samba-dsdb-modules-4.15.8+git.500.d5910280cc7-150300.3.37.1 >  A bup9|\@x;y;om;hln&3YYig -t)knJGc=698ÑY]=+6Gi|3[7uYv~k;+g rC7JÕ\h ?GdAI-5;ۈ-bW,E*pfD̦~.vzX-O< 1UeY^F^t,N]0RaqפgTtT0s)ug9e28c86dba0a863e58f0bbf9ae143e598aa964fb30e4a3ca9530ce67f4d96b9d22c463322d0ec56dfd2f593014595aca7841f208bup9|cg pZRңi:`&s}\P4`NÍ17vOH~SO\?ݏ:MgFӌ#-8Vx&]lUov+2)B݄氷s3>Qx)i&Qd$GYy*u>mՕ ,=sA/I "QlKZJrTo8.XKcUk'DAdNr$,bڔ~Z$A_>_jԮ&rZSy=*|\2>pAk?kd0 > P ;RX`-|- - 0- - Q- -4--0-uu)Nu()8*9-:>>:@:F:*G:@-H:-I;-X;Y;\<4-]<-^?b?c@hd@e@f@l@uA-vA-w[h-x\-y\zkXkhklkrkCsamba-dsdb-modules4.15.8+git.500.d5910280cc7150300.3.37.1Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.brtibs-arm-42ePSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxaarch64rm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigp Hp Hbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrbrb4558ad26b624727360c2043e09218e428a035d01f9df0670530c79861421626bb74633cb8d1204574b52d24e98a938700b70d9693f8f635205f629991b0b787bec90b506f36055b67ad762ca426733f19b8722f83909ef492a0c095af2f381a1d97b3f7922993cd00b2c7e2caae41671da074c744b3e4e4ea7289384628523d7040af403d4a254fa2039c3b1de5925a846c68bea5d77daca36ac3c333aa032fb7244758b833fb85ba9c046f70c54bd791069154aaa233400a46a264a536540fb1aba4cd318470f2f74b3712ccce2753985d9f7c0d9ff8e65d176fde1061dad9b9f5085aec6fb0f19e92fc51dcae1746c24e874e0193de9299f0226973eb6b1b5e8c3ff0fa06fb0e56e585b6e2a622cac5c600d8e7fdcc5aca556bd0fed642f1a33c30d4637a22a41762a93714d1817db1989eb8c5d202e61c770088dcac8cb26130ccb889a6158699b3116985511b6547670655f05186e43dd413c757d90e068e91f2d99f8a2148e17d93f9dee8bdfeded2a672001aa4cbb00f327366920756fcfc8c2093cbf8a8ebbdc4b09a9fc4f6262565bc9e80eb5d444bc7fbb852173914593b7d19c940ea045e6c0a82b2133d9561519534d62ae7215f2d5bda66db5225bc82aab01f233da39bc6f966aa34d50979f3d2d88f10fe136082930934f07aee4b4822be0bbb39cc48cb65448d93267fee92efc2686ef2e879f19dfb8b39ff5a0224e59ddf913cec3d662680231da702a1a4ec05aaf6c99df8cbf68d7ff6453fec2ff2a7d53b3e947ca1210c1aeb543680e524e868b8d420281f06b280363b5da60d391812da3da269d577d770edbe3ff097fa8a92cd1d1370c9b556f133dd452d097cfacc86ec78097e5d0132cd153faa2d574dcb235b6c7e41f8390e2bb4739e3351525cc00cfad01a9d5fa3178d51e07dfee6e6ca77e2f0aebec79880ee5940b49bd22cadf32bbd368b09fb86c2c07af5b8d5582cf40f0aeb5c7f77e68198ed9a5400e04b381ef0e2034425359948aa386abcac9174d69e2db30442bf7fa3021d18c81b9e9641b4b3a77b9a580d3a7c0596d99005ef067d4050dd377de93862e995c327652fa711f67f8709e0b7340509acac3381b69c7b37c3a658276934db6888ffa3dcb601596612abd2c95a769eaa3181452214736cef3232e023a1516b37e4d194d02823671078cb53096771ebdcbe047f5c193fc12e2f87327dfd7215e5786096bcf15d2c924ef7457d957d90ec52d6a65e089696efd97b92b335317d9387b919d149435ad2983237f2b6f4981121c7445fb23eebdd43dfe61a72789a2fe057b83ac8d7addaa2fca004c3ef5c84ae53397a31b7293632d9bb08305751a5db74b5a68f5a3530cc8568d01a572780643af1c5163de3d0e7dce132ac7dd0f874241152538018a446697b4779368ceba87fe7a8bd0572be4a9f550ced155a5d09433886fadaa92470a1e73187f0f6a99d5be803ee8bccae735eda243cfcee5f6b56d715947e537c93ca4d4193d5eee69ee5fa0e492911e546721c97cb35ad83fdff627acfd9b54b7ade42ab7bdd26d0edfbdea18903a462d460c8be7fdf4fe28de9b137a08a90f2439dc4e57b0892d04c2a5c32dddb85d44f664bdf1a1c81caadc5b1d232ffddf45f169fc04c72e92f1c6d664eb39087c4c6e471a89c56a5ff2dc32a5472c7aa578614a72c28501865735d49fad9a6800a8d391441a591a837f05cc0777f24c2ec1eda09079d4c90035eb4ebf7581f9c6a98da27c626a130dc9d1193e6abbeee337687baa65034a6a4c4b81cdb907228e6964f19bbc973afffcc50fe9a23d1bffa2620344fa45bb13ff26f45a4ac031550a253371b023c806bc5a850a30a6240ac9dc36b707794989acd467ab69376734ef62f50d97b11a603af19d9f5948ae35b21076604ea575aab5907843da83b1b4c7edd55b05e57ae1547dd448f5ef1367b8e20cdb802a2ca2b8750d147880da3ee38d50a34bdcd0e14c2227ed8c7127f80c9178fad110bcf0da24db6327502a2522b91724139rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.8+git.500.d5910280cc7-150300.3.37.1.src.rpmsamba-dsdb-modulessamba-dsdb-modules(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb.so.2(LDB_2.4.4)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_AARCH64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.33.0.4-14.6.0-14.0-15.2-14.15.8+git.500.d5910280cc74.14.3b@b@ba@banopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigibs-arm-4 1658745460  !"#$%&'()*+,-4.15.8+git.500.d5910280cc7-150300.3.37.14.15.8+git.500.d5910280cc7-150300.3.37.1acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:25011/SUSE_SLE-15-SP3_Update/46ed53e08c5a8ae9c26d6056ce02cb4c-samba.SUSE_SLE-15-SP3_Updatecpioxz5aarch64-suse-linux  !"#$%&'()*+,ELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6c6e32c60c500948b4bd521785052decba2acd50, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cd6cc9b2b6c56eb557d5843d32f1a94bbcdf5823, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a5ba17a99735fe59ea7051ae389b6e1ab6eb43c1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c99fe7622b32c3560115e42635f15fa07b1d0e8f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7ce535f93b23e9ac7f9067eb51ef138082a0aa20, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8efc5e1ad3efa4571d259e96520fbafdbd2d616a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=62687e62667341c128dc98ee8cbb3df73c6f3db9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=317af2c31064ad0bc5a88a080d119b214f2614a9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ea81e2d2f5e939b011cfc854c355cf9200c7278c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=25b2e77aec0b09c1c2fbbbc69211ad18ed4160a8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c30c8fac93494543ef049e17c94e46d1a7b78f22, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b0c5ba00bff553282cac26d3356c08768adc79b2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=365d3b1ad5746b1d055e6fa92b5882b2b10b638a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d2895c6c0eb4bdcb92ac443d816633a4afe69743, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ab32a6da0393f77352f305182359e5cd22f7bb68, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=79c0295bbfe5e294d3554dbdd14485485dc5a8a0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1da1c5bfeeb5e39e5c91f417a39e0774d227e9c2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e6497627e4709d75e1346d639e2fccced0d72375, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=99c20544f9515cf0767d437cc83250c9fa319827, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=31b4ad40aec03f18da0d45b9d5ea993ce1793a9f, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=526f7797107e1830288d46deae8bfe85bd7f82f1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9ad86d0a985a4b1a8e1c7944936b3129b72177cb, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2921e868b024fd4d28aaa715879c4ec1ff72eeca, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=48df3c04d267535244ec6a3adf94ae8a5780d4f9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a2492a63c0c175ff68f15070c4714d8a89fce2df, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=99c0dfac9e096957615d459c7fc740f4c56b24a3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3ded16109ac1c8a5769c7cb2eb1cadef9e1a0738, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=407b56c31f328c86f698d85504b8e9955761b648, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b351f65be418c661a56db003ca831bb64beeff38, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7766442b17ad7a4760eba129e9858178d8cac480, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=09eb2684bafe164d316a5c9515c658252a3fd000, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5b208dfe9120cb584686a51db3e69caaea9d395b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=20e742660b587f86c43cebfb0e8c3f6c122aa0a1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=798b937bddb730a3c77c005459db58e729d7fd58, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7c805b7dc2a5e9939eac23e7953b6604c7eed9b7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a833cfa74e5a395efb6cddfb8b0c08026dd2c7f9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fca0cb2225d3680e62938df88b993525b30c4f5c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=399e44c3a928bf885f580f119b75e5c818361c13, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=10ac42ac1af7141d59611a75c04acf0f94e4d3dc, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b7c982459a4d006fbd3d435c25382e19eb3c12d9, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=41c78d69a4dc85deeb9cd63c65ca691cd6ab9420, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2f867df2daa12ad092a76dabeef35c12fe209268, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4c2a7e3f350b04cccbaffb5cb9305207abe8cbd1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=46ab6ddd466c9767aeb7cc85ec942f61b00e3226, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=87a21d8ed025970d2b85b6044043a2439361103c, stripped9Gev)DOXoz*4[h/<GRev   7 ' . #  R R+RVR\RR R?RdRER^RRR)R/R-RRR[R*RDR]RQRR>RUR(RcR,R RRXR?RERVR\R^R RRdRRRR0R5R6R/R-RRWRDR]R>RUR[RQRcR,R RRdR?RR\R R6R-R/R[R>RcR,R RRRZR\RVRXRERFR RTRRdRRRRR/R-RRYRQR[RDRWRRSRURRcR,R RRfRRRVRRdRhR/R-R RURQReRgRcR,R RRRR?R\RRdR RFRER^RXRR.R4RRQRcR,R RR?RAR\RRdR RER^RRRR5R/R-RRDR]R>R@R[RQRcR,R RRVR?RHRkRRCR RmRTRRdRRRR/R-RRRRBRDRRjRURSR>RQRlRcR,R RRR\R^RRdR R/R-RR]R[RcR,R RRERLRNR RR$RdRR\R/R-RARR[RMRDR@RKRcR,R#R RR^R?RRdRR6R3R/R0R-R RR]R>RcR,R RR\RER?RRdR RR^R6R/R-RDRR[R]R>RcR,R RR\RdR?RRR R^RXR3R/R0R-RR[RWR]R>RcR,R RR\RRZRVRXR RRdRR^RRRR/R-RRYRQR]R[RWRRURRcR,R RRR^RR R/R-RR]R,R RRRR R/R-RR,R RR\RERRR?RRdR R:R2R/R-RR^RRDR]R>R[RQRcR,R RR^RdRRR R/R-R]RQRcR,R RRdR\R^R?RR/R0R-R RR[R]R>RcR,R RRRdRR?R\R/R0R-R RR[R>RcR,R RRERRdRR RRSRcR,R RRRFRERdR/R2R-R RDRcR,R RRfR?RLRVRR RdRiRhR\RRRR;R2R1R9RRUR[ReRQRKRcRgR,R RRoRRRLRXRRRRR RTRR"RVR)RRER+R$RARNR RdR^R/R-R'R&R\RRR@RMRRDRRSR*RURWRR]R[RQR!RnR#R(RRKR%RRcR,R RRR RdR/R-RcRKR,R RRNRVR?RRTRXRAR R^RdR\RRRR2RRURQRcR,R RR\RR?R RdR-R/R[R>RcR,R RR?RZRkRRR\RCRXRmR RRTRdR R^RHRERRVRRRR0R7R/R-RRRBRWRDR[R]RRYRjRURRSR R>RQRlRcR,R RRRbRdRER\R2R-R RXRDRWRaR[RcR,R RR^RdRR RVR-R/RRR]RURcR,R RRdRRR R?R\R9R-R/R1RR[R>RcR,R RRdRR R/R-R1RcR,RKR RRLR"RERVRR?R R RRdR\RRRR^R0R/RRUR[RRRQR!RKRcR,R RRRR^RRTR RdR?R/R-R]R>RSRQRcR,R RRVRfRRR\RR/R9R-R RdRRhR?RR>RUR[ReRQRcRgR,R RR^RRRdR R`RR-R/RR_RR]RcR,R RRdR\RRR R/R-RR[RcR,R RRdRR RR/R-RRcR,R RRRdRR R/R-RRcR,R RRdR?RRR R R^R.RRcR,R RRXR^RR\RdRR R/R-RR]RWR[RcR,R RRdRR R R\RR-R/RPRRR[RORRcR,R RRFRRdR^R/R2R-R R]RDRcR,R RRVRRdR-RJR RIRURcR,R ROzǯ[ `ʘ`utf-80f89ddb23b44274f718827ba77e325e863a9ca12bc4f09ae6a62f8f32b8ebc41?7zXZ !t/u] crv9wNG246_TeUP ( b=!KkԀPo\~[Bv 僛*]e$nJy \I\b实SpLH.AϧP&nF zE\8ĵ c܌3Z?_r֘:g9VQbivt" '͙PԈoOX4P*=,*`RhV|~LU.Bv~rj}Y^-)}%63+.Kvi5 \Eڻivq<!rwH&XkJmhsy] De|fB#f"elq)5A JP;xPEgDM4!q7T, t?͈V#?4g@S;zLL@IcxJSWU(:#h^)?󾂢utSsh0SW#hĘ캏(:;G.N1aq>ct}SMo]!NZ` ؒ-`pMQӫG 'g1>-8O<ܤ3ts, n\bOu$5I&K J•)(y`s( 4 {, ! % ^KUӚ۱[o0'u.R3b7{ȫYC70EؾwsqLf@qq;#Ȼ$l}&SupCVgBl`@%kX7qъ;(HWo:Ǧ++2ܕ8-1Dp2:Lý0sv3앜͢E8C)QkWIgTag\?+nf@q+I ޯ*d%`I-Ckiا~t_a=x4U 8[ 6gu۽Hjiyj;dOkʃnZXD#}k5"3ex8kR&Z0)_ ģw;A锡M;эXÌ"IifS?{U;1,l2O1AUu Af3sc Kr?s [RGn!uf.'>[q49z_UV۽_g_ 0[DP:`ptnG8ߴLjL7l-mtMF0di@C4po+?-^z#b uZqssB'f& }J$+c; ¥Vq8R"])uWJCZ$נ4$@DX46m;f >At1.]\|$8c;M>产Q/"@A3Ʈh@[13'пLz j `X,fMmX^ݛkK##wS?hF;w#) p ( 7C`2hZ9Ix ȸ-P4'q_(jF6խ:I>I \iLKTxfP,x!_qUk+ @lQrNv͏= 3>~FQXđ9HT_{B_ mN|(iQ3IdW1E4,0֓Х9GJ&!# z3wQ-HB:K^PGӔ —-q˕^Kj_BL൛zG>M:ٵJ\S燀#zBUVelfe#OV_NkɆ{&~A" uU"Peey'Wv>{-ҳprZ{gp"G;\^ IA3Ղ3]#-Ѥ⌰2hm5w90 ^Ɵ}2M>fRJit`)sN1S0B,Np>H"|otxSuc1^k`Ea6Z&~bGC`Y^3DJ Ҁ./4jBD=F.sWNviENL8 c;HqVOכ.#`ë6Ac ltA=};̌AKmB9 hʇHwؔn"~׹+ߞOc]v֨Rej ,h%v\(M'&˝)@gE仜 +72NINt' źKG-nǺjYEr+z/;Cp1v >CZu5X :t)AHtc =MC.ΑEOﭖata@pdC|yj̠)|D^f*'U }/* tam.0to%¢o^b”xOϸO3-i/ߐ3'h'\{{S4%$X"q{#-??P.sf v1?tBwGK1$::+Jj`3} m剳| /t(4`VϾdN]Q_cPRC"bjnžSE0ԭC2QɧisVy^IdQIf<bƜ-\bJd]a]Bz/ tVԬc)%SH-O8RA:)G=  wTB e=xLRza5n0 7e䃠{@zޔ*ǜn"6.}1U@8J_ R >Mq5 ݞ¯^̓ry4s ٮS&2y h \-ecs h)bq\Pذ ɵ~d<1cy%ZD(5z'py>y}!\h{xS鹛!_ o:SԍnwYgTz f|BmDCw-Ɍ; vC<&>6xnnZc7Jtʜ_1׌ݵ@EiesaC=-+lGFP~BV[jK{XnVysz;~aVx4lB՚M5; s."'ϻ5;۠r$O!~qGQ?ҀPK0AtR7@S_;c07Jwrk#pɎo*,)U_4xZw\'9:<|Ԣ$ d'Jc_(|#QtZɢRB z<_.[s OTSI(o9_hlQX莿]*9-9hCUj2|R@i?",Ge5/Ѡ C&g7x 玝Hw#]xm~]%0phԄ BrTʘ{mz-L0مsy-_,uj<)ei8BܣK w 0L^NQ"fJ/`K渷XU)p'OjG].(=i2@ZpЍ;FÛwb w:ݳQ~C0n`;uPPtsR9!HF0|( nlܧ#qq3%COKb}t|0 (_zNyJƍBZLP⌨U#1N *ZUB ~v֚uJӂ?P 읢?|OV/~l&: 5^ vZ6$K^{0mN710Ln3ujK,obrV)"FHĈNNc^R ]](9Zd9^qfuF[ 2^MOȣcÆ?;wٿbږ,'. iDeQ]4ζ?Iw915$C5ZȽ7Fxϰ-!ϓ^W'<TPpΙdS O'Tm~뜭KJ>mJPAGy"憮ϖfMbt".E)FBS|g{,Q;[/8Um-B7ejz"Hc~ﱮ Nτ+ ^ .Y yOh 2 _vcCElf_{taɗAaCHOȉ`Jm‰^s+ ,daZ - ~][. Ìɨ;'iDǮ'\͹~<5f}!TN1mP*pMYBP.` N 8ɐy?1<>FJN@oo,l -|%%آlL^+zȖi`MGRi#l O8I}f<'jDlMVvJ61{.Զf3鿺SEd u19Cgj? 8y[1>b*o_14b:μX} sc,L]dZ$Rtg y2vۢ6HKiȚ,U/m)e T{:%]ӁG߰L7,%ެA\?T?`<k~Y'0Ӫyg9AY~UL^?Cފk,Q¼ֲZ[#Q۰3ծL # P3yKUj웜c(s.]##c;dw6>ww@g-pkQN[MgMЇ0v Gf >9= 5iŽ%6]mwxjNt2hЉKѥT(wT"d@yVKAga?Ť5"'|zD'IUc'Ӹ}8) ΧFԁy[f ]'N"{r4qmlv>v'nRFo wU_%L;{zM:Pku*ǎBF_I|= nq7meݷlg4QVN\WԛreFZNCLgyS#e&oG`$Z*3R(CHG;nnr_FAA{_j .)F:ɤ2m ?l 9ԥ1 8\|. 1ձw!qÿVR8EIgvY._ Zr*F[A/F|Ci.r7]Ap>#!Hh 4#p9'X%z["uP1ÆN+ %6(WaIJ-RHdM^ tdzX" .Ew7ƴ#ڢe*:j.>dK/s#joZ.zF &h2;dE|R1StHG̐[T8*@"_UbKrĔ+DkPl/xi ;٘,`pp(4*xM 9{[F=f,FR)ܕR+BɁ;}ge3ၰzQ8]4Z\@~pCiЙ2Á YdD$'H ΔcGZ-+扃Bs|Dc@:Rο<;XƼЕ>@ ym$ٽћQd0]5޵vWҷ͖ǩO)1Lq(( DA+@0`6q] Cj ф9rg-2~++o@HP՘ [ܲ\"̊eZ~*1_ɷJ~Hh@azpu>i|kNot;8Jm|%5B%xe2wpRil$ox[R6`#۹RLQhPo)sD#܆7,3f̑VSI/[ c$:mıMZU8yQ:@rGDY7ݘMu凍^"%JOtS/B9q$~_=ٓPAifB¸U_@z&/# &"?0{IƇ⸜Vj}h.Lh;VӒj8;QnF/PXoԑnj?# 5gH0k ,Xϡl仓SNÝ~qa{B)F7"jh?ԚpNyB+o=%)IXR ;jSPt?ꑤ0 8z6 {Ѩw4g;}IONqx5ab'Lѫyo%G08x6_]\C{si C:m-:ydg? n$ ԝ  7n%7h͙\jey4N٠*_eɜ31UaإT1Y^WpsEռ-I{[Ɛ'\6"r((p6\%y-P:W?ɦQ)#%] &v' Щ hf6\IFͫW_o$(f^^2lUavtލ@1 *iGȴ\)ݍ80$LgBpϦREKU}9# hʾbil Ex*5;$㆝k 'Bbu@1!<%fD}k#QmPn 2'ya.eqm6q*A א m[;S2;O\:ERgVkr7n?ȋRF2 Z*CM E? #BA5:r$6"\!,t~HBS qL+Ӛ'$Bc}rw!6B- JVhJ zXI8#{6!Lg`AdnX6?}Ǹk \^ۃo56D qxwF"QŰ˞ci+Q^ FxY G& &l4dӮ#,!jǮG > tuFM;)'y` zUBlVXo [W/88wL$c9Kٜ;UJrW1V6;_[3u~eyFNqK;$!>m+VeGa!0zO Q)oVQe=aC%"yޖNXL-ZD;+t1ɫY~=vZtX'ҴшS _#v̮k֪+{ѢKo;R 0IX6&JXҁȐw% ܘ)DuBe׃^qU(=gá 7ȝѲݷBl ;Bb"T7^ 2W9èĤS?/#].a Lt7) tj`:A?ڋ@SSc]vϤ><ىl-Acu̳ me詺b|ZlX n:d -wb3mN8GMi22aK-dKuPNZ. 07AG;A<%NB ,@4$-Av#e0J~p.d 5mW۵$$!ٚA5q >/Nx ?^RO @nU[dqQC!>`ߋU{["c^x'rAYKitmOV~'3tlfR^Yw7q뽚SL !}.bAjRso;oׯkנ o |:o}zq{綅> eQ.;]$~)Ա8w"U@%B `ΛW>89VE] Gדe(0*n>suď&@7cӷ]\@Veh gϽ!px1m ~A tE 3%6(TIc,I@nU:}5ƕ6 BeTÜ X/ QRoXq,S>,sZo*Lj?ֻ2!Nw] :(ea^-c^%Kَu',DZV9~TXtdU+(G[z5#ER2p jl[$ZWVF$[Oo}05W'gJY7*FL8ܩ}|y[n=jY P]:RDUoz BJ`}b%5ut+)uIn%}gSLl-==g}>AMNJwľwm/#6 To2Y@ȺY_DȘT6!*ӔkM 滮#c?PtAO'$*`^טsyN{;F V}/w3*nr,'xķX Ƚu"W)nrQ=uה{4ПQ2%Yz:,eQmL7TcGTڄL$o ?〳wOc,^ofZ7_/twYI7 am{BhA>#_ZFI@0 7یV{UVJԎ@ oIR!.D܍ҍϝ.XG/.?II:?k,&^.fkeq}k޻רFAFd7 +rJdE*7n,.j#I^/7W`qy ]1^^rVԡ`t ϰ:i-x^XreoƭLt2uٻԐb^pmM]hn4~?wv(#(y3 !mFr4Dp`(S\`}97B9Yն,{/HPWyBE*0t>ݲȌJF q/~+#'j{|ϰ}{p4ܜ 5tL]`w ,A~"s]J])`uMљʼAy{x3!<dlW=2U-W4oՠ#eQ>b}o- * hUN4?UiKcmݡ䷴'FU=tI5f(Zf|(W<"ĕpҗH1s+egJ䩙'`"ī˙a3QznRgF0fqSriڛXJSTبا*/_es: %wd͆`&\?ZjH(zyݒ2/ji*O;xlNo9CK9Fqi뵬`WXyO20e&?iK]^.)|);QRqiY)ir#фlZT׺qg-Q絞rZF`fZg+lsLđ|jdM1+OHeZ}vz1j#Ky9[Ty˰ot5!(in$dI ^NL++o%[Ӑh+Rľpyx{o-Ģza^:6OPĸ0gv\绰If780Q[{ó߽u@jƩbϨ(fv^ +jRf[yq zfVwIB|͡$:R`bߝ#YA *xQ>˥)-Gڞ'niiL^!~&cꏂHA!Le3*w4ɀ i#j-~ę:1#YY}kmtPQ71nsQ]VCkT!Z0y)8?Q eFd$x` ;"#=|t]쌩~NI,LI^u.u0|9RP#W~<Uy] A12*r+1}p c-r {RyfCɱ%uXAIW-^,ȵB9턁+sLGw\Ƙo8~\so3=P+a]$bj.S#BS@bbk%f Nv4+ٽ7-)I0KNIw| I2 J{{LMLf0>,Eؗ zCd!a3:gQ!uIrT] a9Y2VE0t .>dc t>MY[tCņaҴbu ڙ1A\-oih):@JdrŕY/%3!Ʉ8@}ZR*pKegrckRz ۲sLQj yrG/Yoy ٧{,~.@.*a9Gbҳ([  \O@Q(IYNg[NĘʈvI#4=Vig<@ʞ*.f}fZ^<I"Mbbk q] <(ૉ"kMVHߏ 𕈕(Nc19CaU)ЋW5t40)\xicy'j (_<[G' r ^^.¹#f&w) MH%y(y}\.@C:::b!ҵAݚRԆ, 3Gt+ďE[+ke(3K(-EKU|'r˰&=2.TVːv5 uHӶ?{t'[dUf^uo6.pzLj56IsAϧy<_ܠ9t)_T3=W0+XaDA.DG\8ˮN_aLoo{kS\}+`kRiqjWG[9]tE3,.n_ vtRݿ9K$X$k)KE2m8S?#Uȑ|X2\r!XPp^*wc"YP{+\jtǡӳ׳e- 0}y4O2PyP2%Rg h(5H4Nn59̞P#p6e60O ~9e֬:xل=zy/*2FJ&ɜ*vn!S;CЎ0(HѣSf.n|J,s )~vzu4 %/D5t&'ae@S$riz.[SA3q ^Y[ =)o+tOy:WQMA֬i 6{!-.'Ԅ+Or,PO-OXHh#ᜇ]}iNL}o'Il=/^oI۪{;2oh(v/#Gt N%aKU nJa)J<8J+ڸc>$syZ_9{~x;IKfiQpx܏C;)[ZeMZο8> @Lj28I+`Xa-=lSw)hI"jzk[H%z? F±\71S4-/2SzxYCm]>3A̢drf8fѤmp*(-*)ugov WvH%ToP]jS̏7e*/#pZa ’WJb"l)i |jA^S@*2!gs{v !TxWm|Vo w1*T Mȏ_2rk+i>.x[ NAFڹM =i蒯GqbLFшmJ&R;,ĊH ]R4/Th :^ ɾa6=у4J!!Tf."_nuyuf\ =ο.F-CCK]='@/2W@ۨf xٽxZܢÆ޳,KOnkkb)e졹rhG^r2Z~WOhH#[~+?YxM zkX 4D? t(K:>WgCSv k1QI$gd-oU42JR= mf`'9)D}u߸2QpY h_XVtĉ V nh:=v# AN`.Pl:Av#,)0",)3w5GQ Hjvl@0sCdAl֬Gv(m/Ó{'ʜ̌丙yb,LDûC4Xπhn"+q%bVB?PJAs⥂ +tAThFSA*;+܍M 2_qXڗSEjr ?2&~Fw@R0Čpaȇ `2,33*,geLW Gᓨxy4>m/MEp=gvg*gs,Uw#dm(:W4tyؿi =Xٕ f>Æ\I::4%j"m{Z~ʜ65+]&3ڵ)_ U4N9}\?ʷ33[dj孆~Tڰ(Cv^7!% !4Z #'~ Yc-&5A< 0 g1vg8J*yCz;%CHAbHPSĻ&l(&Tzp:ʏ}Q/HӀ{&@ڶa `6:6lNjr!V@OE*ӣ! zSu6\.yfO"$)ZQWK5+Pt>  UPE |w[I5pA3Ǔ(Ix2ZHC7F/i|`Iw-7[GR). 4ww8j3{T֪P_Hp}؁p>uXPM^`jC73o8i )Kw؅4'JaM8 k ւ ^|fST=?F& 1cћKPjQF&Ǒ!BH6p' aKةwV6UDF)Up>JhԠ<wEOh>;]H3(xQmWe &bS/vm@-,_{ZV11犁`|mJ on_nnaC.Mab[8"晛o;Z>;"Xݶ9ꅢ$GТHYqu| (2B"~p!iWZ(f H)D< \ޒC< stU)*D݃swL{]YH~'~z16!7&o0pvW7EִR3k4?b[q/@ x!fHV}ӷ 8rteeHdҐ\8$E}aA8ŒEXԏFV-%ɫ0%ա(u8Ŗ#|!'7u\ ,3w䧲I=4gU3 )$F\%,45JN]kշxw݃^hi#KPϱMT[FS_+&o,6#K[$/j o RnSژ=P]_O?!v+z@6r 9c•JDbQ-⴬Ȕ^H/S$# ?̮ rVCwacOʇo]+{ hU#Fd1W* T{.Q# ]Bj}^x~ RzY8m ӱ,,R_R$Hf[àn|qU``N CD+k#k8"cpm굧toeW)wh&| Qk(پOV:~Zp H~P%>a`*JpArc_N "(Zb{x"P[Q+Sh9󑉺N]^NSct,=B.Y5>ZTs:o*S_E.FTC5^Q,92s='!#8]3?stiذ(3j:&rfr7v }d| @})aQ厂`HpqSj> Ա fF$=qdLKN&Yф^$OP!_KBҕ"M8e#T7<˹@+ϧxE"Ж;]E.`ih % L3mDG&pE(nLITM?(@;pHMyO5ĺ)-C\2i?GGt)3Ck]ʼnǓKgX)lZhɴңbP)Wb/kW,3l/n`Xk\XfP8qi 6b>eT dHr$[pn) jiS^@@t 9{h:LS5m&YWDΣ0'^g; Yq\ 븳_ktO?[c 8\l\v=EMV}yeW 'Q J6B 6f. ٚ]ͼp}_WR璅8TX/Su `h3FcZe0&\gK>I1/Y^+!dB /^}t퍌aPuv:\k]tr"ŵ1_kꖌRU8dp94OԾfƕJ(LB-+Ff H6Z`7_,9(KLh]3 I+gbjF 2y-u^33Aҭ+\ / >Yޟ ptŌ|a@hær(OP˜yM){(_ nwgٻZPV@b֜` Z)VWǽ[*{4-tix&tiQvjPl9l" #} +^͵]oQ6 2jFl$V@ 2ʵ,UF-Ag,}gzPŧ}M)MdSxMe\ qQaߙUPnS5ZH p6rW~vS-qE6#؂XW !8c-H 6һ]Wd d~;ZM|ݼ  W!(uHh#b;(6.+h)2ci `CUGJ@N\č|(sCyy'R~GZse}b+ѣ<깋yf^)c1ӈ|XP:@埻 c'y {%*lJ̉)u@imciDٽb-5K ۙ49\~Ge{d+{:r~ %O`#,p#g߇@P-a/C.`K9\2?K0l|dž~&5uR.K6^y$}fRb_o4ɻ\% !-۠z$G<#hrBO7Ujd@Юx}䜠Ge%l@"p1`EDd@cdrAG _ Ą#i;4vV0-6})$47L:ލ r@I-]^'QOkJK31o5!|H;s uO;}[t'1,6@(SPW $_0mK]Wq&-?jB;.sg9C;”x&&nS ?.N Dl%z(i=jA 'n^ &d"/ ޶K%!ػǔJ GDbFKa` VL.70QNcן&G Lϧ T0oVYuG;xnoY\;]oيAn-zL̎?ǽmXy, ܱZY^̊H`,:][#a& b]Qa:GYmtPkPQ-PĦz9]բX8tZ`Sw+vk{mP?1SѼlu:Uø}܂Bȿ^ LYy/O4H;6 <"_mwS)HNo tLn= "0w)~bP)̾ǵmczv b0/`&^'[-yВbIq߻܉+ڡ|, O[AEMnԁ s9Q8_OTؽ3 4PU 4S?@!bZiyBY4J!:Ю O̕ жV 3v7=JT܅*}Ͳ򛸠)`pXQ~ 4”'`~aGWoiġl:B w3%fd#^K4[ϸhhF[-oz sK`?u!J%hMI|y2 7Wlѵn Fg_ ym'dX,2..7K~B9(V,?? MO&p{'Q!iD-Sԣ3P\ay2Oo-s&uClq/"t!P734wsծ OR<]˧xDܯ$j4#cԩO&xh~d@u vڎ[(Ig候E0z&4nF"B1J_sZ~:^cY/Zt}`S,z#$ aHU5!*Wl5`7O[_M0c0MsE)"D-c۳Ydߑ J}|٬b3a ׬q" zL_| Gq^d'f볇6s9M$4Z)B:yAP|O4P YvOXbܗ D5p3*e1Wa9F4ꞵ{sz!}TpuqDlC-Lp!X-Ҳ&K Cq7ʍ-X!{R.C)=6`Hx d0 Y6,.};.gplꭼgTYJhwIq)O?敋V}B_SePXO7. <+TB1 lP㥷Tl֦w蜯jG{bgsd:˂`#.m`"7VWAW;jtUt8\Zᄔ~w~*!#I;J26ߞ6!#9 з .2!G=Wz@!Oa4:I~ff?h]dz|0ЍcbX}{C"n!zyEΨ8c?wa)uY lJC~$^Jc*Q"B/}cTh5܃iAp_rH!+ڞԁOnx l%⎨4Rv)܇jEmZtP4M`_VV*el8mgeITGi\ӈmGm (nzO.8Td?0 ڢ,bdPKU < $盧k)NIen=<{”]VgY~@r{<ꓹ5ȝݪ RB1A?w$Ћb[+΍%%0$^p~Vg_S +L*)9c=s& s0BɅ I.맭|i6.62W؅ibNˠĎh r$pU$vd..GCW(uF n:v;\8<&&RV83{ZI'du-Eyqm/{/D$Ed n=0'݄$h:0HTeMٗDK]"]df|UWxc96l+N3I(Q|=d?0qd"{Z-L+SH@E*XP\/σU* bwY/%RiR&!Zq ݁C\4nbAo,8yV/-XZ>1C17P&_3 4lY_8$UaVܪ+u݂yWB_=X9dwMwj-<"8-Qwٺ8]@xb^ulC8#!<*JqΎN%Lb%yn pt /+^B@ק/-ϤtteѴKOF%V?]h5j n%I1h"mM3ÇYic,b*:[ Ҟt(<*mOn'tTX(56 P?*1r4;&ƚ3F1CdT}S<(+@|v!x '?Pi;\/c$ V(k׶awIc&lB<V䰖H2ݒw9.hsCC( {t1aTn;`Md)w>P_45k:_2| `9]W˛HXڭ2f;>ӭxãq?3ݦ%'#MA=~o }1Sw!S*Q&-˺DFpBHې^fq8bWe3?|CsdzTM~\.Fq9F+1˙OhBeZB1XJj=p^XQDa .D_E gU«!nj>L`)7J<I5qBGjC͸㜛ӝ?9%ٯhŬzK]nSe46Nwr>z$pYنߟt$Hth [Co}&BCP CcQ.LLQ &I XF0|Xjp֮O;exGXSD*:9VEr-[1zIOH7,8ymm#.G5l"&Cp`ȧb\‡+C9~]2|;YQԅ"P4\\[qz "f$ݩy̋@^X++M%oWb5@ tV!s-Ԧl"']@Gx3$JN\g!rsYmWє"̐U'\).밢^Mcጄ[-o~O_~?~Fkm1yBôja۰萖fsgNiy!{pcX#uo%=GH%tcǜc]=D?leß*OA|_!cw SSS@cӇ#\?JCBE .j ~ ͊us[ JӭE_QН:v\<SO{#qHS逦^Fp:*D_IorFnUjRD</|P[1oQO%I&x P^|K3;5V"8SzÅn&^/"|fGK&"gn@=o{M]iA37Du=M`#rY{ϯ.~n ,ۙ&E?]̌-MqB˟1fE Ui:pޯҔ{깎r>k`̂A7XGTĄ~3#Ufk3-*wۻ_Bz]>:4ӹd ȟm+_6gFģ|T.|;,Ji}5Qu_k\#UEt)Bb 4!p2s*|ާ{7mce(-uWP#(F@у\ \%AB!#4ν29Mj:K@ |yL5Dƒj+)6p8|69h|Q$J5;xM$g}^<'^DSt*k/,Vڍ%]YGVզ?ERO7,//M' `7g04 OXL~ii:tq& c {? }ы_ljGMcT_ v{JՌ@)NpG(^ -h-taoqȣ|7B̅-v* 3WV5A7c|'?VxfM/󴧭=Dc|YHrlo9p1J:76]yF;5zBTqq ԍzG$J^F6`ɯHv\P}h'1Mʗ(][t?)q$q7̣?[G  ئFjx"s'ME!>ɠc/YΫ] ( e6Z˾̳ە7t\֯=¿yVYlޗV/xt{r)Y ט nu ZпT^j^³}HE|oVON9w kGz P>1{o^#(fm' E*y+!YK[o{7ˉ\[+RaeŸ1:ژ]!Rb`חiXim jy>_gJ4iU&a|U(_vx{f c<.!X3Ȅp9k o8ltu^*'dl ЊYYsG&Dn^} E8o^mYr)}R3:_4NH97a5x^υ: \`ı>Ve& =0"W̋j dOL$}P tK7=!c/8y7ff[Kpt^iօ8h΁eȑؕD^jd-,JlJpk K=Nn6 sg͹e9Ia$*-qÑDSN_NG]._hÐh(Hi}|ErmgFA~rb9&!+9&"xH ~9:w"ͣRHRLؖ=Dj(XxQoY kyl?r~ -KE^ =~CwdNYO_En7=P}FۮίA:%:ރi{ٜ?^ɭ?5{ }@-x=?eU!"$M/E_XW jŎI4`%DH֨"8w׉HϬ<WxD)D/]{!‹ט{6M$zJT}iENPJP^;Lwys1cȣtEv$钹=rS.s% Z?gt/K‡RS?ΫgY6P^+%y voݢ`( ݭ@+]zIǹl8N1/a@B~D a$}/tGפTj5t+g_wJb⥽3WUE5)j$+3#@~n4>(Sl]+N%UxRqf5{%e b#zjl'DLG bOx 85Se>V%,lރW+ʵ&I|UO a/] 7TJ[LJ$  QH/?Fs Eۮ<]c5큒̼iϛ0VE E5埐qek窵t=<؈1s3VD_*}d(旗qaNIYM3AVcH,2]ބ%z'(gVm]UҬI3`و{aUdw9<&ȡdE]t:d̑}V";sT%Hgߞt{㓒}ysvhsOj.g307vA2`$}<(p)¾KFvZ1K؊7h UY=rL354#A^jf,s++PD )>}A5sDoIV,QQP]-[5G[V4Jtss|[,: B}~<˘P+;.8لp갊ڛ{^?{|ǡ+[HUNl΂Ji>6̦D*ex׿Ǐb6nG3C W Mn)?-ς"02[Ò;IO#/ɔ"ِ>hH ۅiG5sYEK;D{l~ z7vt ̽Th(:⨑wN >[K:d%6?$&4 .{4AW4ykȄN( >wZ.<\>HV98$D'M4_Vϓn=R`6S-Ȍ .4y$6>EHXG "=3QNP )og5_gJ6^]3[1'\xk]]YFXKko&I/imNKF,LkC`X&5u3 ?@:_#3P|R-y=s4Hϳ'h|`޴,PB@Zot'Qje[ãDR k YL%w1˳6_unIg2oM[ש"^QuMvr%]2=͵T.}y*$y:LC=i|#xib#hSpi+FHr$jQj͓]6T6ռ` '2Evt+#lr2_Ţ IjHU;"n@k%y:l?2XJ7M\)Mg{?i0oWg6,!I'U *!y<׿,~-KoFdǖ,vt;ޤGS GܐSA4>-W绫K'|p .%N=&oUԨ0N ;6r؇xE6TȻL] Ze'R-$H.*R\s_ݻRZBݤ"9pSYo+e&C34O{h},\V{רJa=nIa|7Ăx~Ī ǧAD pºܠHG;)?hbǹv*7hfy? }:pZz9*;ĝ(P3ߍi+t}00 Tĵ(7{ fDbwt ̻OrpLmԆ"ӷa!H3BOy%[. )q%x+JVV֧5L_r)nU͐ʈ}v+T4wUz5js˶b]F{z^N_&~C2Q *'-@,ZɢQB`uz?H{'LLj,0mrpa cb"Snldu7T$cp;; F-Le[+dZ+k;-==/B}jݏR&' !LFv߃$^aԸ_f|eeĐK(1Vy}'F 9SL?ov|y]DRٶxp#_aVl9sSMԮ!13 ͢SWfhND04y}2##|:z>C$70e]jR][KeU!\34q0TWXqxLdz!"V#ӏ7Jخ 0oDkE8HUu֫D5a'd½{Y}=bYijiH3/ !yoHӺ~̵~T[y6TyA #_#}p{0.cQ{l7Z'Fn a*6TJTB.Y/l<ϸ"0Q` +f #g~& 'F~5b Z _g-=FRg+ȅoE[J]t@`ǐE>FLA/QQj~th͈=ws QeO]OlLd{ <5`ƈ>-~+ب5иvZt\pEQӽ2vo2ҽEu` 8\ɳE0ه܋MLkfK/2"lYRv͊CGN `k}dړ'-ʩ;geƲ7K)\}>9aiF_*)?`fr!S?q91XuqNr^",3* sĽ}#q%{ھ/O0̣$0{@z$Sݹ÷5*{R:Ή~aSNH-"aMl3ռTxW-:[h6: EwBOSwItTœp6fHs F'<26x ܀F ^XpG !d 3,vVQ͞D0ݼYCt֙S7őUn oFX r|%,B ڗ!|4.UrگGNW8P&={$t Ʒv/!ےy.7\iYO8Z9lH2%}aٟq)3;ΓyKf"h Mr)&A_FD7x?R $6#iSwN`.!^Af$SWfS5]gt,Ʌ7ͬC3K=T`ACB ; i"#c47Dو 0:H+_ϭpuY_`4d@y8 !,zu`}+0bKADj;F'ęI6~ކ%5l5ǸȸXU?/Er,*C zXx.HN]͊.H?'Eq鐔3끐mzF5ΐ_s^8䄥$ +YyodBGb )} '683mҧzvCYM>=.ܻ~"}ԅ\ג5-zR[65t`/b Ǯa&-\&~2/1!2#(Z=݈󒚶) IIQ?yg*^I H|k wQaV6 (|jXǼ!fӛ [p&-n2tɦ [v.$<Dp/npUyIyў@ F&4^Йp^`)v>S,`,,WQ?aVa0T[$ ;cRk[ǞJMor'3B;p)\Y_ [+OJ%gd,Iόӈ<5PPu|.u ğM>pW ?5ӣ*\u`$ E|iIޘOb ޒNnڸMeM@(iÊu))  /[:[%㨦!{S.bDCtr>*CKYB_[8i L* wUIl rAԿ$?.GLz=\PIJ& 3ȼ|2"fG'kCXDJ++J Y&z՞@Tg|[4tJR6i7C 72W^L7Qz;9=6$wej ]8׆i' 1Lz="h(Ouf-Ͷ('!!][G~]g.P+E¯-gg?[i-U$K(J^@%i RN:q>jȫdg\P"BGlfY $F :.vyl찑bIPeC"_c S"Z V#݁jw`"j7Bv]醮# ˿8A|\lNz&Hwx\+q<)++!zW5U gyuPix^jHˏeٮ#B݊b@GpsCF+J e e(жL§BY/7km;L풅\\?)paTCjy^ p+2ӭ<,G8sWcL=I" NP%5L6t]c,LkuLP >'^gESEe2]!v7!J}/JF"l#= >7݇:Sb^Od?F~kKOQ ѶEo@XJ|H~sd1 m=m eN|MȋUiZ$ټ@;i{wMp NF've rcEoP@A*[d*ۈBjC +_RoI:9GsmtѪٯ?Ѳ?ߕF9:(jS⪽\v̶%1#dtt#59P"̝4 b󎁋-_r O9?M!P<qʀ?_[ͽ9ª<.AV`T.SbBgk8?WcU{aLG9q1LvC QWgJ3jx`&bͺ%[?iҧ;S7} o}{C3 zk=qӬEe `C<(cL ?B3â҆J ,n%]+KH#p/7tzܖ*[J01ڢy!΃uKOﱼ@XL 8qL;cnBpXhmk֌DWqUF d>#텔C7[N1n`NW)R!Apx50P>xsY .lz#Q(DMb.{8L\k+Q{:*gyXT ~`_=32bm*YLԤe/BddyNe}VV4M9B1~cɡRKk (\ *\-M=yw6㻰͢ѶA"C@dAD3'p5uPM9 x0 l z II%v7CIJD d8%<کX.Uk㦆$s!'iؕnA_~dyTƘX>l= 'inNi_ADKpRA 㡁< C&IG5=54 q~V䷳`,mP P_w[#C^sE۰AnO:cjgOoRC:WdZ,.K<$!8K!4Tut%iXk=O^l]X}j\;JV5r^&$ (2 WO d%sa Z&1}d'JjC6/hLS hj5S6MxF"q#Łw/E a? []ylǦar+%2 ShpH9WR7-hyu\bn?`"zlȚY}ZVLs>I{.N9bum,lS*e Jbb5ጫ_cCUN;I*u]+bX>Tj7zAHTTgۏr\SJr)'q^ [#Bʼn)`{G|Tx}{t|2d_٩>kDHTUC?PPG)L gz5LdrBs."k K;x l+i*&j!XSYñΫLi]8e1A^IF6Y vOA-H6/XCnoǺggȁ KcaI hA_asq='~1 _MܞJ 3G7aRq[R`e@D%xDk> G,3Jj*Ct9ul>\p$S8(5|{iS]%)*O?L?zi/-1\A(!b02fҮ lc2Aeq|2K'uV"`]ҥFN(>jghcKoHo\. l7L$λC d1d2VO=izZL6_1T 0Na:B(-H3sfBh.:$JǷ36+^ʮ0pGlT EҋPE;QGB1)sșv{{U6x PK9ۤ(>۸2dIMYhjjGSTr:! LB-׮R 3e2' jcj1BTݶ w-d 2 77[΂焽yv )۱OvD~o2ӮGrlCZY3@>gf NF}M0=Æ2̍^B/i泌RI)Gd2n{w0BwRv]- 7I;FP>l~NtO\l:f.6) w|6ʴ ~<+]\qΏSk/Ld c0l~(t@F:%4 U=5@mp]# nF>1B$8OfmL{OA})Jr#F\]pcp ]m=;֖r Սn+|6p(%Њ\jV{Ե**V 4'L4755 q(sC/]5* z6p`x .B9)bj50hxOls.h5U*V\Ԩ<)HP@$Q4?. ة#)LFHqS7wY 'v鴕V0 3`qDn)k_eֺ֑9mX$܉8O”J\Pyi ؖ.XugyK wjYVv-`?S/Yu#,aw5MB@Quu] 5Sܒj3`n#(9Nw{82$&PMrIEWMBv?2)w"IŪKt@+ŮCnLD 5[ru-z4?~W7TRKs}UGqqGd"1se& yl^/'Iɕ&jDaf@X[g[vh9G}IJ?f"(8e! ^4ˌELypg$;Q L//{?$!]ٹ-O|"yk]Ӹ+4LXAr y +OM)\Uʮhh,gHp 1aZ[h5C 5ͮ *@^y3\ᇯ]2[wO< YH}=InS,8JU 2g n.ۙDKB`jBK, K805~Ez0#_!B7 |}1.  D.|cMl).ݑ萻M@,:.tZzTOw.kY1ـoArLmEg٥?>(/<{oi&NJl3: 6>3/-[oHN<5p\·+&vQ PD\4 Vά4mm 9p SPNEYY*#=$.sRrE %T#YD,+1-}7BUS@i4$$1;ΌIn,pn\ӎ^ۘ*Q9kr_]F|Af@ty5"q)9έ ^"ߡOwGp]*PհD܅ij39k̔V]Nq 4FR !"S(}mqט|5{Qu |8\g2;!aߢR%2@@j-ت$X! 푝s*KP˔DPwS@žIuEEz7&$wYq; JHk2yq|݋Q4DV '73yt}t{Um#/;C#~/7n]Y_(@D= Yżf6O,CwF1[A3Z!3dBa3),kntIZd.nFҲwm6u]y![3a1lDm$tū 'r]6LXF[- Uזx{2Y} %Cj6<"%4$ Dgm`H@#04JF'{A} \ ܄?ࣾc;g⌐R1]eswڷ5+%47% ɑuOG cwQ+}X$o#u1` t+n8y>lsdJ "Y8icpis~i&sݩSpϳy= <),pMۊAui۰y0Hj#WkRN\G-iL< dAfyJ{ _՜Pr߇|rJ7AvWFc^\zO>+4)t;ށ.,DvtO+&Yb6S~E\H`hm&PV |"ϬԳh=vdQ"#̝,@䇅IFi#eH6[4m{1v/l&3/U6@~ $aW{+ӥm+}uRKie^;EErL8d#61ext'6RҐk<Ìg,* 2{ hA2RڨJˠkKh\k-(N0289QFk78ۤf& KT&b9 @\N៝%] DGF16xC?V3VWQY su"?5ۣ Ro<趹+_<+3'Pu\XpMJ5K|1 lo+9񇲯]Edj/*cJ-w_#4c[mi#NakRZO* "g '^C9VyevId͕yw]ɖfjLݔf^C3>y?'LY7~G8!n*%>XЮ=?BBE"02bF~Bz ;uT]Ϗ:Eă q6ڳ6#B-~>jYAJ0ЧZ<"hf$ V׺5N;Ėc$P77.uq2Tkb d%S\'x\ӚۅBI:ƖI4-quAVg,ץfjَ {Rtڨ a!QR-\{_(¾ J&z_6HKm| Md!d 9ʏ =19H7q{ ȷLwg gőTBDCXzzy\o)EIF E8(5e,Hԗs'CEn[@ gQ)!݀8jψ݌vf k~K8pp) K,1(FfƜ2`HBc](ݭ`댋 + (-|kkL,HGzzI|BS5i,BWj|G$^Y8-)QɩG]B}Ť`}ܝ (ҞO׋H5Px*Whюi*0s-ƛ0{yicAٮ.C-ЂA(P89&Wѕ6]h<`ĹVxQ@\*+%>`ie8Ɱ?{VcbWutjG\b]4kaw;R (=HCb#ePcoBD Xp(xضO4KdJI gZ:~a VXՆz5TI,Bv9<.V 0&s("}8]ź =fiqQ&c]Mk9_ WeRlNjWB Wv+W"7NS{\%EMوAMB-]ҹdTxb 2  f`?Qka;OT =^GTMWGwh^h -T\qL$]U5HQǾ'>3&`MȆ1>&/&LL{8pN%Sax]lTڳ_}Йqjn~;fWLګP:J)qSŘ3-%eT:F\ q^0yTAWoEqpHȅst3Oux>"#!I$ Ϻo;45'cRXP6/+MEjKL<Ģ*x^( s] O"z +8՘Puك[`jc~צvkan+ۚ ޠ}˃~ z`^ QR'~Œ w~ (LZ*h",4F /fA)\2)nK&4鋓64ΰ?0@s.QSRp`Am@_"2䅊X9p7psQ.Ui}Ϋ^Y%f5}C4 [ lƵ d`xϟ$hʈ>"L0V R Ȏ=I*deXR*91ݔ]SM$0B3ݤLtڠ4:>Ck)苻.@ϱCUMRE[N:kx";@<ګ>qټ.Cޒe BFM[_ DŽ: $%mG,G(}GC ޼73@49ZncZ^Apw슩;ͻS) #^q瓚6i/)j%ާ&*35[H_5Əx^ }rg.֍((+55` xb=YsqgҡhQ'Yz6X2TS(H}qnRBSDh. _/+}O:mc}e)ϲ"P橩L2F<#VPYBܥvѳm uA;.Z}"TډIenQ"= %8lӴBg5A`T xx$oSxRτc;'ҲHX6}#Z$5uWt0sQR:o 8%(/0o'b X=F$]ѽ_'͓/P˙()jLW'jl/\e(=4vu~D_moO)wEo 2ZxSR'4U6;/5v(XexZQE:r=Q(-!|.$‹=$oſǹpo|9$z^k8 nw)mRGs;Αr(-*g8T|WH d"*߆{w";ȯ'xأu~{OT2fgV~"D]0SU*E4 a'Fʮ=f.u41Nz?KO76ЈI\Em+>^$PV9L>NhMz"MP^9dɾW΄K;eq|7^;*cu*~Jxj3ٲ?:MNz]2䅘Ia})͢yrWZ+ǀlUd/RG/NpԽ(>d!|vu>Ò3L xyR-6#Ì#KꝔ=ݖ*\]_mۖ+$Awïc;{}r|zwE=p|!CC* u?*YDzl{gx3WZdCs<ytU41a 372יpRTm_g'HT>~s`2j ݓo4ݬzW0tO$j wK@o>X w׳mL: %,ɉl`)x)dv!\4ؕ Ntoky (bՏ= <}BD[t$|wm` h&rsnlp\O^#QBcSJRr;H9+8y59KKTA5% r<s>R:\o'lӓ&JnCZ0Aka9jPtڌCp&|a>cޠ`>oYb]eG+)I]) \]>@_hZ%wI ?;pL%Zɇk n _u;D@IQcht:&>1V1/2OJfM+聩We]jh )aJ3ȫI#ץ8Az>-ly4a v0s bR' Loc؟Nz/q;jyZil4Zn.=KB1SODX>D?ZFa3%:lwp>6tP\%*Fw{ ]*r™>=|x9Zle>)Mk@֑Yԟ E(25ۊ155Y7 ZdJVzo'tfё :HQvzMu9'HGb^o&dwY37jv%v̺<ٝetyTMƐ,&kDf1-$~1JYr`Ӕi[3>3d-oݳnu۞Yug@ꉝ~ ^Db1;@B+eP/'r)yR)},wKn,0N1.^PqNewy&&S91QWϕ?K> Ce[S4֔5\X\8p2j&Oh@;GlpBFOxkDbt6 #sk'^k%[@5O7hLLXjNl3Csb1"ݷ+zK,haP/>֞qhTrhZB13'fkud%NĘH%¥sV^ro~cS10Lqt~=FKWѰU{H8l42ef7QEiK =~Bx9eҿ sPhxTKjB~|43bk9|hގdcEM$ASjX._ 2xᎳmdO\=E]2rӈbbHAp)}A Xb૷'Hϴ^C,|S .>$4}XsT-MDFQ/ln*Irsv7[vJ8*5BEPyR`IgA ~AO+$ ^zۼQv*R,q)*F\h'K['9߀'F܁CoV5 K|8v|Ug$NfBSMYŜMMqQ"҉+sw)I  cI&B+>c W#*Lqϋ$*&k{3pcm %)9O0&(}Ui 1qUʫbFU!tEGnTJ3g>#kT# #;@6U=>)6|a t"xI%4ǁ& :wncGD?™Q]jMP =ϕvB*5ѻNobj~0/zFC(\ TX^kћ4{DEIT-ѼzQqT&*;*# 6Ds(\9 xԆP|t&b|a, @% >c7))X~MvNzxI[ ?Ed,'{ݟbUq `%mt6GP$}xtQΦaUp1%oTIt6x1pᵻmuORC+ddB:ŠpݚPa.۶ :b _`P$` x ,\~YP@)K3 oE_Zn58B IR="j n8b|\~]Gp ǫL wvH|8|i #fcws09MK j? nr}Xu^>@g G5}~,gkT3@=G`_5gdNfm^(͑(tGg`ޢCJsO-j^̞ .$`2 =<|[T!0<쑤Yc *^a)Bå/(Gv78)F"yW(Q^5G4pjnǬuՔ.jᢀX .]W >rJ G]EY!ϕ mIh`ov2eOQ_#6E'Ua_ T_Д=rگx 䂧xƧb p3Gt<s|5*E  HL K/!c=°qJC~G@;&PG\)fM`DiS.jjr+:g sz?ͭӧ@^bBxF;p\.BB}n1Ke~`|B[n0WvwĤev2b|e Ӹ5ܽy"2y-;z]QVЭioT-f^5zoPDD#+>y՞Hm/& hUܹ.;  x3_e6Ǭn[9sY.. R:.:KƑz۠ޗe|]On Afb *o]H@U!ST |`<(9=7{@zo̒BKĥ!6Kr2U]̴K)W-ǵL#O>b݃ǿJ+{n ct(rTS|. 0`~p/t cͱ[r eNvúoJ^ˡlY, .jf G  #|)[@&qaR-]g1P+h盃=tq{!SJIQt0,`#cHQ(rqkG.ýg̯o޺{0^ Q%!s*ȫN@!;,|?`!^_ E[<ܡ]UyCONWצ*K_P^Sυ$}+ 8oq\|lX&s6 #]֞9=X><7V,nyHYJ"`7IWϫC5qxydiΙ ?j ϒaV" #ZTDQu8;!ga470QC=b:a\uadB#X2 pur@>H#BL{73 ~j }(@/I@#rcvD]ən)/{ıHJFD -;ň# 0 &d~!~Y9C{IZ. Q\r8ڷLMf$9-&>z|8@@;{:q,dBD$Kuw;iZMBb":j:-\Q`PZhf_#؍ڼ SV5n:w7Qvʓ^~C{bjO0t=d},2~M'?r;NwdF8)ҳ8t؛~}wGwvRnS9no}5|mN:!:&ۏ~u1/lU9sImNӻlZZРX<7:PcMnvyHfxIs/,ފ-Šo4i)%So9f5>,j6wњBA6ƞm)_Sn#&Mb!9 wb61u;EVٚP >\0 a v]jSW+42Xn<da =57a#!r $% jb7{nO=1" cD:ݧ8|]t8 B7UMd3KX>pT0PkO"~~;ko~\7[z}̝u%FONoE2NܼAS%3r :KM\;`".=x!Oɪ/'`7xX|O-dB k%ZH9GI<0^y#Akᬞ { r \L ŻD [7Mw͌b+^P/T4-gpn\fЃk 5W4cwAd/ue1 W{C6(>x^AdM(? 'sؘ|pf U\ʊiY{%Gi$' 5l]%W/mH:ZzeD iGc݅"Rہ PL Y/k?-[g1rfbTw ^\qF$]B4qgps4oXMTRZ4K_'LJx9=l"l$/@&::ȠY?W}J[+|Wq{ءt.@S߰,/3*:V 22@evsϯoe0`M _7t<"\M B@OTvayѺуwdgS=t2yj6PIf]#s/e _j0d&h'plJ6C3V'&bV hz FŮ͞x*g򑼹 hR!WOU.ϲ ٰ/E [#_mXI%W_@-m;*DiM-ETK.:ϤJj]VЄksw {TѦN%LU0@\&G̟`2Df:˸/f Փ1c ӌ~E`cd ö(w7)}f]Uے8Pm<v0WSz=%#lrD ^=U\՜AD,d;[x>N1esҷu \C h(8E2=KvFXxyrBa#| .:׻w6}[Rɓ9EWm4.PQ R . nI,ՠY#%xʿ.OkFE1v{{QRU Y7gm+kOg8Ok+:tɗTmv56p5Wddج.iCKY5m]y&T m01?Vhk9#kICbUhFw"RՈz`t[n *jG[Uy$7E6tʔdM9O1m~Y'6,=kun,IBO4AK@֥$NFIQQ0 F!kLze䔹%>X\>h~ %[HtgȵB_2Y\O(a%.1 @Hi$aasǏnm͕Qy;%Wj/WDNp $d4#á&{K4+9a̋H>8VD1p+}#. 8=%͂ 7"?FsózYpR(iD[]X5)|HA.JlȩgQXi Mʠ_4|+xE>FytDi<1<حWg^8g L;gyE2K$Tţb.'{p "BP˿#Tzwa>l Q'BQ f|%s{^wc02dwzj2%z|Xd^ r^!lS~`T _BWk I>ʩ┋TDŭ),DƄˋՕ뺳Ws|=. nz(,d}%"/8։ `u!o줱BRS mc qMeOc0%#cȥ&8JfcSHdlHǗ+KC+UXacSzk[M pe0ZśBEU$#inɳ.2[7SdgDdCNU>Av&WT@TZ~E Qswf )蕊]qUԛɦKh\F}0Jl`K!{нl>ą}JqY32o/&J?<}-<‹ڥ݇/s9僥PFiWD[%W2}tdRrS 3|O4wDui2!S!b&oZF"=G'g ^aSROuo[O+-+gY{hﺡ?&\K5qxV gOxW|F_hgI[,%IA}ΗqQ<=T^IvV\ƒUsbQIy;i aF@!iSz}OiPA 44, ;"/sM ߲ i"(t~}1Ili7?N4 l%u|ŻBo+M${;r*;&*Q NGߒ$cʑ,Q+窫L-Cu"hkfF~CטsxE@8O)q]lDLׯ$`9E}-z;ؾ1sǜSV! mUd6Y-ۜ"\xX`Y<^f*F#XϢܢyIOτq:Ȓ a=jtvr.(A0C}¥k!0{fr5O<1N1Uۜ$}8|ʔ >.Gyq`#&l\ Ā ܅ "@wm(W!ksIa3[ /|a%_-. :[HPYbpnGPn|hp9ߖADp9ɯ` =FL>`ǻ#DTjcsD8J\4!-nD{/c/ܲ]Z2_M p!R w؋6>!hp,tUroƉo*:h 㶄#uJcw(Ld2,O 8-4N'fr.R9PFt9~~oW^31-(}:vOiUn'\; V(EANmŃEy(z/4JL_^OQHY}Xqx9f׆ZP)JŐ4+ep ,RP>7\,VN޸bvypн/st|.y(W{p%j }|Y$9ǎG() /hRDFEurL!\>?|=+t9JLrFѫ=ΰV`zu<|u#z,hpa,.a9ʹĈwkuI MG7:r_)PAZ0qZ(Z2z @+GGiΊbH} "9iJ}Srd7#ȝ#Oݟ&?l$Oޤ1\)bSdE^5RWbʶB,}OgΨa=V{l3$7+f_L٢†O-k}@pjYe儝HoW RU^f+&egPYqtќ5 Գ)<&Q%їѻLhzQLFj҅XYA1Kl2bXj\PNTQ5S0riXش-%1>qVK4ay#x:,tgfBsizj?rBqȔWX7j4VCĹ,,ڜI"Zn338$Β#$o׆èIN}`m12bm !;te{Mm._LC[@z0Gv6/?=2spN2s#pg'Yv]Z`*&7>WQ3 qm1gb &ߗ hA\0Aw$VlaB"1>6QpVG:#$59~bX PQH9?3dɜM#Ȣt][%.RlΞg ̓ yn (yGȚnɵ~`؊N@UA5t%nX ޷$moA Bӵ1*->j}?TP2#1u@H%2iMmevOGkꇙņc}+X&ra6.Q] ||rFȎ&@`xU;`9ZZR ,/_O>9av[ {5lgñ5^DYKVvo;fDLF/nZZ%R3i3yВr{/g"EkfU'?8 'l5<"MN2[ivS\]FwrWaN.Jϧ ??ľ@54V3?~4+ QVd`ڷ6@6B]I,&o\]&u[Sey }.-5-&~_nPݾO2x吐Xif% p$_ꙇ(5$%7Y)<(da|-^|9wMP0recVf~I9~1'hˌHw$*XV_E];{kyԪ *8,*z0Pb3Q1P= kҋ:2a|Iujy% ;~0e \F2b-nc$ULWP$)g5Um^}#Z  c*Œ+n.)]s*wڜڊp$^kۍےطtY+fy˜mc~ o$UӇᥚXS%1{-g[ySMWEU. Y&Ucr 7:eR7I{A½Zmn]>(BӟS~`:z~ :&u6ry1GPLљK@ޘoD۔6LJt`Db(yC'U9t#H=͵P@e`NL#t+π:G#|?ylGk7^euȇyY}4 xX5;էog^J&&cp=K¶XbϱpSYR]F{V ]M V؝4v.T6/:Vrhԋe5W9Iw#,\CA0Cd 0r~}Dn[FxYUeK~/@&obtJ(tLaP7' ώ2A0gւ!`X rr|db&+zcja յQuLf^(t+95. l+ɹ+Z3Kx`҂EN5f])]2F=:T'l3H40=jI.rqCɦY"J$}sb`ɴ=րbm'8h8h63DCCY"QX$yMsTX|fM\$w\Ύ6hK\"Ŧ* XG"b^ RX UUgL.4Xˎ$mv64㴇@t]{jn=_p: #!3rW.y*Gvx[}<&Fqv"YHO$H9A u˺Αt./h{6|b|Vzod|4dȸŸσzLPҭ^ 4-4Mř (H⏌4 tCVmu?|-@E+8LpsSY:AdW/X='p50Ч)7с^؃{r^$?Fsb1x3H9Kx 8|IpO`{#3{3z_j1I;@-6 _&awـd qMkmeP8&*Wc8( RH_Cãi 5 162>K丢k\~4y9mç}jK+w˰[/cy?<7zx7c%ҝ ys" !MFiqUtLRj(1J]f@s]sR8N=C Wi~mBC -t pYSy=5M.a]kyd܌F7/"} iyFK9i59tkj ʛn#ۙ~ & W+^G.N" I@0N1껳MU *|5In,-PiQ(_?v7\ohZA/PtRcL&Ĺ8? : |(d2 `Hss՚:=R{-N6?(-QsUMfދ꾌YCOcaNpb?wrh88@gͅӝ9Ie~9%CMv|v\Vι.0K ۳M#w̸}X{( 4&nL3 ~1dǴ6pA9 l^Ǭ+u;1䴅o[RhCI&;?|R*KyEaj1@Pf́̌`iGU^ s2Pao#eGcoB(K}?8YP_2W}BP ]QTM#{vv߻u6q,i C"Hm&HvX"TqQwqx$\^]X'k-C8k½(/2rY{Yka|Ag#3iP--tR/لYy]4_by0dYǪfDF$)LPwADY'UW`Dh~Xi2FAusi1?[u(M4OܛRc(? FO Z5 'gH^C6YL׵S :ܯ}geL닧(x/$w祱4$y n& 5jIxmUFM9lg5ZV_RMX$2ƞ@Z܂Ϯk}_(LZV~3i7t=Յ@gd\5GmXg^iW=QyRTwC?G-A4>11"D 4&Z$șlhظtM{nTe8  I(=@{\ )O睁5#DIWK(&൜[((cxm0HSX\ ԥ|TO3e~O܇V7R/1X 5 _$r@Ws ,=DO ȗǜ 4y[wMWB E?캁jbX]Uv BDK&{Y@=DŽ:8DhV3 ?bsLOC~|5}1~/O5ս'ժ [,Hݭx ~BV$^p wo7näWgsLE0ϲϯo(8$d-ԭDZdWWz▩^Ab#~}{yw4⮠4m>y5C S&*ms PE GèjD:`Mp5\↛%xDo~ir--{(ڵ߃ xВȭ _t<pP3gdri{p\'겈O/R)`rc{u0լf6[(N\Tﳦ(9 k؁ f=aU1Q^iGQ¢^j?rT{U:*#eKl;Tcir?fwpüք@&S J;cѸhS%!eۀe"4{gxU|E鵖giHOp(@cu XѰGU3۠7tAzf>jbnA[KGz kUr<ᣣщJ%Pyw%>ZHSԊuAJ!+oFbnΖ0b(raS|xmn7]T6 \OQ,i L%(j~Ʃe".p7| 7AbfFcj%KLմ3)(>l#a5檞RA Q-W uD6^!TՖik-"i09%˖G۟ΘL֍J]m6r{fYnLR2| Q'Qf)ƘG{7XlSj?x" { B$"M+\SJ<(݃Oœ~xrY7J9RЦj$jR0瀶bAhၾ]9tHcp9eFΆL&ZrD1#ꍯ"%YO@YuUH"S4?a =y(, >2*%g|I5 VQjٔE1罥?@/ūH??S]^i\a$[@UD>cܧ?-upFĤ :꫔a/Jۢ]@)NDZvt>ttFxK6$־(SoI';TTW,`WcR8,0ozropx#'TN<'jUo2 UؽP|@F~cT ʙ_ 5@L&1rǕ!OBx9qfQ VP0A!ˎFN,MI{GݵM׉se ѵ4'\q<`¹pb5 &WjPWA OnݷFzțqYܞew{X i#&ڧWIN_Az_D%iG>2;vnW js5mś EץdRt* D*0r{AZ=yXubaV$f u[ XIYˤ9{ 'A%NBmO&QHa[[z)^}6pr |~X + ;/o2EnBJBF]P֤0(d1Zv].^'JiUao-98o,7ȕ}ߌ K,{78"'?uur!ppn<8>!qd; O5\ HbwB4Uu O:,Z^RҼ|Fsp*/0;io?mLSI9ƁG˪Z^qN aV @`a TOF lF+ӄ6;nZՁ{b|3uҿMK($n~ذр&l+I4h8`|:6:/;fxT0!Ica]/]gDeLKJpD8('/߳E*3Ǫ=v~ |qP;^EFYrS6cz8iO?o:~:e]{qn|f.>f3q=pw}Bc|sBq-Psc;sAAd+7 H2AuAƔV8]gep 킳7>8Ie P #W ]fA_kqak-w&6#yt֝EyU}mmߣ޻Eshlj7,Tjh[2x%X w_5,0LUi 3H8k78E&R#CPĠ`*s(Nd#$NE9T ^05T%n<G{ZIʭ;/ R|d韾W! qŕ;& p~6ȣowp`Mm߼Ml*l =R.tְTGQNIjgpp&:'.g(8SXO ~D; >:S ,Q +q7u z'̩\Jv$ˌTPGzV.uXTN YcTG sc0-:Sܰ? ܛi_Ǿ Bky/ĂIUe2N[_5鉿KctoET$0ty[ :P[iR[Ewr鴃[0=CX*^@UO(:pfj#ƛ@q]`3`RmtQi̷1&)Otz׍C4F"~ }gXЙʲi`/p8<0"V5f֊^]țUDO6Sw 22 x=2aϱ=`grOҾu&IcLxNѻ?u JMݼVID~+AӳA}/~$S.4!r뙱,4ϴ)To^˴ n~:CU~*Ođ2ߍ^R;"F Ғ`nHWj4>A7{-ݤܯ+a`F>ү.3AUܓq~ܞ aM@u*l+F)Ċ@nZC)}+f2n8~hzBw -a-K3"=@WJzSt9j_-`c8$de0GNEi[ǐ5V#%3<x]d ~2m=&. YX3Du[HGRrC+PXd$.=B%wl7aV~$yS!de*<YT2:0΋:y'B;$<̒əP[׶X^"'DZ%ȦlU/i]VSԐv㶊y,Jܱ fKm{gmĪE4E;KO$S;=ݕ. Q'Ǝh&nmn _Fd$Ao"!3j846@}UbEY0:jiF8f 3pHہij* ]A\֊RaQV\cAoC8|S^)DPZ"QډF1{q1ìd%( ,<ž[3%I_uzwe!S˺Ib?o .-AV*9CnmƱk1`#Txl,ȯ^/,a#ۑv$N|0_b^99kPQ.wJp^]YigQjMFH?mBab,#ƬxZة-k!4ȇ4н`ENMHyU,>u5|ǍyQ[1%fR=e9+O^%$9SRg|;e'H7N~]o|\Lג29ObĵM0$HUW"U4n ym ZegcjĆv@>\?@a7{y(\MRl$Pt vޭ ]ҏ/іO˩)C䗵bKq i_09^ }=Jn(]lP=Nan\}+ W6S-9.Kp 7ٺ)9}h9jh]*rc1`u@JMqű0elZl* n*UQ82kqmA,#fm6Wڰ\\'$zpyijMCm)7V?m>Ij@0YoTc3kg·ڦBHXʚ`~prV b,*;8Av+y8΄X2'6dVRlԱMV4+Hmo(CX^ueŧKx2y0yıK'\j 01Z5u(5e#r詭p';X4֗fDIz7ޛH>ZG*$fy ~Im.;Kbi)RfF4́o 8 ~DϢse {rmoN> #t(ݎ? ض9|ȝG{Q@-@E<cO-4b ݮ6|Ř r2L%SfpR$wNiȎ3SFKR;4.DLg ۢ[Ȧ2o!ɷ 7S65i y.uҀ8sK}ejܝ٬h`E צpݵuʨYGIӜe<mVʹc{L%!UEKx0FmGW7aDm!NhzsM}=qQ&7l 2}8#n2_ [F5i(9uK\܎>M-X0HYD0I(DYr{w^BeQ+q,qYw^EZ4hn+C/YKE̜dW3x ޤpI7~:­1' je.2'Z^Q?ZlyI˻[& Zd4(uEB' @2VxצeL'~&?IN] %I7iU~^rCPGfdlWe@r.;>Jz(9>~B2^b\(cxľAopA!=Ge4SƋ 9# _T2*$GTʮ]p^nϣ'>w5/TFvGlmu^ aauRlWo_[jLYp~{9== EBi A^;U×4<֟թ-OK:bVjT8#R(ЭCk|ΆQŤO>_o@eB?ߎzoO B:Ǘ+[$tWqRtj{-WuÄ& 7>/Fk5tFY6BZb:IW $N͸hҀ_VT D.-I%AZZjD6\6xJwcp ˛x ȭf1H0NJ%:hvqTrQOǶ,yw5T\^ R5Q_ٲ&akfL;. 4&:[7]:{A#%P>`xǿ{M0s tªkc֭y2W, bGEwu),L9}skUI%;S.Bqr^Dߗmq@x4VוjwLvio: 1"qK><W_;vA["Rkxc"59h+H1`Xx ۩SgYreWL<wF_('v2S)㪕N^T( co|ƹa2sܹm@k*B}l\ԐPq;ʦq'<mb?Qg&TgL1bq}].#DXQ!0/zeIp\;` B޴{\MЯg|=6s3b-Ikt?^,Q9>[E 4v:lRSnR Pw-oL) bUrLR`Bz 5-)frTHC2;ɦoa#bdYN<I2#CJTkY|rz"t c[`@؍P7K$ )/b܆فuh!|1v =0)H" asN`?m;z1^^M^h)݈>o褰.ej!Z<ރ&՛G3X6&̀j!0%8HQKӕ`!dȂ ';НHAta~3kE)3M[?J :i+'H-ťm0'5~~J5sݭxɇ.j OB=vPȝoGŬ;l*b7@dȗx3A1NDtAO#Zȁ$9=A6]S 23c>f+';Vg~-5u^2U9?&PZòfI xbl'+KlAAZ#ReQ"; '& siw-U'beQjbsVAJ6g R@$y0{92G~5lY hz6yXU^x?2) e w贬vD֑80L3L&}ۊ3 (q]dՌ`|,lw+Q識?y h0gDz9."dt")ltmp C!J 8}L٫]J)oXԎE8._(ճRYɉ:-aԌ*uѲąo ƇA\~ރ?K]ɄEf/yHĸ 鶉cmFy<i|G A} Ser̷ r ĸǁe~bwEŴ+9P{ƛDz}in+ȗYuҲ`33A SePJOw9<Ċ!&/_zl|rY Oo9\pbAEP<%yS+ 3> /49bxQudH*.0.'Vcu "Rao&Tbcq=S@z_2` VC47*W^F:Ņ)(\f@n.N<}P-/˧=8oF_ jCia^\&CMF@6RK31؝cd/nq٦Y}}"| ^89cvnT.6_Mt\oxvHfXIo|2 ca*$8f '8diҵ,ZŏZ׺YC +ҫ-!jJBM&+ 1$8,*?ع) Ao*Y$gp:9{ ׶n5̠{ 3maW)=Z|RVю40d 0"@^R7/qy[aFϰa+F]{#v2MH%<\h`%[qj l­h8 '4ϣ̐Fm1[DQD'XMVתI\yy+~ڈ s4obM1[Qؽ gs)-TC`P31} 6z^$EU׃2r8zGbc/ !*a7chB#tkBec7Cա=:\ 癩HB% !᫩@JڶyS5SPOMLro ^1]Ia2BzB 20Iu takSȍ[d@Ru;e.2$| KΨtU '8*Ar*~lhk[:~}F4Hd+?*gۧR Miyf9 P)44J/!+.:ޙ6 KƑtxteNj.\!hX ѹnjsWƒő.q}ۼ?W-31;FDLrEqx~BHY\:e.n^G 0mYxE 1ds)wi$hUW }sp`Vi C~7sdrI@(HӨ$7X,Dl?ǸCoJ&6 K.3Иju"I욆|w+td@*z\@Fp%J4P YT=ɖl h5zظTջ3r<;zt~&׉G@X)n at:DǰʯeTo7eX 3ƻ>')S%>e93ݑ"!.ŭ#)fÇ|="p_ >pp{QvnpjȃQCa"<^Ն `iF^N"`0ZAԂ`EO%Ez]um)fjLXO ~!;\kL&hotik sW7sbmwCԗ G Z.$$koD"hSe#!we'փѢBfؑڢz^yVX.B#5ƛ+/Yշ @!+s+g6%}ioRuRs}8OGFnip.xw/0DӛO!nx2Of?YwIyZ'ivPR{ѮdAќ^x6 fj;t"]wd( f] T`/L4gqRw`Z85l_Z7s& ,%u/!\QϬ9<,w -E2PwXT)iܑ ~XS, dJ^Y\LyI.6%Q^Vyp00ؿqCDZ˶{ ~:㹗$꒮qVP =&v`Pv9~`'L'd:G_J8 NOFZƂާ֜$rW^ ~wEBtQF`|-%܄.,sDLUȚȃPMخ"^x9lm\'CN_gsX ŕXZ(BGN .jB|q|i ?'.:HF)R87K-1Ir3m/^>j½ΤZ8ddzԳGk %IE?uChӃT:ō62f|{w&̟֠&hH'gOb6"Ph4ș[4dv"\ՋG-ܾN}o JQ_Kni/px)=z_"iܗ@Nӗ-~0jlTK'xtcNI^N^M˿9A;b(W;nt[=q4LVncGj>5*@r;v^Es k4(gc!Qlu` (ȍ;L?NcNuqp>bW"ppaT#} ߏG*!_,K I}ɓ'[3$~8?TFb- %Z#_߽fC?j]YZ ;NUxS*Y8a\UzY3bUU->~f&zHb}nN^2 AZgjaL6v%d"ǸNѼn،W]~BPOLH8V"4EJCTDFԐ##Q񷓕}j E,PwcrDO![!&w;+;=#t{hTw'U Ъ :q 9 n`. CmuAr\ :rRG,Z.%]EAU|fHMՖvR©D$ٓ"n)m&3id!#;L݀ ?ז~Q3C!U)VCWQY#|$*kYK*\bS㜞!䳶4K,iK!o r1/^Ya\n_3DJbr2iVyq"7 .5䧙(I{ݻ }H嵊d^eYCrJD C@ŵ˯[k[%l n*D:拔ԑY]R΍VvTR~0K]^xt3VDxtĸҽ6Ad(W[+Zod#bP4Ec%1:A2 ymc R[UL  Ź<-jOTeRD:]x|R:2յb\_D,^"R q1w(ZS|Wr_RVQjJ4vq6"FR:-5ɐk& cGGoMX9l̳we8pWϩl[EljnʌafZLĨJ̞QqXMNQ4Ϭm'ƉVF tM~ZϹ9>`6!N; SNA* 9U p/й% x@ "Ƽ6Aw uMV( VqbVp)0Bǵw#y) b6rşZk AMup4vyHV"%dV|%b}Dđ%.Z6ڹ XBm^ˌ&.iHo9n]ݨ6vRv7z1kq=ǒg1’ѧqf>7ɺqeDOKWZ5Nl·__xj*@kb/+59K׫&8H4.f .R7ܵo=7kK/ob!ws5y_[ -w+ APj;Bt 2jCb(Jvf̻GB'v=ULA /y-Pw[&)> ~ T G:=+e*ޏ,}Op6#S,~[8RTڜ\io((&@-|Opr?>uf<ͮ6]AE'!-U z@jQFQKe~$ț}vx],e47pX~5XlY/)sQ#qĔݩIYlaf8}/PF b mU؝zaG]M\˾]KQD7^%x@1b6R.^J; F+v:eX9Esb|eDlkKP/#{fֺY~tZ`Kqx[P( _{{Rhy繟b&9l[M݋FgԚ̺6x9 T쓿jh;Ѕ)މgCY=ypd0ޤuX" PQd^TU E׼>q{ {VisqPM ImuLB:Y}?.aoh4]MsF[=cLev4hjMJq{eMAUQ'A1;/_4G: y Àt2z.#Hnf&MDp,T_i2}!̓DsExfMW(8"WafQ zU^]̶RƸ|h}7Ru셎=ck拯)V-!&w2qݴq.$%]%~>iǃ9FBNjc~#&"lmI(*gLe]y5zZ$5,Bv^ȉDhL$vKJeYGˣpf5.eO̟3^mpx,"t/ T.{BB#8;m/M\i3uą7*']+Hm`Q|\ V1BQ&M*aئ4F MJK>r.)|=^i*;{C+WO##chB x*Ol44ݨns/mqBЅ˗˽D8IJ툎%&wUkpGXK%xʽto*^u7/M 5 :{hX= %vT3;ٺ혭<G֡PjZVl ZԞϽʫbSTOt $PGKWHEl.>Zcbx|itv#T4IZuWa_h n,PIB暺2B N ?-O`pn)).[S˩F)=Нxnn=}>DQ_)R;SrdKadd߼'n[F"j=gf 1vig$q]LYlo\'ģXrIV>$λ?Dh]6gFXy=l. tn idk$q_MzCK,MZvŢLI/{V/Bsm]o2mQH@ ޥwj{#XH1q߮a~:H9ؕINs׏$ }_^ȁ-Gǧ\{{)Q\郺/vf)*p&Nt@AǢ~ʶ-leSåmqv݇rj?iܽRU#;6`~1 m{İu>4Jd"ExE쮧JGe*:%fkM.M"z(z骝 q4t+IUG2.{/E{^DV#Aԟ '"g"`T>R'e3L:0 /AƅkU6ZAkhA:rVPDNƅ]FÔ}mݮҼWóυMXn,׏k:H j}PQtov\LڦR0qH޸Mg J4{ I1-6Q!j&l&$e`6.~ SP:W5JtSx6OW; +ĉkS S 3=eՊHS#y½y@MYI`׉WB=[v6-^^#LjqJni.`Z K&T)x^]?EŊ=Ñ &[ɤhfNmʜ;P/ћi D[_R82Â1N^l~H ˲K/np߳dfަ@{G@Eq\KAmQdB"44O ?@slb 5ÆVǾg%8ҿUps{jI{=NNR8~}-& <]%: J[G5p.pp,G0|m<鿺3-땅v[W "8VXoe+6PHs (/bdqj0b0\o|"oWIYg5|WB77@a*:w2Htn&C0s0ة)@jQT1Z2+lķaͮ&|1U#RefaxKkH(Q*ߤ}o2ik48ؼr U~Uo<&ižAsCPh ݫ`2 T\9k{ B:O"Wlj~t =[HK,8CcݏO?SreڼsDDk{HPgjyrwt:G]Mw>>:jIiP%Z0HNT%gGr5HyelA;=45(ٍ%3-x6&nC}Rl#ˢBLG<՝:pm~XcX|!` }]`ZuzԱ|uZ?Fna@wTgz3.u#r]5u]pq;Ty;T7xbBj.bf >`pi t0@z`g ^&013o:]/$ r^jDbDQ+IO=;?`?S+W_Tw;%&ފ:1;'d*7V=k@E^'6NOJtXhe7͐Cbrq"I]r ;|[o4V~΍JmV[lJ0=z_U{ԃR737M5 FUǹuv9[IkQ) V@fLvpj9bb&ayCсfwlZ7*"泷Pla澴6:R(z=])V/R6 y Qf ^;@eGi]DDPV.!h6WyY-A93ANA+tWW|<.&VPL_./Tu)D֡܍i[ n\kGMLNVt;ΡX\I.7AdbyofLRdt@(9:ht?2ʖ|IBA\)f%9l(g93)hּ2C 1Tl*9z8C>ULG <9O'$khzzB >6d-`xyIҪ <`a $־|3YZB 䤸q‘XYƅh9d_ 4 2{uհ*V@p-_OFS ^A#nj[\ˢK1 U7@)n'y#5ґiW4h'ɔ0*ڽq?ę]HbF/R]p/!$T0˙NƃY(,ŒX8n\tزu@j@MtR[d4w0H WG 85-E' jԇ,IWJ{b!gm!tVjvɣ֙IkCs),e_8>ya _ )tU;_E[7Yj]ǫV]EZײDù謏DvOb?))@svU!7wO^+pcaԿ/`apI,!笷=CD<\zН$w( e0 +!{ 0DkU{kݦRunY`+@ChP@m l}1茢`r[e|1CR!UXyJ(9?5fCxrR/XР δ\g3Qw#U;>pCB6,wE{t 񋒶2)C]0͘//F ,hiPӕi;},I@ԼV"D^'ꌛ,C[sz HrC8Ψ?=YT]a 'b* [2^/CMuހiaʮ@o`O)c$P/kkHHi>~Nlo J#G$)=|>W?e/d"kH]*E97*fE"=vUK"GC?%}h&99(w'_/*6w̧#p ˼uJj9nYk vZ?ثT"VKzݩ=@Q)3^cGLL  aVx0[>ȆD88e|%M'yb\Yݙ`"گtWN1U#DhhyQAT&CmęL`w> J8fX>.|D/@l#s-"P9ތt2 84Us2qB)mCZc؃~1&EBsydO9瓵iJ 1R#5$ԞiF6upx-X4j"$dWxۉQ/;n)oc 9|r(wW*>˷ajZtzjdqSH9̲6uyʶo+pF,K_5ZV /+s1d:3UkS+ O' }P8MMV7oH|z!H1X£+J':+ /^BG?.ɝzdz){>h C1qT$ J,nb hfjKC!+5;dy%ynr$3t^ Ŗ^RK9 ^~N"ʪ/XCn VrvڙCT/ QvKD1s/'ؾRr|ƶW.osoʅ fcVX{\Bx~W6 : BQ:RNDҎm{M*;;EY~f)JU][4q!aC`A$ܗˈGYRKɦo rDcAO@DcDlPGm:mQ "R (EO}2)e?A`tΤ֟ `wFJG }~>?i-Ȯa+^V7<`#ZfKŷqgIX#[[* =,S{.h=R}E;=jfn2,eFHiW@tY)h_ ?pd@86/n`G[4\#M2] mGh CT%I`phUHlqN8 ۸ *"JyoLF\餛eUǺ0߅>H^x>՘YSO]&55|b# '.-eafOS>K|$p <0eG:Af9 'h3J~gL<7BI@}vIоfp$iXR],/s/E<ˈX&HXYJvqki_}2֐ڰx5fS)個|fi;k$61CsvUas>E'*:vD(<3j*j~UݧJD#  ,+~maWɦ5G|)䯬?u ya>kݦzIaNŐ ĮeȖc}ƖD? qr8fejpNsv/Iz;2BF\%Ag ǀ7B;g|5V~ Y 5׿BG߾j -k $ݹ&>hV.y?xm`RRbd(ʶVgiix|Y9{9>z!*"B&D>ЅhBܚ>OW<n<qe@Ԟ:N *g"-r:yLfH?l}Fap ʮ'L?Gp'L'IihtS N*hdНIiNtmvp+Ώh8d~,3/ɂ19;*%m/pZq?no㾺q"٨|Ǩ򇚽U;mʻ=m_OcWm&$>:!0n\Zn$ :4ك-ent5#iK_DQG'M㬴S<2뇌`-vBN/,¤8wkU+@p nfvO3xFQ8\:]Ѵq[9z  I1eYgϴ)o#F<_te-q+`dDs=OkJO*}%Jc$N uI.,sEw5"rI;oq9lqӭ VE#*,^d/\Xۧ- "}vv:mEVn!8m‰*]ی̵aYL/5Ip̓i*.|k?5G/8@eGEF삤Ps$s 3`bg9[kRt}e(E57L䈂*仍|j}<'[IVv[z@"4 ,`)Շ{q؉zӦ!s-~2Uĕ`(ti_w/rpId->"t|^י*fHXV<`PiЃm#Zh%ȣO!u zQAPe(`!s/`'n{b>6i/;.v֭ b<"hß턅g~o `(lĘO]PqIs +wF|Mr\p'-`m\y'RCU*.C _l&'WCG]<͊57%Q&(v}EZqAK\&PC7&f1$bHqϲ+s gK|S3M v%P?,2T!i*{F/A}͋.rF_٤&<'&ّ\|oy8j#q1#<2 i%dzlcVhxRٓ]qytûnׄѽI~˭2P@ZCaW/Ǯ`=U ; !/Cr| ȋ-׮+ikQ@l/u- X0j])m/U!H*>V 鶝*[tPɈ1,;iY&7v&ü]ݞ;? )D4%ft3U(>+'!jEJ _>Uj;8hך2_:26Z5dN)+cݸW}+? u8=0#Xjq2%36pH2ogWh0xi۵7 {&ۘBW Ծ}}O^qgKpٟ.7-\+H;l$h&}PlJZծtW* 'F'QC oV)澀G.[3;R7?(6YbȬ1Zs7ul?Ŷ`LFI6D(qb]\-4{P c:K?~ 2^ GRl1e$Mu"Y/(Lcصjo"2A 7׆$E-xP+YݦsQLw=i29(}}$c_|Plul (a7">w"1WCN^b\m3!۲if:Sk] 'ˋa:X^<A`Pkx$*@Fw>r5b>ghH.^S*5x[ЃD<6I_^ExͺPdwWȜ.0G~J8ysַ kF_e7$:"%"ʄ 5ft~&3(D6sYW jc}Zv?LAAgj%Q.~0L,yg󅭨ziYUC.DS'ž<&.h zEr I;{ %|:>fjgb z #51`TVQd y7AO8i`%y4f6 3{BA^@Cه}@DMD[apf+. ~>VkXVx\o+IX%eteonG"6q=3&  U>}:K8eb"L#t|Am+Rf/d0ޘʝd*om욍mFm)O^%V{;si?zm5\TՁN,J PH:#She*tcy)@A`Of ;`E ֐4y*_BJ5N0;i]*DYW=yK-+ث"5d0uY񉨌;}ݫc1? ND?L-pYep&1[(g>%G" ħ$v>c3d G`-B<qwO5.9\ĸr=5f)o!NO`|$p( ߕڊ$*0.'P>I@^2G>K3N HcKsB&ԴI)%Ufd|r=^g[䚹Idz5 5Zإ?) }5qK:͊P;f f7m#ݥ)ӉJ NBWc]#`VT n!%]JT+Btԥo/-ˍe²x Ϗd(Q 7\?E:UֱNBegmG ?v#WQ1\'E<&Gh c9LQ}!rn6l,Y-/ Y3*3AX`t3< [gD)֍1D@#5)>SI*i߅zbAɕSY||R쌋 ⧈QÍl9@9du oANpH9AFh}uEe2J"w4jQhNJVWB('`;}նzO}3bYgpG7rBrkHQ.5ʜ.?x(p.@;(2Shia|\=/ +$&foQ E#|Mu#l12)Y,w]@'y;8>smd_eDŽ;Lx+K:c#+hm90T K4И^VXFLy#s]+w݄{ t]K}~@{ X{3pX”Yr|<26_aRqwj+J}!-;͑-QA[ n5H4.,*_,vN'7^'L}Ҧ 9_>ji"a2 ^GpT~5'2OBa1/zV6a5WyZ (C1t6] *#dY2Dwse=dZ!!SRFηNί S*Z3)+9v6Ä$z5hP:liCfS Oݢ,,TLԮ lƠ_Ý@~@p*#+=;Lr#3/K\ދ*؟e1T3Us'@@8l>;ӛ )l?r .ЫHu;wRٔևaB.>t:j p6O̧ ) E.iX\|G1#hS6sא m<5yء9 .*N;h sjC}sw'>ԡηA ZLklVkmKr8&Y&wIGK?G_6C%]%b2¥!]qH ڊr،)iX/|Қa\C,5z٘M@†gwˍS%#E 2SHwA-6Ḯ|K0HD7I̯ H}p][lq9/6Nd/()⅓ȁf$wAVBxqMMZ42ӆl\ZU(?Ca&fi}ه:gStn0 -LFFڪ@FĻK&1h҅V:Mң]_9J6K0ݾ͑/K%S D~_qVYG1![k=þ&߭̚}OHƝaG_]ּ罛8Asg@@) Jw9ڣif`\y}v#/CjP5q4!es!Ѕy|قo((D歵L/`\-Y}`:&cM%2dЩb ye(9ViAZ&K#߼ 2?mKw. u ML>EmS նM¥rA%'x/ M]yJ4zBnS fLY8Y1Kx^YK,׍U #VD 9{/RT 8JY자n`p,UFXӏhLvA#FD\PoVRG0lNۚ ݊#Iq =+LisN31&d'&1i*X߃iՔe\?E#PҘgp8h 5w[;Sa֯E3$1֣,16O|6w=XׅciQ=~)4hesǏv6c/17aPP|Cg/` wYS@uSS/ud:>2]®l'^E.[Qe7+P2H֜BϛB9zI$' ^?' % .ZWVQQ2р"7Smg>WVW:fʝ0KE9cl,hݮ}ՍH ڑ"r?+856˔]!'dWuS7]^*z{^}Z4' wa6b|șdjn,176eޜ*YeN: _+id~};L id.k|pbϙOmb RUlU/wg8lqYZTebpߖӕu 쫶 :24ut͕oHڷ@Qb<0jny^%K: ]J?ο𮂊{e:Qp Gs䔋}=̚VpT7ZhΕHP}23!-Fj.V"z%2^tmk#}@0EG" q0fL7Iǚ,_&CwpvNNg6YM=߭ZŭՊ[R^ȑJA=ev (:ͩvS7EeTm]E X/_i1{+}mOҸK<9LX+7򑏆\gLE߳F s b^!Yo#AZ"/ՊHq<2[DQ)a?Yӆi ^#ɘ:5W"iAWx(hY{(Hcŧ\A9:܍_WI|sB[kȝ<.wL?ڮJ3\s r_rJ 3̔ڿAeKtW!Z#T6Ȳ3F0czF"~2?8u^/s vaLgEZl&hr?o -"SHdB?w󊈨ʪfoSx8;td*mӿo2_z_t jX=d*<#X`#52R8Ƚ){"O5D\Xpwh]3}:=,$ߒlip]L͗ǶXRoMO>I*23՛nѿ*(pB2KQV-?_u5Ob: w:6yu7 s>XTҢg onݖ8ZE A:οIA؍(E0BLb dFіg@ rH晰\[mP0Ù1|WH\E'DKu?`#ru[۽7+3T&2 i MvhN g2}(6Y܀8#h& c\ 9/مTL !{hteӯu3N^c0q/s b_m>i*/'c%:Oa>дIkhō&s*h s.`|[a]Ic "rChhRlZew0 q2m L]\}BU8p՞ ǗH){|;$fkySf2ɚPMk?'Jwc8^-A#SUA?WTIwۋ]&QyWgB!OM R6b9rW)3)lX8% PR@_[K }D7Űb$j"ћVڋ#MWڸb4^F0{|!J /AMUN+r\ 9,}ǩ'֓rhnKf+"8fC& TN}H̬Y eeKRrIF%I"F*1Yu~&$Vlݔ\s钗Y(Oy*u QS)9P{=1Kۨz'1H/ZYKx_Qpc׸PLJ IXNr|P MH8/7)AĤXrѷj_$B8>bKod=x]aDUf}o-$qgۗ?'\#u%/]hr# HStb4q?&DEx&t? r?UXVsD֊;i1kC f4bTQ7ERGc#*hW~LjxDm/ JlS.'st}0ZIAP&H`T>g[b~o`dY_VV`P5|̙Hpp-DHXJA`;?e z0EdD5XIU}h ؛:0J0UEӞh-b$%y*T?p{vq`h%ZƽV3sσr`|¤Je2Dd }rc@"~ISѝ=3'5SŮ:*lFIwQq."aIA?ߵf?9zP0aADP@jK|}WCAb)L6p}!EĎOXzbGg9Qڈ4sLA)0P JcBI&@ɏ[~<`diO^ȃ4AM40Q*^ lɘciLqsO$2ќk˻<JQaPz@٩Wk0[pq^#7Ї*{:׏xB4N WbW)*TF^rd/m-۪#j[s J$ kD:#nDwZ^;ꡆ`¦W7xl*JW}XBʹ7QsKT@^;&GNI&'rElǝ'AW% ܭ/SI:+14"={M1!}e`VMtVk횁 ݈̐FElpLfR†伷l&~K&uGTQUp)3!4s He/M #,":PP% *p 7 O9nmPOvvFK{E[mi/^ eȜDs8+=tְ0yvu p.GK!? SwRvwG%;7bx?e@Ogo_ \ 4 RL6yF̮ 2v>(y|Q^笎-^T;ȯ܀PrV< %`Jq3[ RYqciW5B'G$̢r]۬#MCED/-%"}<'_';("JN  M n1IeF2~Ho#K̨Fa.v +.2 URzcoAM?_cyFq/ˢ,5{C_T0 hlWn㰸4?F_)dkTm1TvΏq]%EƺJ0h$*f=#V^^Ux$4kCȧem=V]WY \t?mOfۢ$kCEb!Œ אֺ PNH_sŧ\{2Zdv&N,ڋ ر䆗0h_4ȟ-U6ƭɌd(rM&* jxvm{"&վ&(08N`?rz8,m4S6vn| kSʚSq j] V!w8(!j9Ae5 9biLg%Jy;lTHVbaBM'9%WabWzXڴ qUwy3z,ptPl\,aS0]DMA͓PS//L VKKN`a&#a73xi|$F#9FP K b쐬6`Mdzߓۊ|;b^-(]8?>v˪0fEpR$"\td߱aexka 1xb]ί^\4/ؔ%"X&|eأ}gp//S ntOl`:ީSZJaClx\-hP5J!29whm.8Ҽ'B |f= x|RE&75=O< p 2|X SrϽ)(%rQ+8%n, $ AW!{vџMz=M5 Q=lXr-õzLG cJnNnwLDg1ykJ(VVm4=iw_Dr_"L lc%!v6[#adJP;)٪LZ uOS+'_{h9΀ ?6ъ.Vp84mۇ:Ug'@Pb\]q3UZ/#g;wafH+a*<(al4Ghv} )1`8E9 _;i5Vg;T76aD %GO[,"(Wmv1)=1)wu Ll40c[J/1e^@3͖(ďjflL]K-̏NuwaNQܦf}x8[S$G_+UZ|Q3iAsڦh N6Z 3fH% T. \|dq$uѾ~d[Hr0ͦMXp~tfcI׬p `^ɑďCW9O>TC_p|o(ϧ ԙfWɊVAX|S4'ьu:JPMVβ9ETqyNfKm57GwMCa%`@|zD|M!h~Ӽ vO819QaZ[m 5BYu@ ,j5,h]2 [:T3eaHrL|z+m?=x oHk"6d 9؟hMX<ٰ:%>)a?0>-}%H_6D3E"/@OI;fO*>Cc_'֟^42Ŋ]-n+wuW =w͹hV+67&Vh*2.DJ=%㘞~ߌ;v; c)ƍp?ksRR[HXePx bJ+ e(8 `!@ɍtl&!^Y)6_tzO{V xwTʁWs6M:Hk=iYt"89s:0Ūon˲zhCL6 gmp ] 6!GiMQU,U6*++t+E@m@KiB`yQjK`L{FOD%!3zK40frS83f]>p{͉z8WN}]s O67K6; a#Z,X UcpRWf\ViDWĹ3mQk^N;MԻO8H!TGn  >cIKI30 A:"NV"?r󋍩c'C ύ%+3};V;K}$v\}e5 5E!)y֠ FRmrzy$Df߄w YFH X1$m"EOlL, 87DhEq3|Kyf& hfظ\k{piYQ,Mڛ4vz #U鷲6]/ۄpܶp}p[UWI,x7ㆿ.V]cDQ#}ʻ!v:1eyG` 3jzn``aPO\,K6>ڿ:/ѩXа5I]jRKBAD'i8J D7dsҴiYgKuPGQ՝SґĊ4܄XR38nۀ,:l:چXr놹-y#H9gr|b`UԀ?u?Kejᄆy'Y2KAĥ;S8.q}gUpx6vFn܈uB YIb7>l@S F݀ck:gM$C4@ŦqU{<͹o9~٤Cp!n,N`jnNe @Ҳ(w>o!6ܭ,2ޗzq41F-F׾P2X0JĨ*pD5T Ô_y9AxP}cL#z&gski2 C@KO,wG64fh2##;QE%]\&QKp-R'<$v(IA\( j1/Q{q&:iU{{|Ӟשֻ"F?!MJT\ FDbV.@ER1D 3W2u32 Bt}*o5n\;!mď/ )/[@Q eTSgmY4LxUPΜmJN";x{1]L;+UotfS't!W 3bJ_^=/5nLa0Ƌc@EIqlug*1tZNxISV{ %$ƛsr7<3"r`xAT\>3>}5 - !DHd W;s::,<$@9HYu-:OGjeW@mI?K?+`A(fI#曧տUtxza{nHjhB"@Izψ 3o.SO;{bP7iz *Yf|%,ƭ ^Hr\2@sơ`⌨&' j]Gɰ0F` m*be8w&\ ;5,x m1ep*.`;۳FpG}~ Iemۯ4tE*U2G" n()Yh#14sLe_1 ɞ~6oNض2;0r "h]stocЦEumvyģUЄB.m5)@O ~XaqZ0q6V]!v<,ssmU}Y:EI/=#no Nl;Zoi{$t2If }j`p7Y%X:5 ysb%Yx=[@$G'׭)>|hmJ1AHf5Xa"&2hcy1GEwrg2 9nӥ.$2=^{ocX:]*leotAPICCnΐexQfwnn_aTs_n9qR{'tR UAۀ^?тh}WЈ"ʩԩSt}`(^e.k^p-Ub[iÐẏ0VW6?j; D{NQ&9Hhu xScl/C 3< SL *iV 4':Qxk=l̶$;2F˧lZ.<~"l_$uq+/hE8,++AFNj J:6ļDopvj%,%d4m~oOvšhM zD;*ZUn~` M(xY{҅핏E:r焧Ͼ0Osx34 `LDTXcemQ肓2dUvjT+$ŬцMO3P{ц"$n}! 4C&D)l% ^^'XP t'O521 <>?ފ+$xjO{t ܙnKi&~u&=e*uV7V n`Il߬m Y}VP'b0hy4zJh_]ZfȉmyƩV&^1h:Ǝ FHل3c^]ѮF|NRz|1e2AsQ섺u0v^-/)^5S߁H_[P>'Ri@a#]Ηo Iv='ViyzY\=AxPXS/cVU^ފ&R#bqj$<&$vxW@FSDR xր<8#v@;y{xp +oq5Yհl:`tlvHNuB̓qzR6{X7N6Ϥƣx,JA2& ]HY) -ُlQ/ƍ t996Lʹ<zf $2{%kPYڷvD|kY+isa'4 m?1`<<_ofDvTpCPhwh`)1 ȭNiWmG׏&Zn)#O1) |eֈʅ摦_Jc:]vν .iW6C LlTBy-3 Q`0vDـeR{~g86W;{!yZ$/SR{F#˖5\ ľ#gZ{Y {b l70xoGTd ?=뉑ѦnR_Q&|\#uߖvDA઩m~،vHT%v)i# OM^,_q-3׸ I,N9]te!-0V[6d,ۑT=@p >@~0wl2](EN~eʼnAi!wEbG"k/J&&%_/rJO>1AX7Ph]*14m'$jwX21?I}8AC9g(pow)~)uԩ íǥp Xlp%g\vYQNA1Oٳ lw¬/ei/Zo`??sPSۛRA>Ḑ_@hP߃$HOvDв{"a!}>SQI9~̪$>u@J9 HU('K^?  vnB~D2IeUimLT> IӮ&SwSVX*iƙ'W1ơ ï[y]8X毪+4FZm*]uv1PBK>}zB=r:ro'&ٰhLހ5=Q$NuË~o4c/ޟrLR85Ō,֓4 Z 6vMẄ́*8Y k-lCU) c2s'G^y3d+SVAi^rDiOfhuH\k/$%e̹Y*R7fEoX*X@@ L+ 6XH=[z ץbu}l%Y um.H^&4俴iR!)2PmTexu&6T+R&[aln=4"%[A&6N|WY>: /u޿/eAZ$PoԟF9J\ APC%?E, WU;"ux';X9 Ne%ѓg, o0atգRT|ha:UoDvG mo}G #!1+Z4"9v%oC D]&&Bۥ&܀DI-%FG0e n:'f֧6Нt,`.͹B iis2ZVێ'0 DM.Y,$ξ~|c^YDkv2_N H"D`g~Ϭ >^2+ ˈAZ} bl#FY0Fd»U3Ҫ̞x ۑrZЇ!t ?hT2EJbqtv/qx^,xIKNJ/RP`CFcdbY*Zi bQ.ϖRSnV \d:eLɧfXF <-㶔ӈ>x yaz'7B;AUM>&K)-%-?Hm7_~ޣPmǚ'u\f SQ$JBjL ݕ|/XZł+'%54ƭeuo*d i$ ?|C@tWiؼTRl @9ʫpEnէjT#'V9)lu&/sҎN{OUz[Eg^5#絏nK(X?qT@K5Ѵf#6e{s0$7*.b#LA1gMD 7ʧ& 筕|/ҠQW>uUFc2[#K˶ܤS}RF˴1]c 9qvOuzѕq|}!IN m&hء1,@zU^맢NL.GWs'18 0F.,Ot$2 IȐ]AWj_>Oِmw^3S-3pxYP64qʚGB'Tbuw80[ꊹ* otn5V>zuī/uUk$=:=!Zy x[i_b*U E`x3:ma1Gɿnf1NqBQ2B_Rp*ćf5tt!y_ *U}hY_gT6TX?gBmU$TB f\(e.*_&l" GLE`Oaa}s8 MT/EN,w 4)hHn%4a%^hF.; >#8 ҳ`130@Hj֘T 8(N;ɝ 8K$G]j(b*w|:稽 м:2:/m Si'JqĪ6 raξ:c<.DTnwս "?!i%7|9GN k`GC(b0!9T*,}xy0CYϭ߅PBog 9gI˄I՞Њ*jUƪJ1!UI#$F^%w!VM xB6Q z|!J7Q1z /*t^.xiY`oQ%~SYe%4,h#ƛFP&S4hY_r{РyDsip]a %3b[Sޛ܍/EY Nx_|k?HTGO@Y(h*rYU~'G)d(^4FD-8N%`~JI hIde;BJ?$NRXw3a%å?; ^h8TyMof-'hfnk~-|  Sd_j_9#&@SN,8`D%]f}8Ad1ڻ؛@SEK=#D,)Qon}Ƹ.y߆'43GFoV`@h_ s52o]i(L J8$]kIJoڞ2:MgF É^|#t5RI~G%b%EG_قvX0nOkŴ}ԏ/ds7YƙR~PrK(C01cu"3[qId k@l{YݎFV[LK d~qcA27Kl򡥼I%+v'@@LPIqXt@zͅ h4+F"ۋYjѭ2TcV0Hյdad @Q#zW8a`u*_cUpX2{a<2XɰI4KGPqlW$7 nSxA4(#,;-Apnvta w|rm=2@a7NW5po;3 `ɷM{.<p1ǰ*gs>s{a<-#j} _B],;FNB򕂩Q#f0~l5H+nvr?MfhG Q-STM`Ngjݢ!93[uA4g||!#_;FGȍ8;\BY̗aT ? Ϝ^8X icۉg]b7:`MT3Spm҅?!ktCu7 >Vu֢=O  0⻺ail ֍MHٖ>5tE0U"ٝ?T7 2Cs}j7 Dbȏѫ>J ?>hA2QhCMcɛt"e|0.pHv`TtHÆ:lM^sHxrDՉX}nK|%Kq,Z8|2 {ҭY^*dr;%;}0>2|@(MВ#tob V6UyM+&AlSuc-S9{?5,y>>9 d)Ԗu-7P   R5TLT0D[26|$I'MH;Lђ +#h %]f: :/q\rK,C43Yz]ieuXýKi:_pk&8fu.7+]]#t==Əi-DW̘Ek_Ǎj)tI=FdD%\ΠP3!,UH(eNP2tdpS騕f~F1b]x/M2M x3*T)|f'48Y)dz9 g#C*DڿUV#sBwܺ\ 5c(:#2 zݴXv8DoùE]o.P@7;*@X 8fQf>mBAU N ΐX]KNTj ?X 9yM:@e@.7VDi$g2H3D9S1 %6- f PtXVa* I$Q.E`#E֊m9Х*XL7TlUrRJ 4ɅED3L YSTil8Xs 8ܐw M?X Ldl0SYYXe, R#IJCiؾ>|: :I3OqbtIp!kYHQrmޢ_ Q*JHrGR(u6"$1e n̶k``j%918e{G PQxRe.?_VT53ׄ,h9"7P;3S D4fsZNKrw!*tnvF]eh\ >!ef;N>'qwUav<G-* cSǔ673%h͝==Œ8˚?Xwu v)<rqJw#XM #xI݀b}92ӦO<.HeLHYE+tQap؁x}Na9A3;CQ!sYgYʿ%߄8= aLp)]i"z Knkyjܶwh&%И9b]똮buCXp fZ"z̿FO,qV ^݋\c jL#_)[v4+nq|_?n rӽ;[ ).# n@-df** 8IJޗbJ&!dsd@'oK ^Y ZLVRkSQ]J?>'&Ĩ!8D?$5riټ8n\H|܀9[ӽ\̘ۤMd㜲utŖT}_x@@nxqNd/ҎHYdҼ0Io֙4lP=U sz[>hHƏ; a Myց)oB"y"k{RC,=aGaqI w@ ϥ}pv}Rbp=I$qY{ />n $= #1<)/Oc9fuo3?ceDz;qN`N)}w/ e4r%_-Z#KymY6M|QI̲:=Y 2LhёaŤC7m1iYC1jKhMLuYh 6dߝE SjEkD KI`Y=Uf)>AY ` fn(/ Y ;j#FA0T )#w>Cu\Megk ~IY-l7` ":sȹר*,ul*6ԏ!$b&3c3 gΝݒxgGp kb58LqYtǡS?ؒ`6BF2w^lx>U"5iuHW^C297ZKV~{Y@U6MFoEed BN}%Cߧ1K6"9u SLaU㑋T {gѪVjl,VDdi7ZD/1Xwh,߷ϖ;b\ ĥJt[YEMRO ""V^/ы&q\ա[DI\7ĴKPÔuBAr_wW)مH?ԥe JʄH׍*_.c}ᄄ̋]s<eM\$.K&mҧy2|%IYכ? %'iSJW![X 6g.d5ljjZ&abw6S n1cbp,ԑ))Qh{6$m,}{˴7&D3 M-#=*@ڡ؟ebCF'd1Yz=pmYYW1sUx3/UEa?4ma!*8sɝ)ttk_pgPF0X@.q}2 wGrp-Qͯ+?(uY+۵t K&',JyZ5,4WZ xNT!.PaP$G$ykI&|4(ɣ)-NEW|UlYő |ci7ӄ@F"~>+ |h`e+iöQO] sԎnHGXHҌPYec;C܁s=ekZVA8m|X0LNLM4j eڲEhqGns#>O61ˍK!./o2zcp'_!&b1zpk|*+ PR}RmHLHwdHs@K<F0O5q24"֓@ e;*bZ}7kj dgzg[iNLԁ *( G C'U/NFR-Uj$Pž , ʾ_rC{]3>*g6LKe8l |Hh菝cͮ\ÏM{Y`x^ۀQ`]ƨNUeeV>T#D]I\R:)| 6ϚRw jhfnDICKC [GM "XL#?e*:6̪&4O›BVSg1{(@l#W3Z5Q(o%ȏe"!h8'f@J%EjښYxCVRL]qcV4͌o>a;m:Sҧ܍"˰SH 3~Q6HJ$vߺDHN+ [^}U¬Ro z"l6{|1ݍ dG)5C_]12[bxиQ෍tYkmI0pL%E=F!L؉/= 8ܥʱ]uK3ɷȍz!>! {[<_5>P<8Pؠۚ/YCxBa&{m ];hY@Lo;2 34`L:r5,&Ѓ.bA_;`\jWVTrލ r&cBώyD~ W!J@[jfmqqBJF~2smv{&=Frp93zTPE9 h ,hKR]!cLKUit\Z͕+/aF3DXX>ϡiH&eׄ:b I: N:|jEh85][xm7ё~ ױZ/beɟKWF1 @S48"qVA̧99ް;s4Ff٢f_ tYͮ5N.zF}?}y;Qy@߷顎tZ /` 6m-`BGB*)ZqrdNr+cEyz!gS|3"$ ѭ u Ǥ)MFwV^498 $K`߳CsSDõ)%b8;9؀1޷ܸ㼕AL*YF=Н72gEe-3`=(mDgl䣞rY|,}TF֦8-1QӢ {9]+~5uF   է|UW ]˂A#G0ۦ﨧n6#"qf '%k_.I(A "'l}FȂx@N9ph.S:fY8Vq mo5 eS7}9A>1=\Wk1K"B崔#|FK4!>fHq'AYS2F#|Ɂ{瑳5d<_ߏ"{Q6qMI9ziB^^Q>- $nO9_c E!)u9KjeH WzH?bC{{)5rSvSl|zQ_)Ibֽ:L$`?KųW|V)T[ dM9@mR<0!:u]V“5߃`NZtc(1SmEYZ0hC@GeRweN +l܂R "/$l$5U<՗vGY4-"U8FNL; I|F)A3$7e[j DR?( KZZsOq.tMスϸP#h k(Չ~ &X0TW)![c}rȷZ@FFCrNv[dS4n.&7(PkH =hG` ^D N&_7 Ÿ% 'jAdjXYz4p,{q3[b(3(Xe kGL )b)oS h啫ćc0c;_:1pe]3DHQi">[`$n^+喇pPܔΝ;܍CُO=9 d#E#Rރ^w%׊!156 ׭ k}8nFD%SZ[>ծɔc1 s>E m F6Γ!Q2aF@]:Ϗhz΀eDTiew(W}#2ͪΰy|o!Y_x C QP`j[;0E|NH?z NTj?IdN ZI! jwI[siL6blZg@OgƐ4#Uً\V5xtZY@`՗ފz(yv]@Zd8..V^gd$&c&*.+OG9Ao{XUw2 9q rf0XԫBB QATrb)^vHxf8[E:v~sr)!V~?4abZ2Jךj 'zwݣӴVOH$]TĴSfz1?N@_pu oA2ڡ<~H qʖE!D UUt./ j";CWl!Cq(F CP3kѱS-7\}k4$&FԞqز2{ M1I´9hiE(iHտ`r!༩g'O*;2u!+4a(v'/ޞ_YcZ0T+S᷁ l7qlt V$ #^R`0|_ܜGdJr]g@ՂʷTl @Rߓ :#.lkڐz0M w__x&4J>)9QuJ *ST_1 ]H[}*BGq&c5GmՍb$56#kUP܍VetPH3]QTtNq^Ww'F] b?|'MTŎ 'uX3=nJI?\t3 @%p WP >0ѴN wS"'4! vs* WUӑ$`5NPhr"r 4;eʰH1|@à,3Ҡ_t _}UV!&v۽jR* d_H61\QE儂8Zm?U!n}p_ `4_40*-Syļ%?To`.Ӷ@O˄?q0I'2;`[0 X,r#^glOF]w}5B\ASN.Ҏxm06wnZJM64'dTuw`[WDwwrZ,6P:4$$.Ḝ¤ٕØLq}:1떹RϾq7÷hp~WBE=7fcV>kZπL|^H"?s=`c~ߧ6J-u)[t{<[KRnctMو 8'uZ601s]o1--=J|Xz{}HlUW L?C42'ߪ09PS?:bȓ;5BFt^I)9oȶ?!}hLT?91[sJKǡyQ1#{az{79lozFnGJ[WyZ ߭M*Upes"|b/5ע S<ܷm? 3 MxB7&~F1VB=?`M,OMbNqC+>mbsTU&Rߣ$uOQ,k&NDEtaAG( rm ^K& E7(Q*BSTzMgJa3[ <)iI4A|GWYt-LV& qM(10ujw5/h μM9ҁlew,X @9 ԛj{" Y?dy>*xq64*Na,FJ~ DߺvoO咭yn ( 3/Ux$}2GM'wZ%Mn|#tN%/E qMxw( -9oX8.l޲&̙m;a%ÚpGOЅi0A7«wBEr!\hX{ýnxޮ/q%͆lZA`mT(h%j UUMc !9_V&CKۭDi~`<93T[,1 YA7oM_1 9 -ni vH:zDX<<#F0NC^\z$8ZH!s%j7L#x`;R2W [,9ޡTΤ+V~q8ϝP7шWUY$$%) ++Ndb{ҿ~jd 1WA܁׷;Y{."|s;s+:`[xƦI5@X Xv0^UX)<.~o}7_KTa"#6PАou0󕭿 PmTZ)FݹTGiܲĭ~F>Sl],"Uu?8Z:_.ߚy9\3hٙ&Y9ޞ聰|S OS1CVd[ʉ9yoyA$y ;뤧hXށL8UH]A[]58}"L._@pj9Gn]71p]c ѹS~JLY;BBrؿ9 R57 gYF@7w)ꭞae~0h&*R,1Pioʞ C/)ryVWEN bORZWM$o/ktР5AC;DMRynS9ʼ^xi[oL޼>>ܸpN1{1E۳ab H^\wU%&bLjkɩZ壕=I~>GNh3u.P O}yB]б:ghgN\f+'$,O -d.GzSgC56\vVTGg{g1^_WNQBPUލZ# 2Չw>Lx?--I+ङno9搴9@Ledj\P7UwDs5fpĘ 876Q_ Bxgv>XgvL8%l1v eJ!"Eh@8:[oᄈJvIɲϺG7H#,=AeXF*6ro֕G^Nmɱa0Vs?4gLreWRQwDL>S69UϛR2NXS#&!Q|x59| C`0C u͠+%zۿz4mBnK_9/-iP}kCe\_p7G7` r-Ekf0#3h(ˌ Rw1URxwvG1Vis[ 6_t(l!ޒ^|l߂ͻ е/'UC* QqK?::)ҍ"uW/=u{_ޔɇx p\g@Wٙ!ɻ+Կ]%"mW=_pi,ڃ@rzTvFQ[]iZ0p6"$Dk ҹiX$ےGHvEŀAh`fPE?'yjbG;w!#^ t[Jú\XLrYDϱ y%tc /V|m3(+EV} -czk`O> ]d\ZS-E,K0$#c(SӖTƉQ#BvC" 'Nwj$(v YZw$aKBKHC?Yv:; rYH>Zx!l"тČ3=$A\K*D-0f~ Js׷Fbуv ΨձGPvxԘA/tny:+?'WeDqw]aMܧ|N1 }Ks Fu[+ƭ;`FȜ95.\ŐpZwH*yLf؜6M'_yݑjN3ݢWLeao7"˭M-s]04"@˜ CILS-qB~Xl_Z|=m¥7UO'Xu, 5_\N FVwBԴ"B8ʣØ*+$ ܶf,uuD9̩>FJ'|r8"xtl-CA{O[/HUJ&@g0Wtj K QI@j{M7TokW/,> Nj(= y  TUnhDWF37d: :|{YknEk3NWoIr%XNT4kYoxHX"N&wVN Fq AbUs]i E5ܰŗ~.b.L8ggSm{_X w8CբyVNvR+zV b/yf,ty`qB.9[F#~!Z3vuԙtKl$%9 OOtʼn둺ԗh-1x=f9[NSwV .PEEN@@ȇK^aPyrCդZG4^wY:ga2q[nOL\.;j|sX:{ۓ XPA4W b;jnYMݭD\ g<ѓ-0m Z;럅V8e┫| g45&PrJ|6&%4BSKNR6N 3,nE9YXC-5pVpek#Z׽~]hPv.s&Au<,= B6r0UJr¦_zwWՇ_Ysyǡ_m3S14/AIϰs_b}q DNt)aSWbBcxGE _HJ.tn{6Ns7 gt^ O}y kOM^0Jv)Ll^:k}q ;[ ]^jWR aU# vr1B1CG՚2}Da%w*>CIȴ0Q<<a.l>IO(jw%T~@uilIAr&7WO3}Nmc1b aYO:᠀_fT KZe5Qn̬JZZX7*;;U3aY 2ude1ȺI'U_1w9AQ *$[e5J3C6Dj w /8Ǧ rT~ kj"P8 m)PISvBE9ޙWaUrdp7Pf;]pXWHfƤx\zjr=USJ iqtS^uκ"L[EOIB$^lqJ 12 JZn_]iq_C̻8y W$A#޽!:hcX 60Lf36cWGxrX.IK5 Ix_ C㘏חB2dѳJAyy4j= uqu_m*|_ 4Nd̾:V<7/c:Y5$/Zl'H84eFV!jqm:ᓔ@z:W zκՀa,NrLA+uǘ0UU. .ea69 6қ,lͧ 7IF[*rwUqzJJ8oR$PG'S7(·"ʶgH ٫}"B,aX HE>6ĚgݶSRw7LZߠYTj٭xmwA1dp1 耇+(2^ԃ7/T^tЮ'Y;*;UiD52~*-4֡A\9 xB' %jF8i"}k>*]g-'O;?yp2AnX6B +fD |@ :,e &8Z>kվly f4]˳>вyiA1W %8܆ ~DeL]<@->l˝?I+ssJrh޸߹Et TzIyt}uL?=tXz8FYB;)q'qdڥ[bs+nZ-LBn{ΒlZD!^_^PHD .Px:uM:PT H9,  cB,x=jZai& r_YF)z^:$d]"C6C3WeYjṏ}>oPbe溄@w2vK'*xhF[bN*괺KHAv | _P?aaHd^o{o5*}˼:jsaQV٨TKgrt `(gU( = Wz0o#,4A' ^REtH x45]mnٌD֩lxHܖٰ7q[-*5t|:9ˠRE-oj?:p ݫ!h,.MA=GS-H }4YǮ!P] 5,qV6HHR+?r ٽc wNֳϬ;DCl#Z\̻/Ͼwzb'q )Oy)^KeY֕D-"o^>#cb+o/nOC=E[a0iW%H5XpIֈNM՜w}mYdbH S4qKIlbWȔAtAu:vYA$!TZHY gLmja]ؙ x5NyTڑ:$>y,n5z\Ћ-kb)}[{ҵrDkPU a#M<"J o}fj@F%is;O!,<1"UMAuJ"`w (U{PeU$%9T9"kȠ־3xq=C[¡XUp(w/}kS߼8qyC[\Xv_`$` *1 *ա1 m̮_-!Y}ҙMp A\##\|f?@1iRz!@u,Yj;X2o(uYw$7 \MR kЉ1r 9%V=q엯w-ZK+=ҝ *D\v>>`P b6,`k&8qˢbc`uVü&ZvqLЯ;0=S틟(Nil'}AH>]ǝQboO9F8uP1ߪG.* Alv GLqKZh89[)Q9;e̷NSZ>H[Ӫdn\-Եc0tfN@aa=_'pT^EuwY]ʞYtHY]wt7Cc /h*<`K B#%"V7dO P^-8cb>sӶnNtؔפW+ >4y2+TdinopO>GQD|.U@~|_JYGF.)͈^hRx6C%np|Q Bq Gk sCi>2SZ4)˛sLjßo Adi[ n3nt80fƆSoE/ׄ~@h}aR%9thnPӧ8JzךɻU oY]OD vHeP_D\}@ prk}8CdCq52w >6$;1WW*xņCH(P@fFXq8C@|-F3]TUw3dM* >A$04 it8v}*i8:SlT㣪jiQK Ro2ͲY )QG0@o9U"ñ\C b)Ӎ/ T >j ݀v+D/vν-΄dADeEh"G!8Z_{!JJk~m>"JEy]O#֟8ld$=t0i\5)?~Z%ړ# 4~4 Y5 Ío*$$m;n0\{]~2i>|(hNO9IޢMro*_$5/i4X)Mm:v\[[}<=UFzp b% ( ֈKCU=7k~ۢa7iyY;"LTV;)F420s] b+ɑ>}&۩r>G+i2/Q=q) ȺR>dbPqzUYgwoC`.ϨX[aĠbc JwmU b"=9WF3WԱ|zt OIz%|et:kP d²W-O+uWMmű ׭Mю噞\|9"Y/WU5*&5fllo튖÷QU?[hVZɌBYR~Mw{Gq' ӈ>v/+XQ wr'"Խbs6;)Utƴxs^pIbM9ˁ%*8N-`E9?cZw9`Yĉ_Tu{cF}6'jȆ Q_\;a VC8 kRoq^1hїzUE.ؿ9ˉ*.wE4͇+ozṼ&K]%UX!N_U[KǙȀdmRw L"MPus0FD{v vu2n~b:O7mo D g(ܹAo_'v;%˹³)rG Ŗ-Nw ;218)R2sx i' Ѐ 7-?6Rʦ/0!'a9Th8?8klނEr1Kx`FAVR Zs}ۮkU90c_0J؍kfk"8#CR\΄k_>whDupx Hy @qY.5Ѱ3@NdÃ*yVdE X43G2C+R"F6M87Ԗ`A6[ӯQ(z6̖icg%$P{W|k,a~$ȒrZ Ee;A C0R]gos%(!+4gmM^pօmӈ9$ٷSoRj<4k5PXζ膨aZB-=ea)  8q ]8Y2Rdx[T!eO_0U~Xr>[\ꓘ[C.;Ю1HRDkiɰGg^t'~KdZurWE{{wXa)U2v#{XQCF<{l*"y jw[xˆEN3T,z| ?d ;հ'tގ (m|Oc7Os凖؂h% e͖*1fd &U/U])1ȵ/֓T s\dMI8d*K#Z{̩ c'h[VܘJ`pD%XK4y݋>idz)r e1֡kװBĒ% xp%,sF<4꒿i@64.I\9mJlB+"& :_4ZQDwe%9:>)d"l#*?;kf"ZZb}蕀9NĽ@|O1!00I\ZA 5fE^.EJob#>?i(SH,Y#BL+% ٥Ju]c h!^#u/ڂc_cE#a+Y"W܋Q̎ZJGloVPć >Lјf+Zxpc/3;ДpY:(lp45FDZB3^)K1e^+y\Bd1i_Zp .#B_.:D*G$ږTnPGtP06Ll+qF7(d6IUs3#`]go.ځ:Ҿ&pʶ=дU g4ɤ},Slڔqؚ_ˬ@[Ԇg :m\yu:1,14!C]9a ]]ՈupP˘,ްϗKet υ᳨P,.٤ϑ0+̚SZAd]˝qpP6>T TM m FWF;aj kP=D_oΔX;*uV^?dW~S5cGOEGK`:fŢ2T5YgͰabAi^#w!}4;_-3rAuYd{p ~ 76XKdWJ9c`9~7#Х7ƥ4^ ߋ^z1eTɣ~F0c[SP\חR__TT2/䀰l+ ]qZ/8 ?CfՒWtUo uEP$PdvR.]VA)G+ISGyG/o+C&?wz_kw>lٷ% Ag5MθZތ2XŖP[E'2 "F!9x+K'29*ҾĂCR#߷peXZp-l l )<;aiJFR>*d?HpԋXd\ ~\n},/ 6X`jGl]rlK>hᨏ]߸YNMExct3cm]vlIan'ە$} ;.3 bO{dAdu|$>jN5&hC`,ˢ܉D׹{ADb7τh^8<ZlRƤB5Ia].  픙;NH$# .V 9?USY`n`ZɅYeȳ2V0"ifI(fA]i /αMz2rp J (Y]QN],'SܳeHf(jR#L`B{k%< So;^βxArA;[!,Q^sנ)-gO/?v%n3tt)O vkgp[I~,F.iuVhi `xrJ(!jsK&eF<5۱8㬒#kETCF1tfx'p / `j'T(9J}yJ. 'j&N9B5 Cab7T2Pf1mzC bjr 8Rs*P rYE*+{Y5f'Lam<m}aݒm+hPўСEAP7 Ux;uOηOEYSЀs*ӛ-=H贔YhsP.m/$ŠD;4C:wNgZM4isrb{O]OlN6|*_yDNf$b`)kjKv~H<ĀnQ>!  ~.F?l Sq>˪rb9 PҫI܏4.E،nlk:Zޟ `ON Wa~[4q?vh`T ?o$-a~ э:äO.ÿtjJ7Ymo3\.KjC/)=D!6eo|·+(kEA#w1.h$E>9cjU}|'ܲWd$XEr&/B61 UsAHPбwb>Sͺ/0LLp7ΡQJ܈=ñTyZkAYU`m}?mBձ{I PaK$[̇2 7k/s̜:+7{u[DT":Ѧ늑FtŞ]W,1j,oeplxw{V2vTn/B35ỀMr|@׾vu|νw\у dt~} 9[$$ v?wݤ)1ڰі-:$Jo5N2'&:3Ndg_%Jø+0 񭮅 û\dUp e=OJls)~,uՌEbGpjHp5/]gkԞ"_03'Hb*4hz 3Tf'=ٗ/ #: 4L'3W"o/D@Iۼ:`(7㾻QJIL]sb1.s#mX)n{Qd- ~|y0j4.9I4}UL3QVoħ%XuhMU/G `qt6Uwb9ZZb?~UKHHA 4%4oVK3h0ߥ!0uT?f FfS5&pP혍Y Y,w"%Qk+dx(aQL~С&joWXWn@CT!DNseZp` Bdrq/LAa)z # N1P &K QqL'!ջ f qÛL=s:Qu_]2OY$2YBG MC{s &{dOu mVؙlsV+ڥ=TAԸ 8۬|&8# V1珉 ஆJODbNNRPJ"2USyeMnWH:k7vV窢r?4zA ߭,.IіvU?A^ N2Fm~*nYWA]rkOwf{ots 0{.ͪ@5^SL2J@'"d>pɔLՄ%^14[0uw9ɏ^>k;"ǖ[2ԁ}t=:1Yhz]d#b;m{[yG.:!jĔEʡ3g"m J8a֧*Qۈ*j`ɣHkR0Ό}흗wͯ5 @4AA awW&ͦ :`_qm؃Bò_K0[z~L5/nЩ5 ÈP^3Erģ, ARD7poyz<>56MyxtU-*e((Nm謐:7}d?𽷭m!t9.r@5߭bEj,NmӐōdm^3Gf>A.( h*yki $>dpkYu2(JP&K>V3uDhME{1*猸~DfO9h!*@uݕ0Y&ZjNSWő;11 D% SFu]tCo."N,JF$:-# @«H!y?JO0s$ [{2!% QHrgK]6edQ7h?W2͉Fbd۬<͵4fXVG^[ #.~!7JB8rmu߬oGuۆIL\m10^t`;OKzzx UDty)0-jM^pi5ll|DhB։{Iyگ6u\^ x-I>ETA.4%z6~HᔖUyPH&l7"Lߔ @xwB_ ikN3hlǥa,p!_qKP>+|bǾa{[@L`.+}ǣȓ]='E:p#:BΙGg*E{֊+?GQr"s-Mߊl ]kDBzn1-0]5z+He{jLh\xhcVV<^`E? Ҋ^<).]`/6+{XÇr;4E}ᙩDrNcl&G=S5[W4@ٚ_yJqմ]E&>{W>7~DRcȳpHQ 6v!GH/H;\k9,Y?F}mY;D!96fws8D'SYV6rT8TM=w{IAX0ƷjSL\1$tIܽe~̕qnW~NkLS|r+ڪ%0pe*r4)i  3?L9lފ|rR,BC0r?aI5s{Bj;^ B3ll]6Zİ 2nkhLQLI=_Pw:XZH9æA^M@g@4~F'jݱ5ϧ.`׵[7 VkۚQ1:ӏݛg}U+[]:$3ݾχsg  oQtk?I%J Hjd9Z*ڃ.-U]$N?kQXg:$a /-D<`GVXQ\뗛,i6ڨP\)ñc,c,Gv+B7w?5yc}P|!۔a|@)(?v)YXxn~mV!X&?yj*bX=a)N]= +!s,N&= 'a%1u& RWP+_:[/!:yv%A^TΚ~/XBʥQdmI]B!$ s;`k4: uitFJ4]v3J*uxIaL"9ՙ5qȰ:YotƦz9[vV`MƗ` xt C?J~xdx3'򾐒zk]B9<6C _F2ō$E b]vnM65?k*荨,~1AUoMBZR7&+dpgɲB&3kwlQj1BFh? JqD_-*I  xQ0,[ NNɟ7P֥ xNNRf_=1*$n@X_'P,>6Z+?1ۆپA?#F z+EmZ~+̞#6{*6`YQ0 ZMdg5H%4ls+=\QZ?c)*!/Z&Ӛa&^1fe>q*+8zqe>)OyEu4کF)z X8-t/X&"jNAhBVg-X–:B3BR ?r|OI'0R%1ʥkeHYLjv| yxE8C䓯vVǩȎevEB>@'}WC[RT-u# k~MQVӜ,68h`w8 ȣŽ\QgSޓ" .76ix ijL8թjΞ3Y2mH jKa t҉XYԖ[H-j*Il4)ulj(_S=ƀt*ABs%]IFR#ȩZ|;r.gOC 9o&.{VR1Ǜ;k_~n \XsD$Ͷ6*Cp=&d{7M?[8cvso܌_ s^jFq%08>@g(}*Vx/tj $'Ż-`WEQaj}{+X%bmKe,|x|KJp%U$pE9i&nҖ8j 2 m2ray,A¥ZRԯԿJq#0Ĥ0nJy)K7g~ZkKHU\A: x$E™Kcp>o,}f6e^!C~s x2`#,`:\>a6{P!tII g^ &ipDN T5))_IEdʷּt'$x f'?l!4OIm򖗿 kL<9=E;2R%1i $|V<(dm"><Ӗ/yg "{ǀ<$<x%'v{/>+MɁ'ˠ@#X/,w74õ*ʋcFY4~S6xS ga[ǡG YsW?k:*Oe/&# 0FhNk%U;SWs8QȊ/vJv?2 Eew.@FlgA`arU ̢kIu.4k;ߩ'aoe#jDOS)Uu5ܨ%碴NQ*G4$ (m5~xf=ǟ]MRȤ9TqIl (_Cfs݆k& 6YV/;f_{7P/x~ ~\mQBx:X)u!JPbxCmkd2Q#RgAzz̳V -xĠ=i x4Zx. yGg117i9"4/y#5k2B `#(1% qj)LzRw0{CĄC>tx$\,P=Սsrv9p'8PjZwcb"/L^!|B,mV riuÃR:t3BfnɃJ ^۫]]Pe"lHU8w<#] }ڨi=Q&vKl 86'B`>r~էN\T4\F9RԘjJ֌j B(,S!sgksM3eQI#DW@bW)rkKVv 7gѨUdomRm/|:]ޱ@L݃|vЦCϤXֺᳰK' j@m\Hi2^I"R'TIayVg>T׭؋nsRD̂vF<)=s3 f>_t%NA~t~*LS,qmR,Ds0 lαc=.|[]ϑOȸ*yO?lA\ ;[Zݑ_P/lE+#u=ɽ/։Lq2s!rۈ ʉ4QtNuyg:ILeO,C&4RZ-vgnK<4@:))>hWف^*j( w'L-!Hf` fNW},[hX_gvq{兗7J\=}eؼ1%"cW>B, _P[1:n<Lg; ʻ&ss|N"Gus˸GEV|mz> o[bNcj;mIJҔ/ʌϮ}2 s'ZwU#5]ߝѣeGU%U <{Qܽ0(2th<]idKݙY _|cڹ:Q)83n#.T2Ͱ3ɦv7wV03)PT1x]r~EX󾌕> 10("ϵfXAq: SzFUkTyќZY_1#l,ʯbT4bN@䜚MnV0@}n=6Ĉ++KT3~%7#;=}[ypv*6A1^͏t9s;&+Wޝ@RZ.uOHX@s}3o':C!ٴNSua\Z~I;4ӬOduI1y!ܨ]|IKÃ_Yv+].p7gDT5'7+b ~BE0SS^x/U@J6 ^/¬A}b|hS_Ypy{$4,8N}$x⮧D^L:<$~F<`uV$hxz¢FP4(_?dR _g!5P({=:hͪL>X:{nGc+m@Y[ ԳJvQȁ.oǦC.gΡ'_,-/-bki_"N7:/tn~y9޸ObD:O(LlOÇ(fV0+N 3iن7m8d7~AoiBC)6TJRlʔeCd48P{=WX E-IZD|8MTN7sl0 W)t?~GG/q:@vym&)P8 ږX)c^.Og D Z<)ݨD9reu6,mҰt#HNt:L[dKK (ԴYڳp[k 1cN!{ګ| DVV܊251mBWK{,qxa=j5Grfu9fܝS?v^KUzԪKwbB#}<'{WZ#\3lXpG5FW(s(g#b%Z /N{AbjU٧Ӗn0:[Qԑ{pf<$ n"iꐤgq:/٤zc]=!gQ.f}!J: ԞO ?F4^,R% ,`nSǰR9`16E? ?4"LnЏw5ōy^o~Ș1/F@Dآ@Nl:^~Q|mKL^DwTj!ZEj' W"t7h1vĠlT5#X\Z!6OBHcsC%mN s9Q# aKA?*Y:g MXf#Q߆b\y'ZUiEq8+D~ǷGC 1MϜ4GoΛ-F"c mōokqcn:F xNrey 4j9G梄K!G׏b~^JMzLGyމ< Z5dT[}l&,%gcd_S^+@6Ϙhi&gJ;;fLNxͣI4iJ!+)ˎTO2z>zo6rUW=Ci ڃtd)EkwW4Lg>dwESQD<Е*U"yt9l;P ~ui2h9D GlhYsGVp+qű@w5; S#W4(@;8}bi,I|TqZZ3Tԣ+].K*GЈZ^ : 3mҺ璻^9m2Z 6Wb $#.YT_뀮Ywt}|L:NVy¥gAܴ[Δkk >=B @ѺH:oXeo{}Oz/\:; F /OPX6` mЈRX+^//d,|o!HI-56Cf2 +D.La3l5B\' ( g="%wb@x: @ʎk~إSr^Zhieah(ժa*Ss^l%ID2#g2Qﳡ&տ7;WGjMeɬ:,+qwI)]6:Yw]9;`S_ \)1ڠJU/UW 僴ԇV,PD2n@fȭ\1mkpO|Te`k\فp>;D-pgгM4qSt b {Q='}KnA(k-gv$j 5;-%Oҡޝ,ۿ1FP[QE(]ĵ /"ޯnoڤp_%_ +B w•o2X'ԸΘ~ HTN }l8 Fd(Hf]2~{+=ŕxW|w[V;ȅ$Vӓ475yi(/H`S ) tӷRbI|ji= R> 9V{ˑOĔ164Ε"oUukb܃2&1$ؚw{fJvd b| ksXrs Cu%wЖ=,*.VXٓHڅM`w/Fr-EqT3{:wEڲ7f_!t~*$@bHmYpmm0MgI `k A%[B.uI 1iJ#B%VHa$ئ]%aqxڣbЁXZ|l{u>c#MR:b+cL >Hx,[Xiٝӛvy6'>K^R&y'{WNAHe?ķۧ5Zz}BWmN؈M3t`0 Giv/ $$+fgձJ8ًsPQ85k\LT`Yyr߱Mgͭ٤DeSE9iϖ'8] &1v߯M1›{0ڲvIlDqy3[K2:߆VE0's䖑G|Z3AfD @*e<.8@ɚ~Σ8CcNt=Dd- uaKNq#1Ĩ줁s9[%Ԡ [\CկC>9%`{f6KE{)mA.>]ĒnL2:nABckE**w ovJ}r4 vzQ.EۃT,Viy|]]h;-zp}w@Wsjw{eV v~a@,T0{|<h<ʞgF}y^ "ig%XYEQ,i -ڍ1:#_6Gi5Rk.G&X EMintm"ReuyI%6->GGHN,`^:A@8m":?lB qJycnns^Eo[  +2(.WQCM:þC7}V5^=0b-ٚDY4(wfm94YtOSh? .ZP;̐dSRKwFɜq)ą*ϝűս xoIge) v' ۡ9jkRmC h J7t$Ah&a^sszlI"|цHa}gOf I<|$ И0%g WލtK UЯ50 e2uqVKpL!l[j>Aw0tmocp4L#B{t %^LF6U߂#f 'nc.>rpZrV0\29EKB\¸jm tUmc|4x 6,]^$+E=LOWcC[^ }wK..@K dzeW}7ː_6&QG2#݃,\@,wl9BDv5ʮ H+.1CGn7}SNhb,2iJ~{MXe}[8H(Ehkiv| T4f_t\<ï>Ql?\RjN@SyP^h* XBQ.[[gMLNu|}G᪁XFFGJ{ LosB9\!+bG2nb蘖f"'XĢ U<-x5 f4sGgtu(a3«F/;i@efBB2].pLv؂oz^UsN&E*aʆ>-yzJß -߃ i*y?vsAJLJ.Vz݋jCJgs뎳9he?gpW▭pL8[x8\KE&쮛|mVz&W#YCt Ze|? qmͣyBvŻ u5jI_l#a4 wyw|]h* 'BWon1O^8Yb;ԮEz+5 %."y}X@.):n@QG.Iy0>mp@n!m! ʌ]01L~Fp [ʬCxaȨy/>\9cwuV\yρ*R_K#Tp.a8]mdǤUX/Uc"VuQ2ͤܒ"sEx@:@)tgD[~%t [424a{=ם7[L~ţo1QL<%WIYsppkcP+l#h u/Gp#ǿ%ɏ-:,c.BhHD6(3T ,ܰh,4,5 5ۣkzp}sUN8\8{ygR5><[/=_K oo) "(7> ]Jo|YXu,GV ,&DHCMlOI;B65F& 4vkKp^ApEA -U\$!E1dR1)wvJ$F K^ NzyKV/c'T^]Z#* =[jpYj$tX41: GOv"j֩ӐRf-0ͯ6u'()1M~,bLеM:Ë!J6*-u]T]*c>bVV9D:/|l٨zs$t&M3}šXHP$21b:wЀȄF"΀۵11|t"nBN2u at~#iv4/q[Y@3C kח|B*4髛ܝ: GTI1==ICtػ5V{g6{+d^w7 4t)^DӈDZ-wHάޚhX؍`,cōЈ *C r}vKA,6 N0po«&3HJkFQtKqk[ Ft sFrl:oDIF&aQ]ǚvI0ٚ|}vM?`hj&R<`r2^_~?Bz[^O-ࡵ9n0\ѵՏKU?y ͱ(X2V\)'G)߃\A&i~qH/T5~`Y;@^OɎ~*; : |C_5PwRAvoJa,Նm+_mrDJk, SjpLxO}+ǷAx2binYnFq"Qxt-Jw:9p{xw͆Ebϛ1i +<jMVuiyTR_MOy,F8\=5쒽r<5W4(W9?eC/rɿO%N]8N},#war]5I XA H^y#=~ɽ"4_ ƈֺXsMZIH90269p~D=_4E;M.3X͵1-q߆An2 v; ܊QuMJºdX0ϼ΁L.z58xIXa_+fMsP|z"szUA'Pc}i .~\3^ B'¿$w৪}Spkk aIaD149qꅩ_9H#k~&" '.\s۩QVMŗNbd `.T"Ei+LZ d1cO;:8:X$>qq7% n;Ztzo$g<.+5I|1Dsl0K1^68< ӢQ|8xWN!YG{m+H!UT,9+MvjT|.=d7M QEOJDRvZ :>\wor{]bb*# Lz=.y.Wd s R8Q4{%" ,IW]{KαҾe?KRR=4l[)C9x6>B 9&BKHiJpoB~ ( T2KKL)E4Ccpq=7ח/dY3nPc^Fe \z: 'Elfɍ~fLM^R`3$"{lBgrNS?>PSѰtƩ.o/L-}frJF=g̃ !,<)Y(ˁ[?chr`i;c01 \ tLBahsDA%V{/=]S8Ʒ@iKu]TtJfrև91,+}T؂G#.S jӧRo).z9ڻؙOqA__{22]5 cg.80z,/Ucm@H[ ÌA6ś%(}"[ `i}v5,q8b_e$)g1|:rlRqzvSLhJ4_c/yfsaO rOõϪo&_LUU> &TDox;Do$Z"p̛m@"cWQQzAÖhR"~0_$C,#׉ &52g47܌1*Ob]dAYA (%?].V:%#l瑣l@ "rXܕ-e0^YL!*]"BfMO% k@~! żhm'd>jAhiaTRWOV7,H|Rd%̓KUM5 v6bW_wldIB.`aN2T մs\gk>&iG J|/WA7R csp!Һq+Rty, R>NT>P;-=mv.~36N%/)^4ʼnADЎ v`mh:!#呉3[pt"ʁKȇV#ڔ( 8fjX6rvI~tsH5rVٛDP hh¶p%a#PR.%4_6`FQscq)Hj}ZT]WX^DOibtn[u;Cu\U_W;' oj#>=&@Pe|v'c^8[׹Xa3n]pDy-dLLJZsٮCPLC/O|[Q)jqWzIRzX:xͫ7սlptG/™0|P?9}| J9H5OC#5l &R}0iW[4F9(x5 р(u Áe%pQRPUK,K ,Gi]Kp?NT[mE!ֹwŖ5{@ovd&W*r{W=G]A, QHw`dW!_ Tj1wg٩0[УWVg en)BbqZ3Vڗ|Dp-XL܀' B݂-=cVfZ;D^zl"4߱ .֖'Kv@LĔ|@ݍHa\0{@rʌl> QeCmԭ'Kz <-QHLo lSE3zMeeʇ7 mKw ߓ9޶. p]gp!m]+^r].nos6\/Gҳmz3Yt E6yi\E %`TS, AeSC9Vg%vIx!-_Q12 n<ߐ ?bN{pJ.tao%ږ2J%n;h淴9f֣~ׁ񉚓XLNI_u<\ΝԞ|,vyt ITߣriܙ9!05k;>G&4L&Eo}ȬA6n`3D]Bd[\4 y5ԪG:@FSޑc lI_LIEG^",  f ZAV[,q" ԕf1B6x߶BkűQi.U_C%"͢d _bc]lKJJxō{@V(j_{Fy5t731lhHTdޤpDJsܢ0+(O,y4j 7_w#Vt9- 1f.DpgG4S7)8 .`[a pg(;a|kԞU95dSRP5 B2# Jv־dY2 a-/7Eo;*.PEMHCI+i@TmuP]g:Cjk͂v6=V R7%i4 ~1WJt!x*O9k0`\,W@o^XٝN ֜fYG.0"~#.qY~-LMrmڳ 1],:땑 4Dv Z\3?F$l~|kSzn~S3~~cXu>M?Uv(ޚ#Cn]Ա(At înh  ~nlN|ciŎ3G|`tg5~" x@nޅ*4"gUGssҏ4бXO]kp8gEDpP =Iԯ0aV-߮y iQa& >gS|-Wh+I+rX_#^4^E[ufIG˿֗,ZbxF1x(PkH3  o4YS'6MvRy1sYcKr[%0D0eK8 62+PVk L )Lߊ;A G{IL"#ioH4#>\7c/f;Y?ԎBhQq'MYB!K2Tl3M4zYUO;E! Ͽ0ϻ=kt1ZͶyZ(Y ^lrqg wjܵO=Ԑ(ac(D r3pKAS꘷1^ f0>\~4W fj[ЮCG+Pr Vèޮѿ2s_q$)`%b$K=gStVel͇ &$Aqhp>߮Myav+x""?[oR0#nϜb~\~CfW]/E7SVٵ %.S?\4^QMsTSw騙&ٓJ(5EvC|gx^J9NB,WK `I44v{ħQZzeT5 C6pI ަ*0o7(K}"-!V?NõdN9G#Y8+hl10Q1ģx7:⦫*G4Xd@`q!JtV'ec >^#_vfn]5e>)}H ]#dv0F:; } vaL4k{kzt `QGIC{w2؎䈺ғ#@Y3߹d%xm_S}W}QŞھԯBֆdO&7ҽƏ{N"h ='H< 01N6ֶi/ïR`ט%@OlKjc},߀pqAAh;[}ݒlߜ9xd>6BDC)JjZ{jI]9`a'T0 gƢImܒ6:fFFq|#915!Kvm75ɇ_F{Esn22t%RQW5ŵߊ,+(X%J;vwFW^%z8:D;k/-*HJAiƇLH[/H!5 5/il=pe{ՌO:O2\XuXm͉Il"wdh!ۉb, X|@i6D1u EطS+cp"{ P9pLRGY0H>$brn_hԕcFb%1 F~j@&[_ql[Hm#_Aߟ.=k;L c֪D ΅fʤ\ܔߢs7+wox"NDUF4QH`vcegf"5F[!TW9eeN CGThzП<ǁ޽xd'[BR0N,PT}*4 *Ƥ*MIP7e 6HgF(9+rK=x "!r֣ӔLe3+|q goŞ[ jPG t^/K1cAJpw1W`?$-fSӋm{EڴOt^e{`4yus +9 oϲ_5*G6lDOܽ}p?.fvbcYe(>kzq߇١oj?"(5\< n}JzhMF_aLP$ s|W{ueܹǘe}QEdE{H)/@ +,SX3}8@vI \)D%Ep mo ikafDӶEfup8\Y39.<[d<HnHUh :lh*L〲mm6OK~f 6VVgs¯B}8Se{SS[Orvx |AaJQu֛MyFjX36%i韯9(}0 ҭطe1녌6 m㸐m33~[GSZY=#HȬŽ,0MF4,Fbם CAh@D"$l2{Lv/E`cFv˺*m{˼6/$9mpTMU%g,{)GU\7RSY,Ε:W3%U>B[t WYTγdJ sFee;&U >[;K()}Qs/,X i0Po6`gx[!1#wq$]+`zďyZz"v|^ɩw3Vϸ .1>f}si{3zijɐ vRuU_0JPl7q gdDPj.@SaPI{wJ҇bd0ԩţQW{wzɍP 'n\=)$mu{*ђCg|#!yF[:7GwT*Cp왗[I䠔6U꠴JE2** Ho)3 †53$;e_^KBKFw-VM]a(¿T@$.W&?zRM!DZ5+Uq83ܢtPatF&%z*)DR̺;3D]lU\d2IhW P5%kj5oaW:ֆ/ )qi(>@LM%nTd.] 1f+Lf,1L 1>_w@kxЛê޳?? o WJ9㉽i>hN:nOlnmtD!@bsiBĤ1iWJ#6ҵ$fh0WᘗtM Ek^:`xY0QI5}a*؁c!}{KxF3uKio#Xk&5<̩zPZ7?\K~+ #Ϟfߗ=i{63cP@|k<1a?7E>nޕh@nyn7Jt;y#b1ڭD_f֔S*s\!tufY=SWui:J;8I*i A5v4_Sv'NK-h#2vU8O9.Oq W|A^I)RHKa-|VS2薕͗sڲG2RfpꙴKoLH *F轙i$Zge[2(ǗjTƦ d C%SceKKj 3"-}XdJy#98~nb?NPr:=Pqq=6a;͹LI 'm\-f) Reo34##HʋW(m[#P$v%.REsR~ BMحxsנx[J8\H:3!>2 li@tbtNLL %w0v/t2.J n,E ۱q?)ք%M:ٴ!~ 7pAH2#K&̝1Xuu-%2نM6]3AzchqeTUYpue' # ~G6O-CŢ``~uz871߈.\k>a+#,mU fX%s' #oHWV, oZJ{~{ɭIߘس!3/ܩ!`I3%nUbqwEk4sUQ>!˛ITwPJeӥ34Xq[\T`1<{FzwC%w&-&mW3r 88qī5"ӔpyvЯHAEr+oc<J$,D׏Q~ԦA;> hS iJ t X őe9q4*& ){Mn I_uEPݐă 'j+j9QD| CU3-8]=.o]5`IKNg ,ѠC^cϙ߆W'=ݤ蓪4H~=<}$A9Y3]jp߃+| EKm6or1]Tߛq9ݤN S Ժ+G(;LK񃆵d^bZQ#]\i'Shįіg6P#>3,U=Jw_'IwƏFK.\8N1V~=nbqADžh6_w*>(=Ƙ+9[{@y!xg`D0_xѡ~Aa}NP\u]K,k4cߡRT}l '4PJKvLќ먒y N[p(l!k sC4Q+E3MEۺux%OCIw>(r8@5->Ks}oӰ Ey Ԭ$K V[Π3ہMjfym oq mKp6)'B@G_oAo})&0SqiA v0)fc2\ W&FQȖ!lsS',(vhs:H^sӏ sҝ1ǧjh `o4xHq:QC"Y%s MpgsɦHz>bJiAuM:?sn!_48cu9 h}6KTnGx ۭ*eP̝Nm~ x[QAHQy Q\y8hjv[cC_BKk AXzK(xY;%久4 >BK/_ p-ւF#E_ʄv:zkw5 -zH=\?Wpǜ -MƇEyDGJ?AdKLz͌?mƷUrsBʢqh;}.Jٖ^HrylqOy4(V4Q~ؙ2_fu_(Fbtjsq $//s)!t+~¨ öT`fԡl߷]_?ퟰñuر2 ]LUxWoGj j:{xư{bS@NG(Y}" ep,$ ^]<\g e.| .Ƌai9 Ǟ,|", _?e1jᜢ^_( _<.!On'7N,RƕŹˮS,,Rakw"igL/![Bz xW8igeizo~x. d#s* Wl\l^$&gPMMdw~BVHLc~p,nCnY0Fa?^iym[DBmMjqUS߿(SW0*V);JS4`@KL>鍊 EPR jex|y(HLl+flOI\3QGfRj}ʛH#dcvP^8}Q?='N5Ӣ=rN*bs(8ZC%Dmt(= .BYu;nfbXNH_Q'^31XAP*0M+7ߤO̢14`S:W.gI%0ysKB b](Vp'<,ЍF֦UHbPxx/kYg2Bf;nZ.o3{EߒqFۜ~k ɀK5.~3T&u]7ףyaLHOw ֭gO5#7^\+Ty5kqk9鳧x'H:N1`>R8lp.i#kcCr_ SC FyE&|R䎫5jbh;a6f^w@&7h<%;K] b4Mo>q >nGrp,~_eNu]` tfǁaѼE4J (=)Ҟ-^u4Oְ&_s?ht$AN Jڟ+jʾ6L pǐɉw.,&Iv% ~`6#2 /FR\z9d&czn4R؏.haqبE-2).7%W3 ~B.O ۥ(C{VHm&(m4LzsaoOs2nG|"(g$!}te ЭdǗ$'@Su=J:><^wx;M64{"R_g2z%o^d)\DE1r̀?a`!-`y.)_n1ŰJ DnT[ '4|Z7Z%j |HRHA.6Wobwj$ȧJђ{ nkM;ϞUmۓ;)j5`x3>DK0;qAE7pF'sx^ (u:w4dA57o,՘D #akuTvl'&HE\]s}Kr/)rdk|1N!O+4F?s+\:F!A1^\SUIzc,n(0ljPrtS' 1:p\@ X0p%]tN8`E@ UG2%O )}DV1PJTgۧ"'AP`1+7tUc x.ڪxJP&1Ja`+p|, _X|c|k a^s.K{_(^I9R~msǼjOo&t~$w[,ΎfK p`3|g0\v:4wO-ꈙӍbͮWNgai<җ9*3άYGb9>`kȘ!U(q)ۥOA3B' }97ao 9GD;K]8m}8N7)Fq8L%nC=L@x[cLcgtp d?QZ% ӝ`gwi$ _]`؂V[~%źyoW)9ԧl>sDYP< jI\c/٘(. 񾢨y?mLF4o#Tͯ|JZXrPoA]yt1&P/H;4`f2`ؕ/wA_E_'m7G:#t!:2 sPvؤ}5Ni.%@}7ѕ>KX mRaeA﩯tݣAhd\:. L1J[Х } hҖuɆC! 0axtsabY$I10\6=a x!!kEu9謠$r!FxTJEv&]|[C%W3$3ų@];E@uI$_xS CwC-6z*cJ'k\j"n&cO'`U6|N.r=0U{lh `l;J-g`Q^NX <)Sȴ$؅p^kA 6P/"+Z5Sbkqq`n,]_Fmҡ~HI2H@{Swc26#)xLpzDv9A\tucDH獍jJހ^A)>jH %?}!}"- ̈iZ>oh9ԱkEU@ѵOlZ?[4Y{!]EK1B =6-E+D|(ԗH7%lIYkyo3$[N$Lҕs~\G@dIlA>]櫲0kEr߷13+I40[ KoL=3-<B{9IYvXXf <.,ٶ1)B~xF*0c)Ӎl1zbtd<8md]bۘ\?@BDYYIОùʀjc}vXP}zv#1"q1^ѯ?Y*G6)?HQ^J\F>bzoS2E)oa Q0bɤJ+/HVdEOة[BRQ#]^ n 0Bp]rc>?Ŭ6gA%ށmIG">)샯B3rZNi+yQ)V#᷸齆?G/V ezM(7]\>^ T+'/83wkuЄ^{auSxh/>5n,e(+R!97|_BBa1wz, sr% -7=EVBaI*LJf E*#k2X>% ph[U/ζr༫/iDŽ#Epu޾X3kk+0/-\a_sgK6,dG"_@l3j>yizqݻF _ l]VJ 4ŷP $dLdXTMD95L7p@#=Q01? }sj!8Xg#vΞ9 }Z#XՂкhvaµaA7okKݟ;Sc(|EW/Q'l28^lDr)ewٳ߄nrmZfmT $i!tJF x+#}n(~ض;'kLjSG-X΅;qú7_кRXO\=Q\ *& Aӛ~tv`zZGi)ٽ@KD1hox&`}޼'֖r֍;dq 2^>hQgyoCJ dA5\*Z2rz5`=t;LEQP+YQ׭\ZN^7hiA$uvT {cJ )iw FyD~ꜧ]wζ˖ØR#צ!doWUR;(p8/{*)l"0,mЬW9эR xF $ + Ju+uˊ @6y8¡ҌmJֺY/V^671kGTtmnIP3T*pyhL/VRY{V$!uJK}ћe1>>DG*6[+0if0QJpyVNTDO{f qmuu %_Mz@.5㔈GhC}oiyG^Povp,KiX."l8q1[u.NU{Ca7;x9w%(Rv¹wF{珃zya4q.lY>M[0lċp%8ڠ@1Q@P/x}V}6E6%yn[ů(pYx=@ { Y(1*5Tn b-aW4$.4EmC+KcܝӦ='j̳2XaBwt>ݐj=][kyH>:btQ dtpY*}x32b;;ՓKz0۾8&g0\ :a6u RW>vT(iu@i-^u}ށif#H_HPxVdعRctV jبdAF+{(6E wbU%T ę'I"\7舥[,= A)r Dk=NTS hhBϰY&?-FP 2X6~}:ne01 Bֱ-xXa:qs%eX1X<(N}$vI:`stXW`C_`*c'dEjkqoZ?Ҵxi#ei|o֕z]IeG@^Bs#B2g* Twvq7hR'95r|R#:2'Q{of(UHRr*\֋6 j֐fidxTaxnu7[eڿWNSAY]R[uC6-% K4c5d{@sW^%.wufi\tH*m 񻼱^.eQ_odXWV 2![G0̇P,S: On #v}u$ JdM4ZpČETjzcՈNikآJ=KGRl TQwҝA~oRzN2-ܝ]k(0R$ޣ^ $1AMDMС aL݁~5(~Fw0ZGvʬ~}E"մ'tx$X(H-`$H C4_9S <5fi)qgvRɔ f9{YɛY; Gs%yCJ8N6,)7'ő=ԮtCS)sD,hzVX2wђw8L ux{bnj%Xޜ '۲^Vt^_ϐm1!ln]e=mV ̄嶒Y3mWvֵ];bE+PD,>b!_(k"& .?rWm/ =y[s,Z  wZF{nPkFwjR&+ά s98 NRh ,N8s/81&uv>4K4Ue Gdͧ}"b p~by gpUz6B]q[*הQTBų}T^J콺e sS t/jn2K1ʼFj4gk~2xuI^~v OFPg-_U72sP5m%x@đ6EOBkQ[Hat 1`BZal|2]AƯ~ejʅ֢ }CՍ*ӯsm5$>)>Yd`UIUT1j:PB6Q< Zwb]R.+D7BP&>lo{LB k`#!riS> ^$O4D% Γ)Λj X5ɚA2B ]_h%)_/guij(> V[U(1@D/,=ISyyIzS\ U)` h% e :*7c^ .KCD.7MϺ =uS :nV'1FZ[>2k>ዾ͠(nˆx}K_GΨ%/2H@xo@35{X \-M]]]v{[ Dm"OATTR3U xGbf 3[.r@yn8 f먊&۝԰х90ULDL=ְn,,9Qs:";M H`:&A@@FxEW ˁ2&M/ Z]mw^cK^fgu*UEVMr E1xA&4"S֨|hLWq1=-.L udlː."bZh3ޫx)Yn: fmgHV5H}cڠjtu{Axd(=C2?UF'ȫd-.k-A1Aʘ&q4-[2'{d~ As>ܔTrYٽ"u]+jX;k~mH2XN\(*sޣ0m|2hҼvhd(_IDE9mB_-eV㠗7g粓fD}܇Z 윺8ZCq# M߼9j!,UJ";, R>l(Q)iy U+cw`'M꤂ErRb~DHCLc,C>~߲VKޥX&g\E D+fhI,ۂH*$K fkzPd[̂_vq=Qwa`} R|ВB\^Nɍ˫3d ?f- t_}#,ZޅfRuWjW m1chX,uY8hdʛ'k.fQ':T{ RZOY%{P<4#y e{D Ki71^a9=`e!F4df๢FTCQBN n_<h/,G9V9WC2c\-Y`(v1!S ',0jba}knUbvKZ jAeB䗨#L<܌[; Yl}S|Zb9x $Ѵ!^b>'xc21j/j5ݠN/Y%γPCj;xnGKGT`2cƲGeDɎE|Q]s@Ѣ^O/v QZXVFݏ >iZFqJSvfAE\*+Dھi1T@vݝǧ1mqO=EN}N;B!Ԡe^w BNǦb=2W},tO}٧u2™䆲ERs|7cxE)xoma uohg[Pr,%]_.R|@&O.1&]:II~ك*G&Om/$îk h͖\5\tEOWu*;pm/Ҁ6k[+ EX^_GQ^+BA&pn7Q $GY@Cf3r˄E_7ל+PѐѤTUW,Ist*kVp7Yp:NER_kR&K,qSy=\n*fOX̍(~D9.꩔~܅; 5B̩GU{M+y"vcYu G_V%ƨ hxgY`=j|`|m@v7TA,,jg|g ;/K)pT6(\;g%I}\w|@rd՜߭qh&~n)Ak݃l\Pco\ /HH8]E!28_o*z/WTNN4/D+-2p`q@j/qʕ%[$q0עQՓ /Uo~5̩MGA&U8.Om魱(.6#3 4m_CȃڂV鵞Ѹy eC# ΙE ԑyvğVB2Uu\F=0lk3''c;f%R!t=q)D$|PA8c7sXcv3 yv v~zzS0$ֵV$駈Ski%=Ґb3)b.B2AEd80|ņptngÆ@KINwOm ffhy&3WOĝKk ύ{𝨹a-hWe eTz Q51gZ(#67 3&rcwpP܁r2qtkHzzn0 (I~Dh3-+3BLρ2L5/Hqv'c,P7Vp^a+}as(f@ }DzY\HJsjadY rB\~4PV!gwMB,38Gj x5i0lz,!6m*oW9YD谰,r\s;,*V=6¦'D`{0- ̳IP baq 'RKI S:쒚zi3w5& s>㥺I-sI#*/zM4SNGxlH^@\ɚ4_ϤcY_jl,TuY³F4C~0,ZR#ڧj 犊pI@/̅= Sc(N6R+i.58 `L[P|0EGO)cxoQˆd4<k L3 Sv$5[bUgD.66I;_!/ĭbACQu j8FJ@ فW W6%a׭^P,y5.4"i$^> [qg4p!9ǻ`Swz"tE)X9HA2IQ*+yx,?=p?&g{]$Airى%i;䥝"00lP;l윁Z-O*`3()[((ʟ /4H|.f/FԮXd_dH% X9!y]ҺDr;7 zi]쨲5RfX!OSXfl҈N4Pe:(,>:Ւ HN:7!Ew;,n A\cU% gxan݅Ԓhs$ g}tṇQӸS Ϡ3d^i =B)k`Lu,֌48۫*nn^p=ʝú,OqH6ӕA19ldm:$I|]VƜdoA2\DuQPbļJ \ `(84 ~v=q4UtBb9oq,C ħ7{ 3tN9EFڪSAƆC(bWݗ`,6-Ri/^ "Dw3ýc2RքvL`#ۿk@KC6tt}oIsJh o>\md1Qݶ .5؅IcJ.2)lE^(_Xay|EU=J}_x=R\?n0c'6(^:5jt#p_S (Yd72,KT߯dυՇZP Ѱ_B8Ȗ+&g:[:i. ߁p#c 7;. }ػխ=Oy?֥^qO1q[c;8I($=o7˪h%`./[6"DIWٞ,TVZENMXFE|CH Y{ƌ\0c+ JlgBa u1LHd"J\bk >x{w#jq R$l{SV?Wi*@B]MWZ5.oR"K&E,YҊq1,K Nꩋ+.d\n@{Fb§n7=lD}6RB4bܪJ=tVa%ČYLbf]/|gV(k-PTE`i ?oFP%ڶiY`Ku&GQCj1m= 5}Ƙ?nI+[PFIɸ+$+g$PaZ?x`c&WJ^wTGE 6կZ6R,F6(A)]ua/|a Ag?x5i =4<ڑZijX]ic\W=e N/VsVqsD PQ$e;4rX*13]Wϔ v3(A, .&?d$g#(T5}1+^8ӂ2.;I;G@ +5f {Pv憉-t1y$5k *- H;5_ S@KNt )m]ivû}Y3BMx:Qb F(>koϮ]Di#-QtЯ_{sgNwXy@M]PXdj>b24> F;G&%6KX͆ךĸe'|QAs,ے,̐Um_aC8PZ=|FrؤݴayJ1(h{e[%時qzxB5?k5t¬{g-MUPJ"SʦJL-&l,G>i;:qZ>n HRQ?x~\sX" $OpiH<0e56SgiP$ aD9+]"!J)&@nɊJ#Thg@p^?f*jAHKz*40gS)l&_#`vͭ|#Y7xѝ \\d%2K#}g[I8U :XoE G\3(\Eq5r# #^0kt^_C赐He'AE-NHg&@E@ЈG{D;%a<;o<Ǵ>Rq mc ҕ‡ N~.:Ĉ sd};+YrIF}HzɤLD=~3ty4G9<."45'p#Nd<*,W>2`@:3'qB`nՇ8Z%s=cX{qQ=aĜ_,Rt1e ||JDМ0Fvp"Pڅ)Wm<?Q Jsәϵ+-Q,x; gAszL7 WŁV1sN@c[$X̂ѧEtSV8.TDdjeygN;C gg %( ; }fCi#oru:Ѹd:[7*̔}ug'= 0DZB- %S-@$ѥ#P*@6M]ѣVk\8.#4˱"jq*ru@jh8NL%M `N"桾Td\Jf9>턖=X1{Ϸ)yD0i'lWY~"ۯ#=T$LˍR b6t rÀ(W=[|r1mcJ;:Y!Qr9`;^HjSF4Chfkcl Җm ?/ܫ]$RZ619|G,nRfdr^=TɳvZ\Z\k!jmgYR[Ap,/hʊYk2z~(Ϊb,d&@\Wϑ~ eesrSz p}שׂJ\o@1 \^B+Euk Ɇv5K#t4Mb1#G#%R|Z_}^.Hx/#Jʞ@D^*%# 7!!)Y- @B^}∢~_(=)r V3W[Oao?k?3*̔@+D2'O `o,VQtd?6BNb  sU 3 {Gωsz\$e~6ǾC8N*ETe2#1TW9Eau{Nnit0rț:26Ȳ2`V &u1jzN.?sb;~-&^gw:k)p6CBW [ įij+F07I7#"|_cspmI<ϥ1@l۬G  M"HPۨaiC٢_l$VkwPNzAmZD!L!E.ڰ|<@Nݥ{d9[@-t}Ú2~ȶV{x$XF5n׷n3Ӊ=J->_Ia!m3Y)-a=Vvf Us:@E9- "-wAfX-ZfXɨG60i!?Yh#^(P%+lj6€ʨ>wڿ ^.!9CtWj_kbi4ɯ܏ G#< )@'_*ߧ Ma4d\,õy|\lLRy,g!SՁ m7Z)b{S/?1Yp0x`$C5y1^d(&˖)\R_,4_yEbBK8koZ} ZyF۽l )\_QF-)Ufhwc_ hu,(]0niͮĪ;LAFV-М6VL.Vmx4Lr01.˄o֍il(YTo1d&W͸tgYQw8:chpyw8⚥]@YA=tt;(xE"^gQ:~dW5$B%qY]Ea>ѯ$2^ Ż!A~;qtTZg|mJۏa0@/s~ؙUڎYh!뼆ѩͲ[ Œ[,̭EA :dh`o:-Uo J)JO ` ñi˔ 51OOi"^,a͜rY2 e뫛#~om@ X~⩣7ZbJ&x<$g m ޷32n NTbqe[]GQN+詼*|O:1]tvTe:2f/IX]dѿj> ou[OGLUkNԧuVb%/=Bt9(q#RSؒhesKnEFe{p'K33ƽf]IEКO-m;n4ۨ`nAtЩhב^[h >ÅآT50x1B hca a]L[{W_&co,hÖ[K;b#~-k b?7@ v40;3CЁv\"4.|2lE%#ڒ84f^S љ(4y2o+T|!gu`r_(fxD؊_3oZ6ˮ]`(LGL]rk&9yoQ90\≱%WmNXeaO;Oo;є40~/-ҎӘj?& ’8-HXq'm{r{A=h7+wgߔm8UcILż=cf }&-5U*JKӜ/ X9Co?$8}F7Ié=Y:"FvG*olj'nru)OixdLU&D2FP#bgeIjK=9J+],_XX+ wmgC"VpE3H{䵈fl=Y_6idz0;2sĮN<\=3;8,sY7n&55ɋu}HiE 8!CVܘ b{uHU߲POqx3nв8&$]G`aGH$}7i&zݨ|hA 7h:ڣ_S;ʆl-'v^ȃR8zS4NcMlj L U{KYȦi3[U#|qsQ4f wsP:Ll81l\;1WI's!Kl׏Fg앣2IZ>eAngi=qP}|6McO.kM)1() 6^6ˊ|Zifc:w{i<0dȡZӉ0+ gz+swd3vycQ q *i7[߻N7{T姅/tZ;| /n&iBXmA_trs =n*娑8G,^=~js蒻EKc*v,0iiiP?ǽ]8-ut /0 hB?Btf^:N%AT,i X=Hy#TQ%k=!eC)ϊuM>8,1fkNsS\Q<,A&';ʓ)J_HZa0mg`rc mආ˄GOޘ?魈mN0nPa`.o'|MC9&V laK@vH~ҿhY~4%/60=0б" ~)˶ e kt@ WۻxPˆf2nrWdKi5C3~jEAfA5x5r0s!3ZƕRIv?gމ%;"%%G\X="(Y 'HfCK܍&Bvx fqь>=w`'2 $Ѵ4%)1Ӏ>j=\5slWZ ! gtR x5Pk@+d5sD}&2]2&a!ԕK%`Ltp݊ c0):,ʩ0Vq>ĻcKLleMLJğUr(>::NY -}U'1t{GjB&|,WP@3ѳfl7#W{9"<2z#( I@{?ů^a-oy+n1>`OKj|U@Cg+Ԙ@ $Mc~SZ{:_Z/TP0Gw.K^+yUagR)K IJׇ^ Tl'I$>LlՅtyMţ1!8]V( z9u G5V@s<-XVv˯}% j6@qW~ؐ%*03;)ɰmvS A=d;BG0`G%UuBPBmNHrc#8,sVNlXe lXANq+J*:*[)+)G0Mvq0m|ј;Q:Px[sLNc헁Ӂi ` ,㎧USU/>ᝇ).HX{) C"Bj-Lj)`[F3?|J' 7zɭn+]vtZUs'Ws>}?X$7Yhi$Z h2^SxSFѕeD7b˂tU%'Me&$aWW0"-Q.SĄu_ uQh*dw9ϑf%fD.NR7ҵҗmgW,͜J2x^>YnceH݃TMt<>.|B0'X342U,(D7F-+ g'z*[[An0mg23obU=;T{Hz#Ե&)|GOy0-Zd^Ssd))q΂W>扊trlFz|UTYF"6fF^"O_lxtc|Yb: /ԥvs.LNy B-OrY_%r@rq`{x{J7~Ѫ#CTT!s/gI:/h}9l7NyQݸ#)]4PhL\ `oUS#: No{0J'|{uҨ0N9e01/g[q~Co p7'QYֹ Md͙1'W4G6mJ7wSV  l&3M= pp"7>3P|z@gFs\q{A1RWhcMG⤰g2v ͽ-ꎴrXڦ{—*BWZW!"wM{" ]gHW( /LVRF. $aC{~(* O~Qӑ)&%նabX…W~mDӏԍ4 퓬q)0eKⷮt |U]ɏBz`[ oc_x#!GNFQO_mmJaL ;uoW (f=>۸BaHID*yK1{Cby^g\\Ҳe}C|F̡sTl5Hsa6wvp\xc=ӀhW:>HmE4 W7Bu<aIb>Lµy Fk!$WPA &O_vB jzYP`P/e\*;Ůtl:3L4gSU$a}1}yZueY(*+4j/lSuܕb =|2oCA!?]=*\Wu/@e% [%g_ևJSFђ¡ϲtJЖN-G bZg 'X";Wb閄B&>W;CW[SͶlGg]_d"m_@v[%;4́S7٩|IЧҤh¨(SΤxM VO&*ȰlZp|Si*h. |feUn昀#[!^W[IUEyʣ̠*LZT צ9S3m\b~+Lm(>n 7Hm4o/YI*/N@Yjv,1& W#jn5t$wQݑ4 Ёby {5u vj룋BY6h21Tdx1sof}1{w?$o a42Z|\]cwz?|ʞb\i^i˲zx%r_1izw FLf"7Df3B/F,,*._Kbklc^ȅ'$著_Z0c ^ d =K /\|{>"]\b,ײ=4F/03m‹{UKǚ8bZ/ ޛ&T/{#Нj \L 9Imϲ9q:,+R(iRxyiK]16 FVqPv&e\Qӡ.KH[-v`gބuΗ*O/frQϽʀ-2ԡ2<OG =ӼZN{n[|hOh ޥ?]L7h}V?/gMn3Fх{xv β ܼ-zHe '=Bϥf. н%CMe&{?4=vsV4Ž" zD%)f\֟ȠUc"Fd=o|3.[] ܽ.oaZQ4To7Ѽ?zW'5x8a*d̒wZ^8yUln[eG *d﹭[ fWCxl) ш^|ujwҥ'`E26"UN+lxDlLgsoKIM AO$߀2aͯF,Nဩܚ 4s[jN,R!9CF r² HHս]Ȫ>pZ EP!{g%qWNk*RxD-A !K mNX«د0(. L#Ы1,%9a؇!VinZ̷[ &Fn1bJ'$ĵGJɑ >?6 zٵ-8iVP^ jKVj)(bZzE+k H7fV1pP|>ɛ]tTt-BlwEr3fqaitBL2_JT^_z7ȒRS7#?o.Q ($c] A,*"Q %䘠Tq9~xM(z=(nVՙpQo_U&_h 6;=RK=D2L zPGs?Iqvv/oKs%侻~Dd{쵭s=.t)KK4#el5^—2vG^U-L82:(5[?Vh41.sMA\fqt;L4ES[B+dbƅ8,IX9`1,Y&ͽ8ڢ{gwjPݡij_EiBݚdp -Z䳘_MC lՏ j$#:BS+x!rQخ6v0Ze]Gljj&)l1Y6"HWf֟ԱH[E`M.j*X(_ T.׌'m%2ýe#|\iKxdџ.䵰 *1.<[ޤٹsU:eDKn=[$~4HF$%"*}E-U]}՝,&Ѐd? fvK4$+CMkKqd0˻'4zɖ 9LoR?a}0wLH'-Jc {.h'?Ä=G6"\6:АQic r2BNvy`ɅP /_o(HE YJCe?E,Cȉ;"]GJqT!e[15#:Ql2ݺP4 ME?|8i|RӠx!c1aԊѾ] 12%?Y@A_F=e&^j'a,(4\ a] +QhaQ74mff0HEuVNR1u}7(ֻXh[xdl0-%FN/ᬒI݇Ѕ}==eLY<)_qU:VX; bxRܬ*+u`-S"{"VM`%$A\aknN:;^qV@h}=B5]C$h8,ىv EdC\ޟ+ o/Ny`i 9ӥ#{g>|Ue:\5PMquGI1X;/ԝ8̳1z8GM#|vߦc35ollף_;}Ajq-fbFt*[ZK0F>S8(ҟCܩ0(\YQJl9Ƚc-dW -VW:f%&bvOWN-#|h+=q H_jX} JId=y"wL85˻F3 SB.Goug#d HX j׫$=Ns9^J+ㄏm&*Y==DJM۩80q0m= T{~ ؾ! E/}uVL+s cqLZ\讎 M~kW17)hшwPmX.hI |TxBu/Rڛ*w@[HBA"tѤ0Gn>L 7P#3(?/8NWf:V0lF?Sd,3n2CkQ}[D g@z8t>wZJLؙdX)]oIɧ4%IH61%YTΥ\..8h=N(Uy1i}uK˞Qd$[PŭB#(,ڻx~+]LL<"l{.AD^hoZmpFGkӁg._op?wj~nwQÊ٘FV°+}{W-t43~Ïb Mɞ4OJI]~p|&Hgx7V!`S!x;/=̊o4E*/׵b:^Uxf;<'W}qnT]_>$gJe[Rm(I.%]OqجIb溇ZN2X=ԅXzCGh^%!M&'z~mN= 2T(-ypjR!؁ggt<޴\הx1cX?.]k'(8U`/jxYHaK90ހ^dS)DdhE&ralԻo;0߰`QJs/Wb+8˭2#]Lmɔ,Lc36DyDrqV2q϶: r=CK?O aq][lNMzU{m5KLVLpu_y 4WW/#ފmyTe3ycF]'gVYzUAL&kgKvglCq;^Tzɖxy$:J0/':8BtċoYsZiVKɸD8IZ JxH->lHDsm,R/*ފQT0pT^ONy4B1]G+cչ!=fI $Pl+md#T U3#%W1R j}G'J֟ U&jٓ4޷y|<'T&=v˙N9U;2,d\2͉.dvUtpLi3>7TGu<.מaΪ9{7Q c̜uup˄lET;]MHfV 9pp7!fZPܭvkdӑ a9";|ѷK )$CHQ≈fʆ6Ap)_?~n(WPݼÞU|6=KF^E(M_T[ñٕu j w3)(cl^|$7T;j]&x&zj])J2 ij츕\O~-h uLqq FQN 78`ڰ:v09ɠAifc)NU)tkؿ*ǣ?[M=؎n~lA* Ƃ͹~՜6 x۫7tEz `Bd41~) vg5!u|m{oZ}Jobbعbַ'.8hC "jfPY͒VQB #PBQ7F|1Ag.˵k# ,7"ƭ}ar,(ʮ1 \iփ^iqy3 =uf6;rblab[;)V@ w7V}{Lj &# Z;\{j sVQAٌ>lM8=D35UoSm vx# VˆO=QnJ%>4!St>րam'0|1P-.ǹT el n)]&|A_Jhe,I|kd1(ZcuTq |C'j|'/dLL1 \S. Q7a4ݔ8$VzͩkM;١ #LAMj((߂-bg{ߘ3ә۫h eSfZPUf8©yZUbFIv &ðǍF8 nt9|XzmqE\Dx9w:8\ 3tr}0XIC_Myc"m_{lu{*mUA{L$f?*]AXbÖ&sz:T8`Ϳiˏ[ܠN kAOو 1M\q|*ox|Hsve%q98E_Hmղ 4]MJ zrޑ82老M,-@G_d85H;›FdǰTt,n 4$D^DVRMXH]M) hL%j!9} H=%KVcE aUK5^l9>)=;5.&O x>J>v {[$$Q2l+1$. uėltpg-Μ'7w[<8!cG{ c]vy-g&mR$LALNtY㨍a*;(ZFh_K;p pAkĨ5蘛TXdp+0.ÇHcV2sw[ս6 ‘5yQ{@QY+ttLd,'*21y*7F޹=ROޟzզLք];$:< `?323~Ju P2+U5bv댺P]yꍘ:A )ҞWO[,F7Rhxi~WX`c I0ᇅTer$x$J#|fq‹_v[NmD٘Ѩ~-?Ψ KlKi(Tfy\dW/TVF`v;*LҒV;OiLz#SC (fܠw\r.U( $[_"wa~, 0B4w5wc;O8 &dť[]L,$:iYOBsUޤHݫbLJi2T92K{lw}v. M/_D7V-Q3͕F+(/YF! Vo2w%PLxgGG,dh+5*!NNpxrQϑc{YeũeIs@6΍Fw1ke;"V$IrF7w^^|܎D#ˈ AAq5iϤ;>0۶ #큃(ciG,DQ쯝b"EcT~og9}7O6i-RSGQ$;K{zۭaHE8!,ŰU'r6z NjXHD;eC/DhDs$aJp|xbP O4"wg[_]q[A/r=@`i2#f`AhSL]hBq)ىEm`!8j@uEDőc0 Z0\ΡcRP8z( } [Ѱ1xx(R9 aVw{"iRghôeSJòW.tfC؎1˵ ="@х:qap!Y 27<бQ$*^eC>+4,|\7oVjVꯀn=3 +. Hs,_j7i5%UuKq_1z-@4GvuqxgI[.ofUjLF/e=J=FW[t;v&I]o)u7СX2 K9i~%-Jn(bΙ.9d*cCӻ8zGhZa+cW1LѦ7 (: JGܬ~pH[k*5ג-!>+:8z}>NjTض W8VG. gcE,G pPaRm][Gߑ^J.Y4 *`w]K6jlֆ%&({҈CǕo 3>s_jWqA .Z dk O%\fթhYR&N`Xqzr21Y \3yf.VNsK3g\w+V~djZ|C.:XO5c_̴-u=S"$4 }7d+h"kv={1%\IC})܎1֗ysҏSzXu0=~g$4ߛ\U&4P"iLKS)Y/ޑ5#^:I .-"uinB#l҅MV׮i4 Zja5^Ԯ}:!);gYI800\ EE <l@k \345m8_X\)-9ưt鬎hM帍7h U<`Do^׎Bߧ'їN3p56mZa[6 ;(a4čQa@AlleRCDEiwˁzH-=\Lds Sc=\~j0He=2ooŞekP*1[A8@ho\495ĺRØAT$UuV?`޿q8(_XO|oq0]$>ċ؋_VZW.U /ǻt1lDj+p;tz}F+AfI+C,]r-"GF:l& jDRq!Q9TO &wp5miBi0}n1¿N2ۄzI@&֚Or (z$s#yU"(\~&{3zFۊuc8n(סWC汐'b9KVT-̳%$. g0.-ƈG:j}\0Xb$C=W` K 'e<*QbRYFl+;^ˢ~|MU^?$mP9YÕEI_37&r^|=QEC'DXJhcHJFU7^lоۡH!Brz( 2fVljSKXzɇ{]+-i0X#|՗*K_/zABzc H\7Y5df 1kfͽ;1"^hhIϲ,'TU)F,嶀*P g-!vF߇6۽A(Hx@DXH} v3uULcETK USA<' xOȋ|:; N8Ap-w*%Wh|܎e|Vzb8aE _NC)^q=j27e@M3ew-TAzEJ[p⨾mv|;vXl=m`5;Qj^>Ē4{e&f.7GUw8Lh`/61T)KR iî \Q .˗7F?gek}`,Q *C^[\YM9TJ;FI/Я8 j^Q9UUj0Fa9\1R$:ۼ]>־ YZ=1bD,Y{L>2R]j"1kiN'X[3u} ,N:6j~ޱċ$=n8}D$tO& $ࣹqz+d87c:,Ul8H3utz]#}sG}jۑ%byoiωIN}8l>uk̀q#:DS&RI6oyk4Azs)O:sDYΤ"NL1X+a5ܪU6RΊSXU9neU *17GI[9E хٕ OM"EkX$D\m5Ĩng"L>iCYOf `Q&<9|[wh.T2fE@ˇ9 *~_+玸y?F|؄ǩcuE}sd=t[^Bh)D>@2> W͉ GS:dOvƤ»*0QSRgEԀ}?Q|)1 Ke韇9)K߿[ J0pĕիx_5)ϣ@/}y>XB*HȻ u\ dj45l4i ˈoDlkR9<I7"20T曄U2"/ /l.88F<[p'ni]ƓƗMi~8"LImB# Ohc5Q,\4ABc=+P;G7&+I_l@!roB|łVQi=7l8HUu@p&d`!ϣ_zɾhr|$]6d6}Û:pw(v]9_-jGewC~vtt_'0,䆖2 -^rE@+`:E{en )Mx;s&}helhr.fJ.Dn%AX9X#΅Ϙ:P#."\F': 0ռ ytEH{w_ՅVK*ׂ҆pkZc;Y~mY xž6>Dc J&ssӈSqA`D- aWbۑ4U oL9HgD_Ż43T,H)}OvU7NWT lHMz$$u\^K?^%5P @zw;eVǔ0/ xF$yrOΦ\GS!!zV L%=߶0Y2a,Fzl4طX:Aش2WD 4wYw,b5_Mv_q#ǹhȟ%ܱ ŏZ,ϼGI\-{ ^"T3%Q3Đ]\xh2:4TvkVWjޕ*pL1Q`&zw涾%Bo~ &EQ>rB812ubmkE79s-]=h+'557h$'_btv~a!ih?wvtd:Zನ[\<::F<HJ }2N({I"DY9(kXnpwDU~ɍM"(6 k[ |B\Vg4i^N7c5<a}cA]lut?l륛< ޹ Y1uP8gYĈ@+EoV o8iwx}HqL&Bdv"mڙ7kͬ JցS0hY: eo >ּD &!oBVhKr$m e lx*8"5ʖ.]hio:NJ[_pc2[Xg ߫c4aX^Ā6Xpi2za% BF1 URg*g`*ƏJ"|IiiAuTu-&᭽3?l>_H R@2&Zm߭E(cjӆB@P8#>J/X݄*:"t?UL`grZGC%im((q,M:]}9,FlH~Q}QJUCɌhև4İbnMz{$IqN[?(eq|#>::Y{,@d]r毗G;̍VX )-X[>bM坑͝戦ޖ^u7.BI`lP0Tܻ{rKG}sh%rF]5Ǹ<:QΞ k|qlc%6ǝ 5ɫ([MXВ+ݟX}q053xK cg@ZV1oT|TfV'nyõ\ΞQG:~6GW7-f_]i˟ʀ2'3kO>:tz\W>$FRقT_KH#xAݱI hߧds_P>XW 2/kr Z7At987J.wnUV-" r ^GQ$9ʋ ^X%F<1A=HH8 Nik;Su(zMKgXPՑha-/H%9PϔEctJlٹbů.'ka)YEm0'dL (Rv3L?aD-;B4I>GPB m*)kttaBYOk: w\ @*HRQoWxugBFWbjO!rqe(2K1>S1bXp<1o2Uʛ?2Kƙįyw^3"PNi!h^FXS%ZĿ:)3ȈX; iQ@'wrm]y3S_3QȆ9kl˄7<  HYiSc ꤒᮇ pYzdsۗ!^`Z0hED?˗x=n%mK T9B H`P2p3hV6{=@`ƃ) z>Mɵݒ=.52kG~BY0nobr/c)uyt+2޲em:l4;&oDž :a(I?C3xWhؙ#̇F531a0]dJ1eeR{0Y'ѻӧ9o凌wEU?s hz$`J]B޷mDRPwK  [V(i2rQsUIN(0ݨCG[c *,165}FȆ4ڐS[c "ry ˴#b(Qt^CSq ,&|UGl;>˚ !(e%N7r<1yD-.FCҗj˓{hTk=<'ˆ@"hSq?| EĠTラ!+v@"vNVV.N\٤31Y2{-{~.*.'Lyq]’" HqTdr>֔B4#PzhFFYbVpȮ}H6g\ /^\Af>`|Q(~:(}l4Dʲv?Չ[moRJ`wН0M!=ȑ#$4v4c.}6e㦕.|(aG5$v,Id &͟Fk zQ#MoOvW@k!=(5}USV*# w&BYy0Ǥ9M ~h KV I\G=܋1m$Uєw)Fyʾ~ޯ:r%w_u#j1KKD05hڡ;KbETߥ/am1z7^:\zpG.˺qEJf7z,9`IbBdsPrD !iaJ\AmޏTX&>vk2|s!WCຨYXڔGYhBzPa2:,䆐 q,6 RcoC-桷aƈ̝0tSaOʦ\E):X;38:dG)@pƤJ@#ӅȱU&nz ='ia~vEEDAsq`rZ7pF|K HTUqb BFGFrK6|D {n4~4nx[V=LgBI ̲`hǮp֞|.`ifgZ8vK莴G9^AdmÑ._0W O5QW[enZe1 3~ct`!_Y B[GƳrCHf\TE _Y|,+ p{[oĹ9£qk0\n8(չ|kTR1)y@NjD5O];Z&Mϳ=\)IfһZ6 nD\5Fcwj~5G+&xɈǢ~j\Es$4ޠ<3P!XӇ,-KأIi H;KkcqxdR[K#n>@rޕʊ_E!hY\+ y>.,ƍN[!Ms=E(%/`ymb@x=!O(|BLBro~Cʺ\%j(=-we4W/FF&78:>OD zuO~SHnm#NHG{y"6֡F\u~(5?X L #Sa뎙ImheiZ~!UBfJI,);t;dg"l dWVx=qeY [AV!촒>TpYQ'"Y]~dh^Ƌ=}q046lm6`b"*kc<+UW֪.`ÐSC5̪qUYVPS&3"Mf* ?}7|R*vg0Nu: tDz:Mf2FDGE Hsq "36?Ffy"%sGtܭ& d4"%ޕzgeZ " Պll>kWh[S~sìތϙ%",ڤ_&aȆ&&{hV ~kb5[ߟSq&yVjV85/w%ć95jU (Ś!b,j[|ae0uBe PE`(ZW\[S/GQǕ0j2&q)'o<0hI?3RM(*0/UdzCvD W]o )bϵf*ʴ&."5|+M1d!Ƨi@ۍ ~BbzӲ8Lth`c][1oL71$_.~oLU|`?Ⲿ?uI>jzTXƜ.גV[̝g#=HK+RE8fΤ&\ieZ8֜a1!p˞pF3L:c.'XryH0Tg.  O˾>wE 1@EtgaWcbp1$Zœi؊gu|m@9l˄d]4R4(G߲7Mxvk]d HPyn@p]P'9!/RU}E8  jܓ.eQzE=z{̕Ԃy|U̗N$VH%յ ~&F>Lܘ[X;uOՌ8!M99ĨsC1|C#6p&u1<~t\ߝ x[8N;@ޮQ-b;-27# 2 _k'Z#ZHZnא7*i2,/-}B [sO.)eiIG\)td>3Q'gtU?nu7*h^K a~q1FQn4)sGs\*E+*MΘ'Hϑ_?{d|lZJOڪ<@Όps0q|=˧#Zs<"8?ύff*E*b0N>1g885eJF93GlA(tlZyLSn* 4k⚨uת2ܽUSYފ \@uX7TLtܱ{NRkjA..*#&Rak) *蒝<+i}h& hr >HFHm ڴ걘gϯ P/;hYG#:q>֢6$&;RjQ6ӵ1xg.9F h]Y[Cc!Lz2\O0X7G1?B3epe`@=jOE5$;Kפ.m]1SI~:LE/ 2ipC_dKyHFg=߿iB @~ L4ڟ;?{!U[lOSYgvF Ȍ b FnA%1xcMպUY$/y&9`zѼ H#=Յ\W|t! ݼ<$`}K?A+tW`. lU\ag4cLGYq#DcCJI|p/^bk;3bm_ӈ_Z>6S1翝{];̘3ZvmwOt#Hg-:->@Z[ĚgG꠲mp7s$&o}:]MU a'繖AQ 1C)4ssJQ1 Pi}4tuMp٫E#3RY2і3\L[wiPDxhQy'nRUcX/G]VVܻ/)ڌ6ß4  KF(zeb .џISop\؎G{t?0CB#uumR9((ɖ/bSwX5HiG.|0m7(7fk_}}_kP h2O󂫟vQ ,1C U (9ib DRټҸQŞ_4E?Ag_)ot4_>쬢TsU%8*uZK֜h獿pa0fAkͻL()מ4?==w͇LCMD}W3ZVe)(+P54! 8(`4³%(|*M)bXj"CЭwn=62v1]JvBQֺu6A 5W Fj5g>0t1ٿ78fĮJEcMDHTBU77p`}Q实 @]Ikm9W:?q4sYKVP]F~j'H(\!B 6) ȡQ}T6@&:Cdpx Ui,|-Zﮞ?k8EN1}Bһ0oW K jrV'JT-F C 7k7VᎧMrzM:*8mKǃ=8?7 gp!AXQ_g46o}&z>K `-3bQJ=p{ch2e{Ȑ5y]+t*W8X!ۺqB|~̸G~`ytBkdic︋ȏ;+};e)IIN+fv8G];EE<.noRE(0/@QA`z$!ꯖ%O,X6}DxEњ˴H<͍ErZ!I@`\dK\|[]P"ѫrQo<#{[nՎKe$V*%0Ht/nRBW~6V|⌚opm⟚ύtP~K{t5f} =xԯs|۲@7Zi=St{1BTk9}<l8Um6긼<ʍujܡQ¬݋n }ӊ׿P*:Qui,E);,8۳rkjx[!it'="y3z%Jȓlݯ oNlLVD~\FlA8)Ըs.^Q[@^yɡĩ)$L̄zcJsUyBjiuQC@ۑ&e N+0Իry8R++no|F:2(I43vX$D3GWA̿CjS;b;B]JXiʜ^`16 w1X( i {_+hh*%nagj8 >mpb*p;O%N7cgl7$/L?[Yv2T[煪 Ҝ|v|;m,IP^vpE;Eխ` 9qL؅ t8}2K f8iEK9v0x3C=?,OOȚ&}U@ --+T-0Wun"V/N>axa:c`ES΃s8niNGɀEu6L=I1@f/ܔPvo!IVZ- -sI]*^e:a8;"T[<jT\u; cMB{'Mj1_]>-fKF<B* < [@ C3_W=1W믏A[! .UP#~ n jFEVMxx_\$d COȦ,^OMJ_MuKZNXRo8.ɀ.A]k訚*%M]lN;K#ځ?8.( Ź9k=bܽ3$>x}EQ\R7>qP܂tդ'vb%L CNrkIE_=t &r XuNg*(; } N|Ц|Ӓ(44d٘lIn%ݭS *«L)2(9A[)cr)ڔ80bճ`QJ\tDCz+N}F`p35b欴Dj7䩦Brz5㶌lOlS%E~&z~y&rp^vTŅH|,4&!)AH^Qaeg M Z&68vkFb`nS]t^0B!AȟtJ@C2tAwolu~Y_3[h2 9.roΆd`vx紅8]IYmyqYq?"{35; UY'{}NHX\$g~kW6e"Cu=~, 9e΃>3/QWח DS_BZ-tAI뇂do7ͲN2r`Mq룱.%+I[LO`**qn};~Y\e|_3`xJƦM L@4dV $b \1T! 2i `6["_~kO%[u/-;`g:~, P aD)6F8o#TB"}e-c߿M ~F;N_:t7%oN㌊o`X9憩Lu f&dZf4\f8G1uߵ7; zlG^ɰV5{W{BS=0Mfœ-F^սMj Fa76p/Զ0% Ϗ]] jnǨw). 竏I3?<"v/Z+AS`+ NӲ Kٔ[ +% ݠT9|]f{B8ӛ#!5n2Ψ{' )P -YĠ;!HxA_'>.YpMKt*۶imz}0`M~Vh{^M rX5Ԝ\iǛ(o !UJ0b֪A(ɂ{8>~1˛HMˣQJ @U-djsӾ7`.F);T 69OcF62GĹJ_6p-,!=A4h5_o-,9U-F@MB%o^t"K8Ú\㥾!OꄬO@Cx>` ZT7K1EF]_xR+ h@>Icz|Zj15@’* x~QR}lCӡb{<6B%[h65hG™5n3ODH3O-˒>w֭Z1 0!lЀK$NB?"f2+j6d9`mو[ n|d[GeUqTy[9lEf.qSPcYoOT[#t!%yqpD LNIIiѯڇ&:W90?e"Unjg#XFD& )5ZN<1V}u%~kW𰗶H4'Ӷc|>"f^#wfvԌujz b_sҎh,Hwb/u5lg՘Mvom2:ƶ 1p.ヨ̀C  ,jwLjSgkO_'7A̜-YHYStܜ7'E#\A6P N捫.`%W4.yP #EwPRIOO;fCҖ2xҽ@U)+<85TϰN~X. Ipr9ՙirՃF3hVj~datt "OՓ~ae5ϰyAV-U`~њ($߷ωj=p>n vp_즿ҝ;qo?"FMiXTu"RDαmAp޶m x㒤UGf*|!H05ž}yY9.>dpԿMRA4eo}NVɲdPLedzbxXϕԤSglܸ$.|[HŒV/?w[ʍ !96Z ku?a}E!6V癙𺢾SNh s#dEk0Tf*Qo:)˹~aqۙkWjXE1Xy+lu@!otܜCt4/o9i{w9YT10g3m?Oؾ2Rpﮮuc>KF(h[b}Džrl,4udq˴%cw.U,P7'm-IwŶܯ2C.g+Z-7ܴc{Ū=>=uky<d:7Zaj1i2H)C\}v3Wp"VtOv xeʨ~&.+Ч:[Tfޭ.e0tqh֢Mա~7RB ̱"f"d3qs=΢(w Lfd^?55Rf6# 1'c_5~"ť!vleq˪J` ˮl`/t!Ccg\).^3sξ|= }<9̚7PF>/QrH Q} @}$hTE\/l콨oIwP$=Vƪ4@: % ug-3.ضZSUw"j #)>fW;舁v!E,%%T1 //ccB~&T TӼeIOa]@yטCKH JȐp#xѠVDT] &_2 [7]MGzľԣ!G{El- 剌L>6ʉ /0D`ޯd*0K;+ ذ[VY!3x|Z?B,]7yz8)o_0yOGȞHe  0ʅGȖSt@)5f]$cC&ƽmIJl=&7ԐCRIq(bp yw5A9T_.5O+kæ|!GLIPq@CCDd?D ĭOw }q A/+ߪybou+z1Qt"3|:4FIH @@eŘO$u>0'߈;"}|pz?s^[f! m4OmZ;F`! +.+ dm/Ub~S[bl- ץ]9" gjhGy FX\9B,|L=?xڐYUlXcp'C3|?BN0auUV|<"|]Twy$v-{Q.gBq0R4s:mܜ&::=D/P hF:\W^PM$2u)9X'ccQHpt֌Ebx+v'H~SAaQ[ MtoP`ݭLAU1h#O_N+@ 4bI3և0>0*@GSʵHɷY[swʴ)a͕^X-&~ZI)gw3B4yt^g+d<*!;ތ͵ PjoxSl I"d ߘGoqJШlf_HO㘊 >{ĿgALoHi}u( _mQp:eC"]&&ߦ*/VOpzhiK"+yޖm+6eFIHrR[ 0vL06mjBd8&+>fh!b&әzV)2ggs( Ћ&䊎ҕ EVZpM3_ZgÚBhB^_}NwW2Vw!2AMY/Դ]84TnۡEs^szOv w/F&7d|Mh3+cXަSRUEZd=%YtR7`YhG->_:~_򔦻3Vǰ֔-@įTtTݷRoX>Ev[&.lu ?h8(@sc`wUR#-bj@sӯ8qA$S(1wD6K+AQ',iUKHeeJ6>h[Tx ja{el*D{eR%}o($?ZH_p5\P>3(71^ECYu"#³"Ug- ?kV A1P p)u;G)Ѡxcz+_ xh@wl?*gMRٗҫz5Xt(m#=Rˈ7ndד%~]P6n' T7I uiV踟fJ'4) n˖9 E ۰_I9ާSʎqf2{hf WUԉٖ4JDn`嶋Vе5eF3e"1.v@V2IV}R@Z5{^եW*,0)7 ?8UԀ.H)vwek[k4/ITPgm7MW[QZ-0ÂT.ɨvT_)~_\$ *btz F<Įnḇ5BӥʶFno)r6ƨIP[Lp>s>Tc -!r]]:c8e.QXi6LֲZ;]GƈmG'I;w+j,t%"C | 7Y)JɌM+`dpJ @3}txm?b19^J`(u|4Meqi[Ec.\Ewqt%%XhF/&N(&( ]C203wÝdGRb/aZ&04yzw]z# ɞ*FULAhMF;\ )u=G#4qT&'l?1dPty_\uغ"s+$_Q.8GY 5y*Owb3W&htβ5G6ah&]Nϡ,?7YnDoIӝ:=;@7]Gp݆i 7Nn׮_,zn2P-X}mqQcrUT0q%%d±2\|=jgq܋5O>o$f-| />L:"^-j&jj60YȎ] kxf>}SqLgԉ@{JZ~q_KQvsMq/4ArqlҢ{xLD ; LI3ZC^;x*B©ݲAMi }/~z0{ݨV1\0j[ 0%2^ꢯ9wSzCe@՟u-.tX۲Y̵** xE+PW U'm}wS7J|Щx(e LE휔ҜWkpͿ#`_㓓*YӠ73S~+>jg )}@HWu' 8,Qܲ=Ϟk8/v_UgX5E@Q>AbLKZK>PA=1j. 0[rlr0Ҏ枷ɂov[َZR`dWM']zq>ai`iX,])8e8] 2fG̜5Oܢ+-z8578EWNFb6[οTM Y/l2KnU6Fh/FEUmOrWr;g3w;Na+3/NL8,rlk2ۗ3wP^TNM|Qe3ڤO;Yu"*>kCL1to^>x^L NưСp7[??Gp2L,!}7$`uܶs9%B%oB^` kKDq:3K%.#I)"U8@]!zx,GѮEXqΖ)2 GGcoI/ .LÌs0u+?<_5.AHiͦߗ>U 'x0]y< G}ĽTշk:.%̒ G} T}W`c~R|i&e*c^Vud'mAhN^*w mUڙ`1kT!mA^zw yΡ,=vqM nWk{;J^|AL2 ch.nVN}AXK} =>B4bB]R{Eˤ*rc~SX;J~66rc6 Bkn꣹˭Y  /@ YDIhHd!R6y5ȡHG))u$Ϥ$D"3G U5ѼIh„%SB\!oTe@!E![»~kHPbb WtW a%x K_merW߄d>\mUQu͐Xsn /o-q2aѵAі[P' ]Ѿ!=u_4M3(px3wɑ9NFNնJؓВC| G%cxP"M[ǝQ>a?|F &m8'US i* ciqJEeoY./vwD<Ј7Ս p*AUO ܟ^vyxG~kL[MPb^3RwSxӔO⯮_@[DOE7fw0&RAhiȼ +!%Kl>) 4M:rʕtnPu YSaƫFc"R\<ޯv%/Ei05qF#sݞ- z'zw+k`\G٥a%E&jt'^zkVX|xq4R3RR]3`r 9ȎxA4 } je3 ][?ÏP[qIob t:)T\\*^LKW g=v[_@~CV likhQ#N_N,YM1##70,Շ(دV9'NIUsu23ćdNLEvxLtSKfK_Ye KZh{F_ՄFC>~e/2Ji9Aj SKԯKY {Wr6DZ`rk ,PqiaeRM\Aerg @Řly"}PH4 P|X;HcϨ3{[.&;m[W{;*r(ak>˕({ҕ.t}`C~;H"lGǔv s9&v&$/VPmƌ6=7d A;[}Hy[FХ͝Kυ`!"0oۜz)@ddH2zJ n!`tǸ"C~H$i{>+ Kn^I0{v%rd΅UcX?_3tד 5n{ {H]W{^̡'~&>s&Xe~ڐw--w% xu~u'zbWb=khIWb"\hXruDQȟsX85}a1s3&' !&NDdnaݟ"` _Ֆb6\n。9{LZ@v{ (nthԸZsQvon+*]8̵]ՉK8;e!iT4aq2# S!<`S1#MUQ{ohצ~4IdRskذ<|D_o[wSZ#Q&?^k EN*K!0~Kzp霄Rq632Ɂ>,SVJ~brbeWDDCZpkeTlxJW7#ke989{S$r},VajIX3;{w>ej䨕[L n Ыy>RQ`oAmX>Gcx`HV$>_NK[B#ž7mxRrD QhT }A""W;0 9ۛ )hiO6 NY!H*|an*&(W{x_~~xh$΍.jgRtDpy/*!vWɇ騠^!,pZ6ț43ȳZ8\ kE:XVr/}}5s֏ǷK+/em.% .vG>з( -ԯ 7Z$EA }$V`QUS,`Sd>cchQ{1®>؞kz⌺:00?ePm ;˨Nt AMJw-ИsqΡq$ si r/2DS4uy܁0Uo{\Jb|Źyr`=1X{\*qR9Q /]5g>}qd:6ш^QMwec 8XŞw&|HD&oZP֠!/#J憲Ѭռ=}žcS:h |!)'OcߍT l~.s՚NУV>89CޤpM] #͇D] l  ,jq([4E3V1 P3|7K&rRxm(I=o@s_6Is<3k 0!_G)4lrd'OS3?za >0eccv8naIYU) }k^~!,r9ojFMųҁ)O XC\nNh"J}n~f%.uvzmg.*G y2ٛJL2G"Yio9 ")_nJƛ k.\IYM^fp #Vi5HKg{:WOZR@3TJ/jA:]/=r>X688Uك hV*I_ jHE;gP5\P3AfuB;089B8 # ;9gC nU}aMAŀX>Ҡ]2!0URsAԼPQjb?x>Lac6"+\!U4 pmO"w Dx pX]FJT;)SC8Y`ٯIa h c+sf&qV% KcB4.ygbnUxu<!63<&/>3s8v##[w$y^UhQȃ)Ṕ"6q8D ,, )Sm39;paF99{(3}<2kۼ}Ci ],zVU{ad5\4GkaAz {)@W|F,Vw|0TFehj˗/ ;:MUD֛wb>}b`YȝM$zm-/L=|0ttM ^`ysBn*݄Z\1h[k@ RwvD>D}WO1+!e%:4ڟ%}T;R݇,6%Ύ_lQ٣Cy9lc# <#}֯T֯.29E#J$(ܪr;pR4 $y2J-ضBPjVAK16Us.x|i?\>S%>r&K̼"'evy7Ђu]DF؄تkC f<#5R0pY-*)4ܦ!vV 67=4 N$?^RI/sŋ5A9A e0wP Cї0ES*5'Y +Ƀ$DIgPAA+C4O_=пO?/ĕ`Tax×Qfh:ϪpA]aIDE?-ǟgGcuRLݦN%Hx{ϢM6Ѭjc>&0Ʈ4 Qx3g]mbbfj;34?r{5@1 5eŸe0%S9W(dowxcSlLe"G\D29xWWSwIin8t]/uO=I}7NR{xRjȶ1xo)Y0#^,t[\0GXPVTmdPn>%Oad6#a < AX!_# #ݐgqp.j*uIQ2loP:{Fj+[;f y?wz|j[x4ln"Xh}1G*lK}*46>j ,; vo(=#Yb_r$PzBkߴW~mҫ`y@%ϊSǘ +WA/ZiDXN \糘"<+Rڝ Q?n.,u:=+46ثS3s0oCꦋF y\0v>oBzpN_V\VAqVExdޅcWo'0B}_݅,a|r%:ncWc4@M7N\HاװTwdo%xyrq@Od2TyUa<~Ʋ8O6©q 1pBbmĻn[#U$^C*<+%Fqn?|Q^, ,XcMaop*16.?0(N+­m)>0*D@yC4fΔcmӤM:R5a ״h|nSh}%E1ƒV̗G1 Ds1dGOrRgo7u-0 ҂s]姢=aiTl&}9tJ>*Q1' y`N>Z[2M[l+]NᇐMt5x v,&嗡:TJN^u(jb ^ h'\n: ЮRoR$2VGs7#+'طB((LHARRS8Խ[@T'D9u11pͻlEDY̽ڌ1|^jo5ߒ }+}(.rvMhQB^xꡑSBWLu};p GƍEhsF%ݚ|GW/xC& A-F%2lB3ye)Ku~ߙlrRz\h_r6B Tsqb6JNaw nt!Q 0rjX pf2XNB=@?.`B0J՗OMR8Vx^ 7QɢҮq^TOH-'ĀrNwEXׂ)zry+э Vʽ0 ؅Ѝ_}V3?\Zm_ ^,bZ3~+|&㮋dg'ӵX@;&H=) ;ls|Y&`U;zreR k |d-QV#4GJp *h~[#B3W/yNwgpnŀ&&UN2 Xf#sù[ 8e lTZ\uVNw?] 6SdOJB ߦ l,=qt=7D{J6v7WNo\C6 V{PVgƠ=nTXÆ(]opMRoݻ Y~vGP_#h A?VeF1nZtd4:p2Vj# ^L9[1@WbX+h q(e[FOBH>>YoA=t<=N+H -T粋%ܺI{%Ú xKww&gKetL#,_hgIshڣWkjˏը^[YtJUQ멁w|uB\ Rɠmbً3oe~?V ljq*sg<%Ŷ'<#V8tS{xMu"k"|_/5u܆70[\2Cml b93YPxxa.:g'A4q-ubZa#k_]1{m[ %Ko#F=:  l%̥4Y`~ECxPKW?_CJ [*c{!"E%~_Kp49=&*`pZ^:Ҥ {Ea{Qc|I  =}k(i m"`|zp[C[ҧzZ`UIBԳ)1Lu >ayh(2 O0$E{|>R"?s=(??<0F^niƗi07\ AuJ"8 lV]~dgD+ۃ~ػӘ-˹>=UbPBD{ atZ!MThY!D)> \n)N }uq^dZ0A[U+Bfsb|#q.p]! y#b-Px%/ϟc ex.ɎCdԬv7AD̢Q &ri[df,a"x(mfu^*i/\1q+:kmʬ-\\a2Sp5sԎU.2SqDWY'(dFP./jz9IaAgB<΄QjyuA{?^3ӕY AnE/׉ ˛b<`Z^¥^ز.{f8ms]Lņكt0\?_bYɓC8 ~S+2dlavJq Go₯HrNOS [Z+CM/3Q;u!O#fdהq TRx l:e.M.V[ 3 |%Q:^KclI|̸xk# +SOo  7YzLObbmM/W81& YcK?}d @ʼ=5: Sk, X9:;—JKkklUnnjұ4Xan93jr_bbpt] W6FFʼuOɜULv^䷊R,١=@kBLJ÷EgOߐ^h|9;R SϷM49nj!Vw9f'@'KO Nᅞ!%F܆g 9z,}  #-;+K^yuA޹<4S}]x9Jo6Fh.ҋK;}&dXl}fx56np>Lx%݂l8E|~m[G\ݠY\R49jX_ãvٻ[q-*uլ7MY=D[Ji(NOT(b%?C-i D!%JzX.wxvTZ3}WB|6ۓ0P2ƯQcm[8(oG2QO\-^K2$3o"ܓ֤Z 5TV=Wv;%9ilYwjo@A2zTC]'Z-Y_e$ŐK>.VVp󢠐u̥n\=%7^/zhw wvY@<:lQqO, y&Po$fWϲpȄ] ( l ;ݖ?Rg@ flnQ>u17e 4_Ҋ~F1u:<*Y) ;%>/1 Ofzakh*J֤?=bbetcۉwdXC+?I. 7S>4}\x7>WNÂ֎ym^I#4dɉ2}tWvGy-Q ft4OA`)9}OsLe{Ivp4ŹI|#mG%0Եv P pO"VN0£>iH7:W UxtK"B+i%j2 H_vRm4/y&Y*C{fE/?mf~N-靻1$ qIT%T'?`>}´- o..W>[Ѷ5U8 n ?igWo g:ǦCvhNQ5˥?;iջ6 }/>C߷7%enFw:pZ*A3 4vY~Lobn`WcJ¯ kl':yyV+vx'^!N3TqAJWYśu`Ul&%<]$A%T:pϒ OW 6Hhεp?ZFb#rGg= 0pS8Ƌ$UwSq#mXj12ߍW,<=yR0}[_MɊXX:M|bK I g>ʳHD q{0=Ei\ "yNϰ^ANPpw|~Urd+黲'МhRd }ԆӤvNB )J$T1G+a)¨K7ʆE0U7 ɤ9+ Da)Qz_xǜ !1;lGry_ ,d}r)"q,0xq=yXvkJ HyAZTF6t\B xHƉ1/ng~Hg(5пVɯǝe'"y VҬ|5ѻyΒWh\P_3E.^4EǮx=x\X~>iXE`*yLӰ P۹%l?TAE\gChh} Q5#*uLHws*[Box߆XD,˅(&W&+ޡ;0: B`qe'QaZhiP'HW3%GNݠ $`OyMO5ZU1L!u,/GRۋ,/`MlT|~ 4.CϏG+T`f yzWd dE坻a:ۥw Py{v#ͅpAa^ׯx{uZv&/5ɿi yR?Jxi %pv OszɲcMPFmX:{ȴ&K™ a)UI5̮:<(/M;.}Tط .M31d8Ŕ=J/YCohsk3uL^٢6 W;JGLdU<%-'*̤Ư?m[_~nx0ߤ# \?6er,RI Ym3 'V $ZJQ 4PwߝjcS!wrd>QX-(dRl̉K3=_PH]^ c:mb҃<ϜؾI.K AQL>'8bVW4#L7b(;XFiw.IUXO )<Ϭ#g1#: ly@3aDdYftVH}6~ԙPAuK׵@tw n"ًsh @ogq5n0"KY8%R$hZ 5jKı7a6Kސ|CVScd+MVܣDvlHY^qO6"8uslVPB9C S=9l/i##β:n?OzGޯ_/Z1wC6siA%S"+wʻ}#Cu& "SŜm;-v`K=70^+ڔ' O>: VZz6Nh>Ym8 F߇T ʄv{zzkd53ԧGfFwJ{=ja|9X8 0G{j1Bf҈:\XʆTt阾 "I BgHfB RpzQ:翇,gECWMJ{:hyֶ _,d`ClUb(~F$-_B{|RB7Y }_NjfR}sEJF61ԣp#Fl ?S%5{lp~JjZ81$(kA_'4DߘڧT G5p0Hf!.pcݸh4M,6z6AhdClixDPQ KvH`z0Tdݷ]`ۆr0jчCzkxr|z+y(& gvY7|}&(*Nٸ ؘoBɯ1L95(n(t;}\HKQu$,TyrC.m,YvsZ'#+czwH6j14/UΦ Ucx.(сUUnKiԼᙟ|khaG0e0a{`f52 Vμ%(>{&I=]R$|-W]ذu!F}! =YZ Q/#{.ΉHk;!E_e9P^ x;p/iJ ԬD`Jxŵ鱯kXd}mw~mXdc^c#'A1qU_-MMB?qsa5U+-T کJ2l:#xijRP^7! r 0M<'|JwP.4FtZk2Y3EҪ`,Ȅ&&n<~J_I, O0>|d&b|X5u/*P r/8mSÒ3KzM ;[%Q;f~֝/<Ԥ?Lj#.fK^}5?O{lӇ bL>ύi̟}1t`F}[.~l_m_cT5|" /\6]YF2E[!5n) <r,"d0k~[-MR&Dz'V䁉OT 5˂L hY~2B Pw$ 6Esl~x,bG^*`n|7܏ut7LaO!-OcMbm8aFOlKrQ/ZaJdޕ Q;6--rafE|X`xAu^!zezU}kW8~DuG-+ԗ "=kW!<)-r;RGϹg>,ȥ`m:jVMbD &+'rMQ={ 9)C!p&)G_Dෙ/uMo>LǼaqB:6-3`,Lxruby řR-UqӇzMht}iDʢ#2BK6ʡmDiLV /yóJGFL@)E0`jUc5j֜ȗa7i:a6%GQ$],Y6a +^jg0NwSϏfd fTl58H YT-<#|Jťqjƽi FE @@>^?"+h.jwmg4_V;z}" 'C-VՖQK+K]]%ZֻF\ ෽>F_l@O%>dóKHk_&^(?ԁ̚4Tә b `dkDʔ30WImu~ YU~EHGy &+jRҵU9Zjx,u.] >1ڏi.9U45Hhyˈx,ΰAE~COXlr17lE ]8Iz _y`frݥU{+3ܚdlDr"3\ E4Ra =\+/wut+dVg%@#7> Izg u9v;QJ.vIDd蛿6YCkclciÝY+q뛙o $~ds'ϒcJY~@xoG}IQnQGKu7n4n"o <'Wр~aa8ݰB #1 N"}eXisA[ h!^J<)tMPoIٱAՀ3s6z/b[yQke=vciް#j}o&Ճvg;`~kaRμ?/¯~ %24qUf\,fWM,r}.aSklPW9!y(;ZT-99G~ƪʸнBqb2x}k|@uŰ;)3tp k#oL0!f|UOK+!EWϥ8I;;aMxzca5K\WD.xZds7}^l>% U\팾 ZS7=f= i5ݔ<ņ1J2$ϫLLOس{֣-} ]~vfN؏f(~Ή$>і`dg7 *Rrg02(: ׾<@zg]٣ F\kŃ;4Q*|W7U =Z%ebs$? ^>cM #4^ݐE]%bf}7*FEﲾNƘ+eXň6B_<:&ZFiFGi," |MVhߐb1:Ymf1!R#v8FeJc28N4=KrsroC$Į32XU&uW&8 cH :(nA_G[scF+~M_dҴivJDkm\clqDJҜ.̗U W $HB,ʠJA=R, ǟA1 l$膍7"t tO:~Cƍ/tTM #(lђlqᐲYA?ȯ qnTM,M,9xkZ&6z E=tŐ!SS0!۲ΤS)Q1@dnP_'`U'6Qˆˬ\3o<8JQScFB.5W@9<ɻ@_,TʖP3k]Y7A1{dYQ&/zL[wWOcm1oŏ+ .xEYOm5Y&ƪ ¸ܮMV|a(-Jp`.6S G,Fr+շR SԸw-B1+gCÁ-̅#$&|h-+3|{Qtz)1k8zh&l_EC7=rƟ?o"l6*d҆"-L†D,͑Qʸk_sk]RϑbCD_vv 9pߠƖK̎"ʟP̝ĒF #Q,%`]GU^/HEL  RvφE6ҕFJ_PnG[֯) Deys7v3 b]՜wcխv{u)1f!qUǯJTҗ+ǜE|fn+L,ks~j!2'cwledAPq[|IХ,."0-bE>lKs[k 3,Ş~|{_J/Z"OX5gUq63 gƿ)$b(OVa%rYAa| ޾X8%v<)Xcb8?K!?L"~slRVN/.X03kkBrjϓ+RLQڠ^c~kl=b[Ӥls$ Ʃ jj͢fr-ҜÊ'ȗZd_)+FAg,iMpX\mK:xJΞܢ]"MmEm{:7a7ܾ8L?݈_j'm 0f*_r>(C>L Pp})K0ܦ+FeS;'. j9E !/˅n&Y Ra{Q)]Y*ʭ6,m;w4_,<۸tkɀX/l")7vχh:W j,λMUiwOZ#½ZQ²Sn 9WCB`8ia,i (6EEHh˜݄ݼ&!Kdo/徕62,Ri'r9f-8Y2r@'N7כIPo\008njipfv­gW9Zq@E)UZªۭ!~(ʫݑ`&6,1L/a+8_ $M`tRI'ZT2W1.k2,M e5<pe-mEPM%Xpfj: YZ