samba-dsdb-modules-4.15.4+git.324.8332acf1a63-150300.3.25.3 >  A a.p9|/hKTfL?=ђӊY0lMwÐnJ-pAO?Od0 > P ;RX^-|- - 0- - Q- -4--0-uu)u()8)9-p:=;>z@FG-H\-I -X @Y H\ -]!P-^$b$'c$d%Pe%Uf%Xl%Zu%l-v& -w?p-x@$-y@tzNNNNOCsamba-dsdb-modules4.15.4+git.324.8332acf1a63150300.3.25.3Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.a,s390zl31SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxs390xrm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigW7Gw7gWWW''7Xp7G'7GG7Y@'hpWi@G'''77GG'a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+a+d55b02dc82c685ce6a2ceecbd9f18a28b934f6391ec1c5c84b15c494d250a8034d05a1199a5f8163923fc6f1997d2348d05b153281a81170c095592b55276435a9c0ec60dc24dae88b234019d8dede6f572ab7bc4c8c4791eeb998fd55371d792ef55f137d657afd8017ad02ce03fe37fb576d772c0053cabf2a7f510dbc35e4743760e06f01f20749d219e551b4522e1868e0e2bbbbd7aef4c62b68ef9d4a8de23be6ff7e6eeab5099571c9069d271971a4d4dccaf589a17bcd4e286c3d3b1eed36ad52bb989e8c03c0e4ba5270f002b164ae174468904707b3101b30deac50280ee582f5298faa76f83d854cb386b24eda229800809869dd20ec2f0d47e4bce423461378e0979695a456f95c5a75297c08ee1d2e55d99f8a0e446bc382137dbe43ed2be7bd64e1b41641d21f08cdf25f4a57fdfb6a62977b58a842a5a71efc4e2a20f7567473de648d744bde161191436a1c9f0370c43ed15518cb8feb48d1b79c0224e9567f42df0e86bcbfaa37577780059d7b116e8b058cad19ba6ef6f6031e5e37efd5198b6f8197a248d03f2e6bd4509f893133962f972e85df97c1937d498ef0638141f9619b42d8206315ff1617715158c504bb501d699af3f8166d6a05ceb9feaede13a96b1a5bb3de45ff764aba2307136084342e8d61277bc2ea17f8dc7262e3f523db3345c0fd6036e9e975a9f92ae863450f7a7bbe46c6d039a0ecd8edd1d8f841caa7e977239c6819160b70875d3b451f11f3ffeca1a15fe88bc9214d990130d80c4b1f38014a4a36969c05e8dd02a41684e60ecfa260c06a6b44e00dacb1b1baab9c8f2fceba61e7e61c64cee2bb520c977c7d532b3b11c72affd908d1dcdc9690106dd308ee564f03b7a1a8660c7604ec3f38ea7f91a48c3e4e170ddb2ebac90ad30983b44d0049ba8059088b8d264c6350c48c007ee1f577821903a9bc82ea6805bff6ebc7e8ece0a620fa87463e2c3c8ced653baaf8e3eb4bddf49397695c21cb109eb21a8cd402c1f403686cabeebd4fe9bab8ff866590664bc8c436f1b017a5e4be88ea7b5e8600eccf887d1359bbf74bc87216898b1056cbdb95221e6f606215afadde03e0c8b60072964ecb736fa4072c0bdf1e93ab1531ee53920bdb7f27bedfb1290015054a73481f1cb890f8c42427157228d13f059cdf928757d7cf0256b29ef47f3255f86923ca87b1b5f25a222bea491950844d88762c45d8191b045e6a05edcadfe0981e2f56600517226f25966d338357779cbbd5d0e779aeecf524e0795de257eaaeb359a703589db3ffb1c07786eb63d8ba3a63c23309d69226f47015925a17263aecaee447aa453fe4bba11ea03e7176a96a52cc40001ec901a5170aa2f6a45935546cd0f576b3e66a2022fd2f592dc5928d9acc1de50a8bae412df9a435a71428db5f0c49e3b5f78418de8fd1ee0bfa02b0c71d184948e23970deb4c6fa16c81c2682e24ddc7caa8edf66dafed496825ecb7d469ad9846c7fb1564fa7778a5b3cc92c061f3c0f746f5d48f266870b118087b31d2a0c4bacdca62cd00f2d8f682920a1e53335bc64f85c23300be5186f2b0273f1c1f04dd0568c24a0f1d11c324b3e71a31035c373f9cf57aba9cc656238ea7b1a87a923946274d746190e4ac1165f49e102a358fee3e9c40ee906c0efa8ac23e570d6f50e6dce4681f27c34b8677eb3dfad06e2f2eeedd5ca2cabbc744fb78f8e3244013a2294e1ba4b624079eeeca0a516c2b31cacb784c4222b5dfd48251442a8fd23d7f9612c032deb2c1c2f109798eae17166fc86d402e7af4ce4ab7c658cda488edf67277bcdbaa06a60fdb504ac15c511e158b317916093c3c38fbbef3ca78cbd7accfbbf5ae585296bb7093669f1fc8718fdfee90f6bc50033aa3cbed7ecd79a42616157cb6b0d21045d9201aca4cad88596d5ae6b58babecf703cc12d487735650a6f4d1f8af25c46f4973cdd9d5997d3f25aee4ebcc5759f9896ff8d0f998843e58db0a485a9d66bfd81f7dcaf221af4c9e6d90f585733rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.4+git.324.8332acf1a63-150300.3.25.3.src.rpmsamba-dsdb-modulessamba-dsdb-modules(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfiglibMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.4_GIT.324.8332ACF1A63150300.3.25.3_SUSE_OS15.0_S390X)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.13.0.4-14.6.0-14.0-15.2-14.15.4+git.324.8332acf1a634.14.3a7a@aa@a@@a@a@a@a@a9@a`v@`a@`<@`@___i_@_|\@_{ _l@_i@_d@__ @^@^^2^2^^1^^Y^J@^2@^&^&]]]])]@]@]]@]nU]nU]i]e@]_@]J@]B@] #]:\ڭ\\@\@\ \N\e\e\}@\o@\\\\\4\ @[[@[[%@[@[ @[[t[#@[[Q@[Q@[\[[[{[z@[r@[ @[WZZZZZZ`@Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USascabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigs390zl31 1643392001  !"#$%&'()*+,-4.15.4+git.324.8332acf1a63-150300.3.25.34.15.4+git.324.8332acf1a63-150300.3.25.3acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:22444/SUSE_SLE-15-SP3_Update/4abb22113a3b405a10be97f0b30e35ff-samba.SUSE_SLE-15-SP3_Updatecpioxz5s390x-suse-linux  !"#$%&'()*+,ELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d7dee02936cdc9ca42d83cad9d09366bfde92a38, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4b3530a2ac603ed2dd32df60abce3aa55be8eb27, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6abc45a6c77da26849d355cf539572f2f61886b2, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=57652b4dd72341eba483cf2c30b4c9e014678dda, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e3a41ca927c2053047bdd03c72d145d91cc03682, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a36ae385ac5bad138f82501dfcac6b5b172ee1f7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=65a0d740685739ad09b7993430b2f76f61c3da98, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=89e546cf059de106d36d9b9f04e0453b289331e5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=74562110e8f07028f179c57ad9f2b93ef5739958, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7336ee7dc29ed443cd12801d808a70c6ce0987f7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=39a44e4490064c5c2eb7c57babc9af71cb00c478, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=11054cf6085059c3163029aebbc260c9edc4aecb, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=0c442a3df01642bae7aae6e150066609531e21d4, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=bdf2f0903798e7a656524b30aed997f280ca076b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=32958c3b1e9a6fd48d9245e4642d46715c41a184, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=dbefffa41a0504906d679a08491e809af3e1e91d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2644aead76582b7ddb6b06ca0d32a5b7fc0dbba9, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=756ce712e0fb22ea564b11e6f99597941209ea46, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ffb237d64a73bee6de70d1ce0b0f2b44bae7420e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=711335288819b6986f7b2f24a0b74ee8f607ec5b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a5b195a4bd8cf68944fc497e1c89ae7cf2d828f8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d4fe57c658daad09a9c74851a68c70726896e4e4, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1684cae182531124d1b466e59ae5d48c7dea1a3f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c168eb9fc87da7ab5852ca48d87323af19c705e7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a8f1903c36fb7a60e756e4b518c008cf2ad70cfb, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=83bb52efaf5c29bbe212bbb0fdd7d284bcaafa01, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e51fde677cc0249f678e978245ac088f1a14312d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=404eaa6a4629404194dbe1a5999fdf1ff519fd63, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=832d3bc0066f95ecfd4351741650a92bb2a05fdb, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7395a8e79c37f078baadb7cc762c2436aca779e0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=450927d8194c1b921ed763b2da9bc21777d0c488, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c8fdc30ba4b73252724dcf3eeb8e5fb03cc5caa2, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=bed8b3555712f1a6dc5259243f546f8e8f574d9f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=670915c319a08148e13309d699df9627adb20a35, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=bf5b0f5b37fd34fc70d1598def66c398a72611ec, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b202f3c2d394c260fb88f0c82cc6cb7113ff2133, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=fd3fc09b6a7766c307541cbed979a7fc5915e325, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2c5a6c936b406ca9531f4a2be7c735a41ed0d472, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=32a96883641599c732f862c23fade808089c415d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=16c6ae42a230078cf913df27d2a839dd7267f623, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8cb183b91a180513bcf93ef90d9237049e8e84e5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d2b746e05589338936e86e13d6b9db081e221248, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=cf0b6b5ed4a691f1b5f45d5b5d6e9a1570b48ed5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=0b7c1112f5e30a7b32539c1f1cadde5ea21a8ed6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2f84299705d25240a0d15e22a632c4e2d8f81e68, stripped7Daq5?G]izAMz  *;K\i    7 % - !  R,RVR\RRRR?RdR R R^RER*R0R.RRR[R+RDR]RQRR>RUR)RcR-RRXRERVR\R?RRR^RdR R RR1R6R7R0R.RRWRDR]R>RUR[RQRcR-RRdR?R\R7R.R0R R R[R>RcR-RRRR\RVR R RXRERFRTRRRZRdRR0R.RRYRQR[RDRWRRSRURRcR-RRfRVRRRdRhR0R.R R RURQReRgRcR-RR\R^R R RERFR?RRRXRdR/R5R0R.RRDRRWR[R]R>RQRcR-RRAR?R\RRRdR R RER^R6R0R.RRRDR]R>R@R[RQRcR-RRVRRHRkR?RmRTRRRdR R RCR0R.RRRRRBRDRRjRURSR>RQRlRcR-RRR^R\RdR R R0R.RR]R[RcR-RRERLR%RNRdRAR R R\R0R.RRR[RMRDR@RKRcR-R$RR?R^RRdR R R7R4R0R1R.RR]R>RcR-RR\RER?RdRR^R R R7R0R.RDRR[R]R>RcR-RR\RdR?RRXR R R4R0R1R.R^RR[RWR]R>RcR-RR\RRVR R RXRRRZRdRR^R0R.RRRYRQR]R[RWRRURRcR-RRR^R R R0R.RR]R-RRR R R0R.RR-RR\RER?RRRdRR^R R R;R3R0R.RRDR]R>R[RQRcR-RRdRRR^R R R0R.R]RQRcR-RRRdR?R\R R R0R1R.R^RR[R]R>RcR-RRdRR\R?R R R0R1R.RR[R>RcR-RRRERdR^R.R0R R RDRR]RcR-RRARERXR?RTRRR^R R RdR\R0R.RRR]R[RDRWR@RQR>RSRcR-RRFRERdR R R0R3R.RDRcR-RRLRVRfR?RRRdR R R RiRhR\RRUR[ReRQRKRcRgR-RRRNRXRR,RTR#RRRVR*R R R RERLR^RRRR%RoRRdR0R.RAR(R'R\RRR@RMRRDRRSR+RURWRR]R[RQR"RnR$R)RRKR&RRcR-RRdR R R R0R.RcRKR-RRXRVRRRNRARTR R RdR\R?R3R;R4R/R9R0R.R^RGRFRERRDRRWR@RMRSR[R]R>RURQRcR-RR\RdR.R0R R R?R[R>RcR-RRRRZRkRR\R?RmRRRTRdR R R^RHRERCRXRVRR1R8R0R.RRRRBRWRDR[R]RRYRjRURRSR R>RQRlRcR-RRbRdRERXR\R3R.R R RDRWRaR[RcR-RR^RdRRVR.R0R R RR]RURcR-RRdR?RR\R R R:R.R0R2RR[R>RcR-RRdR R R0R.R2RcR-RKRRRLRXRERVRRR!RdR#R R R?R\R1R0R.R^RRRDRWR]R>RUR[RR RQR"RKRcR-RR?RRRTR^RdR R R0R.R]R>RSRQRcR-RRVR R RfR\R?RRRdRhRR0R:R.RR>RUR[ReRQRcRgR-RRR`R^RdRR.R0R R RR_RR]RcR-RRRdR\R R R0R.RR[RcR-RRdRR R R0R.RRcR-RRRdR R R0R.RRcR-RRdR!R?RR^R R R/R0R.RR]R R>RcR-RRR\RXRdR R R0R.R^RR]RWR[RcR-RRdRR\R.R0R R RRPRRR[RORRcR-RRFR^RdR R R0R3R.R]RDRcR-RRVRJRdR.R R RIRURcR-R 4[?;utf-85be6de53f6d1820c34203e02e619f7f6e590c0c64bfc50a1e6abe45d091c0a62?7zXZ !t/] crv9w82QG"o4pHvJuGy{4,=;2 qxSϑh\ߪP{4rv˻}f̆V !9hD5NMN=d\yQiF̅,J)U XC tkMG4q 7'sj sOqefܰHo>XxXW!M`*|7Hi)2зE3,d5!h"i=%MӨ@H-z,.ucP8ue4#f^KТKzq  ʂ0YMt4 _p]0pAcB`+ yAP fDP̡+XG)7`Wmx} X"$Ȏy(iEf*,&bCKAKUn C~ ݬHW)ݟH2;}P@3@){e2H3V[Pq*oG2bM`HVMvo+fkAjN$~QR)dNnz1Cu]n}<ٷdZ@G/0j6" - KVkõmȹbgo,dZp*-2,\D8WE/Ay <8ִJG"F41AO! <๐$L*u'uQ!`Ʀ\ꪑer]WFJ/;dz+B18akQ7-CGI)xт%GƯî57c74}3> ,#I woXfݓԮ'`K ,{yN+"CL|sPxS^RH,4;# *wekƞͅPd2?> OWC?˙\ lLV; ^?oCٽwQPcú%<6l9uză0AEe/0(UmVe^AJӂrkm`v J MGd٨Hns%aݑó]ꭘ: w ~W`V'͐d`vi:s2 &w+Jڈk48wSF8QWD?{,?~WdYoVHw{HQu#et(ܓL#BAc>w~۰Z?eC㽡m p t(@i Sbz/&v-Bȸ.m>|.>-} oLӽ^~$[AS2M% {vC"NA$Z]]#a-;! ycI\zw`o_l+,GLJE?ODs7, ۉf@^21 4~*9vAM#(7%ty*ٔzi>$4ˮ[|TE\ZɒsˮqRD5-U"bX omr`6K^iCɓ*VJːAc^f2A;ysAFP ] O(j}K^z{y2/$'j*l^4$c S,X%,H'|&TKց{qNWͦF7Cê`lk7R-^/D0XeI22鷿d|u ҧBp V5̽Sz'?&_11Y9m?_2jQ5@*v.f:E:p;hҤmY{_zr޲+#aHa7ԏMl*s8nƞ"duWWx|$O!U~ p bL,8ḴR u}<6mgGf6z>y*".yk7>Q[{~4ו5Y'KH[gF\o123=F[x[.6uPVO"ȫOV| fS.63aȏ2be}9[pO* G4ԟX=⸏e!#x`IТ,ȳSnPgTo ^")e2фUolpu|$n0ҏTmjVA+‹0kTCP>/-C0q~xf$ 1Fu2RYo'5fd3GqZ=r+9HG/m09W3TJyڢ0+wt Z$OL]Y : Эഡ]=\IRtz4͙% &W $nEr /2mI-Neط<4daiYnĞ'M&T\ot6 ^,adaqjSS ^]KeĚyD0jtey+󤞘ȹnnl'Ȯ WZ;M]!+ߌET9hIcsU.1q@@xiۙ86QBJ>:Ϋm:mV\1/Q=1U x5iY[^R:U)>|Lb8zS,Oo%5{X@9XH\IO,0pl*#A2 ~NۙŢjZaxO#~X&K @^ --ށiC.RPg?8t0f(By̻+\}2wvchɥpHx,)o'{Qǒ/akkR/HSI fj@Ԝ|.1&;3!+Ѕ>94ePFVM S[[SRQ6/÷@ qaMr[ᐓd5i%MJ#x(]$!kd8]2Rpwa9Lk֝ I#;_9܍^l sq·{.al7O-zB wڎZT'ĥ 5+^aMgMZv#^_Phbe kcWȌ}85!ϫZN JL^7bmP5ZGсؒJ*=ֆ$ ʆKPn+MCYi=Њj݊ !#B@^ SN5ѿh(%|.|4Q'}dvT)$Lt69 =6l;Rbۦ%$:Dn"]J4id( Bvt#l .XkN3oDQN\cĥͩG|xIr-t?@KJ6hOM(dq]PE}t}M\k<_L٥.u^aۇӂ{YOjdCڮs I תR W?ގ-^P: K.3&Ppk €m]0? lVrBFQ-̭m6U5C}U/8(R3(tqmT=2?ru NCt^(cf?Fny/ =ѱ9GxmߖB,|ædkV#?ˢ&]kz1}-e yA4ʍI8}nI \YXiu -Ǯ]̏ R|b-z_oޭ'2NBm<1 @$E>j*Ry+9 rN&bKD +d'`zv,{YQzb*+l0d΁ؘ.] 2+?g^晔ԀOjΓӺ qΜ(?lk P'!WV)b@ԋgK'{)?=-8k7~wQ0_]o&R+Et dzi+440$]0ܡ˽sU@\sڼQ:@3.@h&ehx!Q:+iR"^s%dVED%g ɫAZߍbB e3TsF.pK LZ!gAUX:]`AE'bsQ*uZe}mC̃NQ-lْws2 K{d*'Z%ث>%$acLoiQfZ.8.ˋR+As]lDUN2osaQ]29$-LGq'5{"d γ#9*,yE9ց"( H5qX~?~MOۘnDAY\m G񞋙,E<ǔ _uٔ@EDϋ+UksD1)$Z5U499ӷ_{{+>c9eGK7OzP+vɿJ%Nv!sirk+P+~Dh)s]8g٬KdCx^)D.cDD?N) f #eu{/3!2v.,_]Ʃ g+' wiwQݲoFE[ i{i|'#gq_*ez*G Cr!&spV$D6WAda<: ܂ETMbl!n2x!"ֆazj%z[(ljGx`[RWǠs5dE5ӱn?` PmPC]׀QPi0B'5,[@uA~ݍi#Ĵ ^fi؏3+*!Ԇޢ#"X31/Z3=Pw?2q3ʓŚ+]ʅPW/rf:&MksWy''*_zfmʋ'.\A"d41(`;3u\|ݳڷ`bzB>xD$\n + 6]NaZʵ+C46kgW6dףjI(`ueYLvĦBc|7!Qf9hvQzQ.Y򞢀n"G) 5`&\H!Z`A; tzt711%;ē:guQ`D}-+b^1c LG܅̶M>3w,SʫC•}գNKeà|EZW >0?|%%@{ǫЏFI<..y1Gqsy:B\ϙ]̓*+r'Ӡvճ{Y"mc_%_ѕaQq#!G<@ j  U)hI.fRQ%VxRn`'Dj K;#T8 _Z-52l׾ {|,K]-ԲG# sѫ0! x@fI^97k0&{w}@ׇ:'򉮺[--GlF")<8qQ'u&h>NҸ UⰒ'H C6dEYS{?$cUGCT(dv]<{qxARX,5cFszOŠiY%nJwRIFV|L":D"@)0vo3 &\z󔩋u#(܈E`c,hHt|'+WF< 4[@Hllh շⓂ@w'ƻ㯞1)f 'ODUM_uBUAufW G4ip5> Lrq2 O2OL׋lwt5FN]Dmb<-!:RV.?yWSS xZSS\Tzfq1']}nmT  t:ؾlj lO9o8Oj(Gc;F[<+Cp6ϿZic bҔJכGP2p9@ A LWS bOLKSRqf"Ee*-j SND\0h u1Ed\ l}O)S"Zu_q W5Ӆ]6pYX* 7m+}p(pJEm.˰t֘H?:no&^zqdW; SfC>)n1]0|A^YSQ"ҲJW|։"M@f`]ema2҉ 6Qwb MQZ"kt:̗@iM!xnh nv葙=d0D:S*ɪͷ49?"K;SyDFM[$yoy^XP,{,!hlrp%9L,{3FAtEչaAo;w`Tt;t" i#p؏Y#G]h>%p-g2:؜~1وRƏDc[-(/}S$̨0K5ȥ|=$G%b́~R`x tRxYͫٚЏ!5}eu ƌf1!B׊X!8;ża +CL%R{FƸj.]|7utxPV77b |/eU~2o1E)"U1^g_w&)@SO{#lrQE//*z- }ɷ3PQTp6P"s3a'.-a3&h~k, }X"Y[e BV$NlP=0? ?wM=e.S: MϾ<D$+Vנ7lߝgK4X 7onS1ڹJg` Em#rfs5dOLӭa7br5yE̮ E'X@r3b"c֠ ТfhbAm)ͭɹ [Gyh ,d^um݈?Vm[[M;P&zL5ėfcy*D:) æ>|9 saOWt<1DnznX굕{gT> U? g1KCú+v=ۊj\x.ywh`Fvw~jkOUuﯛo:|N:dRrR ;%צ唔Acղp IsN:#8=u8 c>[[=>4eP ڰG[ yR}ਔcmQ8iy@n۰Ak1'bS]2n9JeJ41ȳ88UbL{]uBVxbʹU`q^doGp?y ~[%z޾3!zuYz^FA3ßk%<5b_Ε^Y# ԢTY_s/Y 陣B@2&u>E\U8_xZ|QTJ4 MЏNka}EW!z+fJ W*OZhG_v~˱ā7+Ue!6I, gjum3|V{OsaEzv0=#Jzg4Fxe3?in9Xm;>eJ+%uq\8əgѭx'#Bu08ɪX0l.ROF?Q-w ct}ZhUʚϋօ_RSO4͋O!HP{gҎKlI=:mcsލ3,dI9$'h () s.yLְgkAv&ScM5~S@s-Ρ_!{,ʫ*<¢oS[;#u_ΣY*px2M fZ*]4q BDdd0}^/|5v^r[_%Yr<=)atlrwb`<ҝ]aކq^B]%%L7αq&.c%+Gks{,J]b%s1ˆc;zldQ-&dLAtǻF<(ز'$XXJ;pe-эॾs8Ik%z*˯#!kU,vg){n J0- 49,fc_Dzh2 ( a@\F_@}fY @l-Zؠ{\E2,eAXNi _4)8[<}Xԍΰn.v#i:$0;`p d[a}~7F]o?\eCUw瀐'>Κ;$H(%iX'Rcv"wԓW5+Qـumƙ uVVA N qGTm~}T꼍v }F?p3~K_@5>@ yUVí.ZTe!r-/+-Je 20Y aO;sg'Ͷ}֧d A("uO6Y3#X s[Nֹ.G8iR~# ߙh$]Ëd 7.M"AaU4Ym`S ί5NԫMEU !^ ijݬxv;bbƯ^-ŵ'K#xKx/|/lӵ'ڕ$s9e b2SN g۱2ą iqf3?ۅܦcvs~@u*gZx24DE8CYZzo#x3A3i^KLhQ2]%Q)iCYdƍKN:'J-!^T>tzoEYySyyuXWbCi'=q¢K~< {[\h Y7nDQY|1ǼL_O;e8NU-sG&Qg;ΧGS֚/ԑB=U{t5?ot<.G{= '5vo<²LYL:c|HM*hyGp:?s{#GmMs9W qv766IgÊ5#7֗Fȩk Me? ޼4s7γ㢢 eX k4CXX#ƎUsS:)iT59!8d:I&z-]mPwzݑ{o)=˅Ăc)9gċ"ҙ2M3;ѩݼ"2l($hGz^|cJveC9-z_2_E+}e@f5Q |ֳC6CnJǻ9{|Y.4q}lH5jH|T^g /dqHpp@5~I71\Pe8Y$ i|_w:pE"G&'Gm5 4~ 'ؙȳGi5ʫ\. = caJְ/:"(6+V ;=e<z^ ư+J^w4WH[Z8_ZCZWIS)zy%0V{#T_{لGWRnTuf-6//@/ _'2>uқ&2* A3ړ#3Y|ٖcr]iO8 Qi%x8 ($o3!co!օԕ<$CQjv  c$t)ૠn+&ު:s3/䆚V]o 2W?OЭ ҄!J"QuY*k9B"ـŇ"^*"]FӨkOʙ3R~r0K<y/@w7ǻǽv"`[DθQ (0?Ws[5|#| . $NIC|I:V!r@dVYjFXm4JG]{lXB7]mS5es x#"f'ĵ 'V/oQ VP,Y[^ew :lLU} J YXKzo1wh 3 Vqs7ӜDn):3BkBfb mja ]ǓXN%/QKx=W\\vt:}f+{R3p&-SZ"UpgyŔ }E|8:xe[W64&l ch*Yy$&jU|]GdqI;?[Z|.~EjFCQ BMcBr/WPRH&hןkywP`xE\ވn'w.Uw`gDx??۲`t/]5/ɅwL%S6hhЌ0~g"ڰߘ؟7_~>E$̬/np>Pt,XFZ @2 ?'U'G¹ !bIC ѷrn9.ID@av=IUM}_;dӘZJQɟ.|>ڔYٸ|w-@sF{g$}d1ӫ'N+ac3O$YP.JEx+6vՀ/asJy7֨"A2S?}o5_m&AA44Y~ #t65r)q0; "jnJlmpM9:|!)== ؈kO]|H"yjAC U50{LsDSN#q=(Wՙ f "ib䈂~MsM и@Iky`i%_'AM|CʐX ,4M |.Rfp!?0߮_[^Fr{:~j&njm5WȒ%S*M*P*y]ђ"RlA7Vta应v&,)/Aʀ.Ţf\h; M"9SFr"3SE%k+RU(%Rd-=:  08Oc0I(Mq9*CZi)j5S?([j m6,NKfzia(9ц^δ]Znfku05 ڼGM b:S#L~ "+>U d X뿛}ia9ތ;6y1l_X(0@}L b \C_Y-KTXb12/+Nx4zbU;eօTlrqge)ݙ{@>܇j_"򅁘M2=uj{mwgKH_@LQ79g9Fڭ&\ (g[s @ KqiÜ|H 9Z$]2X`B_?c難&9E['<T~ˎ<>lI *WDXp[lvEv{]r)Ob>S@b# GGx`s]>pok$hnXݝ8&($3Od@D&; gLSj5 i 2p+E2Iʙt Fp JL<ͦF[7]Z{.   Gc$2䞋 *3,v<`Yd40m8*},WFO^z ؏dp A ͤ6HeMo&JU9OP)4q? ސ3< aNl[FM'7,I3n[3*όIQ:u/u=IS)3=8]iPrT)7C1]v 6o#HKxH߅GzXQ|Z3\s'O4&' UJk7F-7Ҽ W-?W.}\Rb/-aBRlۈ~ B wGǧR>MM+DvߗL;:`~>Xpv, DN&Iw[n~ z3rHBVSUOI) 6bJy6ܥ5KȊ [`u쨬.Ԥ$8"6 L3,cN68=iMUfu:noE<~l!g-j#+]2\e/Cr5HM\bG#ADCÔa-ភDk+ rGDq?}o[gJ+ַyr_Y|8\1)צE&%*H{n 0]ղ&?0ls4Y6\kDc{B#B߰x`TƂ<=mSE Foq|9j](ȐDgsHʄ{{ @x mhC{/&XBk~§X#  ^AQxCtu=+Kﳐka( 3b%DQ*g5Ey20x:$B"z/ .AJt~uZFӣ nkuXKf#+1.’^Kt@)"Dem1ͭd_"2^rksИ$ U*cљZ=d IA*d@=mI:u˪4T ټo+X12}&׸M"11R*7>\]ve /-`!R+DKueilдiDn?z+|im͖ZJi }cP!ۤx 10ҫ!RʤFTLr[?>)KTI{o8!R0lJE/r,ճ5i Y5k$@ӎ- *xi9*hcu[`C9;8 ,4/i3 r|ǥ ȹl] +8NR!SO_f^ٙ^;e 9i/$%!sihEːL0ߵ9 #$גaL SbdQXYVF5LD۫YN]ݲ1z ƛѬI=O7v$RS~7Uhk'IdtE1Ȑ+w/ &]<;i}dX\ֹ`Z'h(Fd |sጡ!Kp'D%Xw@1ϴl8cD,\3T1?j  Uf?At_ً2IzO_Xޒ:ś3([B%NDHmYψ|X|O3}. }eH PI5GjG$+n}1& @a.k;pij[z<ܛ1xH@J3ϠX2m حzz(nR¦ WGAm򈒫7b(Sv867 p! 5aN$@%=Kܘu mcD.s`Rz(.xKTW[Up!-x[zd\센l2EՍ._}0^Qg Кi!ElA3a0_  (|Xr"eo̐70*$JwQ6MSIeHv&(dV/j,:,;%BQaa^ !}>dsj1$soɣ?7<P T /t7&L;IWo3 fЩ~ %[е41ьV< _f*VF3IN(j2cw j4c G>^Z|tGJoa~+4 nvB@ SPLSp5w=cbg[r P%YٵPߙ8KX3.`3N(*gt=]@ỹ~M`V@j@ E~VyYf|^?`zЖN+n&ax9S5fZQ)J>sAӇ8!`vME5+GMhC\of$sĢ0QkӃ6.c w;CMɭL>"Q͢~ *áH! Y(Bb`nVe̹HdC B3 L&Vb]1_K"PlWipހ\z y1 u^D5 &>BI g6t9ջ#B l y`>tJX+w3TRQBp\II %_:ͨdͣIars2Z)]k+UQ,^U55 WT@Ejr"Y+Qo7XkזG9kbEn'&qesnIyz=3)cO#֩i*ůLa7 TyRL$k(^q?qqI(1dI ШDZ L|@0I69 \>F^9! $UJCQ&ya!DS Mߝۨ1Zmw9tuD;6,J'K#R~:;K/22PA-F9:Yj-Ǎ ꏅ۟C܈gXNlU~OWȌnx"v ) #2Onz;%~$ﺲ'ɳF26}ごdmv^Q C`iʯzV]]r&R8Jk_?>_"!X{q+QP C,z NQ{ C C 1*y [;[t6_9k|7UJ8ԄwpG TYR, Qv]ЋMV;$yg<P#†6orR:yӣPOLPaaD% ~oG8 6b%n(/Y!KD^[͋p@/5MjևnK}"D,-v!iO)nrY\;pFJ\MiW_U+gB|\|ގL^"jң^}fZ4G_x6"ڪGܺֆ*q NRF$缼ʢYnUNXAj sz9`Xi@gG|:yblk5L_wòṱ%j7?C2iғcDxRS+z ѰQXc3vxbu)G ]\.C|\;Q'Ḃ~|~uD6ٷ6Ny-]?a%OaHz h!;0sc{p-V I1&Lv{Vp!F=cG]9~:bC]%E=K1Ɠ8}K/^WVZ[Wy$htc NSY}S)z7ٶx(/)HKdZlzʕ4qU.Ɓb'i5 &Ff+ hr QJ!itX)HfYkc#xCDpHۛۆg7e8ﱴ5ѪOV=x呋\[0VȮEj]@ S$ DS/dmzC"d#҂F 6ŇAwN*{KsiIhIjp;w .l:"H.1е}dգr9q.LLJ uK-#lu60kG"s푢1mS_zg sЬh?|'4ov'^~ƪtAy|Wݥ,7x| ҌSz ;&4%X YCq]2a5ȗnGԅ iwBkP#%ɘSm(ryNCr$V-.;#CHIw5=oO"S;@?ЇE, -y.XgKN~B9Y$j_ * B'zaUQttk݀W;G]9X$7x?K03eKWtxј0V%Bҿ[c-lݼzMwEV%}@h4D*:!ÐɮoQMGQ))L=]&ҜpŶbST驾kg vK(!.6$zR\9׿GŶ\UCs[!x8'{cJNQIp*--Ws:k=}9*mxQ XIܘu:-^萜22nzWnLX.fXeg(<-^|T4er(P&7a|:$y?!fܗHJĪfq<jy0(vCl^ՃFW]l:_ŚcJMX^) Rkxon EӶ0na|1'Pk;' T:O@hA4$i w]<ԌPY)Arj O$.)*`k-}Np}e"xfcN>$bS(Cyt%,%= V HyS&_ ũYýI'R4ͤMb4v7,>`P9X;'>JC!1VOqДhBf ncRVir(-C^(p̪x ^[Gu-6h56e3oBqU&-O׳"񡞹}Lf6ClYa%FKyiVH H\@<QxO0;$o%srO ,/c-E"Uر:R.D|3*J/(N"63hBޕ ٜ#e\M'*5 Uo~}qpy3J92i~|rQJ<{V%,fc9S4g ErbE*˨7`O| C, arK B~5A(S]` C5c52ۉ) AC'M{?+/E+{Pl~|s"H@hら`)o}nFbS4v+_4fǍ=Pys«P 1_?]ćR1dI˜KN9=^><?;]ySr^Rل_.16TksF%J?28G\~Vfj%"1.=މӝS"rU?TP8\"L ʴcPanq@qr4=t~ V[@טs"a I J$X6d~i"(;or3x[fؙ _:'Y͡ߒ[JZZ%7`x8HDt tUhk@nkFXو;P$ɭRG̩Y dr6`*q<f{5]Y"D^6k6HHgmF=o$)nA7\oJ1[m@1L>hSY ;WjѰsnMıYTi(CDM|VC$,(phF˾VRfF5&{vfbXŽrQ9gQGٚ)1=ϘCA 0zeE@&.A_]L{Ayνu١%|0 @ה-BwĆA>WRo#Ml Ew%_$͓^20{_?/יF-^ ţg>/v# \sARgOy`uxI zDkGo I7cT TG)yXuBr}uhn՗d A(xijּEu9 TyFU}V+}9g5r{]3~k=w:8U @JUH&fzr+27f#)E R0!Kw8s*/5R$„ ÖՊu`/V~ M4&G`vO42 2+NvilAr-11O &8 H0jMO2+2Y(ZܠY'jTW)š:ӧMx=2 za^3'1ܶt,+" T)ɰs9[XoЄ,Jm ߽scgVYQ!%@euVP`s :V) FQ[* tMǬ)b2 0}VP;m- 3EJX G+jWЪyF;%ua;4᳓Or3j Y,ܗDŅLChb% Y `<~!sgP6'SMCHr-lpE""Tn ̋rǨXQ_(y$P^@}GBx;Fwm2YU4)FgZ ZBj2g.xi{K|Y@[r(r)7A~;l}I-DUr(% m{tUUhCνٟYDCJ.(7ܐ+G hT8ՂHa:>+HdkތIUy`Oe3^tÂ%:~/Zjx[X6 4TBgf&q\Fbe̒㸾'|dRu ӑ  ~z0C)mNsWl& Lws,G;P(!18KlSFU4D[q#~ :ަ8?`/@n-L#7%!e(M/ ? q yr8PjpEOvt6!:  3 \As~ue*"g_̈́p-SyDs:Y&X̲{rcY{MT9̟z2r>m DEk$jC)ĻnqƮxb2c(v/;~n`YWUTÌ͔K! HƧ'LA.F͸6zc%Ǎ>F%l1҃Ӹ''8ԑy[.~~1=?Q£1|Pl ~:`È:=殺-}lsYǹ{@C6Ck\$;ξdPC&a pd;MB!'A лn rqf\c'(ӳL=p%iĊ\99=VMh4CP)\O獩FJ),{$IiIe, ZS{ E<oUɇ!'}q8>$r6T!MK!d]yr߇0*>AnH)`N#?2u' VZ/<Dz%Fjei]O0DMmq;pԙebBeHq,XW8S9,Z.Gy|Z3}k39&#DvrlWX='en0zJs!Z۷Y0wBG2t$K"̗Z$pM3-|' ڗ8赢|Bd-^‚ ߰tKZSP֔zT :ڂyEHFMȆ,ofW"XRUYsUc+1 lK[ ;bV()J 4\ox7I,)d8JYx8HWZI|ھ&t!I_3⭲T$GSj?$. lvBuM=Cd!Sw 3hہQ՛l A6kmOʷd5-]tX&xUI~Xr_T/զq<_T#6(Y'UN!NVv< ?U!*&ewn>~kDWɮM4]|? ̠Ua5MϴI SH5+ 5?[f*ar?ƉQT _1Prg͙-&V?X+q ˯kS`;sC<&*ox1ʢqlaZb J;z«y6lmE96fSȘ=8o(-Wה[jB24E) , ZׅZJ%֟ߘuCC7dUe(ddgj̄ ?iE UB0q~*%/Ŧ۠w"C>Q<;#Q3J$FIPޝTj?RD!=wV@1~7 d$0:?;j&0?HVk\Ƴ70f5!"#+S 8Q[L*Q2#p;Ǿ_3ʍ;PS@ + E#a ոc u؍ISȘlsj3H_Eʔ~ثSk-\FSl0 OEi>AXH rI2\5r\J Y緰&>ABP Ѽ)mek-܏_ [/#K<=Yd0~>&l?\,lf`zv7QUĮ3%T6 QLb0s.8{dZ7aO\I4<-Nz S Ӧ]jP;3AtUb{V&m t0啄»STX|6~jś:{a7F=GBWdh` b(c%/[rkYrSrtd7h+k1<" +3ώ\Zym#SrI꽢ä_tj0K;^~@lG(O6bI4bpl_NEwj)Ϊl< > 0xc-B!w=O#X/'WWELe$"_poQajщFh6$VIz&kt1LsKWRvgle1 QX0j/0~=9^{z^艾j4DBB~e%|iyOJb3Oމ?'|2[nrZgq0L k%Hm*;<%t0hԍTRX[I)F 9KJYJ3At?+AK33^Se޽ f ijeX S!" Dx1% ~ɟJ)5s< Ԇ|TՕ9"J0WƠ^bmjqU]Ù"rTwL{rix_aᓽ/K2"H4 e̺T+R+:w!l[p9@L聼ٮ;+炠N`_2E+->k0~sxVeB-y:[\"ZsgᆠCr&ߚ2<3BQM? 5_NmW뼴~սb Og VA~@>ݗ(~[o-#HT1 pmMmd/\Cz?)\,]Q=B "L)#H hEJ@&Y/1K^rx=/)6qgb! Ùę"9=O.ddϓ}%R>.#̖Kt==:VB嘪]$ٍf/{[E? oU@6ze#uwSl9Xҕi%A dՃNĈsƕ`8x7*^g"dG9VPܧ /ɢb%./ aዿ5i_` Ӕ r1A20dqP4J?w0A}xK5H [_%\Fg BzVyS>۝rM!A^ٰؕ>vhGh97&OoZF5jرXCЃI78 w {L^4-HA=W QЃԜ%HD}?Q-gơ "o8`Q6-GA۷RDm/m6'$ aEWw%*5%! V@~!~D:me5/c@czk į! }i TTYɊbL&zW&ω2Fnfk}Eq-@ar e{Z7%KZ7@YIx$T~[F\P^[>ܥX68;`e2. f6?uHV7wO@y*S>H7q£ܒiA](>pOtk $N39o@qq`h*p!7 "_Zܸk;9RZg3M=E Y<5R2LsVONOKk ߽.Q]@\xC>aFuϊF F+d;L&d/,} b :K 3Eg;ddJI|s,iv,nIPc]Ǐv PSXOpYZwKտ/BVM8 z:gWP?!=.ݝ5py di(I2#~"˟/hx(J^SB4M1.~N#uS<.&fmvC60i[騿%gQOB*G)ARGI=l Vxu2lAP0!*&Xm.6ؠRw_qcZ6+ R 8SתAnAv2{ϒK `Uw 4n9&# CyV49$1lWcjbp! A , _٢Ma6}Ϩs!NR Z"Ը~Eb>>T!-fA> YکBdFz3x`yxRG]TXUg=6 !L>\hVd : œEآ[,Y4I`Hh-N 2oĢe Ҵ1߶wm&9w.nO11,=~)q&3-KˎuD;E}!X&'K1<xðRΔ2R=\7448O]*%CcӯD(5zm?P!7:ӤܺGd4(i8_[plB4t29 I2tjw-=j$h 0L޶3o;pLf*Hv:[6C6 5I-$]fc%uχ-"ch4V׼b Pdۦ,5GD#ľ /D¢!gl9ZW{vhOS2 y}:oǽ[>[ °\K|2ծ2{d2):"Vz:yDҼX^oVnrŕ3. If!z Cs³_c7%Ԡ3/@7LЭZw:fMe O<#?ybO\㏽w/ʢZ?.`6Qq竭\Б-˒)N+ 2zH/x`͋wMQFƖ|QP<74sF ^C̤2me5uNN;~zy!@ (BQB#Q;W"j" -`rƊC8:WXN˄yd<ȘVjDdP'Y-JҐ/>· _@Mj`@zFtX+ˌv:V$ 'US[]D^¼̡jO$8],5͕{e~T>ş? 6V,sD"ҩ#Lu K,oΠnKra֨P 3RwbJKgBSGJ<6P.LƦ:x!W3@ ${9/!N=b]"X4`q/H.p 2Z#rtꈨմj˧*EdbDF. i:or^2P,<4MIڎy|cY~| <OzHlM-@ qI COG露hFʭM]-9`ZN&|}QDp3=hDɥl8/-҅:_0|0wZr ( =pwzJ,9nԝ5ߎ\/DKԃ7yBo_st2hķઞw-> 2{6A()`@t%!鍿3x3ݸ \O.{ae_7pc9/8D$Ŧ4h%\Q>,[/*Ӱ +r . -sI>(Uk8UtOԧѽ~X=l'Q>TV z~PC> ģ떺Mb^|n)$pSiʹzF_$ZvpDD+ ^ (HB s+AuZ/VY0P7-@pɤ+QyC'P^DM8P=Ѹ3fcp#V5""gx˻ڀ㍑PdXܢc8o|zѱ2xpx/.(38Q%؀@P쳗9+_'şhc;%o"NQT54+kdY>xc;Ku)I.V%Ėȋ|/j(*1Cc*oJ"с+_|l0}F}b#LeA=ac 0a<NW7OQ$_ WeR6PD/ <|sj}[%x`qtI>Pҫ`& Wzh_ 9O!Vŏ>F $|~ƕF'KmF'fvҼ, `QePC/ʢY/nRA#d'%W4/zvC#tPF/.1 B^ )v6xj.Y%:Đ;~~sowi\gnȃE%)B1:O,ZN!gWvVpF- X09h)VRTqm /'OxS̤>\x j& {ԻŮZ-ƸN91#UeEfO4^>=.2%37xo0+ @ `[ ι]&90ٳbױZ:4Cw,⩽LlWAyIA?꒵6p2G|1eRN{ fQ[昏x^@qY2-u&^6FPkJQZc'j Q Yn*K=A(SӳQ,y+F&Tۛ w`k8O bl\t&SZ iye^wBRS/dC( Y6 '.wV '$3K5L* {dQbP8V4`唌jȨ.-p-nЄC%t*tW{r S1; NBm:{jh^:p"V'(Jdzy:oo^YiI>v!B;~Zyt20;V!+BGv c$Bf,W{P . Z *[:1'Ю3C_T'p̿1dǃ̃(]$ ݛO{ '+I' f՝d a5- Tmu2D.[WSHck1݋ΔϡS\I&6iO#Z̲ yxaAG/P:r-f*4ڄN+X*p"|(OI]vy ~i#->GŰfɖќ,D334/<<ͮOKV" LP]F[Cnq뫓?'rAU%,q2Ҩ]vcDF'A/IoM<UuP]АюmU*G4mAfM"\;? YKASs7`Ȑ`mbU yMk<4fʰD*JG3N C}m_WC|Īޅt%uO7CҘB[P$ !m#D|a_fAa1jOCJ"5pDKaknBG*Al XY;>'8`s,Å4Ԉs;OaK%A Qqv|y U* pMZk3 6D;r+ 5sWԢcÓ~B[qJW$(w@׫$ƀcq Ի.MW;_벱pF;ߤTj"2<7`z!{W-bu6>YLdVk1lJ/+l) @.6ON$i H=$>.XIYe $+[cz8, Cotѻ}KS!vHRaժ=<OLآ0qvÉ\G=sH4IZݺ7pXL> (qA}[aʙrޱYbAgæ? KP|@y7§!s{y^! VC%x%byTqCHhl;(`ڇԪZ]\,'}MrqiFr/0SW+uYh! 6 uL8Nk)*\-e9ڦMrK>\_E xy¦GNzkAbTI(>uhOfC7&m 60Z\_VFI. I]„S+F;'I4'{8HG(ڝv:_^3?ZHE""}LXI`Z =ؿ7W*?; yG72hV]T,"F},˗jAɘ|O ӟβC2qÓЮʷ`"KUh\{ 1Jߠ$Uˎ{pC 콄;ČP?7ӈ*IC "@Eq+W"uAiQz#GD)[=)['QwGH% ̶ {T?s9/<Ւ(wӡVȠH[Q{&3|HjU!"ϗf #O,ۑ'..%&NFi@LK#+T^=`Μ,x^H#Z}ЙBGw_34 wBzuIz*WxC&rw\;tGh9Z'u2FP ^m%]aI͵iRxMf 8>YqFb&1";8p-}k'Db1MU}~'uw]gQcMj$:CvFW@`sJzRu\u:֌'FFIrǻ~;*DKFY]`29)+堸}ncm1y] HNp$@}:ٰ4߇F9.5-O!k:vn`B6I&yS! lar3xw -"QG#MKU-$j81W_\7#i]hlBv{$d8X"qe2Odf6 7g}+s #dpY2N jN h3݌N츞[ϿʸG,h|hUzhOZO oAȅn?[-uI6ܡ 8ktjݴd(̯tiN= Lh})CjVbE^O#Y?d=ԙR@Ҁ8N ZA]&~D">ѶқQ#H tU9Ǯt޶mo؟XfϬ_׎9.q/C7cdNuwX&r#!wuY6=/kZ]1 (ߖM`7L1S-)^XVVC0Cab:Έ9dNK7( Jס*@Zw\Eu/8QRCՎblj2WPqKƫyxY g4 SLzG3Q 򍸷 kHK82-՟WNixJ98LO2YTw9@[N$ Snmc.QӘ"ɂB,]ɁJ[\0 o{UÀšoSC p :)z>7V'N/p3F/F[-lMWO8L (vJd^-;*w I`rK;AdTc>1sez@o-ُ,xS9_?gL.gjl0@sRx;jԁ5vއÁݦ]d#*obY>:v9Q\KhTP`7-}K%_wM%?G*/Gg drs4"/;K?s^k/.U^Vk/Ǎ1)7C1;PY~¡@kd|FkLj]TW!:]0Qɦ;M+6: (!(9O/Yw!_|~9)@8U7fq3,XCް}Wgx2 آ;둟 #[ږ'N&mfeFSЌ/ gqR!Xj^e1;F-a?%TN7%El{ƫF*t**62]䦛Nedi2Ï5:x L ab35%7GίP1ZpzL . KSd޺~8?P8Mˬ'D: ?Ա~V=x{(&Aj,Wr8۰ƽjb'9ord<Ui֞g}Ph/M1f)U&NYV~d=Nvi@+!5$Ђo9>!=A3gÊy5aj%.n-Ppq握\{tGm\{ x8?"!dnb8-gEC:. ^||gTB~>&DħoskbGNW aྛ]m(cmvO MuꞖv1zX!uṱ~,t3i=Օ*W*t\3(/$[8Srl&줐t.[UN9  }H{w-$M- g;kN%B9~4KC彿&6 B,+NmYU0O] k "` 褒B*B-אZ*M@wM +e C{7v#jDxfdŜ(˧zx{G 0tޮaM& Q 6u޷>(!bZt+x0!iYV6Tb۽Pv$Df#}aTЂV IcبPf& G Y׳ _31^3>ȧZs(؜b`綵_ݽB06 G*z(kF\ =i\N{\@xy@`댢m,ičYw<w3줯1M UJ;Ք:mJ+bE7Ջn_A?_6 qT;Y5,17ks\25*wbWN[|bEx  8銝Ζ^OLP[fDJ繴V%u|&Dۺ>4da~~3/3lej̓,Ri 'gܧq٫T 6FCя>`mG/h)xtH GjXBEEz~?9ɐ7XY8Owb[`x*ΜWo{v!c7&0ZryZ_,F #SvɉALE]]jLL"(LJim^"9ܕ}Ff^h&K-vrLl-ͻ>+U״?vZ\~(f, Г`G"1vʇZ|1uϒBaUuOB/F,_d .i3NL+!}̾]*Iqu/GGqSlѐʂY[&P` k?p3PȆNtUYܱ$;̪xН %3qyzد %N{7wX>JSfTE|cj.wy);\QI|!fE7^W~@2/`Ȱ ?Vf=^G/r&٨&.|%u1{I\-Oi8snMʅ{ 1%U\cx.He[lqK\?2z!\ʣ3$W#` >\/咧(4h3Z.XfIod S$-')9"F5 G](0~̍%} :=V4B)ڐBxo9=/`%kQT!DlAc2F1j7{:p'@wp$,Ã|:M >reN6+PRX́?_&^ EjX7y R@y"]罥R7~Lo%u^_ (1o۩j >CeFxĀ |G /Di( {v'9ܛa[+V}8|lZ+"6_A卍L \[ʺ^ӮΙ2' v8c#ծmޤ>V !>{OJ'R0X' Y)x9f~حɟ<ZouB1߲T>Q ;$doB%qm9Xu#g2i6npXdI5n5aCoԏApY{"`ǣs!ŦZLD.`i "/e])MFWltdS*dw6ګ=p^}>J(\s }T5y;n 3+|W͖8 _8'ϐڥw |cxNT.''ef[~Z~p8˼g!A&Pm3ɳ *M`A5GwiW;O4DJb.]^+D{M/ˋvRh/ TQTVVa C.hmI۹O ӣQBvvrd>?5($'nv!M% p} {e[[o J T/xȖ5bM~hRĘBރ3wfQyf:co"ڣFerNHSxp" Lq{{p(5 ]_iRHwnera6߳ه^g(9QDI ^`L5R@P@oE,E69IV8? dǶ1cFkewł6wh0P UvRMdq&qτYu*9 MzaTO4kؐwx G]lIe7'48&fmPSuu1ƿ̒d^4)26++;OA.?$VAOQ\ݳ+kB)CyxxܿalqTwvyC*mJkΤnD}c F^+EcZt`;Wvy/C9r~#T+U,UQS.Tx bfc%ri"=߁f! kOv Rۊ2~bϪlZ-]`\(X=Nj=o62o-sD]@ .9N%tKBD `>ioAN ;;dҸ˻lke] ݚH4W&(eKXxZj;W?}EB4" 8jIϽ3VuϏMI?A$(ġԍb ((H'xI16;(yz]?%)DaJ;-UT"Vo_RmngȰq;<n]SzNFb}j.*k|H󘝚[ꛊ O H!#U1-|{4L|ɾ}¢{$ӣ#q ~>vK1MC h$fÒ-%a]: /]k^4!LIbopj;e \0z2d lefbH;]pv4-(-0T=?_=hC:/7C0<j<~-+H!dwDGNʧKm>^ۢܫbdzr-Ƨ+hTbЊ!E( j/C K,Hְx$X⚷( بLNW`xؤzz5˛g; fS7[;c щL9Uگm՗eTh u9M0_3v+'n<]g*+w&!2ހ#d( 3Lh7A(Qj5* h46:c>WZ<U$qmH9^jU@@B' )Lږ)OOt̻߶~ۖPcC3D/Ww}fC?E UG~2%*}fv]jYYYU;3 8#pȽ 1 o +& qW7Jp @rSښ^j}=\ݢq}ס\-MvK~.KWD cT۔C`8Ŭ @olF$-6Dm{]\'XscZu24x%e _e4F_X-P{,j^bΐxGȿ`ix:AZ+zaBb %PKk8F% X]a'jdh~S"0%qQ%N+O.e%8d\SGxI5XXli{rOd5;y;3ƓL= |e`>ER𥰄+2%]ɬa!v|gWaWt,gadηjl5c FnƈD ȻE5^.ꑰ)ctHTLɠ7By)=|sONy..IJ%#AA;f "89asuo{88kOs:r  |PP2ʔ 7e(m<|E[E$|+ 6ZFA[qeL ձtT-[սKZh?!;Œ1Ѭ~B'S@LCky~0 mO+Z=|wt&9H罱.v}whhZ浘7PO[ ^FfwcFHJ[!+NDWՌX[nr ~ϰ{I InKS<^ozRbDk{.55YNٖhjqBBk n9GفilԢ`Wۋ)m.Ei61+Ud'gmL44& ͯV6ka';ERZM5aQxgjSi2!i18^4PZW2jOUWk? Ks1Pfip7|}4tgRZŶ .LԄOL>bayJ?^(jc a9 SʁwC{Pؽ: y 4-P@;DnuË ZU]lĺK`z4-ѯ+!՞}[k\=[tFiseWr |>'xLΣyW HwLS*&3i XM! 9bj&IK:HiQ~UcYw8,ץ$Zݏ^H_V涡 Ρ[?#0>D;- ]jCP(AF p'xx,o3+ж˘]F4XY}ckYr7b,I}C+޳R=y2@.ʉV4 SCT@d0M' A?pr|@iH(Uz+׈mJ6Mf嚮$"g潬nue no(JGK/޼Qzw $5~rYsKt .CX6&񢦅]A}pqܤg9bmzs6,G dRS\ ΦŊm &.cSObF=Ytnzغڂq{7i!54T0akAyu ,uŸYX骊G"16 Bdw57κ!/s3Vժf !C BL#óʨrL\ߤv|"@"2h0[؃R T7ۀ#@[VsP~Bz.xsx"FAדFDbsNs33'=2rx飘&&Iw2\"qy^*-ɋNX6"`.nOy(TdOsQ\-`juBͷWBͺw Qi`K.jQ TTAZKGL-kAvk9Nb7ʩ>$(aj5y@'5n2·Ʃ)DbKa/!e1Z ,P$&%Yq 1y`ʩq)t$5b]un˓8;W2p kRu8Tg弘Ef@+ߠp" ߖ%= (d^ڋsgcvQqFi+$kj}ِ&f%~E\?A q `@r쑮W;\uDMIx1-}h-0"Š1RT$v* A]mG35=b\5&s|[G9~@`ҽG9(pK<-y#ymkOcܧ]&G$Yo 86z}B BķiyP*A]IwmkVkyaŰ:rM0o*' zgԍ;,ߩ)ʡ<7RB݀jH3i@sޮ4 ܈بAF$\$gR,mxd!^ 1  sb4ṡ-t3di9nM3 t[/vnX ǭDvCbgCv&i?sE(B8؄ d1dG'$q(R#,V'cCWen>SH!p8na187UXWx M&>pi4'_RU\#gt?{{:''7cT@{%ՎM]a+o5L7jE#d",0N&pC{|0 !V![O>0υfquG_!蒃e k[=\Enj<ܦ1:ŠpY{Y8"ݚ!A*_!OcJ;i4Nype |ch7a)b ~M1Œ=@:@wS]slX(l& rH%ڧYE/U{}"1ٖ.ey(.)"YZJ(MroS9M_CT!rf*<x]m([CJ[5%Pu3-X2#Xrf0]NOc&fIU˱BT}ע,T3+ riZq822^N>6T(jlZC !/j"B/geJ#SE*EW%5d9I5@&*cYk| `{ cEӾa?D]_ 4vsd- .H@mUv`Ғƶ/AN@7>E]NS>pV"If9 $CѶu^R7 />S)*G)s^%ظZU'!pIڮ; "cݵL". j_pr &k}nML! _ҜS ݷ{3 yj3vu%vduw$ǻ3ıţtk~;;2ȑ`hPelOS]T"(JX&AvP"]P&|4uL.&3;cRa҈Ya~)&h)2Hɱ AlĆ󶖮ަk=; \] Q/ۨ8ةzI5qɗO3;S!Z7d1"s# 7񭃺6*<G+Qq d#bmꗌlt8ghVmp[䠬[lg Xm%bKoH/$$Y -Jn$9+^!\VL`5߆#`}[|mjKҨ*mHB]_|uA aDEQǍAQA,hȝSC0ÂLm . kڧٝsK(ԝ(ZQt .5p! Q)'?}T0g8u*\ _T6ΑHupj0PCYpd(VNW/eZޖY2O>Gs[3PfҼ 9xE0۳ϓ.$Y#n 4P PGKg8K0T0YS^/*X;orMkx={;AVQ{! lFǪp!Q*1%?p97Z\٨TxyzfzE7qc;Z׷! >ǻuAi*rʒ/-vi6 kDͻe>[_\@G|ͬؒ?KzOη`[w_~C*O극hʱӚZ jX,r9fChAtII^<9Q;Kԋ: l@QI}v l=Sp=n&ن (%[#4`JT`[3 @K;O/:<6[>,VuN&Vj_Nss؛UySߕ >ؠ ǫ!Y6$EZAt3_QH(1QIp;IPb>©(g@iFdh.mw .`'g^xa2O^ ,C݉> ,p陾%//I@cNvY`+pgjfiYRJiEuυJaeFi>$~$,',$'v@&/ Lpy7@oYb?B'٥B룧ɵLnR%k]5Vo* :]^W,c6C9uB)RK)Cgs0CEx%3#{fRtgAbh>揖kh9grio o[%h j >׀0]Е1VN,3Н"iV^]ey,eEUfBk͒TD̓MC d.U'}>DZ[U57 Or ԼX&2/8Նk ݈5 'ػ9`tьә.Ur/I$i3q:ᜩ_Cp"5so[ށyL[|\U! )_X&B^ roDA'h :WzoU!WZL/{ +D.(orZʲT$} D/(jc9#3rU T*n'2|ݕAJ"x2bppyc]'}$B2J^Lt+$<0FDMSB0qxရa(OOpnA-3:sH`5vƽ_޼uvcQ:P?iFW1zYCNqYm9yưeȱ'7%bRU|+˵м턹R$YWcb1uA+ᙾ87W䤦E4P FVleAȰ'ۍvI[1!FheRW\T[OX#r D7iI{oSΓ Fh+ub_SrQ9֡Z햊Q"d92-iyzWJٿ.0lW6Q-] #6j[nu'+e`#| g9v۔uGo#$ʉOtu̜RRM,+e!{HUX2+@6Nix@S{Ooou?7X?KZonb0~Հ%*$M ?Y̯C@1]o$6>n ܚ҃e ;SNo]t!-0xO-#鵍YnhU GRiڏ9dPk@ij V˘Ojޖ]AiH{4aT9-Mf8>- {Zto0s0Bs}u*!PHxyzJo4]Lm\'#eB8.yEL5+UpY#KW\ .-DJbJ<Hs}/(,hV+ՐQܲdh>UdN-uB|wR2\vAؐhD>FF&?G ՞.!hT4s'2EFߋC\ ܛGjwpBCw 24#| 8JyD4>KvفwŽ*.f7V0tYhAqzmO~:Xv#ڣLty,8֤7PB҄`Ea H$ ǵ\d*%n OpzqS`ְHn[_ -KОY3HAx0 ;9d`CbڏY^K {A5R|F[ }UmʣWVzI(FkdwjV4^N&4SA(s 6u<6pAvG1EA_'je0n;) )N"E]~Z_)&MƸi$Lj!zY+᭹vołxvwQm-ƷH'RVDSr[wZl*糫TS1G7%f{J< *:dai%K%n#v]U5~#Vh4dQS*on}/9'g!?K&( |\5%6oceߎ9ЕLxRD\ǵj IqMؘ柍YQY};*aC(siI~KJKނKuI0ؒ 74J6ϩ0F~ɟ 7: B`}n+pCa/nCU xtCf2y`#q%Ukp*y`Fvf mVA\ᔐiȢxm/m"/UiB-ظj?ʁX#=(#;B%!RIrc,}yewvTn6 sbaq>4y:V>>H !ùkUWv8 Y!P 3JpM̞M2ސy?g>T@hÝeiI1Ȗ%D\eNѷ◕}Wnܷbx!\L`tFڏQRŸg~GNKY $'`z-%@ڛilښmYՋh g_9gz ]Kg}GϾ؉kM< W!?QjϊtI] P qX@Q=[ǫ/'Ajei!~S|BuR#+au)y+c2o_kzO1NnĻ''nBGW*M_9:9 5!lS/T떼qS::K8` yVb>Ql(Q*+v0jmdupTUy@r"!B?V^Qiƫh w|;% Z}N3MZn[t(9nҜ?)CMJP5[A{.mNl\[yAj%ɗZV uVbuczmh  6^jMql hԳ&C dیݤM,hE'XңI6ƚ1`@-KvZg;gD^i4[mYr55?h.QmT䥒[RfY.R֢Ȁe1Z\ N0y(<{0|͸IY`Ik;,'?:1}5M#X4!Mp̐cWj\L h;%-p).ߝGܒ}ʐjs]NORБ|[e4zH.~n~yH76K9;ɿ I,a(}/Ffvd2SshYb4jc?Iڭ=1 HPI`5-Loz|P4;i\-z@iߵPQ|R EѧnRu=EMuP@Pm#q*Pъ<<Կ7$~6ͩb|$\rqƬpSo}}"2sB@cSr@!~&74Xp@Y{QMEWVguon\u0²b},iUy(;@TQCZ$:4s_,6 ٤rWU=iH%J!;.wLE, iS=UmL|[*K=𠙘l$ vFìp ~*/Qaz:Bpe׈^#d juU~gC{!+Z'Ke&_14'"6Z (1T@^F۬'Nl `l~}qd7RMXJKBQ~".#(Gwru TS?7K/t/3kKNnB -4MۖC^yh(uu̚\@x<8`Rh47,ʖxxHu5sEIb/@Q Ahㅟ6:2 {{>ޣ?Wyie쮻fݹpfh*`b:tm7}vd3f:bH #v uK&,qr$d4c(E-n;n(aƺMG.Ƙ]-ez]=%?rzM 0Ĭ ?Xd`PnD+i+fG#kEڛW`"5YHRP$.],.yu gJ\y] *3m9p[j}"vS&un|$\sq {F^{g,p iS*Ɓg)s$1 bHe&6!}4ׅ@LF #?֡TeJ/VӴDEKNF Ɋ7^|`i~4`x 7Ps[oöO󾰈ktaJ_gLr=n-(Uy^$AG>{L t nAdphw v-˥b)W9XEwR1Y֝'!'ܹfwx$wBVH4?-)⮰ttuƐZ _3Jj=?Dc|ؕ8']B(ՙoPS߶b,MڕG7 K>&A(96G 1I`yZ$,!W<87ÿedyD,dlD_$լHmGՙo\fT岦_Ue[6-w,؃φڙp҃>y^ŜJRL88` _7d['XGc8`3ʢyɮ˴?KY:DQ7$._۾ ]A"˙MM`+p=:fziM'ANמҿ',a8.kzx{V\]ЎdNb+X8DIaQ|*fB_ɐG62o_&zl{l@"H0gӊ")IBPWgBȋ2yS̻B̴J/O&. E΁5/iVh6sB-=O%(;BUaF9 oM.% N$wA| ﺳbΚ`I)\kE0Q(3K0:nikAs\^Oߣ 2SÁ-T_B_:?5Y+ϗj77?!'^huqE~r/,{R9Lw@ q[dSALmbsUw<٫_M~%Th-$ <=eaǿx TTt:+@}~(`X!Qu%aG!bz= ]kԑuPu<~7hJg ߛ$Á5gCBYot &+!"9쨾4;Cv) V|ݙ-W mJ'W"Z|`%tӾZj,ߚS?S:$[&%;JX7; Pq,+UX맞#k+\[5HӰ)VOآ% J ^6 R4P6 CM>]c]y^ WWRONI/D*ِ:ivxm>yFnܟU 7+uS! ('XPgcal)sntҨ#UӁ;nŌvUK@ᯡ371F–NIb"h;GCDg:J%AUE0i5n7BkBıOvL /FWO ^M2 gOZN"bVA@ҕ @VK[!4#dIڿ(Ű!*BM%wJhԑ=&]HdPDa9alSCc?sl jJy}dzP,GxGT8,/ ☥qXczqvygIK6v [@OKC譨$ zQ|u[cr`&)uOq#~Pw)ܜ}L\."W^,! pC g(r0ؔnūGcg<8pv10&ƖSeZ VB,~M&'0^|{+GeAmMr4qIĖ:, DU>s6hU3 *_gWˀAFZ歃Qo1}l+Y^* \Y[2u/)6ח >{ k0)`C}SP#.mR mˡ3.$vaC)5&Z -v{ǎ[F5ڀ}EP_&թYkB;jqYptn_k3kfd c{oqܦIa J:+_[+"// 芾h;3wHG9:AB)1(aɵC[Xǿɰf(2!zd[+ޯxFitg)"}:0Rq:x{0ZJ`{˼tB-)ne^|(w'~Aw%/<㙥"D,Ţ217y"hCHJȴ@t< OKI Ugۋ@%bp41(&<֡\7܇w0Ȁ<&hPPj- QH@VEA ŀ8faḴg,>6Un;,7T5J^ԘOHпyTZf2[^p7 >T!CÇ(ա/4R'@/&qJL)c7J_]A̛)D >S=XPhP>МUn,l(` /&=-G@rr6%ٕs]GךoaK03W<oّژ,rSnI”9ri" HPi32Ii8N4Gl: q~s͓ u5ˏ c n癌py ߬kzznYuk"u٤\@,5fBh`l5?,d{B1(*@^a|G.AƎЦo["2 ! G>Cy.2p $*%4YXq|rgq3FRΪ P}u_ic.H Nh/3/rcb+SK|W9kP9_k{GŴC(_B )r ?o0@^.2raɱǔ x|᥌$GVND1S| fXdD*Nec=$+ ck|67HϞך@6NN3W-\pK@l^WڧOY =&T>/a8({G6\3S|_2>r_R:SQD@3.`v9Xn˗צ~0-rQ#|5/\~^&7<<Zf? : :ױ^'ؒڜ.<̰H؀@!",|d`ovٖz`T0KKL" ~}5߰"mLtr74]<"'CK.̴x}+"H uL5G? :Q9U %[Ay1.q=M=ä~󝥆5Ŕ=w ,/y݇DTcJwxUbbd8&,~N߈ }:49YsAEaZ2914jEH"@ ,]29ZmfuWŖ\c@UN^ Ϙ*Ny@?V\. 8 ӈ'y:n˒FGY$+;(+#b#J1)#*2h\=Gys:$GWfk}6߃,~Oy;Gbu[5f0 .<B2șKP4IȊbͻ"pG<ų>bFHb|Q)ḒZpMso5\;\( 'X]dKV"n*~A?gJ%V\tZͼVƩ݁o29. _`~Vq^ѥ z7jSg_GZ@n8{krWeCEKT^L-0MU2id)%Q"dN>Foi/x& &?7U=䎿R^C 뇔歏/y$Tw4o4B?.%.}N Id E3(G]{:;Ϳ=Rs1d@{Y*ɒf/ hL79ML⁷~Kx;`faK ذG&6j\udF'S{;r.^ $5@IEO+Jߡgc@v9xV&_tG5z~?.Yz-vQ ULa4XvY5&7\De6?YJ^2Xs)-ǚT.}L=⍳~mV6)=u{xqiY 'K4ke : /_1 1-RwF}MTGtsk1!D,`lQ ؆NiC /o؈a:o\ Lb #=>i+o%A0v# HüJ+ez GU5b[ˏ5 eӘVQ!b30[Z>9KMR;PK'3:d{~6˯Da #jλ۳th>p2"#;f8*_\6akz[#ZlE҅ k1":J!Eie B¢`xTXqݝIV{:T2bn)UCXn CwR t9R빥Ͷ&Eb %LfcgmRt3Jc\ߩ&u?W_۷k_<0#ԯ:c]X@c*V>k+3nNr$iN. %whdKАdkE|Xe*$ER*PE5b͏ {>Yy֒ȍ3#Dj߰ g#9,\,6nw;IRAAR;׀:.Ҏ`:2?b _ $߇@EϮ`Yg z)qwYjA m@$n_Lwĝ ') Q+M4\9%CM.e^ٮ4. _ |.[jtEI}ZB0B>U3mHvx5z9c-IF1H]<~޺vXx8}'SlHm{vEK*;h-"ņKL0ZZkZ lMU%?pzU{#gwި2w_q=;JT/6 w믨یh߷ o'j9h7՚ DR\F<k#ثo({gan F6' r7ӝ--\KtFhEq@*:Lwz*y J?%4Y~??0J ,mV,Ro¢aH&p!;ŶJ `G֝ &>a {tԋ8IpH%n'|^*ߙC! ?Oqz=bT{vigw̳D!}`ZwVL^_x]C.{lx%C,g糐ӛGL{6?T=`%!>h>ڟ0qyTwq{oXv:ڵTюQjzFC*n+tKZM!}H~>@qj)(Sy/ =o鲧U~AAU9eA{C'aTP@hfY xt\4oc@NrpfnF ֪hmͼ'_߇[ ʬshTnDKډK  -"_l2̭.-gsrbȄ0َU%q?he_`S'<=L b*Jyә:<=ۈ $FK!] buXgOV_PGefr}6^VRt]jRO C$!lQ%\iGb3r}fwxuaղvq-y#tzh~턶F=[חMI'y~$>}2`\2ɺsj]qg &B*R:t4}ƺSHύ4%6}ܱ<_b ?D7X;Oƍ^ڟSbҡ|-ySJ8Y̳䄾Ebca]){da!M4L*~Z>b ´9$uB-T5^Ǔ7ny_kҕ FR5sJE v>W>OEkG<§FByiSU;o;r}>ٳ*fFo>jpDaw]MfqOV|31+34I1av |-/PcSG{5W:ﮰ_#~c B}M XyM2xIK.k@.JUk^j3`1 ;sDa#O= &ZF=~-7#= Yn_mNО1j^[AŚjnh[bu:.e<wMņ%=$V?߆tG"43 ^7}Vz %CD-T#YqP¯Ndآ1[J힩p=䇪#c3hѻ -htnwj$~~[ciR,FJs?Sz/)]~LY) 2jg *5Ѣ943b^ijD_ %74j)W"vu#"Ջuwr!n*Fz0u dU|Ss( Óv[sQ U9m%U0zdi(_?K}tDɬ:fCžz]kc󖦑=eRaw#LtuAyeq8[ ZwIHR4cЖvR^S]NU``AOm$"M<6 ^DDv@k)X *>?J%BsU!8ш=_wL8G7VEE*gI8zw&6(g2c׹E8 mK m+Hc;qFk4k@̋<7I, )DFfv^F׭R*V+ƥZx2т3sIutŝ0mqxG!J(cq;-ObX *Vuxm΂相E}X63PK盾 [\bNxG[k"|pp/Ḅ{ xgg8a%y/U u !.hY. !hL.˱Btk{}}]'}Wnv{UXRG(^6FmwPE#*Bdՙ"{Moj)UzY:o.9v̰DpŨW[sj˧*N_Er~w{UqͶ,M$Ln"xA]nm',dki|Mb:׭P99 ͅMEW=}ϛK%iyM:8rhipRr3O#(Y^%4kfOQd!M3vIl9ӝ=m|sIl=oLR;B$<`-ۂ'mEA** /n[DUbG$(bwD: 9[e!x]BpcZf'-8Wk ,IsƚD`hPcJ߶.bK.IJʢ_CZ) C /:mG0NJT}է+ӄIFª(ۧ:!smnؑ2m_-ߕ+KpA;InPZn u1^dP6JN: yߊ)(WD>8d3?Y I6k1%]ފ("vD- > -IBpN@ Phz-o"(7&y]~R CyCLɥl9C6 #:V4M1&|PTͷt<`ww 6*k'Nab.duln1H~7w|{f_V^Z =cyŒ'YjxoU5U1!l2VߠJn:_ Gvh|RnL@[>$d 86~Zj4~DAY|PjgvJHvUlHsof{V Yx,x1Z!#7T[cx[};t|2J,} ]@@܋(.*&MSYΉ{*}`ʽ=%\}m`5@'ǣ*$]~~]x ",9%vOpCH6bꍦY>ANQ{_p,7L?1}0Tm=mJ X]ֽ xٚr"VgQLqݺ,ށQo9P\M˜"th۵RAE82l"35t_qqtau=c]) rt7DGuF+S,ȴ )22/g[NtG\fdY@Wa7r̊?vȼ Bݧ_oWS5irE<`RGOחf OFs@:)a%O`mFkteWOuO\}34{~H=Tm ω 2yz'Tst#:د֪Bs!cRԂCu[ݍA,x-_oa OE Wϩ]Y>g_~؉Ġ t/i?㓿I@gJ7|~6 y968{T)bO#"}ʭ7C-}5 ~gˌqmNJ_p9_~U7 i@dH q{Ɇ 4;rtzqIYeZviK1xv9~ Ԩ+daF=^( b-C.@<To͍}QxV]h9=`xͶ (ݤnyBnXQ*VDNu>\}]RTrCNV:G0dS]"ElP~wʰJT,Zts-bAXjc7TЭ6@!Mhk! %et}ٲ1 wxJY&Ϩj^}쀷k.oI&!F] q]`zz״\]K18%PJ 3^4\ע:V '=[(pB5iAy=esSU3l1ʐԜK,xťx!*ALgWdd܁udj O"t}PUPO&s/, V3 cQ&Rۧ]tY[tXiXϟ-j#)Qzp0Yb4zhHصӐIOL":SZ6/ ;Al5NW.8 fXzz{8 GImd9ox˓C^"x! 4O^P $N{`@%.6n l7Q0=xFKbӔ>|,i%yLr/TGL؏OSE;3-Y>Y(D2oKr3BF5k# ]qMk|dNvcq,SCD x6KdUZ#D>v#$UsZ]MPS8%?XoX5!XĵnXt\PD/&m hRO m6=rvc,2'nwa fw.yフםioxܺw0cQG-+B7{i?ԁ NOvi(|y6c* <>Ul{ ;Dp;Z:`k݆s봓('W3R;y,a9`8"fVr31d,ɕ1mN򟭉Ú<0>*)@M9$b1kf3*Xo}eT%`!J]kH`zM ϛ:}F/Vy󤳋}@1ݒ H`E-5;6Wd|B3 QuYD -V5}G;>~O4EvFKlzF;6o1Z)!9YVuD@"q7t,X7AKc#;vy4bJ&7}Ӗ:2IkKfbuy]$zP\ܻ*eC [+KnjЦA/'zK5+WWrюؿg򢱐!JKbͦa0^z/zbk4mV5gq, +PVe Lr6C+(e_ ! ~Yb!6ޝS* oq{NEpH͓5uO>q_n (Z %X}hmgƕϟN)<[Ⱥ|kݿݜ (ʗIgӗ%}G`7Vto^'[ՎeOc8FA>тiaH Aq/v&6Q2F? /gx@1Uʡ"6 ՏB֐ެxw15RY؁,W=!o,c 25SS^j:YZXѸ&{?Hg-p} sBH;qKzⶫ}~7#ڒ-x]mky|_ RǂFI}q/&$9xY= nE N#[qStͶn/_PL _+Xc8B\3oאB1SP H0"Wc15L;#FscS8Ο{TbULpMAL ;6GRQz?D}))cΙ'SrLY-I(j@ÐN 醪ݽyo1%N i3:aׁ3sg'M1!iQέ=3=NgS-;+LY[|#a*] л00:'^RYl]bbRfدyΆJZzާ6Y8y!ޡljZXj?}PuEh9e]tȭS3$cG~;J*v͍/5#/ER`6?*v\I!ˀXx HbX9^&nbl\d2o)ަۻF[I1sJAE=i#xuT"}sl| "ubTI_MǤ8xɋ| 47r1?OcxJJ[\ ͹c(!Ѧ F,0GgSzFU$oiL\|RmY>2Mi;&<&Wy4iQzμep ?n(WoMskV;W ͼ\kԚQcp ,R~szc;OJI%ΪM"!tĐE;G=YFm,f,uUڔuI:/@G "]ysb>UNmn c3ÜONkbգ?|jVݪ=ya ^9|Rbk4)yCF(ub, fCOttɌ꧑ 2iɺlT WǓ'cd@GoܬTx*h#Gŷ\׫\ g2 (էRfa #,Ԕ0H\_e3c\ZKvQ^oo =u?ϐkd9w6+nWr!b0(͂vU Plk?NGR[CmF$=8; '" z#dsZquE9S+Tc}MO鍡*>S~.E}PmwjRoY /A Klր^ G+$4,ajKDŽ A>x ,QMWMR|UuyxSlᤊt]:|ΈP ɟߦ3ZlXQ)xQm1"d<HLq2G:JB~g}xS_70J1T|zEkh3wΤfb5R\L** PXTC^" F?.93V%+,e %fv;8䎂ʻ fawn-v6d%LNא6JX8p_7-bKƳތ#V4.0գ.P[ce "ny.y=7[I=!Sh5Lj5y`g68sضК }a3qs#AN` ΑH {MPXBq~6<4[U!RHl۽Hڕ(7}[C&xwJoFo3ڵi!6 Rx9D3.J$ĂBZYeꌙ4-E?:_:Kg s+u*4y,QENs. jcpEťḯ :xwO\ڭwmvr7$6t]q;Axe,r]%OZ13o +_:`ّ!5ҘMwn]jEr/v5Y^πrZA XzB0znY\ƌ!ʟ!|d] "ay554=#h_W8bAhf"- sw y p6 ԼQr0H~[v`.4}gY8suy/WQ,>H’rDҫ-&&f =3byJ8RNAN8)*$K$p*^(*yCAѯ}"70|U_\MWmh e1W n<3] "o}k6^mO<$:vv[:ys":( #N#*M4Pwɖ!8]}l |3$r894Je'@T+> X1_l% Q3SZ.rN/`>6+韖{}\ *klzBci2^ibM4jB``a sZQ+m+[p(^G9 QM%sw*~/)wʩ(&N֓Q _"tvdXX{*gׂb (b~YiA!DWفVQG?=W b/[Ipb'zRcCwh){m[HoXwM%-4P: }+Xޔ+ q@tg|}'XV\<5TiYm'(xE)k5-m$Ĉ&1|&Bȱ@_QEIzG@@)[|AwpEHEyL4H Q,ڿV/6 p^#, l:QZE[:]m֗%[ۧRge_ֶ4EyIqC lDFLg |$|O^JֵP<3ޠ'-LVܝڔ;dO,$_QsŻ`Ϛ!{;6z Pꨊ2Q׶bGa'A\%shd ~iE={Xve:B!ě~T(U\c3LI~sr;s% ƚY"%YTaR L2m/}V:?)T(T@ &xݶ>BO~"3J4TX׬Qe$,Mo:xj&֎d+5FB"e7^B%UcD?Gs%C6˱ϚG3|koK27k~)b<)Gbit15d/]gX[dmW_ P1$w^yntb!{3;g\К^ƕHo)OREQE=BmoytƖnUS}F6t-0~u!"t=֡.X^@,51EӻkQ090~?@nR zqH"*b H^"wEi@y鏜R$k)Gzϰ rђ3D.  ?pX#i5jO^/@T{4ϓ u`I_)5 q)7TO?-;g}XT 6O/T}Eɴk㐘3 /~eкnC_Qu,}^j H["p#{^fHb[ۤ]y ~iVb!mz5s7 ,u%PUlk烊ԲF,5EC\).,_u+2YS̏ *4].@0_sv5bAo<)c*rv=y!@8`Z=򀘂LU'C^n|x2GY>dnjc1WcҿuJ_9Py#]/c  SxӤP7FSdا*0*go즟H|!M7l0@u[=zZ^4fQ w4\ ԛ Or e )']YTR^.0mh^M [bg[! N[3lCu@1b{.5zOfɌ6b*4~ ^/73XaD#ح_|G5 /h eAK0w"8c|*yЉ'N7ANvXUNZkq(z"qɑEkH TsOOU$jX>?F\$04:+*xf~i@b2jc3\q4kG-䂥cvg=5Egb0}E AbXߖk3\C@O{p9N!t! KcV^):zT*Sɾ%m&F! eOUA,s^>XKh >u%Mk8_qPJ82< wd\A'y vq%|h ڋ{0_67ƍ\,.T ]=GA:kfLWtv>*2h=ޑ?{/AՍثqS|>ڎgIveTv`eJ8HP`wNՏ=MsmNUe_wD38_B!mbGjHՁˠSk\2M"ٽb 묩Yi_:Twڂa !YjBGps֫0"2p&@LlMQvOSV$RN&uǑlgk>*×pT+/Hʸ|Kjj?#!%;+ֆR oZ)8,d}M1n'K-ઞi+ m)q2_$NrK?Lvˊ,+)hpOܻů'Vi?p#2Yхu6"N$_?{ YHiwcDim$0fdy]̯|5\5 ŵ\1i!"?`0,¡sLJ,L. ;Rtxbhp谛#v \7>uO]V`8jE= HgʊU hhHyWSzhc%pf1f'j7I&M+q7lիjPC .ŧ@WP@160i[lag̝#Dy8FJw Abz YsD2rFdgzѩ!Tq7rg[HژBJ^JiF(c£EJ:wl9A<~5x5O~ ,FD RjuʿNSga`U.[1WܕhA2aa`:<;^"+ި-)$~0Z's7*5&RyE (mWB+7A'66NP^w1댿2 2 1PĎ8bcy-\Z*#ʸgf%2t UϷ{o̠+!ω3(cHVH 5T$ՁtZ ߜ{pu\tMr Uc`lruf;m`bkP@- yL.9gaNhT\ !d #b_3(J.y;):!ܕ)bpۖ?w/QUBZmbw3iڀp=Xq)>##Iј?CןTh'Bwc>>Ξ [ʱ.ʋRAg9 z,姾%a^zhŎ6y n=g/ LQtFPP 6 $-Bn;H-/Kuļ<hL7٪@WG:ƆBG/94q^c uQ,+d ,b1ja` 諄UCs5s?wJp:%͙9{jAV(q٧DV"l MAo8ɿ{7UͬW=ZrU"ckߍ<A!L {<"0 V_lJӨKpXh54fsfJrޘyJ=n3kқMV:n*rЊTI͎dR-ǚt_A)N*x Yo[.͜OUrn庴s73<әf! : Ok]C՟GqCH+´| 2Հ$/|mqt5+S\ U 2usL |S^>f_x3$rtCQBq4Zɔ-9H$r l,WȣW ۣ\1Ig+Güi@*SO"}`aSTGͮ\b 5B+n L18[|jWs>;u|meF=&EE@PhJN&}5tUSaM S^긶BR^Ka O-|ReDTPGňWPΖݲݞ7s ư059+(q+?uHm؛z ^*$/8 >\|q ƍ*s# DDbu232 tI᪂0CXt4Oy*c7*I{s޲&YP$龪K[:EIB)lky)hYPu`&rݥyRjc;-y33D2!hC״ݑ7IX1S:Wɔ/P'ij(堰`-ɪbVɽ1b5B2PkyVsns|ĎTg6]j-S4&f &)ы/Z)~NP~8:+lVҾ\4:oBRLυ#l**j3HR?WT{'6aҪ xSٟb9@da<}ĘIRI'K}6~u &oK^hI Chtkϲ(+жhkLADB?yY4e?Gж_DE G [eҞb(W!o!4k:$qJzqNz&vykC`-aL g`›CJ [:dGl1j%]BK ; d*+|8߳@=\5;\ܮU7FYƐRUp%zNUk/,h*:+[woQsnP\@~oMŗcBw݋ ޞ/Xfb48%fk R:H8k@ҠJ_KTcQ EDeT4n02`8QQ,kƠ!qͶ2v,L2TK AtogG8s(봟YR_8 cRl\AiN9y>J/C23OIp>8F]^zS~/k!$$]DA1,:={p8#ׂhw@6h4.I-£?N7$Pni(Tow =:u%KY,p>ni2x uknHG^Aq}F7ɱ|/2 eD_ 7?Sb:?{Ebj\H2TD  qIƴKJnb\BL{w06'fOFM,D~mp9f:+Ef 4FОmlVs gIw 2؄3 Ua`'fĦEptd`5j. <:dI+ ѷkL3"aA*$ QTA)cRՅw|He>*F]lNP7b!tҦuih+Rxsգz i>1gP0dt~ }AA}c TG׼ߤN\SmQh1 Z5n68ES5jh_-¡.v_҅:Fy޾&3CExVM=Z4JktB_Ui{r>st+,ĂtO'5҉46R;W$- `f]W?47n>Ld0*^GfKK HfH 21#Z} VNϏfs,kg5Bí~j"NmĮg߻6s{S3\NCH"ta)˳b4gSLIgGZ[_(.$-@_b$8kY R=Bb~fI{/eEa$Ud/cKJ%C"xLA,ć3jp?TD8EWH7doxX4$T񖹆}FZ-c*vʙή6Nv38I*l-ZX @HG1hywb}>mdRܙkNB PINVO/ a3V.Xs~({ y"2ל[gJ 6L=(vqN]Г 1 5DF nwcék<ˆwQn+^8vUeϮVGdRX_қ](܏tX if>6ʟ=`ߕCnuȭJѻTD9ݐWLjFXVU4T`ZZLG c_ H 6ɿ ˛Vّ9#OYDL' <LĪwfQ\E"L۸sxuoo~XjqvGû81%~0+u]qjtySڜvfT߉^I# ЮVsTHO)]2fGV4Ybՙ'"Zi?~xTJ`3 _&}'cהle$m՜:4jzVv>g@Â7P[T~L|iaK[IqF?Wo8Z Gq._+A1υ>[L~%ij>V ]'2p1z)u,MOzҨ@=j2!{IKPxò+ '`dPg3;*JSx b{ .ulB#]lOAtj2fT7{je f` \mz))߄-`WGbx/wy.ap>ۥ @4f3G^Va9ew4p]ypA`_SvF'q6Z&2`B<. A*qJ`v眵kʠd;AB9i,mJ%TV՝ ~ԣf`[P9CT,IɆaEnhfkIGe09庝CH!+SLV{eJçʲx$.32Z+0X1'RK ۗ+<+,jJTsj7LxvR2(Qmv$@ Z\*h_`KMLnƁ'T ਆ:60W~pq^mex"HԊupQZY :ֈl#!Dwy3EOZisC%>gFvMC |Or[ NEwׅiJ`F<̕Mͷ5UK B*;Ψɓ1=N <)@}DUmbHGA/oRe"^ #aE(-$W7.Ɣ"$jl>G,?qfρh(' {[SävhcDYw1ia\ ܎-f@cf&RJa7K^J95 x s֦Cp|aC!T ׭m- GJ+}+ -5F 2槍Y,2M "ĕJ_9:(S4^z 6"pT՛\ <ۧ Ew Hxb*J-S?km;aa݉ʻZe)#n\%K!9YYPxdn)3XՂ?tӲ-16p^DG@#wc]"< š]DAkKzE!':P / ьʋ?o:Glz2T伲N-P|/ ,}gh/g#[_=IeT"ٗ7M`_0Ri `'"vWmPғ7y4e~.E&`@9 28rxĔ1$e]2,2;W$HC@r SbDȲA~?=~9WIш.=na䢐Q:C|^vfKd%`/1soISKIj\K &ճ:`erݤVcwIh/QSOmNh2o`>T!F̀r"phfY6?y?U O&H2T g?f_=MɬR]rJgHYr:AqԿbpn-\<|qV,&}iȫ DOS߅})%D u)>9)fΚ-z(ب[z 6Q2Λd[kk>ӭŸr*L-c +[ =$---.M 7Ijl̲5/W>2%v`CVAh AKbl6\c #ݙXJ|#S:Y ^p D#YR$i8mDہ-{0LbuQ${ -Z-hBJ@E^1wg6{xV&Fd#YHgfiDs`J,ŏÿXp_({Y$PkcBQ~u]5=h.L癥Qk|(r*E-ټZEyx҂M6P7> }Kiu1/S o y*"Hѐӟ*AdEz}[?VvZ#Y\d~_Wop7)A 8uцU -\j~Ўkr}W9)c ǝozXd7jM|/ͩף*jCsPx6Klw^$ {-x=7r2fYS&~ *aPUKNL̑W_qQݟ8|R*$OQ37@.2kPa_r5pݲ|͖+9HiRh"=$c'I1#vyہ(/qNJ¤-pwԖ"H#Dw䝄`b]eRe`Q|]BkM02xT\ˑ[v0z8i <"P{,'eY9j4N'FV=Ld&$;߻0 ޔ[?lC H%t~$B'hƚcqn6ޮ"aQ_ԑ~ Ucު:v;^'x[g}_q6q4\J% C+Z 7Dh0aO;SIB]7)'B_ϦGܸ(CZv]Tk6 K&|\ I5P%(F@k IFE2Iuu4#!]`Mf= o}.^-,J k\i/>)<5|[% lx~0F4TfJ1pلMluƫQ 6J a g>c P |rOP$Ks@Cd;S9@Y 5mZ")r:UBͺܪDy֞$8aũ?A~AWhy3v nwA+b ,CWQ[ѴVEFHT7af @0ߠA%V03X{޿Wln֓7jQDjkqFq"3Ej]Sf祃XxvoAtS:fNo nlzŸa@rejait^nUʌgS, <bi O+hdPLJO?gV I˹ns0nl‚GQܮZۃzyϛhR1yfP%9Ƙ!ĥ%4G>T $Nlp"ߌ*kR+/5BE064+?BŅJ"]a0ZԎ(䌏VXu]OHn탞(8ZGz~t5$,ŀ:cQy}6ƪm5oo0!.IGm\!/,Y=>> d2XЗ@lf')2(16ք)XYhKxlU}dwu)_%Mh -d~tVagYkf1`zNzX^0**\RPyMmsG2toN Z'Tr@_"Lˢii"H2RU E!{SٲG8V! ޚ=w_bHz$v+)?^TȜ\ SLs!bϭCy\ɂH Xc/[-0Q!kamCjW _CQAJx謟]Ցbr _ oi<]PT~[ hGh(?Ǖ5Qt)Zߍє19ƏL>vyE{!>"Q3K#Qqi}:g@"R EWnK? )xT7ڄN!Z,C1.T l+9OKG 4o%uV|: 0V@O/zK62r#g>bm=\Uω ȍ)3x5ˣ"m)JPT/|.mOv>Rn{ts6q k Ї1%R-HI54_Х=TVv+ 27##%@ش#G$-p*o}z^w$,vv?U;/[\I:x2}uDDԮh^RhDYNcZ"5fޫrڸ$"fLէ>g!~ܬk@_BZl ?D%W#N`.tS>λM}Œ ǟCԾOW<72l),PAA2t~y~f4=VK׭% /vg6dvMX8a\o_-C_ Q9t:1Mk>RއUN@jKxekZ+Ig]BA֘>#ɄJYdbaO(m٧ǡ[HVU(hM7eP]P'҄iĠn30g.&~hhT:o }gj lfNbd7JqP,JĠ3P}86 F=۳mqʸ"+͊7KF˙1&D0A0EELjץumPWeo%h3c%8pϸhpF޺d8I|/]Dw'"7ԩ5\p/)-߉;4,q?1=HI\nRUga2JjL wp&&<3t$*-I:JQbՖ 8K~uM6zVl_fYwiU$2^Y'~DDu,9{pIZ!N n*y% x@ '|m0yu(6cZ5R唘4W(JJ~1PEl0' TTѽ "'f omMUGK"uԛě +@OEb>hһ, CA;sPm8,Y a[0G 9T @aCq%Aa1SbZeU`B7UOQ/0FT~ayHfQR'5]YK/3W, jҺJߧʉ47mԤt.Hl&[Smv OG7h"]lEmRlfjޜfJb3к$Ls/Q;e1eWxfuz23a2E),IwzVe*W `ޟMԧ9.E@{l.荰 c%b1!##؄R{aʢ' _B^ %H>ͤ |fBUq>=sݶ5$zDqYv5pr5+!$D&V=(8%u }: )i ҲP2B,D)Jg(PN<}9,6Ec㊫- z"FثB&ЛV1 Lg xۡY43M1ү#ȃqΎjfǭpr'72Fͅ`?7n;5䉛acs 46nTl"'=M#df`UBO]/6(a,${s=c)"OLfuR_f ˅S2DWf-K'(h8Hm8oBU&H-"S6Iiwlx>/Q0dBԲ|St}_ov96B?;{ouB Zu,^Ȇ~z8FX9]De]6C0U#)odM3Rbj[&.9iXpZ|R9F>mX<1HcROɵ$wJ!N=ׁw) 4˿m+DQYAWzb$1šjO0S y 5.bs_挍9ӄLuYя"sݦ.-Xtc>}"l4J\/EhZcDc2$T0̘ ׇU&e e Jg5{\d]4c@[ /֬W^( HZS\.]a}79U<I-BR/L]BנM=jOZX?MUsy|F牽ģij5vD 4Ƈ>jYƠA X];iy+ ωyS@hVJ]1 A<#or/^+KB$eɊ3x䦬[vQ~nK Fp$O:p63Xa,@3h )5WSKeI<F'ݽ/|x9#;Ec5{_4M.B<#66(iQ!HT$Uڞ٫1>wsd x%W]̏e {Aeg6Gꀬk[~E[HW=6dD?}ЪV<pJlM4'nж_y5TOt|$,=֘TyZ3U,;e1eՍ/< nZJNg!Հ U&#lU/_P!8=ӏ~BLF 4SG_56D>%COJ bw튊Ռb"ͮbGO (m(HEefWSOjg3Բ1`b>TުD,NJDlp_h"PǪf7_$wC! Lb괳nSk  EϜuL)FZ~k 5Fq<猑%ϝ؍.;(&PK:vrsWc7Λx)~_/2"(#OL L0\磠TD;_{):Z+"](\^6cu{~u"*A }ٲ#2r* 8p;xX3jA6yvl:l\-`gO~fA-_+b47;H,y).;xaA;ҞGmB;D']P4AX!ѵ!*c{) rU*z,IphygФo'|UtGJgX?z&M` & lYST칀   =|~-P4aaD._.:mic[=6܍\p 7|h 5& >C(T2C)M(2-`b[+=]V!DƁ1}Q*h_ D73u~;_vq[W/[{UĨ8p;|'Q5g4'2P9]J:P>`bJEMǢCT7C=ÒM 參Ko#USsI0\tk{vU]*`@^ʸGG:@ikb hn(|Xvb,2A/lKscf[&exC.}9Tt /+fѫ\%3L ܪ2|尚‡_c1Ő4IO;sYWٱk_b܃B;6iop B~{rwP 2*D2(R-[~ȥa4sg 1M*XLP?FDyiũh>ܴOK!?[r98 Qe(MgCnȕ(<$P=J@v2_(>.dqڞaDUuRLv[5$Q%TҐLOFO|)DdEg#|rf-χzNW8I=o?I`>E^ة#9w=/Grpfj76Y~OHܽjtӁM*nBG,!&C 4]z5q̹DtWObך4nX8Pyt>gcP)PVgfNXAˣN ԌH][+EFG~)h3lICUXG~|7[5&=$;|Bxۓ?;0XQ;\ sE|:ɜ znȗU`19^G&?*c%l_JSj-3\8BQ_˦GU5VR_.2U*iw^HFi2")>i]Sn+t>fze3W ٚ<,M~v0Oz"@4){m+.a xtj)M-H6nAR a\0s(@T.>^ ]Hr#aET}d.f)s<(ـ}ijdQW#-}o?mbDakωtOC/fWrI\Τ^K͇¾7OpfЍfvw t=N?c vCȔ,0 |T+k/w$wQU|5|T:7ԧUDl5׆ڄcٮ~lX9SV^ \㋘l;jw(+g~ÿ@ċs>!yrV meɀ3, T,ozkmғdnmoOu*ŠQ4Ϥy? 7O,G+& (ef19ɣ*r/VEB-fݜ4,͢ۊ; a<Qsl[GێuV͋\ۃrx(2eO .B|@<);أ HZBbo)?_+h$Bhۻv^|x wڸп{nٜ=>x˅[s0i.s+Wo`+&j8d`ȲwؕJ1 X-⍪MYsv L|C(suRc0|"`c "z) _ IKT/:n@BDdVcU)L-:x;Qaf&x5\pX,$f lSː}/Lx/G4#dC)C#KY 1gOS)]Őp"ȻO }lxhZTBH_}~ḭX 6U{WM@(Tl㟩[w +^O |R=(wȉ#y_eS D/.>߃x=,-:6pMk2[n.8Tr7eQa\|S̵f4E>[RdT `Z!Ӗ̔ZS [\ .$5kdh3AJKpD]#, kD6d2۩oLc(,o툮Ȋ6 60ݽR%KA5AD|A2dIԫxQ(z;],!2zOχt>$ !kŷZKLj=&mƿWZ )a9eTumAECn/D:(P jք̆M2̧\Xch7  f01y9b́d'(v:K6:'4صP/y7Ƕ4h*f'iZ;` ^:W!l 5?{6#ѿ5q4fy]Ş\Y`RUGq3_3?]Qظٓz5׽)f$E":De&ޝ웵i9xuiPձƢW%BegEg#6Zj/޻ q8ڪfxd| )+Y_MB"@xY ˙l"4`;&S- N@vHAEEϓTb"jyLR8n51;:EӼO_>5`@my@PiwoJ|{=qY"ʞ|6;%)w#IǾp!,EV{S+Kj7u]>nUdӇE:B:z]-?~9muaxMMLSr 7]GXc8Y (-cN 0]tjh(_nO쪁fWbl@!5EbyP1+ZYQ{A湼D"QCZ֌=^F-&?k[9(H{kf E h(ދ:O_|! "2+s rS|D6T%2`0`7ElS#Zͩ޻ϼfgI|S}OsPHx#/+YH{[RV7v8m#6cT G1=lFCݍHJAW~wrQC܄W*]I06)p9ɉ*P '2b]Hu]M[ڲ =“yX^UjrYD5NSGo) ~,m"~8 N^'vz~sj{ _A *U "T..z])E)]B%aj\_&S-rb@7+:^%̈́DU%9+/r.t-('_'O5RxiWևBm[H5L3;Iygutg?AČA\I":B٭j楹6f98(R1cƒɴH-"_X&ç["E?qf'0m,]5ZW/Sm9wel?oA*_Jp,VGEvg+PW=!IBhx~_d_Lc(Lj|Np>kpR +!PFSC,WXd4.6C14 ּiN;S 7F8ڨEDFgu}v3,r⹁.E cKAs*#\ x^8o#6MV*vZybGS_(-!A.xJכ!&en϶2EL`obsfa' SZ oAT#]FRA86d0sw೻ZWX'qV9lV ]8=v͟JK7RElR$F_'7ᄗa(ĵmIcMHO2VOR^Q?Y VNJ)>.)7f&K_R?+*‹Zio{r#w?hv7$}6|#Xn8Q*dīÎbs*٠F@{Mܕ)ݞwJ 9x;:17oKlM ie4O;Q}o;욟Ez$E,f$w#J' T M6G@e;˦q ;Ȃ3^$o2NIWJ1Zj/Bh AqGYo)ws v7.XۘXq\2:լm&輈djcnL5;g Pf\F&줦{aY]TMu :n~L6.%W/!OaKѝ ]jh$s$B$b|R,& Jw_;W8 DCr˩gHD!D)[_aY6YƮ%͢53Rs[2?"\ oLMAHa0{g23ek'; tv wjb̒ڝ#F;6<T ,/8ջSN- [o?ܐ+Ez~ +ܺJL4sM13NNNyF_R 'P5 *L>q5k; w^go.dm" t@n5_gj0AJyEg?bMENy[u ָ@2"f竓&l淸PLg p+  &^q10iܝl"mn&x=@>&vx h%[>@픻:'@]FH cy~ɶ-wz&^n8.7Uiy&H؀ ָ:Йͷ8bL[ ȷTO;):WW5tc{3C~IGܫ0# 1*Neڙ̪_mf~3 <|G3@4E@<82U|@<{G_Ջfеf--]:p`Ղg!L5N Lsld9IZSZJR0(1EEc>_|.g!j@[Z-c˾k~7^k>@BZo""±قn^yl{aMtx5'fm5G۬@y`i۟DdSu *!'E7p&##^?ʁ+#_ԨqG੷wV9lmb! e$QҸN \44Xӆg&yjRMhPNvQ+3MWm;W(|jB?fv <$xrm[mr\un ?^Ucjr- [)%ns"CGVN6:Ċ$FxLbWң&6MHZN@Z2GC~a%FJE9 'sh^33-VW[CB\Ϳ h`ui%-7_8P%Kۛ4\F(VAxj ;>ЃOa,nAgWȾ-/vϼ#Xu04< MW&G'2V)I Yn57mcg6@gJH(^ll+l(ߌڊlO,GB}oJ+ SHi9u N^!.6~0gGr'#r(45,5ݽ RRp$eɧ%uB97H0\[[V+#/u-i6@oS@Pg !aNjf2G1b\ dZE@xHy԰طT UeK(UFn)6UDE RccMOƗ a®XfFg%}[_Y9cDMX*yuiQ[ {D_@rVeeʤiR,#N| "oFs&#è3 JDlh-`iNE@SSXSZW\T6g? N4g:T"r86,#*OGkv?[ay z DO= 탦θ@1)~*v:'QbdltA9Ƨ싢_{q VM9{[bUregP傫Q tm$&K!/v# 2Ҕ$Rqߒd~]KS;=Ȳǒ{yԻ vLBH{jj]/cWE苌`/q>ՉsdCz0 KJQO۷T #p ^Dr6Ϲ~\2ԉCD7Vxs<%/MfQڈcAJEٮr?ZwL;Uxvَ~RwG8PQ /MaV3Sa ~7f[W]UE Q6G vD[[DnJOe skWPS/+h|8I2Ϳux}Y_[^=S*#A3]] &s?#RIo-*V5XG'i'q& ZB,PW=EoI 4*?ddlÅ6:k~5Pv)6{Ҁqmw=zrfK; y_Oor=`P+?`{~C`A>3l"K6n2u-c@ 5rLOY.6U<' X&@ĬZ<1A(+ŌAEoJ~uWhSe$)cfT)Vԝ~cߖ_LwC.̡7Ƽ v.?FVXRq xXŽ9 %0uߟs%^1O$!(-ki1;,+/S m-}lMX@U)(M-/uQ)5O_YDz N`Ք:O=^,XcVYsXݐ.2bg&OjZ@2O<ùUvd(~إzjGE+s@O(y+7-cA>rkS* E ™YNas ~Ndh,Xǯ{sxQC tAN{Y^hٺ"iq}Mv0` <+ +NEl(|Ca3ep{դtqۆӉ=>'~2%azZ9)ݣ.yupHMwUs. o֏_ wtCy! H`6F  ͱp=)}GM'Ŝ;}DuCE:94\im>}$㓝HqbtmS8mwRawxYq6{: ̕'Cr/?1I3 9TVG-?rufi:uE_Ŷ35o^CSU)٨fSph1p%ʋӎĠ2wf⩣[Myp2Fm MFU63q QkTiXH 7;=$ ø!q1Pيth xwUiUnb-hnMɾ3C iFEO ,iAh\'Z̰d,KSdlw {r̬2*HU禙 dJsOVV- !>~#@cM2P6F>#ix'r a |(ǦKA=dvP1C6g&lj(ȰcԒ~.DsHھQka}[kĖ`_r򉜍e- a ܄&Vcȗڀ8yc<[\͌0k[S z"H&CM&_r~)5jě~"WQ1 }4;nAԲ>ICmy7"TH3ט.Y:umlu#/kbY&H|mn# fijltɀRo bozRz:LjGŕ=l!*N+1oBV,%E,Y)Kg1yPHx. u@#j@BmMt 7` 'T݇y/ld.mqPS @y*^6@fj6ph3 tX92K=i՛!Z ޜ<1#\-( `) E=It~89JjK.% SbL1ɀ4$-#%b_ANb _J\-7(O[ڶ9(鍄L SY1H7fAw)gvBݹ ii ^g5:NAH)6b#fhhsXT,:\)GT%"/SwEA`,(4Dcn# SQ+vMmSҎ9Z乗wZAð`X3 gI6XhwGQrq ʏ.xA"c(;.^whȉ#1 &_f!T\w`!2}Gߨwv !.Ie F b|PZe7(~19+#Z.,6ȓ/eT,TK+I;[[~D&X"ˆ=w%QENHkm.|5u_%HJ'Gbp묡$f4+`1A%=U+~L|֭ͷ '2#oІN%7Et(Y#mf`i~ϷRkz1}i!Ԩ0 5qb@3e`|OI18p)N΋*[ѾkXLb |{hXn|U?S1 q Vsq \>(3`OO,Ҭb^;KMP\%R2/\OX[؉Gx=6u{:mb5wv |S`E֯) ս~y&6cvȥμ͆5b>[dh$,Qu p AuvhYAΝbBkcC2dj);zFq8zMYtT"s nF"4}9C9G"#p6]2&H#@5&_pqN \&T\7BYŔ?5]*(}_n45P; CSM>가*b[3xʹ6uI(=[hU8 ?. Uk{V}6у"a~&k$FPZHa*~Nѿ_Җ~a2) eEKƩ+NYE.&.seRHԶL|ד6ֵ_-U[PF م roitEc<oB+jZJ 1Tl p>cM qQS•oҘR0I$Ӽd}ͤ:nULF؟IEq/xKe:{!g/]RW)4n1o` ՊmO6Nx1Tёࠞbu3v󪌼!c%<(w1)z&Ǯ4_ <0+mz3.tej2ѭ^H0 /d~CEܡ[x/),:E|<Rj21@rq)g\PgKھl.fUY_cR7hYgwUzh6DPZTF:C/:umR@RiOzCIu L4aH&^e fn@RW"a6r|Y޵O&< n1%:bc7 <7QO l\KC!п]U!dZ|BJN0+" 3-B j{!މ u_Ztq߸Ŏh.eJ g^yH<7B. /NuP&L`c#2TL2,4"ζőͿzF׊D`[SVQ֠mD7dT1;H& AO<\5F!*95l[Flii:cWij櫨I@ +h!-]wM:fK DJ m;}cC)׆|#=X쨓%@w#lp.6F?vrOM|+r# Az>sjޕ&"~4Ly9=xD7sdtڰSƒ v)rzE AV23C=@' M|7^arމOUd[ky_7dLWMfC-D"ٯ2Q.9(:2v?#|sf_;,4tpx+^hO_K'/Q|Ri.ǴiGR@gYj0È͖"X!8ם>+sc|n Ӽ~|ꐳmw^ADo"ٺ6I: tMWtX7"\3*ag ޡ2w&~\^Z/7?Jea-VUYmQ]uml{"uRePqNM8R7 ,lъV=Э\S?9mKB+p't 3`p_ |}DXBmd >$nN=IKOIƖ.AEPpDlLJ?֍র1^ZOi?APA;6v n)vV'z[&%9ZP|"Df%4Y bgN^P|UcYaS:|iyXrԱ]S/c]YmaB#@|ArkvFڐnϟVOD8.MB%4zLÇ޸=QR;StJxfV,$ k?~٨oqZ̺Gn8mJUyFu <&Vir4]euPC^{RN: [_ؖTBU c( V bo-"1$t6$Qsc0(5KJ}/;6̂ga'0(oR GVvD9j)J|߇8k tLG=ȩn"ĶElՖӉB`8٩%эPKϟ8نs2R#tP(ɋӶP9i-\{v tf=tœ Ά2רjt/)))**&A Lnۜ0mY(5E }%.AAS i.Wˆ C9i~a.`#~h0 Av<)gv?ORtd~Ի, Ug-MXQヅMqhɗGLp_,3|Q!c!ڐO7!:}$%28܁*ᅊ<2UX $[mZN)詌輲ִ5'}a1rJ GyțP2(ĺD8}@(ڋ01SLŕ $H_)xvP}Q$]o͹ݸL1^_`trh aL?Hdd~uNE.Nk>R fag 38Pp:«Lgs)'(ɻ %#^I4"rn!*tpvB%@PK6kmQBabppyHCvz@4Y$H">0ԺϹ0 ~ރMcGzrv& c|fcS!0*d)okuˡôOu$ M+i}hR#vRdď~a/=ECnI:3IK Mm@*m{XJogOnZ++?5oY젿LbDad= {+Tst؉KN {*|_|{G:acտϚx/0P_a7[`WΓK6l;ΛYfo5A @~\`h'[O*M`alQ =ݘbn/NHބ!s_$XTa5D|Vļ~x43DKg(us֜Ѧ 딂ƌ!MLp:rClnI|?][-WǤ$r6gXAc^۾=Dڡ>nuF7ȢlsՎ8Z IWA[$vvu1 ,,b6臮oB-"Z<3/lƂ>So ߓN+p&O'])>Y LijpSf`RPrT1ϱz[u9ɔB+wU;uVn%wN%` d:4 gv r+m ʧ:A%V_t ) 4upVn_MH:I-gW>paR&i;5= 9%uf ^WnEog7o'?(MHa"~kdz%`DQZRb,)e42*X;rZ7YhBk1O[5;5533&H~3J aVkCoC3.jN'_PB+ڨ P:] W:\ڹ/h:צށ)CVdrROt ۅq&&´#InB@/GTc!dTkX*"oqa6xOAD%$29 .zʭ`Ǝ{+>{9 g<5•O]-iq˙4|n:vhrRA:瞓-]9E}0Bi^ZwFn{i ۝}kZ:,CeJu4'S|-!u_h;;aiP{m$ c77 ֭~9KH X~˖o}&< d n>L.ޮ!5Hb,::6_Cc{ZֳK#yI3Txh%b_>Si Dx^)듈4]+fZ8)^. 7YqSm\6M1/1os$w{m/h sFD/4)8]S\ Iw/@Ōİk ]#ͥKS"e--lx18J%n'G̮b/M@VS8H*h]-`Lv.U.7]NQJ\U> mgZ- ) " ~ A:!sF$0y ,ψځ%?e*Re-cB,Qg>57qU:vy.x)vP(qRߴp~4TCI 1HpN"Gஷ5~gKm(1.5o? vqbv]C7zm,[iwu"|l}4~T@uϫ2Gz] YKXUD#9 QozSl0%^gQ.Op) Y4MWA;ON`Ύni*[F^IҽF0%dI$ng6BPQnհI%QBlcI?wZ8ENG6%`H+]7.:%ⴘj|^0BSF_9;TnRKTv jcDĻ:5^Eq"d }0:cqwz9z ], >?ߏn`kDfR)Q2mSzw"!L{yu (Aռcc/qh,0`w^N̊.E^z)cal>c/&C΅Zx>dn[&4QU?UEW+J +;PR`Q˭ާcRq5g P` ;S%4^?C;?.tVoﴘV[zH!Ҳvc(6jyA*)qDONyjG$.WcKvY-qȷ_Eg=]!rI8VZQ 9z΍aU(˃U]|[Pw!;l 9dDJ"=C<$ol1і0ghZTƼ˴՞bףO:l /u< 0r${Wõ"f (ʥ.rIR6.T~ ÓӾ0˪ ML]xp+*VIX?lSMJNdH0 I%{ɔ="{Q!q} fnAWohK-fwCO$md0ns>7?c+GUMU|`yk=gR`\?=$bNG7m$̂ hU8xš2\GA=Hr)ڙ:\^̏5%q9pcYS7S ~KMiU! n۽cJX D+YbUo!G vӘ RsTZʶ~6½PhaEFS#524h$aoKc*b&XLا3yi>xB2]r%+ ΥDEg% >ԃ3̡Yp.y;,̇- JXHP7 5\u޶//hr׎Ԭ &uNO3+\hd9 ^Dc J( c%^m 8 } AТVR=WYw鍿m9-d8*R_<+~/&Ľ8<)sfF\mᲫz Kxˌz\vKRkpFMMy 7:DYɑDᶡC$!%1G}MX~Uu. 3epx\W #L r_4BaF a!uOdAdbm{Mfwf{R_L"tk~D2;YȀr3lߨ!A1 |u5r&=|1Mʻ;01\fyU_(u6 dY83=@ (l@vsq({q`f)i# h4DX[N(P}ּ Drx:i/lȒCXR&}Q#WzFq>瓨EDLid9\2Sx ,94WX2zG %:&`d-2QͲ _jM0ovno2QF iل3e\I;7e.:+0}?s :2T!. x}=D)d{uX|="$PJn`c70GW\pB)LdǪmQoL MxڰpKM-.ʿ,!#)u/ʚM85bЄHZ8y3/lUKPvbEӘmgRzH+8}EDP f u{;9㜉<Fݖ#0:w.^_zH(Wܺ'V{ɮx>hC^!FCߎxAg^xV+A.5j3+pm;y SE;gN[ S^ ŷ6)g(s/&ƗIu$r0v:knXZ$k +}-ZG6ߘ>V WW`2?b\B|dBυ\fip `W܌>whK0s[Ze;aO1Ⱥ"V'25_^l$ȶGx.7!<%vv?V0&|ਞ tV "| ʅb~i#}P&K 7k>gZ` s' Dž)H9S0Yw o<ٶr4lLl[L4bE9% }^D(;~,ߍF; Iz)x0Dt64X"\cy 0^KSIRfD'R.Tlٻ5>EQjG BWONpˈt!+p%84}Nƻ֘R4^ѯk/Rݠ)/wOW#3*.#>Ǖ*)QKeCؚ50Gw䱡$vq ꑊt$&չW" ^\5qmhs%)FIfn%r]!iTv9$=wxť2q'$+g]1EBaNjp"DTOIa'K(Y  (#T)6vp}e{1FtTS;嶝@췿}6MB%ʤhm`J #YY$<0+yA̕&!?nC+3Ԣ{gQDԅ`+Frt̩qh :]ӿsP XBEI^%^VwYSp${TEǙM<v||"g4%5}aW'ֺFIobU` o3dmҀlK ;|e}7 MY,:G:0 θ'v{^&7wh^•xe#4s0v\ɀi7ծZPPv5@2TTŲo.ᯰW<=pV>[9M'ҩU[?f 97أ[ҌPjWB|۶w^Q NkFy{yFQ/D=1X;]%&ǐZxcE"1r0U,I͠Pa.m~k_Ot6x?,SuE{bx,0Ɠ%vgc}HlEu@ -Tk\J<=a(gdGG Zc,˜g =β(OH񤊮Eo-krӧ*t4m--PzO(|Be+p!Eרh4F\ m}ϑel_Z^?.[k9I^o.x;h >y69 Aq+ՉC:Dtc! \cQ*}`r!DRJpdhiM:].m@vCr(o3]J~ >VyHœ7Q1GoRl =W)1O6C.O7GٳY+1ή[.5xJe,ط+Mli1vY_cH ai,z&{; A+&6ƥBgmC\;S vyx=$%au1qJJu7ಐ=rY}d+++HV!Xa D5bE*"b,֙~0::j=CL)hu&3n{,-ՙU@B>FL8:{2Lhbz_ 7f[E$fJY9LBrR]߰6-Z]u| -Rş]*}}e8x Eʼئgo5=Ы!wnܨt|S&x;a϶N>5!wsyz}sǐ#~W篗T,[&/ K'A76ܼ!O>c4J)ozߋmW y$d^}њQIZa*@lz^#d:pzlj A UHnxqYF`k[<%C [COȟF BF; ⱉ]|\_1pӧ67M+VdjwMQ~lfE4ˮg[rզhip[̵< A+'Գ3c9Z"Ga6ԪU?#pW'[Y;W\ȱ(V /B\Y}J[j?ؾn;l mW}<&(BI S}ōK^h*`^FZb՘z= [e.{9DHܴ7YsX콟zJGH>H˥6?<;Bv) 2Ul6U5֪>Ltp,yc5;,+8St=e̬*=g|)hۿ4L2?nalы@7m+GL8\ shCfIFF*Ffshj]NN% *?D@SNˏwAa܏4i1:wiC>@f:XEGp*'Y $h=oj[z>$m1#kOҭY E2\v/i)4~<6$Wuh$sʐ,K[_'lnjU<~]  0BɤSuq/"tĸIs==Ȝ#aO3L,%74WOm'5˳Q-7L襙|yab[Ψf̼Ck-4mNi #9 Av7Gd!&j1oTVB;BM,T?V%zD ߥQ',x`i/ BKS;Ea-t8lX͠DO'~ ⮨ ~"mwv%;Ww1m&ߪadCh;7/x$6O^qMGHNYɷᘉǦ_{c)/˂9t{/D*,ZͳtvlJS}rszeL9ν!'O:{s u}?lw."ߌP_pXl 1N/*}Ƿ+>Su %ec E( nRH9})m10jeEw\Ѡ7~{wۥײT@lZd Y%.kE<p'b&vQDR &a;\;Po$}cQ&PA) by]W1 eafRvG XŲW<`1TtC Fc5)Fک}Q$ u䳗Տu.F,4v(f{>sЏ'*8zZ+/Zی{ !TZ%\~R /dnWmD$̈;vuP_a]"M)1X2ɫ$}{lm´򥘑7YXBr QuOA B "uP*).ӖoU!+PW JbR?DP7 r{1\gõ<w"<`Q;ڑeE+o>>7 n=fڈf&r)-+%.W^ej|m;F9NL <tzY^Lޣޕ?nA茪+וQUvtwr\u3<[}9f .8;nrGh2߯XW5RxʯRjHfzObNDA[Nd0[袨6_DZR\KV\uIF2ߞě6!hݤ/5HLKhyО<|۳27[?nvI刴 uÞeMNy"67IV(\{uF+EĒ80lp+d!j ce Rx+&güJ٤ .ԯ+ 2J!)6-#7Bΰ-Wqϩ}Cvua 6KR(ݕQQTTq !4qp}[a )"/ \@F/!wUgF?TUNVuIdӣ@O)?X2%cT;/ REwxi%W-9qqK`l&GK!,:~Owo`r _P=H~z%JTGM&C̩p`s[ިM-L.mxXx䩴z0\٤9w{7\"RU@-ac|Tl.FB@ ˂A^qGibH|C?|^lȢB$#v,.G~1E0h_̈pQdM (USȁl%A1^$`H -ѽ(p>ٽ֨>cI$]wUWva),O]w@@LMVL4pS11|Cox;ڏSOcDdǘZൕkX /ZNG6NHpA{:#`Y2C0N}%AN,q.D^Dv>5c@iqsIyQvOGcL_]] {FqJՈQ9QQ*[ Uio![w E^|0A+T,?BMU1Z*˔' 2LmcJot KI|F恺h[n],A0XeO! 7atsVn@Kn b (D͆zBYyvxuLS[D O./ `B;4=![l=,LV pr5ͱY\0)KvSݶ" 6o\R"&=q68b m+N04.v߷AB{)\k7,O "iV D.h/\c{ӓM96zA(*F pcNo׭DQ2O$֗xjԕa˦Z3rb> p)&EYJql-3 Q-/XucFEݭ)o65DR( X3An/'1Jާcq`jZЮmeG*bX4WNFdӄK `TtlwJzw20Hy_[>V.a3H+]*Ƒ}y e!e'85vXA-,l@Ztaòӵ).lgWH=n_\jj"R.q⹲= RUg6YO5S۶zJ!X1B̤VtН go!dkU.sVYF.} (=CY) h殲Y757kӫEh2bke 1|yO3Ofn;GQ:?7]!w$Eus4uA.\oY6(q!m[K 2Y"+.R] y1?>N݃=VZO-v7_Dij4|K)>RXU=d gS |T>+Q{h6 !mt1)1!d\uɝfqGhE`-p|5x[(5|&GJO*~Im& [ ݼŤᩨ jBz}QD'V<`,p3 #@IDž,y#3kMIh.8L@e%/3&%4V}mqSa/$Nd+>j]J~Y |’IP"v_JA֡Ie{R(ƬkX>S YJxkӷ)~ҭ-KALqk'[eKw[L2$]TBwj/ |7bwM+-OUV%빐n41[hd TΌG#$/W9sdqUɚ=YC߹d\HyX^o.b2Kf߬y=|K1W2惱 {nտƸ$ȜepY%4b7{e烂L 6k}AbcۺJvz-lPkk̖bT|ggZ*jnjfV( oD ao$Dl\bdǶ}: __#DГFLtY}+Y`Hv_ U"(LO`& ~Yҡ)tN\GPvM(\k#9`ۜǺ}_ H(}@eF^b&fŝk+ܒ1ΆZRj3T%̞@r!g}d>(,sKIިwv a_(%řRP@XkWtH&o23w#фK_Ri~O1A+&QR~ߔr1zT*-wQA5%+Q r"E#BnueZMf$`qȐƅ݈vG!a38XID7Jp"HMA(Qnml?ӗQL[\ <^DB˔ 5UQ+/~h @Hˉh "C]UlBpge 6mtg/'`v-xEUT:v}axR904ZPZȎ"MہT M5e7GAo|Z%b QF۹CHG 骖%R$Kg?_,Q:f,m<(GcGA'rzs[IT!anSzL~ ׇ DVztۀ4˞'2 1ֻ j]vKϭě>/O]\nrw>8JdjgbxCo&kB r C 1 7ߝF`꜎<6;|Rccdt(@8Q1ᑴ7)kRW1Xa+ 0=jXmmz9NJ07F-:F?)OEk^N_浧)嵥RZ.Y ~,[qI ԃaSӚJu%_"21,"5UޗtiG@!'esB%/>ǘcJo| 6E9~uxbݛIqEbu{q6Uōo`,z{:Ӑ5yYypEvolvK&d fR*4 9`.ļP5OM06ߑ=^.k!R9E*ܥ~Z'x7@{fy8}"[&O;I:;zuT/`Xq+ƊPu1%kOIe𼢿R B]B8*&;tu,;bYU?hg`)Fu#%7<۽իny&\/n{pQ(9>no5ϑ d[>[ü_%;OMsmʔ*xyU: 6D] "G~;,Ko0=B`ɂP@)\{)N%+A&@2 }RT)QZF/x4$YY!Ԥ k- ҟD!e[TX. $ծ]\"F0YsZ Tؤ;%{H*%l;]1q_䁨t֘Ya{bРp1I5hC <-Ȧ{~~"/ tLY*ڼ[jYƂޑD~w F򠤻.cI{ٚ8-.Q[U]vTp~YcWLb!1e! Υ@b^~35~]~_n卉:˱|w} ,2=bHiŴC& ;64a_~fllnjw ~㣣'C 4/R4Z@*ב%ݶUS] ׂ7W_#bH SgDZ#=ݬ00!J4kY|˘ K ʹSĹNwfT\B(0tzGt,Gy"+u%|͠9LԖRRqgў]$-YC> T.ͅʍZDd".қXӥTa1 D݈&Kđ03U-,+߆|.RP|aU?>h,]%y)Ă%/lxO !Y+i/pC1S_g g< bѵ =iH@@#Ȥ h9ڐ Ͳ sKq*pv?cSO# g 3H>2dx6G) ֵ)At$' 4cct]M4ԤBUWGtkRrJ-h%=q-b$<ϓt?DHf)rYXyܮ:Hqw#%FBt;ހ|7ERkh3Dq9geBup.7PIo&} #D.cp<xIK*,R~c8EIƍ6D*]jټZ$!%ɭ;J,A"Q+[NɰiUV3\Ya>gQ"\X_N P6L~z>9!(<%I=|zbN4Ku ? ӄr_Ռ(2- cPJXߓJ# R#U!JڑWmaYJˡ s6bUr!mN>"/&m$+ނ] NLjS zDѹ`aUG4npB9HK~z7O6O)@;g2ʤ:s;u64KV]ތCEԧiZpm".A_{m;ϒX2" 3.C5}o` _t!^X8sZ{}dRfo%eQhprYE =f*hdT[Qw\@+L ! \> ˁS8hcaG)>Rgh`#$Vb7B@dHOpMQ_@+,N;'R͑JASeR }"^Eo{Gl8HxfVS=pvUzGU@b5{cF4Y  .P!~vEGk2q0j#MN6zJ=K`9W'l:jWca(b`W7 %'x9R/j7̲;ٯ^S^&K0\5)7]3ƀ@X+X^LB{]̳b/@{y⍧~lH*FEz+wF Ki䇲Z .RFi5{F~4wx _\/E'N{Z$Qպ4hOumq*q*@^ģ"wf$QN;z+9퀛Dl<}-gUnM_ygL?).~f6XmoT)λp2 ܷ(20(9JhZa~= Gng#۪ȧҍp뉃 V[ΓRCgbE^fZk)`ae0qΖ(c[ɚCrzO0gIA C5-9LIA{f D2Ň}A0hyQ[ "SC~J=*)d"~G˯ fi<"z *Is#?Uޠ|`@GGn=ȢgA֡^ywwo4s/=$Iݕ}jÅKފWkT78xKbq w~DHvtƬYF;f%UqMyZy:(8,sH(d>y21ڻ\00Z:'H=GkSXփ2ݎ bKayڼxs^>@c6'NAsX EW Sv ]>!-4XHUþK쿳?7LțEMRHeR Of'KԍE=?SXeqq )N׽/nUsDWY +~N3Z9KnDxc$J|N QL1B!Vkbva,ϗ2>WyaS:U=XMT+ZActfZǚ1H܎֭ٳr]5j6QT .yqKo̙˹%?*&W],T~@R#غK'(,䩪GJ㩣Mj&@LJs5dEՁYif!Q2 d| gLNe``wblX.5<Ѽy7uoqP<~`UbAVA&#f\`yY}=sly>R"%> Fwz'KԢ[Ȧ+]![O_s騠#HzZ} -nL D bfq++ł9{9DQX D6y<;Fm^Jt~WS\{'ׯ_5m ` sZz#{ö#kĤG*dX0Em783()9!N+2}A޾r]7V\ 6X5*ǖa3k`]6.5v1'o /{L{M)8aͧ_}jh&{ s#5МDC9xfXadsFd4vȾƙgDfЂ$j6z[f0(3ˋe*NK}DmT~C^4U&BX|}V98Nn< rޏ}iF/ %cf:ɐ/bi$$G-cʅ/R[5q gb(~*a(T2˥Џ}_(N6煒b}P/fSͳ~6ӛѯDv $1wHAgOYBO`Ni<#c`$3eDYzk .=ȴv{lIRr?J}Jy] }[q=t ݖ<N;v,=" qݦO[4ϳ91{B|x9N?cli(68h 710g7Bb{$џ xilH7Q#Io#zQw"s_e穅\1^e"H"ίGoy8P) Ł2kSa~t x) ]Q9pgehDsQ2=eQ,Ě k+K?6 pgw}R:ges(@;nbĶ~/Ř :{dK-*h9lMN'3 k[z!}-uRi"nۋJcdQƹX`$3TwI41yCl4)% o0n3 UGHv|W)%5 ^gZCZBT;V G<ԈV U]s؉#tWԳFcԶaHn/BV 0gy∟`TD*; cUik-1;zz"lo Y6ӕ9u[FPp_%(sZFHʒl6Ē0NcF^n%#5HTgܦm{~ >Ȋ}%HQ+eE{ *ɺi0S!##&u/y|(QM6 [ kOv `c1Fnq1V@NmA*"r LkfYњrTER6 tBS6 oT.2NyqN9Bj {y&M\<,Kd?bS0}MO36ǽ, ń(IVjO{=T$ƥ@m4aSsGN8R{BVE6_֌w[oo7X^AFD? ~R" YB*@51 eMbSɷؚן3 \ċgP*J&5-2jzbp]x=chK*WEUt,7Z5 [*Hno#tsCyb.wC.GEDG!ըfzYaRM%} ŃP͍MB8R)6 hUd ^m=8Sǻ}dmu #oaCw\պ@\ ^$~m_eO:#M3n)m-/{|-wuj #0tZp iD~\9 6L[ސZe@%t2ǝ/N%. 3a ~̀gå?O-'lQCo~œ K}޹ `+Ȋ-KdA * B9lCz~Qi=;;U"}$7@=T"^0A*wa΄O$b+ $S/ce~n#^Kܔf};<\LBu<\zo#?iSSIVp m8&+~O9tĸwW0qFhlbY4">~aZLtWhfb3BlxTKM$\6^jȫk(ƶSZ8@`1#DuRZ&Z5~+J|/zWt$6@oe?%3X||LȀ028xHU.fh_%-NSC[R1 ΫlQF! -pZWbxT!~1J2 =ԺN1˲Vvj1e4 s| &6J]ٗ7톋{- eX'P! fm'B^kPx+ ߎ0&QQR]ĽWR<27a'-] FC5Pw97.'uKR[ Z<^~iC2YrcPSn),%xA:CbKo$ 2`U~Bi,IԘ%EX"0_f6Zt a0fu6~#CaPlݜSKp;5lM5D\\lqaZڅ4Hܴ Dk\0JsTZrPTRg:ySBNƲ,$OLXjGޗdʖ!8L{'HDK9\K=\ aXg)s$uo[ưs(,,d&?Q\W(Fo=&;S~tMW+7ۘycdu-_f=xv+;pFENjdJL䎇\b²;b*;H_gcGS?dkAi4M 1zZcȎn5˒ltJH_j2oVӱLZ#XH 7qX$s:{6B|a<8_1f:Hah/}ͅ\#ڻuD{lzr Y0w!ڸҡ|E_hsɣVܝDz)C  /A!tMvS}+ $r4ȶĄa6~M 9\p(ZbX|DPn8 0YT (&ljK~,1ⲵ;&zInJдc~ǮH5/;F_ ^$85EFFR 9)ݐL|^6/ ndV̲ß-l~3*널hPRd;Ɣ 'p{NޒuFKUOjϹS={g(ױQxL܍JOĕi/>h%NcXP`_=GFg6qo6ynHR rpZ8 T`u:3/~AH^3]\-$"O0wJQAy(.Xv[6 q& N\t,(oG! TT%SI\R6* `gdp ՛9" 1ų}q=!dX`{ Ή.&I8M s܄ B}23G~)몹cU:)jHze.X,D\O! B1$L}Ch)-pU14x8bIy]6Q^rBN^ձɒ{EFYlP;LhʛأAqf:ZD_ɡubDbyH|ߐq\[8eӫ6DBd:7ئEt_5P[jisf.]hui4+oWO=f@RVitK7t"̐_4+!~(*ϗ>jЦRdX]"BN8J=^_SP$.s~}EkF c/U r<$%UVvKQߤ[ۙ!1 jP%#8M8̄v?ӳhsi^5tg rQ<ËN~a(rùyY8Cnjho_Z59;{"VO2MUc=s~x'~2"̀K桦r7u3B2 iɯ,B}}S &حyF'3m7 (cVfUH?فYdAk67}'ae0xB). P'QO#o%]x h7Jf]eWK զ]9WL?PǛZlyF}<{!RY-BsP8GxNJT7QٟE 7PҾKsJN-zV$%k_Ih^Xr3V>RQ7 U(:դXzB6y$xۧ19دSzb󾪾. ṥ CRz-c;Ƽ]W5'oo z3c- $N[k'7BVWYA'@h걤߲RRy.@`:"+JtUE[&"\vئ:,gO0FBJh+[h] ^~3_s4Mn֧Y()._YPs3 U_ hv}WgmSlqōr5 8@kEXoj^ҟuh%m!ݠpMk k|PE f}! Z;0Z%5ݲ gگ#ZL2,"&YK*EnǒKe yCmhr9rmL?S +E?@85}yRnd &2EN@YVfBr7/~ʥb"ߴkod39H=4xnl@mU{ѥe^d_;&p sޒ&eWݘtt s6G¯ (tB/q@ S|MO]S]|qNfΖMLT6e:ZHr1}Lsq LE\%i@ o d;ێ|/d|Tˍ]3ga~'DjEb"EF(?C9Pm )ZenxfsvGAS2??o!% i9.J q<HZYPu-"v8C2ft'3xZ\jm6p/_ZJ I¾1fw^<{Fi[dzֵ&+N$a 3/iG%MbBZcЗyJE`M aǪ"8_Mej"yb<♿ZDĭc_ Ns k~y=+V2A@`FbKdjXqR]kkvث &ےJ3nBٻHѶDq'W6GܽTTJ*ilAUTa+ ;\9[ XO Jwn.O89%m@CA)xxvuv6#m['\(iZz48@`C[ߧw`Z hӝ\\&Ac jx`ۨdezx$<|؍:]'&=G;N0lHԒ_P}SRg)hXL-}`JůKVWZC-orm8 t߯*O5&XNJ.uf˙7)Qz<[UP}w|Ʀ>>}ʦʐ; J :'jzJ)U{AĀQt7)/?zРIJ_j y*/K̜5޺޻h d̀g*^`5GrA'"ݮYm5ٝc "rSHB^1)]бfE#z+Z,wu8NdfCd(:n_?-?Ez?nF`G($ PdޮCgaҵf僫)B)8rc&ۺb)mW&z@.,jOX† PR42<vj>4RҹŎm-Zy6_C1x-=v9~q Y al}}Cz T>3ʜK}6"wu^m\^ﲜ3}] walDAb7EGZ.3lN@`HB7] ##]I.N6HXXh] l:WAjAQ dG'u+hz.pɫr1x#tN硕$-Ïi?u-B¨U-idtcic9vH%S0F0Sh5N0J?]r|Ρ-)*O_;0!BŔWq2}s/"KH, Y>*Q+gerȯp e`D1qcQW >OwCv GT7C6qz+_-݃"p4 i;gS/CKfvzqa!4n"3SFb)\zW7\nW.cpE M[aV.&^D$!o47Uf>]7).֜m%s8Dc®S3"!n)T.xJQl΀:-Dd.|wCxRjcjH^o6uw>fbu`'$-V ߯R/gF#'זũkrv]~>t>Sآ k,@7#1KQAGk#J]&ڰD=Whр]rɏZ C1drVL-Al@|rc/8kͱc/1|hwiAD@ Ğ!cƮ?,)!UT*JZgHg:,@7ߚ8.5,ģw6w3 H1]DcMjmvbr74;œt(~8B4Yő4)KW^^gv#K!])*1Zf ょ-0?7J2np-i3wJl@D,2rkץ%d TgWP+E9D nв 9DCt~w[?0[6D!|ʳ$Qˏex3Pq0;/-[B BV@\aB@/Mv#;pa:`l>Ȫ0mcìhU.vr\aU̎ԣB+("ΛJ`)$8xycq9MY9Z *4H}f$0 ܊NΣ:]Ǩs8Џr_PxT>} ~D nb]m%5؃&ގ>k Ϩ<R{VQS$[I Վj;RHg578#&)/ г"c{+7Y$ ٞ` #~ pe65KW{W*QRPӿ`."S`f9'R K*T=k1ۊC uBOs>2*MYzQimVb_DP6 o^1'YZ`ֱTumMm&#wnJ_beޣ=}}cny8q@uqlmcUXH-C׾ zo]b,=Kzy\I K}鈰Hߚ{/jRbFTPS~ ?/ rӏw4+YŸ͛3 (yFhNĠ&3 Z\=]sg8p,R]R, 8ꊡEgjHSΣ;3Ov/$s̀d}ťC#v9D_k 癫8Y׼tЃ :sv;xԻ]2oߚI2Af-DͫK^~Gw gl4 d~QS3(^t2QҵKKȟE'aLLM"\rD1df^<<< 1}5=.l?_C3˦3odyУ-fgVIBv kT*E.tC_јƦ`q/$$/Ѷlr7DM=V$AE vVڛa`"ICjĄ}pVdH={p忭GTaq2;"cusƭ~0ڸ>4& TQBa8UwHa#R_+K$آ[F.jy2Xҥ^ |M*z/?%%ЌWuZVm+aJM.1u೴/K&φ3!mUTd6qN)13?k&om3LI~ wϛN_B\\Wُڞ$KK$] 2GR itH" ?C~:wX/ Gqxܬ>lDByC O 8hg8VR0"BE&iJ®ܼBCtDiQM b༵k:DxIorA*jpOS,RGBq0N޵9 ~"ozH!\7:Q0kgSfJSj;9ϋ]-q=ĵF])| ނF\BSϊlDY<yn{oa ܕ.- y#EH"YA1ND゚-=n`S5 \|\ tM;aS#SܲG~Bj\XoRj%s纫NQ w9*0?kS9j0w^dW:}CLTu "Lߙ3^Eӌy$)TC1㽊U?ϗAmi Hm=A(9Y,-|xHS^q']>a[iuw26`1vp6&'=˾ԋxf)]}dfPrk6vP`Ag;R\%2xg_ HPo͝ѿ1j {1>1Y{gGv*ga.ӭyH1ڇIhZC"b #?LYi f]2LƮzuWueInsc8LrpٜA磂_6qn=E@37&BzcI!AEFY pa憭e8#蔿S0D4n6i5þ!;̻4RI{o$cpLNQIƜq,I_/`\yڲt"1t u5S.o̝Rǧӈ0{D`瞲H[ڙ˦'[M[8Emt E-ƾ=``{ys'>m%tXYT&8}yb BmiTWdQa.Kޝ5hF#1#AkuRIZXO  ƼGtE,xz4F~VItңglCZaH3DrAPB!}EiyR)cU8E/2#غMOx;&q~LuwC88!z~h[9Z\2-ᮽ 9Dοva(eΙtYed-cX*(})X|s (KK[Ni?ɬǜЯ$JUȭqwbC9o k}mCKI)j:Jtn9(;yeuȖvAοƱnHvt_ϭ_mh>zs)In~(hǓf[. 37ex(Eh%.[tx|sͶe2md|c<ҜUr &s4320C;|.nbw\Bv>bqFf?1tCeFsPF oV.0b`geMD ޵x0R`9[F3."@ӏvZlbS ]U^|,,M 3.6P.W@! 4kDOwئ#N T͊ PU+1ݩ$7vzGV6i/]wftHUlҟO\iFgIې[-+ @MXcӅy`W 9g~mQwwֳ5z+ïG.VI/7[3q'ʎ9>F&}€AMiK 3 Qɶ. 7a?^q>F *OξBO\nu[gmPD>y~ 0jqG5h߮j}cfMcSUd1Xz+ByꪫW- ZTInuffoӱʱ1!4 RIRpuX-~j$1*:>'O-E.6JW =FL[z~E.WcFVћ% )"j4^͡T>N.6pXiIy`'ctY5)x 0E:tH^lsK:X'c^=Ѭ9r)y3NwVåi@iF/٨ Q=RfWqt lmo/5}Hr3:쎍VN* ޛ"sJլJN$I? f,ˌk&'9h8&ui^r0.ư4 zDOzC)2buL" ; (&'.x7R Ŏ e7QSUKK lQzŰ^ayfPDeپ#&Xt(M!'9/FJ Uiґ<ݮ zeD~DMcTR!rcP?MP<Qˇ!ͺ8m=58yLP#P 1: Dp7 X?Do nm"u@̪S]q۬mB6MNX^ulaV>xM&K]K NC/^.ToX@Zq s~+L'o] Ms!{Fԣ'yh͝Si6%X<]hLb`Y. vR_&vtGra-% Ġ[";:KX1%L#Ah7ٌõW _,ްmk`ͦ ؅n Q%1\Mc^4/Yj$=!NkEEfEǜwck*MTiG6*>qCEehfd=i}$=#ۮz{2_^UMl%%g{?{k1algq4x}DGz5G*Q0;٢p;ςĈd9L(įyMJ5a@p`K%|̺1 j|ō}1_% ⴞnBE; ZiXe[*},_g {Eb$9g{>Io,#d>CF(V˨d6pNJ1aT5XxClq)zxz݊y;,bSZ:c{!t[Nc3_F&7T?i7/諃'M3! EYŚZW肬zu!՗ ڭ;[S>=&h S cdJn4"ez",I#֩ m'ɬ碄sgUwqzZ.<ό&Q4Y{*]?VbFkb4Y"Q @:Jt][*BK.Pb6L<<6<$2ȹJl]xJ)̡h1)$ + m2Bqj(2 038/Ŕt^_anj؞ӯ1neg1v;vLYG3?e8q/*Cr"Y0e~c mMSH0X_u+(&_CԸf#"a?~Ll}Вv\,U-ςE~ +;ų ]0yD`+X5VL3akpx\=dgKuh>nb'7²|F(I_"3s .>#tEx;QI$V(Yh[8%hXy3r8rz 2sFo˜(3\ݦU+pvIߡQ&ַnZX~DE;[g& @{XyZɮ5mɎ|(@L7M*8gCDЂfRV'm48L~M&]VCiݲC~3i廯ozF0<0}6 .9<.dvwUy31跨-ѿ]VowHFĪ 1X`^ ;u%Z#7WHBw)fyyK# Kxɋi~nKٵx7S)kdn!J]CCu{lu:HS_y ʢ, 06KOCS93"iOIc5@ >닾#\=#LErt@J t%7q[hzJXJaj9Sc~tZS8#̠S`:@cMVgƣ4%@ܗ;ǑܾuFHZ7=V%2iԒE|NM C5SΣѿI%Z鏫E{D}Q7U>\ ~(Qz GSEG+V::t79f+;^w1q8 W3'3!/߶#x[0Ԓ]WAuΖ$`uպqaMe=aC~\TP!@ IUr. z_Gj;  %-YZ(r7H4 [BiM{B㕫խl4| ½7UI|(SVi ! O5rNAi6RK{/*JCD1Q͂$rx!=!om'MdW1eal>GDGf_e9`sRy{pgq`R!oEnԌ<& ǒJ긢0 {ⳖU?pygåiHi N@ N"(vNoxol KX5zQ߷MɛO6<H}dNׯN}e([:3{de CUX#4ϑJIL 3HMBۅX%87"8g!&<J ;&"3y(O))+WUx]O  N_s1,L:W0J*!@!3;vr 1AX ,h<($9iޅ'jp`hWQM֜zȆ2.7c2ۘ X8e~Eru4˷ öڒtvS.?A ck^; @rk":knp=GZ8(H#Bu4qǽZ6#2Ny;>\}ɸlJ&De\QX廛r&kq¸%cs* ?&vU]'GI+EvFZ|S(2{TV/\Ս6']RC)ȫSvm[Zj %`r.|axk^H#.#sv Kh~g\mJ.oY_oD*m×iJ&4\cpV/[g;ߙ'/hXzƮІUAL7ߪCߵN/J;*en|dnhSK%s<ٺ:^Rb 4pff.*XWRᲗ~&]|_UQpd ^#kwt/cUϲ+b0,ÐBHc /xMA|[s,x1{` Dڧ"c%>Ѥ"efSb{ w^Fِj8Ղye8Z~]$xcyZ|b"#PŪT=GiL?xx^_ʼiItk1X֎*bbP`vP|$@'T}/  BW;GtCv-ɾl _=5Q:|tR$C+\T;2+H2hъ§' 堷x3ae d `FOE#!7T&KhLXY]X&>'sɷ{0KJ\=5=K79N<'kcg.d7u'C%:Σ-|R+sFj-cٽ]av<sQ0BOCfתIqyT"hU'i>)?/]so*nަ[+6'UIByꝧ],:+y(+aoU¾'?1J`ႮG#-%Lޜگ%dØ{][%%2fljspQn ܕxW=ݻPd Qnfv^o/T 2gLW3a5oa0-~y5B<bR޾~mf1u">U|\Ofp[J܀r[Ԙbp*nM]}۲< OAڞ{ GJ^<`ĥӛ^W\[QzgUQ.$rB(L/fe W6f+{"}ӿ,j wY6r% 4I?زp{nzıAE 2IB٫ژjJO#47fDGk2h9H5عPhr >2j`4QZn7Nޣb+dN,'W z;d{5SLBU 9)mhy@nڍHNZ1iࣣ^EJ%Q!E]x9NƝ=QʎƱoo72&lO; o$qm]$Q|آIX_:VBYtl1'=U4K̒Ջо{YꬁCѐkws!Hbڂ\/j|twǸm/v0lGҎ| #Rx8b?Rzl)kz%hUK<+FIH?EmAIdΟl){sUM(1d w:5yh Ӹ֎vwuq ~O?y-dUʠ@hxZ/bgG^C!zW Wx?>畠:}kݸUb] QL=1-~^ցA|7nfpV qV?ѢQm-u졮noZTM)5uuYIU'^`6UVtM:tCpkNYT%Jӑ iW^ڇ`c+ &}bգoE+vq3E.Ÿ{mx z|p6JbB# @7q3̯# ϝw>yDqM`s?v+]%-kh3qMi`W1Q/3jRjX#)E ĝ~ȁiBɒ #ӕ)1cq $-žBw,ъ:gql/{wqˌu+U9eJ})u!;).[Ř~ 8nH9WX-dުH``gjivH/E':m0Sw[}5vFD,dB&V|Hǜ(ѫD>Jن94بnHfQ a+KCBվX+%BUrU$Ok3Pٶ9Ն%]2p'oh~]˻nQ`τX*Y܋^BG2cU *M۽c*лd>릻|afƗ1"MHDL !kFQIpհMj')ÃQ~6TJK-z,vӪ/XblIf,{M-4MyJ-u*7CfG;I<t\su}VKVqhbK4.cGzri`">I\bٚp#ɩth7abK>0΅hz&bg:4u30XΪt ӫrt 0V z<i'O\pFE0 iLv.M_^@axxkTWTX!K7[*xzhv!@>8J%*2CyvsU[ʏA4{n2w^U[78UJ-0HeĄe‰Ndoިe \7yack1oo^8#58鬷Kԏwlx=$L~SWխݓ΁qZ%8ӯnZ2f3^ѬpJz(h|dx!l^#++&?HD-cm `$cY¹%pI[0[-aȧe OU$ʒEۊ x-¥îCxx5uf""St :SkH.od1 E"Iuu_9 ᢅVnU+ЃQאE8:mM,3V1!g[SHXfE @KFEݺNva1,$A\uٙqwzƩ=DjЅ$Z2"Æ`\'_[ %[r}Ɓtc r*wE ,si )PiĔY]FG2wpýj2qrd5o䅗cCm\.B*6i7 94uœI_UDSO7́&<++'FF23ĕ#[Mj+g!ߐ;}JpTInZFVM%' ?u۾ߌcK1;tv_iܝy} RRu2R}ӥ T hFN:rz\@}Id z_9v3.i= GgYzi\_VĊh_ru5xʰy\ zu!§K,rq‘]^Gh!Iݔkc`cwR-7ܵhgȍ˹/Cvl4飯Lo8eocGsTGb[fi=rt5l8tN3M#315Wg,ϓvKrF23_]Q\Y{KEgk(Ī۰L] VlOBynǜcWvLs7>QgY|J S*sk0}}h{MA;|w*],\p.-z&-XT/mܳՆL ࢓FEz8aF־'q kke8Uܒc;>Z[d in 3\;@|֝i|UǍҼckbąDº7sP%F$'XGsjR57kmPwGS*v 0AW**>KhbݸR?ɂ]Jy5i Ҹ̥!]GB Bzz*m$i ̌ISN6tqcrv։{5\ֽxZy¾a6Nz{NޮA{1W ZZ H'Qsg4);k}Ϡ;_yBV),0ERvmYl;Zsݢ`pY)MXe"4vߛAX&A#5VzBJ!9{ !BYПi3nǨ' PBWwLkRnEJ%J(!ЃwuvzErK]k#)S(;WP*EIh0o>z#6Ϊ/* lmQ1ir #f~<@^!UjAGu߷C, ԉ׭+ &ɡqAJO)ȕg `[`)fi!Ȣdmm[/ރ}e[l';C >e\qM *8%as!Cr>М2Uy&= 쇙e|/p &.ЅLQ"_!/kwf"LDW3y%jvZ6)ں;R݅fxȬ nx|mwG4V@VF7YadZ&3 Fs$7uےM4x(%}$z`.pi)SBUٳlq >jgG d\( Hw7-&o;gϦ67N/N\׵;wYLN ?8nm Iv6ޗ>=}&1Guӳ-."ٔVu - ѩlw1X=zAg/t%ٯIh eJS,4bY4N(ݧ֝;3gVځ\"֙>#XW3)@:2 @H߱S;@aL.M*|xYqs.X ZPC TƝߦaEr 0k\C{Iy(s%\p^vɨۉRJsUD6Y3 _ia!:w1J 0Ny@m ]~'Ƶ弮5v=, *93o% n$g1/lEDjM"&ǨSZ,$CPtrR[e;,Pb ȳL,Gb o5{ )6 7a!I q`H=G",kfq?NI^6͌N.^1No`mJ A}оm=8,ݔ&CЂ=!W +1vo;X =<G`/wJ?_ /3-( { O:{dyvLUiARAMկ@>ჱ]hw/7S8Ae#- pR LgFy!]nh>l"=ng$ W-IIK.t_pOBS9)S" !|[j|~Co2¶a߹G4 e-Ǣ%>!*euiEmxQ$-ɳyF{@8Gj=^CG9< Qi̦sah,d MFkwAcc*עpLcC4o|i'vR}v:UVb+h&˛* *|WK.avH]+#F~Ӄ؟>8vr ^?-FBX& ҡe+/]_俷SR&-]PBbXʍ=;:qLkr<"Oќ0D0^%( >9zJl֞Ni _asv΢Bl9['$lD`U,K{眖Y/L@T曵)Bۈiз{_DTc! uJf@$+Dn('Y#lbOEQNM%o95͹<6bɬ6jnDH!ԲқXz?)D5i;=ĎJ*ۻ$ Fʑi>kD9${xnh"|lNݏbcR2y>a,O$mHuWߝ]hB {/WROY03K@$!p)jDlhì&EN컗$|uuj$L3i飔[LTZ w]DBi{gZHA沙nVʀu\*i̧H+΀%"oUqwdӘ0v?uĿ]uj*Yi {ux|N1$B򀒬[+5"RBhe{^SK菊Rpsl )z^~{޲S[?J\lЯMW.&6UonJTj(,R[G3dn!2t1ڕD ps-z u-1,O0&yy1zc5m/]R@go/wh_VbQy7k;ހLrQh95k(`Yb6j-Sx1exISa/#DלD326_es~h(/z 1sATR+ma`I^:Uf˜Fzv)$EVg`b !ķc 5uC OS~v اÀ5K ϖ9Ux"Ӑ٠*9\+)OyHRluIRS_oZ?Ϲ)8)uoܙEBQov^^[{up9*UkDw>V"LdJޫh9҇#am }!&SP/<IЮ2i}6^G'PKPDO+r}AG:c0vQm?nD U:DȜ=]DytAT[=E;/~7/,Xvv/P5%zˑ9 s*<0DDCx}(/v68MKS8‡|]ܢ֧\fDM+ysq=^X %2 Xw+>޽F7$ygܔ3A*oBd YCP߄$Gl ^*:4uP>} W }Ala<͜^S_Lc Ns]a:;f̂`5ULTLu}dMVp5{s1 2792R橱_İcN:T@y S9@~-IES`TdkA,T+Tyll0 @DWc4|sxlY6h_U.?DȪsZРi l邜xbw/c[8Ȟ&}o΃D48jqу{?HKN -U։ma#x &V^η*Oajw CQdy[۫#vQGMFȟnIKYE 5PG2`zz/b -e?wKp.{ ZTy3*V}}=oP)8ma6hvIeP`87d[R+ՙ1T>u?_s.\տ|0 Ș]ZŒ8opKɕ96zqri8ÉtVeS?nL !!Z.3Kte ئ(qjߐV{'257?_YS4Ա?mP͠JwVkWPO1ZkIߧ=箕/"٬ի *`aNv)[Ñ|ͽ_Y}*){x 4>I^[%d|h~/.(oMQNDAN~ϰ{XL9s2*;n_yJ 2N < HICSBSܼ%bnetP#KOOw!7`82"#+y} p/R; t5J6fx>g19V{Eߋ5;cu0Q^RI/du!WSY~U%Oj ԞJaňc֋#'hKo%|Cu#w WpBl[CbnS-wGD@j@:#{K;Gd,u)}3V('^ٸzaV)3]VzP(p3u- N4^RfYn%6emnfr oB*¤N͖'Lk՚@skr2 g4| v4:h,Nk8G`kQ LyE^B놿Cpe -LzgjwK?o& F Ry#: 랇B"-IBF"h86f-R=NTq%?y=f3pJr\g;߲F/N:pT^"U$חG-"6o̯p;y؃wfԪuZR6pMe[Tt]2fn#p[Җ(eJժ:2}qW+'iV3Y<䁧DGbw a2 AG}nA[OjѸ3Sw MR/_[#61ģ7Ʃ$q.dyaoeh<7O\Nūq?׫-k#kt6znVhI6{h-ew+T3y-@:6p!3zd().aPQ54qhJ*x2y9f`ܑ; s?NT/X %8cF]4.ND#se3`QӾf9uG.42W0H|ր,rM?p`{@G^2JQœحKͶc]e%ܕ`:T3izDYm/B cL1z.t&2٢-b6Jnu: MfXBhiOq`a%^;}-p%'C:0#_HlJ剶KZ:a=A2yhXgO11 Z: qP jɗpeO{ՃfDA6ubQ*[SLY/3ciI&ChEU0y 1: *@FYY[Mkl&@.:qX y>׷%hZ;q61=r];DjR-5Fg "cÚ>=JP9؝O kzHY ey4MճMnRݣV |(~h>Ŕ+T.dez)umj؍k3/  \twWjc̸H`qwBK ;mW,V I,Rԏ;@HR}>T-BY<㝟CjviH3WR/Ą<0>9ENV\+VHӠ-MD1u$q7]e]8x&)KBXͷQCL<~y4̧"gV)@D;5l8j%@}A8 Q "1U Xc$_[H)Ԅ30`Q" jD$}ǹ;M8QoqNn).bK&6/,3wŇC禪?wc#$)6X ̇&SwʍGL[=m #(0̟;Pyqu}ph[< tJl|컯L8-1% Eu䏑Vt"<)0V:)og2KFhe(b,''(phIInP)ܡ>Ko,k *Z/|*Jnp @$*.u6+ ճgH{7xhUt2 f#H)AУ(L\krҚFdVtE8Y(?{l8">%oNd4:nxd56Jl4ٯCdĭfYPFb[|qytEv1WTOpK-@rE"rm E:,"q|M}<]0$?bp47r)8R B#.ΰ12uDnl8D5Po53>bMA X Hn4n/,sf07yOcP}cez<ܰ"ǹ5MXd&zV'H1:"ggt:*ySnOρ9ψi[,:5t XN10J&)|_p͂<]ɾ Eu vȨ>>Rd;Nd)3uBJc`CM*gmcsV.{03νp7 '5 ɩ8a"týSċU҇cԲ&=#~:*/23\];p*/vDd Ta'es*KVY85y)M폅e|4͑Q0^'Gq q\)<;-n4AFF~#N)cwكoJsdWbpl9GQYÃ6PhQߚfK;]@rPK)'}θ| J:D;XƲ2tEryUK# lqSyIJje\!To%~߰D5+O聂Rp0mTbvn DyKϋ5kH ~4 ĵVb*c_ʧNκsa`1-lUP /皆߉-{e!P4wbt*GE:EUHݘ- )ZcFh+og:ppGm卿jsr.5j` a隻+&f=r0(bDn5 {KRX-C}?]ֲOE9+l.2ؒu+S|f ߛ\=cS5j εp̧p:juvPZ6kA|@> ^ԏe}z]ؽi`7l}{`Dd3 x]>)]T!|ssbhFſ kbژJO6^SlYatTpZP }aE]dA_@^]H;vȪNT7f]s徸82yjYClj"m?\fȋPi0׏Pe${N=: e7& |Ow=΅>5LB$$"] =I#.Ofx+tj3nv$l A{7 M9,U@E/-Y=wdP -dnf"W :;5fGmb [p*ԇ1׭NNiKbLCOKv>Mj3%"An4r]2??UTp~=v (a!Q|nQ ҠdӇLЀ" [=[o/ҘN}= eK^GSjUHBt1sy,޷_7WY :!9 ³PiڷẙĬ_{- b<[PhAxaQwOga'^ee,ecd?%.ԖgtVtt.nb0oL! AUxv_Mt:^88=̅[uDTc]hA.JJ G,,E&.-YBˊU')HQxxiriUoSqFQv+/g9 ᠳ)9 /g|lU2 "A d 3/{%)xiOkH[ 7!&wծJ͔S}׭a!tA1< ,W85A\[~Siɟdv ut+Xa(DoaKf`Aor)%tү|۱XzYM 4.ubBNAe٫Ϭj'#brsEȖ$e2Zٷ@ W \SsszBc p}i֠%GfYKR$-eX\KP|fE< "62v5Cc^ ք+ 3M9#I{Ƈ,a2D\>%,[0mkƇ9 ]ʘ !BF0`JwL)d{l^]@4)0Z*f)bz{ X.ÄaYW^Nesت*g-/f7{-I{o;ýMhuOF+VI޾uO?LbH(jnpm-h4Km(BU 8N'ǦhΝ<^WWҾ;: kT=&c xgAB%$|XmDLþ r?\8ݨg6?KT/ɕHsՑ8skYĚG7j;Wm%  xMd"f!caÞ I(K:M»G,سs#V#kT@O{!SՖ9U0{~LgDzDӆzpXUK$@oaʭLN Pw[x*q"T&Zi%cSk8qW;b" m"x'4fcUInSS6l_*-Ok>V}FP;,qx1:-tn 5p"?`)z$ۯ'1m>1%&uVkj"ƦJ66 {Ș-\+Z3˙N/`E}Nt[>ښZXx Liu9xfst{2xWD vm:)gs 'M:U߽ca^di*ᒲw,RsfaYjq"`ho\< P*V=%]G<1S W}CAC?q0Czwc(H܅ -),g*lE*Xi.ΐr0BMU)j;[ߑ;:Q ,$o O@smҚCZrҋ3HmQ,fNu°Gz@A վN"=|9,K{%y@ -ҘoB]nC4Ubd;K y픷)2oQl=3nB5=XN MR_{X*N<9I/FA qތ Nw@W| Ir`k~|)b`Hh)bQf=ƊT++ϖb"ũC7{Zz|^&<}ok9865dSb_4~:In!/"@TdtQ*$3"CL`K}:*plikV |:h7<}O~#K 2԰$@\^wm l7Z?m#F|+-k8bU Bed'wuHUr]+Pa.R%EhWaǑNa~ψZS҂sojq"><2\{g|0.{1t %EIq缙q};@j@|Iފn4_Ƌ}6fL{m zMtr$Z%& ,WAa!'0XGz<6TgO)N%]c ~-{GЩڱ2;ע(*Dy5!'yߎ6CT˜xj5>HXH8 _Χ%`Uy9hNX2KY8 q5#VG2&~YO߈t$|xVl cڛFsbH:yKZyђ'lRIlDM6݄3NxliJIpgJD$!J*R, fUZc 8^'wA~ѫzy` ʏ6P%|#ZҎ]ִ p <.w1E Zg\uʰZnWnG{W ql̩~Cހ_I>a{ʺg3lb5LxT.':/ R- Wʮ@G/ )!^:Z^1ؘ =O)9MENiffvѝO6Wu4CB=1a: 7m'ms\B~DXyŔXe;M#1eE*gxXX_`U|\o輢v; <3?˕xr0 e+4llMCT3"r%zu>T&T̳R}Ҳ9evXuGjX&`$ {kѾ6u Rv*{s p.6xTEuqYB#hb3_lJ!^joᲶa 9_lt7Ӽ `5$*? {19 =0.hɖl LXmY[;U@J5qN稃ZPb;\[(VͳVk)  ;wUKѿ};dlY[fĬA era[i D-zPr|Jfv\떉Z7+foIc|,$zaӗ#w)NO+M7#d/2 Jǯ׈|7}=}ڤY+=A8E] :bVp!\pvpBmb]PեPtαhc_L!\J6IVDaVݹSV`95?1Aq-I}{iz}3HR[6fH XgXDWx:l~Ao°vZs$ sua?j zyn)#]VkݺeWi?۱]@KƓYRΙvCI}h0n:ABd(~'jX@?kZ@'rॷIQe:]4ߨ'n|2௷n {Zw!!LBK%΁KՕ7pS WVXˆ.yY0d-*Jvxsr&u*&_^z ",fA,^MT̒ѬT]t˛xʞZ}ࣂ@ݣAn6$aDOfd2" Xz PL';ؙcཤ cv}?vsB\e1}qlm?F.W%Mk[ A<& B`=`uqCbU{s]{䅗"t&$#)!XU]}SڦY65Pm+٢R0͌EyF;l*Ga>ԪW)DQ?Ϲ8z릭 >6N-~dB3GAVUuYwcM~* LL,t3ʡ/-Qc| W/!Jq :m> +7-f|qډِ9B5(6i@>xO'{&c_g[o\3G[T-ѴiQX]r[Hp?5+ gYаƇE2a~ͶXn"Ag7W"duX'HN, ڪX4k,-.yr[U1ށo0sSbVJ5f$CqLF}V+S[>V[]Y7Y MJ3BVvnቶow/ŧV:DDcAD\"9`Ǔװ_z224S0IjWcJOT."C:PJ2K$"1}t]WCՑo0Vv}PcOn'q:PY+DW}tlWh݋ o6MަTt)Yƃ&m zY!^%L1&+FI/23>l}O(N+)ikM4rtש 6r[|cC~Oh\Sf adL/@BVdME!jGT3Ø1TQ>IIA~Anft޿Z~Ծ.8it"V\u,fYL6ྑu{Z A+L]qWV;Y !*q`^k nek!TP?OS=~:4YrWNJ+Oj@(~ k p]CmRE kC}˦/&\ Z F,B&s!bU˜MR԰} uġB5~,^UT#tǷ=p50WGzᮧ60%\zQ@ :$M=eM|Aw:>YGyJF?/*,Y㟭d*J(D|*M4FSWq"]jCer)/A L@ _d$ wLoUƜ ޒ4VNk3if\ڭ>io"MQ] {cƩ&x.蔔Whb.(<#=y}zMW k<8!UhPF<,zc,x)^o'|Y  \8kd1Pͪ?BqJaM%5eBĽ2xP!UZN<ؕ5ޤE?YfW݂Ez K²'3Qįw̽WЁztN&zVTۍAr jʧJpb: +q,kkr2y5٩Q{aNi Z|k:?u^M5y MUOo)&oJm;8&qss{ fcz']B7^ 9V3B8<Ʒ9IR(*)BEl5~&8 m HE(6 ʔ,6IHպ3TݨA+ [hn?tJ(҃gw ChsC`C1"ܔr61-}XN%H⡇ yw&8>\!WưDL}W?!cp{Jp&?"Awly-+y70=~G+(\{;QXmޜ*<}u+HObMp3ҵ8C &fdXԖc`(T9m=68 0,/6zb!)B@YsշDPռu=SmfUg"pR0 ux%ʱwM*gE*OcYhrbe6ox d\8ˬd8}/Gp>CUf)tٞJwYQJ7m^xnսT"d!<|AqP*si͊7@D*KVh탈gBqݒcB*)di˼Bu9Qxn)}ޒ=/7U5$(*C˫0ӣ@`Xn4\yѪ%,ӈM>[X>jZY,eQY"@hnɹcrmZR#$fdl=X-|cHtYF/ *%|tχ`d<}ͳSr;wwF1B=N^[Vc](zE_u}af1ce&[4`K@֛)* X ;ֶ'׵(Xb=C>~=ROJ$PKotss, P[2wN B2(^C "ebf'\6^$>p6*ӝ\pifXR 1՗YqU^hJ-u!$=%,,H ?_/B ϝ)W*E$<~bu>ԗ3 4Mt#JptD|M],o.q0rIczU=pIi"R>˔0&~D9L;6.=i>\(/~w 9?v ]h#wj-uSSIY'KnEs?yeI#^.KCk}t@̺~u\ a}*1yąj:.Sgr).&gH1xnNd )GQ$umX (Z9'c-x =dR:RWʡx57e`\KWJj #iAc2RX7L6<+VKSoO66;RQJ{-=̳⇢q7cj!ʎK8=)}qrm/Aii;{|.W^Wr#Eznwʴ67 =IVW0?i 20~!E,=I3 Zl \~]po(Xʋͦkr2ǹr<.SKCidX8£!MZ,XdW 3jLQT-I緛xM.~*蚑CϣEW}eͤ"Jԅ0hHݐViLoOu1xH&tz ֺ%I 2| F7>:ɞdq{BDmVFm_ Uv8,P/m2~0}/wou IE=%ZdZ`BѴO('PF%'cЮK:W'~젚HOa|1!җje^^ÓU{FG1@UUZuA{c„o j3Rf,ὄG{We`rh@i+5Yh\pmItH!a:1w{O= ê}XE̷1+Y`N@I 舒Tpk~-qT% U4x/G|p`RVCd⦣+WZ\)(zإ&XmV< ECL/ v:*@[@/oW6;4s>WET$)Ć kꞁӯҽ串se=q=%x5E 4Сƾ2znZϠ4g56:r5H| [' ߾E`dú#$i 6$>FoP;sU3i)Bܼm17 e`#'|,"L\ >"EC\e@h@ǃUS!/*Nlm٭0me7fxE&Df'umv,oah~i>,]\-cd$ENSAi-Q`n Jc^C22iˉZyJ_'T_8l,x8Z@1a3ɑ#eO=W {nWq]#\`|hrhX1Օ5F]ڂT tI)HnsZ /eus$hQK@S%S`E1ĕĆvV]xn7ԣ1WYۃץ s[uL2-g݅BltoJ|&+"\Ic\>AO\RPzª7P:tE;%X=)PUئqAPOn?;ZIgR5C}&6aj5ٖbx49E-)WY(l9>408 |2g XLu2+WB~tUal6)[ݦ28pF;";42TĐlU8R6S[Cpd>_QgOi pm `Aq2w"/3w(3\`мB4yc<D}p:,]AY;$J%%/;DZjb͒bw OpÂoZt B7ːBW Vn{/5n1/Z۸ |}b+5]# 2u8VTufJ8a$`O!mqf~SwFHiWu9p I(il: ȃ;?.|[XDwZM2F~x\ەG1 FE7 )c#k3Ӥ޲xs90Œv*٤Ή9zg&ѨmH$W) ᓛȪ)!|O9iC_vT3v D[<6biΤA2=cvR_-JBMg {0mQ{Q煤mxşJO8D6]1u&#m ֜,z ftEss ʩ|C\7 f(e\pFUO)4A-5T)Xw\src{ĤBˆ NAh!=yg8#xQ@xV+6ɖq$EY'ʾ< WkYJnm(\q=-*fTZcK&rqp CgE#Cx.;| kyVr32"Bꐈ)&ضZׁ>nBTA76SʬW͐L.'lp qrb~[2P JDӠhGl36^YQ9~ӴX6hт֙f7 ۭ߇Pq&M8˻(W20fńb5*{FW"6Ft$B X7HnMࠓ#f (1j+ եo?;~j1h ܆Nk~ ovF Q7&b%Qh:IŁ#J~AoG+hUi|A`1Fׯ|]ʼ2AمD% n>hRz7P"72J4mf4k@>LA|saSEh4oe<*EJK;W8Tbߓ]9SNO)ؙkF"cPz+>yQB$ԻE!a{//D/y1 Bx{ _*:yD]7\{PQ$]RzO;F82i)QFoز;ڠ#S_7Y!M|La1s⽔@#FP>,[OzgnNZud1mj{W`=Q!c`nkWUOo_^am__);X3W2Y Vyчt:: *uUf<ӽĂ@ŋz~QBt]Dq3R/xUܛ.>3~?n4[1s8sZRYrLIYT&!\SEbM e+κYDѢibvBa⺚kE<4i:'0r ˬGHY+܃Y:TK/|;hDt>=*:suԈ՟-D}VK`e:̍+|ѫk6 eBYtt q`6]?+a٧3 *p[(>Z8 {L=,/14@FS70*DZh W޸E Br]SD2:%I.e-pwƅUd}&.a!H ks4{!'f6]H nDS%9dP';2?`-3q7䢃(VxD!KDk@f"bqţ6>oٽƅ4K2ǰ5HRY=#Sظ$;=q;0o8oSl[a19itNOg@b9,,[ZRnTz.Bp[dԚ!]2:|?_E=*[{9nF!Аz29餴܅`qD "* a; nM&oTvt}-]ρ5QuͰI/5 =Lyჾ?6e1g;~`I1O53cO͕`Sקr9M Ps|(c3PNeg݌!>db>,I!L]1d`҇/N[E'K ES$5H|tj,*,'7sTngkW Vw@Bڱu.#}[WeQ}ص}JNWY򗩹=z﷥b_{93.,|е?(6zT0iԸ_Cdxw[B[#eKbȦ¯}(Jr,6"Ԩ;]40tUN$(1fYwCdyOfU!J"2?UQ )dsՑiN!4sCl6#.FpxPblUleS Y4yEPQa؝h3Cw6Xy<q"re|{nFYH*B9Vqfr*W"^HQQ71>.˔T:s6ɩ@٬ 5EOu{ĆpϪwt;)gHie<Et,F'al>k~-A*$iiAgI-4~;-UP%^wHGIDx_BeziD yV"],t\N-! 7 HftAWO@[%]rbKCt{B c^7MgdyHe79N3;H&hWT|9xŽ{ѧuI7 : mENAH{ d}}v)WՆjZ0ݲFfP4 Ajb1QA1N.XeMZ9[ =͂Q[OX3-Y!;N0|Yj FuLlE'ܽ|ݖI/$k$dnAXe pn6އbvBYb-4 k+)I]氻wE;lɧۮd@;E-'=bG7 KcnlU3gΓ/B`bvC ݷ9dv ``jw8ݨ9u^d8ưysFFdYDkz~XhҐ๼Ga0ݘ"r[!2PN 9Gks`'͊MȘ N=4E=Ӟ>: ;#eKJ|};M&K ^щ?tU[?aW=RXp9RI@>[eil6:eo,KAQ޸ Uv'!dh-&+2za!gt|ߵfI!68ѓ yq#z ${dSTa׼!܂ |πꠎ6lF}sG,)$(ň/UB&P&3'Ar>eiz14*4 2v"iy5hۍLPQ&$TU (+Ú#웃xKw50u$r>q&] MiBVd{ف\зvn]l9ml xhnBIR.R]7 fU#bLJN}d]kiQ(nhgN>rrTUF u^ܒC}D%W%~aBcMVɪ\%J15`؇ZlL.p?PT٩qw^ k5fMA=[`=rȯe#;-=HNJ.7d;.'W| !f62 j},P/ߝW0`Df1L;<^_rs1"dIZ|*Umrq0_AV|R̙a H`^RMc0^b)qhs')yC$;N5"!8%oЌ Qa @m7BiMΪbENX*&/GO&ևBïxRI0+WZu)Iޱ:cJ?)@dړXy'y%FtZ&3l.hPD-SՔO_8XAɔ!hc2J/^ޚǻȳs< 4^Eh"Gw% 0tBЍyɊ%$]_՗ ih1N5[*i-2:fc==w]xq3횆q}iapeD %hew|?ce,^ ż5D&m8t`;=;F2&Kt}bJ?6w!Rc-5OP\ItƂ cb}pzՑtlqp"W.zXL=+mQ#¥Ha6+CA% jX󭪳f0qL-V=*hurǧ!_r>z"WߓT6a`gKHI&o 9 &P֎u<ٰ y0&m䓫n՟,}S~1˳. 'RwuAjl7. .ȵg耴cp]5ϑ#"uIJ*'@`;[Xֈדи#|>#C^#'?X@M,LPalj(*T5 )0L;:PC5J)՜E34W{ :Rx`;<=]D4tE<;Q=Mx)\"S724ufǧHYWBLw"GSA.R<I!XB(AxR_s&AFvK'?. CBW:-B4CqM9wƻ4+po4e뤔p0(;kh;e5XdWSf5rWn4S)Cl1 QO< vI4QXc_xzfh24j('͈`KNFAݖƨ`."i;6%T"MxW{A!ʅ{ΟIN[ >iyz->0#6O1K0 L]JDxl`n}X*vư^۫=h9 SqX &3 }9 abE7ݸ`AXe^H)>C%gFoYK:>hP~.b]Ky?T[E1iV%%M?Ɔݣ”P)7vzV` MõE,qJYRl_I.EIh]vu[jH}Ji+]7+۷ȹW^ t,g(aV+Ak.' ݭ0 E @#5Sːmf}0X| % Xx;>_Us"xM[(R3nPJi/M(SżZO$g_")tYz[ v<|uBm|K 1DYJ=ڒeISb; )W78LAYWGoءBMKzjdcZ]J"tiiR ,w!u$霪ի?mc h 3͇a(*gHy73<2K$+p|AlM` 3~=Vg:qS\myڭ﯋M2n6*6!p雳!TH"{\2kt܁Z[$(M!>;s,tDJ2#qT5Iʌ@ɾe4$9BIt4hkh0G0JCh $o]zR75jV  sD+w"hqfpwkd(8h\vn(s6qT/k0ށ5X];P52lN['ogjZ2z,)&|z<]]\d07dΠG@xjk-C.tM1˩t1Y#K+{Sxn^Vm2~LA)U]c.y]2y1Ky3#J TJ qγA/T'576Eԏrӭ-_7mgx[38s+᮵(Έ;zԪsWnZ`ShX+m&5J1; .00JzT00& ZBhvaG}?5'ҳ9 Of@,xDIXbbhw%sC̑=~pOx>Mנ4vHtW;wݜ*O\X# B_sbNGEE[Y! *40Ƌ’Ht̔E<ؗa*;atSyq{u:O+[/P9:y\`4Q`=u?&z;U}Ca jV_-/3<~'$~?3H=Ck*2m$KREs:EԚIeߋ2\ M7u;؜3-ˤݻzd%yv>'gcd;NYw81@^-jhjpAـX?O6NzC @ix?wyFxSa)T\ zjmHlWa}` e>&O09j4Ǝbgfݷޅ#*pM 2hL/MنIp?U ڄT7mƝ N#9%h ?ZN(WWrFz%-DdveUmmøBY< IvWDŻ`q,($pZ.luh62Jwh@T%N ̱քD1JO%+1>xV{irdid>`"S^M'+6h&mpF4 9 1\- l'2C,ӣD4C oA:/u7pBIu *-Vܝݶ-]FUsx#Y0DЮ3!CR&`^5 - dy ھp0%{Ó&meW~gͩ Ob\tWrn:!at}Fg8;S1 ;Z}c+|STZjI_NQ;w9a®ݦGKsvױp)xEjhs݅KN0dGn+OI#V l+J}e)1$B؛صV󀦿U5U'<"pEקP@27?*w.g×ԓm }L>$r6Cjm9UH6HEDix˪jjzFoBi:95lj)0w$Pf$FJldی>k֫QŚ";')GD O=9Q kxl{֏xrgQw7? JhLJGh<c& DL.}|Pmd 0y8#HaOGꝂ :ʖQWT7x+*s1C[$|z$Ww#^N4e\[434n\q'$,F[\p&r؈nOiX:֒ mGFR#uRe=`JE3vypP { 9cTrq@7dlE8UVNkui%&ҭ)]<|Ox&WO& {pTDퟫ~N,]#8;H$-j jMحsѢK[bj(qbr~/ES<diPyIm xTpfʷ4ׁ8Ej\yE^ i_.9*fjbc1,<;`O\O"*ˊCBh8!k|1>c[;!ޮ_'@zq/; 6؁FԄm_D"s懢+"g9dHV?@Ä\;1OBҴ @Nyh/~΀˞ΰӦǑ1~dl+g+60A rV.";<щ"u%,`"FzwjS0zMeL_H3tbp-rtY`Y&}Ԯ;zi}c`}irW@Z2 Bޠb'1Dm)UdȋX)S+~Klb>FzuIaZoPA!i N_+#T~W叔eJ0]!\\9z$4!95,#CM8C.;mLf<K*Q<9Fb_bA)6,r>_OJltצhE G"-f%qz)܄(쩔摋QNr*/Ƀ#Α!no+l8@Biws ص>z{NF^Ɖ1fSP ?|M8rr+56\i=,+': wcu&rmj/!R2`@RiM;QS+r˗p@+>2/l};RJ-RҶ٫e!&hJFaV}10Rl`5/jߟCrEtąJDXN{=N*Y^+t2&Dpd \r@eBt-wW7_--mĎbH巃;Q+ވS'閰)c\u}vLՂwPZ.>Y%:wp< 꼸}{3olT'ts7C< r}-ΡM]7 KQq]FB)Q 81'8^Ca/&zv ,`bSEY((TΟfLÛ|ğMJ򾮄m xrQ`b ͉wq Lk6k-ֿr30Fΐ9+~+Q `} q=^VhIF _K†5Rum$#]1sP\\@!u@RB/þ><UfZJ4!d'vAl̏ bbGݒk Vzʾx $fRIq d4 br,ӛBcqJͮ4 G^FɳSg.G3dC=Q^_* hsܞ4E ZÈujCMՖ~1eYx{ԲmՒސf+&J<]r0ɒ&H Лd{@~`5x,!P{d$Zft) ;;wW :`}h$~`BRA Rm]ns9V_K5][t i2.zڶ:MMN0 / ;n|*OFʑ|CiWCV򯱚/"@FƆӕplߏeOLs5$P fe@_4w_| *.!$f':ӡCXTlR=Db{+3!N{#Й4RVB#0zl3OWOK{iB{D96.Z;gwd{n< Y#i/БSVWĒ9> >&8M풫X,x VbR[=[>XIK*=tޛ{ZeLy D4s%˰)9,J_>'ЖLZ`_ +Ͽkn<:5F̆=rdY?<;u Šރn&|DBcΩ` x'xY,30e(GaKl n3Olxk(hMy52" V,s洉cSX%D鳵h|?Ζ|ftkSB.2ԋb`4+fru<| C&%' 0-K>Lo3Ƨ̿8%Ŋn)yzFnI 2lIe  AWz)Q^Yfg7 Rd=mMfp]jz:rfUHL؍SQq*Q%׼}Ô0В?5u2_@mBǘNarKȬgG2WdSp<0fk2ހ0[RAZԿdx0n!&b;7~?PlR֣z"gJHwK|#/feЬ尷N= X-gd>=,l1W!VJ(՛["X?֒gNb_ r=֘锲B2&&ĻlUJkíy]Z^*}'Cy۽7pukmHBw (Qp=Lk"Zk[jpq"3v;:g6;.GXXȯtK,o@r:F+͋QmԜ(\"<8ȣ,F ̱`O@z'd)\`@%<ڌz˅4x'uۖ 1ZpBoiN[+j$?Oυx@Z̃h [mS{~KLG y{|woQ>x48=&-j4=-=[SrsSe港{(}Nr\B+ aPNJf֤*C,UZ uSiY!F1hņu0d=GMyɕǬ.OPVߜ Rcl/mIW ⅉl+SOقÚ*GDt &j{Q!Hj;4P(@ FbD-Mb)»<{Va`T0CsvGڟZS8!6+ %| bĔק]=aZĜuD̰j9"fu~ə1RweSiS/Do q#x1q3̤d;UB*YsB5̞p~BX_tᵊD5}ch([cDfPL |oT `Qobg"L@3\s?E]-G%a_R%LgࠨLcn 'a?hI@?@OZ%nWV!bCt+8IAK2<,E{,tʩT^%7 mI|G(.a>6buJuj55 x!T?ׯdODxY7 IgKE)'*8f}RW} 1 =MT!ʹ~[@XO , JX`_"D!-|eUYIb ؕ1כ#ƹ<-{u:*$׏&vBrՆS8|d+f6Ґ}{!-u>:b]-^"]b`^">,y()cqȷrؔLPULk2RWĭ"QtV B{]&G l"Ό1Ni;gI{aޝrn,4RѧEn$7EKhH@>nfḬJ--/6]*Y_w\8n8r\;*]R܃.Cu3{rzATqXW'\eFn ӂJDWO|nhG5Qir\2zdޡ818n KDI;ӗAmo521t7[q^.5ζ {/B/&OISUa쩎Iy|*bVpv5Ia qQD^޼r-(3fK*S0i*NJt.-yZ̑}{uE\=,UТ8"OmܐG.ʿ缔2Z48¦~0V\Ư:hL՗O9;I?t|k|RԽ6C?m9 cdۺ;^o >*YkߢPJoSo?RV_L ?^ik I0٬ɃdžMR ˎ{iuՎTWR̓I~|ZFcs PG74$ZqM=+ *3?_ "Rq vl "9{CJik1 w2 3{pB`_c[hW~z&A8my*p,H3Vx.Mgmݳ24ς[38,]x*o+g k*ك>\Y[u%p9aTYLk>Z$$xp&եiJ0Cz$дdžnmd|I'~:*Zv|F b+ GO9ء(+*2 c4a5W1@87G|RcIF 4eƉNwT6JrbbN\ֺjG<2Ua }p%_J:fr~DpA k0nNvn" J6w%FeF11L..(M%tȻ+QD5/Z̚?&)0'˄|c¡eԾKݪD]MJÓwob+ciELl/=6(7Z%RG^?+tQm$6"dhתm)#3t%)&vt M\q_]LjcǒX'>gYT" 懛 1o|gy!Ư4B40~/ WIE>.7#QvvF?=)(!IZeiѨ'=@</e`陯( VPw,.ok$B) w >MDS#=uu[3 CɕVvƽ78rqaH6oMWjh. *gruuY}(4i0. (HElMZPN!Yuk88̊\ RUW#_TNk*7HmcT>Wb^/>P?(u|FAs}{1i6# <8.DqK;$xH{r.l ա5AAiNUG^tGB83hyNz>L)#x^+>럞,S8Eke1K'_Ooz2r Z$uA@F(3.CJ (syR[H"@}^tmO8}ܛ~ۼCdUpZ.! Xw1IǓL±gWCPɾTK2z:${Z%^xΦ65?&ѐ΃:E+|/e~߁ł |6A*:{cڀ#d4CQJ4/M&Yhdg2sα\Z'JpRcf7R\^xinXD {S#3C]M!3u].>-L!#tml2qKZ @v~cxBB( jeYcW!Ԣp#r6%W{hގi8f=ͼlCve5G(:JւpldUkrZ2|aoH0]8rºko"= yH34\;<0` &l~M:[1%p:)|ZfJgw"7M}c@&6*!3:A4MJ|V!^=>aBcjȲ9h t9-47Z p_ph(:[$Ev%6S-W-RP_"!GFa> PZj&M?3u!Cu~͗_*9 . | R(̠ꄎlQ (QPinԫ9' WK7H:CtEt;O[\u:_-[a^5w*Mٴ/J]{Kv85Q+BhNՐ}o\b'3 b;8 #23n-֍6'aOrzd-9pc  T.廔]iy9d؊OL٥thM1IKM+ȅl4Gx (XlsY䮘#gi}?x~8C=(Cx !.VYChޔ tbK}N"OFd4whY6.ILr\G+zw񰅎vPFrcZ׻ ϳudk:uj9gB&RڨiNY $jd/o6Cf`Akh9b~&K C @ j18ˮ:kjܱ؊j!ڧPQ R=R]YnwNca)R#Xyue?nYɷ]R2GnXXu>j8={3KvHc>l4[c &mxQn6g!7RA<#O(ڊu6IY`ŃtR/)zqtzj(Y96xoZ?߁G>{Mgs{fǐiȻ)T`t\Ϙ|- Px4l5aDfBo6b) ? bK\~\~Xc-7ա%8:~lʵK%..As̩:Xhy{Mˇ6;޷2pHЏf**>zz̆N>6%~֥.uM'aɕ ptJgMr:STiuKY;j/߿)‹S˺# 2!W/kiM(-Њpn*jM.E} T9i.#nvWW!f!oDE(U.<~$An2|R\I4ՠJ]q2RbĪIy'Y_o׳0ӯ/:|梉\>bo rG@OrN?}~{}ͳ$њʸ EƱA?><+\musu俾|uLR AaL~ћkk;UCbfhxZV,-(V4W=l(㨽d!kJyu2!__cyoG/MlCϳ&Ã} vcTk2V<-zּy O?] G9Z95'9N rj\FBJ"_&3[Cv<$ki@uRk*LœbtIN_~ X0]迃J;~ADJ6T4Nz+VQ%|펭tN[{#+Y拁5كEV4FS=۴vJ]Zvxq~y?R_PS,GD Atʀlp|U3'5ٙ{V(X|1'f ;̢H>?S<ɅV&XxUp!J5؃/>Ճ.;pg#@ J8l'Ƿ8g{>vBaFd/$:~V Ob& ʚTY3 Hg&&Qqˇ9x< jzig-t.V[ӷ(8 Ev%(ۅ8d9(y`X65Hq.H r|6?pg8 u , x(An,9,}]n,ݝJh\o({53[|, `w#xrMx!2xٱ>Թnf |~DuV !貃V%xGXkpi gX~{fpEN?پQ{3#]p¥ ?Ջ\h[|~] Jw: Uou2t+'ds&T҃Ŏ(3m}D5 k` Kݦp6wP`ފ+ܺILƂ}/zUdEPh_oMRlh@zc(6&*;ќW4`9hEw [?B;jěZIz-bS&C̅R1:g/0O?/Z0q` eE30SlOS{@:X*U:>Z"r5=i8ziF_TޗOg4 0e "b@Đt镏? 'Ge~2ٷUh&Xxa=Q}QaWeXqa\᱆vAՈp' yu>=!$7 guɓ%%t}Yp_V;+#sH`W}ܿgVwPA,RPPՋ[yO#p>;O9?Z8 S[3'$l~Et_T^`M]"4'em2 <MǎbJh7F]zHjFv֔gUԮ͜7v[dIH|H!"*G3Y+>AJln;l&VԴ/DGDi\Qky g%)6ho5j0s58RsOA/z@"俱JU'%LɺcC#Wnn龢d;31&+G$$C+̮C:5kbUTM猺<y,YPM(!ԿOBfo!gfdCAJ8E&)9=8nk/vUUPϹ<` xp$|gB%cOʊ>o$ZtS$<㌌$8MԗƓVp|ҐVؠ2pǔ{PLfusIk[=ٴO(nv[`Y Td>-`,9*0G(@qCbm4!Le8!}V'0J.P]ʅؼauK ?r09:X/y p/8f.Nlv<0o>ͲmSIID"koyR r-?x WzuMd.`k,dw7`DGUB}Ը }d)ŷ,.zŒ*ˀ,u'5r0W@ [D"]ǟjp..#޻dfeD+FiKEr8?"ԦkU3,/ەKj`R$|q;_7DGHyCYdzN!@C.ipJ;뱫I2}u İR.6B+A.U.GM+/͇kj{bgzx>g)ZҁC n >s\O "AR%.pka2Vt8~Ct75I 4]MҴn!XR1L}_v).3!_yRLc0#P\؅s3zͯXO>Ce%vsȚ) h7Bb#\("r.*eb#З?' bhw+KkE4>jYl8INY djkh;Rgx/e(aF4ِ\ 9g·*ՓtUSU]1!-bB؍+ޯ$Iuzz)h`U >P^Vhfʵ-Jı2ԝU6-Yn>,6 ꥢG35sNvMUx Q8sAVWaFRnw[PA2lZQ@A5nÎN8UV w=l{)ˡ3wTA~AK82RtPvYe0sC3% P*Q8|ʹ") ˚޶0Ɉ~oMk4M$mKnucbh¿](,QU;|<ybC"vGY>O;8= D Ü_W6:ajwDc3A[e&Q$^V:qbpశ[ʳwR(bRy7O! qpPl_m'ʗg@Hlpωt{&o:_]-|kzA9.4!9`.ј_'R7v؄P2bA4k&0xR{ë}E-oc:_ͥ*C  Ѯ~Zkv^!7]˵_Ѿ_ym4sEP#H铦0J1H;>=9NL͏Z Q.Ռa|<?iJb6E~[L/t>*54z^ Mص3̀&䫦ޝ΂xpBa0'cd$q/Q `Z > Cso?1)j9p|AT,UuR1Qs!>#Otxͪ$ NHYr-5)"4O8,ߩ)ŗzƄ'YY[IgDyz Gf_qAKvd kf5a +\糋J0?eL߉pS C#W!ˑFx@TpVLb>B&%?0F/@っ"3u"n]9Okp⃄0%A!v.X2tհj twBa7>~%G:>j?I zB`1~;*ݺz?4uecM E<@I!9`|Zڽ&.G^ƳG.@'%|Tw9ѓŹe w B-*XVE`uNL4*0!Gk4Y{]6 T,Ojp+bdҰ1@Ųzh7 ux"dEG-ku+ &ʌkI8T0BV>ICPܟeCel;{ݦSXF\j#ͅ NcFHm=M;W`ٍ6!^?g8k)t2b˙RW?z\ <_rFT+(GrYz]Mދ<٘a\jYȌ#=BDRwf5{9(Py9RAd i4쁝'BxAa/l8ҷP޸^Q*|q]}( l5x!ͱH%-'a%6:19%$ G{>$:ՁK՚e]qx1_eg6]=(LDJ̹E-; 6;1%OZ¦Q+>%m+R>_1XGITBC6BiFK 뙴 3ᔊǜ .P!WԾ?c'&jNb5!6sY1m{͖EBu#W~HHFJJ(+S^tMPǿ\6 dG)iRy=(?;(uQZ]#!k#I<5z?aQ^*5 9տm`e 3 8gSžtdZ:~F:\iq0Ldzab.|GBW&y=WzFϒ&"x?[R(T^ntHgYbXFn`X'pz[)bo-)|cDRᯫ<[Orћ%"#.$ix?MRRuBuV'a-&vԟ7Yf/a^osc%cڟ\ySC+% =>ŐBW4J2٬#(iFٛUCAk0HZa 蚎U Ճ=KE `p`À ?Ig Dj<- =4G#nl#ӴEl(o [?+B܍M.,8F{0}^{G1D31wb:zzy{Z .C'tU9Gt& +i&G129BQB.'JT+oׄq:۷ ",IliJw+RH<Ɉajag\u>HOA[jѱǣrm(;ξD͵jco7+z/UE^$a\X3m|ܕepٚr%XQ`KR%.? b=_9L_ >YP8N> y57e&/գIXwQix20g ͤW][L*XUaٝ'z؅t& >^P72SYcLlw/&x~+55 U{3w0TC?Dae2-D.J'f9nDh,xUwkaZ8^{zz 2FO5|اjH4=[lefS4%'ڶ#*y6TRMO ePȸmm<8]_ QѨꛍ0iՊ $ }<7TŢ%nsZ}/;ʋv̑V4?QӿRkt*|RzGܯ6 6s>Ih@ mOQG0vD1iu(lkZ(72}{卵6e*pV*EIdyP{>6B5kD:Ol},?2KVx!*o:=cOlj 7܄-3Eb+'~_WDA)䡳? ѥu'SyKZpA/N;'k(5 fKw< Mk^ڋ(]J&@N<yb\=5v@5~MM^:l/؊0[|nR8%HIyi{g"?=Ýѳ}>K +;K3,iE<pRaohR حf0C'Kx[?n`eǭ ss"*ّK/t}&[Fg,C'!1C  q6(!~e|yh}9oo8˼ յ6бiԻ۔ΉӷF4nKQ폛!c&_x&þHs?]eσ_^A?| ONxeK E#@A~љoV?}Q*=7ȷ]Pg~ g+T6 ^VPȉ1gy>þS;uR·v$ \ n>'^z_BFZ*(明<w ]-3Lýwұ?iڙr#'dJ?JBd{Agocb?{ToJ&1&@>$ʇxe8A>+6g)Ɍ7 7LC5[tdqL+ޡ Trx?"Ԛ\nX*Gy$&B7:Vix0#.`:,-x9P_ȫT KF g"p՘_9*ctQ*YwiCWLEsӣ4J`5Rz2HWpPHV7?Whb48\ #N(5O6Q ΄U}ܹEK7奮s>,C<`y]Y00Ӛr)E~,-jRۄWA\)"> O-YX3oC`TK]ESn)7<;. {F.fbV<v &1I;Y6e֮DF%bqyt|1(Sm"hy{qcgBN%1C3({PCl Y {#`+]u8a~!,O:({=4T=E£,rK_m%tK˰G#ZpOyj?F֞9/X r *t Ӄx8cgV>oY啈=g"B4LUCYRFIdSxa4l"ypqR#.̵hkWhܩ&x1X&i[WX eUpTt}9d.&%dvhVuJӬ XG:PW  kpuBt;8h/-'xT~t!ً 4pJ9zc[7b.( /t5S}pzRUо1daL~^NivQa[V߀ `泄=SwP6q o<G^ɩRVU%[QU7y*9lC@9ntV-Dy?0mX fF|$CXܜ$sBRns}=Y.ˊ5qbOͬ;Zti%ba Xr:z.gV>ga]D$ fW!S; c4mFxOH9|J*]*1dI3\R)!#*iU͏q}`%g`WZEQw/0P+ƍk;7+1dJYT-?4?[!^rHsdTGOhy4}yD ]I`y)WSn3J+N/ iX@2{؆.5T?DD(i_?xTRƴ^aK\  *~?yn$~TO3h!<ɢR9wyfV{f$*ِ|X*Kr''A!֟䢩-< Hx]趸 =S &VJS~dcL #Ne @ƏYrM ߃Ze[ 8<(&4DRs&"|TRkî}]̀ɏ.YXli[{/Y+#`Ȕa,xdw˝%㞸燴9Mf9,ΞмSՕ]YңuJy\kHHP\ݒ8,Yb#߁wJ8-O & )HXe{ GM@אv D CBe G )52F4k=+`w?;emA W nsJ LFiLVk7OX?;FMG@xF1#WIsi`M+8oG~0pJeeY/UvI+iĿ @`޾4<`ZBA2B;=TmzЪ4co"r#|e:wAW]tJAx٫|#Z˝ eUTM$7kS%D 6lB O[ΟSyYѽ:S' I=0VzWZaP8T[w);ےdC.fjmqS$G5zZ9{Kw<hp`r{d[80?庍^sgf8zE_ ,4D^8cWא׎bZյퟀU'}Ϫ(z ꒅ8sHP>De+2Pu-kĐxq}7qdOťA"aa*u&F8Cm^nw+U154?VԬҡOGǜH1?b;(=,WJ.lT]aO]H p W aQXTO؋҇deHBE G (]Ø~՘43(ele'p $ώo!XT0FVSWIs >} #ap9=5*/ZZmghZKx}LЏ<وMFiPv{fd{nG>K.oOҜJ|fY~a ~\["І'b쾔pu&ܗHFr XnDS;]T|}U;7l*<-|c)&DuC^Rm&P1?韨gqUL|A`!>~ng5/^5ϋ$ab̬{VEcF&LLh̎xir4JKZo)Q'RRocAS)DwuL0LYGJ*r5XuJ^TN'<3D9t޼Bb(kB_ h.roV3Y% Z.0Reh}ڏIE@䳮Ŧ=t ahE%[غHC^,CQ)?FW*SP?/ <^ڮX@6Ί9z -"įTYp9e_9z3io;3_/uԅO@ bC?ݵq5I8E>!nn_nYisMǞOYZP`u+[Sž%#Q>QvOi":r1Y]ǁs)E}({*0brC oB`Kે5( | K;m#pڇHrA_}P&<7+fLsM.3}?[Muf h*e{ <؜/;P8t eU{4WvHr IrB9\\Eu,Qg+#GvXoc g/T$tc*$ϭzk!Sb~XAY5-_-r!v'R·FaKꑄVةN6s$*r57 dX+hcADv q~w\R.#n{ ̉|HH'O /8MTeKxmG \gQ9̌ە,iMkF"Q,}dTOLR>'ڠ%VPnkA ߾T5` tG `v(ujV*Q&z'qc΃,RJ+O(z8TuY`0IX8/_pGNL`f Apa )ӒŁة$g>p ̀H["Ww_Kvy1\>+k蟹'nD;n)X6_/U oծezD:D ϖVs鄟ήcDA%6m28(Yƍ]$NIg3ZPZ2oZZyBweQm:xTkC U;l?OiӮkUhQ@:xB4-PL]Q i DDRam.uYK92]0tDxwj?5#n Coݠ3 AwysA~b *D%X;p¹HbJǣ\?Q-NGpk> wGe6S[\,U9\PB D!ց \ܭgt8{Do~ڀ{AKjbXlhXW\TvtO1۾ULy{|51HRYm /%Gl ;e]s'BH%tp a?3-9^ۃK0 sH%^`uY\m$. x4Ah@T7f[}\be\6lWR.X%!16˘WZnN/4Y5Xƙ*9δkAVqbs%<!*[2S<(sV ݳM#%aȦDJNoaeUo $!%Y[MNE G0P_&֜t}FG8TС!vIx饔[f{aqnk]V4z:t1 EȏV,nmx` LkKFN'l]0Nr`5dqR R2v|jޗ/X5Qt_ag9ɖ؍r}uHAcp+No`Cd&_A,!1idzYS@{YW?rFS|G۟(Un&R R_D u$ٍNaJW#]}yNȎ ٞucHZ}LEWrjBs!8?[|Q]oZ@oO4K>k,`$5`b+" fXZ[@?FL|BC Ñ*=͹̈\Zj o 1C YG /\׹{exN_1` 1` )J6d/ǫ GusүK=& 3b;jcs>N̎K_BԽ~]J݀Gv'jܔeUVبi ? }F;cХ[RQGgDz?hk|tuNT;|4%/Vaْ# w'vnsccz ?U*r"vA};lf BI{4 VfE |ƺfNLa ~0C婿aVI^45-cpկ܇-٢!ހj+W\ &Op pc Q;H4X#ĮOG,66We]4+t ?x潋B4>=,VrBln,"y}YIk}B?1\{D. {\d;fŠ̪L~컷 m !򐠜;]eGZ䛠KDsP)%Vgz:(ġlpڇ/!3{fkpbG$;#y.l P7pٜO?$¶F6؋ܪNkg3{.LNeC 8? 7#u2>i»*(^_ p6OwXۦp<a\ȟ r(Mgijfő8olkGK"].;cņX5LIFwMBZXKq?[CTDL/W|#.XթiSW:ns '\-@>-6 OQtnAhƟ-tizLϒQG*l 8\"_%XR4D';܎;EoP9*,0  V>^clR$"uOŽ5@A&o?$Kp)] KX4S}U~e/ӡ)m/(v^P`XĂ>cd&[E \M^kxZFs"W\h>t˩w̧ۣϼYṖ#_ qB'Ķ@椐nV L,鷺kVȬ3O_s*$EFS2 qIwO3נ̯ [ .V\ސ㎎)t;>}I@|3( \rN(VtLʴp;IJ! L? y`y)vLҵp"\OI9+i[3Gع;d', _&&#B7D+ݖš@,B"34kf9b- PCE0aپ\ _Kwӡ`oe(]F-d-Ys9 GM 6ճBQKA7Ys X6gbz+\]q\s2'zkxVm^[>ͶMtEm ޭ WTTK˓nMbfFC -\8cĵg6SwY#+a>2GpQ?"g mXH<tMh(fY&Ni{Hk 1!Zv._x o6raT\'o2H%1+uj< bKh7`,d09AS+b f;s\5q y^UiO){[ho$O}7PrY郷? cFt~K *"8Wa[?b'޾7&NU#`6V*3-a)yɽY٥O$Ӎ7D)ܲn,(.6D-O2Mlc6}MN6 Vyf]"0=CY$Z%f"EHٶgtp3tQ|efHZ~rh' xTq*XwYub:PL%O[? t0lc JvXGm6sM&lnxOw^L0:톂UY'@T>~3sJmq$CR}-fs<Z2(olx?y;[Be}hqPjCncG5N)6߄$cw,˦.0sʈ<W$gJJuoKS4󧷦WiFe,BJ.45N}v)m>v~XIVp5W0Jh "K%A(h=Y0C~.5t6RFL, CLʃw0;&/ 5ƩQHg߁ZB)G$ A~.RAC$< ;{$GM>۔";x:7G[%#Lµ 7 V0rjp he6 Bi3qQd`6,+_ԛa;J^}5ʨU>>h׏Ozyk /.oz2#V E, Z &=7-@wknԷ{ɶ2%"X{/ӟhE)on< c/?Y6g4>ʞuBcr# #h=;VMw+լ9T*^=\dէ M: "]%bWc@ϯPNxzEM(u^OhH7n)nڹiBH=^י.u{u{4bMzRj76iаNN? }W'[#'ZOʏ@: @|s+#]3-Ϣ$O@ݸZ_ S1TQvl[QmS B:yK9[d$g>ili`}mtYsx:}ln`(Nh^cΨLxˑM!qDn6 BjObE˼b)2-K gdR zk /Tp tKTzoër!4R<)Ӂf>^s",$tԕ8Zs.Dfiq#XP6`.+~Gp;&z9)p5q~-j _' G(P$<v7_@Ş/mt*P%] .n|ȩ|r!ƞsb1KD|Μnظ ;? 4:42NZS#-pC0|ܛo9 6Xj:Ȣ0NpadCҮjE#WqaII*49c@Wf e%4_O9K؁C|:3f#Ý4ch"Ob65vX륨F dI7yʑͷ}#44 q.a3 Qpnp{.O-}Au8Nư[ B!<^H",gTJ gcqL@>5 U'K.WWE=y7P|Z%s㖕W'DK~_XŢS/(i C@&1 *Wʗ #} \6J߷,J6D+t8?5jKQRUDq|77l(  ,Ԩ6c^usDDus9?C\ c_#̄S6p]TpWq_k0Vv)ɀjX"FRic&''_)&} ܱKc3k42uϳLu( 3_6R2 BHD&'RCMEُJ*.piUx^wr)c'bCy&#ek#aog|0id"aE|衅AEQ[+P~Fa4@ Irӓ#pi˜-ڭJshV!V IR&Tխ&}AC?wE98m/ sTϵE`]V^#▣__ǜze Mxhٰ sO]5_(dY)W wW:D8pv!&:Hzc#%Z"j6,j7I:1d$ZFa VM}u|ڥE}"єKك[%ǁmõ8ٍ039Et6`~<k YI9VJZa뭨͹wGtVpZ83ʮ|"$*"ޝ1-V5fVx=,wl=4'4Ptr$É!lC+bɶ!~KuK\MB1/P=0 W9dVSkam`RJq0COMeV(VFvL :w%dM:6܏zan @|3uq m#}ֶ,S|uEʊ2Us14됑`"N'UeԮ(&*pٵj/hԪ!?S.=sJd YvFG>S(=pYśY~J7uV.KaU$-rVJra 澳|!՝TaHz7+%\r0o9JT٫z](bhs`@(_‘8 2HT/W{ }Hy$kVmupCvFS_oDI.<[?'8aNV,.:"#8&'jj=YmͲna | fjekfIy,Dñ+2`̠JJsҷw)0^!U\lNe`i,/mJ-HgؑUŔCU58oU$E[-ʟzP i0C Q4v.GN`֤n{˃*I1=W@9_FydѰLLJ}s1&%ae#< XNdxQJ5ck#rƣg-wLU6Z0»?IwxW&"do |jHVf`/ ا ]:򴸨ZD6_r:  SR5#bhnȩfRc9]mX;Ph;[-G$|~&0 ,-kΖduʙUh EYRv3yL}T(7[ Ǿߧ aqp]1}pޜ{V6f@(:Kf 6mc ?穹`s6Xevnf9YxF!TfVW5]rdrҔBjPh7+Z[1 4^];zj]Qf!@3(,zv4BqVzP.YvNV.iP .4C l[?p)A C f0ZG1o]wqMH[''*,*h yOP~ʲm=.PЉmYͦAPQo=3EφS d۵ܽ]{3~ްٵRJf3 &5˔|9j^]edž,wڤIv)|[Rf/ IZ_^† ph6eWzHS{ .t{-QN\Xƞ7*Q-|ɬ:N]8"S[vvX^#w sΖ9I|\W\Hzj)Bu=Cá^ CrA`wsyP~|]h/ pDGpE~F*u/T:NADFY FXg|̃ˍ`pt-os] &? I$:;aM,WQ>v>+.a^DiA[2 }GIpB{=+< U,HxTN$=>1H9wvy0/N!VZ%B]'s &7)ҡJ1۰ru8;ٗ:Ia#J<[jG[v\r' kr{p`4%#Y7$ B!yFrCT<%_ЈsSfj:x8~`RJ5;p=|xpPNivK|dF 9jTv sL®?EZ)Q[Y(w/w|ɰuwpIvd3he6UZ#nJz) H$xs.MD!!㓪B3†+ )K"j Hx$hڿ%'^zX D@ңprv=p/yHĩ<&+%65_#ҢZ [|)8/n Wt#^^MTr38w 6gO]q>?!PQ>nF?4 ~_"BtHv(Џ@߄3gb {li 8XdV{l9'iZ#o/H|ӫ[( v*zBVZ T8;z5sAf;VSVFnX݂6.e~JčQmXZ)j(;Am襜Ak3D"G5{u>Fqhu6FD/M3ݟ,[lpKKFu}G elu,$!AVy,5|jy#ˤRNe\թKc7{4xܑiz2Zϯ jY.sM iQ=(\3Z@ok-F#(iҶMKL\-A戗ߩ7^OI|Jg(ye@ʽy:gx2/z^[D"ZYv2?vU/{k,g#~ye%14m<5P8&Qj)˵_%V/ Wv\%%n TMcu6D!W O{5B+Vz|Xsg-Ҍ1~M&"""I&%fIFQ#,Ƀ>tMeB,bƉ|"AIHڢ&]Y0MC15 '] DWFv04n,ol~LAt^ZrA$W۳3r!]UxHh"@C2Pm8ղî i $ ޔkĎyHZVP0T-:iڢB.!ti.%klOmЦ`>#, u ekrwH__ S@u"J@qgB|M:Γf mR<ǀd! M@wui++z>;_27!I>s]Tދ.Gu;:HN=ܯ?UaF1i9z`/YN\JY :\wn, tٰIrTKJ~\,}􈀠 g'XSvTlPaSpZC7%}WY KP 5 S~Qj.X>te6Xíg48RFK9:Wlyu/ L=E@]S6}b8DtN@n?PltX/u65*!{d:Uw6IW ;dj_OF=LMjFe ֲC|{ީ.}o'Y>gD-3CHT_J,p0 sMIfW*^[RpBRbz]Wn:r8j*28Ge[0?S2TRE%Zψ7lp|5Ucp.`<})6EѵGĵa$DLګr~m*G!4= FO%Vɗ"gM&3ԉtr.>-ح6f'\#)~+T%,L߮A@o{|p{AqptH? S\#ZߞrKjj )AKMc&u_hީYo/0:rJK{$%/h=(+dZzx0GGhܣ #Y/O8Ϊyl6q1͂-ٿJĬ~;{/>ip(.WZD8;WϕT]2nsV=L_EMp!MXJB藚44Bl @x2A/>B59Rf4RRMM5]J"cZ(߹O(Ȗ&O%dฏH^ MJg)">.U4~:F I<2:|k6 B]?"H£ r\?_n{QȽA=o=cA>FO=.AI/ -[kC@crq UE#Q%;p Usb6mpZ x^lD5waFz&Y ܥ.~cz! :diVdhuCbrF"Sk {J9N9׉c|mpxdD6[4@%kSH֋ti;'gü%8aD¨mnA}ʄ?gស" ؂)nl0cn}K1{P(o 'D˗P2FkᲇzMF(DLb/,ī7[ S5qqsaX`~* ö#gCEJ [[) pVg&tYvmPA(psqCC$+ iHzδ+x443_$IXnܫ'w8kԋY%m1'9h}3*Ң kB:p Ǐ7'vcH(1+g۞Zcvj%8ײbwaon8]xvYjm@7`Tr/tNۉoifUpiA}RꕳbN">z9-ͫUxaa)Yc:!A3<&5*ZXb(8!LEe,W&*FiY&'7cTᨐr=ed‹\.Zkh55ֶakH/d܎SY0;C@Z~gZ_.{s=pwWa"GÂw=s;8,i4ԸR]݌, H>%jpg5r)yjNPZ{Vwnrce/y[ >-:>)ʠ6/|j GIIV oOE >ttlԿ1Nեg KOO?> [꽘M@{I.$BO鏏A o"mDe |kS[s6_fy2[$F" ]ksn+2 G5 $I,.#rvWq3wxL7%S̸b 2?z UW>tٜWĴ%$ Z;&Q8 .Kf*%YنwNMm9-v#N̪:Dpv~>Wy$g2ɗ4:àrEsFk ܊'2s]ET1 *EEӥWQz@Z$(X8򈃯-)筦߂Ϙ=rqs&(ZMGB(LeP_swM#q;zKe BKdEFo$` >8{IX_؝#{DAm[l,߫| on0 >_"te 3ˎ%`y?Pf[:WYj(ɃTCE0S>߆HK-r`BMD\H\]!x"mvL~Й/Ĭ=!1oCGTR-.%H;ڏ; mcw<mLud PDkN^;93]C; <SYS#Pm2n+O^nh\BtcQ}+'1/T0,mCfn^`E|`;`bT#oV<|#!4V'-"W܋}1LpGihL,jMhRIĐg+.qq _(pASXnYal/73$ ԓHskVӎ̎o>i.c y \13 uTPs!!,x]74?rTmuj_q'V~aiND@_)엵_*;8E-z]7QJ*Cڸv""9sNɨ]csZ@(UMH~Dzh/l1 Iך I+H,m>!>yclCbP@Sqf (^TH# )TX&E*A``*D SnؔȪRte ݉$uDY NrĈH荠/&cb*MPG6{]5t_W>̲{DbܜG:1NOCLK̞?+|:8gPnZiFUط?xbL/$sbm+J=LR%)>mH2mi| >_HGԪ5m8d:{$[[6vִjE |5qAGєK5KpW򃱩ɼL4(.nt-U\n!ky4 'uW{x&d%@GӵHJ;y ٢Yv8tԼ nXEv05#us/%v:lmfyc(]mxapU^hhiKd0({Ywt\[)P Ƌgv ?}t[uo'crdm3`@)eѢJыŪ+i<:cez1V#4|\/*\=Y~wc~}$^b\a*h*e|`iQ>tuH}է&U` bi[U/!NX%KYPrE :c7DAJ =*C>xIƺB+'Uo9R9ˉ-lƹ3Ud:L#WݻEAYZm4GbfJ]f0/8Ad ?螓]<ӆgmRNnu#1b::]=;25i`id61>SPT?ΰQ&Y{" ]R k͘:ҀQX*in̘;4.~ H {CMI ֓p?aSztuj\&Q…r7R=F"Eaiڭ op=D4fg9_5LVwڡ| #NÉ@Du0r6O SgE HP7.BSh+nׄ񶬵UfyYtľVg AgU$g㈾5`ݩ$v lcf\5_۩zv+ TF9ߒdiV&J+!w5{D؞ UuÓ@\ҥRVG1ap_PeYIs)I,-EXPa+$azZ-%Maj)~Vuy?Bl3OJ9VMR:-!x&-b=xAG3#KN-,dYҠ8{fi~*lFKwm ~_U Hkd\࿅4G KDoIRM|fR7B3Z:jdsd^2̟wfFV,9[hH* [?JHe(F_: @aCwG2mw86a7NuIlyTWgXoM1l'BjI[ )J JxΗwD\ͩ} Hs%΋Ȑ0{mtR*XFmG~kKG:A?ڗ{Zyy.,f^ b:&>:pȅDho0Q 4 |)ٷnW>ffr#EƆbyA_q`_gWzq"fdɬ)ve { ͟B3Q6_o@)[~۩(|ME Oè(BV;-)5T8-#k᧧,7 ̏<_gT0WI}K,6=5/i#9V?i3ϋMc"y.=pOF rV]\tm5+WZ3roL,ҲL`It"vh⭴8Y_=wef^^PZqUđhRTx]|,9VD6ejMP.H*hfT;ߋYW0)ǚxF>5%kr440v9b ..pxC:aY'ɏbWV:=x"YӒ74dIf 2!0Cf .F|9,I5,d)l0CՍWEo$yǚcJ0:bKs˝ʖ6X+G0cXrG$N(TA*jCHv'^ DC'2= S5}ƲK<֦:Zb$坿jpy`tukYV+t!zᬺ t}}:YK$)mvp#eoaRe+7j6a/S.s!d$:xn]GLC5@cE[/s~x@Fɢ~ }}6 ł\f\>⬹ sbS,KQys/xT֫}-5&icf^ ~(vp#na+r8Aj\; &mrg]s|L`rZ,!%AJ 0 ˂p/Rvq'!P7 \5oYEOWR$x뢑+=dt(ݮND1[۷[gB%.M \Vnj-^u )`ͥ_w*;*5aUEj(™`mWL$BU똻ħ7y.gBkHdEdlr}U,֯y0quN.4)SZCT|IJAmnWfz̶aeT"{5]aNʩ ֶq\h^XH&C dznn|1G[}iw#n#`;pB:i"do{{nkO32k*5 ߯ɗc.NVObUK]uG CF8yp15W8WG~u,A5'AO?gFCٔ3´]rgtJAvmϝSN-Z:yt8'fF\_thwdi ~aΏU> Ax>غ"~#o:$ojbl3jdLg ,1PL:.TG#rte@& cX! :YY6f[U52<^e&*dł= "y`4!#ޛX" ;=0lSc(jt4E=zPh+E>4Q.Vh8a,b 6 @c p8cuV}Nc>+ j6"6'G.^#T-]E E_׺ZXGl_^J=a_cA5xsex)d#Vx;Ҝ6^"`K!Y#وfM83u_猲uUblLpGԃ㓱}xNmŜ M-U5kT'+h8 ipfY"(>^^$sQ G Ps[ mx>' +k0"㭕"t #,M':iZK{hl5D> rS2O&$[+x p<4SEr`^/ qKuFAkiJ h)ۤ@Y Vr6%D0r]w)Y^x4',ASsDu2ez߇=9/h?s*Qv6ខوpXtMDKE FYw܄< KTKO$6B{E 4"6l9YKW>9ȾvIzڲvծp1"g?l _lF?* tcNgQ6^?OJx8?3KNg :dr%wP8-ob_opZ |뻛lk[}!sߊ9U|YgZ5?vݗޑ+:˔Æ+0r5^:vF;AakFW-U~jvⰵqPu;FAb`&݋^6,gMGeR&h:2=p%~rN,WtB-lPsɡD`JdGC(B"s>;9'p|zc=pWVBiVLI.xhX#Bh#,++5*}zKqQ MϐJ/B`o;#Nd7lw =n<˩xH կW#~:Z;_2+CJ&n" ,q9242#gh@vr,E7_p۾D N 8Q ܾ~Np`hJHE8>iK1v3P12UO إԤUm׆(ߧ1%_8z@A.j]4^jl%l|d8Uv?VC# lTk(ٚ2#Ĝ}dYGQB;6w\avfx=eProo}ݿ噱jʶJqN]>j]f,LN';jxhZx.Nm~W:1Ō"zϸ`#̈ByK,9ӊ¡Kyu {ǰjGvh!$P ZONiWtfݘE}W歷O)ɨ0ݑskl$ `8(],,5T8mIʝps:MQ殮5+3ʠ[e|9x4g= ;u@fnl+MƈI2ŘܬU#sG`ɟy.ok 6qA  MGRQ~Dz"0F\Ä;"j |%A*_BwxUx5|-yKo ٷ_bCtd koɪ\u'De_/>@,-cw! 1xm{_'hyײQyYX;)bG\P@|ޯH]Ӿ[zT@IH% &(_Q;Þ /߻HZU@a:N=S^R1}=!dW;4~`b:WHjO/ƈ\Q}!; tcONp7 ˞T_%' xNc;-cַ߇)U-av-y+7˺ƪ#hu5i$il&=$dz%bY`6bdRJNw#60W^kṈ`A+d!)Y3-5)&Cz#i:[>ZnWDAo[Dr@qe1z p*_@Y6;_O0B/@,CiJ®K1W. x1EL:h.?!Bb67u>N5=! @@/RK8XhtiG=R L8$#q>Z0({&;ZkCޝܱurK!31YM 1%5O~ P)9f]K(v8dܝ A?ˉ&=%@uz:`5C#:I7|.D +0pՄUPl/Alko! @0F 4>[2{{&Kp;]5}G}@}e6w8lHqLA:V# _ԲIS[rmdB6sL>;8e,@N/,gCqA>2 `jպqp$84ҏoC4Kxg~\=$VfJEWtI%C9mWN^(kn*61f}N\l&-x3KN"eEխHﺎ1M#02 *[G0xt[Q`u%&}҅!E矈&3[Wܤ %uc hAwZ9'_ >aXt<{5Q]Yɦp|s} t Np[!_n~.QסQIU4v}.@qQya$l5G,> |_⢠9r *Kf 6sj|Hrt~>HLsɢ$sk*.%lT.G&mw[5c嚲U;13ud*" 2͸WF=/JPe0wOx b߳UT' z2G"dRn-,5 RɰlKuy=w>vMXaD R[>UJվ7e- {v*@ʋv~/+9!xl&Nj5ڶ#!xO/"40y~!KϏS( YLqb;zf8c*N|Qx햚wG49R 'e`vzDkl@LlO74HYVlǚNk O!P+{[,\zļXu\RJ;E)˛t:7!4am Dxw^@]WҏJwsšKBz7pڳ,/bߊkVgk{C88x7CiY0'/yQ©\a1 FZ9o)!ܼܤj|]Ls6_iJDGb2f0 (OAhuQUgŠ-7^Z& 6iҐ~ IGQS$G D]&?&P-`sM%RxKnJedhOЄE:Z-oUﺵ5^[(jՋ)QZgeX@xf.S'dvl몟|,,> ?fKrYbKLM4N~-FhZjUl_#oυNs=PЭ4v|;lg?"7}ʛmS%v Dz+DiH (Aˎq@n, "*3ڒrWEcC4=2.N.9㱧JwH~R  y.?ws!iW6m"WeuRu]A%]6N1N'n+Q:\zL{6x`"եXbY3?(Xg~C6غ:{+8zZ3h] C<7_<)* *;n R5w ^N툐n-_]ȝ]Ь8):8|۱,L =RyǂQܱF J#𰃝̵!6[LHoLa(5^6,OS (,l]~e9/lXXJsyN،NKUjqC5(k-ȑpF-W9gz?;2MU24Ow( `FK1eDo$c^}]t]w$Z64 TuE~YԞИKyogv&EӁ%D}(4&D|yRR `EDWk z.%Q=,FxCC^tjnCg;jt]lo=׆xYHGOnxjȫAG'/ҺXOBmžαas)$;w? F%8dYQx 5 D4rKt_쮜^c}4 /'A$C@OEk[zZglJ3vYh'5!k"`7}Hps˸4>5yk)=20 赬cEW$Lh aKَs57ķBGȊAZNGDOrNBTŲ'Ș><$4['S|!N"Vqǰ|JBɄSBQߔAP?XBo 4.ڀH4YQ | 8۳VZ] "ʩNQ]d;Mv;|~'ٹ<Ĕ7,F\*rG~JVd :bH^{/h; RZ-aK#3?._~{bɢӝ_\ 0¹z9.KX;~iΥw=˵-'Z4πGģ 9 .XVxn]A 3,:QT4:CXŦУD2? ќ3ȁȭLFs.ZAB^qdӌOԈ!3BԪVtaUd&)mҠ%52XvûC lWy$&,iD#+aT%MQ5|p=dSj.N5fNf1מ2 D .=j׭.\'3ce-7 .o#VbpRשh)CQC2ʯ1( h@?Xh{@xbߑ\fe2ynt0&yy@&7> |++R 3~uhaW7᧢yݒ9UC$m{͹cJT̂iF3[97_< ڝ:ĸD!vIW `8E  D0K% By=4Xd aJRq{7˛ źewr 3 zp G*$ߟY\; 6.t#|ftr?`$X|;+?` Sa0=w]>b"0WbYjkYs3XM2-S&DZ&mX>2h#4F0,agPcQk?^K742O(bȋfsI4Mtq]R_I 'f3T"Ҭ ] 3$we5b,Rs YZ