samba-dsdb-modules-4.13.13+git.528.140935f8d6a-3.12.1 >  A albp9|_jn٨luMWrR!!@IԔ?GɜH/솳܏'3N1^eaO!=( KJ5pz7XrhK> sz3FFcJߚ|nS)^nDH -=ͦa}ۖkKaRyiHu@.lp'E"M8$<>\7]:aߝr &D!;#?FZ>ٽșO}zaغwx&6e2554f2fdf3ee919589e07f83c79e4f6704d0b3b0e5fc51f7772247c3a58d5005f554b0320f5635d2909ed99e488329d7b5ee80dalbp9|2.(Ƃ>L2\daO946jfWE$?d|)AC`A%XNT@񾄸+s X֓V` r8Vga,Al('P^\nT`tK.ϻU8U]m;}S0UPxo3&{d{R╈A. ?(>@[0_>KoID9u*Ԙ gGɹBwP2>pAB?Bxd1 8 J 3JPX-L- - - - !- P----tt(^t() 8)9,:<>@FG(-H-I-XY\-]-^bcDdeflu-v-w2D-x2-y3zBB(B,B2BtCsamba-dsdb-modules4.13.13+git.528.140935f8d6a3.12.1Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.afibs-arm-12d@SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxaarch64ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb/samba /sbin/ldconfigp @h @af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af af 9baaff5b42339ea828c12805b61e47207d3d6dd358e2f00b70d201f3027d229caa77e87ca8bb1fa4c30f504914595dd78f904ffb474d936d4805b15db87617eb4c5d5836704fbdea82427691bb12d4eaef989a97fb9fc38659b49883e78eac6d0e9aa81389277fcf5c41b0108bb4407cd0242e708beb61ce74492867dc6d5f66479b0a9d6c6ab6a8ae9cfa45492704a483b498ad85cb08008c0274b931c4e326578b0463030cbeb4d0e941521f99480630e9c9d524c5b6a5db35a9665c84368b84e23d4fb11b29117c7c86deff7edddbb41e53c09fe7b8c8abd2e8d15b22acae23ff39c74f25fbbdbe5c2ef645434751d5c885ab30b87b7b903d7793be8a49b565444dcfaa8514e50457c8f16e8b4bea3c9f941c90b8ca9d00bf270bd3aab0b245b86ba2b93f5ca2af08efd065c0b6750ec760d19c49e74d903cdfcd6eaab1f90ecfd16e1501920e2d84cbab4bf4bff02ab94e517693fbb9f3355b614f26b99213eb8dc3ec5ef2c4a78832d154c67bef07af17d7e784742990b5c50ecb7163185f86535d62341e2b9c8ea35eca8765beb4257d71985c53dcdb9fd5020c11ec0135c189eafec7e63d69c82a7b8d0f1bc9749ddbef9729a80b4ae1b3bf042011677b6a96819357a331ce4b7d02e4361f980e1e611330678782bccb72fd07bb5d51cf37304ea66bb0f32501b794305d38e752381149e6fdc9ee4ef71e51e051f87b11e47bc1df28e070df686f5f428e5973b06670116654395976211b83553098ad32e318018cd3a8e5d3986c74f6ea561d8dbf5a59926e415c0ecf36a603b6ef712a25adb0032c564686cc8ff492f62dc652ca711944e8c8a536a3b82b56f9b55574a7c63ec401368c849594bfa9fee26c46b989e17d9b09c1255498548656134b50a30017de80e80eb246b345b3e3a2edd0bb925b5149c2e8099cd84f395662cff31fc3271f813331740f64ea37fd9ca137eab49ccbf473ecade04969fa16553295947c6124cc25d32fb14348085caf9436db82793f70f4213bd6d846d3834da595a9fc99ba1742bb33066db03c4f2f7b5fd0035850717415cdd574ea08e1660c8cfe61b9346d56252af0a9824bf4a8459b964016834a3eb1a5215a240ad99be658d5302759a700a0f643fd999c799bc3ace3bfb18d517c53ecb0159ff059868e30f5d6791897684e61ec87086b87e2a620cecfadb7005756dc82990a286d41ce6a612f5f344c31c8639f1d119627fb027ba382c809606f888828947ff5849ac8c6d1a539a2349fc4877af5c5bd54f2238d02e344b8649eb137337a75119288a506de988da104a0d20e0839454868ad5c587e91917d5be76d3170dc4dfbc95a6b727835b92bbbdacab70e8ce04c0188f3275cf0e469ec939ac5f3b81550ed1721cf3dcbc7db9acbfd709cbc41a5256c1c22f20d46144668342e1cfc202cb685a637b1fc52a7acfd9e85eac351d9881464466a22e69e6461be5c438d968400b921ba7cd9e0942d9f26f55510044b48e1fbd5aa10c7848e115f8ee4ca7eb974499dd933dc8b067b4b282dda5ca4a2687e2d2bb0935c4e357429243e52a168b566af4244e10d17f57e1406d9c91ca21bbb74cf774300ad6673e861b028de189a0fd77e867b3147daad3502763525807ac77f898f4a256687a94308bcd278b44df15df5889f7f54863e4e41fa5c32ead8715d4f2d44ed39c2c861d10102cf9f0aa915099e2dea64ed207c737dd9f18c64eb6b0a496b4a509bb06c614fc687b66dab67c9dcb8986e7217e2846fa4cab4c05c81571a78be08655134f29010cb4bde6660452e32c48cf80b9cf118398abc01514e03dbe0f477f3971e92901a7c7625e8bd27e3a225d297cd0f46deb3449bfd9a95137ba4f1afbc5776eba1034567e03efb9c6f6a176baae4d7d75d30034efaaf627816bb050fc8f9caf223743332ec2337c046f7f3660b57081e7196c7e836e5dff3aec903845d37fe828a40fffd051d96cb786e3f73364c63ad51be5fe5a535fb6d1c314733398b7fb45b7ca97fc8b1bbrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.13.13+git.528.140935f8d6a-3.12.1.src.rpmsamba-dsdb-modulessamba-dsdb-modules(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libndr.so.1()(64bit)libndr.so.1(NDR_0.0.1)(64bit)libndr.so.1(NDR_0.0.4)(64bit)libndr.so.1(NDR_0.0.8)(64bit)libndr.so.1(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-credentials.so.0()(64bit)libsamba-credentials.so.0(SAMBA_CREDENTIALS_0.0.1)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.13.13_GIT.528.140935F8D6A3.12.1_SUSE_OS15.0_AARCH64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.2.23.0.4-14.6.0-14.0-15.2-14.13.13+git.528.140935f8d6a4.14.3a@a@a@a9@a`v@`a@`<@`@___i_@_|\@_{ _l@_i@_d@__ @^@^^2^2^^1^^Y^J@^2@^&^&]]]])]@]@]]@]nU]nU]i]e@]_@]J@]B@] #]:\ڭ\\@\@\ \N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USanopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigibs-arm-1 1636460190  !"#$%&'()*+,-4.13.13+git.528.140935f8d6a-3.12.14.13.13+git.528.140935f8d6a-3.12.1acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:21699/SUSE_SLE-15-SP3_Update/08b059d7b5a0f63758fd796f8b3745b1-samba.SUSE_SLE-15-SP3_Updatecpioxz5aarch64-suse-linux  !"#$%&'()*+,ELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=70fb39fc4128a55cf796a50fc2edfaeb6f85e76b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=daf64c31a99f3eccbbda9dea94472eec4178978a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d5f1b395cfd112ac0d0ec7ae8782378770a0d0a9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=17e044f750c83bc361fec33dfff5c16554fe19b9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=27e517f7decf295f4cc15444e2ac1096a8ef13ee, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=134ba8f7f6e7fa4050e5340052f311d02e937e9e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=66402e14d07ace73678db2750d35be4b3e84eae5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d1bbb821a6b584b8a735a71e8d10a81e0e240934, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c76406dafe267b784a38c5f4c47d08334d4a8798, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5c7306672c0a0610ddb7ee0fe7fa8b8adf90eb4e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9b3d28bca149605e2837597718b72a7d8f3c9eda, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bba9cb5f7e0fd688b13453d960e969bc4a902500, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ab38b52f226baabd98ab7ef8a40796cb4c5a129c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5da918412fb34870eaa4fd2f5b257360bbdda453, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b796c08104810aec75fad627e31fc5c1dc990bb3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d0142a47687dc12137c37df5b54548f3ef911c72, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1ea53d33a9f2287c7530efe175b105db38c8dbce, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=23d2481f799abecf85b6b348822b10655bde0b0b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=eaff9831c2aa81a6242d21721a2c333e243c56ab, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=37892bf43f73a2daa4253c21dde7a5c061e969a1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=76088d75fc78f6069fa6c7711ad634075c13da49, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f54edd8f9fe0284d00fc210bc3566b05f8deef6d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3c56f92958beca66b2062d7e2efed586501d1857, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6281b19cb813374750f8f4bdd67848621e1dc521, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=15164e3582e91342c26e72d1af216326a672b660, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2db57e9840388f286f8d34ded4fe33e7134c5c6a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=67e961b4b014b7a563ea691e21ccd157c9efe758, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1b881717ef77d9ab4568c1bd8f26bbc9c08a2f79, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f0c84dc944680b83f5eae1680dd86ecde678b45e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7dae59b4d63b1d05fc48962c349d5bc92c7bf68c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=dc74566ccf7148d01faeee10a68240edee3b7872, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=845ebfa16cf24b563e8a5fa9dfd671f665e607a4, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=daf935ae8bd58ba348339ffd2e6a71012c6a9bad, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a909d9816eba60917dfa282adff1883540a20d53, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=10b4aa57db2662170c74eaaa7bc0a62f08c41bc2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=96fe11e43c3f7bd9db37e435b15bda3fa3c83cd5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f45116dab551b7c2325ceadd1d26d4270f24118c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9d3b10bf79532c4f983c43e5e61b565472f005d7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=18ecc4625eed8d69a2cb2a0f8442bb100d6719f7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=62d13fb7ca6edc666913d9a4edcf2091ac039c05, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=dd24ac3dc815070b1ed339125e555f25df92907c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=75f54273330a62762b6f53baa741be603aad6705, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=99a22dcb4a56b19f3050f4e5e5883f32c80548cb, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e3b179a8da5cce90bc568e939f55d47db51101ef, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=762fff1285fd9dbbd595cf690791266c093689de, stripped9Fdu'BMVmx&0Vc)6AL^o    7 & . "  R+RUR[R]RR R RcRDR>RR)R/R-RQRRZR*RCR\RPRR=RTR(RbR,R RRDR]RUR[R RRWRcRR>RQR0R5R6R/R-RRVRCR\R=RTRZRPRbR,R RRcR>RR[R R-R/RZR=RbR,R RRWRR[RRYRURDRER RSRRcRR/R-RQRRXRPRZRCRVRRRRTRRbR,R RRURRcRgRQReR/R-R RTRPRdRfRbR,R RR[R>RRQRcRR RWRERDR]R.R4R/R-RCRRVRZR\R=RPRbR,R RR@R[R]RRcR RDRR>R5R/R-RQRRCR\R=R?RZRPRbR,R RRURGRjR RlRSRRRBRcRR>R/R-RRQRRRARCRRiRTRRR=RPRkRbR,R RR[RRcR]RR R/R-RR\RZRbR,R RRRDRKR@RMR RR$RcR[R/R-RRZRLRCR?RJRbR,R#R RRR>RRcR]R6R3R/R0R-R RR\R=RbR,R RR[RDRR>RRcR R]R6R/R-RCRRZR\R=RbR,R RR[RcR>RRR R]RWR3R/R0R-RRZRVR\R=RbR,R RR[RURRRYR RRWRcRR]R/R-RQRRXRPR\RZRVRRTRRbR,R RRR]RR R/R-RR\R,R RRRR R/R-RR,R RR[RDR>RRQRcRR R]R:R2R/R-RRCR\R=RZRPRbR,R RRcRQR R]R/R-R\RPRbR,R RR>RRcR[R]R/R0R-R RRZR\R=RbR,R RRcRRR[R>R/R0R-R RRZR=RbR,R RR]RDRcRRR R-R/RCRR\RbR,R RR@RDRSRRRWR RcR[R>R]R/R-RQRR\RZRCRVR?RPR=RRRbR,R RRRERDRcR/R2R-R RCRbR,R RRKRUReRR RRcRhRgR>R[R;R2R1R9R/R-RQRR=RTRZRdRPRJRbRfR,R RR RnRRRKRQRSRUR)R@RRR"RDRR]R+RRMR$RWR RcR/R-R'R&R[RRR?RLRRCRRRR*RTRVRR\RZRPR!RmR#R(RRJR%RRbR,R RRR RcR/R-RbRJR,R RRWRURMRRSR R@RcR>R[RR2R:R3R.R8R/R-R]RFRERDRQRCRRVR?RLRRRZR\R=RTRPRbR,R RR[RR>R RcR-R/RZR=RbR,R RRYRR RjR[RlRRRWRSRBRRcR RGRDR]R>RURR0R7R/R-RQRRRARVRCRZR\RRXRiRTRRRR R=RPRkRbR,R RRRcRaRDR[R2R-R RWRCRVR`RZRbR,R RRcRR]RR RUR-R/RR\RTRbR,R RR>RcRRR R[R9R-R/R1RRZR=RbR,R RRcRR R/R-R1RbR,RJR RR"RKRDRUR RR RcRWRR[RR>R]R0R/R-RQRRCRVR\R=RTRZRRRPR!RJRbR,R RRRQR]RSR RcR/R-R>R\R=RRRPRbR,R RRUR[RRRQReR>R/R9R-R RcRgRR=RTRZRdRPRbRfR,R RRRR]RcR_R RR-R/RR^RR\RbR,R RRcR[RRR R/R-RRZRbR,R RRcRRR R/R-RRbR,R RRcRRR R/R-RRbR,R RR RcR>RRR R]R.R/R-RR\RR=RbR,R RRWR[RcRR]RR R/R-RR\RVRZRbR,R RRcRRROR R R[R-R/RRRZRNRRbR,R RRER]RRcR/R2R-R R\RCRbR,R RRURRIRcR-R RHRTRbR,R Rw%#qH \utf-88f34a77ea5942383309f53d59fd4f7b95c76fc50d5ff72938e36887ab307a42c?7zXZ !t/t] crv9wTh[zN{w=Z3 (X-9]Pju/YR $Ϝ햪gi;ϣ T5Pnc>o}O"ӫl gZ=u݊?,\,4aY΋Ⅎ唖A723^]F[VYRu;Qt{L]L "P5EAAm;OfTTˡĒ_`d@+Ϛ_nzrbGs Q",ʵ(#~P_5h oNaNJfM_T51V![MVz7<0@BwuE"Oyups;Sq!Ӏe]C(`fE~ GaGGC2&G-ebBO9Z sDm|Ҕq`X}hM.4gv|k͵yvO:偖Je<$o]J^J ȀpȬx^jjIV ΜU7*B8V\ٛy )h[Ʈb馡3'+=UjH#?[H uY[ K ϋ\I ΂jԍtVrsDjn"|'͌D0'Ҍw;߮|Q|+Dݼ1K~ˈiq3 M84~|cz5Nל?Up(@RA@@F_ɸ5jXkYF(. n`lY pbmƾj PIX4ƳC`yH?5AzQLLZs\ڗBt~/hjM1n /*҃wꋣu-xBh l6\ũXp:!ֈ{d I.:OA KGPH/]*lrlΆ $b3;'cLLXOd\3f &/dpprsC[Y̶\ X$SnM5 ?m +rn?fßeẂ|kx?If)y1}$O$OOol冭vz!E;8\DQɧ{\?hFC!9\m\a8aVw' 59ޠ'l] h\anYʍP:|)p,,%AqG¡Hd 8@]ŖC#}og˞w{g\`e R-Ì<+gr7I-LJ]BE(65unj)Mh,5Fźmx Dw-G#֍,6&T/m X!Bҳ`D3[+Jgc@qU=dNBbRڙCǞpv,0+fuF\zg3gaopqb1U%x6\GPST?uḤz%PWeg?T D3/˘U4`~xU"峻r?P= 0]YERQ|Z(ExQ0:U0i$:Ęn);~]|B9g?S2[{;_<ߴ1KӝIdz# = >9|8?W&y@0Y]5ImW?Kh&{2@aq*<ĬM[4v91#F>tb h܍ Fi+ :W/ !γ_;ܳM7jV0%POZjƥ\rt;`H*_^HUDA-^oCU`~xͷ?k߬D;o?!$#,t},KQ:5bb'϶ؗGNXf@ M<3&^ۨUnPg[8K ;t*qx:TL\/S#n_ p$ ӔM2 8K5giZ _Eyϸi'fȤ*$'pR8dp|Tg;veudkHK}ܲI$bI[F=h8O[JCbE-K:FIa3Mb!I ́ƚ,Б1tԹĩg[l_{ی( PW$ D $&/ѽ@ڀfmhPK$=X̼%sEp6jQS+BY^Q*>ǯ DPI{8E`jJNʡav}֪NLFgk5F 2?0(0ZFM-B3W;jd>V]%ՃOnDOk X )EY٭cG.7Zm=WMt ;+γqz<}{RF^XiY,a*pHj>el&?Yē*SI|i :ikoe)n5R erfO6*dj-* "sv췭|BrzE%6yYSE!CO^Ʌ%nyۜOӮQMńKzy{#FM VW%sQEIK aB70Qh kqps.'+4=ɤǣ0c>LQ@ƍv넄%i2|PeeL܋v27Va' Wd(.}SB˭(tQf3n+,Xۊ}xU&"kfOJЩI(^2w^ex`ϝ*a2Z+/)x{2=Dpm}z;@ ounW VK+oOpP;7@E 6gjO_5{`a:9 KlSZEFG*ܲBYjŬhHF}j\#LK8Ѐq+?c1dGDz榅Pa 7uxN:G70:!gT>;7̧ү[e/7umc}G:j*S35(0V rM-P<Gq:dFC"(0MXت‹tA NdR_nΝ@u۝/H'TLk7DmΌ [MBIH2k(C%+sLʊe ?hmmvfsrʃ|N9ko(``EM'Jwy0se.[A;N839ӲJ1T!M,Ke=~n6]s.p,zn, '[{xuTij;q B7OʷM$Yɶr~%i|&M,S)&⚦>(ڳU&)$Ew\\G\ÇQ`e h|㏶~%, !y5P@V=Ln&ܟkEL14@tm?P&)L9Kr0d<ΧLXJcUzҪWpnW$[=|+"8EG!ͥfj(&ƃҏT酩?&pUn) oFuiְ~5E _gp$2粩c1pF\[z, o&X;'r1ۊl^& krP7Sⳏ2 0cNy!氩&:*GOJCP< ϲ%% o|MUǔv\@I{ uxDK|ߝMZlK%069f6PDb2˂PxX԰W%C=kXDtS- (R"?Lo)p&h+>~I|X|c4 K)LTBs45ywh EFMRzHc@QN!ҏ@'2='o.#2ILW LPfJnI[׼hEf g'n͓7dFlNpO?V?Um(׎KkI G+=kМM`e5c46Iv!*ٻ6K3æ4Y ^m՝WۋP]\+D^p `ͻ@*}8*䃙a11M> X}w/oLm0."I+[NW.F@,iLZmPּb{2c;< /AD3~Qd _SMf<j 6]M[GBC"f9٩Lj~yM|'K g5ux!-Kbe>تZ^;x~(Wg!F#k33:A/xq4=[iIau1 j}5ۥ'Lq^BȳȐA';U*i(G=[/+efZ/gFP{B=/DY@ޱCSx~ 2?6YYgW !-nreϘeJKte.Mf:#eBv/3J@BJ41L0#)8@hYf5\=^"Wh\K`oZ.)嶇)ˍ'Y`^hu^V6BW 5KDZ2 `jS2+hshI~C~+Eۖ%1Jtn |Aprs^5DQ97}<9k=EtU6i3hobem+ u CE=*yMkC#*d9S{eM_ݒs[@nV³2eNTfqa|1U]fUGcȩ=)AU*^G"Yq[ZYIwfyrknIP6|m"V/I�3X=D {V')*?| ' RpTZnvkG`C\`c彣ǂW̋Ù{KS[ܐG YD:sj}^̻яK]\:I9ĜY}QZ'996M'dy\mP[߼EO.cYM-֯drog'֮p͚ژ;1r*9~_e:p PiȒ[ if猤g .'.8U{,zL0 I8GWS79+Ocܰ쀝J3V4?mft $>zx~2ENt݈dk+46"4&;O2mZ`cT3> _dalw;j>ߩvf ͔5{aZzpK]DGKŒÇN?9_Lk(G .f͞&`e76ԡB7O*vc2k}>n?OE ƒcnlņ̽+}+;_pf! x)eb׊5ܰ%YkCRh7bm1kYQު9Ă=R1L_q{ܧe% Cxb"kvۿ$r -6)qk2﫦ŽUt586/p˳䝏Z[h;(Zly<}P/zָhiO^c[_Dܓ%S2jOktFJym?oU=Lu-'n'G[~+=y9Wlb\HJQ*|RIun?Hsˆz%bCL\O'Ks jh>!(Vje"~h42b|.sy3^-薔6WdjDEGlE[XJdW,* SyVDp}S>1$B.m SV}:K V5#LMH~o ,oyÎ$,- ٖϞ z]Ү4T(4FC4Wm4*nĶ YmyOnjq.} (Tz`v)^̞1!w M|Z68;N$OQ*rSZ$So o=j;mV0 zSūJP8t*|Bg!r )ώb^q^^c%8, 8F 1 Cqfb;Ž!pC3zЯIϒxNFC~<렏&Y 0Ϙ 6ԇ(Wϟӏx'خHfd{hPM`(SVrJ"x%sqgLwA!િ.H)uKzM##:jF% qoᬩDpRgb*1P)+K"`Znlv*%M*%`cQ>GEșP27h3TkU6r,}.]gϜ:Զ&s^aN$'QE]qqPf婮%Pp]lm ԮD ݡ{#1U%F1.-䫕%I%;-hFTbe\$BVD%[@S ZY4TO̸ٳc^ ew ,_|DXuG a7ن2y] u^Q9Gܚ줛^蓋o[u O&#'yDW#_T԰ Te5cH'Dz?biswA;{zs`EI]BRΘqIOF T#:Q^r%,ZۡD~/Myߴ.7"O;dc6~?ga3:!>gIW)oJ_\H6@˶5s^œT6+|12C؂Qen86pqD ͭ.lދH01%O*{Zƌ>t,˔r02,}ܜp?LʷC{g"m0D5d.zo+lUkO35/5|HT2F'͇/|}<y_9pӖOw֌f g'SY>[ D#݄>}}ɓ8!i鶨tڞSE߽IGڣO ƂI kW^Y#ra?P^iة$A4=Q 1twP %$W ;^ea+A{"}sN4nq|Kf3puZZٳF`˃u3vRB t"n.DZg!| .c%[E0rC]iH 8eڶPyΘrnY !ގz i; @f%9Uz$nY^4? eP`Ga:K6q)F /ޒcve%``sP @Q" !ci31xtz{p!{&D7y'@ ع!E:!Ohk7Q?oOWMtutకDK |9HjmOӺt`hK{"|.(!h V&:).5cM./NCJ)!s-l?F˖!7x~k7Mn}mJ} rIEd'!=?\*y5]:Vt/~}8"Z#>S-:΢Xi;xy$jԔ[Z%Xֱ$FOZk1fX\ {Jd@/C-gx=}hGwme?eQ0TdfղΚ0\7Y?d!ҩ-tƢKI(,J Frm]QUFHU#bҹ0FX2{*f8]jwAѼ jTxܢ(TmD,`Fo׍gm]֟əIDdI1:K#̞sތ4R<<{j WXÈkehKJ?l/YD:ô{1ѷ3o5qB['g}T"S#lxtaLo7Q+E!~:mge Pg>4qU[+X6ф;8B%3jmњz?Jwr-9ӫZm7%D,1s9w}' 7o3? pռhSKK\۬zZ44lDdX+`߻)kkL5>wjЙ7_n<Te{wq2P?ھ; ՛zxYVpbu/'@Fi|(Z =v[:#b (ԔeD; n_6\dYw4nUs`\*]i/9c Q咒yW{nyNxzt' FRmږp֚WF讄dY.󟲢>-u4兩y)IE_0n"6pX"tgxkN%ξ}6zj t!K֔9lf+PKo\g!m_ UYct֗Ii)TXzf/1!fT!mg Jh鯈z#t?[cCUFPZ2T6p5(E6#.)n\N]9 }U6d1N&]&c8,bX3u2"Ppj%d:_̟ Fa} ΁3|#Ҍ;`n/VR:5L|DTgnaa5|'mt~#l( /UG˳_cmG' %pvuox2Ф+iSl2ͫkpE ?{6myԤ6Eq:awOw я_t?H\u2XfBʨFe/15FCD4~n&@.6( kP~fk'8'E텻ȓ֯C7v2ϸNSzc_Wvcǩ`R0^܍b܋l D>PXX/t`_ZW~m^h)fGl jNHy("M,L*#v#_) jCJ9XmaE(QȺCe~Ӂ,%G}T@< Ƣl(+. >,쉙NBuw=m=Bo 5LH,W ϣ Lb5qieJ<-(Q* Б&p"Qir[&OАc;-oɰ'4k J=䓋;4 blj66 ;Ujgղ%-γ.loyo^[g8#^9r=ቼp"}0 ;ٺ#=̣ TӚ&(QMK,o. ':hO aN&nUͶ^{/ZÓ{GRQ,#tIby_tm.,q~&'jE *W& 1gX+j~f#`O<W+*Г > CI2 Ke}oFAQ,QkEhD}}t3ׂ[KR*V9b6+4Ǐkh [3}An}U#q2wX*|=m0V SŌ&Hn">p+.*#.A ^zV)'#ԷPjH@&-~.@|ԫ |Q=QmN;0,ú'\Ua6oK/ΛӼG=mz˒,u ?|*bt**G*f垕![ 8*J(؂qcb=S̆j)8 ':;,qEy8pMW^;`h-hUfk=.CnIZc&&w `#S0,gsG ;kY%XEjh܇!t.cd-*M}a>H.|A,]5MVº1x\rfA'9tdh}ꬡ~rZrOdOGNY«(7i)>"xFxxAW&/#MEjTZ0 Lߴ߾l_ga!Kr6Gh-HvSb7:;9:[96#W!NJE 5A36n"uq,g"Xd;'* |P++$ƽ(l7}8F6P"7vdz^eZZ%,q ] 78ݿLni~#4NAWfÖ7u'F =<ɷ K"9MmHV3: ):P daI_tmu`-5nZu"aatvC *Vrtx\C ݁x8C$V-{Ej,o򠔄OT.Sc-,CNnp-rXlIRhRtlw39.5"z? ؉`]UVr{@9ZeaTqݼ' %!&ǐ)<9Z.qu:Kh VU(D>k-NG 9r81+@[4xY8yL`#=kj/'M^i׈ p< o_6t D98n1h~&jW{wvSBzMQI}gvL.̆K҉* "*| L'kp+LogΨ^ G@#-\ߋPHD%8t:SD/6¤| ~tarT4iZл1d$ɘHyX=h7@AjM\~G!<(z&QN [ǭJE2EK=h ıuTfR6/GOa^%^W[)VJCi]M3f@">yRfvllCzgje2tU[m]4$gg2m\}j"[)%7tz5Cw{:>Gx HKeLncX+!('C}Be29Qbe,] sbc`nw͑h|F=yLǐԠCc41D&\\G*::ȉK0HF jX)%ͱbi׻tc]zvdj< 59_oYY +>=4;,6"Y RhWp{_-QLzQ~KIQ*:Z X5]vb@F+[WF{_M$I_{hF2ӉXgZ5#l샡! L%v PH̍«-m{ h^9F&ZXl҂c1eJ52u[ hN+RuM˱It}h9M -bx%Y$t-[1j>MC.G0,;E`~"vI^~FEZ$p U%G@oCy_Kuw}B%)7VSC/,7b4-=n7;G t5eqvf7?[D#c._e>M;d똹_A$B_q|żxGn88^0/Q ThSPJm]~'7S>8Vfv|k}G$UI໫cτp"wώG.fJj84Hj[KݹHIR>nye?f=M씷J# V6fod͑Pl\s%o֤@S`jlQGʲ;x?upN$ai2vgݝkJj LE5]2*s~]AW  } 'OlbW#so-;V0d? xrs*f!Ɖãb7mQM%h(g{ßoS?O3BNh'1:MElB(Sfվ%oͿP;׈L4]Qi8~'zXU\,PH!.|2 ~Fر |w"䰲B [`KHm"f|0;Hʝbr54jCg1hKD%AyZ~TmR-GX0;QՔzs$SeXOm vQPceU'K&Ul %|XC64rfb'fDTgH 8*g#AL2ބIvNfUs")Ӯ(%K'^zjثS{$%'/ؔvITlq/~'47?9{GG54dnHbLȻVc1}T޸,oEUenx5kFUHO$)|ǦX}ޡy<M_[tgwV܍Fha wE ?V0_3 MoՀ~.,0Wudƀ$fȉ徶8uܪt`yAU슁wǚ/se-n Jд.d,?R)V H_]d=Yk%[TW NqDU#=_A-DL?$ؿ&,I"_Ue}OeҳAә;STeke+hhzyqh-屟]C'՛"z=-_H`u֘|t-y_ efQxq0*[=Ȼ_Vhz8 YM}wD9IRY!|9e챹iMfGB}?$74$)j<8Hh3Ξ0غf=Z3NSuBe@MeJ@o< ɄF(y0PB[{IxQ iU< aķ[(-_U+o[|&cmApqo:x4~/+fMl%}@P[& NO9,-WgWwnF\W`pə}%6Qc ;8eS6T^G }-5U#w$RۼdA]d`?G^kR-4MW{%zF baZ39i`FJq& h}AXK\Tʏ5Np2mY& vAόb{TP-A MD3kP~ ;si:8 n:E3ǒ78/+Fܝ2vO?4; 'z3vYm/-P֖K1nd:YXp:\aQxn5tIۑ9bm7)%=J_I "-׺#*pϷ0ZD7c~ܘurÂK98HytT7+Fd7TCeI6{0n tO?'FmgP }jѫe"w𔧦~P*L<1sr*ќHfbOjl 8_ nbv#PZtL uޞ%J$HZFYMҪ^1f ghE-!.=j-vc}=oiwfDgڹ G/#B> 4+,.g 5wRԦ#)s#2kV%;6F: ot^f83b~^I%9P`" E!Ws*|^H2hQ/SdT  RZ #y?73r?ݦawkhS8YlILQ(av 7ujD7K!7kf+ ߚyQtIk=bHz/zz} YM+}m,?)+l<IkJ .HVסN H ҦCo_;s)F=\hY;3~M5U5w sZ,9x50 7>w~Bmb7փk2 ӇNqz%R C`Mh2%H?{P3_HLbx1aʱGsoˁ‘N%u?޻暠JH 9(0`2ފ"0` ܃œ` ՙ_61%\Y5J\`xI,,r&4E֊XAoӮk.!2 &~џ%d==T_;2DqQ XXcDzϡ}}b*`:v'_yCJϸg;ID4XiS6h3?7$T)ۄ a> |]n#}3/I}`.Hh IҔgx6ꓩԶAc~o!C"Q%_#95G2GxW]DM 1G54s )5~ \+^hC]<OG1-FQwJc@b^lՄ5]E*eӎf~8O"?+Pwl@q´Cqeȱ"2 $rY$6ꝴ[ǒq,<5n tq*,הZQO~m俓'-M^iգ5O#[{2^Ȑz0k+sm 9ҫZٚ~G1lXd8]\i%$ Eڲ\NuRxfԈq#`o6nEeCA0TmkVO%mҖd-E胯8O[Xwo ;*/XƈczV5\5z/<֌0Y;#l龋mAAWOn &~Z]U}e3 KU>2d=EtBˉQ0αZ|' 9ϾFS=. +&qf|3gB #' 8SU&@&3S ?H}8MgG9"P1-e2wѱIc_~$/Eۀ7bYs XHģͫX|ˣ\<]m%qLcL3e?q}b14vph+IM*q!b®p 'QثeOZ: 4`_>v|wJr CNaƯ5HQTC-kg/2iyb)<אS b=P%͵_CrD:T!"!Nը8˸~\"5 9rNYhM|WJ`c~s[R料Sq#|YST|% .KAnu̾f9+S6!b ijk `% J7!wjz9~Gt-r7؅XCT'`M/ =D163Cjf?1Ʌ[8&& SO@4ܡ_'&7GvV&@%~::eeya{4}C#=?XFF 3c5%͢B.ى>olidJ%bHh4 2`ӟij$pZMc.Wc7ei!vŽH(%|MɝSjzkuc[kHͧ1q&7XT.\7T@S'Cc× 8[C0!} xYs+tJʎ訂{UJBR^'@70Urڥ1>CBګzEzD] ~RS|?YV)pV=ީG:áHM*vP{14;`?֛{3rEk8YV\d"?qŦ%?HK|R{¦:یkVc~2\! 'kEJ~']L5sċ)C$Lc 912A-M:nz}!ad';Pu/"ScQޜv3O);a&;cKި6$Z .$ 7~HSe-a[QM}fKt`Sm? jtl8ON&}paG|*šBZ2x*>Ղ]NS0 ^U}):2rMs)F'wBa튰hh3⚗W9$ :}FXj FSܴG0oEG5 aPU1sLmbe-^1 ]aJqr"6YD17F;`dn -$D94eG\df^۰ c `6;{73_L4 ~ovyārXHdN|}J:A TjCc;:vX51x`$'kVw) f9",mE83*x;ncH쬗-ȟ/'B|_CLTўlڐVjOa{P7:Q?v.Z'؎^\F<"z{)F")nI.e#XyL"gZk̔:p! d5#u]APP8ʝm3LIQ2oY:a ` cdCG`ͩw%T wĔw\63:_w CXh9mE<, n\dX+)|ܺ;dtnZ~}ƚ=Blऍ›JO%L4Wh:QI>V@0J4ͭvS)k]r:Lj Z8e;K\zMPH>ͦghb>be||.b]HOxvY 'sqh7(ʫmxa('q=r&k'{Ƹ<6=!;kQߊ,oCNQv&Z!$Acn[Ǡ}f;㗷 F|m,N=΍W"g x,ݷn<"Oy;t#fRVII-c=c9ra2Ir0&DT)!f\ftgp$VfqOfS= h&!a3 {H.lw?5xQg #}ݽ7/{FoW9byar Y@A̩<)Gbddr V lUް?NUPW bLQ86XNj.E-S c<)-" L=mB*? K(yS~;*J4)n͑M$*,X2mMv!Ȣc-bő1r^8{7D]h|/(aQkjBaB~r#w-hdG5ڞo 3ɳ_`p!i-0ubwlP7wakZ]j)zQN+u3&4:45-u  $ye_& )SCPz֋xosX%+YS%G +G;NQ{䏟e%eXRȜlE7 U=9"Y&БϽjN?z]ޕfDpgI @vPxi,[BI;ϧy}B ݸiѲa@phDĜ X6Hhbף&ii(2WE% %52:Ru*(at|PEɻ\[ЌI[,j,qgJqM/%5;+ B=>7Ÿtk0: iD\!q[?wW4g0tZ-d7Xa|>|pm&am@U*tT5~cf{S!!7#C1Poe}oG^`b6pTb|2V?9^4Dq 0ˆQge@E>|S2z, Gs埪Vk2b6lVý^{o\9nZ!Rh}ta"2t?{A=0hBveXPQ9В@Xl$Jd`"A΄f/:~LzF :q6t#v"VpD̊ w 3i$*L,<"\#;LF+]h[Oztny=-oikԝ)>'f0OZL!R<y@."PN9VIF<ΓR7={ 1 ljѰV&MXH`4,\sD?sK-XK rXR GG=1Aq֙f DI, s&"^[fX)`Lm$/int|Zd25}Hڕ2ajv_A˅$iunٲHg P(bV:7\ץmV+h z+9eԁ* fsl甡8x#W(Y;ڻu+ivC`,ɞe珇hlotf,vv8W%n$qCwEG^oA|6#EqcT0UO_ƪuJcE!$6?ڲhwp+8%k 򭝦! .FKL VͿk.r'n(JP,fC-T|"dܣ L_ c3BěS|pT{zTT&X04ob qb'5] sx<m)`DAq9K߱\[ +S֥?`SY:a5 R?z3LXH0NQ<Cl;K 5ACZpѕ^.vs2a <6̸XCuڃ4 @߾z,-΂VA"̪nچ7xvQ_H}u20zE8TA.5OML V` o؅7H9%)r|0PZqU͸2|mDגqBj|>)L'`W3N0ᾬdۛ~>?RB Sv3؁݊[n;yr'|hI|+Ǔl:%83n 5nQ%(IA3OUES(!=~;ͼ3 ,/tMM^H^_=70m/NT)O)f0;S[ g/n&$#:/Xk;F)&Vf/Cd)Ig+§w( Cyc3s8Gȓe,׾ӪԮ0d#8,>m]{1ps $A)㳻eK.DiPgeUd7OBͯ`ˉgL<{쀩BF )hЋ%M s~\yPZfIt{%NCg)4 l VX[.^]ր%FwdPaMSl^jՋvlҒeK5_lCe!u).]gTm#ܞi &4*D"2fk3!V`O1hSiPfB8*kp:[ձu(3sՂxk~LZb$Fg +2. ˶:a sNCTMR8lUtY!K uWw_Db/B@?GﮌSQ%!m݊koz{5mg7d=G|%Ş4[?QiۀkD[̦tO h`w j0n)w F{lweR"Wi$t3%Pqhy;>gfc4YL@o`<Z8snM}29SzeZʄ٤g BiϓR_aY#q5U\c̀/FnqqxE㊠F &/ilg\-6ㆅg@*GVK]D\c1#iie9 ƌ}BBwfi2(7QvCfG.3/u< Pi{ÏŲDM܅{J{Rߐ.>Hjnbba:3hr/]!g%&xm].ԽAt8JJJ*'Xb=(tJG3=ObVXЃݥE-Am_su1 ӆOG! b܍P\<9ԛB`+hkG#=nn{ov(N.(TnqRtک v+#ل!m/]%>xDu7&Vtg^LV+̡ot&&hMG|"9!Cm언|͂ϙ&m'ZVrQꄃfpы!!r&Eպ ._C#Kn7ǞF7o'T4n>Ղa;t4zaNb:z117p.mHN1ѹM7>)oi$uT*ڧf*  -ꗝ2h˒ICm[w>^~Ǐ-2kDm¼ks.Mċn,:?HTlR͗5)G`9  ,Jc F!xV 6ZXVS Ԋ;m3yftl# fv/ IfOy%NlC&ZXQ(3h5YܧMuX7>q'ứڤ?7,nTjY;O܃0+ 9q7Xa-E\8 oVd{k_$;qiP-R3PHn~3C>pިFY -}5V3r[:⊓>'ڑQɲ#/@M.~)x_p Пj>R̲_I~͑.t 9:d00pdGe"֒i}4VzL!߾^[y_"2ZXryqvÚcel^/+| 3ǂ{f qd ;ՀRKkئe1lјHeҴ:zMIV# n.WTxmPa#tgr?F[=hj;Y5/^ܷEێw>qof$\c.d^Di((p x9QgItOi-X_/9BuGmaLm0 ҂4vi r.Ɂk8 \̧ܩe un3/l33Vq":@^p/{#䷆ӷBY|bYWwA$?ЈSDx斐#4h)oc ⢑ n:!o=صhݽ l^z`(rzS  orlJF W?KN8P#L!> d2 3QWLk5ua-& | P5`$tԉ&yv4>ܓާcy.I2?CAwej_<>˥2dܨzNXPl _܆,n^S+280cNJ`&9v \4pIqF*ٮL}Pz!ul3Y Rc6~*ѐd /v[-O;HHj_&613 s~!6b^7~N¶j^٭C.B%KCؓ^kfjP+ ([ TW)$jR 87LWsGayb7t qDQ\EO~3ZMfƃS 44%,R/8aaRaJ L,ru_-\.( ${кQFK/rD^XfUQdm xT=2r'ĠljJ\؅ӵV9sZ7;Y1G5s E 4Â:ʽ; ٷ>,K+7b_1?]#FklaA%H^z}|i`/]8fMN/QJYCHL!Ay]/SF[I!zP?pe+(G"FHͤ3Zx\ӁULnAQ5J&W|5,5p{SW P$z \f.7Tos?3B G4GكtN="B/oݟNtOR}TBQ1YU\1ÍU_S F,+? }XMqIĩ\MxΑO| VB#~_;V ?ܔO?qRa oÚCr'AYݲݺ_C@z^yI,8H7kOf $pH%D%\eT*/0e*2ʱd 29.,T:!`8*(f$ ^IMfaDvXlh5^y?8B畆sEz׋q`~FH?Ͽ.rVr>y=Veʻo^@4*Q=z? ud=n4j6=zz\vI|W '̸n@7]Pg1[#JCO&URRE-nGD$j՛;]t\aCk ^DX}@SJj9W*^^OߗF@0P&p&ڪ=s(fd5] Ov Lـ-ͅr6q7!pb{?PFL6k#] NG!=QYYQ+j,pvI30Ԛ'>$-t"rj<0Quʾr~f,`L259Y*ܢe9^h$|gIES&8?s0t$EAZA!JʗIw[?7c er4F=ՏewG-"Ufj$"bawfōyN C?1mw\M;L[ m6` ج0r.# 3ZcxsrUp%Pm| lD$x3[!L5?ݦ7dIމK,[\_C@!5oҮ>7yav%]+%c)3Ylc)fҗ'#~7fT.5P1D<2(|!|cl$RJrACr\c5x;9ފk >s߲+y"vpoIz"ڥ ™gonaiۣ@(MI]BH{8. w]yO.iVb,g2Q"tr "}Q}}m)A˩7DAµe? S`'3`a]) =)XG 3&VkUyM `%mکgI.5悌lb 5m"F%sU/9߽`vjc?rd,yY s߶wS∂H‘4P0B<'}gf1ٱ~Âcgc:uB #'ŐniƷ=k'pSe^8 'Wr:lO)lsN`'pu /<^0YFՙzV4Ыk}b鴒Z&16 2 L2wsWܐ{p$Vי(k199 3``mypI.e e>eA5! "iMHDźKHNOH IW66='&,-ȭf>/ߔ];HC q?DBu+6 %[.ķK̈́>|{mp`ڐO;|:[)uD' ,n9#mK[C4+OFw;sk/GeVju=Am޽ѝ  oUقLL/ZCϛJkAi[oB`"lm5c`@1JFOf*uvSHo㒟C-}e)ĉL[Ju1a^@\T> W)&(s.1j0$: .^5GwE^s?P+ &]Q(M0WlE cKϨ'1ZO(~-(.u\@\Evwcz#Y@6b֬s7MuPCb}B #zuAW.jϽ/CK3gYȸu]eb`z`#fH;<޶^Yy#/_$)ľʩ<2 R\ pEKiTElx^kd^`Y^ľW-ؚXVj̀gt#Ġ>y>F:li&2Yܷ3jbeC!Vc7ެ2y4xu^9cxA~V_{TQ[̰jyr^~UnUM2D{ ƁI^V#hEMT闡@7se({} ֹ՜Jh>䪫bMD$kⳓ#X}OYp3z82ާOH޶;V$tR(!yE::y3@^G1niIPN7]Ai +DjQM\'璥늏&.l&k0'4lQn&3 q΁_ȿ9l6UV*+_מniS*cI5 }$!!0>:r"V:tW˓4a_ה^ (E 0Xc[*] ł3bRcIBfm0TIChC Uz'xl#{{K˨NU /H |QUfD:M_"BAe/շ|NS!ԩ1xDR*0T) +nQv2@N@^8l 쐉ae)AE,gx DAL*Z1S6=52xfdXفׯ Nɣct:!v9nH%]2VqyKRkJɼ"TR)s8&O{bR V\8 1tCL):暿l@!i _<6Cet0)6Ǻ(gYt34'Qu7 z}ɻ1a a]Ru0NE'-OaR htnU\ 7TF>~"ڞ*knjs6b zu#kq}@雅 \9Z!?9:(~B|ޘ* 6eg19+Y?iqҷ&~9XRK $=O˛Jf/Q$!64QĂK? ³Oދ^[{/H '%*>'a+oqH^D ϷQkp9<{ #i!?j(Jo,I@6FF>/ogʏu@C` oL2Õ_p@rۍ>^4}j\(fu j/#Oߵ=\V9tAl_\(f7w N/\QU$ E1.J[C1i?^ȐRc(pD$ibZVܮrQ#һ2<PK x5fF< 3V~d>B?.LK< Sp^W,UG0ذ;_b!.-D:?f8ieahG#Т)h]G&82E24c%.E8wd:/Ӏ)%, E&mP-X\0s-Vm $ \; PKzX?>JWwF"CrI= ֻҔmף=xcrs @Ƹ_ئ."3Vn#,u[n AEu8d `^AݘHݓ=4d\d6ŒZQhP$/,Uy=r+ 2~2)>0m]I.E˰t}3J͠_{ #3m)ǔ`͘LvdGorFSlV7|Up<:np>uxB2`pLg5gp&IVu5(|rFJt=i}܌t+~& dKr)Β#kC"֑WD:ރd\E8w)32v`ߢf83UeEOgP7DҫU9ѯ(1 M7caKwfV\Bdm%}0׫jVUǻ 2\xK8v pCzbaIJuj6[XX(MA˸DHo^:mNf倘.n˻YENaXZM$d<{甯 2p,WU99־7th-/E~o e}q([hPI3$H4Z ";d0w>_8 H"=0Kmy$RԂ1Zˊw6\_sJG jm'!&X`HѪ͙TʏlSY E0*"s|YŸKYjrI?1 iqcURA.iҥ t)A[- wq ?. UPX$:FY}c1n׌,K^8c IuHЎߥG{'b!]c$wN t[e}XwS ~@3a0{:weI_5}ZgmDlߐ ?j8EU b`[URdCB=zD?}c}j+bfDŽ95wI5PGq GgNֈjđ_ߓyϔ;TEϜ6I4lmy)rqWw\x}qe}i_chႼ@ORy HWZF%{}G/ <(>Ҋ'isʗ=aDZ+V@ނAlkɊv@8ʰO⹷,#"f<$ ҽEUe FuWJF-ƞ"&,&KTdI6i fף׉g;=/cdFCA>7~O BUEy7-L0A҉Wi2B_͙ Z>f] yoN>o~`>~,,YV^6;$]2,ׯ~/-.P> 6)zW r]QG;࣯+#ԍR\ˤtW#MVJM y,[߁" X=9o;ȅjHL0m&D봑cȕv]6ӝG8! (T_jB_Bf _WInҖQR[ߵ6G# Y;etr|$s)_u䜡@+1xu>AP"XS{{⍱mU}K2C"^=}}^l*p%NXΙ(EfbŁcaWwmxvj])EkJ,SѦJjk{4RRTUY,ՐS`x:,@4~gweC;l_?!P6H=au˜8nX,(C)Nq3Дe3M zfR@M ]їB_ 9iZ\j ^ED+5it:ʣEKI?SkNo7,NbbA>y r'j}EN+9t&шg%FÕxFl(rY(ُ7ħMݟf+2ׅ;$]T)Te 6!=mk8u .;keL"A+Gj Z ו"g̓P\7ׯerސ?7˪u_uQx-v}vUz.Ƶ0yk J1DsXYg#t!*)~( 1r-ۈ"ڴ蠒> i[x% ,!:@]ComӠP5PGunD/O1Rar`N-_F~b-tcv_.2vU㌑vRdO/S) @U˓+=&{H)c%N3S m*Tl셛wVA&I:v(KA~ًKtC zӀ'xz=>CƔ0;m.Wt&S4||@gXhWamc"*Gj`^[Blped/7S'DcfE1QzIwޭp?o8u<vM8e{`zږܠ]rIYY>b{@WY$R\U;?.۱mntt^0^- hm./;Z:K@Q%.l:oNyBp(c~>(i{GZ.!}'>?<pƙĝ&kz_[ &y~9Msc&ET wT%~A^pkyR>Z2^@Ij,-l&Ri|&B \ݟ46BP؍T) 'jю haBYo{rQ8Ac&ڝP`VJ2lZx|i-+" ̧%Pf\ˣa%x?E%-Gc'-L̦ue&l.T \;6)k] 3H&xI G;W9!\vv3o[ū38#>IL^X}.SZIPÊ"ku6tr̀ԡT:Q@:F%}DQ&5_ɖKVƧp8ˆ3%,d(3kҋ5 >Zu&3qRVQruhP '[#;<̝L+J/U=ꅜ-jew0l)%TJ=Ft"p`&<:Ro*ܥ]jH9{GOv\AdZ5  JY3qa1a C₨e~aӌWU @(O;m&XS@L:Eγ?I5?BipzAtTO0'6'w o/@".սOp'6-XmT:u%yO/HB$?vfeKSƻ'P>p9:wR2@mf*20n{[&bչ=4nza*;\@D B <'cR*ƬS{ .= yB;ʋĄ&0Ag'f1U=~["ƹǦh'=*lEz(@;0[3Z6U¿\ny#WΞ]\> ɪGQc1#d78HSm 3pE#h^J۪zLA J_]'^FB4a`g+2ƭer |~1}=,qM*SFOugK {`"}QfK`6?xtm,#~RL)t0htߓn.ISYT'Di*W"?[!Hi|V~̎~E+]bPbEy3$E1zڀ\K2ɁDAM^ͷ}m\U[Mȉ(N!~:o込/~R -N$ {9+D+>`VB1b r%i&o%!Swpo}rJGLxg(c;:7'm,ͧ&Ι;/njxJؗOJOQ&W'%6fx؃LPM66)KhVdeTv1*{5L&WÅQQOMVDApZnykl^6W!}|++<YSF\Ev̵NO>_~ yYPS8DZpcy/` ׾NF}#sRGړFeZS 甓SzC1<$=}ѨϨ˩y\uZ4|`Y>pCYtǏr ϯh.I"SE5S{l$&Σ쌣qa(6ՃK/Dy3ow5j;\Elp8z;Yvsd0:Y'XؗɆ-x"jp cM{F,~ ;#LVKvadW>n^~=cf|ฑsS"Dk,@˨fyڪL*}tyf ʨGgV)2{AHJ$ۼHZ枔U mS,o$v+{NXfh;LJ`^[t;GYԆDES$RӁFq1'3MjӗeCIBaw no~UĀ/T.OW*Sj:Oo`l ԙ 7[yei>9 ZN;_WР`i_h'e'?]0(gldJ(lPV%?Z=D& pgq!(a&hZK?{ƕ&WK.˖@Q|Wr͉IxX%,{ 5xqR(s?Q7yİ<4+㝗Q;U cP_Q0GEzn:B݁c4Uq'ͬfMP/8X}?Qh#KnB>LztlU ^ϋmr`I~e-?7!U %amp]^&=;{(r&Ltؚ::0dde8A;'//e:Ԝ (Ӭlny]ǒ:' _:Fg m4 M3E#i&AٰDS!.Vl |2J463mJS}MZMEu![J4so68@qI]?n騹B!t!zטy:ߏ1L@n 2g Ο ~Q` O` R#bJC7} 2Cն &6/d4SvHD3׵wZb"Y{"@( jZ)p]'|s+rB_%ؐkS;&1^ B$8-Q.kI{cd_^d2F .Ф$.Bz8L*w [R>wJp͓Ea,ײP5VѦ]w n#Gl1-|=+9]-ޕ2ʎ$oU`BW=Y o nkՙn^\wOR\$RAE[''(ʈކA=i JZjbs͡T #Vu<" z|KbxO` b)_@3FKV Ѥ:%n@5MV{|BՖU= *Y??Rb/u{qrrXbf/s \h om.~6yo;ccQ֜8׬j*1Gl٘,ۦfQՙ9(>Ct֣m?IrAaET.@#NGrFxTi߸,~9>`#3m|>֟<7#'PI!$G Ydv:gdǯv%߷>j,iqbL} / d2S;St'vȬ6;I E!3 2;2}C-vVA7߃G|4H{/feD# ֤%6H/*ʉL?d]M-os nN=}OI4B=w͵f&_!ݺ^H @]:O^5Zcngqʛ`, 1D$Ydbi0oLá5P_{IJވAw"|ڰT xq0LXk¢~ o4 CmѠNn6f)`: mZ5}W'7PRhWp!"4k(BQo)Yjjư&'`.\R+j!ݿ/ɈP*o} nƽVS T0B3qPGgfvT-:_&*ʙ$cw Ap$)\T V,xlL\4JߨG:˥TB@.f lV# c~rЩ*\G"/EX$ q`5U.!`.lh f Qq RߝJlixW5Xk #Jo2\0lou5TkNEHoA]X=?mA쌊>Gs&r__ C2"65#ߦ \h%ꟁ-T[q$30]څB>lh#ݖ x$Wok`wpC"®˰c E7kߗm7( 5sQ{6MT泟SRɏ"5 ;Ro؛a4SYE#P5hu[ޥnfW fD Єؚ>PAAxcr UqldI<|SSX^df:ƅmR;:9a_mTg2:OROI7FIrڔh툟(cG£ڼmg2 u?b[U;&5R I/Z{^oO_#:%XS h$f K剃sVf"P<EcLHR椯@}ob /mIɀiN d/ޘ&7=Mu/yG!n\̱|'RȨ~r6KxJg9D]_f@^1F3pUk[[VC5l\#yqRA7n ih=ݰ[{L ,z3p ޛqYK{x‘| <';#KS+H6ftDž Tr&֛,?]k|oG|+B'Ŋh^7H_3YOؠ!@uLL..l=N`ucbİYK4dF Ϝgc7m0 e Omj e|H@ů{Nņ HIҏ4>Rm[(=A HϻJKr^ӶEm;};787xN$TT^2&J> TQp񸰫I*1.=M6~DY1X `jVZJ񒌭pHd)4&4)rXU Ns79ZL=Ǥ{,,uR_Qv^# !yl9$\r"2( a4*Kj}`\ $y9*'@sMm`<#ELsCj/!]z'c>bHp޼FwbEqDӲBҷ·uFf -Y=h1zL%&_@y"[FCI˯uhGe<:J_*ʁ0dkJ)&3+{{$D&j'+B&_ѪF;2c [RT/%UPC0ƤU$i Eٯ.4/{tlN1 G̞<EPuٕiΥF]G_hF3!8AwvxqR~>=N`ܶ.P.I1Yf2wqko xt/@Ir?OZPʯaEKUR*({QFؑfJDC06@]ŹCZ 8d5N| xl/&-cp,X-)5[Jw˪ 6%YQ~uʊۯ\8rr)bKm<4n^U[)JFYQmj3@to -LѦ,=]#R/b[ٯA}7 7pJAsz-MN35XGKgm'@hmnZrDtҝ0K,A9c"SOζDqΗ8TMu'Su;)ԕh`[>2xQQ904v"l\րa Ҽ˱xa Fi\IUݴ s?mâiO|AZ7Z/PLw9i|NJR$ FP@&Z*u%gש*z ~چcz "^4FC88 Y#qzcb")jĉ>][bg0|Ef1`i9z _Z \nϰ}g p<$r̖rz3\3h5 /:f߂kZٜiM``a@^A->",5H 糎D&2u+LƿY#cc}G&D] 2r VKO E>[# MUs(`m۵iԇ\4L4_oh $[Ʌⷄ9.H—ΐ Y! ]yEZ27~}n'L"H̓f$`K[PAˆu4BV>}\˝8k'A܂&S@г&n'LiyVQ,.?oyLWx&eLV{C}+sK8-8?h㯓D+mMxso*.SFeƣ1pP+ة KVl%rf]j/K;Zz!m#sUmd);p!7 JVkp>M7OCtP5ۈ^Rq:P(x&~(HDÏLST1;{ 2JQN|ǘA4ݕ(` b{-B˲_X w_xފY|`t`Bnǩϯ7:m5[Ry\'!,l6INե9~-s˘C{\$+Mh= (fS6c?[TG+53ْN=\pHh2L'ìEr >^,PƩ֓gg)ŚEKE#l/{ڸ|05v +-ɫ.7n8YB ?ɸ$"e 9137M&{tLfz:LnGWϣF2.r9\I3ۈ#³IFd:IZf+q P(Sp ïT4 SnDf ֲɰb3 !#]/fxb#d/2CpdE0 cHDa"%ak)+ &acQa)F<%S6HU +]*&%K -8"~'r?Ǜ@2@K恂^ua t(6ږg1?A@u?D֗$Scy9uY])HP1zSb?tDŽ̺fjЃC]hAddQۯNf[7 wum|^ +%0U_"6hW\2\#r oQ |,Ug²vhFzJru;e4I_# :̨ N|U`WKnI ~ُB#I $vWuZ=FO@-j'}ocVnE@iDNҮ(DBԵ>~+21@vqoj!$ʀOak3 JXeU"3Sj7/Oܠ^'&a2Q\VsG t(0wolB$ ӸTh&Ub )ӕ lCӀ*:L1tf C~p4p0|pGhυ\Y)אvt^䃜/oQ7‰G].04?a#kACf,z$Z`$8+Ɠ[}^,e"X8v=`P/;lj>U'yo@bzȮ9B^ޜN,~vC R BUG.o:iZ>?tj!,+wy+6^F'`̋ 1L-pٲjtgW[L{-"T齽2Dv7'.CNnCGA[H!uw_q-w\֧Z)4~|3+yR-."Q5TcF OfS䪎 1rKXH0ݛGTPBw`rPҳ`01ndE!<2!R'P{E&lꠡLO,0/Z qF99>ΚJTCCvlEt?5cJu %Ei%*S7[A|iBvˊ]=y(ᡡt k Df&.]/^Obա'jrn|& d7/2 i,ߟ0gz5Y(KUeW+4ΗLն+g%KiVFqx"^q50<P4ʉ"\7(R;r.]pO>g{"}-t"qm{\>y h[)%U5h$dc3tX r hNtMSS؊T;c'7Ӑ@=!/̮WA772UG=.Fl;nCBfm靲~ j'3>{_vC!;4DϳR&2\b~53Rd Px`yt0ܩqW죂 %_e$^g]>}mUk\@vI~q "G&Ny'TEaImc2Lj+70wB!wJEqՀív_غT4,u}0V˞B'"=2XRӤrXBx̛מ o]D"I vKh(qzd9ؓ x̮s p\hN 9([5)s|{m;\'Ъҭ}([#PH09EBmㆥTvh 32|_)fY0!TvVt+;W;E ےu n]vIup&Ր X%!CRt(y$Nt"(*yҭlNN^='CroF-pe{/j<>ѩ2V#yafӸ "rbFëmEzp.rEfW{ y^ՅI=LaRhn, 9N)!5 Z<Ą 8Wϳwa ג:MU =GS$bo$Nj/RX4qwj O';E^ӥ)};KR, DDJ W G"AqX#= rGW>c 0q9]d!q:Gs _l3 )Yzys;\ ]T%>ղRiIŤ_i>Z9ۊI/q_ xu@IM4NH+~Ɓ01& *p",huJC<a =P/Kl&`7_~"S־+Pa k#W, g{}J(bjlfAN)ehGEpHzN⼄]Q/By2RT`y{+PH Y.=Ӏ'33 Z7hBWa+,TFcs`N|sR2+ՌH]O 7<4tqRng g^VUةnPo8y:{bq(A;|ݲS}hsl,䈔 (JDNO^9ٗx״"))h*9P(gE$n@ٓ{jXlnRUǹ΃IdND=v}0,+ fï"R2#qj'.O )z9'ŹjBizlfCI; RnSxR9.J^Of+s]_tܖ~w5/fKO {ʺ l[fgl0[UC<Ą1֟=ph2a߃'+jҨ ݊%Gwc$/,ZOCԳ L3%Kj(06FC]SیABvNooτ7ZQ2QL^c#̬ߡ"~(utrx 1Hh+'K7񔡮yC<3 Vn`8GjHzDKq5 r/r3B;|;XSvxbQd jJϜX96AR??sv7FU1G';n~i W[F3P 0xT!]?!BH3o}GŨ ^-ٍD TnB.esW*9fg⪙"|eu(qViY_~Y `I73!"aٶYK1T,i~)6e{HM £mG"O𯮞'xL_ YzTarp2jibHt,BcW7Of/jd]Nwϕ+}!;tMVVSxc?1'aja&W {5OoI_V OGz ߭"DHM^^\髶#c)hئ'"DS VYV/s1ٔH`lFS&yIw5K]&-"jtKDI7h#rõMsJ[1k_o+ ]jNɩk>4 &8YeZeVF&J@5zV1Xt-j&&Ь5!NIMxg Q¯ _SX5gt ??8jk/r*M-O&NJ-_>tƗ9vv|{NHEghҋ~OgJIݤ2#B X :yԮrSIՓ."=3A G_u@g :Ȁ& SɊS%E!&33\s (0CeӗCU:iʒA:_gL5e n{fx¥Ci'%tɹXZߩp]nFWq!}Ť1ܪI:QYЕ6(ȯhxvȘ F#-P )FX⢡{x V9u™[qa>ՊIc˹]_36!8!uϞ;!uH(a_qj/K?!i8z#w=5 6mC)/ysfmdL͝{B}aRe,sM~xVe@O 4E-u>BRUk$>t8߾n]1HР@+*@6H-Ԛ23e뢣 Ӷ\(S)1V[ѝRZEc[6 xh1]~ c{Bo|q|$^I) '(>weR|S/?*;>~1jJ|l,44-?٥G1X BQfd_KqⱗEk/D 7;<<%#иJ!59RC-N;ay¿1[n'JD[ g|(pCf=9Ý, 3-$@3߀H,0ܵIextq;Ww֭4w)0X/ceA& ))0_d&W3Zf FZu[) L}Ų/~[DxrCS3ZUɹ2_Fꔖ >BA [RbW мmu-]ʗ˗%ΒNܧ{rtw vNρ.. M90O]+67r9n.\2W[PϫFtIx((aHUf|WGRϗdC_QiXWCbV=G ?_'G?WHܣKw[Dxe36o>)4.:eʜ}lM"gĹx/L zOvɜ Ǡ0Xy 7$']k-0NGso.J? 5|YW|3zGCeP eC"z5q`!2(zN$ <5 A ':7I)tpl !KA(AQ ܛ6^ƩRӮJ0pT,҅g>bF0Dhρ(|D[;C znD;8ixKty59beαҹ1Zh8aZw&Ť[SіG1ZD ,4w&eT.-]HT 6 }}'SMK"Hqf~>QEgb+za@ vr={ XZB*'$B)1z8Kf_}Uw:_T˻1/]|{.=ax9%er]@*e>ՋXCBx1/[rJ@3/4 d ET^藠Ol0gmڙaܸ }=MLHHDjۿZ Vו#_!l* z~!I~L!> E1m)(m=q麺cқ{i$mK9ó5;S -Xa׳}k U͔blC2~!Jɹ\(P|&CyeЄՄ_,qç_+@9Břr)ێw;vws w'kM't/&P|Z_<4`*S,jY%D_v0u=< 괓rgM`Eټ9uCOcӱ>q:H cTӚFP4pՂ[%Xƣi! SZC8~]U,ጡve+t uѲ)\ F58{; +k>#Sc9͑ƫ$&Wl$!χB_+@{HKhߘp \hӾɹ0Qܱװù{,y=Q(?yȽ*lFrfTV|bhzł! ]ALԘDVK'ӫz${.̆5,,nG8(}i,{I D50"IWI8mb >>{֥%)l5~$rRBIUhoX7 !50]Ԛ6N2U[E`C' ]|l/,G(՚sӂOۯ_B?Q(s{U&R]pbU&xyTׂY-?K[z}aWC6oc9fgkH7x h/ċl KGԞX.b qt3)IRy0Wo^Am|R7 ldv:շF=t- D@-pgT:K  pgMD=G[W"Ag&kXw1 (GkQ~ΟʫiRld|K;yɦ:5t6w8sAi_ΥԂ.TX#t>L\ 0]_|-IY~5]0= 1M﫭AǪ vgX߹s9R`+{哳9qm23yuVU`=B0]B> VG8 v֞V J'smr?=e ^::-9,.ܸ+xl+~lѰ~g\kIB|<$ؐzs]1MFY#fG/B`e+|Jk;ayх6Q+&c+K#E^!DbqɑK˧5(7UoKth2ʾ5pW䝋VޝMB%qgc M=H B*_ dJ6Ѭ,cXf#! \4azGl85B_c8 Wv0bI=ey'8qSCyh~.jJ]N/x3@U`Iuvˤ۴ TeAH_NKALVh)i gTtY Gp/X: mIAe/Ε.mE13 pu xa%KYˤ,EyYF;>IucTȵ'QQ69cswPqYV,/Cs]3#]6"c6-h'jsJ7$xOAbq0GEkτ㪽b"'E w(VKe#?Jgf14C *U?9#zHEJj0䣱6gm4}RaH tZ Y%i+OL7?cӽWQ0!,+FEP|c"Fcb乹Q v;yU\KӎJ$ŀD=ZuyKz#2F91Ņ#Q[i{<)rPzX>[ #̋&mC9՝ECn~)9)briVcHTCpmN5V}A 3S⇇z<^t#} 9O>@Ba̦&9 R\sZrKkpͷ <' (svFg®o,&^tӺw81zC`ݡse'J *q6^(JQad%uRJt08b8_<{Q@bao)PTut#b;` eš@B/Sz~eaU½9oǖeYd}S;B̈́M{Z1#ru+Q'ӑ, ;+-KϦYtvj|96V|Ɣ"m^cUfh{Tgf Czw'"`V\DB nORCu35oL*AO`ߡvh"S_Eu$ju ;~Y(k+Diǜ|Pcƌ.[7(- >%vE(.tCdl$:L}q0@_b!*Lu*mK;*`!Y]+[8#:xլl#Պp}M>d~-'8h{Hspqlx`Կ}*0z\8iEQdZݨo@Pw]ΰ5 uоL^OgpOI(ڠKh>̍Jzuc/.lПqR*'RNsϢ !rdhk!4)ݲah>|ح5`oC)4&{!ds̋nB8YQdK }2;x $ уo7w=MO_m pu7Mm%NtKꛬv6DTE#c,h9yI@b%F@Zǔ >oX-B2Kffbf[me& BLmo1̇5/;qGKMC{"CG>J8wro=e-L6APq_{,c lUa|$]E^;X̊R35,)eijv4i5Z}e8Hkm V1ޣ8WGr7\:* ^LWjk )Whg_`a*|2xdk?h  5l4_Ѳh*̀6yxԺ:1'936Q`&S"7XW?$cXF>"ll~(kmn2 Q8]l! T/ܣ1i ?nbh/kEܓ0Y `Ma2X'*(d>JƚOY4 +tD~!P#f$L#6*ޅ(Y[dhǵU/(Q1qiv"ƚٻ|F9!w^4)ȸ%X7y %}4 9[ -b;v\Kg ~N{{[.2$eΧe#K5(/lOv$7ŧTM j \&^06^ !i\%7:"I@ cm <֑v^jO`C$A.S g8ժb֥>[EQ~)Rq?i~nLZKʲC- $ 23WYo>wDhw",w1_6o[j8\s1LX_`^V^¸P /oIQ@C=~}!jҜx8*d %>Kš|hRV%N >};,D{#^&x莙4XlC^\@BxCbU꬏"B KTMȍZHD 6Nj#eci.nr' nӷ8Zt|N/q]Iu"ڋ4osp|4='Ys5WqMT;(b(D&/@[\n-p_4T-J XJbҘԂpo[RZkXJhJE;ڣ^&up~P 7>ZG@+[ U.Y+z!qZ8ed-ގEѹHS ܓz#u`z#3ZN&-t[˳,ɱa8hQѢt~j2.&Ca ,T"xkc:a7V5[p,fUYԘʔHθLӄּvpaaPG\#..4κ=:\CrM\ |6Yjɘ  0Jwŭ8m4\'g =Gg>Hx{9z̔\ UnX' xw&y5:0/1dF, aMWɅ۞k>z"5$r zZ`+3Ț[sJmꢶ31-yFjPʱ-$.EXh`"}dAz'Fݹ+Yelv7Z"8}I={ks9^K١z$n/ۿFq ^Z2G ӀuwR֎g *Ё|_j Z ]|iSdG "<j}64iXLTF<@+w\GE[Vv鑒$裔ݤϗ<Ws-DV6lWIxrꇈuEI&xicRqiϬ rH\?M 02dJ=Hb_F,s= n&^au9$JO%xINL& 1mjZlkIv5C9hf9U:SNΩAvm"9lO:\  U!*|8y kWh"\Ke {v)x [$4`ffSUP[?8z$W7PJ;vwӪ$!SM5z'6;d'8ؗNBϯ#i/ Ӄ9.`gXzYgLo[g#cB>McNWfvH3p'QE= 3Fe`5>.;b7c!+Jw b-42#pd hՇ[T ѐ1qY3z_uU߯xCi; Mc|4B&霻e~1VVUTŋ@$RQ8 {ͪ"\}c@X@Hl2a UYI;JO[ d{NPޣVhvct)TO[5EWQMȥV}(࠮NEB]kM+M ;yp:8΃60KQqB JSH9p_Cև: n;XYx:r̎=} ]2ESH)}(`(Bo88KD uI(a pƜS& 3#M3} N)kl^Lw<|!,%uX>"ȅ$>dS*`=VvKs`mw_U10g25 mfK3 ŠV29Ck}ߢּ~,vct$t+j&  *Q[c~tӮג1(㹈NsUn/^egs lEd~=_HGؐ>#U _G^$Rhz_S<\ '15P# ȓ_X%yo~73 %zu'T0R:x|C ڢRB 吓A0ǷUt)0x!7eqilK L&z7D)!)SB5p!ʏ\( ͚IYr?FcMU&Owލwq@߶uf`i _t,ĪNlSƜ9e 'ETt@YR!'R%1߬흩Zjv7/v>*0RNW4+B]2Z(ׄ+3}4:Yy}<4S ZJʷ垂:kG`=ה`g;-Ibvvc;Jֲlwk,EA(fl>Ul y3pS5cQ}KǢ%oSMAV|. IEeGx D&KuX9łcx¬@4ns ʉ#p.Lb ow{FoW|ku~K5/{U۝(RGp8۲1<&v߁t~\8G T> Y-+@&xmwK t` yvI0_ =1Uѡ0+x4^6ȓUMtp,(FlFze`~w%Jm\N7y["&ny;&ᤥChbhrtaccR+$?[G7  WJYmL7=SGDKx>%}$e޶Iy{'Ӓ}Iԍ`J7#.ńGHZb\a=d7%h?FlTo".3;=MRfĨ/vO.r.[eh1ea\@ V[T =;,> chlfNͶC8P&f:e'Co&uLWؓ)QPPTuyǁjwq<_@gqL=l$% ϱ}~`gʀu)JJ9nAUiHuú͉BBr`UbvuE"ɴ*^ `Bl?:80t^ҏmt<-5-;J)y2B8Zy,׈f srя =9NC/H; e% ׂ>4Zɕά+`'zZNmuFFPi Ĝ)^"7^!.$pSd͵YVN; $e3r;.ܚl2Y'nU0zuESWax >" 8~X˹6Ժ2@12aBThc(LTb| +JܚS Xz;wIiq3G虤֡/j9Q8P$r'RzM.gşSYF4 r?~ ŮpN^GBX (F E S^&-|'۞=!c$1_,h<:tF讕̌<(ᒼP\N=,,_2Իp m;]xlFå vuRc$|:I^C֓hzVVjvjG5x H-M_$?$|٢i'Ҧ*u>ی dx.B[㔣?ToLRW"ԏJ`Yqp4I,jaSw҄M 7JmKdbaGͤ?ց^?{?!x\$ËyKkZ>s%?֪WQEpȓz3V'21A<WIi*SgĨ#N҆>zFiw"raV3%ϻu@ `jf֣? EWǂ%];e5& LRlgԙHk\ SOo,_4^:f #D؂!|;6iDIix<l5br8%&43q*1x-ƭ()?mE&H4 /&wʚds4#5px<7t`9/'o%q9icm)9.2 1GNϦC岣mTSkLZZ]zeVE} o0 dfNTCu.OM\^o$԰HOJRsՎWRÐ.^-ۯޮRpe9xGJM !!Md&Ψ4]+HљӼ'L RWlF υs춮+ =I0$e@)y^0W*WЪi , *+G?895zDsЈAᗌT!MZE/{49 JN-']3cӮSpޚi:ZmDӁ"fC[T Eɠt+.G܏h[wtx4 IwJ /g <GQG# ݜUiAM鯄|Bwjuԏ &\i߅Nj+hXg.Dڡ q:Ek5c, 8׊*%ۖ4%G$0Vmj!7߮V0݇w'Z-0{Sq"6G5}8,c tXY3#*EKȣS"dL)P` ]/O00e2~"S 3| أI|0$-" [&J΄ ϶aW?-.k#PILKa"v%5FIƸVN ]M}!l=hn w`$`br3 VM0.WܚoQC) o sXo"g[zsDł[d|P:D0TxKdg5 ui, \ B]fﳄĕT^@vvrw_);z L ?:E(Bub74u*Ct !pr;9ls;s7Q"wr+:ٌJyjɷd;ñSql# Q \NĔ֋080_훭{yL '2(ob/PH;oqݽ/]Yf)BM 3+Ro=ZG [HX-c4Ss4U .ԸX`xЋ̷2X(ڿ6 .t*&Phɞc<NEuO ;& o,l4 v~]b՛~vΕQhE'2_zH0Z_&z}uē|kt7*EKmnmUEiOe1'B7;Cb蠈LB3c{)0Ý;aQO 'EW}(㙸3 ayϜŸ]]E,c:OP&++iwikA%UeK_i zh"H&~|UUGXӁU 9r'Pqb9A`مʣQY5(cm0VBohSйnûf*v7~20c]Jw1"Z2^/E^îCaCnqPUHL*`N'g=o(yYR<ɗ]?xy xxZe]Et դMopEShlA(_̇(Do_ƈe<*ӯY `;hVV,fz͊P'&6E O |5>`#s DUNM[vQ\Ԝd^w 2\_oN3YԪC֘=)89X>q9].-z;E_}>w(dD5k^ ? %QAF ,+Ko yPcם&lH`fHI 0}pk.ɌPHv"/llME7j~=ܿ GiY|vI'\(7W"lIրD!B6w=X_Kۄ?Nߡ* 5/P Ev2+\}չGP`j@k]"ǫláɐuscy+Ƿ Őg.ex/Z#dos.v7s}[M%Hh$g/ũ~mwZ`&7[Xu.$<ĜOPtu@j؈H†aMv +ܼW81d' U?}t(َZQBJڼv~kr՜5x oPb{~~YKgYsnA G~31׵5Ӿ,J3Y. BbKPeBh>5(>,#^Ie8+lW"I F|jd !|Ĺgo%,iT.q)wfu]1Om$`cZ?3+dCݣ7~ A\eN$W-H(ADd- el ڃ/'v{+|aQ~%^5K 3M}pN;Z)@Ωco6eCD>c 7V,f,3qO9颬2÷W x:C6bJ@ i׵|fb(9L7VB 1k GoMJ"ՠ$9 >S-frv'1n)aJ(ۀ!Pn;] #dS[0g9QEp_W}UTMM͓ۈ<ҚzIQAKk.m.~ r&UHYp v(e&Yئaљi'mq;J{%䷮_M9椼\?= udʏdg4ºѽ[/{@;R m;DQE`kת,D%Ѐ "3;wF|:clfNc(So421.W3ЎUrBƣ#uEI\"!Xg(ShGH+EQǟHEC5 XX- F ]MYLš1D^0h(=TAJwBw0B9KEo,b_MS'Ǐϋ_8uFY wFc-al,T!柎n,iZuiԍ,F/vNŴ0 c 4>劚ħZ1RGQq_T[!=T"hc"ԉcsosF1 OTU(&bk>D+r=tf!D?`?W/^SUT/r'1^ ~F˚? %EњB꒤__]{I~bAHn,Pd3&Ek)*CMQP,N5tZ." h#.uJI 355(鍍k<픻[2q12tOs`T6L뒡Fm{lLK¥oeazNoHu4r5l&9uySVݍ:{1r&M̢^ؙ-4mU~jf*`p|'"5#jj B 6T_bi2 *ϐXNOgͿ+S(Lp%i Kq}5 /d66JHS-b } s>,jį4z]rV6j ƈ=h%%L<:]O/ZsC,hG7 Zi+;)Tƨ>b^7J%\_$'Xg\NBdl2i\Nx`"=oCǺ5$ uP5 ޓ:iXK8l!K 5WÕʔ6V-3㓚_T ztҲ?Fu2{t-~z'J0{Zc=$'pY@ UMPZD씮ǽF3 ӃeYS nW(*&wad0_$KEl%9WqⰏWCSRnOq{Yi O:o_2 kGK  z÷[KL7dΓd?"?2>xZCYL:5Ԁ!{PǑE_`aL;JGųȇΐyifjrX}D.uj)޾8Κsnf1uhߌ]ouFmz[v3 JD8 LϓttΫ\}yiȯBcENp1^XV5GԪ퍣rhyF}pdC7 #}G)rtFM/}nE/g+SX*[,Wr) ҸZxG:`VkcN+}uwCMF3cҫol3>u?Qq`g>pBjl+D*~ SS%Qe#9hW2^dhb.RM@9Dۂ,{n.E`nqGWXvS7:Z" BEkj: yPuili-{ 9/_eM2 6DՃ\Ӱ\yuʱ(zڄLd+~bZ ntM#{&U\XJ=̝>l0a AxE~`f՜ʗ^I;jЉBa2'I>51-wb'͛Ċ:f'b7~ eKiq3(=Pᄑs-d~swUh յ ᅣ$j-.mHJ3wT!BF{Z `R_\]ҹwt)I}\^$)/N"[N,D@C},lSd.{՞{u/gpH| sџg[,w;k||"ܗ u(Fce`(L؆l =+/uX|Gk[( c֨ 02|ʏrR:֝v[7cƫ6avbii,!xw9GY~ؒOSZk1{ 7%*a[ftÃuafF|DyR;7U: D cZmbX)EYxG`g3i <_Dr#VX>¾;uD`4vB[_ tI{I:O2fgqC6M"$کm;(SBpN֜m{ٻmfá{*!jN1;Bڽ3!-^Q@]t5QdmyP(ɴta ] f>u¿Oǻ!:mf˦Dmlr6פ oA]|Q+='=(J _"x qr1GxP(1f gkX.T>!Chu4͢8en;ޖyYuj8Ur@K7>mMS`ƹ~]_" h;Rv8"4>-IbOkգoeIKwb6uԲ@Z*"EEyfQ;m1Ӝu뛠+붧τ&I|y+l G@eWY*Š([WM6r7eϪ.hh\п.<ʍ(!!%e z"8]U_щ␴`- *&q }ŁdK2nÑ!#x<v%3<0hC=kKR! 1B]ʤ8 N@~"]Z:E|qbZ&Tǻs} lB||ksIm~PpRcuWc/&j>} \Cb~"Mb `t[#vdg.?}5CAH6}4Y  bՠ.͆1e_eH> ar4A6!B΂us;k\(jg ƣ~m61VsLu@lnhPc&,([CV4֋$ SjKeA6v\:ymYՌ\{Txr2cUf>o*_A>WIzԘR_CT4hQi9!I=y0[R>n ]7&vF[Uz-?7gs*%˄>i?*& ۛJ4-|Iмl)MEuHP9[(Ԩ#յK˳H:+sFcq3jF/ܮN"x>5vo9 ӜhcΗuĴ>c0)m'm`\rl>л~q2fbSK}8y:F[R07Unv$0b 7Eu6=/Ɋ@-4 ''A07Aq5UgF S0LZ HԠԨMq2.jjc@k6X'F꣤9}քXT2Xշ&/BbAxEM`?9oЖD(Kଃ{)6Aļ1,??NP}GXE3ž'<3XЭûh ?NI o}4XBAPK' $]e ܒcFGm`8V G}4 0m<\-2 |j! CEIϡ҃n3ufpߞSmn,`j"g8yH(jI%'~[.'=R֒I*cQ"I[ JiqFDPΐzPQ%l']Cg|l|jH8gಶr[D<`ւT_9Ψ.Fշ(LU+2(^w'W͘T( No"$z9N8څ58?6xvJTM,3í՜7BNJ1~]bPÕ BH*G\O7<@섚LqR:>ؠW/)E5Xp}4x4$UĐYnbpn0K5 ~֤E&#UlCAX7Z "ɚTۃTf&p~ummLf} }kl$+B4{Dp/JZu ic@:{bZZԥQVxVn)ϋvUD0~SvYgx.jxӈӝzs"Ş t*C c,G2qvRڸ6Þ,z;$sTvB̍F4mv{Ŧw'|[0H\]c#4eS[w oIo 3 nԵmcK^3=qu-Wh|hVqoEM7zmEYk~ 5.zJF`rsG>Z-u~{nm Lg?7}l2jqʗTPmbˡg]ى׉&neep{d">/CoųakL3(} 9f),|Z>A;/>4Ҕ9g 72}Wn/zUcˍ~qù=4ì6]ȅp EB!I=9^=OEy>OAc N%Ÿ3⌓38Ud?  pF^S ٨n|x A*xzD!E8']-?+Nײj+QEyB WzMZB>":S;!F:lީLS %Ѥp'Z&h}HH8HLp`fh7y2 {Adr@"[ yV:U`bOyP2l(ң#ymW%@fCUOK=ν!NN#%[ikOuj,sSWTWx>uIAg H (?PB7duV}f0ykig6.S;p:> <M f 0[7U8Nyq˪վom02W⍊Bx͉` 0M2eWʲiy,K|ťLf 5"4Ҷ؎ ,O†Lpż?, d74tH)ͮpr*NFi!ڐHzm ™L劼`Yf/GXvlxzub Cciƀ4}븽O$WHiCw|h/woCI-'\VTgOȩ!mW(uS=b e|lH(4f?~fzvCTc`7X.jp;Jh!wh&zlryO pR.2&Mw^t ,a6HF=뜂fJ?Z5y!$hW<6fsD* 7y_ok+KNime1wJT/>zm ƞTQsjХW ],׃%J}gW4ܖ !.X ^5E[yma3o]Vs1HvJ7>XoN ߲֞;t[:FR- "O{~hh\Sޮq'M&' ,0?7gGi0Aw(rp٤to#ҙƁ/*i*Y/Q`C~1ؕQfSg;0<Ҟ[*DpɵJ/v֙,}>Tڴ4N}J2WPGlSR<}QjQ6Pf `qGF"]6Tu~/ݾaUB'JG=_^hY>mH?DF>ܥq!HjFNd[F#zK=ff:Yhr"\ȑKUiIo<<:obmŏ -6# nb01勵.zBL!=7 -D^0  dS[aCKɃ3]ےGƺpm E++ jaü;'=^gAbrK %F6^۪˱eugKɜC2j ݖ=Mtxv[ :{O>0!73*yX];pD fWW?li6S0o6kAjM;/Aඳ H PւǠC!Yq_6i #79 Q {D96@,AA vcLBo|v \j0 B|{X&ILx'o c$ə]Fx{awoZ[33{F[Q/ĭ;uh֞TeW4]nG~wU8 '{Np#/\ejux1\Y\_f&D3eTdqYVa-5P(v'OӾ ~W2z^ic\I@ C+(ˉ] yV;QvfP?X L Rex-`qkx_/160Ԑ& &9EGyCo-m+a 2& }sSo%zX=IeO3!fpu%* ׺K?<&^U@j\SRm9{|V&+ZYIyd[_Sag8 0PGM[{F~qU.:jpB J01 \]`9܏?~3[V>^ q8n 2 Cj)5(|?@R]h8{QEj1ާM CfM:A-X݋-X+@o'}heAf&>]bMRӁ]R8jBT``SP.TK-&^Y|v8punW@Տq2Ts!!GPBhL NYt!fb,JU-2h+%SAyY"5,kHbXD`渳8slLlјDa򂨙^6.~H8kUfXj26yU)qC Ɂ&aK51 تކ &iq-#wJA{8T+A_–Kwm`m_wOEH {Awi>_CqSIqhTCMe>J,*?Gb Y蟍~p輗Ǐ]+കK/AoVkCb޾ j}E͒Pp:xoºzSdtcjsd`Ї6"h=kQ 3yhN3D\5a^f|*Lnx11h ZJⓐ u9997rJI됧Bo]q0f50?`5[؍nu*K5vͣZϩsz4-O ˡG8F+a|DP7K:KoO4u[ĺX_Vs"P l $6 1Np6ATNl) ԃ򅜹Ui59chsB>~3Ў 0u}#|!_(/3s"6:3pgj?^W CYu|y:&8DE$K"QzYֱVSZᩐ,(8 t NQA*OE\?,̜ MōVC^9}w}"^H= F?3?fP hd$tmDPV`'t٤Z~FeB! \O}o}3B ot Z ^e {ojFV Cb`kwVgC>)LJR(d{,9* |+v *ϙ#FĻf (BHx-DlNewsy`:ݪj-7#!y{mS<3}kjcww T"̏OipOrjL6,a* pݯ.ヴgc)dftӵpꝬXK2CeiN-n|1p`n~gC[H1 FbM-/i\%)ge\i`=s%7 7Nx6}tʻlA 1HXsUPH dϳ-?}&I{ږ増H2mtD$`1SNa >׋9x_p4}LJ *D `d$*`_ɰP 6Qph1{esRck)h&GO f@CCN5CpP5ՏaJ^gm?KJ1V#U?Iтhjsw t$!< t7L}g|nj P4A#%rmEy'7OmW=5/|vkN+շgVuԶud-p3Qj;ê\-W)T9 QBmV ɽ|}n^W"Pr B]%'o[/26\MVg)[yI#dY,W"\j'-O5Pw)>:S{z-b\y ,25q| J9aTdQ̖H0EL5+ᡞ7Pc~)N- BCg _Ms+3/tGv#ε岢 ]>vK&r!?\ rpz>7rV$"oxoX'1ZVn6'NAlpO'O)$\~n(Qsh^CY6IN^r}O}R8sW[kZ94G3PJ17j?{9n&XRs-RMb^0aT?oVo${3d6OUas[CabʟRqd[1t.Us@ bfB nqSѻ*)R_jH@AӮI3=BxDl7ͨ 8uِRpYa뉡o>q^?X9LuoC' Yyz?47NnsAǬɣbN3(k\׭6(ަ9W%ɒݮ|^fVU~^`wBhHGBF+l'i3Njc(O.q:esi7p/h$\j }Jfsޠ )Ean.e\,"WW'n& *M+_4̷b88jB.$ Dwj5o?T"hܯB~Q_{82dAmyјɺ Ԅ1M3S-cZr0e޳E^],!:.sq@"]2ٸb{{[;2AϕdǷ>ʶ3M*KIٯmҫARUq`d>*~3V3ZNf[b?aRyhSS&4;dT4@iFCE`@3:8=,zH !Mu]3_x1Ɯi99׿i\!ʺ4s Wkg4!穬rO3#-D7: K+Y V@% ;O<|n9)ce0Uu>}n>UuyT8zmtBYf 9v?gEC:D -$.b ml8I/D $0kq3wjrf]s%ԧe9_yc6lr/z E *aF"V\ -螆)[:Y0%o{*iIOyh6_IX4L8NW+"R9&umt:amYq'yv Aj}_3ъۛ?-X2n=yrO0^Q}&lw|q*N77bMַS&eT:E6 :G#iz8huCHC8e h&]ؐÒ'>y@2Û[2Qػ>D0VE @+MOsX e ]&"pB' Xj'6IloV; WZl9)^"@%?\dv`SEEa& Q컹eyi< 4>2,!(_~0 uc!e%{`\klIu`^wfl&9_=C("2  [}$XҐ/C#IvF4BŞ;Iŷ*CiD1MÑ"QE*S wUE̝ŨR(C}ϝ/<)Cph([I9s!2g-rZs04>>?$JwD im/2iBa>6jBSFb8 +RtҖQ~RBvsEő9%. +/QiՇ0p|Sluv*{Vŀ%V2d{>Pc'RgUXkIzG4p_ׯ`tR_nuҟcČqa^pH-#d'23y 2{gwMD(B҇NsHkL׻5I*Ci "=T&1?tSr nE֘[Ѕ"RY'JaI]^Ɓf)lmQ^=*Yx}vi>=CtleeVq]MoB'f'!2-‘ҮRtb|jaZdq&ަR?V,fsizkrރ}Œ*Z, RP0u,0YXۋMe~5^WS=X8M%N c(o<ڡgp/1-DF#}*0;/^a$ zL_ٷv433lS pX,zRR@ cۃ9hIȿ+.Fu[C<]w]n]Q7A?ΩZ |P%$'/.gB"m95(`GnUb 1,rvJMTSKĻpw?#=BΗi7Ϛ{ӟWJN6\Z%Iv'=Rm=ac+E4:;ENZW4,ӧE1h.g8G^&͸') a]H,kݺdT.e϶cbȻGieͿ62qƶVP:^z_ 0 U,a^lW)uRD |hg^HtIp!=i!$oJc ކ+zLkd ל@ |`x,ca${3yu`q5Hd,isk#SiqmAKGĕ0P1\4J@zLjA0C: Er XNjٌ,H^8ᤞ,}F$}caӑ(u5h5s#H/< Fv=wuv]="iAc[F]4c DjX$Z6`H>:Yf!ܖMuH4SFRUi7#%LP1&R&' -qv-_k,E.UHVh dRc@Wtw(ϟ;ČS}򞻂(g t R>~+fطuXC`"Ȳ v!!8S:31/y! a#<ʒR[Z(~'4?.uQFcL"0IEr-*^̆lӋ*[繘EH2~d ~'¹\se_m?$#N] @y| "Рw˿d'1;j<жđPE(pmwe# m$yG AẏYfVM+(T.ˣc Dޮ u \}\NT@Okk9ءHdA>rQbFDÅSȏfMO&a[bS?ȹ/3M-\ 3B-\ Fvcckۻ"yk6Igӂ~/P>%>9aä c *5ve FRlb*]/L[kƧ}mI_Q:C6 7t_(,!؎,NiUYϐT^Rߞ'#|r,rhed5kxڲϝ|ϭR*!q33J X~0[fDx4P;-&(Sp6u <HZ|E`^OxΉYbe22*`u1bV?y {e.ONHiWlȆlIvL:a85&0!us@JSIx ߅A͋O)&jj$U% V⇡Q2fsA0nBA'o+ ~ ?2fP c%Y#A8?:g[P՟a}e?nx\#QJly]Wc:&wOiYi|̆&o hLD c䖷|ű!^z4${5 kx5eawT [[Hqڙ;E J`m/Wh ʶCQeI-37ls7X$taP6pu[HRzJu/zT;<$H ^1ԺC|g%ji4lVv/xEQ E/,v@fdu`;[m 'G T/zŸol@_lqI9D#ͫ50|edSNݐu6E"t& X-#|`|XξDpFz3~+>*Nc;ExN= lodoY{..  p)aCw)k7WEo Ww_/8)k~"^& ߎ) ɼȒyɆ8~1o[*y*\EՇA_AD>?xKF{:By~FIԋkAk;|7LÍ,"2H'N)hrLA kV(76? JǾxez1˫)aé߀C4"eGu.˯lY,<aShxwVR /qf6=wzsqn׉$7l/ a|}j#? Sbm[%F~#s`!6倅"x*UMP}&+THԣd& IIF }|(y %EBum-R>{HJhb2P>a}I91}K~&^񂩓 i|֧`mo,g-ƨ\!3$4W qwN'Jדʬ"h6y rro nħa4D0δQjF ".lq~宥0IIöC4ۨԲԷ5&@q󃃀B9]ͧqXy?u>ЋH!F7XO", g{C&Ŕr3 {bjb2T,衑C6c .W@B[R{%&Aj^8敼//]ПBKn2 D%km,EԈIj;u ;5;5j^#jK|V@Q4j'{ߛoS3D!6~R] Y 8+H=U<>/i]!tlI!&&+Č̎5桂F@)v2Qzspeni*}yKclW>Asyc,RMܿV⧈aӱ\)?7y h֭iF&42@x5v3'ЖI|EH3'XY{muum0ZatUĪ"Պ6vFK Q1c>"߈'hf{8 X)Ѹ(@f`l=^YXɔ@ϤC C H!.77qY.^pgQ':;I'4f4tqZHDs W [52^SMW $ ﭺ7lEOm:&:tKIw|;'Mb5}paXӬ,Q])J{F݆(j6 |NV6rV: |&WWiѾ7Mx1t,Ha.ZbxuvC18AGCFJlkY GાQJ{c?X]wb$򳒌[U|Ҟƌ4ݒdslc*kZaa%ox*4=%! LiŲr|8x8QF3Q{eEꢹㇴ H;rVE_YY|py3]d+:Ky9Cs? MY׼J$iMmCaXhc`%O*,';%rζ̗X£7j"Ʉ` .FQV4[*MFl#hn.(&|HHj@yreƝ@iT_ .HoKur"͕/2*E8ԙ11#$CcOxmp*⸕(/_"2f Dt``TWF6sL( ߨ(kҍ'YrΛE"vyRW8%!ZA]bXӐ$\5 C,v$eØ].Ws# 10uj\D'O&[>  ߻3Z|;mR!1%#.4)m6v%ȎT՟kv)j!5 t@ W xCpԺqu-rsA zF@&^H5+ n{G~A&/@,BX;s`St;~|K^Dxi ݽ~&>ꍞbA}\=A/M3-cŶU"H ׎ d5,tje [-Xr#}b2h)/gOYE<ѴC9 D9"O!v F^#涙%Pô 3 C-h~Dm˅GFC:LK0Hj^0)}qcȞ*Bh5ӓoCϵhwl0|uў3j2::1n8q[dKEVbGlinW&iM YVCOlv}}q.RFIL(P֐6"_2$95fP.F=@r9Ѽh.7"C3sX(fs,W䭞 3:R_qS*{/φt6{?yy:6ﬣyG2VV2<=@ڮ].ftEkcV?`sk1iK19B0eҵP:9Z[Y+pr$EZPú"}wm0s,$R}xXA vjQqu#c^C߄L_ gQs7|+*t/\i6[ id;~p=ex.?1rgk*cP.+SP]}B9|L:\jl?6"C #Vnqv#z2f'rxΦ_~ hhVGp”HhOl,̾а hNU96w++o%ʧq\cig)r2,Stҥ$=D)LЪW%G1 4X# Z[ךcg; 7Ez;m㤸9)y8$lox{!A4N,5X{`U&3E> 8ߡFw4}rLvV_5#*>T\s /v %~ -ͼD r-^EZB܎܀qJꐓ7B6eftjӟhn'_nTBGLuLz)̶GS yF*2F_tv4E9HWT(ݲZ;a mr_+ntv_BdB &s K9 \2yAX D) d& nl_78XDVFoR7r ;deoqF'/pn#A/ zCjmA'-ZP;nE?A aŠ2g&۵үݜ[.rd澪ET#DC/޳"2 / u.ҬT^|1Ju9o tda$yQٻ;Hv`;EЇermGJ)ڜמ` .$9 Q)v, 1͖&tb^Vrӡ}d�ظ.p`Xϟ$jWsAg/ʒG\{s."BZʏ|^UdQZg`2gb0&Ց3'a'z2Ja_욇JGP N'la!+;޲r H[` 3DxG!(q!3GHo{:Bgo/2i<.w~AO<iiw|EA0ָ𼘡naOxauHY?K3BKHs3V.ݭY6Q#O ABW,ǿüB a+1*zQNp;icpZ?⹧ۄQ~QBԛ IOɊ&x^LqOd歾OFxWעJO^hB[b|2њ@ҏ봐%|It&' 6B< {z InO缥e"!ejt& ۪eT&=:IˆP  60Dz2ۯ ]kY)X:"~W@ C/{pW}'xe =_f7ȅ&KR/gEZ z+DdždElB/BEzTd.|F- >+_.Aٽ#A1y/2 #G&UsN~Mh"0?mјO_9zd7!$NQkkaixgAp *N\6pQ{Prw XޢWXhq}ni%@I2yS<{@5~u< ͼOJU(h0RaVZ7"V AEjֱJֽl0ʡLc~11^Տrz Ԩv_` aZ3&Fc=!Rی5D;>My$/Uk7\9=f0ԄkCeS+*9 _?Ȇ 5W{id@Adӽ1ȢգpKTVLBp/Df/r [N>ҫ\,[|0Ίx::{9zdsVcKkUŦj@P- R|^*L 90NgAou[TZY;XWxXZؖch\nL^4paCTNTnwIkؒd%o-e9UkGa% ]m04-K֮JV1ϿFKֲghq\eGP) mյhzc$H0¬V]uLC(:GIp,Szx#45d7_ ^WIe Ph61Q9t<*h/>ɷ)ܣ(t}yCMti!H@Lt Ax3tI *Ym2Cn Ҏ7>1] 0[$cE`oG3sQ>"->)2 oeP5~i7pj(KO^Z ͚>=(ZZ_|ɏC,8 gkZ9 V /TZ෪Tka:ɘ\G`K}iÐc8XS&M65}R9d57u}O+2kOQFfwNGu4&Sŀ r{8>ϰj7:sC֟ Z !rTBH/]xist Z^Rl k@{PXεᘶQ*v{=*h5ie8&;OdbcݿNlw=:))cPU'ÉWJ<<"|r Y,p(co'M}>~ʣ6~n13'G y.T[,>s Zf]3+~]K~4x,3c1A ԻAl D+tUscoϻE?^W88% T(T2W3~4T$\Tȡx,* C?ʗBA5t7&O}n`櫮oG٤k'Oxjy"fٙo MX?|)}܎>G 1 p|~[˙Ey@J,* g&QIv`oN uT$Ee/bG 1 vSR W& L{{l=ia?;/ݞg&}5ګ; 2~qZV\ӤjH!9uxע9&_͐qT6 nWI ۇdoikq\MrBJDyh< j|ğ E]M6}u2X:PF^Q#+z "Q[ d?+B+b3RGמ߂^Ʈ}.ALWH؈`Ľyf.{:>MRLB+}O4:x5~B'M ;c@()OGL~/`8 p&Ɵ( t*]iWSHعw"tB0P|/5Y٧[Ҧk.`U IZZ4Rр%3w*!1d|8ʭu i..^ާvn ҽ| tT[~7nAAmVƨI.`R:4^?R~8߲)Ș!Dh|.XY;[="gļ ^"鳆x\]B jځvxgD&s?e|GmCAUOv@FqRp&.}lY.B]hج k.38(Gy ל  U%MޗL‚bSp *E>}J?}%ﴊ'c f 9EtOlnP{V‹fWfbE^X4yIGn~2 62<K5jAuSZ,}`*JStyJMzV7KiCܮхT1g{[^i8i9΍>}8R>.ogў72]¡k )pB+hV jSl<;tZ炼Xm Ԃpbj@bX4iTM#J@r'빞~N2$Ll+ DPm(f.]UjĬ|j|kr9\(O4EFhQ^80ч ?z{0@Ueuyhd.|T!ϻSY`tG|WKbw^;C}E1߭ݔD7=rx <*4U0lOw̝oqh/EAB|k[oK)IuED4G&[&odH%l|_kEwV:{9pj (כZ(D^fEk2Խ0e0N8s|#к7.ץe*#ߒ]GƈC@_#Jls! RWŠ#r~IáѹHB }υq`1aE u f*f.,U17·xB}< Mv}?aH4:5XiGoKvNzȈ"{9a]vHњr/7\|f3t+7=a-vU8Hn}-m^g KE롋aPwgeòo:u&@z?է t5o%ӪF&8-_5 A]V{[jQ n> ;? &Nj_Ve~m\t nT=m]Vl6|IEsT@\5fmn ,75]Jd[!_{M_0GɮB*(OZխtyQvկPc=h`7mg!sO>8`qȟUĦw|{S1Wrrxj,k|!g{gk=nuG.A3Ͱ&,,1CB} 8K:@%ӱR]v,.z&HhMlV1R=OM<9lFh1"jv x4LFKg5 mfMJ  `/Bԥ

ϴ={iܷ,N 9+ixizl̮>6WφdHka%vD& !MIqH(i` aة8oeBO=XEz8(z$`i gq-+JlCP  ?b Ց/ZfGDFy??&|sQ`/Q&D7-qVz\LUP%6ɺ}c "eC,```Gdqʎ˿J>X.y 7 `}(M+rJ"˜~k>nY7߳]$eT 1NsX7R"L1Nk{SeR&5c8e^5Ɉcf·QHb+G&ƀ~&0ݸTc ȢYݕ1@~lw;b*i08\)381bADkG=uI=̆~9_9sd~#Y]V6K>&FUovA8"!\.Y0:joh %L$j0 lp=[_a9W5>ئ/mBp%g勅U>;Ѽl"wL=sA4SIe5ܐ %2L&ܬ1騇ܽY1`KtE6V=Wr6z:3>k7g^>M/&!YI"a]JT&5D^Y'B_b17}+ Y+NoۃK4j@ls0|Q>57 i3:[gc2֟/Ϭ/Cx ߢhsugaNeٝ'$ /:7i(FRİZGg^1)K}l|9zrmH;ڟ]I)v5zJXA 5]tS?RlD2W?eǸ*!jDkT_;\'Xcz!ObpSh1?3Y`}GmʙWa}yF{H~5I'xa=:/KNi9gi1[@6~N J~y/-X9$jz(ӓD_:vNucVeK:"/y<~\3nc&Z9p8GHM Ntr7dL~IN^,_zmjk0=k^r8׏-p#׆Crv1mS 6y-]ɖ+h0|Ppg6W[7KE_Q~ar|ò1G/Vu"})ƀQ+i۵!Ѕi) ~O}DۇH!DEW E>a0d)őX{QftEN3NR{`v`I3(HɘSp:[i}NR!Ճr(x8D'32c$t-Ɔ?gxW r*%)E8SE8-+O%-D2"u9bI'ebj,X°̬{4ڒqdVlؾZ mӧn[l;zY]r?"@ifȣR6\~PS=1H~?jsץ 3]?̇ 2wWڨӅ z?zCC*BkTF&2,}#{P; GbPhnGR,nsJտÞEqj2x,Y#7-墁+&Ի{H@ߨ&. %qDG.eI)ztIc-D&))k!jmc csKD{cbΉ~9kA5 |Կ# Gt~_p;ۏȍ. nAevUƧCT;qsgeǬxr\ڈCVW;ٖ'h( sR xiE}6D[m@b!:XR[Dv0 tK8@qJP$G'HS|MJW|d=yV*\E{"͘&+2t*K9]g#kpGQwpEs7O)yWƦ+Ӄ'jޤѕ'JfIA0АE31Ƌ$PѯE;6)lБX-$0 eߪ*7@zr'AX95 * ˴%׽*p3Ngbeu .vӋyTV˲#D fOiU5}W*H-$I{?d0 ޒбnbt GArR|m }d(%m,ɥYgcwj^<3>軔zPzrx@3QFZǥܰPY}tBUE OZ [.Nd(4}9 xGF*ZH"! 쐮e, (aG7BݭR@ka &|0r?og!ކ:Ȃd)\{!DRXпAaI aKΚd6#;GV ttd 7*oȹdWQz͗]߁f2H4Ϧk_xZ»sQw> WL9'rM4 H.L_1_%41If"(Q4"~a9Tӳ~S)rƘbjOpB:hVNjqrFnQz-nηBN <`}a >lߗH5&?hZF{V48cNy%#(b+|kM SKAA%qe5''XYj<,i=Zdmwk`8Y>"e;/R bnTPvo*>%&9c(](y)`ҿ,;d03xB'W[K=15;0.ӳiZ~u{Hl!HUI}ϴMy,>#n=5 H0X.|@p N.Oy2?Ffl ̎Q(\9d_"rMZIK+`.FП?{C o7Ip\hUskaiKg^(#NK!j`S\%o54 "Uqgc*Ior0cMC"%P Z`"[?wn>D#x/Y( 2@+ԾIf^Fpcd }=^H V3x|ͦ',( jx=γ~=ǹ%=sT[p4iy%u>Yا`qPMH)xOq^5)pG&U tI`%+>^fKq^@ШKXOmbl7LPA{l5@u\P!g5[ {vX!X _Vv xO:D)R,Fqh]88jE-YⓎ@9 U`ȟl5M1Cm?"FP ֩gƶFf|$z%?&w?>_`]菙`}޼j*}BI9P/Ń8%ki|pG57AYv]dޖPzf/?B8P92AvC%NyO՞wUݩf߃k>r ҳo'5T Ɇ Ĝ~[3Qu\Yx>Yʅ{EMدBEl\mɪ'1:c 4&Oa'k_aV6o9XS6Ӧ']6H[]2Bs}YA`I`u iX/vA&Ɛb2|z`s,7"E䈌玸E @q)Z0-k0-9}|h#:eenH'mMhbѝ) ֌_MlT@њQiJ?AY8Ė8x'&Ś7M@ Y -CxS|D[O1ҋ?J3Wa8E+5HdEA2F:*:MgD!l 'W1b[ggAV{* z5P3HԀUS`٬Aޯg2vb&Q[ض%=H$.0a"Vt0?n+e~2Vxw$ E\[MqVLaC*mC"l? ǹ||)O7xvB?tCBԑB!L!^|L$vVzEn.hbۧwW? #Б42OyX" ' e4cX =yԱS>X.fV=|z:T>=evO<>/Z~vy̖  j %D'ו_݃UG',qx>U1w.ȣm!'s9s@1*?:K6iUmA.t||Pۀ\28p!cfl/ChGt) ǀ D ο?LoTr>9Jm+@0f]#3 2PÀr 'ZAɩ?BioS v,O1 >N0,& I m>ilw_?ҕ@#+o52[EARo$4]a Q*1"jih )m_?6i0QoǑ i!Xs[P 8JMbsE v|>-~Kx 7tqFjIL"n1i+^%VDt|L^T_DuL MO܀օ| (սv~||z,$oTL35Ao%&VBk{,lղX+t'}NJYYycu+IS$g71,hi[)i?՗8˜] (^Rf]@AVU3Wi_;\9AyHJ_^AHb^PI{Mo{a'JٮqJ'zJ1;zaD`T}5SM#! x15vqLM˯[7PC8 jS伨GhsߪMTR(*^9"rMgrx>t|7Gs`  g~q}`|%\胵su2x_ ((]sMp[Aɝ?4gzꁭ[.6bNin:1;+ȴ91#'DO$v*v|3jM[<8?r^HgíUaaG)N FGv/,={ǟ!7-mR_L)D7Z \ 倚L=,F˨GR+/| )+YW~Oo"j#nvCdU55t5Jt= cRd]G݈Z^GKT%l}1I[ҐTۮ9$Vjo+%AǙxAv\{ f`">M!*ëq΢G|~Q,g ޿f ue;7站I&el`ΆLZDS2ϧ8(;g4πHj[qXs!@ ~2H3jdޘM> Z!qJ5 km5mԎFD]n> z+*;+#`| "ґҬ\ XDDXZrhAf Z4uI/K HC7"fW~1ZRB85B%$~0^*@1}!ҫmo]WEkMջKuc2 0SFY?S]-Yo&}p߭qL~aG !CUUhs9?O*pAkEϩWąmuB*]w i&7 3h.F' *VwUU FtB|&s+di3D{rSF@کN8K{Oz%4 r3FH8U Rr~6>YglӦD;jզjklS+d83DZE_j&ה@}8Z! W-2j)p˷LBF'LT֖_51gy E`1\TǑG_sg`WGP<ɛh9+"")\>L=ht~/&6Z_dOez" VI1ӫi杔c }hQ3MMkGil֙I7}+,=l,av99Ib0Ya 9KMU'̯?j!P\}7s*Sl 2׮M?F!U^8chU\z*t90Ge(t4gȳze8:jFGHi%kisZ"!E&bԎ5)ؕ;~>rj: B>Io1]1E^F&gC}<7,Owhnע O<&:A+ ldɷH鱁3]tATNr5K]UOb npL)פ_JJHax_Wӿy : =!WM GGWUnқVyFgFHcq=٠78g2?xw(`5;GeW @nZyT08vSPpgүM 0IgLY\!t^X&eK"́٥r )8K47zaD'tQrRqUy )C*M5 6b*^۰~ˮH:!_bbpOЌ xR)k%^(m8B5Q>˒gb1:Z/ HˌGs :Vϣ ޾a9;:´{qI W[P zrvbF@qh6xPɞ.~:{&PřxTm nxq78_ûCL'3VHN'\P໾pFecAYb wh,MԢ\`#0ztCyWn U=cTDޅF!N* J.Uz*sab^P6OUI|3F/]|*TU*3\vaplq7 D8UۮWwIl< jĻ۳[zHy2|SVkw/}4 \Iyx|>lcwEH(F ʷOQNO=Z7}LPz,n7lv.9y `z;گa@V_eŌz.+3q8zO9 =u͊g6mWC&C9c]#C\b1BZ%ٓv*S?‘)} sVʭ|^hbDYLeQ3_&sNl O j%_ 磻Jp &EyWOlWު(`LSTofk oI6!_;*]`nt>6Jd>%8|QcC@ F &@/u WV}19^݇h?HYǧ#s"trIFPK[GR)SQSA. lg2cZvL`8 wo+-LԞGL턍$"o\\K!$YZF:~7t-@H'B8! ftWScW,:̈́ 0S/q #4L}jƸġJ¾/&vv_N\͞b7`\I @N}+m+V)QVi"2.r*aMF0w~_NH2_Bkt@{:[=6ކ X];eJ!,>="ʛ:g.m(?-@k8"ГXT!&8ke-28oL>תvڴ~|m t__PJդBd~1!T-vRĀ#AB|{UB+!z7OD+v5(w5<|ur5)c 4NmZ)dyra9mR2oI0Qdg(g% `ƮU!o;9ӓ:V)I`Fj=z_ƟYl% AV#2=,5MIh3I50X!8ita R/zC(Nvj/qDk;1Lr\g=0m< TUJûZFY{t3bHj6 F$V(Hq2eJrіbU؍@<$TįԀDd[WN~2*[PFC1on锕 ZK>>32XaXIber"Q@zj=ɛL*YCvzp@mCp6N̊*w(5 W!δj!m4+G 1 k1lj 8Ss<^EjQ p`X2<"oFfiIo Eus`g;)&30@Gbcp=3>7uvJ)hP FHQRگȥ̌_g@#v8{lSdj[Ͻ%kzJYZ #P1م|oO2t3J$5׷ 8ØX6j7LLaFe /Bݨҳ=cr:͍wQ|KCnq'guΨMfx:##IXEFTt ND=oZ xg&G,|*I0ߥkٲI-a}IG{H D_QFv;.@eNb[5fUxܺEX OACD2__ s Cф;g3;>31 FZ7?/LҜ#u#PX^w5TeӖS ƿj]x2tDXu`vw{oy5|]2W>l[(:HBo6`[kC,ldFm@d ș󿏪FvSְ!}X_C' "JĚb*\}/8򃾤5?xv5#0e\klmP* JG~Mg5=x68GoG>1]rRÜ@o19MIlw$rstuORSzۥ$mҠ.o Uٽ(~[|b.q ͮWtV?a k@nT kp-pSJ}s>UkbКIkr_7L򢱃-RI7ڞRقJ̲bM waKtި$Wz>W5lɤj| 7T+ټGF;KbU T!Gҕ٬#$'<(5łmPRvnyC0)J <68 JeαuKt WZKqHGn,g{9({ L|r KRif_7G_g\!g^ޠ58Ți{Z,!ZmL07OTt_是/жѣm+KŹ' Tݦ3`Jk} |-}f[wpZsC|oaM{ rAYshHw#AiE~5Eh" GQ݆.~]e,ܱ(_*htHl^ӬG8.e&1S[em rs߬NŽPX~J4j .1:1{锅=T%^=qE |ŵz$g֌)rjN]ȍYm{r8wfE{okI)jW, ⸠&FͭARqWÏ`wn㙕UZ.Ynb:z2r蘥]bW`ԺtwY-vxQ0SM 2cqиkS.ŕHRBn-&e:Ϊ£`>2cE@p{OT÷p'o> QgٽGڨy*%@].0'SD{B#+~_-6X)=4x6RAnbDww@XR:4Q 5}!&)Uٽ0VĖfe97YȽY$_ jl'#gB\z¢&|89ըK_uL~ w7%[00{RHƪ8.,z {pr)BNdyϺ6oı|8ri~s`;A0maޞSF\~yEdUP9z:q@94 g:bb# Xn:jl'@D Jn þj;DDLXQ ʡ;ENڄ?7a>Sf*p=ZhPcbnOQn^/:(gFʣ i13 Z`=BWho|:( US^ gpW*e\r?Yn`*+ۣȉ 0gP}q"ZNeY܉t 4˓+YRfz d^Bgl s֌ o;m6+`Lؼ;C?=HY* 3ct-dR/k+B㼄gAFAвJnFbNMer{}Y'QTz*=hЬ"f*i>\{ZNt; Ep%}+2 nB.%M+Vz bgϸD+WLY(/EUcs/F+jhk% `!yAkq\Lyv+u# ޒ9d_|'*uV(Qiv ܘn߫9c* 3̕Ɍ?8/UY+BT*#gu>-ݍ>w&hdŽ <*`)(nҡ琝y_CJ?B$+2z_?&Yh XA{/B`Zq(+⑽99nAUwO}6t^+hXj`=kqYiR'VNƃjw]7˜l8K)f~N_uxJ n)e,LG.v.p@Ԇb]Kf+=;<Tl(\-%x [3؅ ]{?? $&0=8L& ev|ƭJMR 3A8`C[v`|*>FaJub0FL5pcGmD!% l(LD-G?ev]s7F"*Ĉ~G91n?;o 571+K"'|I,\&QJ幮Cj<ӛWWj K"| +L*GmIxXڵhj[̃7:7O 9xVZ᤭{nY@&%6YE|Ee )3 ;|lgT) 3bCu-rNyCFG#3ѷo]2a'ZN2eBԑ++Q+I6瑷M5C78N߳0\nJ}06eS. #WBDnGjJ^G94}Ay^jϬI̵ƝkO5ŦЍ?-Kt-gвӴ8x[ZYθm*18_F͛=ci" s|4&Q 3pNB,Z2KҰ@rpv:l1dQa0ۓ0 դSR2Љ\:X?;LȊ_f̎'"#;q݊-Q׈U:}~:^3ͳ7?j޸_A:"e w#!տu"424Mc.nOٸvF0F蝕Q,uV@vDJL[Q(o™n'W`[k o7TliT'H& ުK;A_׼@9dp=m{x$m4nbTq>Ls7' %tgK -9гD8l%*s2b BM}ɜusK8\<p ~n OZ;}1 /ͣݹ5;1J܀Wrfd[J8]GyM^>#Y _Y̽tJd 1H7B' t)#yHnLӽtAp_s2?kۃ b*?\ϿcV ooL4%-GBV鵵b{1a<nT@U+\s]J3Uc|7skぼTuP;D$3YZ64լK Q=BiU,wM!#?vY^NjHMD~H%osP,ʑ%CpG5S36륐೨wʣʹ6iO-wϕ'gWg @(Y9TT""[3{S(<BYEƔOQ|2Z 7hjk1z+|=[#&1qÖ_)NU(97=)s~s?g|'FTXuE2 1 U_]ui!X-pڣ&(,eQ.sFa9Rp!>A=g_X2yX ,i{ il |=τZ2ɣ-ƉݢYW@2NcՖ4f"6H|9q(w'9L?o%bϫ{Jv[ڙIy+8Gs c$E19tv?hpd(3=wȂf~n<ݲ)UV%4txIjA\RW2WbCz}o5-dzr;^ b$4!amdq|ߠ!e_vzzrGBB($y,Ն#.B}<_$sn4LhT*單?YQgsSYdV}|]5=mQqƹ"l͉ɸh_2jY: n^b~:A6C# fܛG?HJaH=a=?w HcogbgkC3ZbSu J3,6+XuDDp obAbL[Pvc`?=sYgf[ H+R3y\FEߋVlY/dK+h:OQH9>.91'" ^f&z |r] _U5\sZq~9n}!BٔǖҼF/3EL vR]sӎ+UULemHPxՒ"OMJ0pF^ ޝ]Ti2`|.fHpנͪ+-! m$Ng,ȌlEaX' 0ˣp.1=w>-35WgueVS|:kK(Gu:" j*aXELI·h A8.,~u=2nLb"6݀EwJ{0Wa Ipxj0TJrEje)`;.Y/1Cj#9u)1*2_q+éMޫZ̜3/zݴ,T`hUt oGD5JE%?#IS0|6>gCU\A[Gu,˫S?P*g'i)UAa]xoM$({ |CS1TFi `$FIhP邽B(T.1dXcLԈ_9JƀMR;үW'Ғ2{㳩T6̳FdŽYHШr?Q9${- CMufLQ w󚷔j6^ŵU#%~H]8ߦg_+hAO{iSJ=_O0$I.:3\;:^,H(LM>wO˵宖Jv+_`ooR/Y~ءʂŜ\M]kidɰ x+Y70^N1&SG9pbES>H2DwՖ=)L V<%cᗄ6?Vr/ARgWNTYtKgyyl)$&qDP1:ms|0t+ J~)(I+I @hqXg B >V‹"!geiNF&чLJ $!$TZJ&Y2Pm@Vy޽hC( _ƛPɐGR 6Py@/%~vFifx QAڣ0ico5KGXgW7u*ĐY(68͔w d.ٳs_5Ygb"ű+) cn*|I},8@;~x LAC*|aM\MĶ4*@}UrE䣇 ph"K?21u犆2eS \v-/JeW|>r ae*_ztFK'b)sV6b#YeZߎGR a ҹ\V"u+9!F^ k0]DqgLǩ]CD=q7R9 gBB^r~%#Sۅn#w(U:. Y7]E,X,\N,tuMA2 J.u29?8wf.dX"z >;AG]@ dѰMiiiXuFZ}FM`26d;x[Z4b6 ȍ.>i;))f1>לOR-Be`$ld{sՒI5ŧ|cx)9EkFXuDf@L )ik0=*}%+/ pGP ~.KPֵ!XNԽd-_;Y`j01GݓjkEIV/\Yx5vTNKm7Κoi~4KU0fbob̫2[+;9nCWKBIR]R ݂#lfXtuMI(ν>kS` k,S`+?vǞmcPGL1ӏ/;g| Ck%u,mŖ NÓaNZRKwYRl/t(oF|R/f)my5`-gLB>4.2i3mNT`*ʊYLaF&Jޘ5}tIFVqv ()bz(e0QuftP{TIltL4QXrl6^ lxѮ@Kic%z =yc;_)}GSO0-HEiRDM}OZ!@ %lc y2AN \A1rBٮ (kJVn99߅("wS?ץ6@꺫7X߹_xaǒ͇ 얣y%(TuEEMDc.t4%كi7P @s6E? FB` 9=D5*hDk}I">p&ۤBƎGF0|<<[%*ޕɿf怊:Bujeu{T#8ʽG]VһVL].\/_4GwXչo_{(յF,8\?lja#.Zfe*`}Nd]~NN9Vk (E (YX[嫜Hs5UtA7f Zb0;*y.4g .P&iCt$@g#{?c }*g_2pYj(`:G~֨1XqqOyg(Mt)Ƶ͑kHV&9pǘ*7,4C&4u2|F.v u.=@Pk;Ibܪլ,vᆝ%f~bO81s*gC:v5#Ⱥ ] ")Rplw^iV . '$iV-"1 A$QN'#F7~dpBΖ*% XWvNu鑶X!rҖ,{UrĞƱ5l1'Q[o,Ku)S&;1m.eoUZ!E w`u/$0yEBc.D2P!!NE=qDcu-lxVXF&J$1'-2f-*1/}d3$8 GYnk[vNt3.h.N"pnr4JxgFN}j:e͠+losLW[ҿ@;{SH {WW| O2/E]fE3tPG^BRk );V`"w3gڝxgJMbL? {0\5RNR;{)9ڏJ-lm?Iy61Ӌ?ߙ̋:MlKlJASv燁{yG3RFijG1HS ,59Vj1.BWP>d p}ceG%]K i\)*&Kh>",gQD)Hwr27sfJEb$=7 S =C"[o\q$rP᳎L$M՘b|^!U[&Y?}j))JZEU d*筨AӌEM|JotHXZmJWl tBXJ@y_$J1?Ivg_^|3o#O{_H!(<"_}Ky{W>UXY}~gAuۓ&sWG "n;Hf؛q!Fv,̖Rcypȉ|Y09CcNBHh$,L;@0m#"`V7Li"(e^o#MTXi# S67s@xbZJ4bH.:q: k7Ekm&aN:E(->DmooG~I0 2f>$]⼚ssLdtkSٻTQYA+iȀxֺ9CZu0?xQc.>t:Ч``cy` Uyr9/>iΙnWdId&GPUhcVIao%_Lmq am1')0[J4.x2)߳/1:p?lqBIڿK3Ad6#>Տ$-]Zccp<͚ ./]z{- xdW_ywcYyq ew"7]m8Sfg ZWp>x~ыv v9҃!ʑd_ro :d ۟Aj,*cU1dlH sݨZ:ϸ]KW0ܫ,?*V7K/owշJxJkzZRKg/lR565E 9o*CJA]C6q1MJ[<_ O7g1l5 `=#).0 ec*~۳˻dcmTu _*'PUV#VH@ uJP*ImP˹T zgTZ]λϵ*JY)keGeuɘ   9pBbiiϲ,T:i6DR"d0h=6' ἏyoGѕZ69P Pu`z; a)bش C_c SN\ dĹ~H^axid%b:o*_>g)j&0_@`Xq4#T$p@(͡cūkր_WؿO`k 0ePbŽgkxG,`m(K8 )5;Z6/=ڌJl^\ZLRI:"1 c̻Q}|#yȥ'_d{@i-H°Jo\s#HōV.>c5գ@1ĆO Ƙ"!^5^+Rxԩ\_;211-_V /ۊ[PdP2ѥdIqPU .Ԥ()džR '-- #|lCk/[76 z /-0˩O6P>a:d!Ռiq׭*ե/< ]R樌J s7vԌ!V.62䘌BYL0qćfIZlB: wj҆_Ϣnߛ GC$;)c9و2p`ސԀcf#7g` Ŏ'NhFhԢPtaˀ`_%ňFrtBm:]/SS[G5mSk4˙ɴfONV Fs#2PqEWky{B~XSVք 잜bry1cCٶFHg7&.Z{@ :}Ae3wXQJ)UJ5[3 ɬa% B^'%6O^#>q$#Uq-=fYT1="Đ[Y`'Jq0ʿ2)1OD~ٍD'?uI kBhf 4DHZ'z*[ld#(m١M@7|2Y/x+^U9@'M] lx'C̣H`9yp"jv.ፊ,zY VkoKViCD>EPNՄ utWDaMd [E5#ǐdnȶdA,_nuH w~xQ[Rx(SǢp}OxJ,"B_6}U^T ܝIԖcAv-;v|%Ć G(I q1|lKj XRӮv ';5FVYRjwwG5HÝn 9Wɫ%iH "i8lP$9 bL-?AOl QbWEpBOPer~eg͌J>Y|r KY9fb2;X$$,T1.BWLr#S e{XQ^(2dtMI~S {E)ԚCG<@ku|Ubo$EuTV4J5?PR9[-@^5 KN@"oqh)|gM9tYK!OK-Y4}E:4۾jPR$aQW4Bʫ\[,ԎAx+ ]G$%g+K]|x>tV9ӻ_N/~aQ^:%Px@p?롧蕑ҁir(9@\/`]hKrU6+aFφP*{Fj3%P!DN؝pzN+\ q%08grMz2yfZJ+[G\>EIHG;֕zi~GO<`Nc8n/u"VϨTf5źumFF :P[OO3KY?F.AW!1q\Cd]#._B/7tQ=y_^?$#zY`RacJR TҬdȽG(kR{q@*2w\ |2m ?61T/}ױȸW5 Cmu.{un:$~.ݚ|uO2I7kFqjtp8 ȧ8J"a{LwexS>r<X@h_{7KǸT47k3BT4T0HH͸r9dݩBO_A̩qjӝ޽H3MVq0 CeCA߯h4WqoU&"|_DSuVyO4s`^aytkK^yb䎄c-u^謱4lň`M`~O nu׉TV_4n(π6]6u0w:I#ZISC.O p wEe9kpM֕aEP|-#A&PPƖ۠(iҋW6 2 (h;emGc EJ ، q ]\هsgF ? o:bK7up=.<';,*5oΙ)NG?J@^Ξ(4V 2p)m;QK[-ao_2DcN"H_ FM & bp,҉xN@8>#>E$HY?b{ٍzrlf 't6hb-O+fp9wLgw<8W~ݫ՘l~>,"BTanBPS9꘢B+:ZɍY<ؙi]ݙBHw;I6`u]v"8YHJϩn_$5ЄD%Bkj=$>ebu`',ƛ)㤠3e7")qʤq|eӔWWO q1Crc`fÞɍW•?y3'$X<†zaucL'+Gx2h(^:yF]&$I4ŗSJ]Ԫcn<ֽnD[݁5D% 1hP3& pXg~ECCFn%pv7z*I7a48_pĞ28R=)-*ɌP23KG_O}Ic $D&AX" ,nbɮ,78^afӚӎ;9LB\ a7+w}-5"{Lz1Ӯ |ꇛ1,-+[lc#EIs YVm+ Zm7X:3]bIڀ`*.0LzupD-odLG#X_6!1㮟;ғ0z1Нcː,JA}fҦRkiiӧy.6B90vHH,oB9ÈWqI qM UaX$|s"B_#)76jk ѽ+ASe 1Ѕw7R@"wmo@pDPrv&áo+7@EA?6Ư6B@PB0L尊+k`{%ћ:;2zRM.Ù(7emH9:!r {fܮG!Fˌ W* )+] 3 ~Ѝ]G7.5n2^Qlc2z9@DL UqٚѨi 8 ŖL:{zcw|_JC,G{Ố] krHOڢ^Nyl\.%XU%ٿ:$)2#Siy bXDn KLZ]e<)D8TBh ﴺ+ Z]W*62Vd_+vu_3Mlt+*-IxV@Zc&Lp<%Oxs;4DqG%;*žÝ V=hm+x;V1'K*L}KӥJ' J^46먐pODMզ1e÷2F}r5HqeЫV lYa'4QZY WNN5`jB͞y}>E+>& hO]&FۧSIu5p$a&4v84|JWT"! nkQ8/_z:x:iijǏy-i}[8/ɢ0 VFӮY2!b 6R  k) ^ݤW8CO{zjO38szR'~@F,plBRRD\*4 3c9㌔W>/ѝPujGbQg6*We0R <5{D5U3gFXKF=h)-Qw 76='mN$,y5x5'Ѝ+'/!;_}dfe 7XF -Z-X:3kGK\Kb.UU/ gD24}ј3h܉s:bּB |T ٶ8aVEʜ(-fk`5f[-W _G*R&42'9*ʃ;5DYۭY{3(6+Cϣ?<rZLZ/@&vUw?vGpwv~ՁAU*%+͂E#v]38ߐY%Խ%RE?hw(= u6R[KpI~5*굚ɿ=zT@Έ?}-C/Δ Q[16H?& mel?9Dh\.䲐 @Gӈ;qPkPN(SՏZ̫) ofdLhhxlӀ ZpĚI^5V>UJ<@?=hdXIKu9Mdvwdö;B|0XRlƭ d8bus%L@KŪZ ?ulCGG1q} ȃգ9J;3*ΐB!jC^1 #+kNV,GFk^eI;̗\ܠ$gRP wlufa%\A*ZJcQb"}hF4~ QUq#Mtög.ա)Pxf {A웰UKomdjOY꫸D(<++*Bp .7Q1I gv$XQ7͓)68== 45sʪ2  nBqvxT䧎oS>LSaʒ鹋b/HSþIלE8HHʗYE0Ǐ0l0]yLIJ?kV0Bb["l2f [jݕqjK\9MeԈ7N`AsA70]H}KĚ]o(ש, &+{㌬_J; ALaU} u>Jml,Db;KqGzzOsްZkYb!sxaSN2mՋQM6Վn(g_RwZ*/kr 5j@nyBpz5Z4›1]sPɉItJpͤjbfN?okGd I2zbx͌nH5[yDV\I]ƏX =;qc<8fm3~ Wa8"D:tH 0ZwR(L\~:HJ?[o O8UIpBbhY}=%DlNنQ(1'3Z={!\5}cu~M TƂㄯ *xo=ύ:ȒvJ6B(iDA/P%N*9^WU۾0qf\yȝjHѓYmQR~-{~T!N.CNR̩<̇%~DyD񵞋 FA?JSL@Bv×y)>KIE{F`9Xێͪo3Wboul ̿In|?. XܤԽ}G5TSSVP#p 7U촔4ma4]#"!q3[^x:pp#YPwe!g*U<=:Ȥo,dev#êƾZ\sE)V#AкhDž'E +IVƎOD?zl4$iE&@R:ʰQ@'aEN2u|鸿8}3,TPՓGM1jx>q(7[.demsocOz?GaWYDқ#yEP0RV˟TֱnڃW/eL0hM) GΨ&+f~ЉX1\h,ޱukMT,fsjȎ"x|d .ɻ8'!˭U`E)T >7)Iсt{uLsղ7R3Z#rJNYvʝL@<|J O\1jњ$)Y)~3iR$8 WI){iW @XU(dJ#ip@aJ č=4ֺ>9K{Y m`zeFZ݊>`T@hT='e8ށ8;&h/G~hD޲w {34ki<@>wzJĻ8`Y `Zq«2(u]db/wȕF/Gi11."nQaV>rTI>&RMBzF|<4Y0n7C恗d^gsx%`,p6v郎KgFH]Ao-svl/˂L>׳I?y2P$v@Z~#Pflhz-0:ӟLQδLL[sbXTuQ; ~!C;J0*'Ki9@lI]Hd-S4}Qgʱ܍[ hTSUp#N>ɐZ HP6$WUz%:'SH\Kp4Y<ϱu%, ٯu7Wqf0\"&"LWl.PNA҆遑`ETzj )(Ao:}7Y8Ȣ[o1)`CgeE`̛سMwx٭YGIaۤDV}Sz/@ުלDž!BiOyQd1a4:oey,,g,^~,R?C@ |wV=)[k4"wyM`7 9BL=>4Tt.nh[0ibP?m*v䅞KƆ<1z@sᴥ@oӶ5yW6?tq,O'߸܉,.F*|i$Óq)dUGmFDRmPEw0l-\@P!HFvX=ɺ¢ X> ptȊ;ף kI-)7=vLϩ+рlu&&SɄPd(7͔T=š7sAgFQi.;fv~? q[*1v)F{Dγ!(;=rTi@,Ė k ␲;Фh;} ۞&^bfin6.~} Ӓsch2k uu cMyNX^8l +:͟G nZ)R`? aS":- k"@xfHWW:= -6:˱εΉXBa .kqyly=by F._r*yJ R|+ugYTa SOpg qhU ߙ0t4hB2!+;@}p*t3wP3D.%G?8Ǯ (6L=̵DH+?siCDcnM];?;gKD#og4<YP>oaRl&{5t%&7+|e[KK ;-9PcP7`ujx/ pL$ا{Fy\ICb_:e~h/`|"-Bv1 kְ=iemլFzn㡹ZsHӡ~+j5{BZ_vFJN s'ۗm:5O23"= :3yBvO@ +>#CXm ONm4I X{《G'K{ /RS=XԼ Q$2OVwrpd8p/]O=i}!0BPmM[у H0VKhcxZDˈ+4Xb Qݓ&r}QEȁ8c?\bW#^lbI5Z՞z-'zhK"5GǕ]~nA+93"9pquŸ*&UA0ŏ)}Kܭ*gU4x8E]<7euOXuZNPuJW-΂(BA펣i, 诮zΛl|\ϥ /}DV f Oo?B޸Sz~}- ,{j/?T43fY@;zǸ#K%O7l7hͽ\k@~38雯Q>s2&?w~QP!ϿRzG5#ZvEXH~bUdKxȋt3#' W$4Kv@WB+ D>x{=Jشi0SE" 2%TcCOj'pz<=T`%%7RAqYxb41(ElQ'Pt4Tň MIWHvFD|U toSY>^lK0 zL luKq[._0,w16]bz.Wl Z>sPN/ 0n-Y68}a_ac8aO"$0N7+ [eծ_oru mv4cRǎ=4c:4 kEw9?X/zglOq2›U,p5fH-2 VRb܅w?C'*5qe QOfFxhHR֕+ĘvTj2,ӯ(Dd(t `,m*J)Ҩ ǭr,~ 6Ĥme?o( '$nFqIω 0n oNRb;DH=Un.R4.#,N@E'B[/RN9/-Oϸ8?-&ȼuϰy ?ˮ xSZY d>4"'wQd^1+}S7MxɓqbRd{wqUmd.VT#DfN/%S7MSxτnq =+0mUHgОr"l׈W(2ָCPZR5 8`aw@&m'h*'Q3tNr)n13/:0 9.Lmq->ђ;uq3iS6v-'#uS#-ggh6Fsqۦ =cF2|kant K^m<[C "GܲJm "CYly_;.qj/.֐Ng}ntK5lN`gOSxSt7ro ݮ'Q41 KzVeE0.T̯x$<iDMq$k"lɤhntlEIGUh6\>Vyor9:?ޞ+zˏ;b3Q8?ugp|٭5I\O,b8ƹa$T*[!og rOOo݉{gk#?e倚Wr݌^0½NVĜHUa)mPe [&f1Ьـ-FW$mo4ηL~Q0Ww^ٶUT+($P:_.9!c6kKpIWQX{zcD e̦#E]~AW\Ǩ ?_J]HY3^=2QաYTу7v ck1i%N###"jz@\iXt~7Yѫ^ŵ+I5<= ݱpZ,wQ*]6zn8/g3Whn+q- fnIM/rtE_J5`/ɧ ("M>xT,x-#j4)]忎v:`1buIKg \ϓF^LǽfC[R+&oBe4N1_& a#7k- hMhf?frL/dŅ|o;N`NTW,AOexAjF;Z}+n=wt܅1x U2:kWdFCHnp8pU3n2>;rul W"1HJybWnpj* fL r<-jlބ }9L\ Ok~yo֧pNkjj?V}b2Qڶ!0_\I ^8!3uUv/>akny\OA9 v_c71dAM`mey*2qQWeQIUUZ=7«qX9Wi]a/kkWzMU,%HgqF]6[ʊfrDlUGc:}y5Cy(nfU1eCXǾɌMD_,;k 6j08G>#]&NSG(a6Ld{@[uKv59e4 ~BO>]Haxpb^6)?<g{/2@/H!p6kQn/x#>vj UDR^0ػZR!̕ = }D`X޾Ȝ2 [1VE#SyulVx<a~4;hi~Sc<#>i{g/ ~[gcK}'3w r?s$[ ߝ&@. Y)E8s̨iY&V8KG`Rܠ}JLI.iD0f^%/ *A(SRG*glTE"HxSeWv8:L "I,sDx.t4 hMIJK]`b@,N~ž c5 b:M r@Cyȕ"OٛH=T)T/KeGOu}Y}rW6*4 m'cZK`XGt}.$iʿVJ =m40sE\xN=_s;h%\5fү9[cf l&uދIPae!zBJ=d)ٍ [Z^'/G 4K@E L*6LIJݾQ8YŽHkΩ#0v BZE%:ɓ5$3Nd1EIo@Q>%( JS>f᧠jڶqFNzYvğM]MV1X9$Drڨ;6k⢡q:1""6 +yPE@78m;8@b0=3ɒIJSt'ٟ3YmhGE )I=h#=JYŵNt>#kbE ,Z7*.`Ci3ܙSGo|kr `lފyбO*i<Դ`-,wj9&x?OLۄ&E'3t/|1ǎPw(0tž&ÞW5?$R!?2239b-@."c]mMՕo]yqfϞF,Y.0U" :hDfe}.. #3R.ΝJ;Z+U06^-}=j>O ?Vp'p5SFyyÝM̖wkBcYZw &Br*Cݛ'0 <+Z #m6@QFb!' Ђf1.o``2Q`z@'*Z~04Ì]ϼ[D43hH}^D͋O eݯ (˅]r pj'$Wfٕ( P?Dl= UM H~ؿv : "ǽhC6+ɝBެW" I q|YodZ *!k>ACp$^?ܹ6{tLx VͦJBPO" R*1va.ϥA:uDމ焍gzTj,<={&i)bޞE,?9𱳤[8_{p¦:Pt#{o;5/[| w7)zlan^:GT JWؗMirp::*&PQ H& '1L(kAQ0i#^q~ 7ȫr 60-1??**/59/xA_*cEw5埗|(6c*:㢷B>Ό}LT JӛJi:yo@pJ4p f̀?;4<8+40棪x);">v?m7$MYO?8"G*E-δ\KrU 1"aj/?wY(9:[4[R\tv"4'm!(`FZK-P$P@Ȣ#DA*Mԉ?!)XnϋqʜqKB}m. S1ÄzAVV5`3('Oɻ<>Dkn Dy<6O3(UÁeR}F'!хM//6(D-fT\y-۬~ W*ef_ȭI0{c:XsL2o߀1H@REb7u稪Q*=TQ6I@}q-5i;9oBBkT (>n5lċ^R|SFZbcO'֟5F20C48l 0jD}?w[95 ȺMy>͠y,;pSH9:˞:xޑK}u;j"9 Rx~‡h`5:(bα+U=W$Q ;?` c Ҿal{~z͐AxcxUMvq JF hXz$sBiVv-嘘CkkQV9sD~X- ͓'bHRt >e? Ch"p&Ŗ}ĪG)|x>;G*YH4ʆx h̑hMQHoBbͳ݇5&Y4cPr?~S`lU[xrzrŢD+ݎW~x`L;>N8eJe(P28=a]REs2-;?ei&ld:e-#..^kx5GCVQNҌo4I\zMrۑޙ2XqrYma~wvJű4Ds̉y@('WW_v*J X9&Z|{M`3-*^n!8eLSÜ!2d/;SD\w] .L䰬i#눉`8d$@]h"$r! \WDm@V6^G@v*vpPҖ9Yۤ[l8P13[Sb^eǐN؆~vl1CAnr: pΖيBE1V_9h{3|WRM=wfUlHpBBKs+2Czm 9[f=s?sM̳N.#_&׳Hߩ\T!Er8=]q˩(f_96bw)Tao<,Q%EpZ)9d͞] H^RWU(~"KN^8{k# +́WǍ-|+÷&o0#*EE9f i”$ 7o땤Np%6ɣNՔ4;VXY'! |eEh }$Ssr/]([NB-{P Mjݭlo`9㺂FPji!4VQL}WH.ƺTҦ|㹪s^;ky~J{Ӏp $sK\U8Ge0l6ol2M8XYKEqʍ&ߑW5brͲ,D.CDbo"ώe[<2%H{BR'[5TYYB7RT'K[b plNkkLa]!OWԒ+"^Sj(GCyA$!|x^cv)hqw1|2eb#5ٱZk*ܟ+C yL:\ `bQzfornѽ1fbQ*EY"F8WUARyun: Y+JLvn?P@҄8qm $7ꙗ?O̧FݰY%0U9VH(C蹪g 9FouI"RPԑ#^Uӕ a79E% 0Qf1Ųː}$wV@|2~v̙$v% 6w4]Pąv!F/-"`B9|'S{ҢX#ĂiD1Tp@Q*, p0 1𠣙M#x^WB 2!5{άI9^kYY10kv+7t!h5NFs?H| ĸNH~n-+Jfc+n(>|Z0?3uU<^mQQ7B"#g75c3º>: 3mB:'[N>^]tijʕ:wtX\v8o kgۤ\-:>:}LVy,2D.)cyWxrݒc[m!:pk^kwt`?x X_CbB{HrP13 hM Y Ǣ UBi,DevxIHFNЎJ:&.I;8C'mANU7 Z)E=!dz֩N\{`H=֪'V6mu.b[kj.vl&.J߆ڿloo֏^mī:jK 3%Wۡ{p/w} kjgԅ#q$& kE',Š58p7Mt@-F?`EKG"Z78oϴޕ`8DC2y!2~${￶D.Y Qhq5OSnZhLҖKzTޚ]hS@{ԙd.!aʈV~Wv،kjoWwO7 VbjV:pq,5rkGi)6oEf]{NAB0:o͕QUc9L4I|~`6bOQ+'=|)uY-:_0kQira4K{h^N7.Ĥ*M[a&3 &/Bp36 45q*QQag)=H[$v$vMz$v  Yqy- z`cS{X٭8x^P`G`Lw>mFu%v2] vwɱn5"O}3^Z<}&m2+a "aSRR!bՈ-w-8yM"Q #@4ؼ@Kz^{U&ThUk'yI;砕#lΤqe*3C>IcO պhj:qcs!4Քvb6&o[̅zŏ/'1!X:,hu1vjXr@jRCښv8 ҄"k?W&zrѽ0bNgJm3IVj[W5hhOTB5<89Qy?}o~$@R$b2C@T~3GpT2O[~60}xeKO=J{@aUyawF;4q [KQ*^?<`q%!`˗Eg$Rȑa01SHxVq"QtǕwV rC0PqP L1 ,}rXc3NlhXӝ5?q.:DVj(ɬ"V}->6 %=#tX➦7}9HL\/-p3$zwם̒<>4oHtX1(en".x $pj]q̒||fq8zo`Sq6y P;iK;6,߽5 uvi+.ݙ.UT5(OL5i,(|(|n-^8+惙dFZ  Z-b"θn%|)1kD2TgQ;g-Z%.&tkpna.A(۩gNh6~6B[Љt(N',<{qNn_3q2;JRo=g>] nIJaJS3LN K%I$vo_*g@-|'8cL{6Z IJ)+OU܂SYكyMq$@5l#n%R$%Џj*ݐ1DVUfֺ k\{z^N8sn*VORV&>yyj~]bn“Ύ hgoaU D@Z1G`U ϐ1< ys/b Ck,>SC)O.FAς$jP .˒+!P+Xj6'toW9 [(Px'iR{AcN!~#p8~_S^gaWj3wG_X#ԪqbADJBM)%PIpԥ/b;a`sp"Љk/YtS:63VSz#\e }o-w a8@VM1ehr} y=bLMJp}Iзe=#+$}`rs-zn 0;!-$N̏Gt0D ,C|Sz 'Bp}a-oL<=Cavۃ3FKyx&m|a91tEmIx%eR)ED$ vu}G{ ^驪G"%` aFqˍDDZTQ`a-/2W>,,#}lZ*Ѕ)+8䬚O{.7PzdD^8T\mYXngxLn52@UՖaMl9 QuA 1|\rS3QḮDkIȍV,m#zG~@UAcv[y{7v qYb61VP#]ZsdK[Ik |4o]{wA幩7#<`{oX*#Ƽ;(0Iq16;.+0|To2+(V @yӅLPS{CWvuFzp]ۑУ ?L?2. iceK=C;vuӺ;Wq#oXߙkƌ)0}8ߠ6<(t{g5_U).>RGXmaL49E⪧%RԥP < E`Hz6OpZ܌}q3<9q2h}|T$ЏD91sz−GCkZH,ƒe'-@+jiL{y܃VzJUY nJ#lM-Rd>V(}h!*ĩ#wuvhKq,!C:viկ}`]%jU _y[GWq>iymţp .~nK/H|sfk#plj rCv'}} 3}Zm܍ [d ozh0ݚ!ˤ[PPAT"-&,vM בQ_4/pCam FĘ̬d$š}2w=`-W%34/ubo#ͨۈϰh' 1T0ȇJ {ԩI/ =nglkRg@vgX: G:X5!@NnPv/ϺQ?Q`C3CODz;-{z=6l.-rҀg-G6;eŮ~\>>k?tD\.k ǐj3Dj0Ec2Rbx0oTH!i:Udg b"_9#ܗc]-)) iZ\ 8_?AoPsԊ*({]9TȌ_ͪ]ai-F@ҭ 6*E&] iaD %@p7sK)"Qy.A^TvXt 2e8vyD4~|@񢋕.S0ljb [ HH715\apaFjiR QypcWޞHH\VGDƟVۉ v7%jpL\tJvetJݳ9C"De&=Pn I6`a'H:z_Ϊ0m$ֈ 'T a-=EH~v_@[83[֣:NYi;Um6U~M׮F\Op܉mD_{(@oDžܵdwdKp%&T/Bرm vHL%;z?k[uihTgؚ'>c*Ί(8+7+Q|Y{h6oGvMǩlTk=%y>hp! 66EFGީ]Ƣ1F)1yM\Ԩ7YnB[p_28NĽXNVyB{ FyX ]{$72B7CA$5>|dq&Vushb5]Я-+Aڵi3HƲ3ҩ²]gr:$2)oW1ܻҗ4m[fٔQʮ+ħ:YRWPGʆPdؓ86Xfvzk&cQfsp^iϝle2Gn6u\[VG^)>m7`a/ɬc#}w9Z( K&f&xO!?j,AK} c{<9:&I.>s%SPw-:bo67Fg]kbh ʡ"T,;Kt_շT36b4zir[&#ϩ6vN԰ ^λ|moM#7->@i ?<`U9 bh <'Y}IgYmG16[;6{O$S17mPR{V~ꌇٓI2SUk3XDjQHHhgVe#>;x0p=k{%4&/QiVpРf1z&^e XT$FNϗe}W~c1<ϾϞa{(2ۥʹ˅SՎ3|5Vă`;uWtmSbW1.nh5xoO i$ي&!1zP5hϭa&< IES$`I֦Bk:Ķ+Mm8 J8Kqe{J@emZVh\C64:%[.Uc6JƉ_ۖ$ko=lZFnb -Iƭ0Dce AwÒM Q~Cȍ@ȆehNkYؓm?[MpwTWg7@8!,.=OD0-d46Wyg?AN!ݮ5=p9 GhUjU{/֦7wE\l=9DF! 2\`lǭf=c,Wɘ:ccwR δ 5|({v\`݄TlK>Xh뿨 ē ߯vnL_pQ=B$5]ܣ % Z"%j#IV,\;maI ɈD#c}'8_]1S íB!rق K$]9')A \E񂻉hNF;L9{M(BNLn-j+Z-'yiNH /`97ֶ;.9XcEe/%ǜN)8ʳ ҁ㩾*Pu{\b3c-V,o]o'" ) Zd^ LU^A{p A'Je+sH(6׼4JߍBzyfL y0wEi-1#>p l63 ֚+cuY7E\Âa)CPV5l:W4r <&ʰ&Z!!r@&QWx7߭3˭a(->3|~0X !{M?X?WvJ[dϺ OeǷ/=Qwٝ"fWuW*e乇S ~M2y8ì$qn򂅑 AfEloO_m0nHaĬ$_Kȴiv6'{z-Ki/2nI04u fwELu'tT{7ۨ5>ؾ2iTHVn/*s-NOh.ԋ/:_^pmUzx6R6hQj]ӄޝ!FUe2Cƪ#z)Ecr\IA Q6Q9) d.+Jf_RR.=(X{ ~/6aZȴVHP SF\%jPl$`Dhg a츧P>Q:.%0! [hJJ}m} w%~'u 5|1(!Y f/B#C)kTmO=G;ixwB P qpf) mB ΖJ;UclL\a¤ ̃+*.$d>G?'YqҼQ~k WT+Ceb#ܺ9ofDlhLpISce8qIIMZ&"-R==hJ;;+('_Gf82+gC~L%q[R4 4󕕡2 |P+W̓vȂXB#J4bŠhWݿ2kB *1ytoH ]-һH\!!sca?JHvҁ&H`ea~| ~kkfQGఫM*dTc|; 0 ؋WI-,qN-0Whzٔ?KmN_ޏ>Wb) f6U07_ RjlPr-+tP3@㝞;iJJ#xW] q/zscLπ\JݒxHى3 n_u"ZX,9irLY@baӹ@ʠ<24)l 43GY GꞨhRi'󡩐+l q Iߍ ®OcG;Y$?|_ ^k O]w+SU${VW;p ($ f—% 2Sfm fϸc̰)nX#0Q:Be3bJv[;\={S#1p8 'qQ!r7T7l҃:NUCSvr-qGrB1i&$D졕p#lOfI%).ހssv + 'sĨ+2=P)^:\ ߑ=tPUv" B|<?JK zE9-- G+HM/x @9 lD!_SI:5qR,cvAU:3kسGw%S,FfA'Ay?ɚQ3Dajyg'I.":q]%ZJ> $I5ǿ2n\&e #yOYE0G C1CH(+;d%Oܮ"`\do?5aX&ɞKPU~X(.][5(9@FP1;h!-ܝN+!+ |+,XYH^AK rT.!wo rnEmFf'א\߀ۇvw6Sw?WZK~(UPh;ETsGēOq5R3ԺR:(bFcgGx81N:i*wWѮ#Dnw@B>,UN"MnjOGsĤɴ /]Q_TUKOàU9ԌiuV4$' |;('! )cYsbz7BאVE eyG׬-˹(:hÀ(E 4u+SJN|қ4B%]*Ⳙ8snFhԆ)QԐ1!H;~*8IE؜tGO%x=&^B]U›$`ͷHUnq5C1+.vF+Sњ!o/j|K#~ UiԞzg/:T vYIW;&(D̋HlQj=~"]p'јPӺv3ZNx{rC:Miص_]pZ q:1Ia~&@~h2 pV]Oe7˵E* GoWM(t<>M?l0# mڛ=/IMd)1ȆH;4%ke7i4"zۋCAy{vB|{(Z`:tlSҜhG؛{\WMuhy{+c/Ua{uyDf<,H&7 g#ذ/w;MҾdPXd<}F$`%[^;u#fZq(5*x%ɍ VSqruDl^tp6/:OAP}|GW',IF*[^p&Ѕ?W<@]"|:o%w 0x(R\3C *#TDxtc<1ŰMLTpKWefD5pO3dg ͤ VV-Ρ7no,-Vv0% OQY\Pz|JE^7Dj{Q7 `!JܽX=C7vN*Yg/Ӆ'O("5hrϼXw0Ƿp|Dg}c颦F\ Ce8U%GBOR-z<,̀`pqYORnF,!dV=#CnG{̍'IE>ZSZJrL ?vjǟ=z%0#|ŊaxYUª>bGIWtyPN%](4ˀJdKI?OoI;sAV6 /T2%\L"*[m[dR\54 .v ?0l׭|9 V`\a޺( Ϊ+BҰ9+(ϧQ36(xy_nNwηsfS? JJo=N20w pm4.H #htI*q S҆}1ğr&d(,C0RәC}T>FvGߊ$T.726!ri/˱x؎\Nf2>,/Zk-d!e@RV0q*= {UZ6s*SY[tq-8(V^9-Xyi.+qxFSL]UtQ_ "hncy::>ɵb/;OoNDS!mcVNty=Q9U6O|#>XiTܥZv 'ݝy WJd.g_gB?EGi|)R5g߳pa$rio0k/Z[>ZPfr^1+f"(YۛkN\o\Tv#; 7yKnÈ^)xԂȣI{U@!$=d(\1uig cUz!P?TΜx1.3A"ASbNdjg~dfdLtHXFV"jiW[\]-<%L,촸ct`DOU"x%Xj~1YKf a3ǃ; wp@Fx$u۪#uvx̕LpJ~YMp'q }zQo<[6 +ް0G|7鬉e & N3FְX"]#DȰ8l/CڃH3=@e%A[[ ;8'#yu9jl e[R1ydd5M}H4*@K %,cےJb[V:s-gw 1dV7JRJTIcG@YלۗniDt${uC4Rxø .d1;G bJ|b:}݊dn^JpcX3UQqZ[[u\zƙMLqwC꛱vO+G8pQ*g5%&=([3N#F#M]$ƽT`[W/Ŧlس9fz6y鱗.q,x`9Fغ5ElK_ gxe՗ɗ^ iszvGzl.3oҼVPLX;C#vUeEC:}T3le!@ =TcF:dԆ@;6M] О/#$Pj6[iƊ}Y 5wɷ@ RP{#F0 ,하lIe!CeyO ppA$]v0乿G g%?&3+Ͳ P*t(GY)NPc﹢ l9r (OW7L>ˍUVӡ-EBH\mD6:K_귈`ƛΏt aFf8(0tצ=c 6ekJjy)\)=@I@=3tHew^]$@{{x 7Aa5'm˞3C6:=䌜[-muϖ3w|GHj9GBF0р_|PSZ]7b)W[p#gO) ZjL/E[ yHWX:'GPM'y]֯#*aZ*äF̪Vn$$8 D>=JA#EDN{~ EޚEr=_9dzAݿC:=as-̚i",Nc)Q_lJ&gLYpTT3(rV^A'5=|VĀ"M}[i*T/tTKgF6kK{"m:8`  PF}'QdcENϐ*^{8Nh@0 j5ۃY@!TR[~MԠbc=LNo{T:swfbBo ^(r Aum;0A[L2&oODL2I]7F+ zhLqD7Xٯ?LTa$\nZu& ~:nUۊnPUWPe;OgyQboMĩ~j$Ҟ60zy 9Ro풋Je?2C#qօ;CjdT#딇y<-L\\1J⍉rnIwP94ec7/V"&~v'2f[ړ|ɏ3njg8toxdU+vIl||u=P:)U:ij8&o"Fxi'ܷ>%5|0d aN.[j8L\RG o-  aM'7Lp1AB|rkPr&)rױID~+|ŏ8uɐܖNec_Xܫ62X% r5?Ty.`_q)i µ6uOJS}!F(O ]*S9"+! &~FbMH4k8pEv] 5oNUi#呞 *M==2RW匍|S%S~ʧ,%ÊH{V~^ڣ/VG|,L}lDH%3~y$uKa+ 1C3#w56di('$ֶcƁuy˜b&*gd_ M9pr?vVZn+X52/oNlvĝ|oTv9:yͨss"f6nraYufQž'S5|8Y͏k ߻$TҢ7iQ\N.Qx]AK^9|hNQg'Ys-n XJ2ۜ srF`1il _.~pӀD[q??!mr2Y}'M%291oP #+ѝ9>poDomS`D{;J~*u!UNpܧH J%^su,xO/ ĺ9'=[ r, NDSe:g.mUެ7F{-/d\UPaY_^G13p,Polv)(~?*)X@*:be+v3@(ݙk'QҨ69ׂ1}Dz6{< C]WUz ~s&X(yZLO:lH^Kq@iG+H' Ť<.;V'P@I{!~dsRM1dPnkl6uj˰ UV}|ww`>tZE5l,]H}>{N^&3RT% ONO 0(^=No1@ &t6 ;{P.CN.}T ."܂4+T_S b&NݬqO,2'$k:# a#݂\R S_|O7#;{b6uq.+sŸVaqV/>ݑzQ0\0ɅկNWC &eܠ70JNB4aKm4'4.LdN<@맹k^EԽIS@|X06-` Ԣ'obGb٩sжoPmBW *'h{$<9hvTvv 1LCqLq#ZM: 8=Usz_Yu 4Ȟvh3,AywTf-Y9W`8ܕCL "ݪM䴩fх$epYj-]3 حأ851X۵?H)w5U17BRz[{We*s}r-oTn|c3ύfI1߾l:WQYd1yrqG7 %cxBp_E_G[Llj$3ˍ ֪xW/1:D x`&O2( LJp$a!^Y3nxGscp %{ H3{s[&7!kbc?`zy"  Hȥiu\ɮ|`wU{H aP'ۗ8MI\.[$w5{;DOb6 V6v~+ﳰSn=˓M6Kz~P7Lu&7.}lLi~Jrؕ:t1.N+|8'97>qC2W xUz[)gMl%!h^ZrϩƼOP }r/Fш# ZjXI&ttl(cÂԺan$NK!V"U^y!iSDnatT~6ERIm: 5m !uTbp ?nk *6!MRK _rrsզn<ިL]ǞEQcՀ7M#T.tR`mMH<-sL/,L$7swe˱iQDťu̕|P ]$6_yi̤tK ̮bDB*J+ufس}-=TA?ި N&r&27жA0oQ!Iҧ 'v^[5*5 F ۝}`RD_ @kn4qLEoQOc O!$[`3  C)aoWS+K t.+{b OkcyyԒET]G <8RpvDaոLΛ!Tx B FT쓥]Х7A6Y l6?Ϯ{ Og1nF3vl'9,4Y+ Y#ّx";5 }4$w .nrthfQGVe(#v;/QG3[ux.{DX$x G(W}odV8y'/q9e9' "} ۶Ǵ_ 57;!L(ȑ[FjU;m =d~>|gXk|=R['Q-V'Bqށr="k1ǁS5+:jxP#:$ra䕏U?_u=Mwy֜ñ;N/CZqŲ9ʢfqҊ{A-O#=ϥ3]X\6VGH.HEA_ 2EQng/Ϯu O˔n9"^d!q>lqK*&C&R ǕJ*Z2XRߗ= ћuuENoθ<:f<9X/e/fmoxƗv(q܏tvI^W.B*[V#DB?E/ s&dI68Ac[m/Zƹ;\;-Qy#lGw}K= {ҥtӈ=EGTc(7j@> W*ڈ;7pF޷E *T(X/p`]M/g췸٢`Ɠ>>3jCh8uZyiu`vd }QMUfX)2Ti{ ^-V6w:,ϖ<%r)3|c񵹺]ʖbqTsU=Tj˳eМaztO3 =X"jf|hv޷d ԯ!/>Zdj .j|{؉^)&Cq#IKxoRcJґe3=#q]䡴)O;MB:^ο!5B' h'lt]6"\Y?:B-dtfer̽4]NFk΁7,FR˶A"J ˞T;wy9_܇ĕTÁzh4kAX(>t?LfeiBLta(D.Spۮ:uqhdr4Hi8ޑZAR0wƷ͆/dCmsXCgOASjNb{H{1 |*\8/FfBsq4-0K.,٠h2p=# z8Dph*kr]a;^?(@ncHxÛ4>+6\OOB$0ߢDZPڃ 55QF ˄ e ;QgC*B*oZ-{րQt.&]̂#zqGzϊrХ_XS|'ha#MFY)d:GDzK 4@**ɑ  /3KX$=-,bqi(.{ά*1<$ֻ떼+xϚ^kd_di ֏*,5xp:j4 p &,3RC0uzӐ^aDO]sEJℴNū:0O_ |P&ą8nx:Y͕_)!by']R|LwKy_œ!sp7R]&O+\{ =6WO5SYU~OWKby6!t[ɠwH Ӯv+S{Z|b$ε2*j@I ]LfVK9Os7 $?^rIaІZEvô>{2 ~ Կ̺,sUv`(m.=XLXOoENdpu !$M+ ׼ѩؽ܍f[[H:>6tV8b#ەY>JtG[9gWɽ8* iJFRӚ&Ḇ.G:Yc5?ކb뻵IuA`"0 JV|r3%%L )(yY~1?⅂C=ILz{3|}$% 9]`) =J7ح/ 祴AGa. ϵND'GO`__xqBP0B 6M'$Xme!vfhQv_`6 W`цwaCV`S7V1&9@~0q\`QJ/T8;~a X> z1R,^/Ghf2P*y@f9~!T܍/.G'*迻k=t;L l;(]gc\A| !69^}mŖ3jvLheM}8خu2YrV3g00M;g7{2}(zģUCOG F %2%U[K>]8Њj6n}MkPQM1i+׉R9='ϰ?{K:/=)X+_}$cX3G3Vy+;H#u \ bo޴jp $C?# Byp@NbXOFL{z)jWF/%.2]^'ӱgܼvS> 1$j=1|ٽI"x[{-J 6??fa1RNIu?j1'.I20˶'9p$T~PVh&_XnP}~] ;l#R(Cp|tIBP0)չW7yxMC!&C(L_e\Iָ665 ATYTƃ֎עU`G<ARsyzb0\d@}2ō6j#%`o˽'I.Rc?9awo!άf8[-C;T_yFp'yinjVs į4R695i1RK!ҁ.f6!7[*U=bRdlj^oU*=nDjV&Ǻ_ՏYyCqS6)3 4A3{T4z@n9〙AdGnG #2g!3펙`:@Z/Ia k[CmRlwX7'"]04]kw>H]տ:Jm~`1oE4 (=]L(̉u*rj!Ҋ=+üMgnta[q祅Su Ip6KOEx|9j3i) ?Wg.Ucko*ps,ؿD }dp&(Wcw~T+coahTף\-AQ_i!5L]7ƷkkAW3 Muąj/qPiwGBF^ZH{ 1FQ+D{-e잢- <<$G{s6nBoY=#Ҿx%8OWUX? \Cf,FQ2<}$!HM4O43^:7lMpAœ4;O̒jdCni:wܸxN] `>TAPpv꒺B2}];S-*Ad{_!7@FCŁ;&O9k3jںObҞcZfxEF0ϲ{I\5)|9X=yگ; ߚ2 E ϶nwه1PDs_T}&`YI?/ޝRAŶhƘbM 羕d^!&KK2a%Ffgگ-ˏ˾9#<馞@<d 9!ֺv­u`;b?v*7"G] Q I-e .~vπaJ¬f,!HڑGD ߣOfa7Qk8>cA/o]LgcULXOT WEmw ]wb :\oX'a/v#/X+?~{ǹ^Ofjas.! aRKrw E`iɘ#]|/=6Út 2*Ya7 y H>󝄽8t]ns& h ^pmE;S,u,,`vhES1&u'R8L'!>_7q% _s,DŽqjB'ŲG`!1闙-BnzASӽ nmGZ&M{Ts}>/6Uݧ,`ZjMe{\ 5>ZKz@L G$~LVwP5 #K͖gXUzSEBy>EnclU+JNwM?kiX?"\C??|I ,++wΆ,)%Ku=qZ ڇP|34s񱮶*zhVczTQ^6kccu@K^̺hڤk>R$!)J=>#I-qF;=>kK%u(vU^].3@T&<2my 3rr'悫ot98SOQNd.Ε0  ]"L/Dy*T.\tc:FTXGI Q1WD:k-Fu5ʿ/d-0mj޼䥲j[.H8+̡!f?L}K"xP Y V13.9dc_ ;ՠ#$ՔX#HKSpjK"^ vY>))?1T<=Pe,T+4i&X},,:0S%K+$zB_꼚|+  Vzĉ?@̣}uX]hE <~2ҞNL~{W PuGn#R뀜ز2:d&IGsr NEt)`pW̒'v76+'ļx[qwcn{|pjlCO.&=cFU=wb8aOыS2CN>"lp|}%H} 0כEmlo Qui4U jէUc0Xs &)zCUiVj9tJzںzUbTHn劤TҽP|&=as_Ԭd.gEG5s.PgXќ̘zRiľ J7}'X"luK0O3r^ɨhrjE`]ftw2ΉR. O.̿tJ2nop\ ~䗽4G)G>7/o呼2FŒ{7YL!s8nztThk0IApk?@5?_08ۯC&LL-!͏G ^/'1uO͹hzGAmr8'ěM# ;+QK0%YAeLadnދ X)p& H7bRlFH%)p~c -З+2liO&=P)Kk dt͝T*}E&js8izBn|{NjZµnk_:IiU"sQX j$5Ǘ=$/LoZ-mn7)r't2~o`6˞y1ul;_wSNH{Te} ~D#xόjpFstr")ȪJr ?dsݕR'薉.3(8 Ŧ!3:1tRfW E#O`3 džͅs<3j3e1Ų.u/6"=9خ>;ڨÝ{hS N;*S DC, uyCT4v{OҮ~Y2P0\z@/~)w;4fgC I\WIOhvZ4hnBB&#LcR, Hx#/R>#ǢCq(F4J)=D(&|Y1~)8"xҧkX7`/wm>hAL2Lu {?E37MݡxeC0xI8%"u2 GcܺTxPj)߳OUX>;ي f{*BMIjQ܂㣭yCYq{8bK!흊a[U2m5jI=Y4RFbPj޲}$j7SE*g'63$@0x;c2/ &Xsa Eu>Tȴ$q Rlb6S3Չ I5jFLih]yr0T9YvJ;t Xfrϻ䩡| OJme.[ȣB~cCjeTY)$s8 2rR`30؏9&ۀlf˄"'݃F~8u5WZ`aׂ7$o;>[c]ꡗ Ƌh3cx8O,Mti\(<BTHg%Hnr˽w^ ؔ~ɖE6?"DQ1mY[hFOV_8l^hAJ -L7]5PKﯼp7Xd)xꥳ1QRzKh$MATpجҭu\&ڋHoXx}~|>o_ĜmWAӅ[qSE aPB."i M XZꊊG %\pH~*o=#/$=^|# d`Hd@SՐiJPlr֊CۋG{.թaXx],~`(B#[NyϘ(eL0,~64{ ct mP7B\SHuinZ"ZLsI'Ղ Ir{]9ȃ)ِ(UM)*yWv}aRds*,P8˃4ٟ*}'R*琐j~`@Z<1ΤGg̿ib_eï{D%?d`%Ұ(C-ZI/R6wIV ӝ_7U>UϦ223 `| ٔF>/kM|<ُs=ַDL𢝁wJC1˞_onnR,LltҊ ae-;b3wXa-&^qY2JVģsHWBtpz(Uqawp ~$GEYxq.fXu\ ![90?Pko]f:®]Yw `j@yC'i  /o\kWƏoB|2K/v^Ey8h5 j?cöfZ} PA,N*wCs 'yNn%'2Վ%3'5k(5˰}J:rS8ntZ}zI-b/C&bP~\F/ ":<4 ^׈N(+Ǐ2$-){l!*0g$@a#QSH^?~17 mp`Xץ_#Yh-E% *% q6 U Us*Ic`S%H}tKD_MbzkbNKcHzDSϺ ~% 񋿔ڻC& i'GV}yw8>?WhS$'vxy!E4\fryʫR~p'faƒ2q"PADwXBVDVAI9\e%7%n#2l9 Pp5ֵ.٪k^pg ml-|qqk8f2YYK7e D{3*8i2r𥢬 Epe[*( ?e^hv Pɻs`S JP^u[*1;"x5cR4Ƥ~ԎO ~Ņ*?g дiB19#_ -'xŜB9CL݋{B:3)I܏#W?P~d܁'rP\7tpY=kO@vpBJ*_ Z%A٧iC`f9ԌW!7׺y)9\(bKL{CēpӥyK4}#aƅ@P:L&v mȄxFjrptBn :ÐVmTK](kao(pU$*ЧfCrOIijBCnk.ݹhkzŘR%R3ÆF2ҷTH:E6GC LIQ-n^25cVIdB:T\cwBlc sg 76Ǟwcv) 軦px ō՗~RԿwfxشFCp9d9yntCR\d"BqRf"{rHytѬ"TH*gJH5Y2PJBBLehB쐙?3O2!{ {i$coooD;'/Ђ_̆qhz0M[ Iiٍ{;qevl-%&c X1ӨםTTw؁ѣ\eq6қOTf#)"Ӄ E)Y37~F*2nͶ1?CĥXFitBp璓>~u~Y, ޾4ɽr.Cy1iVczOJWG>+ĵqǭy"ǔ)1AUuOܰjrnPr% 79RҙSokIܙB ĘJHG ؚoraok~ k ֍guRoH0iZ4aa-SkoLzjN\e9?;h bށzQOε 6:M0=T;'U+τ&.p6Ht ]%zN-@욀u`%Ԙb59˂?+-]{6#>A"tMZI^.k/*Εˉ'B MH|F 1@N 49*?x]w][ зPǥk}LEL%0䄚^ضy)zd2GM"ŬjSʌfyx(l8v' )yc<$^W +aXkaDLMFU:JA !rx`4$HBuAԵ؂fihϬYm*ҏ"KDeSq"y9#N!<ƩJ.WVnAz;3VnLk!i)HDKF5[n]i`zǗ)mTaX]L:wDfʉ Cre~F!gGQ=7fn0CQX:fD\\%T}!,_BS \guƹbY{5eO1oṕ6= %e_ ?*bm^K_s<VMJu+Dȕpt\mnglFԪ8MuěLJ:뭾6x%r*r%L&bkm|!FoJpj%i "&ݎKJI#:t! aIЙy_?\ᾇALK% _p*:Mib{(W{ -Xng}*xL=e.N TD:C]+:j UZS^Q y0rxm&9]|T`tΞȳM`Nưe.c+IJ^N;6#􉤐Ls$ĜOZלU8Bm$mn?9͟?[s}(A >5i=@x; @Pn"yA7]b0aP>}ވmZb_"Ŧz O5$Yu^]|",:+ٝH7%Ve0ܲFOcK ?VΣ;$ Lߩ(b]/|N|U (Ҳ[~~v`yA)֭wd3EpY+9k` ċ/xZݥ*F =y,n|CAl.B;OӤ`Aζ\sЂP:99c^ٱ# z>b3AP?'П(د];i8MYKJ%j)(|h4X F?KܙV䏙b~SʫRM"{v(r}>,r14mt1?QƋClpꕡߪ;S%Hl ^hVw|~ UxJbvߡ@qAoH)_W\:l`B& mc T*^hM]'j6$SB`^)Vf֏zW\לA4871&V}P{4MK4TGH;ys i^jG7ە `טDž1?_ăzD.E9-1΍'QCLzdS5EMs _^8 )˛ZJ AF0 IMVjgҚb8g-ZSI H} 6 0E#vX dd* isH#@D?9mgU} )(I| |a!4KEsk]3eGvI&69uP>c5]8srFmwI veD=-8vmPٸzjrk]l;cNqj*FKuL3a6ը&v-Z<3tBs^͡AUK HHʡߥ<78ZF2Ѻ AX;owB`Z1Htr hU|9xaW$*v!GV/YjI*[\^"?7aZ+e($C?Z&I?;Bg?#>r\#oΦ%'r3Xxyv?g:dҳ/Mo|aJŏ]>qŸGf0- SKZ9e:\@̾lP"3<I |hk~8ڷ~TcL;(ΏNvJjq*squeoE| ng"ٌ>w$X}UqB5yD ,4nBghŽce7<e?VG[؄Lv.O&] B d s뢓fԣԛzI;{"n]Zފhq̆@Fp<دGR^#ŒD &`1,Opޱߥ^ՙ۫h^Vl(Ue"q΁oS:()>:$Q](dˈEb&au۟҅?2bT[xڦ<ś7[4l`sv鋇6 UܦqYzsmYjT!rs?' ^^ѽ̥ŨА-YQ> M-~eQ(@c|}Q]yX_E"H?ղ-[ƭ k.gnu Oi)- dSfOA- 0b>OemF޳3mAT5*{lH+iHhQyR$"[Ekkؐm]Ǜy!UǤ6Svg7KmS; bG4lM晎k: .lA]F0#e x]հ 4ẅfZ_CU`&,2w XG]=ńWS`p`E+:Ɇ&&K^5LqpܼMº,? IRX9|@Aඃ|tĕ? <ϨF Xfa)<5L5~%bfRRw~ZC¸'iL.C~y!oX t_>b0rhDL j S5l>DX,9mklo vQfd>qN7 _DݱIk&#ȯ?4=X⎱wnfs=0.)}pfOƋ r7lcKHK u~׌Mƴ)Rh8PB?^CZ(sn+Z^Tq'cU3*2$[)luM/`].mydiM-?mE2[>5uA/%'Oz^@%KSn(tIjCě6FsX)y d/|NM7͝&ǭh$Ebs99Еo bY ;iemӆVF];ۃ:eCΨ۽UJaZ}4|zS:B /*W%2q i4PND% |;Ǖ#VzS|Tabf7_:i-0-?*Eø?u =]gmp>ޙĞ;67E6 }\ a4ZC`k}lҾ`fV}[#&=KP`W#)>Hn<YV1H(B r([QPy믬i$K1|KXC`g0}Нh"yfZmgY,e>xkH7,7g7M1 D(y`{كwgfZa6[cVɲx[Dq_՝r̦7Vc,C*ޛdICu ך/|  "H&Œz|ӼJiBkH-bLM49o\o?n<GPJ\U^0VCf}Sh\VG^Z~!tVnȪ7l(^zhb3Sଛ; 4Z eF]2 @}LwGP&k7ͬmK^@ X s볹9*]D2L;ƌ[93G.w.rkhA$/+lno,X PfxAaeZ.9ZE~P{FeCn\-p~c{xÑ$êV` III%>9Jy>Y<>z7rG }$L~ '8}dRݑȥR^0 VS)B-(X(H?̎@KjXyO{pk-Xc@"; i"](xԬO5@HQz9Ue6kh^LmdvDao2C# aw~/ݎ@ |ްW;ѥ}:,n*bE)0 >^3^ŤppKvr_$VŬc_ ' ]NEK'.nD崆'K0hJt=ebJgF?ɶ_IS^CGb}s M.U5|\jv :ϘfӰkŽ#ڧHoa-Ӑs'S@pvbس8,ɝ0m?Ytܦ@sIj=#ۯZ-D%7 /펽MD_mGZ+_$4_=3;iX= Ho %%n[f° iQ:s 1^znXpBm)onin؊I(y}k"x߮WpJؾ#EYݥxh 18NwZ@}|P36RX#Z ~N0w]RMO"<⃽9dM ab~F}at$*nq7D2eJs:+P_ 9];=~v|X$b0f aokTA Ry8UQݡGdbsM;bEJ s:[]$`YTZ>LDi{!oļ^Nݑ;'g WZ0џhkvM(4.h4Eqg +Dw @V8:O\6q#knXw%V'R& _)sEwlg]5]\I2f(uQYaOw=69n=Uw\UrѦ{eΘGY&MAUyxHWOm|1#\e5rdrod_{0=JٖGP酗, q`z%tZmjPJƟ\ʄ@/| g T2WyMGW*HʝZì*@m*~Ya2Gɺ;1zҽ)ӄrdl' 7*Xީ܄ <=I"._y}BmJ$Ӝfh fkGHD͗LnPYFUFf~F .L<_ɟwoɒaPU;n%m5LLq1PTO?v~w!d|DR|ngt.H፥f dxdNzc-8~Ug#?7emx*\;",Ml)( rO&. Y1;i/kF`h\ѨNV>eRih1g4W<p)J[R ltrV`0^=.ƈSp8+CTr Bl/:'(Vŧ|-9I yՠ)=]dJ~ܠ"hJ'ϐ`I I8RIn W>5X?-nE{p_F‘2|*I3,^@(2-Ԡ>PıTݻ߶s* ~9ʜȃzb=KʂʱA\a6zPhL.X@a+Qkӕ wKZ?֕J_^G1::U' W0OomZŠb0ǐf;-&;ԓZHazH$34~5<Mm%qQEO<>E4EPu\ClR*b۰fb; IIb_ꗱ~O+?t n`QLyFtj1hh@R1N10ꈚR JMh'$g 'ko`4$ Dp;u"*NI}/˗-P:(h۝^D"d(>VCA%n&}gGz("/6Χ:*ޫd>V21}̈Tλ=;=W4!.J!eE5S)Q3YZj`(T F mlm{P(nfRQ_:-Ћ%[gL@bǸq;h0&(tDͩ(RD9M#}z}ʂO%+r4 sk9vH3h63dЅ/M%܀3m#߳), >@E8!: &KѦ9 )зh[#z oC7iLkȉDj~} @1d֙[X1 -eXWGJP<<V&d}-8@i]e\Y$Șm ?YPnӞhS`ox}"m:Mva nzVdqʖ#^=4mMςyĕ*gHRư/l*St&X#7W\H6]ΘM`5h >=x Qu54p.|WV ~)FBM 2 8Vͷ\)=lG=!lQ~?i5:!*L}h* ne-^-㏷8e.-y TL}fN;3(:(@ݠFiSMv&o>{"xLgB H7{x\үvI6 _Dad\ױ(x!y! 3A]E롯׍y:u^q 2 Pc94ž[" &޷Yf{Wp&ul!_p=yY^s2i*/@* tQղGIm {'zƝW Ž@_,3IWitOKD1Md\{x69R ~.@%j5f4`EAޜ2!Y`}xgJ4Ul=_?4Vc7x.H^K8!MB D KZC6okϩ ZWƠnH^VYWa^Vrx&~G|/=;_#M)@~R hg [XcTg갼bkbv/U"+*@sPё/[<#D&[NCKŲ2B I.>Pȹ!rq#u%NҔ-|Vۂ~GmYnQcN."k1vIO'W|4a =m/ׄ$Ē;㷇,XZD\/M5p͒ϗ3zuVj4w?21ZעM֖xI7Ҿ3\ظ3fPEުlJ/}Q; ǯ)05>'nL.HE%2-2)3ݡ#I^?i= fRg._ܵHl2 >uϹ ʅx2-TL|eOuޑTltܹMpB1&YJ9?s'{ݨ E,P\YO|;Q3d+sgꚐY`$7hmPN4kE"s:9 N-A8KSRW#!@Rƺ肚!-ByѴK!4;Ro=b]M}EZU1-zQ gL"R˛Wv5y=Xvd6A}46l=j㖐: VהqzAߕ{ʛQc12 {|/ &C^׽h{5ڷFxѴT3j= 琸=JrS'SH |lw&fwqzFFrEnjWӕK\->4Uzy;-[۱n*d$DWXZn8zмlKA> ^ s*ˣ&Lmӗ 8}"4-9B@Obkx$;k ?i^TG I:]!RkߦA0Bvci~ʭi@4UBSU݀?ci[ݥb @/PK_5Z~h4S$gzz`v`2vbm pt"HCt\F /MW%dmVbzS73mVoN:N=lɻJDv_c'C`sePF"΃>4/bD޶} SY$ K,ʶ RĚs1z SsbsNn>ɨu|:$ c6bů^0) Q kԙѳмڬc{3DeЮ=I"קBFhmՌŴ)tPR4AJ#UJ1 \,)1VpO!05qZI!a@Y.,$俍Y؀dҶ0ϡ^{Z*&8M1ۂ?H՟70ob灵 K!>A+ޞZs !7SC$Wxێc"H#;ˡo,x)5w%[%AWy׃,Q&dS(c&,-!y:zTS`d>l G}OװQ<} LCB0@$`XBvqG"D"fVՄO0{f}Q :6).؎$ɒߦ[@ְqf|!K x+>~fy{*SP X-~ܿCn'5E##޳ɝNG?Fr%*ary <SNeght1-1NA=O,t`o*|+s\w$ J^p++ `7[+{bHI-XZ&G9I IC>9[Ae. 4a0\=5:gR"k/FmmQVmҸKujomw6bw.SϩGaK'fT΃DŽ/ԭL 1D /H+^P;հ7=͞Ob 1NRΓ!H<;jY/U\i &r)4)iC2{Od4_-'%fn+p)=Nf~E}v'lgj]=@>U%ͪ|Ό)Yfe9$괤Saz1ǨkSZf쩝žDYc7DzH:*r23 &R{zJ'eƧ^02!H:`j-cgew+ ">up+ϗm:A}iʳȻmRPF@ffwyN6gOUAȔ~(`>1a&;{Zr *_~];#o48ͧ,we3DR:ƙ2 MbfWi㝭WI|&y-Lpزv=jFp(5Nwk #`dIX [)+kuFc SG^Kcq{¬a"wyH{2~zRKX#ZE+'-G WjpHOTLC-ֵFqOX$ P:EG{v^\7W=I{r%uv}A04q:?m+Ӟ:PHzXg O{?ڵy<ʫ7~xfm(,޳ϧ?_ ʉ~[}6'#, P( VFa-3*Qq(.̵{]2__+}:ߙrK4&oEgp-2|BLlH $S,mӼp;S:ϔr,wA\RhuV,(xΪZ~9;g!]K5bPɀI><%vąYPþ/PT;j^"HO3/E];J)wp:4H0HZ!g3thf<@ݺB|Ã3`fbICgZ~S=g NM*$mFNYj&+:F{n&vA?"K D> bx%A}{ޥrI|TE%{z/ODy&W"A#}p}1WL+ ǩrvsfS|94BjOF:y$wی JoE H^9 i" h%s"ψ7N\{gi*])Ճobln?w//y|:$(^C[EȖ1?!Z@1+Z[VUyRN d TRc=5oÇ@ȨEBOtחo{G5!=!(tw?{FxSM5$2iU'8iGmw`ΌCXP9+)Ǣ'%:w?EiWqcL{1jq?_U y%rxxRԻ$otg@H\Sg8sFڐt*Pִ^z֮3#!? H$o/B?U~BLMԈ/ho>zpux=di)Su֊v,%o{$E,׻X|bEJSσH[.[ J%ijOKq4պ@+fJ@(.SPcN.&rldVs4' HrD425owghjl iZc.2sM\rxSquO{oAr.ڊ݇*bg smhݗBİf8K+ci1BP|/lA$pvjxf~_!y=ȸu*J^AC;L[>C`o8[e+@ 6`?Zҍm_uǨᑑ>-bidѴ$4$AZѳ܃YsSDf8X,Zڗq)"7H;IQ$9LcyQD/FacnA(:-Yo"|\pרN,޲CO3.Kk`϶7Zb 6WWݿZ6iqUwiKT*4S|=Qб}5Nd/7q;w8 ;s)~v >O[1'LL&#axT((ˢX[UКhk8o5FF_fbf4QˉuW7ăXN1bx֒,pmwLf b)l(s@fn.Bm$X ڑEl%$']I}qDU0"ڤ| N adVr.#FuHu6+  ےeHR&a7h&EŦ_L\aHo"b1lmCڂk}&#vA"ߧ|Ag9jP睜byL#6$:VnI>̹ZYA\$'+؍W#9׃eژuO4\_c⽤nh} jSN7{oog>Bn FFquo5- Z4.<ҽX\XV3z4%yxF oW'F@G 85&{N` ]"gj'+r?*/j2׫2/w j!wYJ͚I=3O!;#8{>)?V|ਚR$9ut"H4(SY C+t55$f f˚3][2d OS}Z]V9K,.=})]bzA'v;*|.N[i~RLG:al%SwJ^U՚$,O_^F4k7a-aC7S'"qZ F`J+w |A 0Roq`wǀ_gEPi!:Λ'kf/fV[C)lVȶʼnV}QL{cVtjd@ ͌f10DøӰXϒBքܦYLj fuLAݝr Hhc NxPx$sz'q .cuy8FrҊe:ىagd0D2BIL9+n7@j~#&V1v%'ַ"8Grٲ@,xOy' \Pb)UNF˰ml/͹P+SqQfƯ8"#2oi}1`:B7,.! ͟No bStP]K,"nBuU=*0&jcaW̨]ka{&ZÇEg֪ 7ǐ9 ⁥ Uϙ{l}HpR5OΓl.ڂ+n mMO-lԽoW +]iGbXSr82HDc3ڠSB@, M 冄,u&r|λ cN<)Ppvg6_J'DVź0aw_nBQ?T1o| NĪT/pCJ?ǖH?/m4Mbc׆Yys= mq2~3Tg9` QSygFr`u!aUG[;mFU@XX\S9hFLYzFCc%9AqToN /1|r|ݓF*cfμa/HzĮ+6%|H54}Z%φ;)3ƣD]JwСDۺ[mRtV+kkՄ"R!WCu+zYisaid֣`D=4[.\Vkˏ~Ee\= i]%'O+ "g ch@.=KF| Fhf# h3X3[F0&ձ(ecqw',,qc~f@oCyϻv,^J/ζ jSw%װ)߄R hMYR r/`*n;H&jvR%,ceKb+-Aa >2o!tR5mJ)deaNO<[MmȨ@$+uAn*< fgJenuŏE (hG $&"$52OAIeD:=/zI jFW)*)%&Iߪ hz¶S?EpJ9C+H~r^|c,K^H$ qh#lL]ʅhZRYaQ1B8^ CmL>BJNRw ipBL$S,8VW9E;c&d$|Ə~Ƨ/s zD*{0N9 Ol 6-%mJ/$ "|c2I~6]f%ޟ7.wơ)ja*=X Ƌ#4qZ^ӌDpC[8(k m\n D>g`ץ1ue8PSނ?<ߚ`)M&;WQذD.87~kL(if݊+l]爌aKa:7LAr<̾$d"Da'ryT8'1mikL$!#U=nL~Og@deihFP@(L{ GCC|SY_]+ī,FMCʈ*5t(DaJX>eɇi\W,%ۜ-p .yg{Aq<,3kZ&:/Rk #ϥo-9 ,;8gg;٣~7r2vk܄ⳎNU2-?4'afL>|rd ] A*?Bt#;ccgȶXr'6ݨϥoZ芼űymUG*Me>*t,גa uC5ζ- 1Nځ.38P`5yjLPv,-]B%֕j]Z hP'"9&]T~'"yu0eH~5oBLKQ7!̠=S nJ̲|\p--~l!7O0.pQiaG!\@w%}SnD`cOiYg"=ÄyNf| ^kF? M. 'ʼn=ϧU<-M GB396 vFof[ 94dQ~D 7 wZfq Ƶ̝]nVɚ6)[u]Qx ၠ[8IE>}B{sL`W?;mP0(^]Fb[p|.-dY4o,,i`O5Cٰn0տ]S.^v]\H&vYK;4K]@$k-: 3%ʠ1 ބy}O_t}:_In!?W" ʰ{(zY6zϋAI/i1<Cȣ ".G$wIjP,U|r}QH?١qXx POO|5h8m"Z@>ﭜ6+̲/32,j$A{rUhBu:ު,ћaV Do(5XEj1'z="dt͸G+1㛿N.e(+)j`W# >%p(:ޠ)C+%qLnQ¨^\FUZmkU/M3)|}| T7ʹY,F;d}O($!t>C ^J$.Y"Vb;UuPUqUM|ygS$_r^Lhƥv: "~=6T9MmJ%ZM{_fZ^ EIA%7pqGĂ閎hjmzOP|vfׁq͠e$j΃wDܪQ|MCG/V5_9U_P!"G%P){}p `=yC QE2#Ћ~eLIP⁾xTۿ[< R_;p_>uH֔$|vGyLdXq>q̊09³+($p<0yĉKc`@*,E&ql9Mr YxtKa pDF5@UD7C%.L0L+Q903ܵ._p-_. 9w*@9MyG@h^3#1 Kf"؟Hkx@Fa&oӈLzhI5¿)= %bk)v4w6ЮsnPiD:UrϾy5' L g²]*4*S%TFO XRIm>VMV*r!KhkjtNpxNc!9dU f2sR~>ge1+9$Pޯdyb]?ځTj  ]M2kHɼ.@0vnq"Ӌ-#BW//"&%#`qn%g}wF[[>*={q%nbѓϳF g6G[k [zg ;A>kb?Wg<u<"ͪi:PE% Hbẇ1KKgB8AHEgLd:QkZz@\̢Ґq5Lc߶5ℷRmCC=!8o7vl+OxMT)g Z)oɧ/pUy$/LG?Ep2'yT'#b4%#qxU{܍x5k7/g<=`(RՂ()U' `$G z}@y;WɘTWxqn~)KCVy2{w$ l\csd  fB.<ԌTA:+oJt~γ\®a[87cQXjmpN'1:%u2m4jߡ:-i.̃I xcޣ$) y Aq*]lJ,."%ݓQZ' ؿm)gw\m)<>V1q@̂&aHk 9xTv4J>f9\/]ě_f#P Z*2x$zKeWjTtD7eLXcMגY#QI$0g'lo'zmocIĠF{E `2p[L\1LoiAYZgY\[8ސפ}:j.Q!VU+m&QPC5t?ߙ']nlFEvhAY> yT'ՄKaؗ_6vc#Ɏ.)jU`p``_Dǀo}O}Gm (c+lzt;0 3Rby@i u ,*H ~4wn2«/듰rP2n>`ǔë3/vWƓ̂&jXʄWWn+;*oY4kӌΜ. hJBz2Z.ŇMt BBk8T?T4?5^ˠ`;'Cn#I4Ty\C 0fͮ)A Dɖ5$K,,V ioc\ z 5N]V7׉j=!4}^zI [7UaS:b e Ⓢ7hޖd_eB)ة]ʄuD#Pabj0C;NP4Q|=2m7i{@;lurXLl lBSu'=a bgLy+7AHWR,/`@νѶqMx4oI "ꧫ,̼m}0+v.̶566Ms->Ǧ@~ @ͤ/%+]SY~dn cepo3Up"3@J',2ԀkXk?M4c)36p@6G떏eI֊UlIBGyus/>CꙏҘuYV%ث ۊ<*<}ݒޏ0]A6Uqcl^0L+hi6^GQ[>$ ٸ6zF+}{p 4ЀHyZf|%˂UA #Zax-oF rk϶Ҧ}3<3'6%>NZ-C桞J >ӖHZ*h$A_N)x8X7|/IW>XdOH\҉C^H+|v @6W(3<;Xs*N4yYgf%K91 3pK ,kKhӕJz}|0%>bf76gR&bmMW|MnKRT$lf17 X,(GHET *YS?O龧[5|chT0礱8CC|\l$a@q D9]z'ʼnc PE{`䇎7($}[ȥwK:|=OL8^U? * Rn 9qzQhɳLK~1|*"WA|O۳o6]/Fj檗p< d׵SyxpX5U@y'=޸Q.)wY&š6]P ~Q%w:^}?7 5W;l TWY|eyPje#md,lH$'jI,FБaJEzd ߵO#5 XT!_u&Xj8YQ탁 obȺ8e}=YQ֌ [oD'⊘QK_ӄI~p.·%4^/Z*8:+p:'C]a'^6+!=oi-YL?nFoNe[ (ws>O6.' -+8w0ׯK0TY#w \G6H'֝G>$5WzPw(|s^ vO23UХ+;tg`/΅7; 'hfE!RKEdlVr9y+.U won|pZ.=FЅKA3 o uX GsgrO*/2ᇡ(ET|m7HƔCgYuZ~?U3%2|5[<]Oֻ."ooül<>B(KJ7sGI#'瘓83y]Do󓥎 J3nn&1oP@"M~uJ.¤dj{E`B[^;#tRXH`>wgg*,_E_&4a)i}g'|gJrb75˞@ViOh-f.;&/R'׿X7;V{`Dl̒zt5tsnL#<4韐!nAAWN=I.Y מ2 }4;Ro=vri}jw7m +7KXHuUԲ ´"tdP>lX6Kӱa׷0@ldAݗh1 >PۿEj=ߵBmaؼTOO+pa GRT5Jy+g ,s$C$" 5̈́\QLB@bӓO-5!z$ˈb>gzN';H[:\D ;M&5W, =YV9kX>L"i0M4#1CXD™@5|R+6IL™~ \Z;l!'+R6/#a![`^מB7m/ZIGN?/tҎKP&m,Be`mm ZHݵoTr?H}ZLڲ5r{o4ӌϣ(YI4V2Miɛ|[u:BypY4!Jt[W$9)b5gZRs O}hjC[n"*IޅHmyefGF*D!%8M2z2MVУjG1 =dsjSe7umZ1u0|%vF# [w[c9B֣#;Het,؀SQ ch^ '[ ӣiѯ24%`u9G= 3;9kxM9'sB\5@K8b(^JlBrܧ HF䋥x98j !~iu( PvwjU{*5 Ğp9URba^Ѳ!P”D~ L+3P^MA\. kc8=\lbfPS[FAS|,KZ8j8=DWԗιse9T>mqg¼6DŽc`٘ث!嬙a{#:͒ 2 vxz.*8* I&P F88;vv V1(+\AK[}YeoU3w)|gPG|hVLxRSO:++HŹw搅Ag,48/_vrQTz-t1:6U5Kin+v|TϦUW~a@ ԼT܁laU?5nÝN6"Q!7aP7K8| QxG/]AinSΖQEag Eћye&追`Ɋߪwnc!_ PwO DlƵ‰D&D[og|,}%Co@TjZd1>^DgӬ W*{ֿ(l9mpo]j/uM8£$^ZFPPڭ+x;ƓQA6%o ۖi"jĻ|X0[Qr7_ {؆P_!=D!.@Zn7 ۩4R y]~<=],WǢ_643ĭ``-ŁЖH.bp m;U7/Jz_>heyGE~{10畷yu݁7&0?UڅoL? 3?Rap$8fZB3(*mDC6eI$3҂/U>j 7r7 -(=M9xDT5oϟ[٩yD$B z>%5^Ĭ[V+Q bnIʷ׊T6a?@ !ƺC2);l5go⾋$C!ZhSnSHX90h7~#D vI:A \ lqג9?}y/I'r 8*.7\\ļ<!&F즈fg`ѥLf0bˏfd}uQGr(HR^Ǒax!D!3퍑JE˹~~i*݂ezo U^EU70*i91"FXk#[))O]q VZ6[nxBY/5rKU3hVbu,{~"LAr^m/ mb їwe2R?y58ly*>*Pe[D6ј]+TB î~<>J¦g]&Z/ՆsS(ՙq%4K ̴\tNbyO|";H0F{uqB|YF>a{IZ'wĨ3bء54;gz4)X T!ay'LŖtj_k'uZP jP?ODR;[V46g>~@;T@<6L$Ȕ# Kqg:/L+w W!hcPڻMN~l+|m(OpV0-浾x=J`+/*SD'WW)@"R3*]m: yv$L 6߭NJ$rd1GGzETwXHvmKHŌYSbBtWk!^S҇0Fo馗loXVl}`a(ny>W]S ns0}I/mZ=w7d6(kV &"EvL(JB-w%{,Hq>X#NwAG9DydZw.\m n\=}yu٨N7z]|_Vֲάu0+2^^@1-`E*L$*6榤 84Eg)9={nr[љo=w#@kXw#$ZTWZ00}QY\HߎLsZj3"Um 6';Xagvmpjp/I7 ?]* Vs&Zڨp@[Cat_+OQܔ`(PLĤ=fs.D"-6,0`JTR]k5n`DtrR(Yuڋ!2/ɷWF{8l敏C(HLأy:u[tq|N"3 $1`SV(?޵.4.1ΐ8_% L0'R3wjܐ'r7TA{l}{ҵBpD3|4Dr+u\hVbCH.=|7Jo1Ί3yQn9 F;p!SDH,1bC=@ ӿ]coD Ly43sʵWLy$YA.!2_/%B3g 3 VU&pNV1/𧱵Es)6wbiQd$9 6P,V$֨bt"]G}36?&}h.UWN!zz KzkFQ;\r%K8w^`d"^ AΕ6(/yeh.Clper#QC5.f>k%dh~xN[ϒVV">aog8O^ kSHlX~njKN+z͕֭TѮl⾒0}VU&#H sgs{Y]:UmǽTJ @ٍf9\i2Oqxf.8Z/LF>+ߙ'ң2ÝNXQ$Ʊ-|im"R T~<-5"GjOoo%)@W͙+~u%wtTD,XV~^[x -.n>gv;Z/+ϊSe{ٽlF7\m4P.0؁!Qi6|bDR[ G8QC Z*̘*OXDZqF= Ӏ@nl#gM!mWWRru oEmC9MCNLmc=s T9D5;ʼn+^{4Hk iKx6l"W-` q aHE du%ׁAOp*Uv"ތ_nC1] |HH[:O$U^CzUP%˅dۈ#7,aK8$SD6φDZFJWRlʰ9gRd-Aˁӈ?X6mI;c؍,/c5n:]2HoC)^SCcn<T 3#':'s`se6uS!ObRQ @iLZ?!rT Pk[ h9G$TX H2D/D䞬24XN'ffo/2W.h 1mCjGO(Y`LuONXHZDOqfXqʴfҨ巗/b]f`txOPl(ւ.W"?$=U$'fXbH0ߟ z8jI1 cʉzkW)FO 2AI:oN\T B.SzQX k՞BAԄ=Y'VyhX dbё9ѯp?<ϼƻ6%GKk=o] lH~faZJgv:tHMdx+vRB LT( qOM&>ƺj)CSKTr{.&%s))(h)i|q]!%L`s0Y!ݪqͬɆ9`TxB8 pF_ZU8b/*f9v?Bb ݞH|+9O:~F (0l~ifӑG#"&~> u Sڵ֚^>`^;*Ő,!co.q?!nkOX(C)BEժnb lZFݩy,?u %ٷc"zۿ&ӫV:*@@x $TClԒF>bYZ{;p؃$0;ܚOlFeTO461zasCDwqAi@25bF+ЂƦ!" rNmI47[;tkR}ˋ.a݈;߶>ƀFa!"q/g@6*tЂhӂ`){%6 hEa+&G4hXMs*= ^&taryyR*Dde:OG)<$b@0#(ƨnuܭ*Eإ8xlk!>ftu:m{F 5)lY;tCPi- 2T>h9lhU R)M G H=>Ou#z1ihI@]ם׈oByG\Öc{ku[ 2Tobamv {fIcaL%hPPe88x&e \,\˗''(XK2eӈK4WD l*{+mڃB VXMzPaxgrޑeHe2Tr_H//(yfR@.(`-0YC)\jf؆*m .|viv`C{#nq&)P/0?2fS8NIğ]S{%Y hգƟپND{ ~,YuZ,- >9B# `8HMfT_Ysȭ*`7W S}U+~ڨ9H&:=0]1N>C?_zR0|EZжn#(B@.z/i.X%6[~6NzIKxђ֘HXʰ.~zx]ŻjB|Ȫ0-g/Yu-T@J1$jv Nb2j j4ڙŲ߃<;܎(RO5BjNv0ʧr鶛arlW }oࡃev,_O4vwY_F]ko IN~R!6dw"˸ugAh^X'¬=_Q)l _t?̆tRodkv` V Og#w2O7Dȧ.>:S7Ҭ%M۝_^j"^OaSlؔC)6 ߎỪg|* ]nx :s` eͺHTuUPL՗8^Q;g `\-'V{Q^Zh2_\|8NGʇ1h6VJ|T?#h-n ve.:$>ӵ٪=.ǍzBq;3ZFQx)h[%09gSxɾzZiy(g})Js :{kC 3x )jxHl<&Ujkfh{BJi~b_ʿ+̦XFXwqRC@ MuS]XVB~ʙJ^5"8|,8IPzn \f<9>ǬϠ]A H@톔tTuzvLf¬/ *N Y#[ ] ~pm9խއe).6R u}eAKw?hYF i!u VtSI¤50Ϊ?Cw$Pc guMՀCdEW&"\:T<{_Bw}e,m} i))L)4 0JZwLǙc*TrODK+8 &r ,x#6*3˴n#$)ؽJˆ0N>xCS\Y2B@#U.V^N9~h=d&]Kj%c/2ͺֿI& ʻ=@1rz<86*&kFTPk;//&Onlࢹf6ǃ U{i+ojOU6^j6o&YsqC0 ٶH/5z&b^ ugW̓&eC+2 #C'7 d=އ/& 3Ș*WmQFn!Z2{.& J {P{b0l6Hޥ0Xy!mfCzNU8PeGu(s=$dK`EN?Pl=`l 1r 'o KG ZjwE9JAܪԙQX؟Gt>|І]@pvp!kfrW"A[,3Jfv"eۃdٿZFU&5"wqΉ#P_ʄ-B'[9UY<6˛_T/kj/[Sobik֪t~mG}F: ݍ t9+32|*?bȃCJ g)RA-`mC f"}ɄkxosڣSKriTƠ-Wh)7N C+[P7{i|dЧZj m2T]De ׉ml5?o7K^'z+;KGZǃHOq-L0*윁C>?u3  qv+$;.n^らwR;t@d \W p}rx:]B'vĄ5.ڈb>b&^2ZV ɾ`m$ =&ql}CY3թ694m=Aߪ엉+!Ƈu!dׇf=XUvcpdWQF3]ҥJHV@3ӑJt.x s4v'1p"K&ם6`Zٔ(퐉0#FVzGLlkR=0FRTfw^Ĕ#71cE>#x] LoXYi%6}QM!tŴ } Wgo"&wjO5<ځ}qĬ۠@׎T 7DƖ;l :<:E pLv7<&`D'@p%-s!CX5ߗ̜G% HdUݘ3<ռw XrNk1-i+h3T"ONUjGT[ 3ug9WqĎd`.aX|fmYC*QqWہRVLjRk*y|G(j-GoLW]WSDzf<+P0U\ T[Nݤʮ=Ŕ1Qu D=_ѡ@NHR2Dײ[ˉZ{9k=@?$5DѢq4.BlC"xD$TU1.P>!fxa{UR.Œٜ'H`iA3\9;K`'TH2fE7zF/`KhLSh6*(D: BEmeB-aM9t:~\svoTb ZH \Q2IC*]%J7v:Ӎ1n*P|s9VY6O;7aQ@l/ SDq)Bt)=0.$!΁kAAnBLw6&]/hX;2s  г9wMFao.w~o3GcY3ƫMp:~)t-$%)@ ss[[- $s)_t&gmI|)۬jL㬡D&dӡ{^5f6],w߁{B1K_@{-Cbl|R2 9Ld23ՏzۼOl"m2;KKrP(è8F5 ׺Aq :W_ᗠ}>f]ޓqpxC0竫)ZEaV_ $w"o$'oYJif[u=ZG5xDyό ~x. $i`ɷ٠"FSPk¬ƈuZ~0 b9Bvg pIZ6IT7Jv? rzvdn%pCjHF*_IOO9cn=ì0H*$py=ϓ|v8_"X\+Jμ5Or"}-W]?7fFIlsߧY^ZˁGҀ*ǢQ%üH/xBŬ6m[ #3u~8' O!_L7Rd Cz)ծ`O.4sPP%mpɋ#O̘lT?W7LS(n$L4?Y&=LfDdTWU3%8#V,fv&8OKÕYi%mx  T,6Pʨ ؃k)lZ#p 4]@U *k ˡ9 m~? =ԙ%&U?Mw#~oSMl8>=dAdExL/#lYIf5bm&-T f6z؏4,9i$)$qtX LײUwcbYI`$;g/9VaLj!@vq/""sKWCt MkZf]d;eLij0 ^}jxlk@&Z@Ò.O Q8w: ;8(&F5{O`[\[s Ċ>W=qߍѠ|6j7=7O5RT-w͔VkZz%V2a˪ގ9/] ӟ5 UɻKD ET*zJe=CXCu!eEmۭKd2o'rxHH =x(8e4NF0-q+A38U ޅe$ NY*#Һ Nd<۹/.^RWx(<6nC%{ @$ j : d渋$;i4d~N̋XG[eRuW^Nr=m>FcI(s;&]_y:h '!x$`4٣(uwhwǀ'ԣOķot40FJ2mZ,}yVZʎ:T ߟ#E'faޱ,[rrNOKa%@#!\I}@کڪxʾ&;x9\v2/XY W-QOș LH 3d_0=^HqNM[mз^7"݉#Wa^IRV5zkYvx}uĘYޫ:831ʜ-sr)RBDN1_I6a)5,Woݓj>)op.K)BGAMuMixå$1ЌtxZ/CiIeʴIgmKl,]EWwgnBZғm܏]0Ѥ'g,ﰬTM*\ rJ;r]').);$8 3#IxuwW$=> ! Jw﫜 攽!pn.Tw%`L gu zFyFm)!.hmYєj6 Q8TNbM̫ec^uvy/gk2S5O|2&ՓN xTe&ynM-&#WI4@g/9PI8m%0nT^M{XexC;P="HA1oD͛}w LLoX%xŶɻen`0JUn'LtcjH:lkпl kl錒.t4fyfJf j#k`=.䲛;8+{B-iDFsc@Wk XR۲[fyX2b$<<ڤEXhp A>D2:̀ -5LX/H[lA2  &|J1FفqkH!i%Q6-[yTT\ۨؑwh}ŝa o_bG.$E)[q+:uAYhqYϲi%"1J0 s*?*\8؅ayz}n$,ҽ3=NQ %T=@/\` %T]Lkg7 ttTxz"Q+/Ć%mVOXK`M&8iYPo{"^!X"|6 ' h%ŭꔋ=&u4y`އǤ)%EebnM&AѡX#03&zcJhM  i^dah5";Mw hI5jdupB s,GVzuyV|-vu GMIqTGo7q*xaJ׆?aON&qQ>R{R2bmr~fi= 3Y>;(Ýà`@tzIU.%cA&+bpx׵f%r=bTDŤN!o$)\KpFZ1< 5&h4{bJdAG8GN 1k !S5 HP]82Wcbs{\a>#YT=-LgbDˤ NښlrRqRZAWbZ>a#hZ1᜷R5FF6 v| uo(@0G&`Vd rF}/7'gVC-OgnָO e͒ _~x;[b Hȴ2pPw7d"W ~;prsSKb{5b(mH@I!M''c~ Kv}`dU5 *`]*#2E5*epCKyٰ՛}hRֳ&uEٶP{-YM&\Xmhbav} Լt`v R. #aӠmQJtp*0kvDw/F+F^%u)eůd"ԁ{-Xo2=F%GJߦ' |mO0-Eps}v1'-% pw;Mxgt%M-*T߉ ~Z_9v|3ٟDǼcY/1(v{IOz ;c-H`ڗ0v&NK=-Pgi.CO;O5B2IW͔"Թ$O.ʺqXbZ= >XFw52Ll? i*VV:rG]ǒx|2{C RrVVw Qiz) zuJ37"{ʼT?^GH!oO{?tP8i|bjJj{T24T_hvc8Tk%90>4W/K@Ī=Ecv'u k{iޞ\DZB($$yS=l  U=?u Z9'agMeYM'ǼAFU1eZ!ו:wnO*1Ǡ\60UcB9 3%c:Gm3Ț+Wno$Β;7?\L֤xn7*LʿHYv_͋}Y BS.nNja\Dyչ 4Yy~krt42L>JA z$n6Fk0(SWwݼܬ-"xv)o?^a35"[WN  zQ3IM~_7"h+9\5[UT6#}46-9UgB NT$Bck0Uܥs_KH2%aaҘ+WK? KN`mY[Yi768Xw)n'U n (5VI.X9np4kDgYoԜnPE)v`40$ gb I#>W(:g;dFŒ,3 a&Mh$ UW(b=Y7+KN\Eo >)uw_蚛ۦG ſTwO B7x[yDоCsH⢻bhѱ<dLЛ|f@ /N uR2s$#mi?)+F/<nڗ⛅@/C[[Ɲɑ27%DϻNMrgf%PUΪ/*-Z')՝hkeǯ6N.*/5}:B5ҟ [|oXiWė+ EjrIu%jIX6"HmܷRmD?pe4ZqI0[vxK ?G*^%P"^Q5Bn͒CSٯ6*b3pg@$DQvn3 w脣>GQR O܁=A۸A[s .ctx)m_ZQSO\zEs͟p{j.~&'/L7R$`WF:a$%:v wȏjJ]_`fc @ &ph,"&{nîAگ/G A 1:Zc[CԙeAx姛յlXݟ@ϑ =/ݵyK3UB+hi2Cskja`fGA nIwuI^_\ў3E?fFɟ%,Ef2~Gwh`k"thXXth*NwO89kXc$CDs]e|4^K(rɨW?[xt׷D(['OYR Q rٝSWd rQ _,\XKN];8S<ϳ=8%G*CڕsU}|ؗǀaVR V=iAhֵuL)BnM"6*F;%FN1'#ZZfy%.@X퀷E=+t[UFe.eBUJor'! @5Gu.Io'Cc?ڂYpTaoCmfv5O aoܶ9Z]圗z'ޫ }Gū1KF! l q-s{a׌ MiiYHbIG苛!觭_!_kѰIp@8>!cn_hKz;6a_\(+i$P:(RT<v >R xgýF!wQX^ykcd}0+ $QO{3沃/΀*qD&UqoEvBSlOj`h3e:g^}p џL+#Go+$aM}*8 Yb-9QV^֥'r~yDP*{ҧ6S1 _vu A [' Wbѻ>uv2 U8(M%51!xoel(mGTJrdUTmHOF:?YUT>}JcRjlX^yF%.F,nT;_T b/5PwP"=+MHyb 6X5*c'6?B34Xx&ICz9]Zh?r$; rfW<< L,nG8o߽CW,FCzt'YZ/%]YeL3$)s:¬1;e>q@@qٵd1{8` lmkT}NO~QtqfTVs*uD7?7Hw{ 3m<{DKWo7sj5`q5'jv7]lT` ]:E'װG="?fx٧L~ #y|d׵Cku*ZΎ7 RTo&~Pa7\QyYHܑ};>Is#o*!7κ%"M8>vXи$; x>`vo ;'iop=[ q9IX^Mn󊥀AµtѲ~or1~vC|; jH>Cļ̔`ɭ1"?uQ^ 2Ad$f58CN$R%SRpRι~ّ}3f+RF6#3ʱNSGnf)D 9=H& h_bf^EZQG% O`\W|t~rs["Yc/w[vnL|{]?k* fJKr!;1t,#sl_}R׆aX^Gd0Ƈx>maHΟwki즾lUTwjHlI㗿wl 9k^`04P2[`;; o0 u)iaLs74젒z^շ /O;l.+V_T*fBAp%xOKȭ Gj՗QNN0?θyEW :q!XoD{X@Pd,0(c#j (.BqY9Q"לQ/98uqERV<@/Yf|]{"MVG, O#vi䊢W'.΃Ц{Soa;j"+ {ՁZI6zo8UՖ8vj.$BRį!Η ߽fcqh;H?x[Jtۦe1cAYmX-TaE HK>nW8qIeY0=atNb2uL;Pƽu!aSؔ,w,Sl9+_?( vsTr?4BٱI wiUܚkETgEXmH:I!ib&=@D&S=ߢ^讨趹d@+ { hQQ!N/%3GA\\ v/ a BVrv;&F?O ڄb9( l"¤ˀ8FϦduF3`ulvMTB9%_CA@\$5Cg\!O퇗>''[/1UEP) B  (Hl]3QOzڦ>0Мsب~":( ۳~=ҟhT!p߅G^*J;~z ?Wl*"3]E*B=c"Cig74KA W]NhjExnT䨺Z+QS\^Hfc>ds6g>e1I:c)r[OkFvmW )͙y< Z"p "S #:p ܰDͧHŌT@$cY#](qD5 gZE+΃uq<`@]^0ogz4@=֐lsPzhb =q:eKW14ϗ=@ 4şy nEzMOa/V- [UKܸFiHvpER2B]).:eNnbL )Sn'%#eB+p -4sg4`mgj&|,m;w@y$82 }tgW7Xc=].𷩔ۨ[T5F?] h>%Y4^7漦U 1G'{`8DEvCw.?E7 -aj{(~W[Z,_4jB8 JP>;[Ds#scЄ<b|sQt" f3s̋!V\zjJ #Vs߿G9n^Lp`歕jSOxC9CW=,B9wWp6DK8zFOQmU->Y9sR>Tn7>޲[C zi> ,OkKUz6 m3LW鸧ƙï*Fm%Bnl%ǥ:R+uV':pɑ26* P-aڀ:kޚ_|XDv$Lun?>3@'X_eS[v2s{'v|SX+s2@92nF݁wxwĒCNd}fjZ{6*vb529V{?rpw5v[mN.;b?E*n$ rt f]bDN="q31g*%RF>B^yO1Jwήfx|V01\쾮&'nbMCT/zio~K""$gOMoS8!H~(#zx#*5u5 JxnR ;q]JэZO /秫u=k*z.6K籩bh#E;kun1ox>{q@muo Z'{ erڨῢ$0UV ǔLLsV9#<Kڏ+OᲵ mdpR~8H3Pwh}bZйzhm |Vv*XY"ϟ'VBFCW4’2HQlؐr4cH9iDOsq\pFy.%rZ na d;3Gp;F w78@3}WwI Rv_?id5!Mk6p# h\uJ!`aIonwrJPyy#߲o6urNؙs; $V3A's+^_F䒾0G(D[=4߳I{.L5ݪ$;xDUAZ:Mj|+O]_ Q BהeaɸjtXvBP͛n!r]gC*@HLNl?eWJN?o'H,^)7zĕ[*/OY>|Ir,}VӓqmM l 8ǾF:v(@@Cg&** !d {MWsW -$n磈9fwF~Ⱥ0Kg!YA|6AkY37iԨmJ]p%ş.|C qǶ,+#7gtVHr1\/u/sڅ$_Q?I'3*0mw!O˄w w^庘cHL; 9[*lEm:Mou@DV\Έ+OV#ORʳD!0[ȦȠ-k`Ma5LAVVr2 2ΣP7NeHClEJ IebH0?)7حxD~b|7Ƅ:-SpOif,!ihTyNpt"S.& Q&Dv:V69z13{c U#Rn>Ku(Cs9E4`|\(A:֗EgrI7 V+ vqʹ+Fjc5{'3w(r1'jR 7ozEA_WK`308-) ^o,-W r7 @1rl$sS&99PR4iLUId"dVukM3N4ʛWYDz; #onyaOGTV17\!+{_QjLI̿KC!Us3THV2z8rטΔdk0DTa𝐃yL@π^bu1^º/aGx\Qf|waõwW>UcGv0|jݵaUXo{z0INAp0zbj+o c:(tDF'ڗԎZ ]KMTn`ØF>%_gEb8u( H%f$Q{_hwV0A!٦..(kQXKӒ95_0]?8FGmg 3gx7@F^J =Se! Nϼo!iӓM0O_/ZaMk.e.# ѕW=w8Lga Ha1x1~KյXfXdN&9_[@p)"WƎTDJ_uUϻQl&j;RT!80Vӷ;9Š}i[xSRy"[#dZ;SlՙcU<&+\ Tk͠'UuCN:!VU]Ir *-?m4zzTILbX~ /`]TQiN9Hv) J]~!a}F|f6iM%4w'WQHБ3ccGkj!d'R vvrn6)8E"8 .9+~NWjG!SI ̽ՒXY~C8VJ W9{QFy}b.9%fC]7gTբTK;PE+wE9п8yUWÖ6 YʕxM8T3RлŏUNt~v>٘zCd9‚rDǣ>(d?aR"h|JJh, ǟ w yP_!P:]c_';Cl4_to|T,#Ǡp~]+9w RL KA jru]_ zrAzX4E[ x](Ӄ`;3 .m>-!/:O0]Wxad~GnL AGgo]b ԥ c`4{fI،JtAK_wPqonA0夵s r5?\_2ͻ7]! 8˒~a}(Pp!~ S Y}=T2mEzDF&0ߝ#Oᙎр1u4 A29pԡnڠ3 @ɒl?{||rU}Acŵ+]Kx)8@Rt~ŧ ^wEBL曮MTĊ[Bxaѯ(_(+[^D-DD+1-qgir>Ȏ54{`_hU%ɴ˲oUiAC ^1j BW꽈 wSNqJ{i_+~`\F5pcN2Ƶ+:ᒯT 44—Y/o,n%5/S0]"q<҉4So: k] ~^ #bL/Au]6&?P4+CKZef;z}l &?I]*~Bo } BTBz^䣽k>SW|u >lo:q , ]uEͪ'̯v !e (NG}]fvUd'-f[0g@{ۥJ%$Ftzx*/'oivk1'J>#lűl7-j-/i˺`bn[˩$=̷L1xjlҰOAGb`P!ǴJG'uQ( +I(RS.ngbSɪr}Cp!=^-b/W[#Y$=t1Ŵ)iӌ;٨.6NQ]a􇂳k|&/9JS$X$V*H - h]?EMMrZ"8>kBO! Ӕo0`Tn9XlgsJmhW,:öYX$F0\% 0h׼W"~â>ṭL4ɶl3P`DN%e1+w\C[!$%41$wfR \D$Vxf%&5ᐞ ;Llӡ3c`}oSXi*1z 7Hx29kchO¥6; *: Tfi~w}bf#SRPiЬ" L(2>$YkÕ&{]p$\2ywk=VC1RO?Xb5Ed_3ԥ G!ZHܟ[& +Z:Xj~,*'E^S%/-VDB. }S,TШXnF$![Ї@4yo߰10x|`L ZImq䟇D#k'f=A=F!C6!PtuozT깖$v-:xBbXF$[l8;|/D}F؏%Ywp(F_=oG0ڎnC|6u6G]b#!E":^Fb،] tA zO9XEN]M<](@xc,s^Koܻ4S&sq&`[}l"th:ɦfh8D2,뇁{d*j>J} Tha8IDIQHb^D ؆vb.^Gƽ>*鐤/BF? =.tQq:[%':\c41,Ծdrdc>i뿳}]/)>I6S籝 6e9!ii^w[L֧ /f"VQq&-kLp*=Sbc 0;B S= O8s w`ɸm.Tw 'ᘱR*ymNyV% uVx} g׵@P{ڠK'%/}:ѯƅDq4G,]dy 9 K&"m!+b-!Gמ[x Jw11 e1Cᘈw_DX~u сTÒ3-f٦j"޹MRee*a&N f]i ;{0\ wlkI-ۉS,L7b 0%PO7֙|87(fvNxu"2S5ҟji쎊i0wPd:&U c>o 4a)vׂ܍+ѿG|w!loB-0 phjRIφ;;Ȃ9)I:seob=xKȗ_P +[94ӅlUf6hxpzu6SHT,_M/ڨ@|{VV%lB*~>gp)Sj$"dU?r6n{FUnx nb߾?O^PEBAzTr7B4{]~q/4Tӕ *+_H4[hlB(n n ̆ԦW)3Ѳ10Xt֚$*:E76R]v1jܭ0>4KGҸ㭅=8KJ65훜u{E`#p  .Q*2-PJSm(,F,So@!~S^l(D$&fqn~v,p\VRW3³]" Ae V<_vkHKXޮviDz) 3tp,aҽl(]x ܙ9oV*LföW " .U qVetM49i?誗乥$q9N^9T<t9fmp3V;Z*BoP8i&ĻJRzČ!L 82-;JGrAwOAUL^zv:j5{3>`o^ky }NP9KJ'bR 1RreDVh$nZ֞7`6񽷐ڔӯtȠOﱏYLʮW eݡxXLxP.e=lΖ'ہ#6"Ml/䭥Rjy 22;𖘆ݣ ǂv27bocC@l`e:6ۖ_ɥ/6y>H'o)JAbKW _N9H丱ܡ.2nQg2BH3-؜h\lR^\d!}tL_ފ# !$TnfWR9WfvDֳgK-\g]`2^#O-:IB(g@'dhYa8-r2y{^& (Ė0wgt2&b<]e7kق K[y\e at' $NG5MM_[>L65 $ЦW&>3.дnMƬO.T$gFAxvZSOeP=L\j̄.~HT~,9)lsR~Tvr16=Q^*,F}1QYyS›!y v pZK&{]0?z\o,/N-oVh"qTMDֳ8cŦ/ɝQ?E-t|`eBXI2uE )c 4lCR욫LHh YOƙD堟eu}9 z< yzCFF3oQvPnyAp˭ݑ!h=6IIr`lG2]!TaHW~+JTΐ0 i[ؓ)&3uAs= q2nÉz XO5;ELg3#I АqdFac@Ӳ/4;Ż4FIYH?'1G}q>YM`0˸ynց/LA9*QŤGHQCJsJI39f3J@ЦFe:?#$/62n#Ytvoyɝʆ)~UQ%iF=b#]:q__3 ?wPapf 5y6H@q]7 @US!]M "%g-3zTo_)B4E3(0VrqcMiTɲof3bK3iNƾmQyuI.62!H04Lv/*VA0XOkuX>SZrs'#&$+B 42I(Gŋ JY ̈-H-0+V3ٕA4$d]}<ͬ-3e:xiBB7+(,#`)G!|+ HA؛35]n$kBB14C/vTC_~*lMlq;We&|-ϊwHM :1Gn3%fs:P8SOڔ~D V\Fـ&ekhr81^ ۦ زO +M}tBJp\l1-?C: wА'J0K,tl=CE6D+Mگe̡Uɻo).Z$Yʩoak\WC(z/cwKvձLCK,ˇa nV-FqE#w6gcĵA4f(0@|&:r^h0XdGIq"q.(qMj4q63}Jj`=`~LWh`ё/zdϕ#i'|7A9&RIb!;;{/Y<1_*UaS2IC*iR=C6cw?<^OXFR/rf+Ñyr0gl-G.>ZmV]*aX{ Y{k}4LRiyWUrpW߫ҝ:'TdadDVMM+ .aIRdD,Ԍ _ԇ/FD~ۺfY%8vjt% $؅p͏Pnim"7y ʰgʛl<4ޑljىeAݬ="/EBX4GSjj{(6{tZ 9fVo(llzwu/R\ߴkvc&u-"0{Ϣ^r߀6Mo3ﲇq-b /Lz,w I ڐw_HDxN $ $Oz]@2 ?,ޤ)K$c3\u|d |'.Lûx o,PZ)g|20V AR=2|LIiCc\ NRN(?Fޤ -1 edk_.@ԧ(hart&mCM!:eVL 8ws]Z:%l3{lE'zI Y:鍘%4?í j D4F2ylx QAN-2~0Yv'mlLz! 4׶+k9& (Ҋyu$L[V鳙Mi*iH o{ 7Mr&>&d+l"ewR s b_*kjD%cY:F7VD 0x 6@#{ uZM+ -}̕ ПFm-$h sjb} Cai3@SWLCAF%(ʑbc67b+`DXb[v?"n>:m=5*meb.ɤ\O+_205|Vnrb = ͒X#5s6w~_f?R$phgt %P]:9uwDr,OqIZ]EB{r&qˇ|3#džhY(k-3-@]~U ;[vqpop#!ݽN+瘠^JEb5{ yOTQwCG ?̡SHlXY-.c={>ڠiYk?OrʛD7TIT=S^!2 6(`"QFCۨ3 u`gv=x:b@fO՟ g6M8mBg_ a" `%_㧽 pzxU|3_/U0S"#!F6[ۊֶ,i7+^ ^GQ6f(К~ GcF:4o-Dசm. RHM];2δ =~4u pU Nڧ J;aljwxt"%|p%rh]ݶ:!}c9.O%X$5_g0.nCwq X*X\G^)ݽ1ddJ0C`8{Aj!5ZrC NZi bC<0Q:j8qPexM%: |İ"ϫXPOi*UEdQ_z?WЪ7Śa[?9AâYX:p2v,ջv&tT׭93Zy'`&8O'l\n^Bq5JDE.rON^[^EgY*~V p(w=',֣N@> @}2 e3 6Zhq \vSQnRYVzX.A9Q1#˅AaeD!˅ҷӚ Mtj$sr?~΁r|Sjdb~&?+- *EBjoZ^߸wS&m-G`\:5к tp|1&#d)EW9ᔊ<'Dʃ "r|}Ш6?HHl9ys4;[B_2N]1=Mycڢ n:Vŧsu5 bNM=)r%jb\G9`}֝[Yrh:7 B/sV~ g\2z݁ZMnGEk8L&oh\Yp&⶛0lCJRYzo>}ԷPy4nZJ 2mVx<O,Zn*Lګ|R﮾ k 4͍l9JA"є5Mڻu xbƘW$+<*̟qԥMyR򹫷|}ʈ2 "7W^j5)ҍ.dLdڞk"O`EW2L^{%e<4_7JDqq%Q]'uDkgGzkȍft 6>Ov+c"0p`̵qmtZVL; QrJj?@l sP߂?UEbԶJ l@[E.2OQ)!L0bTؠ= t-|4R('|O1$ `' ?5ˇI<+ò딪[@({n sgm;ҚpjYߍ6Dk[d2 d桴t9MkˊmyܺPHxϨi5 bYZsezd6GT'UMD>`b;'Xgw>'^I{#~'yf ZIdź1&o!v|Xc9 |?R>"@>w]Er}V˿ju $L`!|N%S`!S.KMY{x {o^cs¹\yw_)NȄ芟ۅMe@)L }'"gB;Xh. >܈_X 3q} D s)vdCzÑSm@\#63޵- ҡ @|*@ P=^JUkmVre~#]+XF{L|i3NHY3YϫTbjDo8r2g'Lϩ`!Edq 79PIx>1XbS/Lp/K;䋘f>*?6xNjGvZ A i(KF."No:bq@]0.9@[Ɇͳ-C9 P3/.!t!Q.bH[mmU%ae"BgyJUۑ{"閲,sj} :JRkiRyt] ӭ6v#9L9i,fe]&_N~19D0i5bMlt+ahƼWu NԀR/a鏐 )E?3cf66S@("_x[]MWFRS MOxMnb=a;oh|zI{=%cgT3ᅇFbO*CoE]"K$s7͚*=ߚli{z @ŘAHJRmǑO5dh qBu7wf6KI+ D)_ŻFsOrV{֯ T<}r@тQy.fvU;Ժưe%lVit&t}[ BAȞrXv6PۏLl/2gRwSjC@(|B|(i9> 6DuG28^[M^4 .H|##{TiKݣ2 #\AfD{pKRs4n;sJZ,;"N-%GbK!1A@ Q 0&~:*oj4 <+Z_A9̓n1!~&YRbkR2m.ܪxAD }HhQվkDj.tS%jeq2rqon ZnFOط8<܈HG.n i-Ÿ uȸWWFl(4H;Y_P#˞4m:Ubr@1lKczχq|*&%Vۧ9ڑN7)Q-3Ֆ}[֊ebxKňVl2=u|d֐1_m]xZ.݆K L=hƷE$kJ<1,UƒkP] c ?l/j֧0O"YrJ,?dةv~I_ikj7ȑm9(+_ɂMA?JcM)U"Tj.LT OG!,t;Mrj:a&Y.n3N1QNllrmM@kBэ܄Vf 4)p%UYl-?w\(%5 7m+ ^|-Cq} is #im }!eѨʬIB~ {Q2Z⩸OL`v8#/ʏTg6!@ ;YrjVR5ICHG,/!xe-yD2U_(%u֩/)-FcS|o}mUV_ eo8p)AV*i(ovA$n)F9͟k"aH9wMZ#Z[A6_{U^"%f ?g8kY[- pHyБH0*  EnmU= Pw,QRc2Dnt!1JԽk Y 95 3VMoz"BN$2*˹ވ7q9': YZ