samba-devel-4.15.4+git.324.8332acf1a63-150300.3.25.3 >  A a.p9|&^k{[.w1|,[V6EPS1Z>brAJ"`7|:+ɮs~]NCy(`.ĹvjEaEڲnQH{V <W0+Ϣ~9[=D86 2|m_ 8u a ^hfDW2_^Q\(PmeOIz09ا똬 >- !l!WWx76f53c8004ef7b3ea2ab05d88b1b613f503fa4d9b22482e9acca4571ee65c8a43b621d0d21aba5ba8676e6a36634c5341b183db2|a.p9|],1S(sk`eo Zh#n~.Gª:fQ|6y OWJДx N C.ԫ'+=ҲMS7o2GDt+B}=S'e\L#!giLŲMT,3&b_ qn>_JØeVfI*Tj.Vi}xl'xfslcC&=NY{_$ HfF WR 0.uǤ>pAF ?Fd) 7 e/ Ee|    ! #&(+B+|-$0d01(28295:EB&F(PG(dH*xI,X-$Y-$Z0h[0\2]4^;h b<c=Pd=e=f=l=u=v@w@xByE,zEEEEF Csamba-devel4.15.4+git.324.8332acf1a63150300.3.25.3Development files shared by Samba subpackagesThis package contains the libraries and header files needed to develop programs which make use of Samba.a,s390zl31w|SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxs390x( p=A@!1N  aF ENTv |H)KU +d`@t2!CY~W +g > v&HI!>,'I:l h^ Z=1y<u .Y3T4&{66)w*'A,;BG]AA큤A큤A큤A큤A큤A큤A큤A큤a+a+1a)Ra+1a)Sa)Sa)Sa)Sa)Sa)Sa)Sa)Ra)Ra)Ra)Sa)Sa+1a)Sa)Ra)Ra)Ra)Ra)Ra)Ra)Sa)Sa)Sa)Ra)Ra)Ra)Ra)Sa)Sa)Ra)Ra)Sa)Sa)Ra)Ra)Ra)Ra)Sa)Ra)Sa)Sa)Sa+1a)Sa)Ra)Ra)Ra)Ra)Sa)Sa)Sa)Ra)Sa)Sa+1a)Ra)Ra)Ra)Sa)Sa)Sa)Sa)Ra)Ra)Ra+1a)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra)Ra+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a);a);a);a);a);a);a);a);a);a):a);a);a);a);a*57f48e6acfed5fa9841df0f458c77820b6e24ed8279bb23819c0698df22bbbf19a87ebf5c3ecf098bad8fdc2e0c08317efd3ecd4947169677feb755c5f86b325aa97c3dc8a6da5e8d196a73bfb4bae250089de7237665a3a6dcf5512c71503695cd7da44b981f9782081d3d97dc2d2f26726208f56b10bceaaae6e1a3b497bfefa19c5bf4838b4013a16d205238e5fa9819e04902a006a08044a0da795cbaf34f53c103d9d508de1883fac4df0fff12ac27300409f3a1c8edaf31c05c054340a1dc2974d9c574811447befbe13fc0f8b3d8906fa58ca173857f5b73359ec30f161766db604986021c872a81bc3e6dc403b8960c06edad4595f168293005943b8486186e935623059f05839ab0f3604f56687ceab73bf9ad6070e58a7161041e32e3a21a55901cc3c7a46d6560c167ecef63390fb04b124e508eccf8156fd650dbd572ab4954abffbeef5c35b30e8c5806501278b70a08d6041d8a5685a69cd650f6b2cc28882505519a1655568b836ed84cd84f2c426df2c68a5388066d19fab66156e28d7375c095735fe583c41fe10f68711a286dd7616111bd0ba9a6c39eca72b30f0da89b141671dac7d0b96636639545a74f12fbbcc745e7e2597d71b4ca45c2bb309dfe1684a8fc4212447a00f588e6fb067632fcb30eaf8ed39ec802cd7d6caed90f3ed522fb13effd5b3f9ce1d10f57b87a233f8b1cb8bb000a06b812e45f1d76df8d2fe7405deea4c26e6e1ccf3951c59a55836952be0923e7928b343892fe61c87666774dd2e18e31d70da33b45c5986aa1c23a6a853a6cecc906960aa488b92850596697a2ce4811cd350af7aec0b5278c15b3700ff5759a3a9ac8a09b87e376224e944e12a2067e9fc485ece8ebfbc7d5cf0bf573e0500c5bf24c38a14ecb5e00e24e7947b8517b8f39a652b5a4a7cc6ed2dd04dbc35210090e571af576c5ac08f897ec08b3d0d2d5d40952aa94d082f5550483c051b99b33ee65aad7a50a60ccf805be82f6209c702e0e7f73a5ae774d0c68b57b28dd1821c1ab067bcc678b898c16d290afc34539c478fc1f6b47270a45b389de9fb9ec0042b98e789e2e76a17d01c1684441f27e27f5c54d7d8d1607fb9cede012344438922ffecaceea8800ef2175f1046485790f995229035a56992eb9f80f586460519b697827df8285c4ebf06595b743e148919677ae2a40442c80549d7aba0bc0b696ca55cc095723a52645cf7513c55934096218760deb28a607b5e85f82db7c1ab580e91df20133ceaa62399bfcfa07ae216642332bf119c5a28639f3e6841dd74e2dd515f2b48efd9117bd5054262dfd09a3617405695236094798559211d988a68effc888123ae63e8d2ba5b96004c14b3356dbf490b4e731cfc7a56467079075b6004265e32c0338f01e95f47cda607f72abd98a2031f32f45a1470dec6e13f4c8e17e93041953c7a33ac4dadb193dc843bf0dc47196230f74fc5a9c4ac1989654849afcccbc35c0a397ed9b8ec9579d7a3539a11d9a1f4db4d40dfdf2846bc81f966b17d69a728af436e405c6653b76b8b1b0cea1ff3094b88f184043efdeaaef078ca39f9c1b6ffd2a287d8380c0ea5cf53ceb43040bca0c4f8a37c75c1cfd40923c16ebfe2ac820e071af1cba5cae4b019dc46eb22b6fc37174d15ac7b72c723c10d44a520b2054944d0606d29c16714a4196910a433f607fed4e35d63918562c260077a6a23b99eb7ea40a5e790a7d97b17c8adc0fe8152598db810a35a439e0fd2184591f449c79b6bc5b5468443920523ea943440534df04294b940ce1c00c0a68cab9a5eee13b0a18e6e5b9d87693f25c1f804ac1878bf03800367d25438369395e7f2006fb647db68043d1590be759478e33b123ff9a54bbcf1dd70a038467eb6dd4dee91c9309efa27bed7b9d371cc936612a2998c16e815dca6ab2131a2f005b7837ddaceb2598db386c1d34c1a777baf0d741ea2d153c399b4b0fa22367ee1921737df26ec3e9fea81c7f525ee4076db13008901c9ca9f404a6db835aabe1a026f6f3e5c05cd08a28a339b762c6189d4af93a1b6a87f9d9483d5833fd883506b51ecca8ad6df0baceb27177fb6499a7918703b897a45cdc7605a9ec9315a0f82f2518db30b753b0d4ca10b18a94c382f3ec70dcc443437b2dc9e3ce610ac30bfc17aba981efd38215a457355b1f19ee2e93d26cfc3f6127d4e633b3d89ae70e214c6869f39c6eba1bd4d835c031b67bc5c4f908e60816711e8d87e6d93f84fea1eb1df4a7c2bb8a671480afe65f9dc7f671e0e15cd8eea8e37927520f3ac8ae6b63fe8f7aea81f7680951eec3ab67f4383db52789c38b254cd5a9e4766b17aab8a99813258ebb4b147bf98c9f0b9ac8e9e07ad86cc4811fd17c0ca05ad6fa67befb082b2cd23859d7002fa75a5794f15fad8157402985d19cdd5ac6d637eaff4935f5757c5c0e0ce41faaef178317d28f9d4c1078baea27f685ea30c1acf956f394afcde8741c7d3eb9c1f0d24e77ba69ff7eee8ba90786ffa6c5f4ec183f16ec4fc964c65b35a84e0be1b1f830b8494c8e895196ab132fd82e055cc808ec43d0bf84e5bcc059302e71c0e23a257f197463a9ecad24f59aa597f875a287795dbd2ce8b56438e84f9976bb4b587c364e2b03cea9ac7bfe92f670c4d88fc1b382789f66d991a6e526f4093a1972e1391aadde980420a1dec670f3549f87169c890fba90086de0d8498f0fb36921439a3568cd3a29c34bc8fd9c25772cff89b4edcc989ff5af4189ef2e0ce0e37872c17ad0196c4101f1dab6f2233d4987af03f7dbbfcad01f857b4576ffbb67ed2f4c6cbd9f0a9cd2192a7cd36f8201ae7dc5c1bb59244752a7c96d0bcd9f3e3ad075aecf96bc9006c8087a428c2cbf46832f58f5a9a8a1269d77685a6ea46e21b05e9d22e79fff5ff59e2f6fd5ef76604c85c807b4e3fc0dd84beacab1ff25be2672650e35fc5a2a04de281d9dc535f9718a0c12832630ba0008a46bdb263c2610acfbf6da60c6d585687581e877d06ac2587e1c560a57a924744d428603f832aa43148df878f81961c305f367353717bda17d2ab1d3df620a04711fd5a61149d16c19f34a48740662395d01a17ad400b8e6af775cd8eeeec7fa786bd0c1c686c5562fc60c40b7f0fb213627e0208eaa36a7262e7680bfdf38ab43a302de7a5ee1b18fb5e5a69c693660e5ab407d1696c7b4ac8f6ed075a178fc967e2e68e1bac448bf37478948a1f40401d26eab750f4c70faa63142713b1ca959bdea59f5c83e1d20b52792246b46127464459c635949c3f779518d0e830d9f34a33bef4b8d49477a4a648a2d279c88584caef10d814fafc233b2ed62e1b088b7b99fc6b8017b38dd73cf8dc94a4e97837ae5a7631da503521a5133a57f0445a4dfa2427eeb926d7ece4119a01cd20ba4acec5db90984ce61844ebfb044780a402cb880b08cb0e3b6d709b17117204b5ce3a21b987f0c33c9147e5197c8e52257325852c5c181908a3f4082b5520d1cf8599ee8c5ca7e8584f8e6deb53c1682692aec09dc7339df4507a69a44fc4e889663a695d0e42c4ca1819bd7e814f21ea857ca7a1cf61daa69affa14cb497273b24b2f9adc344da28391ae7e27ea058e1909f8fd85bf9eb7fedcd7dde1fddb48b6600c8b61eccc6409a5a5391dfba7e45844c4f2da58e90d275e42aac178717449816161fe77e2af95aff8ff703003f5691ae2280c0809d15386619c3aaf0620e8697c3c0d494cf0d6a2fbbde841699930bd1f5d8c43118be577f601d6cc6d9ea72bd4e42802e6c88a077f61719410d22181cc4c3581879bb270b0b5a5b091cb6c1c88f28237efbcdeb9e6a60200453b33138523a09c77c8487001cbc5e0209ae5da609663717c956f9a10aa3bcfaadbe145f7723177bebe2a8119752430aecb7121eecb4e1998b5a24b456197855a143c84f2ecaf31540b1f5457c0a2fdbfd8f53f9b9b119b1918376d12eef6aa5248f7ac7d7deb71f336a52fac364750774f797c061e915eb24775ae28d1738bd86f5a5b902862b25dabfc4618da50b85e66272bf52218a6cd2e26338d04c25404fc53d6b230205d0351470ccd8809d4ec02d86007929edab0432c4386098ef7d1c09bdd8cbd6e9b0ff02a77cf2d3de460ded50b04f15ae58b86ce48bba579542df1b00f69e97fe1427fb1031f6930e7c3b058c09850bc72e8361579d8f0b97ce6c33df91db1edab5412d88550bfe89e5d34a73e8be26c6cd20a922ff73294bacfd6ab37123f9f6304ac62b5f3f2c020b7cf90ed8279bb84b70e146d0a47d12743138659271122b65de007d76a54634fb3fa657a0e6c8a3cd600d4be43800c4a74bb5e41f57bbf05d01629d0cd9856ca1c5cd05b52579c70d58b6328de9543dba02672487939e41e910f508c1dbb0923f0726dafc2b4fac411ed2b40275fe0fec3322730f62b84daf91fb23bbb081489863168493d1d893df191dd1a0597fa2bc7c08eeb7f3e7aebc136e2d47f375bc7a94c423e7e20324cc193338e9d1afa0af1fa720cb58bf48039d5552499487ab088928ce1be817libdcerpc-binding.so.0.0.1libdcerpc-samr.so.0.0.1libdcerpc-server-core.so.0.0.1libdcerpc-server.so.0.0.1libdcerpc.so.0.0.1libndr-krb5pac.so.0.0.1libndr-nbt.so.0.0.1libndr-standard.so.0.0.1libndr.so.2.0.0libnetapi.so.1.0.0libnss_winbind.so.2libnss_wins.so.2libsamba-credentials.so.1.0.0libsamba-errors.so.1libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0.28.0libsamba-util.so.0.0.1libsamdb.so.0.0.1libsmbclient.so.0.7.0libsmbconf.so.0libsmbldap.so.2.1.0libtevent-util.so.0.0.1libwbclient.so.0.15rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.4+git.324.8332acf1a63-150300.3.25.3.src.rpmlibdcerpc-devellibdcerpc-samr-devellibndr-devellibndr-krb5pac-devellibndr-nbt-devellibndr-standard-devellibnetapi-devellibsamba-credentials-devellibsamba-errors-devellibsamba-hostconfig-devellibsamba-passdb-devellibsamba-util-devellibsamdb-devellibsmbclient-devellibsmbconf-devellibsmbldap-devellibtevent-util-devellibwbclient-devellibwbclient0-develpkgconfig(dcerpc)pkgconfig(dcerpc_samr)pkgconfig(dcerpc_server)pkgconfig(ndr)pkgconfig(ndr_krb5pac)pkgconfig(ndr_nbt)pkgconfig(ndr_standard)pkgconfig(netapi)pkgconfig(samba-credentials)pkgconfig(samba-hostconfig)pkgconfig(samba-util)pkgconfig(samdb)pkgconfig(smbclient)pkgconfig(wbclient)samba-core-develsamba-develsamba-devel(s390-64)@@@@@@@    /usr/bin/pkg-configpkgconfig(dcerpc)pkgconfig(krb5)pkgconfig(ndr)pkgconfig(ndr_standard)pkgconfig(samba-util)pkgconfig(talloc)pkgconfig(tevent)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ad-dc-libssamba-client-libssamba-libssamba-winbind-libs3.0.4-14.6.0-14.0-15.2-14.14.3a7a@aa@a@@a@a@a@a@a9@a`v@`a@`<@`@___i_@_|\@_{ _l@_i@_d@__ @^@^^2^2^^1^^Y^J@^2@^&^&]]]])]@]@]]@]nU]nU]i]e@]_@]J@]B@] #]:\ڭ\\@\@\ \N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USascabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.libdcerpc-devellibdcerpc-samr-devellibndr-devellibndr-krb5pac-devellibndr-nbt-devellibndr-standard-devellibnetapi-devellibsamba-credentials-devellibsamba-errors-devellibsamba-hostconfig-devellibsamba-passdb-devellibsamba-util-devellibsamdb-devellibsmbclient-devellibsmbconf-devellibsmbldap-devellibtevent-util-devellibwbclient-devellibwbclient0-develsamba-core-devels390zl31 1643392001  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~4.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a630.0.10.0.10.0.12.0.00.0.10.0.10.0.11.0.01.0.00.0.10.0.10.0.10.7.00.154.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a63-150300.3.25.34.15.4+git.324.8332acf1a63-150300.3.25.34.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a634.15.4+git.324.8332acf1a63 sambasamba-4.0charset.hcoredoserr.herror.hhresult.hntstatus.hntstatus_gen.hwerror.hwerror_gen.hcredentials.hdcerpc.hdcerpc_server.hdcesrv_core.hdomain_credentials.hgen_ndratsvc.hauth.hdcerpc.hdrsblobs.hdrsuapi.hkrb5pac.hlsa.hmisc.hnbt.hndr_atsvc.hndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_krb5pac.hndr_misc.hndr_nbt.hndr_samr.hndr_samr_c.hndr_svcctl.hndr_svcctl_c.hnetlogon.hsamr.hsecurity.hserver_id.hsvcctl.hldb_wrap.hlibsmbclient.hlookup_sid.hmachine_sid.hndrndr.hndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_krb5pac.hndr_nbt.hndr_svcctl.hnetapi.hparam.hpassdb.hrpc_common.hsambasession.hversion.hshare.hsmb2_lease_struct.hsmb_ldap.hsmbconf.hsmbldap.htdr.htsocket.htsocket_internal.hutilattr.hblocking.hdata_blob.hdebug.hdiscard.hfault.hgenrand.hidtree.hidtree_random.hsignal.hsubstitute.htevent_ntstatus.htevent_unix.htevent_werror.htfork.htime.hutil_ldb.hwbclient.hnsswitchwinbind_client.hwinbind_nss_config.hwinbind_nss_linux.hwinbinddwinbindd.hwinbindd_proto.hlibdcerpc-binding.solibdcerpc-samr.solibdcerpc-server-core.solibdcerpc-server.solibdcerpc.solibndr-krb5pac.solibndr-nbt.solibndr-standard.solibndr.solibnetapi.solibnss_winbind.solibnss_wins.solibsamba-credentials.solibsamba-errors.solibsamba-hostconfig.solibsamba-passdb.solibsamba-util.solibsamdb.solibsmbclient.solibsmbconf.solibsmbldap.solibtevent-util.solibwbclient.sodcerpc.pcdcerpc_samr.pcdcerpc_server.pcndr.pcndr_krb5pac.pcndr_nbt.pcndr_standard.pcnetapi.pcsamba-credentials.pcsamba-hostconfig.pcsamba-util.pcsamdb.pcsmbclient.pcwbclient.pclibsmbclient.7.gz/usr/include//usr/include/samba-4.0//usr/include/samba-4.0/core//usr/include/samba-4.0/gen_ndr//usr/include/samba-4.0/ndr//usr/include/samba-4.0/samba//usr/include/samba-4.0/util//usr/include/samba//usr/include/samba/nsswitch//usr/include/samba/winbindd//usr/lib64//usr/lib64/pkgconfig//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:22444/SUSE_SLE-15-SP3_Update/4abb22113a3b405a10be97f0b30e35ff-samba.SUSE_SLE-15-SP3_Updatecpioxz5s390x-suse-linuxdirectoryC source, ASCII textC source, ASCII text, with very long linesASCII textpkgconfig filetroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)  "&(*PRRRPRRRRPRRPRRRPRRRPRRPRRPRPRRRPRPRRRPRPRP R 4[?;utf-85e512fd9ad26581df25531850f407b42f98e7dc9e7b6b7ddbae5c63123698cc5?7zXZ !t/] crt:bLL tvq0ŧ:mZq>V]]9LkPJ;p @GA!viۂoc0uǾ݉tX|f{HBfQ1?Ti<~cBpjA~avY*8` GkM\Yݚ/4ƒ:ذkU.9}<*G .X  k^0ӥaij #DnS=D Hv,%e}0uc}])<y1˳8u ԅ1ZuO'~rт<JFU{UEp%K^ &(V!vPm\ U#q~eP`"J٠Y^۾ ]{5ms2 eX+=y_2JI62E$ :ϖ¬F@ۦ@,"Qf2jU#\bOq+of%冗kE"(r abR] '' g{  OIJB4YBt(O3*_VhtRdHCcq;gT-st6Ȭ4Or,P п#8x-}(iҒ-BqD9"(H&D1968=QRVA M{4]fptb15(Hݺ%x]#"Ths?x2̘wlBja4 Hn2-?^܊~A5\CRQm~pd h^Q 3è\"埠ԟYߥ1j?&"4uєJړCN"uC`Ovw+Nз-a:bRKqh&;ę2v zeBбM!RɄ?|RX%8,y_E`, *2O&(J cjJPIdۯq2tpg1CQ.`k X"Sl7 1&' yJӢ@Z~baE3rME0۰<;Ocg08DfD8FB0"XR}tc~î$<>1. q_UL&)@..q.l,isL Rkhो1=|Ks.ED뺰p VjhJX*"*X:voߩ!*$XONj K?9X!hOa`7>"b'@9=~2MX+"?'tu_EG VrU ̟[07,H(rLтM psh[)zHe Xg&k [#S#9P/SMԓ=$Aݪn|7oMtԶ;DlBLdKC7ˬިy۱H̵+n{{V\۱V ߳w#x~:C$"=2\|d?ځ = [hJl8UWInѝphӳHE%7*_\ͨ XLn}~[kIJ߉e#at5`N&Un&:Z op,QEnwxh*r#֓C<ǡɨo2؜[9yMtK.V( xSDp%+E&Wb!AٳF8]A{MAuIuA9a;`\ i[I4-FJ3&.~ckiʿVNvreΛfX BNY_z'T5}([(* *`, "i= }Ht fd7X!0yҕ b)@ S/4޻:`eo6 QCL>eO5*%)_j VsMXAzp;AF=6|DZK֯5s?3N:SM@ vz)~h?UMUNj ϐ&AFsL06Nۗ9!zM^EcᩄwIq1*:n^4(*>oW)$8(ף#X /)>9ٷF;̮xf@6_O)Tɋ#6m\A\D ;8pۗๅ!Ul`S'gC~Tt@aG Smϴq$ i9ɧϸ{Dea+.A:+jw3G_ i8ΧwL8ι)DAnuUk?xHK!'-.dX)s]ڇl٠c_ sLY_PajK m[qq-Q7XGuР/%Ay{.a/D^v-\nJ gD/7xF]oC^7(i_1 5ZQCTľ(mآELTsq'3Shád'o2StWEɟҋɽ39ՎH 8NLԄ,M[BkbZQT>AI ꍭ4x9p׆% %&}xw)(eSw s%;6AX/}d՟?a^YU$_rF lzvHSWZʯ2϶[2pBڂ![b_vXb,X 3R ! мL}= WD]UeGcEx9pwPSxu=Yȥ6E9%s9exXMwa&Zۢ0|εb kwo溮.L_fUjY?mk[X6e.GGdzr)ElWo XHMd?!W@ kW>1ɬdGaN}%)y(T[p$x7%JW +.IP%~?%%|,ک.8\K [7 X.xhM| yǑw^ZfS"v;gc bjԜyAJ3o1Mp䣈/Ty xRu2(G"TE{eW .^RtW]̃d)W/J"_H(oͻF6S*m6/u4Vѯ0hWvˑ R^%A*jD}b~wk8+b4c} ?׎HiU*%*;Z\s%Yi)\%&N"|mԗu\HCԱT^du'ٹ:dĨzQɏ(=<ϝtZ5Q-Y:r(BC9t+0)eUr%TGjV@Yh0`NIZ}3`6{^6-Zloqr7C#)`?@Z[7˨ "Rr+ i7#"!I1S/HڤfB{n[\ډ~ Z7qy1_#[0&+ǐfȺ`_6Iy΂Q}ϵtY OYtU~}T85󩋔׎;H-Z !i*U*-DZJ ؽyu9 j3켵L|iy3)1u@UD@5``&x?αw1mDGm*E#;ŹKH*}NZzvW3+Fum S$=Haj=?Tez]DU!û`43(lx=="4q9U8Jc) OhM͏M]& KI1!yvG[SZ$9PFݞZ2C.tVZ΃>#UN|G. wuE,͓02˺(X^E'(V/=9+ UDWj eA R()㏂Iq"s;\`D`6:ܒ5Ÿx<5?K̨vT?Uߖq@UQ&􏞝Ԃ`G-E U#nbafb[! @|Th3U;NɣlofmlDmq]>ؾIxuc| 9Rxm¹ri$vW9xNOT<×:ę KMT?A"0`G:ݢgk^[3 >snHuALX(B{V fNYRD5@2|YE239Pyd ZV.%,]ît5ɐ7wa!<a>C@jvYѹ!O%|wRm'UQe'-s$@D)J6K]71D6/ض&tP@[-|T<ڟ.:(:zyĥPyn?pc?7aSlJa M\yv%qwa`-(Oߒl0YaKM0@d;4-Z.L fΠ+~3hřX:(`Dt]y;~|9.sj L>Ч2)uS/IE,AAHR(i `J \aހ޴+Vn.N7uzFsЏV죘bYbqQL? Rbҋf#\͏qb۲ffJ"#ߓp#~L%W¡%$חZC_ψ8O$2ifx [mMd/?I=lsZXA#l#F d~l$c5؏hg <`(`q_^Фiut TJQpΙ=T"cH(>p5&a@<]JcG@^&.W}7}uDEKFaփ7f.&OlV,/4t3*;- hO"<tBih:gGZ J 4+yOumw( o fX=Bw0sO.;ou?JyE;zdi4Ek9l;[7BL7Q^A v _dCI=dF im"+|VSƅG.El-#ɀd^m5QS#@q)D79:cGŬ%o#n>)!] P=7:Sv(lu_R+Tw=Pm9no9Z9R%} G8(#f_KGZ!Q2-Q|UJ42XD{<&!tLDIK0-{'Q؎kgB!kL)/}9=*%’lP' &5VsW+N[ y2NYSI&闣sL%ZN>GR vO" :\:. %-k_MYq>ޗC*3^$ohͿqebh9T"?`,'q%(E?"4g'2Yjx3\Yގ ov1 f^ , ;.@xPOӗ p5q Tz}˘g>Ɠ»,bz#?vP4|<1A>2vnуaӚG&sW6K5G;Z V*_"Rj=Ygb2L>GӍfy{͕K]'<`˫ ;Aߒ3u̲XSq*Β>SPZS n|šH5e˖.6_@ `K7EK#h/Tj@|34^kh;\3R;r"ytޣس^6w,V{M(S.'{VFyJAt|.L^o"у/?H~/n,@-:k#vNI*;"DEhӜf cQO=mE,6(21|فZޝMTڲDZB᭢ Db 9: Jfo @9Mn[Y2IPrV; 6G Ár6DPMj<5pƙY6Gic8=y`|u('uoH26J VXF(9lYy@`|\V>6j89Nw aij<0m\lX(DP7%K0Mz3ٚ \?NX*<7j΢EN;c)QΏ!Zl~Dd_W#tVF'3W42f;_k11/v)E"[dc۹i321A2)ID_J sD0˿tCCQžBi>zf5Z6efr1p&:Đy68G7ρKyV*e~$m lB/a-Тc9q:ŝm<4 TAg__E<֌md\_'C|6B{vڏlJI+2~/#u$v:WD%]vʐQ 8IFM56ww/,uOHN>cp((ƤkHQA,vMs=8HIz Srm2.U\$+`qPpz\7Ɇ G2x&6&.t M9qQjY>B'rx 6TQ|Ck:i4L¹܈f׌b٤nr=c2]2>˛!_  ٺ_x]Ux'-|aZHayAu04\99xȄ5^.TM1@lZE-Iq,D̂TY;Pk}oq`}~(3x5`kq'U>ipɏO1K (9y!]Y?MiG:%3^M  +ULG5U g}ଞ~#73#^A}#T<k&Jg=ï^!7[!$~B۬#aA8R/,&^ .貉kMǓA;fY sYcfbV$<pЫi>8.{P`}3ׄi!3Z zX ә7'I뤇{5p x r8蹁CorCVZ+1vv =3#S:Pm ݄Lok.@~Ӷta#O3I+7ûYu !1lj]qؿtc;KySv|/wA!gUL"):ࢽܼ[*Hy=:"fq|@Kw)}r*+) jSd^g  >8=ɶQ]divzσ?.UO{6-BFQmA2`6=<@Y։ɩnD x'9I-yc"7HoX/B2&Fz$ @+to?,K4T] LMGG%JIeF e}­9Wsf3h db&b8NdFT#Whoa?y^5F=Bt?\؛]4V@L )0`v!jK8ˉgr/m4^_s,ohl^ui,`  ̑ r69PSmΰfH޺;r@;3㳨m,=̽QbCx^ǫjz^TG"&V~Y7s%X>=PU5L1 INA9pLL< YdƬQ̆|5@.;%dtM~DzJ,Y+f6Y񋟱5_\"^0A~nLg zqDG%.|F̯/rZ22/QX"qC'{Z Mp lx{t E&э:}݁\|j`)dC5cs&>MI 1뽉HWnlV(EʼAEɫW^@̤)9^z BmTt]PLQ=㭠52#ZBv_i"?}W@(`짱ssTah#z,x)8f^ol$$l?^(11MФs91N2!)|JoA! E!SdAOtN[OaP'M?l2LEFoSۊa&5̾(ĂyoRРFb?v?OgXX }5cDDK#OH=DyD]*ov;q"7*"ӗ{~g=|y8rԁtE!s<牓Mqʢ܌\B#R3R1~v"ĭk'˪/¯?8<[^D~ Jtӻ~̷Kx-J _B"VQzXk˱zyb_SHXyt7!b rPΪ#tEHX<;ӁW "oYgl^B7QKOVez-ָ'cpb#j 4&,}Fpf `zc#78WdĈDC2%jS|r> zU SfGiy4C\Vgs`h3!K KMjp5k' =bazR&2;}dwWQzdUՂTo>&Ii :ɇ`6 o HaLN"^+ ZXAY>p¡cჇ_&(vF̊g`YRBC"} IY<.tح˕U幣x(UCmY>hg'1CRG]~5k^j F^O_}H #G{`|XsxlHf+2VK^ʜ,e.=5RH\%08Et1҆SBi ,vsr(ٿ (5J[B*uF(J_5/)p{9`¶u7zdNnxc7*gbn:D@)B{rq?{֣2kPX8kZˁuvN{.4}}EĢJ0$`4nϋ&VV$#iąk@zE)?K4.эEl&)@eaDy+O(Ym 6/#p =P^zձ^NMrp-Q͈THsGSފ]0Wy.cZ2b| ʖJؔi$CXx4$%Y3I{T<%mIG٣%IlYޝE[(1R<@xѐK3m|(W3>-pb T}#i^2GR?}P¿7(_Iv ִASBKR㔿uo14M8'V#m?“Ұ0zj8o$!38$}!*|Xτ4@Zs,(>N%)TӛR3FP8Bw/U/qlTXp2aOz˿GZ5ng\LS R(6TrC EB7$kk"ɧ/6LT !e$+N T_ H=it=e = .^7W-Е!JZRX5RRٔ ~s/]a\! arVɚ@]J 4Tݣhд0<&&]Թݮ40fD>;ǿs5d `4sZ;C2-" 2CyLGxfr6$[Gܚ5M"ixDKV[G>S4:-7:%r!pD.<S?_ȕŕ j殸|Ayƣ>5gF@ĀюAX%#a,61an{w8 ̔ɓ$y; >hb0ޠuOyHTiѻ5Y _E Pvױ1KWq̮X-r"&wjRK#ND@Hy\Sn!ZHY^-H5Jw3"θw7jP*~j:7*2^ [XǓ_1|[ .Ag#P4zmU͓d0I^Y/ȮO{vTHR"_Rԧ\0xU(tzx؟3(U` )H/ȸʐb_0J%W(fzvDNgC<\7B ,'&ɾk盾ؼ[6~VѪmpK 2ifJ&[[\]yx q@Cw:"POeV~UrKa_ũ^E\Dz _W٧]s<~ġtl@7y~Ӱq7ZvOmaae{'PqY eU-5&pIzEKl1--r P*(Q\l_:,<5 uԠN:X6:v{ڲ TқpqtC36q  Ӓ_i6p=W+8⟺УdUNwAQ8QNK(ۻl'9N"=NF[i,nwOZ*!zXJS_e+N9"="AQxrV7bpPNCf\i%  :PI\  ԍl'ؐ!t.S[=Py!1$Pi)=k4 I ם~8D7۾5ZʓV$˹U;L_%-M<Ś +!tu߆w>Ɠ4<{WEY*ấɁw>1I%Re}¹#Y:.- sZ #nO3@%Fz~1F&1J6>txQ9UӉP,]J G<;kA8ϟIatxI^UqMex р%4)fXSLƒ\lF$_Mkǒ 𰺿iVmiXԭW%|Ҏjb@8 ",}>#_^k.,~6F7I qVixC(PE7 sI*e >zKpwTX+Wu;H~5'u&gD~ z0=+/I3ꯌg#9hC@GM#؄uu&cst^0^pB?3R,| ɑ'Y3F+=ș s$Akڠ <)_4i rǝmf!459iځ7 24A'ec!‹ л9UN߳PFXWm '_XL^_Q4MSMMĘaZw TLZv$ 'yd wdq3xbyɚ_ ƫȲkn}VO}Qr  g9}(/M_#@cתɊ_= 7q#$rӰ$M*VqEϮEߞ\ *`\Wبي!C $ +zw\%zp0sXd[ _g lsѲe"kWN+^Y9 ] yiwLل;W%_ PL{yam0p*\d7ܡ[Bj@(`enHowPt}XHR޳a]ws; 0L&{&I?V_ t3;v)=cEYm>JEdi#j_fÑ{7.Qaՠ}Ivo+YBτ ΀Q-9FKe1byOLbU歭=TFA+dJJy/ WuƩר4=v ;^ZNHX $vLUzJE:jDB#BԝxZ;JN:o4=q1g&Vj-r$-ve⫝̸H+ 7AcYiOF 0jDC!Д5Ѡo_ԙ0c Zz}>cA}'x_29F(e/n(B-¢mOIAm#~C?6iHc֛4M\d@i,џ!D=m&O+Z4A7/1ih&T G0>j=;\u -5jP<1ʣ13PH@*k@.iR+k[-Bn?ov۞!(>:a/й;8yRscGPg[s'U>~cK(g-C*m" &Ԁ WX͙R˛ <ȢV1Sd~r^,b%UCL!)ߣïLtgo?37%Zôe6ќ = &.R@=_7(h{P C*l?۲GW cA+7bP5-d(,)Xq>飌 r)@GG3R&=5(u9D#fS"政< M2B7/rN}izC%!6[!SaX^20Lh2";Ji֩+Ccɹ o$zKeDzaYhKmaMmGmO 08cϥ,[ +/G tTRZ@:=Dz+T,#’%dtOQ k*B?qp?L\E(z!`= ZҜjpZ\^GlM@Za_ ([-T7\=k∛8׬\=X bfy6^C_$I#M_u.h#v{{3R`sxXn i.夆wo>@ ԈS\21U>Ev|Ae9N΂ՔW.o')OP,CiD((p|(SLIWLC­,\/T7Z˞ ȡ;xU0꽯vvh8,pF4O Qv 2S4טO)% m=dL`L3I)cWO>EK/ۂQ񀁱!`' u*IAHU@F]ƇsY;v6:q?joZKxCCfPn8yԆ2Oŷťx\*Rj}avuF>4JkT+}jNu*J J wUw~;/B@;B^ݰ=;잲U<1GֽFR4AT&~eJP62 V_pF]bZuXmvKN*Hj mb mຍcKT.P~o$s"\<]K+ZwM5r,}bjTP@tk6v* m=PLPrDrξM+QNzҥYF[AhyNb8VT;"l!*hV`NMpXgpoeT/Ҷa<ӌn 6O<7kl(HE39UA\ *iPHܮ@X ;ɿG|Ecʐjo=MH-c i5`kۗC=V9Q4.qٶVtxYڳ6jAL=:&{J"cfYhDg)J%.ӋF'[EYVY(a ]^% #pr9U҈x#Rsms#D~t`6٭Z9$"1k8Ɗ4wx(aRCi)_3-"ɼAn'C/y]&pfoBȌo?ڽ026)n_97A%5 9 0rX~ζ5~A Y$V }k1A͌I@GGaW+LveKb]v@J#Q S8R+tD(7ƫV6p~ѳJjsϏūIrDbq|!n?,m7Pz~E^LEGW0+2(̱ž7i]_4v=Bxx ,>s5ܐΜ{EŤ>q-p*pR,%k=eAXoý$,bzvV\P]úQ5`;Ĵ&1Vd3?߳Ӫ IYJ'Aįc:&Ƥn k 6Sp}-KyZc3' +U2_ME g6W6F K.2㴜P9h_#EEd&9-RΟՒuX2QgʎOWsɇ͛@/Z.mYusa3zb)DZf 8ϋ{_|])]95brNMT]`#a*T,Ng]$as5}%)=gMH_޽i/;k-4Xe{~_wA^_Y6PJ5&1NeJ.; xI <>Glo6ÒL3ku0$kIFADD'7Qld@ ̋GS |7#9;,p]@9+@JY3vZn'G "H!ΜpjҽcI%z@jPXm6 :/6)""^ Mqd}a(1ExU ܧ׉A=;צd{j^I^Ap-ٹ脕${8 ,Fwۚ8168#㐞>x8 Xn-\NY5_ϛ'O?2w9v'4d']_7'2թ P~`5N[9-$$` j Q x Y UәӔU\, y+ (KQZq(٠bոC`!(VoW?h"`5N#684˚h:#Zx(>Lˉ? %)=> Mb'o :kwk5"{`"%]ۏ) ժ?LuD@g^;.FC)ǼfGK ?ǨDe4mon>QRWFlj3b1@8^v/4e2J ǘ>3rXJ(J#-׭o)n8RFxOQ4ژ|h,U\ȡ]zgi\>e~y'|TS/|# qD:kϤeٗ߼W@gllrw}nu:Yf%#p P'm Lߨ6j}ʩyҞG, @wBr\/Tn)' ܉C9s}ֽ5Hu}RxºDc4@fu907Un G1TUf f./0V׃Ơ W?*ZZBI<(d}gvh*TɦPę#} 7K#9i|ؙ@Θ5QE)2oSl$O.Kf:5]K/bm>_8ܨکļFG&0?FXtOh ,X|4JdѾH >g ABvc+ze*VdbY{P z( Κꍳ%w I]d!?4DQ8SC5DFznb)ʼ.gH&a~IUG/lVB$q-BjU!D=Uy&D5\=š.1f^Ƶba?ZѾ%A< 1|ͳ;xP*kJnjjG/Q[u\dջݹ$ﻮ15>;Hzfz8CD)BE -8m|K>g|+pvSô1](;An斐|f/Ph7OD{wJXNG:eD <p~>5`ڪTڍ ~k6 N}MH:?К F ܭ-4Ez& -Q~xŭ\O{@*rKa!<ڮG{z$JZVެY+Q}%ό^(c]F#~I*Q(V윈{v<回/Am 1(&`[ųn슩(Gaۿ*&f0'Œ67K*t~7<^oB/`I4Qֲ=C&gy=hEEOe \bH uCDrr[<7rp)| ( [PV_%6[_5c=yB}]˕>Ĭ{w?HP#c20cVPtc̾|vǸ3왟xTSh1iqՔ[#[> WRB~b'1鴵APho c>BOu9|3iaVUpP8Y.D̯uj/湫1,T+ex~' +t3-ڈ*ah.ʗU/./,fe$A̮sȌQmޓO\SRէyjyKd6@*5iҋ߯ٔ٬+cC1TR~Q=r?Kzdx v=;#^+$T.!8wrOM}J{85RE d>F]Ν!}+3nBM#{$rU2L*1ػxGEPI࿕=1-:@"S˳{l--)JoPq߷ ju%o)C 1k6t;Н`%Ft(3rj؂iTy^ o!vSaQ6_G#bj]#m ROU띂hİ7ǃp)=}-sjGFĞhozy9Hyu䌹uuWA mкOU l=ܔT.8Ih$vq+\bS=2xxg_x Ύ\ $>jGIayg QS!S+Y-D7"( ,e=8,X-g{0Y8jGgh6[@l1#86bT3Nn-Nm!dwjPc~3WL>!4ZұPcr!M."q~:X @)L#X&Vm:(W\"- 𕔓(2U)-m_[ ):y6,㮍Jȯ!\r7;_Ζe֧0.ܳ4.BJKA#ݖ,=j&(B&ۭ#LA(5YJnc|>j8'/@q/_l'`u@y?*OԠ<)nuWWR)KNLPBjN6Ap*j_p 74܆fh(d||6* CvEBa#l|^rz7ϋ?ES[nN݀hʮVfaρ]ZZGJU V6:jJ㦂f65K$k 9 ˷y. Ql(&&D̊h{ha6.4b y dG>mOkz:潒Z2cT?7 Xf|u3}]o*Vv) l6N;l tu9JÜM 1Yzg)@cW4V> >J$Y*"%PsR0B顚W9HľwXi>OYlGWN#u)$P*qWhZeϴlVS ގo .D^eągՖ ;t \HǗ^s3y8O3}Pn' 1D},`琷V}l2[M~!@[\z+![rh_ 1:$x%w^#2 .CQUB~bIBRۯSSe_٦Ղ>M<)zi[?a!-npnz'~WM;--_@ T5 7 _C IПmIJ+|X#pmV%G_ &):wX tpElfn ՇH,}.N&`I܈SMj8Vo"i[k7;u+^Χ䠼H93橞GZqg܊>5XX枲"0”ffX(k?ĹkFvچWUʅ>]snYQ;!$CAR:-{ f /!կoz1"]]f$rC 0WR`;sqFб*xC)NtUNN!H/i+(m$x\ DscKPˈ^&Mu[>9k4nxlwrkㄲsTlE%YҙcG#\B)P$ıh@{pRuO e0n$_pvv@azz(WTٝ=ivLt-]xC\ =S1vH 9aJǭp_&)uAI%4ZuAp恹V5YTL3@FR{ ipfnL=@5^o!cq6?bV]f5@+nd Ɏۻ떵ǑNAZ"*F,bWj\.af#m`Rs凨X|6׼y*iٯ:TSzj* * /_fFPM>C1vƧ[0d)TX*Z';k;i&M;|3&Zqoit0[8Y`{0TSj`A< 2GMf,EfԮ_,kϒ8XFO[ Q,2 & AfҢB]sdV6Ⱦ/-W,.BĻ2@i=î<] c4' #^m0Abδ䵉pBf"ukS07. c 9$GÍ6 [9t/e $=5$)txހ`B4?! ՙo1@hyϔ)Ty]ʝ_يMVFPu3 )4p*fO] }[IJ;Є{ PP4<\tOS[.d'q9M&d=%3^ ;`=߶oEZ<+l?[{7eff r-) ݾ`$X –eM=d60yh")Ɵeg }?[Vܞ#һDXfa/Â(g3Yd+"k|- v 3YAz ,P+7ak"*| L۸ < -*-e[r%s.Ń3؃7j  LtCIV *n;xzfL":] o~Rn!> vqϙ]YL~L oJGd*^6Q#VܗY- /d&8Y!RqԤ2dTJuuwk`cA"Gr E-[MVa6_oq&O/qq}ˇFds!;P vs WA-JYjQ/ocΝY=OD~q06쭦LQ3>ZJAI .~.+pρKݍ \Sxv 5,6b;ii* ޚW֬dXuKva.ljؠ̡f#`JK7t:imɚ>6=5u,uWG;N'[ _;D==(a$dr~9QKRg{St6o1_3"叅9lt0 &x4IH3/U_8 8 D+b=çt"LeO?KZzBO8P|x8%5ܵ!줘z#yWtȦ)'>:>  \5R"8޹L$;r#d*~1Nݻ`cu[5+p9F߶sfQE]VȘgD;7_ ݗ^RiTAncU|}WpAf*S#?U1$RaKenJ)2I&ml|6|lSoB{5{6hB;Ce:s DW-GݯмѝyМ ^E'vTy9u0r^=+Fs[ex.߭{F1||,%ˮ%8Q H$X}ўu6l\juK@]JWWo]&92*gemR$:3Vny,fmvx,Hsk7^-)>ubADfs>P(fSã|5Åi4X 7tR~̿J\rرôbd} A1F+Θag6xuGcay S&zVA,x( ݓ=3T!K{oʸxnb񞦛ҬZK;7aWGib"Sm\/au^]-fYu) #ё>MB\!^ɸUru3ړ53SM$Ā8rL8f'<"fέuL>WN y.nj[i@5 *:#jsb@5>y&_F#Gh[^&wj)QƹLtޥv0ZՕqr`ܢnWE.膭F$6M"Ly.d\o HOIȓ$@]>3q'?T&DŽߞޖ>[ N9%fI5gav$=F+b0\fAؗ7SZ@(8t1*A7)φl(ߏ% -ȷ96#ik'Y?u| 4 d6Hnuy6.OFȶwywjٹ/?ʄBw֑VF1;aOBIYT:yb/Lp~k^I3 sڐnxh*ᑥPE[\6W`YDžU|v`&7%zZȲ*( `p YTN4J0O%ٍ{/e̛㘍٪C(Ms8,ϝ!m6YMt(\~}RRwe^h66^It[Wf>!ze+~?F:*)Zs~> ;bf_ɉpό403H3*&.z!%IƧ5$ΚÖU>7, FUIw< \ժl_T_R‡r$ͅeZT,0PsOg.vᦾWiukj'd["L>=`YxBI軵݂L'mBi_kGniu&H";n&՞m.)jB~n ,)./,⑙4[G, eX40剫qVb,f-UZ^Ǧ~%>r>e*]S~&x,QHG%KDЙI[#=K ׼(f.M7f"{M(`|t5HNFFrmA7;u{.CxC"מ9v}XTi.EK pF۰ ^̟Wh|_*V e@?Ex؀U֘(^SchN˒[]k ^Qrp]Ūoi|B *y[-'YtchӫNA&joKlosKԬB^6E œ{5MTaI. 4H _ha= {jg|hRJ|${Fxpu@٤灼ghauO5 NOC݆Üy4=||w#@`>V6bL%oR>LU+BĴV(>ìk.j;o{K~U#{ŧ;OLFn&',*Gs;\dDžY}8NVK;!13LqeQ^j'NjACd/u& Y+ffLL45}Ss2Mu+[1H<c%ϲ-cM &|2Z{>]Ac1D{uV^td :!4w+^AasWҜA1/JGHlɁ5<{u66*G/PGG\^' BN"{!LiU?fp$7H_~ט787/ˎ"ܘWė!jgbJ.^2W ɧĢ,<7?R;@uҰz76c^t$Vn蛐b!OO.rx9ʇX%k Xʀ I_Q>{B VP\%zA1bK qzlX;5#8VS Rb9uxyWiXfLuF: =kќ3OQ>3P?ܯU~} =gWvQ\vM&>~$/.*v\@Sbl5\Y6 9|'̆պHcLoC2gWRb1eغs7*'}màNLKOT;W;S2}`AԶȣ5c/!Ğ9q緀Ae)7RTA;w<^Gu7_iQ™l3<3q;19^{4BƢUI<.g:d&0"1"IEEe?D| ePphL´Ui=|mH>jdQ>Qx_6M"p23U?:KѬ$~Q?#ЬLHgPHۃ-7Do\ L Xa2E[ߎ5@8|T׮G%mɾ҈HL6$AŽX-e2X6 >цwPg$ewc=}Ֆ}*?%b_~.d̪ dJd/`A_`61_*SQy|o wA9j-nDECSe _kTV,QBǶzWfxȗ0*xK(R >6&IIi-"eHH# zŏiL{H"r鄞4Eh#~ȺxU' ̧50537K`%Sk rV\hj0㝔z;z[R鶬U3JG6RnۼE&3eU|8I_fRʶ3kaHUeIu;`_ moOsfq܊7(f}-? JƵMh[?Atɴ[#^ůA!;EZVN1Rj5d> z[Cx{>FXIBg9΃V,G{)"?}.dLMӶEuMJr=dw7Y䞇lr+im?^1y;Vۗh\sJ; |\ͬ>GLpc̞~C1^"eVqEj(J*3zH:lf)aCB ݠUֲRaSѩUqk<Ŕbg˾|PO]ů$AMH@xB]4L9ʗ%U=!{&_G-(鲡q͜ )`젪,a, e] b 75׌(.C9Atް fG$cOʧ=K'҆SWՅlkgYخbqEBhB_oI+vG!jy/Kr\؉WҳmbMN#H@mJTʳ]UȒxkp7=w1\ҩA<>\d&G!UAw>hc!{?&cfN[Rz~߅ =^=γ/ƾ2pOh/WZ`+W LZq2̚X0)Y/Z ߦXc޽Y# sf%Ős[B(i1Qtk?1'@dS 5au?`-|~QMvw-u1XbgRG0 aҢ ct97K(pr}fFfi#itQK"L0 OIװl8E_f;R!+ wȇ͇4KǒO@ma吪E1UX 0X{9GI4 lY0yγKYN)V>!x=j9^!GJg\H*9M)noli ]&b FD4v'~ 2S w3wéC煱3CPStcg>E54i7bX5Um86V(Й C[uQToIRyiNw!4؋zR({knhac"Y'(i? E؉.](,/Z.ߧѻͪѪ~ (V8C&\u ~EcޗzS1K?}ϒIm~g)2Ħ +!̿(}Y籄<]=ΠeWч)g]T6Q4^It6~.Pq$q1 =Gt1UngdJ­?Ac4|[m|!`48ړ̽fYVY a^ɵ:k(I]$3{?]Լn  kU(GX&VD24zbV !msh$HgSN9MԩUu:$ FiJ`Ok. jRbЊp+$i6v?U8 giL})͏syZa?'FdGFt>fOiq`U"~Ӵ1Rz y%R' D8G!rdr6$zT߉b=!C4I;~2yʭOJc Xq|-gx|F64S]VDm%S-SS !P/Ȝ$H=!m}A7d(0][X[Rygf6;Q eb{ =TL7ђw2MI_ 謙 u瓰OKX.Uɂ$ /4SU݌LRm:i2\=pf%"jXN\B vYne靚xW~$zySBxŻM'nmgO3;XzAGP6 M4/,gR 1p@:FUMVq'~Ґl9C*Ljog=#x#]_ݹȶ0QhiVIITaܺ?ZEs>Lm,vf~kA CA 12`E-Gܱڮ /p{jES ; eu\9Z ԡ5/y]ZwN`~r[~HU"#0:/VtP uLږw͒>@)\==9|erFJJ{/z+~YDfci(VUt]R;5핆j)j r+?Pl 2 yhcuqT9C5 &pl4;MɓBmR^9rxSk o XsJ$x'ODea&xP A.ІFCNn\?j[v3ȢM_NE&&z= yEH+O)*ۊg`.‚C=Ժ2˲)׭~ױ!@ya* (>8\  ]0WqGA*!pħ6̾31#;m9$.-4`xMixx^#Hl<j4Xf0WG3^Ig[(µ/|Q8ԒnPkucb4Cۓ.#-?ndH{}$c" \m0s5nlvO Tw1!ů|?ߥP24sQ~>˓Aan吙j U?oBDZ)&!(9`3Af"p-X@akP+ΚӊeprD]|㹃XϷ[ɞ,fyqk6,4Ӌ0 9 k2 Jcɿz:LfyW 7u 6 h}_k~osťω;,ekyp85XVrFya<0 YXc~3rcUX[o&bBvӱ G#&9'y< f)&t?N'܁/Mlj~噍l~jstъߤn֊}?_z-qL!˯ XWXByh$HFOVfXT' jg&S˪=INv~CCǗ\$)4qDܭPrр+foQ$[JsV;ݴ}J >MJg)Ri(if"q{^7Jkֿwϲ[?b=콽HQ AaWjaZq>EĄڨ"#j5ߪĶuNj8>UGm4`c"sL .ּ+5@kgP:gji$"AFd3l=9D$ĹL;s޾+]HjSHQ%Z!=^}lj L=ce% tԂׄ9y*%3wIQ@nVoF,;/M b_U.ջf~}%ou$W3K$HܮiKN~m<6kUZ ƛ/P9ZPoXxҠ4[)j농FEJɓc G%)T;c ϴB⺦"RLjv@X&X*np!g@~<cYU .n.f~ #wk#}X@=J52BXqSe}S(F,p?X Dݭ&lxw? X8Nm_1#B3@)fH-,SR2x!٬}5w _rs5"E:$$k J߭zT\TE]< K%oɶs[%@N[&0'Seڿo"{\.b.R2J 3(P"S'+uf]lr#_ŭ2]~Ƨ* ~ BRb/I'*RjxU8 &>=rA\~nd 2">{؂^DXd:wl&E~ }Zl:y^v:-RI^t]z<"su/ H~@'냙2%.:Q\2# }K o޽RwnV5;sIj 8DaDA5}n-ax بeL+/z%-Aٿ4'9kK'ɜ[ϢjZ,ގ'z5&8WpM 7le<D5#ʐGd9sCQ;G9[ps2p]O.Yc6B|q?OHpڞN68?yMW!7|'?Q ?kkI%;ոCթ3oJ-ʹ󑋭qs>ݮ8)luph巉bmZ: "@?b2?v]U35Ӄ}yp V^ԱʚPk) 7/սF cB(4i_G$v3xwAA̅ 'h^b*l"X[0G]:m泛$RP7(e׷Y~b}$0ЛMVd hm@j79nxy֞%PSmF8G5% hLz3A ,w)F ]E~!8fI `-NL]!6%B~fvqWk ۺ'TϽMu6&uD^,9ECHB&b hoHg-\Ep+K݇UUj'ZQdE'FhCDe&ހ9קykIzsC7BڎQbC ڥCbʐ_7#K)?.IšGNݠKS DI?[7YRoTՌ(xYWw金)RXPٓ;0vB#JSCE{T/fԵE $iA Ð`VN ϐ-`›#D}fңȊ[[T®8E,:ZoHd m>n6\\(c oqNTU&ܑt'di|Ga5PbMPG#iUEsݨAT ^/ygH(UM4e4f"wp\VpEZ%U'Dv18Oy$ JYHfgy !d@}I ɛXu{^LS!iHxadv[2K唰_zO AB*$I' y5_`g[*~JѰD ,t="N:(+tBiEu_'ay#d`w8LP;~I4뚁6l<4D]Ef3,mk3Ȕ_)lWMv[ 4r5ɑ'I%!՚|SJv-nX:He~ ֮=~Ǖk7ӀRqŸh\.`q2lPNrAh*>:XX>T9QA=9hPIj&L ! JcӋhH&2Q >sSGo0=:a',OmiR">'tѻ9 (WVvU DȬ 9\~~oP9Ĺ\eԪ6߷XA}0¸5q0"] EQS[hw֌ڀ;5:sq%rp8%c6lKj{Nw8]s&7 ozrK_2;{O紓{B4:U.qzPf3bwVYC1U3s& #́מ<0?? `X @zYj.'I`35_9O4 sM_v qڥ9Cn ]BYZG×-CAjH6FH6ÉFKx.PR7Œ\ }>!^]p˥W(CGLч1;[}SQ"9Zߏ:'½FO{' l ;#fi ]*A eBGlt,yv[\N4>-*#Ho{{a-y7cIMf(B׀3puJׯצM3ad:nS0&:^b& 5 3A G~>H3PŝuJDw}[5#)u=9\yA% !9=\㜕y%kr겦Fj]6ڐ`Pr7$/(OE mVC)tP֍wdrrsvZɤv3J3]>wlxJwf:bz5ZUhGm-.3YM :;s wp -8fYpG2b6Wǀ1NB΄O@m5OVË-Oy ;MfFLVP5'Nkn[ʥ ~*)PaI_r:&ިNr<[bo-z)Bbzv$o !4k;٩dAY˟Uv>0Dmk{` כhw.oLR5re{{F+JR̼VU1[%>oB*Cݏ%0A|&4#/-`y)_pkK&7Z0qY$ ׬^NO%&UHHRgIɼx:ބ%@i:ەQ[ .u:%ȹƀrоwn5enZ'')5"IוbUXΰ ^)à2B3(ҠhDpA|hn(-)PNmd"mPZ0oK ,tkCX 1k:<\ Club6`]10rF_.5Kl^OR vGx[fɧ V.p.髶4Y|cF+Gqg;jhs|=hcѬxDRF6KwOH$gpMjQ5!>]XuQ¥!{?"-+틕*l`8,PwUAuR]H}u};^z찒;X`~rdKbT?NEЍxMG!Lo+. 5ށN?T6ͽ$_gN2 U4ĖJ'^YLWGR*aMR22~@o#+0np+ڗ>Z06 }/mV6_jG 5ZV 2N6OjCuźy͘awުR.4@#TM6¨!e'ۘcTx5CȐ8P- OAuOcvL`}Õ@ x˯vX6Y=L矪`% \q 9FD{78; [e)L15M|"l1[nK n?;hkt԰M9!֪;?D(´~D A;0ѫ^zP3>)\B!VR/J.)E*WeOKã\?k(ʲHʧNS\X+{9ȼ o#lY1 6 GRH;ΩZu}uvw48GDe X}A'@܃n&Q _ ol`%ph4+D2Z1Z]N S].@BUΩMsA{_|Əࣼ/8@71u9(X͗>:N;| X<؅Fu#fE Q,?L(}tނ}Yد$[ʾ֔J- 0*/vDs`:2;/ǙۈysMRub V;gXfRyo=ΕHX@a!`pFeg𴵗a g8yp~A˅<>5/|e&5ǚQT\lמFrOCUѸK23'ڊ8ifNIAD?/E>GmW>`\1,`~8-TT9?a2q6O~uwt@"v>,*]fZZNNwX=9@MZyrOn6}|Y=ivkzEXc4pY(Yp|#kžҘ"Cp4Ick:n2npΟ(*< RZFV3R{UT}.z72Vn?+;fzC=O0է^ҩS9%$FjFuh| 2BBUֵh]g ?1'dm,3ͦ.NƷLeR((wr,=0˘L*e CWˏ8:j|AͅઇX*=v~n?9ĭ9:L9or_ ވM:cQQ;ѵyT =R_gv Mﰠ-X!UKRtZrFg}pD,=Csx'I8 MK'\IqMU_!?!М}_M ^\1ILtV[8ltϚw\8%2( +u, TSlW@U-~pS}qhU5=}#$sQrqMWDMBhČquF /[0SG9^£^2+57fj]6b=CV#)~5; poeS\o=-;^2S#8dKdz_3q(]¹q /ʬFL/H[:yEC?Im7鹖Eb:JrdHK7׌>< ȁ-$d`H)4d߁ŒkeOۂ#6pG˧XiIpXU0ԁ ) 2 uaR|0,.{Ɩ%DSQ_g-vIm>'ji^,Z!֪|6l7i*p,AL[-EiWH RekꥰKʒW)}!+1.*BEF AAaw]HW$s }YNeͤ/ YCaY4@\Wwa `H| b, V]JK4̧տ] smM6ܘt6Y/yztaP4Z5N7RdS({x܁SKW bl v^qɂqzϤ|e}wE~rXO0JcLGeer5,E2d?Г/7kŀBT[.2eUaߗ=]xԅKrבy{}?VI6҄Țb}چ%1dz[z)Wtu.q7!҅M+)QFZjcP-{?9 ,aM1٫x#b@tB37r0#b CBƃmzZBkTXMMǯ#|eo_ *ȩu`Ƶc)Um| vtO;f(i*]2T'9~6K@1PqxdG =&dH0Ӯae2Pyhv` 3q#dԲ/BWp_ɱꫵ\IY*?l5a*/s%[DŽ15Nq{ݮ 'Ȳ,CD7N4~8xfd7GlWM>7Fg(QH`pYF_<=?Nᮒ ԀtxGݭ &Y8,cC⢐5%EnH8aX@O7}{G Ќ~pQTZ5RWő$^K/K+="vO CH^(kmF>U 7[y_+%NO~X_ӫ"Yuhx>do^TcKф a̰]U3N{MTI.t3^jiEĔ R޿x)ě+&hyU,wTGo*ftw 1zN3l~_|a 6xַGQvtx}\(W7RMIqKA [0TyBh\5G߄୥ T/c6:U\zl73V؟641X+i Bg&:1mh.^i׉z= hߝb/ra<'{`btY$N<-U@*v>.*IIG@mb$CTYY0.z,,2_z< ̮c>zyRҧ\*yz+v"R5ʐ(婳ui'nZ2}0-1 !PE'c_\2`h"ENo(]Zsuiq-]![2[!-z1%u5.lL&uoc~JIߧj,ȼ,98#U+K{譨93kLuZҴSXprۥ=.jd|l tQ1q` $򣏠ڎU _#*q6V[\GHb(ӮB) 8)޲_vᘁ1J z`+>ho%-Ps +UaqIE#7e-bAxm$wP\/CiCtY0l{= 5cʴV"D-b|![]8VͰX(^M~3xa.ZdW=cmwI5@2m?0EpfC)bFMTFA=J {/P$NzDbkUXt/OcMK_;acs+B9{!"~F4m̧o9Ĭs<-䱐] E>t )0 MnB U$#u_뎣SxeAj>ԉEX`W$dսj77J~-)%Joh޹EyaOybYC*-)Jd52U|T(+:5J칼ꮁ)x 5w,~˦quc-+% S~LhflS=9 ?imƌϪ"{~ɘ84;#N2"nJڵfn5Aꜭ6ٶ6>IB_ؗ FGUAtLhaLF;Yׁ,e߿?R!`"f{v$ԙkhYesxEFygsY( +Ռ~ [k-ف`P]9z7Ԋ秇B,`m*?ϧEȉ1<;YBB_?U-J@$_|/"yhS҃iԱo˷ٗ`:O]+ZUP@ͤ/1fa[/9n/me-NlW$]5M(D0-50]jL+tr pӆ&:eJ\*k_6Gq (a[Qv~nHI*Is8Eإ08SЎ}G{w^Ȭu˙)CW>g~"~> ,pb3my{շ$-t V\Y|5[Z^_EY(< kw, G\JSғ\=m3vϭؐ{Oso_ :μH +_$ G@ &QuR)XJCoM<ꗾ K+wbLd”ګF/KL{0iq忽2l[bmc,o#$ĉb2 M0wso43)$l9<<$WzZAXUٖZp鹼(Ͽ +Pcj@ ljr;-ưgCۑ!r dٓQ@(8|O'<@ܨ QRɐ&xCœ<Ӻ#yxN; lAr}olُ yuZ*/wf]+Ed`MCOy崈E,]u2ͤ:yoˈ6(\o,IDgVB[^A3;|p t?}͏A zdA/Yza NYD=F9?V+3-u2oy%<͌ePJs\NF](}E^? &?^QY8NА7Y&*7&sgy#K.߼S IU$_ {ZjZAKbܞPVeY1h1ВZIc`ij/Fӄoc?8X7‚$HGxAD0.LlJ >و5i8zvXb. d%H&FfWPN$.CЩ@ *iUՍJ*_^Qil+ipoe:S+ %G'Q}پ$Lݺ?SJq@zE& +iy N3htcg:g+~uI$p!Eȼn̟YТ˸cY+; tGFs B_acZUD*$dVxɟ}23Yb_Dlق9xv𤇦`J:}I;9lF ?G)nPlK#\_3Z@hP^OD >,gd:XnKEb v!o3_:R@,e>Rq݁wqyk:fT76 >$SLΟvApAʘT.3p!۔%7vT+/EN)aIs,vV 8y")Dj?dC9OK2e,:Zaw ;Ӏ)}Z3Yx{^ TL̐p-m0,a rarRn mq/#/UC2houoΛ&DB5i~ktLW3G.s ըىi]v\Wpa9[N/ѐ6u2;/mzJ/vvS飖JF=Hys0r~U~JLg)E'E} lɻ`_>$e,@[{}nr o=!~dG]تue!sTrZ^ 'NHlfDjԪ \b(p/\1 n VpVY}'B4$w/Ti2BVi D:*+WLcuj~P4IzᩏD-!63 Ts_ҭs}0y^bS[ُLf$ao @__>v/e/P8Ux6s$i`ڑ^:~-y !XIA̡1o#>3z FG~h$6,-ފD~wa=QJVkSƇ# TJg-Z57Z59 *`֝ IH,ǘVH/s5 فhΚNOKq(Tkj$"^RADjm%\Kcp`D ;R M'IإrLި!/`2n6 ]%Et?UQ#cf"PUHOҧg5aۏq\$QD8@x󠂚av!F1QhלּũQdګ({RB'G`~-銂`?-DqI ~|0:PjacF0<=CjVëIx~p!Np'IS[3Q}i:xݍmԹɉ5>rmYk@9}ԠXT֥I0cS 5fZ\\YfQVJeGi oGwf3~%ҼNgڔ!?^}c{Zm&Uy!ɀ^g ; =3-] *VPbogu +F_lS+ s7 ؙpZoEłI#5):ĔpT0E£>ɛC"M"YyH pijaAgE鹼u%{V@'^`S]^T5tK_m /j]B0_V4^BI^i(*]_:Uu3OWV^O tK< UxXE]ZqU[(u*CES`JFG Aep@96AdT%^T~־ASwNޞT 1LGTk,oi2O]akZ7O7ˬT 6l'j{De)ݣbbev3Ȯ܁YI֥il-Cþwt]HJ6Q5gApTGmS:M ,9ohJFů"턎|> }eIݷp+z'MdF<!⯀`:tN2.I\I^2Y,cDnb[XuέǏ=U/ `Pcnm"43]@f͓Eh=0;#݅–dIG%4JV|U?hA};w4x%f H\~,AObkO9fEH\y|"-ɘ&:-ՈgR>=`S؅lSoLn/PP|#clMx>y jzgrбj(i9:vU҇v +@MDB4эV|S x9PN A-|BC-ҥ~9pWC2; E iG}Q^fOe1qʛLoZp}wo̒_ IޢΜAxG׫q%s 2ƍ ݰxdpZg85ѥ.!SrDHiQn6L.n-G >M`${Za\ dNVpvaHaS5i`hD㌬mZhd$2ѿRL MsPG8TnqAbGӏ wf2~jh !MP6VO d _ЌMOOln'1~1 `M$TG~/*͐Mp-<*I&GV|T\)H}r.Z"ln-l|Ctq񶃥.ˊ?$38+?aI5v фM-of>P;+a[2pDF\ f2~ip866Od.aSER:WaB5H09ʉ +c%NvԑtPu,(9gG .hPFaΛkQiTp~dLPBw⦚c#Ư³\oGpQJyxY0`]HJ,#?Ku'ސ0P; mca\G\zR"=?B|]Of'.u}Mi_j:ئR 0qnW/ >D#𧭽ϢCy4?? PW,o Ysb#e&83HqtIN}z݊,be$xcj/l/܏RyP n.ô snEkV#Zo0.Xدz GίV7HFC[pfI9D4?aOIL,?( jpnvsr 2f% %blu$ B!=vG`ޝ:\dv#N4+Z ǂZӁXzͳ@-\^ 'k PRO iǕ!8OT+->^9_ReL u5CܱY@>%Q(+:MAgTVPiݞ@bY*%#ާW̱i.i1l+$FLctHmQ uLa-u9s[h,t!8ݮ7)zz&4JsY5) %J Z$~f,&i=W;}x$Z+pb$.$&&E_M2rX w?9v{%\Ks$"nfUz86 /% G] -A"A&]L0X/W (H+<w >>[1q8}E7H#6V픫kqGVI6]5⳨$>.)\@V-l$NO; 9o#o]fEky] `g uGa,w=.˙mSpb_ 糽U/׾&r+TYZ SM:Od_*痍A7Am7mVYuY+hǏ\Gj *UHQX' ԙ#3h :sf#_'NYf@X7Hlb^ "u9!:wvsvxq**b׾i/q]phKPS>W 6GqB8dD 5]Uk_nWC&&buR㗢,%w+ncDŽTŭ30?Apأ\G^/X\a9ې͆ sפ qK Z랅K%i¶)q*֜bنLc풪_% .ŭlx>)j X֟ZCQk|%xTvJR:i BljBjFI'LCJY9Z'XR5!d mLcYgCaTE2S3!8RL;~}A/ѾOª !̛wGuipOv/jE.}NDIݙC-E=u3,2(|͠=WHDym emқk3]跖.OsTאj.`aWic,K+mw _"b%`ܿQXA}ˬ9AwƻWl t|)f:s^F>4 ̀z6Hxw`*:dVoe<D wT+dدXI\ \9 IYkNS@#:w}ʥ&nևD]v|:BӳԈlxkG`1*u>cus{͓t]i3y8*I+Ke_UF/T=5YGC-b~ ;y ZXWĮafԙ9+ phH(=5,"i +ݎ8Txi=ueŞ 3<+x[S$k8)&mqT#qQNQkh?dP0mDyWU3w! &f.ȟ ⭧Ǣ&NAԕ2zzk ?!yIJúTeS2fmO?& 1e(spC8IT[eK`b%fsR|2<I3Ew!~c 2E u8J4CޮC!c@S 뒪5d]LɓhyGc*tK( 힆#  +9FqF4F:bPtFjY!REvw&R[TnqƁe{8to_v&e>s+p̲AӠ/krwM|KٕJ+r+ըH@|{`p!]zWBΠ!iwfFu)}[<7L]pr%Bb(i ꡓU'.;fHFkjf6JWG)6U6N 5ZT81^g>!kZ<^I9N&mj)4RR oxZ#eS::Op)q2 +E} m{ܮNhtr?Tgɻx]TKm:Lh0̿~,)Jl XT|k+I^M ƈ:|O\-{|nq#'M㼛H槱x,7B &G'pYQc۠@Ivo<F<]Vn.'75n ZW<V B؛`B79FA=_쌻pFU5yT1w|J 3+D qǼf>4 ԑTj5|8jrU}`\֭m讯pWQGU+fĩxh`.}LUiGGެwT!Rg9@k\kQ:6E6Y^L00u $(tg`[0)k# ۜS`ÃCŦ*fitew%.v$)&83ampaejXOKcX[ :Mq=6x1b˕@kJ;5r7dE9̕$IHd Et9Ф+{GbL纷zZV&}%d e8="^dղ=32qw%~RU6 Ï`ޞ <jtb6F3._Xo़ pXQMO<V;'~'L)8b#TՖh$઎EΨZpH!P) &Psr %Zp)+ mx,B;5l{_X >)K!F7ze ;YH. [QdKS5w$og PRU%#|r:0D&b;/2'(Domri"+&;j9R*+~>8qL|ڨegWz1X}oҪ._֮Sv bif~l4f==@Bj9' yI3Q=dmf|b zԱ"Z&HPIG$oVw't?2Qը>$X t'q*0CF]DZS-ћʹ˷ ;W*(Kl6;aƦd,%}m<Cqx"7+> \pZM~7rSAR6fRWDkvj:!`2"liΣZ[΂~, )3\7Ŵ/ά.[k;j2ma/"n F!|̠QT|9H֋eGfP 0BJ}XOحX?v隉Gt_[tpcys+2J2r]qߜ߼ g txo+ c:&nMN:akѢGqФI~~Gքlx˦pƜ0iVLX2V"T$'jH %هPg1fBgdWj >zayD7|kQ$qVqth˗cqY;v~Df0-„i7P3? i)Aѳͩ| Dv lk a1o*yV2Rm$^r AUlOҾwt3]%6{gSsnKn~,Ƈ+NiXpz l|n5o/ n h%Ev1_N|H U`="Uh}˔KI/"tGRKi.9r]2m_Jr( 8x4oPjI~Xn; 0(. s|":=x-˖M_, >1p. AQؿ17~ *wBHɕG1B _UYY@$ ŽDzeb0eC1eԯO.y,md'Ձ7יc"s=V{`,\;G:'E# 8(މ_s~ca5ą#fbIRh[^ñ::}PNœrgR~%]9b{?Dg hQDM>oS?62ƀ>kVs4"Ul-TF 6[!bGc>@jl+Ey8H@-1, A,YXeD*櫺T~= X5ލiz_XX?%p' LQH4A1pPvZsɀe²_x> F_OKПYᐸ"_waN<:dHW `W}B\5 @ӀOg *T8Vإhvʨ'ښ ٵɳ/0|ywe_ k#ñc(l}34d07&k V6Pv{ 0zȘ<ȓg>* V?QDK}I/7􉜬a do c>GDKjK|x+h'+jiz^?8&ɉ9 T)GX\z.9_|1~X4C}fUZGXno_ ضe6.Atݐ*\'v/=}=AHiuDPCw.VwZ227}fe BxG-3v>M't fybo8<<-8w絀l%w2Reop izpCQ7r 0sPpz_1'$ _ 6*N+ X^yæ{emĊ7j`/@y q`ۅx( 'ws"R1_F?QZ11-6* zN'#F_pHFӹx/"{d`kqyIshfkem-/eq^Sm0V%-Bm> -WƯ 0 5nd48cw)|`z"~NF=`nÞ~b&ssj1Ӛ6~{Ͷ@6=BPFӌeOYeW.xᬟY`bvFߔ(f*\[|B U9Z2VP㕔zx8OZCݒg\ e]w&<ʆI3H":@j'CP?MLR"lK公QЋYH-#c=FzmyμbJ"T7!ưgs̜\&dp\C]7OF_/*x@LØS}AeD[K4#KUXڟ0$޽ZV:,#P3NZK]FfenɁ&fE\ʌwHz +P*.g[,>t]F^B kU񓱚ăV _FW/LU*]@ )UB3ǎx.Y-*b4myé>Ǎ7/壁H2Xo75Gwe{'#4m?ɵY=@-;9.&8*'lȤY09Ըu$mo/TQ;–e5Irr[yYZ%NjU-KJl,'6 7=p+ჵ:ZN۲VUT bGTQBNDvуϾ% RF$bSՠo -R7-s)kjUj7eQ+FIpg@@r*N1"״P&;U2r'֑2fZ3}=$\ !eO4A+S%s`-;M1~ (ޠ3ap oֳ:8l?iGVMrg<o4dOĉmySڀ9.$q4Guŀ9Gh"Ɍ0h7&jzOV aZ+V`xǎ8?l,Kŋ4p/wZ%ty'`ytscOC#YG~r{*.Xowѯ??aEnSGjo@zZ}flJ1&:-ok*'ILlZ͉"/+LCu AVؐAB2ꏽ=IRo߼BT4Gm!%_%2K\K2JK5ov-GKTbwD8c=Ş${.X>JkǗe&qQ jJCKՁ&߉]xSLݽI`>oEg+ r=93Pϗ0לbo]PVE}*bϞxUz@ ԡL|?{34av9(oCzwN$E+jUMûk܄בgyTj9*81kx'GjHcyX2̎.ܵ^/#<qM)}pl0+tD#ʸ5oFAU+.̷Pq}O&ۅqϟ8~H"bΚ1' Lgo!Ǖ4@XTwAw꧂E+_8^9=Qkw|mʷo(K? JąRB R|`a,|& .ӀZɃ6 %7a-C;YBRZC8{7Pb&@O w0]塞m.|(HnaQy׌'eQ~=_>iU/5/ThDGH/Q.㖡pT0$7DWC98\B!ؼk`HtPJEi~~gUQފuYN~Eꚬg1lnjAhc-*\MUF3WyiǞf'S6.+Zl/ܝY7a~X<^AoL[P8Ac%BA L;`RY|=ba9n ĞMkj9nes)inj 萤c]Nެ6#R h"naM1⓪90>d8wwwc!!`˵/2X;';O\Ezf! &¶ q5ҫ$AE;cD;{8UqvE)ZGk03]l+znٝŴ{KeTd@VsOq0&)%^%_E*-I<q@E]S=BhXdV\ 2 r~LRXD687އTި;zduOQߪ;QmmT\?Q+,ɼB]C16w@<;7i,\wz7~TC[%d"%et|_zKI% <5N}{|nX/Ъ,JABR9&FZc%BCh~\A"?(l[QTÉ7KJa_KKTpNag}}ޭZ:X03~]p3":O3nv$xP`FNyHGD2~zl3Zaߓ<^wa4p9 i0Kh;sr AwF7R%e67v;yH NkstcG؏"> qƟ|κMU!( gN:ޜ U "ۤ}[&4B걳q48bqZ_ꁿs!v`TfO=q}|J!>0W o#$.4ŤJYj6q^xI{n9WK%O'22\ *CӈwRiafLEjDAp}E  4:%!, R#rd/+Gjw e°k3&4@qKRX^N/&*3K! ff}1pDGpg]`йTg)**x-v79ctȏ`I;V&dEJoI H# g q ,S'X1bi_ι-}S;g0l CT l؂!g,487dgo{RM2 ǖb6+1YF1S"A'@X-t^F![# "0wѤ1Cbwc{Y";X^&&dWA*F$_Wdo(BP(&ci#V2N~L|bDl43竟յ2G#~݂:,<$zY6Ǩ-3-Qu$7lON5#6.C`n˝dS>5<c d60t~LM:\{4tVuNOS^#P !0zjrwo}Rn=wv`.f'q͐y%ʵCQpSr],>b4cR[?gayF߇ƥ }pW{ vI+Iە*EX6icō1դah#EĦ WU/yThmnGZ<]AeGk zy]`XTD刧ǎcz]'۫n8a[}SVCԏ ήk%O*U\k]li=|֏ewK2t=O/4Bo!aBL`G f(Z/9"{"o,H@ :4폣BN l&o?jn{VwQn#i4L 7,A?_nbo3}ak[h{nKGmZ\5YǛ"y>!SIňlZ@$N,ݖNG0ۤ ߣRh^`ԇ^ Jv< QQM:n(<0dݝπ{/Czjy]GUsnp7{Z'ZuP2EBe>,(ٵYoLMI(QswY]@nE`'[L-4d&'\Wq+`YO\8jܳ<\'UwŞr &8gr1s 27llX1Bx^UCE;bQͦ#B1, ս{s2(W>s5|Ofr?=5^xYЛlat+T,?~֧E^]iRlk`&"Z;맣@WظI\vbjf`LgCޥT'Ljn*aHաRI4raKʀ|, K ؜ï9dW$^ J^I2)P6҃KUsXƂ@pGĺ" -#SSI+C4Pfs×sBLɖZsj !!<&dd }5uoפ_D o"KR$}?2څ$;]IQB1LH|RZji^ _b]KKKs@!e{N@؋z28;UAx-I,-<(uzLrrK΢W LJBk{n\oup_qWuGW ~[2>rnMmMP7!7v4_/Wd)(n#t(;QsJTF wY^!Nb$BN B:!-#4r=v)Rddžˈ,-i 1j=\q ~ہF]5}CWry3uh|2غ'jr"E)\>&#( c,{;Wez?Z?dsR#Z!/dsqՃ- <Qdm>| Ze*r׿7ѐ̱,JAOôa,,iTk=E>0g}W԰ Dfg +h ˫G Ȳ[pq/W_ 8 M;¤nE>v.lX" njP=v.F2 qjjnTrVY~O7< VU<^F2b浇:2 ۚCI2ڪARd-[3UtM\T @ikc6QI1qE$NRGПORm}7+y<ϰdk:\vl&l+ʖ'41~*$XFGI(u[1"c;kCyxc=OZ.e&u\f7H9RCk(t{ i/t%U$Yܝh۔|+o{~ݮI._ 4d= .p\ P8hM*y}_UwViO%P]ZIY07،;r-m-F0S!a)Wz ̾|WG 5&Y3uB(f앧"E#3`w'&I(X}e.{6ׯ?Y?߈,: 1C)S /d]"0mĽ| X r;+qZYmCv Bpf/A^2" A"j%fE#YQ~.*u3rh@nz 8y_8˒mL>@Y_)*Boh?1:Oe͈ʦ\]K(IY-'3Yԫ`wʃ ]! z :c43>>4_;Sd/[171[+Yl~E!4bU]64i)S VOG@Drvco]9 Y juUKp㝢l:bzHJp~z\g[5͜1\fך oVnH0MCj[}<-vC502O$gBO6,o{BR7J[jQQ|2 >H#FM;d]d} EvЂM i|QW3ⰧW7Q s)qo(w,K[]Ιj6^DaPf&ZƷ G/ ƈ#-S?JD//e>'g(wjZ: zSk}gPn8g5 No\4,iԿsɵz1Y9vg!Hre0Ig/9b c7wZ2~jNPoeQJ~`QBR@+mN#c4)? v(x Nd ڈD\_0 7~|bA *fTISRE|Ug£-AnDw)//&P:;*ZMwO<Ʒ;NzTlށxL S1NTTU$LtcmۢP)}7Uhvv0cw d۠>K:qa=^ 8C˽`ukz)WnfK9 /h-{'ˉ7RJM0-4j(V!F% C'ȴ>Mߊ<IjYܥ?IC%wS0? mAT,E.nZ˃XeP}kyAĩF\(dnDNFNEqҍ%, tf5gx.fj1UT(|O2( ϾgS4g`j{2ar *g n, ㆙P~vA27lMyɔ伉A9HywDטa7e7c0u4DbqLɱqRj27 %h-WuJq+}xb|Mk:%qSn&nJ?ub,Cdu(5y.A"PW++5Lo+?;wMKf0c =M;ѧ AfAn@hCDY:P}CD3!녮n}u0kLfX*0VKz;~cO)?oX_)ÉA>X_"~Dmq]Xҕ9VhP$q=~MWjUBg$ @bOptj O9.RznRVL0L_A!t$4=$sR [QGE$+N:TH}t[M0nyNW=3R`@8UpSA)qǣgpnX^P4:ys##IĻwI<.S6m9~QًjY9]/b-({ıZ -l0f;X^E)7.t}sě}xp,1`+{9xVcufCUo@T?8;8ڂ|rqf{Ꮿ` rU{h=N Mm@ԛcj{o+ fEzYiv5 QwiSůTuDԭ6A^Yo;'T1fT0^^s!҉Xޘrj雰h['%n%zr]Gj!/G<bT;s$7%I׀|NԀR[:Hӌ[bn ӏJLa,OyfMPF6$fV5xN:![ 8xxգBz,+<'58XqB aϪ}ݳ7eU(U^x__Hv_Za_=䢴J )^kĝ+lU!#rX3HNȀQK5d 6bTH|c;ɬ<ץpH-kfM>٧@ J=3٨z|%^V8OJCgYfx]0' _v( E ,I- y *cٙ9Ϟ}ܸwn,lyNHw:"MiVIʤB*3/X9Ġ2t?z>E1CKt:H_r W9QL+V:F['N>`wy.mG"p\R֮6Fb0&S ?\Mp͌B1O^kyZ{p*oUDJBmuw(q0orG/+3#{4 a{2¿э|\'FGgb4/H ;sSBSԱ|waA$54sQ)5,>ݭpAbk)%m/&(ncN{|>4֡>ygIРks{4zƢn¬H)J}6'2VB2.^$ d*z84ׯ`ydEYl`.#PBM69EzX]/Y"yJ](&sC1#-uE5,Gۭ8: kaݜUGăp(}g5D?Zd0rS&"PT#oֽ6RulDGSwRaEzr\@ulWo,gA&8/f@zKKh֤+ ]e$5Y@x:4ADV16O cŤ).Xedž,l'u>K4j Kͩ`vsHP>װP=hC䓒?ކfCYd@/ZFͿ(A50PRv}ON*I,y,e0E8pizI.9]hF{t r*̒gCU(vE NiwOa^{s wsGƵoutD_&阇ߦ_,NTWDZ*P nUzN޲TgG_]] d"*0ߑu^J{z(wA [ g9 4pQ87NP>r^5ÖxP9:tI%25cM-6ћ(%%=1WSՊ+MvuūTs]'AII?^E<|3,E7tCjݓSę`g lxU84nڠKj҅muw2&͉XGt&|]pp5c_cILp#>WšzZ'|Z\]=Rڵ њiJUўw HkYJ!q!=k8SJb)]B)Y;1ԫN -=AA@8+G+a7Waޟ+]` JN*y4k%˵${!cF@Vψ>wyw)ՒOE+\7{V}kY ^;܉fJ+tS&GEXhus,} $}QBDYVքI,r] 1湠P ӛTFfWW$%B` OdY Y %O 9_'-Fǻ54) pxd~y.[Qzݫ v/^`׿BgE}h[БՎW(^|O[V=".qkARTL @ur7Wjo_sG˽V0vSI)L$*Gx%6@N7eIFn$K'Fg22`q'4\PS_- pYyo톤U3jh˧rj>//]ﺊE?Ƀ- 'K"|-{ LH T{ 5z*Q_Eםgjt'7w؆ԲBV"% 09yA:mrS$7ʽ4xC-dr(͏؝%̟t* d?x6=y\# w#iP̛XKOOo +BCc2! ^?}998ˆ'J-R_.g3V'/=_]"Ɇyf3DKrU~Rɡ?|ij)b4 A^|k*"Bvɦ3n2KMTbWj.)+P,{zGh#6!S`b5iXTjL& `(y^Srba Ƥ&;dX5?qz;uǛ0 sYig+$p[v٣ y,(}n4n̐1¦r+"m? |Vc #q7bҘ[%E4K\>X 5{rIր[WhC"&HV3cI㯭Ĉta9:!p 74L9jLq ѭ_4.z00p-_BHJ[N؃B_ѫ'-je]4;;Y=3 :T}_ CV5dAL( j'k- J|]SRtqʊ(: p;p ,s [eF=l7jz!'Cw?9\S. (,Zai/P)j5]=w6~.I7*&Rf#ݥ*W5rH('0#aiё"DybV#a1uqms[tnq?VE.<1UIm]a#4߁#/b򵔀mwI3x#Oae$W.[@Ϩ'#4o\; D4#1ѡq˫jňudXƆpWzy!#^c0 H هW R9.nҽ^6m v\tLBJzL΍Iy6T=#. rq)Qc4؜4ͬOc@(p 0 sjAe8vU@y>λ;jL;X%V2>:=v;1dvV#o̷Tu:xp$1H˲)d!;BS^?m'Y}ݚah,4 z[dJNr_0"R|h`PȑЋyv߰lxVʖW0]Y ޠS$EíY^,[|9\".%WrKVA\\ 4׈>*J ೯)(A~Ibka"*!ÿ/e}c`j|)5+Bб1&(F!>ӐEr'ɚ1omti@gQ߉B߰M:e"9DX&gڱɼ {s) 41W Y#F Жg-șB!͞Z]KvIVюJIEj> ' l1'D[gm9fr|WErOmXyBǓ«`J BvW*7>sR#Ao . :jjDn#]0kt=VagHIAsS5-إ! YZ tr{ cFӘEbJO=djae09! 0O;#0iEv:;sK,w%.'M d%:#GĆ<Z2PMsnI L\K@]{1]KE&,^WDvsD`˔kiܱVRnܭ9G1L!%~\/ƾz n_ٕA6daկYB1 lz}&y'Ԇ7K1AszU6Ui M8 <;6ƸIƽ42߫!6W"73FHLqiڄ bHtrX N &inrd,pDnek^װ dB2Z[垛q]kڼE6 ^'o!z2'-l)N;$f Hԝ Dp;mӣ/@|Κ[% tW8W3<>X}X 1Ӽ 5ZT\- bâr*r1xgGSY.ُ>8Z]{5%wL d|Rv/;r[hAm9+V_G ¨+m7!6\B*Y:׈̈́iߡX1elE^zGSPKŒ:ކ_4iՃw_*}rI6chzߧ5 "rqe7!c,Pey⍚fdkK uXҺZ>J&ζݺQ蟕^moh4@73Tϸn}W:qK&xK ÖX"!ŝ2tq黢|h :n^CB_29==K?ȫ{h̉Š  d–k eݽm4X)J9SYxPr"أl8K!u#Ԯ5">< JW,_34?7iO+4Va:z3uz /73.~o({~G54)B=#$'TRLvf&;G4>_F ob?586& XS]m~Jf[('wu)=+ U8@C޿T|In9'd>C_u;3h"?"|;Auƙ/A CliJ)&kda uʚ \[XͮꦹVi1X* cx5+w_=a71n̻ Or_V(͎f6r5XG &fAEu`F s Bwa+qI=|"6y}|ۮʿN |P2?p6h{0_ W[Kf)[Ku֣H S$Oh+w= @73zn$ݵ^%RRk+qwQ|>k0t[ %6 Kd:=}Dcq)@ohה`6:SթW/ ?jQ>!`pY֣D[ZA]QD璤BkV`uQ\zLEzCVV8F5T8DO)HT3/\8gތ`+^śOW`@gQXa& j"ᖶk;f}xTO!.杏=pdnkBB0(oV[X, =qۛZ[+nQf=ճˆFҨu\Ę|6Ā_ZI>i rdY1)LrBR& ;JLpr!oGZ4p8Ay9f$Z[.2>lT,57r~0rek݄K Ɖ`-fi' |{ݷ}p7x`oPgd:p8=]qhsNq^AgݴQzonDbCiig>MWk,xW rq1_ݱ =^{gLKM ,krե3f4:*qB)È Ҭ}1̜H㎀D1>Û"hCtr#F쵖G ݴ|LvD%.pLlY/qtq =a!-ki.j3 *+Ɖ8J IF uR[ BClRjWAXvu?bEr28SXa wFM)yV8wh0qpGa{@ F?8>4؋[D ^R6ՋM:~wkAQ{OaKbƿ%.䅖Z|ۛ&Q*RS:ccWO`F3A;0+XM݊(a(Ӣ GI *J^=a(iSJ*&t_{x.{)&A~v7[مt 0pSw; W^!@7Z`KIićy5GiLlz=19E/p`!o)Oon y dXώE9crGʳ HЂq>i->̘ҳDAS|&zUe"`0z7U-A_j:ۥh,ԡ\qTq%mjdW~(W1㈆МiR;o+j|+tƴѽB蟭oSS3ZyZtpR:779u JW3t*{j+fW V=W+ zੈ}`eiK;)"֧z)': 7V6oHRyb B\g!=#;ݹ3#46 U_!zCv=v!hUv P6@)B =Qǝ ʨӔmꭙ$^IZ9(QG|">|1nsZlJ})]% ) mG7uJO G tq4|8 [U5! WV\)x1@H_bvVN[| zNoW 1 *]%80 -;e d\N=l4RH8n6R'tAI*!Ab͛`rXC xHH ChX*% μB&*9[ꗒ#GvGh vT%/CXj}M-lBy"Y "F΂Z,\v@>w#d6ݥE괛q #RSK_O/xa;q>7ؽ g/,:WAlcI͕yƿXlɪ; DjCIHd-j-~i^&\bBӺ﷿W ShJÞ'SYvp_> ǜ?5 km$g׌=&L9YNTџݛe:k$B l]{˚[#V^A maW N9' ,߲# s5YruBwA8 x|xDӄdw/!U;Ipk6?$iEPj&琌TRŋЕ`@Rm̵hg?أO>pSh327n/6:WVئxKI̊s}Y+('=C-'QM ;.:̌6x@Gw&(_*-=>2 ue xP%E$+FxuS@̴z{Z"9H8cDcTkm#7OϤm VZ][)tBS\0n|35SfcRPo+$a|WĨDZ`-'蝴'~gP(1-z,qvv+XWPhӰ!7h7ny* M7+.~2G^.3|o [m@ad۠I1TƍܘփgA?T?JԶJ*; 2,]ѹ%4c}I$o-4l8.Q̵/^MyLc#* k"8x݃QZ`# ۅ)}['+ֱG~UxH ;ѯsT}g:#l5?+UveD؉ F8RC?K43bTAHE8v+k&$_|(M^DWBq 0а\!tôkvH{`t-A=)ZQ# * &[F&YI6De%Ąx^L7aG7F824k3\*-$ O&i)2O,p|\MksJ#XgCs|ŝI69k.ER:ZHEDjuOJ}Y{w G^x"_Hbof\>OfmRE0=M&f^v>1r*_^0.9%Êfַ#^?MoG{A2wmaKz[+w;tzM=.Q!q=?eMf\HzBA |;6Y`AclJLL=OA1㓑I|zxp&?=/0׬3ن':񊽌 47TLw)kAKB KU(lUcLMΒllqi*dCiYe-M(;H纞'Ny}),I+,=~GqJjI/5PŒdcf7drN$)Eh1*x<@\> CoIz,]c UwʎR%΁>QJɑiX~#-F 4/39(2vNI [ q!Cfl8u%g 1YMIXNMUB/wcmS0WO-u=jxx; b^p Xq0"W*c`7[tܺd/>hlswh_G`)܀H%fdLeoJ[+-Jݠ #z>LQ .;zY0Oѻ lvHȁ:]y|U9?Fx!^M̒^q$g驃8v]s|Jg{ ORCMt1R*3"ߤ8>5<stgXC7:Csfvȣ`E2$VL! GSy^Ñ[HOP^l_= N,4/pe-˘Y$DSfBx$F*s/Ka0&Pt= KwFɮySWf[F@Kv{-U@woCO-&iY,#Eu2X\ژ-"v9өRB\P~qnW,mA0o]'@f+/,~xTW:LTIJ]Ћ%,B W l&&6 ۞|VR{*(^yV4r#ˆ.G|>q˘Ø69 FFޕZYW ߦgQ /(Uj[ YBsfOc@C[x9.6oUZ"cDώ!i"VlqSB ̷a띱d{nk" eG9*hT^nT Nr ۨ"׍h CD ڿo 05Y}C'?HFxW%~t)3*?2e}$}9AMҖV=Q#\)M9`hɝ|]03)°J;@K^(p6DwNa.^N|4ް赐s*L)8]:=Vk.N "%㝏D}C>SXռ9..kLPycվSp=ES@ )&.A~?t"āg2ؾD3Z`1g+@9ʋ ±^u} sZ*sK57UǞԹatd~ $,!`\ӯYtڱ1VO숸Ts# +ޭ2Y_m% Ͳ{UDs S𵨪u,VcT6ͻk朇 >cq$cLX7_@EqB9yHze($M :չk) ޑWڲ*W B=wd]̹X=$E%wun-YyR[P{Ϝ%lJ~*.hPauE5p1Md54)67rϵ=K/ @ 1ǏRZ{$`JBcj%K崋 y`7eXև̅#6Ʀ?O71:eu]ʤX (ue\6ˇPKr?z ?NG: HlE%'@au7iu⹾>0XA$bE@ @+2P( !O|oτjԖ7lf Q!M#ʉ-cr#I~ !nVG$\V&yIx q٪@T W9Tkg=DbʅDft%{FQD،lF-}V_2_XX jk&ߐTs=RyZ]]rL"NC6eKd4ԟBD)ꋽRA"Z6cBkxp s?[iӺm i_Rǩx$X`ǦMc nl4S%q!"†;04瀶Gg9>m~F8ñ.CgwCEwL鰙J<Hx; _Pq 10S0Bk@HEwRa`M3QT#ےjrщj-Ρ Xb`9Ʋ9&B6AKpg 6V`M&"zCnB @;34o@Ca]̗i0`elg|ّ>5'*Kֳ8N_@dG O]9lݓ20 AO> @%4cD\gҳf||Q=y!gBб}C9uh]85N;KL36yVK;BriccZAMlCp\:.^ُOz ġ aDJ8}TSXϹ9Bf&E@.|*z'VP/H7f3iy2G^DER Đ\S9Qg'%zzn}BKNZ72\vhA EdB#lsV%P\8ŏ괋Ye9mдY,J*X8hb6b W5h ,$BY$ @J=;g۞FfѭE쁣H,4{CnUdH:(;E=xBZy7=gIz`*Ӧ`О]ʗRG-:']t]HƳV=^(4GLnXr֜e??lC˥u|TOxKwfOdQ(B g:b1ZV:1 4w3͋_zrSih](Upe~[ s G@B72WfkTMo>u@+6cP×dߴTO}\lu7K}}ŘCqkDCa\d볃J vaGнIoAd܀K&JǩcLwϿcgrp@?ݸ醮7ZXZ2it[|+Z WPiQ0LiO!|sLҦXx/ٻLS\ơMj>Uyc-ˆYo8Ic`D(g%sԐp贍5BmfVс[] *P nQޮïC~o6UG?E\bsq Y-.S̲Z-, ~ӶGښL|0(6-\qʿ#4O@LL\yT؇P8#Ȩ6 X̼ncHsor/:Ki\N͖Ncm!xjx93:ם/ fzT TPӺupB8[(w ,uhc8~v&AN,A?_'a SF7O#zQ'Cɏ]*]%cuX S-D_Bf/}*/.nБ`5j>,$Gw9u $rJ(łCɀEj~:=X)`S}Z PgmӰS.Mx:1(3N,FfU!HyA\S E媼_(0Gg<|,I>=d/' mij&)S ϙ߱h~V+ A:-kQl*>% Y|YwCf%Ogs[$$(`w$⋩ڶ=+/ԉ=Xǚ͈V[X9Ǣ 7#lG\ZX<UEQ׆|Z9@fҎz %nn}Lf~^_yc&BTH0SK%`JZ_nm])) wPJ$C#P؋ġ}\J<8 e75D۱&{-"b6 H*aTN(f_Sb.ӓA&Hs^o*¾bpAt3Զ~O;GlC)'hTܖ 2[C8*HˏQ]l1^Wm,@u27F8/=IR' ڛ9ty E4?$C7zJ~<"8d3LV$h T4F9э arE:~u @SO4 w#_TEbb!Zሿ+#/oy'f=+TR^gtⅯ 8( 0Pr"#ln`Y^<,95JEi"n}`}w|!T-WyRS ?Β^4r>l)tVYBؔZ!]y\?fD'gMwǏ,(Y|hð ZSd=`A+aV^L*|^k>mh'F!b]78űR5[ +Gʦe՗ 2]1J4hQMܑے͛(1⛲c;n1m>tPDz-0 sb玎^o[bde|uWl D&&kī#5}2HZ*!a}PuPA:w2~S!eO+*: ۋ.m[0FB oιndzn,ߖ:^'Kj:&#XϜWё|YB<;i,o`[|a-Iak<3F3k'  XuH9eYazn|(y>ΦvUX#1KpGrmbDF,7ŀ[6pdo qƈ_lS܃Igv^]8 7r G+5ѧ:Tg(^K2П㭿XMA1.1I9!t塛t*vs@6{[FaL;RWC^( 739 HuԺC++w$;hb(Ʃ"ή$'gER VdZ 줕3/xEPLfh%"dbLy`՟S3ƫ|E|dBsj/o,Ka5BWo&`4qk V4 .ptsRKp2LC!^6b7hA q$6[/^M UNO~Q?{O.= fCѷ>gݕvow{n=pll`z[R ?[T- m n rQ+ئL@]ΐ~_\*x"J[& o] ;koۑ;$-[!>u,%AGo V:njͅL|X-Aդe}%{҂KYklZ|(z+ 4U96l@P wV`_ҷHfR<8rUE >(1˖U |[n)Be;OـZw9 zsFm zM&wf.!X[F%)W<<*UHCeZNcXCC<iڑ/MTtoyy jcXZ S@$k[]U> 9v(N$+I-.Cڔ`׍qB$QuV,lt`2 f*u:RS+=1ČXd/][L4lWB$:S[5kE)[L.'K1~PcrG'S8'an=o]0"ob/[&+ [XR1k{o2xݐqq_$yE{Y \Y)뙮E)W2=)e@FolPPE屨=9 Wu{Z!".[7ȡD?5ci|3 d8V mvg*= tU8 Laqb&se@`kVt_O+OUiTߑCywڙRLQi[ģ fd>ȣ@0NC.ЎqOn/|:!A4uC"59,*zI.iVa1(N-+cd&o ^Af-|X`hwi}hPn?CV24$AC]qxa[r@&2 - &(~5ԍUyH3GvDd0iAplZ֣TMaߗWSF2HR48`Y S_I@! W;/JzX{.*g JYZ4\^wť'-Ъ(|JrЫu86B:@'w> Bi#EOͥ&cX7o&ohL@\UcyC!915EPNq4'9  r ǭv3X~ؔ餝Ozä}/zgL0 " : յ/R ^Ay!cۖnRi{V)[ZB2nǰd|v"fĹFhIj6%":J% A ?HG•lȹFIފڞK0Db?&aKLE;"r9ԸPDݭĔ.Hӂu#=FhcPKg8ij CtT|#nT"wSSÙZPqdLZr懶X;O>YP͎wj5;@ LX_|9:RIbfڧzp⪼.1%E*jmYFRXL9`[!; y^}ڜ c0)9vf@I]#H-C>n M zNF0[h;&JLRiO(=!AI=(7wa9!Y %hIv8sJF V~)d{{6̖ݦi< һ]g<\|fO' 3tSM(P ={QNo[NE8d=lbfut+' XJ)R|؊O^pZ E I3OYu)vqBl4yJ|Laʊ+,Nzz"gl].N[hB;th1 x0/$ψ(SWbP+6!e-`wk@LαE[ 욊ʦ0R'/ɭ IPO]4uB*ݡxTW0,{2Y٘$jr9<ئzx  J32*b699T{Z` jJ,ϾHxո,ػ6?|ĩU\ׯΌ4Ở!y˂*#uBsk߇{Cix"h^' Z'_eJsN}PhW%o.q3@5"S4.MǁD2k˝6AKfB#/RbEG F})GGpn]S:6Ojb~XI\T%Y tI] ܣ:k.ʂNR,0NeC4B#9C?WdR %b8?0_뾓L]It&m̅E`בeR a:+ϭՖOMU![PIc͍ə-٬_Q saHۢaX:5~drc?_Lóv %nTrwhu˰ poCThYstBpd XI#tY1sV_ /8`b(.;U^|ђH f16!_)u8~Ajg>t\k~p! (P"/z=8i ~WtHU՜ Xg9"ϦՍx dJSe} [?T=>  w N9Z\%WOM[G2 "C50?2@DVud"#6QDU\A`P!ʱvz09;nR \?rKu ۼ Ml2*? "?h|h];)VS6tFtNڏ*C3=V`%%f5u> rOAȷa{>:(*--|K؆#ϵ٭'ѓQǦk,Y-8¨\Ȝ_&aJ8X΀z6lxn~g"!][;sALXhBo*)#og:puGAf!"d_M~UlQ(ϯ]-r<--_BEnϘφ {nw´; z VS!ItIkpݥZaFhE^e.^fiq`Y1qYv~mza}m"odۛڴ]?b(~k\JZ|xFUk7:.~GįRB^&G"7Qr;Y}q"&TuPr: Ce K}y"ʳ.|$8+@tG6$0HʒA4)|(D+l_N }ݓw t¹HczZ#'$dA|l"wk1U HjvT%j RoK@u8գ"uOtaMQ19 ׭PJv[ߠndoFckC#j}Gz1]^)hD{"[t5qM]$ڼzpS?|Ά逶޿cUW+:M\H>НLiW/O@4|B< C<,V.^֥'X`#{EGL4̋aR12̟u=ܰMiEC/ì`z#{'QdzJqK{cjDiGdό>'G\uN3kHs2U4oE@=-n8t~INhx^;ˁ< kl+lI ߮45Nۦ`3zJ~|_n߻l#c2 Pkؤ]5`x "p_tF2FeQ"N Lpic4iL1.<f j;"e U@3xV.N-s] ;A] O@#8+Ӈ9*lvU,;){/\:>"]ppGzOg3lط3 bsn}d(f6M$LuN0՚ 0@mk \u ZM(uS\(% DB4%Prk*ݥsb6?2|RiyfCPn:9mEgYkhx-F$f5SB?&{nz ^k6 |I x|GCIܗxT FQ:ʯe?xT\qa+@.:-8r8AX |h﬘ҙ1u*fQF(;+2E?`|%4W#Y~;dX~ںh/צ0&~YcJ6_q} Iݴ"?5Xm[Aa5n [p+W)ܡwr'Kd+.NP h#FN.UhЬwвqkZB`p2/OƐ ő -@6 } U2ֽm:6+?#y4V̩cGU=.=f,qskv1>˽ԫ0?N-,RQ3t'LXSEElmJz4<6G:nS_ XD?~M+7W 6&;6⛝OᮢRSFxь:XNbBq|IdRBBGT$5t+vyg-xc.އ*.5<}/EZfÄGNqDiqq!a~uv,^|FScO]pʓ^gNf},⽆ ftv˧xByJ$c%vh~ T2^͵w]dYz'qʃ!?WL؞0N; ׽Tf7HHK8)kd\J.O1) Lm9:ޣ3g/}޲*:0Cۼ`܎WAXv%0r ߦo2u݉d!3>mKIۧjC_%4 pZZ^rڿvnmvu 탍C{VL? A~qEk!}?k3#bϞ%#ز\Ze0*phT-ky)_JSK)R՘XS|XM((R)l)) K?\M" BэU ܄Y8"0ƒ?1GJҝ8%I<'-;QdZh|//S9B*ׯܜnQ<1a+i]34Xkz#:KP^]@g]o|GMKvUR=oݱ=_#&Ӧds/-̀Osw%Sjy3&jU!8L,Mr_ ^ھޤpruW!ډn{)le&RR!]h3ھ_Yd3e(!OiDYih" w(&޹rRJZ^Nxó}+*W醹Οa3Pl񨅖aZTjޅexYFUuLmN~#:6!Waw7˩  u P-OB]S!lD'&5qv[F54b e\z38TX7wԴCW4 ˟؞o:Rz<;wM+gq?OW i20/a&A' }i :)I5;́PZ8+^#Pwr"m.tyG;Yž;~FA`Y!lc?}(<sֹ!<"JH~qX9Eh{4$6*biz'O-j7f[ݹͅѺc y$pnr eHeT8^4?["bY.nҡElLo !V{7gKlRzo wkvFL!I6JG$X/+Ԣ2y/To9K آ+}Ŋ@ (1E bv6s*Zg>Th_s 4+?lZ*rU@)@ 0ɔ-1D+gf4%;PX|[.3f1ֶr Y:#|?0򺆍Wb<7s3&Z[ilokcDQa"{KrT{$i}gI Mۘ PIR'ekMDQ+~Yb^EduL;g6lY,}%IPr>?l5ʅl|FB`F,ʤ,}h'8+?e%v e:SӻhC/$:MeU~/2|3ʉ]Y{hî^|2 RtlW57sĄ$(LXG)fN_i5*a:Tg|?Ie-`SqGpN\0kΓS N=[@V\YdO״-C<Ӽg%S\ B6fg[Wt2boJ[c?bo*&Lhaԁ.R@Ho0CBC@ B5Y|6YLk`22c9W;$*R1K*;{qLʼSybDsTҲEmmQ M^Vs]?]۰ ,1'>by 2cRR 3adè+Q;\g.3- &ɸ5pO6P'@\ã]piVA͵gtOjMt݇@"9 =g;0!19l3mUZ@y#o&gm=H cnnjfb 0~ܷ,?W{ǙՑ0G5lY,"/rۺL2rG u ;qSw_>ۭC`6e O&[r6:# Dnb,/b% nq.BHǑt)7GtKhmF˦ݕ2N&=̤ks9ٜPlO -Uzq+]4]S>>}TTNG;sj*(f?S,"@AJl&OE+σFt5 %T_e`mdǻkĜ9W'xfJ9Xdoz:XD=7t B^!a ~~Kױ>Lq>GzM"&{A҈dWvrv^QmUGY+.}a5c/7*B&qUGߠmff~JqM7COO6A/>lt % w }౭?o,Uz3$/l 0'tdfoPp-,Q#V=4lj^qE8 M>C.N SlC!N}I I .RCSйg~֌UzE 3(!+eְ)B$e̕nxd`5H(2`+?Wb,*.iENñ>jIHb;QB[L~wR 4(h`z)#).+Ajۓg4+_l9Qi\[z L?3d8[3;}w8w!.`b9xbiKVPȹ,S/|5Nɔ05 $ous).VYNžZo>[zҪ3]hcR$I.߹5/='͇abE Y)0f4(Hg\ ޯ4xRcJ Kq9_'#oaϛapmJbv2DgG! 2{$A!n^^Kx%M/n"~LpzuKt%ڟc_O.SRf+fɽ6lY7+_fC28>8P*v{GyCrB ?8Eߔ;yrNXKQmJ43XFt '4@iȞw8ofl{q祦v C'L\@ny<,3wL%++60(Ts@:7P3o QY]ut6X:rSm~&_zqQ)a761PI*Wrc"el{JBR]?VC{r=\$dAp#W/MB :n&UMUS/hը}1BpK8ۜ7s9A7Z lE+k:+`vkpL#BZ|H8#x5`9j1CRzZެ"I&}g$(r"]pl"c CX0Gg0-uW+3%q: ?~4 D oˮe2=VLrNyIJ{ich:˴ɱb` 4bۮg%C7,zy7omdA/U-c`w5M6r&qY/A`-aЯώYĄlO}]p`}Zv Es&}IJS T C3ZP*(Zc  %䶚q>VYn(Qh>Gꡕ#8s*{*.|T)ե%'K\6-ܭМGu.Td&CG].gITP(v7 6p>Yx'x~#H1賏JaWhKzәl29\L6jHHAvHRw{麛#!R~ -f]-ZFy9Fa~So \W?IWxd.d~R MZE~! yx|H,MRO&ݦEq-q) ne:]#~ssR/n{znSVG3̗H9/`Ū@H>XO vKt|x~(DH'![:)ggyŹ3N_9B4,Q[Q넒B:=̯Ӯ{rwaһ +[(])D`\d봷 ~E^S:F4akXəK]J<4:H0l& qrp{)unVFrVԋx,F*Jsf%"d/m+VSY|+ZMӭTC.Y3MO]+tF^G nT`40ȯ S, }EYlv&@M)fL7X,ϜMSϽV|"v'tC0*D1nGT?Nhd48ߏ ȡ;raNJ e]udOrB%26.90+/hF7ȵj[C^x+>zPLM:f<IG|&&;8WQualMUnUw"h_WvܜC? Dz: b! > 76(W6w3M'Sj^{ƦeЊ7+Cݍp  2-32Ǥ`,է˷<rr"Rt,g,͕)V1 v.*C@gMqb?JꃀU@/*+ᤫpԕ:va.VȽ cl*q$bCd777 gQmq'B$R۫ !?6]:2[#I==fL@>y#2C  D*帵j7~{F*sXt8>MK^gZ$!_J|#r r)f_)E4^2'@LOg@xj{;҂ϴ~|*Xn80tQbҪ_F͸*?)7J $PW g5v뻽̄D._ŏaR1[RJT!EPbc*iQ;&;Ac{ˤ݀ =zelV$);;@dVzX`KçWf;bwP_ܑ5RV Ub#5}: 'V-T(3Ӕҹ2:vؐ*Yŧwr\cOD}uf|ē:2ri qi^U Y1FkN@ #Mݼe"iX#䨵nS I psz>#8u9(͛p}u5/ V}Mq@T;^Uh; ^ndQ3\h;E-G|sY!֚sYv]ׇ/Q=gz88oR V#I Ĉ4l^T ~YW,r;Wsg2))2-dG1g_9*Q]r{enn)S>Dw>Ǐ/Wn@3o "QXRG&q-Q4gwVI=E8k2 e%QVf.vT2 18[^lI֟KXC+1 s}O-nBt5qp?UG#Ctr$ J=*2@f.^H[w ^ 8U<)h3Чcr,ƫ3'(+ L8"ю2df}pmgY*GH^]ЪVSܡܝ_)kP{ö;jgvaq==)9\bxbWEK _]^mN7ϴQGk^}4Ca9!Oz1hF{pYY3=)Z-@Vݩ ^;BIz=X1ޢoUj,"5rͶZZ~9=wAE8D\ ܼM~6Ja2`uQݶ WbT YNǕSӱ8cD0Y|Ti,c.CtGv?ێ g%dZnQJ)ͭ`QKpI]0*Ch5ad_z" FJQ[괌;3}SI.i== ̉!`駍'w?Y~`(Y&ݟws7b1IOTo([:O-p#_.haI0ӑɎggݸ7$Zܥ>;д F,$,X޷v4U" F듮6hHbHFMjB663 0 +%iAԩbI* Li60c.slw/=l@ 5ȷ|\4i(m4ьo+W(ۅޙ9;]AvNP;a1zSi=CIp@L#dס -:*P}bgP(@Շ^2:nDyxmE>Q5t75{4RW% d@SםP1Fޣ Zǫ%CT QMMAk ʬ@,Q6zkt F|(a3#&5|4"|<ƷkbM9z/j@*hyK (._&9fK*%Vb"n8` nW\ӈJ3kbnрbk:G>Ji8+^Vg-x߾%/ԅj^rn%쩲=N2`I$^VC un7RAۓz9,8 WjQyՁu8Ra>ߤgeD0(Z:-M\^B ɻ]Y2kDeea’0y2\UroA;3b6֔k23B:Zz>QHD%0JtIj [ұE cb:fnBS+YI-}8S3dK;CMptA pK!S{ xYfj,1cΑ69:HunQX+@bv6㐟=J2)䖖ӇEV:kNʹ!vsf~BC}TP(Tb6EQ Y[1)PZF4( \ zG_1LXA}ҿ ́Uc?vM]vŸ. Q=:l" U&q权z_zH膆C$ H0`T!xۿ*T1d FFobMԂtLHߋMK!mxRsH $tQTܰ*~*/r , !0,?N"4I}Ӡ1;o[eʣ&]B"*W7ߏjMIj5(e† {b:@~KwPw]Cn!ӥ,$(z0$\Tkl~܈h܂Q za2dt ydˌA8p mjZ`2| !Q{.bVNCo:Ѱ!QPB%Dg -uwy5c[3#1=v]F+ z DҜREO]i$IJA@Q 48Mh x釽d4&Fn rQq}u}b\Е 2镶Z ^S^fx,?*ķI`Ys:HJC漢 ?3zF&Wuf |ozZLI @{ ^8ѡ$(Qu=p˳Vo+51ȅt*2!95Ehpw(OޟM1ߚu[S;`$Re&wɀ|ƿ()[L6N%Ϋ4OPJcIJ>_!!ޙ >FAOUa+Să>p#-L9"2 pƁ 43Uس[l׋Y eFG%dm;Ě*)*ݸ \re@1Jg,<>& R v4˿>RϷnT;QXigd;b*` j/$tje9]kg6/iJ)Wł;$aQg)RNwML68sQi \K"F X&B% HbۂB"g1Z'=]kAcnIw!'$G Ѡ]Q? ]ՒRU;7K?a^49w~-a96>L8?Uky: =sE*ʿI\e{[T"CV\K߷ N~Psu1̦kaQy1G9eث;q53a58 +TB@{=~|;% qأ#TYD:M.ۚ{6[mBM7SV@"2m/ʤ.4`>A<# ӮF<.t)j)Qk=T5)" P/r.+-M" 6t[w {T .QE+?l*I'%X}JHֈ5e;w~ohPH oc(~1~-DX}. 1|w_aӎ]WpqϺʨ)c:e'>kܱ-XSVbx )d7+չ]Jմν{iyҫz:ҏW넶etS=r? 5hSP{^ҦnH%anN7UO'| |ʘjϲ^vm֡gM;N0<;1ql*[A8 M97>BO2zĚ=qxOKm= LLn˄8F,n,8I$3;%yeVX&xk(H݋Ss-MV DXuq$Iܮ&3ipGE;7c7a(VE3RN})ق|<8ZX-w=.(։ u'=hQ@wPye;EPϬbF<*Z\aџ<05T3te)1䬫eS&ك%HrAM,_$)MѦ}1MEqHH#;1Z~H͞=(~/g oЄD0T^ZK} }aL7D|B-:F=csK\{\ۗJ!(aifq{ IN{-VOHHA'?; ֬cU M~Ҥ 4>W!zL2uuoopk'|8O{ss`sE;mb*e,y#!cND4pSE֒pw;O@Y6VD |5b\x:TV>yx8]C<ձH& 0IE4;&ĜņE,/= ZMX {m2ѮWyDr%cbthe;nS>pzx]6d]+0?Ui  =pjm]ژW}^N!fw Nvap,S ͬƄKmJ', l4 SZ- :UIj9stm@&xlaAUP+y݀kQxs%!˸*F B&Q7v:Q4El.l(!Px9'g33AQ-{ȱzYhi-|(ףE{t즼LӊH $u-\BԐ4EO7fx?{a{>wRXQ`l:mR8<0%Goz(|PۂNK(DoG/OgoO^x8|s[H~') OňY%6?,jTg[*:P< g9h3"؝Lf;i͊C^_ҨƟO7۠LAxjb ߖuZYu*CɉA&y 8{Y{kp\4Hz,o U՟P0m$yd#򷱒3Z0cH;俺~˧$g lMе+¯gKA(_/%u!j S*(p(pdEOr79"**NYE[;'ɜ \XDOt̒SgODhXƣeoq%=.qi+w)hH\1u}Ju}aӣfcz~VhYy-\T&8L ʓpZ ).4^n֕ķ(;@L2}XЛAeyNOD/A8Q5GŨ:PQaCuAvn5 ï1 `.[|I⡄c!M pO,a O`6 ~7YK ֑qop ˅^ruӫ[Tw\q줣b`|Q?Ȭ`h} oz%7ueZp2,0|}O?WQ*S0"x)znY=C;=nǨ-N F9:7lpV"RbX35a_|>oI5${L~UR'"q$$nlar `KY&-A7TiAgO k?Sմ_f_JڛUEὶi|!jR;j`&S~Cl¡(gγv+o(kcC7p(I06{lzfL7/XS|OiTe`Q^tF0:E쩺 (Ei} !R,0L%qNn|+4n5ˍ!O\&F?dN[Փg?~cg(_oBxֲdhG)KgO2)0Zh6Puj̗^8N,f~#sZ7QuhlJ{P􈸎oU _G Au "Ob/="i/~?ދ;րp w^TE=\{SyjηM0*Ly~ks 4Dײ;`/Eԧ,5|˙'FtՠkL_)[{c38x /_s'Y>>Ȏ}hSC2Ǩg!i8hhJ*p4sSYVvμm){jKG,?t1alnM{j@EىQb+:Ȗh|QPt_*~~Nˊ+0xwzwGbq\QOԊHҁ1ܱ̓UH=e)G[4/ $MRCs-l:'$n^D,uV{F?‚Kou[YgI/B(`3QŞ’bF#z'NNoHؽ&nk;{$\u+=T 9Ϭݝ⟡'.C~a)~ W&NQ%ihEͲiJZtr?476ѩn.}Nj|5Yd,L{x@:|UI_Hi3sWl.tqXߜ1Ierʉpx7v-vy<6n.-+m#(WJhJ -R9=nS-BHJ]G$P|Ks D"?m+Y0S_@Ӏ1E+ԏb +ʙ\ĪZ>I&ˤ"mCRt[YpG NuҪ$i!?*T KQ,9 ucCS+)vR[ܿFm.DŽu Q 5a G<QElaa wgϭ#⷟ePvCC/#ή ]#^4RݳqԂP _t#vZ7ٮW;Ƈ{1> ȿK\]A)ëyh @=?NԮ$1;Dcxwj%Z|@2;eȩ`6RHez'Kj.I %E$

q>mmWe10onP@jkcb%]"~Ɛx@537#n}7QaNx~mA_ |)"ANeԠ7Y&M -~e'q%*z} ',E 7چEe BqZo.8V :5rk;zKF;{u{6|dfgk; p ;['] U!7>K U_!+tS ]~!~߲K$c:Ji#4LZ5m9"D ºZH122\[\Rzα=C5S2ox"evZ}A#Lg2ԓQgf'@F=LdIxY,E\ 5ggPjEj#7Yڔ} ˭\Kt5dhW)o> Ewo !M\Ҍh^J@|kCfRu> _o*m:4Ti"~1[G s2bmME`+h [[g A/p6(4tI`}-wqoOm RРx̵ 8CРHH\\…|sYt9eWX1]%6Io1 ǫM'8|9{=&Yr)00 4z;v9}ݴZ1hWַc7sCAI#r ӵYiBNn4e R[c{{u2L p;SDgR?uRcԒ!dž3`EUXIw/*}:,QτK>VUY$8;l=pdǹ 9^CԒ,e]Ԫ ! {uytwbjؾ58vѴXg"I86 8q:ԝrq-0qЁ r-49hf|KdRaimROve 6bY@YLDM_IB-WW.M8c{?w!hSK&PxZ$!~%Ab`139( z3xC}`[䦯t wuKK 6e bV?! F0APᶳxS!K5{TX;\Biվ_a{\'m Q@L?ڱe[Sn ARO\|IQ`-[ewVUgSm^X磧LZv! WCܴN(K 1Ԥ[t?…Q0)I.Zmfj)g +bCfgHt|($irqv1Jڻ(iuB6J9 dT-n-9X=೧IlK{ʠ̪2% v+ rmqF&frAYTN^\Ohghf[2-ljcO--@GBP\lhR}md懥l|p:=8NG)Ci^o/i/M`F9eG/_r#ˎeJs֕(ω}p^\0J4md_$c?Qhv4pYgUcفG,,ɉj!ok;Jh ~/5.TT Xa0[P)ŋaT[ʛe@qKYaKʢ9oqg`|#eB^l$D42g0y~w/e ?=?V~FT-pUH;,n94󎓇s'`^#Py*qoT>rAmA ԂKO ("_ɕ퀣!!ݬb\oq_QGБvSez-9E?ITKNN;]DZ4}Lio7*J4cZD-L=l-t]?۫Ύw; wz*l ,pJKu3GQKaUBN178xVw)M'9/2ЋyT~}<ʪi-Tpbjfw$xCrTdf-x3Ö`pZxJ4}`d*#{`4Cݙ_loRB%xl(=s|6dtR$_~Gełn-Ճ;C$Q!_s ?!8hH!Fi83Lm4,bR[rHDCN_>6n ,ׄF,3i`+meQ\=h:ŭO*@~.يrŇ6n1%qardKspjsҍJ1qG2n~4y^t\:O`ec"ш6䆡(mo .Wdk-lK1totGmL_1GFt"Tdk,{E4Io(HY,JA˺B6ĺX[QLo#G2n=EH V'YVC~yDK @QgY,ɵD@p~~Z,tK`iy|WJݽwR(GM#ucvݱs3{k/+>D{]I0nFEXa-"m%*I ToSGօ(;5-͑ґ2ύ+> g[U*^~j@W1UypS[.jQ۞Bն(wH,kvo\&}@:)/JUҟ|_* 3؝"v!sQ%o2ads鱈ZY/&]22#ܝI/.3q۽Ra_');8&ܾ 9R/֏ެ0Jy@!9M7b(=wE6JI/t#1R̹HWE <,09N2@@m@ 9ajkby{P )T WGk̢n/c :_FijDz;_vnQs)h3S[w8g~ˈp=`R#V̿IJÝwfW|#=l9` 3ߣu# 5,!Oe}MtpM7p^3zQg51\WgH-ٖ=hY 0m>1ٽᬽEF^$cVxx8~UvgFQX+@4 VΪt#, _;;C"͔؞:6DÍZHHLI= % Oۧ!s * 3ɤ׶ffQ 0M~b:Lr1]b#gUH9"(r7b.ytS S U݈הsQ`.: 霃0sBl1ncZSb -gEd o> nQD* +& D+gq1V?(Ft-Gk ^K(EJUKH~^D;KzKm|]B qC!C~-% O^*z hRIY(Wn+;8cRxX2PnyB{_N+wBk3j@~5/X#U3?`yt&+2A^Hziz`8`[:SCV)S6O`Oҷ[>1b7nKj=~Q*b.q`uOD|AΈޞlx54;% \*?^` k7-ԇ 4WNu{aܩ!O)槱EuVQmEx)5#$cdbj8{ӲSP1*md+ubգ,6DFp\s) P<p"xԔsrA+^~dҺIupuA1bi7!bF%qJ>hTI)L'̎(8b쑳GM>ך :*^{&grŲŢl2c8E1euX Q!ՀNIkƌzp>+d%ºw 2XY5R?v`i5A(2>tIp55`3%ċ"0G9OV镜T\ Bc^qC{:#$8ZDN<\RI1q$v@ pV%"Jo8wKf$*Ҍ[)O8hh"j+ alM-YH{Oq@><л en'4vֹoIFnD(&0o =Slk}/l[ '_T7tqĢ`PS%oR<+\zb}zqN9Kgb?9;N$פV)<".MM?!.?Pl:j3EIM IS* S`/\!Nei|*iM V)=QV~K@kx#ū@Q-Bc ɻ%]r4$ҞGIWC,LP.MqV;WqNuMF0gP/T&Aӕ<1s{QЈo\t?=X1[w4H eX$. zx( Knah?99Fs3jJ1HttU4gYҰndB9"B:rA3SK~ 3camd6i^_ $I{vqbPꦣWf9([/̵O iO+%c7w)wz 'XLs } @ńvtwnjc xgyE =kb,&J9= %L5P٧zͨRqT6sz?"wM]bvr?Sq>> $j.T'hSG\>3)ʛ@YThηO\6 .WG G{1̬ !ڕ g\1Z6߳ M|py2Aj3Wy*r&#Y:bamzkZ- [j{v~t[ esTI,g&]0o=nr?q'H]0 ϟBX6n1gwYmKe=ة47XO?sb;[$C:?=7o;?PHo"Be^O5 TɇYbh>ƋL!25?r8:'4; πHPM2xFwrFTs V}~egu- ̾CvP@D<6G&+X*07 uhҪٵ YHKӅ*+F0E:{D؛gUG "#'Hܥf.(--b'J5P>.U*b9|NªPoPR}_ߋyJh`i$$_F7_Nj wFS6F0y {K87x̩d湋1!v5%WA3PHu`2,N`V!MWݬ\$"64`&丶N d#+w 5zuw/^(^4 4s$&s% Y(~>~<89FnހNV"EAPмjK_V%~ EC(H=vy0^50YdsJu t(D\lB6x̛=HM.ʭHDb<.c μI80J1E ">Zd*= !NL8ZoHE@J~7[b`5ANI붽 2߁>J. s%\'tf#0!=/AD A <۹X"ɥ24au eAҔ?e9+z<9(#B?hPx[=Z)[~+fvDvSҏr6 +gr!_Ey9|L7p{|2*9}(?fx"ل0Co3@0< H"%KmUo3RHV2V\',I*Ct_t.ם`ϒRt r %._}oF|(^++iNQuȍ ?Q;7o쎖)<M-`,҂kGw=70 ՙ-[9@}+\ȨPo+Z+%`6WhMŠ0Wӛ^O00筀U 0}C4{b"^ J?33Vڔi)<' M4Ȣ=@ʑtp-eW5+-V_X*R/|zf/\'O J M7gӄNn_fyti~~Ph,ΫeI=E!a?G:hr:q gYW2Vr¢m!l:\SF>cx tEAٷm2'rӽY2\Db kRF!}c-#4XSO_kΑnyav,;/2Js4;;6${o]\+yѺZ7/%>na<jpkfQPQ,W_~%mM$}1F⒅gumU_F y=_G(|71t  IM#t\dkkM1Ǡƅ?̥?/\jV^Q.Ǚzniן!å}yr׆$L>8ByneWk?3~#!b[/i7蜔)RLkCry|_vA7|6s}z+`}>jѰ*_8 `bު; C p@0<.duD7+c[ bb%Po;Xl7%#tk[{qH#ԳmR"wU`ɾeϹ|zsTʪ Jdjgaΐ=?\1LEq R\dIaSkYB_£X^sk3`)q$K=YFWlTx5A"YA+4y8G=$9K8CPwf"7䌤Ti'U!<96-KO]픛Pv;\ 55Uc0bܖUm5r? FᝃҼX}'`40ڮ"S-10L+zd"m m.cȩ!=Fft,X]Y43{  F)ĠDrӪشx<8kϥ/R:=e#.m2hKU@0Ҏc7ӌɚEdmDbFمi#ɼ+UkX$yd=% e[\N_&tŤ$y 9aO<liwo,/U{s.+-,.%_3^ R),sw x&1IP G,2BʩV8[}[Vu!u1֚ߨuO0R:󏡜H :Wɗ;K^5gjfCJ۽ˣ.]{}@[!{@/qG_/eGˆ+mmRBbi¿Bwh$Kah`H QIqLJe4zR+0T˥UjG0 o>BF۩Z'CB^:ק-$}rD ̷Xj02 MC(ԥe6d['be0X 0Nr|vI6reILOA^kSUg' R_멻nY S~OLGǫ'~H|ľ>뾂[i20XnCBUj /+V>K873 ~ i pç7J[(zܰ*jXH%֊wo|~UJ{ZZkeyҤ#.JjO`2fUCpF?.}Zؑ9rlQSPN&VV#_"ǛW9\GIXػ%"{1ƹiA҇'ۄ)UXfF2̪"aF,^^~y0v2K'(Cǣa}ӁV+߭r̥EgW=5 r=R'q0>|h}ފEmvK}#|;OZ+Գ>O~{p/ȭ&g5"MC2{s^fǭxIKg@(}OHh[ nd2cscQ#yʏ 5k/r|8aeC=Pow\K=;-Kё L~L8$\6#&ԁVg1Cd9J ><=T ^kdp֞笌z06pI3 +I `pY\e_3l/i 1ڲZ 8gJ[lRЈK0j6śm,y/GwA ֙T*SŅqǁ3gݏ/'A0Y0Ndܥ*R;#5^(~m}/kݮ|!YؖCFc;aRE^R gh{%Uղ~AOK8pAZaik3_ag $Q^5y)@İ1*?u) sZ,#VպW< iN&lȎ ZbD>OUdJ0!ctl'>l NW2%bD8L%Gm2Vp@MR0%|d@?Ra$}ӿ=إ>Ot-aD̹ҰߖO״xPO$ٕh4{-[uAZU5ӆ F׵Qϔo#[c1Z=3'Avc6b E HV<1{1.c+d~k6]qb` '(Fd, $aD=1HhOzJ)&N@60]/m^5%ΰNw.+iAOCCst8ۢkqߢDznPac]iU/.I5)E#4:- f8/}9в'Y )]Ln{}ȼ\mkV䐌:_F6,ɸj >+sEtC1}yJ-lVFIrM8y-TJw1yt`%5䆻~BϦY6Dj0jS$o9N@T_;پvbQɀ:OGAz <:Ydg=Sʬ7aSzsc,{!0#@T9_p!I1=, |K ZF4\$Î\)Gɞd8ɄqPdm`Z uL+}υjqG^ I{ԌoA (]?J" y݋$7 u0uZ>D;v+b,Lnro8U D΃hJ} }ϏiXa5.k,w;4V}Rٗ0(TR_*{8/,4F鏰ؓۄ "Ru)p0?O7ޢ81S|L"zA (~<}}̻݉_KDevN.46Á0Hߋ*rNjAllNPi,hY Z9Fk(T'EU_-^ D5%BW{T/tmT1v=tW oWfT h1vo6'>unA$¬7 r p)SFZnPJ.Gi&NWUZ%r ^anqLajٺeJwi@>E?XPAKg*(;c5Q: 9nz+i0k\qUb]HJlz"G?F iZyZHD1yU"^z|]x 6M{w$^ +ĭIMhkA| K2VgC- bhfM] H-5OiO'X-cLQ]mtT[6m ;`<8\`O_?W4df qQ_SමyZER jYes(/ɞM\Ry`Ƴ.loLN[p-D~E`\^oA}2zVI[kje*7yه3/4K 38J!sx޶`^CkK;vV{X둥NKxeD wCDzC\RQ7&~ۼV0}<: [bӸlQAtxT0cұA5,t$Jd(xq}[ ;E*cȍǼΪN*%>vNiX^ʰ~%d:FS[^~']aA)B7o~u43g:i4˲ *b˶c[hk=6{Zӧ5r%JqR`^|rnS5#}l/!:prvjrXOs#Cb dlnwXYadTl qbC$,{nQEVv#%VTOO[ BU s& ŵip>W6%K YARk*-io,sB(AAnZHktoz%q5G* Z7S|*!dK`%W _bӯYuMd Wu[ 4#wZpE(|Tl"?zJ^%6H-fv_h?d-$94<ŘIa+tp.QB)l'@' Wϋ$2"QFR?ҊFj08&M3ZĨt@/gxr(9r6`q&oҘFd2Px-)}&G!ù{3"H k黛Eey^?g S^nKorryьOXX1/Y҇,m"\UWS V΅8go?I*Tg70;kPM}gILBIwS򹺸߰s͇`->9-ft :ukQ1Rwwx8M;:^\#~΁J5t<+7ArE=@"()ZBc+?@=:زvj}*/ ~jA]K⯄tn[&E1ٝѐ:ƒ̗$<rWLO'$p`Bq]6<1|Pk7QSBU*02t2)[k1si*q>\o`XTW܉Q%g^ń{1N GQG&0У(DV,>b$L~8'VxGg]R4u5Nh2fR(9a23PC}8 KW؇aԶL_MM:%*Jm~,C.m#A%+"@G'ӑ9Cq~X XY!cⷣrXybӧj'T/n"6WޥϿ -B6Kd90؏i3!NxIYè 8ku+DFPyZb0mٞmo;gm썍 Qug1rB *Es]16=ثgm+1+-rFtqϥVv{ڣ[! xRAt!Wj@Kؠ崝BIe$Þaɰ{wbϘ?Y]i)[ڽ%4j"ilL*͖d ?SAX͑ȧ&a MtQOMԛZ'ɚc5CWzAQDG@4c*5a"^xb'\g#={ļ0 ]kr U[d~H{g{fkg3mϽ~z"u%\?ռA=k7.;!sV%ԂSe !nJ4v:z AL5@NLع  GUAء0' MVKFաEYX Ҿ6h(@dzfo~>~gbeö q2VqmeOזo*La~7Bd˓e{kr,PA%$h=]v$BTf*a|J~L0=-DL @sLjO`" @~HϾyPwj:~ /;-&7sD#A~%K&?e VJ,ěVX٧t9i^W~*RbL'Ta% ueߘk$eq>MhNV#8^'C׬xBpp(\<wQ ?YC%%fҸmdͣ&Vͭmv6{hh!3A?ϔ}v1e%* y' ӍpO\1 z[:+ 4o{w̆RcB^cW߿ {~4LӓmEZ)Wx a/x?O; V<җ>HJ@,3:ӱmh2cۮ_P >&âh 3|PO ) #?"[Yv۴ypnڥ[X _*ܲ4M6^&@8EA︳"Y8-1iYYwERg1XMVuS;gT6oqjAU3$8]uAҫ~^gndPV7 6O^K8F*8}ݿ=YLwk)&hq;WC7ֳmt<[ sK;$a!ͅiSL]"xLƠ}XrDaxS21h~19wf7;#&"]inWƖD<]j91G*~gCb s,pPVX&`$"* [|bt%d988UkEHW0PTWYD=@r&3&G.oeOп<cϠ!? P0$/1 *JAS1lbGDqӃHD[yQ]FQ0S?&pREu'd#&g1%%6`Kjz{2yԝ8)x] N{-U8RNe0m!M}8SCئmOF$M0-BcA *3Ƙm;vUT:ZhhU0vJ+q; z9)ZIEbmk7q|9̅sC$ ! +)"OwzZHM}L .TDςzӊD )xbׄ`HO:|ރy] ѮT;N{l\=s+|aǨ6ޭ̇{A uaV[S7aoA6#tE-,e 6;'v\bz2|UYv;7ܹ6~_o( 9iq );P!-jmTCFO'k^u4-`kg*AsCR#˕hVxiFH3{z[xCЀmfzRo [MtN<;G wuYbTl.)$;傁`-8ޯ]ښ8ູɌ&%ub6g9J94}ndt,ԗ}Kᛔ29F뒟9ۡ}#V/U`M/PJ{m\yKRG?S=~Y P}ce*$e z ([.&&Wr (WComz0 [[g"oy>f0W>+F1Գ ~oǴ$aRA#hr [RT>>o\,uxlnV15Yd sW;cpv\~b1/fKO&%# jε0RYEܢֽEoPB 2*TAG"#Lu_}8SimY],tDi>i䠻~ `6|~%P6bK}@[y:ƽIE* ޖaꥍxD;jj2 1U7gJS1"yGR3x0kEU7,4)YgDjKY(k3_B˦@ e=2PƝ@-鎐6)iP'ʰ8y*g_lO>5_'!W6ӆ>(F`{; œ:>y"exay 㳑xf4:VW*9˂S$*_]BKcl7'1# AN*Oi|DCF.hHl$3c5%k63ِM/ͼ^2unqcAD<^<|{N_’PI8LB:̉({;GuN&H&;nMx<]St~G+tKjI@CN-J4ym'u\41EЙ?s|!V9B(M6bpѡa2CrpUdߤ=\z0ivG .CsߎQO>tMR2t6r:rpj^|;ή`-f튟;G10ը0%oi&K(Ѫ"),@؈)p勬04@!ݱWӳ@;T /r'9zJ_Pӫm T]!Yt"+G(өr=cn&, ;ƈM: %~Jw G0lRk?8> K<ۄ* ;]bq?wvfGo=G|ȬyҒ잌H-Ϯ?wgQX<+qBE>KȫD/g -tT** [vo+XǗ*Zlal)rӜSy{_z􌘺Pv}h7? rAV"$LuvT aĥAZuoEtʜ1hn]ȕt^-Ovw] 7B:Ÿ/SMpNCюxAhzp0@Eڣ`.*wq#͠?;+Z! "YqƑ#@HZ?5e$J1UU>5owFͪ<~@6a. \pa;T5 aQfհU'Donu$(kU ܯ+)0.`:^mYvZiv3[}jœJP~ ⹙b˳Pgs̷cu4<)<Wb3Hβw ;UL*d( Ȧ=QD_ YzcVcT/ mIiu:H)q@K!z*^|L_ؽ͸3%=FDЪW=piCMM˥g)a=%˒=R;EvFsGi!kg_٧aGIa\4N drP՗AOG^;`Q"g]rf؆~?o1YABbq*.P$_k}߳ubI~uC^SgtpX A]IRfo/C|'v"! ?L~IZL)q^Su /GKj+r ‰jL(*X~X`oW|kqyUb CmHybm*x4Y7Ξ10ꜯ}-|[ǃ N! ӊ!<.;'h4xĠ_bF)LWQzd w{Df?ypʾiYε")EN#?_=7ːIPۀ?1)($2܇bE҅}yT._p&ŏ;|%㍎d] BٌsU73<;,zK5,U~|60ΒX & 9Y )s)ү( Aj/]drJEx=gO CU[mG:Mf^ܴKħ+_?UjFpZiG,ms7!fxlwo}g='ꑺ}GX-J(x_/uk1/#~~X$z]h㽪iQn ELL vNĹ'U$Y05GI|ꚾ–k A%sXCM,XN꧌o҆ ޕ4i"'BK C2^sfC@7BG$.dy= tN5q?GN' "•svb pzF|BZ΋f!lv5_`F*iެ~rRΓ#ոLj-BV>M&=m^Q$#*Z7u Co?^P gG2DŽyN} C(<ׅjGn ȮR4RGvͪ;!*ԃi ~pMN}-<2Q0v \)Br#yK&3){2yeG2@SʺeLď!~M5-ثKsge,eXߞ]7:rATvf.)KdUkG$תbJ 2ʚ,8ܷ"RgT]wJ%tw*CeQН4-,˕81hY߰4Rt8c~ FgZ#$0LשFĹݪmw: `,>[1AԮvv-^gP$Ye"؊FfUn@߯0eFa "/ qX2KqAO|."A 2tZU0O;3~øRTF2mte~uV #* Q'sk{SވҢ+*k_3~룃R\j0;ԃl k Y=w (-zO*S1+Dc;ZK;4J(]:nW`$k㰏LTEʡ_lŽ-Jf"b1<dis{> e)w3=<=P97GR{AaYuq"򂌭3cђ)U}, cK"mfq϶b(S( r9Xtd3OUW:{P b$]`hHHMf™yi%vD|-寂Jy'ojBnQ5* Hu@QK틾z`)CoY(Ǝ- {q7F)jdynJ9ND#a@}nw2Ww"Mf$< R # W#>08Aյ;6ytj $#H6^ɿפG݅y BISNo,Sg9##6y ʋ>U$s@'wbt]H]Bְ:]!wGH9?3OŠȱpuF_SC3~g؍劂w#:wB.K:dZ'UFɕ= cTt"Rlz ,u<-O4yY3Fz;{uk9d$;g@;6A֘9dU"H@(Л6( _կ 4:T~F2NI YY l=FDKhVzV4&a&4?&c"SpT >cu#^Bfl%46=|D1%iYgʺn׬Ip!%y <7B">`}AqzJIFa0st Z Ω̈́]J2sR* kXx2ugϬ^xxB @\r Ƽk͌r9[*v𓎔\縢K⑊|b)f1Pzڟnnhi,3@pGfXez#HDi`>8ˋt/'a_Hxk:94@z$x-=OEn-(GR/wj/jly`Z2vi;9zR a4uЮ sQgV{C+.k) ov-≪C1UP5- 1Gu?qOɈsdk' 8~#ܨپ$4/)_Ė -~1M9_,B |)|5$B:4F5zxy6XqS_LQQG[o6 RV/;}zO`ؐ>P$|\;xigI%,VVGKu-M8li+q OÂQiҵ"OHzWOFp=2x޻0e{d[s^# |OLn,+6eRbZ=v*|$JrGpBG?r෱Q.H@; Pzr), x۾䦉M/je'e"=N@h,+ +id َ4PZNvBP <WfኄcZC6/&]{eϕL\wÝ!)m_]CxM3#J)KUd%Pao RܬIxZD{ܾK@6/"|jlY?IqƸ-k\Pd )aFI(9^(dcNd_VǑT;ðY‹>wDesqpUtɰdlBr!%(3KtvhxٵՏW~av)Z2Ytsd̆ KW>?vaQM*dU>Ŷsh6 2aŁ3l{3ج+RRF="F1.dzCـ2KD];bx Yvf>WBJ?J5wL0D B]u4"N3X*"X&_K95[2+^[QɖFL۫ 8,E9hf+kDR؋ \8ˡw0W8_7 w Z NCG~$z@YXiizl;E|ۡnɈPX-ӕ?55,:= `L<&=*YR#4x ?4_X*6jx}[fiIE=l@[c>l MNF|FJ {OnEbjAeYŚ mpɌxRݰ.K.ӅKg])#GQB]m=c+TB;%9îk3FB&!;UNM ӛmeb4%<' g65U2iRpDX5qTKfF7 Y-$yӨL+'u=I-G }?*$fgP"D`_SnS-('qxQ흥uYhy4/h G8wtc 2M;^0]Hh (Ϊ(RĎO S\.jo 8j 9s`ePzmVQaeIC)wsKL@ )-!vx$~I*J?%+od|Hs Jlþv N}L=JiJ`-KP"7GݦZSa=֎! >{~[mH2^?@t4&vֈ=V KJ#sWAzܯLi}𙻉}"C$=C8++ġb' B=KF4,NTY wH1E"Pb \Pw> .s{f%c>h ڇ:D7bڰkLj:deXHx6;Zjnץ0JF!iPo+"CPBaj̒Hʦ:ZLm/oT=`XJpM&u(h!`o $%H6ȼ#)fN,/^AlMnD. I!6I A1pIMǀG)U&16@~%#Au1IMv}%ŔO{)i˻eh*<j[]5^>HWu}?P0H>8AKwƬYqsؾD!*"KTSHdzꎂ=11R͋)W% ;ATsoh,cOv5 ;+3J{wyyNR~2K8s;*qTRqzM㎦*gWIɛpwN(^տ܇BLꐉNy>It`'"~G>9͂i|`uKٖܳhd?im{;{8?CDFNemOZ˘S1xb\$-߃Ӟ[ bP? ,,8^U1#jMef%qhAU1vyos3߿PJ*T%+Cw J5%U]}%S |7):il~'5@8 ?;IL\G ~_zen-3_ŷTU#ȼB@H^嶵5lt/;C.8m;HHs<9P EIRd=Hlָ^KQzNM64$Wd{T3F]vq&{H~ܺZAeᓦ#tje q'Ϥ%"'!&6=p#0$@w\3LNi͌eS7C(}tAR>ND/bjb^/nP>s ]ZL'? p)ATt=aAK_[_D*Xm>c D;f ?8Ufgc-aBj XC; lo0H/]vL THYN7ˋ✹v$\<G3ɫzc֠0 V(xFOd(BAE NYP[vtU%q.qDhܓ9Oa@3xY TzǤ.@Ƒy~% kJh 6*jZ̰uneumOEV7UȪ?CWW gnRG'!膋'JY#Œ`D*T|AxFq(cR%SN;N1  \_bȭR{b69Y|W^yhZ])?ߦ_6R&@ n '6 Uoذhob^#+b2^|@F4?03}|Kĺ#Xޒ):} %7o7J.[4h?HH"77A2o{$19pce8Bq#Yk _wES L]?ڮS|mA̅) PBֈmO fB[ɻ#"xQ!s]:u|g_AIۻډW'Aᇌﱫw/sc u40Y(0p_E+"1ZFb&y 6e=.[g,V{XPWMb`8ֽG-*+ zcȥqĜ|Gϲdȉ=fug"0(ˑd̆[ IJwqV,rx.K .[氪!Qv:7,ݙ mL[?^ET"C}_mزFhL.u@8e`Qg<_UV|/\{qJ3|nl'*q"ú~$;vZTjPLa 3Ffq8{ BUL_.?,QlY|+q+Za#kLdi ]MG%Gb=k8ǴaA U-. MВlMz-O 5iBŞJA*uB' ,Y&W2$~`79-R-e߲t3R¯WamEV]yHܸi {nO(U\\'hsJ~P 8Ėk_ =Ixՙ_}ɨ/>n"5%!q=>gKWRMMEtUWLL/) D&<=0>C y9CȈ]!Fu*a ĥA)ZN#Fm57@ Ŭwlv}D>ޓbHHTAW-yZޙè^e 񎟁jPrqjq9Ł_I*KKp Y-ZC/i&{BY3Z;K'<5KЄT<Œ*tޘafݫ,E%]pn[V˸T# hs3Q`G\$ai+a켰 Ɏ(7qT&/YBb1#o =\L Qsh$SCQ g~'\[*3GhYZݭ<{4XEKEǪ+5Ko˜ω*hS5N;TBU/ [OеkK'1W)ɁohfR f`r&%դtS@`_3s;q>;FOkV(ɒìGӓ-JƽpUT2 ImY݃OV#>j%,g"Έ\ pJ)԰ݤVݹuW$gQa*͙P@drV% '\; dvzN;QۊmjϺ$ [=+w^t]$!$#I`,p΢% a{4ujI8mRABA%2lTkIEmMa WhY42bOM*S0{Ձ~9^:_?3QPI]<70q])t5Ƙyk^$?nZ39yaE5.js$N!C\R(kߊahGR@-9b {|.#U :;Q%&iXEa 탰c2nS'Iw#M8]M_LUDbDu!X>fJr,rCIo|ݿg0Pdn9A}l\j~{(%k( Ɗ Ni&7tC#:)oFD*hB$7y t 23=a>%,Aޚk(s@2RЄtx)ť]5pqX_F]g_"ע(쿯xk9*/r7*߲896T+^vf>;;H?X0qV ۉL[!ۍJj$kUO7'~ؼƍR>*Ӆh. ::,B)YKfJXS4l%,RjdbvkcA~)o>|-eйh|El Qxja]\&gD~tslT!Qac;%м>O7jƪUwCǾٿA¬\QZ44 \sF#3 1LSK̞# +@1F)һ.aR@Ae~IFώA p[aT~`RoVHs_SpY*!2miIq&ijȕ S a;n { q'(|ҊQ @{Z\f&0Zis㽹Yc;pYOWh-o?+8U8\ 7S6v"!.Q0A/X;RB//xydgSbk1m m;{͂J~E6~cAU u9!Rk9+> K/wCӐ\,f4tc Gؑe|1(uZO%tQa!^98p [|n4A1v:E@˼QWF=nК0 cS1 xZ믿xy&%Ոӵ0D~4ltK$gIb-JS"=Rs&̆~,<f*[un0u 8DX,&ky1"}~ʥFkZYBb;|&bа>NK` LR,-uiM?v [݃rĊ/QshayhBTFCxz!)iNpr9)g ))Q 2TC26w6LU z&LNñI}1l§+ZE,ԣRR+ȭ NgFSn簶glsM%+:s{ CF 9gz.:մxcAJKԢ` bʾ{r͹+-2vB&Úɟ\͒8tk:DC N|848th$ք,RAFSh! MD%ܸ@< aaJW2; &Xg^[Oz3]ɕS{= C*DuUÔ,]5H2#FDNb>t&aDRCՇGy!?lB;Vz"SFw:Bj|ģ —lC?;ȥ6zAt*KPKkpkl x6bdD| *+<ƥKY; WEΔ/ӹT9}}L,Pi}d@NJfif^40KAGBv`_ݨXͿ`lv-ZRa"5mY-l`D@msG]\kݬif2d&`u8. lsd~F744h>RL%󠘛cm2qQNڵU`?"oIWNEgPZK,=yϵb(CpD2݀uh@&9~غbaYMCF[3W"e/[.2r$SzCJk ѓ~ w<@68 ] &]ǃjWƐs,fgeaץ~_7P{NE=My2,QY']h>=4H$As/̣T 듾^Td",7\@5(U /W#(01?^  ԌMC6H%1bԂ%YIE=!ͪ]Ur&O)0a}^%ͨBoW`Ku4faS6Gߧ7j;b9"{D:مFS=W93օ<-$9?w?P5%~c j++ٞ|1WChs1;%0Jcqlyr'PY6 90Z}t17vj{CZV0H|3r5#ǐ)l ? [i%\Kˋq?17:').K=c>k3q䵴zUcދw!Cdub!v ALxS&xP9ȵj klsZ x>1/JƄiˎvhOu-lJP_ּ/y&pn'ڢ޴{yo8>ot ].b l=OzG͒rP߱nc_PJrd[ˣR JcQC0 %J3؞y!2:mN2ƻ!{_Jݎkl]U0՜<d+Zv{ٷ@~NL(g3v[bcYθ$y6Bead J@6iD~=&A9>\lGvO&QaHэ=EGP0@IsI#q&&mSMiCw*&w>+qoX6SϭGwq5cW{ސ/Y R  2cpFHr@ H%!)0KLPωR'.*25p nlmmPWʈUPK{ )ôS\(uuthz7Kl^Y[C7I/.eOv଺'HfoO0D GZ] MH(إhu ^D"/E=d,Up n7ηϋjntIy c}Lڛ< HS8Z9ś/O1x;%qZ!Va.dP7}"&SrFIuN϶.x'vu1in{"‹ON9lUdYu:y /{32QUD `l4/x# 5(,qJ$:PQY%%H:/~ms ftpG9mjsIPkQ)W0e"+z5;5g/zT2A[\x%a3pB& /s:+f1p:<{ă4bfe+LUfPv$շ.hà_kH eRD'gj$ł ]/¬Wե #J~*MDZ5@Th,7-d>~,ŗT Z?Z6֝h9+qx[]Os5~̊R›X@\}h[TâoBN¶#CӔ)$úF<4Y &%)J%OK[Eg!#!~)0%~AXv~@ 膁ȥ_ת9]"ekӄk])cz>^~Q b#S:Z8BA%[яg𦸚Ęfg$@_ϮI9\LtH J ę$B]zݺj$^6q8>+#Lj ᛎ.\Qa}@a4V߂=[8AA y߶xh޻=T{%ɨ&s<&,7!eQ<,:&^/B4(A(N{\X= wEegh'hj!tj粃Apm~sE2#lIdOkT`zaВRYfogtqG4d"ܭ-)=5cY. Ҥ6Fp v'>^xX'9Nx<1=?-Xׅl"f.EI9X@At|yieè0ϠU엦dYTskpDΤl_Y*Q12n115% udu tXci7>_?CCHCc/ڡQARJN3 <ެ%#"鋥 qT WN<3c$e4&(tqLANC ꟧}ihlm؛pZ@H+klGДG 2ZZ&QIDњo< ڔVƴ_2zNB$4s-3 c>G!`L2c\Urc.Q|MuArGɖ9+y߂M,y_+l5FblxO!5> =W})EeSrkadPoiFeIP" +(E( 1:FsD>"sᥜ/8]{Wzfnwv2$O0i8 _D8,߆ϺI}`WañF>r_tq}$Ptk:|=GL, hj(#&@yllenWwbۯ.,)sHFϩӀ('[ݶt=8\P_c׆ǘE'x41aT>:@Y?<(9Kӌ !}}ʸa/2>ͤ$7?ul-6sE/J1!+Ja݆?;2{p,GDiՕaOZ_V'o4Vh*靡!bqN6p4;؂;ʥVHAb=׶ .|dZQncxUkD5D$0_kØnBgs+-E"C֪$܆ F>oe<o0>FQ^ާxv!L"ӤZ +Vн-WTeܸ&\D4H{} =Pp{Z[۳-X#. $;r"f. "v>UBj mB_]SXepZ-!- O en:4?z/ OD5~s=ݰȞGWz؏$Ɲ_Maͼ 1,6729rEصHx6uU< 8ay0m3KtewXȷ]v@q ˬ7!5zbYT?2w ϸrX6V88_׃Oh^$kQISU;{eSS6j ߠhF ~xJ"ܼNLf5JQk6@ZZgU8{kꄘL u2ݙmqA9}ii mBt,@5N}1-'~Uu̝ɦHVЗoiރˆnx,mzyq;,*[Bͳ Ҥn3$U]FK`"_l6~).uU()Ɖ &_3`Iw:\@~ED,f1G%uhdž4N 8YAny ԯ=4e+f4Y^_IՖ{s tڣ񲲣%*F?؉='qyNG$e!ѫ~{!?<_RhtpMxAPBe>RyCp#^'n`9R)j<%L7Njs|$QE"7CX[d]L?A3a,@P߅rJZ+*qBOfRՑGTS/!,ᐒ3` ʘɛ[ޅ=ڀ=ߩB`^+4~,(IJ)DFsaQ^=r01HA/Kۈ_R~*kG4_?:L}*ڽ˦O.u5$ j#s/0 [͚@  f- GؖXxB8Uտj o/;L ?%͍I{$Fu'SPSH{:;_{&`$rWj5#:nD<(DT\o܇,.խ`&Atp1Wϡ>Y|ؒ )f MQp[*C1UT[B[;g+ HVoڟ]&w*.Ɂ#O*§]RFͶkV/`ܵW)yfb"yהr"$gzL]Ca͛Fr{$OW2Mi{y7G ݢ"GV&NS#]=N <A_wTk ՞C{$%R-[krp@2Lr1֯eH:qc A\REy?W?H]ULa=z2SKOW,-M}^ dVQrKvi; Xp@c ]kwd)[5csCQ9LV H #B tIbBv $XN|?zXMX @<@|ς[Q92Vo|rR9ayUG dfU`Atv@ˇ(6SWn] TK&$*0tN+BtAO![ ZOM\Cg th՘=\FruX0#2x=Re5oOC z9x(bËӛL6Wcen=ޭ 28VTP}w-5z*-$IqǼ 3q6ppCޝnoQ:LcS^k oP:jUpγt2)#`r|\Қ :FE\!8WBJm nJ[P K6lk|^j."f#U(%BOXzrS\-5|W=>v;f,M EbStVpf}M`Ov+DzUpݧn (dgDGw3r,T;6Y[T)b߸6>l[SPZj,{$ Ǭ V俑[装 fsęL鸇, }J#Ovk]umg a=,}9iWV0T^AUޥEDh&$ y4{JF3:?;'Xpi RoW!\^Ii%ǍRϯ/5Z\dґЯO$Yo)ޓtO| yN`+LAή^o Y̙ WElnJ HD]r7P=~@@b%0 Zsr(M9&CLkȵY>v KWWkʆfuK ؑOtm6+­7Sl?>EeYJ".WWvҥ*jk+]` hyx&:Ǫ Q\l3FW\rNUP푡{p^W~v8$+'XkK#,H'~ɪI\rCuu'7*kI<O6dE.Eḽl$Nr7EPV3N` jTn=bW\w+%z5D=c^3z#eJr b$ Vk宿qLs>BȘDdE?–JTu\i p߃(q()CZQJuޖaf M] s3[|z%3Ng:;мG /5hN{d#JNuHw 7KCmL*Ês>ն3_(`56"X_=#!d$lj./ܔO&̀v_!tw?ƤBF(NDjoeAYS^lU )\>{|aK;Qgyc/ D_:4[>pHg䲃R>R(hA]K龥e㝈`@!u&{5Q] P@1_WG+끭5d`v@Hn⧷ &5Ҡ̤o[՞w).% Tg4KcW39dl5S&9sZ`t8pҏSX"WhY_#y;H =hhyL =]3IJ^nB*0XB$ZcXߩŪؔ2ogl&sz@$w5)e[@^JGB#6"8{HΒц2Ît(Q(Be>wi Ɩ:@Ch7:׼ ^^p:b6G  ^@I$jXLp*zG3PJ4+HNil+1. idf2<@=J ؑ#m5醬ϐN1O" ~(A~w ʾ0M ;i4\f2aΞXBBV5NqVֽEpƒ5 3ٛeȜea]H|0%זr;}J'n ^t#Kcxt>@v+,C?] .aMq< ޻} 9V&W¸N¾44v[ w>;KB;nܐSu5pP9$Ty2h9*=(X};.qB75J9uCKpnZ; >ǕWug&2Hh] EǾoq@ $>% v4 ra{XP=@Hط9#M-W+̀ΆLCa~68P A̱z`eB:Q.GG_t,[e<,%O=)\v1,3F~ޥSDUء.ĠPkt+Q2%K"X?JZm2\ugVH_| ҌorX@OyjB+AՓiqp XVP|ZV']GAa2a=}B Z*س<]e5.#|Plj[X:i] @d1 zhdF"Wѧ2)TGf&锱&xPH #@7q]TsՕ -?J%wSf͈.5C 1eL8.+J8|\q7 I>Ʈ.14J0# ˕I?y&4*6Ċ!+9nORĔcVҥt~iς*rMOn\0 D-uf>W\A`h߿bb{ kYZU%7vbX {Y3s洬R7S#רgTz|DH>$I-5j޳H7:p36j lAZܿ %F-2gbS/~b8M>`;.r.rΣup!y=@D* 3/5םdX7ųnweޠT"6Oݒ3m %3@9)DR_E]siਮg3,^as;pz ѪUy$URIk `M'xhr,]EFMWh+ۀ8çmdV_qfM;8J؃헽(&ө<_;V gw4lյD],eaU?ru46˅s=UYZHV!?q}E]Am KlGnҞn_Dr/0S2e0maLcA21lAF#e3kQb9}Hj,=$ m/@wU߈@pF`1h[ &((r{-1w(AS7zuM D'rf s_A}gP;5}9o_L,MЈ EַOiBAwM7oF5Sf:LE9(ƠSք!8h깸?znZiq&,KO͞.J1w9r4S~@VyF rgBz˱DGr368&ntd75p% Z>H]s3T׀ iYU_4^ۅFӶN~  DؾZfs;}ͻ>Mm$%'IIւ{FGմ|U}ViVگ^_Hci@D8r4Ч.(5q>*@ A5rL} _@F3hݼ)_RU-c7s^`fl~9ԌhFK,v{G7n'L4;m̉} LHgE)9qZ=f a#Uj970UI5M1JjRIS3yYg}T yz V O"AH4E+BWc+ (Kqu,hFW܈JUȯM+1sN\P|2# 8qXJ񜿡InxjUbP# 8@^Y `uxK!M!j Ujm&#fgPT +a.)-(jё*GvGGb>CE^ s3C Rڸn>Zw@ւ}%1g.ۺh\N-T)2w ~@TQuVHY $|3>PȆS Rd$T֪Hez<979k@;WQHfՃ ʍDq`VJ#WRne!#-B'5Yur` lK haܜu,9&]19IHS#b3#?YX"¼%Jl>Ͻg.5 k>Dkq#yNlz]VűݗGR<\EupǰqMBkT@ d62t?=[l]ǣ8)S4p24pia2a9EX_w>F賊!hz$@ԟԩ1h$K|qIdq+bٱ̬|s|]^w/#_.2riᬅ +3jp]:_NwUzm;C,]7!] B$#|˞J$ae !L$ה$md!aLE[2h',,XK5gUe}G@P6<5(uo.Lmi5IGυvcbMp3i9zQ53ףl.?S lSҍ@lqAַlX-TМi./cc'T@Lgf|hZU7@V]h7f5 Wzn8"@{:ֆ|+χUoZj/mޱ4prGPE ;Vtq93::Ѹ>^xG6g]DVyXX_YZWӸ}*"r,x5_r1dR+P_jp Z,Zar*.>rUBIaH85=6X.rjм'7_:X93^zӢ,&Ά e &5x~ :/:>Gڀ%q%' 2EVX  FpT`/e~=P^QkC5? }F9-PeTQ}䴱eFǙZH%e,f0`;ߋM)&͞k@&90痢{'ArK qT~՚lQRr]`r}⻟ AͩɄnٽ,lQSA-SPefˍr^12fЂ)5I'@L#O #d@y4d]=Vsv_\lè-O~MW\N3xpSa1IV A(gH@%b#,ε`I;1'"Y pߙqa)b8G?j 0V׽!FK>3Zq ]R~DT#CM7Apb6 j:F8h _!{7sP}pE1eB"t"2uڙ/ϱ*0 G1piBo YՐfJ2csSG~`Ϗ ^䕋*Cg)Tmo=dvCaTbxGڱpx-B{P9B>6g$߹3vew!8^aMzR͌!;k_,(`tNc}\?x]_8KuRO7@=+bԂ$=Yd& ̭˕?:bgTǶ-6MM,J+trl4< AXpU/\HwLJ'~]9)'T  j0oo_:5w].E.7ںAA䭫_Us|5I=cV$~L:>9GcBH_wizж`?t`G3 =+APS?hhٖ)tOfd#N-o#rչ9g.Ģd%䋠;[0xpu~A7+dgrYaUtjF *Ϙq̒/ z⿅&{C@;+涴X- wOQҙ܃{yoEr4pC; @)xuk K[&fD"ih\ RpdRʾ [.q324sa7Hb*TgU9`5اg /u ^p*\sk6cKFWRx xt*yM*NfkK`KyJߗBpĴUWd]O"/4_l`! FWtfl _vKMŢTߴhסgg`2eMrgD3(BoXk6ȼ+.lߺjs='"\`lX$UAA􂼔[ Eov;͆rj,֛d"wO}Sv IQbyF4kjTy8v$p.(aF{dyH0'v@wǙwEuj  f| ,ڨ$]Wdar!oM= JWqi KZY)MР|V%{@#˘s (Gunlj˹D i1lȞi:T)#Q&̜yo=/.* )3@3'$"xҴX&0I7H-胒nVC19h8_unY-yX=RٹAUfIqHu3Tc}udY#8/{ęcX&Qj̪FD N% ;֑{O[e8'bº2^R4 N}0~K)klu,NmN, Ў}4kK@76df oצgI, jR߮87#kZpy %=tI@ o<Ţ-vM#tR6:tެ9GBt",гa>%p::s.Z8ë%=XTVvȲœH(QFN yr6"m+*+nyvW~D]&Oi; Z 󿭼&7޺N$MFljjRźj=iB&!O+|/G(\[{#21 Oh+4Ve?ߒ2Rb.R76J'-6$)2__.X’pPwX. N[@XRL1R p*^>MՕ+I{눟 Ƒ9*CvzM`d)ag!LriR.\{V1A:Q [1(Ktn=`xm=)nA[_+_c??0`,]_v 2|3m\fq}^ΒU0!&LrCE!2i ! Ge4MFĒ As5qp< R!H5f,$P?oc~' ᄰ8xlJkpl.5S;K$Bj |j «v 2)gut'dڝ!H;_Zt ȚbT]w3ztgEz΃Q{<OBR0g-8܋\}v A3TL@\<:l=ƟXx /Fo*"@[G.j m\yn.]i aNH) &:`)2<~᜙!Ə'>?T] 6%\{Dr˭#i9I4h-:H[a[{ ӽ%#n=v!Æ'Ea7*%0gYKn0G]S&534 GF1m$'A]4EBd3DbCX LNw rۦ"jü>W5b÷#kwMNaS0 w@l&c])Wj#C*lOxꍟCdNdikܩNgSʀ<= L&"y1+>yA3.hEr;!ǀD!]DՎw6Xv[)v9t"o=MgvHF4 y gjswx sGII6ʢC yNޟ~7+$&%n_2 FJ,k9_i̕vMAJ6ulgT vރ+DF?VH{qCQߎOUvxp3E($TF opf ci=<ǖSo ]"ŧv,gM{5ÕEtDO^;pΪJ%,1xIG)VfDD1ޠZ4)CD䭗uވ8ZiȲ }/+n 2h5NtZ韹j#7+I'P~m8A'M3h6>5(y_ 8sj %ytU[tNw4M ;cT F:j 7N)kmT$j\,=(i}Rn,jn!~|]2*7߸"8EԻAe/Lx͹n` zL>o_U0|q"FƏ*}qdIWs/ӧ;+WT븄\$IphN1yۘ-@}k!~>$7X5ϕzE N6xgMa>q]>6FW1"p;n670O^yMm"NZ F-ecN\>%7=2[%x VqQ}\z㐸|'/?b78 ]e04! *ISM kH boY>d]5 rrf/VrOSa*<ށ) $[MbQ(:x4PUHHBԜnFAPWhu5}}99A'jNS, QfL[4{ϷT@B5 $,k<p4M}h>F^G(0ZY]6n4t%_4P@O&{ *?Xû9Iҏ>MbϹBhN=kmweamU5'/I526w0ٙԤnG8{(ShпoRX27X-aO]:uCi=4!a2`2r5*BXp=E{y=)`BijpRI1*\,3q$_ wu\n]SQOU3 f#7k p"5mdRs,xhlKI8<7ә9Y|o׻ា孵{&:8V| ypsO@B\`6#ey8_fD#}2`Jm78$b'olcp?. ۓ ًl'K_w+Y -t@Ȯɞ-jGt.|Wx\M^蹱Dw1•ZQ?g5vo൛Ln)X>Ҙ$񑦘szA{G/I3$W`"L^mQW6J7PdXAz7V$Ǘ!0;.rRSR NZZw' XFH 0sn {<LD"{dh%)UA,H?Ґ: p$e+1DSS,7i"/$*ĶAS" GH{$UW\Li=(]tgY>54 2NiV)v cqp+R C)FCEG=K- ̓ 71丨H͞Rc[ ˛~F_nR ЩuUnq֑̓z^q:LFkvusA4,ǘ-w-ϯM(@@WRhGT/O [K;Hn"/@t$Y~H 铌bZ mqůמpT!; HRR@xcZ&BתPަv7EУJ-- Aݪ2QJQE ]mCA쏼 S7E~}|%?ڮ#VvkwMX׆m܊ Q!c;ۉ5Jf2PifY\ Ufeo?eAS&X溺 c~e7_Q篫#ǾW0Oß|/!"$r0@PWڢs+?]*lA*VR")&ms}qI As& +/@![Tzl>"=*b㦝TJөz_Q!2gU3KuZDE2V (Ul$;E`+G=;vW~9 ^գ{bO=$5_ɽ^DW uucQ׊ ut'&Ob 3+.ډ7m@%XV $7;k?5T{oINE^|)$d@vfg_HTKQ}KǕ:UQ.FLev̒r%| W_)K =K<[j$-!D;6w۾9̘*t6\_ 7P^C ~EJxe U{ZJG%=V)mDThY3d̤ 3R }=a'^Zڎ+Ֆpk-jlo|d%zȍgQ ?ܪҜ'bԞ`;OM(rya TsG'^yUr6 pItS":b{?]E+b\%_cb/eH:wk\}/Z$ڦ"޷α׉`χFxs,گzT.UE'+˨ʴ!u 3 4q5A+ qV7WXohw~ -P'X| |.آz}ӶLDU: ^VFsEnaj@/baTu%#b^8N`-C.7{k Lf x6k&m:Al=O胨'yd*ێ`._n3s6dj {:3-ɨF Ytju\F`sE=H hpM{I޾a 7z@i-WwYm7+(^?}wÊ&jWqaḻ);Aq4˴:"c,Xy }堽=Y(mhJEIxz ,$2\ECgc"z 'XyNێt700]FT;&ӨgvU[߯;`Y.037ܡw8 YIXcG3k5۵d%`m!fS &)91 e\4zݕ.ɊWLNdk7RF3$LvNu$*;jF vj <_L S7p %DӲwq`c82ݵ棱Ph0η&IoHQT@QxcoҪ|Y±(?i܅3V1iU4# a@}grQrXpv$٧!z/~ {QG'%5) R|6pCN._[ZZaڥi4 MJSwtQJ$F†QKs$ hI%w@a*N G=_%MǍ#D?q nv G/{橧-yw#-1l7.m]BE OQUoh[N;[c7LބHאܧQOr M?<&7!6x >>TSdch2%%ƊsI{k<@,# 4 'ǥi@ oCܓ@HAZ6+ϔ;;mpkT0b"zj~lȵrdO :ʛC}@AxY[GF9;/DqGՄWYY@kD/g)z}c,(\~mj l̈́>r ' 1[^8\Afe m~ᇣڇȖ,r >pjp  <@ܳ\dۤ11#zW»5 JۉǔVqX<6͌N;EH&aN]ZPռKOA q&2L L>11ѳn(gp\ޘ Uڎ:B9yPFK$ty nzkB -bªV8ZN?﫝*S=ݻ!Sk ώ9]no>v:7|+aQR/ǃ]gM [y9L^$4 ]VemIv&% VT>fe5mJเ@WN0@WǢdg^!9 vt'$tN1XqsY{4djقܰmgz$=ÔK'Eadyƫ- ORr6~'~.[muCX 7픘[9p6zr,*\|jpI%%Š!u6ɫ@5j#̀GCv-e ,b dC x9=CQG~[ 3iǏo]Pڻ\:dq sdhU=[jbO*&G(go C/obifc2HR>ŘԻpókPN5Sn9 g+IP'_ ?z_0p;/=D˾|p>9bTgٻ.&(1Jp7G^B42I!=6j.|ue|2@j{|ŐJK$d$+ <,nƁ ]fK\z%]&|ko Ыawk-5 D\0F}<:L[X:&@D')UbdStMWQ#x9%nd0: ۙ9>_C8LD獡ܑA %_3AE:0SY@\V_ؗQP0 Fs&K u4.zԇ@$M]{ZP5}b6Vq<{e6G&eyrB>$xt4vd}KFgKxR\\KwIԶ4#A_J8Kpk|""R<9LrUH[K (rfG0dNd>xn0&y̹ ?+E ~ң:Tas^Ü(}PKDa%_ 6qEUZ=_Dh h5)g]ɺ#+|+p?j0!eD0'b C#nw>><dz/2+Ӟ̈́TȢX KKǛz{OaZJBs9s~_oP}>yYm7Zzr3Z`y]5γeb73V?!(b?UϢ>Ѥz+S*R@™.ARpm@1^(gE+*x0QuT;aObkZ_<[4l!}r+(0vtƈF1X:a+Jg z^_JȄj@Dj;">C.56dJN(O!`0oߋJ)Q;q:\EOM?0ǻ'x |=4NY)&_9/ǵ+ n^OԦ J\rY|C W)I:v rId\MJ;Wtu{YZܴj[%4֩xR }>Zc nbNS/*WyPg33<8ax8EQk*8|=oU#8>썣/r3[Aj-\,3\oIP%Dब+")#\kQ UuyW1J٤򂫱O.dt+]"/`Gصll0ӧXdA9{Dd{}=ݶgjG.Bߒ~w>zq^6=ǘSҾҧ&V0= mC㈄MӇHN%1S ~/YI7 Wv4f&ѰP>% h{ tRI0JŤ1RD dҨR=&.)!-slK%f12˜I5D4RЊDGx0?aIP>!8a.v6=Kg +l\oNLJ޾y7cիQ eҺwED@a]M L'N{bݸ\鶼Cm`ho}[dzd*gMl@Wo>-^u$ O& o~rs'Uw69:AYPPM9ѫs=^  iX !шVTHq%Cޱl~e%k0#Yע4&!~D Fz#գ oXX5lId1b}/"+ԓqN)ܾ.<Z_= ^pyN^J3ﶺ+ =*GZ4ST{D<(3:{Kkc`Gޘshs_HMrCig͛ Z`t~OVOfBObP̐تub:So5vז:;uu!ۜ Xi8Ydl1hfh{p2`5\ p1NMMy//XCBհKHƔ] aS+Xv+ZDk##XUcMN)%O!+,<)q奭˯Jy=T'*,-1<#X3@mcYpDV, `vN-OqQ)j,'IbQG&DC©l*HLJ,:"|8 XRLb䁷(.0Q *?%sxNYw^Ryb|͈[v5$ož;4l:GeП0+THg }WDEwٴIJ#񸶌XJ9Yi°];mKnU@M4m[N⣩1I)\!]E 6⮓'I F)j_V$ӓQDҰ y߼5F։}ਐP;G4\f*JŲ8ee4~=eT`꼿~ j9 ^1ͳ&#әp&,e@ W V~yKdDmƷoٿM$YPs:}OX٩/ ō(>?7(* ^&0u#zx/\**"hb7'O./*>6H!O/őϐ@΅bKI^#s TFɖ/Qg"RAD1[>15$Sk,ŀR[`6R;VIz5ecf8Bg~r[?n{PJڒ04\>hv{ ƸBQ{M(]ˆ;G\pG 'o 8QTxݥ$iJYQ9WзL%{wI3h#Ѻ}OoYax[nx 8>EY/nUZaoD9@c$\⵲jd+پ+@^b x*j@,:2Rg2؂009%QG7%>6r- B9ĸ!3XjQӄèFosnˊ7}la,hYLwU 1fYHy)KUUY==Siʿ}hkM) Y>q,*܋-9 ?۵-l~*h~xkza ۩i|z̾)rAX)h+Tt!rWnP1)_q&XNpXdٕbFj,L'}ӌ(k#kP56(Ɂ4 :J "\Z݆4۝,dkD#ld-j{A%,\ȥDN ,UFVt!$ؿG3!&Klim4w6:B lډ91ᢝc)x*qWy቟ឣ(􋠎two~uNOl%%8sq6kەL-~IPh_%I%2FN_ܭ4V'[2oȉ6KQIw/-2V1VOޞe%jdzQ+ Zh).FdQ8x`'i3/K'Vvpm ͖.nF3" dT^"1Kڄ#YChRb6>& prJZd|3d9IO6!w@P4be*n-.S=PH!4O%5-H)|_``_eHp:ޛŅodz2u <^o[(qtwloƣt* /J$X h`oEc[/j^$?){Y~ASZ^l^8C J77;:~Gcj"tGg)!;مsPPbX8{g!z6:8:0!\)Qx=ZQ*I}+ px״6PA6.f?xby9{"t314u1!wu |7?j@Ͳ9zaHSM -WV!j#7+xS-/[&]ڬHdf&(L-Ӭ6blXP77 Ț`RFj4N燝-S28=ψ:C ,$#w 0[%x )*KX/p`[(^sdOG=Nd5;~^ T)mK?,I}JLP|Pk9y2ȓ^e:d坱"ʼnV! Ƿ0fr0Tr. bIȲLI¬ˣmyA6lJ`كt)yA7p{G"cybL)Lwp_5L}ò-l>^bˉ\Yxù0rEn3hVE`h24$Xcne*[<[(H蓘<ӌ3 ,DЫ2M~c岱$ M}OF4!}~lgzF;v݌*ҵT洽NlM"fV~#aݚQ ILpаv{DXT#Xvq_>ckrl<%Us!NwXjмUbEHbϯ75? &U/GE+VmNdMg,*xy$Yf2%WάE+`@#"F-k,ޛq$v46ȡ䑉GJp2RޢUPo /|S0}"2G_·jC;ڵքwrP,߆gDLz+A=9f9J wF30'Ce냝Ex>n\Yqz3>SLcdGjΗqݕ8B._/߫ٺU\7=е mPmA,υ͗Y *Uuc%YK8 4`s :,ިe޷'@_ip%_itK뤸 >}zU.^ZfKM2I5mUf %\3l]-ظA4QI# {Þ鐆F'f$ KԬe99,W=x>^۹M*ٲGxmBMxX<4|Rck ~0uiGψǠ3mWerf\Dd/@oF, ,!訝>,D <]u7vRvSyM rdTΑ+ R??zFva:Bŗ2TNX_Y7=e]ʚ6:Qb[ vtw,O3QJVdOE@Ifv~K ?f!$UɣZ_?|@":))xv?D9T~S09$3-gt@Yy$[}/@g''WG15*nM743Y$ֈiY/m 2qMm|&yϢ10#ד㍦Ǵ)g^fYCCe 1nN@tI#TsHkFD>ǛKI'5iHwAJQ-t9N?E 8<J;b:(SnMhl\V]bV?Eb6!Tq"Y~lSq׹8#Q9!gq`8TH,|j{1ǿ0Q\ga=˚+Vr0Qx~t !#+bn*'!fO z(&&@vgzZZ)Yչ"[/%IV##:`ߺm*K1o%ۨmv|*hEv217s΍>kR`Oܸgcqzr+{O#uaaP{ &G]\\IE(TWDyS'Q [X3Go4C.G||;hBڝUI(%biaSVUޭNSbDs$WFAطu3<TEz2y4/ōӦ"foii$&q[[9L6V 䅆,O~3E\떼3d(8un܍ogI+yP!6@#ξWpg:%i)~ݫ~҅TڤWg)9[|YL[ɢѐ}T0,O,D Y?kVy6 \3޶ "{WW1-Bzm;/Uhe3±8RA`U:7)%zXXATtJL)e|Ӹ~FBX5#7m&@ٲ7 ɶPF7ᗎa5Z2f8J= <ؼ2Ri Rf:[qGL>J j}~R<w ^emHϘD.0DN[df۰(-y"QoYnјlXP5r!6zMv/ޢqYjmʙd@,h :Rlta(Chhw'_?Eb-롱V(|u;[*?Bs\|:pU!Pk‚[*1 J;ya$ i Z;;deEjj )6:#}|EѬIt@ N6Rh|'HºX#0Õ36 AK|!dtlef) 21fYۨ*܈TEu,"+5fiqrakN7$ on?1ia-}JTFYa "KU:XGkz+kDb*8%d/>kB(v;!sӛ@ `'ؐpO]7o7;LՊx4繬j#Db>K}A 2-z)d]qgV ~,7PY yHl@NJ7N@ɦzoפkaƶD1LǴ&f[,u %4J'${?]{Q'{ _B?]P37MpڔmV}fү-aOsdAG=bQ=nmIEPsFR1p ̔ŷIMs%eVJ *`m1\ m ߈~_HБ h;ky]> o{)V*{ G@j#)֋^]Õ3E2YW;;bϋVCyƥ970 \E8="$+Y+#٢nn#K8k^)/h# xcъ`ƻU|ʦ_EK,5O"#j(p.9TJhޔȜx#ヒ}A߃0Xy~n!/DXjY}kŰR9hSCd8.5,}܆ds2 gd.bUU8;påOX|RLJ&;Ram&eV>vxvieHVVvN 0S`Y.eIWq+$G! ZEw;{G ,jx &fq[a]^kօLry(A>R˥'n@iͦ9Ued>dz#*O0?i肤\ߋUw%tnւnJm9'3DH\1~@qI}fs0sl-lVy;KZG{b = uX^I~.O6f:k33V4P3 DVJ5/K,QJX 1N=M}ea;#^ƾ5,eC2=QVސ-07QBá2]1f" #f;^0]5ޭԺTZ/* s$8lЃr 8V.OyVSk*)3fl M?i+%Qڟ4lr! ۩K 5n|{ 'b&Y/'I@N[| u@1 NV*4Ҕ[xOE/79΅Q;ȴw=BdΝ5}fh-4>*񙋸`3186C+#임4Q/+=Di\n%F=g uW˭Pʑe4Ba4\耂9׽-L)ᆝ*A淭v ɣW9VM7.W0Y5IAŎIJw?}㴖,k&bHY[h;+LǴfSTD$Oѵ&@\*ycaZv~}ɋ SZU'K|bY5-':?"P4I9eF_QPPo&,Wà{o&6͔92[:r6\v]9o[hTS+.!p=‡W?gh#h k1e}S:6fH:h\ӽbs il6  n kX(l| <+%-k 9Qt9pU3!-'(3]5xFr0h˱e;7+# OB)l*1\2kA3pNd١jc}8_E4:U-co;ja6.Es Ne^1QX翮սAVS : SHޒ7c$ӏP7 MS}Q #odϫx~*[,.0hDV=K$O ⴣuÿ~ݓC%W_b #> 1˫7o }ɩ`e \`jt7Q>ʟBiNcv: &Cr6eA.J7i' 5x.W^/_ ΗѰ  nj޸$t,]A[)EK4phO~x"ۣ$j]$aY]p(,kn -:@ wo!hҽYG'_)JB]&ٺFJwl@bw^}q [KuF L, 8A4aA^< 90GM€^t{T4mfEEh5BVUrC}6SFM4Z) M+pNI!L][:_r\rGz)}A R֋i<fRv..O'^q^JӢ'õui!Z/= ?E_)[]Y ~r}$hT>fY/(4bCeܛ&Z7л_Tï9V)A$lV椁tzCP:%HM⤫bÛS0EEb#mY3p1^ *6 )Nm';-]?Po%j:%]Ik5i78Em,$[mTF+yF f EtpRT}JiX]fֲ>#eP? GE`:3ߩ-`ד (ZlJšʵ.-n]phUw{u]w[,*%Vfsp{R )"2 1`$1i!S)!Fnwxsw;xm!>+ 72EU.d,o3td8%:r6`ar5p{+!]鿍zӪf=^zUU~稟#˘K0}W9b 󀘹?;@a&$,KfK/TMZSJ|fq5_I+5Zbcȃ#KbZ$Vt>| XrtҤhn,X XK2_Be JV pMJ\)-P=A {h_%>c IWT좠v~m@ōK]qUf4ղq4;}ݔ Qˮf\j%dBmyU5ʔAyFw&-,/DCJd#5t2I$=MN0BScG3v zЮHZ ?{Gy.3S$7 ~Xc".OaI~hO(MB6\CͧYҙ(DZE<hHj?\A9/8uz͏빠b@|"sۥXx( vD- b4&˽ E)cHY9HJMvIy?p{#w(|H> a9z%M[1ވe<{&O-GA,Dzw 3mC:S`vTcܠWW'8ŸPlJw$(@;_s%cv zb(Y~TȇihI+]0Byor~׷Df Qu-T'Ոv>? $coFu !\V'+<{obUPw_c:p(n  =Z]i-3>]҅O6'"y^)|V*JTǹdCբxk?02;7s]$[Zɸ G0Mep06t~Wm?Fˠcg$Sf}eK % \n'/f3=J%>sd PxTLfwK Tgضem9i O3CKCŗLuTsI1XzSP($l:-Wʄ "["A\/CeŤcSgݼ׿jDH=Jħb@;&Hxb2zl1'wxq:b!¹( gBYj+9wL`1Tu茕,7ؙnq!# 5N£Yܧ |)7-LA[fA4V@{P:L0j!EIYhץ̖Xu?2EuK3lwN2X`w2`|cy ѭ9@ոfԩ#ngqE*S ;;exf- ,? {.]Wov8Qr@Q啍734]FH*:Q3SǛvWt㜊ui+bۘ+]\LRPE!],>2̭̕)Xw^eÈ%xu2tJ1w껐.a#ǩ=n-"Lޢ!pR5k0ŮflK$m[WC+NM^w^ $w!-w,Å_sӴ%WSRI{{0G ]#NevNeW+Y<sD!=m}Į&ؔtEķNlB t{ٵIR* ?͙DPj&䋂(vU<Kov^ =A) hɅNͿ upٲЬ1xfD9B씢x6ڙ;&l?QPfKd*sGt!t 5Z. q'6*OBU;&ݎcYO. z+\+"|]CGOFUK]czzFսujLFaHT rL.MB(7!ln*^Pej ĦeGTnO }F >5HuYSd23B]RD$VOn59 eаoABɹ=W`eCz#5: se7pQ3]tɏV0oEO 5HDרsnJY*ɩ.<"b"><p,xe2)?l&E6ghȐ) tPcהVQ+`gf$ϯ uGIUԱf_(&}QozN>fN7[5W#vy`.cC| y*2P[4#`9-YzE"+WOm@G@x9svUNf a鲿GŞŒ&9/i4yE[h@g9*G?CVgt{ʾ;GDZX騂Bar Mp>) g.VƮo0޸mr, FK佘tU%R9NϺdwK̆Q:;wx M Fn',)e3u! Z@!{MCj^F K%ïYZ{H%(ow,eXWc@ܼ;HZM} p*+х,LG^j~;zYmxq2~\eFQ۟߯&\ P#@#Ye"T#t7oG/_mJv2"TTv~O^g=?%:lyވtC1 *oXrsJm"b XÃwOc╊¡i8ܞvk(jVˢ_TYY)ƵW Ac;VWQDYQXSFo CByQݼ'e_D1m`&"v@zp-2oNGB!U qdhgX!jC4gm6~r2b"" u?6tٶ}0X.zSuIH G]V/>G3*V5p 6R2>rX]'fzfxAxg 47\5^) 6/ K7djKʴ~KE$oNR#ou>EWs/COr !io~#ֳdAL֢*#Ā"~ʀÑem0&)O\bw4?Zta#?h.Bs ;pL#$S-yױ_/=s Y2y&&Ct;cmz =\pY孠y+A ˕U%uIrk4*p'gdq[=C(rRÆ/HG[ĥdPE;ʏxEm45> 4yeQ)_#yeI_[{ Wwz`]%1ijl1&|˹ᅡ=Ow0 ԯ*Cw$\е \rYmއ/\~2~ UO ]1hH݅/FFV ,'{mR>%CϞyz`:ye*t|!/á݌cOq/L#L(ńGt}\Ov-iJ Ǒ.z ~"%NfKXN3sm LhkfYS;)2U{c*.u@g+ARLADhU:APu Ctzhɳ$Lk.u\ ))s =j/1Qjo^4n|- %56f x D|Wb<ϊspN3T`fT D<p\YݮЯVP"_barʭ0Ưw_#AuIP}13ȦFkoqwgAb]rdpVe^%oӰ 9.B$dՅTc&75MC%-;M&GQ[W'ԯami96]L[XG|a J]ԝ95$(qh(:54KP{ = 6 ٞl5#/yoSbUg8d@VX#[0ܖhEMYlLUu'?"+N+:BD k2#u<֏~QJCʨ?]74Z(oӈ\k/"B?.Ow؉ g΢gث ]9t5ptM#,~C!ɯ 8ǰȁ+N;g'glņCVnנ:6?Pc ^ws)9%ӳt.̲#h/(a X"')w" :?m`g\6RB"wB@׍݋o@oZj։yZbP//%% ȫ$!IG׆ۻvdΡ|O|3 1B鐀40|DNg;a=X$ti\1>i](UM)T>_lR\eiR 8^Ǭ5NN] *z&e OI@mMT~?Z̋>ԔS5$P8H7:j5 'Nj8X{GpPSwzǕϪy4 I$)z+3'MI ֔?;uU-4R} /JTf %:'u2XC W;V>c ggOL<|tI1BBL/T̎tڊ;/}xuuHbnrFDyL\ӌ|#F=x2! y)q7Ť "z= GP8$NV,+\yOt!ZgaMߙR+{|] 9d%òSTܖև㟯h;°NA@^c1T;R׃y -[M>VKZa,;jЬ#RɷnБ](7YHzZ, j}/j'a˵T"h㥚:)jd aL (J-C'}":_E䪵 ](]g- W,@z*@BӐhvR@U/\'I &!KzޗJ~-%{ͪa@[-qqBlBywׂl72t5& 󿾦7̷m$1f44Pz#V]R.ь3OO!!bD]ľ~"ng:hy[wj0eV2gP^ iuS;*mP_C{Rۜ>݀y8Ӻ}N `A6eCAaT_|g"N"n w-_ik:~fנY11 ܔgFI ??oFkLZ oRs!zO j{_FKae8{lJDd8zky򔯨*tE_vɭЭ2vGP0>ˈ$bけa\wԽdykVf2 5vh7RO|sYdɴF M:fmawȼhwsH7R*h0e҇,ΐrO#=NV\AņS5 wXyXJ)kgZs#`K/5`,3by 2.nĐ&2>jEQ仏Է`5#VA- LB|X8=0J2Z+@EXP |̩d_HS.[Ww q̛A5PmewT ,NlnO'GA{~1>fV- daaEɽlS9Gүfo<^ 6ޓ ƃ](#g |~b4Pgٟ+ӟ`SWAdܮJgyP1V/=3A;2I!~j >yn^di<(Au|᭽` u4PR?,oezX2X1hi]vep $"k%֛ĸzo0>`~-3Q\}n )*hFfBbݷAA5p U{u d戼 0[2LvWi|=YG^V!oJ%im&["Ek'[%C;x]t>SH5f3(;X4 =򄽑 *.f93`^&իJ  B;y~tkы0v!n&qൾM!!RMY>#sŒ\;&5P Zks`orIpVO֍BӼ%",dPĢ?TிUa) _k1&xUdRjpP^+d!g~X,(7怳f"-@?]Vdž6lbf*'/ـWm T+U=/h#v${-<[S.CEۗ8K9l~& ABl _Y3 ~e;u)ⶹ;law!^\wj-G7 j>Zݴpa5%}m?NB+Q;숢L7akREDd[OY̅^pޜ2"P Aߋ\̕b_ N* ff:)0)>럇_۵< z, -!F,8Czr2e~Mµf'|g_OxVVlQτm ~*6TWLk6t6Vfn4۹GcH|5 U .cbvNC4r\ b_h~ /S.W܊~ɑysăpjOIja딅!Dm՗`=@, N a]>^X3>Mh/0ûȩ)0o3^9cGB/~ ;#^طmLl \yX< &:HsnI~Mvc̅#Dd+$<>$F&i'Ja+X(Df(6l>nC";G #RS{͓6rS[Z2MFo[VY]Ge5XG"-M_6bAtlX.#!PWkm^Qϸ_ߑA'ז74Ջ4]9|7 Gi cC?Nu'm*]rzTC-CiQAHGpe8w&s} ÏiZc5Nڷ;"{b7XT%{ofsrםmK.D4aԷgLXmdZ:jo()9ĐP"zD5wFn2uPw_O $2ʺ MXmϧ‡8T]6u, C)q 1h8y}Y.T+s}rSR$UBgp$hpgX1xz_V ,eEXB: ]9XGxQ"_*\~%Fb69S>R|VB{$(p>eq(pai=7p{݀Rr*:ezJjH>/m%grxD)C9/LPu M6rUԻ~/QQSf>%XA}:WO80rR:Qb?gtnIsX̥_G( ;\g8W,׏+ yP=A&d&Aiu"n"$hP-bB\Zycupwb,7߅L&U,ۨ_>ҪJ[/:IqŠD9inʻ]˅5W")vy{ӯPy4RE @\}0%A %),Fs_?~K=eoCVo"iI?/JyPYz&tՅ/tO#2ln-q_iΩՓkoX0 Yf=ꨆK!@-DUeFIïI8W\/}ǡWV 801T9[ ɱ/~E+kޛ L{+ksNW2o޹g2qM[ds1<5XmzJ '^b7DCkp 82+^XiZ2IBb'j:MM_#C(NuˉE/ >Oz (kW΀ LMA\Y=Or= ΃[OPη0܁]hA`LKIi%Y^7+&hLE~w/ƷJB^p[Oa2 U^^fZG-tԎ<3KB\xf=qHTBz-·tT",EReǎj'a[j5'=r{8\ ƮM$VO[BrL9 {qL7'1Vd^~GD?{t^LSEqOj_*)*SzjL3ob_L2chY59B]ąO4w0>I$ֳ:$1vm/lԽK}rsz?G;3Z]d'Yܼ⮓a )',H>uWsn |eJ!Ƞ["t{RtōEib|9 JIsXR=IщON1~QBS+븖jRȉ~ G$oK?:Zbs6*__*i<CoXNNKUox2s#PmU2K$P%*vΈ$Tj\֖u7!A-_}b{H,ײ^w V׳3 H.pK?;R g:Ѵh1)?89OaI;(eXcbCtPf&3S:ޙ\~'N@_IL.G0:!E'c9 W\ƨfR29\*'.neIi8ѮZy|5O O99kF(!-U[JQMO]+*az IV̖`Yj-ū \j1np24 Kt^r:hq tCHYӃv #wLWU.|ߊI/îj;:qw#kЗ77u/H){J0m)5AD^^G1_ef1CK 7eWd,uVQv.of7_լa/'#c_o^Od0݌ǟ, @믕K .RSh=BW]X c794ɍ}0/=Fg&oW j'/4aG\XLh7fsZ LU3vJfKmEjH" iNL}0WaP{K>Q:t3HS^S.(XHJfРdTeJ VzĿ\kE-OB@+o؂gP>.EP&<~ (t;'ǟX~ic]`Ið$i_hUYi? ;֫}Xv>uZRdQf$WF4qmpd7zcix'!]aY 'uM:݊ۖ<,BK7B-tv@?cg)׿\\u8 RٝIZt'9 i bO4 Z㧀M=cÓfkhpbS&y1 fsvV/!6?˙lq;5/Z/H;%ZCZl;j-f-Ԏ}qFLjQ&[6![xXS5a06}2 DsRnjj|uzBq_< M"t+ cl1@(LbQCWf Cq?>(JVD7~Ҿ%AŖ4񢀋t' x`ԋ磒BqfHoq)\s@6R;Bx@j`b*G`  ȥP+;HcU/YM1 $)(~ eXe/~zgFJ`7wRs zuF7K/R o^y.9"Z ;X?P؆afIGW]gWw(qvNNg2;),&W %O,hlwiR?ōWHT/ls6H<[t EX[~G綘G+w[f-?$B P(d*"{JI /J"%L;{gp(kk++>9˻ lA!TLCPw18E~:Dc") ȭ6ƶ=sJn:~j>"^iעrio_1e̵3 D )h aǶivG^Ԕcb <9q>UB_8> IT3k8>)fG܍ش3SZC_yIy͹{\qM2^WTm)\8e"k+X!A^/fcWz7 d!dCyȥH+V :HI.Vd݉µHe:ڡǏql\܃%8^skS+Mh\EJU2,Z (7{#LBLT_>+QIe;aAXЈsMU.݊ؑP{Tq|= ep9b\)3~{]豸73:AޑM3v ȌX51W>tNN u`C3S1%x^͢M%kּ{XHWXn a{*Kd7zN^rOZeƎ0 L aDOt5y_IpmG[q]"@GA,>-0]1\DO7\eyS4`ztGS<{Q餧(hwfk}Ǔ;OʭÇ#*?E4 ܯOie$րTT2}g趠c=u9~@ژE6xG%XK]%V%Tdo6'9; 6C:])d41 /'y4-V^MXO_). fe&KnKwtf#4Q h7֏lqR$RӜHOBnfd ҥs=a|ջVY[qA@tY5~ ,C.٬dJfpJ &~ew*YhXưܪcB>O@q/+%n'.{8r {s,~jDl(DH*t0] h6˥QKL  ћtP\/n*Wamh4Dwh [%xN݊SG<>rFAPɫ9{[K$c&C~瘰MA87AJ~ty/Of4xV Zdup]ւy2IڈP G=}ІL*ClUܟE,e }p2SƎ:}щG:5ۅ! rülΪ@8k(j& K{ n=z>`]V8)?9(k+>3iרR~7&𝉕E<"`2xqD<]xX]ryD:[<^j2ڄp|S1>gVEPR:0ɰJAƹ;ƧC02-%xz} ?Q1;'CˏǢƤӔe#B@eUx\ Rn#\dU?c$u%1nyN^{@lBdS|!S-FaJ5,sM›gus3Vt0qV*U[^ꭡ5Pwe!&xaK sؘ^h(>!+"퀸Sfm  00a4hOLuػ+qu5trH),g¾6 %9{鎷k/m֗ qU~f&V?\}[⢈+E\#x<%k[hž먔R@m%t{ 6O52Lą,̳L]B#uwph]!+7o}>j DgﹿyOeA=dOż[^Pwrַ=Eˁޣl8ԥ5LڗJ*+Peܙ,c8Wۭ"`lʹ$dL FEƢ2O.DHҭ3F9u/Im%1,|+ϡ( F3b})e7N,^XObj&n* dE憀_1܍IeUgj%9{ N \#bD'*'X7dNfsAP$oߖ7B2B,_'X@6\>A_ }Pٌu ]Eg!_8Nt,$.~J-Q 6_Oȕ<4n1 Oy5akB0ÛX呓 ]*$y0|Vk]Ʉ/ 2餸+JGٹ oZ KIߵ \y>Uڈ#kWXEu! 7C38#DMM ٛbgen_%7[W[GrNannlfB{UȆH@R&9wFKwnKF+'Sz:BD"qeV2KE?Yqw 4uĉD:Ze b^rr4ꅦ9L[f/$\ :qƧP9宵KY; A!BnOIΨ}?\Z.ʟیDUඣE"72\,ݩqO ˭ZmwGbNyQ^MHOÉ@?&X3Sɸu|$0Yʁ{ع2%OY&vD(z`V_$%dpx#P(2@򄽭R-(g2hgA bj}[SyQ֊4pZ\b &'lߌ9uQ)n ͺ?*!KHAd_8F&jݤW1G7S|WԮ 3W܉jI|ʏ 09?}aY` {2 z] rbGߟ/TyV0}1V r)x,HVl$>x°Wpb)^[oRŤ kyP+ l5 {_b8(2eF<3o*+@'ʰI ͰdZQ 0SnB͗˞sBkEgr[EJ ?qIu'v4jnx`|։!zj4R2@Gv()ᅱ0W%kTcŽ-Qs}L`X>^ \7dWVZpÇ4@:s~&\F϶CD&NrRCwl4*HTfJ<ՁYp}mkāK,oC\uQ&F%D[Sp|t꼮 D`mT;=086@wZ4Q9J$,&1@91oC96AkށVS}!;>h+<ݩoT<-ʄ~Vwe'H(l"Oތzyd#i1"0!qZ0$ V.1}o.0s+Ie9S81ObScYZ ]5U')JQ[.,QX7"`Uc!Blޠc˄$8-/cCB#U3e wr@שeLߖlrnׇ&F2 g2@mşmHq(_[NK} 0aBթ1]anI:K#֗BLRe>"$|K%쓊0E9X, RbهAӤCBݿg;v*7]i#q;#"U34LR.Qm CYfCq=tIjE|Z"B6a⍷~asLK>hdgkp;аc:VII~( xfZ!"/E1CUpIL ,?ߢcT'ʐ)VqoƧ.+ڗd8]pY٤q\#&^Av>%1 ljEN64gg6 J&du܅#JWv}0Np`C&yQSI,ӡoktߕ7ZpªkO~.R;8)f?*B4 DH-&ENt0o8pR; ЉK5XvNzF]#Z <\eE~5;hSIFó{p_44Xlp[ihCGP{ʜôo1%.K~7mwtph@I~wy}麻r?StFƵd_FU;I/X)nҾ)o f8M%QPu(}qrL #3u\=u=Tnr&wөx=Dv'_,t0v(Ԅ-S] xO,+ Nwoy( WBT Y Cc7?yo{^ k 7!)6ƥ3k[|bl?I~b$e<G{y6lQܠ7oUbwE"QVMLt=@LnRl'Z*mrO'O%C@@e!n{7߉WaȰ"aD;~eb:vP p%EClWC+-9S z-OS7pIGɟz@U^7Z|l!\xcIȎ UX ZJ,λ)z\Ëtٸۂ!'7۱h@fZui 4Wr o/c{3rx4dݙAʜlN/T\ XM҈;4rȱ$|K=^~V&ݓ'>Kӧ3LGp?/U^ƽ dBV\!Γ1\}0wBJy+A8OZ:Wa$nx!W;@ZN$ ͽsUG3՟2n=>莦W 70vnAri:\DD@Hŝs#hp k@Л YZ