samba-dsdb-modules-4.7.8+git.62.c1052da2b4e-lp150.3.3.1 4>$  Ap[d/=„ǖ0 00C􊿀k*w>}H9 4_gw>ƚwh*bh5殏p!VWVK RQڝ Qx$ӡ`>@%v> ql tp37ގu}QQu86e7s2e6WJ(ENfD>=~ɧIl΋#̬ IчO=t W@(Fč,%F0 >Hyr5Z2gb10bf4a51b2440e239de46539ad1562b62d8f4c9e62b2247e15e1dc8ba1b05a01c7f76f6759a34ed30ea14d041abd34562b8025d[d/=„I[蒠̧:uS2F LX=5I2^k^GFVVI6Gb;w2?D%* &[C#]_ nʱ8ne60'*yjNucu2[O`5} LnX󄜊n>G ~#UBEd̎1ݢ랜iS~?ȚNrfL6Cw Ν r1Z4LBх*WtraaS~+F>pA<?,d. : L '-4t,$, |, , , , ,,h,Dx,(Xv0v)v()8)94:a>ն@վFG,H֐,I@,XlYt\,]p,^b.cdeejfmlou܄,v4,wp,x ,y?z(Csamba-dsdb-modules4.7.8+git.62.c1052da2b4elp150.3.3.1Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.[dbuild84openSUSE Leap 15.0openSUSEGPL-3.0+http://bugs.opensuse.orgProductivity/Networking/Sambahttps://www.samba.org/linuxx86_64ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb/samba /sbin/ldconfigH7ww(H X@8 G((_PxX(xH8'X(8'7ZP(HYH('x((8HG'[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[d[de4f550b0cb82ae44d0ca2c6f2fcabf053da3caca496db7944262c71ba79d1502ac6e9feabed42e439141a91cb3c1aa2025dc50b8135b4d2f83969b0df04ef56ca8f64c96fdf0fcc668cf9c43eaf1f218f36ac0bc009801d2d893f92566d97f98aea0b835e6f5bb9b226dd23d44587fa2a71a2266e4749dfffa2f226ac39cd097373a92b430a4c1f413aed47021f8e078efbd7b6adac4a0eac5063cfa3b56174a45a1dc2646aa3d7a3abcbb73eab892bc1b8a750522c52ef0f129e12480ea1744210b4bdf5592bdceeee5f796b797cc2e0c7b244fc06cb00a809f15ad7ff7df2265a07a4f1682b2b05c00f7cf24c7b9d0b39ea87a14f33bdf90589eb44eafe58bc6f17e260a483a1993e9686783ed95bb1fd1bb0ebc3f0618bf5a6272d0c3d5c4982deaac0566188102a8b0e5ec7ce2329d9c789049946d13c0d8b53109e21cbff68648665499c662bd3f2e3a49f8b5b108b030b49a05f1f1209f726a0e140e7185dcb100132b3ce92c3fb97ec0838367cd4c43828279fc2fab13458396b08c3683faa1bf225c4894fcf08c5c2c84e994c0e16a079879d4b5255ac5de302ee5e635763bd0310fa5daf90e3619bc7ff0e04369a3eb66e732d28431d6520494856bdb625ec57faaae37ad52824a89b74e6bfe2144cdf23780b00e584a0e462c7fdf2d460b59556f5296e014fc4851783739f92a99718e61fa12d55c9e613a434f49b3e6e0a8a05b834592683475ff772680817e302c852d3f3b4bbeae055365402ae2a2a76d6e505a7868337d3a4bf4fbf9bbe9d0f2aafdd506d4f3e18ddb778212b88927a4fd61f4282e1c412ef665bc7833d787a5783c345ecacaf0883477c2011991a8fcc4a7752060a014ea0d0bb2e617dac64af29e48b5a7c8a993c07fb010d9085899bb54fb0002b7ad1c665db2c00685c43ced7854f61f2df0a5afa28d6b6accf9d047b2089c8b5f8f4e27be2a2a4f87bbeeceb5e5369d32716a03d4b00628b7d741f053c7cc845747c5070860bfe1736d5b011b6f83491f9c281945624ed115b8c31f5d7a77ab512a2ad5d3a7d1e04ecaf205fe1848549970ea0bd1942cdb187f0a60b312da1788aa5475530fdfe0d96df307c998af4b4b076e3676503c6b7c4e2e89433b15ea8b479462641c7e7493d1e4a0c79f0b73213006ae777d2c0415afd55557babf71cb2564b0913610df5a8e432887bf9eaf01b6c1f48cd062c45dfb47b1308dc2d63463aa1f678c88fbcdc288d66bdf4b17b7e3689464d2dc815e12526350eaf188cea7bdd406112394f9b10a3b0915e6a493b2b82eaee6de9b36e1d82ebbf942dada68df79dd2c30587d9a98a99455ae4cb961c3b5bc81ff16dc50f57fe56239d393539620f08b9b2707c567f1336bf58e1565486bbd616264b3003e26faef9905090f16e76f29d1744a10e6c550e8e6d44985f16bfe95ec905acdef6d30f619b1ad9b1ac5d477cbc6db2b857ac254e5ab6b6c4aa0e4712ccc70ca86dd9bf3c2abae0ae25ebbdbf73748e43a2472df888a387d4f7b2654b03aa7b83a40fdcd47f0a38d45a42828c143c78a6cfe4a78a8a2828cb5b52661a0f1f7e2d2aad3d65e60ce5c818f86d04494496e544da34338ae710a86a98348f50c6ee03ee4fc9c94011fd360e0b35105e4304a34f7351b40f9d20cf62e1c6593d68f2881923bcfb7fe575c8cc11ec2608d885fcb4e08f87ab814b088a4b8df508cf59a0d1a2dd46c3bf707929ce50a2cba5d587282163340196da9bfbc78c3553bf12a2faf47bf97df3e57e3e0c654cd738545f40c634b213e730535e7a4c1ceb6f5731970575f28fea080a457a7606537ad78aecec7b1063943b61deca0ca627519cf0a34cadb055872ba16633956aa4aab73a9bde630dbdb3b404dd30e490d939b8f8f76b20336a7e37afa9023d42d9ed6f1e4db36c26178940a910f5cba96ebb873867d417cc2190e23b8d24f070e8eb4c55c92380d81643c882a6e9f4accrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.7.8+git.62.c1052da2b4e-lp150.3.3.1.src.rpmsamba-dsdb-modulessamba-dsdb-modules(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfiglibMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libcmdline-credentials-samba4.so()(64bit)libcmdline-credentials-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(GLIBC_2.2.5)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libldb.so.1(LDB_0.9.12)(64bit)libldb.so.1(LDB_0.9.15)(64bit)libldb.so.1(LDB_0.9.16)(64bit)libldb.so.1(LDB_0.9.18)(64bit)libldb.so.1(LDB_0.9.19)(64bit)libldb.so.1(LDB_0.9.22)(64bit)libldb.so.1(LDB_0.9.23)(64bit)libldb.so.1(LDB_0.9.24)(64bit)libldb.so.1(LDB_1.1.0)(64bit)libldb.so.1(LDB_1.1.2)(64bit)libldb.so.1(LDB_1.1.30)(64bit)libldb.so.1(LDB_1.1.6)(64bit)libldb.so.1(LDB_1.2.0)(64bit)libldb.so.1(LDB_1.2.2)(64bit)libldb1libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libndr.so.0(NDR_0.0.4)(64bit)libndr.so.0(NDR_0.0.8)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libsamba-credentials.so.0()(64bit)libsamba-credentials.so.0(SAMBA_CREDENTIALS_0.0.1)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.7.8_GIT.62.C1052DA2B4ELP150.3.3.1_SUSE_OS15.0_X86_64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.2.23.0.4-14.6.0-14.0-15.2-14.14.1[6@[5@[ @Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USaT5'@T5'@T3T12T->@T->@T%U@T$T!`T!`T@T@TSS<@SS@S@Sہ@Sہ@Sہ@S@S;@S.S@SSSS@S@SS8@S}SxSg}@ScSZN@SXSO@SM@SM@SG@SG@SG@SG@S:@S:@S5d@S2@S,)S L@SSSS@S@S(S @S S 4@S?S?S?SK@R@Rb@R@RRR@R@RRRRRURURURRR&R@RR=R=RʚRʚRʚRʚRʚRʚRSRR@RjRjRv@RG@RG@RRRRR RiRu@RpRW@RUE@RUE@REs@R:@R6R4OR2@R(r@R%@R!R7R@R@QQQ@QQQQޞ@Qޞ@Qޞ@Qֵ@QQo@QzQQɆ@Q@Q(@Q@Qzl@QdQAQ,Q+R@Q@QQQ@Q@QEQ@Q \Q \PP-P-P9@PPDP[P@PѬ@P @P @PPP}@P+P@PP@PBPBPPP@P@P*P6@Pd@PoPoPoPoP{@Pb@Pb@PWPWPQP,PPP H@P H@PP@OjOjOORORO Ọ@OȮOȮO]@O]@O OE@O!O@OOO@O OoOc+@OaO`@OKp@OB5O>A@O{pw,gr}ent_state; (bso#13293); + winbind should avoid using fstrcpy(domain->dcname,...) on a char *; (bso#13294); + The winbind parent should find the dc of a foreign domain via the primary domain; (bso#13295); + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400); + Fix broken server side GENSEC_FEATURE_LDAP_STYLE handling (NTLMSSP NTLM2 packet check failed due to invalid signature!); (bso#13427); + s3: VFS: Fix memory leak in vfs_ceph; (bso#13424); + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407); + dfree cache returning incorrect data for sub directory mounts; (bso#13446); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + s4:auth_sam: Allow logons with an empty domain name; (bso#13206); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + build: Fix libceph-common detection; (bso#13277); + build: Fix ceph_statx check when configured with libcephfs_dir; (bso#13250); + vfs_glusterfs: Fix the wrong pointer being sent in glfs_fsync_async; (bso#13297); + ctdb-scripts: Drop 'net serverid wipe' from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + smbd can panic if the client-supplied channel sequence number wraps; (bso#13215); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + s3:libsmb: Allow -U"\\administrator" to work; (bso#13206); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + smbc_opendir should not return EEXIST with invalid login credentials; (bso#13050); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + libsmb: Use smb2 tcon if conn_protocol >= SMB2_02; (bso#13310); + subnet: Avoid a segfault when renaming subnet objects; (bso#13031); + 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:smbd: Do not crash if we fail to init the session table; (bso#13315); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Bump vendor-files - Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); (bsc#1094881);- Add missing package descriptions; (bsc#1093864);- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.- Rebase File Server Remote VSS Protocol (FSRVP) server against 4.2.0rc1; (fate#313346).- Backport upstream master fixes for samba-regedit; (bnc#896536).- BuildRequire python-xml on SUSE systems only.- BuildRequire python-xml. - Exclude unwanted texpect binary and libhttp, libsamba-cluster-support, libsamba-debug, and libsocket-blocking shared libs. - Add vfs_fruit and vfs_worm man pages and ndr_dcerpc, smb2_lease_struct, tstream_smbXcli_np, idtree, and idtree_random header files. - Remove nmblookup and smbclient4 binary and nmblookup4 man page.- Update to 4.2.0rc1.- Fix small memory-leak in the background print process; (bnc#899558).- Modify samba-regedit so it displays correctly (related to ncurses). Changed code to use menu sub windows, seems to fix problems with display not refreshing; explicitly BuildRequire ncurses-devel; (bnc#896536).- Exclude unwanted libdnsserver_common and libdfs_server_ad shared libs and the man page of the unused findsmb script.- Skip groups that aren't mapped by idmap_ad; (bso#10824); (bnc#897969).- Update to 4.1.12. + s3: winbindd: On new client connect, prune idle or hung connections older than "winbind request timeout". Add new parameter "winbind request timeout". Please see smb.conf man page for details; (bso#3204); (bnc#872912). + Fix smbd crashes when filename contains non-ascii character; (bso#10716). + s4-rpc: dnsserver: Handle updates of tombstoned dnsNode objects; (bso#10749). + passdb: Fix NT_STATUS_NO_SUCH_GROUP; (bso#9570). + s4:setup/dns_update_list: make use of the new substitution variables; (bso#9831). + build: Fix configure to honour '--without-dmapi'; (bso#10369). + provision: Correctly provision the SOA record minimum TTL; (bso#10466). + s3: Enforce a positive allocation_file_size for non-empty files; (bso#10543). + lib: tevent: make TEVENT_SIG_INCREMENT atomic; (bso#10640). + Make "case sensitive = True" option working with "max protocol = SMB2" or higher in large directories; (bso#10650). + Samba 4 consuming a lot of CPU when re-reading printcap info; (bso#10652). + lib: strings: Simplify strcasecmp; (bso#10716). + Allow netr_ServerReqChallenge() and netr_ServerAuthenticate3() on different connections; (bso#10723). + 'net time': Fix usage and core dump; (bso#10728). + sys_poll_intr: Fix timeout arithmetic; (bso#10731). + s3:idmap: Don't log missing range config if range checking not requested; (bso#10737). + Fix flapping VFS gpfs offline bit; (bso#10741). + s4-rpc: dnsserver: Allow . to be specified for @ record; (bso#10742). + s4-rpc: dnsserver: return DNS_RANK_NS_GLUE recors when explicitly asked for; (bso#10751). + samba: Retain case sensitivity of cifs client; (bso#10755). + lib: Remove unused nstrcpy; (bso#10758). + Fix a memory leak in cli_set_mntpoint(); (bso#10759). + docs: Fix typos in smb.conf (inherit acls); (bso#10761). + libcli/security: Add better detection of SECINFO_[UN]PROTECTED_[D|S]ACL in get_sec_info(); (bso#10773). + s3: smbd: POSIX ACLs. Remove incorrect check for SECINFO_PROTECTED_DACL in incoming security_information flags in posix_get_nt_acl_common(); (bso#10773). + Don't discard result of checking grouptype; (bso#10777). + s3:libsmb: Set a max charge for SMB2 connections; (bso#10778). + smbd: Properly initialize mangle_hash; (bso#10782). + dosmode: Fix FSCTL_SET_SPARSE request validation; (bso#10787). + vfs_dirsort: Fix an off-by-one error that can cause uninitialized memory read; (bso#10794).- Wait for network-online.target to prevent caching of pre-network failures; (bnc#889175).- Use domain name if search by domain SID fails to send SIDHistory lookups to correct idmap backend; (bnc#773464).- Prune idle or hung connections older than "winbind request timeout"; (bso#3204); (bnc#872912).- fix FSCTL_SET_SPARSE request validation; (bso#10787); (bnc#893774).- Remove pre-11.2 patch which by default uses the smbpasswd passdb backend.- build: disable mmap on s390 systems; (bso#10765); (bnc#886193); (bnc#882356).- Create the cups smb backend as sym link pointing to smbspool; (bnc#891220).- Fix winbind service parameter usage; (bnc#890005).- lib/param: change the default for "winbind expand groups" to "0"; (bnc#890008).- Update to 4.1.11. + A malicious browser can send packets that may overwrite the heap of the target nmbd NetBIOS name services daemon; CVE-2014-3560; (bnc#889429).- Fix "net time" segfault; (bso#10728); (bnc#889539).- Update to 4.1.10. + net/doc: Make clear that net vampire is for NT4 domains only; (bso#3263). + dbcheck: Add check and test for various invalid userParameters values; (bso#8077). + s4:dsdb/samldb: Don't allow 'userParameters' to be modified over LDAP for now; (bso#8077). + Simple use case results in "no talloc stackframe around, leaking memory" error; (bso#8449). + s4:dsdb/repl_meta_data: Make sure objectGUID can't be deleted; (bso#9763). + dsdb: Always store and return the userParameters as a array of LE 16-bit values; (bso#10130). + s4:repl_meta_data: fix array assignment in replmd_process_linked_attribute(); (bso#10294). + ldb-samba: fix a memory leak in ldif_canonicalise_objectCategory(); (bso#10469). + dbchecker: Verify and fix broken dn values; (bso#10536). + dsdb: Rename private_data to rootdse_private_data in rootdse; (bso#10582). + s3: libsmbclient: Work around bugs in SLES cifsd and Apple smbx SMB1 servers; (bso#10587). + Fix "PANIC: assert failed at ../source3/smbd/open.c(1582): ret"; (bso#10593). + rid_array used before status checked - segmentation fault due to null pointer dereference; (bso#10627). + Samba won't start on a machine configured with only IPv4; (bso#10653). + msg_channel: Fix a 100% CPU loop; (bso#10663). + s3: smbd: Prevent file truncation on an open that fails with share mode violation; (bso#10671); (bnc#884056). + s3: SMB2: Fix leak of blocking lock records in the database; (bso#10673). + samba-tool: Add --site parameter to provision command; (bso#10674). + smbstatus: Fix an uninitialized variable; (bso#10680). + SMB1 blocking locks can fail notification on unlock, causing client timeout; (bso#10684). + s3: smbd: Locking, fix off-by one calculation in brl_pending_overlap(); (bso#10685). + 'RW2' smbtorture test fails when -N is set to 2 due to the invalid status check in the second client; (bso#10687). + wbcCredentialCache fails if challenge_blob is not first; (bso#10692). + Backport ldb-1.1.17 + changes from master; (bso#10693). + Fix SEGV from improperly formed SUBSTRING/PRESENCE filter; (bso#10693). + ldb: Add a env variable to disable RTLD_DEEPBIND; (bso#10693). + ldb: Do not build libldb-cmdline when using system ldb; (bso#10693). + ldb: Fix 1138330 Dereference null return value, fix CIDs 241329, 240798, 1034791, 1034792 1034910, 1034910); (bso#10693). + ldb: make the successful ldb_transaction_start() message clearer; (bso#10693). + ldb:pyldb: Add some more helper functions for LdbDn; (bso#10693). + ldb: Use of NULL pointer bugfix; (bso#10693). + lib/ldb: Fix compiler warnings; (bso#10693). + pyldb: Decrement ref counters on py_results and quiet warnings; (bso#10693). + s4-openldap: Remove use of talloc_reference in ldb_map_outbound.c; (bso#10693). + dsdb: Return NO_SUCH_OBJECT if a basedn is a deleted object; (bso#10694). + s4:dsdb/extended_dn_in: Don't force DSDB_SEARCH_SHOW_RECYCLED; (bso#10694). + Backport autobuild/selftest fixes from master; (bso#10696). + Backport drs-crackname fixes from master; (bso#10698). + smbd: Avoid double-free in get_print_db_byname; (bso#10699). + Backport access check related fixes from master; (bso#10700). + Backport provision fixes from master; (bso#10703). + s3:smb2_read: let smb2_sendfile_send_data() behave like send_file_readX(); (bso#10706). + s3: Fix missing braces in nfs4_acls.c.- Reduce printer_list.tdb lock contention during printcap update; (bso#10652); (bnc#883870). + Only update the printer share inventory when needed.- Add missing newline to debug message in daemon_ready(); (bnc#865627).- BuildRequire systemd-devel, configure --with-systemd, and modify the service files accordingly on post-12.2 systems; (bso#10517); (bnc#865627).- Prevent file truncation on an open that fails with share mode violation; (bso#10671); (bnc#884056).- Update to 4.1.9. + Fix nmbd denial of service; CVE-2014-0244; (bnc#880962). + Fix segmentation fault in smbd_marshall_dir_entry()'s SMB_FIND_FILE_UNIX handler; CVE-2014-3493; (bnc#883758).- BuildRequire krb5-devel, libiniparser-devel, and python-devel in any case.- BuildRequire libxslt and perl-ExtUtils-MakeMaker and BuildIgnore libtevent on CentOS, Fedora, and RHEL systems.- Update to 4.1.8. + dns: Don't reply to replies; CVE-2014-0239; (bso#10609). + Malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response; CVE-2014-0178; (bso#10549). + s3: smb2: Fix 'xcopy /d' with samba shares; (bso#3124). + Extra ':' in msg for Waf Cross Compile Build System with Cross-answers command; (bso#10151). + s3: nmbd: Reset debug settings after reading config file; (bso#10239). + Fix empty body in if-statement in continue_domain_open_lookup; (bso#10348). + script/autobuild: Make use of '--with-perl-{arch,lib}-install-dir'; (bso#10472). + wafsamba: Fix the installation on FreeBSD; (bso#10472). + Use exit_daemon() to communicate status of startup to systemd; (bso#10517). + Fix adding NetApps; (bso#10524). + s3: lib/util: Fix logic inside set_namearray loops; (bso#10544). + s3: lib/util: set_namearray reads across end of namelist; (bso#10544). + idmap_autorid: Fix failure in reverse lookup if ID is from domain range index #0; (bso#10547). + build: Fix ordering problems with lib-provided and internal RPATHs; (bso#10548). + Fix read of deleted memory in reply_writeclose()'; (bso#10554). + lib-util: Rename memdup to smb_memdup and fix all callers; (bso#10556). + Fix lock order violation and file lost; (bso#10564). + dsdb: Do checks for invalid renames in samldb, before repl_meta_data; (bso#10569). + Fix wildcard unlink to fail if we get an error rather than trying to continue; (bso#10577). + byteorder: Do not assume PowerPC is big-endian; (bso#10590). + printing: Fix purge of all print jobs; (bso#10612).- examples/libsmbclient: avoid some compiler warnings; (bso#10624).- Fix printer job purging; (bso#10612); (bnc#879390).- Update samba-pubkey_6568B7EA.asc which will expire 2016-01-17.- Fix byte-order macros on little endian Power8; (bso#10590); (bnc#871701).- Pass through vfs_btrfs snapshot manipulation requests when "btrfs: manipulate snapshots = no" is configured; (bnc#874180).- Clone the base share security descriptor when exposing a snapshot share; (bnc#874656).- Use appropriate HRESULT return codes; (bnc#875046).- Update to 4.1.7. + Make "force user" work as expected; (bso#9878). + Fix build on AIX with IBM XL C/C++ (gettext detection issues); (bso#9911). + Fix problem with server taking too long to respond to a MSG_PRINTER_DRVUPGRADE message; (bso#9942). + s3-printing: Fix obvious memory leak in printer_list_get_printer(); (bso#9993). + doc: Add "spoolss: architecture" parameter usage; (bso#10188). + Make 'smbclient' support DFS shares with SMB2/3; (bso#10200). + Make (lib)smbclient work with NetApp; (bso#10230). + SessionLogoff on a signed connection with an outstanding notify request crashes smbd; (bso#10344). + dfs: Always call create_conn_struct with root privileges; (bso#10378). + 'net ads search' on high latency networks can return a partial list with no error indication; (bso#10387). + max xmit > 64kb leads to segmentation fault; (bso#10422). + Fix STATUS_NO_MEMORY response from Query File Posix Lock request; (bso#10431). + Increase max netbios name components; (bso#10439). + smbd_server_connection_terminate("CTDB_SRVID_RELEASE_IP") panics from within ctdbd_migrate() with invalid lock_order; (bso#10444). + Fix 'wbinfo -i' with one-way trust; (bso#10458). + samba4 services not binding on IPv6 addresses causing connection delays; (bso#10464). + s3-vfs: Fix stream_depot vfs module on btrfs; (bso#10467). + Don't respond with NXDOMAIN to records that exist with another type; (bso#10471). + pidl: waf should have an option for the dir to install perl files and do not glob; (bso#10472). + s3-spoolssd: Don't register spoolssd if epmd is not running; (bso#10474). + s3-rpc_server: Fix handling of fragmented rpc requests; (bso#10481). + Initial FSRVP rpcclient requests fail with NT_STATUS_PIPE_NOT_AVAILABLE; (bso#10484). + lsa.idl: Define lsa.ForestTrustCollisionInfo and ForestTrustCollisionRecord as public structs; (bso#10504). + Make 'smbreadline' build with readline 6.3; (bso#10506). + smbd: Correctly add remote users into local groups; (bso#10508). + rpcclient FSRVP request UNCs should include a trailing backslash; (bso#10521). + Cleanup messages.tdb record after unclean smbd shutdown; (bso#10534). + s3:rpc_server: Minor refactoring of process_request_pdu().- Create a new DBus connection for every vfs_snapper request, to ensure correct snapper UID detection; (bnc#866354).- Fix "Invalid read" in method reply_writeclose; (bso#10554); (bnc#873658).- Fix minor compiler warnings in snapshot code-path; (bnc#873177).- Remove references to the obsolete samba-krb-printing package and get_printing_ticket binary.- Fix malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response; CVE-2014-0178; (bso#10549); (bnc#872396).- User error strings instead of hex codes where possible for FSRVP errors; (bnc#866927).- Fix remote share shadow copy request UNCs; (bso#10521); (bnc#870957).- Add krb5rcache directory to the winbind package; (bnc#870607). - Cleanup and consolidate the sysconfig and systemd service files.- Extend vfs_snapper man page to cover permissions; (bnc#870570).- Fix RPC server handling of fragmented requests; (bso#10481); (bnc#869707).- Default with the cache and lock directory to the same path to have both non-persistent and persistent data at one location; (bnc#846586).- Depend only on %version with all manual Provides and Requires; (bnc#844307).- Update to 4.1.6. + Password lockout not enforced for SAMR password changes; CVE-2013-4496; (bnc#849224). + smbcacls can remove a file or directory ACL by mistake; CVE-2013-6442; (bnc#855866).- Password lockout not enforced for SAMR password changes; CVE-2013-4496; (bnc#849224).- Call update-apparmor-samba-profile via ExecStartPre too; (bnc#867665).- samba4 smbcalcs --chown | --chgrp dacl regression; CVE-2013-6442; (bnc#855866).- Retry named pipe open requests on STATUS_PIPE_NOT_AVAILABLE; (bso#10484); (bnc#865095).- Propagate snapshot enumeration permissions errors to SMB clients; (bnc#865641).- Properly handle empty 'requires_membership_of' entries in /etc/security/pam_winbind.conf; (bnc#865771).- Fix problem with server taking too long to respond to a MSG_PRINTER_DRVUPGRADE message; (bso#9942); (bnc#863748). - Fix memory leak in printer_list_get_printer(); (bso#9993); (bnc#865561).- Fix stream_depot VFS module on Btrfs; (bso#10467); (bnc#865397).- Use libarchive to provide improved smbclient tarmode functionality; (bso#9667); (bnc#861135).- Depend on %version-%release with all manual Provides and Requires; (bnc#844307).- Update to 4.1.5. + Fix 100% CPU utilization in winbindd when trying to free memory in winbindd_reinit_after_fork; (bso#10358); (bnc#786677). + smbd: Fix memory overwrites; (bso#10415). + s3-winbind: Improve performance of wb_fill_pwent_sid2uid_done(); (bso#2191). + ntlm_auth sometimes returns the wrong username to mod_ntlm_auth_winbind; (bso#10087). + s3: smbpasswd: Fix crashes on invalid input; (bso#10320). + s3: vfs_dirsort module: Allow dirsort to work when multiple simultaneous directories are open; (bso#10406). + Add support for Heimdal's unified krb5 and hdb plugin system, cope with first element in hdb_method having a different name in different heimdal versions and fix INTERNAL ERROR: Signal 11 in the kdc pid; (bso#10418). + vfs_btrfs: Fix incorrect zero length server-side copy request handling; (bso#10424). + s3: modules: streaminfo: As we have no VFS function SMB_VFS_LLISTXATTR we can't cope with a symlink when lp_posix_pathnames() is true; (bso#10429). + smbd: Fix an ancient oplock bug; (bso#10436). + Fix crash bug in smb2_notify code; (bso#10442).- Remove superfluous obsoletes *-64bit in the ifarch ppc64 case; (bnc#437293).- Migrate @GMT token parsing functionality into vfs_snapper; (bnc#863079). + Improve vfs_snapper documentation.- Fix Winbind 100% CPU utilization caused by domain list corruption; (bso#10358); (bnc#786677).- Fix memory overwrite in FSCTL_VALIDATE_NEGOTIATE_INFO handler; (bso#10415); (bnc#862370).- Streamline the vendor suffix handling and add support for SLE 12.- Fix zero length server-side copy request handling; (bso#10424); (bnc#862558).- Set the PID directory to /run/samba on post-12.2 systems.- Make use of the tmpfilesdir macro while calling systemd-tmpfiles.- Make winbindd print the interface version when it gets an INTERFACE_VERSION request; (bnc#726937).- Fix vfs_btrfs build on older platforms with duplicate WRITE_FLUSH definitions; (bnc#860832).- Check for NULL gensec_security in gensec_security_by_auth_type(); (bnc#860809).- Ensure ndr table initialization; (bnc#860648).- Add File Server Remote VSS Protocol (FSRVP) server for SMB share shadow-copies; (fate#313346).- s3-dir: Fix the DOS clients against 64-bit smbd's; (bso#2662). - shadow_copy2: module "Previous Version" not working in Windows 7; (bso#10259). - s3-passdb: Fix string duplication to pointers; (bso#10367). - vfs/glusterfs: in case atime is not passed, set it to the current atime; (bso#10384)- s3: winbindd: Move calling setup_domain_child() into add_trusted_domain(); (bso#10358); (bnc#786677).- Default sysconfig daemon options to -D; (bso#10388); (bnc#857454).- Add /var/cache/samba to the client file list; (bnc#846586).- Really add the WINBINDDOPTIONS sysconfig variable on install; (bnc#857454).- Correct sysconfig variable names by adding the missing D char; (bnc#857454).- Update to 4.1.4. + Fix segfault in smbd; (bso#10284). + Fix SMB2 server panic when a smb2 brlock times out; (bso#10311).- Call stop_on_removal from preun and restart_on_update and insserv_cleanup from postun on pre-12.3 systems only; (bnc#857454).- BuildRequire gamin-devel instead of unmaintained fam-devel package on post-12.1 systems.- smbd: allow updates on directory write times on open handles; (bso#9870). - lib/util: use proper include for struct stat; (bso#10276). - s3:winbindd fix use of uninitialized variables; (bso#10280). - s3-winbindd: Fix DEBUG statement in winbind_msg_offline(); (bso#10285). - s3-lib: Fix %G substitution for domain users in smbd; (bso#10286). - smbd: Always use UCF_PREP_CREATEFILE for filename_convert calls to resolve a path for open; (bso#10297). - smb2_server processing overhead; (bso#10298). - ldb: bad if test in ldb_comparison_fold(); (bso#10305). - Fix AIO with SMB2 and locks; (bso#10310). - smbd: Fix a panic when a smb2 brlock times out; (bso#10311). - vfs_glusterfs: Enable per client log file; (bso#10337).- Add /etc/sysconfig/samba to the main and winbind package; (bnc#857454).- Create /var/run/samba with systemd-tmpfiles on post-12.2 systems; (bnc#856759).- Fix broken rc{nmb,smb,winbind} sym links which should point to the service binary on post-12.2 systems; (bnc#856759).- Add Snapper VFS module for snapshot manipulation; (fate#313347). + dbus-1-devel required at build time.- Add File Server Remote VSS Protocol (FSRVP) client for SMB share shadow-copies; (fate#313345).- Do not BuildRequire perl ExtUtils::MakeMaker and Parse::Yapp as they're part of the minimum build environment.- Update to 4.1.3. + DCE-RPC fragment length field is incorrectly checked; CVE-2013-4408; (bnc#844720). + pam_winbind login without require_membership_of restrictions; CVE-2012-6150; (bnc#853347).- Make use of the full gpg pub key file name including the key ID.- Add transparent file compression support; (fate#316266). + Implement FSCTL_GET_COMPRESSION and FSCTL_SET_COMPRESSION handlers. + Add FILE_ATTRIBUTE_COMPRESSED and FILE_NO_COMPRESSION support. + Extend vfs_btrfs VFS module to utilize get/set compression hooks.- Add support for FSCTL_SRV_COPYCHUNK_WRITE; (fate#314770).- Remove bogus libsmbclient0 package description and cleanup the libsmbclient line from baselibs.conf; (bnc#853021).- BuildRequire systemd on post-12.2 systems.- Update to 4.1.2. + s4-dns: dlz_bind9: Create dns-HOSTNAME account disabled; (bso#9091). + dfs_server: Use dsdb_search_one to catch 0 results as well as NO_SUCH_OBJECT errors; (bso#10052). + Missing talloc_free can leak stackframe in error path; (bso#10187). + Fix memset used with constant zero length parameter; (bso#10190). + s4:dsdb/rootdse: report 'dnsHostName' instead of 'dNSHostName'; (bso#10193). + Make offline logon cache updating for cross child domain group membership; (bso#10194). + nsswitch: Fix short writes in winbind_write_sock; (bso#10195). + RW Deny for a specific user is not overriding RW Allow for a group; (bso#10196). + vfs_glusterfs: Fix excessive debug output from vfs_gluster_open(); (bso#10224). + vfs_glusterfs: Implement proper mashalling/unmarshalling of ACLs; (bso#10224). + VFS plugin was sending the actual size of the volume instead of the total number of block units because of which windows was getting the wrong volume capacity; (bso#10224). + libcli/smb: Fix smb2cli_ioctl*() against Windows 2008; (bso#10232). + xattr: Fix listing EAs on *BSD for non-root users; (bso#10247). + Fix the build of vfs_glusterfs; (bso#10253). + s3-winbindd: Fix cache_traverse_validate_fn failure for NDR cache entries; (bso#10264). + util: Remove 32bit macros breaking strict aliasing; (bso#10269).- Let gpg verify execution condition not fail on non SUSE systems.- Add systemd support for post-12.2 systems.- Allow smbcacls to take a '--propagate-inheritance' flag to indicate that the add, delete, modify and set operations now support automatic propagation of inheritable ACE(s); (FATE#316474).- Unconditionally create the CUPS smb backend sym link pointing to smbspool; (bnc#850656).- Update to 4.1.1. + ACLs are not checked on opening an alternate data stream on a file or directory; CVE-2013-4475; (bso#10229); (bnc#848101). + Private key in key.pem world readable; CVE-2013-4476; (bnc#848103).- Private key in key.pem world readable; CVE-2013-4476; (bnc#848103).- ACLs are not checked on opening an alternate data stream on a file or directory; CVE-2013-4475; (bso#10229); (bnc#848101).- Update to 4.1.0. + pam_winbindd: Support the KEYRING ccache type; (bso#10132). + Fix PAC parsing failure; (bso#10178).- Unify the defattr lines in the pidl, python, test and test-devel files section by removing the optional directory mode.- Verify source tar ball gpg signature.- Update to 4.1.0rc4. + dsdb: Convert the full string from UTF16 to UTF8, including embedded NULLs; (bso#8077). + python-samba-tool fsmo: Do not give an error on a successful role transfer; (bso#9461). + dbwrap_ctdb: Treat empty records as non-existing; (bso#10008). + Raise the level of a debug when unable to open a printer; (bso#10118). + Add "acl allow execute always" parameter; (bso#10134). + vfs_shadow_copy2: Display previous versions correctly over SMB2; (bso#10137). + smbd: Always clean up share modes after hard crash; (bso#10138). + Valid utf8 filenames cause "invalid conversion error" messages; (bso#10139). + libcli/smb: Use SMB1 MID=0 for the initial Negprot; (bso#10144). + Samba SMB2 client code reads the wrong short name length in a directory listing reply; (bso#10145). + libcli/smb: Only check the SMB2 session setup signature if required and valid; (bso#10146). + Better document potential implications of a globally used "valid users"; (bso#10147). + cli_smb2_get_ea_list_path() failed to close file on exit; (bso#10149). + Not all OEM servers support the ALTNAME info level; (bso#10150). + Regression causes replication failure with Windows 2008R2 and deletes Deleted Objects; (bso#10157). + Netbios related samba process consumes 100% CPU; (bso#10158). + Fix POSIX ACL mapping when setting DENY ACE's from Windows; (bso#10162).- Require libndr-standard-devel due to gen_ndr/lsa.h from libpdb-devel.- Add libdcerpc0, libdcerpc-atsvc0, libdcerpc-binding0, libdcerpc-samr0, libgensec0, libndr0, libndr-krb5pac0, libndr-nbt0, libndr-standard0, libpdb0, libregistry0, libsamba-credentials0, libsamba-hostconfig0, libsamba-policy0, libsamba-util0, libsamdb0, libsmbclient-raw0, libsmbconf0, libsmbldap0, and libtevent-util0 to baselibs.conf.- Add or polish the shared library package summaries and descriptions.- Update to 4.1.0rc3. + Fix working on site with Read Only Domain Controller; (bso#5917). + Add man page for vfs_syncops; (bso#7364). + Add man page for vfs_linux_xfs_sgid; (bso#7490). + When replicating DNS for bind9_dlz we need to create the server-DNS account remotely; (bso#9091). + Winbind unable to retrieve user information from AD; (bso#9615). + winbind_lookup_names() fails because of NT_STATUS_CANT_ACCESS_DOMAIN_INFO; (bso#9899). + Build Samba 4.0.x on AIX with IBM XL C/C++; (bso#9911). + Add SMB2 and SMB3 support for smbclient; (bso#9974). + Add man pages for ntdb tools; (bso#10000). + Add man page for samba-regedit tool; (bso#10001). + ::1 added to nameserver on join; (bso#10030). + Fix memory leak in source3/lib/util.c:1493; (bso#10063). + Fix segmentation fault in 'net ads join'; (bso#10073). + Fix variable list in vfs_crossrename man page; (bso#10076). + s3-winbind: Fix a segfault passing NULL to a fstring argument; (bso#10082). + smbd: Fix async echo handler forking; (bso#10086). + MacOSX 10.9 will not follow path-based DFS referrals handed out by Samba; (bso#10097). + Honour output buffer length set by the client for SMB2 GetInfo requests; (bso#10106). + Fix Winbind crashes on DC with trusted AD domains; (bso#10107). + Handle Dropbox (write-only-directory) case correctly in pathname lookup; (bso#10114). + Masks incorrectly applied to UNIX extension permission changes; (bso#10121).- Implement shared library packaging guidelines. - Correct interpackage dependencies; (bso#10129).- Define the source URL differently in the case of a release candidate.- Update to 4.1.0rc2. + Add vfs_btrfs module. + Add support for server-side copy operations via the SMB2 FSCTL_SRV_COPYCHUNK request. + Fix replication with --domain-crictical-only to fill in backlinks; (bso#9029). + Windows 8 Roaming profiles fail; (bso#9678). + Fix crash of winbind after "ls -l /usr/local/samba/var/locks/sysvol"; (bso#9820). + Windows error 0x800700FE when copying files with xattr names containing ":"; (bso#9992). + Do not delete an existing valid credential cache (s3-winbind); (bso#9994). + Fix segfault while reading incomplete session info; (bso#10003). + Missing integer wrap protection in EA list reading can cause server to loop with DOS (CVE-2013-4124); (bso#10010). + Fix a 100% loop at shutdown time (smbd); (bso#10013). + Fix/improve debug options; (bso#10015). + Rename regedit to samba-regedit; (bso#10040). + Remove obsolete swat manpage and references; (bso#10041). + Fix crashes in socket_get_local_addr(); (bso#10042). + Allow to change the default location for Kerberos credential caches; (bso#10043). + Remove a redundant inlined substitution of ACLs; (bso#10045). + nsswitch: Add OPT_KRB5CCNAME to avoid an error message; (bso#10048). + dsdb improvements; (bso#10056). + Linux kernel oplock breaks can miss signals; (bso#10064).- BuildRequire pyldb-devel.- Add libnetapi0 and samba-libs to baselibs.conf.- Update to 4.0.9. + Fix crash of Winbind after "ls -l /usr/local/samba/var/locks/sysvol"; (bso#9820). + s3-lib: Fix segmentation fault while reading incomplete session info; (bso#10003). + smbd: Fix a 100% loop at shutdown time; (bso#10013). + Windows 8 Roaming profiles fail; (bso#9678). + Add UPN enumeration to passdb internal API; (bso#9779). + smbd: Cleanup disonnected durable handles; (bso#9930). + vfs_streams_xattr: Do not attempt to write empty attribute twice; (bso#9970). + Fix Windows error 0x800700FE when copying files with xattr names containing ":"; (bso#9992). + s3-winbind: Do not delete an existing valid credential cache; (bso#9994). + Fix excessive RID allocation; (bso#10014). + Add debugclass for DNS server; (bso#10015). + Fix/improve debug options; (bso#10015). + Allow to change the default location for Kerberos credential caches; (bso#10043). + Linux kernel oplock breaks can miss signals; (bso#10064). + net ads join: Fix segmentation fault in create_local_private_krb5_conf_for_domain; (bso#10073).- Update to 4.0.8. + Samba 3.0.x to 4.0.7 are affected by a denial of service attack on authenticated or guest connections; CVE-2013-4124; (bnc#829969).- Require krb5 and not the non existing krb5-libs package.- Update to 4.1.0rc1. + Directory database replication (AD DC mode) + Server-Side Copy Support + Btrfs Filesystem Integration- BuildRequire perl ExtUtils::MakeMaker and Parse::Yapp. - BuildRequire libxslt, libxslt1, or libxslt-tools depending on SUSE version. - Require perl-base on SUSE systems only.- Adjust group setting of the test-devel subpackage. - Require perl-base from the pidl subpackage.- Remove libdir/samba/ldb after install if we're building Samba without Active Directory Domain Controller support.- Remove unused ccache switch from the spec file.- BuildRequire docbook-xsl-stylesheets and libxslt-tools to build the man pages and add them to the package again.- Build from the package from the top level directory; (bnc#794744). - BuildRequire pytalloc-devel, python-tdb, and python-tevent. - Also use out of tree builds of talloc, tdb, tevent, and ldb for pre-12.1 SUSE systems.- Remove the empty data dir from the doc package filelist. - Explicitly use samba instead of the name macro to define the docbook dir.- Update to 4.0.7. + Fix a core dump with invalid lock order while opening/editing or copying MS files; (bso#9794). + Fix crash bug from search of mail=; (bso#9967). + s3-rpc_server: Ensure we are root when starting and using gensec; (bso#9465). + Add support for MX queries; (bso#9485). + dns: Delete dnsNode objects when they are empty; (bso#9559). + dns: Support larger queries when asking forwarder; (bso#9632). + s3:lib/server_mutex: Open mutex.tdb with CLEAR_IF_FIRST; (bso#9805). + Use of wrong RFC2307 primary group field; (bso#9880). + Check for system libtevent; (bso#9881). + is_printer_published GUID retrieval; (bso#9900). + Doc fixes for 4.0; (bso#9906). + Build fixes for 4.0 found during autoconf or debian packaging work; (bso#9907). + build: Add missing new line to replaced python shebang line; (bso#9909). + PIE builds not supported; (bso#9910). + s4:winbind: Don't leak libnet_context into the main event context; (bso#9929). + Fix a bug of drvupgrade of smbcontrol; (bso#9941). + Check for netbios aliases in ad_get_referrals; (bso#9947). + Fix tevent_poll on 32-bit machines (Coverity ID 989236); (bso#9953). + docs: Avoid mentioning a possibly misleading option; (bso#9964). + Fix build with system Heimdal of samba4kgetcred; (bso#9968).- Use SLE as product prefix for SUSE Linux Enterprise, oS for openSUSE, and OBS for any other operating system to define the vendor string while build.- Remove ldapsmb from the main spec file.- Adjust ldapsmb and nmbstatus man page syntax required by a newer pod2man.- Don't bzip2 the main tar ball, use the upstream gziped one instead.- Explicitly BuildRequire cyrus-sasl-devel, libattr-devel, and libopenssl-devel.- Fix libreplace license ambiguity; (bso#8997); (bnc#765270).- Update to 4.0.6. + Fix crash during Win8 sync; (bso#9822). + Fix segfault when loging in with wrong password from w2k8r2; (bso#9834). + Fix the username map optimization; (bso#9139). + Add support for PFC_FLAG_OBJECT_UUID when parsing packets; (bso#9382). + SMB2 server doesn't support recvfile; (bso#9412). + Fix the build of vfs_notify_fam; (bso#9545). + Fix adding case sensitive spn; (bso#9699). + Properly handle oplock breaks in compound requests; (bso#9722). + Properly handle oplock breaks in compound requests; (bso#9722). + Cache name_to_sid/sid_to_name correctly; (bso#9766). + Fix 'net ads join' when called via stdin; (bso#9767). + Fix segfault for "artificial" conn_structs in vfs_fake_perms; (bso#9775). + vfs_dirsort uses non-stackable calls, dirfd(), malloc instead of talloc and doesn't cope with directories being modified whilst reading; (bso#9777). + Fix panic when running 'smbtorture smb.base'; (bso#9782). + Use specified python for runtime installation of Samba; (bso#9785). + Change '--with-dmapi' to 'default=auto' to match the autoconf build; (bso#9803). + wafsamba: Display the default value in help for SAMBA3_ADD_OPTION; (bso#9804). + wbinfo: Fix segfault in wbinfo_pam_logon; (bso#9807). + Package new dbwrap_tool man page; (bso#9809). + Old DOS SMB CTEMP request uses a non-VFS function to access the filesystem; (bso#9811). + Fix 'map untrusted to domain' with NTLMv2; (bso#9817). + SMB signing and the async echo responder don't work together; (bso#9824). + Fix panic in nt_printer_publish_ads; (bso#9830). + talloc use after free in winbind4; (bso#9832). + Function called in unix_convert() path can overwrite errno; (bso#9833). + Fix NULL pointer dereference in Winbind; (bso#9854). + Fix making LIBNDR_PREG_OBJ; (bso#9868).- Remove disabled and anyhow obsoleted net-report and net_rpc_migrate patches.- Update to 4.0.5. + Fix large reads/writes from some Linux clients; (bso#9706). + Add 'samba-tool dbcheck --reset-well-known-acls'; (bso#9740). + Can't delegate adding computers to domain; (bso#9267). + Fix GNU ld version detection with old gcc releases; (bso#7825). + Never try to map global SAM name; (bso#9039). + Certain xattrs cause Windows error 0x800700FF; (bso#9130). + Samba returns unexpected error on SMB posix open; (bso#9519). + Fix build on AIX; (bso#9557). + libnss-winbindd does not provide pass struct for groups mapped with ID_TYPE_BOTH and vice versa; (bso#9617). + Reauth-capable client fails to access shares on Windows member; (bso#9625). + PIDL: Fix parsing linemarkers in preprocessor output; (bso#9636). + Rename internal subsystem pdb_ldap to pdb_ldapsam; (bso#9639). + Fix the build of vfs_afsacl; (bso#9642). + Fix the build with --fake-kaserver; (bso#9643). + Fix compile of source3/lib/afs.c; (bso#9644). + Make SMB2_GETINFO multi-volume aware; (bso#9646). + idmap_autorid: Fix freeing of non-talloced memory; (bso#9653). + Work around FreeBSD's getaddrinfo() underscore issue; (bso#9656). + 'make test' hangs; (bso#9663). + Fix correct linking of libreplace with cmdline-credentials; (bso#9664). + Fix filtering of link-local addresses; (bso#9666). + Fix crash in 'net rpc join' against a Samba 3.0.33 PDC; (bso#9669). + Samba denies owner Read Control when there is a DENY entry while W2K08 does not; (bso#9674). + Fix several resource (fd) leaks; (bso#9683). + Fix a memory leak in spoolss rpc server; (bso#9685). + Fix a possible buffer overrun in pdb_smbpasswd; (bso#9686). + Fix several possible null pointer dereferences; (bso#9687). + Make sure that domain joins work correctly when the DC disallows NTLM auth; (bso#9689). + Backport tevent changes to bring library to version 0.9.18; (bso#9695). + Remove incomplete samba_dnsupdate IPv6 link-local address check; (bso#9696). + DsReplicaGetInfo fails due to sendto() EMSGSIZE error on UNIX domain socket; (bso#9697). + Fix vfs_catia and update documentation; (bso#9701); (bnc#824833). + Fix build on solaris8: Do not force a specific perl on pod2man; (bso#9703). + Fix nss_winbind name on FreeBSD; (bso#9704). + s4:winbindd: Do not drop the workgroup name in the getgrnam, getgrent and getgrgid calls; (bso#9711). + Set LD_LIBRARY_PATH in install_with_python.sh; (bso#9717). + s4-idmap: Remove requirement that posixAccount or posixGroup be set for rfc2307; (bso#9718). + Allow forcing an override of an old @MODULES record; (bso#9719). + Do not print the admin password during 'samba-tool classicupgrade'; (bso#9720). + Make samba_upgradedns more robust (do not guess addresses when just changing roles); (bso#9721). + Add a tool to migrate latin1 printing tdbs to registry; (bso#9723). + is_encrypted_packet() function incorrectly used inside server; (bso#9724). + upgradeprovision and 'samba-tool dbcheck' patches for 4.0.NEXT; (bso#9725). + Fix NULL pointer dereference; (bso#9727). + DO NOT install samba_upgradeprovision in 4.0.x; (bso#9728). + Fix 'smbcontrol close-share'; (bso#9733). + Fix Winbind separator in upn to username conversion; (bso#9735). + Change to smbd/dir.c code gives significant performance increases on large directory listings; (bso#9736). + PIDL: Build fixes for hosts without CPP (Solaris 11); (bso#9739). + Make sure that we only propogate the INHERITED flag when we are allowed to; (bso#9747). + Remove unneeded fstat system call from hot read path; (bso#9748). + Don't leak the epm_Map policy handle; (bso#9758). + Fix incorrect parsing of SMB2 command codes; (bso#9760). - Update to 4.0.4. + Remove forced set of 'create mask' to 0777; CVE-2013-1863; (bnc#809624).- Fix periodic printcap cache reloads; (bso#9650); (bnc#807334).- No longer use the cifs- or smbfstab named configuration file on post-12.2 systems; (bnc#804822); (bnc#821889).- Shift the smbfs init script nfs dependency from Required to Should.- Fix SMB1 Session Setup AndX handling with a large krb PAC; (bso#9658); (bnc#802031).- Point LD_LIBRARY_PATH to the just-built libraries while calling testparm to generate the default share snippets on pre-12.2 systems.- Explicitly configure --with-ads.- Fix smbclient recursive mget EPERM handling; (bso#9633); (bnc#786350).- Remove superfluous quotation marks while setting the SAMBA_VERSION_VENDOR_SUFFIX string.- Do not restart the smbfs service on pre-11.3 systems during dhcp lease renewal when the IP address remains the same; (bnc#800782).- Update to 4.0.3. + Fix ACL problem with delegation of privileges and deletion of accounts over LDAP interface; add documentation; (bso##8909). + check_password_quality: Handle non-ASCII characters properly; (bso##9105). + Fix 'smbd' panic triggered by unlink after open; (bso##9571). + smbd: Fix memleak in the async echo handler; (bso##9549). + defer_open is triggered multiple times on the same request; (bso#9196). + Add extra attributes for AD printer publishing; (bso#9378). + FSMO seize of naming role fails: NT_STATUS_IO_TIMEOUT; (bso#9461). + Downgrade v4 printer driver requests to v3; (bso#9474). + samba_upgradeprovision: fix the nTSecurityDescriptor on more containers; (bso#9481). + s3:smb2_negprot: set the 'remote_proto' value; (bso#9499). + waf assumes that pythonX.Y-config is a Python script; (bso#9503). + s4:drsuapi: Make sure we report the meta data from the cycle start; (bso#9508). + wafsamba: Use additional xml catalog file; (bso#9512). + samba_dnsupdate: Set KRB5_CONFIG for nsupdate command; (bso#9517). + conn->share_access appears not be be reset between users; (bso#9518). + Remove superfluous bracket in samba.8.xml; (bso#9528). + Fix typo in vfs_tsmsm.8.xml; (bso#9530). + terminate the irpc_servers_byname() result with server_id_set_disconnected(); (bso#9540). + Make use of posix_openpt; (bso#9541). + Fix build of vfs_commit and plug in async pwrite support; (bso#9544). + Fix aio_suspend detection on FreeBSD; (bso#9546). + Correctly detect O_DIRECT; (bso#9548). + sigprocmask does not work on FreeBSD to stop further signals in a signal handler; (bso#9550). + smb.conf(5): Update list of available protocols; (bso#9552). + s4-resolve: Fix parsing of IPv6/AAAA in dns_lookup; (bso#9555). + Fix compilation of Solaris ACL module; (bso#9564). + Adding additional Samba 4.0 DC to W2k8 srv AD domain (in win200 functional level) produces dbcheck errors; (bso#9565). + Add dbwrap_tool.1 manual page; (bso#9568). + Document the command line options in dbwrap_tool(1); (bso#9568). + ntlm_auth(1): Fix format and make examples visible; (bso#9569). + Fix file corruption during SMB1 read by Mac OSX 10.8.2 clients; (bso#9572). + Fix a possible null pointer dereference in spoolss; (bso#9574). + Duplicate flags defined in the winbindd protocol; (bso#9575). + gensec: Allow login without a PAC by default; (bso#9581). + smbd: disk_free: sys_popen() failed" message logged in /var/log/message many times; (bso#9586). + Archive flag is always set on directories; (bso#9587). + ACLs are not inherited to directories for DFS shares; (bso#9588). + Correct meta data in ldb manpages; (bso#9591). + s3-winbind: Fix the build of idmap_ldap; (bso#9595). + Linked attribute handling should be by GUID; (bso#9596). + Fix timeouts of some IRPC calls; (bso#9598). + Use pid,task_id as cluster_id in process_single just like process_prefork; (bso#9598). + Add 'ldbdump' tool; general code and documentation cleanup; (bso#9609). + dsdb: Make secrets_tdb_sync cope with -H secrets.ldb; (bso#9610).- Update to 4.0.2. + Address SWAT security issues CVE-2013-0213 and CVE-2013-0214 which both don't apply to any SUSE Samba post-3.6.10 as it isn't longer built. + Don't build and package static libraries.- Drop separate build-source-timestamp file as it led to a second, incorrect Source Timestamp line.- Add server-side copy support; (fate#314770). + Implement FSCTL_SRV_COPYCHUNK and FSCTL_SRV_REQUEST_RESUME_KEY handlers. + Add vfs_btrfs VFS module for optimized Btrfs clone-range ioctl usage.- Add filter against shlib-policy-name-error for /lib*/libnss_wins.so.2.- Disable SWAT during configure and don't package it any longer.- Remove dangling references to Heimdal from the spec file.- Remove /lib/samba prefix from the localstatedir configure option.- Update to 4.0.1. + Samba 4.0.0 as an AD DC may provide authenticated users with write access to LDAP directory objects; CVE-2013-0172; (bnc#798364).- Add the missing get_printing_ticket binary path while calling the set_permissions macro; (bnc#783375).- Use the version macro while definition of the branch macro.- Remove references to no longer used devel macros.- Update to 4.0.0. + Honor password complexity settings; (bso#9414). + Install SWAT *.msg files with waf; (bso#9415). + Fix netr_ServerPasswordSet2, netr_LogonSamLogon with netlogon AES; (bso#9438). + developer-build: Fix panic when acl_xattr fails with access denied; (bso#9456). + Fix "map username script" with "security=ads" and Winbind; (bso#9457). + Install manpages only if we install the target; (bso#9459). + Respond correctly to FILE_STREAM_INFO requests; (bso#9460). + Users can not be given write permissions any more by default; (bso#9462). + Fix MMC crashes; (bso#9470). + Fix SEGV when using second vfs module; (bso#9471). + Support FIPS mode when building Samba; (bso#9479). + Fix ACL on "cn=partitions,cn=configuration"; (bso#9481).- netr_ServerPasswordSet2, netr_LogonSamLogon with netlogon AES broken; (bso#9438). - s3:auth: fix create_token_from_sid() to not fail in the winbindd case; (bso#9457). - s4:dsdb/acl_read: return the nTSecurityDescriptor attr if the sd_flags control is given; (bso#9470). - Support FIPS mode when building Samba; (bso#9479). - s4:provision: set the correct nTSecurityDescriptor; (bso#9481).- SEGV when using second vfs module; (bso#9471).- Update to 3.6.10. + Respond correctly to FILE_STREAM_INFO requests; (bso#9460). + Fix segfault when "default devmode" is disabled; (bso#9433). + Fix segfaults in "log level = 10" on Solaris; (bso#9390).- s3:smbd:vfs_acl: fix a PANIC when setting an ACL fails with ACCESS_DENIED; (bso#9456). - Install manpages only if we install the target; (bso#9459). - Users can not be given write permissions any more by default; (bso#9462).- Fix MD5 detection in the autoconf build; (bso#9037); (bso#9086); (bso#9094); (bso#9418). - Use work around for 'winbind use default domain' only if it is set; (bso#9367). - Allow smb2.acls torture test to pass against smbd with a POSIX ACLs backend; (bso#9374). - large read requests cause server to issue malformed reply; (bso#9422). - s3-rpc_client: lookup nametype 0x20 in rpc_pipe_open_tcp_port(); (bso#9426). - Fix ncacn_ip_tcp reconnection code for lsa lookups; (bso#9439). - Allow to force DNS updates using net; (bso#9451). - Respond correctly to FILE_STREAM_INFO requests; (bso#9460).- Update to 4.0.0rc6. See WHATSNEW.txt from the samba-doc package.- On uninstall remove winbind from the pam configuration, invalidate the nscd passwd and group cache and only recommend the install of nscd; (bnc#792340).- BuildRequire libnscd-devel once.- Remove obsoleted references to pre-9.4 SUSE systems; (bnc#792294). - Add SUSE version depending pkg-config requires macro; (bnc#792294).- Define library names and use it instead of libldb1, libnetapi0, libsmbclient0, libsmbsharemodes0, libtalloc2, libtdb1, libtevent0, and libwbclient0; (bnc#792294). - Provide and obsolete libsmbsharemodes for post-10.3 SUSE systems.- Don't clutter the spec file diff view; (bnc#783384).- Fix fd leak causing 100% CPU in winbind on certain dc connection failures; (bso#9436); (bnc#786677).- Fix spoolss segfault when default devmode is disabled; (bso#9433); (bnc#791183).- Update to 4.0.0rc5. See WHATSNEW.txt from the samba-doc package.- ACL masks incorrectly applied when setting ACLs; (bso#9236). - s3-kerberos: also try with AES keys, when decrypting tickets; (bso#9272). - lib/replace: replace all *printf function if we replace snprintf; (bso#9390). - lib/addns: don't depend on the order in resp->answers[]; (bso#9402).- s4:torture/smb2: improve the smb2.create.blob tes; (bso#9209). - lib/krb5_wrap: request enc_types in the correct order; (bso#9272). - Fix net ads join message for the dns domain; (bso#9326). - docs-xml: fix use of tag; (bso#9345). - s3-aio_pthread: Optimize aio_pthread_handle_completion; (bso#9359). - s3:winbind: Failover if netlogon pipe is not available; (bso#9386).- Execute the run_permissions macro on pre-11.4 systems and else the set_permission one if available.- Ensure adding the winbind group never can fail.- Create ntadmin group only if it doesn't yet exist.- Update to 3.6.9. + When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). + Winbind can't fetch user or group info from AD via LDAP; (bso#9147). + Fix segfault in smbd if user specified ports out for range; (bso#9218).- quota: Don't force the block size to 512; (bso#3272). - Fix poll replacement to become a msleep replacement; (bso#8107). - Fix wrong test == syntax in configure; (bso#8146). - Fix --with(out)-sendfile-support option handling in autoconf; (bso#8344). - Fix builtin forms order to match Windows again; (bso#8632). - Fix RAW printing for normal users; (bso#8769); (bnc#790741). - Initialise ticket to ensure we do not invalid memory; (bso#8788). - Fix 'net rpc share allowedusers' to work with 2008r2; (bso#8966). - Fix crash on null pam change pw response; (bso#9013). - Connection to outbound trusted domain goes offline; (bso#9016). - Increase debug level for info that the db is empty; (bso#9112). - 'smbclient' can't connect to a Windows 7 server using NTLMv2; (bso#9117). - Winbind can't fetch user or group info from AD via LDAP; (bso#9147). - Open printers with the right access mask; (bso#9154). - Fix makerpms.sh on RHEL; (bso#9165). - Remove non-existent option '-Y' from winbindd manpage; (bso#9171). - Add quota support for gfs2; (bso#9172). - Make SMB2 compound request create/delete_on_close/close work as Windows; (bso#9173). - Empty SPNEGO packet can cause smbd to crash; (bso#9174). - pam_winbind: Match more return codes when wbcGetPwnam has failed; (bso#9177). - Fix crash bug in idmap_hash; (bso#9188); (bnc#788159). - SMB2 Create doesn't return correct MAX ACCESS access mask in blob; (bso#9189). - Fix service control for non-internal services; (bso#9192). - Don't take 'state->te' as indication for "was_deferred"; (bso#9196). - Parse of invalid SMB2 create blob can cause smbd crash; (bso#9209). - Bad ASN.1 NegTokenInit packet can cause invalid free; (bso#9213). - Fix segfault in smbd if user specified ports out for range; (bso#9218). - Signing cannot be disabled for SMB2 by design, so fix the documentation instead; (bso#9222). - Fix NT_STATUS_IO_TIMEOUT during slow import of printers into registry; (bso#9231). - When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). - lib-addns: ensure that allocated buffer are pre set to 0; (bso#9259). - Make tdb robust against shrinking tdbs and improper CLEAR_IF_FIRST restart; (bso#9268). - Add support for reloading systemd services; (bso#9280).- Warn via the smbd log if AppArmor and "wide links" are in use; (bnc#783719).- Do not write the build date into the header of the default smb.conf as this causses superfluous rebuilds of packages depending on samba; (bnc#781601).- Do not prerequire SuSEconfig.permissions as it's already enough and more generic to depend on the permissions package; (bnc#782293).- Update to 3.6.8. + Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). + Fix Winbind panic if we couldn't find the domain; (bso#9135).- Backport FSCTL codes and fix segfault in smbstatus from master; (bso#9058). - Fix bad call to memcpy source3/registry/regfio.c; (bso#9065). - "Domain Users" incorrectly added as additional group on domain members; (bso#9066). - Use correct RID for "Domain Guests" primary group; (bso#9067). - Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). - Fix smbclient/tarmode panic when connecting to Windows 2000 clients; (bso#9088). - Fix refreshing of Kerberos tickets in Winbind; (bso#9098). - Fix identification of idle clients in Winbind to avoid crashes and NDR parsing errors; (bso#9104). - Fix compilation with newer MIT Kerberos which hides internal symbols; (bso#9111). - Fix flooding the logs with records we don't find in pcap; (bso#9112). - Initialize the print backend after we setup winreg; (bso#9122). - Fix lprng job tracking errors; (bso#9123). - Fix setting of "inherited" bit on inherited ACE's; (bso#9124). - Fix Winbind panic if we couldn't find the domain; (bso#9135). - Make 'smbclient allinfo' show the snapshot list; (bso#9137). - Fix nfs quota support with Linux nfs4 mounts; (bso#9144). - Valid open requests can cause smbd assert due to incorrect oplock handling on delete requests; (bso#9150).- NMB registration for a duplicate workstation fails with registration refuse; (bso#9085); (bnc#770056).- Remove backup files caused by running configure in examples/VFS.- Update to 3.6.7. + Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). + Fix migrating printers while upgrading from 3.5.x; (bso#9026).- Correct documentation of "case sensitive"; (bso#8552). - Printing fails in function cups_job_submit; (bso#8719). - Fix kernel oplocks when uid(file) != uid(process); (bso#8974). - Send correct responses to NT Transact Secondary when no data and no params for the Trans2 calls are set; (bso#8989). - Fix build without ads support; (bso#8996). - Don't turn negative cache entries into valid idmappings; (bso#9002). - Fix posix acl on gpfs; (bso#9003). - Make vfs_gpfs less verbose in get/set_xattr functions; (bso#9022). - Fix migrating printers while upgrading from 3.5.x; (bso#9026). - Fix typo in set_re_uid() call when USE_SETRESUID selected in configure; (bso#9034). - Using asynchronous IO with SMB2 can return NT_STATUS_FILE_CLOSED in error instead ofNT_STATUS_FILE_LOCK_CONFLICT; (bso#9040). - Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). - Fix build against CUPS 1.6; (bso#9055). - Fix bugs in SMB2 credit handling code; (bso#9057). - rpcclient: Fix bad call to data_blob_const; (bso#9062).- Create missing doc directories while install. - Remove no longer existing Manifest file from install. - Don't creat a link to non existend html man pages for swat. - Don't call the no longer existing libsmbclient testsuit while build.- Configure with option --mandir instead --with-mandir. - Remove obsoleted --with-rootsbindir, --with-nmbdsocketdir, and - -with-swatdir configure options.- Update to 4.0.0beta4. See WHATSNEW.txt from the samba-doc package.- BuildRequire gcc, make, and patch; (bnc#771516).- ndr: fix push/pull DATA_BLOB with NDR_NOALIGN; (bso#9026); (bnc#770262).- Fix shell syntax in dhcpcd hook script; (bnc#769957).- Add missing int declaration to the net kdc lookup patch.- Update to 4.0.0beta2. See WHATSNEW.txt from the samba-doc package.- Update to 3.6.6. + Fix possible memory leaks in the Samba master process; (bso#8970). + Fix uninitialized memory read in talloc_free(); (bnc#764577). + Fix joining of XP Pro workstations to 3.6 DCs; (bso#8373); (bnc#787983).- resolve_ads() code can return zero addresses and miss valid DC IP addresses; (bso#8910). - Can't join XP Pro workstations to 3.6.1 DC; (bso#8373); (bnc#787983). - winbind can hang as nbt_getdc() has no timeout; (bso#8953). - Fix crash bug in dns_create_probe when dns_create_update fails; (bso#8627) - s3-pid: Catch with pid filename's change when config file is not smb.conf; (bso#8714). - Possible memory leaks in the main Samba process; (bso#8970). - s3: Fix uninitialized memory read in talloc_free(); (bnc#764577). - Treat exit_server_cleanly() as a "clean" shutdown; (bso#8971). - Avoid crash with MIT krb5 1.10.0 in gss_get_name_attribute(); (bso#8988). - Winzip occasionally can not read files out of an open winzip dialog; (bso#8311). - s3-winbindd: call dump_core_setup after command line option has been parsed; (bso#8975). - Directory group write permission bit is set if unix extensions are enabled; (bso#8972). - s3: remove dependency on automake for "make everything"; (bso#8978). - sd_has_inheritable_components segfaults on an SD that se_access_check accepts; (bso#8811). - smbclient's tarmode insists on listing excluded directories; (bso#8922). - Notify code can miss a ChDir; (bso#8998). - s3:smbd: add a fsp_persistent_id() function; (bso#8995).- Call autogen.sh even on post-12.1 SUSE systems.- Don't call autogen.sh on post-12.1 SUSE and post-14 Fedora systems. - Recompile all IDL in any case.- BuildIgnore libtalloc and libtdb to prevent a package conflict on Fedora systems.- Install talloc.pc only on pre-12.2 and non SUSE systems.- BuildRequire libldb-devel, libtalloc-devel, libtdb-devel, and libtevent-devel on post-12.1 systems.- s3: Fix a segfault with debug level 3 on Solaris; (bso#8861). - s3: wbinfo --lookup-sids "" crashes winbind; (bso#8904). - smbd crashes when deleting directory and veto files are enabled; (bso#8837). - winbind_krb5_locator only returns one IP address; (bso#8897). - Wrong assertion/comparison: Compare value not pointer; (bso#8859). - Inconsistent (with manpage) command-line switch for "help" in smbtree; (bso#8831). - Fix incorrect debug statement. - Setting traverse rights fails to enable directory traversal when acl_xattr in use; (bso#8857). - Syslog broken owing to mistyping of debug_settings.syslog; (bso#8877). - s3/ldap: remove outdated netscape ds 5 schema file; (bso#8869). - s3-docs: fixes several typos; (bso#7938). - s3-VFS: Fix building out-of-tree modules; (bso#8822). - s3-docs: Add hint that setting "profile acls = yes" on normal shares can cause trouble; (bso#7930). - s3-pam_winbind: Fix the build with a newer iniparser library; (bso#8915). - Avoid null dereference in initialize_password_db(); (bso#8920). - s3:registry: implement values_need_update and subkeys_need_update in the smbconf backend. - s3:registry:reg_api: fix reg_queryvalue to not fail when values are modified while it runs. - s4:torture:rpc:spoolss: also initialize driverName before checking it in test_PrinterData_DsSpooler(). - s3:registry: multiple cleanups, fixes, and optimisations. - s3:auth/server_info: the primary rid should be in the groups rid array; (bso#8798). - s3-printing: Add new printers to registry; (bso#8554); (bso#8612); (bso#8748). - Fix the overwriting of errno before use in a DEBUG statement and use the return value from store_acl_blob_fsp rather than ignoring it; (bso#8945). - s3-auth: Don't lookup the system user in pdb; (bso#8944). - s3-passdb: Fix negative SID->uid/gid cache handling; (bso#8952). - Fix typo in pam_winbindd code; (bso#8957). - Fix remove_duplicate_addrs2 previously it could leave zero addresses in the list; (bso#8910). - Slow but responsive DC can lock up winbindd; (bso#8943). - Broken processing of %U with vfs_full_audit when force user is set; (bso#8882).- Disable included build of ldb, talloc, tdb, and tevent on post-12.1 systems. - BuildRequire libldb1-devel, libtalloc2-devel, libtdb1-devel, and libtevent0-devel on post-12.1 systems.- Add PreReq /etc/init.d/nscd to the winbind package; (bnc#759731).- docs-xml: fix default name resolve order; (bso#7564). - s3-aio-fork: Fix a segfault in vfs_aio_fork; (bso#8836). - docs: remove whitespace in example samba.ldif; (bso#8789). - s3-smbd: move print_backend_init() behind init_system_info(); (bso#8845); (bnc#730769). - s3-docs: Prepend '/' to filename argument; (bso#8826).- Update to 3.6.5. - Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; (bnc#757576).- Remove all precompiled idl output to ensure any pidl changes take effect; (bnc#757080).- Update to 3.6.4. - Samba pre-3.6.4 are affected by a vulnerability that allows remote code exe- cution as the "root" user; PIDL based autogenerated code allows overwriting beyond of allocated array; CVE-2012-1182; (bso#8815); (bnc#752797).- s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; (bso#8599). - Correctly handle DENY ACEs when privileges apply; (bso#8797).- s3:smb2_server: fix a logic error, we should sign non guest sessions; (bso8749). - Allow vfs_aio_pthread to build as a static module; (bso#8723). - s3:dbwrap_ctdb: return the number of records in db_ctdb_traverse() for persistent dbs; (#bso8527). - s3: segfault in dom_sid_compare(bso#8567). - Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER; (bso#8768). - s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path; (bso#8771). - s3-winbindd: set the can_do_validation6 also for trusted domain; (bso#8599). - Fix problem when calculating the share security mask, take priviliges into account for the connecting user; (bso#8784).- Fix crash in dcerpc_lsa_lookup_sids_noalloc() with over 1000 groups; (bso#8807); (bnc#751454).- Remove obsoleted Authors lines from spec file for post-11.2 systems.- Make ldapsmb build with Fedora 15 and 16; (bso#8783). - BuildRequire libuuid-devel for post-11.0 and other systems. - Define missing python macros for non SUSE systems. - PreReq to fillup_prereq and insserv_prereq only on SUSE systems. - Always use cifstab instead of smbfstab on non SUSE systems.- Ensure AndX offsets are increasing strictly monotonically in pre-3.4 versions; CVE-2012-0870; (bnc#747934).- Add SERVERID_UNIQUE_ID_NOT_TO_VERIFY; (bso#8760); (bnc#741854).- s3-printing: fix crash in printer_list_set_printer(); (bso#8762); (bnc#746825).- s3:winbindd fix a return code check; (bso#8406).- s3: Add rmdir operation to streams_depot; (bso#8733).- s3:smbd:smb2: fix an assignment-instead-of-check bug conn_snum_used(); (bso#8738); CVE-2013-0454; (bnc#811975).- s3:auth: fill the sids array of the info3 in wbcAuthUserInfo_to_netr_SamInfo3(); (bso#8739).- s3:client: ignore SMBecho errors (the server may not support it); (bso#8139).- Be more strict when using PAM_AUTH API from winbind if Kerberos auth is enabled and don't unintentionally use a bogus domain name; (bso#8734).- smbclient fails with posix large reads; (bso#8727).- Use the smbfs init script on versions pre-11.3, or cifs in later versions; (bnc#744614).- s3: Compile IDL files in autogen, some configure tests need this.- Fixes various deadlocks in if-up.d / if-down.d when running under systemd; (bnc#732395).- Update to 3.6.3. + Fix memory leak in parent smbd on connection; CVE-2012-0817; (bso#8724); (bnc#743986).- Use spdx.org compliant license names for all packages.- Update to 3.6.2. + Make Winbind receive user/group information (bug #8371). + Several SMB2 fixes. + Fix a crash bug in the spoolss code. + Add new contributing FAQ announcing acceptance of corporate (C). + DeletePrinterDriverEx deletes files in use; (bso#4942); (bnc#742504). + Fix cli_write_and_x() against OS/2 print shares; (bso#5326). + Fix 'smbclient tar' for files greater than 8GB on BE machines; (bso#563); (bnc#726145). + Remove pointless use_memory_krb5_ccache; (bso#7465). + Fix perl path; (bso#8176). + Grant credits in async interim responses (SMB2); (bso#8357). + Make Winbind receive user/group information; (bso#8371). + Fix Windows XP clients crashing smbd process every once in a while; (bso#8384); (bnc#731571). + Make VFS op "streaminfo" stackable; (bso#8419). + Add an allocation pool to idmap_autorid; (bso#8444). + Fix SEGFAULT from net registry export on not zero terminated REG_SZ values; (bso#8528). + Make DSO_EXPORTS_CMD more portable; (bso#8531). + readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). + smbclient posix_open command fails to return correct info on open file; (bso#8542). + winbind_samlogon_retry_loop ignores logon_parameters flags; (bso#8548). + Fix setting the machine account password; (bso#8550). + Make SMB2 handle compound request headers in the same way as Windows; (bso#8560). + Password change settings not fully observed; (bso#8561). + Fix double free error in talloc; (bso#8562). + Fix alignment in the non-extended-security negprot; (bso#8573). + Add systemd service files; (bso#8575). + Add systemd service files; (bso#8575). + smb2_flush: Don't send uninitialized memory; (bso#8579). + Enable inotify if sys or kernel inotify is available; (bso#8580). + Increase a debug level; (bso#8585). + libsmb: Only align unicode pipe_name; (bso#8586). + Fix marshalling of samr_ChangePasswordUser3; (bso#8591). + Don't limit the number of open dptrs for SMB2; (bso#8592). + Fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). + Make cldap work over IPv6; (bso#8600). + Fix intermittent print job failures caused by character conversion errors; (bso#8606). + Improve configure.in so it can be used outside the Samba source tree; (bso#8607). + Winbind: Don't fail on users without a uid; (bso#8608). + Ensure we correctly calculate reply credits over all returned SMB2 replies; (bso#8614). + Fix migrate printer code; (bso#8618). + Fix crash bug when trying to browse Samba printers; (bso#8623). + libsmb: Don't duplicate Kerberos service tickets; (bso#8628). + POSIX ACE x permission becomes rx following mapping to and from a DACL; (bso#8631). + When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636). + Fix the vfs_commit module; (bso#8639). + Add an update function for Winbind cache; (bso#8643). + vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). + Document the "ignore system acls" option of vfs_acl_xattr and vfs_acl_tdb vfs modules; (bso#8652). + Fix deleting a symlink if the symlink target is outside of the share; (bso#8663). + Fix renaming a symlink if the symlink target is outside of the share; (bso#8664). + Fix NT ACL issue; (bso#8673). + Fix buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). + Fix Winbind segfault if we can't map the last user; (bso#8678). + recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). + Try ctdbd_init_connection() as root; (bso#8684). + Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686). + Fix typo in 'net memberships' usage; (bso#8687). + libads: Fix malloc/talloc mismatch in ads_keytab_verify_ticket(); (bso#8692). + Make DeletePrinterDriverEx remove printer driver files; (bso#8697) (bnc#740810). + Fix major leak with SMB2 in connections.tdb; (bso#8710).- s3-spoolss: Pass the right pointer type; (bso#4942); (bnc#742504).- Use correct license, LGPLv3+ for libwbclient packages.- When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636).- Fix incorrect types in the full_audit VFS module. Add null terminators to audit log enums; (bnc#742885).- Prefix print$ path on driver file deletion; (bso#8697); (bnc#740810). - Fix printer_driver_files_in_use() call ordering; (bso#4942); (bnc#742504).- Buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). - NT ACL issue; (bso#8673). - Deleting a symlink fails if the symlink target is outside of the share; (bso#8663). - connections.tdb - major leak with SMB2; (bso#8710).- Renaming a symlink fails if the symlink target is outside of the share; (bso#8664).- Intermittent print job failures caused by character conversion errors; (bso#8606). - ads_keytab_verify_ticket mixes talloc allocation with malloc free; (bso#8692). - libcli/cldap: fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). - s3:lib/ctdbd_conn: try ctdbd_init_connection() as root; (bso#8684). - s3-printing: fix migrate printer code; (bso#8618). - Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686).- net memberships usage info was wrong; (bso#8687). - s3-libsmb: Don't duplicate kerberos service tickets; (bso#8628). - Recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). - s3-winbind: Fix segfault if we can't map the last user; (bso#8678). - vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). - s3/doc: document the ignore system acls option of vfs_acl_xattr and vfs_acl_tdb; (bso#8652). - Winbind can't receive any user/group information; (bso#8371). - s3-winbind: Add an update function for winbind cache; (bso#8643). - s3: Attempt to fix the vfs_commit module. - POSIX ACE x permission becomes rx following mapping to and from a DACL; (#bso#8631). - s3:libsmb: only align unicode pipe_name; (bso#8586). - s3-winbind: Don't fail on users without a uid; (bso#8608). - Crash when trying to browse samba printers; (bso#8623). - talloc: double free error; (bso#8562). - cldap doesn't work over ipv6; (bso#8600). - s3:libsmb: fix cli_write_and_x() against OS/2 print shares; (bso#5326). - SMB2: not granting credits for all requests in a compound request; (bso#8614). - smb2_flush sends uninitialized memory; (bso#8579). - Password change settings not fully observed; (bso#8561). - s3:smb2_server: grant credits in async interim responses; (bso#8357). - s3:smbd: don't limit the number of open dptrs for smb2; (bso#8592). - samr_ChangePasswordUser3 IDL incorrect; (bso#8591). - idmap_autorid does not have allocation pool; (bso#8444). - Add systemd service files. - s3:libsmb: the workgroup in the non-extended-security negprot is not aligned; (bso#8573). - s3-build: Fix inotify detection; (bso#8580). - SMB2 doesn't handle compound request headers in the same way as Windows; (#bso8560). - Disconnecting clients swamp the logs; (bso#8585). - s3-netlogon: Fix setting the machinge account password; (bso#8550). - winbind_samlogon_retry_loop ignores logon_parameters flags; (#bso8548). - smbclient posix_open command fails to return correct info on open file; (bso#8542). - readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). - s3-netapi: remove pointless use_memory_krb5_ccache; (bso#7465). - s3:Makefile: make DSO_EXPORTS_CMD more portable; (bso#8531). - s3:registry: fix the test for a REG_SZ blob possibly being a zero terminated ucs2 string; (bso#8528). - Make VFS op "streaminfo" stackable; (bso#8419).- Fix incorrect perfcount array length calculations; (bnc#739258).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems.- Remove call to suse_update_config macro for post-11.4 systems.- Use samba.org for the ldapsmb source location.- Fixing libsmbsharemode dependency on ldap and krb5 libs in Makefile; (bnc #729516).- Do not map POSIX execute permission to Windows FILE_READ_ATTRIBUTES; (bso#8631); (bnc#732572).- Add ldap to Should-Start and Stop of the smb init script; (bnc#730046).- Fix smbd srv_spoolss_replycloseprinter() segfault; (bso#8384); (bnc#731571).- Fix pam_winbind.so segfault in pam_sm_authenticate(); (bso#8564).- Fix smbclient >8GB tars on big endian machines; (bso#563); (bnc#726145).- Fix typo in net ads join output; (bnc#713135).- Ignore a potentially missing AppArmor snippet helper script; (bnc#725256).- Update to 3.6.1. + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Several SMB2 fixes. + The VFS ACL modules are no longer experimental but production-ready. + Fix 'net ads join -k' when KRB5CCNAME is not set; (bso#7465). + smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509). + Return error of cli_push when 'put - /some/file' is used; (bso#7551). + Fix usage of cli_errstr(); (bso#7864). + Fix 'widelinks' regression; (bso#8229). + Empty notify servername; (bso#8236). + Add man vfs_aio_fork; (bso#8256). + smb2: smbd logs "Invalid SMB packet: first request: 0x0008" and crashes; (bso#8334). + Add a fallback for missing open&x support in MAC OS/X Lion; (bso#8338). + While migrating forms, don't fail if the form already exists; (bso#8351). + OS/2 sends an unexpected write&x/read&x chain; (bso#8360). + Fix build of vfs_prealloc on SLES8; (bso#8363). + Fix the build of gpfs.c on RHEL 6.0 with gpfs 3.4.0-4; (bso#8364). + Fix the fallback to the deprecated spelling idmap:script; (bso#8368). + Fix vfs_chown_fsp; (bso#8370). + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix smbclient access to NT4 shares; (bso#8385). + Optimize serverid_exists() for Solaris; (bso#8395). + registry/reg_format.c must include includes.h; (bso#8401). + SMB2 server can return requests out-of-order when processing a compound request; (bso#8407). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Fix "saving as" of MS Office 2007 (Word) documents on Samba shares with SMB2; (bso#8412). + Fix 'getent group' if trusted domains are not reachable; (bso#8420). + Fix infinite loop in ACL module code; (bso#8422). + Fix wrong reply to DHnC (durable handle reconnect); (bso#8428). + Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429). + Fix segfault in iconv.c; (bso#8433). + NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442). + Be smarter about setting default permissions when a ACL_USER_OBJ isn't given; (bso#8443). + Check the wct of the incoming SMBnegprot responses; (bso#8452). + Fix smbclient segfaults when dialect option -m is used for legacy dialects; (bso#8453). + Fix uninitialized memory problem in group_sids_to_info3; (bso#8455). + Samba PDC is looking up only primary user group; (bso#8455). + IE9 on Windows 7 cannot download files to samba 3.5.11 share; (bso#8458). + smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473). + SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474). + Don't call smbd_terminate_connection in smb2_validate_message_id(); (bso#8476). + Samba asserts when SMB2 client breaks the crediting rules; (bso#8476). + Map to guest can return uninitialized blob of data; (bso#8477). + acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480). + DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493). + Remove "experimental" label on VFS ACL modules; (bso#8494). + SMB2_OP_CANCEL requests don't have to be signed; (bso#8503). + smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507). + Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509). + Disallow "." in can_set_delete_on_close(); (bso#8515). + SMB2 create call returns incorrect file allocation size; (bso#8518). + Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520). + Winbind cache timeout expiry test was reversed; (bso#8521).- s3/doc: add man page for aio_fork vfs module.- Fix uninitialized memory problem in group_sids_to_info3; (bso#8455).- s3: Samba PDC is looking up only primary user group; (bso#8455).- Add script to create or update an AppArmor sniplet with permissions for all Samba shares; (bnc#688040).- Add "ldapsam:login cache" parameter to allow explicit disabling of the login cache; (bnc#723261).- Retain the smbd startproc return value for correct startup status reporting. unset was incorrectly being called prior to rc_status; (bnc#723724).- Prevent deadlock in systemd triggered by if-down.d handler on shutdown; (bnc#721598).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; changed defaults and documentation (bso8473).- Empty CIFS share can be blocked for other clients by deleting it via empty path (DELETE_PENDING until the last client); (bso#8515).- winbindd cache timeout expiry test was reversed; (bso#8521).- Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520).- s3:smb2_create: fix allocation size return value when opening existing files; (bso#8518).- SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474).- NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442).- s3-docs: Fix bug (bso#7908) and typo.- Return error of cli_push when 'put - /some/file' is used; (bso#7551).- Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509).- smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507).- Default user entry is set to minimal permissions on incoming ACL change with no user specified; (bso#8443).- smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509).- Handle the SECINFO_LABEL flag in the same was as Win2k3; enable Microsoft Internet Explorer 9 on Windows 7 to download files; (bso#8458).- DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493).- s3-docs: Fix typos.- s3:smb2_server: SMB2_OP_CANCEL requests don't have to be signed; (bso#8503).- Remove "experimental" label on VFS ACL modules; (bso#8494).- acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480).- s3-smbd: asserts when SMB2 client breaks the crediting rules; (bso#8476).- s3-libnet: allow to use default krb5 ccache in libnet_Join/libnet_Unjoin; (bso#7465).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473).- s3-netapi: allow to use default krb5 credential cache for libnetapi users.- s3-docs: document -k switch in net manpage.- Map to guest can return uninitialized blob of data; (bso#8477).- s3-registry: registry/reg_format.c must include includes.h; (bso#8401).- smbclient segfaults when option -m is used for legacy dialects; (bso#8453).- Fix 'widelinks' regression intro'd in 3.2; (bso#8229).- Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429).- s3-spoolss: Fix bug forms migration; (bso#8351).- s3:libsmb: check the wct of the incoming SMBnegprot responses; (bso#8452).- s3: Do not fork the echo handler for smb2; (bso#8334).- s3-spoolss: Fix bug empty notify servername; (bso#8236).- SMB2 server can return requests out-of-order when processing a compound request; (bso#8407).- Remove smb child crash fix. The issue had been fixed upstream differently.- BuildRequire ctdb-devel version greater than 1.0.105 for post-10.0 systems.- Fix samba duplicates file content on appending. Move posix case semantics out from under the VFS; (bso#6898); (bnc#681208).- Make winbind child reconnect when remote end has closed, fix failing sudo; (bso#7295); (bnc#569721).- Spec file cleanup as suggested by the spec-cleaner tool. + Make all BuildRequires, PreReq, and Provides a separate line. + Use %{buildroot} instead of ${RPM_BUILD_ROOT}. + Use straight commands instead of macros (make, install). + Use -p in post and postun if we only call one command. + Use %{_localstatedir} instead of %{_var} in the filelist. + Remove superfluous AutoReqProv on lines.- Remove %release from all Provides.- Fix segfault in iconv.c which caused a null pointer dereference; (bso#8433).- Use /var/run for the cifs state file in the init script too; (bnc#710304).- Microsoft Word from Microsoft Office 2007 fails to save as on a share with SMB2; (bso#8412).- Use sys_write and sys_read in fork_domain_child to fix a winbind race leading to 100% CPU usage; (bso#8409).- Fix wrong reply to smb2 durable handle reconnect (DHnC) request; (bso#8428).- Fix infinite loop in ACL module code; (bso#8422).- Fix getent group if trusted domains are not reachable; (bso#8420).- smbclient can't access a NT4 share since 3.6.0; (bso#8385).- Optimize serverid_exists() for Solaris; (bso#8395).- talloc: + check block count after references test. + added test suite for talloc_free_children(). + license info erratum in the manpage. + fix typos and better differentiation between versions 1 and 2. + preserve context name on talloc_free_children(). + ensure the sibling linked list remains valid during a free.- vfs_chown_fsp returned in the wrong directory; (bso#8370).- Remove irritating "." targets when recent system libs exist; (bso#8369).- Correctly initialize "idmap config * : script" with NULL; (bso#8368).- Add missing include to suppress compiler warnings; (bso#8365).- Point the chain offset beyond the current request; (bso#8360).- Fix gpfs vfs module build; (bso#8364).- Make vfs_prealloc even build on older systems; (bso#8363).- Do central cli_set_error and return the actual NTSTATUS; (bso#7864).- Add a fallback for missing open&x support in OS/X Lion; (bso#8338).- Update to 3.6.0. + BUG 7462: Make SA_RESETHAND conditional on its existance. + BUG 8303: db_ctdb_send_schedule_for_deletion() is not defined. + BUG 8324: smbclient cannot list directories from a big-endian machine. + BUG 8326: WinXP cannot join a Samba3 domain with a 'even' hostname. + BUG 8327: Fix the reload of the configuration, also reload activated registry shares. + BUG 8328: Cleanup of idmap_tdb2 code. + BUG 8330: Fix NFSv4 ACL merging logic. + BUG 8335: File copy aborts with smb2_validate_message_id: bad message_id. + BUG 8341: Fix segfault in libsmbclient. + BUG 8343: Fix SMB2 crash reading with aio_fork beyond the end of file. + BUG 8347: Fix regression for HP-UX, AIX and OSF. + BUG 8357: Make sure we grant credits on async read/write operations. + BUG 8358: Fix a bug in run_poll_events(). + BUG 8362: Fix build issue on old glibc systems.- Remove references to disabled vscan build.- Add missing define, includes, and initialization to get_printing_ticket.- Use /var/run for the cifs state file; (bnc#710304).- Fix #ifdef CTDB_CONTROL_SCHEDULE_FOR_DELETION issue; (bso#8303).- File copy aborts with smb2_validate_message_id: bad message_id; (bso#8335).- Fix reload of the configuration and also reload activated registry shares; (bso#8327).- WinXP cannot join a Samba3 domain with a 'even' hostname; (bso#8326).- smbclient cannot list directories from a big-endian machine; (bso#8324).- Update to 3.6.0rc3. + BUG 7841: Explicitly pass domain_sid to wbint_LookupRids(). + BUG 7888: Deal with buggy 3.0 based PDCs. + BUG 8083: Fix "inherit owner = yes" with vfs_acl_xattr or vfs_acl_tdb module. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8193: Add new command 'enumerate_recursive'. + BUG 8195: Make rpc client code working against NT4 servers. + BUG 8211: Fix "inherit owner = yes" when "inherit permissions = yes" is set. + BUG 8213: Fixes in idmap_autorid. + BUG 8214: Fix smbd crash on printer driver upgrade. + BUG 8215: Fix Winbind unix username lookup. + BUG 8216: Make Winbind returning correct results with 'sids2xids'. + BUG 8217: Do not stat-check the share path in 'net conf addshare'. + BUG 8219: Fix SMB Panic from Windows 7 client. + BUG 8224: Fix the build on FreeBSD. + BUG 8226: Use c99 initializers which are supported by old gcc 2.95 compilers. + BUG 8230: Move .nmbd socket directory to non-hidden name PREFIX/var/nmbd. + BUG 8231: Fix crash bug in 'net cache get'. + BUG 8235: Fix smbd crash on startup caused by migrate_printer(). + BUG 8240: Fix Valgrind warnings in winreg/spoolss code. + BUG 8244: Fix copying files larger than 2 GB to a Samba share. + BUG 8247: Fix Coverity ID 2582: FORWARD_NULL. + BUG 8253: Fix Winbind panic if verify_idpool() fails. + BUG 8254: Fix "acl check permissions = no". + BUG 8260: Fix DCERPC responses with fragments larger than 1024 bytes. + BUG 8262: Fix build of vfs_commit. + BUG 8263: Fix build with --with-fake-kaserver or --with-vfs-afsacl. + BUG 8264: Fix Valgrind bugs in svcctl. + BUG 8276: Close all sockets attached to a subnet in close_subnet(). + BUG 8278: Fix smbd panic when CTDB is unhealthy. + BUG 8281: Fix build of examples/VFS/*. + BUG 8286: Fix smbd crash on premature end of smb2 conn. + BUG 8292: Fix a major architectural flaw in the SMB2 server code. + BUG 8293: Fix log file rotating in SMB2. + BUG 8304: Fix uninitialized variable in error path. + BUG 8305: Fix segfault in nmbd when using 'smbtree ...'.. + BUG 8307: brl_close_fnum does not call SMB_VFS_BRL_UNLOCK_WINDOWS on all locks. + BUG 8310: toupper_ascii() is broken on big-endian systems. + BUG 8314: Fix smbd crash with unknown user. + Mark 'time offset' parameter as deprecated.- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site scripting vulnerability; CVE-2011-2694; (bso#8289); (bnc#708503).- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site request forgery; CVE-2011-2522; (bso#8290); (bnc#705241).- Fixed the DFS referral response for msdfs root; (bnc#703655).- Fix CUPS print job IDs; (bso#7288); (bnc#701257).- Make use of the actual library version as part of the package name on post-11.3 systems only.- Fix winbind internal error; (bso#7636); (bnc#659424).- Improve ctdb vacuuming performance with use of SCHEDULE_FOR_DELETION; (bnc#705170).- Specify nmbdsocketdir at configure time; (bnc#700953).- Build the tdb, talloc, and tevent libraries ahead of anything else.- Update to 3.6.0rc2. + BUG 6911: Fix Kerberos authentication from Vista to Samba. + BUG 8166: Don't lockout users when offline. + BUG 8200: Add support for multiple writeable ldap idmap domains. + BUG 8148: Default to protocol version 2 for SMB Traffic Analyzer. + BUG 7054: Fix X account flag when "pwdlastset" is "0". + BUG 8144: Fix setting timestamp when touching files with CIFS clients. + BUG 8153: Fix setting up getaddrinfo on IPv6-only machines. + BUG 8156: Fix 'net ads join' using the user's Kerberos ticket. + BUG 8157: Fix parsing a cups printcap file. + BUG 8175: Fix smbd deadlock. + BUG 8189: Support shadow copy display over SMB2. + BUG 8197: Winbind does not properly detect when a DC connection is dead. + BUG 8203: Winbind needs to reset the DC connection if an RPC times out.- Make cupsaddsmb fill printers location; (bso#8132); (bnc#698209).- Add "winbind max clients" parameter to remove 200-client limit; (bnc#697461).- Disable logon cache for password lockout consistency when running in a cluster; (bnc#694836).- Fix logon of AD users with many group memberships; (bso#6911); (bnc#657026).- Don't lockout users while offline; (bso#8166); (bnc#692607).- Update to 3.6.0rc1. + BUG 8111: CIFS VFS: Fix unexpected error on SMB posix open. + BUG 8112: POSIX extension opens of a directory are denied with EISDIR. + BUG 8132: Fix filling printers location field when using cups. + Remove fstrings from client struct. + BUGFIX when converting from safe_strcpy to strlcpy. + Fix off-by-one calculations with strlcpy. + Ensure we always write the correct incoming mid into the share mode table entries. + Fix the SMB2 oplock showstopper. + Convert user-specified domain to uppercase in libsmb. + Fix Coverity CID #2302: FORWARD_NULL. + Fix cups_pull_comment_location(). + Fix double free of cups request. + Make cups_pull_comment_location() work again. + Fix potential crash bug in display_print_driver3(). + Properly clean up in pthreadpool_init in case of failure. + Make plaintext session setup async. + Reduce fd load in Winbind children. + Avoid a potential 100% CPU loop in Winbind. + Tune broadcast namequeries for unique names. + Properly deal with exited winbind children. + Fix dup_smb2_vec3. + Fix return check in nss_wins.- Fix to renew the kerberos ticket in samba after expiry; (bnc#669949).- Fix a 100% CPU loop when ctdbd dies during a traverse; (bnc#693945).- Make dhcpcd hook BOOTPROTO check cover dhcp6 too; (bnc#691969).- Handling of large (> 256 bytes) ntlmv2 blobs in winbind; (bnc#529946).- Package static libraries with 0644 permissions.- Add Requires libtalloc-devel to libldb-devel and libtevent-devel.- Rename libldb0 to libldb1 as 1 is the current major version of the library. - Add libldb1 and libtevent0 to baselibs.conf.- Don't call the suse_update_config macro before building lib ldb and tevent.- Update to 3.6.0pre3. + Listen on IPv6 addresses with IPV6_ONLY; (bso#7383). + Fix wrong output in 'smbget'; (bso#8066). + "inherit owner = yes" doesn't interact correctly with vfs_acl_xattr or vfs_acl_tdb module; (bso#8083). + rpccli_samr_chng_pswd_auth_crap segfaults if any input blobs are null; (bso#8088). + setpwent() actually does endpwent() and vice versa on FreeBSD; (bso#8099). + Fix the build of 'smbget' on HP NonStop; (bso#8106). + Fix build of tdb2. + Correctly detect and deny symlinks anywhere in a path (not just the last component) if "follow symlinks = no". + Fix timeout in rpc_pipe_open_tcp_port(). + Fix the build of "--with-profiling-data". + Fix Coverity IDs 986, 1340, 2047, 2299, 2307, 2325, 2335, 2336, 2470, 2471, 2478. + nsswitch: Add 'wbinfo --lookup-sids'. + nsswitch: Add 'wbinfo --sids-to-unix-ids'. + Fix smbd with the async echo responder. + Fix the build of vfs_gpfs.c. + Add a 10-second timeout for the 445 or netbios connection to a DC. + Many pthreadpool fixes. + Fix transaction recovery area for converted tdbs.- Add PreReq permissions to the krb-printing package.- Remove _libdir ldb and tevent from file list. - Explicitly state not to bundle talloc or tdb while ldb and tevent build.- Always use the actual library version as part of the package name. - Exclude shared python modules.- Fix printing from Windows 7 clients; (bso#7567); (bnc#687535).- Update pidl and always compile IDL at build time; (bnc#688810).- Update to 3.6.0pre2. + ID Mapping changes. + Implement SMB2 support. + Add an Endpoint Mapper daemon. + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Quota only shown when logged as root; (bso#7080). + Fix printing from Windows 7; (bso#7567). + Retry DNS updates when connection to one nameserver has failed; (bso#7690). + Unlink may unlink wrong file when hardlinks are involved; (bso#7863). + Fix 'nmbd --port'; (bso#7875). + cmd_spoolss_deletedriver() returned without checking all architectures; (bso#7880). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix cups pcap reload with no printers; (bso#7915). + Fix bug in chain_reply; (bso#7917). + Fix problems with "kernel oplocks" option set to "no"; (bso#7928). + Fall back for utimes calls; (bso#7940). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let winbind try to use samlogon validation level 6; (bso#7945). + Sgid bit lost on folder rename; (bso#7996). + Fix getting username in 'net rap session'; (bso#8009). + Fix inode generation so nautilus can count total dir size correctly; (bso#8010). + Use jenkins hash for str_checksum; (bso#8010). + Add explicit configure option whether or not to enable dmapi support; (bso#8033). + Fix smbclient segfault with Cyrillic netbios names; (bso#8040). + Fix file creation on OS/X; (bso#8042). + Add "--option" to 'testparm'. + Fix crash bug on smbd shutdown when using FOPENDIR(). + Ensure we don't return an incorrect access mask. + Fix bug against the new Mac client. + Fix leak in error path. + Fix error where Windows client spoolss returns WERR_INVALID_DATA. + Fix a segfault in the krb5 locator plugin. + Enable sharesec for registry shares. + Fix memory leak in "security=share" and "force user". + Add "net idmap check", a check and repair tool for the id mapping database. + Add new 'net idmap delete' command. + Fix segfault on missing input file in 'net idmap restore'. + Fix 'net usersidlist' not to skip every other user. + Fix potential crash bug in spoolss_PrinterEnumValues push path. + Internal restructuring. + Don't wipe out all printer drivers when only one should be deleted. + Fix winbindd_dual_pam_auth_samlogon() for NT4 domains. + Fix memory leak in print_cups.c. + Remove duplicate cups response processing code. + Follow force user/group for driver IO. + Initiate pcap reload from parent smbd. + Reload shares after pcap cache fill. + Fix numerous Coverity IDs (2041 and others). + Fix a memory leak in check_sam_security_info3. + Fix a segfault in the nss wrapper when libnss_winbind.so is not loadable. + Make "net sam list [users|workstations]" list only the right things. + Fix a potential memleak in secrets_fetch_trusted_domain_password. + Use the right credentials in check_netlogond_security. + Add support for AF_NETLINK addr notifications. + Fork multiple Winbind children per domain. + Fix a deadlock between smbd and ctdbd. + Add 'wbinfo --dc-info'. + Make "nmbd socket dir" configurable. + Fixed valgrind errors. + Fix a memleak in receive_getdc_response. + Don't grant SEC_STD_DELETE always to the owner of a file. + Fix segfaults on addrchange errors in Winbind. + Allow machine accounts as members in groupdb. + Add IPv6 support for the endpoint mapper. + Free unused memory in the rpc server. + Fix possible segfaults in svcctl server. + Fix possible segfault with client_id in rpc server. + Add a 'svcctl shutdown' function to rpc server. + Fix a resource leak in net_afs. + Fix a resource leak in smbta-util. + Fix possible resource leak in net_usershare. + Fix possible resource leak in 'smbget'. + Fix possible resource leak in 'smbfilter'. + Fix a possible null pointer dereference in smbd. + Ensure we send the direct levelII oplock break to the correct fid. + Fix private libdir and codepages paths. - Add RFC 3454 to the vendor files.- Fix idmap_tdb for big-endian systems such as ppc and s390; (bso#6901); (bnc#675978).- Fix smbclient -M NT_STATUS_PIPE_BROKEN failure; (bso#7635); (bnc#681913).- Replace jobs by _smp_mflags macro while calling make on post-11.4 systems.- Don't crash when publishing a single printer; (bnc#643119).- Carry error status in printer list IPC message, do not refresh printers if cups is unavailable; (bso#7994); (bnc#675478).- Define the libwbclient packages ahead of packages with a different version.- Use %_smp_mflags for parallel building.- Update to 3.5.8. + Fix Winbind crash bug when no DC is available; (bso#7730). + Fix finding users on domain members; (bso#7743). + Fix memory leaks in Winbind; (bso#7879). + Fix printing with Windows 7 clients; (bso#7567). + Fix 'testparm' return code when EOF in encountered in param name; (bso#3185). + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Fix "Your Password expires today" message for users of trusted domains; (bso#7066). + Fix maintaining of users' groups via UsrMgr; (bso#7262). + Fix 'net ads dns register' in Windows 2008 R2 domains; (bso#7356). + Raise debug level for "reduce_name: couldn't get realpath" messages; (bso#7409). + Fix updating the time on close in vfs_gpfs; (bso#7498). + Fix "log=>ndr_pull_error" in 'wbinfo -u' and 'wbinfo -g'; (bso#7594). + Handle Windows 9x adddriver calls without config file; (bso#7641). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix memory leak in the netapi routines; (bso#7665). + Store unmodified copies of security descriptors in acl_xattr and acl_tdb modules; (bso#7716). + Fix incorrect unix mode_t caused by invalid client DOS attributes on create; (bso#7733). + Apply appropriate create masks when creating files with "inherit ACLs" set to true; (bso#7734). + Fix "dfree cache time" parameter; (bso#7744). + Fix a getgrent crash with many groups; (bso#7774). + Fix requesting lookups for BUILTIN sids; (bso#7777). + Fix smbd crash caused by expand_msdfs; (bso#7779). + Fix atime limit; (bso#7785). + vfs_scannedonly: Switch from mtime to ctime which is more reliable; (bso#7789). + Fix copying files from a SMB share using Gnome vfs and SMB signing; (bso#7791). + Make Winbind recover from a signing error; (bso#7800). + ACL inheritance cannot be disabled in vfs_acl_xattr/vfs_acl_tdb; (bso#7812). + Fix "force group" with ntlmssp guest session setup; (bso#7817). + vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835). + Make WINBINDD_LOOKUPRIDS asking the right domain; (bso#7841). + Make WINBINDD_LOOKUPRIDS returning the domain name; (bso#7842). + Expand the local SAMs aliases; (bso#7843). + ntlm_auth: Support clients which offer a spnego mechs we don't support; (bso#7855). + Fix 'net ads dns register' in cluster setups; (bso#7871). + Fix 'nmbd --port'; (bso#7875). + Make 'rpcclient deldriver' delete drivers for all architectures; (bso#7880). + Fix flaky Winbind against Windows 2008; (bso#7881). + Fix SMB session setups with Kerberos against some closed source SMB servers; (bso#7883). + Fix stale lock in open_file_fchmod(); (bso#7892). + Fix sporadic Winbind panic in rpc query_user_list; (bso#7894). + Don't set SAMR_FIELD_FULL_NAME if we just want to set the account name; (bso#7896). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix connections from WinCE; (bso#7917). + Fix opening MS Powerpoint files; (bso#7940). + Fix endless loops caused by inotify; (bso#7942). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let Winbind try to use samlogon validation level 6; (bso#7945). + Revalidate the pathname once re-constructed from a root fsp; (bso#7950).- Require a particular library version even if the major version is part of the package name. Using the same major version does not guarantee forward compatibility.- Fix a fd-leak in libwbclient at dlclose-time; (bso#7684); (bnc#668773).- Update to 3.5.7 + Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Disable separate build of samba-doc for post-11.1 systems.- Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Increase the log level for missing PIDs on SIGCHLD, printcap child processes are not added to the children PID list; (bnc#666460).- Do not require a particular library version if the major version is part of the package name.- Use the actual version numbers of the ldb, talloc, tdb, and tevent libraries on post-11.3 systems.- Abide by print$ share 'force user' & 'force group' settings when handling AddprinterDriver and DeletePrinterDriver requests; (bso#7921); (bnc#653353).- Remove pcap_cache_loaded asserts from (re)load_printers. pcap_cache_loaded() returns false if the pcap cache contains no printer entries. correct call ordering is already enforced. (bso#7836); (bnc#625936).- No longer force activation of the cifs service on post-11.3 systems. - Add X-UnitedLinux-Default-Enabled to the cifs init script on pre-11.4 systems. - Move the cifs init script nfs dependencies from Required to Should.- Recommend to install samba-krb-printing from samba-winbind on post-10.3 systems; (bnc#661845).- Fix error paths in cups_async_callback(), an empty cups printer list should not be treated as an error; (bnc#661842).- Abide by printcap cache time, reload parent smbd pcap cache on expiry; (bso#7836); (bnc#625936).- Fix race in cups async printer services reload; (bso#7836); (bnc#625936).- Don't tweak with baselibs.conf during %post if not present; (bnc#652620).- Don't make use of baselibs.conf on SUSE Linux Enterprise 10; (bnc#652620).- Don't use --tmpdir as this option isn't known by mktemp of SUSE Linux Enterprise 10; (bnc#652620).- vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835).- Replace Requires samba-client by samba-gplv3-client in the gplv3 packages; (bnc#652620).- Fix Dolphin SMB share IO with SMB signing enabled; (bso#7791); (bnc#656112).- Add Conflicts to the samba-gplv3 main, client, doc, krb-printing, winbind, client-gplv2, and doc-gplv2 packages; (bnc#652620).- Add Provides samba-client-gplv2 and samba-doc-gplv2 to pre-3.2 versions; (bnc#652620).- Obsolete samba-client-gplv2 and samba-doc-gplv2; (bnc#652620).- Remove Provides samba-client:/usr/sbin/winbindd from the samba-gplv3-winbind package to avoide an accidental install trigger; (bnc#652620).- Add Provides samba-client to the samba-gplv3-client package; (bnc#652620).- Remove all Obsoletes from the samba-gplv3 packages and only keep the Provides samba; (bnc#652620).- Add fitting Conflicts to all samba-gplv3 packages; (bnc#652620).- Reduce unnecessary ldap round trips and eliminate invalid DN messages; (bnc#654719).- Exclude cifs-mount and ldapsmb from the samba-gplv3 build of SUSE Linux Enterprise 10 SP 3 and 4.- Add the _build_arch at the end of the vendor version suffix.- Provide and Obsolete samba-gplv3 to replace potentially installed packages.- Change package base name to samba-gplv3 for SUSE Linux Enterprise 10 SP 4. - Do not package libsmbclient and libsmbsharemodes.- Update to 3.5.6 + Fix auto printers with registry config; (bso#7280); (bnc#617153). + Fix SPNEGO auth when contacting Win7 system using Microsoft Live Sign-in Assistant; (bso#7577). + Fix 'net idmap restore' setting HWM to avoid duplicates; (bso#7578). + Fix "admin users" when using vfs_acl_xattr; (bso#7581). + Fix using cached credentials in ntlm_auth; (bso#7589). + Fix Winbind offline login; (bso#7590). + Fix Winbind internal error; (bso#7636). + Fix mknod/mkfifo failing with "No such file or directory"; (bso#7651). + Fix smbd changing mode of files on rename; (bso#7693). + Fix crash bug with invalid SPNEGO token; (bso#7694). + Fix smbd panic on invalid NetBIOS session request; (bso#7698). + Fix smbd crash caused by "%D" in "printer admin"; (bso#7541). + Fix 'smbclient -M'; (bso#7635). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix crash bug in rpcclient; (bso#7688). + Fix file corruption when setting Samba "write wache wize"; (bso#7715).- Let startproc wait for nmb, smb and winbind pid files getting created on post-11.1 systems; (bnc#520036).- Include the reviewed french translation for pam_winbind; (bnc#499233).- Fix smbd crash with CUPS printers and no [printers] share defined; (bso#7297); (bnc#637755).- Fix printing from 64-bit windows clients; (bso#6888); (bnc#640870).- Fix baselibs.conf for libtalloc.- Fix buffer overflow in sid_parse() to correctly check the input lengths when reading a binary representation of a Windows Security ID (SID); CVE-2010-3069; (bso#7669); (bnc#637218).- Use cached ntlm password in libsmbclient. Prevent lockouts when kerberos tickets are lost; (bnc#602418); (bnc#606304).- Add a dependency on nfs to the smbfs/ cifs init scripts as they require the en_US locale and /usr might be on NFS.- Complete fix for trusts with Windows 2008R2 DCs.- Fix authentication dialogs when connecting to older systems; (bnc#632055).- Adjust position of conditional ldapsmb %package and %files definition.- Create the /var/run/samba directory on the fly and package it as %ghost.- Fix preexec scripts; (bso#7104); (bnc#632852).- Add missing netapi, smbclient, smbsharemodes, talloc, tevent, and wbclient pkgconfig files and BuildRequire pkgconfig; (bnc#632770).- BuildRequire python-devel for post-9.3 systems.- Only create precompiled headers for post-10.2 systems. - Remove mkinitrd scriptlets.- Add vfs_crossrename man page. - Call make basic and remove conditional proto target. - Increase libtevent version to 0.9.9. - Remove wbc_async header from the file list. - Remove remaining cifs-mount pieces from the spec file.- Fix printers not auto loading with registry config; (bso#7280); (bnc#617153).- Update to 3.6.0pre1. + SMB2 support is fully functional despite managing quota using the Microsoft management tools. + Internal Winbind passdb changes to use samr and lsa rpc pipe to get local user and group information. + The spoolss and the old RAP printing code have been completely overhauled and refactored. + The SMB Traffic Analyzer (SMBTA) VFS module got added.- Intilize workgroup of nmblookup as empty string.- Fix net ads join when using parent domain users; (bso#6364); (bnc#630812).- cifs: do not restart during dhcp lease renewal when IPaddress remains the same; (bnc#573246).- Fix "Too many open files" when trying to access large number of files; (bso#6837); (bnc#619787).- Update to 3.5.4. + Fix smbd crash when sambaLMPassword and sambaNTPassword entries missing from ldap (bug #7448). + Fix init_sam_from_ldap storing group in sid2uid cache (bug #7507). + Allow previous password to be stored and use it to check tickets; (bso#7099). + Make ea data checks identical for trans2open and trans2mkdir; (bso#7188). + Fix editing users' groups via UsrMgr; (bso#7262). + Fix Winbind over IPv6; (bso#7341). + Samba sends "raw" inode number as uniqueid with unix extensions; (bso#7410). + Fix printing large formats; (bso#7423). + Fix spnego returning incorrect mechListMIC string; (bso#7449). + Fix some crash bugs and missing error codes in AddDriver paths; (bso#7459). + Fix crash bug in _samr_QueryUserInfo{2} level 18; (bso#7479). + Fix 'not a string literal' warning in netdomjoin-gui; (bso#7500). + Fix calculation of st_blocks in vfs_streams_xattr; (bso#7503). + Fix numerous build issues; (bso#7504). + Fix session setup from linux kernel cifs clients with "sec=ntlmv2"; (bso#7517).- Remove all provides and obsoletes samba3 from the spec file. Packages with this base name have not been offered as part of a product.- Fix a NULL pointer dereference in smbd of the 3.4 code base; CVE-2010-1635; (bso#7229); (bnc#605935).- Address possible buffer overrun in chain_reply code of pre-3.4 versions; CVE-2010-2063; (bso#7494); (bnc#611927).- Update of the SMB Traffic Analyzer v2 VFS module- Fix trusts with Windows 2008R2 DCs; (bnc#613459); (bnc#599873); (bnc#592198); (bso#6697).- Update to 3.5.3. + Fix MS-DFS functionality; (bso#7339). + Fix a Winbind crash when scanning trusts; (bso#7389). + Fix problems with SIGCHLD handling in Winbind; (bso#7317). + Add replacement for IPV6_V6ONLY on linux systems with broken headers; (bso#7196). + Fix cups encryption setting; (bso#7263). + Fix exporting printers via 'cupsaddsmb' command; (bso#7277). + Fix SMB job IDs in CUPS job names; (bso#7288). + Fix segfault in mount.cifs; (bso#7315). + Make TIME_T_MAX defines consistent; (bso#7352). + Re-fix a bug with smbd serving a windows terminal server; (bso#7357). + Display an error on 'net conf import' failures; (bso#7378). + Fix bitmap leak in dptr_Close; (bso#7384). + Fix rename problems with full_audit VFS module; (bso#7398). + Fix setting of passwords via 'net rpc user password' command; (bso#7417). + Fix 'net rpc printer list' command; (bso#7418). + Rename mod_name to module_name; (bso#7421). - Fix unnecessary traversing winbindd_cache.tdb in SIGHUP handler. - Added EN ISO 216, A0 and A1 to builtin forms; (bso#7423). - Winbind not working over IPv6; (bso#7341).- Honor "interfaces" list in net ad dns register; (bnc#606947).- Exclude the RPM release from the vendor tag for openSUSE Factory; (bnc#604049).- Enable the build of the idmap tdb2 module; (bnc#600822).- BuildRequire keyutils-libs-devel for Fedora and post-RHEL4.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- Add "net conf import" error messages; (bso#7378, bnc#598189).- Define cups_lib_dir %{_prefix}/lib/cups for post-11.2 systems; (bnc#575544).- Update to 3.5.2. + Fix smbd segfaults in _netr_SamLogon for clients sending null domain; (bso#7237). + Fix smbd segfaults in "waiting for connections" message; (bso#7251). + Fix an uninitialized variable read in smbd; (bso#7254); (bnc#605935); CVE-2010-1642. + Fix a memleak in Winbind; (bso#7278). + Fix Winbind reconnection to it's own domain; (bso#7295). + Fix segfault if hide files or veto files has no ".AppleDouble"; (bso#1206). + Fix parsing of the gecos field; (bso#5198). + Fix several printing issues; (bso#6727). + Fix valgrind warning; (bso#6814). + Fix race condition in mount.cifs that allows user to replace mountpoint with a symlink; (bso#6853). + Fix bug in vfs_scannedonly rmdir implementation; (bso#7075). + Fix handling of bad server data returns in client rpc_transport; (bso#7159). + Never mark external domains as internal in Winbind; (bso#7170). + Fix access by multi-threaded applications; (bso#7202). + Fix 'net share' command; (bso#7203). + Fix DN parsing name was always null; (bso#7204). + Signals are processed twice in child; (bso#7206). + Fix returning of group members with 'getent group'; (bso#7212). + Fix the build of net_afs.c with --fake-kaserver=yes; (bso#7216). + Make Winbind logs more verbose for troubleshooting; (bso#7225). + Fix a NULL pointer dereference in smbd; CVE-2010-1635; (bso#7229); (bnc#605935). + Fix automatic building of vfs_tsmsm if gpfs and dmapi are present; (bso#7231). + Fix race conditions in CTDB persistent transactions; (bso#7232). + Symlink delete fails but incorrectly reports success to client; (bso#7234). + Fix "printer admin" functionality; (bso#7255). + Fix value-needed calculation in_spoolss_EnumPrinterData(); (bso#7256). + Fix _winreg_QueryValue crash bugs and implement Windows behavior; (bso#7258). + Fix job management commands for CUPS queues; (bso#7269). + Fix smbd segfault if using vfs_acl_tdb; (bso#7283). + Fix core dump in 'ntlm_auth' with "gss-spnego" helper; (bso#7290). + Fix smbd crashes with CUPS printers and no [printers] share defined; (bso#7297). + Fix DOS attribute inconsistency with MS Office; (bso#7310). + Many disconnecting clients render clustered Samba unusuable for some time; (bso#7312). + Make 'net conf addshare' atomic; (bso#7313). + Eliminate race condition in creating/scanning sorted subkeys in the registry backend; (bso#7314). + Winbind possibly segfaults when trying a trusted domain without inbound trust; (bso#7316).- Add SMB Traffic Analyzer v2 VFS module.- Document "wide links" defaults to "no" in the smb.conf man page for versions pre-3.4.6; (bnc#577868).- Fix workgroup enumeration, for client printer and file share selection; (bso#6880); (bnc#586215).- Fix tdb validation for offline auth; (bnc#587014).- Fix "printer admin" functionality; (bso#7255).- An uninitialized variable read could cause an smbd crash; (bso#7254); (bnc#605935); CVE-2010-1642.- Ensure to have a valid talloc stackframe; (bso#7251).- _netr_SamLogon segfaults for clients sending NULL domain; (bso#7237).- Merge missing pam_winbind message translations; (bnc#499233).- Remove cifs-mount subpackage for post-11.2 systems as the tools are now part of the independent cifs-utils package.- Fix join of Windows 2008 domains; (bnc#567013).- Update to 3.5.1 and 3.4.7. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222); (bnc#586683).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; CVE-2010-0926; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7; (bnc#619787). + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7; (bnc#619787). + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7; (bnc#619787). + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build./bin/sh/sbin/ldconfigbuild84 1533314470  !"#$%&'()*+,4.7.8+git.62.c1052da2b4e-lp150.3.3.14.7.8+git.62.c1052da2b4e-lp150.3.3.1acl.soaclread.soanr.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soextended_dn_in.soextended_dn_out.soextended_dn_store.soildap.soinstancetype.solazy_commit.soldbsamba_extensions.solinked_attributes.solocal_password.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosimple_dn.sosimple_ldap_map.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:8543/openSUSE_Leap_15.0_Update/0888bb83d8eeea1972b4b25e13a26782-samba.openSUSE_Leap_15.0_Updatecpioxz5x86_64-suse-linux  !"#$%&'()*+ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4359012e97156440ec8a301a2ddd6eaa4698b65e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=56749ca7fb1719b330ca7486c13bc4c5a8eec9fc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=32e6576e10b97738e63bf25d4f804a3b1cc130ac, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ec8cde2da5ef27555691f4e9cd94849442632b45, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=567a8bb6db3d1a8e3fe5795ad49e610792f771c4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c517235d44bf81d85df77453c2e081d4123ad5dc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=92413925235c8c79f99cb420ed2a49352baf3414, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bd6c10a1aa2947688970c714e4dc1d8912518447, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9f342bc8c796911fe3340671df368912860ddaf3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b311b79f51046b6360c8a14bacdfdef562abe24f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3956c1aa4b8ad28027e85e895d7e7b59f2bac653, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=be363e9a6caf6bc061f0dd390627afa90fc2f9bc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=87a72faee69387b527145a5aebb7fce26bd13383, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=07399672a687cb8fa4b17ecc743e9911f30c649d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8635384154b99b0e23528bebbeb9a9339cb0444f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8d9c5b591d017bac027d43f5e02aba40d648bc0f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=829160b4615f3f61836603a11159eafe53236e8d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4f7429d544405e1f3560e380e926ad1661c66cf5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5a578009c16a64f9833e11117f3638f186ab1d0b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7402b1a6e5ec77723a693918ee3067deb3c54494, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=37af69fdf464260806fb39e90a39f684a1a52e3f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=90885e4bceb26bbdebdd57b46adbbf5db27fdd4d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2d462af5e91009d0662281d2b94817ec41993b85, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7567fd77a8d93d206c3d12485af3247d72ff190d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7716e9947ee0478872aeb43d6e936af336f3e588, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7dd15f2da2cd106906332ed4b53e02f86bef3430, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e115636f47eb54d6b9d6723d3a79dc5e8106202b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8240e31db603aab6f0a39c9c3ccad8c4ce5e0c6a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c6b0fadb1034ad1622835e660b64e0032a1b3a3a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bdb276256a6449af1fc3de67508e98917c17bdba, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d3675781d1a198e27415830d3d4323ed1d792b41, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=deff983b26ad90986e28c1c3e3ccdfd03cb9fb7d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bc77f257b39954540e467c429648a372781c5fc1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5af451b1d757573db8d5b023bca35adc068b343b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cfc85d15545f2a0f579bf8265c2173050b840811, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3e4a59368efa973294704cbe5d7356045f3da9dc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f36fe17399569ec7caffa47c446183b499cf518b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=47d90f9600fb2a16ce08277897fe91605781f695, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fc912a3a216691bfb322c9eaa9d10f3d429e465c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=001444baa25d07ca883d8b7cf278f408c9e3429a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ca3446e406bee5d05ecabb01b82a3bded0127fa8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cf8f17e0a686b8d1c5a48457c3bf433b2e67d383, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a5fa3aa82601c16e009b883ed93e68b332028002, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0ed75509292396b311781f89f731445bff1bcafe, stripped4@Xp(4@Qao 8IWhq%4   2! , !   R,RRWR]RSRgRR RER?R_R*R0R.R R\RR+RRR^RRVR>RDR)R-RfRRYRERWR]R_RgRR R?R R1R7R0R.RRXR\R^RVR>RDR-RfRRgR]R.R0R?R RR\R>R-RfRR]R_RYRSR RgRER RR?R/R6R0R.RRDRXR\R^R>RRR-RfRR]R_RSRgRR RER?RAR R4R7R0R.RR\R^R@R>RDRRR-RfRRWRmRRoRURSRgRR RCR?R R0R.RRBRRRTRVR>RlRRRR-RfRnRRR R R]R_RgR0R.RR\R^R-RfRR_R R RRgR?R8R5R0R1R.RR^R>R-RfRR]RYR RgRER_R?R RR8R0R.R\RRDR^R>RXR-RfRRR R]RgR_R?R0R.R\R^R>R-RfRRRRoRQR]RgR0R.RMRRLRPRR\RR-RfRnRRR R R_R0R.RR^R-RRR R R0R.RR-RR_RRKRaR(RWRQRgR2R3R0R.R?RR RR]RSRR\R^RPRVR>R'RRR`R-RfRJRR]RERSRgR?R_R RRRRR-RfRRR RERgR_R0R.RDR^R-RfRRR RgR_RSR0R.R^RRR-RfRR RgR]R?R RR0R1R.R_R\RR^R>R-RfRR RgR]R?R RRR0R1R.R\RR>R-RfRR R_RERgR RR.R0RRDR^R-RfRRERUR_RSRgRR RYR?R]R RAR0R.R\R^RRRR@RTR>RXRDR-RfRRMRiR?RWRSRgR RR RkR]R R4R3R;R0R.RLRR\RVR>RRRhR-RfRjRR*R&RMRRRYRERORRqRUR,RR_RSRgRAR0R.R R R RR]RR RWRLRNRRR@RR\R^RTRVR+RXRDRRRpRRR%R)R-RfRRR RRgR.R0R-RfRRWRURSR RR R?R]R RARgR4RRRR-RfRR]R RRgR.R0R?R\R>R-RfRRmRYR"R]RRoRURSR[RgRR R_RCR RER?R RWRR1R9R0R.RBRRRXR\R^RTRVR>RDRlRR!R RZRRR-RfRnRReR R RRgRERYR]R4R.RdRDRXR\R-RfRRR RgR RWR_R.R0RR^RVR-RfRR R?RgRQR]R RR.R0R3RR\R>RPR-RfRRR RgR0R.R3R-RfRRR&R$RMRERWRSRgRYR?R RR]R1R0R.R R_RLRR^RXRDR\RRVR>R#RRR%R-RfRRSRUR_RgR?R RR0R.R^RTR>RRR-RfRRWR]R RSRiR0R.RgR?RkR RRR\RVR>RRRhR-RfRjRR_R RcR RRgR.R0RRRbRR^R-RfRRR R RgR]R0R.R\RR-RfRRR R RgR0R.RR-RfRR_R]R?R RRERgR0R4R.R^RDR>R\R-RfRRR RgR R0R.RR-RfRRR RgR R0R.RR-RfRRR RgR R$R_R?R/R0R.RR^R#R>R-RfRRR RRgRQR R]R.R0R\RRRPRR-RfRRFR RRR RgR_R0R4R.R^RDR-RfRRR RWRIRgR.RHRVR-RfRgۏ_Nn/IŮǦutf-85568144f54332c3198cd55d1dc4f13af2e6f3afef85613ce020b2afaccc5f5c2?7zXZ !t/U] crv9uRڳ{%ʭS&N;.ذ1c7`.d^&=笁Rh]_L¶eI페 *99F_yQm`un R6q,%'$vY`Ea{[r(n/ ܽ SNг/:bdrIym,%gӚ1`U>Q)a#L&lH?o oSy_!ldVC'ٮÀ+)æm:2w#5L&$-?OHj% +Kz32J`з ƻ)GŰ&?^p]t4-yS=?i1+OSQsN~BA4l*@w 75nN4s]zBpr(g&PЪ0Wvv՚s3I겯 GFtЎ6j8ַR50q!N  00C'94cNvȜt0)zA;Oor׻FQ)AÆ b9ten^g#oQOʣ[dPdYDYlW */C?|g g+ʿ[iw,i(&bL r t 3~s*( nΒ W,з~;w ݰ,{+l5گZc[TԇD̍i KMh'oWMf3Iv6/ "@2J*DeM D>9v7<|~2PvSk5nf5kPA EI[7F%]i/A Y{e!Ho l(zĵ@=\c31]rs"n2ߴPi @](IkHx$noqvؘ -AƸ+mJ)v4{߳8N'՚7j8"-\D]޹k[elb^|EPK 83pg \+՜Z:xLenE:+f><ڱ]a%8[m?`_~:7O; _ܚ7ŕؼLB2{m؏{ۡͭIAΜU"0fὭvRkљG*@޾ V6pdʣcIw]giN6jO]DN2> '~_ D>p޵hEbL'B^K_(mA <'6W(kjxR u׊F)ۢPH^ԙe*#8p)GYuE)L ,Pt[ KѠaQY 9\b FyhH3Q ,͹lfYD3v=؝2@nUŞlC1?YaFrV]Q,^.Cׂ !zɖM'+] ?;;nX- ¼_ xz)+V(ce} {IŬiv +jy>}' s3 Sw_RW{Lb*j5kg*# x*]_q)3{8gы:=zJg,uOQT[9/Mcހ{Ӎ}ͨFӹdޟ ]z.cӔ[`Mu4n·a:Bg>3 ߈pfۼ tAef5o3Yޮ> U+@Z3C%H) J9{w M̽D4>u7`+i:G8F1:21V*L9o?H&"%u{Z4v㒨9Xf! ,z(Z,[q;xC노4 }1jRLJ)-^ I"b; pv7N3m>Z\EDhcA2'XvwWڒ8b1 /]ѭaս1|6>-gO[7zBe:5|HuBӹ@\%ҵ#2O؅F 6,3-X8tl7S?^yy\;F0ó Jt?,/+1ۭl X>mx7ɟE]p+̡_BYXYn+8^DiiwdnhrRMG8{]J iia0P8dPFJGd tEN@oo`}ײ ]am-Ȃ`ȷv5jǽ`2PF7DdD\}nrKݫʓ>3Fa2K-g'/u#(͕j)26o:mB"ŗ>G%]VL\P,GJ&Y(MYxZkXE Jtdy_,dR|w6z.@CxF*uԡo5T8,R j dFRabatd:W)'G{>g*2}= }J3xZu-)~{lD4hGtl*_k6KWg~>cޭ)ֱ`jUQMLEJgna7QkF1#]y=) q]r$<՟ Vrapa?A2H'L=G0Ь8@_JRFeZ>9j/k+q0G!ZCVy+ };]UfJ*)Q\cxjoH`~?MF4fģX '(GV&q"ջKLVTJDJ>.U)q[V˘'ӑ&I~qא(yRY!:AyN2Jd#"MuW#'1b"-t;$Rk=h'#$PBjR_y~]1Hmlj. ٞ0~qƛrH@{&@l shәFj0.s f59NIA:Xʻrh ރY-.xlTpz4u+!Z ,2^c/2 SXZ5HG"C+_␋2nnʰRYܿSi;޾Ő 9}J}6)d0snoWeH#wxW(QʘR} lH M*@c1dxwdhzHݤzu._ SQZ.:ޛ]%Q%aX #qO%4[cY vƧI tgzy zgR']w͉ Y4S؋}:ahZ!n^mO24B{M3CV ypJ{u3*wct b'@43!c~3]І$yo ^ vAX(fMǒĥyn{bX>`><*%VB $z+-*|?-ek=t.H?J,zȷ|2~sMJ Omu2Q[TÑ"}`%P[kɶ'!4&Z\ZUAφ6{).(Fh)M ȩ7::6<a[iI煇X1vLЫŠqTP'h۞AI( #e K0A:{P?3G!6SF!5K9b)G0D/ I.dh6^徢GvdPollVQܓ´~M8_`0Y3T!BhC^9Ma) @"VbQZWfr6'>").iP(Yu;ݩI4+;m灋g*L5fc袅4!EkX<;G Ŭ.O:\^aγΛ 7ݓ\Av&]ו̺/&< U7^΋dW[~qt,/*i< JO0ukEb2c^G%9#'mhkѧ %C EB ?5.eYM`+Y,_ @jNޗS :mŇ}`TZ쌛KC N9ƌLn *9=eѵ`-J7= S|=-( ᣁFbL8QyN3Ӯe@_wJ9v][2t,[zH SUSvW]L7I+߁j8 ξމ'>XbM0(w^=-`_T7_V20 dh7ӸɺBlseD6 MK:/.?>Z'vpssD  Q16Ȳzq]Wޖk\^ "`:jD.}+P'"`2l:ğ{ݝizlhrA+ey[ fpdޱhj)SV=u6zHnuvQM;o=S)lIـLfqqe#Ar9*#gK֦6CJEحx6P.HO|C: THcUz)M9 WwXk9 2#/$G7;e ]xHC3w4XR^iCDPGi;3/75`;nONfKrE3euƇdV"3|6{w/"ݱpb[UZo8ӄS؄"LJ칋g R &ڦ?9ʯpfc4> *xoj qm,9hYm7dYz@)i|Ȃ>"&F"3Uc91oouE.~}#sԲ7 Q}zn: rC="F/"28-Q"z1AJ߲qS#Cbk"Z^4WbRM-_\$n38Q[$SS$( /ς&Bd'\ $fW=!ݙT$507U.rwrBtu%R 3DǸ_s-.@5%꣥ݛ\>~rUOڣ*ɕ>IDž,7PߋGmY]aҾٵo$OOp8$< gmSd9cT RR">^kJah$ùx^9ۿdXfNj?R4 [6 f ޷.IW˔N_%ש;7ZHոoawzd!@U(Y4 I ;yii`ս=V¾8`۔`9Cʍ :AZWXT0)u+竛%z22d QViu$_XNY$\SFqk,^Li6-ZQwߪ]Q 4̓䝣yFS2KJ#諸n幍Ɉ\~ܪM~S^}.Bbs&uCZ)ڡLX[ys4Q*aJ=BS ہB9+(<JIA_Z';/̳M-E1_Qhm3!trc8nGO@hAnk+3ϲ씾 .^@&[sKh5gH=gLA }yڏCд`^c9I )D~,޷§WGիN #ˮ1l8^9T{NEv!k0ڌYM:R@rb'/ߵ??o /YKprG3%[xzMAuFtU\嗅w<-h%!2 05 KZ_gx17inҢOkybi!jE;E1]_Clß6J{j-BX.eҟCDzL/%jIB gT-F|.5J]:C A@a_tJ_lq1){F\[Cfo+sЍdAv3澛Pos"ɽ b+k_\7&`4w꬘|U4Y]W%23 3|yTD t;P^$7rUvS !\[USbȆ{WN,Y-DrH7ʤ pRnDr<g(e?Zۯ>-!Q[)7gڻEY" N,hZ$n}8JC:@Y vیBrΑiGf-)fX j8dO}ob`* 0584^:"X+[Z >\,]ܒU?Ξ3D7tԦd~P`ed6f Q094v\Μn8:rO2C=U))sK3l ̚ Rŕ945"iS Efq7s/^suʜgzK͏~<0QmM<ΧsWIe2Fs_pqx7x.;;~uhnd 7C!O~(%+뒑QI_W wu3 Z>.0 ٬fvoFJjwV2@"|NO 4Q-1X֨F IJ{LVTdz| y Bƛcɀ0y-7Bm6+鑮 )6 x*|y$8Y/ D>"q_/͠XŸb䂞KcDkBO^w Tw3Ws 0@ VoYY, zBVhÀDLu9.e_$UrJsnDχZfH&(6H9"hoUoaS"1!^sR3dSD0 SܡnizN2w+Jt='u9xyI`P5%YkeQLn+\)XR*h{C]Z$o@dB<PwtUƼVcұ|rU{Sdƽ{X:ϾgiPbUKAQ=؜JY׶aAћ/# 3LM; @.^%I>K5[E)bC @*D9d#n @ۻ]ScrsBENCaȳYK~gyXOsMd#'idRY5)f,`쿑/u^ẅc7ɰZ*ok$KE.B 6! tnea шˠ<#vPLP$Ms!8q?tCdg82u mBiv@t@xF7j[65 .cӨڈ>}oIEL/m'xo;+ 3 OPF[?QwM%J8Cn7ƽn}}zt2kEPU#ؿ`u(wH47IQ'hids]gQ׀ur9=3uQs3 o%#^AS!~t2 ˉoosi98ȿ-w4Jq1|HEڨ)t" $B's*l872bB)EydDNyhÏ n4b@' Hb g}몰xoQ”`§yjZauQnsG3`gzWynD^5*495؄nC4ax"k\ Jk}L#mdam7*Wh7+N,j0O2b+q|kqO2~Rd鋂\mžkb5ke5 ]&RKAt2*+mzz_qPPђaК!5V 4_]8QÚ$rhinMY}[AA~م^S0b:Aa:>33=Z}RZ8?}<bj:%%م1M_X\I׾s-vY,Qt-V׫~ 3H@(m=F> :CFHc\<#C8A-XvNT?1uI{ͼP0_=~v/<@R^KZљ}k'k<4~je$YC^!'2ypADUh~A~\س}.ak'BR?$LZ>!nB Mn^;.X5 dfMV\HsoҘ*JHwRڤڟ~;gD6̜9n#ՆF TMKe;^5رgw 1Y?9uDź!u:IJɌV[*|%x[ҭ 6m $;eRt?k2`2:i`XDS:J.Akj gʦLCWl2P&0zf'F]Ѫ򄉃{՚AtԈMnȩ4QbtD6-Aq&4Ť9 j<%&ξbC4qߠoTgïe݃|6yZQUS.A|_  5{®mlEu 1`3MΏ|W_g]vW |NUhN6ܲX-wU(_Y+~z: *n}098$N,ߋѦoh_T} PH%V '&̈́O# Lwi3ɫ,yP>jSsIP ̶.c_g*-딾U3M75[qaC:w3%ЀI[wU oAЙV]`żʹ95yD*ltPq8+S2F;%"`@fF}puܸljWl6s}O6r} (IgfG4=WŸa"7閛N`?})eSdW33fXRߚZ5`d lrATMPz ޿+NKmz=3'QCTp"g&&Yu\0'uӥ[Jv Jn tLoK.eq.W:)+2"y5x |o&.똔#^]vȆm:8NﺟdauKm<~:SB.; J 2C֖R%zt-hlڟf \ߩ;47f>aSJAgp)XqoWCiL<;h2E T@EV e&\ڢ1 "/6QldyPÑtN_N*?OdR-1:[2pl*hwq0>VTbЎ}ݞLfA}=CP$;Պ宰wpoUF&}U/-kkX~= qڥ$D[h-dx^ y Z:qP]uB^uvܜqe.STKi$Kc\sũjF,׊;;'%mDe[tc+8XpG8yET,֩bjJ~Q}8ZV#Xő|*^q.*˭3n*;py{;EXd5cI%+[]v}UkbLz#}RqYcڸ`felBs0q: GOx9:0VD4Q kNlIzqTi(?{/je#hxi ztL#2w Қ["ou mn/K"fC1~sJXN$&Ie)1}tR:EF.;8ġ[qz4z`%txfƬ]2:*KȈOjv:v@%PN-/)#&7sd]`dsyg'f7$ ؀p$QTkH Nȸ"ؒfCod'BnG'_urx3cGS.} VY:xNB{&ix!jd޸y_]m}z/DL8PȸrLDZE(e$tkS21sm*.ڂ|dE"ٖAn_8 CO=͔4 rhؼf$dP7aZh gdJ j٥(5C(=ǿŴC<F(_Mz"q0U.F 0INE`;*}5'AeT7k~gvH ]Lc:!d2^>XK˰ `pR1^bב>ݙ%;9wgS5[G|B͛3ͺ(O pYu%qwW}}S`! WԆ x{2Qt qhBw5ymtjvc.?7>p8Â`*MC<5jaXFM82 l 06/F,!|[9{=ў7c?,8]Oג8LLOV]Aej#j$blS9IONyӎcJ&dl}5!"#.cXPC3#`+v^bDjepv¿eL 9^:XR*)-6;;wgӍ ̔<~&GMaR،kkqm6rw ]ߵrHQBѬ"V@[ } oJqCQ O81Fvg4Hyڢl'pu7+& ,ѦFqU~S` {(:cgpt^g?c稜q9b?O_Xԯ"o#O=2{6%2R0JJx0u53k0oU uމ2&SJ%ҥFG(r`k>h_Yn h)S xn>+S-#0TqgpǮ{aPgf+sW]iy]A#}h>@CCdx&&u248]s\ƝЀ416\iAd;}iL[ek%$>t)pKa-OF]^JyQ|(\RrgI&mk^E$KP t 6.̯fgRuea8VdNA*^'R)=gwtUu*[Q!1}D_hCxINЗn=h?w4wa`S!g'b.{A9]\qOH]^p͐[{F7X^˝w8TEE ;ܶ•!~cL;,hK6vCe 7(o2u ޚmU]P\.TW-X yTSg_f8 5$2@qZGEN6uW CaġCq_hdr^(Ɏ@v4ĩ%*yJQo0s)t.d,S0D O.я0F8Mc :kd­)ڱ1:D]rui/z*#7,wK+n2$ v_&qiX;_P՚<uFIe°h6ė8Xz1,1U_҇ۆ^3F! ,Hf_ZBYEK0j!Tj jLfLh?2΅x /U:2@=NL܏KN>ZU~Y`ZՑO{_0 +Yd]y* ڎƺ͠ vu2jnʵ:LT>Ec(dGٸhM/Gy;};ll"=e.Ft6z2@#FM{;Jͨ X"9d]ZU}B|R 'uU7}KaL^ꎂ 8׍ -DyHLyIX[e <>w㯧YUb5]2 `j"@Eؾ!3Xao#c[ު"(fQ]";MY_dĵt6@1}*4P"pcsB2ncȞ_3#~wҌYlA[:lX_31ĒJrWtCk{;qa[ܼme. TN&yhzS)0Ӹao+u%j{ᕁwԷls_XRJ}@(day\~խ+=U|b#"籤4p4y)-+?1a.'C)a}_ ri yo /$?%>*fH ]91;#kykMK`+H/Ydb\J(Y^Lbm >*K?CdZ_ϚMw%-#Yo|]m S3'pQ oҕ ]ږ[d⹫ɓ5)혠06]֩/;Kfo|ta∩vWVŧ*"5ʮ +ò,2Lk "VjBSR9Ez eec8a5 cFNp!^SYcS%PH0KuFks=2pQ~(!ض ysK/Skz7tz@g2權JUFR]Xsiׄ EGdufJm>22Xf#PI|pV[۸ef~UB0#~™tQc.?h@O~z n`$as{Ș|M]𪘧_/B)C+W+-ɻT6׶F݈1"!7#\!|.̀&-4>ckfCjl嗀9ӒvS5xxμ JYHPm(;1|ޏ7:I4s<.T ٖz)0kJ.9HZAقdեL07\z.@R?Ebtk+/fz'~H ?'ݬashj@H%`鑚u7bE)F6xK/f6A? ~ \FȽ=]~"RW;UeRp4Ѷ?w;Ng%dcV/|rczBƮ#jilf/B_妨\q%4gς~ꬊ)vW4IG%+^xOY ~W&N8 4p~e :%VWd=:IyZ(_[5ډ #S3!~e,x,_Ыglb(OcJ }-gq1xHw;o5cEP%I ݃j( uŔNW.qʿěuAjMgbf0ѢBfzE|!gaHOl@sMLAO RrIEj!/>48Z=ПnprQ-V`Xy^N ^-rF$3?GYb\ZؐKC()OWR?I @56XBzvۇ=!NpHfpPxB5B A+u ztu'x $![M ⦵PD$i^;`hZW̧`'8˜63= T#?_Ii{@@7A?ZX~u`-׾o=x̂|(炆R d?րO[MazWÙ;,ȧ0K>mFFDf|>p*Yj}ZFDKٍޢJqmGYkC$^v{Z ~tD!;C;5a0A@bRHFG(saJpFr ]ࣕVe K(W3?s>/.=p D}XLyCLe eotv}QO9SO`2 ز#0yXܬ5q)(l$!=mVʐ(k7x 8RNܱ9J}&IY>*EpZW#&*'6Q|d"z㜝IB M ƖÒc,L6BSw*pi7mF(od}TUď[{bB*Ni 1$ī\C2CXfp0;7YmN@Ll$J Sw8o"JEټȒo=bNxh8O *QMR6C_24j˜L xM r=(9(b}a5*8FT>XK~C@Jxz/G0OA9'~ԯ%`psG~20}V:}䬅Dj}`pvnym={.rI2cS1jwgֳobҚJ[qW\ }l팙ܬe.җz|  K#N5LFSG6a`쿁O%^=c4b38[ ~ fM4k_ -ʚ_?>BǷK$qV= *Y'}oԶb['ŊVxҀ*DK8I{0p\F[0ZCo^\oq=g%sƌ<(H{?8Y #-gD'N>%Վn@yJKbo@&sDz [CFZS?=:owls:wdoNGtEx>)`k`yQ_4vx&:?RuU˓r!eiU%GA$#s`\zԋianxBhdXnWH['Ouu+}QxwW@R7Or#sԲ xlm^N,v5<3]pk@%-n;@]P/8b}-Bl"bQ[UFQz*\cW(-O,wљ0w|{Izh.Qwq|~.#<_>7?ScZ(p,YCS^u0׶*,Ҡi5y%5jV{?SjD䪨 H=.rC`ALhO1My8[ QS~ ?jD䩊B]Ѣ[uˑWоy {(Tzַ9{YW}pөCʿ| w%_bz$t)HZTm7M@}{&U;Rb]3牿H"͕j8NvBf b_DVGktv㮶M\R;y]o>i+$#҄;r1mEDiI>SR^uʼna T @"L&%+$*ȁTjj(WLѕмJbJe~`u̫@u1")6 x.S)VzW5Mr8]i̋k;a# JN5ͮHm,z֋K b|ܠ.Z}yUsdYKI1EyܔNB|慀hH?[Ķ zX8Vgث#Es]w[֊W@rߨ@f|*+k(D0Pjd|iat"(ٜ>E_xPyіI;[7\JaQt^B&#|#WOgts5e?\!",GEIC2΍S CU-X9ED¦JcP 'S*2, W?PKw e?Oz)#D:3bg~f`@*!z 5\n[2, ogsk^GQ :(>rL|Þ$OT} \ e 0}skȷ.x(;3w{DlwydR2Fy#MdބHPzLSJ_--A[5 #!|FU N-%R)m3P4g®3eTAALQչY)6CA&g9iCh86R\UFĔá7p]ҫnxh*DmFúQ:VE6cJ㞇0C|Of5@/CePJ]w2fٛ$rys>.XirnJ߸M,(HKs J.6(v}%:b*9WU3~.Q9KjifL+Ft؃*vꊤ ,眱RV_yP2 @R*R@+cSXD.o"x2.[[BDidռE0酅ڒ(wk}Kq (Zܘ~^4%Aۮ1h5F’?^"[=4LiVtҎv|HC9U% \U9(% |7!@f,-dA7)N6qU1܇fJ-gj@v6WH5i# 7yN=2>IАd 6NT|Q"7%m:VS_zuM}\aSԩD0e]_٠`0p͸Z k*'tF&y1~/ 4x_cG5y*kP^qg <+#|~]/( )?1CX2СCovdfJm$EW\ykҡ#B$Ԑ#\r={ kD`KMMxbI0C)]h4a|sHMǖuO[7pII骇/4N1¹5(}#~D| 7Fp GB467QͶ5E3ϰ("- 9_?,`jP@Kv^&I$KMX.eӉtJZ!VNL>ϔ}QAwM7.,3FG@;F>1{免sTe@e$IE3L܎R3'y2zpGYە {ٟ+#3?7嬨l@Ӂh'$ -GDy!:mڰ({{o%R4~rj'b>W|k-̪O[z8\eH;dJ6~d߫{jPtLubzq؋ɻ}HXT&z#+DTt1K6Qí[ةj CtYkm u<̶YM Uy(oˬ&p7uS*f( *ZZg঻G-3 + -R8}i>mo5ht#57_ {Yy:GieP0?ɟm*N#y>ZX]pU;{"4Ir npfZMұl) K5S]m|+P)!@csHLM6?pdCŵD(]>X𢾚V|MG2,3Y+2hxnDП06) gNy-nz~Fnq ֘m'-`rR}0p3@=).uD/ë袄GZBoN';' g+]b)* džc f> a2=uyTFMQ;Lr4e=ɽ}2#A![bGr qҷ}TSWAdfA[cv !KIx 붰xV$RMsTc7^? 1>7pWh}sSռLt?ϡ W(Y֫?hu "@1ǫ&+x=3R㵔w1:K6;F<O̺,Zg+ \KٔKach Y0Pr/NJp b*f)&̃$7]_9.d_;[oA(rFC _8<< ͧ&{a=o}^̠)T]7 x8@(8bև hȸ2UsG"Q{wH+Ղ䐏J_qkS*oׅsV%+eͱ\ѵ[L)ҿe='SnZjމp|%'=Zw+ʃ#AVMHo'%|CՅmlJЗ-j_^]VMifbgzPJ7LE|tfg>4$L?6g[}5&2GOqJX(kҤ LYWP3,>.WqQGBI}gpj~h\kP1MͶ)ba "R `u4&>ehH'(BA}T|r=I#ΐlFA}- zPOK Y ΫP79d_oO Z d\ ʝ r&싢bwvA/t=m5eYˠl[6FwyS UR:Xݦxh\+Q U% ֥^߷t`[D=k^,\>o=1XEeW dcNU4GAr!_&:;ZDMiE#7jx9&QCkc.תȇˆPCOGR)5H /alPN !;k?Dԣ ʗ `mVn3ew{U>4O} UN+nIg|y!rzG {5_6ζL,JD.DOnj⛮0rpb*GVf5mP9ۃb5{dn#+/ < &Mam`k;ܧ{k$"5U UP:ͺ@w坋soz/n`B R;%hۇ3iPo-͇Xa2b]<Ƒ[Tp.#Sb8Q=sƣD\ƔkVycu(O\U=fj7,MȊz/U\5W]Ez$7 L֙k cANE9 e J YF,6K7}MN$bf5cb[Ԛ,ϖ{a`AEHo]tXXI fn<E/Afô(_2vwr27vqn)PpRK-upAI.&w.HNay>؞=zt d5??$Qx/bUy=ݜ=ABuÃfG ȇ9$kYrE!">EeJj;g(?Pm n{W#eNHyǔKAs&Y6^ O_H>sKycwIbNzzOm+DA.z`=L<#F|MهsgIi~ٙMJH4>= H t@Q)o;8΄Ivٷ^Yў]}%#!)`∊N6ݭ Ji]d5:07o`6,F bi<åWf$m/,F zbr؁> ܠa˔e?t<#y„HҜJJek$٤Hy*Յ3^v PxüەTSq.ʂT!7TC]@=U=c^⇰ <%%ldQ\ܝ!%id^9nƋTUR2 OGO/l _P㲵S:|$ :ŵ/&(4 8Q}i.J=oϤ X&7uu-TFN+p 'z@ ߮,eg$VlDac?lK< c*D'~ZC/Ȃǚl&}y,ءʱ[HaV,+/O L=aP=|X*Z[bn]Fj{Bhy?ᬠ#]dU@*Z1[u폰j/i@H/.]Ie ^nwoˉ֍Be:t%)Ֆ~fHS uE _@7bYNh"3 I䲒 +;J1}vsikKktx -C-͝MxJ wߒ^4'KrPw_&AևR-?%ٜD R)ki#¤lPkĭ,)ӱd{ӏn/)aP{3Hֿw:dvGPu{[~kܮXD%j2ƾ_A|k S1i]X;M[ͪGT T ,܍4 ,|Ѹ'=#F$}ezc<$ ͈(6Rix\up'[~i7>SÊr܏ !HxҷСz _`4"SxN{}̖7P/iہbpB /N59t&~WU(q+|//XrJyODd?n*+1Jhl]4 _> tx j߱ `C5@Rcʿ%Y[dԹa3O/ѹ<, ur)R[_|g QKpڂ]$w7/uU<ճRi͌=h5&Ak*]<5؉e~I ZOdo9T&Vuج3_}$}N) #ѕx_cY-ą,%Y (St\<1cVջ!2̼W0k|X&$k'q*ZMMmr'V,EKT!oH~(wLָeJTm6AqK8K S"17G~:H|Έ˓|NΎɟ ya-ET;elJv9UQlgjǛ%1ձ<黷&bd; )qLhd5+4 a+89ix룎7e)CCiJ-D]=Zdn`!vbٽ5%.fV)Om(M)4әԡۅSJr+eci;^vtE\kKQ<ܗYY KAVOv)NM_#+;a؜z" {iA})ؼ +n[%zGsM"7#_Xğ^،F<~TQqPvK-U:cZ$l M|r`F(/dad^+r̠|XӖ&R'I9"k q}Cl&4=-\'x˂]3VșYa)bkT@$;IWe^S/F5X$utܽU; xtь+ TdhR5CRMPLCyQ-,ùf-ZscT3CXk~81=xS6엚U7vYˑWisz{(?/sYS|ZOX9&^k|\%On #`.u艿:ZvKhR4;zJb;(}}w~aNqIa6+8X|n88*YHPL cCG2Mvuq-L)ctqn3jx[1Ӏ]{JW eV'nmO@< :>̓-oO@YwȽGx'XiOT;)U@Wҝ6!)V9%gy 1W:<϶ãT8ؐek*;g$ l:lmBzsrL'q[=Ǡԭ5 "e4,v#?3B'^M UH(Ktq1 uƈξ)=d8] v#'"u}ZTq7ƀ?Oj8QlЋ䓔|B}9y>hXkZC3j%^z D̊2s4-H8.xfɂWtH20LjYͷȖ+4w2<I H9 xr ٩.̛HI{NAmbݛݕ~!HMdiun+BƍP,KEMu!e6E?*X;) oSiSN%2PD';λvE7RcЫW߶,b4vJʳ@pYO=7S+ 5JI9@Ou.3n|k)S v[dPŽ SahڟG݅7jz.6rTy9lGtD%0 g;b+CeCΫmm> Qe9N=CFB=_R?ÝZ<] ᧑QqO?\0[r˧YeLF z_ӧ_vO{/S ѥiGAil9ؙ3䒈_( ]Ze:ZޜZ>"'rnȘApɂSν˲,Sd@D8J\Ჾ~vBfi²`b4j?L[z-`c1X4m ։Xh#w W *h,;@n䓅2`+ye`Sxo N.}`᛽3xD/OIg{C|{ ^IKКF> _!vo,nSYLHlC mpL 3ЧɌ̩$u8\ a4zGy*hCK*i fg~BlMe%T v96'3a@e* bPυ=6e{Ú H@a>QM‰a:ؗi>Fۍ<5/qKfl{+i=ZO?ׯ%ɱ rogx"JQWMrۄqBlrXQ{L|> ޥ <ʾG줐v]MfGi%ɫ tnܠn@&r(/J},m`Cŀ_"~oczbݵYw,zѨ^"z0h6lͭ ƙ=P=]up߽܅^wUȆ](~;+z U>L ^lqb@5NaPXmu]jTU[S@> ǃlŲVl+r}k]p  U[$ bVptu<})£ݏ{gm);E,U4SӐh]ݭ7 7F, g8omcS$J-W+[ZC~7-fX1wC|Vx`R#>B2429)lp"6:HqubݠcS\F+jj4'Os> ;Z`][i_t\9v@z:+Bg;u^H $ś3~#өφb*2xz eĪ-V7H!#K[Ó;@B*)ZQ+k"2b/chӍSik%@ )a3}bI ٽycOBLQM|چ#8I>OpZ=rK ]}+/n&Όn}RY7cbFo ד1[ el\jXޚO\aOx3T)웺Ǻ RW1/N5SªYeRZL(.l+,Q Y&P͵Q,S2%={Dz1%, |lؤ/c˂Q;G4t o,F,Z:QFkR<~ȒY:Xr40eRa0gPy6&4}eLKW ! ( %3dk7O2ܞ;]SN}ˌƒAbZ IucBoF48bZ7b<' P7J,K@y=/*h7bXFx8z"8Hၤj@(,axK{#뛪x/H? &HCkzePLfn>|5t +LJG}Ԙ@bXhf4=kUrfxˈ a?xI{*7ec:%ja@:x;3Y23] phɜy Zb="tyFQrQG7sy'{`׈,(8xX ]ȈdN[2KF@9q_aj +ڗ{yځ`/Y_S%\pr19cZ݁Mys ߻%.(,.I*Nvzp)Wq5MZ)+m֧Qk^5KgGוLٴETa:hkL|ޚNhE0aoG/N;'Z1&@EeR *v6߯FR/"VUiۆ6yYr@Mt#8jeGżIv5xqL |c[nxۖe) AxK=wV'p|RZ8qvA=#iA2TOfڊסOwzB WJ9,w LUR Y`pc}dqnR+(H#@*.1BA9b]U0 OKT(Oto2(@V0vAYtuUApW7OH|Y1}˵Y>mAs ;)!mX tޑyF!, @?fxX)@X6NZ성Wc8ܝ*wњ}.j=MmWHKˁt:I=JoGZ ?Glj7ME1}omdzڝZj}F#-MյL;JO jvW0FXNݠ)jXěʱ6R@ۼ}F0IoV&M{p#b\a]浍$)r7^YDs۰zKt(CyRЗn/יe]!pOHי#|^}XJiQ,)3Ѿ r,L]IDks a]ĭ,g$Kܝh<=ڦ "Cb=t{pʵ~NBvOZڒ}kk!@d1qQbo(}̈́8M?Id}Djb!llT/up&A^xeޱHl[2TU0AM"n,=be&ىנR'amf$X >X8&<_Gݏ g@|# $A0ڠ8I4W\^Z(RM&bPS˵vĤ%c, 5bq}gu1F~Wf':g }w{ zrj}t]q/X*HolՒ9P$kxdzhh'05˚vy [GG;o&_1-tZRz0 wEÎB@~K4 xVv8\(ȋݴzd$1 YPvwAcF`p0eK31&N1fk~3J'jIvWX28~bs5!c!'܌ j}i9N`606jruebSb{vARw*?{OrWLy.ۈ``W?&UQEi:@QA^&e5}X )V Ϝt|IMlKI^. hհfTg-]b@I?;sb]>9?'hՄFm MT5xiڒrJ ^_>T/Թбf>]_D#?hylc}%XitUW`Ll:%BOA0@B{or+Ȑ:psXgNhƴm؄ )ddSl`0?+yBE<_r/N9 gm}(I]< Wz34=ʼHТxcWnڜz\1KBß6`,- irt%PK%> FK( cMն5a'zPl>L6 .th7QQECY"seQHm/̵ڀ|~e/L_ٝ47 VV"^ *o 7>\\|q*(+3S +$R872?TzI ~@]L9L{TOgSXUsM+ G4|lK?msӎ hy,݌f%iN]p"иF_g 2ЊmvG <1Ef:GOpCd,/5V ݊p:gC`=k.IBtx(d.viI0o/}SX?# 0Tuk F'eA/U#mQ>xvsZI ~h";<$BkʃS}|h8RdI!M t44O Lsɸ5fv9!BM!#vxGNQW >ǵC)[ֈIJ$YNcجAU7bN6eG~]_f|l m 7%ryqVGTC#G2<_t1-PLdΚ7Ƌ-B\9U9^%)~D wI'YzS:f z;zjȗej1./N [Ŗُp]m-z ,u.~1 MEe;q\<.2z& p0d׵ &0%c/]ŵȿ*uq`J(s`s;wF@ HME l7f 7 u_IK8K;w.5q8.T.ǚل̥$mt E0.N}g*y,ٝZuWsoW6ˋa4ϛAჱݕ  {T7˚MVZZ!%IVej6`-F}w.PGn ٰK0GO{n69Oy8IxI"u4sqL52K0,IKW6سǂ fnduI)!&NFk>/% RaHt엜*h\XeLZ~ҥI hCTs 4#/սZծm ާLdsflR#d5 Ĉ U?}BU(MBK=eEvV3e3Znecv);1, fK=$f ss+/duX)iA =Y~|:3RB|#޸h?9PT^֖1Qe0}:u7ijE=*6凜.p/#(iX%t~W@Ehu둬8@0a]'^C d'HۊpaU%~Kl]Qn#u=ixꍙO9ΰJN Q`ދOKyugDaw/# eCGZw;P#0^OsZ>*Pq #ޒ˅.`|v!W@B,Q ͙<]c+qONP"nv^[;f\Vz}NLeFǵ)72t/Q #ƍ-94YΑ$(u2MeMvs&m/qNnB7Q*K*'q`09W!wRw ,T(za(T3AS>1>fHKlgm/ ]g#=ѷ`4;5#ȪE@;bWی`ycU vgpn9-[6Ř19ȟ`$ Yaum"}f4i=&i 8_a~=! ^VoP;(B6T((gPTdgc,] R `Ur'(MhRW.+y?FiZ8TnqF],B?VQ|Q˶1SW2ofAdYu&aK?@CW3%Ć8"35vs\qH|kp#$  ~W]בP$[qGc$3&x2l\BoEcdWq݊'tmmPaQ=~gV-.$3e,z_5azRL帶*AxF%Fku-gcA6ju#rpDz˟V98ߐ} |xx##q(+\ys&n^H>MG㳇&5Yť ȣbHߨ*ط>S榅l@=|7Z%}Ċ}ſ+T~]j̥p_(Vy8p85U68= 8ՋyvϬμL͵NRe5+&;iF] ]u?DT(j=/P;4~3)@Q3dkl"s.h!M-C%Ii2[yYm5͛sFV8D8os~X9fbT}y] 8z-W :V{-#{s0~>yj׎4`tVjFGBy0\mV鮸l̻7yMgEV^ +Ss60$xҭuPgHia AƷ} Wʤ SuOZ_8q߃__>G]ms(#joD94ݓCϛ7:ar9mIYDQUݡkebuqCbFʆ`v덎Usx \_%*Ϣ"xڃ0AyuUG`7 X.41`8c0e u*# rqk7v5{Q59PM(*\S~LaCB &dSNju68|sꈖ7&iB)V[[L^h%iJQd%Ǚ(v" ,>-fdmc\Ģ ,. °0b7A}91p{KHc/Ý 4a nGUm\C8AЊwy6pKbҷmI;TdLT_ i{$M7 d8v{G\79F[jźǛF9+nR?GNڼo9pZyTӁ I\ I! fd/Q((dK B 4ŵyJ4. ȸZhK(x>=o 'OXdũhk\|*/ s(j6z]'dVL͇ }[īXNȘt9r\4ʔɀi w8<2.=A}mArh'{M˲]UqgZ "*$pT&3h`Z(y7\ d.jd(6=B%A)$SIOkI܄ݫ8pwTLAG-8\H[lhrDaԚA1_P:K; pv7 rQD+ rߡ"};@iߍȽ[_MNjyU!HF/X" AKpwTy֒@pl׵.mVu]5mIfD]!&OzWPU8&<1A Č:4-}v|M}t^0E-9yͥVT|vSUj+r?Jﲶ!&}DOs}%q). |"cxX:[TW- .Q9 V9%0uL~s79RVV}ӟd!*^!{4]fp8Dd(0ưAx3v=>Y & qH=?ux_~Fו<:tw<p8[^Y+[ q!Rʉ:cOo|FWdl:z)Z!&Gt^'mxq q9nB cV1H[;L}5֎AgB)f5qa7F5y~ˏkci8;A(㪹#F&ߠYZl1$?4Syʖe&5 PxČW(__qkoC6RJ@ 53YlC35yE`ӧ/K7yDx#vg]y 7 0_33G~C[dQ#U)ebPThYrQ[b~&Tvb 4ӧePm(\!C7Hн_7pw. sZLץ{. v_ ꢙ#"BVe QGbp[Nr{EpJ*D mp!'NM2#jYisVw 0'lN&(W]$eْ{j B(odӀjCN .Ko{P:mBJ0~fV[h{g4\mڛP c㈮lZrfA!wWk4Qd(t w‰vI=+מs~ aݤ| e.A{/#s|-HX-2Hߋ:rgwjԋ؊NʞjW$ا>@'-7z%ePS(o,z5+e//ľ=I1[mB' S]Λ_JW*3hGU%,4Ņ'[OR2ʚm֞q mM\޺hNV;Sc4u× S ~h.); =)(jF l_,Wx$Er }̯ 31!N Լ$ܗ]<7S9жΚb?Rι}g5M@[أsH>)Őf`6_t4T5; +3 #!VJǜ<׉vnkfC:{+2 C`XT3H0E_yc bFe yR僽 ;IEkb%=5حMȃhGԀ9-pgqdgs> e8 0"-9*yVbAIV2q!z~N~|3I%9n:]48V*,B$P-2^K z~h"~HOKX߽P0aB}81VP'c$VBV޺ 豹cק)Jt%3-.mv/"g.5v3yB¥/Rپkw'{*cW2VlZuk?[/p$Eb\+2{rȁ/6sY1p/2? c*{U ?~5xt&㋑Qȡ}+#őLxK3BG+僢X3`G/AfaTx)KXο4â\Ns$qhz{;M("wMT߽C~8%떸q0IJWj[[`VR ̽)`9[N]1MҵI]R> kDlrppMKwNb7PON%5vBF|7=γW^=sމ[9"Q+r,.k,Nn EC0a?fm!#jYX{]o3g~}8XwQ;DоTGa!aAŽ8LrdR[`:VJ*}xU 0; x \e²3miXAhYO8$K ;̃"۹ | wFMrťb'w-8HLҦ.ޥn>Uz.[Mbb,q(!0s(c*]x1v1- c2}lʄ3M!ߖ'ͨUB SW0I&+VP(\<3-_PoCZ='mVlUVp=LDIJ{ӂ[s\cE6,"jTDEHȰ'M[󪽞_!c5pVe ._5PB I>L-QR OlpǑϞnpMǍvW4i/#5kA?:0s%JFN82)94Tk+O@jii8p&(3d%xǚ j)e$oU8~Ur, ? 8T Ҁs.vW0\CUm?Y6M \29$\EHOLF7m(#BvQ}+Po ^Mbp>0>3,V֝#xḰ+5%zT fpUG%bL(yuFB j :h&0Hy'i`LfRحwE2 o70X͆{Tt ˍDDokG" b}/o/UBJ rfcʵc{$~˲UN<NU\?1(?Ba?U#\i^bl\Ha@ $0+qze]+NAM?u,~12!@ }ԻtnOz{x,ds*hdM0vn.*eïbOYv̙jl˄ nAym㒌2 Jc=`S(>$BH޹ КwBhHWՇN@AQO2Ȩk>ݪ 4j[&41/9Ivll2;#i[; l qM邐6?09 x>:DHMySM:ߚ@0#\?xt;'~[4/uy`6pd[쇊/PO(;hpykAojTӓML)O Qne 8nNhB(5%r.QEFI-~WrQEiph 6cJM/S؊?._Z P{m5RllŋF?=;SIV4<+Ƌ X4?v.QɄL谰]h"5R «nDS "@bXhjOB>ð6\RE節١4 1L{6RCȂ=j=V+X*{#I,Ma=n],q8&9~y74r3؞{92\s"oƻKy??DCң *l邥0k˲.Urd@d;o![Ngc32jGIzA>9lmf+6u' d1ikʊ޿n'HYF"Nn GxE*Xtذ TYW@M= 2>"ıJnhc^ 7 '0[%[qG=A@8ˋ~ h!ivk &Lh'Ï|Y, ,IWo)ze1qYGH'bɹ_`ႽocjK<&st`px|N"1 i: S^T;ym W Oo_Cb6ZGu;XxNubA#:Vjp |HC =s!^f4)_L~ >^bvp;%(J?Ommx}gsvqkp2EP+i V#z ?-w {3Lw$&4# 8PzbbWqHj & 8ڶL'"0GoI[/Xn#Gc1]Vkk%N7{pBYtҐ9aUɺ _Mnl&CWr pf %ڲu4,(/H0P=ؿN4IxABNy/d]{J7S6L'8,ē%(TPAJ u1[?v@ 3 wf*3eG_ 1*Y`jR+Qd~X0 4zeR>P=DZ1qء۪!5m1 "PhxxO}O"¦㬑SCôe-cف* 60}'Df+,b.rL fu6Fn-$; mZ9gi0Ez6L]]v^ #/zµ>. ? T.SBd"\@0)WfoV=W! t*&&߆y`Gi0ۗ! 57|Ș-2wNe[RI>F|<kcqV2w(DR=p+>g`敋8X>*<"׃3 sq oQ4{K=6 JhgnwBǟe[SvyZܛR/OZF&6B.և_ED~;Ze3AM[iWtl;:5>HJINZU ԾH Խc !K F#srs x"0q cX-biOș\&g`ƳR>B$Ú6yJ5L7?X-S(ypQgf4~B%}3NY9lv &_^ epF W\~kM[7<~_(P>D9qJ{(.Ř{*jTI")MR)o{'Iި> Kܚr̓>=eWE8VV+O8bs; 9O㘁2Q.ZCu!f|ap*'̸qDbٸ7|QdHDI7rvbIm\f&]V4RA/{M/N^5IӶ͝0cZOWm՜V2¨@BZ;S[0]3ilNvnuoϻ?eeatvEAkM y,.nQ72AFipV̝flz";`b"QC 8%A=CPb >P֏vqKBFF->h΋ ӛQ },h.0Jə6&LM;Q~oJ ꁔxO #8z)p( ׿bI'a#1=l>b qK-$8Q3V"GgՆooR ;'F' kR?^wh텥i> s{ 8}IH]*h7=d<#hȔ!m1b6wBپanm]5v[ËFaWNH[HiG^QUUZǒwoX9e2~0$;KCM >_(!A[ҁ`Q☡ӏۈK\jbW wzaˣAcŭrCp{l2ґ7/o2"7,h&ЉN$ie1Bue||x#Pz:cCΙI*oKeA:Cjxru7P\tELz7*m`oU6^Bat#?wa%qUR3v%zJ74EUM kZct_zyd +H d)>yK"&ݹeO`U]84bl2Z.p5v68tshOXmZ=MZv 4 &'o Gf8V!.E Zmz1W?ڝ:7.z1XGT*,1:t7xZOe̜֘pj+lu]+z`y9Dɣ%0&FS[5%i"qlGo$a)SFa^+^+ϸVr4|SSSf A%](/6<`/{jS5A@]5Q ec(2 ^ rK;*^T W'k. ݉:TT.UE)3x(eQ3tm߳&^F t}]w!A{u=p%F. sR`OS5aD3T)!,TTν7t^NhE{&ͯA!o4}%(A*Lrz#)LDUF2Yl(8G:{SzGqIJ޽3b0mIo␷4сX;sqyL >.0tXfՎ Le7C hȰ'ȿ!6/\`53u@%Γ$vXy+<5ڷgГ%l:"nzLJ=(,"}Aj= ߸v9տzjG؁35M7f)}h:JeŐ (qjsQ;x ݻoŪ'θһ2W:MXX1ǒ|R~Aᤲ%8;C|: O$%?n#{/gGASwb? ?//L3o|/y]䰋Jx8{j oUŎ:y7}spHV>Jt{ǐ7r ī!>$Z"ΨLo ZM<3 lHTkrbt`wڐMcAŌ#-l`1VV!7s3pP:{t {k)Er }G(xE :{Քek{zeF@!Τ#ܞQ D9P+G`Uo~c64XkϺ\sMc%:<2nSv.6x!@(P+9Un(,mbǺb.gfm^Y>mOtjr=c'bLѝ!$8'?~z׼zK Bz ?FxI< ]8௔m<[#M@re/#] :f`qʴ!OK b 8)s! .S5<6g9LqIl:Q_AWKlnJz9g/}+NJB-34OS@Ĵ~leɫ!PvӇ^/xћLj'^Ѷ ǘa9 po~#_gƪqT/),~o#OEAj쿆hܝhW sўMms4P##izA~®s1Q(pkU6C#t3F-R[ƛC OALP\#d5+DeD~܎ ؉d4byH` vĐQ p1>Ao8[$I똯^l|XifP?_W.)jdL#scg&k./ ,#C=n!}lQ^Go&9qABo fd"vOh.λ zG/V*ʐ`8rl

B|0'3Z`/Uxkq'ᎀVmq/Y'ox[]W )=ľO 9Fh\USQax.zf [e|Noސk\Q!1$7],+F. AyBZv^9&ưUwg W7ќW =no0yCfU1Mͭ% }20EL` Xؐ.D~vXW|YQFѶ{& ʖEIK˻6{+{5ŘbLP6*= Q\ >48blhmV7 $ǡVC?l2+>c^^.Y-a@VjNFG^ڔA]wmi1%.% AƎ5U1^e]Tv*d9wțVxGpߎ9o:K|e"^1]^5Onư=>RCJ#טyHFEup'Jgw) ͢;Ώً@I 0`rGta4#רi@|N}{ ȴqF/7:Ș9"_+W~BpwM`0O{f[5s\p)gµ)C7=;mbc`_N0Z(ޞjYYYuя6j‘& s$/^(  Ȕ({l.sTD(1(v ItB"]!BsD;f(9b+p0 QtxA=ϙOuSɏ.ᢈȧ@q=Q7eίCyRTJ%1$ @<guxȋȪ&u(\en KU>2|ls,: l[LA$Nms#A:4gڝ0c1g'\>FL+B$pu2#׀z6ZCIEzov7ZVkWm91*FxAp'O׃zt?J$R@P MsND"(aGc!=Y8D(gOޣqPfOL *U \Qy>B=qvx }B,8xDՃgyR؟/r ws6 ZZgGj^fDxB?UYi@]Qz)u`JKο1F_ &ӚG6l[@Kы'3vvq%jcϧo̪8mlf2,NU{2;BP.ځ)R`5R 5f-nĖ.ܢmz^ G#YX6n}6N%2R$рhB&݀zBE4Ý&N.5T!)^q4&*xL^i `Uai;~WdSO~׌Gh_{`>'°p0j[, 5OhY>]! %R$t=m7 L c>?ƚ ]P)wd! B$蝆{S4*G.Sz@ CC&2 Ҭ9!&h%"vl On"c8/zse &JA/@t+ B`g՜-e5]/<K]̉Aؐ]o~>g%:/GqNP6^<\ٻ\O[gaIsb]pF9o 5TJ?B2c.A;@!2cu\ޠ<0 f^ +NQ]Y'A'/D-&J"#)$@7ueULds٬+BL; T)SHGKG݋$ F&ڿ(PN qpI>)BhO %ZE}+ga\OhۃnπoR(,ǵ>׽ndN7*qhEꝼr.Ƽt/@,2t+olxIWR&Z*0^洕tR 7W(;k/V-1󃿶i+v<9כ#Q[:( I Y.;`Cz?˃L-ֶ@g@DjdE,I'2"dh'Hϟ}_} [kFHwIO ֑P˂H'l>95;+YO+W1JE(j^Wl oʽFP7ZCTil K|,6.l9 ɗ8ㅘiNsAy 5K|kD O#X>ػձF6%ّVUyLF$>JQm8B^r2&+?$c'Q „СNVW)ob$-v 2+W- 8~ UR%ūV-;5{:|FUSi9e37#0P6rXpBIݔ#Kcg.@>4. " n62p3 q}hrs혺\x<6en8B@DQty8Ȓ&x1-zףa(Z<[}dLI0ˬ Ɣ/iAK-Gv@j +"BoV$2mk9*/G0l3W%F~y]↟P=hw';xV`^xfR% \ݽ8?: CAY7 Y=i8^E5—!~l9 om.m/g]= Z0AFա)7"o!3aHPZY?9LQaF0'o62gw-*` [Ihob[UAPZHNJۥyܨH(HJkmd23vE#.)~l~(6viA4f1s҂ayxVHP53W 9K ?z;iI|[xAo kV;ғC^ bUV?H~eKjoDqys31yJXSE(6ՁV0/TkV{5~KkϮi *y:ŎK91c$yP]󣿛[l-5^f7Y8M#5_eܝHi;m}jcļi(CE.쓚i`247x[[~Y" s` ݰM=!~@nG{E$$ԩGok?Q .B}'˰ `^!g Id)" U`4N#GJvqGoGE@XmiԾMH^}"&P0a=_uDP2t 5Bd}߿ D~}Dbv@d1aG K7n޹3};tD+ C7Ncm9^kߥ\>oXnXsx.k*fw俰|/g{ܔio]⛊PA("W`u@\4$zfnBU'>m'Hj4! Kf 2:CW–a"ou$73ZZukB'b=8h s$@e{ v%Tp]Y#z'b%mj!dz#{ "֤ wbKdv;Q=MtE+RbW7ZGʥssQx).H 0~#n[B{'g 3gHnn`Ŝ&:M9b3D,97*;*W;ǭp!Ud|<2*PeS|(򐠇9 49IU`KvjCj-t\C- 8ݬzXCrUrfBSع$К| ovIWox"i2g9 P'MVuK]Y"֖؈N"Lx|A9zY&BZ5پd&\ 5A~X7>PIG=VL%?Qe>qw;NG+*L)ps\\R:ҡ/p\Zmk(N (yn EI-"kRiWdGMsB\QuKD$3 Fƿ>'4j˦^+/힁=I6<}糙H9lr@2-b`Y=k.K_! ;"Lz=~5*B`Kع3(6+Owڷ$7EOj}(Of@24кU I6V\mRi8@Io5hv4Iz̦Wfzy"?!$Us s/)]3<2hDf%%;́T)8tb棯}g~5+g8=FJ一sUGe|Cwӹ%|^z!q ?xB7x~C.IAOlءVxBh)ߚפEPqN2ԇHpt`P-{AA3@ضӔJ/zZ4|ˆvdA^I8Ә򋙑]u?ArӁP[K^g]ORvqN"'0 ^GXB8BJ{6 s $VA"ߛ- .ռOmI8~?<drA EƷ^%=轌$U>~eayIAL=ahسe:-Өlۄ3.Ga6hrjfbk hX}93m[!w7=W\(lȻs)wkǶ" m!&ꗘ]7 SNj=ŧ1`Ym(ѭ; 8Vˊ)Hs8^_1i42[[(;hN3 %zM{I]T3}ly'[;w4&}2tPu :MVh])* KV{FL3@e_ BR:X1gӡvfr>w8IIWC>R46?// *Rfc7TVьCo&8-Nt^ȘP3{$Kq$. Do[ǝ YAy_!*C)r5eY;9p_x/'2x=t64nbu<IVS6fAU611\NN[.MވRbȴhqJzafҎK!}?S`éC*AYu?O5 4Ώ忰$b֍=zu  "%wO%_s)̤#!7cZG6 ~aN9)1shs~:N:ӹM#S b`g ~'׍Vh[:nV4j望M&H7@OAxE³tׄ1#ͳ(>3EU->^H:\TDAD]抍t`7E6VKErpTKWg`dFa/}ZxkD ]ΑqX;:h"0-h@b}+:n7T8φ\ZGJ! ߕQ4iZW1¬u01 $f̽ݪs{N.nSP7HPH )gvb];ɚ"Wg_w3ݜS^v"gueʪMI+pS^T|Nxm·KPAï$ĕC[]5ReZO-Ue~/8B: u'D_irزُׯqLDW=a(#?66.őAY@xp} 5fF 7Y2z RL3 + rت4o5pR@`gB, SʪOoǾq{4PsxqPW2#ʽL.ؙl+"쬞LZXm&]!yGd[ꛑl[^O@UDIOxj)A_J겶^lmdž 9T*NT,YTK4$ vlPN&V 7J2Z7"v-H҈߳T&JMQd%/Ka#1YȺ)܇H,"F6pێJE/Xq sgD5j`f#֡ޚ^4Ii`ޓZ#WznxZtѥZŸ9^z܌*uj_}Te[f .hd3_:&or|j< U9QXѸN6  6FL j1w# |$8;i!F}z@?df5dg'Vy% gA[Y2XaqF}rYA;k^+ʮ ;a+5uЦ(pC@TdFb~~ re65~SE/nѡp*)^ewTۿ6q 56VL!ek-c` ' @r"*Ea׹qB1 lxFoh/?VtV+|蹬\ʾ>)I=^eHͅ2UKD?z8JY4>[g>X_UF|卅O%{)i|et ѓ &qV]pu$8](,V;"d+ (>TxgjGә|5^a)Mq9 kV><ېyWa)&RG6-8,\w7.?Ų|i75z(k^uRM NOr;$Q`dRdX97ۜoDnД3e}XwR ,`)6zċg]Zɺmrج G%1VqghHf<h"˥I@)óqxu>{ };S1)qwfX 9mO_ׂS/"1Xq|%1/+A-ݑ^ DdK[l uoA{^/}2wdGzikF6(O.{.,A*_ |p9ƨNtLq[.CmE;{́L@ _9=;qEeb*2wS Q{ݍƟ9X6uhjsdBy ; Bd_$#5^Ď,Y ! 'p2*ߪ|1ӗR+Z-k;ErmUu"SƉw/ f!cEd^ }UmsVuH.J3Uh*ԹSɁZYƿ](xֳ*aon`JOK:Sgw {zmPbvܣ(ߵWXMFt5}n q0ҡҕW=Ev@ݻ0'TǚI8n!A0Lv1 4NZ lK6 uEhoE;~g.ʏ#wx0ϢtI(bLQa"'N=6)-YzD 5)QhfiGθ .+%txyq VW,:mzg=+\͍>h*ŀx@Q(RP=BR)3Iq46ci۳̶UqyIࡐcێ/yr58Y׶t7|qH!݄?ϣ)iͽ~3IL&ђe_N):{FÝqN ex!3uJpK8 {{3M%!9[Dz :.ׂ*,A00L\-C/c]2Iڛz_*ȇ'S]I~3S,'Q @4(%*S3s~q @V 3ݴ77ZaڇƲ`oa*i+.)ωnuFaKWN NI. G#+H\J*M4f/Zq&!1@r" 勒rKd&龚n$ѡ0^Ghvoˀ8(8d 'h@um^Q2*N>ҝ3Z{.Rv5ʌxqmIf}י}4Ksk#'I&%H=s+E{y8yʔxs|V)i ҕwFKEP~ߦY:8%xF@m+'=MYq z#"4f>:ҭ "?8PdXB0Fi&74nI,R7`ddmfp%w#˸˼y2ʞL%UZ/bBkKAfgAVT_%{WRj F j[i>qkZ sr o_7B,BJ]Y$g8g0ڒh0󽽎)h hQm~8aCvzxx72K]qF4}oQuGt21:1] V!z8':޵01w.[XzrmcR{>4d`7Q){B\>'.}/*J$J@(~*WDK2y[7yWjO?%I׀Y3XFq6.,ObNןY7$-@ t .@cU"%=*t >-Jz Fz1*y5G{C]nyv p^teǿ~j7֊mEiNV+Y2bIv?q[s uMD~LRA+ ? /ĸqkd}QPB1P!YZ8J+KtI$^Az3^:Fh^>%@h}bq+n+)d@N-=] ֻd$ /А2*V^`SVB;q*m[W0W˅(Be)܈8k {:>n_ ]M8Y(EAKV'-GALF]ލhLhp;+- ]=U} =a3NkqiZaXoC\7s3=r |9*@K}Y[2L8gOXnc8ū !6h{WDF.HF%ywHz5pj`MwO-z_Y%C5#YiT^{)}*دt%=zT!E 愚]`E7Gƥv :ۅOSb Vj?!Z)k&)D!>3WכeŢIm2woMR"*E#4d>. >Lvk}yYӎGwV=i -pPZvɰ/DwxCpI@f7/$ 5 *}U?WrϫqXB+`c[u?刌*[ 'L:Tϟ &T0v7_+lp!O:L>1Sh?]=h\D n2Ӧu/]dfjA"v{8?r+Ba\YKXaxt\od*\S&wNצr$FZ堳SQc(4K MC Ӥ5m\'vH0$1.['rm{z<t翲PjQ5ޗU=J7V5T =cTvͯ4'h{8=ww % ;חz!a.~1BNv F.Șӽk(odCu;Nsp5KR2Z7zfq'S)L/K>>b<ΐ!xr<GyT: ̄0qz+5C=|&x%#ysY@&d,FZe#Թ.zްegL 3~Oz~{ 'FY7aϸF`bopPsk}W_t ϝJۋJzdEBP)rAx1FyP˼V<"%bF5rqXTG"eB܉pd`09KMU- Ը I9QSx t|Kcy16Լ&x-ϵÃ4klQVYRq$LM);-H[P> \X5r]"G'8AtT_%C,*drux&5ۥ:]a48T d_4!("(m"s H̙ȭ(uFK.h2o'V^]B0_*m/*} NړǼoAC/W1٘*$l-UWAӋKF%ޣ`mf"=.gj I^qC~+e4 %{| vEjvJKVV+7nQ]چ $o58XMd_w؁] >O^cBlne?,ٺ|K_Eաݞeg;Wx3e:>>vtXƩX5TA1w 4f 1[0`C&J?2@MMv>'1D"g@1zYy٩#YͶouz@)*PԩQҿ.$ piԔ*jwnςW|D:yhi:@zF3dKn`"Q ow3OSIcO-_z]`$P~v\ d}{.xrWH896-qg,#M;tB? HT _,xo&2hBvI3rp^V[Hnk^v5^3Pi ~ɩ$b6A =E+ʀ9 8T {w m),,W!Mi*{%VV K=4o)Pese~k/r kr_'+-5#3-?c;8m r)q>Ç?8~stXfm. /ϖ 0bw쾱kͣVq (,Ԝn#J3HZw}5߀ojٙQ7'j<%X=Gv9n+(;:\SzPQ.V;Ɠh`xJllWqT.VPx\g㒑޵(˃Rʽvv>v2?<5_)Zo-hb󒖿OiRˢnA(Ft{1`bG?a [fَ'%Tٔӱ<5aȔ$w|/O\UƶSgs0\̛dYN(?H7U|!{}aĎsS QځCU>a&/G~zokHDC٥.쫓j%{cAu^3qM hZ ҹD!ڪJE9SsOl< e΋a6`q}"zacȳgHh/U4.0Y`a9@>!LG6rjL1؟'BIIi}} -DX$PEV@RǮH\/m4livv.@Sk '#ם(') r"KIhNUCx[3@ޒL̖/ظ.+\ E  Qt9K>ߦoؘbp9x0' 9!YRB |b-!,wgϟO/GeP2fC.͐O>_rn-dDR? Dpus 2D:* Wsu^Up{>3a`{ף+{A)?j "Ȋ}+.+4=x.8u6s?:lAc} G @oZ'iݫ!I,?4)>G d Y9 .~,5!z}gy{қ^<+9Ng˂+}x9E'eZ,6/И!Ke61Zwf~4p=s(22LNzUO`e7D5r U{ L׆+Jt3t~Jj ٥o'StAq,2)EexL!`ל^Y b`6h`e "ܲTIt> йOi5gsTyP6G#W*dn%v7-kM@{(.*顚 Tcm]S4% 9_y/Wt Z٭>u4=7-Ei5Uegm'+x(ḭ8E nc:Sbe(ף"+ VHZz$gQ [baXI^oNտI-4 R7-Ĩ8b$n$ܮz-$\Vΰ^T5koL~na՚ <˹S]rz /TaH޸.OYA&2 ^|IO9ZbT\+ d\RX63 a`Dm{WZ}=4*1^ xmwM":,X*&<{ -o(S͞$'BI@2JYX0s?o;SVO `cۍE2T1`E\:(2],W>> Y0*RP%: %m*Eƿ-m]ĉcO3zJm0 uG³[ nz$ Zy6idDryNWjuTrP%lqo>K@$ -@܀~X5"=5pNiJ5ra޸naw%̮TK8AQ}I !h`AavC0ſVDwmSnhIyEҞdĚVa}}_IQۆ*jwR\b/ǰ) zv!(k yQ>cCR|6mO\YQpGYR}ENmpWk˨OhoKR(9t5TZKOwy' ()B"iS̼Y"rl*4hr,NvjHmW/a~ .fV Ry5lSBShi- S*J͜)"=>d[=V}pC&!^J晝N&IYR&@{n夔 NSj[{nGа' ?fЃ^t#^}2EKnTib{e,- ] \,m3|{[+>A}jFt<"ũ59+6ǤS>h@hO#ZQESJƍ^gBs6g砪dyG5*YF_L4M4uwcxt1f'AoQ&`+x \[ͮO꿞Gc$O,;%g70 25.нYVh|Vї 9z?֭dݥxdrpJ;FˋWY͑i<މK6(#uMJL*6?R8Igq>'|VwoA*~?<记>0,q[Z/!Z܈ҠuFö oW?ߺ-:Gf ,HiNY!3Yuh.em]O]UI%؈P=@Yke_[d0'DRPFGfIBfM[ޑ6v?&< %jS@uriQz0oJ*kfV&2n8eƻ. MX8PXenn"L^ȳIPc# _dF,zBGYn&i(Q?g*D-ki_?8g /5]^\ݘ`.pJ&{tZ5^* \٨,jqO,'OŃx&/šCHJP QExq^rA G,l/wS~C ıtiɣ -oA*N!Noe5CfE)̓V?XWi0Bƀ"e @Td#_\5+A{oy$Ո/?z:̯—ms] |I&6Ƈ\i۸!/Qd%~ eSh0037Q C̈[G4rAnDhy=In "[CLcuEL0-ZA o#$tO k1f*;p37 `gE&+ ,4RF>FC_;'Le'X YQYkiK[$.u~ @~%;&{EoKP.qYgyP4 c?29+F|%[kFu WӛxP 1r/8 uZ_z~ʦ-C?[4<_"7~s oh} )?(nh?ѻHQN}d"pi ]UMY>Ԡ+rwp,q2c`r%s M~G 4pޟ%Pjx,DwyN%tߨدMy\VS0FD^Y*[Μ 2qm ,.y B 1\yiD3ԝ`ԏ=<<QD @OQ pom E?ˢR-T2.}U2Q1A%x롦'I0(_Za{;sߟsB]+s+6%RVUUD@H5adMjNGK'P#n4 PDڭx 6r'}U<(%@[uC R1|CvD<`~}d黰VMVrJ8X2|@9<+ϸ$!XưNq:ЉZ xzFrɍjz|Z2/uN /IϼC%ڧ;`Eb<:?nu!#rd*/8vޣ}K6.ѫMa eZ+# (|,^jZ Í,RRmGb)~̰aCDV|l?*=bTϨu0(SP} #%PY=AhTgڊчb2|k ɬlOxyw^*fPQZU/iaVuHM^A8zmT٘DZ{ 3`>ְ1i3iyn_qŭJ+{U5x"X(_1x:iS@ lP05=j1j~SGhDeGGs^~Q |4.(&Γ6G "> vpMŇcQzFtRs +| ؉.X%㔂ϤΚŖn8#a@^:3kgm(<=Et} p e8u|1G4ޔ+/7{ky܄j?l Nsr&Tcȝ&y*!SG}#Fnpl1YZu~7mxX5gI ל7v {MjYZ}n#$ԏ|'.LzaPc#9=~T [ίmJD/CJm9,ʠIMKJ.9Pcv{oEocTp0MSYsDW!UyGD ͬbA8F(cSN5Gq+u1,jjlM!~ڤir1vht|)O_ tis1"60mg03^L!7reD0kY rQ 4j:íQv7c,;UJBc8&EŅˡ u0K.eW'R)vߛK=+u?ztj1;[♴B I ۠<0;M-uX.SKNAAÚ3ؒ%J? )bı5E= jcSQ%*ACHUR+hV{( PBUXC2 G F-@Sm# }<{ڻ͕"}.3zh wRe-<,5w{:V{RCeGi\WP ʛ\o׵g`UYaw5:xK9ǿA"+6'0QN:89C11i6iJFZrCo“Ios2_oX w?H E&#IOhgfcBNҕIm@CQB4Zŗ/׃ڬF4W:w.^YЫ' [6O= $d(Uftɋ[8|EE uP=q^\ :H|r4<)Ɇj3iNzj0ٰB |R1#:#gI1Wߜn6n1ÐR찖,@Gԥ3dO-2oFn_{OsDMFV<+%cd?{]twgzQb<+[ȁF}걽#+zlQξBU/9*ݵ5s~P9ʦtӨ+%XG&X =5^`3aM_)5|qo_xEm$X*^~E,J:=ƚx" GR©U-KL`oncℐtG3L[-f-fb,a^ *!cp%*?'C(*MK=,e#{BtSq:sJXNͺLoxp@WW~N ؿc 0B[SRMAOQ7H q1b>Gl<ièڮ{}JMGn.'=y/ɕ ZAj9AZҿ̎*W48qͤR_%hy~oV, •yrV-+)~άJ EF+!'ArǺ"u>V̋;Yb_fP;WQpp?1i {;Fbrp~"ҸG*a,V=&8${}aE0L]w7z 1*Qf=LX3vhѼ0ݴ!Q&92+W,fӭƆIXNXb1*aH"Y9a@XMn m]tKf\A  'V+0m۝6mpCUAո:1TFrz0D\2霵!')Y.UfbD%1*8nPԟ!͟zV:m #DYoX vf*5D%n8[-(ᗊD @J~Y%+Rhmӽ<3'D#w6Ai)#:^~ _JQ+n'E;5PP mgq9}yH|s( }.!ZG fF͞jz͢ }f~=b'^>UZ2|I* yiQ0iP8 pxzźϴ=)SC@f#TEtM ká'"&|0>Jo*(FS>uX>{5cZ|44TEv be!9 b;|S,d0#JPVƓr;U) U[ĄBQΟߥ vɲg`[5mT}BV.CQv , dȨP#\}f*8 Mxi`R}2bAN'M5˗̨i^gD:Lu]ՍCv)z<h."78pHXV5oF,I=/Q 8 by~ײ_ܹ-elǔid]c3֗Uж9^ѻf$Mי%5c⒪Ƅ|e~]zW[LE7ߪfU^TuJ6bD[)ϺWѩa{HkZ@#trFjѽVfA\xNgB6V%+eFl(sb‡ce0=W'' 5ҞlhsPJ~ y|l,vQFm"DG]b#0'Y!%N ,9urFqHHmY};սP}:nꟂ'mrubCt9Dca6#Ul|CY0IԸ((  &] }zzA: "1t-gdG#x ^δ/|ۮ|ыsꗺ'>~ţ7^P#߈ f#9g>~7VaI5Rtt,~0|nʧlOȉF؏-t-,.-SIRB:XB|dGu=$[T m܇SC/h- zW9 >!Xder6oiG-w&?ePCE@60S&- c_D[чϱ,-kW"%b+yŮ\/lH3q,n7_$d5;&8_D+ R~D;y0Zq-<ahb3n b_&9u%I8RKyPBG|H}.| dB+qSidJ,=KjX/`m͇0hZkL-{kW "ZQL(S כpBlUq :Iԕx.φ_`6w^PU%ov P.uu]}J*f-J-Ep*^2 }&i0yρ%s$?- Ro5Ec 4/9chML(7x3:YrtXx_қ D7t'4hWp7g9?mq c~cXogJʼ崎ID^b\UE'A ݗmq% K,8.ĚiyHC(coֿ5 {. 00b[Gc{k#4 4gL[tGH SH]X e(v3|2R B\1c5^\nTb:R0&#OĀ.׸3x$kPyv[NXI潩Q,X7 ōVks4PSQ R[l2A?IQʀئ! uĆ+v1ldU]~{ -S[xP̽y&x KԠwq>|+Yat)A3N͘PrR=߬GZJYeRXi'Iϩ1A8 Ih,H sJP3(x PҼOP)Waƣ8`))ͫ#1Dzƞu#7B5<4S@ |z,u6gebLw04K|Ghbձx bqE5)"r|U(FhkWaz}U DCn$}~պӑTn<՛^9pRdi*si/U(@z[-ىa%vYoKqq n Jüf_ߢTi-3rB݋>"̳^A~ #xEQ.ƖUhpHyN-Jf5k<%Y<ٽ偯 TH& K/~?YLwhe11仑DS_Jf#g9h~E<Ђ5ݥLJwf! π(2Kec1$R(!Pae -z(/%p&KQ޽iXP>`kpi28(赺H:MBw>X{޿P`z魄  6 =Aeu=b]Bo_R,ŗPF].F9&C2;~o(\9 t^m!ߗ1]8eJHՏ?p46i홣s2HttP~6fqIYͶ; gG*@gFA$HDa u,E!fHNTX]PJSQb"ApKNٸa(/Bm{ 76AGxTo {2: Օj-YSn=)#wny2O~/f`Q_`(y#y_sO٩,ٱDfa y2:^ 6* ?Mx+ݑCvo;GWOޥ ;!'ٗ0 M.ou9ګ9IÉ~STj <8#:pp{3q8Yk:P_}?Jk%r@uti,>cr.+J-g-9`*B5`EU&FHQ:E/nhytvڨ6`|,rC2LUP@o }iIߒb[+']Z%+]}Kѱ}O'Uf+:BXۋyܤV_ 0Ka&4G eci qNXϺ@#biUt 13`%gߥ(d;cL4S@>%X&*,lO Җn Mw,L"+mQ> 8xŷ!;g8s[E̊Id"!GnDؠO*`C& :ж mi~iԖ'~!BwZ\̦ϗDW/F,>JWہV2$ @XΜ}&`ie2v}1D~ziHE1CawWfCݟ! &U4OmdwJ$ H)NZnNk'm:=BZ5iD]V_EZgktƸ",c!?b ojsVmQ?DkFwϜ>Iy2Vyrl K(!c]QcN6ؒ~uדG3er~Gr 4Klwm8nR(vh!h VHlYxV QTɘS095Ly;+|&9us dV-  ,= rf|~%&8F!p5BO p> 4T @)CwGȸ}mdIqz6',ʓRer a@9vsM/=yzRאv+wPFv C&Nq.k K9 P ҟn۪YQr\G"Kܛ`v}[W{j?5~&HYU ") H\E%bmR2ߠ9:,tI+Y\/;lV#h9(01h/K^km^>i:̒]$5C%1/29D~%z,¿ш–ƥ)&p/Yxj:)a](_nLDgt% <EߜnNnkc7Fs0OV`9b|BaS!;zaOM mK%po.V~@ ͩ6!GwE?oyb*[x]{^2pwaTg$Z+po;<_ k}Uuv-Lv`!?EbkW)zzBP a]HRHs@˭2xxr ³]/o =7(t LmxCK"wCj~]hCenG _*)EK#)g ̴" L:wj4 +MОH6d/HmݿMf[>, ufk֧&G>AbhOGgJ`ع9@ffnSKdkC&k6쇭Z.knrCHD'ּlc h7neuGȟ,F=5h υ;.W{po^wDdb㴑k7YP{^AOq2vm)B|6v؇K~:.OVlpRwH-ATy']nˑBvZ5Qo}k$ĘzQк$?6WC xձڒ~s1ٔȪ#tVf~h*'6iX |*f;j*ROԆ!zh/nP,iNI5跷re_Őc2h ¶JER(spj¢bx㟼Z1do^fca hWdPJD.Y>>em\tjѽaM1dɁ~bݯCs:pu۟]H0G,[]--(=bN^9=pZZk}EOر)uXpb2єIFa0Ҳ$+?dR ֧ R@xhlkdHL?wMT$\nj6;R]C~AV|-qExjiw닧^cN Ak۬ʍy##ޏAZ[Phg~' <ŁQ܈u3c$3 I9w@#~*r˂Z\KY}ι.rB<©7vF,WDO>\KR^[ ~HsmA+?YmUpo"}$5 B2Io[aE@ v@eHAPAMЇoQ~{C08].GZ~^eniz<Vr\#Jrr{6נX~w冷N1MCUeup9 np!?,]q?x_nim䣊$!1Z ?*(W# g&{Ljm% ljr?'b?ysӤ 0^6XtV[YWZQ!b1>4;b/ sc40ACqv(i: R,AK Sb|ħr!\ؙJejNEP/|ܸ 7X6n\,C-cV@T j7#w׈pĶtm>ԈaHVnj@r׭޳axXHXQ=C<(^V+(`z,*Ms;_WY3WYQƙXe%=i4A؟8XY댧n' Th:er#8 0̃"xP~@ ״,盍UU6OٖFd:}J cMҶv¹adEȑ8A* \:o졡#f/\k|J E_7`Kq;k[P~"lާ[ZF3?5) iX8\]-(xiLU/\Q@tǗ S}rF>YZq$8ߤdF._#ϙ0{3z "|h_3$%Qp_GQ x K;u6MAW5evn2v"_l= y4j7B 2-Jۊ=ۘiANџ@%xdx\#ܺ1\;~iZp6נXB %r;^&u"MGW51qdu`[óUJ9L h+zV90w9I {W#VH2  Zm)|x~bԠg2%u.G=;i`יfwkl^[kc`\YJ;?[X6EE*Mv֛'݋.Rʙ(eTGOu"mNֹ1mSMb0\+JZ<}xn}}&YcFr64m$T*ay*czYc^Gø s/n ֎dI9MCEerSzš_3,֖îl3;BcǰH+XCtTJ۸yˆ47yhH0= |?XA桞0IHtiI+՛E7i= q[{$1ՖgDa&bտA 380f2ߌZ%´&/q,&nnx2kηkP}˅9[HCZ^_թnr{+^="Y-"}d AV*>WRn 0-\IE7l!6q] Z=c5Pj?lgU*`kczӗ$3,{hбW]5Wj 0?F{|*$*޲+t%^geC3-_CO"et@֋$!xArqWl^AP06I>)v |55%)N*oA{<"k̗wy,Ep\lZA (e6`#z;1J=/jNؾY\S!W`2OևHIeV($'[SN@{1)* o K{$8'^R}OrilY-E+NsߋSgఛG!*:L b\d@iaMdyK!9AGr^wN[UJ$sz `\LiPll*Ǥh}<0mӠdpVSc]po8*,M Ml&\r xb ѡ7ޣۺaR!)׸um%Ir#31zV܅L G)%N#m'jh',9JEڃb/l0lDsi)*oDx'Yf3mB/{NOҡ,IPXI ](==44azmuzOj _۴$9+T߄?6tQͩ+=qq~_'D.AA[;jb_ܥֈ6G^oP9`̚YcØT;Vvbdr|q¨ 1)= zT{Fҳƫ^\,~Gg;!.ZXٖ$Ux϶Dm>>N#RZFmA\?;di'C4ȍ/ ēm'z{S^V&.f{[\%J9kQ"%fG:uի\A߇\W'si8ElxD;3JXc&Zq,R7zKFV4rW'sw=P? :{\aMe8NELu'Xs />!wEqj j%RTd .q]%&rEE3`也ɱAas]s=ǞekudJՉ;|~'k: T@!mtpe?GW&`%߆" (>x78r!Ξ+BU} U}( T> eeڛaS"ҏy=Ȕ 'xdYveߩL1O?a}!L( XDT|Y%k*޷_q^k:nAh`9&Yܿ64Ƽ` -1{E8d=X~}#GB!`:ɚaLzR q F;r3# 5bkYmf24 ;Ym +FT˘*uOsJon+YDvWD VFΊ*a hAdN=s?xeYAQ(bM'8@TgoaVUFYO; A{E- i!,i_g1!|=V.\;~X]MV%q?.;^M9 _۴D l~>j͘ clŧ*@bSPFb+懛Ɲ%OZһ(? 6 t)yt/+ʘ+@6~I,O n@q8wW_g"'!VRNZAS-oC\Fh3/U2oWOnp*SGR>l+Sц dAH> SJӱ{"nO/+s+h n(:'6w!˵39S9řglXe SRK>vtP4t|ȩO @:є%0"cQ7R ?#={E#Iъn4eD:3y(k;? ?uwz=aNk *<gm,&.a+*MTZg64?9i#bdbVKu/E|zx\'~q-0nWkm{:Z>Q I~ж,/*8#` )#ypee7B\*z-ُѶw?w?Y1Dku˺Kx=FS$(֮`J'4%Tr wUy&0Qꑧ9=B9{ ?f"3 ǏٺJ?2Ko> c \ Ոyw[@՛xwd퀃 4=zN!&?i2hS`܀JeC# uSd\\?ڭ>[J;_N~WDк54MPJ.؝R'-gt  uC>?GO(r|;HiܯF๟#W˛^n`̓6o [$yG}@4SyhK4ҔyݟaM-;bQ DK$i-Vf?xiIo|s©һЈl.G *ɪ39&3ַݪ&X`?D?埡N!|8j}9ǟ+y+70K/a.v/"_ȡX*(_a|Rn+פ\^Npw,`jE %xݹvznY 8ǺacDNLev nR!ˎIH8at?!+4#?ك/2!b-'HH vZnG'Q&`(M#5=S4< >ujf_C5M UCH3•1!ꆐXe!]֪f~ypTD#Idt ]Qr,'=hbu۪{YZ,=dvI43:>ul6vY8Vw`E߻1BS 8G2:iu)jWT",(NRn^:R0#cw2qg o(-F6*it*zyHo+%2NG~bV+U #e@ڴ)(OE2KX7 E0Qu6"/IQW&FY)ZlR!Y܎_uAPQI-_r㞅^g)uhlYnh]%txN 8 ihRll/I 2V2iCɴTZ3G twH\"V-^9VPth&rظϧөhd[= v7 {&}[ܙA\jF`;I?ߌD,X\۩2XF65ku u./g܂RVp-緺mk:xLfT8Xٛ9%Y>J8.rbUCf uN #bl/i.4izPnwΰR5@3r(bAd*X]ZP|`^٥Sx[>s]T; |2m)r}&MŠ P=2NQfA5Y  ?B5˜lcguyų(w_%. c t uX[[K/kñ6Ɛ/e 0z+5|JA)!Ԧ&@5o؃S~( r治!vr)'L)Z ;{ (G*سϼ,zQ'd!Y}i3&%Y OmkdB7cO,kh:#OF@CY䡦ؑ7ԿVF2@[3-+ĺ(IV ̀I(du+_Q5^'i G.o3zq hI'r`0-R1_8EFbבίg WvC4gI#j#}I)Wb^ܖ#Tkm%oly6D2{H&Xܩ"Q tGh*'/<0uGECJM6rܙ,eLQSL#G>ގ^w{A0wh_[/'5,UnQe Nyꊠ)j.&z8E[ICn!87%>CE\_8!hx`G71Oc·ba-E}]"$ 5,T=nE8H/展q{}`)E4濋>ҽ 2Y~>O[LKWN_0k$|hCgA?ðZ OX}QC4q~3^DXA>cmGh8/ HǖqE(!PږuӒˣ*N"]yyo+Sf@D"1i-۠4u3DKq54XChhF(hتS*N^5Sa47p4;FgTXU$m?@G,ቺQ&?,;͡kK!t2>@$Si>6536XuNfA# .7=JbDn>w-G{|~X7s2:qpkJ ܃lu պZuT,Ik>/aWd|j'iz`7-45OsSՠlԆ#XetO&F.MzC r/,I.,pz7dF$xd ^N$m,Au0mPVp&s[0bXoĻx4/MHϽ; 0~m4+/3>T(SJij;Hj0u8[0ɳ/EEnTdߨy~mպ 0by*@[A8΀^g"hk(zd<莆mY˥ U`7C(pB/>/GU%;+jÔwWˊh` pLi qb3d߈^G֯X_Q>_1ȯ6ɋ^FûOpиy" Q (t,GwNpE\K{0&lcWYA&Ӽ0ձKILDLXO 1RCԫAԠf:b> U24 / ~?I(=d% ~$wU_D~{R 3W0,zVdV7H[Z&k;t2\qYyC*61=@l @kTaQԎDup@Oj4l,NqՃ8EaԠ~k'J9]D7'mc񂔱b+Y-6̶ʓw~.^8[CjPOKξIôsIjZVz1l=:#]~רȫ=8_h_HZ NhxODA R At~4m PPsBe83XڒU6Ҋ@@-6` H Q{c:>-VAV /\ڽ\A*a]bLE_iT(f'>d@۪MEe >(״fdtR|= )XD ]Fȇ%%sQ&&p-LUP_RPw8 ח;z=06P fUvrYG叱50]LS6FbE/O}`2hNqiojҙK_Vs}ꈃvqXM>U<ұɃ !av8Fbp`PLd&s@mZ ^gV\ 11󺩔h{= p\!IލT`W,;UGDݸmW|IEr"BO"08Op[km9 ;RNNSu]mm0#nzT*9;Cuc0]DPiV料 Q0MzZOR37;TھtPe0 $fK*0S_i9̲(ʱ[{\ /lfj;5cŒ.%Qnss))fi>MX"N|= ߥVQ. Ȥ/NBejDڸٺ r:<,&XQl$>HguFH2Y6jO!eDy*g/p߫[J$)Rh2"]$g!Xn$]5鄕`rꅢ*o:(٪-^L71ŸoO :iW6_gtԱ3˾ɾ7)A^@ cYF9TsĊhR7p۞Y0s3zCDCo5BX 510! =xzJ1"c <}وx4eВ$|["xణ1$AՉmȾI 'F gaMIv=r.koA>j\, V CN{Iu<`"Ui b{N[w=z¸$-Xc9!E@(87a:u[4jf"[w,t93 oF2( wٱ%1Gޤo"{S(uQYAu.cfΥʽΡ˾@6m-BbgOviFWp|!"(:/#k3JJt K]h @3f簅Nyoi@3dEϓs&{`I$ 钥͢9˷ж$/D /Vc|9 .qc HvQԖ`]j]%wbv{hqƯ9oܥ(~N ZrI!FކC?\car.b38MwƇմ:d jZV5q:|Kɷu8:sj9\ M(Wn)sp)E۝9"]1 M^U;ԐgA9%,pࢬ,"pCT>d!,frFY&S{tnVE Y[!-IFgbd11u~nOC1+Pr9|vߞV~gCykC`gH=>X[ ߮+b=j/%qPvdhᙨVv`t`&.ۈ::K&.  )y:38,Hq1%8N1:R1:UԆ*lyӭ6WC@.f!aP<;KUFkfQQrLBinC 'bZV+lS,V~/tkLKÛ*B zJnx]i15X70 Ĥ+V%|#),c')[*0zoN-ȏ94z.3HfXߎzY1yR}|8GoǗ}Uu#>+P7+ڋ; ۍd2gv>Q9E DTby-.RLyΛ#)/zBS^H2L޲cY ڪHV5ju eD ס/,qs SA}SFk|Ct"a/<{| ,fqPj櫄5K*aͷo'3K#޴ٍ ެIN΅2iR}[ WW7WPd`؅~]ӂWV;}!8 <.qjQ Vem! r?X3R#ɨ5]k G\ޔBJGfuĥ7LP'& S h<ճr摍r8 sZqtZ<,^G͌4?-$ѐjӭ >qJ=^ҒEj3`|N=e3I4Fﵽ 4 憒Fd32A|DB&Dz8ZCz 'ѕZM3t[Ǖ X%rSV~ K-=`lLs#&d/7f'?BnËӶwi칂; 6 gH=e$Lq>d|rBjE8/ +R47d&)|N:4I#B/n4#TЛX~T[dŋR< nrBp{w4FsΪSwqֲEX'}hjj)m8"SRO㠯Ϋ=Q+ /+P튙5 V"8-_uaqj6K`8K荞j],fَ|Pߡk&Rޞi@eyQsRFt4THϡ<]vIٽEtzUd>T >s60ҏ,yEޠKڙ3'U:"N0r SAa8uN\ޱ톾*wHBO PK + σwڔ\W< +=ݼ@i$wB(;,Ģn!`,5c;/NFqXRk'\w%RaGUMZ2 a*Qˡeq{\WFyƿsܿ%^>qő'og-qd y\#:{C:CJ.~TN i c,KFg~ Ә0cJ{+uͷbW8%!. = 'Cv@a(@ BO@q% j\}<(pO:b Ӡ`,cUX^DԃB9-& ֣s=/kS1#%VVsJZPc*WD- $[h@Ul-#.O6\]X|H }aG0+E|,qAZ(qkFj௞_3q*&k7B{]Hi}D_}HcpÍY;m9׈ ҫ 'QF x%FoZ`.,*0Lm喘OHpNbu@  fO<"ƶJ 3bdb,f-=%u^_t9L!)vFeb&c/k(e%ʋ;1aP[6_iver->1E򬟡q B~,l0@g h6@OuY綾2I#krsTkRQl^.. VX$G|zG629=vz PkQ850q"\l JCB0c@dvl&x^jN|N s~v'ab9XЕvǼ .7ˊ= `o Gr{TJr,u7<;,3 2E#g]T@kA8O;YZzޱyoét N3·xaʞ qSو Ne0 Tv5-3iLF% Ra 6@g W)'NB ?!aVC(t3Hm}i0wN)F(WA= K5ƫ0b(F9!^)%6!)_%0 ) ]3 '.ܔj\00 |~MzRXg>䕻>G=XrG#~OK 7.aqq6L =Še2tq˷bԮȫ)^Uj]Ms-$+(I$8k n 78<*^+;+I { jQJ#P'S)4͑  zև~Jo[DŽ/%Ŋ1]U{^Qfbj9LPn?}oG0֒1r5_/| l/P{MKV B }}%,*%[qg *-X9+̴\Qm.8aZWsD`wxfZ`:v]clCq#lQ j%C]pg2;e6^=wXP7n[jd| `R+ŰIr,؅k\ OAwߛ?KD.AUKW@@݆+h_fbe#rDy$%A:h܀^^sqZ a1 pъM*6)T`ka /Lԕ_$׾IGf@y74e{HlLP96钕=;74KS*V;=o(rm0ɪ ̓Kщ{>bG_ Se5EqoU'ûeMC%; `GwL͸),]h<2oA\ bxKaz= 47Kf z>]oPSo8Wwya? :M`*|wDRInʁ?uN|]҅S>ůl6#X{w&otVhKA3d^eQsĒ4nAwF<_C\NB\;xH<XG}tHx CO+:O/]$8F(μDSX![ Ds{gZWfYFdoV'/+ 6e4k*t3uJ킕#曲aˠv_#Ki0Љ}w/i^DUXYen\zyxfaE/r@ׄq}XWB!Owݭu®$Uԙnog'e#n7Sj5njt&X/,G`q2 P(T2lBUT63`Y_mȫYb-tߛHL2=fGAyE `-B h:|` Im rb[C` /ydstr֭B&]b R]lEEfһu4`Jp\M a" dZ}7=\4 {/~;,ޞk #|>`lU,  v檮x:IEG}|)߫36~ PUQs-ͨ4(YzRdǩ!0u ׽?gGUU)׾q*ϴO}jw\9"CH¥~W)nOO3U'?k9)~+۲ϕ0W:^ BF5+ cf2xz)3 m~6*;\VϘweDÐ:BX>42bo>wkz{1S 8c;wmAaE`DBGԷƠl!5M\ᢧd/ܬ[K 23}abaEg) !~S̼ 1 U ܜ fbqV2[c8MqLo)!EWse.j^셋'LA*P7_٧6.Mp%Av\Cf9yGGv*6̼Iᩋ~@wxxׁSkMcϒ5␕q/`9u 3%u&Ecϖ$Lw _b; ?1 mzIS t*̵쏕H02 =lat2%uYaE ths8%. (~q= %u.6Hm1-xs :mlx$ehd a5jJ rFǔ&x;UA˸G#XS=|=K'u9gS'hO-*A8X#-[|yy(q.Do3*[BRp*U}<EhBeZX*M4[ ~#}"E-W׻!f #}3V;B8edOYvYFG[DӯO.[E;26(I\QQ ʄ&]BGjٕH./=T\c3"No$k@waNT'q7s[)6?axaw/fњ[FJp$~AzAB?NpdS0-Rɮ,-\/h{gU,$M9;dTUn܁Qy?ct%&6HRݚI5+muK߬۸1n .$j 'lVԉ0  ^ EG9,&.}AYB6$ ʼV8W ^"eSGRgՌ SkmԔ̈B#%VOLa ̕UcY |PzhupkCT XswojjR30#rV{7V教4$o@/`=E*QlFGd!}6׆ì|JQMTj"a'%DlhYc3RCLAK I=.,HM .CTp n|Ji?H3ن( ˬ,Cv] 9㝩4&Oz}(T/Jnwt) $r36\M:%qDTj rЊf VHmw-=M_$28tXpdP͂^UB3*Y+V',CnO\LۅBJwoD~ˆZ=`+!{8-+Ѩc#jg.V''`hҟBh1 ?eeƔ\AfNttW Vh Vm" H--e [SG?CQMbj#'z [A(8}TPl!7d(GW-)Ŀ(^lJH}XgނrYmwJB3GcNƠYJ F{m-0"X&*[w~ yfw~h~tF"b2+YOW[=6 !y& 3,~1~cX_G7C4 s}y6 .(G(NXE/;+l7 ™8^݇|$T0;\afX!QU׽{e5* :3_0Vws4\YOb.,ȠcDS$j;i=,lGr *Imfj#Yֻ߸9ǜVfe`0S"rO,޼"+p]D᛺%Ym9h;b`UP‘r[bxH9pVYiK~sUEB`V.=o3A ֋mdd/-ԯĚ!ƸrٔV>x|'=!;\1^ύ$??.,"EY/l\ xM0ts, j>,^C*Ag#;NǫSȡcr 3Dh]wlpPZ>Ee;BEW/-WTb-/nX䘕 ΡW}#3m+-))f;,Qk< @nAIe2vZ!~7\~ѝE=Qc\t"1޸s'x#2\ a%TS%jr58t(aH2XyHqq x>:ONU>EO ID٨˰2_Q/v%$S  :ıYAI#+,3Q)TO NuZexMnp<僉_|2e3m;!#BJT2>oCz8//cŊ'- (5K H})D`,Qw] ϽmsLR.%vh%Mtϛ=D[ܢ"L>@Hx||Bg8iF$4 ޢj֠"W(AI (l 0;ZT 6v85`M/k]ye*BR[*obGr3!u@$geQQUONr%tp ,$4n~K&퉌䆿~ pEcSS(X:N:|LBeyNv ? ]r$5R}V08낼ޮAiwЇy) :byN(1dxU2憵sgVCL/RbaV:B|?(RDzcYyӄR`Xo_S%oFO+-O6ñ'gbzs X޻R":uPRDLWgMōY9V)Kք `N3t4\~`G$J%qyP/ @H~xI (!穡A[Uvp@}@b|OP8'ikt87GS4aIKOĉu^cz<BN6H"Fi'N41KcfPHk d-f<.P9X65~0Co.Q<|%^CgS3nhTZQsSyPҞY5;m iqnT@Ȃ h2)tnj]j4&ʷ-[}3*]_Ƿ>ψoGMZ]/Q/%y}竂3$i8ԓB^/#uiJr*Fl[e-wMyMB B&dXX<tmHU4?N/qԍSX3ӊj젽%>3c̩?p4qKpLP?4N )2sa͐blxwؼ]TAy~GGT{%pxkW4;L_(ύelc][<fgف?vص _n/k)|j1^$ѱ2}^ 2Qi3SY!2a)!Ԋ]2 ꮪ}wB)f=BKcRsA ފ\Eyz&в&H5f2N>[Cp?-Z/f]?\* >jyCw1?V} %*k -ޟn\%\qoo:Щ |̅`_7`I+Ɍjm?Գk7GGp6(sKL ٙ4|BiAq#>l^Co nj곴!5}K Q܊ ^Qiɘ_ݕy0AS l`T ?@-qJ` S02 'Z;kN:f2y y޵` (]pWtݙe?RPhTGܥcϜS4LpF jJ9wկdW KQW#JZMh2<ˎ2&TwLB3aV¬J 5o!xƻ CS6T0w)'GL(3*R8P=VM4%0}gݝ,S\}#$+s%)`ywj^*PziД,sKWֽ!kҤ|9{JhtWttܴoWpݭtcs)d-5u)1Mږ[a;ZiH Fpa^:I-Di4<;V󭔾Mql3V8}.]IS5WJ4 Ҩc1w'rKm]y$YI\~>);ne(JD;)=ߟnېEϷ y=:Š.Uoqiɂ'#K: 1PjZ\+Z7@=u mPeui$H%iHG{q'}1$ }p3uN2JLzUM ?!h\Z.MUQITГok}@!ѥ1.W>3洩F]{l1|c _v%d;P^D;_L%pkߪA7DKBV]$>ZKldd9"ډx- @_lC5 n]K𖊖ǣ}w_"zlIR9V7YS܁(JNDGqVIwY;^)%OZ`) &3KVK7qs9A+Էؠ| $2[;򳋒: 5uUfwLk]{~y(z)DŽ9E*zܱ% S*i3@ۃL}lnf~ ~Ӭ!9i[am IQB XkfBX|i#!KNbV\uxsdHI7~ G"bxMYBrp i[k-ƽ`yY8 L3"_k|txK4c-.f\~P"Lb-[7ƲwœIBzC0[@N;c3Y B O4,'Xf[#1#̠~gҞ|Ľ>eW"ػY-{%73"_LA< z?63׼NȬO]_+j&% tnL(fk@kCJ>Z IQ]  :d 'H2*?9 pۙĴ^2XrV/4PO258]k{r_(pB>* %!fT@ȯ`!`P.Qci /+Im:gdtPZ*XC6uc,-2Bq=4nfA:̡ Q4ʫ>~R%2!:~1"hU : N 9ӕt%!3#^'ZU\&92a¯"?V J;%jԡ68͟ICaI'5 k{p~c`?ڷDg]Ξϟ]|ǭ59`K_E?#IAOq(L-cbIyO{y:Wn삽Ǣ1l˿[Lap{h*a݁b3)"E5ƽj ;# Rl5dSS,q/KiY7^SeS#LH ( ɘ@$b U9 K&~yLcDHXcM0k5o;<6rwO}:|AVG G}i_aN'gtwpgC uM?uu.^i֩ DsS wVukg`7zֳ} dr{\TIO@O-Йl.o ":j&#N?[~~T諭\։LbG< nkp7؇^M%%#^n'}~W[ ?-˪S 1F.}^'pMX{~ d'h.WӢT ='jGη^(C^-< o KH1DɆ x6 t^bnLE:W_x"KmH߄p4oɧ hSwI 37 Waa/&kK[C̡)t\ x7Iһ30o٣VȜ-M<`\e8 냝׷},N{NS3)eq̝^䳨PsH@.b\=,mu1&U.,o37N;\#+g_eʓZ+<C!ǩf3GG{mj5j˯zd yήsNrw(°d?sG3u7>s>YOhwM2<O~9>}I,@T=vk2 ǂ34BnV/.@}(,3 ݀ qt֤߫5ʯUpD8ĽIRwyc0%f`AM-eٕpb_ǷLsvtj`%FSU-ƐjWA%$Ąh4$őL9<L>jnXCqBQY lw~A{e\~Cד`::&]WjزJ %nd `;}h6KW]0M"[գ4LrWx~4H\Ъ_RNυt{Ya㡏JoCC7k^7d57p)q\i\xT*;Izb^*ڙQ12(MaZk&]+$lv]sPCޣXLKe(Zra>څ#>i:q䉩'c1UIarYWLU%+9p4E cE?twY\b?6P-n 5P*6 n )*OSjXp^YqFзլF$Б&@C' JzȚk>1o U'Xݬ[{2h^`G{% UJzz"k#0툶:I\d߿˄JNϏLM3=#Q.v7nmKZ >pDPqh¡CB'b1Z8A\O.\D~|M1|"/=(Э"Fhx)?>w脀A1gg}`#/q dB@\*/1]tk(P!׷6|.6l47Icxb铠{VG/u&>*"p|8%!+a 4a66gdK2#DoUX?t'p5U}vwcii<^·\%znĈvWBpD澹؅(woY֋C*;)L~%] c 9VUV,gZ+>Wn O] 9/|61*ō6GV(xJ> )׉1Tڍ8GR3vۄIڳk8Zά(>vծ KG2Wr_aBf׃0@;pR-D[f3;C m{yXX'sNfS"  bUM.plȑ$j^$R 'aĐyX >@JהPW8>&H "|!]mzEvy2j#Id&Xҕ+ZˇĪoZN6ҷC+0 ˧p ;e{AQZt׭^b0h%[ŇD8wS#}/ϙՠ!VJyZ=nO~(Ueэb2aQf= uJ36gc5,w8[Э]H8I"%D5N¥ۤrLђ܈Qʜc@ަ'r2\ʃ`ǿyOE&0"puQK!r WLjO0 OeY{Ը9i*rT7i A'\ވn]I>/&`W^NLNBVЉ#_"m4,P.]~L㣁xp 2'4P^ikvdOOZ-Equ(12$D}1S%%lfVTk%9㢮;@:&'8S+I><=ؙ3C*kGBV#Sdq[OGΧ&G{'!T}d|-#?- Ӱ'&~!P1y[ V$P$cº,vزi $aC'Hk#Cf#qi_v[榌 }.a".j],AvbEEgFV ʟr-m gE ?e?G穗,o%*d-5aW ݡ5i4= $:|=U4 SA׷uF"L@-Q|DM*dݦu2(]< R7C&}p~9))"h?#Ut&γn@7՘*VSothhrYbmNbwv|CMk=i•͵BEW p ݷ 9"`qԽ8dK.^eϭ$}@b 8^59`k7]8 E'pr/rL{L~oN39sURo}M" Tzۡ rRCSAv w$BK \ҊwUo@x-p&SH5wRRdbis 6y|sH-@)z?^7xV& "6-:]i zZ55!y8+HhNцvBi]Pvsˉ, ʺ'yZP #*)#)D+jA6o17BAS͸4~T?= n"~yG)ÐCgH\I5ߡyzdgtsqNII?F <W&% dcJ Pxb]T߾0P. cU^E VPEm|ߥ+#Ɣ$(  esmėJ]4AE:i Qֹk  wq1Yͤk),;i`Z?[;l\NG 2r o3.Y`Tv7(sDEmęWeQn;B,2&4i׬ea* "'}-R[:āx *wsu+K5D/%vdBn*"Bk?lWjg^ItӍp[ ^<4_H.s44gm8" "| R1 %QF&4z: v8iM -!Kic6J&Bz&?w6ir;%Gv71/(dF7"8x9L jP]X>@.k?!o7o'KYBŽ5/N{!kc@elYB*(/!V/QD9R븗]xՁ }[m7,vi%"GI^&F06T$iUމp;WH^%)I3Tᑣ-mA8M| ݝ)HH2|jʀ,EؿIЙBhaj[rzoÕ#G|dK9!:c9 ;Bˆ-8ʣkpE2>%r!%W_&΁mô ,kY=ҭl\0r3 0\*d$By͎)qk9#ch[gi,rA]kwI\l=$j;#daPgg ֧aWC0_rZ"r39qI6$"}KL)E6TGMm'q*f<]Lm 45q~e8v٫QPAٹ-;) [JyJaOTU8vhV7,Ih$NSfzf} ) q2,7p[vrTpdJhl-mcܶ]PsM/I -),KIPS!@' 6MK|^3LQ"^ |Uˊ1ͩ1;Čƴ mYau3X>nʉoZ0.!Vt.<,^jR"CشERU#v4_ĖKW54]|?MI%BrDC{8)< 0ٜ YqX&Bp@+n€@Y-!}oFK?U A6ų? 8Qqɏn˘tǎ#ϊYI/7{v=^ɧF*LbB<:N\4[y,G_p}j3/t.]pX=\7=eϱoo0?ɷBRN緛6j!aZϯVǭi.8='QoEJuiۿ8I s -qBln9fAX?o]kktcUHN>sp<=<E.JFa)VBzJC* o6uoQ:ڒb[5wT,LQbhW@s }ȏJCo<ʞA|4ipҰ[s~ Y$^ڙH,Dg gVd^a"aEt`1*WJ>)Ё&_AA"K)u. 򜐚Иu&;$b!8"eˁ z\Ph5&oS*̡ ru-f5'|ۀF>lOZ8.3NEϦ ?ED+mI [Ò!O (8)"g1uP}SKG"~55_h~^ћZsEU:A`P2O} Ma<,=娄''br[{, rtbG^ Nn9ñNqyO+z/`K0;cԤfoR7Ӷ$q96ZRs[ɾxӱ!gO5窋.2!ru$DyR).zQ";Ҵz?)`)*Ԙy9HEA;09XuQGr}v߻@?@9u_@PԋfM>%>p(0G~* QҏYͺGE0X[Rl#sj MĶ/(G!})>Fj$:7+*0MPr (hqwG)HKCY@:@OQjlN}tfliCsyD2Ņj'=CDR }9T(;~%hAQy/K9[ʜӑgnǚ!H7OO+#N ӷZn4(T·t%r&@T;c`_+ (`KfR@<$GFw8+Zң9u1,mql}h k5i/llM_&]"Εw9pDHj'@U;pΰ?Wv [11@Ke#A)euM%3 'sEE"鏴 -[]a c-!{,$!|[ W g{iAzuyZ/v!q]sol'i{dNs*JA[?ڃp Gd}vg4$'KXX+ \)@l qv-tyKkΟ.ŕO15yDP:tIR{hNX/]di_DV)G#n|h]p#y58kgdAw`v]^?r Yީ#)ޒA Ac.1p~Tb Ljz1XH^gBLhǀ j{@'!6٭L_}yL/&d롻u|XIK fR0?W4iW"&AGډ~JN'󬈹&y Exf>f4ǀÊ+R6]#E)1A\{k~̱fO : 3'QQ&e2Ty@EKop*k9c+ټih1*\1ئR~p2 |Eҹid͔e5o #tDàMT;Fא_Y TgfyzvٷO7rV"i)BIp;-5"CUkd&{[!/eJx˄Z 0:p˕= RIv6eOp [9#}PO2`آIUV,=#Q//G!ʎ#VKVjYQ@{ XёDzޱp<(7oF[pki p G0i6Ftwh 3?0єyR}2'0+uO_ַcP2&9S H utAT"Y?QU3c grͅesd_Mf" @dl콩[,TPIz^)9ULǕ]q;qР7D!d@l6wXj[2/k[n_cV6*.iM6 #YΣtq}3 DCj{JVMyf٥*g޼ת]M2crFkT&@$1z> WN[rf!{ѭ1BXvϻ+˨ f=vt^:ڂRRW/KUũ򇯗O8?ZξV1a6-0Nٜv#.57D+, ]C3R~u܎2^9^ M?3Pjٙf7=Ax@nP~'8{~,DQ0z7(uke7B&dW636*iAk GJMΠeM@ʥ y5a!,se/_mu WȠꝄIda:~ڼ^Dӕunş;f$᮲$/aؖՑ1?+ DQi_EWrS&^],ا6aFm3}ˌl z6|=_`h b>'.-6/u$z6"u@D7eqw#F<\3Ock0)Ev1 d %CUXmƵ{j& eg^R1 hYb#Lx"?#6B k(J r˪31pS@oHfި:Cq gc& VeFk:\/CKȆx7ÝՔ{׋Ǚ!4 !CyUh'=VXQ$PGC ϵpXqu#%[$x*s;?q"k:]跱]<G%ņLQ6S &}[Rͻ/c%! hNJ g̘٧<4d7b .5)*"{Q87JLo E7i͓&G&NX~ ̨pwM,{d 9FBkP47DxR g>OuWZc9z*)yQ*(>O:T k6@V7&#!^_9ڔ|OhQzRS!/3OiIv Ң3AJOars>dh}&LI l1d˃<]ǎ!Êwl79;6X#n&F:qi~V̺h Ll!~iPҹIpbFZfhOg7UV7b\JZn_yzp>:W ҟmlU⩈p1fSoϺ&[ܕ+2J1Os`sTWr'G2}Q̶q{?Q8&3EA]og$҃}9뽙˻ %1g%WX|x;bۡT 1fIضvfx&6[xyu{^uCPOuy027SYU_Zp Ҍ} gr붋ƆДtFK<<&3ϯo n0TgLPnITtۢȂ:[éV2ʨ%噫awNٴ%8bt=E-ߙڢۃ M~ҲNSI$=+)0jEY,>@>DT% u:Uo]* :F7ئ0!H7:6DV5$6WҢxtyZOJg~kei ²hz7=wbdXxcB sc~ b( Phc̾nD@+z`M$?WKCTxa;K#gEʿpb@tjr;M|*a"$1t }D oro"~φ瞴E%I{Avl"d &ogB]yT8VV 5~1'Ќ_SH"X?9/:_{0"0yǩnE\ %IMqyJYAtK`F^bnaق@̌ţ|YR8xAIñG\(bd<2ur8fȍfuӉ'`ԯI#sdኦ-v9:%,G^O sB+ۗ6a-aS+[?)UYylaFxGқLFGXEhR٨/@%4hƉV7qvaLkNb^IG֌f~h_w\}` {`b=!:=6A?i1 {6m*?F藼HdquTTǼsDž&.7uQ<#ri[vFFݫrv`U˴rK朖) NV!4.(~(3!ds%kʑBotYG|*008O0$D觀v}MwR]"z!+m7Q$d#u6vf@I^ %q$N8Z_S%qqN#ʀﺦmE:?Xtn~<>R)]{A8GPiH''P:H‡u ^^1+>F'#{gDMҽ޴6D 4Fs/ld3+@[F띆bT)M1X6RzGR[K6kk\=GU@U^P}q|kQMto'&-hz¬uryO/6?D~ (neLLq ޲8a%y Q!)/#f4%)"5k/i ̠1|%B5W{.^aY:7rǰ w4,֑z"g?)+x+~7Yj&2=YqPЊbjN 0MJ^[:xIʞ5'ѵ;xtV OGsnऻFRŖZ0ntNgNIZ4NJF+G pa葳ŗԀ̻<HFKE$[En0 aeeT@5^Q>I z24ۑhU#*?-@HξhThFMSїȻIeDh X  ՔbIL Y[}gpL-|%${,{7C<פr_VZF.brv8 [faǓz9#8>37aNփWS~+'~^`锰6) ܜ%YrC"zďA2̒;tJK( aIʦvGiQ.ɽ~O1&!y6 C5[0GDFǑ/R7BLʔlpA5ٷ?Fan=R-:[\il3S}?\Km:FnM}5j] ʺZIMsK$ l:xkՇySU,iБ d鎨H c1 ՘f£Z8ʭ} ii qRaT5!YkIGt}lahʙ/hw: { 6<25kֵiƫ6/C~0B_JAlpK&Ǵu^ŋ ֛c`!jkASIs^CW / FHxfB[3 ,Ќw-3ŹxV/gH.(P8s׎_'^#{!4I*t0IB)~t#톊V.`~ؗ1=}]W§ 0Iּf T_7w=H<3{(JIVK={-uGy~ID#`}} v_RYK0>2]i?xzP!=0g6%C{kq=qZa6ٯf{Ɋp=;VHɶ*O/j.>DToD6uKċmѮͨ0$2$U[I-kÛ N~Hk]z[>òs}Nl'^ZeJ0e01hzޠ.-ϿaSYb6* " ΢.iTK֛=lMDc[2BCe`[ѼҘad!/"ԏ#E7|rh&r@tˍ")saخG0WU؞;\%? 0Q{k8hMaxBr b9<  1S)EInJ һf埇BCȝ,8#K!a?iU f"9h B)`ROza/ [W]#&?a?GoaYk!Ϳ+i! gI^sPf=y#hx,W(6e>8rHT(?‡O>OAc1EALn ` hR}陉>X ,k]* Cl青n(p$Չp KL87דtM"% :䭽?MK _T[GSDK~^m[gdKS@+|LJ4 P-KAh|aQ~`c9ߡіwI,odO! P¸BWS`f"X-LEӜwt͙npϛwUB 0g\"ag-zi'T1lfLTmN8ԓ|qq9;OŲ~?iOqV!#/$H/պ;2~>KZm S:VcGtb\I,S#yht+~uݒ'$!#I{^g41 ,8 >w3/ʿjo?ǎ jT;x^a޲DWL %s4* ف)_zح)3(|` ,l>bk-HkI󲕝k=cC3̅$+ „iI-:)͢c5Xfg-?p&[9J:::"+]Čekl4rۤWqQR-4\~) IHN2pix. M#fzw]t |J޻_wy;^o";`8L=Ȝu\0xCK[Yμn;&g_kRH`^FMFl!*QZ^`UqN)rْuRfXtͮ`ڔ˻pKгXD\$O !bfu&'SXS#2 NJmlkȑ0?vvު#*Y9TI!b1-;##εj MFb  ?^W5p1jT׻z+!!t#v{h F@j@uje\">fN24Iע 2y+Su> B_nKX;_,/X8JqG1WRhyhf$ ktx+l,Y>j#vraޏ#<'E:HkRrNa/|7m&-Hۿ,0~ǟ$81";5|e1oz}2/p y|IcRH*lȶ 3a\j[=JL]0^yqޕOzѲ#gQ:)}PHbU`Ɩ0Nm]I"H9Luz©DI]TNG$*2r6^eä{|W _\ XT^W܅LQJa¶jT)sԙ/~ '7C _x eu`qcF-yA9wL5!ˬ(AҚC81B즱x-̲5?&F4VbatcKM~4|쬜+g^r4K#ЮQFpe0 fd@r]ph]zj`cʐu)FG13igTUz`wgO6VZ^Qm˿ɧ=ΐj9C'b1zvR&3um@xH``43:+n%gLteK:㬋|W4T]'OBI&_!m8rW=WEr R"| t+ύm|gjXjQtU\a徛nK2B S, 2<ᥛNx:Bٕx}bU֞"Oc86K |s܃BzQa2hvn$aPm~T^K(2c%|yXHR-_ӎ㮌* !rO+Ҏw啤R{z]+,41ۜS~ -B2#Nk XZ҂UsQ [u"h-lDFM', _a+3,KȪjFC:?{ZX+D@vEjY`,h]}+B9Q@*$d5xFEiN$C8Jc#R-DA!ZH4yz''Wq?<[fץ'|0L:7k}2h-!Jʾ|^PU*G;KrI꧶5&uWWJ[RܩexY6VV~&-tb%d6012rE ϣy/iDoh Nێ*Z!JT=NmdIE 3AS `7kW&;?\0C;J5%A&iҍ`vY*8L/ЛL4?_̷$آlI%?܀X䃱 u%s. D9..Ğ#$VSa7- B.iB^^ϲM"00h cՒzpܷYi"$JVGK42. jΌ s M؜vk<- bl2yYG*/E&C~%ZpZ򏜚#\cRM>19Gwß>!-=R:m0,_V,e@2/EVt!'9Vn=_ZP<-oҍK{, k n$1:L BCohr]}5+RNn:C_fJrpC+|Wt֬]L}cLWQP1dJklY.(xAU!lE*S7H' Z,~\Æl8ֱr0P# H?К؟20m)#2\bE}=sn'H -1z+2IJ4Γv:Gel+ϽNd&SY2]?)Vp-JT <&A7DkQvNձi!TDi]ꑦjʖPEjL?pk'F_D8pW+ȐNGL,^u#^O0֭d:_㠟gg! bJx5RQDt?F#e\gF}:뙳Av,  0&T]\F;5d́a$.?Q,DZe9vh]9gںC8un:%OYa+ 4pIO. ܿWыαK4oE,{e+ F^ ?I7kQ?/Ϝg"bOm?|2 n<}fd l}"Qc޿@⒗I*=(r fP#W%kflאs"zZ1Xbuo5JŽbj}xmh =qdp6>71h9GȁYOr_,^tq34-#Ntfn܆hCK9gн򔓶0+B.Fs:!t+-u1Vi|B֗=fdBCW>tIȬuWxU U}a9!~,,fbma2ZĘQWk]w[>]2z:PP$(l,z#Z}E>C|ƣӅI}LkԮu-=T K?WsYM.X۶0}cZB"EW?{S! j8/]6*FnTjm}}}J_eOF\xJv]06ZTP|o[!o6G;d|^ ÿZppEDꩢ/S*IBG r_Yi^12>cCϼIgʱI{c֍E@ DInaڎa=y3+)"oа#Ürl7wH4@&1~1K] &g{;}$Xfق P?LjA1h{LQˣP^yɟFWC6 z4tW{lz7'1`o~E+T%$=J$ SH)w=Q;F1_a2Ƿ"$(ҋ<' ||e=ttL[٬WfXftLeKXz=.tԶ诸qIa b8aKK"XV @C*.}Xmːy}~NwMdHiYGy Xcmθw=f=ių.x^'C%[zzxN3$yx4z 984ȈtJ8?b$Ty$I٣>) +*iP#23~{V0nG˔JU\hC\nR 9 sc_m:\ѶQn8!aӵFvg,|7Ma*uA;ؤur7wyctavrڀLsrI@q;$?5{iZh1%_./·lB (>=&P]v%C(HQ %$6"rK`2Z6}~^mOGIo8 1+͈} F#*[R͠{>oaP$S]G؈?䢦$~n/1 1ճJyƅ(1XcLG"4Y>2me/5(&a[-{]jQ8qT.H۹&2kX .F@|2sIu/D~Jw=5 %CZ,+FX/ ^aU5ő1֪yQjچU6UaၩOV<ٗ{?F'EGqgSG5h-7?Pd_Mfk*nDisapo&%ڼk^5vƷ*mOv_2j`Cm^d,Z d+nⴟboآ Uf \͸ 7h D~^UM^iguD]ᚱTD&k)[8n{ !4EkR=ۢsS^4PC?( Sa̎qp|uϒ8qUOՒK7QfZ8,!N;&k-~>i+N[ux'!z}0]SY!xQ*Y%?R{LJP[r!lߙAH6, {̼"~;y/t^nSκ^ +WɆR@(dH#<]:cUt"G禖N/1/ٙb,Gne0uz.-7/jN"?:`P)xnClb0W y2@ zwRuq1 iЬaIфHeMQ+}g&.~})e#zjb eiXh1o*M4`Cr qF,oj߃~jI0G϶J8}ñ'o }e@7fi0h}k#5Lo)-w]E'2j1sD|!\+^Q-[ZEܠ/)aD:zn^aȩ kB#m6_=!mL,;KH׫z G-7}Ph`F`㍄d\j6Em}t6/2@WDUWbk½5gAI1춯UӖpxq ;͑Dp-ĆI{-YLvJƄKט^؞\g#H7C>1y-zEf*QN =w1g1 2|GrFw:iqqO&G$ }Y,HпS'k2&F6Di/f`I7 1q+aN:}Hђ@}QG\Ak/[=GHe`X8ݬIVR8:ҿtϽB]^`CYv7"wsP+|/~~A5 O97OwbCj䂌=xO=S빾@_: EDqǎiάEwcz# _k* l2 P/I1xr 3J4kk]/#M |@*[!kJ'F!6.K^C/Byɲ[}݉ JҠ< ed|8BDӥY ..2N'n^uULGZ ҂yg6N橇lC|'dqwuz347OsRyևqe Y!ly>Ps8-ٝskAhӑՑ'5F@ݽ7eB"Y<" Sxo7CEhJ FpKn0=$x||zE{+LMi[Uк^φM܁ikQ$xMqNRq/M՝dK{.?'_} (J !JԀ-> *e<蹑O y)12F E}o*%NDo ۈ)r[b] P%[i.n0fs-6yl77keCj@L?J XwĀԤȰihSr3Bj΍_ BOE@]-u:\a \_EDlg;%~6!DLGrCs'4Q跊evYɦٚKOa?rId\>o~;5jm8jF&ܹP =]sb@O!?KP19G 6tT~ɸ&}?\ ^D!Va6:'氘 x Luډ:l梃nikC26W01&X jo4MCS: }㙊Ϙ,TeVzf-tY-Z!A,(Q% ! ̧1 `I=o胺IlSa@\"1L{ޟTW&Dfi|/^CLB% h/cnWدv;J?;[zpD"흱ses9gˁJTiFǯi-mPG 5p;Y}F!y[C&Q oTH Է-g槅ZBL,2GJKuM/^=ǜb:&_"t-v0Ù% qD|; ZKp불VvTFF|pK&WA筁Qq.|FR^Fa>?A`L,[^M=ocݠ? ?T/勚Zu!g ; ۞8>ٝuZ{X^tm݁}w[JbGU[APcPIJ瀑 s 5qd :PvU4NX37)vnRUoX4pź1 Bt͇LKCΏfd)ٽS採4%$!$6O;Z Tl_i6|oI̗DO?NtLRb}tSrB:}.LFƕlv [xɏ,C`ᄮ![V#>fu|-M=)^;VC:(a9rdXz&I zi샏ߴz8(}V|$Ɍ #ݷϣ1|5wqZڍOIC3u1IR%(&}T.L㜄PXyYi.½r;jԧIs)}kmG7K 牱#mMc6!qb?FYhmd j; }O? y@FsBMމ%:b-UBJbmtt|E+)AJ3l&AA"6_h lUFͳ 5l.mżL:e7-LWzT8j:F8_޴ii޸˩P:8YW?~B EL,ߘI^HuSJo"Xa_@AKLdaxbxA˭~"~ \lԶj;1GҘk'D^o,WMD\ݳ WS!5۷gYUzxC%}'c]J_|z0"%heZ?F-`dk6;Vlxz4Ff2 Ѩ%K8ҎOIG[9uՋ\L{UlwHbYe,σnFIG(IoK^ah}OCCRGeH ^-NՆՔS9Wc-n=RΓ L*2+I& Z:\VdwS@bsSu!V(pSA͢7V#ij ΋=TFȕ8g+{=pݞQ4L8Kv A{UOIs4~mBl5`W Y"^ jL6NӾPs<xmǸ9fe LOӊb b.0f*kSn.y:%@-h_xzX96N0ze[jB5SX܂l /&TΤhP/)9Oo5⧾(gd %.eʼ5YoզŮweb݈G'0 [C&6>X픻h/// \PͭC˖ HC+G6\o@zjR2K;[dxQ0I*A/ yG[fte1\Kp~hd3NE3OTZhX.fă)s.%kHkҨO[vqSޣ$/=.QdbkT.y KxeR3ĶJ& MxLdUpLZO3m2ì/,ôRg//-ӸLA*49}3/s>g{ɨ~V^6W i<թ4z_spg9CY!]ա?/Pat&O_UDn0/\3mWhek_AvA;}FGAXPA]Rdjy3b7NVj0dSf(pеbчIʼ{nWճw #鉓2<nsb}dT:1zA;R7Pd .\,jTjM܊N5[q@]# "ް=h+-rd6vBȽSdeu@X?btD{kG{ "o MJ㷉6 l$p/G oW\L^UH"hzBr4="HH6!8wOW׬tGиH@kTJ7"P.5DgX~9Yݳ1m/RYi$o$fx@t=88$;.}arȈ8iE˒QP B/h!xs ͥBŪH1`Kn\Ybi5D.}K!!,}Aj]O;1D2Rڂ a5 K4Y;*7یRMTjO>{|%Cy >)*!Wicc&.Z4Y#|. ObP]IAz%1ke7uv mKkW&R ;5@07RK hs%7kegil<3ʂ-w4\$W.K ,pвo'kd΃ivo*N/1ኀxwa@T+uB")FsFE& R͍uOLNy vvU:ғw\-W7s}1[3H795%gCp<LcM|}-i~S`]dѰj[`EdLV8]1Xʇ7d #H k2 Cʏ͚4 pDҎj37+=}~XKeLr0M!_Fyݫ̘!~Es%Z'R#{V9D݇]?SMaiEš2Jl%z!_!h:rކGIY0w:hmPJ PB X' b^7 , o?sl,#ͬA(&iź3_ bgтgZ>ɞȜ77>̪P[F ߢrwRӓp9 ?&Sr6!^]@}[P+Ү$*iT15sP=pIXE&0+6y rAI}OX}CD6k׿/ivCo=Ko}hU[DB߀=0E;t[d>^h?hS,!ij2C"lWhĸd.5߈P3o*92ňgee`V\CV7(~*S>M2IߞzBF~"yjg {V2Q!`SiwGj 9 Q>xVh+ڂjzS9&7A{-k `^4LѶfTřd_ ]?ˊ=1 LJ8zt"DV-VR8`c1} idʪi,9@qMEg̯lEr]_Y=oJ6(ڮ< 7L]UOMbC +) mBUi| T񀖧"T~iM-;5bDCk|͞EXLZxΉS ސk˽ׂB?\!8åCsMk`@?مf^!´-[aߕ]}H+c$J%+%IZ¸Ǿsu1|fA/wkL!EPfo޲vL]008RAVn}1A.,l$G X-fûydMs='sf,Xpr"1oJGpkzZE w|/Ev<ઃ@mu:ANM?8|%XM9xDL0܍K2ojb.7SNGƥ{gn1;*Qǡyr&a3]ٌ&Z(? OݾM(Au7ccp XPHD<$g=5\"pm΄A0ӟ~:D@1C/V|gmdwjEZ QV;\ @hv>@j(<r~aETop%DqeFiOxHpjہ.9 Z~Sgꖢez-*6v+dU&D\stQ`ͫ{䝭#0q˙ DޯU]4"b#Lg?jsQŇNW}{bD0' suZߋsy6]p$;q(2|g=\b5IZÁ(*gm+lvhbOqՁ/C%4>J"&5JʈgC3;'VlX !f)XNcqqK517L0ZL2.yN· wԖ5(RӍЁpH_ %e: 0pZéh o'$y0ۖ K7R`̋.z8D1 Rn޼ uz:=d[[Div\g5_9Q$q V7s%ZZBOj fXGaf j;zh3aA'n 9u8ƮI Js9ղcH﷾D^tj& `!S)M YoZ+x6CXT-A] r퉦 38zض!]q2%/Re\Dp{"kt8!51E>Թ:Rpqd68km-sbxFbu ?-hs:H򕲤$buS:k(x7L}=r tOqt ).r *48KF!Z. :ZpL(!&/;]8Әfݍp&ѮճrX }[$E)I8:Էbz@ Y8m$+$BmBEzZ"VD4rg2880=wƉn<8z$4KX ~5$ە^~z"лR(Bxے]q3:.q(/k%d z6gՒB]K_OCZfl m5 j+Z',A~׾3nCyݎ08E޶1QSo<:X Tt7s_WTHBA7vzN&Tʨ$ӕDNQBh[* ٫Ќ +Wt"Y=x[jhƈC6U2=h\!cc#.SpN:Fp#VF|'Z|жM$[9oHMHxig#:0]b֐'H?i/b?w_xw|UVq̉Q7 N{񟚂f*E҅Cr^>Ŷ8$O1ѓN&KiM8 9;1Wip%`BgRٚԵ14CyZ/ŐE,l'>P/N7ڰ+E9٦Eh.7PO2T\u: Qم5oeqM?)yԚ+tơU Od5͘Zl,^"|]G*'k4+fmT廅9e ߰zcE9 68&;BSnChQ8ok0ư\cٝt lsU:QCz^Vf]t#ӽ{z;lYJxeϺ`w}Pv>?8gC3=XA 'H<`)UK[d3Pd %941Ih&CK55tZUY83Ua&t;wTK֐a}D9pa݊[S8ikK7]*Z k^?"cfz`=>Br_{qQGo\@OP 1aU'4vcEw}ƨ9qnޯ#E î.d-|.}  `c\ E$Ԍz 4fRig!x0r2HvT6rW*~C9YdZ X.gZ#%Ӯė1#CiUv&"TAbw4IemmP'ƣeOJYǚgFRnK$ /OC=ood &6BwZ'i<ޫ2AL(6hnKgː'{M+;VtT19%]4>S5nKFg1oX /l E{ߕ IC:]٪ 6˛Q2T`~gxP1(Z1Z\1%B8sl-VCKjdt"9YvdfԒ8}9tQy ,OOS4c]tޖZxչ8CT:|F%aQ8܂tlPZ4L0V+r62pZN ;]=гD,GBCm߃\ ׷L`uoLK +k]>8=`)*pKwQif20y:!LWeN4ݖ$OBX̅Bu ןu͌!]6, { Ը! -9'=p6$44ghAuϲʗGs̨ʐfO>>FfP# @4Ah6ϗ)n>Z"%b(jgq%)i=)1oK=Dp\yYX3DR]J{̆?7H*uJuf'Ilt4qq6[j4z]M;*mڭ>7㈺yw*V/Om+!#'s?x!c~iDRƘzHGBsNZChDo%Qb .7@^R D BvZǜ4Qgƫg%fҞԯmWNGrnugu$]u4S8,{{P0hT(RPuVT.G^+9ڄ" u&s1/@bkX_Qχ=F;X"E5*"47/Yh9kC nDBy+$cZ(BloE!?ν !=$SeAxa;RFu;Y(9 -ȶaW,CqIt-淯?U>!!z@qns8nr,f_BM=eKSͮ*Jr*_~no+zy-Pk=^*)pKǝ9P\1,ֽ-ZMIOj5Vc<忎v?%E&䰶fZ iD#.#OZ,•rfW1j{IlbI57wK ~$iC o-BiOG ]a(m?x]hH\`c^h9Қ<7ϹZIsh: eN b4bX'Z`'*DKud[^{OݥڋնdeJ :,sXK7p=e:M@:WZ]!qx_:_kV(߷OQ)7+͟yPtO82[xI!dQD .ōDAv ]9]{YD-Mp^77"Z"Kv' fƊJA -7ϾRze>]OjxWN}Lz9,,@pde$; [8ŗ_>C>ƙ )9g 2^^DOxqyk}G9}|v ^n2~ Ի;P'LzFB`fbN^_)-BJ \XB>\pe͈ˁ'bfo/G]c%^LH>RFYp[&L], "Ycx z@3!ÛtDzhGHl,!ǕIۀL2=-;?(!I߂ӛeVDJxtRqLO^$Mc> A_H( nZQe)]S5{++\p6ϽX@ґS> (@Mx 5OO"}M'*C_(pVfl-tg,u az- fϞ{#(hCXr3D  )tGVM8 芄\X ʘikfK;$㤻 A~ 绥}o\ .ڙpFB|Y64Ky&,T>{jk~u72rcd `TJX<&PiumLsN2jVWs ?tK5RY`d>G깽i+~fԄ $;ʌK_rW])^+=Yi`gxZ`(bCnZ}%Enؙ}C&u+|v\M ;u>"^ĉهn `Nzs @js]Jׄ=ga:G W4QY0O :jqx>v[y@GZS .tFt_KƂxX:@*5hOiTO#ԇDUͭHI#h澨jaЉHDPsLttO> Owzͩ .by)f0kgafX߲35ֱt*"8 5Kz)Rs9a~1A'Ƽbd92vc"el#[}2Xx0{UZJ]ARK͂8I`eHkZfM`؞&G`SL7dV%yˎb˃4.6^ݼ_* Շh 8$s?Fş9T zFyNkcx{fE|Yn. 7YH-jDf>A6hD}e5*R(Q-gƻ@7dK"-B!1<#úӦj1kut[>tt-Pknt3z֭]S>2{4c+fc9}*'qTIf+yk; ݖ:"-F[ZO'My.eKMqi3AKvtS0 1cBüw[Z&;$W)Nx5hR4کHvF]O@y:: Wjx՞|$>$vW#3&ӓ TOקbNi*R%7idX#kPcYTä+2GCFߟN<*zב8kiu}|dMp10p~nj0laV&Lo־X}<໬ ;N"m@ҝŪfgB<sFʖz S:w+ݼ;%$EtQAݜxFB)#"-.9pg:&5"]j2 X k3zXjQT) 0%~]7,Jlהvڱ"sNE\M鼒 CD!>/1Wzpc[؃TKbAs%c~(~pdd/JV *J{. kx{t =j]be@mš53=@ s+Wډ!+~ qcˮtۯѦhCL(; _oE0}AU]:YyYjml~H~?5>%B].Mn<\7JXQ▢* `h%AL>^2T@[{zD#UzW=9i|q)jBL'O/WAH?ֱoRfW$y 9|)[3*2Kk<tHA~d@חa&0 %H㈃YQ[yc#)[ F?46,%C|O`R{/CC]dn}:&`yGܭ_1ܟzBTFwV<'4%.{6f&84HZ=e6gm!+OA)58% 2X?੐Y@%1ׁj@ 1067 ꇿ̔vٓ5a%yq*!0Ft+X&Л=&Y( #C⣷Giʭu hG {ef3oC5 sցίK%'C'MΨYJҹIFwGj޿j0U [z8Ԏu`qՃ&NI{3I*!+H30KA&ۨ}rY ]cF#v33w4,_ZBcw$DGV'pyn?:w.8AپA$۽ˌV ?+؟>9NHX[ uzxA-fWHOzĘ 2[uHɠcf.zTQy2 Xfe7_l4`e*ڸe 2PU{f$O]~[ulrJW[ܛsnى4)Gû rv+N}s.I7[10@]jW6-)d!jwC;qSvSYsdިٞC,c?P%".)^csKQ >4[`>Snd~Oe$=D͑Zgad"P,>[3k{gL>)8b>MD},vq)8&?3׷c+zZR~()f&jÄ܆1>ÝH~wTd;+Iv{y\¹7" k3ֈ@x0PS* :Nq־9[Bf T]婙))˪[~tȔjK`@)hhksW}%yUlz9owQ'y.kS}#t3%p[:T|Vb D^'a7RPu3]"3I`\ޱ>LduĔHtOY ~LbNl-Ȓ ԖS$:տƸ2ɿ05xC40>,4.;Sw0̒qN=,j/i% Wkސcs<@zn@ BkN/xtX6+μ@&lm nXr ~K7~ٻL :yWQMmZ)ڸx,ޭTDlyK`%Px;x~CD6t_ czG^`|Bpw]vwy1W&Fm ' 4i$oSlY5^2pQ x׷^~HVTDc\*v,0@C{E.~ P&&uo CqO'kw&˯t93;nzmT.$UB3Q҅DAn]ħI DfZY)Awij^[pH9`w\WI6K70v9yQ'6>wBgu%z=ےhUirDm&ShFx{]9Im~6=.a\[a1rfzQĩt3%,J{'c]Y, |iR|1 J-kOI):of -ԦՎg?"I-"l> ;8뷤( ;Fwv|ilvOmsG먮_BlߵkֵDDd y JwF{?9͊ۄBZ_!iB;>l:r^uv'D!N/y-0n?qwpo%i|0aWf3K,Ot?m ]h ])eR22׽Xni7+#w'>4&,{e^Ds`3;ZIP5~QenIGArhDg8nkO9V!7iX4V䙈`'xLCG>LJ3Q*TLxF勭qCH9gXc"DhR&٥I4MQnVد')[xRay9 0/7s;O7=˺^/^vج@D&%GPr=,n&Lƒi۵* *[bunb0ii˭zr0۶ Ql@T˕y,I⡹ W-;g-dׁxemSE, 9nE.^IWlHE=pƷ[3_y%&R$(4Ɠ>Td'\)W,oŪpr[5`:RU@0`ݲL_uZjRՋ(E%,$Kd]g Е2uM#Vb\-̎DC#%ձ|urˉaDҵ %s~V(7]=uByi7T qaM"X UZ@j.Kh#,oa~I<=x1:Kp6"Ԣl*!C› ΢tm[px6. E9̗PгgxmFs[k<Ƶ(1А4q!|o̼C%Kӭv3\p8$Znlfw1I~oyK^%6. Av:y% ,=iDzxؠ3\y_9T?9)i$feC Yy6+nVDub,7߬,>4ly@B<_kQW ])AẢ7\4KsEʀ9IZF.$4Z,Pr%0a5J/ԥ0IfnY랅7g̣eL:M $B"( ,P? N(> ^wJ3BYtstRCF=qԜzz: Ps_ˆ EaރkSh#i%o5K@Yz؝'rB5}M0YEJt#l :>4;xY7;**gڔa4EgTsÆSF!Ř .>L")9ÏRvH`er b4 "H~TD"z?>#@x+wp%eg;1"5떻C BH@#tix@~yll}79WiJ LA *l)*@(֊wLJKÜAsr @7R7TH]XȻ" z+&m;rpƀg4M6݅]r1SU7ذ{+B ǦNp`[:; 7J&YߝxEک!z4>U%OA1*@,N+ Vf,t n+h V"]3FSm OԸag] >槴Do TKT09[N*ZYWR9"Q.gᘲe e`ccTG-Y2hnXi %^YPRײJ)nSa/f9|~e9.o72hΚU OboqXphG=)tzlYd('p0p9B lԝ! rHѶ'Y6# v| }՘MKvq~3 ^~JE^r/f"4\ 1T8my :[/i ~5MetfKd( 9'Ex*2ͥQN5&e_ƍRa%&nłNV=AV3|[.*BQ@sd̴w(0\׆_N1,$V I_fkS[V%w\. Kp-4VM-j)x07[NnZ};~)Ԡ ga ڈ .^R+cܿd<\˅Y}8:Ln@0vy9ֲIz_JwjNJs_Zd0}PqR0ۂR-Qns\]]0+l඲dm-2y_xVIːis3tRh$@ۈqZڗoi}Mvw.3 XD *v(/{sHQ,UVtntLw}YfVhN IC"oAffNd J$5u-9hU:v`\TvdU7&&f'¸u~q]bN)0E񐮚X'2"⿥6LY! DTX'Q߫W%q I]{e+bC0fkb RMC!zEx0$Wwep W WqA&!p`}B755-^,ki o$Ag:-ܢ5&xA@<}ќͽӮ;wtxjYFj|W x}]Ͳ{gͰFat5sR/VcȜ(f3Bcc';ww2a0eψ7s4Mr:H5#(vu.Lc{q&#9W .E,tCNjn ̖Jh$iYGG㟙ehU^`vCd'Cu&`<5sg+ q!L J : ᑉG=GT^/@@Ê/ YsCm?FA&#wz/3bO[#̪[B(tٗ7*PFWz&syFQkBPG΁? DR2zfmό&~L&]B5YC;d?*ϕB8L%@0M#ddCC=IMQKSQ,5 P8L{b&zteKTLvaWz]| c!VzLB.l/Q^,3 Ìۿ"qn{L8i'.1[" r 0x}XDwf!l[!._S,HYlcJ @g8Ak0DIS |7ta8ny`;YCpuMZ>I^o0zl)xt<q;He=(d._mH;FfU\ f7ú XE-;ۿdž7f`(_-lnǐJ%UNAG;K *UB6&/6+@M S{XF6-jr*\dG2+%пP89X__avHzwfbD7 p eUŠ7w ^q<8I5, c&\N+T#@GC|Y<= .{8~]wNS>pe8Rcf)Ŗ=PT@# H<[ވp@bCMk?$&ulI 86ZԛG;;"n̰Q9*LjrVJEuT)^T>{U=ɾBڰ@\G($eT7%Az?McKYanߙ¢wh1-Cj'=sAQs{v(4?γxN)4y_5}&'Rkw ]`1G0xcyu"2QNpЪ!&ԍ,FoNOk;IyVD'2 uן=RN+ńn%`,]Mcau((4I.Zu(7]'t BUmn:&ji;ihKzOgt|G9)[ YH`p/y*Xop> .P`y!4]Ok_-,P!Z  jw\Ka55"`%Fӄ-5)*p7ξIcq՜)fY/A,A~h2UYi5zQc/0EaOo4TݡT;l>9'dJZI)5N'̗¶ȣr 8mc5 Y"@fRNalwh5:?>Y ͣVID m7|Ls,*T0 gPwo6&S&NArQV s"AC_@-3jw#"=U81n2Ln Idͮ-y13ASeZ["HՉ36E;yY]{E"0ܲ/ިgl,Vd銒"iYoU' EPԳ2-(hO 8 j'pAHq)֏fIK' z1g pyf\`M3)ؘ]@YOY ᐧ̧Z Y?)hnA9-BI07˟KQPRP:,1>2J I >s>zb_tٍE{IɀfbW䨑$мa/!M[pHI!_`230mPv( }{v #[%D[Y{,B!!OZle2OtxxuN9;Ro܇3IOk5hmDD~_X,*눌wm_Ldj~p7b@/`e{zHcE?O+ĐpN&`StJTsOaG+[pͨlxߖeEGB%=<)a\ƥ;Nz>W[]!Uȏ???ñ fG9ϐ*s١_&:"m4ʚW{/[{U"ЄZJ@'( $+a $A%.)Y͵AR }Nw #\'E74~ 'Vyݕkpa|9Zaxmkq^2;f?$PN2l(Us2$anU:cJv%*^*pH-ChX[CkOp]UMuT0!MEH,Fe" bԈK83Hri]<5lY[nlW2 ;s)a52s5x Тݘ\44c,J)SnewҿO iMr'/Xv2y|tV znu \7JbdAWTY". tgB ^ Nݥ*,cϬ3MFSck]qr2T׵ܕ,/&H\"Go}g[J%PdU+OnSäz=*PT012,`!?E>)sJzm\萳7 X-u ҮF=_t-Q!A&DPaM#L;D8;WoP?:3N\gnPM#O~H(N$} EsyHgQYu^.]w }fewgp?Ow׺Ku sq%یZ x)C[;3`s AuBfe~~Tunw 2 F*jm~F鎻M{O٩ߔ'l!A9 ]9P؎4j _mُ"8cSmY[#hVH`Ώ\A^DN(q.,q1 ?Mzǔm ĊBԧƱ*$uf9tDV3N޴PDn9;vIw#cQ90+ﮫϥEwr\CTpqX #)Rye#CDj0X)kx@cs?F F+&"#PC:(il3b_> eKt c(9[ m$9ܱm$26 Lmf_$BR*R[.072"c̄x b'JG.".1A["sճ\ÒjfH\.x؄z s7[%QYflV{4[9WvFv@7%eԕ$OqYǖ$$ _:WykA1c3R9= jd}8֧z_-6jN8Ynq EY7'RE#"Ӈ3C,NկZ)ų2`$Sz1tMROOs JVƐFHyCeX\'SrGˠK Бiɔ4*49u=1_?+`"~;Χa'zwwZSs5w6NI\S @,NuGcq\W1d!rG,&.?/'arOjqtyez[t^|gl&Yp)oK6_%I k?CpЃ5 r>b}S~*_nZ.@`7KúxI<>k&kA`>kQ3 Y)9V*#[A1/*ʪW^4TӄJ3|8k $k22Ͳ>#&ճ }@@Zg"a ٍL- ;4(}s9 ;9-q(jţJ-T.H~X5`2+\Mp͹(פo{BJh]leʂLp7[Ą |1oS-YҳS*ldgaVa^a_ yLˉ[rUP1-nt6WgؒqZԐ ak3P%q}#kh'yH(Ӗ\ϣD.ZZՁ~/uWu\K]!Ʒ5*y$ڴ5CŪMHM؄ZH&C)3!5#Im<粍dCsOjj3 5{ut5a儣7\j:wm}]KD]l\ԒѰ4S9?`)\BOOX~?~%c *EY*zo^brdxG"e=,lOH.e,Ө#&,' XsW,^IA5Z~A$9]%)$( (q7X|k]yG$(7E>5;M*>+i_-{ JBKVF- ny9.E ́ZR ?<𦊂o&,eP=pY[g/$!PU c˩>q v8iVIm0a 5%f3^{;w&^Yl9J=ûI;PO"x&ZDa[ -ݥ.帓MnZyr  te"ǽBs 'ۂ3pyPɐ.e&mU ϗz|\1GR?-#TlNT+Te_,\KԬ`P|s@Skx3frgt=/ 96kB@M)!\j=&|= bf"mԆYt1hiFfD&c ߭Qycj*3R3jqx4˷y_]40:.K H^CV!\ȹRNbBP`rWiŋHzqدCVxՅh8xo_DD c%GA+;&o#>9gcɾETׁ'X.(]JCCPtcd鄒 sTE҄[f*߳ZyNiU\}C;:~]nkܔEMHjV-W?OUVzf8V;{za8?31I jjhqzp}-}txu蟌Prg؜_[̍h`exQU `7cr7LE99y(F_W@3d:P !uHRn !ف$9eϽxQ,ЯLsekjH ik`bW(0o2=?gK;Ke4p ̘i??,,l ?GHXH/+:;3w!09^xes5iIBy{քl}!UP΀鼇dZ=6dthBfO+CEBlr18*!_M$f{VL r}:s{ǵ f-SHM (I㉲NZNڍs Omre@g;.*icmH#)>zqbsJGIC/ w8e'v #Idʷ֟;a|1L֘,$0nҰC4pqS+`,:1GJ9'X?1ru!H,C?72u#fZ5rQx|]C$*P! z~>*N\6n*`=%./"mD _0o'1=& ܻR򌻦M `\*pLq T)@0@`A!Nr6o@.XBRp;՗/F51y¨3r5Yh4&1Q&(=2ޥv=ejl>نwm%~&&K~VAƴ-D7_y췥G;#J#+pK3Dh %=.^=h_aԳPk*o;xFyJ|o17w.iE1"ib`0fZ ?` B5ǡh3NOzmfA.#;(m`cmD%l5if=K9:xiJjq>EMH "oxߓ"MӨ4g8>L9XVsYb э쇞C:7i4I5sD9x ]gZj.ۇMo?i/v@Uw" bS/oє!'NpT>ϱ˽QM4RaMP?t$I>/Bo!!N mzMN n_=aMaֱ0lmСJ䆠xtژ_4 Y< $a؆(TV11ܵ#2xL}e& p6k)~8>=/w`N,}˧me<>зKiBh{sk@GŰzg--e ֍VFS'D`TTee9-_پ {dQL^(:]%>"/TG6++6s~-@[;=f, $U1-Fu{d+n;b Q- bcp{*w󢻙|f&i豐ۯ,OH QŦHgx ̅w0ǧ`٨598xn૛q檽DUvF4kso wq6 B8HGi(v g„+Ii+ێb W@ H<=螐7ai "./q(J׋ &TpL`Pk/J+DBD^:%c0I?Sc|DĪ6PJ E1* \Hxǀ9_DimUbl F{_ k ҥ\[fY7}:)!8ηdImH͡=QJ&#ÖO*]U vyBk&0>e>jc4,ȼWSp܎fɫ@LAGgk/GkDH_epV=ޔtD\`f(M4d ɈX7G!5>{`۪b< v\߭{(PXG:liQB(qRoxTo17SzE彉MՏroD!;4ɨv&\J\=hXˆRwQ:dZ.5ntCրW`mQA"+-GQiqnBbo)~lY,[ ȦQ!ڠlÝ&T#P[+#K˚вBj{YUM{1d_%TXx =oNY#R?jr D\w[XAp͡ mV2eǕ{vX(w MVm6tEp1Rkr~' вI'&/XГ !;6y;RmTd&qoIbOg\' TGu6ln; Mrx!p=f7ڎOݵoV%1!BO7;3xf.&/Ϋ0!IDvDE 삗 sQrT"|VgtA}mB[H5YzG  ;NiLmT->WhP&#"DQNEl6U>PL_+gZ[rޣJ Mv ̦U4/F+6UoALcHע8*]iʺ%ThPv/M2iubҌhPM1 jQYs5%b,J^/|_O_6@pȫt;D/3ߠ~䌷6v.'{}2QU*"uhˎ*=YG-sfk8\^&~~ ~8 j5eYwJv@dlct,atҰvPg56Lݒ ]2ߤ@"`)Snl"hrsvq X?Z8|iY?Kj93t!ط)]e9 HY |2m0cOH"mΩ#Zہԁ#ƄE5QfWmVZmC xG0EK|!=`0}ͬȟ_K8' !>#";{7k@D 1q2Nrh5RlұX4-ZT =dΉ sT݀ ߊ%%|+e '>N('Ms|76*8:yyaR+{"8`f 7~#z-{S3"ڳY_fR'I\d7dM2pdb윶*'Nc-oTU# fsP@bp1SuFH1H%h3&ƵuX.Æ_hFZWtzfHvÖaW'[IvȘ…6ױo{UIV|^Ȃ!r{q#/4Hn0]oMYGmXXR%ɾh !1.2HS"nSvSU_"*7ގkHрGSDrOIYm/RzF|?Gۚ+smPhu +ΐ8v;{[C @mǎ z;D$8-p/c%3ܧD=J^^!dWRs `w 5%RuuoϮM=r&W'T AX i8ƹ#)KA` vCm{GfL5+L.iUW4 m)C>~LJU'Jaޒ=Д=̰՟MGsȓwm m-ᎏ0-ѬX ܉_p;WőѨi>TGLdZMg;mu@ƚk.fܘf5d5&nS(cgRx2RnSdhWSv`Z](A{wOInI=ԫF棟7^<cqa: Rf =rviʞ9Kw cEKn_0UׁT[Ɨ qصXmn6Z_IKVPȔ 6l~k{o~IcOl;`[<-EJײ'! P Ko` z` ѧRwĒGu_cb&Ap2CxYصO\=3!WCMGm->{ F=JQl }0 e z_r}&hc^g`!ώ ęߍjMr5 j W ;z)tЗϰVcr0ZX!U%zѹ[$Alg'K@hHO&Dfx_\/HB kK\3|׎tAN=M5 8f2B֋J5:x*o]ޢY=5$2I(ߕ|Z_RZ)1LGA6}/ebЈs|5_i25Ab6T p 4_]W5x[iΛ*.abYd73Zmuˈ~1{ڵz dtM*lٳ%4\V/""3R>([TyNLB%/@4zWQ;GnصPF"nSJ%iy/+Ppã0&rб`.1L@ @Ph<%3 NCg]ޢ^7YOp*Dƨ_ 2M3]^4S8ГT] !݌bο:#j dIuIʪ;2 k?T?c{cALE}3W؆k9I$j%ᦝ\'m{&gdy,O#ck˧e9C+A g.FbV`o:M -Hl8Jnw"t|x{sHTW\'jL i0s9tnx;?\*%ȡ* 6"hC77]Qѿ4X4O|2ceޮp٤P!$i7i֢d YeUtZ%6@sr7(_?rd<:˄hr5t`rR)iFʦ)4J7ؑ[3Q24lɳV5#fRh.+`%MB2ٍh+mr}ydco1* *Bo,&ڴgW{),)vtk,>:1'ws+.=Q q$^@t5d!pj l:AVOSj%h3cULC0S7D~O!E.4F*1^ES! ^ ܝ DYDٛ3Vf۵$*.6ؓM)W71E\i]__J2|S#V# oFyJ8d{-ɭMfv=~ :gW\ҫ|$s G2'ks2{#-Yz ,3-zI H)}nE*iϜNlKxb;2gKzO8qӨ컟*Sh3՟k=i`" H 4vuyņDd$ncO詡TKr['HJ{KDvfK`6??`]@8:D8=}S՝#$1sP!Z\pM{BgF>=/6Az;-rz[*,%V.rg򱃑ͤ({`gV d=}z$uTAs\ g3,6?*[Ur_$ IBl G!Qڰۿy{JNV~:$?Tc}֡:D3]2jraB\GʰCB=Q(-,O`t~\[/>6[!V%FO[kŏ/ׇuң=D?&u1|գkRMQTJ YXCv.#nU MoA/;,rq5Ԓ1Q8TaGLIkL&rbBeXCcS$a }Fw é>6C}D_3Ʒ ٫?'G9aU^fWm{VXCTZ7c嘔!g"̫޿ZSU<ոT+*򗏁پ$T)2j4ì{D0'[H+XRH è}"hyBABsoXJlsyf(-iH W;7G+]Uɵ1%vpqo`zS:O0L*Z9í聞W\72EmMsC=b&)ut|j,Yf7fJY. X^V/l2 yv wW 6L2&7]j;2gQCu;ɟut|%&58'F륛sREl{θK"bgfY۞ZykrÔq$7[eޠWC/ 2s 0*}>aX k9׆~ Kzu;Gm.,4`UAe2|l`u`DUÃULn>s{2>9gNR}\d,0IdFB4h M=ׇ.͈A&TGAŷ@z\,btq^ n*B,iͻe|ԁG12P:hC+8V*p@!#]PY61Jj3w:J*K_DRֹ|觎]n&~l U$[2_+#@6K-aƽi\zIFioYw[ebRxs Oa68crQ1>%hX&^1MHu'qk+u|#M3rb;\%) QQ ZߐH4"i[ݖ+) H= &dSk"8̴Z%.uWnKZU cB ESk J+{mڴxUOe N{yb4 ¸1 3[%Giܚx;/5N8 o)I JO F y8#*tMu|O \[V9`Dk*Bu 9nC`ds}٫Wl!1A! Iֹlaꩈ2}s v!$,(.ȞrWvzsep\"Sٷ7"; ǣlu?22Ut٧zOG1+E -7ōc1?+#\11˪y,mI)mB2*26̥f9 C!̱nqEr?w/ZH*HN$qFֳT!>-8'[ C 7,o٩(U׀%;,tdASQޣՓdzQz7~Y -^S\lùΈ\!60 T'N[wGuM7xU* sv9!u`K"4<tc qH~xR_X¡" IgK1t}.OOD_TL"rsCҜkZbyT) h_*,M.q9ұU yc/νa2Σ;# Iy8ʄ鹌Z9$Co3* )@7IUt9bƨQr* 9pa馾} N* XF 6[ˎ|unm8y@[6pJ0F43)5%v t86ME0}|ㄋ?˪Y'eTA9w7( %[uq|/}W" ˀLŹV͙g-| ^rRƮ"U͡p06w2Ȼ5ͿڲxxZ)E~i\ܫ5Gҡ1~Խaxغ}tTcP8/6X9 v%LJhݬjJ ks  <$JsA\|zd(Uo_0^2+\s@m:. ,[] "yKpbzŜu$,4o_ JdUJ?26~,x}%뮂{"qҫQ'^8̽?cDfLɾ ]+pNlVJzcBqGKmh36SR;U3 O2ЁpPˡi(_*ӯ"9soil@Nገ5SyߥcD&R!hnn_|gޣd8QO*m^1&`xV9amE#KZ3YGM-Ӹ;5s/*9yp8W&y^t Sv[s'xK]c䡡cH|:j6;`xjᙔ׈{5 90GMb'??GWz Ye82KhyQX ="R<]FQ\'^TI(o;v? FK=O!SYi $a2C%$0!B8p x70E%ߏ T-jK)CנO@ Aw!9gnc)$,!s`)qMͧϼcN ϛᶇcw.-t)#)􎶻MȗYW8O\Haރն}AH<;o]oxSm%;쭏[r/>8C 0|! *BQDSʝ /Pϒ͔*>-V h`?t+YoīϱQf kW,Vb78Y_[ed| _!ǸL@pO7hZ @0E0OHVb+j3[u?ʯ1B L;P+єތ"?%Cs rv&NW`.+U \} h%:{V#هŞjTz3*ouP<$ QV΋4\%zM _F\;_O*ι@+DYr;LA-{<88T>]XN*5H!DV}~J=N\F9<(,;EOykg,Cp\#~+SiYVĽ1l*tOSPL vNaV;nx‹3OR 5p=ς>sm'畈=j5)is2>)Dp( K펐aXp hKvMg|羭v8@ڋ Ǩ7k,qb?)UDi9;顳]G** b9teԨK4lYML5gi)Ci{>Q-;1E\xA<أ4 Uw%hM8[0=3Qv$髀&k庻=OЦ{6Ep?'أvDԀ0Bu|@0PEaƿF-N0yKlB 2dwE~Ndw 3h$3kI=ak D94 UC۩1{grЏ3t%{mE$3ыGOar'8!~ը7!NlZH](J/>)ǬSVp\O[ #}:^3ji+rUG \3ꚇrì&p=|8f^r/˽¿ִqMFkvN{$}3!CCǵ?"!p=Bȭ[[8ǔl__!=7Imd >$A'I#gOh֠W'>CA1'ϧ.{%V`mK*G: JUгa*h)Aq >x`DҴ} #IA<FmU5W63ɰZ@c#,v~a÷ud 7NV )M,uTYZGE; qtEĻ*,Nul,=1e+x$0xf=Ȭn7{N qظx%\5; nᵈP'<"Dxnن܎e7j]7hm\^qT_.?&MԹEG nfpeN]j~$cI#5yqaRǾL -v(8IOq56Y!o"Nj(A[7HJX(;'o? Nhm{8(*,tIXukKpn%uC )Xh{ӇYϑ2fU4tHoߍ@/h0v;cNܲQД',&D_Q].s +Oov'|MŽ-eF+T$[ 3O\7a E֒`*Hmb,@*9) /މ{: #lCV;[+*|3m:'"촊=<{ꡢ}-փd&C rXIpDJmmيBdYr54JGǬ )|8>= W`!i!$iVJY{H;H#|v_! ]69eVI&dl Oݾ|äK%jY|T $oFxЩ$wwYht&Am =@FbGCz([L/i?\wJH?1Opv,֑6nEb(BV!+qmuY ΰkYw.BTD%,QU;t7s(e$,`:ӻ0>gא0Trv퐛ysP5_4J6}`y2pe)?ycLo[7X8i'Nr@)3w+0v #1%I'w[yg!Yoi]qU(,`<1i0%;(sCsqs7LSˬw6vLh;%ZcScM[/Bv֫y_Yˀ?0{tta Nc 3K2->'Zne1dź8q1B#Pfʓܳc3QPw5(F{YlTe<ۥ=i"TE.q#!<>}\.A)5a/=τS̿#m/&5&6 BfO6eb  |l3Ym:Q`5)2+B}GW#*X6 M) ?z=KeՃ^r 0ЫI;6,L'1-@E"͍xbmuMrEk ^C)7wa ^vGґd!TO_',ZUQ4 蛀mG(]Ŗz0WhuY 2`qء~ͼoWCN*HdTnTv[ZbF׬H,/_:kTBPIj ;q$ kݩgdKRc]{VzA/c4?r2's&uh0z\zX7»_8Wlpv5O4Ow81̥ ~2QZa]d`'{Sv/7xamn̍;k!Kzv"b6SV\%_&Y!>])֒}GD(Bڊxǔsthz(5|@i@~UN"? LӾܺH@ Dpt +yj A&1r]&Bn`g:mcE{ƈj1A=mHޣmtɹ>kN, %C/-c GJ,U*BxBA&"lN^fhQ v'D-:f.Y:kQ-Tÿ3 =2)ӿwzƗDW(q`9MKB!1#B&a(Z8z&KUe>ݯel9ZD ᅵ"Ͼ5$Qo沞o~zJ .%jaJ!$H[xև?ߩ(szLm"82$@KFUhLwL,#4V+6oHcUx HOSʇ‡RM1׎,;z †~%.F`vAm*lġF{-lOВgrr2{g# u g hwP ScۛooK)D.i[ǟ|Ə) M5U]c= &G/W9q6n,#ÒYp:ri4o۞nΣ3,&R5pXWJMIb/'J"LO8{?zxhQI"E2T:GI,\r7Z{"ùc}X,0j9,:틽" QazF_@K2>QpjA؊Ǐ,H[}\đ IE8&R3㪪sMfAK?c(ny~pz1%AM؁~?\]IR~\rc|} %hυ==ҥMƦҞ8`ވjHSN_\ vZœW& as ރ+sx& Wr}@v/+^+&rژ4|hعCWяOmm* \#+$f}dH[w~S_ vg~C^Ys.ӟbw% JȒt*rilWIe gL8*tneI+g -!V=qӰDՃKzXCnߋ=r$@xPU"Ƭ&rw-,_Ok3[V5Ȧ6IvrjnDI/*!V osV&Q7p,5(+G۲8w:HVm"߹.Ab33~oW189Op,ٹک+AXBgO^S=es%aY6QS\,7.Ǐv9#oPL% PoNJy*߮w6vJ yȶ99I9C4Ԥyur߁2J~_iv\ PǴTAu|_C|^^nABG/R {F`Ol \lI+\G&XAo-#".1%qnH13:2Pѣ=J>=r7Z@"&lM,0k\Nz*75؁T9~ m[(ve DW7xi1VchL5I}w WRZ{.WyEhp~7B{SF)Pd sk"Ia*(+Q|:A∅%. thN?Ep ^ïPW{Z"kE`Dv=%zR~y1 脍=m9GXW?<coDڇM'xkjlB2 pog2V̟SB ?OǸ2rkfb0  2 ko-I%!2 hsp*t 6PqeNm\(q/-Z[$B0!&gϸlwtIm"LgZIΈ6B)aʖwH?>v(+BfpO ['|uoH;`GJ{MD'f[->EJPQS~՟_ Mr^'" $ԑIWE~sC38;VG9`qW( c\ns1B!j=EmYIȰD?7}OHDCG&/Q}X83y6-W'bGtN֫+զ4\{K`bC [BЖ>ԥHcvokvPa|Ej[!nv&33|.h$uuţ#0Ti,YbO ғu_f_k"I6HX?#5P3bv 8׌ =XX̥1 coYN6O[U)[Pֽ>\Ğu e1uY!%fϰO~pJH-pJ`HV)<~.D!*T: WsGn`"pX6 L_]]>a zG N3rQLr بTeNX8fqgA]y$e &t"Eߨ7 @G^;)A'd`/lc ;Wf$,"+H> g/gfM8R.)Xhe♲ g5ԒJ3k0BZrWù_[˂z [ .|hj`!ɄU3,IHضtC@i0Ut2ib# _7;ٝMu/&E~A2Q5_ /TO$TE4Os7Ro+eґ/tDLmo2fgA~'V2&9wbr`+jm-5/#!ie\r hc)җ"u^{1?Ǎ?r4$$/=z<'~9fx(;G&.b ȟ)!dC*ϸRG E=HanNa'3^ d.L̓2(ex% Nq(%n9bN %cŽ.,o.Q]BAԍe N4Yj p_a[AHgJ,se_/=XףmaGik|kU2.kNdH<$ $ ( ]@`8넪kH9L 8PؚyIeO"?7gt]C7̱S.<6!;NnS0h&;#$b).]XC7woS ~hPTFF~&,  m((\zDTh2Im+?ׂ*}T쯏4 @z˛JhHGy 5"чkE)C~E<1D~O7-pTdQ5؋U>ܼs! #ΤOF{>i5[":ƘkZXrBTtWjZzw!`DzjOQEɢ!Q nA'9\ǵaBKXBf eeΣ߰.ݿC>d? H/oCAp qv\*R_:ܬp36p+V\'&7kr0b鳾 ԩΏݥ(_Dj XhDGe1:&87}xfEan!zS9yQtWqD>l|~݈d@jjOZ5=NY+>Y|0QmDLkL[,%k;[_">_Hs5E b ݾ(4џ.sJ{Rx9|QLvq"6 M.i.qgF0CG5ˣ/=]t`{} 4\%q ԑLP&!߳AS@/cݦ]Y57ERSK v|Rz- уB267ត"SqF{w-9TiX Tr|CtHFi_?CoVX7=/ 2|2B:z cV_8ُLEOq-q+^To߶/# \x vP/.]ȇ.˥>U ͘4\# -'% FY?ׯ6,`{9I\pr 8bỹUj! >o~B+FKpnkT((#D].Ax֠tW`*Myef03A̶+}倡3f?BS$7JI[HZ 7It"n%ʎ9뼲\JK6p acԷo!UԈ-?ţGkf3g^F@a}mA!O\/ "uh6rfPCۇٷKc75f5l?z yY`.ml $)gŴn*(@z"7wX LoJ(n/9<#ɖF( υ\>`G" pL(dI(2'.USo4(ٗE`/ﱁv&صp)L!zJRLv$9Dw? e9mJs}X׆L1ۻbWl+7cjsm6~-w kě3GC <6LoOQ_A %^ٿ)^_BY.kGX]p:? icEǩh#_ZH]o4+y')~B̃aLX>[ĒPic &Zyb^HMX˙Qa1jWr6K3@_bv-<m'ʧY%<yR}W^ҭ2]@Ј'!k1֨5ny@h~MEjlwL͆GWG wWj#%k%+"x"u1p;c0R@WCa5R*OGj훭liSf0ٜR Ia=7;8AKJ&)ٮOD&tjAO pp)3a_A"3Ar%i 9XlQ8!&*n#txj4z_KȽHB3[g'D_|+Ϗ|\| \ز3"&VՂFp{"w>w!uLa@5+x=I$!8I2뗀rÉ G|2a3XuvZ*.y+pTBہ6NOFJ<ծˋ(T\$!΋(Yl23 56Jp^$QrIRRz+KѪ*'ի͖Up+f$! $~nj}?_pM-v;2VPyf.<˛_-tbGU~dN8<^Bh;R50"(H-295.ҝ`[&'q3"?] 6d%E 塁v\A=Omfr@ko8Vnl*./T+bɽť`Cvʢ\[+Կ)_Bx(I{^@*q :H`ߞu]9"{4#3 eZ|fl#rPd10YyʷUoQ[(]4risOs&ܛ?{@{"hN < VfGꏀR54+u4KdZ(Ӹ;`Ή.so~!0+ۍq2dQF1<+Ss6t;Ff sc%}2-1/@Vyׯ㧗om(0\ ֩!G(2}|9!SBms蠆.t[GiU);1%k1_e^ܡ*zh9pkdB]LeC,0*$7Rta6-J7Hw,d.fwuc̲.fBѾxV㺇yg#;qEqQ_ 92Պ3+" :GJ]ڻmc[!EM+c@pmPO틯x1): YGr>0s@4@80eG%AIB_4c:qi[Nv RNfwyTr=t:k%Y6=味lqűPbm {o٤Uw)W.)A)?!|JlKZ@iɧZĥٴc+0^2QwLdh*}c!`kS[6*ćp&aH&Qp()0}t͏6?xr:*Ga?~ިT> )){xp%kߡKV*YG@Z~@R4pϪ<E~^C$3,\a"#/@Y5($ SC/mr*ADCKq4B3C,4mU'w+{gr*$?WmVca#F׆t |yIfeQz +zOB@=Mq '9 ˰l4O)AJבAB-8cg^;.ESoEv|{ y#i= Ǐ'ug_h7v{-PElhpf'B+qso8MFG i /U<ŴZy%WLVypl kg6VSPS36kN֧ k4V0k5[!F5 {)_!xzT+‡u5S'saiIm5vy6> 21;%`e'r`A]=$Z|&\CnY=R@$GEt9*G5 : D1fz80^9w  CG!'X0btX2#FcvA@F<ģxkNv!Ȳ5`Y6WN:T/D.nTe Z* bGb7g\V=Vs[j*c^*9^ql'x3Cyvul2꯺Zubi-jILҊF&1x ܘ0ɉmod}RV|7\Ah`:2=/J^.IQt;R3`^n%Aݙ6c|1%o ؘòNQRO?h웥(`f ~zˠ?0lIW*I+ޖ<ށzh]_ZV /[ZZdYnf4FPC%yH ZJ~FFi7<ՏaVNWĖG4)'glbx-1' e_;*ۥ,Z黭$ϡ?7 'Y:Y <וg1RpF. |Kj?~1wST*{80]Hr^b[8Tٿ@ڽ DX|D}6F3RD4G 0~MA%pT5ؕ~5A3EcSD*rvW=^(}.VvŗMj%%xp(Y'M'a#@M U`:^.5ԛ]MVal=,[/Mr;5+ H(s'離Hj/dj .2j 1]*d e)hl$m_R`N r)c-'E=td"LNΪ:O+jTYo-0C^b|018􉅈2.ks+1 #XcxMc.EG̒yH9CWUcд~+P$n,0I"Cv^E\mP峪Ǯi\gS 76*𢿏>/ e-^ u=G#x-aP1q "E䰵q+k/> .=]3gY*h n.#6uI{,8To\R-{"F$c~I9QVfq_Y3o%m>X.t`@Yo.82"$͢z9sp/BLc[|~A2'YEj *KK3+aTGޡ+Gz 2#i&ߦ{ t㹨 A";p;tps ꊽQEbލT` W=A_9T098\" $%*x N_ @5b!qā\mL8ݔ=Jt [~2k| I?=HDV\ B0*tcǺ"9hq˙J֎nP<! ?0!UuHnӒ(Zc\d{V&Uek/M7mYl!x:6: !tҡzNxrMc'}U1ְLsT_i 9T'ސLӗ1ֈwAXo׸bGb9\=+d;(Q,>`vmGl2./]9Bmc-gUt<:ǠcEMoOܞ-G3$QHR5juTzo_SF`;3xɃLФ#) \IoTNw 2eh=h=GgX!>Vxy0K@{A0CL?5WQ >wُ̫W9fD0WҮ摋aOĮ{67 bm~t(СʮNPa:S#jD/v?{Ot:31TN3D mکD AgFή㩶l`$& ~,ס#5ʑմ8MzF0\e^JBu1͟SayU!O/Tkfj"\v9 .EN]_NSB~wL8 dχa`\zvO-~A{\N;;+%G=1|Ka(;ԇkZs_N.@u\Ɓ>͚pRGms$}W@[KC*!"Orx8FI9:FۦX=QO\pT8; K3cýueq0"(PrD^E=<XwgE8H0%вpQ޷Eqxv]7ɨTn,2ZfGKNBW){>ȮWoMbDd ¤ &MFP#5GU y$akgK#(#ƐSH 4<Ům@AfEkD12E"ԛU<Ttnn~D>Gt\}×{k_\eďVr(ffV_@\6aPܻd'bcUcd2xϢ_eINiW>L") 8k³m`:yйSrij[#O:oͤ~чd? ?փen]1C4Su h?BUުi ")ac2HGnrA="Ž"gNLkx.5 ~~пM0XJw5QxhNFt

AHp|=upG^$цK*&VZef*o e-WpotD;j<Ƹ! -FW`iX _)J/_[#]AO4H ٤⎝n}E!VV$5Wm9_\hԶ|ŗa=Ne5+/dm}ulW3GޜxH0'Ey`GQy?`.rLBדiBPq_BQ"6Nj'nK<{K\ !m ~[hrʟאָY&~^mӭH-4{Ƶ@+)9Q߃a!}I~?>4KBWb,§m ? /с)~V{R]p~G{ߌ0B13(V*5ڛ<{IK8>MzFqEϽNj/P=E.?) x[vu@(ٱ3!1$F'9 moNS+[I'`nN~9)3ڼD2R5-8%Em:\W=2blz.fȦ}%AB(Ƚ<Cbb6E4وH|?\Q24G]<)1Ɉ/st\*v5钑l%m\/}mqoo`O_4ȴLi&DdӆV:lenYG u=HG UI ؟x L79啭4v y[dolۂ22K; q7ZMP^HQ)>dZ@t-b} fY8@_n{Q'^euK34ZcgXG?J "9'R FfQٞpnը2A(ntgPY%8#rVZ5–\\;ʋ$`2 DiG NpLDk<%xQq;/,L|dǗQYq;10 ,8J3#֎}CBQ01ThXnS$Nx$LmT5͍QB&$V'U|&!Gui$e4 ВiTo4O094/ czeJ.yjU])42 'L*o LVy[E  !ү{.\U8^U]f+BU ,!{ - 9lw 'vx3`r(Ƚ$CNL{&|e^mI~w@$G?-hdh!)% !xXI)!W(|Y;,;dJ@V>֙ȶz%vw%=u/h%Y73+!x!CcQ6{`&#f~纯 D7! t,EεV!&m b8;ThGωdό1}n x37~W"iH U)d;e|ju$wy@%1`̶_6S&8?>ZeZ/'noجTf_K/="^?lmNstF|~  t c5Ǣ*HqVh 634"C#M(bEu+d[Ź #o-VbU!h3lE{Pf)h.Ԝ dO%SY5H<ӝO?"N$8tG ;a>Ƥ%BC# π&L4EqbKj2<*y$xc*JW{A"V%i6X Xƹ~ҥ6.0bv<˚!X@@@hOTٷ {9~=6⟧eށL> /6Do ZۙS\ Z-.#ə]Hgopp C䔻& PnCHWY*vy8O~Ƚ=B1>m.?%EUbB޽6)4܋[~:L̖`Ti(΢4$I 9Ik&.S3KUhW%`h>*u9֥ pY̹*f.?!r$Sx4p١#ڷK):%>&EXkV%!i f>/R,?խ.nغ(Gz15FV%/c®X ~[^o;#XhzFPF=_pй=<{R (6Wk[45sz.ړBk )T7!;Oٯ$j|w~k܃sqWLu.#/_.T@~v-3y]+YGEs'?j'ft̀ [?'qdȨhhgˎIm0Tx4T[EKd4 ZPt a-PrE,⺫QvOjVI! fY#DMC/$༵i`i|+iER01:L<Nן] 舨Rz :6?yI>G`k7k3UۖJξ6W']sjѸF\[lکEf]輬R"3uޝ<%mqWVΡѦ4 VO.jnnyn$LNh Z"jK~aQ3*c]&/w9df1-S rLrNE j&}߉:szc| PΉ|'㷧+o1XnVB)m,-(^~k^,.odv#ʉ0ȗ).] pe4d-2-2Sa| 0#PBH3L:3Ele Eq.j H*9gN{e "`M5˄Jo0 `pYP(:Ԓaq ޢW1"h|KZиFt\r7 b.(>Au.,ip^bZ9dc@!&[vM@?#06Ӵ2"parZ9Ry]IRߛƣʯk^  UI©0]@v[m{γQ(ZtYQ%VK̳1Mၩ)Vw Y$yDQ-5>OI~Ml=XNy767+e+F\X>Hvt%7XE (\'I0WrnIRLƯ,M]uɍrsFq-<IhIvE?g1ս6DzCGo%2+{yU7a _Kd "5Gu8XEY=?߹Ӌ{[qiy#:%L̰xp\岀&,d;"l.⢿NR^TJ 5~xAncX7|E] =@d`D4W`H`Zdo1&Mu,oη0CGT@"=9Dl3VF yKd6Q~'5ïJ|j_&H6KWn}c!dOJWD3#|^Ends_>(?1 7%y=W+WЯLr"f?Zl}R$JL- 2ݽ^HӄД)R I 2ݳYf#m1* \W[zClU&;~g$ÝCuE2IEOw~JOf-?6C :/{FVՅ.^B=hS~%UB [⧓N輅Dbt@5VBЮu-g=V4S+Q9,2*seP#tbJi&G;D,G=#$hM% Pj6  ;wkTЂT-iŷZHH/!氱P.VQǐC1tk |IOa{,c} L.Txu.G> Yӏ^D飳8b6F[ {kUSy9D~ y ôTs] QxZѤk+ޥe`uTV7%QtUv#珴X/J;^:,TKI(҃YQl _?D3}7"ޔCysto#iZs04=aj BXGw`bL* VZ'k v {mb{ 6'zI\6# 9'VN]y)s[@8@6/A䀘ըt2]d6CB[_EޏpC wEWy ᯯofwUvmm@=23#W{ L$%CTE ge*Ha~5^hجx ѹ3 KZW41Ko)0xaӦ 1FO D(e| u&ȿirzMOWPVD}7D5`gyɕ,6dƀTh1̋bSix#Cdh]M4>3d|2z2Ȼ7ؓ:nꞇwΙ+LEȅ;?ۜV^⫯! 'y)k^OwF]!3w$@xx#Et%B貆C(R>(H9iNT|fPb Vz^lJkUN8#K\I/=?H5y4 }:ԞD$k)r+V?kQU6{cۉ@ {~dek3z3įiт 4I5 $:k[tSvxy|ˤCB̂S-pe&̟H,-ʓu.F& Vw}I"EY ȇCH8|seTrqs"!>¹; #F 9j,Y647lTfMGJ'TYL,ʚ΋L׉ ΎKޝr5a0A#Oy:(.^ۀѥ!ZiK7+Ew1hfw'x:Z!kD8R4.[jUkeXc,wyҺbSQdY\3\m^VLdk3_s _?8 cY">>ώ-6戛j#>e},U 2C,:+a|^c!eUn^:v(q7nɈLjnr4l6"b=#$I:}璎*ernmv?*A&_yI.sL$0=KAϼb"Z )Ĩy'ƍs<#lI\SouDΒȴ9s3|vY@Lr~JW o/u&5Hr` J37n4 Jy]yOejfŤĢrw,Uk }Wg1̀j= & ܌O]2Nhb5Qu  H˥q|>褯fw+!{DmN.I"$RWu7m^zΟЈW{Q39ؗM5g3e.błn)0=x}Z epDĬ~EJ䁌 ^_hYLNZjcO*V71nE+eOXk< B(~ @H ~rz9E*=7 CFgw+/4a`J3vRӢSJ"Vg}]u KȄP/m.ESíWnc$^qI=bb"MƆ}*0{kl%z'{#7 rEISS=Xj`&y}X5)J1 QA礲1ɴS"2\ɋrYrqr=f)5^S*]\IoNY/3't]4anaCufd`nIW,40u,P]i>'SR̳niʽf=C1" |4( u˱g (tUIOMD?  ~W  tz6xJ>OPh(Z}H#'sCe;JhKzI.ceH4L FA%8.+'x. `Z@9oV2zpozDDny<+Ѷz6Zs0_ãOuDs ?̦ctJ4L ,Ѵn!%!F{Df2lϠޗA, ˷Sr)Lkfv Z  9dW]{2eHjW԰_`wo,a}ćUuWWsGJ06~rVlP*;.SQa tO5-\].ҵXAHzN(`L\8ρn U 98l) m%qUUp㮍?gk%c amkitG =cXa"ӌPT&k [}rOj[j )T3p>E-=u~xw&:<fpiJ+{,*ԦHr%kvn3VX f5ItǨ]*]UM[B d#6~.JCYUukPAdCA2ޜ'g.Z~F ^};!ݭU$}Ja|-bXٞ9Z<<9܋RV!صnȗ>(j(s6R82$~^P6= sZEVq;(.f)as~;n3G~2C^}t<vY`iVʥף HQew {UI,mMZvߜ78&y|cK#~M &aW؄zHғQo%̫*Xg`7, FztJٍ_60L"t> obi}wx*$?j-rQ$kVWa6BpߦԠZ9zZx6 bm >^Y`/d>sRxk2rpJ &bwP *8~u)2-)GL|y>{ffR`k.QӜ=u_:xN@<9~Z"GaO"K]J'z7GZ?SG~i!(vbTH&Q1(Av4kZ\"e?db+]jr _-MIPU @esyη:Orcwf@t޻RY(&+t2dmxSJ rX3CEb'j (8HHx_ÜѬk7Cd9uS{(oy}3 Rdp3 {܇.ˇ+!jh7d.<0õҍq{F]c< hPJJjWڐO[L[vLVe *qi+g,Gp@Wahq3ڟ/{k}ȅƱ"*n)]>d AXtՀK$^*WkQ>/ lc?+rՂF KER"v&Y?*e/s0 Ry|U.[96=hY}+,1"0h\q:}pg]ML'oY)Fo?;Ou.3nPklG{kZ/`nK!]5I쇞nľѧtA6j>LM:r|j@DqH| dA7dZ%9c4ot5ٵQjC/1DÖAWeqgH]y>Q2FکdG\8̑l^x Gj 5Zvn6B$U6*T|]cYxKk4nAMc%MK#4Cӏ2*nI 5D섅9 KDJ90[~}n 3\$'4U~xH $k_٦`1vyxރO"6M[iK1ՄTRs[X(ތ&)6StJ$`@KMX6ﱡ@7Eb7CH( r3JYrҦegumQҁmS3J$Q9!7"|^mZ׷= +Du^dS_U z3×)YΚV n}Yǣf=+XԘlkc_t$ 7$ #"P/Ĺ+AtXp2. '1 =wA4\czABi{Wo *@\<㟃-ǜH^"Uü#,|)>Y;r֓,4a{0Ӄ6G@$`zNV'#ΊI ifx gɅ%,_w^cPiM efsgp5Vx.2B9<E$#d\-ro:r(W>Z[aT۶юps.\Fr^vE>,jqmnvȝ=W2>';4Vy+yϱ#} O(涐Ǜcα먯j=CY?%쳏5A\fTQ<~Yagw S_́2qԄæTx0 <}߲^=^՘зcLG;IG 6ņ6+OSSΫ4at_3b`Uc.,IWZ?֤L ޜ2(SVc9P;dð_pM`$xo;G++J];y 9+o8C()x@eL ,tlA͔xJ5U ,pjF(* :]Ơh╖‚ r3`ǏújsAo"ce_y߲LcUউ3Ev7@mv6y~L!o&)(ɁpX!Fib~o ,ߤ{TE;>.use=MJQ9D:Vyd݇k+|E,ӳ+1[F:r,or;\~BW=É`pI 8:KT.xE5*e&YZnHcɉrSksaҵHfpWׯpU̱ 6i璚R@bH"-&[Z7%;HRaEnbO)d\|UG/ϺIhf xX&'J')Z\Vx7oacl*[2z+H넕7Z.e9n /$x:2p2*!j4N y) OdHr&/#ڿ_-B~GN`Vr4\wWZ^p6gjׇA#IDi}ȸ)C1j"s6xě];$ݦc_8YsDži;5--x['Zۘ70XkP)|@W蔗D.ޘE*XQo"xL˘vؠ)*"z_^8H,XW(Pnz ;k8/^&-%W eۇzӏ"aC.]<%m!HLz[&Vix]V#Af'[֬okV0ʘ[1,cVEB& IP gqW?kafY[qL3e2 QłirxۑD&;·^{6ޱlei,޶iivDU/ڦh ֢;y9J6?,/'x˖XXZv?]DDF`uvX]x`4;yZoU5˙DP#N9RKK:M:I/JCu,&@zH!w.81;EPh{G:obZ/BfxSg\;*|̲ݟ3uK|~>paL+8_:u`e2xM% C_BBt_xl9oI!\dssf{ WC^Nɀ=FcP뎍wfyMf/| C78ED)cGusSIIWW: Qvj)@; (8G" Bñ]s҄ }t.g+Pèj?:RamTN.f*Sww@n :+R>Xpo8/jkrv+Vg3}79X)gXS\dipvGQl>LZwkR3wYPw't"SyS3qa)2h\/A@**- p3̂^I\yP: UϴU;N ok@!p wgz,'-kTtQаg)@Z=ףRW!,+.ARL-Aj.=v-{9<~I [^UKu* Dz pi)›YThGǂUʔOɬPmߡȖ#E70+Yy=S;"?GM>O5Ljeg`lo0X2ml/1pKSad~uԆHS|چ\)z0 6Ziln)c *hJD9}V [Sq=rLX-{^ֆ!:<:!Lk99 D?hFVϲDpy߯y2M˵hiKS3wHER+"(+9mWog%u8Nɼ$ YvI! n런6Qld XD@iTh< 7#$L#.+]QgP9v8HB@,ó>k'?Gv+j m'!]7B}TU= 9Z.& ">dӘA2[+,Đ*QP@)"3#8eZ뵏O߻30vKkswZϔ+_ +_+]WyGt.RJt , Kŵ CYi ݎ tiP-UO"@n9 ֪l' ( n-:v]#pEg4V]?֣ !5ڷ5? lD4ž=)$\5MRYC[΅ )Fv7* $ ..AЩ6H??mY)k[^X)0 }eYb]d4ɑC[~֣67oۻLH"_IpZ踳)Ux0۵$}/t ӳ9˲ rCݫۃϩ¢f)I]9Pg013V f̡@$Aaa@헚P/$mvAϪGsfs.<Rާ)έZƽQቬ,c,(!ѻ}Ͳ4ײjhADĝ8Ꝟϖ<ak."״l:{/õ6LF)C2&G}[a]X5U7!Q~KO`Gz p\Xi=20?Nj椵h12\ q/W:ЛrZv\!(lj̃2D}]1Q"Цj<r5VYrU`WY="~mm%f*84?탍3v2@@{3PoeESbUBw6ٵ"UvÑ[Ǵ {E$pt.013Fc]RL}+Mw8G5!,\2/ /̯qͅ =T-K'u=#>&pjヂW'˟k9vFaiaI3wڋLl׈4Uą2t ^fsx+-?κ6J,HZobt JtrlK"kDh2:/3yWN5sܑJUnOɴ$Y;nyA 6וTu؜ufV}q Dȶv+t%puIh7FW (c=Yh|O .Bǯ$1tMhۻL٨P*1t jv<4p΋T-WZ WUT3Ѯw{b!59^RE^7nX\qI[H_I@Ûॲ[Ji^6,xP~<(0sݡ[D X]G910 r&XTPBtُN+P@Yca2랖P_oP2bc Պ^y39 !IY 4:QE@A1Bnk)g'Fg09Jcb^=UX HaBI uiD@D.oIiO<ڜbc1ALO{v LeĂR bh8:L .-EsFG0?VӐMaE{& \ɽ"PAu$ƪ&7!_@e0OKW 2R6 ,L{$VОx@K?b/DݧXďF ࢤ)CqMZ9A) 5v3t%ƉT Cwu@~M@* ;Vg-$[Kx+͢l9[FǏe TՒ%4`c*@x:+la&/)]SB(X&*?Tog|: Nv99L]tڼeXz~;D4o{v(7[=ڈmV~cN,`d:&37zʼnb: r!pY8ٹ=؄+&Ru2<[6Qn.MOy̖ìQH ,O™t޳)(ZMϝr|IBN$,2WIKl<]wܻ ^dC2lr1qž$^77Vo=xt1&p{M:?iupY׃U o1a=0M+lDS&憗(aoju¯x-$8gcQv:I'"1ã.s .r.Trx;ʙՀʶ3HpFLsfi/' dqN2*P岒PY}L,P"Rr'۵t 淥Ų qa3ޘlϠrzj~ֵn8,aW~Aֿ k'3f~˃\MЇQ+o!\ٍ*z[- `A(>. I06hssUmhn߷~YEwJ4{i{f4ƁE%o3~PmX`-Z?0ieWI> #zp#0dvsuСfFkF2mYGVIW)%\p1_W9;kQgSCNn>C5fʶFsNBi޿&nh!tYD@AQ!dNC w` P>.CLOB~:v\ldra`KHawZP=m}CǗrB<@:hi?j0 -/blIVREY?jHhiYH"Kop6+ĺs~,fOxX]rsϴip&`v \bRCņi# s ݫV{Æ+hNV|19 '"05Gug .}>R+ i!&d^2l̡F D_/ssSWf@ Cl-`PykʗIe~e6BZJQxC\xtR.P2w%e*4N*U}5rP{urzs'J@Hڠ#9)]cOHj,)F=\į`]NrqP҅e&a&lHyFl^cfD{S)]w"6-?ʂ<+xWRS=D$/sx 7Vq,c :rqɎJP4Fn)G49,ՖSy.}ʭ"eJwDoE-RSKDP<;OWP}F Ytr}ktsF5uKc[M{1dх>ͻфTrS;ܺnvZe_meIR_Bsy-T{RC5FaF%#^S=:$bVEzY$_֯"iu]ԟǑUlxxgx̮ 5ʹfĩX%Xqٲ-[ 9ci2N4q}BOVISO%[#i;84` qh;f fN_y=p@f|9;om46p_"4qBg={g@.ܢ$5K`6͂Q?-V% +>3fGuәNku@A>Q-[y9v6)①\1QK0#{Kx[q,(ķ&# BZSmT6\CIVQ%bd-0C̱P4`K}Hʧ r4vg,}SJC&x|\SRB n\WvDbY3bO֛}7Oɞ&Ϛb W /1e!vzJUdBdh7;YdcW Qbݾ|l^cŌl"d@5 UԵ_^>ʰt#OD-,;f] _zJy2=d<\,"7E lùY+ׯ%OIB8 ><>`HlȣW)ryTww$X,Yf*YUy2po8Rϲ-ˍsE{kFtE\K9 `ywE{W4uL:Wӱ*NvaQLfcZ%0s[M&%2FWP)6adSi~L(u@V%~3=* \3eU?ExB bw8[E)wPͬK8'U}^B!&`v]963%0|<$JDez@*Xmdwfӄ\‹enPqqΏJwEqٛh~4W,IJQ<w?4NK6.}E(% dAMI б*7"m͌TeQ)G4č4^ L!el'2]($I ikeGd|q +̔G ~XYP^.gNz\6Šv'1Xp'4.B!@BNsp 3}ϤWCR?,pIDIQ-2m%钁\};D'ue?{*3݂"ŵJf9iv4WN τzEV~ [`yH0:n[!zb~oC}Tmbg gA5e> ^ȦhCnr{IDֵ0q*ö4)".LTf:t$m֑m0O;HiH vw7{ڽqۡJhCDv Xȉ9UXchZV@*\=o+y тʚ$b$EMGUV⪠Mp85|q#.\#{lqbJodqZ0*۫ 2Zf@6RʁO\mBVBe[[uSN:Q/5g3%- J\,Z0a Dž ~3\KrxD?a¡mRo"-:{ > zu!?h\3yXZ 6|9,$G K{8(Zb_ad-/u /.WTo*QzӜ->9 5llV?rbMׄRyEG=Ѿа;7v2~;0Y+zcĹ~OHbJgBuS& ;Y[u29., &WO2ec2up= T >B/8rͭӽQKחZvH6k_~OHu="7TTljוuԗ;ڳUz}Mmra+%??/WJG|\:棃w^+=Z r:<@,Rm^^kŽJ4C,`H߻஺(o|ok/ap_S:?g9l93[l6ɟaACbUC}՛jo ?6|WaU cpWD @˗٫:!|< 0&TEK2e7BP>$3ļE!ö7hzDbaŘc$[]wǑY1S;V6D}CQ(ƌ~ 0wU`5b49=T_6,m D~)!s׼^3!,~OfBG%{@)d?lyDÐfXLN Èdd̿CQ^w"[b'/kka6`XBu@ rg2^cDSoHQS+@Q$6)u.YyLMk# qm@8ȃ$ac#RlPWIBO:5;2GT+8iyG8p:+=B<Ϟ\]EtCj r=ޏ.w(/i\?"L˖P9 ?!}A`%Ds< j(Wcs L6@X8Qa+eE(LgO#Į})n8tbK #S X&XMq)F`{i{.* Qe AƱm?7ؙRĶL5@)40ʠT[*S-"5DB#jolCx6'>ŭА"}=Pmw ȿ9Dtr>~*fyἅFm{9苌ZйD*XDRn*cpO˗T8 ]R{B(#.ӏe_gnTF,g\՚g2/\Mov R2SfXVjCc5l ;zO,qlE:;SDm"|=[>r関:wNX2ԨpX:89>)b*ĎmhӌǙ ^FطT >KpcfA{.[9ˌ>]4NFEcb6]-fUZh"]h[%+YD~XUkyiy&)WN!F07oL-JMcA'Ӕk|M!cs%ֺ.Ϳ\D@]B/L˺ .Kϐh A{$Y!LؿAV3F*YqߡA1T7"JcGW\Mao'\vC/ZF5j5_1 ]/ ̶Dǜ%@8'!'nBEM]knZ߇eKk !iPTB{.N/C VE$&ETqe·0a _O$c$/ (e7ReXP*F*lL3:|'b lTqu='jWPc &$1okĊZ҂y)" 5k5LE'QG kF,r 0Zjp`+:N [+ۼI3VX1- JZb ܥ\4f(1HsXKG!vSFWۤ8y)8Mcm +| W|iřf΂DMt+uqW{2g#OH[EV= {䟫>ߦWeGP%X:Lca|wfI6{3iAyjR9D)kK{3>5 P yjKi>wGhԣd+ګ4L[{4N퍛)=1~⪮K[| OpHa#yvh ^8r子CebûstopWÉM[$sH\I|pLv݆\fN\œh-] \ P | t|szzîǙ Fu{w<>uQFO~p J ϫ$:ㆩ`$Ni;ϳ&aYeZ0qQK6@ 7}P1 +#XͿ*Qߐ]Ifτ,wߟqKl8Ó.iztG 6} _1D Ch[~ -쭩``ej$c( Tu,sGn,Γk'Li@o<{%øXf쵚ZqcDׂo9hOg$J\LeF6YE~!`BJsq1] c>J:ĆiDc |bՕ-p&E:h ݸiH0a,3dL9l9Wz1;iQX !Lodwlv"M:#=iu__R%yFO8 NW;匶צI`#íuQb7jC;xPG*;F3H9qXh\ oᣁ ;#\Tx()wno6uƉ䄬  VOw;E6zI/oMNrM+($x^ʔ7MQ;R?YxHYJFi@)z7i6X*х-PnYeӜ$2}ҽ|`LƂ1ѬMt=ShW#˄b`rB\iMs߆WoRAAaq'qa="XxGkx)TSԊ#n$l ;+&#NORT~a& L\2RPf0RV珀MǜB\d@ls4e!7_UP n"#`g~v}T@8YI0/v8LNq$_V9ڵv5 ϡ dVXSvH~ #{%l5uCH}q i׫< wkU`,л\{6\I@hM,nHR>mHh5Ҽ]yvBXbM*I91E YC|RS e|+wS+LHcwp{'CtcqȾ=#{SE/Yb-}L7+K0#O #/k6Ow+e6 IU[N]J'x>/m! ꡐJA.@R>,^6v.\LY ,QEO8^=ge|Q_g?,[A"O@bqF;$jU;Rc —pb}xR`Y?'?af{ѻ7ѭTj{YFe6N>;u4jb&d?s*sCs23x ^kl/얈0Ik0ҲyM