samba-dsdb-modules-4.15.8+git.527.8d0c05d313e-150300.3.40.2 >  A c߮p9|(&8 sbr5͚}ŔaCi"F{ϳoК` MCޝ#X23#U-{*Ёs,Pt%VߵqO~(";dwF?xYĹ*'c34bc6894b4659cccf23271e5de2d90583467b37c4dba6bddc4105a4b8d67bd947deb1e31c7ba2a7424d27236bfa0f68ad1af37c$c߮p9|bVhD,&! e6o'zQYsR#Pg?+Rx*~BdPP32Hq=뷄I(k6O54\h!=8EP4rMRkc"?R4*Fx>i~g𪻣Eձ)\>z$C!n æ@ҿךm:o=n\<XGt3s$V4`JV\^ZYxd/8}ǖauɿ t\61O9|'3F[20>pAmX?mHd0 > P ;RX`-|- - 0- - Q- -4--0-uu)Nu()8*9.:>>;@;F;G;-HX-^AbA/cAdBXeB]fB`lBbuBx-vC,-w\-x]-y^@zlllmmDCsamba-dsdb-modules4.15.8+git.527.8d0c05d313e150300.3.40.2Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.cEibs-arm-62epSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxaarch64rm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigp Hp Hcccccccccccccccccccccccccccccccccccccccccccccfba69bd47bab1ffb572a90c098d0fe0688b23fe1e0d302a13b3da5b43d8d551af0750f0ee2bbaffa4c0717552b732a03411e194e7db1f487f486396d71ebc37fa148fb5a4c731fdac93237649b0bf580e744d5ecbff9fc1a6c21e6d45342efe59d6fbf6d4e4db391a508c1638bccf91b19ce32e13a29f0f989de09ddc665c245b5956c3a822341c2b11f03486ff659a083e4b53079ba7300365d9496979b50f7ea51f7b8cba79547603944da4feea844b3aee77431953226a28f5fbf127a1a8dddffbd457851380fcdb6b075e8819a35ebdcd0bbe2fcb4e1b3a13a733a1bb2f2632f6ec56688c9f8ac24d8fd52e08ea5923503c0e652fbf4398f9048bb0e4e776dc17daa99a785cf90d353c479bd82c0d4cb497789aac47484ab5237d4159cc183400c6b45c593cb862f2dcdedcdbb2c15fdcde1212fb35f2b468bc2e8c519578f1636a7df7dac14202f7df3c84b208cfe296fdc5879b326530ce7b45c86781e594baae20760fdff7ebf74149ac6ca28b1f3e9e6f94faba61bf28bd9b88ab319a682c530bd259b31781e16160fe7761328fa5ff8bd75cf8b9469c0c0d1536c8d9d5c5b52f1542b85d428f057e3010fcf0b3d8977301e2276168caccc3f85eb1131e8f45047efb05fc6f74256a7fe4a0d179b806fb447dba8571f8495dea7b8a9a25eadbab76b8dc88a3318a50fd2740d08568ecd59f2a3f72e90313209c8a7aa893aa5ebae285f9f90696b088f6432b113c283927da518d0f82333e7db858b6721bc6b2ff0c17da9e872f27d55a1ca67e12fea3fbcda427776d29443a080b7e0d08e7f17cb9ba987118fca91539cb993bc59bc33d35fc02da9b3b5cbad12ed04028c239cfe6453a3a971d3e757d93eb9e471f58639004a7b5c65d6970a6433cb2ddb1a05d2cd2faf85d56bb8d0c6c2f59a35e1337b50415688a339ea698d4d3a8d50512a5ab34eac35d756215325cd33a46921edc265dc96fd661e2b95511a5482db1738bb08689a18494440737f6141141c9dcdc96bdee78d7cc89370f604181e4000588de534be2e5a2619ef00e1a85345ca8d171b6f76a3e5d4b42f307d9398e10dd90057eff754108a01a3356c663836553bf42779148e50810686c4dea8e02a4329e598d5f69e81718fd7322dc19b1030c50631625aaf70ce826a45c0fae48fd2c59ebd1f57ba14c3277a470571b4c51807ee983523a6dd2218f62136798d7c114f5fe45501c46c146cc635e0a94445989d68d8ca102ec667209cb8d91c2235f74b7718cb669a2d19a3fdf2d473c8cf06b5cbbe08a3f480da0e86f031a997fbda86550134c1c008922c4a5efd044ff2218ca69514b8a0b2792acbc12d9d72e5a589a3deb8f801ca3210d90006e42709354bb5ed509224f8984c654efaf9cbbf822abc0324fb0509e2c304f3bc304f8ba5ffb701a139665421a00b10895d9204a5ae920d7e1791010a595f9d03faf30016e9f9345e05982d1a17b295097efcd33a45f0b4f680590676712ad936ed5e985ddc0fdc408f3c74d4943cf5fca4468f797074c4894b559c9ed08b9a8c0a2e479186414f12fc30acb81097dfa4450a9836d5d8ee09af9d35fe6303dc4bef7ae740767ee643019b5848c237dbc25e2016f99b7b844e5accf94a8bf29cd1f00feb32a1ea97807b7fe2a041f6a0a1403256be8321beff7a0eb6c8a757f2347f88e422e4ca5734b7e18987b366b28e07927020912f84874cde54d54200df164468eb19f395630aa91c14d1cce443a7caf3ecbcfa049f1a802f2d017427157870d12c30deee0f61f1007557520b88d2df69619b69b77d1f82a4e911a4beeab60f398bd5f491c4d23e26c915a18d878e0ba3d32e6a482ee13d1e0ace1c1a07fe9af312a26d3092867eb0c15346c082acbc6f266d3c2b32a8d2db0331bb0d97c04971fe389d90debe74f4e72ee5f5a0b362b74ca41deeb171c7b18347dbfd240d86c5894b28cff141ef501d2a32e912828d24fda6b7245028ce1d4df69aaa29df5a732791a20a1fb4c296321e19397f9695rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.8+git.527.8d0c05d313e-150300.3.40.2.src.rpmsamba-dsdb-modulessamba-dsdb-modules(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb.so.2(LDB_2.4.4)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_AARCH64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.33.0.4-14.6.0-14.0-15.2-14.15.8+git.527.8d0c05d313e4.14.3cM@b@b@b@ba@bascabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigibs-arm-6 1662115141  !"#$%&'()*+,-4.15.8+git.527.8d0c05d313e-150300.3.40.24.15.8+git.527.8d0c05d313e-150300.3.40.2acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:25692/SUSE_SLE-15-SP3_Update/31bcd539228044ed3b978b6d5b198532-samba.SUSE_SLE-15-SP3_Updatecpioxz5aarch64-suse-linux  !"#$%&'()*+,ELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4db5a2b1ee328c21e55b0e11a530fa030c38e4cb, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5f73c0d5502950184fdfb48bf3de10b9b3e6fa03, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=959bb10bdd3deaeb1f1ae0f4c15c0f2bd3fd737c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fd6f1bbca2f3b27cc6f831a0d7073d850730f396, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6a242a9d281c89a944b924fc6256b1ce9cc2f92c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=93f83e727da9c526169d9dd9d2c9649dfb6cbec1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9dec549494d1f810b87270b701a7d91ccea94017, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ce011ced4db8c516db16e2d52da5d25b372c3c33, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=da5ae74f8576f9a01bbbba6a2dd4322dd40caa98, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f254bb5a6248f78d354d81b2d08afde9ef4abebc, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=84540f71b1d4c16ec3554f5390ef09a0d7bef667, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8d038d47f061f3e52ffd0e4bbff39514c5f6fcf8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=58634ac61d9cc41451a0d00eb9d0e42820aa89ef, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=eaab1f485de8a90117c38f3f80b926a2b8e9a9cb, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=860165bfb0aaf1c30e0bc3ef5970e9b28e2051a8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e267c6b88d870f2d372910005dfa0657fdbbf5fd, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5df5b1c8e56156b74b8f47ad114bacf64c8b9cb2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5354834e4dcf8ddc84930e03ea3f40a6ec6c7597, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e068627aa96c07248f08055dfc2d076f4667d370, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=177ef6fae6129142d02d9549a84e6db81eab911b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bde7c1c2790d6c337cc6ea667860e055044cd0fb, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e7055816a47074829cea9091d976c3399160494d, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c48c40881589d4f8cd518e1ecc1318094899a27a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f9cfd9fd1c6b93e57566cdaaa32691a3a0ee5af2, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7e4d01b40736d2c1f716c0b84007c5de7ccff88b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=dd1bcea1e1242d94323b4f5d327d52b334362e15, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e3e9184d2b5125cd84b431029a5ee8c96edb26f5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=787d4d9911b987c7ee7d7b9af9364acf03738b2b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bfa04cb99adc6a60296bce7d9ac43e4700e83d63, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0c2cc73c25cac8e228013c054ded6beb33430474, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d4138950f18562a45add8a6677915b6b87b36817, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=30c9b9febf9cf6c7b7cd266657dff58fe9673d61, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=499454c7a12524a1f40cc83c8a7092f167abbcab, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d5dfd26a517806ebb3715b99085aea9a9c326846, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=96239f84bfdc3a886e3a4e018ee0f7930ddeddcb, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ffa4ead1363683e3327fd6bfee800a6c57095ed1, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8ffe7211b9ad0439d543b249406f64712ec8a687, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a1e6348d989c1dfc7b7ba074c38e69eb2b03f36b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f124fac727a74b05bd879796eb0732a240bad8ee, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6050a0f3f12fa97bf99e5c83626012154b3d1c49, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=81450340352348769b7bac556e36fa5ce0dc9003, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bf1b8d51fc74a2d59079e30c3f23bf6dcf83799b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e4d0727e70005a61f47372e06f7257e8913d2e38, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0de8259e9bbe3a3e7a6a4482f92e678d9db6dfe8, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=075c426a34a9f50c7411cf207859ac64824481c9, stripped9Gev+FQZs~.8an &7DOZm~   7 ) . #  R\R?RRRVR RR RdR^RER+R)R/R-RRR[R*RDR]RQRR>RUR(RcR,R RRXR?RERRRVR\R RR^RRdR0R5R6R/R-RRWRDR]R>RUR[RQRcR,R RRdRR\R R6R-R/R?R[R>RcR,R RRZRR\RVRRRRXRERFR RTRRdR/R-RRRYRQR[RDRWRRSRURRcR,R RRVRRdRhR/R-RfR RRRURQReRgRcR,R RR\RRdR^R RFRERR?RXR.R4RRQRcR,R RR"RRR\RARRRdR R^RER?R5R/R-RRDR]R>R@R[RQR!RcR,R RRVRHRR?RkRCRRRR RmRTRRdR/R-RRRRBRDRRjRURSR>RQRlRcR,R RRR\RR^RdR R/R-RR]R[RcR,R RRERLRRAR RR$RdRNR\R/R-RR[RMRDR@RKRcR,R#R RR^RRRdR?R6R3R/R0R-R RR]R>RcR,R RR\RERR^RdR RR?R6R/R-RDRR[R]R>RcR,R RRR\RdRRXR^R R?R3R/R0R-RR[RWR]R>RcR,R RR\RVRZRRRRXR^RR RRdR/R-RRRYRQR]R[RWRRURRcR,R RRRR R^R/R-RR]R,R RRRR R/R-RR,R RR\RERR"RdR R?R:R2R/R-RR^RRRRDR]R>R[RQR!RcR,R RR^RdR R/R-RRR]RQRcR,R RRRdR\R?R^R/R0R-R RR[R]R>RcR,R RRdRRR\R?R/R0R-R RR[R>RcR,R RRRERdR^RR RRSRcR,R RRRFRERdR/R2R-R RDRcR,R RRfR?RLRRRVRR RRdRiRhR\R;R2R1R9RRUR[ReRQRKRcRgR,R RRXRR"RLRoRRTRRVR)RRRRERRAR RR^R$R+R RdRNR/R-R'R&R\RRR@RMRRDRRSR*RURWRR]R[RQR!RnR#R(RRKR%RRcR,R RRR RdR/R-RcRKR,R RR"RNRRRVRRTRXRR R^RdRAR\R?R2RRURQR!RcR,R RR\RR RdR-R/R?R[R>RcR,R RRR?RkRCR RXRRR\R^RmRRZRTRRRdR RHRERVRR0R7R/R-RRRBRWRDR[R]RRYRjRURRSR R>RQRlRcR,R RRRbRdRER\R2R-R RXRDRWRaR[RcR,R RR^RdRR RRVR-R/RR]RURcR,R RRdR?RRR R\R9R-R/R1RR[R>RcR,R RRdRR R/R-R1RcR,RKR RRR"RLRRRERVR RRXRdR R\R0R/RRUR[RRRQR!RKRcR,R RR^RRTR RdR/R-R?RRR]R>RSRQRcR,R RRVR\RR"R/R9R-R RRdRfR?RhRRRR>RUR[ReRQR!RcRgR,R RR^RRRdR RR`R-R/RR_RR]RcR,R RRRdR\RR R/R-RR[RcR,R RRdRR RR/R-RRcR,R RRRdRR R/R-RRcR,R RRdRRR R R^R?R.RRcR,R RRR\RdRXRR^R R/R-RR]RWR[RcR,R RR RdRR RR\R-R/RPRRR[RORRcR,R RRFRR^RdR/R2R-R R]RDRcR,R RRVRRJRdR-R RIRURcR,R RB?9?oN8X,Lutf-80afa4b0b143fd5e81689b3a1829a15f61c1ae1036eadf103a31fb64807eaf47d?7zXZ !t/_] crv9wga6qC.0ֶΓ8N.=rSR# Zq&ߖ#+QU}QAE _wقϏc{~Jԁ> |Kϑ`r+T%b!Ew + :c}C&4-EdjC-|q(B3X2uPr^#nłbgɇj F;_7N5D>MqaN"ӗ#o|,uHQB7dyGq`}&ܺHx/mT)GX0z!H hvղ8ժ׶~ƒ4#7PME濔܈ [̀ +mH/̓6Ez+Zy+H ŸT{P&67 W| 6R'{_!@MM@<9n~T8R3@LIgw,o}L7ɭ4ޓv'NPd#N MwL,`Dˌí4-R8D<&aQ$rr*ܝ9ܚLdH$b@^w1樔Q:ۙSv6F5^Uys)#g.,sASτTP:[XRo=hFZm{DEdA5c#N%NbU5ˬryՉEϢ GY?ۍE&j:^M,9~[q! uQ_6Hk03HgZO8H)AwʿE}jℭ x Sl\ymS=/.1J(?wgJ} >h|%{) FQ_SMgޑXJ^|b+SyKOQ帶kC:3-!#وSґz?~T]RPdhopl-t [5f_Q0^K>@4qX#& g׺Hvy5KҔt)/Y}[{]VIw-wݜY'ހ,-i6[80Zm6wGH7Y,7@?`57d.guPO LnΫt*QT =k U G.LaO>{S3]ƸʍC$a7|fG9k; {K ΔA_E};x"Jzn# &%j:H!q3щdovG#ZOȔ^OoOqS}gFt :^Z$}Kh')=,{ +.tzXX " }ek0ѡqⱞe ' O-#1q5ns )X=Ш߭|R⯮#Q 50 ͠[`^ڪ݈>)d"T%?:^^r{{CyJ.'{N=s7໎hG{j5P{s\yݧ?p:bgkv pJS ? &Iz/Cc!vk(+Sw19kt*Q~88abajQcq\[]y:5ˇZ~ޝS[~|Z EQiގMԈ 8K+;i)V\ID&{Wab^Jj|Զml05ݚR"bJM)>TJ bofn1r|`:.EH$na$o7/J^UƁ̓Fu2,Mj?:21Hv6 ퟐ5 9ȾJL@5gRɫTbi4'ɫ5̋Om kɷYEAk^HyNzM3':X# *[5k,xDv&n $K܀mW=}U㍙LC ®Iy +1(nǮrW{ѕG(mI+.hyc _(1[;Zp?J o Kj%v!@ >B)0ÀU+GQbȒֆi k?(1͜ *j>ٕBU&g}vb<[zd V`uQV:>xQ|M2f%%l`!.Ч*gVe2=kvbV<yRY`ק.1?T|*r8NP$&7k'%nLr+ҍ` Zl]lDϧPi@/*;HFHԛ8mJh(J=Z瘛뼄6Jۍ(׹LLKT 7[h?5*=&H5!Uo<&9f(U@hH&ϑ-uA?7 9FXޔ*h´BNDnp1;ɥ_K_JU4Sk+F!T*կ|MXαN#:muds*"z;&z8&3a5@Cs:D_#Jn~QYƱ:.MB !Q c>zV#} ;M {NN1:{PBhbba .h@tyO&L~V2WV\b.EiHĴ:fe< !%W3X(-rَ`U@>&&tn[2#u48{S 3֢[Ev_~ƹztcjQb|wT@CsPVRQ⚢`\ 5N·]uVP!I'uRX]ĉV3]y|Jt'_R/7!v&孡氓gJҩ^bXlӣ_ViwEZ ;> M}.('x3-h_*JyFɉRN@:Qɇ[6!"hC"RL}ɺRN؈}lDe^Mq,aGh,)a6 F91C6;MQUgڬTt9R ҝsL-+yW G?ЃOǽ_ϼ?~\M-rK[;sjp#{ssyVz8hP'|̿4D$'#䡶 z_]W!sutb plj5 ~W5 p&*gjKf V馏yx^a粩;YSc.΄\SxC@DU j63R8!|ꀌC**)= D BHgD{[f̟t{'WNN y%> }83d#fopFuC7gW"KՌȿh(thl/ ǔ^ C)I;/'And 1Z)jr5 Լ8 ws;q?bޓ-jX߀{mЉxǴMh~PF<0:T--rA6 kVzp:,9Ɀ ?KD{#a @^XTȺX ;>Ac^nm] [46t,O=WiƸȗƞ@ LCOٵb_=4jPֈx~ hʔ #_@zh]{/wNŶ+^svML 1 MD4>)P>[2,*QqѲAܘ>),b2Vb{X)UN;dU&YR./^|r͔8SNx~?^4%!37;j+vX mS b ]zdhOcgPJG fa5OTd׬W| R"Yq,ML"N9E{"`+*cnY[FU%Y}>IVfo%8z+N!%Y( \"}#~2kvڽe5+L'{ J Ruq/_FG}zWu+PMIZ5mT/Gfc\P)&\۫0 L1Ϊ.g2 qޢZ"y@а';=Y%5Hal˭Zzvk&7z 9")c~*3˪ ՎvR56ٽX6> zN0veyj8c}S% TDbU̸=(N}#b.ᢡW[AQIsy9\ |yÑ^pAv™詛ePS ƖJfu!5[Rܻ2 T̳ 9y)-׉?_&h\>QI XzN<*'CduF[=6KM{-yG":c>*g$ן]: 3˧K 6a_ϨLDߖ{uD[B[rZ *%$Yr;j!FL %KK@ލkK"[.#3b?+Zxʗ"qp9Ba"9m.S !%zv'~#vsy}WƙW v"n[ 鐞瞥zy!Tg]dqKeyS\,7v |]I VGi?\3d' s$ k%3^Agfۃab(Oe&K_>=ʼnP kDE}*7 ʉ^o,! ϛ20,8'i…T(uNlTUzn *~ =uπ^jN"L|6sp 3"D5|*vӾ%àZ=n}7$ nVEQ*ru-c r 0W%as IAY3O ZMK^dpemߨ=:%nhWBDY0:P]D/-vF'3Xca9wǫsb[t +T2k=Zq?AS>ܖLA g<$L 1 ?[4X^ ;Ah%!)XJRg]V^h J$,iM?ᯝ=:OqҦ!OF{m; !i0?<&e^^luIբVĖ_iMG:eڭ J0j߅aށx,\MQvȷH[0/rRKŹW#}}Dg$8Dd̯~MmGFdzO يIΩ\+k^NNn4.Yyx75[$+:#o05t# <|~1 /sH?G8rEGO)+?-2@UT݊STg'N݅fB %!ܵ:;Yj!.6gJ~ %u'ׅY6Qysbv@`6^OQZqhTR]xKO?en;X2@8Db5e~c/yS<8b#CT-]bK\AW D-Kn[- >ޯŋ!KJEN5&8x+YGv¤ Ja@p,?-H- jB[cNj'+sRF'˗_& M^>l~i~Pљ#?ڶ =؏߄:sܵܞ/ NJVx}G;-e n ٫)&+jb۲HO .35åUgePo*/ "ɔ2Ɯ8^yj6/VN`iKU厌ߡҴsxs`-EuͩűX=Ѐ_Uw>E]o Sܼ@Ɓ<ȵؗuiNkJ3`DlKGg*3 ^&/LQkiY@Gh$=d+t^/M,,q(<,TfC/i E->+gYK`tsc߹!aZݛaP8MNcBGqL $3WDN1]AF;+b|'F-!@;GdRaLȠ^b:R1t$6" Vl@o[L2&*⑞@˸]JXâC;'Wz6M[} #Jx-E3|d0vLbAt4gUeW& mTu7%f,BF`Y lp5 ܶsHZ=sgk(>K4Tk^f{;;0eRI8_Lp{,=ym^(oj @kJܕjѯ OM0f]ED5rJQO3@5J9kHS<8`Ų#4F wۇנh*NPRm\ ULh+2:}lF حze[/vXofl# $Tk몤^U N˷~+JDqܽų* ,o/hUP ÿc޹R9$Ug,ZiF\ՠơ+u K=: H7zC~UKTT}9!⍺o1 [E_VY)a}^@yrZHsN4Ng|uKQ1QTW9JEWYv@=_Slsn@j,AEeXWa^$#aӝb%in5;f@c" ,*77\h3G3v0”8nIJ֪cBVXzc-L7ZhYXݕųHyTu}KztG?͆[3G+n} C4A{^fbPC;oZn2jrx"A4 }ɕb~>RY={}~5,HQφ>OJb'w=+bW0O C[y cb) A+GggCb!G,Xdo96 ^p)>T憧ZTbB6tՠBo̦DlvQ t%lu|ZzF]kćI!$j~RD66ixuqkuR95?r:39P⯯u`G\&޷i҉Qj/I`-k)[J& 8k/Oci@kӽUA~ۍuހװbf~ma G7E`p}ǎ]BN#It,팧~޼N 3.ƥy^.j >0)}:I,)*҃^~*ŝ99$% cީG;ף=QMuDg6O=1TÓ%@b)/VbT6ӛ֢t zơ{ ۰(Rʗ#&kW2MlxH{=j<DE:*9,f1/>`x ( 6[|B g V:4ΕomԲVvJuVQ0%*4 H*k;[O4]6N/Uf#GU^bֽXJpsW  C-UJS#׉[_ Y'BMxü~ЯLi#FVr7|yP &3tӅMXhx*Yuoپ"Kl$ɵr ~X:fpH3[g0I %2¢Ŗ!!;RtMF 1K]=MKN V%{bmV iUi'apL Fk34$$؇οs ز0g-V -|_W+lj#cYyL; $"2i(C,-tK  \}ߜl;:lڶewa_ȅ<$d[Z[XD)Sibf*TwVŌ/? R)% =կ7E)fy6 Ԅw`黗W૧_ i]ϳup!`wTa's@Iڙ} dcPŸstPF%P C"!Y›rio['Nβ~V6/oA|DyA 6'A8uh{ȕ~83)"lF}5Qv3K`R|x(G˽,F JJ!5zO<(·CE$Qu!RW|!es$E}#pݑ$^jF]\RS&j) =|R2^v 巭RCaU %-VZvEc*'䣔O:G^ nwWFՄEd(i}fn. ,94^dC+K\,XbD/}3R5GƒfY X칂DϐE'LJ,O'+GaJ gggH g]U-*]n-Թ{]])vMo|Ü\?]H評Mq^#VpmAt;uĜ"Lk#J" j@O$#j4e)ߨ'XfX BcŦ˸D6o-c](ƾd<!k~rBb d 6֯,)+L:&|D9S=׾59|Bd=ތ>ϔ|8#SCAu\u]`Eթɐ@uVӪm^j U D_Wz&fB~tvy/oك=9J.),Hʍ%96mFQj*?D$#}A6v'37Bf'2*7 FDb\d3F`|F̒9~wJ4\8^i,q7?m4WӃ &ξ4tC4 aKԌbUm)simSI&poA^*c>C䗘Ɉw!Q3srq]_*@fF*]#s n]R _o|>k{?~TI'k$*Uc+Z~0꺊m6 ,{~J_%~o%YƺiA/P=QQ} {WG*D9ϿaPnc6 lH."("%< >@ ܵQv1 zCN86܁Z(Y*io@5~+4LCQq]=;N4xԱ,B dofn$۴& _N, r0bnfwݽT2|hP$>:EJ83-I 8]*0 _\Cu*Όg>m Q3rxɡzm!fRǂYOCxAhAZAJ]Su & -䮠O~l=K9!ևF)9+]ӛ wkrJxu:L_j M,5N:8`)}wEQ]]q⽙iH9OHC>DJՃG1iL<'PU'6JwgE>DT6bnf)̞nDwkm8 o)v1M^%~dzC)o/' 04 x%4" |T&H5\*5BA!U4*@>e`z%߾: dN/U{m(G%~d|۴ŷ=PNU}7i> ;bK4 ӕ*e4/VØ@& J%wL6,Q"R3D\+a)׊aYzR77zBBwPO⩑ ^q\>Uu`A)Lq溸cec7{tU$ MNJ2YCQYPD IL4]U*D A;ҏgR,I[Uj4 ^dˉU) {, wx&j8w'[&sɋ&iB3Ue˸pOI^Z­ )q(C-d˯.ߛ1eVG$-5[[ɣU*煆JKK(V+'v]S?(:s(/z|(JU-hIH:^G_t;bޘELgQ$ʧl B>b ~Cvk*0>*ẀSh7:K̸,hBqIęU3 87آ~\ᆳ:Y=(']WfR2Hrܳu찏+¼ⵇ`ua3'$p1Ukc_cf+߃M+zG;FQ%U"|˖:wl '@>lA3LL%hiAKW9_l Dq zb{`>|QUf3Klo 7ᅳD84.B~(7 gQ ,\Ug]>=_'0 ~B~#vGQ`ûC7dNc\~;k\|Yrk}?n@]ڋEi#V?!Ip#K L#{@Px%/ueWN @Չ5F12_8B#8 "(98h\^]dRMJVLQo>'Y:N֊+3B,*kD #_KtAY/ř+c`zR9tP&" W2)X0*R3}It Vƾmܷ;xsvI>u7sdgukHEEc!tF ^`iRyV9ptbv4$+ '!1lTN=O0VW.YfI^wѦuSD А`9%vIk=p$=.[#-91LvAņY"u.V߅m (C7F'BL嘜B&<lOc -sVIߪ]v!=Z>*'v/ O +=^z܎uo5Ӷ >zCtC:д5KjV(~G/9%hLk*H gӜ$?䔰kVNƇb!r Nʘ;v-^N[U˄nIoTLWt[ 1,B[KLY(P25k̅YcА;{'r(/<|q+39/퍵eFŏKa('ͤ" |DX9i4[ hx)*p Ɵpm:cj[ Uw'w5ʌQbW^U)B+2m[!b2haбJ @CB,' =,v2 > 2xJy<^kQ y8/@bbD/-M-;쓚om TTH#T 磓ıH}W{HLsBh5H`bd6~0vT "Ģ<B :(T) 7{A*7B^r0!4zE at+\՛xDѮ !U1N(gwn`n,??֭xmOeVȮ%ck7ot3fW dX05}^)LbDL.x\ڳ20wdwI,{f[bd^bHžI|H(g$a j;-|!!+JS3pCjS_^`%banspJ(saC>>' L'xkw"յ[٦Uٹ%!pϬ,DMQ@=QLT$O=qPLByhɯs2mI;ew Fe7B!G7Pxh{ЁLhq܉x3} q "Kd~Ռ,}k+!oo:>I%ב0٢n}fnIT49Bix2 y5fFYV<)_<Ⱦ5lֹ--m:# 9yXV&!T?;gBjR8^뾨0 %Z:i;7h m\8 ~X*UHSXޮh<)`䶟f^oFj61m4Ԟc=?'1[qR@H-4eaB8L%6jDCov1⫝ʩӇPx@±RH#^Ssfq4bvHl  m&vV?A6bE#7oi~OPHٓ'9𵽟&/TV0QmBԤ~rp`Idk^G_)%Nh6`T۷RGD!`О.a}b9=""&$}r3N>$OiQ_8ٹ ֲU1I')s@Cl 2QL[Вue7~朜1 "p^;IWqܧ !aXj6٨r ?%g-xLpK'b,m1<3=u`Ib0"< $BzìaˏQxhǑϙr=: lwѩ`1 f6<%DlK>@ I3sUe'1(mi!.r!{M6q2K )H"\wj\q%g]v!U;-Cު"[\\5kw&R )T:Ǭa.yW̠[0[sSz)%+kMiO^䘐]{TѾYkYI5iG7mYUXkI~ 5vO YܾXס>2_!J DL,^8ˑцJt ei?}6u QMuӢð=<pX/;T-La  Жj3ݕ:;O|䑥wcIo("{D{DaLS\γj5O9gr}^鄎TF&P'9` u pzXbv>pa ڶn>v{Pے];bOWQ0 I+9 ]_i߭Tӕ.rz\zcih íLXAx S]-ȐS3FhԧmZHT\z"r ȄW֛2P[ft\L䕭Zlǽ//@EPv5hxlg:*"ϜIS24>ŽAQqR0 `m^:l39|ǡ@hhA3D8wx%$O؟g{p 7WՊ飻4hʅDX(76`_ݪ6 mV`2R@t'rXQZi(obӻy4 $SSիҎJ`ֵ;lYؐAϻ.I?; i/)l[w V# >sgR4b48; ?41ݛ:fPs ӊt) ).`l?A=`"/cz(T; NRnpʊ׭}ܪ&5O2H9dVb&QŭC}wK twz6j%J.rIV¿wmo3uo&`=1@u23e7-h2nT>^ofwA%X}wCy;ԉW SCJqG)=@VXuH¨sMf!dm`KAܤ*ZKPJhkOfyGdSty;p4z0oHevy,5$ꍂyEb;|#FC s("k2pȌ?d9B*}Y*~!s}^"r:DI3SVjN{*sȹ|pdYyӚ bZ~ѧx->xjQ=ϭvSba_gmu_`_3<΀3|s6c)huV*W?K +xlDYD Lѡ3 |yjX-JnM,_5M^zW ʗ?~9Q%էe#MW:#G0F2 V62 0W$$?J©`1vG$V8%M[p8ێgNȏ13GY}ٖTVPRl~DB@LREzڭ EhD P С$!j Si=-턈cV?(z0NM_%.TmSڟS|d.{}II<ZL`ú,nZ^\>brrimi}~3ļ1bm/$P<#PIc`llT@AcI`X|eҟVUX^{m\][9mx_#ue=o M8? 3~{0ԛ& R ۄVWEv)tr.-IGb^e%nHĔb]X-q+|N>GΑ>#bc}YLxB $qjJg|K‹SEt= LɁjh^p azrۙ+4oң0pxnOmEU7ESm9QJBG1H*.'y˄:Q}~CG`lq|xp(`bJ< q]`SW:;/R {Ďسncz8,F*"8Y+ZWX &[0`j X = NDC18I8.o+y^t' _I.^ Gb%_`}!o10bÅWrpK>0HOיӌ%$Py N V$tp3Ir" 6n[Ģ|%QY!%sڻb 4GLE-9#W#jJCY_IQXUp)/*&,VrVr QPىG}qN@nnjyíuv*A~`@7@=hwf/ Nf 6?ZE+g2ؽ-@2Ijĕ<11;w}{9KX Vq5[Z'ĈVy_\q;EъƼ5xF߃h`5%=SO67CMu"!$r• kH؎2J Ei ^ℰc֬IM+'ᤵm T~R[VUC2Xy8Std 5>@y~=߿8͠y|K3'_fԊjahލ멪d.0=-J9~x'8< Ħ#A"'U<5 Hl-"F?^,- riwʩyHh! _DT79m+&-~%Ά I'qhd/dZ) Q5H<: wo'J [ZH SoC ^fJQȏdKƶ_sq& r|J mߣ! fqkE$W ɇ V u4/x}d9-!9)}~Zn|K<ۜ>so7cUQ^ Db0snC:M>utEBݕW\>&s&1 ?jf[ubUi} a:>`㏐9Y%ÕZ6M %%jGdAli&#yBd0&{??Fe3=oDM(MˣXpkbƖ_#XF,IsU(B71C.u"\X:1yډo yQf~ѝ} H ab1bIl=w`㗂% kGg/x~ 1" y n(uXoLdT EN%~ngU)x/"6j5'HOZtYr&->$Z,h QoN1)Sj7y2סGM7E@-<@Ѷ&*j$$O&zjcy qɁ~=R*첗`c9-&|槅6[0ArA7~+%V*t/7v!! ,=q Ƙ%r4 T;=Et bgrzbɷ$vQ^HY5 G}T =kX?GҔ}ߎ(o91.t0"j8[W\iMx0}-Uеd5KQtesqE/!|A_c5J ݙaVtiMoz9!6|E?lߵ?#Dη>|dlZ@0xڭJͭ߀pzt(QB8d SGK嵰Z;՛/?7OB7Q$A MSIۆ"@o*cGNE=WMhE]:=oi}'WKXG%4NI;Z'K(v&W8MP>Iȸo>]9GqxR\hT眓,4ƑMſZ{`x<=d>Y_p~ o~ aP^y<d9;+g Vg)19Z\*Y^"U[F# w׳34W*@*4IfG!\ƦDžUEa>AǦ/ BrT5}Uzs5]{$Hݕ !N=0򒍨TkbpG fM*nFcN8 k$]>|'7;\O\|}9|̖SrC쾄=$c>`SV ѩkJs/ܞc/qk=\#SLx̏%=03]SdL}l,P|.Q7[ 'kYѨ*wQi|Y+׼M%oF\Ecw>㰭&4ء\=L(յX 8zT=sa%\+p&"IA[אJۃnvScWƺ)JFmu9SW~'<*MĽkTlw6hD&0D;B ȄuIC.^Vtp J˪8@14/8|e uS̨dT!WnIe1.uo|3dN1U γWMZݰ2P+IT >Cۥ71'INq; B3Lk$d0 wZc <&@ mLwx  ц٤=ikCaz6JRJ/qvB_3mulN)3@~]DڋǢ kįAN4TB7!<ùLJ̸'=ma. q`xݢNA~):69`{Zw njjY;نZ+{7_YI;xY5߈~L!N[wO6󌪰{VҺ:%]ύsZڕqgӵrzMxrvyM& 'GKOqzB[c[j [^BBnYЍ[;"<PF,q}ⅷfm*DWU~aC.74٣'DI_gw` ;dF$ZR{峔-A#Bl0p sRisیM^|Bkի(6`-~{MQ``1?tһo{ ZoW(BϠx.h!b0Jn-C?N :ˤ`  jK5?NV\'LС@d#b-JQ9~$ Tj:{c`hYciI\G󑡬j]pYzj$x< >,a.4/T {'^o8u_ b,m2ڷ 4DI0e9Qs ӥh  "vVM_lAN7'+-6d)s9hb7f }uy\.kT`].w lĭBBL>Q) v9|-eϯlߪF-N.V"O,3N7#̂g~*Mzm7tc%ɲ7^ztit^!#SJ '|/v&9w-R u{xYm0 Ȧ#y y \a^5`ZlsH&a,L,oU Z>[ oO~ckٛւtC4.7ƙ1tqA\}/SKEa: u^=c#O[7$CY[\fm~?YTM=W3q Md5a:-prS mAoHRsVf \ѯ,;PH]AؖM+cl=N1n3?@=D#䰰2? ^2k]w&{͇MgR*jHf*!R+N{|@@lOmRM}{l0(!0]նPp?Krg);v܇G {-D݋Y<9A'z;P(~F7@ˏQ/nK&-Os݆{kJVvu^JFDoVkͼY@-IˡB<V$:8<O6Nk5H4qr[ߍ)BB'~gWpaKS~ `?q"dBۋ?1(v߷fmؓac*=!%`In%(Ө1Qr01-o*8^M;{S"(Lȭ]Bᅰ4\Xxs!(TI԰Νmآ.g!gL67 $fUŅY?|NF[%L0?UE@v:)xypMls`jM1u,-4h= |9H|-`ʇZģA!:-R;e0;֣c^wz"2%P=4|-r8S8%^%V>e1jF րePv?7b iyR_(9k1Dpv$uktM2d&wg˔|xl -P k_3K3?4v7w[4mo?6OaŁz2u1X `K/./i8wGnSJ5E wyzܲ.Xb's6""$LިM`f~Q"y۬f^ 狇d".(w|5ksYO-dc $P+}j+>:1]});"m3%?C+A+襫=XlkύAT $'@BWSzYRay,PUeߜ{&V(Rt= Fᦤw=X p"iv}N;FlVTP\ԊJ¾=ɅyJ {~P4};+< >FD?7b d[kG~c#o'z~z'&qqb<*ӧ`om2Q׋(~89H)6WdPWZ rۍ$v&ۦz"bmZ'~^|7?:V~SV:&'F(2!8cWp =T'td:M,<6=evST71K汻Kj"|@nn\U+GRl،b|&/0mRb$=Gz)lBMZ`Fߑa - V0~wX eCWuk-9B0@uYZ>z59*vf&jKˬV !L`ᶨmx{ϖhf(@ ձJ /dcEO q; 87S}'Kغ]Sf֖'NWm1Z'(BvdQ1FMA)$1C,ksJSZ3(wuOqg+b{DܪI᠋{]#&P'쳧mmm\!z9G}VIOy(xѝ1D·JvJ&MPnA23g_Wr"-%~5 .{ŤK09ĉHS>wO Q@1)1 I6J;$ $]O"hlB2Ê!=I"iLxN2/˷wphKc!٭crB|P ?+8ҎFfu=1Zp_%9(>=iA}Im%\#J8=kdՁoD #+8q0/@,>cEP+V] \H1;Djzi%Cm]At~k̯}_Ss߽lspH{_U4whzL5ASf;L-IREjWq8 6<中Rw9f5)ġFUr#A aJi Y >ҏ1&wR ɑcʼnzcL! Ȕ,d!/Cuƻ5_ }-cع\fLCSF(*tL7ݣp͕*V-$` AB3Pyp[+5>ߌgAnJ0#ִj AmO0qnfe9}w#[+ngeޭW㈟2nͩ_ǴPNlK`0az9Hu@^b3x#9Gt H :KRHmӠj7Un8r 9ՖR-^-%0譨AT!6TkF]m÷<*hǩNMXbPA3oއ߱]Z8M)~ë/Bp?SY"pw{iW6Ŧ#M#y뢻XBCN."j7W+QFaGxhLO;7[P^#8aDIi41&TBe2*{>߆裦$|%R:1{ISǥW4i惀@= ` b(g0Y9oP7sΩ3xգ{ Z:p:<(ab9%C 2Ic1y>RX;H:X̍Y~1R@o?,%Bfb2]<2yi0MNۭ$ CW2ﭺxqzP٫uɯz\xMC5A7pMn7cw ϱpT/"+>Y#25&+s,l;T~qD+0p(;!7&",>`u%1}7a_u3?8܅5X#|=9b遌b]qo%Jd>7op?V;56!{:%qx#:b7ǵj>ZrOU@3O;{,%@H,>wXWӗ4Yp5sN oDwbscePD2!9nG(*Z PR ]LhyguL G j4|o~ :#t ûW/@+w2wHkB3V) O0j3DDz0b~7ocvR@1/۔P vDŽ$ʂM>IFU!M K a6>@d:,= s ͖{P@_el4Hzޏ+~iǴH}z%zv.ٌ5Tǁ'!ø˃e-0_z.s=݄';'wz 7$#odBa5}T%v s4:>]Ո,n%6x1ipc)/brKǗ&?xa_m%&TMS7uAe7?Coቻ Lt:!OFwqz0p=(}2K:JQDhog46pl9{?"jC/q©?<xR?“S}X O^ó{4;jc`M\{TT 8 CBg|ynCǡ4x010aQ蠢cimjݵd$6/w|̔ KFJGl? 2kVU їxoij` E<8XBVuɊxʵ k$l[ϩnEhx>;Ye@TM4".v~ ;(bY]>5q i]C CaO~olrcm@^=_YژD[3$!oxv|]4J)mGa,scsD`刀gzXh#/\#^t?\.0Ev8LJd ~C>M<9k[L0oJav[`83dx3N/`V<ϖms[UԘ:Aʐg BEr'+MG_.!! "}X'UX,*3Mya> ^زYx qd 5oqa9fkӹɋCpOT%)lye`So>'h ʫ9M ~xD3H) IB]D2AGMNմiȚ6<܄!;"p" gy ==qeVY}-7|oxIvW#=#aM7De^ᱫg2T%0>9&!|7Y.t|(sj8<}Ͼ86M<*PzGy*_ Y:9QXX*0M!w$am <[:4GV(rVX‹uHQ+<;鷟.fo7'gz;F *j,%{npe=A;\R1 V`)C,#I2 G"rs.~$nE.!$jdiT:EM8uN RtAtu=|&=Y<pȱo|℡dp7;q,]*a)Rb`#d8Pwf (R_xr՗ 3]&E.z O-\F*?!$@@'VPT]DS8OQ͈ikF yNG;d;=f9I\'*҃үN[!Kwء A@&8@W2sW&6֞o*KFڴƲ@h6xKh^TBsn%AA>lsӛ:t:eFQUg)6/=5"PiTd@ rI:2_{eK]rT pL`̸ĭ_{Yr^I!T)2pUQ iDEboe8}cO{秝rR|WI1sD qCطeo+r~ ˽m8`2;d?s=I>kؒO-!Y5i?\އ\.#>Ӳ=}gWul?n) J^3| P ¥xѦ3G>t(Ҍf X3/lExػ@ewVo<DV0zgKԃVR-Ŀ`(SفG׿z,_:Uq ": ^훊tɂԔLzvv88; ­Go+1(>?َv%05=L|Wa4]5XmAg /^C1f]ܢ_K#:˒^׍0lGE﯋7yh{9g}L#BRR \Jul ܐ4,xIx_LS+Uĉ_]\|(@Nָm;;㚴[7-nvIB3y8B,[B<4|zU&q6BD _%( F]e\lȍĈ9 /E"ԧD1%~)zԹmUehdZ;k ;LEpPRR{4[э?Jq0n4Af z Ko<5( xB.db߈beIj*; 6fQ4զKG+:SYs[ ʹ*2Vg;GmMH}jc%nwǔl 1:ᝀ^|sOj +5.^Bm隧r6,ӥ Ƀ7F(ҍNcD {˧LAR&]~@H w6}?= 1aVd1p//Rg}cń~R*sRu9QXqQ%o:Wޒ}*`mPFnM-67΍?LȑFrD%T86qy8~f;#_U]ie/VtזԲe[kfwtbDJ̢Q 0vU%]MVM*kY sro(NԤa4{f5 Qva|)OC&S!KXY#%A{J.$bc&tJ -(WCR/-T_ca'0lxʙ6)KHj8VDXjdu -57'FOhYA4y/+ڹe0r뉾YX%#/s:ILBBi||DԤWXs2pR*=*qS=8E7a)kvH\~:E8F`M\ޏ]wQ<)DcAR9" L+ 䂕Ձ2*nCtHftݦr.~JnYfŸveOCo9MrXmЏ;q, `䜬WZ hzhvS|%3Z Tkq;S> d96$΢FPBmb\j@ظY ǔ pJ]#)~?;JxWLxuH[~ws|9[_ ="^9{ª\6Dab+EX0@8Χ53+apм5r3{r!%pj)fZ}k몈Vf(:ҰĽo]qxNDUm=LFtpoph7M;_49PKYH"p]4l -#lߡ{P9x ~'5CY9okB0u 2 ,t_zg@&9\C@>9wǫZ;@-7~+TA ;F~+PC u0i*1T%V#3gr˒rD_h&PZ;:o[ϼ `Eq;kh3" ep52JO3bBrHڨ/Cb?24WˌhVlG\yA(~:Yהbap5QjFy^V 8 mrQSPv]Qi'aqdT ba%-#+:b4Ϯ )㜄V|T@p6YL#2 XqQxnͦÈ" Op :M; >u%q?96FB slIe7p[J.|`g8g?r'O/ E;Gc쬑 llOGto_E`jZGZJ/jwdݥ{&KK|d`>RGsگ 29(I(=DKedOP۵cAx&M RvgEIʓ-m~ڒfe2v#epSբ^ghTec-[ LܝJ C1zUn{;51zFYiCk5[uJ|[ Axg&iF(}u lȪTs9>$ #8%H ;èxx3+&sEFdY5!T{{ }m+1It<\{N#JN 0hbUcη6trvv:>Od!Gus?qjMש?Jw1 hzn!RaL4>bRb׈ MkůfW]xrQL-=]=2;Qdl@?&ˠ> "/,g?Б\܂>! 5fD˕pt#Exw["#Z푻vj q:k6hxr0 E o$tQK0|{mw8/@pC%[l~ZGtOS}p@)B-}]p{.SuBhྟDPamZaCI"iP.#k&|rQۨ x}MN5 7{Ļn s.0|X]ؙ*rmf}76A.Ѫh}">o 0=EA\O b@:ON5l\=5.\c# |t㛞CjӗDwk~H|FڡIr2𡟊u NRRp F FRS;^oI&vu}Y@#>w_ ?uk麞S;c;01K,鷘Z$ֹҧCK>+϶, J7bhovK.RowgM.$4Y:~bʽm3tja ankWDAkmhP_g9u&Ra}sK=(Հ,t-tFOyzg_zfLW9KjuM֫g.F&]eV l'+T;^oj|fɿw7t:)كM54e+r7s۪eYKULʲLn+hncY=e!VC2dTX_ !pLtzj & NA[oW[~m\׷wLj:Ӣ,{(-cRb<9Ҳ uςN(r`m&i?IA\8|:{g&=a&?8$b&xrwuZ3 ܪўLsKwv[ϗBk'cl,m%آp5xhd!mLp{W"Lέx?$Br֥X O{G^1sDlۻ0D0 ޙůqϯ@5a0km2Ǔ A."]xO#FwU/RI.Yׇ->q6 hlx |C,jsyx.jΠUiHƜMLcgWcBB WBQoJZr ԣ!hN Gd{Ϋºz2+ceGmV[[A:#QPCZI=k.;O\JDsuV?р7&7G,qr=$fenN|銀@H~ddt͸q:'T4F?΢Pf*' :3@Bµ[ `>/&ngA2B#tӻUVZ~D.' ;IL%@p?pHC RF "޴"G\H 5%&hU ZʬY5cX+j/G$3/X5^`l芑m/brD9^| Ph:fjqw5>XsDZb L[ϟ+FnY4qXxhU]E_4a];X%%>f!qyC͕T|X4(w\Z Aץ?zl`L8ɃOz/)׷< }ߚ'!6 lX뿪3B֜& jZq;w 6<4vJ$'5lTl[Xھѣ|e#i$[nK-X`.:YGg %ai#eVXy3BĻ? S*l04$â;x,PPVMS pj}g%va~N"C?g $-sׁoܾQM[yT:9 Ԩ3FM3M-*;#)ٓ>|دe [֛gxtC9p0ez:*L 썄8H/@Ji5|1Xڭ߀So͂*+{*oJ2"!3֞=Uv#/ývͫէS1AuXUPOJ_ڻ15?jnuXm18U~R&{yꞅ4j`6a΢>J?W^F*ϥ}X;Y$i<#KkJՎ’\>s4,SGT@N{HdA>D+@*QF'_`*Vۏ*~ԚC3 82 gSӯ8f_,%APWjb͓a!Q,-8 Ñ^8xh kyBk>B,8-fm?tqz7W`vۤq2NrUQ`}˨>EX%qۋh#[nD+ٺB15S1Mcl2wDٗW h0ſ7j89O*/;pfRcO H-i\$(5sM̢QM<jcD-+u.CPp 5ǧ ,!׋g *BǯS;mX"Z4v ~#cHbwlyH2A`L4ڒfS<]|&_R߫'s%$F3./dzCK)(Zۙ(`J__4 1NYv7C]Y|RS#'ږ!ylCR79Sfnw?g3O iUw[4ߕmedTRsuu+3Ud$Q %dq>0X#DہƛH[:^&Aqoܣ"lbYȈ&E" B!)s*Yr_`@!6ƞSU/ d,J)UW#{%u:%z?%X^9Ah.f[*,v̚_[2^їF&2L\a<g"wՆ!\V-bSRZ֜\U@DTf`|>1pet]0Nf,W":؟Nfl+ۀYx^9gR<=p d<)po(w֋3+qm]6><H 6MF$y' Rȳؗq+ eFhϝV̚q" 4"z Ka+ZU:{My,0p@\CG–{k.xUؽ[p,rߊg9󓨤M[~qEJԵ,V#&Zn[ l.X2QQ!ٝNJ`׆m=ہ󡞚Wdr-0v?@֛mc;NREusi?f˜ ԣLР_HbVQjsF|,In{=2 oрۘs2?T@21d4O (Sjւaw#J*Ex}4hXٺ(m<g:)ikzW܀ K{LVIVA߉)FylnVL+8^TJFaW; (N.< GyYY%ʃL![Юc H ΩsP.C)jҵη0%g6v$;dHɔb'gNAU~o}ט1@Cj7K`g26LS/0NS5^@"$̯$6fl!gW9ۖ.ugZ0^2Q.#HL` ؁,B@G }j ӰV62sMKMphiB Zh6W$Q̉]`jԢ1 =k{#Jkn+m#4T^B\}7w F$?__TY$ r3^Y%c~IOL奷@@A 94YB5LeFӀ2y6|GXG;v&%M6Ic!Rj1&HZ@{5quULI;(/XR~cCU/+0&R Asl;~9LM9HX`_)zܭ S \)r®esҭskP9+ UmV iH=k[p4c:}]h\(<?ZZZ9ǤB }/ԏ@(׋V?(\FCx/AQPg+_byIe ib]f74oTᅦO%JY*^hLjq\ܕ3l|yw:VemTK><-!(vvn3NT\gL,P 9p ɢ(Q,?q)t_G.!Q޶mp?,4(3VZ.#& ~Ziq#2 scjTG#prk̙`532=s6"XիLՇ3f<|մ?QkEMN 9>Ω(& S= $2g3 $&W h*8-|cboܬ!v <uK>Q}nm9LXmnJf+,c"~/\-ҜAR| ^J{a¯篇.k)$XucC UPQDHI[ u )C)XV}d \6nd6}Jx5.Qɫg:!2[?˺-RH2y!BBC6zfG;O418(W(e`X;T:1uڕsf^;3 LcLܫæBSDB#] xcTQ0Ghm5>Ķ%pFUk94*+G I[@fLkq.0 ;ս/t˹H̯JzA1q(\`\JKWFCs4J=}TEN B~ } 99l t(IY2\t'>MMlI#a3z[ߡw㧌v6M$Dif)nq r|ss>Ҽ\gGGڏ k ?*g.3UCw\Zqf?dP[l֋(v@ .^ƀgBAYnaB@>>%j,Ȃd4yk}ǡj\xo{D['}v\^~zI$2Gb.2y]S#\I{8?6{#XxvAQ yffyܦj۟+$m$rjJ_ĭ8/BSM,%ޏvW06L&.MN@WZ# gq 3d5<tgrr U߽0fb891fCUQRqJtn0.4*q*਎1C}Ur9? _ =W弮ǃ=2LOZ9Ik9 NmrgLtѕ/~<8}4TohM|Xt&1/}RM6$.½)0 e2v'-{%ɫ0dn%osF&*Էa3⁍`F$hϫS?wUSX:񆅸؊H+ a*GlMepeLwvԋ)(̗UڋnZӰ8QcZv2b~(NgEg= B+4|oa=# :5Ro6>]T.PC B:Rz>D3@{ܿ <Npb_޻E;Wa/0\`'SmjCapKlèGaY3^*szA`llt J1gY3Kw<& I~l[^!v `FtĞH3TlFh0z.t*[^فT1jvq@cM7mEG_BurG?'K;@ (#G~Eo{7ƀwnuٱKk'/tJmrrrc5WݱX2DJ1=~SsZp뙬"z5!d^=EQm:5zd~@(/9]kX Q+c\6$J)bKMj}s|6a1 'z$U`q2(~13Wa S3lևrJ4BXԅ^HsObr:`J~9]^8RO 9wh!JNF]t[8UhwJv/2`2b%A7X:D$#SRl?t)^xG([H&3_ζDYr. e>'K] /ZEƗFؔ5$h]ߩ_?&eTCLO4̎^s4 #];C9h[AQ-&UbaA<S6u_4,& Jډ@#vgQ|_db(XǏkz\\Hh *kO3/q ƬiUc)B~83؛!=Md3ȐS0s#2`mV+P#u,gŲJ-{5m:_p :m.jܒ^ 0fgDً@qcF``yHBR*AkKfA3LTA)/uS38C `=Gj|eCa@6AncT6yAAJ*2 " uWƠxn|di2!QdjU3.oF݌*d@OP#& ,S] ꡳ߼7T?(z4 J{F9c^`2ό5RP!DPlHC+pwz9fQ k} _D<`EO56JY6-3DŽzޣ,#Z_n ,ɟNĉ|9ͪ%rNi_gIwߨC\dΝrXs${I:xZWR[?5)=InKi+@z] nJ<x0k*?E;KcF uuv yG3Z4DI V_]Ƅde9^>JPCe~t5W¡/ͤ|#>Y!q?i:-8BS.22f%$5jug?WKBWޔ9#lV/Dx\ |= )~k&jh=.9Q]Ʉ끪m&味zuBf*߳;̱ęqvsq$>T7_b 9,8!s~pBpYp);U;pvZGQp#6_HYxv`2>6#"{cͼ[*UHx-bŧ&Q>jS&R2xk_4ʰFԎuo/@4N;2)Ǿl!ZOȚ f:&0D݄M (xbz*)z;ɱzKu8{$(KJg'iq)"$`fl"*>3 >*w>,Lj4aɥuҒ C41:Kq{;{f( _5,-2muۚA=,qbM}5B /y( 5\bz Րi F '|K$.j^>09'A1!r쌇D^B7kZRW鋙( LC!%ka6I>pAS (L{"8uzka FOQ3ð} !w3f0=Q*E>! *< E~}f]ϲr< 3D7bϸe6p{g#'wHFTY$3*t[~ l ݂)J.>MVCJWfP_kFv1\eQM2w!p"×D(UlqNMΛ Ó1WiqyFF,ACN_f)JԈMJXج?N ٨NyQVm0^ق{5{桏5H"yRH.›k p3̊ƹs:Q]ev"8ǯrU>ɼ1)H2֞sGZHz N $Ow|f~̔}o:M0ց\{` cS{&*8Hf>yfms9<2#UcԪ5NO DI^C2Cc7T+ (ڶhhCcowl.,DI +Eæz5r*{-и,C5c~Sy."Q/ GB4mj~#(gvż(8eZh}p%6I,0O{KBiK7K]QsPlx{.ڬ,泂^g~ܽ* l@_ lÜh`Jng~VM!w ewkXD̉?qH;ۓwKLmMfAhV=V6n .#T_[xX:O"/N^=#i@5HNY"'+85qPF,5i6xW޴}U'{B/[P[VEZ qN9SԵe1ؙhsU ݂Rgsm0#gC\8zJK2c |>]% ݋SVr,/t)Is&]JeQL[.;Q⤙?NփG4} -U1ए1NZ-r/4RJv ֵ]5ZECV|Ňs^16zcĘh6bSjh{%Sl({]bӹzAElJO?n5 I.l0VmBgter_&괲¾Hc]"猘Ǧ'Z߇"E1* a~ﶭF9d^R2bo"rTfR_FOɣ؍w *h0UW}wcdH;X,Py;p( F| zFN yZ ՛-֟0^v7e1Vlǰ# L.lyz|@N0/+8, ʃC٬ЭT8^'S!1 t.R8RXm_R/`>c$V y*ގ OЖPܫ"$t4o5헼b4.J],KV5i{&A)-r ZK9`!Bn^^/W8bD%7mL qϱ0 .hWZҿzhap,ENy* 'EޜvP^A_tO9bNbdZau3@gPڪT7]i\pCwP%B*rmρDSimQ'' ˁ:q>W})LĨSi輨Kon0[IJW)[7>3Zѐԉy|Anh7lb? <^Ҵ^EuH<Wy򥐐uYz%;gzALL$bħBS#|>ކXbr26">?? JVGyE%zճ >-Tṡssqn8D=UpMw?dC)8~GS:H=l?K/ $[= @њBXi::MV߳ 5ߕOCwqFTYa).Ծ1Ap90`g?2pKlh  ]e87GU5/',%c}+RyҝzYOZʵ Mcn:>ɞ/xb}a I"++>njP񧢷&,GG}3>,꣬5 IJߨĠIηcΰW!pJ*?%-PA#{~n1+;n!x1!*䴲hîqJrɲо}?9Lш$oeQ,%Gq;ث*}98Y< *Ez"^`^+toF񦆍+mǘ DA!vr8*(i$>uoy`?~ i*[QKPIsKK uNwB9<(Pb_"qLv=waw{DGܓ?'ٳ&'`nMH'ҼO}(ߢ==^w6 ׯm+u[!s^HxLiG)q*PtJ gL( 6.*At\~TX_,w0Ѥ9er=ˮAPp,?Z +FxŨfbv@ {b$/`_րp7G U]Ҫ B\4A'{_[^g@|G"5͙jIc(w=kS=7"iLߢʟ}~,.[#5vcf 3$7rSsh&ySs`׊^o}(]3;k㠗ԍXռ#jruPK"Dݮ`) Y% _Z37ա@ۘ$7LWnܬk٧Iֻgn%s~CB&_yN8{9AwZ@kO'&wV ݢNQ51Xsh0|m}(G"gf@Cϙ֓TS~RŀTH WF'ZYVhL mNLH!Ck]|'&ۧoL5V=r"91%;@ksh4 ``s˓KNǻ$ -'u$6FNX@%Tĉf飿 w!_ӵi WxIڣeo5]Qr^U/E6S8hؤ6{\:jl?r@]RE!:oܺ$o('%ѣ gG@d8ɮ= PviWB R+twkKG_k"`oMU)DF,[y03\O%*}NO.KXMw8Q*~'Ƚ"fUk,DnpQ ?n}Pn U6( ;Me5qͣK`4ZkBJyf‰ 6wlktGYO6!yOM8>r^ 0)P.BE/2WSt PR'SBY*=j^q4ֿyc2@OɐP'j?-aH/39^hx.9v;p飒cV0KcM I90C.7֓maCņ3[8 {v}H*tm>ԯU™ٞ6¤f. Sv@UDǵ!1icP-s@ 1=KLsUŗi|CB'{Hi1[89^32goeƌ|"/ⱬ9`V{v-^R BF\=H275#OA!Njjdc_<_p+ FpnH.pN*ք.NR8ce/x>`hd_?d{~k5WՈk)v~'AB#Q? j@_ ̃vD?&|+*f>^)u R :m"Nj'DqWb{)N.S*=vCTpXu{Zx `uӆa̒>oaI( _#+_ŪəߡJVҕȩ{~[|kH2hn=ۖM, GD'pjm'vwo6ne8QlczC T'Q$Z`壕+ܿƹ:qu:C5OZwe^b'`S5P#M߻G6w1ٵJKl7]iV1}'ёB73;D$=1 B V;: G5Jte\d[90[s;BW$/QW3gq׸MɆ{J(vPa$Q2,vA ^yD!Gد0%lQ68X.䧹aJ,;!5Lp=VXYGêtq67U4W#9/9'1Y\_J#A2) v%d\؜薟i7m6~!R6sV 毘biV|Tυ FTw)0o m>I r,LRюD jG{aB&fG@hV4 P0ZT\6¸>6FR#9^P&mG/H#vGthujk;!]$tXgeܑ53+ 1|d8fLQݐA>3Հb#)1nprlu"QS͠h($sy3`q9J!Dr=9Jp`R^Z1A+)!="\X-ӞgN),rʮaDTPXR5Pgm12[]U[Ɲ3҂K3a}6z!PmxSj@{\|cw z~R<D JU^k A5ZiL>^ UF[I&.N5A/q=Vɷm/:,5aSBs!I8aЋE*Ӗ,eE#(My#P$Xb^"o㒝jC8;0Y?ծqw+l.TbuZ^B1f1ɨHvB~8|x u: ;Eo4NPwgMuW1}T`\y=Jad\M"D\$М 5/RIzJ#U.lL4Z;QcQŊo3ba Fsb;o>upqw_ʐ3AP!5Ϳ(w0EɥB1"#`?0`5@27-}';$ODa:`D4IHϹc's -w¨Mʅ=884 6{EF_AMBʧ~ԄhIyڪu4鯅_! (]Lׇ \ q\E&w zxJm6m0GzlhoȟچFOiEޒc5]2B>Ӓi[bƳӃ+V^Nd$4H^e0pdx&'E̊aH~έ+ [H SBJH9@n!Ќld 4*!cArӠe0NoB3{F8Zt]JBy=vdJegQr=LJ:7lZ򐊐IlƤ#T/!)J!ȊCC>J4)ǽF' d)9E/]1Bԟf7D{`vT Ka{>h5ɇ}Sz;?I6TgE}Yv6JVAE7J_խIQWlJw: )"{գ40~;5qe+"KXϤÇd&#čVٝ SZ XkBJe yr44^9Sjsq&0i(|K`֨cLJby5u"Ԋb .Ui!6Edۓx` w_]\ڇǍOJw5ׯ>K LҒ[@6 -Z13،EUId=E92 uÆ=wJcQ `}>h>lTuH8nNhv83A:]5ަ~@P>9 :s_}!r8V/ɖ>v۲8y}S'PCu[Oq݉@ <=r&/1mhω ^ߨ !#<ˬtҖ;> &@$ buA2$ cQA:1 y ;9cnA5ڿ!g2cn^i.AAGL#νh E6qr7ܿ `4X]nmZCh%2lIS.6D3+вzgy@s쬣|A^윽@})kY-񯪷I)vhgUr .ͣ?RbMuug紅IAd+zUSJR^ő86/oh08 f2~X;o JqlK+ 4[\%=Ge@i0? K7 }7V$M'#x ǰW?o6~2K5S =WQe@ܟ["s)bErdMj<7ȶf%T%.+QSlσU IBTuמ<>c5%T#;"D`VH<Jp7k;q N4ȲUeF shaGז#Z<:d:Uu %d1#C~.S)fM/3:ly>Ѥ_1 ݍS~@#&I,2q% 88J|#liIc-"Bc(l6h R5aPbAH#?;w)1CbW=KMp?7>+ !6-3o|->QCZ]iءM0F__~5k(DQ%$,M2JS!pkC$MՖ',*s[f֥3N"jT os:E&mXn] NBrɔ+%yِDa\hKBAC\4A֚\CEϢ-$C:2)z/%v[T.P6"%gp]G6,0*.R*m'^+Ώ! 5nhwxh՚룆x=ʑnn%/!19̘) m\|5/Q7IQiI0/|@bkQ| Z & b~wW=W9Oئðߣ ˵j+% pQ24eb<`8 -ך6X8G8CTq0Z}6 /: tGGC`8vmi sM}Xzo祧yDdXu뒘?[lM;jYyFjo[Zt.]bZSJ{ n)}N'vRǷŤ'Hoy<$$ʈӫ9%&VandUBuYlLYǤUA=H S<~KQnX\" -Jİ_wvI{joSE@ƒ tKJCϋZWE*H\HZ 03GDُeM0lf%GXXFID^ +_qEPlܩǍLbܛoMNY}SnuX-۞S\&@Z_9' ܗ р_JWj!"7- [`] u~{,yMWgd/;-oʑbM_Z2-P*3 Ag/Í4i+ꍈ ̴PZ.$FښȣpiWRbrYMQW֤qcdmF6^jnCI|`؀ xxv# 5Cf-A_&:BOŌ7}ʡ TH޿{q<HpfHk,.-w dїe/: pЅzѦ3_+vk[-deqqc[m6 ϯy]Ŧz5GVRF" 7}w@u{Pi|rcomg%`҄g:(lY6L =[0 wfIئ@,~{sq}sV[h> HOK9@uW_?mtV13s PVcv\58eqPpesw|W ߶ vJetC-, m-37?p[He(x-gBPS6+ql 3E٫$g(/1B mqGEm"N߾{?'k0(S5M[*Wr߄:TY#B~u^c~ѽs]dsKu=kl=0tn $ (-VCLK⡞=5%gws|>@]ho;qgqȍP(3<8q5#3fW ڼXi:K{ (L6Z$p3fT']twtM +iے^(MMM+uՆfbi <$8_E ;"nRzBčOgJp+%)7ꙫqkt[~Y *"87K,j{X`g,Ew1k:[pщ^4tT~ zA'(hPd!E_Y.#Ad6}y_|x Og6 $5x vWe4җ9*gݚ@dRs k+A̭%gN0 wUξ'1K`;ij<)ơVdCSXC]?"\Gs"Q 3NV}l%[czy+㒸M d?Ty~N|r {>h(aՠ57#cGG_v0+3Sb+%Ek|f:g9"X'h}s.(P( @|wǜSFt9lbgnQP2U~`$XeIQR\_•s%juj-Iђy -YܾǶk/ISI*vBddKx00O*БlyJ1rh.NsTT$< 5,hFtƚ㒚2 SU+-܍y=u[6&iJS&N FH3zX*kOhf@ ){,͐Ls),^b/~HS #U9nGD+/_3.H( |`|9~Ԉe\O졨R%аȜ esӞȰ'+Jy>(`8w^2R 3-ު\d!͐Ø.]xR<ڌ > QQMj*bkFj*W%y4Vhi%J5iebj"Ĺ*Z؆uF 4JQby+w!~ ;ߡP7sG*yE !$%#. }Na6?A?@`~^(+$ӇbUVHqMy.'ʪ%Wo"HMkSo^ʕ&w2N7F䢢EANr܄'Wgd#ύؔFJElxJG#r UqV4 pu"Mx5`m LH-dm~;7J *Cٔ|f>ҋ  ;vvd1zʷ-3%@ LoTk)lVC~b`Vx(]=gP6c l\>H{z 1s؎A &9ai3{϶6f,mǰ4$dU qo4pgzt\5 V&妴IJ>)]}KKU)BkNcRqBMײ驪bXQj0BSؖL"Wٲ߷Bo,f$v`-)g@s:S6]sEF|`g%q AΙM٥XY0ǯ(%˭9'")n66ē?j`4 bUTi]bSn,>o+1cd6# Y8 ?+wkC@ Z_J)ý"-`V1©蹒2^"b]+lI*i+ȿas[,`RJv|Gi:c뱭<jfFR3.^#N5 |qp`Nb }U|WFDl5$nsr6A*_Cc/3CSjr,U)z?|S#y}S*Q≖VNFOsoh) ^sXA%.Jv]CjRheK|5y7C9:$e0P6=X+Dl"ESuruӀ|=4m (q$5ܢ-\)Ry&peqx#?3(?j|Ȃv|@*gRD![vg9`\:i.P㧚'ŅǫC[J[$mQI3(~d ـIěpJ n^±Y!;Po1Gmv+HṷTOdFvkHݯN

*c*C;#J-0H҇n#kP&`'Jykȯ JoGMGOV`:ɂSrF[ MRď3\l ojQn&4N`9ȷ ru n68It_Z=$4!Ղ6ח"Ikk]tx),u׬43a`bQPMPW+q6+la(&ւ:;柸PgoG%QC-e(hQRV6)co\uZcˁոϩ1^iRgRs@Y.#C~ePkD? xB]٢. Rμi"Q{O(oo~_Rx@{'~z"dqч>z+isƇ"X瀂 C!L;h9PK[R~{ozluZ.M bfCk9D4̺+-rY*" Fm^㷳 4x&vJ2QZZ|1:SdOF&'O6pTlk.A=O47O?#䭨b'E[b*="Sc֢Ky#ҘXB}WL̩A=o bǨ~Ĕ$@]zywm,T dPF$1-ɥu`v@!2~M֚o0`ՒBlZp-)u "ɦng \R135`dt? H 1k-Zm| }v"a~9=m1ZvvZ~][&D EǗCg9eubE.ɟ<k_'󌄥Ļq`{]{<ʢ7`z$RnI2 9c#ʢJ{l-#d60kGn5Urky:΢|\ph\^yPiM$o;G?}a}j :ѢF-3"ⰹR3-5Ͻ/u,CVo^ZHҵ0m|Q`\NI b#4sJփe:]o5^XUpoSuUo7wRn4 Zh GK@!(}[`;~ $٭@C]l~dDe_M ;S-Ҽ8=%x&~f%/A5{c] ?s6ݢRԄ8l'~ S93$Bgۈ$s[̉޵u$f}v 7G+$'(Em,!~V:T'bԠ L횝n T׳m;c#Hu]kaGEe_ w,u|by<xiBHvCa<{Ih^R/-%l&3Z#N nqW/!F6y3<2w5,WGH-A]R!JwHI Bp͗V Vޠ[i݄ sD,_Fs9Gj/Aoeϖv}@ԳCYIUjn"ވQn Nb}f07 ӦrQdVq( ԍ" d]IBz"|&6`, a O[DNJď®R~nӠOe{_#1X|!TW]VXl . MH\yIUn=,{@ /b,_3pqvIL93z ..9Aڄ9xgX 8x.\%0(q GHaI^PEܩ0Vm2Vh- W Ż;q4o'B~ u)f9ظ7<`m.w̪oJ[TC/F5쇞Ǥ (i#4$"`$(zR$FKwˎ4[U/<)5ilRd%º"F%5.,ip_^yZ(jByѣj7hY{A CC`gW^FYV8\([dr&"+*TdOӝʨ' n|3OmY†}]>2G68](+tf6g߇M'xMsChE^ "%.9,"V i*mPфکk[]&N5jcRx4 L];S j@J-I߰5>4|EptKi0t\ti'+I[)Ba?>E4zv" '˷[nokd1d&B^vHr%@R3}YeKcbZ\}W̖]Fcї֖!n4&+;ps+IGE>LZ+Ʀȗ1lUPJgO3шWRLo9,TpTfC*SʺdJ $9H41U#K:%Ȯ8F PSep#@CFGqnN{kz+ ƎYVV@#xd8@NLk{I3}ɿFWlc6w!} jB[oB5J ~ź{,s2.8J9LsA/dh֘}3 u$mc[ =Qӎ>^䉅!s>Xǵ]YvKeo֬ =#q(Mq-TslTsp@Cq9ʐ,9ӳ5ao,VbC ~^Ug ,99poC!@ x+ d r eQĨ j5lh:#Sg렦+32M٫rBԊ"=Hr[)hG:M5|J3N (/gX[3gMz9sz)6, 1YU3ȞapJR7:}8$U07pzk QG@,S 1&wNqt1~o)K!r/۪KBVp 6P.bsu*7 " re]<$rٲ_j!׺ n\zI"d)ds 4!&p=^͓\N_nm[Fw tgu$t[(`@bb|N&vCՔncVA+%vKbQWH*ԪZArv/ΘcY_ WR[8K7X|3{bX m^H eyl.|vxcةp=kKU{~MŒeS+F3}< FY5HЫuߠDv 4ܖ6qEz]'YQ%V;\1BrmhI98Vhb鐄Z!Yhb _F?q; LG\VYbo,Z[u(iʤO,0NwfC_?L8v>y⏾G/2.*\M|, $sPNFW,b!zF2LX?Ƌ6sR_%@М1c&eG'|1 4LS^ONjq*IEO8Iz̳/CDs9>)@M. ddj۝cO0I'pD5LW -$.ϼ9 I"?{ ]weL{,`aAFn}.r^o|`^Wۧ^-tg 9PrhI7ZǽrWS)ɉY2a n%:Zͫ wE^5tQl'i@[}h5wx #(zX&&ޝ^ R+E"@f4ITLbɴ:)/n5a (R!(i2n=U+}}hB #$S{a y- D#dHZ='alzT"; XPq"ݵC\t=m0'Bɛ2%:3C%[a;"jONᱬ$7)rBJ+J .vk#wVw=[Sz7a$]Zd!-~o|6^W'JnW^ݓaɝ u;|kr+o GEsG!^1dܴ=ॊlu K(s-gcE)`{rc(RwQMe{q|6jD?ګjuu;s7 ܟie*2M/~,cm?SYWWmɀ&){c%s?s:tFQv /o"jH;AM 6κ"a+&][kʍ#l*`Ն6.TLVX9VrEh)H*oLDz5^+6ޘ{ҿpA;UψAtW"V`iNDgZ\ĄW|a]5*U CHIJZ|/1@ܽ sӉ)3\9TӋlߛ~G.S:=6~e雏4C `-32\">KsSϤ$ԖSx%sW(&D}7.9.VJ ʩJ|mA ./zT٧KSZ {QZϭT"l%$oe SD#n7ro%M ʩݷQʊH :zROվ)xKARW㨛A"pg$sVx% qwJ _mu ':Qvd,.,&Y)nɂW}GQszH,;ؐWxz*36C( [ <cY;wB.4xk &"b8_o !>%TXc>kaF 6kF8I;/eY!0,f_9X ضeI#MZML_3 t<VtlΖ+u:T+6Q&\AdZ%-dxK,jZYtySq XKp;sgnC5PRIK %m($3]m$.sֽ*5(W"E.r]ubVۮJ)q1zor0DmVC<9-XGB[{T.+˱,>{`XMՈ6)̋9I( ~/PQ`fDH 8QItޤaoK)+ϧ/uCM͞_ol/l 26NLF{*;f݇E%Zw c'@rLؕΑx(Fَ촲bz2fo1[GCkTwH][Pۖx0|j9 C=eQ!ϯA׸i](~$6wWLfc{j<# ^^[Qo )z訁`YԝoW,Qٝ!ԝ!k 94ytҏ\R3]4ߤÇ/̏02- #R&̖pzfzkimt&ӣ_wIqÚQc}$㰏FhMڬ,rd"Glb&zn e RDxUq%m9`2'YcDx4n-C5N-B۴eKrA .8a 4Y>%Z}+oe4?+aOGkϊvFܻhoF:x-![UnIǏf$ ?M+縣NB嬕*a4M&*Ql*2€%`ʌw +} |X|HrV8K'\1_8<@鵭'ٍjEU[O)bG]&'v\[=TޏVe)%l E8}DRh-- `?EbЮJLNt|a97LT Bm-hbѕϻ" =Z~_:*l)ywxV-FQ}OLZ 蕡>ڿ}{#4<O ۂA09IDqWkPї'v1u*s._N~"$zX2J˟?c|irwlBV㣆<#b 2*MuT.I_ʼn/եEy9{Yߣ׍^d`7)É'L+) BrTQp}b==w#t3-L0<ө5s|Ң?ʄXAXhJ ,8쁹ۉXDd~gt$%CyWG81d,48SG ytgEm*}kB?..@1x9Z<?ՂnSA$}=d!qcgh Q1c刏p- L`;u A"y2ԣLJJ\E.BŪPs3\Gva*Y3pK΀o3B: 6aG|kOo'֊֯`j @L#X|Yo|Nh}P36}sbjz4O\z|S]tV;//{?=G*}nN%&8Qp%\O煁5v`}ΛFDpk$O|iF)GVQwO;^S !o0^[5KҨOC̹ Tu/R[PL#x'M59Z#ENGXPO,A eள`.dశr?< V޻w#`T?ů+IaqnpX! ׹1Q"c+?Vw!> ƪߦ=l;vsrD&\Xl80tl,/#>7N3}uERUjoL^1Y)1X &³b>}UP\G+fW@vWEI\陀n=p3>H&DI]qi.7[C;%A0JhaT.f2ZSb`< s=z|5kMkYk+v7 K Q31}RJyay3UyQo-;Nu:qvPڌyg/m"{yH^ :T ׸aW 1@\pП/1 m~ 9P[)fo Ĉ7Y0gv_$ΪV?U$IH}c[;vU'*}GA:ˉt,GgEjə'^N&JyL``MJqjf 2'.hh;ge*朲DO"33h5 *)<Ҟ o8N eb+"_:jֆTrMzɕڱ=D >jLFl\%m 2ђu' $!U+Kk*.eZR'O,.dحCifhMV#HKsoYʱ p[tű ^ YCfdcnA=R,w[InjإS9S Tn>;F{o[c*\?H667b1,!U8'&A7ZJ%o.,up 3QUR'/7Z~ThksVfYĠ18āQv!KqSsLv@`IOt3[|=;vᱞ6K1 Ckv4 I;D]`w3U%>8*ZXTwi4$S_(xC.BR%Dx4Øn k8ְr—,Ezۚj֠\@q;@^gEb7'\-)ݍounnt砳VܻL.4k<d<{* ~TWX,dMU8f sA6=͟o~`a~K?6\d;IR'k3%@&ލ4I+qqq <$ISpJ"ԏkBB̒BWL"TiP(Ň(Fm{쫄nWāLaVr "᤭ф!vmR!ΥhyG98uh)8gK1}G`{sY`I0E҇Hb"Oa"z3xTEZ N0ܪ~Z,P, ^`hfdAxX? yX7v'c?R?Fäe?6Ǘѐ)!- P9WrIU )Jԧ`oH=M`"B CClJh~YS#XI|pT`{2E'%-l$t3Febt~B@&z|(y)C![*ҼNH4$e3!1w59U5i7L5H4ʧqh7{la2>BYWe?7Es]^],"c/ 7Fy! uM<1fw>f9E7(dlf6.oQjU)$>˅1)GV4v8ot98iGONHP OQ`'hj2To.|i|Q$Z?{ʧb Vgw3qtv[4_E-S9nE`ST*~<LψGc49I"Fzuy'쇧qjeO514⊧s/DbNϽ(HрBeϨg; հV;"x3FhhG=BS}L-a)>T_HsD7з࠘zSbKXX9cA^j\s&@NөỴ* 0rBcGXLCc\,ul#cb^],e"΍/ICƎ,wRFhaB2D0HwF) yo!ϧm `Du:'ßjEqšҠ_++nwz4X FRH JXF}ϩٳ }5r{/N+.åheHU.1X}¤]a 0~)tAp}V*UEeoǁ# rr;J_þU")k١;Ws,X}S㍾ i"v;l{a`g"cE V!#'ƙA8=dȞ7čT[J2GA@J*Fm`>ﯳmnjMj"58~j*Y2t% :ڈݑC֍LE26&a(gٗjmpa_89;gJz ݕl(/܌3Lǂ{`q-@VR%x_wIV3rZ*{C MgvLݠwWbTQwwHH?/K%e+2t"R)ӎJfBGr:p\ݴ+՘?K:x{*rVIJTG&zS7:D eHt|$n4@fqqUե{.74蔇[#Pw)aVšٚ'PbˇB&!092l[Qfqk&m%^%&ޝN.r0Mξ60`߇(4o.ȱR+ {w}WJ r gP{>U|ӯ侖%_bZcQJ/VUql B9uC Q&ay99G [Nߝ8f%.!A#}. 4t8 L30MT0=5N4<Q\$چ٥N.I.huGHoK𶋋xI-hךNAڭ )du8~f+ +~\ i֥7;zsƛ |9uB%0[ʧ}9W phP?X&t;dA uia[߁h_U]o9h DMAG](ir/_4sYrv֌Ղ'Pfc葐9iK ~M ZUi9EISFlv([0 t!*Ĝj3~E/R^7F}ew+E# ѦfmL*+"vfoM%+5n"skA_b8clo/ s(qqh?>XM[ٶC(5^3VPW]ʃ`K>[6"sA|%Y&?.5}ݶƏB]SZ\sMd2JJ#/DcJ R:R=5TUE=ks=nRDV!U{T+':|f7/pnkd4U]4b(7)b8?pd6$]w).f=fE3;=s]@p{hl }I5Sn`W֯gͻ:}{kԀk{"| S:2 Zp$tr_Ug`E")J{#95,,[B-hxk?m/e(|7sG6>9xQpt+0C!:vR<*C b}R,D @б8.fť{ `'j{M6?٦tgMW|,cҋc݆Đ{#4lwZ͕~򩙀f;(bG:M' u&X$vPC!>*_rɣrm)*m)$_ޗA3{Su@ QsE!ۇuFYS,51Vf5 j}I Bu 쟀0래\IicԙbOkn_뙨$[ sAi4lIuby͂wOΓ`L9F?XjaLB2|{x 9y;iQNbpEj{ =!U1QCn)nzQw}3гgvm*XR zb၍:o!~Ֆ+S2NgX!tl8caũLjBtSJR8jӅ!=JIKC8@ސnَo1E[vD' 'lVs/κQ Hmf@ h˴A'L2ڮ+ zi=TM8*:]f^%l-EvbLF)*VMRTﶳH퉮7,t!$F"rsXqϚPMV Sf8CfeL[|"`^ {f8<@,GIgXP!|6.7jО׿rY<ڨKgEn 5 }N=.;DCj_ )A?@_9ZK 8 (JT.֘/rծ& DWpOyk]<** L ԖGx~wJJ91/*D)!ȯӷRZա$h"I~7h]&` P.lz& {^}?atYlg&hg^w_\*;vX11(DmGZ [:?}"/n([\x*;n-YWiنIva5`jcR@k9zN[zx$2D1DZk#g1Fjkl 4H!}kCBcmInn5^52S=@&M/g],K0 VgSf0 @w9gRvSyƟnp @SZZ6+h!}5ϓlC#Ռ2rMm&dR #G]6^4BEդTH*G4QV9+JOh=]J,yAQ+ɣTpdba;Yek&!M(1C5 i8,NgBF' kbi3JnkmeVg$V6A`\پ#iC3Y:?>({ݺsq3I)?SXu_+5U~g~#f 'k`%-|- R89|`4!`y \PT*GCIsjz4 *rR_7Pk_F$&Kj橯bӈ;M:&E# va$IM۱x=;aA;Р.{%4~f'jKv^sFr.XhFҨ,z(] ξcE_- HO. Ϫr2xfve1>BqlJ\ )t G*]%9wGZULeBգ7O5vaم Ӫіۣ'&w%F@؀7|6r 56-CFti%^uV涘]/`KIj9[lB["/WccO݂|"ԣ6B9W-IP,Q$˫f <6:!^5_!.].}2.?K 7RITts*P S7ٜ}q' cF<ł k+H Ui Y Jm`5WY]VW+s&l9YkN4Cha]4n Jhm6 lHMQmƵ0kMύ[&!|e'WDrG!n*LOJd+7 i_3ZRS}4}gQ8oMa Y5쮻E|pX> ּe=Qw|0ԇݾ$؀haSp*#| lc#F $GPKWN# faa-U7vH8f).!wQv|-܁vWJV-e|4 $c2O;bQ,'oDq60mめ{^@~xDoL1;(RImyԣJ#bz4 {BzC? *1fnnLVŵLީ ^Ln;Tޱ`) JE|f a/΢V䈓fE2$k$$8D=X/Ce4okD@9;;#G+)Iw'7>^8j;Rw$XV~3zfXzjք1"D6H@)' z_bסPxp5ގlx|Y+4JD>g0 l0T&{:Oz#2g:k+ۃlYw^yGU_o8y{j'afkXlwi/pW$WH>c?h`lvB-֨!F@ǜj;`Xt& Fx-}ynf'r#-)>#YEtˎy/s:}v,H(ʤy/EF?ZbĴMX0(q2 J8K/9/_Br@߶A-٭v6L-dc?9Z~y9U&<eU{Cxr\zpQZYhŎ*:[6At~aΗ6`1偈o'-)'.3 dZkT6MZՁЭO@#p\<&$+RH6GEQK;qK @&Jpbн!1U6 ,p%v3lTH["O5M.I=E=g3ÃMO4c/l\f__whOhz {_\El9h**I86I֟$ޝ, J̦Y oc$J.> F{ٸtr'O?:onqϪ~o<%ColB8cϡo"W5ظoP 4̀ s)txV)ZaPﯙ #-ejI^do^2ΎTP`D`2`JLD8gU=2i&ـAcg?{|nXm7 Su.o @hFߝIG/ a)5Ofd3/Q1 $,89hB+bҔx+嘜SdNo}mn$-(%{*s:EӁgԟZ&J632eG9U1Of8>wvK!q`E(2UJ{qt 1xӂHFe 1 1, k7d|Jz8&mN +8 .ӼV>$oX4#OZHrh]sI.|E#k+vVz%̕FɊ$K=- L|idM++RHݗ$֋ꗧxaG]7s0Nt&"qY5g㬆 !B= 25|t6FO#*WZ|lQuS'* [DDڻOMnuOhleoVwYoHG~O8 8RSgЇ.HǾL\ӎNX_Rt†'kFmA텨)";(hck JH>5R;il,ޜ|[aYDr|zt;9XiiމCQWWȱ=۲33]+B_/Pao46՞a&:g6yؘTp^L t"y8jр* 1caUd$nCg^H]L2l%LI$ʅ -n?t NNI'y2磹UE~mzwX(9ϑKYNv0[Ѫ@6c}-%WT05RMlAG" Abiז9wRv)d)C9sZSD R܈"K)4dH$39׀硞2S׺r(<%謻(%D Ve댻x|TtϑS+6{ĴM [@FB9E FCj0 75 TF 62ga1 oB*$XqtX#" ܅^bi`~ ׸:GEHE;|>Tdʦ_fLc'/N[f4)BO'W)XN*2 *EtZ 369ک{)bBZ.hFG:C l|hgslQ[b ]~|'#ߡ Ve]{wfKiB+QZwk3t5~ |h.1ݺ<,s٦b&Y fAgvym7 ^RłZ+ϰK q -w&hN*udhc zS JnԮ ƀ ut !Nvz:sWg~Z׀ Ց M`TH{_z)?4oMN6P ,Jp ~ˆosQ#=3qLxS#[#=)BE]wg} 66Mt>[<Ĩ=t xkpԞ?莳]1ڸdL6l;%s9)vχ;YM_ݧ%xڒrVRCT/[lN k+<ҧ\K@takFIGN}ٟ@y>;ej^*Z9su[GǴo.y4 $‡EklS:BQ F~ IE% ~~<]z7c%T:e437ZenGpR V)JLNҏ l^ D7N@K!nN֝ \b p2%HOߍ}:{bnJM]{V(J}YERfn}.6?>-OЬx5盅F˸-2631| \4'd\ c_\:OXZRt(mS*ޕ2g4V\-$ cEyYܳ#)wSIv}0B[Į6!+%|6t B׈d9`w h#=,)?ǼM[zJ|M*Ei.x ANP7@44-T;Dͽ~;m`QbqS[f~ܯ-F2(4 6c{Ecxm EKji D WXqF\asUR62Ov,a循AVY[+e̛Fߒ&Q3$bZW '&v ]gq-` ""ȸwf`DƛɷU`i2N/}9gQ}dKv BM?fif`PPc?Bw/ҫsA?8L^pd2E(q@V[Kd@D@xttҬu)4F1V^C Z nfo{{;͚v+qd5eƫDJ1+Ou%Mx_ FpfJh헵pZ 4?;PgWwӍO0{u?}r'jb+AИ8G$aibl ݁ `FUUW! FP&yO1aKFk0o@4\RlS$ βoÅԫ9WJ" +쾌Uƭu~L i+q])"o<}$# ` zV)drFFG&C*˻tV}6v>=iti&sUCX,YjDd>sފTHAy~PDmNȂ 桚RL_[Εb\? c> 6ˁ5dNKdNH1;uÛS(@=bd6#='j|VVoOwQ_}(Vn["Z,<\T1+Ka\f=%qf aO=4 חX&L|g,y3gһ{Y:ȩhz=E;]'5<]\ ξ(*V`UZÇ a,a/:}9 u?Ϯ@wY)&&1[]Mৼqci#ʰ8h{93; >Jn}uLaԷ^GTX"ׅjnCFT 12mbC^Dޮ{O/&GrKAvg0HH1|]oTA `.ŮYLK0@""2GjmIۉ Q%jTŘH_XxF3- |ͥ\NMhЯ#Їc0̄b fQFaTsj}UȅVṬ^Qrݷh@=eb$3:FP"3n(W>)A?ث"Ơcbn.|jpn6lnNoa:Xas jƴڭ!gzFz*rW(OlBtαA/rv1/5ҹ- -F'ǫǸbl)^Y Ē( ]'?}8DN&h^M\m$I dG8U_een[6[Xީr{ l$#/#!ޚ (˲Et fa!oyEŦϡci'7:̵{ƐI&gZ2vKEјE-NYVP;&-Ƚ.#K~ɥ%ɸM>auRbHwD-8}st#15J)E K [yWWו F_AǏ( m?>'nU8Ë>%n ˈYy:|z^Afww$ȴ#zc[wW4nHQU- :ǡ1Q3܈yDfL&像+`>Xq ّ)\^Ƙ MyI)s'Uػ;{bxr74<}ȗpO*{{ su63,kSrMk'KJ8ZIF7*&4Y#ܷfIh ]޼Dvݿ>\`Wa& {F#= ˎ/?Gq5 4vpy|p[7ݯ D:h;$ z R-6ubCMp\yBE0QT[CNHU,^FdEĦ~nB];@?.9}&x&gyo^3MX$:wgf*@xS7uϣw}Ov#="^L\a.DSKY~O'6TFmKxavvbܼʈ膎s3X=[k/Qx{Gg,}u2{:uoUR𗆠^o_vpNf5I1/ƂtM 226hx0x(; e݋G?^G\֑;$آ FmDe,st2= (^/YmPx1I+X$_ΈitP˞ (zHާH{#Љe/ {A>T( pa23 &4_'z!;O?|Μ-PU}×*Mz':!{n a<\'`Amf 9|,Sq5Q`sl&-w6 `F}dωEHAN,C79tbV,LIN7SZw{#J233rOF#RA?dTap$FgqZ:y~^,`,H[NLˈha~`=$y|ţza {5صW>ڐP) ?'| 8&_.M#f9 Q-.ӄa3b[7žH>Ujeᓱ'fᨓoNUCiJ/z i]$z",_2*f-?¿Zh̴ho/np wo|7lKf\_L/ ĴqPƩ?:9|Г;˖ L6]˗Rҽ81? r%bc@UKYὫVP52%շUnHіyԤ]-x )ϧ==I>>ᵅQqָ@V&q`h"v_]q"#9 k{kb' vpIBi~ `N7$ LPyeio#EQnψmeꤦ:bQK;DMYr}$=̺Mj;mM4B?v L:%mtBquS]3,_g ?j5#΢l"eemQN2ߕerZ[R0 aP4rrJu"TNJVj.X0O("kq^k]sѡor=& S l>׎Xlr"`"oN9UwztV?ѩ&кwk1,l(̍\ťu7ʔ1SCbyدrap6_ қZ5B1c>e;.chtxRҠDFRU"tmJs-gXCNIߑA˂/UB}5[_._#KYiv$s93C?2\/J7r@K$&»:kE8< F9|~?b=Уm6{Lg\zj:ɼ-I%rGv$%Xlf1MNOZjK4pE 5|ÉDzm^!yzL̽\Y.9 G% zuT$|;dMpK.i<ǿ+JND5>iQd`1z)nVW>4CZCG*(N$z MiLWie5Tr D('U ݹ8%~JIwvEk^J`b!zgo5T6י|9ڟh b8ee =#'PZAnOlJf.T` ft3xh7nKz!9UuH펊xn˜*iyV߻1Nz ̐N^_iUv w'S͏F,M^qjh@< cwgxg9GF)c:Z:GIl>f_ħ]6TucSW>?ޡA0b'Xz%s  Aa;ZYBy'4KL~'wcZB$^yGĩ&>-Qƃ%6uU:s Wg0l׹$(1Cd:hg:z[;\'q&Q ?FPf|җe3[>NWýKi?n6 %7 d9u =8Aq0'1}9mω+-'68;V|(W'eǑ܌줔SM?p@wl;rRS-}2 8` oUC7S>#ZKNY_ylXH_Kp퇶SyDcɦ <`? Lh/ J$0Ny<#Rt)=G,*kA%(E[YQqSUyL*6кxe@mq AEUJ+ j\rִ(9MjAW76-խ`ɯ@؄ Qq}8> 9AOĆ >f7kg$e^M_/:D@J}Qk:=5}~Fk}3"sGwe|YP.~3dw+N*Ҷq@?,>^wś9ǾKfv|(FxL"b9›wAY,zԱ|Y͑Bcj1$-eqۃUʷFRdbtI$Na֜dsԵP u _cI }!-6`X8fX'3ePEl#CTΩ@b(%B舆MѕtB٨EuN[3088ięp#3X)nGUx[:7D{+. d^SMק.b*/t5w&X%ӈmDG[a!F}O,/Ls^ڀ. iyF^Uԏs-9p=W!frwZ酏Tx`=(׌۪, @{֣pKߐ.oP \X^`}l#I!/bB{ i%6Z@؏y dONЉMǢ`A lqPo;>~x~j֍VXd K>Z߄cZM\ǡ ]%w>OBc-LJqv ƶVBM6殻Pԉt% p1,)xF0aL~8fiv "b wS! OG374/bBw>j]c^ 鸚۹S_%x<e"UH]'g+ܐwպ2CĈ'APGc g^dL40\qs/Zr)y%: 5kpaᄈ#HIڵ!VYeZ;im:8q$4VmΖZeґ7 Q )fXN¥)v:j]xߣ<KG #و njHң0,PbW;7j9Y]U#qDž>V p9^!'5lUPy >Ugŋn\=M@d)٦\Bߵ"A2cg*Q }<`p$Uz?Wu*,Q'=7qٚmh9^sW*NJK tSyFͅTQt!ձkJ+.2x E*Y{10|J~,5d+f͋ myY/GTv$위Xufa\bk_)va#s䪊q/Ht=9vv~D`L[ T }}.'`-+cɢcyD4cU4*Yל!\pB:ee+A$"KeQW1q1E|4n_JfѴq7=H|BX@-xߜ& ƾhC<9Hly XX|,\Vrjv@07`3ГXx|wפ#% % 4OyaC0Xvz3ϩnM[Xo$HH촆\WցrchjkA@WJgw3oFr]l))# ֣@$08Q5$Q喊IG * 8Jύ;>r kc GőzW=,qEID 2_7@:NYjepYuZad  ^( gt,/vk[cn&1ϰAߢUr#l_$J"E?!w[0ܬ$;D ='! ![ыq]Xa_9JW}ؕ\?W.4%~cVsƪ/AF[ZL")...k6L$uFƖ(ݏ:`9Z1fNtwg9 mSjn@QncMݾeuJT^~Zؕ.'c$FVoS?j8H{wUqTt8AgB37c$V A$|b<k_.DwKzfk# 0'AAy;3̩/b1R{_XCȄDP #:`BS(LKE#y (gT+pbVFv3+UuNJnocFW&{FRΡO_ǹjdNrH2%j'N(1(}&)¿nKIXL0c$S)|'NjDY]<cZ:8(5"ȿ'" Slq*q1̾Aϰ6+eJڲF/ލ!D5}]N Noe]MԷO>٬i F\S׮sl_j^m(iª{#DnNfYjPKcOcQ3iv|j#k6 -+k8x&$9-H kT)ҶʃuyVbP朗!gü6Jɭ]U,›^3?5 0Q!Da."֒m&M7uk;Um=?m)BEFR#l%`7S y~-Er5ⴛ1鰽Vf.(C\DZ5`g3 DUxXflET 8YIX LL\t7Acj6VIߣ,_+ 9faZuoȃFDPtt/PGƵL94w M/H2`@J^yKuv/mP%jԙ2|&*ȷ>_Ʈk{#5EɃڍ of3'" FשV )z>xGV'qxǚ8^;C mЯr Zw*dIAMI`oi+l(jByH%33]•rR73 <1Zrڔh.IYՆͿ%a-e5O8hbLF5I/ yJP]XmM-7i N^- G=JY|8,1ZvWà={2.dQxy HZv6Eр`!j10>'D"D/k?;lWԽqln:+cZNyl*^@O.eZųNQ/*gr.Eءh鷳?bAZB½&[Cyl&g&Őp Қ0i7+ZG.rJ Q r$Usɠ7Xp-BTm(aN& FĒ>v#Ax5E,^H4o!cC"hM`ojnlal#- Hx- *Љ/EJ7=׎+]Od6ibxlP,>dYEpd2C\9I̲KO#3˥͘;c;{x`EEͪLduҎLK fR|- $⣹"6=g[B#VVe!2C*%H=95,2egPC%,3g򊔏lv6"v:Eҏ#%K4yQs惜{JM}e7sأ͉ry],S)ʮD{s]O TmV9&=ǙxAM >y"}ZbU#0n“QtBCh6P:rY{vVWSI4CX#8mC!~oJNt_jtr Q/zdzRR>۫% B7Lj(T3 I ī5I*Ef_]r-|wڞ.%,YN|ZRloSհ)gwq_%k?<P6m3J`P$ q7VrUXj,C)y#.UVKz %LL)LENsQJB&2'@Gwe Qhĝˡl۸ .@ syL5sD𒬂ПP )ٕs A,;`?gzüQ۳(a-bS4Bћ&aUiTq|h?E**^e! OQ1F=Z7m)Tp!d3qy`~=Dl' tP2O܊@/u 8.iX|oMuQXJfg^]b k)/K Xlf(.4hjrş\?AZ=,\"Pmi'xJ <5 Ie1kr^9QlDDߜbzW;N2XǪ~FV@|-1LгjjLSUXcaÇj'HI gMZ+|ɑN#V*Pm,Z_ qV^>ψKCw:: eQvmoY5|(%籿 #?Y%9>~k&oAu2ypk#P 8cc P}|xMg PEC5 Y\r)8te![`-br:xoih@R*?s ՋnIRw360lsf6[ zAJ5ܖG{ y#0,cqJ)k!6ěIγ-^5=>%9{E˩?FtoKxTEW,!ex[EۤXT8eY ;*`㘏峩!1#- fW{SvuSӗni̋3gۦWZDe:mZul餭E:Γ0Bg@0):Kf4˭'Slp.9b+`t&͟Ķl A Ud-W 7f7R kv;p)48_G xԡ]M֝H=^+BՑ^C<1rjUcNT* iK!YѪ稠0V\o[hp.R. P9/*3|Czv҂bp \݈N`tzgqCUv$Câ87"L2 T9񦥼] ĶO3?e+^~ByyyVd;}~:T|pNpxt{Kx!6bd_*[M#P?_$H7 Y׀k7,WdM 6]ǜ-K sUmއ )YBg؍<}.22nTo'l >6~6G@GSQ>8F -2VsP!a'sOZ`gG5^GA-08^{zJ,}\Ok'Zڡ8* ʽޮ@Vxsq1jUC&eMRp2mYV3/5KΎη"ؕl22F¯s]& n,EG&1lVt!z`x\!ָZeE*I:K&l@W}tz/:teZ2aLXmPJ`W&@)v畕%QĨ驀dqo`s6$m[CmghG7z,a#D(Uss mv+lANL|7Q"45 b"CW#R':Wކ,1^8g}ŀ!Z2ٔ2Tlg^g/ >-:CߏhZcf\=<\AXѬ#4tld**Y>g3jG. :L1^#ם~{"E1ilUO: 1sTcկZS"֟+/m4=?g2n ~B籂ډgǭ ׊批~au ҍTCHꛞd9/'XeMB61֒(_S \X^HߐDz -ll,@.D[?wRIM|j1ETqXnԋ@` R@`Zs\KQFbU@/G:&.qh5.M^W;l\o)LS\f_t ;47] e|[HJd3c&h&8z㪏!܃/P:\:kJ>=cm,]j@{Buȱ %k.n@3e Bʂ>fP٫+P/fL,S7ڮgqTłHy3soU \*VU!c~ՄPCX{I47aK{2 P'SIZ'.zR!.P#wG>E^ĝX_!;{'h;Cw[D < VXṵQ-lD Sز37%YEsHgmavT/]nCo$ó:tsX b)DOy_C$v$(3? *aGP+'s]Pm27A$UƤ?~-\E&)GoTa6H޵ iڻaJB`%!iC'nY"OI̩nʹڹ떺On7@=^}GPdP˽zdhbxy3KIА#gGHdχ|)8TyoeG7Ze5PLJ5r晩|ڜ(Tq0wMGU+ReH"9膑M_u߄ V[ N"0ĿiMC@TK8<ѹRQ>1c2f#'C})@1B;Eϣ gL,] ~3+o!CB1'+hfPwo#E>ߓJ&& >uӂAlޭޤ\`^Mw BΊC$d`Ro:p *^8qee(5zE`8rh]}~*Iɇ2)y _K]Osklvs}/͈d7i!X 3)^ʭ؊Q3F_4DYA&策9O^z]u~x8؆揉=]h;ٔb1WfO^@Ls|Z/>uo$ðgVѐ:mX29dv6e3XGwx M^{p;$'vz"W t!mBSL.VS)9E=e Yl} nQAPe>u{~֞wxcQ\7kXn*޲23Zշn̍P ]pnկQ0%5оsVv<)BfIaVIu,`xo+{O1P\_3G"HgGz/۰٧"/eܔ^TiY lQd_G2CyIKゑC93Q̈,^34`3: NfB95I[wªbgI!o(]z ae5vhG[?0*U"@?&ݤ( ^,}?sOĩAw\!e5|LA[7B{ `&ym aAR;m*ΩvA"5⃮m]dla&\8xVcZnϳv|P s!Fu%jamMNM\ywҋøy|bmg^܋ K V{f6 3YvS}VP!'<9 Ms*m!¡Z1xYa~p ;nW೅8s y]f/J"_N*Xii]jO8F)A b ǧ8mp&i$JNỰ/ !kt#HGoª듐+אD \sJAKLJ+W8˓TR\<}HIҐVzK&ȓ-w?='luErC(m {EThcMy^Lʻw;j}cʰr9Fqv3fD! 5EC: 0 =/1;:_^jIgLle+'Wh{rNS ]IbO$97Pا ufF,KL z5Xgkk5-ޠ!@`"(e CDvhPxgMyi3ILՍ@3дŶ% U[Znύ86}7VEGTqZJڎ|s'yʏENZ U;bG&L^r/h P>8g!VxMGS̝(G i؁bh]-yZxHDZN=P%}v߽ǹeTO& 2u2S4ߡZpCuc6'˅U^"7f';=>̰4<}m#^(Pr wpnu[ o&ax5Qگ4`?FU1>ƎCS08m1 &犝gQl5r([^`6EEJx]~')~읹|F˃fH#2a;073!9MC;9LB$8):M3(@fYė su1ޥ[(|G6U[|/.%hk~TN0,#zi-^,GT &N$P&ؙn̏}".`a$P lMo]Sh}3_-WTZ~!2rH/%48e0I9M6)G_4Oc{=)*0XC=K pĥYlHAm~uMO$Iz.ۊENY ϊGGn pl4f9¢fE~㳶bdeso,aK[/Gi|ޑk:k, ^W0Hjfyw:LF71 b=1KgB5ѯA8S>aIL+{ V'Ѭ #<1hL* jDOcÊmVXJ ŃR =#jnڛi-aOD:~ÛyݵHD֦Ygm3)M$b"7'V)UQ?_>J bHi oHxɡy h,r&Zs o#=1Tt`^U9RM u|c)Kc Uc'-Zºl&dS'T1~7>yvoGCRlcHF:a5U)tt%~ck?|F"&3V.;|6Xb:| g8c2,;y1U>Pzn^j3)\--ձP=JEZ?輷O{M VD0|dgO3[Z䜨s ҥXRpԾpBo (pLEba%ٳduPNF7j7nǯ8ll+Xmz%RDӊ'+TQa7 T G˒QӗnR>@W4doOv :nVeP%"b TI\5"C* g}@ie= N6s HQMG" wߌVN2-)m\U rzb:%čW݃܂tWeO44TeaېN9UW"ا7D!i$\^4N =N{N^= @T$8o[ s|_'w8F %YC 6cvrPwh6/,(n6 _pqGQb4mTu'3DdGw< `1bi~H~AbpF)8 DS@$(Ab~O&Ё@B-j#޾0X0W)NJݹb>|Y0,om)֛GA:U%aGjp\`Xp~ʛ 1=)bfЀ iJ&c06D=|i޴~Luap8HXKDp}?D. v5z S'^~rZ_i<ߣy;Wh;crNVc`Jֻc 'A)bux f=uXUU>gNaX7.'f ذݼhŦxfCr'1麅 FAxr%Kd5T졃 W;y[Y/ ~bK^A+5ЇekH%TSIj!T'ȩw/w&^&?)5B/kײ>ʶbJ2i[|NSOQyc%I&|Gc9)-dL8RKEo [}4 w&2bWzyj\PY: End7R\o?e7_#$ԒC3xCCBTt\6FDwjc>ܛSEq7KWa:)Vu3v2tD5yqXʺۗ1kjQnLݻ{>+T݊ɘrtk^rĵkoIAY*8IY*O@r7 Wsq=7Np),}\ RӋW v hbUz5Ͱ'2N1/ Z{K;Vodj5Z)02aax,oԩi?՗Opl؂<@+ sO/-kYs7ڙoc4f]evgG ^28x{`4)C@i"[Q #qJih" [x}DzK\X%]j-oµ+&oXwPROt(?Eu&G?€ 5ukn [;(;3\^dE Uy{"o~=-|"%vuJ8RQcs xQ~~<aN{ -ܛ8ݣ]u$.>gքK/c'Kcj} L۔4oמYD|g` Ɋڍ4c҄)ʡlO#^H~.&%ClF$3Q+TdE4YX t-7ϥ!PQ sao͝Enʗ;f5.~=`](}0t센曔5_I/ jWNm]A;n ϫ ck7 BK\ȅS> Q>{0ݨ%x$|Jj`7DW[3,(6J!4A$#nҴbq[2r|I.hvφ*椭z)Z>mSzbD}|PvK5Mw:3m{\6m1Ali &$dV몳fV(yNy=H蹣m[7O7:CeRGa@4dK57vʋƍCA23пؖ;^ܬNMZG{i2_GS)=-L74))|ooͣ {ic :qFFe.R'YnckQj2p騭-* Q\oy,SUh5{??<~̙-ap3V( #֚5Uc2U4)un:]}mz&Oq" _< {&q4-Xy!/Apid:",u (h%zh2o|h9gO[1 0R^2!kIw #A^X<5wI s@ BQ:]:2ߛ;t<=˺- |>X*QA/FҟQXxIaRg\ƿ #fA%وQ2J3wPьcCiXXHܥ*7oykR~ [l QD>WW4^O)&'Vq6O7.\'$2Wk2+njAZwUk:a"ʹ\ }8j2^*2idR@%-VTSc4jԘOĈq2#CUc(-'Q0ŚIcp=@߆8WSƈPR*8"C`WRkv) c ~&]TO/aUn{QW`u|CЦJ*g5̮cr&D[M l̷z'&4"uƞP:U̫*26Pڪ? c;2;xN2}>JF5h?[>*^+ѺZKB 9&Я{?llr{]f8L%q6-TQ'[Aoc[6a+pYʙ_=Sۊx?|57x>kѸἤ9[Lʊv1 ~gkbg9n6A4&h/brJF=^wD[mˌN{K !d9My<-NG߁T m Y_?eYc=#[cpXw 0n1|v0x5VZ`XJ->8lAPLޔS> l8!bq-UI͓4T1ͭQ%/'LaΧ]3%.a֌}AO6>R6ZՀ`d<ȍqn$FJ 6*Tvˣ7S/rMů]{m I]yLDWS&niMGFzRb>5Zńw#!o,| G!u+I y|0¢c.x9^e;E e;ZMU9T!nSλtJ<?괨geZAcuB;.jXC '*r{GZ|,54>, ~M!ݫ&SVRٰ)gT~f[X& u}Z1]9O!Gr~9&6·)n!0bh?klDz3]=Jץ\GqCQc\(wGpLG!>eEsF-Hd.P/YȨ6cs;>)`o>fpX6K'HcokFH|QL(#̂];njJViMYra'k% `(S3-I~'q݄l KK{p6 # H}qr3&=J 0'(ԮY7zvNǬpkóP&ݩ՘ZW<+z#ѣ_=AuJc5ʸI_=vX-;I3[t!KvkZ6 U_m9*GUG_m p7)Y@^6„u8%cS9|TM¡Z#b̘h͘:gU6m@L.!5 h$#F<}Ɯ9,D2eo_{p!GuO1.ց*.kf(HWew3R>gD>XkgwӍr1ŪXgދsƲ6zzәS}]|YÈayaI?bk,/Vc|J{@ȟkEtm^1rJ5 cq$7fn-{9K],ٺSȀOo[x?8Xb$m[ȑ{B?BxwŦI@Ӝp4sX.K<:AM4D`ep:*eZ-cn99J?FQJx z9KuRjcѓL0RQ.uܕbOGbГ0-HE֖'ole<%xJ9V cAY۞[ B$eC .XgxM>ҡ'.iCj f4o%jm$+łk#|R'HUV޼ijfM#xmv8u|iFw]ѲM VADR}ASwT8$Py()GPMT]GI2kCO>&v< nEX.0'DJ!@(\?P1v2n$-Y@i~77ƥZ5pX;wkqgAm7FcSZg-RY&LeAPptXIP=5ct2E}'=k M G#mZs-a~ (Ju8T"VZ ? jp[}^FGa@w#/(ĥ:u"iyrω>^S`MĮM"JB?ӻ8CSavQp[‡td8";j m?DX*rڇrt,Jo\@uЅP/6 ul^) An+L{cWkʼn|yK .2- 76<=HByigAξA q3d?*'n 4nJmՎ]ZKĶIH2sWt1I.j,>|X\Oƹ}╒8Dz]#fTHیSp!4zH>A5OܯzF'g*6Z 4 ]ž:A1P1dX#ZWd( v?kɕ7p@ڴ6%4sMdF3gh(il_Z{|]a 6$wL$%1[QxOe7v‘Q&} <ܠ"R-1?u,ڐj{kE˟⚎TqPD[>O"!$E1$/C[x6 O>-0r]V̜wv$7S18i,3l]D:.B֥"oMǗ&1DTB##>,-\.k>2!  šw!ۃ6OGȦܻePQrj QYk\Hvªd<*NlKgwFFB@BMSUNNJD9,$8HPp&<h!~bCa W7$x|#MF[{v-]wsD!%'3RFq- Bѻ_HjHutuN%~PbߑW4'#'cxYg$B\PٟuЌ"/a@X@\tY*Jӵ;3̮fEA"h{_E$fS)J쓒GC$7Q äS9߂nl;ޖTxOSNuVR*ziI{ s}B\_^F/s#K25MEs/61ZF͚E4'zkG3H6cmǦ*ܺ{h؁-PA߶%7o%}QIp ojđpiטݗw.#E#5&T l3X HFGu(7N8kl4k.(GgcX_=q( ]y, L ܙO[ jqC[QUyy94w s6y((l_F0ro|t }v@mJ*SٳѠOVab>ؗo:LQ 5xVN&(QA(ddN}Hkl^ ЍTk/E׉`C:5T ͼU̟ kO}x#Y1kcz N+S]&\ȅT ݮU7mGJ S #9`=3ג.mOiqA`YxH})B!5 2LZ9z8jF1VB0 $%VZr$˧%ld벆dNX]= T _ܥ8xz_lG-71֜r^tɠa0)ciMh!7„ĭj `:([= lA,ttFU*B_eE` jhR#i1Pi )ȑpJfm]?(9j"xx~N#+`Xy×ʻJA~g, x2%V{Lc#QiM~>g/AQjOm# 玄X$U) Y)-G22ZGP<lˁ0pHɂFrТy1*K`"]r\+-Ƿ+XEշ9Cs&ՎrKI?LEr*u)YYf\ u l&t)Ӥx`!]߸Op |kjk0:4L17K׎1V$u ׅۘ2uE•T$aov&}H;lu\bkEcҲ zw'/>3҇*Ow0vƗ49^]ݷ6uQU9"pT S!dbPl]*z{uF_J:n }x+CjDX[ y9S.ػ`mc"L|59~q EaZ!d ׵K5LMr`ZUAnhX"؅1wh/|#% #َ_A YFM23:[09d_݆vWF(+1.ֿ>6M E}@R,WDՒ6WB8ֳ_ *d2EE6vG gE6z8b@w< `Ly:kX@Sv_24' V\*=jiHJUf/K NmL/DJ{i]yւ+mӾIm4=X@L*~Z :&ؔ9P}wHLMpAs&H^vC,2{b3:d`ŨK=TnypRh$N'4[U|p9pr 6mZi-^tG[-% fqtXK]4|ҕs<yj̻z~<[HuD#D J#]BR8MH+n,'μ DTh Nm:J}:2Pjlp$ka T3%TƵmĎpb2RF^/;+`NLf+7Dx`:Pw.A,8^y81OJ.i$lZ܄cܭ~otwX>eSQ\Q0&܉Dh/fה!ˬݶg(BY^Am|P#Lk:8;a ~kSZˍG0!4#m9bB_, Zm~-)j8DKeflqO#9{5@|3ʕD}4<`Sc)O1 9 ;gln%(5xlŦ^Znw'qo@r9$?J_֞Ieq&)UDxPkI9( X ̀|6!A{@#I*f u)wggqC 5rXHR=7~0ѮrSfoNr9urjHkj fڦ/SM޽;Fʉ6SC8H2h}d"%t0Lx"|+"1dʵ-mWKDU~pTYuX;)] M6^*o-v~P>9FMRZ]lÛfm8'ݣN#rU%n;]'{IҺ&{vJx72b'Ȥf/zĭ ^Eid%챛.l>qQ{3sF"W:3du uF(ZD||ҳA?Ϭ|̛C'2ȡ92n/t[ [t.iF}e઴"eAw a\ڣlhoO]<1w s}CPL ^˛w%yY@UjaANy1i4B[$sP-wHoF2+o߬2T;Yǣ[nd;7YBݧ!F*X 7imkĪ%#Yh`+j(]&>䆄?kC;NHE!f=bAPoVTy`[-X-,u8߲C|YrXqMhb!οҺg:qĐBwAY8hݱg7jA";Z J+FٵN yuCu&:!qאШ˹5Nl >'iar]0o*tSC#bs{Ν\tvdXFNnC ՜S1Gi gGú ]µC=,C[k`오hv$ B qV0u0TN V6 pw$|w%TJ[+ꛢd:NFuP]MBCٞm}?zԄr^pJ6P) kQM]v64hy+F#؆yH*ޏ+>տ <1fs}kcɈhz +.k=6@ݘ3qzKJ.u$bcn)m!$`oUvl4\qv<Mk#o joi__RO9,܊^_1L.K3N_F!=U7R N+5On:g@ozRZsE;_}kנ΄0ax׆aIXɄmԭ8w"@j f+gR$3G\Lm-v5VF/͌T4 (9 t8'+2}e6JZV֏mvgC+!wIi3 Rg*j1nڣu{$U^.t| R#;=] 2pОu@b'VqaBz> J'z\XcpcasgJi{ i',ٿOۏI&Cq6ݸ8U;Ѱ, Z&g=+IG;[ bd;U0.zGRQTKYw߇w( X cWM#"+ +`f W36|MիYrd#nJ~%RjʐUy5[n%%WB)2qg\LSK"WE\BqYOn#$Qx!bND~x@""t|=^3 Hq|j3U+{xt>AXXaMaPf:-}Lbo~>t~U[G}jQĠ<ϣ:G;=h6f C6e?W+~D4Vn#: Z[$^'|/H PS_ڞ:]־M::(<'R/<>B]ۗakqER]U"0c< U$xyRA`47DZ?2LcmIf89(Hj/zkp*.H HSNjՍpV&^\n]<il]t۵jj55,J_i-X, @$Z2McqII~׈:oƾP2SI\  o]: cҮ[5Ə=I4/}BYKfcP1[=̓ԲzG7:}8>{gg&ܦW!,{XGuA*zuXU~L 2).M4f ̘*M~F1b5B-IZ zWCm\c&0U`2A֭Zʜ%ۢ]@zؗevR'&զEv[t5p%~cPDXa"?>Mqm9:厱 *ÚV#'|=yX^9R6oMkb<0wnفH0D9PPTa[+Do(C}/vX3XT*l=}i<9x`/GsM.zX'׵{!xry2_ 8A(@ ? $ߚd!ƌarqkksBces*H$Vn.CU4ҭsl Hti.> rUoV<{X֤ mmWCW~4|Oi_>mĽ23_8A7^6(];P4+& PX%3aewʮ ,wf P%7llfY7ucQwwm\9GF̀1qKF^{;NcOz)PyE,$0iWG{ٳw$S܍&~ hg3Gw6UL&'̗F[iN$~A): 5-^.+ c#y)PPCxb3MG>IG'D<!g셀J!@bK`wÉM#yB yRIN8qxQS[K)hg fyܸa &qL˃Z o@\٧X+"l&@<ͶK KD2Ǽ뱼 }L{_;F)Cw”ANAǷ:lptvcmJOt cqCR]pM@8<1ӗLܼ#ITh4! HEn,dᯭh1oi^dM) Sx)i^R:όL!}`wڣSNY2𡨉lkm*q7å؏YLddNo?.g/GE 1FA .0!gV5&Q @t^,9* )D .sp H3Pp U;ACg/=F6ssБwTy3q! E+בm8_Q`:}M\"P J|  c}?nH ;&Ӓ~d^;HսL)yYqK ju xiBl/p/Y'a =\N`]N~cI|.lLdRo(e# ڢbu*y~UShϘcJ0n.}`-GE|]K(gG#%,~ ݳAtm:2q?;ƗfͥǹA aPW=I*Ha8-ξ9akieZޖJu'x_ 㡻Z^~9+i "繾4nk0D&U+@ⳑ.w5wS\Qf}hIj-fU0>|֘*9,Ki v[S c0%%)so/,jiṕmпYdh_il<qv~7*T 0;.kYA9r')ח\IAa#^Ω;\QoϜkC|ERuqu7̬I*g>s A<qkb'[DZBN}Q;Fm/{7?ǩMe6?l&5U%yVwR7\]M-%|]NjI2QemJ9Spw 5h D>(x#-#3W8ꮰ;7fB_Ma v[{] NB&w4F:gBDE_S]ϸrq:5R)%|#G6P%Wװz*S{ 42g bTAv"y 6|Uɺ=h3P.y@D㝩N k~d'}' Z@s]n,s5vEk6Q4ȅmW@BӔ; cProvۅo jg??av@L.@ֶ!jyPn<o2FCs& %ToZ PZU'85$źŴ40ν3AI;$y&[ot>-VIyW=Al@A`c$CwX~.9IdtsL!N=t]g;G93?)\1 l5T.kkXw\++os%Ldڷgl3ăAxQ-rC2xspLL >~*Q8^)gwk{*Bښ e 0JlBo߄K{9ץx%).I4X)ן(]e,_u?A@ VޟVÓ B*rO-q́Lhjrx:x ۓ ͍|ei=\1A `KQVX z/SNTZ C.P ^`oGiųK}0D~1Lɿ(d00$VL9aٶX> QK{F\Aӳ'1u|J/#ŏ<Œ؝u-:/sَ8S3p5I[Ct}+FWd9Z3Ͼ”rgE ۭrDmf@Ms} ['O,P5.bjN+9Sݕ vD e9 G[ _hv!)ŗicbG )4o(<i\æͬ|ќi hn eI!Ul <#VIJL Z,XzՂNdLa-&磄gKW*>̅4L =D4ThǖaXVBҥ MCNe>uTk.ƫ#sm26 s54Jz JVuH H,Yů@aq)4i2 DŽB2ww.E!c_ܳ})(uI~80A #fE aec'NLpZ"#F NB4 9&xt7'<*tk..f8p6ȕ)j_ *? 'Drl-(-kx>Jpʪ‡V/I5}k?Pa dj,&m'ziˣLOk;xM'vKa.RXzyl~t0 b?r[ysJģ&soĮyl!=~&cym5CuegM /nx(2> y&)]׬M)0 %ʡ8N*hn܏hb=ҟPi<cA!-t{ݷW5b$#c!SնBw$-aVD&m^#b }7Zj]%QM7izRHEAPBv`Q'6 ]XTilqJ~P `kH*pgwjw60q!BX_5{aXd"Epψw>.W2$eBo=/0I*Kk'c:6L}b9p-<`umBf?OA 朲>HQA*OPirq[8ͽn~ (b{Zj"@q&!5|MmdMM&trJ~'6ԟ\[uJqSS-`48&/dvx%RDhR# 39>DAa V\ %r\7S[Q,PX XNRIMO(rn['Ŗb@CBH5E^| sجM }7ϽPP>R׸^Z~)!?4 %ΊgNXz$S.܄]0u+S:'ɋw,X!4#} f-y)69D ;[6FL,W)lyT׆O~vvtW|h$gR!r.-6ydu/g.6K%3/݊m6LY@G "fGVaKXIs<C6yDF,b A>c;?-|B1g5?x52V`$ϵ%|1L Y ;|5!5`mSiӼ^&_Cy.jǣKR_X}򛿚wEV\ϓ%cꟚT"rf|̪{ݽ48 +Vf\z+v,36׹$-^OJP_-:Ók"Z,uX(uHd|@s &IZc@:b4?.[*PڳomOXnӴ.*/zqm"?H/,Eu+ lD\qu5hZ lQ`P+RI,sB@>ܻ/+nkjvMmD)颛 z|{Xoٶe6ɦ?:0YR4WlxvE˓?ẆڽY$Qd1LTZ FkXLһr<0qYP8+oMHMu( ⍊h~۠ P%bq0,!1"CN {_]O-P~y{+4X NNp87+oʝN&slZGO.D#V3儎\<cdyZ  _yt@5[+zt[?ß=kY"H`5SɢwNH˯?Ci >Y.InXVd(3'TK',Y[^-4+PF6e̥PKN<;цA."WX\xϲ+M_\ÛU1'<޶|O5VB&vEIDF-ʦVw >~08(2[QN$GX$rd&ǻ(WAYӗ!N5X2*+< cHa%ER#T)! G[Y!2@5ange<%[g2f[~=ӨLta?LD@| i|wY@sي#_q3#U&4Zo/OLNf|b_wfͱ0bBr4̍8h ͶK= GǞ1b+C{(8!`XOOJ RD|J{8g3<ǁxؚq&bfu;f(&nhy.ls6; (OÆfxVUoZu+0f4%J]8OESKځdžǵO)5,ttU$|m]XXcF;1Tpi;Lgfx)Iiٟ;Bxg2:56[y,{ 7MTIqz+:V7rd$` iOgj^gp6rV6d+išlz"xt{|r|7m،?zzcd ߫c" 1"%H:R2uiE~B5+ vc״x! jTH>AUWz=|KQ$ U0:H>[]z3g][Lώğ 9Gx<&zV\gWԴir뵨a;S{kZH ]Dr~WCý g|Mu,tH#u5wk&>,8F3,#fU6\h=uc֖ wpN>8@&:Q"P4 EyKn^&8۵2Svx4aGJ*5A' Xb2ij,9VhpBt[v2h, w:!ho텬͵\jyIcesw̪Ė[Z bf.PY[tЪgd80DOxU",ѽ F &—F{kJm+@R3S6S.M-%˱@is|%5]*՞T 5cݺlBy¨˦yz*j[0Y-OD;,MtacM OӜ(kԉ-vw +{/Y֖E捙Á6rEP͕UIv77a xڧF/q|ǹNe'Yytz#a$+ÿ+_X{4&ٕۙt Η`aZ 꿍N[րޞJ%h碸7KNZg侾>U bI\==k0K#ى҅؃=CVC\ Xngh@멽Cڽ9aJoEjfTo-tl@cAPI?ƾ^QxXA.Bx練tfm}߲ Gi%.n/HvքLJ7< \{%R5%eDFU]ߒCYГ֫H*-J<`^4,:Ey9~8뒖r+4$#\*:0⺞BqZ#PSc)Xr`eN{ڷ[2ڴ{HD@\qR54}=ENɭ rѻNMayXx <(ɚ_),mm/5ʇjœכI:!n445:Kbr\- 58땋nw\#E4dUsT.9y\JqL P̀S+lӚ&y +q=FR5o{8X;iS(jO%1&1A%B 2MZ` P蜒Be f|x<ێ27ժ67o4x$u^(6VpA؄oNYC f\MeliʅnOđX]&W|fp#3 qJq>*ڪn^&D˞f,WRVxVC&uMC[P,3*jtCsʐ'70ԓ`񊜂+Ѐ3z4AXk"^?u M1V:0l?˪E~ x֭NioyU!a#53jl4|uҡEԟ%Ja]"Ȉ';:.f_ xr[ݠr^zu~cH2"cQD٘+cH")#,+!w{l̪34{J.9XCl* b DizCGRwB uw`#ml(IƘAK3[_A'~: 3?o?>egs<5kt-2ZE |;eOIz0&\ >n]Dx?jCB7.#Ybe>tf,X9[+g~YPs̳G* Mb^)Im4? Re)ýؓVf;=`D{msUD?sS5r3UdHwAZRHgy'ı} 0ahO$UvJڸ4A&o߻8—Y̙4/J̃,p@vZKTj>ɠt9 (@_FQ]pQ% @912%ĘU #АuֹiPF^/kwHtn ri@lSdfٚ& X=NU8nz\Vӳ0~)%Չ D:m"&mSܸyG;"h+D#Mb< DQt]C45n$ɔ@:is".~eIKeRdqυ M~-DG9ϙ '/`ٜWQ\TԷ[XD$oaX80^@BBP P/Tj2svA+ְHYBws9GU"o44ӓt~J'y@5VL1dOt}NJ݄Yot3 eSx5j o9>PƠ0JYȎ ߗ=_2=Vl)I:].-e'=ɸIQG`ƒi8U'*m:CDºbr%`=M(5O ǰ܊uʃ |u-QBB?e-Ni&6/f+g#u[6VjN`!ՌVv,Cq nvFZ۽=N`%h5 Vvh\FjEi= (Of4yt/rpD F2pS qzEz{Qx<;ܗglpUzuۦe2d vwN&4uWgbn*Z͘)]1zgn?Ȓoj}Up8R(F ifUe߈ _a.пlK~?)͂Eu{]zC#|+Ca{=j/Ds SFf՚MQq0Y$܀fK,֡]hgA$zؐG7: `l3V Q"T:113V}[540P=sp&ԐmKY㊯Hx_jTj7$~ެlw-luſ!:^뚴 {W~;$P7f/3 a.USg/&ÚdfF^1<t1CBnd0 Tό ∜Z8/%w@_&+,h=ἣ٫nYcr텆WoQ.PdFJvҊR4a@oWÑL6Yy!œ.J H:4ĦT־t99HΑ,sXcy{VY3 s*~4 PТ.ZɃwUf4^}yKIz[~8> xݻ,ٶb3)ʭrM0$ib ~'9R\V6?4gFZ[Q#e1An:1Y&y&kջGI!g }8@a#pkB"e !{75Cm8ѧJ([B;zmĄZp+s%&\fI~4 =.P,h. q)Ts~hdw;8aKJyALWL<]aQi *ISz?7:o/6-ŭ"zKj6Cnu?7tsx9{%Mǥt*>{ eWH JAw??3+ =kn?UmA4@nGd`I_mOןYUq ]_v~zxE5}BpunK& w9BKI[P@P! X(t/og?2J\4n2+Opybߣe2z0%y^bƝEnO; W 8]˺ĤPy[(ybK虡k%! l?T+nw]-?1肆F~dE607 *|ICȟD,fm/NjHc@qgf<(NXގޝLn:1\ ̱NTiu):VT1|j~g'Q9rzB3Im7-Od=H(F" 2aJXz{>mp8= {)wsf؅^( ?&GFۉ*KM5mėP%Z ЍМtoDgjs;'.e2V$BTtr3Q}QA5d>S8[T'Yteݺ Koq(oTvQ#&dZ@8VAmiy!5#/EX &_SiZ0`C!z|K+_p󶫂~(c0r OŪ DI~7.ȅ-bӖb&>0gf )]M/(0t 7ȁf-i-åeJ7 *lugt>[p$^y 9[;e[JIEKQ4jIy弇 1.\?șIágA8n;ő]ce50ѼŎD"@;1UܘV_cpd-&I渁j~U@=]j-U6*A2Np9ok.e1=?qb\[ߠ_5bQ>O jݻθ8{<Z m0PĈ!,Po<#sUZܸ8<3Y*GCfgJ+7nOBo?:|ǚM`r.'R'qHeF@ׅ,|0P3o3-u -Fj% yk=Vb!;hAP]&gzBkS~}̺{}z4R(2%9V$V9z\r,IYl{n@㉢ISXL 5X_0iKLVo=FlEjkd~6`;θFnP/)C H̪C&++WDUdIT6,X jJ%#Ly&)[fxof>WIƉqm5d1ܣ0-[9_oNzUjlO3\gBj>^NB;ɤ)rJJkH /tZf]26Laxh:ܥ7?uCv+]q8m頝&pt5&MUZ;( O`71m N6jvKoBߦ `BQ$aVIfҷn\0xWq.x:﮼M5:? ;& Z?ci#}fiVصz!&c OS@zD͗cA,pH܂V;g~|#E&Ά(t%0~K)*okS H8-w L?ś St ̯n+5mtmXDR.iv%Ϊ{u!Lf2n5 Ց9EbOk_-.+j2Ie~:6bsמ%H/\LgYjK KC]3V\VdTpvXQa39+S![KQ jZZ,|-hA#A9N! ŒݞjDa&qJc0n@;5Բ)C0G Ig!IT*\k73U· յxa(悱%bNQ90M^课iclU; u$+)>՝* J I&vbcU_` v$B6kW90]z41 +2Q5^<~OmN};PU">!:2r %pQ $NU|EQZF+DPjod>A{2L=m$Ԛ< 7R=.zDҬ\ttdΧ]#М2[mFG/*̸E5v!Pt4.->>J'iiGw$aO!ݝ+yĘȈEΓJ'n2grF6I}<;>I'Yq{Wv|$]gP׭i+qO24OX%Gz bmPX3 S n "Oei\DZ%W&L?H|+52z7&z#e\756-d|w}V2/zR<7CɎ'7HV}dZq?|ݕE)TmGQ'/Spy}6hJCBoTXwEe.GT'J L61lC]XVU#ܥ o ~Ӧ 4UЀvuδ˓ErElz;[nv.){X0f\CZ5^UnX wZ=Yf@(Wots[3.J({؂Jɿ~ (QяS5LjۯRݶvkaUI~ Dx5EBlc+HP p7,l,4y໖}%Z ;Ǻqi׉BUr2G:wts1l%"a҅_8nɭ.JՋ)VО:|Zײt% ~ ])XKT칤gڞ:4k-82$+f~K34R)Ң(RgٷT6AO p } k^4M&fU}EIDn$1e_gP-))OP`sîU.@=|>/E}|FVNC# ꣺7fkKfrI{ x!tb] ߀8 P T'ްZl˰kR/Ӗ[N Ymi? c*NB]>++_?Sh΁I7)]䛜'R#$xZQic_aKWs ɼPMQ@T3zQk 1NM=Ba#,|Yd7,}R,")xA,}}=V.3XS>VCtI,%IOa?j^uEh oN98F7hI0M&T',Ω}Y;D`X )7@4Zb˙`b/˻[9Zt/sȆAH_ؿj )dDײ=sAX2筑{gܭ*O69l }Eی~\K|{+!i=U 8:XvO&R2Cvr3p 7U|FDOa9՘킋+ncAS pp3OL=l;Z7T_I|kZk yaRR ڡ-D&r [mH#Aec)ڍ̃kbV&+ 1ֆ&P"rU]}K 0^|w*NA2҄MJhaHv܃nPfV6lړXaQ8kx[ 5\} l9ᦝ]K"EҐjr/S|-:xEv Re<=Wv踮宆&O[@)`yXޢ7~J|hHeۮ7y'팢Zu \H^X;PZ0ϙ@-őazĊ<ٗxv_ַo<2}R*p,^~N?+ 2tLq|'Q̢l'Sxp[ׯxS_;G$…~$ϼN bQm&짘2³Zvun $#ߡչH-:$oV+ L|`k[!-l]04;6u?Up 1UH/ $!E朕U:9e"(so Eƴ O(Tڻ+yũKf: Z/`I|V.:ltXu:~>7N6& Pw<&ѾB&Ңs匪oQ5"'(;7o]WV fج6m6.ͥPAy^E2g$-7䫹ꋯSH&e,R^[to5m3R]nau#MβqdPu#yEejR왩P1Ij-[3i~h!B] *|-Gsh~r5+̸wn@9f?[; W 4]PH;𤢺+08[G (C|]A-sNPKU.AgU$;G]癦9rqm1IVq»m.T"&> 0?Jq۶?: k- )%@eC %Yr vxk#In&p(2S(vM"1;`In rn"sg FCGyP͹<<Ћ?`߹]ɒ$c;!qoZ /٧[ .9+*dm\--M6 9% ,De*U[i%Kt\%1\g͓F]a&50Zh{8CՉ !yJ8_~aOwܶq2|:ǸΑ*)rhE9yi03xZXrkD6ztHiloAYUola, ¶/sϭ8n)j8veR/SmsfOlZYb٠s}\\BNּh1\oZYS0@d/!oq`9{%lԮp#\L-3Isz,L2ʺPQ+#K;؅/ .rlyK?l]=r1a :s&i17O7ɼ;k)py Zh,ɧ N1-ke n͛;gj? XD"2¯^Oi9alxG v!.CZ}P?Iv70N #k\iG ĕƨG8I%Fܦpc3zRdx4g(/Gif]}l;xeSϦipk"zRM8s G9Fu9ѕrL+TCh>8'20T&/0R>psY Id=72^q]o2 /Gd@?e,w'w~iJ"'[>]}сjԶ_=G…V'(u 7I$ԁ5!zG0dh&#Fx@7[35ؖ_;ϰ9xm!$Xs?qD&q6:f>@)=Di7>'?&8yqf5νDmUk,gp? I}&q%|M$H1ş4Ƙҕ,zt *JF!/.WDI7NԓEm{P^AZ(l}KɿkތGRx.C"|٤5?#kw73+Rֱ&_,6e=%a2|w яߴ)g9H=0$ݖ^$.ΞW@M3 4+6Vnjw͗B+2| PYVK2N7,RQ|ř%B{gtśWo&t~x@g\%8RPG]8h ~Y OxZ<: [}4+ɶҿ:,rjLTծ& 6ؘYt cu SʆR&Fǫwc%mlF37]SQZ[gV8A`ʝ/筓hjtd , h?MbY^F)Z>) 28Hʼnc89?&`Nzem^ ,, +LVܠͼb*Kz 7L80ܼ|l+7]E`n7ϻR. .,#8A=wٝ*l`ۥ z01LR0hE1JSEZz} u,Z3{0Q HFq ^6r k哐cqF9Z^C83!: XAX4m$#/#&OSS\[3LTk^%|c:=:"4!͏"`YdISxd _jKEcwRfoBpj'6{ 4̅5F5 ipګOЅaMogI<\Q RH$;Kv݃5γ gKVA2Ym3V9*l|ct jᦶ/Ԅ2e]x?jȲKk|OշRK!?|A6><򉦂ShŃr"VD P,[TiA~PJ/ɏEC YƊ0KC6pzA08Hjn ӑWLJH36]JA03l.E,=~zle6x+0]{[IԵKN|q#X BeM( p!`+" çxTO[ֱa|a *ҦX1߮09`$; {%-|UA6[T8a+[ #2j#_qƢ`B4)=OӊL 톈Vɧ=* ڵ L5,%[務ЦW!e) j-A>]Aê}}kF"qtج= î^@ob'zg,F)Δj{3ɕaѹ k `tG&@|,dg8؊؁IYlP;忢=!* AMS[kp)4 r#eήfFȗZU;j<evɡg+%A؋*Q<H " .7{LM9,}Rd;VC9i^\Ջt B~[^(t 3^j&\jҶ =:ɞ'Tð 뵬کOl\.P-GC7T!ܨPrXYk{<ksp%72`7~5mGy#3g rWΝWz88۟c*k\u [X%&E#vwlfA;2J×jɶft٦%i' :b) =.8,t}@^5`jPri؃=<灸4(,NA<)&T4Ȱ~Py';^|uZY\7ْ`bvn3ǝf@ ڿGC/; Exsũ(~`_+{KmFGTW'> d!Wl?W?5ai2!R)&>jE ev nc~JS}h\v/\a9fEBP5L~00wA[W[{ډ+@&p}n$u?8a ֜f~&W@CNx+5߱#fM?>]O#Eő<n0zW[t& SH:)s?C47ifI7ύo؂iQV|! GbxCnRC2eaBr[jXAjiQA/tň yZ,8R!DڈKRۇflcdy;{- g7y/P/ɇ pvXsۢ2,Z}n7ʡk00ܵoc<*vv߅(sm@=e eW jn, WXM.d 4j]ɞ3zѦPNJ_ EhAOZ9'ݑF3@>g;_"DeĀ7:CB[ <,Qʼn!ɂd"١ ##=B;Y ʑ,{phaN P a<򀇽$u?(Cw_ ͱ ?V9p*xma;@"OεὬ[xC}0 ڍ2ҽiAu:QC8 sö/E,R=r$X c9!+ߏD+?`T~ .-M-WlofoGj3T>FKD$\]wU] »^3 |oTIִ'y5sYD)iڳ h=2 ȎAN}Bx[Qb_'vvVDfSKN,;4ȷ0<;R )x"-#lєZoE-?P򷯟ĜMkٹh3j)Gŝ=v41>C˽$ D. \wz.P1v$UVqv2}VdVB2I _b#>^KvӴ@lĒK먑/89tױ2EQ{f`c9M}D:l(Еٕԉb7\U[J;g5Tn4; Op i+53ݧJn_!MHC)L!*ʠۖ E$3Fa+))k:["_By}1@;RH︭`i(ѻ@_/ʻoSq{/ޒ CɎ i4hC&C!t_n"i!'L"hRjj<0Wʊ/du🝐l\hU jS ?d 4xV(/'tۆâ/'qQM !5[T)kMkII1oGDz^aB#Ru@"h3dLID/R`mv,K5M bTX9%'${l*<s;\t. C:P$2 7 : *6PP`-ʣ;P hm1|"HT>:$ze֥QZlpʞkw4sd2sZaU|]z?SlrtsqHT@9I6bdƋsPٛD@j%Gl/3 _ Է,"Jn,IK<:Vw"V2GX6 ΐ0\Qe-{|٪e^v'͘xL jR (-@? DtJI=6]񹍫g׏& ҋ!r}2Ӻ rJ՚f z&s'%D5& H3d: pUi1=Sb0b¤Yz|r,u{/ml [9P:yj/)KPd#Iyk`NChV&XLj롊r\,mRρzPv |0R W! XIC+)[T9?Kuzrv/,d5Zlz0&A̦.4,?&KU6s\Z" ĭ@5zR̈́=7euCP4=kۜ?QTS-W $q~GTޱ /8yKNEuxЍL$CAql\T[dW%-Mw[pnj}ZRVw -ކHȸB)dz"jH#iB8]PGlXحQt0i4cG)Èd0VfPEm1{$k\aSb|,6Yьm(K;vuOK܃<4sV5'Bs:E ̇[^Ch_sn#~&*4c\4PK+ xU:(}KӠS:\- F+U\!4,}sѽ価S㧕@=zj^PL]V3ifQ$o|`CQ#&)3%60yV56äH*Q? xr1׈F KqC1őxxksCjaؖTA ^\BYK7C}9V;ZV8pyhIyM5o>䘳X㒤=A6^)jD/I򋣋f%tى@#׮2 ۈ8MBĄzAGb_MK`~rC5+xܼz`] pmR0-R*-;4(8AتjKI)0ѷ宔paߛBH ^\SULؐ "͚MaGVHݞ&7#Grn$:KƙI g}>zOսgtU#2d.D>eTUAS# <6(@WZ@uQ~gX1I4Cxg$],ӅV }֭EYG+$k.Qڌ8zÍk 2;Z lb%ŭݧ_x`'La^u]8 }ʴT˓y䣭Hyk&;nS}0kuG Zx٩D&Sɱ( bBLhK6L؂\h(xP HYľ2RHۮ/ |4]#z- >…])cAM=S%g.@_ "X!gk4P}w8eǩȊXf]Uў):C@4R( -%/Z@%)6D$ 8!/nJJP`?CM5 v{ɍ}*lORHป&gdQ+< ¬Cc8b"sq7L伴2ҷFW_vovԷILA)ED7OWTR/t;n]9L6Uٶ#GޱE,k=׬ Vxx鐈F=~ :]Ԛl%N?p#Nܸ|'ȶ&eF9^SǨ2Y;65ꞔ^Y`b;5`/Λ6NB_*`Q[d-7[ Ԗr!̫/ܽNE}ﭹѽq!fiׁm9 U?\5”=H$ȕ)2_{l!6!_?֦{L݃tevM0,XA(5Xd+QS}d.'A+@1өH[_biVqgNbKdTq8#ix"~e%ůp|ib@K{P ) K? 7Q_ϋ+ڻvCLt))zUTj& Y b^n*ɺGŒxFUKVT+RZA""u7v%U 2F?L zLP̳'ĒS01Nj+0;,`lR L ]Lv@X }ĶEs={\o2E9X5?./Eb4 S,R0 g5-'xwy:N8sҰﱊ-}9$%"YOo-OƎ J *Y&{ WTixr!>Y 6 }hYc~^J/E^'Z2ރ>j'6>^f()* 7UmFzn] CbǾ^W T3a+eH$/(']h}_2XЛIw?jʼn0|A‡X%rj#YB/$|8ߌ`RC"gg|W@.|4R 2)fpNPDC9{,w||k6BL W`9W\,b⨐_e332Gyt*ť8D_2<>2K[_pTks*23sJ9s:Ќ_ok`#I!m{KGQERfRΚvWAR(q/Hs-w.U %+vaaͦ>[!ĭ_8j^22~ W,H"8[^'7yQg~mĉFg8 [VMt?*0Aց]&!P$ tKy|?@3^RFs¹FpO%%Ź!C#bf+ iXQIySE;|K.E`u5{v;$e!C%4?kp8xmĽA,K2huE. Hqϒhd;.ftkveḎ/dYӆ_ebႂM] یLSK~R ca6WRd$jV!}9nʩz2"FpnpT 5 o-c訒57UmeݙDnUѼ/*ejNԧ&noaW$fenfj,ݺ54Ba7q^s 7IX*WǷua:eeչQ] <ʻ^ TNRA_k68ծt~ˆu#[6-X*~-6'2]{EU!婨e|I dS&ik1AcBG@NA)'(m02͹|=@\ „a

q࡫DḁDj9t6?J:SNl [ܗV|XRT }nlzQ(rj!9Jy?&Kh7/ܷz4ɷ^FD{-<#`IY''[ i^D ym:-&ͱEQ ]f;?\Qy2n^ruL`9q r3Lg" D>z\>Ę3:! <^A}X\A?bfTTtl^k/ !(\B'LlXj|A8dJI'Iх_2AHE}2eGw$sF0UI\` jI?Bn}PD)`DeL(:ls)қ2[&94\aƫ5U/!ȅs27!Ďoi~ve1-Zx9ACW0NYw]U{`Yx:iKubOMCD8V`{ !I )(nk _Q{QYv_4xla`FR p[:zƎ؆Q7QdyKI%!d ΄/RnTz6P?ĐΏ1ƕ)|@>H; b.WKJ6ĤapYƍh,ּp/6t-b=#LuW;E SwW̡B2^ZVȖ23a d`r>\F|ڐv#PƥJ29Q3ܹ0*u)mÓ} K[n 8HNJ"RQ*N!ܕ|0K?dw}3Ewe\rlQ[b<=Unϝb5%HE&wNx :gq* )D:l-U!-%L[<2.w}5ͷ _G؎ŭ웺EJcHM40 o9J 3yYyj ;gy^aKkz>(Rȶ;WM 1I 3Jr-e\j81{T~u;V7_R~9ĺgy0hvAMJ\9B;f*a>{#/rѭ!xnin|a'`#[5r̼?],_j8 go;׾8O~c%߱.w[.D3C\|[@/zgs$F谀~bͅ,uFb՟w\7/{kN"/=H?w[_eTԃ./.x %Uq_ءӌY^<>Tkq]! >R:QRx[0*1 Sqt'ڼ:W.Ԅ O(9umtYK[p0:xbN]r IaUD$#ya [YP69;)Y;uV,ҍ` \~n8KetjjJkptGyȮh2_/9f^ܞ>uPa}?WjR p1lAj.MJ+]>+&-+.Usx_. 2~Uzg59l[:.݋q[e0TT?cGN0T)*1BvCkX uэ؞;!* 'g?z5p>E͉PϫGcd AKӻG*5v8y<'YiM`Od lz+Hf )^ƣ\/L8W+ rh*r${h樭{evSiTȺl f u"/B:!gx [s#O/fi"l>5[i(cSyD,n 3(։眩d.7nv<1p=q5ދ$u7,4+AK YUf˸UӒi]2}> ojG~v"j ͙i53ÝN7@KeEW8*߇d`bZr<51 w-T4'_HNiSK#Iy+ҝ:`LXn^naA@`_g]^JYj/ lm5{@n.)<-3!Vj6mLc{]:iX&LK TGݢmvo*ty4Z28*{a$JDZ$Ә~3)_.`wÚN#]V?OiE<&sWG}whȂ|mȗ p<{9$# Py C?324.874M8{{[˙Ɂ4PA 9xU u(ᢊsI'{fH',߫[tG~Z#4'UN(cQ >⃇f{hw,W\JaC\"GJElGgkaugѨQק!4PhY.Yy èxUտUhX{"%na`+7~D27[:k9yMroʒwCP*ؽ%qMnk#ٛRp;A HM: :e'>f^룝›F !?vA ޞh49a{[`4"&CK*-徯xXj5ۦNQUJkE) }i$chܤW{KcfP-O@hߕ2RE&!sR@ܱ냄"%Wu#xtr^|RMo2!;CZA u6nN܏3$w$븳_4{ɤk\ e9k~1JeKE~Eyef>nANeml6{Ķ0G.&3ylI FW2pA@Ou2Ao X]%#BzY`P\f_<ʑjqW;MNzV8W6K!1ǯ{v-~$̆ـ7}T23P' =DiSPsiBf%a3"$ ,* 6NM ύZu=U71hzxڸ%*Q~DM4(a5pdA>OCԦ lFd)!6akms;]GdAcX#XB'j\p05=FtM}ks>aBm%ycTA$lb8V$(ϏBeDW·D"RΟhʥkE驦 Py.y|]WPL9b/'ζr;Ahߪ99Ab{E;zqkcPNm xuRFTB^>=(yEt۞<6RoGzô`sIwbN ,XƬ(h:Z[: GNu)Igb9%>d_H9w$p:RGD4Yr>׮8c=횖 JcTY#`ӾCJkxF%Lm: oMg\_Y$YIߠ|5 Q[ k'Y~dTg5BlsxjQ#۬~ ƸbKo{E*^j 1_GQS77h4s^u_^. o6_ԧwd/xX1U;+H;h0m_;An30<( 15[3c pN/9 N;̕ 3%#^LLn~,PfJPo%&Yi07h1¡G93JJ PqH`kbCF ~dqHFDm:7 b:uFՎd R?A5iѿUqYsJ_r~B'Ĭ p /\pO4=7iqdח^ \hT|3!M>A;YZ): (oWvh8:G)p <59Q> 0 uWdF-JOy -$*r9CF,.U~as=bt]h HXϚ,! &,O֌>Xa#Ha89vkdi!N*B:-gۻwQi<,$k]}ʗզ*F:>M>cxNIҡhO,$KTYk%kNڝ<{. ?Deqz?FVJ+;2Ӹ${. ȗSD-}AuI9]б9jЉFaKbQI'ԠG Ru^0b~Tb1&ML"G}в+J<߃IUᑃ_0Ыϯn'E[9Vrв q 8NfIAٙF+o ;!E^,@koGAv(`q7HۜwϢ !wq}b&5"@.=ղ63]M@T ,n&HĠ=u S]pa~QG}n* &$ m:t==Yt{-z ڻUtx6 !KhU}N6u扵YTڱ_spϯTВ:m٥>XVДO,DA刱TYAELpە$wK$D: xy\rceq75xPOS-(ꝠHEftj ŭ(V-3Y(KHR8o)un8N']]W*9Rgݏ=꩓s5CㄑP\;Bws.4mzОNXYIxpc~rP5zz~aSǢU}^v~Kds_!%yTw4S`UKlTHKT.u!/LvmW%:\rgNQDrp`৭yz (.Cq]`ѡDѶd ?!Y xFiNS JU P+.FR?Q{+Ɓ@ҽ+ utҔ}-GR`eFreEz3'͊ţq }0nEXȵVU+@S bG4(Bݢ((A`3̓*kQ{˿EpCZTEf6z:P. ]PVwiCΒgFLrk74u( o0>M [|a{4uPBn|ϴ%Yl_{V]O@ |lݗ:b=I='",t#l<Tx#5ᆲis=TRٰfj"v`{:r4,7~iC.="ȜoDc ߻9UmtnaWV-VԐAyɞ0cҴ.;ZJqBWZw,n^!Yn~-5-px"#L)x9 K]۬iCr&K~`4#C&Hz-jp̟YY^|i0Wvkj3F=XDGբ.ˌҭCQݻ1Soc|֯;^Z3 jz|] IwH+KR9e*H->.{v=BI"I> @qY׸{`pIT I?fYE}\)L >g1'df'Q]0UZ|h>VH- Ӕl@E{$9~^mhWr)俐ToMvX*4'EZ+o:)t{VOx q1 RE9x:0 "^9,J*w [b3SY; +0$ bn4?de{0"Q.*`– p Ѿ5jsoǾ 0|x : *XQ[Q"[ںH V.zo["Em<ɥĝb v]o~vfD3f%YvK[9H h$~ޟaˑYy~|~w; Q$SP/_j |§fpk<)S/ep|)ȾZ;v’'72Yh մw$Z P&k"/"J͚n~=[ﳌYQ!ocTAE܅QZ{_F5`,uvenr=yRq u:in*?WBYL^JCI]&WqD<(iSc:%id|'>@YP$DP Hے50ۤ(Si5Q5$Vb ^y7G{נ{)'~o1lMYȻԂ`RR;D{`T4C(%bMhjsR> 3.e=7QZL=pض3h =q4-xOۡH%^2i/V$p7и )uvKmܢzKG]njSMa% 8D(@!񀊈IP,Μ~;x%F9 [QslC3u \D}{Ut\'4s%y;2/k~*vTtN=XMo` x ܺ]7.ĥu &Yl2Y3%8MA>`pRqgtMR[I߅arfVWMsg)jH;`;mV qU ؉4iTw[kP1pty3T}qGtByze*F Hݺu&&89"oQH+>O`[:dj&ze|̵͒ C/o˕?7lYF^<|m1|{lP @ј^nON6I O/vb+>Qaҹnk4ίKkq3mw_RY-&7?C7oM4jh< nszxcxFg UL{CcHNZ|QN?CysX^{R?Mr(.mYX$TO^%:Uw 4L|=Hzt`4O%8"dKԎ11 [څ"q@;ˬ,͖v$M}:EEQ %Ǔ*L_'ARLx(4]gpON~r'i-p#֣~'|J_TKOc.|}nG d8Q'FyM},}Ry/ˣY\+Ew£FG{ -$*sT=X.^%<^t:6qѬ doϷbShD.8抚gdQEWDNTI*I$T~8L'!eObxFH/w4NT {MA-dVWi1f9e%,U>x~k(@oQ'ar3Ukj/= [ۥiDvD`Ј8&{AfNUG<W/+Z9ku/ "Ĕ%Ėb8":Bʶwi}SLlի{'ڃ*y2)',̦,UqE;짂iz^jM1@ K= я.QBܫ@dU~e 6veTT=Odʝ TJ>jjpӰ6[E_en,緯= ĹGch[xw m!Qo(B!e(m,/l, Tp`>kr7q}}8ʦSj7Rc΀afe{4QT󈔤;װͬ}tD;"4[}@8YJ5p1 l]^/aىXwƶh҃9eA8\ūbe*Zh^W6&5Tu,#2s/rm`,~:naCUІ7-)P٬1/EbݤKˏ~ ^ŗEQahu 5} ؃Vu萆7AD bO 3&JW}:P$dhldQ} Qju@b0]F:\- ӿRe?*4F,>,#gQ,owK >j"2M=S_##.tECP7K8 Qj(u4`ܕg$G'e !u[D4_y0l`\)Wc$4٤m.<GtnXk󶡴',2Qh {ߖiBN'RT(̀D-Df:0ċ"IKgT6JfhZml1'V!;1J &{%L7/e=7BU$:taF!A J~rҀ~wi3f/4z*#anza`֜ga$}7]Uw؃_yOrV0-2|[+> _ہj ڀj68 IPּihk)`<Ob0,:3YR[ ,Cn?(Z@N֝\ф@^@&G=A6тȀ0 #O|p|D{PV%(>ՍI3J)k e̋'L=y,ɕe_x&\M#XJVIӫ@eimwV!?݈(t_1dI;B OqM5|[\} EʣbB#艃G0 fRئAjzfS,G@n]uKp M^ɚ d9<{3L('i TS/տoMC{.RUCoڴѻ Rg^@پ ++ѥ-OXl8&Wtc%~q$OL.dqkT}! N%o0e0=V]-'׎i.mOOw/۵ ϬGק7[R9~fRQ(uD;dk[cL#; o&/FwY ~+>.aJ"&9Y1+f_7ZRjws? FzTnuK(B,gejV0Sg^㶅]'%> 5}LH4us|gK, @r;w8X1I?a}Ki`P+Tр B*)x3.pWǷ# E}YƔN Ϝڄf5ɑLoFEٕ5A%) q>p<֠9Hhv3Wdb3J: sK.1mT ERgZ]zˣ̭/JNY+_CEBHSM$bbOS5L%q4%.5 VW#o[r86aMe\nTevk FD'4 pGQOÑQ0,7Î7)B]* xpN9ĥɅ2Q|z=ojۆ,1r|{$ 8yՑمn H2wN^vNeOO\SZ 9/4#\ ? 4 WY1}xV.5zkGE GLf&\e3qc9 ቲ6㸁s 8DhwpI[{et/5Y ?rx@9ZU7 Vۀh6d2}㠻>WFA:M-AԨ-k^&x"P au 'ŔJT'Ù(Ub^ap.o~*if}1FnZ؏j%~]wtc\\+͠a+5_<]߲8lT> 7% p8W-Esejl8=MPҫcɓp %w$ ϚJ[Qۉ^bGJ#OKΩyA9U`_Ȱ&O7Cexj {&\ 5zv@]‡68"+ي`/*Aσ; kKn>%[[^> Kp6pk~\w_)$e9Tס4{nݰGC=(uVW1y/#Ȉ",(uM{36dCbțl@&uީoLQZ+z!_Vkp\$ vo!jSsq(;3!Q;E534jiL@d2ܘQp Wu߄&$|6~%t7Y)a<(V&ˆoKd#>X8A`ZL˨Ψ,P&6-q쁄Vc~S\H`C:7zjzq ӏYJ98M ^VAH@sVo&:AHmf^2lf5YJ(݄UyFcW?@lcYfujsC%|[%gad'\>m 3>WnE7D-5㫩ΩIu(G'ůNeQD.KդG[Jheo&!}7F5F+Ox:.)W23TW6ƾUu;cNDZK7W q4ZQpȗeϓctC%n:eֿfct[Gb g{)yQ٬Cڣ`xdN%loO6b0{+ؓ]ogvql^s͡!=@OۃvBUP P+БzbJ8MVB/T_ipPh^:E{'j*l_(dFi§[0H3@;d['kIqF#9ҝk:|1RPTXAT?QABǺٲ ^w$hjtGj/$# jyCnNV}DrM mon>dX፲sq}|(J{ov^k[ ::cݢIXjuveP5.9pY^A2qbS`."G DZ'sc@G: %&7mg2q3zDvda ߸wᣕ1<UG2)e\a fK W% P.fnv*.pnY'8yX E+3>jDb:oG i3,B#= CʔڐfE@cId'rd-C2鰠Pf A8Tq]M k TMbIQ!U(.eѼ.[t:~ $?qKH1fV$RՑ*G0tυ,ȁxSN$YrG@"3AWkȹ%ezFzٖU.$PCd ;y߆Yݳh5Un*n[W~%EU"*8LMwmfnX] C7(i[41崣"I *'*6ThDv 7>!Lb{ZUm'SI~ZyR"0RV9(w{3SCfT/< xK39Q _.KM2b\ R+@,^B\*Tf@A'IɐMZa-Z*kE <;@*=a7r%d?Sg\~Ta./=Up4(g1}z~|7Q8={ev7q_z ݟ^x, dݙ;ἱ18|r'UQ_|^Uq`cvmd2<`4xk*ʨF`Ӎ*C;^ڣ>}q7NC4]KrQ ЩU "X"0]}_DJAxC;J!:A<Ӻt Gjaj{ /!m1_ Q]p?x+ 1? b3,ȫ۰ +3.G+NS_$#@R:J-E% $b0ż3QzEeVoh:(ޜ#L= ^mZi,1Rx!"7ꓚȍ}bi6jcv ?Jgv2)@Ba@K{3ϊzc6$#Zf &c9|KNž̀@p5nbF;Kt-OipFRRyt,GZb4VeXY;!p:>nnMDM ( U X >b~ɅdɼDʻ gUD}Zq0+cY4"2űaU^ZDӼnG}SoAdMo(/ gQC)IO։QzABo0Ph[[Y t7pMՏSqg=T w|㘮`*Yڭ ^ҋ=(l }qL_Tv埢ybF}*($;|QQnY0^091a?j掗,rRϮQ28>T`YL;]QN,iTv95MǢ)tEU$G`{fyo(5dDa{C.pxl 'b +o>6KQ,H=t ?і:KrrN[larNmG..<9hTd+gV߯5](ҟD-ahcH9 *Ky~Wht]DXOv}Pۗi?/N@z'W.OJG"_9tW*? [˂i=>[ \{+[{El }}1:>箈BGs옝B[Wg!*z~*\5A.f<zeTE \ē8A%cv/ W.et\nW?Ha ٿ'0k׻70FzLyWwLgKHR}x:}ouMn]+-:&O jiX E@/>Fձ^+-x\>3z\חX2_O鶏nKNVЛ3$ >}jBb;Ћl-4`6W^ ފW_kS>׳$3oֵ (qT?y 7G?;+T(k^,+A6ؤ h{s/$Zј3Rg_pXkI<9%4-TcsN)4G/|3Waힵ`!n#re YgXฌD>#9i|DW`2eZΓgӍ._k?^w˂;?5wn{ytf*O‰_:@<Ì'~J'5*Pw(EüS9lD QCP7Z^~cY2sT)O:O6$QjwUNûMY(b; TԎ#%d7W!]bߺYCz?Й)|5rCa0;+dW)MpwJvEߡiJgrX +ps@pecsdj81ҳ08Zޑ[v;F^u5ͺ]6 ie#7A]?4[wKQF A\攘I/z_LMBCWKl'ڤPbۇ@ZE$ Bf 0"ǡAttߒ?Xn}k=Ƕeڑbڰ |dB1C";sr3l~}V}fm`fWl/ .MqfZ>åÓ~~=枬j`@  Eʉ*ʹ/^,17ϐ,Ry#FYj v9h"dij&с܋Gq4*vJt>ϟv6E Bb3|v&ur WU]hpluDFs)הf!P2׺Zl_(~cQa dAe {}b ;fN ,yʹȟʮT3*X;ni2fmX x ![jD+-O8 TX*}E(7$=,r  ^~PA'K$G A7'~tGp&7/I/erdy (;B z~ - ȃΗK%}bD 6tQ À BU)M!p~s8l3/iMfi,YRס)HY#E *H>&>Ό!ormUk\h,]vtѸ-MK_e~wxZޞmeF3^rKP+5Y^[?? Cx²Yk2jzf$"(Mc8܀\L7^n/m`|OTcLKͣwCvV<$7][E,m G"-#X>7YO,> K-&!Q-BP)_kNEV9r=cp"נ܏nvTy}V8hpwl\=FĠFu 'H&̻dODD@}& ѿVs\/RQ*wECѤ#ze1;n!EWh~.J B"3j"h4)IJȦ sGcD;۬9D% 5:-Kt&p~Z6){FlPvѓ_2*ݝL_ޒWGIr߽cVǬ9{9T)a*a|)yoy'A 3mnH^njT}ҳ0%%`$/jnyD7&pOp$P&_?v-r{ qk2 SCꑒdVVu~0(u fڏ ƑFaom˙5M9--x?ZLibNW~aVۓW=׉ *]RTe?@^BS䵶q`Ad۝7֋9 !!M(DMOkD w#dpKZA^^f.INO(LLh T _tNqsN}]{/c&h-p0fq팵qMoc-J $x;H %apK%Z`}=4O&{ {xJ@U0S=]+"Lx|ETҡ <)Qv2x~x\r@9՟;Sa7Zޱl1CeBC9#7hF&Q ˹J3[:#naj) DkhןvϺYl.""K, ھ墥fI]CI nfK{YՊH 6:?U11ta)daZ4Yı OWy /~ee>1'%;fג,^i Y,Λ"蕿9G9:DXϖOL*εʫ˯J!->?uoM1נH- 8߽=8#w:I+ИY7EG(xy1ZeVYxnF1zET Q#1(bTp-#d55Dq|L@hZ8i~IF\nREwywC-hώ , ۲zi܏zoJOܪ<(J8:׬a$ hK ^ ]L:i}9b-3fbr3f-tobKBC5X7sC(x?h\'GDs; |:_ l30H'jmK;PB)ҽDg1턖<3' WZya멄_,/k[3 ؔW*' QS^EX1"ʯ5CC_Րgkj넮&9H]45`ՏňNqY0.69x$ hɺ I)eՐ}{wSDjG["V^-K[Uu1-;ff~ wT [}ͥTߋF@(fWfM)wo(a3gUtE+Beyg}Ylö)\  6j ~\g~d:]2/%݅D(?p? *" YMCcɩg|Z|KO&ki$S$< جH햀 %qPrDTNd+neDHLFZkɜ e =\צQD÷E!FVd<_+V 6ȰI1w7Ayh 0VpA :vTJNS7fUރIZuǓYZ#F:; ?W˪7䷗O;N[0 ``ugt ׍Պh%.YM.C!p*.G^ #; V_Һɺ;foJɥ AVO dO9ǵ~@>d#7FL%w `TeQ{z 3El~fU`+V#~`Gj mO_ǶyVѕI?w=({D5Cj CU*^C_ۯ8ژ9 gB"/ZI*6Eʙ> c LͦLsa.׭C [Lb7x b/Ւ#3JkSzDMU qe/,lg qXjpӣxN2zvuvUU"8^>э/bB|KM/I qDGl|[(?QW/A,o S2i$2>_MwlAX~] "Dۊ -ܗ JLW+e(0Tڟn&8toݳO@q~sDzn=9"HH7!p +sWzA 9P81ՈR2?:F r& Z/?UwZ  [&RmG>#,Ǟʭn |O뙄`Q+I;qaG\|)pYt$NwV @Nȏ &D"۟%T^@f J%wΤU@ ;P8'Too75K~u?mgh,+)'u_=iݟgV3@*/AԵ hf #plb#5AxrMk;Q6n '0K^n!sL`}&!, {l>WMu&C>,NWxLr3f@)wȼg8V&2 #ŕԕ۪66Zw2 pO.8nXԸafo8s75?44œ$:A=@TyrLh;'`R{>lWpe9EF]J-|r|R'BnXVgfEt__cY6'|d7@r{u}~(q.OiRpܘ.WWrU-il-ׁ4 3?{|a])Hv+XVDe+\_X`5OB7[bLӻ*"˳-Dq3a:RyZp՜ Pcau֯' o{55lw 2^6[;/0BQgA'6ʞ7Pae(nNvk;z߯<;ݑ9iD"LQ;/bܳͶ7MkeǘXw᯵҇)eۃoږEyTҜӝ=Zv8㏡nhM1J0C'h▟up?PFy}jzP[3t&CQ?IQ*s'|SEHJ_? ?{uY]1}ɵ#ꉃ؄kV.iXW}x]A| wg_kia(G֧62#x[&;1`PwpdÀ d,*S}.i0e 13.lu:DX)󌚻6-1Wb_չ"xJ 6~d H=b9%wl^Uu&FAh̔gf(8?RV??Kd}ఛ%ra'$}gM<UlPj*$DdSZtxIz *$bYtv&zD3'ihONPOG͹;0l ;%gy- ouGC7BcwaȑDg3d Ԥ/Z%D8;T%+qZy^.׵ SJ KMU,5BZ|IG)!lg ͉d`kw-ڦU胶 كce9(p\7deIS!v E|$Eف- VZ[DZ- sq<=_|G$sT ƌ͑jHw!GYxg%7]UIYes˟]c\a v&hWB4M[u2miUwdZ Я:hxXM* R]PT $pUnC^@Ue, OzD}rK)+ą0׏ckIqnYK_]#蛇%ķ D3èg>+qvq WfmBD:y<` 3"o]wCޅkAlƝ:#}f/EKyitŝmנCN~Ͼ Q˻7D`)&VO,G?Eï`̄!=wc, W\R8#3|j߂ 0m:~?nߊ+>2tn]2 ?ɭq^F H  %=%T8]VY;^1얗½_5E:` W[,{G}( 0H+6ȬJ(Sߠ,&J"쌤c;VNėe#|o5v?uӒ(eqq->!SdHME1T6R0224 D  #̫N?Q3uY/Iř uD8OΊoߨ)и_jݨkJF`U9R ?2q鱟6ڧeQiUz]=[Bsy  \ >&ܐţdCz{ xcf7cծ){k:]GhхLM>3!ry#O9V싁̌}$+[AGX7"䁦+O[ߥբHEJ5 &=U,csA@ s~/_߸&8DEO;Z鴐`ǁioJޟp%pؾ:[ATp QhFuw{Sbl%WCsa_46YCN;GftLOi-vD՘fkjwtLß`/6TBkfHrYԙ`ZKZGC f?a,hb|(FN]-b ы2YةgĜ;j3e'g&̈4nb 1Y^o ݡ+eGkN}QEn}'eHϷ]3<ɑO@`>yl*zvʐnX3$Ofz)7m88  [)K@Z(ʑgp.5p|+/X=FKֿˏ鋬zNYN7aYs}Nza~m'O xR}90M.2[SOZS~wSlFwaƨ0./8X)43 q;l& v_ϲ_7| 9\Ws5YЦ.Ÿ^}}(?]<`\gg[18 NQwѧlT~jgTu+aBHV?uWYX l5WT^ i#?peajE6B]gH Lc\kPx۪Fw&^[ݸҏ [ύ7;tc>EsN]+-S7 wvsb"ʸ*%Г z^E`Bn9t'+/K+ NڶKWrZӲXQ8ĵ)NݥOX'wL5WND:%2&l*AO.N:e{ɹ=4Ql44iS䀨;F +|Sq[ .zq 05%JJ+$.U52z-1P ,Ee% -\ d2Q燏j7vqZ/KVHEJRIJUFcX7qCjIZ@?PP ';E9RKf!_ajD.ڂy Mݫ}?9:4!UNU.GS'ܑqA ܎Dgͻ*AF]1s^Pc?W)Q'?d }bf؜2qJ9>^.Z, =*6ڙ lۑ(꠿OWvfp;kHWX7'Gь]•RB=#W!a^qJ5!j9=40Ppi4S0{êDyQY13G<@tP *4pخ%':x\d<;_PeǬL_ LJO^#?DbB-Lz,{}{E9qg!h)veWgn-VTqL95 \ͭ > ]Pjfj͖rHD NUhl=p -$ " t}F_m55ߛ7~Ȯ um aدVR/~RI8ߟ$UyO.%{c6{i8f7 =R?ĝ63s ; 4dAh7_~CFN;6Igk#KG1X t8{$ >̳K2UR?ŒK߄P1|2,]>`)~4Gkw DQ=Qt W깢Snp \h@)cdjĐc%y{CW3?dӢIV>rn iJ<'!bɸ(^i. kƾ~\ N9=P 6x72ӛVb)\ !ñ3S!he(r*(c:!s¶6uc#Zrw܈Z):98ITŇ|2 8Zv7 @0dKSoJ-C ,V}ByբBkL`舻sft#5N)2{}Q7خY`bqzŒ֤crġgWj4q±~ɇ:6|Q./$X%pf#DD\Lj8E"m7;q$JCXz;{3#Z5u^xLx8`v=j[ ]G%D0",M0öt$@)oܠC\6{2C5{ᆸՃs8K7$@ o!3IN$")cPzy;^Dܺ67% L=EW`9qDa-GS\ \=NMYu۩UwɻEi]C.0ߡɠZ;'P<2FT_F*}픗q|kH%aT"Qu79x%y]d@#?njZh೜ oC/qE\CІrʌf_p.Qz$+8w)h%^:CX m--8k_F.pca{  f" 60A6n=38.jyG[ 'BqɨJ梯D ʺH(2B[/Gr =ʸ-'Ѐk&sLAwcM1R.p÷ գziHUr[<^2!vI{I1wW Pմ+yRIaepz{2B3ZnS6-4X5Dߓt 7}sLzw{[v'S9vAf&|bH^''>CVFҠxҢkڠJ0%<%&gK <XNb@>RhkN'~s$ ʜl6%do[4B:Ws!.=D@Y@LJ1(־yW1z$o~],,F$Q鰰٪X?j}fvb]]UP>z,]~x@j}"em Y_yG5 ܟ\}N%Aj-Z)y)Ŷ.4t9}~p' Fp;F27N|Ub$[AӾ!dVA:eCz/kNɔ)cS¹ݭ*ÍGҖx#h˸{StN-i٣Cc褫p^<.Ħl WvW-^[NBr = ;Ӫx%(B})P!d@{g"8,(m\.qmgIg՞a%fKgo&|[xII Q 1<N5h; {Y?ZM1᱄V};;H 1D=4#fs֚HX.>fˉ s29|.9l>;>ΏA/Z*-n# !HYjv@kpMGZ+tbG er>ȑl(C*܏KjV$C2,{@Z?͒sa 쇒R@KcΨݖ1_'1RƫGiiw5)}ڱ-iv~r7ӕUQiE2K1cuWu'//s#=`R|gUq̤va|glV++ުe(Sh.4i\h{! bZ+ U h D5#ƃ"Pb(C>Bus2}*[y?o d u/G9[Z8.zT$i8WSebr OZ ƎiAck:CV7O 5|&`slZZsKl&+ϩ: /%)AmVSCA9CN{.vQH z +1Äp3 dE11m#NDӁ9~g{KNNm)vۓyz fmP BO{r8Ɨ@t)w>7[~>kGbJP,^]jU܅iE-!g{lrGskVtlixUuR)>^:#ܺ)yuWi B+A/؎xo^nPZݾ_̒7cw Gk` K0($Z#C*$HeÎ 4{(\*IIQx%_wtt+-lz+݅k讪*h `SE. 1O̥^pySYWDu~r4ŊUNE]JWF0e%BҬhWjTmnt^"ʱ.srpl W;ܕ#~5@3Ԍą&ֳ߂u?ԱCM1iiZ+iUO&Köed{oA~t%{>i$ Lhvv1]G(ʰm HhQ7֙T;l&2H&K:AbMk<%.d+j Q7Ӛ%8>^ozڝ8'Dx?hA #9 \JD{T3mi&n~wA^9Iv\JAwqMU~~` z;rFm[\ѾXɦWIWe fv3PrtpKСt`k&=\(SடEacepơ_S?,9CJON3P\&E[jomtj.gC8dς+Aw3b2CqLe4CqYR6 #JhVS0߫lE ;$`}U?oZJs?M7ke$ô/U #1" o&~|;@1PZW~GLNJ=譎*}:3owrzZ1awM.wb5:.8QeVrX :r5h8 `qG<ػ#y]Kʕ.ydgie#QIb&.DQH|k{0m\0 (c q !xwnFDcHiV5c8i+XhfdnC~gPe}^G4*MߐRUii] kW؉P@"JS @n'\ K-f: rkqV$BiGOM+u=[H.Wc-78b/h$[3Axbj)ʆߗ?p۷jX;75 'po*j<cjn7Q roM680sFV@F*"Ptv a"*t\@0 ŠP܊\E)umXӉ+:mdʣW,CFsl|\Sl_6^ڶ>Dnf.igeϯMs(DEB7 zɣ(ksB?$ B|ڍ)%Ԃ&q(<C;B^"tsqI1 .~lbc^=q|CjO0ɽ2H[T5斩 L~G@#65oeQ^"QBEzׅ{Wz"{ T[v!Zi}C'iohBr` fD;{]}T ℌߓ}0m"RV" !0((n/`S'wA}ڢ?/0 F5CqmB"IOb=.W׃)x;:w_s5ɉߛ.h0ԴUp |+N]GV tVqOQ B#fǚn,N+~`Wau(AeۥǿJl; )'ļ^OgB=cG;նFx~!C Aȇ/s>O_RB7~q\(SIW,"_toa¤Wl?JE\G<}Ŏx:ǰՅƼ6AkBAl~4eK*DE%/TV4V^햴9X̻i&i_7Փփt1~[a[&!Til7ltJюl֣!B0  t16LuK@bE;e/1.Sj/F^2huXiN)`TgnCsg UHؕ1y|)jpd5!`: yW\[L5`W<:'fغ%5f!\ GnBūes zM`2vR,+) s cJcpNy4UeP{Y-/\b փC4'~#;\p &f BPϺ-LRMPs$cųS`p@_5SP%|@R͕B  4sE[-O>JjGM^oGOgAr)0JۻHj11P2=9 f۶Rq J𖊓W_N`Ґ_;L-xJaM!wgȇũlUĪOM^F\ߎSDI3MXā#v Dg#!Ay|Ynhd6zXޔ!văNwӲt2MmȏBOƔ=/6eAla ɰI@mQVs^u~hdi‹w6߶@ށ7ﶼY_ (;<r~JnZ2(j=Qfڪ'>5-Y#1 fPӼ>Qش/G (5Qb ֪K4S033O )ƾf/ mky/b(1 n-n2StM0<<47^8A:X8m&:Y9qu ku2PɅ98]:/C`m, %js/|g+ݞ6jP[Tj:@ a2wari=n~ر'sC+K$/s$Y4ClEntTHy))gN/RSIw?0$D\P>R}X3LAۊ *Z-E5"D#JKaBJӥbΗA !6{@xw$-#Xo%1-BW nț" S \$1,]MI/χ<2,H`Fjzf !%dZ=_ؖeBK6 A~)/?4j;LM^5~@&\Lq>3)|mu{}CV%e#?˘w MxIxYr N҃?2P~);?= TtokYCY}x\2*6Vy Pa̔-b`\o $Lگ(jS'Yx:G4\v̼͌-m5r%;* 9'[h0=6:8\hz)sHδ,fcG#&ؾ9 lFO5W₤bo^-V'p|qO(yDC~>AE+Yg!Ihq+!,^|/w8&5g4?>kax_ϖ=`b soIQ0-Iof\9R0OٶphHNmXoE'i^5ң+ q5+TfljrmSl6K!l X""1:Q!}ի9. ۃ3ڪbj9nl^ӧ?Wk; \/G Ui@yrWg4fڷJrf`񧖼ͻUJnz>AVt~ˆ6\$b X8pS  F<H0=t~G$$,0ul3ɖQݜoDmoRyWs@ѧJ&C?SȏΣmL.WaU%lI{=ޠE*.)h G@|@/)|O7+zhkJr쾆:HaeLC i!G4 ΍Hw|(`1[O Eub$8hCんm*1q^"\]2eP4 G,7rlJdF Tqƨ]$&LXSq3i)o$Q-oMՂz]Q2wHk8WEOvO'owDŽ`hsS9BNet}X/jӉ>g1K[i*ʲьf/hqQ  uE{q|jFIU5 iǀrO+IFB4:V#g} 2;K: Zu'?N}ƐKۻM=PO7w)R%om>L(]f#ns_sut.p'EK?,OivPZ$N)@Lg)=H?)'P ~ fȼ|eM"99qWϕ i C=0pL|3>B iXaL#tDLus,¨>cEQ줡4&.Y>JH‹?AWC4 C].u(Qjr HD+r8ҫ0et#3$TXa;E,,v {p,,y3AvՉp:&\DHDι6Zn6Bp [Pՙ4;" VAs#f:sSlibRݗ=l9:[bnjZc. ,Txc4ZZGIԑ x[FwqIXZ*!׽Hv!ⷩ "۠RgKd6wSi0?4Y=)oѪ9w Ko_g@rӚWc͋PLzIC;Y}۷9í\lh+Cq4͌0oz>}BetR{NFWDНp w-UUz셱zC][F"ŀyExyY=/UeSl&ϮwQݔ\}c1%ŧuF»Aqv]]ſpR+vQ =hQR "c2} d⧷ ͧV,3שO?S+MU3 _QRC]ӹ9nZlAH  “C@ƞz;fƒ^O/ISjrՂiJ1lc΍n@AaMho HaI:ȵ<%+.űUlӑKD=O)DqQIhяYS] bhJٙ[S)n'K֓];Vq@Xj*(Huihk 9l?R'%?,u$tܟ;U!AƍL)aB7_0ruqrNxAOv XZBgu n]b߲sii9;ԇz)y@xݗQߋR *ոL ,t'nZѝYx=zOz0߫tadLRU8tsCdy=L4Es"Y`xُ8o#}ddy̦1*)Ȍ晒/&;7k1tpԛr?! 9?WMS57 PR{ᠰoQ"YKI$2cQ}t L*1YW+ʂCQGjP ycDw*.&H:R (tcKM(ǽ5ge#fs#D1SU&84wTh%ÀI"5VwhKH;-MaʄdųlXJ$6i6#'& [\8H1[Iy$r=ϵ(mR4G\-Exܵq|I:Ȟ=8Ih@Τx2i+|Qcrr-ݕwyFlzy!8'^@3]a{ a'kQ{oL9'+Hj?&#v3AKIg7HAAk^ArVSw(2GeV.׺=S^*.$j̙k,BmY^ tR?{W+w~Cl肃*v_/iƟ(`*fN]524ϺAG`#>XdM^':w$4AFnРKɼ<oppeBk+ci&1:b8n킬/6!sc߿$>zH{etF20w2xu ۅwEHQk*d|:\SoF&55R Ҋ!FlyO9^Lwl VnML fuhqvM zǞPOjFͰ*o S0)6hI/( )]e-Txa<'7ő $lFn#1>&YhuQBm-cR-h-WGN~=KcpҖƔ??C5~xlrG{& !:C8u_c;V~D\e?WB\/jjff{W΀= t @~C]:BJio<.wt*uy5ި] RC3ޙPߏB!} tuҰF7ҌAO5JQ$A?D[;wodXymUG1a~q1v)%N U_P`Ȍr6.ZZWZ"ۯ萭N2 *,v pIih،wL&t-9ӀToRVFdḹh W´_rѢ<$03n!7Ԏ0*E|:XEH6y tD]Ukm ^## Py'U9qO'6* Y s,ďB$ino)-֌}OwXl82La!GZhKM̷8ge૦IsW*eXDS9Jآ-$i#E lruD9qav3Cm:BΦ'iwnպQV[Gx&88$%wfN5;(sB~+Bǃ)C@˳;͏>k,[$t-^X!NB38NO\јS`O;f{m(;OoObh绗CQk?ڂβ\+~G'\L!+-ɯ\SТeEN7h&ﯾ6*tFo 3Q#8UDvj3U Sjt49+ Ɵq.9[LC;0vTS"?Ɏb=eu^EJpKBJ o)wf{%)h2^Lܜ˟kge>Q[(c (gB*T{XJd$-ko.YEkXylDF7 Ԕ|TiF].^Tz9##GQVkGzbzq!Hl&;ܖ @|&f $Pjk aQ2rx9TߏL@[,)(#Bo/:C:=ɍiyª)O3@KA'.vL"gMܷ,S䟽d$yNR]"`pLKUdq t% [PeLc,|o#StÖ^!D/AF|W*%(jcɶ;"%'BcpP+L5 l7aS#̪ozع2Qe„a.r(`f1d !'w;qŇh\Kb_DMVH{}r݊yvFD'qGGv`w6q-*UtIriR ŏ6++eQdқ8?8"`y_zj1/UE,a3dܭ48<(p^~-NV aÉqH/pDžۑ ppABzo <-\*V͌,(6+jEqp=&c,wd£gnK0+A=o`Ŧ>@et:>kxv#s.[u g=W:j"evioJA̵`Y]kXbp#Ӻ6@+4n/y5 ռ _?_OnqZ1U$ ~Z/icS[es+jCs>K=kدO?2@3 G`F z\&AgoTh.t6Ůy?ctH / 4Aj D8\ߣw'dm}Ck=Q:{0kkj=&?/4-\^5GA gHm']}rAte]0]ic/͇X j(BWPBn.6Ӗi]@+υԚ6(Oe^N$'Zg wk?[GpW O @$`ԠRsj$K(-&3za\7xXNw`Xk S0o'(NSeL%U9nf9&Z(PJ`L.ME%a>Fϓ˺A`ܞ;yg0?R |rʈ-trdVe8M+rdr6>+_㥛YP lj'X7Qk2 Bx=񍸾F;\V}[zfOqjCAe?44$|O30ni|#5^)NxZ`X-qsfSip\psK9=jYܿWmm&2 \Hz?+L^)MƸA뼇bfW"3e=$}jZXәhmV cZ E=SmI)6=% 7>T9\(3MFXMtx^nJa <ײ~ ĈJ'NU=RUgZAD s\diq*>JrNNwNU%nJ ]Y m 0q%1[8]z fF3^)vb 3(^I]bUt*u-Qjfz4F; IyAط7Kտ5둬Lĵy6j/ͼh^mנǃ5Q\Hp1KK3Ft]OlP`0/&ߡA{![a+ZA\ L82K_2¿nh b 2f`VFG҅_1fQß`":=sڣ%?>Hl8doQ0wr^+=C/ܷFA!rV}!9z]u`Ǭs%)=J )EiB=amWhF:9,K2kiKozp1/*#Eq@i=$*|מH`\j7PJ؃\Z>lB&%0yM@hhBlr?H`nPҒxBTYK^*vP^bq҄[lE!᣷ΔyE!M&" D?偖 B[͡ʔHoy%,Fp[`m c/W[v$pBy~~FTתx׈J _،|.?Ȍn;ɮm0 jqڳb n~\.!_3olrwoAƣwZ1y0IN'O(+b sHыElxPrg[0WwHMi$I1ZJ-/vmNg{͉w(E˩0q ~|9^MFBW3A;{xt# d$K.Ǜ8es>]J7Q-c_hǎ>p#Xk0faA*H !p⚯8v~OU ʼ.ay< ٝxP[]?{0vCR:-r/@ Wj˨~hpWd*2r[,\eK\U+鷈,d w'FM~rQ{3,Lřڗb!т'ݯG>k2*^l+ Y*`Ih8O;`x(9ܹQ/}׷ ^u܃"/unS:}a^>EOPc 6qP &b_ ix8o{QBxDP#+gIPvRNH2s8;/iZT * …zN/$[d[dW5 i ǥ_ | yƶr*7W <) T\5߿)h S\D44Kd|>fUb/N=EƲOB#hiQ4"CŚdߎ; H5>%L+›iW7Ƃ۫eAcjV`J'(ԗ#CC".XGA"0޲&Pbd<ү 1rv9:qiM*R¦Req:o +]za2 ,uw< 恕).vHZ+.yĸ!Ev)?;2;vw-f46}4IOM|N4`┾lwߥpD/nC}9a!-er_Fk)~/4 jbbGm!aAotn_cy cn__}"ߕ1&6]'IWZR"N $3{o3{?iɣ]N l-74~;{`Ը>!Ϩl|6Tu妔^PgB&=;'tE0 ]`eEB&X%mUb0:7RC$7kex$HxN4%Sb ٰ0!}w[@V4喷cP[Wvv.C~UM SBcB+m-,vB%iL/t8v%>zXq7$iϐ+{CHq뀸Q"雩.:\fQ;-7>CE2$쿒t aE਴4[?=ɕ>AsPJRkF SL%_4\Y)$P8M\?9(;v?ΚoJpݪf#ĪHՙ X&DYTfhŤYgfi\ feޙe[?77۬ $7rh D`݅_6Ùk[۱Ȟ84-&mg$.sncG4=r!zn}p++ 9Iy+(vʋp)T̶A*w%X/ $&zvɠp;Šl%۾"<iũl,4T)#ݒuf;kȨ@Ϗ) +rƮn}Ň\x_)Q~t+h"Hh 邵} Z"=+ˀp7ndSǛbj)|y1R/w`u}י)Bmיq*_\J'O֧Wx3IOalX!/mE fh?Y,(g8H45}o싦rare4ęFX,B$:{ˢ$4ZK4fx8!Xd~rߜO 0 ԉ.,>[/eކ2b0ɪܵYq#^ m%Kpk;z 5͐("ED҃YB^確*F%ʶ%l*yrW.0LU=t6!d(iR1cbGR} cgĘP),$0G ebU,Z ۩IW;hЕkjᑋԡUj^QӈqJ'9jF.(KdB\_3 Fpi?Hy#pXC+拵L20BОq$}Js7'|jxʮdz  wt [׋z- LK"פ9hAعTz rN)X}6QRkm4̰ޗL?TT/`aY~Y_{|r&>@NE' M} ă|eӧ0Zg+%:H%!i9 ~'Rbv3$3B&-6nޏ۹f4)ylҚaTW?8)0 3ꚍ3CZ"UyO"gh>+|ѱszm G ,{쉷7E deyZQ7\8fZ,r7p9dMDȘVA $E- !Wdmju1;ʜY=Ծkc8^Xn:sXhk^!Q4u!گQƁ^){ɣgYp`ZXvQUWMgMe\NolJ|t_wg~J›I`C",shLW;4f,$͎p-ZA+:Z Mlat]x+6Z\l}*H4Yq0A:QA,@S=9HT ̜ުhndޮiՕ8` W:30@9閛U[g ? 4#;`'/Ii;Y ۢSrw5[1@(FHT b <}!={ίrwg*x=UnЊX F1{ja0F>[,T&^2M!v$8n_/Q3j&j33zUJKCQ+w9xұSe̶+9zSmsԶP:iBAH' /NevV\_3iqnI; ёA=[<2|`%b%*'p7YdŦ@!HqW0.Zm3Tee]:"bx+Xm Ï.6xz v@~EA"t1ҝ )XdyZ`,RAdpE-e50`d*YǓKBP.HjYjkJ;MAB֊\F^CW}A-}$Hǫ:G.Dd姀J݌6昅QTdٟϫ]K i;ojoo~/Q}9jgN3!81pI?)l)+5DTT,:E.CNٰNM}R>6:E4Qw:րI|\ˁ☮lh獰]~ьbHwjUNX[̱焉u X̢ButKvfG/1l)r7Ulqc!q6!^ӄ*f-Iμa5B}g"koij~WmX6ʓAu3MV᫖X:5 L/l>yT>iap\B@|m=_.@;G;×O 6OTˡh6b+e<,Ph]'Y[>-RDw벰:*zpc?Jz`2#m A RC<*W b\*k6 >CDHR PNY @i&t$KNm]' :'-5r6io؆\`\U_v8Ev\H"3$ 8/ %|>m 5d;&lq)Q}_mEZ+h#u'abl+ P]U$Dx"cEW/1V\TwqkuVqRo) qٽ Al~2h)93/Z @+* %wLPd+/n|+}tF} rCd-LAj!H4PIrˢXvbV|^e,:b~ݰ$Sz@q#Q3ȤPCVe#w"pڨ쯔ܟȐ71:$++a=Ƙ+FfV@rH3 )zYc!-Gj,m,ǷIqa-`<1:$F7=w߁@^q){տ,y۪;Ic7{n%~HT`KN[%`t-Ԫpxхu|ON` ܷ/m *CԴxj X I¢S)lڗ]ǟZ+zUm,7 BJ+ avM sI^d\lj}6\."YW}# m+*;YjɣCKsu&F3MfZv o7)tY&4:@BGSn =^6$a/ 66pH iLߓW/XR'J]bL/}Rml7 \@RD[gJ.6Zrh: w=jʙofa4"7jը$zLY>Q/"čŤYȸRuZoto#恊 ĭqF0sB&49brX-;1)H6{k/ˠqkՀ؊EV;' ^!>ɖ(Z`"QLRPOV+FXFC 1`лd7x$z8ew/ܞ_^0Ӫ[I~Etaf\5(Gڡ!`6˭CJBJ)3pY&&|sdG61Mnt@z5ƫU'OR%gkffM(vBsj'G@ÊcgW1'uٙNnPݙ;Rc6DV31KateYu7uWD͊kL#ڣߎ1Ήni˜0 ^*\QA_KJFt'i'+Ed%?8ϯ$#Y޼0ػX+x;~[k;=̀{_*mtՆ6r0'PGBI09:|UirL+]+ ;!'kD*$]wEHKҎx 1&C3]-.Dm'+ctC0|qxNɤ .}Xv]CGr|Gߟ4r6å;lz.|`y׮O1<e;iboc{d`{JϘb{Vfkpk,V[7{w&K#;r}oP8iVNg#*$um ٝJ."wzn:KS@-:hcL8.K?bHĵfZVs귀l2Y|@VagŠ5E3K3,Έ.oEƀfҋ~⋰E ݜu$+q֘{a=nGXPԯJA`OM kA:mD0VV&C1=麳ْhHGx)!0ye˘^9Wfb/|/^4H}qvXnpb-nJp2+v(Z ́iy@^>&N( '=Ma>qkuhƇ$RPߟ؟$@|kJ,ڪLIV|n;V$$! }*i7&5餆fBGTRAi9Ȋϼ0_Wnm9!@ c t- K7d63 82+ Q.Ј!Xg<9qFɚ*#ݭ2AeB0[m]W:8PKEڛ+n\bSFP{sSg]$’O(_:hvך*.谪3$xNJch@inlK+WǶ4 Pww m]*'bxA%T'`yGc,'1"tE$3J2a]LF13i1Z.OQg=qzUC].4 A í4z*y+p*p"b/ OB=վ-ƣTP| I>9Ly~Ŏx*p0͜`YGƃٸ{^Q~xg3-HŦcI4f"Ro7͟Uo3jgi} |Sͭ /o1yc իM11 RZ2cEAzN෰BN5$DR!R^ Jf]0t/FCerv>D%ppk&[. (0;+l/I;Hmk-$_5;ZI<9g}P "2`3-Wo˅ǁ\CzϞ>T oop Pxڄ{SYg5A7LV58RӕC'*}1b(Aq۝!b5JSD]htHehԽys=oؓ`m b, rVwzܦg sdIJ>\7D,񗓤v.)޺RjYB-`&PRQBH7E٧3@uF#_tͫ>iFJLfǙPو9 }_ڞ3,IG#@;v\0*ϾK )OupP\1<[HqjXT $WP@^vSڙ3;(+'$ $򍩪2 Ta`} O&zViEk`;mm#uñ7qZ:GPGg ڭAl[!&sjDsPXOB$%g{<&ʭִ8oulxk &Bͳ#tYi"H ٺЛTAQKP "[35Fq,):4Rd>75$lnl>0}꠱!5'WTܘs٢ȕHְ19M\sb"VXNY=Ca(_H[li~{~P8mFt e΢"j:ՃM=PֽZLEEoZC 4m؀,T kʥ{Od.J[ O4&o9GO:tWGj0ZVБVVeݐŰZLIc@̎VnQ /B$GMjIz!>Y-57HJ(oMnh8kS;yFH& *Xי'{j8ݴӘmj ˍGmqC&U0%:A#+ ܣmP.Dw:bÕhuZlCDZO;F01+t.ҔTkؤwԝ ^;_} +'`,kښ33zDQht{3I\E[<_c 㤦a/݋ "Ҁ^y8;Q`!,3GN6c.JbAiW។"}/@hg5s3e)$X8u(_מ{<7-[BFҌhUF{+.{V?ނ'&`z&J<8jlV:UJK;K(譄k=°md0p uòL4~ /:҈!]-\40ra_ê~z[InQS"w `D;c1San{Q[Ǣ̹ؓy-ڔx*>O\HUpHD)cp89H˘qvȤrb/)|uF\> qL/~lToȐD( B)yu$K }"`Keތgٸ %Kx<WT1h| &u+EjuLF}V99>Gu;%g-%$9*d8 In @Dg鮺C!3ڿz*ݹ]>ETxR2Jl#b6*?8W=(;9NG}hJ$m4-lx~^qsŚ+Yܑ#@+C`캠J d)ڴF6`Ղu "v>ka}l?ɩ8{`SXE￯Sի\8 )97saG2e~=VصqNOUs^!E>n6sx2PMA9O5)#4DH:" /űK䩧U!{NS /3m-6=@. ;8I]z%)ӚJ2s?'.myZ#;/V0(dJE:ˍr\'. Vۨ{b:S{jW 1 r8 'XapiӚx٭Y Rx8)8Kv D!):埞iLA;K}u%Q^9a4X6jty Њ֯lSR([,F>{V1.[,˱s `s] jl?L&R+OsՅá?gJ8*ZRC]dTF%IMCHpY,|ǔC?-~S6&f=Y/ Q⛰|\DO޳@#C ǨO4SOD)'nS9x*=Q҄Ra0Zq.i@ DJ\00Cޡ/ŢtC ծ[3`5(0t S ɍ2bP*jȦGdKCKš)?wo4P$L7 %t_01jJ9eFm4 68\d4!# +i ;ܼP LMhYkB^V`I#PGP~+ pWemljE>vEEUD[$a-DةKy}jVI}oFPJzۦę1їJ= [Ջt+\H:+Ndc W/ ,5MW95;4z̤## seMޑCuL 0Gd =uj!|a'1m{MmKIH(os:#." ~&ca~Ii~CU2HPkQ-AI'^ "Խaը  Zvtdn\I? eٻWـh$u|:볜erV2գ!iytQTUU.韉^qEnL>LLEV5S/87Xo7}MRPGMN!<֤UYZi"4/ :ym3DieL*ul XgqL, Hˀ`YM#'?Fۉ!9TlBy8r Bp*k)e>whyKϤr-+ۊ 4K赖y`nS,Mw۩!O:I<֫-@o8WT^4攺] ^j {)2;c^䟭vXgQ@N8-E5p/4J- l8r)Rj.!Ėm|-X 8dcJ ӈpbI-JsJĸa>s !DQdD4u0(~;D,ӰtX@ϫ ,:ARF,eQG]q.~uPG?eZ_F]eIRr AVj7 ü gjg/!y('ð.ʠ*HzwcسP­a\ޗh$ʕ yI>݆ '̏[I.+/U=WpYqOɸzK]FpeJ69?m=AGP_PɼWHs9g(1̝̲,! (I _B,9B~uETO3cII':٬E'm8EnUei(Ϭlܼt8EO׹}ްy5yƮ<Eˊ ܢgym#FML9@nN)*i0Am!2d-rU3R$w=l鴊2:*v$aF=rsdL>)p@s*ww>R meGk WWL}) :el`zj'm޶U3Q1o;xfT{~/0}:j ͞)8HM9{o|FBdZ!zi. q:_&mz>7;ϻϟ4To\;(E14:ypo XƛCȽʄJٹB L^gWYjj~q?leqHSYb lsQyj*[#WI ADEu}|,\V-ME8f93IetMPP}KdH OiZ(9jRGEN^Mu@l8l"Z\;[OEqh J~0Ȟy0, @*Z$>9)JԜ#ӢwP Ai#MlY|!Q pu%xU׻kWo SaGU]P֋K Š`F{Lƫ vJN!*gZY~|I s%s.Z>_rme=dހF \9av5ըA ./d_v׷d.bPZZ1"Kv>NˤNhxLQN>@0u* M't"&1`Vq( _WX) ƕZ(~`*߲7=瘾оX=3CsP.-<{& $#yMݲ hQno1dnmW3׼rJ>Gk5pOY[cY?V'D#KqyH/gdEŹ{[+ aU^gj:Oۑ GKuFs;T)@BzG5rhLW h >۶-CC{̧4tN6``/1%ݑ__X p{+c*Ӆ ;,yG.51Kz9 !E*l4GM QX7'e^L+Xn]wi;tpn@]]q}`U] 58˞dž%8AU+RYb= kʴFNRפ37JYc#qDgDC M r[՚)fxt GZ /`')W/J픖C?DKBSq}$;Z(HGވ7&$.,c}E㳎8?iO%^kw$) @ Y&)3J_G|ﰚ1e=<;n~l)LwiX̑I.+>K"EH(:c"l||M%ŗgQwƅF/Y=Vք'ל70lR:yf>%R磼~%uQ@s?Z2 gm7TBHռ zQq$[ie f|>d֨$z9z EЇoxs!DRDKă~ÒD:|><>*Kݟ2rd `ax(@a u%~^Y/=_uG85aִٓjR"Ms=s92D^T>uk<=̭qŠyl[?+efYijVGhuD3wd7#w2M:Z8WtL$\H]*"Q:bӂSCD*=)fk0v,M4X}UD!`ĥβM~AR4 ;~Jd@$݀'=9_jDiGa7OPzpA@Yu 1-Z3dg3-.1U"J?sZYҧW.UP7t̹ƉzЦWR}JZYP780@-nꝚgaOxR3_Lzw3 GL(bAfamk_0b Kۼ'9fsFC-2%u5,Zh藋n*vYt5SٰkaԾuaBzld>$kC;͙dV@y24xQQ&Zsm`/×;<./ Zӂ,V[9ljExUe fOVm#3&Bj`# AʬW}Q,J]B7l/ )(Σ|]ۋȽʳE+8*FrZ&܍{c̋UEZC,%Wʺ5@o$&F27ӿVq m"=CosJ tbK`O<Uz'C3_%$[?MTQBȃb]nY9ўZW1C# |, ǿ6Xϑ|q6aָ +9K"uZd4)1C@dx1ꭑ'lLgͨ4*'gu|CsyrGiN! PKSxߟ[3n&Hr99aT8s)KR#EHg\ V[B5RWe/nH8A~C*@]>v\Rs&sN,G%VNM0>EVڰ`= 'j :i@3ϹzD7pa-z9&ˆ9)R,ȇ`rRS61::*`tQvE8.k0.j- Ա  6+}u2.ǡ_XjVZ1օH0~Z]"q$@b*K#F`򩡓;5"uh%(kRk:},C>_%'(/:@LۑJ)v4$ˁEcfQ0=ø*#N; Ue:k}vLNOJ=cC*ZaVSʚӷI4tꆯ'dM'`7p 7'/w/5Ӗ#=+9'00jפ5taRS<& 3c}vYYG 8iw(VA7˙az>˭ ntf{[TDeOsE;ȓSɛ` Zk[ɧ=/~3``;+D$_oC< |(n:v} O%C{uhP \ČCqLjuEڮFsFۣUT1txĬS0~DM ߫ш~mB9;58ˍ|c@{_,nY|?ҌiI9Pvٻ9ySʠ;&;6`6 bY[ۈⓒm\Og0?D𲲇B95Fۛ) '%nlJfզtLWǥҸhKVEF,-i} I8anS]_ܑ jGz [[u#^XJ> ΢Üb5SrL'WHN t̿Q+ț3*xsp-9$G9!xH_ !~CCQ>, K+UW]#]GvILm o{hpl|o+kQ  n`TD#*)%5?>c.vgI;m=&" ܣiNBqqu)rzTD/GZ75F&R%2$T\;W곲F+:(łngN&|?tI7Ye.0i{/-[[O vܠ>{6Ae)A x.`bHm~͕X#n%QJ-|G9i}Ӝի#[1NUXa)@eWLL瞴e;,LQS,LL@PdmxӖA@9w6ИݯB<pn7=wp >Jɢ`5JvHhw1/cvVG0 gTrie9sb#QcWé KG%.8b#Ai>؄xj)>>}4FuPr~))ݸ> sH 2t =}3'@tɔyM_]I,(P"XX/[-f&Xٳe- vnZZ8>7<'DbzCevĺ[O{DB}rǬz=}I58SY:@P=cEulH7o[Z {0biWfsKy|<.'֠SӥY-Xgxqmʸ߳c$]IN%. h/e|J8Gn7/w31jN?]< O3 W+ufbQ7w\] oL szNXUpm")/7 9!U W.h6V@/ TsNI|Ɓ7x)ֺ]ɦO㳹\1~Zc)/FO$a UƖT_퉸.>fu6Ca.F2)~q|Ժ_k~%)@ds?k{FY%Q7v,矣!{ӂ..{ ᾲ"BF$괽,B'[v\ov!YD6ω.ˆ$:U,PI<+቏c;}6Yj$D ,2nKq-Cj'f\ºt|RQ_0&L 'azVRt\A98 GtIC(%-`j*MxrH"s0SS$c5[r{2_?B}5 =Jq`sd% -o0Uh rCtqHY{)Z:Q &HLq#"q2#5qA~%Jɯ+kDm&aNt:u:z>3؅Eq`yc6DcFZ'c:,(M}HGNZ:J@cJx7.*EUIJ5i'=3Ï7Wya$Gc_~ @!G)q, :eI.[Q)Zu^ZCϴa$_{u,Ƃ(fͩhHj"Af?B (Mnl a 7+BwzG8D@}gcBDzڥ;_Jl~>>O`N8'±mӚD>'[  ]@Xy# y`U9˙m|?XQOчaRٳylZ{|Fҧ;|vDVg_͋h/6 LP:Cţ@V/&@YSsD#Lݝ^ߪ60{452Բi!S( c16z(^=wAC ݹ$<02RnT:6ɣ7= &Z<r?OM٧t[.oȶת^\,9SpC9:GZoezQ@SEbxHm.": [AěJ484v-Lqn^dQ 8I!Dԕ(Ne8_䰟EWYA:+ dՎܢ u˼a 'wB2v53+JQOA3c4)}=qx4Շ?)Rŭ/Y֡}yc^7Ic!l'V]vwX=.[;zz6dEY%Yl& g]Ȩ=y::`?WTMilrqHqƪ2RK.+ؾec_hJQް(8f2)(JS*jQV,Dn;ՕfnY"}U\^ss|ޅyI@c'0ݮ նA%DGLֱ櫹I/U?#bpl:(ȮݽF4=K{~Q0> v\S7E|7ht+ OYn[s_e鐀': ] C oMo'ODU5!~(1&LAE- ]XOMWc F9{ tqNJ&P{L.>h.Bɲ{Os=y(9ѿԮ+Q%8L%LLNp5}~-M*'@<5H5;S<͙ ]nPw aAD-Sbʪ8 n=)B %]L4 %ʢPT*E'}MS(e(YԈ-~s0e<1<xT]'Igة5dgKdl)$#y2X*}~ o);U@Q U*c"j^iCO0tlkJ`GC5{17J(o%P]Y&}64Q)Jq EK#4mzἶRܺ {{hѲ>üI-#ڿw\xF&G׻j;Dy{2N?ͻs*&=աr%)FF3X eV>)XÒk@M[%wwz]bNiadbRH@H?ypL.c h+j+@%~Kmp5x1Z T/e<4$6iu[hÖ0Ҷ؟䆝±Yspg뮂]+EK%c֊FDA=gfCLJ]'FpSLgsG_w@nKTs n!98wCT_X;7ꧪ{`fc'\AM=d!8RMԨ`G8qAg@ ( Y]~b- zU3!P.:Z["nńFrgs8Q]-/,kCC O>Lfu>;^fhu+AL\/߳ 0ʭ4}?(isVfh`:ƕ;rFӪɫw#AqO^ @3_kM)`[lV;gL _¢WА& 79əm$-ekN5E(75I,"$`q;JGT/L&_lz䦧Q:l|ZdVcf!D?^6+lK(jP xX^ru1>sedq 1 @˙9ܴtyq;{u{T:X7 ̀^/_h`Ɍȏ"exٽT nqncche'ye!Vm9^ӫi\-1aJy_Wx#YWଳu1q2P4m)N0H Sf)(?1Mpl-lSvdAqsK:+_rQ&Վ4MՊ>p;\֚6nclXXo 'yY,ZKC=XWm$s qIZJk:pA10C;Y8a{ #twΠ}LS'G|_؄^^ogW|$u.ݫ%u!L8kxػT_WlqXɛM1__#4i9U>(HB)Al y?xtemJfBUt6Ka1יִ#ӉrXWvPLՎ@qnR29VLMeU7CQB";&LbP+SÐ %JxW},xebr*PB GRE{oΏ\oQ dQ`BׁRcE鐢H0k@$n{x8a\cI((Tvx8cu0u7y͠'̄]Cu,cbc Y?"}yf(^ ӤSVoR@QOB{-mms!1fnT!lLxؗpWXɌ G 5QfQķgc#5}5۶iEdhx^s%莈% E\r}l\;}M\_POTepLQYuK{G~3b.m}S@7LTfF3O{Af-[2-w}ڋ"'HKdxЕaPaNG$ϵ=c$y+R<-j\ i)35h } DvfjmWg/ճ}`9ƂJsQ3oH,U-J b7"Zа 8Y vn̈PwT%îgCcADOb>HR7advxn'ʃf`4~e̓r<LFf-kڄ.qkrw|w/8> jB'"#,8hvA2gCJu?g7&ͻ=K=y빟wb[-5[ݮ)s@f (U1; 8Zz&9.|ZqT9+`w &Dhpu,4Q=Vb]&9G68IxT'$̈́F"]wG4 4 zBzV3"6'{ -R{lQo z]O[4.fjӌtɥ `<^gؼ)_@< e?bif LKzi3wD_@S(RG% {<= E ]%؄j_nb5j9/F(/@RˆWn-v;6'i!^n{>S&)6/A BMe{6.MܳbJu wJ6lV0-!<eW7sT=>P;?u++)CC6X!cUִ7#6oXL}C_E4$ tD :ұ:\F*#ו-MhKX[&HZ:|Kհ!.J?m v_?QDrRV.I+%n2;%Ud;{jbcp]@D`38V{u' &f `,6-+]uRRٝ8]RD{V %:/~ >oXi.J eQrǸ4X}8Ѐ6M!=tRKAL .5Ia=Xʾ|:2x /A2יtirz[a=/xlrp`C5\4 ' oiu4McITnsla}D3J›#h"eLh{8"ߺ5Cs6{1}ʭ4EU- ذ ;Ω?>1WS'Ox{W cո'$,aNҞY}O nIaF8K AUھꖿ$&uݵNW߿ΐykp\9IJz{ʮ״pD P*CvNhUz4CvI&B#r&&_]TVC`h/@*&.gC@zd:FV0v^z% !tat%;> }"6kMm\nhCD x Y7"SDT`+ 䚁pI0HzxH;>qp6KF4G}`·wEU8QG/CJy{2c}+Ew -\j꣟М}1@cqǢQݑ.Q!h>X#)k. V9a*Lk-`VddUt&~Z*9`/*}4d\)h7d+23 )} > wBr.g(17mؒ:7'Ѵ٥B ^ GZ xЉ&x1eo*{=DZ4A/pθko%-=f|8͏טiKVC*T1}E|J"רpZL>7$?=e`B3=%V*#1yBƙ膢O[QmEL,0biF W6nv\*fTd Z_R7+6G@Ɋɏb X=|زn͛žhCOKpAD4Ou.o; zu™ArÑC|Vu??°#$ \Ywߑ:ҭ\~X)]iL%Op?P1M]:! `KeҤ8XbtLi_2k7s *Z"!V)d|} S`#補ѷtOH7V/h,uI4 N5}xE1=:rET4:O MfܓN$(ZQ %{a&@@]F؎aCe?A8 ån\&-RK.jG<4xkr턥{d_[T˭{WȽ@T<"Qe-ͻqHq gK3LԳ;1yWg||&Y'xgr(Ps9VA-)1,3Kvf6;otK-s5̓sdl^(*lPx%waʲa䳨՗Bb4/łBG#%V^rTq{$B)Ѫ}+mnPr=fN~TѴSE/ZB,(7[Z)P0b)fOQ. &S Z5h_(bSe0B2ug.kLߧW,; +@MI*Ct7zJkEq505)nX[>y)I^ Hue4Gr̿huX_Z ?5.&QAeRj1ϮNo|ûQU?ށx '` nvu}n2ކf"$l`Dd݉ke3ddxj̋ G߇bo$15>8' rɚ$) B&2,ҁS[,A–C5Q,H'UW9&ֿWWB;SR"J[k: gNES&#gW. Qa`z- ڬYS_ٓi֣iZǙ C -p<0U޴idG֌`@ܛ 5ׄ jwTt6X4e{25şC,\Xdo}B'!2@jhlY8-L_~_@KB|B [U k=0()YEeɑԕ3t=zY÷O@To[-dA#[I)F{XĪ;;E@PH m(S>toRHvZPϐqϵu9sA>ld:Xv E}r8!]ni7/y?h1xC[G~{5߄ 8\fgF[p2A*ԥwh6:0GgٞR*=—򭫿 `4 \4^ivuW,\vh 9`5E)ֆ@ax*hC.ژZ&{<39܇nj퓵 iGYm.}/nB;S7ƈxhܢNls]*lxQ0o6IKs:)74ͮl1۾zv/ǽ?!B:HW !~nQMAmt+; iJIU19lS $ɤ*Qەfk&g?L>1H=L+˅b"*&ƒ,qc2YP(7_XZȇ`?7[zGja$g} iXm% |>DIzANǃ'ooQ* #c"B]jS˝(2f?QBݜ(d׷Xs8p|Ϥ;^wq-9_eSƝ5kCxeJ|Fa)WҀ|׶6iuʩzg*GqDtS#b1\it?s.f4д9OY'</ 8)m@R& KdD8I~P)vDG|%PoOPo2*FC1fR̈^0݃T XWQ>y/OL/p"lSUyA:zIB\@S6'VVX̺Nrbjl s5f\cR[wՋF?,BS`ޠupn=K`Юӹy j`C*UO{ T[۫ˑ'j(R`G@ s/b\FգY nS0DH,RY 猒 bq7MM߿ئ(O;UxN|r̃W>*F9e&7M:LW9mOf;typВd4gyU1填Јc(Z/QǝƕV-Uqnry,QXn6AsV6OmiL Rim2'l, 3gx=и&'JjNPGkٽ@ q9. z3|n5^DMk>Qz(@Y1غAww~A>S}%a.8-lfn`p~Mj2ݭc{43@K rI]֛1L &<'!|v8{9ZкC01%FևAVq*$v>;bpwbQJdz$] wd+ dXdEtN|+]4?{oga@MO*?5u? {i^p%^yYnsY8f:@Rq~Quen(|!Nf `DD%K(ir9qBF"PwxV{ "솘?T2JdQC߅ B&H(Y| .`#)v&3؏$E)d8%&IF6LSxjTh 4ɭoʍX1W'B7‹=ޟ*#c7*Ɯt:L6(Xe#1ɎKݨ5hZ^>_e՚\>tƱ糼@ͩ['׃̹KGK׸'@DDT7.nO02N¾Lrk@v4Q1%<μ|/5vvzEZ1WUR%2e Toq%9- xsPSfCSͧW͘MȑIY6MDT+1RWs$o.$V/,q|3UӒq{A8aGP|i:qcϟ@p`zwt gȖH{o[~x)|jmsw'A~q;4_`rLf6XɽeׯV ׼ХtOȥ7Vم '}% (ۂX `Y6g3M#ReГ`/l%c gރ6 EW,L%U@Ȗʍɗ{Y".f]tIz{q[ ֜&P?I2%zeDAH@Sf /J-D4kRzd6CY  j!Rp@Ssb'm:?F Du~~h\je~lEKPt4%i_ g,=je!9n>`SD'ǭ+(7~SWnݓiGzdW).6q*2uߎ :҂=A:;Egk?N4>/rA\J\M;Xx{ڡp(E2b Н)oJ-oUI6>lDQXBw`_pМ-\O[(kέqF^Fxmx:7M戮VqjPЕC<֫#ylyb 'R%bgcq?(#7S0YhcZԓpY^yR;枝 ɣ(y$V r{.AfŭREB,W/Hs!\+VG`/pC8s$Ce2u(P)@YȄǎ25GqUKkZĝW]wLSBZi5ͅn(eCĶ,IlcBf9+ LKs͏T!8%cjƩ!6*-y (%"bϰf85֠"2U>, fcWp6rS;C Y88;hK#~vudC\yR,F]̃Q1ݔvYThpW{Ld[o娊uTY~2Rǐ@M?M'˽B^e3,uvV.R 85ګQi,q?Wk4xWc4m-!%H1d,ӫz5aoj&9W c0RSG2w%m~+Է)_JNi"\+ݐFs;36iQ;R?Y@Bkv#_Ltz6uyŸUtFVq^"_ \:^=0ƿ. _UڣV&Cjgǥ쒪VkOS%#* mͦeBd`jZDЅAA#i&v'MqN D$3FRs"]YX|N9VW_ ] '"-t{1$vQCmGFӹ'xb^xx@I#A?w>|PDJ'$G)҇N^2U;)ۇt+_ԬtayG-#Ǡc.ϠMvj)+6~zvHB[( KOeRrjࣽl+bskߨuQy2ccu"ӊ;R2D5Θoi7= YO53BQ`}Z+ sm&=Hcy0F0[O&H%庋}hH< s\3 4Z5= ΜGjL;?H9j9}tyiT!LDA!iNфΈ^UK)YĖT7CVl/s딜k#:wtʨǢxnIG [PD jK(<*r$x6dI~XEty@fBdg%'R_1Dj%~oJfM@ߑD{$@8 -O C8lv,fcڣ0$5Qr~7ZV3(c5 i"v Fo:x-&LŚt<^[G IlsUq^'*8̀U%&'u⹙$h)Ŗ累3 d;f+ L֧ 矼%$~6Knf/kP]@1[[j 1m3 x_r!51s, ! \I,Rڸ~'+W-^hr ZWYt0.bo:* $5WbbVI=~ a|ei|LB9$azWx0܋,S޺rOQ1/2_UحYH'Am ?_ݏʵR!~d`$('gXߗg ൃ9$0䐦i Or )40vz41M @CA8[ RTbKFzbVқ-m&" G{Q[HKrtĶ lI#s_"j}قLo-^G3?MpfHJS`:O@_3]J uH@s Ȝ̯"hI\GSueQxGpUJmT',F,T>/a;q:5%w51Wʥ_v9ޞxp4UtyIֈ8JvV;D@$a-+*A{^٤ ̚TV+Ch( *:M\(<8օ9`"sEٕ+^i\[3~ 'IۼqunVeP\4,Av;JtjP -9RP>@^ew`柂o R1,f0oaǏCZfaW՚};wBpKLp|S_izFS? $ӗ{ EFaő+vW-t,_߱B)*c< ί)X2~uEO$zJ| x8|z V!ha=V8gFK% q~.tA5F A[Z|]]atiSڏV=HcǀY.|AV5QZ` Ú\HZr13U#w jwGGz2e_O<ܷM1_5gR:^?/3 6\? fRk-e&r鼈 zc8z8c:3)O^.~tVC39坷WrueƃȦ ۏ=Fį GwA0Ȫ;I2(sC``*QEs/nFW!- q5|a۠h+i^!~Lc׆>$^IqIE_G)(lq)sS-Z^OXi fWf 4K_QanXXw;x~ Œ2r)l9Шf֩,kK^kk9I z&`{¥ =YL@Z#\FQYC@UFv౸R"r`9LFU ~ԦG߿G>w8E+ؘ5u~R'ș},HhEn--$V{rV:ȸ- * E*F Kq-|#|"04bwwmTn3x+uNHdXavRm;f,;֛Ϙz'o!K;8dS*&Inbca׎U}uz@q=x|. k.]j%I9rFm@3ggү&' L6! xYg#:F֫/Ġ9U+ₜ?U(>~y坉n+#$1= =yq*Q ^ok؍FP!}xe cQ cywOYk2ͯ3㬻#ge{{o|6NREWc⧔YSjaEZtgR:Fz9s/ZZϡ٠3ͲcE}a~M&{;IZRoÌ;#6"RŒ0=VPr7ܞ!牣N*77m9QUgn㒡^;iws]^'* c.%!J΁ 'j;1{co䔃ð|7?œ7ѳ_J:q%q^y:X 6U݇椾ge FȅE^|'gp@[GY.꘠h^Rl'6yJ-D0g ޓ39O&Pc|&b .4o g}8y_GX~UA~P =٬j?h"HG:-"DU-ޙ`*'ŗtЧ{f&PD*4)YݫǺ9gz: /M&K\'&Ch@!ЪtU(ù]+t5:'lPe㺄ksTqoy"m+x:>UiwO`l)۝YFZsZLS%C*bD2gdW9+&.ˈO_4_ym]N-=JEu_Su \F>ׇ y }̖ySḬބ ̨m"®߼Cg=~6 'W+SSRCSY߻A h).b5_$qc,+1q/ڀ,3,^u3+Y֥9msW-hU{Egf=ZX90qs`7\niI Dh͵B; k,XU% ƭpT7O4pfJb14s@^E͛L1.8.O=9ms?_ԑg-`pPB ""?ވG>n#`Ւ^Bs ac<V|=sM \CWGGY<-s!dQsY\{$S}M%> HFC D.)H K > ":|"[H-\U7gMuW/hWC|BHd/?JHeoC|` C>I_)iA\5f_ӕV'?#l ihQg?~IR;E3ƠFv, h?10((_?ӁSgU^zjATNf03F 8g`BU7Pbe@WAғ# I훩j~A,%&W,iu*1o\ 8, ԪgT5 D,z }aQ0/,ӷ硊˿Q-'qcOnfh<8/N~yvfX隰Ti%#{CC-$ 4ZC`F3R#f:ѧ= 書l!̝WhA:!B._InO54V,e_TʣuKc1Ǹ.ji-GN@,/700FtjhYOPP&yҟtX.y*D n&$#mY\304/NxK{ [{1SKőa=YJ\LeS <ėw']5mcmu_ΌBXЭ~̵.= 48c(|6V$FثHC*hn/2mk PEdΛH|5Rs!A8pZ$zT4HL*A4񨛸zHFo0 Tp?Ɇ-cGfLKN R"@iyR OfH#17"e.nMFky4YNrȚL33BMt A²Kw`gwv.B)gxPp~zp{^35?+t!` (|n5|"TOXd7/^g~TD IمL1~j{PFB\k6A; %ulߕlxi?[wZoP;{A)C;?U2NhMrԴytl8U:?TM>!nEBuKaʂ<i[T1]rŷ5rȧfiy \QB_Ƥi}I ~M/vZ ;.A 5cSc?'_kh5(ߗeܕཁIU e~枔hcԫ~@ Y܅g_H\ܛv?Ccf59׾x^{fFNćum( Z-e5mT+JžXCIv^lc *{gggқqR)eam*fֹj@^]1\˟_d⎿) xRn2z4xyaW*VգzdEeQZ5x>"zuz ټg.(c/+|EA ":*U9Nn9ma^i#\}!K+h) 62\ZA/!Iz" }6 %[>sg4ߴOx1'JaiW \8Nf=L? Ntݥ'ܚgnc[UI\{H[/c^jɲȾJ<` * (o< MKjAQ9'SH)՘U#}Mpb'sDi:9w4+U"xRGحKL%J-RVYAiZ4ŻL(/E,%;dz2$(ͣ~jd>&JbjbxJw] x mYn, ,1hX:FXlkR49'frp=x"IRޱuY?0Dy O qd/ypdCTR@ Z*ۮ]Ge Oְې w'竾t[mUU?"ut+>n!ka'U99py}Ol v j}#!Z>XO|xfsO,FLމ2e\@oHƾ/rQ!8KyOTH-y~Vv._7w?$ uy~rAN籐 Wb^x|2÷GZ  ,(;`tl8+/UjvNۨr<>o+Fz@J0H&4v\xNM "J 6;QtX3;φp]'V]}g=׌}#T!k81M&u$)qT2/k' {!mA~7Q 'i޻ΠӅ S' Vo;XbdA\Å~G r{;Ԁ-=5s~nќps[?Vjj4 s;54Ji᪋%"kY&-6봩mZyHCj]Jp4Fʮov,c>7X<fL.s7A3~l\8~b+bnZu%^I?WxcD"YS uz#XnȌRT(;J:@[p_:[*cc&x?CG cm@OC4z!OLfqSmDdJVp*fj{_,9b:<Qey8>ӻyKkd)X%g*|N^+0]" 'LsӑAP,A$vF*sW[L ,XۿB |$-?;FF0{Km2Sɕof >ݼ-`A^u`ˬ#;H0kc]⦶E/a" ,8ҟUzɽU'C*&!)l7Lm0ItV ء2ј$d][5'nM$~vu ]O$P1'. Mf*S9!|3zȫuyx5CB͙ (~],7`v8ѧz  J Z@rJ+Mh"M6,VU6q~#qL&'jܼ̟ u"WI;>w ȤXDGZ݂cT}>@&Ag~6Nz_v5J@"+[1Pad> =.kddHs&-\o2IBVhOtQӅ!I`ꥎ|Zf4hjV>x, cP{vqEĪhCݭ Ѯ<-&pʊ3iRAV!Cٱp1$v G0~b}ָ UR W@7e aN6xr1F& mP}E=_e TeFԀ*Oa1[Tv޸uvU[.]ueHǵUz!fH7 ^41%Ag%`.w D>pHy6:eAd;|wc1w&jd2$.*e?_ʯP-4gAW ˍp$ ; o|W<ܓK6~h%MظYM>g~8~lGv y}DkjۈهM9읶D]M/* `1:Nx^.~91lQ7AߡeΗQNz">*p¹cȾ;Qkw%rDj74<-j/{bwnTb2eCkԓs FSuR;"}Y/S..Q鎈&]0gbV#h}Egq\٢*z^FD+R!b(,w8$m$K˿fS,()=nYA'-:'+En Ś B^J,| V҇c:`!96!|`xE*ڛmGo^탒PAaiM,|ΊY+"ᴖ@,Y;~c)d4H(Kh^G\cm^HJȖ0zAvi"s <@;xvnuF4%d@:J=C{4{#Bs-E3ႃ=̐bz7-%FWC9i? ^Iǖ2G6Ǩ^o֯T#Eԟc`D:4H_4bwlS{,*{a/ rI@~:p~S7jj{dmεg0Z͜_ ͘,毂rJyrx}<8vM}nRߌ,CSL όU e R>Bl#ٱdtK!M%찎 ^$!$b%ِ!k';`<|fU]zm nxݖD!Fq3.ӬŘa1C9̳ia v}5GY+) w;nbucGzߺO$rՄ©VvRmLB)΄ ;,M6td2{ =9 ']|Z9dR6s"]N|V- /` cl蘒Sq{ޜBu޿K?%5]~b?5g,b3Ǯ&7B4#t$< ws^Z8~}.)2:5\C>%*[;^,Au=ۗcxa㏉>4eewM/;kf Jqv$Dr_4ZTz0Wl*]Ϛ/{VF_㐡GِA57&b8Sn[i;PC)7n黿[KKIV$kZ\f[zj  /´~VA 7zbv_ΨJe{Eas.-QO4KP%z3DPO 쳾E`tb+Miw3 ʙ]Y`]+o{]z|>D =3֫rݽlȃg-)mGޝ7:J8it-\q_,^⑃hSؒJf@xn+IX1 bu]x ;h2N'Qvqă=5Z716p2R7|WdbvţX ˺z;)h5  p'S9v_ Ax9J )G`7+-.羥zVT$.gA)[XRq lF2k!;j YNQ5hAÁ ٿnAa?*kiJtǣ3"|R_m2 T8j+JD4* { cS>FWf xbaRcCcMH"{\St&ѐ_A5],H&<6 bXZ lEF_K\+Gr[@n o8w(??n$SDӟJI0L Dul/o[@sR3T\& Sheم#mv7O. ܧ 9z͜T3۟I3![?pb! DnlڠƐdK_ Ln*Tx$h ~%Bqjѽк`Jס6L`2?uj-T?P{ȩ-_Z7"];%Mc6L7.'m<1y6H)`GQGxmr'c{ZEPH Z^@= m՞~j*^(Gr\4o< 3 Z%|=9!O+MJ 5 ijO'b.DZJ<_!cIp)T[[q\Wph}1_}m L' dk ʅϟi[  p&qF: Iz^A,YbPK W z=ǃlTI$D_jg:Hsr0=$5Kt>IJ|u9 Vѯv8VPf#g6N,CJy^M4@,ԀJj() >뻳*7"~hQ==}ꃄ Df }r79{aFWU|0pVP0Q>γ;T"2l\ϣvqQlU;_H U!vIŰl!ůMLBᴂoN2NYSb+n#kQS"" qN_IyǬelY~f쟜z7muZ4 oAYŢ`jI:>އ[^y(sTV*b@x֓5vz27ĸS&~6\$?H\ƑXzT1F6xd 9EKqSy3?dE`H ?VYjц`!#lHF jnPDZpv~9ϲlA5}YHW/ #I%)͎ޛm]t@걧Ov-G~`]Hl9vP!ܸ[h%KfT(@.^d?\QB/Rܤ-+v&(@bAmL–4]:fl(G5i'=3'FGwZʧ״dtF+,M*&AYXEpş׍5iDDRLQq!ù樳y5Pd ^<߾/ƵW4]|^aڨUa<ֺ;*/"7)=@P1Tfꏴt”Dm+WmDLcN8 J=E8|s 'hy~c/ Jz'Ԟ1 _Wdɜ.YnuKUt3%5츛+(qlƈSo0BkDlUjs0QKY*ZM?F~F U !ٶI =-?_1QeLG%"PAVv9gE?=o#J|.LSX8+w,n|H(e QPeFx5R2'ص$0*.ȳ5/`%˓Ɖ7+%s $犞ٓ8<HmZ\KAטm3Е\"Bo6i[e#o\Yps$ViW,itq E`"g២ik[\pUe> y׶o=1fQ(=ݚsvZ f}M϶y~XiNZW4z{N"9e| [1L=6N6\Û¤ofW!a|_W&rZM:jT\# ifA"oJ0{MwN 'ǹ["0%J's<ٽz Y_(^ {,(|e@c Gi >2;"d?+mǮ(: |Q #zۜν fSZ~EA1Xf(w qڠU}k~Rf6J[ؓ*n뙂jbUlqXB~l)m| I="?9WG5M3pāHkPh.i)4^ ua I mȕe@m|jo=5YdEVvBP,!k<`Y!sxsKpG oi+y7ɚIKpرb#uɹĮȟS-Aq 4A9iTk[Wa(¼WlˎPRl ٵ:88m,EG,)Xɜ㠵<(chm7 (D g%R39 Oւ 85/C-r;Ϗ0 W/ZC}AYJ Q-z@}!)O0V_tjO*vKgդbܱLJ.G V>BBϹ[DS0$zvO*G8$Nfd&ayK) ]i^;bXh @A[E˹7CF~IwB50p敻uAU 6;/0`yN{^e!Mz{|_(o^3g+8V'H5ad%0*q&`ҏ2KgN2+pnO_UdKƞCj-p(^a!5ٜ᜺59qOV},kyŔ:&蠖u>% Q.:*YtƆc!GD2ܱtz3m *s0  uA_/G{fs2Q%,]I? +Ͼ$|~ҷq!ٰ#du DN X+ՀY >3v W᱗vr.iic 9m0_cnG3M&nO/bT p Zqg)*@f΁R&ZC-(ژb\ )`tϣs ӄK>tNL٣G3,yH%Pe7hDŽjQ% |mBaIlS`s<=t`ƅm=5XU9e[^g~.aIMBJ!>qB,ȎAH)St^: YZ