libndr-standard0-32bit-4.7.11+git.186.d75219614c3-lp150.3.18.2<>,@D]⊸/=„_]}8O\xo ` 5}K#|Tty냫a5 =: c[}EwΑ+nf#$(P3t_3&M!aЩT7$i€qm{N0 XLepv]K IR>f1MFwb&"nx@0 :-۳rGc, [Q9͢OaRͱ8ər>>1x?1hd4 A | #,5 N_v|     $\d$(38<9:>-G.H.I.X.Y.,\.].^.b.c/~d0 e0f0l0u0,v04w0x0y0111"1dClibndr-standard0-32bit4.7.11+git.186.d75219614c3lp150.3.18.2NDR marshallers for the standard set of DCE/RPC interfacesThis subpackage contains NDR encoders/decoders for the set of standard DCE/RPC interfaces found on Windows and Samba servers.]cloud133aNoel Power Noel Power David Disseldorp npower David Disseldorp npower npower David Disseldorp Samuel Cabrero ddiss@suse.comSamuel Cabrero Samuel Cabrero aaptel@suse.comddiss@suse.comaaptel@suse.comscabrero@suse.depalcantara@suse.comscabrero@suse.dedavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- Ensure we build against correct version of ldb; (bsc#1131686); (bsc#1125410).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- CVE-2018-14629: dns: CNAME loop prevention using counter; (bso#13600); (bsc#1116319); - CVE-2018-16841: heimdal: Fix segfault on PKINIT with mis-matching principal; (bso#13628); (bsc#1116320); - CVE-2018-16851: ldap_server: Check ret before manipulating blob; (bso#13674); (bsc#1116322); - CVE-2018-16853: build: The Samba AD DC, when build with MIT Kerberos is experimental; (bso#13678); (bsc#1116324);- Update to 4.7.11; + s3: util: Do not take over stderr when there is no log file; (bso#13578); (bsc#1101499); + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + s3: smbd: Prevent valgrind errors in smbtorture3 POSIX test; (bso#13633); + Durable Reconnect fails because cookie.allow_reconnect is not set redundant for SMB2; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + Fix possible memory leak in the Samba process; (bso#13362); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add virtualKerberosSalt attribute to 'user getpassword/syncpasswords'; (bso#13539); + smb2_server: Set req->do_encryption = true earlier; (bso#13624); + s3:winbind: Fix regression: winbind normalize names doesn't work for users; (bso#12851);- Update to 4.7.10; (bsc#1111528); + support the new v4 Performance Co-Pilot API; (bsc#1111374) + quotas don't work with SMB2; (bso#13553); + Build failure when quota support not detected; (bso#13563); + vfs_fruit can leave lock records when testing for netatalk share mode locks - causing panic; (bso#13584); + vfs_time_audit is failing FSCTL_SRV_REQUEST_RESUME_KEY requests; (bso#13568); + g_lock conflict detection broken when processing stale entries; (bso#13195); + deadlock with ctdb_mutex_ceph_rados_helper; (bso#13540); + NTLM authentications using default domain/workgroup stopped working; (bso#13126); (bsc#1068059); + vfs_ceph lies about flock support; (bso#13506); + Using sendfile = yes with SMB2 can cause CPU spin; (bso#13537); + Durable Handle reconnect fails in smbd_smb2_create_durable_lease_check(); (bso#13535); + cli_splice() fallback code reads wrong amount on termination case; (bso#13527); + LDB 1.4.0 breaks Samba < 4.9; (bso#13519); + samba-tool trust: support discovery via netr_GetDcName; (bso#13538); + samba-tool domain trust: fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + conn->vuid is invalid after a SMB session reauth; (bso#13351); + Durable Handles reconnect fails in a cluster when the cluster fs uses different device ids; (bso#13318); + cli_splice() doesn't correctly return written bytes as it's uninitialized in libsmbclient code; (bso#13511); + Threading support in talloc_tos() crashes when enabled; (bso#13505); + Incorrect talloc_stackframe handling in python ACL test code (make_simple_acl); (bso#13474); + Fail renaming file if that file has open streams; (bso#13451); + vfs_fruit: delete 0 byte size streams if AAPL is enabled; (bso#13441); + Creating missing remote databases during recovery can fail; (bso#13500); + CTDB_BROADCAST_VNNMAP should not be used; (bso#13499); + Fix building Samba with gcc 8.1; (bso#13437); + Uncaught exception at ldb_modules/password_hash.c:2241 during new domain provision; (bso#11573); + "net ads keytab add nfs" writes only one enctype with older kerberos libraries; (bso#13478); + VFS modules that implement pread/pwrite must also implement pread_send/pwrite_send; (bso#13425); + vfs_ceph is missing async fsync implementations; (bso#13412); + net ads keytab list fails with (smb_krb5_kt_open failed (Key table name malformed); (bso#13166); + s390 and s390 needs to run with 'use mmap = no' by default; (bso#10765);- Fix ctdb_mutex_ceph_rados_helper deadlock; (bso#13540); (bsc#1102230); - Fix vfs_ceph flock stub; (bso#13506); - Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); bsc#(1068059); - Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048); (bso#13360); (CVE-2018-1139); - ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056); (bso#13374); (CVE-2018-1140); - Confidential attribute disclosure via substring search; (bsc#1095057); (bso#13434); (CVE-2018-10919); - smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411); (bso#13453); (CVE-2018-10858); - Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414); (bso#13552); (CVE-2018-10918);- Update to 4.7.8; (bsc#1099702); + s3: smbd: Generic fix for incorrect reporting of stream dos attributes on a directory; (bso#13380); + ceph: VFS: Add asynchronous fsync to ceph module, fake using synchronous call; (bso#13412); + s3: libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457); + python: Fix talloc frame use in make_simple_acl(); (bso#13474); + winbindd on the AD DC is slow for passdb queries; (bso#13430); + No Backtrace given by Samba's AD DC by default; (bso#13454); + winbindd doesn't recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Fix interaction between chown and SD flags; (bso#13432); + s4-heimdal: Fix the format-truncation errors; (bso#13437); + vfs_ceph: Add fake async pwrite/pread send/recv hooks; (bso#13425); + printing: Return the same error code as Windows does on upload failures; (bso#13395); + winbind: Improve child selection; (bso#13290); + winbind: Maintain a binding handle per domain and always go via wb_domain_request_send(); (bso#13292); + winbindd doesn't recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + rpc_server: Init local_server_* in make_internal_rpc_pipe_socketpair; (bso#13370); + smbclient: Fix broken notify; (bso#13382); + libads: Fix the build --without-ads; (bso#13273); + winbindd: Don't split the rid for SID_NAME_DOMAIN sids in wb_lookupsids; (bso#13279); + winbindd: initialize type = SID_NAME_UNKNOWN in wb_lookupsids_single_done(); (bso#13280); + s4:rpc_server: Fix call_id truncation in dcesrv_find_fragmented_call(); (bso#13289); + A disconnecting winbind client can cause a problem in the winbind parent child communication; (bso#13290); + winbind: Use one queue for all domain children; (bso#13292); + Minimize the lifetime of winbindd_cli_state->{pw,gr}ent_state; (bso#13293); + winbind should avoid using fstrcpy(domain->dcname,...) on a char *; (bso#13294); (bsc#1087303); + The winbind parent should find the dc of a foreign domain via the primary domain; (bso#13295); + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400); + Fix broken server side GENSEC_FEATURE_LDAP_STYLE handling (NTLMSSP NTLM2 packet check failed due to invalid signature!); (bso#13427); + s3: VFS: Fix memory leak in vfs_ceph; (bso#13424); + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407); + dfree cache returning incorrect data for sub directory mounts; (bso#13446); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + s4:auth_sam: Allow logons with an empty domain name; (bso#13206); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + build: Fix libceph-common detection; (bso#13277); + build: Fix ceph_statx check when configured with libcephfs_dir; (bso#13250); + vfs_glusterfs: Fix the wrong pointer being sent in glfs_fsync_async; (bso#13297); + ctdb-scripts: Drop 'net serverid wipe' from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + smbd can panic if the client-supplied channel sequence number wraps; (bso#13215); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + s3:libsmb: Allow -U"\\administrator" to work; (bso#13206); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + smbc_opendir should not return EEXIST with invalid login credentials; (bso#13050); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + libsmb: Use smb2 tcon if conn_protocol >= SMB2_02; (bso#13310); + subnet: Avoid a segfault when renaming subnet objects; (bso#13031); + 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:smbd: Do not crash if we fail to init the session table; (bso#13315); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Bump vendor-files - Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); (bsc#1094881);- Add missing package descriptions; (bsc#1093864);- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available. - s3: winbind: Fix 'winbind normalize names' in wb_getpwsid(); (bso#12851);- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh4.7.11+git.186.d75219614c3-lp150.3.18.24.7.11+git.186.d75219614c3-lp150.3.18.2libndr-standard.so.0libndr-standard.so.0.0.1/usr/lib/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:11379/openSUSE_Leap_15.0_Update/be996b7f12a3d56812e012720e2d8123-samba.openSUSE_Leap_15.0_Updatedrpmxz5x86_64-suse-linuxELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ee3fe4e91f51ad3321c595b78c4a34efb437e2f, strippedPPR RRRR RRRRR RR R Rutf-89060ef9f311e35058ddb69641f0f46029ad9d2655a5cff91c9c851bed3012c6e? 7zXZ !t/]"k%p+qvb^G+C<3x&,}iJ!u]kǾnїyshOa2&kiF&7~o2tĖQegJr;N#b`W )Mf~Ȫ&^y#d~nM:8Ky>5IK igB+b(1`D[Ly/7#8W py48W}U%\707{n=f5g/+B> si Mf;6QMb-K头vze;< o9t_dHlb 2@Y*$)tJ $6zuRlT !XOR ?^Yķc7&FWn Äw|28KKKv|l"e-Wl_=";lؚY7elQC?Mf_Pz~ t\fbǟm;k,^prI5~i?q9 )z/KO8Ax¦%5/!n-_ }~%XG6Ch?/_e.6ZF<<(;$ 0zz`|Z%dn bN-EW+T$P]x]EU?X=z(a56r1P^Tci~]i>_ʼne25߹0ڃ0n3 K!2-ǗYPYyL̷\ P@oBx[ 3Ag w2:8@ȍ)Z8ԊEN,ORС6WJ*X!'1|M^zH+G;gr~t0Y^SUoX]e*%_ulĮ Am53P.nb}- B x܋&&ND vÀξ|:,By ]N(/>5 a߬D.AshsK i A>ix2Aab`_o_>FkgQ41t:QHeshXg<[SL܍x'+㍶NHjiLMSJ16KF_@if SW]FQK*wP Q%`y a85i zw e+eÎ=\9L&u5{UVl% }cO\ZZ=9x_ Vu37tB $⡂1vɼ-fJ'f`xR1x3bҷ{"F8K5V*hC:ĥѴ p[>b,r;*Ӽ;Zk贲U}]D}2ĜIH”Wzt(gYǕj2!ż+h#,mɵmrmtkb8&I`PQr*go;۶H34oH fkUkfNd=mޜbί$j&1Px"oor`74"JGKYݦ|NfGs)nq>U nQ܆Z"|:3‹#um 鵜rŞnLUN~TMMoQyS!װur!3_;*^YX txz\ *HJJء#IX0g^ ^W14:v4F46ą` +4p  G ʵ8 E~_?:F@ JXs28Ov]b_8ɦyI:gѸUDl݄9t.]Z} sqV|,ΉRYG)~"X׺LYιyݦ$d?{]CòA‘cbWfdJhٕ}ky~hUŧz0ah/[6Z |Y8A a 5 8-fq;a: Hm;vW^uIm- վ2CMd]jN|'jOh9VS"]8 q騔ug4#U .VSKa|*;SB UAC_<3eY_@!aAɊ(\S0?3624c521[bC#@z D7/#8(?FN3ĝCrή޺ doV>a*% J˖_CKAwQɸT} | Qa3~n 5'~g>:+jk3xX|g-5Q5=~ءjȤsU0DUQ~% 8/n5vB.w%N'v1=/ߘXyhYpҥ{wr'.d>r7b q~bZ3n@>F'J4L%$gs EY!Y^bZ~FdU(fEcȤa4\C K{/<-Dvqk%%ȅ4IsO-硧Z12QqNqhi[|Kf(Ju [; e$Ƀ7\Fz8D]hm; deR*WܼNN8²eLr#ő'e/TZZy$@LL81x(mp/䧅T-}65b}BZkze4&OҁNFgIrC $y-1d:ރ:W~W>j21y5_פ~Sr/ N;NCpiR E{Wv>/i΢Q 'UD}_M'yihڧ6Geb;ؽVK=߈Гer뚥ۥΠGU A\-"6QQ@-|EA,3 ?:-ϲ[Iּ7x&hts-^Yқd>QkYmT{lv(k? D6Ӛϫs,*Ȼ@:At J oAօe^&W~2mf_ ) !k׫=5;Rɏm3O)t -u-zKi0)ؕKttBD^脅yIځR{U&n <+fΓa"A jMNW8=sc=`Tl 3g2Fշ.FB4=<C3|,4w}4I6g(޼&I۽,_r_Rn>kHhHwa㑋ipDګ`B*i%QA=cm:Ga ~B=-k2yB/I'n?ǜTEvۉ;J2hP*ҏ#$ͽ5Z?)m=Se*_.ČKB@Zvu*9D,Hybj0S?;ӲCd!*H_L֕>$Z(oE-n3It~ΟLq:y'Τ; )Dxs:W~<)Q)gO;ЪRJ 7+W?@W1 )_Uyks1O;ۮ+{l]mI~C?};7vItrJn^.2ebOkv)}(-;25{ ^rى1Y t" ޲}IOF>ԽGM~ڗ;-/r= d5vBҼ%.P}UiB)b7 =UjB0p(Q_NoL2n*l_"d/m41v%:YBn|fyC[kMEq],@$~q_VIN:Z̓]PF"n({ܷn$߽rQe#xx؆]_Zopt͇h`l!7dHDJ62c jVd+_U/ÊZ꣔2R Bds ^S/tD}4(g0NAzʶlrD6f&h#VF$ÕwH]3&܆[[^zI0{+.w,q˱.;H@;ɫhCx3lh*U ětc-!m ݲGA}cAﮖ-}?S{+nQMv7qǍV]KcOVEhwFԋ-$Gp2~~! Wekv>4x΅tR1P>ZޙE8w,zDRK9J[r#O~1:#'NLjCBLrPw @JXkE!kCHˍvbP_qp\ݞb0%?OI44%7ʻݧyhfo 5+sI=9 BYG Kdo;*HYh`qiOY;2jnhwj 켌'-ǀcT}#eՋ{(C8ǵ~mE㔂'R{z柳UkteדYćieDGٹ,?E 1-^'Za_4KݹN"4^X_0_e^++@]'WW!J~);/0Yn 7#q:ba!Xx0_Z=1בn5q&Mٱ{Ј枘t)F`>tӟ.XzMcZ96߀14ORpG E2Sq! ,8@ W`*g, #/[' | <laUc[f`)l'wŤƌ$n2e]KMz vi"Xf#/`31p}' 4#+ZQ'!lʋz/oc?GZ2!}+-c'j=i?v@vS"V2,}uY^(NաھG1p*,= R1['*s&stU Y>m8l!Wٷ`$O8;_bc7 !+< :RunvLGJl,u;ce]GKɻN:`i\ѽy@bxXlִ^ގQJBL-қ(X8ǪPGH{-U97Of`HMeRDqX肣bx${baZbU˪sAqJaCOQ\ҭj7B@!J&Q^(j_*}WJssSh7nF~]<מ)aTʼ#ct)CPRH"{~@W52 6u چ+B9]!:s:'#c>i+{q/թV=6S$z7M?)yqsw@Ԕ4>؀1Z2?tz3R) Hјa!e$- `m w da}Rx&d<9U Us^74)D1;)wz(6gKOcfFCXJ2;0_YӘB>xHۏ2_Ds`ndI|X5ŌwmP)r6OlڔF/FMYZJkCԼ ;9Kuӹ@X"p #|KmXYJ- cG`mH-Pa?$@~AH$ 2L9u-3%IjpZ0CXp|G*#9tlb{pi[]4مW 5ů1}Z#H[$%=?F(> ytvcJĿ ɑu&C*on\Đ|uQߟM+ +}gQu`] *eKƒxXw \FwK.;H4 d]9Pu7KG;= A72S߁"*}:/߄Q? _~tetQ^{@$Oy \? hXيo?V(iwusޜ߳v$;D2+Ydc 7Dɧr{m"sn )%p?tў]}FgWofV05Q"+S}tF̴>G7#uc37틬W !k7a! ˓ GCv_Jn_Wq ڜ5FԦ/g+I6z۟`nGY`lӃ˶3T5H^ gPRs)=lF?O ^? '__T1 Bg̦3z? zZ>bxg̤f"g|!b Dz \ 菑,WXQDi!J3z R 39E,2jꡋW -d\aW?E0 3-uO@[c;0TbYHӊ75u59 D'gۢN`Z M\eMae=TFlٮp/XM~ΗJ|r}:<u!̀DzZ/Wo$!xȐd,1"Ǔ-jG.7Oqn5k);<9qLp,< l}{` J9nWb^6*|X^5d R):E.la{TSm܏@?cvt#YRAn^"wx֋mVsKǒІԇރё"{<\R5CYaR ÙN%>7͠Z2}@Ex"=2CC3~De &7B`J5^@9ny~dK?C'.H@[~qyl)/{_r;76lU+ "}/i)Elx׫!wSٖrmvPNY꭫z-@B1xG]u7l$56q:蠩PA<2:wڤ>ߔRK .+9Ucp$">lG~[9-4*I4Oz0lƺv3ꡜGp )XbKYt|^̪Vk, d%<7μ?u>`cr,Q=}E_ԄT!jMQq]sz)B^Ɍ<v&(^JuRO{ixEqWCd[LSC5=UT1+NI4ȭZr_r=RwV&yDیMb[sR2NT!u|ϭ?l%xp>B2tH:G-;R!.mw*'!KJ3$3ˍ*ck10"X6su˲-epnq&ERDPC\0= vdUh'ObR)y$D_FXH} `B2wx }' (܄/6h#ȇYX͞/+^La:$aHXĸuý`\@gRpn3$k]BtH&!q%'J565{՛IAssnXnp^nSqml?/WMJf\_͸,KV,@[x@Y0L]yQǺP~c&ҦiD~b(v  f| I>;/g@J]ѳ3JkX)k| gW]%Z]]xCUrdsI6"QD*Aϛ2ڹ]sKcϩ. =~Q?.l\ ?G<, {->it3ȉ/Rr~~pjf _R(1Rq m%ӼC)d?Ze!+T "&kH$ӼHwweqio"cJ;lw/F_jV__HXs=FOWMykabW;%N{Rk)o/ƠZ][,[n!!j)~H O/%RJGW#6o#)#>Cʔvג `p %!ZL:x6)g&l6Ts_b*ݓe4{eO$]Y{C=6rI_1H P ?1Hn zF5dxzO4R-I6Q|, sN+%[u]Uh{\?vbEMܸR~3814Cq4PK^9*G+;O1[R̝H@D 3=x@2zG:Nud=$= WVCe 0rSu/b(6%"pL:)س)E_pƛ6SnaB; ɑĹ0 F1&n+bw4U;pC7pgAC?Ủ@Bҋ |2)[9ŒaJV% WUGyf8^Rjls+N9B䡏#V@Jbqaا)@!EbK7.Hζ,|Uu'^>DUoh9(EW pzqF-u6¨K=p]S ]:= kjJxQN(w;UZmS[e A>m蠴O,Z}"$l 9Ɔ~wWmTjݒCSOdܙ5G}?n7Vi ЙKB-#ovGc, 9I_*y+ưbfgn^Z#G7=g:ϴQݨi5\QmnJؖiCTwT,' ZXʝ]x:91J7đX&H8$m?.\j=Fs&W &iQ,_Rqj0IPYeVp;ֵ-~Vc;>.f))u/I{jGvYLDݴ'mBO2$XZ7[f2A[X22LEC-7uY^T \3jS%(ReTYx3%]?. z@J(77EWK*fp- 3rb3['>Ϊ=Mv&numF"ļc.'<]K$۪DJ{q% ՖQZRb<ϯA#lD6_>j@g^68 :$^ tLPu99i524D^zӜIiNily ?!V9ԍ}ќ6a2 q3?1©# M⼀ 4g=$&]Q,VtCDv$0 nU>kHSD'I<G'$&$F:P-xh*dm׹&n?̓-oM*" '83ոQ.buj^q",x/Y\H;ɀl+gʦޝYqN386Z |Oz⟣_rXjE6oC9x ln͹ qDֱUw'7k-0wh9m@l#'׿:~GgjpXdqQ|xD'ܲY.buPqLa-S]fn(ynSxC3vpbDg)k^yّ t)Fہg]}#`XK4MR WT }xt]n%*Lۖx/x 2ur-R/fCMQuW5N je j"VE:|v,[:6i>ɗ^p%E^l~#/O x@ϸuu+Uu(K;陦dB_[*h# t>5x+ 縰 DRȥHSa-E?fa*#̾{rWE [Asq|<\R'ρ7|3V$}ŋ:8ֳT$ $%O`0󟻥u.`mihJTCcKp8>_t u"7+bhFRe0E/jk$sqb'hֈ+ 8VmsğldGK+N.;K1.r)-d1 p5'>19v}ZS Rcĝ.gõU9*1WȦG۾*tiM8D=6$i<E\v2(@eQwJU;u>GNR0b唼9dU.O60C˜ )Y t|$-8壝-w륵Y)Fh>01X~56Uı_2w%=OFϛN?4՘D1&C 4ͺeV3|KP|dz(I|[,eD&f `DpI{3B\XeT$v9JÜOk߅ww'($`KK{z'NO'z2}&ŜM$G#m־OJ#Fnja^>̵OQ:=i͆yܬn’ܵ_z\m6KjRk-|j {_֠58fK^UXhW#TKB6о93 F+RI7o„K"mۻ9. r1Xן+&Oz.2}SH^| @fEګR~'T NuA=+ФDVԕƃ>W)gI Zp>|clU". k&\)%s )&.,n(jQtN\h{K|Sq]k7W\U|5ɓoAu|3X^NG]1 Smxm=䜣ZXC [-D~% d@TM($P h>_k$2?7/ /[H{ 3 69t.tKu{ʗH*sƊ/Z3'wqr-~:U.PE QGzP7d8."cuGՕS G_)Hivl~ sG /0??%Np)?P׋0DejzT)<vҾA+EI\8xgFڗi3' 8J]6e ] 4sJ`֯N_tㅹܪM!h[<˺}LpL}z]2kZp˶2&eXR`;`l( M" WKP*t۾slGn ^sR<)+D&Yj֓ /ޓ>XP它'r C|XE$V<\C.P+,m_HFk`BL[𱕪s3{bSIZ64RDmu3 |NjpV_C8 1(=RжkI|mJy)!\wIyLZ@xXq=?WT۾džD_St-? ˵-49%TfbQ+xQ"Wׇ+LYs_ڑ#rR7S<䥬PwO+E]VZnzO30EgD،/xǏg|'6>Ifi: (OM*r ~C؉Hyz|#*鼡w?Dۦ[-w+1k7ŽS/I::CBWdC}zNG7b>N5v:zN^F;0>.u>nڀ$8lD>E /vhFpd嬉-c5Wv*rA+'~twƎ$Q|yt*omo' *68֖.HU:Zq my4I_cw( ̶4d<%Pl c0W~~vv;+,{6o΁,|]w2ޡs:)NHSXT$ȐmTӑ;Feլ ]žY4߯V|o!XtkC@]BwB~ }|vr#Ft(Wy.r'oSxXc;CsQX(z^X2PSOX,Յ"Bg>hGvƞR'V&NxF2 L XD :QWA qY W7|sn:҅[Ūm~V jHޓ8=Oob,0IV}|W5b=oTi%ҕ\pjmBX"6N\w@`A"]mx<),"(aߗAI&6*\6aë%5OA>N(N'#퉕~uײa1CLjރ@nIfI6jDĎl$|t;髞SanZˋ.ycy @E;JaQ1uQ!X j Y0 7GTt䳫`: [p[b)"/6e7f.f8b`9 K%@ Z÷_.f1 gʓM8C[OT:ͶE]7Vt1T>Y?hs < &|YNUD=n>]!T|(g}5)M@xNs͵Iz 12h`Qc0΢] ⚸/`S +XuTμ)8LvD 8&q kE1Ѫܫ\%hjTtДUɳ~i!OZw NNdzsg,>NVh\nM8 nBz fYט6mq@ 00W*M8r[ʎ`QVB;}RMFzD\yWٟsߥyt y1IP ;Fd @O^5V(Kt6iEP~r#n1ߏWsC|x25h 8w[BxH.!75i/ڌe۶Z3;=jRB&EkU %хKNJG#=Tչճu74cmc22a?ІQMg8Ec'1ѕ _0DFJ1BQUGtXL@ӟMXB'u6nܥ`iu:mÜHZ濑o'/ mxٿ{s"DwcI\yW@]6!ݓ4ar#ģaCw6K:G`8ʑ=Ev, {V>]76\IpŴSdQV̉ilB9[2CR-6w(ǃo\)@ESB .maË?=ZLъ  `_W&Im&~v??- o"p3'=ˊ0XDwZ`7Lgp#<1䪂9dv$r ]%HJ1vHX֪}`~GI*e"X`ٖTi5+RfJMwFufNx$z5|αQSpsy! oe* [oH}%aSO~5wAc;\+?$s_CXdKh$޾Ex? 37f b=r)rb==yUs(il1}"v .)1~OY|L$C{# ngf\sD.S$ 09g~S\?F:X]- 0OA=Z{'ߨtyY7@spiBZ-f!-}ۑL;W.2O'Fɑ%Ju먡Z,lw>)(1bk;. '?IT_[|v!=,ڻW&I_<bxCcM5m~J[TyRR6;J3z|m,cx boGh0tpiEN /w ,sʊb mz]%g5bYqGd,iTk-00V Iq n W?J.}{LBx`!4Vn# e0 q8;>q{?Z HHZC96UAN:.&?z+x$Ptyt1X:R =5=` RFc~moH7jh#mu?C$ָr7MgMپBfV4,HS,sɸ@!TG"Uft,iuƀ*UEB::pPs:3Ol){3"zWFpgMwGĸe[tb@|l  EDn05 {fBwXAw=HаfL2S'.ׂ[ *ۙYOiY[`Dsv p~^z3sMDŖAɀD[hyR抠 głwh~M"/8T{p*zcҪt]C!ηB DZ`Ha5@Iϋ^ݳG6dY$]+̚)#RgxƫPW[}T1IId4 \rɨgBld5zzƻ`gGh߲P"PuNmu: &]UO?WH7-c.yw߱(:~o~Z#uiE$Fk_턡5DIʪҬ2bœS Z؛+'TcEgÐTǖ=oi'V`WVI5D_rLDgPi&=MY smXɔظ?bqjc5/5F0hb޸0<`; Y N0`c09*m*S Y" >$ VRGc =LX# kUȣOEFqCj,)rNُ.qb_\ )2yߎáS fknBtّ6rOX5HڍpyF@nTFE!V0˧4s[͓Cm{K֛tkj\~mLhJñNmhk;ul$ 밤Ό)OZOULa2aǴU)\OheprsU# 7ц"s:2G=wxJ*_Ÿ1%7msEJ\ Vd-%-&hޔWcJsIxℚIBኹ O0C6J;EC:]Aa^ÐxSҷ!0I9 5,]6S" +`֊P3R`lw 7~7aHBɔ/zN}xϣ4g>/5," [^(t?(N6pUgyJ5cC;-(ȯv |{wAx07sSfj 1Eq(0}’[M$w]=wLKk8#뻑Tm,.Ϊ[ ڀ=1<ȨM^b>z,6'FgF8i'6z"}Y{qcHC.ԴǢv6zĚ-9fL>(ƒv?h-OvebY[\.Q1tX3xV675B%Aaձs`U d5`R*epKDB6 SZBӰǙ`E"qHSorke%b'b>)<#R׮*xZҰNarHfݛ룃sqǩ 9ԭg.m ēdŶGT1s*'A2M#$IFv(lG1RGU.H^4 4:"J՜nGD֨L ѧFD_@bz2]_E`K+ U GrAH1'y#QTAm1, o2\s6b"A_|nVIN^RPx2inۃkdKxͬ)W;IR6IHV(u{SFz=DԨʭ%vTpZm=OL%AƔ,rv]?1-41z d.Lsq'( )IORmȡ C8 &¶ICzoK/୦zk u{TU-b8 zpiւa`gA>u,`Б&S|:ۤTK2[ e0W5+qӹl+j,'|昡mm)ιvN>6mfKH6av!V6'UCm+ P*q4`Tě϶[cC\Pd{^Ĩ Hl"TpW2=at8N2Zxbfox jeәFvNK*uhJlKqkq5g,g8zDDeCc p=i;f)J`z3H'ʊ:g=پLqoRiX faщP <5f`fKEcA0 AuPfU?كs36s@鲙J Q?WE' 3H|xs˲xā՜А(+[Fg['N2Ԟ|^XCƒӔ}ID[KOM-S=d֪Mub+]`0C8Otҟ_1G|+,y̎~~t<ܙ䵁fuoe(ou!iq06!֕׆ڌa5_*Nf°K s)xCu o#4W\VO5ibs,o8L_r[\ޙQtNAO* 9o6_\F F[ʪGh=AcXzGi$K`{ٝ~X=wb>/x8<qޛ~lߍ֬Ւ=Tw .Vc+~v3םcQ @.}I跫%7$RwUq/Iyq@`bs?oǘ|R \)LW ،*(1!TDgF0"6S~IWkO4ӛ)x38ń5bI5T~{bL|PM -2eӺd$eD2ZMzP7RN[&;,cժ2 %C&3ѵ|ؗcCm4 \nΉL[L5SHP M{NIbZO[h׬PkSfSJyؓszu(C*@O>8z'$k+"ŽujuZ1G%p$k Lr JV= Oa"`id QSuXo|+[G6pF׉"Î+Kg3IJBkptȣ8G@uvMY!@ݨMIz`Q-n%&WG@6yJբkI͎R1rF?:T;\ׂ?LZPS%w) s5$G½run{p5h'0ui̱`-F|=U@[@b8#wy}냚Ң Z" FJD茼// dqgRR/-mjlusNl S_2g1f@`kRkN+~GЖźy{,PaDc5iQ ~nGW%Frjlyby \b(:'>tߵKxZijIյjFMC7I]Zؖ3oX%Ќl7/ܚk+vscRr/5*Gi%h(Q^E?o>gn[J 9\{>/n$((O#ş[m 􅁂_eAD-֒S,˱4HH0[vZxbMD5M]̆OBZaVӁNizQzZ'U֔hS iR7wt4w flׄ&âڣ7< -kgx=((wVz#ϝ'J~!骪 yłѕ4. v>_3fwO?Oϓ<‘+ 3Fɸ+S Lƥ+U@gv4Ɓ;#G (?A9x[GSΑܯk.U,8=zgI7&U ށImܧؾůbwQլ! ntF=4BVf?G//1;Bf H.0GhmcLoPS  Mq`ezߦW%p4H6)ե|*%Tr^9ad#3PLlN)7c /)-d9!m"㲕a\M3<%B[136?;L?c{P&|9֗R%`xHth@IQ{AB*LI:-UBxf+½E#}SM"~kI3 +M64`i5Pz {U E'ooklfce\vdw|NleV$~hLY2 Xʼ+"J^TqRu[, f!;&aYLR>  J#dy ue8W ǒ*1o2)pj]KmPm1GʞL䕰þR$*B\nUzlO5u&"±eO} ?<ĚNb[vE*MRij@ו:C:RE-Xq[S뢷:w"^4MO *>iή:<Ou#*!!8|VRyycʹ'EaWPtӸxǂd>0$x"Z.l{]@,<38I?XhK?$m}"X;ovh7X|`dKg#Er>nvU!RO3AQKz>v`Rx1EZpLWYVb,uV͵!IHKs. )G/kByQ?{.WL_ JcYZMIOk,XdRN,uEop7ݕ%M4zv]lmM,rLwR L")/]ae-ra:T(˯%$;kFu#Pv̱TM'7Vy=Ȁ~SE½0 >Q -J0ؿGSYHSYbo}Xԇbj&8H!;Ŧr 064w$pdgym%m-Vk)L%1rϬd=gOXq+"V;e\ :_8< >+ODCα(v}DgV1YQ[Xjm~E8"TZ aHtwKd.uTd=>Juix*ձ:K"a\R)E%Ԛ:{۵jUśܬ 3?t;c u^]mņ! -hЛ,h-]0Y}WT{仌d"k'4l'ܑBo? ] TI%vC*ﳇ1$P P1<޵/ٟ)99Ť ϝk<Ǎe5Rd-01qk<`dW8kmsqLͤ74k,̔+: #ǐ_[ԍКBz'LRFS⽟P L]ޔ}暅r2ug):yZZ O EK4aݒH b>.ǝd]bJVL7;<_3h9IF /x:"D, M_#:ap~[CPXQ*bt+gm$޷xGm$fY+z;IK,r& k1WSݺWA@?pKqƾbe-ʨ /4mn !I&/R|}FTg9XF]mY9/c QKy10*/S2ݪIsgs{hY]o-tdCN>+}!$$1neQ{Aq} hfz 2*,aCH5LO_㫗ME^261&ΰz+9ҾW<+@n&@> 64AWZ1;@NĖzBx 6Mn=>ยfBk(eծOgƎ>I=0 ɥ&VǍ,Hv2&)SF٧cTXs9#r1&U9r'1&"4d75c3 áxNv> c"/G{( Xf`-D^/5DtukUu jD^l&%w)w=S 95ᶃSGK_ m?^%lvH:| uث,mt#]\ew4!%fz`0઒GLӻ[5 NS?ka¬س}:tW|aHWo;Nf4tZ,N˛mˆd,dQMJ'F;JkRe>^40ݻ 0'=o/GS,( Nz>PD,%?‘]Ԕx.Sh*G(oQ`ŞO$K 1=BE-HaOxELA7u,@:eLR?(Db,,( GtH&@'U~?;<@#RWy`_Υ; HLܱPVK*A`XY-bNz|jְԄ?[_QfDsAL㶸S\rhp?+C_T= ĒOb/RF)+; -a;ĄP [ǃuQt$jXE voHΖ='0?u?L"(n؛cMheTL\1syS}V\9q+K9HoybL$+ 6< 8]W^ ]42dWR-d}Fhw<-R p"WS,\lq<(%l(JFS.,=9xwgFG0wl#}eTLt6֖qdLY篤Q98~Y1zFeRk~MI]n9͓!@Y$7< ^Hq0i&L-#];r\QS_8R=[?m P-Er葀GP|laCܥo-k2~`mkz~ ٘+]qX7Te7m7DܰFZgF*-T\~a**C~\JznDO= x]ҟFҐVᜅ1# I2)(>W[g:xPEлTs23ef{F.KzW#vvD.蠹ωZ# n/Īigcq(fH+r4@F xMc|mcܝI4Ԫ kggg[6h^,=P߾!n,z2zgCs`j W EP_ZMiܬFh܊ ;w4*ԙoRBZNT}&_JՊمe;`S&ů(fR !OX'rKoauNљ&xʸݳ/|d'V9;= מ,Xijwm 7p-|a2SEcWo\̦[|RoONzxvϭss|a1pD0q[?;tUll};@s~SPxZCd"²1/ZfZwD(WD[b*(u-6#r#^H^RfH Mu5RpzԸƇŞPIqBFr48UX؇E뤘0*zqWߟ,D z"Ml~^ j%'E$r֣0H^>*.dGl̚)ܯu:j݄y5a)dk64;xώH+_C富Vj` cY@=Ąkh˒yн51@#4*DP )G?N1ݖfD,h*TvJRfGܳc{۪^^So(벸$pL܀l2w*PfEuhr8ll˫֕љ#y!c"^hHrRk"4L/{?Yy% 2.-zn%uN,d<"!*4B\}Xp!QGwl yH t㝐Lw>I = 2{lvoL:A<e>g҄D' YC/]an 0t菿8OGkFi\[]?@4ODcD JKXzF[k$8}dKQw(l !1Pu%H_[(֠֟odEKDŽ_ot7Cw j!}_мl@3Yvk`\g5-=|ȭ@oGS> Xձ˹7صMIdeķ%W΍QM 㵏XPd\~o yc?Bɔr5Pd.n'q0jۑE)~tHOJ+$ުI{)I`|+nAkb{Ó;'0bX ~m̸شY 6INQ=##L⭖}|W?P4r#V[H]3#h ;! 7.fJF#Ncr>Kg n0`ǜ=/uc@l eeɧA>%<bqڙUSoVo-r,A9!Dǡ<Ō'<U1vUgL<:xd'`G3,@wؘ{B[R9|l 8 >*r.puPRu2f`#`k.k nkq}s.$)u ˙s--0bNag['"tއIcuI{0Rrg7\Fq{5b#MgMZin緭0aYrR%-g!G6f2h_d|HܼiI YI/hG1^VxkD-{ҿVC7x5ē=wDcG{BmϰæSc,ԟnhRB^AW: ; YEw3j+~䳫'bnނf=V|S_@w>U1_ m{TI*~_9:-R$ZD&шBεc uۆ=Y[ kG[H@=; Ĝ\V2o!g="PL9wLKm^|628h kSm@=¸kZPY]%TN/)T/ϳ9>Iӽ9mx"#:3 n9gnoҮ,O{%ʟKVSA^{/cɞ5^e=FmԽ2K_oU:H}j黌8ELs %edK=P{wn3@Ƿ$>PwoDɯp40@uP vhZ߅ 4te*]P|]hH RpkDF{Kvm@WwCʠneq oDHv%nyx&/c2Er'2_]G’ҵh_:r]o ssJ=dH<Qg),*"-F3FܧSɉwUPaD[1e'C) y}e&UD g0E;UD*"J3IQpkSp# ]>80j` 2HVBړ1*oQE nQLَS)]_+DEBeA̳[M͠HJd[[!盉F UJސ.:Xb>5"Z%yyZA]6%r^W .y抃0Bo \>sc" 5)sk?Ƀ5\ T:We(VY::eWw\nb\.kZ8K2: eYԧ\+H@yVSN~[V*z@Ԍ1-.w5I\Y9.+`~.}Pi2i#D4zQ4p9Oȭrs;6;K'Crw iL 9 Xgb@%77poK6$Yx(H7ŨQ(v,ޑuFKzMl9P .rǎ'(k.Jmp ]{ՌR TNmy!=n YGT14^%84"gmg#6<32$ 1~Ur4~hZhGe􌌺B|KI3fh9JM7,& ZͽɶےI? V+<$⯽+/F!ǵ-ꯑYrt\ɾԮ4}e菼lcR^3y% ]Y>\ŋiv P.0@RLD<;9v@ʛ(Q<ŷ&5A:7;a[7{[)]6#ɉ3f{j{Λ>^/+s&4^jyd- +?֮FhtjfAת;gb{ xKިhQr6J'"OapMVYAc+8?igț]\ p)TZ{gu3>(ʤ+50fw(eEz 6tw*eX̮gBοˋ% CB,+5+vR>[\9=<l &rMA+*%-tt~ﱀ`xnUJza^m ƅFi99gh$ז/@+P&ZM4~}M7IʾfQ3w+Nj`rd׈Uo~ݔOT+rGUx^͊_Xlo TXÍc5 2EksK~4FA#f&)zJM u4U~ْvZw/'7L6 iQWGg؜Q+vQhT8"!$}=J%h3ظg,[_1ŵ7kTJŠ'X{}vã8QU1ÅXF72B}B_ Weov*N*>tf~RX[YyWSLA| N4cL`߄jw\Xs{) }x[or \9m4Ox]8>y@'e+2#4܂}3%bo.x\c@&wz0(-yhxz }#6w/Af=pGD%SsVA9D#x複c*N_zZUk&*lC#`4WM}$=^V O %Y'1an\;Y/ќd/M̧bA߇$6_Ge: +5OPHI,Fs0 Bg#6>ظWɅ']BNvنT]])'a@"5u|tLMY) j]Ob֥4 y$ǩ pJ'n1v_l)3HLi͊[<9]KAQպH_ UyyGPUkjTN.&1jdx>ù7DnLT]#Cj*2,05U7hxN]Gf }}U 4t^̢4۱ -X@f3rЙE++}es^^+}U r.wa񵱖D0 >WP[%Tzw2/PΗ)(!RGB,i /Bž/MXn2dƄuZn (ƨf76Ex )1_r(QnNSO8,:{vΘ 5{*)#e ZV3_'0 Nw}V4s=kSAI\0gLPP.ԱX|ya" aJuI+1 R:u~!W}#юE@fO Ab_Ni;Tqv"{c&%-v*sJB&?Cm^dt3+rr\Dߕ1Ƕ㱝ѻdVcbJX/.vɦiuZOKs s8/W) ԝz%K'@:fmJtRje59J  D% |8&1k:f^o =/Ar)ǚ6MdN|𖰻o )XX ب/S[SdESsNgԔk(I(w 2hT5KkgfL~\[_'Z3( W`DTѠ(9Nm\^%q!w\lbHQ]b̹3JatIL;b$ϥGz ŊO yT ԻlOtX9=S Kfz '`,mVhON0agIp\߃41>D|lU0M˪;4`.YuĞ;LmmjJ_Hrjf=p4}詯84 4~g*Mʄ/p=kÔ^"L9w(_C'Z7ga:aYʀnfW,˾lj~ ;]P{ Y${9m%xA>iL.9a PۣZ#68<ρ &J}dQu>킅Gz3ZG M`;A87eU(9ОU ؉[e5i(,X.V})ON[*lqXΰWD?F|*+%\z6~/(V; e@'{bVau}"ZV6j24|Iʑh h:Id mjar7) \0QiNÝ-ۡaf6k (ntNNs&q$7rfpt>R ܟWz4k ڶԷ ߞ-nq@,"B_skw=RN6'[b3>1PǦ D"8;Z@n#,DVh<5Ldq _pzӆ98e(Y1x+qFv8ͺk8أ}zYw֨' Zq@I)Ic7*% K"(% 6\9jB.8[ R!ka;SŸ-HV9X: o16Gӆ?PRBmu ?AWR8nIzRvK1[.*w"%_!mHV`_?DL Osގ8SMs DwV>|2tXLFwЋF,Zuxaf.Qp@DJE^ ;Ff{z7@vUi<x Sv=ɺ>M|e9Ct8SZ}ص:U/k#L`l=@˲7wBʃM0+V2_T0tgu%}pe8*4QS]jZwsh(s9ԦST)kfj}o6@kqv% !{6Z$}{gvTxIJ²T|]̤2"h88,B94q}%O3Uq5#`Nmg>eFVФ[ҤaZYR >oJD98J ;ѩOA~ꆰOaJI[*½J|sqEρ$6& ymڃKc$/ ,*;;T~dP#:TP(#U;>@rB=?X(j}wvWYj±9Wy2bI$.@D\ o^ѻkDdHMu}_fiG"8 &EH 5nFZ8s '(~td x)k~p\DNjQR4iX t<\B?GT8ki(C$7M-4W@-~y`W7~I&6BsOv9}7Wk;,YZ ;gu!I_{$AS(#v'*ea-#'̗O5 eߏ߅S;;uHܮ;teE2ܜ&$uh׺\:znuUl.'ja,t 4N[r6BtB-r`57D#ζ?Hx:3c;}z L tLu+A)ڙ7Ǽ{i5B)9 |iN5bc$]Dg>m/DJL*N/fP^?<oKi 4]N@AAS2h`|; ܰz3߀GOl#hF(rB9 e$/1\{ ׉|ku3O Ѭ vA4͑ dObHj QQ"bOcQDKzSP*2M[fD˜au6:Tqwʸ6\oSE}z-47Y'> \~^qC#lpE̩ RFAUp5^D(rIrz5\DxdWKxH.sb%T-)Jme;]vĸm7YWԉW0\bmE=5;e覬JD0ʡ j'-6HIRTw*,mR-wRzpX5}墦YT͋nNCxPkhsuiv|#',iUqߕY[,W3ZqCn4ίfc q"Uc!SMtrfiLTbOo!\y!ԞG\h+(VzueoϳN)|-ƅB1!7⊮%":ÅG#9aK/Em~$R`c6ު I}+4:,/&,3k6_ë^;DD.pA+%2X,cȘPzPpY{C9oв^aOތD+i  E@a!D: J{P!*>QPA}w;u)LiZ&'Q|yZ:)JSOJgSスG;"Dô 9a>Z=8"WiT[' o%BdnpG.yMIXQax\ha-qMqǦn.ui M| ,@B%CY8v %^bA~,wBH_眖rA@ӿo0_ .t6QG)w% k,H*Q6è hF!ym$|ѵWOxy]LQvĀ$)G"B>fz$ CbV< IV  őHBcQ/ R+ :.!zMZ1KCW_[$`* m(Z$fZker@Eq;C 8M0 e vهPEԖ[W@:3?[7c9Da6W碩!/0@X4o2%vQw|B^DLKXn5A3:J7F;b + b3LyΈ2dH;+ugG.s-s1脩tD8ÖW=pfΆ8Pp;+#/ ?ٖ lE5Dք:>{- B4|G:>{ fSP8+h4r\mKF8ig_m7Y03Tˏx"Y\Wlt >4h?+݂3 'T 6o8YuVaюvY-WNرCQ<7঳3Re})FQ`1kXžxh0YȤtK ]-zq7OtmG4-P W-z -7"U15GN!Lm7ѡ<Ă9u A eMϘyj%cZ7 Vbf̚it)I ~C޻Ss]Wmk`ywk3R-8|1NqlfԵn|&:Sb\Q ^c=owwho.GP}"녆N='ˆV\5#t2! DX֠JZBj(V~1Blԡ5r蜋& -Lx]Y2{۱=GS:dEuؠOɕn0`!cWHfwqBa~Ԡr%Q" |[C^3_0lvJ qlǒP#g.Ymt 8,\ ۿ[wP$OY*j* %Sv8(zPi_lJ+ySw(8QқG8Oɣ@h{G-:s1& )!1/@ tJUqboViV<1 Q7;y1-+% hL@< #Z;1CRN˪0\A[s ;VДIsTs_8 |Z%agZXB캒@of!Ng][Uo`w,fExp NT/<1ty`CBi%l|6!qP_|w\ e]AT aSQ"@AlM`FoJSY>4s2JKHɽ0mG&NJqjkR74RյXiSyZg&X#P1:ot_lL|@BΩF9HnAWJ;.. I*Ap1ʉ>f,c2JHۅB12cޡAo[#׸vO ~Y>LȵPJ10>T\+!%O#bpBa7c'IF iw/]SH'FmUyvem̚Е븈>|'ʔɥ'=9 h1j`&q &O ȶ hs4fs]~m/!dIJoK&Awp*ʞ܌:P𡻅oھÂCMۤߠѓY<!iӬ#~M7 t@dd6sSfR,BdjpNTcDęWP}\1BPSM;1ueMgDU%r'!4$עo΃PaZ:!Yl ɆN+fxTR9h=gqpm)/c=IS{Xqyɍ7wAgKȑݍt[ͫw9"?b8nςPUÛ?v`cD!%H!%z4*hx`?c >= FK(љ د/uoܬ# ]6q9a{Vxo s)$go/!Vɏ+9v,V>o!Fq &.8Q'a0,J;=M wH;`DꌺMa<~t Ok"Y?=PrUט- ITeIz*!Ffe|w`vx\N2zg(t#`lS5.T`(n-xˤ`&g>VVo͊Zv.aHhaM|C9<Ab\ Ax;L:j-ҚXr+~IBxnkxd!U3$1YrzﮕOSy dmx+4tqB;g[uΛyp3b\e: [cݵW}0ٿ 6+"p_vy[n:7oIhcky^ 7dvKB~ydz5cKi!rƳ=u'YJ=tLF]+?o䷑K=aupYo3(FdM~E|=!X]{EђɊY06ĸQ((b_ 5H@ f'a ĜrhͤӠP^~Nx:wLRI .Xu9zyp4ɾső ೘IH<(_^q~ձ0T^1.k& 6/y^k=I nnRpp]Om̹'Gpsk` * 5,[M}}qw9qKlTWd[{1&48sWBm1.ΚaRj0^t/$It8b+=}L#~.`ϗJ"%ҝ7 MH܎E^z()U8AyX猛hpe4`SnԓqMi_[%bpm^9%(EMn& DXaMȠۦS՛'_6RZ6+Xd+CT 8č#0*Y5|i m[yP)wNlO_?P>oo㊟Q bLj:ؑqM=Gw)b&<PwnHemHߋ^.;Pu#=h v5Oqd8|;="NcEƼσ~%0y;mC蒦g;*yPї4Vt1隹oX=!/ fz`e{gJq:{Ńp8߉o/ueSN@Ӳ٪Yڇ3mLvd檻{ w<0O]u#Cm+SrZ@и .#D_HvUtFٴ'ԩ*]&\)&}#D]~?nyŒ̓:f@)O+6l6hi S$NZn:{Jj7L'cI%&{EgOqX ̳hۅ:RP- deN' 'QAA)cWR].rd:0,eXmFqx'bOÿ5sn / Wx@_Jܢ2q6遞'T-Xz`ID[ė5w%ICaD| ͧ t1^W˖܋!W*7~0(#'k ^"[Đڑj/ԝ1rgKNSĢ(?PA2樵ŒXiНNhiEʤ-Q*Z]Y8絯c擻}#^u:v@./*x1u|J2QMK|-}x,^9ᗢT҈ xt2ByTVVq`ov^_fR'/!8Vi1VPQߟ}3dTN.]s"v\rpGJ(ٮ;()qܕPϬbGNg1'ћ))6_Bo#b>܁ X(f\k=eAp*4m%rUȦmehĵ (D}A4Y !v:U^*ڧ`Ca!X1's_v N o 9 V0Mi xeH 8SCL7׈Ϫ ֎4|i7=Xrf*g\dWa8wBc4AܝJLU 89G,ߤ cičnZEP9Вo L˷f  `!-=Ma`gG9rZx71ňf=KF7jۡ'YڊT P-SS󐁸;y>9Pۯ ij:P"$=3`(\)L5h&܊GDZI˸x>8xoP6.? b^OzTybhz2=0IٟhE{|ݵ]1#VnȜ )MZ0 ij&Z_gg1-1R;λLpR{7֝ʿ-R{JӐOZ5vm\sBݽ7U3!e]L&/B"q2H@P7,r4t!s+~0%;X1_&; H@Ҟ T ɂ\v~^]w,4r+$W1ͪ^Jed|,?7>nq&A0+16iZp¡{#Uj'^ %=;"&fcp<]6dŖ3N/AUOK H dV/84^2hVj>f7#FbDNjyy=?m0luۅn}2<޾"Hl ,C_f62L(QbOK[=:0zF0`$ĀYUCaq9 ؖ i 1w<(KyvXyJFz[ѿ̀<,QKJ-gXz=Nl쟭ձe4VR6_Mڈ4:wp)ynL[zVϙ+T} OxIvQkцZFSK*fېܨT2TjKqFaϙZIsЎ˛+:Sc=M@HC4p> 8 A5ًd:q}O(cxY~?kbS?yêHvrRr#" 4<){í) AA!w.ql7\tڇqƉfܷ>reTX'xdW=yo|y s쿔b~bd@ܪ !Y4U ]a/F]\GCɽLRDR4XYX70XsCϳw2%mFV&E-.X*E_XwbfKiR=@c7)G(l%D cBGI1/Zy$+cKnA+Far.aF~XEwQꒇlg&uu_7'*X3&@{=FR&mJ-M^knҙ7D/Б?TqL&¯|+ .ŕ冡\TDzUv`pE˭XIQ$,ݝn@Q} Qr~ߡDM,VǿrWZ'MϯJDH,l{n cXd2#_Υp|ߦGXnբ*s[Fv!ϕM'[[?gNLiUau#|ĔVD?5^`][TBh*iQ/ Bhu2-6v2nD)vA )8ET쿜9vN4,u R6@˃OI\ׄcRz:!0E6wl?0 M\C6h%?`~9 *128$r/]Nt k8X/>G.f~!^U`nBӱ5KcU)jȲ:@0nӌfꡧޏgoZۄyсf's0Dn9ў;"<P9|ZvĀ' /33&o|-h f ˰O }7n\Eow4q {S$̉sp):'qY$H2D-!絬f%Q9iA>42=,5kjÑ84%"EO{Zyj۫:p.巪mwgc:e'~-#+7W`Ɔ)O=k`FZ eL9OEBE<~}gw8/APU}7:*j%U=R0O,ٺɿ0ĻkGuk퇃*M>TZԆ~6m9J 샄xE&yɖ0RSIa)>íͿR^J xw] B*`YUKf<_Vn2gBk>:`h>3i|>t19pOcz w+^س᠔{tY&f>)DFSEG+nٱ^9C6 R/:t0?࢖3aL8;'j"ߊ1?\jN$C!Ęōi~ |r YnB(IkVy -% e v+ul/} ^xGf8VnLo=󣘇+ީN(kNX_z4pzsr/_?[3|ƶ*ؿzd<3T[DZϾzj.sxP77h?i+t}g^gyu beVa0ٞ|R 8;s,@7iZ:f5ǓA>Ȋe֌o.S^d28C5Eڲ/yJbd;\£r<@,xSkXOaMRc'|K~`~M'LQE rɳPL\g 'K + z\~h3>({ջC.4H"{d_2}h+z:,*a Gp gݸ d1 pa9+ւCw\-Z+^VX.#e>g `l DmNq'c0${کvIxFx{CM\M0p}!N~ `}hCi۞-1N0'BRh;ؕ,g AVو#@;Q b9ٺۗlG"&#8{h$AX.=h%ڛet1yZd&I $tN (4V5$$=>=~rתKz?%\4u} Ma Uc< PԞi9e,Q68abs0OǽO)h,I7VUbzN> "2 `f*e~P%;romYzAPdE zi`ANiC'B̖>NTq-x=)0ZU?6bY ?]PNs-;"ei\ZN'=' ̎͟ToICA_q&UM| Ml;!tyc% \3`H.ir"_ ѢT7~YM kRTAkx@m6gf^]|g | |؍*Nyzon4麰C5BuQQ<d/BҮ6ck7EH T'D&P9t<"[ rު{ Y1Xԣhhd’"eep: 2#_ =`4 UȗnZVsϬ3%TD(HB.aSȘKodz뜘MV"[IDqp+>ll ,%kИmҊ;L}-e3QSapz}tסހGvIZdd dg wdVNq,ъrabW hL|Qwc[*7v_E'\ ri{اAF7s>-'nb$#_Y[ޑPs ЖR߂u_p f,ѓa6G;}`x\GBrߦ-.-!E[/e6ztg8g!yp?B(pԂr%͐zLai:)  VgNn -aCO-bpW yH.{үDjZ#H9Paԩ H$*E:?,Lаq~qҵv|m7]Ņq羁q#.J5^ Kmڋj\er#n7qƖ? iWDVUo 9 ݽ=VHN 4U$9<Zz$g̶ s8{, +K'g,60@J+-4-8M|ꒋ?7 u ?NXXmW 2t}u/VDi3(OlIнXn{p +]ޒM8l%hgU e.=P0WܞύbS-d)1"f"Z8֛jlt ϦX{;NxQ4or]'U)AY0O{`S_ۆlV.'d'_g%Q4@Hi¾sQ#T^A_B3g;|{װč6N@Oz)mj.kS׫cU5MOEu{OKgXLt*1qPa$iBK s}-"blJL7qIY$@CCk8RCFrF | hHP;PZXMU> "I:ij>ɽ<$xN7`p^7mc)ǩ=WE #9ϒaN2w[aM6جx >QAE@v-tR ?DZՍZi_ 5 T[8%;f`tڱy\ | %1G/}bp [ f;|@F+l@Фm ";6tւ$X-Ƕ%I`VlRGL6I)RRHǒ?F9}]P i,IO#>xj7{"/ I*\Qފ=y_kbSPD'.=ڐz@c^2\н?;T \ļkl!nB\D wx}8(ڳLJO4S^CdiB<;wxnlBTV%㓋.vj!LeWKsis9օtdj=uPEE50tE8cY -nOoէYN4ҵɌvWP_~㲇 6Ƨ|)0<W_("&i)zQ>(il.􂽕z/O%>*4l!\!(;(@}=Yfk-P%G}bLEn0y2|sS$)Fa}8h'6L%7˅~Tڙ) ++,H/"v+f`ѧnŅiV?11Yei5X{$8;m[T=΃坋ģq rox,[&t 'W/\U]o|p.qN6x7Wz jهn װ{i0_˰\z6?c[ƅl?^YE:HOzi}Ƒm"辒PWp9u՛O*{3, Ht19Xf)(sS1J+Kއ6v ]CTv#AW3=ЙcJWң@795yIv*iSxs@j+2=ݎ=r 3a'ImgYyXydE' Wɝ(e-OUeK#^գc^K8BezdP.(8dA0ΟD<$P@iWwd@[=XoJޥ$Cݣf@ƫO ۛtBvO{pǒJ֪9;vFh77 rp\N#ΉcQ{UcXlǵey'Fp&ɖ79;Ku%G7ȖOo`$7m\b"+Vպ,)%E4F:2 \ !g$H XbcAHc@[Q;#tI48Y}juױ $P*u<(\(~u)myUMuY[, +lKLu%tF)rQ4fڈSEΉg0TPm&ª깈|1U8m<1܏4:j!O_VHZhP= fש~p^,M+ph)öB鿖, sΙKKl~ڜ2T~i>H_U6~8ēxT":؀']QMj o:Vpnh2鏟u" 0S*[DapH: i,E۝*NW5Sx-S J?ro3 v0AfV5lxv8{ n9vwaĦdQ$`KMb#bф/`%HOv456]A(OȣFDʬv0x+¬!ZI^ocε/8lNYZ Ⱦcqj!1V,x5/\ sXsV#iM152{&cZ4@oȇ](qK$ HDÇJj c^.zzµ= |?'{}^Gt~hFIQ<܉c}rV*e$SߤLχB(zֿWf#@Vbh+`mR#=mڞsR?`bgtJ_Pb8?`Y,P_-5Om%.TeO5l-Q}7/ ;_ّU=ŘEE>"Gl) jFv~XX_Se?),p7Tк-A3հJ#GOEެWQ՞UX87EI{ yl=g4^]΃'"B}S4n R>VMeЃa}`ԏA_Mo$ ⭊A91a|]|;Z)6p1ݓfa%/%32bƉn'94 6tƯCz7&_RsRiVw<!)!3 1ξ_7K~1:@kw*AA^%^v`YU|%yH#MGM<QNѣ>yR|.7lp=]8%7nMQd}!+z : ;K/}!l]ebG/!&s]6^뇗; ԟd-ׄ‚y}M%T%?%&DDMWl^qΪ?houA{)W@5U-A1C<Ho]ȑA1V6Oo9.+џ_%6@oFhC0I EGsUiі̾wCa$յg\/c?Cr }.RW7]HO!=Q|ga"!]@"T`.ΎZ~,4 M]e&I%6Չ^@aY^'m@,WaIk K+kAQ"^pi٥y4:u i d^ >yEӢZ7تtwV_Ň02y$%F&ڰp+^0a Pwt+B">b*S@}L'^ᗫˎfˣ%(dpE Ђ9og:, a/ӧBM8G7K 5w~,lZEo,/OdK1o; GojW(/[es|K6{q br(7SEG<m^Ya3{+gsVi`\ - EW뇷STV)~ich Œp1^JB zG U'ߎ{f|2J6yǀ큺N~s [~>z=٫ק$ܼ?;sMm8L,jE!GO)(y=P+ 7WXY!0hA1#IcΡ´zVB4H}yleM4–8>CyȃKu{wFi1WAdh)b,d?+^ZydUљüJ0S2GF>}07R IA5 T FUz\  goac"iu-&o,td4  0pqxfs,Ҡc,3Lmh?2aU& kr~ݝUZ5}Zᬝ`6FG8цAf%$0M-- VrQ|ҸKa!UsMtD!ҚC_ 9@nh"sꠁE҃Rp`a# ЖP2mtCcyZ)noWPmJ2kC!Re7H;: an4pYIvNC5 ,s,GD&K(}bb `ܕ8ㇿsJ8"|)B !sBuRS>d+‡S@Hl ?RMĮ? \ z:kM?_S G#KZTr_\;ꁱ{?Bc+>Fr}o0έDI2 B e3@c>ɮ8<|Ԁ=?6v>Ӻ[/Cz9(]; cfgIԸ k W]T*detl]'b|iJ=} ጥ'Is|R8IBYo~8A^W.6Ck{>ߔ>[<8ju(j\XZ;kvdR11QFm ȺoW);!qB`*AfoB,>r4?>fM[ݚ2{<}ؙ m~ |[U.Q4̮.leh}hֱ'U;[gi9~Uv[qj훪imݕ">!gݡ*$||Kmht]܋M? F20P>9` Z TB I%z= qgBEn N;6xaX]|{{"l[WCMք۾^(-A"N% Og'Uk$qENߏ? G,B6 [^{Gs+|yymݥ+`7LyK5 `*H("_>fҠ)R Ϲŝ.0lfT 9hpƔBcuJxf7zhЌ 1keiPKX]' =.e ŠR4$ ~}ce vh@I0"" Ut#ɰ䂫 6hxxu,̃/:*@j & F z%~|2,5LɝW8u4z EC|BL4^^R W+R TR&4"ZBD@ ȁ\4d@bܪCw˶847Zz[yS\wV?28  W<<'ы_:3o1*D*=G,cT_K)|nzI}·.g U D |H %D*qH#aj%&PE$|]>.aJ\A<| sc-/U<fq7J7_;{E}9MROa R2P!P;;(bWמCVY vFr(5.`>k62{ǖ("<b|;q%Gzh+Ta1& ҈a3 ^C FdDVBdGJ :~"UoF$f ̡t~ qm@c H5 %RߓI?#hѲk-q="Z,MI1&+aذ\pA/TM0NeT<Ɯ5kyhs?uNlWB>7<i귇?|Ocd-t!ЛPш{z"2SĘ cߙ%>wOw~!Lh々Ң59x?w3qb&; I /2X)#yا7~Ntcdyύ\ԈhЅ^+MI2vRYY0"D|)x4q1Y`!U|:u48ުu"%~O Jn)~{W?'21xF~}ύ=b Dc)N)L:d9585șFCRUCFO99%ReoU4me*<$Y)_[TRgpǣ$`OR}ux3)>ԧWaܸfbB Cz|݂$G篦S3$ !2rkH-]s5l\ Sra GmO )߽}-[nϻ }dOw/7_[߁u[uH.{xyo?K/}dg(9J*%rQ$k5CtGm.X3.ꫝ&li>',-<'S=8m|qf퓦!6ǭJ8~̵f=O~d]=4/)Oޔӌ()uY?:_IMtasXo/ 0$%s_OhCeuF|[j}.)g\qGIxB]g0c#R2(17CIߚՠ!yKA8]qL@Xyؙ͙H.Cc86T2U6p|hg1O}ܾ3hqnO&T,S5|D!WJIh.92 >RZ:/woՎ! yD$zx0>FWOIݚu$ D&.ZOf Ԯמ +2.1#Ps>֟F̞}=eBp/VXݗ7˨g5_{朽Wf>6guVx{_Wfᐁ2ގ=t`3D2=mn Kw^q}Z{}[ReXL뵎 R#*"bg¸dgndS86N8/,4W9c@hVG7eNAg&댣˴o_/K3Q5>fGY=m֦B#:q E* a^ 67|^'r\s__w-#PW7~ʤg5oC8Z56DYYjN,죒 \@@6 ;4xX)LX-SkhN7xW![*v1yuwM)eI%O_Wlӽv7Q^ս%&A $#^=>~-#x=HOo63O=E ;* dAmE*HS&wL~^:5Ɍ>2ZJE 〙eS4K.~znqp88AJ*E>}]=lfx}te <ٞb*Y:62XtIo}( o GxZ#}]8*7T^""uW7_}mMV} PU(d'J"쁐7.°owm֖M4 bᦳcw)N&ũAP 32"ʈ"To:{9<Ǣ/ XCs/C'J6.'/B G~ )+hEk E}t0bGZj63,g>;v6৶o |"q`|Om/=_!6tl)B,@#;xg&Lű 0D2A2E:2#iXp ٝ()p(ѐ! D@`aHOIP:$!Zg7Q 0X_;ʃNIBlvq]wGﺴ?>I>Ǚ|D-y)쿓W[yZW!C3lL~W@6um εxĨ)9zdٮ;?hI?DboRGru/)',Pܭ"cݵhRO`ˁGNa3)e~YIv>;6@ym(eZ##eјx)526>W qSVuIPc=ȯ~W9ddo3fb\l6{jCA)VU$ O B?]}o~kW?R>\twV3~!Zo=:㚖B [g,;;"f 9%b,V-*6BXL~$["RIgqnbzfŮMVig;IS@ dP h$ҵN)iz 0ڡݽ䧏42t$ 4VnFqe*@3衑g"ar| ZS&`_@ uȢznyʷ  1J FD@a8#*EI_2,[.J&~nط<)dJ>%\ᑆ$%(_cԠb]Q3uoo͒BP⢒$s瓚S?'Š$!_S 3!J$a<Hј56j}41QfSD=Bxo=Mϻtъ!WUD((tUi4 $!5~(ae{{&H\qM-es~?)YN2Jpndy]_ME10dāZ696akIa;_B8CVPy=`~T5,>]1S6H7~'ڻw^+XѸchy'vQJDD9?16NW EJDEܷMxSùEQyoG9\:Òٳf&BLug<"MO kfLna_lrA "9*I>sW[6u Z]ٻ9%* Q{ɿPo઀ŴXn5WȕOu% uHvg=jK܎ #N Ԕ%הOWYJ" O愑sǹE+bpb d~.Lӎ(8 !-z\>.(Sw~G;8G0D xs=M:PՏOdZ"'M53lF I)_bm X"2mz(wB8)\$;0\%/gAM)Yxt(2hQ#Q$fiA -,d9oi{FeUOT%H-}^D8(H8 !;PVbYz$Ts"ƶzZwg꿒 *rUV@3 STW]'?`e[gm^wn#Īaݴ`/@aϸ1ACu}!dn 窇]RP#c1e$Rs#^|̌20}L=/"Cߙŀ"it#H#~v#1td3o)=T7kD E u7٨`Q8B0upa bH0 B꘸Hdcx`_{lz ʲnb;̊D+4WtW٣5 5JI!jvʅa&4!>1~?)Mak +q&Oc4H#4!H~.]6<%8,R()'x݇?a8JIR&EG/|<\p#~k[`8_Ҡᗚڀ;,ل >;9*‡ -рH}$vja&1G:N.sroZ*ֈ# si w1>hAkd .䕫ĵVC̓<<%KhHCXaP~/nؕIU]8Qc;MS %rbђ" ;!IU\; y}l>=[ƅ369P 22O>.`1إ Q$(ϹF}û"F*$Y\aV~)QMҚ ҨTB6ap`&k >wl}Z@5" KA+̸/(>iXueQ)Mkv8=r\?| 5":k@(R hkֱ6u@7'gЯ7yּ?1g4łDHbva]|7O w=o˃kƨNe^_j{goN~E"/K \6gJEu7̧"&Jnq$ipCV9})!tog ;l!|柄0s[ؒ:uBQkG/ݰgrJ\YI͇+&TJ̨NO3lS}݇kyC ܩY㧁i/܋a?K313niͻlVn&g]HMÎsS cS^9|BO8[]sYzXޛf:]~T'!K`C-ɻIe [d(Y\Ln|6ä8Mdh3Q<7='dHLiv|`PHh_z. Sdy7}|B̳~!ԣ|CXk{{_I6NM+Oi͛1P!"v,ǜIN-}{ԛ)6-:Mvd-#JHEJ|e5;4f?ݸ9 L6hs]> :*TI=rVҶzTM;7]v*b[#Q^hB0h҆P`%vpѨmr *=x~e=CvDrzp%D,h7-P3[.a|: w%-qd2"AEA: PJ*@ aMt{1|lUZm[rFj[~H̃J{vnٺ;a0E+1sܦLdMesR_4כy\wвɀRN}(1!Tk+Ipyބ X2YçW|]N!uF9v6ms>e=kb7׵[{Nf'qޘ/eO̝:gu跇{>I]Io1bi=#D8;:la@iFZB8 zY ˺YwQaAU*5d^9:LylI'` bsdӿ7 `v'P4g?1Lϻlr1rcNlLeD ^2 j%!,@)!vnsڍS1hnôË f0Y|ۧHG5 &mVs! H5ؠ$AnffFhON5yd8"a8K݆+7&B&2'}Gn'D3XllO70rBv;E'>M{ibCesvaG+#~tibU["gt3 HDLn'~+ٔ_$IJN<&97>ȬK0̽>}i$% =auGPLKBLBKgvu ^Rgf|4I^^lpMxR8H< !N ܀)rJ73Kw{T2L`WsK;qVܘh Z4v\}׀\݆&-3YsO@t2 /g7VgW)0y8x̉L>{ooҴGGiPg7M6s<I 8 /㰵Dxwpi^2$~ f.LOC. ~ [؛1Df0>~< Kqը`eOֿЧ+ 3r7 •l$졃 ؈nMXHvycmVu:TRmp(LbT \;g.pv{кHs! 8s}5K߁ٴii՞m9'rP:`|{ { J__Gekc|nu_t[ņMHnl\]htHa;Fok⟓ gϗQaf]U-G%LdnLMm_SpB/'~m7u9EOztIXO778 "w|WU1>N!SߧgꏏgTvffAfd`~;2 ? $DRZ5X@J09xAA% m5Hh~>'YG+V%K"dATPGI! zޜD1ZS2ZS:bL8"wsNۻ.n_>M?qX%|ٝPG E!@\Q^*,B<͟$x' FʩCTlU1H0%@lkR-(ly=^d^ykPQt+(R$7=vR˔#Co)_w&aNX!(UP3*L0 +MiLZES-*k(F@bͅS(7{1gWqӏ;,~*_'~'Kh>k:t7&<2rBr=ùVATagOP-m>j4CD7Hf.:HhRJ%Ur>ә.G OoտqG;dxζp@xq-;NީpՁ  jU&e晭Rcf[*0J #]gnoT8c^.'H[0R[I?, qJj7`3ˁx#2"c?B$$6wUh"*'#L /?EAow]_&HRV8i{irzWWק}?>sEuQu&WqX!{q%et 0)Lk @7(06,o]^='g`2O?ҏ:[OL R*dU<(hS :δ V`|&ֻ+1rHf~uUA~J܁?t~s&٢hLMd.,7cކ3 c:wv='>#i2fudߙꫠAԁx{yHm:xcM}~C>-!|$/n\UB`=NZuC 7`LŁ_& A/sot^-TO~TE"hT޶( }]DV 6J^ :&z_ }H:$\@ws> /_5o;9ʗYkuC3 )f[ fhKƊIp1h=(~q7aBk{7c_G~Fh!ͻ;t.k0L {vt%6(Bb C=%?{#r&n[{7eQ#@2HGݷGGdz{gj'z:P 35"Mw(/_ۥokiBȤTxըH-flP"T(tDAϥks(=hrϾk漵j5ܠMmO"RԪۏH7z|,N]y(݌_皍aŶ%"Uvam]xo}os+}"q7gHul]tr3h:Cn ٷ4YЉ 9hv98@I'F$̀lCd3L96u*[,>T[Ƹ1K{ 8CmS/.^_cxS't9{eszgab„Bl7foP֚ t%/ 2P?wt0!30÷x^A `y-a3&ˁl @A s/ ))URv騏d,a@]DC \{ ,%Rьǥ ]_')S7EcZyo?>΢MR̓$ɻNז[qf_6IWr'$6eQ87Հf97LȔpTuq ] B0WB7f>LkI!訩/PlR-tz\|G~s<Uq=\XD_Plo)Vڃ +>شU9v iͤ"UƘG +=Zaա:X(fG#1zBEa{3Ϛͦ)C~Ac ~Qk!pǿ. Zw|6ZLQޯ-!O]yIl:;pJ& t)̩e0@q4`Ѻ.Mqݓ޽x̩uSmU7݅4nj8Fta#5$E95]f-24ճD0[YTɝB%@$0JY^i:u0525[M#4O0sˊ41`7cWa1~ᦿ#MdCAC7Hpz[AZ i)!PP k;FC*GjVgGogsYgwyXB1e"`]N#e$䞮WV$I$YwfH3NcN|םOfݯgsk`x뗒;^9qghhL,ʱڊFX\6r҆0iOr˛:S rv]f; x-t3 @S9fPغ8q,+LDlzyTEϐx_nй1?^9t30`C(~&+ 9¤!~+C3)(71(g2ǮܝEEd d&=wMY `;gP-(_wE V2P```Xn4ڃ!Îȿw?^z'L!V'2Igux/3:f!̼n{#۰oˋ[ju(*qbr$RE7..Ʃbimo?ɿõ$N $' }V8JѺ#3}(%?bYx4!wjHH0sHaݖ ^vHuс ߬}YZ5U\-rfn̂?]YXH(đU+fL~Np/0eS.3 Zؠ*RJQQ-%0l6#B~!F+ t!0ƙQ A׸^L71ZSl"9?an~>#%Pow<&7 o @<6g[tsU_~Sn:m $dtY|M#3I-e-E 0nVoqmط_~j-w)V@!I;?K?~g DRYV0^V2x7:%#$nDu*$q[h?"?D͇ B 7s ̽4rq"C a:ikͷ!yz2~mۚw ec,0?{\92_^'ȸ/Ʌw~?w乙H딘(tOՀn >_Vj|=tG\槃&rCذ+З 9k[sŁn8ϹIiәz}"_2-v ;Np[UnY95w%’c~">F`=+37!V/sw+\jMߺ|=^l[v/4?bf74|dy|mmO4Ӭ]|ep<'uw[̛]+%a7`},6dQd=rZDU3ddV28?E0Xض/i{L,:+&V,d2 ((GC X3B >+bU VMfR$l>RR6>NO&Uoi;Co)qQSnԐ!ϲLo^?%taL7=2#BHAC+1oL`?>x}%2I]Q*mK,N\-}&bT`50^(fɄS3Xh2%i)i0W#$jĊde/EgNA37g*h}{8ĕ7Ȇh?TBP!7~'"՛R4 )M( ,6ˆo>X]g[ 0T*1ViQhGi:YEgI'E$k'aw}hAH!(2/ĉ DdE -).3>8e{arF6ޡq?YT2M۔C~3vCjVa ,ξ)xȰs8֏wؾl+#0As-׻tݟS_?4D_; KM_Kwm5?)P9u777dƨSgݫ?9=u>o.(}/˾1X2wwqoI?U@vEޭWoӡ{ݮCT;T÷N1@oGrɐq#úc(q [ں" !̓wN߻.g6'd]=rl春,)칞`.Ftl8MpL?w/ZJZbuMsQV2l(3Wَ;VQUNAjtUP2XԌ!DÏQȢEEե36ΡM@1>Lo2Oosd܀"o_Y>dO~<_JZyAW p(4ՄhX$5Y6}04:2dn!hM9bv}"}8$rFKǻl[1D<&HLGZ,1z##Y ?k+&i#>iuYPvωFµI 9Ak7"9E.LEs,mm9dӓ7dnm፥%^m _Ocr/V~3ۄ}RLSGL 4N3NLUUC]KMs|Ne:N8;;LG&3F*EWe{IټJ)b`K lO2,sVV@u۬Eg0ߗ.]c>}}aas Wr6S{_D߯fs$3s`E`/skQ7f<|//#bfB&;zP%Tqʖk{n щ{EJ!LNpO*ڗ{E 4CNE{M/ftI*ffYݏ6 3sz Ur1ח>xxU.gy֦$;.&AKqW\D)uۧ|G'lJC.xtm =k銢?LS}+*77lOXYH33.RbYT&n4Mđx!ZqoaNIkgjݣ;:im/ʿ/闧& )O]G;NOy7Q)PRAu ͘Yd|~xCs䤤Y4[ =@!`TRDY_kD*4 ]~}FnwsR7AtzyNu9ޗir8*sʢ:TqsĹO{zTINKgkl߻ RS)pcw }]Jv3kG'-\jUM*=LڏL=.5<2GW-gNs#KĎ\slS:-gb:os`B&vFR]=߉]-i.IlBmG9II$7ŤOmVM$C%.4/q2iQ)0;@ShE>4;8ܬg6Y<|s_{6kB%S,Hm[Ҏ^;؃d%ᶄ]7$}no'BkI_ќt=6ksw(O}P;J9>a-ye-Y6߿ԅ(s4szyLf{ qh=lWpSs#$m팹F\뻦^(pK6KKʭ:@+E.&A 5/ vDs'[x;!=L x20=l_3pWG_hZلLZg tr*ۀ^Qƍ-o߆3< [!$Ful1M~C'4\!2@S4a2V1Y0LS &~M:$lɦ&7CN%SZ`IChCϳyxG?jQb⃕Ct6{l6tr=^{ Js]9> LUcU mD{`Vه ľUT9 eΌ&Ajz]܍կ0RMJjլ-yxy9{7O.̥f:mdc?{bM[W9+e*w?}gƹ(O3\|̻p4ugvÛ*Xc'6s?RUIph]nurbVM5*nN7G^a䫑n+5n`}ÈC fGG)м8iɅxKϤgNx[5H+Y@;Oz=]%azBԳmڭoF1f4w8v\tBF3yTo-y[XOǰL;U"ǛXy({|O>%/g%$7#Ojq3c'1!?<`@sM%I~`0ds8}ei'1Ot 1*R%7ٜx(VMH^Pej"&1s` (MP7zeٚt&oJ4ѷ5۩iVdq-Ʒϫ FX6[Շg^m ڐJyT $閵{5ƻ}\jo=pvr/ OdRv`{֚w/%gؙnR]# oCn苟iLwdl]Z;uq:֘>~e gp M¦,dno}<ӿFL6T99ήfL?yޮQ2S[n8䟭ga[<9xv'covilX-`S>ZxbM+$iM;]{ 7(Э֏IΝTY4=\)mց_\!˻_kaѮ8^LF+5w\;S vK/Iduyw.8"(PTP2{f9ze#2y튨]qNs YuTڢj,Zs䚪ūXb`ȕ0Iks(9Ql]vKJ%e_63IQT3ܼ?1,˪9dȂLC/9`OU͟W޾(,^RfM,a;aHjNRŘņ  x8{︕wG89&=f B0L- |.$J¨r * sDEE>U`5"<8gtkǖ  8@XLNsӪϵ\X꒖]nJ)-轎x Tۯz~wųp,W>zz=xD@PBf$[ _U8m.ZK4 @Ȁ Pl|,:i+&:JAԡCXjdUր^y^Ő ;*jGy=Y+>8IB&DX3&w+)(1!1NeրIMɏ?MJ11;=W2fLZgZܟW:>$N*5WpQT:ǔv ]3!@"1FM@J4x79*8dSh_x5e dRD Hɠ#ej(%Ec%IfM3Ÿ_ V`q1Ҡh63Z1б5Mu{m^ 3vj`D?1!P 5UXi*.oo8?p0eItB |S827ϯ[xs3<~6[Jd+I=>wrK#cJ^;q)!@BI #JjZU1P:11&$Ʌ`):Xk0(ěu/%Ukt9Y2$jN'H;ij9iI @^mM()R"RTX Lu2H`hM rֶ^oiۨذ萪ԴTXY—6vH*B: W^ٚJ{֐o(wc˅܂ @CFdYD  reD1M =zI-3i6 zLVa I2Lح@c71alB*zʈRL%L 8Xl3CAd*% mU¡ s0Y=хC'>ӀPqxS Nj}ݻ&Kv0/T)LB{A\0FMKMl$8Ç|޲R Bq3m5f*uNݻXXQ{۞6gv(NC`s^DI0AE!VD#!qCNXY "N8cv)PJ-IQk׉L'|u6LKm3yw'ILb,8 a,"`Da i3C3ta|xXS8LRa^:*4@Y,J}g^:Ç ,˒D3->&Yw f` zlE"7!!Iḓg9d1Yacjc!L*tY0I#\NX1IY3ݛ3z䵂$TgtuDՄ9b " %+"r2I42a4l.H9y9*ٮR:..KMp/ rR1:e{q05&ˎPn2<&ɢiiٓs9Nc)dxNP-'@d++|Zt' ^l kdDWr8^@r̜2ڪyֱ݆KAkS Ӊ;c0:0vMbH",`)P$\ӭ$m[;`Q*#QNћ#ХȓR仦2q$1.wef%i:k;s08P$$0JMd@CMsM⁄:vjLi;LuP:yA;'M۬CY[`6YenI(D9t7)*T'W/"JRW&Bzgj^ce@eC8ݴS 0yĦ2)`[,eH4 MBjLyt+R@M!.pJ.lLݶs \9DAl9L8 a%QMCX&\pU0=Xzp/6in\6Jf3i"sIyʈJ9’ZNm69͚h YI. 'I#+!:N$:H@2fw@7-0;!BPJ]PikNtޕϗQfD *ed&B8! )͆(B:7_M@Z8ȟ?/t ~Do|r8g,mO Mhr=os`::R0=qc_YaeǂN)6pg-M?uÞ/X7^_rM~k6ȓ;~dAߖ"(}PxrH)4I ?E;3љ;C;=ֵ֌k#fء! 3춣ЇTHѐ@u#+o;޼Sn;ԥ ,\,]RNۅ1%7 Mh=Mϛ-0zxl>nV~ӿ6"K)~U" SEDC$z*50fw*_;7m3O^K9utmzNs7gwh+emWךp3@|y< 4棭Ttb+_1)72.L6{}9z~ 5ʀqip.Jn2$f[b˱~Lܧ;2`';VLeՖ *w@>4QXR+SM鷝kXi=/4UWP;n驨TL.5.+C6FM¡Un>C"C $0g}o }O19^-;ͱ#t]mj/"C0?L4UiKm4YH)Qd_e rL _Ӌ_KC~<&nw֡^';\@0ޟ6&/c߉'EUm8JK_aPLQth /tk&|(fkQDWڀRh`vDH肀/Y?>Yűo#/_"Z}\IS X \rd/ITPV;F=]*UKa9j,1Q<(aGR(YTVY*NOǹr_?o hCB_`$*-=Ũ s Lf{cfe>t01y;M'X3f˂PU'C\|]5ͷj8j.|&7Nky~jէw{bO6rRÊI-UW3e^ʦx1L&ʛPx-,FBY$G>ںPgf@k%V]\wv7NN m(JVKmurݴ̲w@kFEkNˎմݻJ-w]%l]r)$ʍ-֒s*r-KF)eFwX h>yPW`w,  u0HD3]$x]-@Fy.Ъz79=wS`ٳ݅)MdL.`?0}:Vg3N(tt H$v*+wE6sijQDP;BxVϙ>դ=8'/%3ЀM$-\i@Aߓe5K-q\,ƾ=;#HfQ8D L6B6۳Rwtא;cOcluʬLa(V 2S^)5w *tt)}Z?|} N*s2HMxiAUEPUZy}O}'#XSڹh6X-0$#jr:ɣVh]ʆz 㫚7p݇j83N5R&G HIJZ+"RŤ(?9U'i/t9Mw.l_Ƭ]gCjOc}J&HntDiބ3vM1N$1ImZeS_r(qT*tw;¦ӿ~"wqqnyo+7@Hpg?V]!z* 7tiͧYYP'/z8⠤Eww1|mBzσ~ߢm 0eI )$y{ iZn]:|8.;vpT9n7biqO_@ڧ6Msݺ(Ů h|~lMƒ|kȜ qہD@F9E߁)2WZr.aH~>I<1WKV8H3L(pyKx *3 ?fZ>iq*2 pw|fz6PdJHʉzcxPa8=oNV/e[ Ӥ}&bxS|}sqqc睔t 4.h0Ae"qKc?oBgJ!r$-{܆۟.D.sǣX}cע۪jkI[,7~6|ϱ*J^_~{~KݺG[Eg|MWUi[+Z'O,_? nu ߗ~g DrVhD %7RrL#ٙKĎf˽&pKK7ߊ/Dߍ?6 'RG;N%R#onR-z, &,_k05ov゚=Z{һk{T8Yܙݔ(k:kz`T/ ȥ2VV X8M;v#tLJ=)F H SIi D~"SJ2b~NǭxK U00Iw1H{⿆ԂTT.# V]J9D\?iR>aL9Q4FR9QGws0*\Y50Tì2Zegcu xq̚I q7inbd4Tp3i6 v1&/2~5]k)k1<3DpShB=7 xmņNqL8w-pc$F>{9(eqP/ -BذDFE>hr3b"IjI X=rJAίGdhaMdr]rɈ>.dCyy"`# P?HCN"7u9,Z2TGsT~G싄_tو 4#n~.}A >ns>yu0fw U4"$J ›)b0 ]=%MGc52Iwa*eYa+򥲺Dj4([%pF(x.2N>w,qU-g$.`r[oFAVI8J5ilɘh6D,K}6 ;J +vi0E$h1N)& 6+gLÆa>)2[DO?CʤLz=看YK_&ڊ< sNB"~'OTg0Bv+vS^n\l+S2/,v8B,HHU(#9W7۾k3r=傯ؑk}/YAo4nޖ]-1yLH93&K7 kh!#F@YQ"jIT0[ic;Ŕӽ6/ Sa@ )jz,s`6,-:Mg\CgE~o=}.iXv|j !75p (*N_'lN&.dʢw9ɇUiu[،Nkrf^1C}'CVpbOFFKW럖_:α2:>,?-Y|~sH.˃/iuy&w {%3/ϺCI#ucO?i"Ӂ2va<OP>{6db]q(ryh'/ WBiyA]C2y([J,  xU†?v`<,"0Hw4=VBg~m|[IΒƆ"5m.`d8^wʐʌV~%.eZ5+G8xq:3Q$2Ef509y a?*f1HnNryƦ !)XJ%RU%g$)4 @]MU]0Յ@`oCQ";[mqE$@RbUH,Re7FeK<:lʷB"pʙ^F@njoP5s8:W,jY =bȰژ LU!" #]Q]~T㻥JSSH@ CV\%cR\,]`O 4J9iIGL9嘒dY!?Gu(JU/{C5 A%bf7g"ټ>ǖJK`ǥ{8c5atm9 _ Lh |,,ADXnasTHt$aP:J5<":ӫ>?6[ݧ҆0LC2N02bYl25! i']3|&(T\ ̸c鯙6g 0ZYdS]g:ZT20C7e׳aRyCf1b3gFdLӏ5,.M3O8+9/4\J-lJO=fvpv>IvcT$:%S+6ӞH9̯ws+:'3鸕-)7;yS&H]rg'7ɳ.NiQZZ*P#%YUhзO*vG{~E Cm^^do!7)EDP{;/z1'׏U)/YmARQ}M}䣔DnN~}/N_ƯFֿb^x ˿V_ǒQ#MM/s;eLJmRI?(C>5(kgA˰3mToPErff&[{uj;=ͤP Ǝ0Lv}̎=)}w@o6L&3sw>#*MnođkEk7~d 씉LKR9˵t& ԄLLSgy~O|qɄ{|[H y \ɨaNMD)H%d[g&M7|䄐iG;an8'wd =aWRPhTU$ThI9U噛p|/IrioJt:J ҩ3;AC:n `3D3IYbCOm17~gF:;}S-- {2|UA<w"RU͎*fkN9Օ&R}gb/ &i{dLr-LtiHjP(ja#E0/U[~WOB*s{uozӦwitxc$S՜qmҤ/OOFbd4vE0ul&_9l\.<ǸA'/|Ǔqm)X-E5L"YXLk5U,Cp6XJ WVگro*z20dҙeCRg T\Т[RI7gI_ReV9q/ZRqNceqrWR~t0⎶^>~# (_巌m_{6|ٔSME|, l.kQ u0;w?JBurbI ܻ@Kqp{9>7/sd 2&yo\d]ftƶ2qcd:``puny\ѫNIƱ"_j--_vu,|TM+2dG'jp;?^d}Z9у^TS:ԯyBvϘ3 ~HyZ%TRF0`'&RJBγ7#Jw=|Cbu׽dnx<`o ",96eCwfAKcm\ɆJd<> &{_~5c`ã\t Ûwe~nP:4i#g]:RߧܥFe|f>lכ'AmsP./WWsOjͬ6;uV5kVtȆ6H*etҤ%U ԻXG3KJ Ru(GͩH?Ϩ)I߬\X[EV&R!uNMخoFąW4[Mn$r/QxIU nڪߐ,.ȫ>&NŽR "na.,cK%$r!@LҤrpBx: Mވ3fkDpi' )>0)0i 6 BdGSGt>gͤyW4_P '$Lb,*$(%m;F1`dw2XS뾁D*h䣯g#0*]L_/::wt$gr"@BuriUXUٸ;,0.d(iAj"iQ+\/٥+ǒ#E isu<]7Y)]aTmvha!E|b V́pɍٯ#)6Ϲ[slM!$FL!Nr _`qQG9pw1`6POYݠ@uqs)l}1Ђɬ=.(D}xJvr0;`>&9I^uz $*nPbu7><~:,$Q'gd秾Xqvd6Fؼ~|lV dJ$MG0\}>%!v=Arx;=<с]Ш XfMEZ6\w ћtXڊ ?Q*ES| .j ;rVf܃(<{,I!v X~ա~R.9N~(乤8ŜmrQ8(-IHa*[Lf>קIB`XȲTG%<_AΙ-CarfsS4Ɓĸqȑ L 0y4zLcԻ u ͽ7I[9J04' r3yM% 좲tRR`9(ʹ"lbee_'P\Zƛ_ii%rk$m{Y4Ɗ/„ItEddԓhl~mKz힌y0uKNO壚ʤ=g\&Wz*I~ =m0GL5dCWBb8ats[{L,&:\XngHN!ΖɸU {t|$|zEM0_&H;s5ttO FL%b{ L-윽!61v"F%4֭*[\Hf7].e*fbMOO, NK.RL\fncg{!^ws:FYänC|3n&laEomc9&B?ljC|_ިL&`Bu;z;:n1vL:`0!Q.Q줴CQ֡X P'`+;_uOd)d^*M8!Hd 7qYmD1b'XE0LQC]Jޟ#nWs 삊"H%M2Vz"@&"Ƃ,"e jSS=v^ c+%K~dbW(xΏ3.u|X|us7˱:c"ѸñN+,_7c{~v_K&Ot:Xѓqt{Кo'V3v}S"[43),Q^B/[H0ZFq}L9tM(Mma*ģ.雚?T$Zc5_chͪ2̼Mf '7,fzjik.IXgc@vK Bf'5?3' KO +V 3cɓZYZm?Y˱8d~lwi3:}.L2.A"U@Bhp W `~|4HJR$?_2ܽzilؐ-fn.j!5~sr~(> dI {2<'#› d6t2dז]:UkSJM$D% GjoÚz c` 作uzi*;_%$| $-_}9FZB@ Pw+=+*%meٺ οIx|ͫrq& I!}:\؉qqċw,.;'>k!YU&Š ,\} h5Cvn;Dj vHTMzB`󽇤4e+Vk[e] svyjnfkBwt݆꛹t%]]gMYW`H*K,4gzT(99q/kO['٘]F;vO{IF !F5o;^K~7ɨ4!SWyNoBU]TaC0$A ju?cLt1$^ñGgө\}ߏxU ~,k܋UI]YLSI|\~?jvG+0bܨdq`!~ro5Zg免 E_;l^·ti\ b#JM:SE835}U2lN7#r8/a;:<&[$]-xw.nB X.@ g6dYy[<̊#d]pEfeerv=fSX֚Uf@T$`LS"V*ȷ/kwd4#Ϫ>EQFOQV)E{u7(& 2rۛ3~Z'f4P:| J Qԫ]a v$.AS x?th6S tHۺ  1*~ߣIIv.F2@.ԧ>ӝw5GSALoH+_DR*)kK9Z9&OsbG]ֿ̀˚hU(Jg ;h0 E uipRx{lpȴ{< z,h/M{!%mNO2І6 4yYy>lw_հ1. H+Afkj #K齪;D)^,;DSevLlcQqB)|}㥻eg~?ؙ+Yi]~/'q{PS("TeQ*X"- "DdRjAd 0 ؙaɢ3))[rtdh 0Qw(` B[%doښSaVZ֩imfZb-YV,iѴ&}w^ȟ>~!}SuA"Hl<ǟo(߰XRX,-Z{z:Άe}~qɇ ]'O'6h! -*'!`zFqijؓ1Y"@TQT"A Ng$ueUi~pɚ:~)NrˤcPtI&x Oti*3Jm@"#@!tFP$ J pZ^m) n*hӦ,#*r7>YMGy0$ BĄw %z10GLֿ0z|~1|DEchDۢ%1%j1E$K# (碿& {C߾ @4 ƄhdI$I $-?|={nY_3tab-u؛q1zuU|O_ 9nm:3QTfDSVn$ۿ6M##{=%L/b{;7wH,D7q\n.jhvX-QPX*~vqK&nmڢB{y־M,DTJ 'H+jyW]X {>T~`}f} Se1qN C8`h_#kg2~/ ?z:X0s3{|ږ!'2J^[@&HL({". Z ЈKP7|[q7tϊQ Y$,oCp-rSrו(@alvC kK 0ݥuTQ/_8' Γ+D#nB$G)&̎A!jCA20H Ttds.ca4$ F͞D5$!2H[$i$jnpmND2 lK0njQ>jET"ETz,!9g4iO~0f:s)v477& Bl'fP(xoR꧃P_=?q9zkR&ʒMw}ߝg> ?5jL{,4*Z7X:vgAECTQ)RD` T3@j}V?ȩgw B#7F̟yy <6{J$ PD2_)Իl,`Cf@P4 AYE+D!,!,BE10&YD !ԉ07h 2][ \Hh+M7L6AdfeҐ6ahYDRH +Ό%6f1{LXQEI`.2Lj7@i@٩u6IYJVTPYiZ XޥC+˃$ ,h2d0\9 6MN2ACQA&L%98 )%$ %im KDk*puii*<1*0@udYW[!NBJ U~k3.RC0+ -A %H]\&SkrC" ,bY.5 Y!0.uaRDi,d8"0v$L rQQ됢@`ft( @6EUT# "5 B́ hn*A M@*;''0zLܻ$pq HY ,C]lgpVnn[iae^SaCd*q 7%[KCwq1$฻pW6 K! )J A$"nʙWtsꬻ->}'DĜ>=ϜuBFœ)!.8E6/H^Qa KbЊ!mɴDwd7s! \ (h].5J362 铆gW@@yfեR6)#@ddm  )$P`!S$8=u8R[@vD40`"0FZI3{i2 $::cR*JD4`0d )030e"dLE  Ll!hBin92ibY`2ժR X/rGa2($pL\cvBfb2 `dlp' +q6ntruM2-yr^ZnA0wi(n@ĩI ] H0# .(`P+qn#vQ*Ffm{4>v-#Zh 1.y/c1u{uSΝ;G}r+yIw>ǁ2 E5E bzSgh9V֍AJ/oaFGodc>xJy8Г&Xcj,wvwr;[_M+-="d#u:wԯeڂdaSB##yd} ؛TlʟEsϞjiuxyJW__x=5 Vem<18_O*`6 sn<hqvo@P  뤀4rx>"vkI%Tdl=t_r{ӆ_-d{In,i#)Frd E|@" JP ǃbM]y|.lgP>?dz/^\[' YD6`%wː] fOs!Wr;>F'<4npAz}8^Yßc;^jt*VΉӦd ndy dEԥMԌAKSŚ<VoM bqb"ILV J! e Yc¼t/Xx xPUJ%G ɼΈ?;Zڞmunˉ"]ܿn~G/|%TusD\YX#Uv  V^U }]l%6!ZO '`IiY'o;~Y4aQH,y__hq"0D9:7[GGw;;Ñ: . r}!Y#tRv] ٠( e  CQ*#)) T*%z7XSSCXaztFya `wEeh?<Jѯ=t= 3>: hPE~jI;LPi0ur[`t-d77x3:@+NTδ|.Eԇ)#BA25QD))1UD pQrK/ϦxOS:^;o2Ņԥ(̤8-@U™JW )X)(2^͂MaM>zBlNMd"FDCݧavZR`(n}f2iOu *[2 0d0<#To. U!B^42B#oCIdt'vLt#28Q8pE[)d $`G" _w^ҷZ.[\Y{x:ٙzd<ٸXVOL8nMN36 uJ5/p5. Y8C.B+na%"n1:ģD(҈y-GM[q `Xs1p娌+3!2Qg]3$=lM:rr~27dyhSU:=&|q1pD2>6M{g@NdDZ\jMi/a3D͢B$Ī;NgpNty*clީc/%9r+)R``eX[h3"'{+_(l42A6YvYvg!4aeL\(KC0[n#4nؖ&ͺVS7, ܡ5Hi2027ͅr ,JLC F41c4`aa~YS,<"Jä$BIln 4$fL@>eT/#y#q-漬@ l%ZX#w_6.5},p\ #L.&P"sH=ڜzqM st0p`PrTHAULz)N %˻v_7wc N}Jd|cr{Vjb[5<6A\ph腠02tT ! MYeon_}hHr۴ tKİۇUDS7=9LK*4X+xInV7JH "h &qD̽.~ ߂eBG9"0aVU1{+뇧Z%"~Lw WaR* &ѳc3MQw&gHL 2sj#L HʢJB1%r "Qb*!$RF$cDX^C×<V4I2kv,^+rC|̿cuֹv6dŵZ`v ,׫pt:yf6GDihRc8x?nP[5[u+O'A6%(RN(Po^}ZXԜaO:IЖ\i2t3# `vII(R4C:ZTƭ" 0heΙO5}JBPNVx6bŕz v&NS?)ڙS\Qc 1<$ak 6N a"M5k%I2Rz&FLд=hghyʳj nTmtL0And;ˆNeW G1*Dzew1ٯj!N2rZsZ`>9YA?1L/=q72hÕXԌ9Cm"Tػ7\-y@nsQDL$qEo0Ąz:O팍woFg(ɋQZIKdf|7L|O,!_ P쫩aÏL6-TY]^κ$m]j܆r4D9B8C]تDfBr(QɫBl.IcC21>Wa;Iʏ_$6O翾(?U#q8V;Lޙ c:wĥԶN~,QHZf{2PpR 8XJd+R6.S¾ŷEjғÓ.'eo?#g3w/2azRrl5W"'Q\5,;bBmWn:y3X:TSfc1{|dsTJe27buO[j_ S=na*e ZukQCpbOy (gdBT=tO~ld}v\6r(wN)yI^:aS<{8K=o/k8xd^fo:%+̾+Տ(/ȵw©{6@]$.YP~8{iPԸHAABϲTG$! hiBYSv0<}1HL.>ˑoa8MQo@E' X\[,RR4`2df@˦B&k8mi{-^}Hކ.?"X$ta [Og{3-*e7 0F9( e;|/KjUL-lɇt YI`P!7Is)4Gz mf'ǫf`S־$Q]1/z4dbJRMUY7nJCӷ,J͵ X%2? kIRk>4J,bP8m_s J0.Dؚ5h6R3}7iTтݖLS0WJX5hZ c!( 81;I18CYiI=\pthcf<V ZM" J\wʸYm<_S$Feza,RPEBTJC m\ Df{ªS8 PIdRn?iݫmSozwHC)s8Y $JT*kkV8Vݶ6vSç.«D+U,LL8e<☺"s /F AB5iKItMɶy3|a~m9 ,`Sm6lJh C+%*51smrԞ>&P$ƸmfU{ЮbX4.M/y3Iɾ7)Dׂ홑Ǵ*sb7MG+RZ Ջ݌ ͡Id=e\̳s=/qc"Z/J36b&Y~g 9#AJ,٢-`)c;!o,= hôR;^oso>k~8xy 3AXxDnUa~Z횋*ŲM+t%HDxT+Ja`xRELVޮXBF)"TC2dɥS-336I)4٤)&mL&]u&VFIA "K>~w T5Ey7uh*c^q"02SlUEkDD-F*J \-N " ޟ>%^Nm DXcMD@Ž0OĘ{Rl2pٞS]g78=0Fdm#m-JRL*B"VMfQc4V {X=x,wP d9 ? J̊3:X-LG}JR; $ 'D!9KZ$ ̣ M}9ɿ:ߗo3j KP#UTH^BHg{4Օ)7mo2_{*c|ulͿ}盎! pN2 h$ HCDH:UlMS2)+B2V`,Lٓ`(H*zʬ- rҰB;J"jsj*E*B aP)e\6#V2(_๖9.I< Dd^DH,OF +XB EˉS*ܶCL̐"rT[ DHͮ`p=z;c} LE =ʫ(J!$˄g_ʇN MEVd}UDӈT v_•1g[pi4.aNC}ip#o<*6g>\B] 03OT~٠'7w?Sԗr :"BPhIBGKDIԗ4۵"(Fc{-P%+% L$\P ZOJ;q=$(ofkPm4iZ{L" ^5}L&̡M P>Ysցs:Id{jlJexFf )\sNB$㗨Dia:a'w(?sS]:rĺ9G>$B Y4>[e2A)%3BCA,ի9{ۇ~>.4jաb6~^?>t^Q0Ϳ2֒ 2)%MLؑwy$ԡ4j>iaT <ڙsff_9w=wo/O[nBjSf嫛ߩ$$i_x&-͌2f̝LU%F%!@fi08t?ڋC:u?DYt}ڹw>].{ E"sLlВI_O~m #?ƣXcVޣ-\~i `(e6v&MF@TDVIC6+IzI% $MzbmOivu{c~,;wɃn/r.lRBMMZc%C2cVjPҥ~K2?~5"+.CBi5W>!&M7|I~}\]Th*ER#QS8l e]W/\jk>Ŏ?g@0+*`<=̱|LkE(nYW_0O6%[׬9IUl3 uZupQk_d2n P<ڋy&ܯW9e E|XW Dzue}9a&َ`n&l QUSmc͘?-@黫M#$:&CA""MND/h&jNby[b f۩HVT(x*&>{ln+MrETkZ76LٟKA\v^3`fahdTL IPXL7+Pt)K旉VWCJXS$u-&~7_5oos+Ol6 ǣnׅշg}y-7Hc5!2p:ira($)c4= m ,w%k84<1C6 QirӑnIZ9Hy~Ŷ<dž[wz ?.&G7:q(__~Nfn?' 2,xQwZR0E*|wsa7D7[_X+CFF pq)5q7y`{eG8پ~Xܮ؂s8&%G@EfW!YRG zi{?/)[eiQ~n˞SO*4~5۔=HQ+" 6B'۟lKzPBҧ|eʸC;p͖b߈as"s&/-G̠.6&|ΫϼȺxcfftHBj"3$Ƞ3rY((U=ߡ(DQ_.Gf=`3 J t54;vH\HH@M4B`1{_4u2~wtl:]L$dljH&Mc2B18Aca?Hڂgu<&z=OEuPwLC3: id:3]o\tlի2  3~" Փ5Vw;KnsѬM 5 fc=yoGsa]wnv[ 8[kx7Ļic {OIzW8 9ݷp8_vW+H ٗGze3hjUfCjaLƴa H౻խ~kZֵgsw{H*RWJunF{>'6+}^L~9yW+]7RkTN.$ZO+P/ TT, $[ #\wFm*B_:L6'R*%D<UrmYʥ2d\5}j`$7JPLaoA1Lj=G*SgrYE_̠P${ AT dh0j۞Es!xVmģ]?[r̮>>NiHt0SD,>7ky:/oOp﫥_'+%9n.Y\БӚ $d Zӥ+$޵Qh%ogR;iNGfMӛ!ـY](J7J5,1ч֧"13H\W!cg *o/=-v$,2k\<^#k]3b;Hن2HgUϿjs̘I{R} Dk;qdy^XEOדzf|ѹY 6||ʽ 90@$6v}ݎC҃.oZhY&TJXBCvU2>9l?1-LaM_G'#::!+K >qי"sC{YrDdM2+Add3`21 ?d/Κ:^O//TRr؃Z~$'L% )RNlx-&nhpq$߇ `B#T"K*ڊ6 = B\1PXZ:bE&'p `]y:q5o"OK.̪Nas+<{y]:YM1 D0$x}55֘,m4yBXWgTr;ҩyT8P4' ׯ+o]cU\6v8{ (-VJ唸3ˊr}_m s.y[|n/X,!Oaڈ"CWQsJ|,|}'6#lDרt3%TS 6+g޹MO M1hsOjΊ 6%~.߽r\/5ư*os9>2?Gﻁ|m6^}9 ^",eaUtbհ6CayTSWu߫z/G͈&#mD'%ƣJ W 1@Nx~?3olIQ@r100*o,B ycwV#x7WsY{6BDv`Ol Bּ$x=" d&j)(/ndREF$L153RbfD X![ǮysbE4H"[0cF)(Ij02dMh  blfLi ,hbe\ `%l7Lh k,Ec_xrͬT66kJRC-%LH,FM(RIdcL A!dɲMuٟ:AR (ŋDQdk4dԓ4Fѱ&*6Fœ$ޛXbe DbRiAFA/WG"ChX#H!f tl/G#œS5Zh͏iJosZ1So{ɠ,@&1(c*d@*`,dA u}&4se1+7x#2g7~Es۫uŒ0Q=RQSoǪdFFIADcYbTBF6414#Rƙf@5I~-r)[*J(Ff1"Ȳ0ڬ&ōE&&(6ljRL6(QTYZJhԖ` )iyCƊɨS+͙iIVLhIeT4d)&(PFi5]GYLhRQƋm5Qb)6aThAM" X! CfZ6d3F!m ̄٤HwIS4 g]F3IŊQF4̯n|Wf%E E)Ld4MRƦ5&X4QmMł$5ƈb0K,la33F2"[,i/nfyI2 =m#41"H41Q% $Ŭ["TVQ5m6V1~ŌF& h11bȓQm&)6mFƛ0mF!" )TZYD M6Lb&I+6Aa2Q7I!IXѤTLƐ0X%(-%DYH!2` BRmѬl&6 h"AbTVYRb%c4)ALk~E6%F-&6c+&$F*ȕhH4JB2(҅4٦% &LwaƈU+D 3 3"M@I}NM1 $IM)2 Ff0i`Y4f*RP)3D$,FH54&5 ́CsPmw_.eLhք1ATn*՞DBie˽F ]>Wt3ߕ󋯹+-#{N߰CCLu0)[C$];O9|A>Wu복sXWԠCUTы%C,RP;Oyxn/N{kw7yCm{wgm3>/.֛9GwM\J*yIC7vۛ_Cc}%oM+mx{?x `%gHd\ Cz~f2E氄[O%sGvCTc!oW߅`r9o:< #7}~wɩx /ox'p&h339iV`OU^Zd~"wCm`C 2NÞN}#:9 ͡0y?AxVKn*lJJ1)I)+a|+21弸2JStA4ġk7Do:\Q?&?:ll]ćOE|=ٺL;}xn>Ag3ԧڜPf-?kp\[D6ٟjs>APxk4 (~ "ؙio=_x9[e6[p,)q^n2%Tм}m?coeǎ\^szo[|n}iܮKf}s[{̯MOaݽ:(P 2/$_ˆ޽Bu0^' -322K,yKJZ`t۬v:m%w͝\]@2<}uǕ=KAq-Ew{q_icnwm?SNx1ٿ[Iyti󔾂?`pp@27_C\͜L0?M :MȅWu},3>_n[O:WCop֯ u]FlѾk4/?|% am~ey(>G͍unN'䑍X0AJ3X:eBF\}ECC   4eӽW0P(Oߙ)ynwZ^uP@@"iFgq.FC0ׯqJo2.龟qJ/qέ= snz3_/| 1j2,>R~\ 6N:E{OkUi| | 2#eLha 4`Md 2&%:@Km~c2Ad5aq MG#Lŗ3Ħnbb 08S.ed8 dv01 +Ph֬?_GܰFe kehڐH(Ҟ̬[ jZE@b#nܛ5553jR+SfeLٓJ5aJ"V(b"rFE2y{atYtc]޳~C?GG<Ω<]E ;íf/sVF_'@Ys-d…Rf U-3TٖTѱչ 1&Fc'h*W%`6$>DUٿ[4yڰS,_Dx|z5(T.d}N3yyqEd-.z7M"_ߞqC[!G/y"ob";(v;_ V :ז:K j]}ʞRݘϾHVabZ+U˜+k 2`+!SDhQx{ۑF kJ5 1$\]4"TőϏ:WX,3 x*k܆d+a+¦!mR5VKs}w_K}o1! u{<̜,γ8n8/^&&_n{nd:,xSIY4M6Sף2T$BunLWEP ]<5э7$,0y}(# cB ?"tlQDF #YwEG/>YMmtV6EVZQLK29+N/!M Ax˵DH{u[v|%5x2&@Vag),%FA C:A^7E, R*R;-YQuhq#ń"X4> ?mH " A7AӺx>mlcJiis3nfۉHmo5DzmFnBI|!u;L5@SRd5r`![ˏkw  Cg^yYe5.JPr;Ƿ ƲxF``#UڬX >mx)"V cz,*hE}$BtrpEtRPP3>ՄwoVo0OIGg1\}cZv ycT Hb @0Ĉe0|lёwKPy{NkB`X2S8 H,  ,|s_yxbhYECuok.!`g>CST0yƀH)o>ݡk AUy(!d7%$vE4Xm @-0gniKW kưΡ':h\@!%T|<7YkWrlן+WCdŬe!%?5=}VG8h㭯%%R7ݳ~UiZqewRH|H݌w+g\JVg4ێ-s'Uf]H+`p(=}F8c?@kW0CPش71d4SʶzN(^jr+y::p>H8ȸZSXԼ {o0` xE0^\Ns,1mP? Z H쵛)jJgR-CJ<~Ct W1qQ{8z=$ `f$=wYbXy( <$2:؏q5ޥVDp=S[δF.WA/ d i;^ yq9ue}̄^nJ -ۢF|SxZF?Q075ܨXj탔5/q۝5bE7, P'8LF$=3yy]zT[Q^V 8[:䵶$!׍`缏,zn?^I 'ጻXQ~̹w^JE_@X(Y$׹%YP#R)TT:S,b<^sFTc:Ӊ kg?`VReJk7F+jҾ 3'Zl&Q2-FmAT—}@,P"UvU65=j@=1ʀÛ4:h`J;A-F 06^'mTZWkpbf41˒Dz -0'ulI.4%{^RW?&Vb>2 Z k퐝8є:!pKHi%ۥGjnk$>Ƭ =e9FNCQb/{:x,&9oRe[$:P4cf>%VхNOnZyŻlvgcijnuRnپl/X("8M4dxB>iaǖI݁2K$F} Ay81$muUƢ7-Y{o힎|o:ZWRH"\>E)hX<[ r0/+/']~AL.(@ARY5"cdNAh"0\԰e =g5Wþ#cmߛ-3"z#eQ @L[$ ̛&IC}kD%WEւg픹t,Hӧ ]uN~?FN5|6%v0x r`Qn^|aGl ֹG]hR|'l`_X'bǀ,Jo7yu-g]3FDQbgM }a(#Bʰm@V>3 L,dGK՜ Mbɴ[ذ3sH"2b=q~K$` /b^4Hi?w/yᵏaAkA!I N~(fH۝=^&ߋ*m$V0[}$tO (bB KUTQdl%#(D'dC^Nw| st}8}<(3r[%_V1So ]*Pd+&V{0'S>x[n#.BC+_&XV\4Y67fb*@B6>)fHcM*::1@hQ +_LUy˙R9(#zsqn_rXU;wtKm780H# +S ܇ )=K\qX愑8+%_!ϒaCVv+.?&J$Eл\2H,MWU6+tY=ྈC Xnpr"B ˫czȦz<9r.b[vAƏݭh<[j}NMH4KOd:]L=|kfS;tZwHoc |LP8;ЈG"lD_󂌋X7_TKu=|[b7-"cÊX vuIu&&E+GFʃ/X?~v´na M 1{ftRXF`͔sz܊Um=:dO:k iBpxn)vМ͕q0UpӃ/72ѬȦaPzmZk]\[7m醺DR(:MP*lB:gvH{(C27s%V5]ʹ$_MUĐB92ކ{܌֙D EgV!{O,4$r8J ףnNnx$.C ?#.%ɳ2>]tu][`nE@k~XDK6"/>S#!$WaF*],④<]V_t|b>sn>N5"u6#0fV^9;Q# {]ͻ&dKʯFg:*,Q+._j8'HvWX,ϐy_nA3\#؞)$ )e)d+ w*88oDGˁ˩+}e%cS TYwt.]+3@ 䢹<瑸|k_u$g`aBoqId9#JBג'pR 9<ƛX@Z#q7Rl٤pz_5Ј֏7|RxB9Z g5q~`J5~|l(ޭ6΢C"KlhKT/N* 3Xat} Ts@؞ e߱˖]/< h*7HEЩ "amrCPbAFF l럇P.{^Swt2qIK殦tc̯&gZEg"d4y ZHf f®/)A2)k* 5QLa$5$ yWa%֑1&4!HN~b,PϹ8.Iqco}o&`鰟eFV^R[=[|\xZºa%$-%F) HafoP8e3zt0+vWV"vO)YHtÞNK;_9˱ƅCTtfuL@*%A debPn9tP ~tYJxvA5c$Ve .igz.Mj>+6,fqe J9$^hQM Yu#m|5/r==2VDJ&%&p^#ҡ״]`" _q_!W%3DZWP~aF0_KuQS..gl;![LENy~F_zmEũ6+n?F6RL҂ҏˡ%6ice^BD,4n>]d-t4G:)ke?bsȖ\|\э9`=.Fim*:kvl} a%>zDܳӣ?Ta'xT/-h\  q?}o@eN^1*CM%GbL*ͮmc*0C\>A=Q&n a?H|~WHV~6yB?v5$} X@ĝr?>1ģVjbthtğDl >0n4]X39֪'P!}? h,Inm9v}c;~0{ /?Z_6r[gM`DSBKQR%( eXt~է`0U%1(5ڀQHdZ{V,-r[+G=Ho 1p_w) M[+Љx溽4"< 6B(x&j4mT9#&@Ot,2"05Y0F?dvx<:Y',9ۯ7&S/ & N5:7-ը }x܌A ͥy&MΨƑ18`*.YJ4+!xKA_# V) jBz E0ϟwc8\r}'XC/ڝvzg'ҏesˍ 1siQĴ˺w\5 &RߠD$/ fV_F)mF E I \ǶcZd L +ߛZGQG1")Jelfp[c3]VŚQpS7iy7G`$ 'U=M(v^)lǶop$-Ud N?'3ߦ @~nJBfPޤiE w9y⻲Pp2xvzFxR7F#Kf;B4CdzMkD}DE<j̚8ݪzzH >qŗQ*Wnbrdx&Bܮx0hjfVC`ohjf_e :,r,AnTt*)/x̓^z(x{t?D{5 "'R|ɬT3{qꜜnQc`'uo />zSD&_{J$ARՓ~WBHI#0nTK&; q>}0 |f8^}@+mщ)^2%<=Sz\7`97r_| {L+ x&‡yWR{ 5<' 1(_Azۜ8$[J{)dB?! ȟ@ǔ,yse1h,5݀rږ9KGnq񰐱zO<֜J1⻕Aꧬ7 :hI Ajg!\&05GwYpS⠚Ӷ3 eʰ+WkW+{(wG|534>K=/[ܘ\`J@`/A-3oO -vqA4- Εɖp~&)K5,9%|Y ہA ܟ|JǪy拫7ź4@9JsEhG3^xg0̥u+j؍< 觮u3/Wth@PnOʾcT`ҠͶ]W2Y鄡Mݓ{2\d 7yTÆѤWc}tsXCA:fH.tC޸ [Ʌ18p*忷-AC%OyhOP~zDJlEqH9](G++B,)USq_wvzx@ 2Q G?at+GY2tFYSrg9ɡo~ ,@9Ln&ZS^*T~|=mQ,WA7o\pwm%iċM3IOEFfgz[M&`$njZėxTFNb},-.v1C[!Ok} yIqkJݮ dέ9SF&Xmq2,QlTHs1w׺_jAU\c?D>mߡ4/mz_'sE-bM^7؜B@LH*!끮sI> .ɐG6/PY6 CIP&T%h|̰9fgPf$}^ۘh*0 7A{KLhUCq/Y'{ &KuWҟ#LGA>mŃ;9/;$yܾ6LJ0Bu8Ty΂ ül-s48V@DȕeMJh9g?\[@WNԅM:xk- uը?u,{ЉU3[ F}<%xl,P.v&U~3J#`Xm7T_u1 5O3l$/+3Db} 윎,j;F2yHIumpH)vԘ΂fKڞ GLF60[K5Aolg5Eviޠ=iFeh\aۀ3 z=NtL A?yQ=gI}U0{J Ge 6[}$Hǚ-M[&Ϳ~0Q[sZ t# U ,ȡJKڪ_Ǚ/_y]7jq᭻ޔl!F&oa=n3gZwM<=Z=4'YӅ'1#Hmx]x`ݣofb#fb#4TLctz  IhOrEL+^J/+0Tb*.Y3I )R]5B賐Cs 8m͐) hAfRlGC]HB|yL3 Q3]M%cֿ,׉:@|ո.|sqՠ4گ dl?Gڈv#- JP^a͢nZv=ș.h]]bN]hl'bUmh!uL]Ky6 P};к?1#VX%8) xF%ye2<2-ixQB_[Dܩ F3|"eH#W~Ϭo-RpUcKp+C[Mo K9+.ȟ]BMެl" OYtQWU]VgxƗl}}[A!1w؏o8JX5ᥖ`PB퍞yF/bL]-1ب`t!CȅۻQ