libsamba-errors0-4.13.4+git.187.5ad4708741a-1.34 >  A `-p9|c/f,ϩ\@m}&>`[M1鏝X!Q:O"{nz.|) 2u c+ȯ~Hk\ 7 AuBpIE.`XCf"7.agvit$ /ɘpV͆/2ڼY0eTKh94ѓb"ߴ(^,51d57d775cffdcc781f5033a06b01bc2ced367cd0791297fd71b6eafca0da573e5524bfa71390719c5bd39f50a03e2f533fc362d1`-p9|X(z͸"{ aH /6W:GquwӁpկDHw ,saq S;(nEk x.52 {Ɗ=q>h1^O:L]ƭQP#^@t(Cx/*!k"Xoe+7O ;4T*c=U"?m#*~SzG1؋A*qިbkg}4hxY-\>p@ф?td. 3 Q  5;DH J L P  H t  (89(:>Ά@ΕFΤGθHμIXY\]^1b=cd=eBfElGu\v`wxyz$(.pClibsamba-errors04.13.4+git.187.5ad4708741a1.34Samba errors handling libraryThis subpackage contains libraries to handle and translate NT error codes.`(sheep69PSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/System/Librarieshttps://www.samba.org/linuxx86_64P`c46b26ef57e6aaa898f281d4bb59cf09c86cfde7765be789e96668f447bd2bberootrootsamba-4.13.4+git.187.5ad4708741a-1.34.src.rpmlibsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-errors0libsamba-errors0(x86-64)@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1`@___i_@_|\@_{ _l@_i@_d@__ @^@^^2^2^^1^^Y^J@^2@^&^&]]]])]@]@]]@]nU]nU]i]e@]_@]J@]B@] #]:\ڭ\\@\@\ \N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USascabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigsheep69 16203103124.13.4+git.187.5ad4708741a-1.344.13.4+git.187.5ad4708741a-1.34libsamba-errors.so.1/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:SLE-15-SP3:GA/standard/b5c3032238a4e7a6b51699004483c0c4-sambacpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cee170f63a924e791bccc512dd53ebd95c153959, strippedPPRRRRRC^ډ&kY_utf-84c3f2e284e1fc5c73e8cc0cbf5078952af4284f08a365b7e7ed998167ca45432?7zXZ !t/ D] crv9w +`_!ۤ#i>or53US:v't; b+xIUv P㦁tI%TYb#v_B6t=y] /WD'ʤz4.4C/d Tܭsa;|gwG3iFINqd= #jYL4dl >STX"&[M.6zӠ]D֥b<'$X2Nnf?t*vŹ!@d|Q[p"ϓ3`39X70 cewvyk!Z̵ l`w7㴐#.~xSD3aZƝ'gu05Awr^\ce3,gֱTF*!]$r=œ_Toi$NEP.{SǛό 8SN%SRE, Ȁ)bA($wXn?{'%O!7NQm0k|Գ’L0Uz0DZAOj9#REkqsH 4QT̩Qea\H,{DvDhY$_)?,t0Yr[]bE`KU tPNG =.%=*;T-VH >KCxvty9r郁LWzE\ Fe}ܱ25Be4, UH&^\ F{@%)wB@UĠ%N }HT nX$"E_EA@=\:~7ᬔQ.s'`ռpݘDl˿,:C'mG<.zTÈ[Qs3̥ɰH;[k7 h\;_+Q{ԬÆ|(G_ } YJ:OI7jm0fO "BDZV‹)vO>R6`{+mz(c<'^DX8{#Ja[2?ŪAUU-NхcZFRA?{ݬ4bUK{F 䵸p=5b,$;DcYY,kosZ"hR/a}%z %%鞦_q"b9"R4C}MJV|)}.Ȳ"}uM?H![L[,?? ͤEH7xȎKXTWre#ޒVG$yϖ=7fCQ"w`,)+fcޔb VFURUE;~*n:Alb*Z45*-,N&m8yU?s^BuTh):[nߊ$ݼND,̪[wv/1o0e8(:4()Rퟬ׆I ~Cч/ob?i%n0FG#ґkc;؝Gi9$w\L( (!4;篘^Qk-$VBuC YHβy͏ރgt _~(È< 7y-$Y6IS\HN7u,&ph 6X^aFVHOOd&Xdv|KFTdjp7Q}Z/ݖ -p oV/-!ݎW*/,ɖ B# n lE VI6<3pZч(yCNawzÒ %MC t.Ԙ/pDm0^2 .HMpyg,^D%~x=O&_R}k7ty#گhmEsCbPݜmr įK20`m݌7qx@<- z`9YDNJzf3UivĢl .5TEmrn|A(BdtŠ8?ʖh]ո)gM$U5GiRmM.$FIf$O-\]E߬jH :M?]N_"[ 6 Lo`3:c>E>> }F{'ף>|mz umYEЁȣVpKp( OK+bM6/k<",`jFMj!5$iEc*ًdB8ߢ j#epm-x{Z{FQ:T+dԌ)aZfIsOZO%T{Xop{xC )hG%30} 7CJX͹Ch]ImfIٱW=js8:X?Gi pIa/ySj֚ )l"a77JNh\Oݶ$y\%WKhj:1u'089և=@)ˮgX]zVr vpm`œN9V?ڏ= S ~ Da~&]4kŠ޿Tde:Yh۷N,;>KקNגP6MlΌҒESLTxF{1O> ]X90Q6@M@BI[D[vYs]U^TTW@ؙ=Ff0 AN_gQ&sNh5&Mo ̖7b+ L;}oËݫHC~轡@;s_Im3oyvQ Ffq$!ıwVv 6,@LZ|{ ۻPܧ%shʅƇՂ;ÝtNJEETOdGVKv.0"31ud2HjnVGKi11L_ 1$F^,?= iy$b4{;ufzH3&SppaTh|([U BM^1EIW0 !/=MҨrQeF9[+&9Zk9ZLkj~/MHVA p(P^!tE59Lֿs'8r$1۽}6L&^"p?BԴO /WdndΡ '  ذZXd[C[*LEwޥ4O00%ldFHD_=?AyiPҤn+ 5ڊgkInhgg +3_v!dF! 2L>pڣ,>$:d7My54*ۜrr"qSң'όʑWg [~]HsC$wF&;M}}Q!=.f?D]kvgQ^Mhv 2{w$Wx=tS]i<]EdVoh{T'n|IS}ΰ =y2P^DPH!` "dFc/:-:j7 * ?mh/_Cr"HRv~0X*=&iPb\DL3,(1 $/:T^^F.L&uGw<9e`Gjp고˞;4kxZ>rF$aP=I^`4W${B.NpXk{3u/mc#u|b +Y EB#TTw^g#;+âˑx+7NDO $gcw JX0-A-ѩ1H6qݱ^% omzDD&k ra|&AIJ'xljn\Lzj | ӣܦ2΁GY|ГLT#Ob,tY]>UaFRfrl8?`/& )Xcg%ᷪ I3YR|VH401%nZ'( =/AtX#TbTT~NXn~ՌZ~O)-51_8DB0[5?EN%IRR:myFFWGI{3OtVOu&Sp Fg,>ek赻ꨂ8*cqIU x7d!베 [.(Su U21Yo .}zYĽ lPClg4 5H8}kZfső%v=$_?_Kjb&ehqi=U2-{ &EX αo :+¡ qCG6r_佸b8 Ψ@ Bt|e>2/ԕaenOH%?e=s87.zj"X˨|mp ymr/ 3_OAF LTH)Us]]S2ѫ jSpD`Om5| C;+8bHzƯ+wJNNɀx(ùLFpytj+5Ęل_  z4x, r guS~z=8騀C-h~|ԡ=甈c@ s(]LERzvx(֗2BVm,ZўoS}ͫ6ʥ;Ln!yjv,F]2Z]޶']3EJDe%xcSfK1vstMM?N NK-('A$G*Ƈc7T{~Sw=/MdgkVf#ЉpEWHy9 >[sQіEH(L  >7,=hL˨=]PKgފ(Za%6#g"0pcjh?ѹ -wԈD+Y+\??\o {jQ`Jki%U/CW\`cVѲ!3K VGb( g rL2NI,dzS#iob 1_FB90,Bl,HbY*x 9\5"aײ.aeD@,)eBs Ľb\>%2$ LR`ٞvK[ŕH.THkOހQvk]+SP,-ol93basВwj)'fn E-,T/e B MK6 {g~Z և؁]֔vs]9؍b[gHQi8^؎N\LŁ\_ e<cz@"!C%FWZ[q0 _x> '$.= ,hOIdxsJ,d=՛ Lǒ]v#q'M̞[;U#߷C^|.# sکmG#c(N8R+C>B}Cu,!jw]3 #L*O OVI ')1cgM:/h[,[KH(2mkCIOݱ'^;(G?֚>l,7ІH*7Ϝ6@=0FőS|plɋ7"l! 8g @nY:pQnݦ|:`Y[m6Io;8΂X)bUJGqs܊Lc`cgJ<),4Uвᕜ|(&V}ƌBx'?WQnOkea ҕR?켨`@k+ډuW"2IJ΁X ǥI+yF"~q;?4XRʞj6 [RT]2>ce(,``t7u[oOո,0Nn8 6dy5dtLX ɦx6'v%t#+Ef?ey71iM7A @]8łF}dqUdW~)WK!5"cye1s.սG}H]Ys=(̇x<قG 1*'S+2Q(*Yfn(=<:HA-so "y<3Β m=EIXU*QT,'TY;/qn&drwR+Ӿ uP¿n)u (ɧ%Sڅ z Hs*.70e3IpU9^P ifhem:IplbU4k\ٓq4aNq9] ky+&+M M6Z;BQBpi5,۱wT :;1Vjرfh:d^rM*C1{H*k Ŷy~|BŸ\HepR֨fmW,6rLl p{#k:@ kZ-oPҍQLUiXzS䶉)=Ά&I}竭-TۥU-oUPX$#p1")rlz;* dFw'@NzǣFP cih_<jqbsG6ntJMk{(RԤ9PԫC !+bs_uͰ0t^>qoCgy/KҰtT9>8= r8vҮ`H&)>H:B;&ˢ̲doэ`$,Oqs$,.@`q8AьvH`.&p {ԕZRrFc`6Ώ 5rLJB$A8-ʐhK \ ]'(#IƿsaiCo^Ƞ-&m.o<_,сޕo[ lΥjqqcgc ѓArqS;| [ʊxA F"FE*mfdhe]+MeOQцUp@~R %IK8L tjJ~9 <"71|Qݲugf-+q }pqOW&( gO Zf 82q$tl,ĢJDɷ+g2aS~?G.o}F?ҠҟuFib|%MOP҇Jcq$_Q ` pɇi y'Ă'|is7j;Zw$BY{j !RYp^ɛ^ a'VꖸjKxE4;^nXtvf=u@)/R+7(Hk9窍eaC2rγ k/ݘ>o6]#Q)=p&dYjJN<.\ rަiG?ga8`*UJ(tv83UN I ʫh Q2pZ2Ҁ͟m8E8,Ԋmm|gR;׽[\"=+Pcw{#gUMN+٧s_s;po9&m7l}Na0]\OoTf`۪G sϔ.̓"CfrX,>e`{kWJlA/`ϧRƑCzzč{mvg _s+Qd?V_H6J g6ڙΏ鷕2&鹳/q@F =.Hb-?u&1g W0}xnpV9[dㆪ n $DW=^1@CY]NqGodG9-iܳIC`Bf%X/r[۳O`n~$ṕ-%4 x*&M|Os['J|Nc;'.c\*-\ &0? hAG" y9D, j E:-,z㲹V[XG!aPx$1B*r_Fc(ԃ` jjmwnQ:sG&}$B5%%:eqXsnN^J"RI7c '}%1,oU7BZuN"GN@WWw -sy, :c^ 3]!0c1oAH)lV.Oxo*3yv"kEȯ._0IA8[(ơںnei5HtLJ_?aX@eG1ʜ6Ouړ%VI蘾M@r(JY]ATmv%8~tue]I'g&bdxqބI7}$ކv&a~yƈ ]x]y~6pS6-q}_]D,P"B?S[JS@L5G8K{ ;Xaw#S|:j} Sb&LKV"gK Hv8x P$Me 3 #V`̪io^v.E1${D0@6Ξ?t:ȕڼ.cPPv7w O1~˴||od[)k61QosNշ9oF"70bذy0\%")pÜ<\ zdW/f2T~[]nKC9Ϫz,QM(5Y2WF]'g轝krU^M Xq֤1PVan-rG\C|Oit ܼcE*=b.=5;G0S{/+}?mskaM44\|Ęj6؎APw~̕[QR DKb68Q^ &vhbKf^j?.M{-_zl/> 8 dz/6I)y#pզ4 ,i0}Of)a)D"g§8\l$˕ѬnE_mD^z|3;|PP̚QWW'ծءG/r YZSQ7/}i*EIfbH6AB_yQwS (YH"(k 0Js=nRi-4撣Dm}L;+`]3F`S r{t~*r#(5N;6_IUv CHmr=^8Ff=gwdW\>5C<; ?AHNU#mcQ9'@7${ S_hU~إ9l4J,nc)x T@Je8{:2kcqb!XI#+Rq|߫i #^&X0@IF'=>2]GJ*v޸F6Iͯ!3f9#nj/hÌ;+z jl){ Ȯ %$dB\~YF5Om$D~^M!Ji2'dԏ^?GQq`8CLC6&fQ{Aܚo =!u);#3{pdS oӬԄĽLJy>^[؀Ϙdc+5 K Qv@ ߩyuSsuRcj6|7?ɖɁh h?##y7(f@c HmlM̢$ Ly8X1/5+vJ2>%RU٩Y`IpT+;M* ȠwCvAe?w*Mf0#8Ӄޓ&Ţ+bJL #`1+p9V5D Hzvm pgaNe8.9 0Tzd}/*SMX-Zsm}\O.Z*j?Q<0':9 PJq\Vʯ],w;Abq=wxGgswB9HfS'l611Bpl#@s۷u-a}kv dBWM Pᆓ G(!Ć;⢦Hg QcCjC#$4^4|1u< 5`7 {+{vNxOL)=ab'VJ~=CpoqBݟeOH^XP/E |&l"%B2v+KY\pZ 6,`wiK4 .JqiU5x|\'@{D 5`t{5{tuL;ELx/~j0g v7zQ-t=K=c\T CjIzN&q(ޣb;J'Ewlrm,ZE Prv9țq<ǣda=$CAQwo_7R 'nn[[*wZb5>hҳ….a9n$}n8:5#O ⌴fufiXO py$EmmB;aV#hm9_tXfF7y1mGw¨K~rҏeFif-2{Ya##|qE\.M-V@=<7>:DZIKT:0DCXv#q~"=y{q$$$sf\ ix#K[ջ>Gڟ|_ZE};}ɋ,OUϜ]T@z!ضbgM`/I75r uks2E@TTe@+6^&+EYM#+i'aTl]m`lcO}~=Á +/Ec5cyV2 +JK{{u7_M-@,{Z^*쏰%$)_sN!^fBMJM ZJAVH Ȭ Km;Cz0<@|A ,FB$|6a㗵f'{<)^`lU{l\+{0[q5CJ2{:2gSUfSkQAFh"-.L`U.&H ;;mX$[!IQSJkLF%Ɗ#=b^}j~]| a/ߑ;Y;1u#ӑ~s":#ݸL}fY*N`ڳۀZj=[6!Qw8gYnީ#Y͡Gv?@H)dEۢEH1;"%ILKi)j IoOTԋp2Du҂7bKc+撎|疁b|)@Y^Ư%4MtߢpƼ4?s2)rBv@ /&g$2+z bagՁv`?h ¬ L"?^Uz3|.A>CI1 .wG9?$ݜhΊ_D LAVkNH,Zs\sfM+\,׼`#F/VXKދNhJ\OX N,GG|jl*n, RD)^fx 8 DxxC&Y=P DZ h韙ԝ ܑX` \>Š,"A~\-S^yD޽ 51ʨֳBL-uS'FDm_t"y9Np`-Qqb!Y:rX7НTIuk'`ܒ:2Fn[kzɤ9c0[LnUU+;U(@.F,Vnyn'FBͦsc?O!;h@Z`Qg7'D{ d#n1٭ o}|U(Ȉȹd1>ICH fb~X(-WY,zy<X?/>]=X7F15+nOa]'HNltJ禄aH,}8oC 46x^Opc' \j,,0ZyXpDt%8~^Wk&?TL:o_l=,E`ե`صk'IFM8.! =Qo)yڴ~HXf*HP ܻ/֨Y9\(1W~S(>.ɊLsטּJoxJVwU3"c/}@>–3uզ'YuAAA֪@EBwڕPz}_\j8l6jBM[ץe3nFAf9O(h *'g/P򟼸F)dX %r.foD97No`PrV/}{{?ȪE-&JrJV,1DEusSD1_L f@Sr@ːRȊЏevgT'))H}7f3:lzB0w}Bk=xGbnF~c} ,ޱ#&=<J;ө~k=EgbNB6o>_[CCZgl~3p@aqNX^ Bj-&8!dFfhs Z馧\'wy큰nu~ t@D`5J9f߱-Da\aOvڻTAPÐ]J ll@WgqU)>zTnb$&_v T;S6vm3|fز& ƿ D0W"+әpB4[fhiƇ}_^B,Et__2'٭Oo ]n]s &DzԚfel!^ $JdDݜ, L%#uIS|>֐U}EO9i_t Nt $ȇ~#Mb( ep`bpnyAP V*Jbז-jH:-@6Q?XX`hLDJ$EmYR0 edč&MOzNāF|D y Ě3Ut , &\UB`\!IB%e \)l#4YWxXHђW)$sZt/dI>A,91,WCG?L, |YOoCRPװK3},P+ȕJ.AkYڱEF`52o>o\ɴMT;.<,86B3c+,F(ϑqES;m0}1 H*DC1XG8*:!?oN/ZHTXҳ?l? %4]Go1YNW&{o)v.1^?#b~5Љ} à9k+ V)vΥWɍ غDO= hwfu3+]"[)g tߥd;"#Mz;tBE8TW*(}!Wd,F5N].WX97lش‡]ͩ?/㷭o ǚ(0z #4ɥ\$ Ԁ,d4ic)D[E KM-ſ8[_:aiQ9V m): O3.aO'Vc{bW1x*bGdJVZ+%JsR.zd([(a rQV;Q*Y=k?ԼZ{婁bv~ZBqp,ጴ^;`ʆE{ A9>D x% zc) ?eqj_Lsv%\,7ʄ-75)#Ib{hq}]U*(`A;lAsqO,92Yr *S12A}s-Oxz[懅ZNwΓ[TrVqiŸFb%1j qQXYnt=zgS` ϓyeN|+2;+{//Z`J݄) .-7V(4K 3N$ )gDrT_DHkN%|Ac⪝O[kG%%,Jߊ 3gp4ŭ'X$bjRlz䧅UNAHT/hE}8emH@a@*X }Ѕ,bDݗUU\RBј?~'ąv؝% tT<6W<h?47N=/Y&2 ̄/i~Reޔ79nW ӓpD27 voKf'@X;t[-V}(&O25ř;ŀ8~܄<BL,O+%TJq^m:%6T̾( P_tg y*7ZƏEu kB~}U} cVPPԄ:%~ţI%Y#ٳq%?w'8}EB#<8hp.wr_2OjGHk窽]Ja, z=ݫ ?Eca ?"oVE n]&iZ.arOy4l?abv~LD8vnKN7U:UF3rȠufA R[Hz;eT+ʩG#\e-;#G'H# LFw"HnKކ OjlP(ֹ-cѨq#4ڈ (۪śmUl>g/ 2$C-$Bc+\}-yPY &jҩ;΁w.X?z]o3{STx:|# giS{ G6zZ-~?B r(8fFZh20guv"֤k<6XiYZIQ6]k^!n1 لlYSƹ*hƫx[$%!RTn@dG;r)bJ`jOÚ+\7ߟ&!-8<)у=c0XOYXe?8|B~VƀsŇ%<emBOx2R *HA SNbce_{P3.R]T#H/BG@]u{& q^{ B|%%iMr֑ŋ?ڌ1Mgw@Ѵ+tx쮐ߢfCEӅ_钔 25=/(&]b7૓nemY02 KW.|%5p)lٟHj6ŝٗp h k:Y S;w+&z.IK13N͇Qm?&"l+H>sϧ';W'm?iO8)P[7 ̿>Au 6[9ae-q45y$J,6Dn%yTa wt52+QtL qn8>[h hiMΕ&:6 lw`*;b5̬I"}qzzb+mU-##sS b,-mcKe`ܧ|TZ_.T[&mcT<(fQ^E/Ms% kn=U'S5k2&肺#U1E|OqjY; D䈴 >zIE >0/%dC}*Vj3_BhaN (0s=(>n_ Fu.B5r,*܂RLqۣ˧^ѧ0S8"c@?pj,[|Jo?)` pra{o9p;tȢGS12DmmIC>F cp0륟i[N0aO_؏^fN;}w瞏H ;/nZxMйz巁D^Y.XBHNՁ';ģ޸َڠXal\<~K'-͸+q vJhi|K~p&?KɌRm[48ӑ{ꊩ^ O&f³EWK]R3UVXmOe= ׇH2)3h *2-_TS/RFc&J7@-ѕ{ koF4weɠ?]|Q21$P:eV h:\@x\J_btG9/pE`ѥ뫮˻Pׁm5+s=v/q ^U6Tv|jꙶ_|7r71{_/3ngGyYSTiY%rr(ou(pVudɣ>yǪ`2Vj|NI!;֑fˑk9nwHc HQij|#%sO%u\J5J'J ETA> RX6]m2AMtEY}AM@F Zc/:`nCg#]p aecr5_daDPþ~$O*uiR8."-kRVف˪I;`Vunbh] +`BxtqսHPxbwQzYG#77DR1^jve%ݨӇM.O'ż/i6a)UI(@%m4XyS`cs?L^R*Lry"o ~X&1p+4# ys ]'%T],ȵ; Cd))ER"˩1NlG FsA'znGzQHT٧Io!\kn&4 CC%|L4T;:ߌpf8ň;^̆pUB dL!py,;$ LLd$d`ņt:G JTFP^zGVj5_&qfbհMI4zNVfDže3H~ӧG7r-͂,µM;k\)C66sɀ L(uգ 㑲=x\[ìȢDq$!T%07?75r3#y{Lm. Gcn_P?|#;4,K:YUyﺽ:Z5WOsb)p?DL9ڄ%{2(ۡ?LC Pd7$)Z:52!ip8x7Îtඞ Mel];TT@l F2JXbM߈{l͒x,;U{яw8Q>CA9Z4p9u`ʺz&t5~mL逦$SEڕ4 hU.e6j$FfD>=+:oJpn5׭n(lEPC(p x<ϕu7l ~M]Ec{>-W;y*u;ƸPS5lq K$Kg0-b$.`s ,Ȩ*g}hڈV90<73X/ҀKDF*L?鴦LM IzCKY*f}9MI]T?3 s JQ`k˵z%Eaqg?j`:|^F^ DDZy'lzHGH>VamDۙ|<:PiL=2b$ HQP Q"F$= ,US➍tXxlb CGC jaMy LdC;[ӓ8SoEXЁ=M8gw:n@)Jٞ$;Jqͩ۟)^,^ycn)$-[F/ׁ-r3!f:8D1/B{7/G 'Ã./IsQP;zo?VE1rUK6Al̥ؔU\[L 84[l  5?# $:>n>э 1ǁxDEya D&!Jc[E;-V-NS$ޭ$m14!qc[PCo'}3%K}R7c1vQ3\$UO?4`/IvlH"\a%Ѡth9Wb/Ey#UUډ޸X~>$qu6n g8MٙK&>\CW8ȠF4YxbLry?Ť%p5q?>lg҈t񚇚r7(),b nÛ>(RI({>p R\CQB1KHS !1Mi-vW> QmBaidvȐ+gMQ[8؍X ƽMJc6mQY8N)d?ˆʇf7>=_'X^A-E¡8\>^ @ QCgGȉ/oaox97>1XQV{tިׅode8xhtan[lul,|S'n?ª3|_VYiK(aQw3]lc!K(ZI}kU7APop{ll0܉SW9QhĻJtEӶ~ #۱3yNn^ 'RaC18D]e Nb]Y ")`EE g{lg՗(§3 P1D3y2{^ 9qMz1|\,/10ahQӽ8ۣnUzcI fu,vHjᢵ55I6l:/AX,9v6"Mf>L:Sߵ֑YoiA4!L>5_wt 7e6[Q4C\gR녫$qim: &UoI#,sץ-n k-vAIm> #x=3Zwiχ?TL$?Xm ֚-1$W sY*ƪ) a֣ d(5SX_!3)畁jaS&3/{ ڿt2bTC#};F]W2ةHq Q+i#zԫn 4zUq/G޾Չ5׈l@b%|\Z%7Qwq1=._X&oUCo,+ {wǽw3m2#nޤ/,ȞTB2ę(3MdWzԁ6ǭ?M-- ڒ/:u3!.C41uZI8#D!n|RgOдEĎC!@$M5=TQ{f U6]rGxΖx}Ny]0_XٺciF=n'k ?1v`Rena}q}u!,oL+?q|̺2;)Þ,2Yu3HnCj ZPhԜ{&XS'S˶V P,)E8'e FKX4X UMk~|u4Wo <],5XVHޛ̇et-S~2PNXW 3Ř!D'Y y6A =NcK9f3ws ;gTwC@!7eBғ^P=/gssRŲKVЂK8?S^-H 0ɢAtS0}1cU򘓗D(?!@ڡn`Dt'ePrzmb'xr1f/*BZ_ycs~.B5u- %_#Zڒ;:3R=#i#,J'L /Eɂ^NqbGα:n㐛2г̴)N >?}b,+ ԱKck\c&2eq1٬zO W[ѩ_o..(BVq\ՙmoPUGC1Wq_W.j }WٌUҍu<pl9=:{HS #%"l|NK28-UqQ}%e׳LZel%@mi3WAJlg{-o^Xvx"ڵ 0arE 47ߴ:]кL+>%PÎetHE~vvg8E8`M;R6R|J(X,ɯwm"ԍM6/ZW!&X\Ҥ+qq~ny!G?<[p8 < ZZ2c"=Ӡ7]w8iu#S 򚷃Wa" [qzJr$'~pGq27&1"<i]7= #OM0;~704n.L5gyu$72>( e'dw|S9;u18J|kd[- &Uܤѕ"EH"R'cڢwMO+B`~:мX))TЕI# \/W ~iZ(&v:pGq2Ȩz#~[x]QUqL82UԪFP. 6IrZ.5n> ar똞i\+ąB۶ujy=eeJ=xU CDgdgPv;g4EL/@ޭ2{ n͛G3Ǹ^^q2˶ Ey&d( a( C!0AӍB;13G: Àv,͜LZ1^@9s< ^V":ǂs*no %k\w]|3|%L*8eT ј;rK;r._te1E=V4!]q`f{e<\eZ7ῡN5*:=F;X"`-%J5ѯ5gVN;){*ݞh䭦<B@p5PPĊ 4iJYE5d@TYfH0縮[ͤ 9erE+'c1[lΈNEJ|X{2UqLBvݤpJ5%F6`MF:9e;JةւJJ+8L,FuAG~ՀYEf i1_nU/{A'c    &J騷/qN{BTMk3AVO_i|OA }}9Ԭl-D})uә`$y5{ /T nֱ/,~lQ.p]huNoi:qk4QYpÏVFn|ШDOiRμzw$'a\1n{ĨI"؞ӼJd>븑}ٵB_zypkEHIu]l{Jsb![̛1BvYut1y[OCC.}[c2+qt_0VޓtPjՀI, ')03X9%^Ii$z_!4?9P^_1Y# s٩ ~ 8_%6@jrh+Qn5[ƩQ")r1ioyv=3 ^#T4՚3K?-9P5Nʌ܆ev~Z{%J7ZC8=`PZA`$Ulf2 )AMx&U+0z"i Z)(&(Pθm+yk]  ]{v4٨L{l޾EUDk8ƜRuynHUÕMvݳd h-2@ F3J–bFx.쫸&MҚ+R̕Fr *(]/'aTrZoJa ~za^,'86KĒ NA߀H9y؂+y_ -Pp_@F|e)rOs?ID\:EU5ܚ 8O6F-?t#{X|PeR37YD_YS+L5R9żiXii0|+-kVG&aU)Ϛ- Rtw ÐYdlZ}̠IEX3B kcN^T11?ا=DZR,yhq^(b9`E8L,M6㿔l:Η'A'y8J` c=?8ݚM1I-`YIXl^a+*B=N^>L(=;6f}U=ۥh*όYv}H7Vۇ&K嬹}τSRGXR`gM`gvsIŇ潙 ;V*EV;x4S._)$r"rƜFDQ(NZĊJ:F$awSʇu HC^\"]0`9dNݹy~JPK@(Gų(̅ıfْ],1q@O_Y?*ӨI\>. /'W.UFyأ[0̝΋>*a#fTN$-Q |~eiXy6=p9+Ě!8;߷bfTBO5N=M9@ڕ#F=E?Yt`L>5mrAߴO-PqextNkAu7KמgޔiW?p<GW* cZOcư+6Tc3bz+)z(Og8C8DcYPtR^ޮyL,neIP(:zWh$2*B2j$L]/iXp-*ebJ?AURĤ_?\%6|`|j /I4N)Bw#uNޑy&H|`NMΥ?Ę"M'1 '[7+/[UUĶWF߉+cg_9x}kT32E 3NZbraA2 nW ξEbB4u# g$Nrb}uBc-mM%{>YHzW _YrT; x";XԄgu"l$NC?=AǜUI }R{OxT.cz[_ 3U>Ъu>rwePۨdMgPP(ܣ!n_QL*h.V mLTP\3o QnG6fop3uGoBIun,Qd$@fBԞlh ֣Zn[aApWMZp]KmG$K;^" <^pG*kXT@sq!P~ x|YNL .=}$'+$Bޕk,@T6bi{Z}I4 xr~4јrKKw͝حPm1^00z!sIps-2 3 <Y^]4ᐵC(G^$1m+N O|tɾ v9~rԣ9J5حc>`YꐭU/FNk޴fOk|X+wT!*~MVMEGT9PWJNRؖNă.p(P*іFvޛ?᫝TwԆgkco 3>@$u&ۼϗ$Η<*Ƭ,o:1ơ6 [09>*R5Mz+jƃhdg7i9̿yY=o$;㧵%R@l g-cΡȜ4ϕU;v8xgZ$zF&Da}; X`{^  r-y40"8YhEj|J*U\ <]6p癯:`eQ0>JG$ !Tw,^4o.O.5P勡q^Gv\_;-6, Xg\_%HEcs/[jL_TmBXM$M$鰙L dg]l;QyZ4G{hJ?T:CX4*LX?Mg&>4%i#Md*, cF['EAɱwӪ|mf}m}~1!+CF6ɀNyξͪW̛]7`/Juc1-1N}=iݼYJD)/,r0͔NzhH ԍݟ8i7cc<˴1GfNpu.H-KKTku/hmUZY#[@|:#|=Cd0ׁ ؟,Y;A/+zU`kIJFOJ{KSWϧRxر̜3Kvtmw='%'9mēuL!Yı޵xG1ѓ(a!2[XPfk5t:Ld)ONꤐ ^^JWr )f/rxGf= K0XpL}s䚀=Spm$0ONp>f2 }GzLZN:}bt{*R῍H #OYŠ<g,fSYbJ鞳AKd)ץ*o .2rRj͕KuCʗU>CSrM+涕+g3L|1*ւoӃy-O*_m2W 63UMT6۵Xn"7 |xr=kiׄCج/,2ɂYY6ć2]Ng#wghz~Ė:J{[8ǶGG[^/z-q5&WZ=G7h@[ Pk' $^6$nB\ISfr$NDB jQAddui#c:—q/MgY6F~=^ 5KSJ؇ս)i|9p:0^ zRzԌxwfahNƃъf-슶ndP_eTV^ŔA<\i`Bς ggF]9KWo̺.SD8HM'YochHɁٿ~2$-m=/'0{a+ݐw*Ɉ7 jI5z]p'?em&ZFFz<wV+Щ/;b9_bי<ҍ7'ωfC'- |Gk|vzuC!;]6 6:=][1\)vzI_:]/ *_,P2L O|lj?5AS3Y=){,S+íutcv9{)JCzZJ0P5`1Q1@i_YYcHaxRR@uvyL~!ei Rξz~3zC5ƴDmm7Կ\D`oLj*pNJrz,S¹qD 5?^QKΥ%J/q)a.z#Jx?@iIB]h aOhyqWBVp|O*-nhN1/̲c`-{9Zs~ X-J^Yr*:R)]FJY";h0v날z KhvsJf0x-Ǥ"n |*(FbiH8lViZtސxC@ 0 \, I{/%lF;A i!ntBoM# z,4.Ȱ>7M`9Qyˑk*|eo u3&Ps]~k2CY/JbJ(?$u;G8/}2BIÜX!S/4?tFzr͈xs'|OӘZ-ƅix=ǡ/6u": W8 o׮,_R׉62 /fY';{XD&jy U0$p78I) 1zՆZr/+0 PKmS)g|l% xFJOroXNFA$\%6rjΓr{D0}F,#´zōb*ڵ'QPu3qc}sfnW 6+۶Cg+gjrˢ12z33& ۅ1 j*.)';.?Ry]yy(Tu8Խ1p! E15{yo:% 3`%J; f56cmlѫ,N'BdҴa^Ѐt1fV3\i%r)"lT.ȥ{gX2uvAeUzuGa FCQY)(%+NT?j Y "l`HOFw[qmдo^n)s/ACP^ROe#YӾMYA3kB؁/rOWtyQxYkR: 둽dvņ4Y)l<"*}$ d?UK+`#&\Sx=G"J NJ$eOʲ޳!dɎ5eyPqN/4d;|0۱mNxk@mx @nWzΔVw AdayMّF=%$ M,CcR1YrvOQ(Ay^{@A*8/m@Qw?9.u\T ሊ]RgxC\G/ɐlDej\c_kOvN/U@:,B%IMaWa8V۱p q"YwZp JN/s$2ES`pvIh (|nOѵVpnIS(" yn ]"Ft%B[AW3Py )LBɗVXIјh "omcSԱ%UYD/Tɺ?`CUA4$/Hg^>-sK+[t8h`S@-8dAWK LfsIr f(ͦ^-fv y1@-R&t*!^hS2 jTW!4p!l(^4$#Tӓ.cr h E`/,?IRM"(GeW.+b{}<ͰkŽI7wj 'ߢ-[LR_ N D  ۱fb:j;nnb_> yS9 ;%#ָ4kTakFYRĬ IbPȱ ESRfd()r - ޙBţP}d6߰[yr|*;ra$.)( 4pد)uA#zyy=Q%N9ͪYV}>䢹|S㚾6v&>s7uA?]&Ĩr2HhJhIJ .[ ߏ"a.o/vn(ЀztݯEyXulsAj&$4xΈ \-2 τ[9y({ZD]_3Ϡ55ճ7uwt 5 VąΏzTL'O<#De@0h! r}8=n Y;CJ>Bw8(WUtLmqs5Gȫ}0W" fT`X-!1$<-o,9rwfi= }*cߡK_G8"B[`f`+jYN6ORP;h7C]1ʇ@-^3Tn _8G:鳶x1ٵ3WE }QJ`tܘ#@&X(j]>1./Qq?7t's]|VPzw/g!G'֞al}iE7K|l@( z>B_SrNʯc%Rt3hb/^i&ƥeᆰ _H{HA|A C-i}pFf^SiF5 DI5id}CP5<$ۛ¨Ee4Ceۚh34$He&EcHߗbq&BD`U?\cr֍=PTak&&euḙV3^f96T )TMqL;k:{ /T 3@%xFq:*,61p%+Wr 4=}9nPlG]'?;vƾQ!DCP|*a{O%BS)+'z^4> ْ3F_1n{a%{l C^S{T_|ɪjr]ͼP32)Ei5ɪ_Kn"_dbӑ" d C/wM hb}[if}u s ³p4B~h7rW$q#B7n0EQo dr}d|0)$3qg:W=P%»cUg&FnUzdɠwe^Bnz}5TuK,Kx6"vYL3Ipuj*9wJu^8h0|'-W{+eѺl}2씵e#,ߛAS<~,[8wFL4\2OVc#:>CV<'I+&4Jqe/e6yTѶ)f)*)Hb)<5OTsUM [T43z/JwHiM6`HNH;"S/>JkYi`FdJȕ>plwsm٣i{+\T /s{63SUod)h2@?vŗmQ䥰ʞta;D_{-G?%w+6#WS`љMҤ6~Kq\].2@R]YRԣS"qseٛUOaTV:L]Rsͨ7DYzב)'MK?/C,~.ў2X(n/=䑿`HVy-SP^7U qcՇ;Qˌ(Vߨt8kSY 9=㝜?38c>oOۇ) -,>G4xjL+]AvV MiN-f7Uo6vݵM{> jw7N H(xi`I˨P|}sVkRE 2}׮*<jBO7^<A @)ڋ .I}.5~;MJC)gd7'C:[ O8^B( kmFkvhJ3퀂 hWoAw ag$7/aSۨcᑆK8D"!j_ڲ9fP9goԡιPWw $^0X9he,ibMDOTRxB} =ǽJCxa }rtE w Iw?%˘i(Y/ȶO,Dm Zv́gv\fꟴ*yYl]JtcEh V6p`!SOs|&*;ړpK 0ؐ')`ٝ \*l~z}f9zf?nRʣٮceYwv\z&k]PC%芺]mZ7&殨'vU-1iem6vPQ^Ma8A6odfW) \9c}O;~,Gh,dxW`"Vu wlHݖv_m-`LJmqw \ R>Asyq{q Z˂;`|P݅ 2iop1i跂۶ D{uJEP=MFP4+,fبǤgRs)$sDӣ#JD1ǺhxJXPph[򒻞zO}Si,7,̾T~`/Dz,`_tlB K l_ĆaT(q<>4|"4!/K3(7"Z󾆀KjܱkIֈPJ *L׷WQcq&ߧDd[7RF)33WY{tHD\gʑ4L`QCpsηm( +;ӾMʹqf+CāUZ>Qn+z\-SƧ H]G+|hĤ@" ޣCŸڞj|X5'!TfQS'wb΢̤P^7~1r3aE2g)^@ ՚:kL̖S+Pk.N(q %SeM0a* +X`0P4SxU?K;arj*zoc!fT*\pkЛ_lFS/2o,xv±%\6CA~7ԬBc%L u26KX f=~PV[lYN Y(oeIr|[YhcJrͭ bo<;Rʍbbb}=~ e썷a9Bd_2'&.0$Dv)WRʐ lhHHWEjE"C +2y(桚PW}$V<&. A;杻mGQ$k~C-#J" FqF~>A d,7@Ǎg'!Ϭq0DtQESIXCQk q  ytƾP\E}X`6:CZHbݏWJ ;"؆ =lQ/g.D2J,QcL9eƣU<9Qc޿IL_!HJ!RD P(R=|t|Ve-4JWRj`8O8>XӂAer+uX0~Aۮhku+&Y]U0me5G"ԗ)WC+o+w},F5\4xNYRXk ZHPh8ƢeҌ; ڞw It:Yٚ1alaSfW8 լZ6ЃHr?BGUئ1SU@nR/0Gz}H%^*-Ue?FVY !VB&%oq:VTVa 䢷uHٮZ#m6b"ξmWyҁgJ{57^fU)WV[.x@_.Ậ2SSH]6e͒x~6Ƙ#2@SPNAӯb,挭V4\_x,wpӘwplecD(_o=D|1xY Ps3D=ߋSah:oyRsn៲)Aacs{[IIj1JOf7H?+{- N\bߜ{vu`@V=ɔ  \5R>Ceax OyP濺a QD #-,t$8VC}ԵŏiL漾U*;vɗ6L MW^ə Uoq8Yĸ##mYz o!/'r"sx %7nYL9\˫dsi;K6AcD{iR;9)>쵣OXu؅+Qix^r%k]<$n)h^^'SrѶ+ `}ɵ`|@Kx`s5D-kf#;u2!|CuRj^/>1Wm{ֈ爨BPZ6V!YQy }U>؄bܴmE6bVw0@GT=EN1P-sUi!]`;(8gL셥AqγK>&H֍Z;X ڊ3}TR ä5pd "dĬ%'rJ1RG7CS^\fa+SY\qV vFjldPI0w'vC9zc\1-|U|xS.@N/0^gO[ ػa`^Sn$xijT̎<M/gS;ZQ]#I/s1`:K[ݼwUjwI_]tL-pZ#F}kVo$;ЎG9a9qFwd2j1~+5uG֟SPe ?d:vàbl hq KeL\qQ1炀gcxFP5X<-!ꜪjMc*S֚phZqO|sO>AxK`0-6{HOe3+@Ċ< z8C#q=+q)vDum1d)4VxRY<;og>Uady  P.s:Ψ1`Dx #D0HӐ˄8fa5tDsZF/,oGδiZO|GpJ 9 ş"-!Mӳi>{#2+h?u9{ExTd,5OS-GL5S [ !k)񼃧Rop_j=tk2̱c҄OdZf,U[+82 YyM'lT`}l,y> LG 5'é`' 7: Ϟ$Q|h,KGޑsH׸sC5-Q`;Opr흫; /R'~~;@N.YQG|) !Xo=҉}!H/)H"U#wKėtaY8#BSAUAtE9&vԒ,^3t3s_=$K*㽩䃿hzl;'bF|%ѓM̲\V}g\IX#_uה^&xψ*i5z*C bЕQpN$ݏ^trZ)pt;9M.(W^*-:I{"{mA!-ic_nzTϺ=3  jj-J)Oon<VF,?"=q9200gygK(^'B#ku Q vP.@]pƤgbK*}C6Mvq`]0~>oU\?wRۑ}5R7TXyOx$|nګ "LÍn[+4v|Vt65*B@NtmTun)^wž鄦!*CJ0C"Uw9$]a;neh< M?Y1 )_Q?:N^Qqi#hӉ.Y ; :tjY# $ Hⱹr %˜ven Cc^@\jQ3`?`/)ƤCq)yh3TcQ]E,Eg_'Uχq*W ll^vTLiKI2vU'As( !UؓmzU56ÕbN\sDzW?;>.%w#8}馗}MC*auQ8Fiz~RYK ^]OuuQί4 u'wb ;VtX}4R+gy3`(1rm9(Xnz;tel̺W` 6;N, JD k8P1_4MfGw,̸ke0!4EB5ؒLt”Ivht\rU?MrUsX!$>vߋG%NRtOײzIRh=BDap0m9}hQʝmK( :$$[j|pwSyX2ZRc'cWW<a.ِE^zY@y5Yit5|a= }FLCLQ[.A`eR6pB.R0>l\P[#$$EƨҶw~r#\ 6j+Fg_Ew4~U̓P'Ji[Â"DDXP<إ=Z{C]$jevu_#cdD-PP# L aM]Qqɉca/ڇd{[ k;{2/ȳ2[Nxehrz㧘d ̖_~Uc2nQv֌#w@C03M;+Jf,wIm>۩gqM{MWUl&K0MI83P_ #*L'k&̐_԰k2iTn-,ӄmSBTF ' K޾T,FC)EC\xM{ `jlGUNzm&#RyG>vvv, Q5bއ#O2~IFy) d&Й^ u!}o>=bS1gs~ ';uY{\jf{y)% ?k/mdP<'V vÙg[0Uf|nZ{M[ W.dTWWO!XU"N,GO/#(#~\ߖ}<P~ʾ7sE_(|ܙ*-mד>_a.V.[ 1aaE;3B % /q():EE{!=|ʏ=3 ~!Tf𨤿!|̶VBpkH5,m$]˓hᴲ- I:mS 56#Ssq`c1?I:KeINv)b1wtL\0ѫx]b{aT9 !hAז*lȟTAX,ڬ7P_ 4ncbm(a$yu]lO(f GHa)ŰJϮѱ~ K ^?>&GBG! *Gf$ln2?t̹rTA+ͭ\d`w4(%c__O@<,>(K~e =h[ c\#L gI+8eS}x)RGŢl__kJV1 2|nks]{F7)(3hd0W4{*W}i!ɑoQ]sΧXil=c+fT=S3L-z}X9+ p~^dW{E \5ݙU)QQgX̔?m).w DA1lߓI{t(om~QRو~̠/{#{NS=ƨn^+cUZMğ^jI\R{"M"[4 q):yNI %5/̈9Je*ax-RflrDZaw s۵8Q>{#!直pysM44lJs`ʎx'^c/v8:V]a4gpmsAk?0y4ORpG>+C=CY"Y::0~ M/cp]0=kiG=Ҫ6RK,KF2h_pF`uh`}xTot8sD/F0㑤5~[T,;ƗvUrpѭX矲+܅s 4P.Џ$1ι{2>-s8i)q/>\T- M(bYn#!;~?čјY&&.5L˒n}9R#sOWn pxW!4N'e٣%~ld4{W4䛃)bUmƌ,,߹ALP68u]$~l V: y;0H釞y 8퉴۩SA!~'U  \(G9I`q>'E$V mrBƏUKCeaSᮘg&Lxcui0 1چ=/V֑YGc[fRAGڎ$Y M !'lɔ^!KqNL Wߙ|Sěv5p*KFWی3]DAy2JRdNNjQ9 (Wt%0bwŹAdBeb͛ Jhk&.*$qZۆ."b<\ƥR9Tv[% S<74+8*|SOdc6NyQn`SiU~AM Ynz*IA_H2&F0Kd؞Gjiᰎnf|@ĺ RS: ֱ!Y3.,<3ӓS}y=_^@~ZkxM @ !Foΐcȳ'nΟfxPsIt Θ| ?EPEU|IzF8c:<-"$jRr٨fc,)7Hӝ׿W9$Ds6yaW҂OmZD,V5{|:s/ q,1_&E=?@-NlċQew$3'àO6nvb"1kGⱺ6g (Z JRY_~x},OuxT;& oGf}COo5yyN9ftmFhډd04 lS237-O)Tʼn n*WUuSGG2ֈ(fbE16îC8!)(R͠a̔JdAR'*nQr@uƼX~[H|~!ysb}X*u='Vi:g.⪑L'x.:i-Ē#)BЀ!Ƅf| 5<%a^ẊC6kCkRzw 6_6`1w*mS %04|eR;+r$X hAME#7Jgk^1\57mp 40Nm'0^8 rV鰑"drpMvV%'XS~I wD%vF^Qʱ\iE4g_nV10? 5 /z*.p*^Cra}9%6#vv :ff>ؒ䆈z*)oz:a5PA+tfERNDVh6ԣHI9U29 PbGpC!ssV[8~̳>o}(rfSݦ'ht0g)ǏّUyQ 7:fޮn(@WLpA[a۷èh{lCn~36Y/+Y!J CJ/,^nEdo퐼ޏȂNXkA 5K-zc'P^OZ\~T x3 ^h'>b1q x .g)*Ma:dݛ!؎ }"NP[@ ~ӝb"C c X226nn5Rclkc YӤUM&nʛ+p]YMrZ <"_B-D Q}? {<'ǽȍ7%iA@'-#WQW+{TTCo8Vxi( Oyi>0TB!ZߤTLr]d<Wó 5p6y;VQ0ٞG~m*ȹ>&B|Y,[aC|*ㅄՂ 8CZS*XȠw#J{,bb;'$V +\ҥcufSwd" tnlM(Ƹf.>8M XN+Wk6o)ئlٗxv?ܙ`6dq>*bWHG+--iG} ?-y֞;9H,:EY3,f&0İ \4ǶÃͳ1 ƦUn~[֠kȌ-iݐn㗒 Q"2j\EJIMG~6+[ftzfw1j^ ~50[RT3v[4_ktVYZp9y #բG-uò8ZVW=%|ɟ&^l4ף}K2\*htLU!=(C m|x9F{39H|~0Tr{ T{]t~!Z?o p{8BO=GLZD`&CDx )'%(F 󃶌[3Iv"cgfIPvI '4Tn|oo;JTp_d0|, G%. hIe,rB+0%xӥ˧V?Yc4pk17ٽW'{E7aWvEG :O* Ã[{Jt /D87?ʇQ 4F `˒,E]rEْS7%nA{-ݒ?QϜ/ؔyW2WW޺nɍϷVnjHw8Ho;EBZ 3Kd [b͹Zj fYD I5WU綸'QIxc4AeěP#Tz[#hÐDsjAfB9B͑c8 (eJ, +vus]w%HnI9sjDj<k0$>G,o#{jReɽm$v1!ez4M{؜Ue-*RNjQ ٭an&ɰ ?pWN)B=5RFp4wWu)%Z#9|!W"XMyTŃG嗉+-GLJo'o_YM6^8'i&n|ك,$]*('ŧdDV;8UT>A{1DH!2} wb+` a_sSzv.i?|*ۍO"1(W5/ a4toY]%QV0ښW)i /ʹ)N+ L?X4s+-v_vS PX^޾09ɔ֠&߯'EK2d-٠NŖ  wөjy~F*ꠋ9hM{u^U(Bn UӤkp'Kuu9vd' P@0I) 3̸A =LfN&mj]FƗǵub38L!मS6MXfG}vUw$(OQN(eN=V[Н %})>3"qsP:vxD8PH(OQכlvf[_ė%d53q8->Ĥ@լpx ZeEǧ֊bhdLi+Uͥ-Z9C~!R&7p/";.(?:U"6DryRيȄFc76ޫ?/Y ?uin1 Dp!"+|GYmԤVA`]>vwfur,9yЈ5;g>i>Q$ٷOma/qC+#MIK@ _ޏ#oY3+R iBjB,U`p'R=*j3=/㉰iq+Z!$Zd)/RsB{@F֨,;a m]ˤW+<T?v@c#p*&DKo=^{bHKu0ɺx6ؤO9~tj:ƕ);{z]hkȴ,5sIٹՐJ>$)Eհ1 y˘.6MT1h`qFgtRņ$ɦ p]w;{]uF) 2O }/ͷj#bhL/&넬(6j"+4$8f.)Ǥ]"[]G˒+sT8Frsܟm@lȿ/h6j^L[ QL["qvΠ}2$L?37ZBy7yw7 hr/5CvܒFi#'Z_ ͥ^z'y,lYhyt\2!\^luXYxRt|:\pS8<i"~yYmēG\ m׿lZjU Wgs;e6*<P|&Nz KK R2I_JdҔt!s{@R=BFeD# ;]1s-f;AQax.++hNmDZ#)jBcXé>3և#0&},dT4=`gҹ̀7, GӅj;E,wiYaHj$(zQXC7'p~֑B7r=O:`>TjHcgvGNJ7Ke7]Et_kjw}ow6/' %X䪣((V*{JOQitо@׷!Xu4qG +Ӳ:4vݏߖ}0]V\+-Xrc>]Zn0t+e=M]A'ƁzSTՖ\*lIh+nܖvG2fr /` q3z0$d/xM )Z1i׹.S0fRjńzߞF)ʣI;tg=CFN>5*ù/N7kg$h<쇆m6.\U+Id{oaU/$yx<L'C?-qAcryƛ`[>"yF_::`kwcf wi%wa]݈`e@4_8n*6 k;ԡ m' ^] ,d)LA.;AٴGȥ08 fߝtw2i>ScrNh<*p?Y vAH:=9gqdbG"\zRflǾt%)`^|dA$w=GE$Q7ij*z#]L(f~/S4ξ݄4&! K3ڇl $xA<01κ2% ?CذM3ȖQc #z ghe赵.-4XGt 싟X%Ȉ& ܺcnz\a39} W8ewCvҗȣ`jHg[ձ"CbFIkpE`EӖ7&tN=g)%27Qt8C8.:8<֯5of붋,88WS6}1AW d( 7bCto=PCہL8+ȇUq1tIbRaED!ɖbfxoM0mUF}k\w飆~"W'gf[̼Z[m7ʔK0Ge@,a|yםY) .Y`#7[x@_c恄0۸-͒AڱjX6~f~kC!.*OZ3,Q.;cޫ p.jxmȅhMmuL*3ZEd"QZjZg)X@%~HG  _[,{'oM熸a|Oh(Q:a3X jeXEnȟ9b@(yZUWuP+SuBXck@V5v[AG5y2'UK`zz70d3Cwx0hNaLY.&lpĭ M*^m -w;\^f{2>'!yh=!"%U4C͌ |yp&Nf8Y6<-xɾ/Ff%Y^14a+r3 2ʯ/n('(څL`j~hQK` e'N]wRVSY oz[["DF䶪B^l.Mt9#oW j0< (n9Ac`f| ÜelԻ`=fyrc:kA !F73\x&jzoEsf$j\eϻ zsB 2vʰ![,y? ',\9Ϭ|a}_3,dx7߂pqXz[e*r̎·D4^֘zlׇdɹw`/#!):f hx$sXHӣ P-1Jatjy Œ60ڴ(?4}<ȅãi.4С1r -tλԺF&}+vebM, YPQY&r8=ՆEZVzqU9HCt_ 8]?o R3l\M*C[ #U,&:abo<5K\әIe#P_7}fM& n'PLbnX %-7VZ"y]& asœ~x/=wV؇rR!)P0R4[7;D B1`VX8Y'@N >ͰU"4S6Ht!64@Ya8 X04Qm2'Օ@z qtv_x8"W\rԥe@|JfI ! 1_[R^ݾy*9teָ`tFN!}XVͤe}} O!ƞ۵RT6c'iFCf?+1j7< okA5GP*>>ZO?ٜyiu/͋jީnwF2 4v?f*UvIj/<T I)A=@KQ ۈhs nBN+r;wK6c%50L"b`^Ɔf~o~vu͔c1kԱ-tkDyyvP(*qmǯwT'f+0~42[iWԙx$!?t7v2q:; #|wq?x:Q&^1 \*7z,RIL0iXl-= :AɈD FO\i%Ч"M#bzS;-oYPu#;CۆD' v@V*lG5W.#+,}KwT"S^ߑRE 協E`V!Eo }1&3uа8N:N<=f;`4/9e#==gMo/ߩߩ/iWL<۹skMGxk$3lw!2>0~mʳ?^#ӳcX29d4lאʅ,1mZꏝbDC%QeKA\p&r[~8:*i{#O󜐫wo= 2x[|ztyF7I: !Dk睸DN,|O3]FMY;ZZnJC[ 4[ Uhu0@ǫd^}?,BkK!9U Qq_rdXڜ~HJʓR٬1$﬉Bmߟ8ʵצ (ث ui` ODO=0eϞh_SV% f n d|R س/ho^ >0tYAO)Z)TU_ ;?P}F7͆_鼵CWOU7U 74ha'׽?2ІSVJYmA LajkKt#GMxkKv )f7aQ!tKWUE=:]+z/s⺏n R'_L}sŘwDDPEƃ O',p'Cz9ql슢4h΄(jPeY;?tUm)JU PѰ#[[8>~T±0si B[nhZr>SxO/)yw!p5 9n4 mSU~[lz[k&ɀy m3&5 롆#]6 C[*?)SΎ,!<A~M}8OxTb{}(xGjWeRy2bs禢n}KZfRd3˘UaQZ.Xdz=nr59t_ ҍ5.UإoQ\JHzP&0a.Gz0#C&<-aP)/ |q9atLόM%96ΟNd RkH~vձ.Gr]:4wzBgz˻NDkjUdP74׵Kg>>/So_*wHv=Y#xJYEi _WWsFp++1{%YL7Bq4&B3Z%hv]4L :@E.`g"T=/;_iKQDBD)򌅣k( La0hFy$Lܻî1ge?*E&Q|sS, a~Teďѳ%-))yVEWl2}kb}aQ=B谴y,U vkv)Eй:c-v~o'[0{/}) S'ȰsgPb[?Q6(Z$v/DPwoR%e*dZTpK7l)^8iˀ@|wG{E(U.:Μ>N퓊?畘FFw6@ݤ7GYa Hާ_:B|[ș}86%G|]+6hԨKyK<!v_蒯1fmG^1'f8ߧ39Bd%n-'OSE2J#X m_"[B;sϓy믋wf%<}30e)+Ks.he>P+)+vQOGADåY}>tim.`2_rĈWondr:_܄i`cή+֬woQU';4Ӱ]&.&3 )ixvv* V@9\0=Xc> F}/BmԠ$qW}q?Y^ImX[,NNZu:Eu}RFZ$o”S;aA{JϨX.+! ,崁7G,(ZDiu+׼e:^JN3mYzKJѿYaӌz-O]>B ux/!"d<vT BE/Y:7'J/rK*hD^pz^Ka@NĹ~]<^Q{MH _Z( a kwj|!5<X ^">%AYQ>/|~H=6,e`xm*.Vnv>79?2l5^saR>K! 9I3Nw >T~1VXA[n(號%9v GR1dKWv:Y $1E&l<;{[Z'-t![e$<`K8W\1ed#LKȗXH7bmXvEY0w2iGAyAyw` )8$+ՙrtw+ 56]kA}:GzINPџ`?ĵ  ݇"6(wgAX0©㢺4-xeo /U38Ȅ+Dy{|"BcL.x KوŒ>&%W,~G3-wMv8Ǟ,M'Yla8'@q=rq0~#q]on#eaPLD|IgƭvcbeFF$;Y1n_4Psp:M/Ib#qaeja]wAFr.1#kWGۅGcWWFVz>hIOe?n8h&yU(V|PcA YxyB:?QL#XK1)7 Zn:ó{UvYB)TVMhW?fHm Rz5.f%Z5v3:!4ǙG1\YwxqB5r/IG[&as+.|<7`d?,uRv-7rTwɹ6 rlc ߫<ZEo߾ {#1R+YOեf9ZkZp?bf7m7m2DXWsIgəp䙮!BJI@'ƳOmp utǺF~uP&a+:n)cz/pQBRVTtIM9RN 2ֿ8DߨlsyD(/7sVſ MWE$ۤO6"_Yۦ'NeE] id] QM-a-c(Efpk;>>Px-N.gyoŃs,+Zؚ?6CRFHݷ[`)ϖ(Ń^}H4q=5# kO]t!]$+B8^xӄw0ΐm ߯^E@ho:Tbv=Lr- [0g~8m WLdqz80X  XX+gb 7_ lvh&7 A%lR+F3zK"`jdUHD{%®m^"ex# Y` iy) m?a0m0Ihf_ud4w sLnőѮ~z^L(]f̘븢Ckp_ */Cjbq9GН y-4zT%?R_ Am^ L&Hg@Y»}3&?~ye ]%t~=ġ|[g&ڒe0 #%vClA.Y5_n,O^jN:!T?~ɇXnNŠv2^@8rEQ)HگA%*=xsHȂ~kٽ 7Y_O$ٰ-|& "g Y+qB*:H@F k-4.Юps[!z^z1Wvs#5UqPa)tLUXDw}jyaپ}IQ4,kJJ1 cYqZ9"^mJhgIݢY tA SRYA;B3ֺQuGg黨%;{8UL>'{OdtxXyY"2v,{f9H/'5P^K;vM dQe_auѱyA|xSu'dt=ǜsPh%(eWf8S4<$~^Qr#n\";M4춚4Bulb.hqC,3a` =*3"s6{(qmgi51»HX)@Oi%NlL?BJ:lZV*ФPrcO&VWrKMc+ d~.C|ESjQqp_f`XH.(t|]BC_&W#VyQ 6]i[4P5sHͮ_bRn s7C4H|WQuoKBL DuGiRkQcNDb~H2,wY5"JSUy7h0L8) _7q_Տ$fq*9^ucD8TEq7BbPgt 2f(#BY}\O a 8ߥO|zjNjh5K5%1n!|/+xEceꋋ[h]u ^ͩCisUţ3w/G1:&b(AiK+_qI p,#hؕnx W<޺ύ^hHԝi1IFtT p߇]uqa=!-I$tWPPA7 ڽ K$Nl7P/ڣ 8o|?mw4mzN-& =(*˕k*z,3N)%; ͺŮMչB֟CmC|"A:tM;loa\I5ѱ!ۢm7 'R HOmX/^i*3#cf U_T!glp T_fN 8e'흟:+=Rez83HU'U\+F ]Q-VH)zk$r!ڏo"ofw4Hѿ~4 x¸A'u;rfopbuEL̳:1-F7F|x=S=*gНq?b$Jk2.G&l0K 4-) [nmxTCHNkJP+H~sR^>_iԷo?|:J#p/(!h!}ʳeqΌ̌R]=@yWiZ@DJ ?. ԮUi,+$p{mQsY۷$3ԷbMnZWLU ]q FY2TvxHabvQ|Hz{2[ Zi&Tcp_}y&ߗ<95̔1͋ ܡx?XU2ml֝s;:6gњ-s0sjS#XV(\8MN`b랰JBuu~语]b2e_HJz JQؐ{yPߒ&&Oƕ V)ꢘ+%zf#.~AtвNLKM@]T#LK ?OoqU g`&AꓽN8 /5gf6xM'd/6;wkz^K0=2e&٠uo0b.a5_ƧET4Y=6/yŽ42Kggs3ZV#pSEFr`<+swsFά&aiu~$mS?t,I_.&q}(- iD،cּR=)iTacAƺ/-B#H6V b3>>GGĔӧo<7s*Om8ν5E =J˵H\9b!}9翎J p4bNjimcubZ*8 (&M 3O^ -ڧ 2Ǚ gDdKtA+-CtaFk;rۥl+ɭʮCCJs@EʰЎQ0iQ[苺0.hŒwxÝ0=-%]4KAMxginyaі\ۏř-jA &rڦihAy@'=$}4yLhAQ S<p4-pߥ\ Ck*lšF!R3qUK?塀T$sOqueF4,{1qw +Æ FW~6p?F3$#]1H4s$eT\Z>-7Ѿ#HL'̛a;]{y&#@>핯C=)!)h{*JVt6KùkQ5jC^42FlntXM*4h)(PV%5O8;2ח|NB_(x&V䮉`S&y)Met։(`yH\R{jag5"|,䁟j]6RO\Yn6[Xp̟ţC[d\[+{ W1a:s'TO>*ofӺr4QjsvA: XN7/]qVR NMn(Yg{q%GZ NhiSSsՍ XfӔ>,`CQ K`Si[fN\l`DȗKZi[6>kny?(n)Q\u.`h.jzZִ~\M }&6.`M֓qb_I i=\ <2c(Ms]2R#P 0[}eD{.(>w^> /ucr7ћA gJTX0e8)Dxyr豑DG5di׋͍7zJY!3TX+^61Dgqvouu< P7tKX*y#]sZٕA,ڎf{w Mq÷^ч8c]YaKuoձ0r/E:)B'.p׃{Od:1Iw|p\gZFFRƎpGiP,Tke\C;W VÊq,hrF :<蔬}1wuiֻ m+?<^¥5)G{qFgϲ݈ ~4XQ2krk쭀rJH 4GIpMFNts]FSjە<nn-Ƕ }kj 2UF0L~bauC0P[Ӭ&Q6=GЌNjNa;+ZyjvIŽP*%ct=/ ҝkR=D])ql?"B';3%'c^KJhsу&&RMWE7? y `TLV:BЂU/c_BmBJx&kx? D6Z81 ~-3dtǰ@iXWtY|ԅf_y4 ~nłW}d8_S.} #պQ.in^]P=> *&P`KI %9d// ?4Xp|ӥې(c@,D@SHۛЋğ(N}gv"|1F{o07u&]/1 ,P;}thDz)?5(s 2S*eQ[W[F7{O{Md #'}fWu\ a -xjcje_~1vom9ArMZ(oP_kcx[ 4O57˙@37RN)[O+/?ODLF GCF@ʡo6.Glⴲ1-B@m;4-q%|d66f^fV٘eѹBcz& _T{oYb]ͲQR\rCꏆZrrE?଩8n/Fg:вa6  ޶ Pj޵S5F 8:$LT\;l*C2JI]EIf4@Ԝ[h.ا\%Dki'\uئ#6UeWPYjT>mgnygAyPW'Fϳv&Q W}Ig|9m9{;Wdk5q89ͥMrgoM@ }?&iVӤ3ˠߏ)kccHC67._ʇ.j(p6i6QZ~ӕFUnv7ZLè”WQNrT Vc’ W8u }>?@·^ek 5,+Cl٤:L/ WD"KOAG]!_Et>>2WO x.'d[rW-9䈈opŕ]+3 {!`U%BBwٽL]ûG:(1]0ܒW$+} U҉`1v ޓ_1Z {Tv"0G g-U$PMILP'd:nC\O >>!3X} U;e=ϏA;wnD ?_:gfG.>M_h}tc}rG =jJ!G1 Q^&i Oң/O15̿0qr3F?&AVpeDW?ޖwvtgŹaTw+|ҽncĤF)kǃKJIǕ7y̑So.E;S$sW,QĆA`>-42Tw92ц)jhq9mzЉNrggBZup*uAs?6l˳|ޟ > GEǃ#0FH#I@-(kB&NAA3vJQ~kjv#|]!]"f{)V_Yh] Qc69]XEt)\ dWN[*Ϥfc(=0n:/Vsy|WgIy2q#vE_B'H4\zy_Ŵ4p=gќCj[xf?s&m:RxptpE>!΂+K~60HPPF!8VJ$tGV/n! \l#7։(_֪b*Z\4 շ(?v(QNx]-%&MZ,Ǵ=_}KoW*뉙JfhhɤEB :xWQ%ܝT:XƷ$~L[2k83y1L5gM w;_OÑ,kJL8ʴD  IE5"қc0HK2KBP۟,ѝGIw6IJAC_첶WTt~Ei[0٬ezd-GLoO^ WxbNeU/2]\ڽ̤] f )*nV»-\<(#=[a~}^05 ?'yuxZiē'T!+;*Ɉl6F5/M~/>/↜A 4KQJJ`꼙 )Y}AX>k=:R~HX8-Yj[]ibt5`@I%O kYBUC#ynBpI)U9b2=p6wxZ rHN,LJ+L-?ei}[YkgER-aD: BS/+'*xfPhs1Ϲ.?ny䗒U櫚lO{w*%GA[~P;BsCQz+>3DdF?}t;Y}9B ;~? j'PR8aeu)ܾb`wxl8aI.irle;X3Ĵ#mMϤ"k%!4z44ظԘ&!aɨ-ˡN瀽k)tt" j7OjKRi&R >Ao9:r%g#G[ s0X`ń)1Z7WW2 /$M"rvsĕ8V5if84Lv'-}݉?J+#@lD.5.U>;cC_Q ܸU1$hWLkTXMWG^oɕp^|7L䫶ƊXy@KKbE㟇 *]E8׼2(I5b ;Ҋq } @-߫M,Pz0nT^Sk:m%j#͵e [nZl<_6EҌۗBWi n)˪]|op6n`&/wj~3]*_ϳ0#ZIԤMXy /2y+ŝ(<LnA v7'Iȸ$ć^>S)lDaNsw^ d?lVOQa;2R@ )ЋFZl@v=EbBϚ]L e=cڠKFjtWopJEHJӤCt.NO#ip.+Ճ/:m0#ƭρ}%]۷ +4NSs*vuL*0>Ȥ/v!U-yRmlC%QY%&_Xr|jFHzZQ?Xbyw#dHC#QE=ɤCF.DPkڔl5.?{Q8+]yi嚯27#Am+5l}Bj)6'W8?'~;rQ%J˵~x]0cm/sUh3(BJ"/[OAkU]5}6{mfaJHcnw;Ix|n4F$H>|+mBZ ϛY=[ sTN_&ethjW+\pH%93F yA PY5U/5Û&ů.OHyk@ FRnς8@y_1aZQG ^>{궀 ӣ`AT/ *)}Xݐ4TZ5XZm1E49wfGnѶA^H2EUπ咞YφY<h6 ٚ5!udkOWyg9RL[TC-U/j ac7C [(7좒N{31,fz1l舮;QZ$}>SFzs6E3 1-VPzoI[fRp)UՓpacp{EDUZ9}f͟ 2pkR7U' 2>H?hM~,_e\GXџҢ ekQl nЊd0]6~%!@ZsJ[/{::ײc+IL7gCx!l>;a![Ԧl.x5|K(Y2,LMoLy^y˧_8xL4keZ[wnxja VJ1t!0"f󜨍o,4+ޯkP#՚e# i-7HZKӢ~ &1M)$C jleP%{@@۩kV@þXJ( s7KjICj6[L? |{)g-G4KQt~L!jZaY@2Ⱦ#bNBÂ7轁s G5Ây8)dpY vAʪ8ٺ4Yd޸qgPP\K%b!^uQ؋;ԎtȦs:f ^:rϩd6sdXXg %b V~F AVJce]=N]^ q wFz,U5ep 8\CXO:Z یy5tΛXp/tmpOI"HTiJC b5<.k.vBP= z$]@5nȑbqD]m9HZ%"E$XG+d0vݣ?w +>q=Y?|Pwn%}>Xnz[Um%MhP Lƾk_E} '#L;=r/3ŽxCMC+eӳ$ \q $l}f̂,P^_Jl$/BOaWAfi~Ɠ/S9mo@MVOJs_ #m#~BJf{^dFZ*^ O$3=*t׃H`u:ź# -/O#L:4SQTBy)o4X {} 4؏ P/zQ¬c A x#tsp{Uv24 `1(҆rotL偍ΩwlG-Bߘ!x:18ڲ~,8+7O2·DJ<"w*uk5Ysė%#?) [cnC }pDGTS. [d?j=HmIAK45aK`trί(`j&,w9{Rdpn{P!A!G,A{>ߒ9g;3%lC2G4]FM۴t- *zY z"4^XdS$` S7P)ޢ@ٗqP夘aan(m&EMR#95s*xyB6جyDϫM9ZCFsš?A>XEļsٮ8 +gOfwEZrD77ҊR2P^auIWoXfYD&ԇ9WBq'`o R{<A$`<\ȳ\Qt;Ef<':xԿ9@f|)x73X\%P1+8nHg7zx!20 >L)~Óz߆Ì@,g)f&|)UE'IJ;] t{=:l3)B9h ;-hTyЫ%kةuE-x\ @̽Cd8N_l6|gjw]4F%r<$NvdZͦVz "r4PM@?Ѥ~9B{%NZD/s%U-/8ե>>utyq AV-죴?i.@xo" bp @a[m#ℴ#][%W/ȓױ_T@Ljk?yu?\!ϘxtR⁻ }k5B`1lod@"*iMzEI;0mF+rMzB>Dyv'8]ʆ3 "g uCoSZk{}ԩAR+Y7p&3ދ?BA%"}> K{a\)-6JR6VLn` f$W5X"b 1G~""ڂt+++ ֕:u/<.>&wD4٤Q6/<`ʁ|I8!Q@LK7:A! 5eKxyȀX/jG H~ů± é)Lo6G|MeΡ~DD C\ mb^X -?H#LCt#)>+üƈ^`C~\-i3ʮ=,v pt?KLiRH+N׉j-_Na4lWX0|,ȸt;gD 6:jeHyBNReĶ*](Gg`9)K ?1hjsB;dPt<'Tp5?i t>LRh Pz^_9d4wWAK-׊ (&(4JM:X@{Lw9\x]0i[D_}`y9o83poХ+.􁞳nu&}y[rce"z^,1ИA&̄U.t,jbAT-FKݡRe#̑Oj؇9%U(= d?>wyw@XsJDpRX)9n^w352}u>`#>3i-6FxԜQ]g+ ;U_uV?=ڏ%~7t;gزr}]ɘ"ydH#3 -sMvzBӶ?baҀuxdMy6ЍdԵf< T*(+4s2~#󻐴9Yr yvoX7 DܱFNdjf9W{[UX!.E|f>&S.V_RlI Ƿt(moMT*' yYEULv[}BJ;o;Z%8E5ᕖʀ.){{.p۱28&B7r1Z."$\+sk<غ=2d~g׈'/^%SA&9 zü%)60Oƅ0*~H@Xre%Ԇ29%@+ȜF_gΠZE.FĠFb㵻qL;ZۄFϯ~ +g} GoWĒDKkSxȕ/+/-JGx,@f{ Qk_ƼrY]_!n )Z6,sϘi)o5`]xT4>*Vş<9h}R6C4$iqQ]^@Fڻ#C"A۳aiF/Q90@M_i2KR{ ֒Yk{ft 4ѹAİG@/pb)r`B[j[l;3EY4 ñŞMU:aɽOkQIpej`.^ ~h) &w@`^OX`zР|-GdЫ0cmmk73b4&|Oi-+.0LEnngN2*yKk-͓y=\̖ ~#R&=aT O# J! Yx/}9 3nmAqQCG\ +{T&}6x\xӓk݋i4x%+-K=Dec06YZ2aWuPw ?9VMeAz7#ssAҜY6Vvz Y=e ,ڀd>yX^I ܹe_BӢ *xnl"[}{G0ɟnĩ(:|Hg=`i~+4Q_u:4)zKdG8s~kRetl; SChAgtM]Vz۾פ+uI, p"&f3#ƭrϏ-f­)[\^ cܣm(WR( ™_{spY[Cc荊{ܖq~OQlCa0#wh~}S/͂l_`- dv';R?0 ]+szfSw}M!pSV GPPf)g]thAn=XRZ)4x0x및[,۵t?="axsY w4 p0ݵ/VM:f%akR';nx]Ѩ+:-F j 6).0|Yʅ"| gq@Aŋ1)gJ4yk(gomߵ>yyO]V]`Ujwd(v.N\R^gٌvvY3~~>H9wII_n;Ôڹn5 *ѠwK20ĵ &($X)q5oȵ\%hCxk 78 ?T\xj(O^mJ{ͻg5?Z,:`/mWO?.=ʕ 1X,qYc-gz0v3 3EE| -c%z{36-P輓h1mS!+lFW^E ]'r BQ\guۍ$&[P 6ؿ?+CW ~+fILia?(6!ߖX,@5^e٢+Բ /^dZ@>'F9\fAtQ `݀Mڐj]ĖCÃY">a_!@\c(tzJqp.5%|h}"|`W89'Kc)EՂ[l)< Y-uc>weqmTvqr&L!еt_MrC7e hDC*}iKpK,R^r,);=8}t IQȊ+ؗxpZ8F-ɽZ.ϳeYB8°4E@PNz_gA3SXpo7d]5jMOp:"a\RR]X M8pt7c#g+9W7eS_AA _ h"p!e33%/zn}2 ! Nc46&NC}]RB=vhʦUniD xR<1af+; P+kܮO,5@2k G^gJVN Bet#S}v7Ɠ8~ f"a{ȿ,J<IMu3Ik0kbbh 鍚b(9u~{*@/wmf\oJ=Y-3)9ξeNw}Ep2um@"fL WNR!$DuzR:?$G_^ y[cQq5H` +ܹtpBHu~*f9Uv* pkXH%lM A+Y_d;u\s{%g){`NW<#J E9&kuL"U0$Duь7kSo\2 Rl`")?JH5,` Awu7IJ]M0i{L*JhU LCPed<ISK}i~+@?wX؝ 8qԯaη*kxiU#*mD9A|5\Ų1QPAd>ys Q BVC}FD3Y_ ŋ4BTRĝվpa|e[ #ٻBF]Ԙ -NBrm2X\EP Jz:/\&[8Ȟr`Sξ,lzSQ.f>"c{I`\ؓp.鎈 NezT5x /幼݅E&Yyε\~7N1u~[=CIX{޸3kǯmo*܍@BRt}}ىo6%& xe=%BZ5vqxG2[],ܩd I%}NjʘܤS"ٓĩ#8`(^Ȥ#uqjr2`>ӻ;ő#+$I? ylIɆsXY#Kt<ɽAYRX"~ޛCg&8,;{:9(Zul:\4/=IҢcjj_}^ _,64/plF* KH+lD{`+v'%Alb `y2ݭ_͢nsoLQU#0n R+H wWCAmv#e˖gGۨi5{>&؄u 怩&=O|t t&d;ڀoxY[-OarP{I+tZJ#$ǡ{³lqCN9 6ah?uGH܋ 8 V c5K0Pۄcr&L+2Gn7EZ V{[[) ObxgIT?N L&NI[ŠB&%QD$pGSakB˔?$(_G<H)[]L1KZ}ૹq o@z)/ʼnTȡ  m(fLߝ"c'W @oZXҊ,v^Jetȃ'4^4EjH"|L:19NH7جe3tpӘs\Lqatfx3 t_=-]?LVUU~Dc?yy1=<' t"ysVa٢ON`{r>l(1/1,{2mdhZhv(67P:YV瓙+T/9Nf@7{-7's1mN05&]ˡ (XE?y0}<;F "У+6 bůȱ2v;.J#R*ͼ?\O%~I>tm=!w׿Qո>@ه^(WG9VK1MqsLgux ׆!ַ.Nů )_[U_T;dqGDa+w= G4+2Y9%a˲:tmB>F !m1Cv3x=a\ Aw)XrhJr,B%ae6|y*# | ;0X fYDK")&喳 |*10cpjPBK|DzEʧQs]/~o*(&y8XY, pHZ;X%+m 1Qڵ7-=u JMĶbmMChVt9_Ù ~-qaXk{ÔՒrfuFaU3*J?B?\C^?1bk42Ĉ;_ڍ1 Bn, &.׵/X ##۪D x?Xܖ .#Y>zְ'@Fds/!EdD>\n̞4f΃ah0c%J=Iƶ1[ t||YG㆛{J'S@?"D;ySdbEqؠpyuhz}U&Mq =8%>e ~UH\nFyȾPfH. mFxAdzg6A蛊['5>r˦MS@PԪLN<7֊9.$!᥍ hmK.7 /;hdVѾBev3QsV]u Kz>yUȾ y彉)px{wQVB$fkC.\υQ2l#6XdR rȇ)D 5*W[ 0 Mg1PWgl/$`_` `V:ђn3nJ'1w]u:A9ڄR(ԧHECE+eђX2^^jkEBxUȹj?H K`̐)Y@)!uyUjl&TEk%zR@6X1 | nrv1R]R- = E2d2P%Q(e(kߔ œؤvU(E> 6úIB!Lkm֙v֪B.4=5kڈ6TY~C0DWw$U}y!,]q%|¼bĆ3yynB5b+ 5-EgIsqurl /f8yo}J0wԌm)IWg(yY֎|e%-u,|*nC". -)ajaӉ(*VköCEIޑ׎N3'(*+WnDAoIq~P$~k@x.xp+۩Н|X.A6,|J[=}lj\v5K_Mg GD<]!T+Y\=Eد\^pۗуȆ74Ӗ4U!b/&,c{")f q4M?!_)}KjrH {B„3,ycE "N$=~ >A+@N3b:I{6% &0J#pC 8~zhcADsKƬ4"D'@@Nɒ. ˱uŪ) ']pĀ2ѽ}[6PDj%ⶵ== g16$U<:b@M+Ky! ܽdYmF9 AiQP]zrf{VxqYY z%Y o(A`a=Ñ}3{݆E#c'TB*Q.m_-Z8[tD"WLRV B/%JפHΖjo2LȪl)Ե;㸉W8m7r0/@ICU}`me;ߧd'ؓX5=B[ӑ6$䗨9gw٧֙YЕDfZc(q6&Jݣ_Ek*qI4n4KR@hB9Ȃ1~&ހ;0k\q98;Dx|&j$JHB;nOfcM ݋o{kTHqsOkr )L#ӪY`/+:7#s<Q9/55s \Gz8 }~-ZUR8g/L`š/ǒ_2>cz!І}I '!R_ H1%ґӋ>F>2!#ͻ.EEJ Q#35U]=x ln>>'#3ÈptU"?-USVQ>Pt_UB>II_*Yk($R X󞅇Nő6#[ƛ Ae _T hm|iуm æDo+^\@b;7˴$zHuOF6te,QvPّʪOM`l "k OHpnvWqcn.4^es@Tdw/iV/prlFMZM rvYSة`0'o)6p\6Դ6[62C.^{"8.0!X gb"_"D)$A3NfrLr"^K-kKxVA*Ŧ.q~8+:O!y@V)΋* Fócyb F}Dj-cNA mi ;'!)P IKqbcrƗ*71**lC{F@ng}q,cde)= IPГBRa+JI MiլTV-djkM0вbѨ@[bxltv)9$a3'ǷQdi}ds<%P!=8c }i6v-*=y##f }%J#k5k4xis ٵ!R<2W/*lAūŏh;< 76<ܗ !(x=q\ûpF0ԈcC5oXң e q Rg>[jڂǨH֟pa?%#Rb+RU}jF]M؅D͉+rIXn>Otɀ`"&'X)v L;fY_z@5 Lqt4R%6KURuZډfjQJ r$z]xڨ(01-ЫlPXx۲ PMV+~Jˡ.;ЮC3Z{M$(3FR[ܹ:I0/w3ߩi%yYa͍Ğ+nW1:P'A PHЯ7")k9tk5jx9 jE%Rۻ;PP(Bq$n:<J= Ʌ OJ5%c_UK.A~ :U#NSaF~lraD|(:zCwua-u]ʌuJ%i(>COSPN] ,Mi2Cϭ cIҍE~6N0B 1 LoqNbD3D+#cㄟ&5WootV>tT-*WAW ңr8X,I[C%XW$3d/B.Hx~"@pTp T]!;5_X(P.(Z+XJm& (,FTH%[T~yX x ԫ,+/릏I/B,ddRDLAo>a&+Bs.d-_Vo{irb{1}Nã gD\&ޙY{f3F֟كZ'x]Cc1dt.3Rly<܏l|;|hfEh{[-jh빙١&sܠONY+=kնiCqD63[WuCM[ܖdwC-BnL#=}7In댐˲,Z-rkǏFD, *1+Hoqm(s[o06LO|Z4ִį̴,^/ }Β',]V4TC8'H)k_w*@;ǝgL0\XN1]/f]Y%k7,a ~Oפ5շd^d64b"]4s }\c\&aq}q[sAXLGCt@;>~ xw܃?$Hrǣc3B# &.eQQī'bu"hS2>-q7^BuL^JH{I]vb4P_j-t%_uWk& &PfHDGb䥏f4Dz-VHO.s:vi#W޼T\D~u.;c{sl&cR%Tz ueL )r:so^sڄTiSu%I4Ҏ07<޹{ tB~SJ4۵3h ŋQiU.]켚ZgN8F o(C]8o0 O"{2Bji]/WAyR?NqM:8> 0)F]VX}XA V+C؃ J-WcAY ]T@zoy*]6okƳy'S$8˯MȇC\ a=<Ä]eB₮ kȼ6 !}umV +ahPgEsfю$ր_BgYy0 Qֺ۞V 3]^n;Q FbOP׃ȳƔ'y`۳G7Ocx3M"7N@m1U `E]muF `+ q?~ܶæ@dj؁n+ˍAt!C:OH#M}, 2n _{D;ziLe ^5/7ÃEl@ gE*g)n(s&/oUMnT D-{lIz5:~~|ɢ,rqT~cKI3>>#єc_޸bo/U_qzֲ^yiLX7&xo] qJ4")%m#͔9zI tn$-ݢi bҶndsTqTA,n" L q6tҧ4H2[Y!:b&"g}*JH=7QKY|)6/Ď¹qgEX $F䍚aQfCэx+Js0D#4NZ8•={Soms`00כ>@󅡒 y643W ɞGCJmg:9ޞ~(.l5)r柄ozLґ6K!6~c+(W80mSX e"+!PW&*J:(eސ%); W!zt6O,G ȞƄ9iS_V^$`Up[oWlwb҃&wObٜ2K̔_ll03W8xuwS*eWUT`ޣH&vEd_厇rjKBBq3*v>z"7g>ۓd4&W@ śEf`W\͒?)Ss E 姡C"id.ȉ_UOAtvlOoԤ?)$m'<!dV-'F /'Xmf(]V ):3 ɛ6)qM*ǓQ,JT v͞J@edjFW %XaR> ?kf^4īG{%'EGbnn=d$$<,B(Z=Ԋlџ,\Ỿ*^ O z;oGol^ltеH '[Hhl7{s٥{Uj 0mu@j\ lv$#"ڢdӟ,d]7@a_O]̃(ʿ'9=P[;i,ѿ*V˺30Ms3@n}+X]XC,%0!`q{ϷNӳy11Z@lZX+[ӡB~A$6.N*ph\8g.p>$|=QBEU[܉o/`|#b"@촲][lJ"tp g3T+. 5hl Xo{GUT8tɾF !mzVAD2x * [HuGdɽEsxbucz=LVE**925$Ԩ1tWRlSC> ?{_O 7 bO6r= |l,U uqJ['#4Y"WBPN=.,$OV3OH^\h =lR'J138M-"R{ 8bdSqyMgˠlLŝaSZ00~s%!-ga8c1U(?rj\#xxM7uW  HXrrG|ȮY,ȊAǨ #xdY0=O8*/*dע>-HO=(T&?`o6oWp5 mxivO>'c/`Mg՗2ՓZn7]}%ٙG 5xrBmDZe بLZ|pB)@9$ΞɄw+A ,B \^FM 8C~=&O\Wpa ?cgZP|}\\YP*= DނE+)oPSOaj8we@&eLfYD1 ޢGz!gY' 3W2vt T;{+acϮZ.L)t6Jm2ϟiFh Xp|4 $xI0 @/@E)HW zj]zZV_o.{i:@l.گkQ^Bf3Rg 9CpPۼpY5pJQ;4$tYBpTjþ$hk 9)DfEAV򸽌ΦYl`"86_ljAkc&H`8gGN6: DdPos˜5d;$aAĹk;)7εs,1&{L> PzmW;/u,zhʕrF&+yi7֧s/k”z"/E#L]L z^EM(Л@V坻̉dp2cɎr~gLiT8P/0`'xqL^ń_}Sr7cȪZU j%Pdƣ&2΍9Ї@)Y$ZJ?З(n9 iEy>'Mܫ^A$:+9b.56H  DZ$D\- 6TH:/47}}<镵M5O3KBA:`x5<_hq-bF4EaS4# c*^xCoQoq%27N Xs54g6Wsf#T8 G\nN``vfeYGs?#uFK ۔'ogvidVeESx;m({6lfm:ߜ '>\:QUZa|qm~f@GNf[^DPJ,KmUaCrPG)K@3_C@7mZRTu?MCm9Z°0pFb8$irvfH= zw+WUCɷ-G3iyp#~1j'Ui4 B&:"ؤ#K6zdC_>}A= d/_|XtKcsR`a>~p>+ aa$iaZnY*jf~f][a$^α!Ӆ] F 7`QZ7jYG KJFpy.72{ۃ=097xh/J+=>zȅ`9dCr{ m}$%(ܢ\^4M+gλlIkFMrGhM #fwaj7vA\93* ]oUV҆ ZGJX~ ɡwmEFIIEYh[-&i Gi]CjF oKⰌtiUfȢFߦVĢfr/Ʊ\l @`ثvg5$n) -ޮ *c,7UuȁlsDNDV͈rEDG]ʼFKjƟjoEbD: Z>ʌ Nr]Xi&0Ċ;yT]o~c?1$fHt)cw9SPv [\߹ӯݻ|VI\VA6Ph0*1HIgjKE֮]ĺNSuPpm6sJ?^,sDXJMQyr}/bWb[\*/G0tE* e܈ZyE9mhM[El!/hR/X'h5%#>{MǷ^Hef 4 |b<ikשHf{b>iҭlٲl1,A JQӚ$*鋯܉٫B\PΠO'iI}' `mQ07Ut6ˎjP^R'[R݄ݮI;/hOΩPSYRS md\_ϗp&nTAU9W_+ i=W-jؠ+‘|#'8[f-ܟ`Z JWaU[=*Gȥ5}HŽ|AI?:ܱ>?!R蠅3c`JWy"n:y+FncG#X,΂ԥm?QCq+c3M%< D-%E:u>CrgVXMbKk 29%Wdl؊6mY##q)댾=#qAE(Z ;kѿrZ>rvlSճkm*5.:eT۵% _N~뻀~n( d?2y'S- `\21]F~մoQ2QɯPq,E>Xbt%~l$;Dz_<ĝqUlֈ@gz ͭQ˚`)! MwClA QNq㸱MUT%Z[GI6g ur'N/DMKd6?P*s;$X5j@luhx Hx"rv--/UX=UYT΃P~rQicنva8E`8ݭPhv'KRZ:Lg3(a Wu_M)[kYBϦ]~nl;m4oF at*ڼbhB}|%m8sm9I ɞA$wFW#N=}C)be޵<ZJ* T5p})'k,1 gLQy7UϬHPbt_hxvnYؠZ-C8҈^bÆ^ $:YHj bh/_amHhTIk἟axs@J{VG6{k6L~.!vOBy`:Ck9g/wxF$pM pFX7f྄pK= pDxS\Ϥ|xo} ^`z'(`yu*Ov[gFUSWu= `-Ba9f] m}z'cU=!Zxo4H4F\Tc +Ttη64.㴏:[ZJ0ZHFq̌Mۯ+-&+dԋjGA!Wkb$BsyY]ix,[&C2cKW%m#qxTv.sm h5)2PqKej en(q<^T3R*pڬ+3FO\Ny}`iE WDkz&5uTặ>` oXZ2P[E0jlPEOk>RFRqкWΖekvן#7gN `딜q1RX<{mhRo<m&PZKyt%r;!;yI!~dmÕ-Dx|Bp ]H0_&PE0Oƪz`z C}t |g@ã8i](%O^Ƃ;Hg # uo^ӿ6&PmRgUvZPV(Pde/?>JeTJHN-+-V7:&x1yF&c[0Rs:Oe;Gd[y}]h#sBwh GՖ֩0?%sl4O Vs\lDe# 'H[paE nDc5+kN o?OdWoص+.oJ AZq"c'% m+.24zAJjP~DU~N-^v4ǽ06Fۼ`%^m?yTrN^󥻧|&<| +(lh1n@7+m@2ccp$4l q q7b׊D!~{^U-ұ$"^0%){"}XŹ'z "RMòEa6#{n\$u*+UčG3vAS9&y}qT)5?X^`FnB^m) c:j#7G 3w<\r_W? $XmVUf)%YK?kz9WN&[0k38r 9울MJ.H4vRwLvz`Q9;Y5],k@ܸw40b>X'laT(ַrݾ&T'l ѐ[3]k;ެ I(n 2GA̎b+f'g0{BZwWՈّixۘdZ 'GGQD$*--X3+"˳۴how`LC ۓ$zn 2?Y9J?6ڇ_YN# x, 'ѴN@J(ab 7/K_8BnW9`o6@k~OQCoցVD| w>E΢l MC?,iQ2#d:,( G"X;/fF}:{7 `w뼔LۄBDVv^m~y0:).!IZZCYՅ0!8lcXOO_/nk8WךUFm(_u\R6/f$nuC'$lu*Pg6}Ԡ=̥ɭ H^, 0ds^Y0ڥ6bBaÛ HPAMi 6} r42w-}IH]_y=d+WczO&.MV 5zym힎q{9#Z~3,- =% ycDcgo>.Њ5Y䡰o{&BH\$`S) D Jt}D.&En_] Z,ȕ48u/TTzzM_´˺u=|@&אiCXMo_\k &lo}8ˤ- yh#0$"Ĉ*S=R{gk(ll# T9]_ː|Wh$M0l 9ʼn9Cԣ{=ko}#mM<=*6N7_.t8e[LhO+Ij3!F$FJBj'NYE䴐@*7]#a!iLΐo=jyͺV@\3YX3k(IS0fyh4i?љX^/c%:.]K830?/u\(L! ~{sZZ $=8SLD.nTdGg :x| EBeڞ˾c:)W 7MǹkBz4FVjҔ,|xWCwL*dbzaIiŚGf_G"@E5AM ׄAKA] T=)+qyZw4qf QL Z@ @\ղќ5W`*Xm8KlS==wq}p"#~9ģE5K,=Ԯr6X[ p`B=,ݦSҺT& >=weI{"?ҮUkD6pNiն.w!/Wz0 skiGiz̯ōؤ(*'=ķɼѡʜsj{2s[lRs9"]d3MKD81 aQ0Nݧ`omߑ{VIrh!JNfsET~}د+N$3{sŵ ͣV:yZ ~-`/Moַ/{k]kg15<'a#WVX6b94>QKd"i!Ց/JxW6z]"m.~GD&(h\{JA4NB@)vgVTx6i/:QaA T(rśôG\2EZvvUv@>͗r5zy?h| (coq^dw˴0QyJ#EL28*r2`7u* hqn|h.&SZeg2NxNh #^v~ZU.\ Ev >WCPTmMӍ>ژ/Xfz mXpaaax^EXQ9'ƾFph?#g7S 2Ȑ‘i(iZʩ]xb]ud8@z<ƽ@Sf#]؃=#X1okc~^ q9٨t7/YxPs0 rIE N~Elh58ZA1m?Li-#8 i.4rN-' mur@4I[HVy֤_Hi+Gx@Ej DJ2].i_P~A04 V "Tl m`2fm|$ƫ}F('1 3OTiu9>-s k`iϾz0 x c48zE4W :c1~=xO$ .2 mkQ. 77F |3גk,K}PQ۶yԯ5ek)n&Uy9 fZ bb2Zp??=rsc>Q|0}@gup9 Tu°ٯ ;b$lĉyFXV?OK(1&;ʀ溴6E!h\9JaAHz #?- L?;ċu SoJ'NV.Yn +aŷ>uOC@,8=u}l?}:.ٓ<"oC~حrؤ9CI52g&zqy;.AN=)z` jY(Q+4*Y\ fVI3ygg?o`LBcƆA?Xͳ!7z j}t^# 1mYlhJzO65#9_DI zd%y$!p| <} 5ýk FA6D$>1$\q> QvD3 B7!5#Z??t(l kqR4s+sbNb5Be$sfhx& A=PC` ;t= ]oa1wvaeW%R 1,іWfI}uT?EmhH+p3XE$#~H~v8i+a(?S6=M=h2O5@EײN4ls 9мm>G.M\xLc$|وe^v"bv|h%msnʣA?9w=1qHT 8l|PDǂ %K.IkqSǕ),/5O=qRCK0i,FKq:pOnؔC=,SުbR*%))SNȞY&jmOyzj'ͭISgmBAjm0`#^{tzg0@Ax;Ω,#u`IY5*!;~~uV/s+SGhKa1='l, P`\7XH k-5_ls$ސj[Wۣ~uxRu&v Xb`$*R2Jz?)o w'>\wesglޕ9ꬁK'}B .ddc~4E3UO`ozBG!lzt Hg .[)]1h@˧Xa$cy"mlNuduFɀ>^͸Dۼ7V|i./MBx}-%!Ku}؎Mʨ 3&oJc| {G=P FHx/'uEI mcpԽ"k wiX\Ż%+?2W%B+i ˏ~ ֬H/#_/N4* 7dG~E{=./$O!Q>FkpO@mRWfԁfž?jz1FC`ĴA+v&< G;ñ3W4%wsL*͟WqzJۺUaLd/UTfc"TX\v;q0V BI=GݖB9DoDH8n7|yj &S[kR]1p|,Qvw-2i]rObs0tWeIƣ-_s8Y99q^{\`,"  $,nt4J%,}9lssX)ʄ>mTueWʼni Ҥ X9 jh Z/oW% T#*5|LNii6[ xi (B4Lıf(h5Wcp7!ƻ} OH:jkR~e:7A;CP,ѭ4\?1Aj{5u K'hmX8kЭ$P2cWJQь/񔩚Yoafm?oصIh 1yMjtP é;+4u}gɱ &-p4$ +{Cf \Aư\ < !#Dj~`8/>j# mNZMy|` tHٗ..y i4+._S6*;n@Pq3)e#\B9p %{$ UcD tY)`\4n\ , ;]xFFTݒ|Ѩ$[${|i%. wN^4~"sy{8<Ъ?*Q Iiđf,H] di5滚]3M-$|pp FJ鱸(Y":5s1qr$:N~w/T{q>TGFƎ+kУ+^>|ȝ E@D# СDpE+T Ջ; PK%nB|K&[^(zGf[sB֞rN2yܒlIHa$)^ddıYg!)8y%s8U+7+Z[/b8Y$PNznu\&J4 k@njHQz{wϒ(-q#h};5zk _AI1-9V'!%aRlZY!D#q3J; TA05ܯ\V#W[GK7\E%v* 4[񼪵|u@T%^@f[C3C@#9K0A3FWJ]6HO*NֲLb{#g5gZ!ks/#3䦂Ri-xXwM\6-BKsy ?1ukTI}yL«'HSq>=ckNgM> Cm<2Yh=zGKJVU+<Iǎ6L9E_:sZE)xū;6)Q"`c80k?r;H gyW^o ,.*^?Em+yOHO7׌%#U <[i=C_*r'P@ao.v3uhVDiay=Mۆ8\Y@b q"@| ev]NƕI%4w3ծ~sx{ ;5v֫奺 mE*|k`%%F)C.MԽD4}>|#Y{2p23%.M2d1Δk9V،'l9mko#e}sDF w,S7Zj Y[%J Mńr<zk~GA!  >GHa[%'O WD܍@ύţZr=%7j+6<DB=*ԩQK-!bFB>CcU+oF~I-EYi ?7Hjb-#Rm]ADȨgM-fG&͑{Ģ0puiUS(| F-ϛݾ'vy+:!nacŒNuDtF]CN1f$yQXϣ[̆;*C_aZβ=f9 R݄0jl$VPB%nԂ0x+S?ҵq/6:^PS_drRmD:K4/10cl4[8"iwͪ"L •妤"kÓFFav# om:1"xYBDwՔË0]&8ûIi>aR C%#ZQ2Ծhces %)5\~JOkRc^[}_bfRn>wl.M_Q]^2ڔAcp08<훦)aƗdF sg|<]Tgm:d ۣ)@[ % Is^N;&6YJ39 ^KuuR ,^GC2f$;ݼ|UU@]G !k "hjnzi߾ tPN( Zߤ%ۃ9vw CLF-;8FjCH +^/P=깟x  D._f[a?ph5,9%(\Sh}'f0o,Z~{߂Z{!f; EѹvQQ b"/U-ov*9!.<2>aj9"]*(JBnj&"N [fʗ h@s;=T$F4# f϶k Ғ/Iq 郕6ZCDL#C$WS|9t7[q b@x S(υ⻮wX\$DK cP]?oZ{ig̻h04Z4`b@6n3qQ:bĿfuM<}Ti3iT|c7Yz-|&g@WThW~Vy8x! X(e?8'5L1AR4./2}413л ) [98W9|t]U_.SXId(4$:UӑeU2hBo[&BI!Gq`2iɨP}3Rhʜ)71o0B ӧ(Xb3XYch v4D+cdr|hQruz)>wf{q1Lhzo.Z熕Y!.&ll[• tc9q^vhorO eZ7Ly-mCCޫ%o#"$N fȄ(b-GhSקǝY0>43neA/ҊgʜOlCH; a.-."šQAΌ ,N90+˵<'|vlɧ̭l0'RWrܺuIR7 8 A^g Vd4NJyh5~|͠qpj`="ӊ1FNo7ǰrOfDW쀹(>xy=\o2iCԵT4ac./ЊWA=e-@ /_"OV '{?1B0/t"jIu%D2!̙(ޖ*fėld6eq g_'ɸ( zm#28UslN ?'TBjZޭ`^?wFM6,lq׬JQhlT8ᄞpOƎx{%ί-P=>tS3zu(Aj[%hW"Q*|H@d޾}_E#ѾH' pӊ 6DDqc0?*s`\#|i et2 VrȈcЪ>]m{LF=߽{]F=E5 jUOra >^xKϜT"1|/fD|pb+G}EI4ί,JxW8~0xD9ex ^E z,+2zigoޔc \ bkٷ,˾YbOLድL>'ge} ,%Lf-~dP&dʶ .L Y ml}䬡w'nKJA Ҧqi>C9[XϤ!e3څI*S˟Jh+͇llp|U/@G&pg8#nd/INiŻL#y6*2J孱| 8!үKT qlql > u`M}s=G@؎\ {_-i~+o@bzyPKϱ@p~H,.{8Ho+Y,R7T^X>/@ G8ꢭcxꊯsZx! [3kiw!83oG?r]y[]81ruFK +N)'Q#;)!ƾ_m_⬞0+s7+5Joȝ S9 Ͼ尣rjsapaB5:r.:d}x-箶ɡ$DH]H1ma&Pb Yԋ}DO q|ktbZr |hHKFL]\w0P>Q~13s%R 9RZJЅ],9 *W tə0e<5.;@d 1`aqC!8|ê\y la5jrZ\xIP2֟GmHW s% Y1B@MhυO-BhGPaNź1@ ZҴ^)7^>%d0e I!o F*7Y/Yuɤx'}9+3&TQlQ'W0ow/f`jc8ߺ#ʓ-j(<Ć&bGDyioeW7vGR۠7 )!dK[ZuE6J&Ē} $a}v`u|m,#^Hrv4n5= (R{o[nң D6@FѺX(xzSD5,vڦ*3l3WVkiՌ&xܙU~t63N=[$PNjjF\.I;l pNxs#9 xJDus۶D<]j۱́󚦉YXjWX6"]Bmo7oJD!_&+?EgA4JnLDYd685J\g$B‚?uX |(F*Jy3'WY,C60.V_=asf,}':|^ώdp}Y8G8j^2FB׍#C!Kl凵FG Q}xl`dmO&D$CL8Ʈ{` b:-DWQmxsvA=?i#'D8O7RoʹЯ_Mηھ%"5mCp"@VEhO꟩ͥ} oE B{Z@`^7:]  -a_8Q\ :ZF#}[s(sVA[yrPZE)sMKoNkei< *CqOk,H}ў UClCVqa#|'ku^,C8Wۙ9t ͢Kc-} ,\[NOly@Bk[0rQy&P#cCϒ3S >.#t4"&\-en?ХiUVv e+kYK{;DD+:=hKոx]r^Beo!Rݚ>{c^(ĐX.$V=ȎXcV64W:Ǣep4F:1| SKg‰|QO*BQm$:9M.{*S}gk64-F~=Xt9 /!yؽͭJ`xLǠ!*Akjݩ^ :@>o}0n_xH GNWG< ]9|M0ߩ3HXKOn|وSuzЩO6h{g$+\ Qu%[IpލN[yږp gGIƢ1OZR'<^ݕT\s%Ϣ~Sɞ)FuR$?0zIw;>*AwZ7B@TCN}kEuΙT7ܶFF=q>N0H]u&Vϼm8MWl<UCTNf/0biHU^B/f8ȕU ` 2Cj0R@;z^Nw&yQ0}(Zͬ ydT Ky˅X>OZA$4mgͤBy=}|:E[WAl0Vg~-{UFxA{ ('E>+[k<.ט fV^G a3?S?+P.O BN~ciA1DMP#mCIQ$m&zb@ROpE^ (\t鐹~@'V\Eӡ:*}㜎UUo،rᚚ_YWC|Z)O/)qamu~sސg=SeT=PZ 'pg̊gMVNE|$JaS+a]!ܑbjf^ G)uو1-[bcĝ:"$->s/ư9!mZ޽Z!`f&Id-b$Ršg /)Ly]:+{]VԜϣ?m-* [2E B21`Z.*- w/~=A-"4n/~\e"rFc+Je@Qq11st-^(,]=P*9ϹIJzG=;- 7ӅRwW3Tͅ|3tޘS Okz[4HeI2 镫eq<"8h_ƔE/:72"G꩷X|ЭX, 0"b>CkgDBWsAgOۮ[`ULm.`ˠݕa $&JS/b>PO{R"f=SKAլFvkQ֕ N"3H{ Y Êe 0ѥq O"f*r;m€>1_!^S}Tͥ}$nU]=T-cRo?FoMoѪ-n;*6*Kv1o d ,xՂk#Z C[hW_ud g6ixw;ܙ2n'Ö6 ]Nޕ\ʘ"W@n75ncgg^RkM :${ Nb $Mٵ4#LL kX` D|E; QC=ɸ KdVx4>Bpl8Ѻ~|paӞe{G"!Hm~`&E,HnsaL\Zh.f`7;61-&*odzg )\oPyre%UAm*p޹TR=OCƊH@킦%ъ"Hm_t3?3F"ݩC:;PcpRq1uI"俒能 60/ݔjHl:SxވFǵ@`QuQ @70^8 QCÌ yȕ|W c2m, jI[P)W'QiӲUy'qۦR,-՞^TblDqh=薸iKY8ar49,BZp)h MSpEdKFJ5)DY$תDRBUx-9z,Nѯ "v@&:I͕FkA#{EVl[GSmnjmu2j1t}U:˨kqD{XɇGH=20;+Y/>˒w:g9Lѡ_/Xjk2K]mGGX_Q_2YNtꎃ]b͠С)߮'Ε;L~՛I ?ritٴ+)ʁF@zx8{"Ld& EEu^2"G5 Nl,烗5bMZ71΄w.1V,b%lX ,p #K[yXia0iO%!^"bd _DSIp![Kh"|˻NIj_dZ(l_`h0ǽwE+LTs,A=vBͷY3ȟVlj2Y64(',|X%7Y4JK$|f Kwg&'~|7S-e5u \>j` Im%3*$^oB\@j SH;r-Ox-,Y0X N/8ux(f-/p: nN4yݙ D_{u {"T9,-wJWAleSf1GNSYcd;< /A;mK֡"{'LT%Hh-K>{ag@*6ܨ܏kiXvV`]l tSuoO,8On=$HB$efTw<-}m =1haDjvu.S4?Txs,"2c\ǛIϖ_m0q' e찋 V뱢[ڵ$e-ß)/!_ǟ.H!O ]4ĭJŒ^͎JRg2綌11Fz~Y j)`xtqa5$ 9ʶie[JmIeV (IwrWcD:5%q 񉆒M~tGޔQ.At_`V[EՊ]zKK& 2砶HR=ebTzWWr!ODg8t؄^瓀ǶYhQ"ʴ 1/ivo^1PiE=]#lX%I̮,ЍW85Z%n} `2_W~ tC翤'n` F ^Rw5i5 'm2Ŭߙ3hGn`ĀTs"vsP@YXU gK7~-`YN$A#WF<['6Q|'\M!rPa_V  }۬_,FMSpL~7hCP3n$p͙cqMWJ!Ψ-h|yy}/i- KWև04-/'ZP#s>Lu/v3LV8o^_.ӆjʼnk!w\_~9 ϼ<'m8K++Ҟ/C`ȥȖp#{ dB1ښSm"J(2Iej2]5AY $VϧȪAʖ1D @1nJQ]yv%BK6oTvGlCJn= «$aC8/CV(d)g,q-W`pWL27i4CF@}-G m"3Pp,=m s $TeH3Fs$`^<%%Hhׇs;OD+̝W$ ?{mf@9/\xx$̓&;mLl%Q$l$ \So'8*. ;!ฤr4`rAY:)wRF룠;c1htՁA+L;/d6 Y;p$0s(pȕV5dvy؞Cq|l׌!$"ijZCwPP+, 2_sa5LjOq'fQ0ʲ{ns_ArZ{ߧ+ v,G @‹hQ!$%BݟO1cyR*KN)8Bێ%~As oo,~b=@W{ &QY*vR6xU1G;cD5CdKHeu ݀y7 m2 Ե3a4dښksLT3"mp* c48 W*]mYZ?Ml5Ґ-9d$Z>nTDD7n+|%]>nҳ.?ܪa\ir5v TˌZ_n /uj>n`+adIX+RtгJj-6Ng=Qm~?/tS) Jʌ/1Y7 +b\g// jAM2.=;k6:I@ W[";gf-&cuO!B7'xzyaU?#ߖV.5I[As|{J ,z?Z::vPД|S܀g\6K)1zZA+gT>O;"G!Ip=A{OL ,nEYLǣ gxaSRvF1읽G? ` yoՃ܇EM#OИ9g䄚ki@N^Xg#tzunQ-cLs*'X^Ym< -SI*iE{zTQv !Jm`tp~,t"^mX8Y=Q#˹ӷh rFԔh/{\C?\KqRafc6AgH?Q*9?)a?g>91Z"ʸs5&`xmgQ<{].g{kWκ6?~}t't!&/le"/<5Qh7жv)W"V jq'S^y?nv l*PELڛIۼqޝGG/|PjlLt*tK$90|Z;>7-ߦ|AJ"$a{v^ɡ+m6Ime%TxmX8<X.)~w$ZeoF͓px}^E@{L4"BS{g1bW%g>-MgqiwQk.XwM _kltЂUM(\k8+r*9ImM-;#gM82^!T\@4hg5Dbޑ!GJT-xmOSaC\hFi 7Ec>z^Zv`WMm7;shofetAČZ:%אJG_mJ&gV aɁeV]ͨ[Ŀ˱xZC%{NL7_*H~sg!Y}jmw8Jg ,[eKfY5.;YB9(򭅵}.4wPEJ?ѭ^cy~~`$`/gPIZ_ )6()T\Bn$&QH|Tw:4嵱aZ P^|)KFx JciE+AoqcЇV1CW3BEԱDz`s $EQp{R w_c87mjM3x7eM8&3̻dzŎp~bZ:{e1A dCVĉxaؾ;v0@7p~>ƝV}GA]"w`bCB!e~7J$fu;(Z^ݷ;ޓRi wwx[yVs@QVXIeu ~qX5TbTtʧNlawm\/cj 3cDi~*a٣5;E f6DY"~d[noe|"<_rD&-; ƯWf |"Dwơl cn Y>><6GbLB)sny6评d323n4U SՄ@!g؜42Ƞ:,o}LbA++/[q}YQWzTnrsbC+NPvJ c.\ѣT׆~=jZ7[Eۥ-eR{v#:'HlPPkUUi#>rJNBʰfgPMfjIFJCڪ(q+.4y3)͘oѧ`$I.huEBTbkz~]N#[g6?VP@TJ8R1^{44xb<|a-ڐס i=ny^nݔ)+yDPܾ)پm &jཧY/^u,Q8Ϟb}*#=_fgDjx`K`6 l?zHC*+jv-.!$<'xK"1gYk k_` i! F5`lw&s-_ɽQ5> l p OQ H [;ղ@UշM=v Nm{֖O.N~ElA̽ao!EU5LdԸ0 d]=9s*=]Ϩ̰[YټQb-E)@Q ]47sC;mxcǒqIyb/J!nh\ F`;{w\8y>zm_nvbb-/s6HRF!;A4M^_O] y=!Cq`a)xB0 uclZ=F? =0f #*:IO\PN VtJ522˩aZۮ{}Q~IGb@A_iK)--0hX M)NlEF!ܶ/__=,)=}iE>Dy,]vz<۫D`+͌$0Iw=`.,XobM5IJ+tnGtOU&GEԟ  MZUCz[G0+ {xt&蝮a;&m[mnxc`56{ge h{gFWCUYvysCʕy,5OJ| PO~=hiI kZL_=Ne@傥 ?'Q3,svb7ߒT= (d? Jv RȮNuv,vUud:9jem)<Ђ,!r׏7`^4X«1>iL6hE%Q{BBH8A̫ //v/Jm/v}UWc24?v$S1Γ# <& o-|.i;24^=*K3NAs}. j]N0w ӸH?eePNdYWV ՘=1OL%0aG;4EO qJ_Z̀e1rzr\YUn1 6_+^L7D/ ISVk4htL Up_\ܶ']CtHXH!.߲ !,'8&?SCΪVCé>YOZZPu2Bkb& BANfN>Nbxj/4,!euS#KZz۪bj-_u21iosșS?uGAg>`G-5k-2GH+d&7VT"0)<Q qje1'[mكL{V o)ËX>*s!zefnO 7%N&u}"]3Jl~ź<;1q[B7viy6s/D{30:4 _ ʯH?yΛ'w#>c)nMNK1]pHŌ -kbIDgЦD.Tᐾ}ӋqFOuv1v.(zd/WgjDWh[{M ™@X?>MyR7EB=O0m5?-r3= YSJEhơ0ޱk7.2+a/t l3_!&z7mNq]M[Q478Ɠ^eOq`$1Xs|wSw{E1rgZLw:b|f:Љ=nZKZRx#u'}tWض[cp2j&dؼ;R{)j9r7hQqEБ]-@m]Ot7ն u%2$w3Lއ[O/[E6~TNJ+ D"b]2@1 E)ōK9x=hZNK>M] 3 Ҟ2b}f6DV4 b_ۄz'_N'I񎆻)iVM谂, םjC,r6w W?xrH`; MG!࠾v]Z)4eemO|kA>7~:\Y`gk/`űTDlt܎2Sƶױ>\c{15^uIiQ3NUpG^uvpd }].Un_J'crѧ5 0w1GVЩsk-*wy}Mͽm-=6@pV6u߬-ZCNf^eAe>앾3Dz9je\fBgW͌>ЋvLyOU܉ DjV}|+tmT,_&z] UL/+hË7pS .Bwj~D]'Ss+d@(/O̎IKj/$'І|KMh s[ Ul@h] T&xJ:s0:C,| ig!IuA[f+Li:j&nj#$HEa\RFl{ZEJԵ!WlF=P3~EďZ41&N|͒\C74PBԁW1>3X@ϪMh~6qXB¥!d*{F}]>MX%-fVBZ=Ӳ$5k3!m TW KaL3$iPOú´A"=ܸAFU502/rix} r?,l"*yؼ!\-suޫimVZ+pI q "}l9<%[ jH7E>"]i oe)-tlprP4a bt44>\»CК`Yym i(a?~ ?T⅀ȸ!Q[D;XnJ_2#eKCl|)YI/$@џB܎RJ/@th Ķ@ޟiǴKP,T% YϏ;!ۻͅ5~VČ` @NIB}:L)ܷb?hʻF,ldazmPCW8Qm’K?\n{R3:j!;%wWI.H^3ү"|FQ6Lce iUn1kܩPrZFr}L<+tWvUe\'MK+Xb4@L_pI2]n8/"N;fܹq)[XߋN]LB"?FXem=zs[8*|-Oz> ߖԦtI0,6J:7җ ćRW&C<@8, 5kof8;p8=OCK|p3a.4YMAݧW>F)ds7:rf- iPJjO7ɿ@"6j禺,A"5=z +APoOG:*qܛJ@O_dЂI@gj?FYQo{FjLyu4XxBNH@F]˶oQeۿT'\vN!T,uumГciK~ p)9zGu+oSb\pA˒ݿM}CZ>p >CbzkH hUfHhh,^&(ϝ3lkhC67G(:oUXo%ΡYmV>ȐQ}vc⩶+za`Uު<Ԩ?ML ,V߬'+-',@la,p|B~1^Cku5h[@ qI賚ϗgzGT\;YD%$(s2tԍjgFbÜɰ͓0MrI?}=P]@:X7؟$"tPl~\*ruv kTwpmcR"9?T1{Nli9]JJg/̃pZmԭnjY^o}[9#a@8Awᇂ%(7HLh&dZzmFU ?)I0Z fB>LTrn(u}+nR=S[܃wh%$Ǥxk.I?,"-J0;'cäoF9_\S^ɹݕ ']{AcD>g!g`b-1;dYn\,os R TxDze3HRonJe9!u5~ l0 5֖8oLQrQhRˑ@"<95gAQ< lQdWו ;a^z߻k涩~\ǘ-/Q%-:;Y#@Oym3 ^9Ÿ䙗072*YƐN=9x>@{YR#EZ")ؘ$ ]e qQE-,>p%mv?qaJA8~h1W1oŲ ΢D/IID*)1A## T U[m1ϣ/h}ʽ]O5M#&f`m N&,˰#~Կy1?˰5")@ZWH fs@77UVsL5LV9~7E>! o!*e@@sl;<`M'#Dq4"Ad7<) u0 M|,ŝ濆yÕ;M_Pt;@b;sbxS[>0Ɏ^}tl,,KH >39eERR(T1D{z^gi-GŽ]qC/WPLc{c{,Ҁ@3sʼnshFFDkUDX\5$Pi0mSDt  d5<zPVb + I aWԏrzA$:-Վ$i ,az" 4@|-i)̷""CAn`ҽ. 궜D%ǂ_Ud/C]p2&R솫yE&\Al \ԇz~ H'– Odh.CUci,fE|TZ7"ar 7?H1p*W8䀩n"%9'^Zr5fobб"`MdSdP%3B5rko3Vn[.o"_ZDY=q1R 1ƥFUN!⌸x[VD=m!08r2wпӿ# 9SND6ha΁=Syks ^mFdS:@;!uΌ6E:4`mU_kjcvkˆL qcIÞy`Hagr8G_@sJ$^SS>eʄ ôx-2CՖ]{3SLJf?ֹ]TXU/*Rv#V:I>K$*"AvŦD|-H$E3 jZRuK-9[k4abB/E ft,%V[9;9]χ$)R_D”N-~`g98\)paIF2yl"7P oE= ?j\v$_沽&q}tJb@bhe5Q J.ø@}G :B1D#5 RO?߁J(5!H5K{+M"RށW&}&虽(\J#4Z&˻L,DOȎ3Plu;UBB8NK/:. 47I},FJǝMRR3}-%.PpI텶\-yйpsPKt[ dN׻:- <=uy gPD; c##0֣# ?>Z!Vϕ쩧l|Pwׅ,mtKi⛌&!A,WT'^ *‹e[wET\K4v`vI"_-!b;\Xeewې࿷vtޅ qjR /[/!dr)/Tu9˓vc?,ۋ ^1Y9jSA+6ecOd(~}aL'&VU5TgMBb^>ܸI'xǓg%y [tqg;$8$F`fzLbu0ghb>wlRq5Ygi-P^D8azbY%;d̄YiAElQ7bm.!پP4u@JixR$|ng_ML3CƒgӸKc݀Gf(c 󒬽{4b Hb}4{&>~f|z[}3M{QR} Z]֞9\n0~Y2; ]ńA{eP .x{ajsdM-C6oM$yiCbu N!.,á}HmɫR$Xs2ZKo!}kƤ]^]@PG6>1N$mخ G< ZےimJMoe𳙙I}bCW G=L^wi7YVJ~%_(84;3pS:(G{̋$cmQd_5F8%N ߰捱dw6(}{lu9laAkġ'8jNs$EUt5z@RO)E9F3ִ˯ގv+49Of_vFaԶE0ͥh_A,JyVe+0ltI%5p;~+wGd#kC(HΖ laU]!<pU>S+ :h$O߷z w:?^ 'XB&)=#q哃'rs(_5>5Z ?͠THnd1鄰PGq0t.ϳcֈ |,G\r&#js?X!п߮:ftJ:NLa Gؙ/ISͰRР}W'wqFuߍ[2x^ U4A&70D!BN\ZgUu珐gORv^Nح<g*`;e;4+,A_Z.~*ވ]xB !!5כo FYL-0%7ԖkznJ}MQk}ARS#NA2kAk,uk˒E,w]CXDr uũ=hv=>zxg`r?\XGV$0Mu4?TٝEpӌp:y|o>Cp+ 9;GyX3n~H!%^4K8p*!1&!A'BJ99_+=7<8oТLG,_-4y#vmdͫZj"g84?^_ |q|Y妠%vAG(*`zALsOKHn32VSU1Q ƫ0ڴo;1 ;M.rj_8kȧ^yِlgݯR(=u= XNx$ls$h['`Xc:}ئpɨV0G'3j߱5)($wC: s=[ZrɁ2HKĄ~p|:o- Efٽ"ZnT [>7ĝ@. Ójd|U&}8XJ{轞 ǩ̼9TZh1S*cAK~k}&O&ΥyuE?[ɱDJcԳn <G,J20ZK^_ ,[bnxPU?,3GcKSN?hqq\=J:883F}]Rr˺s3 \=! wq~2Gʸ~)kµGFvd ͘ŰۧKt3| Jh *aMfyme;Fݜk`xq`0 `M*mk@:eu׭tQ/- Ҙ5h*s섚PÅkV5h|iqILk9yc0QjxqxV}/LaoUP14NIT[n*Չ2 1gM+$@# s`mZu˛@NCЫ쒺vH5wOwyɚK2y!q˭Y8/x`$#;UDb#n)-YtzhwTPo*` ,IlHdDv"JԷ7Ndx^/\2؋R wGmJh$+SʜG]1HȲx}`Ow]hze1.3QH #M<~t|O`iC@͘Z} 3>s#]U$$O´'wү`4i0<}uHE)цb)i>ģUcws*iaٚ\ܽ꛲R;:%Y+?ڡ'E/KvJkL|n nk2H_OBZru؈jtj jнKBš}O:c{B L /(WF͙ /ˠvHJ8_ T0-W;|&yیCh;ox;؏*Da,h*42'SMһ,:a̳BI.o_f% S"=Hiiz;^Cm/^K>MǪq/1 BEt!3ocli4X"١6SiGQ&ӓO,t0sҕǠ!(-=j '0@d[l+_IHC$hj5~U ܯX2?6!2'5x{R GAH-N^n6 WdtqW?0z=7&vED)?,J_qʂH*!}Dӭ]]DH´ȶl ]udX\GB U#c@;QH q%@6>Y0 fmr o8BXJI,$w uUXYށERxA( 9286oPcY@/z53pҒ\A~r$E\W(i* C~j"-pmN>f)}e}F .YݵD[~bUNIJuM^t*p=tä;?(@)f>\d*ףr񡡢!ܥs_LGQ箪OґzLYKnr? lxSNiǠONoԈ(B;\]q~#ʹF(ȟJXIvO{zߚH;Yt |pSSf7E.t +Q\v+%5)u/~{i%Ad^Ud`8]kg.=&:w0<5}K鴥Ҳ“ݯݰ RcGd‡ԛJkU˅AX+$zJRF!AG<twCyߺOikJV)rI=#ő[}QAp+^$_}It?COxPVjXFrBj"ׇIUr$EAyb1a-aoug 'bVxߡ\,%iP޶IU-DyG/nrN^v 2ȔrxG=+ *1z{ thN.x .]l#иk>",}pnScDi֩Aï+)'Is߉^T% z~ R?&`V(なRuz 0"ٳ+r 1oħ.^DOhȁtjhHUuiSwbachĮ87RcSc`ޅ%\uZgOaF_ta4@nb6W5Я̽7_#rܨf6ay"rtT}>100:gL ]CBeLɉ6 ɑZsSx>۽@"czsM䌞PWG##??AHH2էH4a(nܧMJ’yMrCQ R=xT/l,56sE:~B~C7·,~!p >hWNﴘ'ѓ$d^_h\P9'): *+,;M7&ol&yp]N 6x*`!^ds3jп3>X[sLaps}TjU}e {Ҹ_E=BsңB I j;WW95#HU{XWl|a z/t آ?@}<8Õ֐]KwW:uxuBbU#@;/lbC`>jpJ*Jls` zJB_,%pd)fpʗ4:S2iJʻ>@{X[׭!,iq9ݏ4̧Mi ei߂WkO"W&;Ly~jJ디!= _)asLB IIYJK,/|o6CJey ,M"[CTŴ [$u:j;d1"X%/ARi4\R`#I" guAUw4YGVրz=]Kd !zV4Bqv+%8oBkeH/u#+cܸpi}yD;QP_QBy)?Y`K.G2@ MLV@S[C'Wխ$l?N/N$(XB'vj{w/oyIg40뿘9vpiۃ(Y%y^WPv *Ґ:Sïh۹'U%i%=GJ)MĝFR`jI?6PM&zQw=LT=7+hb+Nm\SˋsS}zDk:RKQ!A0P'㏪6v1RfɪUn fS7VRjo[(řd5j;N& m"p/]A4wF6GfoWHǢh˽A +@!IL<̀N\'1G} I0;@L;}gr a9C,r*{V"Z䥪^HM F -;aae2L唌$&ĨK=.J6Ȉ_x>j~CI(;[6'.u VRIjyVe>FcNN;oҶ+.!ve}=^I(3F*y8!}$0v2yAS?<"R'+3YbI蒙 vL~ z^U G6o"ru҆py͕.r>[퀅ӇTco'FJ57Fl]b6VㅣJ>a9mދo$ur%(sCp6N E"1rCLĹQV_No5MYLؑ3,[M+S3cd0A yq\]XP,aD&E(!;sPݨJH,R,M ;B,5iEQ>_\4BV0h7-`s9ej`DrYL87ڳҸ(m& Mn5{LzC.OK\)un>0ǗzecVXFf3֞P'ΎD`:I5er<@p[Z|!y Låzw62'UV N¬a!eXx,m#qhNeCz~~-Bcv!|gLq׻{d@zWgIbP^00pTljƚ>mǧPE1]D?&<`M,_֕J+;2ߞ< XʇG$^!Q2} j8'J, d(DʀahրiN97AˀL<^b7ji|o0Xc(&0*B#0ꥫ_Wf ^_($>׺lThW=x_]+H+xH!m6N rzk 86sҦӀ F #h7q/DoTʹ!LJ2=M,PѯL_u|AD"~9Y٢/\z2sY~$NZ ΁̍ 3baSs~AKymgy-!o֒E,~$]ꪕ!bS- ">{F"%jE$0 +yS2lmtQ{> RƚN3#Ubɜ \zr* 1e&z%DX*yYJ攂 ۆ![t07P}ar|pLDaϺnq_/Nu>/bpIl&a|.A@1L@'fzWGf|ɽY4P0 Ёw;v[vD \s5&l3w[ãޜU<CWdPV !N\evMv@g;̵Җn͸isf/KVFQR#!IlȪ ].}ٮ+B9F(M'jUbBG6J}ԟgDzUڴnQn$ab/A-A>wriRRl#(}a aU\ E_PSL(C3c&>`iyco򅭜<zVs^w [7 C*gATZ$R`fYmfWYo_qP2|ǩՆA:Jv<3ˈ:&Ƕ MtP7d6'"NNƵ+ȵƹ!/Vlzԉ<@H&?2$7&ܱ-.Qيti6S_I,ӐWh))G Nhu>Z@aUѲq`{-ҳ~ϷnxcB(2i-ѦԻ}=Փ ?`MZGtzho۠љge'xYRTbzä?) Ʒ2F2P$3w9P=V3$ftKiX_m˳@m>?63kva:;+9,XHl+ -qk6Wt{̯9%AigigLծ u=\V^EB;vwRDyPpi+/PѶqLqiH%]32^cpOFVvffck{zJB#(hDŽe` EdQ&0ƎOY@'O{҈Qߏ# ҽ ;YQZH-o¹& ꁫS%U@ըԥR{&9yĽ 7h<`'3Hޜ]=խ؉(DğC+:'LFYrvCߣKhR*z0^P&8=֮-f]JѴ=՞=gZb0kJp]BmK"}P6h cH{AGx4p~,a|\ &I/yO\xihYWĚ&_ V[UFޒ΍Y|w0;4g GJybB=+w #U8^R vH>ڔZ"AO2D}vއa4xƍ%E%S23p&sbª S, O)ߓ '}r24 [\oևD}o2a_Xw-ъhIliB53c7""\7VyVKapgʷ^VdQh͘-Һ{gxqR!1),B.CBUSj<2P$y+"RBxG+n((ch.PGx3KmvUG RsνN'f(i>edqqI<:=]]0E›8~C;=dBtO$M-@8}OKGx874)cۯf`@b~'dʣB3 4b!2gI dtGe&\A@7F26WV|m q%Th{G(6} T*:e0!Ej&~a'6ϧu>ٵx m?69͔Jo  B =}*O/@xQ32qA+Uc-6lەڶ˹}n ɯyS'۝wlhOP&  (8{dV/e GM,CƓqkK`ŔHok.KC(RKĞdW[SDLJomwװ)rG(C $꙰[C'D"[)܀PC5@ tsJ u8za^V6Gи !˜ZC]"$qsoGTQHSڣa!f/AfZx6Qfԇb\ ,ÃhZL>(vą'`3/*o5T(jtwg$=suI/~l e|Ah<O1DX2;"(F c6wKl9 rm“OJᰦ1,=W+0Uk"J)0b:&;=aq> +)+g˚Xp+lX5;jJ@FxMWwUMdK囉0i@P]DYct4Ǒ9̣.4"bt6) NncjEI`tƴ2{:0R\rNNKϢpGsE| #8LUzmi$^#?RXrY ?N9 \S3ud9J#r=h~)4k\g_Bi5,|z`F CD=m<`az# 4 KEچ=.îzؕ͑7q&D&9ધZEpL^LT3Z^(1ʑerݣ`U[c91J:i,/S(,WN@%|{-oFP[0d}Q? pAr.Q_hN9&v:%v26 W&" ܦ >[-'1 1 Yydҳ4oG}$,.%[95Eh".ؑܡ>)D93ƛ豽U6ySF 3+HNM,qeLd»3<(yڈ\ *؏yب0Rދ~2YcHEULHճK9nDfvO[s=}E$mUo^ɺ˨] L@8c,&1>61u]uǒOhgk]@M[hxesCV1 lMxzDY hSc4{horq8Ck8fR3xY#}t;M1сQw{`4/В4d1>tk 5 ~) [yc>J#;ݸ@< ڵ$Ak~ -os&aCuH}P@G>jxV-4_lz,V0\"3(rb=CpkdIeAM E3%)}D[wJ2U/()nHGusC!? Ŝς|Јo).3s&Dd`K(e1cR撤"ShȐXiPg;b715P)A ݳx̗|+Q< $\u"~D(s|v4{T_J0D_T^;Kl++gF NY`8e X:m^[$&(a Gpyׄ{\#RYx524-c;J-h7]%gYý]V 9 |sbBՎ^3ݒ.V,2[Վ  iyFi)̐ˉa;6 lfP]< ]q_|/~"7Wk m̮l,ʡXTNJڟўNfɻJd!&H{9WyCYgaŢ+Ҳ)S8= k}4s0kxHo0k됩7"yDH,DmPi:ʱ<Hީ`Z PsMKؔ}` J/.ME@h~yS  ΫdhoO[U<\g6E'R7FĀ{6S! XpP܉{iW:~MţZ?lK-$ZWMb=<赿V6e[y2i*!ŞckNz#d>M5,Jk$7w?˥SmO$GX''LN+G8y v HEh:fײl䂟zP:eVΉ5X{̅0]׬ID :RQ OxV>j JZ}fi7ݟ`2%MZʽ5)&>!b^kb*E7~6ydv 'zl)FH)rEYyΈnEc5;IDžh@JY2 W/ɤl2y$D HcϬUsW׌)ΐ^cDd9+%4 y%H̗\}ce&3=kTc" {B֞$U eI.b7)nMPߏL}J׊kZ(Vk+L*s>e\ѤU1o8q'X<zJ-QDCfbHG7Q IR00d\^UwNjx[\y|8/QFHRa 7jnߌth_Mk=u2PO!b摩=pBh@.h3$~ޖAV&:ۦF<7J56*f 1_w} u)3ѕ]Fng*:;A#5,8j2Wi؊8h#G-,𼨫bhpy+2mwI~FLz~ؑI#n ɻq{7_oREmmJMH;cPef;m+n}?9ՌD2n 1`YR#(۱|@bιġ6N$2UпX2f=K@TRG̠2`usNBL&.S:_urt< i]p/⬘A|S kEY6syo/MֺgTVĜ k!010j# [RjyVO%s/Yv[pohÓO`}AR >~/  S$oIo:tSՙ}F- Ҥt-o4.;^Bua4]^ }#2ʾvtC(ZTvm/hx/?:?gQBFdI;DΖ]~`#Tˑc(땄7nHfn׻ɜC Ucgg6h_ZIzC cH~1}P2/fv\nq?e!5b/kWTж\`;m4< +|S>*KWK!GYqPf Qt+UqB$& xy PcpR k'!fg>B1R!{:Ku<|5-̹K),tM2NaNyŁEz>?:`tt2u&W)C㪌$/7 x1Fl~~) A 7>Wq8}TpCӆK_ND 7[Y\/fk:\:] ˋV}^MQqCׇfw@}6%M ަ-Fm݅~s7y:v M{@ʃxS{cu6<& Mc|6iz7Nhl Hg TpCDFTqYYܘZȨ4 ¨e*9\e1W.q+ƙ8Œlie:S5yQo *UF'E'ۂcDqzPޘzWFئaH իLcAEsvh?rI*uK:I冲)ҧGN2큦10Lͥսwj7$F0vS#D>D9H 4Ń6p<[wż?KG`66x4 bk䯭YXa}@OwJX:RLRʀJ"G^^?oM3 a[vcw9_}'y)Y&^OA&7JZ`%OlPoԼgqcWy ǔYIT:L/[I=&RvD&= M8& ĵڝnY%98Ҕyg[餉X ̘1cdPfUH~\+ ڳzM9%mIhnDBsg<:صtnDYA^1Sx7R I k..:!-/ygL.X7w&+Wx/}yf"va @iǖØgq4o\?QkfsՂ#8fntWXĚl :6^hyn5A Ϭ66sT+ѥBm.$I tg췹M85yӃ3]oFh 'xa %QP:ZE@Jյ$S;D9S_0 W0D< @SzbD8vgE({+| F_=hu,Pj7sc#w~էą<8wi,C@~J㬀^vu{ R9%+0)>,oߓu ; reCa-P#`A y'k4a<'=bѿE*c)Z"\ FŠdXi֭i(~3Z|6`a8쐅cSKJ_F1ђF*9?嚡D7~T3c}y3z|"rsťsZ5З˩Jg,,kUy"a@qDJx8oGrhv+\A7`U\n@Im:Jp[5*fY>vniZj;;FwȈϺzWVY"+7M04prUM` bё]ItAfG%ܐ~ui{|~$V2>z73 pX ѥu+Qt׶a7-K7 ĘHnr8/`ϫ[W9dB:jO/pUl<[}ExW [Nz^ͭ@Pd=e e >k\ K!JA2"IG ['-i 2a7g[_HLN>nK.&أ{?+nJERr_ej_pQ|×'Җ.OH)qL%hf->_'^WLpCt2N"͐XYX;|NA.;BxL$5t`ֳnIH(jpזdPI#I<f7o vqeeM\چʞ!t u2Eizc};yL2EO"ǭ~SSs+;D /YNˎkC-h IAdK^a\*xO_SYȻ:e@Qm,3'1r6 iB9׭ʹNy!+>gjf#Unh( Vg֫L $3>2 R]XHhTApJǻ3؏v:8Hpۥ.՝NxO?аC ×V#^xD`"q)2WJ5S\Raਸs`TC;\9=h洼\>~/\fVwb|5dY>Hsة:[QºR]"QG"bPZ1("PU`$F}w\jol7cH. <~ll©2U褰HYX 'rjL1Ip0XTͦl~l 9z&l@ 2ѷ'F<$q Dͫ}mdR ]RMV9kE`q)G e1b֪8PGS DtCRDDaiV/ВZX1ݳCe3 Qy;#4Eŏ+f] ]}|A#fb3  )^!?[6"xPkz'{>B u&wU@SxיM܎̔%EYm3%&j-ʍ$Ry?cvPoӗi7*㟂*;bWK1Ȳ~+}Z?vQ#$=/ؽs1fwaHժGTXR0--$O`, A顡':e T1 k5E1^޶$z!vDcQ%!^=,k\z8iR.>Yo6gs3˲ާ̧Aws3?*5~f-|n}9߶ h. yC}QUH$^4DZ~[/X݆k-*9wA,L) 7 E9)e{s"+يd$tk,?GAZ*g1R0 Nta H] 1&g6ѣ”p #a8 y *Z+1%B "xx=ٜ-3a5`igKoۀZL,5BXF|Y:BQĹa`<洜v8W ͬ2}Ɯ8M2uÙU,J<7x`tWF{]uɒ;=1%A$ąt`Z6&9:dx_79g^]\S LK_T>IPWN} ̯s\R5yOz}:+g:h_wȜNq]dp6mcyR # ͔Y3 Kr/l]ȼ>xi;McYNVE#6 2PxH}rH ڎ*a!;w%;X 8jEs  S pk}ٿ|zɇ',*,Gzr(HoO %عMV4欼B[bm7'J X'>y8N' R}Z/)NO=9Ut_ BhZ7h& X}*U8^g~TdBa\`^'ͻ7*qpW\ (GBJuF 5`Q vn?~9C,k\гẨ'o [{25klɶ W( tSp|eYyW!*#,frսZDF6S3Nh'YqIs5ZEg:䢹ʃ0)Qyy(e9l;U,8ap.!Ƹz'+Mk[2_R.ڑ&> Otehiy[ ϚMX d8\븇ō,| Q*QtēN=!{iF"w{ޘ]Rd|DTg5\cXj%g B}K0hiYRNfr3(%a| Ioᐹ>QTx'H}ۍAIкwJ6"k2%7SpɲczC>[e eJYug5#}Ri]\w}$2q iI,v} Fcf1kZb|[f+POk'rEךb&IW N!o(w?~NxW@%HuCq0HfR8gRv@N Z܇62(6%.[r9ޖσNL^2{_*X29;] QŐ܂BpUHܟ:Fyr *YA""^11m0%OqN#bKplP9sjNNƸWZ!ɩ75LRv&a=" Grpak3.l探h OEórvAk+{*C|;- &lȝ X)(K睵O嵓0 B[Ǐ\+${>Pi$$E z$ߒmHzރ|oN]tWcQ ., қ(ԶwD`r>]،2NӵPWOdcI}|pߊ֝ ׍Ho#rc*u98Nj+5KUo L#ҵ{rt?{hCTd $׷y0?X}*`FHBqKZԏ(n֧-^Dg%3W3h7 =nqtۺ0i2Ƽ)y9/Upha Q1H&ʍcEDE;CM= $JLCFw1>L/gn!!4O~PDֲ~ oK}wKT9SGҎpD R3'eH#5&tXrPC_Kɺ1 aZnfPjݓǏ@%5HEhrG]NA_1j2&՟jɏ IFgGw(KCX5lBT5 ښ[0{. odjp`]b *ﶘkQquu;bu~vJIdZ*!S.3Z"/hwpG:;^Pƹ/be9p͜ӂ8? /!jZ>xGV T%!tBftT,8 #2"Fep9#[ͼS5DlCWY}:۾Ɯ yxb;L oKj7%s|թ}9h]4N,%ɸ Rh e?<=,N=I̒ʢ$JSX<Ҧ.>ЅVWRtZop"+7P?VJٰ Ò#ʣ@_&iq2Hos}6A>CiؠkS-F6PІ:IS>O[ T;duɉy:lskL4ֿz_(isݳ.vJ}eEٻ'Xt=jy$ɼٮ#hQ|UHXG{ XSTr֏BoDXW`_8~cexW[d<\Nˋz,3\v@T<, Z :\,#FZ#'*#k!A`g/!m6NηT`~rk>V6}ݵ4L;\Qi#  fEܞsex|q pީ%5j :gqźQɋH ԷoH2|As2| B3`GRT]p}RO-p?["?ǃ¨biE9Luؓݟ+Q8h:0[ 2"ԕs&@>K>#'˴NחR?)apts:d^?p霢 ,8,̜7Ӫ%@$ 9լjLz%@l=ʜb8 0Hp].14#)$sρxAvm9UJW/YaZ5x9: f%D.56z5[A_bWuEYGl-K4 fQBգBAS).2U9^蛒Cɰ'U\Zm;Bbɍ筱 I%lYdlRdXy4׏G $cKhj->&|^jh?#\tn_̄wÊtZxs -cۖ3`{Y;`J X1F+YTVoLܲg F0UȘ_8:ci ^)DNl1f uh q<8*Beў33*xj7S饏\ߣmf| e\SF̥cI5!oSof몱~}g5||X +%ztٶ`ag3Q (3pUϷ9yy& Q.[;Rz$z(鯢[d5xd0(MĺemX+2Y"E?Xt4Tw%JY(O>Fn%=׀\4VZCcpcplX l*1nl*2B4`VP@3ϖZǔG[rTZjDډò:1^>B6r'pܦ`;&?e2TNhsf ~u:D!mI;9iaӅaI7:P\͗R݂@t 23&@vxU6&E6!i4շͯ6QɲH2%]2 ygb=lĭWHOrG;S [b%1ǧ=$eC^\+s#VYCq 3 ux`%Q+GUvkYR|{{ÅZA|q""e{&v|5(]Jgu fGk2@M>=Ң;<-VsΛ]YxA~vNUcNGq7AcK-ê[Nbv)r7¢nLwF]N 64 ˍFQk;k=Q=5k<Gz+hWG J[~M"JS]o;QC]A]_m\zH].W4yM ϑ~-16j^\@4yJckKZ+&XFң(g\Ge8o?R8d"Yze $gk]k>)-%]3q]n{aW`/{Z86'W8ZM~~&"mlGc#DBȿ4zO{H15)spDB_.4@|?C'g-26i*ᏞA^;L̞JNL9€YwcaL>BU&Dv5`; ᪼;q@ Z~"y/D (28$;ҕAT7ĶСN9&SL[uW%[0%7^6:/-0L)r*a$0=t 첵 vEJUQ/|$ZGpk-_)~Zo/w S)kn.564e#T|v̵Fo sp(+#:m v(S(oQ1Z3[R_&9ะ#Ց<,զMC=|63{B[3S[}K!3UNKv ]nZ?69~atNY"Krgh4~Vs k,ig{U ,E,,"TB$X±"Bntڧg98[WHAe_Rײ rSDǪ` ku1KI}՘ i`DVV֝rJwaWesvU -Ȁ2 .8i x]? {?A_$1yGi]kpFv;Q8Ɠ5VIsA{ ҦQ5 # m QrbdSrܾVXІ cFZcs4>UFu:ՎbB' , U+![\lqy E 8^g^30=ʡ4wd (jIvRxv5'ZŋuEG9x O<IixK !RM9FV /Ϭ@0,%Zv́p!%EA1Jf f:>}&;5m?}qM"ڃ: N#]>s5qɡOK,ۣXM7F Pj^B嬧>l)Іm*90PtZ1`9 !B BG%=}YxL&L 򦻢&md$Iß/WN,:T obA\aV Gt ^LؘΛ0 Β巐0P!oEjH\N+6sfoi%0`se~n:=ArV zbڋW'_/93\Dᘹ`ã~t}:ȁWKU^Po/]4"XUpR9 H48Tx~];E/ Hónel=[׭[zy=DT8ȟNs]{lΰxqODr3:,9f;ʅRJ .#NN_t*#)iME m0Ks^/ߺN0$*挮'ڄ%bf.Ļ~.[,B]( NDIcMt$x74`ޖ*]o@1[_*vM8)5@]Z=WuC/ؖnHPEvjjix9(EݗwIkH ZL(w}Ed*UU@ൈ~J%! ?י`$qԞpeL1aY+XI:Ӄ&?ɠB{lGt$Ȯ-∗LΞą(q >n;d9!fE]Y2AUGL`fA·Fu;H J^*ɽQV2ㅕ/Y#W;vf)$Ayt.6[X8܌bحMS4wع}S-_POtJ OYEư~z]l {h]gANB_jk=Vڋcn@r'RWObBJ۾yO;/?lFE-w7 u;Jpչ0FW`a'? 4#=5ſ-Q-&0k\p|Z~aE{ToeNM^,ZiXb~Bm@{Usg5"ϻ?;&kw wTc߻> 62΢+[T|N18@\0]S7bz a_BMV묚 =7u4l8KԹm,f d>82N%^T(>0݁?)N4.L>JVS^;eJeAd)P+13{4٘!Wꕼ̖Ґ[ U/ 亾5b>7EWJ!hv hjp~GätQ>Gc[m/y0}O pUm0NuI:^-t2n9zOrd0l?+\]o>? 3 9wdFMɌEoP#tBjC1և [𼶫Y#>76$yG:[Uu6/ OJdg@phh@APH:;8xk'YK{èl"IZarfs֣mAZ U gkr@մ?%G!{HǏ$u5}F}͞$Fަ^h1g&ds2,2$J^Շ判0Q""4{4"#6( ;fس1AguG'A~f啗&5Qŏ&WX*yLgسсY-3 9 ^>C,/_A{H]gJ v61t[\&v]Ɗ󓁩\H_|RyW 8Bƶ: dQlCQo>0! :mSԈBks#8%h^klugqTWw[J,0fh:-*^OGj{@,Sצ(Q$5~JzjtW/lIW1$֌g maOyGtUF(2dT~**E9-єKlmvVEPD_Yi*g%zJ F&}팘hi*[p]>90D93{GHQzR%D251}DEF0zPuUԁzUيaC+A2qC)aRqa;:sDK1Z$3Rh8ַ`rf+_ӇnD ߏf۴\ݐ=djRr܏Muz-A1/ѧPwJ+M!>#V MAG2n%G1l{{Sd5IjJϿMRj_D׵h)Km3᫶1z TDhpvy'A\04܂_x.G[2 Fm.&h水'85?}Yh3S~  PNz/'X]1zc S+QLOõ`SxPI ++Q7'}jZxDBfɊі(J$V lqQrv/qC$ q1z1]Xn.I(̏ʗOu|Py'gnPNܥ7hN|R`9FeXy͎G>QLUMċ[CB h-bb _X>yLWNRf>]y%NDM{a ,9 ">)hܦ UaWRNb| SFH=u=qr3^1Y\lOO u?ϓzYAa)_!v>KET|( -!C0BK$pe Z|kk (Kq C< ~%ҝ'Z)7FY49E(:wi M>1cExusp\< WX:j::fά4%\ #pߕb`f~=uYdհo/iB*5M7 4 6*PSu@;iSơVH?uT޷{GLY2Q-H,ZBO\GWӦx&U)+n7ɇ&uJ%&/.95Oa )j Fu ՛آHDDǧŘ~YWKd+!ҏRL\?4z2|p,f,X$,ڂ(xY\~CƸ3}e,500lKUGߒB 71.Z;l'3vrj5d0ݡ]p`ӥH6:1ۥoLی{"O!/$M}^_WDlZ+%$Ҏ k+% s=})o9V2uYE)1n`VM/n=jhN`}dIZPgF 7SW{ خЎ)DHX)h%n~-|CWo̞kߣnw#k*qPM3uMkL/KϺz/a+DubuONr2C9LD|f= ӻh-|8jޝ*zxPJ˧͟7тs|bƘXZz˔w _nvuۤ#3;Jr!π@@Ỹ3)τcQ\n? +pLfے&#Ѹ\EN4)#<"&'J K(Z!5碗 qȜˮ55-T7YOeVVېա;lØSJ,,'ƕ(-8}#fm SdeTik^=E0tb'?V@ >UBMϹJ}KY؆05'*_xOTj[e&B.X#{ʃuN-PvT/<NVa XX +;% sfxv*}H|=67C" T|uWy-޴`TzF-f@e^7nk0bn7o37uWZ]Э󘃜$ Sw*C,8Ock *_G{ۣ[<$+P5:r_aD4JN&~lSgSi'vYP~_}iY)t|n%|IfpV!hlؽV0`''5>dbNϒ/fCU{wi' `<yW #o(0Ue:-.!1-SxeBn,K#ɋZצ&r1'nx6 QgYʚ ]z]]3,v0Ԇ} =pJs]@F1կӖP1c#Ӎa vB5P}n{rUu=nzUvʗMHhs ;g,n"ɯO n0haoJ|Xt3S~^`*3J n5hD`nhqm2 Mk{:6w(/1lV*5vLK -reks:]9'U}S/VQF8Ė.!'?:SGAF3Qg`BRWK14 !0bTi|à8R&CM>/fx"{!G$H8Ħ+hb9M .% pv\#k)uV00" &kz׳MoEK)mQ) Z.-N;aŵ݅$P_x flfwZ2§49FF+C~}\e G< ;D(WbVigr))'UOKuJmmFr"_wBbUqP9wBtȠ h'A2T;2ZOm*r~[Ŵ4@pkTknI@ŒQ3ؒ> 655 r+bdYh#4wzl[&؎ eMI{TAr\r8l/}{cwoZ0 EC|'Na6%\`rGƞ4:=Y:?mW?8ylzȮ;@VUeo)|kȶ?dFt#gU}X+]Z%l1whdȧFF$ec ;lBOt B(.\ÝwOSCmF[lo9r4k>h׾Kn{tXjE9%| _ºQW(LͲ=MIXu o:KCYU$ zx cZ?3-8Ď \_+H+niJV?0̀P%ͱPuxXn9Qu8iD}Ihב'GW"ԆHHQHcbkQi LiBKбXMԝCm뎝X\pH* 8&ȏhJ9D'nɼqW;ѹ,U d$`0 PI7[T 8_=ŭٸ17CG5K7$S[_KtyxRs'cAjjPR/}yIWl[ KBGn)5 eӚ}JBͳ6*N2 iHes++n2<gE0~S"O+Wkq\pt84Eq;.G\_qG Du6;z 7jm4[fbaڕqӘ,Q(Wx?u*\Ɠťyi אyL?sl`V)iL/cShA-25FdgAI@6}|PK< ڿ:ƸD$ ~۸F0Thl4uQI_ kI:^kc13~zqF%wnynEόgf[Kϳ_OUN5&o]êtSJ<_pͷibSxm* I$*&7HP=%Q2n$V~Z%'-VaZ,m-! * 1mN">tK"h^&b8?X_Wˉ_z,wƷ"$rrb 28⡳ONc,&$}y(^F{8t1M;D!ͺcIÙſ4ڀWf[Qδ=? zu!2U {^򈑣yu~%J7 4!e`׌º ^6f˙to<}V]3}|el'}\SE7nmN9*/.9L7M3Tð;}w!{Qr pEgo'HǝJZ?_;WNG]{hZYIȿ#xyyih&4Y)M>1g-s(V . T~:cwZ)c^9ɺ)ֹ{aW%HgsKHh`{oёVDS x lvhw_~n:Hy(z7徻3t-d‡ 5;'cۂkd6:UX*5wW.)H1 ]dI:Z֗Vn2ENnfw"CO겭~FfJ!؇i淓g tǕ{@-Ӿy{_I5M.jn\up#NNy{}|h`0Θq1  VTߗV7 np)UlFПd~ғ佹KNsWLN  e]Kpq8A!OLwi(e#';(B*T!-Woι $ 󻥓ͨ"#_2@(vèHd&8*$8.RaߛODVa>B6qkM0>dG!9Ӻq Mg少e :a ]p 8fithNZX׶n~EJ#'2ɋ@&m=3d˅OIdyT0mzkp-4sQ ]bE,bP.5.>vegRt߀KB;sx2jX0"1X H숵3\-i  r8)pk0|7L@5wn_(]ލm k qo qfb?x(WS'€]r ?V+; b|v;8ź\#s2-7\Pϡgdxd#xzC+<H8xQwĒmq_X=H7}lF((ia-/2Jd0 Ķc5 \.)!1+@(VP>ՃIg^ܹ]8|r+r42eѾMME4r n*gN^eWjg]]&\^>vI&*3k#-䥩2+*:KJ6A[dʯi؜@K#g3Ip6n fRԉ/6g~rS%!9D==3ѻ_l NP{*WkWiz>F}}trzf/Ώ|?Vz| IJsCkZo:l=e0bEMmi;FVY4[Ue;㳁DǛZ:g,JwaAg!+VFC f{nr-r{:#|j3osضڢD1uM$iF-eLrn q$NFaKB^OR@(&5_sa & ɪY7cǞ,HwCd7$kY@z6t#CL*)!ll??ªh&eEs>GC/?+ `?y% B@PJyI=uL.oX㾺P_>bwni>SH< 1IǼJnu &725d=v2^Q "ls5ntx1:5RT,D}v㥜㟸|@ o<,/,W[ /eǚ2%,46MoKhX-2^;J?|jQ|dzmY<럯k.Ȣp^y9^;n$Ї.-[o( jľ7b2>$'u+$V5ɄژI"=KSL> LB/0 Axn8Vz;֬kn 7d9LUh M9yE8 n!NQY}r{yuI1Si@j"ak B{:䓉`/ .Պmp{ON̲> SWx`(6j+v,%.KGA{^Cv"k#NILꮯ~@(UyY lE~jJ uۄwtZ^kr )~)>,(ǹզwIo1fwc:S]+1zIص ,ߕeD_El nt=_ , rXOa2Rw/ ;5`$\@  i??3)ŵWC*GU˪L DqЂnhS$g3D5Uz- $MJ܍K*z\*GmY9 e6jW4Y£ϦAt`o.zvd$׼KZ/]cr80Ȥz";jnfkP s5Fr/aژdsž;ɶ-/t*M! OխfD_}frS6s|GwJfI2,Zh2IT|ۃHI_JպqW>wqL@N(Zٙ-v4ejXh@n mWM?@`7+'\><+vĿ<7r~Τ3vd6qlﺶ"_: !Q}4^AMY9P`iQ+} kձ-}泵deTiĒ=SʃXF|񿋝9A LϺch]7jrw2 `?8Q[tWku}/ cmU#H6QfS,jSY/r.Cs A$dYPemzy6+cbgHo<( d4e mouV7EsCy˄3 70evT˱AO@'P.mm.v^kWEc볍My++so@إ5k$C8'j1g;邉&LK;U1'OOǛρJ+z$eJi kI,4"E=7,pF3Hi2G:Ꮪ^%XÅ46\YxDqPL|'Ye%0w7>ZL8br׼^ Tsyc1'uV=@ ӏSafa%(=,aFE/@y-nG!HΈz ɚjaݼEsLqTLXz"qW@:IJ*ތ| f>(:ƧWnWOi ~XYSm zs7JsׅG͙؜2%nesQ|sVpӡ23b+ZӼ,"2rm%AqlrOvN6d1ܰ٦F>v{r4 -7-/S(Eq^R*0h/ *DVRFq(GxJknzZ T೮\ř?譁pm9A> fr^MlSt 9~KR Q[K~U۞k_1ri[|; n9c{>"U1-kkbzʢcߠӤJf$@8u H.~F' ^tP܇L?Lk]Q%{s5PIH= e8 +hL~*)'YddYԧi/ ҹC%k7N&QKVBxӊ@]XNF2~T]v'-Ah$dl. zR 1|9Q+k3B=>{M(< WB(" a7Ǚ]t{;iB[p0_N{2{H:AEm?ygӳwS'Fu'g/KΦJ{Ub r)E8d p֥b j/oI.+p-ŇׂQVA5}l="ƪ0t&}ԅ?~sk;p3[UnUPWNMGiyHҋ{wA|0>\[RT*< 5 Yk657@օ75T3~^~T@C= CK Fc$^yl|atUs!A-7\OOl74S&Mゅz[PV"Ȧ%X2"#eR:zuKNE_~>tn}hY+zmÙ g M=.. KJJ=toiPRLKR*xje2&S {=%y|CA12:BZEz~WNGx\ҝSU umu詑&&@nZq ^Ѹ oum6 ^F2S&/Kq&Lf3 95k$2Nv]Πi|R)oc1VLQ0%kPRp:a1䂗Wg vZBQ͟d" W yRH[}dRNo+@$NN}S*3D&h^~{ ǒ%'aŶ5nIQJ!~f漜0g?$aGFb{׵:n.- 0Xd9sKZ1NGfvHxeMdSe1ToWt)ӧ|bQ-0lS#RI뵠E.{C #(WM|CJ2l~fBs6z_ D @,IuPϹT3YPzh ֒eZH[zs z=nP:xZ+MZ3aͷ&Wdء浡֊Mj<޸7bݞΜ^t6JlJѻȿH{aQaA/nmn'k_j _4S[SQ0" 4<@pTJO,;Nc;V, V!yqFwPn()ڟ,3ų-q0nG j&4D!T$ϭdUrᐢ'0Vm+0շVHi$8fmə5+01;\aX`H۵h~R䳁XlD t g8!(^_Bo ׹ՄV?uV3FKr"sR{JQLDw{+W$yD3{`xf'|X|C.p:r'S%2ILj;,0KݕzPF6ٞ;rl}W=YqP^6Εiׇ# *7 X\>URXw`pn8sI ɔ/ SG,?m!6Y841H$gmqdQ/ZWeQ ?'/ Mu J3.T)K! C^4]WZZ5;6w9i?N}u`ðJKy+݈i*3B! {BNUx 5| Ͱ:HJcjbEΗW:0F٢-i!;[܌! "ƁP M?$2~A7DK&UW'w*C.~W 9bnM^6ʷc AHUU"nS(ͷ?QzwC-.DX_ ZDW3hG#+xxjUQU+dYd o*K]>ARp7" Oj<6hd' 2wWNEsdɧ(NVG/fr%#I]?;4 צ=: v$֗W&{gcH08%d`ICX2|A?"b ڑA7 Q2)tDžy_$(42֓>(DFYVf J&*fű~'ъ_ tsV2b m>[c*T1`ᇔSi"f`cyk| TJ0m|4'5|#L:Ss2bS+ ł@([.,&6rҢi׶e{0Lג?Aa&2+Q#ņ>w7mpPI$xSh B%]ώO?dq aќ9ޱ_J4柠FN9WO>g,LfΕ<4+$eVj\zJxBđOKSq Ҁn]r䪩}rV2Gt!Y}V\HK>Iavd^3ʮ8C?LU ~D-`5k(lf4ՌSQhb1ņBzVH}ЁG9YOA~Z?'ZNؚUy:k4b~S =Sc;ק*̓#a@Bo O_4 D@;A%!C;'n꒦>ls[1u48eڋlwZ-6%-+EOS[ŝ--|)dAS=$\o+Dy|U؍PYSV-0?vkJܕw*|s<Y RrFNmp[e/W@xEu: bmo2>v/wj2Ϛ$$J]s.r>³ig,ء*ɮyl R|AZcoK@G:} * I_^o#AE󬵮o:.㯭ݽ^`Q37_^?-r7,wZ[5!=ڸ=3̓[䭥n[ ^z#ވ\2h2YaPJRAChfi8*z=okK%m6sAC7ɺj!EjUy2 "OJ*{]X>Ih`CX>w5.fomL@C3+c52{,rZWyj-'ljנObYL={I. "9_BHn,&'QdDs޼Q7bŶv$ O0a`zAU%Shvb/"oj($ VKsFU6F$r@t(/; ܛ4U sCoji_a6OYMA-A턂K̶#1+󱖲Dnj_Cvo2Մ7tXmD ˗SᦚJ+].y,[-s{=V "Ι=w 9U,KWK.n)^/,iOi7#hZh< sbܲG'8xhof7еƝ؃B~q-_C,f;%פ h?sҷ7W<^A[q96+S/op+TEaMWҼ+,*֛HXN)x u#ۈ'w=S{bb+e>_`bJUЫ]`~۹͘0#,.MBw:^;Dt9|^<Z~٘y>p@3b ݛ*RɝiMrYVH:2MvȎdH3+Ba8;]4m0VXs`u BS(|z5dgٮ'yu-CF g*bÎ|p)k eEQc?EJMρU}':3h>.᱃S4t#^j`Q Հ/+kL907z4$@ fw%jbVd=X+PJg]o S(#}п*%44T-b:n ؜D_!ſ|F#S?sW)7o5ɇ6y&&-'lwNDB|#w~>&M 9u;<:zfD {U>bxH| }sh#k2nB<,DE^>{zKg;ʫrJ=Tr2@[husH]oGj *4,q1탞[h5d. ZD(/a>)a?l >*gy.^_]Vs6cFܾp;wz  r~=~n\ix*c90F@M`#pr0 BUSyfEӠV;:?񟔦e]x'}gvuC]*i!Fj4b4/MpƝaXd GċK,dDZ,lP2Q?^k c3H)>sofцEC .„2kM+j&u&悇%{Ev@tQ!t6>1KZ+eI띲K^VmR:ږ KkyIu$hߎ'EC2E䇲E>ТoA,% ?W]]*eڷWTp@rj?QW|Mz/`2ʙ ' ^1Q .' i˷'0iP45ecH-݌,0U}yMC._F sMv1l 'PI)Ue >ۋ̓.W1Z5_1r߾.[D'osn AyT3i`?}٬fd{]>՜LG"GB jVƩꏇ0H b;,R)(`Jࢧ"G^,v`m4hx={Qc>+oSU|||ZVT9u;N w=3FIR4O<BЅql0rrq򶦮4Xޏ= Vjp=W_uAX-A:sg\hrY4E[8`6й;D&-`P77샜ܠ\C2$JgX}F|?01D.c45U(Cs]A@4р5I/³ Z+:NBcXVҴԅ mwttՌdar%_ /GwG|TQU].=ٷ˩@[_INkpΦnJ,%UkÃC@ ~3+M\Y R,i71GÂGld'm^2e8 LZ6;a{S#K em oIT .w3`:j=Z^2/-EpBbuoz͌ރiBF y}WxےtzQf TƉ(:Ձ6\ Q-Pҥ$T[;יمB^t"4"Z`RW荶ѣ;My}R-U`MUӔ ЛOt_L9 rCh}hڢ,NvEa}۬q뒴T١eH6[JΣ;ҦnnR#[GESmwD/XH(jBa-ӱLrI%) X]+ptEdGDc ×VRd, a*)ftnMY̍@<צ-r򊯕"-\,%5~RMWCaJ>?Z7 6=HLC q`ޒ@&k]x6`%"-JlS5{ q K<^fDF(tˀ<U(_-oM`B N[ѭ4(IF4ۘH&8<}tnPلƉNnFXWESKEQ*3[po긅&@-gm$L[/a)+ bѤ=8z;{V%LMo,*{O3nq!Ty7o2ElK)f}SUuW<88$ A8#:/>oBsXr)+~hJq60iHzH>p8k,OmCe0 "(,TFUto3ӻDكnIZHZV> ~'%ӋXV Ã.Q}[v] e%ޟl k߿ۗQ0aä56m߾1({,[xw2E՟S;Cy"{>c2v9a~jRa)B(_c}iZ{]g0 yDkgEBF 6G?r@O@K`.z $̵\MYDXq+'l$Z^P=6EqEa'R!z+~AU%YN~Ց3*/AUE~5\Et*{vL2z>W&yVF҆N1`CT: D Z@TЫ]`DUc:bQ46 $_ D 0y /&DT~?t:pV˝zB ?`l-,fLr"YDj7078@ĭ^U(}QuhK lm~7txkw Dm`F}Avsh*h^-PW|S9o<PҬ-W nX A9~* l$)~#u"!#EgU>Nzo/4O/7> 9VHr>o4Q@u [9c'IR ~7e}quϹIWgpMX׶'WZPD $w{7zqruoZPGF`+e=nH Jj Zѽ`+60z!4bzX,j^R },,۽1)!s91R+"GoE{Dr 'P= Ծ"ʻ)+̠ES.bɌ&aE6'Uꙵ$*ϋ$PneJـ9.*v!m4]_3l0I{2fk _jZ/C'riPN3:4k.Uӷŭ Ϫ{ِ,Z33mJ ke@#槝+8T ^yS`ʲUx0ٱi%@&'P3D]ŒZI2)%UdtvzG4> {Os-Z냾n~rB]-ROg( POkbqܧrOc߻'~cz~p!Z:")h9l 'W nǰoFnV')nG2s[nh8k虆饫,υŹlK mh_$C;^])(+bG8|_mv]k'Kz/a4Oz6/8vZ]${Lk`w*fo"s8dU'ȨPwM+ߙ݂&!N41QiRA7lãuFI/.4bfJ5M{`1ە Q 3$:VgGj\gIk&5G˂<B -|gNͬAwDZt+e-PREsd4i=) |+PAc*54UౣciՙKHÊn1b![} 4L*h_Յ~ {Y}e2'Ljꚙ]g@QXAcG<J[P+B`l1J.[g<6svO* Kz\f/Sܒ$`ɇe6x+S s0Sʲ'0p Qr,4pl4ҽ I>Ӏ%|ҭ{?ȆVD<Չ6,lL{$yR6?~Dss$Uº &JֽN)#XOfQ,.~ gÍd t*sZO\ã-pa>̄bVK W&=Vq͙ UF"x9h lGWڃ4۳99Q|j ٔ>\O֨~0nU*$W'1E {{XbE|Ikz<L׺!P֛8c6u; urjhy|UhBW."!#xgd.DizC2^'ˁTkH-FE gjʣ>Iw]3F˟/Od`]dJ߃? գ  %T9U2J~0. )( |;.N!X-Ek[, ][Q3.DR۷lGԉnN M OdFpj6^$:s*-A;+{Ϳ>},\"c|rYrNVRВr6və7d%%ز.aJ@{#@ TԙIQ*$*ArP&ٮ歳"x0/]Xk"kC㯚QHBkrVwRgS֞ܳ-|Ֆ8I&а}|My$}9;S6/:EiQ 6}R .+(QT"?S (zٮ+7CqiT]QlݐMR]qlb|dZ_%= ۷C֋'e3*>/;Je1SMMQVGE,b ?<'`, UQ@Nfq.n>65~'&*FwQ~~kQxӄ-0ޫUz<'lkr/JG\WTsqT.{d-gLxٝ !-D*_nҎ.zL?Gs-- ,`H2x\`&Ǒzm,bIl7rj\hb>3⡄`qT6:Re#lARO>ЂcG` ߀ 2}fjᮜ̝Lq ɴR*vјDĺOq]eʋ׬ b ek?? l#i" I,|(u,$ݪUBW+-ԼTdBւx/i4:¶pOx.= ]"kx6B 4` sXS~8~ ǐ%|j{tkEZ ] <حPV@{mX`(&@PBRSεjbbāpqV ;|\s U)r}xzdb/SKiX9 񞆹9 TF7xr) d,8裫PHW׮Lx]8' 4*'`]+T0i;*!z3b6?ۢޞ&}{%5kXji UD$ma^<ڿLc}NKg1Saɏ׷e8NIc6A=:0=hiP;N=u5™&G3 ROm"sfx+9Y3j9%H;8a#%_:ȤsaǁXE$yp0vg8_:{e_v8gQ7.wC̩kC??[FhB3d͕Z 񞌩ED:72rgw;a~^/FMe#&ǻ|pCԙԋUs zt[l!ͦ(v7µM*pլ>˅3C~iPs/ʐRϝc-ȼz GEg<O/W_yq^pA,Wp So,5Pfy*jX0UN`LVbZ&}),$d>7V/u&P{1?ⓇNOp7D|ۨlNZOfEDh} C̰5Қzf+>'+tdZG+o:ä[ՇbSD*Rc-[U9]$stY',oUU j;7 b9@/&`AWnzv˥& \ӲcRCC`P]pV vLKBon6xҌQXJ3dr]PZѥ> +*sdrtlQR#HMr6\kZ#h&P(k*gR^|I$hl̥RֱpȋǩW7'">wΔ aLºDOk U1j8hdG)|qTd|<d?-7U|ֹpR3+9z|_bx6 uܪ֠z:Zy!Q;J*=t}DB% p}48W|樕uK EskRh{1t~2%R?Z !~眨{g#ihl|nWeD1ͣ=ѽ@)o zy{ ,-*F~ d꼮XBWJK֔wiqp*~QVs<-)h x)a&@tD)S~\{'Gi;VqFMNe+1Rn!t6U^9 D4՗#dm۾[k)O @wh&uX0 JrDE>n+ieS | ~2E|J̥(OR诠!'ֿNF7/è.B*6Ma[aLf395hPQMX);ri Q>WJ0yɸjE/&3[hd䈂a`6ـT^@Jb"p)wY͏Zi㯪N`w5_ t3>Pk1' lbOd{̈́U,&B-j+."z1ۚkǚj[?]wckS/\lVv*bL)N>ς>Ho u&=U_&k lu.WX42:lT!*:"8K,)Zv)L5lmo70cnh"92D7WnlXRGHO[򋜜aE^sԨOGG-8 'y(v9| ǔV]ζf߶c`oSuF~7;:z"ә%ѓGx/Bm^f~XrAx3/+6)?F;qe#e ,Ȑ[_a6rT^w~vz•Lu .X͘)ƻ #{BJ %iM><_YӬ%OQ6YH˿8܊%:+&7rI|f[ܚ#nvip3CF>!]"1H|yy.*[;Q'xpr4'//xI)PFa҉o}_Ƚ#BSA˄Z-0&Y P#9Q[LQOq ,iUpI 6G-rِ% 6vO̳502_=C36SRE%}ٺώT!/WHW"-(Hs#|܏nEAB[=z*IyްGB9~CC*z7"Z݈%C}:E`hˇ7KB,#gS=У\s;si9B2U}PD}Z-`_U?& %ȳ8SA~wW\fLOa 6ŰBp9)w'&e~(d'n/U $(~b1pS;&rV<$ R@E=S?n ]uB6_z0Wbm@ VGfh\E ?-N'} HFtS g TȬQB532eXE #; ֖U!ljt#7|OpJ\ Pr5~)]f➒DNFa7fEfw8{#(} c3YV9lPـt{>EJzm 1L}JpY2)}]2b8-ejC[a-T_-4 =6H&\eMV-<,Rs@L ZΣQŌjHU7 q`G .rmRqU7'{E/q60V:-%QOL<&zf>aN.,6iFIc}]\ 㫡NZ &jT/̉뷤头w6V)^^s;j2XJBfD|e_HDڌ#QJ5 UnzTP4R;J{%IF5A<*IGF]{!Zgiv)n1HBy= G q{U#̣2ķI+y?Rq Ss ^\KFYl㧉\/ɍt&R,gL=E)X &Tw*a%QA@0A\5(.ErjE?p&Gﳋt;S݇ҧĐஉ=ǓI3m} ZI_\w 袶s$Fo~m%,rh8Yt̔l6@Wd.ҘA?ou[AZA!(RO~$shJELyUj@-4}%P~i]6FN~O2=jHU:_*!{ V͝M^fl1"hA]6(]ڢ[,y3iv:lfX袜0S#Ms N8x[S ,q*YLuS e @ [)Ű5?´"%}+jBDUS*,tŘzY)&%df.P7ۃ )Êe }-l>YXЍy}wKOqLHE_j;|ӪѕRcw܉ݖq˅tK G: ~0~PLi ~/#Rԙ/OXB*\?.k$tp+ B`/3Vלq]pHX7F(o}ޕXΏppIsK~vP P|NE>KnptƮ MɷlHL nB_dxn/cZkcZybhˬV&/,!~d`{2Ҋ4D.S$~Vd30YNCM05 tĪd;Zrh/2+-5ERZØmyq^|(ZuOq(j,$/Y *C7,bHnu"'6Dv`Xlw|p[{}DXL_Ft@hDµg 9s6Is~WTG?PxY^гfT;?pN*6H-v5I(_Wg3ڸ ǀZsjU "\^?`6 2ƿ_n{eBG:iY)SA;? 9YZ'F7bф ?mU&Yά:~Մ ƃ3W}kҤ1>KسSO=)q R SZ[uxC0#ՍOݼMm@1k57yɒ'ܑm^44=@'7-;^DmS5$]lrI]"̄p8˄7NK\J棹pP%0asR &bj!Py;a$kjj24zBHPZlϹ$=)B}j9|%_[p-Qߩ l㷨"LE$Whc-1Ydc:Hkn a£C {QlԽ}t+=3:Lg&!LD\&Ua"@xDhc"Sϭ=*V3D6G8,U Mq@ wWSYHFr8 ][;sA8%0P9l#>!?wi%Y>AJ!G#( *bvs *<(5MŶM^ {EYgU&qG `e^*'ᩂ,%u?-Wg#m~OTT&+:sDo^ʟՉ!֥93YD5 3 Pr*JC^+5VL%"I_!;:Km/;e?{Jrrco@,#n<ܔ|قDeq|ΓsuKo0 dG[M~֪7+C64W/0OX&İ>Mk 14 !Gߪ v@0&2 γɕ@2(%Ӭ_;9<#;4gc.΂W%!6$ lg:RHP);S^<{!xaEuMDfؖaBnP"}7̜I'TEHPvvaj#O# Xii]pLzEjk) >h,+ǭIвwgeO&{#nXuR~g &*\d~Adaj {EU%P n&l)l*+ISɝJ:m(kQ&>WK79>i=zum#`v@%4zd..AlGW^eq@Nap:9'-NZڧsMgQb7iC@p.G-dCe =} s)8Q.l_B @8Q.GF+@uQM^4PyѬCuE Jۖ,pvd a>&ɠ.y|l"ۑXPGFN#79 L nHԞ`؃PaGtezº7Ա84B;'q:BVqJt׌&S>H&6;eD̞ϦS+ Sp8pL H)F,а!NH34fŮO)}³Gv9}@6:` U*KWn;-fKߑgcbHkwlG(o A$`XK@1 np ]{XpfwkZv.[a> _vcwoed}K!1iZho.- ؠ;cFЃedž?Ť> Pj$MV}[0wWW9C6]iSz:CBsQa)I\A)#06;@HO -e,nGo}{-G"gڦf5R,&h[W{}M8-bRmY2 +O/?].nU`\Q Hz>mwPR=t5bfӀ3+ (ݠ$U?1'R糵7@_u1R2xlDJXڪ[ +X:VZt0QmkqQ2HjTs"ο1S4%C:Y`C.OU/niYg;bj]e wVqq ^MC"3сI;, Hsgli|1[t igL@Q?o;+ 'X 1^$Σ|m]A,sՁo}.ʗl(.ccsbر j,߯@.eO=Be#Dg~I|b$ &"gb,1h2ˆ~\6:n\i/S$ʱƳ4/)XAwj|]a=O O6NKjX$CU 'AYLj(ylͳO(&h?oե* aJ ZbnnE{_=7`C:;=yka j]~w)lEhIaP'X̎2J.lpUa:*9~!DccjI)F~nr]:\_|PCn裃 EhSg_!hz4NubyTE.JJJ1Tl<9t2s~\4ك"wNؙ6a+:lY`ʠ/4zldpunl#k SArJc} 8Wb88cSm+|Q/Oysncu["NO ˦]kv7|@_Nl},;9%Y K=j ?\51> /!bEpi|< aݴaMĒW{Vp`v7l0}+qWw5WERGunɷ {$26sha»wz:Ttj(! 3qё!bWvw/DMyۨjg"spX@1. ׊PU"('vb;N1,kGp˩$kC[9SZǘӕWɣI(s$Ef` 2IU^CR(G.F݌4W{~*a]rE4BNgSWM?DV'K2Xݥ^e&V&}NĉR) m }Ec׎H~,!8~3,&P"@FAI<έFC LQ-ED >_=;c뾷&lpzHK$*f]vawq,E;J,.i Pha_uAwTH=0>pW* }}NX/XXN]jr;UΤjmU)Vͱ3yAtܱ~JL,fq(8V!aVčѫ |e1O{ [LJYi~0HdΈ!L@HGv]I'M*+ϓrY.vIn־W@|k*V^Cۜ'kQ^Q@u1m0|_Cφ)/Hr;oi^3opи%p3,qdd@L8%032U|sV ^?J턨S NXE1'ә{?X: tQ9 L-V7%|s&#b> z@QR TxY5:Eb`#%K")gֱ&]Ιr2lYǫzÙX NʞeRP\p'E.R f5:B܌,fH9֗.M뤕["z~C%@+V ^c~DT@" =C1>063)3GR{;Y%+&HIv2F#TP<, X4,hw/iO\};T-`]S 61;>^ *86Ϋ&Q@c#BV\ $uq B"`i,Zd*CT`b80r?#OX>~nE2fh-/i3zhZ)`F!.]o(^JesҋJ* dA =9:CȆ=[y0&1'= ^>U>,gZSs ۥ6wGʔZ\-%S`ۓG^RP%)vPyo 45_rDlzc(fu*MCeaM>29f,zݤpm&yY94x nc-&W?XgZNcpU#at^Z[y0LT~g cߛCɚ!wXʎRFrcp zv O 8hwfxjFՏ24xd{Q ܙ]~I{F--c 9Zj},/>c g}g}Jtno*2\1Q-ᘝnM \s^F{77mpd&Vq\jfi%5^bS'tSL%1c>ԛ"_y*vQ4 ѯ߯|.$`^J+JlXl)&E*.Xe꾾O|csѡQ0NB%# ܲR{0 YZ