libsamba-util0-32bit-4.9.5+git.187.71edee57d5a-lp151.2.6.1 4>$  Ap]x:/=„ar1;3@UR6-N<2}Gj( iZP)Ā!l>=?D+[˶Sݎ / C)Hd*KԟLSVHV}Ef7AZ EIDC $HjUvy :鄴h2 Vz|顤ߊ6(-Em'{LCJW!l+茲W$? g^|ucU8 T^  pw;dgvb00043d87b8d248f7d354d91809ca73de53afd23dd75f5a4059243c529bbaf830f7dccefa1188593e3cf32b3c8d3a9be7c14291a]x:/=„27ϗ ;I FzB]"i5UK 2:>p>]?]d1 = \  28?PX \ ` h  '$''(-849 :>YGZHZIZXZYZ,\Z|]Z^ZbZc[vd\e\ f\ l\u\$v\,w\x\y\$]`]d]j]Clibsamba-util0-32bit4.9.5+git.187.71edee57d5alp151.2.6.1Samba utility function libraryThis subpackage contains generic data structures and functions used within Samba.]xcloud109openSUSE Leap 15.1openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgSystem/Librarieshttps://www.samba.org/linuxx86_64/sbin/ldconfig]x]xa42efc89c1d131c0ff64fc58b7a2677b1321e81ada0bfe6b281e97c0256d8219libsamba-util.so.0.0.1rootrootrootrootsamba-4.9.5+git.187.71edee57d5a-lp151.2.6.1.src.rpmlibsamba-util.so.0libsamba-util.so.0(SAMBA_UTIL_0.0.1)libsamba-util0-32bitlibsamba-util0-32bit(x86-32)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/shlibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.2)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.8)libgenrand-samba4.solibgenrand-samba4.so(SAMBA_4.9.5_GIT.187.71EDEE57D5ALP151.2.6.1_SUSE_OS15.0_I386)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.2)libpthread.so.0(GLIBC_2.3.2)libreplace-samba4.solibreplace-samba4.so(SAMBA_4.9.5_GIT.187.71EDEE57D5ALP151.2.6.1_SUSE_OS15.0_I386)librt.so.1librt.so.1(GLIBC_2.2)libsamba-debug-samba4.solibsamba-debug-samba4.so(SAMBA_4.9.5_GIT.187.71EDEE57D5ALP151.2.6.1_SUSE_OS15.0_I386)libsocket-blocking-samba4.solibsocket-blocking-samba4.so(SAMBA_4.9.5_GIT.187.71EDEE57D5ALP151.2.6.1_SUSE_OS15.0_I386)libsys-rw-samba4.solibsys-rw-samba4.so(SAMBA_4.9.5_GIT.187.71EDEE57D5ALP151.2.6.1_SUSE_OS15.0_I386)libsystemd.so.0libsystemd.so.0(LIBSYSTEMD_209)libtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtevent.so.0libtevent.so.0(TEVENT_0.9.9)libtime-basic-samba4.solibtime-basic-samba4.so(SAMBA_4.9.5_GIT.187.71EDEE57D5ALP151.2.6.1_SUSE_OS15.0_I386)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1]_@]J@]:\ڭ\\@\ \N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USaJames McDonough npower npower David Disseldorp David Disseldorp npower David Disseldorp npower David Mulder David Mulder David Disseldorp Samuel Cabrero David Mulder ddiss@suse.comnopower@suse.comJan Engelhardt David Mulder Samuel Cabrero Samuel Cabrero Samuel Cabrero dmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comSamuel Cabrero dmulder@suse.comSamuel Cabrero dmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh4.9.5+git.187.71edee57d5a-lp151.2.6.14.9.5+git.187.71edee57d5a-lp151.2.6.1libsamba-util.so.0libsamba-util.so.0.0.1/usr/lib/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:11057/openSUSE_Leap_15.1_Update/7d5b3605a519e39b7d410acabc99983c-samba.openSUSE_Leap_15.1_Updatecpioxz5x86_64-suse-linuxELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=c52f238c2d06d60da7030a38a086401e86d02e37, stripped$PPRR RRRR R"RRRRRR RRRR RRRRRR R!RR RRRRRRRRutf-8a3e453288c68887a322a81fcc4c4fa9e8782e7230e153e6ce365a642a6a1f1a6? 7zXZ !t/>] cr$x# S~ݏ1%թ,|, _-ϘV'a?%89/+.Ih䣛޼0{FºTofݞjQ_VHo#).n i]٘?ZCtXIGK^ scъ\}&x#<*ў5p.tn˕iO$(:lHLw<ŷ.3S6D#馛4/Fz"6EIí."< JL;GU: m)| 3k6耺*'9!*7ytbqt Jwd%(>c3/$: ;Z|}zcJ@dx]$xX~1<[iSEظ񂗲7}AW-ox &=$Z~Ow=%&=5G}i R˩W.{,=&tx2eXZyW !E3(k+ 58ه>2o':,-hCr@z9]\\`VLb [BM"nWxĵ<:3_>ޖvY$pհic$q<hOr(KVQݾ"<!aM+G8jo?\Y rxc[`QFpDv1amſ$ 2Pa4adɜV5EQ)wP叾L7@dM m^Rtw0],OD4YAOZFSw -um8Ec&37un % 7by 硖l>sz_R~Eٛ|u{JoiKm2:/4"M~hNF#g=%/)ɲ}>i *&r:ʩ G~=N/ yrM_5珅l]Z:#T\֋̾)iB ik-ILďZe&௙I - M{$E h ܭ6՞RɆmo'{N4 ̶,zsg LhO ŗ 0H]{G#:L7˅87[$ZRH!*(Ãi4)({jRVIn_F޶p88e8 vB,(IjJ*`:'E1{A$ZT^:.'0&]%<ռ~ݑघHB5_{Jh KW׳iÿ5^GR1L#&1/S>9ᱦ5W4}pjpߖC>f.EmOC^/{ N*u^țPt͈=d cv)NۯS$R8N>GUDn#O F00#CХxǝVD\@'!Jr(*" 4\߷hL;bg'8VYx2CZbei=g_d٤ͤx09Jz'U=4`Pd$|7Xj'_ d 1 iA{,?nh8ldd 즜0-ARyr"4:Iha7'<@Se@MVnFM6{/;籟2|N ~z]1Or<2MS;i7UO=7|`QBmA14Bua@iϴis\iyiS&& ڠяS™U?r) *`2BJ\#ϤT'_.ZD>IYRe{rGHƠ5j;ezj1Ey`sn|%dSS[M1Ӡ[|Lcē,rC,&`,a UʴMq賸fz/} c֦4'bPʼW y~uKƂ >NqҌvwb@aNX̵'4WgLBP`\ jZgeZyÔQ7ⱮR] Gpu>8`RFJaއ߅TkyN N!c$#]*=Z`?%l2]_АBrIN,W0\&6 w )q(b&b"u58}:9S]97fr͞D$e ~ǵh7~9$F.E<^LǑ} Fxl?w`hMȞ18yx JmY:gىfQ*AI/ P礳\(5GS sʟ٥8֫L\7ȟ=-U 1̒|Ɵ;S Dq'殎 d X]@,S44*2kBfwXkA|GMim{mTgPrOe wH0DwA cO8*됃[ʹp5 C/([ζH%*moPe+r DR(`^.z[~Pd YV-ĉлH{t P2MdC:PwNMVH.=hˋP rw'_+X-pi >P*k/E(jB9>~^ٱu6ׇ~OԐ&m5DP£w2pa쪽50(mtN/eM=KViy*l89;8`bMdy !Vm?32Qf+~#x\;=uD[Wyrr3Pz jc^hɵw)M/8"IDk^B!O31gf4NiLO0ma"ak,_#kIqЛ`P3l[:Z#aH{nE@QyD=٠W]` Tb\I}!I"̩ʰٖuG*Lc%L'4%T0@؜fn+D܍Tm6uK)/oˢ o[9Bl^HOPa&Rz,Jc16 &ttB .ɖ5i=yi6hJZB>U@/-]s>ܞ@\An"" 8;XpGm8 V{"\ܚ I !,D_@][|mׅ$a[ 2UX$"^ EEa9YX!: @ќ3YaQ9fXIpP7n:F  pL?1&qblp5J%~nƟǜr2.VvE~۵@Ivsb!1"-`<Ɗ5_5>9C$Yy&+lh ; 3F+9 'GЭa_p d\F;c@=tml_Ӵ60r_e0d93`^,7ttPuI0WI˳"k + '+cЂoW¾gkQZC9pR㴳d +:Iݪ u(}VYG ާgmO3KއEI H}ej#Zb/%iLL{s!BN]Byˇa6<B8ha(=3@Q= q@~)x-]R]@?s)ZDXQB-$1pրB&&56V=QgWt3v&)Փ(d μrkh?eq'[HV3{0=[S }+ϯ m7si7S$ oF>`06XkH-㟃,{.7WxrZv raUm٥qsOzahO JMsh E!㛋#sӧ0J&i`'\: gDTIY:2bnC? 5*+,S tLw.PzlO|}ܸVj!4XHT4x^isCA&e*۪l[ք9Ya $Bۼ zr2rL_݅A윣8+ Ms6ESXJ'-E 4b]rRrGy?&S*Aݳ,'|<}$-s rJvV.Z7^;,ñ]0 I-4-WnJEE) "S-ud[BC[צjӳK)[Q;4NORKX#] pmWY~r,L}G (?#3ӋCŴN "^{Bb{,kWUBV)b=9%dAف~)0{S;|mOlDB"jΨ޷ +5&NE+KwTUvϱ30ڑC-*b.%!o% T|:?ܯ .'5i엧9▗R Qú>~TO| 08W\VK18NpmI zpXPţ?W[rj(Xck ыr̯:UC†=@Iڎkp"[\CDxL\n-r]83%Ela. C`nzKaĽH]lc;[gⶈpK9b؅ju8/^̊)fMA0$QOMuef)Ѭr\!,$}a.*x b(_vDll)h:0l#~7'y Y_;{kpL DDVFMۥ x-Ļas* 49+'61V OapǛ#!Fj0JcV.YmK~ul~_LtDyWi3Jí4;b/̳2@U%yTϠVU~$e>;EPg8 <);:v8aE2R7X4ɠ螞fh][rNe`t-,왉3A&'%8̵5h$u3ODQ)Бg&^R\բ%3e8Rȵ*F4t6Rr_9&G҉~Hy{\BX"$mʫr:Izb%(KӊX \""mMi1~5ԢLx=ܫc쌨C/\ꕺhnfY_5tIÁ1/$OJwMH7A@4 Alz+Ɲ-"y7lVQ|6տh_P0 PJNO WM@/ 4UW;~Bvvݕ4 >L*$ |6}ס2 lZ$ܞ{ E;nӢ87 O( Su 6=x2G"I'llul{!9~P{\݄džiǁii mzޝwJ.6^ьJ/q֓q '9o T3M02a$Ƅ١[|FP54qdȋrI)uyQ']u nSǁ9[ ҎZ@&+T-pğbRDWx=*xq2VἌ]ThSC$j`g y Q)ul'i!ph OcY`H|s_E{ yI_\6`l%Jw,tj#ωn* 2J+Cgl)2W)y@$ QhRFDV")s/zr hg;uة}39jA?0 fտ<70мB ZۤO_`Fvf̈nV>E0 3ylyE3] k!S$d؆C L;ax0dWMK)FmZw(ԕb?DQBsm>rqNM~͝ުEEƕs'aB>>.sWD1vq@6۶ˎ,*y SA6]h쵟_ga"l1D'5^9@Ts0_jg߆%|uH߅ˏz6pXR1?3X:e&9d54^-_61/Nϡb+rwԷ8rm@b  ~\7( |0YQq촴zoB_ cϖ z>h8TERT2X^xfuD 8?\[W@Qs 3?Ewn'`} S,ȘvƧEbwr/6IͶh̿l@5#z} oo֚YW1T*}o$-- |-8_G Q%qk3kv9Ж &D Nj,n% 7aG6^1CPo[U)DW݇Ӥ<;PЈ NpooyaUx4T&G9Nٝ}U8N` }ajȋʣ$ gDϣT) Ni.9m]qԴ}N(tqmn_ٶy۳j6[] -B, W=(;]Ap`K1zsubV>BtqRCH1ɦ9yn0%sz//Zr?X_&w;?=Jc9,e0va_GVV l"6Hvm2 vތi}E!q \]J=k.+C26n^q< >dz/X}Mu ?GT]&یi`ԏlj[cb-CXe(OJpC; <ϼ#DABݣ-"`G2oIn E: zsʜxY'zKNA5`Q'ʨL qC 3=1b5^ޕ ԄL6S0Z7p!It({ehev`Ѵ3qw+ !w͸nTUY.sGNۢ=<d`1BR4s<;%n^ W<`'\EhmDS-K|9^{12WjBҎ?j ]ĕOl -df<ݏvVN:QQpWjl 2F.z1l\`1SqcȾYQ Eg4״wR8x!u(Y}щ0HuL;;Fff%]gDzʘƶŧ1iȂDb FSS7GOq7Ӥnm"+<ܡ"a.b[ MRӠ&vU2-f{ٔ)1UbPkǒJL"ZbPRK)A1#o 'yW+哔J4`QET =\]x0 OI`U45nOR|}ҝQ (dؙ h/?llOmz^09j&w#3 vY7h^ ;"kwRs*Ҍ| Pyeߜiv':RBt48tB."ZCPO'?lR ,{G#Mb aF0A aa=5?a$?&3fMA ދgW(BF?=׭l}!٪`ZQv?1q*6*(dp"M~ZoI7lW!-(Xlnw7 ߟ?pSbl+qnF*_\WB6AUO}N7%ʴg 6Ѻ/.DuM>:䶈6t[ރrWlԣIfeiH0DiFezM_wfSy~kezIZ1u!2>7am.=ÅNr>hCfmCհ|+?U4 Vex d41C}JivV_Զ]zF)ޓ?RFO5ash{%“ģ`\Wo/2bvAh]Woz^ћ9,:B9hIi=0ł. PRɆ(,MբpD e(]̶vgս&ΛO^pqTӱ[/;M/-V+ܤ1 Niw@NhqAWm HU~F B]ATمV%% 8$zMJq'/Hb3%(c_}pnpQQil~1o CJ|LR>SXSO%Cx}X=)e `kjwWFJ→ؐ1/μdpF }x, U5>qBh". Q)0WJ7*?3$ck4m}_6UVdَfD\-3*= z'I!&rw9YN_*\Z[^gg%9(0~uDNѸ[( A|I#r@pN67խod(ioN mOzJ^pmϕOW;# \M<{=nfXT1vZS!S|]u<("vO!e(Q+8pH2pхdKjObZiG"4ɸVrjL@*oAرRd $ Vn"FMEqM%BَbM)?WVڥ܄yh ݍ-:EId|kQmR(l[|aHA?yïu Y$=ATwV!%m Ф>]Du<=WOy_ktТl#&&Fepؽ!P HJGe8tMy^W=` zd/?7o!vL\?-HJj$tr(8̍:9~k ![ēFrIRL ssHgs}ό7sZiY+ճ1[/@ƏDQa)L54h>W%ewDrRѭ(-?G54gv6SVV{e]S=d}xe2Lj82ai+:4)MLd$\ʷnyf7QΕ*GX{cK?Uk@7M_II\`Dx'&E+uw UM[| S|"~EOe-Pm3wwX+W==;%X1|_;w%`&I vE(Q$%&{ N_Q;}ގ3GI '`Xt nPߩ KJ`LנKv m1r#e!6o1m 5TSĦ-My 9kh ~rC}k-i\l'K 8'טmbܡ Q_DpfO~fJ6X3[K&s}Rj?S m&sFw0ч=98 1*:As=Acj7kF\nf3XMCد`|fדV?FH#cRSK1dB@1Rc2)!ou޲a͂ 1yj!'o`R%hŘI C\fL +Spgdd =|#&3y6I@G:{pZ^!i^Mzʁe)NKJS#wҁl@uxWT-n)jP~/c?=7m'rZц#UYZz3/u]vO TkIS"ݸUyіu 0<`,ErO!J%bE ž]㻈鴶P61r*Hc΂0wvԤ*zȽE_ҺL :U`c9B_"9yDΉ(dT7 YȚb1U__YCN*rKq=c+(byԼ̥ DBAY`p-} \| !BU=Y5R;Lxӷ^Ln`,% 1'̂ v&^@DBtUP(?C4R09.}@]2*\]ioo7(4vh0;Q gGfcUW渎f( avYm01 ͕ fKj>HTsR~W #cJ9%Amؚ̓@JFmV:N99?krr꣇00Z>+l8L6wb^#[  c|&,. ٷwWW"[_๺0 Y;uwxXTW;7+NH ߸*Df]PQk̙9^O>Tk<| HH5p4=oXhiI\r_G1һ/4qV(ܚ!V61R8 b NSN֢!`bה_f~OoV!xPڵ;A33C QtrO,EMe9``,3Sr4w>fu "a'~h2Ra7 Vw.DWG2-#+b;ρT~U3l?^.Y]zy(*uؙ,u/$ ,Y;:b{v划\p_E6of| Nk A=?M7m C F0GP&Ԡwž>"6Y1jCN~{>q)E9_xa3䨚ۙ߸D0dhNv{I3{_~y-#x s 14K,vd\g8{ZA0DHY6@)"}hNfn0,UWٝ;MGr1mZفD/dY5++Ϛ#y qh8P d&yL6F29AAO]^1=fbpU,gTV%7)2@~AӕI^V%: }#\|0 M/lANZz_M+NBTԡ> G IBˣOp>CW1i %hN*όlqRM,D%l7tJ7G vܤ%_[%N%Ϙ ۩Lݾ CR^Վ$yURH"N^f(EX/]o}DYx™x4#_)_}Jٔ;g7]b`1+:g6&{Lх7SnR^jqE+{&N":62Ou|6nԉ Sƞ! 5)ƌѬm檦5lw!^.ftzjc۵5PrU-G$hG؍ƾDo{fhuSEvf؍L.@B+d^|n׺?pBbMy~!PR0dAyAVYbh;V[W1l(H4O2J(#+9ڞ7N(ҫ{<-ujՖZECgm}8t%nlmu6ĕ(^Sb,]#r ɗ-NhEym[<[z@2'XonF+|b`qxF- m0D2REЮ.:yu5xV gE-Oty%dPV.`˄ t,b&`Es 7޲럄6qf5CBKW:KPK03 O:Z*v&6J v:ݖUo ^bq '1fP/ƥ5eS~-@,eje:M4,'0* A{?PA`zfQzuEhx(d;{.ZY6(~:" 2Q.I]s#,g*i`ȣ5aZR`:Ddq{,M|̰ϔjK Hm;- ,-uD^#@ʏp'4=+:U4=%L, ?=݇|'u2Ij]p}%Lz/ֶOSCjG>Rm=J "%F_k@@,J~e4xIo+2YSf"Zf*-&Um ݇!zeěZ+KA_aҡ@[>'2 +=JAǙ]gv.):-nZGPŜ:e,/J *oxk]}{(+ǴV*'!6q$݀1P"T}XWFt {"eufuAҪ\O{Iƕa!h5w^RS*Sl gJDYpWJC)gTqXʽ<8eG,J1$=VB0O -C8gqp3)efu =N/.v[1q5LӚo|@!v_ 9)zsT-QIHPzM: Ph|Lb <%R9w̨(ӒߋCեd\ZqĘxA\(~nVˣf@W,bx*HI!q^1]Cağ~x2ė(XL(ʆk5/.)tCLjHa-0l5\_IZ6E97`%K56q] ԝg7OSlMʲҤ{ *#srX#2&[ u2)WuCj>aһqUHJV0.ԧߜ{j`s*qxIGJ_R=qdxέ?Yu N{F\"`Q'ۮC^ݳ% jzb11Džh~H^mOɅr}bVHݼtbȀ+Yu>DtE9\R{((.9uohb1n 3.lud4$ۈLՃPK_ [o0,ūb  9O5()P^ܸ5͚M GqI?1|CɋIGwNeߴe{a,V[CGf㭇̪21 e ZiXaB274 @- ˜%jω<z e_'!: }vtVJ s-_[[]~$5 q{R@ؗ#FQJ_KMM\f͘VfTԟZ n(kTHGB Ihl~D-aZ8J\yNOhʦΘbk%sHK ]Hp_Q'VzhF}L =:L(X[B5]&&OQ;^"ݮ ~͆ň>d8ݺ\;d C7f=$xQ)V#U}Wqޤf Ad>0p^3:s194?+DjÒU)!,?w&]#mVVkƚW_) @08H._Rhb6 5Yp-M,Ik3JfdbaB=FKJτ"@rUq\ XtE6NږMQ0wt작yh 61N:\t+.<'3[rl KFzX ob@Dc,oAı#b I-*0^,I ɈhUj-gqE1 3GiNXbYO[ PЂY= P{˃pi~>#d:vxbyOO*aL&>ޮ1 ܱ.m19޹ex]-؟)]4@(*VxllK3=X=0Yh|#41ļ]]U9t3U%|=t+MBW]y6bv+3cbVLgJv^}U ' jZ~WR60XkeԫL`)ı}5$`Wy}ja@3M;~sWVC\NE.ƒH轂 uC` NǃGX% h|',ud]=Q|G-4kJOBd\1;AY;d R}c$MEYbҮ./ƙ8[8ZabAx;0NXcdcq]v/?H+F4OFY2}bx3ԹOΝk; g@xNJU#O_܀jZÉW$#OMp; 'hPeXLM_FK,a -LkXD {*L;󎺇A&HjRtfXUv`]տpzVY;zܭw?DE7?.; > *S n*.-_liq^{qAN_-FK544s1$ [5<wS3 2]n"I uĖ7 mW?<\DUb&p_gB9e ZfNJ'+}6WNM^bGU ;s 'ui$M/w0SOqOZ_Vv#Y+h7S1 f[M({fM7*:Crz;}T^D  ^h&>)7n%M\sLd: )|7բ: P;mܙҳT崤6q ȷYPķ9[$x3(\>yde>mӰbT< pٱMxpkx汌%*Jk3-%4]>&}*`&L)x3^ \H#6 SsՉyL\g9lG9^p-e0,æZlJ}kx U,/gj#^N+:D/q1@w8J*(I $>ԞS۪,^jJJ>feGՠ/>pN?Cq.I<U<*A2a<~ؾfŌeyz%3a"<vmR uO#h0K zE)q5,.(M dFkZwFLr}HIa(#cU'dKy2w$;k.&je:"'ruZXTFjua5[;q/ [H}KR)L7TzFq|~gM$8u gvUqٰmKQH;wxRNQE*s@*h0h' (Lz $SĊmS(҉p qo#l%@tC)JalQU+֔7DM_qBZAzK犘P҆tV_QIa߭ $Ȏp.0_h݂$Hk3hSEaΰ_Ya>߫*L+ կdI*=t # '++NIW8GDIYb)"d"Z杣@]GVtH׎% ^I8Hd-S7t\̃dۓu*WIL+\8tWٴHd˄g,^I!yjӑdG=}q\O#:Mdc*qEAmWU,Qdzk&B 5]t'  gv_ ֹcHg5CF(S3^=@irhQ.$x.rU0f᠉4 2 h -hÝp$6cYf -ֲƼ$$Z4 250LP̜h?[K}jώ劍&)&#^]+%3&IK0;N-+Y:ċ#umrdQCcq z :sdu6ǠBހ"8 ha[Znu늪ٕlguZ ,t;ˊ_iKUwgI"Y(>_\"탳m c Q3:elr7M&ܣlP4fD9[*KP!?>ǙvLcM̝<?=siQTcX#?bmU|xN_:2W",PWN_C${jl:.. 44WN7*JU$r(3YtTX/_bw%lЧ:D#M{_ެtջH=6*aP-^g7z詚tq\S$}: )O^H[)y}$מoD IcLc1㓷Lk@ eówdP9Q+M w̯PgA1)|B<ѽW_2Utoɽ-o:gWױ Q/$;_Cf:,P /AD8,@s#?^SC"rUV鳊pJ۩HvcOܴ 5)Ɔ\XYPt`CPU0V@4pBXZeg8!Kd^hz? wgwVJ8`9+r28\|`ӧ/hծ`}ʆ`'&|ʎci/Y*_*f⫈=,5@RGjB2jv+hb++"L3'C>;hHH.I4W7葵Dq?=UljǮ`< JAh.pn |ty߄ƽU_ 0( p&_# d+g2N+%!7TafQӮwd7 \{uh`NS32OMrM$#bNgWqUGiaE@{=udvu+/#LCQ^p8Wce ]p(riGȵJ@KAK!%T~aުLMX.G2Ć_Bi0vm3LwPX$/huڷsh ]kL [鰽Py}=՜3-(*q$/_Ƽ \ܵ8s2+3d]e&(K^J6ԓ*r* Яxڄnuj[g:^3#R@~h kݹؙp|>0ܮ&;u @-~׶_9LaG$!-.E)6x+u4p,U}=?3j4 Nq6ot3g?_ԅm΃ϴ³ j?ik+ ]sHvmKf* pVq^G7~j A>xgq3FJWv$9=2f{1k5dϼzx";in*-Z5 i2p20|3ܩx7\K2Hu61eYFWI&s*٨z /64)B#poǬbrTGc7+b'a-BpmŔ櫹s"h,ʖ OJ8,=JUVȞcsRs2글?0;L 9xR >n.N//Ct_ LY+|[CExێǹ5 CR h=qƵIJ'gfXң$w:홨lH#a^ʳzJR@_k\lbU,!!9ئ| tuQL)ZWԕG~:~u,cw=<*8zHz5KeGA"ƛ&OI=6lX jajmw56 {[S[V8]!)4e%28kf9"aɆ4z{w-0i36 6~PC^-}Kyd {rr m>%#J?y,֏Co7m}:"Twg{1Qq{-TO{Rud!>TLY `hC&s0{-\fL>ZSK,j*QSF2;cLUOBF@ e]F2SB6UYNK* JtMߥ6IР2/xdNviQU2ےCnvt FmzǍ&'}{@o24uM}.a D$>":Iz),;\%v| 2B+=I/4ZkWWp"ɺ"I7c3^>V͇)05V4Mi?-`qGͨe40l'˶:4IԈJA{^[ZY"iH|U09SA[lKOʕIA zP-RuN9c{8fe4Kn_BC *[]n>(H)[p@쉄BoLʁw/DzCEAyt\SXQd;ڡ")'(wyUcjAJ/o;3ϋ\\@:iw *<)*N0c%! U'o*H-w&Fg♻NzN[/Pd@ KbqkfMKyђ~zDF;RNH_n'pi%Y(Qf )k֭Qa[QP`x@.o3Us)D7س&qdq"dhᨗXt$ %zK76 ;'-?% ;{{v=W^ǤɺS]iϙyOb 9Q 义ie9n now la&ۖѼFPW{cnV >_d^A͗Bչ1A C8ob20R,`ҖdEQ&j1I8V|*J&NwIƸ$Oq~X}~?DNMNӿ˚nv"cZdZ*ͤ[ko50ŘM=zou1s(O޲mB,?1&~jUeJ7Ɂ0LѪG w-[ӎ:L >kTgv/bʅA]#IJ:aNm!eR}fI ыF>PnUY8%oz'sPgY-l>4«c&_YD q]<`I#˕>*S"XhS]hj?q[$ @cY4mhO׌ } 튴^DVt̝|tp {?d>@EoMk+H2Bu:+XJh~97C)Bb7|w b(c:AAci=cx5K-;|J}I)1Wڤ=ct97~WDYq!˝1Y^}&=0\UʼւZmR>Ńت \y-M7MOǶq~t>ͲVlG|#?}]$/> b5. 'Zz B =t]dv\`7-V0 }EtV:pԶ0[4y䶜)PtZ5n@7ƠMxƵ?#>L8+UϗaS]6 -$%WK~~yysU\Qa06?l35AKɘ鿞 QnffhSJphr@DfK=L|~8y`) 2S#ST͔4_.)]^z+fD;Od| /ׄG7ECl+]W_joA-7QAdR _|k~ xsۼ1?J} ASi/\#$̸ܵ@ /]hv2OkݏeN%" NOq-<{j&CcJ0mxe<z!c$ &;Xb_5?7q@11SVj X;w@ Ŝ#ՋGNVǸϟmyjf6Cnsj>S/^J*yLc%%={V,(OلGokc$QiA"|;#;PաCM.~V$@ `o&!^i32.CF}P塀F Rn>Z𤋕 vuEw<9*z<}VUCS!T{`a#fk[jF[jF9!/6snnV\)"A_0pRNXndTkeMPz.0_'. S/#RX#WMO'u:SwF| րu'KJߩGlt UtlS3ʶ괎 n'"I'&g^FɌ#)Co;Y9Ҋe'FڱCO >5&vCmq߲^J&4ܪp 8)oR$l+)CM8Gi+02"sʹ1V R0ބWOP 5HB.ǧWϾ'zŅe!pnngh`~J0^W?:x󷲩/*u4~Sݬlޱ̙O^֔1kKjFuS$0Ə!ˠ4Jl,{.x\X_qS|&9~Ɂf|-u5xif%DX@?7@j<ǫ;d8{`0sDMo͢# L靕CLfxM?[j+g: "٦0ƜV߭x5|<[ VYI&~wK8W ` :\|Z큡kّǬڥz+Y,-dD*+E.oU\5I x}z@%tW KT½U]|ӽ:("kEʡ}kخ'ݟ3&m.Y Ca;{U2"Pwr͗A&djSo뇈e'H3{Q)Hw=/|Acy7v7g P l>0advB֋ŝr(Rp@_ N12wΓ?.`jg7TU{fiQ ZAyk6W%žh38v/A~mne{VGu3Ahx䂳x_)r=r8T#,߀1||4,g *٦"Mbk5gH`MLˎC۞A ^!Z! { K4^' b\(7b)5Ґo GUU QdFrAp|DفrdVF~ծ&TqVxHف1P"|ct%#ăm:w\uz`z?^!0B-s!cY|Ro1W`#u Q왿]C_Mp@X l Bq?ɷީ"PӦW"LKPNf^ԛ^EHk>CYiD5 '\OL(3h/H[>P?31[/.' Y%5}{|#6jM҄נY(4b+cUzi5P<׵~g}GV%9=Jhyfi}x<?@tZ%V8$;xz|Mxw#|T<֪wD|RρFE]E2A W&|VMy~:%k"Z;+߽}b|~-{5H⠄WEXH 2vC4M#ޜo|u[¦;H7w0XA '9ǽE8 ^n; qS ʓ{ǧRWWHXۿqQ߹`l=$<.%;NBP_z`?^; H6E+?IignrAdl=@;-XAn0j&GlKДOnia4Q`Ɇni6i).a#㙛|럕I\q]dPS<5jgAsiۂp p uauJڅՐu#_W>ЗAeoB؂Tq (/&E/)1?? }AĎk-ÞtɳBi E]KQUhdxҪ&^m7щ@cp4/LOq48dbl@]%kEզ=&vћ 1x(TaY"yFI˪ {>hz6K3wyfؔ/|p+rƣC ƥKnT &7ܪp*eWu~jG.| HevwVʩ@F)&55/^NS蓕57Z&|]I"l{hGT '8Hv0ihŔT_xȺ# qz˺`rx}ݠkwIekvMB08Fzug a-[N1ϝk!gsZ|#K51[MԳ޾=e%@n4$L8=qcp{P!d1gw#r/y`I{lL,Yԕ[$6-O(5đk.0Ar_M'?H1ï w/ȗPM)2[0·< ([pE{8ʲ |OAO,jqpXO^'4n`>/ǏQ5<P[~!yo\Tڴ[jX 8hI-| ,[QqyW ^aKچ ?K亿ErpBfp=C=n9 `F%e <=#ny(3Ou_Gj؝Œ4#Q3b<$D_hXѭ6AO=C&pJu6|ZA*&eA(璁-sk\v dXWvYwe'%zڼul`s6F*Q:'faL3eJ UWƾ7i'@0'oŶw.`w H =d* $;B0W nEM0( }qy}i)E:YPk;Ej/\@c:8*:OUvι7 . /tM`g'lWn'vK #Bb%zC[Y@e}D Q̧MpF>y6ÿor0 0Y1e#C$ZAW_d| 6 L>+h5_5 8Z`,wAV< X Og{BMJlbe 8M ,J[eIe5ZnUPL$Rzˬȯ*d/9I#HZ;Y}Q@$CdU;>$r 0r:uM.ZMҜ #EZs;FYT]ϭ4H"ߵ郱SKp8BmW\44ڈ_4GC Wm!^Á,(p2j5D.FMp4/ߟqqoVs{')f0*`u4VJt $@#Br rLZ>s׼ b*oGVuk`WR[SӃ9?ei1Ȱ4.{B%8͟:6bqDyERE0IAb 'f0@WeU2ry:SΣh^"-@mY:.G}o]F⫑ǵT UVLVq5xv'Mbլ_X紓ׯ>:Jd:X.S|?ZJFJ{O{F܏:G9^ XEQ鵪I;,@Z-yoI |Ngl AP랽݂\5pr.t[&H+G+\`#J#ëȂw a)3?̲)lւںl>̿Gic8hlzu0MJ4>_"{ Ps*UmH<- t"ޏ8vsw;ijP^[fu(D\OMY܆"'?AYX^&Ën_SwF˵;F4K%m;ĈИ&`4J34/>JǬB&\V/hr`k#MmwdD4AZN@&vO1fH ˙!{p>ع+!?V@Q69u~" ߦFɛ%.}pǴ?R}Q sV?fxqMɝ Ԕ}qZ*@h(IMbyF OU2JtH#fsL` <04 8(7\|ã^e)GDx2K&Ӓ 3=;K)j `1([ 6pVǍi*#$hz eAܻ& }  8f ՘GZhUCRn 2)d&$;~,*0]T5 `pOh5E;zkM  OMjHn`\ey80I~^-.ՉxXάS!Whs͠l 箤v* %^E8% jh4o6XIhD~<8;a*lu+ߛ^1BI'[ܬ, ;VCr*'$b.FƲ)k{ 5N4qdNU ]Å0c".a_dyv6ecDI(vf?!"ZXoKR{y"O0mG=~ka͂#k#!qCtk0 tr(++Wɭ:va GNXgg(Ă_fu#J /t,olJ_94Nxz!ݭUyKՎӤFE5v2X)&VR#J/E29!;AcCŸ?=W Sx]l OkewrfpdD)CݍѺt KZY1*CS1GRM 0^j󄘮""Q߆Ɋu&;%gUOE[Rx7XzOsL]53SvӔI1*TspR`YDz-|SZڿ|8 Hq_̩mO$P B1)/)!Pv㒆,kE]8xݐґ~E)ediY|a}r4 r=C읹)bFI-BqB[| rwG6uA#yfM>I@.$$k#H[6ۛHmVRlM"8'jpYjDSڲ !,2/;"1dyLbxVa!c8Hzrp' A3 ԃ#}(8@:ZBJDNESsywS:nYol$S6)= 2L.é񫡫[7t/;plC Iq9π41jn̼^ ^[bHFx,H2RίB{uQd{)Xb논$?k&>̚"<1qrΑ79cWRйC\hnb":3lKctCwEz <ԣ\d.M\;wq熁Ώʮ <[h pSt-!}"J@`2͑ɍyD7XԣZO2 By?(ǣu8U炛EU{&tIxz>x3 q0 ä`e/:nc3JL,IS }ex}mI'KUQݎX/ ͧC'6CLG WeYYq`瘣>/X?_h ,n_Su9ᦼFeʱ/Ѕ ĘeGF~+_< :y֡GNVT7,D)']D4N#r4bQG;%]1fxp%A|S5:>FrҺ)"tQAB%tp8fڛSO8Aj; ~t'趦OptR[x cK H /kL7FI>("Emqr,{Rua?]ŖG\Hb9 Br!T|EchW"񱳾'~ӏX;hFйK-;ipp5UX"t3oc[nH4PO!ȒB[Z!Իav  :wOF50־CV]"LMׄ:zj hz.>oīiƶ>fn_A8ST';6(T Z̃_2/A㸇2=- P3NzH7Ϡ IY 68 ŶQF"9EΟ&#bƦBhhm;K̡TQC&S;bKrLԆf5~ (PPt-/'Ak:$QBYí>|2YѺvZ'hdPbv$ib;4x~Hos>Õ!n[NŰydARA 衖?)rL 4*2ߺWRBnPOCkO 1) hoFޭ2OmLX( tzN``f ȐOC# 19Fv5ZxWe}yq<)0ĜTj- <VJ+0 @&-aKk{a"Z>x(m^ߝW,nzOB_v2f5 `Oe?%7t"5r/Ku@#IЅ>d#}o;efud`ЇtP&5T'R\6za4CGM|Xk%zK{h8:2׌WE IƒS>0!\iih\-V~$QU¡:}yPĞ-MA1Wj Nꖤz']`@qQf!*u@4N_`qsOOZ"]Q EYzC8?v=܏CXባ)AB⇘g 'dDv ۔ۥ '<'ex# ~HHc ~փ:tKr!Y5M6_xXV #-9H/}7s 0)0c'@Y8SJզ }&voQI4n?Lqǭm t=_CR_~_\{RRwC:JX7]6!pte~)հ9t\W+twz! B ohz^ FIx8G︘6GM3d75Lf{3%3bPpq+53퐛3T) qtHӌOJ3*Cp82g/XkZ&DR2$ qv2Lqq~߮Ȯ:$OeP,'o~IF[*9t}>wd3B_uv|S=ĕIԉ'~͙P'ejeOч@G-a CkO 'av'3\5ҳasnsN:3+*pXu;/e(p*WP%?I9i+$$1vA|=al$mם=3DѼ_}g0R@gn"i(o& ˘],ԚpvNIJz$3p;T`]XuM d7SPeٝBl)쬜SQf&OV9SIpi1t=U 1B[.ItR0^0PXS,Ըgj[D66{KlJg 6J=ze^!Qv 7F0g ;aˈT8|f'W2Lq뉣 ]FUYBz b*śKiIN>'>!^B 3^ _xˈWeBw@$ _]h?[$D, ]j(1ԓc#P2eVuwEbi\i=%pB J\1r ]E g q/u\"|jQi#Y/G}B^ -. {q@tѝ&Vce- ChŪ/B0A+aA$^¤bBxzp`ZHD-6&xXmQџ$&3QTέBa*R(eQJ~ClUa6Vz<\ul#B:3Mxʰ>' ( +F{?)zK6z(== \D}L)RE]"b`UC-{&:?$EKmb"*P׵XN-.U5og$=[ō9-4J$&ߧA`.RgT6 GRS&C֨IǩZK ȧ{*Q䣈'R Rߩ1DNVTYAjbM6Ql7L/<] ޭ.){X3,Q1Tn/)#ʟ84Eqf`>&'0" oF 34uE y- H?<p<;Pei<% +ECPܺғFDəEכ`N|$FGτ~ p¬q?]J["(H~,zꢟ8@.'G$YzvY< M}J#k갬B&Lo}ʰpu-p8_Iy zX9& m7A&!ߐ#ȡV㟋ݐbAC4,l4/*&m<|Y0'F'(4}uaŠg W<@A4P:,ݵ\Xtz kv&u2˟8|(˭$ ur@ APF[~wS)s7j᾽z(e~ߖ1j%PD#IXg 0t.* \ l=E8(%? > 2lNBRu"́U+߾1}oRcw^SjgZ|w$鹄 $Ƿ趥'D؍9̥((]CO!N[|-,hvW8vcߡ?+͡&>}R0&*?ZaW$AVճћ9r,PiccF ~02翻_` lC̡BdsaxIaӚ_KIe"’xem~v߁H$J_؁E6!Oy&(4\@m j./u^JsႋնwPfj`7 FMtAWZp0[M[vXVxD[hGʵK}l3}ުŸ&Xת`q UQ*Hеq$ E-N"dfP9V c_@ F./G]AYC<|/LP[se Q"D HČҰlw!3V4(Sd?yu~m*Y I;l߽T4\8Z߾1N79+ udp.,\lO10#Ý;,$z#dq}/2'3 L9qBx{-zHN)URxx~#g[էEfE~ZDЏ maʰ0;F9z=L;F̾ ް6# QgRC#>2qHӖa"HSzPJ ԝ+V藁{M{٧@`Jtt!¾p {4Yy2?ɛ/Ttm' {R-7qgUG x-YG;C؟F˜>X1lNT@3(Y f *gwdNG (e!?0C L&nJ23[3LU`t? W┈Qʐkz>F ]'XG>`.BNDžn%9ѡ6.pĻ0/5ǵ}m-{ F25HXہ aLr})0r H3/V @M)ܟ?XZZ%#c&/Ճ:L&PYkmKg6=|3i@^oF P >nWMxu;DD.+YxZ%2]4^k|B5 y38ej0e>&srGp>yd`e#Unv-Ju*oG9Y.Eު :wF[x;sI @W.D,HAo7pnٕ++8?K|tq>> âˬ=<գ'dϞ?k6’bH_tn93+Xp{wAFs;s$Oր=*[WW-drpBkW=oWk cXE鹗} A K?QLA&=L|b(I,vG ` 1t_Mν}QÏNթ!gyj BO :l%P3F5=x@ m\d&e(caU ֠5G^j\V[s?.'> ZkTrezr_4 |N~\Rc55F %v0 0*JVslAp@?@r ->%" )|>YlR@TPKQ>AkT_$z_P_uLч +ƣ.-vPf*?9ՀA_,B>X24`roA1֣NBmjdÔ|a 33)m:O8;2WmlL}%r؈M])"|\4&sTÿn@%$>_h$8`cOpsQ 8Ec?CƩ`9R1ǏUKD^? ȁ!qs?gyLXja rHؾĔX@J/}*iϓ Q//qJKEw3SlUЉK&jgl;'Z=cIo d과aLفIQRX6KXwPZm2It;S(Q_q~CsF82A`$8 ۄ~e= c2 n`ElYVfY5;p' %+FZŗmn}$Bŷd7s/.!AUdgxV )Kp%~l >:]z<q/*$&׫Rb zsj6;ݗǘrn0MEb^/l#|(fj&2uD/=0C2𞜗SQ.3ʌJ8O{ lM1c6?w|C80Xp*ۀZ4 gd %=W%[[*g psG!`+s]鞤O3(D'rzhwx_Ծ$]MҜCyՋAW7&=@>׏l+S&]?<*HW2 Hw m^"#>:h:ke ,ܭÝ"HEI;*x2w`)[,ݷəvr4Q/ a L6=N&ZyF65 ֘_ ik1!޼[I;n>uDf ޔ(䮗3p U4܊Ϣ{&i <:H;Q]hœi9la}_|Va;/cnsFg=A}R}bog4e$1Q阆*O8cU`0GrڭUimx7X7ȅyǁ[ӤfDO:{HL2u{یL.x*}oBӰN5spHsx::`W()F}qfm xzM4RV)=oV6PUAZAGҫ1'rN513eUނ@,*0w,h.vX~՜h _A=H^I&/WB! (fn JZ4I[Fhaxo{!y ج$hs6C0:9'.* ⒼRWHN-k?|8K\Ӡ3R0Kdg6G>H<=Cs'1y`NꂦošްkbCsꊴK xgaL B y_v?۳'9slm^P%(q Tk5=$_Ej|r^]گ=˫rJGܑ JV [X! Zl[iAuVrfYʃaB8@Pavq f)sE:RTXNMu,kGULbCf}HF ږSb"r^ pDg~tA aU _8\k2__fA]Ehh-4v2M'L rLw , p W:cZ$ptv)F\H=P- asޭڶz0Tb|nV}3YTnE:4(?9t(w;6>AH/xw\98Z?vp;%56bdV l;D1>] > L-s'>![[85Y7rLwqd&+`:1b .:-7;#AII*6j)lFȲ|I24c鼡w}h`(M˒H֒b[qS8V 問HQ8˟缋A J px-~Mkdj Ð :nyp<./z,!I/ay! Sf_Z{TSZOgjO1I66kZ-Li "M*4m%pQMօu(FZlr^32 d`p0?!00 }R/ֺGˏD0/[lhcuF}qO]πc+=1BA o)q2Tjw\uCֵ߄*hlqʑHBʡr=xTR 3 d/M@=f2oaJSf][7C l 1)!JrhU"AyiwNQW -{%)jԍN8/[K;qI4#9D@w86r1A+ĂS <(J7f3Igrrjব- {./")PV6'M3hyH^NEgD3蛏9N6 v $8}X73>SD:F8I<_y"}gۛdPo*ItvB8.]}}'ƛ1;*11ЦFZ&FWr;A@f^>pQ!-yg) +"z6d^: :CF#o (!ﱧD/UOYٙo}BjeC*|oժg{GUWA!!ONE2p^F&n&ɺ˛ےK #`J: Q մܶd0#橗{3[}H ުEv'fn9 2+XqK[FyntuYѹn*&9ywVM5r$X*aU(t\HYA\Op&>aa×K6 f2 I ?xɡ߬oJ\źطOJ>zMJl*I: 9/7_Hy(Reo4 $G=mFGdn)Ϯ7-Z'-$23T@psR ٣4P#SFaHqlTƕdH[<[e1Z\ƽ2Ba&Մ&Z (Ҧ;rɇ9>+MؾAFu@Md5/I%J'h>G-K'܀:Dgԇ8Jcipia(LY)e-F=#}L/GN<^f-j2 Wmi{kƏ_1FVJOy #åq?6mg2y?D:gʆ%R7;&s?W-0el17 b %<}S&ɠ]Q_12qEd;XC\5XQmg .AB,6CϧdLsO--xbYB%{Mc>Lv@H^}gᇦGUS?c!8HD& 9cyէvGjDhίO{f@`aVi `xS€A—QpXjJp ?@dyQD2”ye}:P,/Պy#>O etc]rMt{\"O('lG2cbjזI>Evtʶ.SƉ-9Y9"j6oK+w=qήX{n?gםamQwvH!Kz}6U1՘)$\}O. oڍɤY _J'`EX2wZx6${z,~wl&PJp5f|ZωN9̄`H%׊" %S{1 y&d} dN3,b`۬jnJvApEbOOܬ\٣7 7c 5Q$ͅj}۫jPR6%F4m~ՅOhh_M^pYLxc<|ɪ懡hLN5Ȑd'A]6[KշdX|]Ww+cUIٰ z0ZuI35qD'bJkb\ kZ X/K.I .\l7)ְ&`Cqiv;MxxoJa@Ho>r Cf fWZo&iȢ'}Ts Ɓo2kKxgz=J1=J4 C1M)М +Pa@'[ʂXUbT.xHX{~ kbǛ4  bf Zm5[;@L4)'E8lõu`˖|u$"0?Jt!e &Fމ'd#]` nxS购Tt\@3{eq(j; ;Lʃ=#ruߒfl(s"7I{j v+|qN (r}&&Υ LB ^y#t@=Q5x#o;·UF+e*!Vq&.xza2r Q|B<ɡnNʹ;ոBs mqīS<"Eg]qM/iބ ]TKYJ5C { MynېCږp؞%͝^~bAmz0䃱5#o.J0!g1j%fePu%;iA,,2V.%W+޺:P-sX FrYqNidh-ۿ!|( .+:eLÙOsLV{%"0?y܃(\ 24Ms$4mJ/+23?VHaY A 'Ω6Rg8D7水ӝ<|{b'LmnT>8PKA ζz&r{J3m#E*[WS;L2č8u?kᨩ zz{`F?/ wO9ȳ;0:vD_S?dAJÇyK𴝏3#bIݫr5#V!A_K|=9*zV  ٮsYlM"X徰 V@{KF1+)٘K}b(GSuk0y9vr%ט4+![_y|ê|7]692BMOtv7\#Nߏt~~by>|9Kwjt\ql3.r4Ay&'Cy)$^aJlCC;\>S>鎿#U+3Y'NxNac=(3Q2piZLاl e;&@2شpԷm#i |zp8T2QzYK>m&7IOG쓷j5ZgNɦ ߣ nKC EXgА@2{qYs}v YbP+j/9SOgl 02gOU ty܆Fnv$d@n{MSWz*eOqx) 1gg!`HPKcARZ7ֲRF#fs1՟Ҡ-WړN|08D1;Eۓ#pWԁpUC$3Xwq(]Qюݷ.P3^TH,xD~V?h+dޜL Pq#YYTn՛pי%P5- w[z>ݹT5{Ɋ^2CV܈\S =r96Qme*n]LÄ,"7D_Shr"E+i'`{$Ŕ\{2}mmԉ]ԻvwK_Cїg0{fM"n<\Ǎ!1-fVu#8Ag^GO e }*I;zMjMp˚\PhFG?W@} 0G_SMV<hJi|O ʩnt?\l\tdj(Kʾ+7x42} TV,EQ#ۊnpsyktm&հ\V *}GV2~q$p1#u6U xˊxp9P7(n AiDۤMۯ,EZ[ʐC<µ*(§Tkmt-u֊LaaPT]5w>Yx'}*qؠ䤝Ga:?$A dK5nYt^z|^ pуѭ-h#"Kp܎U?` l߰L}VsŢϠXdZ*/5* \gNFbbkÔ _:0͞,b'4ǥS1w 5bov%Y{`d?U|EAV ?Wn[sU79' jxƐN"j|H8z* Zcl*"a=LfM'4_AZ?+oFL?( ٓ|35hM&%<[;LjGwLa?n ==Չ3q&j ωkOu38DZ528eqD9EͱʚsS's7w Vx%S"zߵ$jW76AHZo'Ќ5B1å)BNGaaLo@I$z.!exKGSO#bq:?ދq;KEmXjM,CXD) Og/%6"G$dL?߰T^k6vrWtcIg6AswG2눶kuPaÐJhʟUP/.ȖB8jhsvH7^0ʂp*L[AC!&$Xy݄U6WKU*%Թw?=W-Qfŭ NB lrB1U qU^F"L\>~Ԋ M `d0:ykpc;.izkڥeTVO{ʛo1^hXZ 4886F[rYj jq|imARqJ `nV{v||! 2È;ӡ^ uFJ8C$\Ci674EX_M!pZoOFT!#!VԣLȬ.( |"[^Tl%P3{A>3rN`VDExGcJdvHυg#/;</@k g>+DT J,Z( AĸYf','3611юz9,Ɗ`+'"YTʰ so( rMχ6k7,cŻD}V$¾f_ _t F/PVLRZLN9ZrQ#0p50`}s"1%W f𬧠cM;DA묜Â!f*\|92.Bٜ) b(D'].m_w? 6l$i%i!0G"y1( HMy/G`\NRԭT*~|L ?o, ߺE8C;ϣ- E}bQN߮:mأW ?ي KΩ)D΀%"рƪ>P/\hQe "ķr#tw%J&~6 u6}5X/7f~TY{X33-DVrÊ ].ê.h=D^l(ʿ{9'(!M{68;1~/wD*\43ߊYMiHRf-͒#E]Ϻ!`V${ y|N bux-7 eG ǯf4!&Ia1qaqf>)x!jx_Du}k`g*PjE#%6hp26ו2b{6P91ft0}q`gw 1nsc+yR\ R< _.Ht(vr>PfZ(N{/T7l, !tAO;Sұ JҽC6D+~QKoE@bS414;ׂG?h@[š2L,0aG uF K`8aVj8!4J;t< HwLP؊멉uĻJQFk>ڨY` GpkG 0'/BH||l\eYW\vb Q Y(WD8m_i-e7[,?3sQ j43 J{d fL[3\:#rl{Jmg+Pb Lp)PeGV= F[71 WǠnߊA^útzˤ:K,7`Jg}C (M~^zW|"7_Oxޝepx Ub݉Jm6 a7nii%Z񙶢>PkA1hb"/ۗ%}-ኄxȢɆ-=Gp) `0%_ƸT00nm. TVXH#I3:Izqb!:0րQF<nߣcE-ޖ='Չz16sZn**k@oa_-3Yŧg=-T]쫦 e- n3iUCdtdCQO 9®16N{g÷>vZ, ,Um&ȫcN(dY&S[Rv_ ݽ9 _ې/|GdFXKD˹ uKùen%zAYVҥ$LsI-bfճu s0PO!/D !by;T+gJ3rBѯS,;Eu; .}eQ(?٬jzbQw$kj.bl_;.7}Ec9F s户 @E_nx>~R!E5 R[qn!89_n4}hӺ /[(6)a*p0[t#ђG<[l˶uOx¼U!{9?PHٔ8؛戼 ꦝʕ@sr4lwj~t*MT<АKz8Xm&}UJ+LEp7ܢL|c)DΊB>p/sD\R]!T+Ei&Pç}H <;ʼF_eTv{^%wGN cZ- P9z8Pdpǭe`L*#t-Q]ζ=6 %ϏKyxXvdG3ҽHc#7!nEvv?C9hYZJ}I^^5ߎc~L2~\!g>St]># ά1_ Ą%$i~3IX*RiDWp꣈ʙ=ˬ# lwl JX6+`G6{t,rm <Te-F'^z]}.ܪ@h25/nɛ[_Gl+ XjB,{<y,׼QIbJ]W܃DOdެ6;18BXZքչ[q#s/ wzǁac16_gmEbzAhajI(&':ɔt\w.D)H3F$J=_y r)-5wXTbguh X8s(Yۗ~-ûfَRQ9˸\yQyŨ~32"D) A{^U5,HmQhs'u ~:mQ&dȸ]R-du@z[&y0_QSތxM6vISZ6caaLlj: %3&}&L@j2n9S[w]Y"GVFF8CM# %Z[9E}LXRg$bk1p/˄j9gxShR$HGYIMm4JfG<"oK2\?rS.&z I~Vnwn^4݊z܁w.JKӨHk*F4Z s|n@Ԝ{玄` B|iE S )⤎~ae-q"@ rkg.Ry}RS~ktʽ`-N䗈>R>"w#|*|\q/,( hۿ`>%>5|ӲsMܸ:84o\[/:n8CxlXM̭*nr9lqm-ԄSjѮka|l. A}3JvmAX2uTPPof}8itI֌,AafgԜKY:E"Kw?۵QD_ +nF) F>ڌlzpEҏgeU3"P{8|kP)w%(J2c쬛A(5}_LzÕg{.좑nHJ_*?.FC 5F:^3j|0A:ڻ7Q.҉"%sbhжc$-&Qe'o[&Ca -5iZ9~Ab[z™ /'`XjiRVu\'Dј׌gUݴlM:u +{ \<,96Nץ̅o>+<$AtȪ;HZ-J`Hm.LAD%8 $k֩hD3[CSS [@WWԹ!$_F4 \t9h:o",@ 'Kaj2sJM,I8bLsy=+5k#GwISNЎ8.@tP>:Eh ;,ZZhd+Ď'7!LqKɑ@EqoyggQjE&A}ET(}6 v.7mײ\9U122!1~e {C_OQdA]1=ɒt֕L~/T1ǸĂe/H#P#r〥QJ0Rw!9ɩjLR޽[J+ 5ӡ\ƀs4>]ѨJĜ%f{ԷȱL?3X %Mט{|jX C|ⲿ+NRi0Zu{Qſi;k /o3(WgDBL| lݢ,66M@KֺtFd )`&?PSr3f'ĠQcX|;m!1a,~hNhTy0}xxb*|+%ܖi!7>–܎feNYpR6;#9v))Ey%SWSX43/s-0z%;݇I7RcJ .:D7#VUujTU3M[˔SY *CJ3p!}-`9s|bqGi{\N ({smI<`vi3 6ŧ(hu/$:4)*8x8~Rz0Y">t̾ũJ> &΁ڢ :Z,J$ SSjJny 6tz8xq Pb7ب5fg[ī2,)o[mmPbFccT\Ra-+fZ{}/Q$&UA&ms[F9pդdɥh2Vkè KvN50کXGIgNvi/dAf*?DqS^ ѫHy/2's7f#WTĨ[y]h0_$”ч£r2:,.!-j8 btGםaդ嶕eI_TY4ߤ\#WI#V$vQhmL 쌒u ^pxSײC*}&u+ؑXȭSal~pTUA3%ny {z?8hX[g"N6]CP)qtP.Jὣфڪ4fD0p^LV1qPMȔwDLl`e߅<%Uu!G5?Հ : t`U^ȋ)WD"fkL.]BI0 _)WT _`1N<'kۨXN*Iޏy)u}݇˒W^kˁ*.tz 4"QMFSg>BUBk֨N4j=o$QDՆ4y2lE%`D |^|ٸ kEC(bpY{ϜTXsj͌劌^ަ_]b G mOCs p|u h)R[r| #j™V5k m}`$bf4('q$MD"ĚUFu_b1U\t栓@\Cv-(oLrQ|H0{l_6Kf Xk[NBZ0Cك:Z :ΚG\!98D+hbU^#PlGklX"%rb3,FfH]y mNO,mFj9љ秊arN8vǑ;>`O+͠ @]]~cR=/.22Or]DT?L 4B(1Oq3nJRU=оؠ7pl1@x?Z $ka/jGHRrf'p^~,P"5NMKX7pkѽ$V Ђ*yfySQPȪ$PC%fPaLnig;szCHиućvt5X,jK| bTj,6*N7;kZ9 !5'q n5%;[j4[Zx]B6}ͫN0*,(Dv$o*(kZt0D:- uݿsUD2yJf7 B^88_*/}MN2&Aqדev6>X6!AYpH$T|K@ G ȮaQƨ+2-0{Ԥ.5zަO[ i{22+s9'?ضE Ʀ`>17Yc)i!\2f'[~ǢZOFPk#`?ְ̈AgR@.5[4D ~}E!\mXP^n O l kML~PM 6Te,͑dXE f#ZC!yWb % zgz_ 'e;{Q 9BgkFcAƜU75[>wWLġQ֌t$1}+fb5+ֵPa$T*Гzt #Rsn%}\Wev%VeGRݔSuڻyؒK؊|Փy/xP~BeC̾$2"]Qj`@cO~tEC*b0fa^u;SQ9q?!fD9%QXB#-W9×騜X6'˃МoY[j5J4(&) ܽhD] >|Vq()0m#Qgb.vҜ%Vgm/ja7j@_XuYb:' [FX܌"^s&/w{UXu?)۹b%fl88; 4g)bqR؋?[yJӫ(Bnp;p'SA~q:}#/.otAysb rdF,{+;3m=Â1؟ ";7ϱǖXX0C~# S;/1k㽤kgNbGE#e{|9hxsrYWv?ׂKjlo1|3ΕR_aAsʄ3@ ɆZTs{ΒiXa};F_#Ac֤u{H;EGOX\ qR/W~Lf'^Ε4!n5qeխN]Q7-2=0Y\?L>,$hqSGp^cX, E4v7A  A񭄁]]H _l#EpvI@*VDJU%]9!{eKe I39 ~9d'Npjlj31!F ׮:Jˆgdiq[ǁ~IUd*֨5P.U~4]?5Rct ܊&HpD+GnmR Y 0 U=K[ NsRʸ vF&wTKgKmݑ Yr}_Ro{FiaHȑ +8.*. J+EzXڞa56xT(8\&y{{|OxQ,Zw:(O14/PLKؽY_3_c/;p P222e}-g>UI'wrAJnx%vx hT;sZҋM)S)ui43T,Js's'1QY'XJlTAM.ϸxfW&TIb8(M6@[NHe4G&m(@/ie INgI;T+mJG]aiV;@Fg߳#>JxViG\M]ue~Y<iBi'*3&Zo"RI bD=w ɂo1l&H{ZB~fSY L_|MD{7φGᦸzM?u;3&L 8c$zdF$)8ZcO(bԴ8^OA|k^]Vl3SKo/{-wP(M CFqP/j*mF\=hS7$ҼcjzDQ#jäUyeuI;SJ {BfLf?Q+M\⃐vTPtv*2w0(pRB:_P-{kPpjP&`y[9I1ϱ909bw̘;]$0`X|JIYN 31CN;N4UɚR0R'! Cc6úº_ݒ_$5nm۹/B ٱMv+4@c_hAMAn_OQfV߻BF0;aTRB3MYڈL7/"YoKuHTsN;Ze$t[ Ǚ%ݬd b| gL8oK<|-q?چZEN/ 1Fdɨdz@OXu}|ON]e?o_}{Aey6h&h, ݈ss![Wp?H`Wet-Hے~EÓ,ԥHTejMيcPP0\ccqXa(1X-w*mgI4T֑~:qFA|rf F6B  \<m^p$½4j/#/=[Vhۙ,E>0袚5(v^`v>,|7Q PϡBǐ9k,-\^Hdʽcw8&?\N@FCi՜iZ|Xm.dver'8K*:GRGt "E[+K5n. k$ÕwYm^bo@_ ޢ`x``v˄9bR+[U@hk~slW'źԕ*/!}꼏z̅KYϝT堙8/ݍovL|{9! U6 )sCFzg3:t4Y¡+5BA,N m`ٌcubwgk-T3\)\2nZmGվYe<Њ u*;sEHq?S9Gij4J@V\FTk-(}@.מNN7G-^ (>Y}} i5+jKuFj,Zt}#EANRObkUˇyFX |$v \ iVHP8|45iTXdi@h^Q|M7Z[Ͱsg]luͽUrە/l M{\_A+R5M-FF deVպ5B|.ENԆ4)yF G-*-,R'OEV*U_^J,d{IcJWS|`0C!vsɐU92DKps@/>r<QL3)$Or}5z/Z.gL541#څ-NjhEzq \K;5]T#Ϧ cGƇ`!l4C^2y ;&Gj@x;eSՀEI}?M*g~0tO,fxab1+"!K "fGJkyEftla3@tNM-(E".‡b 1=>E)f"jcyA QC F&qnLXG?9dV Vٲn< ^Y}5SG— `zGފb04d7򙴦ܻ_$5,3萍 qxE%XI:U**䢰WjtHڥWvs 3$%ׄxJOd~_Z<r(hɿ{OI }l~;KSVS)5g/F>|[8n} ^:=u5F㰕B[UJv E$V1OKò?;q[.3}ϯ+WCfm+=x43koHam@ৄj;_mxv'`c.4e_.A7vGV+c%畴z&$s`*rcdž cuW⛞K5>̰8dZpRA+e]xdqYM:|JՂðޱ8^xÊ~0&kTcd$av/ݦ _IHX~KSMp7LHC7'e28ΪYbYt2|Zq:kqC?*T7 mm?U[h fL҈Tז4"seǼ)MgCLrQ+JLb%]ǐr4J,xl2s맳9w X_X)k^2"D+=PTb]};0넕V6!`ߞمWB+ghVUNExeҭQ\m㘥 v_~wK}$ \)]*h@ vy5wƨP,5*%FC&w0Q$fw7Œʹch+e-҉5i]Y՞dy|ZeU,U Y,#UC%D n RƖ U#kŽs* rsC( +zvWgGs 9T6f8|Y5Lzd{9p@25:f%3}iT%e>򙝔w|K܆=d /gRګ: p\mFxYM8fziVIt:AC捁\)@_c8_bYN~e?QO~nW,ܨv|Y1 iY<,a''"K |4R׀?p&lٙgI+ lO5Q}MB57`ku:響mcLq&s|M: 5*,ل(aHYM}IOQEޖp=qXp$P;e٧Ao~*L!$Pa YfqP;\#QLԉ&P>3nxyloaP++%_fY]]fKf|9mF\.WPm-R$sn=]خ 3΄2+$\[r1H(k@?Ym :4k(UlmG70\jIa$+#R .|fu/蓛Eg|O[X5 L"Uti[mo2DC% 5{{vRs:s7łQy~9^F'sh0DQ^Zz8Cks{rA]u}Xʻ]*qb׭"Q\WcLMZGALk;BTrjytʎ% >r $RsZakU}뻉욙Y|JzW`~^-dPFMj%6N,VQ#n.bRz▏ꫥck%9c|k)"JHNiy03!BАUwW>.'ryt1k%7Wщ /$Bx]D`%*Ux#!6^=0Rȑv]nKّmϿlJګ"(/l^=7u)by=I&ywb#[UXf?U{5׫?$1Jl,\&L@7׷(UbR17krqK!mBZBnT2:m,uhNم+1}˕5Rwcy"/> 9F(¥$eU gt3KɈB'β5YZ{DqMڪI4i_;6 %/!%pYwZhT'nrkǑU %͑ܶ*e;ww-"2s\'k;< 0M?+Fn=6~f<: >) Yûeo®ńѫ5S#Baf[$O)Ms^f#S_-~0@򿬍=E]<1MP glh#RY&nɦ*Kv<`!\_ ۙ+byQjFQ(:gXU Qz ưҎN[!(ȗQ{,]g_<}yit[-ge( ߆d+1PS@Dq~f1]IS [(i:oZmD;mAxz6wn:*\)tK6fd5S:ݼ*gZmtگmU<}? ϕanmzyb6DG8qQwxnB:Lv"0wf^t%n2fTSҷ Z@{.-\3&AW)-oSK([.i?c nO= P2eT4[\蚅t1=@?\#OGk$"!J@F.y%|RxqM iLD34(1_zUAXp6ysXuv/@=KA/c.mtՒ#r#N5+/і:#= hI TG[0(fpiV-SH(. MMѭzKS[6-|+AVֵn-[|iM&e+ۍ[QR9x؟xtC BF-Oc aP'#apy{T=`US+JL F{`rEmzrǑ>, "Um zc^WR:o f@5^F0)XyMw.(Ȋk+JF$vB6VVZjgp-;uT4a":qJڕy,$NDa A ov{zuLŠ[""vJ*.0i_)Kaj|K Vx6 O1[ls-Y=A\d|FV S^C_- 9d&B6~bQ߷2۵:'cڈw}†$/-QwVTؽ>a()5~j4IX^q/{`S[NX,T힠aѽKQl"!$ Sh#DB/,7٥E <} E0|zH_Q>W)@p[`úY+&V^~S(Ev j8QCCwgg@"30K!˪rIWno1KAS(>qyмwCK+ Ѵ> /bEQnl%3zLv/$-+_i$1s^[-6@c;Ѭo`2P|ݬga Oi=e X^:ۧHDomFwz7CL4ˋ6l`,a[\2iH59*pR]g3r0Z\A?}7WsP r5 ;Z/!PPAh/!ȟG{2Cmr4e54p*)w7MVY $+ `v]9r[uxt\Xݫrq{"UpB-e-'$D8 6~ ^L4E5~]c̈Ve0nS݁Bu 6ti3T Ht7mWK2Ð_^yuMQUE|`y j{-Z0` n2nʵycaLJs -B/A`$QF ]+[7PH5rю;C!c@ Y.Wc T׉p?*OR>geM Δx&̈́.݋%A2nZ\N-CdG1UKBIa43!1jF eh#"k6 "+0ͳϼZ.uzNKslك!<"3}>Ќ+uQ03"ch;~%a9T"`)7e4p*WM1`׬4$ |\W:d"܌,y$qQuZp^Q>piDѮ6y{O&9(Mi_.c Nˋo@!vPs;e7鳏svqPXRRH 9|Fa:2ޙZhwx>f׏~zi3USs+ać^T Ƨ<)t3dPSxds'CUD.1Zx#T]ٮ AB  yUf`Eʴ5y mbqͮmR\ug]n0nJjg/+,{!gzdtt3],"Zo9sItPR\'`sl[Z:}W=( d 5F.E÷ra8, #l@Amne[D5s*~fF`v]G|}N"VzQ9Cԛф`od\/_󚨾޾H}9!W'TPYϿ9k{vA$ڠ=.MhDd8w\* Ƚ}y/b:8ahųΏ)ZDs5ZqГ&}=%_Ɋ)R'G>oEWHKWm|.kR{e#~6{k\2ǥQ~X?KƝso%fd"hlǀ}w:qbV¼%Z|vێ&EhY{Mb-}:Ja^ց0T3GC(gYB90{v{.WWNA1ZzoNn Jt('YܓXL'`)ѯSQ{ˢ^BXm~:M_D` &aNbw2 ux5J3ug%=GexA>w\CEnBM<̘*zؙ $T'Ʈtc&VJB \9>ݲMN";Bz*k`٧x~SpI _a#tkɗ%*05Gwɕ ؇Ea*@Kn[ dl4ua"GnO۫"uoNOt N.$X㹈Qꥨ!mzQ6\%¬۳C *S1vV]Ӈ(ȉ$5ˡ J ˟,0վWk_7:"eo{Hج3؞))ra<CIEbC|W1f/!;ȅQ>47%?D6h* o}ݰg&6` curyO-1!eifT)c i=ZY2ҦvbŠX>~؛l=IldG?" #|9T 'ܩ̸aZW?6C.Y\2k&G"fO'hELJ!hN(Q5jI7AٵN:dP]~ 0%+0N칔LǪMN s o qoנFwNa~KAZ[ԍu Oo]G66b?;U "²m[&p -<4+RWE "%cd֪U ` f.H hwowʻ"*gI@̠"q?&aO9%$$?_GbuTqeNw~eƭ~ ;I =T+`hs?vM}_C6f^ļ̗|j/ȏm(ߠf/ٚP=beECOھؖoi&|ߴ?ω A"uVZ|Ya$}Hqb$otkLT*;oB1'b?.0ע++/Vn2/jԂ AQnʎ]qр;p\HcTU{8ԨTdw=Q&Nhհx3 6[>pHO Q5?ƀ6R+4G>E38 ߅`Ʋ7zezGIxzf.r/6Nfw㫅 R Bx ˫oSUڢw#{ SBh%G7v ɁB Et$["eYVxAo|P}Y ly`i:mQ`٦#@6JBc1>ONLRAdI~z-b0F+x1t$ЗO,v琿>VaILcF2:'={ (XUo5"f2 4LNF{Hbev|Vmd?Z(rGE gW޽Pm(@[9˴ELбdYҾ/z4j:/jS#b-WIRi/eߏ pčw# m_ qG ԁy+JT{XW/]{+@EZ \WUfNR~{dυk'.ǂT+g(9!Oo.ɋ@~ê(|jF4O7:Qo`v/} x ۅ%S-rz+Bu༴ X&wKb1X@a?`P-#K\M٥l|0磅. K#bs "H.5徸%r)@nXl}{ f"zǤQQ&0 丮gnMkk;sD05 +{Bj3#ì7 xuX1d&Bœ&<*"ĖsяD6>x gl j}ע3ZE``tDgϪͭԄd`'/J Z*#E Vw $ oewebauF` Kg q2Q+G |RB`Hc9B}eJYRN{uP4VL@|0QqJ`6ނxȔI?&?渶뢲}~DfBQKLt½czF3坿 |A8 3!PtB~@: <XyQNRI%fܠ֔A'\ Qoѱ'[~JPkR,v~̴N TBb^q_Ig]5kHs.N*aKLnDs;K>RXzEלm 9Xq> T1֢ bRYd˰߶,zf&š'r #ٌ$.KO܌kPqiWS@)3y:L<\RDuQϧ͜`U$8[AJ0c<ˈlBSȜӡ7#~{5 M^q$rʃǠk0}l\¹UYͦ!c% ;@`R_L[7TXe2 ]]=|8*qVkr) |k{ֻA;V^rXhZgrlW3#Tef+Sv?5BJ6ʂrio " G2xP>\tO1gHVbm4-ԏ1Nf3xE[UL]rp3W^$d}TFVV\>V ~ e4"o!xN@`fd[vs4>?UPL^5&62%,AP b#xaޚBi‘@/߇5CsUM>WUb)W3ܕa~a).q -%T]X1_XPޙ:3/'mjG{Zkz-vM3'!w 0jn 9\w)xė eWRl Tי,/KI^w1xK \6tLi ++^#X -C`^fvfl~Xc2.jp*-nD̎|%ߚ3~xIE:t0Unx%ZnF-g [ʊHC6aYf;޲Li6 be%!eˣ"|˃yg;&J>k'xL14$ӫMٛb?!}]…`eT|("XInee21Vw*k%&ڰ6EKl1[7y,0~ʫFKwMoWD2y~p!ѥޏQ50Ftb,j01[NAlZuB[eXdT"lcU zAJ;!;EuMCgN?e77fc֕nen cu%8.VZIfb)~AhG+"-$C+כ?#+u V^`n!NH5;,J}[/d'Ȓh=oao9r(4nx;ư(#Y?gvEАC@3O  ')Mu^~/JRϰ%[MD{8G3(/%>α#U:?N IA$^.0PVRme7P#'jf1 cUY`Cx)Q LįG^e/^!F垥!a}SFw@>Tyb*$ N/\믞3 z6L*"LY9a9<]or!Qv*:?vq'j>GcUXG 5V.w.9+ (Vpf*s+* D=Kaթ:_! wr$IʍKcꄚO1Az>h:Q؆Gk&03o4GhĤv\yl-rdKGQ!|mP gVIAY %_7X, wyŋu<^i-@Vzuߙk3~i`f9uFkۭ4|8{eܷ%n ~`*,2i)2ă$X0f@qӼ] tEU=AQiҬ #:+{:LUXv<&Ŧ(iKOJb[fEEu(Guv(N9?Q#/\J8Ecy^6JXR4|RNtŔFx(?mJivU)\_ylۆ'F+=Z-+!gDm闟_j[E7Iԉ.F -(")lG90}i,h.lA>np(k\OdC h:s%׿A ׸un;5m8lJPDWv}Y/ ȬwT,w⎏憦?`qkf>̲^d0.(Q>]OXdtʩ&gEZbayӛd91y<3D_W.de/3㿭^]U!gxQ+1LmYcL%7P߲0[9ZI$qK+'oVq DC7'dڛ=jSLF|L87 ;վ@z= 1B)XcS9"uXL{6;rphP໣uAϠ-v_kEκ5^؀hXLT8"bSKzյmw1}-W/gj~<)tiU)K~lPwOy`@&'MNu5T~dMnvЌk__2˥:+;dka-mպdNրJTjG $jjSLI&yK̑>Nq{1˔/XdIlHx?~UЄqϬ-| :P:g : &j`~y`k"7 bbw+]Y ͺ;۠P(|98gSӁd;V8Y0 (>b'8EÆ$ |/hO½p$IQ57K+ۖ헒e͵8UiWsn}S},6EQ<̽JJt[V*بJowk-H— _JC' Rfѣ=[)8%~^r SrnVߌ_pu4z+ga6Nӝ }*wc9UÚ80G?k (Co!N f_rËNT\l__F6I/ y~_QXPGΫ#?*x5r?%LQ V6kVh0qV~[K$YމP9p/1ކ)`{SjU7-p?~T4Go]x~]X`HJqL_! {?Tv_^(e^6k)KOw [4y;.6r'gЫۡ2'תšcJS5Ԧ$SccNu>@tGj݇8'\H#.ɢIϏZ9Mh㖉$X0ygH+i3EiSIHcjkYaQBS{0}N3D@QeEGj)]߿ytSw($4dH̽m7WGQlտŰ, 1Xi܀4߸ 0-Z =ۙ%ke&Izn;ǻb0 4> Ck%BuEU3WjagKG @'Խ7FZE_ 7+Q鷪1Һ@)'ck yqc_ D;S&Tz=χb ~뿐wCtѣ ;f3z\6y?dl*[A\s1auZd)B߃E .ul}KTJG,xO}"'҂u4uP}M|<=f#gɮ$۽?$qܵ3<*{\UXxH}&6'u.k=t6{ebmz*| xX-)ƌ]XTzOJ^C |=~͊#ĥxHZ94W굌nد]G C-hUZ_>D&%(\"A2d[O*|x'ٖl$oAF6o[ie&a`'A^C}ye(}Qc$(lXv5k+Ւ.#hUtVi7ǷSCiKs[~z"8APzeZpIP KQn!0^.rm<í V1BrC Rk::5^sssb$A6O5WPTz lnP!+L2 T) ;5lP1RUWG\iDHbUTBN$b2g=5 [aC/`qXL%(SҒQ1xS8nѹi@݂@N<,"2cke9_ ' [KB6FKӬzmd,T, 2'rGR~MfPle025*;-NKmbs&<T]~*?}P (7AZ&JzDÎ6C-*&bMygHMA*#WA[?_(!r%_qd5[]t,)s  zKK *DЇF{9䰄Kįb?TUSkƛoH5' +[)2=U$$%ʰZLt穽|jD%`)iLIblf⽅FX r%Kϋ}fl(B i_`'>*%3?f?04\ȟY$t,BnB ˭;vCBJcJ~y"9x2iΛWr"`pbڟ}*^v2key{򐁅aM p%{&DxHNAܾDcH?}[zvA@z̚RV+&=t*Y*n,J)/ۇ&jż폣J\$jISG=*{AW NLR`pAטFҵIWJ ؐfO;0POWN'nGc>P#D3xO!!dbg t^R<5RݫLڏD=%}%P*8 bQA5EdI(̃/)Pp{ mS-v} + xmkIj)7>Ke4-yka*\Wu &ֻ~袵( F'dD*Zf+-SIe *åyE,'n, )WBJ9974BJ#B1hk1 d $kFNT k@:͍[@GeNZqfM2]1-~=cgk4w@A߬Rz➒?N(CX:r^y#E4X3сR'֥x79#I?NbwXc<ƄϵkWD/ɪ}نwh/j3SW} Ѻ !`kwv_p$=qv.& Â8[5Z4٬0sa:1p7e X67Sk`\ K.mX`Tx]܄xMp?k/UW1*)INyP])Ɉz|z`j}|HR+ո\hJD_)l׿c߆vؚ^8^n77سȉ[ǘ~ρuyTuc)(vm;S/#Nԧ4TBqQL2WEx$7Nt0=Q\GNw'~*8h֎^օ OXq8oLUyzg[0%[ʑu #h1[Լ7սxӈmwK;dqu?_nۓN{]̋הK,iD2d6-X ).|t;RAl>\wcElͮq{\D;H$|R]cA?9^rpztXV2Rha/8&%qCWKD3_jhʰbGVE4J`E9 Wk2̓znl|\սTlM"n-vX[5b|,Gxm@H;0uҾL&=࿌-K[iQׂzC Ba_+M骀kR)UxK@UjrAm2\f?ѮSH5Dge;(eY5Ӂީ8n8<\Kn ϿD jz<΄Ъ 4O.p[1^[WQtՒo*>9D|u}@_Sz;vj2=?r@KؼU5 I]cdF#TE%Бsɏʧrf!$ 2 h M=aIYCfrW l$BDp9eꉈDCVWQ{"|Zp`]a=[OwNzIq޾{y=|3=Z }bjиaTZuomm%ψ #|7/2Gtw( bE&_7R eo,T>1lw QAu8[\ 1|tQ}l4}x\6Pz@C`pEM\ eI;`@- -7oٿ:CWԩ]҅Mm){Di$w2U2{5H|Wn[>Bʶﻊ7#4ˎU 4k0+bqО@i'v&P(͏ު/0pTX+ޏ۫ H\k m%eԹQ=~e?bK@4ubi%Ul]Ə9ŏ#ULC+ C- Obj\1]C~@QӢ}{޽zZRJ_/2Gm!nnkl,:/z/1T}2RBEs?Ri(Elgp t #z}g6]n[˹ߞ S*`ё."iқ۳Aےp@Md>vIDfE3%Cw^jAm_ QMR 8{ۘs7OEp'}۔pWo;,qɹFhF2#s RsEMPXnKâW@-3ĩ'ʓ$lp6\oؑ7*t^[A<-ܶ8hE~D:)™;刾(11l`q~7Jqs&SV%jSqu\~L1k|&Gu7E(Ys}pSP#mSw/4luE.At3PUnU#X'ܮca#}-tAvY2cG *RkSu=[ԅ.Nť{.C+F !MJwc]Pm2u>*)mĔU;w 9_M#S\jkAήG%~^?$_fdWabS|^oj8gwut p12=\C,%~}۬*d+G' ۀN̓-JW1jfOoXpQxJ'2;B|<}_^{NS0 *)n ·++EGVHưֲ[ᥩ1S>[G(ĦD)`>-L05iLר.?bHrAƻdÄ&U>l-za:?&SC<~הes^OǟQݯ{烋aVI>XtBO;{Rݨ Tu Ǐ$?n`1T`昃G+3$;.!Vxv42hwk9%_om"6+@):8K=$)GhW7̞u^/?g/͚m$|Cc] }|Sz4qmH/5_-&DIؑ1|])gKyxVu>!h 6PKƹ2;zKiJ.P`ܑNxW Rrط }x\|AJ8m~rj8Ha@>BR' hDZq_sVd<ͶWc6K7bb9smPwfXу'4zۡC*!1$D4EcN'"L\<{(Sut0>"-#׏qt,?T罹}"2 !d#on&/_YA5Q=ˌwQ؜-s.B(L0LcXS715#0jrЮ`8:*ۆEeU̖oL<-;FqLT7!KDo>J?R.*̅N^ήNv-f#@$DN%Dv33+E VxHo`!Cp(n~b쫷]K^rGƛ-87]߾M$cceUSl68$\r ;sK/j9M c#EUZuj;7X-"D#۹ت)ƛ* ^qbz-m<b\qI<hU3|{r$t#L4Sz$$p3Z:4! ೭h8Jl,QhC>,$#U|̲rtԊB 1bn\\J '2`jQgjDO061F hPt7g^-18ԢG8G袯Xqսm5WsRH ]@\QvX bHEkwCf zagD.d/n &5ط!{Wʬ@+7 q–oS5pc|)eoPBAG 6loOg G  W*-4ķOt>.\a60YW{.[ FYGk6 U@t"6p(밳[dĉ:5#à+ymgCs/|UCs ЁygվRB*h:hXQ Ѫ V{fP3,2 .9#etdGrȖan}olß~za&F#̭Mm;ìM,2ɱM2i^VH#3`HSrB i (^~e9uGábn:_6)(=7w\Zv]?C]EI'sPdyQIGs"5Bɫ~P{'u >~kox,Kl'g[>jF7ŜD.sOx^tNgoR]Մ[E; v&Ƞ[owE%W^K@L&S5I{H ^O]1"0)U O׵QMވvv$;A*| y)ݭԅohYN|n{O11b@Lg#T^?3l a;| v$DլG 7ڭ.2(40r%Z;v. @7 Q8z,NK!^:wFuR89n9hĭ1"K ^j`XQj9)VtJk ڼjxL2N$ս}Sʉ$qKz.|P+Ӂ<'xdz춍?6ڃe*gZU:5o㐥CugUMmx bi6^R3:5]!vFx&)i! ,bӆ w5Wc n4>a>܈|e _2f +|ď2k+\G~E:jtL4Bb|>EL6v3R7=/bqа#-\NуXmr|m>>omo GR#A.PrZ.r" z")e3dBx F]Rbs!{6Ltq ϼrnEYgcX=FEJ,5Nq@Ϥu}feO@a N7ԡV,ZvfY%d7%iꘐJgW`JrP°ܺZPÿ#d"hhDx(#b^s1jƔdML x*{;2;(Gڂѝ)x&dGjZL9EL[u\A#zohd,.ۇ^HD" wۅ2S)t ͖^Hɾ nH`SU/|XzτFxw{!.DXRy6 6[GBy \>>3 utu}om8^)rB($=&Os}]^<ɇQA&GqOM?0uElx?P+~| 3ϲarKje oeT법c1WȕP9+,+s\k;PBAڼ&!9`!%`]eցwsHUx,u\+^Z~µ^nv,eC[>tPe%IP%X=}<` .h AqF"gz@9Xi]E7Y ܍|@Sm9 Vm"Bhj& @Q0dAi,TZy`NLppJrĎX'4Mb#d=Q-3iT@,ܯX+(u慴{.h">|9T5AYd7˞:p>5 x2[rv91C1 uvkE2Ο͈G8kvu(1GoPB ċ br-ӟǺk+NXд,eh@ =[wa46=3Uv{ع& .gO2X +:fqNF/7XѦsz)R0Ƹ$8 Sx]Ρ$gԥ :c;8GVKK? CzcЅ ɓ^X}9Du%M W ~D9ݐ/1^(+P!q0Q/HUh_ol)MpRnnyWi 5jC۝OwZ91! lnϞ︂L)8ބ{kIL+-}3ƛJ{l"J8m|a}Pݫڎs6$y!MA/qIDJL6;O?c(/g*0BΧ2a PKl')g; Ae.DZH2Yf! f#'mWӄ4m35,|NXlϛ a &Iԃ,; Tor6aG%E?4ԗߠgݲb`h5Z_Ut's4V>cƌ;CvD9iޓw;!"q gƚ^DYDkn_#z)yڔ0<|Dzȭi8Π#C2ͫ|9-nG@ϗbqHSɾ&S_DdoO8MBx _+$CnFHAzt_, N̝RR?Κf¶UY})Xs-ᵶ}EYK n#>&C X]s*T ?ǘ}R%PYgMKq5/ jB.-8ͽ?EF0bNmd4غ0s0G9"ʫ]UMdg` yYn"h^׈uoOu!MTyFm ن=wG邹yv}>ܰ /'zzB;:`{pkCXD!kG!f$S 3 hgf/1?+CNqջi4qm5 cۚ:J&#-,?U#c⬸>>\'qQSϹCD=|ned@S8`>w?cPJRAő&o3|(^:M32*GsZ2o ^CvlՎ`.m6Oat[ig7@C~ x)&P7d9I![5WۻТ?p "ݑzaY^DGtђFZs :A(!T%Yu.T JY %D1ѩ:iO/_u'O@i\YްKg!:z!NNS:j.MooV{p9* GWХZ$yrC] O ?=Džp;*"ìX , X=|0h6 4Y,M%~YA~OV0b+B=rhi'n@6tI1)O|Pl<_O{[8[KtNor,7RG3PUrV'JO8:kaz~v8E;ɉ)9g2=:eE1Y7ƅO*oAcL=iC`Zy0*9p1 ޿j.,5LyD&h ]QLH5wJp4|HB_7ųQog~VFX3T(d'p ij :O:EKTg,߂wНKkx3"@5eX95<87e(c.lMmDmv6&Y6B#6 ݻvhq(xpPKZhDE1"4w7 3OGC)U*%w1jA:-2ZcYxB7&½jv*h'i/dKNR7!`洈.f [+(mR|_VV6C2t'#$}sÓ$s[DA:'\/PkzjcU4[p5ȃ12e"jW+ubGfr+*ֻ/VŨ$ `d.;Yo(K`GZĈ@ e9Ϊգ>c`'qk2(ZESY;l:|fQt9'AuIl~(*)CTj;X'XPI!R2Зi6Bpm]W =ᐳO! lAP΂ȕ;kc\􎗥$ e&iyfF~ V**9=SWn"аv\ .c|_obO^H<3PV*Sp^Td(eѻF-`>[}wA<{<hrϊ$g*R0ۋ ;Zǃ];g9Jh<0wv-CLlS<&-6DVxk|juA~t+X3?)y7"Dc]5T) dƀLH{#Ί#$})>`j` (Ҝ 6G"Q ʃwu9v6R5d0U) km+|{F}fxTnt "Ӊuf•e@:ML:?~\o,wF`bUt+32R%-=bDs BcJbm=$E~r#:cE HM ǾKVtAoWմC9(R0&m۵?APi'wɘ9ʠy#r݈81n:;+T\v-v2۔l;bC~[{:,BusA/zoc`66jP?khygm^2|l{*p0]T~<{Má Eߎ ZV,e-V[T՞¼`NDcpȌϩfPy+fo71es-л M6-V%j<]a<22 ];lA0kD s![sn+h:^uf1h„,:2Z// x>z]Ǭn|+O" ZK}{+,ha0$lO߻wؚ<iv'|| !4a!X,¯v;'$DҮHv'T 8,rv<(xB;|F/SVΔDu+uMB#=^n~} әB"ou'N1ݍἧGǯ i? :_7-AI?<hm^&RFfNu/AwEGiA[uC'C iknC) ,|fNRLDL*B$V#l!;-cӤ@p -mLiF5#eӔ&3w Jzu?=@'=v8yC6{9ćz3Ac$zg%aR*Hw973Ȗbݙ"G3 QG].<mRdho6^)RhVT@ Ȼ](҆^@N_GkaJ 4n<~ 2Y%Vxa1RA%yFVT_ ؉MEL0=hػ 9RjxmL%L0߿Hp}ҍinv^s7%=[Nd@. 9YԜ}10Z>nfllz|`W lF:lqI/Iۏ4QAO4~t`2!hޒ= Ns>S-52NkYZ  ?$C7܍l;&>KlxOϬvqWw?Sz:HP*3{`$Yd n :RK%?d1<#jT63D/oB-`XJ}?i,-{, 4)%:[X\`;qx>AUN; ܈?1K uIʽ# :Z O8u߁ ~Gl.$0@IPWƗR?otʂvvamS I2h>[?yMdF`]= .߾܅-9qJ@mB ۗj=m/L=Jdڋg[8è[k=yaHӞ-G=V;,~擔K_neuo"(QNYTٍќ 3gvV: 0>oflp&^r UL]gB+w&ϴ۴uʆ@qx>K+*w%v4dU!oEÞ! 8?W̙KE*7pAQ"]0IdR[s DαFR/M}:jwդܪ£gu-=%_fN9B`x-9|U.&P .>t*?.{YY5l*CpeZ79am袞a/k[e\4KHu=d΢PPi7q(P3Iso9&,tq-Ga:e,C@mDU?U1ug[=7?6$N{*_X*JRqrYT}Nϣ">p2 O0-AE%vחv-l|f=4G(,ŵ4Np iqHr w y(aOJnkk==l5[//"m2kMLvqNcURv乍0!AOWsZXt&{SXq{u)6ic$?Sj r?c%%l5XⶡgW6S:jr@B彵GL]4; @:n=Ѽ%A~gT_ ij,(ˇ.Mؑm1R)o\bOϣR=:іTXZ!:Aw=B(Y(z?“2''-턈 i-OB'Dx5g(*Ծa PkD@YC Ho_D"ۙm \\4/Dvy~9xqٿtbbZP3̂ iPdOGAJc쒳x$dݣRb!$XI*U |?KG߳7 ,Əl3$1[EXӾ0LOlSj5'Aݱ1Ne~{q[8k!\`fNQv6dA.BIȘLtSB>CM ߿?RB-]vT"y#yV@r8ƚy/m8;groNuY"իzhW"ӷxȳwvMCyީPj Gpab%0H-/Z cF0cB2!\BQFu: k\ob.Ԥ&U AM. kw=.b4sp3ux@$.w+i WGz#tUNmvF}O7G4S4c:SJ(<`$(FFn$^ '%ZHOQ:Yp`HArCR0Q'Qً+r NN;L @Vc4F(Bb䄴cP& H6&,pR;+\k!WXʵ[X*Cډ66DIņ9q)ޱb'6΀esL¹488td˛6Zvk]rx{l`uB Eͷ}X2~4 u(mM^ [OsPP,dNch&ЍeuB<4@R:-L͢ V^_DPV.~W},] Ksq.pm]oasW53_M/falj+JY@ScFo{/^Ǘ:pm);Ëk%q+M>?Cق}N_zv?,5yOsd:+Cgj? qhő3gq+Ox¹٢.SoeukiRFG b>nY2̃^ SnMXmX\Q]/vmT!C(s4y*0tr0eHx{+\2*QC _Iɽe-NE]WJSZTA_"cʢk'?1T,[;憖8=La}?R>۽fB}~+[<؄o;Κ[qE(dرIݧ0 ?ѼB=sWt\Z@0(ڨצŶiuGs&(D ̬6h'ݖGxfdOnٳjiNBrCMBqw^[Jڅh|?V^;b{VBk.j2 TEE?]!cK b[d3NN2?$zbHfspGl;29gV'0: y=sCa2 Е$A,5_^@CPIO"/Or_eE[}#ȋWrR~R_p6g[$YY.ISjc/ގ teej}Q@(4gZ#Ts!20jK TjQ- γ!_TzדFoZLX S/!@[u{uľ-ӕkt(v /S|]mU? ݑVGdm+eII|t猥γlb%_򢬁~tk`EյjֽdEMw>90`smm~6͹օL05Kc[.3[rySr Y)ycpPe,` lU+$!L!= D=ŒB3۪ӤqRwxt3}PvXM0oSص_V܂C @*0dn,e7 ZM1bLkIFqA:vDÍWyr;iw0sICDL ׄE%aOcO?{Ǩ"E­`<7)fbtāf'!ġ8X^-ptD!a}|\~!>Cܲ$;|!Q )G蛻u-56$FWACKэGp2[O m8+%q寧".cfDcόM5n^u&p94q`?EyZf<҉Ȣ {02i';>j:r` Pۚ6| PU!B+,]-Cy]]KCDyR)F |~UМ6 غݲ rhO\2è5c Z@ehq eqfWfz˷f~[k*Ghgbݝ ?W SO)OCĊ/9)<;RLQ#~=gb!͒&Ko|jv8r$p;8,B9E f?R50CQ[=}u*dT sv "0 &^oऺW4//(sXd;xs+s)! 𹔬}=*83!PscROv*ۦ,.YQoM}6/;QU@>K3hV{5񯶾b a3~n~ FJ4`>K¶O0j'Rf0a0l>`h<?;϶}ȓQ=׵$9KN' Ց61,&Vᇔ%[+!d=BB3Mm7s~??!X1:aH˃z|@}4&v\J,;:g7Qi``T<38*F^pov_N@K~kD{n ,1 v^'4:Mүa(ݝoP%qL<ƜYش сzJcV]P<|4 ɐ@6R\2kRl)!x#(DQS2S;Uu۞_X\%}6eCA>MpaL~~w(Q"P` L:(u\HTN'[.b;Gd $ȃ]+'| +kgVbR'Zyzk-0#Ղ +8H)5'K\: r=IzwJK$lS-xy8h@$g&PLXEjsʴ1\9Ʃ=^ϴ /5&;nHz=F WWծ0ݔ-|7M4Jy(V㦠rtFbٱ|AچG1D|ulg7Ywļ}rĞx۸>##.+ۿ앙zKo4CzI'^b?kk" 7'E a,% t/b{kW^d/sB8!ˑ5 KL. ,YW"98x 1_ %SfW|N B5)3k> 8{`'^ESs z~ZΤL-9θcyBGL3xxDa WS3^X?>]?5Zt* S D"ůU۠EwA}kVM:ZHeȼt䙃>͡:!U:Ek+>(Gr `H# *NoBH\ʳY5! *H+5e/yUltˆ}RЙ΃N ,\ӱFT{O%jշ8)QOJ7niǹ'`Q,2JϛW9+# bi6<W;gƊgtRn&ڀDY5ż=fDHԎՄ|r;':b8"qtI#;aM!B=b@j?+џB -`=Qb ODa7UƣRg)< gnJ^ jʝ =<$r{^5{JBakVR,Yu,I!XZ_ׂktȇaJ\d ʋDb\f7Yn#j:jBSC:EiDf\ly8/ UDQhߙ|\_?2bb@Lm-j㨾wNx:C~-!9rlnB!!&om7)xٍRȱ/v6%TYWED$^%,7m/Ek 57]xjf9-4XQޫ_fRs{mX_tus4ʫ O jJvCqy>c }D+FrNP> ~Jѱ='ȑ[-M,!uR+d*zZ2IFkC^jᡆ A#,:ʾ.8yl<!ۢkPtʉ>.U`f,O+YS%kO P>Ӽmc3L79q,+ՀtXd[N;8:aW`6.,L}r|c3ō0a2+riiPdʈYQȂRRPjT9R xS[oQ/\6uuW]ZY0K`'JIXUM0LG.mxZ[h.T+)|܌o܄=v>X>pl;3x(1]rjzWFSgɫPթ%ԞÚ+ DLUtdcjڈ'q70tkAIp'4nb9 ?('xYe{m_1l 3YxoXHmkk*y]ghzs@+M]s'c[D ,K8֊ˇ蓦J`Bimf@~6c܄,Kkn$Bs{uҥt>+\V,t 㨤[0<~ΊݖSSȨ# /2CnK:?9!*aJvͿo" T[ +dJ! c(~~eΩw aa9YWQ-'Z*.噘L u:"[JχJ M+2TUA]IA vH=0KyOH7 wr/XzBOxh) hsLrÐ%t kag6e U.tvID٢ǵ'.8-J*};"]ڥ* K%s0#Q֩5ẉfmiWvS be*Md"A}+IHOmղLNiezmƃW:kaQ"?3z?ݺ90LYOg[ޮ/roЯ=\αݕYFh=x[C`N Aϣ3llu[5+5DXD~->) c%TB P BAv'KSgw[Gj.'^%v12ⵈhj0yv@Gz@FTv`?NiQΉ"swҞ8af娽/'?QhXi(MbwgLB?;D|Ҵ_+qB/ڲ{KJCpX9*z*bk_1gEH\([g_I|\Իg.`` 7aJ\1_v`NZQnHxZzN&k!*9:ZGf2滛ƶmh,9.;/ysp맲!ɺ6]u-Aɓ,bfMO##^|/zJmӸoIq*8jc2)xkgڻs)SLfgBw9M鋮oǥ#zk0 u\ d`dϧ7*o(X޽ex$%MBAt(Ĉ!?ޗsTB -*&xh=q*YI~Wn'Ncg{xhh;(z=r:wBu0o᡾CN/:,"wfF**jҘN. {-Ĩ]RDEV0{cM!;J=N觼[Z_q&&sA&J{;-9rNʋ3Bզ/ *&û-uN=6j#R.擖lώ`>)Ojuw)G< qd^]`㌢`JGGƩ/vgΙ阷8ŀb*}%}nϘA1Z@7o/>dI&ԶٶQL%]0_;*_U%-%2,d;4OKkߍk=l!}Oh&Â`/]E Xe|hk$jq?^q=7ޒ]ʹ\|`V] bVq.x<ֻc4߇;uj>=q7<xo󰺑k:eq$Z.8]c{d8 J[kG sS n}K2jQX=` o( ,ڠ|k5 TIUjށ[xCv@CyX"_^dZOZ 6c@:JL7ahz?[t'N0ڒXckF^ h4/T=)G)u"DFU͈"̨grD j'Hڪ=+i׌HK5ɤї;R/ZK~EEK^8&r2FjQ[W .%\XQO>hD>$S;c/ Z@oJEsuټ(7:y #Op%Z h8dJdØI{7*VA;v[aIzьTL*wVkǺsLmYLԢkErљs #FcY$9tkSFSuJ .x4g?ZB!!hC-dҊVNܞg^viqY/ VHgE=dXj 칢}\qDؤ;* NϔWWcK5,\V(33uBh$?nԇ8y/C,ݰ1'PD3/SOгf(u=UGc,(Y[f|/h8X3jN(9sNQb"@hHPs+c+o w g*ʭɲw=M?lƏDؙe~tz}6 qKkĦ 1usy [W]9PH༙LߓCXI-~lZo/s o^߰.'Tp @tr_7`Qꙩ`.@'~ѐnMpɋNAWz`N RKXBTĽl#@)gBr_;OUiVaZFVxlqkuFbYdr) B vˇQutؐí;uj$0ēO&/ Σ:RG21Dƻݮ. Hxv9^NsLzz`E/:.>80,N!7&rZ@6&bVN|VtfL=i1GmLy Av>d??(G@`7kYbcҽyTUQ~XT7aAdhgJ sL01x3[Ef]N ٶ9(=d>wHP+FArZPUdzVW&m\ Mvf<+=={d5Q|yׄ]~;B%-)|)%AM{_g- a\ycIz^KGopl1QF`0FIGkge_bSUm(hk#4Op&]©.#tjR, n/|S_z7;-mKK"K(;9m&:'qx.6u﹣$6ɽy#i$WM^b?dQKnp\ EB|R ,qx,3Z ޯ 16qM:߇߹v.R3Ul/ot<Bo3u|hIL␇;ҷM܁_c3eY u`Z1QWTt-O5UeٻxyU,De=Uk vk5qc?b-e1X7hɮǂgǙ`&nS),S:"?a)8׏՝X[(--g9uaNbQD١5u0n Nth3L_ 'sP$MK1s|7 6t,݈9{YAI-Oܟj9d_dVXhbK8`3jtdž]!w54YV)ĸs/kP1N}R)IMrv}(ireHLc׭ JU>leQ{Vۆ <`V?Yc-dl!]6+Xk1O"0o#Uf6iCh1>t@-wˎ$:E |ać2ԗVXJvjG[RJ&;$VNwsvkx<&]ղ:CJ\!&ܢRw$?vHJY6Kj} Vsg)^Q^j]CN UL>|hZPE4Q"Z<1YQg+K]0Er> p秚k^1DL} ( MlP^Vgy(F禸 ?&N8 xSu] ?<+=L>kپ=9" Qf1#UnP)v7@ &R<^dJ(挞![rL$`3~Ez,&$Шs,`-նD9 2BLi=,Jk8bmkkPGD(g茼(ꕶ v8=H<^C!\lj:R?L@ǻߐ=`"8yR7Q5WwtLr`jM%asS:HD[ANmg}v[8ZZʌs0)(᧒fmT^,:q "~3lɹ,3A WzO?wRg\b*5OL';ڀSNķ@?a:G?VC}`fl<.  /wVZ.n.t?F!w;`.d9.IxO׍?$ {IrNX SiDތXMLwFqNWp)!H01ȇٵwN!e=i񯴆tŞ1s0DС8vrjRUTA,#KF~#>?>#VtW xA=WQa Q>dZq5BLK=MeR0'ft{è&> P{qLx}玤y߰QBi2XlQcmPz!FYCc'č6ɦ$7Wqj!bQIB|p* hΉDJanȉ{y5t!!{.MjOa9*9=s7 h5l >lͳxhI!Bf˺)[>e[ХrTjuEV) MO7jWAwoW+7j e31P!C)C Rp `Ugxdx}@Iχf[P{|erv23;. >Q8sȢ",2DJz\Ϩk4͑T`UV2kT~Amw%Mp6}m4 :Yb4tz!6w<fQϞ'J] Aanl1rQ֦,8w`7(;͑8Tdu+4PީOC+ =yp1PHZ~AudޚRBOp=q~[]۳;{7g=[hHb1 YߠY'x\E:DeȬa@KHId8M \7!b$J[B._y!dyJl?X1V2|*o> mᔼg Spn%6@JO{-|+y806@%X57 OÒREx{NǘG)P q6?_7F5baI5:@xi.RQM["hf$$Ybkc3?4H\}6w|ddIfHuEeȂGQF?z}TL̔V<}1FM}E_b-7й| =?xSzC5ģEDNc#pL"7>nΧ9v5MMaD\}z;S =oPY_zKYM$ER@<݊AF3j8'щkr/`.%!UݛODZP7HPmmCUA;؆/dҠ1MCa't+Bd u`ˀ[eK lqgl!MI~\o"Ώ9Pvf9G" "$kHBK3hi[c8j)%waqU"ajꦠT M1Y]0 'ٸy;vϑWU#E+" 4t1y.8 jƐ'[A r'$G#VE<(2F-zz|ʓ1>I[RQ@wat2(PZEIV-ާ57A* HcQ ;5aJMuʟ1f9CRŹ ągKT$J^٭Ey ,ŽITzgxIcE~~okoyzYMnc0q~G!>_fѾ7+a?"1@{V~ۨ~GMoVjl~ߌռMwfj.Fq|Ğg?yW}f'N>|PiU 8gmrPz -Æ'S 0VUM:%V)Όo+]Z3%„sj'bo 4H k(.P*5IHwzh~TYCaśqd" lˬ +mz laiA#t^ dI&kP+Sl􉣾[a B9}\@a/mj15)& ՠNQ. pg"i;Z4кysGwhXkIM2E^.ΰch`>2}KOnQ_jWaNޮ#WTc ^Ta>5;AGmzF8~~F&ŊN"@vFHh#џ``n&Y- ƨbB=e/+w."_6o/c\E"A=f:f ˡǕ9?O*Dƈj͒-su!\P9-G+4iv$*]l˧} CsG`(QNkn=3fq!v2L}E+"_|yC=41&D>%C5Ȋ!0BD`X0y,lmxPᙹUɔ4b˅m\/A|ZTz(tYPJ?~SBnmt#ʥ6^*r,SJY|DqְÁi)sbj_:*X[SfLX.n(ZۇeSjWX ]PrG䰝;pA .m)vLǮ\Vb!%Xk/0G6y8:ڭ9xw Kn9φW_gz7?n0)첕L[7Nqm[2G@j贳"(s"Zpr5Y`cwR:ʪ;L^|jrssGZZ7U>Ȁ5Q4|WpxcLlǎkew!>emEFPk,{D横]*gA ( GYRͻ ӟ@U JDmfXw>pjwaI&n5N\= Q~hƈ*{7AY^Ff X9H8,z7@w.}{{#$U{BLˑԠi͍GTzuuW M|(h0iF6tHpqj45G=r_1>!eE~Efm- >)zc( ʪ&2Iih4؋٭sj8+mv1c,&AHH߽̀׌;[˱o٩[89Q ۻ n,UGChE'ĕ R%z#;KJ7y}j9M+G$Z^H 쭄g>͂$/~%).#{}\t7 FQ/mE_QMwVHJNXD[,fJ2QV r D>kkdvLg!63Tck<͇ƮԟgA`2cHLjgTDBZ-Y/x+fPS%pKCxg#-@!P!YYls8=tD9%d>؉cBVT<ݡ8'uL4 uΓ Ao L&>Ixg)9De h_.Zs^[IµnO:r4kw__-cF03+m9ؔSz*UҊ<}/-zuC1FWK7|yo4(@)WD]).MU EFkeap^W&M:7t" *< u^T~oN_(6?ޅmb6=@oqYP`8+ ΖnNZ: fbs:/թ^3 y5VluVwjևf?nj˫7nu]nnOhjpLHYQ/[¿h5]nޠ i^jDFHA)W?:mWP A쎒t 9pjp7[8۟m R2G%s>+d&tEv-qE|{%^!!ǵT飞B-Z\a4H ꓡ+_Ȼnx55I !sp~,tG fOVnLh2bn,s ˨62l~Br^j}`dC =Ma([ossyn:Nj,"@`G ը}I(TLAKf8e ݃lYFwg26Ğ/\u ' T$Tw=v vyeނV {G1O&Źo/3In D̅h[ {#ط<9σ8^b,8|o94bN 4&bR*`]ƛ !T;=+(D}$SdΛtX菌K]j:WHaʦYa7}6>^lϞ;!/}6f($)wi^5#R`뉍osE bvIʣ7QXkf>B^ywogPL޺:NK߰e?CMm/UVL|ay)Wbエ=JHNmK\w/-Q3)ldâe05bvY•0I4d^"ŧBԇC S^X܏|<2HaaJ;m's.;ƍ^!!^8Jtʮ 1Tc r+,+ ӧ_兣_ 6^ krqzȔ21Mx$F:r]V96Bxm>w)) _`uy * r~|7־#l@ykzDZ*:vs ,Q" YGC-#[OVu P׃ivll?CG{ɮˈLuXGzu \5CK \lm9f}5}5Y;7856yahÄʮs=`K-cģ_Ю?gcL1IqU#dG:lQ)ΐyldL%5*dk{1t?m !w2.wD}I4_ljA!zCTJqe/i67M'᎗1FIۡgxV7[uXm0VP)7*>NL2-u-͓7ʩ&Ãm*<YjFųevWNׅVl^GC*'tuAPsM]gԟ#IQ.;kq9,wuA\˸q3Ԭ[v1v0p:DܢM>:Ĝ$S0}FBR O[8T dRo(#gS}V=)UGQ$%dIN:"ON \9h*AoEN'(+X 2WX_52v,)ُpS|K>6k.2-_%%|ehX JBueDrVL~j>\rl 5A D+_?؟\υ3L #)8꽝 W%9>`H6UgHw-m\P*٠;%iPm[a3sr$!5],\wG\X`ψFXM2\|&62&^zn\U˧: rÝ`V`u7(S*WRr9zix|ʹj6J &tT `ԨӺG,E:@im{|sF&8m.Ha"YޗbJ؜؀.u~1ߩZr/Èܲ1m2?EuCVf+R6cdF&ߪRPW/&4}m}5"h0D"P<+_[M1qw(gqA'W0 )aMD/ 2f$SAJ9~+﷡;߬@D`OE4Vp lXʟ;"𭄀ї*G˽e/ES65iGGdٽn,={+΍/ HATKh_ x [OR˔ZP 1E4Yb K%|iWKW? /RQ"IcDOClFGP?>.JE1!^8B7zP,U2Վ,ބwV+lwp`Ljch+9 o^=x0P:6*x ebGZozeLJxbsw;"K/Q瞕Ji{;2:"WHLe[咒4M> s9eO;ᙬcR oOd]H?%lws)Y57o]C\T@,2|AѸ3q|@9X0Na46Wa;k73b!BJDt*?jfLm'M'~9[L;hI}Yh0c+:6z* V;6!I\NQ3nכG&*:kؠmk¢41Edtn/8p߂‡}$^;{1I&qIKmjg5I gyb.їM'n^ n+G筝Eͺ2DsQuCgc,H?b'R ƱS +is]*TClv uH--9d7/{^y]@? 3A0n'b3ş4 {~9FnᖓPZͬIGТο,M&ɕ ]ۈåqC#|._ ]}$or~Cku{ Q!ܹG+B*R&G/M|=銃ZسF yvXN"kȋ}Olي48W\tG./cE2e\982nLv /J~aH$ bTXH)8QK%GF0@#aH9@%꓾K6:qHsSJ[` ] sEU^Wj~хv6jzOt? -( L oJ$ ?$<,A\&U PE%;*S]^S׏` Y˭&0rEkF]Na^"Z0TEN,hPc} t!% 8ЙϫѡZU[ ]xE8؟C:wU@FjJZ_GWNXJc+c^l0lQ%Ӣޜ.VFz}[;)FOZX}%U>\/Q*Kf[F&dd)dliK9{NxN7)e/ 6I]_WӬěN[9_ ^#Lf|rۄ~`ЮWY"䶔4^_t2q\V{#O'"fa``ΰ/1r[hJ<NDph䷆W%H.W_mġ6@D6pJ hv D6B-Tt0<>RisD#tzw}R9%o6Uz5RzmľgMGYF3gF9\kgzVR̽3<Q9pt11IwO'0l^Yh]4y@8/ $ n[7@vb)ş;s y%OE/>/1&#bGuZ~*YDۏzDX٥܂|q=pV%Ux]2ג{OuOBliߌK1+9ќ S ;c!Y*QLg6+qoo%N!S[jT0SF8ENMRnAn0T@ Lq )$T9r/2&L ~q `'%b!y5D#-jImH)J| {}{J4A}$wD6,!W*AE"W2# >Xg*܄H06JOĜWus*Q^(^}rjnC=^W G-$›8ޥjv.28d')% Z-['xh?INŦїtƸ NP'3+nRcF#V+W5I}KӸ}֝pZkưH86OWdHIlD(UO \{HSiya[:WJ/5.Wt(%nIFxC7vB%|G>kv/LhBō2k46HqslGd.Dnv"t7 3N/k&.p2\LmE c:]V g埽~XF/&X"d@"=N.5I*KaGmpib: L޿hc؋%PcµvaH' TRlga_.Yx+J'ƣ F XCK\kl)[:`})< S]y.͒p,jPPv2΋ϢbYƏqwEȦuʵ00кkkffzPvri'fL ] &^=~_a<9i}$0[o|8p?`gHQNקX8r㡉l=qO'44yfr0|Qށps֥)zJFxȗ#_dǃ1V]cXt_`+*#_EXZ&)zc3ҥс70teD:uRJI&gZ-[{|'-ʕ΅OZ<`:Qi[&-9)a)&ϒ-WC_]w;dǸ-`n؅z(u᥄?!ђ09SO=!x.Fbv^n_:~c,עTx')+ɬ1'\|ˉD媃_“hN!*iGsDp~g{8AYѽeozarfhB 59޶KIӏb^qA=/=׍ݎn@[/_ _)_|ײJPm~juMF*aX/7fd~Ybt'jGx5j>X*_epm~!jbf pG˥dNCdF/-m?܋iVsCxLT9P=h&71ae>AX#bgF务@GWbTsdxTEzpW0HdYP𴼮6~0kpwu|8Kh ,O]wey Yڞ!DAƎ'$uI` RHGSnNB0kr,W"x{C+!Ջ i8M0XpY,! (TSEN>C|G*pvsCf"D`["SУ.Χ3GTLS M@HkzڸnmwUF5oi-"BH 7@n32MJ["TtY42!I0hh +!-~TP =h9HM4oX:j#p[|f7旅_|%9Mv{O\f#&Gן7NB2Т3 `^nggIhȉsagN0-7|4l\GAX\W\n)jk" [g}@K9+[5۶Ftu7}4dP'ZMQHj^IAM\LFt~e*{:m4'+^ё`Kja NAUG1|_]\Is rO6SǗkcϗ.]q{\("9,t=h-2859ڗ| #@0^qq2]}Mz@m_Z:$göj`ɓ50{B}n;uPmD؍!PxHtD"5r*uҮfsS‰Jӌ>eZ OE5@y"Wk2D]F`/h(S~gӻ?BtMɰ7E|rF"~qє|ɠڮS E( z.̋P۶NZ6=R𜕡Ϲ6 hOp#ռP1QS>*B:HVZe"=ikA3l3!lH]H=Ndא-:l@x 1f_׶`7Ե* H9~+uTϩ/7a+fj+5I\~L*d;gCƤ'̾#Mn'h&h2v^b;ɏ}bSt`38w QݭuMjNsŠk$5xHL-NG^ZK{O.ʔ.y[e}|'mAL`/`M_h͞ U[A8t1p 0[dJg \S瞴6r{!)a-:{&ңmsJg/A/A((exfA f~ކ4>6OFidu( `#++5xLz `(SjjzM &W1C1]ڮ#L2贴lTZwlvO\RdH-=ӰvѢPcUB[$;.;?ci23h~v<&^W,e'MUduAGv冿HWߎQ :g՝^rt(qvDF긔ddF*eTipOEmF`UBF>t:lLc<؂{5LuCR&b0>Yz^ v-θYM1A~ټ7lK*Y#%ms"4dsi>,D]t1dg^<8h[Os.!|yp^7(5!]UYjYͫxR) ʱ1*ӷnX$ѩA@zZU 6H٣/|ݦC WMTql|3Kiph9!jp`};g+_hQ{{p`hYmwՈ!3Of1L@hVbÙ~oyhTm;İc~[NFak"D*Tt':Ӿ),X 槟F-A\ BZL@h6>)f^4<&<5!qJHࠍc1 <}y 9=M4kړ^p .0PRE€v'S5L3e:IA+ mda(2?A\N֒Rݭ&^#]#$ߡy]o*> OgŦXB왙ײ7=K@VdYjd3<^KLХ(Z<@,f, ؟[G".l|߫8L݋J%ť|֖kn=$UY$vVTt 7uC_u 1g;/吕yfv+3B'cߨ>)C/bAtyۤ:u޷׾=im p_Wkqie }{geEaHԅ:AbyΞT&3I' pbNp![3])U"wE-[C Րg#fk dFSՉZNI9E Mk~cv/TTa>`K!:TFu6ۚgaOBig+̖P,4 /g]ZnAgd^\:]1Fr.vg5cv˰gmC߮Z Dbp&Lo揓FPƒ QI!#?5p'JBܑ5w n!hfzkѶ^ @tC+Z@|.9wZqGϫٙ1 38{GKmJft /WB4}$MWGdS5 kD:0F!gaᙩPu$ 0Ƨ?m2SbF?Bk6j얹U.t~Zk+E_kj⸃u[oU2OXӰptռ<ɩ\pdPS0:+X=oxIC?zJ3 H8ɼ;EL:;-\q3;X;m5#lTp{ `Hj ss9@ B5Moëd!rXQ[Aa߉#"uy]櫰^[eխ[BF-g#^-1zvU}g^4yR+ss(0'<tc%~1=?^%зW^R%t'(;lDe;ʙ+/=-VUNgMsqj㧮Dƣch*7*ܕ*W,CIK3VdAP:K\?yұ&⒙hH+\%~`]k t|<U&-yI!؟07CH©SGVwftM (숲ZfˮhWZqi6$#`)—r SnR6y>jӔ}n2ւc HB@~16+;Dne22/xZa#PU}CN?9.p=KPG~d ˒5 Xh J#"Z;N ؙc9D&(\jR Kde楗QV4` S 2q[g_`(&)gB5f[SNYv14VW S+т&Rxo`H<f2ZX6yn}VU+FwҪfh&ICItvuv.pR_rSUWM|h1a$x$y"c߲kdX%$ 27{PTSi:O);W:53IV֞](pVTx^8!Jx-0yhR3m(yYdnT:D8-ig! -z&~կQ@,Z:@ 7aA!2&5ɉf/A@o$YD-i~\;]PN<,03adzf}8ʱy).i2O]6|'KW]ؙBKQ۲vn}~8=sȶ*DiN9И>T}13^IZ ?=]h%fSUj/AࢶHDp?)/4&s|CP3b]0-6:(qq:Tk&jb\(^cGY}dR>㽟#*j1)_2No5"k(~ gE\(5z 0} I͒ML5C%v-9gܚ$N*ǂX\fFptpg#G\:w39/l}(}mR۶Qf$fRH,_xsD8s`IH5aQbaJ}_2P-o}zcxyN]W 4|JsK^8oI)ĕ %E\ 8p}'\"̦ _*>>XHbTEw5Zz2 驄/i %dʃW-[H.\0- q- Z}Mnq`83IY2#^;q1GD(x4 o Q6 4ҧGsLh]8=qQ5f"\bC 2f;E: 8<ɽ{> o%-MӬU_gDiBx/ \AYHEo*|p-|̝"/7 Zpׁ#ĺZ:M$ju BU*VO3q~^ E{hB m/vCQav,к2F@NVޞ2ˢYד4zj !Or'/C#GϚl/p0%$%FaspY?ޖbrYSBƮgld)@57PKc2-OE}fnF" ,P3-ɑ{'O:DLɽ 78] [2H^Bb⿬5+ڮvfKM"ucsΊgPvZ߬VKr%XH 6IK#~TtdU=4]*lmjQ3(?(p *z%p׷Vavugȑ\Lutv~Ů%ϔ=Z-׾}z^06~\~T-hfnQb.IX F90}le={e#~HwEٸ:B->^ !:D7dCeaBS#Q6t[͓R Gbz[c-Yk%z\YDr ikwO1nt+H٪~;( ECi o Qp J6C- 2/~" )0٨FQR)B౏7%1!y__sj4"n$KKD2\vnұĽn)7j;F.a[5W]r/vsry5,. c^d7zI>BgtMMal!]!]$̎"Otm&Ǘ3z7㥨f3]tAk7 8K1b`8ߧşd_Eҏ_lދ Liu(n)uk‹3=,&o:io\zظ E/9-bm}8ZImM5}ue/thx>NBٮ{%EoqW&*QH_:^ b.]hؿֺZ3wH& ,Qo\pʺ/] !՞uA|iH!x:kElmw|rsKB;DlN>9 {/QP$, / w򽭐'I;pDADdZˆ@ m,%ܑ4+='/L8)0Pfaٗ>n;dǰc-W<2Dt pQhG(s TSVv 8+/Ϻkaᘜ]swS}v{b8=v%(:Ķҍ :&]YP?/6^Ign, x¿ zU܎}JKd_U<|U!IX[{!,ϒ$(Eo {)S3ǩVHEA)_Td&dZZLRZ}06veB`i/?B(6ʶղXV狥ž?`٫s|Smڴ-7(G[%ڧQp[|uo,{CG{E+l7p+[-!R]I.ky#3ˠG5hmٻX^YVԦevl|K]?'khldh /8#O8t撆}]w<3{yQI8FZsDy%ǗTvv3rdIUoJm HKOؗVDי8i[DԚ\OMwZKЪF&/]Cߘ}G[F / ֍mv6JɛkKVzd N7;F:qٍh D;,-q1x\45)+LQ<=TߦH]ޱڱ۹$ϤlpLa)QV}S]}(>{CN R "]YSFPiߴ/wYbx0^f,:!?cI}K;XHӲdjZm]4:&Ԡ`̶ǀ5V -=mτUA="i\%,zHk [~tVF?Z nO׎2ޚ{_§Ht*ts{޴ &nM˷ |U\|ž ,<̓AۄM7shó͋8K5|2Ƚ6%1sK9Uwu /ϠD[Ãh:x0^?;OZx!Ô# ;`3[@_j[WCw?t%6҅a>b7+?М[+& xEҮInwI?w y 5SL*F3%r)à &j0Vjg7cOFʂ ݦtB χp';q; 7( - 􊃣e??0}g,+|{([ێ &j?6CB7\V W=V|tjAmJW4#fM2޳; orA%[|=%Nl氂Xe90t !ATa%U@+|F _+>Z3CѡKǟ!1Q5CꛇOscR /n'O zIqKU'ݗ|ИNo'y[ 1r5}jK2-{Z2 GAM]ӯ1V.{X^u3%Gk?'mVRPDJgзۖ:$\.SFОgܹ?Oi/s`k^$aP@5/ FN*L%"zA #&ɮհM:#FK}hh"?Hr@Y{6ޣ.WkD}Ts_Y0l6OV,fWX4gu{&`Dj؇[L8$3mwqYZ$‘jA[7-~`,ƴNKq8gF?1 [vYG3ak[k8^sB\$9suK:/A[Ҳy70Qɷ{X ݫģDeZa+)?1/ա1,&cxQErv'X'Յ 7IL YsV-v:FU`h>o/%Ժ燺9>Z]l8DIoYe@<\muXYOϘHjr$JJ/ޚCUi #lM.I^2]݄6$O<=M-+Y\cr'le'$ΓIxrھyk2j8 飚Sߠ[sz7WF=ð'Xc[+_dja 3?ՆejdUca3J(8$䪢*=1_z GZ^\[R# czD8 Oiff L㳛՚ugʎ 43+o:'W7@p_dB#-F(/4YJ5,(NSZF')A DyK p qVƭ52 iV}+!, U0QL4oRgZ~&%[9pX+mhz \#4Ę¿)bۑ|6kRD*+zQgL;vv\@.Mη -ت $o\x꫍G=^jݛpNπh,+$>=VLQoxsM3ki]6Dh7, Dd(X+|t*5;O[3x?rbl5%ֱx#@@S4π |48$ֶi5Kd*ZXgQnk>& H&,:bex6ﱨw)Bt –6cL4]T$b($EzUgAy)D]Ҋ36;h>gy Ex6 be [JRP0YM㙨<ۤ]oW7/)~SId4_8G>T?e[׊/n)DJE ᕗ#>L&윧5r v`Jk s߬\f]C$*~ZR@!eBW&~P/0}M~))DE7g&^> o+ˋJHѮhSuF:flMe|6ˁ#j<w Z%l7$jΏNEzكMѕ.?ʝ+%SI<_태G!%ӥADyE9'zщCB#7PEX-"=¥&׊Mo`<cN!gB`f o˒O>$WꍬUߧڍ".s妑!gx%__椲EǯX_O=^Լ*zYM__Z94J jm(3CjW &Tu2\=lP6 CȜrWf3 ?6C^}1_HWnjlITkЍ=KBOj^L7ߠVDtӑɰ0 6'g}h]:\#h!YݢXiJ䞑ά\cN*셲y.p {ڟ4GMxzwi|֙7T:KjB3"M Qj:pxڋ}4S~nj w?n<$ uT>M̸+G{J"lD^n\ldT͖h}ώ5iO9xb,+< &fB8U;TGg֝k$զ",s P\HyҢ_+/b 09c"-X%K=NlbnQ YL,J\줈v}aބ>Vq?Ct 3eNlN{qb~4O韌Aقeƀ׫p*酶Lyb8E;KL `3@B(<:IsZ.1Ah|bpn+ךkdN)DDod?eiD̬NZq D\ ܤW,Rr?تeJO6JUG,\lKh\yMk#Kf2J7(`x``Ƒ~rG;2(+F2ZI.dR(g Lԇ ŽF&YK?z=e2N i&õ_cG9?,~db` @զRy@Jx5pilRlcx:s60#~kPީ#D"!OӰOp7ǑFnJ#iV-AyFw!jh'lISTlv}z$ۊ~jpQEN1DO\9"KIK|fsP;,s X>Syd8G:\+7xI M!xSX8)6Dy pr@vK| $7HLu_wV;{W-sBS`cS/@`@-.zhDqB/Y3r"W-D~У_/;DIo\:E$|bm|Xx9vl%usI] @DD$ֲfҔR%/xwCm"+Gakmy)Wy]! X$T^l P K}4A]a=6i(g;aK<1\-%S鱙+P\+Xns;BX< p4ynV,]W1{_T_ZA虍ANyޤA3F'_qD+ %I[: T҃5*kNx)W-(W 5ݟ%.VB[=lvwm ;޾@Q+xrCJ[P'\v}WPbXxmS՛#"s2hgJۯS\ݗ-JX,l_3EJK;gGRJ3N?:P%tU1~dĪ{LqěV:6;(GlklWjQm ^j|4~?Fh96Oo%ԗH6~ej0Q`{YEFC˾+Mh#͘2Φk"͖u3a^k(&׸٧2NZu4BmE[PަuCZ@&-)Ga3h6'MW [ {؅djLd#CypZ? Euc~)7*!)EKR4W"#}Bq?Iihaxb^N~o5+XdsTO%h)re~ Kki6:R%ۉR -Ui^0A<Kr.v܂9qJi(H'd!wXH(\zY>C5Ӯ;3>JoW{}@ǷƥBF#&Γڞx<[ɇ! ?w>`g{#RxC8) t+@PPJDE^؂krg (o<W N[ؒ +"g6J#Tܜ!ofȵQH*&(>~X@l)?̕ hk\[Y9 +n۬vVP3sR`ɄAUBBb*΅?Lpnl}Ib2^,3vu/,ܻ:I?C} z9nb`e:uҎl2.Nqܚk#Cޱm]>ܥ!6TQ2LQ'yF\pRۨeؚ$~er`!baڥ<>wvZ< xxN=?oI^,N9ڮ w񴷪'ƒ)|ތLl5 /-E2tq-J]Eg2]T޻Np{"PU/Vњ&zʑʤAgWoS]A/K"S¹(Se OG/Wc9/zqriƚ=h.|1?ف:b@,~NBiۂ(ElX[YdJVnh--)j`]&%$>kj5nm>ǏzUdyf3'"ݭikZotɜ] [qu$h*vKŠ]; QFl)@.GCZ)ڎÓ0 UgȹJC\53,7 n0g۸*I0'i1dCNNpfqȗY.mӁSYC l0XEH6n@/wΏ*jq<` ]@+5orOV`Z +|MkVʏDY$_6N)9q4s6+!Θbm'UR bׄ=BjC3#"c&ocElqg|g4#cvAn. GޘSb9q?zh7"\[4a;pֿ?K-9eMWȎ;ޛ#aq@BF&$nݟ_>c`IPgva=Ez1=<`bA=ׂK8F Ɉ=u &28ȭe}a9.޻S%5ՙ;T>!%䦿Y'-iܿ^QA= ұѩP; /Po s xޟW9/Tȷ[FT?[趽{r%Tm%Q+ܶ F'S}vFP&qi{(Od{b޺bV<\l\[m`GIU9yffJȆb^s3[n PV-rwo$64^J;O.gGJ ,ɌNαi`Kd*?W`L<Ǝm}w}H3X}2a? }sQ;G%jCTp5Ogo9#¼z+X)홋~hD&DENdL;QZW>%A 6_!Gf}f[$=b*I20zǖfŠۯbډt%DSīr ܐaEa?jb]sKw2n)SJؗ5NBq/x@jA x&_H|xqXS4"W*`ȦlDBP$zo(FO90QCLT_;t NW /to  WGdxL݌8ȃT5PXrV J$) QTJنE.^8-is-|i8,m3@u#y]X|/l#"|h`yYL':e}S/C ;rȉ+%>/6'YiF kfw27v2v{vLZ)!-7ikxLײ)U-lj< Ms]\enHab sP腩NX=]h myo65&G%Q7 j7b|%pJ  "pEO0o0}Ϝ)4\K;جJ&TYU֯v16J^EQGs!"W6<l7)䥘(b^v V&_=mԹK!(d6,]wn"T1nr ozl}Хl Ry47KAbՆ>u{Iġս PS3 c`z2*dkaϖwځ' {čxOG˯Q 뻊l':qBJxvnD)#c@^PF]v/e)\'-Q~bqV??SJ =f:DBF-+|ڄ =$RTw`ؼx9x*a4?ɝ okk:18&P1Kr2蕬Edʌ)nrL\tGO=༄~ˊ+"q2E@ GLIazT31[kr_B7<;"5+-騃^7V|rky# RVPr8 \yjx}2?y<]#x0*VhQh*5ɨKwWA$1Cˌ:Awq?AH#Jyȯ3E0bnc"`4"$0>[c̻$mnЯvt)Kc1|PMȟ $u)Nt ,&_5s $׳03{:DK8"-z B(K=r#ϵ3 YKQkijTqBƋ(t-Ui4'SP}aٿ48qb)o%d25q3`ZCla` w'G&iOHZI^wZ{輬㍅q"?'pܷoE?a%P~遖Hت*1B^j΍Ht,dpDQSIxMq3ˁφrCQd; ϙ# ݛ%7njnvĖƜPwۮSfUrLH&Sm 5 Z^..7~iZfPnB]fORXCUG" (&؜oŇ-~T22yeퟯWhukE 5rkjcd`~} iMmL!ՏߨphTHSǺ7/i)|N6Lgp1CBI`og Ҳ}X#^RZĺg7P6<v; HDX5&*A\sm R=K4L2͕lLF+Re)ȧFOI~UwCH>w뚇OV6걹bg,Ⳓ*(I 剓ҖdTKQ=T+?DfDyz=G 򙺑NKil_1Ƨ 6cS|ghGy]q4yӻ{v!Ei/=꿪mrC8ѯx*Nif1^&/ ()t٥>NDFm` Ml!}C%B'KwXo-B*S{Ű@ <'%vYK8cLEBۙozLa̲?b (UroAŇC81NwCsWr+G.?Ry?xPƪB`'}n=YʈRݝ rhQ .ulIYKyn) Sƒҿ0^& K^rd:׎۝f8s(Vs $"0/ n <d&P36bZ !w~܊veq *?Q-V|kbV#d+ߚ}mQɁg fb_ SzRD2<{pyͥ9P`8ZILGQE(3sݠV%MxvQר\*zyT2#vex̋vZ@n:Mx,eH( (uꔫ0GHR }ZoLRk{" ޙBEj8ú6皚NZ!{_UO($$fo{sR{DcSSp0EGJ-FN [#`L2M 6G֕+n7=}CȄP6PPM$Q>.'F,?|1P1_4HS=W}Uhxlj'5=< vh'qA}TPnj pM FE,CCe;B'iT@E 5ҡ&c}e8rLRQWghLoCXV6.ZY\#RȆjL&s;U=OgVXoYKx2@qق=m`JGȏ^H 9W:\UB~ cpFbx0|9z#gc"<d#t2:@ ++.%V}o RAcƔpĦboꡚW:qւ8 (L5)*{H42e]7πņPhp=CI=C.uO?y$8>=j\);pz3M'r77H׃o~Tl-J{sߴ%'JN״R0^$u ۻBܜj o#p쪞a ́ # l,5jNZҊъ˞vY>x{#>%tcq>ުlTtzg*?T\fİAxj>h檙ijyiDo}=XwP~T]|N(>TF F(\0tjhKnui(NR\V4g 9wn`, R ҂cOb?]oT`, pm9 61خ IH_ͭ317yY?hLů$})`'\HJҕ R]^|8E4q~dE[CbUDP4::iE8O`!jy w^LÑN&ha',쩕h,np9*KWp2Tqi |~R9dB 0n"@H7/e "|{)i6G}vIfrLbbd.KLQ r~za0az+$\Qj#&p^uox&iSaw0>ҩr"rMVZ}; ͥFxY˦9W71-T.|O0.=8BE&*lL:s319$yI ny#& W&?וYõ,x~)P3z'JSхJ|i FbixB0PO#c| 1gR"e)dX J@*:VNd~OyǪ'ڨlʢ߽J-RwA}P׬= E/=ɴ9`$UƺX?hOY/b'ƖDa?GBQ]EE ^}YxA8`a6VqNj6B4û@Yc?v MOz%zSc `6B41(>k~:bxl E_^qz2ukxZ ]brK=MD# :qY(uXfRMn9&q{n߾/ MzU 2]5zQ2L^g"tb]u?z9'G 5BĖg[[%㚌vP]^TQxE 1\e@yfD^iEp_ {(͝'ɵIнE͈I+eXI!ĴwU bi nizwfEʂO6Tyi9<fl!}l'U>5N@4eM'8Ϡt|YgBWpK`b3/Ε/?~2.WY6\yAh>G"A"pOTVtJf`F =ج ?UȡpCjV8'7: - \K\!Sz&-쪣"R& ? tGՔ+=/HJn8ߛ*pǢC;Vq} i<-#܇6^m"nr)|p9BqH Z9 1J9M7ϔZK.C81:JV[L`k}CAy3AB &k|9gaIF+&,*9;v%c}5"V/T4!׏#JtQ b/,׿#1g1b2D x+'uD-9]D +I)pB ވr}1m<6դNKؙ0ބҋKb EB]tM4RLUμn#Nm6'{ݽ#g8KkbX TSq+|PDe:6oE_Xӗ79lYbG` -gBlyI; ˚! t{Mp-K_G)@(Yv4a IJ rz>F< h>zIyk-Jۨ ֫O~ Ұ7Zvy\׸G+ڨRNMkb0XkZd1u|B[τ`zn=%T6/-@}\ Qܒˎ4!* Uw^yUD3yX%gf^,5IUS^~[[x9N/!Bt4jхK' +zjrSf./,6Oj`)8,nיjs%DJjG$>q/Dsp5wm{uT ЈB[wy:]IwHcS\K1NF"{2Hƭo4?tٚNu)vf} Œ,> ;7T{ uG+MBaGMf.=K]bA]hl_C0 TdK:8pԫOspwۉf:C6Q>V6 ٶwtojYQYH [wpa82bs~(1&5Hv &|U%gf:< /3 bm^OX֖9:Y}$q4bAOwd?MQZ2X>I-S6 MmL k2CniBxb G2`2)vpgz6&6t]0ݚV77BQe ev/|Cu:=j5+^3^xyAʹd{lPYeec,!X =Xo 2zyD&`Mٟ[ \Rٷa9(ۂ4WPe#M(\vqP~ph's|v,IV,RһS;,3e r煳QCm\8Dxw!Ǻm' 1jxgФ25\ܯ=az3!.޸46b@ ҩҀlJA(s_ -@bP>OflnP( YZ|dvUo[.FǹX֑yd j;_cPU͙ MaaiPר"Xc{d¯|RgUv)_6g߼Hم=މ Z"ڔȃi_qM5ʗ_-'K /G(p<.NvCt`Ս)iCv)v楽#*'ء Nvef0J1,NynJNlW had4dlTYd33Q }"]UfxR 'o dD noTyk* 0/UBe Zj0:Eq{E>7x$^!jc :Zphu&Bzak(N+ĺNz}{9|kY!s*{lH|#^YHkz{k!iԪo+,V[1]1-gn 8V>U Zj<r:AOTxr-Q vS mT6_z &NvjX=V&BJ\"z}B.PHavW?9DС Җ{fĹ$'ƯkxOxxlmAj)z2ĻH P2Ӹ'/h=Y=W%἟$v*,k3fd\Lp9) ?ٺ[%psCe ~Ws!6 /Ei>X3-ͬ}jA8*񯜧$")ҷq]HK&:Wx hM*؅mZ˽Hf#e/L#N_Pŝy#]B?K*1֘^>j{pvnrPK,-/Y-fENJհ3y RdT*'ҙND[OԜVB'бW}u呕;)6RZ9XL#e$o6lxgwTͽQ[=\# LÊ YZ