libsamba-errors0-4.13.4+git.187.5ad4708741a-1.34 >  A `rp9|$q{vf1 YZ* UhI`8UT7R]0+ Oeٴ,w6h dguWVT^~9ڂ?w-aDH[D0O\UPREvvGcٰE"\/%=?=~eoB/tqajWNgݘrM` h$xZ^:^_o+Z9e4ZQexgR\3K0l3ff58a09df8a3a1c9687768bd6ecbeb5952656a7dc7e21ec537703fc08718e914683c8d5f41706c6616245052f9c257ca875f50814`rp9|ytj|GX^IBkCX[W5>cfWv{R-Vwzjof&$$s8ou,m:-D7 %}|٭eiRh(qNJYlɑW"UX#Z7JwFbfG5qS'{M~b©pOW Rͳ q'| Zoi'2{L.1.qy .]4X_Xv4G|vX4ik*H5ies< ? 5:)+NQjy{`9>p@ф?td. 3 Q "9?HL N P T  P |  (89,:>Ί@ΙFΨGμHIXY\] ^5bAcdAeFfIlKu\v`wxyz$(.pClibsamba-errors04.13.4+git.187.5ad4708741a1.34Samba errors handling libraryThis subpackage contains libraries to handle and translate NT error codes.` s390zp388SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/System/Librarieshttps://www.samba.org/linuxs390x8` 14a7f0b11b161560612f3a48a0232e8b508b305599a2a93010dfa873afc0e5d4rootrootsamba-4.13.4+git.187.5ad4708741a-1.34.src.rpmlibsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-errors0libsamba-errors0(s390-64)@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1`@___i_@_|\@_{ _l@_i@_d@__ @^@^^2^2^^1^^Y^J@^2@^&^&]]]])]@]@]]@]nU]nU]i]e@]_@]J@]B@] #]:\ڭ\\@\@\ \N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USascabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigs390zp38 16203153384.13.4+git.187.5ad4708741a-1.344.13.4+git.187.5ad4708741a-1.34libsamba-errors.so.1/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:SLE-15-SP3:GA/standard/b5c3032238a4e7a6b51699004483c0c4-sambacpioxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2e0d746650acda4906bc7faceaf8196400d1b2d2, strippedPPRRRRRl>eJ򴇂utf-8a6b090c269fd10c665eb0ef0fea1170f6936d3a0900e7c3c5054f9e20e884a19?7zXZ !t/k] crv9w InKg2Db\x@C(,<?k:5BseOzV'km |]F Oɘ#L;²lͨЍ 'N.P#re!vsH KEgTbu[pF h=";b)Kpu];u*qO``Do 5-aX1W!XWoTS¿T7njK24+D 9#Jϕq7f4nv ukX2e= 'D4Ā7Yٸf @~Ws^'FT1n.r~.Z,&hL/KQppvqNr>g{]31To(A@eibL7@Ros;  kyfaMA"E̶?W0bN-%9(dTs[D3)֣ rb8t&nx+u}xR˩҉MW>;ЩbS8ޢU>ai4_Rx͎N=3RYgo|Q?7;My*@"9[;7avۺβbCloڟ+3z|VIg-ǽ*|]k@eZR8).1ҩ(o{xms C؅XXKK-fUo=IaW_w1(+auQ:W3Gy;>?~l%1 $;`tY7y$˨$1֥?tcYH%s9^<C=$(Fc1'A+--{@J%cY#ިJŖ5 uU Ar{6v XP>%+*KsJ52%2*ԋJ&⩤PBDYiIsb~u|0zN^1hCDk|ŶCzxtv_8e(W&y3خ&cF윰ur?Nk9 8A?Ya7J 8jsâJ%2ס[&Г9F>R:;-'Z CZJXX_0v9r*ߞk"Cc6S4^1Ca. 0@1gἭ6cOY/E[k鵣ٸ &lM@r%\cxORsz*8ʙW?l 9l6~EjIՃp*G~zXc ! e"]Eu/)*k `$0Txٰmk_;\ wgy9h296T~F,~r[p$!q|jڗLcD xqdyZGfrN˚w;MVzB (2IMtZ69C P{!C=%2 &7R=41-MsBZ[ 7|n"PR2|xoHMkh 2pmI`һXGuQRsBcktS0*^J]#kdlf q!EbS?nndؙ$wlyxS95oۑ;ɋK=QYu†1ѦCt΍-%Nc7},nE(%7ytwrM!})%<|ɫjliSVBҭf;jU"mͲTi s=1݄N>|Q7A_(Pui45Xie)FecVַE/٥ex}d]I)̕3q9.kb)Z JIr3YXV4L@K,7 !e@JGs GOih6 NOO:Њ?:7:= /bZcyx\㊘T;3!GN Ēܑ;EW\߹psUn᱈dW|Eᾆ[/𾗎F/W{B P6gE`:5M6 llt]]C;dԗ/ ,m@.mȊ5ǢǴQOJ0QR7=*d: 9еAQi)_/r}^?Se #oD pճ n#-z` .Anqz܇uz';25OitCɒПjeb)0ΪpFK~=~/F5#R w&b:F=.Nއ`+[_׌#HT.fzk,\-&Yk:@)!QFJk=? xӾsT{U ܊aSL|ݣ2t \/5o^Ա6SN;|& /enrN6& -BυvqG]TB-G7 )&:zzcg6PN[m6U]'6itpkN7KLmk55<%1q!e\=觸>ujnZ\P>l( _G>f8޵  G/4oçF;Go"~.6Ub"@XJXsӟ Vf ;J)y?>F{31ݨw@݁W_ Cr8e@k^; Ʒ̓[85fs`#W[]7&‸.'lPc٦6`Z@8kIؘmk=s쉢@0Ƿt9fƑw:mGxUe yLɫ<xbш_ץ=sSȑyXQĹPh ș_a4o&N1I0y G3T9JNUxYàZ.1&/S`?G䇓H({i%Dmh[v<0ct ^#Ps% ~/}jy<=j74T\К*Ȕ8R`:UYG6_jOm,EtbSugX`!s4ߤЅ}+[+#Nu;~ j*v6MXfkwkARa;i_\1<]^@c,bm*)q{,GkI 6 Y׻$<;/al9=-5yOE>$C;XsN@cN2E~cFؼ$g4&|O ErlY$-*T?eLr;0Nؕ4omd d+euMՙmIak5mEdXӂ*IJV|>f-p<Ֆ/1 *(dqhg}ydO2R ts|)XQ|P0^=l2+l_W)f.ڵg]B\ :$4#d7똤ȭk% DO|4Yݗ#4S Im7Mѩ9xÃh йEI]c'Pq}ߥŧR6w{DKpfSQ BΙk@ ~l"ܫjY-?<'hA.nCZe^GaCSZ;!í_r3-+0 (2vFjh5ܐ>+1XF3J;FLtnI 0pKܨ6庺 _ZBd ;! >_e(lEA2HT~K\[\Dx(x<Lmkgw7JerV$/*9!zlnۆ=CEHGzYfQXiIB)Y-n r%Xg嫵YAؽV_H BNzTWh*FMPͥAf\ux_8񱏻p;m>"rj3N}KM]痣BtGI2i{QM[6M5IW,O t,QK(뜻eXfPUU0[mgwIqmD8L, xͰ=''x8-ҽWWTܣzs'@6\1iEujHKn8slBZ<4fq[E̛M,xflX(-{P/&`\VO)4|ѫGD ':-~ s2p_?; 22bV_.a/Bs7N}q(=mh_# ?\][}>PMJMT_J: tp@,R )o\l޵'g饃›A 0~ipҊ Þ" [fCSH(P?)kdžФ&A`;eBh?⃆[8r) OwtEYnkh!ha{ŸP:@tȣuqw<7:[XWSNѦ[嗐z&A9 p 1|ʓS2U% lhN ~VGb.Ftۜ+v̑/JJZ6ڰH]S u?u:zڪDhQKPWW5-q-~y$㣦qrƒʙu`@jw%SWMqy\w pAgS;uP-[ o #5[֯} F20< _X і"wj#;M{%]Ē%$cB8qgHg{$-fOKZу΄vf.0ZeBfez{{;fo[}aQWW {t4, ⪯'OGU/{\oyO'hЪW>I T]s | Y.Z޿#ܪM*$- ^~k)Z>hi@6I#iM;p:yZ!{>FD 1` e#{abMԸGzo(+{@\NO>żKmw;8TpSPSO8PqAB6}[L7ح PgHa(>J!J 59h,cm'w{Ln]j<ޒ C(V {u^ϼ#.YGUGߏZByDr2Uto5;#4!{Y}Ju#Y*Xný۴ -}3f%J(:ͶQ2 ʕVEELs D%?Jx8b\c?h<`H&)Sꬬ?ĝrs*o'?]ab$RPϮh`_S t0#+|aM~*qMW؊h@,Q!ۂEo9-% SClʝ$"ɳsRjnEhoYqxcRS'Qk8l.F23?gs'ޚGAԣw@ %]0Re²80 YzdWVw8jG 7-džXDEUΪq$ЌgfY:"dyp %fB5"#EPlh:8)FKhڎxDiFD%/[x(RXcs>&485RaM*͋#=Qrk٘0b'ywL!Ns̷' w(>Cl?0eX2@0̨SI]ËOxʡ@-2W՝V{={RxjSN473『j4ѡw&LEߴN9z(*Z0cJQ < P3c2snёM7;k$k"_y!!z T -a"cwf/l+U_@;O 1=I3UG 2i#Hh:D0Ώ=Zo,wp&Խs`"2pF1| ^x{'P:bB<C.O ScS7yoU }5n< $^VΣ֮d,)qgWEV?:;c;+{GR*yGT.΋]T{F1v.B(m:79滸0`Q2EҹX]~?t^X3$+٬C@!w?J`2"hڂS\cU8G1r>Llbݚh2KkxΗK/w8em3/W~D~Y{sͮva{gT0pRmR6:m:)9 ˪۫tIL pۦtP (MD0ِ W׶ A5-^Y$p'#慾8;rI& tKc[p|}cP5[-~wG-n:zOǮl\@ra*{n@xSALI6OAD^*?D,C?3LyL7o=`n\TБ /EVsP9Y &$@&2Y m̳Jj{A=}T+>i]}sܾa8`Y IS̭@Y̵ޭ%4|v{/0cV !2[  ez)kwiTQ;Jԩ2 Ɲ)nOnذ't^l&`jɐI%} ?CB>eHqRzq,!ٰjI&si6x`.QT8R'3D([7l7a=G׌߲f^=39kwT\ȈXoER*Y|D{pg 5ӇaOtY$;c^dGtK\yzuq9[K:>CB3`('I}ѣZԄJj0#a=쭍3 iS27@5E >|\(:*4dZ&6Zrz)ށ', lk7҃.7ƒҷ10᥿™{qda*>4VQP}0P[dN<3M&!Hy }F0{` Sդ8)U^I?# >j 4.F=Y0Rh>>Ƕ՝S*UlMI"|GAnp"Wɉyeq@\EH,{dӇM3KRPo1* yLCtsͿy*]0CcMŔ_+♩nPQa:HV2RHcUPqk1)x[DK3dpդYr)b'L dbg YZQէ~m=$[ȧc|/b,1EQdEH_fscf h̗+YZiRrfw6GlJ$f@/ Zr0HGWGpXKg_KQWtw#Biʁ KwU½&#O:nڠQ?`0g >esüHUHM*a]d bJ^-w|܇"ՔEHQtUT~ͳK"OXKmYre]Ԭ-{;IP-zhc":1-/Ѥg2CQ%f^ ;C5-ZjOj&)YBy.#c= X! B"*KP (Qoݫmtg  L~0Ix l?5z'd($XܿaOJS%s/lCԚ^jb"Y >;-V ].ov,Ljn+khY7}`Vgϖoܸ *T'c!$S]'O<,%ԉu)qL>`˔x+ڄl?kswስH cȉa}5[]29k<*Ӝb 2F~W=y4nqvQ \l$=,_>?Gp RKԶMONs'WT-p 0 cPJwFUJ6JBr¹T0%A*Bk[ &"*3: Ry\GW45@S)@ӈ*y39V]h|bwq?:8[gOES=`x||%FSKLD\]6b9!$4E1[#kf@4wN|!az+$tAHo[@M.4hvNNz}hX||rL?^ |Ẻs#7 F37/ l![iB74j\a&OSneNf2`];.rѻiWPK3j-2DI4J e E"s=bt&j]_jh6nGCvZ6qQ|q?Q{P7M1Z6eg%&1'[MG)h5>My\aw@ H\[3<[s8leY _ڔ\Q;᫦nu3>95% ҇l_g|IIku]`N̗g1Roڙ~DyQKٴaP^iʏl'FӖ24:\^ޖdV޺ENj(el㉲nC`ߊi",3#) jQv/u}8rpJh7kU1yͳMvTr'0'`= s0:6АÙ#PNLbk&D˳W 0UCWM \-ONM%EU'AרF6' ﻗcM[rn @/yt eY߱Chi XW\ r__څ1ՇZu7_w Mj`#S"a'I胏8וYxPk'T6I Kef/m2ԗrLrV~Si7z "=5CMxyWmu2P}|DpgT^XoM(!M ju׭f.o׊(FBi)#@6ر%ˤAyU_zk)~XmpUCoTלdcD,[_@:IƦF]iT @z+'h; %#+zNE0L&9uƨr})tG"+JcDR? tݼq N_ iU =ɭwFXBV#1OuTNhH:p/𔌷j4$Zڅ'axhݜZ" U(Ѣ nL~y0Wf.j{ؚͶct k!w|)c_1J 3w*}OlwOc_1 ;2Ygm[%zfmDS>G >*ҕџGg6> kG/:HOor,cʂ譜>\9{,,8v$M( ۓ O$aBfEsޚ(BPyQ"&[dHAlhpjy }gcǃ/Ou9-$D COrTSjnz{zc21d;"or@{nV`sGƳ a/`ukr/iezUx@Nz4 !HH;G_ÙRď :=zW!7 >ݍϾ@QpO H+FqS*6Ke7Uv}a s%ؙC#czĘ90xJ0P7N]q.]pJz|wy:B}\U%DmqXFA5ߡ l+\-xɺzo!(O7h+pvԺ"H&Ħ+if1hi(b݌?*uI!@ ,#s1Z9=SooO`Zlkκa6"V.F럙d4wrFqBj-E7"2R {w/$z:CZK/{%wZbyB7:R_{߉=ɟMӍ!ulaYDŽ= ܔC_!idPZ|_ h҂ERMIh#A2f@[(K'tP] 1O6J: èd*|"$QR-AopYt[9z[2`L\C#LY;3C9+Li +Tu6"E 3mQcT15>%gRw4.v+Q }ծhNf/`;B5\5鸳3.0{i',A(vhZ.%Bz\! %5WU˺̀Nv`ͦkDڨJظ x'¹9w]4߸7_a)iHCD,1̲<>'39Pdb݀ډčsS,7[˱NN4M"#|ׁqYqV3520{Us[>뫃H_M}*_Vغ?;%8߸"*,µ톖KalҊA [qX NΥ}ƯarAgzqǥW2r u˜{>g4;]FC&D(]coN5AUnD9=4$w]dG}j_E3ۇt̠PoHIDk?:>YCvJ5 i=Ȏ5?w? |jqD A ~y 0Jb$e*SwvN};f_}C[>BcB$g't\5(.a~Ȁ-mY߽MNGmΣna&T(zOwƸ^Ȼ+v o>e>pWþE)縭}idGCA=j}(FW!TΰC@s VfMwvq Y3[H,@nB.?C^l @%ь̜^ۖ ȝ!"eJ7:8G焤N:ӅuB)qzo!3_:p0m&?o X,M43QPKD\6Ƭ HO !w):6:qbJʛ6&6k@^-F(쐴w]&gɣn*\\H%`ҵZ%ߴZg \5K{sTZy>Y2y¤P`E1v#WUɎ*A8%]옌0rg3#Z)!NUHVeB19Y\͗ߙäcEv={}KޥO7d[ '/L0@.; жI-bOިͻi7ٺE7Z 6#l]6u{: 29f6xuS,Bϡ-e?H?Y 8øYR,'eS dTM !I:lXРPF\plQq:#fm8`} 5#N9X M-xH? RF  ӣ0WVzր x\z0M$s}F?+[;6Y 'CqTd-t "p)e*jZu7Jz;}(dD?h+U4 X?S ~> b܌VG's(\ue[.xfeDANFmˑIf-1[D T ٳB &̧PkT[p\5Dcr?,6]9 2ƫGDOF"a bDa,jX8? l+\+(uǗo$/i E~Rկ}̷?~b77u$ ej9wN=ǨZ*?5;`FHir@U|;9//F"V ,>l]6<=} -_䄔SrY*xvh, ZǨɯe$\;7ԭ ;#ЄQTo)[59_Q,U_NTԩl0nh&{' XK:0qwv{ebG7 %P5)`%pH![s[*"j´m[,f 7@-&uw$V2v٣czWz=htxΊ#(TPl@-;Z>WjOJ/.= ;|5a&,1g,j #%]=)Fm JN?i.̘R6v{V$ 4؇ Wz)SF]f @Ö&DNny0j7GYdXx !4[B79`8J;1hNc07|E l&+6a⪚XK4-f 2u^*>0 36gVnƱ!]CRܪ -EXj߬*rOdPp"jV072?޸4<>`@M#:�<ƟϧZF^"( 粦֌kL(QU{M`V0i+{;]Avq,^rQ3pf,S\kHCq]ۣd.1i؉p5OGʈY8هPD4 >eȺSK2Q8A &0͸ڗQ2[GvȆdB#QIS[AwP[ߟ4d=O~QQ\'Y+iag,ai#7Cqࠦcʹu/'Rq`#*9CN0~5Bnkdr`m?9ng %E!M]$~]*@50 x b)ݜ+:GYڥA1+9:I|dǹlP!;hX M\cB,~ #m@Gj4MĞ:W`PfԺ68Zh#⩁_%oNE-E67m8!#'/!))s#=ٰUQe^;R Gԏ@Lf/ж6$l+&Dy<= D n7s<̴Def.2|gҡngWm6TE5yA;D,u@ͬo+W2}+9+Ct2#Ȓ%461f6'# hۄC]S65KPGK1\H)1w1I*d?~'5<ΘB 4#NVqJa;{-7[A,}d\ ,Ga,)lAԶ鍘0*+k9se՟냾efM0L{MZmcq(5aEg2Ƿwe4X}u8>2U CZ srBAB"-YZygOߞ]oPȟ"+ 7-+Ed 2@!;m{6\G1 Ta1R/ c@*L|nԟ#mqT]DJ(C}ft3gÛK̉A}K@_AaT.{ @[ p  ~]m>bҞԙ;MAJ^{fM`ZAB'x Ŏ}oP8c: B/QO!Y 尤؁y}^]ʜBF,-UگyZ$bLY9n4)k򡤑JJbpg/L?4s\: ~mTXEݩUsc"^[z-(%,Iks]pvWeF/imܚ_p98'g$ckб@*}%#\~Q"}O+Xbk֗G<|S8(,9oqydmU+KlyV $L.G*vj[.`5Vu EC9HdS5k];x|TјrdɄb"1yȋOt[lW` %þj-ZmUY6?`^SPϧIA[Fp(r6ڞҵq JӮwP-JƤ) 4̊P*(A.{3 V(!_mJDǏs Af٠*,eRFv*(N7ZUL~j]4I'?vW}zFm=h+bm+ĩ,犱sNo✇Fs?uA2 otxD|w)0lf|vDN28Rk$kK{ɼB*->^ ="P)T+Q

Lيig L4# OnpWdxe35 TϏe{gXo#W1_[$?<8,6)K=O) 虱ԓN2~iy#A,i6>@ll:1y$."öWcuN!YthמZ_cQ ~Nȋ=wDHݜ4p!rq[fLh~ X圔4UhclC]#Ck/+DNpriZ!hVQ3SF]f$- JԟĿ~8*i>TG{[(m"9nL |#Oza&(a0awfDup?7^3bOe7V5G .` PO; 2۟G(nX<{hHvF# ONؠ G@qTK1eݜX]u'9ph砎00N:M<@c~H[B?܀!".tK~Cҽ}⣷:O;Mm]!]/ǡ,|%P'i4 O_%Be)oS0xL_ߵM+` oԅ쏦:iPcT*rHw4:9G.т}׳L=.V.鳻# ?}Jؕ o %Ľ%fq }u XgEv tȤ~C~ ^ye;4DiCʠ>;mP+~xF[\0S`"Kv1r2<[G H(S ([C[*&~ˇq1&&C~lḱͷ9Tv߱=nyMdq O)1QD jKHl|/C{Q{˕rpq@cI>[p0Ĉk:Dc܃Qs ./ڮEv>yAő.9asi ;L jq^Z9AƋ> mi$4J#3"KU\[iEYbϗA~9Sv;bl6<=sws/GnAofW_d6:Ng 7NQEAyD~Fb`ھ^'qZ6HHS~,rAD`s#vB|uc_vXԸ['7ŝeza0^mWQe,鯿g\vmUn)quǯŵ:r$LӵUJL)@~f5tvyD 6QОiu UnpoJaS >'Y򬏧>q6dv}{-)=(Hj]gF~%61*gʟlF= 2Jq 58TW(bnӇ *^ 4 f!S-O@*'c4 (M?z{Ojj9v_(UL!Rq 3p`Ѓ q0%m')y3-[r[v UJ an7U&~9Ye yٽnPwVu ro=wT##4tB# RAB,D jƃ漚JE-q5lul-?7}) 5iRAX>\:0aVu01Jf>3XȠ>%-<K9c+ߎ7AiB-JCm^f͡5cI!Zaʾ(e,\}HϫF*, s>YST^E%slͽqVr1m'2b~J]7cbV4I?[^ԝPzӎBoBP`յZa lIHL&hQ۾)'U_ Ȃs+Qj0@ծ}1a42CRP`lq B) ^Whñ3v|u19;<i^w-s0՚w/jdo:xiH{n\& w{ jvϵ-mw]L_yVOr!Z\rI$I d"=ab6IviB8 8|18J.N,wsլ?zeJȱC:&ō5k/-NGӅ\ ?84Oؑ^"drlG/ay kATP=H NU`V *ör'O\shWɵe.9)vC;K㘤!ifc 3GRJ0˗jOI0r ~] H/nwR;0")&Mp,\]c+h 'wC~T`@40첟G*k+3\@g/%'r>paܩN3,ǚB.@я͵Nd91ڝg.J1mEUۨf4=_&кi 'Kp%U L9{8,bKkXr5U{;&m8賔\_EѿZp&흺k|&i#a]!}8ZUnB#6<1)`}>N/: ptxm@"^Qg$Tr؏}ŽC 4GX=4g_V4 U/ DC+sgگm8y(G}^^zz-,?P7G3SzWCLt}xE}dOLP}ҁrw )38|"POF獅F+5GH_ C1*"7z@(f?:B!QphިMCv.\H#7kGgԊDɧ}vӝ,c2.!*#tCj0nGWn䐋i!㤊:R1SrX8-SR>#!vXJ"tc nRkK2 OԖxlw9|FXLwh* '(N6\kEjyu]DU)K[uw~6ԮyƔyQ؊9-kONx֒HT88-!Qƕz*B1%'hj7caXtVf=NotBk{gL~jo&kk+=T(/E* Am`yVuDNk++ :C?3X^9tB_U Ȧ .`e?dUX&(+$ȻGq})bKxgHs$[ }.䐤BQa Yܠ{5Zj,%YJЕIHY|KZp]K T:;܏M*hN!6)cZM x鿎)Uq﹒2ϩ%VC~ H0C+g>j]bjTY^G/D{ S>M$زu!RyrnT:6ȼn3g9}/Sz3߶;CA_C2Ҝ4353 zĬuR{N}bJB0{̄L l2JT tu;Z\SU%Ğ_zþcj\$RܒhdZ uxhbTxO\iA5*xTr2 ,$д~մSk=^s5ݯB+^H[ 8$F 8nZ?@QreWFK+3c.?TSڋC eI? ~ZF/#o7i=#YZh%OobLmp2qȡ0pDC\;2A0:: #*}Zx04sz]ܧTK;M3?9$=6,ޕM`2``<E}~qu{W.f14 V`{t0}gl];qS3OC?Έ[mC4bҌ7RiXi\CO~PI*D0R1?^W:V#bdpn OôZ^}> P铆LĖҝLs ه.=xWej‡h[͢{ Q7~Q`HD+ܥYmQ0qv'j0\gyw{ Ԥ=f{/_)g"8s~@nt[NK%_AYd#n&\܅<H$VO<.v[%??B6W E8 gִ݇[)-tdQȇFݶ=AW%*>vRM/!BլrdcYRKtv 5d|ks$^-o/_FuUנ́P}'L緥Zh?ȠצK $pO*@$ ZBmC%K20ЖaA+ݺ U'U7T'-ݹ BIKDa(ddqƍo;(O]׿ۄc _{!ײQP@iDO<򄮟2ʟTZ6uj&ux0^pOG`B ҍJQ:tx]C dlpL ;/\ͩ0I T <Յ, dWI=cRP9oJfp6E@Ѳ:({d:m1$6޻He(a. .ar$ÛU=;XQ=y,)1,Wph6 ֣G(I8\ړsԜ=Oˀdw&.'Fm=m3TEvɗ4(sQuzsqfoaG-t!MM7g%N솓cHW 9ϽIG n\q3h!%7[AɆ?a ;TlW\Zס.#!`Єkm9z! >_ M2\Z Ţ{ı(/Ww3 ZA(2:u3y v"H(SeLȥa7G|d=>0N#J.&Y6So"'o`VpRL-{VuxZe2.4na_ףbVlY54RH¸v"ENQKwSDH$(oB!O~Lļ 7-R\:RSn\u;$f|W 9¤n`dwK3m?#JtUsWʁ;NBa@s? %U&vLoa %*Lf*svg6KYf~>]i6ƠȈm?n `X^FnS J&$TNC6r =~c2OgW^5&_+%< pXm{̽e4o_ kM:SD|ۀJJP=g, O%C]6p۬^=wI הWX)Xi2ţb]h<&EHG~Qӣ@4s$P]DT XeX' P< 񊲁Ў <PN&,D-p,Py:la5'pQD?AǨ_I"t} ;XX!Y<ݒ~υ =TupsMtQhB“+JuE[?7;yvMQiZmȀJ&'=3!m$] E4a鵰5_)C2j0Z+0Ma&o]'斛X᱑e&ZIP@ "=ЫAV,fB%YwvLyMv P>dfu 6 S d9x@ e_,"y5v hMzUFр߾PIn6-~̭s3MP%opRHVNsQey-wxٕs(<2L,WK{"Ƞ2q}5LOԼ8?ݐ*߹آJ2}ԥ)\oxI"/=-#AvJ;O\7-DZ@k;}/yUR-_Q{.Hɤ]\f&%dt7?l:^}aΜ},8BWiU@!-ю1P؂V1H2l$gVQ!$2Nmbבcd^ǵ :X HdXR $%ݷWY~3Ex>"&/;sfSf{ܪ8r;bHOUiq?j؍Vt ]7da] qL{vhW(''b<%..sJ {DQܫXnԭ_l01n43#NF4۾4&'FjרŰei f* l.ٽS%bK}e:;Ό!ң1Ŀxo}XZG /~t-m P{ʃOU@ '!Y!t 2E>em﹫  \,?ߋ$Wӈi(ޤu%GWQ$C 'YI`UK=n GQ ?q*xRpν肣d@/ڿBglW`x׼\wz 4.\+y¨.)TD״VC k`uQ"gS+ dXyC)*1 V({/(t6YGuaN kZ '#']TxRP!zdk*;=M嘦 tRWƴr Lq=Y,h\ݘNX5Bf2ZWOa|ۛ؉"dWх-}?4[3!o$>cƲEM1Ho^XˉzYxduB8avL^_T$5qaI?P.EQ9 ]B +ڜS юWK0W{ueisՖŪYDHEO'UrIgk g 0BLưp)!qKzZ!/Ŕa%+ jrFz[2DSC6[ًl ڲa<|_h??/`Z’%$f;Gk{p{Vq>+ >^R\_:ޣDiD2`' rէ]a M>ScK٘qr%F5~1Ac%%O ?Ӱ; n8VXqŵ0 D!LJ -cTH\lb%'E`[cGy_ɗ +@l}oU;'r~ӰKS”qiSyHZ$m(=\-DDo2yMY Xfu%87o@H`#vLR_SpҬpG'u-&mkgq$|G/`ޝ?µWIO7o9}[3@̐@,B'$7 ^Ą u$lə@.#/߁T*`اP5_RNf"*6גc;)B쭯ĪJaat'T#Vb[C4%q7i`+N|]%[ E(VTypȔ\ ,/tp4\E2$g+җ aWsPlLׅ nm4['Q@|ܧ{Ppxr$Nuԅ5!>͒0mrp` u0kZ9=HJUհXUPh' BF$eH.uĊҋ%.w ]7?%XF]O7hٕfTͧJKe?} kbs:=2Vȋb>NtǿRxm 9*Ļ C,_"kxg' 9?1^rP|3fPal(C@9i~@#.fg ]L_?%9MAMq6\ eA4u)yLn0jQ۵A`l? DPz$ 1ŴӄҖIz}V7Cpg^ >!jipyw{8*GT"Tj2Dp"7W$ (iXVyAXr7ZdǧfO-@^If{^C2I9mC7_q k@t7H|m .Gb`µكֲ Q0)RxU҄8<G0U.dKN E;Ĩ6kㆳ 9E[373=i JS) vjACT3xr8.~A+;wDV|tqz:5G2G'JI*,&zh {*9,:|lmU@Ӄ%}ڽ[ 簦U;ʛD OEYǶzs"qO  qvU?3z M;Ϋ ʪ^/ڃg'8p{3A k5U.keaľ[j[P\>, ;S_E:Z{~Z=y%  g) :vtdAn3 kd$4}jqº0 3PwSXadK89A2~xɒ6]=p \Z *CXp-<?˫#utw'c vo YcK%KE>$@:CY4 D[Md˜KHj r4`3U)t7Nj ħJbMP#K7=)TP-DUv" =z7N>̑<ch[:q.h@;yWC%a7֟=N ]h>$F0⣀7yWte[Ulh鸓2=6s~FJD1ƙC;JS/) F,~IGJ6A!= $h/?\޶])@ !`bn)Tyi[F^|0,c}*ȗ,7G;y%̂S}s)/${D*}1y WM ]?Za]g\< k-^߁9[;`gxuT>I_\1՚D>vrM6Xr,ʞ@T0j}63 ZHkXB{3M"8\`OUQ<ߩ?u26 ngH" ҞLK-4Fv=ǿ72NP~.$LjXs|?my O;U 6aNŷߔ, Ÿͽ!WN[D6Udcd Wqn'~+AUi:y4e?o~YˣX 26'sUI Γ9*t%/UTV4ꔸE00׊ NCugrRp o;J7Y|0Y˹ke+måKsW\%;}=[rHoq| =-mT7G#A{t U~(E3Lj6d /"f3i$E/"4Aèǖm|IM!f͉_c>k Ww7iq{4AĚSYh[(\EK*tP2pc\xRS ?fpUoIhMrJ6oR/Ҷ–}V0MmB9[{* LjbaK1gx =8 ~.1<"!ԭ|Oz?}~ݍ3bDž3lΛyQ)jNo[)?^ xy7%W("(O! &>z&ӷFiQv*39 Vt<[L}zFd*;!M(AB~gNRޔRP '~O?~qK 8%7>|%OGО,X]C&O]ւ)ӝH%ovKSvLJ2&i-—QFQe}AO?w@CsVX+)@c?fxStPZg~V5`-0W|&pmsCu~J\*ÎUlԍ/9"8N<xG ntp 礭^tp[!+yU@ @:^I$Eh?Tt_G-(ZFaex4l֒Ɓk]mn@k77.>&QC(3%է5ҦsB;7ȿɴ~drU%Eu6 ~]Nz \OSK@_᭭eʳFyF"7ϫ7ƔB8P/ $7ɡOW/,<^{!AFb|", D HvE1]^%VbVl>XٸUjYvբp:pbvM H!㾝㛴jg!ZJEd%#%tA #KH5X`N! PkTa0` ^cD]]  I[eFX224]By&۸tnyV_ߎAs7{@X[mm?Z=~#9!Q{@]:!۽h]l z=3D5.j?װ%+sNz2YX s+3ZxA,Z:5`{r.R 5-%vOrr^ghORE@8ʧˣv]T.{I|M! XUcz3/ڀ8@k9ɸ@tYtX\eѰ45/j5ǣ%Ԓ JyNwqvT(Beb9Rg0Ao,^ʑsv-gd?6±$$aF4IGAK[#IThq |!Աbkv+n "fݮ6{[\" HK`#<7̣ IĞ%6!`ⰔHBr-,"Gۍ¬ [$0p@Uϴ7<0, %Ɗ7Wo9A$Ԃ7ot&MGȝbToyS~pXq2nۏT,fJcN5opTztϣ8ok4^0;lR%ɦm7Ȃ vscxQN +2<>IPGiFҝQd柽>bQ|^]M"JZd<+LI̬i D>0T\;O&iۈcK=IG9٤颷-d0 DB'&hڹ*dJnPD~j_Yt`^껤>۔5|,0ۂzXQOڝ\1Q B* RڿEwQo(לE:D[p3zmj_l j-l%b wGӘ9Yii⍡UW6~(=.F<Oɕ0;5F(Th0mteƂikۼ{NJlAh@8Rz7)1Dmɀ ]O'||D-#@h"LKܚ_;WIXK EhpήE'Yaowkzg|[<̹B G^U)VS*Q ׆9@X)GCXWIF\aŽScp'Fw!%[.ߔ3<DVhYr\ɣʑwXsF;`GJh=5Qk>: AI} n,^%Y%ٮ"b6p/,s/J~*qN!)10C@~dB mu??4lr=u;;vl"СJPv+s]j}xHxQ_3BAle*0^=t+[?KgD~ceL>})>tA}JBDbXd#ҹA9C`.*Bg7XtZSi6!'fs_t`Z/fQ.sI3-g-ye/H;cjƢ ;NӦ@/_# @S ^313`X./rlo!Jt3\c03~-y0/.5` F \aqt 1 ̤>v78V2ڵȩ{Ho,r/ZXYn"ӸV96G!0>'VªxlXg}>(&UUr<%2n%fk3hHa0/ @$|ħ*X!qe>DZbTwKxȡ~@(%Y{ßTb E AՑhУ:"/ޘmG _>6[ M)6 '/}21Q>j-8SM#l3B7bєp-xky1f ͧZ70]Or% Fz3psn@3o'}ZAcMt8 +F =Gu3=ZGq؍'\@zF,0c?$!Af ƹ.nXk54c8$cGk"oVZ8묅ͳ DyB,ro Kn/ȁC)Y*xn6K[hB ŒvZ_HZm?CFa!^ltu2Ő{`1K}~n=P:S\ l{~sW+ <}{!P^f L=Z-cwnBjJe\JFG\RkdlkVt)]ӿ%KGOzsxʆX6 4No1`ͽl)M-'i* pdMS2.Z׍7罆6`Q"4R^n9S9~JY[~~SJfkc#=וel$۪g^U?YFqU8@do" 9wt>)+žl+|YPXwn@^8Cwη+u,8ZЈ>yR);|gw@}. 'c驪~}9O[Huw0bNb'-; mS.@枔%Zc ԢP.3.UO# uU׷^wPqZJ-8*D]F!<:wEݙ`&E4 J2 of,ry[kn(a0OJ .Nbz9|6[-_Mgs"OP!v 03‰&Zx4ZnqP` 8?[:'/{KPۯ}tW -3R1S~ dyDp:^*U"TfExsQ?QweuCnDL|VbMuTqIrFC6="} .DPp fio_=^iҮf{&o?zAS@ %:z6&sjL)}՝WN&I vHoސ6E)-ɋpMY3O~Kzt `ZWhaIPU^H  f:8C>Q9|Zwm U7cx }sQC.KȰ~fi]^R\~*h:A4 0˂<"rx{%/=epMNA Cچ9zvGrpQ3?v~חSC臚avY)?66kkkl/.s&4ߕy Hkk2CRАPDtJ2߻\ּB ]RXrգZE}VkB&Kq>|ɫƝdR@ۥÅ(vNdh2.ܴ*} ƒb9"Ӣ '&\@%B@u +1ӛ̼L*rəxzg7Jk'9i`XQN`2i2ъ\*X| Ff.u>f`*Yu}x^. (5XERn )8"w}EJX:spF5l҄SĨsTYC djKj K{iIŠYuL:ҪOڛ`A}c&[E_VZwUt/E?Ho?k2H֟lt8?!Om}/xLeUoKcvm^@ꯁ- llQr2fʦ[—~Yv\DdhN4'Ygmmñ.!:GWڹ!fL1]5H0 {G½"(&rX% RskS&(l/q'gS]xbb~i k{zcN2ER[ފcS`64I,Ӥ;AΩrY>u<% _kAj &WpqPL+\p92zR+g KIkkO vr%o\~Wt)DEc֩S|\GM"o`ӌk]XSTvn81_Iy˿-L|L;1[P<<eR W~wέp / E/܂Op "yOmodz~PI2vPWbޱ :XhYt?TÙC?7ov}6T6LMdr*dC1} &JB/oI#5.hB4xVeJc%Zh׼zZӝFOobnuy}govd (b;8QY ǚA 򒘱ڈrv}p92yQ~eb5IO~Yy31;c ~ 8+mwON&A'$ 2B+@tIzjp񀌭];eA`H,PRGS ˎ RolŽm&rUVnj rʋ}, Z dI2uRN<3N{AU9w5gt%UќFA|L8!@8=[WQYzL ΞaELve9/uYBȪ;.msϝθk5+y8a>y8-Iif%<װ`qB!ףHhTʌGO6cYqM.ڏǮUl7P;նAgmK6,@sd 98cs:Mb>i X X5/vt"JJ1pc6)U@BC2gF)nY~ybK88&g55NR'5^"ia^uETz!듈-   ^[N.M*89yj?'z?nfHJħf$,& UpRcƶ9]#+zĠ_'5M*i^|0M,%몳(W5]@S7YZ۠Lxp#9$1F\ DƔ\5#^W鱶%ho D2>B\kZ+䑯]JL@C%^X7B=J9:ak!:m'(\ﶏOz0>P*2m xSWL2U-ʘuH 5Bog{@׭W^%klPK2&iU_a1G8&Icw&}]8|5<>]=9d@9 نnIh0,Qvnp[T'~:4B{E7u#{(g x Mk!tdT):.P`!wxW 5; ǥ-.V{g9Ħ\.XuJ@\1ȡ [U, S_VBp*o,cJDh'x__e帄ΖӬgOjOrx10G &/Dgx(0OæXJhQI.QRZ7*QOF5J@R ?~5NnZR1d MBsv[Rc`4'$\l9VX QSJj5o Cl),tk9b2%)3p.:Y}޼VY̾".zm O%cu!hێPnj\?IXb7DErkʊ*i?N1:pT5kQ:㌥ ?xܾ"K֕M$C +&wb*6 B łY BV415CtaLLd֭cMW~Jyu Dh@ٌyx O~աp 6B*(,ۋ=XBse&x@:) &U*yL= N@5#"y Fv巭+*pgN~Tdڟ&UƢHwJTv㒣-5kvaٷ ~=tk p(3.Lj%>\l+!%(j58EB"n<9#]OFJO O)-@"PG}:3"eB _@A0%tϾu3^lj%MBGDSӋ}Z=ݏN?gPTwQ\F%p*XץP?W8NH`L<ɐ%U)h-i6\07u?Ta} z8v鶊=|c7f1R BĪDKgHjT^`]`ćnQ!x\Ⱦ%Aa{b|SŢU`{zrp3s1e"pT]z]1j߃26>-Zj,͑`?__q-%}ʵDYļ'bw)S߯geڀg<2ƧIvǽ>Ph0qQQ?ELʮyJBdmB*T 1쁌wm#) &(N?3\BUl7fѾ_QA08l\LM8]@˲#8z=r˯{VB`ſLB 5cvrDR{X |x[[ Q( ¹3;r c5AbvpX B۰U F]M+(W@ZJÖhb>9!$Y}4̠`_jLSz|(y$klr7y_$i1wO2 f|)R-퐿tlʙF5L2W:D1mߢI][R`:ZO5QL; -hg{Fw܃9r3lneI+<~OLƴb ߑOEg4'YzmɑZċ} cӫkjHNk3!W|!=p @E2ڱ+RqTSF*T@bYWM5NC]سP]4cQl ǕÜ3/ƺ_+E}`Rykh iFGC+SB,*5v}3˭bd@kplTJXHn5ףYTq8 seNbJFQ& ž2.  )ǟkM :dA]m5/AqJ?izF.M=hBfb ޖyigj~_hrOQtᵺ ]ĨuU(Nؔ[ JJL:&/BGW?K/VrCB}=TaF}Zֳwy;hS Y ˑsɏ#SD#)cc7SDL)B{kF.h M>fiHzrs>'TuFRĢpCA/IJcq6rU eLI\sMuMNԔ+ ){~^dT@?K֥]h, 3fD@Lf+9z4}4;u-Eл}82+ a˗JWgWf—Vq^#?Oc՟ڲaס0*&9,ƌ*ƃ+tnmuOW 3ЖX᭔$?S[Ѹ5 1OZvv0qq^]ꁏGwq;Ƥ&L#ϻI;͋ATT;0cvUu#ГUmԳmEYPb|n8)JJS;4|ϰf|UYŨ4A9HW/2H~pGY8t6#;S{"Xvqp9B|_!GιdI:#UxA}L9eY0&C{X{6r0rz&5&'F+}=>Q8mɤl{}??x k@HduM]q)Y~Df3=<1~u#a1m̆,*ƨo&ryVTYՔR\א޶"ao\VSy1F γ50^Մp"BeQ#(TEy9҂,Kpբ 0MXsgV| z=[BINmUF(,~DX'J$t-F  ?{HPtT~GV;.!9UoGρ 4];i:^Ü:9Sn] 2HeeGut/?­qL j92'k49tY3\]ɱ-F)@k!"OV^&B7[N%]@b%hvH6눠EI"c&;{$*ԝRkc6eڱ;/4xz/86;'Ife3`1K)mki7wNqtZ]׼v8N͵;FrKKs_^cXl^Iq?ޔ/_4] c7޳7c CТ0<.3CPS Z$B< m>JIFRw,yގcM"& !{n/P@_6jSdrnc6!lW+QZCgZ%t)-2 }ӞuDTY$+ɞ}O- LwP9yNxGk&6ٔ;qlXmPf?b0taO1DsNۡ%P2Ϯ8[3Rr|U} Z=3ףJ`YQ" _Lx2N,Ё& nJi$27 `4:+o޽JҖS q"F P 2 +U_#pjS »6K(씗KkGh Is&h`7%&k=duU.Soo=Q=Q[s_%BdYp{U܃eՃWPhn}ͶntT==il֚ԔCZXȐ3eи~.oEgyA?Y6~ - $YlG3ȍ@cZV/9$j_ ./0r@ffdMU⌳cIpEVXغ9> *NS =ӰĎ)eBbf]oF06&xxWdsl5'DzR[䛏:.|\Hpc| D[tM~]-^C,X*4nKY򳿤^88k.O/ uP\yy8i:na(-7Em S"gfr_檇ȃSbVrz9Z(ͻGn0=aIL/'Jm{Ѡgs{ʀVЀ-dxe" am!"NM A$^= uH\J^AbgJyX]w̺\mJ^OGKXA?- 2渀W{BzJb:Œ{V05$;_m'yOPnb cc1ҰZ:G",PH_x[~푋WlZb97IQn@>xsc$ίBbտ~/*E"MfC6-ީz+!7,(}0%AĔρU!~RbX J5y\QL .MP?.r:uҩ y455 m8<2)oqJ`0n}+uzτ ⼢ 1bAuLXNEMy;r.äg,q}ܯ#cFG^giϠx̓$;5>4Gx74!5fA-R6qR0K 4ևVdst+l!{g@a&aJ~.9sXJ,wi26Irf9Ά- lטrgH51='ʘ8x7[W ٽ<]c``-&@nXL9啃`nA9H+r4Gm {,R(y7"ozlz6_o0}P=P H<7 rWcdhm^oE1[ag%7Y3jĻ7${tނu+A OW\-sW )F2Z J0!ل|W^x-=ijr=00+c59"~22Fɫax*ꋡzCK1t.m)4MgZmWtF ' +?*KXnUie `j;aQRO lF10V iy͵n^m+;=D5loP;|ɑ7syOœ* FPܔ\iCaviTH }\W#m\!?vj2IJ>P^7/5(ޚxnV0Qΐ(~|3:)r .IꢥB@-CQ!,O ꀴ1hmn2,r .]*"Eq:b k[7R{(3E)n]שּpґ⼌Τ!w0'l%y$4:e{|NvBx˵Jeouꄜb/ / _2߫ٔ? רY@ʣh+jƝ8!c}ZjAC0t`zYMO%>f $t,fpm.T1SGЅ\,H)d68Xo)?Rec WTfdc(pąxQK@*πmF@=#/!<~WNVMp 2?ᖕrTCJH3|m.ΠoV_aaV6 (i!7MAG5Wó'8롹fpk^Чs Qm='@ \Yp1eXIYL3"Il pR )S"؅ٓ3uQZ )JAͳ Zt kc`Km5Me1xuqx%(PќAO``7z?!maXfLdx x2HonM~hn"a`l0ټesJ]0h5lxkj.g>1u Y>8_FlkҼRi\=LOMZ4(VPgTh~%.`!(a|j^$!a[^RIC|oz; >?UŷzjA=ƨcgJ xO,q>UV؋vaN3E_r(;PkLDU=I |.њ9@f}Pu.]եݽc%&՗~~^D9ݷVWRPvĂSTP8b`t$W 6Cߧ~=GQ 5`) a:i{4qKQGLHI;a]sӵySebZCC.8;[ :A*?m:-PJL::wZb`&IA>\@ XzC#5X/hM);k2pc=u\o;.>@OaBKKE%&>@:B7FIX@^ DqI@@BmL} += >N^㟊d!&3t8XKmgȃ2u0#+ liNA:%R+?/" j8srתm9ʦrKL`{*<\Og+Bob=C-:9RIF$cCvq+rgM86Px~`{ wד3KV9rXp5\10TAA3e8f$IdxPhqWۆx!P [.ErtEm`Axo^bh $:Zk#TK_٤4F+NU>=A5; 1ھSk/|I0!͐l_2F(h]z" g/1m0ZɰNnr2=tCY9IO=]O2}siqQSP"P0LkHnG(ϸ fdU&HV\Ng:ϧ/x`f_#N˺3nGEF,e?Y2wA%f`ILU-ryw/E*$ٽ.8'Ƃ|6-OND |m- r&B܎2C'iP |0sR]]cࠀ#oY=WJ!vqV@*ېA錎j[7E~" 7a)?؅Hu^ξmS0#~9 @6>==(ylB SҐI7yos9o@V:u:qPDm >&@YxI,R {ۏNtziΌ*&`L#@XmuP-) t%Y 5Kb3Gt^͠OS`d4;HH۲f^WwFY{\g ;;u{2k:j0%ɕOta-n_*{+NYTR/3vB\ ^'-ڸ_?n2HlSi#QWP-@#BF"m(e5RRR y2d?,I|faH|NC2F ژI}R',?Xbvt&wǁO+ׇ1qH21y lg}g;:.1ϩz%blwѲ'TuDGe;{B&|%SE"zZN9gm>bRY {Wݴ|+l.VPvrJJ |E =?AS9\E0qf 6a*#,|Qzk(q9hf"35瘳- 5=c&LFџxF)["FNCwqnhzZMqbPi\׮N&8Ŋ%4Y"0HyJ>G(ҝP,4BGY Lf)&oK=(D8*,+fGz7uΓ/#m('Bx(_x }QKs֦kgd?2VJSf,o0)Y;}Gf~qV^Uԯވ?BEJy4qђA2?3# rL*R#&s>F>L؉&˜(l5qdyZB <FimKzR֧}"Ȱé\Jan5^ǎ# "yosz' P`[\l=_/]ߏvSEI+-o@kZO;z6 9I.J0If5M%0LWޘΰ_,C"zfh~^uxt m)J){B}73`8O/@R3"0q ͹+ H;yFR, Ѡe蚓[k;hBοnf[Іy3n|tH@Z!w7rگ9ߒpQ㼾V+aeTQ$1^BݜУK`HlWmC\.:Z.dOeʌ  A0lh#)N<󺎟WWsTNq5_"9՘žU#!`e)ŵQ'Շ 2@yO VB.Px˻(uחFVnI]@gI~s( B@mfxKObg%ϏAΤ&MQtqE;`aF$_\-FF?XG;i7aٗ DJZ*Z; GG|潭^ZGw½ 7hF?˸P#kJ[ Iꇡ`JRzd(X}\O^H0m[I5T,rfr2|H]Tf->i'H,{4 䋢Lvt^RLSڑmesU^qӅyy"Y AD r}:®b8^D@tl9w짼ǵ3x7[ Kx.@!c[wkpN͚CK!5 ^VZzakS?wS{TY!b9䐗iFR7slbKPnÎh.nu3yʡə}cZ0k=?Yo+&[U3>f*O0~{ (8fkc095!ݴSƶ:Lcbg')Up芧$Elhhh| A@D1`|Ǔi!b0D\,AŠ̉ \j|d#M4NU'Cz!A=WC h (>t/Jն}LrȵC[BOا1۫`)֚\/K}V\$*[)"Ec}$Cy 0dSk7?b'0t|<>c YRn`c?V#`l8o"DN}cGyM$ I飌bZIZ6Eh"Clx} U6:2H\yVyb6qc@NhtRl:_yc"T2XCUt)7)]MDoXw~*UW5Cl \nYmK̦uCǠ;wuXU9]qWPRaHz7X%rUq#^tӴ4;RyHMI.s2K"ZSK9uC[Z'3_ȌdǡTu)cMI]RȐw:{8;hKaC"p1SLs}`*K һ5sRe07m(S.udB2huQ1ؐg cI%u|)C *$` EuMWj?\wz϶J82&b4W [z46%^4u=77Z;;YA;` aLpR[Vb11>RD.-u)0OW07Ss$zIV20Y-oA2%n~Ȗ -熝s?/\. ףJ,|uJz.ֆ#>DY20i+lH{1uFfEz _ehL#)E㜁[֕~"}=`h~oco,BذGyٳE~BQSu>!c/ & wjm8d\GV.n7Xc(LWZ. Q iJZ*dk۵,PY8:E&/O>i8gNc96]?@ ۨycDϭ<2v~WwyİcSRld:({5ANB 9cГD$>KFhx?2`7>@o~e'Xp/[`˨ɔߛJ$jR/G4o5RGjۮbcYjs\ /'^.>O[3<4cQ3vzxcP3aƸ!X/V]>>mp.:o풢uu23IMi`ZOiy`",JnVC#hT!6:Esfpnfr,v#2~sζAEe6У剑vcBY̫n"6.J7 jE@_V[7iSzk 긝 (?/-]5y/Arw܃-9#>xվSK]KZ'}-%aԭ)O@|ͣD41g>蠹L2LçK5=6Ru IW =9<>/S;_$G1̾w7` ;0<-yMGƃD$&|mHBjb8zAuF9˺y.hfhjv$5L\0SA@~.:pD@;WS t+I(rKc;1s-E|)xӭeW~c?'Gk2̹>vֆnL} Dr~_\؊2e5f#϶`,,[4&lqMs߭]I'ٜ4Wߩ`-Kf]{R3{xS\7axEAңҹ6Se%i61ˋWlzHh+xVњi]Y&╶(z?n^uخ'_kBT M fyt6Ej!5!2^G㫔{~@@T)ڜg1D=uJ=c΃. QJa%ȿrb SQ:7UVfRcG|<|lU[k2q\rzDRM u^-k10_'4=c( 7Z\Kr=)`ff?bF|VtI?:%M(#;|Nf(RV^n?UjC-FirB_|& l,y'#׼pBS2{ Ee{F% M w5DE s-=2R'=B!awAYH&OwA@ӂ TG7{nLIpG$nˢS ;C¼a"kB#0SA>ax Fu^ې pR{L68yA\kS^"jLC@f(.Gy'_- Uv{X1}__ǨL6*:0a-Sifrۊ#: _Pv bo,o xkQ mu5,_LYc) 6OY[T- `*>iLjedسNEҍRs.Q\mx8(hN it܇W䜣Hb*Jzo=dVE]8Ci3]@y YT`N"OMMr u|ßc6ENɞMGTBvI*hs-^)D <^LWlB_Ge)(X-fbg59;S g s#%'inֺ(5m y jǕLQuВ~o?ET;\#Ʀ:ݹ'&#i*Xϝ(1;VdynĚh~AO%G5X62Vӽh o|J,{c5ڵTf~㛜w#(l@;?=}~YpNШciG._" ٙ0oEɔJiW-:ї[Cw@1O6C 4&&+(șw(: Ì5w٘`U!e&:y7 /3X89téx57߈72E^˪!T uLK:tv^}%Uғ*Ia"yfQwW!nܞ82+R,&p߃GEO -7YM;)nNtȧ_ Y䙁(ƉKN޼*bI399^MeYv EvdkC,)-:ā#PˡemJhY2|(?=~7-QOV7,yBۥ׃"/)=q1Vb=^֩`7_QFt4F)ٕ'%qc+$ޒiv{Jjv~ ]̓)2SH5lo i=X(xyXwBQD ZWO?4f(JCI 8WʚoiKFu*fʕH+4d>?/"RKA[;h_&FȤ+ؚlAe{ έ&=ai0䨆h;|w6f6@f<9lkm('t9"$Tx5*b9 \TLg)B0:,N۞*Qh[=7=H#[V3zyH#u]˕5DV;zwdXUn#A} p<ױ3UQ)}$sŎ3;flp. K ص>.o^EͿkKpvn)K^Ne죑9lA#,Ck3ψ2#|:üics&!L&g s2:+6^\FA` BatyN3߾N16cs'U…|[3;_$#Ҟ5I Oչ~T!oʛyfX'>ޚO"xr^a>W@(eY#P4O}R𢸀?wP'H_B+No-Kk_pq>%yӑZƛˆ 85EPN=VQE2o 8X[5g^v:{;{b=[S)JzX^3ݍuy !6|f/)7V{&IJY#̦GFHD9*L :e(R/8smkCųZ /u!S4;E oM+/=20,ԥQah5r$(G\qA#`EqzXԋ: [{kqVrcZF @ CŰ}HCÿtcY]&:boZP |0oWB}gyVщ i.qbl$f$dJ ^=Jǝ^Nl *<5{B0hDQVFCi<{Q?<Ƚl+eNsx' V>CJ0hI#bb\TP'qJLxn\rMzX-F`}kKqjxınhE/a%ezY Q0,xㅒ5%ǩN9Q!D"J u k^>,^%vIk1Qq|A#§n3\' ?{ :dB|;x @;kM Ǫ KP+Ņ]vtJЩ/9޳G\ZψP7<>8AЏ 2HZ{ `91V=;?O,9iEԱ;c'Is#Y&aԷLWѪNfoEƧ=.Kj4fp>C c4%mn"̑X36tje{ؤ*Dxh$!6Bc͍ʨOڝ.৴h_cjhrↇ[﷟c:T>yl q Dxz'}%4mQw.V `xxI&_6L5U K3cR42]/Dh2VHmR 's W JǹB~PNE> z7DX4T$vVoe!Kq%r b ¡HO#u]$FEGim+Φ#n 0 yT);KFԳW9VWJcqD2LqD> ųJ{! &8܍_*|0 5rKenl͌߻f)\e!H,3wIRM6ARoxKa#^~g:t_R?|S[o h=3ps=~;y01EEfzB5v7I͗_il)Tl|V7]D%#DZa/,C{oRKi\0lzeM"@1]?N/+o S^օk #$ aY0ԯZZ'~)@MRihi#{^h#߼q=90 {6w|mjqʓ`+]gX10 G='J yGT> $=>%T[׹ 2N3U\t>fIAu;(fW^̰Nɲ0Y+-v(峃<3HpPx/:0G!˳d3}j\{R}|\w v\foey'qʁp 1\V<.WTpjS:X~Zi9w 2^3EGۧD !vEwj"I}x-jsX !t1On@n[Yco[&4s BV|:$2TOKڡ%Pp}wm6DL-xH6s3T4M-K@:fO w³Gv#Y_ɶ SAv 36i[t SC6rE`Ez5GX;JBvsRX86Ppgpub Lp KBz벓rܖdAtl]Y#5T?A DI #}]$ ؇qHx_d$W&i8Rse>w:tWCز3Na|Bv/CfFJ2o=MuYV8L? )|\Q `o ,w,nڰZ]ˠQske/H _t`f/C!^sJV31Ge%۔ ?K=2eT ̔$`oܮJqq\Tv.9~0\͢?SI6yr 0rufzlc/1[(H\gw4d/$Xz(h׋T~W"h1CҝR% A `CD ,r·@[2kx H`2װd8qð +fZ~y/G-*YPRD{KHSu*YaPC)چ&] |x12 /0&ڝñxz`C)NXL8WKX0\\̀=KisgvrE»G͝cM*?ȁA{>2/s"$GN)^ӧ@N)!p(#tHkE '}'Qo4?1xIgO*=e S'9چs`&QKf< nB+*DFPE[efs5rm؉"$ m@0˜T q(" uMë7.5e#ܐT6oO3i9u ÊHGNH-"8Q+GDyOE zRMf?oJ0MpdoiU)v}s56 7C w4i)5}RJZUk)SyrW (  R`s+kOl luF]W*=m9|~+aژuNDC3! H|~ & +Dj,I #| =Ύ .pX8 VVΠdx ΔQs)=m, !hL͡:l)}0,|^F{šge,HcmDC8J D1(Li{J1Oge Vփ:;ii?X*̒#2Mhn6+ FOcڟNq`ƛsq@HšBhve%5 _2@Ċl6UI2aO!}8-4[AƊ޵ȟm@t+蕂$xK!Nk|]OT#D;GԍM_Ygxj$rz7Ķ([!idr90Ha!*r%LjJuR[v*-J*YqEliB~=i}Qnk9o9ՁCG]3|(HW1&o{ ;M;5bz9ga̿e7#;pr RAOɊ k}5Vw5uK\^Cj"r|kĦd.Y $[ `گғ\=!0]oaƯt}Ѻp 5_p 6X9Qrh `(3'X@>M>3SFAм` =Z7.ߵ I%7y;%BHU2ݯa zGKmtKˀ`_:`bMȻwԖ+IEXE8#4xΜ)p{}rDtlub2׭;bͦ7 7۸p;A@Z e~C|/ƦfHH 33hc;Ӻy 0%!`×*Jج{L 5 C~:Y-vLͅgM=x?G @dgq-z]XO<:&V<_E%Q08 _o #ױ؄`4r"4>_seȀ6e9J<i\SXqh9jqٽiq&bÀN>ZJ>њ%}/KT>k`r&z]%\3?k)-̄'/o,!Sk+O߇¿b;^LCr킌ĭ-<ţ ΅)!gbtm}ɡ͟OMZ>6(&[I7\,@ZCipjp"wþsd=1͎`y%XϿ6i92g/ Tx$|Z%q_u*ןBHH>TuhӈGҩ ^0Bߞ]*APA *)T0}<^ hq% F P\nގ%]TAv?”HF8GE,b/J8VQyAy3y*߾M:od)ACiƾ  alva-< Hq+UHD9eѾUgڲrRֽi*-C~J6OUΙs|7$Si?QY2Ù5OT I#y27fT\ex\v _@֪j#"^JQǠ_IF= t7ԳX2R4j 6x/x_ U?[LcI35[# !JXF=2ATaq-4O1+ 43[3#WQ)怰|u“Eg8hCz K(q {/3ˌ<7i|ٺ5d'v˺dlm]K2Waּh=k4-/Ӡ] S1Y$pil M/OR0Wa y۳iTa 㙲7fHu*GEgG+x YʕPכ,pʤG9f`vZ2-k$b"^-&bϸz6%=HSGm"P)AyM͖%=2Je҃0GA:j_q 7@t;zbvX"/' rgh'@9W.xR`~ڸ0.k^-6@> A/?QV6=M9>D& uOC*Uy x1j]N's4pѠ0T9gt#x{}38-E"o"pT)oz+-6 1S2CsV^AE#{JƢ*bTR)+TїkMȿ!,[D,7*6z@P8HVeb0" |I;xpkVp:"-o1a}wjIqR]?znm6+I)pnX2m a Zj) Av 523;%`|+K;Xbګ(T;l#t 8&nG=DZ<[-Ժ.)Z/倏Y6$3|pؒo+(d#_a<9`@>}ې~ @߉xC MXՐqZxxR͗tz}/bFKLD%+Bfx"1\#_X'cWwz )8+B * rv}h$]]>.IB0Dd+erQq|B vO+' 85&w4o4h35ȴ>u&iՁVDA|މM+:MtK?psp=l?yqn٨v X61#h8D'XBm*ЦW!!t2'SBHT%&i]vhGHI>Zfz@o{AԛB瀱/גM6%$G#7x,.'Ar)i,beqϧIk9KND~2٘)B_72!εWP#wsueYGvZ񈈑y]6,+SisA2%C3 >J h|Գh,76]ŁOAٺOj% f5O?+ndnHہ::4w3/=? t#O(no!$V`.aqة9+x ];yz #>K@_yU[Tܭ6 Mrx Cʉ gX\|Kw6w y1aWl6v@xy9%< xZL!`&LFZ%V ޚō~z.qʠ/M^ Au~*KpdSDtZۡ@Gr@Ʀ MGAo@MqaR0Kd(E\]F"dz>ZJE"ܫFuhT)b'|C}~jDDWZmu(9ju~)c TZ{s-~[E&}MhpOL&=lخ3X"2 6TQ#hf ^}lWNl%D8t+i5`!z9cZ™Q<HTQ\~kQtibP P_ Æ[RA-s/JTC`m] L(#SOcMD@Xzت*Z9T Ýe0qR{zF:.t aN.YSV Ou=ӤG)Lq;oj޽NNh/J[4Tglss -c@W 3P e:*fc;Š.WxN[Ȧ{ڥpo;MPgT;R81*q@o>[Vg}L܊ߎ M_W̟]_vf\i&ؔ2DI\nmsz0[aa#@ ;~4&.;Iz0l&d7]N \]"Kǯ&WX>Ub*~*54xvnZW }iqrq_XU&J! l!_(-Ԗ WNiY2@\B- fv#=_^2`2.W bNNpSg~RXv!N1=VŞ ]!iqTS`yuPbR8 _8: 2>`!A95_`&˂6]9h:ѷt|<ʸc@nyX]OaBLQnzYQ}Ϩ`  '=߻|̚+>QM.IZQ_]zAx,%Є'!z!4KstU=~ -, G䖘9Fv`З8uߔS/6XddB6a׏r.?&wW*hpC..so/@ nvoAּNrP&Jfn9'}2Y?l #TZ^.()Lp 7O#b a|k,$Y*E^QN (Q`7$ZQP%a Sdg=0Zk B2'b.C:wp4O$Q[iV4/r]hMDAi^+@'T\T7C#׈ayVxx#Ռ?Zd|}R,D/3cGiyf,7vm,AR{<*^[l0 %p7!ŜVਔ::E{")w ahS](SUK,yyŎZQl%##eI#KoZ_#tfGFGaH('9݉7MmJtngDy[d# NI"bŜ Eփ@zL^b.Ie^rW.1{ÅW2x BڟX+&$^R|ՙL:Pn?|k9?s4ZbSrrt+o7U< }Pvݧ{`y5^#rěϷ=;ECPėlE =Fqߜ8ōƠmp,$mj9G+W!Druzrz@aKЍ_ `Ea!~#5N)b'ul(_́)~;p(90#kK)Phu &:.j3VGk"ɽwpѐr6;=b-Y6MQ. i. *a !ϙ8WXׯ^Qwr ns1|.EcWw uM7)nP.%BkK?@!Jk=E38햃JJ }/ ?:ƵqюQaov!0EX.[tb3N4G tK"QXctga1眙5 ;  +֘!o"q| SfW.Vl5NnoVV.;C)y,ڙBPXݗ]@DHbu-٥>둜 "gMfLYeZc37K Ky `$we皾V-75I ş0̨_~*Cc驫%4Շd2Tc FQ7/̒pj4S~I?|tBaTz nlDISc.Y{t@ AyhUF%F61pV"pK=v@ɬV>$9c,Ao`RH@r5 Y䏒R ?celTs83p=#QS>ؕzFf־N_tl'qq)A_t.R\y93CO ANL,uZIV)TD9tq?4.J'ni#f*vс삀G(} m{^~٭˿ 5|v;ٌmm֑~pӧ jC;|h d iE9߱(pT|oݩF~P VtN֜cݳh,,}M_@{671s9 ^@D1 z5q$G~#TR7Ʉ~DY&T^[;3bth4^)BH.gowDiv8^E/z3> LR9P@: {u|H{$* B" ة*0 {s yNb҃v reVʼX >VKٯ06Mx?:G|P_VAfbi$n6tJd5)gtu@:r1r&1> ORA_vf& xןmx \w+ls!FغxK !eYQsH^X5EuE|tٶZQ%Xo$hc̄<!7jRi_z\)*P=T'I}hwg mʋQ|Ջe-u:KSۤ{GUhb=bz5ջնvóyBgz3(i+(@ kH\E!Lpu6CnPд/L%5謙K%=Pj޵Sǟ!iM-FDZ]C~WfK&ZcBaO/-ڋk`:Kw5%Z/#2mC ]NCM(H=Ndd֍ҶCM#|<wK2nY6~q8F[W] .R}^Δ:ozXUźГsVZTx^`׬t5ś@a 4,ճ3: _3HU< )oKB0O XZ>6CpvT n7s]FNP.g[ Uh!$ΝE[4zDsX(6)  Uo}CU`yb${B*}ߏh~ zI x iZknVPEOP2nhҁAqޅ<k $p+ЊF9y~^VW?VX7%9ҹoD9Ừ.?'?K҂^~M| +Rkg@Wr3%\+by:ޒ*޴yٍ<9!w t Dp9PtO:b]@(O65O,ͶPw6=yu9_VcۣqqT$avQ@ q`z3GnRGR׍Gc#iN$H/ ] eܶ.q_Ūm;`|fh!Ho+!5868U>UQtl1u鄶u^.Z,:wqVuBNQɫbhL{eٛ>GqBj$+"=SB6>g!/Uf=!ME&&(dS _$Х7SnZc`5_G\mȠHOo`/aҼvJyr g%K99q3T4Xҽ}0=_خۋ!1em ͈bŹ;Η yE-= b^$sM0}D™tY&JG,8w@JTM)gO -\&$&T:LSf)Z =C"r]>}~B¥rUj`Ɯ nX]rP{/xr'+H< z6[Gĵ-;'X`w#OiI[z EP #3JWXUCjQo?[&҄9 Ie8ZƪrIJ3-#U!)OBYgװvL3'A 7V tuS%;k1CNwć%@qu-c$tϠv4טfPCI}+\XGx\RfNk|qȗ w;ODxvj%Q59^#+P? kZXɔEF@u6b* )kƞb1E7;ʃ{;Ԉ4 ꟹY-+yy֠(9j r/DFf4'yq0ހtgHXr`Tgh" ;sę&zy[OQ1hty+G"j9~,K.b kgXDl3|*~D7 ͅh=Ayz(qd5b r#b^6N=\9FRX;_!ԯS|K[X.[ \n><8.$KbŹ24 `\`D^^ސov 2<hI))CR҃2ڙM7wyxh9PRS]u\f`l_K^ dA Cjaՠ " 04X{o ůg꽄~ţ,֟Fۣ΀0TvqJ")nՄ4 0ב?f+vOѓp=|XqdT78kqm=u$ ށٻ%h`ڳ>Kqlr>2R<Ra2dU98P 'k K7sǜSSl/A.ɉuC@r#:8"el",WIADYW2Y17J'꿌Rb9%/F-툍(.h=õTT''y!B2cJFRTQ۩'iMf;2ҨMD1a@i}X]'`8Mp{)(A ZM8jv32zmSibZhͩyqu[mNiy 'ߙsP p NhƝa5 0jȋs䌠U _,nN-ʧYJLXzs~k@GvCmO>\%IJ=2|xxhAYBC dXFL)Vڔ$U*)7Wt_x_)7e'̂"aF|H>%l<bxuQJ$Tz`3sL>ʫ"¢׾i89? H-Whq.΀ vc0S<9}\IAs[ˑ<8v ane> g--mVqϞ@0b%ԼG7D) UzOH3Fv,Pu(rsΘHKjr4,@,wշԂ}m_l ݒnihK.: >3ueqf&Sv)WQ=CuZqG}sv,kc18NArK jV qK-:%#%swH]{0k]E0*/ 4jzCwK=m &q'PP);ۚ}c` n:$I<]LޫS4u[ "兂̝ _I`$wI9;]7AJկ iG}?X3{^֯AՄ9" 쮾3B L]Vn% dm {7䚓pk^Z!ӿ} lr0/5#kWO5pPEtgGbOuJĮg8@J` G d?<6B.Q Cf[_u^]ϕ(*Y@>C H Y01'ATHZ |؊q1"} yga~Ru]Оª^"[5R63``tgN ' ,$pѲ͘*a⽠O9??p:ogpR3 L (PKƂʙpor`'c6k AJԎK0S Z,q9\ƓL+WK=(\:Se+68R0"xs|=6적 #_:cnJ!۵ҭ+SG(;AK Jl**~o$bK$E#H`T)=/ FtX5)h(+ #YDyQ|FX}l'I㟲}H VFB*BMhtl|Or:ک*Q7#j@Ʊ8T]_U{f?x ZXMCG-|5ϯvT5좻RT9& 5M?XyX#N6mʭRTkmoX-Mymca&*u w~e}6&޵k.'1 i2pVN$pP\UnpJxz!\$~Wr*ɉp&h7@iZmb|Xqx98f<1@:Wz0oʕ ZIp SxCy# O_^3:>&o +mp7?$PM vwf3nxK[{;&"I"A@>iO_3F2MX98 _j>_laEf\pum(:"Ⱥ~a@q#\@)Xq@ (:\92q_f&RYm? hq3ԜIe('*GtpՐ]6#ye2SY6dס~G]5XDDufw%SKEnfʄѾ+> [IK'?ܳzz.=FHky2I *$-&bE +@R3KMt/;eKeI_hdj({[>M!Յ @pP/r㊕*xԉZV[6}}<US#n Aȅg} SR-eo8N$RmZ!=5Ȭ A%JmBۊZhH'E>x0*P[p"6`>5h::Uuж&Jvdo/H8 ?bFNZmX?&8_Qq{{ShC7SGSI{W3T~[ۺ?}-^Hޯ&pr*4apjv.$9f_ @G|<ǯ1pLIVXԭ %mKg&k$7j_]ƌ\eMb04: xX[Ȣ,>&͝Mz_3~?ÝP9ݻ-W`|F,:Z$h)MQUEvJ.o2'ר^5ѥAaɌT$%|%ǛQDf'N}-_Iw= ~$E.wzB.""}.m255O6 \RvuyM稬?-?$_ NȁxeLrOʌbbF趥#9xJn RiEa0$m7-&LJmTc@yhm%vQV)zN Fc_AYz@#;=W'nmהeù@N5$~ޚC"sDS6+`6A&YREWfA,>>\UoՔ)ncK/rY%< /Y7A1˫-Hs܉=Qtaޗmt\dxWze4.zƹ'c%~lybݳ#Y3^ڱat= !HN*vRz[ oL;P۲V<ՖD#Jqn~TkߴnxC  ]2+g|AZȏIeKVXQ hPg:#(XQiZ˔Vt垦C>TF.'YI~V\cӃ0w5q4 ̯H[B-L+%t~gF#xL-beK'kSO 8q6 8R%k&G (X-V>Kn-++PˁC! "uD;C#ti B+#/7bg!r:;/`%iZ핻 o+/g)[WAf00NN?chHҠE-Ibူ=y|F+̖s/U&+S{;>'ŕpﺴO ?'08#4߹@z4ykQ k!nmjtތW֋1iXسc&%D(bj<9o=.lYRQa }3cl* Nv{{!jȭnPД-j"\|N߻ɞ%5`:|*NCB{WUKqĬәKJ2L:th7sttfRGRԡCgqPAMAT37?!κPIHϱF9`IT}:Y[{PFoUhvVW1Jofj;Ag?xg74.;#n_WT,͛ɕE,T ."S"J ^o\R1|zNq.^| ycfGy "N ~ĭpM~Dϰ`HD} ΦV0i$EəHڹ]՘iv}XzNB'q  EzUOar#Ͱh>Pw` J'*<< /1;=" ;?qՎh0Tӑ ?tښ!_+IІ:AW޳-NM;R8^*1wK jy}ԻVRYmp$-θ`ۜ]Gdfdp-tzZ &Cc*d)$4 dFЅX=0*ikov(:_֡UZlTf)4,3dAhoӷRgLcn$4I:6'N"rGH~FuB\B߿8#ˣ 5$ 29~}{\ nrsOvbs=6z>A7߽w 60.KanJstڹ\!㽬84s Vĥ-jLi k>x_0!u>|]NzwL3ZXr9$oyP,eO, ^v N'|H ;7t$ӺOi y;":PI&)]aWxj f|iQW=谆lU5x*nd-Z $ڒT \^ϗ)Ӎk/׬jM,2xpp:5yɒe8̌,E{V@gަɋV Y{zGs?2: *e.x-aNVY?b*cZH*~hChq0*a 0/tuvv;g ~mrb;ĠE> zNJB;«aEƜZ9Bɾn{۔90qߜV..<7}?NV6S#>N.@l|fp2WjHs49" cl"NWk"\FG;gi_L# Sx$^ÊӭAL{>LH9T)9D g$0nv0CHxKfqfT>O-sqNQ]m]\ H%Ӳ, fn9Y-9aH(+`΢H8xsNĆ#SGwlVյ!*mo,Km\ݝ|wx2F!u1n,ܦ=9NyXU7[ae;K|)N >Z^Z {f.Qs%YIHW-fAo*H]FcODŽ޾QOclnPv(`-2X؛n(⸑v'kC<"&6y(XtacU:o#E3b`B)L% ߱l$ޯRnu"IBtu{ Mq4Nujda%:,QR]7=7Wd:8~c["QkƴE pǘ[?#X6<ؾ6}[MBo]S*kDӕ!]'jADURtz7cy1,膻nMVܱeF͈ӱ05:dbm>yGC4*5~=sYnC}-apb2ƅM97unNM1QpP"8HBF_RYQHO}ZMV.jJ < 1h `^СV]uAk05Rid6U3@P={#(P4 y殫WMFos!\r'Hض!liK?l.(wE3z$ ~7QBKTpB kDO nJNr>adqB9Ԝn.288wW, MzBG[{J:= (g陁*GQl=tcFCNHM':f?XKX0eRAy"&:H~>B.;\e]PZX|\͏PEAxFJ<`Aw<(>"tA͸^(,Ā.')8c)*hzX=hi:5_ G[l NymqP>"?Gr~҃)N+튅&O kUh)pa3eR`WCο%nvq·vq@@X51wV/msn\p?ߩ*qhެE~@ce\?`zc$K<5?ar(T Ĥp&˵G} |iun-JaUkgcCq؍}gukD}Lt r1ud9B",4suX? ⨧9- 0Z vV(0%l6 {v9)/8Jz0+{>#< yLGa4֯ړhM?W6q]:oqѪd1G-^Xc8^~U$Z졨A/.Gp1R"lcGl&h&P,-7%VlȣeM4YT& V::!Ro5lNN<{c]5eg cwjBA_xbidž>kwZGE2/6?8)o:ȹK[iL Y/,&WݨgBn?u"}mH;%z4!#0Y\R 8w}ေik0C8ղWPw\QD/E^nޜQH]<XkԵqғfv*u6 :B<IF_W!7$i?.Ͼ9AamI(D.8pt"E`6ľ)kTi`]#`lW[*},F24!KqfVk@Rׂ"5*?]N:P.W| suGd"@(O$' [$(X B%=+Dܽ*kaitMZX uRFZz 0[4/V>Z@ՔWL4 _@\{m\V$Yj2l]6C"1>}M bW1bQhd '"DNQ4~9b"o)!Qm4 ňi,.* [B/}zζ2Sퟭ @BvL o$ Whf eF׌7oDc U:x\H&X#><3rl ϶S+1A"JUEɶ>W)Q]4u9r=Z `8%kYWfI.sEaZswFGZz$%6iRY77f=8-?viɜ]4ox.vPN!]i.S?P@-)>OC?@)9yS EbsN$}]5A:ےQ>Xh46߱=c[v֬泓K~)7zriwhTaX!mH&cMu݀4[ v͞ |WL!azjPPR0l;^:1נZrK֪..@6#T +9FzR}b܂u.H _E>uXhZACȤBV+ kGsd$Ϣ㌪?Ă-T[}sҊsbt"w`-2`-T2fy9ſF\˰vRgk;bש~D=+;OO!hpun5L bJy!M@r|ώ¶>a%TŎ)UˡWRٿhiˇ]8Пl(uhiMp?u`4J_1cʅ1Ңr. Xh.zI  L>0P#+s?5sI(Z+(?:uv+loz2 IrɇH$% g ݺjqH: Rm(Ʃt8aD^Cm^zkrS\ 9ާ P&R/;]ǜUFd+IhE>;+h8u:&LX7pA^17YJ gImwh?7#ay%}M N1ZJu9PKK:d"E?S& rd*!Ԥ1Nc(M>aѪ ,a*K {0KN׃w$]5 U0stQ]^oL+LJE4(`Ľ^s9ßî8,Da>fs_ iaҬfL3% =t}Z(OFr>d0jG^@iYxV4XB)Cwك3r,BmCHW%IqF`PY'nlg5"}Az#z+)EhWQԴqo 3` L殜~%5yW@pӎ/pgQSdLa^Uk 1'ʂ-=AcǩA9WV5n_4QcxyS ,h]xlc U4Aٸ3`z{['%G+PBZ5u?MY~=ZU^œ̾>39-&1BTFr7R(|yHV r'{SD!Lcpkm**s~Za ?Ӿ$Ν=G>J8ĢpƱk!)rehbKoyQ2J*B/0Ii5 4& |&NK#uSrj9xEA$])47֎iKrܟ*' #|({q!%,gf4oVB\{cC .^oҎIvT~xS5W+Și8M"[vkXZGnpZP'Vd H+eeH:^څOS{9 dxA_B|Rg݊Ol,b ~gאԪ %H 2[aU"gt, =iUHm8J|}'/ƠUπ,Zj`lYR܋H`"ԎZLDDm&0.(﹜{X+TI>)LMp}kU [*G3lWc ;pS #P^󡎜XMTLeʉtX@˵Y{B7j̀oDS ,&l~UOC} 9ɳF'Zkgo<Ԫ4!zAqQ(f+nWuz9&quRFn#DcxazOș[|ZRz3X捊Q 5[eae||/[(9y6$ ݳn O Sk57W Z1G"@fIM xx9ԭXᇿh&{,)?J=%2XQ?%׼D]H?`tAN ]gAOјB}l?=0p]<'D6⩝(z5ann}@5Bz&ˍW7A9KQ뇗DՏe ƅuOP^6;íaEEgcFϔ9Ccz 72]s0'PK R!V 5qRl0.z:'Z8/.`cjkXe zK#M[.T |Eecn.{ 9UiCaKYuV.+.jV&VJKKnG22iAC q,KO.KvHv4Rk9JCؔ_k70%d*G^WR|l'ͮ|(Y&Vx:(j4fAIJ 8N9kchHQj%7UT[ԮJ 6߳8 {*dN0̽L&q\֔K=P.j_汤:g9|ݤN>mbycߝhΤ4W}-gJE^Ƒ8V"29r@@ .RQa8 0aՑ\ o1,76!} 9K<M釃z5 hx'yhmX`ij)E9KS/k\Oy@S5,AP[&pĵ9{`X7)͹b}juwCbCPm;>$,)uG7~#a $W#iR8p;9u$.4IovA,l F@va=%MKyr4"]&ί̒'[0mhA OB1& _oWk11z쫀,#c;BUwOZ7*Wws+'#AjJY ~4fxF';hC$TZӑQ2CbBġ yxX/LHm0t:8.ơTļvšdFed"y3R 6=,/W8 rho>MDbȢQ15{q&)9n/gڑN {+}w컨Fn3]ս][̷'*{eDta(@EPpՕLvUF-2'gԳ}+2EJ7YPCsfl!>"bjf,_B=/;K 1e w&+ XHU84f DmA83 5Ƈf#Izĩ!yFJˬx CY= [O.֢u{y|@a\X$0@CԻ$dy?n9fGP\^U+í؂99=E ;F'>jN# o6p*3je7HkKsݙ*gv*WNyT8Qٰ$ DA$Zy>8f#`cf;ԕ)V\,o(7ޔ\CMv{e-,`WrAK8|xuަεOihxo|9% `g\4Ȁ'N GH>ddP52>P+1| H Hp!]Ra몎]^vlQVÒTMt_ONIBP]U}ByP'~ļgzpgyojt!w$.Gv C,YRxAwv}: I-~Y# )Q6[`$6h)2T,K}e#M썚 t1"c'EWLieIAXY^uMM%ZCYbwV3Fc5[tD9y. +Wx%En[0 y-z$4"7;*q,4\L-(gwT$>Z&O*KZ3E_Ulq}4Ҋ1IJ+3S[ kˏHj;y i$|o0^ (ݹy>dhԾ>ob@\E.EpgH6qӖ<+zev6[u"Oa3U@MGDgO @쎦Q` $m*N$Qh>a@~d{@jX)kAfJd$;l\.:r=#Se^quU r V(@D!u+PYnl~?bq.SSg=@ (?@^+I@{5]f|zEFa3ɞ=k%qX/}_4?&9nrYR0N9hΏUGy3p*w: (yM+ Cp]sg؏wDV=^Vc|#Dqzl J6b|c1?XK ĩo`xo;[E"1f1_VB;ܓ +h{CZs7ڷfy gE(.!/`!;텈/l>pcʔl:) s |-o`CbM /CE^/|_<8x?eNn>Er3Gw PjФpkp!ccs7:1ɏiu04i^Un)Q#dό{ [ȽԕzVQ{}omꏽF)n]AsnՁ- ϏGDɜMSS JLʫ&5I/0g٫ήIm ~U(ϙȾmcrG*jr 7RT5,iّ+5ѰZhjgn/gg%"Io.&{s1/W 3lY?nuURzb o>)[41|)izKNg,2-IzlUJOsˊfxamg\,SlJ^-&4i\]gw'WBR  B7A3sKd .ak{KW~ς2bY}Ţ4Gikti(^^AQ~1)_J{DylêFaIɩP6yLh6o7v[hEN;7Xq4bae5l*+"~z ԖWꣳ=+*'^ OiJ^8D_?鱆J)r[XJMAZǴkWXKnWIXӾZ GX>*xIK7SKd63u+]@oL%Jz$Xé疈tB)ᥦu ^&%Ku;0he$!P<SJ]I\xf_"[]<BH`E]ެP*)IV0kѯGƒ TڡN$$ ')@Iq婢bqc2цu9@*/ i56>R[;+q~A]ZH-]2@Tc6/E 8kN PLwZ])M #!mZQ?׎+\M'M9)3s=ۣ_ dJmtg#|>B]{[ybR 1 mܡ}]h_{G)w_,? Q syXDV~[Zwq3jY515֪G&8+O{"i3P9zIǼž9׷9mׯ.&ˏVGbK[zh:Z"9MaA<|Tt dp%#M9?42 S}ؤuQ.鵞qkXdjG1ixaѸd.-MMV`Q]Y^AZ6 ׈RhT7W? ݄v5kѹ&qjKJ{Kqxi.cTA4ýa4l5aF6Mv_7713b6r2i+]e'tI:VNm[@@yF.:[n10[؈]iJʚwբ^X=$y2[YT,ܒ &+hTьDk…l9*LaM[d4rk5riHr SBtj)$nZtr|9ԏ]0kSڲj[gOA "fcIyh&G^]Gt%;YB8l'nc߽qYN M"*W.3B5|ѦX[:5'xd_nq`M#FT h uIWXX$@IJ7@y;7V8Tȿ0FL#`J|]xA֔t~ݡB)UY+cf3`qJs}0B3}Eu:CIHo6A84 _M{ t9U yBRi `8z0Hxcd>6މ )֮ |#'H4c_aJ@6fn^wj8Bk]]Uf7jքoڠit {m=dWR'_#k5a|Q<5G(q6ʨhAXb;@RsmʜS]ټhx\gx T_39kѧ"_0;ϰh 73,Wַ(cӮ5ؤ Wʮ8xU'80e E4-=,@QػJTl8jwc!_EXÂ@iwv "1Q[ D72.yP\M ǗS+5\.P!x~**mh!'x{`Hi\h5k]N mR?<=壟6;_?XvM=r/*1^=5bixw$Dp]@ œjͩ WVdCo ^keKT\.ò6yhNhfguRY)Ŵ84ln] Q  >B+ ܹ!o1^:+|:ӹKt(/^քKW MLe]m X)QdΉ zz|\?#c~f+fBFԈ^ +ujxq4N`蟠GX9>bHr+s!k-tNx'RTzƟGTwg-W-NSjn.UjTofu LdWEqE/e"UW]^rH1%"^WN JV.$T 7>>XcHTd*MdԇYmE|Q_ev :,^=7"<;0ɷmB-QIAiv_ʐ[$˙\r(:[Ǡ+cC1 gbFZ[;mތV͉dQa ,aT ^GNu VTsLjlk3vtEs0(nƥ ~1uĜPbi,C~#|x"tVȏrnHۼn2SkoʨSBa>Pv˞Y!TE= EڞO8[ F:ƻgcEAWA*šQ2T=U]z;wL!7d]e6y;ƦB܄(`o/nEoX0+rS%Y .Ыm6b]}nʹ. &*ԱQL3!R\DmNbxFDvjW| Wf%1;ckRA}0uQϰ}ōiN8|[Bo[ęMVg#+Ȣ 5΅?RHMZg=rrY%DR[!u5"+^#s7P#Nj`:G7eSa f+C-3f?ʜYUA 鈥4Ja )8|m]~yFߴ_}:@y>QdLoDso;|5fԲ_ۣc/~ ǞvWL3ƃ_ $PNW1಺[. 'f܆bz[/|kվyy5x啳 s#UA օ5BP?_y-͇P5g.pg 7nAC 46s|jAX oOKt_Uif- דOV%.Q̄:)Tl8#aD.H 5 zF K;o(;tiMU+ϴBIƄrȠWOf]Sm4L_4rvNE3{Cw29kڲKRjI #;pҠy:qtƢi8Y!&33?hg6 w; X xR۹Elη7RJR_kk؛',98a MS˛!L@&yGd? nְQgt+STd`Ҋ֢%̽F ڄLsܧ ..vʹ'`' sf%҉&=WA dGE ̽0fYFޯ%2vlم.%4@YSuu%!'.&XxP? K]?n 4]_f(`u@<{F r0-Ui`DmLslvPļ)Qk^s(SlԌjcz?FsHQ{߱2vF)y;EM+fa_γTDfx_þΓvHO[ y_P<pcl9c[/ߡJd[;77 ;0®vDȲU;:Դ]~Y0Bѐ\%7x*/J[PS:Y-X'@F9 9;0W9o$jI̻U"8F)lvpjP̮ @eHcuNuHR/ 6<'b 奣w:+sn w)z&ÄT܁V?%|44jɭcfbh{&{ 8)_@,uWC/E] +Ԧ(9%=?u+?L]lP$-iIϮ 3O3?ߐ,e-A"^VʮgvhZ4nf7)GW\> pߒmPߠzY(:{ۙv('p7CLW\0z):%FBst0b;aYMYxAšQ]YBئT}^vյ_ɴ Hkgq±}Nq1\>,(k@ m~ ,85]/Tmvj,`hX2W: D9ΪXdɰnE߁Wyen-띲9+]gb rO1_>^ O e3]E,e#g0GkJJZ'c(59v#wB[DVrF;lF{0p:D/:5#ڨKp 4d9}zm\穩8FphW"-k$ۘd8PҚwi?cj_ ('Geӂ8:Z+cu8qf.D ;r]>\dky>W~SIcaU+U$,PnW0}>VhmN ZPu\[i RlgSR }:nbNr2{98V G;?ѲCStlpmjG? )PxDL#6 pS5p_%QF:}J򺎑"\`ki.)TBzu;鬪NO՘K¾>D.uo:+@F/4B5KlYs2ףC/$aH]?Ѽty\h.47<'Ylb({!mj@z]#"ejn-AOG5FQEo,oq^8~]fyP, x8߹g1w!vUSRJ5 2=×z6%H]v5~eB?aJ{x|!qSYg] Ov\S(]zPc]fy{| |c 7P9]jMRg_wFҝ`&ۘQ~*9xk w zjX:j% L$ZK@x)&2BT2ÖWi@A\ڥDܸ65,𜐣őp"RzreP P9Jêaŭ+Kt6 aoR xesoUC3c؄l 2ԡQNrvsM&t,J>+@< ˯xjZZ"۔G_+bLs}ؔa ) W֥UE)-F8Gjsd ͣw%$wrunҘyNTIb ʲ͂W>8=а^ݙ.WZ^.pj!!/t9A/|,u|&&,!Ϩ32H?Os$~r_K;/(2—t 5~m^ Ec6#,1%f'JW&%ɖN~]/b&ޔ2S@FW"7/XSZS _a&4v%&PCQ1f;ݑP>O0 , 7f~L^>EpE e++DvsD桰 ] '@oWXf.@Ÿ@&πx 8\yBtRL?xM6,:U#.j-X+Zˎ#.<i+1q>v>xG#?D-:$N#h-H݀Ts!.] ȍɵ+@K'< ^5BNhg I|`7K oi[SlKj9Ug{@ ھE|U:uC5x)%yLi쩑Gd3T>?@r$+O,ˇ&Z}1 &V~cGYV~<;i(s:_{Pݏ x4Wuq>K4J"X5:w#]@ w+}_ j% +d1 V—b9_BwGu@4T5*Jsj%'+s=!)ZhAd>SU}E?l(8KۚM?Bz](s}'K̵䁴;/g>EjϤ~ۥ>|ч^?ĺڬ,95hIG")5`Ч ĞN02/` G}rivEy$)$ZQ@X$*^9NV4iyTosIN 9jc+bWEKhN'(%f򹇌xO)Zi#>L%KLzfҸW2/I={3gCid@yҥ\%eoL#m]Mu}QNg|}R"$dhϕW;m8qSTT,|m9 ݍ(U m h`z^YV`z1? =7"I0t~LU/dVa N~yge$F15oTF8Wy-bCHc)%hQF.tVZGUm&Eǰ~Ͻ2NEnR_/h. XF}GŗXy&eKӑ2CW|#˒-}asuX7uˤq;P,ap%L]m6x%h+1brs5H@:%meE "ǷVPT;O.e~>Z BlgcIFqḌ Ȃ-7Av\_odXдK;j Cիg7'~䅵OI#ۥi0)g v~"R򥕙4_¡wⰊ&\ W)*N|I*_LzGQK[xՎ]ţe3@$O7ȏz$W}sFSӋ%l2Mp^┝ Koq# f2ӟjVpʗյZyJ0V=s(v50VO)w6p>!8ń~Xc~ṱ2Pb)kKgN׳w&swb4yG*Wt O֙kks+tlvM̖t>'j*N>P̨bEHqsݨi)5|{PP0VFߐ(t꓿1+'W$Γǂ7̓R"JYH6XnN?I',̳,Tw@;[h3c 6[t5D[\Abt'@5F4:kyM$o'QJIr";e8'[ }VT KSFU)B /-!iSe71p/\:JV(Vɥ(&OQ5sb:UՔ́ 8ģtsLnbdT DY'!D0J}:<'f^Vب7/InE-+*#R.[]_pL|h|rC%=A]#N"_ZXDDSgF@|-!h7?Ĝ7f-˚W'{#ՠH+f9t1Y֨T2!h0V4;'nRRsb9B8Et#^'pLȶmB+._ݭݙO:fOGy-Si:LDJ $an@X=vKh Lcbg̴GOأ|$IS>&3 E4b́p [jҦ v܃k(vN؀dwm147Pqr S_M11}puƆ ?jҎ.[m :J*f:,r"9@OňHۤ 3?TJqK:c J﫤Ecg9j]}R4~wG]Tiã';\(#^t碗5cn)+w7 =14y0Qd=}M- "nɭJ5n`h10)fP5O´]|g"S{6{2{P eC`!>͆w~Ytk@|ܵ.GgFJB 2ޝKp|bH__q̂|w L:La"Jt- %hl%5k\i\b@[(=RKҹXOY EU8dX7QM7sz%kNxSZfW175nUZ8ܘpEцRR/롓2) $[o:)S%)G~zK1FJܮg"TWȠ0i ņ+7BmLw=*#ѡ-wL'l؅K qT\:aMrΘضy؞rwm{H!]8I0CAttbb`]APR pvYwy)2& ~(e.:){U Nx)[C2'yݑE|q2M ·i G|ո4@<`>~7>&.Is:-_q2YS3oCK UydD8*[gUgS< 95d#Hyw7#)H51f9[1?X;YA V{N@I$MG~zUon"C MB7JE׳HGȢKÕtDUE7*ҮH$9,< t~T9nmUXf$ Xm=Q9˯z&cM)=t.J8/S}DqtU1}(z]޽7G"uv&nQx:ol,0Z8@8EN'`#AaԪ}?_"A2o.KL9*4j tw]MRM Ip,Mw9TbUkڭZ =eIPfx>1! eBVcG_U*D^'D:o2GZE᭵w JelGCF6e}:jWN]Ӽtnз̴fۮ;˔gPy+x)34 ++bɸiÑM PeQF=SzD+Lt0#O3ʼhK(<_^J@=2S94,'X-?>#/]1ݔWeuU8DCnd2TjW54Ji_$QlϰN;w,k 2a:{ZJ2O^ rDHe[y@p䓺: LOکU%|1ljI_&YyNה1A <^mTb=9=K/yRP|v8Tӆ1EJ[F%xTMuMgb%n22rRrx/t;p =`RePՊ"wg)'F w6<A٣FoWblv]j'<:[$2{J@.f+E9}uڤ:H} ]\/Oj\uFR,dxڶ"Rʂ-Kh#X oƑ'?W W.o Ο W bDsмiYu< 2k&֌+T9h@),CBwi4֐nFV+(mŗnpGL]Cmú^Nb"$.utzZ?wO~#8bb5zk.^VaҥNN\<[Q*{ N%BJU`*J,;Oz;/~+zr<"ܰ[$[ۂԦVBQz~?"17;%0 X jS>3(mV}O W gQ `1Jo^ *Z7oα*Cإ9 ֵTT]' {69 O2͌IK%&z1Cݒ?]Xx 5?j~W(5VɑD|NsD2J=6GH(0L-uYnfV+;24\LRXÓq|p,#=(G]>32af~K0:%<ԗc 0VN isڃsx8 7XχߵTh?Ozl3,֦soݫӫLܮMGo=4ڏ`W#L-OTYpɷE`&Z E&]@T< ݫ GBXYgfyB)w;!Rm&gcQ@] a$M=%tj-%3)_Mi/)4}1lo6u6Q>8/lN5i!]bFvR8vIu)8*)_&e)c.^gM$n xG~+ERޝL/Ҝ~$mdˉk HЖvRfI.˥h).w $GWo&Ly/¹Z!Q6*c\dD{Hmya ꯲U+6+"elYU܋;MQp8g%4xMHܺ_Hj`ч𙽯}P Ԣ2: W';`iX#vƆ@ 3h,CŴ$D imKHdo]<BO( ' 9jPKE n?[{H #r 'b~fXk@kv,;ju i\$.GQ{c,qgw|f .O|MOl?Xg+Eɒ2\B~efX}G6k䛲V+/5tUF{\LF% KX,{z!m!`# ݽ^jx/ ZPBDc{n4(ߦ8bQ$-8Hn19>\}g76u;E|%%:GE̥),u5ӿ(-& I¤?@MNvLϪbsco47F}; S2KQe-6;$8 y*yWs5%_1o0Ayw0 *0>*ZʎIdhO<Mf6YRo:B!), , ҟ(5S_*fEIC3a.T Mq}%"{ĐMEy\`$š=4L b0l֖:bd`q`\Ew7GλJPurmeCH;ZD ^d٦v޵?)70l&*k:TwO@@B]4_7]^fJ Px2(Dkj@E^.FMjwc;4pBxR/vFM)qwotd@.(YB޳;zfژЗ|$*~͍%-:akЄоVhu?ڀI0ޫc"SGqF㾄[䆜gv[f{Ԫ80>a^x?߼:I Z9, "B6,'7'{y&wDw9WBGWk ;CG IF*{6uof㟑nPHz Cw/8;WʊEKN͒[$ǕZp3YeW͚nBgq%ȫp348 6>}2x!u/?zɽӻ&P"zYi\VBQDՃUGd԰L x)q>˓3 a;itŦjN9lW%DU󈏸h2)2nm?0/}U:#X.]تbh@I !g 3Bz>"c5Fs4=8T%*hp 4dX_}߸MrB!BK7H/'&;K;c;eZ恞;!J9=D|?Yo${Rzn 4`4MŜxvI-1ܮ5ce#tI/uI̙epi7w )Z&ݘ[g:nGp(uTͥ`Ho^2|YL &EzuFќ2isfSvaъkaV6˔y `B(t7:uFs<.4{ Ȉ yQqeߚ|&MDJtfܴRrԆ]k)[X@|nǶFOHW>8 S2E`5IK>Lr+xM0E)CSHU-h;kZ#bB MɓLS&U(ߴۖʆ@꽃nzTn*SL2tJPPbv?.~!unQfMvSO9B% +E ~pB: j,n^_Ѿ B>Sg!;l( u\xRĚd-r'ܞWr׎M6uCc԰R#r5G4ABxoZ8Eɛ u.F ~A5Xn[Fq启iT{u|lcdx?J9-~}K+󫞵8ւg͡o1J0Y _I},֋v+GS\,Fa@Ns049|cB'|;20]8 @)pU߽\3MޯRgbm;:G 7գp+q8epabB>M9eY23 dLٷ&2(O}$#0RdyCV2I.AR\wZUhHjܿD["+Ko<~9ty{Jkwd˜6F֧{WA$~U׀B:2nu=W)͓h2NzGomCg* ko&+@18'QFh5MH'5d{C4zA$إ]t[v OjYxh]qȴ΃*~ϫ wِ9=s}!AOZ'˞FO]AzXlf*m)CP~!--I8TM# "̮'K5j:cq6+LUjJvN7oM,|!k>^ΜȜɰ$`PV4iqG.Y>EˌnELg{ M\3ܕ(.,+,ϴ ]1}e]Ԛ@Xv2mP^q1@c,OmN ccl']"\ O 4_J T'7XuGd'C͛IJnЍl-B3>z nǍ,MlԂ#>h,W:^C , &C-%,s#BFmSN:{kȃggHgCFs KC09)lBy ~ə81!x?S,hy1H$C1O̓ϤxJ}degV5R]i?[RF`[wqΚ|2Ӏ.Mnp#4%ȋ!4h=2/̀*vj+(K$Ӗ>Q8g3o[@ l O[DߏԀsI%jimQC,9Ѝ Y>S“bƁ'"_E#b*@qYm/#Q:ZYq +)\`ɦ̹7.PM>c +ش8gU gbFIޫeL(Zwܳa@)k9 њX]зтůVPد=`% %S,re״rb]&yD&fI@ku :Jhhʮ6}KCbhUb9ƭCE,yo'A3#?ycn-mә]bB@<=JAw$kɶGug(kKX]m! nt%1Kq^ Vc秝ue];2cШÝW!z"s1vk^q(,]|s4g(M)KaS-;; dh/tij߿tCjSGj g_RK^Ks}Hk/,-o=\sE-9‘_"uHttph&4Il|^~ ̚;9Y ?-òhIVt7lPD( = xs_;vKcJX!2kN&j6q$@;/x 40tvgzsEesP}5n~4zi}/Q?DLt[5co,|{.-W"3`)LM1'H"J=0/r nXMv3&s RLC*BÞ!(k,ּ.9|i]Қs\ӦlҊڻZox8|94-"ʷ1E1H}NBa<{~N>:ϼr,TڕF_͹Y8ԙ-Sݫur.H-讦x*ms.J]ʂ6iS kDKs;}K0mw6hpqp$Ux=qCԯIސ ~_Y_qpagCTj;̶U5:y.O*f}r*, +D4wLTPz)AJa0N}BCYb'C O!\G \蠋Ǜ&trk :#W=z~԰_KO;&\A>+DHM#֦\|P NW%xpo75ljlxk=Krr$)Q!Uz …Mn'kqM ts zA/pVZnG[aKEj{ fz I TgN*c=E2-݅/ˉ4KHscUc#J=ʹaJl w mvJer(~`U[2.#0֨եI&gHnAt$ R[ (Im(#nL #L`Y4Ll)qkJnj4]Uix+F+[kmIG.):k=X*G򁽣7Wt?yp+BTP,#ܼi$ߥ9bOd#W1QRٞ 73c1r~v&3XescGEYb:@cv!Y毪D1RO^ kaP#ӒIdTL%CD7Odn #:s~e"p"4Xy1]3fgl0Кx??Ḥ9? GT23=ef0{+z! |~ :pl혊hX'{񃭩(Y@ 'qyύ_Ÿ439!'g]dzlIy쨗.(E+6MBQsM> EQ+|ȵzɵ6൧n؞"{h+oWF'OMcm@1s/ T(* ̕^G1ћ$bɯ&a1LZHd3 3 E vyBsTYKo{9[ͫTO+ j{%;@9Y"TP+$ "6mS^aZ,K_?7;j׵N5U ~7h¨?yYև/־^#Mszxai%yHwP"Z3(%KބE,#X1fsM+ѵ8Jڻ)jޗhbMdCYoxӍ߭?) Yli-biH)W߈l#OtW TPnnb1Z />r)G)T^cCbƬtcwzO@J[pI219A+a ZC"*q aWwSs"ژ$ nXP H7/{g_nt^Y k`#3Ek2t§e \(ܙ|fԄ0[yd )3UwƞK%HR؆Nku~#2#Q1?^YLB]1CW 9Hhgvb~aM ُ3=CܔJ 7}h!$7ȝ ZUai`7/ ǹFqqkIqmG.uNDUsO^bd̺濴)b-R]JA9;ɪe!ۇ8EOC`\B>0 <Ĺbon7{Cz% fǘVI ]1#0mQ5TDj^Vrp?H_ Fp3 Aj(,1ScҦr@v v (jK.>w t`S+)6pk!rĘB>,WLs͈VS0XU/bOi>p;O$] RIh6{k}dGp-2a}[9c/F:HI>=SJb-*>K;έP~e*EUqԊ CZXܝϺ%6/@ak$. oM?a'd @qx[GΘ4La+[o@9 ǟ^T[*~QT;b͙fJ<| %1{D*{ qҏ]x" ̧ 6$rP28Ŵ^< ڱhg[8竢k\tX H+l}(Ǐ\gz;Q%7ȋEXou{R'c[8RؚE[B~Á0Gu?(OvcI.*)%1`|FnzͳSUJYinrZz$@nSTDT14lv 5ft 8,?ʉq e?B_:Ktf1Y\{e5ocE}3.X<u?r=ՂCߕw}!} E ,YF2\lkMOn)kb_Hy w!ft|Mv|Sqc~n O$4dWƛmt#*\Axc;yΑ.NheŞ`mZ ۂř-VmNʔ> &V}9zjք[HQ@Sqߔ^$VC1gu&OwkX[P*0)<2KO_԰yB[J|MZg2x0PXdY/ڻb(' O@t|4?}}%t{%zC !T=0.S&iZE͐?08ABu7߽Xeb*!ZବS,UXZ(IxL?7a":z2WZr/>$]hM E`pQ W3zgXW6^Lv~.FD5?'vNM)WLKD `DOY;pɌ$K${dQX SKH懅ymHwpϲjlQAIE(Ew:d!֑{ O3|80ѓX4߶)bK9];r(} cL^NpTvԆr˲"2r=sZЮ0kæˑӔN./#?Lb(a4|\zdW|ʌ_C7渟0)"2z)ܽ(Fƽ_bYTb~|@[O"f/h ݪ4^J˛][a1p ˱9H;-0?uy&0Joub]|v~7:~}`O nWH(4ؗuddX_mQTݖ+oq|aJb ~j^Yx}E Γ4G1rpLj1539O̾X2pg~!nBɴ=xS18|Ŀ_2}1nv-Qm$5*8 $A!E~O@i !1 g iuYJk/eH~aQSJU"\O \`Q4$oHB._ ^N1 O;@+_z%sB9Ezw\0Iys_YYڝ3dmⱉIt~:xqP/>Xx1,ŠKV2p0vMg9ȃ:<GʚJzqWo*7 1lH0=$YVR@*Rl-qZ|5D{2`gaƄlCزIwN)C,<~wڣ ]:׻|vB߿?+WKɂ[!񋾈ZCM Ǧ<&3@qv4}`ϒ8A@at sշI#}g1>Г?811Dcd\= }RsU{bW l$1 1>7 x/kg6@P U -^Kg3-w*ڸ %(&+c5c>l)>_R._(,'GDhixF [:TXj"J +xImv+M"='0vjblQf'/[r \# |eǴ{y 1 n[WThWLp[j+ӣfl`@ )o/f4yavtU 02QV918|@ >Jg8i`U ]&u[?:cD$H]\y5=#DH;F*̌D]XջS*D E2<xʋf_P <A"y^~+Ӑr'3 NұSgn]H<㊧`;F%F`c}< Y.ȲhFK#QADKC9A :'V4δO8EUd&\.C/Eh~(LQߺm> kzoYn5FC,'t}>I u 5*܆Fej _*( ˦[w,iz)Q\A@1 |zgxf> j|̳6ԩ.#ôA{(컅iQxchLQLZ^4 W<[9[`۩>(>13;LP^Lk¿`OIS5ut=[Ota#[YsxwXse*pƥk7=9:2E*(=;<`qe<tZ;cüd_F5%ffa,qZ!PÎ Mc't= c=[e r$&{ֳs dڍw[>1UOb ,xwۢ;ƮjEmȽ/_fO"dADV;;+s `53„֯b߬lyd'Oh$3<.ePM+!.okK$ۭΐ҅D &0zGnn'ύ.@똑ܹP`n$kqWUBa&L,"1!x;T2^V>ۛjPbϖ ;yILc":sEPɌh O*u_NE$~ #> 1j HhyqbP0F3z>ض Ie@Bl(ݷH.|i9O΍Ihopbx}'T!+}QYV*s=M,&Fs, ;87"Ԣ+ iCqِp=E/&CXT|bZ_lk7av!c\HHT/-3,ޘY]b.bs|κPYcK} %ƬfT?E=w=U 91 mt%xMCj6bL[ Ő^v4ھ^W/ tmq=߮B΃!%^I1_e6`Be=Ⱥ="?0szh @+M_^IJG^իplh(W+,stRڥ1t9"<qz&~Rw۷w6>|(/GnU3pFzk3J݂J$mLF_e~BAE,GD޼*} כS?DHK&BZ rëM;Fu`N [4V05'=ոC_JW`*/4BI`qb8`81q `eJ3\g%&uo/GEV\+PWrMb[<9֟oTV~}֥@'$S%GԶ|T [pcAːXJrOv# j@.-lwNDN.hr|Z4:E931T)Y{hk{F2БXlb)K"'hNZ#v$?.vLP{W ɓLn+AM"ى)@?0ũD̉0Φ+.LU097} qlev|EL 94@d* i 44nRkPw+6ImBLn0:FU_#vhbI#.^IJ6+tle_[a}&4oDUب:tقVy3)j~"u¡,)0ːXw@KNL_'FAŦf, -Fwe :Ԏ χ ;\:Ԫ=/?D{egk_WMW $0XY YE;&r>CW؝Ĺ_8`$gi?er<="Kb<1V̨s?_:(0P 7 ^5]BEl* \rU Σϵk_cGf*>X}B)*r&]SmB9̤j3n<./t/PTIur8rEfoxc"Qa:j3U8=' o&VvU?B7Z.,⿽p o7Bzn S2=0tcNAo<۟]9/JLD)2kRE:QtYHɵFGEѺ3ot0]H)#jߏRGƃnlZ~p o#v^ -#h,wO^̕z3_V*meDsd FZ5YVi%H Qb'P*c2̤zT۫K8ƈLS(a;16zZ9v=덼n ^^K(n'JM9ce%) 8j: )L59.rbgڎ8cz9^W2 ȞW e1S5ҋ*j=mD4yʴ.&MY)]fTqQCgE[¨d='C"N C@cV0<Qii;T-o=!I/P/E,f{ Oh>tӖ-ՂO(7Zp$CXoI^Inp+H~^& .G=#lncD\8M1١C~Ay7N"z7;IGdH6߲(_[;?mrM?`F`z p69ӷ*RXAjW5v5َt}E^d>#ƾg}jmCyDVSe6UGU TIgFB>lwv bX7Rba!05ڹ_l)*\Msn=tc&h]T0jܷބ-cDk%NZ!r!3:T> aU.ǔ̌+\24q(lg9,)Kxo 36Z@InU79뀌@  X!#@`'sUVm߮Hl5m ܭ°^躸7<^(>|aʐsAWݸ4ogj^|RO.#}5B8WG\?1812󿘖;8ZSC8s(GR?#G8 ,'Wu[).ˇw?3~L ' B:ĺ>)Zkꐐ)J{y ylhQv[Yk_B8Pcz7,?=r-nc9[dfsW$E<>+(C%Bu9J/'{޿dw0XL1E yH|jXkvVW~4W8Oe&Y9?D#{*hA7掶O?&PeQ}G0y$>1WgZLƌvuȺ%M|Oƀ!SrKR_Eىǻ)TSպqqn`Wwn!wLAG`w9D_w4oᝳi<ǕUYrYn|1~5ֆP!?g|!$q,~WNGutC@7sh;Ӷ˸Y! ty삉}BRT7'- 6hi37\;qʻ~_d6.';봶ܥ oGhd nˁhmGm4nL6%q^iP ǹ.] dGح -TYLle0@e»Or;Ż?ؔQm:.j! ''1vR0iܚH m].|7_E8s!!KO3vJ2s:Ӈʅހl!~620 "._hd:K62{b7]H4)&,KP}5aą>|?.< B5|]?(ljȃ'F3"m CBӟG3rG2ձ^ N~tq8=u V.'L'vŊ\؜ʈW'je nrUIq?_Cvo:Qu&" 6k1J@øP; $4lQQ҈VԂNCrʞ2;M1/UAra՛i+E!TrgSMyQV݋~,sׇW\bez.ٴ-OwVpTf:!vgH gΖQf{AvK$_8Ol-@ڋl^2gaE BiPbC?D$k#<Vg'*J_ڱ? Nea 7r7Z~\"Fht~.Z7Gꞕ3Fb&'F񀡸D79| ԟc<3@l_S,`/^ąZmFnW[FK}p4;fgCvd Z=DBR.`ܧ.Y1s M-FS3%%ģx/&R$91g,*&6 C$^ 4oawGX.ZH?sb(ĤwO6OTTh;h"6VeӼzߵYrbț?\3>3bu͏2.#6jԴ SdyV^X([?A) pu~]0مﮦ0;בOK#s [00(.Y}_e&vY:]{}[H'+Ug;4H_^dhz= ktXl=ұ"TSc3f\h'ٓgS"fEO}zg2L+#}}2+z_W_7*m!<,\u+O:xGG!Ƭw++JI&_X,|hQhClݓ#ƺK=ssºi/yO$z1 P]9b: f :NRʵUx'. ̾} [Ƀʾ1wѰ!.gWU$J-YQwyTԗ AߓNJNja[6j!1tjs3-nCZ=ߜq[P$RA-'=*i bQn bj 08q!7q2#w|-0ofFŏp٦8:e>Zd{JRV&$jG37zVs5,gg& Qh+-O;9]hw%CyŸe奲XGqH _m6,nM__}'E-2䲃tZcͶY9-2>Pm M{O7}rG vGyl{VN]W$;{W{z=ɻdoco*3D\ ( 2.D7O}I}{Ӄo)E1"ϯܼWHllͣ^4k- 4m \ yqm9}v$*VYn *EdNE3V<:.[ Bg-3V;| 3(i$ȴa%B`kZ'lXvuDjr@ċ͡$rtQ[e"HM6צ{) $H9tpRY_ KY=äƱxXz/W͛Qki`4UQJeV6nqsY`\ iV'-\Կz_J-.b ?nOKFH'2\{^tr*ӞyQ1H׫  &4܃pJoE{EH agFN{ٔ H')Qg?|hnG١vlUNn' 9w/X[2N>fWQEP^Iv!*+LDeq* "׍&}qmC !p4|ͮ|N@rx"&y~REψu<Ψ<c wm"vŀ}#ʽąT}k FVP쯻)|3^(_'Kw݋\]Q~Ee,I$Q20T)`f"2iG> C9.8WhC^=r>LȜwRj9P<1Jݕ=Kb7 ]vK祎ʑhDVu06PAdX~DM**g]ȜN͊ṊEަy-RtVI`[ӵ+"Wvr`&K@KA*4J?# Kߛz_+;$Oª2CIr&])ލhJRT0,#, S ItY_fv'i.^fa>ҝɣ~?UI-Z$R7ӎ%JYoz۲=U'HmeYÓkʆ\`d r Noq#ϊߒ]aY1i&H%h9vuCf3oqc6Ǭ@,qmn8~{?FQp9d . &K꓾ȞQƤwD!5<[ӫee%Kym+q'ȥ[[L!7Ԛ2W1`s?jTm'8[>֊tDNmZzIH&7[+,[%J1_Gg<6FEp}D0Җ% hf&xòXBY{Λ8_TҝUUW1.H6ܹ9&]t=3 ;]Fޘ2ƽr32*)j0hrZ p9C{mq5>^& ̻s7kʟ![GGߨn۞\:|sh6\N4K w20g&6sw+D?o];|P9 up19T{DgRvD*, /aLn"2|&K}'Dz12t$[y+fyD F225SB |`M3%י[w}K'd*C)3h?0!q%kHѤ~2)rל^'Tp~B#[/D5v֣ćvt*JWW4TnKz:n6?8 gJld3ꜩiSm%j>]z'geZbVfU}Ok.;2z]i风`GqoRt6;YaZ$iڇȱl.oCL,lOS/PS VȱvUV{Z)*ͺnG7S2_=HUxޕԘDqA{,M8A@/%aTԁ07R9Yi;>a.wes"8wlޔ\Jr\^iG8߽O>пDo87/ B$wvuc-n7 \oXZ9s~?-lQ>voY 3CSL* 3BRneٔzu@,!4ǀ]ƄOǁs1r\mvIt[= ڀOKT5lcKMu8<8M@HqJ#ya=ah;I6G9X*V3.<<{2Hά5 a{-cai!QfC?kے|G)L%xC*a^d4W‚V-m!V_wRoFYa l  4~dKAsQR,9p+egP=߇LoɟZ7a^F -KkM\%Lpsm!#Q3wāN沅;CJCkF/?zB $vT֘.~_q93 p ;'o: @nz1z?$8 .N̲{\Ak2HeM{Ѵ&j:V%5Ԁtl-@6DkuR ghY<3\ Z4{u@%X;Ͳ0&. 2j+LRN7UA$ am4YD媰* !R: U.[[AZ9VñOcyEǺ&ic~$ibv>b7ϗ3D ^£^vw}];2.]cf8jiV7e+rnO+,&Bő9 uNP/,4Y(#'|&ktEwgB\).B1(hXXLPplrco-|9^x1-z3WDoRb+=+#6Ȱ>+O<UfZxD?l%9ijv Tv͡LaJ^ephy֖H+ 8F׵ܠz2<v)ǂsb|hsAS ']I9׼)T@0& cijF*\*!OUS>JaR l5\30qi>PAYsyic%ъZz\q6'={*I~Z |ǸzLTs`|+v#?!N'vbd`RzLNSlYc)5A&>Ny.!=J.,Rʩ.IdM'$'ۋvZSlzm?ɏD~Wʑ5ij*`GDo2DJH#զŸDpЌqc?>eGbϒ]b|qMa'Kw-(@-N5a샸H$2XRL`V`cB|V?;*_)!%D3%3zJ:3FU87`T3 ?B #y 4nGQp SWM~hF:}p "BJQ1C{5$^* .ełKZ^Hɕ[_۷!k{i۰W~hBȿpӵ?XğV9C~{*\Sx F`|a#;-M-"O<҉ȰՓé*8jf-mvҐ' |go>b@@V6f;vg LA8k ͙QqQo\h5+3_[z>ߒ',u7c0'֌ω1&lN4%'x:sFjڲfWpJj~oó^Lr%D"y19/wK 鵏qA)~vP 57Bְ8%v!pUidG92^]e}8K,cX>o=/$C8{Հ#ˮhN w8fs[iJ!"8a\_$RU'_ʎN.`LN }:ƫ=< )L2mOhE?GR^CdV05:V#?52TN)" dzTI\bUWG!1G)frծSȱ{1Q KKQJ So2:exW.cxCL"g]3NyiBwiKPh*mzxo+ΙQkN$~pпg؎.8Ý,rFe5h~&D8]yj[[u>#`6MÐJgCFd5ǯkv^\MJ2HqRP*T.}KYoXG'sK6TW -wp$'$O}wIAb LAϕs#{ZPԼ3س|O5d<2^G 0R\w,L*ރ5A FP ?AZSzxC3z;L/i '୧e?l; vL{5t\11W/'ikz'Zcd]toI9#R<3bKGْ) z9uӊ5ј" ԷUai3׸)Fd ,NJ\3׬rȮ:M~Zp(귷@H8+vk|&,yFrn#P""3Ey#šJMsB{-ۆ홶`):pz3Qc݇'xi4jGw'S" UɼW"0-/.)xǽ']a9L6Æww/9+XݠO?J:.tGxX/`r35z"{S?vUD,Y}4MA Bϸhpn 0攮\NOkk>XhRe@T՝!g\<~H5όDଠlˏ(y։ wziT+ ΍ Tc3$4Cxy!Csiei yT j5EK"N~} F _LAMxa+ijCGsG߳%Rx}ݮ iT= /Sb 7I@d2B 3>5qۙ-.x"'8Bwvf1gz 1 ޱ6?Q26A@ȵ?V@맓o 8lBEFjPMcs pk W}uPnΠ ,$ލJO9VM̵X>>_ 1+"ND&Sn*,NO\01iO. W_C`+#\aw4E Mb:~"%IVSfd+KmjW` uzC.j2jvH px"7*cyt:YPh}C|, ClBl!۝k Z77,LNa*Ѝ;%YL%Wg nLYNrY3̵}g 68Fvͻ|!f0FRxT|Ϟ$e,ŘyzҰ;^x.P \ V=!5YSagQ6⹫qnԪ627A-t Teg^7(P5VXe5mSr\0:hTz]f\vΌ-v2{ﯞV 慠ty,Sa8`\"]L9!zaЉ<!i~d[UbQpk/Ѻ'p@IXSֶq8ovsG7>Oi29E- @~_Cl 5UGܼ{{uFIY#ê5s&+9ЕXZ4,ց.tjBf1|NM{_^ _?t=Qs)9?26ӗ7K8dCGmD`n[ 8=+eK> ?m9F+Zj$L{)PtdF,n9T_'ߋrc؍q&) J?[n"m؆n^]6H|qE0]b[ .B|khJT8WH< #L'zJHRL>;(7C2?&%?s &(3cVMPƟNr?X0D\g!LϬc['Bv"P:6v% aZڭ=ŋgUǽ" 3Y$Ng5l66i iҶ>kC +1QP0ioՄQcf2k8?{􂃁 y(ҏb4UJwx| G_%@C@t6!h039LoJUlFiRJ|Gep ]6 "^|Zs<3KtJ*`o  ;[1d3t7rxDGyaf<\2+Tpr 3t`/13O>LOЂc នAd T|^(m),Q?>%Ov+WڨtKkZ^_ERCM렯b>DD[-qڳu>O{l|@ KVb1ɾ<e?rJFi(J<=YfŽ٭OE ]H][pұ1 b~w!!sYKaZ~zB:W!K0Ƴ5{jBGZyQDe $w /R{ӚLFᙶCc:5O ot> XQk Wh{j0V@{i:tHw%7I03!I\wAb083VXfX8niރgwI=o菇VvYgfP(Ԧlⷰ0AkZJ,:1Baٔ'^6]);Dptm>3bi#pK0YOJ#y4|y>a!DAn.MGjt!Q@Y4rEzz IjHGSI*g#{JW@ e؊f_-N;f}p5J>Lood-"#=#s-XJgѳ6U1 p~M[ e >8V :/)CgfL[GTc.{ffo2|kD3;(mPU0DaDK<+"uI)<0Krc%CRGmjRBқ.>GRƚ%$-YvBѬ cȐse( |4y𸁴oΧp!%~B*wy%KҷXߘ:M)ӋG357CCMy(FS*ϼc-|u zKOy-NrPN\gO¯AI!`+/69\RAƓ] ծ" L\(fsKJ0zKO6VW\2&ٜdvUSx7v1ǽxBfb7 KSTvsޚ!eiٲ 4uJf ׸lOKHgR)a!BA׆l:fH$z@B^?q }s݄Ml^`Nj]Ϟ3a@`JlL>tA!.S8LNjvpd.H .X&oJ0ݠ=VZUh1?`n3-`alae-:Zx%L0[1}FY0y8#d(G@t}!5L'Ac5OiPgeT )p[;2ðc{q43vQd|YGUm;XxR,eGXbp9GUhQF1 hoΩ-O=wL+ӈd@S}Ei%bn 6g\J%)r^\/Ab͜.kOاcs-ȡ乓cg~.ĽOeks 1&(h+?,zVanu;\֧;d˓d)NOh4muhU'K`:e:S lfmYvКMB-#]OemZRjOIؑM;&e>N؏ .cC RjVaA?<J_Ly5 2-0=3I9?[t^řV1 ᓓbJ-b@ rp(!vA 案%>(;l _ I1MIbu dX${kk(8IL?Jk0eԼ>Z%GB a+BQL$$>] qP?뇸I/a2l*|ѦKT`.WitjA.Q߭8ON->Quz/O/7@1ģ-5m6Ŧݝ vM;0Ǖ- WtPپ)KY(%(.Mw"jA+uQ}~4V\޾|eߪ!=z1Իqhs[ /G /P |},%g\WՌOk Z_EikfbS!7H@Dd,2N/uN&͘.!J—U5kMX~qf}Fڎ#Fi$J͍\f "Fք S#{`[O {0dK]Tt!G!,fC.Zӱ@}'DI x T)H׬jX;aUvbw9 EQ(N"~ppLr0K=e( Kq.HB>ctp ypWALテB9$M:EL*{VƘNd 'l;~TST>L1/*hyjTGC!Y* 4w,'něT0q R17Po|2-Si.-KocB{wSeL;Jm^&Z}y#IֲUFP˹A770˳j|2^rx᜙>̐#OB+㿑'=1-PhY׿nЬkE gHdߕwGca`+I R'maEڣwQ=mrgYi5,h֗}(@jHn+9ְ>)M`՝ʈt+Ę&Y)+[4~BD+hkaDq(AFᢰ}%1ٽc1[c=EJQfӗ½؍6@*X@Trf0$#j^8-ln\Z餎# -}vuJH&wod }Ff_ۛ[Z4^>*U{5ydC GnYme%X@[f=“BY-E]kJ]8y̖Ş6eW{R[ȁZӐKsC͠߷fy8t 3a:1I~ԕ]iYg$ҭe(˘gc^xGyG*3C:7äзܐqϙ% 0b׌&OS2q c[&wK] l4ayz--~ '*E&(+ PN- "lT> `ᣏkGv17takj8^7 MHU)FGŬӤx_X2GVSLQ/ {Pcn:unWGwiC&x =h,;s1L^!;t0H)\3kfQ>fkLbtk}z%N^yfeIі5$Zy% [Uщβҫt͆4>0퐠٫W]F"QR&@r=]pvQ@ֳ"Gl[J"aT׳p\#,jgjgN@9)?2 P ^D!sGl\l&F7 p h2ZI 8A|LI qG*g`{]gp%ƒgXJhqZ>hIWR2q5[b>s8(s3 feoUXƃH&MrZP-D7'7^nEGV8†qxbmxq5\SMĒB/d_a%mVoF q7p2 pWP-).I۟5:?U3ǫ`ɔE7MD/kG}В &TCv$@uq/IM Pcq0pŌx:+ˊqj,Jx=}}fnH5 ]no֙D۪sE !H>\FuLzQ9=K1d b#2?Vr ظݠl-iiD !Q8|SVQ$Kpԯp#ǵ8L}ύ6ݙBj&A6RLt+ҩv]B4)x[%nSۻS=vN IRMObbUGߢG bRJ&2H]l|)6c5 oXjr6HZ 0;q4h9\J$ xYL&>ݷj4Qo=wKv?lmnUY<Dr<=S+g7~$\=<ȏyx 9 qQG~>GRDPUJoo S5G~r=Td壍ywXdL E[Y{) <՛Gs+y2E CV QcʈB,FEO <#Ӯ-k_@èd2|(0Cg\6JPlԋWZ+*Vs& T!"B\Z"|ڊ6r wbz xqPkaR-.Qĵ7tQ1aSIXuN9B`=/oLk' / E QSp|i6Yg-ka:tz[{|ǝ1@rsjA AwWֻsE˓ؤSm(Q-Ėu7v`ӻ Oc%$,tr8Ga(0ņ)yU<ϔӘkL*k( IQb!!QƖ,!A8ifr>)oHAbSx)[O^̭&X )`.!<<#_Heu `_ 2:@%tTȗv>:?6nV`Yc(1Ӌп2rgWDO10ԩA䓝ܮV TZR6 YsrL&٩f◞ﺅWc-XzVrk3@{ Ү jVLVCz! 6i񇷐JIlbldL[> T[ʃ7.:?ol 蚟ƣra8zOEUCGǂ֬Y>QN:3S\T,90!@O;p soz\& ^A1=z?툗t&ի m5ϊlGyP!øUh+ZC[Z1M}nz-#RRN>X1U1{#@ h2"dΕ0,8w2:Wزu-Je}1?@*LWV$6\đ(^7<%rZe͆QJb'Rrl3vF|Rn򐲓LKq~tn@ΫP<j>saROU%./ <#!jX90.bb$9$.y}3C ti"緐dK!Q6M+r> (bҗ+AdSA(:b%fpR)b5Ql~<4tl04Xp EG>t kr?Uc@ޏ3`G ,XLnoJfޕm :78/"Rb_ #;ҤCtvM[!pnNe`ͥi6!_)r\"XBvRĀ<.bF)TfYe 'v&fK9X⍓@[-HX} d@#5H1DPU=ԭF2dBZ8 +`u3*Oʶΰ椺beYb)L&`Nэέ̆dH}ZX뛢I?~Q`kgKǿS *=9VWz6ƍEnrHP6fan'xKMlȺ%~uAb>O$3<A _Z?{@tGT0XM>*qMԤkiV)Uu97) @Wq?Y1Y&Ó 7?L.fN"—^oؙ,2t} %_BN!SVbFY7IӁ;\PQǸc,P8P2i}wezgΊ*d+b(A$omMUP\@mhKYB32*53]NGM5W褢SUMUՄm6fqKS|-즄Z}j o3QVr՗a~ b}o0ݭF[AtFP4㠐Пkcf"T ˹϶ PߥӺB<l*gp~V'py@RdXiq]ysF-h&K\mGr%nNS% ƾ/~ӿZCD(K9zpo1b>Af.Ty.(453H=<{2KR(Tm3f['m.xaz<j= 1Fv!CaVfaɟ@RJH?8Lory.29Q1G~̡o`YpkVӂAM9Xqw{Rg8$; (w݉wOd9X%NwЛ)@=wX}/_WAY|* g}V4h"88:fx\Kr(#'zVKjOED> 쪣'0`JXS߾`bU gaëi(_}w;A~-3=H\Z#͑O pٵ8% ;2}zNV0ibCx,ex`_O9 |T|g9_e*2S` ͪ6#ľPWtt۵n\PA|<-d۱K { G_ 9<._BB>gɩ%Վߟ2d]8mǽYT6`# bوX8; Z.sw$|+X ܴn33%/ѥ'fc^ϷR2E\o1$4qBZ僷sФS^W8LhRʺmX.Iy%"K:2OM4FD҈)ȜP#vhZdƗiG|JYbp)52wum4$cNx@U`jd4T`ðݫL݉A2ϕٛWJ(^ކ~R>JmcTp~_ޡZo3CbefieДA|$JN^'TI_ ?9FG]ebDD~cZBeXoAcc7g3zC _YNl7-+}:jy ߟq\ϥjAH*fm韰:dkI[^"ћkG = H悔d*&>v 7|ow{˨?H KVg$0DGrc]4^yey #Tm(lH\duÁϨU$6U|r@^ナۤ&Z7&ZдEG 弫>jZOàą1bDLHʹu=בVWh:=mi?_.z/!z8uÁ~ F\'ۧtxz eJ<ikR*V ׏`e)_?lbrʑl3?ݺSk;\`j{1Zp1A˃հV 7-Q{DF"H&ZLǺQ0aPY~RE=cIz(1t弢OY A]?УH-[Y'FuON5 pQ"Ę{Z"n1A[GpB8d}q!?O&\ fn]_ω{/ ~kexl,5ثUzZIw\EW3v řVuT!Yvf[ e Dkj1f$=UIF[XvU-.DW:l_Km$ozmV#G!@zfФZy9OAp` %u&!&Kس#uLk'4Wdߛ`^1;(ב|FSUR* | v*:oWqugjc`h@FU?6p_D2Iw5y+~ dʻ`iSsxeR (td+:ϴØ=:p~U_'m0/ Ay"@cij9#cHSpA~Dt־ =l Kפ4։V&yu{zX[ MfW2oOl݂ύUkĞ~I0͞:#o/vX,zl`WÕ,uPՑڎWxwDR}+&W?0hB>aEǴ9{ ЀNIq@_WOUI0_]m#eڮR#Q0Y;1 @0*㖙IMNHSDX'Pfך \wGniѨ^~y4#olQR|sU 4B@h1W W#MRɂYY[)W2xFWU/Оrz'ek]rm-rYn7Wq+W귃VV<,;s߶+.qH{+rT e0NӢ6'Xx&qT{Q`pb-[x tHsj/EΛv7$ C=E =itJ! L =mf>!XvУujCOr>y%:!6i|v%:(: @l3+z K:]sSQ7 0ƣ:Au.6xBpt ;2pUVZ)T1e,iTs* Z+eRE1bT34\;83kln%d)*#b9$@:bwsNH _Alљi@Əd.^&8br?:YKA6 ڲծhl@a5YwîB=,XU^9cX{Z)N+'Q>?㽛axM>2Ql!\f)/p]h^O!3%0g,F3jxG  ))%>S?ljn\7hNiPv@XIh?\Pl^rjB-&e3E&]O4.P-GIp#/ؑ{fFrLm\zw`{Y)UX(t4 Wm~6,"u4Pz1jQ$AipJq馅dEixKc11e <*#9 iPQ>ofkFc|h|x֚'B~hbK#&k6y Nz{cdqb*>6.AAtjv+(CsDURx9s=@Q8fL KC7di~JziveA= 2gD/eR(Lkk)r|PYڌ`p3m V#sdH՞ٿr7xUCѺ ,U?f`E`v>`zw}T)_w&M:W] ñ.^pYWͼ^=ͿAit.-w>w dYGoXϭ&g_2֩:.OK&qɾLX+YW#6_Oky5}Y#S"6Qix36"#^yGe*RZm /QO*+!Kb@Um!yY }ђ.;d@å1ll"]8Uvs Wl#g7wMgJG_ mn [vxRoU=.BӼx5`Kgr)̿Ɲ\ĸx>?2c;fD^Po to8=LVx%aSF{qzl0k}p@*ڎl /h!i`k߷'q@fЍ;s̼^S`)% y{8IVԅڊCH,8Mx6K@{+%%:k` 5>ڗ y=ί٩Gj!I6Gj8ԇꢉ`,Js:%V12.7.i 7&gf{)hn+PY`CnfKDlVVAÁ П-F?-P/} cpA 9U <ǪOԞ" G?kr/n_4x$\Y|lDA G:jΝ1g9G-ʼnoX-2NpjXut@߰[3O`^SOpy-`/Ξ\N-?D$0\ޖ.(EV7QTSلppqe$rGT ł5_XV|\kT *Ly9(Mc!g/ⷮD5 0B ]цoLg^n4b\IT4O07M+d4NYC9aKDzqL X( fLIY⁅.h7^A`ODm-pk2w b,x^H(~Rk꛷c3@J`H5sikCy0KCfݭ!9$7!cِ)5re>(ZxxBQ9Wi ]m(5  g'"E0AV?2J ?-w I bo`9ÂC2pG60WxO;ڙЫV*&Y:L6FL?(2u8ɖuҳl&ݐg.tĐ6mu;8`pB#Bvbi,4JRD2Bg 6Fuonq\/ZC $#$4E wZ'FXzS&!kFLo 5P%{|jx׆<{Y46V ~WlٜwŻkOIR6Vו v-<5h|1CL.2+yv Zo@V\-N&~@֮LY[Jb[z.QS,־3tXl8r7=,8|F5bT=i.dkiz)RLklK\4wnD *z|.H|xseLQK\^P_J9>؃o1^C3~ iqBG awBM 0 ;.yɊe#B),*|S]k-+Zpd/@M$Q>NdPؑ¹`, ! Bh`ެ" Ge#j4pkR{hR o,1iϬ??g-cB>>V}-tdڋsAhnA͙J?վ;_MHvH유Y.XB:}=tҠj=y27q*N :@5ģfkҠm\.ΉJ>8Of !_CzOu1c|Mg^:'U'ahN45h 0}Q4Yaxo}+;rM~Vcƒ`GD:y5E8$4%| %ap`KT)y2a$a+W-('> ذM~<7>:!x1=^|Z{WAdU5f-ZNU2y~rMC^-K%*%>'[f`-ݠjAѸlx2Q= kLEHro@Yqzdׇej'2/x`ԩxLn:vW&B,S̯ JBXQG%{(re@igvSKc;ʸ))F/gTƑX@j06oN=&9i"F#bMPǶvS' WD,ҝ{GlU*V.\IY l=QD-h0Y)=BH"/PHJX,I=L.#)r (Ȧ>Ͱ^Go*RD0j;OBB}Z]9h~Υ k0[4+[AZg({H 5{=Wl֥t_AWhAF&a X#4uH)l?2qcg_1껰ahsቫsMۅ}cf-Rus,!nCD_(wcQMœlmt}‰] ̜j֤}F8: +jhư9WDqA>0{k*}V= mL@M~Iu=1n-St*y4C =}*wI!P54|V#rq$n6W%t.-E ܮ̳vPca}=e=K7Ζ?$kpجTxvxk^:W͙?'WQўl%cY]xP׺EuVtʓQ^,Y3ƭ,g7 h uh|~82=:iڍ.Y\E̛Yq688) g{gRv/ -ii2| *ˉEcԋgiZ MWz7 g/Rf#N$YHwR3.LVWzeOل2hj.~WcۚE|O5ũ b;NlWHj4JVhȀPg[g05>334(X G dR{-qZhSe!sKUņ֟-'N;ꂗID!T۱8sF̠&><:9]#hx  fςB/i\X'^G7sL|9?qv k_wD̫u u6|;Ŋ„8ǰpt\Y(+o0ǀ;=ӺPS+b-Y܈=:Y;ܛd']zToT7Q>0!0L[d,GisQlw5+#}Cf$: ^6P J ? g?aQi8m'ŕj{?t'ҭ|ܑժR]I[Jk<ģNU|q&F=ZDV%GuU7!T``_aCWiy" WM^޲" 4HSxh땸 Y肯-{~շUUz{ބ_fZ,Ic؂TUl)X&H|2!Gr01tYtk^46Q߰vGKQ7S,EE%رJ'F-տ]o?ӹrx()|գrZkprT{b^TWz'eXrNyFlzϚ;21lf%1g ˏf~zחbKt /g16CX[-Sʜv_486 b/UEZ]sT%v:Y!?X+P{q>?˘b2dP|Ao; mG@ =íΡfn먌绻(E:I.RL#/3ʌ6W\!zSCrJbtʗLD`tG`k8GWDUeaNAg Ĥۑ4gK\5.("$JƥO fIu_1&Uv-5KtLd^()fZP\/z׏>mh$f<]|Q ݦ-p?!auLEz pL32x8j0\-{j (6(#a2fd\E^,L Ykfe͛Б㬉5pV.?‘3z {rY&𽙯 0<[~8}hx;-7-4s/SӵӉZ }1C$){)+1gYB]K.]Pp~ո{EX)@%\}DU i0My &Z**I6ɈVԇnlE=nfqNQJ}hC$`͑6 YH g4)*R9U,Wj֢]FJ/ lxlړLҒbĆ`n/ `C v_D9߈"[ I/[GuYR~4?`+/؊MK=xO] zDF-Eyf\w]96&pɱB,^%qsR|yVЏjk"NydwgcNbWSj&aXM ;!We}I|-΋]:G2KXJ.3Bw@o{2^U('He$3ߔ۵bƽD/t*Am?~z!..Қ%@ZDiDkB)=rֽ4x -_"Z%TNNO@RL,&ɄB"h%?`掱%ð j{JUONѧ .-2p|oИs6u1P-=]|k$W~^SXDVi&743ni؍&jd$!7Q$k&s^&b-/2EC5<,b|?r{(9o4vZ490 ]@Jn8@YJwɇS]@\᜹Ǵ~,-]oDz{yhn\Cz;tyB#HTG{|-b5 "x;SӦ[Յ0-Ki7JjJ=-gv3T=hf Y`i|ĠsjP2vCe>- kzfʛ^y!+'&Q^aW|`| ?Ã4(fĦL[!΢Lh}@B$uOUZ2F#T hwETG- m !MuσaVP ;lK .UE̙n~s)+TC 'D:cY7P[-iw`D9+IupclNkPJz,xGԇ |#[@5%4s?ԅIk̑wbYY BC#mݙ6pEvfKӐ[-sI#KԚQǿXm{ moJE.`8" v}TgӱK#/]~;𹯵%lybL8Ohhz&^^C%]W3֫d<&.+'i8IƓIuk~agmߛ띨FbkZj5hR5'EM|Z-I?`i=f[%%i@^nOĩU!R1W߂ RvE،ϧa1P{h:Aʳr%q>G˵V!jVIXsR|sh38u %vqofZ{!BF0Ra1FDzBѢ=(AxV' {& sp%2l͘/Mkri&T&P "N}l7GZ#AKSh!@LJ5.\!L[>xy (+Ze̊{dkmnA{L{~珶|y v.Q ]"M@a&`Q#I&O@%9 6!; St0& VLV|֤~6 秺tf&bʬ 6w d3,iaYp k;ߖ Ს{W(AvϟY՟ꆦ+z Jr{OGJHϷZE, /bHpB:8"N0tJWr%-jizq-WOX4KY><]sM[HMyJK/1;>MעREx8 EUv4Q:b6LyÆ8"R"(U:Ζ|dU}K^XS7aI0f6(qmJVWl!mn3NfkqN=q, ڂN˖knɦdݪP`PdŎJM4:y8@گ.1L|8]TCw «B|WK;nآfJ jRSņads ;揕"00[!/ļUP э?&5__%U*!jhf=^vWmIB'UP%RYwn>٘/+B' [ĵU#žۇ3w"Yrz?uC`zp0j5A B]$'Gvf9Og4Qt% I9!ÙBs2# N-rII- WO9ۡ6 'p6{x xyELv9;!k~:.&Ökf9okSB@lDKJv.~kq 7+ޙ@ԕAYlR0$n/ZIX;(-!.,5n_\vRqZFǽ2f v~"Oma(8ѸHtOur۠pkЄ OU88@ 94F]<$(^t7]02ڂ(ž|ɖ[ %MH8isM=m-DI1~tj]i$vhر5gemQc!vitg1$R@rR *i{jFD6*nR"ݏ@<#%ASUd]ć%S>2E1A FzP'p^?iV=4w, !9עQ]Áy*E[@ouuL LA{F:~uFOB YIܳ0Mtڟ3]#;9 X7 y-O{Ρ5A(.5GX;Lg 4mspe3hmZS3!PeMbtYAP Pl"!PrLR;Uvwd:RR=ހF]OUiB-5hI um-;"-wȒӞ LJخLXPJ^nXnߗR_%+Ѱ)%j_քeɚ*-u:Im,qpr_], &YlmtNP}gmSv3r ?3A^a3BuI>9KɘIQ;U IgқU%n&TEkr )x9Tek1seGn " PC6vMvhc_dyēkʩ֐2 6(MLXM20j n:a6L -5UmJASܩZIOtqAk#_2YY$RK޹-[H<߫p nr-!u#bq"c=|3=clFBRi "Aս*E< 2/kʱ\>Wp)M9R6 6"of[8他ã'/T zjʶE$|8[j`ӡ43dZpFU!Xv/S 7nf0U-٤}?5=y35}5&:S6@F'wX pBObg3{?KAC牒Te\gzZ~ 14<2 /tȻVm cՐ *mm8, 6(#L f'\{WZ VA\f bʤ (+`Otf6q5"lp90q-YcMSܧK0|M3?&)4vC@X7фB4s\n[j⥛ظ1 P\A"*@[q(! m) vaCiWcUR<@ ,l/n`!bT039DuQvHg(UGj/{ownוZl& ^0hx =r FD;RFgW@sTpS 59v߶!Df?{0&^T} jcJfI*xvCbzy?"~4NR?xSI#EĚܔO7ڎRI\2 ,lU!"R*܌j/U+5QRMYB$Ypq"ޞ,׉Zg:lMۊ`Ⱦ01%)-y;C$%:Dy'1r/xzvy.h}U~k >1ԟU"i7o.s#Yxx:E>]R9bU.hQL=ўVz_h4]Ypkfa &:5Ћ LHMq# 酺s:`x;c\5y PMjB>ͼ\\y" j %=':)w7NՏlOc8e^`?ˠLjF'i̖,M@=-y:q˞?x76s,PRq#.Oѹ pPfR: u7,w)V %Z͊ݔzh"%ʰUhk$nng @կO3o:6tISI V%vKa2tu֧8YXJ5`\mhd*~ceo.yS9P XJww$|Vv|[H$୕R (;g:;X-(̓=6Cqٟʃ@Zisj3l.H-~?(9_GcFiq)r U8D@ ij_#|=_n\ˊpq;9mC5Iәߧ]6+sORc՛i}8$=RNm} NI.mpTHkA)>-+>mQyǙ Ib[`*ie l8ϼ _OD>+ԐߏK*ީ[*Y,פŒ @mQڶgSӥR4)-VɌF4<#n}5aO\ֲg܁*??g~nBՓle 0\,ESc)[ dG xU+mNEq4J ^8_id 9մ/zj[gohj0 wNw@*.i'\ )(d\Vd٘ɳTf$9uRb3{|ZfbU% 5g7:s9X $bQЮYٔW*,wKCFb03LrqLzWZ)UYgtP>b1DKi1[^F>`ePsg-N9>OZ9]u< T7*F!cE4L9qzQGUwZXΨL Et;}ӷrb/v4_ }DT}3L{Ӥɵ %Y*Fs7ѱo4l'VQhu71Mhx (9۩iڥ"eWTm5ȳ#ŗM0J6nVΆ| *8=3xV6`}fbU#&dD4VxQj)7 L_)y al> JXnQ%*Koke'jjp~#!rJ: ej^S4* U2Sg{5-OB !267ؐ^p{2q(2u&u".<NlNYқ~9bށJо[FU վzvyQCs-U%+0ec .nRYfQbwTt8 iXbS6 <^ȗ"Ӻ`ǃMӯ[: z.1DL5ۛtף0?}BXLg 8%E"l2t ѓkY0'p-͏k'T}g`2g5 G&rzNj%͒/0?#1ռc7v¤G3n|y]\{DJj5Ieb`=j<7L0pP7'~'ǚ xpD35đ׺YǢ+= =ᬜ5q0l}#lq$(Ip?!Un@0LJYE>isp%ẅ́+761lhF2m]qi+P/%~i*Fa2b:RGF۸&sh=[liIAZ2 3y~pH$H0J ?EWar@~:A;eѰqjc|hXܩ'1ciѶfTm*rhDh~l訪M{Qĥ4ȳd A:G<3P.%ۼKn9 S_鳠@P;uz*$w΂OwSgEpp~!|3+Eh|!³O4[^ ,4j-?Sucv;y&+Iөѧ?q}kxG#$?RCȽs7/4_h*PD1>IV%A3H wu`nbMv붍ߞ1T['Ô$y'f͛[02O0&'gDtܝLzўe7*NSE:I^SPCu~ )%#Ћݦwޛ܋4IjDGCgr \yN n6qꊫ#ΣP}ϴx :Uk;ʼniA奎jSGB*pr%Y;d_MEWQO, lca. h `*@dܛjve@j0IΚ_@Qd.}`LmL`۞1] + |3fy^)bR5C9["]<}Da,:}H ѷ(ܱ.-2&t gC?qUnFCO94!%ܟZjbG;G%.3d.{4C nqƶ:Ҝv-yt.I tL`-k%@sv3rQ: {~\يr!B W<_Q|cnG?2^Ez_gg k9KT"$_t_4aVRGl)p;sODր">fԶXh׉ t5 AkOgʇ1/^ q@yAS^#=jJ _XD{HlTB_ړNu2r̂(|'ˤ2惱NƀncE?S Mpp{6Ŕj O/Tk/|,1CZijMqyʫ dD_TR٠̂+|q~tD3gLeD.Q%^ Y<1& '/Zcǀ |  JvB?m,"ZzSe^IWv&a!9˂,t)71GKrCd"4ٻD T)UX"6t ~; XT{{~|c(|ʆ4H{NŸZo@VH bw džLQJAY|)]b$%Q4P9%Ƹ|}K:cJtC|/X]k1r%~#\܍m$ A.Pu{/vo#~=}Du )q,ߙ8?e p=#i.|^` $+4qΟD.raZOjcjJ*IGGOt5)`H2T`+̦fTnfI1ծfTrѾf!:qzx#eaa#(@$\M<뚉Q#ww#7YQIG<,.[9E_I?{ F{v|ou~>2ś;|9oAS&YM\E' \mzHη͒?y{ZS>sCPP(~M݌<'Fyy(%ynAᨁN *?klq#q1l  G!CtFΣ&vt֮hBr Wdf^r1Պru`_Gs!S-xoٺ$(H1Ɓ Mr~-epGxHQ>tYhaeZu)g*L$!MF[Jx+w!^\ {W \VMcpsV4})IV>݂'~*S} D q\MGi_ڗxH-: sVBr <tߍ˦" >ha1y`$6ӥ+䟏v=ֻO[[ UIs) *\8!(Dkj0}7]w L?+SI 9V^O9<ݛXrۜ1QVGZq1+zw5n"$+wg9jU[7pnNn2Q:RU#rٴH18*7(y)`QG kj6SeD#`zx<=NdʉHJZ/-=ppsu ' [,A?<s2R!T2KpE)/ODn1'6x-[g,L;Дh'Ht:䧛?ΪHJGgM]< } K꒍d)zR77>I(l{"H_)8Z3[DvK T9(gQ=(Y`joӭxRŻj?lKl^ !yOPN Z\lN[~p<:Ug/}ʱQo<*FՏkgۣC#E\d -wBevW!uSNY\h^}W&֍e,ɽ/ךGr_. NJM>:=Q#Հ`6aX\HyMuNmRYpI+ɭăK{3XwbWis| X9jNG:cj#!i)izNaN _ur|YXc,PF{ Fwb+8(H?ro_kwX99@5 o7뿬sOjő/RMRrs8Mٴ[3V;@>di127_\wS5dE*19H)h^1{yed&aB\7=J*Ct$㢠q _@ތ!.tm=v-q<+mT#1?Ycs sB}WWKtCTppBcW0@(D#IzP)jp?qWXKb*85: k뾕v\:qGsK8?;Jfq'53h,}Rm Z{scF-r/t"`!& ;p]n],>)}β}FI;c[Se|.{`#{4L -N|>:׀siOh!85m3*b4wbGoTe#KeQvHO68ܴbsF`9 DSri{WG#xć/ v$҅$Dk=ǀcf7T.1. b{)_?t}z{f7cU&G$[=+E]ˉ Dǚ]C&/S$|"Jq)ya. u X[ONC _Sˇ<n@xO`M3yjB$7a@Yx];YzKsKI0_ON{Q1n*Z;${&J}87ϞAi3y9HEPƈeF1QЗLygFa=4?l.U^iI 9:1 |+՝xnaS[@Ţ f;Lͱ I}3 ]0 Kkp9p.I2s-&Dx{?ѐubX PV`J@5ظSCOU ESYbhQMJvA/c)0>m O+ CIB Up!qsc2ﱛZfRRU,& JG<]{ޯan-4ݪInV=g[l_ iaB%HUbޱY >6? ۠Ɨ5F/S;3YUܸybbM]}z{G^_L2w:q)>YCIg~㑽>֣9 'JZuD k wXgK_&<"\a{p1L͉s#w0q..PhȋXRY;S*aLF~;STڠ^Jj))%নh T$c3(UHr7 p\J;+o=r" e͒&%6WpXI䰥kYO$%Xw&$O-tR dֻ9b<I`=]?Sk}~(1_. X9PE_?uܵ٫):\'2@xqY!.&i5=0<+Jn ,<ɚE[~?x2EQw3㳒VJ&w/溪/n+D7K*];p/ʥ8€njAemqY]tV(+^sSP~ι^8˓IA^ ƃlX&RYᄽzB2UOvK m:ywZ2L]xr?z`ŕlY@ l AoSk!1CEH+TCQVM1GB3PEwhȱ$I jF3pCe;,Pt 抠0֣G("~ɐ>,v*o=p[4(BҰմ]WkJc/ JrMÙgj?8jOOs>L9@WxթE f&Cuz5#ٔ65W=.^2$*[E"XJkrBy[LLcӶlt)D)Jxujsk٪'/L[RWl4TA|99AI2Aԕ$TBIL\9oņsЕ,Quj-CqVsªG7E$nkyI7GGJ 1(J'(`*_;jZ yя̜ +o7W}:~A/ZE_,#}瘦mBL#ua27"^_['VI@#7@R2Xy qfa:hwn)i>%QQ(h ۶DzumB;:s{uƣ`w鱭O$K ވߙFՅb* O`UN#EP2xpꨠw-!]x?NP=Q֪>:#ʡ%\oekRHMF3z8yj_-<\[e7}mT+~Nbߓ q-;~Qg)>worT;9rMY {TqkN10X (Ucy ҅;BٷpD^<Jm"O(5X 9M (_ʽ`u6 AAgS*<\l Tdtɢ 3j*uq _{?̑oل7_ My?ꁂ+ = d 7 ܜY iu;<됈_ kTV=aewKiX+z,bqe쮛_,"nV, (&eyUo|FL!ɚ8yy,301#ǻuD}Ŷ@{XZGW]f]k=[w o> Pd'7%]4EOw Ql*]Z8XdZ w >F^c݈F21Wg[-I1[}{mKJ<~=LzLqE)BpkXq&6>Wdg hpb| ҏiԍ"iV}`ΨڳxMרBuu&.4KI"#ּύ@!c=G'^Esh홚P֋Ec*zTXԜ˱m耦H,FjgʣV8{[KngsIۘУJ EzeVV[^xmR*t!=ɘ("t;َtUlY,7\;˲.'Z;zw YFW/YOҌ!DAEܑfK;W"SaR8IC^/ȦYtt?ʴUwj~rP!Dz9p*j/YI s:]T 4z8*U2(L}o#Q)L,h|k&A4VDo 3GiPADsPZzpH ,ߣ:p*,0~ҮS;WEKS"3OۻZb)Fw3'IlSWa7qd.Pj#X4UG𤠡[@6g)φԍf(O:;eM.T{֎:sfԄ;S!t|D逌A@UV6-åS1ɜfprE)8ҧ]JhzOc*:~I,8aU X Z{69fɓ&!?iuw>s[pRCi]F`.MbJQ Ez+|c ք 4uՠ4csg27i7cxEw~˭&԰34?#4v n Ɇ=B ax=|enQՊ[7fdE #9:ܰ+kal+x"'Hgfm%{&kڠ~,w4θ&65:i?!~Mwqh3 po=1A3Ie}AcU>>'~狇r sSzɠpdW'K#{vfe*[7#9Q їdDj_ɩnT˧8]8)&ʞ{)?7pTkXAF\\_5ݔAWtԌ$pٵ *8VL.Ի>,Ϧ\Đ4ၯG9%B\A `]mv{9yDOH6PY`+sEbtnxU ǿ¸B*} 5rHA9,@Y9ʏp:]e.ԛ!aåsɟsMxѓn=0bB 1ћj;:#4.0]&h|X s,y"*. 0Tk-B;7-֌>47EfepQgÑ-n Kn\w`N;=gH#ՀqH:^}pTKSFsOq[kJ?tJs|&Q Ћ?߼G`ђseMW_bP=4Z?t8R1dy20j}niϣv'Uϓ~?#M)۪7\Ags\ED[:Q}7%m;dLLsϴ=d$ˬa].e!lVuTSWS+,*Q6ED] -Y ft3b[2MVk:vvڐ8~HHo #׽6]|D|e~Ρ/\g5sEPNz#%nmk܄9J9#fa̲ ZUY2ƸlEjnqrQ(SfH\muzvOg ~ui_+P %J:.!;2.ݶşd|i<Zj wAUŞaed+R.fF1( /U`өN"@# OD.:u Hf^8Di*ѵ%l UC"C ̼g{Ե,XkiJ`Y=۷+h2⓲xiIgpkiT4?DAnv'#E8BѸIžDwV>)|1'-Pcm̞ SC #_q(41TI0Wj3*89&P>g|}|mwUށeLNR#i',I36s̸ɺGc2WYy }XlS;"l}PQ=H0#?=.|ِك6Gn_5VgcmrZDRae:>% v=E (Q֝}W$je w9V;q=8T>e8&P|R"SrF0S@# ǠJٍd-)NI_(%l"6uNEȯȒ{4ĽbR1 5g7N ,~Աm+)kh  I9WŝهpHzTyb[jTuчc:tC|ƌjsl^)JL RUuX JΪK:;+)SNUJQr{Dm6a#//4 &A[]n3a+`0-2ټ 0ez8.3%nbѢX[̍tBz{ox).O\A2HU tTWv| 1cI/ 1&|RBD fXS߮hiBo/.y>4~hΊ|GK b |Uٙ;UȪ`;$-)qΞ3(b{"V%3\sIuf܋(E9y>9 CL~]9`J4䀞`؃a0'>5{t)3hBuX#U˛ sӊqGSԓ(>l\AM-/X02@Ũ\ A^5A.A{H4dW!zjPv*T-@0@(ǟ{&ă%)133kv4s.{#|𓨗V;n9r׿Դ{( Nۿ 몄mi'6@J|d8`A-1fд,ij8@UR2܋qh#w9%ꅰMtn#ȜԿ*XY\m*Wt.]0 2s P]| i] s7b?,ŋgι*!7*??] zD k(ƹ@ڣqtb(Z"omQE#c =TSy ŹH_.GadJؙ~1'y8J]വxYVoGp jdj8%,[*,.j2X=ѫ9LqxcHQ^%1Od}mݺR>}jw*fO0=!*Sۚ)D@W#L`/Z6>/ϟ+=2نy(ȿ;b= )1i ժJ*HFCzc&o^0ѷXzt0PVRқ0m\&d? 5>z*r_rlQޞL]|pTtYXW/!90YZBB*d~O>OadCz`jP1-X~G u,wLΖԩ&[M {MKO breu@-u0v·_WFW} z&Q(a0!x LN(cIucM2/*eTgӫ:LY.%cm)lFX5&wz ǧ }lpɔ5|I$;qἢ6mjQi`/e2:'G}l@Ņ,zji<ړx(Nίh5Q5w1r[Ū#WO{WzУ,hTC7C]jK?n?8~ty ̅y\(6'*nCbӷR\qr pM F X]cP'– uͧ^" QW{.vJJ< 7,`/o5{}Al%ܹtI$#I~RI'MCiW܍Fx0N[E0H6C {q U[mfLLMN|d*Cfvfr ^22 Gx)kG_0X{*Bsd+1DF\c_nૐDŽ-ƅY.O:g_b(>B+" Q^h蝩A h!& U~;]Pd/8#z~D|w{Cd@C50V0P DcA2ƋC ŭp#ThZP|. :c3.̫_3M{ 6)jbQme$қ97kU)((Dvfh6"+Ț>Q  v"[~^Ё`1mWTϯ6 o"䜕 |uY~9@@^&wsdā8a:f+$%^ n ]Ccߎ Y\mRg .izl"W˟NbLk'Szp5=DTgF0tLXW[0 SRLf*sc='*A(2eai[;iFRZ@/yA_TuK`XLα(żN&VM{j6&MVD-l>dO8.Hi[h4%Qގe ̙H@4T|R3سC`:.lGN ܳG]W`趨` M`_e .ߡ3J$zLw e]V +w:7Q;㻨oB&Kh `QdwƠ34Y4pm؊d<QSXmZ ZIqJ3Y !࣯1~krFwʴ0 *iM+2oے<Гl6'#_7Q _)oS !oAQs [5% *LSHY\9;77=#63+pw0Pp)~N qw=NW@e{܉\teRG5BG[-0^_Lx;)S"vM#Ղ-hIAS鵚.[bI߮ j ]ҍ5SWCzۉ "}.M(*~8)>kk$ fZe[v&ץsZ"akzZ,{C -(-ƈod B?UϘ9pv]E{(5uy\ SЎ6&ۅOŔ=?& Cp>yc̎d `9S/!#.@ _{L`_j_bVvS?cH@Ŭ^,c'UGY ̈1㓕hwpAK~6#RH2D Ξon +^9 eu]I*L_ `0RNٿaJ)Ran$"'%Z s3m"BzF_KslZJuH)RߣͩU[8PHs>a FOC_wODI kuX DNϰݧ`x0#M4 r^66զ1^]-Vz-sxyVuxgL9ݑrC8 HMaB7whE}Ʃ΍ON(#79#ei:S' V4=Z#)Nn]d\裆/q?DF%[^jpH*oi훡-ƶYšeYe?;@*})`vZS_`I1 3jm0?/b~&{O?aK qn l{Ry jrw *2L堪fP<pn^1:S[(Q:paosl+OF+c[elR%oQAaw{.5zvi74泔4va`-\6D Jw>iM|٬*iB⺒jU^G'I~J-q-#>QR M}a٭*P4ZK$IF:1t|fU=qmp]ht_P~1* ^`5}d[ q_Ao{љTK8lw\QVARl,@ ?#ih8!I+v7D`j:g~ala,j5Y0 C߼emVecxN%t>cN}{|%$ /6/)d2bfXB3yj8LRzM \ѩ\m \8Ⱥrr\ .Z0d#9 }6=N;vyo5p YtWh4rзӉΦqg8ªOcvbGHc!4ܡ/۵dx^<LG\G>Zd(Ka|lǏeD./Xu^ٗ5 πc]oON,4-Wޓ(_&EXV:@ W>9[ Zc$X)<,rګy݌@L ƌlL l4A,ē(hibaDdY.wNT)-loZyڔxTY^ x3oMzx&WccZiF@ML})^ewKƾhCƕGHcj4[ς#pU[ZVgY WPK} T584`uy7/2]#ZnjY3XaM|[#\R<J58|[u ;!z_Z;l#F}}snmgG`u&=3\pE#mrcA65}dkq|]+/Z|?l]LV >geJ_8'UfSu!Gt)3߈1qÀp]P}Ȇ4H% QggL7wikغIn@ g63Ij ewڙp c(ǹQF&~pfbN]d5۫X}U7bzj|A b`ܯe {imU+D&I1&|G|_>Ț&NU)2V/@T ]:19G1icP+>iD퓍fz}O͟W:oW$˝ޏ']%>#-wLbk{јYm?qNA+;HF8 vL g ү;:fj}Pgnvft.u xU IpwF` 鶡Koh e5@m*_8;&R4-0\HZNj#Z5 7oRP A0qdg2ӌe-5C|NT#O;AS^5{&^Θ~{lA2> dztA@͖gVFw6Ię"_(i,@[F\18y73;::سQ.M޴{ $f$ŴZyog]~ԌQj/D9i}"ϻ'Z0Bg~<ꩼ\P΢{=\@eGG|i@6gGȢƶGhyģIMLY2@%a*i!H9D@JA(؃pDxEcykܗT¿1K X@)Pn|* F!SນZ*nAP/>-V^3Zµ]!@ %XFJeel=wG HX -Be_rYq>|z -Hp9=u[̴Az}`2^& ^0<†,bu .vVIgɅPkd/ơ^reXܺMV*j~6 Y5Y%.:ܦ,WL\¥TaH{GPYeDڟ&aiF,75 }B9@j$\,% 6F%+~Ck4T%'Ӑ'_ūPxq=~JR (ݮ+XFjg5IFpNÄ1AuU#Q\$ѲaZh9I?3$<$^8Ѧh`\ݾr 6 ?f kApw;ykvad\"Hl =T4Mj47etq2&o='&hT9=Ax1@1O Šf6}TtW.~"۱]qɅ-hZH94lYv+q3`qaf@+,o x@[ߟF 8+=0S [ 9(^j!z*uwpCy8Q]Rqm5"Gv+?~%D+>M]M).8al' {c9(0kݖAeX0%+WrӮsZzNuoX'|s5G *9t)S%t(Ai~ň_)mc% lz3f,"셽9Ѡ9H.VPd`WF* &Uˤo$2cG-C;(-_fe^4-f!EA{WvJl&t7+1luu>$l'#[?v :S$҅E|<]2@PR1\x Z].'ezN>JJl" A.qs+&i$Āa^1E=QoRRU|i:rE˂}.>=Fԉ0FatMVc.;9<V6+Oc=6P]s ӋU]eY$tMۑ(P n.0?'d0#je!|+j )l(gxdmvDFMb@w n׳l~nVGATeY;[Nz1z{Z B@[WSA-h{ʰeGLwE{ETfV\Pk Āoq8p a;>#ӔϮq9E 0\pݻ6'X"z !ø^,Cg]r(3d1c!.*P|3xX;+K^V'ڑZ؜z#Rl)4_!@DcQ΋Mϑؽ켲vKMqJkE6,5Dbo;M0f1-:rt ߟiXK3TSԉF{Ĵ(gSUC;)j|*D'1m=m`Q Lao?VZ Ju94 pc׮G- 1#,Q Ni!aW\zyv ygιq89+e& @~:6_7ϥp &LZ Jhe]m5-Ôæc-z_h4 T M)N$ !S ''qˬˀ%(w/%'jAhI`duMw%4kT$]!rJG^w(3a)#R"pBztA$E/EqӏU`0ӽḬ"+ ]qR T9~)|5ٌL#U[. {nJ}evhuL>jK鷬J64~*◪/! N@xT& `KtEXHW|~oW !;9Rm%|2'lCc4{ G`7dx\u+%QEL1({Ix%Wȳp>3N⿃.]e0oG)$4o ChxJM";|Ħ] w<"ʵɓI'\A3åPŹ1d$+pmQd L4—G9cWM!:խO>"B~J*r"Y"2 WT4e,I|~V#{6&< 9#&sS5<ʨSAh?s󁞇Siw1Yu/7Q h{D]!ܘ$M$z jlM&`dP6J&lҼqɌjF=.T[ub!p9|.j`]5SxOTTQhgr~I0)͂ݟ'ΝxXzY*dYJoEי& ce:_E'u'od`NEȈƻߗzkmtres.| )c}0*xFo{~ǔ&BxT6lq]}ԇ&R8`$ʦKىăNYL6zhZՋ۬+T P~̶ YZ