samba-core-devel-4.7.11+git.186.d75219614c3-lp150.3.18.2 4>$  Ap]܎/=„.yg gNbU!A<&9m,'wL=dQ>:4oCך97;$O: lIT7&5R}ԗrSPi3`,`Ї5yWC6}KMv+/ZԒ2L/=CˌF[MrI~5 OPr[E|ss`+ayuuQF0*?4ȸt;}%, ޵12a9fec581cf43f9c3179c72b8d42cbd79d577d5689f9986a8451b919daa824223d7579b1d58e692988ca650d0c3dfe33227a839d+h]܎/=„h=}%){CuCCGG=džuf)QVG7vKX ~<\yBT/qJqu+G)O$V2t&ܙ esϡ]vvV o`ٽd©NPYӊq"o^H"2* ^Fgax]pϒKt/.6 BIdGq~3&rL!sԆ7zaԎ/X9{7X $ZU/:KeD%/4h-j2;wE V;>p>F`?FPd. ; i  "BY_h6@6 6 6 6 6 @66&64l6Dp(89:!F<G<6H=6I>6X>Y>\?06]@6^B bCcDAdDeDfDlDuD6vEzEFFF FLCsamba-core-devel4.7.11+git.186.d75219614c3lp150.3.18.2Development files shared by Samba subpackagesThis package contains the libraries and header files needed to develop programs which make use of Samba.]build34aNoel Power Noel Power David Disseldorp npower David Disseldorp npower npower David Disseldorp Samuel Cabrero ddiss@suse.comSamuel Cabrero Samuel Cabrero aaptel@suse.comddiss@suse.comaaptel@suse.comscabrero@suse.depalcantara@suse.comscabrero@suse.dedavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- Ensure we build against correct version of ldb; (bsc#1131686); (bsc#1125410).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- CVE-2018-14629: dns: CNAME loop prevention using counter; (bso#13600); (bsc#1116319); - CVE-2018-16841: heimdal: Fix segfault on PKINIT with mis-matching principal; (bso#13628); (bsc#1116320); - CVE-2018-16851: ldap_server: Check ret before manipulating blob; (bso#13674); (bsc#1116322); - CVE-2018-16853: build: The Samba AD DC, when build with MIT Kerberos is experimental; (bso#13678); (bsc#1116324);- Update to 4.7.11; + s3: util: Do not take over stderr when there is no log file; (bso#13578); (bsc#1101499); + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + s3: smbd: Prevent valgrind errors in smbtorture3 POSIX test; (bso#13633); + Durable Reconnect fails because cookie.allow_reconnect is not set redundant for SMB2; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + Fix possible memory leak in the Samba process; (bso#13362); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add virtualKerberosSalt attribute to 'user getpassword/syncpasswords'; (bso#13539); + smb2_server: Set req->do_encryption = true earlier; (bso#13624); + s3:winbind: Fix regression: winbind normalize names doesn't work for users; (bso#12851);- Update to 4.7.10; (bsc#1111528); + support the new v4 Performance Co-Pilot API; (bsc#1111374) + quotas don't work with SMB2; (bso#13553); + Build failure when quota support not detected; (bso#13563); + vfs_fruit can leave lock records when testing for netatalk share mode locks - causing panic; (bso#13584); + vfs_time_audit is failing FSCTL_SRV_REQUEST_RESUME_KEY requests; (bso#13568); + g_lock conflict detection broken when processing stale entries; (bso#13195); + deadlock with ctdb_mutex_ceph_rados_helper; (bso#13540); + NTLM authentications using default domain/workgroup stopped working; (bso#13126); (bsc#1068059); + vfs_ceph lies about flock support; (bso#13506); + Using sendfile = yes with SMB2 can cause CPU spin; (bso#13537); + Durable Handle reconnect fails in smbd_smb2_create_durable_lease_check(); (bso#13535); + cli_splice() fallback code reads wrong amount on termination case; (bso#13527); + LDB 1.4.0 breaks Samba < 4.9; (bso#13519); + samba-tool trust: support discovery via netr_GetDcName; (bso#13538); + samba-tool domain trust: fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + conn->vuid is invalid after a SMB session reauth; (bso#13351); + Durable Handles reconnect fails in a cluster when the cluster fs uses different device ids; (bso#13318); + cli_splice() doesn't correctly return written bytes as it's uninitialized in libsmbclient code; (bso#13511); + Threading support in talloc_tos() crashes when enabled; (bso#13505); + Incorrect talloc_stackframe handling in python ACL test code (make_simple_acl); (bso#13474); + Fail renaming file if that file has open streams; (bso#13451); + vfs_fruit: delete 0 byte size streams if AAPL is enabled; (bso#13441); + Creating missing remote databases during recovery can fail; (bso#13500); + CTDB_BROADCAST_VNNMAP should not be used; (bso#13499); + Fix building Samba with gcc 8.1; (bso#13437); + Uncaught exception at ldb_modules/password_hash.c:2241 during new domain provision; (bso#11573); + "net ads keytab add nfs" writes only one enctype with older kerberos libraries; (bso#13478); + VFS modules that implement pread/pwrite must also implement pread_send/pwrite_send; (bso#13425); + vfs_ceph is missing async fsync implementations; (bso#13412); + net ads keytab list fails with (smb_krb5_kt_open failed (Key table name malformed); (bso#13166); + s390 and s390 needs to run with 'use mmap = no' by default; (bso#10765);- Fix ctdb_mutex_ceph_rados_helper deadlock; (bso#13540); (bsc#1102230); - Fix vfs_ceph flock stub; (bso#13506); - Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); bsc#(1068059); - Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048); (bso#13360); (CVE-2018-1139); - ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056); (bso#13374); (CVE-2018-1140); - Confidential attribute disclosure via substring search; (bsc#1095057); (bso#13434); (CVE-2018-10919); - smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411); (bso#13453); (CVE-2018-10858); - Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414); (bso#13552); (CVE-2018-10918);- Update to 4.7.8; (bsc#1099702); + s3: smbd: Generic fix for incorrect reporting of stream dos attributes on a directory; (bso#13380); + ceph: VFS: Add asynchronous fsync to ceph module, fake using synchronous call; (bso#13412); + s3: libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457); + python: Fix talloc frame use in make_simple_acl(); (bso#13474); + winbindd on the AD DC is slow for passdb queries; (bso#13430); + No Backtrace given by Samba's AD DC by default; (bso#13454); + winbindd doesn't recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Fix interaction between chown and SD flags; (bso#13432); + s4-heimdal: Fix the format-truncation errors; (bso#13437); + vfs_ceph: Add fake async pwrite/pread send/recv hooks; (bso#13425); + printing: Return the same error code as Windows does on upload failures; (bso#13395); + winbind: Improve child selection; (bso#13290); + winbind: Maintain a binding handle per domain and always go via wb_domain_request_send(); (bso#13292); + winbindd doesn't recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + rpc_server: Init local_server_* in make_internal_rpc_pipe_socketpair; (bso#13370); + smbclient: Fix broken notify; (bso#13382); + libads: Fix the build --without-ads; (bso#13273); + winbindd: Don't split the rid for SID_NAME_DOMAIN sids in wb_lookupsids; (bso#13279); + winbindd: initialize type = SID_NAME_UNKNOWN in wb_lookupsids_single_done(); (bso#13280); + s4:rpc_server: Fix call_id truncation in dcesrv_find_fragmented_call(); (bso#13289); + A disconnecting winbind client can cause a problem in the winbind parent child communication; (bso#13290); + winbind: Use one queue for all domain children; (bso#13292); + Minimize the lifetime of winbindd_cli_state->{pw,gr}ent_state; (bso#13293); + winbind should avoid using fstrcpy(domain->dcname,...) on a char *; (bso#13294); (bsc#1087303); + The winbind parent should find the dc of a foreign domain via the primary domain; (bso#13295); + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400); + Fix broken server side GENSEC_FEATURE_LDAP_STYLE handling (NTLMSSP NTLM2 packet check failed due to invalid signature!); (bso#13427); + s3: VFS: Fix memory leak in vfs_ceph; (bso#13424); + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407); + dfree cache returning incorrect data for sub directory mounts; (bso#13446); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + s4:auth_sam: Allow logons with an empty domain name; (bso#13206); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + build: Fix libceph-common detection; (bso#13277); + build: Fix ceph_statx check when configured with libcephfs_dir; (bso#13250); + vfs_glusterfs: Fix the wrong pointer being sent in glfs_fsync_async; (bso#13297); + ctdb-scripts: Drop 'net serverid wipe' from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + smbd can panic if the client-supplied channel sequence number wraps; (bso#13215); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + s3:libsmb: Allow -U"\\administrator" to work; (bso#13206); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + smbc_opendir should not return EEXIST with invalid login credentials; (bso#13050); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + libsmb: Use smb2 tcon if conn_protocol >= SMB2_02; (bso#13310); + subnet: Avoid a segfault when renaming subnet objects; (bso#13031); + 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:smbd: Do not crash if we fail to init the session table; (bso#13315); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Bump vendor-files - Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); (bsc#1094881);- Add missing package descriptions; (bsc#1093864);- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available. - s3: winbind: Fix 'winbind normalize names' in wb_getpwsid(); (bso#12851);- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.build34 1572461267  !"#$%&'()*+,-./01234564.7.11+git.186.d75219614c3-lp150.3.18.24.7.11+git.186.d75219614c3-lp150.3.18.2 sambasamba-4.0charset.hcoredoserr.herror.hhresult.hntstatus.hntstatus_gen.hwerror.hwerror_gen.hdcerpc_server.hdomain_credentials.hgen_ndrauth.hdcerpc.hdrsblobs.hdrsuapi.hndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_svcctl_c.hsecurity.hserver_id.hldb_wrap.hndrndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_svcctl.hrpc_common.hsambasession.hversion.hshare.hsmb2_lease_struct.htdr.htsocket.htsocket_internal.hutilgenrand.hidtree.hidtree_random.htfork.hutil_ldb.hnsswitchwinbind_client.hwinbind_nss_config.hwinbind_nss_linux.hwinbinddwinbindd.hwinbindd_proto.hlibnss_winbind.solibnss_wins.so/usr/include//usr/include/samba-4.0//usr/include/samba-4.0/core//usr/include/samba-4.0/gen_ndr//usr/include/samba-4.0/ndr//usr/include/samba-4.0/samba//usr/include/samba-4.0/util//usr/include/samba//usr/include/samba/nsswitch//usr/include/samba/winbindd//usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:11379/openSUSE_Leap_15.0_Update/be996b7f12a3d56812e012720e2d8123-samba.openSUSE_Leap_15.0_Updatecpioxz5x86_64-suse-linuxdirectoryC source, ASCII textASCII text$vh]3BFNutf-87856ce13d73d3ab36423c71c2decee0173c0e4adacb71a5e7200619366d2d53e? 7zXZ !t/8] crt:bLL EߞlRzcnDSZ q] J /K_VXSp חs'\A6(b;*-B|W}*Ea&,ywRzH]˸zpûa[ (UReM#9WcrtdP 썍* P"}'. -0SUG{?o;S`Dӎ5ǻ3LcN8Y;SefU u7?_~64x.jC5/IZ@؀?H"Q *֜l;+4݉oẇax ,F LSp۽>n2󹫤SIiۤxGL6oVȺ۫Ɗcx7ZcC>oto<1`,mk6ȲI\r3q%.y(HІ~X'ҷ[5.Z'nn4x$<;"ewUk Q; NC@h\q`R/'B9 d y J)Cebcһ ^:sND9}ioc+tNJ  6FSy} ;ɇ;̢JhU wp(`WhI$aJJ+ 5ҥXa@[!̬s60{>%_W\tJ ! ʊp;LM%)1A$7Gɦi$!Ҫoؑf6Ɋd:J,a-&Pjʊ4EP{2+Gm@; :y^N:!\NTSH| SW [4ޏê ,6ɟ;SH:3:en$N7<Ԡ? ~*/PݞJ+uwpݔM/x=%2'VnSwJ.?`AIk~_"q0'^vO p*rh!fŧ 2S0ٰK#/Mp-C#!C.1U H>,?y|}2KvW&tn/\{ݡǵ0[ͬRѓ|xv:E4jw:i&rkX#hvňRp;GVxx٧bb}Ąu~_*5&`к6ܕ$Zi4DMI S>,YlXk(*H~ ^rgc~!VZHx0p*OTN_qJ!"@)å4sH%zK MTa2 }AZ4*%/i J%<2ZD{tS%6SlՑx0<:fЅ-K״tKIlQC  p+#&^kNį g#Քb-{mbE&D,FpusD|dY]|]a' d^Е(FG LKLh:[VQ{ՠw)wx8!GC?;8CN [gLzyYoȽ_!cy 9t+[dA_Klq# U|8JZ;[@ ]G{[=9nN Wx\0;1'+j䟾SH,gugyv&oahU#%TԃQoQ"+aodVxʅX\˻d~LGLڇ/ Bˤd TƳs B岝70VTG>v͋6aB"3TW&>@ro'_1D#`-$zu i$ыDϸu3vikлQO: 6w塉r 8 FSRG2C)|\3Au7!zQ75ʦ雱ML\CI?dK]0VTGvQV)nCk) 0;gE^n{Xgf!` O" # o9 'eƯ~"N ȤBKi s-or?cCV 0e'{%X<+] JJ+Jt~3u"+Ōzt,#^TiEEaZG] L\1p`쇕3* dx[ ziu;Fxؖ&| VHU]Y\a;s,R O .Zp[`$ds W5 #$NŹBvB 8bmd1g[G;d2PoC՞^WC43"L\T@| BX-7=:~HD"lbHucB/5T5mDH"@۝-QX~_ĉ'ޤ=v%67[Z#>{kC\TGgSDoWog߿zcVKԦ˧-SVu_w0[W|0h&po7ىr,ma)_Ϲb8n'2bK*J)q6A kS|Z\ .pï2F>nvEeӮAp}ȅCQz.^zg0nҹ_4.; %;C8`4~h9/VP%[Ìc&{^p3Ӱ)pVlWJt -fexOczGoޛ }Y~KQ,|3! Vr+$HՓ5:Z=LWy4w:fpF m%X^{c`!e֜ z^SM,&k{xeB۸T+xf6g6NR$yTæDIyү% noBrCx BFf2 #N|wRwB[ؙ Wꪲ0HEO3>i@z h~b@n^Xn?1&KVlO# B[?Ɔx>/93U3^5L_07c{6T Be4ʛZ3)' 7 ?JQ}+`Oىö<Nj@,P6cf0@&(&e4IjQȅ'0(F͊D ye&sJ*+'[A$]YJ;@|zќ3_.)^]vK%LIك.C]4ศ=st=݌^ͪןyG# mxWyB , n;FdQc_四\$$yt m=p {N^!'Q)u'>߯r s⟏uh;Wb^}S »ZZ5n?5|,VE`@C F\V?~pjҁ*{@f>CdP |7Fk[7XêXgc1[pfN7Wp;wKp6F=D+YiqQ%@0Y¥-^o (  DIbd9*Ϟ j1]0 3± 7J|~$.I%[_jlHC=ȓZ^^L$lZg鑾d!D4e{fjsz`FHx( cnBY:p a)f/ę ~ ~6;uÈJFTy<=jW9K1+u7:rl%QN;NzjN65W5%a ?h:99 p!}|Q{Z!P777m]Ze/q>IfйR1Q1j  '9$X~DTeA9:*^pJGҗt4~wݎ%OVX]CPuj\a^-"Q{g-ױC5Ù CNkBI,$my@i} 8[/eB&<I3e̙Iy՞ >l{=WJNMHpxciWzBa'@@IB)K@Z?TjcV(+teE"X^i>ME :/D5wj$h0J4Dg9E6P/IRV%ʈ*W44{lk%9s-t+4mՅzyD`֨ӄu_']# $HAݭQ :YX'ܼSn[6u,N0/"=ɂ69 CNkƆ㙡+HC+a/jL{`q+_}_cUK P9e8YEh Z+H Ǐaшk$J3˱&Z-y, 㔆s9׊\eQc>!- |KLma} fKfշpmd }j<1Q7<ޞn-=z |]C}X1D _RhFv~|'NP(ijnNu,^K8UFugAW&Q`T,ޔT̹eu`t=ܳL6OuSpO_8F™9nr'B^L!W#DX͡@ &VT+Dq!w ׋NPIwibCFXG0҇a {PcD y-'y8UN%!Fhi {|H/KQ=O^N^BnXW͖r!bdB@S!ק_#$g: H'$af˶Ax*m-*9&o4~|q j w/TRP^yZskG ?7ЋRPF(d-IOndVx)B^ qyLRKVǗn,l%GW;D*6lSDO#XߤFq\u[._f',;!f{ (/|<9M 9!yx, ~hƠ`A_Gre14$_w9# j J.3{4ܴdƅ7*X$X>:#2u`zoƛ5 !ʏCfBh6zzmNpeʺX0G,'aև 8[>%-,08UuQòpSu>~p/;@vF{%X$MmU#8;p.+VGy `7;z14QiQޘ\Si#Զi_lׄ GQ݈[GIUgZ HBzώX#L--ixi pmX8+}^wR&A<#-Mh~m1WnV@٥DN OG#0i3w)jP+gRv)"n :M'y UNn^3ҡ' ϧ1&C3ȚdO) /Jv?hw\ +U|灷L`o*y2|nyf}d*UsN۫K2SNDM䑋@Yo*9--@C~Yqyo4.%UF&L G] nST&`/ʷtpx`rTpZ$yE_V;S~0l,bߐ*>qtꝳ2ukݟ+g\Id,)wax1}³up"vCxE2Xk9 LIM["ﵖ˟-Cfgbfd}\<\`Gd%ؚһxq{IDJ/*an4B #|کTNm]Ix tEنkCZgh6πV9/N#nF Hyl#eU9JLza"-y 9DK*tHxITzbOџ̸a.)UOb&5Ȥ@Q%V#U5)E0Β ~dm.lt½-XTOJ4B%B؟:Հc`Rۭ{V En2DQ@ 9G4Ʉ:^D礠k & \_ŹsO˰/j Ŀt#E6:KIJu_4L}@]y.߮NO-aϲ5Y)Q[p8`=%q}-V؟~BJ-d!m_L;uƸ+<[+3UM}1xl0uaS%ҽQ2M0' g4f}/wी{7/;K.#h`$⸿Xؑ=_KUR0BQ#Rz 9,铁#BC@bLZ !̱M?6 Κ@ 0TGpNJ_$6c:xX_TFt7s}$&kt1ܯi̯6Ba 2+z:%w/7`Ĵʳ?ijawcNG~688LaGsՆ-{"4I_YV3k@aYfweQDanK>mZ@$qyVM w^H\Ǽ}yMlFj9#B͹d;,ߜl\MorTKFi@g<_% 2/^O=񫟼k@c:uocE)9|/%{^ir`s8;u6ws$**䈈ijEV3esٷ`YADc}#->Fᣐ{w͋/B;n*V$# [.bA@,\eͭ=|#ZWm 71$$b 5F?[VG(ۉrr=@mM^*'EJ˒zBJ_ޜ܁l ձS!.$B^MښT|.q&|mk-)հaDzILJ[r(mj 9;)X{1b&O^G,Z!&{[6)B)pEAM!hz-7 3*XgP8B1q 3 De 'Z?@Z*zXgE٦tqs XޥBTY͐,u!J2LyZ.M`A:<&n߂5j-mJ>f2X{h^R:%rLWf6 &7ҵ}.֣Vh"77Zn%usj|| tיl%3ǥF1T nga97l$ذd|\`H'^H59&ҁ0j΃># "a6Z?N^1 hLȮ9_aFRbN6ɚfO]ZN9lp7v.phŦsQAc{0Px!6v6:$"u]WR vֻP -LSgH*M k, Y{uYz`# 1`#6bI<=tUo8[0#4 (ZaRt';m .0p.KQ/bZId*:M ž26k8|mStq8Ÿ~U5qH[ ZG1Kɶ{L33N´jkc'KVFxLV1gy/[û9>UW'#x^e6Nٟ({BZhJ%P0 te{N)` H+6ryfn-;;.۫x Pi81ec7q6S+;H6p5Q@r(J׮I& YwOBjcra]7!9d|D+1CmǪC@x9Px=m j0ˆ"JC *a b/%,]}zK?ZP̋𵄵O-$z\0qc1s \J j~+ܩQ;0 ˤ hBwaW2ڡ8nr_T=J-oֽ^AC ԇ. 3g:BRU9ɦtp_rW;7mJCV?Q#ŴD%VyxųtR_oy{<\u!9ďΞCEd+8?Ѽ"cH_db2_28*Dy9M{UjD;E~0sDٓC$V 3LlαH^4= 3]Ѧ VU^ÈM'Dm.K ɖ^[ GA<,8T#jAv3܋b; jy#w6 pPF Qܩ)64 'j⭢$BBO'}5׾+hn'^d6h-+lկ`Φ-Z0Ĕ&0;.2yMVbc\B-(6BA4cM6^OܶQ0bik 5dd垑2qH%탣Py}; ٓ8x[SV3Ft+Kˌ6^rVF(:dejOJ󰧀6qwOoX#dQᏔb |]{q=8f #*r`b]m])QU m;qK}x[x7l5f>!{M8t݉}X>po %9姨0OxθuY wBYۻeB&5Ҧ7HXr'zIY'V7,bǓ92 ղqS#2( 1ԭ09b " dq{-T-'OؗB^rdġphFW@QR"(ynyׁ=@ӘXtȔk~kXc[pdLt9$P7\kCŲ½tIkNO#rpj6#"R#%!)L;,XC+OM֣[K^ [@Q2`gn썂z۪~917u Ս\0? HWxcpH1vP3iHh,h9׿q_N/o „AO3b:(ɐ;&O08g(0$3 CHҤ :,aoj^g N5'r"0zoA'pFN?$72)U*b'^$TX^k`֮́Z 6?pRgl^jn1-n:_ XεloJ]V*Zp_2k\TW?]>3b;i”nj~pU4Ya˛]* q]Kn%TɱXn%vAP-~Yv^t/1QA3r #}zfm|mwj Gh8];TxO JQDʪ u"LIbH T=s{$6@r8"d6W^C''Hwzyܛj%qZˉ g2IDF1dBr/@%.n(H8BX.Ǩ(h{[v5tfTcz~M6ƞ:PkϻsFncBm#5 /pL3r/]d@u ?-^!Dx$e?hb|$ {4 µ_*c3I/e_fyP/B5Þ+EqE@v]9; -]o$KMXP(瞺rkFiy4dzcj~!?㶈 Uq`xѶ+U5.;U0;ꌔMթUWa3d|P7%f|zˬRAnQJ(4zvsff"4MVlO"0MmW%d>~2Pa:Ś&9WAN&d-ç|z0VUG;;hw*b_vc1]_Ts{&={'@Q|.$JDTAI}>V ٜ~6zkdLw/yFNyS aG݅r R r`\?7xS!)^X(/3_3 P~7}b?R֩_E~QcܽzklL ! V+pp 2'WmN7hvm#{F=m|X QPT7,^E2o '-0y V= E2¬3TBw9مȑlF6(CR j'ECe^ↂqcj›*D;P/z~ӌEq+{2kGҚdϕNhF_)Un1R HJGz9+DV*IS3Kr >៨~an`^^cioz9^~xT~xhZI &́y)E`h{ yKeFt"yZ;]vP.}D_>ߤʾA677L~:dg_iƳ1/&(m:hRQGB%0nfw<]vA!mQe>`P۴YRޮ"2ޢ1͚,ܛV<㬝qG]}ZvQb؞P̐[IT=G.Ko)T(iN)4 %K45 ?Aߗ ʨ_*hLqξz2h;SRbTS'zޝq5Roݝ'G[-)-CoMN4Q'CYO/`h]=}l*"?g)+;:-WV5 rceu-VNPG4 ~ mYb8~D,I!ͥڴ״1CP$Cr*ԗ4c%}L^9%t6ZQ@Ʃ8^91մ2=D.;Eت;=e2fJg{( CZ^la?G4}Q@N"&4,̦Dߜ"v ^UG`wt.,c9orc?ark`u|Vk\Kc3xsrǾܭ2IٷpKTC/\JuW0#7PI:$,@#xl|}KK# +¯ߟTH. 㚣+}+rSI9쪏3x\}cZ9Vj%j FƲSI(Kٷܰ+;Z ף|*8{zuF1d3i̓#h(2epV(V%N`ޒAg]eU(F6_Af#*LEbub>) 'QLl)0R 﨨SMSz Uqb.UcAѰɭ&@'6GC(d/kaĨ9̧ˁk3Cv߾ MPoKP`g ~&+8S%}4!֢Z0"uyӞFKrv -M^ArlFO"e,C +6|lqfl&w9) 3U6|nSC4CPaFR]N;@1 9+4#vj?,a~C,:>R44BV^ Z)#`KrZ)o'aWWVU襐O\oYkf[Aߝ`ak^R{Sy\ n'%c]>͚qC7ʯ*XAس}f:\hj}bMm "əZ؛KP ԥ_P1ۨ6bO@~7+'}’ LKJ)c9\'+/<® D"J)t^\ݠ&%E(;rKgKe`< !5H,] :i)#i (|Dx nsH#78ee> 4CՃ5GI$.Ϭcy`kϳ9iOD72i3԰o%CʴBG? *45^cS=QmHl٬QFtת:қ nģr&i^;uun$e /%8xlHyt@\ͪuoZu7TE4`0J._/[ĨT^gQf[J%m7Ճ[^xxZMƧ6BR]$\L08EIHH0tHRTŠG 0 wy6, f#@>rB<'IHe}%ct˷+7j$l|j׿(YP T@1} uhk*ފnS!9c(S{0(L<1h2˜2݇7~R(՛WF*0>x֟=RhZ,='_8 d2sϕ{.L][c@ϳ*445)t'u?_ =7n=a&.Rs5-;=c̵sl]Zޱ9Y,n6KV [ִ+3g-9j;[Fe'q@%"S+C k36&$4BFqghD9_QC[[\7NϤvjx&ͧ"wÒJ%l@fJ6*OiRQ]g\2N1 fv>M'?P~ GlZ9 3̴j('<51j盡\ {,>qi="]Lon'.DYCn+%mŔwڳԤ-Y~VoUj2.ۜ8NSq?Dt.\8M1Ԅ_}o'v>aY h(5檻 a~07<^7eY|'sj$E91b?`(\:. kHPHSqb2`^@_h)I.MKG8> YIb XhEvt&כ'Nf7*np(ݓ#1 QJS,G4c9"Fr^aR>}¨H+G!1{S{ݖaYbHZ7P#^rZbTmTo3_޽59}sT=HTvDTۆj0 S3M4"wZyőJ#d꼹2ŪL>T*,i)%EPmq6WLpwO=8vwc k[*H T]De1"q3[1wRGB|&ږ\<;}-NG{{o}=J@ZЊ+I#ĸ)SGi@WFc|MJu[Y`MdcNq!\ܥ?VtRP{ +vZ1֏0}5DJXl ܖHT wRwO6tyc5LWnF)d0V(Rԇ_|'Ӷl$=iSD{@Ҧ-KtFS F]4P[.)P ,ܣ5#&7Wʓa*"Qq G.~5|+Y*-‰YVbR;১oyع{ bF!s3Ƚ,wl'İu.+qb#Y6+Z09/bcXχŒ6]-F{Q^q;7=q9Ac, n_A ^J8X#:)Wu%46kjɉț]!Tb`YLG8!t"X^0/ 54/BO"M_’Ze(G, v@yuz$$^6E&q*j7c5!xL}VmDgn-3B6*"́E. a&fP8nxX**QOX$gNG*nO 3(%R׵N@/pYkp<* Y!ШJZ1cn Jk 8d,"ZEpdF]CGiUFvH+GM!c6g{ PSUoI5}9R'i-u\ EQNVy[7):Ș_^K{>椴Ӏx4"r2 a 9zK5uuKy H iC?[QQ"B$%jdӫ<4[ݼFE!BW<`Gd~l,Ƅ88]((민ICc}\EA oSJƫa`j:X5]l~sO!_:kƃ'  :!qayC@!2sX:JFwRaX zr4@+K/B1,78:fr<"l;mh{+G2hYND.I2Z9XB5IW~|7Q$}d"ßWgD)_>jEHZI wU~t,p71f .;|^|E7F8,jhc Z!zq !A]*)ŏfRcYbx״0L$6`.qY%@1t*tP)-}0Yn ?P:׀?@o8^{\N"n`3/q0lG[SGCLZ?HNqc`]lv z1j+UDBD d)>gi>Ei'J܇|Φ`+C'D &,X-:9 m \5ۃ3nzVJ7#EV]ڦ3fspNC:r] (U=N6Xǒ?  #}yqlB<"`GW.eȠ'q10BU8S9E;*bFqK5h%DDR#o1J)5qdqJI:Tg t16H<Ć= ZKG}u!ҠT_2F/ 8.[ ǒPi)frKV Y4.91R6A,e5WEA#YAg]HM FCd @հ%"oqSWTR;9^FA b:9mV y{ PG-{7.[5Rgr)yE#Hid`򟽗o\,:-J|`(Caz%GOdg^R?Up ޭ̹)ΓrwJ2|Dܬ_#ɮŢ4jv&9z@!\szGWvȆ֢EWY,G\ &uB`;u[!N?4OsߊvAج١ @^=T t"hmPzHu1*)~2}xPEp>r$@ fpރ`)^n=SxJToW1~*Nv8+4f:0)\;^GVqui <մ[>8hoS񧿄FO{R \6:{| _NL2 ࿱ T8HQpw>uL!!.Km.Ҕ%lj/a86Ay SM~fTdig/Tw"j4]:UQi~D0* |T`kw&e'G̀Nb6J-k.h-A@oh6X h\%$ڹ;_ j^=ֱ$Іv~X}v51άkctӜ0ކ13ȇs`;21G#lwq i晣˹q d/0KA/_acY]A67꘨2cȂulUiWZv@@r=b,RG~ힵ]P$Mc{6r3dHj׿D@$gUoM.5LR,vjeۢWM8M? έ"dUA}Q\6l2aj/Ny T: %ս9:x‘ Øk0! ['Yv}.(Y:,"Qӄ/y #Qq~N{T#o1&l&,SԡJj^0\ k Tm ?mDUgΟTrBB-Üs ҟA'l˲"ľOX%ؐD!4 _2Kq:OQ([IWe1Ec]-FY[ĥ_;]Q ܍6zlCRVg{x`:ްJ6!y@Æ D}{DZxVJjgE; dMԈS$R^7j"ߊg+RE0}Tϭi6[K0MtaYaB9ttLko|5}-| %%,|hI-= td\ᤱ3JsB7hje.o9n6y~#7nU:pm8MBؚ'ϛd"|Y1`- s %(oIVF"~nP[D {Ty1\~EFwdPR9AE s`[AЂ(@nX㝬yVY€ cBtʚ.ɂp˨":ft)ĂtmH%f8K7_ :M~x? ڸ}xAʽWqB2N43Wa-M<~zo1tų"sj?Z QÁU朂n?TM?8Θ,L'ˡ:=Qst׮!]wJYzK93⪧(E+[8*-DAn^Dһ^9Z%}|1/NNeL%0u}$|2^XE;(pz˹NBw?\[1ހH}xR lJJ .ۮ}4msHDd$tPV@ۻŇ+b1c>K [AȆw|VGA$U'? BXFm^*C7?>8QODӨ VVUp'd|`1Y,q2=@qЅrP;K⌉9P=BN~]8!p\lg U#(VDN͏A'p7'U@o)dq@KL2}9 S#`gʀmo1i@M(SvQ*r1(EGP2j)A\7puw N7ŲNU b;(5䫥f~Qfh yeW"}ۇ]]18)NA~ڈ@<|pB^7 /i;(g]J/k4Gi!B/N!фo$;Rq-W-2[;#2$!(0䮷6ƪX~@7S2,iA.. ?Ch]H[.W(4ɊUmlaDǓ[K1 pS̪i}j~MR,na8Y3|Y9Ʃ@+ `HNo @Qi]+mIޚ^5f"I] )ɜ׷JqH0-Ot6' s~`0>ƌn, Yqgîno4y"oY*bG5rgGθ SY`hY8RW= kk{,Z by-'z2nboq [E9hf "'oz^"^ل$M=<(!slo;ܺI_ꏶ$T^@W^B ojt8_SLp'ր2ULx}&$V}ÿodgNz>a#~,*'@h#9KOecL.g3%) iƔwPlhd3ŝV+9h^X [PtH'k)ag?=b+r((}װ'͛R",p8rḦ̠إ:K9?mrd&el@K@[a ]J~yG^ګ<x_ nn_5.uk-\sYqtw.3b;I^¨4Q_y }!5?8a~dDWUj)X9θǘ($l;@[#t_|NFr0V&:^E=aGrREU\Z|[hXh"Wr\ϧA47U,_!ꦧ+?I =jEy& HJw~ >|so#A+ @ 5 Bc \LV'rzUeL1V9iѱ9lE }|ǭ} a~eB &UkUf Z!C4MBlژÈ;hlygHaMS"U r.WVOooN'0Q(B(PцF>Nbx(tn= ݌ [%&\΄a?-Ȃdp.2>I hQˉx_S'+%e|(/ F!  ? I}`".C]0$gk8" !b25Onܧ`+Jm#j>X=ƽH5 k&AAըb{6' yG% ϗ ~V ^;ܴ2Z9{S8zlTG~ͪ컁~npŌO*Coȋ1̖uțX> R5?jpHBJ9V_ts69jX su3"IӊhZ; _TǷr XcW1jjE `9 AµELf samz=eRNqCBH_]~j< [Ε'(M-Sz4my>C 9bs'iCtl΀e8  [05mf=`zk`{{Nv'R {mKp nƔm(3 G^OB!.Y ?UC QZsYaھt!HT$̈́ߣ UHz ]5T2E|67-0I`=BqRXD;娹%~d8l#⪒"KP m _y/bLojbp+ 6[3nz ,@F\?7Yb؁nh╩1rXaX`C~*zTZ?0w)",:M|IM-b_7P7cP4yV| Ј!-; enƮiΐPH\]ksxZj_K֗9zP+ј07E 48 t_bn c{֠nTUMٵp̫lY8=X^V٬(P^WDQù)-cSZh_8rF~qq3Ћ/T5 @ҪJT! qF0fR }-[7<-[VKYdWw6qݱhrUc7S3g61KXZ6\Ui)ՅLYm|]Q(< )a T٧ ]?ʴ \ig=/O=X5fmK''4cS>"2CIWk9?66(F%Izō-@%m '2$ Rǡg Bb'&^/!-[FQ9:_/:L8!i뛣AKn+G1!S4/~:[27ToxVi2?dec1F*OG,靕R~|+XdkzX,r3NI ȍ_cѹ^9`@%)g;ߢ=|P,z]c;sn1Q}Pk[ٛ{ [VCԅgD_ZAf pjR.z.jVW+gCP'0$wڪc̽ 5'bq y~5uy_;C|0{rfG', ٝԸ1ZG{j|]#8'96(%4kx>U^]!(W! Nw`~uTN8z6Ef5GY@q;؈i)9*+w:fIsr=bԕ9əvF=‰'Qvw+e^\ +'3|#+=Ue]bLwiB)S0pC(Td#+&RGYi \ @wI~^NX]>%db|YxB=uKemmHk.MD ߟ*h;?xr-Pߩ%.1;氄)}\`](/D\X>]D,t=4cLSlx;rmdc<גE.笥8B(%z-hժ"݇8>0Hm]/Ia|ZO8SR}fl>>dw;BG t[Tr2SzI>}>G3P% ۑ)UMLOlJZ5 L]sKR}6‰ދMӹLEwU2!ǑUL~)gRElksgܬ{Џ)O5I~2'1}z9E1?BJY@CBkY**݃\d<J1:Y2^;54nɴtb6:w|2r*s5i M2:hv0EdϱkA7L3d77'WkӉQO㼭; W?RYŕ`.z 2SbUk:]IGi)+%VXĂ^GqqPzf9CÇpi C)^L?YUCuʟew0y۞{ &Ȋ&HЪ7?ҫ YT'e<:XF+-STji2A!*]:7wJ.۴!I10>*j 7r.8?xq GpR"IźM$vr[;fn4ڑCiڊPS ~5!W~I ':$pz5#H){r?!s\%cDtg6k2إ}煷+l,-bHNH8S ;|Wϭ2eb5љF3E)b*_p_fH}ut|I#Aϗ1A|H`J ց7dP6J*')KL]g ^̓Re,_-'mRE#ƍbQuݦ=mϔ {BaZogfHM82 9lڌ$o6yȲ?&AT"Ы3: zgl.w2rIkpO+Tf}LosOcw.59E2fCTr) *Z, .QǦn~{?U5]^ xaTB$)P0"hFΈ,2Rc QF&LB )jl<@Q%*MK veJmQīoH%+D|rx'-,"pƞy#-tr翫r\1O#ZG7\?<MuFNUK!dR,38tmIM7_聭S b\2Ũ߯uLgQ36| ]BxWa~BoQCI<5c!`*@Y:Jl'5̂4nlF  E=(@'~i:iп&#O]ژ()W 8ɒBf%O(k=᧜zDQ~ًqŸ忊j <ϑfk+(lSL٠Cm !2pȦAة*wqV(OQ1vo!r=f.ȝn#1#C&*%($EH)'Ҥ=$Bi֩ TFwEq=x(pcrY1Ѱ'Ny4#!;i׫1ȱN#K-9EOa}V82`iUhXM2YO;LElⰸ+2٨a,B0΍.')p;Hq QqQzwyyhmMrg HU11 dT̤FsJc~U`^*4([aa/U|cs-,Q;41q:#pڗiSJ.R1L'j~=H]F>/mOG;z~ dEzO$d̳]r?n87*B"ȧ3>O.h3 /bT C=tN~IL&e aj B5,5,XwdwSV† ԼJXR̄vSf@*W﫬Nkc˙";6h,l>D|3 8d;Bϴ90Qvcq/& Ts:q|sz~Na}ĭ$91utߣN3dlpFL4j6@=G)^O[Un(z[㑦;_!(Ɣ_g'#Yke̽\CO0E`ka+J ߻|ARj%jןƂwAYU^;}&`f<+,1Hn1$8ivf$~_FG(HNEd2i8ɿ 0Afk$%q#^bR%!n{vH "^*E)*=ai୏TSa/w}'ȧ;PZ urDjӹS9TANjyҳ k2s]Q|%!!n;`}j-3jFzjAղ}-ʑͤ mQ hvf7ɓyN~~@̞FIRuA@fFAc%t_r~+ .|U3(EKu1!"}܊^ 3TGߠU>}qnDi6 05"P٩(8qWpg.Rw4Z]_)[mDuᙙs%Oz"ѸW2<-ci=d^ﮐdlzsaid` Mb*ik5nd ɽQpGL@:@e.L(` (Ǧ @ifغ^ĩ_ ':I6a4']-Y: br ۈy+NqTN$̭5Gũ_3,2J_-wt`+9-'œҷoO 6v ے~ECui,p]<^mF L'ki@ 9îaY/*^uprpn詈${/+Ɂ"PoݛFJ]j=t4my-42]ᣑE'h$F+^ ukL\mqa/^`ͮ҃LE'%=X h7 ͅl(h/^W }M$+UUkuZ`UoM8<,UI^.Ma8DwC̮Đ]y-Q /S* X}Z2mpT#t.cZ"oIv_ EmЫNRb4vW-祏/FsyI6[ẚiG-8FY>vPvodI&[:R-no5ܚ:-^W5`Z,=NWBxD(Mѷ:yUNjb;@aڮkƏ^^&bl8oz,,]g@qd/ER}|rߛSbS?]Q+"Xv@" %C^ > )',# l8x~և+i)>ihu ͛nOLJ6y' _bl1Y DYiiA<(^w"1&5v@DĺhG26#9Ao< 4T2q_q#vs'>` qKUKFnu+/cbUƛihC8 $FЏ.ff1kjVa@}xRbO#ZHZ(^B FqbSTt?Ww+!JsYYOx@ݒywWUHMq܆$Jȁߝx5gxZ0 ޜe/lj9]<=+ostws8k{O-wؽ> 0pc%Z]]/x_⇺%)<^ƼR/Q\%Z-&ҟ|'7A d N)kb11;i HZ'd =c$KrъFX(`qbѡoIIYIB!9.[9Ɉ&D3G&zu˜KͅšV4-VI#8wu_""ks\;P}TK㲥Nq[bT$tb="Pqtَ^sfծ*vȡr%z*Lodw<xEܻq"EHFҩQ] W #ChRy8eh]aUǚKrEhs-_Xs7#mڎN#ЕQ.MJX?|ƒ]LL~8&ph6b'+]]TF)+] NF իkʸˀ싡W>p~3Dб~{,'CN2H&i9<,qk.`;_OX@NJK45t5RpPS%"XmPDvƝ魍; 5d^ռD[eLܝaSy1Lqt`T݄f*DI$R T>Kp 0;?`a#ôPIYpDMcizŚ'*1]amkfvẉ#W:_]oLsEPkG@.E:0h9aS*ǓnjJXD|~YdФ4J1oVL׼drXj&5WjWS)ũ׉ xe ywn`p'M6u Zmi_ڿ޸C4/qc^=ԴŤG(=uFu^D{zHHe#CB0G4[XֵE4&%%ӷv%A4kS8y UEjui =vݷuMEK=1zQd/)GiuйAٱ.+/Ges˕pO(w؞K,\"LApFcP_u uMX(xCAd\{Fin"E< G/`VhN|I4닜A>a$JcGG(LMK udZU!]ߊ2 BVF g f'4ztxid#zu}ҕ^PP#gS53GkF 1!ƆOn)B:ӷ_@!ޏSa.WMΙOl..gM(m`_R`dC<ae^53V+^53cCΆ&=3qE:e/PC& bŚNerOՒ+w;GC>IDNj/FFI]`vka>T6&d%r ~(ʅ14wJ&@e`KԾ|%^┶lT ˈIf=#*7z Rҡ執8Gᩘ/,OMQkkukWx3a@˔0WkП*]FtH. `냸1R{G-~WmEy &V80ܬŲ;OOL{UZxW2`EݢcXqGPɈ-{GgqA~^pL?s?w^褹#Z;\npO KE %^ª2bG2OЊ89Ú5#{}`ݡN1{ћH)P( wC`/'a6:BV/5qk G=NSXvA[${ҩKhYt܄ @Nҭq8׸tJG_+H+)X@c: 5cs;L<ܦ{N MZ8t(݄{i# 欖^v3*!x50dbr {:t,8dT86ؐ:x÷k`/뾠O3OJ> ]w7c]yEX |X r*c~O2BMJKf~Lku]>,mn]osP=gV+(PɆ~&\!P $ z)⭽,Ҳe uCf`JIOt~ s:]WH!=tnoouO73sw_f3I?:Q6ײ>MvxKgqw7wtPrH`ʽcU%n9ʿPYrNL^{iǒO?S >ʅ M*+T8RQ3rv?aMȍ xA܌bsǧG+昝lQ>$6BIg?ض\i: ]C#G nsH-6J\ziJ1;v3W{5i -j34^G?q# (eSg*,3N֍rz[Dy8~|-QZrr)l,!bb0(#RkiM$-[@D{9}.Pm4+!Y>֢P8pCkjdKG:x^q1YJ: we%^d' ~@Ά;";m\$TVݕfAu- }f6/I zE26WwXal[UVEeY]45)漝xRI0oNO^OdžWܔ]4aԆv S:GcFSdĥ0V]5AW$1[zY=-E[ǷE+7IݧX3cR.@ b I[199Rc,oL4hN.::>dR{$и dĠyt Dor=caq̚\Ҵ  FȻȼy\-v!Pƞ>t3@ԑQ醃e*a P:#/-@u%Yӑc{Y%(dvB#ں}Ҩ,4A=.i * )+M{Rtw{:QTXZ"l𛆄?Jog: .!5\uj(!AcnO #8ZlS>`қ;u}"G{N:x)OU^yx>OsCl@vb ϓK Q6`(DͱS,eH\P,Z\H!oŰemmγ )z(dH"Z8#iv9{gr in)wV #[Kv1]1xG%~Hk4\NZVv-"en{=aJ&rns )l騨W5)E[߯b5 x!-&~)9h)nn=qA[(ϭ;+B:/g=oU% i`if9-!a!: ~gÿ. h)[qzNw(ޙzw,*6k۞q QQ*vҰNNsb&w!%fPX#ڻ3(ˠIXLQ[Q 9q nG^ ?/"(ոҶ5XAM؀ e%N}|3N[QlWmz8 /Ua'B+9P67\>*4l{J¦ ˵۴ʶJhF17YXfP=}j~DH vwp:fV0`n[T69XLWSJZkt> ܼp!a#[s?2~rE/*.O?g_*lvAW4\ܽN/5U.f "'r/:}Ƭ `xOԿl1˭Ul0~\2P(ڰi]\Os{dNnUYDXD ?xlVZ>qwUXoUI,^:tB:O],.xBpĢ/C8v> ې"AذܝeZw4Y.,^;.N rЈnrXS@Ub6u]0PнlRh]W|mL4|lKp]z Y>n~q}RG#m{Rs/@ym^T=ߔ 'rCܹ_٢YUY^mYc0tQ8gVگ:7 S<'}NZ>XQ.z"WQECV a ak{IZ""G.7[|+t Im5(b6UPƒ>_rˁ ˲,-bj>s4zF~+%@vO=r U/Rֳ+؃ 0L@rF'B߅z4•;lj;hW#Tc P~),!aq*^waW+Lu.޸-GKI Τh;088 )&I>H@2 ݃v@iOZݨwS٨f&O'+8%҄\+z9|f0;QqH37޻T~|!Oh T7p~P 9T~ u*l5І9g=<=~vtɢE*`݈7T+-yed[3w{R;, AX/q|쑲 z䩻N4] g|luo ~{bZI~|rDm.j40+whZ">Mfl!\꧅4b%* ~V`=a aIŊ0=i}ZM;[ƟR&gֱZMq*ʨָ#K96M3u M٠Q v&C}cgH4A'v-Z͝x55y>b[E!@>",nmKSzq֏7jBHaתȏh6nDUw9t9_|Qx6lJ s?O w=iJ^>Oguۘ瘩Տ@}*uc".Ya4<`@vX ;δ'ek?gGZKSWєӇn*K`=V<*2 ߝ렒[S0=>lBdWPdM@G.\L6臝d?80+n>9K]61(.X5U4F MG\?k]!{> x=4?tD52z';=iFAS_~|6Nv XZRa-+q G~`adqgOa| {%nwaLmVι(^^̂KexvvP'DĻ̿Ts:sl8Y ~@[CWmPӚ : xr]筙=M&=y_nǟ{h^')7N%7qer6ls.x[-Uij#w(W:P\-CpNifiHNB.b.lE֓]^̄^i+&,žLI-7ЏddO.>zX.`0[/X- L0f!KqK(} AQh=EWuy $D鰘+D_K-Һk0d?2vFt%LQăU0ݧ.k/kF.lo}%{6ٛhУvjh$7K4߉-_RW]DS42&3>S BI]8)%d;@" +\Âl  )V%B nxX֞AP wb:8,a$ uHiIMUߑi1%uEХ&YBT`o(1eGqU\YwZe'7v$aԢ,-UլBq#z' ُEf8ܶ?s~?Ō^c`h\Yq\sS*[T1CglDZ܍O X(iϻ]{u6X Iǧv&[hL џ.L(4}0]#8+1hC8׹+ )ׯ5&w{x6֝uLE;!4}^@ yͅUeL $?]Lo.5JaC,xۭ/\,FHLyv:ލ{eZ) U ^W1> 2?` lؘ1rfOjp2 =[X"iV<x<#'pIٯ7w,@,A"E²e}}OZt%xFy6}OXT`'BH֪S“/{OL+d7I. rw7|>h +C8ڝ7n/M )35jbW% ѱw'i˱2d)L7obz:-tm7[#J괞7LzۖBP)J- qH7+-0vY { $?hڡ"\؇glن׺"b~d ,7YS(YADWY6+PK Zl J۩7ȩaHBCIAn0ͦ@'Kt=Z[?lw!,yd3{$~+]O.,wywj3Q zQ=vYKxlΞí)OFH>U[p¿.f~Ufc,Qeߒn,(P h̀jq5gP\B~h<(B]-Czk >/amf&`QVKSw- M*=ANh (ϳL= B'ύ00@cn!.Pco" ൙|[+ũ}: 1&f?qr 2Mwr-8Fy$Cy"!?B2ǹki=c ~ PEF`BM8Np?+}r2VVHE2Ұ[;!Q~)oURЯP9Ruݰwq 9 p 촪@ɘɇGS@娇$#y8rʍ3$'׶Qڸ'S.#rbZ?)PАUV4Lbcˎ@r 0icYR{{YHҙ)dO<{`̡\PְE +TEDJbVquX="o؋VkO1Ȫh"? HcL7x0|Ьpv#ͫ7=˓oXyj+fm{Vq L 1=S/_[XD8[?@S w}?:qǸnj64 r&V l;KQOE9P@t1iG"cp_f>=!m}x WYf}(Ųt0_naS`Ԁ ]Ҫ۵|.WɉpFH4]{v ޻wģy.9FyF4X/}O]ʏ!/߫"1;gkF4L3PS+Ec~u6c18ѝL@T ޝ ֢L&\70 9Ct2"xm'O! \="OT*#Ũ)!v9\Ab9aӴqòȥpWql"hcL됴}%ꗗVvP C!3=5 p@ʀMcfh[m:K|TW<`MSPU {6Nr@Ж7[,Ad#spi3&ͷZ8cL/"2UpGؽ~ ڃ3T\.9qY:OftB]3m |Auo|Y /rIMw%Gfg#+?F@N%Cì"A/kW[X%c'kÓX.%`^HLœ[3Y.?]zjA)51"q`TCh8vj4"[ Hkt J龢.< %02pdlbmm 2Kd~1w xgB?/䱖UDQ?4UBp .,oCcL &vd)_0Y #k12H-O[zmG i:1{%P_Xa>|>X5&ⲒuђG ܕW]E _KZ{Lny4% !G'ڠ^lGQ+aSD,|.1Q H:7fYވٴ=srnQ̙ym.r#q[?a_V/؎c(s"jb:J Z s!?/n"G'twaޕQ?g6^%W@.Y\7J5mK95޺w&tҥfREBt,ʹ۪Y: ~Uϊ&v@Ak3U8A,ȵUSnH)%OqD41ڜgL)9G]kaC8 ?V)y^hGixپw /'[knRR |Q[m-uC{H UzE~7By7AdD[G24k%%xn%1ӰFWcQtQ-l<#01MM /1۪68AG|eJjaN6x0,U+߆=HM.P.c v.&> '%, ~_^idx_a]˽z%Rq3Ug*#H[3W /Դ.^.D 2h5&=Е,ȃ"m;W p:WSڢg!ܮ:['z#|lGaK8LGε^ˁ<#g:&YG,&'Wa2]oD?%ȶJa M{K!k<;Ԇߐdh,bp joE@hjf?2}+Џإ &R3 P/~^vMelJ NXjV7K'R <}Q#whЃ[PVҵ%k ϸ[3 耵ӽމkA_.x^x|K Ҵ3 kX/vv ܝt%C * {!/}G,UW$-;xB.z+Y=}™TvN- } }4pho޼s ܍|6}1$7pGjPO\L8u | E7P#r<\thOw寤z4ʂ~zJ?} o"#=bSA&%A=r gC=%M~Ajx6t.싴HIbH+Lm#_c_5z@*F6DϦ>re$>}qEcH[TMHQKA W";YhqQj)e2Jbs{gHvL1=yJxk98(,1U啒CyEO3f"CWѴƒQ΃ֵ0$SBjݍ$$EFalLKUFi[@ nda<aWZ] u3] _Npx%-ɂ &ѿY,ٜ0zV_*Ji}Gͻp ŝ$ 2ʞ軜R(QDP.#Σ^n$Z dA&bpȴNYUr^uakbEYH}dy{ þ_ G{zCsC'ovC"FFQȃ-~þݪ juXOh O"9;#!@mn3;υ6Cv-;5S=~HNpyY269J`C˵gZmk~*oDk,1gx<"&W"uUI*g.KKu1'爎-u$PK J\5g3}R9 t'$4;u^zq†I*0CUq3q%bsDj$"60{(Y{ңdf;^RuP2.wx,8<>._dЀP{Hh?>ژ"cϝmfI3g -+k)KͥB>B0[`_QӝJ*v.Ͱӳ* -c rݳLCsNW}m ] |[Q"/6No>T8|]B_ꫡFJMvq?Tb0)~ e7d!IaiOp8VJOw\js vb(o}aDs&P]<|rslbM3yEk-o֔1E_`pDOұLH3;(aF|} B@L!?L6M ;Y[uu~`#ġ =W˰ C!SҮX:4 ,nz';MB9tv*G5٤j}wsn:1^{ .\YU~Fi."rdԇlx㮫?h|tǺČꀫ6LB7#?YwO4; _C[RxҰ4Šݰ1&Qo-B80rii`n}Swä-RyT6dt(f nAKcڴ]HTSzcN|e=}g+Ifg p=X ZR>.쎈?SƠa(U)V u'3r3L~D<)[u ],N~TS]l}01߁-W?W<J7):A)0xBhHb L`}$"MKاWO,Z[ N͐Ѧu4ƴӼR}:A?IǧZ5_)vb$@pI&Ӽ`/SAW3eC݁9uC7yA!U<4`R9b5,.7qxA H6~6'NhnoT! [T)Q\ mdD=cV_2 x)_4K#S4w8JӮhLuP יtES?ohy}[p31E'P.ǷVd)`STtYDʌIK[eW5>0=LwI{Q5f7~.![ZHN=%Hb$$hrɡ#JN;,#ըu-5 .k8%,'Ya7KSwO.j!'e@@8d=t37»pˆ׌EUS/g3I>.6g)xy_U(ٛ ŠXT|#Lvl0Wk JVbOל=@wwdN'WW* /5"UK'ٶΡ(RXOo1viR"agR57Me-8d*lC4kvL| PP ]Rw OڲMC%dYn*} ٠9gQ6{Wxi?u_qpn ( ި( 8$_ Mx2˻ЊxO:gPQ`>L>PS/18 J ۝,L qVHNc˽ؕJOx!$NNi]wοptKu˱LjTSQ*ΎwGuoVc'H&<9$ ⺭@[D|"ejpOhns5W ٦|UZꓣyO\H)a:Lvg'dcoC*[ Љ@~s՚LL.f8BcO8O!vH]2%7W.C܉Z:؄av4Jc 8)D^IG ^Zݛ(1(N4=qutLH }8%!afp$sC#K~c1 >i[ĻuoHX*AsW<`τ~m.OEcqQCͥ#zFI/$+ eim#\A[B gQݓ+p:п{Yb -c֞ +ݷHPfWw|noY9"q@jJkE%ymYo P?ds!LƋo|)WΪ |C/}&$fދQ)̦kQ+T/ӕ˒ZcAQBG۴['Bhd{ˡM ݩ% Pz̗_"QvcȂ}k~wXcmթ9ͳ}++#d=RZ o<F}e K2`3GN|EU҈"”F{-SC1ՙ?5^py/cQ{XNg!>8'um} g9XgLTw?G(k A6MD o*}LU\J7Ј(㱈 ̙'*Hrz(|iB=Zij\,$j\Vow&-;6R>%ht+hKit]1x'9['y\ GelG99ڎn2R+jV"}# 7e030Naj?.N<F,]*ܗ/.Fj78QxoЫwV&'ETQ YwT64 ua %=wA؆yir.tDGm0&8Agscqs|ޛ qU>bfMBF;25u`3CL_s74x{AN 0o 6L:@j5HgD]򃠷>: ;Sq$l|Χ1=s!|Pss\u sR!`%`:js#Fׁ{f-X&ј>C~:}Z *r)-] _[-%$c5g¨ xurQɎ'w2ҹJhC d~Dw/Ml48f5Z>nmA7˃ʹ?Ag ]v'gPl: ˕+B*]Yw@[j65v%8۰(i]D%^M}5DIg&T7J;};5b-\Y8()qG*@\+bm9 šSwrV.J-~ <y2~ IN9 q9A6F=J(qXVqLK(ا}H%hcX xdȌBv{}F !_>Zp~϶n /蛭<֩GbtǞjcyjYSJ.8F1ϸ[&!!؅Y0ӧ frmӉĀ,<ݢcPuCƹ`Ӕ[ X@: h&}H:&di2kGHu _C D;@y2: I zp4鹀5w:<)1c5]n&"sCGG. ~$[8 cޅWGף8MDpؚ'Sc^j? C4HGriNx_u"sWY ],KEˉe5Tgگtomx٠hBeXZG&g)¸mc:44 ,(Tc{u5-I(R22Pwkg;/*Mkֻ!TW+ (_\^ᵌ>" `h`)L 0SrpOXć-ꔇ/ׯ^-[֢%&8A! ݜ#Zv?V ,e+ޏǠp[dгp}ll_|dF t. ^h{ 94?? v4#6yQ52ċX10[Ajِqт2!CmJp#>p4S%C.Gtr26(ț3J* /.,XcJD8H`\fɊWKDMg-s=(32QaMc4Uרެ%OFTb9Al`.B /uQ"=RB'5wX |[~XhKG5 j6EE?ԓs>Ia+mbV4[#!nS4ovQTw''iг̾Ǩx;csG2c㱦d0D IlQ5#En8z=0:!٭)5.ht'D="j_f6=6 dER(*IX StuÊ)ֺs&VdK[z~ <ºSR ,DlpA_U6OyͿTQvZm5,3Vҏb+.@ށް%6:W,,!>W v# gV5d`%Ü-b+듈 E掉,i"|Kt_ǒٿMrz4b$L:]zaM:ާ<>4Dq _Tx1.kX cU7=FEYH: ;= ^e?q%< Cz!So,vkXE0 7ܘS u$n~2vpuA{zKI}UߵZ !oV^x Nn6G=cܫh ӝY5c\aͅPnhhقqT}o$ t-I P-g]i6 CS+;5Nِ3t'状I?&u0V ?Aޑ|oWVly:f uq6yZNllD,P$1·=mk=Ua^ S v!֩FT"?GhHąH_}4FLxy?*+M\mB$FVV¶a ~* jXa ij, LeӞ߆hBѹꞢҘFE*_ywHS*r8:0$g#7E [N.͂_Q'3w)RL{ce7l/lD:hdNo^ǘ>Zܮbgp$M5 $`faGGmOVaI64)DIv4b@|~){NDh't,.oFg"d 똇IB O|zWzu UL\ s4Ư61Rɰńq@"? .}gs&~meF;28 'kk7taSa9g>I@dUDθ' D;}/'m5(-G!jf(&5ؒP>B>ebLba--#B/FvPE-0g֢@2 Qow^J Jj.4&ck)*6nҬ%"P|aY̱)v֕H팴|Nzh#=AܕቖyWX)V`1J7VۜOͼW9B.e 7  K\I0Af`vC}=o.jIM+RpZ yiSdJD`YΎOpmtP zcjb]a)<' e~7=R "K=!5{NI7ښ휒uLFe:_MP]>s!+j꛲"xK:tpԜET2=7qĒ˛e]Q_CxcRýDJT1=!~sՆCЄmo3MK>j>rzIP7qy?ttVE 1 t$T,DLHp0^y{!4~]۹Ek-ZLyFz2UuQ':Kտ 68=RXyă9x%Q%q_jqm\lU-h]ූ[ʚƒ^>:_Z2-ܾ٤!/ qywip!u w"$Ϣ ۺ\(C*<DOJ1j4aK^ULBx |gî]h|BT/ LL%u+Ʒ2MgsT x*OauRlX~K [d*b',R|1Kz/0?븺Na^{I˩Z"h$FY7@YE0OJkJD_-Û4/ǴNќ/{~y,g M´ s y;|nY J{(h敢is2lFJIF5 4WA*f"BhskSD͍?'Y=5.vLt$Z -K*pSGg }.ho/*tk6=+wmYo@gX|Azc0ۭS#DH6zv8ÉA[%6O)Zv 73pi\x+\ȗc'JLw1 Ia:#H*N6{?LCb삻++~ V2$)H]x7||q:8堢OQG {NaT !#@ۋV,7B_LE.%06[8{=>'9,zXB0e:Q?Na j,u?a'0_unj􂡥1IF9VS@RLBWkhd-YzDXiS-aXj!H1wʴ;QkNؗx^7~BϚ8 $N:ib.n$;ݤi(&:)^C?z9}DyQ,xjpv~'2P$wwEރѲ*aFGvZ1} ^nYhV@:3ot-тLTmgZ9x`z'^LtÖ)OQ{6wJ }+imf2jtnӆ{؏K"bHܛ=+):h!.cЇO8wƶ ѭkB=pt/jMoT=+~(8xr a{Dij Zpq"*(Pө}sRf{|u.滉,ώg#e5g1;l{#URES׋ӧq A5ӾK@L&`;e|<;tTqs"-ody잾>7IRMyT㳰gk5wMױK{I1k1!XSP~  QOVSLSZȯZeȕrw 7oǧHm̺KqP{$2YI$Ft{RH7#x#Q;agLOI`18fO~|guDfnCKA'sOdY KBw_yo{%i;R]܎ WXqyeri^2a /ڶ;o0 "E(0Uld}br7|w{!Uvm$C*[h(a볯.nb׾XB$zlWšTI) 67i3X&]l+Ywh5 rs ^գX̲11C0*<@'ev#! u?MV58H#K #C,sW yI$l +o1Gi'2ɉ`k&zCPO]W!ĥ6Y[E4)I@z ʧ lYĪ@GyBirKAzӱ54-'^rƈ$[ V 2䋸ªXU.i#A5DIhү# -BH!NKs"t+JjǶY6ſy< GyO{fg03ׇp|E$ ϧRXیd^ʧ?=đ uѱ}d$(8d1os~Y':/%q@8p${~q\1&A LHf,(6|rRL,`imL;i֢;̀?UfWAIOZU֚V`FHy׆aTLr#mHD-v-݈j$krss-dP- |ۊw䥇" d$C-LHzi&4fȠd>s Rʣ'R Щ*p6$;$y[? ewȓ7*K~]!~W PVMN]BQȾl#ZjjFBh[W˿_:nDGpSyof ak6qo|>FN9;H0-aHQLJS/Щ L[___`~d() "٥jeupfL!}mo[vF?r P#? nz:I&{-ZSC Փͣ?l i_gH-=`f8709Cg(Ë/41!{yiOyTAb Eh^CYTxKHt㎩dʖ'M;0=/* oӡJd9 7v /s{]=cT]Se+T.pfÇKlR-% 2ܼ׈Mc1& z[53WۚQnz%|*zAA;:A*B# TayԆpbgz3MX_@46dt$+Ӄ۷3#q̑|F~!R'2RƪH'j*!1I@ԭ6y?1d`<[^-0xHA$|cf2I֬ ^R^M FFj* /1wl%$A!͉HeW{:WZ-GY> |Ud'JE͍2ngœ,?\ NnB [w$wIҜ"l<1mof<+dܺA|=hm?uv!rw(SPӺ ZPJL&nYp 'Hm_1Az};fda}Q*?WbLc;awj$xMI_ beO^FF4{GhY8i`T|¿pGò&蟽 dvQb8(Q*e]9?M2 .dž*y('#^?8NЩ8"}z/nqCF}%p=+VC DR~)m8hIm5NY=̪'vt lw]GAS!te$;8}*P=QhYC!'80F:2yfdҒ\SicsQq.3,Ey>zVIJ{ܗ:#f/(:һCS_,!8z^k/-ʣ/HA؜+:lPga!-/eVO i!t;)^ NT[GswȇB|8rSsCw9&.ͭ3iD1†GMߟrֲhr@[`8VVV;r03Tw-pc | ,sl{V؂Q[CnG6{H}"c0՚T{?Z^u Rizyg22y RiN# ȟmNbY*Hܴi-MROP-N ~ͽՌ!]hڗsT€Kv'_9^CN*۸#[g|0-(Lׅ:5tH{SX3DX_IƎ`w2R|BԐ%kUg}z˔ؤ.JDNQPvqF_|/==bI 糉X'g Eˁ*Inx#D%BiθwfE7pMrV,h I8\߹d|qE_ ya؄*6J" 18qc31K%ܰմ➂ /%Wb )R2Kc>VB:hr<5?Q}E˭=C'ƆL{IEn6`NuְP4Tm㮶Tɶm]Ek/XtXBbc݈SX+ڤ pxEYBp ?B-i 35&ʣJ>LǝDN{1a_`[,G{>>!HEb:shRb:FP,'҇TKae?OVsl\2O~LAN?S4(9)y48V&*AĶ{fw<"zqDž߿ ^ѝyuj: lXQ>L|R1 "pK#.c6zd >/q!l;'@ќ0S} `$[DOd/Ң_rtkɢN-)9PM14?D'J"[JRf`85{4[*n د=M Bz<`c1hۡLinY(3a[Ǝ`P!^ǣnPT;eSkWy>R[^0n!E!;꼕FyP"u-c=T)F =9ށ?&[]L:{ վӤFLSQI<6ŊHoSc Qeq`-<;31"g Ì~Ta{;G,߿PӂYBCCZz?+LӖ}R5k/gs,?w&Y0~.BEzReVc1gzbiz'V:,f;SAB{+"l?BM YW*mCw”D_>EFIs7qRby$~xh4wܨ27-fwoRn/n/VUYF/}!nCbikB 1' -h;ѵ8uSq(<^(xmGw II @.4N=,+)MSi\|"3"ځcOkEj?U# ƐK  XD \ao8NE5p*6W^+i S+Ģ  \X!yy2I'muDDH=b4i:ܽzƝ F |]*xqK[ wFl+;WՇ~.AY" ҂ -mvkнQ4HUѠf-b4r1:f N\5vi1iRDYBl%v@SLjDV}!!%t2e]ZF5썹V]ܟ@]o^$7Nú"|.\x'{21clnCLC$u[D'Fɤ^ynA2}r=d]T-I}PzEI2vذrjS_v ='*GuJϳh^tꧠb esGF$6V}]cd6=~;9qٻ:C(O8A{U-b,Ho|jGF,1|ݹĺ%J_s- r Ȗ:__ʓ+Bt0LF,NGtl*b]'ףM xF1Qu2O3nڑhr ;Tvyf/hp (DI4|;q-3\b<<`?0gaVE#A5Qq: ܰ{_O'K^hX29-fBb(g YT;b^p9aYa#Sk ]-*zWߞkZdK7 Ql1BLC+:YbE\b4BxxoR zpQ A!X*,SOԦ9Pz,}e|q'#(%ͬvQkJDy2T/Ljx»JJ$/͍[xz4pf ^v8X0A15=ϙ g]unmekq/؃Xw6]V<7viH&h'`huA/*1;jEq`ZϠ,m2K-A wԚ{;!ˣHzK vbirnń/=yЕ!䗃-Xša儋#6H 4< G8r<9Iq б݇hP"G -ziD #,*DT@1% 38e}9&7k8bpSXmTcm0A &Fv$tr flsu< պQ2SY-́e6/mcE{aoJC `Td WĕIoMXym5\_QXu0ޱb"n0X 8Ma;zpR8n7&;>[ˣǓx)?C$[ԱiQ۷jDyHj|͊⦂a9Gx.N8@P)1t.=!TD-(-Yߟ)詜&ċ"+PgqlV gXI+:b^ىHFkvQ=݇YS A;Zzǫbx /u3ˣgөg<*գb6`bao4UZPqd#o1_`w Hja4A\-,ǩߢ|nd/p P!STt#m Ac_iA>vI;^D+^ ̼] `F_n Ks ~cU#CȽ; S2),#}DAra4T;h╵4L26ewT? ^QNQ 4u`qҲG4"Ԧ)4{|y(Bd>k䂞%aHu`޸3r5h=Cwr"9 xQPu׃* [-a6Ut0 t3L9$zД<EMNb"6N N^"Uc-Tě,`ڂFP*'JrӉ2CDK}`׳v9 v(3bs 颪O/&F̀7EM(-YH/sh]]<7 NYSfmDZ5aiԐk/txAe.{; . û;Z)Vx:@Wb?D,v0slrڰ xȻyҍJd|DՆ<f't_&f(x gkV 7o7ɭ9HH 9sJy>0jbt<h @ zA#2EoݮLڽJm:8s/: Mr2٫@2}ح~5\?Id^?(me͔ -==AuW7T7GvPW䧟[#A'9vĎR1+r/! ]lڛ,3gFm"΍+S 70(,|"e{DL$ O-;FPj-u5S'3O4BESH+J'2Pmo֥D×9G9nU^,AS,rlRƷwI)sXsWŵpx{ֻmNzXt@M;a<Vh( `qóL~iQPt‘ʜfywFt3p+ IƦ5YV4T=E7(n2S(u«;Y*1#cc `80 lsM$N\t 0=֦q)1W(`(֕,7r1ǟ*FmKOVl֣TA/qwE@67;h' ^>c4&Kzd-5iz4=զEhtO.ܔ{|.óUʭPLMŌ/$?m w6P-=N _Y`wɊWx ;ny9F%F$*4YAS\B9P0sX=GEZJ5X~6*0?$7.r@'=^ N-],9|tok&,"^VڇRß՞>( _{7vL D.Gr Q #7947?N{%Rv̜Oy*LtodYSri"Ś2;oLFi, 5t%I 6J 9 6d?g>_ZP7Ohjti p聵{!84 Dw<;ȣr*0n<*{u}f^uŗYYL -^>%T*,;BhD$LxCh.ȱ #Z ?fDUQ~V/^A76/U^ W|VhfGw[@^޿Ą*F@ODK vhv ^$ '^A Q>^Vt׀(ج kS{~ x=KPl|K8Ei t?2X =..c""`bFh i+/hp .D1WWh}rL8P ^]j=m&P*1=;2 -PFWVFlFE^s2eg<[PxZșQjC@z&Zf[E:Df;rF x:&I'!3<(z4y'Ek‹nf9>' w)N"'K,<٪/'^} f \¡$SqƔ#ER!%GzuK?ԍtؖU:A@7H_G+Hޝ\iNH ipEA_=UM$bO~vWn0_wϰ>r )|h2. ,1CS& w( ^UԬpnT) #.>iM(ݿ$1Q˂ `LV`os( +'w0DĐixeP8u1')ؑz[Nm&l0Oh|%IM;xWȢݠק6bU kN r^W mԴH9^F8Z+Ogrl= Jwd6%SpK#i&ڇmTm,8Kg\Xu4xcͩq#}@.:E/RO?A*pnT E]LvNAxr@&o<ظ:u 8#CzsWrv/ tچ5{Ɍ'gJX4vṖHkHoɖ=~x鷢n{bkcS- >^X1^źћ'{+ KG-+=H+بGw?ulDZju!长OέBTU&H" i )J/&"{38.RQM'<." jώ&%͆K'z2\)KЮh>4([nFLUB= C|Ln0T B\*#,:8?7g`|1#ȓ&]Fy"d*B 7x^}o 9K 0`2b@&at`*hx$E#u³2ΣA}+ #t;nV0#T(ogIhOHV )Dzw)N.\L^tAX]L=('Ai3G 3rĄyCL5p^{m3o(}Z֥fЭNᠻ!gS]%~N|dʋ>lrke 7=~ps;3F<36*rV"JT2'G3߂n]`o(`DA}@L?|hN/u5Jpڤg|L;$! Eᆋ+wD4rsڊ*u[ـ=I5q2qaԣQW%8)V"11_p Tt@yT`8zU l6?ꛡ8p(>cNM[ eBiu_l}Cլo|q9ß"Ҷߗ1ɿ!7-l̒XGMd٩`D_ڂwFjɵݎ uQ%_&X)E~uu nw㘨eõOoW7'ú Ux"*H{8[ʟ7,˪v&SivQl- [\Dċ/UO~]%f4 csL[ꭻj f4+&4fv||/S o1V_Ъ :NUf,@67Ez>}բo8E݉LBDZqR$D9C rdRh?䷣2O)vl^P֢͌< |ֻ / s]ckSw~# w`=l%Si,c73uJEozļD6oe0D|YhC[SG&[>FGւ:`me+ÛONnIp%pt,"lt( gf_q9}/J6gi^k$|HK8䎍|r  Ksr1CL?ꛂ%'lus(-Y<| iLCϡ)ݩ"vnMgNַnzy'ń8\i7bYO+xeK`挲jl"ϰ?z1G+*AW>@֣[]#ė,[ [-_tEy]~8G 'B-056574&~u|VJt0?ˬTa0I̼(fv,MЃ\;Rt2f{YM ,s#IR/p(eʋ=W8Dga@a{j&uNƆ")dUmX)JDsiI,6q(*D_-|{V{M z=E56YSP 65r"r>n2x't5.wԤjnqr/p\{_f;KrV)T>1#l 6EBِ$մbjxE巢dT-3ѱ(R1vPex'L5v(бiE>MG4R3ZnO h s-7#"*ŭppD'-'ݹ%'>Df}͆STj3ζ J`e#gg;2pfEdZ$:Ւ!Y q1I7{rEUNQH^UHÚ |퇶x׉nLuyI]4! 4USܺs:֡z27 T\X_ES `'&t"_ >Q\^,D~ؼJwcNﶹ  s7{̅ڿTiCB}"$􂍓zW}JtS0Ƹf,|cg<2s:̦7,Ya<0jݲfIF3d&BǻM)4 Е&σk{eRszY e.DbrץjwX ޟ 3BF.)ZbBK8M)-Pt|ɰ=ri&!xrO-5'M F 8?*-rBWaSX}vGp3v:`7+/ Uj.R`/nOvpBWhsZFz>8KmW p7’l c0${|tro-D< r{am|9u붯SjDpl*Vn&QnNQ), w/ިo2wEP+qUB=4$uo=܋R ht+ 4@@<[GVl xAH$W^Vωa){6eA0l@wQG|TCm|Z2Ū8ϱ^Kv(}}fzIlTo41|ƩJX?Cags'࿩7pk4TL༘R!퉶mnN 1]RU|iu$(W`zySg@, 1 ŒPGcܨv[?Գ8 ob4}otp=]Or,R,v_+oIzU$V 19!TH;HbYm4Z`L^<'?F,$Zq->/v" ` VG$:-AG佪Ŵ \9 BWo ÄbΖRQڷ!L$ŋe-%Ӱ!!_o k=+WB5G(C3/w@'4ʂ|j??^ઉs<=@3ٯ;wN!eNGřbJ<&&Oq~TڞzLJKַ ,OJ2nu K֝`Rb{-cmU؄CwA=M>Nv8`{[xTEv%Nh8D3Ps8޶bSRfgoQA*cݞ /0SYwQcr3tõiQq*3\ ^k0Yb^Y ᄀN-hp_.zKHy?z22+xC,J]e@ Kulzk/β ('դ݀ ~: G~M\9,Q+l[aE"ȋ},d`8L+iIe#]:%kbayPx Ɯm,ݘw ΘbK^v1 xOPzF:MLOm&9-!"9^A%8q9;nؿ~TmԈY=6ʡɽ95(4̈́&hhP`Zmj*ً~Y|:a|4W-n-L&Q3Xa쨘:;?כs@kP]y:zsGUG ߝv;XyȸBpDKם]blO CWdT& $2Vme3~" 3eMPJ R0"Ki2q)z*XM,kCֳT򝃅e,ST3f&'ʁAihAE9iu16vjT-f+ 3A.y񄉫oG?#.Q2 2'=y[o|i$㑏 f`Ar`B%1YhgJ5e{ijFujO=됎H|>)1[ZL\}v*Ah{sݙ],O4Z'|QD1{@jSҠ'mXwcg= pDZ&x#XCk,}aྮ4W+(&.f 0V;;HLB4ӈ7hٹ/Pm~8'Ν驐u;3䁣pwf0LrnW_%hJ\HE/i"`XӍQǙY l+uW"Eoz"ji2e=DL&x8 5Ȣš᣷nD6ST, ++& X3<'fĺj#M$ zn*uBJGÓ [;VW_::X\K?eui7:3GvR蓭xO{m/o-2Dc^*TD /Q)&y~)'tc¶&'MRb.0.]NveuM?-Q!OOz6T$IE-!"<#B{-vᄌ9z9MHGMn?k}/[Q{ ORfq /pS?| 1JXP4U d5HQIRBi}gg1KssnkM18" /* >=񬯅fҖԹW塀z6R;7瞿#$O`Â+P"?2bWԆ >xs}2hdA3!8=< r>j:n .3Xb?a LIқ,'.jU< l聥: )W?GzJ.by(}"O/@ 3.@\bi08`ȹ 9F$-.5F@Kk ƅM<ʼr\pG׽DNܗa6;Wt;]0/ňֽG"|g7M+'O[ esL t(AT y~O1F9J. S0ض9T>큷_wU4`"X<8D,ܑ,bE[ |$ͪZv!"uYnx`bLsNcM/E< \7B$-.OhH^ b o֪aW%{(u(<ɥX({q1[N_Eչ2 e6=?8\EUE#USnjh37 U[񑴢׊vff!cU&b`3-lY]#W^E%Fd4ؿpr$Nn\ѝE+=l0'33af~0K~JO=i87SiD#!,EMp>%j ĀvưJqٶ)2V E˹"Yjۥ<!\u[Z5V2긚Y=Ikjtn7&@Ft/nJ0w{L ;aPZ]~}OJ&jGoYF豽>̡cZo.ߒNG"Gr:m7S>옒j cUb= K^sTF c+Ri%4:?*rLy${eSiGq wxX1d{_~VAuh0*8> vKМ]8QP8Rƀdr8 G^ h/.I3:Y)E-r " ,Ŀe( q9J\HG_ Aiv hsw >4Sش\`ƶSثӇ}U԰T)skoYX[EQZ^tC NOWsINwͳC\]"=xH(F sR%B|0L` Hq,v(e>Zµ'ל̀e)I,pf '`Q:&|ifCv:l<0v\V*2epF+"G6t?`n-yXC`s2J' KcC?= }~W1Uiخ5ȸ"v$B!W[`iV|9hfB! _?7')V{)L @kDn^tm -eFxEg .:z;|2rrfi/+aA=1-lH ()!q m1?)G$;yKo Y%JJg@/36L649ر˜.'4{ VGh\yafϓY[y?*YO䦚)^^vAjAb4^(_t-f"%Un+xfALš2QԽƟџTtr_py3xT}4Ncumgk7k[r;Z !fdFk6,ŧiŏU"k+f/8ӑE*1EMq5EWZe%73b SdgܙpJ='ϟtmoȷ=y׻]J;iNqZ*mL Oݼ_8؋pqnī{=fMג$t]\xEGꞞ]CklvJF, vnB]uc1"czaD*ђmmBL"N& E[*Bh?eV&±'0iGFyv`b7$<_3&|S!Z_{Ym=fƋU}KS>G}V7ZƯ= E>hi)3–ҭV]6Oz)_jwܡf\FF-y^7j$%Oj'VܭfMSIݸ*03/(m@[?wiIr(@~P/7x_#Yr?Y:vv!n1+-`Xq2F hN]hM( !y;㸐]hC#j;JE @YR?z\,.YuAMW {us8e4)tLIOLv%AK;ե98z"ft6zT"ʗݱVc0!ǔPzy!#>_D(y($S\q)1˹7?[{ r׵mxXtC.UI9- {Ӎ5W C5_9/{:#l34.%v̂؋ MQ Lq2Qi% l ZsàL;ل"މKSXDK-ΠҾ{H5ZWj今s9ـYb,E02( `\eW XY ChۨT . i /aS{X0ieXq "4 cLME>Hl`mU"f $QaNY=оɏb$Z@X,,'a5fzi{`K)Ec.\ tN>f{a;y4Fz?vC~.嬛/G3xb AKUU 9?"D2JK[g_% ege'|%Ee.IKMVD8]WWv` ʕީޘF/4 ǖc7=y`:d{l>}" l1 $)!֙7I5 vG?L+1_ŊS %݆w69v2DqOW䰰>.@C|kzFX 7P!,xLYb|Mn&!kih+}D B3 VzCTS=wFͦ ?CXa raU A^dXb<9 _moYof&aˍWRuybP'||˸ o‚LzEְ>?ZXvHTXD=2n˰WtsYOOk%Ʋ%Ӊ*QH R͔ewD΅G6 QYᤲ1==HSUƔb4zᡷn73.s)K\0 1as{7oEƑytNj`'C" #.WY#ǷYM{ʳCx>\@sF`Z"C|VpR^}O;P%]mxQ5XIqBO~5w,U=6]^9K oQ4_E>EZewi~x^)jz.t%eʐʫ؆)~eɸW]`{XjTήб3K:}*ky^˝*`yeL,l\"ʥ-ض-- y98 XJrIF[_ZdCD]9a\i!.r:kKہ7 T]S6 l#G'y]XX޻8_4rI0K74(XL"(5x׈T">;g[kQkriTfxIgR4ɯǥLR8ǣ) UB143>OnLqlgK%[j/@mzA4|yax}Sc>`'2=D~n>o%ٕR^4P,&kay% )J޽kn|.L#jn9ggizvjT=kUU !S_ߨ ^RZq󴂙!v@gz <ƅ׻cy2Y-a+4]|7t[Ee`˚0*$1ďP葫zvVe"o}0iDhC3!Ӽ?Ҕ1#~:;abBBT šf xvA#4h$:/Ho6\Zpя 1su#1e^*;f '[qGb;r#7 72iV.Ly3`&Lk69x9a Yl1 ҇'+q'E^2ViAn5¤alNpEn}=;.[EԀAAC)␟m K ^a{Ɓ޿$IL@cO!\}8*^^?o%_o\xWz&94_D5kh~'B_):2N2,lKcy)rA%Vvs o.a2$dSaiC84fnEi}[K'jH$ 呙I`WbC0-Sߊ$pg $(5Z}b+dtW=y/K-^&Q:nXi1謁Yo05)D9wpCw*^*J'OeWAWD Ms=2884̹arX. ]|wŝ=dCYBQd+jDŸSt̟U.# bSi[Noԉ6u]]T?+Wyo$UmoU2q'mB*%]1eZ 1d2 -"uΫyP+הEد &#AwlM)z\ںV6$NCrWf?c̈́0U< p<1~C,N( d.1]SJJ4 ~ 6-_CuEe*4ZG|w~Qz {&y]Z7:w0&!ivY=2OTƛ*(-:}a DMTrY"f]ѢRQWB$7w}MO%(˶8:37*3sxq8_+çI=u3!L*lluo@C "4 Js1Э KbLQGT@[(K_lCޟ;_ e`k>ڕ(@ K|pp{mu1"(%B2w/y[v@.˻ۯ 2F^PaN[jo\q,eRӓyȘn*'HY`Nj}ʻ;S\ S) p 5+'5tqجVŷtq*WZqo<, ]Vcֆb1 V2ϏX5%-%>ԤkeJ2Hݨյ |P 8ܟ/-Ov<ɏjJ 8V}aVq2vȻ601aIRLmy-2{Ώs~39$찳!0ayELr}F KE +sbPS44]F'y~"v7` F \ %~"o֓ی(#/?mgJ 'eG:ا*?5:Iڹ 9|K}XnDnP7:J}7̩킞v_BLf".n )tK[PQ#?~"O˲7 ['%Q? cm-.fT)' ;80̄Dyuw3+WsXw?*%UBS)j& |`^3+ų! }(Jb׻>7=^:t/q^f2 /׺=4Yh2dqELk^]Sc&[&]s<. :4w$'.fL;!=h*,ڰ)mUgْHnor/).>VO-XJa[qX9vV y5LV`Dy'ZH&r}Z?ML3%Tqr|+ӗ[˜ɀSNDv@yyFOR[Q[y!/c,5JDd4yᇀ5b{e#S| m8 39K`]y?O"U'FX_2TG`'~ #|Dd3HÓr4E(N|r1("λd ӭs|fH& N7RPX !:Jo5լKa2BHo@Z9z`30Y*5Hf1z4֗!7%D=o!!٩jueADl9NnbVqjfZ;|BzU.\ͲT}/39U&ʰ N t n_)9V=Ge/a69~|VHx}:s6ٰ!QΌBbb'KO8AF ̲ٯL @0\&W`<v+PN _ Do9s2)ǠiDʧDg)#i_9\T{O")MXoF#i{X`aդ> Kt<`'.ST&v&42MsLGhA؄%v~څ233/<`́mnd8y[UvSSŧa4_3!Tk, xD_0ٷMj7[24[-2*Yr:96' œy wj(P=:zPXwx$'"QCRj#ml"|M~_hzA-ߖ'p}fYCѴh{6n\.Laf25ݐ~Rr . RXጷ;tztpB8c̐ 8Pb%]/@c2'{;5Jk6rQ̮q0C5D~t-٥M?[́h"p)nm&ًXP)*:if\< =FAi8>rHj+ \ꫬ#_n翌N=dbD"YSD-pxHVq;3 *&6wŽKD&r_'܃tm{*|`uuS)7*Dw3FV6e䪹7mxM5򳌲.]6[U!e]9[2hhH(yRʧ/Z$OXH qV3ݾj @vfܻrLW \WzeX=0Ac j6dJ6N0EB˫ u Yxo,Ւe"/`2&mڗߤ`Y'Mc*pqa ^'^B;0`]t<-YZ;2K+@޺h^ рSPڣ (F\O M_pk3{$\c{Jdߓ:("o s焺'*x\) %L@ᅢn|"o y|eRtz 9'QfȘʹⲎC?y a[m-hn&0):lէY{X Wm )m'`1DoGlI C";f2GG!K a2wΌ¨XJ0.<0}@ 8-&4po]cA9XSPv1QΖ'L/m8 kMVCY>aF " ?!^ Wy`%CyUb4t9ssG?hm9,*ݞ)7w:ren &."q^t0M++q!(\,dWݩ ?ҹ"WtB`l\&e1FgSˎ@So]EmGmזD7It5O_ULe{8TfXmއ̌xTh2[PuΛչZ7ISiZ] î󇳹[q1۔6$Z[HuJʙK"lPm^7tN?Lчl%*ڟa]tS%"osZQBpgECkzg͉ÚZWr,gPa>O‰nCfskz <:>eiCj"?[M7BU#Ĺ oܢdzu'ΨE1\$d#FcR&Fi c/?5ZΟ84]Y4ޱE +)#eW̞I^g%Xkgpaqq1G:>F|ݶBA !Z!nmFăT}Q$mS <Ʋҷ iDׇ5F!"2%R}tMV`YF,CQ;R5.ϨPy5)Q*$j=S0%V4γ )yXlX i t~'A8G?V1m&/H<]-}T@* M8jN#{SЌx2si.?ĐDR<ͧ̈́kUzL|1ܠqر@ t9w7ye3- EFT}ZB1L9RdQ|pF\Tt//ZތܷLi]~yEeQ9O31 a .A^sU&[V\jgغl쇈NɆ 6M \xQ]fEv5Xg-@jMҳBa8i)FZ4ˮh0NFȜf 6kNBo̦sғ(]Nѷ@ iL -l\܊J(@#MxU0n#|$n@22JʒB^EBM䵨wCÅpUx#[ka%`p^K@зOp #OFb`} 鿷tZC 8Px&5Rؐ[<ݭ:hNj"mw `c=@aC?+/#u3" F?P^̠4zu]§i R+Θо8\Щ_ o ϛhELuɖAW4rB]{dp|)]4Ymlku|kWE-mN,&2>䐶wnQ"%ЬLeN֪pKX.\8vek𡚝mi[Tk{+xO_ ! a*{[Q'[pK+ݘD7ߏҋ@r@@CE`=!M ڹT@5r(91VY/ ޡO`ߌ&βG_ TE;\)y?3]m5󘕦mp r6w[)hEvsPZ˵VsMLKKe@R8Z^6I";;(34wX |zy tT#Վ&rԹ 5C$a yE.,MW@g5hjUHeo}=QF䘁/¼D'qV1Y_ kn+ {0"r4=&:R< 7&%jm|ZH.K|J3PYn.w;S`TjXA:+Bc(O @;4E4՚5eV{`j7:ʇf¤*p 'vz{X(CS\^'Ƃ[fI-VpoG*^cuȓEv?.enOm3BڃM-jߒlUNALOw]ɾok Ⳅ.;<>;&۶ַdiwZs{x7_90H'uQuFObca[X|id\ {9 'Ћ"7WA1;ĠaATJe OD**y~#u\BykЕ%NuK1"|"1X w|'}&Pͮ+* ţ תQ̘5]vǯQ~h d"cLi/T;MA#̘׹>r;_3ByPL%Ma,s#}dZh:-n{EC:%pRGp&%k;\i+.(1Bz+S}(B ̈Byk)}E]Èu%AmLs Ol, eJzϙSE [GYS^VLT1JYcեOy"@p}T+=aϝ<!m _BQ>v)a(Ib@-N {_9_\='`n$,InyTn3!& o|fVrJw{". B|m<(]\D%A?ts9Lj`m~Dc'©x0$:0+Ofjy3:5hnHv ܽ<)$ʄ+}H?2H}|2wu{Fkh%3pȴ"wܒZtZ[9{ P1ݫܶX'#8qďj(u_w¤ >Ʌ^"|R=8b,DǨ<(NP]0[$4.؇#}(!IJdgP1테༒U]$lb.8=? *~WIO(ϲXMoSԃ"eC8'@Otؓb@/J$01)8D%d'MP#C?QH.!*z ;gHۂW|u{Do ?ե-˯c&P>4t)\9M"vs f_Bbs( by/#V7bii%ƭ|mK4zwvm# ] 1l~^xjQ*,QU>( Lu=KQWyϴg1jxBe  p ^gpX+&6Ϝ4M viA22fJLT翐:˵(Rl@AgQ3=oIu:Oj6$=$QšM6i@䥻6 IWoYD آ80TP-]#dי8#r)Sps&c(}Bc^!(u!Bˢvp̓UInҷ2F$6jC)MtH1$}3JVKĜTFy[paT9Dlpϩ3S2@8 aɹu@}ļ3 Ehcfž3Im^t|4M = ]O%uʞ*UU#9 R `-=-`l[-bJnJlL)QI#7XdS⏄tH ]gA>BXVX*w#ؾ=+_s/1KWi`2e$O>^ AU2C o$;FZ9l1?yB-ܬkVL!7[X[eWmZj9ScKbhhPE"]o(c0~;k1{!:W{WVm<Z^VB9~|[$d:H{SWn T1#=[dr>빙 ѹlZaMɇ2KXpX̿TpzKq{\('8^`Bo݂ExAC!`yI2ϖy"VXBE#͉UJ-P@-ݝ6*4Xdp4 Os) V.A5'Rei[P+M]ao\: .r\AL ڕ*<ᓷjHy|Êh~z&9YmwUbUOkFLĥxy9J4432~QZFlTG ?{cr!b dPO{76ظ.r"PY<#zi'J.s9]՝Qk%pr7՚]IO JEqt,DXksAѲCؼtbilt`V5Iu*m@KXklVH}p?)y/^'ϭl>vo] Lo7ĊƙJu21~`ajg%Yh>U2Hφ|XŖ?cK HnX:=c5Mrw 6r% OB¯>y: 3pA_IBVFJ0r%*lqRƑ:g - lg4skf*`-G7]~ )UeRm&L;^3~a$E2,Ulz( <~*E.T+ :rlꈊˋ~tvO*nD8?D+R*?6%'uAi\sQsY6 5/K]Izت'詀cܚDI!F-zt}Cdh&@݉$ <{(58=oh./@#]\J,C 4.7d#+?'GJ~zVQxkMÿ>ef*n{Z$E6s*4s5 :1+.%99dڤKۼC":u]\:#? ,N:.n$Srm q##m{Zc"aHqW}G+4z%b/R:l&wiu,^`kUs>zŶxq \P5aP^Nx}1Q8fh+%դ F#w큨BkHiM"}a¢&<K)/cz÷ Bԧo*9]Ne+L%='H+LWCOՏe|>5,N7揾񫃢: )r@yo YYP'eGMlS'Z?uMl#.۠oY_+^SHk#JV{ӶWbNVՠ4@?:ۻyɳߡ7 *$xZ}Y[] 3u0`GE*T("a4 9RCW;:D{@5!bK<1B1U|K09 mgx?+H-'ci7y.j T}ggSd&<_]pXӅ|ךѵWfiz__:Ïwnc:6С` nLB+r9<3BfPZ9%| =6 h=ա _Xw2?6q{9'= o ItHYs 0 op~] |xb,ƺ\zN2$?29WDn(.I?eʸ ^"g׍ *lTE\fWQ8m'74I5J1{qg.WJ#+ ;R"m'.6{J )4OW+^hFsv5rE&MwPWKYa\R(Ge`ʎ5YDK;2jhgөH HẄ|{ ;N H=W Dh .-Lq9OLԘ#qy2~?aK^Um*U?~4Z*k"cq< |ߦ8ʝID*TF~T@ba9yq?fZ eݞi/m4Q}䈮_$+iwG䡉i]!^|(Ys1Fo{զε}}m kvzãFcb=# :K|F H,T(7H`S.:;$i@.ӚWKUHg|z!`>1Q֊araQ sr%5޷4s PH3^X]pHdOhv \ϿנŪS1m'|Qcm~R'{W;^ 8JbUy y͡xu> _wNk5"q. +o`1$ ǸY(;h}+ kRL{p^Z53NDZUI%YIFVcGIJxA6j-yepH#\kbtk -"ݶ7ˡ'kΔ@܀ByucS\Sr&:M->^Q],?bcy{omؑ:^["&/(wèغvd+y 'ܪ̎!}y/&U}V@-PIC+Lhhf9*C)-5֫5^ge.ì COAKm}ZƁPLb!zG8ޖx5Q;6d:GMmr|AmQĨd) v(90AZ,ڿ@IP.F񮪎sn[lkvl%aQx CgZCaDtd꩸lnjl ػnheĠ4|WMhB)"5  EEISBj mI;C]=~`*:?E ڱ`+l5UMEliw 1M6֌wТM֤ptӻIxt|iKW;3+_sDs(m3eg0v>x`9J`* IT>AA <٧)Ye:\!X 펥u;4t;vdsȗ6X |_mPϻp))`R `v<㈐l-/J $#dւw\` Pk2^g-ǭBA?6HTw5r^_,Eo5TrD L߃PeK2Oeg8wqvOl.OX뙟n#Asຂ~'UɅBgFAۣ)*g:&׽R'(lߞČv"V AS*Pd<88Z̝BFi9[£_/=9v2K:ƃI}ȇH잍` O@ %qgRNR86~8٬<}j#H̡PcDgVsCDQ:?Ϟ@>]N 9^ܿy0||z #q4KD +PpS_n_z9НGqG?I[OQ+Qлf/S^UI馧}m`~2d2=F1P|Dp-ʭ*nthY1 nr{,0J΃@e)_KmߤY8P/(5qA%flzon%~-Y1Ę#f^-Ρ2z`yPI@/j 5PWR液[{>2|̨?+ `4u))&dEUwԬad^l5H|; mg1t@ X. pfpX@Ћ%ڊ>~fAJ;NO < |&_0pX/.T:|k;uWJ2~Zk+tgGm#bp)bސ`=:* $tiˆJDܤli(v`t }ac1&IB>`Öxp< ΢s4h㩟CcPBzJ[/vF\Fe "0(f O6>4GwEA! Q&ϯѦ!zIR2UdEW8W}هWM #ƺOQQI>L4]&fg '9mNCnq|U2Ґ+ S(\7w+^CrCV6HiRz-"kXc1$XL.1g4M bӃ9[3r$q,2Vݙ)]bC_Hed$=Ӛs&%Sm$@SH~^׻78һ-uLVsȌ<嚗XٍC+}tQcP [jÓbu ?Vt&Z0؜y%w0qIZn`!@8e VpMsX$:%|-E8T+s7n2qr=N}+A~ lGG+ yu,]p>BKF8VW#1RO~ӊ=M2 kcD'3!.f=A _nY9$U]#`媨SÛ?=H}'je.]oŗ\1)շƦEU͕IA,9Ѕ@rr 6 ^dy SMPV>iv?`6,Xo깪r/yRY%hC<YރDq_ :i;i=XѢJjc}&V> Qlz/8>/@+4ߨ0R˩G>$ -.|sC̦ſ ; JNב,rMZxGq+^H3Z.Xהh xB ˞˶.s8rjCOD;JȎE2W"c?8Btٜfpտ+bdx be:TOFRʑlHd(ēQԂn%Ȟi]"HoN;UcQe'(o JrgQe qjq*(upYw7P 7 L6qh7qECܷjL x%ӄZ?p=\B^iWTtPԿl7A6}ɇz J2137HPTF,{bG+zWiZkgXّzvQNVՅCH7d;C.Tj)j ?R3kv4<5hbw$QV*bx 0a=*H cG)Y27&vE?r-unx~C m{6CD8"Y6B^XU.V8T授"*۶%u _\9Fac|`ojgj$6{=btZkL"~ӨkxO@瓍'hDKQ}l(.MEv,9c$D8aϚ-| W#$G>Vq6ae/'gT@cn'R=PA֓L=FK@գQŠRһy`Ǜ `OoCfӟ OC١ҲPB%[s T$ xs G@oy[@g")?T ~ +6ATҶJ"h3E'{SbHvD4Ky|2I6GEhZOb3tMk&=\J0b/ )|&E4U~oK?l4-Cd~c')Sx+eJqEda.9?'?ɺ#:79& z C*3Xj䬗CTR58(Q6#̸<{!'"h;!;O0Ë0mZ)+v1sؼXɇ( wE8c6K%h ){,aϵ}xïqJz ;*U?H7-h` Mr:)]Pč$k:_֔hJN̪ Y %@^Qo Ux=KoG-S/V;?OyQofA-a 6Įgu~f b{pRЭy`H܋Ԗ> Q* "F 3vQb`S 1yb91Jze;Q̎ɲb][zؐoMKu%'y:9oqdadrz׬!^B3rqN쮝h|{cU߳#ѫL8i&c0'+h뭡j+Fo{#2fcQARGRI$q:2wkV!/"e;Jul̻nb1q6/P޾A&jf4ºRq }0EQC4*bDl&>i@99_bý'[b92Ag|o-QLY% 4 قCh> g :tw>O77<@ ')c k}27\UGo>kp2紗wXƸJ?ԃš jzӹjwYBoWXƿv[%ç DF0?aVޛpS^&8Lݼ(y p9pvfZ)ck攷'u yQh{|'n=lf*FTrE'KM3o)$NY:ގ\ t_v71R\܍ o/B[S;-/9I+f9BzsI^-FgB4i]jFvz誱^s1ߏ;p{ eE7}Ȧx V0O$ި}5=@ ok.K$1a[ iM23sMLJ/oSĻL64'˸6v }$""_BSEU>NXtãisɉ\dF-Hۮ5St}nHAfn?ÉB]!AmMolx mrvݼ-Ȕ#UIW.5c3 sz$z{W-+fqښMxcB7 7 xEzXi7oD}L'026XTޏ`/p|iZV 7S|~)鼌1E&g6wCȿ6ZӸ $]!E&68?nY mtܩ^bVk&h᥯H:tQ#|jv[a/=qaڅzU?gP}H|VhH=Lk!rd'?O +p&0k<-){ICͨJTLX]PRe[5$>IGX1ymt²FEzt&dF/I^4~EiTjϕ*becrwDѠ.(Jid"̀Rd;U/DZf<ܝ脜Nk_6A$auCL.|mƔ.*iߘEM)l%A3EUAԶfHh'Ȭ9Qi:jCūmX>TjxtxTg9-7X]QZ՘~޼Kgv?wHieAMX[lBi-ąÀ,(3 m֙K[)>h؊ST?p:%u]u6%ʶXHYυ=xd3otPeX,{w@3jgF Ű{?{? rfg[ FbgX|^/,Q*6X)c|QmNbQHxkn}[Ujo}j= SKx1$DJn|_ Fk*wF¢SlhF^.O_?QFϼqǷj{]@UM7[z.wpN *F% $oIy(% *:hqc45CB=JGptF>}.B` lQ.cGP0w£YU5x+ J#m <&l|WT_׵Z'2,% b?v"cFnN[i?L Zt!y`)s*FjM{i3?ǮnV?US~F5<N<\yX%DeŴަ7qOu_3noYNMbj|ԔMpC#NbMT)AYf Wa˕`![ )y)"a7Dh8? q}x, hk^P*u@-w¡骫M(tc(ꉔW@M?!zq+On"L(l%`Kf5Rz# 9?-?N/W|k'{Y5  bӾjnA!+f!+-C2crƥT44XNFA 8b73"}j0'i%ݮE )wPaitRW c ]1Wzl'(yyzZM&6MHĶg]~/Ī!Ik#(P}R?$(wYWah6uJ9۷=_e_\hCٷ" 1Rut  m'xP "Ȭg$:]mn%5;f85BL MS lHt3R /n['-Py.>"WxAKQn,9c H>|3^ *v矁BP&a4\=J5)Xёሬ0:fWA]i[d q.3S-@ 0y炥>dby"1[2J^߇GL 4;Lp݊>IۦۼfIhkn/,vBd?aZUkrb]TC&_Dw# ca>4\fa7l6h'\EUs֖e<8p[LBz2|dj#O{Af_Zj߿iՉL^Y>R b;}#ɈLxdEPD3v9C4;z7wꋶ.roD4"GSKEg(mBF7+}VBo=3?/FߒHPyGu@#Y(ߪ~uǟMQއv[iY-9Κf|d :]/Ƅs$^-Ń՚:#,r; Tm !C7<#޷G E!\gOoZ8~Nm:yRZե-eQ}L M|2$::MvSKtϤS{0l+*UΈ9qZ"k𿓭;l# %_c6z d"JPɓ .+Rgm ~[S@ץxaӑ*6]N_LS2tmrرӯcLu,1nxyEf^}љO;КGTb76HV-nT59}*'\89 톲׿ Dkn! a1ý+16'\3~j ÄDc$"?gQ*Q._hF|),@m{LDh< \u} )+v3v԰#|Sy1SRbOq$>bh:D{ݔQuW`Դ?;}5򭿄r T<~tڧg.B=sd4@ ZߏG׆QC[uU}P- (J : 2y z9(y{a!*m1ԧmT#Hɇ4 <'8"Q"LQjfgd;9C]޳>P6p3r ?7U;T،f?'GI%iĮ!Eq+12G i92}Hyך'Y"";igHn0pf ,|,8x/*C E(62u=Lq@)aՁz DĐs?UKq Zj  QZp/Qp^c9wX ~lѪ ^ZYNxX7QY4z?UUvWF.G,G|5X5o?۸6@n_}b`֍M%'#5bi#j%&LT?8w(ճh4OѐWef:/p\ 7bY :d׍+ƒj$9r6UJ{YmTQw]Y#5u' X1j8;P',t&? ]/ sN**xF=NՐ S݊&`C> dsa ;r[neٷpr9EU..8[8KZ  cvn0-=H'`P:ϩ)O[ @J^Tj]|;X"dryq6~>iR6_:ӃաOLAMVх Hhuv z/7BT)Me\K0 s, %;;\AKm^τ Jx4VPxQI'GOLivgyq]цmL3_+}U2'Oвa"s (sAy-מ$v݁ nGcf?>2kUI^AӔ=p c^N\KAҶQ\U'=ѐMBgyGi0:O5.7/i]Ud)2Iψ qm=Iw*2FF b_Zu;-3Y>E: b>~d2 .b@qZwDݽ֜/l>_mQW8+2Nɬp4Hk=b.1ճ_dt}٥J1QY?+@Pﭼ#FZuR,-Z׉7|h麉C`;a8ch'^GA{%ֆ4_˗H`dj]=/OOV\(FK{5!" .X2"`?$r4l\s0An+Fįc9P`YFa/#T d9؜γ8X 7xQiTb i "'̈́{,=Uڦ]Ȗۙaͦ4r\|svDiB  JFx eF7̟&ͽQ%XmP|ò=lY3N'*Yh(ـwNQOo92AJ&E.! Z66[0:Uf~H~pAs ,j3K_.X$'Xx?H S_PU"s [cLSٲFK|O0},&,äZaF;f4+@0N:Jc@4e-ЀslG$dF_Q.Hoƞj&P6+XK CQ[f+o^9Bӹ{ÛuX|@߶qjW ^W4d|t# f}̷@Zg( vCM'Xڛ4ҪJ;67ߵ| vmI(O jwc.{-Im1> j lk r$QШ (I}ʵ ntPp6S CMq6&6;b_7F6 nFP5r 9 lAXmD_-qWKZ~>gNlV ynΤS|L#`7n##Aim P"9].UU]{*z>c>6lw(\[8zuFtK:hJDǧ$?SgyEZ9')w}Wxj {gbUXſpE*knz/X|MW{m0byDr; ՆAXc0P} ߲ ޑ)U G!^If:׫0,Jy⠰ZO7 /JBV=Զ)T|<G0pfg\C`mu,h@ԪxMw`{M5Q:WؚWo=U= Ѽ:H>ϳh??RoI!+ʿz%ZRXU_I^1VY܀RJƵ_.kLAiu>T녘D³%+uMh=LkLPw5MINV9 uك+Xo;U23,;M\⩷ƍϢn+h`~:]BX(0u^|Lo7JI0V̗QPuՠzT]$ֽtNRHCCm#.Q⼙Zϡ_x<''Xd55¤ ZO[Ԓ ueܚy|~;frm H.rGұen@b& BrsX1YdnXYdj|w=\e] =+~&A9WhiC RHoE_i&w蘒m H} 8$X,F > %eE&psi;rK`@6 `2]ʥzwTTV8qL3g+ʧ̜sx=ALj. ITа%hG32D J?\֘*4 @P,"=4住Ts1a;VhU gY4F|2.똤9da s]WAC Fг@T8RDn&ۄkykUPa#(-yW:b5Uy i ݉8N|8"\J[7e[ɇqqn1YQ~>}`U>c򹎏 p :vk 5?Do}Y/S)#n+9'ۑqjdmcCa4ְPF?<8vc}LOUI]d#nOЀEC $Is_ 5ޑ/@~n`>nOMJZ|X?8c7,ea$U j\ˠ<|֟X_?#g+/OXq`-C*U[0Sf]b8ub4<{2|\(]Sn6 V `|ČLJ:?V&5f*hTL⮐=P JɄ{\:jivD 4KUbhTmȌ!-q3$ȞH$SQOhS6V T<. I̸^5j4HH{fpxD䧄 Q_L[ o> ztT3:ua@f 6(PXD|Yh=lQ^41(>1Ȑ6ٙ bv;2ca](Ad"wa2пod]wq? E-/XA:P0.Qβ ݋ _]1xƻt_ȄYP{="*D޳ k/{~j"d2KIuG+R FK+yj`jW;@*ux0͖e$IUf!HujZ,Vo,?_HA*$MK5QE!)A*Q_QWD?yx3Nxz y&|;Gzn~ #'x*X()Rc@{Ӂc9g>[ "$`Ze fnڞ8ӏty t­7 ?UO*ns ]pjL z<0|5暑˙5$@W5Q\ؾ|8cb:ȳ{?"D9l_ Ɔ.7uT;yH|!դz" 2һDrLQB as25>:W+Y;ߛZ?x ם0k-̱gץC C+ct#u-]y_{T0Nk0ȉqqBrLs2*GoqXٮތrJg9,oiZPXr.!G }}cSyL/C2x.XdzWۢр-yfM:-"cW 珃>Z)F%fZD_]؃poޠhwfn=2C4D^fB~vR(k;Ҕ菰;D8M.%gI'tUV%I] c8<Mpo4FiڄL395E{si=X>DхRzT[2\ǿm%ĽY4"[ϻ(YuOD ldQ%9fx$uZ=lpr"TT &Rgadߡԧ_'@qZ?[l0J-N>U`!mw2;duA.SA;lreI38vjtwv`ie,0Vx` uxZs㼾y% i|.(/uؾl | '8o[&}*93DԭbG.aN4Jaw}Qi՗AMa~TT֋n|H =mDfx&ZI 4k{XQMv:)Fd ļ[;=9 5}EзH\ʠh yZ,Ѩ΅Z}x`uxʣ`NZn}25HaZ#H+q+yՎ.wn1֓Ƅ}fM~2իDDo20eǫ&,m)2O"ձFҍFdTTk# %4ŭþ3ڽ= >":<dyܩ"P?-7xoimȚƚE2-t:hsOW4U`YaS0d}5BЪL\H@xjvvu,ǀHELno$=tp)zԁDuu+ C?V{5]B?Ɣ '#x_s\M2DJ >eLNz{vq߂{vuc&|({;CC7.JxH[2 9znh@20oNmS&#S>Тn1{DSI3l_Cjt$0E?zn5F7ְߠg6XEKej;;3CVAo,m5 uVōJlH tRW=grHv2ޭD rhv0{*}X#Ķҡ5y!ɹPL>>t QR\hzM}*i,9cLrqbȆ#6uR9d,tWX[$4MW˘[;mi}2b.&4ٟW*oRlS)(|hx %pk#@E3@bBDmo6| 0G("< 슏_L%O/pj!׸+v+h 7&LY6%Q=:8<-5ҭʣ}Dwb~ XP9B˛W.sU'}^8#,RZf&bTeXko ?05[mpZ ?L |v54.ɣȯ[9ǯʗXy7lJ=}K.9n.T8X-l YZ