samba-dsdb-modules-4.13.13+git.531.903f5c0ccdc-3.17.1 >  A afp9|(?﮻kfN$k 0fO4)U4'-C92zjI[|#Qѵh~R׃+08735a5f87ba82898de80dd69051a5dd5f5af248f4e1331ce9f0350f8d125d31f423ecb409fc7ad31a665e624b9f207dc5a8b2d5fafp9|epNFur{$H+ֱ(_8:8=tT s+ٍr-:dvYSf)~^8bP?(?7@7ȢҧM) dP{΀teYy)gʼn!pTgwۅO "?1DM[R'FLvu[aIz.m(ʑ ΓI?X! 2wI!x;oЍN!HIy}~E?=Z52>pAC ?Cd1 8 J 3JPX-L- - - - !- P----tt(^t() 8)9,:<&>@FG-Ht-I(-XXY`\-]\-^b3cd\eafdlfu|-v0-w2-x3-y4DzBBBBC Csamba-dsdb-modules4.13.13+git.531.903f5c0ccdc3.17.1Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.adibs-arm-42d@SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxaarch64ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb/samba /sbin/ldconfigp @h @acacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacacf5a5913413a93a7bd3ffc37ada591e203daa0cab37b38aece53cd13a822de76c7e340ba3abb6b90ecb0f6131dffcd257919a9d6822e7321292ea7a28975e2adfadd2c8c795a45f0efe70b63d434a032dc8f5e34fedb7182c3f8475629be69eac5ce3ffb091c139ae64802de112638e7d896f4bf00efce851add97cb4fcd915d32cd1c9fcddbd6973c38b1270736dd307c0cabd18b4e64f3b12f3c51326824811987c00c474b8dc4add96823d643987c4f547028c4c1dd9bdf3f68ed28b25b021396488b3abcce31ed1a364fdfd28f9cb68e3cabe4872fa0401525b794e87e64425249f57a510f96785578961fcab19121fd36ca6e28fcae773e65495559ca62f4adc53f5d3f04a4120e9ad321a8434e3d3207cc28eef374e5e27e11116fa5aef31e4992eb73c839789914e485adc6c1618181cd8b55423570b301702e11f7c45db40a9da5efa393f8df7dcec9c00bd8a707b1a9492af060a8b27190dabcf96772a285b4f0d6d277a91f145e02cd2e646d9fcf28b7a067c00a9127bacc9b03a1e037d323977cdf7f28955dc40f947e6903900751bddbc386e237fed97ef0e9c612a883fee552b563e306b84e4b1024c22ebf3cda7c7bf6c5f137241c5e0eed8ff2b4f62553757a6ccafa1cf5446064d36e60f78977304dc32f360c499e3773393bdbc711e148c4269e8cab118313e3d2e4526acd45ff1094e15f7754d9e5a13fcf68e1a0fa921428b3626a845ff4b3111f7daf1e014253ce301e6c3ec19a50c5c99b14ab05828ee79f7568049dbb5deee4f51fd9bd1393f5945821df99917fd5bf7474e5b422e62df0f9ceba32b846d57cb537c0570212a38a93602e6d5c5796b4840ddacc7b0edd3fb1112ee642faf4926d43b3b43810a06469df051453187b21a1121017ea350240f15d3a32f9ce009c45d145cbd6f8b6d544d13e64cde0d37564a97ac2adcb1c4f5303d806c460b48b0ec542a387430c7127e6cf27c24740795ce9a14ec2fa957e23c359696091cfa365d1647a48b6ae205a18fb7592059bc1f32d11362185004069f9799d9bd4b5c49a3512d9061a7d358ff8a5789d6f898ed1966ed16ffbe1140d03c3f191541874f27fc1321ba579cae6a1c71204d28d8105844e348ed29736da6cf863f1205becbd7e02ce1904835a8218ebdb2ebafaf5458c3db74f71d8cf1edb6cfb8f17a3f4f1454e28a4f5dd310a9ca162256e2b50938496547304a49fc902e0b831fe564ccc4379623678dbf4aa098177b55b958770c87e86fa7d39d0da725ef05d72e39dd636f0adf3af08d1e67b42adf5bfea504e78cbb97e4a82109a14fb220f44001914351667f32b7fda71ffbd7b2f281e391790e9ea4be8110222893508b300c1a8fe93f394291604689436932489750034304aa0f57ec349e9ccf2bdb5c71595910925bfbcfc73b406f8fcbd80f3c77d673cfc4b35fa56118d0efe832dc91b4934ef83443f89f8ce89c00ddb718d9adcfc2725d466859b79f518f25dfc18f712309c8280f9aae3006d32475e3a42ddb1b79e314044658c114f19daa94c933eb807d200ca5e27bc24b908dfb2efec7648fd6eb8cbfc6510bec7afaa3771c48b2b0ea97c0566bb686f4fdd28abb396476d3c31cbc82dcbe071f9df2067585d3ba3e58f410af3c1850d528de5ea116ee7c73c9f8a4be03d2214e53fee1321bd46944b55e55559b58980ccd7e11fd4a1b96bf7b1697d7fb6e657130d6b9aab2c918ac8d3b1897daf15dfb64a5b1a110be34b7a08eac8d4d37cfdfeb9159f122d9c2efcff88a83d36d3f7debc045a90e95475817a1d9e7021458ce1d917b62e295dbd336f732744c6b428b67cc74fb6b69bcd8da9319a20956117fb96b4c4de11747b7d5a90f0636bfaabd237ea94e00ab8389c4ed5b9dd43e09eb895dc3aee63a6c0adcf405aa5010fbea1edd5366c3773353535295d5ad17168c2e349435b31d0e104082206a65140ab44ba0ca69fd53aede3f4981f9619030b593c7e1a59104a246e892ffef671b856578dfff8bda103c9arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.13.13+git.531.903f5c0ccdc-3.17.1.src.rpmsamba-dsdb-modulessamba-dsdb-modules(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libndr.so.1()(64bit)libndr.so.1(NDR_0.0.1)(64bit)libndr.so.1(NDR_0.0.4)(64bit)libndr.so.1(NDR_0.0.8)(64bit)libndr.so.1(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-credentials.so.0()(64bit)libsamba-credentials.so.0(SAMBA_CREDENTIALS_0.0.1)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.13.13_GIT.531.903F5C0CCDC3.17.1_SUSE_OS15.0_AARCH64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.2.23.0.4-14.6.0-14.0-15.2-14.13.13+git.531.903f5c0ccdc4.14.3a@a@a@a@a9@a`v@`a@`<@`@___i_@_|\@_{ _l@_i@_d@__ @^@^^2^2^^1^^Y^J@^2@^&^&]]]])]@]@]]@]nU]nU]i]e@]_@]J@]B@] #]:\ڭ\\@\@\ \N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USascabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigibs-arm-4 1636656155  !"#$%&'()*+,-4.13.13+git.531.903f5c0ccdc-3.17.14.13.13+git.531.903f5c0ccdc-3.17.1acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:21756/SUSE_SLE-15-SP3_Update/d81ee65394a4fbb1f1c97248650bd532-samba.SUSE_SLE-15-SP3_Updatecpioxz5aarch64-suse-linux  !"#$%&'()*+,ELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cfe227e7ba0d0dd1a963f01b1117b7a1d845fe89, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b47fb355fbea3190a60f8e03af519b1312776577, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=db47be5e238549d00cdd64b8cf656f2a502e9181, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=86bfec73955bad473c3cae7c97373b8a64d1b44d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1ae80d7fbccaf1b6bbb234a4d4811abdfbe7ee85, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=072c654265531b3fbacd693aa9bdca7ec3043fb3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=10104f61784200b9bb40850eb943ff5a6762d93d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=90c7f7dd2d1d8c9cb3fe5da6b09c923f6b5b6392, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2b81000aa474a13a942679fad9c5a125f925e9ba, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=008ffeec317808b231b2382d4de6a220f4289d6d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b8bc2c507799fe24eddf9717e98388222aae932c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6739279366118f6646517beb8735455c7daa4492, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=727a1766c497ae0e160c5e6d7dbf57d514b3d841, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=890393b673bae562378f100f7f73c75da94eb2a3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c68c1c996c6b74de09fdacf55c5e1775808c948d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4c484d15263b1ac7ca0dc640ab43c4cc2378b48d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=74dff26cad5329be136385eeb9e2db89c669255d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=209bea807e8b44fcf97370308272a9170ccf7b01, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fd2c46a698d5ee34e062c33e987429f40b3b12bf, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a4c33e0d3e14d644102a27852ff8340e95dffb04, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e137d12fa38cdc7b5a20fab9e9a27ae1da8362f7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d05c94a68407fa0db2b9983cf9de666f13b8a06f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f0239c49e8cfec9602f720d40dc2479870633a49, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=353e8d6a987275cd9b5d49ad86af271c499739e3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=40a944d1a399982b9dfed6455eb7208a00b65bd3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=878522d695903b6aae78e3d9e2f36d4a31302122, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5c157cc4766943b1cfd3e1b794af8c197b6ad97a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4786c9fa8a6f0ebf90296b1ecdb722ca0cbae918, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8939581bcd9be6209c5d441860cd552874c6ad28, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f2b8805538e20617bacfbae7378526e59090f56b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=477b0a0d627bd72acd2e71035d830e2588ac5bc7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a28fc157d643989e840da863b5d2c952f0785135, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=031f9e627ce243277abb8dd80f1b9d614a542f72, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=97bbc4a8b4beb1a9b966bb6eab9244ec19c89966, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=67aaa427695323a6f1d561fe935eea45f19e6d89, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d7e6f22d6acf83a70963d9d033b50f3de823ad56, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=82a1c99b80e595d20bbe154f6fb2189c60ca8dfc, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fb986accc8c20ae6d20e1e8225558c63e00e17ca, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1c0d6cd33a5c9d7e935dea87483aab9f1312fb72, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f2526f299b5522f97488f105076d25b2bdcfa295, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=136da16116e55d4c94c4589a11650de6f474ba13, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4a11ca6f6e1bf796cacf67b593ce6c23e0b11098, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4bcb934ccc29d5f2995168c1c0de319a11913d7f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=723009818735aba2264c9f08214c9f1ded55abb3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4f32094a79654a5fa95a1e7c6d9fd9b65c5de554, stripped9Fdu'BMVmx&0Vc)6AL^o    7 & . "  RUR[R R+R>RRQR RcRDR]R)RR/R-RRZR*RCR\RPRR=RTR(RbR,R RRWR>RDRUR[R]R RRQRcRR0R5R6R/R-RRVRCR\R=RTRZRPRbR,R RR>RcRR[R R-R/RZR=RbR,R RR[RURDRER RSRWRRQRYRcRRR/R-RRRXRPRZRCRVRRRRTRRbR,R RReRURRcRgRQR/R-R RTRPRdRfRbR,R RR>R[RRcRWRQR RERDR]R.R4R/R-RRCRRVRZR\R=RPRbR,R RR>R@R[RRQRcR RRDR]R5R/R-RRCR\R=R?RZRPRbR,R RRUR>RGRRjRBR RlRSRRQRcR/R-RRRRRARCRRiRTRRR=RPRkRbR,R RR[RRcR R]RR/R-RR\RZRbR,R RRRDRKR RR$RcR@R[RMR/R-RRZRLRCR?RJRbR,R#R RR]RR>RcRR6R3R/R0R-R RR\R=RbR,R RR[RDRRcR R>RR]R6R/R-RCRRZR\R=RbR,R RR[RcRR R>RWR3R/R0R-R]RRRZRVR\R=RbR,R RR[RUR RWRRQR]RYRcRRR/R-RRRXRPR\RZRVRRTRRbR,R RR]RR RR/R-RR\R,R RRR RR/R-RR,R RR[RDRRcRQR R>R]R:R2R/R-RRRCR\R=RZRPRbR,R RR]RcRQR R/R-R\RPRbR,R RR]RcR>R[RR/R0R-R RRZR\R=RbR,R RRcRRR[R>R/R0R-R RRZR=RbR,R RRDRcRR]R RR-R/RCRR\RbR,R RR>R@RDRSRWRRQR RcR[RR/R-R]RR\RZRCRVR?RPR=RRRbR,R RRRERDRcR/R2R-R RCRbR,R RReRRKRUR>RRQR RcRhRgR[R;R2R1R9R/R-RR=RTRZRdRPRJRbRfR,R RRRnRRWRKR RRSR+RUR)R"RRMRDRR$RR]RQR@R RcR/R-R'R&R[RRR?RLRRCRRRR*RTRVRR\RZRPR!RmR#R(RRJR%RRbR,R RRR RcR/R-RbRJR,R RRWRMRUR>RRQRSR@R RcR[RR2R:R3R.R8R/R-R]RFRERDRCRRVR?RLRRRZR\R=RTRPRbR,R RR[RR RcR-R/R>RZR=RbR,R RR>RjR R[RBRRYRlRRQRSRcR RWRGRDRURRR]RR0R7R/R-RRRARVRCRZR\RRXRiRTRRRR R=RPRkRbR,R RRRaRcRDR[RWR2R-R RCRVR`RZRbR,R RR]RcRR RURR-R/RR\RTRbR,R RR>RcRR R[R9R-R/R1RRRZR=RbR,R RRcRR R/R-R1RbR,RJR RR"RKRDRUR RWR R>RRQRcR[RR0R/R-RR]RRCRVR\R=RTRZRRRPR!RJRbR,R RR]RRSRQR RcR>R/R-R\R=RRRPRbR,R RReRUR[RRQR/R9R-R RcRRgR>RR=RTRZRdRPRbRfR,R RRRR_RcR RR-R/R]RR^RR\RbR,R RRcR[RR RR/R-RRZRbR,R RRcRR RR/R-RRbR,R RRcRRR R/R-RRbR,R RRcR>RR R]R R.R/R-RRR\RR=RbR,R RR[RcRWRR RR/R-R]RR\RVRZRbR,R RR RcRROR R[RR-R/RRRZRNRRbR,R RR]RERRcR/R2R-R R\RCRbR,R RRURIRRcR-R RHRTRbR,R R\ѻx[ tutf-8ba0985b815febc526419befdfc7450dd2f8c393a9131819a14d8d64f0ceab606?7zXZ !t/t|] crv9wWd>ĕ|s؁S$9_Sӆl+Z,hAxӄ=)3-!8fx8%sz-%SLU'Fӟv/s *>-6@|$IA߸|:GU'T)ЋQuzF4R,` D⢗QٲavWK!hiU^:DPXQ$V?k\w| K ?_U]3G[ˀE\ $FjehjP&mTr8Jlu,2]n 7A# HRa,{6&WãYE!tp L"5ҳ]n L n {eѳ+:o,~#/}bh{#~%.A@ѶFojX٦rJ_Oɘo[)B=q+TI1Ǚ?bH >r R0u{5!\FC7꙰\4Vn;n1]8N$LV}_~3Fj;pz<0TM  uo6/‘mcIuZrTӂ,m0*]Ќvo./~%Xst䎥;)xWhj %nYN6A5+?:m??j:tV`F=~Caߜo.33]҂3Ӈa> qϷHϢezGe=W'P hxFusW%/Xia;\?:;?q6hUlGɲZρj,ǘ=ԍ/˯ߖmfqj? dmy,ILn^e$puLoye9XWsQ-iT:MV]pr-SSD_u_('[dX g>1isԮ?SJ3$]O0";_f@!u,Py.P>XLv1u%vɩd>jwahR"l3lQ!uOwJpA0LJM/K}5ڐPG)ksJ?eT1,N" MI{*(f^8A[%/z {瀁MTy4<w1c]aBΥ 2wj99_He/{z鎏. MgI ȡU^J`1} K h,Q+6;f\֓a9Eqa3l>΅y/M29v 8GU P¸=1Nˣioʿtol/E]\^2P#PfQ4Nw ,Jo$FBֺ}=b.|COȦ"e ˁ"n\FTTZWGH_t 8Q1 Op%y3>C,q@̟ӈK ~`͘52j$58el(]䇧|4h˝LZkٸJ#:۪FDM<R)zbRѰuΩ$OKKs5Ȋ+:\ -—*3EqFPKFE~ YfLao;3 tvvemS9{ %vuX-{PDNn7F.Yzv ^$2Ёknr],Idz ZtR_ֺ49q[!U 62EH!JV*{>f{Euy7[Fl1B?S:%I(Dnq1 PC !Z]:6aB"ȈKq8c/&%UʺJY~eO|&IF" @?̚r 9+:^dfP_Sa_‹ܰ&`(Aj(H†Cgh خiCII~g[{uLŶHJunR, }Ҋr ApaD# r޲$+R b![;۱NAo!2)0O6?bӈ~@RtW;Z|+v$z8I-[u#=mVs~衵m~pƑ+g-|!SXҏʰ6kF@ RN{,]RIŒa\R.Q+z몮;}̕{lCO S0J*N=DxWv p0m~㹝F`2f75\ D=Dyo8q~Ԫ[} ShV mCMJ6Io+[ɪG, . @s@XڃM,_Y"2Ӟk?+΄G3SgZ< pאfY y`\йsr=]yb dyB%丳G: w ɱeH8a'@%5oЦ<S #}Ƿ 8eyuf9L0Ȼmӯ#fa="X1H,6C2#*+0L@3OO腟Q)dV2Bo~?H Jߛ)M7SMstW @}哰.1m#Xv_6c Y4~+@KF = M{PsCzڕv7@ԱS9,-B߭b6,*(rBK%X&pWdѥQS  蕹 qJDLq R-+ yaHA}BkuU^yhn0-؏Jm+ڜOb\q{-'*+=(/Gۻ] _H}ᾢQ06RhPBΖ:'KmV~.L"ٷu!@bM))X۔I4Wq xٿN`j2/i LGgn<->#ɤ'7J?u5pH0TH>T.nx%ܔEw]6hV]uLjU.t3ug6Miйu lɟ-٤[{+Z' 60mŕs|7OAЉ@/3L?s|,TH3ќI%"י eK0)zfЕL?B@ .$n(o&MV8s^C2ڕ2vi &w9`,#1[qAzz]SY>{pHr쯌 W=E49Y!EkSE3F1c9DȓrU4.1a?ʼz'1Q3#ȇNW˲ɳslt>5}k]$+ 4eb`&HMw~x;G>;kpYCϹw 5!398*w⿕s}WGA3j /iKԟ)h1ėAΏ⛆nA^LӦ0r^ ZZɌ&8uEN.OUbun֮EMyY;AdEO2xYqfhG$#t7WOeScUI>ZZMf[Y}+t PP%Mۘ{h8enDt7T6egC[]\-egSoc<ȇTw-Z9HX@Φj?uj9H!"t 8"{KW?H=<a:M2 U+O. ݁2}"KZ&$s!͢>B oXȤ!( Bwwe-L*Y#e.]@X)bx麚F@5i͍"m.&dHh4YS8q`Y'q TtUu^隉%ݧ1] ԡdQ' Rh/kݱQ$v޻Fd$Eǃ"\\]VT,eJ+=+O n c)JH☯~{VRLPӾt(qzz -o/7N#^pYD[ʹTi[dXy+\AeY'vbPZ4VvL~^m.[Ц@ 9α/'GrsDm*<JyТw1YGr ;dv6YyHKlS\z8|-0f&kp4,څz@Kk6Лom^ǽ+hedEA/+Y< Y(Om8NT" %7q:q%Ko5"~q nJȩ[^Sh yFYwb/FY fH%Nk:WVxlo'y)bW>Ky5W< rkٍ! 1dþ~j/ _*ҍU /hc-Gbj)nȾ[H|GR> ZXjyZP.dՇ)IlK8-,YQ8n6|7N{&dW{5i!5Re 'aмkeNqA9fJm W򝉏Ya$T@}H a!A>u򄔯wZ# 2f셦Ͱ_A͜ٵqw찝f;MAg_˓\dfy`4iAa3ѤmD~̝Z 3aEӸ..cp'ە'>t]._o޿JKoSt1P}]$AUu|݈Q_ƐV/L d-^9m:a R5*'4pzqv&sc6"dA r'a}dvFt#o ^Hws % :/o[)0`0xG$GXjFcѻaK5dAkMDl "3UʓgxZTa⣯a{O4 3W%mڛ;\wp$%Hyԫ| Z](ؠ5eHucLfbgNYx4No.WDZsb*c) U~6P 7xTcJD 3D2yW:bi$#O3Il>|}1;yuwfE m$,W]'E:j|KI$b\欉yCDJC[,vaC>wh=iwJdzi9>Am2lwK_m+XBd/#;XHŀ}99=W4ukw_lGؾ/qOTN 0]iq%/m._H˺LAji] H9rUS )SET R3BH>o4g+؆vo|Ă+$ex9yc)ś`HD@7u$84("k5M":I;a|DA*￵GH`m4[6re$b-ny`ci(ӃX9 QK j}䫄[iTba6bh6j̫9[AJ-o7D5@4+ri= P Aϧca#SS.^(H4V_^ׂvF 0\MYz%"VHi:h{6ay='TىT&EщgZ 2{WȞ9*ֶgL h}Qph$KCÂ6$w@Fy8μ0Š&vU:z/pV2c&~~X0Y;cRs_pv- T1盫 d4Km,m.k"_}i֘/49hhmW^q#~gbә53;e/o!{ftl'5?'u^Y=l@ &^}wXa6a=5e\l9~li{RBd:t pzUv4|"D*c (fr*E{/iP:d=V#%xEF#ube 'yUKaloLI򳣚MVnv2}.hv_;иOnu# &Ol߆N"pC,e?SE\y8 [UA^E@c5Aq=?ϼ7zst VAIz4Tp_ Hk%xQ!$'G|̍\+u0ntD%EVP&0 q˾ ?6㫍]ރi"$>$g+([*}(W hpaW哉^4z5Oe(7p@#F{4Wt#"IrXewzy㟂@c~Uغ!2I:11FΒL˽8#zGJ*2/ :?rSQ F&qQWrVľ\G_A- VاLsB±ɥ J7Dojʧk/W[e#vۢBŵȻR'~yԻJZ$x=NIpO(^/8im,Ҩ%b2R/0mf Tc5́w]K(<>:MicbXM3f\&R\OԔaSG UoܽOMJC4LMvP :qp GfaA4FLm:tY5pa=ݔp2 i|t#\܋4#sX$7l>mcW hb#!AqTN%QAޚ.:sӰ ^!>7_4lK HIYVmnI+ǽ$j>*\,cQN.h<%[%Z4=-vLj{Ui$eٲã=C,9b"y%l^AĕCj!( (qQ87'چ;m -R9-t$%CF-p1g`Ao@~jh*T-p&PEA4ZaL=vt'q*]mip׎b3q!MfVDՍ^=vN"[C5n7Wڃԥ?57 JCyz$ӓ&Kn(=.gDn$Q5biTJNJ0gG7U,t2֗M.H'@zxV{ST6j-!+毣&z;l/'GF-ْ5l}lH,$O8#^ WݾׇL+%ºe/!oTQL,h18W?)"r]of}]xPqb1`0WUk6Y6ЊZmx"7U~/o}4f~{ ]k.,0'٠E@\il4m,WX\z#Da3_aqe-pV0j2 7<~VaLUG^Bpi\DATTb*Λ\C*ԙEgWkV$AKJV=DϣNv5We$~3w(sWʤ7=1bc3KWj|cn2aǜ@IIiÈ)hUm r rnU(,{"m U.EEqeGU -EJo]T3U29ltm_^YR;g8?'.PM ^Vd;`7Ƿp1s{L!y]vc"1agGLmM=Bj`[5)ԩ8Z:`0YB5|㉕;Sb|?h~{lɇ@HEA1W:br60j+KEKfGtnC̹FMw/aIV}P0e`! ْjlbytI8r{׃&$CS/~MTu3V˒еMnw_DqBO4dq'>zr0֖>7uBN]7QԬiCYOv8tiStٴ\ƺWXɗaz׃0ݪc[ 876, Bt#eT~jG}Dw7joDB' \q7r*@hPƝyv߷a?iY t5{( y.)8ϏJ$Y~kKpwϋ|:xg@6~BrȄ8gخ c^zA鰥G=Q򺗶SZ+ib򧣷yeԋf/,c! bv ]9ǧ\V%k:-ȷ%(89wzĎ:`355燸R#h!{E(,3Dʙ oӒmQV;( bϼ-5ׯ@\RMj$\vث67Rcp ŊhU.p;֕OvEy~(k~օ;UwDAUDzs_vTY潅2x;vGbRGv(r !0{`vqtSoaxk kY73z giXu7?N uŚkr|.Tݍ,B=<_VJ WVip 5YؒDOT70,XhMC6 G`3i )n)4eH~KρH.Ȩlk.PSC(-~zYsƦ%=Y,Qe,N3BOըq12= 9<68hlc ˊPDm/̕ML۬X%<XˡK3O[ Ǹ=5Лfpr Qv`j'e3lHiwE`|Eiܢ O6s%d( I&Y-2ĆEK'Z Q~eA;")&f;̣JRk1yx#ESZz ZKlSNYgQO-59p̯QB`x{vv^mn?)ŬYh1kQqϢA *iz{Y}.0SԲwO/Vz MuEwiQGûݫ?j`p䟉(2(NZÍd}yG;xE68QA"nZVmќL n]/RVU[4 KJs~yWE7A^{#a"/=&-k<Wd˜^u\:%RBh["BS}VsSn EdHٹ@vM31(rƀAuL^)rlI!o.5!v3dmRoD6/ ͔Ln/jT-*y>kDe1!yG N;tQ͗{hQi9bRZC^hLT+ g2 3VV{޼8qM,w=qPJcQ"#h jx y"4*O u_3o-̃NtwDbb)?m%̧NdFFXuW"j;J2ag y2{ǎ#\_cs%`x p_ 5ܨIz!_V޻dƚRp~~Y&rmISbS!.3>ߍ8D٢aj(|>xkf[:sI ahncH$Χ TbAo}u;wu^/=q.Cѭ4j&Lk ac̡[6{*=]ؘT0 }5w#Q0 jE‹`k>QUƕ?AXv8Y5z&b: vK,3c*rP0U)0g"=HDw;z+xeY,ne'I%h4z龼 #xmQ6]hgRlny:SAiLm˔cQ|%-$ f ${vU(GTw H*ȯ8̍܉-u25̝T,/녹Ĕ+ѯ.J%fCOcW6/Nt2إ=oG2,!v?-(5Y*}!GeL vW P[6ȓ;\]І(.P/rY8| `*s1T/8źfbY @ JzjъRbkB#cXMy9nW_`y0TGݵO7WqZivƦcZD9[3*Ǫ/6Rb\'l[2|Ǡaqͤ$^G&nOZDx5ҫZĭ؅}q HzDKgڪ%ڪEĪ-4y?ʏ[)YrI"dE%H9 -Lxۧc.yl _#+N:~?ȑэLD0vA"NH~!V ʢgiR-B,yC}€φG w2 FLwxѷ@۞ZEu@;p؃=f-.3RnL#enL8ݡ$}y8Fפyj?kV_A/WQbC+l=~x6>,i쎜b\CcPqo1 6fۯlgMuwc(`+=d dG>搛-7N nGg *3~7E܋`e6B)0-*S*! fCCfZz]IaS!=[tB&q=grr#c*7^1L֥N~|Fqu`Gh;4/ Z "x7ѝӨ W= 7F3/_HsF˵2@mBk$t [N둪5hH䯊5 jKctssʏ^'X@oUbD+Pjd(kD?HP%SpOn5]Q&rC2rk%Q>nOxߢ>8;+H$f$q6_NXJ. wL+B7_=q&ը/}Ȯ2 﫥<\,eF~9;z(qmsŌ±CH ;5 _ -(Uxɲt::YVLzkYוTx" 42^?쓝w}*FqKq0Zzev.l1" Ύ[3 =lAcݦ;ҙh;ЃAtRꊄB6, xNz=8Z YRQc- / 7__v>6_ 2E_?0O \ևƮ!#*' }A/&"̧M٭Af5Ftecm|\vxGwrO aB|A䮩e YFH0ÆHf"I2P&w84IU_9+"米9d}ya ӣw,P5o S!.Iޓ߬xvu&Pysm!+AK`vWUw$uGK2ёpL4 $;oҡ \IĨ <v׈V{sV{!IOŒ6L@%WLJ_]1~"l¨Av0\c zM$dseM\ g dZ20N&Jp>UB zu:+imldBڝ%ܴ [tyCW'=帕ϭZRP]ၥA8$Y7.w##5Yd/7l;f6l)H-zD0x#wp`bROMu "' Q91Ot~ _*!8b'ڢU~O?xב1}B&V͈F1e+'a);uGws)bB`1Ǫd[Thec%1GL{2Gl͜"݃K}$̿$ܸسNedY@"M4XҽFAٰ'8qv\ / v"8[Ł|9Ts 1n?#:"4BTFOڋS/=eۦ!4[1iJL9 4~ʛ g[ _L:4VatĠ쀜l&y O%[H.i,>RL# gMK `fZ V"eD[9Sh(M AiFwaPEe%L#ȃ4HIOęz$PPgp"nOCbH$/nd}v=ٻ'ٔ N;zxA :zvnި1*I)OG&B.dtX Z2sgc*9o5#/M[ʆޓ#x] 5!"mXk tzBFRXe_$]h2L?mei ]|Hk(<wf~j; sLئ2Aw |ȄEKj=J Ձ wAۛ)]2qv`JYRPFS kCc& wČc5t03?t>z?SC> ʖ0i :!(5X&]\}nOggefpiüpjV{sӬ܏֥?zR6R[ hF[,USU =r6"q$K;e_oUO"i,I]ɫdz ]2.MvMW'f*{TC(0]DXAQSxGH]_#tHѬV*srf}%HN=1ȿ{VB)mw[iN8{Wb=+̐lOcZM-d4 v<S7#N4{y/8R = l/-25yJs?9C$No?n)J=pS&iQpw.V=C|Ҫ;L նi5T3}]3R9*#C@/s#ak!ƒN ;#y!wR2^lVtJl7Ώ6T﷒x"'l_sF zwy7ppX꘤[0#<аz?c@-3Sz&x1QXSfoN8` @ *NO=hVɤ3- +QȒ~NXX, %$*?iZs,\I]Y41 N&=ZʜYsoENXk3tn%ƍmLaE9N2' 1"- 9R#p+)"CJK;c?N.ẲSvyR_bKF $ `"_Ow 7@}"x^84@ ڑ9\Ӧj:Nt7d[K\i৻KX_h\ui9d9c(zrJ ŏSHT߲ۊbTUE/FOWŅPՇC^Cd #ڳ2s3O/EDTAHl}=a_I fJB]&M/ !8/G_anEOu< ߳7c;v58GNg?wHz!f-_pˍ*T'٨HQh70#?ՋQ3iZ"Lj8P5-o`&ghgnIc3{2P;dو7¯VUw:tvE?d0Y. ςJ)TzH'ї ^\z_Y'!?Y];LtwDfik 9')j0K Dr)}e eIq$I,JR|mOZ8`y$D+rb32vԓTJL;)(L|7{tTQXHcYs+l &ȝb`;^}ɝ {9?u(!;*lv.(ܲfF+U&,r84)k&b`gV UK)NhЈw729>5m}ndn9?@OݨC`rq7WiU餉TQZ'v}rWi^>7LZXVBdxk g D=D-9Yw: zjmWY .[nÝк{U;ӛ6x0wQ-fƥB*D[ jhHQ@]*>[/A7$<]1̶ h#p5-H)+r.+ "#Rz["Ԋ!fthukN E7A Z3; sf`Ѧc !ꯏdT+^vV ]$asgVJoD85=wx3kQ=ftGZ^~hbqJӶ.Bl422U֯2{Zc{ʤEe[1["L,I;Flk5kLB )j2xqE xYʾE ˰bHO9Yls 8sձaY P# XgH̛O*dcō!;Ķݮa\o1*m.n^Y Z*ŸFbذAG]A }/N4e)"Jgf'Uw"5Vd^TjƷMExhSߍ|EyJOw " =lM F1,h̛r?29$dq]Ԟa EQ@@r-S98`7L7(~%JZ|+~E#8|"H:9{kg6 dS~EanZٸ@QjedNvc^4ějeAfVRbDNs¬2>; Z3Xē˪?.sl17G[-CZ5W %ёmI,:fxc6ř *ȭ>(!HcME`n9NE4 OKTg84,0|\|RkDw"M}(WȨmhD,9E: yґȂ)?*"dpL늚}9,) k<wv3te rL4⧌m;QȵbL琜dq`d^'!/":Oȟz?ϙ3Pr<7ѷ~yVM;;Hu2vPLTLhJnUߴPCuV00pD g/dKWqƓ-qBw?-䦯>~QBt̉8DX^}tl{Ri6Y"M{/HvBOr7(gǎLLgSS+'F#R!=w8bP.qoߔ'l;R^Yݎ.N7Dox"K=52%pJuB dd<#6wj ؂׵\)W֠)c+C|j_\Dey κ.MwP8Jz5 㖁!m;A-eR u 7)QqNwzA5u^!4eҀ$?`lQ$ldGK( m=wKs/~d PP@fAE tT{A *p nSt:>'\}}tKS_*V98/0)JrTZrrFXqHUCcq#˳,^;+YCjjF.{W>rMN7 &CH6am\+g &ifJӈL[@X-͘M J5b$$usm_'}}#qH @d1f"}$8.([ܴ?*9-_d߬#y%#n7[L㪨{Ω ~"([ O i/ zMVUؕ5WٵGG)8ءXnN3*z+e*j!Hu6*Gžu_(%)#/2FrGBiSVL^@w<=p jNsL2qE0q蒛f~ȋ_Ŷ$!hj"u"yA$R)_1yeBOwfrA)Fi) 1` j^VY.X=PdEia0:.oWs!3.nVLBp:Uٖř\چKsc@G)RIf_X'O sXd~4MA֌ќR1L}{d:G9;`VM |Y=qpcm-^ϲߐ)^駍#Bu!NnB{e/6p/׀uB/uP9#uvԂa>1dn}G#G!nBng?쮈f:76GhۨflwԶx9I8J=Y<_dqΓ4B>& o9ږA,Hiws5B"@iJ}7Jom!bq(;'+J(Zqwu\HA'E%qKꬥfgΙ68.Q L3Y&"zyD֓nd}bq񮫷Ne[n9GUάk= z,+8aKQ7e{\]9,${.Lw{X"+%A+Mk UK) P ° tM2-l}#e/H)а\*]R&c6Ynj 4=jR5C&§yĸLmB?Z).j?Z#SU=Dݴnn6D{V`jFyF;ɦ4GVt4z쟚?I{-{tJ{~P9tUtM ^zS14j6e2VރO '{HY>[Y Cߓ3X BD(s#d#"6Y15#'^7i#gz7q_ cr`wS8+pWԫu{7X;|yW *|';}.]S-7i4 P'i6h'Oݑ+k%!7m~pfϑΝe}1X˟4#]ع`kqtRְr jgg\&Yל|No!rXYԏG`tl)Õ\_~oCnξӂYCWo^nv[$h֖PZ#|GClp2M0ϐ tzJC3EUim^*fM߾ Wq2 xu ɤRxT.֛ KksX,&fUpYo #ʋ@Ye=գ8PSQRbʲe]";: k!.48Q+W9|G:2~M%hBmZQ>qYv28Lmrm onb^g6ɳ!;y8haB ;8@W^ujHD"|T֯Ѕx ~pOǣ6q\&$+ ń;T{Kb`JV>䀘vYԐkYa1 RS@`v?ijvSD8f<-¥c" IF4-k,`֖Na OνeࢺM~㮹{fG[6]HB0à[ڂϋތ Y\!`}[# b`yA*405OPa2!9]ƂFs)?nWWɨ)=;.t[gcn0"T{~qn!~nFxT-K"L60 P\(o8*;B7!vlZNaQ q:Qۦ>K3S+ Ezs6VI&_`SR,H@W5+=ML!z:t__}wņp-g?J :?r^DKLl#yR (_SURD' /'r)rQVAbd]t'̞5k!3F-Y.t13$hʳ~yzxqǐ\Ǫbl~I,H$qQ r )%"ч H|^7oj m2!SE$qehy~xe`0x8¢*< qbFcpv>Ԁ$` [yt .^سE96V'{\2Sg5CqoA$vK%fWvA,a>1}#FYyuf8S>>z t2TUaCm,U0K=[li;9Ԥ]M+jܵ&O}`Kp"#R$_@cK`*gğczgu$wy}jJ}y8>W_yrZj/QK]zT #V@j%l%\Hh> tDg}vGd_!:#vr媪`Au+ׇE"q ,Iiq~mrQ\'>UDcE@S,5 V1Vz>VՑEZd2 b=TRZZQNkDJMOeoWȨ`}?¹.wTmۨ㢀RdSHP>~A1.ߡC[f+^B|2YPhjg#L1r`phJZFɋY@ys("jX\IF{#3Rw"}J{aSPAl\ hZ:tT`Jg'm%#_y .?"=zaF:klVe뚞rX^yK0Hqݴ ^r^q эT9KRrVzvTۿ,.{; c|T 3{7 {M[HаQ!RVV"n:o~:߁t,aa{@!)%.گSA5Njĉxr^Rނ5 8:3.Y!wSouk- տ'ڐn{-(v9dx$:g5Iu☁~>4@"spBo.-xauɀFL%*kFcx&!Hi$oAlm"+߼-/QEٙDf` ˾D> 2'CLe˶8o$تfdmyzWZd`"X(ePte^rq CA<Hc9.YLe6q|䡼[d?ON/ߝ,6ɗؿU/zƖfMj lt$t#(#kuaz^lwνֆYi@@w=Šo4N\] (8G %ez%2D‰/aaj>n)wyERӔ<~DT$`ySw*ey'F碠zZh_3rvt;ˢ-2>6犪$UI#ڋ4R)~hCG%X^2*H&֓hOi@e#?xk neͅ7WH Hё047$^N% _Y6lv"6wg=<w3+g>51phMҘ懭e#r*v8,AhL.=U1^``ա0a]쾞jػv-B9G~etU5f6êLZ5k5/AB8$YnKXS205l\HΎ`i45N[x1>MN[L=Tyz 6OHeN9x1&b)X_Z^[D5(eCfѫ@tppëf0Se\8TN0EJ, :`82_ OUs[iJ,bqȜEJw W6 OƘ,q>>s,1S ,A2IeH9os/?3h' ]֡ qzŅX*E h}_2 5q]{]{?>_s)qv7(9|:3W7pd?E]?LcSЦBZ8Trʥo tƘ]C*Als2{h㟘#i&ڸ&Ri  > YXJVVXƋW@jFoӭ[B^O7{,$bw;%~xR7{~E}M'Ł>E?'WH A>!^~=DreWI٭.%~d%5VO%.I;# Ekt a`KR1,W\! UWq0e[&C1TʜmDLU}ErdsӸaxuCNȬ❰W\G4:Y}gat#KqRa7'̣Rb0h>$Zyl&:CLp˒KwUibǒ?Xy0c_ϔ*В9TgjX6k#bZ||VDPң`_VH(ᓉT`ۏ:.z.K./l٬?%ԕ.ɉqGv^O3t~H%Vb/SL18F `dÁ7XnuJs bl52TA%Įyi56-YdH z7.7S[\MfY}HnZswP*7)Aڌ윚LZq _v&.Ls|i=c;>kwxb4&SĄef \v`4ٱ] BPq DwsJw辰z5Bѿ=qLVCU?# Qʉh7]C$ 4i 2+43]kP)殇]Xoq {$7(E" OlT>Wh g&ְf@SMt׉l,4bW/}% ">Yv8Ҧf!z*wC0 "-=Kc`( yI&ҭ찖% }_j( J^ A[Sgޠ/: u7ܭhб{T@YN{ufCܞL^TN{΋H~GL!д0c\G$)i8٬^vTnBOlqcD|Mxυ3omǖBXys4bZ~Q[r M8usGf Nct_ c؍tiv4 X]&=íQ؂ы˖棡kM8ZB#BK38 ң O*tH{k\na>6\0ᓯQp0eYJzoCh@uxnoYcmlH77m YlUZM[oY0Y`5 /ClWw?ht:'̟P3P;Ofo; &s&zJ إ׭WZbihtƙefwOJ5?[.:CNO(*\mɎt=DJumeȹ+q1!lK^{P шKX+ B}B!ly.y2ZcNAQ)WK[#G0dv7F}*H ^CNEMF"/auOwm[BAl ޵Em5j$ƩP%!l33zJP4.zA+=О+eN N²lSZGL{Y kP2K/:7{(7:{qHsAwu܄mRcWjBvCWB]$P Jc0G7\Z{%H?[F5^gR|-Z+0sZ9`M imKϜY@ύ͘xJ4O'dlk8ؔ Bo/at;rE4jRǦ; Ľz ޅ9,\V19ŌLwĉ C7uFѝO4O:zZcuY}#*Vk\C9r6,лRv'SaI)d% (|=\j-BG[9jZ?vH6iE$*(;5QHj"ݬnv~qK@.Y6gLR8p`j-WWDu? tX T1!OkDG?UBc:q|xĄ3KF]Pp·Q6ƵJOՎ~@.zDDXޖjo9FR ]]i4-tQ+2# H(W9`Jn6K)::x[\hqT)y^_ z rMXJ0>*Y^!L.6^(-h̓3EF rz)۸ B~CT1`7֧b@3DDL`( @MzVH|K4fldj0E3.k9c*L%,1eeH2iH٥b9xuK?䕧 ] M e4[\ \1| ZZpO*Z_Y>Cx` DZ:d(1/Oԑs:q ZݾF eؘS@a#W+"$#Ce(2X%GhxZw[[j5 6ȿqu>/`LRcP6:4+MO 8%Sh Б?cgԋs2e wn_d9 &[8y$jد3QՀ{0H6-9pƮ;YמyQ[|#,8JF8-w_c[%Ck1m&ȴ c A6>Y xPdBI}0&!ifbE Ӗ=U5Yb˫~9B84t^2=0ɤ5C:j)GrD:̡JAȎPI7ūN};īV `ˢɵ#D0gJ' TZ 6FI }D~0?riɢ'p9KN- 8"Ex/o;U{ D\%FNӞ<[<1JOh];DP?Prz Jzg^(h] b$zxk_íkfaO+S$4韍ߟ!Oը5HHD&?b /;ӭy9ygDA.G}{rajJ=(#k)p$ԩ.[4(F d`a\ct9.+褀Z RFA W 9tYY8xU.wט$c=]ړZ [*MРVzm[lux}9Gޠ}Ef> v=`%s/j@@:;9Ƈ|`!磮(ghOR [N?wԹ?HcF!nR05;#GX JdA>RlL59*ػԿ"[ߟ9~G =ϡj6ҝRp ߾˰@񜠂8/M&rg r\diaƎ 3&~L[s>ywͦ&bVHX+&JxNfJ;h7\Rh''s^apfIhd"Q[" 8[+b/ qE{ G$b߲8!Z\?pw4NASpEb Cg:&˅Ŵo I>ky,Y/?]}jV|Yf-b%(zA.ҟ=(β!d m{a[?-Sʫn=:ei2C.ÊxBxFq*X-mq[m9 }%Dy1ET{ v%6B-$c1Y|A\&ȐNTF)篧|olH#m|24ؐF^I٘J=`?73 L噂^na'x4IIq#uVMSHù{ D4q h_zxfZ̺E-!+-gv,-%VQ(E\bݬו"4Cx#vn3ig]H`߸40Rp2ʒTP\酷-xVf"k%}Mm'FnGmކHw\*Tsobe]"UI#rXnҵI70=Wٶ])GR%6Sg4d`Q}Rjy#NTeˌHѣX+nOdcԑ[vZf{&TbcnNѕ&;ol΍E&.W!|Z: BzP -\=J)9a&,2ӁPg)=unjKGGlUƨl jz|ySA*U2B-S]1Tve3Aon#U^IS_9F1XnlV uCbps.S*vH3=.GykrPNS&Rt?#D )n^C|mA1WITOQQɯ͓ɧ {3fE~gC]~mK%O2וMGx羥j M7Օi-RkkfkTE71ReEoS뿻? ҞMVf/T{ uotVұ4I q|@bWȚq ?[&%ts|,\X3+9ER\B7.(}k)!v OH0!ɥCzvȺk(ZMiN;QO^,߷*4v7u{B?}ef5g?Y{,u1001#+AWb4|fpfLw)'!&G3hS#sk>Zw4RcC÷@t5}.UJj(WbX,M㎁uXsWǘ PV~SV448e bR,,^[z]- س"[@Rߚi%My\  g"'G^U4kXvE -˶W Sjk mG0)IYqέ8HcQ,Ϥ]@]h ;.,>Zxk(W#'_'DM$3aHN4ꃽ$Q/8G\6_+nMj~y1'|&ǶZk=ިIe͈[3WۉhBJ)v_WxG8RkDAy; 01\}m\V;d#ID֍\81ԻL _m GRҩ/5R oo#wA`EP/ ij| eغqVN=R[O/<5bTWTH8@'sNv"-_)82L;1N8x(-Uq=!B*~9RFj ^Z#Iix9R.f#ڴiĚq4Q[`vzJGU^(Q!>s*Йo;& -#bD= !kֈhp 2^fb|.P|Bv% XeԖ],|;Ac[UEw̏ǁG 8١巅rl_B˷\CIV$#'/3 ccn7Q.@߶&U IP-;&I%npwπؑo$z Qۀ(ч iג3}?f&wYk񨅎\ï2_ke! W5 vA=&39bh(\WAך$prV.B U8%̲`CV7ٌXͻ-a1K0h;t}B)!P>?j@VM(XMa1G=yҡ8t7:> kx#u'>Oɡ%#kYBƺ>f&#{qcf8E,B/]Z 'A-T\\+ixKBH f(Fty/V$ĽPTyV\#Ë+P TY\^T ׿ޘ/'0jE w$JyUOi͸7$s\" 4!EF(|c݌)0O"\Fu$Y/KlmXZ+R4Dωg g?CzUQJ~R><7@.V{}dz}~XTuȵ=fJ=<#B1^0 T뛒cIc>IlW\g""3*"$і@z7VSEA|~F";K,(QbY{+8y=Lz N^}H=;gXjөkG@Ρ ?a\ "'zA^LtgW'!b̘hHd8UëeGf)L?xx1-uw2{%.^rEl9F]q9GC"L@F ꚸăI]R(@Ż&Ķ^U[ дҸ*81dxvFF%>˒صe(4gاu}wg*]y*SDRǽ􍖱K=="ϑ [_y]:,eÐ+7:u-j(<-'mXmҔ' |eb~Zk:?rIaFk^ }6BHQO>)M: ͷ(ՒgU˒-CY~{*9wB<>la jMLy^szF)ӭ 7;]g$g@[{GTggfF0^\ir&CD]T:7]lgЕ'2uohrRk\c"0/xink5tr,ƚV~Ho& lW(`/}Ą3店=e,9I=%~sx$Fg )f9@d%_#!ٯoѨ,uq݋vM9RK,ޒ J| fXc.u=TL/i;qU} mA d*eΚIEΨ/GAmr켿$zy3FbMd^(<8"-Ϟ$F? k( Dܪ%hN@*3jɵۋEv9]K̵'_Td܉k5̊9g)Pd|o}Rťsdiq1)rlo޹ՁBr- ?jyCTh;,IIBRjgBUBQDYXЛ(2Xsnߞ`{2qE43}Q"WţfvmSJ!1Mg) >WLJh H|8f1Nq!zQS5*o_ r_x՝Y:Ǥ˱x' zb,ߤ|bCȡJGVzϷk}j]+Ti0ӷ0F7"U-Gb FEi*`12eG"~7ȭQ;i`d2ؠvh-+`oHfyrh_6{*z}xl$t%8%yB0.ĩ]AN ؾZ7'bsem&&'F݋g yo(B$;gEO 10s3,_VL2\>PC?XFz2ld+s$WYeSh-VӠNK]IDnIo9dhtFմOztIu^q7 Vf󫧯k* q .3i)P(Gewp@j:aEKHڥ%@egc;9'÷1Kug) ^XkXxed(oブF/[Æc@&qAh;qD'*~`'^Z,#yA9nv&a?;9ZP!G@0 9COЭ\4uzE=r.cxw&dhmE.=K#19^N2 OGӔ{A\Jil\iZt)sp{f6z_i^VjiXB6Hq e?*hyqRG?XWvgp~&]GFßhٴ>KeI7VPȒݡ?+l3Wv myɬmrQb]/d!@H;x |#[7fV]~Gs Nϲdץ*J(7"]X$U<%U0PㆯoYbU+:.¹%^*I\&n3=82F}%O#Gg.NXB_ҧ! ) 8Bi2yf8&X1HR5DLg5B_]|ZB_m ٌċEij7 6 ґwɫrallX>GN@fN펹.SJ#$nce-a`:7bKխwhv#{ll0R[`Q~5x.bk(mS@VgdJOɖ G;pyh˛l‚N,B#A8EGْ֟ZG#gkגUۅw~]Q.1e?ru;Yi}ȿeH9,aU.Kb"`&=lDi/˪ O@;$̱>G$M%Yd2\: 1r^K/%ChRi6H ]~l٤0Uٚ{*J8u{0V e6a{1N,T#ж~6 JvRl^ӽ /mK\+4jVd\e?i`tn.-H -Ydĉ<qȤ!v^TY+R!$(* ؃w6,4Y>Ca.A㺒0jRoW b:E',k$ewFYmF>~$JB ~ja)Iש$ƙuA#P(^Dz4%:v1O66*`sLVE@B>"˭ǕX RszL!?]j`n} ' 5WVl4)HrzKW2SVg$DtGY$AeМ y#aN+Q+Ѳ/|^_;.@1&q] z$fY({!et3Y9Ę(mHN;cRڌ"y'oP72Tz景rIuTK*M{ـjp@B3βY&&!"!Y>ȏkʡ. !(w4h*֥(w9^}\5ِ'&%hꁪHx:)[D)Tt^̎[`*Hncl+Sa(_zɩo:] 6ߖ uN1b،(?$}_;EihDk|8Dq2rxUSӹaO޶uRr:5&u%z{1rOW>Tqr|߲yD o1"͇ASd1L}[ej?ҵ !]?pMa( 6TXWm۾V4v*J ɢT>7Wڵc6] -^u 2Jbpzsh3_]QE^R[Ktx`OKQ6SXɾpȴ|CR]g%E1D1ir5[q: PԑKY3W~sH k܄ަ]vXM_wjskӛKwurG=eή:5*qCg]u8CMX}*_Q7⓺*eknkdxS}k_Y^JND| Bn{-wx7s} {mHvƱsRRޗ(-C^—qzCJ('&g{WЭU#x(d0ʐqUjY#CL :^ԸʿIUh݃` |ܦT s89ՏJ=ISTn7ڱ Y 8YRo"`a~{@ˍH*;=b:Rϼ2 (s aMMDU8Mgwndt͎0hڣn ,@@Tx WN@#.i**ߤHD޶lرaLx@M{0|ZPtuۉ_}Fy?οK?epUlkiv-ZYSfنϫ]`#5 TrEDaUkc˅S,5F^UƟykm fݎY nFQUYtfJ6NW \6~u玜k_#] *o5Rmj90@xz\@>tlYAL);p$ؽ-U> h]:0h5y,j2ߍ뼕#X{??N sJcE`֑ca*{?+ 2yH, j)M|1&ecK~7ث[v%{S?}V$eNLlB9 M; (J6?@o>A:&*hsY\ys&*)c幚Cn1{򬕵IR}gؤzʒ9yC.Zy r˼[PM nUjS7WBEhjU?T[4$D=OK` hYʧXXEyы>P.\\z~qx=z|י|˥:)Zi"]꿢B4q-)B-grذƷqJ+ZS;^S|@+>CW5&T&y%Q |!6g']8!*4~a.@J46`o(x9=F՜0NCߴ;>3@}<3 Lh!?FhJrxJ5۩ c3V-" 83#+tYnBcXi.3N7(ThR, >=9x|;|1)[b"i-w .[_y*XMj1t@/&tZB$ ^py6M]*ro"bG{!A1+c%E/ͅV?U3hgݡ$#yv]q%88.pGPENK ny 9wse! ݄ dq'}n/Gu6}~}Wo' C K ?iފ?/"w 6cVB~ ?=6ĥl[@<ΚRܡ2U[c偾&F Mb~ACC MDj?74+5#%RFI$Q+b~pU.DBд\g^} V+F!-id;ywd:?AA>&8@GR֓X̨jG1^\,TFEI|8;qg_BTTJ/͆ _K_ȮJ \юyP"R]LCo)7G_O!5lgh+Q]3!X3+``#Sur! i;.IɹPDtQR4:SR|^''\McoO\f?u}=:{DT?Wu]hacn5i~zBWT~abqlکCYis^ jk/;֗h KyP4.-qGSX`c-|h9^$8>dH=hb Z:u<ΑlM)Ÿ φ͓rɺlRPU7OR8үUU]hZhw0'j꺇X>2Ht4BJ|؅7}X9"k'ۃy}K-p&=9I,ȦV Br h3цpkيd癟(+-<e= 4Wwh8 H8/( cjZM7 j\+ uH E}VDW0LjQ[TJM8N'?Z FRZ-lT$RVQ,xG'Pu*ĎpHx6E.:H:FvIRM{.mK8#Oȶ+_SZڐ<}m qRk/Knc2ƒ`Th5+nG(?Bސك 2B7o'VN^ ۮ\r!Tu3ƨ; lV8D ?}2IE!l8]׼j#;=kBo=/P2|T8O!eYoSѕ"%zkX 8eei\ I!Sa@h$׺%̃yo|Z<QʎrF}•TU1- Ӌmj,jgɴ¡#jRh{Ao'(ZƁeŒI>xmj%IZ~܉|T-RCIC<A&fw>`wg3mn0 wm^WJthqMrjhiE7bI xF y6}6nU^6Mݥ}u ;lrpG\xQo4Najs7IALa.ԉxvQnxgqg5swGywT:ifwV#,<5)ؐܤ['Ƣ$ÿ%m_ nF޹$Fk.*Ɣft?aB i]jT|씾ua\YZ0zJPLO=;qU٧+_8Iz 䪜i<{bj߅2xxskMl*Y8`&qƷLqMFA '̊6Yq9s숅6ZOIO ̏7؊jM72A#J'TSFF@S&QXbq4|T)XFB.wA#8W\&i_H4_!Ī7L+'}]J'>NFXh௏76t]f@n")de*& HvV&咻nfU}(T9unb@P@"l! J- 2XOV^]WU ,9⻣Tm76~}E@v"$i U/GMn_9mg-yK3L?|{y:LtŴR? c x~N{y R *`1H(Vgi}hljgs& -`QbQַmǵ6aC7=l 'F^I+ z EgX/OAßj!\2V e/﶑*@9h~f99y#״'/_dR6{Q,(q|")_@V tf]'|km$W,aQ:5[)جPʨGHśmHl]BouQHK6$DjQ:. (ƈky#c&*SAs kTqҩ7mDTcpdWpv*:إ+lܥ35ǎHJv-v4@J%]S(-mjx v4I_AƷGTl:H܈mx2|fV8;7Ny \:l״l\>AS?PՈqN^@&[?@fy==xJffXdJ,5@IKSyVr~NJx=r`-t%x<aj)\)=y[ _Iךǡ%Vog>ĸ,") x`p&;hgĜd^ I"tqpU3Zy2c=dF r-($ane`P1od!+~e+HOv_)(K,^(' rk\q!sp(?iG C'h*upkR m>낓\旅~TaB󪇫&E],+);Cͨ1_^Su )gpY62whA< c/ qYsAv،,ڤ;]ڵUmƁ%Z{cg5_08ja:#[F2BO̘˰s:*wE'geba ܯՃL;79ģwBTv7~ 9 *fCkp$}UiO 0b,bus˫ȅ C;!N]3Z:2ԃ)e3K垑y 0QQ򗮐 <rm.!Jr5qu+&ZX%6 eWFI>fB+!Ad`\ifmOkg 8 QyD+2ү,&O^n7 G%;ojǣa9GF:~6~Y2Ꟍ3؁Ŋ^gֱQMiZb"9.&K;˳"huM+fwpp>|S"{dW ,KqH؎)^Ӈrfs$|!KPVrSwVQ/t WE^!42 V-еFE;n1yC8_|AqSsv"5 /U˿Sד{frֻ{cz1jr&` T|Ώ/$;KM?7}}a~֟)^uvXrO\+@$'8&" =Ie(ЄJqmRaN7mÇ=+gD{;W&aj;EzJEfN͝dϙ`0jG8z^ #HH╨\YOS c *=Q#iwO,vXm&r!ty<pbwQm"S!]Y%˂[Bt.;a 'D}.'3)ݖDIri Џ$-JT8#v@½RƜV(t`,K38xa.bZqrm[: 4C?ܧJ  5Vbաp+ XZ$kM;./ǹ:Sb@i<'IT‹_GQGfBaԆ\nUcNA0?<_VHT.Xm&x䉏 1bV I%[j\C)xsFKDĄ_@eϠIl_oM*k1(ILEw$W[:Q|4GϚ]f*V-98?:%!O =1D&oh7E [eE1ӵ*K8CӍIޣόTD==˫$=%H cO˭X`S?fZSr%t/_[4{O1]uZ gnmܛ]gz\>srGK &\tW#<\(H&Fr@x zc w尫dr n/+1'CMC j"XkjWtKo:Tp`*y>;ytYWsu?(D2S]i%"ŕ a2\g|7?K C5)AЏi(Gb姎FFc/[DaRàYXkQMM>!vڃ'Wr#j6uCeYwn7{\]w/3[ֈ3/Z:e+I!fVm]wP'zN~(Qh)҂,;ӰGSg80(bQ+Ǒ(uuګFYFDhճזac)Vjq׻1~Od0={\ 0WU&3~AYnÙ$j\D]?`?.{z"\ ȖzEm_9! .eKߞ"s7e w8VDcNYn5BPdשV˷6~L*$VA|} 5P# R}4=eBr4=W6PF@$>,^*xG\l>`<N9(VRr~UR4q>-%݂_Ppqxrӭ|mYz@(o M H;KW`z_&DT߇5DK;L)O.xl4z-7dFw/ 8Q}fcX+{NqGW XDD> CrKklsƦWbf2~MA|]~s-gߍ7U0s4ݥ &3V9ĐSgœazU.+MqV{P_(UV1iTe4Jd/lO3 *F)t"Ό}TGOgHS4 {S;c}2_rS _C: ,ʘ!et!@(<;A➏3淫7ixhUH09}ԷY2*\W*МEK5Ljی 5~eJ("|Q3V]@זGM0mCxfzB؃Qn!'rvǮJ>!DB%FxUfF mC.IݩMYFm^C}hn~朼vy XFNFl%x9Hh( $Ȝ#ǽܠI=6:ShhK&[B +j4ā>sI@R1++aZa$Ðhڦz|i$UXyrΧ rI,jsž%2U'Gk:Xz`%IE5s?qd ҥ#zEy\ኸđt\fLbu\ջ \zjj3B(h^hjq9?~f0  -Z6bx" 6By:WE(Uj2#p3Mdj<_^0^+2Zgu=Oɖ0MEͯ|?Jа%پ$^GMYHFڰb#D/?rp}΋!At @,9^lnސMIBO3"`m( 8~45\╮~AF~I4izF Ingcw3%91Lo&kO9>s7oYz8sk9 P$-G,}ta Y S}nWAÜ4u2A)5WolO\-g&PwYTZDHXj8dVU ҄?bj1?+1Iq1%XoFHXI@ʝ"jmƒ@SNYIF~{: W=Tah6k/6 L& _#`j_`S7ԗW=BYys)FzOgu6I&=ovȸ蘑.!-6)uF>0ugY-Mj!v ~!޳gX/]iҳBʴ.ߛ.4Y`J]#ѯTv9OsL 6ӫrlTϼTq(%:ro(W8f.PAyU:{m,C1ZmS$KpSW+sM|@V0B91NXcOкsE*(|/EB'D@D_&fC>fԟ>퉝L0*s@UTeL[u _*6%"M)>VLl#X3 Ws){rOr*ͪ_vOeLZr盤cv^ֹrz 36-L&5s$,[?B5ZeRHKRHr)=š/Rۓ -柃.@LW򉂟å:)Vm#˨3 7-"ĈP98`˯D]>wq<\cxRQm̴o0aHbyON ʮ~^}7!k5R]Lk4@?"6(g]z)Me} )4Qgp:ᡬmӜwS2r[MNu)SdW-|ʿꋋZFM f(5;o=boNksȻR%=r E5uem(d yBuk&{0ݷ|u|yJ[}mSd˕k I! PEqiP 3+U>ZL&#'3zz5۵@}n`~bbVJ aB88A/#yItԡ( d_tA @{+5  {ZZgk* ds'jħY޸Ζ߸ JJov.#1aڳ* 9900b,;pvieGX[[E'^.87Olzд(L r3^F9kw.tߛꮿ~Jx%ߨWGUKR AR1[HR.n4JՎAAL~BLN&4?:źi/#p/Vl9u~Q2-$Fʥ]ؤɦNߢ@X3qxetJi48n2ݙP瘮/X=aXWJ$gP >jKHh3*g^YZuj1ڢ֊JAv؅O\Uz/5;1uʓL${^ymtdN4ܵ ܫSsM<;aJohicct?(O2oi-r$Yg|3x͙go')ph\`%-H gVlgn:%2.}P  d K|j$8k+_!S'bw,pJ(Ne9 1\}yjB>ɒ?fMp3dtO-a?~fA ɕ/F59̧&:xDg`|ڠ yݱB7ӎNh'b;>v:֙! sWӀq˜C5O{- #tJ@ƀ/❅byXīgwIW)Y׵Q(+L t3'jې]woTɍ#ŷqS\kdWHQJjSw۟u2g'@ɞl$# |H6c Q=Eҿ.Pݼ6j"%Kasq.5Ї,PVDNnd;u`&C" }O]FTkr/Ӏ+.ɿry7t-S%UG`LE%}juSRrNeDqsœU{l*NJYF,`fIerFIݽpҮǫ~~ ]%Bp]8멒7ڈjZV ]kvctEGgA09޻'LzrR@EQI9z%8?(\%T/{N9'WyR;[lW0E6:Lb7O{#C-׷5߽qhF=,^d7)߈pɍrzaؕ .uKKva-tAe7{Xo`Mm/"L16N#3ri|kZ:_l)?LJծٳ߁< rU2j(J(f6C =x?np.^n&mdL!k[j?3k1I?= @Z8G0, PTifY̶V!£;z-$@Qn=d,*Kސ?sC{4͈ v&KPۜ{cܓ E-|Cr9N{N%OEgY+{ZB8zww8bI}p>j%lTFV7 "]R[m^@oתHஆPG YW7#Yl HheM_ G*,Z۪85r xұ`M(0\bL (ުKo7*惜]0Wtm-c,:O&16ȭEzVGF[Jj>exLt1 -G|Uw (3|A2[~>ÓSn83 shK3Myq=W2&Fo(- +Zh];Om{Ǖ8ϤbƋm`8m 'Y8jake%> Ԏƶ,lO0F$(L 5ä Ǥ^'_+JV4ƷG 9aq -ov |Mf1~m4nn5ݶרT#d4_3>:l"dƳiJ9 糭V 68_&K<bڒ%gGϓ*&N z_wj9|jrQQbq7 sR!k(tc~@dYؠ,B`ggB%FЃF1AR~aaGX^(L9ͣaM4jFrߜ X4Y jZ;%.^>uGgC0#;3'V(W74RHimU C- I7(J\މ g,oQrgnd3DWpuX{r_ԎJ3qgE E4jЇͨ]$g_zgB[@+im =Kqmȿ~=Ԙ%EQ(0 mc~gAV{ હ-Y ؂׍Mt|qS47,4oB!Ai͌J]ͣ­Dzӽ-eV?fm{j0ԇ ={SXX-fL3 -3P~,:h(,rlsIy&Bar-UƵ Ifo#)^ong58Sl1<&{P'3K2(sr*`^>h6߯5D^()`҈ҍpXFfUNTHe?|Sws)&"x&OGu1lѩ'vU Fwږx oBdr ̖ɥ5RKݔ1$T-f_eH<fKLfcWtVn;]E,K2w(`"&9kuU^=ܵ/>W1KهDtf;dQgrr\8^^V2jZ \QvPζqg1#\nLlzoOxG6]+63W O8~W#'[f5m2 m6Iq3R0GD>VBpO[88&B QzZb2aD_:bl\Oq|gwPefsEN.B+:Jm}!Y-F❨MSiw1 2 8׃wXKs{lR(F-u'r/TfsЕS_-Crx6h M R`~P8yYN9ϷWYޯZxjѦɥU]:R9V%F&'.[YB •ӵʴ|O]h8'.`ai q{Tq0'ނ0"@|jTdp5 }\Gآ8FgJ;w탋9~Ϋkmoe^fNCj)UO\X\94 nrnĝxCGAz'+Įqqd"40H(إyZ*? k-&$|k1EqaQ"uPhR3mrNeMMXejϰy~]Q@| cRD H*{N&?%jvM_wr\j`j>76E? cj|K?BCnvPI|^`',Ҧ:MITG|-x:DoZd0k_k PJl$ڨ6Ի7؟<ˆ{mw 9X AQt_3" -և`\G,b15G;'ɭ*) cgsǴMM샿dUQ]M\p9x2)?e惉Kpҏ_(?^tUIAsD3{!J2 y^|=|'8c[l #ڒ< zG=S,l7e|;tnq]L9lwdPly7IGVGLl45B7utR6Pr}: 8:Ikx?IqW[sr;.?5ᖨz6? 򡟦kgLy\n)ؼYQàLNh)Bc4ؑuu܅Gr0K:1n#WUYE.f-l!|m>g@EƼ NlSʸrf+`>ɋ/$GEWJ1wx3^ W\쑇{A-?B]SG 2mB3΋3Ҹi SSu Qǯv TFx8V<|LʙF;>%X h߉Dq! neߒύrOr"%-S5xz 0d[^ kq4q|x/g6 \1b֣v: aDmPQIsvwNB2>Aqj3MёE]H5j}⾧ibmyE%5NvԈY[ <ۦ+N9V3:HA|ЀͨOҘ„: +R@H*q;,LT]:4Š~DLG*$#*rŒO. 6&6zs,dYm5"GWWe4COy]kiKx&㏮tZ%I AD<\Ԇҽ˔(瑡S!$ "]LCIz=,ڭKpP:+f ?0TM >6a^'k&u_wՆNBq52v/ekXīBG +1y snR}]!ײs^eKt'- CihXǷ&ćTbEpdZk~*h71MrihƆR';sGlTN$/@iwejdo b-LΛ/8hw.%}`ΈFv9r Yz7ZdmUfV\أ9jPU=/:]{j@&V8GOLώWtN&,h9wA{X-"08i{ůMU\~ ,-Su#EwYI麩8wSly2gsNl>VsQXO{F)?$jJ&uWz4w+@Wdz.f0 |)3IuˤME 0>r`).D)K. i确a4b _|]0 _DQGI~K/.L13}PiB87Sz .p`x[Bg[A$"cj% =/Pa˅!]Ab˹E3+ `C['_T{N{b aDDDhr=0zZ;w M=R&V9x4҉u95.@zBvb&DW 6B[փ$i݁K7 y4k'j868=< _1k:؋4u|0 G4oGԵK!k J釖&o# evn룚ע"w+744 4$N<5`~0T\ov#.Xw;?7/^lDh נ|' X=(kȗDx\OWQL`8VBpșZ?RE0^8x4lA,+Y޸'.դ)b]Xm5CvӱbO0o_jP-OnhKD2X-?,F̦,˒78f[TR=sME#!@,rӓ]Yflrn,M TEăUyNڬ^8j%>QGbTj]n5*$E.5(yQGTIɾGsp=ԀьƝKrf*8U@ vbJ2{ܧӪt{]ֱuПx4HÖNK9A ~Hvo7٣ 3WIi ’2.$ԔI(9r=ǿγ8@=˜d= +Y9.#T/q;K?:F{з\W(JR5E.Z}TWnY'!>R;uU ƼӣGϷ .RE&+S qkUc.yߓۘ26yVKĆ{Y0`h]: 9|qL'q6-"8]um@6IVeCجH~e`l$H­If>vfF/ͭp+\@m/f5EM;GM;OZAT/JALc+&Z66!%,GP4v͖ܮq&621KFf V8$ꎵ1ծ 3 n'_XIĔw {5[*M*ƁU%P+ b^ŰW҆HmY 6)֮XC FJߎlu*_˯ ނws[{naqg @@U-dUY#>efJފ)==7Ґ4ah1j.X:dAr8W{#ԝٌ {G{TWNj_WcZ'BnjX[:{/m+Lm幀=l"_'שE\6[:4DžxtUK|0ъ碳<̴ 7 j!O1n,:\dO&ጽ_0\/ȽI2ۡ).Hu% #LRjOQۣ*p+$29[n[o$8 ֒K4Vm+_͆TI YBt/_~놔In[Y)sJ>N);@*3.֝iQnyB8X{/ /5bP 9BL)mQ2֣=YjlhY}݈7Z%٭.nkQ."]A{]qw//8W伄Z>.n<}gv#( R)FaҢvX|/T7}BG{,̗}5i.Qu&wg3Cc3Q6Zm4 C-^g/_TNsKauD]M_} yy>, mce_8K3φ9@7DK6:9T޺UENqc#PkLU1& H0bқg?ǛkBa(P~Z>16[xDs~f^ `h DLBT0JYE7S3wPǍN?8%w]3iaÒ}Gn8a磵LdOLFWQUحqUF tAWt/ְTpwE7˹J\ ڥ܂a rR+vw<}OK]nX;cx \qP^On˖evڬv2dVΰ`+>Oȗ{+֦8`11>FH ݛx(\WAvKi`uėit^QCQRKhssZ{[(_?c_ʹy<&Vi*&MERV d"0 cu].&udjPZ!aacJU&F]K /RZ}?JJ% !9SM,Ndֵg<]W.jtH e\!;J[>t:n1'2]!]}Bͧ oeBv4 xB1 VUZ.d=IgU^ݏoj̾k=FurpԪUJt}X) hG~X M @Kڷ*$y-Q^&g&;o$~4{,ԣⲦbɤ#l4diͰWe]-' ƘQ,ITv?Q~/zb5.ܟ$%fOA?>FuzW @s=? @Bc84 6aU$uZ߀}ƨ IO>ֽulw4x9~ı_ !\v{2o<<)bsa>#[9(ʰWE4,l-ܾj z ҲA'›l 5O}lB Myѧ&u.4SߓOXQNGFNEGZ\6Ϯ2Hؑx.ƤTf(_\P^`\젲.o^ șA‚.M6{̟{ =[*J9{s}Uq76li{/|ޓaVVP39tBtK FJ!g8& =~xQ-R gB&QW#ot^W <:f2v*|_v_%r%&@ӕIue f~ցِ%͋oS{4Gn;,|-ƨagK7,~Xe\4lujk)XKCT,y13Fк~+hI\ bG/شk5о}e$ [}wS Rtcqa-גy6un䱄<%fzO***Жg9Y7OjŬBc5RZ|]Sն0Lhjz'i8#%Om'd V)jH+1Se/zpJ'u 0TgkEىGS`ʙ߉DG*C@l=_X7#Ԃ+]?FT,;-Efg lΑ8wce+ ?(tKU ;l}'?k'CPq#D)J0(慌9 B9: Ԓ{;>=e/__ӞU5[I7h6o>vVQ 1񂟅O?壔4ga4q@N6Lgq]5zo.f+0tIgBĜCb# S!*yp},F]jM1_A ي7nt8A?6F,{:D/h]_ >I:"kq$%^-G1^aqJF9ET<=o$d@ _#g6EO.t] 3;(QLF^!&kT*ԳzUm e{k V06Z d%F=mnmh!]ozVB=n\7 !At%QOqM) (< Av HIv$dN/WI6G]M:}}@[qqlϝ>@QRÉsMwa_ոQ,ơ['|,}sip0y}:SqSqȦu$蔖?A8i~'ed>w2bwi.b9숞j=縋>8E H7P q 4\ #0kXsvrs&Tp\=#Pe3ëa#d-YylL_&~7C}0h`]FprFs9MT j,c5>ef,$Vq=kW2f܋#^,9F@=MLx m{  \4ODZ"Bj'pFD͇I4GHmzdKDW^²-TH5".8Kgя^`0b!-q #x^`d{$F.sOc؛OV=²p#K \x`i)G^$8 *vh9M>>Amyq+4iגXެ%)lf *"k1/CB4_ͲS(OQ(Na3@^s0=3yV1bCɏBoGEwTetTEMedm!kK'ro{#<"gH E?ͰRH+]])Y>,]n[.hig[](۪2&gY =k ZaVdC<@$!ՙF>xcԑ/ 'fS<"ua 2C]^5x!)Z [s:q}0/XUDwln'N_`" x{q,alV>̱&?TS3Xx{+>0n0wMNG=xv;ǮzX[./QZ VGX-ʠ!@;xjPIw3~ik.G]f[=b6Ҋ )<8^aPQ^=|OE[ΐDO Sx@|Qj00)>[͖MZ2Fg]eOnxUuCYխr-sMf^炞-lil>2)ߦh Y`}WVXͦFiӿN8DN[ŠGi%Vr@ ûWsĶ X_NXLX|8.ZdUƋ#x?t`^ğobb*?Z:E28.\Ab׋J@Xt;e }2LKe%L-W#o~,z;P;Dk/+ا0)Ob(,2&.'Ib]@ĪU)' u*cL+I6^fN&w/ք"uM.MGxY՘}G$` f͏e Cz@I2no+ele.nt^#d9xeuiL,vrh=0,ӷvf`? 0Ce >-JD66E0 0N>6wNLrg_N?t/^՘]3\ YoE<^`׎)׭F^,܇/i>E`R1ssÕE[KoA;Fʆ]㖳~#rC=hMOW \c}Z(֖y[ί.LͣgkëW68'gYMRg͇Rǵ?A]~N_@].aX՟PwMW.>3獇5\Ӑ'VhJWq2eзp:3$8)$J -1i =&_+cCܧO夎YՉ}7´^uODuVqڭ󳿭"`RڑqjybQJ]kbGܺ:2hB8lHٳ-K-i:v+( 1F :~E£!4-~$Ei43KvuN*onV@t4HBOcz(u!0ā󣍟Tg՜W" 9*riGmZvd_pReSLJjwpnXdQרO(ılp`uT?CJ@}!ϾEʖM%꧄+wF i/wzT _]#Ge2҅ Rol-ҔP'(iK?Ꚏ#aغyTrnhf._'s#l'Փ(o7KyMulYjDј&.e[B a߱.ott;~ɍfmR:aဪеa-4D;}uѠ"pqɼMy#j}4mdr1KNE((|%4ncey9j*; Ceeޙ/ʖihmhjk&3̾ H v Y7JGXaZ{Z9S_'1M4v_ (Am/`RA. Bn$2~rG{ٴ ֡Eu<]m5(&k{ώ}#9<>GJ CJ+)hNp_/<$/jr jsoZ;(cH'+_>{\.XlJ,jmJ6s G;8m(>q{ڞAX2X;ynuBnz\%#!㙼:jEŋ|:{{nyk&W6@ˑ|`5u/1,}k|.߱5zMBbp%:ai&aOؑ~?\mFq"Q9SZO>n~!L<ꮞI[{.c_`cުNܖRBÙGWo<{T65oآHO+ }T?g;ACz䜘б$Tr鼳a bVuڂ=q>^SQGؓw2yfY`f+?cBZB%0Sq4|H܋K1N{n:?;pKfoK^g pFbaNY(J1Uh ]bEɋL (1pʹ}H.kBW,f\ AZSףq3̝Qi(TUQ!R: $ <_Z0]ϲHaТIif vsT6m~j(iӊhSGa!XNph=& Fը܀xƟ+tKEUBO<馫|A;g/~#?ZewYhС+xQ9 ;Fv!ck@^B]a-BpfKYe`C (ڗӕmcg<@ѵt'jN_g ŕ#,`:;"@JtםV 4'q횝( RA2)[F >-i5mR:̊^Ju,56Y〫׫K4axr7]HGzs;I+E;W髱X[ptAa\Tjm%݂7&NzC:#lS+gڃP o`|{BN"0\2M[(~.?vj)K_ubIЈNDz'u+@E>V~#HkM ؋ep[M!'_v ن1''XRrS!1)oRږh$9carhP0ɹ@Ro|wѸ,ْw=V#n? 1>v 8:u .ԿSiFZA?^U{ / 6i :Jʵ .;B"&vW@聊}יy{/o#$bVGmiZtY*,ӁOmV'/.ZJzSyğLBlpE>x{6$<,vS n4MNwENO\ZG|X$TׄvY5\"b[ў06pU/3%((bއXums>> ihCj y؁ri>sUNHX g6_V)ՂIIo:J4X BW*(WyY8OXݗ{|R ^؞"< MJ Dn݌ɠM˞,X08kK^ RN" =6yL72-Ⅺ:S)&3e@z{Ƒ6 ,5~b,o+&֮`0`cЉn o/gIthQRx~پSKl&`M=E6$`HA={+EY<)x$cr*j+v~As| YH׆4LlO %[Sdq~|ZytHPOLP]X0ђB.`߀YMѤSUE^lu N!U.%<I|6ϯDsǻyp{t"Ƙ+fnm Єŏ TLtKV]WS.dFEL$j_eŽ|u2—*eom{0УMz<2c/,EJR#o](I, CYPw{NTˎJOOhU=\o+8~J-Ds 8Ru˜鰈i<&5gE0xsV/]XɝT6d=FyHbdoz2vbӾ,‘R WEBoP5q7"$eP.Va@3Vy%xELa@2gs,}ZѱY쇫PPg``-o} ʽnm)U;2oS*1x41 ޾ZxqGKDH7ʪ M؎Y׾Jzf]݇<_{ٝXd}>D)'Gd+ZNM G-A ==CVU7aP'oq¿@R%KQ*3 Fa˜;DRCjk {JySA}> _!@? ӰܰKnnֻ WG K(FMٴ1UUCJJL_ yNX1h$};$w }P Fob[>sUuqx CCT )0'B+;gzXA `KV(2cG=/44 ;+ÀG]3ClvU5R4/8/ KTNX?cL3-0q^ɪЅbakWwDZ\­ NBPۓ&3g5,H%2N=b+|6lvd;T9vfVk כ 7|#~$uKwW:OT5G tJl]E$ `W*-:b[DMP?Ҽ5x^_z錮mYF'XLP |eSEUOQNGΥ@dagʶ>L^`iڍgiW B WoT:q~ed4C?9)muyrnwKel@㳿r[d&N m-`?ĝzl|㘪%[B 0CՓBg_,YT=P8;mDjmǸk'7ĪiMcTL1M1h># Z7e:4<.%dxX!FHec=XU-oV;?̭mJ Hnv9y! kË'=(BEĠ(eMo'le1\ۗ}MHb~&gv|.Hڣ_ Ĩ9'&AOu]}9#H7O tRic`Rְ C}.g&Md80pMގ*m绛~u|*O%F{H,kӻ xMaz,%t tE|yrJr1䨱ւ AI+E,r! OCqOmQ'"O9u@c|WW=nbs>x=|)p}2/锪-J![aȃ(ptebpB j_D׫'5lou!o_ϲG"(U7Dam{/.Wx! h9ᗑO H!`H7䱉__mO}Zm ]`0z?5Ё#5GDMֻџz޶t'bzuh+'*_"v̤rJF,>W„ ӌL~:c9 "*ʚy\ۨcltLuši\[',%0x#)! )sp ݍiS?HP,Em%*wbЈ\US+bDklHkyRk7)i01u8NK$?DKJ蛗}|Ac#āI%!>><դ-pKSހ!oŅkbJXN1Iy1HdEZ=5{ߢ~$LYt5{v8yZh8 LTh+!%9qClKBL$4@._e4*许QDn!(EFƃ$=Wng_4w%KQ*;%k62e)RU!>P$~pY"дz\=Kt_"~|G$2baAyBj'м(=lg`z7!qu\ύּVABW"¨;4:p&B|/jtVWcyʬ8ɍ5iz dkǮCiW>dFѩxC /'7JƑ-ْYI$T["'(1#> Ӆ*q+ w2t8mQM !D`0TS~<-:1 G `Up}f7o5()W56wEk/ГnI!E"\j9%g5|u!1R /G߱nItv 3٨TE#[ yy$pc2i7%9 9YOOS4J)5,"G:Jp?j}m/\aOΚhILxb~"`-bamĸw:ߛ_sP,bڱw)pr$>ut5f&GH72\IR딙2P4L1n}E{*|M AAĥl+-bA6D!s.'km4罞mSΠT[t%m|йEv2v<nZbvpz PRl`R]~䫗]ES\{l?N2d^_kE[RR3Ƚl=n._6+(#=L]BIVtKޥ_~V,X$F!Υu ;cG[/ X D-߻@nsaVߚ< QJurj^; mdo2":( )tjm1>*^A)T`jnECh7'H3A` f!0iv1-ЋS6o6 x5 '\knbHLc_"/ji/Fiς@*MfTYAG [jHv*4swyWH};[I%P0de0m]K-`qatGDh_|ƪqz>RX0VjQtыuL;Dz.id{Vf8cDp%?І\IZ i}ѢcWDL5 A5YdzH VW8r";tQ_YazE/z( `&|; mW}kP ?A;]>C^+mqq\Wㅲ4#ORhCwSi-pj/(NɧKF KU8F&OƢsEYhO4A"?<"Z$IJ%'Mn)S6Az)H)nGu!DjA҉&cML*_k١D5b40%{*ѓ0*U AinM{mY_ĤhfS<6qBMe;X9OrS j"ȺQ,_3>܍~*|Ȕ;,Zmf<~n gÉ, Rw0Kv4-J svfeE}~SUԘOZ,xv%c%8BrqU滦VbIrwmZV?k?eaAjGCF_Gn.׎E_oBgK@5Xa~m&$2s(&n6_!B11GD~=Α o95K]s /VG;q }t~RۼQT>]2 !e m.#1 d ᢗz^A IS2 Nhg'C @ }a0SL$a9P΂8|rMXZU\PYкl@CϴW}=r.b3."f!_)QC:tu+JvW?Xz~3W+;OCjL 3zerj'{SƑoc\miQ[l6f>{%(, 1~RuhH{5ۗ$UWlVX=V.ÅmcίUrC₴]; vvF:d_2kuQ ڑug\xPU:A=r0(ykKgb4Zˣ6Sr0A4`ɟzMѱ# `-3X7Ľo Dކ,qg %N|g}6M_L-ЎH$ <$(T6pdrisMD: Eod@(nqt,h۷tH2B/K x0hv*wkET!~z1}8ŖnBHs a5)FE jPsxLM8&NdePk4 F=.q;] n`bylq‡ev̳;g|̆̕Y^ꐠw}6e`QSm~ "zׇ߽@2 b̍u ArddӰEwix7Cq_ЅAt?hNml>ך*<@'vIް~ D<QwD~NP\<ތ,9 s+"`I}B5@A@J+PͧD Q@+],!hg=>|Ԑ[;mjRfܽe0}v`byZrA]֒,9 }mz-#jgđm7j;%뵑mMt`b"YDl>3sW9hY$}:KZb1t%fYyÚaJT8 ẂT͞_JZkn`gzF^%adIU}^GiHb>#hqbbxAG'+ҁHQA?70g?J=Kwu5$ah4UYZ򥀜8S6t$unAi`3yp~f3$ 4\,l9skvIt ;vݿ-7x=d$'BB>Owhe{GFp;i5K!q1(9qqOY\r Y%ðI_A :>?vcka϶A^IreU/>:ulf3g"2;_iqN)D=z3?gT_" }ie:-$PC@Rf",F8׳h3le;iDhw=( 19idfB 4ط]=SH"a@w2IL5LTr{Qvy͕-]\eۧ+‘5P@̍\"rlAgTJY: U4å_#c?{]v,bhj7/K7b0T Y15X.?r%83{|(I3[g畾hHtQ<̧>Jѻ"LqiGG4RJCOK04)(t8\`I&9pzSޔp{k57Ӱ  [5)ZDT8ﭗ쌸z}N,'ds/E4Q?`A|tݚ% dYSg+'F\oXaR.֏24}XCsǂXR 2ilgeJӫ8X!NwhϕdOJHcT}WfZPq̸iX_:ģ'.SN9#kv` !zs34cWq wK4E&U0Z5k Kb(!RdWh2\Dqƃ)2SLЛm7j/2G]O,GGZO'+:H>4J&A͢QO}X&{LcnH9ÉQ3V[ov@rؽ%d0&!Z[3gS$Eޑ_q2UBK-yGAEI2]BvU ghS =$r4%)DDKR2; 6Ro}SCg8]"Y!`6;FZa\5ʨ~Qְ:fl&BCeVy5;5_BNo-ZW[ua 3Z+^]f0/.x2߿K]("1M(^։\Sa*q؜ޅuV).KPHS!p]xKе\#@x?s_>Z'pe&o DQlz5b(!>:D=:faҒ~ &y3foۀWgf'sLǢ| ԙΦ!jrFUŒ D'7 dBP,t\|a"БhtQ/"o 6 |:Ȱ󠘓{eZ &h'E t8Ҹ5 zPֱf~ 17f`bTm؈-ܦ/MH Wӟ"/R5Q5v։LK l|E9.S~hQj ݷ .+A쪠#iҳ?Rv}mfw Z`?L@D߂hdyF.-^p/v G}>N?c} =Q?cրuWgxͧZ,mRsLOx29VG')¼ ~4֥Z|z + LwR GJxϚP!\pkމ]/d!Td;I5RP}畓~jf>%d8=ئhIAԚ>PVv/uJ*؃A?_vqHf 74=AQX7Q~ƀrEv+OʩHȆ'}cNZMW_Ys ,,}b{"  *JpX0PZU`{թ|i3 u\1lgEOV˅W?g)z=kTzP[ޙR3FRz:R-[brQiߦ[0d7c_)hQ4r&D0Z ަRzi("1,NuWT4Z^B>cƭnVծKR p AvG&[ڟa7,pڥZB犝~IIos 7B J*@ ?@)SpG$2o/OE_\qPfs0a<+SCvwvi.7GnnFC*,rJS|q,A. K;M5bkt}*]/^+IpzK >)}P *{R;FW*kBEx4Ї~]{`Jj1 ib;wJUs[?Z]uqqӯӚ'n|y6} TT纠qOl,)w%Ȓa]6rru.ɮ=b7!.<:4 aYZ??=zAm܅ -׌4Vj ;SL<+ 싃 v}RKF`o_5G1Hh%sO|?Ul-T;W=ŰWw/.z=ۺ*. k9'x'_gB>^>gbOb,`}^rzoQKX[a@UYa%s1Z1jmOWYy8I/^ejc>^aF|P9j9oucУɶUSdcXpg2=dg/ǭ&haGcw03v$pڽַtsTv mcܻ P1c7-Q(c?Z.,E>=O,r1~Xcݍp5`{n֮OQvXlPIh"t}G b'㟱rŃM\2YnM'2~|HE &lI_Zh`փQ?1RDfݬWlnY|ĕ:ӈwpyr~c|de=-3CHcbkbؙ 07ȤNZZ% 5Dz 3~i`#Y :`OHeIY46 oA {+^Md(8>&kb/gS[Bp$[>UuiR֡/Ra#16>vģU껮l蚇.k)(o :ʂ2ULHO+ܝ` ]0VC1Ka" Y3.dN}:k+E9S`kdjȌ2K޿Žҽ)T3k׷%V| qNsQ/̕I5e6@WwC]uRtuFK-E\kU/mWU кݱضZ#n Q4Em"A>]$ۑn}㩉,헬 FG Q276Rbսć {#f{ojSPq sb1271iQp|o tn}{E`CHR] KNUIw*um8`Tu(A[DH1ek‹ Rew!+O#*فyxVɕg-{Lk?WZ hc^=Gאַl["kNGqm'َ 9`NK!"BݭY_dY^<`V/WZ6tOՖ aҡ%hƋr:hQNăhl~VݐPxזƨ4#G0ɝtj%*S`"hl/n; ałBʭ츄Pwa@v>c5s%UQ9#?4# ~!lԝ[l0i^(f&#mflw&SM؊wqo^x!YQ^)k;Qp+O9>M|SChKbQcW_SH(Lt8_r|cX,kknSXz\:SzW@@JlQKK6qxpnx@ Mrqy@ahXƂF7شU,SRHԘ,W#Ton/ !WXP'7@5^~}gZ6䰋'm[Y-ł:bW mz0jDt :(z@W!-~xJ`oCNii8c.K+iA7lJm:@?RA>~v=4Juwgd6@xlkq:ső!7)צ,Yc">qw2QpZ1AA\I)R{Ğ%nnj{x[u/9Opkn-5rhQ+ʁVԨᲸ`Q|uI- E_`T, e,{>6/g#d< OEyN~ӭϕONulLWʈb<d'.I<`0unjO:*䶌&e>r˒Q_z6dH/m"gie aCU=gRJ)Σk>~YP;X.עqF5w#\Pg (Yz۹TmY^zS nLl@e:`2%KLKӭs[o81d,(bWPE(_χΊ@V?{ #;e:!Aِ'~"8rLQ8)RK?XVT_EQZ- A3yv)G8Ş㪯x_t[I2% LlVx(:]ERFYHb@W[Gu TvZ ]E>CvgyhէUV_l-DCɮƩ(pDt͹$رatc;X~$;kg)^IJW?N?ab:6^.ppjBiʦS@-Vj3a%7i\1vwW\z_0wOG {3JXo=$2ߏDmL1IENɘU=v=Û:7[#Z^ ;哲ȭxx4p|R6%_kOxq^E< 0PkÄg'TXFL{.Gh(e)gPA6տUfiy'hqJ}/S=C׸ 9G  3n}rN;iǭOFys#LABM~nǯՠO™Zb+2`jfINgז;tL߾ܺbvG繮}9܍kбQ']hһdoWwB>LclrƮ2o-@xL7MճRs,Ha)Q*M0.:M7Sdmt} X]ߎfO} k<|OFW <&KXr_5T?n9Ɵ >X͉'_M N8yiDz,GY|mQLPz~6@mu}iX m1w--d;Z3C<ģV*kY#3J!)u.[rE>+YsjCrA0.4eLv.aa;,/≀ù Ǡ2VF^V4?xɸ/-H2x0AĀNbP+o0.|'j#j>~іc ?-l`|:n뼅\Be8 o?4Bq7~1R-Um.o҃Gut9?nlBrݜJ{ս~x@ZJcN fԐ:%SQծ6+ZrYd 7Ư㎗gb:tP R ZΟS ehim$`S]Ǥ7eP9 YMKi<^9EPn7gSNF@*iE Xi1Xehs+] zL!&8ћk[[Ndh,Vm2rb MGI-Q-0dφYܣ8h./ۦ̤k2QzjAXrU6.-wY@BYwhzQreC4PѺ,p/Ic/ /`l7ucBFl#wFt;m+ؓJPW)1:{cE?mƶuϫW`,Vov8a:LX"m 4!?'p* Ul7؟5H򌩥vWʝ|~A\wk [^K,#~N G'Ab iB w.wR/5hcuF \tVHet73G:#HX ]cV"f+-B08"Sepx# "XtO'.UA0(S%NA\4&ȷ洑ؖ#C=U?nRTтEϗf{Qn2t)iRET{8̣M(սT}mAǶs|s)^y,Sptwe} !y w5!W<w2&책k# ڪVcnK :ctphG-<@Ŵqgf!gkW鑤LvS@'~J5XkUGYx łnYA!oܻiRSNv-+a82*y9j*Q+nЏ`q_0r/~_\2 ~a"kޕ QYiG<,^u:f̖\뤷ǥk%4i6GCEh-)" kOʣQ-\-z1kV/uL|lf"+r̛t!urhVdՌx>]KJFL|!"0~ˈ J)2d i!BeYy%鑝ɡ@$gE)3R ~ތG @Q"C՞ x1em~# eZWMEJ|8~9@5 @ .%% T{r j8jl8[p6F.{(TBGAx Ⱦաߊ) uS]#oz:XvDd]1v@/8-%*/O o v6BWxC&5:O`/-aqnHEcry>-uHձU$]}Xdd[b/F xa(GH3)o:+Σ1.՟ 6HRU]9vA>uonn9m޿EϝbIVJ+AOv l EWߺ2ڦAezs^+X8t8 scAfqXj]7 k6OhX m tĈTz2Fiz @S,UANJ  ,6# aO;xrT<:iބ4{'m 'kMIyn8@2Vnq >jaExoR 8Ӡg~/>sJy+[ܣMwe C?NE O5>L0{3VIN\?v6S!MZ%\Cmqr1_^q9yX 2!x l6V:`C A>sK?5/aГ{&MmMZ4n~ɻwGn@SWЊØ,@f Dhzk_Kޏk,Z1Dz^^uBιaSVsAtԯac#{7AOyտWELmVP ikȺwv!nT=$arUF^c'ZSw#(]MAlɠxrv;ŋPbЕ~fΚVv#{c_}WD/6փ,ܟTgXmݬٍ+qalIR\ڌ}59 T@{qє!>8O:&U%/Zﯓ:0L+bZ8޸4`!UweI?]T+QS"\.z΁ҒriCӈw?^~hټf=Hq䷼aQJEc'VְH22b *iڀoO~Cg 6!~l 5đK-'I <1p:K_?lfx~[ncF3P ՁFv`Scbڊ9wٳ+1un8Zg8[wѶiVd:/˄XnHl(~X.k5>?+>618K-;hq ;!Ue&~|DA,-QE/R6CM^VtWk<{3]8 Rbrm0w]Go`t[t).d#gqrjfK 2 qxCqvTCW}*P='nO)Z ֬GsϳhP~ٴ47[d"j\--(@>dzAJi v䲆] @ߔK564H}Sjt,^xdj"{an}[ qyD;D@A~s03 .u DI9lVΜ$ȪIԯ9ޑ~' ]3v`BsmC!W9ޤZ$;+U&Kv6TvuHS+L6X9ן%tSH!Asz(|vp'> -ɞ!;o9x̽Űs~oo{CԃOUiS?0hNi-ʤl[m&L n2txK, <5- . T}8MtHr%lG+֪RWA'ǎЏpP3$Ʋ Ļ/AOCRiRDE=d?{+-^DZlyWth/T%+(ao*[.!tE(n/Rmt*uЊ$0yH'Jt"qCh\+m_8~Vm8xM#6#5C\ 5;صĪ9 )g*CJ5R'̪oܞr'_aA ~=+RaEbGK]Kdi>|RnSӢYAǦ<ybnMHsvDthZ!f';ϜWSjT!.]"y:_c͘?e"Gz-yL)]B<YBxDJ>C;K#p\*xaP&0%9Us[oph:ovvۚj=4;Gtg8w]E7t8EdSGA%'paOi]0a!NSz֩ZV~s]E()Qf9)sjy7pzlJ{:Q5N^ |mh8p ρݴˡmo6.2PJO}B-EaP{pL:u3DE?gO} ؁*Sif@!(=W+c" 3; ;P/-*Z׎x|;:>א?X ԭzFn)Er3O?KŞu&+g ɥ ۍe dwV.'~L/6O}Ҥ`Cd7~m ^|ܺ#J NA'Vc 0qk`j"$|⧪貂qP/{I-I9"#Hh~ϼIeC _'T5H %̽1bн,z Ւo$ס7αE^i QH@L*Ǐ)|+x:S_^5sLF :6|]b8S@@^D|}b[_nqtů]\/!?U?jMkUSGHɸʍ||MIT(]I(+ozac%K Έ9}xQh\9{X|YpToFXEd:lS@.ng7.|@͘R<S9`Gck(`k8JuYx}{AlB8<Lb[ ^uqX'+d>lּ,Ci욭ZNXqvJm?7wގn1X*pmא {wFDKX NH{#ԠB u}0'L-'UIz~3nvb"zĿIymS% k^}}y:R K9cO_KR7`Ŷy0 %.( gGCčׂ`}K'V`O!FAA7WLV0ZàtoMˬ7:37rd_~C%hh=*R:{. ؆PVy1P 80Jbl?$w/ 5Jղ 3֮Y ѷv>Ѿs=[:j1bN@"Cs}Q,=8UQOKriK5"%YUQIӶn?lyKZz`ST3u+MY7\R\\Zǣ&- H2Jr12̭Ӓ6?Aʡ?aLM2h3%i76!_R}\>tzh97ћRO> El! ssi-9 L߈j+ڽZf"VzXI ~(ܟ5~C.`:2Oߠsyl%qPvoR!?sB$XKZ:{\xA!\&[Z:^x8(!t쉣[HLb..9CJJe骕qݪ_W^[t}yeT:Ebv ?euX/cOD_oA`Gq&#HD?2ztWכj|yl^E) !+ـiMA2#1Vsqh+=s}RPNٜ~urG``K4ӃI\`'fwy}tҖ>˓tu%NGUP Hܹw\vCɀ⚪?|۽TEvN&I9&҈{,)'.J¢8Vvs[/R ĥǗ ՞G1N3<ߍX җvQhC;2H.\O:m#aL6#4Rbʾ(:sbeO-c9-ye 4m何@]/H9G [ W\ WJ &kY% P|[ON;a=s*svMflfgPe͒"M傃f^؇cΧE ' sα*a`v_Sɧ `*وc坻v q"CR5Qd$oo>n"eco}-F-Hua7HS i(ȝ1*4K9X,1s#g)6,Us˥U8V3!]| G߅-um)drVF)&Y `g~b`W{ӧ*Wub=iG<;q-}~1^%'{)ٍfvF_֖(ӣXcOE *s֐az wHf{1 Ki-ȜBsf*kFdYl؊%M/|bjR%N~ό:k6 {2n]vɽxJc`Qp/􅅪Zg7#*Y5!B)UJ.A햀5$F"[ϡvnA~BU1aQB.\c 3z{?bM `sXa6,g/F_a̎g~w~m-lO7]X`o-Ӌ]j<.IY(J`Le(Y3!/m6q}Z5GlR5gb_Y:ܜ!h-'_%]N8{gi1!$^yaJ <ڞCInv*fnjp^e0s_w#@aOmM7̑F P9TH^i)MI2YgT6=ݨ9krWfRѩz{7=c@Uxd,>a1h 3~ VF}--) 4&^$3 ~`Kw.Gj~bcc2`ҺoMa JSgGXֿHO͘ofi.p*Gq z.,юCaø-~\:M' ? *ʛj؀W6w] }W?"8P7ė)4`^3Hyy$K?j"JZ¹Rҹko"N5iݯShPbfCvt>oǞoC=@IÈkOkX8-~lu$*J"X$GͿfj$ W40jv9N& 7i6ח>6V ݪ )'pHn'wsB*{ݦepwZe{+ڧgOB.Ʋ.hy0 _8 a qKk8u#Ҥ VkhacƎkqVqzս5"fNT9"!+t"gR:"A9NwjNI%Wp@Zz#Mz~8H sĭ=eE00zD |;-04!hp Ǣ?E}͘%׻W'%#ٞG|]ڂ5BY<#R[to)nW@a|E9}?Yߐfzcy[*V+tVYfËf3\w=n0|iU<9LXOS]sBoD.`龞;2HoV3M ў>AhS׌KId]<mAnPPgoݺ;*{XғVϫhWW.=zCNOa":-p>y˟2uT*HaKa2}T?"ϴLX.}\M>Z 1 xGZÚ׵ZДţX7hÍ* PB1NTiC1Y|kE;R"YB+) 1[&x[WٮI-v&7Tȕ n({؀):^|RXz ('Pn׮j]WUZ!(~r=K*`fmF T[Ċ P-Ihj-bRT|t7Yxu,!Ra6 wnqwbbesMmZ.^abߤ.1wV݋Oοx-Tc#3mm A2Ɲ: . 5Hqz0P~] I#=?6&WaVwF5^Kx4Ep Ҍ1[3lTmTQ$]^{vd)jaa 9o#VH/YjvG:oD2y8:=xCj:MD>08` iQE ?vB(åHC(^ ZTDjnaHgdZ{S:o2KˡBKO;fDbYϢ{(5#Ɔtln0ɗPq Qdz "msq(L%~0u!MFvZ17R4# SA36\X|[%B1ck)h/A ;YF'w ;t0QV2az!87Sb4iLDS6 )U8.X@ [gn DfUet1>S99=2% Jh<,P0X/b2D (Z3~K9إnfU &Ļ$ 3Ki!kJycίiŢ5(3t-yz82YFV} &5$uS'ROMHE̔2ՃPH- ρ7@īb^$SkG ;%xԘ'7#t)ғ'(2zvò&c5(,['L w)IH >p¦]Q#TMCm+F i8ȼ ( ų^sm\&fiWL= %?[XT(mvOBaq6(@[/i5?|חg(! V߮kix16 YTfz6J*8h2-=p1ԑ:] B_$:ks_*X+[:yν; 84; 3"2 `?7i?;p mɍxv:MO1֮~Gk:(X7^fB*Kg['D.^v?.fXϽJ0=G\mˠހ=CtvG92О;od~^z+ Y"^栕^&ScU^t2b]`%.[j||jG|]P C @xj%"8V8HcD#|<] CgH?tvY\+b?#SRA4sZ0gxd: ʼ`n'o]lT2U DPF HQ;aus^ >5"i/C Ob<:mxx IT csBޫ{/JfdS:xqO&E.^ Zzv liy%17SM4,48+!V  'xDN m wш%8EOWF<.VAɞ\K[lck{}V/ -c9/|mx5]My{@u:0fF(oq:XLV~գZfeMwYwn'1C6].>C2ۀz+.gŧp5%|axAR2n%98h\DB@ zW6ƙ1N?NROe:OV4[;)noN *t:`|^PTL]?*dWVlp6#`oS!࿦~Z_`:!>XBfԳ-&xAg91eх\ހ^9C7Ջ#ST3##2n›ss@D9\Xk7! 7j맲 E-[0u* -3F⤏tUn򒃆ī'EzBT0xSy ңT!\Q}} VMj3WvcqGZcVg̵@S@i%%*JENIVjZrImifCweHJ245–E6d9L9󼂮~N8GU]l[ 0D3Pa>(=;Bf}SC]R0E/Pd`eiզ^1Yz2 /^`q_23Qr̙rku+.=@/PS4s3Wz=\~y'qJ_ȶF_"9u>T;(b] #?8(`}J22߀wTXY2E(l>~"O~*g}y9aeZ7a&Z@K{wП vf%g$3qd2z[|?a<_A;(M4ѬE*J X?pHᰖʩ'y{6D铸8Ix_ǐ3QO%L̰+qT~j6YFK&>WE;we7:.epB*d "Ȟ)850)ֿHhPoCw?WJS `"Nn0b,֕Au}0 -tٺMJp>&c9ͭ3 ~9wU3Y;lO7L&ٴpKz.vQAvry eg O{y8Q^')WNjd Xnn,SA)M+ ApyT% ʓ(:(= K- :m<Tl ZǯPsq".cT,'FŽ)9>/%|[m,)A/@P_4Ql!6 FQa/ZSހw6/M% (_o\d;郇ږJ|@r7 {m?6BrV^ 9_bBl=zaSI)*}%"mA)- ̻ݦ%lܕľELskEXH alO5`t@ ki x]Yi,3beIKrf ;k|\=Zz%Xj ݃4ڦnK. 1&أLjl5ϛ#W܏\<@&S!\˷2Y@-0GµX0trTǶZus:l}[Cp Bf} n3MJj.RϤ |hG*"%Sku)dʰB’i['7(dX4]0%YO/j#+ gFh~yoZ:Kg^*/b@ bNVӮ#]WjkBn} y:flB^ ׅ?~E} ,؉iAGGzZeOf# l90'jn.>Tt MMƗEޢ~$: {a-<渑i=Bh/?`DQZkksDN`#䈌IP ak:Oqls~S=czɐ5evAF(M*AuTj` lsFMlܶj&冟Ԕ I"V\Y`|ףț\rpYYBӅ#ጳ3|Y=N3֟Z<Rm <Q_UZl]G6Ah!>pIѷ'` B;'N(V5GuMRj ]%u7akAv(gRmaG\V>ҭ?>+˃OSZ㆘N6T1}h9uۻ{XQƟLge yvľ/TƷ_fիMWjb (p(s0p5G7u Ȭ\?%1];{zac@ l)>?ø* ͗TrH  1xa ) gא",'P[}oWb!G:ìdMG(P dB*0(,gw(G5;8 ]oNDY,iSt!O7~OT&MTS>!^"W'`wދg:PnDv=o:˴3)wf`3c|# &R]遤6B;6Kq+v:,Dq-5vC~bǸZt_ ];k[;gK`vJ/Zj.r/>л,m\n"y>݅WlܯBnMdNR]OLh_zŹ1` | "<%Śb7J!|4Tu BE?mo:LmSx:.eW\{"i:W=TʞaKz#KQbqrFЄ%-|ʒptr|}1Sƫ?_w-Ӹ"P!n ^Q u`Y*dTT)ЪЌaEp[2)]&]}~A٥Q*t \UTo)vqf&G^Xm:wQ0ww&| –l|FzaӣiҖiS;$Lڛo{6c̈́|cRyGLL4b9n˄un.<;`XV*P3d7T.s__L[~"1(ôxԁ0(E6^'~}^HjuYCi75ЩgEmFXlȈ?y,(#s"ߝ! &y5q#!i@B^Q;^H5*0aL e2GlV; 1)6O$A\MU%+8]4@Z9tK*MxV)2w ai`0z~<PQUXL~!R.Uo}H LꖨWX71T<';fr^lP7i#涐Ҋ/eہ=׵j/ZIQ756 it1TVw6(bsT&3c&^'k)2fE+_} ΂Ƨ"mٙ bUOIo,+ )EkO ӯ]G8Tӿl\W"9=F҂kTU[xq .m&KQB Pշo%ƜTOV|)$4,Eh.hpCpF& hg`|'bj$ӄ_{Afb,5LZwAob`]f]e HfOz}IMes7]a[" h>bp6>[1CmXi9A`+Gv/$ |D6p"7L|ulq15$E.G)ܸBKX~^}攽q!M^vK,y!W歑>;oLIG<.)F?\Gv#7 ͗L&OhJ඗Xk6TeNvݨ<.ȋ|] Fegt ꄞ4bEYD|?g8}I-pwwn=AfU#0CL/ h2`702𩰟5&*ӽ5DHPpVd]Ѵ6ʋG_͜'{  u!4]) r[=9 ZG羦$tyyΣḚĔo^)w HjeU ? \wq/@;] p~w bj"` =)Ӧg q\XoPEG͐nقmTb=zAL`qlDb7a͏=!6SMitc%ZD:h8# QS8g9 YXѳfo#9F:J W3} J}Po. GntχeqxR2=SJJMͥO@NDw^c'0{j=hmc5˰ҼR!:s.z^t.ʌ ygY۞ղh(mu;.zF!g$6͒N+FI4 djvd:yQKwF89l8o8:c1QͻZ|f7]F ĀC)EI٭;./vl= ~rpFKn4)pODȻF,WP0IWbzvVMi6gH˚׻bp3yZ[Š#H췓(CV9~ieh4!Or5U=U-/Pq.A ȻtN:@!1?JѰ1cxWlڥGX+:# @DN)G:esX`>WrV4<ٹv``֘IYNdVUEm o\jd`8H!.C?9)ğqSIwߎ~b,WpuS=ʍ@l:֔$ Rl&zaQ!:X&8m)9&f)Y=m"xEEs9^14ߗAs*2')sWfES[7+yFuZm*b (qM{K9Uca'Xƞ}bCC[%Tj#/FwÏ䚗L_En:HimqI8UaS7d $M(^uqRiq݉vNCegbŇ0.~Z>pg"<ώX7qosfoc7fmmwXaϳė+ ڔX8_B-Oڤ~2Xەakd"8Ff5/7bzD)dǠ VvaOk'ԘAQwSvHXl e bk 90ⰮpʍݔJž$w=ʭ*U.x+[OvKGst\܈;'^ ·gt凞:Ae1C: zIrqL&Gp7D]vPf}\j,1M^Mrgf7N!e(dP* 9H Ř!q3T_ζ V+jՀ5øS.n{vS$ۂzŜ\ PJ1VN3ODc?+u}9?O#%*p9,KA0!>I-0 ^  <\AabO*FtSrgx#vBy`鄛δ[x^tǯ 5VӜ4;H;&)k%36 2e;-=mDW$sX~cxf~]DlTz_Jͯ14BʚZ0 1u i``F0et"hu@S\~wGHRѦϯaLg(0ozYn=pҒC= q+>h0Z gG9ࣺ}Ubq*U"V= ۫IxxT2 k>ֻٿGQa_!=ܦoQbpQdJz>wqSi*6gԼh$+\H)a36umہ2V`F{ JO*j"P~^ؤhٸ2ndxfgAT" o)@'̦$g@=21QKQB lOjot҇DV'ʳYΒhLdGiA65ڳL ]w1m&Hm5z1 n!XQ6 _T ;BځxO;ȉU p(F boodgWJu%9=m'9: nC-/a<Lj<(.rr(M@&>\j۴?彗a4QR)[Yf6:-i\xjQ~lU\V<kNq &L 31.YPW\h;|<\+աߣԕPk*ә< FnցzDUh0 ;8M0Wa ] %gQ(#;2dJɁrY>tѝ l@ +LuLgT#0њ zѡf0 y!|Xk+1zKY9rT$|e:Ա*oUN76Ebh2dN+Q=MXH6*|Hƌx?I{jm>?N!įls3}2] _tB:{;/usg]J1Ԑ 9ձ # u,= }/ĝ:-lp $Rj,]0>88]D`iGlmPhG}?F)isu. *SMuxF%_Q `@aM1er#㉱ هGx#aD>j9'=HT sGFf!QjYkⶌ <,'S[CʙF+N="ͧܤ=6>b#ܳL5Js2&m7Rdm֢_l fyJ=h"c /[$F<n2l<$>Dg~ޛ\eei| ^Lbs4;["LsȳZ69O|^NkHa;l='moAak0lf>b/ <eNjd=rvH`&u;YTk7˩Ҥows8C321d+MW96rjB{f׷`yD! YuE?\Y?Mj_ޣl5e ͣuP }eP쑶mM]l$<|0$˜DVX]+ޘ$&Ia˯apW+2J[Q{!R}>ıb6gkSFZp?Ђݗ8_.6}1)q E<N5R??OA*\%9`ϕ8w}|3leꘃ2W6VuXe#4qٶnʮM00!ܸ:>ӕ$mz~L Utc_C~!|_t.#@IDEa&e(8ռU u0i1{r^V9h",I4ob1b^;B!=SY_Z-*9 D>_e6#g(/epU۸&LHN- ^o/fحS< MgR ğ3Κ @SfpR:֮~io4K؆V9q!m)Z7vK~?-50F?3$fGoM("~y}( ˕j]7QV<lusɘqRsĥ/8b&#46F)'z@^FHmOi#Oսk5NTnk[ =GD탚Gk;xnkiXnw}\ΎK˦ \`;8C-ͳ *ܠjNW0l'Az /~FP{ @oF'~& Y(p1#9vYUro.9-'$ Jrshj5"d\$yAZ~4?&Byp8  зv۵tKamO54]^<׽㵖'ܛ2>!B*M xdR's8H _Iձ]}\L0+BFDwe7Pˮ/9Eqt =3h 9:U,QC6kKlcux}+PKGdI0 BQmc8*"SØh 5k"#f/XKoO*4  *}A5 ~8[= 8$sĞ"~H~P)f4vvgjp yz8zXCop,C6N;՟Z Չ 5& {`VA]@_^Dc&m8D;k|-H|J"d]i!\~:D-y`'M/橅$(e"~He`*[5uӪੀ zɿS#Q SǸ\/ :~*5,Ԥl uӭbϚD'ή8@\Xu![Ek !uŷivg,Pxm.! Vm\|SOA@LJ5 -E2(Vd%?}eb$ϕ9}tuY9t0WT^_InL j,*jh G|l|\h 'jV-?6ښ"jtxCBB,PKjXްFNA*+XH0¡؛/&ޢd9 c#>~,hTuX ьIu*~֬ܚk"7C ]widH !Aw7C˖.n5sҕ{󊨯fAs܂6^eѡW#N ;6W ו327<[2U!hvǂOvse(赸519|.A38xdNrMi<4lb+6"*Ą~sEd5=$ӺxqOoH9I pwP^}/.0~Kݹ P^M(\@mP&Fu l-${4XLb[іO)`*.4cd@NjFhFbN==!D8l&Z|RUP WAl=GA !?~V}ȅ*aw%^b+жAH4㤡A ?'6s"b/Iç7 pc*i(h,:fL8om^?u:v?{.e|K3 -+%qNω4mrTR|;loD|AZW8܉9exd{Wu{"j2)'S)> 48q*5ϣp>Qfc?RT4eQLEE.7di?.۝ ; ~.Q~ d;,ǿJ9bhGZX9b +bBIC*f;YVBQ)]{@m+:w~WO&+LOgUԇafHjV5`..? Hϐ2]mMԊX!QUQFw3uڹc̗Pdrm}?·/V4ljO@z]+bUcDaC* #̶DSw Bd*RL;%FqQ}Yfi:9^[їM7٧[-j\MQ'#"^x350L)1TXmm =cZ1( P_BT àՊ#D\UјڮU.],'D@kO8:x[O=ꈘo,@e٦۝c0DՖ[05?q!@[d̞"[4'\Gb~Xq ! y^U2Z?lmR~Q2gBkOϩyTXmDJIJ@RgxXK6\qidס I.tb9n%qڬ͕ d!ߗ"ZOAv&XR$PMQ f/葜;[Exut~bǹ ѵTD¶L@FEg Yg{{Ǣ vꑔ#8Ye 4P`Io28\6/iV_1 w`\)h6&C{)!uYǪv= Z}>EsX%𴗺Yz 5DOd^lFj$_1*1PhDDHvUi;AuR`V90ls\-4ITs2)R`2=cŔZ*dҖǩ ,24NDMgԁq B"quįai<`p0%Ć[Acq-3袷"wC!Jq6s@<ý=k4+BF+孈XP;$p{}VgͤQW_ӻC%QRr%V G 22xg9/m/Kwj:{\*Ic(vJyUr80yXF ]^{mʠ18[gjR{>0kT1 F,j`u P\G'c5Μfm*J餼S~XgiszBgSP i>-uS~F9z-ZbI} 'Y8/F@D9qo9uu끥:6%@sEL9_SycȞs-Q,nU Zqc,cl'k6/w$y'00;%Z+ a+P At_Lp^ .u9,ВzbQ9%"n$Pə80nBz m7[xDլ: Oտ >IMBklL"ͯ9v~44JNԈc H\"RBEUHr:CMgPmO9zbUװbsm Y 2;āAQiܫ" g3XcdKe@= n Okڂ5]c-i|6֑`ŸȉYi &ワY״*zt 1ĶYFǚ1L}Z+HgԴHG5aϘExm(ψr xK J  w =/6IfAZ lO@ M~K+A6XHK;-? 8'\TФ6~k{}crg(')`+yxV;'&cOJm"BQXA&~₵haFWXEe'ǾKͦGK}62ŜjBo|KFŘ) >d0+X+p@d o(䭒:lnl]HL4!3tnK=yZVݔ$Wsٌ<7R3!dq.w}ir,1e?Cè;7*uH"ybx.`sX=UP3y&M?(Vczkgk/pHU:D mQ7(8 Ҥq~ oQ} KvP!E)XE+++D~fcg?Ve)GA=e::)[XFSra2EAM!X3s&}L]nZR[m;*:/?ss{]o΂TJ *i`*"mV-:<0-]! sH+Ѫ>u |N֑5J/.GvGcvh5cl d2kZ2j2ԩI}.2s?7fn6U_z,)&L,cE)ؤ.f|ڶ+oK M(Z.#cn+t0_&̀Tj| pgԘfZ"Z(2pf f6U4wA?Is=⍇mʥ2V.dyq=e$'atr#"3s'ޣE:rGAo}D3)Ah|K+NRԒoG)[{Ww B1+3OΟXf1 . zyWm9iVܠ7NIȳ8,XCl&l;Rj"z>l*Cނ5,wZD9i^7P9,Ӆwf~4;҄: tC!e߅2& žlB;saNq:*Z bp*_E'ҽa_ϵ7)~oS@uh KHKU>Ჶ`_bhm^4lۇ 6C:IТ!!.yEqf0㬠H@~e+Q!ۚ {΢LD_V규zUu^nf_w1qe:=A 黧),aURo #d!@)e?xXڐd(#9^ }VE3o}~ÐӂnXo[Nk(y;)/ΊUD)QK (>,g:Ν',iL- Fyyߏέd]1JBUr:Y:.h-Н,ozFL;@?&Hom:d_<ڏ@FT'K\7l9oW-jJKic /gpƕ0?, :]op{\)nJ;#a^0-ͅ!U,ÔuW>!R*,ٟVg4UICk$ 5~PH .}-q)BzWd[lt^򁈘XLW䈶D?dSaEuH<Ƙ(5 nSHVW^K2 $0'} I?~zB* 6w {f;'Fٕ($1u=Kl)k^"Cl)FH#J&U: ]}8UvN$62v@6CkcUtJ AKEB'jwL>RK"hзʤgg^AμBJIgB}؊!eb-/ `cŸB~8O)3γ?)hn[鬫ÀS,30rXA5n[IqfBtDA Tb)DY{҂Vzrѷ#$l#kSmཅ(cF=?F.F!:NVdZMbV>,OnȾ}KG:^4F$DE_g j -wxNh/I^zzAi˳`տ[/H~Xv$/'y*ĺL)q!;8~?Ppi:S%=!~j#]sa{SQ<;+ݴm0'pګVX~w@T2K߼V- ѩ&lIVŁ[϶]OYzW Yh Klvwq] _Z*ٿ#}X0Gu]6H/X䕆|wͪ(VRPpS Tu$,zL(wN14ǵNz*hm4!i_DMFǃ45iޭdTݱOx;u̓Q:sE0SDrqQi|iqؗ}S -R,~cəo{ M@3eV|벶T!Q.q9_5>[Q߼v^g'qa[QVH Z%:<;h[PIO{g֛h%җH0ݥR{lP{tOR b2hIL m4!cfF]Xsy<7SfCk2񒧥^~9O{ᡅ 0EyaChY[ES<#>eLng}qpBS"ztڗ4:r+.#)<3x,>t\`:l?ZQ(ɐ$q#:lxGÿ%)uY ZgjWɓL}t,4/淉ZVnή-Є8QK"`3M"\wQHOYR}tË8]H>_l|G䶗m0pZ`h"շ(7o [JbF\mp h!Qð@g 9 =G{0^,yf ɑl tLWU&8{9-mkfs\,oS~t#JPUk{c&lc| 1 OA /~f-н!LUG5Wыq<76#n7L}- SxH%7 QN/cVi28\nK lXj ȉD `Ptn̑/kW̊E>CÉ%K?d_T+M7D4/BDM{$x0=^pvw"r>\-1K1!B&e^?fF -{-NwA~(-vkԠӝb6~YZк(5mҶ)VxmPxC%ت7`fQIP-1|1v1z}c6P ߰.r;OS`=lBeY2],I~ubhz?X6b艪3$ϒ3S镧 v VA/p0qDE9 &%[1vbx 9kڴߋ[q7-]C‰OPE0^\rBuɠ2Eƾ?>56y*Y%GsʿY0j,tEP03g_99-UKt<wc}K8u;da>@Y,L0;2+*M`LI>JN b[ {Q OQzxS5B͏xH޲KR! ~xZ2C$+w;>nM>׬ AH8)r*N f7O*N  ЫCE DIpM2c6zQգ^"{zo@G/ﴕY:N'kq 8dZ`W9CO}P{+Q"׈8hCmX#MDȓ8,ZSK,L@KXbNw,!lBMve+VyrNtc50p[l*5v*dTjH{R^ٔGq?ˮWWb#F0Ϙ>yj.&m/au f{s jxb_pbs>faw ƄW(Փ ^DaN{0xEe$W"V--vYՌ hj#jXeP~\( ҫ V ;0IUd2Z#j3巁(Ћ_ѨB`UJgc g޸=of889Lҷ ^UO佁A'/nryVEK# ͉6jr|+VguH'WKI* efS_m Q.7 j4\z6Z/$YW;O |;OlMFmi=07Lz4@f$/|fI i jV 0f:qIp)nja"BW(i4k:0jDbrJ{%DM'l M5>&<{GИ[ Ȕo+ݰkkDE#Cҟ7W\3eX2Sųc!JHZLKqYymvaBrG n@;BD#[onhQ2g RZ(xRJ+O=jjTځ:#58bNd]F#F7" WP^FE|w)bxƛI1kCT)uDAjߒ;b4R jfz4v$<1eƿBWP7URp=xB-3 T+İ 8LGVl.pd˹gbϸ[H k? 5zs‹5AW+Ci{Q'BIqP~y@+<=].v Fyҧ_{"HCC󔃤oQyd܊vH|JFOdְ9 !{Cp]~ܑt&JC ,Cj 6.\K=2<9c?ڵwOR k̀ /.隼pȻ;ST<]N|pI|Kd grdH?c^"{1]0tJ' X[ܦA;gc:Y<83YUHלcR]*$R=OGkث[n.љABl˖qwdOȿk**S LQr~FY9Gi_~ VFEZ==m}F6e$]W_˓Đ*uP#'k;o9/ o6[ㅭ*c )o$02}:)P’Vğ-0]4@5ӄAc6Mװq? Xp8yv8ޥ`pEDN!0ms # 9C8G=FHlM?Y!+LĚ єá<0vna7C~md ¿ycW  ZdߑNX]I}frU$u?@*չ+2gWBp2?Omz# _8d:ipғpimVWL4?ȁp}%`X>(-z¨*RH6K~<^L)FiiBpS=M]Tx甯 {kqˋo۹1{4`9(% O;N,dnnkbdlX26t\C>L qŕ:ϞDpiѦ,$M#o}*7 a8H^tw 14ȉ f S)3%@7Ӆ8"Z\Ey8 W:db`*q9W6(GO7SfG4 l~[[p*;ɕƶɴ svk!cUaJl/]o3c;W[ǥ<LOM]uH<ldag_zC˂)< 3;4dKN(#%>}6ȏɪI2ˑ'Ԅk;q`!p| :k' mozYՠvKG1fmHNoEP<| c(TA}eֲ >]ľ5|ο=ח:&V^?rAldAf`CLpRz&^~F_?-9qRUGR g*tv$Zʔ_Ŷ.|1% G%?f8ÚN6lv*VضltfP"/lhJiH;n1ZtFk,Z Q1[cKr3Y Ij+ TZ͐: h1{K{ͣUF5j=#'Pe. Eh?4߽ܡyrOSOh'Jv:aow ng!P8{Zfʲ Ȉe jHt\}:/n&ʇZc܅: Wb did[{P: ~erA1!N^ޣT:%I8QI㐝dC&`{싑fZ咊q βvQPŃρr <Z qТMQ2M ڤS1 A`pN؍c^ 'eEA@Y]CA,v*|(?^8ЈLؼruۙGu"E&MmJr $Mx9f@SuGbv mՋNFuWR%}ܩvVmC"+]pS3 ӓ5CwPQ~*M[CΜTo,'QNtd)Xsm׸bXv\ɡ8I%+[!&nnMqשϔF4gt `!{`[&'8X4WTכ׷hEf$_~ɠʅ&3s4(Q)"DJ Ƅ#|T 468Gq{tb3]QK&?\?i%DOMWqmv#4OwMPc3@|oR1qλOb/J!#]AM9{]63w[n|`6]:+T)nHy0Jԓ{mG)#=䂲 i*N0G}^4 &9T=WҴӍ\N-jrlD\`n3dY׋h?Ӷ!?yXnJ0F};EeSH]0ɬ.@6+e*%Oi;ku  ?ƿTsUdlʘKcc0wh()WkfF{=1?B8ngɏn#IWOϧ  7 #5%KӐT88ҙ7P =HhX[kvTW܎ңz4mSb| b6L߀:/n@7K /0.wъ%S< m_ ypŇ,I*A(WG0nhl?u?`,=8<ЭTq_ C?nw4` w״|cEV?h]G*ea0oXwl%.ۆE=-Lyntn6,' &c&OؖRz6pQ"5MfϬiD( bgr$RG*S]*(͞w 71ɣE0j/$ =lx[g reiN#Z~q{β=7qVCӷ u3hKBU5E(̬{^ ;:mTzg!ؠqY1{/9mu3f:)ǻ.LD.[Uk)Q[o !j=@YzJ(=Rqn`عZ?]R{Cu4/ _'r}A3/2Ā:p=rO/Xaivq3|hF+DU(FW&fCG uat5FORx%y.ɬEnd9evsW)‰F d%r>gxwOI' YU!}QVa,?{Β%2,řSd&:)?EL5= <\HwJX VS Y2i 8>r)&Fw8*;AS|S]>`eX%6S7m'9`Jf+o#Pev2{\}|(hЏܸtq VMH3o;{rld?"2O]MYۇx!tt `~E}UXDzQRLpj ;=mCVwbBd[E8q,&zA;=;7)OeymB-z53hg̬|:G1 E +/Xxw_?oQgD7z؍ A#Pn(Y dst0-y4=>ȯ[$t`ug,GBc7ꣀUjKR T𔳘u5=h:FR.P6Nrgf~.o Lf(ta7/ӧzGtelf#&F-:͙4/y4.dp[@ۻY6d|* Yt ,Vm*۲}׮qLcT'Q<}n#Ȋzj+WP?!lB8 E9R -ҳz9hKn}`bڎB#'j lj72T@g{rW ąBN|W*c6O+gHtㅻyv v}.\XǍT%SBN>ԪNբkav.ŬU~Ϯ~zv#~$wAÓ.#vPH#7,bdKV} (dacNo{^H8Lz7 ]j"" -"ͻq2.-I>Z!R{HCęJ[ޥA5hef 01-ۗ?ъ]eT}9. DuǀYz$uBG~UB*D?zS9 ;QXzF!_ܺͤ^󑌦:O8Yc̥S ⽆|)DB ! ξnlȣ%F\<6e[#Z++7#Dlbuu9eŚj@-ϭg|R/TNm,m-wDn"OheM(vI=t6 RGYn%#cAzAAWtBEuGwo ZUH5{F@gLMsl1Dw[yȞ@k nuO WnF5YuT%O_хg[A}mݱzK_Vzσ2XKJ(vX IHB̏wZ0KTQSb9!pzJjHڇʥ\g3A=& t`Zг>Lhnh}EL(dVhڹ` P۫2]COlX8"c,e:iqb8(S4+M"c ~0]@ZZ%|44P=>rsD֭M֯>H04^Rʨ p/xbu'2wv@uWR$z.\PoWxܪd1.) [ZN4gݺdx>AQ2 +JQ9_gm$>J p&_&")?V*hcG7̳;:_e:" >d tʻ)LѐE_Bz $L1h kES ^z>Z lEbjA^*%RF:%zާqN2 $#)H\:߻4Ghɩ->uKZM-QyBID1RFq(ndjUά6 ȸvX<O%7&d(³rF4mX);^&hnzV48V3"w?50>50+#3=Æ|cEZGHr?؇>64LmA\UhٲTJY2']1~ ̻bfwo`~YB͌~s7sCyC={h>6C3%\[/d<;``@leDYC?Vm6+U\ѻ5iq';.Q $0ޠ7";) =]K%XFeFSE[48&1,u@ Y"fWoT1 g UBr24 sX#&o\]oEoDEF_*4"7!iB,c1YPIT pE}Q#us߰qe!DW ]b287YqSfqzKHxfNC{<;īJ8߮!AHbir @;OmѻZO0=ɠSwJ5AZ7GNU>.BqEۅȰw_ !R uG[Ho6]%1s7 ?.srv~E0v]q13%d8yIJFˬJG`D~RY'o~1?tv/,^\aR2 4 U~ٽOZjg117tC9W,`F/mcr䟦' G3LD`-"ccRvj]76NVŜ{:?U"wYHJG-2,dUTF4)V VwVm?MYY;j15 РգeDıTrW˰?CU8l CQ ;Aأ!f'XiEs@{#'ol8 r(TI6oǦb ח*HZ.tps@$:qRg:_󶹨w<ZϿ>s䎽# |FWS ڵ֘bwnWN90! ~pD %NayTWUu@MPHb9ȨT|ފ9h K,M0(Bؖ7MX&CᵕşH+pURn%>x4{O:lB'{H_ǐ%XB7IGdPFشxLu~ Wdzmbd= ^VJ>?טwƹ%7Nl_NuA?aD+8D@#Md{,s BB\w8P,x;%c~ˣmNgr|Hv677బ4gwA^Vph+$_<P>%:5x3zaEɈm-,beߨbmXd` ۙCNIVݟ{jͯ}bwB7p c(ITG(joq awD'kb<ڢeL#9K' ^8rx%3N,fq{o+mq&Wcr1̗&",K⵰fVȢaZğh(LyOr&z,Efѣa5;@n\r7l9ΠJx ^, ɗ,|ͳoJԎ$~GE.(&[B.NjbTKiRbHY%3:!k742B>BFm€ ydzCO[ uYj9'(F]#]GHB%wڐǸb4qw{s !9rNF}dԜt68-@;V])]9ԏ>ͰѪ{ydUhE~ڈD`*'_=}'jU?^V\[ $5)`,UϋM3>c±5#Q܇e䉅xAy#"vumBn|Or|})nW#ҟd% i()9a!UBO%Fv _ʽ" : a8{Zzg뙹u|e&./J`Zf_:y:e. DHIezUuKl|qy_}{ "Sįj[<V<[S (=Q4hLc.qiħes ^:!M&7x4&zj_S*b~ w` j/Lи-n"j\׳6JKٷN'^IR}9"I.|Ї$Cs{KoKQ*i N1Jϙ.R=[K+l;mM8 <ܪ3.|Q-,INׇ]^Ì({k S> M{ ]X%t0DdL 7~S|yC2ΥH1"QA3ShƕĈ0aG?`5x۩\J iYX+:3^>rAsfQT:k_2)7cQ1S֫nY_AP، T㯭KkUS!el"PM "p{.;ot?_1) $~nĚAS֯tb=u=\=$}}9h/wP&.H 7#"l ;.yQ}X 6o K3k[ҁr#9l[Nޕu9f79 Lr"H ~İD/K&BJjv,>ePG>vehs=7S0yr᝚,`K ,KRњOG#.Ś xp|9$uq;,:gޓin;\[![U2CWt#٣BY\@q l!O3`k{CAI2!_Co$M:׹(ww lY&rF2)(ګlY1vI|.f T瞑cW8jVb]i}ͱK&Y! ez W-}ɊmT䩔<<(qhQAcA-lv̇ 8)4&8 ,:*ydt>(jQN3Vlwf0gav))"K3™ʒYݦυmǝX?xf⽾u).O~ Fsgf8JLGq(eh8KB{y'P= pznT&EoLh! `'0g$F&gFضM=m2 yB{`Kh7nULـ¤W{ K?ifDM! / Q$S֘7o4;e+] V?T/DHJ 㦅RR5 m7=M>Qun-ْ噏Gb.vf@^$)bj3Z?O'ltҸC#ri-cEn ,_o-_,2(&m~N- ~1C̢>Ljy1E ?MKwhUSA9ulrloɖ~UT7|XjLS75Uo?]IM):(նn;hF2+eK蟝Q'ȣɫPRʚ&և_T@!A9Dݣ mp{}}dc+U/jSV_D?L]_?V83%Iƀ)AHj+$ s2> 0Tpzvci$>J9"z+-w~jH3Мg] 0YIHl(M|Nr ڄBT +Q6rh!.-\b#,od9BoCiY^SzJ{H~<r_vE5(+%2>AnAj tX ANXgTpHy%ҶsAGM;,԰R{<>HNK;7y3;2$:͐? Rմ7N>mdٝ6*f"{|Jl۲4{1{xS 7'Y(] D?Gbp.ԖݡP<dtԎGjwYm$BIC= 5v$@N~w45ӇgH|6Sga>YzGGKNr ߋxť`vb¥ f[+ M7-Li{FmJ=3҄"TmxUapqM1S(SXo .zY¼,ްn_sIo5ċۆHBiZ20f_ rgt \+K(#kroӷ\V)XQs&1T k5Rx-»[81Ay5-,543|u7?o~[c>ku@jL-$@Zljh56 h=B@nC .PwFA;H0LmpD( m<:uIBil:%}ΪqG)\B>f?NBұ)9Ͳ}ÇSAXzvo|J,`};gN7}쒺+B12w]輽a+utMZ iK`YO%6qw!5ڵ0}!3ZR!W纭Ψ8)XTrZvj.*nQB@fGO@s&5d%$u{kцXAV,zK&v Xn=D+iF.Ś?eU%TQ.JT\!qz@4Lp@@R}[O'D #@-N:Fu5h-h|t~ VW;IP^ly^ߞ5 I V9é[J}]G&Xv"/fY(PlsOxLdzL,j$-:k"~sq=#tgXuO*V(L<3唍]ZH.v\ SqcD48 D:#i0&SMY\#NN$d 5It)3~tH&KlmqD8 {Wb 6aJB AWRSrP_)TmtM{u/'IͶA%?B-BKeK9DgLe > [::1ߑ\:/ &KZ3Vy{Hp*.^xCH4 oGCؓz)kՊv`+t x`3%7 &߇%c {%. }2E0i o%K;Ix'A !!qqLeugGQc~TuC;#Hwn 4 0Op@2TQ !9=q*Äk:@` +:P'S5X87~!G&F؄ӍF o#ǪCX `^3GS%[`kbaQzGe:FN桀VW}YzR{_ 9|d Z5GH燅S8bD+fa68k;~񬳉hBEMK֐Q󅌰@R[쎌!^E b'c E[E`g@z9no5ݦQHgVcwexE۹_zKNi6%U뷛,1K؞ۻ%-L RkJ8aakc6DA <2(4{Oudd|B"y@=2C?Nk:I^ڣPItU wGW'Ĵ$5r.rDS$NXE42 Hv30 >%ۃy,Zfzm ʪ@',?_Ѳmә`tNqNK.kbNEMSZ}:sHl>KH{/!S2>^StđM /["]tauImɓo3$!/vKU37JEQ %#Ql_WeS7`iF=Da^Ss_F5-NGlT.Jd͞Iߢ[]GG}R͛lFk2"~lyf h[5^md._f2]d@5 <_2zͦ5D~,6ł4>]@eaosby7X<,NE#}:-">zWX}@X;FQZWRCM|q <44B5%|>F-;nwgmyN/STNrcV,nzƲRbxԍc?nEqalwq稹߆jZDegk hmT',(F_E=;4<Fj !sEqT3cS̻>1  eLIZxsK"6ADIXQUS~B3(h0Bv="8mJ&ÕJ.ѥ}ޜ_P~W1nG=IH: VgfA?ƫ DE]6 uB*W0w?P lt}TYnc\:(MLϨdNf'o{le0IvoެaW}b E#\{_z1Ɋ"0^A iD(3)ehIxUF] FI rqZJA9)Gz"qx8+Nᅠ63? :mxea1ʀH(f[qmHъ&|]/'nT` f` \H`s;֕ĕ,( "nܛWVfet" %4F"pUd>qԍF ? A6 PڷR1tЖa}TzM4mqꥺӌS~=0m8T誗aղe&R3}9GdKQN)QWا؋DLŏr\P@8 1rIP]j[LzrGf㈕d#ȧrQQV}I|x9]tT]b`xCrqZnLMS~9Q.0p pcD8ͥdݯ#u.@7,1d5ޓc[}PeJӬ:+$[Ǒ^DSn $lXP2缭]$rYߡW =MNORTŪ[%`+A~dłt fT}OC4 ץFH?p7wxnU:;a _FGI85f!ҧ•˻5s-x<(d.Rz>m1ڨivQӧ?34kKKprGRfDU5QU|'L{']bKDšy* 4g>pRr#nt f 9)iOE[2Za ӔDUSVtщY<*ܲε qe¸t0TYNY@ZgVv|`_ee>=PC-0U; ]7 @0Cy .^%cXEާX#P|[c`%+OPTnj]p2gR*ԇ뎂Y7)ß8_xv6Bté_ۯgBhT3ܺS;r3,ΫwrI4 0]U,%R?=;=jx]A)ĸSh:Qtvt PÛehwstNGcPX,*e0 'jBTHjxq0TfЯ !́>QBSlpT6[VHwuS @rUf\ t'''+xT.)ܙ6f[BUƥ.0eݎ/3r9CD +60p6|úXBX|(7g] w|BgsK+/wG /!|g+|ٻg:Ra92"v]ɉ90"v˦3R&l_ܴYES2^W[OuEz|\Ġ>zt)RQ҄s[ABWxwʞ- Ado m W.\s -ӻK@hBg0|T!o}o.]hb)YCX:cI]+sQ$22ϵoNh}>@Dg/+עP։%3傾؋Q29§]Ot;caĭkv8`'B)R$e3J~kwK2eب E:HZYn4Z$l^j^ؕU4fZ"2.j`i=^`q'IS}7 ۧLܖYkIj$c/ISMJj5OfE~Wf[XOo9(T"h|W9@pcK-yn(Z$5k oVb@_ JF3}:}[gaTS r eȚ96֋Aac4Qv|/,~&(#y&`=ka_础 `l(\!vpi꠴_s(k 2:syAE:)omDh@&sZD\ =Ago]l.Ȕg,vB}%ݐq&p8ӳ`vteJu) { 0F0hd>*!i,d3'A,׀A% ik~R(݄ڊ_E+o-´rx 92ի2ܧPaN'(BIę^r".~c Ze+nN_-nU F9q"TMc()*}# *CFH}-3Dw;f]e-ʶO`;8ڌnAͅjR7Y2w%A3'bOi ڻ0p*?PkU] ¬b*B?8*%^|`:nDI}%y97ΥURt}'wtnŇ#7虢,xrEjf`ȳ!ږwm 'c[%Wa \y͘fŽ fjpQ;i#[xL3s̬4w3kwZW|I}Fon*΁4Am ި\Y{?QyM T An}Lk,t|x3WpSNN<KQGE<ž[9 ĞD 2YW;7azx5˘tH7ZhIeIf*wPX^| n9o1hbY0iOkGe\r.rM֘ѓAys C[%|w1Ӄg; bpOo@+'_CTGtW=M#"PUU!JJWzb{ZGd*4Jc$W]^G+Z!n$))=W}N"Y'Dj0m"8>&6V4^ 2jQA6eߛ ~Ql}j Ƥ vAa& ݨ{Cg5FbTYdEs>[0a/dd^i֟sJOe,k=k'#gPQKwYk<nSLiTr:H,$e-8GaY$ZFeCYG+:S &qwⴥ X|2t&(x7VjBê Ys4g%Us*wwRdݛ0:'G*H"Se7vV:HT>S5`R^)\_מ? ŕGԺड PB~Gݸ\ c̑ Bdoo`f$3\2͢~@c*7Jpkn_2u uBP}w~7Gmm, rX~"bXJ} ąZB#6ĖʘZ'HkH  Zق,EՔd 496>/ۺGHLH8^c1򛋖^&3i.8z2XWW[xLP8Ro:U"2d㓆.!ZĉwXgP杞kњ155_9"H0j\BRy ]'(,]~If7tCR,T5V'rX 37 0пV@Fo&^"峙o5f_PN/y{ uSz^3~aRT9KOn*:/{ԌSkg/z7mfL[h>q M0cR&xF GRhirZw}.g-|2$ Tiч$GlȠ22){_df$io֞c؀^VRW{^LSwPA3njOZSŽ ouy3hrlFt&ѫuU{lP$][AyI[^Q2_֢Lh3ڌ(FZN(MA?ᴊ=fdӤ9sRL!pG@dl)d3(|hu,GGgL+OseƖܝU[l*P%+gDdUbO@];-"+ l0([#1 x9$,O1_:u9@$aĎ78|7liXiPג ^u!=Kޚ\ A0-{M=/12t%36^(5Wۏ8+5`WOBw̚:ba=0\f{i`>%uVbͫ[tŖ#TB$ y\Sۅ+B' )>څvbu_2x˫oG Ī`ɪ6QӾ2Wo%լ5_~UV:,fjCV7o~BuB W" fA›|~0-1Bzxq΢FS~^Npr(;AhP enB%"'WO& ǓK;wĖڗ 2/iQaݳ;֑~(aA`&)+*@R7nfVtD,dNoy,cK"A;l1Cf+#2CeG0VyE4]quW9 ;)z30qVz.cF};g_/t\!Iqx"nX?hXefuͻnâ9LKdX%wh+)o=`̕:"lU36AJ,D3(fg܃֬FEx?!`d8x^sffSVW|{x@Y)ʼn6Z~*^[ I@l+}@(zp >w+kc2r%VCez-Cg10N{,kqgϚD*x1JxALFfU:!X;P|{ݢ˥PXOk *6TG0H|iKxi^E/)BM)r1 6.xx,B [jok,}I(#l] 6jAő2%byo|b:1H>8YYNI-t4ᅰR8G!1>6WT;ǚb lK5\Qh[CgpM+k4ŽZbC_5҈tQ(Vƈ0-*Ke}ܑcoV9O:^/'`Rm#&0lV6,u#^lq}~a70IvA'5B:'-pN@HRG'~jƥ;xCUr|{uSc[^>@Tߺ~ b ky+z<7e@C5\ʊqmNJ 1lۨ _ me q`:Ìң bN}6 0 p]փ?H)^$[ClH'`Eݙ,f‚/zïG]-iqW@Yd8'Tj9}JMKآ#U7|{F[P;4% H/ňFKzn)Q5 +-wg?OAYB+Ɔ8=~R}z7hN|" 4)I|h9z:Hy_BvC4){dyȵ,zTwvt%r2@,1 0/+R^s;r q=_dY(̣F'jypql̷GSnx'P#ov2'WLxTtC`C/f^oog&G4kJc~QadlsuͲHi s;9Ew"ۊb.J InZsu ` ?:lNVjn#'ոћ*AYp~˟-D xKӱprQGgKˆXrL3eK P2'FIB֡,hqk0'ڀNJ❯:Ltv-( Ȣ^-#X}++'kAT^ݙ}=/MjZ]p ޮ1Ƌ6Ah\F-MRxMy[i#?W4Xal~.CΏG{]"%b{AĒZ`sʰ /UgyuX5~~zCwwE)#B̼UȪ#-ݒ$XEі<"U}fZef7rL`Ey oI6tpռmS.BeKS ,<~p.Pw%Rȫ !{Rv xOs1l\73 g^vysy~;J%+x6{ѡh#O(݀*]&Y&vv_]ᓩk!ϝhg]M*)i/g[߈QAI:/F3+3I>2vXn2A?0ٓl8#C xNG7Bn!W^n\Q[L7З+qصe]04ubaA^;bΈpg)Vl^U=sv&f3!H'Đ4}M;W'b$S^ޓ1BdA8w7f\QkEiJEvW uMsBX)@yJT6;0K: (}f̶ys n6A:~51:wFbF󸄭%ItsOΧ3MF?fCKn&J51IiDZC3Ӻ1;Iq&7m_06;*7.Jh,[*A$Ij>tG-}n OXCQyf @yxMt?];۱ qvI9/D]0S<9c(R&Fg_P*kPC6(+Ph!Em T7*tCtU/}]dvD5i}굒W"*I+l@GIHC ʕjjTӇAzSG zB9ƙ R<lxOLƞ%QM Ow/9P+YBEF3{UHVJ|FCQI÷6d'S}z7k-NicY o󡛍 5UOx6'_` :rÇ.܋_ ikƮPv[uGUᶚF?iQ[[6RBa|V9R0ZݗQXrd?2N,ĩ?{f.`L@imD9ǔ/wũۄVVLTU!䉓]B/v`Dr;BMehBvaZU5Dѳyѭiv=n%w83Hӈl@oֲ,9oڑT 2C.f<իQu|`N1P6oV:>YjE[ǝG|s07 mmЗސ 7GJIڔoT IPd+`՞R"Ԁw<,YÍUQBՖ&ݞŰ=(Q >0D` yti*[eL<&<~%Γv@#"[g23'Z]"&>YN2E"1.[~2v|V%bV~0\;+CkA~>usz`YבrepP-PN:׶e0ݛ!2kvNȴɦ z+Hg~6TӜ6p<g l(f7B@y-? ]#'3{S7J;'fJ[1ͰP8c 3q}O:eD,yd& :'"oh&U 8=8 0A 0 K4xoꔫ:v?m[bQ7i8 @Ս۵2)_p/S/W? n.eO 3%DcCUܳղHEr h+ѹKenŌɮ*73r{%wqQIQ}Rҡ2BpL+-LGhi"?Ы] y>V/Az= 0"/pGg 9 N^#Ѧ&I,5[N,Fn=GP&cNk-?),'oW+uTO)bݗ(AHDgYs^˿Ӆ~F]a*k0B&%&]">aa6y>V#!M\nx EL8 thQf{ԢM $f8*J+uucF bR5!DO^;:^/8^!.~] ue|eU^-fUcNdNW(8!"LUw.>^Г2=FX)_6!!{\/L³eWkY a0M5\Qe.J8P@_ֆ)/\*EFHi>XJi  2av!H1Ֆ>od11/$3D Hs2\rGb 2;1[TRQv0V |.2ċ$y=)a1rfA = a]vN0S" }ce3~4=՘Gzu)SG2W`ޚ#,} f3F5V4U`PPrAllXb;!,Wr mhy䲤4]G?t>7FgMl D2ޫ02.)4D>h̩Q7XEV I0 s$|몜QCv-吓$sOq?c+O.a";I&-YAyݝw 53WHGLYzʀB4ӥ}3ddfǐ#m,>h12epO/.C?[ϭ1hNnۭ]mҐWڀpmu837 0sYx3s=6cp}^*};w9Ԑg|4Z~ ?8!DRJa[زEJة/JYP=3qK,: 04R3MA_AxnJ ڐ ,mI39:lf(r b\9YxAYxa5i޸Pvxq}Bi ߔ;*]AW/}p\vz/Zp)1KF( 1PHWo-K9SoF5W\D3 VY;BBb腯MzrVjTc:7'vˣNx1N""8&Ĝ[8BqP;J|I  (Ф; 2Ԏvҏp_Cq/:C@+aZ:7ŸYpa˱#iuRBg>F-= Ţk5mM@ m<̘(.CuO+'cwFN~ oX刾~%uZv.™ PEvk>S@FԟT#O hVY헗;:YB'ᛟ n_{`GM-x0Z e8ޱHYÈKNCdeCTbuʓغ^GҲsĞc!5ĪĥgUV :vAG(cK{͢hjyvS+Lc//cѹVzݲxp"/$r &PPfTxǯr^s 0n`<ބ9/O Lvgjm_h>$]$ 9 QK ׮+h>v㯁PLI87JYD;|\|r9${Pk-GJmY?x;C Dמ;.xI{lA#kLM [2oN_p3MUͤ4y&)~ɘcr4;Lf\';O[è~Jf{cfvIz'N>8`nۮ=/:I{K%i]C ݴ8ҝ,p2_\ -5pl#0}฾.ޯYy["tBH([)6EYg9:epGB1o\kk82~|865Je8QYy - PvafjH%%Q7OCHm=Aq7Oo"-8CicJ2I~(SQUuAA^6dPU+-oSɐC|Q]›~䘨Qw0K7̾N$Xe`7$qV%&ؐ % 15Ɏ13B:FO(::CJW*T6uֻDv}}}P2ORq=|WF:^Aptq(pb|P[L5 ߒ&%R8 9\<]2&zh2!5ӺHD#4TĂ"bȾhĤ-I/ eƤkZDkkM%Ԁoz뉟-N_'@-'_ގ74|RBH R#0EYfIւD2 $=UQh2$D=+3LE !e>]:k/(:聆,:L~CD7v[~?r4˪zPID`fR ,tT**R"#{&NNHj(%X‚ev>({&Ģ+tOB3Sk]Jc]gt5Ц6r&/ra\*1h%\'3A)xh3(f< uazι'Sd(| )A^.c%q̦Jg8.:nl77dj0RDq5 N*;ft1ܷST4p_szo|;ixtZb8t*n#'y'4sxyl@:^01h[Ӓm+P4O;zF,e.ѱz] 2o^;GH3;skp,+RM"Tw~#Etn聞:I) Пu6t} = Mp/ EE>ɊpT4!$B0|v)ࡽ|!(4B Rvj$|P0b~RqdHij*ܛrU:&+5]Ew.+VsU{*Gt2ibgClѥzU#a2 g@6}}r]ʲ>ZJIB8l$Q,Ь ;30mۧ:*U+'/sA <#AdiRGw-t8 Ӥ 88ҕcve%e\"$ ȝktUSQyPWUګf`;]c8pM Ǎ %e1`th}k53 ܄j^!wx[>X~ÓR,2U UC^&㩳YiF&pʡ8%)]"aZƷE"O7D *FWG+?r^559O<.EVOЋ/3!Āl O2;虓kyu_xhMi(R#b޳};u/%VKCʟeb>֝T6WMv~Ur`?#2Mē7ش?t,y88nѴ4߿feߜA吕R\QG!У^0jst n\ߨѣl北/Qe3'$2rb/ux3;uB' M^Z5"ƀ֢"@>а>VfhB]Sf2驠DY*1[4RY˙E;orqh|/ d!{]g(}y)Ⱦ+wt5 Qvy 4k^wkG p`>exp 6 J",=orPidd<P+fE@~$\vb2DU~ ܳ߯O-ӋKAi)"=痗-./8~~x`wtI̸֊7%7% -LYg)M!zݢŸh{%Dт«}Dj\t҆vKUvZ!vd:K%ieyD4D{~Jo.}*\O|ij,wcP@ W--j~u@{ٕ7C&?́<ϦEF,7G_:+x4#,E>hLTU,ގW"[YzWUMa+݊`ɓ@`m8VPɃ:uHĶwk P;IP)na~?R*I,iMoUX$z*P3Gac0jh7SV|j,iU/|бvZl7dDrz,ZL og~_;8sFa(=Waa$W E'3#Ura+ rLc3ワYYl,ͽ_fr0?o $Nۺ~DKt׈TZx8{E~NBЍĴ~]m>E  a+!bjg|yh@"N|rUJ' m:Ҡy>@Rږ>p)梛>DZW.U"itUz :rCM-s1guJd paMF3yӔ`kJ/Uik1q͔V+F 7j#}P.FTr(u[#mpGy〳}p]xGNÒp~ ICCz+ZI]>H*Ii.>v8Μ>tp)kV4t?H4|,+*xQqr,»D1k!U&@4-%j' _HQZ)ʙGof:J9¼gVK /9' ccbH(#Jjeq}HRw.$-ԪgfC#3.'RBcy*jO$%3, : ''DZgnpO](+|z`~& ")n=o|:Yo[0Q:bDMU>[P[]m m@5+Ԭm8#m}CEA<cש)d)uP0Fœ MkBVc}c 2=ub9b:|fg~]0$$]@ݏ@'g3V_ѹv\S 9"/}KeѰ[;],#RI{0=DogZNU,+28#PUhlE'p>nWZA5L_Zw9Y9M-C2TA?P d)]^K<5%T"N&> ~_n `>;.U 4ey3qLqVe(mAӖ,LGb}x>:\*I >'4k R%6ه}DH&\(xNs!oh<&gk+u|Z4ڑ: H :| P%cgJaW>V.*T|JqG_pYu|7!BWpFtGXԙ{}|-o'~\q,[eOYb>X}(7ǒVi;\XƶfG=RnZ,@̮Sh^^3~1©N'DzBGbϴ`峹UCp0"ATQ䕌O<7Z=d௨кhhB)+fPl1\ku[I()AEPUb@_%oa7{g y?:J'GUU3;oNW㥃v{3")g[ngEɊl;(mkhSjZy<ĸq|m?RPݠx_J%Ua՞ 96"_;Wmg3앷kV;_bY1{0tgr"DW\&,sğl.k0\-:sQ%Ȯ0Bgɺx-ҕGӄU,SJ l:dqUtN+K=pbGs~?XQuQhPLQv}cb9۷O{y;R M>„;$ 夂~6n, lp? 0TL>҅ !hM%9$t2kG[UkCEMn,:64!)Eg|ĺs>5^*\ܳr ouo'/ێӲ$Ȃ(ܶD5A\Z1U:0|J7%D$EDsBӜ2D([(XˠRYYOabO򗦝`8'G )՛L ;1ף1 ?*4}燕,taRXS*3_#^*#Uѯ_VI=4Bh.+FL5 [sD&v鹙_Kl({,ph렏Es7S$NYc]_yBKPle}F1l舶i鉁]#vM,刋u:yq.UDx o)']n{ d&uRA"?ع<ukGDk\Kh k:l'^.C$P^ e~ sSQ8[3Xp`?x<0L!<Ma5¦7H"@P5 1|U!`S"6F7KW@oX?S؆ `B@AI zkl~V y!.hr[_LM>{ N{JFBqWjϝBHjeFhsJI)˽wJ)(kFM\" =9>A 6TdKof 4 Z(,ۖ~00k" |f1 DϬ߭2 =1gE<ۍiȲSW :d%V~Tm@ tVɴ$mi)S"J2؈XVe#0"\J]PbA)X9 %˪gi/Lm Di>l4E^1Jm?1?15Ğ4 `:lmOyhPSFFVM|Y/ghϐ&;{cL<,L~q!#ƃ)ӂ-A3*KY6yۮ>Z5CCTLœ8dm@gq4ԍh1 0P$vy vˊm?gNZ:lbLcT55"YX36$'02J)<~r*mz좑'*v)s'֩ΧZHBuItuikGzvRQS4Z7$,}_\;Iyy7.fKR#C+3t ߗz+xx~LwH4iZkD!Ͻ镜 S-:c/K u%WxC "gӂ=.50e?Xܗ9p 0OŴmcܥUii9/Z9MN#{8Hu9` s-%`@`^y(-b8TsdR%>=#uƠ\H-0e(A5EFX 60L'@IkQ%c2tq`7Jun=ߔʒg䦨 +~[G #(h$gm8Uh]HX朞L &F?uA,5?v9٫fReK}~bHi4%dt,hw0^+Z[L=AEZc!ӎ@ ֝Ipca/U%EsKW}BZtv R<*}a3I:&T{}y_lsFp.kSE4 %2Q9\"}Ӣ@0JMpOPJB1@[Rerbۮ@H3Fy_[hJX Zs6pFd &*#e-]|lin\U)N< cr m 2HBOyE;zK9\j($ =0h1*UT70~]&Pdt?*!e)lnjCI?'c&њ2j T%/RYXm4<ђ0Tp) tizD1ZӮ2e/9VY/fH*>;8]X0sB]=[fnqhYpK"T߭vkXg6ï(4O:qN/yoU%== -q,>PA5`7Ilc/ɧgjOnGz=RBh+:= d/ޚŁ_PoH,I_^&p2SrzmyBzzdYuSœ e/"X5R5G[lŶ픺16>PͥpT恵^S'0CPn'C1糯S6sV"3aT?Fzڣa̫&P,T~&r?׾y h*3Zi:ac@~#"9Z 30r^ A!_2Wm4?4Rb/9JVp\Eؘޣi[t Xm?ɐ*ϻ_8mBY_+}eW'aߖiR1SEUY1i+[ ==IK{@G8*!JJj8:¿p@Ӆ3Z߅ U=ůtƨBUkc? okI k/V0Q29dd2w\o9uU%jRsdASԫA4:l7L'ӴM06:M:QH;"7=V[=T9zЙJt|N$g(j`UpnZPibls'!!Gf3YT_OBxgBoWrwF gЗ# ;){ T F%3o~A aF#߬j~ñ9JJIwE_۲ycVdUT5qERK<4$[`+Ɨ┃DGHvB*⦬˰ HFslsqЖJ[P3j#?"Kݳf6ۢ5{$;WhMPP9e"sg1bRg fQbTTK_`,Ys76-6qG /#/6p}}!i5 (M ZCx`ԐHd&\)}Jxoh@_B'Pmϗ^LgEPr)ee|(y>x|5׬4l]|)#)O?唱L#ɛ` l mR7}DRq\UkL|3ɏ>oõ ^[,˚L%Սg<'i=E聠Ughv'M%6}t`y<2ܶBz%WøS:kM.k]uu@o_.WէnvSx"-Ж'yQ9.Ц0\(NP). ",pVpS2~~:ٍˢ*ULc̙E&J "2$/0IGU *Jy擒 nB0\nd 6a328I+oɭYƅP!*H&rw9HK7RK#nFyfw~F(Ȓ/ºshP/A JzOkYis (rɓpl8 <"+瓬(^J.!2f±'ҲTwȌajFt޹Q EdWD-j}fw ׁ2ԫMϩZ`)j\rf-fwC3C~dHCvJ^ۆjny[/YC^eSka8tX9L^K? FkW9?Z#͔qlR!j>7{QE צGF΋xHewMXPYsYզ.%[S/*.|(RIXӷO`[D3 rR $kHkd;v%J^W@ U6V oĭg Pl:R>@#XeO P`+W .IW"\?Nⴌe(-R B:YLu ;pYA;P}-8CUv!DA=2Ϟ^ 1bQߚ SsF?=Tn;ocsĥ\^E7 c ^I:f9HCS岸 /0o2[rȝawsv10u&-x Er7YA8:,qFZyjmkA[wpQ<+meAlڀ_@(* ֯!t+SΗ6C:,Rbb. Zt CS&oT%I#*s&t(?,DŽMeZ;Q)"tY?Ţ;j7M楊%(M2ڤɕ0{ `zsfkdbsp> i k-D 7dqNZ6"%, #]CP{9er(>=tR2م;6̧[L?-M3? '$9Ί-VjP'7QwW;<#=Cs6~*F(Y%l ڳb#VO wPxeԁHa Lƿ5 tLN򘰶Ftb1GQ.NVg.w6~$4ֱ1IխxQxj i2he6%s(.PTKB;vC^@A9$3^.ociXp8'm-خpkk~"qq%U]uaµњ;7A`|j8\gb=~7c zG]R)y$jS0} N7yzDii0{$*,(X*K^y\Ǽ(/󿽼'ʂŢO4mv%٩C2 M xEIphUdPuۿxwZlžg|8Ds4[ٙ ϟD LQ"1{?G\ {OI"Fb/W-3V#Ы+ݎ ʬ P6bS q۶փj6o44)K.Ew /C#Qe@F[#*lC쓁sF} 0SU}ڿ#`_]%1iw})ey>×ᥥJIU(8S?gx}M݂R1)2UEqx9'q,sDmY6g&ՑͨYɼ.lI &Z,}ނXndI pG̃1D$@A<;ܶ6ϟT>sP <@nߜMfdc|tMLS) &a;/*l$zA+,?l$򘦮e|.l&Y=Vt>9%Lǀw{ wbPsbTH<{20yc< Ќ$/J߅鞩hhm[L}L:Y!=a:!g{m/ Ail(0He VeD/蔭M Rp:،E08fx.H:j\v!sGry1,bG+ϣöR\kKv^h'\[ZV|n#]0Wr50GJ.Yg^9!VN4AVG|LàgĘ{*&HzݨqF_Oq&Yb~zfp*ĸRx-u^5.arټ!.3@`՞oS\J{gDWLUh |X̪ rNiu,,U•\6L3+gU;w fQw=4 ~o|]zS&]R/K"4hqϙH XѕȾ3?GF_82. 7樊~X{zy +rQ~zW~sh%nA93D!z_(˃oҜ2'TwgpSIjr[q5F({rTir낏Y}iDz5F~bgeĜvSls ,N;!Q#!](cUPgO,T.ϭ71xf7//t~n8*I^HrjKCblM!s3zYO+RO'(y~ ihe<S2=HC`SЋ=* dd|!  ob:P=* 0 =7TI^]+`&] \e0i LZҷ O%,H:r>~ b5ǜX}ZntH-g#fͳ'[p.rS%vrO-n3&/q F棜ᏐsO~L})She)oFs"R /K/X").* Ruw?khE3{#n5ŐX˳>'d &ljJId(uW# lpy S}һ#Ʃ|;`,&e~U9(:=gl?v<8ŽmWc`7(}(;/H3t%S'mvE7G楢b1O#UԮd4]!6` Ewa~ݦ/] =Rnfv{mz|'焾ήC=l/pݘkȯZmSQUq V72O!E.'ZRԕoeЉĎ&S/5zF+""]̕Rl?Z ܕO:NFcFuW(EHσahd$ѿԗ"PBFOLJ |es6JnJ hb\4yZQK M3aiSsf]xJ9Q_\9XDNifg KX?8Sڍ?-2gvd!Z"-y/Y,r5Xb<hnH:U)C?u5n,1`Tр=ǾE=mY3ַ*_ ^cfض<@tRx~rBJB ( ;\:kCˬC&h;Sg *٭ gM99fTgtG]θ02q(v<(|ybd[G`sGn8ҎC<2glw~`(E/C w+}a Ldgۡ|/ Jtu"I&>M#;p=Pu?nUoJwB9kl1,d[} <ޟDX <6zJ*vKڄ-3 ma/HvvQ-b 4ٟ9[=g #i62Nln V9%j+0T0$f)IوL+ui)YB`D{\ܾHY$v`k,VZ;ְUF 0{z-Y}=1lb|_8 w2q%] CLښ5~eb$.˻$Obms (i,N#}k!=5P/I bpnn=Z5rc@|Iplg6abuK7BX3EI=Cn:L M9NڧM2VDj1 1I\"ޒS,G~GrôL-+!VOqM&76ͭ |=u^,ƹ~Vc9NDtuYIL ia4]vJ:=S8h50?J"7Ĕ%rҊb ]IZ(9U-'. #N\}T?$VMj?b&9}u-6~~v%a#yWRpy5v %RHa=i??\WOղsHCsnH,9f5"(²Xr%Ӄl߉Z#mHLUllC*Ke4Y]|k3?  zu\.:cѣ%gCAg_9.UiwY0@C*B-X#;FجfZ ݿ(dĒѰ<7f")lr c ~/wȱ'9THҬHߵ>ԀX}`/uه*Տְݔv_DźÚ.RH#kO =8Y*5ȑuu,?0.Mn'R^ORQTߦ#s'\\zN!yS]8:e <hm^^Ee4h+:) :U|~\K%5OҀ>aWbv5shbKyY︤s|w%)o4> Rj5HF&&;kyGslh{rF/97@e0\N瘲%dR4A1p F٠PVUqF!df'fbLu27ˇHkx=jhi9s#̀B~D!AXYЩUuv4QAgOd巷ZbFC}C-څQ:*hӛh6t`rBjCI_1UXriI5ԕǦ=ZC F,4K׭>P{P So1(+'?=Ue[yi<$|mKϏEJ=z<<=YbdXSN:&ij%]Zg/ZɭCrsIAA*L ҃j~Eav@!0~h$?Y4ԍ[mÿ%ht;u膱Ns #Z;ۘr.Pӊ )(/,Z}^ewbj¥"#C+Pg J]!YgVBb{y/,)#cb~}8?J-eW >̗}>}QY%Ks1'00F x͟Ŧ^b8OՔ /4o8Xx9_g+~ޠ?Cn9*˿H4nԊT]%/82y# =#AFڣo'mT)avӆlhuKp3 Gd %Q[êq&xfDg~Ң0'X;ڂP ] 䚲Eܣ\Y$ڮ6~^E^ؔ(ҞYqw$0kUt֜ᚑF**j=G6cs|e7.hg(--H)nrˣV0!._SAgK[^ x#CП펯 x XDL 7/8!^ְWFBй8" %kֆ,mIDm?S)EGa{IR_8aEyo`x):"6-?07DJXȲIIT."YQ*W(8(n,8i.A25q}V$[Kb-FFwe9K4>b)(c@v=ޜ B!2v4}Gtp#AFS/'YZ @o& ,t7@ПFE5#7 f9%{!HydS\ĊxL׍xc~DeN*bmvI >p[WQ]d2O9 ](#RsidT)h &@gމlbF4W.Gu܉4ib{7M\t(HQzugY~*j0]fyM&дB:DMa͇`s$E= ޠ2`|w4wŠUZk  Upex|ds&+uᤅ"o>zI: EԂ ̞vjB Tn>ڴmK5>}7_b; 46@s ?Sy'*Zʲ7w6]d(K=Ȅ{u£(ٳq*Wo~ qI:>0}V_Om|RݖDcqQ~-c':l`‚`s%l,Y::@UU7f| pfpSGUDMCU\s<3Qznՠzkbq 2]m ?*z]5nmZ@ǒ)ZQL`]׺)25*; i j(OF>&iAx~8,(Lfg"-CʕW'~VҵFk㱷y~x3<\Qvk!ɱ" fWEuYN =X'vbBxVL.BJK)zOj+|LU/6U0tAMz+8IH{-+ "}䰤V>`E\yjLyV ]|ނ<>CVgORND3qioN=3sy¿ښ !l]K?GOH[ ѳMai{$zcw7C,]D(̛5f)Z2ZkZK1^Q٢nI02 7c:}wAto#8;ELĒO7p`uLQ"iKZJ|S-1~Yӓk[7f w1;\K |z9深4%A7k~Nio>dvI(cG9k,G8sW>&^n~ze~TZ׌4zDr6r@Ŀ%ia3f !?:Gt njׄxYhJ%F̸Gb C8P_s×3,\'Ñ>fW`d)Faǝ=\d4\$1 L;V# e^ yA-Z%<%)V*@N!5gT F*9ّQ-`=v⁂{4Dܣ92gs23HΏYEw 3h2f ́K%2f0ӻ,qẢٸ+R3AMGk3ɶv>ؔ:+^~\Ĵ?D`N xɶ`\ZOIzڋ $_'ϒ EƾZ_W&!HGm}pJzo~^"8ʘȆzFdbo|]/Cy'ֺp qt?2NVAsL-<|F&v<.c̄WI"6j mz EzK֓BBWBv(YPE^NQwL PC BG*eӝ)zj/We/NK莺Vd+B.7ϐB$"~;:Q)iD}`֩yJŨl~ }WL5 81 `Iko=V#arI=S/2 $ ,L|p~aNFog nvܮI7b?u[P5*ԵWS!Nv" bCiպ\u z`駬8*ll{ڍ qDŽ0*.p+JW("uv#Ojh*,^:} ›Zg+.MI9R/x(KNʮrŮ-4b $ȁu]Dݹ Z D)"D7Ozd;`׆gp`1xr[4L/1O]Ǒa1_ {Ӄ͖sL+eXpD{H!?q{P4t@E[Mxp[I$}wIm7qW5 HK,ڶaF ]-qz}p4,K3ҥMHrie{Lm^澉 C^6ey1A%)|`UyeyeQ0e;` *=z%B %؁SUNrhbV!~l[.1b|zڍٟJ7ӦsVVu Pu~Kw~{+$lG^`+Ui& k+]0ye9~ _ف8Lw̆wG /Eڴe#5 4ʕ7 [m*$Mg@(Spsѣwrq|ߍCuxIS#4Lt"ƿ!Ș{Ї@Ciu N5h FykL##k ?S @ `2(뺥mTI ޟq=ZBi+?{EJ6>S!I!6`x$s06a듅h#8j!vR]8%@S@/cq0cbiT^]+%2߀ t.pikz_?6ó#{pxOl#qcy#aU79{V摴/}">S7(U|W ~A\$QkhBTWEĖn-E@`Id -=E}+E>e+Z&*Hqe5FPQIV1q5qXp6L<>@5yϋwA&jg{* mT?I29OYUa1di6ZGthu!V~iu'ߴ;_FRh.If$b*xyׄeMg+^o "JK#P< g'7XsYe̽H}o.,YQi(7Zeh˕d>e-oizݡ ,Kݑ,J9u{=-Y].kU1Erh\6`[qdmh,jsE"RXf]f OZr,y>(yG0+- hS#wY^[,)w9%G5^Ydŵ{O֛[UH-ԶAu! @P+ rAn0 TvBTyK'~"h9R' i J>m (+e "4~>aʹ;[@ ؞JBbb$!w/4oɼD_<j>?~[c`,{]Iۓş )QWJ^X'?+Qi%dF)EYIy䁆nE%Ȳ\k^ <-5$:ӂϾa}cč vYjÁ,³2ٝ|l*:J9%}htyvݖ:X$O>~`uI`#q5}pu0JT_cB<[Nw&}OL6|U-޸-/\KfUt༕KW? !aS}^rv{IP"imC̜nUt+vS!ص9mVH:~re Iv d.C.%e(~^댬߾^5'83-z+e#zˊ1HluT s$ҵ# Ά[Ee*f}b RِQ>-\cV*q"@Lmߠ;9R~qZ˦"$^g3BO(&ܶ;eB+q$tAErҋ0^ ASJ.TΟt)嗴 s:Usm(~xĘo0(QW55ZO\I;iRLfJvN%-a2mB7NSlK~ŀ ^HEOoJ=w5NV@p3_3xŽK_P=XOב%[[ ޏqCϋ%kcTfN2CA5 1yN~/_6(7 .ޢr)|s\;>Qt3YqnjPUY~CꉧڦL삗hQʗjKuOPa=HJnWE<զL"!^xf8>HB`W{f>S5Y|v{)S4[jsbRQN'Ԙ3 W$!" D3 Yˡe:Oa4.1pひ<2pg*2"QJ~Yla*zRE!Bp)1GRt'XqO%Of~op³Aslɶ1x凃_hHSW* a yt7{Y9Fi|##XZd|¯HXdѣ?éWX9P>'.Tl6P7وGe`x#Qڥ0+H޷U'7Ś>9* p %2;JyͺRIxMϖi h_my%3^6 *^$=#tƘ%Kg4a70ow.|0#GCz`bԥ6YP2HNlTf E*C bDG@2MK9mv^4CntH.eK;:ɎKR?O6t+xŔK23a3{p}sf?,2|I7%Mí< n{`=S&G{u!*rs]ʊ2j ::1-8m*-e[ɢ#L9`┅X>Пf>'&䃉 v1/ ylO앛 w;sFiBU z=bn2ssKS ߩdaQd@Cog&|kt sYX{NϵL]Ʋ΅/U2Q%z*vca)z?:K"|WF5Ucn3 z&~#s C tS-hi[t;IamC |'-Xi"0 OH5"0ۨwO"<!cE JaKK5ej[ɔ'Y.|cZOџhan0+q ?+ގx٪4[Qb2fC䦘.1cQNۿ*Wv4A9ZS^/[&]Wap+OlK]OYm3P|nڬ%IO5s(7,b򢽽p:֢FVvVU f.e'hASZVT#PH2W3SzlQޓɚ~WSR^ܚ6 xA[0W2  DvS"cLQxN.~dZ|2)Ĝpl`eҭx[!G] 10g٨@T[fQzé~ҏ*ЕEd`KnuF\Y'~5VɪDбm(y͊潜ERP-SLu1vhs0ƫ3I0\J ^jl~l9y`2,@9.CemBj(S"bSzXEt$. F}ܖ|o[0ׯdM@G7s<կlH3V˩KdixB+yЦ?@bh+D#axvXȣS^Z]hBcJݝ??&ڹ?d+Hukܝwlr O7 )2ݍ?h`f=s㡳jC%yhuHQ(p˭u?ZPq m#' dv۩LF@M__kr@ {p= Ƿ 6ז^Zg=`_^ЮKx>gC:6- !$}&R]&u L4#:p\]R3T[Jl] TfNF}r ikFA>}}'OiQ@ĩ ب^p5㸮/fVәApyX H#X=I>j3r{ YQ3BQ?+WY˒g6G !9ke޻TvXqN A&#p[.԰PRU>$E'[ǑLYSբ] vʕ/ )b|9%* ]^ ʁ/柉1LI@f "1E_jêϡ*+]dFG[fn>*GsȜnT"md MN-Djߨ/zFP ș(72˧dCX.K)6 I (-siFM9e?&IŲO6όe3zg(zy;8t%WhQlj2="%˸7s,Dd#aI[c-':e!#y)pZu2"b9OޏU@+o-D3skQ*&4fOueA jeg4Džh$v 8:4tCb͆r[8g@ֻ e+zp{3ݵ~w:=~]-2 .} A%t\tQ7' 'A;_L|!#cop;(%+?+zbܣbcRo8$+ݮ5;O5bcA-LD5mW1TJ*`" 3n ɍif$ ͕)KAt9Kq>=yR˲Ɲp^eQ6 /ZD#'h\~3ǧkaFT-uoݏR_>RIsVTKOd\CƞW~N3޿^?F?Yn(yr?Q=vum>ȼVINu:{nT [xA|6_([vLdx-bcfs][`'/# z]ϓ)~D kLAth?X2 07wԕ@z-ŏ'AH!0K{d}贓0Bt#tM 1()ʨJ:!xKs#KYQQ@4F,?o1Iђ O5#f-d}q8=c֙nrpNDMO:ŜF@ f7oT҇{ۂB۷'ͦRj,Ac>XϚ<a77ʠAA3/ջlכ*ɢ`OKpcj`#ߥLJEoEe~Xux-T;`,;=+V>mfk L?QL{CK1IQ3Ãh|nqlߔCH˂zȄuhs! nKcq֨*𧑮g~JËgMg] /06\:IJd,]+-Vޏ5a9fvpVb߸$_r؁пjy~24Dpf2BTzԥ<|'lmxٰϋ [cͣIE'ϑV>C*Q/VlF1٪cv,lOipyO] x +c/aqdvN ?q./CJC5vt7(Ȥ29IGnQT=M8Ԛ'8g1Feb?ӭ񔍃;TSѥfl_h܀֎23ۥ'"Vr|٨ n6&{QȚ6_&FffܢNIZtq %Asv#T MfHeq'6j]xxW&OJ4;Q +! G,>׬EMTd+ L~f\d#k2L-bpӷ9f!FͿyqrMl5[I*OG\Yeqi)c|a@I(`]љ+Hiן>\9n채o|;Rhldnd4: Y:~s|; SsKE+ۨ?N4~DE8pnp/0d A@lP6OBH`jZOJZc:*ja嗼~]Zr"!Rx{7sJmHzITjt'XЉ6-I-`CQg'[G-3KG̟̍vzɮӅp)ꅣG>{璷218HZG4LsPNKe߈޵<tg ?,ZQs nQX:"m'q@ =y%_eaCրhtA>7cXRڴGr\:H*7ra. h3r]|CW_(&Aި38 JψA@Air)NhSY_Ʈ#[H$lBv&\|rrY;J)bD1s!ĤIr|g jҵyTbfVđ6#@+_(MݻuWXL`jn.ٱ7ayJZ$SwoGxʰׂ0cy vF^Wg|o=8;{hh~U5];zBBGP'o~mnV贗2p&# Ӏ*ЈK!AIi_TyI$3LpC$TH5RJ^yV;'hl&oFBFgosP-ɐ])Ȩuw LM|'3~OH RcL 9"MNt9Z? L6`eo;bgj9g%:[Q ^:6d7b$yܾYkMs0yfIê@M.e.Ĭ:襋}.<$GFvDN&jA1ZnJ\ 6Ɣ!F=,pƕ+]uǓ%0/޼yVzHWe2'\LR 6Ձ1tau,CUџ+WɈGB½ekd5:ROAlUD>9 2I';;ރ@SXnNJdh6Xuyyb*zZf;3>~zw =#wFBs6oFỴI>"{tc % A<G97>][ ,MTW Ilfok-y`@t%Svtͯ};&/~GbЀwdb< g}WaߪI.&א!8P~C?>VVQ9Թ)N0 ` cXV*t(CX2J AE~5!&+u.K1.3ԑ EKd#AOrKK_s.]­=K*M+X;6#8'u0zbܓʁH$Nʋ`Oc@Zٛc\mH8tɫ^uq5KMOm뎴Ex'"`$ǨL|hA(H:|:|*=\c#zMM'#I#w!A'\ ({p8#y A`O=$=]u^\kY>X焎{wh6ֳ5Cz!-=I|Ymac?o_5)%kvوyP3/ccc}A`N^iRyثamE z@ "և8;~E/DGWu[Zcٛ+}?dղS \_-w_0m鷞#稬羰c}VEv<:a2ZM YPRA}h{,˸H<$[oV:4AKxJ,5c޴]ϛK N 7wPa^lcmKiV <7PɆ$s^0;MÙuc#ͽa)v:cm˜m^j*kZP۴gEo`YM}n]Mr>n#+btL~(8|SJvD< KAzm^j71NB^^!8 ͕_ocnɺ7'{i&5( DV.Z4r_O-)Ϥ)T!rc|yf,>|:X`x=uO?G6PSj~Q"$ap68kܼ@l;wV|SB7[RJqe=.vuOja⦲HeR0INdk >= HKW߂q% B%D)T&0h4 \탑l$0E`Q_mYklTaE̮OqwLkR+|x L"i3wRŀV5z9>uN7ZLn}V|UH$Z t h(p1u<U;]ReAL69їM9.%ǫ~w,'Z2iR; }F>:(,(0#wx6f~y "cws x={X/>|_kxՖLI4p+I}4OPNkD2JZNjqN"! $(-+ŗ^T]2n$j,ws1c'smSa Nި i/ :bG0N'ƽE0GbgR;2Ea݂f4-59%+@~!)㓖jN{-" ÆL'uAf~u $ k Ȳ" kvl3CqO E{C|, ff}MNظ.]YP?r["Q|"@s(a Ew>~ ZT^3s**Tu;aٛ,+^:/DXu~谵]IHAWU6)]s\o)%;2k荚d-:ju}iKbR-FYg#&A_R1OeX^xvSK Fu1.4I?(Q*Hz+Gw,VY- X=W1|L2Wi艻k"1m71BdE/k~('FȀkr`@ mۓ(D>b>UGB{Cn&͇Ҥt%i1f֜INsB{+b~bY { xvLJl(r걙|4IP!便ytxiaY OiZ S-k0:?ӗMx KswDTot#biγqktZ8jҝܕwFR;SƯ&71kp>Ƙ4Z]=2aя̢@MmLjiO +'zJLnvGw?v+Z篼"x7؀EM6w Ugk ST7uSKo >*΅ĖO; 9>kXKTqzيcp] ~%! }Q6?.f!D7Ri4߾{=;OF!x!%%v)▆0q 6h=/w+%pu2J87LU1sqEzw!=?}vUp0%q SbPN{4WO3QZE9<'Cǧm$3=G3>N/ĵ\:i `/#2z !݊,޲T0Ўdٗu27'y\CD8yM ZYd '};^ hy D;[D8ye(-|@h &sw* C-4}nU<6JoD PfooFN\x zPj/-esJgj1rO-q0  @)+Asdj[%&†#:3Xď݅N Aw +,S5ndMV£}Vv 5ܦUz]MS/2B^6}Q'r'ӠepDA|DX ;ήN\r/խe&̻@"KZ|">8)쟋 #0Ǎ7A#>M /* J? KAV *W_\0MJ?c䔊6*avwxjoÒ=W!|XM{UQZA@H"q@=[]NIT& WT)pU$㴇x1|xہ%dJ)~SDM;?JEZ;] op?n ~x[*ȁ+/OcsV,Q@KY\58yYPmeQ%6h6iHE@ o_)w ^G=L~-ۯrQ+bgJT]c(_8{~]oq#9;=;-bVO^/#*\[{"Һ.pό5~x&KT&κ@~?ŝr eVsg|T) FYh*vҙ\8c~uųr ЖK[S-E%6&Еc:LAjJUCᥨĊ,[Һ4a24 )ӿ?aBdN}eiPUjBșGLk:|֥y Jӛa; tO[u=?]<5;N 1FocA3NAM'\X-4젥Bsl^t@.*m*A<Ȏ J %V?j0R #Dr6dBPov!נwڟ\nV*1 a07K&'N QOL&pdܰ$+yQAT]m+Ƚ #S|h=Iل" =:yT!;M,gYF؃Ius,ZQg{&2/v)qh+!|1`:g1P )WXǿ.Ӄmq>sBbVR}hThtoImg>IZW )FՊL筕4x58 rf4-R1"dyHB @o\sK*pV*ZC6M@X7]_-$P#J*[f sr|zwl&U -}bV_A`%}j*n|>d_wl~@veU0Mnt1Qa ?U؀ f4 Vaq@zw\ÿ *㝽ΜrS[+ie,*ቪ@%mB,PyXZ9=`~Y(H0&:SaP\٧_1&F؀nKXY XiFK9VQ>INfW)0`!8A<ثuH[! TY# c^ ۬. +\uso>N}-=~Nml&3S ӑLI@&uN?7L=)/ P ێr|aWC# ^YRv njAczs7jxHCl&Euj /HCnKK'vbuCh|GI_9Cwf97ysM+X5ҕQkx>hKV>ΐe)_u}PR\ ĸ/{eF_a3lC$> u?&uѷRf X|f 0zlVJ7sڲbO 樔9ة 3N XonFp%*OuA $X>6@o!U#;a[^ 3Axh|ϧۅgn=%FYnHYDL/3n}1Z#(fn v֝zȳk^i"J5RY7!TvUYHe0|%vҰҾN*:s*I]8# +_4H9WDR`.:f &Ľu' V#!^$Wm=AGd۾\^gPѽ{XpCZy9Qt'h;1A#k̒g|' e6t}wcL(9k eauZҼhaB4!Z?("yd:"=F>uã(bUs[o^F265!"_F*Hl+`Z@Be5T8ʣu|}OOyxcg#{A" *`>kZz]jn]#mf!VJ'O}F&-)ˆ8Z]/ @$yo$Jzp,=+)t($8pd(< WL ƬrYPtQ4Nbn_#i@kjC8dg@/`_Xl_qtX9Ⱦ!۹ؠ'<C,gǴ2zM(Aڹ]>fSbSg{8 ra[묹F9#7_zyݻv*C]!W*gZwu낸lPrcnheG6 ΊP haI R=";F7x1GfNbAB2Bw~ó=OS81'Q%YMIcV?¾8"cb]n-Ke=u-yڼ.0LO&_zEtL8F\5NYPTyԱoLJn;G}v{'BzD`t7+ Bq¹i~߃lrI<;3pE%0iTU]YF٤} nKE= &Q GRV9(D#/[O @fʩ(P [\|dgL]{en) ΀]ϋJ'ց_d|@ـ9CeI%Fo؝W^ՌvpVw< 7fŷhz7eB+Q(E]2(Dfq~53Ѻ$e-ӭnX0N9qӥFe% =)0ƠR4B͓2]msO=Yݡc18L&x{ӾB}Ñ٣ )ƣU}GuB3mAp, %[x2. b~0-=CnlKt^"3z3F^Jfgj>$#eJc7Kh ] /x;EڌFEgf@_C=GK{-%" H/ÎAu³u{?0 ~`ǿ(NOGT}ړH'[vZo@$['u/U/Dhse^8 Kce>!iX'/?em띘]Gͻ-y-tbaǯEde~8"τgpy]}BD/S_Ը=N㈨ib<a` ڤ5AЬ[·w̨R V~eE| P7t M4Ts) [fG95ՙAFj%.<|RFdWQ/a52#@% 6݂ X$;N{DJBSw>J;%D{:ujmgX?lS,Xѣ0wt|(9H˨ lʹbt=)Jb&Ŵ -BzKE(%;GM;(,-Q^N⵿lw>z'D)[rWqx Z<<)%KUgk>^}E{ȣpoȋk3c\IO'AVq/%Mډ37nՁ;coeW9Ԛ󩐇{!~Шl.O\9ΰ R %Lc^gO_#/^فVchG#ГDK?(=<-`=,1hB*Ѽc)8bYKBhs[dtW}o*l4gb5%\3E! ɶ->GPJ#(^O7"UF kANNX]W;u0~%'JPhc-k|TՀ?D&ǯgOΎ'*^=C{7`{RL,9Lx!74&);:8ϞJZqܻV!F9H:;jBdBǬ }j]@27R!hv 8a4yV3&ehxauK`o(̀pqvrWC[ 3܍U)wrSj[ׅݾ%r!Vh 3}7Qf#a)>/ ub[]1m7]j_)6L P>w4('sMCoɹ-S+o3'[i|Nc6 AYڊR3$qPӽ9l9h\Hf\ 4(l%q/;ٳ4' uk#D⑕:Iy #4(v6t)AH 1ȁxC, =uSX}5I6ӿMUPN-߷Pn7/OLqb܅. RV< fez#36iX5쎎U_{ti\0)lp-m'dqBKX8xaϚ߼xr@d6wio#J ڨ_PU=T>$:* ֚Ag"o|- OWE=Ԅly)lϨ5܂En|BHXC=8_ *`Ձ]S\Zbض؋ڊך'Om\FZLOŸ(  'H=- H|C(lҤ%&?\B-$l+-14 *v`OD;<*{5uQ>Pt4oU*-QE&t-mZeeKkW186~I42=b'\p(iP7sa<"vlg{8b43%uP{ D@ΟziF۴ډ'%!M~Eqzo$iׁ|tpRXWCC߲4λms '^Da<#G< &!Invt=",ML)/"bXUR JT~ $9 rgYXH,j2ҤqyrB 8'HzB!c-~(]ی_*@SwUz|½ rCauCw㨜kħomĒvS>$yfD_I$fIqu-M,m+L/l ˺v.Ya0QmMR@/ Ƃ!׽f@_f9&![R{]!Kauۋ9dź<9SsBfk[jWPƜ"߁c]tc^kgLSU Y.VC_Dp}j:8pVWe4960m~Ql8^ǙuyO, ]:qOdP7;20)=}Y r0]_RQ^^upH̎H4Edm$PL3E^(e+Jٓu, PAb@+bD Е!zt:XA[QdVI;j UL ~T#^ q nZwg,PcYw$"!% tU2֔d J'ҍ?X_';!8)-r+Xt[Wu:UT&f{ /цfAc5|Vdw%wKI TTq?Utt8Bnuc ]QJFlђcDty ڿ .]28y]I1.oڅXˡ@~> NjK!tL rPr,S-E%zW92Iw0b@,roXҷ 3+i8Vc{78J]K/dҰXkӖwuTuC6jH)XW<}uꉨ ʦb%/=$5cW$ ꌶeEX[[/}s3!f$aΨXCV+Dn|eC{>Ayɠˎ r݀n)]qg4@<&ˢ7 N9W<-D@_I Hlأ[e "G/n57g]Pw+hʩ|br>'%Mh#R&\tNG$\u .kX̄iPÝŸQN;7G>@{#C'l'[KJ+MjuR!ÎD.Rӄ,8beq  "[}h_Ey"!–X.qs GǐlHic (]b*xQ w#ek@,i嚒g.< khS^M% 3/2V<59>/ժHߓr4rH@&t=Z&" PɞeP;gm0_"Æ I@|*~x@0Iasz/9]^agGݜX,Iiݍl/p?HϠNh~1(q76覜~9ca Dӕ6#dGyv*$;]R0 o}nNexߪ{xfv3O-4e_JEv`R=r\T1ŜqEDQ` s\S)#dpRi>f~[(o^94BkQW}ʱêݧpުY|}L'sZNwނ@ZTH%3͵cFײK]MlJy:`&-AW0_۱>HZi,d4c!mB+smg. psfOqjM9Q R)ٖ/5e*3;7#4oLG畔2㣗B&àt<Ř T=Xb98NT COA ndlZ̽8G!е*ﰭp埋.t(C+Xƍի0Vet=I|ߢ]FBb`a9J(^ %u{ikMh_Ԓ 밿ˌB+2HjVͫoGrY#d^ =Jo\ M󑊞4BA,Sa@ W45̳S5 S -N殍uҗ?,+Iqy_sTTr]_g؈%:pQzЅ֤ɗ/ S;anPT-'U׬r_1F\\PfnOW#[yZ:-_x.N[XO}N^g^G| XF(i,":ȍgm5Z3tU*ulѶ1"'všA/K>|_RpA rj]u]"ӳdbK FS?8d Іk[#9ROη h&J:WX<^MnjޫsLU'[2-dGY| @e?co@ tVx'سL~g.:Wr.gmk(Iն`SQP:RMd+CW K6ߖۜ=!c@Xh{PV&:уVt@0TO=wI"(_ -d1X0G{wu-q# HkBZư;qЫ==ݎo/y[<`oap^' 6"7GrO}\rW+VV!ǭJmY.E|(0tmckdƭS5.]Ѧv=^=83|9f' G&kYZe|-9}7731?A&-@ǕD]q2՘0&O=&&{#I2 !z+EF 7ZfH,0Lk'8~u O# K-Śܙl(Xl5qJHld Q\NVú#GfS{Ǟ :SX_Ou]ԥKl .)#'Sn_cD^[7.&`EVTyOqtʳbaV{yGD~4Yq>fm((=v^uFCb%w-nE(5;bv} \4y.%^ɪs)m(_4Aev b3G&VppŐT:s4 7tc8ي>bBMDyHq7PRSf5T`9^Ra^3܃4 \0@Z!i5yzO%4o0gq O+9Q]iS z|ĦI,I8bhy==9׹x)OkJbŜ!TV2!* j7T2 47Gm;@|_8#OL$/iܒQ+1Õ +-4mM((6АYA -GI1^fH݊[L(ffr}Ղ8kL@`.PK>)/a2K E? C֯h=Q^܉ |9߬ځe*wN6~zR4:iѵÝKDX[ {c <"L:aQ&C5Pt?>@&H䧥MVK}NC #Qo%a`ULG1fgrr}lN .& $E;k/RJGNB;d37sb;:\eDҷokp5ϕ'PrPwg+[?lCQGh'M)KGVvbE: ujħ%Bqi` eU 473odo a Hr4q0z,a4 oe 7-X&+,j^H{cƑc6RH%sBpNE(r ~5pÉ*بp1EG~^:Sc6,r?eu\xHNf${<" &F/#{Մx_@Ҍ{˔R@4ZO`5Ws%;uƃ=_7lnU+|JQS{+C(e+U [h -}߬3}ؔUBKO>(j3|Di/5;>-o'hbtxZw@\"Oq,H$ 1[HttșNj ~VaZjx.4GdB̦&hHaM?nD$+ʬ&=;/4Z-ZOM[5b9e)L8:\kԾݡɺ/b-mmLz ˵.S=nhױʭ_UjWE ;̀lvNмfb{P˳PEQ>w`1H6I=L pgm&tŊk}FM#\A`.F .꺮=k<#V~8̟8bю_qJIen9~YϿ_>_-w]VuM%1JCG69q4czFm 07Nj_gʼ$b*f["y(0낛EaYyt$3z&V3 ^DoZ Sِz*2/YZUƐ{aQ@pMK]FhW<t>,ؒauVBQka!b"cK@<'O=jZpCB ?gA{ϷQ u}I=vA2zaXKOMT3lDnӨ "CَV9Q-Rz`#E0ƂJǫ#% rX9GY3XF>fn73qrPq#O:oVʞ'BA52B;9c΋ۄE㯴Y5^.3ڑ&4 Q%:@Xخc0--Tq~ldl,zFkSlqP.yPqQcзQ*8Y .|nLD0wϘ>P, ƱXI7xOw1;*ڍsYTb=v#QJY +eVL1/TCO8&t]VZFwS|A킯nX7ѪlxތʡRAZU%6ȾT-Eȥ$#s'y c:vM r8DRLV玂TC>HsI?l"f\"m9/BDTX{_kNB>vWZ&)KS.ʟ@lij馭+]7 4c2\68%x(d@7 B .5l0 z;n8#̄,NJ5EG\ԌG~&k=gfJoYΡmB9zs69NrLSO)~Þ][J^a_&zwJ=D :4)y9yg ;gbl\4sUTԐ>w?(|3o=LFdAc2$76љ(kv߼5|o)r>[LZy4_˔!"l4lћA}hgݐhJbd+zʗ~{UHXL2)1&EAcewEG5Gf8>f fjKeP{/w9̸,mlaQUZwfή!%J|]wb`.V;MPdx+] s  ?`5mO͘7aYÍ=8h#Lߓ[vJUᦾ,ތ-B[>]R,ʼYcOlWe)E`2Bd7&=c{0,]|~{b۫Eh,v5އiHΦ@$7Jz`W!WCneQ-Z1Ig^@H򐶪Ə*+^g ,iю36JnS_?Q.Uc2 ɈW bz~IPȄO,{C)Mz>*CCa,w`̝ uwwyaFO('?'(ʵ XR= ׏ x4Dn?Q$\iOm7g{K$e?UDvU-K5Jhmom=S'[5.E1|f vF5\#&)!. ]e7@%:/餿DP[ݶj]n8oaچ,6~[$+U rAf%` #=/K2DDx_ Rխ mc} 7:K<℁4_k 94ݯ{{vuwpv6p%OntB^~cW *ʙ+0+)SS?G l&ޖ+ $jE`z.c]El)j k_2i#d\LS+ŐɫA61-:ȴDى:MwO1c";M~n;|CnMCIlq, B]qUM?Y%I3ں2Z5|!>*H+bXN!8D+GoYR͔-tdo}6-Esv68 I4噂DKqBzwז.8rNŷ/7K`<^xkg:e[T Όzy)]ZʫW6wՑl VUq %T^uxܸ峅%gp|#d\.JHZ^&om?8Ru S) ^ł:Q*F~3)j bs5=XJ5m+mlC֦$7JA&qlculϰ:iX +HN?%*vFILʙ1( H@sQ{+ ށWUZRe}wl+ F EQW6.hL#Fi;^xƕ`  6h'm`h~ ay+TJ6Y?6ájrt3fR`e1_x1 dNT%K 6jEz%i}C;>p$BjpH:Wn/JZH>yY?^u=$k8@uL%gRA!cr!>š Jfo%(bIU!ѥʒRbJN.ݘh^z'BJ D0;zw7YaM_p.d=tViAŹܒf<]1pNɢeIE3QO)2`* WS]P(&*0oux}yݨTkcFgY$}=NCW0G9v8q5[ 5Άj:G,n/'$T*cC5qvz1BvBhm{zuK%0>GTN'f^X/:%r2*u6^8 pl, sw<6O\yA#lx'Ore"EϲȞ6K TKB' ^u@Ůl6|*nP22p&S"IĘ')< b0B- BވC<8wp[5}@] }[w+^ìY:sDcL"s-?.6.! q>&6N^SC>tq0-fakid&ttN!əS43?w^ؖz08q,́<͌ Q {W*t~趇-NS{x7I1- CcZ]ya|r6;{M<-xLSY^!W;RiҰj兎{ ]^3VT'XqNK U7{vQ3> ,:+uI&(f$:I .e7iUյu*f[A+ rNOSQlA,Yhr@i ?\⸦6A4A! ƗϘa`[(&L J Un]Oݙ qdk`KX[Rlĭg#y eiGWK;N bn#g #C&̤!$@? VdumOؓ<μTG͙7\8%\TkEн_Ƴlr[px;ꭻޝGgJ`'f1g`>DYF~|V*)||y,@3$f,L9 p<ÿ߂c"玉AjNs\6$F /٦QL';^z9>M[o4=t>h`i?N,јR+V&CO|\gͥrp6, S23Q,"8$xݐ-{Y?(÷H+ɖz:aJ'X~/NX t!PV D '; ɿ3=V]d+({1RE!;M}u%x~?a Ls(ahO}q ADԷAqn~ WO )>PI3x^pH̏ce8c}{Q~zZ ʃ*qzmhrNy!a֑^1N1HٟCWy/&Վ1űF${͌qn%F$$Bl^yuF4&Qo7 'kGK³gY>{d #)SXyҢxWqBsy]Qr- 2 ,I&OZQ;d$yUe @tcXNmAl,}'鎳L]7bQLhعv~٭Z+ԩHHm7lNh<4DF}@wCR <$)ϋ劑z8rr鹭vVɟ[Ap3HHhb'ːK>,Uru6F;Z@x9(&4U胜Ui" #}e#iJdB<ۖXo^)ڻQF{Zx5nFى+uKKw0{k`jX gJQcKBP ; v pUTj^hS<dˇ!4}2ɸt!ÔpQtPBĞ߷s8Х: cfd,aVBy%"8&>,p乻?3Q jbD Z1F J='6c  WJ.>%y:J/q}-J*kȈJsBzD~B\/=w9%qPÏt: sҙ~Sߝ̈4_?cd}xa؋S^h taG ; /71S tNUT?ear&hpcs/{rX/Yr;pdqY?Zlȡ!d[{&tFKJ$:-4Xos >_(AiI)X;>B_g$5$&+̦0WsMg#[cm Bspz*yEx2+(*xb?f=8ljȘ=$hWǎZ*|C磈kuJsNWF, KhdH* <[>u6j+)gg!WBL"SylgA{ v5#vF ?@☰Ɖ>ۮ AMh/ ? k'6 T,O:ZT 6qD(NIdӧ)#0I=ޯ򙢾"06D.Y͘#4]l;UX}I?,vj$`\oHR`pHH`@XCV7vdNe w=돏DslP!Sy` N׺%DfHC x~;4Dvh.j:=)O厘 ZAID]jmS&}q<kbv| fW<2hEH.Cr 18+NkGuQI̹N[&?JV1K3-nKZ{L涖f_+ۺNGijj[E=<{DjIƎ{q.y$H23"wi%I}aB(*3jD{%Y1t6蝭Cxn8m N9TE ̽NzCvNJ¯U;5;tWJ,U[~`Js\cq Jڤp]SqO &$"W"E+6&/ N49rpߩ@2 H:,6h(< m1[w&yX"9 peDp#"b57RׁlZM>"1f$"tmϴBa.YItCNI,Ig赾 s5Ņ);(?VcY-K[L@c;}zR-_|q ,eRǞLhgW;M.F΂W4 2v1Z=`ha+8N0>?N ;R[:*9~ptLBJ؟@nq{z`XJyw #tGRd(k.]RlJN BIЛi?H ,8(* Y@G928 4+ׄ!{i#lwЌuHEuRZ)XsiL:xUs?p8cwy$蹜45 C0 51ÈXkyK]q)/=?,Yj(SZqL~B_WbQ!ی㰭Pd)?)-]z39\N)"*w>j&f+x|+A= =#nVkږ#_)҉|ţ$bHv-3?okRg+4 {J7"#o'[~S?J|ѷt{'q[Ax!E'{t |7a)K!P,K s6ߋ&~jYKz W02a3#o->g<.v2$Byluw1"hT'Sž{\kB U.g-H$`-Clض`_L =zY؇K;=@1Ikd3HVu7PK[C#LD16AJ(%FXA0W5: #…ũ6ڃiEE~&U i β`+9DY~ > 4;NZ97~ >!ω_88ze:uJ&&24DE]͒hro0x'&2>5NB'M#}1%AvG,C*^rgG7Sf/Yr7嬴lgqOI QoW\AhH8?",# tL۷]/fl) S9{sy"UoVU&VW|Mqlf[-68:lqa:A*\5o[ˣd#J /gtop#[dɯ~uUԒ .W/'>&8\Ɲ;Q&+C8qSvg6!Ǚnq\ i􇜻o]JķWAo{ ֫O)AWf@ؗ1P q]Oc,٢OU j#'g$ º~`՜H7.%RrժH΄~(xvbb9Z}VDm:O[" vsQÊݳTB.䉣@>>U(H$0=>:- nGW*3D?LQV yڳ{cAL%IE_/_"J}֖IT6Ё'Q;pkڎۜ"[7b<0(YO~VuTro}#)0zT`5 M52;Yn|*VUWyh$*2WI F8BQ0qقkv n<g+]W6O0> z9:ȭ¦`gU %SDH__Dzw=7[,P+ SG ӌ! I9B emX 5jekD=% =~?h-f"c3ͥ Kqc]jtn^:ˏ`yq :{> ~JmR,iQH^?s=)6zkE$6F~Yv RK֓#&Mb\ ީ0h+J 2Po"o2uƈ[nFEaq ƒ%;W'Up|# ɽѴ>=s*j\;6s=kdC|I7 9hwg0ݎϔv&=P!Փi =,kTI#7\+l\iMV2v DNAҧQt @ ´?qף_NT LbC b&^CJlI<߈Kp"ؠPjzucd ᳵk+2Q֑I]3>J\ZE`B{2o~a$A_~}HՙS"ݓY`ٍȻ1})mbVmk6\(𤵛GcK҃!*XpRiN) g@Rc8ă"{YY]#ʟ< %vW0H)8MПZ&Pm)Q g9^.S'~d{],@!y>ݪcLHyqe0>79=B3,m̒9'p:2vp={86󹧎Q5ԴfS79`JI׈VdeBfyj&h;xe2G%Ŝ%W(!Oh}=z\lY8 & t5%TL X fQUUg a"DQY3c+QPeDli +>!p(#Hx^7,$=QC9 xS !_ Ie:4 oʗe٦2Y|Dߒe&V$B`TZq40-vu\R.@gzy4cDc1:Bzc"3 'MeAeJ޶ wUP>A[$e!K$8si {o{Qrs33G:ڱu=;v 瀣L&bk˃?3b+^s_VG#%y\Souuƣivu[; }dq0"%`,,N[w9r_yqٛ;XWd  ݱM9& Ymk|Cq+p<:;aԆl0vx0sӦa.iLUe2ǾNf`ӑئ1N AUB _qFa ^Tʒ(_a%O&`eI|vsKf'O2%8 G@ҹ;?,)QBUWt13UfZ ±=vZ0h몋kʀ7 xkՏ·pذ8egHoc`$wT*8KF!Z=Ʊ-.Iqdke`R 3F0 @Y_b :L .;k;eewqz=ъI,\>_t,qyy7ML]døym!=chi*4h6@f㌴ 6'6* sYo | 8]eHT'y3w%<t~#gea&ު #-: y; T{nMכ 뼺8I dR ++Q 3w]IfE

[ȴ>r 2=H9e/l*+F3U.EՆAv1iX j'h7e˃O}Z"c:BF-MR3 }Z4?ܸQ8*vʕoCU_-J>%JݔW5|8:*X9Qƀ(Y串ĩ=r!S+{ (h5A[SɁ? ]'n`KтaFi RRO&JFtTT,cQ xX 'PNVw+Regy a)AJG5C#R^gBL2 /$>׏K̿N{'4= e]lqՠKc'6`Mӗ)6H)&qFKv%\3{*K6B6S)W^/LS%$`B>\s([pt{#yԫpbFD74-kM+y! )ǙA4 1 S'b @%{V#e[ͥgxaRCVxi9\'!d01O~4.t;TW,i"P|'wV+[X%U<ᛏI68C#t92w8oc$ɔ4v1#t2s^[RqSOm_Y}GyX}?P^QN-9)ZS=aOك׸ǒž62@gWe`5ޢ D.z.`£.Uv fКGۊ"Ȅ>aƄN1QF}2w%)LO3w2E4,p"8 sRJ*L下6nH2IhUW >$;%='T^[0(%e91)ce{(9ؐ %>@빺|9r`͠360ߕ%G ; =L4-H9A܎7Kgc(F_/ekSSH'),0t; |mVqbImBdJiYٓo! m,\t&sQ}L*jerܕtP8lIFTp|$HpxQ1W#/ H`Y fIGO{T ]/R:(8iTCͪdK-)R8ypm]Dmtԛ_[w8MJZ'߾ D qau(=h\2lù0"k';r~iurw7cؤ'-ta 3,0)"b<";M2ǧ|x#e &B4՞Co'9X&qGXϛUf,9Kf /9`kt܀Cո`El$wV;bc8@҄Tn!hˑ K̃&-m!] ͡BvTIK,\Q'WNBeut~H}{t"[5{[UT9$#4uTI)(H&lJ0X/M72ĈGǹɈZdSxҗ =Ui <6!Ԏ[6OEF6^MW uVCO.N'pFUGh8F>#- C`1\./pE5Rλ{&ԭmI%ƈR洆I4ǡS1 q'8Uа$1"?̨ebw> Ƴ:iQȢ h qg1(gLoS;zII~U]h1#k kNWA+d,rplΖa`qx_J쯾C܁l ǀs-yJQÇ {?Li~E+u"e_T]e}a0dz%c lۈ5+:L*ea&w ]ƥHk3c.C_>rAnɼAG_ؗ=OYi7Կ)hl2u٣ST 6µw~<̉_;%I.jP!4wVk~"k_('kN 'j1 Mxf~y lKoExTK[*,v1U L_񚫦;H7>:U?_vO:B劋-3-!]D$^p@e[zf\ñV{(˭s?DX2V {ka,̝mA.]Q/u ~1b0|^Sp2R3{σCCXpؔ53$2se!,sLI"ѢJ9WY}q̘(u6`ߚpԜ6v?ݰډr*׺Jp>c=X#R4 [wLhgw۹0yFD>+&2R{ڏ4ܷ} DJ@]Q\u.Y`wGѿ\REf˄{)xTiTYC63Foe!DtQPMmB#֜(@AJbE:%zKaNsyo`< wOZt,o"Yz)Zz -^^rcT'Ask94D1S!_C8VԃzsֽdeJ+.Nu9Q%iRI*[(LV}7?`cѦ?u[qZVkYS |J:T`NQ7Nxi:$BxICc^$"lȍ1a=,&7?l=0 W^A ͬls]ӓd[MK;_SLLJGo&VԯT$^r(HT? ?a2J92Ebml8}$7%$m0QV DW0g]r}jf!jt68Co&\xܕ(?F5_isvUtF+ ގ%saQ!ld"0=jf ~ iz߃P ; QӁ6qgZB]LӺZ+bF__S=A$SQ=?8';b{V o>R7DF$ĿcGNQ] +D{ó24Edu]|B_W(ꌕLOϼ-]h917)n'tȆ8#䬼H =~Y>fZp ?%%tƶ.M,[ ΟB0 _:{XhT+jʌnz4k=l!]1ǣݧz +DQr+ᩕ6tʝk(FjOmoI2#QŀJ;BP3](: B'z]0W_bG  9L F/^+n0k\6΍hA?7wMƙyX4?aB-nٍ,nMY["$oI ӲE|h[СxxYCerC[66) Eo;<؁@䲏@&$qbܼt:?,&={x#'%W/i#vOe۲dR` { W0jy@H.gr7]HG5]|2)F^Y 3osrz \8}-sm:h )2SІ`y:RZmX\䨗րiWՙ tEf-̒Ϲ~}oab98l~F>JFn(*?2&* Aq0A7ڛB:hD Pٻj͌f5D~_R@,Ci Afη6aۏL 0\C|JُNS9_&pWSD1A'rUM\  q &{2gxJ8q9~Q\?aNH9pET D>"FBʴs ]'8_f-ݠ;a̡ekQ{~RX)KNDfh4]Rٓ_*"Di9#dr=K)./F do 1!f+@d WaE!0j墛4Ʊ8lҙq;7ěhsz}0"0n{3y%DȚiN`sN@뉾A7uUAL[tteIdcTyE/`rLʠbG̡c#5/w&Q?o%e*DJU!'†WeiP%wu?ڷ9y>GvF|ZmNsfBb.NjyRM ih~h+ȶݽogEJ0]9Sǚ=fΘ@i=g(e>w{u`/=,&v0-YQ29g*{Ln{JaǴՍw5uh^|#NZYҟH&K|\.핟5h(|V:R\{\.9":Fi:*_qlPw%a{f`rݓ=<0lD #4ܬ)5B} JK#|PH_i2_A.*ŰZy9*8cbiѾ]nLd21*`.d _m}p3+uv`,*DIB팑<^O.qqVig,13`| guJJd͞OK$GC}`K9ѿF6c5#F0; |;>#wEC,`-HChlH􂸣nz4+/|X/7D0-8 +$v}4~0~W.&Pk|NbsYiSu+%{3L"w>);ͻ }li7 āhʟf_x&,~x݊Dq*! FW,`WH`0_B9k}> 4h?q*S̑<* LA${PP]ٳ[CoWw[~d1GmhI^Cnw.ċ QI`&LیMv: G4) c OԸ.jڃSU<6(w \U_t;Y}ksuqL @ ⬍&6Ç"kn$"#AAڟ ɍbωOM0Tk%8SuR ,XT9TLR;ىܽ#P2Tp NY/.1cnS0\%3n!w}-&0!@zğ7`6@gBоX(#6!s?p3 V(44K?5ՙL^"%P@*܎;[ӎny~|6"=P>Q似22;Tz?3xQ|^oeM7$ec8dq@x SLתC[& li:c^wq+7v띈۵` RhN&f=|齁1>@|ٍ/ $NڲuvJF[ 8#ŸRәSGXH9JrwYw-qȕa`(Z'hw̠It@H)BPB#Zs %6!\*̙+gPe]=d{3#.?vU긥u *6 .7~! nWb5Y>Pͦ(V)x0سS-k''_C~bE )~V~&E4MdP"ǑAeꃜ k$Ou˔]Lj ~vVݓ>(<ћ/+wY"UhTꪥCs746=-7&2傳(A5X)}PH&u僈9e r2a:Ø`\fE?T/ K%pcVǗ~$UIk]Ze a@hof΄ue 50qC1A`@ԡn8SPQ.Zud}RECj+?qVSrzh(=av+eEC"@:=m.uo׻TXU3̃d$"9ӵrBetF,Ҵĕ)}]D g}&cIHH{-V_ ʓ+A~KZ.sXHtOWHn;껪):'"cjrt89ā{Y˷PxLl] R=rWA0T~m2q*\:J(̚tr {ƽOqVXA\rhE6PЇmJfζd8h!o+:lArn\ 1uvkReu ^Pm9H o`SyYŻy]ypYm\{xvSJU; wT1 &7f GUmu5wU2Ps#̗+;x07Cs&Zv J{@R{*&&8voJ-*gvTd7AX uEN_o {N1)pV;Ts1(4´<}f}ǮJUtZ*uGk8J)61~_]; M?f綷U8#ȲJBx!B_LӢI} ;9;ip򤖶QUbŦ}NaK&`jw\ sk% ΈXx}i̓ʸJGtm"BJF5.k"&&FAp _瀐ʑ%N10_sDvsRǚkq|KS!`F(7` j-^7Rbþicx@->/<=u/m*X|LSl(SJQ`)POq~A6[ VU'jrouBumКbj: TN Y> [ŀlAjf>8un`8}#`3uPw&. ffAJa h.ԷHzn}geqҒQ*|U&pB/ʬG[c-buz7U׋0m4QwQ`u@GY R$.ࢿ LD[w`~2Qk i'Zsĭ >ʒ3Sz4zK9(kuC)8Ga魇Q+F\ux*۲(<>0ex^rL#Bp$3Y)+ 2w꾓%Z']pY$8q ր?U)?ck&('_YA]޽u/iTrMlx^ݙf lf'41G[+erF"mB2LҸ)c{(WkpGOۦkeO<ȲZk튃G>*D!c''_ni=*c7p,%svTzb$ K"7e S{~M./hwB< )8<ԀF+On^oE[y˸y#N1nLgD'QoҢɪ13yW_r%N$?W/U|$K ۴u[[Ԍ p[شR)IBI$:-ۄQLvVޕұ=uޓV 4GqP{x]4Um-@88ֈ)SS{hHXxu)7<ο 2' xYxgߜO鴜脋¡xF" v!\UNJC{He9wEX@op<K;"j(nPx+8 ܊I, Uti޺Ӫg!4/9MG-IP[jgZm ' Cf ĆF+@VY1To 1pW2xL$J/)IT:F??`ceh9ҭ%k qU־ڹDt=K{|9$Tp6/no{6ݎ#\ tW,CH[xbQӮr27MD?Z#Qbaeѓwۗj,2[K}fz"wd 10kt=_n`<ROVN<K sDk荕$P#[LJ"ٖO&d'en` +v _:vFUQP݉TU#|G?ƧOq;Ex8(ײ9g4~~o?a#MVA;= h΀,O8pNu~콴0r~<WI!% kcTv03В9v;#4N2rU.M>078[1#!w{dK{zΦ6S埖qbgFToN~|*79+ZpvPP|?mO@J!\a<^W:#ьuE*x5b0\O P-<,t=yyHnb5jjG. 뢿bo?f*7^Q|QisS_S" 9k7΋ X> H=W$t\|!qFGŽͻ~pSݺšF _1+"_.fZ1Κ@G%"d ~ϫt-6S0|vСH?kYr r XdLP$)TvIv*:Y41Zу]*kڃF΁ۿR^ZVێu7+6$A4])eѲ Kz"w \e:ܔ9X16ˑAj+<9u ??ц [8_LDWXkz4Mxňd1->9.}J,sn"0հ3߂&T!R՜΅:׈xR,o@zȋ3ϖND33õ&Rke顙>D- )a&r ,4ISy8ZH/Es~ak%A'т;c<kafB,]Rkъ7Hnzm@vtK,(M*pp|5E1gOa֣F FGˆliAijnH%D'{k}0+ӯ%M`;$ l }Ir0xt32nMvMps#CR>'yW]*R[=p2az)*}(>(gq"98qKL=vRךcI~Ax:($1<1 Sџ9e͗ B0j-f:~XdO $GZYҏ˃yv/&z3ұ?Eٲ]xvMDȊbLdn|*Df{t?{fDĝV'W&9I?9w'R23R&}0^@ -^N&HҌD.#fF_{\t8>'mMd- G(5P&aNʛޮLPXs~/ǯ 09ZqdSe8a~&zwW;2M粈p0'k7aΥÿqKSV-1SI{1^h@^L 3&B1V後O1)U*Otn9syTm"wSgQQDQh/Vk QKegeV˩(pG/j+̻wyQ70ܥ7GúP,;97h;c'a2`ܱa͸ j|Wq$i(=EQǝOaBZ CK+Әu<;ߙ 26 P;հ-8d(,vOy0;5P5ćKwI* -+hFVC/q2-[9!vXy>FiY@z"ge/Ƒw 6TUŀ>DI:7:o@hCw5hr0K[֤YB,29c鶙^maW N]13Y3hvEIvZsr?nNDU87*)0[;&&<>+/nM95 z0D1h <ݜXVD-׬fXN,]Sz U}}JIzLaPVIV+_ecL@;HRewkݭ -E?>MݩmQȄ@9;5`@}[m*B_/Xzʙx'UPP}%P_ZQyW\?!|:!F~һY֑طf biQY{5JX8(w H޶ۭ-OsX&F5>}ְCO|[5~'~័y+o@a/-u= ܅ 6 TlV3;A|Grȯl]x.$=և>  ? l0q@H"RSFݷ NbCU؉*CR7~Ek/cNڅfVf_#ȩ4G_7K8éruc$VLIPP顑>=k,D&vΌ5yu,D/pdxؿŋ"_( Uzc 8fdtF9 m/M p:4U~׽9gCB Zvq`kyBpgYuSDhe2 Y_uDn契x٭fS˸oe.%F֢{ۘUV qQ}Y;K69B+I\E1x~TZ2F1'1z[Ւs<5|=%%+1 DZ?xޒֺ~93Of#b1JRKz Z}r p^)U[F܍Iehh8wٞ;͖y 7ih/L G<0R" tr4 @|m{ówCU{{T>'5k+sN~lwN^B5"44^p%}fצ [;G@e8b7(" ZD-t \!An./O1n϶EAŜ8JZɧIW,lKO[XM)1ҏ#> f].:o"ZǛ/WJPp.R+dآXv]$&e Ϲ 4fccxF;3)|4a eRN=4Xwp06N}\Xke ,)S7 D*E;a~T.,F[H?h!lt 镅Rs2} 6Ȟ _o.(|w٫ .AZ"%&μ_"A6T8[ o~e.ͳ `W^kL qML—sճlL\NHUu$=aB|(8UoGVA{SI<1P)%˘bg~sލZk+R];5HSnI*FmdJZLȡr12#'yvɉMe0+.ZHD J`\؟uBHC@o>/imD@k6Kcy8#IH'|I%WL :q7;PЧz*C*0ngm:*4)<@Z SAi 706B_y7=4ӷ* U x̙%'"L_PJ3`+|] {ݯ$œDT$U튩]gs(qIUM1d*N#3c4f.-T6p<{ xiT6> N/_@0pUݞ ^U:[R,Il a}\h?mf7b}ƋNN;0+'-1>˨ukvqX.6͌N #[, \و\K`Mv0^Rw;Ʒ"j|sv6HHeͪƒ9-X;uc2awǾ^aZ~Ȱ) ˳:Hy#oGs٣>$ Lա7'/29IX>H|#^y\9"҇Z:9V4:*R_;4gPf)fɬ%D\X󃡀!e<khtx+.͂"aM>1q]2;g,~˅SЕr|_ .T(>1jpk3Q⚨8O\e@h\`wK2{CAN\?UIM%7.Y[Y<:H{91VU Ȁe«۝YL[]S&qζ;o! IOP8F󡇊|T@' >kgar߁n>DCBp'tHgȟF^ḓsKgߞTy邗=_MoԱL So9׎x= LfGZf̹R(CU=;Pπ%$pYp|KHnu4*ĥM+\/Ci8 /M}baA?Ȥeu`bdz*26,AHa@3{Ǯ\PUf]1eMc3~ P\߆&!n.QOU;58@QߞƎAI&7^><<󢣠)Z_JX5F}?D,up"I/PcyAhu jߠ@+$2Ê&$р#Xa#OSs8;""2"dHg_3~ &vws6Q״NtIU SyT݇I+%zmYv0HWLSO|Fz#N{HKP xwӤj%xW>xh~c/WNpq ZѢT8+`M~܋m!;Q3S-ǔ#)g S0u_5+ v,$`~{_s5Z>1e܅H LC48.1ͫJXC•n pH\8b$;x}x5Rt ĉ\\vNLT=q;++X5^n-'ZW["ngà\t P}[NN?74l{ N鉃 6g Yl`=oTM\3rZQ?|z+QIj%RKn(PyƒfUۗfXq,SCy_DX֖ax,VYi$GvCIx=I|i1c`VHm9an9bA#Q,;F-4v&ٵzpR%cnQK9a6llp^Frw@=r ΓHGFx%/nEC5s2m(ϔS䅅\)'dh;nznfȻ|`E<++ 5c/m*3E'Ўq"2&{r. * J18Ȏ=7oڛ@qKFof@FAels樶8 vAΩ@3MSOEx"^ުaLgMo]ӽ',9@<9e׎e&6/R zo)W~`*rxF'5FE rdnOn仳aĴ#?>ڟvjM rfP9'}.I1)HZ ~>0pȮWooAQQeA&}_?3|gm."%*1¸]Ii.\;u{Lt۵<[#_wiVXi/x~Hg۩Ha`{fs2׫{=(%+s0p qGpߑ6v]ou1QY.5mԗK7ʿ7Qeԕ2XhP~WQg"Y:]2AdSM8̍ln FĿhQ cBw `z?y"Od2:${H%U:$r&;Q< B UY.:YrƗj~ͦy8N(rpa4CR Svӄ䠙0 P12fW(SQ$U7u^ARVi&Wȼu@5GJ g]. %ԹfBV83 X219X@ԯH OA_hFrO|^f@* s-CZp l^3-K$ܲ"tW85;^@f~lm,6PUASYe)}pd_PX̩ Z֛Da3e)ѥ}:}HW7m.[sC aixv=OE 1|ZR;^%ç.Z^[v-,QCǭSY 0k#tF./Koek~žGL]S ѣi $.-&"FMctQ{fu& l. [D7;֫^uX \,4+J.Uh|<$U&=6gyV@w{C1Ė)дl/żat*zJ!"C _W>%}"e;g}eH/ 1&"˽q砎D-b{24A8錹ORi+ƨ׮nM'6r@Mm0g]^g8\IWvo( J Vu݋[l3E$4vȰVbqB/`gw5E> 谵"* 4H@ SW3>uO"9Q*0[V!X+ ؖ@ Hqz$֓:qDJ=E:`'GQlgPz,E}Dm3rEh͍x7xҷ4mtk<.f֩5 %ևϙ>rNE<?/Y ̷aL6b΢b,v]>r(>aOD)i^BIQt!?aj6Wu5hJ7{M)-teEE*"b :&Mt&^ª ePQ Mv 4{UeEp/4] -6a18 d[trrX^|N$%~_fS˨#^/a;ڙc ]Xi >~ p^Ux^)p"؏ X3yդWF6ܜXXkub ~m|H6mLztsSGXFm=c)ߠJd]p3 ˹]4!4WB@e@aF'D>οgs[þoU*z w۠ޭH/7Mӏjd$mf/'[e(S^6oLT;ݬHJo :B[IgZGG3"vMNNr|?d& s;\\Do*e'{qXa]^2Yu .ܖwR_5:b.!Lt_:֘(<'[Nt/~CmQpFV\+6Y3ss{?kDi kj9Oom+8wu>~8m `d\T3J9f2Hk|J؉K^IJ;{q[`t\c+^KK( na:7[ %o҆b!1k=n n>w!D1?M$<%vK `|%#U|MxVTAˈ%صU1H s`?/&^o@$[Z*Ifu8R}@G!گ):}Ju Y!jvyԙ,nC7ɭ3< yՒ/A*L䖑p훐铯b'P]\ AԳLSXTx-#5X9eL8' PgC{/ҋ@=Js݁05?6Q|t_)4zÃ>p%xץ"e//5h&}2sfญm^h1Dg42^MlUp.( sp,ցú0 UhFԛK!QKU@e=m Hr(D!kJ3]GӾ{gC'T.pa#d.g;S,s(UISO1${l` 0lEKZtzF1Vq{ytw*j4Lvh4Bpb(OXgwUͽcfIkw=(j ogSwR͉F 7!ם8}p[7z(T!NDLo-S,#Dz3Xr'!k~UnI)/Bh&54D:X$KӜA1Q8qV!<l h|yGrwA\*f]lT36o̮Y; -!- &K ^2"3Z "L4ߏxIsYM'Fjq MGoDL<9V.SzԜB,q.S}Q/\cۺN.v PHh~_!yO%ψ}M1Τ;n2d)*5ɽ1LdD}Y3g=u!70vnuxX {ܭ7]jle5RӆW7^ݻhe2x>)GuE; tIpmiOڌm M]*J'dS͗ûE,fDSw 'Guv@9J0uM*om6RӉCz lH-əx)GG8럸V!:o*qwdTY W܁P&"Mw)O&]u]]-Qd85< 7jdG!ɘ:IlJMP6- !EWtm} ccIꎥ:wu$z4gEG8YnfW>48ox3HԵx9ŐM?6FCJ:۴A#ޘXち6v7o)NqV̙#zJ`26OZw TU jWضo<[GGs;q&_>DKj#%yϯ  "eֆs c?Gry:B(D'oAig@)T(1y28K݆;^l U#҄}V"G IAiG3ۺ/>B@x1p%UMZ`ȑVO#t'JV8 9&&NrSWcJ1"%)%R,+&duQ$lӖPOpB /[(4s1}k52~n4QIr 4dwKYL^djna]&nF˻%7#ҽߗ(]} &A2tnuKSvi5͏yVY,s $sw{Q }GSP`Mx(^PKٰ$|*ɜG汁ALjXqQX4[6xh~Tнx)hdkAsQn*Wpjʀˣѳa o%d^w U h()ɐeФ;00: YZ