samba-dsdb-modules-4.15.7+git.376.dd43aca9ab2-150300.3.32.1 >  A bp9|"#{!n$ i`?;좁? p/N`!% r +֧0R 40BCt Pf1^֏wXGsm h㶉WTo*@%?4徨9i3-^.UG|Nvp^XXOhJ R}T*&efΆ?+Hr,9'1`(3[ H%9x֊ҡ3a?4 \Xfab2b43a30a9a7e99215af99febd1c50e3131f035e923e868b23cea287927b6eea4e86c64e2aa8b29c474467b0b6c275112485c9bp9|2GFo_ʴbXa@ u4z4^pAb`?bPd0 > P ;RX`-|- - 0- - Q- -4--0-tt),t()8)9-:>n>0@0F0G0-H1-I2X-X2Y2\2-]3-^6Yb6oc7d7e7f7l7u7-v8l-wR-xR-ySzabbb bLCsamba-dsdb-modules4.15.7+git.376.dd43aca9ab2150300.3.32.1Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.bibs-arm-62ePSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxaarch64rm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigp Hp HbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbXbX404a0fba9516a01bfdc53952284038ce0b3ebedfa049bf6319b53f5e8ca3beecd44fce4f77b42667d26c08e681bb95a042bd4bbecff51f9daf041ecabc03104af757e1d77902e30b1e32fb7d61ee316dea0bb2e98d326f11ee0d2a7967f8f3ddb366960722eebeb09ece448695848ddb0d96c5c5ef1ce6ec70356de5171faab817bfc178f5f11d6e1b30916c0d6af8f411c1bcea24472c1bbd81309cdbbaf0b94f1b40ba42db25342bbb733ebebf805a8e3ac8e1407405cb76f38ad2bec7d78b0e9ca16f0a8dddb118fbcc25b11733b6337e1b6e45d06377c6edd01b7b797d2395d49a82cf43f8222b1b570b9d32d60203b547c78631c8a2d8fb98f4707129b6a3a7c01d65a2c64452e667d8aaf9ceae5c9dc9ae39ddd2baf636f7444e755ed1eeb65c58a2b95ac41cc01be4fa085576043ec7b0cb762442855dccae4ff80d31a27c78c5b95e7ffdc8d33632ed9837263d5cd29c0269bcc366d0929ccd45af2912814fd40e0e3904890b12f89b1b9822345aac890898a3e7d93043608dfb2336b7f7ab197915573c45f86359990268caafc140195bebad8676475d7b63c1dd6f7a6ce14d79cbdce290545be5d041443da97aed8721f2262eaffef1f68cb47adae75ae88612264ad1b9e573d9e577f91b5959b06465b78187a6cd053e712ae1b1d4debc255ab27d7219ec7683a0f14966cfd89ef531bcec3dfe7123a1835191993a5d7c7d9b91ca80861e110c1252fc018d97cf11b347c06025dd64ddd4354c9baaf32e478cdbbf946efdf9746bed76a304da7acfe01b172ff0deeff6ba422692bb799b0933913ee6fabf525c9516a3afa6b95961f2e112c9b48fe8697e9f20bec232d9cdf53033c294d89e21719a412008726525d23d1c6d7b9b1dd3ac3561f6b141994ba0833a06733b7654ffc868cce0265c7b3ebe0af2d29ca80f1210298613cc1cd836b710c91fac618192d2a3124c488a8420b2006ef1c6ee8679f114a2a879173ecd4347fdd9092907816cbd03adb26522fa0bf80ccee35d02c66137abf0a380333446388017f1e9ec207a71c60d96ca404d7aadf8f5521c4132c75502f825a0cf59742486269b56bc3799d13978fff3010e390c8712360db47d23fbe3c80ed35659c403c2018587bfe59146f2ff8d2778d9a3986b1e28975da2c6817ba5481e89c4b8fd85f87bdca6b90f905f35d990c3c2bfdc8d5225cbd745ac1b68109b11cb4b4e73c1708295a097cea89ae8e87ee5c812b1728b64efbed57c237564d6a423de93ccb71eaad1fb2fb3c1ad46e950402cfcd1809839982d029e3d73d0d470a7597cc599ee05dd83ac610e9d553052d6eec668c38cff3aa66ec00f3b527e7e507324f51935155374dd48f987334ad6d2483f045c00ac40cf7a4fe018a2fc443ce65af63b38c2d872617e6b6098a410038b7e181b6dbbff020c0fc95348989e6dcb177dee4acef02a7680f4d54714f97ea89abfbdcfc0cd3c29afa3fca2645e266ad030d70de48f6561e4a1f5972adbaec34fcb05a9b9688c95297b93e58aa7035d888f426ed80accde5b682545bedaeb07c6458482e779a9c59e442e20a7c478f1920cafa4bd36960483faeb9fa8e276bfc04ceb9283864497f5c434c1293f5f1ebf5897bd8d7b19301c141da233cf0a2d74349b82186de2aa23320d05c8cd554384652214905ccb0e01945736c2ea1d9c2b6bc031fb1958b7b3a6dd70bcb896907a524f65df6d4561f4ae34b67fc1f557d6496a396e2b49e4034f6c4529a5f17130d3ba71cd5b6d650708ce0b77973ace6580f13c27cb21e937f7f5505aa310f10748bee713a9150ea5186acb68b3eb5c345f0e392fa428ca083508d79b4852f02c6becada1800ea5f8658af1472d9441572f380d6201694ac049dbb70aca0c900ce643ea13c2859a1ea7925c3d5474f690a457fe7cea245d7c03bd53668a9ee878a87abe0f3b837438c34ebcf6bc7562a0a40ba3bfc3b1e3cac1372fe4da239e8dc1bfe950f79c7c31abfefb78357bce25355c4a3382b0d9af0913rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.7+git.376.dd43aca9ab2-150300.3.32.1.src.rpmsamba-dsdb-modulessamba-dsdb-modules(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_AARCH64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.23.0.4-14.6.0-14.0-15.2-14.15.7+git.376.dd43aca9ab24.14.3bascabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigibs-arm-6 1652865177  !"#$%&'()*+,-4.15.7+git.376.dd43aca9ab2-150300.3.32.14.15.7+git.376.dd43aca9ab2-150300.3.32.1acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:24194/SUSE_SLE-15-SP3_Update/c0ea892337fc5048773e39b4fa88f344-samba.SUSE_SLE-15-SP3_Updatecpioxz5aarch64-suse-linux  !"#$%&'()*+,ELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5cbfe7c1975077ab49a081ce7251ee00f70e03df, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=daeb564844ed7525158e7f5745c1b0018d29cfba, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=75801eda9e4d76a8eea031ad35ea71f65ae31305, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ffae0bbbf2a7a603e2cf6b844cf53b6e07c0248, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=49355d49fae04d1bbb726982cca6e3afadc0361a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d0503898233149f98056e0b006a4b0ae67db8ba4, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=354eb47e6e55b3a942418a98b6f216517080999c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=079b974f61495af7174dcae5bb5704e22c636f4b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0f97c107a5f6aced7cf0a3f01f6a65e9c8ba4811, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c7181ec977b2edd7e51a5daf6097f23e9f301624, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0820281ff8775460732014484cdd3a6c3b87c6c9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4b2967e4b8d8978fc4bfadb0ee54dde1e1f67e2e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6b4e3f904c779fd5d7d2164ca58092413ff0676a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d3babcbe4b06bc492f088c536b0b495ce5fe9819, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=61114e3f67497113b6a57c22a19620e0a9d7140f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a12849beff043e062d773259fb8efa9aa46ebb30, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f0e46aed049f74bbfe72311e93ea3bdd5bcc2bd9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8c4fe7574a1a403982c3bbfa5d9c1db7ba5cf21a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ac0daff6cdad7839183837c7cff9688494fccb1d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=479ce276580ba975e04d6081237936f6388a3329, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8e02229ea2b57b24bd0591191f2e186c80da55cc, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0ed7873742742167fcd08305fb506ad33c3b2892, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=87d64f64c6e16b625319ca2c1200ed529bf9d711, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=85be72b6c2ad90297fb10cbf1e206034feb4475e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1680e526bfcea2ed246a79cc64f8bf4a9ef403c1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f18448d645cb76415c91ef2297964150131b9481, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=09ab23a181cbdc3ae50a2d5495e889a90d157949, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5f03b989e502cd8d444d40c9c93cbd0216979788, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9b7807986fb8b402069da07d1dda65a58f95319f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=eaea8ce016f711cc19ac9ba9108f0b3ef1db9088, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=46995f824bf2c2f14639353b3a99ec56c80efa71, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=34a692379c5b681facd2a69d86151bec420bdd8c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=80fe1993582d55beb1c3354f371a7a9d02582534, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3cf8f4357c890b239cf92e2076091222a6a0bc46, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=699d35c30204b0e65982c904f9c9554014a4b461, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0da2ce0b1f24f55f33855f5270956c97f658815c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=443d41ffbf09febcd2e9ca892e3837a92906ccba, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8da561833c2d21c4215c08e615c5beb7e624e565, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f740a4b23d54d77b01b2a52ddbb53d2972b5d935, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=08b0f06f927e194ab0e2cd408c4595d900221496, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2bb09e40d25d4bf67b86725dbf3e529f06b23759, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=878078f3cf4eccc6fb7935c98ab85284f11c3914, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0708385fab2578d914abdf16446e9b8172724bc6, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bfd9e5fc6e9532455e656bc134a0fe374c206eaf, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=34faf83527a16b633ca34d5f2ca2b05167f7a264, stripped9Gev(CNWny'1Wd*7BM_p   7 & . "  RUR[R]R>R RRQR+R RcRDR)RR/R-RRZR*RCR\RPRR=RTR(RbR,R RRWR>RDRUR[R RRQR]RcRR0R5R6R/R-RRVRCR\R=RTRZRPRbR,R RR>RcRR[R R6R-R/RZR=RbR,R RRRRYR[RURDRER RSRRQRWRcRR/R-RRXRPRZRCRVRRRRTRRbR,R RReRURRcRgR/R-RQR RTRPRdRfRbR,R RR>R[RRcR RERDR]RRQRWR.R4R/R-RCRRVRZR\R=RPRbR,R RR>R@R[RRQRcR RDR]RR5R/R-RRCR\R=R?RZRPRbR,R RRUR>RGRjRBR RlRSRRQRRcR/R-RRRRRARCRRiRTRRR=RPRkRbR,R RR]R[RRcR RR/R-RR\RZRbR,R RRDRKRMR@R RR$RcR[RR/R-RRZRLRCR?RJRbR,R#R RR>RR]RRcR6R3R/R0R-R RR\R=RbR,R RR[RDR>RRRcR R]R6R/R-RCRRZR\R=RbR,R RR[R>RcRRRWR]R R3R/R0R-RRZRVR\R=RbR,R RR[RRURYR R]RRQRcRRWRR/R-RRXRPR\RZRVRRTRRbR,R RRR RR/R-R]RR\R,R RRR RR/R-RR,R RR[RDR>RRcR RRQR]R:R2R/R-RRCR\R=RZRPRbR,R RRcR]R RQR/R-R\RPRbR,R RR>RcR[RR]R/R0R-R RRZR\R=RbR,R RRcRR>RR[R/R0R-R RRZR=RbR,R RRDR]RcRR R-R/RRCRR\RbR,R RR>RDR@RSRRQR RWRcR[R]RR/R-RR\RZRCRVR?RPR=RRRbR,R RRRERDRcR/R2R-R RCRbR,R RReRKR>RURRQR RcRhRgR[RR;R2R1R9R/R-RR=RTRZRdRPRJRbRfR,R RRRRMRKRWRnR"RRRRSRUR+R)RRDRQR R$R]R@R RcR/R-R'R&R[RRR?RLRRCRRRR*RTRVRR\RZRPR!RmR#R(RRJR%RRbR,R RRR RcR/R-RbRJR,R RRWRUR>RRSRQRMR R@RcR[R]R2R:R3R.R8R/R-RRFRERDRCRRVR?RLRRRZR\R=RTRPRbR,R RR[R>RR RcR-R/RZR=RbR,R RR R>RRYRWRjRBR[RlRRSRQRcR RGRDR]RURRRR0R7R/R-RRRARVRCRZR\RRXRiRTRRRR R=RPRkRbR,R RRRaRcRWRDR[R2R-R RCRVR`RZRbR,R RR]RcRR RUR-R/RRR\RTRbR,R RRcRR R[RR>R9R-R/R1RRZR=RbR,R RRcRR R/R-R1RbR,RJR RRKR>RDRUR R"R RRQRR]RcR[RWR0R/R-RRRCRVR\R=RTRZRRRPR!RJRbR,R RRR>R]RSR RcRQR/R-R\R=RRRPRbR,R RReRUR[RRR>R/R9R-R RcRQRgRR=RTRZRdRPRbRfR,R RRR_RRcR]R RR-R/RR^RR\RbR,R RRcR[RR RR/R-RRZRbR,R RRcRRR R/R-RRbR,R RRRcRR R/R-RRbR,R RRcR R>RR R]RR.R/R-RR\RR=RbR,R RR[RcRWRR]R RR/R-RR\RVRZRbR,R RRcR RRR R[R-R/RORRRZRNRRbR,R RRERRcR]R/R2R-R R\RCRbR,R RRIRURRcR-R RHRTRbR,R R?jT& utf-86cb2b6fb0f771c53a8f83f1375c87af2f7ebae632bec475e98f5cff866211b04?7zXZ !t/t] crv9w!@t>ݼH/=|n ,R3 [>E|y 8SU`9,1B+aFYN}FQ,%Z\R?fa YMa E9Jq+5K U|";k\L *T/2M8*]Vj# O?7ok9ņ؝m9\Sо\ =W΋&{˟B enL+>yOz:ni'q( Fe ɼ.,S^&`~_ŧHkKAVl#n]^g! ~qe6 H#vr'ztNA|ﺊ,f{lqd EX $QGRS{:j MbG/` 27uѿk v+q7πU 7G6XRrBH?TGA?5e@z tŃ7իy!5{ë}ioȡd7czSt>AnoMο7{GD*DxJ~-J̆cP INqPXđN'i {" +Nngt)P)`EM\\r/^lZX b  &Tm wMCUOV[`)}K [Ƒ}B`D"y)pժ)hē]"^"]sQʩ^ĔG)A]`:h3j"//mƮ'Q58ӆ "itu|H|Rmar %=p[%ۖL_!~F2tD4Ư4D%KG?V/^8_{$"6hc*ml귴5ed 1[&Y~{U']̅-h$^t` EIקP3$Qόܟ/gx.=&Gl!JF,ۧl-ajвv1&3¬R}E oBnM/mGU*ݳSxzQP׊Ų'qᡠjp'g?υN"}9A:xqj~W[ӐnI0fՊ y̹ ˩;+~3 omSM@!^zo-y I?L8ֹD) iq7ՠ?*L$O7#8r#֡F~USZbUC`{jڡ|VlYۉ_0*2Y%]ô|7D6کn5ִ_mdE@=Ŗi)9DSe/FM/R4a(2~j56AkpKFPNC,%.D•)?*O½Ks@Ó @8cHQ-.3u[ zNWDkgky`u7"?Nbhⲅz.45ZyՉS^i4 窂匽id֡=O;o&Zsn\X"[zO**i]EsG2B&L3%J̤:h{ctBqtc>N_ՓY!aEl>o[HNh?#MֱA3P9dvxCsly d$5*_3'[Z/`9t^RVk[Ët&r6^v|P'v܇԰<6 C *`_0O89伾44$C9rN+PB¤ec1b 1dcjnoc7j2tUhjzZ_6$gEµ :DVeEo=/ZvBMrk? 8*|^ɿ[{7%<٭y~{OP9aGsZm. o(Wms9 aO,'E Ub((b ]@]3e mX,EYMBYéG[bԠXvVPoV :ڭK~\1n Q+mrvS}a F}VNi&š@?n_p~OeM$N{Mc;=v:y$!D[p&IrB [L^TI3dרIY[\y@<4ج{_bAY9=TB$ɐ2 úc4[-@!ܘlĔ+^t5kwHU1n >ۢ#7ePퟻ}ĶXCcc3'lXvܔ&~>y}_ D6Rg%{,+3:R[Lc7K =&Ҏ5ҏ|)1WC&,j?58, CS*tݤ+?':{# N!{X~A6|NIKOk"=2 Qӹ u E+3:ؑZz΄ˡV3U"e:JML3G)n.Jx-K֨hc۰ʾX<.PBߠR8lT*+kk Iyo9{k:ARCl졵h~e*3S}&2 \b%Hf?j0JRoyC%eq"Qvff@۬hΰBZV/J,Fbm?}EirRq/cZݰ;o}8+fͻ-ǻK4h<܊+>w'%(ih 2ѝDa;:*] ѻ 8ov c̜LA視aI+6XE݀.5DN*ɶm_p2ܿ*7r/;ksD;ck`|6mIĎ?zL"ܘ*|_SRsW;Eslc"%.w-&a){#AO&ࢲ%ŒpUTW RjHʇz󪶿8`u|8ab$P緮3WMS\=l͌#_W,MIbs`dG -P%NNOxnT@~(jd^zx>#_o6堺#̦42&5XA[I:e.C{-l0\LlNj̖\ίx߻/y_5>d,Z"IUP=CG(ocƝDI押C+γ1? p@#xd=QVi]bVkƦb SqB40b) b։iyCm ?ri8{ 贸;߮ N=>2D ^jiҟ&ު2%*{:S+W~)K?(%g>Rl#w+noMuD똻X6 ϡ.L3NOgod鎗^RP< }].KgM-@jPuRgNyh5*bxĆ_>մ $z *qsBܔ(5T| | |PCLi#wA~J-D+hR>k8*o Ā"Gq!lc3}ўdnW:uKw2e(id)|(ԛvT1X3ZGӾ@ȧ#-9\[E B #˲$@Z%WzO'AF4?ܷ;;'p*> [RdYJ]k̛~ykzC(FcBX{fzZluc;ԇFHZ iJ7qмoz?UZ0bAݝoQG0~) 1C檁]JKuԖS bP9/So뱁IBMsDm1*ccaTr1Xݛ&`Nia8~(-0RRlCcRZ2 |Q4Dg$)93Ę<ʛX^ϟm;&ק{ y,,y>28+JIg9ᅢ6Owە'v"+t~~^c֤\^4{"z4j \QQ}ܳ-^ T=[ b\q ީ߇n3ܝKjXmݯ;4x ˂ t^L%2G>DByᰋU'`?;d R 8$0Xb1S1ImG@CY`F07yK?CR-4Y?Y}ϞdKz*՝J[E[s`w2%}quںڇ6M2- ;]G%T1ޘ>#ٻkڸ$vP% _]Nx][ H_QY. ZLҏ ru3P3-4IeKM6QImk-q!d+Ǵ (<;O=/3J֋Tl@DŽdA=!g hOo<% b!IN>+cQ6" wxLslz_ 9M<ыy:IÏكZV\UQxl=qԁ9oXˈ75] &$N9vEN&"K(͊&3[z7fBcR} +s 3wKE.^6WC^;tp-`XI?f֐zߜfN mhvUP^Ŀ;:C g_792y ]oaN9Q\g q~#_wVNI953*b0 û5]S'͍XD֤ɃS`7*ѻoHtѦC~D"a=ܝ0%P<#jgU5l͎e]o CfcW@>6~W%)I]i5 ,oT!/MJz>w|o`O][Nn Y2~,[9X¨k u>rv V7:uY|z;j5/kb 4b!*?7E09UȡիZr5? -`fc 9o{zevG^cT'/Vv]9O/`="s=]Op]tjr=K9yUD<0,#2k8>)L$yS59͕2jx~깘R;]!,'8JZdѯoJ$`kK5e EJjTw0\A޻{y*5GyѤK@]0椭a}:x,k Xsh*0v}%VwQ- ->MA[pcb+wml!Ĵvʿ!?f#hfk (B^)G_RZVC%@}.2< ;Y K$u}:nS4 %֭fM߲Lg,5h88*qe6q_҆\*oYo:I0ۊXu*Id}?NZ\gevA0ekSk?"$mcH.1K )1DOښ֝uZ +"i,Gq.lO[Ϙ7Eʕ,C͖h0lyo2͗o].+ $[,)urrTLARw\WM|Pfyu"7źM=4CTH/_I Aqsb ;3j͜B?ܼj ?0@^G vmBr- Da~l%i딭[[ H_y;g=J=?~FM |jKmr4J(̘7 p'`1k%/+Su'䰫ONI6Vs+de\5\]M>!dL-%"AT`qsL6>>UiWJoVO^ϽQ3MTzNj-v` ;?IøqFȩRHD努(Z"VoB_i(2NwzKRZdVʟ74²Vo0N6v׭D.u]Qû|줏uFe+#Tu(#ќO_U1 #]z@8ho|XBlb|JY gMc~vj2 #g *rTp|c(Vq瀑7ʐ˃l q6 [Mf5",2B+v!5jtD?v:5.FV~ؚut:xVCɂ1@@2s23˚|(IEJet0FV<q%(-gf] yVӉ.i$(5eҎpf.hL;X-`(<9 ]ߚH \81zb~g=7S*i!6&"@\szOH +lV~ Cq%UZ4_-;S 1fNNҾ/re%T^\dv$fR?J$ hnq(O#d.}W^0 8/@<%-ފ ĝciעϸ .4 yIl%2O7lS&4* ruy00E&ϘLᓎ0 `s D~9cOlrvy^KjUo(D9?B*E!޿4Dfj:>: }2|l6ʾkԠtњ>u ǥKF%UE]8ö=Ygzm@:$=)(K+m~qc7 Pnm^ 5¼BDنen{|y䜁G\4up"j@M\trVbvƍ~a?@xLrR1x{5̬6ZT^]K=7k;f*m.).FI3 #^.)_x煣Pr?ßvqQ&G wswVf`_!;́~-g^X闝>~E 5>"AwCHZĥ-[,a'xR9*ސPbnas7h@aR׋33[J#*_ T\zmIZ;9 _FUɟ0\EI JilZ0_g'kd2i:b%t*OYex+9/״en(<Dݭ^T he^^WCYhf !d~A Op;cS:U6[_dma߫"=|#r0B:GHdIPoqz4@e8 d^q]}Ko{0硢9 `וCR:'#]K/p'cl% VBc}CJJR,v26͡ @óS[ܨzP:1B"vnMάluXù[1+kUjsj-NOl, }rbo}슎Ƈ%D)H%1$44?}hcMV7 )9a#nZ%;N 1{d[j`BroԎ2 kf(.ܯn"abNwv}<V i MIm>>KxH"6Joq7 ]a]0ŸP@ǚR{{p(x\tt&[rQ.k?z1&2iQ_D6QU5 Ų ?g=}1]O){uP1]$`k-Wc+?0ȟVs~j8wTyb<1{鞅HĿULV7K*Qc! *ЙQ~t/ylG,n%+*>=.R1${ɜ#6"`J򝳚xƎ}`Ѓ d{]e~6KǷaC;Һ},>zЃ-?'Bٿ* _OSu2(Α1^mcUp܅ch/XF*TT7!|s9+;'Pjiajÿ́3;Zu}إֻTyQ(J+Ñ81V|Q<%KP,>E9 ^Q=+ب:[ 3gʢvDH^#wKg- tɨ'׍}Jއq ^&#HYН2L_ ?zKȏVPZww qΣ4t|6! !< an7o:[ij4OGljzU)M6'?/wAނA4H= x"*;EIi7_IqȈDVt7D!޸w*p]1ё_@ ~PR ދ;f;3Y` i.l͈wм4g*pjcas7EotHIWx41HWi Ԭ侗/1 9i~9h9MVoe"I?g"ϯs>BfܘsCsPE }g a!й ubذL$> hzl1C%kΝ7`Q|M9}`#CQKß3ؒZPEGʻ%68ܻ h7g+kcx֬J4;uaiv|]/r1}e3ay NI `B4tˁZNg{O߇EhiʛRISD>rrP٦x'c0VZY읕d& 5SxiϙYnfğ0ThTiϾO?[5KOr@~d0|ڈo3 )}y63~]?*rFbi; @tT4դV *፽w#;- CqK 4IƂJF߱mqTž~_[DO2F3!ۊu/ piހgl'W?3E;~rg^D4XlwjKeMlN:d,c W2d.,Z*jˀH˽]mC"+צ+HBc16\Z6!YS)ˇ,5Of.T/I^0Pӱ#"Eh=I [hǦJ9&Ã9\ry%󿰿DY@4ld+d_L.lAdďvt%/[@"6X U7t.dD8{ {՘M9Y\'>Է+?DÏD jѓ&W_Uw@y(8 CشR'5Eng V͛r cL:څr5 vÊD)%%Kjɘ)LrhӶW_di\yAx\:3d>*в?yoaX/٦{e<db(H`oClX ,eܼ!1UZ{Tۘʾ!?6a%.Q-̠:OU,sLlAؤ 5Y>К/|K۸6\]V'#G 1 Mu*ˑ>ICaֱr^H A6ky l25#6V ({?I6 {[dXvmT w>u1%k?*1_D~m 1Qw} 8Qxg@%C]umlStfr;1kf8 Ю9ܺ &~m9Sg!3k,Zr2yQ rW(()"BZϵă>ͧjnXOB3pϘ(a_5#/e0ꗊ~$vUOL~ΰtެ{/ R{'s}.}R$d>>-c@LQ\dxomSŤPrmC .F}iQ oGjEVU 6#ξ,,@FED6XQC v;V4kϊzt]*Z&J]'-[P2|he, ԕ9Co3 5 )7DF _{ِyy]pB j^Țdo04;>dDύbdŠf%82tD3NZh8jO<[_l.펔T2 5$? 'CRV]m(H~J쮬7^PnPRq(=]~Yw|*j,'}yjZ\%vTFYQ>\,ܑyY"rBdiY>Y.Қ6Uk(Zݞ+6_Ѧ;UpffP o&f;D{M~* #jW˸L&;2^b9L?k΢=:6P{o/gZ๢V7G.,9n,ջO6Էf:o.utRŜ Sb܌<ʦm]0/ƈ8@Rɽ(uh#gt%@%/]J8z`سp׸>zĒXObEƝ++0x;奉URNmJ ܥrNG@H֌E!|~u_*XJ^ ,e}а˹}"HV6tfMM;uIǟ'wi'\Xj2MUFN Z ^π3<^}q>lzQ0OcN[l!FXGPY+{FNWB(O[*ER9WR!Q6c"#&. T/Ό~ai22!9Es2FeM`Z'H / F9e!JWoq7bEs `.pF=f%shPhcFd@nMmiȨÙ {+_ j}׈T[.oGY/$gg.d̈,NM6w04SqcJS"N>;}JkC>)MbMw|ώAOnCiwD熵n+AUjLl2ѰE;\Ɛoh>mvh> uOX-sE},w3?Ԧ@,3,'3بF$%WJ.brWyfwZ$ !Ѻ 7 xфz;QeTU(c$ԩ*hL{}S'),v^M]46Z =9_?ėNF^ sbnD/SAXE_ů˦DޯiY,-i$M# ȶ|oGTg" :+L8[Wr: 5&fBdgBǖde]3Eu WYc矌Yx%9°~4Q-rhˆƕK~Zzc E3C3);dׁ>n{U޷F1,Vl9<*4Ud>?FK813A./۱!rЏkJ}ӑ'\yBB#D'tP _1nT:O-]ꭐICQf|,^O'qSDs*ڽXddA~H =xG.c6 4ذOiGV<%Zf3G*eT\'. NHGI[Ɨ92WD2Sa[~Vҁ<Ҝ\~.r%<;t?aMWg*rj/[G6#GG+UVDBwUgHz\T7|tori_hkݛ61:v sFkr# A3|g߰Z]u&v(ˮ6_QAf(WSXiABj1ueb$&ؐTP?!=ήU:R;=p 3$X#*;`1D&@&%GByƭF'zj4ja΄kCUY0E>"LDߟkczLe~5Id:!T5o:hǒFgzFӞ'7ѝ`n++LU%fDU^:^v zuUP.x:G+*>*!p&8"ʞ :N T-ꦞvu`-s^b: ‰5 l\86*t{(t޽5iOmѮJm\LbOid43xoFLd&[į$]CFh:jʺ.~Qc]RԹ\h]sB!W F8,*um|x^bs.C$`Bwvz/G7 ڐ~fu=g#ƨ♭zZsb^:"Iú2L>#Z~7!!ִrsF?F3"fA" .=_:Jpb}xǙE!ㅣOő$"QhOxyh,S$ZBu÷c3 8VPQ `8%us3T7%^ey{xE|ֹ Rˬ-R|FIy_l}mv~dyg25vݯ9(6ࣝM+qP]D_ɩH4M0 bfW9KG:!zLhgH ZW׃GG/N$j ~(̢h~&ve5=Zfa0Acxߔ:6aF=vml"A$"C8/c96jR>pwr4 ;i͌9. @u{tۮimZO΀+`-~ma2pK9|[ 8rEAeKۿZĵsz*!ہQۓ̣˭tKBr{mުZO`r(ind:kFRe][h[`G  6A-9b6jƃ_*N Us8z[(q٨ܑðw-/;B`'sJj(vrYEZqEdte5hy:}a{/J^gLUX9ib4i]xx)!&4;&o; 4i@ Ȗ{M>NG‰wS3Y<ori r1`ݕrj/VJJ[z>Mut+mz*J7$>#0m=IWMf)x$B!$2˓iOY.חi{z|wQ9`L9#d1 G\C 0kP_w|x)^]n.|ܡywg#;r #m~}چ)/.hB./bAH6{/邩>p\)QD~ "pf$=F,`PXhBʟ'%jiY>u4򎔍Cx g|KiCL KaLds*6eCeRPJ}]?݄عEaZ@\57LnV雷!g+;.g6<|R0͡\=LRRţ ΏN& f y)vk<9|1^VQ7ƾV Hr.\3\Մ73@7ᔵd}mIDSD/ٞeg$ PD 9 'PCŝg;ўVsS7YtҝxKq9ت2}^m$ ܔ}YQ ^(%1Jt Vb'ˡ\[ٙUG+YH<]sLD0) CA Uog]{8B*dpq.9Aj,9dzYM=u !/l;GKgN{Cb[Y=u3CxcM]eoh܎4 _ƖP`4w4et Z3z Y)d2?hUP@HbŪ7ZD@Hp&B8ȕ(|>^4MȍKTItmO2%{,uGdz,mCo$ G;&!{6J2rFTt$t! 0ms1#4JiDr&Dz,0De"QJS3|ҰӶ(NoL)Q˪caG ,^p>:IBJII"*amGƼQXo x$4Iw{m#k:tr0bFWꗥ`W I(PVdpw]AGSo(+UhYjB;o](㛮L舞Pʛv+Bho VЭA4cyVX5@˜Gbl უ 8%0T6u 6@Q`簻m<reXF&*IճԛKo{$C. d]壱1}JI`JA^>Fu뢓݊Û?I)[(Flǡ!t\./'Kt0aE q5ǣ1c1Li:O=RA_j@ޠ/W&) rŠ9o {M )c9, (a-](%3`w#w=~U9]C6w͎/Ve$e/%w4GP\%a|Ovl* )ZDF|wd;~~FE]ȯ1kQWz~Ʊ#m d&t|a[2⇓fs+j$!g{=X\D_o@ݏWg'm#k Lz)tU95s`P Py *T>FN|Mާ=HpA(vǫJ3n5I9o sy>eǓ.LUĻY<=2a'D\ಪZǿq(Ъq9N`.hGPZsyHӓ`Hz`< KڵYH|v[tJj9efa blF*Fy~d{(So$33M/Jnk;0ZڵsWg'<(*߂;zn\Z~Q߰F; 86?oz~eWVN~8~P'Gʩ}_.3?;%G+/28CYK81}`K'{,խMǟ r$/cA>+maD*\U4 /Ҟu- e[#aP|cFmQdKsSj+,˸?TjS${P=؎!QV} i!#5G俭3$B<it58Fj@y _0"gfYbdc|OIAG;Z_z> dɎk}X,S*flP/Ϥap˃S!,l ɡ*3y܁l<h':K6ww R2$(`*Uǿ ab37œ`!7k,94H-Q74_j|uh9,?x%@e5tj㔡|Hǩkx{z`CFyo`f"ܻ=`S=v7sN?\tVwwWzs0~8:bDkkMiV ge ]-U>=R2 &1i)< =2/|5 N+od?ކwHFAh7`;Hal=9X1Hl/T}cZ1E$Xnɦ >6yV]wc)E,zH,6#E `͌Hw)E!k%GKH_a=B҇#%3OW@h *(`[y8jF|$M[QTչ0öQ;ٔA^M߫,auil|KF ;]XO *k M ;#^)lpҞ,h=h][ X4YVϽǫd™|y!;f(+ZVx5yT7WFP'ɋMuJ5qOW8:OS<1eΐ:ԖExP;hZ@L G&Z<+bYd h. R(D`a]]E6hTW_E oV#+S)" Q k܏"+Mv-[8TzʫK׺ Y0S˿ތ zs_IAeq"Su$ CR#Aϑ?1~r*)#%0` 0qUg)|E;^B5hD !km;iojF̷izԚ7UDO Y Ab3  Ӂ&ϾT-m4f+ TN.Ž$mzhF-pdZwÇNdzL9#o'*_fV =$/m؄B(~X|)6;qlX^ s!=Y'+=IQetW& -CfD\=rѫEXD[H8j0B90lbK6CgE3nX3:i$DA|"PdlseE;xV:jfc!!Q28:!EÐŖEn/n&-T7ejNt{<Dǯ'ֻbd)Jkm9?2DA tm[8d8ktOgɇ0T'6haNV)Cg7:wJb+"E-x3ߢ(0DAtkHꑔl iÙ% v/}NǞV̲A7?}n{q~xlՉ̔%~B }[nbe˓G z:k.N(HQքk55}jĆb22G^%pS2+/fz{Hh>(kIX˰Y,7-#eNqRf2HXhwY's3hĦVk ŪI52[ x;BF'R4ρ{BT`nLI|U(HBgsDi,Ģow &5ljɖB s5ai9/ѣ>YFm~UJztT5"[DH2_&FsS(k3,/H e6nXrLЁLԦPm3m*f V}f ;WfJd:FW훳h2|pbQދq.آų"U䞌u{[pT2j42rFT_'OO*gt!~{D]0;,Rb^N@5֓2F?n1<3P=f^s[pJho+ӓl!&c44B4DcRiȄG `/CM^Ţ% 6۾;5ap,5XGؕ%λ9dZp%\|E CSʀI}1<3D.Fi[!R ofV?.PD2/zRv*6*rk>T=X6Uӵ+s\Xk<*i`YNކ)lQ#k-W߃(*|htb렀yh䘒?tqdWP1\ k.oČČۣ ܗoJ +d'w(aZ nAmG3y-{9DNc)_;ȕn\ x[ MF.ҎB3# #{)e4"KV)ʻUpBiir0Ne\Q8yFxO|*V TW P>~+++mKiG|N@2?ʻj{:+&J~|ǯTjBGݘ^#؃niٽCc^a~T Uc{$6GfTyi^ٔ dn~uc`0Nl@#~@1Rq|1oň3zԦ?Ajm):-D_e00/ֲS#L _tqU]>5ۏr>(J"tU0ю@+(ee=b]( ݠYΨvPߓj~+8`Ŏ9Jcs~w2,1>x|e0*6&^s fKc IㆈA#\aR5.C?ۤ 'ȹ1nhʡc LoBhŧ)1G\ M1==?!'<,YXC'y)V2F) :sH:l@JRm]CLWJuv˘fTO}T!ZƷcZ})ne]ٯe3WNx RR&Nkڙxu.031kx%E _JAVRC%-G/cwZUAn&IiQjaG0u +tZ.Ue`,z0- ^x.p|@_NivI_(s,'\I 'KVJeDP<-0=y'k\N /Rs{lҩ+>Iq;zuNyֽ75 nd Ҹ):ܽpv/ )}eCִ C0KgfzxnhЦ[Xz;$i&O'b[l{X9 謹' rJ]%} ܸ(Vʦ4tb4z*~2 )a`dy[{,DiM!7F[RtI!hHoBVG.[r|$t mgHQ:?ᚾm_nD)" Ș`CyT* c#S2p=e*RV޺Avʯ2x,~ PB g-!t{8O !<k'P {aʌjF_Sk ([ܞ[ܲãޮd eG ёjST;'̋") ZXf:aUN3"O(aab^.!L׾¯ ({bh=ȄXi_uЯp63 0ю8~EL]=mn}0"ıK-AA6Ov z FWy]hWhNdJ,|MIq.LTLuL3wGVˍل(9\bc0H8{m4Y_eZg~)C1^_NK@`א)+=1gR'@be`S{O;g]_A b8[-.v4Hr`~?;4ī{PCn1V ػ~sWN^Ƶ]֐8=C*AZ-YxT0B]wh b9SavuŤ!NWorݼ  hEb|I oseD&Ct)o݌ Vs  dۜ'a2EҷOpoQ)ktG~ymsW] K{^ ò|x٬_JoҁĚ$1e6Gizܡ@VQc-w }qqkE$߳}|1w}?Ksjc\@]pgcтG9p\|#6v8(:eC& ϣ#K]El)KsH1ègKl7JƎzEY&:,Xwc.XB}o1vȝ3qVmIn#!S}%dNKLM)D`J]^Fa A Pح.e:VwңJZt6m ;Q\7,pij_W/9ӆvGF_`~P#:,Mflr)!.9ڪR"߃s!QD¯ A/tq帹=)݊ 2 p&ނ+t1*ykjɃ\{rڀ;km9T^JY#m'l3-OJ|[q]LhvM#mYѷeEb甹p}Ui^JT%$G t +U6U~< 4h謾0Vvh`Nb؟mX.>fcnKipgnb~%:.A}ZJN@Eɀ)OI)߿&ko^MH9*ku~Zz iJScwyIZ[sfзǠs$,. 5J2EitԎ!3K-RBE"[ iE.[`N{Pūsbb;k[` 1闭qVVvo[[<{rYJp"Y6QA= }9߳yt^Ipo0)U\~Tz--m{@$@ރPr" }Y $.jCܬj#O7b[MA3}5=(b;Е!D7s{f0 vGC}v8k`!zlxl9hޚpUN $o}I4% ;WY5hte/Ŭ1@mg9] 7l+&us68#H*)ʤRG>s,ZLTY7D:xaP܋d-n{g (9OTN w_yVѲ,kC߲봅3}ǧA ?6eQo .D3RҰ|N= 5yA1̘_DDDׂqi$Uidcvm#'NX}y.ʿICYHF hSy MZvB>UQ|oPL f(X &4}0,[u9/=MFaPהÞMs"Z9G{( Ǭ#oJ;J-A1*Aj adbTpcZ3vxKӈV8َlPPOȱ w>0^bICtJgMuY BFY lxT<АIKry8S\?o:u/ +R[?q#zΘn4İ]6-K'a@M%Urk|de+9YS4ʼ?2\ѿ  6 ;h:W-I3X[_G {mK^\U%ӗ"6ޗDծc;iRx.g$ 72pدh:^L-HeuU?{bm.*yFJgl@)V#|sr29/S#Zk fj!lYV.%9fJtk<;wr6*rRCZ 3xR Zgh*ӞT!.F_`@?;7eq FUQJ&گ?N?<>ݫX&"wq% )4.V0]op@hϊ=܀ |_M԰Y[į$TdJi0a\p 0 (vO@[4,/0@6"L+睎Non~&GJ&V<>vȮ-t io551 "%)`qجD{3 2OZ|]rsZ|>yP`zrej!TB!R^I\B_DOH@*G ƔVBC'IxV{u*bާ t򬭃w>P^) 3Z5bB]dg'$,ӢU;M.K)sxL C+j4t@0yt\Aei=yܥ?kCTLKr$OJ%ı їy.mjڑtV iYbIOMGP+3^kփd:B3o`FD9PA$qSZ~rJM PlwKH'5l(=KaY꼓M8#1wr?Od?38#G6"zYf5ƼoD`S'Y:\H7y'̃/k#`]D\e a4\5l[^OLE]"_[*uruBARj%xfouScɛ[T`ӟ|\J9;8/+MQ|axU]BQ d)eeRn) $]n;q9F}p// m.]vaZOI ܃2)`OYJRdyLa F4 q8Z4(MX8j_#}+FR_:St7- }Db:hD1:6awj3s$cJVu#O נ:B;RTv=iސ%} \}o + ߙ^Nb׾ijԂ7yA}zD&ʼy*-.еMj)a{r1\*4b1^~a IxXDh's-VLOPyMe 5VLXzi33r+B큋>: ~<7Y.DiM %<5 My[BJw~Wyն"ugF++E}͸9'΀ն&XwIͰ%&+$@̐JHY/i˽ W,TQƲsu:ϲ+8LH˨@nH{Q̔>Dd;qޓ-&"r7gRf1,r+(+En(ʞdERhU-}ÙC\Z`GO2ƴᾟseV?By&HÎ-ɳ^[L8H!nғ Uy3q"cy cΌN*%BR 4Ie3[0y&NDH:l΍Vs+RXsqMӲ{М{"2y$]UuSulʛ/pٕ]M rrG,|m)޵5|: Uo<78hCdH-|CƩZ\sʧZuBEld cM#F[DC%; M]PiEA,i f9Y-#J+ڊٖ@sߡ[(r~^hWw(TlP3T~o=,Лm"8Yɋoqʴj(t>LnlB+eAqQz2V1|Iw#ai)v{Jl%t_r?Afv*BQAkd@)KdRmK`q̮V+sE4](X1͏s+>WF}iF#n+\Z>x4H9&z zh>00T 9R$:Emf{dcU E&E8C@(SEI >c&50D'^TK1ЩmjצpyY2rFKt2Li椟X2L$nT_|cf(j 2o/Kfbmjnp5Ιx hQ]Ii+%g%:򯓂%G-|I<_z%Br8隇ÐۉyX?%ʽ~fi֟#g٪~ @{v4dKwp w"~>;^fŴtLv*:J;MuJB$N%aOWa[҉4x7˛YJM}+N 1P'h> x乌l˻)#Tk+M:s+쬬_J^^D8lNƪOz CMWPc0&xQiy"RTh=%=0B2x0E]sYE=sY(qO3.CӻRn8:8π uut9a>sJ,8y„Z8/(DVpe]ǐ-ƚ.Ȥ>)8w<2WL⨚%maWGɨI}~a;n`\;:?q/`&-HR*5jBo '/cDV>NnL 7]uf("43=M0ٰ+k8UޟN<'- z6Gح뇥|#*h1kYHhLN@<&)>ܟo@M |޾C-c*Ÿ!ڤ~"e2MScTԵWD~n NׯgaXV5ÝhvU 7A$'#} TJ{,5R{5)ӃwAzHt!ɟ5ʅ(a^Cx$[E& @F(14ԿN~ T{WyA?"*=t0a=PkiEDإEz#uڻ';V,ìnف!,{3#M1V~lxaU%b睾SL9hEO+#lxa7T! L= 7u\ R-KPc tp~| 6z\՘3v;<?5vznf# gԏDҋ=0*>~QUI܌cUH߳dqӣ6-8yn`:6ZNTr@t%˳,<~#$:9EYF,m@5H$ɧ W<圵23aغR\{m)JRobBJ0p;g°cԋZ|Pۼ,PmwRB30}R!-!lsxKOOy1$;\F{$hU =EС QMN]ƣԹdv` [Ј]V[вUR)vT<́{ߌKx!7`}?BxH^ &;vL'Z } C606f%Y6ƮfJ@B;ɜp78ɇ/ç: `;pQK]\ ՝DIݫ6],ԲQUV}RHك*/Ԙ+OE~uU"o9 (;*[-uEg+qFiHHMGn>p`pNӧ1dg{}uEwBU5!|W۲Pgq^Q\%dGUmЋ ׇЁJfU1b]7S1$Ңx?#?UJsG**~xjf@B˜ +0зnMK˨<gDDDY[\[|poLh63qӫ?Wvv\!MQK'ɻIh[w5i ;ͱVK &V%zZ~F*}dBOs̱^EJYeJ<"Bi) Ș 56#8M?Hgbݹws\Lc1.ϳGQ F2~Gsӿ>f4aϓF,5uaa7.m6QkG\ jۧ>@1K102y۶7,Sp~z'͝&#VAά CqTv,(<ѢcQ?Qv!Kkߣ}šس B30N֣=k:5P^]Ī W1p?jZϒ"Q !$vS>m ԭjy9rU(jZ"cK2 rٞdNf%Fr|>=AtCRV6* 2h!Ui7N_:p(K.)Vrȕ}j/ Hؓip FR ox0?,sr#RC6!#؍`?k'(|Q 1Z]r?`7aC9;uEpe[k]&ڶ}?f*bk h8[M8&󓳰Y\^B<L K>7zu}Kر$30%`L-Z̈́qvq|f \'2bk3tyȹJIJɛϐF\b5م'"+7Ićq,/i uyG>3-N12.`$f%2rV&y@oQ˦BO[=ܞ^LkJǒ\<8x3'Mo>Y/.8|Y6? Sa|+_O_hZ/T@+_K єYZ=vW@p8{|W^U2X!N ̄ҧa}Nж"*lDsņFMh=Н2#LtmĕP "#>̵6nYV}43Y"6"YVaBN]-䫴1#)cc~b[8!MiExP&6Jͯi)H|E.5Q35A;']m<)%-i40'=UD'T f/FLT)`T}ЇP5ј'Sy з&í5{áַ)ˌ3I Yzfql";fASԞ7CDc5΍ )A}ZQ9yX(qv"=Wۄ&R0*v?*(UX6g>s5:IMD0)`Uuj<#s,9J 3`> L+pd6jܳec=Bj TPzZP/zO"]b8{Zk t w;`-1N"ĈʚF&UCY-"}oԗ o isZHQ4nϮ&8CjFck~/ȑ'ܦ<;(m^z-bO.'1rQng|ebMk7(º6Z|am`v8[ewKbAdffcc.g.IcYxFbP~MMp'viV$Dǥ%̷8Xxs=D)0IKK0U E`-~hp-DSVQCgyy/=t}YP1?QUi sthJ@#h@6uǥ j,<:ݤQϾW}yf KYlԡP )T;,4Hu-U"NZUmqe Ysz 9u:*+OG L ?X}^`.RפbΕ+o2V@h}Cmq6 w 0&{7_5*xiTmO)*#a@n[DD!QĘL:WdC`к<E9]]^[AO3U- :Pu'vx*^Fď+jx7ۑ- u^۬3rte)V]RT.%C[<ڇ͌[H65 'א5i//Dd]d#q>bnRaQpNܯ1۲˾M.>v\_ĴMoa˻AY&> ISvYE+9T^~*e /BMz^(7_̰.Xׯ ܁#|"7g.XbOVr{៉ѡa7(0.(D< ̣3o X1b_NN w<>$1eC YlcثV9H n}9|MnK̤wN$qn9a9pQ=69A:"U{<㎱G5zah+>t&S>zt-upA&>%&$eR!l2- Q4ۄEx>ڶ޹Y)։kF^Qhߖ^ 1 !Euj|uk'\N/}NJ9 )ֶ탿e>% | JVn-ܰAuiS]ӪM,>Rj/3;ϜnK޿T\qLe|%iN~YW+V)AŲue ^1\Y[@I&k|%!yi'kU&%SִfCW~0kZrexԊfwƘa2,^1h^{ y%\MRĽ(i~ugic5:-PD?LH蝁!l4#H˧hOkpN!(N+'c;~#L,G?syNˊʻ]p 0,hVR\V㓓$C+ӛ3 6^+| BJA|x(~W(vvtQ]ʄKk~߲h1{BˣA K-ZsJB޹DTpGӗL^׊~g+?z)qr=NbaB}ۖsmm$gl̰] 2duޭSH>?cvq,1Ony: ,V'JE̘i8Pg۬ҽ?Jh׵1=ˇ Du/{?/zh wi9]Ⱦ-:˪c0 4ChG btwF q-"zK=&D#YjbG.Z "XKVOoS=7鸰t͔ P dv.voQ2`?QuVR*r/ʝ{ԀaC+m }3%麢r,;Z\ILRڬe1lL  Z3.IxrIq'1=@˔Il+KKvhV唅-^7,`lsY,9hf?2>e/HcՁe}{rxmEIQ>a4I&`f0+lduվTQݝÛ}I1/_ 'ԳoUY o$*;j ~T!nc߿2lL֬T_tqZRzgv ^ʛK[$x&WNʼvhE\hhDua %Z3#RGιX!we2_h9Lֺxd]pBxb2ٻ06;,U=B:ax!(uɸ$G7rs&MB!Br@ i#xrZ1TmK%2y7W]F`caezd%w~w}R, hbӲIJ:DqxlaOg$h/w.w>ђĩ70mK3ֆ2>}n=RP)d,_ fuzFZӣYa7Dڞ`Cc%-L?q\W8W˧PNLdk8\A*☵ױ"V%L:/eT99Ǔ}`k&ު (%MvU;T)aA>GNz&YU~ݨV=k!zzعapS1*)0 YLxkâ+;EpFhx-Cb'sO~iwznqpYxŬh̴E*BٙZgDHmXxztrj. Qd(r" c U{yk9="A@NvZZ0*aL=YǏDS/dcKW'Xƺ![֪$fӳ{4+Ehlf;B=, ;:.p&Bx^5Mz+K4Pyx6`llJY3cEκ'*x27"؏w9Hq*Ҟ{.u)FǥQK 9gQ7tL·Cz 5İ؎`yjĄX]Ϯd1@ĻeKb(x .ś:6O/3MgÑM(yykIw"=>-X1uEqjjHP)Þ~zN6Sv[?^&(sO"bj8^KX>cmxcֳuLO#N-l'8LH90;".)R0WE@^mOq3Ӷo6<_MY'S2GbG]iS:$,?~`鹤=7t~PAbYxy^IJ~xte֚Rx~, ]C6v5 Dׂ+D/ ltK4HgF>\vi[DFniT,=[>[ky U8o$;Vw wZ` V|tkCZf*N,u̲1U>3X_Y\ݑIhb8$gnILz{Ru=ș(R{ْu\!`OY/aŇklnIN-,Fr0 A{~ =q7HQJ8F4FQe0ȗ2.~{lɝzC}i uxC6G,j M?rj@zqdjM,x`:] ALw8v4lrT' ?E\X+nZc F\bfSAm] Rjh}q'ݹ)gwdTn| DkR0.N$=(b⍺|7@(A t/(K)ue[0]A6O`\vl'&E Hcnh*#RKq2L+$Q:&j ()r4'àfm Wl]xiy*iۦMO^ֿRj}'ܥ8ꍾ'GTy VV[<XxiI+}VW:8'EVٴ0E vT-tPl|׼4rL1|h*D%f>G]7by\˒^-At?5 ɻ ?o_`jl"rlO4x+(Ǧa @GhxŻkQAC}C5`b}x \C~H TQƩĭ{݅dcXy-K`kQ㓺37(`̑r4ۍpҮ4ՆdpK"alU-8d\W2l,'B[t g8rZSsU<Ð 2k +.~vMjZL[m@F|3YL`>c2 ;d;#cUt@(AzJGX3+)ҩta쓲tYng'i붖+j+_EqglHiN'N.v~?@ӿ^+:NsCc gj-&sȫ j~ r@U^>&1 6襖;%!j @y01H 'H#I75\u"+&aVR=3w "=+ԕ4ZA} Y-p 63j7o eRϲ45D풾?/TIkrcmo#X[އ@1ʲCOPb{~ Gr"޸<(dߔgIk-#ȭΣ֠29էUtoT\)h_sa\ꯆ@~9#|H[r3ւ!)2hĬP*J>5VFi+Br]KvE&ٺ  bEOX7Ȓ6Q \y N4RE⯼ވ(e삅Wn M0%%e%dѶ<][FfXg!!7;N b# GaN&je` ё~ H%m=M2k=׃R}{&ޓ}WoinnIbDU"͚V~WXΝΈBP!V0?3$>Y-x1:/Q+8\i!k%2s2\oqzmBy¦\Lm]/XZ,nڥ.:9MzafHp5NΰyA1I,ƷPଂ}r;yl{7Æ?|?[DӸ*YEd#rG-YĻei/mu(!8S@pL b Zh{=u@3"iFHA~Ǖ`*54z[6 Z2.+Gޔ26ȇvF~įmʐ# LdlP0"/V8k~X~ts,KdEIpgˈk=@%8㣡clo>ȝ3quO0>Bz9'2ǨK>Zʴ_Ms㛾h}Oog U'2Gg.&a}뇴EY8%~mKas&+ZG_R@+O͛1fƮ)+NE\,[%5_QS!8+R>%t_]i:cbRǍQa \&u ixGBTT]EO* ~4{GH Uk@jKAPy#L$4,{2٣,*m1pwSU@u<_8OE\#A2z/-nnZ-E3imM!{o퀹gK AssbB!E a)=)~d?ܜ(Z!c^cc 96*TN*DeQM 9X{ZW:o Wc\ 6njawIE Nm)K=ྑCI4O)Oޙ`F7,)Ф }1%Po8KOi~܅/ʏpQE$s;dH%$~?8x 8YT.)3tR ^Z~HIi?]`ALIǫ tB.@M,Ugwa;]#w.vzŋ0u>ayv;l@sDU}"2 d|fnR3n},G-@сR#tU1Sж= g m3W= !D$i&:Amg N wGǻ1TA(O>a-жk8FkJ>+ D,'"NSZJ#ԩv)MX6\ɶ3Qi\5,6;Y`N^ӏLm&U^1}cNz:YiikrH¬ lK~Bm&4:wIz'ŨQTψx~G}N|/ }82x\NȎMpq$O}oaMM/{4)9+EO?n*$rشCX&r)~>y\P:"kxm~" Ma2Gmgcmi7諔edYz'P+li( RЍ!)FAn .-Uu9>G@ad2A%tWcR=@/̔hU=|P H pQۦaʲ!q ZNP0Yf3=lپh D2]ycy5j8pKZm'iY~h+%c@{WIOaZB nQ<*6E9;aH{J\i~|b )+G/^##  Ko7/Ò022(]<"v[{Xbu~eRhnA!ghW8H/^JHe8vS~҈@4qR<4:j,̕V ΍IyתEg?"k%*;nsn:#of HlE4C6xQ;Q .cTs'nTJI.KN0Up@>u1-uJXt/ۋe_=Mӂ \]3^BwxO L7Mfdc(w@ .pQ0 BfnH!}sFЁB, JfSx Xfu8:a?fЂsvB}:>`49M {:0*yG|3MXUR4\ݨY< kVXV#Xȿ}Mb*8 QȎ>+s$d8p2L޲4%TZ#;W؀Y['LVN3HRQo7rg]^7.SOExu~SOPMI! \}M*L7Nq?2,>YSr ?D[1@kG˫ߔXq#3|5lmv}i/rn5M}'8JY}N=#̎DjaO RK15|^m tG;Z[2Bïaƫ (x=ĺ>ⶍ7_WDyhNzR\4E$\UJZV5޸$|m+?ˉzcEIX021oPʤXy:1v,u$ar|cs2F]C1bTɍiAT8(@| ó0JY846; ܵbԤڣ_?C4lؐCPf2:6 E( d')dYڲ"4@@| 4oј+[κ+#o58׶JY HALjsb(BoCµ,uϒaB`RUnF&R4ռ{1A%9T>[Mgja''F)]4Y9@o7zq#~c٣n =BD譴* ӿxVB_ ;ʺKXyјVqag,/bm u&`՚F|+7{b>$鋽IT(`ptGY]8.`fede%qx%1haQgs$3o,!9a'hz R![Z0D<{Yo MR;9Gb'{0߁]!=Ɵ k4[8VU۸|Q: %O\滹62Iwuux~+)ʆW%e(~k_7AƥOL5\P> ę̕+*v7nc$il)Rc~k`N g*˕}JAYSMgXǢ!`*jeP1N^sc&m{b Qqr&וZ8w b {;8y(XP33 DQuKչ'A,P묂kI譇EPqP.^ ʳdNWKqc];3ç__+X/P8{ xa-'=*뙲\wpfXz Zy^c ,hU(J`)ȽoIB*ޔ0~my,#5BxR(R~[M忤ZxH\'lHbCBeV=v.aw2+w' D/HZH\P|F8!hLXTЎw#|뷘@[ ܨtcGލ& _qus(ܠ|tn N $i*buIf+vOB@r(g] td+^s s^c B)OL,D&.P]갽t&=!m/zƪZ@, !gIaڬLי`~4ys˳t\@S/>sUZЉJ/z~C^e%S㈄8QkjFj-ocٞm. N{!=KNIPV^Lv+zl%ytw2FN='kiWg~S'=X<HG=+Ao L|[<њʵ0sG-9ky[&+fb%G{ 9>er*@d x6v\rt7O/4VN!7c6 x Bu#B&Pt\wy .'ZyWӈgDn蜰/5wء\Ȃ|Gj2뎷0Q>d"s(fI>M/=˴?5bnSe}VoB?K3`C KS iwi駲a^311vסxPJPT|<-xY0HG:Zk6ƿ"6#IMW /Wė+RTU;Z6G&1DYЃu7YVs[؂XK]"pD4ɧ . x%!V+ƣO`zUCqި,12Vt?=nuefQEcp@q=-#zfh?D^r* = $mcbrEgi=M/($=c@Rj=kaX1Twl*mbRKH7ɟpΜ|HK˦o]%^m'hgeD Q<G#eǪ/BTb(,OKMf=2k-։WBEze3`B)`ɠc!@wQ%';=pQ*Scj!t^g%U-ni2/c!? ~J>^+2)fCADiVip jq4vc%惫*&1_ 'ijKny !B.V/5N,?!X-)߻WSQY^.*޶5tZCyե0HlCP ѠNr4iKG ֿ /2"nώpI (Ȥ=Z*S挮٠LMi'¢JU疄P>(.靜YgmaSdpQ?Z v8A!7 5Z}8tn 7~<vvM$PT.*u؄P` #>WLI@#+ _dRSHܵrXnt.zfBTaQEGy{g0oPDLp olӔ'XqʱQVw=WkQ ^/q49xemphLCY>S詩Tw%h@f*N mad0^20@~vG=b)ځI̥1Fu@s ōVoxx OA#a%rZO)n;&>2d M҂UO6FƯiEO-DD}oLl7^7tqcYHA\!C둑\\Là;ٜ0l(b/CI1AdyRbfiFX܈P`b%ԾJN52 "l9fRO*XQ4J?c!,M^n(ɫ bci1r@YTBL rsS-PyqX:Wp8!¥,WB';kU\>#Ǚ1r7&7~zK^ԧv#խEoC] )fjM/14~+Høv) WaciMN b Ջ>LN aO~M i.9Kcw8@{ނfr\7ٚ@]a=9%'9ЫNq XUnvѩ lnMP(c/n.ɚ6FC#x 3iWS͵3 ]l5&S+U!”hqA^>dF1WbQU`!&E̿= b8=4y 8Q&Kuf&KȑQT$5# ۵7-QQ*ֈw# Aunf1=%O AS7r̤'/ct|]Vis -4]\5)ڂTdogH R'cQ-xf~DN] \L۶̀ }Ǒ3A9eLZGJqv9 C>~6iI+/#M5NOoMpp=J,w &=,d?֡h=j(t&go͚t4 ~:4t0.Aq]坢30b]lV@hb`o@h{DDTQaSrƱLYwBQlx#"6SM`ǹ$fqx${&GRo򓟂sf1ߩ%yxbXII-"bQ:~Y0>r_|Rs]i .lLHaN* "[&fJnpg "hڶV[REUU~! B&kOG/rd$80? 0C+:ε)Ql+P$:g|?w:l3=IbZ69^&@td \7nѡ F_}`Q^F\+Ґ_n9Ů;*B&m|囘[Q8l\UWuګp?bS\i6Ŏ7\:S|iW4#ك(%)t4 Bj/x 4@.ʉ~. {xdH-{QN =I~gē R$9OҸ?wIyHdټPW;?h/P]6y39c:dW$ iD­wDM9sBM߷뤏Ah1x=B|;izr>g9y1gPRAKmä$$"ck`v.SB(=FT*3sP^P!yoB yS#]-M"Ⱦ4IPĆf1iϑg٤>ĘuDbZ1xmn" 6vQyTP8}a.{MiFv?{*fAwFsZs|^6 Ѩ4w"ן$™s澵ThuNn-e\c Y/-h5OvzwyH],?|S)̋m.C!<r+iUN:NSQk\b#%77TayLg38> Yn5,|hT9cJ)vgs}1E&˴ *_Zgi++qC#7S ]XV y }BYIjU=svgCU"+rr>~N8W3T`# e Fin~ p<{| a9 o"&Pjom2s=|Un4 J7JWA, =+A gO$b bze(]fzb'=8AEr WxNj̊K1ŀw ?τ)Y1MsWZ=:׼I%VY ]0:~Px>E+e o9MYUס_c4)2eVGHьzpUP'd9hw# BصZ/3g7#I#dfۋa`B4#L7^\OIY?mH6Q]7.38ef#Qg o|gxSv܉}-[<G1 'DnCy㾾&;Տ9q8gm+|):Bj|)I"5^>zbnFQ;q6MeX0ul5@mߺ!(vm_^éBMVƲ`.l .n<6#H{wNs!Jw:VʇxIy. ؀!dWke!2WB3p=TWljGmpdjif#nmm*IM}j16 tb&Kˇ2Ö+=B:8)KOq{tO쪝癙}oKHdӂa u@-aL4ϷVYVz\S[g_^&"q-|b 4!7r\)- :GiI{s*OnQJju7 1N,':W )jGmf?bÊ~X`Ҽ \tM+ />\MgS2;r: ,hvƾT"JU-;L`LJ9=G%Ag"2W19Xޚe/ǵ)z|Lj!{me Y(k)m8NwA&Yr1ڈhn70:$"x5.r@AּLdbՌ? FjL.FGUuθqu/iJ?ΈsŲuߦ߃'ߨ-Vpg);ltdcvzt!L_x1+U|!EAxC>ŽB!悹Ң}}Uty124KG4* ޕ SNyRhVbGtֽS[Nj-DҪ4LAh)~ZkQw荞g)}z\wve@faAǴ LT"ƼENg_nBBTA+Ϛk->Ql1#'R@ %%Hk !!u3$pI.h~&Cɩja7G/[Y A4v\jsrcR\r+1bQa\ }DS/!w[hMjXsfDCN(ul71; -1iH_XoSZPYol!":v0JLle)ҪGlyX[f*ހ=%9H/kU3[ŧ H|HJiZ`|'rK2C_y;Fע4J԰lX|8>i8;EDPC4$;ʦQ P|t!nEA֯dS#[k}S˳?sm<洆!pߤ}sd"(`m#o%q_%[חE\lWb/.FqG꼂 fK+YyX+6P+1q HR_a%ܴ%6s+ݱFV~`at4&R~5!|}۳E8d!O<\Ɣ @E/DT <݆VytnuQ?4WO0c;Xo<^1$Xe C?n7 E*ĮVV\ذ>p a4΍ʳ~bq~;Bi`L6)X\kJ[8v9bTW6 kDd(BQ/pIc*3XL[qDsP(}x;*ǣ){ 'wTjpl*{_4vu1OgZvo^G A8kPϑDY݈Z,0.'(I^~eػ&$l2&Dcfxs jN"jA?j :~Jc/ /9Ղ{woSqobӛ7ѸB6bÏRsћhJzÚȾlU|k$hpMm55ѷ@ \PxH1ÂH~ 9%fܨ}phoXM _Xʥ9\ :8d&$/Xa]hjr0̃&JꅜMƬ0oWOKf!Voo|#BС ]F:QjfBW@j/|KLNaQTVGZ;"SRc&=S!mvpMr|7x+V\3~0jS ӬmSiIЯm̍?Gnp<'FNuK{%4ay du Z{?1^;]ÈW&c-Vw`>c-<(BJaJ{e\p >.zQ7"=Ppۤ-A*3sLbVVO;V>R0p  T$(&wr'< e}#;uXb5d1X gF !#X^"iѮDzU%qwbk3n)]IV%&9avG+ h3lͫ~a9c 0tt}>5@ށ2XmR\9sc[c9}Fg&77cimX)Gyi:$T[Vs9Vʱ9mџȍǎF#vu lI*!DNw*C={L..激=J zy .;JB:Y=鑞u̾Q3Ź,2NB7^tsхUkM+6\3u甸Yyc ]j^2BJ`&_N!&Ûi%?geɴY_7^Mu=]Fx20>q5?FdDtcU1BX:1 çeMV@IUTZ}ڵ"9gJ㍟ 㐓!Τsn xׂ0(/v\ǿ?cp9\ۍ93]8oܞJRaa@N'vMlG.-8?Ph"V@=A5Q5 +\{d)S<$,0܅YS=Z4Η̯4,ً9VYނ&qfղdTQK{fkx쭞?$+QRT4FJ1GOlہy7s Jmy_/zJp) ,#c=fE;Z9*֋)Fqxְ$^4VWni%Y5Z7a3!쏦cIA??֟9 p"= D,ߋ ֓,[\i@A@XVd`CIrLxl+•GJR9fm < FsG!$r@C vbǾ!LGUfD#I`BoraƱml}ix *1|Uʵ HBV];ڛ5ZPk}Ҍ?e#tu`,@dG"b$zlt,Eu0rܴO^nGkU*o}ҫ,”dŒzT X-xpEFް?^r7>n-YJ!E݌xR#ux8Cq/BRX,kg!tu-@-Of uMOH 9:UqzZ 71ӽW'uBm`_| ;Al hVӖblW@p .!@Z;KiBam}k|hO_v'ꬡTm AbJx}r OH;1}>G>cjA:r{hXEuMwwE'h/чJ KP=a~#)$j &$u'VQw:ȎTdy>p)J\i3>.(m*u޳Cd6\Zu7+=8^ÏdY1Iypl|Ƥn$$['oZƍg=ߑis2cnНeQ Ez+_ǿȞJa'xvd5#Қ; |ឳ٤W3w j$pQ0^#Wex օ fUU½f>RDtg p.GV$``26/G]*up|O|ӼJCH&*_|cwuS ꫲ%qլglD]S"M oRI@N1Ńv? v!E-p,aj^j<ᒽItxh %6rB|nZi y/ː!Z[ gg'5z 6һ<_zC;5ndZd16$ݱBBLWI2uA )DSlB\ :(RZ|ipkmjruTeְ{ \=5 zC8 Wv7encJAc_e*( thv.R2>+^v사Cukp}gF5`s/]F*kQSN޺H@]~^+>ń&Ԧ3C2QnOp2bN ?m޲#ݑ}> ;gµx{Ԙ]Dᐱ d:h$a[Q`X̔27 /iB:2GƠ-^Z84n)*HX,ՏBNܜI07(Wi7n#bFk77.DJ(')/OW46a$&=cpM휅U(Ri G0I [[;}#CeAU֓.TzYOPˀȶp`L\|ķGw8UFgTOxmfltƋW? sorXqj*Im&ܿ`?Lՠs(ucU,Fl[ICe(P?*\"-'|A7 O)ϠNaMOlnrԙq#H4*VSl\v[7$|,Ϟk>k[M3D{Ysk)->tgt{(wҜ:7(Ñ=6\1.FHgN#Ԙre>eL1#{ysB5??mKa:OłJ[ߢ~~%e] `gYs@>~ۅrɐl [];qdJv  lnc\mVw&k$A}!/g3~/Ϗc[+7 0 荕~Zaj=fPK*82$(g{x=%3.ΚD?GȄD z 8Q=v|#,!&[-M Q/;r1,HTX9Nf6WMΗ1G 2qsO 7;U/&m`MXڶn)= 2 RWnoEY\F0ER ?tw)h%/RpɐC>Zԇ7~Y?LP|nd(JwiFL]"JJL Yd[/UF5WwhƼ5sŤy57&CrJx:c 78 U-! D0DGxUuH]_;ޏPX o '?qmjd T'(9a5RH3O7boXa}l1Q 3qm[ ^_qaqߩ?T/I*|NQl6);AH{|I96-CUϏsx)*m'ʍUjٚt0 u>}aF$8'D y.ϗ/X5.KQ6!0xay (/aَ!yT]W׶oI'U y|bb#EvS԰类/>yaFm뚪@Ծ}cH1g;A\n(ެf?!24Õ#[ۻ+JO77 ԉ2aSݡ}0/X )s{v1!]җǾwD/!IJb C1n|^˿r/K3NsI +Nl=LNJIk䇇0!Yd*gf7am0HV'tȒ^g;H0&;C:1 ]cV-3@\v[vbzejKֲ|:F&q7PPhm[n [sD 9/)a$e%Uuc_CAD^~DjG WCEjӒRx,x1j }Z:/7l|r+hp6B=J+ܗYn*ӓ*2奀ƤbTCR要 Ol`eb?9[$·b^Kd15Y/M]wߒN#gv1mn9E1$1UgnEǞ>vn&[̀s[eRF,3*?P48VkY~)T` Ff!p fhU_t}3{3y״s I8*M#11 6$0U uFA3B}\ʈ5G< th2r͉HsD~mDQs\~2sODҶ6;[@ߣ5le*7GS+Vpjq73uLqeA#K!x {s)(I/2 ۢ1rNp>!Y-oYJS,Ԫ3Wq}hIk OSo3fkpG])9xWfYŔG_*-!S+vz8n>o5z0#4̫Xt/bk(Xh8!lů@_(.˗PJj5&T}{<)y,VNhÔAhob5!֢'s5cZ D;O4…~qVuaV̙Qx>v.D#!ȸ;M%ni,jb^^ RvA?T:6=alC!2}$*'_* 4nVGԂ\ZD^-χHd>ɡ.J\RNnYa"j˽$`e$Ndqؼ? 3 -n $N#wm4oRW/CrL(Tu~ӎN4acI~9~/l )r(=lLfH/MxY c% er_N6*1#bӤxM%[/3js0H Z :NK0t_7fwl8ԪR\Rm<‹ʹ]4 vvwӱydꎤB⹇F})53Ћqkbl^kmEu_OrNwLm]&5\d}`ymK|߈ Ouҥz*y^.[#RI蠋>ٵ7#h^xT #`Փ 1 gKA]֔jGO׈~CN1g2΃[1ڽKzԊ3!3y2eMdi6. %.SqkM}MQ~K8>(|yuE4ˁRx2X ,[ &GXҕ¬T;!脒UxzՓFZ-C~mgb'ΈT/1~]aHR0whO+A=CY1I8`}#_!zFob+cЎ?XbUөEUQ=^@ܼ)wie8; )`\ɟ3)T!<)g:ިl+'j@u] Cq,owRvФ-Ik_$My3ؚY$ creI:Do{C/o@nħ^fk$y[]v=?OSP%j)]{4`dQt'8m9\JhiDeϫ;t+ bͩ4`GGTrW.Lfdl7hI 9}4T2ncL5wGzqY;G;{ whȘAtH*_JEKCec^=Z'&Gi4<\OEogbhMeJDG4l|l E.ahfp2[)Y* a-XXG0ABV)ԫ!xu*zd|YTYIg;'&coy\i$wXbw9@黡qxޟ2ac\8+0uB[ _"+ FK%AJeV_n'ȯqAl)D3dICcF0m`}ް H+?}yY' 5yo_0Bu 7:\.ۚȿPf2q0%XSuW6kZ.%:(`_GҚ4$e̳.^іDR.{=C%?nB?-n͞X,f@2r xby_mA)k:\:@٫ KP긁) `{߃ *&u?Qk EMƖci\=0H݈^vzr5%tZ,c.SvxsTw?W)БI>P,!q`D$u0jٕN'RwƀY]; g%p2N7!JIV>xZJ=شp.wTףYM 8m0eOMnvɦ W.AT DrYW&Ǔ`t!79y!@uW>NuA݉^qlJR}Y0^x} &\+4";(.'l1I:z'}L}pE8p -jj]mruS0yU:D,HsQ(Xԭ׽ڦ6SqtghE1S06Mʾo!d#éhP< ^'ǒ?燪>Hu(8w4N@Hv+^`5 }rC)t͠KpVQUEIɬűTc ,"='27>9D<˻lJdJMXUM*LORΤ&l7o* C8FB6cFvøt\w1=#G͞{V\\VkTx+SUKk&J ?c6y:' E~%tW8\>қFޥNBUm@EoǷA姿sT+F\}>8XFnSnҒ܁[*3p ڴ6>fMJR5܂q$.#+?^aT'&C=iq^uRK]q>?Qs spB|Mi\8q;Tv֞Jiy *s?HږO$n̅D(3f5( _ IƔ[c}-<>L"2r Ti ݲS"<3}*;/IH1AQNh+],#hr&j'q)vg3VV.c댿I`.x<ծMHbk)sX9A|<6ܖBȋ1>VAPz1L+5ik<-!p"QvŌG.1\<麟I8k}/)ʎRrok,3R6NeI}7 U~zpA%hPސ.j!pdܠ}3p 96 Un~7,ߵXz-0iџ[U-Iڑ:l F 񭢆[`94Y^أkEj0Lbj5d Lз e!"ĉ_a5pG. ^yqc(ѐgJY6P3R Sry[L^r*O+#:{4@O.$X 30fH,]lr|n. SCR3٦449u?g7 na^Bk8Q\Z27egη^o {H׿2-w4 2 жO3>-b"Cw ʙk;wx}gސƊ;M[W/?@֪(hx˽>Ms+f n U`>~,=d ~χP}%^@Leg2ecN4o2&RP0.+ tv ]7UMPv'#2mc˽>=k lJ՝_&o9nV7:Li'"LqZXO\ݞy,]1PnF<{XiIiX7! ciǀ͠~50b٭Hg(.Ϩy})P)Ho|+>RHsM}pkr 5-zI͇9|L#2[-zj;Q5jDT%{hɈװPL>b|٢89l}ކ6c{Oĝӫ7c\RȶRvHUtxwdmU0}u3irNPeϯf~e*nQg֪h/R3Gjq_"YN3Q:fEAğ ~K8 7_]QPԁ!"w,Xr?e 9i&H^t/kPI &UN*hBZ=fI ڈ8SKK>MF`kh4D:aNnq/u|tGc ?dWa.e5RA!n7\AՙXѬ}6DcDzj"d}nefޤ\a93kMw^iC֩Fbdf%f9Jˬ^MK]@vOW9.Lfem.HK,7J \j* Pz4&<#9o׏!Y"a#&>DT0TJQ=&2PU=vM,gOR0;i2 ,"-Wjcrk4\f+6yX*aPKNj8_AU$OЎXd5SWehA5"%'*DxheQ +Mi[1gЛ}{cj=alj</Pp͙VL^gA(2ə&[QA[)2hZ+hϘ>. 897pϺuvڐ!w^@OV(@[^sK;vNuq7eb"_br S)rձ@*ʇ"-^<+ SZAS PBsT<%I9K6Gyxdss6tݺ^MټFGT8DI#%n<9ɴʍmZMҒCCL 'odk1eRW|&<#G (A3q,ʏ|_rȩ}ss0.e |BXQ;h-Pί* mze#Ro|e_}uewä&O:չNhv %"G;Q'R3%C<2j5=HI$L#pb8F?lKq)o|"fċԹeY.(e`da$E^lƜ GSY N9uw?PZy{c??PdhӅκ:d696yHƴ%EV&[TZYK UbR4htϩ0K( X위%0Eª-FZtb̈́|q5Gu4o9yd0uBp%[7dY`<(N\;:UWDATȢ(fʂaMƔ8bE{[K!.!$|x*QoFjإ#?8ab-) ;8N{hNEs9PkxUZ_a(;8q!&1Ae{N pH^#Ucv:-~9) t+=†!U gԑ7eÈ,j!xogxOW`M 0o`w+NU6LBղNkތRmăQ!́zct_ JT>k+v*GI 7{Z3Pxq[*q  sl?k[~UqGXI~dϢ$&IѾeɏ Ƃ/ ` % N ; j[G>>`dիZ?p{O12Է~RD\9ʂC<gc"T0jP_b h[̼( q|u_ofs[.$+|Xqε(uƝL&$W/"@4{逆`5s{'{~4|-֞ba|#i7nNp%r$+g',hUC9݃N[ӍMMO$\ιaeR*. ? j~ #p9f (?)A|ywu)<Ki+̜Jd⇊K8^T`>0u܄oA [v>hu7"JLY_-ZcG>Z]-3(ˬkl0OwZ[2&SmxI=OLNbwx7X ӡ&0b{dxk}YևN;^@bڦmԾ>_-9ǪyƷXl fb[@6[ng_pL ؆$whx%^ұ"t;^r{ͩV( 3GܰEJvT`wuc4So\/G.OQ|~`9u(bgq2kzN.q̬ Ws,h/IGFRW]ߞ& XDj(6V_ Awh8kd\M{Wsx-(̥ X0kݬW. 6-I\}BsF&WY2\bHGv˼Ee[*d`l0Z#7z̈́@O™;Rtr'mϤE•450pĔ u8 \3 "=%U@D",<>`6,tĂu~)%he/]l9drg`Euz;65jVc+v(ƈ|Q3̚%+VKG>R 8D>hǦ>m)Ywyov"#.9Ha>| h R$Y 90w';<€cC]ώjT^l9|&A_Nz(NjOTmĮ-d6/s+|ڎ'$ٛD!ȟh$nxsG9:}__|tțS(q#){z 8"am.ߐ+ 0سq1;ĔvIRe*w?@WYd'O6.q.h'@ PlU"P='t#@D]bh0̴QzODυ'Hżr '-qX3§zSlrU֚OYmE5衲K& nM&G]ND#8i~4=~d+gS (eukQv,63ž caD$wS$.z S] (H6>ۺ$ZW.kR'FQNUYb{!&zY0.@/;]'הDѶM[WvdeCT;}‘g%l}B7Ž<̤T|*\ژXe_X甹m7/G[Ƥ?үBL 4lJkX9PKa؞@E>2k*(!rgoa۸}'P]XSG ep.Fj,'q+TSw l߲+Jarw|ԝL٪6Fz$ٟz-WYLqK[^%5c=o0sG* Ͽ -2OX"^C*CY+fpK1NJrAHXf70M@)UUHqGRZӝFgT# +/WZާrQRFu'Y>ȑݷ4# b2 ,~|XɖZvw;[m֨ ģ[sYrk+56i6^|kPVA7ވpV0,w̩ٖtyrPRGj{G `)P,``O=Zb<̓d_ߡZ)h}|)ᠷp)_ƓZ<3}`:W̐8:𸘟q|뜔Nlgr࡞nP؄CPtyQR5d3B²Q1=_0vD?Nl…yj^ =.5tX1p0IXu(9]ݒ/tlICɧVt更_NWW+_\*DN8mʘ4* h++xUƓAu0,@$LtWgguK>oЛлqs"np~|D_qi0c^&%5Px+mmz`'8>3@l&vl ٱnqSJY5v2,P-vk7#,>X@Kṫ̖9vM(ײ!2G8v $l X3 P Okhܴ !rDǤ4w#F_($ SJcdE4$OH3$'=ɣe3.PfT}YdZTpEQqI 䧮02?^B^_O;΍ϯuzdEW8{Kx F GB| إk)C{ Gز6b~ }N5;pei&P|) xaubeӆpeUT>:+&mˠp#/t1R{,Tz+1<Ž33Pvb[lP_H]4S鼰 Zs''lHAwrF[Ww^; O@ڔr%2dђy <0f\pij_٤NcRPS'NV%m8ؚji%,3 Uӕh#fo:;R5ur<.7@(,9"dn72o[dzq>[gpf"_)5#j!-+@JEj[jtPH֡#4Dr:*g^<8~tP }+#Iw/f 9#cKӶE5bЀ$S$v@-c~q+IKW4΍ba&!Κi Y=p9vcG?!ض78VmɲKGXP]ɭq&`0SA[yiu-¥^+hWQiH'ӔlacfJ=A8pU4.z@Е'cyz %L6l O*V,@ T_^ }Y`*}QXrNW >Vv zk y2Yr+RFp_P DsG+p(sg)GC\U4=q.I3MSc*èpD˛^(8Kw+P05~U{Щ,/cޑLz݁=\ka|;p팰2<9dBZ*f!kހq=z擿QxB-^> o Aȃ1-lx!?*Tz}:2PTI8eyuO_mEhTC~pj˙_915#z>"QX>Pw>=1`V("OU4t5FE0%H0@tba=S$$%2ghivp~qS [mx)ʒQloM7FhݾI\HA|ۯ=GKF;'LG`c^I )Oʱ)uж~%$KDž"~s# U} )%,JUL1%Λkv+.4F琷β jGh jQPԖ( tdPE42 afݩ3f;xLuG/ P\YLDFe!( xۖ!w05qdgR)r>NChpm&ga,$XuN$x`[М237>DHhD0eҕW2H!l4ϙX4%+ EYٿր0Fcaz!T |D#]~=E畹) Ԓt~sy@C~Qy8 Iv⯕yLD+T\%*uNaUfsG]9v%jLʂBJuq+dk?c^[KPbVJA"4rL7"@M#7Џ.1~s@a$_Cb.h.]dM'f9C@Ȭ^6uYTXmtv'#T Χv@AR崮Dʀ~.M\p6CNm&7M5pT 5N*VWA:(lyZHR}:A4ܝB:KhnwI?ٖ]/J![g Hx~x%nD&n;a >L}2qCBnW{^`4j6K.Zf&%opegIm(q ~4sF$*Cʨ"^(p ;S5|H !6iQ\)II xGY٥:ޕ8-NTEҳ@Ո[OY_ա%ÀBBՎFؼݠ%]E=ZSXzWpX;uesG,/ٯ`6)NoBHTxkIGУFѢ˺,3/&i׿۪8+5y+\=wI4ͫ4ldlDžG(t`77؋~,HdP/,M/Hr*%ó]7`uBMEQAs%Q],xgߞCE[ǐ>p?ƺ~2-Uk!kB`ېZ= ̎Kbڕq]"MWȢG-`xm;ʶkW~`#:9;V)[l{{9.*f  .5 bIgm8bTr7N-3;-wۊDxl ^J)(쾮TP1zOln)vX$#3h̆hkeΉ9M[+~A̭W,6*meqՐ[N9c'S D4n*pnºfMI(5Y!>W)%;WO$$) ӆ zս#`lZ1=ʂ}L/x0 fDT򣦿@?v0:d2 :u=u`xJA/] ^TW+1"O)تٖxbzJ eZ 2j>vdu_ytUfIU w!?@"GQx!@oΐya=g P >O@[CP!F=Qjlr 9RU_3w՜zXD1qR3^W[r0fRu\]44l(m{ <meB<.qY44Mw` L_ܴY$G3cӞxviz ye2%3m`;NoedҫFñn5JaaG}[(l^m@|>d,e*J4HN&h>ة,ũH5#*0A%T^IGxOyrqj=Mg%`:IÍ#H1e< ye2{ Ce1FrJj"q~T$BKyk_xwU+Zvؖ`"?/5!߶i!<$Qp6sigXo1⎇:|]1`}EI! G+{ah" ra aQ\lLُV Wjo5Y1Y2MWT2c n]gIK3(F.5㜡 [z'!uQ'&t1P" 4w#F[7Y%Pf7ج,s[h)zKNQIRt X=OH&XԖ5̃l9agWdukUji0j"E|Ez<8,@fpjd:?1A201'i鸠*ͭLʹsNn}3}y{!i""=0ey969' cBo*K[o_ 䌠"GV(untѩԦEOslo| ?st*^+e}(:?]4LֽTHrN3;U^,&)@_ 9C~Z)`?P/_h~AYSEa 4{֥3,w0m&ۖZQPF,qul8E{YXhƀ/sJWx -Wbu}w4qZMȗSB1Z1 //!l5z`-IϸӬ{nimď|v4 CEȇHv 7KwLN>Z(r[*T!ni 77W`t(k<]Hͅ&F qY\xv/Qܧׇܾ@l8: W@+ A؀ bA.s1ӓzf*6i=x@46<_KjK kP5y!qz`xbza;Kt5;qt K`ޞzc'KmV}g+x*!UZ͞ThWW]X>]:2QM=DZQ&9f*;jj~X0۰|JK׻VF2)@ubHP7!d88 }rͶ_h8X}.Bn'ǣC *wqDOZe*ZIŞ;PA$)jy1pc^~xxT>Ocr>R4kh۽mbq+cH`$o;V>vjv'lˉv'P;赞A3Id/ Te'g.s׮;[>Rx[.Ke{c# Ñi$,i)T_4 EUܾspZӰneLHvDnYqGCJG:n,ʨCfsytiʫF^7ؐ,EFCS/֍ ޠ`B{۠{8C-csPz\ҟ q-bV+LCwmʠ |$j .lZ5ݵؼP3MiKLS=;S!a\^h.:SSX[ )IK(^@} Cã"҆=pĸSXrV{#m@1% QL&DA;*M2B}@ O88zԠW=.(=J)]KK{K)v>{7 f$@/g֗ ȼ;\0 <F|@i %-iӏDW"C|' º 馅#D?ac2@'˜Qbg^V Xtӟ+1T;rG7#l Ճ$@?,Yx;oFP X":k+B ?\PWPF.u%3dL0? VЬʢz"i"$`M&K0umS8 ^ĺ~Iy /)364s#UoEozYsg0KQ`o3~b a',\bKVZ+$5M1()6&߫Y74A(2 #4}70h%91R%CgD&0#/ǯei+|U4{iRiPtC3b5W~y?u{t]Th2ImtZb!4b~U:3Z枟m ~pV1ܥ 7|NiwR-td-\$1OTgb {cL}!|Æ>,WؖD=eN m"GϯL$GUL.!_nNG8j\ۦ!s鿨'9ȼg܅29צ}c59:S =,zZy2ݮM*i@`$B@]0z-]h ;#G?4h"mJnaՖdʸ>s.U}_KϭRAv9A[A`7џknfTbt6|.3Ql(rp $Y)q]HQ/nF ,zdC-kH;@D`]B۔a5ppfY8Vl.sثĨV *')Q ,JHHď.iFW>~6QX)ZLvwdԡ\zJ%݄% s6gĥ .5ks!Ye!ћ^+&S ~|MQuVK[ ^ޜ ur+Y8ݠ$/03nU?u=ot-R3F' y=V\ /=>j~eUwN2zu2o8`j^ +ֱZQjPol4$*ây i|oSnJQ':,^%M0ܬ|-S߶PW 9==E we]GlyYt=.Bt~S'3kK-ƽ|0^v==AQQ/EH iiQҞ%FVۊꃾ;d0* WSS7mQ (JLp~z&.a${-@-32P6x`2p ɕc薲Cz2 .g3[:]~D$az0TޮG'哅xѹL 9$Q<&ԓ^a&: n9#o}]h@W.-VxL&fbT%^Ƌo"+Bbԑqv$ ngK[T&~P/ǣ>%.QutbVg{H,55ާ0kg*L!R"P]c&2$K-4( -32nMHg09}'i{Ne.huС '*Sb2E^Ix=Gn+j/n%̄,xtoGkw\8N1{(z$ ydIф.v>$bT\tg A͊/)De`2l˴+pk+0I) Ԡ"O雵ws.vM +6{"ra&VJ|[6q,U兖z49A]4ZL%Hu8A#\O'!! (*wRgM*%gs[A4ŎlͅXfoc%@]6 m+~_Nx_^b율1ȄBEM$kW$|K jnЪoc A|uuk(ȌIHԜ !#x퐿#Syu%OL%rs&>j[׵U4+"=Aݐf06hҧJm P,zdPꮉS\E 3)(I蠟ϚpN%0Τ ۢ\rڤ$e2}ɸCq]3 CpJ$73᭒%@J ~`AȊsM딭ݸc}QT P ǂ(2N~x]²fŇ Q".]C]*xCJt(Z2s HCtf"3׼Wg??B2]nwPxM#cܲy,ygy(.  S^H; C{VK9uJ˖;UROu N L}5avuFy7BK+Z:)X1F|Y3_36H:su;N@5S8uv@j'*iOI3☝VY2zy<ܧ Ghz`\;R/"LDvueӕ0PPn}0" | ]GxPA ?DZ,~tɁ0r|$/ۭa,Pl$ƈDQ1J AB ugVt=Kn]WbgJǺkT\rvJq%`*Xa%YL?C&YV5l_4zrFf uñnՓ ;L &-'J诺WY`Oxxo1^UgF kq qۏ*X aB]fmY-_}D"^XwB/(-WBgTXGP-&h-lM<{$vN%Sjc$}<,W~X x[_CǂmЉsLuk?k.*C+W-uݘQjj0Y=rOF A'Lu l~]FlYci{H) #lh=M/4·W]1@+Ck:cVԳLldϾ]AYAP.pT;b$!^C ƣw2&'c_א`K5CN[ PEgTְ&?:#ƌpF,ͿLXHG⺑X@\q 8c3|֘r7G^'9:=VoP/W#]spw b6%o~F ԏb5ǿZr;M}\dgŒڄ5i*'Ƨ#YT †C5+_ύj(B*z9k*1$\nuzbf_/-|㼻CB/< ϥvҢsG<7J&-Q0XZqAל}E`ng G I4|5 $nGeÊ$E$ G]lS fExۀ%Wc|*l/1o~&;xqg9 A|Z q 24عIkL FIg| >#9cTD#vwRLY?"f܌}s)a1<]x3[aq3+$SPY*pv)kf=׼x3fEa5_*Cq"I#)K9F%B{~s[|v1X ">TobgIcLJt3k2/ROa~ڲz@<_$+^McjgXc8=6I%+cre*o6\[,,O7j je݀ " )$Vr 2 hdQڹOezXvUiRlꌛw{nYVI,O5ٙ"ؠf0[5+I0P8YUj @]X3ޖ?d٘pF* ;z*g۵BN v aئ빳|@y {)`"f~3a=`ky~ǷkYBXg÷S77qlNԭfjJ1WvdڶtS 0Fl>@jbǦ4R¸yv uR̽C qLF㈗Nv/kOS y.J6J )Ni@3?F6?S=଀ zsƷ[D+nQVb,a^}O6o"1_q1BN'1b3M?R\mR_WD}jR< f@۱k`eoa$*AC mkz3SgWvG&ݓ~<zt>NRD Kky.c q32ߋW*XVXT+/g,Vi;02`Y#^k>?$ָٛ^` D\Wc:oZc[n4quqk\-+Vo=qJ4#@q?Nt9G ߮&]En#Xc5&QZJ Fbx=nWMMA "p3BgfhMi>YY|M,ɘS@ Wŷ,)v>s 3I Q2r+n 9^Gm JKKM, ۷eaՊM F`w OEXm:n~q^1MѼ*YckencUO& ~qo{ 6,N+[?ad)jS$/"Eq-R0&tHW B55X.!ōFuɟMH, ѧPkX_C1vME 7muWR(x|L?MG<dS,a,w=\r$Cʠu %^O U \ $bWzqK4YKHUDu%҇pdǸƟVM-`q|\.&1*GIkئ%b:TJAG)kR͓M:h"=|o#"l3Ud/#٭^5U`9 bg,~TBW@4VY_mU>jGEGES-6CQQ=GS48O2ϱ- 0pdhA ^'°uQfn(_MZN*FXzB8nҋ3@49b ͌UTglsZ$i~LMt2u KbptT/w]cpšOh֣ӜJŲȶ^|{wczl7i]L+% yj|<}5hŃ/I/$t&Y8 og˝OJ 8\ p%j-eda=L9-K(Umw2}cv5@5S?? `}#q@|ig K$NAw^˾jxR=BPjP]R٪|՗sU}bN*t]0NH[C}|7~Nݐ#Ԃ(43qc؈hwkh$QQ4=]fҒюOɳ3u6;A=n?jP٦fH?zzK^ >k\Fc)l=dG ̗KMĻ_0E"B-Je: Hd Wxm.Tl"~\Wq,v*21# p$Rt܋eD (aY4,ViBZ\T;? qB~H!U' a >֞%% }YR&_I+Te%\fc 7/HwAv 2ӆTi|Ҩ? 0&t`At7o~wqVj?RJU%/Yͬ"ݝř-Cb I-7?K×B+ /"xx !?AH1c~iޚlxuЎ37~ (fuTU{3zG0`阹ИVZb0G7pEl# *o599K앳s,dW awG^V^Żo{`{ cA}>d,.? ܚeqҷ_ʆЄ@>٧\p kWNѱ'[ ~9Y\$ۉ ؎Vޖ!vjJK -Z wuatN-\ Pޜ^4YE`,Bcbi)|ZkҬ^)agv{'v칕f4KL$?w$HBZe[RWo٬d DU(Ef])(A'\\ԡL'|ZyS嶡e{y#X5`, k<w(3Ko7:bHF3uܥmDI2[<S4$t,u{(rjۖy^T?p!Ahh^Q.,?V}u ױ8;K"m !# g:E m1y?u$_L iu_2?-VՀ|7Ogj@ˠ!J-[0H5yN5]E+OSat8RWDkjx 0qT(.Oy|gMыˊ1&S-x*qe0n ^%̤ݷ )P?Ɵvm@v|_NYbSyŖdתeC6 O= >Fᣤ[R]0sVJ[7$Ci RAâDh;&EJ[1%gcc7g2beudYDA; no1F?Q@v~Nr/_eDӣAo:ih\ө(P C GҹOȜGyg[#`ePLE,7+1.uW$F3g_b}:>T-NqA;g>(*~FTT|e sl埿NhDZ8 y K2<'Bhǰ#`#Ms\OI&k k$n5C#c…|K_܆Њ3a &8x 'DIl+U`i%'OBK^rg*;Ab}Hb}8 "A;H{/jٹD|*V!Ƙ?Q1Vc1gC^IS>y?r"ǹ?'X'ňzŭ!txtjv?*,p.ŀV$&XiP+\ iW eϾ3?d;<nտKF8 ٴ wk""$o8H =C H]4,V)=!ON!A[fbBp'׹meTzH+R)gvƘ?5s`><;۶q هpܟ4Q r4f[ & s!>jn ^tfK!7[h6@ ERb|jMfI7M-|Zwh.;oXTNK:1cm <%R䑺2I)Op&U~`P`aF E}T]2X'Q6)!7WAyRˎ.;M3=̧4&P=_%N jB>C-PZh4enذO-zf?.SZأP@a5ͪȆ*GL.3dʔ 5lh=¯P< H[$#0n@bH>;s*~73&/S~^_ xk椫Um>#kYc^T8ĚN3R2c)@q{5_9_Mp'?RfTԁamlR'mjNHWH+ˎmY9s̛POpm]n^,ۖ<Yޚ89\~cz{Apw@V ,ZaFX٩R@V.13 _KQgZ2t1Ie%QTch52Z@e؍'+.5rz%>NI9ͨ5@aVp):izUe&a J/N+yP㬦]073$v<_xc JfA4NV6/5{`T%KU Ar߄㬩ۭeو%&0&9潴c$2 T0q3N˰XjF={L Bvn@vyEMA`9,| G5$ C]!JT=^ł%1›10}g= ;i:@̔},ft Qf蕩 $rsud4LQֹBZ Y Og+vxi`d,tRK}X}'(ώ)`}_j*|xeB[%jHB&ӱt>tQT*3d' \6]Y*o~YVxK6+1u"sua:<14@GC}3Y@QhUٸ?tȳ2˪f1/S*f*)r1: ZcKT8Q1Ԥ}Cy$w_3!~:bQH8J%wumLv&MQ46ez+od~Yb{"FMBV!'t[_dŕ@{QZMڔm)@jT*9n"nF .BOlwKo "hh!(d1N)\7!\g"srܺo&>͙jA|^˃fyTp46T)}~|$1~ܥ4h@ᐎչzx.:yOuPa*j) ƜSz5Oxr\U@FyE_& X,(URV)!4b48qyr]UvdԡVMͱʓ|ArYȢ n֪qNYf~dq>PX\`@vJԾpA/+qX $h[e]/|/,,u^ƀ^wAƈS1S!]eK=Rp.FKluc%z7n6%O% C@Ķ1 WVSQ%lҚQn8oxEH?+[dŶ(@*Gz?qr"KBM;S D(Wz7|LF?"x-p[י(! /E@&4ܡtfJkC:3șXgGc3,3ש*#S o?f̷Odi&Ea#IׁW[iǝ^g嚁1r_.F 槧}zl$c73O+Dw^7!g,柡6փ+L|":-hz;YoU5g~l/ 񏟒[`.؀$!kPʗTNrN@\I &NFAV7)6H.(&nK:i bO VP\+''0^fers *Z{UZ"7 iH mL\i<(?wDPh_>ܕ[fL7W z2{i(6ŕYےeQ15)a&Y#9XEYyu>Sw @N ;[Ct0иWڥQe`o p}ѩÒtEn%B1|եzfJaTPgT$'36Q$ڒd5bbe_m@BÝt|F4TJdF*7w]Բ Mڰrgk}=}+-46>O1 ;KD- A( u; ,fa)#ǂjC[FD5? l.k65ũU'|܍"1u<5`u* (WD)["B #,'Cϰm*Oe'3ênHz[ OGuֈ7h:Zz* I6^NB#x*?6鷉YEX4r"tR2*.&Xi?~^8vos$%Fxw(U<`b lG }Q4'l2-|O,L IФ+6/K#Wv#Yr72ƨϵ^^XՑ{O+ViKKF뚣81T]H{S³j''ѯG~uʛM)jKKvf3|8po$ݴ/- [wpO?w}pbj:??\F.MwOsEި]Yv‘J$9Nyq+ V rjxi-imلyI}f܄pL~*p@ ŗH2\w+Tp8a9/.+X7I ''gXM ^V#K{K %PA3l7zø V]0v>W1Xpr.x䷸(}@l)AΘh!r0cY:$n&IT62TOI@5T6Ǘc)wgzdVJib >$1FA #^&?AUVO#<֏ҟtڎRЏB ˫0dv~4MQEV5{_Y2raB…YRUU* Jf& 4Sowdå_JKNؖ_L9mLC?cD彽SIi>+dfJܐKx1 Sș%x4/[ma:ôo 0z2C>Om3p,Lhtt-l~:r.19fZbo F>׷3-Ȩn_v,pt:ϥe B6go!5VR1.N/[W*I7Z9"?S=~|u# ]k#xH[˅F;_SKbTT*GE5($8.Z5eYZFE9VVP큊^$G,P0W$<UeMe:D|I-&ui3bD 8B' EKh6x./cTHfl +ohe]"C8雑=cQptvX| :"<]IOONMX$zZ\8GȦ [K[d[KIR'ʫ-#Eӓ?wWdlT)NQ(kݍ&!j~r#G[쒴kx~0wcCDhR%CՕ0(kksF,OB$)B~3|S&>=bl[r8GeMXҰI!ewRXyլ]5F qcwn~ǾCƮ_ph"Bw]3io_@!l|& K< !ѫ zrq7xX4e{;+t)N*hdyfPAc%۹iFZ`p6H'eM ,pT /6! tـϲ%/ո֣?6j>P,b(vq2n7@]bMF'm GdBY0爱f@CR?M>BswQlkH\ ;^0c@ k eRv=W|5`פ+"'e?rZN}f<^9.sJ.OW ;Q7)` @2|%w@G /s{23졀B cEQ`AomNFXҤA㙔2 NpD5&ρP !2oE@Vgh QeZV#הlEiCKӖ\E8G^?;0 2 0yr0uW%H͑DC@޳l8mE^S&E@dܾ@<u8{(nSM\@jZѩ:ȪRc95-36\ň߁+sgVuO~g"SbB $Kһ̥`) d 5Cb۷l]mT+@ ejIeo[z"Ϗ/$3vzDOiXwi,, R*z V8! *blKSt(C*X\ NL4>ICu*6r. $Y@}} `Vv@+!)e{9: OB>I>x׿D`G3c|ZEoqmgV~^ۙ@),B0ZTO_ l‘!Oj]?I)#㛞D iNFD:K))_ úE 1w؝0'<hIq1^nb_TZ~3k@NBNm~(LOEvju0qQZRΡ§:v1:W9]Nv RZOF"av =Rn.u^WdXb@@-aA3脝V/ޛm_٣ZĆT+_8tN |ub58D -cdf:C [ uk w/2 Z6zֿlTyWA3%_g_@&pm+ܜJDS=Dq_"r!#g5爈v nϫ kك^WkC0Cq!!SF0޹;D\fRu:6e5- lyƑ!G1)V9XqjQ=aK(E{] d,=W@|biYc=UlܘcoWV$@*hsa:ZrѴfL#<+^0Sp+-1z?ԣm"k ٓ=0~xgjBô;C脼E3`EM6 OUͬJ̬0r1Hox5RS` |z'f&sΰg_o͹xlZô-qn"#4 | !m$B^'&-!%Զ|v|*PAB[+.:?jƂob@S–5^1ҧJP\Ω@Ҁ 9< ,i"yVvou E&YE#]BV6M]?e}/'9RnD*vjcC|oJ+u޽]؋.bw-d (xBXUit<0IlUcMx#)X\lt9ߤ\ $X¬+ WTC0pqbD;qH%xLpsGз\QcR~-uj6$xO1{_-ʏ; n hߊo'LW3ɟd{^8#& ~Vz8V{U|6x:RiE櫪z7G9 gF%#NAm590E.o3 Jᾮ1@@3 :HL&Es C=nG[S)@ݜ ,}cLW'|P~Nk~CYǒ񀋯_ Pھ'|_<-Z%VGqbl "lbKɝv2 H2dJb-bIA-5ӜNMCV lu7 -X-m+' btX>gWPdI־lt2|+',9u7yPN/R+lq7=pC|S% yh3[Q6$ m8 pk>\;Ut5;T?(Z%2fJx53dp_CeLD hrEtuC2I[Z\&6?% &Q;ؐSd>TzvJEyϵQO(dure]:8 * C!B݆,D.@1[irn]qbE)80ED#ivzWKIUoвYI4NQ w%N~`Qt~ 5J[j-ӎ!4,_VTDD\mUPw_4^Oo`X""3'_3=PKpߜu ?rȜ4ϓH=k ET## ^0%霘_rOvRNTX!sBy_ކКCL8tm`㢕44(|Ebǩ1 O'H$6@V4ƌ.2V>E~I&.D^!g#q妗o2Vua$,pcہUrPW_IөY`tO81[ELEO< 9ԏ}1>z^]UACu?!ʋX;w8Jӣ&aj5FYjϏiNL:Zg 9B- A{{-sGxcSCӹ8O1-3ɪ &IfIxcd67`J%9r^PTK}6{^R+ GO'{IM r~Of*\,H0wtZ.i4ZJGލšMcXVOwU<^>%&E$>+?$lHd٠!3%\fAb3,S7$Ż3 JcRIu9˛#}^)8 ?cT%;F"7עe&DҙSVڵmJP+QBo۰]QXH/#N)FEh Ȉ#bĉ@)~O>fA۽\gϦ wUAE=ANN hh:Y#gP`w;1 c'#@IޫwZ¶wmv`Jҭ}xy_m̆(=8)@r% 2Zg Tnx[𰘫%ԭY!+vzVc0sv4'*ǁ?ɺdX#/ _xS@̆HgpMuF^;w+73ۤYZ/"[z1ATu)X'7Zx UHٌN:,k!g3y7 ee3|>eQ|T;ִQYn2l93F `mw4~S-*lX{l;yĒffOTӃ (E'_ oøb J~[Hۡs#\R:Іm4QB߶КbHcMwqOFn ta }kPeXx*QذGeoX^@AIfo(YE4t ׭-bS*kY]QB<{uT } X};o6NZ-sNi9/O1xFN2ax Rҡ$ v\ @V9/ peEWv% 쭩%2?4}CKu(ֵa4‰PEG56ǃkкwalN}kK 7z R]0nmʤoe@:sgw-H8ǯ+lϨHVFCCs.DY\{ohVBԂC Em_Ǯϧꊛ@!=MpmWR)3' fM.%v1Ǘ[sa5/Fl]bh:_I MJ)["-u'НOƷNJfM4|n%[Nu& m,)ntULUъqFk/@eH;U:ϲL0,?U/Gvte=DhE{&UɆ<3K!yHau4ts-aLTHzd7ab|.O)yrOc#M'NJK9fx$GTWk֍֯Z7rYQ\xmhUKO:FU059-f&Pzp7#wót'$;" #U.x O #g #Sx">@kUtV1OwqfvN@yygdԃ MlBT];y{'*l2*8AHIPow*0m;o-M6U,>̘O zxZ+퀃pEY);Ab>.'Z)> QwMH:c+\4W65o~i"sҗx%t6S9 NB^QӶQ.&6*RݓkCTL}p":[t\3ηA\&&-G6N>:0}PmE [Y./:ruHp*ߒ~{c֣8/h vE%sgCTcԘ"WQpDZzrBk,@7iM {³%k+'%-N,9ql 0tPו! RX &4VR@թhSy@(>ie`ݜuw:HLY2Ր駁#:9NoWFS r' zp[˥B$!_oBG5KP]*VqCv?oǞ J.+v9/⯋C'(_}vkC1Ff{D#i>mߊ)S@uA:8q !#R@#Tǐ,bN Ti<Ǯk .tIDWmLb\Ϙ$1QWWwJr}=f"zn'\6 10)h%$C]W BgɺЦ ig&WYSuDž["Kp'bvfiFE-Cn%Ybc`m|u?lUo/g< ~x|][ !e'L2z)<{geﰱ,H8u${,c^zéϯc,W݊(ƶP SӋ1r)#mDazA-hɺc>:(Լ{ _^g뎲@6s9ԹExXu~Eq* 3zhGe -#SNX}{O.^Yqb.eM{ki=3k  ^"gƖVqNmZ>)L@-6dP[z@cL샤]s^be D 6Tמ?0Ai@oKqUFYK rO3tuy8oa|n6 qxwc7lDcSgʎɞ돢rD~º/MCjz,^ӡbjFLh2wwےяl '.oJb6U4i0B2$yj/<3~=EoIbƳ/(IEng ~3VOQKzd{Rlgne@> *QRZtL&ֳHc/ŭ{Φvhܚqb%~XQw93L9N;DaXE1Ўͱ؀9RE)K'cUQ&{8_DrPuDL!XdE/!ZkW.%5X3;i<ϾX {V_9(`ʕP i4m"U!=W#2frI~ٹP҆/E;Kb@jN4;$ty:rC.}<]onz;/Ϳ?[-[$ =9- Q 2Ulu8nb(a-0Bi"R oPT.1ͫz6)3HE@KGķ}m꺮dܶ{wܤG>FT<@# [i4Oؚt{4Y:ڎ ^uh qDaP5 fA= ׍<MdMa) ȔqޟAae#+`'Z~]2zŝk׾eFœ%iKopL@i_wjZ#M,Y՝˴`¨CsHP=V< =$8fPL1NS9ag3n|%_$#z ꬪPWёgC"\,COq= 'bB̔1`6wLQ>8Gpw53sŎ 5 n[+*ե"֧4mi+B-Eu7dw93a6ހ 9nuz,汀_a";yA\s 5hQ7Iwy:|$AO'ÕfҘBf(zqm9x%+eW{g)pMN*fWHY a9v U!)+("'vLekF@*fblgXb莬!!à awdx l8QZW ?5׻5%DPBt)Rs ^eWF )<:BFa+;) |:R\օo@1 u'Q~TxfE`jeΦ;ZOh1pb Jl썃d2H%OxQV"!>Ec٥|FY[,Lb G!Chzj ,)H%=ZN)kr3HpD x-^8oaPcJJ:jޚM}q[ 8}d=,Nc[O vqS}.ds!]fk%T$`#N~Yfؤy"jr" ϑ+S3Iyxl`ɸKmγU7?\Jת:wtqspKHք~| X8B#ѴԌEڗ5TQ2ljB>oy\P-;3RZ%༭qtFACtR[EnγɅڑ#?^Pe@bIK+Adxr;V%~[ԫ5dQm!"k@M`c:Ehx9Gd1'`I=3xٛ&؛4_j_t`)G NR/qŨ1M/3i3i篁.E˛cp佾*{ȑ}BH$8\jXuAPLEDL" ·)5!oRQ Re2h<ǧv["kZX=wzܗlNnA !Œz',yt60ꥃx'beO 5^ѱ'}\1h摏Nr5Xu!_XfuNpzٖ3f9q$bEKI6*z_s%!a!^FL]·Ў@dAM2z_\:/)^L iĆA/-]ɷFv&"#N߮FJREG<>W&06?EO:uOJ/q#/fTeúMz8_ih;^q|b&㄃w+Mi&9a-)t!7UEʦ m~r.> aW#Ƙy{jM؄k"?M /:ƅNצC69,4A ZuYY ?K{uX}3m#uxZB:/Y`nhp0YW+Gfh6.^M,v--L%$ZhUH ys(~ ǒCm^qÓ$8nFSG`O*|IK',q}tf!JVwj#\Bu2otgdu֬&L| Re@tq./) ?u9;RBI0X1z< w>y@֭IƍOJi%.?}0ߘM)Dhɢ2_+FMZ,I?_D@_\<^.W6{(iVbo <J0wam67HzޗidP:}wr]ݖοxzØKc(G<3lc§ ޤbPbb_>azO&},YbG)݆ qҨ-<~9qkj*-5Urhkt+*2-7uĽP}P{#NiL 9uWƵ`E :X7qDs:!NrE]%ʶK`3u^dzfnNP z_# Ȼ{F̻,\hאe?fЦ!W@n~?yO3l%< ˼I0> 6k%16LM'.D6<㴔 N$QԬ³wP1`BM0cvCCRr3hGc2!!!%/ĺ?CrN[ΌH+[0b 9e W#,`aP4)+ez%,值б_ 5;.IhH9׾Ho3CߌցdQP }X$;In?TAk #Ai nΘ2+I^g.Aǭytq~]=!X"`)" e4⁘!9+tu8]ݔܼC "# չJXW[nbG 2]\YA9$`9kOe Lꧭ@ƶ>ۻoup{x 6\ƃ _Ls'wh 67w% ˇ3h#NVCFpUۓbTӾh wh/+$O98dIl`4y_vb9^*: L+ٍz+@;--L7ӈcdVM@7̼ݚ<_Cԃ`וx NC9Caۄ߀pvt]pȑ/wELXN2^Y.-:iCO DqDxa=&8K$iE60^ѝΦzR'4r`Џ׻| 2~atX6(Xg(Nf\ѻ ~@`TyM n7cbmЖ4mLdRmUzN 筈:ϯRqJ;E$H ]:Fi_$k(tϺ`BSheFFxV}O*]w|恹T%pB*!"\D0YQL'ꕊXM,TI CR1q]~$u$ߓ+xq1;WYB vj$|3_c Q3וt4g[WA}`8緣@ qvDoe>2rnt~X!F;S%c ضf6(*LFL̘)={Pm<_~5Ωzl\uПtd<B/u܆p{qю:9Jo9T%>\$QKtÑJo6ऊ߇ PHVRuO\ދ|%l_!IVS?k -QR"jVGsy&!c }ʆΒ2"R?I|CuS51-UrfH)FFУ* @xZex- 곎6uO/,Aw ~|XrPGP:u^n @̭o* ]]t_W IKHyY8尭憒lX$ } lދ.H쬐@*vh2qr<ߟyӛ~c}#k&[hНY3x 81w$ĩ*/D}؉ .bv9}+x3$E-"lI]}%N#F{by\B,NU3qȩPZ1'##&QϹZ((C[&pZ!=uV\}6U 4m )(!\@a&!BI{s*.vōn1;@ReNHt!jM2ݠoݸ_Xnk|MZYk=YΘH1:t6Lfs>5/qUY4א _q+ 1 4-籡̊ۙKm)AJlP@(GiTEޣ ICʻQ wK]\iyh!7ȗwpk>kIc'YX&-X'v4+aT횽aQEުA8U܋d<O W UkŰ9s$Ҡ2 3%3` ˓}nu4:>nldFG2" RO"EAwU|d{RKPqPXLjM0*1o Œn`oB{{}C_*Jxv]ϙ;X-j#A S2{*;_ 5ݯ1[wv߳d(h[ jńfuRe-myߌBGtz "L~q5?s!:lA gժЮk#!H/DC#K'c @m_5qiZaM@g)qPGUtB,1& F7uE>317UX݌^7:l_%&qpr!|[yg[9Iim;O5My$?sA;8eD!1wABvCR'*N*6rnљqJ4w,1ăp~&DZR>;MTNS5lgw9L¾x]pÍDn;TQUUP/8D^s:3S&]u Le,z6~^1RC} E qZBa즧lEy㺫M |Nܒ!\?\)W_@V]Kr[(*zɋdh O,kQs Do\KP{W@Xc>(KD_!2|ktJdu{qmK`b>b@DiVHݠa@µƋ Ǔ+pp%=E#;EԈyXeWPd7o7>-P@YF AAD*/i*lGi< {p>("=z$#,է o5le@_yRft`^@d _Lye܅gG Kbqּ!µR?|K0fÞ88(^Me_QM6e~CϬ>/!pu}%+5ϗ"OJ b+ C"fR$ToY&dA:jԐͧ:A^Qn]&4= &2Cȹa'0O0; pIsܽXwO^nnU! cd 7N1(!q5L"ז| įu6R,]\ n0\ˎb0f]M:quEmzm̤Bq#U-#ec8m'X<``bw3I~)\s~lRq5$,FkaBߡEWw1cW>wݭXe_pojvh$z)lA]}tМsO(\0tLjo}eg1_=&>~O׽<j idzWܒYwb(Н%46!$'r2"n%`ˡ:GNEHfxzHoNO^øTĆ/]2 mxBXfW!O=W|˄1QSfa*g7Yo~/0h7|pmx f$oe oS2]wAgW H8۾ ,uKEh,j1uĩYЀ9V޿;*|&I6^ݟ5߉'im&W(VHQsz̡̺6a?^N0hS,rLj "(m_Nꢸբ|"hSq  sD,1CtR,4[f7 Tm8K4#'UUس]}{MUa̺V_˾w]X`P4~u% (΄pb(|y#fQ9d qwy%Z&AOmzU6*]`Uɸc8$Sl2`:<8<@0=x:J|K \瑥u :Eą9Ol[ (L"Gl%1U'Y~.g`V?7ZJC Sc@dҒ^fʾi.X9)TӰS)碓*}>W1hd8pMM- S4.|7I;, 5KD`72;IIkP.}^'lha6lLĢ`ˈsxCZb"kB JçP:.,1Am%)Rq2ep1(ڌ&9 0IVv$(gȢOdjx_$ Pyyfu鎑'!; +ԋy*AEx5v6K*mh{I_1݃ErElWUTŸeI?'Eδ,< SJ[ g3퐹zD7-SP^ Ve3UTSvE{lTTD8(7اߚE0݀+$jG $-T EӣЭ'.z9@9oRP7xEiĘL(k ZǾMu<6mtZԎ,~IY% ).!Q)Jx^,pN\Hf,1VF28M`8͒I{gȝio \P@BYyR! K pܟej/5TA]O&-5̡loQ[WCbIqT̘E06kT:Y@&)e&<sp/ ` I;_wj%GE$.f%"hk0)#ObӨ084F,mJĦp7I*¬kͥ}OЭD0& MFZϸ/K~J`?cBAxx6̻3X[S8yyS©H/Yq-[(+$p9$D){VYGpxytOQrSHx@:.1n Z A 707xǐ" `C܋a{'V$oR&`7֣o >hSf5Xs7?]jZOQvlF cf{hNp%'P| shHf.R<6VhZ߈[̋'j0PvSh\q,Cp d^8Dw@L99pL.Mb͇O_~ 4b{ "n8ZKژ*,gqø\yҋa;G fo9p^ (2(*zӿ\ 0] ȃy~|e);?X])j@A'ց0i@XGٜt^*@HTS=%Q(kÚۖӚ\"9Yv۹~4!̓Yn=G W]846b#=L'b5|T9P(ᖣDks//Dsx]*kεw`DzL( y+YЄ7T;JL}J;zڞ +ޝً Ecx=|I%dɩuw^nMb /ۗ߶8,t<>p' 5 e{r4Fz{!̔OGmAc8х&O1 \zHvSy)\1 c@H^ #{@ ݗf&mwtbOmazuIo%B͒]s Ŵ2**1FkE@rh7@ 0vhN atRۦ?=: pbgYZiD: #OwfW\W%Wr a_[]i/h/xs}Zej*! i1wEp_ּn Ů)ŨFO9^l<||i!F%\tɋwFji#54PQYz(dc٫<.Ω kIe+4\yx(3?p+:Z>{O 2p"A6)7 54z]Jn1^FGG7{nΑ!TgI&3qZe^Wu)TiMRġZ?Sc ò*J1Lt×ƥqC y&NeH}2pw^VZ)~sY.GM/GGR-HrIƢ*1mde$Rf&w[y:%gi(܊ԷڝZbdC=6걘k~=Ai ?{:pH6"Jf?]|. Z. rx) u2 6매W%{L&g.&=09Ưtl)>[zo2B[R؋$JhEX~+s ]ʱ3<^Yg(w>z臭ҎRX Ϊ~_ӯ[75rʿ 4 oe.nʙdЬ*6-^R'FXF(eWo'LNy(o|T.:k P^y4pDӚٌ9(oRuD.4+Ûc岰=3)tUK4C=dnW<%?[4K!i ;~##q.9%W_ C;ᳵeDr(%棥)/־TUB\\ѡs._Wug-{/0ųŜ=q{Ց1EDơJx x!w/7҄Wl)dXL@ W1ƥ~(?翨ْ|wA]q1Rs@4aDH_2+ 9`C53)kqҥ nX[lISKye+.DQ0]mZ+ 1[i}3bk< LEMcl47W+θ-4Ef^@Xez4[#2Ofӄ>v Mĸ0{$ /6pTxF$amfu yKp$7 ٲ.ёFO{8ءcS/ކV}<},˪keThNxX vm#)=wN.E侙vҔ,VeyI)Fƍ*Ex'tN(-{pcCެ^ibcAR2Gw<"DV; ,s0!G@3Ɇuޚg Tɠ UClW|(:J+utw;Xu?*8 8&7 J;gr $"IDTmhqG_ S !`cxv@z:w4~2/tQN*gb1oNe[^Kw[XX Y.+a W1x+)TNًgjDIRuT=Z (2^GP7#8:iN9++4y)&ۨ~_o aʅ|$A+qVz$=0!J'cП[~V`%:ӵZ޷^Љ0hg,G; E IqBi"ɽGן(Jݔ;a0pe"K@꺂5ὠcHV!~Ӵ}:&p5ȧ)/#\\~@ +'9տ$Dm!!IqGޚAMgLFpW0WTK6M|W(W<?A}'_̭=,Jnymn~Hyjfӹ`~+ &[+mֹBݤgC%aU_Û`<]L(67q)xwfHs ٚ€^Q> h 01w 5`iP㪡;tnP[WwC ^ 5yJ췊Dp=2F9ώ+NERGUwLx(' mYN$+[Nqm'@Q??X @A-cQ#lɯ&)ceZR>cyɓxOǬۄBpԀk<1Q7oT9>~ IDzF 0 u"oޤm?^%G=v*Legv?Њ! ) yo뼸:#xTȿrE]yO.3vo*|Nxq2U{a)F=ar]BIvloeWx:]gsMk]z К2gme{IC\km$-|~SB&pl[|=|ÐSl1 {yr&MzGƟ#/\@{:3m%7/̷ $S$]^7Dڙu0u9ˣȢ?,.O1y&A# iY@(Ҿ \iR @ۺv`rF[*W4qo洔+(s}8 &+p{g/Zrmҕ̫Ʋ+ ǢTd^q)'fB%:؇B=Aoד(ҁiYl*dp 1dfZ=)ծ3%chE#vA=o0w ¦6*?wǎUH[ "6;f)^Z/tS@H6meA'i/vT ~j~cgB84?Y(sbiA5u/Dqmc!nJ^d쉈0Eؑe*iؠ+3"d8#zeHQfjP87)%+:8EQ&\Jː[p/EDas6([ [ ? Ku:{l͞`. 8i.Ha#g ;[rLNM` 4bO]p\|[]#bo>qn?c:},;;&9k2|F`D)iq/]M: ϭXL@fHڨ v!dЀ:nSNJJyC7_ 1V4V>O.MHNpCۢÖ{cV(hO'% `Yl7w{@ /}0cY zV ~YJwg&1 k.N\1M3(^8pnC^v`vCc\Q$#ܒO2R(U~I^jJ T3Lx;k=gS"0s\dH.ʦ~C:؄G4P85«nIC|FOIPUO3 <)" 2 qYCA~ KNވ WWPިxs!|yJ{SI ) Heޕm'KQ} rlO谽.aH?L}tIitZȐzS&҄zH4ѪJt "K*#$CÊ53 M帑}rNlKC@~'N3?)'7jl0HkD/w*![{'^Av% Rml9I<ۓ2Z>DUhtǽiݠˌ3  twq_˥ڲ&0J\fKt+%Ivr^%-pԷ@yZ(mB1]ǎz{Dc/:'5?(O26϶vi`79&A?C+Gg!kLr(F y΄UNQeZy3p"6 25Mt7YxCWk% Vَd՟X$31'[EeAI '+`5P4oOmw?li#Kc܂Hk0\6{dri{hꌹdz%FBH@ ߻5ȑG*6"B\$q?TY!4YSIl'1'K,m8iʌMƮ\*.gPz!1NE(쨍Q45 ه{]-τ@ٮ٨fajR5"ۮ%ːe!a42$&Q< Q5Ъ7ω̰q|+#@Ո\vaZa$iLG3Jf63R ⚴z=P5.v`xE'_nFlim f 炓gi_QR7CD&%yW3|}jcN"#AoS CkuS7C&cxf,l7)q[9:@~' +0i~A8(-v(6>hJb> 'e0"{ [ᄿr'ҭv> r^ 'н&̫,Y}yԙ`v-4+#LVe3pOfuJ,>$JMˀ?5^LY \1?ow2 /']ѮuϿЊ%LQ&%>vTwM%ɾ]Fn!Aj{ I lÂDW8FoIMǣaO H%ڈ!˚?q TE q3UUmy^! yɴޏANlО#1!0" =Dt*OSY+8 .?yCBTXZrnHqɿ˽@uPjڱOrvh$M]\cRfyWqC\;e7)akڀ3#̕I'2D7чKN5#m?v{`;\v?䭔$y"u%9_>3rWm(#P줋6 *s%4Rmkv(*zY>ku*5XNJ cS@ %~=Cu(n-@+&Aww(zXo>2fȍDX 'ؗ qz"Uן-bM$k.J{uG@`f`6xސ/oI#Ϡ0aO 'ݥ1-u6ǥ]_2f. S%S]zp2@Of(ؖ,Hqotw`GfdTn :dht\X*^q򒕈Bfڤܸa$ae<󈞴Qx(N\mTB6~zf~_Ӵͅ+b_ԉͥPMN~y+^Zx>hHtgLoRʫ qik/)St`ᰬ0 sxN#HB^iT&0H.vr`cVۏ䑤bz9 MZ4y1 쌛>J9:7Ţa8 ab񕳑z(xAV HsXAԆcp8Eڥ9!ܓ`'ae={xwk;).jJn ׎O&ԥNJ!fQ3WQN~Ai8y/"I;Z &T9"2w~iZakЪ`M$o0nfQ֓~+N0L6!Rs~E۽0ƒpZ}*DHM>Y!ao7,j]isfգ{7! ~afѿmbWM_JF16, DqL ۼJ^7=24^* ]>J zhn?T,ͦhG`dGlIL8.z7LG+U?T_o/.D"T+qҸ7LmC+ix#֜iF +krs Sv: ג(&"=ûoO'|BM?VʅؿĿx~ ]<f߰(X TduLZ r #FgoB}4J"[> 3=EǪ|H=|I+2hea܋dmĜW?x@F\u1(#ҟՏCiBnNu/CD}Ei֛z۠6RuVY8DžB~*]T~^–k~="4Әb 07 I%zꨃi}=HQs5ą&D>1Bh ټ lZi6D&F>r GɸąmZ X*ue/zř"%mg/^c yspћk@?kF i du¿I, o~P2:03.C}ݙUmG3|Qظ,Qxp: WqbYh?I~LgbUi$23𨌩P Mr#l 7`SAQGhZZAlN"|6%SBcl³3컡 lkv6kBᲗ "!|mLW&ɳq.b$M@.Opĺ45B:0^Ȇz/K~G;B k#ɺ'T[ lz7T[ U+Ow Mnپe#FOa9@3J|TjU-QXBWlGd|,D`1Z;3NZ6IX?L[pb>^JX+}4v27׭k3ץW:YOŒ#%(QO- 147M'´dK^cy &0&=k~OtoKgqӶM0;/!iHN5 +ȥGG}pD%"Jc}}tEA=P=8._S ^-r+ 5M >vMc4r5N#gqgtЋiw? Ә6_'f8ys˺׌x@ϫ;-JW?r/^v:Y``ZaO}L2^&KQgv՘4_ݗoP6RTOuYq~{re)wy /Ia'N;:M#MW?I Gpplaq7y_-pב"@PS"uNse!-ArA{c|~%,Pɋ>ݩ?3J98G/H"Piu u>]f w,wi Ң#Jp켉/ j.'Z f߂pDoa\ćwLN51QwKRT<|!V M_ۡ09#S@6l%"Ɖ8+BbH&(bl  $u^v?r]q7(ݞG){ǂƻ$Bj&Hԓ>=*XY=".o_k4^L90/M('wCzpîW}3i-1Zj: r%~Oph9 uI0}}.a3mmTkjv 7PSYvDҩxff0EQhmnO }\~pOEZ}6gɐIwPɝ~kc^`u0909|Ђف@8iw<+rUg 8$brړ2"X }X,xʎpp/ 04_H];$WpV)oj~p-cܻIȢLy&-NT|x |'j+`r'ݛg_|z8޵G t 7svGSJ%Ddäq3),%.g:У$c%݇u,mwh?:nj2`ltCjOy"C[n`V̖ C]C=hMbuXAH:ǙBe~duO~;w3پeJ \ⵝcrllnH i!0ԓE%\4˖-DaXai2I}`2Cx.~xm:I} Fl&5-yXޚMs|e\By֊_ɐjS"!o5Mr((oh;n{V̯͚ "Z7d,:ZqG6V饡s|pRvܤЩQ%cdL@ {V'Ց׽ wEe|_JP6+9Mi_G:vW";K]/;qr2 PB0dB]Lzg.O? 7v Դ[ƙᙦ&U=Rxo[? fQبG޻2cX| 6rށW hFdf(?+Mj1 çqUO*5EKd٩!EaLV^", WQ`ɢ=C $*Bx3ʺ$ʩA 9B5, &S0q$U_R^ I9g1xV=0zθMke/s2A;bG5u$H(ځrV<4`j#yAs.çCLdEDIqZLWds=qhS?8HY}?1Eb9N/6H{p;jLA ˽UB'pl/yD%+4Y7쇅e c~3J|G4Qn r P'C`;vx6+[ 8T-Ro@.mo\=h#:/rQ@H j|VQ>#kw/2s=יw]: f1uoVTgRi]U9{Y1u7tpiDdIlON7 Z +PY~ `B^([V`|P @: ctA(XG AʅyR5-Dl]9 /ҭ?"ּ% < AlZp7YlCO~bHҪV#(v{L[]Hu#vWB|Ɓ # ڧ'nwsF1Wछ0S[|:eېS窴&Kj&=5W4혹$9i7۸T3[W{5]Rxb8$SNFFjFFߡb씷5KtĢ< $7soy; >P=׌6rTwD3GAP`H٧oK,G[j_{׹rhzSA05- GV F7mρ 䱾';=>ϝvI;\jC@Dm4532wyV8|s/+r2. SI–R\`s\R'G֕wM m!ߙ9^&?)DjU^\\q!5*08"2$ ϩXP֮협)h^N a U{C-F%:piZeos8_ĂVMe2;wn8S6i:f{Á39 0pw[b2[n,պor[pbIa?2,_td_2Anap;O_PBhA*m|egQc1w2d9J8gbAsϧ)(\d#gܔ?O좜zG'l@홍@5Ug,l ?]vmly){PGL2 $bQk'vҕ\f ֳM Ȁ<7g0|lg-Ej'Stu~cH*?{wR^iuB =(kCAb\ ٍͪD2U!k'5p^h;BkԑW W|թՆǖ uUZ0 0qȷ^TKA7 %騨0Édiƍ8TM$Qdn )"|I4 Uvϧae$Dɿ9.tT\ AV}~fϹ{|0JkTwBergtD^UQO/oU4NECs0oӦ+aLco rK;* n2: iUחƔT@}ELi0_콤VQꕘX%϶9xv$K\m4gisM7P 5|{yYw2'yy=3n <>az(.i+U ;3_0y%/,nIdݺ׉$r6 E^+Zig}T&i5OُV@iRwCc(У<ΔZ9C@`$a}g;b>%Nu*)1g8bO?6^)Vt\ĠjV*KbClKt`SXgYl;:Vgy!GbqVqF4uE&6̟uuCUbIaZyO6?(׈Way|g97 ;]\rV/pV22 0yD^ >:$%/@o@fH6r:\ך+,_zc[-(C'$Z9K1AF07B&EWS{J]'ߋohhWm [pbBiOk9[6k0F`jвPx<Վ`ThI{2 oW ] 62+=X˜ęe=`2 w`)H_ec ,iͅ8 =e!Ӻ{`̐#[)Hd JptsF$~Hۀ}V()ɾsN̡e`Թs, RL}z# QAqPH4C@;j5 ip7v^P󦛒WpȂ5kA x%"^h2 'HaX}K,npL#ܻ)x#yG<ĂylfrlSS>8_=jh9(-ޞ"y9bgͣ Nv tXeɩiU}4vwQ| #>ҍ jpM,`QtlRQ&O\@E9šEOŽ WqB7@'Ւ\bf $!4`r߰҅#5=eBgww:8O 0d'Hxnbsxn->E?VL .1q+)j*D2`;^,+ 1N4$-"3 m"g prЖP ;aj??]s V0LHPRmB;" B.Nw'zݲ{yHcB9!cLyH9w:]tmuk @!h+0=x3`/!*`f~w^Y$^PħS sB2:*uoaNknj ͮӲLn:j!?Dg-+q~dMcF.f>=DƶUOE fK"}u=(X ؁$+vrȘk/,RuҬFF{jQbJwɑ5W;CI˻:#Tm1, YmYZ `I _olA aI'7)Tw5dk|VlcQȥ5]PxhCɠI]> e.@th>:W#P9}!XʙDex7l*.{r,ڕov:Y6KBZ\//R6yzʸTrPd0dkw<0kס5.="hY]Q>F^N]0ȿ'@|.|ћ(X ^{79 lfcM8]l/ʃݤS0y qƧT J,[͸S}Fu ҽ ?N[̲iy&Ļfn d8*9YVR<2RI6-ޠ0r;w9!ɽQp":sGϮ]tx;o3Lxpu2m~i_%:|_|!T^bᬧ= RZ1dv|*>պY97A -Ƹz5]r'#ʎis4 fRpaTwV|0~Z͐E֙N0I*VpKn&XR|% f'\裱$$0v7tyV4WI늷x ^ 3efωxMA. QBl.vLK }:/ NwW y$Ǐ ]jk۳k $eK znuF,Q3jp/6T@m{>G!-l 3k 6Fy⏵l\F>wK5Ep.I>Q{5 lDLOQr`R &|*XQBve&zRKDo( det ᯨIʄ۪_{@_OmږO7hfE,03zPzΝ>ΐm.AtձW ; ȤGwhLG{J~6*><6 ]%{Yv82k J '} hhcUYL,#9/"}u)iwv"ou!p,tT U!!gh0ELY) L(TĤjU2S,U {{~?h沕5 :ك.\X׿{Wuc}l(׹ A]ƭ>kiWϑ@Q 2+Ѻ~n:D:zjr?w 1ůkCS^=ʉuќ:ϗΟ1u~"w;{3@W?_K%1hB[JSc*m+TH$٪ Kr,>nY! 98rPe Sra*.cU~?Lp+ ee:e4-69 gGvY[Sk1:9pD3H9`@6bzA,N;F7.+΍s:T "(#=uK3?J~xIl2a$Gm)ĝ%r F("I+-^0~i`=aK-7_n_Roo`&K-ePVF-a >2eVYu@;zQqQp+]k|?}.pxK I{psO }/}R/~Zߏᡠ1rR~$Eǿx-f!9aX'MҿIIy׫q1g\O.F=\PXnlt(Ts}H`rVA?9*\%V&(,WuE6ILY/"7ܧVftrj =n();ЎՆA>i1JhNχnG>bAԶrj/J5,W>`c%~Kly'V&dv =4sKhA1`׻ަV `T4.󒛉~jУ[0%sdz@lPuХs']AmJS2 xӋEXz K0D_;Ѿ}϶v'LoDFbOE/%RGwl>RM=L?l  PH)mU0i=b,No'%@!Dyel> )%.qa"gH(lq/ kZRtie|ͅwmSSwe,l=vF?9FS K}_%hؐk<N]~q3U+<@U ;R^w!24! 0I"{"*>y}. viLN.,ҪSXF~]3qF L)Ci1ʮ.I>FiBc B~t /'^gkemO4% &ZuK'K7,;kYUldGYwM nrƟDM'ٓ'))P;2]=>S9n:+Gݛy@M(',{W-9gіR#}#JQ_T?+ގohM}!y{ڃVamHWcӰyl'CͣՄq( ZT+lcfgW'7*"<4ME2\&%A>b0)Mh?M7؉g*#_-6]G|d2&P\$իQ sSאN~NHf51":($ Ÿ1وA+)Ю G{? BԂ`UŃ8mӋ+B芲0V b-mu* @G![ JN-Fޭd*$Me8,)*#E׫: oLRM3ͨeӂ Aa <<Qu<0I{FSU0kR3]CsF.2Y$ DpPwD6 %ceZKem&mhC;Z\y~ nHE,Ұϒ}@x0,88O$MW%}A,Vgbp„g< UQ|l=iVɚx&%mSkbI]N=qZJ_DzW1D(Ls,!%n78(>hc;̣w͞LGz:Ōv<ߌ@)94Z^!La ?RD-1qweLY&R7OA@(.W’l IA,'M%!j?:GvҰ+<2Gl&5b`9Sد>"Oe}xG{%cR)L(e~VQ4x/b Or6o$i]CzV#|љY#/}eGr5j Keh6tP+Zk@z$2,ƫaD<, UD[ yb報3p؄CԅEÒk&$87jӏ?`<`uYi$[ؕ=?<'\vEZߛNu zPTu}K y!  V/OZ=Upn dBB/݆rX} D6I_|*5p㼵e'ijQߗ}oًR٣>#e='Q=*E/ rƗE^?~(]O­9k70ISy1Sh_;pk2[2Ί)NNdƤ$VY,ssp앶Byea=,\JOzͰ &gLQ RDrSsCNd1ji,L}2|y= k$rAhG?2J-^[ I^jRإඎBGNx5[U|u&  ~ښB?,Fj z ,ȥZM!(9!J$0}o~g%[:SbbӔ5 X:^ \q弛J{EeaMgKrXUƽ<dNAh( !B/ \Aȡ=ƭ4G|`#ŗ8:|/W;jqͣ5Fn\4WªZb4$ԉҶS8>v %sЖs/,&~ 13Ʈr,zI#N!wT|X1?U ]wè)t͗ȂBCss]ѵm11Ф?Gkg]& H$;)[L/n j/*&]f+-:|oՀ`2\XZ Ӑo%I`ґAߴ,2Fl|%]-|AܝAn"ˣ+嬤>B<\W}4"ͽz2 >HNmG=xYu콅qNVtA#F4(?ʔFTI6(O>伕F_ ^,k,5~|RRl3r~KI 'kGz[GV}cr AAXa1׏I"FFs3-zZ7.łmSMR\_䒄j=8䢶v[ol~JIE$F}j9uWW2&z8$3r v 6%>9lN# +zw,YN}Hđ :*%"H`wT0}>O*&'5=Q擱b>CʖCmMc>`O,ր.; T74 ߫=`cqwl ZrC=EMeP~+m _j֌GY< ܬc.M^EU=i 9~_<<2ȵHcJ';2W˾ l.=1g->!D g!Ğ kJ8ƥ.6W:ۨv-Jd0H鹞H eV/S b]MrBw8DIRL =i]@5< YX/$p>1sƔBY6e#yκlpqGcT rkƆл'˅v8ֆaCpe ./_k a9q_~ DA>} Y0d3.y)Н ~mL8"a't0G#Du u墣3sȂ,HΒOk~Ҁњ x}Hϲ: gϜ]iL ݲ5a>Rz6Nqo! dɨ&**I7mY<ޙ3u YJ88#O3WKi|ݬr2Y*pxF]"KfKq LJv9-#Kƾ2Fih!`gJ;N;ryT؜ 6 n%8P8I6ǷoQNmJ_#ivƉAߢ[ ) Z&q- ֳزˤ3p@= 4n?« 94f|g*:L‚TB Щ{''NXoG|\ ݡpn|^I$$ #ٕ lmJ|nbE)IW@._9gbX8ư88­%i9OC^t~?xp*< !Xίt se~ۜI?4#?&Iύ_Oʻ"%SMQvy}/zb8X.޳I w^c(f|`pZ{%ίRG  Y9MxLwJlWVb`Ly`0(s?m9ow] =tqqM> : zo k\b~ MR2=ZC7 7AQ'р7< md B4 &A+0l_ q&;bT3ǢV$p FdrjuRn^ ۼ8 ld F2Gù'rJ:y_|uk~6=/TPWg("N |^sg1 &I.Z_!4fhʺVDT<gm`1lPAOf^D!/pGq?vty!*坴鞈N >HڹDDcbV{u+$%O ZE;ohw}% ww K<^+`re}krJlFpnB{ qwOmvD\ёHkh/iG\p$`|[`ԀZ(P (@b\G&rЀ~=R0bD:M kD/x @GM>mٯy\z )l԰S#zz q3u}M +L-I&kZYJF2&tgqR֓!aI"7g}44ȹHGUPy GT9L>C+ 2͸Sl c`m:;3+n-ݬǷG)S#b,dβ ZQܣW? ߞI:|= oO!2U;`Q_dDg|VBQvXjAm*| !mA žF1`(q&z XC3˦Q˚O 0?ZQH5EL>UL/ #*LL>HPYd)>ި$]U;c 6ļ{˯C4bu5rWvhb.(&*XA霓+er/[̯Y߇C;\zVqsYiik1F?(&ȾF5B|lIrxD)BʸTƶNpNs_q1iMMz'cM 򥸋R@|*(KJmL$Dq|$o|bDo K{rV, ӅkcX1,\ӍVt[Ad7L3ƣļ`sbN9k,äG1V@2@ tn7}0pFGĒ|Ì_EX7bi!b'؊~^xRf=&Q**&;p}FU>Aޜ?EoIu$c_4=9mMU>( } qSa֋Sn`Y5٠.!q FUb=B2}  9aq%q+}rIIHM IXϙVQ5#qB4kh*;bmaa@@<! g_7OUS*{Th%@g M7u|$t }LY I-[Z3 e#!!f+! HT1kR Nz?%4%ciU_{ݚ4&Ok=@XP2]Քf &EU)GUpa΋}4@EEWo%;l?E?GJ}B=5sЛJSC %n #H(ʔ셠x<㰖?-PP:H92mTxݪ9)Tl8xQDbDD6| Gd7rCZܩ"0p2ug1%y-vXcѹ.sFVv!0]zL؋ND2ٝvYDU8R5^'"z?8є';HP+Ԝ]|8RƂa=NtKTؾҘ &:\#-r~9Gp!&fI d*$6 Ccz!02_T7`ܬ钰 6 N䑡+~i q\ j DQA0 / U*39S ?ƹ8ycnx0!a!C2'P$z(&Y#uJoi ,Ҕ(ߎ[~]*I}!`5/9cp\I)ovO+X~l~. +^+Y>: Paxi`'i[.)KsB1~MA ։&O|FѢD 2 nVg5/t+}f\Jn$ x>Ct34LojċuJ%օA (m~'=W"KQ}L=}{~:nS*?s-xIUBY@X @|էzΫpAhg7 _1{G'*k]JU7'K_WNKd{)$Ԝu]8'p_-!gn45&P~=a75|p_[ qS x.Bt{*U)ƭ\X8k(7q/^zsRE|sR2]5Ҩ࣭]SDY@:keʤZd험؇s 7,Zub$JFP. m$Y .rzwV_Zh <: iBoqrD^/4M͠+X i 3_iT7JM3w`2 #B/6%|ȡuwH3lb mei:=]2OiPBBˏNy'ZU߀M@F=#W£EvfdYg<,Tܰc) Jۀ4Tף_R g7b3:W+0C15gwPU6깃GNu(<_!/e 8Y#F?.SK?!'WΒ Ķo|8ȂR K6-wh|4>R^eP[VwDt1&0L'M7$6wR!JM`êļ{+-cYܛXWC.5{."!V?IӍ&w9 j{XızvڵNTxe]Qğk4CiH?vé)f9x; UTk (@"*85Q54yPJ.1 ^5 YdR8:~mo[D\ $-F7!LStAM q}Vz?%g|i~⠢*5^f7i[ &y=diY>hwXIfmc"fʝ-#1fM"0͋@*wno8ǁQsjo#hϖo`7`{).SWo#=PWB-?&S= yϼQ! Wc|tz-Be`Q;:y;2&R~Q"Q0&%XZ3h 4Ʒp;n #J-mŨڊ@GJ$OX>^lG S4em1( ů#s-ώ sZ Na3ܹ9q;`r >sݒ~֕rbمϒ1hQ‰&x6˜9i\qY%y }/W¯R[3^}V6(gAHZߤ)M?{X[*JVE5ѰWvm3jr*7{Q^\EXf D"AqVDGĝr]fh'R)ލaMq\yߨig>mKzOkkY^Ga422z|h됮6V&\p nkeh;h|VѢzOWr`(e(3ӔC8N,;|{8vgĝ-K;k߻-@^p2N-ꩥбkt6xq/VJ\RҡzXwكp3U@q>ð #0WVӺlKedz+] (j /eYp>Y~R\NH =v]spXk yY}jtи}|K)F߆'+-lEƢ\k#l8Lәӄـ @fwH ( j"gUM5'WiV7/(9KAiՏ\M;?0f[[0֠Lm6?D@:o+k Y8DA\eEbamPo!%w)Wg6$1]\@ܱW8J4*T" o(oi8Uǥ7u3= Ķ^t'i\U\+lM>JjSpm2 !(ΛZ4ndy"6,XȇW5f \O欋c\RJhV@:ED-ZaPb[XɐK>4Š,X5U|H; f-9R_R [TikG]-Q7:pܹ# Vƙ26Ħ T _¿͞ KE:]Tq#RGpwql6Wد"j͉.J:{BEv&PM"7.Moblf;97]~GDŽK!ZӷEƻ;K9%9 oXX{gQwD hNǮFRtW-)qn>Y2}NQ-3;m,T%>Enw+p($S1W@?R -yiod]q-&'WWs[Z>DLcZg8}3yC ;h 9B̿ H>Wr?MaIIWwـp zfiÂ$C:!nk+6x_F WxeGYZ4Hs‚QxÎ};ax ) [v)_z=E,NJw{` pv%ZX[C\EA]:`]9u^M𪿱[LڡH%U'ۋ*2"ȸ5IڍE  lSt(e|9X:dª։ҷع1]_+oV n{B;J,/W1;@e]l^%z;3!aASr+J2V67fq$d%ZY.זixDHӽv+,P.p>$Q\|b*qv;]3E>yMs}TQxE2ԆfnFEԟ\͟4H#ryJF]gj2WՆW6}4i]i)\ $ 5 N?TZc࿾?178˿w*=2\ Ց u؇!MSh$ߚ5_VU'< E1@ȾY؝Q|KfIܞMLIk&YC ˃' 'б8;CbBwN"'WXN#ILyAHs0]p\vʲ|s]]ծb 'Ϥ4c֛j#%e#ܝ 6D~Y6ޱѱLuNq{]TGԄ5iy,N>ͥы+#TQy u6VK{y,uݫa@%{D!!~6 /O%al] ~u,LF.jֲ .AwyiBf0Z kwIJ)L {O^#\E T)D.'`u üvJy \:X4bD.\p}6jlk~_cH5rpQBN*TVXf8UQ]KM1r!1]^>OEVa/<~zPPt9#7xuH菊XDi IhuK:i:SCFe-xͅ 4j$3V4OXa=Ò ^Zsiٜ# [BsUQ"zS6(Z_S)mX\ѹ5jsOMp]muӨ(5<?qs%r[# FY(暧v! 4ˠhK9X@c2ܟ&3myF:(RDf5I?BsbTYǗf 4m {gD-0fj9A>A|VywFH)*Kr쌅5ТԎ} -As`vXV*6=="=7sPltFzΖ3LDq3\ ` 7V35WF(TchQ9푒tI3$K`2۴$;WaC.=3k?䰷:̽.T?_$}n }Kdd^%7y&Mꊹ٠)ӊLncGzGYa捣@U $2[ RĻ~QRtpjvHOίm鹐@ VSL[pJă= ^h_tǔ&S/ e ;bɞICa&Z[Լku;5ـvG\#bxW KfY Ay&h೦[kl. ^ >ճjHvOkV(ձVRf""5nʡNi% Όz[5vCrO?_d {/J9(Py"m퉚bc0H ֝u<!F׸A [;1۲G|[BM%{b ivt.AIS4~;ж'k_9tśv Dĥ3] :rɔiGUB*ty )YAEVQ&&ziWQ:Ah(nG hkdcOn*V҉Fm*Č}<@l\3O ",,aRa,XZ43k-1e/ިlKT_>K_.Zzi7'T v`HN5"_e1\#'Pͣ~&Uީܷ4 qwL[גJ#Q5ô͈XDz>A4qBҶSעA2ŞR/;14P-bsv5VdE`$/RFdK1,qX9::bx8 a(U]QxtiJчӲO%H<>CyC(\SšZO?QUycތw&; }0 *kȳ uV-fw zƼ < Wsuu/7C tC]$^^PDau0)~*p]}H_k!aZNЛB@ ؤђtgKAy, ]V',4w!)C"{+OcH B7kMF0>I"ҁ{H+ȥXBZbDDTc+cI,阙*Bt,+Zd1#cW 5#D5G~!t'ƒKmkzv0=ru`"ܱ v< wFiIe^|_~E9rm?]uzRO-"VRN \h8ͪarSMjD"$"iنkFO1'EΆ] {S ; ,-L'Ս"uEcɴ,@2 9Ɏ,:pM@iluޢء+zy)flbKڻM)s+MQpt'Y=cK P\H/j|{5>`>ڪhT&8_x&/cj}m"]~f%V>l$h;1\8+Co8A5CmcV&+#u?uj*yJ(PJȠiߩɰ$s@\¸ݠ$qWjnMRUbGCZOBVpQ8}^iyló^f%u^@O{, z ׍XDT<>l饴qeL p;k 쨜G^ذkF?u;8~lsAVi#ҙND3tY/ PnƄ(H:܃IJ.GY|Ó!zP/УG]0!٘ _%.SaЧ14HY;Mso1[Rgo pfc8(aʬv5ȑG3Uj$Yt1 HLEt&TW\28o3ND ibmX6;d]ݹ 7 T?M-ib{m[0{H]єկ$~3Oy?@0"77`L~j =d/F`.L7<ЉSp$|W+t]CGE0?mf V;0IhX Dj 53Ie'BOT ӘZ~egFSojw,kDC|/+t|łtCTRP h3Os#~ςF3)V^0T/-ΑePջ&6Z,|;Rm]zǕOu6i"D7t0%xFj6 dl:0N?hvk*,bVP*>, Ŏs~S l˟X4) ُ18x@a*ޛ tLZ_>(rT$";b:S)Idfh*9W/!h5ǰɱ5m^@Sg ?Z z<x:1OZ݀cnA⿙K.i8dcECԘVQfY/}]6pA曫\_3рvӂS;%.5'nSu~_O[u!1xhG8 e };HDfUd,S:l@:aV@x]e{ܗ%W8S6ۻtfbۖRv⬰!~{z  ,8d^i88*<Ċ9eDZ(" aסB)㨺0P4>o}o$߁p)Uw0Ľ|0?H)Bϳ6a5sZ9_1ŏA0=!/sfze:%^Y2[0F^^gϛ{$Ne3 8Ȝ%r7'y| BjNu+uPPK#M:#2`j&}D˵ZRH7=qb_sv)k>32OA EzUnrd|Y\z-Gbz?H!P?kY"aӏ2a%t8ʡ;+2"N+x ̰u/O vVů*b0,D|j/KvSm򐉡FnX -."e F)q]qP⥌aƼkQ$yE? nNV_֛:~ڽe?NR\ѦEQJcܔ:#7P?`O,? 1GMlGM*EQ`ueP/$#i崉?u/^[ UAҔ>.YfQ!ZrvXPs 7J{M77sd︭,3;ʨ愱. ֭>2PDZwc/Tx)5XC""(zKjׅ%l;j_b "}|2^ngeN#s>Y*a -iJDW'h0QUL^T}RHQծ~1g8H Ik1F: ع%偽oM_Cq<8f',;/5^iK)h"+pdϧLzI->=:}wٸ7~e[Z%Yg.9ݟAF}1[-vK$4X<$`703Zy<\Q3̳<>2\Gyx)[DQSF Are{Jas]joA?we$9UΪW ]0U5FQ,sgn+H. #sL`aՄbFu*WwBIT(;,t]jfCOڗcۗ(~+QmZkuf\\䅛yC#V 3@E`a+?7Wg>T- A}uHULDگ֊*#L;h^BRDZS,*" GU21E'-¿S0yHHyֲ G ЂG%0)J V@f#~ 5Z %' f+\8;Tjn2j3#KhbJ|B/Lk.Qk~Ung$L:|pC[Յ~3%ٚø \}QG-`ث;g mڸJV_Y,?i RF^ P•0a5 2'a’>&DT}"5<;ftWtFie{爓4P$ѩ;=}1=˚}y tյd[<eS"Fۂ[]3eP\rmnNq7TՑ^cӕ!9|6:zsnREǷ22rTRO;Luq}Z.u4uUw cjZ/v =|MSMvqX{4X.p-K2t;{i^ƳG`\;]HVfq W N¡vYH0+yDِ5?80ķ wh0:z{ awK4\%L5N h^n,h,ByY}ʂ%f2|bfƂfWpנ1*=}ڥAlʜr?rNytrK 嚇sDuBn|B`nDHrܲxpM0!*o\JFy(\4s䁻WM-nh>К^%07.ENSCOJ_`&ĝ_Ϩ Z|V6FaJER>.-v)'&~ggr]Bw+=pFF@=)eֱJ#VY1}gtcKؚX%۪gb*IH رMC2_)(&#$2J쬢f%\) z\<^ِ)~&dV,3uHsOEߴ^dputw~`UvLNJ(HUR$,zL ܝg~JFzu i>)m < t]nvgL{zEٳ0>\2[s!`N$JXdf#?]%GE?̼k ܷ8%Aa)~o9վ NYmImr#DY`wl"~w> Ӭ èa:fǮ\rD'G3*%0-#W+&`':(wfaulg"dAvӼwlJ+|dSK%,-Pky"-)6RÈPuxQM Kk9:Cf3*I(d/P8?eOE-f&;vgn(-DI !)7&cvp: ;) czn˔I 0rI*`H`QwudEҙA>zy` ӏɋW"3\Rcucmx&2,zdd?.94hyt\X6{YpsROC̆ch%W:=~4~*`ǺJqtnWk " 9 g\uc?lGVq&gX- !9k]4o)RYɤ?N휪Zo4x: Hd?LLdfG1\={d 4}4E빯.gƮd&%b؃ޫ '=CM3@NJV^ }k7 . 4Θ )'J/#[e-  ̙Q4Ɣ#°ƺ*Rb)D$z<P}̓Tވu| 7Aޏ1L 0'̑+/&_@O ePߔ-k icr.+2T Djf{&O5̗`-:7#ʌI=`݄*d4z<+xc{`ZI%IIӥqln3:~V_zA~I0#d4jl\仩<3Ic<qZ9s. yVxQ/Pec-SLlYyzf޺ӫKn`3gy,)P,x NhV D!eTsEG(.z'=w#ֿ%;jYl VICY.ҧnSK9Fȓpf*zTBݤpK?ISa̓ f}T)SVdR\Q`4Ƈk\0O}iO(,IMVu18ee~OطD4 Ҳ,?Z1-DBڥ9 Ã<6S)>{1M RxBvhS5&wa{EJdV(ō O\85f^:!.āe6m'Wiے'c)Pʿ>j%>({kۗ]}^%˵[/N0N~yf&xNbMi+@d\lMU$8W=[ڝ.k7³E.,K]`?n &h B\5cQ_ԫ}K GAYmˡxo=_9ތ^6u—)vES$QI|FOfPI=@ ЩC.0l( r CJ0`uvs8OD7~&9铊C1~#_{0'Me{\h$.^ dSvm`٢wEVhBy/#n;JDW/R!",AY*j ssume]]M-P$eTIgoiU E˜ XqGy~6gMPqMԲnB[ aU15knn" Ylqе@hAN]Ib4$n R昧>.r+Ժ!/nr2A^, ,zC#!ZgV G~ 2L1Z[ɛAdJĊiQ?53;r+]a8<۾(EKyH3#E8|)UډXI5riXH0I,ҷ02Qx &Kv4v)1YUɲaDvAQ!*_%O87_/8eB@xHMPW\!K֢PSp |}fE>m^k 삙QXa/rA݈XsV"vE PUӈ 5L}  MsV JY(0[^hٗQ&$i7!湇XTyI;E11;v "׷˔dyQ5FZf}̘6o%W `.h0ElB{K.>sJbSȍ81nfjv=S0si2F`85-q qLWPnrRжU(jo~pņO]c]VchAˣٺ'wP"n?dĸp s@ @,>qRf(H@)-Es,1 y5גzmz&lޛM:ESEѨℐ3'g.d)V! + h톹/_g!nal2 ޟOp9wgcX'Zs~ߢ5=KcOٻ7WMjk Us, -:fB p25[Zjh>zJ;jn{tw6~b8e,1 RIEO-/Rl#¹Iiп觚𴽦b\UܤG ™x3H~$EE2erJbyLڈgl8{11!2Mk'L_:\kOhY Rgo\o~FY/K2NV_z,pѡOa{tctN-Z+B3W0`tVO~)6뇣b2BSY^ݝϷxyۮy1n^O=^oIemTB..v&j: FkF=sn ]Nm]e5 ܖ,[-腷{jZ_rvT`CoAkFq NI7P޳f0ZpR/EU# QL_qtDQ.Ԛ YʭZvdX? }I\ ,%Sh}*5!I CNlXYz- t> h=ҝCxRAE|#&u# `|_y>F\d5a0CM^e^T\̈V!EiӨuj`ᛄR=w8`Jk}N{k#LJF4$e5ú% KXc9~ ^t᫟#c10ZDϦ+N23~xd g^/ x[#EvnJ@ ug;Yȏ`3ȴ%(SD]d|ʡkTn;ehk;|{{TIcqo8w#} ilfe>/nJ]>]XӬ@}jcKJ?(F3Q{>$RXsU;[Dqk- 9By\Z@_ TY4b`C$/nkʔ¡c*$ĥS9 a6'._wblg@_(MdבXl#<9.An/A*oޛ:J^͒뭉Aޟa}J\BP@kj^S͂ⰶv_A\RHX(ꃔUsQHnTQ:ɐXmgucOԋ8+<ϵ^EZ)y8B[K^#rbi/+#\PDp AuRl?S9-ړ>k;Ooˇrh3R)qH8D2`p(yv`+81@M}[!ڐ.e=nzspw8a g2KD7ViU!X}{]WŽf ]# a 9Vj]ݕ%x\jk\6Uȸ)L ѯpф]I&,3ʗ,߮ 1 0ϚhʐdyQ!!]Kc:p,"t;v$ߣM{0 H"f+Mr^n w^[bq}ǵ[YQ<.8~*~ FHd42=~"Vas|Z8޶V+H큣Go O>9e*Uinwcmv QJF+HYf ο Zu<>;C.Nf]OٽDĔo+q:)jbt׿{3XRy3Ghv .7ڤA"2׬]ȧҡX߻}@T7jsL:vZ"3LC?I'H,E(Y~op&&ph홽*ssǿԊ-?IK/FqXw eSp47Ba6dWyh3yQ3~M?{=i%Ӣ`2N{F}4%5 ZnJʷG=G1vzJZQ T&-oC$ecU(DVʞ`RGeY<3 ޅ%"eQ wLX㩉ŰdFt*JDCX!c|?[=^w3FiB`Űs֝>$NC0$A>>m&* j 1+',n򥊟Li°Y[W tjڼu~ư`/<-LRPSF%@6U;Ur]@OO*baiӚfFk#`"9D4 xO~>;"hUF 8OMWjn z%f*^;^%s+MƯ ./4Afx_CaJ_﫛GuĿ'5y + %4\ $7֓ں!)!҇*LRL4E~K.q{Ktຯj(Quw". 6φ)AlAFv,]pɇ~tLnس)&Ԧt]+d^nzu&Fdl~b$+j~Pz<v]!} ?əq)ZQc]_vA) 4ExX d39ՂNx옻'b(hudLeq61S,6v,4VU\Z_t_'}lzW*,;a^Q`9Ɓh 6y$Pot6.zD/q(RGP LGmOl7otSL&"e&/,wW~[Z6r0?$;Jv2./ i5awÊ)Ki޳@βl*7܅^KG#9˰pU C&]8j*reu;.% e8 @u)M#lO'.VߞA6-NGl^EL$}CKg[^\gysTS8C`[*#FjXyCܑdsgLۇT6;U-w9Tguw c8"'b+ލ`س{2 ZXMleyݛśߑ&P\ie%B35F-F!-XܬnqRFU#b@v[D/f$+(*[-PdX ![;)WF11- /&RB ;*/mP758 eeYRxbI N,Ir)(Z˽G63׈V%dj6{8>`}{~k\RIs@ЁT~ 4WK.E/ln!j1[tD0]^yӝ-bܠ;s@MzB\!SDGe>=&#i Se"L5-HV!0LBP!y|PďH٦ -6?Hp\ؗTmEkO2޸ u0&M`5!\$W%NcWy*WR$EhV Wۏ8|j|# Ѡʂ0Zd]bJ؂^8G@ڙ%dn;|N|?4M2]c<~">Ts#:  mS&8<`2zBdܖ #yFz㟒 3]QHR* yȥu;sJ$WTK } Ujդ艴t'g)T }kA]YuiN]eЃ$ B|ޯ_8i9:*soyDO/z$C 7W,@@9Ľo jϑI<)lbTvwR˞~ _"f3Z]#RSkT}VdgʑWhMʋ8uhr@[,X7mѧ bڒ޴rxRSI ǗHP3: xUr7LZ9K'%!6xQnOho=']wÎL9v+\mSiyvP)e7P؜0Hi'2+pbyOKO +0JԬ'Dn.1u(Q(έiEXc`b栎mYQF,<\ZEiYÒj,'@٣SuQhQI:MMʲC2 / zf}%{?M?SڠV N0OY@[ "Y3ɦDKJc'ߒFPZ- }&z.@zl#EEzN~~1̼agn"=DuYKm\c̠"4iixqLI;}|?j(SRV7 zf* ; ʉHCʗeB64.NT1tVj>.nJ|󏦫l;DF_SKߩ)?-j "[.- vᯌ,eѩmq1V$h_ivs' _|`^<-+#m-+;d<h6Y✲z}7s~ssaEO,*ECRXh˅ޜ$V95D_>jRGl∖) 2zBMI_@I`5F rTK9@;F 6**֨|! ۆ':ltժ8,IѱhI6}䒲E^%Ha &d]a):24Q&=:{Gl* >f[3[4 ==Vf ASEŠvW~eV6QHEG Il8qdylbA4Ooo._{Y@D5w3A#kCn7ky8w&pcq>EKZ1{;r>G}.ɪ?+7朢,2RǧY]@MAً"d< eH_5тsJa͹38/,7' _2}i`!K7Z{2d?5BbxIu̠PHUq Nx 0y[ݳMrs;Q\np,ܞT+ľ'qm3X o.jt^6P iB @"C.N3SڝiȭygwW{D2{ C8n!KChhʻrKt{Ks}YX +pZЭtk?ΎҔmҷ?n;pL̝ƟD*S kr(|$L`DLY8zV 2==%91uUջoh2ܼNe9G\2hpS>5Q\fH ^Ђ~N┧}7ĥ>3@ؠ-+Dz#9C b+{Y.MY⦷!Ei*)~S?gG*{!puX;[{EB`^T N'nlra[L+T^ J$I5Rg#s?L7DM(Ӎ]C/Lȼu,'Q t5h `Z\4W!~f55˃ JeI9ڌ(eX)Ch P}Y% DQ^xYu*4:-+P]@pH>|R9N%V%[M\f[2bH;0cb6h,>DlQ8].WP֡7@I6X;<85#YQm<{p>NR#7:.-4-pbk/j] %#h\G=쇒І71CP,OKOQl1/l891X/ua!56,ƶ rk\\^<ßÞ?v܇WI^:8siE>⪭M` C%̐+ d#c A:rixΩܧo@̝E&nq\DX АWI2*XpmaL BIy(yO1g҃d5xҜPվoqSNg3(s9`Y5r^`W:tZuh\rl=v?U fZ(4L.c`zxp/O0Yfa+֚Y5z#aBHF"b,;$4H>tx|9VVu-Fi^}@H;aО]$DВą9)C:IoG9H8Qa6hYFN"|QEkIeܡcBŊhסc:4,2Q炕i07=ZSdQaͣ4 M&i6P?W%Rh#5N9ĻBYK7ѩɌwt=DEĥ(a;r6:na+,˺G~DpN*Flv )-#Ck7 ~7R+^VrEځ7N{'PcAc5ӽ 8]]l^_`f.ptEZ1asO3s޺u[2^拋%hBX'i\=P?*{Cݔ⤀虳i^r?:ELʤ gG aYfRE 5Օ;{6ouzSKE_*Vg7lQn#\n*Lw6-$.1ra"7ъ$,ien~⃛>80nχ618>dQ?9}/APV?ϴԚnF1tOU=s^~O1vo~%V?SI> =OIE{nm-k^[]C;%G ՞@1 YRdhKw~jfI)ckeonʕWy?bGOU o+3KRMly^3[* Op~Zc<"ǜ*Ht* ?f=ұ5i@A^4 |CCR$\ǶU ]; TYm[ɠ=o,!0\ў3Xu>Ī)P`bHj-;/<~ o`0ZAAbmt֪~ ۹ tmgF nCaju+/ǰ,`ߐߢ`#TLyVvm 6a[ ϪJ2 PX[Vs6S hddzBPY"Xj-#9~;BDRZ▂J{sϮ !ysOЬ({6v@/lX_,-6I5fTa(/2U.k*!Į 1 8 cď]~ɍb[摭>nn~=J 4S:_t:2ܥXB)gV"Pi|\KEt?ЧJt:u_x́pV$%M,HQ9SCW]БU~G|IN؍i^6ƹuԈO?u֜.ϲS:ʅKy?Sf/Jrr[!SeYyv&Y%&seѽ*bMHOARC"i)Z,!J ] Aq#(.0!q r(j<g*Nh}Y6DxY2r6O9P|~)b[[_L;ۨOV E_ld2К9)8?! mߧ"F4* YG#cܥm'ٔL(8WrPAnâg7r"Ew_Il .WUљs2V@+4 Nx|$}d$^l MAtNa1|qJC0yj\DIdّ#bfT ]c>dua/ߓ!$H_~P nD6,Y\?Bn,R$sONRgdD2̉saR7wBrw(TF>VMɜ}G36e JQ҇zBruJMbE4gC=in˯vl6R_3%jU4-q:zRrw_[@/V-9ܤzzA/fD['vV=1>Bh_QIyRC&q7̖x y# WE? bSO2z=p U5tU!aM焖;)$aq<,KaYTz-u]YKr}@aF~O\8j/Iat[^S?Ej/RKaZ;Whҿ L0Fl>M+L/yLϤ&FDdLu%Q0$M3Z: 2Y)G (> I4_#F'XPtX&m'wy=ip/FTA"J?@,=0얟 "tklheDuspe#C ?voZPNϮ.<ǝWz9=);%J%Ϊ?HiM-Tc[guˉ?rwԮ0~5X*7 LX#"Ѐt !QU)Ek=1ۜ] HUmG/z%UBOo{Fpذ&3?.`ojw+DN,\uz-w}hVo)pF^& [2eB™ =:*:Kk$Kr>#sJ/ '[J|v4| B0@3 ? JL\m鲙~S7w-uu# f5>l^{wAthȽV:\C0!ZB[cEʦeD\2Ɵ(5g?'7)cK{?G&P[)=&sݱІME ZU;wq`)4vsmL- A[u4@k=9&6^e6BkWѦ@k=R_=_&J[۷2QٔG̝ j"qPki=t?nGc{ ^W ȁy[iEFiR?u<O)%ih2yO#lT8Me *T,GKYEBE#i* k\VJ^ џ qCW|R4D}!M?y[uqO<_1!څ8PA2ЕZn'(n)>^x6i''tf%5y]#gݛFCa".Ѝ+>@d 瘞%2&0]JSNFĝ %a%hZRB$Q U+'% j? 5-dw|2F#T"Rv~ CGYܫ~o>t~@Գ)Pd@1ב#fDeB#T)FEƒ#eqχ_Ol>`/㓩YelYap*)ъ) 4V7/Q\no8OhhV5h nf9"$ak ?EkhˌF g/wBf^hG6p_e6_5I6D~c*K)2;ɔ4v #|*aZ^)n'9Sx:XSb(=<:u(> ~Óۭ8ߕ-D*i:b1_/Z#h=VN &=&XuA0hI*g})u tLBVI/7TP矌5Hk_[d\5N.sjVEٝ>|zR\ȚXLF{MnQhهLiHju 4&du;TL/7ؚ83P=(-"\c(tpUw!ᘩRkɤg\KTCN4:G ltQP)/M̓tARX7'M]gCQQt~˩<$&mk /EDP(|9&DTCq׵̱Gs8˥/nLGā;,[;y>b,uLYܥXcgzJV"z>>7 zt̽Tj*UKKfI=|Eel"Bl.5gJsH5eV c;U{TB`6߭C e|w@e!rΊ+I ,Zl!_hNl2{qߠ 춪=7ݢ%}z,&3By#c=!:gΦȤQ tiOa Vۀ㻍pqJ+&EO xumǮOtg(k_{B~Ō=kvpDGl,E[\ERI }˜S.3IhMG낹?N |m>kN-q63DyR=Ƹqfh=p]贩kdxVd)N;N3Y3-*p`)ExqDfϮ]:c8^mbVKMAOѨĀkmc3h"wi|F+moi1 4%+%;i:'#!HK@NhkW;V6V\o#f _u374Hȵ.-@ 3%Gk#ʱ81M= XԴE([VO[@#EoCq&}wBL\CM'>~^(jɢfD6IS[.rnf V)2GI HD3u^Q@LqXoye5 R](IWiyqMpZȸV,LGa\z蟺PQצE\J\0__+b4Ok=[[!n^AZ/&:3,فnYi}+AeR}xXrcW(tT楡dc|՛$"8(&M{Z`7 eG RΘ>k-x9iKȱs*Kc Yxňml~CH9]qD8u} M{͛\^[qP;J݃?0ʞX`o8o yhmBCUuT`sJ;Wf ZːY< OdUߨ?#g$Αx,&h6 A,UVDD %As/Kz4|չV,L1[A63H;5B0# ?K{ ƒBT(:sJQDzJ5^k:&DiONd< ʢ I󠌃˛ɰ< UM:03,hJG juTsCb.MiŅ4|Dyb)o~{G\~ˬ>ȢAu8P7Tc/]Kڟ P#k۷~$]5@BrJ^M YPQŅNQ:󤤌NUiAO3ryxcn lR&`(G wYj9 _q\`lyAjf "jX~8ӳ@#Fd>%{ZY ֍%UkJ@_Z y6;-.^GRd4lb"m:l' y3謲 ^3>wG7"vs>"?HP,l.j#%Bݠ@ Iy/]p%)=$/=$#M|1^Kt ЪHHLַG,L󅓠`{j9FmA"FnK닷O)P,= ~d6'dǛzR48ab1iP JM?ǧwOMRl'8¬U~ "V^f+2#f̆(@5"AtX2!^g|GT*=lK2,2 W^ T 1cŘP@qYm :ؤ*iFYT,9Ǣim&4 qVc9S=JG mF8=m6'2KYo3I{$>]?JHMv?}-4'MA-=24:$~LDF4q_Vm#LVBsb hrmM7OiH8tsDD_f0sq e-ޗv6-dM̭ r:\e7o:^f] G U5cTYq.͈O 1%q_'wpw /%8X6N)_ Ɂ.!&XmwHemo.&RbA$\ٝLY8{djϊft G8"KIe}J EF&v*RP sTr.%i +|NX 57d3H°gFqOʨ!"j`YĊ}z2pmWP٧ݶr"N>'\N/(;afi63b6,[j4c3S u@~eY1eNܵ&f4'z#!*i&Qo&Hi'h،yx!ysXqY79,AHMA{40]*7:-:ms%Z;"@txﭳ M!l՟[ |W-@F3P&Kѩ@6'6q"w \bb Dei`9\E\nP+6 cP@-B*j \A^XN6GVS,/Y&233)7ZlS_',#ft) 3j~û$WbB^.gQ[We˛][H+ƋkAornmf BX?U֨1&pF IIǾDZ- H[aׇcAnp;Xx=gvK ]hJA){W3'&}@cR+.{W* cȯ QT E_.e*őiSiJd1Q;(ZUlE8Cg q֘'Fƚɡ*7Uoep<6}ݖHӪ@G T_iHi1ILm`9ÁXJ ? #bJɈ25LXJ,]+fwhX…V$V`M-Fc Ь[e.R eZ2iS5H(\-d3qg= *@Xa sr\hm)e/7Dg&Cx!QQgYtګJ-4򠫣^:/>S'VKx&+b!fVE*}[!ٽfA_ g <Nl'B?j6zTAYaVZ)~8'ŮU&WyqVxPm^qGL|,Dz*Ndej\m@,T,a"I3oݥ-6z1æD9K*x/SEԂTC(L~ZLC Ϲ{Q§D*36owFLҀkmNDs±qgtֺnta?*kD dM<ߥjc׾6*Al~X]~sO[س^So`>3r,_2~ :\|ݢHl(V`ڂ;0P jAB+Ҋٴ]–MtGեao9SUցӖ KHVwmř-@S 'ٞ0@~`ko Cf 'Fxe9LSpSzͅO➣B4GC2mtvD$1njh!TwnWZ=S+6w&ΧuT0pD/Nj9[U̘%u&?6QyrVkX7O -;km5^EW4Bpg(x3/T\Nѵ`GRC}4qYQR[v {6K4o= [^7e4bo|()^> 4" C ZRBz6?R}.:~,AD՞8~cM'ކla +}NJ^pd<պ >g9 Ba+ YʎC(kyӭRK4yؕvL>u l]g0=N#ijEK4RcziuF&-Ǐ|E{;st$6!*(HLVanzuejx CxrjluW[A[p&X5EcEK&f{XV86Vr qp B1\s` r,TG6Ú%.[ P-+L赚j.9)LR242ZMX"bt'^}MOϢ^lҺ+n{Q!» C5,f`s59|.W`8<6UҀ8cӠ'sfՓ Lz2M!-`0xNW E5zP˕.ؾR߼{}Ӿ"mvyݹB0CO"Ǔ2jlm8(s^ ~zhd<>'(x՝v>jUƀ<q1ܓ#])}waAEb D4RtӮ Z## nbkvϠڪz6+q`m8<o86YdApbjO'J}J% @j7]#w >lSJG@,ўNx8W ZZa:-J'2U2C *ls[wa; %n~|آ2RY2(l?SaU8)O)!,sX~辝sdy*Ҵe4B qv@ZZQ9嵥{$=Z|:.nB!5:P)o3[#:'dq]yw@6P#JQћn,$C;JJ̷0PC1ӺtN88r"ui{HR$ l?r.-aPXbAHZu+!|ycbs Xh^,>Ѻa׏}/IH+ n%g^X7n@5`}@U7`VEa6k{-Y*)Hn EJJxɺR}'c?rP> f7J)+D2q9FO, BQ ISaB \ |^%\.. -Vf7? J%Ͻ.nƚdux;@pbX>ȬϵW^I32AI9اO1}'xP` p< S8a l;ѡ20N&/jIi!EYx~4a;N!{|^gs:f!8kDH>VNa}T؂'[L5K l{IG8okS`B7T#F. HJԔZl_9-F5zv}!!XH#摈0HmL{Y=]=!]47M?tS{ݴDa$m8Bӟw,6i(L"Hmr y%%n,*rf1eGX\e^Q̬t@!.ŵnqavΊ{igY< LP 'tz'.2IgI2,1GPԑhwk +Gg qɟīӏ82Xk΁"5Nb1]in%I¥N %˱-wVP9^s3j9F)ߟZq'GY/ݟ:2 5ܩrXG'fP {+:OܺH6.LX[h]B!\`$}^¤jdq63%!(lUi-+(;7=Y;GRX2a3 Z"&T E~B uxHh?M*"KoS]4[}ey]*NZ%0pҩ|!vXҬ&-bz@1ݘtU ~3E wƿp bzT# ,Y{~3Dy͇z0_~O޴uղM޵%l\|30=wse2 ڴ^9rM}*;-D# ! mC oz @%5osnzgM!0 ͖+S4S'ix n)ȶņIhc,!@{As]Y {eC2up-*:B罢3˵389*QBEZQR^!xeA3#+I4`&smWJ4[i%QzIjIdGF$@K lhN^QhMr4|Z)dUOʡ4lLW#VeVO<@9 $k;APzU2<|V&n;ҹqOH>^:`^3iNF밓o9k+bӕ-"!]hPz8*=/IB{n-`[ֈnS՚_ڶs|L2[,o1/8w=\Ym R[1 bpRڜJ۹)_΃#vm{f%/yHϟLbTS$|4r"SHEbK~uxy-z*/ V)!M2,3 {?6܃۠YZdeZvH 6v-g Dx|G]9,&wUw|Ⱦ0w'F,;N2IRSh{}V6W É哊_6iEoכ&vJzDŽlRD)BHӃ{ N!;By츀E^USk A@s%rzl.޵)#L+0p 86+/Ki-cM) 3=&49&.Y}dwVLnWY6 0'M ]GՔqԵ{޵Cg~uXO5Q*myȖMs:{A|js |"p5.T a~!$[5XR/\9ofze{=+<3PZ Pm {E,q3ZOAqosP[d*L%-̙P/S]ڙcY¡+ Fq 2|@|\\*ΙRlh<[txmh T~?BlT'78'L#&l#g/Zo(=:iPRܗD:y_`%_WÆZնXڮD&@tK. aZO{&š04XT't7MY,$tK,S>g}E=CaS7c41x%kgg8:Fn 9()o؟>rJ7mԃNpNjJVmv :;|xH@q˯|1)mnqK6B۷ }D&B䁥1{L)X:^wte ʽCr贍xһ q4Uu?yV•,<𯒴>aYc{Cp\{,耖h91FF{ĉz{ҢAr^%ݏ5t J^?UgMPVr;mx{a% ] $C?ES!#K2F7ЯA y yD wxؽ%z?>VAa+jWRN: cuIo0trCCkO:t@̗! `3d3&ůlS:/L@NGe\{xqɰ<`Fd x3}D.n3tSzw̭b;Z$4UI..h 7NDR%AOrXo 9Ӄ#5:BcE>22 1go+b:> Tj\sVNFTU6Iή[>/K[ ŋ:c1&Z:$:Ms1`RjŶ7,f"Us 2ƾa/ΩBWlۆ>O2"=ִC&gm/}mr8l.#m(KL֜ XB- 3ABXIHjÛC#6 m4LuLMń&BP##u/aN n}cQNdR=:mI|Sbɖv4?U@+oq#E ~z׽Vbl#~TDgF*hD2 f`9G^!e@Y`6[8B_>X[ZG [qđt7Kڡk~a/1S2@" #[7HYq V(pu ƔjNypk8-+)Ui+FV2~T:ŗY&d6>()5Wa6aq!K[HN  #_/`:#C|7qf5(L̛vdq/ЮPY&AcSgYxQsG91<#uX($\K|Jk>~䷇nءm,od~8"= fL(g2X^6-_`1Vך-+Ud+䁣Qka B~ ;t7490GPH/2 7gYܤh3(p.B.Kp * ت(Lt3Wp1`}nRSܗK0SYPgۍkճG>YAOhԄ?O7[ިYYa95L5ta_O9m(:Џ;aIbl{&&b aQv [->n*O_olM>V;XJG-:\;viyl?s?:br,zԳٵ՞#nlc~Z 4b0R/;)uw/o]Ću:_Ìm<"1% eC<)S~O& dVuue0= k \ı au,Rw{.8E$O!0js>Fcy[&w9Z0;em&>_;z%&!oȯUc-‡ce_ḯq0{*gn5"}?;XhA9\/LКHy q!2\5iyJGǠYI`$:RUl8b4ݝ#; ȑqLVI8wZ8ƻpVZN2+f8MQn"ZU|}P<ܳoݝs4R+!njU4"5>h"$:ONKAezS{ׄxɝޜ 塸65(Vz*.Q\T@#YM°FG@3A'mhu?O,;{Z;f@Kf>bLm/dV &vF{`ޠ܁W!CbAA $qd&aejՇ9.e:AAq%? x3Z4m|t~dKGXRj)8Кs1*뾇0NMgcJ&Ʒ&wxa UߟC6T꧹2sbh2 "1>9-tw٧*7I-5HSt`ڣ$>т`fegQ gTc߬B=b=:v4.XugS,uRqS'9 ^O4=5/Ŗ>HN=J/{hGjP݁ 95͚ȧp[lr nk@fk%MC1R8\sEu FuүNo4'WvX{l# . -:,,ʠ_$'jU]~^&Mil +X*]ߧ3k[FGm-,lce5sc܇k29}u;UZÿۓAf; q[< l C3$7bRʹf(q<>GV!+ "6C.NH?'3nuL~TY.HJVi1f oﲆ%Y,uj] i^-qOx?0+a uwmD&5O#uFhYuli.1hYMjxmDrT{$5bȖ&>DfQYި UH+y/[&\WtQYi挬v ;R)w?eda ̓eXZl% 8(c4롡y`%Eb"i0޾TѴsgXѶ$~W02Vtb2?[6??1Z[ `W=`25xAK&Zˍ" )}xVT> !_\};1}ޯ?/rKdƻy k|jq:ޞ<<|€+gXw`joùCV8I4nj=-!{ U>i)ȋK(?w@3R}=qp越 rtL!M]\ ԔL7xHŔs5Z$sdYZ :~w:"ZU>WFhC "I,[=ɑי:TtSqt601ޣ;#IN$C}y~g+:ޥ`HYXU?{yfjmTw ֠tC?4 Bm^,ez܁9!apyj*!-BGUO̿!$6)#I"n/*,#MB\8'֧dXS_zIwʖCO6_4Yh*:E.;O8*Su.M2kC{'U@_RJ[Oxj7(k[$s/vSynzgѕfO̼'WPONVit /Ѳ1G$̇i z,o8|?fi,PcA а„~`~鴰cWu@fQ0Ur~Q%ڧz>K|B:,JU.;K;3.F+yy%xrxx`C= }ī}h-TpaI$fY(uLAV>Aja? soiHyָH?B4b>O#m;5Ky]px\‘+/*~Q cT[fi@ֺFnƔ QdU2\)7|,h8FbTymb$ڍ"-?^\7!ڜ@/hs -dV~#1r0m=2Q X 90"t#y蓞:73a@R}d>Om7 +%*!w;ԏ5}*CJO"Xn/70lZ 8ލ'3$SA_S@C"l7C: "H`-h'4WcPj¬kE>8m?X7XJWVE8}IK/#^[ g_i`Z[vϠHKg9eu䇎.MôFJ(Vx[Is?#zux?>B#zLNь+)!U;]11͝!ZxC̉)pwzvuZ*,ʪ1? :O~~bH!re7Vgòf4P4@~0X|@eRw iZPt<Ћ* > TvO&*x^^N e w,1kZYS6LeEўZTk~[mR$`c_U =D$ JE8(^ P&zC~i 7jjX ͿReH~(bo:$#J^?HHa/4JMr?j{ 5gF´/xdu yGׁɦ[DBcI'j]nR%=Ánm%Ux2FoxgL+Oc^pXzĴY9E5%#C0m.ZF#7H&"M#?R#wB E_CSlM!`V{';{)ήGPSeݛm%ەN8Y)U*7aԈ8(`E}F]][xѧƣ`YG \oK[c2I~,TJ;goyM*'8猽 S:i'@*{<>toU$Zpo!HEg3C{Tߵn7Cĉr[ _Vlv $H$r.)R[c$U|)4|BՕ-I<_1ugRoP٘۩Dv^BXv|gcV:,,߰I*1={Q!dI^ Zt]=etPQƆKjٿJXn 1!MPr8:ULDPLA%a6$?c9MihHT,/| lQRsš[UC-AhV)c:|㹜:8t` 'X xy@0?)K 8Zms~ xYe2 FcƾJ6a .g|eGnҎ#N,wʠ+37o,WԊ{)φ]AhzF3Ֆb>h[ 91i -IfE^Z)yͳhHi :C;ϲcÖɹ.> Ȥq7uqϜKN:TTr-/أTA3iqZˆ S6k7NO.ca׍m<7֑| -^tߖo2վCNj3IN\"M ٙ44;w2^Cwyp_l7$QHFwwn1[ŽX/iK3?iȨdi;%j/5QY&ss=~0WTEiC\F`/%[o2$סWMcmph+u z2Zc#_  F0% )ehО,a"#:~ǶEt![. [{Ja /oGwP_r&XP6f̹4sϛ819@0lziOqğ:?4.^s_y_4om(UTcBcmUyb[2@_0(0ёv`V%yĖR|WOC (Pe ;1~#U:_H鱙HnjЄ}頾]".)ωc֏XѡCCOXD_ȾmܳH[AxN;FaeNڥb5jNµšN[.}dPpנ| ɻB*Y[Efj074˾y wߦLNT ɑ[w3`(j{9eUey~0/rB4rNB(eE–O50?ԣ'Bgܥ Q,iA.AJ f۟&"+~=ɎB[ms(]&.pS E˧簕 (odhr0(VUSGgUXTP%c9aP<%l9E@HLt^W [fqeG HHsAt#rm6Y$x0<sc4TH?{|ꅮuY;]28 sI$6)ӛ;%<CG&(,־)8o9=~sUꘕx޲ r(x4{>K>!gD3_yӈ/bDUn:!%nc{3£F8y3ŋSWgmwsA_iHh ^̟^sPƓ MFgdr 0̡蜨~ҁ ɡi<ze3u8)=kNa2CrP{]. +!wR\_B(0 ?nIӫ9&YՓ;J$=0|ů93uTls8-dfkT),VQ ^G=._aO0~2nR>әNY(*o uGzz/G,PU =p {A9]zϹéBXJ4R5lA0}nAGg]:_Aꁿ=4`b~VGWp5n|I@`3өXv3r >T|7kSڳ# S2> lB(z@@Z6jPёT~5젫V**8 >Qd;3"v$9=7L#W-1h/.]+hxb vAPg@S!a"#M&nވ{݂ƁhIM~OL f/u[j<߮(M-,fjrL=w*4k5-ܷGy"R#-bu<8x?=y|Ñ.GE??9z]w<@+VGZ;քg)^dD@),c%^3ԇmUX~vB:¹[6}W/2hu> XKʨ`&hY9+.q LD)T&GzM '&c'4'zqMB6 yHЍÙtZÏ[OmaE3TBed|}ޫVp-m "_׵CSJނˁ Hߥ_O_WlCpZm;3K7Av9bkqKlo,T6G8J$?]zLMp#W-gBL%ɬ؁h /iO` %R*I٫>IxjOFPoLd#' U'?jc>93k0 [E w${T&rC܉r8苯se\Lޣ^Y & W͎U-#~:B~>D yjk9'(tlHƥ 0WXPg \"w>^,?H9TB#+di1N?92 q4{؂eUۭ+ڒc9^! x#.rL p ǢoԒy/ X ]ptGN^MlO;=\yf-h]|CFڛRځ/.γ-o)ƽԣG^wN*a-8])|N%]'ńf͒BZ{9~s˓305Y$Z޿Pr$=DNh97pED"[LA-W5T?Q<@ty g0B:cֲ RUvX&K(o$K+|!H׿P&ȑ(|~׋.)EaI2+H~w'ʥ#Q / /N糛utCUԜ`08npdx %c1fwvyժ!Jo.L x6vO|NX\eGzʦ%{}ʹt$b&YL1⒍+j&DNmjF_VP&ؘ,hmEʼSbg(xP,`,BC?Xr=+̀)J#F&6 Sim׆Zv&li>V :uߩ~Vbg ͩUTO%IY8>^IzLc6 -REȤ;"V}E֭~Hy8Iكן8@wԟkh,҄,8{vld|T2X+6wxƯx .ꎃ+ ؽ)D.f3 u:/KFfg.RQGSbE;E C{t7'aW侕sl&rTs9Ă2- ƨAe.[&'ք$ :*zB-Ϡ؊v Ikh5#uL2%e `6~q^XH{.I ąX?~fݸ.8BE4#"CTUFGUu&53gt8`Um,g~yP3`qoIÕbE^ /;jxtF{U k% ^ Ⱥ9?eMہ -ڣrG @u~f-2[S<׷oA:J UOI~{A"9BfXb?>kj0"^Xb禯,?V]aU& aGX ^ UAأ-Ul,ꩈz3M Md%Xjd߂0PpSc4}Ro5Ѹ^#22%2[7.qE :=4p :Ȓ R[ր ᨄg*&D o}0|AU~yҢ¨n@Z*VU jeie !$XOLF,#ىh>`֩ /h`4vI:~Oj+eƣUi.Wj yFF\!gBTPc{IZI` 4MЭd+ .f\ßW}t `B7|rŖp1uUi7=zwXqd5F4:/!1xmR5_ 4ujKw_[B/ #꾰V_㐃Ẋ/I % z}˔ܿڡfF(#~Bb2םG,Ǒ*@knH+Ov.wYr):7c.DZPkx82`~Ł-C+%$Ih @#.V$Kmu?;{"0g(;t;;tjA =SvՆ"&0*5_ WnjM|w$rkH,=pq^To{B)p95r8NI^v{ \ >rg3> m숻JBfnxT-ƣ1ÕC;#IlDjIB2 QTZs) X7CnLd@e 5tO[1t+a!~GTxLu`щsPL5'@ΜGͺJ~邘",& Ɇ]ŕS9ݦW+vGT}r$~֢?S~?,Wv2ͮ-~@Lʟ8ǝ!=_òLxSuDj6_+gP}STDq65GCrb*`a܍ Q2nN# чK8[E9;KWI]b^i 7qm K؇-AxΠK*kFFվGĎIi#8GSuE -#Q<2mK P"g% Z#q ?fYʟ_:AZd>lojkP/iD",`y]r+MǗ>Z폀 W*9GlbL tIPϲ&*GJVgI ؂.ٙ~W%|!_;E3Q'[ܯ7b>7t'GWK$)NipL3ba3-+>5B~`' jD'^/ 9 6ՅPP}u9>pCGm6ĈDZE:An}x嶣v!x+]oalx\F=s`zQfֿs}Uyo 3LK%.x{5 v"S$Gy@3^Z(&z,o`vOޫṊ ٧9o am,m'AhĬ?ob[1pMhQAOI܀2>\_XA@~ض7OypOh0t꣮CQSPҁ(h4~v"Fwj IBph7 ȉW]g M y2 <΀]Bv&KBe@R:'xR/s]-:`JU 3<.EBLɇۊqB& ͹. d?S9SL1ֹ *E$wXN1T&=k Kت 1fwDliF.8?b*>h7ɥBۘnPZxr{#@_] sca(|yBb|`GZLKXt@hأ4'Ba6 }s%0D%mE\DGsfF6ip^~x0zUB=Rt\7xZ{%O%Ki&f*׀nc~Rhga(E sKln¯tu]؄D(t 9J=!gk'?XNkx_.mΟ0X€3r-em=, "j'~q<~x^gD>RQ6|n k@ʞ0QN< c* )F~(  $^k-P `Ce ZDⓕEDt $-G_~/)-43ow Gnr$P覚kG`~- v6'RUmԕfjko]Nϭ-g,C}yQ}+ZyD8uEPXȮn9DGrc?T?baWg F&n=_1 l:>.U 'VӁlwWin9CE %^lRzPNo<ǎuQ'ӥdg*-G< H8%f(œU cE!G43oZhP RЦL*e_PR ej%78uNpUz,8?;><1Ϸ;K_)x=i*Q~l ?jOs%,+rAw&ϡ^;:u#e"(Հ:{kL/-eGb[̩?68Ux-Szc0T3oĔިvWF iJU7}`Go5mo0I+?#*M5W=7v|h=R|~۟;tlb A~?gs9>)ar ͎׎ə/6djlWd\%/::țDҔON ]hiլ`'-u"OU*>! B(cϖm[)Ԏ9y3 3:] vHy`aú0;E&y+~+-_ψK'?ϓgQwVMLoMPV 8݄Zٹ:LB7_!B69PQs`ªO71fP(Wq^fTQsv}➥m? Ll{;Frlj,$TQNi0f!3~Խ]&k^D": 2D%"fN,wG,/oP>лJ=t1,}OE*1z}K1Ys0c4p< ?%op\!ZdW;$'|J^ %%tfޏ$x>^U'ƥ09^K>"qKE-sbo,.@!mHD.嘝a^fZ*=GO{Ǝ3%$QK֡!Mefx# 9|u#_:SU'ste#0=[,Gix!,n?|? X}~}s Oq(N%PsWq\=^ -4Qi+SW?apz5\CCc3kυ?ˈ_qȽQ!h KlY "M`3/.hnAܺ*W>C{t̷}iY@<7JXYf6cmv4mBJăt3RPgb8q?O@ љ51]H]_^X~`ܑ]N{NjbŹ ڞkZp=xO U2o>(U8DBE\/ש\ yDv)CF.yΩ )jح!eGa|偩J[} _,YPם"y~ b-?,v Eոco ^Fu4caƟ1 di4:%՟Θ.cJ6B2\M,_ Ji`%?ەbA[5Y̧,rQ >񱫙@;װHTAtcs]Lb;.P^2scjdtUqj/G{K}tݙe,s"!Cڥ_Rړz68Z]H=4(<^cj7^/_#-ʳz c~[Z^f~CڲwԞ= gT-}چJBTSDp1L~5a">zA]XZtY(=/HhwdkWγR+H*QKJmpVm?z:>%Wuґ7BeP;r#| 4vCo`\<0ԝHBNL$Hu[0*6-mhkI!}wf-YdoTHQoZ *ANc݌b6qAAk4AIXĒ!Jbݞ'j]sЫLʕ0LVm+Y^!+M[LnO`ivXxQcGzk좄#[@pMՏBd]sr[_CnO͠$9,U@g2€یOp~ә4oXd<S؅D5&QRt-L\N(h* mbu *~!ܪ?VLS"瓱j*㕜Y #n' W}#ƨTY[>_J<֗)Ei} iWk_1Oyh=2"3aXIQ! "BWI&gG}7D{P%Bn+J1T$8X  k9: e+uhh_"vhS:F F|9sMY5:)oS7:kCxrۼ=HZK$ aF#[ec2q>]xe{2zy&>#iގ+be֢0.^_"X.]syw,M޽h),CQ;zz8#FBS z>\F7)8",c>yw_s_%~7/BMq-OMl:2 ]m1uƁe-cAUXε?;0ckPS|s5Ѡm^ZW";LZo[ bdIWOdK{et ̦簽m`MG)B?&jqFFQ=Df9ᗷ bV &fN%K3rCXd&QΨ<3iEqfwZm6FC/(f+gߵ~x"gjYH#!~l rL U2 _z8Z.nxڼ5̢oi;Ǝ]ڐm|R80 vsB$#3EIX<mǝ_ {ٿiz]Fʵ4[ 6)>?寧 7{C`yp{؋qE)5p@.!736g.DI;@@Glo8ۃ-mh;k/Qn .o-=W9G+$9i9Á&~Hg0ob&2RY sXm:[/mà:);hsri!8 G{YkZ 3."Kd\Vv( ڱVJrŮoW&r ? LT+u;{%Ta-*y[ЂЭ"n/Ủp(}t~39#7Ʋ/߻J?n|FHm uCfi(81^ y4SV\7B291 Z,9gi<e!}NsH8p4>ShJ}2Bz]6z4^?|筟>K8)ԟUp~}z*a(DƮQZY*mkw恃괬J5p>Z]bES0O0u ݬ@/^#7} Nq* Wh憳Mן%33LIvOet4 D"|*="V&5얃XB6w&,B~2Kv>%f2'.} |AeaWz~Bsi$u[UX ;HΚIm21uH 8;d ]+3`x$4Av3Em=vv3ݜ&L%^F!FvL(b)mbJ=-EP#|,`*,^7XW:Cȷ["Ru#Dq%ȇ@wi/Y)) yit! sىYw"nݘ'U˶\O_GzmRWVw?=_B}x+F^72Cئɔɷ2O'Go0tG]Q0Dhmj=\M;P}BsogrHB̟( 8ibVkDmc a- )wA -Cn'˫|&ky? UG>!K#J*ǀwK4;i''R@XJW7Oc^1h%pͣ\YJSWi t(\̥uϺ`^7@gk!\BBo][P4yP[z 1&z,?JQ(]x0^Y9 [SЄ+CHWw`ղe-wKshtї6 Rc^4?ZȈpy>qaInjBgbA!ۊOfY2Exy0缞vTԚ#0(zix#~vBQuZ㼔?YfCB]-k>Q,ݘmKR*"Z@Om(-:Rثxl!hua9f$'XZsNEJf(ѫa:lWp[- U_} ~`q:P.Ϩ\Rsd{Cm+/ Zt1VNc)0.^ˊtȋ!pct6+iHͳ{`J8:)Z-o{<(Qq<} $!X N\Q^Kֳ#Ry%qnjV#gqϬnH^<ܦ77{!?DlŴ6ԙWr$hIn`m)ƼՌi:URdcst7OPKo)sa=/~Z8{ hݤaIʼnXʊFKHEag?2$v݊=E%8@xaoqg3 |u4z0mZpEO6,-uxQqshM@³I\v4IIߞ uF$,Bgbt$sH&qxnukN¾ܵ5Zq]hP¨[0OxxDӸɎ]FaF'\H]*ApYS @2p.ON3Zٖ λSk׹tQ8J b,39KYy?[szBPh)L%~4'*xbv[ K gq*JG^sG6/D#P%nt&\ AU `k@>3Y=1E¼VΩޟw nuuu%%X(ވF%Rʐ&z>OAm"ȱ,ռI[G*_p cc?^kSTBզf!KqJJiae͎-T~i לd'h(U.MQ}/|ɤ12ti-@| ⵘ "JVzCgŸ?b8V'J9Ia@{(N1 ,x.$)ܹcWT Xu+6>YOn (6I*Je1 ByA,*v pŞUxrn2bRô/ezlK>"7g m,JIs :Irra ]'';])] Zc>*e.vhҽݖE %(5&MLvh޲vsY==3pϑBOefMY$s `,qzH2z qC$D?f ~ۂA-M闘nu=s⫼B2$rxFgwj XY-ч]+ss%8#~y=]mHr*¿tSc3cN.:g )d5$ Mr7@v\'2b+G|#̄K*z&H+ё h8i]JcU{B֌ $AF8iQsK* `,kU}v(RDs~F/&ᛪ ](ݺXe!>~9zZa!U60"oG͛֗bL%6d7*}ݡSJ3hr$u%rtJ%:,oF 2mXU[Оy˷ՂY;3eP2[-lquhO(B%•Жφ^Jj/߉bdIj;g =#_uOA92$vǵ%tyX$|S0Od`yݡ~ 0K2: J¯Z' +0 |w5fBCiOB_;WǤtF?]jNzE<3*ء$DoEuR 7P&0'6=&~ZЉ%O!l<驢qn}1֚ؖС3\STF)H;`cUՎ~ru*(["h*ѫ^h)7 ~b_3:z*1jG0ssqk;0q 1b& =ޫͬ}/rfq&T\/78t9VF@G;WkbKih[$ٕ*!H=.?΢֞j%FP~RO}ݠwQ,|PܹY(A+]P<4 8b,޼E\/b/`HRF u%ޝ{@<=VYFDLVvz@Zd u0ܼhSzf u z\xrp{F^=jb#\A$z%71\g؝ oVW9 ]A^S(!"3ėX/t9@i 3oOk׉WG1X]3{YU4Cϡ2>b~{P, .dO-'V]ߟp\R+"eG5.f0L Sڃ5I#H\7VaAT1+vF0uȜyYcp4Y'2{̯4=eف3ox4slIsK'y>Kd)E<,a&Wd-ղ:3D{@W*G? _ctS:aoޥMm'z48AXMʅ-_M ٙ Zwij)7-S",˕w-lPt)c3r\.zȧ>JC|,,1 F(C[9qf.lxHUjEg](Iw݆+,K@>T|AƅHNO3[r]ߝ~aHӽ`b7݀/ lvGTWւEyC=e\3#|O,s U&7v䩫SՀښX;ʈLbeƫΖ!~ QqGxQ(ޔH^/p?q,`MhEؖAoGz E!2fx і)a*.6!^*vڵ.%A7 'NAy óz^~0: A;Ca5.(^["\#dH.VCL3(qq D6." Ws55.1P ..u%Vs齆) 2]ZvO]O1e:(D)WghcqP)jz]>){G=?CM nIZuݝ߯[cRQ/( wb#iFBLбٻNd;z`VG)\RxG0>+*HOYFprY#AE9PYZ3ގļ`Ԟ(X;J3ogݪ\rGWs-\O>uzC͚\!['vn]#WȠ^`vs&f]OBGSϋ]׷`A20'^R݃/( i 3= H2H" F꥙K%ʧ@եM)Wtpe?w33])`[Dih`rqYo)T'֐H>Ϣ(3Rܷt"J{GE` H2u=»`nEwoH::pΌZs?;h/PܠF]SSJ 粏 jLp}\R#J]U 7!Ԧ!`\D<!k3'#y(uaPJEʶ`!*6cVtّc^;u8K;pj;;nz^n~lGtR' &{w>KQc)琙cjφui0S*v[ '`dHr^-$goeIib! &΋Λ#7 I q(b t"v)bl3hP6 j as|7q)la6bQk;;m(FH_yULld; l]F@2ߋ j SRY@Tp&B|;~>Mu6p_ki!* pXdJjGnCY6A9bAeׄla${+34mϞ Q6Ւ5o΅P75g;G8AO+C L?┫pN!fG$j$\=խ80 wڷ;'ՔSv]% bvӚ c{D"YM7ւF@Nmb*"XӠ:Oj Rc;Ik#A,ю-ް_3YXK6 Hqa!I6ͼ߶ T/C##:8GQV5ƒ/~uD+s%8ɮp6Ky0CI7O+gOuiMCKjHRѫ򧯦}F*KpL lO jZArTgoCC^a#T$(c4}!$Kn!c?;蠺 Llb;m9*QXVNdIa 4a:go$:>NPАϕ"z\$Rjm["L=J^#&nsJ:|#CE8Q=|}b(nDI`?XUo.JSTBL gRiuDc FG1x\ˑ"xwL\r}N^ЂPTBJc=%֬*o>Y2rU\^Hlnʆ'½ӂ2ptă&Ԃػ0.-vk@KHk4ϴu!'Xc<kԖH3TED0LOFएm9s +(8zUEҗ:To ,=yʏW"i|t_MCbF #tqnBZ=%I1r+ γX2l8G`vDއ|l?)A趌xG3o9hΉnމb{o&.G L3Yό]L)ϸ{#ZňEh !oW.sWKeThk>Ns!8'˥b=ߑ ;Nv޿'fC!4l0Ϳ 3wXcA:)23(f@. >F} g,L(/\qvjK)^OmI\8WcKmg9Rۉ/;FVz6Skp?H;NR˚QiF{Ýy 07E*Q 2֥|KavCEXq:)fڹ`O cqS7.eq/T?bEzlj<]omPG&= i˥ǣ[6ȿ7*:&Ry#O8sr=S%݄Z5 N* ꜙE>JD C||ލ 6uO舨= ]Ng@e8\}f?Y#!B #f9.)Yf< % :z/.(XcQop\-8lsyKdߐ6/-cֈӑfJȭJ&2EUvHkm@ͥy>' 4GCj{A] N)WQ)CqRø{8|3< ^1 'E**ZdE#đҟ ɶ`bKKQ"_4m,?- JfNe{/ UV[ D`3]1-E=@TXfSNwZ[bYNn.[&<+J^A&)s+D>bHM!_t:Cء7gr#c2,iaV_-c /%rDA RFÖ>Cjmǟ]N{hJ@.s0{S{#ix^,Qs(T1G/W4{΅Qu5 J8P_)>kKǙEAZ% qABMv 8;L=gO`[jҙn7n(x QZ J_ڻWa`%AaᑦXe#W׋.g?Dn֓iF}5W+{(ɥx>aHgc!6E @싔#S@u:uv<+BtT{tbucn@H@W<XGQa:eHAmu˯H j=;o#oo^|MFnX > 6C!՜`)_;M$h}nşfk%ʀws2Kh5F*yGOyN^W]_E_ w@C,Ɖ1!'찕PAʍ^HTMsYXqLamh[gg)aZ}CvGw g\!tF1dj-^ ?hYWgds^()R]SlO=ݎ c X]1Oeު4N1&ރ#i;H.ԅ4nWq+# N0Eָh/YƎ#PEY!6mj R[Z,3OoeJP l0/'Nݝ!48Σz9Cj=,<.AWI9nޡcD0&A tzpzmDf7"!:V \n6J6W2l0@H()\,yds1(t81l<"YY*lv<i5ԬN&mf?v;JE+s9{]hYzQ#8N>H?eh{s6B96$-_L}4lvl0%U3S1O}_TKh]ǜ?F䑴7յDL`b  a!yCM/7.+ʵHⳎM"Վ8rJ>5vA!Qmj?-V쨕wU1P(JpL:U( O_]#Eq<ͅ=9ʍZg7yJn <|f #D=Y(QCȳfV.[xZuΩa\}W 'T1fI ")dXqzr'C#nM~}ߎ#8SaN,t+}m777fƔBƅYB}C |O~{LAj0۹Pӟic *h곮m߬e26#e%Ne")"#FU7-\rҎ?PMY<_ѽ=Ĉ@kH o=9nyǹ@xUFWx+`a?<6 Uq,8\ii4۞U#8}%|G52G=`hM%qQ 6DQP1t+ptKx{K/7<=O\3xZ'D~X@iT ppe{!O"qA7:>.c9тߺ]CXlD`ߐJ*HNfej?sE lD k~.}I6x|D1uR6^x|ʵV?kJlΩQ=)ݩi#wŎX/l-GVGR$h!G-geaKA&LP9R9a唅cMY73mq?p}?xQ"MHJ1Y,-6OxJ:g.l)8Cyɸ-E0CD_!gsk.oTt \+L!_eވ2|=@f7~y-D`3|/ffM'r]:a V ]2jnCT.}:.PG&2^W?BўJrdD`B-r#Wm(ld`<cY6mAd]6K?BR.D9/;b^?6Vr *As_ݱhCwp?D> qH 'iԸI+PX!vi*)l2@CȠSi Gg*g٦ՈĊ VGIGeݛVez6԰PET 5DF"/*zU&jZv,W򚮅I5t7[ݩlDݩ/lTaL3 EqEotFn lz% -rhjΨFPk1BzSoٷBDa9YB0,k?&KU{C:(KHG{b,D{2#?=Jg%psmsm4|n]:FQUm!?m/pKCBη* Ʒ|_@B1KOJVǣcZ_Ds^n{ɴ-E+2qݽ|p/9tq{z;>I%54mL&c*)o -Y^C{A3zۍk=0Yo)&O] !/9'| ,⛵p #|JRCx3媷f0W&s%O{V=n-sNzU@/*Y/D-Q{F\;Tbȯ85Jfvݛ6܅Nudt"RLXdfO{i.Ʈ:{MS/v3* id8倜'mrAME]=K97h2CE,Dp8=]7em\ ~~:C+@HG "8BSIF4 /bp)pO+7T~&W] OLՌܒu&7h9G;D"oY*/ _w *nCG۸Q{?Dē8^K4}4u^Uܦ4"r%Gxf{ڣ2wz'&95!LU֌jH|H̽`w/D:ӓ ~ =U+aoIT&n~rUY#@@F_T4EIdLIN#\_eΐFcn;s;&kNl-}xMD!D;vVE5&H3.Drp2hɲ֘z]9o|_LE})c 0{ܥ9hn*6y+)#~ ]y[7Zrn(DZm+M# USlQtԲ8֎pjhÉ;}R0Ü4'X' F'.1x\P#F)|K/CvsKG̥Aa'9\zWQ7T̘'S-^Xg>RUoo,x"Ŗ3Pf&.(/i 5kثB5i3*; iNmH$833 \̩DB(#ꀤ@iy9kQqSC;:vL[h`>'F4%Z$COM_T)yyC1BƧգ0 g+IwRCezŚڊ~6TNsni$RKjRZeLqWALLJn^Q *\ՎPY#į7B`WHTt`!F䨐J/v2MVHwEM>5[!09в{3h_r2^ʫx/0԰&w6]G/䐑p!Ũ<*9Rvx^$nw;Ǎz01Q7*dku!u.'rQBg]U<'r۔\Po?KKsZTk9W6"*KRW)UUo> Ggriӕ1Ic;U:M[.\m c M*лl y_w1q CVQr?RƁt=1Õ!Pn AGv{̓:gtcIZ#ۦdrզIրuù_2~pI 9^[flKC9J*j-u$},FAٚ)BCyي;,.!)e"ك]%nf'/!T?e4|WKFǝ usj[ j0`țXO+_CˮT&Wӂb9 *%(MIh@o$J}Zr [vPκUٟyg+MStuap]R#NsQdA-ۮS(%3L?p-h/\{ET;,7 p2.S3D\bH҇δ: }t1|{[Y<@\~"ׂ G~RPltӶL ߰y4#8Zz@҆^C4- (4Hм-"L?sx.,wg|! >0`eh!X䚵`Kl2Sjol]_WFs)DSԌIMVSC!\bb\od-p;6ᷚŮFZtG_ \$A2,c3E\oYl8FũF E\H*+7EUQ,J|  ՀLQfl3^cA$+`\/f厄ZBDd3DA 9e6;"dyO h'd^3a})Q nz TL ^Y TܸW%f=׈oPXB1m^']wKJ03pYdώģ)OFN6FoGiPSC6:.0Ҝ7/e {4[ 75f3̵H4H+IPuZ;a [ sFNkT\Icƥ_]N@G;iCWjݵȌD\Y,QTCZPlmi,* 4n?ۚ ħgV#ǽ:ilФ@@3 5w·'M4fޑFE5D'|܏kr$c?~˦b碟nIn6}.Sɥ&;N?ijh 6l8WrsaoAFHR||5!F{4K4tS˺DgP8h3NM9__s93 ϼ?3P^g0|"?>؎d>=P&JK,|## -ÍʿV{ 0>QUOC._vv1}f֦]VWND( p>yK*fpxD ңEzo0уFH#0 27 vNQhTґ} @ N8&3TaIݎZn$) |ql X9eKjf|J D-bwXZֹk/2e7Q=ߵdv,3j-f3ʟ jC>`({6)pIlpyA``Z=qS:)>a=ȫ_aVu*$K}F bjrwlْҠpK-%~LK l7̽hCk$Vщ92r`Wp)r N]&H=Ԍ̙D&qZ:t1Z֋͖jQ]_w]_1_d_N]Af+h6ùy7?\ 77Met] H+}ޔñ%ٟzKmgO/x:5aZ3,ퟢak/7mA;]̧[*.e1[6xc#";{mP3d% F纗QA#3ao)5xHw7Zy9O@6]\dgໝgveZ1öU/}⫭~ }`;omuS[7v da%Hpv=Zp+xt>֘o_/LЩx?M x.΃8"6.'UlBMx h;sw(s9!1 }R֚dn+ L<lNbBE VL?^LԻA4f { R85Zz<)UvfHe5^,-"97 c1.Srwz\+EAl2b K1CGy +93: nTH; K;VeHCv٩w4pw݅ki=ҽl$4_݅&,ۏ5obRE "!wCxWRh zh \c8)KZ QlB|;%UJB>Pt@;VO=5+߇onC%y3 թ*Mk FxV!u;Ra\QBaȻURٕQo6S2ZL 3#Gێz(L m;3EBv_!ʕTƧ2oY;t\VH ;"yQ&q̭s,}G4*r%L)2Cv@^ʘDxaS3!;vG"M>tŰ.P:52(-sTW cc:~lly*YcDe&g6 .i`jxe+e=vo:C9[d}ޛzzx7N?%wFsmGsNύJZ*APܓ3'tHcݨ{ڤN{sD8Š.Zatb /^//<~w~;?K0~gW5 4Ba?Y-9/iEǬ6:eC^gR2Qjbs]UѰ+ X3Ҥ(cà1Il(U˓I|"yάx}/!u([zi: *>5ş-mJz? s:A\OZ_wE4.͛6֒OziZ2,-=qbtXj!k\閜S'D.^õP}`h-QM'Unv2Ig;Ts^ך& |ZsDmLO52|F!Mb+2bdj1%^^!oy'_]9*yYDr{]ώk`W=.A ? ŰWmE<*|^' v]z*1`Sv8,JtJb 6kMapݦP5"Dݤ'> ,=H}1h0dM)XSbh{X, " +!xQW s n:y.*0'6pU9٫|t{9)b { aS.8F6?w I-oqPPDR_H*cfdR)3^֞V:Pt݋ qt`rlCy~pK1$#^ }8G/3^~2J[hMsVkTY'>e!2vF)" U spl44ڟ sjܪKJU/S$ u`\^2Q õ]Ory t;f|iw2^8wVشiC;!owލ$ ^ ұr '2YH[0ECd{j>$ 䑊/^@o8^cDi`g#F2Cb\JP"&xO~$n .gÌYMI !}6jӶ+mO88a_K~l5{b#M> *~qBYi`x ;;a_? ~ЫkrRmjOP~dHUQ.}''d =DZBૺ",렷s$#Ex0#EE~R@tў4X"N<4ua>s0Iʘ)pv ~ 0[Fp܇»Nk p*aOK/q3}.i7yq*.ˈق_$j uwaXHxsx}t&JQ $2x 7.87 yc/rWG)l{''.{V{Xr.UoqX,=2) 'aAkfe~j2_xp !YAS~UUfq-8D$;}%ֿE@zG]\Li,)0_|o?n|G %6aC5 DN/&l9%NY^, c )0%>vM٠pwBRE{PS}ekJgM;YʐXd #ox+_mR0DˀPNU>Zm뛨4ZodtO+1A{g0`pӓ/%?"C&݊p QnE˰* ,p:6Q*Z5QKW߻|n0d&?iyT |5 C*Tu٤*,?˒ki*TYNsgG5P%V8݉[n/n[ U0q#1"X@Id.eRvG >MuQw_]_JB8%cJO?v9D)$6"ɥ,c'ny}9Sn)IGGH&]|kؼ "7 l u/i_GlV!O T;\K%Al A  %^/1vPG~۳#]B.UҽX^ 1fa)(@׶fTiX fVH0Uyqح`ɷ ݁5,|x+q|b3)N e\TABX\ёsB&!Ho|Xs.6vQ3 wLh骴'yzZnK;:ONQ$Y TozSY惊'1I %כz7 Jd^0ܫ}n!WhZ2=մ_ NC%C _c>6+q>u\XTa/?/zQp#_>l X=#! %S*zĕ8 %pVٲt7L䀎n;4+Nix9,L^R=h[)dZ(48A\O7G?\PЦx嚵]cj-y VDZR#/٧TFFGsMOraIƋIRzk|_x[mU͌$@}NY{lSTscYS Uc4oL|[1LXS'$;@c{NIc)m7ʜ%ΉE{ߛ׭ϼ/Йw 3ņ[̤]fW:,Rfgzbi`aӀy/ 6^\"D^eįeM\Dw"Q@9NezF-β }P߱M'!HnWe 62~Vc=Fu{?GƟ*he1Sۼnw܀ )0VBQ5Pvq ۍQ𙟬朚iNm-5 N;&?"7i㶈F,e^5m5d,t/&F;ө4Su1eI>QE#vBl'uPQ.P#µ%)99sWPy^#C#&!eY4Q:,Bv'@Zo2TuJql`Bo1 _<_'W2+E4{)ך\3Dјgj -aApi#L72~1ԀCn \؄Mw34uIA4e19&-(a5"p}?<~^15JBeh f GvI 7L# Y bW4^k)ˉ^TFcN@Keh1Q3Pbj [1Oŏ.oG(֣wU M&9*{;jU<·tq42bgohw_Rk8f&K^%$iF@SiĎԭ+m+yt.}.[ J>tǁng\82= la wFTsB%%p&,&'Q\/#$``ݒ§<65+B&aC㴥 : 7c_@#pKu/[*yP[,K o@j$R,?`ިd@s0ӓeHbn ڻ7hŵEe٭Hʂi:Lz/DIgc Rma"X!DJɺ96`@]*e-dQiɪfN'?7\,5_RéS'6;+YرG&K }2 H܊f0sTj7A ,Qa6&'n3HH3ukt`>l+[ ! u gPG52=u] 8"Yz< | GdZgrR}ԀMxc+x}_Ru7#Dh)VqʝUC6&V1e)5NO0йe_DIh-cE3w3W͇X V7Qc8%;Q`2B30IV?9|"@yB| _! 5&Q]K1AAq)Uy%^/Ihvb$|eE]= xL j@i^  ug碽9fFLrz#B-pʞ_(ݩgFJnX=]uJ7E: _dBdn܄Hg_fS9Xa M`E9;n?NM4kNA1@=YǻA9[g@ >#*@ v[oh2}H[tv[OZØ$E$tCZZCldNc(RI_ʾȘSCBk*8 r# " %_вK??U]r#/[6b 6JB$넇PIw&.4ۏ@b$|w/a7󟒛bekҀ?GDЍÃXʋk0FERQ{jV]n xM +Pa:YP`!/DԒ]&0sH;4\Bp1mE`#諝c,0s+j~Sy[^MŸ࿯_׫7b"ڹ`}*)Se߂2Fpo%ރxካQg9=-*2OJhs<f,M%6ܴaaP dT]ҠJJ]F}gFlȢbNh\^an fc 3{a%Y r2IE:mG4_/f]ؐY ˈp2j~N&սsVs+mh3# ӖfCh2mjSCy̝X>koiV܉r ͍f.961V"ꐙNW5$$  #,cd=h[FNՂXƽNb~Jm{U٧aCe#+[7hC6KЍݬX3@BЌd -+с3ݻFkuS"dA[n]0^vLФ%}b`_FLyL S;iݺ?.Ve؝Rz'sDo)~]AE۾|oߐp:,S[&.Kd2賜%4.{(瑲.T2L?5<ȰC[>Z&1]H:I0ߚM:aJq3Ĺ`EpMO؏CZe&x=6>6O1O; OW':)}Xr5-Z=Ŧy(#f)S#sGl! hBEFnsit70zڡG;~J†n\1*z?9&='G&-uwZN7hI>%D T,$Ւ&{ro"`ܓZn ޭ*cw;>]l&7@ؚ9 Ж;t"v61w԰ GD;M9CUtNZ=F;xFDrd@AM9zrh%zI8iSY0.!!a^#b^>/[]RHw#cjw&Mb<mE˞9DygP X|\n=F}k{à)FFuQbgu۽;t4֞׼t:V:s51N*T}(&@?vM~*-$ ʝW|t!!?9%4髐X٠+VH ^Fȷ;!*ppB)c+)y 5yḷ4a\W֑ h_AuD 0Hwjd8$]֤Тa\.J k *ͷ&i"Tx Ļ&jZG+֑G咷:([.| 'K&ν*d DIu7:\̟FHA 9` 4Bu~VsAin=Zh߰*=APt"Pݥn| εƺ~)%~$ʓ)\&, ܋YGh4:o8$J.$(^U[\5;M9 e:Ț~Rh VnHśsS@M;h?~$T?TOÉ %X!*Z}}ce#-U4qUM3wi& (J&*~@^Œc{<o< nkT>NAH[:NZ1ͭ[<\I58% d^L!>yߍN𜒅 kݿ!uD wyC U:,D}Mh~?!_7lZ@|X{STE%yy?!L40t/%CO&`8Qfj2B-!wdI5Mf0X!'q;vmE}h |CxA.2HB3wӘ`LN+i<輥 XJErP>;PaTeô@ ]Koѧt o%^MZGtgOV8.F6"ԉ>sH=1M?-" $qY.$XrԈi3"U@up2~"rZ@?~'hWv.>ץҼP(xNh} YIؾQVyr`k‡+ ."|zyil6hmDn?jI3ͨDWwx!!]t1KlX"kS`gfVjM2>6VCޒ D^|}QؙS!dl~ 4m!(53-ހAzu ?5nG bΟD `0pBk zgu5qZrڞJ;D ~K(HvӖSo+P 4&#'LT<7&7Qme(ǔX`@yBTѳ<7wbԄѴ\Mg^= )媞O8it=}^ }/?g }K"a0H%:%e.] K;9\H eq4o#|>G}"WnQFjOjA~nhǑFdܝI*o˷ٕػ`K7KryQΰoĄ*9z5 \o1ns0rpР 'MN < ]F1?f\U\ງ#kDF^P6 w0k%&Wg:lֱ[BvĞjC4O%웆9~ptwȑ՗aelS[jLhfyj-sb 5:)0HscG;4XN#԰Q1q ,*z:dO<`h& kϺU;Y N]UCywz03& wᯈ%j:ްٵ `[x8X-L1qzbcs7nR紲wHx}_ѡz%x2Q49~U6pON0(-ןG#ADfp^Vg"u6$W=> dc26Kll~7a T-Rq`ӹ 1itxoaG׳X#ٖ׳^9'^vrBEo$-bJ3`r1WyIP{4*'û䓖AE(qDz ̓ɲ˞L7h)cY'L1t:GEq9 ;DZ<~\g׆w$vF OC{MIrvsɯߡ? HY#lֺTf0$ n F,vk`l=gpWW"ND߿10ިL$qƑ:hH p+ìj֔t3XFGW^i:w0l$c=s^p6Se^ͦfl$⒮Hӗgyp,:~eiFYP#Bk@x@N륱>D9+9_n: $u}yЇy3c42>9sa{bQ(?|zT ^ VJ{5td9J!oVJ˖aOw/HP f98sOm|Sޝޖ|^J! rl0벱yFgCɢ=UzMy{R,Z+C)uw߾VnzE|ֹ/ehlQ73"opbcqbhKф/ew%r_gMϮ`|a5W; zىj~bn*8j[RdBvAtm tZ:AnRg gnCpA GPO<;~lGkȩؘsPe@Noq7">3o,`w1i GK#CY9t- >* ?C7ӌTNm͑Oma \ɐZ;cO7 5B>H_zo龉)_fw_N/nnffu .Ml b i<v^߷luŚʺiP%<$( +7;(-xy_4Zɷ>8.Nc'S@{$ q Th"'kϿ囎6ˋWoN%?x&V6򼙨K:Δ;EOO lC"khҶIt&0̺QycRgWZ8J~0P3G0Kc6OehsϏJ_9ޗhn$33ҿWZ\'?UZ>5/1,dO(tBUAY3!ǜd`BAjZ7TR!k60XO$Mi t'"\@m ݘwx|A8^kDk:Bl L jJ)в' sT7!^"*2W_Ry:ZuUе0 LUjuN]~B*Jh޿юnmkcZ>7Œ ꧑ؘ!)"ֱOoM, *En󯄃y/3w:>zrrdvƣkT?/d)ɸ|c;Y`Iƶ"B-:㲐5BwUFfӇZ1Q@:n>yD FWpr:>C_%[,D3|[R߳4?SMޑ7E O9D%"O NlL%=M1UALPKφy\;LQH+uJ.v рQWu}}Zʛ8-;}OYL# G[ Kۺ `>w u³dR%v7NQWk y4K/)qlZusgv!B F w (t`qo@b;[ d .*E2j/sdJѾlt+JoqD5J G'zP~^]Bh)34Mp_4Ad7 DZҼ^-TY—hQM DR(ݝ%㲣A؃JL$9ɆrM܇%\!,)czi,A{N mcWn:9,]]U :|b^@Jj^δnq!18xLK9 qs㮀 ~1sBf}u ͣ a%H!ZMՆH JL u5|h@PpiL:PP},,puJ[  ŧEٽF(QKJ'󅼇Gݦ5B@x-kW}E%;2W r 8˩Lpd-:$hRaO䄕#)gP^&S?]r<5lo}+?@'8 x*o9K[XLM" a{H:0ښޒ `9.IMIJXIf HYEܽr!!{ir5zO:roALgK%Jqq~4)ⷵ (\dx+ (h~ !=u{:*MD%s[MV̲Gw jID4XVZ^tsQX˨B;/ԔTy{թئ59ž{؝2H{ !e1Y^GC7uKIcmmq).82lRC5ƴ u"7(nS֨:+ gT;o }"$H%<\e S0bO)HB9Ai) C"B:B?yXlt5VV4I sΖ{Fzgc;]ޘ*fuل̱z Ya<7ƙ:`=1 "֨ $RüT[Y: YZ