samba-devel-4.15.7+git.376.dd43aca9ab2-150300.3.32.1 >  A bp9|^]F!wʉB5NJxu'T\"z( LMBm"mY?^<*qn@ g/Ş Tߙ) EwyTpLssHܬwXOjyP1Bi2(5yuX9ZGTʹ=-;0vDQt\\HDNjb]W)(8yQ}H,ώl,“2J*͙gw!#~5sVZM5cd2bba4ee31976d0f3a3ce6c3b489ebb85c5d62c2cad6eb21017c807192160fc31703f9dd083c6929a8c04f0a2bcb74ba7f419ebp9|3RhT/̓z+tuJ Y.y\ DoeBApNI R2zfUer_)/"m\eUh6EF h%rf-:Z >!oFD:xyMniҞz2o6 LX PnkRگj ^娕 ھ"gx7vnaZd.sԻJ5;E0|2ߜ9 [boG$pfY^k&Ș>pAXP?X@d) 7 e/ Ee|    ! $&(+F+-$0h01(2 8295:FB8F:yG:H<I>X?@$Y?$ZB[B\E]G^M bNcO|dOePfPlPuPvR0wSxUyW0,zWWWWX<Csamba-devel4.15.7+git.376.dd43aca9ab2150300.3.32.1Development files shared by Samba subpackagesThis package contains the libraries and header files needed to develop programs which make use of Samba.bibs-arm-6xsSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxaarch64( p=A@!1N  aF ENTv |H)KU +d`@t2!CY~W +g > v&HI!>,'I:l hd Z=1y<u .Y3T4&{66)w+3'A,;BGZAA큤A큤A큤A큤A큤A큤A큤A큤bNbbhbbibibibibibibibibhbibibibbibibibibibibibibibibibibibibibibibibibibibibibibibibibibibbibibibibibibibibhbibibbibhbhbibibibibibibibbibibibibibibibibibibibibibibibibibibNbNbNbNbNbNbNbKbKbLbLbKbKbKbKbKbLbLbLbKbKbKbKbKbKbLbKbKbKbKbTbTbTbTbTbTbTbTbTbSbTbTbTbTb57f48e6acfed5fa9841df0f458c77820b6e24ed8279bb23819c0698df22bbbf19a87ebf5c3ecf098bad8fdc2e0c08317efd3ecd4947169677feb755c5f86b325aa97c3dc8a6da5e8d196a73bfb4bae250089de7237665a3a6dcf5512c71503695cd7da44b981f9782081d3d97dc2d2f26726208f56b10bceaaae6e1a3b497bfefa19c5bf4838b4013a16d205238e5fa9819e04902a006a08044a0da795cbaf34f53c103d9d508de1883fac4df0fff12ac27300409f3a1c8edaf31c05c054340a1dc2974d9c574811447befbe13fc0f8b3d8906fa58ca173857f5b73359ec30f161766db604986021c872a81bc3e6dc403b8960c06edad4595f168293005943b8486186e935623059f05839ab0f3604f56687ceab73bf9ad6070e58a7161041e32e3a21a55901cc3c7a46d6560c167ecef63390fb04b124e508eccf8156fd650dbd572ab4954abffbeef5c35b30e8c5806501278b70a08d6041d8a5685a69cd65ef487680f99891e461bcaf8245acdfac7964fa40fa4a298184528c2fe2b51b3066156e28d7375c095735fe583c41fe10f68711a286dd7616111bd0ba9a6c39eca72b30f0da89b141671dac7d0b96636639545a74f12fbbcc745e7e2597d71b4ca45c2bb309dfe1684a8fc4212447a00f588e6fb067632fcb30eaf8ed39ec802cd7d6caed90f3ed522fb13effd5b3f9ce1d10f57b87a233f8b1cb8bb000a06b812e45f1d76df8d2fe7405deea4c26e6e1ccf3951c59a55836952be0923e7928b343892fe61c87666774dd2e18e31d70da33b45c5986aa1c23a6a853a6cecc906960aa488b92850596697a2ce4811cd350af7aec0b5278c15b3700ff5759a3a9ac8a09b87e376224e944e12a2067e9fc485ece8ebfbc7d5cf0bf573e0500c5bf24c38a14ecb5e00e24e7947b8517b8f39a652b5a4a7cc6ed2dd04dbc35210090e571af576c5ac08f897ec08b3d0d2d5d40952aa94d082f5550483c051b99b33ee65aad7a50a60ccf805be82f6209c702e0e7f73a5ae774d0c68b57b28dd1821c1ab067bcc678b898c16d290afc34539c478fc1f6b47270a45b389de9fb9ec0042b98e789e2e76a17d01c1684441f27e27f5c54d7d8d1607fb9cede012344438922ffecaceea8800ef2175f1046485790f995229035a56992eb9f80f586460519b697827df8285c4ebf06595b743e148919677ae2a40442c80549d7aba0bc0b696ca55cc095723a52645cf7513c55934096218760deb28a607b5e85f82db7c1ab580e91df20133ceaa62399bfcfa07ae216642332bf119c5a28639f3e6841dd74e2dd515f2b48efd9117bd5054262dfd09a3617405695236094798559211d988a68effc888123ae63e8d2ba5b96004c14b3356dbf490b4e731cfc7a56467079075b6004265e32c0338f01e95f47cda607f72abd98a2031f32f45a1470dec6e13f4c8e17e93041953c7a33ac4dadb193dc843bf0dc47196230f74fc5a9c4ac1989654849afcccbc35c0a397ed9b8ec9579d7a3539a11d9a1f4db4d40dfdf2846bc81f966b17d69a728af436e405c6653b76b8b1b0cea1ff3094b88f184043efdeaaef078ca39f9c1b6ffd2a287d8380c0ea5cf53ceb43040bca0c4f8a37c75c1cfd40923c16ebfe2ac820e071af1cba5cae4b019dc46eb22b6fc37174d15ac7b72c723c10d44a520b2054944d0606d29c16714a4196910a433f607fed4e35d63918562c260077a6a23b99eb7ea40a5e790a7d97b17c8adc0fe8152598db810a35a439e0fd2184591f449c79b6bc5b5468443920523ea943440534df04294b940ce1c00c0a68cab9a5eee13b0a18e6e5b9d87693f25c1f804ac1878bf03800367d25438369395e7f2006fb647db68043d1590be759478e33b123ff9a54bbcf1dd70a038467eb6dd4dee91c9309efa27bed7b9d371cc936612a2998c16e815dca6ab2131a2f005b7837ddaceb2598db386c1d34c1a777baf0d741ea2d153c399b4b0fa22367ee1921737df26ec3e9fea81c7f525ee4076db13008901c9ca9f404a6db835aabe1a026f6f3e5c05cd08a28a339b762c6189d4af93a1b6a87f9d9483d5833fd883506b51ecca8ad6df0baceb27177fb6499a7918703b897a45cdc7605a9ec9315a0f82f2518db30b753b0d4ca10b18a94c382f3ec70dcc443437b2dc9e3ce610ac30bfc17aba981efd38215a457355b1f19ee2e93d26cfc3f6127d4e633b3d89ae70e214c6869f39c6eba1bd4d835c031b67bc5c4f908e60816711e8d87e6d93f84fea1eb1df4a7c2bb8a671480afe65f9dc7f671e0e15cd8eea8e37927520f3ac8ae6b63fe8f7aea81f7680951eec3ab67f4383db52789c38b254cd5a9e4766b17aab8a99813258ebb4b147bf98c9f0b9ac8e9e07ad86cc4811fd17c0ca05ad6fa67befb082b2cd23859d7002fa75a5794f15fad8157402985d19cdd5ac697ddf16b6740749e406d835b707ae4332f7fc660a64c8d772ccd2736a816eea0c1acf956f394afcde8741c7d3eb9c1f0d24e77ba69ff7eee8ba90786ffa6c5f4ec183f16ec4fc964c65b35a84e0be1b1f830b8494c8e895196ab132fd82e055cc808ec43d0bf84e5bcc059302e71c0e23a257f197463a9ecad24f59aa597f875a287795dbd2ce8b56438e84f9976bb4b587c364e2b03cea9ac7bfe92f670c4d88fc1b382789f66d991a6e526f4093a1972e1391aadde980420a1dec670f3549f87169c890fba90086de0d8498f0fb36921439a3568cd3a29c34bc8fd9c25772cff89b4edcc989ff5af4189ef2e0ce0e37872c17ad0196c4101f1dab6f2233d4987af03f7dbbfcad01f857b4576ffbb67ed2f4c6cbd9f0a9cd2192a7cd36f8201ae7dc5c1bb59244752a7c96d0bcd9f3e3ad075aecf96bc9006c8087a428c2cbf46832f58f5a9a8a1269d77685a6ea46e21b05e9d22e79fff5ff59e2f6fd5ef76604c85c807b4e3fc0dd84beacab1ff25be2672650e35fc5a2a04de281d9dc535f9718a0c12832630ba0008a46bdb263c2610acfbf6da60c6d585687581e877d06ac2587e1c560a57a924744d428603f832aa43148df878f81961c305f367353717bda17d2ab1d3df620a04711fd5a61149d16c19f34a48740662395d01a17ad400b8e6af775cd8eeeec7fa786bd0c1c686c5562fc60c40b7f0fb213627e0208eaa36a7262e7680bfdf38ab43a302de7a5ee1b18fb5e5a69c693660e5ab407d1696c7b4ac8f6ed075a178fc967e2e68e1bac448bf37478948a1f40401d26eab750f4c70faa63142713b1ca959bdea59f5c83e1d20b52792246b46127464459c635949c3f779518d0e830d9f34a33bef4b8d49477a4a648a2d279c88584caef10d814fafc233b2ed62e1b088b7b99fc6b8017b38dd73cf8dc94a4e97837ae5a7631da503521a5133a57f0445a4dfa2427eeb926d7ece4119a01cd20ba4acec5db90984ce61844ebfb044780a402cb880b08cb0e3b6d709b17117204b5ce3a21b987f0c33c9147e5197c8e52257325852c5c181908a3f4082b5520d1cf8599ee8c5ca7e8584f8e6deb53c1682692aec09dc7339df4507a69a44fc4e889663a695d0e42c4ca1819bd7e814f21ea857ca7a1cf61daa69affa14cb497273b24b2f9adc344da28391ae7e27ea058e1909f8fd85bf9eb7fedcd7dde1fddb48b6600c8b61eccc6409a5a5391dfba7e45844c4f2da58e90d275e42aac178717449816161fe77e2af95aff8ff703003f5691ae2280c0809d15386619c3aaf0620e8697c3c0d494cf0d6a2fbbde841699930bd1f5d8c43118be577f601d6cc6d9ea72bd4e42fa96b0bf03b1764946f28b3deeae86aea0bec44e3c3fd05afd367128b4e2513a8d53adb8702d319f187f0f85e8fce860d35a185b5fe460aa42fb6f41698a0cb03717c956f9a10aa3bcfaadbe145f7723177bebe2a8119752430aecb7121eecb4e1998b5a24b456197855a143c84f2ecaf31540b1f5457c0a2fdbfd8f53f9b9b119b1918376d12eef6aa5248f7ac7d7deb71f336a52fac364750774f797c061e915eb24775ae28d1738bd86f5a5b902862b25dabfc4618da50b85e66272bf52218a6cd2e26338d04c25404fc53d6b230205d0351470ccd8809d4ec02d86007929edab0432c4386098ef7d1c09bdd8cbd6e9b0ff02a77cf2d3de460ded50b04f15ae58b86ce48bba579542df1b00f69e97fe1427fb1031f6930e7c3b058c09850bc72e8361579d8f0b97ce6c33df91db1edab5412d88550bfe89e5d34a73e8be26c6cd20a922ff73294bacfd6ab37123f9f6304ac62b5f3f2c020b7cf90ed8279bb84b70e146d0a47d12743138659271122b65de007d76a54634fb3fa657a0e6c8a3cd600d4be43800c4a74bb5e41f57bbf05d01629d0cd9856ca1c5cd05b52579c70d58b6328de9543dba02672487939e41e910f508c1dbb0923f0726dafc2b4fac411ed2b40275fe0fec3322730f62b84daf91fb23bbb081489863168493d1d893df191dd1a0597fa2bc7c08eeb7f3e7aebc136e2d47f375bc7a94c423e7e203b82c7d925f8de925ae2a7fa411e4f01552b55b174d6f5346652ac116b3bbb5ddlibdcerpc-binding.so.0.0.1libdcerpc-samr.so.0.0.1libdcerpc-server-core.so.0.0.1libdcerpc-server.so.0.0.1libdcerpc.so.0.0.1libndr-krb5pac.so.0.0.1libndr-nbt.so.0.0.1libndr-standard.so.0.0.1libndr.so.2.0.0libnetapi.so.1.0.0libnss_winbind.so.2libnss_wins.so.2libsamba-credentials.so.1.0.0libsamba-errors.so.1libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0.28.0libsamba-util.so.0.0.1libsamdb.so.0.0.1libsmbclient.so.0.7.0libsmbconf.so.0libsmbldap.so.2.1.0libtevent-util.so.0.0.1libwbclient.so.0.15rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.7+git.376.dd43aca9ab2-150300.3.32.1.src.rpmlibdcerpc-devellibdcerpc-samr-devellibndr-devellibndr-krb5pac-devellibndr-nbt-devellibndr-standard-devellibnetapi-devellibsamba-credentials-devellibsamba-errors-devellibsamba-hostconfig-devellibsamba-passdb-devellibsamba-util-devellibsamdb-devellibsmbclient-devellibsmbconf-devellibsmbldap-devellibtevent-util-devellibwbclient-devellibwbclient0-develpkgconfig(dcerpc)pkgconfig(dcerpc_samr)pkgconfig(dcerpc_server)pkgconfig(ndr)pkgconfig(ndr_krb5pac)pkgconfig(ndr_nbt)pkgconfig(ndr_standard)pkgconfig(netapi)pkgconfig(samba-credentials)pkgconfig(samba-hostconfig)pkgconfig(samba-util)pkgconfig(samdb)pkgconfig(smbclient)pkgconfig(wbclient)samba-core-develsamba-develsamba-devel(aarch-64)@@@@@@@    /usr/bin/pkg-configpkgconfig(dcerpc)pkgconfig(krb5)pkgconfig(ndr)pkgconfig(ndr_standard)pkgconfig(samba-util)pkgconfig(talloc)pkgconfig(tevent)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ad-dc-libssamba-client-libssamba-libssamba-winbind-libs3.0.4-14.6.0-14.0-15.2-14.14.3bascabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.libdcerpc-devellibdcerpc-samr-devellibndr-devellibndr-krb5pac-devellibndr-nbt-devellibndr-standard-devellibnetapi-devellibsamba-credentials-devellibsamba-errors-devellibsamba-hostconfig-devellibsamba-passdb-devellibsamba-util-devellibsamdb-devellibsmbclient-devellibsmbconf-devellibsmbldap-devellibtevent-util-devellibwbclient-devellibwbclient0-develsamba-core-develibs-arm-6 1652865177  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~4.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab20.0.10.0.10.0.12.0.00.0.10.0.10.0.11.0.01.0.00.0.10.0.10.0.10.7.00.154.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab2-150300.3.32.14.15.7+git.376.dd43aca9ab2-150300.3.32.14.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab24.15.7+git.376.dd43aca9ab2 sambasamba-4.0charset.hcoredoserr.herror.hhresult.hntstatus.hntstatus_gen.hwerror.hwerror_gen.hcredentials.hdcerpc.hdcerpc_server.hdcesrv_core.hdomain_credentials.hgen_ndratsvc.hauth.hdcerpc.hdrsblobs.hdrsuapi.hkrb5pac.hlsa.hmisc.hnbt.hndr_atsvc.hndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_krb5pac.hndr_misc.hndr_nbt.hndr_samr.hndr_samr_c.hndr_svcctl.hndr_svcctl_c.hnetlogon.hsamr.hsecurity.hserver_id.hsvcctl.hldb_wrap.hlibsmbclient.hlookup_sid.hmachine_sid.hndrndr.hndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_krb5pac.hndr_nbt.hndr_svcctl.hnetapi.hparam.hpassdb.hrpc_common.hsambasession.hversion.hshare.hsmb2_lease_struct.hsmb_ldap.hsmbconf.hsmbldap.htdr.htsocket.htsocket_internal.hutilattr.hblocking.hdata_blob.hdebug.hdiscard.hfault.hgenrand.hidtree.hidtree_random.hsignal.hsubstitute.htevent_ntstatus.htevent_unix.htevent_werror.htfork.htime.hutil_ldb.hwbclient.hnsswitchwinbind_client.hwinbind_nss_config.hwinbind_nss_linux.hwinbinddwinbindd.hwinbindd_proto.hlibdcerpc-binding.solibdcerpc-samr.solibdcerpc-server-core.solibdcerpc-server.solibdcerpc.solibndr-krb5pac.solibndr-nbt.solibndr-standard.solibndr.solibnetapi.solibnss_winbind.solibnss_wins.solibsamba-credentials.solibsamba-errors.solibsamba-hostconfig.solibsamba-passdb.solibsamba-util.solibsamdb.solibsmbclient.solibsmbconf.solibsmbldap.solibtevent-util.solibwbclient.sodcerpc.pcdcerpc_samr.pcdcerpc_server.pcndr.pcndr_krb5pac.pcndr_nbt.pcndr_standard.pcnetapi.pcsamba-credentials.pcsamba-hostconfig.pcsamba-util.pcsamdb.pcsmbclient.pcwbclient.pclibsmbclient.7.gz/usr/include//usr/include/samba-4.0//usr/include/samba-4.0/core//usr/include/samba-4.0/gen_ndr//usr/include/samba-4.0/ndr//usr/include/samba-4.0/samba//usr/include/samba-4.0/util//usr/include/samba//usr/include/samba/nsswitch//usr/include/samba/winbindd//usr/lib64//usr/lib64/pkgconfig//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:24194/SUSE_SLE-15-SP3_Update/c0ea892337fc5048773e39b4fa88f344-samba.SUSE_SLE-15-SP3_Updatecpioxz5aarch64-suse-linuxdirectoryC source, ASCII textC source, ASCII text, with very long linesASCII textpkgconfig filetroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)  "&(*PRRRPRRRRPRRPRRRPRRRPRRPRRPRPRRRPRPRRRPRPRP R?jT& utf-8176d23e0ecd396d59b0c67da5858d5e6d884a8bf8d5eabc382135e482894d47e?7zXZ !t/̀] crt:bLL ?+^@ E\(Sl+"g%>|E= 8%*蜋|t)V]r-.̟#xtuo%F&C${'u=S?,8~4ɦT#^}:7چtM*w/,jHݓ?B9 }0#5vXx6"FB)Qc\{ɈYV{uA&oȍ|/Eā-(DMd3|9U6}KoŋuFȷT dsc氞b"RD UMu\0 RVH2s5&by=W{6wl-0B9nv}6"Qv axxF\!s#FY.xP{rк[=ێِ0܆oaI{xKD6~MJS4Ee mnFzCܖ-w'@HᑗLS1!1FytC%#8<:555 d%N&_35#K,Jq\qζxh5"K6UbPѯu~~؅,*pe!NP5Ҥ0"vQCkXdKnh24IZQ]cEU=#:i@D8 ˴w\IV&$ wT|n*|\ y~+|)&;5.< 3YF_Tc?i . Iom4Vqŏ`vт0y45d"`)R/]Z3dXXMD]CB>nP6j滵]^DAޅzYE (ܛ1BbR(HA+,Gnk *OʱߞM5 \.TKαe(zm(Qr nr9[aFX"(A\%2~r+/*D7!<@|q$tm 0UH$fچPa.&J6@wx?+{iǽ@1®7g WYch)H/7*ݾ^o9:9(<*@E0ZfdDcvN=IԦ]0'i>,=EOWU:6:0gcYΓ3;gw7ly 5wH@)>"ġxOaČFm]]L%̎S%)39uiyrw0p5X4(3}YURW-'m=ڵSoRPK\u#CSF< (yb!yu\8+(Y!48K@]ioB N/&6cO^-?{=waKmPsNx7 ^vq$>NH$-*$r_ܻrY&)tSgu|06M`{쳅%PNj\<ՎX~)Q M`Rt>3$'Q%4~!eq7kK5o.Tk7` cO#1gkV.}X?맥@MY!TV]*bȄ(_vvĦe=[t|")j*K5ASRPi.E{Iq Aя:YbdUV`XZ 3ZF&q#'[pk"sƕ1 )=8hO7+%l5ͨjY2ܽ$xT*bg(?byE7dPfLRGUg!;ߘa%ε/(ƁlUAQ |:=ӼAu 4Nʣc4тJD Pnj]Ғ:).gucA!8`'(mY໓s't', Ya04%`Bv djw*[Ѥ#)mˇQ kЭZ0l{bJnˇ]U-<鄞NUW?\͸>=7+:AC PBafk%9g/tA`Д)8ÕUσuD`ҫ Z^h-mDFμ"P]m9V1fZˆAsMI3y~J[wZ;~ѦEIã<0Apmw2PG)n가X9J ,1cdo?' ;N |W2A}vkB (V'+LQE^:@hj*l .&|IWj <"0%n{.G m-P84gO,s.o 1& \rB3{\r}qO{# ÷Ž]۰/"4coD@g6l``(C6&BE6枖Pt#xE6-(ɍ#>= w?hT(l;|?*Ռ E&:QA5tJ\YN9C.jG aY5fU7mSsJ!D-<̩֑\6.] в*Hvz_Lc2HdPK„oIDe9E#S0S`"23 =esj\ppi?;C5&CY{ nܻCL]foZrTH~\,2:j#6u9q}D|S &qgy=SďY} S3-Ӻo_.0=Vu9H_rc`[jw#M@1FL$?_-#?r@B@}$Gwm &X|Y9C_}'Vs ;v"y;2ξp0,exMC%4zTI'A[3DZ9Wh]54 p j*q+0 [̨!Uܚ1oe4T56ctecThf782Qy {+;(flB4Cj;y KҗzN?cSctclL"A6F@/YPJݫw"m?8*a9 ZzQJy[Xy% 833!z pGhU?=qq˦=::|m‰3ac|!]cE?eMV#ZǯTeû&{> yZM!¢IHWFDpà?"xL U( 2KnFE¥jΚ ʷ%}5c,1x*}5m5B. e|eNsOӔt^eyFot!0=kw#'YS shU@o;()kS.ӳq5sg 3rȒrRUݫVPùq3vrsXu@3]cHh%G J/lmKԮڦ^Q\KEZeO]̦uW55\~XQmױC2hY&9I q$0݀}0_4ώG9&+;5*ңl 5[E Lu;ܬ8n/gM qQz5o]#/s h}Hj43\ڹD[@)?k$c![6=!q)IHOԣ׍tDtxp`CV kpl2Ua>fvxdYXxFL {lTv;E>mI>?$|rfqkEgQ@Tб~\5 Ն܊)Bl!"S E.R(⃁pL<'B/CLwm*-YOpKi  J 6N6-Da Q )Tf$ B^M5@Ve 磢wd:5G,C~o7ܕO=\ 5`ѿ+k7.>78I]) #<ԑ;\K#ۋ+ui),Q Pw\_eb ,9mqEZ6 `,dvec(T>*4E=6fQļ"OjW;&f'0{s)zI& 7wvT,u30$-RF9Gw'SKY*tL ǰd2QrۘLGY5 䙣Iؠ `cg) I$xڛ/58Z@28͋Ƙ7yyA^sht4 q &) ձa sE0ԢuM}:Xˊ̫۴|CoEz̈́)4H\G"xUÞꭽ(A;Iع5ȯsO*XvvYRY'T0I߯k,#I[aSHU!}NxPR;E'|P])CQ8qxl˖^?Dw 64%Lbu_KAy{$Un<'"6F-ig*e]+IaJh΋vair3q*APGORI-2 aڥkcU"'iBTD8Ȩ^}:~+f*:ii>fhN_ ;J^'- x3+<IK+_9WM>AQu 9$|1>a5 ׀ 9.;>B AqC@7NbEE\\4n׿* h1K*7߲N']rJN> 瀖E "k, gUd N;*NU[w} ,R"M!U4պDQ]c4H=aBlp2]&B5g N'?):dKœ0Hf2UytOF(Lx , -'pl{yu)A|erj?3!&v*N6ŧnp&Z%6@ǿjNIH/=6DRV#1ҟ5cj"ϵڼ1-tkc9mm]͙tmKfp[-IS2⎩?b: ȩtcao´U͐e}@Ls2uyq&=IJe,iKPO>bF|/-WM B U}ZpłyCJ cT()&}Is&3⬴PXup-xdsv[7{ m* ҧx+a4c]FItKI?DkoqȝM-1͟*4A7< *鼝F%{t̥ѪdjVvڒ5\e|2l)eðNScw~|6Įy"/2W~yM2ars#{Dk 4xbG6g+U *B͝ Q_"VWB«X>`gq~ź2ήt>U8[Mxߣ/4I x$ vBP;6AԕPJe9U0"QIjE*z*"K#qRNھX9h z3Zߊmkg8F/YǔAf,h< @ii&O15ZBCxfEvuWr]?p"g MkJdDQK9ya+kBRD2=h1#sԂ^_BֲGt ӐvX|KpHz7u$l|]c6ݭ<ZΙn旬4Ȭ&Af EF^EtlQW jv1cy7by-8y4^Dž^_p ]rߊ7_BSX># i-=&}c|`w ]^ٍԏ"P4zs;l3j<;Yc?ohuVD 6 0|?T[aEx"{GWt&vO*)OL/bHQ, aj:SW60ˉHy oѿ(`S{ %H}caL6FjstyWdYu;Cj\a[Lb.'mlc KHoBfFVnP4s3ɏs(T| ֕ ږsޱv6騬n\{578OiO wmSGn]ueRaR=8(S; guǾUX NVTe$2%'zmF ڋjKQ |fRVO,oD[ar)m&d?$$Z&s\\КANN9\=tqy_E YA;[K:`ӆk~as_&si/x.qQbz sCG~?}9o*R`DZ'-x8pZ(#Kw1ǚTwygс& Ohb±hY62>T\ٮڌ[$m1 }xBLQOdB=tc]{*#CJ6vzE*_9dpwEۯ0 >x_EBʙh>a"ʧZ0Z+"k쀾z|a)Юe4*v" *~y[1$&qQG]P[P VZ lhXJx]y}o#'x"Uw!i.1 <3v5碰Ue:E%"flhNbJ^L[3 Fdl՘UH:C 7&qK#kqla?Z{mKAַW e@՞HqrKmlPbKkfke1<9^sCU!?Q=eGqb8;BHYh>7&b݈.¬t  N>bEmp$ki2_bbԠv@8~Eh0l5 g?IZŀ7HSF@ݿy%YA$l`P?#pP b'SpfYS+r/PƭS -NS m!k)lrrk&6IRhÑV5ǿseQ\{ !\`ϵw5pZe~86uHƕ,8X^?HPx*jv|dnEgϲ4 =1? McA)hzFpؕ{c2joA`2%#caֶm4 Q:?,Vc]Jmo'v{؊- K.4=|UOx{GfFTvxe 7 K(]kA2V;cJez}H4lwKL"1#{.B@~S'|1ϭbCkyO(BLiH$x zV*(DgGWNh.- NaXnԤN:j+VՑDsd?>H+ut %+(h Ϥ $` '?}(p(b9$H)m8ix|:PhPf=bՆӮ( 7E( Yм|"߇ ;SzXDs6Y|;Y'GQwLB(3> `OS軵wZp-3*|'_yȯjGdt}-Xj3vBد!x,:;m8;s@:ƐSV^`=|A6f}4|).qN⒃c0eHC5%6ͭ2 Qŭ72"/#NO<8\Cج &Ao@So_%=pF@1%PV3SտHt X[> 8 R{4 %ӗZ2<.-9}WLihCZVd+9EAC!ɠdApHn<(?MrAx{z 8Q)=#&b עAox3$N3ZKkѴvjQ_o{Ȭ^2ڭsV(=IMvICMK8DA?D9*vO e 5"ffܪ; /zҊGJҚ,CVJ^ f}WZ]uh+B8ڋJϳ eln=]Q_ћhaYV~Ay> s  Z0Й1]M>Ec"94PwQ6S.@Y-48ϔB+%}ZR2߮hԣ#?(j߼S7vo)e* ofԽ E 'M~n .f ߉<9"\ni@H@9U oZM>~9':eofavnT(֬iN{:"@lBb) @ ]-I'sJ;? bySv.n8cSJ\XƲQznY!nCKA|wG=:%is34 gĄd#$MwFiD)ۧqFԩ<,sڮ:}uCG,܅%oF) 2N)0-a%Bp[cX6„%9IpR97xN ?7.~̌RRfpKߙ~5R]W^(l:Y"&`%p#)Qx˜Ew5-{5YNk\ƜքHC `+|JάtGݿLl& Hɨ؂ >6+9| Qxuba >"_I2t$Z&#f}k$ /=y2-I?*VÓ/Id; !'҇T\*{k)g1^.-"L'yh`ݘ06X-wiQ2D`t0&wa`zkGN4bv͏lAUڌ[O5B&AFyR|b>X;f$R ~sYx,4HB'ѫ L馕{|QL}deVZe+N>V@z\n<(O%_ lP#~>QM`p٬Кz]OPj8z(%ejڄNg{/xCE'/l?Lizl`Kcey9 W)p!㿁TKc!jp17ubtl]BوPϛT &OQ{%SVɅ7r}%j=9U)E@DAȘ%\#. 3\i;/hi?WFeէ0Kt[NXqX(~{܇IK4Ȋ`ʼϟ!B{]|PS`H+=o}ͽv>k@A]JpF^лgIxw zA628TB)Mr'R4{ڧBΐm҆аWlw5*% { 6i!z`9{rtA!gg$wR!{YxKmy"TDa%0>`~8NFMҼH4"1=5}f\$}Q~VG`{H֒&~ P);TymxnU0etdiP(_#ܽBVxsSe\$lAgg_}N6!H!k8gz]SZua A<8LUP'۪ RFqp^\_2l'w0@ VWRclbHh~[6r9E[NJ3J\܋7{I^pSkJj%_.4Q~mgU6je̎ QI'顾%JФ0l$:$6=zquc䋛ʬd' ~}[2;,@ S 7Ʃ"+>>hZq8P!u劫 u >G}t0DJG0A+=q1Ódi>u9p@,Vd~\U23Iar#PFLZ|j(ҟ# SA !ˌQ15it *? /;}SUW:uʳ#I^11Ƽax__H%X_Kd8ds BjU7lh&$-Ƶڽfc ׶Mim(Hu7u?͔m߈N¬RT) }6K"9rsQ`p[O"IQ-iǂS h][GӷFZщa7NX)k2Q 1ElDaftLhْYNbJ(Uheև+G@L\cnPt%Al&7.!g{t*PEUE@lS6 rQh̀*=ۛeu7Xhmm5ϥ~,il6"/M>O˼ @&n:ąP[WiHs &7^{ !H$\4B&K ~WC+4G /D< 4V6Ө;[{n|/d Ղ2~=TnZnKɇ-A#UKfBLEOrznp+LYj#X_^fLĘ$vFӃ|jCk)*ZJı }l7 Fp {UH*^wajx/ w߃)&w^!EҠ9x[5(}UuTwUE%_c/U8"`̏C('ܡtvZ)jR%Yo7 S5(1I_<+&IkתaIG|W]WPEATn\_9)z0}([l()sDiXb;0O؄ˌ)+`#`j4*^p=AIYhg 2EPIeKJ'/J~yMOe[ePjvQ H74LXȉ 0XD4i3 h(=1հ!א fftN-&i*Z3&-9qo!%,1zڅi$Ԋ@K b[1149|TT̕oi}m91}EΥ5@hn]6ų3P ~:䄋Ҋm=z;i;,VL<p>)g>G kʻWc;JzXcd.ϭiOH԰F×yn 6g[~<_SHwiܣ *g>ނ%x:?S6aBλ^Z "bs+V_v!w%We |;fo2'W7>Uo+s{7M<dplh"h䋬Ļ^7aKAL٨evɯ/Wemh#uxPA۰ux!I_Mr@~73WDŁP3/z:u-$n(YI41\'820X^GqNQwv1BJrrצp* ҰUowzTEghָVnLTKQ"܈%&tE}Nyjfo,uq%-xkV3ṡn1yݯo}}m,n6KoI8{==׳ChPv\T{mKS:mϜhW"83}}N0j^$E34,h8.Z\x1ϟY mmdE&i' #H6gQ6^!}y+a=!Ek^.Ӧp L <+DwGD+M Mpۚ-շ?fp26SY-c{g.AJ3!b|WGSq/!ڂ/A,=׷|pjv[ΔsV3|Fbߋ7ͨwGf0<9W٧UBGEprI?fn7vd Dw+:뵬7Db4|RaF AEk0"AslGJAulK&7b x|Gr^>BbCx4? dIiOăVbx(nE냱zaH"T"~!LdIb_ %]f7qdngNJL_2{}7PV!^ z),8 dzO{\ӵ%6M v?U>zQJڝA9r2X"WFM_Iӭy˥;OW1iE  ;fkT^[|(WCmrţ-a;œu3/gAFMۿe3߀ y?'fc]ǐ{8c)Oߟ{MT|ʯ#??G@"=s;W6X}|HRIMAluu3GJQQuԤF0Wx= bM]ƃfKoSE|D(U) =,A7\ő񽋧&,qī*M!9h.e Zkș\+Bt-ĹO_L&Y 44di"?D]LݪIA9"7y@$eIȹh Ƭ5;E]5x0ъG xv+} _NUlK(A'^ ocw7[@dM݉7ҭ{Tu!"H(Mtn.0X]@l0 [3bonO*bZݰns`DƻOIM\F0Jj2 .Le(OyۦjsޭtqeߤiZH)`MIr&"I1Hz&ZM͐Dh<":3!ښNOT"Ȑd: ""LW=x۞8|6噔GHaiR]':ۤ!C36FmI\dI=5̀W[\ؘ^_˄0!ՙCr~wqPV1NhPvѹdur^2Ί"ZIJ>w+Hl!@)d:ѻy @ڦ,3o^ce1tIJ=v tu gHg$Qn G2OLD%v*Uu!HG-P3 'OXF '?KZgŽ㨇܌[AzR˚RY-#]Q}V:m fK/5[)a+yfaHfj}tI?UI @&|2?h'5!ZUn< -7kVlu4;25NZQѰ2c҅"h . TַTpV ';#wd⸸M_Y(!a[ O vؙQj Ql`;JѦ) $Пۨ'éN8o裀 \ٱ)b.9ZOic VNwўw9#vŀ,>lW`ł'0|]3A܊* D2ngMfw-et) ]p |Kߦ_ v hXgpa1;G^=&^5`];/ItM8f~xT.#3~ILFZѰLjq-!5e52@q ֳ~v?XS}M'Ga) 40S %=W+VSH~eFwJG^vߐbqLJV0@@7YoM^ l9=@Hو wZZhIVݽ&$9bۥ0h$˔ '~g4POۅ-k<:!? [ cRU}PvN}M%N =VcʋKҷ^d c?/ti] "սDeih^JkI^B`s7 s%vUbiVXP/dX3܂lIo'b8 Ȩ J$*0 zYPV,X  W6*zgԮ<;[¯a_v&[JE8~sY脘^p/7>UY7.<ofU\CD1˃%j(D)@hy55ɴCH]#ES`l[ndH{zx(ɓvӕ/.%l`{.rAxT-#eT Cws6**GȚ[ǫP*kݓF_~?X h܉ӭz2k5ۇ|}IA.VxJIHd-0yl;RPY0/*پS0eԉxijzػkQYC!Xy!9(^}^Jq(O,g$C\6r:jL@[^AKu :j5Hvr0-EMW9Icl[nML$".&i[ *eRk_=_Є\ݓedžn^_Րu>=gMV: DR "R$:O_(-s=Wb "H=٩Ө9hP@Go;C^L=^WK.$'q|oc?R  +}Q<4z (zˈ+Dy?<%n OGN {xXA:*^~=, Zx~fP~ecIiS9VHf.B*uA8~mH{/>PTgYL3!l;BQ$6vblVzȿb:3ep:p)S@87 ~X&f߯tn,*@/(ưo #v>$Ji`a#%K· B!^rPަQ3!m4ISEXͰU\n Ar`T4b>]#sֲUI/ggD^VhcZ(9@/Df^[Zb]x? O)9x_!JD&{TGݴsҕCno˷a8On:"VE}7Î=9F[ 2?Z^:G&CE]/ɧK˴BuC_8-"m zaeom&Cꚩ ɨ6-,yV:.aC1#9RcݿTZK:hm#\R}tT8>;sδMJ\lt#Ď gʅS5h#E~*0bӡvɒA()Ofh[WUW3*9r}yŧeRliK K^#},θB1pXRF5d޲ &26Չaְc^ayr˓X.s޽oMQWR|#bNw#R8YF֌cay\ǿFKKDy2,v@i}à.RC;f*)2$84#/Lֹ R7 Sv4c__3]cEq"D]p 3R$C_w mtX1VT %F+jGv]Kњ̻njL7Ao7bvR_M|k*pey(8*oDKKaW9)E|y E,T0hU^=`^evhj9Cq'H"cZ_:)}H ymT/V\߆-lޒܣKIYHP$E/9EH`KJq%JSg랛ᤈhim.MzMVU/Gbteq1iψN!CDC#˾oi`TExbu݄h'ZzΚ(KQs8@v$Gpy;0ͪjhL+\쑩vbZc\۫qGX5ܥ8WNx%4Of\?q/wֲ$/{({'%F xp'{cXgk`9ݥQeᙏGV5BsxO9ZXx&,+Boi/vL&/hCqa0{O]#t%w'`o"4j8 0U_9Yi4ؾx8ϱL|d6OM|oST2JW-|qr/qd>`Qg&˵9&P*Kk?p(_. mI|sQuƢ ֱŕ2Nc0c d3٢[/ڴm᥹ohƘi E7BFy,貺 8xD ]<(*&uC S.>eA<(PFP̗PjZ_|joC}&ҋeB5W[;MQEyP䏏":$[3}ZrvIzP4vMu"uj |A9ΐe* tJ++߂~7Ё~kJHV%`ҫK5⢅6ĉrhueZDM=!Jo)&*߅*`%&S̰4l;=“c>j2a_%/3sw+Ss׮gzU1кK%$?JU[cx+¿ UF']bWjMԞo2 iT;DH;fv^5{PQQٝ/NBjۄ++C>L9>esVOm"j]h*kfzZd5=ٳFt~zT. 5Ul4Q߸P}F@|º { GA Ч`Ni4ISGz;$:ZnvoT|! ߲z3eXJF/c߹B8eg7HPc^Bld&7]s$hg>=TQ7=1HEU"ƢQi^i..oZT@QUvn1f1h DhF׮J8yFt@ <آ=t8W,7dU]2CZ#Z=C<@X[rF2Y ]˵ MTֵߔHr?E2uXW7Ӆv*xƖZUbpdI yu4e[_1G[:`N`xjd ףWɧ+3i3BB[.yP 1|21d9pEf#L:UDoWE΁[SBV:7B 3XPqXtԽ`h2? O^F x!~: ApyB:hˮ+KdQ1EA]1?Fаw5g#TrU/C'?+4bև"mXZ>B^&^N.i#xѢu_ʥ8G}=MO7BKs>&j9.PQI% #je=#'x1cO[zQꂃh3=f`P?"t֘NnkheR }w_t2}vP1doxi1[2  \X<,Ve:}[3*i8(f's"@hn2İ&Xn*u(L GXd|ܟ?vCp?,qFuw? lp#'qz02z~ c975m*'\j*N,.~/=!v7_*ch@:j&+5'.鲁 !JRF)ZpScWLSTYguqfP*:+ |hYɭ([R$k!e`%7֦֫A "'s[^ksA1?INO2q߱H:vl֙.I tSi͈GE?܅Gzê0+%g%;xYޞOBT\aH&DǸ<*gߊϕ7DWE&Uӷi/ӓb$9T'3W& fs6\nX':rc˫k1?d*y7I_:*ooB_)e\YVU"\!Kj8vfRV Ҷm<>8uNs!Q""!4V;y QmH_uŞ.# QxLE׏N, 6bUY >y옇Ua}&_ 2S5,&1j"o5Cf'Q*Hs?4@(0Pwpl}AޥH7wZ 5PNiOPLa<.jpjR[ICdBQGM[@V{r/:MRݽmNagn-46v8Mڄ9T7hd؈W,l) ;K3!o3K;MhbN1/-OV90Aeiē}Z Ϯ;9\28Y^,R4::T㛣D 7vqj*ˡdzY* beoYg,}ǐq/d`k'QZ"lޥFipb΃tIW*z 0*Xz y`9 5 v⋍L<5"9BUiG6]lhD:*t!~`G嫣lWGVeD#dJ's $^ۻ{Uc-fB2#TwPsNUw6BeY,H,š/z.zšjܐx+uKS0VTcc1LJ̐:*0;`Sb6}>dGrZ)`ɶ[DBM/UjZӌz{a?+b|+pmU/v\y"Gq27T{)LRS%sW?!8))uV}ߟ]8Lv񴷂<\{$*Sd12 M&:ag"=)?{ىP6IS&BºL q?Ğ]}_F Y\ <ғ`Oh3<bS=Q[)ZHj:*FC 1%yVJ2EnKH?Ͱ;{Wh؅]49^8S,%XWkEFmKbqTNa2aejf8z U7Y ~ 9HŃ3ݛmd/M6=˪^ ฼0DA26i:yY3s74'vgf\.sVdMx_gwh>hV;GP{zQ& 7n߂uS,O=%. [:id'&6AAW166iOZU=HK@NΞ>f~&]Z;m ֺ):el@Kx>x ł)vM>B999:(<;_'lD齎Z3^GX<`&Of6o$C'eAw+ &gqܶa`v#iݖ+# ]liړRx͒̅(/LY1$p*m!r3]@Ol^sΗ7׭`:Q̇}P $۷B 6p},=yN0~ M6! }90>18W+/Shr÷31AEݹT[$3'↻ G 1ȼxEɔhdWaR)L _T(,v4~}3oiFI+{?R9% !-Am'8 -RXHږ֠Iɲ=K!DN{}bd"&Xw0>~|ЭZ&PP`U^ěESg3ūW`UodnT EVQE7`f~u gw+K\]> 3P^#'m/ӤU=m 7 0[+4<#"󙶖ۿO*^OW1YL\RB2Ķ)]Wc%M7w72Vdȁڷed2=Xɡ@cLc !5iaɒx7>e%RvV ⚬gN(fbqb = B9uِb ~N_#R?)5n#ZE b)I lIbP/^(T(y['j^\hV )ĢوǕK@#0]݁^ ?/>nwp/Ջ(W{۱0 .xy7468y\'J4m \5oAD S![S >/?l Ͽp}=8nHHFcM7R4%ŷ0e;R`]$ >Ty[»VmfdH5e^[ MF9PQ.uA@ co0;ƈ /88qݜ !9|N/A05?ى\M|DBk8Υ&we?^pErMo1ظ%.bce Zq#978#{D`ܒo />o#x_r7pXWyz@Nt:-=1,IN;d+Pu(t}qli5w]vvR) WTekXA,dͽG\6Ɗ_>`8~3.QI/~\^{WmVzS1M !xۥφlsN|QTduRwB(&į|he T xݺp9'ún.4fy 2׌TiMDrn-rJՃ uG9q]ϚܳwE.D$OT&o/̅ 9 @y)8#Cĵ֫q ŕt3'\ec2Ƹ[7Dnuezv%0v9aQ*ʪ9@UΗ48tS k;~ShUG=|4R1bHש(@ƎmZdyuy^)d U9Vbv9zii4cni] ň~уg {n:N{ϧ} ̥!&hZ}Yt.awөi+ mAA2dibۋ\}9Ck"!`RMx-EYQeA0; /+"mnX-l/MW(_sF1qy\<,Qc06*4Qu1лzN71Xw/$Hgj0Ã()"\.#?CRK Y`x5Pc ɐ"퉘|rGw = &GYݼX0DACJ/R[&ր(qepAGl7 BKYt:騀Mg6o-'MMՖ`jWKT^:'v*'= a_pL9ܩIEt뒕X\3P12mLU杖,4&&l~ _4R`ucLsmkqu.:7۸h E6MtsQ#RMڂ #uoG8˗Qi[anYL_ Z ȵA *'pE7~ s+M%W"Ys>q4]7<Kza`"u=S@Of!iUTd2 p8K cƚE z[,H^FXHjs\M suQ#,{4s:JKF'6uʏQ2wnJ&s2T!Y2K&Y7 FN..AUe Pg $gO;t3Q]KtqʵyKt9qXg^^uڋr?֯x@Jl@ XʸLn\RT @/W `Ta4fn3Y5B{=TaPj&0:!WEjUzYt-5j>bH&Vnͧy jL6N7Cg#4f"GsT#G jŸxuvOB?7=TrOB됝zc(ꤣV0b\IQ(\'LF:h[-@ ʢ'F*]@Ԫ̽EՖ9;xK:&sr=]2TTkd=S4#Y vlp*fU`| ]֢E9+/-9եI074MBU`ȦZ1`UJhhbh$ujM+LLJ\;<~{bC_/ ɜPj;1LpsCVdO|=e1Kn45qH\lH{ ]a!缿l 0Xon_;+=D/?K)R94y6EXyÖ q\QRXL7If w7 f(Or%+溏jŹ;|v`8M=5wfc$x {=VK֥bNyAop7~[~Rp=g#Ժ YCed:?%bàq@x^v^K"1Wĉ~nC4lj@ݲ二$N@Wq>u$S4#*O]w>VqK- r3 by D`+{~|QWLƘۓBkѩ̚Rܜy #hT-(iqť"S19,vz"!2r!}YOOh~TX%Rw7 ΞPUDK9ff!HA]RF,+8lW:o;{ =GA) q] MTG@-(?BO]O4'5I lS<6> X3rv'cD$% k퇩&!"Y=[!7fU~rk.Xru cwpݦ'W5~xEj'JJdonOUJ@Mi>*n1`B,j(\HVL!eU5L(^3Ĝ,եB g~?N<-Դ#${# DŽY<2x<-IqGM89qcS}u4oA.]|JeOv<85tD7 3I.]a]o =$Xm\ɟn0| J(2 =ď$7ޘ8CsMRyl`o`𠣼YEB|8u3U1?UVZ^thd(5q,KLAE, ½$S\nu)'3wabCd$ @`sJ"@"#|ˑ'h;0=h Xe>mm9+#;n"cȹjTA>Ϊ!Acn f w$&3Rvg@<'mi&t,")b^0DF@'T>n 9{'@B\.D(#:)"6_yOS#p]M+wqٗh9vSεS&ĊfK=w.PII[o]lWffs&4AQZ0ݱQ򴰷)KG(ybC'AcؙFpFXy|H 97R!Ew]3w~ HrVby[{{5N3P5a-6Iy'\kg7u`azA.YyvAzzf e/TOUP1oyr{2-Dôx O  [|+Ѯ>`>:.ƉXP$GnJR-=Qx3kԿЊdR*nōx,q@2gsF`45;"\Jʆa1d@'|GC +UF^V>3<&So)čalpl~Uu%SDE0Zzzjy4O:Bf[sf=O\cewxl9/(Mտ oI)ᛔnBYӢvbk< x1oRj& 0J0ԑ׳,>,ޏ32  "ab'zp|u뵋'~*^}՜esj1)gFU)G} W&@URc"1Ջ)<7K`X5 {ST205'j-5}|)'J}oZm"aI Xz6$QJO5 zLqLwnr-3kj@Q$wxn722%p42.=Bh'DNU.W@HvhveRkIuϱ(a  }V@14i`V \*S ITG'8<,H~4vDv3<ÞǏf;\dƯw[DoBJR$7NJx+Ĩgw*˧ȾDh0c}MѤ@Т)f\v_"\yU Gڒ=ٯ;O}L㪋On= ykΔ0ŠL_$1 ^M%~e(I}"{:2Rl u Adt%p6 ZUiݦk9T@]cDM H>!d"`V'] Z۱Evl ͥxEyO0&%1"J@̮+0o]3Uz_; |bRA8"4Ɠ`M Dp]ji.OPך !ږ4nC k+9ɣG7ARK pӔhr5C"AV:5G;T> T@ Y&BL쌋3<i: 0 0U{(JVq~Ɠ.<irJ ܦ"EO˪"\\DYb4J16f=nU9V IK8o~ ˧ \\? ՙ҆d̡EgJ٨{^4D1'RoE`D4φo];X鹁UWEmOO5F,_tO"1Ȥ. {ANp G;dBNt)sǔ+ȓ@9N:ikxD6q H p_W鸐/"#wsP"z GC jw½C2GF!MlϚ aauU D:e.٦߻s-iTO)IڃV)B|2g#[զrG@ }9i˥-5&]P.ǣ|:RhR܄C`ᒲ>.qwQG;;uSjsæ9nѝ.J_M-Yn{ ^;?Z^2{[{qCcUNYs(]\47_}%!U}׺Ր Q arSnwp*ˇ)-鸑=o)v\@ 'P},vq^3v4I wBS>XDV VlmHs5]W= fx6JVk~PvT>v}mOoz]%h%=Jl -Fuֻe@H~o7 )_7NG ~8$VG-5ߝQ K-nf$LOıPO J)C| 3ka ܧW \|=&M,N Bi\sngc1SbtٖjF"9"ȋ*cOi?út* whF)::WclPS>k3./8Qv:q-HMELM2/"?j 1!2;z`ªiTq20Yi6hг啝[YI |?}Pվ靟+[(y,t]{4|`\u4 :{ ?i?,.Hi5դ>J皝O p Pkv(RE|ݓFU:BCu*hw.-нj#O_1TUMgG8 { Xԯ BH)HH5r@Ѥ`)^:%dGaшHqI e͐uct4QPd:'t:T5>9g;U^pypHE k`{Cvܺ r<b{H+9z/o7'z2(qWŷMB #RKN¬֩[ڀ©NzGO乄‘ڐ[8Z:e/mQ3''[k2m*b7g%14xkiKIQR@ 8?{;5K겏7qeL.)yY1AC,aa܌rN̶`Eΐ*XUaaGwƓ!H hJxCք%b_HG1\=٫}"BahsXH0DVѩ`g0e^HM TRͿrιAdX!?^GWIǒ e`>(˒C5)Vhehs]ROnPNm6GL?:G$o*<{l; @N oҞH+&pÒӇdǑd_![qD>bnٓXҫUIsAC 4S`j݂ ~+7ӓ=+/RD]B $AߌZc+,:"6tY %!(0q ?'͟yɞ詿GyFe٨~MJiXJAy æZ<}34ъ/p_$OF쒯1gا%ܺY-r4^VsTmܩ`[nMsra ~5i'呸?׽gVX^okx~p 68y|eH"{#'Mڢ8g|] 4 K!.fp=FFշHftbҖǨP[,oU/³Bmrg٫zTدx,^h\f|5)a5JJ:q پzIEq)‡urpR+?,>;ƻrK(wmj@(k"1_2ăj=v''P[ӉvZ$7tD`f|D2_\E>G{9#ϋ \6M<O0>?ق[v@5 48ɗYp;"w8%fSjNl xp.WcS}A DWZOf7,Ѥij\H'h azRzN)d>)4A؛=9K?Ψ6[s@fŖOHn39C6ޮ M#2#z,lOcVBFZP,>5sOC+ Ǥ`&fW.^)@DT;%zc:Ky4팼|v=)`{"u8|`SWis1 >鎝GZHTg8 "-m; @9VLMhGģ0UނL/6"D;K_xPFCxtdFDmuiW6<cztB~xDލ?S0߶6MQvgK+9f^RElu:Tqi7g"F yu}`_hE*+؋*-Es@Ztm{˄UWyfp һax[~Pg kevcb%M٦iq)#'lNz f1Qyzֻ|KEDZN ~ApF)>Hn<)g8tjǺaȋE;_Ģ\ [Y,k&/54}.Y{,E\]I!(YYSWRRaFoz̈́ki Eu}2igPL#F]B`'$foZ%3L^X[.A]'(A͇G?-'V9˕&\g[sD{^QT=Mp0 u_P=F۱`f#}my#m=nnwd#pYzWlQ`+PXʫܒ"VlM&Jl!k?/H97Aޥ0:ck%VKa3 e.Ҙ\~Ic̗rwX9Ιxi 7N\pzB cV$2L9VV ]n #Qa*$^+=2ܙ%ex&:<6 }Sh3-4tpumJӞ# C[kIlp\L uB_aF"~ASb͞U;ßO?k maMiH9_fǘj_w&HɰPVvZLfԥMg$Lsﰴs?U vȃgʙ  a87'RSLiovI!F/PQ¾EIm.e2# hXǂ$C%<3o5}[+r@y3܅n l?#*=eOow~5qOCoZzMrq؂t' 5:@*ߪB5EX c2g9#2\yt3gbiDqۿLf`BYuL'ƭJ>_즟=8Ts< ސ^Miq0)kݫfѪEGi;<ѭ[hWt0#f0cOIa2V\*OY d,^3wxJy5[%:^jwAQ5Q7o"S%×ZgM},HO)/HŸݭ3,shvr3Π; _V{ؾ0VUt<6:˂`Я> 3"_ژ&Zϰ3ovvdWh ?e}OuFM${И6Cjw2Q^sGmG'iݼj"oĐ"Wػd@'D.-F gŝlɟF5ey?T 49Z,ka4Kgc` a΋ ֈ.v@zYG+M6i"5)D5>XV*u_L攟`s1$%๎螜Ei +\f^3m.iKmQ])XJw

LU/H8PnPQd1 1h"C{iYXƣ/JhޛM"R֜%<ا\hկ!ޓ,\fBs.hnJ14$B$&UfgCL ]}iH5eE:GcMW{yofhj`"X?l!;WHV7u .a:""|"hS~6uя 4qaN >EFJM^|%aRd%z;XC[ wS}4 E^]޶?֍xr0 RyRksvԓ'{JMꢤ T.4Yrьq߇{$n9u`MPlen˵\,kZ}wA>5G(/Ok)8CĂcѤ)OLUd ecvm[ekdX_SJr0Tf+$xAyI VxD8_],`>J VG ^1Jjܯ>=eLUp,;\}v6!,@zYg]Ռz[Fyc5hX%% &c}rku}Sc'w6Dx[ktC uF>[#ѸCP P^?Q5)@IglgaB6iD (T=&^[XX8N51S yLp\3tY;Ĉ2|"ɲ Yi?+pVEF^w _2%1(z9 W\snSh%tV!ELc sH]ɚ'5 2Lx2 #<_lŎJ#޻$qF<'2t4ߞ{ğX%a>E?Ft&8/0o B`ZM^&Ge/@n܎zyT(`v^˙Nw8B5 L@k\Ŭuz:qV]y ]DW! < B9檠 %j(2 <WSkVw9K/7Ij:D85o8m@jEӿ(U2D:_v o:'|C/dIv!Hl^*+Y%J~Uftb*">ui6aGHGMNI`-T[K%|O33ECKP՚v cJk3cgD^pG!)gTz}^^_`IoU\9$toshбK1} Dhy|": D `-9M3‹ށ eDDn3c uJ (d6nwi?q _=1cݏl)*N@/϶w[OH@ (yy NaRa[*8u@)mf V|FϋwQX+xڴ##LAE/=*Y^ ֞DR_iy6]~:GRXs#{d-e3L7O]0ヒ+x'(Uշˢ`Ypxbh 箎'mȠB+ČL<̎+\K{Ę< HÞvޮhTWw<[f^ H`ዉ@P2I xQZANhZ{`/3X9yKi昬 2>/q54Y3, trΖXfwGUcYzd~2}2-]z/P*}=$NuGɤvMZ?U66jЕ/aegiK sxutDdf1D=[Ej➝ʯhtjI[qlؾD(_jxƞU{p}(tR(?S*hM&a&_)t޳Vމc1399,ӓȞL=m1!S@IUW=xdzGB(GzάYP6҄**ZWaL_E-ݶ/G['/`Cq̧C2HOp.X=8[=SEzOx3`wD^esB> rt 7 3{"xj^\XSSW6a~RCvws` ?P.=zFq%Fn1*coA[M7na =;GN.ՄX+-o>xYs/UDjK* wn8te&T^ ]])L"؟(.4b` ?qe#ɶGta1 SuD߼Q*Az>Lx-Rѕa[+ãi9f-POm؉Tժ UUb\!6$` ,-pѰ/͆ eEdY4G|H cpO.vUo K$q2(@XcD,%9Z1|{>ޕ@| ḳlc#| ʡOgc}EN=uW+(̐4NBBv0Uřs8ITjIx'.q @n". %$s`X1@LL>1d..c87bgUu8AKJ=R:3tn3Gj:U@t];~l~2+易Mh> BNBqO={U?uzV"6&^UnUsc*od)~u!FfwnنrlpnoYGQ@Öx#ɱQX}ǖ- c/+ZrXaW3%Y-7^pZrcLlU+UGc. ?Oaְ0p/a-4@u,b˘jV<ïE3Rʟ4F82'NYHKc6j|_ݻȍC~ѩ-Yj&-<]0 Ǧ`Nj0VȬzd lU Xnpa;x fE K]j_bG0˳|#) 웧qQ+6e HDZplsM6An8p唻)?kj$|*S#!W c!xoٴ sC)(4A(H^~ DxulL;(S2H,C=(0˅_8ڷ;Դu)Ϫ0R_Q&v7맟J}wBǜ1,'7lx_ \PD`F<|qEGR*+_[Gxr)Jj*&&)uBZz QJ$~)%fK@)Så}!V'Lˋ]:T)9#fu:`({:>1Y7;58V@תQcvbeY>UoR[hGlJ깰D=׿DSŦq},+a"=y~jMaoW7zrإ\+ Ȅ`0$'w%MPxnjӎ `rbԟlԺ<Koh8<+/4R`yˍMk%ZlG:tb0܇tHzܜaHgƽڦ$I:~N.h}xxYw4Po#C묞`j>_].S88q$;ܵ}.2Okra- H! l[-u3+M-B@Vf2֕MMP?9c}Ž !¬'֟c~Mbjo|媤r"ٿWf 2%ToC.z`=?? [IXG!jFCQWg̋7̉tM%pqqtRvn0޲~u7ԌOat)\~0|qӼs$ZnDiȞYKTJ-eZ$HOc hМI>SB8=2D n#xr\{o*=ݝGXA^r)blEϊW Dq2h,3GRUrp3F:'ЈSێu`LE8 SXwnB YدQsm1UYE3%T3&usu{=`Tp#I3MepTiDilM(J~(ēGN|F7na'" e@XLčյq%B< *iD.;}[r9R%T|>C8?P?E uZueaڣFo̘ꁛ'{5;y=R%;὇=8'F0 b>kqoz(Y ;8835c1~bo@RR(~Cg8g61G3yQ5wBY 9qs#-gԴ_ၦA'Bus*c9X!Bqnv/Fލv3 QIOy![BV"i0cA)ATx9l\? VmFڊ$:rƜ^eޠ"F?o"9{AH18ԉZX:@6R eEi)U4wonF㓇&XɆpJ^l"xBSA"p]M+M+;=l9;}Y@8TE)EG'eBO"_Mf\0 金.sLh\Js&=>-֗nW$@i5Iscn(.)\oUnkr/2-(:,t-ҰݰL0J[])Da[gVsK/[w֓39\0 H}#!?2gLub~*lXuZnﴤp|oE uAU .A>;/=wk2N.B] *d.(.%\g9qET% "Oz6`ԊYk-SLjxY U*aRR;,"[ 5:0^tS! ywzub@",+fI+PvK#d9]z 7^?T1䭓9`ޖuWhVž, 9%"g >h[-jlص7jggBo$@4hf+|ț$zӢ*xP26YAoOWc<w* Fv$p5B!^-pPBE9*SrodO<< do):~"?ߪL^JX)p*dM.tf$dvwQjR(ih}N+5\]|L",*V+gtr/G" ^N&Y݂u L6|>#S4{ޥ0-ċ0"H$$/5ca9uFr}Pt{FDYqEjZIL uEYV/e֭ߢ +;F9 K֗cWm `Iey@`}qSlTp7)~A'āGe4~њ;>ԛ>^{q aviQ kpfznqD7 6tC-q;jŪ|l'ˆ5mԐ8>=E[rݽ{t< {%wNe׿|}Q#pߞ?ިcX?/,(ԇ>1韷6eJ".Oc|iELc ,._ck{'JnQ]߅X͟EubRV$[I)3rU:O0_&cG#oTlSjAv<ƌ]];u lԽ V^`<]9?6 ^`9w6/ y`&!O__y] -[bAW|{xvTؗ'ܙ2N#a?,= d@QBX./5gSZ;2R P˳hJ6T?KkE _]jY'W\$&g,)" W,wn\^Q0ٵ,9b*izg@[Nk z/2}J~ Pi48{m>v|Gt\ϩ?O2d^x;jq͎QjæD˞2e:J&@~St({;`CEs&Ok,h2U"`إ2.dڵ>AnvFIYC|5 n*A yb; ,EK&5wlOL|`2ZٷiVT" ?.&@Ɔ=N+OA'L"W^rBmx9ժ Uis1IH -}\iͿ{҆/Bj32t*R!QZ\]PcGrဖymÿLoFV顇-dd~]}6Ov.d:M 1H.KDOs@D͌ ֡ߜ?>0[o\N> ^3,`UA# l`8)|Ԡx: C}Cǵ{ #޶ĮzzᲲXi ̹}2Pl3;naKECBAhF;k!#_\BlT;}"tVkԠ-F;AUVON[sCFj¬Ζi-XNg9w6p9! [Aa]J!ry&<{_+iwYi$ً&s*Ȗ wnenmE,bN'\V jyib$֧iY %/"@I7+1ծ5L,&zh^$e\4K颈O%Y]Q?lfNAM*OJ"Kq'37w )RS;\Iafz<*SG-@hFH,Oz@wÂ.c"bn27Nb_L-۫1iT Ӑ)ۙZ.xzZR3xRzQ;) e,vyarhFarfbWR^hwm|JAPF͔調ɲC1CuXc[1銵Q}no[ LK`D84[7:Iy7sg./ŏ9 @"A=br$ @#e5+-I|J>F &m-Sonu:+M[/SDvK* \EՅFX#TWKc{}(|,҃U㋯;k Sh ]i؂Ke&Ka$% |42m{ F+h,U>|uxE5++*o#etd4f$!؄š[Mb_#ONȊ0}=a+YFudt |a[_Bg: a$shݔT[n)LeRqrJ@u2}dFg؏nm#0y=fn ~?9B] isd%*WXE܀H]p1Ag :诤)ZJ4*_Bp[ME;>CZƜj^]=KLoOat ''vh{Hpܛɞmm3=$7ңX՘( (8*y"="JNELU3L0B>LEn2 :7,~^3`dIOp˩^#BˮW6KN-t-!߉@t LJFw0 +7)󏊔yRSfN9[1Bkl󷌰}`qc:;+ϝvKCW-x]T$/:ǵ"> #=}ܦ.6 ;|x* B@O蚬W6ƦQ~,=ˮk?aP)X.L}(ak8\YÈ]W+7 0ʙdxhoI޻5V<])FY#^|dSl%@|AЭ-M*yʟQx^f?e?)bS65I@\]DJ@^TNs";W _onv<`ԉ~)a2!w|;$ z[`8*`Zd4*y)t6K<)miPrcH?OLa9yϔ}c g_vVqۋW 0soAe.J됊rFl[[y:* !_kL2aj KL欹/,ek-QL$/YS^CŹ>W ,/ 䇆#Od+=U6o|K`tFls"Ǡ=ʅ@-1ذXc}xvR>ݜP6 L$m(qp0˵^~;דwwMkW,8օ1?¥K`놎럃As}NC({MF64W.b32G")}[)uS\mLirrItƙu /@e9BP٥][ ^ڣ ضnP*V~ğڳG^{!j ˓0LcK^3+{Ʒ޴eeMC5]o{N)e!̼ROр:;0Ԗx/pc"Du)[ 1Xm(x~8E׵p| {֦o6ot;n`4 S2L?H23? a]gTWd)u5b6@+]gQu ]7cJ"Hr$o)t5,(تRk)8:.3[^'6W،6,|r@tpcg$PN~Y둥/܂4dbҊb_H' '9GR{@%Fّ߀0*U[H.[f}Ñ6wp̘A  ;w&T&;nAjsߋTsVgCl8W!$)^Ԏ6r6ȁo1@ƿ0?hzz**gkO4Sw} BEgNΣƤ|foN,9šte<=T>,^̨[$ՠ X S@FFPFz~ɞ UWkaՁ1"/)mȐItUx~W9,`xX/wIuX#% W,Q2S%h_jeL7=N,(fD㚋w 7UFE\6Hg~>/%.k *OzrYEw;t>M}$vz.mnġy}(Ն]}O# V鍜 }U A7i.ָt%P3 E6O0`]lIHrCG Ll^B6kIh9b/nU4Zg(P 2K#7A@â@jPoX&OѲ1;^X8UV-޾)BtHROQ^L N8e6-!ynSjwjn<<5Lm@hQ{2w7%p(o/ZN$ `a.m:"@N2DbGǫɗ#0Dh_K4Qρ6OgX뼳6 VMmY?{]~q+ s/ﰾyޛӏi4!h$h 6qUBzq}AA($UE7&"VK@_tT9ڛ\rsKXiCNjV굓)g fHPwB1r?L+ ɎNWAjc>7&hC+}!pz/TFO&~<297r^> =2v34s76o̷Wv7 hT Lz0Pu Wゞts*̋p'hڜ0S[ʹ( Gҋq1j0H2[!Z7Q  poɦ08X925ȹ`4>*-dM@<{MHJaͼ|?'ZXzc~Yo݈n th2-3L7v4;L[I\'pޘA$qү 7ҮvْҒc&<:#~* ;l ARϑ7v:tV?V^7h9`,jd3Dn:FhG%1ANr$ZD9x&m1/MB`OSgmqҏ H"z@;s?O5MmY E|jeeRl_Pkr?2)oO B 34'o=m$q&㡻SIyh7-WZ'vn YÜM8zUqd?ʚRں <+3ZPPޣ}]Y%h.` `m>̽mԝ*sfߜWMF TKDH MbE6ٜlWbfTMffn&3ϾQDJ9y1QXVl/9)>J,0o$8gsDsޢj.l.|xgw$GS%H`YW EO7 4')*(Ri:l8Kfe4I7ԧ[^q 3(ݞ%J- x6kV|ThiIz>wY1;JvV.5(>%3x(9qϭ]e">x03Թ[) Q/0bI$`CwKA Xgؔ\V-FvXEm}n>:_z:/t̼3ⅵZ_84_N9<Aa5۝mʡ:#ӡ=֮e+yJXn5vb"P;bVCŐg.Psc2m&} euX'C1N-"n%j|҈Нq0:}"gY;ܵ9j'(c4z}95_c EWm%60>FJmucӃZN$yaAOA,ی48Fu,GU&ۻ^c*@=ߟ9g&no~^Gnm6`m,`H.,Qan"+a|ypīotrZoh$cE^<׻{ӪicR7OTbAi` Ԕ,_O2"74`8vW:9up EgzQfwR{9sʍD-%mȚk"y0Ӓ鯏t"R#רSHW.ˠn$AE`;[K.)嵇{H ,cNnU!M4}$pa`usW-81W:2HEM,g 42cƀ E:ud-'V~Lc(B+w]31 lg]M [rQ*ebSP1 =$.hHZ}Xz2x!K|$W[O/}EHv*oU pjqǒh#zeB07?sSZeiE|:Kf}9GF\9AĉiDO33G3U3'0_FuЁT#$Sg#Xu#ЌŊoF;o*M :@p )EOAB<ޗXf+[-E&!踣bDHWd=/`59В[@2ykAaeDRv8X +C@(hC =4zkb4eV O}ₜ^q?8u/'L!k@q K*qVH}h#(ɇdy7QC N5g&9:\O{BteSd,1.T%B\9 C ׄhYÐ?/-V?z'1}ąĵ_t͊6:Qb7a{<"ϲMEt9%C𦤱?c \?a: -"LsnB7 Kc%4XhyDrhd&@pm vvذPt)U1djho>*Ggnmf ?tS'Sb {csf}W,I> "Qʶ`^~:BS2 0@5&;hy,]ު: CK23t8MrVoXAKX@@C%/ixMW4vTs'-׊c668ty$sj~ Fq$WzdLeWcSYެ}khv'}(?W"Er|vr*_f&M fנ5ktßeTE' YlzQxW"l/1tdJҚbUÄNI}R#Ӿ'pS,X 7vd`} 3D@,rV;}-$zB^ 7YhH]Sq >!L0>9ݣ;TΝ4㴚9r( HX)C-nrjk ;T o8)xn {xX|záo9!&eH,n>SPQx- nɕ`EAGʦLE:&E̜ O=tܺHNXPg qE﷏KNXfoӯ6u:qP=BV! M~ .rr1\[T BV~{?>mFy}=/`-.Y##P`¶3; qP檀Zcʁ'3: g.a>.:jQ[YWNjr*TOuTcL)?-uѓi54nd KrZ+.Uw2ՙdj=~ZR'tF4QrLLLygNqFc7qW+xaQnDæSl{/Z7AYFgN|t v)ʽFdrȮd$2#|FYp&τ$3eL\PnB8ފIKHsab&_X\2/4?qm/@vu%]KNU(Qs5%* NI@6ckU@?-Fꊄ.]C/~ٍ2UWZVUb86"WFiZ8OVq If l&:K¶W!D!=4,LfJI{;G/L'5U*BFѻS#zU3h7K/kB,II7P^~cZC,sA\Y|>N M5 )tOiZP5Rh%GGg*vP}n9J΂$<4.)X( >0t~6mL*S *y3쬒*U>̥zI{reOеI{0FqrramOsCf9.a8YA.4.ݼsOֻ ҈@E4ĂJЂAAP cWPJ)6.zF3e+iE~rkj_%1x jq~Qj[{Q,jC}ke'l$[n&ZF!E~( Γh cƍ/l{$Bao=\1۹1 մ/ᎦaK"%83v=v8bЖ!`̩Z}D%su}+]A ڻ%NL j~5H?yKs{0vx(_9<å+ *Zꪹ"u[ e8|4%*Fie~;oG%/Å .0Ma;q|KI1+FH_kPk>eBW&9 WbvNdǘBwӄc%BGӷl|l2Ó﮻))yW@I6fyl'\7CJj8F~rbx" zDAY}lebanTͥJL樺jq܋%&Ӏ_m-1@I6qp t)6@A]62"=wn_ +|wʭD~x ݿ]xD|"NJ5x*V:AxҰUlhB V5ϤfW06~2G}Q 9^[VFb%"s}tm嵾#յAş[YHAl-_ؿk>mz1D:d8e6MQȘ#j7 *#z]˹5}jڥ,H:+>)]F&BD>?'P5m*_A21/"- -w zF_9lm&d9~G cQW|]Du؝z*Op._u*Md\\~ĺZ?CF}I2PBж Xf4ѧ]ohV{wV‰6#~u+/&z\^&Ny<Glx棹uEGx*c3Ņoi()UsN!p}VލԢaiPK\y5]S0LR{\6r"T uhN#:A,b׽eMB>T ˧a/z츠H{ϥL(uAĆX`㑋?C0N߿ӝX2>FmxJ/ ,f'ĩIU. ZDnxl6$yD +H_ºf "ɹ+l]J~\$:]42>LS/0TU+r 럥0@Y?Ғδ1fVfX- #߂!14C|-Ur!9$[e ҐC=ͷK=$2 *_p|8~Ҽ3''K0lWw DɾXUSg0 t{v jZL8W**%`bDQp:)#a/ѯS\$Du~Q,gp/7l1 ׻QjbZ!jBXp zWP܈ :e*~KP5o6s2 xE `Ũvz{f){vo0loJ3Ǵ"? ݊@e;zQGdžfPBNȷiarݾ#r:|n?H~Y^hl B"3H~v;pi.= G!Pk>FX;Bg0xMIѡ(8?Yqyl] 7hNMnj)3R(}ܦi LGD2*xo1J01Ŏ|ʿly.v(nN1D.'h.(ky*$7œ~X9:lHFNR*<)4{z =^nLLN_+*mhgQd5Ѳ ɣ9-=GfdӚA6) AEy:)0/n'4>vH-:׳SG:HOU_%g ]hsGyEl+A~Ǽp(9ڵ 1ó4i츒# "V 쉦y0,ۂ x 0ɧ0y۽w@0a(OÝdMe椦V $w8-5c׿Lj;lO+~{ 1Cr2Ŏe&Aٱt ߥFk<eQUD?YextG }LueEu/.s̵+GH]ɴ@%~uuƐReIm\W4K{-t Ki;tiolOk|Lˢl Ε{W\Wx#&dߘ7$GDUkPd sQ VG޸hWlᄪVR44ϒ9e>6|ҪfJ+$_gWm;yJw4)Y^-CICD҇("Oz1192^4 ,P`l[ jl4@?,CP/S181'`/S28E *<'9|Qؕ52b8tfv|g{~Bqs, mJL5VSuM>Ÿ$k1,S+$9F2+ (\ll<n zCL.36 ֶin$-8U5O]$T [}] FO+dROrǬIXL*V$'.iicο feE!g"rP*?\ၹp7Iq<\D(YW' jAv+Ω^;P@ΝA"JۆU(2F!%4^HkeOZo23zwuZ3d-4;2I.'A]G=x(6ޡ )P!N2499Vb7]KF`Dw&Ȼ^~&<у=)6aƼon|ӵq🀁LV9!0>6]`y;e:^)C$. Ŭ0(ˬq`ܰQb1틆kcb=PI2g#wfCJ$mS` ИN\ *b'P$xvs fM?4A@Pn)ut}*5d2hŔb9}:Eb6MH@`u{ʔ3TW5XQ/6\~v.% -K.f(rU4w,he^PNQ{S2ނPr+s,ڜz=c w +3ɞ@ JUsAXC&%S{S2|$/zGkq"(E'62IOrgUsͨb_hSO>@/V8L.E!K<c_ ;h=[Fȴqh7X ",S^  d3nB]/C u >@Q|-TW#>3IXF&2s=inǠ~.`׊U!I avyUja`/^ZqZaBО6>{p*IQ uaCt9TEEg#>B&g5cSBPзbr'hkCx55կn`%8cKRJj9&/|1<)g&. K]u.w4ʼn# e'xΑK!3m 󕔔j -1$#kv)ٚZ%P!dkFr?#c)Meߧ~r.{r>chcu.Kh`ʙzIUکLƼ˛N+Y%6rA׮x ŋ6"L@YtW0 r4-nu9;}Eʨz.po4Ex  ^g*vnT'b6=jBN˯Č;aBC?M.D.LU԰'ϗ8`+NV+1\Dž$T2 M-*)[hȐQ֔ 0˶aY3E%`ڴO|A:/: ny ~EԒΠx&uBQBa=*^|4NZ=Xɨ2gwryz[1r)lR/Z3xwjsA*YMl|,+XR͓vsc}>EPOj!0$bX5.QJW<=ttD`z4Kf5^$: ;p1PCȖ S>W#rMoPw'*&yvl@t  e3¿?6jdq\Ŏj5a2a"#Ƨ}^N-Ù6h1ӺU`ꠢĝ ܡ$n}CnV[AۺF#G v[Aklu;"uQTv,6k2F#9+_%`l9Yu#I򱬉H` \Ck>ĢAEs@З+vvq+tƧUᮭʁk ڂ@Yڑi0î|r=CS?/9Pk7%AhOLfQKzaȣNL6Z!|Dsz}eІα}'8PXx\Jn~~e랲%]]惮Z1kCh,-'2M$C~\!uE9TY]dߠ!ua @:CSio čtB:. ${ ym*ݺdJz<-2s=%T`čC_OfBd$smy}>:+*ӿw]GhEDU0~]!c$;}6T(9cNs% JZPۮM8k7[4i| {|B9h{/]Ҭ&dQ C,gp04w.r -uSۃs|F(]I:bWG*VǑjT٤*Rj`u>c0[ *cڦ*X<4Q4 `H&&z1pӨطb:3/\=pxD!1Pb-PoMU!pNpH1-}7ˊ/ +KuD ΔQ]ށ5^Ϟ*R!Fؕ?4 ]E_U8 kⴓY)'M-|v1S>a ]ّ*.}"Ya S?6v`㙯)X*eУZ?5a-Vg)5?^oӰh9kal- yM($ٸ\+z̗W񊜕;7?RM♊)$76zV^̢?t}zkp^xRU_4$kuhOn_n +K(HB#v]LэVSTˌ>&4@ieFO[Sml'L;jxsKW}'%cڛK^N>ѺgƏĠ{j1ܔ=^|A>%Q ץ |=3_XEL353TA gx?LҌ9r GA:#rޖpiuZgo%jYoMΪ-@ LrY(@" e,g ކhwc6l"{fx1XǨRf 38;sH%zb2* 蔆$3I@}x+/͕,>Yn~o`Q&)HFc^UXCA]wP1:ڳQMiK!`7ga8G35eq)uI!=m 2glgF3В%k[6w!} ]tu _QxRr{X&H(>pYFn((@0^YR]1@8&Wfм3^GSyf_e5JE$\V[%xmJoXj:2A+m>ӌ41T#Ljdwf:%Vޯ0"Wj4wO"m]PJX JGE<A5 4!e`HB"vᄛ5,t;u@WA2#\*vIs挧qD041`I6\VW[v*)O@ӠG򊢕q8!6|q"R-%娺%U*Y.pV񃵰&NıI "IxO:<w#;_|p񖭕]jv˽Ctr XeАy3=L97sS5Д**HQm*jwb(_%@]@,Y+AaQeƒA9n_a$ƛFhTwԟYR .4iPxg~ KR}T·9]Z82k\eNoKr@"eUm PdQFE7y_XCIC}*#O [tͨq5断KA%NB;-rbĉ=]g%]W/8dFIm1?m5QK5LcZ`O.yqv@ܡns"x@ }2gVNw. Зc4/Ǥ$~}ȿˬ֑):(Jy!=.u ӳYǏfe-8'Jv0(C:ƑQc>i)r[>^uvU!&ns>X:+~ׁXf<uɆrkߖM+e^~NcLc2%ODsAx`>I>;\aЦKX6 U/;ʕ2FAaG\N\1r$rE.wռqs+(loR]/f`*\噒 ILY%{}X6? 玜Lam^:Y;#՗> gy&?/=6 z|Wڱi0v̳4'"e+p^) Z°^-o+>sЀfS*OeDKO#/(؈s sle|$48;?] ”f{`@  >h'hF̊M#˱:V:]OhؔhiUL%mJqþ5e^;^a]/2f{5߃ xo-lu4voS@DAtݙ:9+' &7O}zT^c!R|U M a0*%\ڻQ@]AE:) .\[=$De+5?g~6]njMf4K;r r S? 9E[+Xf#ERń HO .{" @ed:h }f>/lzt5pw~ [jt;חf;{޶2\Bzђꖤ,0Wv:!P:d s +aD1U׬͋Cd3 rgsæhg;'~,NܢS!,KT+ؘ˄bj32zϛPNl5ԴKf&9N~o$B" |[,«,eB}ŲoX[J3ҵ ߷8MEsJ| N}E!ڗðtvTJ,V7}Ji7 ~FH@GYK[_ezz|ύw-J3^%댕l,FF,\OsPn؏/:^YG)Y~3_Ȱ8B 4:I|^28h~ZUQc 1 W+mjΥOHga 5FODzC{bΚlœtOx㹈)˶~' GpMIy^c׍(O9q%KV3~iLzWpIA v{ӝ*S'&Kʫė\h R}G |&$UǤJjTdwX+fm)ZK-}ar׳k0f7Bܮ.RKX&ݘWrsY&¹!Ԯ90'pQL&# טs/;;M .\s Qk9,S9|b5co]',c]}q妗BPR,Q=yFʥbR8dnj(bcNǯ,>XD]m4ܡARq|!Jew\a # ^(0lyDQQ6cEBXwIFU䚍3S+2z2KYlR"!G1| N Mu]0Mjf8#jBdd5oYfr buiz:Ga(0: !-~u"FZNT*7}>9!'U/2bJ KN>ml!ܔBA#πxZE@2.`WnM/kA|9]-L (u s;Jsj}cHZ%ݰjA[){j-vHCHv s#&"a.'_9ʴ.j7v)mڛx &GMw3 t$JL3RKp­I4`)؛TP2f^9w`E̡#BBoi2 077epOz%j@Z¾]&.\;RV5QFz\B-^eTpg( 4h&hQi>aާ &f1vuy:?$q&ޜs>N1m8/b_u6ZxO=N;c_A!^Fx547lʬ)u4v@juia!iհ$祺J|U^D)x(P""bDd#2kƞn R",M}zEzFAԆ7x=IQ=Q!~=\dqC~aev++> >L5wQ ٦SQ/`*"_| -5% ;҂ŕb2!T50r"%>HKEd'sgףSVڂ?=;Xq sQP]ךxQJ?,莃i`f3DXd n.3KFV9$@L t.i 7_#GKC+er'‹QޕfzVqOpQ/0lz>b|y^( nB/〣Lj@Yvy_)eUP G3{~Sō rLRCxÖ;YБb^V)ӯO0)k:柴DUbZ`Л=TÜ\^BUYn@9LjJ4Wvة'A[ +HE]nJ.Sq!+߬I =A9T>x!Cxȍ 2rupF}j&3La? &C~JJ\,ѽu*OQ6ڵN{9TcR&q>TNQ O+C/GV3&zz2'>)*[$ofd:2?I"7n@{j{IK ׺0{ o8q"9Z<#QKiIfrT3!BtHU/Y guJ ~^^RJIɡDLqVsC`w~5BGC$DE]O^l>|  &Kcn^aZ6C%Tj~|(GF0N2?ʑnl4b͉oad4PZuz'b V 6gh!wl-Ya1S<^Qzp)kVBF"KIH+ͩ)}y #VL*Q2a0*Y^-x-W^LDHmŽiEquf¦tAS ;pF\'k֦UrŸxDHc pUt$gR1̧hYChϟ?|4zVնp*8prx66s!CgFA˜}g{ յ85CEQ㖼Mt놿}*AnNMx > ~(SM\b*uiN|1~6(MuxPM;֔P*{D "q z) ΀3#T 王BzRt!0=Y꿼1Y-+h| #1s  48`AA@)IY #R ^"9O Żx"؉4Xp mm mQ!BuXgX=peN'if1">,YV&u|Cp3 K/aeҕ ܫ;GȂAt-Jx5ST9&;"ۭIytO6ϊg)qƀhɟy:`bߩ}s)ek+n0A{n_&9k(oQKnR9RcR }ב(tqErf?Tʱq- MXNpM*bMP87ua=n U/X0[nޏ)>ptYrPL̄U>l@Bi>8nEV-a۝r[.m'c#n8]2PKR2]J4NJN1}'{tsp}PfJ`Egc Pᨊu=AWN ,UʾK<֭y?ǂzY[M@;JD%A׏z Jo5fGa TL{?,97J}>z= gӾẼ Hz>7ȀM_287eO#QpKM:+ UK=Ła%0ϪϨ21/ڹ l\ba@Ѷw}7cK_g/\ PRz\E2gHmMRq?>vV*|8~ghU%BK"uMLDN J?w%5l8R kGqL\ 7ZbWql)~/f!pJ\d|;rf!)F!2!ox4ҊGR.(dUogDT*NQKn1~>F]4?SU$L …WaПf L YYquG#lWĹ]KEAie~|[PEH$ $8j 0cZ6EQKk̃Rji}|JET!UKashPߧ[;Qd)s>r H=slj:dFH ]E[Z26f^Y)_a>AvZ*ׯ¿L7Y`]0:"'W6Pk`39Z1 x_'}Q<3drsJH7L/p{/\ESSPN1isdmO( vȕ9涒*.))oN1(@*T`@>)]$ /Ii= ϊ#hkicaR&DS_W mJ{:fN+K|zqc{v 8% &<$Zbȧ mݦ7HVJ}ُKa9"3]̤bMlj3 DإZy|J` PDSZ9 ]ȂEe]D*ݚ? #Ț%nKƙ&p?|"쀴w 1V#@;܎gJUJv\M|3HҹQ'v/S23w"V=.5gu(}`S#N&6b´=[8~:XȑgBL럂tW Un?_mreh"他UyiĵҾhSbWoLs;Bdtd_zM2<$WAP})bg,0c%JyShJ1"'\wF_:eEx [oM!?/(^ \? `YZUzm)C"dE\и3s*{&?BcuQܪ;oYSKaݛWk9 $7 n)*Nx;u\gєD=XM9xٚR;-eԥYp͓i3j;M\c;> UX|7Eݫ,#miǑAj 7E-d$r;KCU͓rB7FrpJuI0SbcBȽnqo8bߺ?ɾ8@S1%?镰Өc]X6ꉮVŦ!*6R!S >W,8aH90Kw<#4sAdXga372|0iW*;=A9k quJQ'ldy/\ʺdiOied pSǤICʆ W 0PZwm+8z`fƿbooiQi݀Ӌ 9w<$|iGQf"a 4n&6.ۗyKǓ鼆axե@ևo.Z( _U=VI/f|o0EMCڡTFJWA{m$e-Q[R¼hL%&Sue1UUCߚan,)([ҘA}fϯGXݹ%Ncci<-C}B1@7RYc\;NOaGCk2ZB>`ŗh9w'"¦w϶,%DMk- U>?RKU$x $s!?:{iy_}}78.^/=֙Z(hPZb`>)Q,W_{)0uw6u/^QvhUs MpD$>xc2QhxM:mXnF!\YIazE`k%iCa8@S;6Chd1߸aM&80_ !&fImXEWqFPQVn}8 G+pyXtHTLOxc e+ˏl[`@:j7>M> w֩kkٝ] I =^\^IV}(+bsil/jn>W hڠAFo'd(W\s~f){8ti> Q\ARpٹsm.-˥{\m힄c2tw- Gk:)ڮ1gc"q<=xi & ~2‚˃O(fNYW>-ENwmz9S1@i/ܛ0oq9g2J3(pcu TY#79A1J]9Ւ"צ)O2a[<NPLXδ_QRNsbx(<™Plj$2 Mܘ )j 輘pmp=hxnuMa`MEu_s5N7 &|,5]g%6]G5" ftrpG6#{oahQRHRn]t(gFkq5ﶞi-n &/=DԠ>(T_'ռ^h!*[I-|֝UʘgdEzDW&U$#:(9:VYFWHJqMȰkkvD !5rnPГ[:YE%0}[͖ٛXGtRP+ES =IkA/ D$ gmaL{HzoE40\UDă95t!Oe]YJއ⮠8|~͖d{6z 6|vnQ'ÕU}Umnã|5Qz$+KPCeh}|O)G/BU* 6LPғ)[ T3nǗI.S6=m!>5`5L U=p@po=\8g7jDT%G殓Y';6,X_"u9rQt*]}ℜQS.V]A]X-DXu Λz&[2X`v0hs\ocN*27>[*tޖ!ƌ@nd՗&iFV Sk:n6Ts9gpjQ-ڝ˜Ŭb߽kR}bĦ;}}h#홗$6R'QA8meXZl } \ 1<kD\w|.4N*7b` UN)WQU! )u8t-҅^0si,pN{'=n yW+G`}Je-ƅQ\KA5y1-:%cioBg % rQԞ_O3}:GuF$׋X]leO "./ /R픻Q[ˎ뿇`h^+WlP0Fbb-쯔{ \r=&kGs dTnd~+C}1mGk`0"3^@x(aP}߬/ NSj*+?Hd}5|OPDzW+n[.Y]<>@\G0K|pՒ b*1~{&l*lP*{ům°A5o+z ׏QO7Dhi$+~/؁y#%R*Xf 5Cm"Ի̡Yr&Oѥq,^ޥk߼~x&ep8[|~x݂ZH##-]o⩑xh$N-Mz9g)PBu*۴^bAweNc O0O F0 gl.åՕLYT q?**]Cne~%JG8)SnS:Erjx[26 +R7<0#4ل hQv.\+h7 5Bzr @upjհ,#)KyZ-7 ݗqkv,<x'A?>xd-@x4_\$aJHEhX3vxOLq^ (^AfDdr_$h/vh#6B .99B{{C2`c*$SnpQ1aoE C :hb$T&%Y8` r?6t33] kj|ڎ5D<1l^o5wüh`,y'c҃V) Vu`졩mc1Q32XtR\C|+#/7BѨYX A*F Y;+"ơɗ1N-u@E`-^Zn_> m}Ah e'8s[nDF,ΒD5r2_hew^𢸪s>J8 (-]pK)RGnM$ \bؙdw˛Dv.k*DF'Q_<܃YR>㦽=pLHC;p+P峑 7cgwdr&W8_NMKlCn_pI%DK+."ZÔ1:1ک?ۧ,"ߨ4>H:jA) ͮujW~~fY4gI%w51͙nyOaW s,ݡQ\& hD`-X\a*eX)Do)<b@X)%L,c!oj@TݡiyUsG#wiēRL{u|->E7mrG.X]'/ X~>;[9d7FB=KDvzB}q'WtHB$n^ph$ȅ[M=R=<r_t0-eL8B-^ٳjs 6B<>j-as \ު<5{_S=oMvc@TUud A~ցWGn8JiL5" uҗ0T|t]l2Iõ $E@A#Uk祀3^.7(=0ڵ5'5 W ;KБ~X=UAIiM7R'jlae ;pkbk'/?[UЏq:i߇'Sɏ+'IKgf-+7B%sGa]r|>xEΪ}5U2jpc@Gf1xPTTIm[8.TL|Cj"+%P'-PN"SՁH_yogz`&x`++?[$[:%/?O:,B. )6Ғm-Pi2{$I6H+KŽpG;}c{'bnMe[\ZV\\؜ 'Ge?T]$\p Dj C#6UϜ D?16NXGD|=4/?a풓m-,rUV[Wst/*j:AbUSu8YHˬdI1pF5"`p-7-"Ҫ&wT^x;E9L ˴=x Hqqmd9F&:ϙ f w1{hnADAf3}ߤ?ˇ Lt_qC߭#L5ZR#T&fMU5Q!1[]hPMYK;|%!@7_6_hU\/W+R,Д){c;d7+dG?F]<4dV'ޞWr<ԘyYa;qGZ"w FM٤֬jؿA1F½16EE)]XY"q _ͿEy@6W[RfnӣT{Yy[C*=א7}z:TPg]}czFmg$aoJ<]c'A7v_W-_,q c!kVHO+jqQۨB`Hw hm8l/v]Ha wIpة܏_ y;ڊ|@@߬D7mgTf_E+L~Bʄ)krce [FYhRP.i;K\<5G+<2f+k]nyd54wA:6GMߎӔSXo"л# -'\Ѐ"@x rl%Q*T L,FYa-,\f"JF;VS&7~:!mLR!oT<3 ,A<m+aFRQUnװq(Y\O69m*zW5ď(_= vnMgD ק+U[E;}i$ gidɏvz~bAY3̮vۈ1aP6m5e(*̴\uK|uã+jY_/;]ۋM-yYw gS/$[>.Nt[w/|cDP2L-0: M2L p@sROh5S*5MNc(*9U·mc"[5rY>GT>x=>}qY Ya+Xxj4OѺ6Mv*9̬[3_Bt0A`(I¿z*΅I :I@_6QYx9)Wߜۖ&-o T4h|'b`T~\xms; a34Z-WTt'R&t舮$zbU!.LpK·n HtUcYh4S m@Ttf-Ҵx;0!nHJ ouў 2(ղ^a`ҏYkne xi FEMV[]sTK Zn5ׯ>Ŕ}$1J{iwjyf6 Š,]xQ )$z"nb3 flt(m:Q0rnm7l)yj0;c.'BǠ+X;f1_ZDu-K#,&#v} #ju(njD6% }?!ϕؕíCNm Tn6ÂkڗUr_v`*$bށZ@0 eHɲ_|m: HOΘY@3x; :6a2L N*=Iv7FܦO;>HP}кw4cfɯf6UY0׽ *NMNPպic$KywQN=rpKp8dgWW Wq:΄twRhݸ|OMذ{Sa7b=e#[_oѺh:٤ˤ #<۾_\θ0hn!dCh[fX"]XjefjQ,5Mg*h43a/=\0i' b}uآ86C7xBx>aE|‘c(Πݏ#pdYiRP9+h|xpog棭icUͅ AΟ{zBX3h]P.W6$\~ ;j^i|pI$cF@h/Vq[ө^t(xKD?c_5:8B8u4b,0{:ceZc/m|[󩎖R~p"ĘIdn_ʭZiTY/?E(;-]6#s M^Ǧ,{V5nGؾÅY:$ 1)d%!DF\iyG;4YW0k`晻JPQjTs9Ζ.5R5}CNA-0/KqцuN5r(BZ4 "#I#_>E |Dqk۾h^FcT+Խ61T)?W h,Y{Ɯo/@K/ё\B('`Z!/t8]+v_ߍ\1l-Lt71Vƞo!۪F/"rRL,^F .c L7AaQA;yѥʻ?AZec3B(ҟUB.Oo9[?@94br8:Qa6_@B,QN.Q:EuR_]Hg:pF+|ځpi4Yso~w9^ۢ*i vDsՌVkj0DAzn<|M֜M T;$ft˯=Bp,fkſ)11,&VP*!9!||("c7moB85ٔx1&,ƈ5cv\oU.3bQs/>/@v1sǦo9*V"Ɔc)A?! -DsֆV$ +]âШ2:%]6oI`lxyq4j F++D)0):[mD/+(Y,[X:b)X+rt7 ,Y;4Q8ȒBhwc7l١+Zd3K{) x;ȉ;;+**k͛'ИZm|: 4զMaKW#3\ѮeDQ>fd5!lػ 2_#9HT{X?#w 2 Tcؚ˻uULXkmg!|p؆FhҼ@b)v4Ee8Q;h:M͏'lhKX|~VޓYF rdH0{ j^X0> SmA._1fٱ[ ջ:qΑx,KQ6'oITr|- QG)u.\Q0Rq=IZiWdȠ*).ps=gCݢ|9=mkYw\D31);eR Jڍb_b3Elۂrt;bJN 1{ozVupstnT~X&5dnStލBI2&OGu+TcŴMFuARN,kh4NĦfpa q5>i~܁RKJҘgeJӡzX.ɀs > b 6@46$:Omch$BE]iB5wJ5C,ݓf5(kNbˊAbyz LQLWّ.qL{GC&Q} s΍&e, ssVBNW4U,;9v1¾-zO}ڛőOiuAeDEY'(LjC_Q,cR?I!NRiuT"4 _nȉ3#MtfdQ0nl9u-[%PU{WE#]/6Iz,% ,d<˶[g RֲCj`<6!*/s6?v`!2C5D?<ۧ©Lt &@!: @D0vyҢd?|)6+> A!\!&z(Z0aļ K7ATY=m50z;'g. "PЦs{xiDov23mqz&ߍٽv[kX;m>"@s*27!;@y}xt) ?&br۞pX{^\B]k.Z[G@ O3 Jq0__b26d@n[#^Y{dU_!D5$Ŝ*3G+qKõ]MuB]biGt464;kO&<,+0ecWW85;8W(e6_N]JLu2 3wX֘JeL7o {3iQ`?۷ +4}zqK>gNꐉ##6l ~XjZD[W@αN\t(Wư2hRepCZ>1dk[˷,zFImE)$5\@ ٬4tla[EDt 7;JK,-kB X=8)} lF>|zenB1/WmHQD0 ]GppOVL7rgv'r{nA֊\̥[&zvjl$(K's'-rW.oGμ:mPH%)n(yQ _ڿ;eϪW̥wf1l?xD')>Jn/hM|fȨwR`Zjxx]z5ui)ĭL'N>o~ 0ϖ<Z95Z#2tKG'46l~R6]f+Jo݌;G +UwכZ!>V%ng/6|Ew.1Swؘ>fZ p<ã#R|6KwOS#ϟHds00Ƴk {c5)2UKa͂ƨS3XQxc![+},71*؊G0V4Z}عkɖKTuuJr^Nn|eِOʁgtxspKmЙ`[*HD/97űZOPQ۪Ñg\r|nܢ>]+#>n羾}͖CmF9 + ]y塺 o`*Ҏo4(=%NMvò,#j:_hbhaM`?WrЁ Y~]1}0<#ݯS8 2 #V6 4[P+dQؓhJ-swSu:B~igc!,Vh AgLju67bqKof~|AG5 Jctb Sx7)md,`du*b*~IpbvȻRtZo8%tAU*=he'lGB)nc/H*!P"1\I8k=b,хW9e>{kj1MS6G'PwªX8~x m-4Qc MCMhhPY_ػ<W> B8RJfaW̷HPuiK&v6ٕz}TR./Ն5`Z0n.(#v qUJ=0^J`JٝWo{ͪXJ, 7a>rbdj%]5% ٬g g|X@&HPIF"T%9A|lAx\@1@1a\Í!°n&n=lE@zs^9BfP FH(E՞5R%NIf.[uwfٚBIӇfh!!nз 靔(4gF+ѿ;MLߧT8キ!!>ԤT=x$|waqk%e" %"e@jmR>=~Hf˱a@d"TvQ߬lcDEN6<d G':R"/t7$Y.biBY0:UPـegqč \/&}kw(*Av¦DeL_!>Pe@4;ɦEێ=ĺgM*Oe#2-b>+sK !̱CWκ',]R?:]ܜA*,DܖFgN3(߽m@tƹRfIfe o밍E'$$j׫(f΍S=Ij<,{mY`lqvDt.dJhQZ d=#@ t2މ0xDwɬUNe|>]/y 4X ZqgFYs QTƑd}cNICR h?/( Þj%I^[nӾ^/a-,*zuN&RbaSO%YXx f%ҍD0`y[O=!19$ OjSAZ2SLNy$i1{ۼ8 Ƿ.`} v*ވ#׵?}u5STu>'"pq ) 1rOy4E1Ȇ|_=ߥ,O%\"OvlY cbOz8)- 1('H9k1D0粏g`FZWg.^,jJRۣ_]kb]`3}))Hw٩xVȦ3! ZuG@j_CQg9x*jckNMZ/Qp2T!脠+AlBJDzt c 0[{Qիf@i-}6D AքH1C%L<>|j4 ^^@h-]>^$jVKdaƩJ %%?dE%,~ܡT"?HCYĤ8`<<5hIqpY#8,Fni8y7c44n=?JK `yd=#0LH5i9̇l>NDXt̄Zj%h&&/+}Ez9֮ڸGȡ8n.Q Yo9 $RL>Vk?U}$:vO|nK5 gjLg6u>"Qy('w$BBd݇QъZ-Ze۳LJl=+i9j(_3%0Q-ۀdic74;tlA/<"00D7z )rHB-v3m 2 'xe.iTRzjX+%O  X8RsAoE/DR_`v0u4:8(ȼXBd +n|ۤ0P.;{T^1 $GH!U/i֯di0Y#_ɏTKdk|pպivVYxf(L#еX]{zu 59ѕel4/仳#HW M(Hh~7*hn_+ݎ=L# v8c?twôn6$ I DE"Jx jUE'hfIkSjS}!TdGlC?Čy>QN?Q^()({k+&Ҙs{2+5Ũsr0^wx^Uƞ[R$2X "­ B M폻y  ք hQ0cnA8 /_rA&ч2M-_؊ƅ@(6d5ʤ0`8悫Ӫ<#e* GI} Xx1XxtIʿ_& ӛv?HSrL%2]뉗HVDoS VW7!e:hYO<9 o=p+Qvc #PK1#㊅{A+c\tٕ{´l (JnjΏI%rqK%,ojAF 'RiUdNF7N3"6*$y}GHsE4XIpz 'HZ!]np)PH+-$E\@hQ1z&xؽ3~.*\MFҍ1~vuzh!H ũyyVx'-VtxD_Ԉ =[xKdx?ʿ |70O̍d1R/v@Űw ufl {x‚ݯwx/Iq;Vj(]&R=H "Y-5 *!>m0}-!w;5P_r{kDWo` bB.ү؁KmTݲfϸ ѕŰy͑3 đ#Om$˜#Q\$6fuA>@,&]C Õ %4-6A'q%?/2 :8@W$<8xOMֹ]ǭ+tٗ*YZ@LWj:RPJ0?w1¹.;:veJZI Q,3#!:xo] Xv?F@o7tKNK-w1'6|5`nkE’n}/3@,}Zu v=VЪBR+?wR08{xU_֐f.g8?\%ޢ븠"Y ΎェQ$@z`u* QdsΐQЊr$1& NF'K1Q?kN:gf Dq:꙯a)0Xb-lܐ~)PۤDǐ]}f{"$ Fm)e*5QD_{1k_{Z+NY@A[e(9\܂I:.nQAfZD.yRO"3ј{&zb qÙk1Wx*?؏&P)y'7%'S+#FBA3بۅmc%PA߇ҵE΢URUcd񊼸'M^w7xLi!E3*6;]R@c AFɒa_"`6E/` d@".- {t" !s[A 6Z#`/U\5K(c$Ĵ{O?:k&W02 !Sx/9ZQ@B8Ns{w1k`C}*B Lߺ9q~}Ya~@XeAbE@-[M&$9jöWǁIZ#9(L(]~V=}%'.)j5w-` p3f Z-6}JClvDm]EjotwB1:QPOo`ԣ=!<û9ZF)y:U=m~¯81Nib.up]"JLD?ABxOWHZ湬xAkw6?Y?BcLkVWNMR,}y&̷%ڢ\uA[߽l![A Β؃*;ڟ@D%]`pz]N4&V8JkGj>ny "=Ӓ#UdL`3*~ڳz3L*Ʌ!lиCo럤ZԌf65oiXz1^RzNwb)S@Võ͸a7B=>+Ь+Z-#R2B@9 Ha*8O|gWy-X_X t!6y {7q |JkDgnJX $gvGrgQq-QPYI`CSJӓv}UoP 5lFVe:&o('ttw7~oShSmd`'mn2\w=>ߪ+'$Z9dz 7'bwk/ ca_WLxbE?k),;#u;p8+lW~xRw@b!2g&x| hVC]d,#5DF|8J_RtwfO"iVi0 i`P!y`R nz4W5,ég"Jcz `X4vF,LM#݂=AhpFqpxbl}s%^Cq&&`ixر˥vyb;83˻^.IM7qc #5V֚ֆ FgK"ɧIMAŨyQvdE7p' =gkj|x"/yU =H: +jFfhpkhۄli#[rY'iKr^uLBm^bwO6y -NʼnŸLAG%ۉ` F!D1{X> hiڗS{F'bJR9ye*C,/Ұd{ fp H@cP }O~|٠j2=y$JYud2" , d ^9뫳m VgT[*0BlOˡ>q0)AS^z#󙿧߃DD}t Z}?(gbFgcQvo.E8lQEYj1.Ծ2)EY-ܗ=ѭjb&e3pJ{>v 1l1rqɄ/Z`O8wNR: gQa=˩I(Wjr h]>B)!n[ƥ9mM} us"GDvբV9KBMW2 `2 \ C J\Z*TcG7 '>YVqnfo8 y:#B`#&h en͞}-Z*Lx=B,^PgB\wUΚ!s6^wQjm;ͻ1MsG/a&2qno2jmXϼ8^C7l;_X')((e2{6u4 T y!=wȕLmm[+EcNmU۟\LM}a AJ\ &7Oޢ;a&ɺ48.+J Ey&V3|Vѯr@Y*:>W V@0D֗eVQ hWfMR떩f 7z&imm{pt/!NDNLǾ`ZX{:Cњ$mD˜F.w$P 4@,zoPVkځaS5(*s"}sls 5WB#6o{R&|GCr-.S^BF+1M#HXtE&3q|ax/rbc+`=ȤsՄ9T$S<3 ;h Bx!Ȗ2Y7n|&@t}mJJd.ٝr%DѬɊqv„ VzpGn^۽nXx}䚚Ck:D-j}wŗ]K,UzqҲ7-:k?ʠ)m1`vo>|N.dP­jD s"G82jcHE g*%LcVN9kVdf` #TQ D&2/Q>ɛ@yw|ŭd-P7N3 zfHp ?.3[ GeO Zl`Dgn߾x)|@3MZe sJ"S1.{( fT;Hj ڈs-n 1?놇 Nea&yoqs֑`r0Qm?MscHI#:Xk?TNd#"2s|"HC UȀcpu38??A6 ]Lڢg^8B4n;c[ZZB:_dX&q :CP!)}Ԕ{d{W۪Y | GUgW\e;jSwPulrL&6M!,OvAeqk43 qH1"=}i2(ΦgcN.$;CHߕ_EK|[+[aVYJMR Yt2m%&x4K<'`0{gHŲ~V Nfфvm%0*¢bB_jUu;Y {4KiQA2|ϕra7 UC}R A6Ak S*aFS<B=dK0j;DN ʴ$v.>,3|dZyoTT:oyzCImD'n.Mx-nV9P sZǫ79!Q$_}YgTpLsHKf>MNjZȔ TqsְO8dV٬$ $ Ƃ^X~9"(;{UUnBA>A BNؙXa>&;2UEqDJX'\bK2R~9,Lϓ#R, zuFJo2U,LLqlUK[찉0h\3~qZy~!Šsԭ̷k-Kd 6邓3;wN6/wlb"eip׼*KA3^{^r93X Ⲟ@!͓/@Qy0OWoW?czV~nҳe- DJq8J@δr~ʕv?HmNy|qhte}2LO//{K_=\{}P`qHlhUM: dRdKH߸ixWSPd9qG7qL(oBÇ$=a;/iiz-2ڴ7]& $#3MxN(BKT~kPe`&Tg)(Ԉ$Qۮ 銆^Y[#b;GMKPZݑ\K+#'n @ ԯK,'(TC5+"KG-J~{cvj \ˠo(bCIr 8i\ }ȉ䄠R}6lK񈊿EO@VI5O ?_OX:3S41KzQ%k;+i1O  lKԳ=c.`E4==P~;jF΃5t͎LhH9Y xrF|}mQ,=/b/LCT|DW[0 TrrZy9 M[D9eu9y8T=yc7nuϗ;57~|Ƴ$dZͨH*R^\ލS3ֻoӅ|\wy>sͶWgcH qI¡w_{DnwW%o3EI&,Fkrbz-g&~UE;h?T^̖KSP[e1AUǁT4z[ 8hF"7";@&tuEH]i| p}.Һ1w`^d[178mnܿ.F&͋}|$N|FÂ<_ %-T`dIݚ Pb;Hx`xJb$ ge ڳq l H.ˠQH^漁:@!fqi{߃w6XGfhڼQ9)V9IgLn&'4op! sz="3y(kkO==&o ^l_1HiDw5 b̠>ž83E8oIj:< U}[9pÓyFSQ#ҿX:.QѱzI4b+J(ld4$/=[!.h.9*?YngyѲx%A}/ؽol]?U 1rnTs-'}$H;0kia^P͍GْҠD-UP&'"!n}<>ElU/7T}41@A>O[^ /SŃCr~ eîmFJA$~o]}:NfنaARH$E(iq`Ѧze5Ac)7zWaXaowN;&)EFB?*:)3 ~BP%F2_x2 {>~ы[K&"|"Ĉ:;O Lrg,6%V&aTWX*Q2j"(T8)wcu#MO*t:7K~ܸi5>' ^2+jbώ<1Ző}|dDΌMGa7;h0ۀyv[&YvW.]i'ɇwبWڪoXk4M>_pV+\ɞ'ܲ7; Ѳ/&лq|UPi4ռY b07E`{Uۋ=̤-rIc䗘k̑5iGH0U_ 14:}#=;L7NC-P) fW 4+ .P h #CNܟnRUeXՂ|WO5̉c2z+ $b1~41R*מkKp5 X,b^~CDأg6'!ȕq>ӳRX  I׀Vo7qMo-猭eǥ".0du␆BDY՛FJ~Վ(&x晙δ~O'fLejd'T> D64`>"R`TASdh/~$AYbjdKf!,GUI$|(;t B-n, %l7]'F7XT24RZYaq>.eF# wqEnB5_.lVI^qQ GJ5Jѹ9OGEG1<ԅѧ2w|hZW`IJף*hm }m `4ņdrPoggzg\'yZU,_>(ɷ[`N|7P-6j2$-t=7 -ulј6a#B;2B΀b8"AK|=';tC'Z0 "t9BF8)LJJkW՗F ]#$~?a?:hDH.1?oȵ'piQp _GĦaTPzo_b)ۇ\,þYw;>7ij6ȷpB]53;-Ȓ_؎Ij"m"5{po粤MqY?5~*ĥ8 kz< yFv%Ozu^0ۊc)X9-97yӕ'sjӎȍc^`5(^P}qӥ5P O0>ha=0qSO$:'_ALNz ˽WJ! cogԎ'6chȳ~(W6bwv=@2lKz>߮|A;-/]еֿDUb2|yBbܧ J̍kzp)ҥ$P۴p8Wi4}43ɍ7 S0\rv8awؿٚ"ϩmMCNUϿ 2^}UvN$mHUЃ{ 5n{N\@'UptV9^~Zf\v򛮷p¤AW%+К`M[I!e '$P#>F#jU!GyLʒiVU3]he#[{lLJ[;2}Ѝ1u2 3=U= eO-UpG\bhI[wKa m H0Xi7/wuɃm(hd4N4ղF%Tl^9[=~Gπ̺߹HoP}u1a_Zf[4HL'`(ȝْ!5[moK{16SS^_w(z`ZB!a[q$Ppia ;ۂ6d_ p88ifmVFJ: ܕ;XG:uJV(tfk 8EN;AtAU7l`$we:P nr]rpmNOeIt+IO X7>nCQXݴ>N^tw#7Y"0PGy|cTw _vz Yr)N-VWBų.3 YfT2o*W44fV5Y kƤ%/P(f( =GMͿ(yߦn$"c5gFZ|X ~_x[l+\ӡ?>YmIsVwrEdN^ՠlם^KqNh?>n73@Z`X*#IM k%Wƴ@@unсK#NM{{ݩ۝$Q(7+dJf q@q$!Wǁ;Pm%nqs*>+?0ۡ{p:$X5J P!)>xѻԼ3ShJ1`㬺!پTO Ԗ]w,xB^Y <$A^xwSIck8 "笭Ͻj1 |n^OڑI">ALkK:_،Ԝ~a3I9?iP29>YTwbx/ M断+ZӒUK~swX c\ `kHÆqo8GGZ4fj&Ljo1 '.d͠G P;[h%uSIS!&"[_y .[Ux9, CZDijN#^% 2+&ZHl9}k@_z)oK7AA?Sع7PBvh9#PU3Bb[_M+m [0??s"WKTUY:s %_xߘ5*6a% o0k 3G?!SfA 8'O `r#Hi wI]Fy XB 3Ɔ$? SC4E7Ћ9qX꾮&HYD݋;*m\\iXyuDŽ,/( X]"sT]-A9(ۛ&)Å-KF <;8"'6XJϣ~y_tzMb}NHH܋:s{sAQLidE]g c::J[_1D{9wg && \=ndHpW Wjx&.AYTbcZH3.po)%MH&.)~iK+VFs~_{4gOةԊy44AMdK;t+k2tk֬N/dh[ϞBRX54,`ǵ_s?aSyMUg ,c̏, @]nEJAsA/DN",n:P¯{2tP~.VLDDrh`^>X831,qZzQt9#ގ[aK ޷1$1u0(~NQD" qrqs H튣bۦOfRu<%(_bgLϋ}Q +2ք ooiT0&De)8~GC<\6qwMq4KR?<)eA䳗"&0KH |UPD _|:Wa7;2q\(Y̰k_AA U@*'D26rR 4ꞽ/ƹ`j~(o]g|L=qJt%':˶iw@b b,wA1矯a9N PpLd e\y4g@r<]LJhjZu.@hӏ4j\=P2%L t^r`\ ~#H[:O~n@1#UB9LۑYEVb?#歬ggآʽL8=.!hEcL;Bsvs{*Lwwb!]?>ðRm6(=]E#XP#ElM!x1R`HyX>Ts,x0vنGon(5mE?CRHlCSC$ \ղ 4yQh(r7cNZn#Xї-Q(4OS)t*F."F.MN}?}sXurpHubKC|@S@slL)-lHI)lDz̕GӪ)}67V6?X:Dd1<r\8R%Vo}+6riFSGKN}3n•^(yw쇔ن׆ A֩г1JLFވRQ>p)w)7ۊ.L V7QNdK;NM>/Pkӊnxyv>+qY*Z8!{(,]} CHYj֪Vm6 \Դu{6Eq1C&~IAdr#3V]`,xy?{NHB4!cbeX^jQlJ/HT2k Jg/H:q1fkO2}Ilf mn1=Tnk=K;:h_۔"$p|Սg#Ƈe "$/bQEOІu*(n$\le\VȯYGHJwg4©S rb4B6Fb\$-TM,HTa-g#5&IIԄzh}*zBTg@tmdjA-!HuՒ4w\/*i6mf  yč\H8c/Aءϭ#QaO_nmq[[ n(W3e*;tv2>3=e!υ\J6+ÙWKF\h:vO';O3L51^P}?yjOz4R` "S C/FOR# U{?t~/[A ޑkHЮʷxt߈9_}ȑNKlpAXD,CY m, Mb56+ys#(wN n:,N*}KP{SL1ql/U,29so`${PC$ڨu%P*v,d{$ҖnW2z=};R 4L;FaH#ʜ咑c$26me(i Bg|ٻ3xFԔn+)q$K" lOzqt#%^P;*Gfrm,hU`顉B%z,F [L3$}@(b*`vcYҵ`~tK.^lNdӷT"ʑ&(m^rg@.ء?qI$e7/vySβ~30N0Ʃ$ %+j8Ct,٤6P|B&#?ꋘ /ty6@}4@e+=<,-$RU5qKSIc#o%o>k 84\+"Ӆŀmm;X`#Y脪Wbø8ؘ! !Gh)όBv"v8<9gBiwFA ŻbY.qT[D#-E:XED.?zvxs㯴3/uԉ@Fbٔ,J =h܏:<,Bk;8dNnh#su3zmSXtug#h1l[f$-3bS)9uzGo(orTeTP*#"Fuͽ>9||*[9Q^[$7j7} w `WwUIc+/3Z5x7,d 2b6qAnʒU@+e- ϓ.Nޠjm "D\rt0=V܍fXje ҫЇvEo @]Tz)9N㳒jª>g@E v~mRAƈ?sbV+QmQ)خ/] cm}eZr$E/7҆pM/M 7K "ѼSy$cNnvڠ[EƂ..x:Lt_D]5_W-[;(e\JSX^ SҲ_+%t$כV:|R۔b<Ŧpi:o(c9r1NX`:8Ϫ\*B}ya+ax?=Ke~ "$gޮg>B)X\5 M@= Eih[ϼ:q89O(n/M5K<1,w{KKxX8o9<  iyvsŽ#LTœj1K3{O) kX4%d*O)STM"pBEWW'bǭvlfܨȦ \9ݣQUh P+M#RMQ2cn \=!,o3J0㌐WÔC'WY}T{s}v7o8(Xh EcW :nlWssTv}}* ˫2SY7Z(rS6XhdR}9CB/9m uwD̟QZӠu@MYkyH ś-C b"(`#ErPW8 ATMT0ܡ'>o[/v "'L (@g7MВ8*W&bv)\91{]:p魯-ǥ )҅ֈE1At8XB0!f9>01H@ +Oږi(۪,==~nEص*|Ȭ3{mXkl,6wꄶyhxSG 5-“+mޒFB(FxL)' NJP@"4l$7tRjIB rPйLi=I x쭰҃~z<:njf/;ۯnG<OR2Hw+[qSj넷ŔSm z$W>lق1F8Y\dCʣ%*Պ iyU"torhTf[&;"Kj%2!Vުӝ$_f\jbZG3W3D]>3~/eKl&]"#3a1\႓TV$h$˔~P66WRFUIH⬟hnbv;"]rKᒸYz Ʉ2'uSy{/ G])R?-z96Z0q?@i3.B]5#u]ۓ)>tkolwâ^>,<Ѧt+ molgy ReE2VÀ0ηKOVi!xll cɫq_51K~ȯr1ƠeL%lZcßܘtNԫ@ov`b\|xp=yLWGZ n+Z`o#OͨvV rv3 LZ-Uޙ$(|W,Xr!W;©Cjb/`߶r5k410,b{Qw$*pYeh+lM^.*ݚr}mi{ ov IM#9_NlciLGQawr6O8„عBa̠iq2p}4֗X8u ~XFZlT.z%}/Gt6`EDY_=I.!ʕʠ#|D,"9-o5. +pZ4:O 8$ #%ՉE?=dl|@ sb&nf[tb8K $Ս]ݑ1=ݻQvGeY9C fdUxj?'J'R]s0"ȨX$9`09vԝ:?tWca8yR"I=4]׃uew(X`O=eӡF/ ^$=m\”NPgآyY-A=8’偙KFW>Q\Y{+ 3wX8DAõ<8 >N ~|~LT!|Ez#3TPy]DyJl&(HiP\CW. ~IG-{)EcVkX5Mk銨!VH%,w=L;8(c FI)ww7d߽ttFK~PQhW#j @cz.qap\6u]Ȑovס7ϫ]2b̯'d֎Й¨>\7*}l0rZr'j+Otn /ǖk߃QKޏSxiGYSiOG0eI0+uHZ!T";)danvo ){ϵfQ7y,L gۄhGn-q({/،ZrQf$iZnTsGy^ 4eahIԬݬvV p"C`V jlKD#-g}'pm/YVզCj~ Y)B)#]Iű3u>BG/c ]>$^V XF&Wrkt~1pjQ)5/RO+-: ,Yry`N/ޏSlaK!fڻJ]4M9Jxw!!MJFȀy-뇡-Pޱ:[MsCNDQ3BM096K!aY6oã'!ڼJ_)|Ka$3̸]\ ;_]7nO0u}&CvJbNݏ۳JT.84O]U/03 SʈԳ*ȹ+^HRvMY 1#ӣ8ݛϏ!3VY$ado2_Hf.*+վN¯!H*|]t9/`.ILC5y57]s V)v܋A{}oHcB`+h5i k7Hp;='ڛ{8R{Kݘq;gD|j̭(cX&YcveSD>ߍ 9K"A ^<+qNmgyNj7z-}7"b}]gL&WIK )i,c#СY&)ÈTg ^(M=;C= &֜*flXp'+܆PRܐRWڨDɰīJyEYTl)+xUaPeMNՃ0kWB2OfN s4H]fAPk: r  o7V2eX.JZ/f=vָ ) tG2EAۋ?@N,i{I+4oҭ͖Gr0fFZ>uc\΃u{>凄纫(RrI/Vkx+m-/_F&5[LDKysӫ}z+-6&hI-Jd< ,)=^$}w`RK1'.hM$?|vS"A$J_sr Lc =AeB/yzl rGXt%Ν㖶SiXFa^KP1]X1+׉髋)^ky }dz,Pkv' xQyEox?+2M A։ TbMsg-EWj9JC [Q7Ve#7&ˍQ[x[Pڷ?9O#HfTT1.y7ߞ_^ţ)9sÁ$xE(2PRۈ @kS#8p=A©`DC9wvGQsb p*HvBP %2U|IE>:(D'b38B "^Pbu1+ S{{ǻQ3ld2Bx5#d4ѩjgp!U2Ͽ " אa&cӾ?_8]kn,4ǚl{D J*n.ǹiAm ;kM(a XזwpG* G K1U22yYr?R5&$&XeBSl$(ޣ~טO&<ל [Ƕ8ԬLD(oq{]&HOFFIK~&-ꓰj; d:p{nAZ+ CHPaza>Oq <e69!4 wlUҐr΀|k%QX=-T9a 9guo)>sʊZT4s7-s: pv8|N+k7`k+B{YE3 T=yI^ؕN ;Y? )?MJkZį'z!Hicev'kd4ͥh=K<$J9B/ZIgmu7Sa 5eukm)j{,oYe]a7nP{J8f!pոVj|yΛ6fNQroʜ&ōfy8ή;]_ A6xڭkJASͥ~ 'pZlEɕ4y`W+" K5һQʨAvy?o濁t|6a8;b8Md(*&hp_DZٸhQ֟+۩Z3,󤁒>JIN{,A dȿj8[U=` 2gOWN2YyUyxeɲ(q;"?VՖ wX M>g% Ѐz͇DY^Uk껨Vi~RE0#ʽ7Kx)U6D*<+셲Tr98ZKuw'n$+8םqu瞽Ymω{^Eu^gj60ZLlE&uUc5rcLAgd "[ynxL[Ǐw.1P>:!s .yyhR ܑ%4bx<%vw){rciP/O:;}iNg%rJAKKY{£Ϊoʋ*?14p)Mk56VԎxh% Q$[*"**^vj)np8t aOsXL;D 59Ck$l%d ̇9uk1P [F=,!`ɖÔj0<jCt U:64L>*k!de@ʑjW"䥜'L'OյԸa˷r9Fyּ-޾%h U'nV4 ?*heZB$WKîشn?[}xz'^h_H)Q:o~[iJp e.=Yaւaҹ,"U̖"9[ t-g%A(+ dl NgW #H*j3S>\怄 3$7sR1)>_]1.1.V[8.qXNnQjM`c+QVL(?C/[G ;D&W{h=ώA;jO9 ZХ'e,6+~G 01D;3*+#{ޑ~NwLؖdTfDXs^GV/}6 w0ofC/(owK-!ͅ:[ЏM7t :>NJ6ѴypY5{pƌqh]l'r72<=x),v`Vj6*,&RvX]7@xx<0dEh2}}r@^k ֤R[\Q1Z{d% yԷnq:oڇj"^[ 9 )f+CYvʧ{1mb'#bUl JE D hpܟtZبb`=!ی~>R|U[Q]R]!R$HZvV-ʀmiXmQ:)3s$Cc>1ޚ>^]L#%5ُ .Maict2t8pJze蔙ڃ Z% +f0sLz!b|[Ҟp2>\! /$/2'rpixq/*d^(Л\'NUEpDυ;yIK-|UHB-Fzf~6Q8_-}[IzxseScلGܛ91l ""}YǪV ỦS J|\ m~>QL!ېU=q_k|M9ƆWKi}& 'SVG;2 ?Ⱦꑪ0BD+l?ƫKIw@jh)SWd}>ncZ~y6lHG# slK͈Sy 1G(J*l4ڰ& gS"_Bl~bp 6؉4 HEXP]_iIul{+~D\γ*)=v,?-֭Rp5$&c)gey32 CW!pc{'M;Ja0%LmO(HEn6#X?ȝdHi*ab4(Cޮr;N5dqL0C â x cXlk-&]/ Bi"b\*mUu|һ4oGQ8\Fx(k&`lĕy:%b^iZu VmLɯ +T&I1 侙o~׿ĎfYUhR;"42^)5B.xP j`2yvJQu|y"ӌڎDcXB_.5⭉F&ʺ:P 9<:ʤaXM'6_EF)V@ ȴBfbU>)A{3U׀˪"^@tY$߹@WY `!\Cnр$hT7V9PꓤZBHum$^S&rEǥgF:WԴv?؝X9~ct 4qڏ|JC,(np ȥ"¿[ k?褄dd^C"TUESc0BgVd&MqLsNLсEF !vȀ:ve"Ow@."n#랧MCߘTd0̹8Q'0O蝵߄r@Kp?NTaK?6kPYW҉ж-L&MKd߰I Iv FKIH-HHvA=('tb?pΟFZ )3d`@OW'LY5!|w-uM|KI#u--01evUVᖌEV[@f 7hr:2ZFLywlו%ǍHkHK_\%Nx!Eib[){^ۋdhKA-~.^,~iC2)ٔN54ί{(/B‰JQfq<,#yOU5M洞^] /jZdD1y`]pvF>*a8M1{_^jo2S2ܺ)/"Bl[9yI!<ŴaK㿷Sſb%C"dAr3hEȶ{bW>WćZ&DPp^6%v?IEQ\-YO_\c%EF&KX 8k(cm~$g ʒR~F^Kg0)]\R۽]x&3%}苵ʺ=Qn1&yBMKw@>Qm$jxB c֊$NCjKl8߆eŢ0UL.M#OiZ},X #"\Pt5luPu\0Q3m6sɸ L{)yܻ Z̶%;uHյn?hc;Ǫ$qH"9j; 0G/ѱr,i!Dːs/JW]S9KT<!zL eZgrwl#޲6{Jt?  yBUZHЯ;!mKSH=UA?}Lۦ7'Pc}YЩU9,>]jgIk ʳ?F{繪^#n4Lh"hP[?zK;]('`H GFȟn7Q\odjg^ N:I+:\:>EARGm1ďSmҍޅN <(79 B hm1bM6qT#u=h*U N| sGA -b[$?ٓa`4Jt{hA&PˑJKn r؛"&&MP.ve') pYe  nlx0DXdXgKcaHW㜕M~bC+fjd-^ֻ#!G& ȡ<2\7Bw&"5Ԁsrܧ6>  O1MUmL HhzX; );\^HZZBGU uͽM8e:xȍInuS:I+@j@BP0H~Ԓ5,r%JO߬-D"<$``7w򳁻H(G3ôߒ)٤DB!Sd UBG/b@, DK= ۽icY?]ss' P>1X= ˗l HWi\-\Hk9cwO_WQuBo]1ҤըMΏR\'1hMX#=-> Sb5VyqMgL"<+ ?([-WQ=ft}.ه0j1MŔ6goy;sRHb} )ib.T\h@>n5Zw|2=͟ŹCg$+&htA30= K@-z~ Ps0M>0 }jV4`:%t"C72N'ISBc~=DmE#ɝCL@͟!Yr^pؐxdg II5Ϻjb=TI)R%6H}> Xv|Q%Xp" x[wWI$|1pVhc?[-4l3H{%젫!8ۯv3qf s7 9a+(J|L S:X 2/~+?}.ZSϘW>!`"क़E.&) t.SzƗNO"ϟ:' h[ z=ۼϷSjEccG$i8A?< _PV*%<(C [\<TBN/Ni9^aKjU)aTd&#mO^^{'"8?; sH˴X)t6:+3':0B4zKWmςB cjq~ )Fd?w˛_H30*̈́8d3Iy!W,Xr..YY/ϿzRY8ZZ84q{n^Gy:0驂aP hc^J:4izGn/KP8TX;n |}y'#%s3Z`4 [' QVi_"L9P.(+2؜etP ԃu޽6C? I#-b^Ln{we5P|oUz'ɝv+S;V"p !@ZY\pUB|aBv\%Sll5Dd(?f_)Zd,klrǠ*!쑄u%dD%;Ѹ5)޴J#޼nc2VAp#ĻTj! ;QY9=&IDK2|uXw>%C!Hk'lWs"3YFp!@9Iry%T0xV1g+4>3_\J+OI6*2A_hKq"Cu{2#Do \;ԭ)e뾵jK%ڲMgqd-ߑ }ҶKz~ruQxsl00;?fNo`ւ@[srSaGX Qv=D}ϵ] ?@J.cmڀK0:˚G J,RJg4XEF"MEK Nj[{;/$%xM㷢X) տvv #v#PPLv"<4$|[@e|y삙ysk!q%Bk09 6j~3LaBBҐg_&LvY|˟}A~Z<⢔yj &Z<{Ԣ`z?Go~2P%,5»4 z +*oW5ǥYyeQ3O>fj , N7 meS7}(Rބi2=i4RYU${2Ueĥ'?T%|[G5߃;_F}N 64r'FPieoIMiㅐٚL  ,d-N?#cۗ]Zg>siq%@EUc,Hp"ƉPMJ}/ztNXMo0\ -Hd}[`Bs葽k6wxp:x1vr0`NQ|~~} :Jsz[>u)CHNDU^FCG3Kt<>svSw?NYkf}*rIp7IBk94 b:;ޕI- M5ܹFyMA%L3r&:JGxM۷PCi:Pw_]u#蟟 ]wtkIF u Bj*-o&VQaaL=EJFI'W+;Mg;!,̟ 0twg n^uԅ>m/9戼o#%Y1C Rߙl16p(JSh[9m<2/ƍϪ}Dcb`Q 96ITu'˼OL#Un;I9㿋X$MKQDM$ȜP!- :E!z _;Y]l$a>4ll(~B!T060_SpBp%/r8+WE޹JaQ9e1} ͹2IYbu ܷ3KFwb. K!W]mYv$K6?еMDq!ռT᝔vtmW%v28]G4]]L`n࡙5 S iO>)pocg7eߢqE-Kf#ۻIޔ$@ۓn$YU'$i.GXn+'>5k)+<4m;S,ӄs %.DJi؄~HsJ$k&:^ ߸:7?ra3DDƵ(]lw3n kDd(֮k6S [=oۭ"ḃdq2wQZg'rՌᲤn`nGP^Pbj - ѿSD õN:΃tjc Jf9 ձОx8|?-#'vۍD(1FY,+!2 q^ ns+t![H޾o:9Z25@KY5iZ4b9jLG#xDW;4I659L &imtRm -;zH}z3[U@FIZg5=3V.K,suR+E_g_1te>ifXXTf50ķBfBD?#J*8q'ZuEAmxoypq$_`BzJQgnܼV2w$eIPʜa )' *m|";s:O-t,ֹ˜"OR*=q9'caØKYS/mגhժtAeJM͠`\'Ӄ<Ļ"udKӪ&9)eؒ*Ĝe8JKjMI! P+WGiˇU}Ub! Z(qT T9ʗ5%? "{EI Z#gP\%9DE|^ ("Y5x=7vj2_l~œs]$Z.7_cیU!S\E+AlnrJ|=T4\}jH5 H=r?`9r (P֫&B|6=:ublfz1 ņ.ZK!fƌ ZHle:@m:$lco ֐~B6 4-2M|sUO5h ^zT0gE i^$sW"ބi3ؗ}t8 ggZl_3=&۰@3NDLphOI'׫O]WJBpObJeD3^ d|t!Hil'uVSb:'E#l83ozq~X{ƥ\`ge )p.A9 Y\8VwMQ A#G+5cS^IXNCk _#~QÕAQ3bڬup';^Q=)iYXNvloax39u H*K؏}o>3Ĥwx`ie궬 KBօAPt݌yQlRjcZJ֔{XZI=!OR)yTݲ̧=g?|pCt 6V j\r=qwrM720f4G~!Nw1' &Q|߱Þ|_s] MS\uA |CZ7wwxe6J.TP^eӁ3{l8|?֘ԕ%J¼sc`lWptJC]mF8pSG9~0OibGWspζ`?+BN5Sp52 I{O`1hӪӬX3q_A]Ӊp4CCs쌪]pIb+;ND$z2Q3l,)1e v+Xu$6. m7l0>'a!E`2=K@qu.%*IuT"Nk 2 97W|f2&ߛW/Ef7$7'"$C>B$JIm}Δ(AH_w1;n`4!dce]5HYq=ukTmO78½mdyt"BCLaɞ`߰%T'*r&^h,e#I~CE }Gs!y: v|BK"T;EuEwKrvw}Ȉ5Mv*j!For%WyH-VJdJxABBqC*I&A6pw@x0hqQ>.ɤ\&Ww/!&ʵkkvٖJm/=sR}wη?A{ \1ڣ4+z0D YS^DN4.tO|n ĹF_' Hn-r?l΄v o{U/yK;K[nK.+ՎB%2׊nћUjgIM9i9P(lGBqs'fD*_2R#)dž@>SJ%pi'@J)ɰ'{<JGKU5ΒtYձDjhȤLbEd_^#"vނD'郂i݆սtu+4g& &1x H}2CrԃZ Ǎ³p)cڶ(b*Hzu$d|gm㷳 |84%-xlγQ/ھQ{إs |L+`pE3MkLw-][[w |ƺMҚ~s'9ZP#2'c{EBd\5nIٞ\k~T;ܣo}U憴Yu/D@|!΍H/8aVc&{,?H./%4LhO3JmFypn4 }4KRjeBMΆڰb tu3S'V`<])pg: AMl6B]Io%\PϚc"Β,Kۘk<lavG~X{iɠ)1{D8\ajরky 6- 6XdR-&{ k=idTl +&RRҔ> KˌT\) u0w1c8v<%ٙByνH؋X5cb﫵 ͥ#@Nn]DP}M"G q Ժ4o~]rq,H?x;`/{2 nn@19c^=.YV+/k`ʎ@sJA{g}5XUj9/ugze?<Ѡ$ j@ݯфUX}h~4j`'+6&O繱jwiXӊBj&m>9M.ρ3x9d DJ78]`scGЊm̯dd?d/ t*iѹ /nyau|҆=CM)2=NCpcΥC$!z** aycGcҸ icYb6r>.i)rx2$TMEbVNf7qܐ2!&?lRZ JSxC侫qPJ\c,9'ҷx tÒhx+oӓJ!ӆ@J}W@n0k eeR?b6բ_m:P[9\cLl\*kIB;J3l›FX\Љn0E U4U2AHXI?l9=o&Ϳצi/Д ;auAɭ2J%m9s ꍵC.Lsd .c2M#7Ckzdxĭ9b#m6{ڵ-tM 4nDGnU{:9ɢK`b> ]l莶g`-`芳aŗ[07Y JCgg1"P)pi/H6|Jt.uDՉՉ!}GQ%@Mxy !Fe٦FbD{G#IjH ĉY`c ]u; Pv߳nds-k/'㑄3LƸ.{i/f߬NY~}<|8_?B!Y' %85-X!aDԴH>dzbiG鄊]^ XG*<⪒fvT>qx*_w)3ޤh:^(8]XU0C'Dtfz_Ui*&(5iKBH8"9]K]7\#">"Űߡ;^*)|, QLrK+;c'GI^|KΞZH݆ct]?8bhg=a1A}U@}4, Ez-;"!/U4+Ig];8O 'Śa:J:XӮ?_zpMH jTAeemnsk"o!)Sճ?_e|[i; (l (ɇXu)hUhd^i3$ylUT!_ sjN0@6 2D/n/ sC"v"vث"k,k'ҥTJNQW0f+?*09ILbJnթ+U<5ll[tz1_\ο62>ihsΖ'"a:XSqV'֣b; Geo`ULMga#e3Ȧk^)C7%F<I,"#9*7c|J+z>z@O=SAl8қ\8ʛ&/^#E677lrˈ`^ ^d,z=6ծ]O)w 轖v4ie_}Xbӯ[X䣇zkuS0#@*!y*=n"v~<#xMTPs%ٌ 8u/9P.I4`EWil[,W}2-pj!=D8A" E/a [Hݢ}!'qCD?Cp\aXyEHM0RkV  sHM& "q+OPxV~?o"ٶG̔]%A`KtMEK~Dz pA8.FCb=Wn˽[S}[!}J1q$4 qn@9jl̟ͨN±N'4,X9y640E [FB[PV\j_H@K=Е/Kɢ(MrN} CA@Z* E' ЯEC5BtyݮfwZɘ"5N,k:QIrk4Aw4CQ/t'$V>5j* wBkw5"|Y X#mm} RHd z+PRY}9ot2W-~Isӷs5YgCP]+ĚOrGGshA9$pV/: DMt+#»Ldv7mQt&MnLzՃ?(?GC fߟjR1PUg֫5i5 䊎6FQfkq"Tr~CS.I 1ao`! (/bD%rDe.s7vW~>u~G8~SC%T mr¨o@"1,gXM?d7sk4#G=h+@w8c2VNA]6UڛRYSnXBFz 66[:<62pځɿhʹvtc!_$I$lICU5mwnQrs19b4Z*ߧnua\<6jS^[l7գlOW;ao B@FCнȂmsUMEVϠ>M"JeiIg~PFg8Ad5c$+y= ϯjzu=n'U'i%%o̖ƫ1#(=1YIz&od)KL/s##"Ā1ث;I&PB P[*Qx`@E!kJ؂P<LUퟨ1_ی& M\E''i嬾uCUj%1$S.3fdM|:IrZ_:]\sUeˢե`Ch0;CJ7ϻ;"DMsp;3X8U=\Ri&i=mi[urCܠ:yfQ=RljhFȔS8 >~1{T^gOuhQMڨ|7h D`t+@%vs%'0Eͨ/9ioT~u޹kʴc%3vE;)WŲ#` @kBu< ?mri7ftVieO;x0 >l]_)TvD1=/COrA /BR0oa "hxRCwX9%6&;);zHMX:xV3F@`CZH k$ ԍ䱔N.!\\*K$*/3DsȐPWhvR/яr@ (HreRa[=fqo^ A!zª|nLH |g`&~Bm*Õ3& }z<νUX$Y6XYMOH|-_=+Vя_8h Kn7S&\ކ >ʹOb_'%DiҞ[}zQcA95w]ݳNrKCGUK%BVuC&{W.yHJ >5G?D>(tsD&oA"{/} 2L~t\JrvøRx̪ 3k}~HH4 ;RWy^?P.>#5aznJf /]B_PȔfڮ5Z$Hh //jXf_n]ޡ! 7>,RnZn}@۳?ըP0?gmG7kzWg>>%ur/tH&BkO?RiPBTc"H%X̯f w?!,)9hY.Kx0[疁q sR_ V" #=[)~R߄Ue{i-l;xbԢd z]shHk5v=h;Kp'nd Ĵ JTu 9lJ"69Ϭ֦4&)R%E<7CKON۱E~8 4qPQ\NgQ%8&J[gldc2T8k06e G7A20cjU6z'0JϏ5L;#}A?dFI6D`Riڈ^j~Ʀ|c! w>ӌB`գ0,x' cCT/@py7~L*0eڟy ֤#c>c 9Q Ǵo˕  Q);qa_q7L``*AB)/H75s|,? d8 ѱemhHeA-,;0MG2:+~Ѓ`7ة f!`&̮͕O$B +$4r βvH"pfN,~\м__~ZP&LidJb/P U`E>h|tS'/Quɽ>.VRQs7?!Ӧ1?sWsǏ:G}H/៯ޙ/$(hڔBɂTɅ;׻[$e>e;TZe/|n҇L (3kHӅd6.;(/ZKt>K E(8,_~țg[N{'Q\3`LGq}8X,aG󚤕tsFhHGȺ* 8M +a}K7 l[q87\dJO I Vxmy Gg*tK!d/-Ne'g4iM510²x *Ѕp0ݩEm9>Z$]'#WAi()q&`Ґy_rߛN5A2Df"BUlZ]Ur  5x3Ζt8JVF+ivu\Łp bV¨!*PՖct 'nwʊ7? $)e賜~\G8y&LN\]k3^֡Ќ/!|/3نhYҥ: }j5 Q<'E:ѝ 19t+~,NAWNxL}cSr]\~ @wՊ(-E?=kW-C^)3+VQT( |g8 k5{z;%$?)?UMb̪0̡I_F0hq\t,#̺^່sP4XaIu S=>!ٹnC&s QpDyDKP6!9LjUVǙfSonXh,y9GI},@K>ғ^Hᢤ;Qb_%G*vRP'McKbU F\%7)G/&AYYph!cqTӟ@/*嚗i"ˊUi %XYިD+%Q XV?hs|_Kv'Я̢ZX,^?qa癃퇱 6E6jeĶ0Y8dyd!J0 !}Я6UdBg!nt[42bs[|t'.MSUt?wAZ&OL2 &_ϸm5XmPЂʺ8rez} kO?%r V aV c>U8e}=)`\"-k8j Ɨ [^# \|";φb+&5;:}v=tYB"塃 ̟wK 'HShھک|ԬӡE-3A~b Y'gI3|\k^t+\ &?~Jչթ>JbRHse5Cw>rMWDRF.< AY-]O!'Zm=␶_R 4uP~EsTӱI;(*EƐSP[ϹPd~ckmZ)p9~mo"H$^PY;4ǽ+y\'dC 舝LǕTZ6ilM)z @[ZT7yv#YSH㸭Sqyzs ȋB4cz#YF4̠,}_5wvT5ҫN t`y۶OZ/IrK =P4sҫh;i!e}5uT$)yNF<7!E4yfRJ.)H{isyC~YbZ ż@vN,BX8P]~|a9Xo w_2/#={( F|uFZ@ϵ\FXTdw;:eH=m)m'w@E4P,ͅ4^pS䎩G8v\%#CM:D42>&^$p}:>(f ^gذw){:xjMC<>N>GiI?Y`$6]L}v]ƫhz~8tgY@SML:$bt(:N!(F,ĽD6r'5;&9Fm )v'&$x_),' rDHM&L" ĥ_k!cfFM>&d@Ǫ%IL%o@Fii$TQ=\2XI1zW9_jFOm6"CҶQ9A '?!`% _$Zy3~. Igp,d CWk0I`OLys4^?·8$_@2E):Sj ; ?IzIzʢ씐Q)q_ҿY;㫯@Q6L8N9_\+we-j5]40YTj{/XQ3uݦһʝ@ ^'MJl&D[o̍Ä-ޤc]v-i Bpzcպ 1ȁYn?^VO=ZLXcL7@rZ4 : Lv yu[rLK/7v[-s#?öYë!Ki솈ku |^4\;k{ӳٝN44C_p`i]E!%Ңkջ.S4qE iۭqHϤ_9D.tRU[NmmYTS SÝǠzn_elzo3ڍARޤzKƠ*R( WrvQGA{u#`E/>Msy5K?)~X;,%8>--|Eq٢LqaY#+aՙ3  ,`rĉ9ٖ^P7fJ !g4OhUB:B]kn-Jnƙ-rɦa{MU_$Kd tA#Z(ox~7_7?$pTc.) zDۆUXU…g JPKbtJ`֠|^'/-Tp]}LI]ViЈ~W' n798uG.w寗T w) G= w]9o:ʘjr0ȵ˳Cv2kB$*^7wN+x,O]*9-5 s;4d!4*Vcu>c_4fՇ &',/}Y,^]: ubthŕ_s'4Ei6 ,Ȟ#'ܾ(N^"NF{Pn!sq O=vr0p3#Z+HYՅ%$I%d ɏ)YCȥ2=7AL"BaښdneH-ҹ34ŊGa)OijrhR9{@b_vObH@(R][\_ٓ\+nspUXf(D*2{fO66~ܗ6]#JA[EAa.ؖ%rNI~ =>L58cJ\hsoUΌf ![3N.ϤZfЏ<fG }2U՘|C<]HG5=AqZWt<K4lLC H+pŚ}mEZ3w BfbNlV02qS=7u*6M`Ijfy']G`~J K@Kzõ> UDV69=>?0T M"ތdžQMF`'w^H"By\XpjW@χ3<=Brvf^q8\<{5QmdİEKv|MsjWL$&[HC>8`#;Ŵà>޻!Wj+8'Ҷpѣ0.6Ov<k:uO"P8lqy DADɔ&?kSLS# x 'T:99_>y>?ϯ\Ao?$k[\3q&0ިyvN $pV&?|a7οFH$1)LG9~vz5Swɹ qZEL{Ebp -{l%a^@=^M;O JІ+'^*Ɔz~G²Eɡhwx Q@B-4߃czWi&Żbgo6NUc<;\ >$H7N݌="0s" 3(gtۊWV~wH((5}[6uEޕ* yS,i5d3M5'78`12m<88OY3g+iV^W$T4`/]d ^tom-µ+aUX/*حRQdT "= z-x՟ ete-81]wYvعPBĻ*Nhi>7>b'ᱦ9 ;`y$-͋8{@QѮ=3c= 'WDP(?]yX%3zXq e)[J5#3̜ g.%gV0z?XѼH^q3dX]-= bH0[ObפcGn i/+@IKI Agl1{SS.O\4NgƇ=g1kR_DC͍.sc Hª ;yĖġq3!5=ݏ0-ҏ48}t`;Yw`J]6gkς bt^N5-QU{+*1>}SЁMJ2a=lhyx <Ղ&fy~:`LOj۟=y ]Tw @!,`5R83L$:oFD4inğ o" a֛%f?ĶAR#lɐu|.]XԤ lvR<껤 QIHڌfaaǶ$~ϋ[]դ̅3TY,v"LsX8J 7 ; X0@'XlԞYh+.NE浿kE͞ MUZ|cbJEJ>/_[m @U".&o&^} k?oq^#QH~ИEl_HؿZ" bq !d9[&F{^n~3+@{zsENZWg^1/g˒TCHRPçOels%иSDl4!X0{Bi45m6FsB?n?(1J^~VW壠U_R7.0.\1^+1$+Y.bnz,iQ=ZE1dYCBonGǷ 49pfiD#fv3&"~z f`/kv j2A6~ğ@͆u?x3΄8:ցdʞ`en~-`xfi5ۨ+ >f G1jZcVNH9g!\ZxI#Z-J{@y݉T[MLac_XlǛ0O#UJ-oZAmZ)D WO7Xw'4z}lW5v=)iVϻ l=ÊcB?Rۉ+{ekX)'95wQt@,Ȩ%}w1J_3l$NMxpQ,w(Op/b)]*$BF JYF2%pmkºAkoU*Vh\zU`jXp7idijB!W35n.XNn|J>[.rbapX.e9ffx5~[?־.^I"2 FcgtyzP%͈J ]ƹf 8>OH} q̯a#qЮS<˗]qݪ$R0E B6 PAgHkUiYG/hrn!|eݠ539*ZTbB&W>4w`kC߾-wЎCPRFbFYV/L_+f@]T|e[⏎t؂jg؇bU|%MgXͦ]j&䔏|lM? . U{s~ڌ2FJd^<={ e%N^' ygICOFY ŲAM %fk`EG[,t}2h+,A<`|&6Cܒ2fv,*g~tj>5t!Te]VZomB{#KUy+mX}+A(3S &iC@}8?="F-kT bB_i/Zt&eXǘ*} ?sH:~lK Z&=wW>E- %6:L@y EᗀxC!2%pWKC2:h$`G"H4<'A7A)E> N@= ȟGKPD_}RQܞ4'y5-#tO$:Z~xaA$dgEKug[cq?w=N#RV; YG-f4Eo_cCV(&"Y_*P i]ON  2yB UY28X܆KsJ&)mn 1nv*pżemm-hߌ6G1j.H5q%EVbDLWXLB_р*axsBb哼WݛkW!Ft.ʬF OyL .pؿs+5:<nտV)ܚ^Gو.ЪQLIA4S[i{\ߦe%4}w jxerGŝq ػh31WD!.Nw$0:`ﱜjI4.KoU4DЭ R=  Iu)4/H, z J Ht:p77dt]{"o_) 9z#iIiK7Dô[ԥh_P~d-;BK0K<'*i6hV iw8&"*S>U?Bw" C]*xVZɴ%KkSdXf_N0)!(= _Kt/bxgj?\—/&sh8 ^yM1w^o^`_A11 U>2>/x a~3l qUh1^Vc 12#,rW#=z-9˦^s(_gׁg壾sc52_b% ٲAɋ~n $ʦnmdRڃv %Jbu"Jh =gdCxA K$?vLm9 .L-Љ5qaՐ@ٛL B?,)]xM&]>Y}ǬP*1 >4MgPb0 s ܅L !Kc%Z3,zXף/LCWy||,?ڑq_mĴj{x2l~}SD90SWR〡d̂Nq7Rm7,90OxF#OjJ=Ug0T825gx>(isSFЊR2r_~ᶱT"3&GKŠҥgwպ'{dp ɇD+#mc)sWMʔS*z4# .iMw(2p" ,~YokyٽkX0wS1;׷l[^nb W8$ٺ2 6y;BubPޕKx"/Ch6u4 ltOB a{@; f4; Z9ڮēBGgH~›Ew ̒Ouzb`1XJ-8 ̏?O7zi@{?2j]}9axB|)8 @!#ZZ`n-ΉKf%fC?0V/5X:SB%] ~ɺ2jy4&9μ*R˩̶ޟoGǖ Vܦ-5.㖾P.ځe)YG v>)D'Uo 5*VDbh@teϨpP8)P?GtsBVk-dR>{H#O!_7ť7n$5z4rucOY?U52D.IvK =AmF=DV}8z#פJ ڰQco d]ڇ۴E(Įü"8*啥l}5C|9΃^Dյ9⢬OnFF;%`viҬw@;dAs7yCj#7uPÄ}a{5^sD#+ ?Ǐ2/>O|.s[CO3ta1H}h'=S H'E{Q X?x:)eԒڰmq3oXRu,p4RTN{޺80j3Iׅ,[^|(dqͱ5꣘KTr@C( `V$͏X iE@0t= }h{ɷ օ]Y̗8$|?x9 1L_,9fvsLPӢ+_&;6xeJ\L.L]?w֊c(_2_员C寓;&Q:'36*IYqqlo> IJcͨ x3&{;x\ oߏ7DXr/,9S:3PYZk:gF .?Gx֩ R|0aO ?SmE1Ir {a)zx|:+f5cm#) 1ji7O/Է\ |Jc]bpVڗfO3k,2JS$)rGopRXL0<ו61cD~X6E@DFfۯzMШ95#W*%/>H&+LV،/HgƑ]=_& z!By~xGQDZ\ DfESU.&cbFx l B5G{]9 - ߪF!R.bmj`8z} ҉,fcve̱d~l^K *5} #jl`G d)o:5.oށnR^3 ?KY5&!#5Nsl \1M<lh XB&,h%9}Y⹤Gd)'^M@t f.16+x'e=b}\YQCeey,X륦K\g diY2IM48`Cyh`kL.ɹvXח2駽$:wOi*FF( *Ki>&*Kw$˲adظ2vh|JgqFR7t + 3sy_5k} UuSۇeSxr6ˋdlg+z C؝XPxZ)/⣚7` 2' H9ݗQv@.}뗼'UA' & 5x&-H]P4WO>sfsÙЍ&y ȳԯN |T;؍r\ сƀQ)E)7 zz;^fH\|UzY60fp5"T>*ԑ;MCã ԟWʭ@6R֯_e·y[se~?@(0%_; _`BtCƯAl OA#&vcR;90fI^{}@ZZߵ`X,?3E;ݥ' K,t*X 8A"XP^Z8,}!y*:^,UH. Fa] }|DP0OPQ }yㅷDFw'3EFQzW}֤gF扤P\XV6́O݈0e,BOd$:<`ɭE`,O)/"s(2c(UJr 6ߘ~va}nr]Nݩ$EV.c}ZM@WwQx .}pW'jؔ`%rwpQ#ft"HAi|?b?iN9>3Gpp:fю鿨}T zGƢ`CvX'خWo_ʊ˷h Κ'3/88QnuZ?8z kd>FKoKGac jXzDBDfx"|ar)"P#ƅ"Z. hߓj-ڀ쪛ާg2͡#jlͤ% o(_P ir,>%yfqfTS֪ҥUMb9dh`wX> a=~s@R+PLI`}rيt43 D@Q)ZeD!g1vpY!9{`(G0W]S$8TŋѝBt-lBȰJ `~‹Tao,2DL%*zi|s r^by-Kv߰ҩ^5ǥB@_jZ*N6/6>K!ӼAUP FJB3މߺ>5U@mY){ T"88FdX\_8t<7cN)v$!]9іGj>l8)_mNom\~ ^*>互\] <T?z~ARb +d,63!>kPxj7BX`݉G(Ah*.r--=Y`ֹд&cu*5C9Z'ltln,oNe%b=PHI8zv\:^emkj0cBYbl~^0TɳT?[xېy‡AQE1l{F=ʗXv^q7Xz\'> |2|>(kF4bJiP48f~,ڢqF钩`q OJWG&HGC{n!/@ hLbzP @s:@1:bkuM⹥Q`E Nyi<joj ͨ 5(-gS_bh !Frkb-D7=g[0:w% W31x!ph(lzouitE2td{'. `V3<}kC/Gl`_W bmit0xTGbhxMH@c󍤖 uHM*Qpº6I${(3ɤcw`;VKn/q} hr|GPZj5a[EX@a$NxQ$U([P,GM%Qªඑ>MސYt ^]zdr*@+ϊYyrh rCˁ=ρ{Jkltj 7Jw KClp"3q}_휙~=ˍLƬukdηf'#a6kӳ$ж~]jX4=dPOm\`x{0Pێ?+ lz2̘U"_$n[ZF[jEҞUhIcNVHU͝LUC틍B,$*&df*]atnA}}B3ֽ0Q$t<+=7}iBa j*=7*+o4Ig38 eP¸F~W;rflQ飧0tm8`(1 =_t0^6bjn0Q|uYލeg`Y?ǤB+l 7 n7p*?\uR!ZIOȕ.VY0nbg,dwj9(q=gI;<&۝tLV1*QfKk |dWFўy7n;Q - I} V/qB t2򩧵U%"o>e(hs`ֲ?>{ܔn=]@k OP{溪|wkOGe y-3 E/ 27>K;βOYp(qDZF˵aux-CjBNq001 H,Y4,<~ҥ~Cs +ȍAuE&nͤ+зtN <> jjt!_ }ùm Rwكnnc+`DN#YPR&2L%|rNATUگeO)а6ufb? BNk,V40[[g1Ď*xCrj'+A\YLsQ aJR)c i-$ˈ=[Me-ҡx}8gbEZDUl$7 l'"~Wa%$򻺲!}R2@-Fi fp+P*2S/Mq}CìOz1 R*sc&}sjP7Aʊ U1a ﲫ|2 cR$b'bVz\)0vsDХ+O* hKoʆWbK+4m2j864DKX&q?9Ҟttu6shd4N'551dDx[ c Q1/sZ=׵0xu!7u4\>ػ`ֶk>bz o8jP[$D!2\WD+F5hq-j&7Q5'y$9qvK;8oL|1.%NDqz@1Gp+'Ѿ aۘ5cC4%~3@X;AOIΓ{ҳ@%q$0CJ x9- l=M>w)/d3%A&X%'&+JBY(TwO+coSyCH, `ynܪL9g8nYiǭ91YW;u@+&RW_1iL IOEߕA_с?Qh!@gC`981 Ds7r ;n=2̏ci[,xzt h̩HaDmr"KO{_G=O,}叮.>>'}-\.{R_{Onwo5h =^R T~9{J)JeqyS }tTe-zP2;2YjzY jAlU'> ]֘!?RDB&8&o{@IC^ |P"O(Ot&~kdS۔]9BMI“=po.;5;YDFkY &N>xF1r`ʤF.J)8 ]7MXB8b7h8!S3ycp; #ZHtv4zrǎ~<ȁWH1UM]Jzb"> ǪNhxpLҠpȋvDM$x1w͟n1覫ˬae"3-.M{U3oi|,Q>="+zo4i7ʇɱl'rnX*JV@s. A7W)^ZBjW:vL\r8 & PC""}qG m0ۇ/>Eםd5ўJ2mxʤ鍯ծij.~zs6HgŐ& /9S ?^@ ,9 C^)\y^ִ…G1%`2ArG@ij{qA+%-n K\:Kw*!|ɔν'0&"aʫnZx %JTy8#QSZGCOaҵ0}LPF5ķ\Fp.Г騂54oG+EXؼ9p=u틅C)Ϸk k*}^^\g,HoK-gmqcHdd"+"pـݜ72ՠ/__x~*uPfGJSdԬ2b=hYC5}4EgY$*չ#BZGaMI0.xW̿QP`Uޯ6P+KJz`}2:]G&0#IyB[Q ɛTH9,n&%X4jUtm LT@ D8%hzVYRxW6卆mĩHM,ߟ?@w+,,)EP]{tr@(*nFYR7w QGN1j4r`;\mEY OQgIB0~{oNb=Er-TNx 0Vi)4x4e!JL(&+Kmό8FlI3R!D-0LX;qY|[8xVښ3C-o1!סǽc-X&ќW$,5im=ŵi#j g&NrJܙ}v]э7:gMhxceމtF >q%WmF-KkEg-{hO{h,lHа%W~5!XgLR(/`(}l,ջ6rbz??$ЇhQS!Kbۄ̈k0XͨH8-(悩bBl;~#/U'8cJ]cSc0>`;+ S]XgdW19Zos.|#w9.˕ 1>83 e%c(\坄'l`և"WIMPꃊ+}ھF9 #̈́5 Aj}6Nq3Z貰Q 3#a5 mn+^=8U5wMl%kEJK0r# Yk.S( JO!0˽KGpoqƚԍn ya%B7 (2z]g;=#}?jөE=Jv\@\(d^ #)Kv[Ne̎ʩ!G.?㣑5&c٠SHCl 侶/ ᱼ:0 4suTz?"yZMGN]1])<{ظQD*( 04LG "NTXzRyZI%A17*1|m f{ɽ42 cCYa.:mƔhJ wƑK9peR>7*w\m;-#RPNmaG)ޭg"gJi&dH`۾%WZBmozcױoτs0cy;?$]!;9~S0*PUUEϪtjbb]Il05Y8q}ً@Q#D¤]hS)9BbVSMMH˘%Uk*bIml8_0qbcִ_CTnf|cg5S@4n|քtj]希+aeЌ02XQ F8pf63K*n/xNE7]պv3ENT4VM* FdHh+o&Ͱ$ڑ U_@z G%CҠ3n:Tfd@X I*}z&bXUi_CS)%DKުڗcDAUrEp1zsAa܀*yN4FuOF"1r밢 +tN$`S2#Am%Vi~lZA $>$ E^Bĺ@4lUB yjb;@f\[\4{5xoeShV1lDw%S$ZA8!f;ѳI 9 }#\'{r. D?>5?$*{oï932D6Y0/`/!x~WJ~:,:^rG *Ghl.] LXRf5 .d~̷*!JL,tɖA$># Za>/\K:M6BSO?/$U&@%&P^:5S3χ!/1achJe-%`J`[BG].rՁ>bmp͙i?CG nTFc<_ ܀M#Ne4Ѯg/ " X&l\ڶXS>B4Ϯ!5 J”cOk6}St$!jJHmш_킹ܙƓmy4a6r^l.Xd['+"C_,b(TxUYL[w^%^=Xb"7{\B;+XӠ:ǩ2F4%em64;fwB/X =~U{ ?7na;i$f36DmCYPn%=:}hBr߫O#7?B:L l詥1-Eǫ79AhaXD!6'MǬYSE+Ց6gn柛GOoZa.kC+lyZC7g{TPgŹ߿<42fBȯqavH$4ѷ 1)Õ PaJ*z:sZbꙋ:a"@͸NH}*ܙyS#cŗK[;.Dd++fҐSi~3;.~a^2&pr}=Ya5@F-JqtEYڿ, Tm2$ZFߞA&Qʱ"]9g$l̰dK=[eày Mv<1\Kg@ jXU0 TRVHUyѯR3.jeƇц=I?>K1>n~|ۆդ%Ό4 24S+|O'i *NwXp2 (G#< &!XZlA҈|e/,y1^2`u΄J_g_:hk/zHv~[/S\G!H5S֯W(7rI$;LM)?|ܻ}{@T&2a ?~Gi:r}꺹Ұ 75׳Oh_4GL+]?kY+pțkKH ЏSn~ɠ 4vCe= Tl$a 1,ނˊD -d,rJ̏x栂(bə&a{zoW=IXNU4)hI^gRdI|GJ Q&[s;Q 岦bĒ#u5wf0M,eGkZ+'Q I횗BL.|n<fWo4f;\ahx.Wq#;8v\N":F iENx@g5giBmW/~<GUK(t*M!&ĸ5B݃lߌ'5)O&*xOi uYYx4gHMQ,؞/-HrpǑb<H 吽~F}"ːKq+υʥ4ɏ'js춛ɳMvZ.Xya3 E՟:5;& ALBxJ<ǟ DBGc=@y0v4Ku&ДnH %Nafݴ4*F'p\fz'8ng[tw(da,IjE*7cŨrӮ u.C8/*yZɗܪMUMm4eU3-+{>NRp9yД2_]B:Qɑ6=cp0/Y7i/]W垁 g154IbGJ%H|y}wUr$KrEL6Wfy]BlP >PEhSˇOyO.typ6򻩫P+#CE,hb<6цwgl=SN @Y8̴\aߢrG6 m%tix]8('6f8@7'R˓Vy`~:Nx& hqp@96٣-:" i_d´ej&TGMA5v"E*6seHErF|>u[$"f-(3f,r. 6~vvj?h6ÑbG6O?'1 OUXBSs2FyI7ENH~t,2;5愝-*"z&͹~cizgBPL$%(Hxk$J⻼c(Ш-͈( EUnli,cTg0eHZVJ Շ{Z;>mI; V}R .}8Rju%1І{ h**x:a hKQ5u)V fq:s44n zs+mueYMn5M<|}>u8gql~FWh^M6M 7_Vel3݉\XPyCzJn0tsܕzuK+V' 7*=, yT}ZV=?P )ݻ_F('ANOHZoQvC`1䶺# *S|F76)ZΎ)o_K rC]etҡyw3jWs&#ZlvTG Rߣry}}`_5q}PpSjӂO7BhIص%pOd RU@undW)EoDu 8IJYS=r)ٚ"># '`at!(/8ُΞ>y^*,DGi͝$`L3bEu GK#B$@J;rL&$2V:q*3:,au`*1QO)) -w_Veǒ{2- ~ 6W_) n і'XJʣ\_ eLM Ntpԣ -M 7x2<-= \.V&aA#hHUE􇻌:wLx`y=o^ T$FPK|Mn5Ѽ aWشۊ5ICpG TeJ|rUJd`֭oÆ|᧎l+m0-u^p9 J7pRMlW#wOFpCbÅX*Q6,wԏf͚DnK+W=BPK 5MNBt0۱%Oq~5Wj2eg/*o#¡#Gz حfr}?/@$4Fa37鮶ERl ~aypo˹{_$~BR4-k`QR+YX6ͨ,!<wd("v"Q\jpyKb3U@*IJWt b71gnv `k"3EĨM*%@ggN2MY=rirǶNc$C[-FD"7gz8RINI52>3{#GGL}akaNjd%K R Ϟ5i0=oӊ1glwi`G??E@%m$pE /* Kx[y wQ~p TLq,./VWƚ&R,d\UbJHx‹>Y 7bQ%rcdhr_hƌV !e%V3꒚ s&l𥊥Vմ%q 8c͕ɰF v&E>h5Za5^^O/?b "Ts %2>Qh0p.0ѶbiZEfO9? ֻ~v5[t!]d27}br2?>wn``>T5q6ja^oBD+TNe1Zw'{{ئLadQl؋R\Ƃ JR2m.cNy%FM9A>j (Wg&%rjY4ڔ|//vk0b 3V{m6^\=?Y *b=މϖwurI0 IY5:dݐYMyh 0^B߽Ngt1g>{d Mu~Hhu=CT-灳7G##T߃IC䠊EK?>^*A^L{92[GYIxXk^9)`/RwҤA1mV@ Z;"R`T 'DF5M&hi+"t@!g鉡Dj8wUi\@ǥaK笗/#"ߕ)[בήV"N6iUC Ů1^s g\θmSQvٺ7a*2.TKS_;3K*@O_`4bm_Z'vQ1~NKqoc `.ӞNۃ/C; 8Bl7PVٵ6Ȩ`\->>N_Ȧ'#E԰-'a@`JX#-MF~gO >oOVX'^D uS6q\tv>1~bhI8\a*\J*N/.@ -dɓo4b%C+$++ݴD2ݘ~ jIʋLU(@UÈTy[g9>&BLkׯQP~CƋJxuۊƲ[Ӣji1a҃/X>%,DXnȨ2ఠ`Mm5YgkObsrxFH Hxv|&Wg;婥/ K )[l_7O8G\=6FLOŻ+T _U]+!{y5ֿ[_J Kvﭒ5W,!9V/@]\`jq*"^[QH%L`Q40S%Nì2ݓ{fS4"\8;3<r\Ȟ5@]۲ oVV_Z%!@=X&kөt0I qDP21Հ z}1 JZ3:."ۀ.d.z1[wx*s@r}#΢d ]G5HJ:?8m&GQ\52#%7Ȏ'=o[kxG4xC=-%/$>"DS6l*eCdO-1zNLӠn#aU)7X^SBc2g7%F]"wRI!x09h^YGYU7(>+:"Zߙ⟇$y-> YgQj%·h$eZ_*#*#\C\gUO5e pX]4\eW1C;hy4I{^($劻|>(rsBMj;=uVr\*M( [iȴ~O=J*B/iY̧m PΓ#, \tXnA:Xxb&׬8Z&:w;O*E[(}G]Ql[ O|c$TVJ~2 -iQ)}!lABq  r&'%9ܲDCLxL #Obn/!ZNgh)DqsQƃ40(^A Ey-9ȑ7׿*r =xhB@oV2 ~^ԈW:9ɺlT.u5)Hpi[zs$HW+v1ΔR9N7rR95OJe# Ƣ, Q"s鮆d2 w]ëUMG5pm顫.gz݆?][<g5wOm!.EAQ4_ ih=릯LvW_:ZJfkCW,()eiboW%̓l}_|iIz[gsi{=[hT4G  Xe^^u _vIrM{7jpF\pY ~<' DXHnqTSt WcyȾb  ib}0a@L\<6'1v?&d%=X>b6} qĹ|{2S>2fh"8\VIpse{14+ׄEyd+k*rLы^ *佑 exeI}u|`)W [Έ$+R*=y6"=a1I&ypbYU # ]n*+T+S]yv5Ajq)u(ϧvCi1VS/uU݀UDV`5q@ol޷"rV>/`'2z3|厗b{"-Q2>RĿbG5݃Bo`,%"1qp'!tl9\3J1]Y0 Hxhp=ýx밧E9viP@rjg%T?UpmtN C@hSP6fV*O^ַa&qEQ&?Η}UȪ&svH U 8[|}&k6XX&M+g;7T1g5@'5x} zg-^Ū]=YT\m8Bל%o192 +{.n!#/kɽTםZ5icSOCKV96Pq>l~%Nmv^>{G%r L4w 9O;%|xSm@=~Pxpyu#l?+MЌCAw׷x|+'eti۳!2f;_|][TxȼO6JVVd|5İV-&RŃd-_kߛbq2ҕۢ $ؿ{J&,a*ҊɅ 4aԘ_?ŎyTP DE[,J jCy.RHdAhv==Aށ\bK49"sU<`^ff,"ʋ+I.Ď|=#TfO _: $Q]2cЧ6ҮǺrF>C 6.N*ֿph3*9`Y^l*9uq}kQFnd8?J$)#քa5(ҝ'`o=l^ L?RNqihoNyd dA3ӓ)H+qy%q2_84ÅXәg0cjC?, Wm8N[+U> ?C^I&D MB㔖N<;>@WeBa Z._O;0lh\h|qzGkUPR!CɆLz͐bPcAAނ7mf z0Ls0v ˋ` {`@HĿLZ8mKn)zrίG hr1XP! q6 6kLb_uT/̝]eK Zz0rIoK7 "ZJ"hiofz#% Ùƣ>T$i ԁK>A\9!iJ)U[Fq&(ݢ^ f'al񶑻- Xe{VE[ nn<}Әzetc(AHфxhe`/On-`wo0$9߰<ާ#+@-u~e *1yv!] eY;_Κe| mt/l(>T'u,cm#C^8Gn>{>A$sqOd7iF1j Oj "&,  L Hd ()B3)hk+j'[WsJJy=qkzXkqw,i,4d=!D//c/kT,0:h4vIC }6=fKHn+ =^OyuC,xk>$n/{,;G QPcҐP[00?. jOR[,8kElHM1p>G_w"pJ\{V< O~X{MȘkʯ.ŤXSG@|:jn1'k5ӈA4Y] &Uii*V}2+eSzbp,bJ]GM;UxĩuEnCيJǞۓDKTe"ثž'_gږ~}m߳p9+2:8W2Apjeq8yp踁8^1aւ48<ջ;_!:@/`k7&`ڹv4#)`(o 1ʷ 'TN1X}3춠EH+p;nwaDCwPnu . }iݝ¿jپe& e A|#9oZ<4&jΒ SAVN)~ J)zCM:k-q_b{ ͱXtJ[I7>tu=V*WE6_;b{ i9XymH=J ].e-nҟ, &}a dW~~ZfEx :Tc+^_ԧ`@9%%D+me>dL~-94yFMgӅk>JG.׍ʢ_dԙfo/",`uoգrp5nkR P VG0 m C(owC0YiD.ϗW>B\ܫOuUm!&.%^*Or%DXK=IpbRXnhLrK{& bg:Kt n*J?VO\7$t){|&C6ρhSxR2Ĩ[Ej5ZUl%+!%PRU82s` M;-Zz62LV \dA왃 I[hE2Bp6 hC(\7TsvRe12°O0>*x0S@eTUg9zm=<Q{ZWV'*X=HC YRԷG$Շ)c>߈)^?D.K!~z0]{"GZ<;:M\m;sXddQX<ܒݯH,T7AҿHfNR4!u`*V-  Y> ʍ5 u{% ~7×¹bë&O-_seʿp>Sn.Q8``bH@׳})xوsX!6)ƍ0r`hv$ѷ;] fnڂȠ7~Җb}cAn#n;C=.-1\4?S+ă/R>0c7 p/+?|7ɩ)5BWP(ʛ W/ɽ|g`s9㛯6!#nATn4׆h ;}+㾦Y9!de`E:N¨4# O-Upjwm> 6bDSKx3r, ~c,JQc҇FG|^Uo-{]Y-1|?W$[w#68i/OIh].4hC{Ϗl05S2-3@[D8"ֽ?)#'iuXy0WލY$0;Ox:0hU&̈(տc˚7 ] pdD3=q|L!,$Xޟ+~Xz+ @yIsF@ゖ=Ш 7P,bvh}H8$yUkD﫳_vՉ(fWiF=HT dm-j~.{lU!"*'~ya+?y7)"mQx>am(Sz6?U; r`<1a6)AulZLjxnx[ǜMn"Iz8"HmylȟISI|' > \sgaSS1|pt;?ikL[g[ٽ# lַF O9tEY:6IU' uXF$o!Eq`dNz?-ѣ<ui7ޗ }E^kVv7Q&+Fd&Qh()إ & OZ $SffJ\J\LԽ5 '&Y| dx#G2Yh%Cp4a>D1ЗdR鐋C݅~{.orݘ.F LW;;ƖWA; m %!ʣSrv%0)u$,׃X! ds5]keiE/~ِJ㤋2[TA#{>tL[aq?A=4X>܃MNIa6h€ ~jTK&7JBTXU2ԗ8 mRrteϫT`c7n>&;T2St:Wsl#eJ~Dv[zCzСNr"Yص_e)۾u*8l/xA:Y?<|튀U - 0C̔L/g򰌼@;s>#U􊚑x˭ dg-}69( /sr)#B!#?dx>1}eՠd*ǂV++wED/33j*z:DRf }Y̆%Tb3:7RVƂ$"c7C$e4oDp:40 ̯ע $>G wR;)t폏jFwR:T{O OҮ#.<< x̝ zf.ĮV q.\ aeahm8K#g֠fuxYxQ,U+WéEO.ݸ, F`{aOq1/f(sHQjF@`#tj:Bhצ[/hkTevuAA@pы ^eɥT{%_,2R"$3߭G*YCA+m+h`,?ȩa%/Ny_́m&h-*݆Q4`GH/S{ 2z?:Bi1v? vXWʣDO4o(?Q9*ORB󍭻e6վf;D,:l2fb q`8!&7 N[amzc/П.I7*. cES)n,g7*eG~o@({Ap ]gFQ1jdhh Ȣ{d0+ ŅK4.w.3F(tM[n r#Ȼ}}@9 0X V5/jw֊1^G V(.( XN6:gvDv P)-CTR2̐BLw 6Tq~'_ H.d$Gcq}fФ ᣛT\ AHCɌZ I A#59`j$@6݀LAkF1s턓WX!"f-\{ aiAn]/Թ~:!@1!"꾂~Zfb"J)T[9 yf4q,aQ48w%r>mםɥ[ `ꗁţΊ(K'<u`>@u3X΀6" 73G┘ +7nse6 9HSNƫ68|٘ sZBVs CPPv.7ZP F%0X!dS&~qwDF Y]P҄\HֲMĵ;omOL42~U'fbD`9jB,ܰ>*^:@ik {T-S7gu.'k$#SWϟM!k:[s_u!Oޅ`͉X*,6|A"~La)\{v0czHWNJQ\ќT\!@[`eE5rS u6\-r'3F˩Pz %E"wܕr%Ɓ*@.Kꐭx%O_åD&6:gUDL؞ A|dnm/6z$y?P ~MV:1E/v"dd**$ ?BQ5d;υ}ߩ4@۔ l(!+0!#.&q:*)@wD<o@xǑqQJo2f (dY GҼ _oYp02U%U!@N¬NFX VL# \je)os .J&A{YLdv+</5]([~dQj;sLnaX/'gv?htʾgFN6'`ZHN!ȓsmYFƀIj&sK bJI`&x5`}oW`Nw4 aHQMLimfCϼTV}P@|UA6n^x|C.ew{Ң7d;W/Z(y?bcæǀ!j3 ՃQW0[6I 8ΈXZ&) ad܇D+DHXMGgoRO7\Tё2jExAAK$ NM~ɷ#N`zC53KƵS-^(xnj*0v,ݢT֕rbnf,EDIc-+# A'yY?$ߙb>}IfZZUʍ3FRv(;'a~4hZ>c3FX( Ue-9=LWt儍fӎ[#}2`CdgC2N; A]L?cHb"_fK?(ԓ?R鸵Ouf%nן9]&)+y6 HaNX(QMrBYzG Ck4r3t:ro Իu缋12ѵI3LʊPCY \taLt P9(xQ8L$~E}B_ϠI';<Kb`LD3<,wDW!Ku9f.4KOHU-*h~wc3 ^43N6;5Eyt‹2̌8 mprs TbF~,YY*%OdZFd͉K"j{*,brozddZ|x˃"c(߆ƦB>_m-+v Px>QTvTd~= o9]R,A3Py6fP ezV;JY{ry{#K(^% 1T=fɑD #nRtA8aC+71 WPmVn4$Y' @!z*b\Ky0n|ڞ P$$0 ;?Xbeᢰџ2>+o[J+Tt=DF0͚*oA3,ӊ51Gozpj1y]GڄzAD6%õ4&a!?JC-?Lv*CGSH/F zQ2$%هe$Yg^]ZbY߬w(2.|%.|VmjoOtUC; "sZ'Ȝ=L̮2XϺGm2#G`N@w[[#2xqHsIvV[`Ep^A{v&`r'/Vփ{YYR8,G Vd*… _ۄx1N325hϸGMźӶH%/y5s.zUe@F$.ocj=|*᪊m7, ~ páψ@=^ȃPiE6^QЍ5C/`c' 2c;>5-]S <yHlwBC#A2.d.I>YvIώp#3 / Il2[#]BG ,gOV:2\h_X'0^Yocj?% xX=:1LAV(J3&P~tIY67G$/W}?nœU=uZM\S̛2 $qo)~/*6ZdcBGdaM2OOt@BW[ȽpIrp•0zx9|g7ΔHSh1ۭt|_Ť8z62ep[hi;t`‚77 QѿJ<<vngYֻe ׮G S.&T;>m@r}@Y6bvdٟ^.5LQ朗!ӸQPUoIfwx^K=`\=>+QvZ-5&; ]~V'KkM Ȥ`YbyM"mi'wM( 4a *+lܤ6 Jﴐ"b5wrC٨0*8=SkX"IG 3vu'w wIK`k5 ؑE;#հj7~f޺kqppHn4i%a;N {zIfdҘD 8=] *`5LvܙNQZUd3m铜|:js$B~|e,m{`RgLX!_o}ɛ+5 ϝZPGG[ntJd}Ѳ:<iL I]#>װ2H֬QۡnxX `rql3s7&֮qe>PlH/vu-N4G ' |oL @_;2ɇ7V9war1{͙t;A t~%Yޗ`eTQ%gR{>V"ˊѧxWUK| \ -@מX^:A_Z} Wa, ij5iq"#?GT6iA퉃V3(ݧ)]RښrCem7XXJ)msqyMhEY?"f0ŅJw]W'T˅+.'kv"rS_{4jǟzh؍b+H@(ّvܨ[K#"k5K+ϲGfHum~Y}H u'$ d+AzKe1OI:@D4=X La4l'w1|G#aNlRt6KL%Nt,g[RCs(su)9V{#U̎ V枸?3)6 |j*o5>@]mRZ R}s@JzS$Ɔ§BQX/F֙Y]]0pIгOsBe'QkM]Yd fvrx[tWe7ysg%U{!eszTS;X{j[/wl`5OZONھ)VP;]=$ۦV1MwH?(vxe ƐZ%$YU u׻Z٨\zWΉSZIA7x;7c|X,@(3 B#ȜfY9BHRWc OiPjI}&)-k]-R,Dkgq:\וc1f%dwV7`ʛU;dP Ds$;bX6 ɯm=|X]0^fh΅ Λ>iU /hд`3v.3B{'kwUUh9rnW޳8JϭIp6|a{ jfPoHI깉 1,_Wj`ԮNܧZ{ D01C<OfmJ0# N2Eyю;!.~7B ,Z>/N%Z i.icp WS810zkkZf`46!DgXǿKWpr x0HȁTDlQ|GZ1>G~IPv&.Vg7 #*=,ľo64Uӓ|+f8 !:!2c_ѫgE|3 ^2eP+zbFz69b D*3sq_fQ[m7$Q d9YV@cuێ/4crm3@=%z:R}(e4]uzyGs!heEE|!o @AY_,C:"Ŗc&BZIY⟅ b)йBTbKߎ>1Hˮ#ʠ(z݁`aH)fz⯭e~`K&%;H@贤A(`C9j's߉WO+^݋ڙdT$o ߷t-S{p'+ dP%:~Ca{Ӿ7 .֐繠<[M~bT5|U؁m0O*J2h&$g3[Au(cN ck慪?ObPuNIܔrO+EwaxY|!૾N"(8u3T8_a*mlHÚ`ߖ呤_[k]-2-*XܪNBХ SnC,]|@9[#P{>5l~PbIAE旕7ZlS.,t9dBBy,2ECC}%΂@LhwV\PrteTyz%zCn}l썃ӂ% K VufX@^ 4p>*><{vM-}VL‰O,(SXY￘,vb0wK3Uݼ6UD%0]I( M͕9RX<8x|gv\P,^m>B8眻u՝#Ԋ± F =>Ѱ'ku V~,YbHbHays{S~KW6hh jVr]dBD|V[`z78K O$1L' u?XpP!K\>0ᩴ dppE޹qR|0+2_|KiY.0s(wH? uHvQG?OFbo9s}')c25M`;;ΨD ,`8c4wk#F!|ug̭HyWvr\)EX]{nkS{x9jSnGj!kȫ ;vH}Q}2{-oyLY '<ʓMٟb "Z}~aP M${r(qcu^+Q:Һm,)R LD]u2/#Oe&q-qhq %v,u R!pX5M폝ta::-ׅo]P#ڱp^iOj6Mj [%}E-Ыqnk칍MEԌeʊ0++1 DVg8|uK2m?^#=ZPfq“R8CF.17 ykfVU8)K2dqZW05e[\7(P7,Ne F(&i |i ;wuXQ2(9rwo_ 8NQM%,CqiOA~iv; X(LY0xaVC;#} \o\~yo|7h#o5Ao*}%YQ#[9ϙeǞx9`}rm>ǟ0J%#O5[C<ҿ#--2-ҩD a$?[*I^fPLV^Av'}!eYqt;%fo 㾗-ߞ2u7 X{Y'D#L{:.qj-'Z\,6$}X/$:#C%棁'RWl=࿴CX/2G])B?G#3~)hfޒW^*P/՚)z`Ig&HaX-ĭ.0[AbHp\!/=v^uUUH ZȮ}BrtI=R7MB_mdX[mx%}CN YA$CW ԿW(ZؔowpVá~8c7o)Fχ'`}}|#)5_č<B)eg/t␯}}Ɨ2Iy.WwRw1%tULNtmʹ=*C\"Yӹ "Yu )ӓJ!gm:Q 2mSu{D+7JJj%m,n/!$|8hm r*^~hsJhN"jx2)NVh"r$J1 fZT,}۰79hǧMjp>` eA 8e &{28Q4ޫ8thMD|}a|j.Kb]L`5%C-a\ _ܼ̼(Rlƈ+FC,"؜ҁaJDd%e%VZy"fi/ ݰ7 41E!n2[hYwӡp -b.{aP3v:i{ H3>>(hڨ  Ȧ_y0e.aG,0}?eS:Q܉'Jm*יyi]|O3c,+XrYaepvͨljM !^eM4cM46]8rS0>Tj^iʂEĀVHc9Lǖ{ōj? ̪Ο˱a͓Wi&ko>dQbaA_JH 9½[,Ƨ1JEKUdmA4:PGlb"mȹ\#GT\c03n={!)5g@vJ6Ƨ\qG}yxJ 9HEtL_3(\8Fp K`<໡V o=u! X4\ÕG U9.HA:RV%}iYLOۮ{;bźA TS DW]PM8 O3(>|bQBGsSet3ve_my 6PѡfN^(F pXMQUuC'&rN̠+ɄǂoL8(%Ud P̍R b˯Y}ɔ/wbOksxr`h-y`/2ʠVo]goYW|o8U^snf5Q_/bs`=).ϰV c҄?<-!ڠD,EH@+Ȅ[%it~P&|Ӎߡ(^wCKZ\U iu{{CsD-/WZneLXsw+)7?vЂ;d4ÕXU|YH_ynǢ_j{~8'h]tԳrfT7쫱;- v*²$gЇpleIr0jzMu5i8Ģe{N4!E@:io0R^[$IA_VF.]T>6u-/8_VMpjr3%j:Йr nޱ3ZyMmID@ =dZ)j(尿6<"K? %i}#Y+~b@t0IVbMxӟSf*ݳ(FDбeo_;5AV]ƥC@ )l=b'T(1=c U6҄nBXn*p.Rh{b /5\yeDC &/3W(mږ-;K* E&Z6GP3ʟ }-[H e>D8:Nz>U=X!UPL9'_F{mh^J]m?UX;0j|sBZ>n HHj*7V2 ^@Hœtg;2?*mHt<4\Xuvy`I5n1{Jk7KTȺ"{2u-pv/$>1NW}r!l~q4Nշ KFꄨ+t}R=8fGw!]ߓݝzb'P+6',-Ϭ:8)jtmTq r!NLfuzvmX9Rb'oh\E=Dқ|~ j=wHĘZ{Upvb%A*:ɎF B 6RaNXBdzP^dco 袖|mX5JEâF`pEQPpK)-@'3 =ة+RDPnÁ5C"5 ȅGi3i} WR*1oڝ%#%iu^%ȣŠ@]zu b4AWUrjc!;lj or=N]R%"knbOY'E[Hel*lNzsd)fYqۜ`^?¿z}MIQl?½瘹RxlQ]Ȕl9a[ ?D+ gsl' \_|g1+6GOm>E\X87ȐDY#jdkԂI~5f䛆"X#IzWT8Hܬ_$j+s6]٦{AHP멕~vt0I@V W<+L{xUd1k`mWI\^{{w4Q3%sSh}=ڏN-azEW,Jp;mX4fتY +0|&oW53̧D=,f }7f\u0EEFL*W~(W4F9)|'2 5״]\RTq2}Jck=| . ʓ.B+S"RA**MSg:4."Y5'<&ɯ]2uo*7 =hs;، r>ġo,hcY(C4(Zw6t,吁" lUx>[M7N N:,E{®Tbf1;P-r҄!tx"eʹȕ՘e_٦)"z@pNa%j>}z5% K3تИ" ~c#ZQpFxzh*JjSR(^P4eJ}GY|BLW,~&f+ iןU /oojUu;d-F5NKPp}4?'wWӳl:MnZi0dĖAx"90AJy'6/n0́%g~n䁯mq*y3XE8? <}OB]S1b_#O`3>1¥\ Չhk= U?L ƾG.&I M[[Miuj.mG?<Ot`o▐q&I%j_1 BvPW5-_} cp?7V<Y٤ bSMz"*g~3mc8:|1Qξ }M(#z@jBKK4-#Rrd!oIAb'zynC'3E56}{e*QI0X\3X5 ǂ,.UE 2e^B ɉO;H;EQ5\27v3ݢ~r栗.(5vd"wRx[þ}waF%XC|_oE4*} ۹+'(%n\,^OG(`n/o5'֚whuߓaHyz1&!rojmmT?}oa/hb[tIjo"!JmO\ eYB>р+TӞ\Fu(>{5},+tYMkg_rB8-K!JW57 98vCU?mb4\ rI(|6'`@3ip8r9rX}߉ 2| CdS߅攐Vv7/ZJ6 C-`t1Xkn3 nNkx EF5cXJ;?6Gܒg G %ena=}mt/=V)?}Cޕ/luى\B( .[~+ Lr:ӌ *KTHu> _ڋqJ?t!24Y pAee$sﺠxmK%{rdz ctBI «4M>n# ,[Lȷq:.9H/Ϝ(bz qA*%wRnl¿:,^ eRuMS'6Lf׬\p(P;ۘaQ%VQթLXs Q?&"  fhwǶn:$(EQ%;^sbBV­m` l5W12q0IDBxo*3෠4&%ͦ>"d@h_u+^n,ou+4NdEm|%tU{zaF0~GkuH6\9`Y&MZiVCU*XpZ$F+0& pǔU{R(I}SEyygtE;Isv)\"W3{9[r9|؏_wxfe^/ك&cwNID?"h~8{OpF^Q٫L~\ʧF{;8&@aHif >jphP_vJg`M.,'u l:M,8=K׉l=O@"=OYa߬< õ:’A&Y 4Ƚ&"3l*]J_mcK-);x$~ 'd|:P0(/ :~S aSwr쒁 ڤFQ5eP?W`gr:ZMb5Hw^IȚ"2b -@''~.ٟƾ"}BJ" VQYD->h<)v .ώ3  ?ELe;JG[W1"dIL6l!nA 55>1RT jW]99w צ0BϫF;x6Bͺ ˦WdVl\M_Orq0#E6 b )R=g C 3 3WX! pfʱlT3iӦ;H=7kTƻbcG"v9>xY`=i{4m sϯϑ]>X n6/`(Z k6ޅ*|mQh^/;8džꏶ)̡yJF%Nc=& zv{ z>B `=\q4_bʼnsC p;]Pbҗ6N+ a:sHSwPAh"wUjU S⪪W5*}KW=ҜaxAaJQ\mHvq\"v?yZ(@21#Rfclы ј@uJ "WeqȳsiIPD<%Zކ@8["sS oTe5rg$wkV hs[)Ϻ2uSR?:lvSBMD(=,i0}fR Sɢ͠K.G9:lz3Ƕ)3K]xi %%O}E[ N腝4ɛ6$>}F&a5N82j1}$b^{ :ӼUHZBr7,N«U])v?5]aДz=98q6ً;K{oK5jfl2PEH%Sȵ^~Ĵ|#N˳f@'r>9J4yjRWpf赬Pv u>?Cf]FwrTP!͔۬G9[L7fż+i׶!r-Dlx~=PA|)q(N67@*D&ʵeR!Uȸ Lhj6dP27$sJv*qtJPB{\<tnA(Dqs]n.kGG-HI[L 4k~IH?.s*,-$Abq݅XogiP pl Eny0Z:;);o#[zu" VUپñUpG XZSΛ۹9 ?:Rwws֞x]>dN&stP+K&;^ݨMO*(WtCA}~vhB W6ϗ7'Y"9ƄIӺq?̃8,<qru-Ba᩵ӎ DFi~Ѐ1-lYYn*Eo A!3)k0Mxrۼmq*4SZ9xRRH©4t^%+a4C6T!%DZSwӋhvz ap`zNGKߢTݚXٖ0^?$bCFVĈRv^}V)hKz['ZG=ٿ׻C뱄jU Z'0=jDs퐭gE7%_Ԅ2+ev1 @~:-ouFS"$41R2Fu86/S s7yT&U䰷D$h\>4;z;sHbd{oKl=Knj-_$7xAzxZTO 9>r`.Qbx_*Rg7]Ik E˫:{!,c[n"o0װldU,@58d]R#( m ah:3|RqpdC7?N0P8afEV~1 `YzP%F'գh껄O_oFp <H!,a>'m Uh!XR zUc 124  fPb~=teCtkGw4g `J$q;dX iM %l-h;΂+:y.ot.‚@VU< ŎXBVX@Wfd{Nhn4U00>Y"w.+{RƧ[;7tfn *!=H$=^H %)%rzi.90ld1$q0-斧B;/ *!NBz%fO 7L)[NmPd컾eB(↕QJbнWŏڈ{Q_̤lx#pfGL:{.ֵdCF/cRD,4bAtͭOEzL~r˻F,M.(*T6՛@\*v FI*gT!u4R;Hi1Qt' LhrEr`M@?F)>b+t(i*~opFfh (w3s PG}YIc̈́+ucF0ɀ0]'k#KN '0Y^o2fz 2IˉcJיa b/mCoУpb =EY\i\ ^0?`H \#Wf}F+;ŋK\9ν_qv6"MF0g8\~Аy*Q_אn%jۀUC⿩oZpDd#8tx`<mW02|p~8PQu5?X޹|_gKBl;ݵ޵`!>1v?N9f1mnY[W}g̍ك97n: * &_"3˿k'!S;Idqf2YUeuG}68? o6({p@!-U Bpz47h8ϕP.&L]_JLVj5 OE,Q9[XԌ~h6 l㏎H@P_CoC!V[?.:8߫E|5*u!tFj?L]R/KU~dԄ7QݒzϴHk>EACcOP(9O=;ҒdJGdjጕ77qLD@u&WJ1Ei[x@ڙ|WB:yA_Po&x"˿:afKH1U]66[Gx4fuG[k>x:w{xi}wA;*Hv,W] 5'j˖>! =#P|eئL$ŚP=>GOAPiFX;?ݳk\~UJ}xljur%lݣ9peT\bLzkh[;F4فrPJ.0-I.br3gv$$NmH&:C22G|`_BM$庉ؐ{r/vMRj(XQ%b6"rCi M׏2Gj8:z&`ʓ -l; Q"8o," l|d$`Ma/ PJ^3дyl52^椢bZMϥxhF Q" %߲#D_dDACkU{кhAhP蕛z٢!U^ ُ<6K 6&//HƖl3.3ee%D'sy='OnZEAwT( hACxH3 \=>KT.) κ[N_y&*>wp>E0I嚹@Y8Cik lvS184YqK{̂I!Rs埥".6־ Xi=ʙ ϥ@p@g7钩3 ]S^[Şv` D%AS.1=Uk=Z{9͏"d pHam:KڃvseyK'Js?<*XգE˖_.y7)4HIPCGS 4ڍVN6`ꮴ_<ͺ-&Ńҕrm&mJ $.TT?P,a,ͽ ]sU6@2jUk&k C{| `QیimcmT zP ә fU;(iįҌ95Zic|F7L+ZsɶA8vN^[SF QyXD@8V hWX"w5AifehBa׬1P Oڀ<%B5pZc-&F3j5Y>A;L&Ee4=ȸ_|_E g\ r]7o6T]F7k0gS!BK<L/Ik (M[U\MR˞љ WIcG*-^ęYe!\qʯO['kG.F8RQcsxʂpy;p)ڈv(2 o`N>ˇ gxȤ`WlqLr#%rbz>GI^^3>h" cQoF8Ew zfk.fѭr!)e^F͋uhQ,3d)niN*,i2xuGuƝ*dD5xmJU6u kY3:öp}} լ4>nDZo_|XUl?֭P͋5Q+_,w׎ \<c!^<d Zcl恅/+L+{[#g-1nbTͬ3FN'ejz!V.HYN@>;]0urj6&"b@iA7t nP4#KZ =H4b5޿1_8 jI[vusQ\43w`>B* KEgY߾a0JSEC1؟z6չ[=_\ρ$[+6"Gy#9›Rg:4drą]Dfo+U.ldμHYw'&v7}foy|zXDŽf9Jm7L?Y~ K4:7,$5BQyq U!>sH=Rd } ǔsRx{Y,1ZNQ>=֌@Z Gr`P.fW\Y ~DB+YL}gO3lirJuK1\ϧ9)fێ1՟^*ܯhS, 'J.bU:$x/ w;l:Idouii/ sxTb dh*a_ 0PY`=F$78% +i'0Kq߄LOx7H gFLԋS^8ͅR$"XbPP KFucVIRN__m ϖnRi[=,AYܴ%GU9ނA --x3VpD7O ~H4qf8BOMu%dZH{ow9KWAtV,y}Gx41(P\o5f)U?D3bc+1ov|'=h-_=z_6cK@#cmKU<9r8 T*6$}h;똪@J{pG`޵rM {© Gv_8\Wh2 7P-wBXkL|5YbXB) syݢ?1"{D4ɧtn6* W97xG89s :mitq\1"8;Z҇DH)/U%#GZmjԋ ~\}r^^|K'7IX&&6.K8R,$~2lEr*T.m8p{7cU\uGcFNpP[KetF2}D3f5H4"O^$R|D"E?/boea|n16h(Tƺ aHשψ%3lf%B)$[j S Zp'CbC?(V_ 8+%/= Mϳ$MiY-lB.Po7qHN>|KUEU=_9T8ⶾmE$z,j$y LO 5ijSL87Lj(eDs)'"x7~=(?ER\[q=t)a ?xK cOa*;7+nzBw$qބ Κam}t3]EgbU˩=п6 YLӫ7eBsRs-ad!{(Li>ix89] F{iE!RsM^ҡQ53^(Ps04-#G_{RQjF9K/ۜ7KŤY^'[R֐؈>B,̻(s'ӆ 6$蹴HUm8,%R;҇t†~˗.i;Xm|ĆL͋ҋLJvH?H;% Tq??  i\4/E]v ԥߚYpsb(!wg`GP8{Hky8kOl'Ȼ.fȟGǤ|9ʝ#'Q]x|Ձ%q¾/6l:5!YEE (t`osmpb gu[hznb?k`ukWs cc3y\2&xsY-<-y%]GQ.` RcOdՂ':pT -ѿc0@?9A0e]eЌysX@^#EYt]%vE6dvck?5$U|q#3.ܘH5{w q遌;hFIMܴpQx5;.MU/Khי| n]=Zڋa&_R8vb[YH-l XćJ4Yb\z d}}IŬyx|_; 0mx;$sH&R|w&&Qp%D"EN'AH?Ge~o"ft+ *>.*VYbZߞc13ߥcY;enRt1@6;YI@O趚m={L๦2U{v|:d{J30%$^Xboe64ۢ- MGӈ3%Ȥ!A6/-)^+ VJa !HtB@ V]O'$ ?~ ջG[mc7&FqAO/Z{LL= Xdh5Áᵇh:ֶ|tJWkI̸ܫZACS&g ? K5< DNv؇+oFo|[Wwmq@i ޏ8f&L*@ŪG#\p$HFPV+ й\~68.48{2J$;hݚt|Nj"IZ+dʇ1>ΊUmBNՀC۶UnRȊ/j<&$ K*`xL]ݝzkC<ٓ.JC;veOic=f0CЫ{x2ѿ2cm@wA}f7;DFp K;V= ja*,V{TN8ɧ!ᱺrmC ڢW%ڻsVW}!EB&ljo"/}Z 8J&oWќ;@hlMku4\Ļ:; 7PAbqLY "h7RSNB.6fS&ȆZD.*FD/$=lj[Q} x)3rg+Yv:"p%ׯV^IG,ݲ所M-Rs j1= OntU.D|z,UP}6! Ar%wx:[)-,Հޥؑ^ _%fOdWrӞ93eA)zwzDr:|ޓЊB54&J+LL*C'oDF __$#yjgө(,,y|]gτ{rd5<^\iau:wfxERm%W$ܲفV[G6bӚ>M>w_` P:ANOpjtxL9H1gpF!AYî5/~tM[?cxWXKﵖ2q1C#@%DppHMWPxpShq.!:{|,?R qfJ0xy%v,Kϧd#QjԜ@MPr)焚ѓ+8m!䖶Xߝ>: '߻$#k.fhk棌j GX\_.^K/Z?iO! ϲ#;ޏyZJI#8NH'k&IY& y^%8?ðk0Dc 19[ !D| z,u ;G<׃T,p [ן`+e&<<Ӳ( x)xCG5T\P.<Ȓ>@ˁ)0M; ݡprDĈHjf;w-98- 4}*tjM1tX0GB*QPZۏȫ,Q}4~!ryO6]yqXevFI@G^ Dqvl45H,1M`|CK[ROf6 <7gB+ B`遺U! ,1LqpWm늧?soQ_>K-TiVcQ|Yf/tg~I 4Es<Y۴fcr(HwǾ0߼-'訩ܚL7Fb~WtPKƄH P2j#}\k-mvN8f2tgDX1GpD9qƶV;cY6HLyNb>9Cir6 kD4NF^(ሤ}&ie:onUbfz݃ y׶YKF0Us8p gtǨ%v (PFzo4+%ׅ[7^tfP'EQj1݀XY1Z .Ϟ9zId5ؖ]=& STpԵ"VrZ彞=E9dڌŤ8*P7)NlSO~Yw^L-3cEJQ_ue5_@xGX@ybQR퐖̥i^F/iue(Fl{n &@_&P@UAy(rz{ yۧp8PYZ r,_D'>n .Fq?cήYuu޼ l7PQQP~YBT41 (T}mSGk}Zjs#T(mX,Xk@hiK]b1aY̓9>x)L6L W_aH ,KKN Z=mOKZ s}=(dg+`UgkB)䗉$GvÉrf;^ JBwt#ʟ:;1}QrN=BQ;z֝QEi^UZ| lߙK"L b5q*Yx%q9?X뛿sL1pޗhd+YgͤIB!;ob阽B;\1EHP=T%uZ!@ڍz/"Eel@9`{[jn!3J $ڬ3 B9o9zŶc Pۖ"؍ JDJXYym׶Zʦ7 Go5d'ih3ALaDbop6^y.8@YnNWUS쐌oԄ}'uO38FF]kU&߮pX: 5Esx57 5nreo@Ezg$dJ_IHAef%~>ai߾ ^*%Qaxw*VsQִayƛAHްds\@ܒCJ⿗! #ǖae {r<=knj6쾭'o>!~r2 ": ޾WAQN`c*_}P8]r~ '28pUy'~hwanr^+Cy 4ܡPpĝ'ؕ^#0* +.aj'ѲyJ##Y ȾKTx֟n7bV׆'&L"ͫ+r#o4)QN"*+chL.|Ua O ̌a"pX[ nFkVq j{NH^=pξUIEٔVCu,:-*϶ZMx.JUK~ U_j,"ݘjוO}Tiv],#<#񾛰:h=lt$5#.ѿOvT.}S[t\d=tc;,0̧ {4##Q!*J5N+o[x ɯr "4NW@VC.L+uLHku=7d@`8@ZWg+&ߚaƲGp&Y+yAS gd| Bl>mb"+ep+(Cm(YKETab x^ƒdxidzlMX>"xK5H ~B*@w)/Ua><حje6 :ע āƇqM{A5Ƞ}:nt M=̐,~S]XBa%)r(!Af>wdїKf\.c.7K܇,XgC9(5ьsC~J{@5O`*̕>L@J/i,d\sRY* `.7Dp 1 19Bz< @$e>m./0 kAȑd5j@[>hӥ( YS[vyC^Phԧw8i \T PhzvC[2'oFnPowLiS3س^FkNp0?S7n^tx94Fםi$xV.Lf9 Basܚb%+,JEX!M LKN)^ ^r%cPBʵ+C7&Amf?uV=:EBbd!FGYsˍY97g lDRML 0qJKO2"BcxkW~s-@-Mbt#:%mGȏlfe͙ NCWHa4yבRw:OJ붡 P6kij% ?Tay;43u?/ns8^m (:3 jh&uxBmʳ"3&8TaLָS~4=_|;Iz;adOIp/w3Pqiz8M "ФH#5Q)]vI@p;"y:pG6߸9WSv~\f'g?6 7GAL`toGȃiA,J<3Ci]eɠ_c-\čz?%yHF^PBY)GO*) xKHQkqyOʘE_G W/q$ϫ2q8I0WgȃzD:Qp4JNzII`r{SX`5YGEˣg.;ϼmkkޙf t.:B V7zDfF *?It֤B*XUT$ $ӭ~Wm֌.iqy62 ' ۞.$״5"y 1GX4|8MBA7j(uosۣ|-A_ r%0"u9$,'wK_fǩl ^D?tu+FDRHc^h#0q|0#d|gԀ=k!KɈ듒bpCKu,H n?͗ZwlAo uٙ?9peAKc-%#/rD?ϧ8 ¾uゞz;F'&^[s'$<ˢo,`P{CRpl֯Ÿ]gQeրU]<-o"$cAUfWd'^ȳj6UHϊ",ܻƭ7_{9񓩁:L8~m :MZݵtM`' sC%/Rډ)O]U1T^;p {UTX8TwguY*>LVvM+dhyOpfd>%Z3e2 Z]:0~콯_ 6jRW XȔ@@I& >rK+>Ϡ\yi1j!Zups0 L3!SB(r+AD2^zҁMpxg~NMII3sv oMv@2̵ \bE!^ǟ%4ymFrXXy4 &?g90s@Q+ed+yIvĬ^S_ݐ XG]X~OߖǒWbxVB%>f~,RpП* X]#G85Za pTN KQO{gìkO 8Kt>dѶl5Џ e 0c/Wԣ{ߥ M6$Ss갉55D $˾]&FT%I- dFDk0σj=%Eae,y&ʴ]7X ,$(\<:-vJҍebdĩ!PRgp5SÔd|snp#6lo݅ϑg '8`RnFF>iT iRwJ2C @̼0sPbft1rW}akܕڧctVT)I#k~ Ů[b540"MU5e5EvR{a4WO.9'5X>ְ69DN&.*ܓ{ /!sn^y 7)1m=~ yзE ޔ.e5PxԾO&?)܆h:L^p4<Zn56SSf`#3=%{_;qhyB, B.ևN쨩H;`/6O8ܴ IK>kl af.i٪QuYg |1N*` D>!Sv2DNWjR&.<#<1ɪ] g0nždD[8y|jIe+&X2hwF7iTsuҰ3 3NwYoիhuxge\s0DBYrcp?2kgm+2LXiwydhV _aK57ZxdgNrcYNNDUB/IIKޯh6vpWJ7V3{^ O2R= kIIs YZ