0Tm\-O?}2ĸ}ګ- m}ҭ8nEO8wv)2.d(%{+Jd #qKp@[+gtW9DZEs~+íDkKgvyBS@ LīݮIlv:2TLN1[S_P^i5eIƘC oSr&?&\(APJi> \"nP\Czmgo N~霐NE)2}z ܀P;g33 Kf3g|ͣ:bkI^rK0;$Q )=:?ђ zWDPV^ vL)2v,pt>2@!ƀ.nP݂ie-J\|DLՠ۸ipD/paዦb*jZ`+<@f7Nk [[3 F(cr)&xQ,Hm"Yěި"?lQJ nBf*U`%zn~ Xs R[giDT,0 ӛI 33@%_c5(=t}K·_|鼧G5D0`g)nD]A6lh~&iWY7_q`qȹ<];x 6.yG%im=B ,f޳x]n S*5R" QrTtfOn N!ush5F ( I:]bV'кvY!νbýjG-'FЬ蟕o=PNFHtK>NmC6?J))+WpIZ>N>-H\S[rXPy涘mky޿ùۘ_E4 '"4~Vhmœ[-AkHXl5u /i]#z~*h+As2,ep{Úby4tM+!;-7hiƧ_=y莏fmlIaҳ7 ni!H8nmYCz.r-DLT`C:2pp]626ig>ZC0\_Xun=0GX œ*0?D%} 94K(Qטwn&#Nf{e U$%y{KdQ(g)YR@JgT($34Å\MIRcǕI@ۚVV>-! ѯUCgU6oK9']Gn*Z"mi&Q^\0'q,?Ix9,RɁSs+KfR"/H 4zþ6˲2(e|?Jh>2^L*\v(.NO{Bn☀O |=9aὌjs:z?͢ב:B_ۨE>3 6fk \5g?w$4U9~K ͢ܓ&*:%wFFF=-W -#8`ߪvpBo77b!?ڤ}PHtzε"~?Gs4OlvgHX2>+ .0SXnF;(OmCB1wrӂs*i={pakw2-Ҍa[m2YmtP}4cIs CUqV]V׉m;Xs2XwDOh4bn¼cX,w>^xDF9?&x3JbʐLge[bLzEK"똑`rYYx[Jh{a|JxN ?1T!MW`gjŴ(tb;VgiP2_4IrN*yxY(vj_$4Yl"tO.:!bߥȰ/(_TW²X \ch%U,X6l4g$ 1dA:M-h~*gHuQu=-P)eeET$OK]d?N|J h12`{+qqsYtY=Ji+mvy3c?'GZ2|I`ېd1onn5g.Hzpq9gT(10{MhJG: VWeRLzذ>?cmU[s$.1AY0 ӲXp63P 5Aeb|:F/ɳ<#>U60G^-3-1kd _WoQ~{YŔNp 1V>?Q]uZd4g%:~͡F0Wò Q(-H\~%R_&b@9bB馓MPdD_i+$F.$&IBkxvoMmkTڒ{}ODaT!e&&s ;}$"Lu&ԢPWe ~up~ %gA>l;+;Ɩ InQpBt.c::'{U'8[?΁FlcPY!yll= YcO e/?yS8jG3r\0EZj)1F5Lţ'B{ؾK(1-W&|5:Mٱ6Ѹj4S0 !4B0\7IْcjNV3>UG{a<:-Hve,zN](]o6@U!>:` e{X/Vҭ]^+0g[Fz!Md^|HtKư.:4DܴMWXxJ2J’4Pӷmd,a-A-ȩg5N]"nfA\_:r=u4n̰܆s@o<-CsiRXI!¹MPBz]A OH?׏9eg_\A= A h%m׊)yֲ//Œ ڬ?cbgǜ(ǵ/~G{urQs]7EP"%zh5Nq 7PanM3#R]<@\10w<%JM[8Wu!N=6i JxӋF:j]z1-qގdw y}_h(yi^a@yav Pvk ~V'Vx<'tdC,@..mF B;UBL3w"k4S T)"QKB]Nj",:Ej˘fwMAQ&OCW:JB9>=H j~*f;IiN2HZ#"bK/~zMϒd_7<tJB-[xiUOCA&ɷkpWNkxaHxyzɪ9Jl9*7|nY+ZzbixG#1~CȞӣD"aW=Z۹ >TLۈ 8TK|NjBh ת̾|޺5ϳyqH,cc Sю=#-5\t3 +_7&m沯7^ބozz6Ao=.f;JXmRh<m>yQckױf [1w`Ta)\!Ct)[䠬׉#Cz]<[׿BTйFV bS Q: l|U&TZZ' m(#.Ҳ.3{uFbA k^GJLAwD2R5PcxmftMM+Rh˺`iD-T(iQWr85O>(f] G/3ksfw!yRz)AwH60&H^>n͋ /_yvh"IzHCA"p閴 ZAD@`n fRy&k+%jk63K'i R1b& e"EPsR,̑5[SK(+QlBpK&I\b wg' G.dL- ug_juK(C%س3dZgyݴk&d_oĸpA*3F2o+|FsH4ܛ+<ѣT邵l3Y/2: vmÃW 佽0 H"*4O>N)V%e4Q* D(d_Ȋ{fu%RA؈OP#Z]kr!a\ϵmMtjuCE,W$N!i,l#F72P,ٚ"Aaķct,8+t)Au‹@{8iتY0)ݯ$)^e4>6tk_]a7!<`whmx`L%պHAƨ60nW LP#WuDlrvt`Q3G)@9F n%v̂n#yVB7""I4e rz%VJk0(+=}dX0l3N,Q2( >\听\T\lRE/[O  nfwnٶ D"TL]% {o~j_gX?*93NVpkmV< # JYaopoE)XRLnP(A{$eў@P59Ըl-깐bIuHC %/uA}qMu9!xM$i< Mםm#rd+$/ڸd0{Yn.s YP\lǨ0gF) 4u|8?'X`4ޟ{f+/"s.$ I%YhgL܅@zYv[ys  ⪛x%Xrb?#' K/;"q[=7 g 0Bb7+dyՃρcF2ڡhK[+[4n"q?~wtCx(G:P3Ӟ a&WB6[0Z%) !@ʵ.K(^ }0F%o[LAa.(zK!NF!ABtM^!1k.uUmp^pØZΜ .Q1kD:47ȹ_6 @_a/苔iy?.(%I~)reW(;E$5]:c}W2z= 4c"PT@MGd3>1DAFr8`F25.(KRby5>UMe7 *tn%Hb}rl.i10gU ;Y{0čcQt"o?l1豎 ,&A*Sl%Fá$U6/h4[Mh=3'c^3yW3ʅ>E@eC2F&JݮyOw.B GC%af <*s.K=tHW.$eT/G*¥f0hiN)v1􄷱]L5|t.ȀS}D1`8lc!ôgG~zbŲRk]Ǩ#k)ȍy(--MYW=>SaGO^'lIpꋒтPsOE߭8~ӖN1l8!&$`H-)T%,?p8bd2[XO ЇBI/ |b|zz]~*JEj `cBZosUe h0:t"31TyJeݰ`5]ӫ`۽"e>}^#D[!!o䨀u?^Mq8pI} Mm" }vtR&rKʭKw}G8+@wED̋8R)̢ ZeS H_avAt|8!d" < IAZO5# ߍG.=>,-@ÉuH &adf"m3\RP6Jb'wyAP}舅;w,ST1MBNNe_fYI5L/Ro@)*,ėk{ eh`hnjUc푸zzk=E@a4Vǵ{!⹅ۖ ? ^e3@!e&SH@Y!~:0xTQ&{hɗP;A[_y~dUFfmvn%V_FLePj{͜V_sCrSfYmE.h=uR$"Q;bP1MQ'!q(\C$Q5UX@&I\\f2!;U&tPnAAY\M):Y =NaBx ϊUkSt  )aN?Zûv99`O|6@7 &ŗC%0\+t9qƘi %_c8mj`|z+~E;>WJ0rć3Ƶ~bY @]:褚 ևiF2RS +Gn؟067G^}Q1!ԜCPt?iDvB7x 8",@7Xe !C)|'p{[qau>9d%WA(Q̐>Ŧpp&|[uxS7m1.~N036as !H0JD]: PRf‚~S6Z9WSU Y*>! e=j+}|ύ "eT DyBN^#^5e3&Yg1+jD+;TjYh -2Ϳ3ii9_Y%Iw#JOqeUˑdHaz-C$1 |=<1~Q]- ؛m/d+z}0>Ķ?oBK!X۬jcmnN Zwc^}1RUM'<'Z|#ov` $7Ȟ 4݃b}a"6j(۟uʤ6p-L91`f/MSot.& ڤK).GbFDHHutKT鈗!ZN-Y{Y >5)tDNo*ƴę&) vyVFcp( >&a\ ߃p#"'\d>=zϭz8s+Ah]|z hLjzbh25>Io@;+'F2PN'BqB$^ `amIR\dB,aw:2Cp |On.|):N{zB\dup:EڮW'f؂=5c&xu8.&ߡgij8 woBI ZyGĀiK~Anybsɑ3ymEZ{]"{'. p' ázجxdmKV8 eM|i| 8HwA2YClOAY}7Z^ -q&]WMev*SۼSmZ -1>d2`5OZtGuOcP%kB8ZI?.T.E"G C%!ɺ )HkpvƇyZ_B3W4O3&q+˹m`\{{,d5dn^PzO(6$ :yHͮiXnY S^ڱFqi]ZiFkYi`4tiΫQH/q-`X 6`IjmL5uަҡ =C4V9fӇlSg_.󴁂S]IV9mKjHfPFbh7_ɻAcĤU`u &$ jO si]MA^֔ջXqՁm5C yV V uCQd7!iӁ'^T yuо~3ןB{=|^R詐 p!30LN^.#Y" ίh+f7^}C7WmxG(Ç\څxS򘫵ˡtlo׽?By hW2IN`)!W+p mѭՖ )8Gk4IH؞Ԧt |DJBY5 !'gE{k)>mp' x1, X _SJ1ܩ;#+X(5OƎ W}|%/TX0^F.m٫V#$4T")xn$,Ihex _l=Υw;[F3*997 j`o ~UOu&ڮ!>ktЯ96'_24[_MJTdE1Y|GڼF3I&PҸYR'Lz"wM<ӼnܛH< CTP5(I/#ao{^؆FeZ3EZcnI \04ȓ}j%C@*v( w:5 ~L㮘:ݨ3dN6 O b"LTW:Fغב@;1 (-Dt)T|8!J.* 4X=I#V[*RqC(INT n=hXy5v(B]egV<6l0Q%Ik6v>R⏁K>dF좈t)HDxd]{Iw^o޼4$rp*:k4Z)"]yI1/_r@m#i`!G/3gt5yؾyk}268'QTI@"?$-kX6ҼAw:=a}@b n|;"҂O XqmtG|c2P_SP|m۬rlTw#~Z4;dXU61;SMҍd^0\ަtK``x7~SCv" |X*,%s' 3eQT>GN a&v)gVek u߫:-t*ː~oް >Lt Gwt-[lgM׸^AƗR%xT?JkaqyS$DXRdۓH֛냍K9:c7#oYZsc$w 7KMi" jW?'!K K{`BM;Q zR5>mEFz,Id4Ϙ~6SEsE/Z __zX鶙zLi8neILEfKW1Fe@kO[{$+AX{S<>.Ѵ}Q}dIq1zz_jфVѣ>a]`Cs{b ?Ր|^p(_S{ƒߎ4n)XFir)hh`Y,JbTAi-jYtơ?QWcgZͣ:_K0~xM)oxKyUP `F;hFG4znp5NZ-p^کFv$}>4 SmYzRE^-d7)\v(' j%6R _]Q'q>ňVc]USB裱N`\_eUts,yYAT.q?qfnt%jMSM~}rs곜,vxMyUՄB_ј+b[e|qlKaBU+gaG;Eu-U,Ss7؀$&B:\,qZХ+  Q ~ewH[ްWVKV@d%I q ӯ:h\c Ov ':zf(4sEmzʆ3Vo UIeG'TI,uHHB+y|XܙX Jɹ͚0̯B()fv ,!-Q2gft^R}MM1?wW{kđ/?}Jx%AeL, u ܱoesk=IhaǶg&Vks}{ =Q_o_NRn]x=0[JHmz_2Jo--s΅;^Cg]xwq4~i>UZ| 4-sLmP2W{'I 9fT 9N_JZjģB> hw ڄ:oFXŨR`X{ Z@cc퉅hz6_>z> /@?gm%dp2젢)VpO#dpo&JD%le m!Ƀw+8`U GᬮKKuĚGV1*q24@٤jRCFAWaM H4C)JɁwApaT0 Mtnh628 d߇1yͰcS}{&_?[?hCdYY%4f~#AWj?dv%&̙aqn"A3 XyuY>Q oWlc4xɸ"ʓÏZf$/9_d.FE!$ߎ/Y@SPi0U(HR/J.=ADl%BT싃[ 79{|Bt|<8/xКa=ҁ2@-?H y'ȁDFz[0rD$ͫ&9ZY+#~pTiίݩ&N69yY׋SLFW'Ю'@S&EvR gYqǙ|v1J5ii@8=oY+ϪߢØ!q,z~u:sΐoҰLȁìA#A_m;]ەSFePFk&tĝ-84RhŗT 5ļ/ԘFS{ {# 6Jyx ߮`m|ZŚˊ"s͑ U1!Kw Gn %BLt8ð{vプ4̶ !G>1(G3J> ì9c}!b: N ni4-.S?+ F,`+!^m+ZR>o4͛;V=Ȋ$^[;?&laj]4AT֜vIҾY絤}I$Ӟg x,eSro9NV\X+f2'p-P 5Q|qLksyJUQzx:siMف#ZUpXY=kީy7) 0i/U^Zl뒲__UT }~ ^M!Ŕ<ާԠ~2|M*(_F8)%1a ǘ%&_‚nٖ^t w KTͺ:GZL3 waPaC7傳fy$:UqCU9ܬat9\l E޷`E 2 Y@z͔'6oX(KH0Qãz|2W)7b(B^iԌ,Uq]')u|ޕƱckG8iݽ=鑣i.ߚ,1Źͫl#TGh~IA>tؒ*Ob_UQUŠO-m a0+YPfi˺L~Cj|{ZW!Trb ?-@/ ]ݛq} \ʩs^:9$mH.'ZUAxFB N@#9< j]hfDh/YÕ"0%vc6w:D)OJRvY6OXwNQvPjJj<0ô ZL!\J3Ef ;>+B_N$ww/0$HDi긎Kvv!E7GFӗKE a Kb.ѿ{zg$hHQFz$ŷrUOq0x){rQL/$R\-ZHat]E8<) 'wȎɪmÆڸ s ؒ7bgABU{Td4bU'jEݾ۪2룬p+D=dx P2n`RI{c{ >V1DQ1j@οٻ6)!9Yl"r;Oa;@e 2ޭ,QervI{p 򰖲OS>_},+qZ颴x^`y+2crX=#`;|-3_6=%S$sײiv;#zIqI%U Io}Dѹ=PcqIF jrrX? ӖC`9EEg<HR" ɼuu֋|i>;ߏ`G%7[ l3~!@8Y&&D:©JgeJN%Le+@*üHprf;/,J$vc qJR|ՙ'E# ,yR)Y*=:=k~A*yO{ue !s !Z D_epHzI%%ͼ ld- v9|Ne/Ut +rl U~'Ӽ4 #dsv2 8A/4V!#ٚTTYIAy1׵ۚg6c$!m Q~#ugʝ DPy*qV^{Q2FRR>< qSŒh6[cV[.QS6K9s^K\ZedY2jZUo풶onr7,a+L)`A^@|'^궤ML=ᚢR"ZzwRZx2f0LuN=QfԥhM| d5>2 с{/TB̯^[/쮈楱-|"j8%dX2џA(DR'+5WמKwS0P@VQ61m[?XiqZ%OeP¢Y3PY b ZQ lT}m旊Ǽ Lr#_ Qi'^n"^^̜}v87+ =&¨7[r4'C Iz@9t?1ʓl.~v_sd1=5 :orJgw+6Sk2V.XavyJUkRD~V BNz 4_W_ T<n˃Ck_gЖ{CnE2S t;7P'KEi+ŖDLǹ^:}[tߛNEa<.8m#;)*^L6&=6tT:%6f1G\Q n\- ,oguKGK $?/~cZKÝ3RTil{!G\ 7mrȁqO C#jًg6\6utyް` AՁnD.++o>]Av2uv #$oYTAX 3nѴ:wcp+9@.! GuU͎diY `bvYM `]9j糏/, ^zZsAцg,Xd6㢄]̫6?^c O5dԦWY}7xx3͉ZVLdn?/ٟ.C~#&!<w9,z;p2F߶uz\ܳu*:sR5~Oڠ !5FrKhC$Q5ˡ$֜ )cH9qҿXFkz&dU]T>x]S흩Q娾۪n X/ODi寚h]ˬWՌW{rD©#i=k .cgTۗ%)VA/Le{uO95M1,ܰFxMXq^!9J3b lR-eYÙ?13S,qm̀9YLBBPʕ{^KSv"Xn,̷'%Ϧf="&lĜH8be暦k\MD H91b ?/J/aXN~`;kq%;ϙ9ATdk3Fڙ .CҕNj<{jpBe'p!ѧO,CƟPʷ _1䓫M@>IU>Z=@ܛNO"RS˙5rِ9 h`qp,}*ƃR2`f*:=N; rB foQ$,]E8M !:@}L}S@](=}^΄ɰ`<_q=ۜHUg](T\t1y<+-f8!nKdzMU 8X JO8u_Hj)\S.VA.壐t.((3; 6|FGAsHls?fFj:fw/7JYkByĿutKwc=9Şl(Z#R3-.3ÆZ|hűRݷLib0x9#T.8{klQE6iF qB#롏?GȰ;0Q8h6 _v=k9>=|pMFw EFnT H/&t]u1Cjs'q7jvיT2K0g((1&T\đuwx5ЀK>SCOo2RGJ<ӫG=%4g@1#Pv1piFX$qg3W5℉'rh 6ZfoHg89}=7C^n+Wpm_${o!^ 8ŋ1$/c ϖ^6PԚ;r|g*1}&"񱾍HHŽGaE Do8yC "_-C!(kyaY"5Z(yݷM\B83}yesL$9-JJ ]fpkA4p. %`Gz2:x,mD_j&HAijyF3#p]#kq)G)ea 38i$JB^i  GN z9ۊh|:p̙7ou{cU)S鵹_Z6Lq<\`Qs^ + 3@^Q/*4T -,WOьlx@#>5:|JgU\8V~+\z<})JOuAY3p`Y#2-lAn=~)23LʬXJxDSE FM_eHgzxXKv6,s˪p6pt_uwtHHnZ)w4K: z , ,vDig*bhG?$PB7rDXZW3. |YO-pAR@ uK&þ#0. %p~:4Kv6OP٠^Mz@4y'Y|AlY%ep"LDh7q9N* $.Fdz/Xp(/G":f([wUBީ^1\)4dI_ngy1sANKWWIil]NV<\fYkh\ |? o|&r:#RM& d Qox LZ ۃ UyJ-ۿ4EvffOd|1YjnEsڠ U“_|;߸?[AWtWK %RP CqgP5Z'vy[2 .Öm-} p~J7$Fp {jphs,t ᐳk[ nkrh?$aS(>ZTq;NcJck="_|g1 c_[y46ɮqam&Fr+hdTpm!1Ig58XeoJF< bZ/gC^Pk"ŐyE739.yk.Ytoc @FkFl#.Uu?U8"؆cNܤU{r| v~^/jkz> U9kCgwRAzOTWvg  b(sgQAk^E( *c$/W:O0^@2X?{a;Rk0v #I.I {kG1$,,D\zb1/P ߯yVgBAQ12c8ߩxt^oȝA)|3-qYm,uG UF.Nk06w܅qPxDHL= 0q'+xyd{ً6 ۵2b+j0φX_"AޘdC#X0#h:Ǵ/m fLE%2gfwɜ+.{eǬj`N,!w޷ݷ{dz)tv~?OYi~ocbF@=9SMfRMɉgKlgJߪscs+_-D͂I2…j(?q]yS r+_5O{g7pn .)|]TK o͵RYg>FşAE]c<|j2`4+-Ots{$=7yS4q>5DnRg'UxGerCw=/BSgmMT¯1G.wC߈36+S o@bkvȆԽaxY&+X,)PI[h9hV\B8!fz Sh4Du3btyٮ ne1=?,s޴1(bTzKO'8Tv+\'i\NVX yGwsGD¤ԆO>lxBLJX|5{mo>{&4x.HZI֜&N-njx23+KVKI9k=?9q,7S3gԈSM1|kR>q ]\jb- ݕ9"g/im՟]ZK}dm:6:[Ū#1Mv~RhT rXVl3 e3l*&ډ}?]؀~;iBc "_)܈Dd\f]+s $'5~ &0jF=bjgTҚ1-6lzߋYcCkz-K.X#f-`L^g>/*1%vAH>ƈHqr((9IiXnp0m]oKi*c gܱ9 {jd]8Vtc3ʦM:^V LfEV8Ἁ{6NrU2ɘ'1\8< *Ap o8_ sʒ bAfetk$钵ypRXo]uUP52U8hBkNVy[{:(] ]Rr!븓r]>4^" Ϙdsd&"XMdty;eu4s_?ҪvI@+i $N<\e.YӠm75L [4 ח#X_rli3Y1f 6q^XoLPl#N3&6KuNbI|3,R b[YIN 0LsH4baPJQBMsC7UG[]A +˅XhH3Cdb|:T>Kp?mgy W)^liHO޿X\ A^fXEGιz%M-]+EpbNctA'H)_L>,(2+̧W.oJtv}nLf"á V^xx[ߺ4>:bg2#Om߷tF/cg:@Pc4@ f{yQ!QuU)]ڋ͘qt^BtKP'% j [iͳZf,<&'kߍ3S{oeEkŸyEc])(۳ቊ 1y i(*yS#KˤdjZgobNZ_c~bp_*PA9fņb~:ڰɣ#mo76oP-9spR(8^t ej#j{0`(ݻBCzih&bؘRz%+?"+jd^!2&1 *Hy>'.A}4v``ԇa:? O4u"zwi99뭼8/˓cJ#uA7z+vfjphZYkͧ;k1b0 *\/*{yc ń*:6 pEQuМ.5zM:wb[=@h5w,Ԣr7?Ҭ%-c.=hZB1l5k( 4x㘧F@ʀhymw>|wsSxkkt;7B B ڔG/HPzȲGә[{p2z[-vbBS e޿~Vģ9xZ(@;ŒWzhv@6R[^0#]8L@⁔6-D#c97扔HAp g]IIܨڀߐЦa~Mϴ~ ۹͛k#zPM]+RXϦ +QO2&AIl`3l֖)=nSgEk~@[n뇜\!sü3F_NY}'4ȷ˰-lZ[ɅmT/> >҇g|V0vWU-oP6B`p# U}'Wko|YpX&J}xjͺcٵbD\q(`~=+Pߡ$b<8;'n,6*پ f:m?EN RV!S;$_Em/N?-OfY&v˷:xz25Xhfyѣվ62F{ڻ`U󣛐dv[]o&ڣpvKSC^Sp,XT5[d+=u'S1Dȁfj(Ѓ*(FT,Q *|)'i_isDkN|mv.j^ejt3 )֥x k6J.E۫VzVqJQW0?*M_~t&*l ܽ ZkZh6\YO۱jX^!=7!8ÍN5Ţ\(/ZSJw@C1 Y[P`mw%Ecn|C/]!1QKp& A 7m@,Qm!<>N-#aՎ~;F:/ "4cpEٝ%8^BW938j;=[{meȗ |gb|Pމ2 dg#身V D*H'WdɟuMe݌ 8QvD#G ֺOK(sf-ьĢ(K93׳9c& b$] 슞x} r/ֻ@XFeIӢt:,i5RM2V2&3wW9n _A+=CJ]-v[+M 5^ knW'db˂( 'bm,,jBF/mѢc*kc >" #3H{qnQhH>ۑK5!<3"fxn-6V9)sON H1~[2NE`Qq{PJ*[f9".$gm0{`rBHc; άݝԍ,"L2c/EySD}՘H(ۏ8U,`\ʲA.% 3J {DD](9 ,B2XD.7;`B2BV:A*bwCd;<0!% 7/}캝;zZ`,EO B*fq68 hDdn`̽/>WPWnvpE]przۡ?KPEGm}Vz?׬'72 #YRj6g0֠f:} J0?CzI0ugW9uO2=C@c8" DRQWU"T{Ż<|E,V[dbMQY5!eU^?SV>r-WH7+&.OM$?'Yi3m#Lp @ۆ3 _H_8cIk }RJc/^0 l{ 45f~h|f"B &!M&#˙4Fyx\3} /7858+)mgU+(*%jҲ| v gUEψތ$EDòΖ9N N['O|dVok.mFODjt;Tw3I_?iOZ:):3GIӋjYֿr٢4̘vO aa}A2"2d.pg#;L MY隼v.5$)/dx H 2>pBFL'IcI3Aξ] MƆ'k~,۹A2xTPjG>xj&>SfSr}ažHs@Nw&&WMm/MږP1nAp~lENC4/_5tvR!GI<%Rt|J}~ lC8m-;"-u̍%'KւUi3QD,QU; lȄa'K @Mӕ 뽄]H䪫TӊKi/|ݛ!{rt]=1-Wkԫy?*wG" =0qշp$&`VctJd뼑Ji) bZO v-o[5V]ՁH/*G{[ጹZƺʍLsDsZ gx +eAA%Wnj=kS)R{t6HGVfRISL _:HBU(rLR{ <,<6NzePq`H,+]-,2yM19W-E%uDc,Y( ht'LbsM#M*pJThWVbQQ 3Ԓv#+K܅t{oWVQ/K4 S. 淋)ښWS=/X]aLyv{!ndc",/&?7o`kЃ\5vm1jbkHMu6m|rO&{ʄʚQrzpF!;`rna8"۩ݡ/]jR<nAbDP%G{$-kISg3cO sa#dmALvi} | [4`+?G a N}HkЁXFd@SC=5ÏH:_)nq u]6a;A*BHbDfVk54|vB27^$k* A96mAaR^U_7`ףT+w*ߕ?|h;NyPQ觻ŏ+A/#LNԝlu⮹{囹 [c-̀)nJD/ pC|S@wI=RK+\;_>t?N˧%U . i{ K`v2XdA#*trhR<`Ώ_ZOŇiq_Ag*̂mlnˍ6vM$naҧT z\]6w02(yBC`;~bSùS ޥ9a [TM F;itUOA%szyGhmA EDS/:.YE=LB׳' UP^{R VdlCQL;<[]` ^7YJRi3]Es3 XUʄxm+m19V:$I4}W_ vڇ2 t[Y.E1ݷ:R-H.V%!kvnRG<+vRh'n|t` r^TY/ٙŘeS]EAX, R|މKf( ECƆl^:scl<: JNV h@꠪BUyl"x}w٠t'.`l0%0ZuXb9x_+]&e;)TI\'0W̢R|JΊ^}LO<)Gfצ-sM䚙^N~Hz7FxcnKA!W-IgXKifMNr+&- )yLm_qf2j-'K\p.|lqڜ#nsj /+=?MK̹=:Y1 pDb#o+'m;KQ ֺ';_>*n~I`%ɭeR̕};lXgyG)3Ӧy kE w:>xAܯfƥ_6G duCs$/(5aTlrjHbXdSQ-V}$zuXt' s`(5sLhO=6ǫ"GO(YQzFP_UX k}yc!d*۷2`dM#*G"S_^᥁&ƲPehYl: ]ag_fAC\3{]ӥxߊŒ|4~8^hPEm7_{xDZGHlL`;xGC6SXC :/ѡ!;TtD:'":TsXPLpbl̗ߡYq<rcr:-UJ+'&+~?dPv᭲81 ^M?ocOF~݃7ѣV3@{*FJ90r8eO)Ę-tU5 }tK)1[7 5Vv+Ѹ2z`:Xw͎`/uEUxmF (p%jA);={|:|_mjʹUF&I>tͺo{Vd'I}Ks )<ޱtke.Ot=Cn܉N|%m.?R{yC>CCwhd4&cIr"s! ؗ9GvQLG ;%rl!" UzQ%hoh)df+V+WVAW(Q2j֓I}ftX7{U"hPC(Z[H2֡ɣ{W/wfV<1t"VE() Ε>G V;5iAM!A(t,_q_i~CcnX!- =m@hn%LQCljyO+?q[.OhX^=~$Η$E`Eq IQ\Y;;Gp4? +!r"7[Sݹ c/2u eL{EDk21?Xrl~`RšʲQlm"ZdJ^wf3Oՙ{{ĮP8ʳbZ;PAs0;WBm}Yfh9HL@q$8Ժ"V̚ib^}pr$l,8M[H8UFt>ه7X k§P=!Ή( @#Dje} vl4wx .E3Ǿj軳|ܧ+1k`W"69OAW =Dq.R ')5ArIL@U:t{sEB;tlAܴoC %AQz6_!'K$v/qrm:rp.%lߙ9 (!y'gn;y1'5}\#J>%^"R?ƉSdMil+PZ5CGq.6 E+?KL[1V|.HaQAA+ؓ2`EP >ƷR; )0WxNƩ[?Nil0S„Ĉ`JT,,bFGH^x}*N&`\EA׮?lm2 ţ"o{T7s{(AyL2=J`XRTY]iz?J"{8 C0xAN}_[v&&%>c՘ẙNI0|yIONYIKK|nnE%2+XϩpLCYK?LY6~˜syxsI%i8yzJIn֓4dϴ".g դ%b}_ǧ‘.cEu=P9l@٭a&P}~!okNEfN{{j#8LcK?w83t,n1n˦sl3O,"}VU-co-$&OxRP1-9O2BݚWw3(32񳫓29 6cez~!9-%:ULSCJ`¶k e:Qa#mmxnh\'iNkʼnRTD1$r*AoWNA1@_"EZ]BG#Pr5V/k{D%ɰq3LK@3Y5>HAZI&EOo%oOkG.! (hFܯ0Q ("LyHd"R:оXBBHn)-?<)ΨgUt[bigU~ar`ύ bl9~&JNjwQs;/-.K- y9 mY>I`lzql%ZLDp٘NT'|֭"?f>xؚa/wI`1jvul֊91O0rVN>=[C2M҈5M0!ST-CUI3\P.;I YjxŢV E`.n#dݺv#.kq-^JZ _}:i_zhCdqHETb`A*=j/Q*s#/ѽWw) },Hr-WLE -$Xt> nFQ?m6r]XLJХirt:i61\ _s%}?1ƫ*Akmo،4L%5RMH4O+Pccَ&:ՙȰy{z5J 3ޜ+"XvG]WfOOl;{+,kޡcOQ4@So@-Ȥ kUTvpu<<qz̥t7*MCU<餋La;yMTwRscQeڎxj&h7zJӣ I%(5V:2G@LM|PHW2/mT]uD "/ts0 LBH`nx;D炕WQqkΘĭ_ vy F42\rrk߇"PvvnrI}P@Pćh$论r| Bv 4w!\^![l)&bEC*>t Łhۛ,‘dVr}&ccVõc+bh; g[N69"? U;4y2V ay*} u-C DN=sPYvVtFmsEuM@iTN3O=SNvڟ8Ǩ)s,vX8q?m|I8*J\ ?URm߲+4>A3ۄJr԰{ïՌ+{oi%jѵ>Ljm(T,hO)h~g( g :.9ٵk>X"T$iCU ;lRO7I@'Sސ8OC FOiG>lOހ\Ti-t V}_s>FE^,ρs ZCoo }:j/$!wueR#3z>I cz3Pnmɻy>LM rˆvڂ:DP8!d-2fi2|ȇ3=ÙV@:,z/@v ^2D-x~rW4"gA'4]*o܋r+u,}DA 9,c]ߎ@rZ}% `j@@D%:)oϭ#3@Kb= ͜C}Ѫ3"="jKߌȀ% YYX5, T"3 M8ތc&Q/s2K\8RL_Ho} ?/"-dru$Z(+la"t[ 5WP%Wri*rEpDeu_ơx[zQ&Զ2Wђ\c_+zɜpzȵ9cS (ۆU a\)BCSyjʾԉ-Gcq?b߽z*2&%l5Mv봲 R֫oA##p0o@Pԫvv;pXw9PccÎj={m$#f709d}s{m21pO]TpvM"HS\)^Q#bBB47fE~ T sP) F~bA2žb9E] Әr޾k}CvygK*Z"7H)K`Ǝe la09(BzxOӮ""~tuFNDo,>&BArd3qM c7`:oB/?Vk?$/!;QGo% [ZxGqH >xjp0d^RX vGL<xQ/,w߽r2\/ҧk- Ϟz/<5q-A˃)2+AKzLt+զy֟Q|-`x'h*o{E6pkn蘦5fsv;cĢ?7:.%Ua `F% be3ȾJF6d$_^Ep`KZßx@Y|kJ5/5HƖee5g6.Jr!UNӿ|fN0!M~*x!|)/}=dN@Pj6 4z,v?%A*vI%p%T,pB(='ŏϺ1N.-5]E|ugv S U(dա` sI^^]ڱcBL坺3xryQ\DgֳN\9Xhz@^7˶B*ُAi,@BGI;fUhIu0 b)Q˵W7Rr1Ci8s^]>B}Bm5`E>!4w4>$VژvGd낤GLtB.gXWJِ0cPFbE}͡'(9oyM\zz.%^.VCzIQuiku '+_/N}F65qzc05MZ}sL[}ѮtYgX~.V^}׆6?xsόLsZr81@},S(DqGٓp${wD2_ݻ< Z>)iN#Yv):P*-^`K&nej̶# ҩ!5 #ʓ՛$}apL~;a.*#>Auִ0BTš&:U8Y٠ EXՓ8 I naa"NƒJNC\*#t'8ከ/YoTxưm"ʠ x'P4(Pdvi._L`ݼ6HY12ܚ. $h:zvTzE4WD{ρL7rf\Q1]lZA"Έ?aUy[dCp9gT/-+(z&<^/ג0҂]/b$3ㄮV8Ǫg1$Ug-#~{"+9//l+Z y1<f^" ,`\Ff|iT :gP^K!'ȠFr8?Uݬ@3" iŹ0_ݕ~&h_X#4#5P`X I˭>$=b_#. S(pF0e340$0)suBg-yxy@ S9zM2 rcŊ|XjWbt†b/AAܳZ .nAp7k,v|$54/ח2NF5 q".8ΡYߖ=#";-ض뚄s_?zK_&IybWmhΥKaxaPzYH@%S3 svu=Լ&C!A~R/~k\`djϏ)m'j8YFs/,;4;(S)3&OrT Ȩ.簻Ւ A#+jϵ/~,1hLn4}<"4=kF'<K-NwÜt(#>$o[}x-&B1',̬ώs˾~Vƒֽ:3tx),C>ݠiI]VgɫXZTL4ji:Zӛf]dU1,92Vw=FSnwΎMJEU w.1Tьd6uVh8-dRfXKwDouo!b ]P(6R+rt2=K dJ{~Lt=Q)BP~v/JluVDt#ڤ珿 X&ox3H~$X-; clʲ&.M`ۗwWĐUd+wN ҍ,=$?,X:VJ~_u Q/I=.ZLd:b.L9h$Z{jf0}:K.( )K/QYQ,$K`;L̷ 40Ef-v9%4փ6,IP6qn:T2jTF)- Rw2()2_!in:u\w%zzfn"9: y8` MPhcPX0NA w{mt Q(E=( c*[>&MΡ%I In֨"s-C {E {];6n92"GdsGpw:vBMƋq3.(<ٙa4rzG ^6uOW@ ܕE ipmZ5{>*N@]#wWI4==//  ?M-ϼwZ@QrxdQ-=@K? $^wA7`XVwֶHL쥂0GVJyL ] =C 09 @ZީA5+iZP.;~dSPq:C VWrE>nySםue ͯnFH 8oӼXYˁ#>=.%[q'TYI6 ВRpڳxL،/&@ܑ[,.S3["S:qr!MJ^:2I|JUFӉ EuL$CEU}" S g˕ԨP̟%2btnJ2P ˹ :2+!۟\1UN}8Ă@#hH6Q"nQ]7<^?o_q㯏HQ(BNLG1|uΥ6 Pٚ~->Bz"< m;;Ì-nx4wu8~WcD^nܧ#ex{*V.&^{ #w*@^M()!G TCpno1:U 9HyKn:KlJM}ƇW .:x7d?K) R(/e~zRj6eL aO[6ҠJS䦌S@ (gT}0+`4.򾅪GfyXbOWfe A;S6`ƒyʯ5i_<渟h[z+JEi4WηvAT,p\.h2zB؃>ڐ$_).cWxrj:Z(_H{ ;'M!捬a ds"`R ,eQD;x0RÄij2qn ߰ۨQ[G,]Bh@ .kմyAe-vv pnZEP**\8 %]5\>/ɦigZ2Z`W<,3tMU%.GK-y xSR9n#.|䟱cV:iGҁ|>sZRm}P5d=K1ysEO(4Ψ~DI`mKn^m{z}P}ݘ7fAOkDPnGy;^t|WNU }arl}wz@`۰X@~EPHg<вH ,J.֘(yFq3ʌT(TtrE({4.; `Qa%eզͥǟukg͈PdtgΑpױ,{"sAn\?$U7 3%]$ϥ?"(ШZ#4C\M8%fKz *Iihp~B )45čMЦ~x5ZW/˸13Vp>4qt1RXa4*DŽň3芾AXOTmrnM=W, \{^8زJH[ͧ-*n:8%+teF3M i¸ i{*Lmu{OEH\؜(-2Yv0Gl1e&[AQew=x,&P ? t<# \gAy|uFbnh[hMKĨH:W"*CƴՖr ^+aMZ<`Rk3,?}]y&,A *V" U dUʭR^7LdP/`J"'pO$yU)l5A>ߞ^%n R.Y/w]veC>}ΡA5o880GYħ{]YXmbm\I]w-۹رw!v~u6b e"FSvR2`KԵlbEVMִ:p<ܠI/+BRer1g}̸Q#c^GuJ+/_M-2ּ-tn %@/>H $cFxO۵bkϑ ޶|tDl-BE+fը߽bQ]mb.Է _X!]=Et Y:9{b\TYb ԓ:U0K$T3dWt;?}xDiTSqA~wz)}1g;歛}"Ze`0/.l UuwV; =dD&fE9ЌaH LeW}WrB/.W`TXk/U_ڸv-gNQ;h[9lPs,o;@$诈 ;E3 a4 ߤckl[0テ(pl$c ̬5 Y 9 i`lK4vS4,a%+Ss/zk9זQ޻~ 56x qjդ|_lgY֙jddNCWUJ3tR\+;D wp"Ǿ;sw1\v =.ߕ'm{n᰷틤_[/: ky2m#o֢5TM$Ly~2H>Z(6&/?C!T RKxBAS(Sa;Gm\`4-"jV_8E~|:lt3h`<(߶K3i) !%\snW۔("\Y4q-H RVʅYkzdS-:p@hX@7o5n l]gʉ8LEy G#LGBZ[Ʉֱ ~76frSߒBTKMڪ]גxӔ.vy~<}r( N2.[[MwڒV qԃtZYఽF'ҽ65ͺK8aPi|aKV(rm 1!qq:q"2fg#KPW!l'jISQZ"7CZFhG)+TWOw,kww9G}F󥖞DRȈmQy(D=#'Xh%&oUGכcއk~j)j~9['@ u \Xu⦒39<$vLD­_oxm&fH_> TT-_}~FR*V/^nJB'6t$y1WWrOL*Lϔ=g3>Mf83 H=_37v7cpNZ3N(Bg^U696Mӂ5@ D7;:<" |Ysm| jW?ը:=‡nVgl|w,hc͞|mvˑ Zxw]|L1Plm/tU:͏5ye`R|m5y. KY}Ke&B>\ g$Ȳ{A{@ 9?f6P{[ @J1ġ%GE&ËDL>9˦t}e@HK~b=bo@T7; w!.IgFG?5H"t%oM8Tl"lz^u(ꯍ`g4)A w.Gq׷0ƕ\|A"z*IL2ei@eۑmW0~ <buThw6]4x gx?no:hgˍgzbktPg2G+Iyt;z"ИH ݡص#}~u'^&3 Ԍf?娯Q]+=E*j~W>MJ1 r-j._|8$TEj<@윴 1p,s6~$E#hM9_ѠQȄ`,1fMHrVW1?N-NLFsGiVG['%0 Ckd;ߢ4հؚGFH5e9 ?#e\KTbK׬dC ( w0!Xw`iս \q)cL2*}`z ϟ 1\[(ɣmbp'ȫ4H*6+v(hzi$ˤ'=]wgjqrGtgK`,G: ᕩbpB OR>u^SU~mq3rZ0/ ŠqM~𰋩~YE- lo\d5aҘ v>ވOXe׹X[F/e$ІxGnǘu~{o>)tːw4<@,wPz*9~{7G݈X\B "t(q n)͠%C zvpeXK^HAuy#iTBz3eA&(d<%p2|X_X8mq~oE$#?Mo<~} My^p8ďJƔ@;f"-)yvn=z>H.NKpE-̴[nC:!hP4m =U4Q?=G_y($ؐ"vƓik~Ⱦ)]e04oω1 J:P~ҮaHC0z@:so{BW,䙞Qdqw•p[xkrSh >eqt&+]i0AVښguyI6,Vrx|riDT-E˲.l3Vn ?O6,4/"rJ=]^eEhho`ˁчjQd!z7/9)Q)%G*4۬9t_ J+UyUMLSVf@L=XUgኅQF~|xVN*)`YXޣߖu9d)cnܢPE*~|D6_Q-97Ds?qԙVei4=S4dB rLhDLoi 쟍h#"oP5 :tt\|maǕNn`܃2Fccqh4Nm 2..:?>MB)CqY3&U#V\%uLtZ"Tuթ _?i=jו'?9-Wkz|A-x=  `)!yԦ|X-w/36\W.H:B_joQD:K;WCYh`#9.j+I -^(〯aBE@-51၆2 tc{@/3|FUZaMb?ĢE*o6[ЯHv+ WJ7"bЁWMWwI v a5q5.'X I]tSA?h`1岘MD,y_/˱ׅU^Q24 ՇoB.x^;,[:,%MPg $ gĆkȹ"U@(TrjFO`lHzY5DbA?gG*?-&<,# XsZ-q]jwH)@S TX2bM'-eGue9sa7-=-^޸ 7&}9:J΍CDk`Һq0G^J3<>_4KR-8E,.Qop |v(+#~jg3\W%|} b͈{?{LjIg|ME{ #.qA97 > t萶35O 1X7}JBZd |P]q(*MO}UI#KKFo<$ ]*gs( pKS=Dl0o|~3ˆCHDC#[[RR2PiFQK}M_Fh Q\.Wy2䬠+v=$$s .S+$#Mb^ɐ22l8s`Muf Bna Lx56\o參ٲ+ 5FHB{?@rm8ȓ5 px e6dn7v_a  Ckl̜i90 R$#c1g8=pMZ8bq|Q˯&GI@ Yj!E{s|5[E$&S}in"/r9DM"%4kZE_$ SI ڤZ"%BqAzx8~:3\lcN&<95 ^aS-u0,0B@^Eͤ,%חt~܉*A%tlL݌0]x8/|^`͙(a~l sTJk n_… Ay/ٳfÎ^ri{u DM}s|qfs?{(mct3&KP⥦xgβ>;AoF Y*Sa a'7bݏk+(C>3nレb;gFǵY TBd;*')uX#2PC+BK\D=Si1$_+c=C?2@ YcQ(^̩ґylBޗх J>~cb[7QTaedŗFv1"P&ʨv B44ks6wg `Lϳwu^H,А*Zl1*9Yˎ_i1E3P8,R fa|Z=' {3 )&d$aQ `NugM]P򱼅nՉ“ꥱb-l owՉJNH%5Ž"t冑.4тw{,I(4P+טjRv-UzO*E s'_]z~ zλo<.QaWbg1-sA3xV&$=t6e v6 wumAE#[:GWtLW`8VX?LT|HK'Ը}|>)o1IlHċ=V㩁AsI=8p܉]*SK * apwQh[٠Q³\VFj6˲QGCjHE,D^$ h][1_{&`x o~V@Vo:Z +sѹe8Ӵ^Qg>?EZ{/-CN`fxK%Ж-g5L Qxp}W7;8'b-U|Hô.Cp`ԫiEצ<9/@21H5oj.RԄ2,E<+nǐ\DWUEomEc%G&,bn&{(Tu`)pm]&C$ȂTŒ?$c‰-qmvD݆3PnR_~ԖhIMUCVP]u)vdz) xd4MU3U\mMB5bpLB},*]dk*NU{M?[/Ԅ&;]wBfBI`ۭOZ~4_3qk_5Q*Rݭ!ޕC6͞a԰ &zhU>hϦkХ}b0Α7[vSGo=ѠH-ۨJDDZM7dud$_qx Δ\&(ϛ)=Bt4M[z2HMP?)(&A5ԏU{ՁMQyٲ eZF4?kxQL/\ZzNH`[lՋK߲?_EJSo!8$YXzoRKUn3gutf%V>yZεw VeiXFƗMO(YUH1Kh3}m5RGnQ`mҨ( FE nV}*L$W潖YؙD!t\GtnCvuɲ=0\=5oxXW reĨ?`'l^UZ 0yD"!Q }y2Sht,h'$WaS~݁bfkpgLI{C|vVN,DbO j[h]&=UWY3[d 7$5 k%|,7o|G?}[7d0l-'=^ `PHX^῏ 7YtUXs÷auֳ#ՐЉR$!v^5d{}4M +] & TK^pAP_)=Bz`!ʄQ@rurT݈ Mvs*8o 'McǴ ^ \9-/ݽ655_2 藧߼ /ڵhUvAJbz8Nl,/bgd Lbe cs*1eu@TqiqM4 s,=\IVؙA,{a|5pTp}PPzmPY>r)EZ6Y*ڎBQe|ԿJ\ѷq#Kxc&xCعI$Y ~QɶQ:JMf*˺yOڴÚ4v W>acEl jpV6=N01ݒ.#rl}\:?9"Y{DA.l LvB]J)&͍Bkd#@Hrv[%Eڳ?T7LG41YƋ z[h>bؼs|zPlWAW|ݯ;7 )|g ]1Ѕ1 x).47G"9+6|㫥vL>KO+*yʶ#L14QʉWY^]M"C$\ glY<"&~G"3E7P_U},?Vy'{i=hͺPU_x%j a+'x,"{(glRLG\Zh*p9D+d< W*eSc|<łטA3[dF&y!8bq11KxopKИٵa ;|Fh3 xQ?&J_2>H c ﺥ/ ,#b4j=jxx_zg{Yfa||Wey*iHz?fpvP:$4ƋH+ȭҝlkF$d#yB3픝?k/ߓ߼?'r1P,qX%y]W4ed4kNTrڋ'xZF+ /5oX-|ĈL]4cN:IO~S7K{$|,|"(?5]}@{e,::ӏ[oN&.C_dz@cX`+\k w ;xyim5E{JDw[HSB¯ˡ;xTY5|Tf̒D<5w"OuKG4zl}9sUO#5G-qXvϧ@R"_hK:ileD"^:fi_JK70(MPՃ=L\Lp m '%$@A݀Tck)(uXHSCm.Qʢ|C9<*}x4.#],nA#WAMKSpⅨ8*LޠfFvr];e`op}E-.+I¼8ܪ Ȯ ~bzu9-pタ č;xk ?9.jIa,>ysc{""ym_>dm# 7x[uu̞$kR=4:иXf?=PrĔ{4ޣ`YbDNi$7/1Gy$S.j1Nt,Tq*bPͯ$a!|.8E %2Z[-:RU8g.4U,3< 7?X=l<e![2r ?<y&^SX{uC^QehzLHv1e3rd`E+NO/wzo<(#ac;bɛZ!#8d <y8]ɨ-]3{u`օXpMxO]އ;btZʑANM&OmL-Y'i;_x.) AT{^/.ma,W@%Fc:"qjs8cb dj%g@ Ҝ]u&B}(S%Bw| :л|R*C:)0e軛*ɂ)uziOjgnSC)~qSjyQo)=| VGQڀ۬]-LNɠX.)! 9N+prkD~##p<WG4;5^n{GQ R0u;nrU0k+c;|!NI|zئjDFRdY_kqt~XW]DgCn(݅qp%}2 _\HTEԇprmmau`RɴJ4!N ~yGU$@EýlW+{C )O}$:XpJd X5 γW4_Qv¦o_@IWruoM\eqZ ZcΊrwOdF82]X4EL~]jtņі 2gnQvY۳*D5]\ҫ WAiٸI{.؇tR'i/vrqC̱Vnply>VcO7xjKa2P+D:Pa 5k'X*39iPbgW-4\}qf1BVCİ"Ψ}/] 4vE+e=7tSÍT*:d'.\Sx>/>bV2=*Ӡt&@O=BsåE|JXϟm5cm3U+֓<]t-4l-]Emdsf'H5z1X|wk`^a˜%6&gug=1 :sy5Osj(CYVÚmuyLcu~ԬҀSS}iwtSs&Ѻ9^d,A+n:g<0GQ&" Ng0dό.R:pxV蝖=$#1fCwX>NZP)+R yeQ\igbIo:oģxÌE|?qۼO gnXXvJ0kfP"Z!wFa=#Wz քCd!t JLXJ#.}KtuW͔ ɵ:*c.}]yoºㅶeQ{yWM\e]'t;F8"[P.ȑDHEf^Uxۨtu%0XggkhyS};GԌ`2t=3ԍ[I6ZlO蟆x&4<KS5P?E@ =(/Յ2ޅ6o6+5`mLh' T;cc, W/k\H ࢀ> Wxϖ[|sS] Mtr/8l(lHn!;2!3R v$Rbn\ꠃS1é+C; !{| gf( B$i#VbRա'\Y:/_ln6;̄BSFTgrRsu3$djwW,DphM]_dQ[?#:S JP7Q_RAgd*eQf(&ʢ%isR:F؄*:H28󺯼f 8h_`?aL>Y!N%]Z?L0ac,JE_`ca`]=i Ai%J=t0#si;6cﲧyVCr6TPXy(ʊh_WA,MMI#H3[vaDתàR~FT9w.Z:baӂPmMHv;|\laӤt>&Ov z8~b-l$aPAD{ScNZџw++WH]c8@@.oI.8ȉȝ"~a'}]$e6<\oET \k"5*$jO+P f}_t|,"K7gT#:"EO8muM{H2-B.\m8e85䜄152P|f[=+7me  Ґyg0X3Je*hLpc\F/̱Ps\S됃Dh6t5W_;b4\v[<LCm*,h@}/ɤ~ 5towՈJ{RCbUӾɥf`AY߻ŠY;E}p;oЬ#zaauna̧03~L\(@â}iaD/Tc Y)6Y %)y'U ?t>kT2RxYS=@Y\p$nY.d^ &䦇ON$|Xͩ pVh/)fETN > s"B3anMLMlޣ/M3-p* qHE؇'2AkyEӬݷg|:,"YMbÌGUZr-0妴Iw{+QߊBUS]Low F1Mb:d B;;ۊn%5s7 S _4{S9$F'#%"t~E8@.eFGzOS@':erYF H+ʖ<+3dF?:D)GQ.Lw-Mv }?M a9Ri<ɐlDzZũ%)Qf,H4D.˫ {&C퇙@[Ix&M1r0QF8;)ke5xs ya0rzT 9Ol4o_4pfujy"_Y1 %VY vYSpDIhIpHܥ}>vbTZ*r7tqPڀ:?2 Lz7`X"lQM {g^ &S&G"஋DShS,E2Lc.Dkl%m"\"(A"uZSK2g܆š#g4E#=uf7v: 8BXF]'t+ͮN쯆{w!tl솙'[5,]so) GC 0G7u"4kZ)Zi/sB(~s`J͍CfcmX\̔ h'-6^k )dx gIigR!J%yŴHse?Q>ׄqॠ:I0)D w3L|1*"7Ͱ "bFxNJȇ{^$<-Z7oC,I`/ٞrdQ4‹Z*ӆz,G 3)CSE`Îl]+p*JAe=ѾG嶣YѲyx88vD}vx=:I.O&NG~;8g|AEuZ qPCԙDM5 )4m%aʍ R뾭&Ϣ0B΍*/-&ΐCkM'-A,XZmU(_o'Y[]=US^v9As^(>KmF]eXfn]BJ.D7}v͍.NBCax|t_:_rmwFz] "v!a2a69,җێ{B/08ݽ~PwK=pz-{UJay\ia)Ϋ0*Q l ͻSmX $`"ݣ?s "WRI-i.Lk1o^uNπ*>RaT+loϗ{%M"9`=|Gw Z:m2g7D’.Ah]R~cc%ifrM¡|F)/}%4%IWle1WonMf7/ 7jXqǚ s5ZLմ̪Z ÁnZ,umkC,%Ϡ9";!tr>qJg, zk *yj哴_iKM7/p:㠨j>B7TG:eɷs15Ϲo}Y^8Q<r6WePbާ3oXw  k@c扮0**f(y Y|xQW\JB䥸$ͥΉ\KGๅ`qi{ sֈmQ)ҌP F m@\3q07wvɽx 7F!/#SJ/?_WJ C JrKL͹YAht|wKiA\ ㈽u4B=x 9{zG1.ʝN >azH`O Gk`)A%Ufź;G [_߿ڃ_t ܏!(f_Ń~papYx GyR+ 4H:V UFƑ2]S7tÑzp ?}s}uhNmf-7^{\i)xЩ^ W R#4pvM>6 5^=)aW2TP n7FkN$C5;=yɈ.[ACbJi 5޺Z :y_︙(5L} =A^x1S;g|@ߓ ?VRd,?CLjO0FDZ\ Lj("8 ((qV1 \y4JP"ojl]b8ѱkQ0|& )ZuB 7L,_W>Mjj3"lA;tS2p,L/NŝEԵjv@*s)˒ N(h&XqS]q0s_51G:B/A+a;!^ގ3 `]Y,eDkmsm 3Hss)NS3]`!s,ջJֹ?r ".iA)r,k[5~@~YM)0,,[AGdFqOx~ڸPR#`EAXqfND(A>?i|˔AȨ '2zm +|m,r%rc)Ȏȧ\ riKXTqRV:٣QRZNۿ;Vg]{=ܑў~lFm$h0a5DHN/VC;ͬDJQ#ضD8dZo=,MLѽ4314s7]38@9kW&F6]:[pqJR |r= f[.3/)f <K1P< ^M8t!/]z#F&p$=@Lp=\w=wbCiO/`C q'|ѥqZTq$NUQ.KԐlv'!s gɬdCR{J 1up$_zgk˂`r .dOq0&+ J۴2@\du t&js\~!R=Ă̯z_+E`Xd;|g cxqRjb2Nt0 jDS;1ל ."^ ,:4 #,S އ vc >iU$x^ pG-9>=w 0rͺM?wx ^#&ݹ/Qw s6_vAhJYMq7XQGkP;M [dkN=dHcYǺ_rDa ǰ3$7-*&@mVt4#1 "ݣhA<(fV82Z[{s1tuȱe5ubEfvƪU jQX/%Ĩ t"n[) r9`r yu?BDj:gf5p\'h>sjLhNREA!يx؝敂P|zf;Sp hU6K|S5dl~B+w.dRF %TAUA\N }?/E<4ZO gvGщb2I⪳`Rŋل=}v}_&n3@JG=b zh~fd r!2J78-u"):5V'{e쿧nݭm_ȳI砡ǓF$TfDshum/4s?*7p{CeJQ59f*P3Y[xZebuW2?l{e\昣;UUSR H m* '_=Ғ(`_W30ko0DL#HyC1q˛W(Z eB4L-ڢ=Hl?SBm쨭'Cey/ %~wc+- lf9hXym_nFL?E:Qj4!bL;nZ9O1 NV#5U [uZѹY*g~[Ⳡՠ]s}G |(}ٿ;h]e4<洍n2&+6 'tĶ<}~$30fgofNst~$p  ŔߨwABatꁨ퀵̄ G^bEH:4iSYcRZB TX?>) 9j2AaBWpsU?bPӓNJE/OY /hH5Zoi9)4m{z8Z 7~^sA%^8Wן`4#ѣJvj~6,XI)Heؒ݇} GIɗ╯2O"=]dLO(+ UbASeQ_{AJKrukZ-2?VJI]F+3=gU]JA+A?|?u6e/DK= '5Jg1ջ89 \!T׫̦1`S{6o\a9 oPbmnrs(IQ8,Ag[N<,rֳĆxLT0񦨞ތo;zz_nOU^4-'bb`PdUOSEnĈwЬaGvmegjhuJBv+oo\8HrɊ0.״!5 SWLwFFd~2-~Ujm<Qܜj>ۼEVH<Ǧ;*i9}"3WNV.o쑗*tn#es^?S S^~L|9ʄZ!!GWrJ T*< )|:}[}nM3YvYx?Q)HџAg bX*)#-"AMo$HUn׻E>G?Jgp6*c/1H*n፼d,%uU0xxpTqJ)/¨*|Ǐ[.<^ז XCaj' 8|'dG/J)2(y0!1w\.])v(.?4EY lzùI4r32"z:N#Ma^Itձ3*m쀚 =/, LiR=V͠{7.ƥ1{O?[=}<ٖvy9^ = mHo]2k짆jN]2#3BBQ} IT?ٰV7y! ϧeq_k9&~`Jc."^rg'V q pV~?+PUxUKp.oZʢ|9Mڮ3;)\.ydzN]BIVnkU'A}堥ҐI/% =`\cBy ;~ zM0'K>Z*G y6$\.j @^ VEbMn_[RDw|oG6פ9Qtϕ?~vS3\Ω0Bs 5-Eb/X~%T=tgoP|9(]媉quQZ )O,*APX'O m1_V %Qq&ځ{f^Д5ՅLb'ߣtf|b\"+^^~sŨ4qc zu铈VȽz^>*j$ItEע6SKEvV9€UvPՎ9&'x @FwH9`Dm!`n %h2IAnn)͘5B;@gת_JS7܂yLI?IiEgňC.((kyMO lW>L&uN&7+ms }c%rŗwQ3qj2 \P{"ӏpR:zX٤!/=ֆy -6bc4!_l\h&i&wyn2xNU j1IW]:QT.;*Tqtm~}.{SqǤIj|[!]4نЁ@-M=F_o荝Ofd^a@p^%V o`n V^FC=͆,gĎ (_ Rm!eBo%1.NMP4|ٵ{-5_-EP>z선cR(I=;J͌g0s2)JNRhNfsЯ98~ MeWFƊߐm†iMh6AZ`_9+I3f6zL=p =xJn$kS ?H)\@\]zW~vС_bYf7k Դݬ+hyи-4x{3@3jk:ϼS3G;{( Î?GƣHX2vhش|R%ɇR]6-ͷFCl?K&X mFGEh{ߋ|y~2Qt+vDKݿ'h1CeYPH &S[7YKh'C*a GXˠuwᐖ#+Be[M[vklӗ+pK6` [ryOH[jZs5oGl3Yô|#A7ﭫcjug*]DnIj4/"<+?m}#ACtQ 6X"<)7<8ZXE*Ҥf4kjil;9Nx-EqNc`Cg;PJ*+,3bKR2vXSj{>W *)赛@i\in#~l÷-уHw I?3ζ΂Wwɚy]Cu=H҄XD &?3>NŊ! hT-b;4!^*f a0f\G/Ҷ0Ù!dGU} (;˂\܏;Zhy!JRX3w#نAdOP !a! L6 ULHF79ύ|P^eV!.4)jFҫ3rgvAБs BqARkl _КIi,;S%HqRX`-Jcќ=;ߤ.Du{R烾o"k|QIY-:\j5 ^GwU2PZ"'_ ŏ;bO;י1H\$%f}\Rwl뙣cٻ5ބʺR G|DNCSi%璤;"9Q]s)QvI;wAB!?` ௟e-laK?dH"h8W%5NF@['|MD0O-?7&loc3mvzulMZ[bBFS{zڟӗ*qF0 )pHѪ_}nF<x,!DPJi:[N$92M65$S<pPPtR Yw6! _rcȧmȋsΐ2epPI)LQR<)P =E`:=t`3_w><+ې1fK C4D|B7NF 8fK ݇Eޘ& '⟂<6"1o}8R QZCCPn췂6ޚK'e ;λeX+mC_fͭn,UOL1a%HJL84'$/7K'ܥ]mA*+zK(bCEBN/*H"eNM@S;9c8Bw׎T䀤%YȇJBv0PhߛvsmJ#|zZA16?()ٝHY? :Px/%/L<%?qs[ 3 u\qN35!- 59:ӡ*;];͈P?C9#B֦S%@V!,KJ:M!#uo;;$u.o6zf[xy3̤]#aB/H:CuUi8/ ǀǶ=HdS?swl.^ӅFL@ôں>.n'@凭&$LzZ}!DU|y~TN(y<]a!]FIX67xyK< *rLSOc[k#( ɮz̳y%^zW<%0$eH {ak54軃qs`g6i!⡿;8n}5 ljG= *DVEX<@!{Gaxe Ƽ@{u%dSt+;'A q5}}*MT4Lm[p)n"ohfRE'G7կjY=c'$y|)V@=M{T'=':mPGnmǞKSZ9e3yi17~'GSZdz*ԡaˣ{u Qn+G,;󄿷#]! ~8P2U9aw'6?bAc07!( !93bPZ:p ;]ňJaMCIOA:LH47pBr'Ц xVWdFM‘*GBPOCD>ew)ζVńJB1x2aɊe:U\G /4f& z],9`G%@= UM~0f  ЭT3O[?D¡.6l!bVSbh*1Ntyl#?VƵ)"+LM|o3vsQE!ӽJdʷ=bw6Hmv Qrhm ^>ǥ94^ؒ2liqY4D'Fu x`M /9Nj^+ǔJNm5XV"kyW5{¢ic&EEۻJ",VwoVOZUDf(3>LYĨ0LL|6=Q{hνmMN#>Kf ͅ->f aC=[/[ݖEzs.*qb0CujNPƒ@̘^u '#{I k6@# P붇u?LWۤ(NP0{U x&iWc.Nrϙ,o,X淟„F{d%_Sff6`j=ֻf|VhIv{7wS+mM2j@9mLؔkΞj=]) 鏬 *Ba"t" cqӤ$?()2rR!`9>9%xIp>#CŏǩM =AK=nmhCn=u}y6X PFÔrU``gmӂN`8 h%m߽"o]%IRYvj)$e% Ė@خAQLFL#[[{Rhh-J xkHK=DJMr:T#on mH .%B4,1Yz)MϮH j)b'|JDa\)u Nv_{w6@| ␞7|xCdRcN<|ܨCWa@4uV q=@ ̻3b?d>%Lz@j(Xjmf)T2&|Bj4I)r#>TSܠcrxQ3F{qW:7\5Nn)[Q:EF}9bLtXm#u|Tj*pYRU%_꠱ zRMj1φT jb>;QH()UrwtKҬ/L#@rfkqatIlةKѻv܏@߰ǧ;v{#]Eݏ%0Ygu-֫Q`Èr?=-eSve@P6U3!uJDFu̯13+]rp7\ʪcG[v/JR8eKQ, [~}ĪD 9y{i&h8z.h;b]RMǾ %ʹCTosx`{ޕ7)"՜ k <Mn"?g +k}7yaI?"ʭ΋HiL%u|+f?#eSW"4c {ER-)H!/饥 _OmȠubj[%g"gq`Ŀ#`;\ęV8A䩄"$-18gv򦙽3eM1"w%{l,6n8c.6QOX>Źb)*zFSM /D"=-ԩdm^Id3nhpaEآ>Y̺~lI)cA 㨫7z3SG(+L :\=+g&nI2ӳd|ٻ{?q*N`^W,B&rQ]#l/}D}4cGz?}1% RR%S"꼔"4iK>vUrрM~\$+ݠ8}uHx}.KH$ nD(iM<C$j tU hyr>˩2mH*3K~QD)<\'No*ݘ%~nj P {MV$\A$ſ|xTڐzTzժn5`X?RݷYCj`e/1/Rw;=WfXxz@5 øGy;g#!b= 4]u4yX悒aX]!<<#IB̦yB 1+Ș"tS{\t $TϾ#&/$3BTVkL3H.J"}h$ST0\oM+9ϔ#݊- O$!N_SM™Lִ7Z"JCx* $|^lt._xdBJ[f#0l'@fP\AJ{v1IB={Z!fzQđh.%mw^, ߒwWIس.B뒲՜hmpvdR\u9TZMӑF_pQӟa+|Vuϼ arc+ng$bIbs8\igbHq%d`mީ) ;}8j9u4ꛥ҂-I`U}NErtFjh &:9ܬl6MB?hLꃚ+?I檯s  *tVD F+mTdEA($'YNJ8"X8-d91n:R$7(n#ty O"˕*y ? ol<X=gjjذk Fr}A/ztDO 'EY4\lns {3]ƴNnq:tg# Dzy<6!,le> `L֒tЍe![Yz\z.Qhr{"3[yV{jfKĝ[kqH(E1t5K3H"JO:Ⱦ\p>_O;#RdyK ׹F2_Ygty"y/[_$oRܼd>#AŵYƼ_3'=3k?g `VU)_nH$.'ݕ${A M5,1qLڥS1#{9 }tNw=r(L5cpLmWa}K=ַExr?Х+$`sJԭ'O\}m(&cvYe& d - <SWd;<)6O-uFw-uA=c2Yx1%ޑXϛb ܕ;\6?s Y޵Gf~۔^Z]4<|MI KwI-ބ!VPvRI V*`:#xEOnđݹ ǯպɱD<{kF@RGÇcY D 9T@k've'4]‡^\wd08NJ̺W@YVȑk$m/0Rk%ig*vsi!Yz5Q:2&.򐘞H!\vc.zH+iM㋒`l=DY m.f?lhunoq P{F˻J`V1.\z.?*+mT9P,Ji)!I3KDM3 s T0!Ꮖ֮q-+̗ kK\*Y@&A 1GYr ź>MϞ&Ubq0w7oQ/v xڃ\#I6p0 Ri8Eyl2*zc+kocs&j<6160qpΥZʭ%m#Ie(rn}V-0_ " =;m٥`3hO@#5}!=/:7k.@Y\oݓSwczt|H6g HtsyV#tdHvʧSvՆx\jxp~ULȁxUd%bP,-܏แm 4oi庙3Cֻzs-[{2o7% r[OU%3YF6NsQ˴͉U$(C E׸7FSmS'EbRFЇewO+.Zwctcl1)<)6*\ON0FU֭?j|f L_1GZp#<V$rvt?5nPGߢф7}QIbZv0ҏ8u֠ nJLJM:%.l?vv#}8X}t-CXbwT’U# zՏ@nC$fui?c|sBr2,Wr#+#S-Y"cـG,9*Jq%l)pjFHf,L x-t]wM<#_PT+ !`6n~0?:p]!-2,78_"˅t쩇8uWm?iG)<75E£JYtz s9hImMO_;mÄ[6I9`|{Q#J2u;Lo^vf #G@Ly q-`S)^LuAÚpto -D?:UZk y ›BL/0O?ZghۗbF؛Op_9uBd)ʱ7wQ~~ڳ.y4JoӍO*SI[O"u ړ+H?]~/BXB%o) =6۰LٚV砨+,Edolm16)ѨHRb6iN}X[r6`ˬ0"Z\4@}EQ4?-{ȁ8̹r =!N UbzSpQz 0֗ZѢľ1OWJz%sO18ϽYIY-䢰&nEl#λ$Tor[T^W9bʵXl W_2>s <nXw죩QMD6Pݥu3/'^/پ,Dh91VYP(D W e^IĈN)j2FɌpev=k4ADKyt Fk" &y#u'L ~ 1T q{3 H%prAjY<7ģS(s4|Mګ- )319TL'L-~WztSL{dV`(H&`yO .%j@HfƽҶ "F#Ohf"[c"ؔ:R#ƔFS -'f z8JB[Tp\s7hycgyq]'$lw"< qG*mEt s.7+gO%cVƐiM¨}>MM`EJn9C[ ityDL̚% 䴊s|'$5p}'Szj |4I^"aT>['7s@@!n Xv>Ť %TN&ݒR}b:-λjyhG#r?5Giqj`tK+,y5fn{I"рp '+fHJZLX2ntasyOJ  C$L= |{'$ y3ȫ5V*>vofSM' fȯB|:mt[2J0z}W@9ە9ZVdة^s~k 7vד 2 ds#T*5s'|u0vMMI+N;$TDǤ/]2b1f/u1'{s2NRgKԚz_$4{mz_Co^$;)Ht*minܳ"J8PPJ" xr@@ȳoJ5!lb 5cJnv<53qJ`֦q-ĩB SIΜ^vkU?5^ͣD 7?:tlB)i[- 6v² ٕTrϔv()|}ʽ~L|h09JTl _W_oHzU250+kodj*C 9qƘcia]Ccfg{Q- /m[YDAΦ手}dXs. ;؏;^IafTv@ ",G?Q snupJe'nxߏs_L3^Kulj鳠 T[acllg9 'd Gː|r3WXLǀjE{b~6Ш⪱9aJ^uT:4+s$ό a,ΤJѲ}AVOmNJQljv]9p2,9Jn&k[c@r( vPhnsZ%cR*APKZ 婶+døS, mR44pnS됻H0Mf",j4Z[|&0!8`#؏ 7wgFR"7!@`C2OC[;4dł]D2_{_xpk*jw˜U>I;9ngEB}(gm{2^5;:l[eAyO7j =ZfxQVHf5ʁCѰ^:/$] YzmRɜ»Z|XN?L#eNi/ 4aG$a䷼ AܵZÆuqDr$]*e./ՙ[ Cv?e$nV# Sk1>t86} :-SE~. s< Y|odeQcG(7 { 6g/UgrKYFumzJoLSOb(oT[wFWB54л Z1&Sܧ?p}HÏH)`)`@$ 8t5n' A.5<7t;R% m!SO҆EFUEwӂ}CjEQB.yY{2^*JښZ0w++܁PVV,`pG), ;QvԻ쥟/C}<*,!qyI):酼6z 81j&m{o_*2\vf?b*- 7we9,}B*>Bb!ny7]~Υ[0+ZiRks]2+XСabubH9<  \EqsO}rR %Qzj{e};uqɥxt1SX1&&~ZζߚI h;cz{(NŷTʵ 1u0;ObI~Ue(ǿŔS<&C,tҨfS4]jey;fu  rz U"~LבէHQ˥~̤IQnXP0#?KQ$\N+>s*cy24gcm!< 2W<;*e\DxA0.̈ YD)6W-Ɣ@惈gMW"*si߈#-/] }a`OG2SMw}L&ᾗ)pdW|*M Zt½cp/7„)+OX(8eUk;ß^R8 tRXQJB N>fSqtgv*0i.sTY 'cp at@͛U\T@Eאq,Y1L !]$z%YI\kwv]A~ Lrȍ6\U7TOlS2Ɇ%[~e"+Sb/T)~}~!=3 pĄc@I{16)xG 796/rAaH$Wߎ!huD /.<-hTw R+`!"$vjBTn_f02 bGL?_=9;7+5+k#a@ $X_NׅȆhjr8zƔ $dR #j&aG6gр WZx1)v3iGocDdO5&f lħ ,5 B0A}<5g, o%1AuqM$Bc))/(B !^-|o0QRDx8e(aMb"?Z55^({lHoƲUU&sR PW>ڣ;ơoaV.lO0+M TR{{oӧ6ahF )7@$ H a1+E &`_<Ћc[ 0K9])458*: fwVoTD^U$_x6J_=JB+M(W$gn[*)!I,觜ō!jR\Њ=&W$U([;BŠzM3 }PbaA'l_yОRJmBآ"'v !tu0pXq)㳂"1$z7'P{jz|0>S)02öOCC  , śrOELZnX\3J?6u` _a0NlUbhN4R"u }֭>5f // 'q2kc1f@XUpc8]Szh5',Z pQi7T4`<P:) =Xز+o^>@8g>&FMz输GUr[LF=ɛ'`mVc=R6$Ik'be;/h(1DL GNܜ9S:5lJw=Z ϲ͵uۣye{KELcԢ\U3@G@?_[_Xib)5иq JBG}ǒGI0\+.?A̖yms/Δ0&:Cm > 揳EN?Z7`S $FOr/fs%H@r"s\-=ci)kP=:ŕG1-7cg[5K |91b.Y})s+I?͜zn.7?B rU'X cW%ef&` P 9Β,rRlBl9i'ճ/u}#fJm[l$4jc;xV?QɃJmvRfWr=VFljpUwsϣ{<¢,cdEɑdYm(ظ!;jx߽Xy£567$k͂~T6;<5 ^8& = X#*:Wyv<Q34&o϶{x;ݭs}O8nh2RTb4:[dL"~3t'.i7D]$5 " ;4\o^|[P) G7 ~|_ԏ9 &*2A@c  VIP*xݎ@'hŭ=]8R~'w_ 3dK$6eF4 ț%Qq1IDmK:H6#dYk_ȳJNQOHa;.'[5lA(6g]H "{_ҿV`%2o&Z6ɯ%A;~eY%+$|HD.KTAZR\k5eI:ZMkwQ9=»UmO+:.;'#$^cO>k_ud0GA#-ȟ36yU3yL-=+nd8z'm WU'zbƩس/MfagB3qs܄dDE92&I~b @&LuxޏџX{cr;d@<(ZHoDiaꕿ tBZW3d}k>p@FsT]7ڀ}mǙO$X$9.IHobt^N(tT6#בa"\>¥x dàƔ[+=C\=e>TN>ThvFfΏ~8Y=H^T*kV'3MypQ{ PMYDy|Ju$# FW9ȱQ"}Q6EhXK62z\} 9zQv]z=.#b_<2~z0֠F#]桲ZpƚXkFΡʍ7j?h2oEҞC lމO^6bHvI}`nEEQU& _ӌU[v$1̊_3M7#SA&_RݖژM sK1|%",Ez=)9YqeׄۻP[\JݽhR9xUKIuGxyH]d^Y\˙OFo)RQI'w#V2+ٟVT2>]J"AFQQv:~bٛQ -咳vK' (3B#yS.sb&ukWjM }-8=*Ք7%{Z*:P|AZ ( ^8@N4n"ܝRF[}foy=oXVjB^HU $BKٍPtF-F?V^K_=XA]\!sW!zιO^V< ˜u5^m7yzi;޳!Z+]$6N*as坨sX fM4L7؇ugLx hB,jFr( 5 U! s'DwĪ2֬-8\ny43l E(YU4%z$DBe`/WP]CDᕂYbxY,R"KϏ5TosF27DyRy3vTq ,Vؗh%[Ě܄z-&^.>s)<2?[NCjtv 6ؾ; 4;M9M.I{7~b^OWK&󹾪+BiC>([(_kgvɣ4 "ewӧ Dqo;!c-j{A"JǢy/W7z9y46\:ǭi*F]: `o|ShȪɤmN[`lzY~ bDҔG2L%UBxBG9K$+Zyf(Pqщt!sAkz3%Wz5iY ڞNx"h^HåK.! ɣRYǓ(*ziy-Z *af {S?d\|3>niw:8[Xfed(L%G o;]3bCz(.;pS=h =Dž6hSA"vzm M=tnqJ)5ljO>_ gjFSDkr$An3rx WS;5E氐^-eD1(B"eϲ,fnffJR5tQ0SLu|IFiv 8gŲHT e!թ/drrJhF Pa풱P.o W59LE,&d` aKB,*I"[ }Vg͝`FU?ǷҺm:PsIL۔6iW44+3_˥>Uh|MiL 퉄Lj?SNzRˡ=ݤZ` DT;`7&Wm45ؤ#hiVq<A|e X/w?m0d0$ h;`M3 "<i4s]cmؿ_1I!__ 01>vSP :|M"6eS~Z<>pתFT4-y;VLoNǁ6D,E: _;ÒS/Z2(~8N7#'V+$ԅ<-2(U!.9O"b ºk04rMsnHkNL׳j K8}8㚿 ]֭S}x2=nGahq %FB3 ӪsɬxN̯j` wDʱUZ5X$ZdJYo"׬:jQBl~`Iӡx0 zma}6kzP^wy+ݨdHw:ݲn>?580$L= |AyS?aY $§k}mkxEs9`^'ޤuS<&"y2ʂ̸tyV)B'VeZ~IV ņ#HI8*+:h_m,E.y\*i]% 6f "p0 )k$L^$4UTb7=`)ɻb NPSbƮ> ǒQI7ZAV91m)y຿8 0 Ma/,`M'8ꏹۧ2RMb7 -)UUEꎓw4pɛ!n6򷝁ekC.7vSJ#/U$,<8C{ewز~[C54\vjxZOe:4q88ϊBEey䟆V2fV,+[N#z!?5?d`MC&KF Du@a]Ԍm7:?9dFݕsT^!V`b!a׿ 8q 1/M)jp2;gO5x5h'61RoK\zPH"@|i,@糨 '\+n+aPy=f^ܨ!#MNx#x=T}pBe7xK# ` FG0oBr$׌K鯮GIMKXCgZaV7q 9*ztQ%C#h&IgGtH}8HBǗ`CEc c54+2/A7jg-jxRň];R1.AV;Qn|ٵ_VQK54[=|BFٓZ%YDG^~AE)haр*q*tW(ŃbڿOox^<ٙ4Rxb i͎5L=a~[*,[RW)O3Qg\n:}:PM`$"f= kܐP(^̧Ct?؜/qĸ',?G'zjg5[Sh=6~lg26-xLSE2[I9 J {i9EZnmb(W'x#U:7uJF|<}J%@f=V7v]8݋wc.o|N󋊱8 qb">+Vn (C-g62D9w4O+:4YU:0<ҙه!/1!;bE3VӤ=̣nSo~MU@0(+c\3} >"7,>]Z$J+ؕ;+:ne@WZWOą谛:5hEʲy/>wu( (ZzpOol^Ź׶FM!eS9bS3 z^11J&dM ;8&?cdʧ,h7;:ؙVܯYGlOL>RӘhr u!`JJp];dU=[0\vmzq <ƋwCЁoD%^8aJb1Ic>ΞS%'c!͸Zj.GMlꦭɁ~a K mȆ#$5j0U5+ѓ/c3t>ǀ%4W K"ɑg`6QH2O>U._Va@ľ:m6nv=ԬZ]d%+NK^o&D5-R.xqdo U\%w(6#U(A{hjP\y7ڢšuC!UFmL@ۻ#S7s'`K}}/ozm~̱3nNt 4eD ɗuqȅ=k\ݨQ3]Qm:N H3fMDsjɪg$A߹9Jا~CW' )b//gI &#ɚ3_왪9f {BSal B?]g{íN]}'t!PH%ԷMSLS1vשMW^$bsA/us9>BbyF머C0?<]_d'̒'ӥe _hpDv^p`Gr,S YOf!,PxgIn I1Ș/9WJ["]Uv;qۦ]A_΀O`4*qe$# dL<0tv]ź4E[:۾D91nW>K*xSh.,֝fDVnڛxA_8QhX" 1cl{s1X2v+f41 }S1yߧ?68o u9b~x$U1%IQuF+%Xňu@`{o X\dTn|`+Gs霅qnP ΚPۙ]PICv'i]t L?hÌTS8d㑶kMn/X0|kʃj([1nSlԪYyz|vbFb<9#}ڗJˌɨ1mVZ,9V[7 ï r j-(".ٺǀY!Zqyṧ]Q @ ]Ad<&#5 y&wF2`2^ TˆQ.ڙF?vb7[Z WyYȶ~i+Ǭx bH:HT'w:G7f(01?'f|=P=!mG̊7kỚ=eƙ+}ɨ߻=2~k39|zz7z3ИOPbqR_4 X[ 2cfB*2/C+z-ܸݝ ( ]g;U&ķdC Ha+T"$_J3D)CEz˭ :meo`3y;SYI1|)Uz%ؙZ %r,eOO9W3+1taBlQQbPoXŔGc~Ce\Z:$B.g%7yzulkCq'Z/vmI~]iԘC<Ś <#ZO߶5H_T=:tbaQXH,&.b};g#uכ"U3RCXlwڌ M&apT6vE2 )j+CKAь3e&oE,O#0:^f-%pn@UUzT`e5I!_Ajڱ-tȎXK񭱜Zvj[/̾,fnor,mr:ĻӮmbMVҠȇ+mQ}0](ẽ-XF {|ԓɵUNd+/0f?c%j`h.0_Ғ(hX(i=+A[X0oj+9μDJb>6лCiCOEn| 鬾y8k+`O+f.b@zj2JqCcƇ'xR;$^t܊X+/ wr&5d(:(70%?&k|SnAm[V&6t#odRl['>뙃?ޟe ONx.S b׺f{y/БpĹYS|3rqh$ls#@®ӰLַQhpk 7Q7qhɃ7IRxή;߁ 0 5bI; q B5!>ԣ/Nmw{vN`3,{b si-<:}Eu{>)톇^Dl;y-= !:]֚:+ 5 m%Z {5_Zm_sfgJ 7@ҍіyjIp,h O7@a1I2j$Re't50_>2+ a[咮%H;k$5( #1?r77X wšh6ӓ(B.A^Y ,\4Z%,CADJ}E[PЖro3յl\ud ܤ4 ǷT+:b 5MlMͩ 6%Պ ~zӏ5CC,F*-% h{MY\ Y?p@_ED[0?ڧwblͥbXܻ2:/u$Uc@[glRfn}P%lOnVnp4Vw_԰6M]ΤOAfdqeR8y)Rר)xw-;S7^CyP㫌 Pg;hfm/Yq p 46~ 2R3} ^wfM^o-k:^x0eT B#&z #QU3~>|MZ‚5+x>۶0U0 ~Je5 i2%I霒Ӣɢ 7]G;"Knc<;[gO Q3,j3ǰp_Su 6X-/be*q+Ng4"[}\{YqWFPL.{P.b/$\+zWF ߥ!з]nY ),|+>(ۯd Tcv[*64%X;$`O3m3+m午AFٻr4v=zKFQrb`t% 8'ZkF[H&]fBO8)ǫς]⚾@ʷ-QĹYhxʫS nJȄ͢SqCŻ"9x]h//VF@VQ*p%aHn+=4(]$w#͇16 W 1Xkr~닣G=L E/cCYʞYjA;]*5^e~=5aB~&Z>s@NkTZLwnGt+F1Ixhv)}-!>U F/4H%(R8,*=NXZ֩al_\\m|߉r`n+#ŬxBmtm+REcQrf7P߻ +X'{ktTn1{N!OK.XÏX'PN&)=P/U`˒) pG &H8f:b*? `;,ֱhA";s[ X9 AHAcR`ZF%$b29NUw&  xƤܞo&ȁ>MmKxaE,QHx7wTU2Fd7x,L}*FUZ&9ӍU'PKEzBf2iMs{ȓ1Fel@[׉^5Gkx-馇{1.OƬd{%+aDz"+' qLh>]*cPo9hd^39&0A A66I"V լæC!dE<:;-*!\>vC6n{Ӈf;XbBاM+ @J1=Q",m\O"֪/m3D d0*P~W'彌Utڲ䍞qc49tYe+HIxJKk9K%V6e*5خUwg[( M}.@C"!D?R HZ05;VYOyF/BSEsROnj "H55Yې]j_p yܻf |~MMnF6Sx+i Y2 _,i^A51v=ޣ_˓iIrbߵu̴o)_k|ka9NS<^fDk")CU5m.3"0e2o9BNH)=*X"+@&K̿TC8Uyc6lw : Hf!,r8wĠi %wvע+7;B| D,r%k}PSӥkSǝ=wV*r- ;=Ҽwsœꅯc |"A5s3(B.Alj[̖VE'"e;wug6kOѱ#F"}qPie+L A$J4cP^QTJ-Fq0~ǐE6VzJ@;Gw{yH Kb&tirq=Y"a8Mi5I2!V$5:=Q*5*4TX(!8?6F$T J~JS'xsB.4XshGJ\rl3}--?X)!"+Z$\dGoe4+?V ]?NB`G.ðgM[_K]Mc[vB0G_l$͊z/ H>OWP .`" !Ѫڴ:bWf}@ pE&6SAmR')a,]WGc6xE@3]c40 7xoTf3̉RQnАzLq jJ k>6=t@lX^gZѕ:xCh2o+NLmD|F69t[ !'8ߪ,0pp-H:ݖmUB1jnrw !|k[ Rҗ# uwR Bc1ߔn=c|.MfD2Xo ]X< 8h)JۈD(*o׍!99X5i"GS[RZϏvE쇼K@բ1$\`ٷlȭD^ 4[4xx*/eklۚqL_Lx4+)4P}"y EW *x9u-r==4@Q.?]<6q593W9QY(6qT~ ;7GK`mcwn3j{eS-@98Z}]@& ӌXD_N[VP]Xn<k˼*)l@ w$$ɔujXb-LrT*9>xr' 5@W}XMn,%6xpQ#%i"WE ýXeJ!D+*cvGz.8-C7q.b (hGi\!k xv"Y!)|p[6ݼmg#p>ui)Q̣f3`?%y-g$>2X49$~,.h6U.P=\bl{)M aQ5AH臼Bx—ti$ةi ZT=+u*ެ'6Myߘ) K5+:3_-NqDWJ0 y¯S~=\N$MsCL˔qS 0ХƄngU4R ē=Q/=vps\ox6"E=yI*UK r`V eԖ4g(G}7 w0y<>dgڷBG1b<LC8Ubu/ 2)@~WޥMe"wlE96X.0Fo0Fn|NQCYe}6FN.Α.M RQkϘN8XUn-(IZflf\4q ^t@רJ9.ԵA Q]xi^/* sQVe(%") X˔ߓ ӥixV7F roBw_oUU~ZfZCe)^FWJY V$l$bx8$1rJ?LtH?%"LKd.X{-GoH;JU5YpI)֏SߊYo"ٴ$ #-p"Tpd2P' ӬpwWGvQ|5b?SdI[a2^uVIb W/iֈ_)y}pbBHmhmdPޡAQͿ<%ŸOP7}Y[Do晰xL;5@ F ;3A=ڈ3 ԉgݪF&3eT*%24|!8V`ohw Кa wCjrbdDW,RMf^2^O: b^>|hCxI5[! 4)9`tz?9R,ou{yCl'OROD Z*A-V&?I9 U@ V,{H&μuZAh.7_zD!%HbxX,{gI>Sm&oTJ(Ըښ Y~vx9 P V  +nM5&;r9=5pK==b/Rm{|?/Xk+><^G>RfjCBxyrMso RʴǛڏo@se$QZY,SاoB>9'߻$9z?-!Mm2`%(qRiWY n֐"{D@㥫Կj(e^@>nC ZZFV2`V:O 7F1L>%O;3$Dt(tݗxG_~rwǯ\K Z)YP=O_*Si!/GjW/BpZ]zmyN-d` P Tl}޼(5m+vI  +\I \A H#lq ]կ/٘{?ӨA(:a&"6;~'5Wp袙A;~A_ݸSTBϏ}:(am92 nze wIH[.urbɿ6'~8.k8j?_\u0zJAaX>-f92tL~a5+n:i!{Ds]HpO8J &$ Hϓ28ť_TnnF5f0[$ʔE6yX !E8Ibs I7a;` >|U6>;Dda_UĪ nmlĖUsxH~[9tn\GT!YS]+_;R7ʸߟ]~vvJiNL4]H]EGK^#zo"n}TfD &-?bqC୹<`pyJWoXW{BM E<:Gj ebaO%WkJimc'g׾ xֈ|;W+BMXP|Pf8Q1_.M1EcvY ;- ˜ڹFtobE7 49bW~A`(nڝ1.Eh|L@0)%/ЭGV+VnĠ"L e5u^8.?o2Nǎ&A3T>JxL'NeEܴG,ŗ&7K}_̘̄Ҟ B9N٤] 4ؠKorx]já^G}bv&E %-4?-,'[^Wwuؚ7dn a{QHkt~{ND;2ٕf9~jB% P8sx7 !\aeIM*sB$gr9qP'!AJQr':aMN$3E/xPD-މ{&gnF%`΢C-i607UA>Rxhm o.LIOȏ }# cѢ+R3^Q;E=KIM&~x'5}JSIPXpߥ\&`ǃ(HubWb|itjIEKUokgcЀJT5;%:hj}M4<"Ig giNQQF!X;NXluau4uvͦw?MXþclR-OeP .׋{Pi>US GCWx.7^GUZٵX'>t{pp-cCxX1sW Jf9]mj4OpEEWfHt/띬l> *!/3G67~ʳXNg"i.bќDaa(b_`W^_'MWcuM{p#־ K5d-1tm>5ʱ^\L"&Cz2Nb}x%g_ x`Aj4"=8^_gf&NRƲvP&%'^DAkz`ҸlL4`MJ#guMt{1bwBZbTSLfay""- 7QV+'"D+dQU;^x#&[8{U}=8aRYϐԚ{όg[[C,e|Ub/ gcMk;bjD#nw[6i6RZ|Ak=πb@BSՆoZ ڍ(EpxfFU9vXiU_u}1C*vUSH b^xu5nCJ긎]؊q!`O~%J]ѕu-/ .(^7:SOػ\qP J%UTA}L(|:̦+߃&= fĖꨗ-:3aI\xfq: |tBF5at)LkBϢ!Ͱ}C%u_>QaQ0݋"9btoq81՗Gx z{F|a=3NMgdRقݱ_e,R M4-53Z4Οbaz4ԝ%giV!5 s`oY[ O><poQB!PkD3)SSS?Zrv Р?FH^}Ű nɰA ͭUƜ"?ä0LLT慃GpBnrCAVI+Ok&Nd&@4T)82UñF#K4ip Sp'P`9["_NV>$+Q& =hSBWg!f`AX)wp}a"*Ugo=!SGfYLL žMNo MMu[TSH'QtyWG%7P%uo`ܠxhGD MN=FL$On54aEDm Vd-(d\W s̀{7uah[ $$|+3H2i s̿QvbuE[4)RiESD? mh8Ōgw9idW%$Q =^C_0A 9RHMuӮ1&TCHnUπ|ސ5s ff{AYgq V)SE.|k8{\3Dbi`n|1^8zFנRo<2kbwM!*[IB,Hҷ[K)YTWH:sPCM1a.=vϯȀg9*H{VU%m} Xٷ!sˢlPXy<,Emdԉ$%%`JB.r1u CT_ &u&%%ڧb~Tz(fEV3IXN9(W/ĞФGLW@D.K~{# ,c12T-l0yٛqE:!XŎ>IZ6Ll_+*'t/z.qygi2 9S1זt{e1.OXkgO?0<OAdQ+cNFsܖ OT9(PANPxxn:5@ b.=ƥhWM|(!#ۗ"S\ekRGcVmBhuJ?iF9`%JCFIYM_w2TIIq9uCQCFmHV<v:H DF_2Ө4fs&@n-ZNP/KĚP# >ZLέfC?GB[Y>*P#$HJ7<"Aqpqs-Kn'i5,ni*S?EQS{խEfYc}%#gzh<}E9X}goz{9BC0JR'̠E1B$sh ZyE(ٳq~Lne^wICH8Cej2qħa_x.V~/gzv:pyBHLZ^W2HOPLI?u C)bD9'}+?sj肾A$;xUpEA.5]ącMGFԣh+KvQw-!XDBig弛Fkr^hTq<ZBREz1P;\8[U&JjRWCF%πۯKe{xhm"PQ2ȨOe!kj5ߨ wOu[6ĞʥM40ܗB7>6<쀤ga_DZ1W5fVĩͭK2U,"YX0qWG\@!>@96[*<={YYepDtN\ȭļds̏J3 )W jwHIu)ks\14~F\U؏k*,{ xNOb"0ɢNaS(LXFU%"4?Pxv. OwrhoXQr dprtp.~ZN34cI\][7|#ږ3rC\v͸ N 13NdwݧZS[Q}Lh >D5g4\|s(_sQKmp5p5EL"z!rDt-h5`gsioaj\'D [[ް;bWhha ,?" mbZ' * 2qINsrssBi{b {> BXM OsK"LK ,5diсF{DbME9; J|G\ vN=/ RX '2e[F-OPΣGIso6!E/&d4,Xb1f-WTngh%Y{Q/L6j{u9)!q_Y`>m{ntɹw rOgiU-JLᨃʼ/\UlAjh˨&>OCC t)⺕ݙ n,cJ*Nv3u[4Њ-=b9$%Ɂ<3؂ ?^Z- LpUy ^Slg/ ۼAE՚.G 9Sg4BW6u@ߵ*"b%M"k#,yDԐd5"tj(jB[+٭Yo[dqe:$ݏ%+"0o~9:yh<cYurM'mˉ31J؅Gذz̈́P7baI$_hTw:ę0œ2!WUV!hU$CBǵrug?&%ӥytʃ#KkMPsuxFs+xUG4 "UVHP~ Ϙ rʤNZ R͐}qE៞饇 ( 7 HƽhI $U&FߚTPr~EϬhrS'(~сGm펚(1"w;iqIQ/NQzX_R4%:t  mߨqqߟt]5z.0HjiN<{;c:şEBFkl-1^iݸ[]iPeb^>@jY!HѴEgUfw4(F6YrP[TN98'yPE\cZrN? b:)v0ӣQJ `Ydz;_4X*iӀ}m%ugt?{a zz1`t] q337dMRz*Yx*1S=':o sX1EwmaP-4|t+Bz6EN߃ѓd<TjT"kgRa>9dN8&eͫN&+DWMiK4r sHU'0 V3ʳd(3Ʉ%G{ZI]Θ^,*aӧ-5ajךD0RmK;+`zHP ~~%G[Ƅ{Dxg%w<۲y|v+K->1e!RVj/XaegGEP|," CM-c{Ce9\V_40g-I{ء.֟y Ako%'X㎢3v΍& 9_/<𭷑 ̽HC D_ICdyDӌܔW5ljr<ImR ? 6tXrU>H; jVc7KQwU?]HЃ^յ_v]|tQ6 B-0yƩ ̓U>ۆu{x9\]c{TO1XH n> ߫ !1n:7&^,ZI_v%<(|W:?4{sא/ Wwe-j%qrъ^ҟ+5хrbR "uP2cAhZL^IR^L\^!\cM4Xoc6g"U1q]n> ?2`>&J`i| cEȯ /ZeD΅4+ݾӁ#@=E.@5xn5@1N@^Ɛ&ǰ]^m\zO30u5ffWEuS#fܯc 5b\ VR@ ;'pyUKk#Ё7N=L;}/\ H%YΧ]1p=H[rg,wֺ1g0ZNQ3Y7xyALe E'6y5qD6j,ñ8JM˻hC)7WĎ ߟۜnؗ%iA#=pjUmO!cfngzVFJW&'wGm4l"$⦹Gi5@î Ok-@~^ez/B]h֬$){6s4T(xtä|~?˃fOwJ-#aV8TF:5;7 *'"36jDt n2em Ɍ1:$l )Uvb]]KZI/\Q懑Cf547}s QN\iJ&q()Y&ɼ^r<9zet쮟Zl -('iTwI-62Hmqj$M@?9;T0܎8,J⡫ EVHru!J([`0iZkve/됷)|ný& %M{&+3)cUv^ l1ρzE.7bC5_N~q@e|>g8Z+Qxfjz:\! [J70J=-Xx}ѵ%t!D=x"5s$ԧkJSJb.Cwv1J5hS{0;Rm֓-j6b:sŒn]͗-V!xEي4ċAܸ%ж8"SmNx,I.aM"%̀mމTl%lgR5I6UqA$^æ(0#9+!G蚔EzV}bMI6 [䛑Ib_dK}S 1ַ?"ixω  MX߆Z"F),gBǽBzR^r"Á8{ST{'+7eQzS[dt ?}:XQݚ&M-$ "?NU'j?,u;rqߘijԣ(֦^Yl&3yʹzF[~(< =ge۟^ 4_ Z(2 _ 8Cp0Q`,}Ia;GH K23^d6/&T!ٿ5F(X_d^}׿NGWpE*:J!;Q$ssn~³J aƯ в$a@2RG'Hd#> n bCCtu̩B` [{f!^b= 8;'@[PA_p^aSag#$r&>D~1[fh iSs|{@ -5-`Z.r"R=J+YQN1; |fUn9egĩ0H7~p3@i"pr m9'%Zq9$wGsVsY#bb9ye=!>)DgUɳqx; )Dqv Cs̀u$=AU`sҽ9_PkP kuT6OƏcߗ 3?̢oZcqO+EfWUZqM;iakU*qOGj"<IG%%hWzprslwmMr>İ zj"!oGdJy|:7˝%ഺJ@e-CdD_# xh dB{tf7'[Vq% +|J~:i+24"se$ tLंa:dcZ5r<7`Xt448;-jˇ56lݖ`JKNr4zz\FD<`rPAzq.DjDRͣdcs] Z2FuQ_=iD;F$[l[q ^"J Kݫ˞Cj<6xc-#\pXVx|~~pK{s&QAitM'uv>ǽTTxE(㺊z k$%7Eɯѧ4+2YŤL6 L:B*-HpF8=mkBѻ*J*>ő4]חoZEX=nBFo]*]f0 ?YSeIYSf_ z5*K+s'&Q*De'v&)K|n3C./2h%!9'f+i~Ii63c.z4fт{UoquS :>Udvj[MUjjLx9@ gl$5"ݦw8W.$mB/.&vDa0\.̦׹fL)9a&y'IRhA-~3Lfrb\+Bnҏ LG&c-lyksQkL "՞]omSG",g}OE9d_w?o"? r9z p 15R(ɘmۜʽ[Z&<Ӈ MA>DIX(w{R~7^R_zp <)/P@W =/5Ǚv3A&%(Zԏ9x{/XfVCx&BbE[[pY'J[7+m2Е~n[*_t*[c#⻐G(-s0B'z 4i_7$ĝCMqpP6W?uVIR\EGP߰sM+$=&[lJ-$)%sEv$Jlt5z;A,r'.7BLKډ'CW }-f%6GmNY?̈OR:l >9(r:>d%&D.yb$ΜgJB!(y T#GeW%8Љ~p&hЕ@D)#G͛αejAȿmUo'w!;TdJQg;C ZmOnpďf}¼W0[j>ǾM 9W8*?፥a :!Tlz{@IY99~A^b#|O-f鉿t ?I[*M\]VNcF_7IscjkߙNx$LL4o;+VD&aTzFe'7l̶.,p3^}i˺Q:-l>,.4#eN Pܜ~Q#: 6nm&ɲ=giAwO%x&˴s5Cshܦ?-;FE<},u6NHy}OE-&nab9Zŧ@(lGӥ]_ c $íE""zL0O7_qؗ9GvVKc S24`tskbP,{X60צG(Lx*|최RIJΎ+!ipb Rv^aP՛"ZNF'ЦCcI"Ѝ6P`k] "p@^x2Kƪ\fMS#qS=# Pۚ+ǃ 3;zs#=bD"g`JʥoW: D?ko+zۻ3[n4|40g'A[h,NNi0 )$Z 1=e\g0 4Kjr%j.i}X/bmۏ؅}9l!( yt"h #n@:^)'%vmJEcuMcFT.&}A=8baQ|i * LR e]W^x$5~tz*{޲/CZ|ڛM4z]37K?h!td攡E$cz0nu 0X#N1o(X_gzϲA'׿Q }UEt]$t.&Z6UXl*hbBw{1X)S+gI{ng/ *~r܆J&rؽf%O v";>p(G\wEՂ24{u[K"ElX|/X"UdT"!X@@tX>zouPHſ5|k=IftWm"J nz5 wtle*)Gdži+0şx+ G:ctQ<.fh)}ց}\řPР~YYMAÝ<.j"܇8${EVָГZpcHg}@Œ2+H4a={H"xng*(u0(;6'!P@,l=&lR1u^]dnl)a+^a \%-_n7O'*"z*&O 0ce8 Fti2t/G利;vlVYOרC5 >rjWΟZj e֦{= )h|z.R$o X_ PT ijtfTuĮ)*!wc\?LõX, Xddz+1.8$Gv̎V.N݀s@:@sC\ ]p6>j]c 򛿁BWL40ǂA41@3>(¯n~@WMĩY_|rѰ&^: 1ػbUyU7@ Z=JgHKE=U8v& '0:us-U<qs| Nj5R/T< ܒjM%j%7lT;E~s[TmBZ;8x:joDo i?jzZ7q;GY8+ʍ별y4)fWcc!r{G 8uՍ#? iLTl{A-8BB$=~hͲFŢ?u-gHgȕ_?~ cc%!4PtCŦw%D]1G`2ȴLzp[fCF>|<ܒVߤU};U{*ǯo<$]L ;s?X y('65Mb᎗2zn^ֿYYPC"6`Wb6xSY;83,剭,԰ rj}}ۖGfH̩\rYDш~1aLbX_]=߱.j̉,#b(DA]Ht L•Ef@u'dL=՘$<~ڭ3#&#~ jY/ô=DTgj\"=hZX*&fXx?̳u6p"|nuO  |%"iUe/!;~DL*>ԐJ%-hx[rBhj-Z<ITn$ 8FȐ&_GM_yvԘB}RPaDHj(+X]AcomYNF.gJyϕ^9z#6[3j|/M0 A2x7ύY"+:@Eرc)V$w=g22zN+&\ψ 4/%3MNm(.;_+vK{%/#B7_\P 0P#2 R"KԄ)/se|\7k:oJF1h`~llGߑ7]FéJ]n餳cٞ:P,'B$ 1/{@ET>]Lm.{K!Vc_eB˜o9o{oU@aXpX83yLSo|T-7 #ߋԀi*=Nx" Uč-@|Uq"~3j37-Z>VZNQ=:(!4esǾr'R LW ;|R0A4d jVK1= ܫ!9MtJb`L22ɾHXV%Wh ˀ$Ww}E%=r=(*^ iIj⌸7>K4l ;!R,U['d]vܼܚRR_3+_$D )مwAh 'b;N1]idn @ D[{4&YI } "#Zԇ!XWό;=O`-zݷ2vr9l/F{fWF;/Y:6BOKq$9ytB?H3-7K7e4[FO&EIQ L7Ԃ IvO{O5#v ױPҬc[IG* g"׃\T?מPek$VK %t;@CCghܣN`[,aŊ|6)s#[&幨UT}{++YLӄ)A~ vU҂%_n뺴:pH^,46%k9nĞvuΫq7"8֥`sBBR'ÒX?wj9(ʄYbKǓPD}$XW=,xgg@f^T%֎.O@@pfT)K}l 9NLƉ;v G|?RAp V}auv3 |B] *LPZMwhm 5dT &Oj [dc|j@8xXrLN¢ 3撳Où7`G[8P{ u #D\ʇj[kM)Lz"N9̗ZOڮdQ }Fo1jx}N^WBOR[S P >cU ó ]LVd3avAZ܂#Qt3Z]L(7 l$ޙC^J+eK--F8d#d[uVz~j;V$}C @][*,]”xolm ڒHDMǒQs,OMZ:b- қD(BU Kπ3SeN0UsDvtA]$t@ G . >¶!Ab,ˡiN ɋܙ{apoc*ߪF81HoRL|CK䔫l/k  "1Ґ7e#^%eA2bq -2U~UAnXmMA|_x*p) VAA|ې>Uq|U,jdQ)&Aϱ` ! ƩKRѼ˜e;U._ ia0Cyb +&t]uǿgvqpە@dy' h};,6d|!,%!+eG*x79V%$N~9ǎ%DI+[. 9TFh*jMf,(n?ˎa#9l}FJͷȣ K]&$H{~E8}*ɈpbL}/,]88AsTduO'\ޡ%\| ]̓wJ!:h`G ڱ %ĿUJ]/UܴT3tǭ`oh-ʪawd-=vdew(,{,El3텱AU9tCˮ5M/KTU+>-Tt Ae-N'qM1r ɔ >x}s}VT* u7h0ľ7/B[QhccU!+̧t=nls VZ4*xqtLKکP6E&[|A~c9KVN8=|PRYPݱ%Z_*.6^w0anno:ڃ7%׷VĀ?~?\C6,tE+aՙF˽2k'mk4¦%҆  fCv{'ﭦjcl Sd[绬9 K#X/kV%=,ƫas2;*%٘a>'#ѷfmŖѲ`y^}}WFqhUPMSӅB"I [~Ə(m%@ ST:CNŷYyE 2˭#Ŋ݈?,PhS_u9j,-q}YY6~+d|WQWo 3*s Vk{F=k 2;-hf&4&]s~=eN.@vEO 2O4O#p'/NlMOɢ* h;S1yZ(}F( ?Hx4uA^6bS <Wd[=`s%Ty#cI#a- B'lp6ዙyhoYZ9$y1N/O}cr82=Ml Ds3}2Qk~`mfznc\"kvһW 5քi8gxIjK)|I$bgâ6.F|{32$/g7h|LC_D^'etݱx\b &'Q#n,FMYN y(]8}fQU{8BP!7)ÐyF^%EPpz}e:ҊF`FF%},!L!hn*FP9V*[ W"n68v]SWC p Q}ݢF?A]O "Tņ RuA `&=!N (3,Y࠭U^4adːoG A#P0BzE Zhĭ 뷔ϗu-.dFSl4ܹDwT<-0ס?Fl䂒$nGcOU7qKGtֲ_JZ({h)/\K02 ~89b(cz٨&oW "`=C~ Bn.6 ڃjFwsT|Tt鍜Ϟ?TRhȘ2-n/"lPl m鍮Ī I'2zm)SMp`+MúJON/n 4<`֛ Oeq9}>TZ|-_j 5aA7ftaDhQ1 oE bŗ[٩ -B 4@Vqk^ϰɒ,XspW\j'VDx`BU+pTS6G^9Sۼ-3bJp^Ks._>qň 5G^) 4b^&*8hQiG/fX|{YGO~y Dԍ벁.^\v83 D22{NrIFn_u4!x^ X6Uw 0C$J/äu1R Sթ/hBAUv?c ,WF5&=OpN2̠Gf&[Av;˭5V{8zfa'q1XRM)ߙ_r`47&e|(c$X#?rג2۪^Fp641(XKȬNp9B8 NAg,$ؒGT*&Ք,Cxeg7QHqRm0n-e e6<+k17wjݗOJzOT@\hLĴ4JY2bj Y{njwilz:CZQh^ԧШ9ˠt@@4=|b3FNF0R>6yR `r#v6 fOM`/$PdhqA PZ:/7fWФN/# $C5 ^IFҫb5I?iaLP`͕2CWi$}XCٗ@-QL ͭG6-նjqfj1 uřt`;AKWlL]AW$N]i9JK%\ hU/rf-3k&!/@Ԫݧ$<1cKY_'Zp驩ވSH/, >MK=)ETXUXQ5i/^Y*;귱syc)~hNBua,%#XڣVP#Œh×)4=4SHAɄi yh>=`ha#lC]BrB 65?" X^gNJJk`@ΰtWHuPS@]$#`*;X8@S鄗K8a^n1aoi)$>pP:ZfZ M'u'mk}oUx8R'HxpwfQcb]U8\?ޫjv!9)n Զ,FP6%#F}mz響rړΗ!B!6\͚5Az[ ;y4G,1YҞ1 ִ<*M#P7CDL1k-:SNdE߬!U)9T@J|rgQ)jA/&6՛z&,C+Nؐ4Wdđ1QK|hm9N | ԏO?{^bHa(3avxmP_,n}0\|a( v”@4MMށ׫>4lu畗D6&[q }U0cK5pW6qt9;Tb{fp]LtZ._{/-KCfƳ3VX>4E*ޖ!2![iІQ~|[oT&FwArW5ʎbHw",[\ lvV`~#1N ޾!C}uT,xTun9MɐT|؂k%/vA ( A& m*yBzGD! x?IzRgyWryJ_Ӆ;6O'dx?CjewɼƧr>[(QcZ_>IxM7zof;{o}rЩbs*fUto㊔]aUc?PM5ơn^0V7N Vb\X|lrsZ0'̲~SA[zr!HǷU3 ˜-J8?)]BbzA bI\f&~\iVw!%_ųc'(*FGj9wyf5aPk4V2:4lh/Pv#A %-9z[t7v]z.`dfwEVq`0Q6W^ Ef?k-8ug]XWem*hn8;unNqM7 PA0|o w@Tx7~RS \_ɾ/Whgm'Jz- _OV9֯lSu>Fo3##XٕRC4 T&uO4ؖ  xSN#,2HN\O| ϼ$HFsqC_GrrRd|R-r}59YΫ_91~(7ĘlVWSu®qޛw ܀ێ=~ʖrLyTY \\ΩutXph47pjWd._▅\^ILp@*(kd~W/si_(!uZUm^QOy3j- 02 !1;xDtgcL{f,ƫ4dIq1:&N2^0w8,Rf/K)sQr %\vq_v*E6QmC9#*Դѡ%>]wJJZ/bB; Z7.s' "~ߟw}[쩱0~k2NPv'/#H?ؓ]t^ePBdq^|-gU}X 9ӹݲZR&P2n a#ySG]~) 8DȷWq-6u]*$Jk> cUk,?R-V/TzTG=lny9!K+B]Mܚ ǻGv Pv@/ &J>(t$CVCRF*9^._Ho$g-2$yK'v@n5Zd kA] lTV''^JנIqۮAUvep(]OoR1BmK'㪷Uzћ#Cqú_ԐyڠP@>Du)a׫Sl.@(b`kĮ 9Hл'ʬLKnB-& QۂI3y'd5P|؁Y QxQ…>yUK3,F+A\|svV9̗MsB>&ц Xtx'ag⤯W"ե{ڌZ%Z-$U쓙"ȑCmץw Cl2jL?t)i-Su݊EipVMyWyi׾byZ>oǚO+Sh4M.a{ߗv]h\f_.a_! DԼ,=88&;+ЃJ~onǭHA[ޮRvh Ys*m7M$w괸J?^eW)]^J<~-X(I%fw<&VF/S_}YȿahEb@V) Xy܄ +HQ791~'D8S6rfD i _ZTLu(2؀Hr2WL:BNa˘9RS*Rx ߺ/+'B2!r^lmVBAOQaA R\yvf 3IqOLC,hz c0&]J ld  eoAZ{ #ya x/,WXc'&@]g\p"<4B%Eo- 9B4Y]o`Nn_tKgH>S#XD@ %r=|?2ĕ']bc.d %AZ0^,N:yilcdŎ7! e_m>mmQfBW}JQJL?[ zl8XwͦIЎ;VV{w{H^dyvuVhђϭ"W](bujO' gpx10tԎ6ȼ<@f$Ƭt@h1۵R8譻Se:= qS|Sj-D^-wwqp:O@[J3J8\[]Qt+{BSD u}+[K`C1}[X>t6p+0c柔`yrpO=~:mإ7=0n4GļNMCu]q5 GaDd(s|p'qoB4 =Zr: lAdWć3 n4"\Jle:6X{yׇn\Z|| s#G lblk+{NR NZE`ҶSF}XLI4S^/hkpO:߹S^!*jc~Z62+.#; AwD_tCU=)(@9,ZV8_)](JXw cɟۯ # 'qژrHMb_< 3/@ tkM jR ^8~G,#yg0 B}Id[>mȇaF`|G{AfkYLOz+jM| 5aB8w?{R^C+ U9sӀe4)Qnr:HQI&qn!S׹#fLΊ:#C&ui7!0CO| [eX @ m)go&P/Uyr6z0\6/v?=)y+h}{ئL['cHq,okSdgGo^ڍ.f([r:i7KE}z.qZE0a_-Q';\n'z.GJ(](3?z!t*tqÔf[!Z8ڎ 9| _MaAQt&cR$gszi_+pZ! jE0@ ^vK7ގH OXMRZteǚO3g?*^6%\@$[}d3b yYz?mߦP"n!(^eE%T뇑 -GSKI[$j|}l ٺȠ7x%jkh<y UA;Ď(IsLmcڐOmJGۍYp2Eír{4Ҽ%2FA]}w]%er˟*2z\~1g{JaEk$lQDƂtB}a W;:?L!m:QtBtOCS0xSO;)#[4̥T CuU[]N㫻3h'_}8{#IdhŲa)L-DoL{\N;*@g-NG9G|C͂ ݭ98(<D6bu':_t@ɰOi՘`T)Fk463ݏ!Xdg8.tx1?j/綰k;ؤRt.ycR->;]kT,֏pqx+.S E~צlKrdzL$CRmF|nqo{юYzNp߄d=VwD_5y k Ҕ?!G/{dcQz*8Bs[]GBOlkӀߚh#w9V u|g??+.It^Y1. nԵO'dqyWR?7'IAʟd'9}1N(x-dQ0r 1H&nUNwbdZ,_d84K.4Ⱥ~x"oq Ϗ:f(ܨq¨1ikN-qK126 dWIPK_'yrӽ}Z2ЭP{(ip hwlFx[ 39wg x3$.13%S\xbO6 *:3JsJZ}яr[MQ JW( C/o<|'0o y™+ ?|طM0,}Կɣ{d5doS 2- =/Ќ!r$.ɎI%{}hKpa4\hU4-4C}DJ@׊dtTx$W{!^gDL3gxfs{KBL\o&Ԝ@-rPM@s|am[eoyY@ ǷrnowϷ1e87$VYj̿k $:*~EPɾUߧ56p K=I|9Nu*;$1)uT3BVjW>g >`)֜Ckk4kB$L@؇Y1˅8VƱILt˙LW; Q{#:}՜.{qT4xcd)Moq4j҄D9ay:Xnhۮi,:Ɍ"aIȋVf{V~}QЎj}gg~[uAdI[ȝLpeOBϻjkܤ*>IxOq6٪Lo1A%kD= H^D|=Fnwϯ0K85J'Ԗ:")G'Jz嵻:tEf)(4OڳPAG&fNIa#m RLgw:f%<;?~cl;hhΕ_¨7']!cF!^7Ϯ^X; NH},2Jb ״ѡg5\9,O,:V͗zEF Fc?kO4;<&ij@>ǑvĆ'qn]K&/Fn=J9h}HZok  |ުD b :죁gγǸsu!q?V|ޠOtyol<06SۭAo"& (3+)WnJ|LHW5PXgm_򖝴B3z(D izU:3d Y!;19d`WhײR z~{Ǣ3_%<ћt@Y-;#Rdb _\,.NiŻv'@SmZnj&#roTnlx-ʓE- ,3HD1X&Gc[kY,ɂI9zeD_HRԴa&Yp]eiEce aWK ڨ.3()KWa]-C0GD̎` `̉ݓk4 7RX;̪̂vm\ƕq /:Q?H$&L2rhq IݨE` isI] XdiYĴ0~>!B*(*1"DK ۯ={!TzӆޑXW:zh{'̮k8Am7_vme# yKVc f1,O|3ΦHXrY2[ԙ E@'"Embcbwoaniˬ6 ns{(/ '; b iೌl ۨrᎭ0u0?ޮ "&钙sN Wx-+uw/fmǻڊL0OO8BWS U?qËtGϞ~KNN| 059k`?~ZV7 wECW8ʏ@yv zxXb{a 8RO<~S ё$->%j4n<`KvJ'K@uDu&Ff*Pl%3\2V#.Y1*M6Yo %D]Q}.gU'xI4@:sr4<˷yu"ʹZ2nU?YN\؉&+M3>˼Jx8ކd= spHѷ+M9X%4b l-Hӆ"MDT{{p*{7AHMa>;{$~θaaK?޼:tW0 +O "7q&ohbt,C_jf{1)(*n"Ef`0P~"\=xRCcH]E8\|=d,]AJ~X2悊x$%. Ue/hS tަ3Wʔe?H>-gNFz6Ϙx7?XtNK;,B1JHuJP[ WhCGњ0}Zǐ4gw^˽{Jt~So2$/n MH-zg1\U CksMƎ^3 =f1k*!,y5EJ ovոD}tOHcwʊ-oXzX2AH鑸>TԹ!DK7*%>(1Bet "{ ZZz3~_Θջ)ICz "XvL`[}gS݇ߚ~tL V nB]O~Y82[}t۹LZ 11fKwh$˙e֤DG&pi_q8!\k"=MT5Zd.ci0 _h묄b v'?[okQiE-Zq@ԺGYpW_#})ъqoQw L\ػrez!0&!ijX4Vc|+GMqH,%J>}! ]ȋ>9 /뵍{յ8~< (~_k lo+ F&6;]F70<V+Uru[8 *)f` Ƹ#t5^Vv|8sA\X c)GLmyl(Ԩ|;s YV.u\ М@ qR{+hsaKx٩SwZ>YT)Igc? fЎvQθ[j] ŲVTWvvd+S6f" U:&6EKhNĻi'B8yJ1p^g 1u&p,yғl`X Gij ~"^_X^:ԶȟaTNcSAҋATBi>pw*ܸ,t]4dJ K1v n &@) sqe! oVvX/ژ+W]$ʪA{vx!FrmDg;v]VG꣢\̑&-[w.bg~~cP-umO0doN6Q/x"zLf&ԧ"S~|w%>D9'LF9"ѓD=\VO7Vl- !kNI<[ Qpae(6}Xr/d^μʐJ(m* ʐ"P\ʨ V/,3zd;8;mwhs0_V矦BiP|0Ѵ bYFs.oݲ>"Y1ts8bmwUMK0=4QENH<ԜDiyN?2&=m '~\^WD'mD`x2lg[O |[ yȓBIk,qwCGe+RkR:+Keif޾gVwč_CZT!#bYL4L&j4Leto:8$4CSd`пQ`a;oj.7w 1č=Rhq9h;kep6HE.XzHNЮƮpkɄsN"pPޤiU,֢Vȴx^+\~W<%#^l4d EA߬Kcَ{hg-LgX8 !fA%P=9κ$>$'6#i9gcB_6Zi@@ٗە2Vb;V5|ZV G׵eIldz,A^{XM8yIeb!&;B|Jb06$Ɯ7罵9Lj,tF 4ae d#xaZŋC_0ʩyCuTrrEBg+T9?Kָ$'oB bլ8Be*naR0ϪBBZmגc5Œx4xU[RW[2J/z֫؄Wj 9nW$kp1Ҍ #.FO Pwbo\m'Ԣʳ+m %4T3|kҠ=1$U`*U_bik4 ܪ>5`ŵM * skk0آ+kKuoEl@ZݔH #%8s-R:2v#jCR#Ԫy7Ss/a뚧pELZQJ+N;3Na70v7s`) mjH3I<#qDNmz}Pn<~yB7pT K.,}0{uH&͇m>gWaLl_( {yל6j_-R&״^> R@D=? 8@_ a Y70mt_^K2mդTgjȑPr8bZKl ʻL 1 [͏h4{Ke-הc3gD~ 8&KIG_ZLCC&Wcy<v$7S h;&5 OdF5;1U^ @+Z*b_Y=,†:΄ (ywmo׬Eռ>pgqj݃iתYb .Pd% bY1{()E^wK|5 Y: , Słq\)W)+Uh%etA 730ci9lCH{EKtMjz]a%Vah3IH2]Ks+;8Tݫ#yddgC̄vzawXur[ŝm#k?D?wqkYip 3@P:SCw9h5;6K~ퟡlې.oKf.C$\PPʭ{dQf5 HV14qR<ӈUf1[Ddu9I Q5m5GKksz!rOǴtNpgѯFsO2ഔģi E[w|eAdzn1` n9ghR=nZEmGptl.YHL Q%;Au&€ӵ $i&YDbQs D|۳eB1\ikoehZߚs_#WIj/ )c<_uC R=|̱f5Ig?ʵf3izb,Tq]KD!(EpGxҍ(/ f7uuPn0wT=_4}C׋=BzXYs&3vL ++ X?b Z-L5-)2eGAAg3@:qXqԱԾ,M+WeTiW7(vȭe[ʕ23$dղ#i` >e1ifJs({ٕdzst"ݬ>gqADY%Qʄ>bJ^" kŀ\B'6R]'`ߌvɖ])v;:"Nߴ@a!wlT?>|O#:d=Yy}Яw>. {b:󎏤R^-oo*5T ^syh}MHzDQw|Ew,_xI{:0w#gl|pqdkաl{Wqù{yjSPڭ\<= fMx|;KN~$̭ڙe:ڝ??#yb^\ģ k2ږ0lU(u]g"zuxQR{k T.l I{jS^=O^pI2SI gtZZwuA4W[#T׈PGթpvI,lY:i矤SF6KBᓩYsG@i:7Ƹ*j4hs ץ\Uµ+E,eH-f JKx o ƴjv-~8GsT6 `H=hZ، J뷫2T胂\24ǘ<"K1 )8T _SIEG#i;3MXzEhq yrOEfO&W…NDs/75漯M9*>Y(=; kEe+HhCkZr8czyEVN+ڛ)CsK^&c{qs_?k9I/ P+}!fָk8SňzS dԈH孫Vv4 UδtljLyq:Tjy-Xmq%%6XHX3wvfT.FN fUnF廵2%ɴ%P= CDc,RsjS}tdH_&aE[M p8M 6籴h8>r *b8U~{wVDBy<U $60CN _*:tJ82z@,ºf~=?^W$fiw< #g$]P ? Z*\4XnEc^I]sD07K#ẙS^ q9__)@[bUR!gˆcNc ؀#k-P1n3pѩ؏<~L'أ &8&Y΄y%>ѐRu4iKh4g$LڹEǻŠ+-} j,7(E}E'r~E.qZ>:o"SD`m(?E`XE]r|NL8l?#/v%,-y  !z Do*n*I2o*[JS'QJ?#oҊJ8*~8-s x#T}صyI)D/1mUzp1w!8̦%/2' _kE9u7 鯴s8eai0 sTQNLƕg<oB`Gq]Xݶ~f)Gl_UL⢗!P^O1K{gdQ8]lEfoECC]KV!i ~6us]4r zw k_$ɺ9Wt=L2QF շMپ WKJ>3#B&&1Jos1><=DI,[-yW6~eLh!7uH1m*c?كWDE$*'s9ӣͼUr85 wLO][1kHP 4ߢ7um5H +jgiT%% ~ÕҤUIzv͊۩GCh:Iy HC>r) aqL,F;Kl (u:,8|8-{24HO`Ӫ]1h,RV_ F~6$E03ecy./ j^bL?1xƆ`MwZTL Ak ˠBDgɉ,}SG&%,KOz\UQ{ìh74{ͱDSePrՙPXxʳm3(A>8APowr=ICdt(ָc_2O3zwP@.%yjqS};%Av0JOtLK5=!3ii¡ 2b&ˆ;dv:L"ZE1pvGa nF9ğe1 d P9o姶n#R9$$SwM[v$-z"}!<쥗ˋ zyuU=-䷈Tg{ۂO'ր>OQ}޾,Q"\ȚNWJF5 Kx>P<;yDO(3J:؇* y"!<}b3׾5$ sצSv(m&qpj(#bL2Ui%X>jx(%?hzF.NCZώ͞o!ؾN>=wUړѡEj&Jq),e>YB3Jˣ?O3bHى YL`Y1^!c;eqwusH]]C6;T68;6>ʢ>D,@vV[MCw;Z;] }駍JoSTrpٸ)?4H4ڌ!rfqBl-3MC5]ZO10r @fk ~ CljDazrsı" I=AIM5sE?vK8ũqiui{ xHϔ"z٧ȩpDI"Q}HJ5k9?\?{CPBJ aŤ C9@m$:S R߾O/Efq<\Mz ]yбB>﷍U rcD!}FR 9L)7Y 5Dq Ҳ!\XF{m|48~XB@zH5$0HADJ5y>W?rmv!aM.8v {t ,A][Rivne]g!&|=yV??_f !f2p2G8{6x H=cq*~=g8Z'۪d{֚ ?f7JcmEo1vO>=4R(*ſ4r鴀Y%_ijtIS:OӯIU] cl Om]8 }$%vH1ǵ:PQ|,/NH]rЅ"^QRˤ 뉧t/86P/Gf^+L /<"KHAMR\kDd9TNޟ]2xm>lȩ7 i/m>:HLI8 t=.S[0wg֭VX 6rh3=u.;#vС,-mָ D!`c֭p$Xx.0$M@2^Rtfx` Bk}:tFH>k>>60z!G.ւK*m{,c7'qU/SLB+ݲľƎϥV*~5!gP${ٛ$ᤷӒ /AD`JBڳG8DNanD`ػ4 #5B'O{Z^^Uy #n _36H2jYUw 'swʳO.Ӏ:d*IA}xiLynܟj 1]:6[yShe46›]s&(iqJ~ « W؁2^#5N8;JhS;=D: `9"Eg ^v}hc/-:WG\WEY?dv܌ӛ9` oֳbPofNmms_4!tV5 6 hAdL%R!lG<'2 v]6gC2BnJ$?mU˧^_zM86e*i s_+  {+"Uscu#1w}^\1 !! L3O JDP3~|#Q/~`|zaC,y.S,Λ@% 7a&Yُhc#]QWX!% ?"qBkKlxAEI-t,%>r()?3iexVQtIdpέu^E19BC  ,<>>ųkO͛1ʒ0r@_Ų=- $]?tg ت޲~1ax.[u Qo{8C'xf nK3͵ލqIG/>>نK-~ljhXUʻO :RRI |*gGu%/_D FcɱA>t~Of5n@vÎguBNp?ʷg0>$Uƒ]xXBAntp>g!;s^|D'ުT;Lg*cvnWb:u1m_*)=m|jlAq4s ItL4QTߣ?uIIqI%fL$t;ex~ !{bK@?Dۺ8EC1ZW m(<Փfb6GLD@)a/e 1mmջJ8 D_ݔ׻{<#Y `5IN(bpa'-%P_ŵUgὦEl-w*c(TH[m"hO -t9|>(~ [PuM]~911 #29v-`폟ア)Hmrf{9|gv܃ pҔ}y:5fgkqL G2)Kq%VO;;M?&ކ/JR@hrPr6O'Wsb3zLwV_"&Mmu}iݭ,}׵^OWb$}9 _O'}Y:D'Mc_J` GPݑ =i{0Tbn};(Ts~Xw5>HGػ'2r'$(ChxU4̉^3׮ADLwgK}F/h.Y$\LbT1Zgn K /|VJRq;a==F"׎fat-^xvDCCgv7 IآD݈EhT:U.W?1"ׂӉ0\6, m+ք^[Kb4e`%yɿ_Ŕ!O y5hܶonܘ.w( Y8ϼom`"תPZ-턎$`^KWyHKrSt}§ɛp.LnClBm6L{B1mt@@ Xez1.C% ##땿fw)8oex|%INOU(Qv0&0 ǖkMkrXl3Q*yANla[Vi\S. Xj\;]$YWK.zA2yr\u tv;l@? &D~d]oq-tQ7X+pB#,u6y'eGg~}Ѐm氈6ǃȿ+s6)t79vA%M7B+0R_i#XV=t(Kt^cS$K C6;^Jni?!"oMUreIWWf37^;hs*s"o6T7!h-[_'HbtiH? r_NpoB5fFΕ~>`8#QlvC> ޒVsJijv;tĹ )W0Ibc \QހY~C e'5 :rNZS8O=2qA&>{dC¹Cp7`B-TǼm ab6LW#,I#:!%SឍH' gS,ޔ_ Fv]jȘ৆СϡL4I;2<f~Q>/ oys赐ޙbFM\OS[Ʈ1zg1')vcK< v~E?qMT翟ZpI&~&Q``8mӷ?Y"*'VfSMMQf݆zTd#(}Y˾vlF]*IY@-4SΧWW'r)_1=FMSd̤^& WX$3 o:5@oGjF ;H}=Dl2_K'@ U<%lEC/YC90X e r^9XBli"myUzWGVe&.U: L)؉D\PZhX-jc Β^)zK@jf#Bu:yџ8N>)!N<ŋ4\cwFqf{ٵ ΊzAݠ@MyT(eH w@s׿~y^<1:^F ʓ wFoo˨wߏat z]4y x!P"嘘6mfA tU/ BLK4`S=m$C*ji%Le/[]EĖ(yi&f35V_)=g!'qMQ1TԘeDݩ'ٳ3( w7xP#ξ׫"#+39Bɏ UO*.B]ӷ@ᛛ٫H{ ^IzjΚ6ffМ!2z](lv͆}DؗV]nv/7)A*ӧOw&]`'>}*C5?'Am4TT?SFjZi%ֆ7z'D ]g?orh}:fK~z f;GJbxBJЀM @ j _`#5wѪxW1Jh2þӭR k ;U4NI_豐h\'Ҷ062޳tB* JiCˣ ;GECI#>8A#9x$er,dxi %h;o;VˈMbJHզK(:>jF8o4Qf=Oh93M@}znL`0/,Gj% Տ|jEX4eNHj_(1+CVm,Ϗدc6lrh*AUfRI [hƚîH9Yιwza@D.^+|{=JD-%kpcM~s;VZ{7/XiPM2X~.2InIh 4\'=_^L1~.Y'q~#&'-YEs͈( M, Lš-l_'5L1<Op9z[=m}:)UBЖ6u3_}GFEg2iK֞;eKk#eȒZ uhogIV,g-7u+c Ғô:ʝzyH_fAIJ~ĤD gn;XtWU5$D:~++ މ5{|`̐9#IR:y%.i!-1B` IOuxQFV9 ;ljI=!>r,7QċY鯔Bmæaق8i|^:hIó $radHXO|6G4F@ -:GRSjey?nvRl˦YnYsȌ^%7EJmk2ӫVZM̓VGbUs'<09YpGA,NFBԣR\~!&(jj^Sa26