samba-core-devel-4.13.13+git.528.140935f8d6a-3.12.1 >  A a\p9|̱Dc_Y?ԉgYRX5=iRЗQau*w&g:SC4h `69<+ AelL#'+O T L aO\dr Ћѫhmk33nyI30oΉ400"9edrd2*5O1a̚u&&$VwX(l267inq.DG&Q$O3^ta.S(OjsnĊۓ*E/tkN>2f1625ed49ba2e086c95c6ca0cc36005e5cb96093ad08f1e054a1da0d54b8e1ee4b0d30c343112ac66bfa8b396cc6e5d253783c8a\p9|kzeq xUSH !ËCxuȐl$֡+^u$ROZDJ߀oqV$NiUxxs/G."S˜ x&dXFv Y\Q[X؇;OYIZ*1R\\OB\`Ϛjࡘc@%E_ʑLȱ xkYܮ,FME[)YYZgI(ZɧQ W8(_7au#{xaˍlaߡ`Z1zH6 sA+/ M>p>?d/ 6 d/ Ee|7d7 7 @7 7 S7 7777_|(890:'FyG7Hl7IH7XY\7]7^6 bJcdsexf{l}u7vlzCsamba-core-devel4.13.13+git.528.140935f8d6a3.12.1Development files shared by Samba subpackagesThis package contains the libraries and header files needed to develop programs which make use of Samba.a[]s390zp38,SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxs390x'8=M  aF H)KU!YO +v&H!:O hMJ<u4&6w+QAA큤A큤A큤A큤A큤A큤A큤A큤a[$aZ,aXaZ,aXaXaXaXaXaXaXaXaXaXaZ,aXaXaXaXaXaXaXaXaXaXaXaZ,aXaXaXaXaXaZ+aXaXaXaXaXaXaXaZ+aXaXaXaXaXa[$a[$a[$a[$a[%a[$a[%a[#a[#74fcef3b7f520ae81ea16d6f4c3b33b66596d152ae9b4fed05abb3dbfcb87b359a87ebf5c3ecf098bad8fdc2e0c08317efd3ecd4947169677feb755c5f86b325f624961a932d6a7f9086124048de36dd84b8e84fb7e1e585b20ff771f131390d5cd7da44b981f9782081d3d97dc2d2f26726208f56b10bceaaae6e1a3b497bfefa19c5bf4838b4013a16d205238e5fa9819e04902a006a08044a0da795cbaf34f53c103d9d508de1883fac4df0fff12ac27300409f3a1c8edaf31c05c054340a1dc2974d9c574811447befbe13fc0f8b3d8906fa58ca173857f5b73359ec30f161766db604986021c872a81bc3e6dc403b8960c06edad4595f168293005943b8bd572ab4954abffbeef5c35b30e8c5806501278b70a08d6041d8a5685a69cd65621c4a13388bac59b78fcf253f55bc55e17f02d69beacaee1a2c71798c8e0d6466156e28d7375c095735fe583c41fe10f68711a286dd7616111bd0ba9a6c39eca45c2bb309dfe1684a8fc4212447a00f588e6fb067632fcb30eaf8ed39ec802cd7d6caed90f3ed522fb13effd5b3f9ce1d10f57b87a233f8b1cb8bb000a06b812e45f1d76df8d2fe7405deea4c26e6e1ccf3951c59a55836952be0923e7928b343892fe61c87666774dd2e18e31d70da33b45c5986aa1c23a6a853a6cecc9069b067bcc678b898c16d290afc34539c478fc1f6b47270a45b389de9fb9ec0042b98e789e2e76a17d01c1684441f27e27f5c54d7d8d1607fb9cede012344438922ffecaceea8800ef2175f1046485790f995229035a56992eb9f80f586460519b68e17e93041953c7a33ac4dadb193dc843bf0dc47196230f74fc5a9c4ac198965a491192d10cc3c52fa9eea23be4d1c3c4ea33d5f3ee0642d0e711e1f3e2ed9f50923c16ebfe2ac820e071af1cba5cae4b019dc46eb22b6fc37174d15ac7b72c762c260077a6a23b99eb7ea40a5e790a7d97b17c8adc0fe8152598db810a35a4331a2f005b7837ddaceb2598db386c1d34c1a777baf0d741ea2d153c399b4b0fa22367ee1921737df26ec3e9fea81c7f525ee4076db13008901c9ca9f404a6db835aabe1a026f6f3e5c05cd08a28a339b762c6189d4af93a1b6a87f9d9483d583e610ac30bfc17aba981efd38215a457355b1f19ee2e93d26cfc3f6127d4e633b7533e9f55f0f3748e050087a2ffc63261cb12891bda7f46e4c6fbf5e424e498705ad6fa67befb082b2cd23859d7002fa75a5794f15fad8157402985d19cdd5acbb88410f5f49e872337c443ccb39a80f6a090188d29592c534bffe32d5c7ae35e6564aee9764e4c17d03bdb96c5b46a501043ab648896cf8dddbbb361226da5c4ec183f16ec4fc964c65b35a84e0be1b1f830b8494c8e895196ab132fd82e055f87169c890fba90086de0d8498f0fb36921439a3568cd3a29c34bc8fd9c25772cff89b4edcc989ff5af4189ef2e0ce0e37872c17ad0196c4101f1dab6f2233d4987af03f7dbbfcad01f857b4576ffbb67ed2f4c6cbd9f0a9cd2192a7cd36f820400b8e6af775cd8eeeec7fa786bd0c1c686c5562fc60c40b7f0fb213627e0208eaa36a7262e7680bfdf38ab43a302de7a5ee1b18fb5e5a69c693660e5ab407d1696c7b4ac8f6ed075a178fc967e2e68e1bac448bf37478948a1f40401d26eab787f0c33c9147e5197c8e52257325852c5c181908a3f4082b5520d1cf8599ee8c0e42c4ca1819bd7e814f21ea857ca7a1cf61daa69affa14cb497273b24b2f9ad1eccc6409a5a5391dfba7e45844c4f2da58e90d275e42aac178717449816161fe77e2af95aff8ff703003f5691ae2280c0809d15386619c3aaf0620e8697c3c0d494cf0d6a2fbbde841699930bd1f5d8c43118be577f601d6cc6d9ea72bd4e428127400175ba02a9301ab4c10a51cf2dbcb23ea4de9c5574578d66b8f36ad26941b6815f5ad3b6de0320d91d5deb58d7bb5a7166360599779875fb758316964alibnss_winbind.so.2libnss_wins.so.2rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.13.13+git.528.140935f8d6a-3.12.1.src.rpmsamba-core-develsamba-core-devel(s390-64)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-1samba-devel4.14.3a@a@a@a9@a`v@`a@`<@`@___i_@_|\@_{ _l@_i@_d@__ @^@^^2^2^^1^^Y^J@^2@^&^&]]]])]@]@]]@]nU]nU]i]e@]_@]J@]B@] #]:\ڭ\\@\@\ \N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USanopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.s390zp38 1636457309  !"#$%&'()*+,-./012345674.13.13+git.528.140935f8d6a-3.12.14.13.13+git.528.140935f8d6a-3.12.1 sambasamba-4.0charset.hcoredoserr.herror.hhresult.hntstatus.hntstatus_gen.hwerror.hwerror_gen.hdcerpc_server.hdcesrv_core.hdomain_credentials.hgen_ndrauth.hdcerpc.hdrsblobs.hdrsuapi.hndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_svcctl_c.hsecurity.hserver_id.hldb_wrap.hndrndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_svcctl.hrpc_common.hsambasession.hversion.hshare.hsmb2_lease_struct.htdr.htsocket.htsocket_internal.hutilgenrand.hidtree.hidtree_random.htfork.hutil_ldb.hnsswitchwinbind_client.hwinbind_nss_config.hwinbind_nss_linux.hwinbinddwinbindd.hwinbindd_proto.hlibnss_winbind.solibnss_wins.so/usr/include//usr/include/samba-4.0//usr/include/samba-4.0/core//usr/include/samba-4.0/gen_ndr//usr/include/samba-4.0/ndr//usr/include/samba-4.0/samba//usr/include/samba-4.0/util//usr/include/samba//usr/include/samba/nsswitch//usr/include/samba/winbindd//usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:21699/SUSE_SLE-15-SP3_Update/08b059d7b5a0f63758fd796f8b3745b1-samba.SUSE_SLE-15-SP3_Updatecpioxz5s390x-suse-linuxdirectoryC source, ASCII textASCII text#Z^c8]Xutf-8baed57f85b4271f8850bd66182b1c0fca79004a5c5817e5af50dfafb4260bcc4? 7zXZ !t/] crt:bLL Xs+c62EOP AN{90AxFX67إ+ʝp)$0ٶʤ̈́_V+<;К྽ggipjR,s/Ul_M;[vYPXjB; aʴr&h6[Dnq1Fu@ 0!m9)? 5Al9'<%bOVAukAK>|.gF']FKf $=mS<:!00TP햦с[M+*3G?&US"4=⎧r;P=Lq{{M5CkݎGVVzg@2n["*|V;JKK+#>t,xYB0*Rnˌ|2o.?-d~u%rt*쿫ԲsPi!]$% X2n(d1\:Lyi?8C`Cl.uw^/zZޅId6Rqk2޽" ʥ>&ҕ؉CMT×0ؗߛgRnr ~=7vqү~GNJ&O:rW &ĕ]+k VA/' &'dO9n+?&?cNx"#~rwi06|S EVy*X"k,lqgQpF">ڇ`+Ο(yD1 zeTdЧżI*KqRSuYhd\= ܄} 8?U3MZC 0pB 6°q81Q0Pmq={s[V2!y8N!HlEm1gESfNL76?Y-Ϛ$kO7э&D]  )(30vJ,:_s8lu9$) |<<;PEa}Anԏ"#xwSG@c+ȳI`vL WѶ?̆NX2gu`|ް8viK'ܣ}Kl?dQ.HfmB]DJetc8|A@KupjVQQiV#RrHNߝeFq"JD%_z8(6x Ðh|r1T~:-DGuZB^从tgl 0n* q`7,{6sѲ?Ze ʁr[c+;PmWֶ*Nm8BΊY Us0`tBJf8Շv"/ڀ zN4,@ȱd',xl-MēaS[ߠd$! 2Q:֚ufS-v ;)2t2E+*[CLu¨Anu=`9wzaD#R ݊Fsd6xy(l5o3a犨a\ VVr*eTa,aV"Z 1h1 PH47FcJr"]U_Yce3 |iFoNX2o'at ߎ(Kf! Ág~g LEyb-eo0Бt/4\yǥGR/9[Yu4Ms ! ( ]|S<09o/Bm"|@gMg7'o-Dq?6"Iܒet/yV QZ3/Z_ڂg 7-"cQè/䞗muĬ^jP5Do(nDϴNN{XNm]MϚ2!ԍ gi_&oYuxjHzC=<0cЄhrsDr7켊8jGYYuaqu7gjk eRNSNϾoZ+7-?gGX #B.3˕SLzlPx/a`w+c K(v2 R3pVW|Zs!R YW^{ŗ]+D/I/i8wUݳ0g.^7<;-I}wڊ?N-w]<ĿW ݃MZV5|B28MiA8s(l\T1T@]^W|AKa! UOeWpeʓ:w{"goǯbRO+y-\w|}pA21HE u4`R=D?h>(ex^bnDݰ?*,Y=Xx޸ P+cpΘgelu)[bWp1{4`L!xEP:ˀ Un;[4sCb6y #eL3m5r^ w 7@Z^?O"n*,Û`7-'eHJ4ԦTc )@+iu.Rb4`oY -I^q1LscDŽsjASl9^)!MA8fl Ο6F!EKvr-O8 23Oڎh1G]"~ 3S>Fke?85! &nN ۝+kFx0YAjaJ)%LINa.pOqf/_C26fV2J8z)cfUݷI;*hMJ{Ҳ_߯/gJ>TFߦ!5&3ĜcUcNp'DY52+-cjP5N/N{qH/`olzb3T"ֻ]GI5wz:vӿ=aY ^wQ;X~7el)@`_}h@ose1UtϢz9UH1IK|`b/rYlߗ(uKruC.͏5 !_0k'>C@9ጤ \dm4gzN)=(aKvA՚=/ޡuIXc84.įvZÝ~'n  `7 _!N̡6zF2c˽> YT l f{V^Ctj7u: H|#L[|&\'MڀBBʤ,gqcaow-ػhwRb|'.)W7U5gk ~Tu_éآ&[jU dC.[+vmKlaao ΡHnÆ0Ӯs<4u/w_WGwCk)@yV ͙5L[jFK~cJx}W|Z3C<¤aA Y/JClQ. WZؠMfϔA>xD]'CSE^Sjj&Ly.e MTm`_ :fYyn \r}-y Q×)3+єm <G-V`d-p[s>G,G7ġi >|H1hil^E&i*'L$j< ZZhm;!+-t[@t' 4Nʍ,D]Drb](Җ3tiP# /*I^^zuy"@Ȧ>>gεX^"kҨ˺9-Lss_V "ܦ̪! ~]kaSpw[ȝY*,S$f`|ԯE?BHtUYN&7Dj6؈9TV)}Ұ^ ֛G8" P ABcA!gH*CA1}:.o5$&eB!x#/z(ה=vMjtXL.l{ }̍FV0 eF;"'ܞ[6{\Ѐܐ ߢ<3 ϳ8/~$=` j9{3@l4nAtkw$b-B 5cHW5SN];65ІI~JOq7$o-#HscyCN\5A,ZꡅĈd)L ;`kWa,!&RWrDu(ΖC%X,͊m4zIfƵ CZ;FhK#FH΋`܉sQVpY@pd0EYVD5Zp)TeUcmp(VN`$'^z7k++<X~W& )bz(dv\]UK7ǤXt9 >s]@5TEdY9A6{L[UQ.3j0(|} *yk|#5Wt2¿d|GJ0ʌ)Eua*Zl;,Et>VxirLDx% ߿p-{GsT4+SXRGDΝ@^/~zP;+tW>ľJ%yUd xs)ԙKR*oB榇 zƒvZ=-K욐r^X'ܙ*cLrBتLՙ}:vŅ3iϐ`G]>:Rsq'Y}$I)a٭v*-_"r uvs-ERyNu@a*{UBFlJDۼٯȪz\r~^ _IQbI~ wCM80xiyuA U O(FQm#|_- y6U\f^hiS]V-*8L%IdQjk+c)f7"t zUxg(W/ EE)aMґ,T//LT\:a Gn5-C|آ pٚg36nڅ 1٩OiMkّ:43U' |x+T{8V[w$5My;A50-[f?VN,`ʙK.MtVc෧=*;$1Q$y4P%Й-_ h1k'oroyK <X цY4]=eتJÂֈL,X== ҇GDDT b1_z3kS d -"H9(Lㆱ!+X0I@V-thkk@aK=ympO?NFv_\I6 B |7`(}_$|;f,{HJ .f}= 43w'G\7_3?peZJ`O*v;҂͗EwA ˲k)p-ZGN:P{4Zj䉖b5ɪ wĭ^k*T:W9~ `j✰\\ 霍67k2I,H]c%OʅWD# ?dRז"爧1 DovVS+B6#Вb0!A܎\[WKEIT.[SP"/'e0_KgHѕ!e)%Qb>>cR"j(Ik'YIU!ۇ:\T=gcf+%ttA0WZ+Y1WCgb~7Dp%xY]kxtٔ]=#v˨WNp`]H?3P2AqAͷ*CNy"|ڤWuQ/8D ?<5D:CCh0K?=Xm^'?@wơ%@}$O["/q8S⮆x#`1-* ^yl诉ˢ 2ꂇ) Y˾mٚƝr~ʜ2̡pjf/2al:p/D0|X׶(Pw_<;[2b=cA7!/ѝrb)P>4F 8Ԑ%m0vI}߳$노㇡2|kGcT,A`T 89t-)L9Ω4YW߼yl4>gmfVl c]׆v%Wuܵk9fŹ@6܅60oGx_Y;h͌pF `P+25-j!!:FY =)inͨ}mh\IWO+ #x-͐b\)ɊF TrJ tf9JDHRؠq mv|MS+#aaŸ f =(7!\7}L ~;~3NL$hKd8uIIۙwkTn2hR]!~RRĨ abw QjwQ)P B ?991exYC\Ma:X0!n;J&dfC4"I*^dA((7DrX%*2pO%!>[ !kш"IT|~H9)L^bEں ptJ8)T  FWzl1bCt+3c \L< }{Fv đ$O2IVdҼl=kOZUe) BAˏ_P@!όUp9/ҘW)݇Tbe22Xʓ[_V):fF2(źeHҿQGrB g"Vz 4%VL+35lu_gx*gSo jjd2?U20AsV`f;\ϕGL3+abTBnͳerD@5D5"p15Y>ud䍨@u;5DIHĤ=§}{Vj$W՘C]LqtWa"TxM՘<-b''Z %?^ Ր/䥄wPuv 79"/ oGۣ5H_m$| uHwD(x5Z񔦱~/-q@gBo"9H(o1WMRvC1hXbFU$K5[._|pI$gxi=}*ZV$GZ>Cdhg7l+g/>Fۅy eZwRN,VM3Tz =ْ=!BL̓ >o 3wJ[Exə!ZgP&IKk%hC([ uSk&X8POk)"%Ps5DF=4 3BI6p=n#<Z&(PG,aBX/.m 4 '.]ҁ-d'M//҂л32]H?,3|oV @(O_LzqJRV~u_CptV&aO^)YoM!nN\ NP^ iYJ4Lu#ʓ1c{_֪!Wz<-sM;ю7L:/-Cxg"|ċh/"&*x?x/OX`^tAִ X:)y6^CD]D ,{@Yv,BNw4Xj*sXxZa#5IP!؂Ѹ!6,~zbu(%3#)r 4ND%gH KW,sqy͌(,fD*,AJ䮴`A2?>B8.,;7nzo2֏V9=F6eܲ#UV6^ۍ0;h+PmY\D)fP!4zh`)>nTG 2TZZIȰ9BiwtC@L0xTrƅpK` 3K_ܰ F!`Τa$jE.핛ͺ@M^\zbǜx@.Z64k^8MV[G]\`|N(]T/@ߵH1[hT^{ v~2CV> d rdIXLJ_,bzɱ($WnTL}dO,&UX`Z@[EQD-R]o|r6UwR⭈Q:29G22 !Pl"xr+tܤQʿ-w  Ja`}7B>{@pI\u { ?|!KF-@Q2<^td pZF2qw:.r~}@%&-eטihxzgĿ}\~s>*2)W- )Rf '-e ŏlIp%WJ!Ƃ _N] OYR)g@b>atlbZ8+: S_U]}8+NxyNn@52"LneN[ (`KH%I|< T븹T0A젙ɼo#ca"N7OpL|1&90P'-ŕ ެr^n,˰QV <"EFlqc#A;S%D'g 8Ox͕ ?TKDf"?w0Qf:;kK?,Cjl⮛t?Nj~Mi2(6:C=T=kS=:Bg?F!OQ[WkˊT^u260JL' d8Kl/>tM%;+x{[c~(Np)rT28O2U JWGO9X5u0ˈqci`>~F>!_1 ELYǚ GB-fon%Qr ^Uj5%,̚sOnY׭hD!2ߥ"d[J11.DhUI,sOybu6{:RKȑM;TFFTr ۢx[تTGq7%'o >9/S^>/'ޘ}1zUC WÐA-NKqp-:ba9ܕ8ԆGcu%1 -댔tQ ?ÌYU&V=uWA[cݐ] ' de\/v?1YJFieF?m_Ĝ%Q}!ʂ }#3cDŞ(D01ȽSR r0o0ȍM~1Q*rZPW@G%H6Wn-d GGgӒ7U椢Go'bTw`  pBWYp!!1u5'wW˾1q-ba,4P4̜zVj_xrv-Db۾ej'\ABI՜tȁp;D*Oa1'{ZQqVv ja|tP G,c"I5Oy]{⻞-nֹWa[<~kp59]-|P8[ 1n)+2rPŝ ޴,) hCpntjo~^gup*!c9BiO :BwwYV' ;IAhA|=YR5֢o WG8 ׈SxA.Sߕ;gqbuє4'%9D&!|q"Նi:>,xD ;g=.Zyt8Hg1Jz;Ih67LJb)Rfc8iԍnC~L7lEDXgG#RT\6FٹiYC7uP)w"2r* u'nRI_6PIm?fqsʇZK{"]_'PQCÒ@t)J^54o`~mZ0o5Nެq  j`h V-B jiaGobam޲Ө^pǶ?08?z-jJYww%`} | Yjwo,*k! j(; +1/o|0Pvv}<(]A6\@uR% Q`޹n:Mi#aFRI%_)5_c)._(R$f ΑŻ6ٶ5S(>~}R_mnי)SSGd`zn2 zB@VS$O :B2W$kצGO2ED:6J "ynϔ r*5e:p 6+dGUN/r0b0=0f U^x8Tz)6{6"_h>l`_y7"5hyj$*4 Fа+@\at[!slDQe ΧPKW).$F AEL&km)ZS%C NBhs=:.&JBunHj`ejEgNQDDnh?z)-#BaY! LlHxձQ9(VSl UGRS:K\sɜ WYz/0oBaaS~nO&_l Gin8;VsOi?vNϸ EG}g 7ojZx;ԡl|܏Rz9+Id%48u.؃U5)k1GH>,+eIl5aute_Z\k(Y]G8N_иtc}]r Ȭ_NK[':m,D[٥3T/Mo/Fwr#B[ H تߛW+E4h(@l !gMi͓ .GKA-92n"L|i4{6RЛ5GQ'N?ZiK&C2i9}Nz fgԣ<0QBf5gx80ŗc2ݘp ҃-C>%(pK,? @YCLxNsi-q 8M1r*`13E :vjd8%T'ȕ=!u2٘ݍ3=! Q7s0شЙCSh%+-IHp )LEFtۆVKKٴ~ugy]d&ƝgWOƒ*:&J:`R3 ".\6gAQU^NT%~mI˪%Y_%@LŘ'k"pa t]#duInkWkq眸u5|zF\!8帅])dBV4دqd(Vr2iWg'"!"BAd\!C\Īm+z5{5Ă (n@h,?Iu݊g=1Jni#73R>{H \m+JFXjK㝇 VOO2ET 

⑅C=޳@ 녚Oo]?&-=(9K9qsGɒ6$`)zb_.%ȫ 7k p G0wF5BqZ;}i@R[lWdkg9Al,|sKr5Y $Q!kcT;x N܏M:6僼G*TDνo=~Ft=CwJiiN%kuE:J9 !0Q[(XŴ4קHmȓdP; /ת2_f +$~(6{-!N Vw}(#!TqWEH50t~k8d:sacH p5^ĭ ݖ0bv_qZ94-a2V0Wyvlm5RHc|k/7:Q~`seF5W'ܖ5avX71nǠẖ;BPR qV`aEMu~b|(炐W4dx%/uP7>20u ƛ*)G%Bh*K ٻDl7fҷSvG fPTdIKAY_rʩ}޸XTv?\ };^r N>W!${aTB bds}F҄ {ҽDfQ )P,+ \gŔa3cpcW+< ĈesT-%5ֲĄ Eݙ})m0o!2+p1k&~!![4|9u }O0,vHXw g/sUkWw@UGTX'E՚2"+RXbH0U0'󶒜ANZ:xڽ(6[F " #vM^+H#"rb4uAAIEfxRR})1{;j |6iŁHY0HAXye)S"y-QMV?I%Q(8~6gEul?DRտT ʘp:}9 ʿ_kʡ&>!uip MqQ._ HJfvqrցg֦?Ty0")n{_ #:թ+>HmBl٠&Qmhef| ;v H$h^njԭIEnbi}ppVE@}.ImP%`)UcoK ݨ8"HqUF`:dziQQ>w|ZhoSW [hA& fKѵQi 4kPn؁&8>buc*$ ;UcBL)9 Y,-'RWh5bL?HnY'kK2~rɭu nUtцC,EZIǏ-:D Nh#I9G[ /I}_#8clVz7cºZxe=UE>Xʩ¤}$>_Io)QeFk|L_f5jCd&,O€Kyzl9n2GPP{"`>]1.SrĘƥY޴zH0'fRbȠ̉x dbpq _ZKKjJׂ "C]d5zcA mz1;˅u OBf zXR.A~͢ȄwP |\v,X͌ jV!q6!x$c5wbLD4-]L/m9TxAZ}8%R^ aBϐ|3ʢaz `H;)㪔"&0M* TW ƚ6s3|Um\t9)R>-i$t7B>i>ݘUˣkr3]\q/N^N7g%b5m2@@l):283C!69-":]\WQls1r -))vT9]p/d b_8o or /{Vm20-P!*j@eR8 :ھQ{{-p&|3P6`h:\ R/LOݺf9 s1(@4[jNz2"xƂlqv(Lj/ 2ۇT{.ĝ$=]i'½9)LB}?v"t`),%e"zuM=(m7k Ui>?zX\kB`Q%4yxw\څKb}{fcta.]JȯW1sJo:PڿO|耛&x;R%(1{F[1 0Mx K2`"ՁddVOfHE=@ y-nC~'A[ײ!6"mBnZ?AnXUJ_f*-`sZB#2klK5aA3TeUjk( yqHOMu X.*) M0>؊UM0'&lϢg1y뎫(;(F#2N.^ח y1%St9Yתj퐉>ƻBkYIHoPO(~Mm(JwT Ϻ_2p:-zBr'Q mVCtgS*nd赈S?"B[Ɗ.d7 0]şaAoAԫкdk 1b^ЊJ~rKq^j Z($2X2dvQԀI߱^p7͟xrehR6JN71`*ݾVRcaҪte֎CYhhnbUUl횣:6ψZ]&#lr{[ 2Jg9e";H<⇃67m>:8b$pmɰ+@=1M[䫄n'0}]JbBPBC1ͷ:(Mޓ]J,&O U %glzD|bHH:X(4iӵ.i^KP:WMc(jͮl!;T[@-dME aމ*޳@83YuH-L 5k+z,gֳ sʹa5ɭ9)W3bL;X+هj~$G0XoNw.ر0B '#hHTv 5%Wp:7T_qKO0רM-B%MuiBp1ZIxJSVxw[TၞZ`CossO$!Yv'M~i: %S0YOLMnFB2H% baN8VC/7TaaxeNAW @Kbp7 =b%Fȁ5#DžJfR-OJ._6ڹ ]T݌`z"#!&^ HNf~ϔY*ݿ\fQUYҕ_WDa V&5+vRuhŏiŜj>/Nh+dbݸB^dĠx&8fq@2%]W7oa{w՟.[DXQ ~]54s⒓)y] C8d!Yx q V!l9C5&㨩tlDePU>s2ݦ;Y6䵥v+' o>+ӬjjlRl.˺ []'7ZaQéWTjའ›Z^;ceRy7^nz+s&ʱQj8LOJrgKyoͿF4|{ufaB(!zk-@Y.ZA# FB\65R[bϝx"ߐT9pFg:U \/"mp:>zAyhB@jZi[qD|6r1K^|f[\D}T+7VԆ^iSisM. `͛A~BO\+٪iҝ(+ϮxL'ΪAO5f1SEJhS, <F%l|Ġ}HXF)86#R=L'Zb oLȩtZR6vwQm6z"NmO1ȇ =Uy3ؙ}Z!DMD447|+\/$oT "øЁY i%ߟFy>? IZ}Ҋ`2`? /^YǻjFVaoYIqo{9yf?28#$ǃ.4lĜ7tmWԩrv#mw#JE:$B*ҟcdREٮp͊`PVe ܏µ~7%m|q V[5fG3|Xțq\אRi$R٧[Ħ/wcS؞{| xU VĹuI] 6% 5>D6nZT!v`;s: ئUxŋ8k-JtP.&X€}C6p؍8d 彔T9[R~tqѷuqT&Pz^~QC u*YsvE T`eZBw'6Ll56x?E >_&MU;Uѧ|=P3B號NU~U_ЊT{um[ tڥ±,-7#q[ -c9 UrbGd]Ԓ<{:Ik<lq'];(&¶(ΖV_Z)vLvVnGC&{G=lq{TiMW%~ޢS D$9,ݩW[|Z{ʵ*X. UFGrE_io01܅`'NG|x}6"J\vüIzMt >TqřmFʦ$ ɷc;ROjQ5Ƒt6׵ZK=dlt6&9U}_ C ^:w(v;iD'lJd$+oVmQEFX6mx>d=~RBqv* yfyKJ%"`|-xܻggG#8+TByspG {7 C}/y$֤cÞFIo82ow)Sxi58}{d6 K`kOz@U{_^&1ݰ?Ew{A.;vs7ctɚϥbv%yv*8ZiC80POY+> g|6s1,n?23_VE'wpiYΕ"L.Sȉѱcɦxބ4p^Z7jߊVx>NeQqf֒Nl~X=˝Nn\]ڪy\g>v{$\(3IXkXuiI{rĺ1)+ O_oolᘻF(4~n뽏wUKz jA.AsCP15ӷtNVd-f?,'\x:5Q.w"œg|g+nj2@Ձ?ɬrė]|͡wc#;i )w (0z{5m[{aqa.r>/ af {Hq]b!mU*Z4cRջ$ߦh] ~5PƇ5ٮE1&Uufq,IK# pՃY V$/TgG Uf?H#S+}H^yerEJf)jx䦊#9\fcQBEu-Y&7O0XߢcEܶ66Ȅ]QS[r'yո/*p8 l$,a>y#^\2('m&Ii8 .׌sIMp(ZچKW0$Pl½T{ r-|UY_i._R.GmF[fbXh@% \0?%Ve"atV;TXT#&` 3W5<iSs7̐yUsLz݊o38Ț;6UG+~`l nGZ4v[q1urzh^6^]LULRkbtϛWC.U81,R{ڣPq rY˥$LBS8( )GgAnX ͚^]WP߲l7%돘O~}lo17C]ylqf9OS/ ,z&j0!`)8"ά/ɜ,np`s;^81]~~\ A+h',߮|`Ug%$ZMQ~=b5\ 7~ײ+M.*]:۾X^{on7E٫:-gm5Ǣqq)p9cxA@vUzr  aMͪ+NjW5d6~YEtΒ:m+}@"5l>`fCDm+ ztiaIq_^hbK$)9bL^4:@]$͘_ nN_ROx*59Lk3˨%]mxu}QRzd+ ɩãOSvR{:RIL,{6 ^:I*i{Ёr+'y1nlG/mEV 5HŴ{(`u_>ʞÏo(Z $Rmo54׽Hյ:/ՈI0dʾ"L)7b/()Q(wHw\aw(&<~_׏+I2'Co>GI\bFĒm* TK6?T^g:nr.J]I-4+|O!N6`!x YV!ו7|]P(jwR֚'j|!o'HًI\J&0 ^}LXw^(EP=fDS Epu_ ` Iho\Fie* .A@i0)觫 5Z2'W*PZڶef9ˎaDO}lZY7UTC9vsYrvy~K]O?Q tIQ[u/^Gx0# sVIݭAB6B?L;aCv׈?༃v4$]^QWûE:W7QaIPmK S~FELl&XB@i| hJUDCpEr=V:Zƾ,iBp6jh;mSآD +:Fsvt^SeZsQGCa3o` /g##LSϡ [P|b4UfԸ#cjzī)P z;ȸQxH(lGT]7+ u"Rű}&UF< =휎.d!;T+Dڅ~9E抵Ҭ}"z)ÀSB]e8˂g!{dw%ۇx=;>faXf]ʠ Y'u˨MEh.1u6g. x7ǡK$gܗI KMбa:qfYˬphwshТK0i»դAٓz1;Ѓe`<__gJa*>XƞK)e ~#K`p/3*.z;[+kiå ":qZD~UE:؇oǰP{+"erՔ🿻CEIԟLrzY\ Ӎ?l9 Πǩȋ;/a߸>_xZa۾J(Ebm| EuJ',8 O헄C^gxP& r4qHAYFsњ53އoC3E'}'#g8ҡ%2QG[q 2*b/@=@}0r)ʙ k}:[%cFo_w5@ZITiN2.*֞YU㘼wR # VUFk2;SM  :`˥A:M~I;̜/lˢ|g u[#罾 Ф@Gݺu3PԄ:m9ΉãiR/T8O 幔9#Nz݈rt+XMv/ԂNտ=ZDe77"~i]"@7lJ)63F%s) pǾ$;‚"MYqR(&̡]tvr w)<bNy*JzXC2\PGGTqfU?0aUZfQm]x/}/!d۸5 >oC~:YF+i8:,o % o=JqSnliTv6XZ~`)ܢҭY*qyrDw2^h7{YKn ߿";hlWIy4);n\9s'q" ˷đ>,XyEHg%SJ=F? X1-cՏf{&R.tˏm1DkL:[J3Z|zSn9 j(툥j=Byo_:Xmrh#y.gLjb#6ϯ#@<2h (\{ `xLsLYC;*Uw趴$ L9w!PmG J'E^e .`Uw^]&ޣr1$Ђ\bN7}.g\H Ӷ%FFI`M[}̢Kj迚[/ 27y8<Mw„6'~qp;P\ (bHiruĈ6qkE'޳n%Ͳ Rވۏ^b+.BG3Y@Lu,,0bHnĮ}I6*ڰ!9ZAeCcw)QDI lSO7H)uh\ˢ )YNI؞F0Kf2uD+%•#^%|]H/I/Q &r/R@)K._k3Z^Cw>=Gʞ;{K#] ?\D;K(5ر1 hrdYTn*]?FM6tB'&~_4 %xlGeGw .#NR2VE IՓ3B]9LSVි,H^j>ƿ60a,M/LDƈFV랻\U-m#MN3+] iYx3]4SvgԱ5WE"Yw9กYx"4O`Q>yC4?{~]1xrm:w@68h!~@5oT"-9c7&R)vı.O68Jl[@H:twY1O&+ y%":HfoFx?QtQ gͼ#CгTcoNu3X&nKPX ˆ}@&8T?$}VYk5K M]2_߽Xi-6*5L>fM 3ĚQ}]:؂S>Chy9yT]]+VZE#xrW.KhmJ%%pUز҈p=Gr-W`{3?f(R~Tid>") &Ǿx$m1: Z,g0Aݽ&o,jZ*$\zp/[2Z5Ҳ8R$K̻A?2ƾ;Mt/hsc"Ȣ/Kjzqyє?{:+G%\pFQM g%Uk}! 8ttȬ;4@petȮP"RsY!2=/rv+0 vVMe(%C4/Q#DS{ S ' U"-K 8wIMuy4vA.8^+qR$,6ZvaՄ#û=Ra1G}E 65pzyAHNL#潍9Nt0#RPY5`OC3܂2y-#ܼCHq'y+r+l'>21Vc+"GSS $DKӷ";wϢ 7=GJ7 >٤I͛w*%0)鄦jgx+;+l ϧܪ٦UM6 5[Y88M~LP"7 f3 v؋M\A:@vy0{G@Ph{ D$[0gi[$@0 'SGЉ*ctX@xεQj$W.nUl$s \WHNLvٻ 4c5(;}Ⱥo)m.2V RąGkK8aΪ'菫)%4Eͻ&zӨ#jp~[džO$ڷFCһ7̢CGCVJfH8} p߭gH\DN=] ]5> r j JZW5r:Bx; 8mXF4<\6y(S#@Fiݝ2g ҿ ǷT-U6!cy* <݊ɉ4FH49$aD8Z?wN G& qOcS/546g#a#H꫆p//cAwmjA"Kڍ@ 7K` AG "/3HTp=W }^khyBʨ 6Ҧs7UFZ9P$MZ44U4 :׀׬1@' Qqq` z]X.Qe\%NTTD;΅J0OZ 2ms$5r K}}pg#xr7 PV{ks:"ze\3],]!E3v#Nۑƿʥrmx4$&(UL1;jhzjdh~tbVbtYYg=Pu/ފ-R06jKϖ֛HDGA8FSU4܊5'0 [O~9::g)jt:DZ wMN$·pf ߬&~> V]^sqvž E 0SClV+ ԛGZMEsc]m]asU"2KŚA Hr6&<̚g>!Xq'Z{.pbAJN =lϗ[NT7%bCBvN,yO bC!ĕ-g H֠Z C3Kn+o}!wܡ:ey{A\3D~[/pVӎyr@hY˸:3s˵ JiJ-F#QRVƺ5 4.BΚd6^[9fݤMO*8P\ BHUb^32} 4}_to;ˑzŶ8 ̠j;Ń!f 'WI%R+{Ẁ([C0-FMӇDo\w=}y6+ Vn6iIH,"u+VaE85g@(GmyݰFnFV//| Rg)*AOp ʾ| ~ErZvD% n$ n~,z$lХ Tߡ_Vv]DVE^.z-1jPU=ނFxeci|7jt)t}3\8t:~#NQL=(юo,Ͳ^@_ˑiR@p*}vOY]~Q;& StԵwZH(r{\]6l_@Z=Xr?9cL!˼ zm&G5ʘ!Mz2Og6&x8ӽ5{rzK*?v˴PkUtg|rkETo{yeMg1JZHϲ35, *~S>Y EqĬVr轝+jg?X5ǯ[N.[q*}wCtgFkmAYؖ|1o֓9 [iwͲ䍔jhki&Ti?v|?P=xŀb*)ڼy,ƅdi[. (t|퐦B[Z^ bWg05m +qANW:ѥ cB(zp ?wk?DۢW\v 7l욣#=Iy%KCfv/&+E߿Z#{Kθ݄K!^$ m2.~~잿J5Z# lևO$-MQ4}lHE}ѤƘ¦@Sʺlߘ2vDҀɍȖR5np㌝ӓb~%}n[s*9._ d@izgep3jFZkfNV2F]a[~ J :?NN#g(E6PE8@#kl=R3}~t4DO; nv9)^IKXYz'$Y3eO0Qs΢{9"+ bO_F哏W>П@?V^<B6ufJ,5DUϞK]+|hA=w{{*/h7sbƸZ#gK:.wKVdA28-ozo!lX*8Ԣc˸nO EnHo9pגοNpQPw1h5uu_4%@?fYh 0RW+G6L ]I3'U3ڰoU- Tp닙ꛢcs1f+=`+U`9!s,,$'lWəyZCyufhP-0Ev17})-TfNy;L;._<\H%*%̮$ɼop{&yLwk`v.;qIl,-I?6n`u}ܚfwJEc+ˏOil5k{2%bF-)XC VRrm㮵WcC+N2&I8CQIzmiT}F"|kWHJ.qʸaҎ|B[e[׳ϟ&tzFpSh29'1,K(tfJD j^jzDu3@^t\=-Qp- Fa,R@Q?{Xrgr [Z74]JmN-$ʔy F{1 $"E|K O"[tuY!ҳXS|ER4j{8Ӛ}af&".Qh=Aui9lm,&ωU 2:5FuJr*H8-~YsxPe.$C*F/nvm7T񼃁˸9 VT~Vyrhtf?i/(n.açh%Կ֩wAjb &fqfdΤ- Rt)T[2Y.(7t1pDc2)st=p23Ymҍ猡֘EnCdsk}iahNa ^QOZzJs[lB:H\ϩ<^Fxni{3g0p]JW dU(p#W6N(215J$P /8KLZ\StJu8L$n5Qi9ZE 6E2t TJ.`mbz75(1s"8x \ =ι_奯|k˷Rlyybm bdw'F6T# --EENR&d) {ux:Q 1䈵?(fbo7n::|(o r2EQh")(Ip2I nҝCF˽`TFb+k[qI 4A){ElȘ};;x_eU9DAj1<I. ?B͈o %q &>_K5F[y= Yro*Hwl={ kwj3s_'umx$,%W}  Y(/ۓJ*${W"sOՎ;i o4o8,@ ~'} DAdkgƢQ[D߆] v}%-*"(}΍;XT<ۃF؅_ɹ)Acmqj&ISݳ<2b8qo0;&3GoJtu_ h]3 | ^\u$DW5,H{*=L*،ynlW3ճ.<1mVSNoow-p>N/S9-PH'#Q0$5sT |X5Ln3 8) Nn'Y9uW[^szI);;^f-OȾX r^{x%fbAf"퓦@ :wkڭui Ro0%bĠ{ 6D q-lX 7M:(d;A2_4=۷rK6Q l#8 Ĵ( Vs#^OÂБ(~v+g)2< Tp<9k gu0XjɎ]1cJ$mq2<VkY}5t֗U)C|w,-[+tc9.e$-,A;oaf V׿x":8xFg.pa=a# }=C`t}З hM3hQZnx\0$6b͋m;d(ٞe4(]Xd|GvWoFA2vzɱds sTׄN9k1.z`d[)mlk{R?_P5,eOM͘#.'e]8Qr?d#,c6!;"c'w:A_"[j*&VGͨmV)#~ ~b0o ] MQ: DRKRa(ZA)?:P^;+w\vQj%('XV9'BP :zt'._E+.MQ?pe֝rq '*)p 68ٔ:@~2jRԱ_Amd}7j*߄VMnTrmoJ=N @}!͢ /ahZ=Yl€sC̦`og)CCAo|Fg$Qʎnѫ?guoqduTtC{Zlߏg !*fi;ai6p ?TIcdhp({ԥ)W)~K4gr36 Q_9 xhUSH-_Ot6#]sZY`BYν۫:GxhS 2${2}U9@@V]r'l&4ηZvF(`Jnhz2CYe܅0:]nB?NZ͜Ju-C8yЩyY[-F|[ -9>=/hqV^2'0^GeZJß .̫bJ BS!]Hۓ0Ջzf;jRyPNC-N۪?꧍Z0ku]#;<]A^q-Brug+IcZIO3rw>c ̤`4o' NiiUZJ%N'ww uzrV9pÊgNNA0igo%1X'4g2 ~4 4Rj M\ew˾wkĴ!FWWTU| F8Jͧg02O cjpbh&_r T"f0(ֲz z~$.yd|?Mlv;o܎4\/ET?uQT(BϨ4>=5rHdim)Cuf;[gwRܨWsu_vJ:2+,?䋴8\7h3~ˇeڠ5DBDHbC7BFM?.&6C9k 1=h4k[bm$/|k$\vD$R$tA#pۙPn~uA kۺ[? 2F>x mRFϒڶg*S}" #F&Rl\;m/(䑶ÏH{޼ 8sڗ$sFïk\-QT˖rNHD<Şzæ0LV6񨔾$E_Sq1[`n?j*ߨ>\Ev8+ k?lgUv{_KXGW%7GOYl1?f gbx<2_ПiRѤ ]9_|=FA@D&bY]t/,pm~ LCC1"?|Wx|0WH3sWR7)dgb܃h^5]^7dvd-J/ԭߵrftW!xPoO3ßWm.V⮬Ԧ1G}WhTIIΙRyu l) 9m g\֠\ꄂXRNW?N&6l~ J|S䛸BbwUմo=7 #´gT$eW1`0.YJk#:8FVRFeu!ۮVG8y.\DcdG&h\yچ?a~]؏ߵ\@271Ue> 7(;=h,T`U\㐕0;ga˦)]V:GL;=03]5M J= )yyΕ@2 +#Ys~H]GZ,*%erPQMxyp <7ŅfD+g۳~x]:JG]Vaql޽$N܇F[DnpDAn憣Ÿ*I3_Q7]IZ8E)z*@YpNT-=P':Ms:(L P8u84u'GSR393;Y?fxVZKyO=skJ>"^2p:ÉW,2#L3}5*!d& S .#O,eL:ݢY"4|G\^uY9~NX6NhKe]^ ()Ɨ,w޷T$lͫh=y0DG ETJYW.BNJ:mNh.qy=+~H;72RM +kPMdYI2%iPuPx ICy㤸uNa( 6NYb7 9^Ş(vY=? ,[!ǏdÝx;f+!d3wU6x@, *$k9e^Y OUˋGmh1iy׶M0G=.DŽƽ@jad@P0ߑfit\90ODLZZe*ܶ PäYD,錫ꛍj;=cyWG4RONyByqZZĚS:?"lSZ)L GHVIY)/pA$]H>0x\p> _[? z82T| ?wu@g s=_kd*h(T8#lJ@2^755.?sLycG|yO}FoKc Pީ2cC*sƈ+\*"bz V.z 7;3퉤 b0/D7V9ˣ)6@q;'O .TMJ$!ڙuY 1+Du _>+4T*yGNCe9Y B6XҁFW@ڟxw`eЌ i$/Xoy{KYr(llP؆6Єzxq 24MB!ۯs?6^&](9xI-;Su~rvSH?B:jO;Ƿ"}yiY4/.&G!XHDpNӆ#iBcMkGc3<-a CJC|۩j)o (EW2)YΧق G6u4z"q$zCEeZ+ Z6f6}+sӍU&];u U :@,#KYGog x'^zaMX,iZ̫{B(B |g.xG 8_dIŨɸ}"ɣݯYf?K, W=ߣH;C# Ptlr"B>eAyd ElLU9VeYlh;YhT9-{zI`N9ʄ߄D04tI\25pܪϻ,Ƙ]n>͵};l`Q;~'@eK B]EMZ̚ 5i3XTǂ-ƵR_PDV;RݐAշBw&<t4itw `|F@ؘ@V>)GM%R\qWH.:yE|dB[":'  qSPvzo@L}©yYa?SF ]uf :#%#R ԭ-W c?I/B*=KWWSg3|):%.X={'hh@%g|1x{uқQ>>+?"`m!? fJm>d7VՔ'D16t vwTx&j¤IIF=KA:DY@Bʩ'%l5v !̩.;e͋N/-ׁ&8EՎG#c ŋ6lx"TJ5w<=Ks r%o{gn6w0Ft{5k6kȖjr+0t6G眳"È3Rp Ĕs9un7ԝƤfV^/'|yp7Gj>W4̈́їDp[К6˘m0a( qɝI'{9a}>N\ϡdm'bnm]OQ}\2\qއT쐏i`YR7*NZE>LWGsڂ|c@v~vqU ުV3TKܳ#tRLJ-ce+-u{4nGO7D}$j/Z]W2X+Ai(ɤjƯ`اnӛs;7|XM6#_XFO7[JȀ \⪗aZZͤp|9Zqj'İ^qB5> lI?ʦ\=w5a|9a3ͫU:S ڃ m\EƼ,K I}aHs"PWOhl`DSd%ga9ΆbIsDTK{*F]ji9XAP7hI# 0|&E4aY쵍"5A$伪n@!̜^(5ZTQ$- KwI9*D7\sgf̩Aq{O AƆ>nGĚ6 S>Xw/'(}x N֣}%JnËҢR_fPDAȊ^$#qYX4?frfg3,S3*/e 0eF3k)F("y#z,QVn6#I𳍅3X5&3igְϝ8Н4%䧩ducp,k>,-WN$W72ėvM#uj) S3SI򐑠 )wjdW4֧@F4{ J'oh}XP9gҠawj3AYdiV|wg{|&TP~a0?-IohU0R0q&/C۸_+S+_ Z9;F.4<~LK`Y}a||W5⫋0*$Zcݶj󵻓;f '5φ2uN|_"h 9ϻׂ{;Vj̈́fO0O.Jߊϝ}x; P0j:]'S0Wr xf,rzEn;/ Í@@a`wֆp4>fKCC90\a{ru$t=J^Yޘ +H(b\UzXo".d=H^uWDBs#D6 >xEBpcjLJF??f!Yx'>Z6ZA6I*'b$oU jU&:WC`l`Z1@E/\ `W'tn#2ǘ'ͣytkKhRprO&۫×d *#L֟3?i='%ĭ7@ލy9]z WVQ@/.x]kzX{eŰX-C5߷--q{\“H]}FR-;)/bZ!P%-;SptVzXL}oe⻦럨I&B܆s8Slګj PvP}W_6Z!UVYjЦ(Lja.ljjL}YTbI52ԷgpPE1:1_tϙo w]YuPj;0gڜWA(R8g:/.S Վ{~|r#703>MY,k {3/T*KI{(|@3OUP w&N!7X?Na?nO܀(z?OcVㅜHo(^Ot\8.Jg^ˍuHYym_e`!/Ռ1BDt;@H .ԖɵnVpk.iBr:ݠݸs!̩x ṄJZ3IFH$mngm{-;C,{5|ύtf\:ɓByq„q'AFC*Unƥa8TOHD[|D<oiԉ.{~E"A#?7f: FiuRvȖ NK"4*~C4:e;e5@V" 2] /7wy< كѻIef־&`h\noX0*L᱁#r9Yӕ˞((׮ź6?3ӹL^ɌUji09-> @PYvU_\)ds<rŔICI) 'm)Zrwee[bFS>6AЙROCd@},z)$vժSʏ؛-'`:͖n17J4KFDdyE7=UkK,Gykd]IUG鼽#ޏRd^3x>%!?SȖ6\nEhl^Dug* Y:j71͖a*'4#2VGJ8 tg*߄fxW.H{yi;%YHgNjLrfYi2>#wbĽ i+s }ʱ_7-qκyp M֙WJ8\MwW)͏ g7H`+)d>> P#jO|/wԤOona xP,bK8h2P_噺[㺝cγio#ӂ09\ؑZkݥyK$i ppHN:7ȓQXzǔ Rw 0R@Xkq6ʽ*I-2mQ'꫾;UK`H".̂@آdIdPÔ~9(d"!h)KaGtTL 6/w}`V41SP؆jl[}ͳWY`X+Ϭdp.ƚ퓁sN$}V -H 7qsY @_Q_kR]q*.RF|إ6Y A[h$F_<3!}\rP/HM|o62(*z3SF"o;A8ȥ3Q?k3>I&nsV*`NMB+= EVas:aq"M0H5ہ2`_ rm1T'`M!`wXHd"mQS;!]$G?=E~WDd1o?lo`Mh;K7wm/ 9[ ';W\I9u6z.ᓀ| BZL?ԇL}L5c YIۍiRVsEo .{ESgM pPѽ@!:@tddp gc3‰l32>au1?`7C{}K} x@%$,%uY7Fr"Y?m =$[cEDH>. 3U{Z-S !{LF>4;Z1}v|tfSۭc\iWBk`׎9P|sJ{i` bzA@Ѹ3X|!n%\3WQ 1vPK9lI^ 4=brt:`yrtI+RvZGq{j|Is,CҪOGPw5fnv,EKRĆsU&r@] } {2.1E:wBP3OֳT8q>,RQ.ǜ)7 fYAn).0K$XZ6.r›{F&VeA#+*~n9[{_|🽊]VSS%j4m%UkڹC7JYWoS?k\ْ m37 4{8gGۮJu3OEB[pou^ZOCH3ھa&~ؾwk@P9(^MrP Z /󱍎srz况0 Lsد`Ge|V,9 ԯKd%,"X;;QOE4ۖ\q#~v}CN2pSYKw%SȪ薂M#uvnr(Vߍcݬ Mr*k1ܧ a߯^ d\s-ixo1seQVȊv =nH[c@1zO+K-lx,9?+X-l,w4fĸkۿ&$o 7EuP(4X-2ؗA&rwM9bw<1rWgR31FzgJ>t(ٮХ&zZ_TG쥠 ܏ (([_OY!e`t&" rgxI b̶?YJ;W.u[l.OP$ o.L}->V;?"* yJ/$." hyb[cL{[瑞_t̕`=>$ IdN⑋mCp@->5*=Qإau?d.B, Y+;4 /ΜβW`kwsuUC2"v;2%M,SC)U]"u`/`1,[cvid8ǧP SªB:8К|&kovpWV"tKlF=1ѴP 8B( Wh&&,C_ݹԀݡ M 9@ϥg Yxp\Wlq cT\Ox# iE+Ӽ T?MdVWZpm۳g'/`ன|,`nt!1v$T]pV`4PίN'4F0#IOF}.=C!:=?>~6 dɐes: J}ppn.ˋѦ/=qZE_uR ?Eswp`,?eoG͹|zZPZow9UWUnv,Xxa_1;82E2RpVcrVɷޜ5%_̬5}/cvҺ~TroǤ@AY*ttu7zk_ 2r'@}qO@WZz]6Nk E"ޝx#٬αRtJch.*כ> ;> X> ~Lrs=pq' , {v0%ǘyo4&8@)Ѓ}yN^'5sy HG l{((+du:PclÁ;1Vdݶ7T⢀j8kƱPͳl>N5S@3?29u).́T-;@km,Bp`=fK n&.89HZ|=4/(#m\LYdWh9&>xF1IOS2k57"* -~F6ׯdx(bPmrQSp _H1iɹi%GNTErV؟rfTͿ/O[ݜLW@i`ƈV0p[^?mO*\OM/h Q9Luډt$Lq,ZF_j[V?21pqc/&) m:;C)寸0. ྐP~2D,e/]ahh k!W3unCHdqtos.HӺ6/W9t gTg~յ oˊdW*%gifq@98\ioHؙ(AZcyGP^awM,\3%}knA'7)( $P ۝L_H b:%EێX.?hQWONoGeZoYm`Z4齀0<yHUT {IR JY/.hSn /g.ARM\{G՘ ZX7xJsKL KH9)Y<c;vprRHxBnۅ¨7(Ҁk3`n e#{O *AxAtڃ #!zܦksG0~EA fW<9 T+BIJnt}d ^<-y2oHz+e V{leI7.^cs&IFqd5 +@NwV }UlЫœ?aUFMo0dd`;W#6yrAʨG?_ 1z>!ɬKo)j0Dp+Z<7\ 23Mv-=+MKМյ59'-13ƇL2 sίi~qh#IAsmRʱ ,љ// ?c0+l~P' bV#awt.ߟC,!Ӕ_-?Kh[[GiЪo2]ݜzé7 EC>5?5 _ΣN RYO} BmE&Z2|)D _Du%$=&0>Y&k^BAk6GP?I2EPO@˲ϱhۤhsc]M(heCd%:?KCk >JѤGF/Sh(pMwOer긿yP.4_3oR*Af~Fu{5@xeɼȡnG#V|@KY<0~. 9]dv܍1Y~)BV WydQ1fy'x H G/k:zEp3\.IA@N$.K&~]A1[1ec4d׸oSnDP %"7PӾg$~eóCfa@Kzuߺ.t_?Ҩhl!<f:^R(b,0+#Q`0b5C]WhdOƏ)BS"m݉;)Ayn8ġ:7d)Gv<%-5R9եWya~Ԍh 7KJ=vƺ?EDFJ_DSqf@dWL#y,TDC:4aח)¼ȿ&lySBOKѻaybt_Y^>ӹ2a8ԈW3Hm.`ܑZʖ\LO +tw&!2ڮw!ȣ^R8wl\p"[Z)ynKO u̝V; [|EWQ}'xS$}- Ƴq*߽4)V0FQO%Hދ/bOC@QYFC7gl91g5T=/)^\lꄞ<6E+[~cR"t 1u% Ej\R0 W=O+pMWB0a=狘]l%)]}:7B@(3Ҷn+Q1K>XKJGN`&?ldJCYv DdŴrPӾS 6^7A,|v{~~3)wx;>`]/C;Y Q TV%S8|(@dn.Z9C 0Ox&kL Og"CvNjCJlP;;eWcd?UXyؕ7jgN|wh8F>*X/ Qc¿0lgѐs0]E7ǩGn cE罣ULg19v+{kc.tVv5=}S\ Z{HWJɤ& w4_d{*g0 ?a* ̎;7 L7.xIIgjL$O+\x+arP*µy=P4 J=,}k Sftz:\X` c*V1rG~%C7w*ٻ,+uIQ^ޫ2c;LO ~ՙL#HM'T@z;]5`M}FJ-^ 3vRb5z_u7K䦮͛.rLl{- E)ka(\"JCھ]D:'dy{Ri#:D 9AJ B#я̪%LDKGPf0Cn~Dg$x\xQDtﰗb/va7TxxO]FH(XVR,7d϶esWmVo=^ڳd]洒-W_y绛푲-a<~͝`=, &>x$?KB2IҀ7\+11.~ S 9yp{rMXz gV QwC%泹Rv>S$I߉ ,)JucNz?C0ܦ?0muۂEi1%i =gߒFD, 8ƵֶFxg0l*`li3<"hD@:/^fNb6T C˞kޓq[%rl} :QW}Ҩ3,-kڞhƈ{> hWy uIm,rspCk7RkE#G1";㚮̂N yȨ`BX aoᐞ8#ЯS;:!/ UI5*X#agN4It'yP$k~YH]:z^(&%cxmG 7hZfXQ3@HOQh_a(~: ՀMbQp84^4~Q/N]۾9h$mWB}49m۠g(LAqoouC"|hmHhƍ\uy^\d*ڀL/*S7z*a}MuF6j5 _!€f _DxfEO#5R[]xI;JF=çB6LI銣OR Znυ"Gmn0zo8*UnC]̎ݠ$DyrTA=FU80Oy9.~9oGh߻'#S꟎!/#o;?s3OߚS:Zm@8F :[(-LB1=ћ:RskvPK~uv a\}ľ~çqkL㸐Ěe O 2qS / ^L[PQuXLM^ڷQp1%/T{Pe{‰衳S>P[θ+#Q ;A+IJGk~6p疄 ^0dz$T~ôN.Tȵ?vN|C[@\5fg:±s^PeE~y%}5q=eKH#`&wJm 4ݏaXLd}~D=u[*:lLx,UEsa  ?tl@2 +B]>BCi:9Nl{0ŕbȶNnA5z 6otSR/9* ex?3|!r' D, vKrȿ)%:wԗ -UٺG5@/7Ю[hqH;BF-DD>V Ы3Xѫ yOD`NX먤х 1X `CiDOمSAq&);U\GvAu`WL  EO%7AUJW^D϶rO`5i&#A"NÔBObڗtp_K9DöAOF:CRpZj86Nkyx!t o旺_/c%;Wւ# E=mdpRL 0W B Q57])Xkaܶ߷fM%j!87?8rծ1#8 !<~e: 9Ǫ(DZY"s_W4eRTP:pQ+zJUH2ff*0 -+:n(@G)]D E"^AIw>y#A-?cd[ ǵDW!OFh. ִ{VXUD ٭kҩIo7MrD|=ޒ S+Ez7Pn wr`Մj{-w62ƚ˖>._V?, xp;[22+4r޳vJ7l& ?سP936옆rc mi&ALFca#T$p ]Z 1oS"UVWڪRGFGcM^D]ߊA.-S@5`|T4hRx:"il3EFu ~bN\W@)`Ĕ<w<$V[FbW_nHu~'wEHoTO>;6|+Zq uyl)9-X߽Q$Բ8甯PcljbςdZ*:jMz`ZFe$>"\1W֚O)D-, Ƕcs,ؒ=yH9*!j|*Q'Es!s0_pJ8)9q'SO0.Um;N(ϩ|U3"6}0jrK8$f``BzCkP2}*¥@~"sI\mݽvyIN9OhVT .Q`)ʑ,avWwM.Bg}si.[ҭ!<;ISJm2c+ޘY06A}u J7 dvEQ4*sNf(zUpjGpPCPsov-)/@~>yΥg3XN(,0 z1=ѯ&: qv.7 9Ja^N:i@Zo j3u6$cRDspt[ Y=k]vdO,QkɯL&Z8XB8.<(w,e.>ܒkeJ"WPpogbB\|/(q6}PX <~„Kg~Ns_4#^0Q9Tkf.`xhauMA݉ͷRD=n$o&6$d_'U ׳9}M;~/̨0ݧ9d왘N'yʜ<[c"ߔ͙Ǥ]8ctV'i`E t7DJ#<߷z91=t+nKq,ׯwOSF0)HAz A`HdeSR2\q*jѤΥt\ؼ 7tc*!;DSj&q 16lEkaϻ Yroވ280 VyJp#-OCyAH6 AF 7+*A/ NJUmGޡ7mjޭ{{N>9u謀liJ˼MjLh?J- _&l@팬l=̑ =`=G" ɺ6R< L(,1WHP]믳x5 s bLy("lcSGzE0Io1UtJ54) <%8 xU*.nT0 Fr\fP{n/C5'|Q4 `(=jySoCP p>Z,: M Es"@[; ~I#bB 53S%8oCB W_4lJPFH!Ք C'o"0rVEQ[FV^ê0Vta/cMoƴӀ`789hT$81 v sp6,!NxG*gar?H@VȎMe gōFX31MĮK"AeC@E 7<ج9,HRlY\{FH[N'4: VPH4?;&RJMNo)-$OZ7eut _=$y3ё"4 _Hw&,]HV{5%Us&>c/y{FUHwgE3lpP+(t5U;"ux{7JމoG`. x4™v1>!Tm+ 7ڴz_[Zs| <;E,^;O/!T9P_Խc-3l_5Se]@]kK `q>2iaGV1t':Fz\P)>JUUECWgo`qmp p:̫A$yGIG0aGHR2,~ P<'ᔃa8$/xaeY} ZFtN Z$amtL^.", 4K:uuHT+ox ǀB0o1)Ow&{Fϰ:|CXLHx64)ED{_@aME@O^O-M*xݔ5rQ50lt0"<7چ DϠZnb@l,|[eewJt]y3O㕴=UO>G{u'D"4(u4;%[4ѐy0KZ8YcK9}|@ ' sQ.T]%&wPPFثT( trp pOg}SD_tSjg.z3X7H X JΘ944fk;NƸt(>'qeZ|+U-@Tx ^(40ĕ8oHh^|]) 8nc6 'IŎڈ[[(kuxN[ q< iw˜y` 7)KZEaX\(Yq3m>V~Iy讘h&qB>}hu0[>Ú)#{=QNgNY.ͦb-iĖ xh~Y`:8Ή"-g4TȅԜh]|PVƗd_(ky,x Otpո_UJ t޷rHNltNCc-ݾT$t"P!JjwĂ1&T-L|vJ>G X=H:LN-O&Kzà4Z1;'bTKzlBA=⇵cS!m"ho>mA~hxR *`-BMnSš HR_|H7P-0'#=BA 9Rhzhfs>+N@axYQiƉO=8>l@eAI`+p"Uy= 3Xx& N97qFKg~J\!_=~U{vG@vg|$cQWӅvۨdKj:H 6 q )~YɆn{ 5^#,rݴ'΋c\QhW R+17˙ˇszj/9j}d],%tsKPjըg(M&zȦ$KkBP q-IÀ쌟G>)܇Jl)̧H-Aq Hk#,{nBRo:9(3a?+V ,ǿ0} l+&sP^9hdUmP3+cǹu1O斠$f>o3y!S7:_6R5T avd{F/@V bX$k<MIq G3~4]iP ˰p\-eq\_.tpŷ;o.$^ Z.2(XblKqɯ!& cޠ,uM : 0DHxa_ ?'T4?o#:DEH&:Rhs=H(+o*}]Rq8bted9eDeu \4qkC[{sӋ]q&-~WVmrfJ}kg-Xd3~=ӝ- (i dejfA+0V 5-W.S:g2;d9ު~ 1<_ol!i'"D/nj(O x#KT>aNVscL6pjDTAe첯tMimT"j ~HWO,g>hJ[ne7b>h*+O oVx/+.ܐ]<˂vF{P=-Cv'8"F !r  }&a;a"ΝX1ei0J7]UHMrM(4twpõb2uAN0!5`7AcAQ]pJ˶^Q9 }Qk 3d4X!.Y"}9Vԑ Ÿ?y>;*Lɚԥbiq)-x^?,5y̞yVpVI "c֯)[}nLb;XKàcܶJX;"mCHvɉmyV{w#Ugx{RD=HMzi$]Pg;m(\5"u O Ԙj: V/&bҐ#7}EkG 6Z Z,q5x"V2wcبKj#E4}$}jmSJ}YzUod9j@˔'t,J`0O$(GɅGz0q  w (CAQl#{/N>jBS'iR=(%kQiOA Bt1VcL<:럴6]5*,2V1{U}iH|@K9a ƴ"s%fa Vu cwIt)mWNxhRm^^?{楜yd#GTAܤG3k%m]\ϸ T}犊q@M;՟PBFd$.:FfB%d1nx^h>^cukK+q7X䃩ad!Vtrb䓦еJI]5 .8{s8}M{gIb h:چW>vg/*;p4h1e*'LR&zi],ys8 ݆ $0'@I{R jT3h~R-F(gnK$BQSV8(EyFk3=B+Bua١q/gBM_WA_N7/}##dJlSk -j~U3%m=^r6?a gS w[ ND@xw9]ǯ4f5^}%5͟d2.,!SF|gP[z Fm@=!XR!󌈨S*~吷r7+ߘr!l co[S)t.zX P +,p$vZj-=.Q˸W!ibxm܌vlӠ<kk q\iL +Qqh]LBP{ Vߕ3SB@Q9{w//j<+MTh L<$!G%JS4ޏ(цޕJηLzO PՅ?4s͍lYNh&Ѧ8/kD߃Rp{ڭC=͹ARƴPWIE twv^71KZ{?,e^=oQ" ArFDId)JAtvt=b90 L.ɲ mq5Sj¯Y͇ ]jDZ=M o_3Sk1jbx9ixILB-Q`û:2nOf.Iō' T{Ъ.igPqM .)vN׷¹xhWLxo^RgWtjN'P+1d !7{3œWM+/3 zh_3h9c5n* H' W6ކQZ ,Z})3(3w7]ÚkyN=-]] fyrFKYcS3}顕ɴaźB}cX"< xg7mX(sEeÓ ".i,C;:3!Q0oR60Av?C{j U ^ulr-] R)/]&H~0Ŷup!^gj쮶=IpI:nkI;'BAT|=ky,೗l9+y} R v5<}V >b٨=Ql+[lx:Ǒ}2`v9dZ B;rvo&xr Ƀ9^b_kـ{:qN2 сĹ9Bb!3op䙻coBG}y b MHsCXMYpiysFRKw=t38e29%Luvjf59-=R#g$U:bd.o4clC,7gD%d"9^UUN#bm>]MsYT>ʹJ!RNCSP 3J |A35H/xKp_]VHГJp%ۻIp5֨6lũ-%%[{v=iVTD@KT)E܍?ٞpYeR[X|]T5xAh_cc`bPSe>Mqǩ$6\aWtW]<[fH ~j@ 9\E_])i 2 X㰃I64v+4M֣)2OFyPҜ@/ {^%ҡrH%n'Yz&,LUG(CϺԥx|jKЫr^ә[0ǹ#KXo'@/@ Eo&*NPJ_Noc͏; w33v}'u0݇9'dň\Ge&/&1i֚[%^ȍ\bqkV Ic{$$Ù=!+%ӀٜrŦ#BYq;7kiqE" 6Fjgm`zhS4<ߟapTOh H7Iv|öοF$K>BdH_Z@kcx +k1o\^d22X.PUڋI!Sd@jɸ3 u,&oItV dzW$\3փOA"ÒΧdִV٫)sbk~(ۓNދdr.y*kζ>-S+q/Mz"VvX6ܩυ|bwcmsdT[ElRS7.dTJ?!%Bsvc9L.%9s:*MGbDl6[72(=/ʜ>NYmU)!zrY*#wzyVV#3?Dž=h=r@W\&B_Hǟ1[W!Zv]v:"C2uڴ)7y.0-PhStb/eL)Gu%;<1B2r|{zHu<@C #GBn~Nu䩳TSbdtI޼܇0C zrjg kixrD*C;J)/uQRdmcip$8%!WlwdC>WQBqc Q/3 Z2;CYI88g1F󊸎6^~uyS%E4XPܘ g;ɪ)+Eg1nֿ6s[d[H<W,SKkC?<$d)1#BYMI"LgDpdڑ04wpW1JdfNLEervLdKzY䕩bӘ9^C6B=32j0l "L1ۑo/9!DRVլM3M[j&[1y:!< x(⩎EXл|YiL#~4x7f@ xkZ/Cړ+DgwMTԱP;U3햃(9J&qK"ڰRmȇ!-Ia`*~њ!VD60˓:;gE,r-d"K9tטH}NXd@`̶@"t2šwkǬRFZsuY<׿wa3mΨ(jKP|~(Ġ'B 1ڟ/ζ` kv^#H|埡Wݭy2/ pip:H0̌~?Z 7ZX^c4z)ouNQ+لY#S0ǖ1pR(o~&T"jȽ; sW$O@vc:"->@h eų hP yNvb)5nN;3SRkQҐPiLaO_xAՒQηG^'j`a'Մiɭ8kFJdV:ԺIBIK7fjE_S>7Ǫ{!HU!HN$n(ҟP%ibjzRZp!s0 $@ܐ؄UͅjVGd"Pn^^ò:x^Hj05j7`F"JPWa~L6"`'aOgUJ7P@T(;.>[[{?q?5`ֽ[$x8eExnuEiz u6Е-Bi7k5~}+;6#bd7&Q$oVj7"5ErN XL(  Rs6.rxC֌CEw_k 5R֒ɻ'Nq+sCb ܈w큐IxV[ɇ,'ۿ%*JsQ]"߉3i"9`@L|Q@ū|yf':JAK-0oӑuXd"< ,>aؐ&dO'T\Ud:&ȒY3Ή 3u HSțG _kHZ_y7p8_;Nx#k|DGC2UV2oFxV堸^ڝUdɁ ˛ KZ#VsR.;Lm&;~tnޟ}_fR>vx藽BH?͋du6$m=<.ěDC@tW늫p3Uت|-Tƈ> 2.%pkJYkS26tU"T-YfCDN]dp_D7ZDT7X]gO|>4Y,\n@! !PJ^Lm#XR5! ݗ?fG_hBRգhKUݰ pfZcY}iWBɂ|-羡2;%Xr1 tTPN,L7y 2`1ø4?tF؇w-Ӊ> }cyAJ`X> P|tCoM Av+4C)~MAI=Z 7FyvI:q;$Նt@FpS`Y{rgI3~j^H,ז=e(5@+ҝ=@a􍟳 ] h(8SPO=/.A : V~'v'ya!$*7fAdXH)8un9wqnJn.yg:mIEP?Wu-PVVPf&.;]=]x܆V:$0ܴϳ?$}2Xh^z2sc[*$!.ԀP&$5Go3hK*FF+@ r|nrI,n66gQFܯSbB>,>z婏'EnQ:H]\mDDm`rKZpjѶPK6 &458&Ş鑺 zm!렎%;,F=x JuJ [Rꂚ.v¢4GymO }0gܐL ,s֗ɼմoP1`X-ۙ}jϋn@K\!HM+®E[h2&vŶ%2iPi֜ 1R -3`rts{L"tMXtn0t=7(vAL!GIɏMqLz;L.,Jhۑv_W;PFҠTRVG"'s fKp˅PÿJ=4Gob;bFdG ܲ ;TnqO @.S <ٵLђ1ȒmGʇRF29i!1u,ڶ`',Z/]Do9b*NZeN꼇3{J2W^,;#6O:io%:z3J&O:71jnA](] eKgGc)"?$.|uy?V^EgR#D@q2N';:wyˡh*_?x]sepۖ=㏙*y[GHkrV$JpI+wng:%t=DMM:Txdມ]"ˌ`DĊk/!˶B&Mp+ݐ RC>8KՅ,j +Ak&_MlCU(%?w`pvKLrkguބiT3ԟ l׭a뽃Y˗^Y#IGi4cokrrS@X9 $59C*` t ę좭?9'9(B8^dSZ9Ī <||rm> z $s+ۢ~WȜ_'hs9r@=aB2*{W9f4]DB6٦ 䎐3~INDw;9J"ZYEų!#zN!d}4vo6 & ċ1CdTĿWs0BDپ~TX&O2KOa*}2u&|9K,$-^): ]PPg E)QiviDDq`0>"R#uJ*:3Wп\1m+PjYqKA-0>XF[զȑfD;[:X[Q Ǹ.bAz؊J"xw ކ?/ Ww5k**ے9h椹Iy6~ﶭ t QcxAQrsǔ:ycYjq;jܶsoc,SGD4|jO]5-)G;?aCїXẀЁY+i4i&xAvojnxCtN(&Jtٮ'<|k:I7}=SS )5&J$-4FC:oQz LRGbhݲ#6DWߚH>JH!ՅzQԇD;'_DRb12vL.!BN2 Vqw/r"C,J`E͠nH; 4_D6,s9Pw4^ hrEo)=zʞO}!|菟>\.=U=MP|n!릔:g[eFN0B (s5mf khhX}p%RS^ 2uEO}, Bz2FU ͼ;(mNm ktBݰ/BpAm~PWG̝b!B2Q0]εL>A+H |wq!Q젊uެ' foW2 rx*OHXlJJVIBD`6iƜ" 9pttG@(CSV(`ƐšjD=7aˮvkuq#bQkIcRw ߩFQK;UcQKX9G:?; jta#.m0` lbǙ 6 Q¯uw2a l#ӰA@uGcH%<Xܬ˧,BQV ;vI}'L*r물N~pw 3U-X9[@U{9EB(2U M4 #Uקj14yG0҈ypٸ E M6O0I/f+tؖtdI J5A5j-ZFdz6w'N@r.qc0Vṣ[V_RqBD=90E1Tr {gQCbFV `X&ɀ豞64lDV#SACxY:M9zB}]7 g ?nUZYuJ;qqQ)X//_^K, 6b/䉣]k [ʈ,IGƨ{d&HgJRAMN]ܩXf$H`w$u6])L<{xiVx!~b:-s,3ǫǗbY~W>;qxLwGG'P 1&PTbĴz3fgDkҞ~58b'AS 0f%fk\8fJ%]ܡ$pҒq)Ӗ1nx*N ;gY@k`b꿹&f1{Es3I ~IY՘ ΎĢ穔cتC:EBj·$AhAH{B 6kR^L.q_c+߽* &~⾭[;ϟZyW  'r鰨7HR}LzӖd&Zg 4__B G p7=J7܂?m˖$ձxXJ(&U ˏ.vƸB>X!@w@v`-ιIJU̪bi)ۏ_>}?F1poIWY"O(+e!]?=iYo7ciܩHbWNayi"sHc#^8֦-+MX7%ZTyFKSR @{\Nn[R0{ĝTVzG`@vUq3N,l cw;}۳iHмGHX%<Ϩ4T"!k'?Xи3gr.4 谺IS/w\36 aVw+ds1K2Z\^ 6v`/f:VH.bװ"L5yJI_Zgv -XU~b;d۩L~0pR:]q.͝ݜ췢aMҁrK#86Sɓ\clAhSU}c/`}l#DKak ?+sEY9/V\s3R{k<( @?ʵ#uEKD,Iu`ѲoAB#ֲRK:YTsi&ApLۥ?/xS]v0 uuM GAq;tY)ח; 9{Ѿ@`KW{N0'TI\mr>&;-s# r2>FK[N S, jzeIֈR;lЪm .;̊A =OX7y g|Y$֡{8ieIFŹUa$ڽL[F4 <|Nwh{ij)0.a~$'CU%X3 c>~YZwVO g$|#5N˿l1s4 H Kt-nKP_ZNKmZ%=>. m2PJB:bkQ#м%s ch|v j2W%&7yȔ8rj,Z3_qwmhtBTZسg"$Mqxe/jf`~]OfIr#;-uzZVܶhJ4LJ!mPɸ؋rv ?Z*ZdS\a_Unn+.q0B=3C< g X(^qw- ?a3m;['t;{Xqw|2B| yC*jEVXEX2! {{NngS|{+y|xq 2άW&ƯH]T﹖I½a]SXWl8*'ٲ4P%ۜrh#D1X'bI屳IW!Mru]sߑGƄzzȣv= S37XOiYD&gG?@wkKlu%;3tgUYG^2' ^\3`oYߖ/pLv׻^G^1 (W0Aᑙ ~=W6eV$$ܙfaiJL+s[љُ[ّ^$VީN~T:ХZp```eZ:ln/%Gf)K9RF6սӟ]u*WФ[RbPOu*ĿMϛq}0dтZu`y1/ ՜Ef CS¡w&|nn|H"}$VcndC8-Oԫ ; QsꞋֵZ,/lQ <4rw6Vs$u022D{^&M۷WeةN ;ƓB8 y")\]Qrb}?69imVb/&\Dd;M4UpWиTd;9k"mM*w;,3,0hGUB†&ߴux-S0|<rP=cCxE/~6Z}^L|W/6xQq֦O2R%K9Eq3''tΫ2ɰÞVtiѕ| 1zlu$0izbl&{3LP N} +НMNPlj:UZkZּ$3|XkgAz?O "a ]~=H*,B_T]gc%}8k/g ZA6AʥxZ$ Ж h2axh​XZ Cq7\!?`!f o0n +UM@I̠h 8SFXi*Oɻ e >;NlvPڬdHi ߡ@ҞrOw0Ujw6}OO!2*I.ޮl& / g)w^,a ϟ<ޯt\`~ (7`;RbW۸zb"2px"#1i##,/M:'sܣ;?kUͨtDJ;K OM _WOD(fL7HV/&i(0_SI;"ЧwTYHk^* dO|[g ДDAD[En\ 'C1[uBw69_UXmQE$/ ᯻AxE=^ {Bb~Y| AAdw4+I~e¤Q|nU0/B`eL~{ ث@{q5-kL(MO Mj^ia^e27XfLeIRɼI3]ln Ҝ1*܏CUZbu2{0\ZuJgNv}ڒ)Z ȦTa'L/lQOv lIB+2 'Yݏ&̯5m8=  %}YT,:,ұNW:IluuR_nr)>Vț9q>C,RJds"vcEg+?;ټ.wB)NT!%:ލ$$kjڀ) Gzr:W#KKIxSrE@XsSA Wlz4~Z)k^qP( iXHbĶA뚺`7 4闬I%ߩ(m0UI*G.]W2`__s%X B-i)v"ZZoltp-䱻?PmYFXUY}|ьl,ICJSfϕyiйhW6]0R)ѷ=t_LVr_,tgApVЙ@C PlHsꌦ饬ֿbO ڋP1CZk;BE"7`V.`Np؎Qm*B7dgqmMQ A=mt|>OrymkNYוFI 1KQ"a)`$L\1y%)U?ċi},XSڠGIB!5R4Xȶ?}zǽhx X!tN)W]8ƋX[5duߏŋ\# HiEdy)J .]lAw27اH׶S!KLcݣfkǦ%@ ˵||緀NB< ﭅p Ie^ @'Z'UkhӔ|tke-Q zY8rFY44Dfŕ͕މ?7 Jg7TB)OM\/3ax.UF&j#WYWj 8/ՀȊW{y~,)*EMbPiԎLht_9SѻoFpc}+;ѹc!?[hsdpаQ@vKV/ тqSH)"Zí2/o̼AG)e1 1| \[ohUw(-~Rn?Vp-R#R`HnXۄ#ihézV\ }5=a84XVw ͢M^q :8u7F:PC5 U> my1$^ЏwQ4oPc2[Z`Qۜh/_t1W"4k [-Khʀf-%3t('r`|5ㇵ@5T֧D3ٲM$ bĮ_iLYUXZ[ߖ>C#_V,l4~97VUĒ(3Bw[t^N}!(9ϞwpOf:PQϏ]$G.:kOY[<[{9JY :!nj=܆*ko_}GP=&t; |?`}W4{Z"ְVt,)A&ku(4uZ_<r6'8oIx85C#ac( o딗87ͤVgmLJ[T:j0e\-dfz 6.ՙnʄ`A,0 2rr!Fi ]Mo~&`2l_B|48|Ue 0'z=ۍX2BR4Ep73ݐgM=sb>N^8thQFM%#WLgcO^[g @QN }0\Z 2:` xOSVͣΫLY ` EhR:pIg( &M|hy95*#/Ǫ%lmEVT$zEޜsqp4#1|W<ER{;˴2GjfEm1tmx 2X2|D #}Ҹ u-v<R:[>JT]ZG!p99k:-<&|F`9e1!"7)3։|\̹6 /R  _8Q3z  Cjץ*J.0"[gF0Ϯ8XKĪFZ ZcoC zΈ Iŭ|}2 uV;0 n'A:¶[t[ 9.G78 })؍jJ^+0t+GˎxiXQׂՙI:^)`L;P0-KjӨg+)Me*1 v7:m\9 \# İ'zI!pW@jrԪ,N3=Z ! wf rDc5X;HYW[V$d>pLq|\8K͓%Uטn[=uXt=׵p'LJIx]xoiپCJĸIFvZ%Ťo3E4brhUXlbwHٜӰ.\O63m'r0gK[,UV?b&A a;d,EPJlY*gZi|K)e,{Y#~cW/Ҍ˔ E*hH-o`խeO{6/E.g$@!мَd4a}b,mӧ,3{rHw"O/4ƈh%SN$L[!lʗuݧ$#Ү4>qŊpоx*=.\+/b r7uç\XJ@dz hz־o:p"\&c;>{H6м7,Ѧ(Q,tRF`QW_ wj̲ c{U~j8Yd6 es8A=hЪ/{X$43c,쯓MOI7T7^t" MLBW*؄/2N,+# :x<{n,_D{Z{%ZeAgt$EbJ'W5 XLdzq+J o[TwCKNR+cMipX\SLQ=.C$N_K"a95˩;-eqU7_m@;rTQ݁]D{+A 5cܾ?+[FysUj(N =hSvvT $BiӭREԭ9Ҋ'G|?O2Gxt %,54$%=H}.X%}bj}Оǫ -e_~0k oT 1 9B\Vs0ǖ.+=g`Pf;֧cɱ.%KEh껸!t&sbD*"wlϤUHywlgw>u؛7e3~N M%'}OFazyΈ+6 z,X5ƻB87Xi8[lc!P%b\l\`I C\7.'1oJ-z\ ʗ%*bSwĵ|"Gh`9ISǠfD nW1}P՞߫ޡGEL{5|B]fᯟu$Qb'։yp3]O10wZ?cHe=:&ƥ m'oQswlG'g̘bW0(f})$"7gb8]CV^ZP~&.qkgſ8CyF}W,w_GǤ=b}(1!D mB^pĎ3(CP0{AcQwc~-sݏ`9x^KH]%rz"UL" {'wԌF0Ψ1Y6\fAPY9 7ܬɹYU$t|JtTKaIJw&;s#ϙ~͹U \F2qleh?,^9?lK&qٮ ^^=D󣩧tj^bH+/F&%CTPh,x[*ȾQJpeŐ?8˰*jƺ|J<#w(aA6cC{]i#EuFXUN!) x>1ؔv3m" i,aˇ!{FǘjC`G Ia/ӯe@,pY2^VJ5Pu;1<[a.ӌhH -b ))5Ǔ H b?W{{{2Q.Jn'(=p(&r% \c$=D.24>aEf-/AKͥBy<"BO{x%*;|2ajZ ?<"M_Wѝ+<ѺoHh`[ŅיǺJΙ_WXΙ7 * &^RO[Au@vZS@!|EA/kdz%c)"E8HM/Z_O>T\K r"6iUKGIu4 ;ҲC~(5Zђ`ia,|ѝK\e|G ~=y|t7*!iVƀӯCXaXbRjt2W_(A<l)=muQ)2Iܨ!WZumy{\ءte[y4FI8k*/:כ+h.[i:80vrX#v[ZϚS#]}Z_2Ja0MJBtnٚelp}@r5j$ꦺ[d* ٩sR"7n U쵪"Y0lנ, ;P/LR,Ěʩz4)ݳ]~+'`WpS(ō3jJaelX F=oLm)^md|v*M a+֡ ݤ_uVj^ܝS8߈ OlPitz$J1HgSh1CvF5,{>; 9*%ʴ5eL"tagb%CLWG1 Gv,qEh 78eTo̰(l$k_jè ΤPg;z 05غ@\beQڸdaAddX#I'P}UD y_f7F\n˶a?hÇ)0%F '!u ꒌ5t}ߋ>3j4 gX xJ˙ɫ13#m`3ڛy7ã".zDe_˟؎F"w=!醾SEZEWA/uu۵2x < |;#TD/EXd zU(2-jYDG!Pe\igA?* `\p:?ѿ ;O[wyLkᱫ $8m}ooaգk1 TH_yf3gE){FAQtRHJArœ6륙)" MFe\OGqHDICQ}fp$[c$6_C0Q+WGDJPJ~<[~ac!ir)$ī4Tjs)7bv`rz>V3ț\$^4_ɞlSu{?0W-?L>V.gO; pyf%+6.@hKg|7N VP%?w{-Pn6*ob1Ja!" srF*uI* Sh(abs~&H[6nnydx8'J EFR3OiRG"] Al:RKRq\mLRǜ.pT/OZB-F,ۼG!D=hF~k%w}0K82uWš 85cf #,,xg|2\H.֢ W<=XTZVs<\~7 My [ӻ2\Mfvdݐ{tcD .gqل*3*F 8F )x-6Vnſ%@RޤS"S R8Gqyh,41jBM wuѹoy7$'|BN'K3cB t|%=c=n r(&*gad$s9dKn n&NeE벐!)tuA`XcG&h[qI' ̓pݑdu_ia\goܺPkMҶWk߁F۴3K,pVZ ;7n`&$a ϔ]zi=o期04kLg6%!y/vR4t(0rR&el >gy+cj^󮶓+ v XѸصhYs$zF]wWi=^7Dgqn㹔CYW]&BlœLlaR2o5[.q/⭼^0vu;j']J0k^A.f=d,`Mkɠv9޿DI|))6cn5G&:$[Y^>nu90{3KilPouMyr-uYDJZXh:̀"Y[^(=R~JOغps Kɭ/eCN W%pΒXz=;{ *IIY&ˡl xkXJ&U]P!3:ig".IQ=ܑ޴ H@0ܗSFAke+>lWYg綟F5~Uqe͘F6E5BBI'jR |fTԿ7je;}_`+5_@R{bG+ [8H'O%' ]^mEqtS%!&)mOc嗀R'9&ڗ;>:Gt=IJp{dbe:9h^2c%WO ht@o&ypj 2X2sI3<ž$:h\(2C1̻AP(DRD<ߚꅳ/gfyP5Β~֒80\seUIZދ#-V'hI >@6 R4%Jpc`b(=+E?I+Rp/ZOU!SN-їj8aܝakZFڞ(Xbh x "4$!7&}.o}пЈwxj J>7J vvMEmS20Ol 4ڑ Z7 L 3& YDtAl.C)Wl16v+ ;3{nwU8EtvQX޾!Sq=Yۄ͸Ǔ5ó!u>:TI: sI;)F@_:xN j']IIA+P+"ޯ6S&NJ̇=;ҽkJ*Qrś?-\uiB5SQi@`^*vB̒-7td>TP֤41I|]Q c @K-:N.5&d@fT%+!px n7UPXngޯ$b:4}/G#-֜zF>țNT*?lM$Sr 09e}}D h8 :awjϼ_wNcu]Cz!; ~h d T .?wRYApX" vKVZ"\CFvs`R4;bWcRnD/v9?!0In --Mk Ph5| Raqq1yKWWnj%gj C+Hju R( ";ǒ!gQ_WˎϴGz.m8`NY35LdZ|5h\Uڳ.z_ĭ(w`]q5+ꑗKԅh@;v'Ie}G.1XW,1QON/"GH\3R;b~MaKspr0S,n9_Jʃʿc ')N.\oH4 5կO Hq] +JXu >"Rn揋B<#-Vv4Iqi/z^(,Aمh?/Sa6u =[_bsa|iቁ6UE/(Bܱ*,b6*dB%|-W"O :T)-{6,ˑ?/ _~}ެyZPa =#Sеڡz7Iؑ)4E{7в'Le׉Y|!ӡsn,؁3M # 331>Yۮ&JP]rs-=[>ܰ`C^! <$>AVz֙ɥ0L^u@hK1:hPf"LA(ā+2{ U{8cb;a2Ap x&M$ĎԄ{|eiEQLST/I|`M鉉Z*S}vl:!Xsą<4kJ{N03co%"k{rxZoƉ瘈Ze6+f+pTC$3T8OҞJ54wjNQYicO W]nC~.Z>pnw5WaB#i@ _:*h#)nzL7dFs[(4Ps.;R# kɲ΍B$wCO5(=?kkNPI}/]C@"gpi9 {7?$wwcpJyQ'B5a~WT\I4!zg{k {EgjZ[`:ON0#[Y@hFk ʞ$XBGS 6w$lcJy$rJfv %0*49pkdzzF֨t$?vr]G|l,i7'!5\NEujsxorl~/k8# 9fIl]<^jG% l8h? :LMUlC(0"g)mq/¼ G`'y_UI8EzI `~; ImEUà҉'6+S6rg2^ @Ul):6xBVr\>n /R!;J<_]=f%v 5LH[b>Y ǟƱЁƙr]T*S@cj!Ol+&?QUàuAgVp̑xm@ V#qi1Ҥ'ȡ\k[&\g9f~x3aDا^?b'YHOd3\7|k9&G-_06ԩ[/KJ0y5[ >Y@ Mi| Ƴ]5tWf @*2䬼^Cc2o3%w ƢvvNyx+7jfį+XA!m&syUb+ev::s]U3^JTD1=J} F(Q>]D)`*YΉ} x/O{8A]h1D=k!pTvD;Ihr*y"zn&N@sv/7\ 2¹fh_o7Y8ש.{gԪ^q-$+W+GH B}խHf!N'QBV,, ^'mG [ӹu wf,> ;\@ oFX2WTlAx(=}JBQ+jL0ZD䠓{qOZ,IuY# ǥgLEHqwpLTܿ v3b0TѼhA!̖0zP[QtG/[pUtduѱ~,S$חvWġ- kM+*KX9;=urHW5˺jķ9{&^}EC !$cjIC]a_o-Db+(H/unBQ͝DN;&Hlt\z!-+J0z8h@Q|E(2\lDG1|#Y,\^Y,$|o{$[X9^FLUU##a H:6$bW4r$(Oqge ]/E,6J~ۼu*-h󇽰n&`Dph#ЅU}+xSPy~5hy=>E'0^70'B80C7֧s¥}e߄s9 2D 99V%)pC*k|8 ΄F; }P}/c݅2>(HX }4qm: qD@Xe(ͨod]>pOG17Ә'}wLiNfvAtk}AfOvSn*2L>+~"oawß|^\b1…I @ٕ^ر8>`x|(pmmz)-{@ ai [~K Q'#s)?YRtRv0z60&6/oMc>XqpVU2 Х* j8V)YSH'{CQ¿^S+q>fZ])g!.|(sd%zܾ|&vڒvSO|GN5\He `Y6+3qhf=P/oZ}5uNu;Ҝ?Mf\ N#T5kpG7~0 Ä[I ?Z9]Lduo)*d{-bI3Y%U xW{]+[ @~QhqydlAr >x`o&{:CD?^6>Jyo rzgs) " a]0VIn<dV @/S0{FM/ σM lX+%CC!wc =HNr/ Zy2N0P҂p0+u5?/ţlYȾ{ZR ~6NxZ' t!s-w$htv`s ̌5?"ųP XFT`Pbf DH·qWVc䟀"{fOá:7$N>ǽSiȉtEd!`a{!V~Fk>aiQvQR[E:["Pk_ bh|tU F- D11,E{Mp8,)ѥL@-m rFھ5H2פLbyn8cIn t8wLҦǾ)S!XT?G#°j*cMS=K!C}G|t2ԟ9zttODҍf$qyHrL&&xxO-GShohaw&s/h&Ӥ\(;w7r%2Pؿ*0D]MsR•,$S>6^sBjǮ/# +iY<&ԭGlv} QGN_- AiE01Hx^K/643'fHKu6w2.{W cJU35"؃/ 4D;Az%&lZ2E[b{_0ZYU- jPLK]aHi`u4=k?GU꒜1h3?E;* oS?[%|_.GJmU: ,zM( W _(9͎ړא6I bam8yU"zAv;ZI0qla߾`jh9G.NprL2*"r 鬡.!PK,uVcJh(DHkJ/;B Y^$=9`O/@Wf$h\*b =8l[ᜉJ: ɷVVWwGLlxQdΊ$/~ZnW,odd :P)MI @rq0:{@o0-/hu>\H ulꈙ3q#y4L㿇T*qxƶ-O:NtY{EG1rv|w+^|*![O1ӳof7M#ʉ3Kd#ATEҫcֹ]gohd}|Cr֓8एWU)AR4M[zlsd(bfS OCP1k(&؜٤8HނZ|d]yz?L8Psz|a x  /svFH_{ Xx\6&)8>jv~4)iƱC˗4(U]0ї5;5:J\`p,%rqwld3+9#24&{LڣAw1@!Lmřόum[Ȳ8`~qE'qafΆnGZēt}}g(($)FrP;X@U2svNǢbv](7L`߇PY[@5'5voN$O볣Л襚io[&*JZ33Mf/C 6SjE X LMrRY2R+zXnE_f֨SCd EnuĬoͱXcka0_&׍ ;a!%T΀MqϊF2yY4n={L^" ~I 1Nu;FYv g'49|@c(&RߪāU޺'q=Վ5nʧmreS(_ّQH_^Gύv-Y."٭X+q1iܔlxr ߉2}\T4wbsLž A{ ן6 k?%So q^ѦqPvOA]6+WE kJFVȇ \MȆ^NqL3xR9v[zR1UK[Q.䒽ZP{H߆s;~P@~' e-%o4DOj/iҫɊIgRy4#2\* )/d}OZ]I<#NK{6(7X$E m&^ &mۗ)qHb!D?Z[42/'X!G4H>|(6)dRb;|2}ېCU/gO>{oEƲ|x_w\_Z襮FH4<8P1$| tbEֵvh[/u1 4rFQ_e_kRvu͋GZLGh^L޾UtvQ ߴ~ 8l[־>?=/ŹhVOpdyۙn5EwUJPg*\ri MB6 >osx*ݏ$pKnVb&(AH²*Hؤ9I$ ֧o\(6 =;9p  cq۲{܀C3*UmkDQ(""'|]'+>5H蘶 ttuP+ѕ_\>hbaJqE(]f38K@>?9$ PoQU1o`Y8Mm6}^#&9Ѫiǐܟl2VM4(;&yt.gG6{Ea&9|R_U?"~a/3U&$CQ.%U[aWL@Kstpx) utT HmAbiij譵bF$E MDKXҠF{t #SVS>g91ʗXg6:EVMX&/~.͙)!9t퍖+[%,7м % v( ͸#nj& ,غaBGA?̊OHÓك ƢE71>'81ۼk[XjLʯwj} r0PˤY}ʚyG.!vq=} i+UxD4}{:s]HE'b(ɾO'$Hv֞M|b^4`sx#uvru<z呬JoPĀi"UJTaj/uod{V]7u`0zb*$C6l۬D, ;yh)Q #MY䵘C%NTby<(NvVVG&2<v9ϚS'HAU"n(TCoUt kҖC4!P^wOE:-I$V#* 4Yl:l>f04vX|lo33a-OhH ݚFqD0fܞR #蜌nUo/İrkdL4vȟF#$,~NE)|?%Ļ_?OUHDТQ^EWK[Ͻ:cXVd ojt`Ǣ"p8[10l/ŽprGnH()mc H&XC bc+,ҤKQQGۑT&ԗV=2 's|ՃJ>EwhJ|*~u͉;@HO2pAu8`xP3Pl4XoA@IEΘ-c="hQ.B"̛ ]_=^`\;]eHqԪ=e14&RWK=:#xF*sRV4nJҜ-x2-5FknSX;j&]} ԹqB */>Y#T:`]y̏5) )ZA#xcFk!8vŋ$@s'\ys%0iޏ|Qۦ$eذ W?Zݲ/mq@<vRA0bjSFϪ ͡>71І3dWrh+su^'Yo!2ΪmcMsKx[ܣN0RP[ZMg &b @RF#mб.&u N[3X%!yfP5:gl##%D,kdO'C峴c?)]!R@ K( ķ⁏gʲrzx!*)o.el/X &,coHplbd d )9I_nsAJS<e:rPl릀TEaD]~{HkuhX _?:mƿĎ@O9/#Y0CHxVw ʃN쐈_[UҰ>b"RF  ]p[s_ZV j+8+9IҏϙzV h5-|tۃvŬQ"D[M/kI)<aM 1aG^{9Pu ]˜J,Y<\̬G-$)YCNfZnDb)4: -̩եx (~] ]p5ӱ^cPNsmds:vƠOv} 8`C=K+JZ{c_XDdP}QR"`sĖe?!&x蹉cFL3b66/ WT]z9Zx UufKHOB&a=EeT=jQL-Ȏ0scE O#+>8%>׭_a^'$k (HP'2B3C KE4ʣEZ!+NT&NFrȖN#哏;7u U]X?4ĸ%/ILsz'ZlRZvnlE/\ } BopLXE)PG\`چ΁\dnXu!(5|[m"B*§~S*ҮBI#S0 ˷H]_0T$kgb4$FSli %]f&fFM>Q2nTQ?u6Ff[ {L2OϫtfpO~ƱAtAI-VVf9SV`":d?HIDȋRv"'~͕\' &Mԯ6_z `?^%@i%L,S0q)1bGvK'!19K]FYp`J:iZIUC.3se:>RT)k?`ngPj|R6 ^౅hĭi|ku~ c[ABYd $.ͅ(&"IU2` =h$]ğ]ˉf7%U6lՍX0t8k+OM(>Ʊ( G]'2S!.z?)}ԁ}vrҹѼbqK*1XN Z۷ |J QZ6(Xl+a9 ijFΕIUE}"ӊQ+|6,{ vl]sv0Ԝ WI <.O|scʼ2/8"SHr7\T~E0Inb$[QsWkGz!lJ=7#s,ʖǑ97qbg?ba7 =O(x֜E(;M+6)ZudL_I7Qo iW1j@6q o>T&Ƿä4D+X r4H4"9˰d6u0ߵ='t$hfp~B=1~ngb5 +CaGV!^& wԘyl(@>184j Q Wit'4_B I[9g+Nl~{5. *d7lwR!z뱶;  '|0S~؋Ǟ^yx{;>sO h9yώ9?DYܻX0{J;GakFL]%1@eȦX=v#'\y%Vu bSԇ !nl[oyfWe݂Cg3߂o!S6&P0 o%kӫ~3&DB5jcC?$] Gd.u+(j6h|IC5_nGOAfosUT4t0e8eD!Sՙ]NhKĈw$@s!V8I#F.=i"(yϪ7u.p.o9(@,`VI8Y^t)/&JL$60*WRA?loBcNϑh*M\Z"2k]J@6;!({gԣ!_/MY"25qs pCOW)OvSdwk@כ:L"˵0SG#9 b߽Nb_e̽hx-oÀ7H8a*єY,3ц)>6 ~ !5Խ)93ou|=0}B{6>l^;} {|~'0L6kz`KMVGo}?lj[qHkWQ9c)}0D|b oh*Cȕ nQb{ՙrr73;9<0" |ԿFףğP\g@IVw#i^ڞM|,Ck;ByT6tl鐺 "݈zy]^66ZMkZEBJ."@#ghYR7~=_/ƛF5o>|x3𶽗Qdh"v;XBg_XNح;qs!BmdҘAgc獗\joS@`V }_d,Ha|tԑhjD0ɫa8tH4bIFYP\6J ۹}y47 p%,'$ZSGJprP`}0@%j#bEy|Rg# {lq0|mK:8M LtSh'(XfmXB*“`v&GmNvEyF[`H`d7y R >=UЋSW^yӐ9/_A]yq< M׌p#R\tM$囆Oۑx;l9.o[jOxm:E"[b U6]4rhHysXo_[Üx؝YLvVE3B i,y8ZHTp JV70'÷z` #l>詣;L-^Q$;ֿV1xEi(;**ܐoծX!ܜ\rrՍ'nq5q,ڪiqxY%)( |5AW/,ҾU7  O:ʓ>\#'xNYKNYpvMOpGtҎfgbd9"#5Z4;R+ŶI3|0OA8-ƥƯ*r-%89iMH'a L;I>Bo `5OjcWGWW&mhFZaQ tO aD!5ߕN?H1h~6q/zQ:>gn^Q-`Wbx~ rj/׵5e9W.7pV$dWthc?![Zi)m'w OJ[,bF^%cG%RSJ)S}t]k+|ሩ 2U `ͻu~|ݤo9yMxNSRYs=czvqq_XlaD~iLCb@{z3@p+>pN!|[e%W1DP!VA8q bD`B:^<|ku3;%e="em?/280R}X;-=2n6ஃ?ѕ4 Wٺn G"<K|nz)[BE5;XI VREԲWxyϿnIa'RA lVl5{$[*!|f|E/V=ң)a7{9 PK d ӕն@q\oeʁf_͖ Sԥ?^Z<=IU&@n?Xq{O#,z!0{D(M ^)I"ᰒ}xE(-H\=EY]^llzXeuS tb>1Q7qv?6EX԰,b]1CgvѴe *BE1yjGuՌy,Oipb:q%cCJBpcDcg6ͩjfZ ,ƣnaP?"`p}4GYGxTA kFF[qf4N ,4e3gt;ʂ@xxO'YNHM7N)ߐ2$nJtW\ˮ 2>Z r`zaJS9Y'4N}C'/mqyv8Bx̫>]^A_;ˏ~PK55#mk-Vk3߫C99NS?W,]i y_&Ke;#ΉQid+foqw7_ۖ@/~sE^r9q20n%xOXtS΅(OZTUm:NI.H ٍ#jݐ^(\Va||GVJ 0Rg(eLXkIIr)/^>x9~j{8ei6!'@*¥r0~X`*:G}4wzlE~>ŋ7ڕ yUfG"01޴ F,I^8b}$cL56>zKc|¯U>qn\̄Pe%᱅0A}AnhVZidKqztd1d3I{héNKn.PX !`[(8,]~6RMn9ԮG7=IA.̠}^趀 N|ڗC[?xpC\cđ[Hx0fvኻ64HI;X$4j2+lvz@ / Lp0N9, )t4<^+ ؁2oMI1b@g E$;1{3wn"78;xn1B34edr\1Shl]\M:S]@reK|qA=i:i=**U!zn54`Cb˭u{˟?sdMܞۦ񱬩^ JCfPk mٔ$3L.xߒݼ>jch"Ju=<_Gy9U.1m{F&C(7iq?6MS|ᗱ%hkQT~5IW>$rߊ7E+!РKʷ>տ|3^ ݽYP$lcpz廉b)C(9Pe#n_;ŖOUƏٺCCSep`\Oн@JNW,`p`_]\*8M U-Z`m+MliUZ/T%j*To1?til$X AɊI|0j2c1"&}$NHFfye]0>kbi@Q#~9ߣ䮐IQ#nGt.IZEdQ੪7fdQM}4/f$"I^Uj'64(L{䥶+$ց]Li1(o{MMU  xIإokXhTkuA$t <ݜ\JuP7H4U[PFݯji֬XL>JsI5>h" FaA.c^\ NC3cq f!ߠk50IuRZЃ*b {mE|RdѫyWAX%vE[_A$zK"qE5 )Gt}d1e}nLy^i5&n]Kf`$u4DG7r#4@MƝ), ǀ)5䝤<&H=1ziX7Q9ךKTO42<],T*ʶYEA]iJIT BNƚy::xf8$L6@ikn.骑 2p 2#:79lDq{`d \V7N,uĉļ**</FbDb dSz*{ x]5*od(}ܑn!(SXihAV94`2DCR#B|)db1f*tF ̯Z&Ď`,HLK/d_ i\B[G Z݈،#Mek\/y&lZݙN-)W0Qfʟ XȢϯ<E_;dKT+;{[o$+h}}'4l/mE,=ga \&}X+l$Dc\lFmxqY![ᎤN`af ώVS.@fcZNJJ=}dSNJ͸~y%C(;UyB8 c:`rucqceP*F \ {>[mUBpf,tj=MA>FϝbHᛜ V+2bh^qC/E6mDg()Fɟ{ڃF+ wnn2,սsxKӤ<Cðk!yݙ&cTL=:dh>'gd|/?qj䒾$ 4( 0Uo[3 nS҂r8!dkʦmDC|RĩhO#NhX&p(|_LPe&-Űc3tr{v>x2 unM4_}Kۃ_ߤvV2b.e^k+`{W#8&Z$F-_Xo86g ~&C^32r*(}&Tg069 05 #S@rfB}*v9r+FD.L{#od;{!tjPdh!ᢻmIonxוb%)TLϽ7_|ù PH" 3Dc*)#Fv /-+lh~9)B;'|5X !u+喝t; a0RspD[3 a}в)Ѣ?X݉G?C~?!'HU] xX<X㸡u!Lz~hhWz-t^It$_X!e)؆8X sdR{z{stx/ܓ n(Lԟ<տL*0ܫt81y*Jo+9͡mlV䫘fEi> ІN"1Yǒ-.nH0q^ǧЈvh)"=C1W h0yv9wQo }k,t<@^1;G M_D]KOo;9G c{-\}0Ph>3kv*EdW94uv4 u.54x#6MO!vs@ڿ h`%;tjшsbIS{&aƋ:tJ#f-ˌ&,YM9vgkmϙ UZ|M@H*¼br$ZȘr7nO"Zr2*us C R7֬K8N!\E5Eo@%tUT8r ѡ(Da<$\qgUB86]QE(;O +;I<Ow؂3;F \9 PS5R,^CunpP\هkB?'كK\*0^$R,#w'j=8%֖!e<$`XV*%]nH_֞`U1mCζ5i>L ^" |(5BUaB^k"V0šPjPP I͈ ZT:)@n%/{PP{I-n '&:ۄݐŝ~9`?4ұ&;hCK_k6wto&rrK)+GC56(..!,zp:59ơQƺhmk>M +@%`b?>)?y4 #eI]ӱ jeSa%}Z[,7aV!PǸУD6qh+&MPK}